diff --git a/dag/gunbc/discovery_census.dag b/dag/gunbc/discovery_census.dag index 4df3ee071a6..e83ecc7dc88 100644 --- a/dag/gunbc/discovery_census.dag +++ b/dag/gunbc/discovery_census.dag @@ -12,7 +12,7 @@ import gunbc.build_target { } import v2.workflow.required_floor { RequiredFloorDisposition, - Planned, DeclinedLongModule, DeclinedLiveTree, + Planned, DeclinedLongModule, DeclinedFixtureMember, required_floor_site_disposition, } import v2.std.live_tree { LiveTreeDisposition } @@ -52,6 +52,8 @@ import std.integer { Int } // on the ENTRY PATH a witness was found in and carries no authored module name at all. The two // are different keys for different questions — where a declaration was found, versus which // identity it is — and the disposition below can only be computed from the second. +// `reads_live_tree` now serves selection-eligibility consumers only. Required-floor disposition +// no longer consumes it, and retaining the field here must not recreate the deleted decline. type DiscoveredSite { module_path: String function: String @@ -197,8 +199,7 @@ fn census_fold_site(state: CensusFoldState, site: DiscoveredSite) -> CensusFoldS CensusRow { label: l, disposition: required_floor_site_disposition( - module_path: site.module_path, - reads_live_tree: site.reads_live_tree + module_path: site.module_path ) } ], state.rows_reversed), @@ -244,7 +245,7 @@ fn census_partition_step(acc: CensusPartition, row: CensusRow) -> CensusPartitio Planned => CensusPartition { planned: concat([row], acc.planned), declined: acc.declined } DeclinedLongModule { matched_prefix: _ } => CensusPartition { planned: acc.planned, declined: concat([row], acc.declined) } - DeclinedLiveTree => + DeclinedFixtureMember { matched_prefix: _ } => CensusPartition { planned: acc.planned, declined: concat([row], acc.declined) } } } @@ -296,7 +297,7 @@ fn required_aggregate_from_census(census: SiteCensus) -> RequiredAggregateDeriva // THE COUNTS ARE DERIVED AND THE PARTITION IS EXACT BY CONSTRUCTION, so there is no // partition-exactness check here. Each row holds exactly one disposition and the fold below -// matches it with no wildcard, so `offered` is the sum of the four arms because there is nowhere +// matches it with no wildcard, so `offered` is the sum of the three arms because there is nowhere // else for a row to go — a check restating that would be validation standing where construction // already holds (DESIGN §5). The floor's own host-side partition check exists because THERE the // counters are incremented independently and can drift; here they cannot. @@ -309,7 +310,7 @@ type CensusCounts { offered: Int planned: Int declined_long_module: Int - declined_live_tree: Int + declined_fixture_member: Int } fn census_counts_zero() -> CensusCounts { @@ -317,7 +318,7 @@ fn census_counts_zero() -> CensusCounts { offered: 0, planned: 0, declined_long_module: 0, - declined_live_tree: 0 + declined_fixture_member: 0 } } @@ -328,21 +329,21 @@ fn census_counts_add(counts: CensusCounts, d: RequiredFloorDisposition) -> Censu offered: counts.offered + 1, planned: counts.planned + 1, declined_long_module: counts.declined_long_module, - declined_live_tree: counts.declined_live_tree + declined_fixture_member: counts.declined_fixture_member } DeclinedLongModule { matched_prefix: _ } => CensusCounts { offered: counts.offered + 1, planned: counts.planned, declined_long_module: counts.declined_long_module + 1, - declined_live_tree: counts.declined_live_tree + declined_fixture_member: counts.declined_fixture_member } - DeclinedLiveTree => + DeclinedFixtureMember { matched_prefix: _ } => CensusCounts { offered: counts.offered + 1, planned: counts.planned, declined_long_module: counts.declined_long_module, - declined_live_tree: counts.declined_live_tree + 1 + declined_fixture_member: counts.declined_fixture_member + 1 } } } diff --git a/dag/gunbc/emitter_shared_layer_producer_census.dag b/dag/gunbc/emitter_shared_layer_producer_census.dag index fb08ffe2b2d..85ced7a3bec 100644 --- a/dag/gunbc/emitter_shared_layer_producer_census.dag +++ b/dag/gunbc/emitter_shared_layer_producer_census.dag @@ -84,9 +84,10 @@ type SharedLayerProducer { // witness_test holds the repair and its two controls. Against the pre-repair binary the repair arm // returns false and both controls return true; against the post-repair binary all three return // true -- taken by running each test fn directly, which is a real execution receipt. It is NOT a -// standing one: that file declares ReadsLiveTree truthfully, and v2.workflow.required_floor's -// retained DeclinedLiveTree arm therefore discovers and declines it, so nothing re-takes these -// measurements until that arm's staged deletion lands. BLAST RADIUS: a full required-regen over the +// standing one on main before this cut: that file declares ReadsLiveTree truthfully, and the +// now-deleted DeclinedLiveTree arm discovered and declined it. With the root deletion these rows +// execute; their terminal dispositions, rather than this pre-cut note, state the current result. +// BLAST RADIUS: a full required-regen over the // 135-module seed subject drifted exactly one file, v1_compiler_emit_rust.rs -- the repair's own // mirror -- and re-ran first_generation_equal=true once that mirror was installed. // diff --git a/dag/gunbc/floor_non_verdict_classification.dag b/dag/gunbc/floor_non_verdict_classification.dag index 6e11b1eaada..a55d2ace27c 100644 --- a/dag/gunbc/floor_non_verdict_classification.dag +++ b/dag/gunbc/floor_non_verdict_classification.dag @@ -79,6 +79,8 @@ data closure_dependent_repaid_note: String = "EMPTY, AND THAT IS A REPAYMENT REC data closure_dependent_rows: List = [] +data realization_attempt_branch_repaid_note: String = "THE COMPOSED #9106 BRANCH CONTRIBUTED A TENTH ClosureDependentResolution specimen: gunbc.test.claim.realization_attempt_keystone_test.witness_planted_minimal_module_emits passed in its 179-module entry closure but the old floor union shadowed emit_produced's pattern-bound render with std.layout.render(doc, proto), producing the same missing-proto error as produced_decl_support_preserved. #9259 makes the lexical Value::Fn binding win, so this branch-only non-verdict and its expected-red row retire while the witness remains an ordinary regression control." + data closure_independent_repaid_note: String = "EMPTY, AND THAT IS A REPAYMENT RECEIPT RATHER THAN A MISSING MEASUREMENT. This list held the four v2.test.manual.bootstrap_footprint_anchor identities, the only ClosureIndependent / HonestDebtWithStatedTrigger rows in the population. Their cause was a Symbol-declared field holding Int code points: semantic_decl_string_to_bundle_node folded a String into character atoms carrying raw code points, and canonical_hash_of_connective routed that field into content_hash_atom -> atom_identity_hash, which requires a string, so the hash threw before any assertion ran. Repaired at the PRODUCER by giving character atoms a string identity through from_code_point, with code_point as its inverse on the two decoders. All four now ANSWER: three PASS and bootstrap_footprint_canonical_holds FAILS honestly, so the four left this roster and the three passing ones left floor_expected_red in the same change. The list stays declared rather than deleted because the CAUSE remains constructible -- nothing prevents another producer putting a non-Symbol into Atom.identity -- and an emptied arm with its reason recorded is a different fact from an arm that never existed." data closure_independent_rows: List = [] diff --git a/dag/gunbc/floor_route_gap_seed_growth.dag b/dag/gunbc/floor_route_gap_seed_growth.dag new file mode 100644 index 00000000000..b4c72f77aed --- /dev/null +++ b/dag/gunbc/floor_route_gap_seed_growth.dag @@ -0,0 +1,20 @@ +module gunbc.floor_route_gap_seed_growth + +import gunbc.roadmap_model { RoadmapNodeId } +import gunbc.seed_growth { SeedGrowthJustification } +import std.decl_ref { DeclarationRef, WholeDeclaration } + +// FORWARD-FREEZE RECEIPT for the typed route-gap expectation consumed by the required floor. +// The modeled authority is v2.workflow.floor_route_gap FloorRouteGapExpectation; these three +// declarations are its seed-side realization at the interpreter boundary, not a second policy. +data floor_route_gap_seed_growth_justification: SeedGrowthJustification = SeedGrowthJustification { + hand_authored_declarations: [ + DeclarationRef { module_path: "v1_compiler.cli_run", decl_name: "FloorRouteGapExpectedGround", field: WholeDeclaration }, + DeclarationRef { module_path: "v1_compiler.cli_run", decl_name: "FloorRouteGapExpectation", field: WholeDeclaration }, + DeclarationRef { module_path: "v1_compiler.cli_run", decl_name: "floor_route_gap_expectation_mismatch", field: WholeDeclaration } + ], + reason: "WHY RUST IS STILL NEEDED: the required floor executes in the seed, and v1_compiler.cli_run is the boundary that receives v1_interpreter.HermeticEffectGround after a claim executes. v2.workflow.floor_route_gap owns the expectation vocabulary and population; the Rust realization decodes that authority and refuses when the observed operation or closed ground differs, instead of letting an identity-only enrollment absorb changed evidence. A modeled row without this consumer cannot constrain the host terminal ledger.\n\nWHY IT IS ADMITTED AGAINST THE v1 FREEZE: gunbc.v1_maintenance_standing v1_seed_standing admits work serving the v2 self-host program. The required floor is the instrument guarding that program, and this change strengthens a pre-existing route-gap debt roster from identity-only agreement to operation-and-ground agreement. It adds no language behavior, compatibility route, escape hatch, seed feature, or emitted public surface.\n\nHAND-ITEM DELTA: +3, exactly the closed ground mirror, the decoded expectation record, and the pure mismatch classifier enumerated above. All other Rust edits are inside existing declarations and are ExistingSeedItemModified.\n\nHAND-LOC DELTA AT THIS RECEIPT: src/v1/stage0/src/cli_run.rs +223/-49 and src/v1/stage0/src/bin/claim_executor.rs +5/-5 against origin/main. The latter adds no declaration. The item observation producer is currently absent, so these diff-derived figures remain review evidence rather than a mechanically joined admission.", + owning_dissolution_lane: "v1-hand-queue-drain" as RoadmapNodeId, + trigger: "Delete the three seed declarations when the self-emitted claim executor executes the required floor and consumes v2.workflow.floor_route_gap FloorRouteGapExpectation directly; the modeled expectation then remains the sole authority and the hand-written decode/classifier disappears with the v1 floor bridge.", + current_boundary: "v2.workflow.floor_route_gap FloorRouteGapExpectation -> v1_compiler.cli_run FloorRouteGapExpectation -> v1_compiler.cli_run floor_route_gap_expectation_mismatch -> v1_compiler.cli_run run_required_floor" +} diff --git a/dag/gunbc/guarantee_rung_drop.dag b/dag/gunbc/guarantee_rung_drop.dag index 69638339e1a..bdcfdb133f6 100644 --- a/dag/gunbc/guarantee_rung_drop.dag +++ b/dag/gunbc/guarantee_rung_drop.dag @@ -1,7 +1,7 @@ module gunbc.guarantee_rung_drop import std.types { String, List, Bool, Int } -import v2.std.algebra { fold_list } +import v2.std.algebra { Cons, Empty, fold_list } // THE TYPED CARRIER FOR A DESIGN section 4b(3) RUNG DROP. // @@ -288,3 +288,97 @@ data next_rung_trigger_enforcement_stall: GuaranteeStall = GuaranteeStall { }, next_rung_trigger: "every class this repository declares below its ceiling declares it through gunbc.guarantee_rung_drop GuaranteeStall rather than in prose, at which point the population becomes a fold over rows and a stall missing its trigger has no spelling. Not satisfied by this carrier existing: one row is a carrier with a consumer, not a migrated population, and the 4b(2) obligation stays review diligence for every class still stalling in an annotation" } + +// DECLINED-LIVE-TREE CENSUS, observed by required-floor run 32882641450 after the root decline +// stopped hiding these subjects. The fifteen executing identities below project TEN facts. They +// are stalls rather than drops: no guarantee stopped holding in this change; the facts were outside +// the ladder because no required consumer executed them. `ClimbableButUnbuilt` states that each +// repair is specifiable. Assignment is a dashboard routing fact and deliberately does not live in +// this semantic carrier. + +data doc_graph_orphan_population_stall: GuaranteeStall = GuaranteeStall { + subject: "the derived documentation graph contains orphan documents", + current: OutsideTheLadder, + ceiling: MechanicallyPreventable, + blocker: ClimbableButUnbuilt, + population: BoundedPopulation { members: Cons { head: "test.claim.doc_reachability_witness.doc_graph_has_no_orphan_docs", tail: Cons { head: "v2.test.lens_doc_reachability.doc_reachability_test.doc_graph_has_no_orphan_docs", tail: Cons { head: "v2.test.lens_doc_reachability.doc_reachability_test.doc_graph_is_clean", tail: Empty {} } } } }, + next_rung_trigger: "the derived orphan-document identity population is empty and every enrolled projection reports NowPassing" +} + +data doc_graph_dangling_link_population_stall: GuaranteeStall = GuaranteeStall { + subject: "the derived documentation graph contains dangling links", + current: OutsideTheLadder, + ceiling: MechanicallyPreventable, + blocker: ClimbableButUnbuilt, + population: BoundedPopulation { members: Cons { head: "test.claim.doc_reachability_witness.doc_graph_has_no_dangling_links", tail: Cons { head: "v2.test.lens_doc_reachability.doc_reachability_test.doc_graph_has_no_dangling_links", tail: Cons { head: "v2.test.lens_doc_reachability.doc_reachability_test.doc_graph_is_clean", tail: Empty {} } } } }, + next_rung_trigger: "the derived dangling-link identity population is empty and every enrolled projection reports NowPassing" +} + +data enforcement_live_closure_gate_stall: GuaranteeStall = GuaranteeStall { + subject: "the live enforcement closure and its question-zero gate are non-green", + current: OutsideTheLadder, + ceiling: MechanicallyPreventable, + blocker: ClimbableButUnbuilt, + population: BoundedPopulation { members: Cons { head: "v2.test.claim.enforcement.lens_module_gate_witness.lens_closure_question_zero_holds_live", tail: Cons { head: "v2.test.claim.enforcement.lens_module_gate_witness.lens_module_gate_holds_live", tail: Cons { head: "v2.test.claim.enforcement.lens_module_gate_witness.question_zero_verdict_live_holds", tail: Empty {} } } } }, + next_rung_trigger: "the live closure question returns zero and both gate projections report true" +} + +data mandatory_tag_live_corpus_stall: GuaranteeStall = GuaranteeStall { + subject: "the live corpus contains a mandatory-tag violation", + current: OutsideTheLadder, + ceiling: MechanicallyPreventable, + blocker: ClimbableButUnbuilt, + population: BoundedPopulation { members: Cons { head: "v2.lens.mandatory_tag.corpus_scan_witness_test.corpus_live_clean_tree_wall_holds", tail: Empty {} } }, + next_rung_trigger: "the derived mandatory-tag violation population is empty" +} + +data parse_ingest_grammar_relation_stall: GuaranteeStall = GuaranteeStall { + subject: "parse and ingest disagree over the same grammar round trip", + current: OutsideTheLadder, + ceiling: StructurallyGuaranteed, + blocker: ClimbableButUnbuilt, + population: BoundedPopulation { members: Cons { head: "v2.test.execution.emit_ingest_grammar_relation_round_trip.same_grammar_parse_ingest_bridge_holds", tail: Empty {} } }, + next_rung_trigger: "the same-grammar parse-to-ingest round trip holds" +} + +data self_host_candidate_generation_add_slice_stall: GuaranteeStall = GuaranteeStall { + subject: "self-host candidate generation, translation, and emission disagree on the add slice", + current: OutsideTheLadder, + ceiling: MechanicallyPreventable, + blocker: ClimbableButUnbuilt, + population: BoundedPopulation { members: Cons { head: "v2.test.execution.self_host_candidate_generation.candidate_generation_translate_self_emit_dag_add_slice_holds", tail: Empty {} } }, + next_rung_trigger: "candidate generation, translation, and self-emission agree on the add slice" +} + +data non_fold_residue_roster_stall: GuaranteeStall = GuaranteeStall { + subject: "the live non-fold residue contains an unrostered or stale identity", + current: OutsideTheLadder, + ceiling: MechanicallyPreventable, + blocker: ClimbableButUnbuilt, + population: BoundedPopulation { members: Cons { head: "v2.test.lens_non_fold_residue.non_fold_residue_test.non_fold_residue_no_unrostered_or_stale", tail: Empty {} } }, + next_rung_trigger: "the derived unrostered and stale non-fold-residue populations are both empty" +} + +data retained_rust_live_tree_migration_stall: GuaranteeStall = GuaranteeStall { + subject: "live Rust-test discovery disagrees with the retained-kernel migration authority", + current: OutsideTheLadder, + ceiling: MechanicallyPreventable, + blocker: ClimbableButUnbuilt, + population: BoundedPopulation { members: Cons { head: "v2.test.lens_test_migration_debt.test_migration_debt_test.retained_rust_kernel_wall_holds_against_live_tree", tail: Empty {} } }, + next_rung_trigger: "live Rust-test discovery and the retained-kernel authority join exactly" +} + +// REQUIRED-FLOOR RUN 32942047138 first executed this ReadsLiveTree carrier after #9284 landed. +// The direct byte-equality witness and its aggregate both returned false: one underlying fact, +// namely that the committed .gitattributes no longer equals its emitting authority. This is real +// generated-artifact drift, not a stale expectation. The floor cut's generated-artifact drift +// gates are currently absent, so nothing refused the authority/artifact disagreement when it was +// introduced; this bounded row keeps the two projections attached to the one repair obligation. +data gitattributes_committed_emit_drift_stall: GuaranteeStall = GuaranteeStall { + subject: "the committed .gitattributes differs from the bytes derived by its emitting authority", + current: OutsideTheLadder, + ceiling: MechanicallyPreventable, + blocker: ClimbableButUnbuilt, + population: BoundedPopulation { members: Cons { head: "test.claim.gitattributes_emit_witness.witness_committed_matches_emit_holds", tail: Cons { head: "test.claim.gitattributes_emit_witness.witness_holds", tail: Empty {} } } }, + next_rung_trigger: "node://adhoc-16f7520a-85f lands: identify the authority edit that introduced the drift, regenerate .gitattributes from that authority, and restore a required generated-artifact drift gate so later authority/artifact disagreement refuses" +} diff --git a/dag/gunbc/seed_growth_admission.dag b/dag/gunbc/seed_growth_admission.dag index 2ae70a6e531..0f4a6b0b6a6 100644 --- a/dag/gunbc/seed_growth_admission.dag +++ b/dag/gunbc/seed_growth_admission.dag @@ -42,6 +42,7 @@ import gunbc.rust_item_identity { RustItemIdentity, rust_item_identity_key } import gunbc.seed_growth { SeedGrowthJustification } import gunbc.stage0_rust_host_observation { stage0_rust_observation_seed_growth_justification } import gunbc.floor_non_verdict_enrollment { floor_non_verdict_seed_growth_justification } +import gunbc.floor_route_gap_seed_growth { floor_route_gap_seed_growth_justification } import gunbc.whole_corpus_compile_admission { whole_corpus_compile_seed_growth_justification } import std.decl_ref { DeclarationRef, WholeDeclaration } import std.disposition { Disposition } @@ -146,6 +147,7 @@ fn seed_growth_justification_roster() -> List { [ anonymous_record_resolution_seed_growth_justification, floor_non_verdict_seed_growth_justification, + floor_route_gap_seed_growth_justification, stage0_rust_observation_seed_growth_justification, observation_scoped_run_seed_growth_justification(), whole_corpus_compile_seed_growth_justification, diff --git a/dag/gunbc/witness_deferral_freeze.dag b/dag/gunbc/witness_deferral_freeze.dag index 2793eace4de..25b62b0386b 100644 --- a/dag/gunbc/witness_deferral_freeze.dag +++ b/dag/gunbc/witness_deferral_freeze.dag @@ -91,7 +91,7 @@ data witness_deferral_freeze_forward_rule_rung_drop: GuaranteeRungDrop = Guarant restoration_trigger: "BOTH halves: a cadence that actually executes offline-homed witnesses exists, so a green witness under such a path has a truthful admission row to write; AND a required run enters the discovery-corpus path, so refuse_unexecuted_deferred_witnesses can fire when it does not" } -data witness_deferral_freeze_shrink_log_note: String = "SHRINK LOG. 2026-08-25 — src/v2/test/claim/enforcement_inventory_witness_test.dag [partial], 7 identities replaced by 1 executing identity: required-floor run 32794539384 safety-interrupted seven tests because each independently acquired lens_enforcement_inventory_live and its whole-corpus declaration facts. enforcement_inventory_global_receipt_holds acquires that immutable global inventory once and folds all seven assertions over the shared value; the seven old witness declarations and frozen rows delete together, while the three cheap non-inventory siblings remain frozen. The 701-identity / 152-entry figures the notes around this one quote are the FREEZE-POINT BASELINE and are deliberately not restated as the roster's current size — a hand-maintained live count is the change detector DESIGN section 5's oracle rule rejects, and the roster below is the authority for what the population is right now. This row records migrations OUT, which is the only direction permitted, so that the baseline stays legible as history rather than decaying into a false present-tense claim. 2026-08-24 — 2 entries (dag/test/claim/deploy_access_privilege_witness_test.dag [partial], dag/test/claim/host_effect_apply_witness_test.dag [partial]), 4 identities, DELETED not exempted: these identities were simultaneously enrolled in v2.workflow.floor_route_gap floor_route_gap_roster — a typed receipt that the required floor EXECUTED the identity and could not route it to its subject — and path-deferred here as LegacyFrozenPathDeferral, which declares the identity has no executing consumer. Both claims cannot hold of one identity. The contradiction is a property of main standalone and NOT a branch or merge artifact, which is stated explicitly because an earlier revision of this row cited a merge head and would have sent a future reader looking for a branch that no longer exists: at main head 8ab8a8e75af37a1f8b15021048ec3c5f6c98beb6 all four qualified identities are present in floor_route_gap_chunk_04, one occurrence each, having been added there when the three unconditional shell.Exec mock arms were deleted (gunbc#9049), while the frozen rows date from gunbc#7804's bulk sweep of legacy path-only debt. Computed the same way as the 2026-08-19 sweep below — joining floor_route_gap_roster against this file's frozen_path_deferrals, qualifying every frozen row through its own entry's module line (not its path string) — 4 of 614 qualified freeze identities across 2 entries collided, against a route-gap denominator of 110 enrolled rows spanning every floor_route_gap_chunk_* function; the join is empty after this change, so the check is discriminating rather than vacuously green. Run 32761519653 observed the resulting RouteGapFreezeIntersection refusal. The typed refusal proves required-floor consumption to the effect boundary, so the LegacyFrozenPathDeferral rows are stale evidence rather than a live exemption; the route-gap receipts stay, because removing them instead would delete a true measurement to preserve a false classification and silently un-count four real no-route gaps. Nothing is rehomed by this retirement and no cadence receives it — the witnesses already execute on the required floor — so the disposition is DELETED, matching the 2026-08-19 38-identity sweep below, which is the same shape: a frozen row naming a witness an executing roster already consumes. Both entries are partial and every non-colliding sibling remains frozen. 2026-08-19 — dag/test/claim/srv3_host_effect_apply_witness_test.dag [partial], 2 identities (witness_srv3_nbd_proxy_apply_observe_unimplemented_refuses_fail_closed, srv3_nbd_proxy_serve_realize_layer_dissolves_via_host_effect_nbd_proxy_serve), DELETED not migrated and not exempted: host_effect_nbd_proxy_serve_dissolution_trigger dissolved (observe-side port/unit read-back grounded on gunbc.systemctl_is_active_read; actuate-side typed argv dispatch via gunbc.systemd_run_transient / gunbc.systemctl_stop_run retired the WitnessBin scaffolding), so the module's disposition became std.disposition.Terminal and the two witness functions were rewritten under new names (witness_srv3_nbd_proxy_apply_emit_artifact_transport_observe_refuses_fail_closed, srv3_nbd_proxy_serve_realize_layer_is_terminal_via_host_effect_nbd_proxy_serve) that assert the grounded/Terminal behavior instead of the old stub/Scaffold behavior. The old identities no longer exist in the tree under those names, so their frozen rows are StaleFrozenPathDeferral and delete in this change rather than after it; this is a shrink, and the remaining functions at this entry are untouched. 2026-08-19 — 24 entries (dag/test/claim/ci_exclusion_proof_test.dag, dag/test/claim/deploy_access_privilege_witness_test.dag [partial], dag/test/claim/host_effect_apply_witness_test.dag [partial], dag/test/claim/interp_recorded_fixture_witness_test.dag, dag/test/claim/random_bytes_csprng_witness_test.dag, dag/test/claim/self_host_00_compile_behavioral_witness_test.dag, dag/test/claim/self_host_01_tokenize_behavioral_witness_test.dag, dag/test/claim/self_host_02_parse_behavioral_witness_test.dag, dag/test/claim/self_host_03_ingest_behavioral_witness_test.dag, dag/test/claim/self_host_03_resolve_behavioral_witness_test.dag, dag/test/claim/self_host_04_infer_behavioral_witness_test.dag, dag/test/claim/self_host_materialization_carriers_behavioral_witness_test.dag, dag/test/claim/self_host_program_assembly_behavioral_witness_test.dag, dag/test/claim/self_host_program_partition_behavioral_witness_test.dag, dag/test/claim/self_host_source_authority_behavioral_witness_test.dag, dag/test/claim/srv3_host_effect_apply_witness_test.dag [partial], src/v2/test/claim/execution/dag_add_emit_round_trip_test.dag [partial], src/v2/test/claim/execution/emit_host_complement_equals_eval_test.dag, src/v2/test/claim/execution/emit_host_variant_construct_equals_eval_test.dag, src/v2/test/claim/execution/emit_ingest_python_same_language_round_trip_test.dag [partial], src/v2/test/claim/execution/emit_ingest_type_decl_round_trip_test.dag [partial], src/v2/test/claim/execution/emit_ingest_typescript_same_language_round_trip_test.dag [partial], src/v2/test/claim/execution/floor_diff_observe_witness_test.dag, src/v2/test/claim/execution/proactive_verification_ledger_overlap_execution_test.dag), 38 identities, DELETED not exempted: these identities were simultaneously enrolled in v2.workflow.floor_expected_red's known-red roster (removable only by observing a pass) and path-deferred here as LegacyFrozenPathDeferral (declared never-executed) — a contradictory intersection, because the required floor already treats each of these identities as an executing, known-red subject, so their freeze classification was stale rather than load-bearing; a frozen row naming a witness the required floor already runs has no LegacyFrozenPathDeferral standing left to protect. Computed by joining floor_expected_red_roster against this file's frozen_path_deferrals, qualifying every frozen row through its own entry's module line (not its path string), at commit 063a604e0099c56c3e0a1f72af60d7a6199d1f0b: 38 of 669 qualified freeze identities across 24 entries collided. All 24 entries carry an independently executing consumer already (WitnessHasExecutingConsumer via floor_expected_red), so retirement here removes no coverage — 15 entries had every one of their functions collide and are deleted whole; 9 entries had only some functions collide and keep their remaining, non-colliding functions frozen. A construction wall (expected_red_freeze_intersection, wired into run_required_floor in src/v1/stage0/src/cli_run.rs) now refuses this exact contradiction going forward: any future frozen row whose qualified identity re-enters floor_expected_red_roster fails the required floor with a located, counted refusal naming the exact colliding identities and the git head the collision was observed at, rather than silently coexisting. 2026-08-19 — src/v2/test/claim/execution/long/add_arrow_eval_by_execution_test.dag, 4 identities, and src/v2/test/claim/execution/long/pick_ingested_probe_test.dag, 1 identity, DELETED as subsumed or duplicate coverage, none migrated and none exempted. add_arrow_eval_tokenize_holds, add_arrow_eval_parse_holds and add_arrow_eval_normalize_holds were the shallow steps of a staircase whose deepest step, add_arrow_eval_resolve_holds, cannot reach resolve unless all three stages accepted, so four stages were costing ten stage-runs across four frames to assert what one row asserts; the survivor reds on exactly the refusals they redded on and what is lost is which stage failed. add_arrow_eval_produced_add_body_executes_holds had a body byte-identical to add_arrow_eval_source_driven_add_executes_holds — and BOTH ARE CURRENTLY RED, which is stated rather than left for a reader to assume a green row was removed: main head 5ee2572 fails the pair identically, along with add_arrow_eval_direct_runtime_holds, add_arrow_eval_generality_executes_holds and add_arrow_eval_lazy_arm_branch_suppression_holds, the five identities floor_expected_red already documents as enrolled-and-correctly-red before this module relocated. The surviving twin carries the red; deleting a duplicate of a failing claim removes a second report of one failure, not the report of it. pick_probe_resolved_else_arm_has_magnitude_child_holds differed from its then-arm sibling only in an arm index over one source at one stage, and both arms are now asserted against one bound resolved module; both passed on main and the merged row passes. In every case the assertion survives on a row that keeps it; none of this coverage is relocated because none of it was ever separate. 2026-08-19 — src/v2/test/claim/execution/dag_add_emit_round_trip_test.dag, 1 identity (dag_add_emit_add_fn_accepts_holds), DELETED as duplicate coverage, not migrated and not exempted: its whole body was a call to its sibling dag_add_emit_matches_serialize_holds, so it asserted nothing that sibling did not already assert and paid a second full emit-and-serialize crossing to assert it, each claim evaluating in its own frame. Deleting it removes a crossing and no fact. This is a shrink by deletion of the witness, and the coverage it named is not relocated because it was never separate from the sibling row that keeps it. 2026-08-11 — dag/test/claim/long/inert_lens_hygiene_witness_test.dag, 2 identities, DELETED not migrated and not exempted: the inert-lens census the two witnesses read is gone from the tree entirely, along with the v2.lens.inert_lens module, its two host builtins and the registry/contract rows that obligated it, so the witnesses have no subject to execute against. A frozen row naming a witness the tree no longer carries is a StaleFrozenPathDeferral refusal, which is why the row deletes in the same change rather than after it. This is a shrink by deletion of the subject, NOT by a cadence enrolling the rows — the coverage those two witnesses provided is not relocated anywhere and the scope narrowing is declared in DESIGN §6. 2026-08-06 — src/v2/test/claim/long/realization_vocabulary_containment_witness_test.dag, 1 identity, MIGRATED not exempted: TS-0/LANG-2 enrolled realization_vocab_live_corpus_receipt_holds on falsifier_substrate_long_lane_rows (FalsifierSubstrateLongLane cadence), so the freeze row deletes and the live-corpus receipt executes on the scheduled lane. 2026-08-05 — src/v2/test/claim/long/orchestration_while_emit_test.dag, 14 identities, MIGRATED not exempted: the file returned to src/v2/workflow/orchestration_while_emit_test.dag, the per-PR-discovered path it occupied before gunbc#7098 relocated it, so its rows now classify as WitnessHasExecutingConsumer and the freeze row had to go — a row naming a witness the tree no longer carries at that entry is a StaleFrozenPathDeferral refusal, and its diagnostic says to delete it in the change that moved the witness. Measured eval justifying the return, on a load-average-28 host: 94 / 54 / 36 / 8 ms per witness against the 5000ms gunbc_ci_fast_lane_witness_eval_budget; those are wall figures against a thread-CPU budget, and cpu <= wall for one witness thread, so the bound runs the safe way. Rationale and the receipt live with the witness in orch_while_unfreeze_note." +data witness_deferral_freeze_shrink_log_note: String = "SHRINK LOG. 2026-08-26 — 3 entries (src/v2/test/claim/enforcement/lens_module_gate_witness_test.dag [partial], src/v2/test/claim/execution/emit_ingest_grammar_relation_round_trip_test.dag [partial], src/v2/test/claim/execution/self_host_candidate_generation_test.dag [partial]), 5 identities, DELETED not exempted: required-floor run 32916382395 on merge head bf1cea59f3f1149a68918a69a39c004cba357632 refused ExpectedRedFreezeIntersection on exactly these five rows after the DeclinedLiveTree census enrolled their observed semantic reds. The expected-red roster proves they now have an executing required-floor consumer, so LegacyFrozenPathDeferral is stale evidence rather than a live exemption. Every non-colliding sibling in all three partial entries remains frozen. 2026-08-25 — src/v2/test/claim/enforcement_inventory_witness_test.dag [partial], 7 identities replaced by 1 executing identity: required-floor run 32794539384 safety-interrupted seven tests because each independently acquired lens_enforcement_inventory_live and its whole-corpus declaration facts. enforcement_inventory_global_receipt_holds acquires that immutable global inventory once and folds all seven assertions over the shared value; the seven old witness declarations and frozen rows delete together, while the three cheap non-inventory siblings remain frozen. 2026-08-25 — 3 entries (src/v2/test/claim/complexity/accumulator_copy_roster_gate_std_test.dag [partial], src/v2/test/claim/complexity/accumulator_copy_roster_gate_test.dag [partial], src/v2/test/claim/enforcement/cost_coverage_witness_test.dag [partial]), 3 identities, DELETED not migrated or exempted: required-floor run 32794539384 proved these rows never produced a verdict — two called a scanner absent from the loaded execution index and one divided by zero. The witness declarations delete in the same change rather than being enrolled as semantic reds, so their LegacyFrozenPathDeferral rows would be stale; every sibling at all three entries remains frozen. The 701-identity / 152-entry figures the notes around this one quote are the FREEZE-POINT BASELINE and are deliberately not restated as the roster's current size — a hand-maintained live count is the change detector DESIGN section 5's oracle rule rejects, and the roster below is the authority for what the population is right now. This row records migrations OUT, which is the only direction permitted, so that the baseline stays legible as history rather than decaying into a false present-tense claim. 2026-08-24 — 2 entries (dag/test/claim/deploy_access_privilege_witness_test.dag [partial], dag/test/claim/host_effect_apply_witness_test.dag [partial]), 4 identities, DELETED not exempted: these identities were simultaneously enrolled in v2.workflow.floor_route_gap floor_route_gap_roster — a typed receipt that the required floor EXECUTED the identity and could not route it to its subject — and path-deferred here as LegacyFrozenPathDeferral, which declares the identity has no executing consumer. Both claims cannot hold of one identity. The contradiction is a property of main standalone and NOT a branch or merge artifact, which is stated explicitly because an earlier revision of this row cited a merge head and would have sent a future reader looking for a branch that no longer exists: at main head 8ab8a8e75af37a1f8b15021048ec3c5f6c98beb6 all four qualified identities are present in floor_route_gap_chunk_04, one occurrence each, having been added there when the three unconditional shell.Exec mock arms were deleted (gunbc#9049), while the frozen rows date from gunbc#7804's bulk sweep of legacy path-only debt. Computed the same way as the 2026-08-19 sweep below — joining floor_route_gap_roster against this file's frozen_path_deferrals, qualifying every frozen row through its own entry's module line (not its path string) — 4 of 614 qualified freeze identities across 2 entries collided, against a route-gap denominator of 110 enrolled rows spanning every floor_route_gap_chunk_* function; the join is empty after this change, so the check is discriminating rather than vacuously green. Run 32761519653 observed the resulting RouteGapFreezeIntersection refusal. The typed refusal proves required-floor consumption to the effect boundary, so the LegacyFrozenPathDeferral rows are stale evidence rather than a live exemption; the route-gap receipts stay, because removing them instead would delete a true measurement to preserve a false classification and silently un-count four real no-route gaps. Nothing is rehomed by this retirement and no cadence receives it — the witnesses already execute on the required floor — so the disposition is DELETED, matching the 2026-08-19 38-identity sweep below, which is the same shape: a frozen row naming a witness an executing roster already consumes. Both entries are partial and every non-colliding sibling remains frozen. 2026-08-24 — 10 entries (dag/test/claim/artifact_store_fs_witness_test.dag [partial], dag/test/claim/direct_rust_door_write_compile_witness_test.dag, dag/test/claim/external_model_scope_live_cover_witness_test.dag, dag/test/claim/served_surface_browser_artifact_integrity_witness_test.dag, dag/test/claim/stage0_rust_host_observation_live_witness_test.dag, dag/test/manual/git_upstream_model_execution_test.dag, dag/test/manual/mercurial_upstream_model_execution_test.dag, dag/test/manual/pijul_upstream_model_execution_test.dag, src/v2/test/claim/execution/native_selected_witness_bundle_test.dag [partial], src/v2/test/claim/manual/emit_source_store_test.dag [partial]), 19 identities, MIGRATED not exempted: run 32721781133 executed each through the required floor and observed an interpreter-typed HermeticHostEffectRefused route gap; typed enrollment now makes that executing outcome a checked debt contract, so LegacyFrozenPathDeferral no longer describes their standing. The exact route-gap/freeze join was recomputed after retirement at head d4f3aab194c and is empty; non-colliding siblings remain frozen. No construction wall currently refuses the route-gap/freeze pair, unlike expected_red_freeze_intersection, so this join is recorded evidence rather than a mechanically guarded invariant. 2026-08-24 — 3 entries (src/v2/test/claim/enforcement/cost_coverage_witness_test.dag [partial], src/v2/test/claim/program_assembly/real_ingest_test.dag [partial], src/v2/test/claim/self_host/compiler_closure_emit_from_ingest_test.dag [partial]), 6 identities, MIGRATED not exempted: RequiredFloorDisposition.DeclinedLiveTree was deleted and run 32730435751 proved these identities are now planned as executing expected-red witnesses; retaining LegacyFrozenPathDeferral simultaneously asserted that they never execute, and the expected_red_freeze_intersection construction wall refused the contradiction at head 3012f9ce4ec. The six exact frozen rows retire while every non-colliding sibling remains frozen; their executing consumer is the required floor and their red standing is carried by v2.workflow.floor_expected_red. 2026-08-19 — dag/test/claim/srv3_host_effect_apply_witness_test.dag [partial], 2 identities (witness_srv3_nbd_proxy_apply_observe_unimplemented_refuses_fail_closed, srv3_nbd_proxy_serve_realize_layer_dissolves_via_host_effect_nbd_proxy_serve), DELETED not migrated and not exempted: host_effect_nbd_proxy_serve_dissolution_trigger dissolved (observe-side port/unit read-back grounded on gunbc.systemctl_is_active_read; actuate-side typed argv dispatch via gunbc.systemd_run_transient / gunbc.systemctl_stop_run retired the WitnessBin scaffolding), so the module's disposition became std.disposition.Terminal and the two witness functions were rewritten under new names (witness_srv3_nbd_proxy_apply_emit_artifact_transport_observe_refuses_fail_closed, srv3_nbd_proxy_serve_realize_layer_is_terminal_via_host_effect_nbd_proxy_serve) that assert the grounded/Terminal behavior instead of the old stub/Scaffold behavior. The old identities no longer exist in the tree under those names, so their frozen rows are StaleFrozenPathDeferral and delete in this change rather than after it; this is a shrink, and the remaining functions at this entry are untouched. 2026-08-19 — 24 entries (dag/test/claim/ci_exclusion_proof_test.dag, dag/test/claim/deploy_access_privilege_witness_test.dag [partial], dag/test/claim/host_effect_apply_witness_test.dag [partial], dag/test/claim/interp_recorded_fixture_witness_test.dag, dag/test/claim/random_bytes_csprng_witness_test.dag, dag/test/claim/self_host_00_compile_behavioral_witness_test.dag, dag/test/claim/self_host_01_tokenize_behavioral_witness_test.dag, dag/test/claim/self_host_02_parse_behavioral_witness_test.dag, dag/test/claim/self_host_03_ingest_behavioral_witness_test.dag, dag/test/claim/self_host_03_resolve_behavioral_witness_test.dag, dag/test/claim/self_host_04_infer_behavioral_witness_test.dag, dag/test/claim/self_host_materialization_carriers_behavioral_witness_test.dag, dag/test/claim/self_host_program_assembly_behavioral_witness_test.dag, dag/test/claim/self_host_program_partition_behavioral_witness_test.dag, dag/test/claim/self_host_source_authority_behavioral_witness_test.dag, dag/test/claim/srv3_host_effect_apply_witness_test.dag [partial], src/v2/test/claim/execution/dag_add_emit_round_trip_test.dag [partial], src/v2/test/claim/execution/emit_host_complement_equals_eval_test.dag, src/v2/test/claim/execution/emit_host_variant_construct_equals_eval_test.dag, src/v2/test/claim/execution/emit_ingest_python_same_language_round_trip_test.dag [partial], src/v2/test/claim/execution/emit_ingest_type_decl_round_trip_test.dag [partial], src/v2/test/claim/execution/emit_ingest_typescript_same_language_round_trip_test.dag [partial], src/v2/test/claim/execution/floor_diff_observe_witness_test.dag, src/v2/test/claim/execution/proactive_verification_ledger_overlap_execution_test.dag), 38 identities, DELETED not exempted: these identities were simultaneously enrolled in v2.workflow.floor_expected_red's known-red roster (removable only by observing a pass) and path-deferred here as LegacyFrozenPathDeferral (declared never-executed) — a contradictory intersection, because the required floor already treats each of these identities as an executing, known-red subject, so their freeze classification was stale rather than load-bearing; a frozen row naming a witness the required floor already runs has no LegacyFrozenPathDeferral standing left to protect. Computed by joining floor_expected_red_roster against this file's frozen_path_deferrals, qualifying every frozen row through its own entry's module line (not its path string), at commit 063a604e0099c56c3e0a1f72af60d7a6199d1f0b: 38 of 669 qualified freeze identities across 24 entries collided. All 24 entries carry an independently executing consumer already (WitnessHasExecutingConsumer via floor_expected_red), so retirement here removes no coverage — 15 entries had every one of their functions collide and are deleted whole; 9 entries had only some functions collide and keep their remaining, non-colliding functions frozen. A construction wall (expected_red_freeze_intersection, wired into run_required_floor in src/v1/stage0/src/cli_run.rs) now refuses this exact contradiction going forward: any future frozen row whose qualified identity re-enters floor_expected_red_roster fails the required floor with a located, counted refusal naming the exact colliding identities and the git head the collision was observed at, rather than silently coexisting. 2026-08-19 — src/v2/test/claim/execution/long/add_arrow_eval_by_execution_test.dag, 4 identities, and src/v2/test/claim/execution/long/pick_ingested_probe_test.dag, 1 identity, DELETED as subsumed or duplicate coverage, none migrated and none exempted. add_arrow_eval_tokenize_holds, add_arrow_eval_parse_holds and add_arrow_eval_normalize_holds were the shallow steps of a staircase whose deepest step, add_arrow_eval_resolve_holds, cannot reach resolve unless all three stages accepted, so four stages were costing ten stage-runs across four frames to assert what one row asserts; the survivor reds on exactly the refusals they redded on and what is lost is which stage failed. add_arrow_eval_produced_add_body_executes_holds had a body byte-identical to add_arrow_eval_source_driven_add_executes_holds — and BOTH ARE CURRENTLY RED, which is stated rather than left for a reader to assume a green row was removed: main head 5ee2572 fails the pair identically, along with add_arrow_eval_direct_runtime_holds, add_arrow_eval_generality_executes_holds and add_arrow_eval_lazy_arm_branch_suppression_holds, the five identities floor_expected_red already documents as enrolled-and-correctly-red before this module relocated. The surviving twin carries the red; deleting a duplicate of a failing claim removes a second report of one failure, not the report of it. pick_probe_resolved_else_arm_has_magnitude_child_holds differed from its then-arm sibling only in an arm index over one source at one stage, and both arms are now asserted against one bound resolved module; both passed on main and the merged row passes. In every case the assertion survives on a row that keeps it; none of this coverage is relocated because none of it was ever separate. 2026-08-19 — src/v2/test/claim/execution/dag_add_emit_round_trip_test.dag, 1 identity (dag_add_emit_add_fn_accepts_holds), DELETED as duplicate coverage, not migrated and not exempted: its whole body was a call to its sibling dag_add_emit_matches_serialize_holds, so it asserted nothing that sibling did not already assert and paid a second full emit-and-serialize crossing to assert it, each claim evaluating in its own frame. Deleting it removes a crossing and no fact. This is a shrink by deletion of the witness, and the coverage it named is not relocated because it was never separate from the sibling row that keeps it. 2026-08-11 — dag/test/claim/long/inert_lens_hygiene_witness_test.dag, 2 identities, DELETED not migrated and not exempted: the inert-lens census the two witnesses read is gone from the tree entirely, along with the v2.lens.inert_lens module, its two host builtins and the registry/contract rows that obligated it, so the witnesses have no subject to execute against. A frozen row naming a witness the tree no longer carries is a StaleFrozenPathDeferral refusal, which is why the row deletes in the same change rather than after it. This is a shrink by deletion of the subject, NOT by a cadence enrolling the rows — the coverage those two witnesses provided is not relocated anywhere and the scope narrowing is declared in DESIGN §6. 2026-08-06 — src/v2/test/claim/long/realization_vocabulary_containment_witness_test.dag, 1 identity, MIGRATED not exempted: TS-0/LANG-2 enrolled realization_vocab_live_corpus_receipt_holds on falsifier_substrate_long_lane_rows (FalsifierSubstrateLongLane cadence), so the freeze row deletes and the live-corpus receipt executes on the scheduled lane. 2026-08-05 — src/v2/test/claim/long/orchestration_while_emit_test.dag, 14 identities, MIGRATED not exempted: the file returned to src/v2/workflow/orchestration_while_emit_test.dag, the per-PR-discovered path it occupied before gunbc#7098 relocated it, so its rows now classify as WitnessHasExecutingConsumer and the freeze row had to go — a row naming a witness the tree no longer carries at that entry is a StaleFrozenPathDeferral refusal, and its diagnostic says to delete it in the change that moved the witness. Measured eval justifying the return, on a load-average-28 host: 94 / 54 / 36 / 8 ms per witness against the 5000ms gunbc_ci_fast_lane_witness_eval_budget; those are wall figures against a thread-CPU budget, and cpu <= wall for one witness thread, so the bound runs the safe way. Rationale and the receipt live with the witness in orch_while_unfreeze_note." data witness_deferral_freeze_purpose_frontier_note: String = "WHAT THIS FREEZE DELIBERATELY DOES NOT CARRY, so its coverage is not overread. A frozen row records IDENTITY only — that this exact (entry, function) was already deferred by path policy when the wall landed. It records no purpose, no measured cost, and no consumer, because it has none: the whole point of the freeze is that these 701 identities (152 entries, measured at the freeze point) were admitted without any of the three. The purpose taxonomy (which boundary, population, external effect, or resource contract justifies the size) and the per-witness cost envelope are the NEXT slice, and a frozen row is the debt marker that one is owed. @@ -188,9 +188,7 @@ data frozen_path_deferrals: List = [ FrozenPathDeferral { entry: "dag/test/claim/artifact_store_fs_witness_test.dag", functions: [ - "artifact_fs_roundtrip_holds", "artifact_fs_refuses_non_scratch_store_root_holds", - "artifact_fs_delete_then_misses_holds", "artifact_fs_mutated_input_misses_holds", - "artifact_fs_eviction_removes_only_the_evicted_key", + "artifact_fs_refuses_non_scratch_store_root_holds", "artifact_fs_eviction_of_empty_receipt_deletes_nothing" ] }, @@ -203,14 +201,6 @@ data frozen_path_deferrals: List = [ "witness_unprivileged_mutation_directive_is_refused_terminal" ] }, - FrozenPathDeferral { entry: "dag/test/claim/direct_rust_door_write_compile_witness_test.dag", functions: ["direct_rust_door_emit_write_compile_holds"] }, - FrozenPathDeferral { - entry: "dag/test/claim/external_model_scope_live_cover_witness_test.dag", - functions: [ - "red_cover_walker_refuses_missing_root", "frontier_cover_of_live_extdeps_tree_holds", - "manifest_rows_all_predate_freeze_sha" - ] - }, FrozenPathDeferral { entry: "dag/test/claim/host_effect_apply_witness_test.dag", functions: [ @@ -258,7 +248,6 @@ data frozen_path_deferrals: List = [ FrozenPathDeferral { entry: "dag/test/claim/long/commit_witness_claim_roster_witness_test.dag", functions: ["commit_witness_claim_roster_holds"] }, FrozenPathDeferral { entry: "dag/test/claim/long/import_closure_live_test.dag", functions: ["dag_import_closure_live_witness_bundle_holds"] }, FrozenPathDeferral { entry: "dag/test/claim/long/reference_closure_equivalence_test.dag", functions: ["reference_closure_b2_safety_wall_holds"] }, - FrozenPathDeferral { entry: "dag/test/claim/served_surface_browser_artifact_integrity_witness_test.dag", functions: ["witness_checked_in_screenshots_match_receipts"] }, FrozenPathDeferral { entry: "dag/test/claim/srv3_host_effect_apply_witness_test.dag", functions: [ @@ -276,23 +265,11 @@ data frozen_path_deferrals: List = [ "srv3_typed_receipt_carrier_holds_lines", "shell_bash_runner_still_present_for_p5b" ] }, - FrozenPathDeferral { - entry: "dag/test/claim/stage0_rust_host_observation_live_witness_test.dag", - functions: [ - "scaffold_host_observation_is_live_and_observed", - "scaffold_host_observation_reaches_path_derived_verdict", - "scaffold_mechanical_checks_reflect_live_classification" - ] - }, - FrozenPathDeferral { entry: "dag/test/manual/git_upstream_model_execution_test.dag", functions: ["witness_git_cli_fixture_hashes_projects_and_independently_reads_back"] }, - FrozenPathDeferral { entry: "dag/test/manual/mercurial_upstream_model_execution_test.dag", functions: ["witness_mercurial_cli_fixture_projects_and_independently_reads_back"] }, - FrozenPathDeferral { entry: "dag/test/manual/pijul_upstream_model_execution_test.dag", functions: ["witness_pijul_cli_fixture_reads_channel_sets_and_retained_conflict"] }, FrozenPathDeferral { entry: "src/v2/test/claim/complexity/accumulator_copy_roster_gate_lean_bash_test.dag", functions: ["roster_lean_zero_suspects_within_ratchet", "roster_bash_zero_suspects_within_ratchet"] }, FrozenPathDeferral { entry: "src/v2/test/claim/complexity/accumulator_copy_roster_gate_std_test.dag", functions: [ - "roster_std_change_dag_zero_suspects_within_ratchet", - "roster_std_render_repeat_string_bootstrap_within_ratchet" + "roster_std_change_dag_zero_suspects_within_ratchet" ] }, FrozenPathDeferral { entry: "src/v2/test/claim/complexity/accumulator_copy_roster_gate_swift_test.dag", functions: ["roster_swift_zero_suspects_within_ratchet"] }, @@ -304,19 +281,17 @@ data frozen_path_deferrals: List = [ "roster_glob_discovery_zero_suspects_within_ratchet", "roster_lens_traversal_zero_suspects_within_ratchet", "roster_lens_cost_model_zero_suspects_within_ratchet", - "roster_std_algebra_zero_suspects_within_ratchet", "red_control_planted_copy_still_alarms" + "roster_std_algebra_zero_suspects_within_ratchet" ] }, FrozenPathDeferral { entry: "src/v2/test/claim/enforcement/cost_coverage_witness_test.dag", functions: [ "cost_coverage_smoke_totality_holds", "cost_coverage_smoke_recomputed_by_execution_holds", - "cost_coverage_dag_logic_has_three_fn_bodies", "cost_coverage_reject_is_typed_not_silent", + "cost_coverage_reject_is_typed_not_silent", "cost_coverage_dag_tree_receipt_by_execution", "cost_coverage_v2_tree_receipt_by_execution", - "cost_coverage_unknown_fraction_is_derived", "cost_coverage_corpus_roster_nonempty", - "cost_coverage_decl_facts_roster_smoke_totality_holds", - "cost_coverage_file_row_totality_holds_on_smoke", - "cost_coverage_v2_ingested_body_is_not_decl_facts_skeleton" + "cost_coverage_corpus_roster_nonempty", + "cost_coverage_decl_facts_roster_smoke_totality_holds" ] }, FrozenPathDeferral { @@ -342,10 +317,9 @@ data frozen_path_deferrals: List = [ FrozenPathDeferral { entry: "src/v2/test/claim/enforcement/lens_module_gate_witness_test.dag", functions: [ - "lens_closure_question_zero_holds_live", "lens_module_gate_holds_live", "red_control_unenrolled_lens_refused", "red_control_redundant_verdict_remedy_refused", "red_control_genuinely_new_distinct_surface_passes", - "red_control_fully_authorized_fixture_clean", "question_zero_verdict_live_holds", + "red_control_fully_authorized_fixture_clean", "audit_residue_counted_for_known_pending_fork", "question_zero_fixture_redundant_leg_fails", "lens_closure_question_zero_live_matches_gate" ] @@ -512,8 +486,7 @@ data frozen_path_deferrals: List = [ functions: [ "emit_backward_selects_canonical_row_holds", "ingest_forward_selects_canonical_emitted_holds", - "emit_then_ingest_selector_identity_holds", "ingest_then_emit_selector_identity_holds", - "same_grammar_parse_ingest_bridge_holds" + "emit_then_ingest_selector_identity_holds", "ingest_then_emit_selector_identity_holds" ] }, FrozenPathDeferral { @@ -595,8 +568,6 @@ data frozen_path_deferrals: List = [ "native_selected_witness_bundle_primary_interpreted_verdicts_holds", "native_selected_witness_bundle_primary_native_verdicts_holds", "native_selected_witness_bundle_cutover_evidence_holds", - "native_selected_witness_bundle_cold_warm_equivalence_holds", - "native_selected_witness_bundle_discriminating_red_holds", "native_selected_witness_bundle_divergence_hard_red_holds", "native_selected_witness_bundle_missing_red_refuses_holds", "native_selected_witness_bundle_non_discriminating_red_refuses_holds", @@ -655,7 +626,6 @@ data frozen_path_deferrals: List = [ entry: "src/v2/test/claim/execution/self_host_candidate_generation_test.dag", functions: [ "translate_diagnostic_reason_symbol_inverse_holds", - "candidate_generation_translate_self_emit_dag_add_slice_holds", "translate_error_profile_roster_nonempty_holds", "translate_error_profile_rust_add_malformed_bundle_classified", "translate_error_profile_sg2_projected_arrow_serialize_accepts", @@ -1108,15 +1078,12 @@ data frozen_path_deferrals: List = [ FrozenPathDeferral { entry: "src/v2/test/claim/manual/emit_source_store_test.dag", functions: [ - "emit_source_store_cold_then_warm_holds", "emit_source_store_mutated_emitter_misses_holds", "emit_source_store_provider_gate_holds" ] }, FrozenPathDeferral { entry: "src/v2/test/claim/program_assembly/real_ingest_test.dag", functions: [ - "program_assembly_real_ingest_module_roots_parse_holds", - "program_assembly_real_ingest_host_manifest_receipt_holds", "program_assembly_real_ingest_validate_module_roots_red_on_parsed_roots" ] }, @@ -1124,7 +1091,6 @@ data frozen_path_deferrals: List = [ entry: "src/v2/test/claim/self_host/compiler_closure_emit_from_ingest_test.dag", functions: [ "self_host_closure_witness_layer_roots_reexports_authority_holds", - "compiler_closure_ingest_receipt_describes_carrier_holds", "gap4_probe_all_ingest_reads_accept_holds", "compiler_closure_scoped_ingest_parses_holds" ] }, diff --git a/dag/test/claim/data_row_shared_layer_authority_witness_test.dag b/dag/test/claim/data_row_shared_layer_authority_witness_test.dag index 749a9e6cc20..f122ce286e6 100644 --- a/dag/test/claim/data_row_shared_layer_authority_witness_test.dag +++ b/dag/test/claim/data_row_shared_layer_authority_witness_test.dag @@ -13,13 +13,12 @@ data live_tree_disposition: LiveTreeDisposition = ReadsLiveTree // itself on exactly that finding, and guarantee_floor_class_probe_witness_test states the rule in // the direction that binds here -- do not dissolve the cost by relabelling the file. // -// WHAT THAT COSTS, stated rather than left for a reader to discover: v2.workflow.required_floor -// retains the DeclinedLiveTree arm, so this module is DISCOVERED and DECLINED by the required -// floor and does not execute there today. It dissolves with that arm's staged deletion, at which -// point these three become executing evidence with no further authorship. Until then the evidence -// below is executed rather than enrolled: run it directly with +// WHAT THAT COST BEFORE THE ROOT CUT, stated rather than left for a reader to reconstruct: +// v2.workflow.required_floor's now-deleted DeclinedLiveTree arm discovered and declined this +// module. These three now execute without changing the honest ReadsLiveTree declaration. Before +// the cut, the evidence below was executed rather than enrolled by running it directly with // `gunbc run --source-root dag --source-root src/v2 --entry --function `, -// which is how both directions of its discriminating pair were taken. +// which is how both directions of its discriminating pair were originally taken. // // THE POPULATION THIS CORRECTION DOES NOT REPAIR, named because the split is real and a reader // will find it: 24 further files under dag/test/claim call compile_dag_rust_emit_check while diff --git a/dag/test/claim/discovery_census_witness_test.dag b/dag/test/claim/discovery_census_witness_test.dag index b01b3c78f91..6dc4790f32b 100644 --- a/dag/test/claim/discovery_census_witness_test.dag +++ b/dag/test/claim/discovery_census_witness_test.dag @@ -28,7 +28,7 @@ import gunbc.discovery_census { } import v2.workflow.required_floor { RequiredFloorDisposition, - Planned, DeclinedLongModule, DeclinedLiveTree, + Planned, DeclinedLongModule, DeclinedFixtureMember, required_floor_site_disposition, } import v2.workflow.floor_terminal_ledger { ClaimDisposition, Passed } @@ -61,16 +61,15 @@ fn live_tree_site(module_path: String, function: String) -> DiscoveredSite { } } -// A MIXED POPULATION COVERING EVERY DISPOSITION ARM. It carried a fifth arm until the plan/walk -// residue cut (2026-08-26) deleted `DeclinedFixtureMember` together with the one fixture family -// that inhabited it; the site that held it is now a second live-tree read, so the population size -// and every assertion denominated in it are unchanged and only the arm it lands in moved. +// A MIXED POPULATION spanning all three disposition arms. Two members read the live tree; one is +// fixture-declined and the ordinary witness is planned, proving live-tree access no longer forms +// a fourth admission arm. fn mixed_sites() -> List { [ hermetic_site(module_path: "test.claim.alpha_witness", function: "w_alpha"), hermetic_site(module_path: "test.claim.alpha_witness", function: "w_beta"), hermetic_site(module_path: "test.claim.long.slow_witness", function: "w_slow"), - live_tree_site(module_path: "test.claim.reads_tree_other", function: "w_member"), + live_tree_site(module_path: "v2.test.fixture.walk_plan_stage.common", function: "w_member"), live_tree_site(module_path: "test.claim.reads_tree_witness", function: "w_reads") ] } @@ -189,14 +188,24 @@ test fn w_empty_module_path_and_empty_function_refuse_apart() -> Bool { // THE DISPOSITION, AND ITS ORDER // --------------------------------------------------------------------------------------------- +// A fixture member reports the exact prefix whose recipe owns its execution. +test fn w_fixture_home_declines_with_its_matched_prefix() -> Bool { + match required_floor_site_disposition( + module_path: "v2.test.fixture.walk_plan_stage.common" + ) { + DeclinedFixtureMember { matched_prefix: p } => p == "v2.test.fixture.walk_plan_stage." + Planned => false + DeclinedLongModule { matched_prefix: _ } => false + } +} + test fn w_long_home_module_declines_with_its_matched_prefix() -> Bool { match required_floor_site_disposition( - module_path: "test.claim.long.slow_witness", - reads_live_tree: SubstrateInputsOnly {} + module_path: "test.claim.long.slow_witness" ) { DeclinedLongModule { matched_prefix: p } => p == "test.claim.long." Planned => false - DeclinedLiveTree => false + DeclinedFixtureMember { matched_prefix: _ } => false } } @@ -205,23 +214,21 @@ test fn w_long_home_module_declines_with_its_matched_prefix() -> Bool { // control beside the decline above: without it the decline could pass under a `contains` test. test fn w_long_home_is_a_prefix_not_a_substring() -> Bool { match required_floor_site_disposition( - module_path: "test.claim.not_test_claim_long.witness", - reads_live_tree: SubstrateInputsOnly {} + module_path: "test.claim.not_test_claim_long.witness" ) { Planned => true DeclinedLongModule { matched_prefix: _ } => false - DeclinedLiveTree => false + DeclinedFixtureMember { matched_prefix: _ } => false } } -test fn w_live_tree_site_declines_when_no_home_matched() -> Bool { +test fn w_site_is_planned_when_no_home_matched() -> Bool { match required_floor_site_disposition( - module_path: "test.claim.reads_tree_witness", - reads_live_tree: ReadsLiveTree {} + module_path: "test.claim.ordinary_witness" ) { - DeclinedLiveTree => true - Planned => false + Planned => true DeclinedLongModule { matched_prefix: _ } => false + DeclinedFixtureMember { matched_prefix: _ } => false } } @@ -235,11 +242,12 @@ test fn w_live_tree_site_declines_when_no_home_matched() -> Bool { test fn w_counts_partition_the_offered_population() -> Bool { let counts = census_counts(rows: census_rows_of(sites: mixed_sites())) (counts.offered == 5) - && (counts.planned == 2) + && (counts.planned == 3) && (counts.declined_long_module == 1) - && (counts.declined_live_tree == 2) + && (counts.declined_fixture_member == 1) && (counts.offered == - counts.planned + counts.declined_long_module + counts.declined_live_tree) + counts.planned + counts.declined_long_module + + counts.declined_fixture_member) } // EVERY DISCOVERED SITE GETS A ROW, DECLINED OR NOT. A census that dropped the declines would @@ -269,7 +277,7 @@ test fn w_declined_sites_are_rows_not_omissions() -> Bool { let rendered = fold(rows, init: [], f: fn(acc, row) { concat([render_label(l: row.label)], acc) }) ((rows |> count) == 5) && list_holds(xs: rendered, wanted: "//test/claim/long/slow_witness:w_slow") - && list_holds(xs: rendered, wanted: "//test/claim/reads_tree_other:w_member") + && list_holds(xs: rendered, wanted: "//v2/test/fixture/walk_plan_stage/common:w_member") && list_holds(xs: rendered, wanted: "//test/claim/reads_tree_witness:w_reads") } @@ -283,13 +291,13 @@ test fn w_declined_sites_are_rows_not_omissions() -> Bool { // identity would make `//:required` name a dependency the standings list can answer twice. test fn w_duplicate_identity_refuses_even_when_declined() -> Bool { match discovery_census(sites: [ - live_tree_site(module_path: "test.claim.dup_witness", function: "w"), - live_tree_site(module_path: "test.claim.dup_witness", function: "w") + hermetic_site(module_path: "test.claim.long.dup_witness", function: "w"), + hermetic_site(module_path: "test.claim.long.dup_witness", function: "w") ]) { CensusAccepted { rows: _ } => false CensusRefused { cause: c } => match c { - DuplicateSiteIdentity { identity: i } => i == "//test/claim/dup_witness:w" + DuplicateSiteIdentity { identity: i } => i == "//test/claim/long/dup_witness:w" SiteModulePathEmpty { function: _ } => false SiteLabelRefused { module_path: _, function: _, cause: _ } => false } @@ -314,7 +322,7 @@ test fn w_two_functions_in_one_module_are_two_identities() -> Bool { // --------------------------------------------------------------------------------------------- // THE AGGREGATE'S DEPENDENCIES ARE THE PLANNED SUBSET AND NOTHING ELSE — asserted as an identity -// join over the rendered labels, not as a count. A count would pass on any two of the five. +// join over the rendered labels, not as a count. A count would pass on any three of the five. test fn w_required_aggregate_dependencies_are_exactly_the_planned_subset() -> Bool { match required_aggregate_from_census(census: discovery_census(sites: mixed_sites())) { RequiredAggregateUnderivable { cause: _ } => false @@ -322,12 +330,12 @@ test fn w_required_aggregate_dependencies_are_exactly_the_planned_subset() -> Bo let rendered = fold(a.dependencies, init: [], f: fn(acc, l) { concat([render_label(l: l)], acc) }) is_required_aggregate(t: a) && (target_identity(t: a) == "//:required") - && ((a.dependencies |> count) == 2) + && ((a.dependencies |> count) == 3) && list_holds(xs: rendered, wanted: "//test/claim/alpha_witness:w_alpha") && list_holds(xs: rendered, wanted: "//test/claim/alpha_witness:w_beta") && !list_holds(xs: rendered, wanted: "//test/claim/long/slow_witness:w_slow") - && !list_holds(xs: rendered, wanted: "//test/claim/reads_tree_other:w_member") - && !list_holds(xs: rendered, wanted: "//test/claim/reads_tree_witness:w_reads") + && !list_holds(xs: rendered, wanted: "//v2/test/fixture/walk_plan_stage/common:w_member") + && list_holds(xs: rendered, wanted: "//test/claim/reads_tree_witness:w_reads") } } } @@ -355,8 +363,8 @@ test fn w_refused_census_yields_no_aggregate_and_keeps_the_cause() -> Bool { // away rather than reported as green here. test fn w_all_declined_derives_an_aggregate_that_blocks() -> Bool { let all_declined = [ - live_tree_site(module_path: "test.claim.reads_tree_witness", function: "w_reads"), - hermetic_site(module_path: "test.claim.long.slow_witness", function: "w_slow") + hermetic_site(module_path: "test.claim.long.slow_witness", function: "w_slow"), + hermetic_site(module_path: "v2.test.fixture.walk_plan_stage.common", function: "w_member") ] match required_aggregate_from_census(census: discovery_census(sites: all_declined)) { RequiredAggregateUnderivable { cause: _ } => false @@ -391,7 +399,7 @@ test fn w_derived_aggregate_is_satisfiable_against_standings() -> Bool { ], acc) }) match required_aggregate_standing(aggregate: a, standings: standings) { - AggregateSatisfied { dependency_count: n } => n == 2 + AggregateSatisfied { dependency_count: n } => n == 3 AggregateNoDependencies => false AggregateRefused { finding_count: _, findings: _ } => false AggregateStandingsUnindexable { cause: _ } => false diff --git a/dag/test/claim/duplicate_definition_binding_probe.dag b/dag/test/claim/duplicate_definition_binding_probe.dag index 9a4229f34be..b15a18b4402 100644 --- a/dag/test/claim/duplicate_definition_binding_probe.dag +++ b/dag/test/claim/duplicate_definition_binding_probe.dag @@ -21,17 +21,14 @@ data live_tree_disposition: LiveTreeDisposition = ReadsLiveTree // binding to two definitions with no refusal is silent wrongness, which is outside the ladder, // not a weak rung on it. // -// THIS ROW DOES NOT EXECUTE IN THE REQUIRED FLOOR TODAY, AND THAT IS DECLARED HERE RATHER THAN -// LEFT TO BE DISCOVERED. `compile_dag_diagnostic_census` resolves the synthetic source against +// THIS ROW DID NOT EXECUTE BEFORE THE ROOT CUT, AND THAT HISTORY IS DECLARED HERE RATHER THAN +// LEFT TO BE RECONSTRUCTED. `compile_dag_diagnostic_census` resolves the synthetic source against // `build_module_path_index_from_witness_roots`, which walks the live tree, so the read is real and -// the declaration below is `ReadsLiveTree`. `v1_compiler.cli_run` `run_required_floor` routes every -// such site to `DeclinedLiveTree` -- discovered, counted, never run -- so this row is not enrolled -// in `v2.workflow.floor_expected_red`: enrolling asserts that a row REACHES ITS SUBJECT AND -// ANSWERS, and a declined row answers nothing. An enrolment here would have been a false assertion -// wearing the shape of coverage, which is the exact failure this row exists to name. -// EXECUTION TRIGGER: the deletion of the `DeclinedLiveTree` arm, which -// `v2.workflow.required_floor` already carries as retained and staged for deletion at the root. -// When that lands this row executes, reds, and belongs on the expected-red roster the same day. +// the declaration below is `ReadsLiveTree`. Before the root cut, `run_required_floor` routed every +// such site to `DeclinedLiveTree` -- discovered, counted, never run -- so enrolment would have +// asserted a verdict that did not exist. The root deletion has now fired that execution trigger: +// this row executes, reds, and is enrolled in `v2.workflow.floor_expected_red` on the same change. +// The honest ReadsLiveTree declaration remains the affected-set selection fact. // An earlier revision of this module WAS enrolled, justified by a sibling census probe that // declares no disposition and was inferred to route and pass. That inference was wrong twice over: // undeclared is `ReadsLiveTree` by the fail-closed default (`cli_run` diff --git a/dag/test/claim/quarantine_probe_disposition_witness_test.dag b/dag/test/claim/quarantine_probe_disposition_witness_test.dag index 47f693f50a9..4d6bcebe2ab 100644 --- a/dag/test/claim/quarantine_probe_disposition_witness_test.dag +++ b/dag/test/claim/quarantine_probe_disposition_witness_test.dag @@ -31,19 +31,15 @@ import v2.std.logic { Bool } import v2.std.text { String } // THE LIVE JOIN plus its discriminating controls. The model is in -// gunbc.quarantine_probe_disposition; this file supplies the four populations from the +// gunbc.quarantine_probe_disposition; this file supplies the three live populations from the // authorities that own them and asserts that every live quarantine probe derives EXACTLY ONE // holding disposition. // // NO `live_tree_disposition` DECLARATION HERE, AND THAT IS DELIBERATE RATHER THAN AN OMISSION. -// This witness reads the live tree twice (the module-declaration index, and each admission -// entry's own declaration), so declaring SubstrateInputsOnly would be false. Declaring -// ReadsLiveTree would be true and would make the required floor DECLINE this witness -- the -// guard would then never execute, and a green main would mean nothing about it, which is the -// exact failure this lane exists to expose. Undeclared is the honest position that the floor -// still executes: the floor's own decline scan (`witness_file_from_source`) fires only on an -// explicit ReadsLiveTree declaration, while affected-set selection treats undeclared as -// live-reading and fail-closed. Both consumers get a true answer from the same silence. +// This witness reads the live tree (the module-declaration index and a declaration control), so +// declaring SubstrateInputsOnly would be false. Undeclared remains the fail-closed affected-set +// selection position; the required floor now executes it and lets the interpreter classify the +// actual effects. data quarantine_probe_disposition_witness_note: String = "Live claim plus controls for the total quarantine-probe disposition join. THE LIVE CLAIM IS DELIBERATELY NOT WHERE THE DISCRIMINATION LIVES: it is a universal over the live admission rows, so it stays meaningful at any population size including zero, and it would pass vacuously on an empty roster. The discrimination is carried by the synthetic controls below, which are authored here and cannot lose their subject when a live quarantine dissolves -- each of the five holder arms is shown to derive HeldByExactlyOne on its own, held-by-nothing is shown to derive the alarm, and held-by-two is shown to refuse. The controls therefore prove the fold DISCRIMINATES rather than merely agreeing with today's tree." fn witness_pool_roots() -> List { @@ -65,48 +61,14 @@ fn module_for_entry(facts: List, entry: String) -> String ) } -// THE LIVE-TREE DECLINE FACT, read from the entry file itself. -// -// THIS IS A RE-DERIVATION OF A FACT THE PRODUCER OWNS, AND THE FORK IS FORCED RATHER THAN -// CHOSEN. The floor computes it in Rust because it must decide whether to load a module BEFORE -// loading it -- the same bootstrap constraint that makes the path-exclusion list unreadable from -// .dag. This witness has no such constraint, so it reads the same declaration through the -// substrate. The two computations could diverge, and A DIVERGENCE IS UNDETECTABLE FROM INSIDE -// THIS FOLD: nothing here observes the floor's own classification. The strongest control -// available is one anchored point, and it is asserted below -// (`the_live_tree_declined_row_is_the_one_the_floor_declines`): the single live row this arm -// classifies must be the row the floor really declines, checked against a named run rather than -// against this fold's own answer. One anchored point is not proof of agreement; it is better -// than none, and it is named as such. -// -// The required floor declines every site in a file whose source carries a `data` line naming -// both LiveTreeDisposition and ReadsLiveTree -- `witness_file_from_source` in cli_run.rs, a -// column-zero text scan in which UNDECLARED MEANS EXECUTES. That is not the same predicate as -// `reads_live_tree_effective` (which also derives from effect reach and treats undeclared as -// live-reading); the floor does not consult that one, and the Rust file records the pair as a -// section 3 defect it deliberately does not fix. This witness reads the declaration the floor -// reads, so it tracks the arm that actually fires; when the floor's copy is deleted (its own -// deletion trigger, staged in v2.workflow.required_floor), this derivation and the arm it feeds -// dissolve together with it. -fn entry_declares_reads_live_tree(entry: String) -> Bool { +// `LiveTreeDisposition` still owns affected-set selection eligibility after the required-floor +// decline is deleted. This scan exercises that surviving declaration question only; it does not +// predict whether the interpreter can execute the witness hermetically. +fn entry_declares_reads_live_tree_for_selection(entry: String) -> Bool { let source = filesystem_read(path: entry).content source.contains("LiveTreeDisposition") && source.contains("ReadsLiveTree") } -fn live_tree_declined_entries(rows: List) -> List { - fold_list( - xs: rows, - empty: Empty {}, - cons: fn(acc, row) { - if entry_declares_reads_live_tree(entry: row.witness.entry) { - Cons { head: row.witness.entry, tail: acc } - } else { - acc - } - } - ) -} - fn subject_for_admission( facts: List, row: ExplicitWitnessAdmission @@ -127,14 +89,14 @@ fn live_quarantine_probe_subjects() -> List { ) } +// Declaring ReadsLiveTree still controls affected-set eligibility, but no longer declines +// execution at the required-floor root. This holder population therefore has no live rows. fn live_quarantine_probe_facts() -> QuarantineProbeHoldingFacts { QuarantineProbeHoldingFacts { expected_red_roster: floor_expected_red_roster(), route_gap_roster: floor_route_gap_roster(), home_prefixes: long_home_prefixes(), - live_tree_declined_entries: live_tree_declined_entries( - rows: quarantine_probe_admissions(rows: explicit_witness_admissions) - ), + live_tree_declined_entries: Empty {}, path_exclusion_substrings: Empty {} } } @@ -155,20 +117,18 @@ test fn every_quarantine_probe_derives_exactly_one_disposition() -> Bool { ) } -// THE LIVE CLAIM IS NOT VACUOUS, PROVEN BY MUTATION RATHER THAN ASSERTED. Each of the four -// supplied populations is dropped in turn and the live claim must go RED, then the unmutated +// THE LIVE CLAIM IS NOT VACUOUS, PROVEN BY MUTATION RATHER THAN ASSERTED. Each of the three +// supplied live populations is dropped in turn and the live claim must go RED, then the unmutated // fold must go green. Without this, a fold that answered "held" for everything -- or a join that // silently matched nothing -- would pass the live claim exactly as it does now. Measured on // 967b5bc1b92: dropping the expected-red roster unholds 5 probes, the route-gap roster 6, the -// home prefixes 7, the live-tree entries 1. The path-exclusion axis is not mutated here because -// it holds nothing live to lose; its derivation is exercised by the fixture control above, which -// is the honest split between an arm with no inhabitants and an arm with no test. +// home prefixes 7. The live-tree and path-exclusion axes are not mutated here because the +// required floor no longer has a live-tree decline and neither arm holds a live row. test fn every_supplied_population_is_load_bearing_on_the_live_claim() -> Bool { let subjects = live_quarantine_probe_subjects() !quarantine_probe_dispositions_all_hold(subjects: subjects, facts: live_facts_without_expected_red()) && !quarantine_probe_dispositions_all_hold(subjects: subjects, facts: live_facts_without_route_gap()) && !quarantine_probe_dispositions_all_hold(subjects: subjects, facts: live_facts_without_home_prefixes()) - && !quarantine_probe_dispositions_all_hold(subjects: subjects, facts: live_facts_without_live_tree()) && quarantine_probe_dispositions_all_hold(subjects: subjects, facts: live_quarantine_probe_facts()) } @@ -209,17 +169,6 @@ fn live_facts_without_home_prefixes() -> QuarantineProbeHoldingFacts { } } -fn live_facts_without_live_tree() -> QuarantineProbeHoldingFacts { - let f = live_quarantine_probe_facts() - QuarantineProbeHoldingFacts { - expected_red_roster: f.expected_red_roster, - route_gap_roster: f.route_gap_roster, - home_prefixes: f.home_prefixes, - live_tree_declined_entries: probe_no_strings(), - path_exclusion_substrings: f.path_exclusion_substrings - } -} - data probe_fixture_module: String = "test.claim.synthetic_quarantine_probe_witness" data probe_fixture_entry: String = "dag/test/claim/synthetic_quarantine_probe_witness_test.dag" data probe_fixture_function: String = "synthetic_probe_holds" @@ -417,17 +366,9 @@ test fn a_roster_row_that_merely_contains_the_identity_does_not_hold_it() -> Boo && disposition_is_held_by(disposition: fixture_disposition(facts: facts_with_expected_red()), expected: FloorExpectedRedHeld {}) } -// THE ANCHORED AGREEMENT POINT WITH THE PRODUCER. legacy_test_behavior_unclassified_frontier_is_zero -// is the one live row this witness classifies NeverRunDeclinedByLiveTreeRead, and the floor -// really does decline it: main run 32553487573 (sha 967b5bc1b92) reports -// `offered=11812 routed=10439 declined_long=543 declined_live=830`, and 10439 + 543 + 830 = -// 11812 exactly, so the three arms partition the offered sites and the declined population is -// real rather than inferred. Run directly, the witness FAILS (claim_batch, cpu=183ms) -- so it -// is a live red control, not a stale row, and the reading that would have deleted it was the -// destructive one. This test asserts the classification half, which is the half this fold owns; -// the run receipt above is the producer half and is prose because no .dag consumer can read a -// workflow log. -test fn the_live_tree_declined_row_is_the_one_the_floor_declines() -> Bool { +// The former live-tree specimen now executes and is held by its observed expected-red verdict. +// Keeping an assertion that it is never routed would restate the deleted floor policy. +test fn the_former_live_tree_declined_row_is_now_expected_red() -> Bool { let facts = live_quarantine_probe_facts() let subject = QuarantineProbeSubject { module: "test.claim.legacy_test_behavior_disposition_acceptance_test", @@ -436,9 +377,7 @@ test fn the_live_tree_declined_row_is_the_one_the_floor_declines() -> Bool { } disposition_is_held_by( disposition: quarantine_probe_disposition(subject: subject, facts: facts), - expected: NeverRunDeclinedByLiveTreeRead { - entry: "dag/test/claim/legacy_test_behavior_disposition_acceptance_test.dag" - } + expected: FloorExpectedRedHeld {} ) } @@ -447,6 +386,6 @@ test fn the_live_tree_declined_row_is_the_one_the_floor_declines() -> Bool { // that does not declare it reads false. Both are live files, so this control also fails if the // read itself stops working. test fn the_live_tree_declaration_read_discriminates() -> Bool { - entry_declares_reads_live_tree(entry: "dag/test/claim/legacy_test_behavior_disposition_acceptance_test.dag") - && !entry_declares_reads_live_tree(entry: "dag/test/claim/method_arg_declared_contract_witness_test.dag") + entry_declares_reads_live_tree_for_selection(entry: "dag/test/claim/legacy_test_behavior_disposition_acceptance_test.dag") + && !entry_declares_reads_live_tree_for_selection(entry: "dag/test/claim/method_arg_declared_contract_witness_test.dag") } diff --git a/dag/test/claim/transport_script_wall_compile_red_test.dag b/dag/test/claim/transport_script_wall_compile_red_test.dag index c3acf98771d..f05cdf87ee1 100644 --- a/dag/test/claim/transport_script_wall_compile_red_test.dag +++ b/dag/test/claim/transport_script_wall_compile_red_test.dag @@ -10,17 +10,17 @@ The module moves out of long. here for a reason independent of cost: its long-ho THE DISPOSITION CORRECTION IS THE SUBSTANTIVE CHANGE. live_tree_disposition was declared SubstrateInputsOnly while this witness calls compile_dag_rust_emit_check, which reaches the identical build_module_path_index_from_witness_roots live-tree walk its sibling (compile_diagnostic_census_witness_test.dag) already declares ReadsLiveTree for. That sibling's census_live_tree_note had flagged this as 'either a latent mis-declaration or a judgment call' pending the falsifier cadence -- since deleted (2026-08-15 floor cut) and never adjudicated. SubstrateInputsOnly was the mis-declaration; ReadsLiveTree is declared here honestly, even though it costs admission rather than buying it. -THE FINDING, terminal, not pending: v2.workflow.required_floor's admission test is long_home(module) -> DeclinedLongModule; else reads_live_tree -> DeclinedLiveTree; else Planned (src/v1/stage0/src/cli_run.rs run_required_floor, disposition_rows construction) -- an OR of two independent decline arms, not one quarantine gate. Moving this module out of test.claim.long. does not admit it: it moves the three identities straight from DeclinedLongModule into DeclinedLiveTree. Measured at identity grain -- RequiredFloorDispositionRow, the per-identity receipt that made this decidable at all -- comparing this PR's floor run against a main baseline run at the same head: claims=9686 unchanged in both, declined_long 539->536 (-3), declined_live 763->766 (+3); the exact three identities moved buckets and never became Planned. THIS WITNESS CANNOT BE ADMITTED TO THE REQUIRED FLOOR WHILE IT READS THE LIVE TREE. That is independent of #8470: the first-touch cost fix and the admission question are two separate facts about this module, and fixing the first does not touch the second. +HISTORICAL FINDING, terminal for the measured tree: v2.workflow.required_floor's admission test was long_home(module) -> DeclinedLongModule; else reads_live_tree -> DeclinedLiveTree; else Planned (src/v1/stage0/src/cli_run.rs run_required_floor, disposition_rows construction) -- an OR of two independent decline arms, not one quarantine gate. Moving this module out of test.claim.long. did not admit it: it moved the three identities straight from DeclinedLongModule into DeclinedLiveTree. Measured at identity grain -- RequiredFloorDispositionRow, the per-identity receipt that made this decidable at all -- comparing that PR's floor run against a main baseline run at the same head: claims=9686 unchanged in both, declined_long 539->536 (-3), declined_live 763->766 (+3); the exact three identities moved buckets and never became Planned. The then-current floor could not admit this witness while its live-tree declaration selected that arm. That was independent of #8470: the first-touch cost fix and the admission question were two separate facts about this module, and fixing the first did not touch the second. -CONSEQUENCE FOR THE COST QUESTION: it cannot be closed by a floor run at all, not now and not after any further first-touch repair, because the witness is never planned into one. A standalone claim run is not a substitute measurement either -- it disables the per-floor-process memo #8470 warms, so it would measure a different, uncached quantity, not this module's floor-fold cost; using it to answer the floor question would be a fourth false reading of the same defect docs/plans/floor-shared-fill-ledger.md exists to stop people repeating. The cost question is therefore an open item with a NAMED BLOCKER -- this witness's own inadmissibility -- not a task the next session should attempt against the floor. +HISTORICAL CONSEQUENCE FOR THE COST QUESTION: on that tree it could not be closed by a floor run because the witness was never planned into one. A standalone claim run was not a substitute measurement either -- it disabled the per-floor-process memo #8470 warmed, so it would have measured a different, uncached quantity, not this module's floor-fold cost; using it to answer the floor question would have been a fourth false reading of the same defect docs/plans/floor-shared-fill-ledger.md exists to stop people repeating. The cost question therefore remained open with a named blocker until the later branch measurement recorded below. SCALE NOTE, unrelated to this witness's own resolution but recorded where it will be seen: at the same measurement, declined_live=766 vastly outnumbers declined_long=536 (763 vs 539 pre-move). This whole lane -- three restore waves, an attribution pass, a policy cut, a night of argument across six sessions -- has been aimed entirely at the smaller of the two declined populations. -CORRECTED 2026-08-20 (WITNESS EXECUTION CLOSURE), and the correction is to the REASON rather than to the fact. THE FINDING paragraph above is still true TODAY -- DeclinedLiveTree still exists and these three identities are still declined -- but its stated ground is false, and a true conclusion resting on a false premise will mislead the next person who acts on it. The premise 'THIS WITNESS CANNOT BE ADMITTED TO THE REQUIRED FLOOR WHILE IT READS THE LIVE TREE' is wrong: hermetic mode carries a checkout-read carve-out (v1_interpreter hermetic_checkout_read_disposition), under which a Filesystem.Read of a path proven under the checkout root is INPUT access -- the commit is the run's deterministic input -- and dispatches to a REAL read. Reading the live tree has not implied un-executability since that carve-out landed, which was after live_tree_disposition was authored. +CORRECTED 2026-08-20 (WITNESS EXECUTION CLOSURE), and the correction was to the reason rather than to that tree's measured disposition. The historical finding above was true on its measured tree, but its stated ground was false, and a true conclusion resting on a false premise would mislead the next person who acted on it. The premise that a witness cannot be admitted while it reads the live tree was wrong: hermetic mode carries a checkout-read carve-out (v1_interpreter hermetic_checkout_read_disposition), under which a Filesystem.Read of a path proven under the checkout root is INPUT access -- the commit is the run's deterministic input -- and dispatches to a REAL read. Reading the live tree has not implied un-executability since that carve-out landed, which was after live_tree_disposition was authored. MEASURED, NOT ARGUED (floor run 32345970386, sha c812b9fb6d0): the decline arm was deleted on a branch and the whole population executed. Of ~783 identities admitted, 626 PASS. 157 route-gap on real host operations, and this module's own rows are NOT among them -- they complete. So the CONSEQUENCE FOR THE COST QUESTION paragraph above is also answerable now rather than blocked: these rows cost 53301ms and 6682ms CPU in that run, exact measurements of a completed claim, against a 5000ms per-witness CPU limit. That is the number this lane spent three restore waves trying and failing to obtain, and it was unobtainable only because the floor never planned the witness. -WHY THE ARM IS STILL HERE. Deleting it also admits 55 blockers -- 6 witnesses that do not RESOLVE and 49 in a cost tail, this module's two among them -- and every one of the 55 is newly-admitted. The mechanism that makes the population visible landed separately, carrying none of them. The deletion is staged behind treating those 55. See docs/plans/witness-execution-closure.md. +WHY THE ARM REMAINED AFTER THAT MEASUREMENT. Deleting it also admitted 55 blockers -- 6 witnesses that did not resolve and 49 in a cost tail, this module's two among them -- and every one of the 55 was newly admitted. The mechanism that made the population visible landed separately, carrying none of them. The deletion was therefore staged behind treating those 55. See docs/plans/witness-execution-closure.md. THE SCALE NOTE'S POINT IS ACCEPTED AND ACTED ON: 778 identities in the larger population against 538 in the smaller one that consumed this lane. That sentence is why the closure work exists. What did NOT change is this module's live_tree_disposition, which stays ReadsLiveTree and stays correct -- it is read by reads_live_tree_effective for AFFECTED-SET SELECTION ELIGIBILITY, a different question from 'can this execute', and the floor conflating the two is the actual defect." diff --git a/src/v1/stage0/src/bin/claim_executor.rs b/src/v1/stage0/src/bin/claim_executor.rs index eaa39713166..d394ca5aaa2 100644 --- a/src/v1/stage0/src/bin/claim_executor.rs +++ b/src/v1/stage0/src/bin/claim_executor.rs @@ -1547,9 +1547,9 @@ fn report_required_floor_outcome(outcome: &v1_compiler::cli_run::RequiredFloorOu ); // THE SUBJECT THE ROSTER WAS PROJECTED FROM, STATED BEFORE THE ROSTER. // `planned` is the population that SURVIVED site projection; printing it - // without `offered` and `declined_long` made the receipt unable to say what it + // without `offered` and the declines made the receipt unable to say what it // dropped, which is how a roster that narrowed read exactly like one that did - // not. The three are printed together so the subtraction is visible rather + // not. The categories are printed together so the subtraction is visible rather // than inferable. // AND THE SENTENCE IS NOW BOUNDED ABOVE, WHICH IT WAS NOT. // "every discovered site is exactly one of these" is a totality claim over SITES, and it was @@ -1559,13 +1559,13 @@ fn report_required_floor_outcome(outcome: &v1_compiler::cli_run::RequiredFloorOu // entry stops the line in `run_required_floor` before this point — so the guarantee is stated // rather than left for a reader to discover it was never claimed. eprintln!( - "required-floor: offered={} routed={} declined_long={} \ - declined_live={} — every discovered site is exactly one of these, and no `*_test.dag` \ + "required-floor: offered={} routed={} declined_long={} declined_fixture={} \ + — every discovered site is exactly one of these, and no `*_test.dag` \ entry offered zero sites (BarrenTestSidecar refuses upstream of this line)", outcome.sites_offered, outcome.claims_planned, outcome.declined_long_module, - outcome.declined_live_tree + outcome.declined_fixture_member ); // WHY route_gap IS NOW SPELLED route_gap_unenrolled, AND WHY route_gap_held JOINS IT HERE. // The old field printed `outcome.route_gap.len()` under the bare name `route_gap` — the diff --git a/src/v1/stage0/src/cli_run.rs b/src/v1/stage0/src/cli_run.rs index 00ee29e135b..f1c23fc306a 100644 --- a/src/v1/stage0/src/cli_run.rs +++ b/src/v1/stage0/src/cli_run.rs @@ -10813,6 +10813,46 @@ pub enum ClaimOutcome { }, } +#[derive(Debug, Clone, Copy, PartialEq, Eq)] +enum FloorRouteGapExpectedGround { + UnpublishedMockCase, + NoMockResponse, + FilesystemRemoval, +} + +#[derive(Debug, Clone, PartialEq, Eq)] +struct FloorRouteGapExpectation { + operation: String, + ground: FloorRouteGapExpectedGround, +} + +fn floor_route_gap_expectation_mismatch( + expectation: Option<&FloorRouteGapExpectation>, + operation: &str, + ground: &v1_interpreter::HermeticEffectGround, +) -> Option { + let expectation = expectation?; + let observed_ground = match ground { + v1_interpreter::HermeticEffectGround::UnpublishedMockCase { .. } => { + FloorRouteGapExpectedGround::UnpublishedMockCase + } + v1_interpreter::HermeticEffectGround::NoMockResponse => { + FloorRouteGapExpectedGround::NoMockResponse + } + v1_interpreter::HermeticEffectGround::FilesystemRemoval => { + FloorRouteGapExpectedGround::FilesystemRemoval + } + }; + if expectation.operation == operation && expectation.ground == observed_ground { + None + } else { + Some(format!( + "typed route-gap enrollment expected operation={} ground={:?}, observed operation={} ground={:?}", + expectation.operation, expectation.ground, operation, observed_ground + )) + } +} + /// Which clock a completed claim's cost is judged on. Operator ruling 2026-08-19 (BUDGET /// POLICY CUT): chosen by the witness's PURPOSE — pure modeled computation is judged on CPU, /// external/blocking interaction is judged on wall — and NEVER by which clock happened to @@ -45029,7 +45069,7 @@ pub struct RequiredFloorClaim { /// /// Modeled authority: `v2.workflow.required_floor` `RequiredFloorDisposition` /// (`src/v2/workflow/required_floor.dag`). This Rust type is the realization of that `.dag` -/// declaration, not its origin — the three arms and their meaning are declared there first; this +/// declaration, not its origin — the arms and their meaning are declared there first; this /// enum's shape must track it rather than the reverse. #[derive(Debug, Clone, PartialEq, Eq)] pub enum RequiredFloorDisposition { @@ -45042,18 +45082,18 @@ pub enum RequiredFloorDisposition { /// matches a `long_home_prefixes()` entry. Carries the exact prefix that matched, which the /// former bare `long_declined` counter discarded. DeclinedLongModule { matched_prefix: String }, - /// Declined because the module declares `LiveTreeDisposition = ReadsLiveTree`. + /// Declined because the module's AUTHORED name matches a `fixture_home_prefixes()` entry: + /// a `test fn` that is a plan-driven FIXTURE MEMBER rather than a witness. /// - /// STAGED FOR DELETION, and the reason is measured rather than intended — see - /// `docs/plans/witness-execution-closure.md`. The premise this arm rests on (reaching the - /// live tree implies "cannot run in the hermetic frame") is FALSE: hermetic mode's - /// checkout-read carve-out reads committed sources for real. Floor run 32345970386 deleted - /// this arm and executed the population: of ~783 identities, **626 pass** and only 157 - /// genuinely lack a hermetic arm. The deletion is not in this change only because it also - /// surfaces 55 blockers — 6 witnesses that do not resolve and 49 in a cost tail — that need - /// their own owners, and every one of those 55 is newly-admitted, so this change is exactly - /// the part that carries none of them. - DeclinedLiveTree, + /// Not a cost decline and not a capability decline. These sites are the SPECIMENS that + /// `claim_executor --plan-entry .../walk_plan_stage/plan.dag --plan-function ` + /// drives; the recipe is the witness and it already executes them. Two of them are red by + /// construction (a body of literal `false`, and a self-call whose depth refusal IS the + /// observed subject) and can never green, and one of the rest writes the very marker path + /// another recipe asserts must stay absent — so the fold running them is not merely useless + /// but corrupting. See `v2.workflow.required_floor` `fixture_home_prefixes` for the full + /// argument and the dissolution condition. + DeclinedFixtureMember { matched_prefix: String }, } /// ONE EXECUTED CLAIM'S MEASURED OCCURRENCE, minted the instant `run_claim_measured` @@ -45209,14 +45249,10 @@ pub struct RequiredFloorOutcome { /// A cost quarantine on a different axis from execution, and it is REPORTED rather than /// silently subtracted: these identities have no executing consumer anywhere in the tree. pub declined_long_module: usize, - /// Discovered sites declined because the module declares `ReadsLiveTree`. - /// - /// REPORTED IN THE HEADLINE, which is the change this carries: the population was - /// previously visible only as an integer in a `[floor-phase]` line, and the run's own - /// honesty check (`planned == executed == receipted`) was computed entirely downstream of - /// it. A receipt that cannot state what it dropped cannot be read as a statement about - /// coverage. Measured at 778 on main; staged for deletion, see `RequiredFloorDisposition`. - pub declined_live_tree: usize, + /// Discovered sites declined because the module's AUTHORED name matches a fixture-home + /// prefix. Unlike the two neighbours, these identities DO have an executing consumer — + /// the plan recipes that drive them — so this count is not a coverage gap. + pub declined_fixture_member: usize, pub claims_planned: usize, pub claims_executed: usize, pub receipt_identities: usize, @@ -46525,7 +46561,8 @@ pub fn run_required_floor( // // WHAT THIS REPLACED, and why it was not an optimisation. The required outcome of this whole // region is exactly: exclude a witness whose AUTHORED module sits in the long home, exclude - // one that reads the live tree, claim everything else Hermetic. That decision used to be + // a walk-plan fixture member already driven by its recipe, and plan everything else. That + // decision used to be // made TWICE — once by `required_floor_manifest` over 10,498 records marshalled into the // interpreter, and again here in Rust, applying the same prefix test to explain the // difference between sites offered and claims returned. Between the two sat an interpreted @@ -46570,9 +46607,17 @@ pub fn run_required_floor( &hermetic, "v2.workflow.required_floor.long_home_prefixes", )?; + // ONE DECODE, TWO ROSTERS. The fixture-home prefixes are read through the same helper as + // the long-home prefixes because they are the same kind of fact — an authored module-name + // prefix the floor declines on — and a second hand-rolled decode beside it would be a + // second authority for how such a roster is read. + let fixture_home_prefixes = floor_decode_module_prefix_roster( + &hermetic, + "v2.workflow.required_floor.fixture_home_prefixes", + )?; // THE LINE STOPS BEFORE THE PARTITION IS COMPUTED, because a barren entry is invisible to // the partition by construction — it contributes no SITE, so `offered` cannot report it and - // `offered == routed + declined_long + declined_live` stays exact while saying nothing about + // `offered == routed + declined_long + declined_fixture` stays exact while saying nothing about // it. A file that claims the `*_test.dag` place and enrolls nothing is a witness nobody asked // and everybody reads as covered. let barren_test_sidecars = @@ -46588,7 +46633,7 @@ pub fn run_required_floor( let mut claims: Vec = Vec::new(); let mut planned_identities: HashSet = HashSet::new(); let mut long_declined = 0usize; - let mut live_declined = 0usize; + let mut fixture_declined = 0usize; let mut sites_offered = 0usize; let mut disposition_rows: Vec = Vec::new(); let mut storage_agreement_rows: Vec = Vec::new(); @@ -46599,6 +46644,9 @@ pub fn run_required_floor( let long_home = matched_prefix.is_some(); // Diagnostic only -- computed once per file and never consulted by the admission // branching below. See `LongHomeStorageAgreement`'s doc comment. + let fixture_prefix = fixture_home_prefixes + .iter() + .find(|prefix| file.module_path.starts_with(prefix.as_str())); let path_is_long = is_long_home_path(&file.path); let storage_agreement = long_home_storage_agreement(path_is_long, long_home); for function in &file.functions { @@ -46620,11 +46668,13 @@ pub fn run_required_floor( }); continue; } - if file.reads_live_tree { - live_declined += 1; + if let Some(prefix) = fixture_prefix { + fixture_declined += 1; disposition_rows.push(RequiredFloorDispositionRow { identity, - disposition: RequiredFloorDisposition::DeclinedLiveTree, + disposition: RequiredFloorDisposition::DeclinedFixtureMember { + matched_prefix: prefix.clone(), + }, }); continue; } @@ -46675,11 +46725,10 @@ pub fn run_required_floor( // it is the construction's own statement of what it guarantees, and it fails loudly the // first time an edit adds a third arm that quietly swallows rows, which is precisely how // the live-tree decline arrived and stayed invisible. - if sites_offered != claims.len() + long_declined + live_declined { + if sites_offered != claims.len() + long_declined + fixture_declined { return Err(format!( "REQUIRED-FLOOR REFUSAL cause=SitePartitionInexact offered={sites_offered} \ - routed={} declined_long={long_declined} \ - declined_live={live_declined} — every \ + routed={} declined_long={long_declined} declined_fixture={fixture_declined} — every \ discovered site must be either routed to a claim or declined with a stated \ disposition; a gap here is a roster that narrowed without saying so", claims.len() @@ -46687,13 +46736,13 @@ pub fn run_required_floor( } eprintln!( "[floor-phase] phase=site-projection state=completed wall_ms={} sites={} files={} \ - claims={} declined_long={} declined_live={}", + claims={} declined_long={} declined_fixture={}", projection_started.elapsed().as_millis(), sites_offered, files.len(), claims.len(), long_declined, - live_declined + fixture_declined ); // THE EXPECTED-RED ROSTER, read from its .dag authority in the policy module's frame — it @@ -46819,6 +46868,92 @@ pub fn run_required_floor( route_gap_roster.len() ); + // New enrollments carry the operation and the closed remedy-ground observed at the + // interpreter boundary. Their identities are projected into `floor_route_gap_roster` by + // the .dag authority; this decode reads the detail rather than authoring a second identity + // list in Rust. A changed operation or ground blocks below instead of being silently held + // by an identity-only row whose original fact no longer applies. + let route_gap_expectations: HashMap = { + let value = v1_interpreter::run_in_context( + &hermetic, + "v2.workflow.floor_route_gap.floor_route_gap_expectations", + false, + ) + .map_err(|e| format!("floor_route_gap_expectations: {e}"))?; + let items = floor_decode_list(&hermetic, Some(&value)) + .map_err(|e| format!("floor_route_gap_expectations: {e}"))?; + let mut out = HashMap::new(); + for item in items { + let v1_interpreter::Value::Record { type_name, fields } = item else { + return Err(format!( + "floor_route_gap_expectations: expected FloorRouteGapExpectation, got {}", + floor_value_shape(Some(&item)) + )); + }; + if !hermetic.sym_eq(*type_name, "FloorRouteGapExpectation") { + return Err(format!( + "floor_route_gap_expectations: expected FloorRouteGapExpectation, got record {}", + hermetic.resolve(*type_name) + )); + } + let identity = match hermetic.field(&fields, "identity") { + Some(v1_interpreter::Value::Str(s)) => s.to_string(), + other => { + return Err(format!( + "floor_route_gap_expectations: identity must be String, got {}", + floor_value_shape(other) + )); + } + }; + let operation = match hermetic.field(&fields, "operation") { + Some(v1_interpreter::Value::Str(s)) => s.to_string(), + other => { + return Err(format!( + "floor_route_gap_expectations: operation must be String, got {}", + floor_value_shape(other) + )); + } + }; + let ground = match hermetic.field(&fields, "ground") { + Some(v1_interpreter::Value::Variant { variant_name, .. }) => { + match hermetic.resolve(*variant_name).as_str() { + "UnpublishedMockCase" => FloorRouteGapExpectedGround::UnpublishedMockCase, + "NoMockResponse" => FloorRouteGapExpectedGround::NoMockResponse, + "FilesystemRemoval" => FloorRouteGapExpectedGround::FilesystemRemoval, + other => { + return Err(format!( + "floor_route_gap_expectations: unknown ground {other}" + )); + } + } + } + other => { + return Err(format!( + "floor_route_gap_expectations: ground must be a typed variant, got {}", + floor_value_shape(other) + )); + } + }; + if !route_gap_roster.contains(identity.as_str()) { + return Err(format!( + "floor_route_gap_expectations: located identity is absent from derived roster: {identity}" + )); + } + if out + .insert( + identity.clone(), + FloorRouteGapExpectation { operation, ground }, + ) + .is_some() + { + return Err(format!( + "floor_route_gap_expectations: duplicate enrolled identity: {identity}" + )); + } + } + out + }; + // THE TWO ROSTERS MAY NOT NAME THE SAME IDENTITY, and this refusal is the reason the split // between them stays a split rather than decaying back into the conflation it was created // to undo. @@ -47057,7 +47192,7 @@ pub fn run_required_floor( modules_excluded: prepared.modules_excluded, sites_offered, declined_long_module: long_declined, - declined_live_tree: live_declined, + declined_fixture_member: fixture_declined, claims_planned, claims_executed: 0, receipt_identities: 0, @@ -47541,12 +47676,21 @@ pub fn run_required_floor( // enrolled — the failure this whole lane exists to close. ExpectedRedArm::HostEffectRefused => { known_red_host_effect_refused += 1; - let detail = match &result { - ClaimOutcome::HostEffectRefused { operation, ground } => format!( - "hermetic route has no arm for {operation}: {}", - hermetic_effect_ground_label(ground) + let (operation, ground, detail) = match &result { + ClaimOutcome::HostEffectRefused { operation, ground } => ( + operation.as_str(), + ground, + format!( + "hermetic route has no arm for {operation}: {}", + hermetic_effect_ground_label(ground) + ), ), - other => format!("{other:?}"), + other => { + return Err(format!( + "required-floor expected-red arm/result disagreement for {}: {other:?}", + claim.qualified + )); + } }; // THE TWO ROSTERS ARE DIFFERENT AXES, AND THIS ROW SITS ON BOTH. Being // enrolled as expected-red says nothing about whether the floor has a route @@ -47555,7 +47699,18 @@ pub fn run_required_floor( // not cover the gap, and the gap does not discharge the enrollment. route_gap_seen.insert(claim.qualified.clone()); if route_gap_roster.contains(claim.qualified.as_str()) { - route_gap_held += 1; + if let Some(mismatch) = floor_route_gap_expectation_mismatch( + route_gap_expectations.get(claim.qualified.as_str()), + operation, + ground, + ) { + outcome.route_gap.push(format!( + "{} is enrolled as a route gap, but its observed typed route changed: {}. Update the enrollment only after deciding which route the witness actually requires.", + claim.qualified, mismatch + )); + } else { + route_gap_held += 1; + } } else { outcome.route_gap.push(format!( "{} is enrolled as expected-red but ROUTE-GAPPED, not failed: {}. \ @@ -47685,7 +47840,18 @@ pub fn run_required_floor( ClaimOutcome::HostEffectRefused { operation, ground } => { route_gap_seen.insert(claim.qualified.clone()); if route_gap_roster.contains(claim.qualified.as_str()) { - route_gap_held += 1; + if let Some(mismatch) = floor_route_gap_expectation_mismatch( + route_gap_expectations.get(claim.qualified.as_str()), + &operation, + &ground, + ) { + outcome.route_gap.push(format!( + "{} is enrolled as a route gap, but its observed typed route changed: {}. Update the enrollment only after deciding which route the witness actually requires.", + claim.qualified, mismatch + )); + } else { + route_gap_held += 1; + } } else { outcome.route_gap.push(format!( "{} never reached its subject: the hermetic route has no arm for {} \ @@ -48377,14 +48543,15 @@ fn required_floor_disposition_label(disposition: &RequiredFloorDisposition) -> & match disposition { RequiredFloorDisposition::Planned => "planned", RequiredFloorDisposition::DeclinedLongModule { .. } => "declined_long_module", - RequiredFloorDisposition::DeclinedLiveTree => "declined_live_tree", + RequiredFloorDisposition::DeclinedFixtureMember { .. } => "declined_fixture_member", } } fn required_floor_disposition_matched_prefix(disposition: &RequiredFloorDisposition) -> &str { match disposition { - RequiredFloorDisposition::DeclinedLongModule { matched_prefix } => matched_prefix, - RequiredFloorDisposition::Planned | RequiredFloorDisposition::DeclinedLiveTree => "", + RequiredFloorDisposition::DeclinedLongModule { matched_prefix } + | RequiredFloorDisposition::DeclinedFixtureMember { matched_prefix } => matched_prefix, + RequiredFloorDisposition::Planned => "", } } @@ -48460,21 +48627,21 @@ fn write_required_floor_disposition_tsv( .map_err(|e| format!("write_required_floor_disposition_tsv: create {path}: {e}"))?; let mut planned = 0usize; let mut declined_long = 0usize; - let mut declined_live = 0usize; + let mut declined_fixture = 0usize; for row in rows { match &row.disposition { RequiredFloorDisposition::Planned => planned += 1, RequiredFloorDisposition::DeclinedLongModule { .. } => declined_long += 1, - RequiredFloorDisposition::DeclinedLiveTree => declined_live += 1, + RequiredFloorDisposition::DeclinedFixtureMember { .. } => declined_fixture += 1, } } writeln!( file, - "# summary\ttotal={}\tplanned={}\tdeclined_long_module={}\tdeclined_live_tree={}", + "# summary\ttotal={}\tplanned={}\tdeclined_long_module={}\tdeclined_fixture_member={}", rows.len(), planned, declined_long, - declined_live + declined_fixture ) .map_err(|e| format!("write_required_floor_disposition_tsv: write {path}: {e}"))?; writeln!(file, "identity\tdisposition\tmatched_prefix") @@ -48678,8 +48845,10 @@ mod required_floor_disposition_and_storage_agreement_law { }, }, RequiredFloorDispositionRow { - identity: "m.three.c".to_string(), - disposition: RequiredFloorDisposition::DeclinedLiveTree, + identity: "v2.test.fixture.walk_plan_stage.x.d".to_string(), + disposition: RequiredFloorDisposition::DeclinedFixtureMember { + matched_prefix: "v2.test.fixture.walk_plan_stage.".to_string(), + }, }, ]; @@ -48693,14 +48862,19 @@ mod required_floor_disposition_and_storage_agreement_law { assert!(lines[0].contains("total=3")); assert!(lines[0].contains("planned=1")); assert!(lines[0].contains("declined_long_module=1")); - assert!(lines[0].contains("declined_live_tree=1")); + assert!(lines[0].contains("declined_fixture_member=1")); assert_eq!(lines[1], "identity\tdisposition\tmatched_prefix"); assert_eq!(lines[2], "m.one.a\tplanned\t"); assert_eq!( lines[3], "test.claim.long.two.b\tdeclined_long_module\ttest.claim.long." ); - assert_eq!(lines[4], "m.three.c\tdeclined_live_tree\t"); + // THE FIXTURE ARM CARRIES ITS MATCHED PREFIX, exactly as the long arm does. A decline + // that cannot say WHICH prefix admitted it is a count, not a receipt. + assert_eq!( + lines[4], + "v2.test.fixture.walk_plan_stage.x.d\tdeclined_fixture_member\tv2.test.fixture.walk_plan_stage." + ); } #[test] diff --git a/src/v2/lens/complexity_accumulator_copy/roster_gate.dag b/src/v2/lens/complexity_accumulator_copy/roster_gate.dag index 02f302a1973..92afdd71676 100644 --- a/src/v2/lens/complexity_accumulator_copy/roster_gate.dag +++ b/src/v2/lens/complexity_accumulator_copy/roster_gate.dag @@ -4,6 +4,7 @@ import extdeps.filesystem.filesystem_io import v2.compiler.normalize { normalize } import v2.compiler.parse { grammar_validate_for_parse, parse_production } import v2.compiler.tokenize { tokenize } +import v2.lens.complexity_accumulator_copy.analyze { accumulator_copy_findings } import v2.lens.common.source_analysis_standing { LanguageGrammarRejected, LanguageGrammarUnavailable, @@ -13,7 +14,7 @@ import v2.lens.common.source_analysis_standing { SourceTokenizationRejected } -data offline_roster_gate_claim_batch_recipe: String = "Operator-ruled OFFLINE (NOT CI discovery-enrolled; witness_exclusion_substrings row claim/complexity/accumulator_copy_roster_gate in gunbc.ci_layer_roots — owned by #6452, not duplicated on #6440). Serial wet claim_batch only — do not codify GUNBC_EVAL_MEMO=0 in CI; diagnostic local runs may set it. Std tranche (PR #6440): claim_batch --source-root dag --source-root src/v2 --entry src/v2/test/claim/complexity/accumulator_copy_roster_gate_std_test.dag --function roster_std_change_dag_zero_suspects_within_ratchet --claim-run --wet && claim_batch --source-root dag --source-root src/v2 --entry src/v2/test/claim/complexity/accumulator_copy_roster_gate_std_test.dag --function roster_std_render_repeat_string_bootstrap_within_ratchet --claim-run --wet. Prior roster carriers: accumulator_copy_roster_gate_test.dag, accumulator_copy_roster_gate_swift_test.dag, accumulator_copy_roster_gate_lean_bash_test.dag (same --claim-run --wet shape, per-test-fn entry/function)." +data offline_roster_gate_claim_batch_recipe: String = "Operator-ruled OFFLINE (NOT CI discovery-enrolled; witness_exclusion_substrings row claim/complexity/accumulator_copy_roster_gate in gunbc.ci_layer_roots — owned by #6452, not duplicated on #6440). Serial wet claim_batch only — do not codify GUNBC_EVAL_MEMO=0 in CI; diagnostic local runs may set it. Std tranche (PR #6440): claim_batch --source-root dag --source-root src/v2 --entry src/v2/test/claim/complexity/accumulator_copy_roster_gate_std_test.dag --function roster_std_change_dag_zero_suspects_within_ratchet --claim-run --wet. Prior roster carriers: accumulator_copy_roster_gate_test.dag, accumulator_copy_roster_gate_swift_test.dag, accumulator_copy_roster_gate_lean_bash_test.dag (same --claim-run --wet shape, per-test-fn entry/function)." type FindingStanding = NoSuspect diff --git a/src/v2/std/node.dag b/src/v2/std/node.dag index 9ea7fd8f3b1..6323c738eac 100644 --- a/src/v2/std/node.dag +++ b/src/v2/std/node.dag @@ -1644,4 +1644,3 @@ type Edit { type Diff { edits: List } - diff --git a/src/v2/test/claim/complexity/accumulator_copy_roster_gate_std_test.dag b/src/v2/test/claim/complexity/accumulator_copy_roster_gate_std_test.dag index d15bc943c96..1acd487536c 100644 --- a/src/v2/test/claim/complexity/accumulator_copy_roster_gate_std_test.dag +++ b/src/v2/test/claim/complexity/accumulator_copy_roster_gate_std_test.dag @@ -14,7 +14,3 @@ data std_tranche_string_carrier_debt_count: Int = 7 test fn roster_std_change_dag_zero_suspects_within_ratchet() -> Bool { file_gate(path: "dag/std/change.dag", refusal_ceiling: 13) } - -test fn roster_std_render_repeat_string_bootstrap_within_ratchet() -> Bool { - file_gate(path: "dag/std/render_repeat_string_bootstrap.dag", refusal_ceiling: 0) -} diff --git a/src/v2/test/claim/complexity/accumulator_copy_roster_gate_test.dag b/src/v2/test/claim/complexity/accumulator_copy_roster_gate_test.dag index 1df66c7d01d..b8af976a3d9 100644 --- a/src/v2/test/claim/complexity/accumulator_copy_roster_gate_test.dag +++ b/src/v2/test/claim/complexity/accumulator_copy_roster_gate_test.dag @@ -44,7 +44,6 @@ test fn roster_lens_cost_model_zero_suspects_within_ratchet() -> Bool { test fn roster_std_algebra_zero_suspects_within_ratchet() -> Bool { file_gate(path: "src/v2/std/algebra.dag", refusal_ceiling: 3) } - data planted_copy_snippet: String = "module planted\n\nfn f(xs: List) -> Int {\n fold(xs, init: 0, f: fn(acc, x) { list_append(left: acc, right: x) })\n}\n" // ASSERTED AS *SUSPECT OBSERVED*, NOT AS "NOT CLEAN". Those differ on exactly the state this change diff --git a/src/v2/test/claim/enforcement/cost_coverage_witness_test.dag b/src/v2/test/claim/enforcement/cost_coverage_witness_test.dag index 9598525c2a7..9b2c8a9377a 100644 --- a/src/v2/test/claim/enforcement/cost_coverage_witness_test.dag +++ b/src/v2/test/claim/enforcement/cost_coverage_witness_test.dag @@ -77,11 +77,6 @@ test fn cost_coverage_v2_tree_receipt_by_execution() -> Bool { && cost_coverage_receipt_totality_holds(receipt: receipt) } -test fn cost_coverage_unknown_fraction_is_derived() -> Bool { - let receipt = cc_witness_smoke_receipt_live() - cost_coverage_unknown_fraction_bps(receipt: receipt) == ((receipt.fn_unknown * 10000) / receipt.fn_attempted) -} - test fn cost_coverage_corpus_roster_nonempty() -> Bool { length(xs: cost_coverage_corpus_roster_live()) > 100 } diff --git a/src/v2/workflow/floor_expected_red.dag b/src/v2/workflow/floor_expected_red.dag index b455ea6707b..f6aeadd36cc 100644 --- a/src/v2/workflow/floor_expected_red.dag +++ b/src/v2/workflow/floor_expected_red.dag @@ -611,8 +611,13 @@ fn floor_expected_red_chunk_18() -> List { Empty {} } +// Authored by silent-bear-842 in #9093. The duplicate-definition row asserts the missing +// ingestion wall rather than defending today's silent second-definition binding. It +// dissolves from this roster when same-name declarations in one module refuse at ingestion, +// then remains as an ordinary permanent regression control; its green single-definition +// sibling is deliberately not enrolled. fn floor_expected_red_chunk_19() -> List { - Cons { head: "test.claim.direct_call_argument_type_witness_test.direct_call_arg_type_v2_module_red_refuses_blocking_type_mismatch", tail: Empty {} } + Cons { head: "test.claim.direct_call_argument_type_witness_test.direct_call_arg_type_v2_module_red_refuses_blocking_type_mismatch", tail: Cons { head: "test.claim.duplicate_definition_binding_probe.duplicate_definition_in_one_module_is_refused", tail: Empty {} } } } // FIVE IDENTITIES ENROLLED 2026-08-22, and they arrive by a route this roster has not carried @@ -808,17 +813,9 @@ fn floor_expected_red_chunks() -> List> { // closure in v2.test.lens_mock_totality. Keep the historical chunk rows for provenance, // but exclude the now-green family from the live expected-red roster. // -// THE THREE compile_accepted_unevaluable_program_control ROWS ARE EXCLUDED FOR THE OPPOSITE -// REASON. They remain the authored-red identities in chunk 21; only their LIVENESS is false. The file -// declares ReadsLiveTree, the DeclinedLiveTree arm declines it (declined_live=899 on that run), -// and the arm's deletion is still unmerged (gunbc#8977, gunbc#8982 both OPEN at the time of -// writing). A declined identity is never executed, while live expected-red enrolment requires an -// observed failure, so the filter keeps the identity and temporary execution standing distinct. -// -// RESTORATION TRIGGER, and it is a COUPLING someone must honour rather than a note: when either -// #8977 or #8982 lands and these identities become executable, DELETE these three exclusions in -// the same change. They are reds, so once they execute while excluded they count as ordinary -// failures and red the build -- the exclusion must not outlive the decline that motivated it. +// The three compile_accepted_unevaluable_program_control rows in chunk 21 are live again: run +// 32721781133 executed all three and observed the enrolled compile-acceptance holes. The former +// exclusions dissolved with DeclinedLiveTree in the same change, as their coupling required. fn floor_expected_red_is_live(name: String) -> Bool { !(name == "v2.test.lens_mock_totality.cron_mock_totality.cron_mock_consumer_is_total_holds" || name == "v2.test.lens_mock_totality.cron_mock_totality.cron_mock_omitted_member_is_red_holds" @@ -840,10 +837,7 @@ fn floor_expected_red_is_live(name: String) -> Bool { || name == "v2.test.lens_mock_totality.sec_edgar_mock_totality.sec_edgar_mock_consumer_is_total_holds" || name == "v2.test.lens_mock_totality.sec_edgar_mock_totality.sec_edgar_mock_omitted_member_is_red_holds" || name == "v2.test.lens_mock_totality.shell_mock_totality.shell_mock_consumer_is_total_holds" - || name == "v2.test.lens_mock_totality.shell_mock_totality.shell_mock_omitted_member_is_red_holds" - || name == "test.claim.compile_accepted_unevaluable_program_control.primitive_call_with_extra_argument_must_refuse_at_compile" - || name == "test.claim.compile_accepted_unevaluable_program_control.primitive_call_with_missing_argument_must_refuse_at_compile" - || name == "test.claim.compile_accepted_unevaluable_program_control.primitive_call_with_wrong_argument_type_must_refuse_at_compile") + || name == "v2.test.lens_mock_totality.shell_mock_totality.shell_mock_omitted_member_is_red_holds") } fn floor_expected_red_roster() -> List { diff --git a/src/v2/workflow/floor_non_verdict.dag b/src/v2/workflow/floor_non_verdict.dag index 9ee62091e07..37816dbe622 100644 --- a/src/v2/workflow/floor_non_verdict.dag +++ b/src/v2/workflow/floor_non_verdict.dag @@ -123,7 +123,7 @@ import v2.std.text { String } // dissolving the machinery, and conflating them would be the climb that deletes its own // evidence (DESIGN 4b(4)). // -// THE PRIOR POPULATION NOTE READ 15 IDENTITIES AND THE ROSTER HELD 11 WHEN THIS EDIT FOUND IT. +// THE PRIOR POPULATION NOTE READ 15 IDENTITIES AND MAIN'S ROSTER HELD 11 WHEN this repair found it. // That drift is recorded rather than quietly corrected, because a transcribed count beside a // list is exactly the second representation that rots without anyone touching either end; the // count above is derived from the rows this edit removed, and it is zero because the rows are @@ -135,6 +135,10 @@ import v2.std.text { String } // `floor_expected_red`, so they could never enter either known-red non-verdict arm. Retiring the // exact non-verdict-minus-expected-red set keeps the 15 identities that can classify live debt; // enrolling the other 127 as expected-red instead would fabricate semantic verdicts. +// The composed #9106 branch briefly carried a twelfth identity, +// gunbc.test.claim.realization_attempt_keystone_test.witness_planted_minimal_module_emits. It was +// the same ClosureDependentResolution render-shadow specimen and repaid under #9259 before merge; +// its witness remains executing while its non-verdict and expected-red rows retire here. fn floor_non_verdict_roster() -> List { Empty {} } diff --git a/src/v2/workflow/floor_route_gap.dag b/src/v2/workflow/floor_route_gap.dag index 1399293fcc5..f6e1062ecb7 100644 --- a/src/v2/workflow/floor_route_gap.dag +++ b/src/v2/workflow/floor_route_gap.dag @@ -4,10 +4,26 @@ import v2.std.algebra { Cons, Empty, list_flat_map } import v2.std.collection { List } import v2.std.text { String } +// THE EXPECTATION IS TYPED AT THE TWO FACTS THE INTERPRETER OBSERVES. An identity-only row +// says merely that some route gap once existed; it cannot object when the witness reaches a +// different operation or when the ground changes to one with a different remedy. New rows are +// authored here and projected into `floor_route_gap_roster`, so identity enrollment remains one +// derived fact rather than a second list beside the detail. +type FloorRouteGapGround = + UnpublishedMockCase + | NoMockResponse + | FilesystemRemoval + +type FloorRouteGapExpectation = { + identity: String, + operation: String, + ground: FloorRouteGapGround +} + // THE ROUTE-GAP ROSTER: identities the required floor EXECUTES, that reach a host effect the // hermetic route has no arm for, enrolled by exact qualified name. // -// WHY IT EXISTS. A file declaring `data live_tree_disposition: LiveTreeDisposition = +// HISTORICAL MOTIVE FOR THIS ROSTER. A file declaring `data live_tree_disposition: LiveTreeDisposition = // ReadsLiveTree` had every one of its identities declined before execution // (`RequiredFloorDisposition.DeclinedLiveTree`) -- 778 of them across 112 files when that was // measured -- and since `claim_executor --required-floor` is the only witness-executing @@ -18,8 +34,8 @@ import v2.std.text { String } // // WHAT THIS ROSTER DOES NOT ESTABLISH, stated because an earlier revision of this header // asserted exactly the opposite: it does NOT establish that every discovered identity is -// planned, and it does NOT establish whether `RequiredFloorDisposition.DeclinedLiveTree` -// exists. That revision claimed the arm was deleted and that "every discovered identity is now +// planned, and it never establishes which pre-execution disposition constructors currently +// exist. That revision claimed the live-tree decline arm was deleted and every discovered identity was // routed and executed". Both halves were false when written, falsified by any floor run whose // receipt reports a nonzero pre-execution decline. It was rung inflation on the very axis the // sibling authority corrects ITSELF for (`required_floor`, review 54035) -- one carrier @@ -32,8 +48,8 @@ import v2.std.text { String } // completeness, because every identity it can see has already been planned. So the planner's // population is read from `v2.workflow.required_floor` and its per-identity receipt, never // copied here -- a copy is what drifted last time, and it would drift again in the same -// direction. This paragraph stays true both before and after `DeclinedLiveTree` is deleted, -// which is the property the sentence it replaces did not have. +// direction. This paragraph remains valid across planner-constructor changes, which is the +// property the sentence it replaces did not have. // // SO THIS ROSTER IS NOT A SKIP LIST, for exactly the reason `floor_expected_red` is not one: // every identity here EXECUTES and its outcome is still asserted. What enrollment changes is @@ -414,6 +430,316 @@ fn floor_route_gap_chunk_03() -> List { } } +fn floor_route_gap_expectation_chunk_00() -> List { + Cons { + head: FloorRouteGapExpectation { identity: "test.claim.artifact_store_fs_witness.artifact_fs_roundtrip_holds", operation: "Write", ground: NoMockResponse {} }, + tail: Cons { + head: FloorRouteGapExpectation { identity: "test.claim.artifact_store_fs_witness.artifact_fs_delete_then_misses_holds", operation: "Write", ground: NoMockResponse {} }, + tail: Cons { + head: FloorRouteGapExpectation { identity: "test.claim.artifact_store_fs_witness.artifact_fs_mutated_input_misses_holds", operation: "Write", ground: NoMockResponse {} }, + tail: Cons { + head: FloorRouteGapExpectation { identity: "test.claim.artifact_store_fs_witness.artifact_fs_eviction_removes_only_the_evicted_key", operation: "Write", ground: NoMockResponse {} }, + tail: Cons { + head: FloorRouteGapExpectation { identity: "test.claim.codex_app_server_press_wet_witness_test.press_account_trip_yields_standing_or_typed_refusal_never_turn_started_holds", operation: "Dir", ground: NoMockResponse {} }, + tail: Cons { + head: FloorRouteGapExpectation { identity: "test.claim.codex_package_delivery_wet_witness_test.acquire_required_codex_tarball_sha512_matches_lock", operation: "Dir", ground: NoMockResponse {} }, + tail: Cons { + head: FloorRouteGapExpectation { identity: "test.claim.codex_package_delivery_wet_witness_test.acquire_exact_target_pair_admits_wrapper_and_platform", operation: "KernelName", ground: NoMockResponse {} }, + tail: Cons { + head: FloorRouteGapExpectation { identity: "test.claim.codex_package_delivery_wet_witness_test.materialize_codex_runtime_bundle_produces_native_executable_holds", operation: "Dir", ground: NoMockResponse {} }, + tail: Cons { + head: FloorRouteGapExpectation { identity: "test.claim.codex_package_delivery_wet_witness_test.materialize_identical_input_twice_reuses_same_release_identity_holds", operation: "Dir", ground: NoMockResponse {} }, + tail: Cons { + head: FloorRouteGapExpectation { identity: "test.claim.codex_supervised_turn_wet_witness_test.wet_select_codex_exact_target_closure_only", operation: "KernelName", ground: NoMockResponse {} }, + tail: Cons { + head: FloorRouteGapExpectation { identity: "test.claim.codex_supervised_turn_wet_witness_test.wet_acquire_wrapper_artifact_only", operation: "Check", ground: NoMockResponse {} }, + tail: Cons { + head: FloorRouteGapExpectation { identity: "test.claim.codex_supervised_turn_wet_witness_test.wet_acquire_platform_artifact_only", operation: "Check", ground: NoMockResponse {} }, + tail: Cons { + head: FloorRouteGapExpectation { identity: "test.claim.codex_supervised_turn_wet_witness_test.wet_codex_runtime_prepare_closure_only", operation: "Check", ground: NoMockResponse {} }, + tail: Cons { + head: FloorRouteGapExpectation { identity: "test.claim.codex_supervised_turn_wet_witness_test.wet_materialize_through_prepare_only", operation: "Check", ground: NoMockResponse {} }, + tail: Cons { + head: FloorRouteGapExpectation { identity: "test.claim.codex_supervised_turn_wet_witness_test.wet_acquire_selected_pair_only", operation: "Check", ground: NoMockResponse {} }, + tail: Cons { + head: FloorRouteGapExpectation { identity: "test.claim.codex_supervised_turn_wet_witness_test.wet_materialize_npm_ci_offline_only", operation: "Check", ground: NoMockResponse {} }, + tail: Cons { + head: FloorRouteGapExpectation { identity: "test.claim.codex_supervised_turn_wet_witness_test.wet_materialize_finish_after_install_only", operation: "Check", ground: NoMockResponse {} }, + tail: Cons { + head: FloorRouteGapExpectation { identity: "test.claim.codex_supervised_turn_wet_witness_test.wet_finish_observe_set_identity_only", operation: "Check", ground: NoMockResponse {} }, + tail: Cons { + head: FloorRouteGapExpectation { identity: "test.claim.codex_supervised_turn_wet_witness_test.wet_finish_observe_manifest_digest_only", operation: "Check", ground: NoMockResponse {} }, + tail: Cons { + head: FloorRouteGapExpectation { identity: "test.claim.codex_supervised_turn_wet_witness_test.wet_finish_observe_lock_digest_only", operation: "Check", ground: NoMockResponse {} }, + tail: Cons { + head: FloorRouteGapExpectation { identity: "test.claim.codex_supervised_turn_wet_witness_test.wet_finish_observe_native_digest_only", operation: "Check", ground: NoMockResponse {} }, + tail: Cons { + head: FloorRouteGapExpectation { identity: "test.claim.codex_supervised_turn_wet_witness_test.wet_finish_observe_toolchain_only", operation: "Check", ground: NoMockResponse {} }, + tail: Empty {} + } + } + } + } + } + } + } + } + } + } + } + } + } + } + } + } + } + } + } + } + } + } +} + +fn floor_route_gap_expectation_chunk_01() -> List { + Cons { + head: FloorRouteGapExpectation { identity: "test.claim.codex_supervised_turn_wet_witness_test.wet_finish_observe_protocol_schema_only", operation: "Check", ground: NoMockResponse {} }, + tail: Cons { + head: FloorRouteGapExpectation { identity: "test.claim.codex_supervised_turn_wet_witness_test.wet_finish_parse_largest_protocol_schema_only", operation: "Check", ground: NoMockResponse {} }, + tail: Cons { + head: FloorRouteGapExpectation { identity: "test.claim.codex_supervised_turn_wet_witness_test.wet_finish_parse_canonicalize_largest_protocol_schema_only", operation: "Check", ground: NoMockResponse {} }, + tail: Cons { + head: FloorRouteGapExpectation { identity: "test.claim.codex_supervised_turn_wet_witness_test.wet_finish_observe_package_tree_only", operation: "Check", ground: NoMockResponse {} }, + tail: Cons { + head: FloorRouteGapExpectation { identity: "test.claim.codex_supervised_turn_wet_witness_test.wet_finish_observe_receipt_identity_only", operation: "Check", ground: NoMockResponse {} }, + tail: Cons { + head: FloorRouteGapExpectation { identity: "test.claim.codex_supervised_turn_wet_witness_test.wet_finish_observe_package_tree_tiny_fixture", operation: "Dir", ground: NoMockResponse {} }, + tail: Cons { + head: FloorRouteGapExpectation { identity: "test.claim.codex_supervised_turn_wet_witness_test.wet_materialize_codex_runtime_bundle_only", operation: "Check", ground: NoMockResponse {} }, + tail: Cons { + head: FloorRouteGapExpectation { identity: "test.claim.codex_supervised_turn_wet_witness_test.supervised_turn_materialized_bundle_writes_terminal_receipt", operation: "Dir", ground: NoMockResponse {} }, + tail: Cons { + head: FloorRouteGapExpectation { identity: "test.claim.dag_compile_clean_shard_totality_witness.compile_clean_shard_totality_holds_on_live_tree", operation: "shell.Find.Files", ground: UnpublishedMockCase {} }, + tail: Cons { + head: FloorRouteGapExpectation { identity: "test.claim.direct_rust_door_write_compile_witness_test.direct_rust_door_emit_write_compile_holds", operation: "Dir", ground: NoMockResponse {} }, + tail: Cons { + head: FloorRouteGapExpectation { identity: "test.claim.expectation_frontier_witness.undeclared_effects_emit_the_frontier_receipt_holds", operation: "Run", ground: NoMockResponse {} }, + tail: Cons { + head: FloorRouteGapExpectation { identity: "test.claim.expectation_frontier_witness.fully_declared_effects_emit_no_frontier_receipt_holds", operation: "Run", ground: NoMockResponse {} }, + tail: Cons { + head: FloorRouteGapExpectation { identity: "test.claim.external_model_scope_live_cover_witness.red_cover_walker_refuses_missing_root", operation: "Filesystem.List", ground: UnpublishedMockCase {} }, + tail: Cons { + head: FloorRouteGapExpectation { identity: "test.claim.external_model_scope_live_cover_witness.manifest_rows_all_predate_freeze_sha", operation: "DiffNameStatus", ground: NoMockResponse {} }, + tail: Cons { + head: FloorRouteGapExpectation { identity: "test.claim.fleet_revision_relation_wet_matrix.an_ancestor_current_is_a_forward_advance", operation: "MergeBase", ground: NoMockResponse {} }, + tail: Cons { + head: FloorRouteGapExpectation { identity: "test.claim.fleet_revision_relation_wet_matrix.an_ancestor_accepted_is_superseded", operation: "MergeBase", ground: NoMockResponse {} }, + tail: Cons { + head: FloorRouteGapExpectation { identity: "test.claim.fleet_revision_relation_wet_matrix.siblings_sharing_an_ancestor_are_neither_ancestor_of_the_other", operation: "MergeBase", ground: NoMockResponse {} }, + tail: Cons { + head: FloorRouteGapExpectation { identity: "test.claim.fleet_revision_relation_wet_matrix.an_orphan_root_has_no_common_ancestor", operation: "MergeBase", ground: NoMockResponse {} }, + tail: Cons { + head: FloorRouteGapExpectation { identity: "test.claim.fleet_revision_relation_wet_matrix.an_absent_object_is_unverifiable_not_unrelated", operation: "MergeBase", ground: NoMockResponse {} }, + tail: Cons { + head: FloorRouteGapExpectation { identity: "test.claim.fleet_revision_relation_wet_matrix.a_non_repository_path_is_unverifiable_rather_than_answering", operation: "MergeBase", ground: NoMockResponse {} }, + tail: Cons { + head: FloorRouteGapExpectation { identity: "test.claim.fleet_revision_relation_wet_matrix.no_merge_base_and_could_not_look_stay_distinguishable", operation: "MergeBase", ground: NoMockResponse {} }, + tail: Empty {} + } + } + } + } + } + } + } + } + } + } + } + } + } + } + } + } + } + } + } + } + } +} + +fn floor_route_gap_expectation_chunk_02() -> List { + Cons { + head: FloorRouteGapExpectation { identity: "test.claim.host_cli_dependency_wet_witness_test.observe_echo_wet_posix_command_v_check_does_not_crash", operation: "Check", ground: NoMockResponse {} }, + tail: Cons { + head: FloorRouteGapExpectation { identity: "test.claim.host_cli_dependency_wet_witness_test.observe_npm_wet_posix_command_v_check_does_not_crash", operation: "Check", ground: NoMockResponse {} }, + tail: Cons { + head: FloorRouteGapExpectation { identity: "test.claim.interpreter_dispatch_bijection_real_roster_witness_test.interpreter_dispatch_bijection_real_roster_red_holds", operation: "Check", ground: NoMockResponse {} }, + tail: Cons { + head: FloorRouteGapExpectation { identity: "test.claim.json_protocol_schema_memory_split_wet_witness_test.wet_finish_parse_largest_protocol_schema_only", operation: "Check", ground: NoMockResponse {} }, + tail: Cons { + head: FloorRouteGapExpectation { identity: "test.claim.json_protocol_schema_memory_split_wet_witness_test.wet_finish_parse_canonicalize_largest_protocol_schema_only", operation: "Check", ground: NoMockResponse {} }, + tail: Cons { + head: FloorRouteGapExpectation { identity: "test.claim.namespace_structural_root_exposure_generated_witness_test.namespace_structural_root_exposure_generated_witness_holds", operation: "IsExecutable", ground: NoMockResponse {} }, + tail: Cons { + head: FloorRouteGapExpectation { identity: "test.claim.no_fake_anomalies_witness.passing_run_shows_no_fake_anomaly_holds", operation: "Run", ground: NoMockResponse {} }, + tail: Cons { + head: FloorRouteGapExpectation { identity: "test.claim.no_fake_anomalies_witness.red_control_entry_with_real_anomaly_still_shows_glyph_holds", operation: "Run", ground: NoMockResponse {} }, + tail: Cons { + head: FloorRouteGapExpectation { identity: "test.claim.push_event_witness_wet.witness_push_before_payload_read_refused_on_missing_path", operation: "Read", ground: NoMockResponse {} }, + tail: Cons { + head: FloorRouteGapExpectation { identity: "test.claim.roadmap_receipt_continuity_live_witness.live_roadmap_acceptance_history_integrity_holds", operation: "git.Inspect.HeadCommit", ground: UnpublishedMockCase {} }, + tail: Cons { + head: FloorRouteGapExpectation { identity: "test.claim.self_host_artifact_materialization_real_execution_witness.a_real_cargo_build_materializes_through_the_real_digest", operation: "Dir", ground: NoMockResponse {} }, + tail: Cons { + head: FloorRouteGapExpectation { identity: "test.claim.self_host_artifact_materialization_real_execution_witness.the_materialized_path_is_the_one_the_real_cargo_stream_named", operation: "Dir", ground: NoMockResponse {} }, + tail: Cons { + head: FloorRouteGapExpectation { identity: "test.claim.self_host_artifact_materialization_real_execution_witness.a_target_the_build_never_produced_refuses_and_does_not_materialize", operation: "Dir", ground: NoMockResponse {} }, + tail: Cons { + head: FloorRouteGapExpectation { identity: "test.claim.self_host_artifact_materialization_real_execution_witness.the_digest_is_of_the_file_cargo_named_not_of_some_other_real_file", operation: "Dir", ground: NoMockResponse {} }, + tail: Cons { + head: FloorRouteGapExpectation { identity: "test.claim.self_host_artifact_materialization_real_execution_witness.changing_only_the_source_bytes_names_exactly_the_artifact_axis", operation: "Dir", ground: NoMockResponse {} }, + tail: Cons { + head: FloorRouteGapExpectation { identity: "test.claim.self_host_artifact_materialization_real_execution_witness.rebuilding_identical_source_in_place_moves_no_axis", operation: "Dir", ground: NoMockResponse {} }, + tail: Cons { + head: FloorRouteGapExpectation { identity: "test.claim.served_surface_browser_artifact_integrity_witness.witness_checked_in_screenshots_match_receipts", operation: "Dir", ground: NoMockResponse {} }, + tail: Cons { + head: FloorRouteGapExpectation { identity: "test.claim.stage0_regen_convergence_real_execution_witness.a_real_regen_stage0_verify_run_reports_zero_divergence", operation: "Run", ground: NoMockResponse {} }, + tail: Cons { + head: FloorRouteGapExpectation { identity: "test.claim.stage0_regen_convergence_real_execution_witness.w_RED_an_unrecognized_flag_does_not_report_the_success_marker", operation: "Run", ground: NoMockResponse {} }, + tail: Cons { + head: FloorRouteGapExpectation { identity: "test.claim.stage0_rust_host_observation_live_witness.live_rust_observation_matches_actions_subject", operation: "Get", ground: NoMockResponse {} }, + tail: Cons { + head: FloorRouteGapExpectation { identity: "test.claim.stage0_rust_host_observation_live_witness.scaffold_host_observation_is_live_and_observed", operation: "git.Inspect.HeadCommit", ground: UnpublishedMockCase {} }, + tail: Cons { + head: FloorRouteGapExpectation { identity: "test.claim.stage0_rust_host_observation_live_witness.scaffold_host_observation_reaches_path_derived_verdict", operation: "git.Inspect.HeadCommit", ground: UnpublishedMockCase {} }, + tail: Empty {} + } + } + } + } + } + } + } + } + } + } + } + } + } + } + } + } + } + } + } + } + } + } +} + +fn floor_route_gap_expectation_chunk_03() -> List { + Cons { + head: FloorRouteGapExpectation { identity: "test.claim.stage0_rust_host_observation_live_witness.scaffold_mechanical_checks_reflect_live_classification", operation: "git.Inspect.HeadCommit", ground: UnpublishedMockCase {} }, + tail: Cons { + head: FloorRouteGapExpectation { identity: "test.claim.stage0_rust_maintenance_census_report_live_witness.maintenance_census_report_positive_control_derives_from_current_head", operation: "git.Inspect.HeadCommit", ground: UnpublishedMockCase {} }, + tail: Cons { + head: FloorRouteGapExpectation { identity: "test.claim.v1_source_audit_witness_test.regen_stage0_write_and_verify_share_compile_refusal", operation: "Read", ground: NoMockResponse {} }, + tail: Cons { + head: FloorRouteGapExpectation { identity: "test.manual.git_upstream_model_execution.witness_git_cli_fixture_hashes_projects_and_independently_reads_back", operation: "Dir", ground: NoMockResponse {} }, + tail: Cons { + head: FloorRouteGapExpectation { identity: "test.manual.mercurial_upstream_model_execution.witness_mercurial_cli_fixture_projects_and_independently_reads_back", operation: "Dir", ground: NoMockResponse {} }, + tail: Cons { + head: FloorRouteGapExpectation { identity: "test.manual.pijul_upstream_model_execution.witness_pijul_cli_fixture_reads_channel_sets_and_retained_conflict", operation: "Dir", ground: NoMockResponse {} }, + tail: Cons { + head: FloorRouteGapExpectation { identity: "v2.test.claim.dag_acceptance_rustc_wet.rustc_accepts_valid_target_source", operation: "CheckSourceText", ground: NoMockResponse {} }, + tail: Cons { + head: FloorRouteGapExpectation { identity: "v2.test.claim.dag_acceptance_rustc_wet.rustc_diagnoses_invalid_target_source", operation: "CheckSourceText", ground: NoMockResponse {} }, + tail: Cons { + head: FloorRouteGapExpectation { identity: "v2.test.execution.emit_on_demand_classical_not_ingested_family_witness.emit_on_demand_classical_not_native_one_build_holds", operation: "emit_host_native_cache_evict", ground: FilesystemRemoval {} }, + tail: Cons { + head: FloorRouteGapExpectation { identity: "v2.test.execution.emit_on_demand_family_crate_witness.family_crate_one_build_members_warm_holds", operation: "emit_host_native_cache_evict", ground: FilesystemRemoval {} }, + tail: Cons { + head: FloorRouteGapExpectation { identity: "v2.test.execution.emit_on_demand_family_crate_witness.family_crate_member_change_cold_rebuild_holds", operation: "emit_host_native_cache_evict", ground: FilesystemRemoval {} }, + tail: Cons { + head: FloorRouteGapExpectation { identity: "v2.test.execution.emit_on_demand_family_crate_witness.family_crate_dispatch_change_cold_rebuild_holds", operation: "emit_host_native_cache_evict", ground: FilesystemRemoval {} }, + tail: Cons { + head: FloorRouteGapExpectation { identity: "v2.test.execution.emit_on_demand_field_access_family_witness.emit_on_demand_field_access_native_one_build_holds", operation: "emit_host_native_cache_evict", ground: FilesystemRemoval {} }, + tail: Cons { + head: FloorRouteGapExpectation { identity: "v2.test.execution.emit_on_demand_kernel_witness.emit_on_demand_kernel_native_one_build_holds", operation: "emit_host_native_cache_evict", ground: FilesystemRemoval {} }, + tail: Cons { + head: FloorRouteGapExpectation { identity: "v2.test.execution.emit_on_demand_match_loop_fold_family_witness.emit_on_demand_match_loop_fold_family_one_build_holds", operation: "emit_host_native_cache_evict", ground: FilesystemRemoval {} }, + tail: Cons { + head: FloorRouteGapExpectation { identity: "v2.test.execution.emit_on_demand_variant_construct_family_witness.emit_on_demand_variant_construct_native_one_build_holds", operation: "emit_host_native_cache_evict", ground: FilesystemRemoval {} }, + tail: Cons { + head: FloorRouteGapExpectation { identity: "v2.test.execution.native_selected_witness_bundle.native_selected_witness_bundle_cold_warm_equivalence_holds", operation: "emit_host_native_cache_evict", ground: FilesystemRemoval {} }, + tail: Cons { + head: FloorRouteGapExpectation { identity: "v2.test.execution.native_selected_witness_bundle.native_selected_witness_bundle_discriminating_red_holds", operation: "emit_host_native_cache_evict", ground: FilesystemRemoval {} }, + tail: Cons { + head: FloorRouteGapExpectation { identity: "v2.test.manual.emit_source_store.emit_source_store_cold_then_warm_holds", operation: "Write", ground: NoMockResponse {} }, + tail: Cons { + head: FloorRouteGapExpectation { identity: "v2.test.manual.emit_source_store.emit_source_store_mutated_emitter_misses_holds", operation: "Write", ground: NoMockResponse {} }, + tail: Cons { + head: FloorRouteGapExpectation { identity: "v2.test.workflow.frontier_probe_closure_readthrough.frontier_probe_read_failure_detail_refused_holds", operation: "Read", ground: NoMockResponse {} }, + tail: Empty {} + } + } + } + } + } + } + } + } + } + } + } + } + } + } + } + } + } + } + } + } + } +} + +// Main's shell.Exec mock deletion changed these five rows from semantic false to an +// interpreter-observed Run refusal in the first post-merge execution, run 32768782787. They +// therefore join the typed route-gap population at the operation and remedy ground actually +// observed; they are not expected-red because no semantic verdict was produced. +// Run 32794539384 added the sixth row after main advanced: the Claude SDK parser-drop wet +// control reached Read / NoMockResponse, likewise producing no semantic verdict. +fn floor_route_gap_expectation_chunk_04() -> List { + Cons { + head: FloorRouteGapExpectation { identity: "test.claim.effect_plan_bash_materialize_real_execution_witness.effect_plan_bash_two_declared_operations_execute", operation: "Run", ground: NoMockResponse {} }, + tail: Cons { + head: FloorRouteGapExpectation { identity: "test.claim.effect_plan_bash_materialize_real_execution_witness.effect_plan_bash_fail_fast_prevents_later_operation_execution", operation: "Run", ground: NoMockResponse {} }, + tail: Cons { + head: FloorRouteGapExpectation { identity: "test.claim.effect_plan_bash_materialize_real_execution_witness.effect_plan_bash_metachar_and_newline_cannot_open_a_statement", operation: "Run", ground: NoMockResponse {} }, + tail: Cons { + head: FloorRouteGapExpectation { identity: "test.claim.transport_script_stdin_byte_fidelity_witness.transport_script_stdin_delivers_exact_bytes", operation: "Run", ground: NoMockResponse {} }, + tail: Cons { + head: FloorRouteGapExpectation { identity: "test.claim.transport_script_stdin_byte_fidelity_witness.transport_script_stdin_fidelity_is_independent_of_terminal_newline", operation: "Run", ground: NoMockResponse {} }, + tail: Cons { + head: FloorRouteGapExpectation { identity: "test.claim.claude_sdk_parser_drop_live_witness.witness_wet_receipt_control_response_parser_drop_holds", operation: "Read", ground: NoMockResponse {} }, + tail: Empty {} + } + } + } + } + } + } +} + +fn floor_route_gap_expectation_chunks() -> List> { + Cons { head: floor_route_gap_expectation_chunk_00(), tail: Cons { head: floor_route_gap_expectation_chunk_01(), tail: Cons { head: floor_route_gap_expectation_chunk_02(), tail: Cons { head: floor_route_gap_expectation_chunk_03(), tail: Cons { head: floor_route_gap_expectation_chunk_04(), tail: Empty {} } } } } } +} + +fn floor_route_gap_expectations() -> List { + list_flat_map(xs: floor_route_gap_expectation_chunks(), f: fn(chunk) { chunk }) +} + // CHUNK 04 -- THE SIXTEEN IDENTITIES SURFACED BY DELETING THE shell.Exec MOCK ARMS, measured on // this branch's own floor run 32670248426 (route_gap_unenrolled=16), not enumerated from call // sites. Every one reaches shell.Exec.Run hermetically and now receives @@ -477,5 +803,7 @@ fn floor_route_gap_chunks() -> List> { } fn floor_route_gap_roster() -> List { - list_flat_map(xs: floor_route_gap_chunks(), f: fn(chunk) { chunk }) + let legacy = list_flat_map(xs: floor_route_gap_chunks(), f: fn(chunk) { chunk }) + let located = floor_route_gap_expectations() |> map(row => row.identity) + list_flat_map(xs: [legacy, located], f: fn(chunk) { chunk }) } diff --git a/src/v2/workflow/required_floor.dag b/src/v2/workflow/required_floor.dag index 95eab116939..0b09f0ec100 100644 --- a/src/v2/workflow/required_floor.dag +++ b/src/v2/workflow/required_floor.dag @@ -19,28 +19,19 @@ import std.measure { byte_size_count, } import std.types { NonEmptyStr } -import v2.std.live_tree { LiveTreeDisposition, ReadsLiveTree, SubstrateInputsOnly } // IDENTITY-GRAINED FLOOR DISPOSITION RECEIPT (operator ruling 2026-08-19). // // Every discovered site gets exactly one `RequiredFloorDisposition`, keyed by its qualified // `module.function` identity. This is the single authority for that fact: the host loop in // `v1_compiler.cli_run` `run_required_floor` computes admission by testing a claim's authored -// module name against `long_home_prefixes()` below, then REALIZES +// module name against `long_home_prefixes()` and `fixture_home_prefixes()` below, then REALIZES // the arm this type already names — it does not invent a second admission concept. A `Declined*` // arm here is a fact about why a site's identity is excluded from the executed roster; it is // never itself the mechanism deciding execution order or eligibility for a DIFFERENT gate. // -// `DeclinedLiveTree` IS RETAINED HERE AND STAGED FOR DELETION AT THE ROOT. Its premise is -// already known to be stale (below), but the deletion is a behaviour change — 782 sites move -// from declined to executed — and it lands with the measurement that prices it, not with this -// change. This paragraph is written in the tense of what IS, because an earlier revision of it -// asserted the deletion as done while the Rust realization still returned the arm: the .dag -// named two arms, `v1_compiler.cli_run` `run_required_floor` emitted three, and the header -// claiming a completed deletion was rung inflation on the exact axis this module argues for -// (caught by review 54035, on this PR). -// -// WHAT IT WAS: a site whose FILE declared `data live_tree_disposition: LiveTreeDisposition = +// `DeclinedLiveTree` IS DELETED HERE AND IN THE HOST REALIZATION AT THE ROOT. What it was: a +// site whose FILE declared `data live_tree_disposition: LiveTreeDisposition = // ReadsLiveTree` was declined, on the premise that reaching the live tree implies "cannot run // in the hermetic frame this floor runs". 778 identities across 112 files sat in that arm, and // since the floor cut left `claim_executor --required-floor` as the only witness-executing @@ -55,8 +46,8 @@ import v2.std.live_tree { LiveTreeDisposition, ReadsLiveTree, SubstrateInputsOnl // "cannot run hermetically", and the decline was a prediction standing where the interpreter // already decides the same question exactly, per identity, at the effect boundary. // -// WHAT WILL REPLACE IT: nothing here. Once the arm is deleted, every non-long identity is -// routed and executed, its route carried by the claim that runs it +// WHAT REPLACES IT: nothing here. Every non-long, non-fixture identity is routed and executed, +// its route carried by the claim that runs it // (`RequiredFloorClaim.execution_mode` — one route per identity, not a second vocabulary // restating it), and the interpreter's own typed `HermeticHostEffectRefused` classifies the // residue that genuinely has no hermetic arm. That residue reaches the receipt as @@ -67,19 +58,19 @@ import v2.std.live_tree { LiveTreeDisposition, ReadsLiveTree, SubstrateInputsOnl // `SitePartitionInexact` wall all execute here, over the 101 identities that reached it // without this arm being touched at all. // -// DELETION TRIGGER: the live-tree decline is removed when the cost measurement over its 782 -// sites lands (run 32345970386 measured 626/783 passing under execution), together with the -// `witness_file_from_source` scan the split retained beside it. +// DELETION RECEIPT: run 32345970386 measured 626/783 passing under execution, and the staged +// blockers were closed before this root deletion. The `witness_file_from_source` scan remains: +// live-tree disposition still feeds affected-set eligibility even though it no longer gates +// floor admission. // // A NOTE ON WHAT DID *NOT* MOVE: `live_tree_disposition` itself is not deleted and is not // deprecated. It remains the declaration `reads_live_tree_effective` reads for AFFECTED-SET // SELECTION ELIGIBILITY, which is a different question from "can this execute" and keeps its -// own single authority. What is staged for deletion is the floor's forked, syntactic second -// copy of it. +// own single authority. Only the floor's forked, syntactic second copy was deleted. type RequiredFloorDisposition = Planned | DeclinedLongModule { matched_prefix: String } - | DeclinedLiveTree + | DeclinedFixtureMember { matched_prefix: String } // ROSTER GROWTH IS BUDGET-BOUND AT THIS ADMISSION AUTHORITY. // @@ -256,40 +247,72 @@ fn long_home_prefixes() -> List { } } +// THE THIRD DECLINE: A FIXTURE MEMBER IS NOT A WITNESS, AND ENROLLING ONE IS NOT DEBT. +// +// A `test fn` under `v2.test.fixture.walk_plan_stage.` is not a claim about the compiler. It is +// an INPUT to another claim: `claim_executor --plan-entry +// src/v2/test/fixture/walk_plan_stage/plan.dag --plan-function ` drives it as a +// `RunnableSingleClaim` row authored in that fixture's own `common.dag`, and the recipes in +// `plan.dag` are what assert on the result. The member is the specimen; the recipe is the +// witness. +// +// WHY THE FOLD MUST NOT RUN THEM, and this is a correctness argument rather than a cost one. +// Two of the nine are red BY CONSTRUCTION and can never green: `failure_red_member`'s body is +// the literal `false`, and `recursion_refusal_member` calls itself so the interpreter's +// call-depth refusal fires — that refusal IS what the recursion-refusal recipe observes. The +// other seven perform the host effects the recipes are about, and `stage2_marker` is the sharp +// one: it writes `target/walk_plan_stage_stage2_ran`, the exact path +// `walk_plan_stage_failure_barrier_recipe` asserts "must stay absent" when stage 1 reds. Giving +// that member a hermetic route would make the floor write the marker that another fixture's +// oracle is defined by — a run corrupting the input of the test it is running. +// +// WHAT THIS COST WHILE IT WAS UNSTATED. All nine were discovered, planned and enrolled: two on +// `v2.workflow.floor_expected_red` and seven on `v2.workflow.floor_route_gap`. Both rosters +// declare themselves temporary, monotone and self-emptying, and neither can ever shed these +// nine — the first two by construction, the seven because the honest route for them is no route +// at all. Nine permanent rows on two shrinking ledgers is the skip list both headers are +// carefully not, arrived at without anyone choosing it. The fixture's own `common.dag` note has +// asserted the correct state of the world all along — "discovery-excluded at dir grain … and +// declares no enrolled witness rows" — and that sentence stopped being true at the floor cut, +// which is when a directory stopped being what discovery reads. +// +// THE MECHANISM IS THE ONE ALREADY SANCTIONED, deliberately and not by analogy: the test is on +// the module's AUTHORED NAME, exactly as `long_home_prefixes` is, for the reason the 2026-08-04 +// ruling gives — a directory must not decide an admission question. `v2.test.fixture.` is NOT +// the prefix, and the narrower one is not caution: 27 modules declare `v2.test.fixture.` and +// only the walk_plan_stage family authors `test fn`s, so the broad prefix would pre-admit a +// decline for 26 modules whose behaviour nobody has examined. A prefix earns its rows. +// +// THIS IS NOT A SELECTION SHRINK, which is the objection it will draw. The 2026-08-13 directive +// forbids SELECTION from shrinking the roster; a home policy answers a different question, and +// the difference here is that these nine LOSE NO COVERAGE — they keep the executing consumer +// they have always had, the recipes, which is more than a route-gap row can say. Declining a +// site whose only consumer is the fold deletes coverage; declining one the fold was never the +// consumer of returns it to its owner. +// +// DISSOLVES when the fixture stops authoring `test fn`s — if `claim_executor` grows a claim form +// that does not require one, this roster empties and the arm goes with it. There is no +// empty-roster refusal here, for the same reason `long_home_prefixes` has none. +fn fixture_home_prefixes() -> List { + Cons { + head: "v2.test.fixture.walk_plan_stage.", + tail: Empty {} + } +} + // THE ADMISSION ORDER, HELD HERE RATHER THAN IN WHOEVER WALKS THE CORPUS. // -// `RequiredFloorDisposition` above names the three arms; until now nothing in this module said -// WHICH arm a given site gets, so the ordering — long home, then live tree, then planned — lived -// only in the host loop that walks the discovered files (`v1_compiler.cli_run` -// `run_required_floor`). That made the type an authority over the vocabulary and not over the -// decision, and a second walker (the .dag census this function was added for) would have had to -// re-author the order and could have re-authored it differently. -// -// THE SURVIVING ORDER HAS NO EXECUTING DISCRIMINATOR, AND THAT IS STATED RATHER THAN LEFT TO BE -// REDISCOVERED. What made this ordering load-bearing was a fixture arm sitting between the long -// home and the live tree: a fixture member that ALSO read the live tree had to report the -// permanent ownership fact, not the staged prediction. That arm is DELETED (the plan/walk residue -// cut, 2026-08-26) along with the one family that inhabited it, so the only remaining precedence -// is long-home over live-tree — and no site can be both, because a long home is a path fact and a -// live-tree read is a declared disposition that the long homes do not carry. The order is -// therefore currently unfalsifiable by any authorable input: it is kept because a THIRD decline -// added later would need a declared position, not because a witness holds it today. Do not cite -// this ordering as covered. -// -// NEXT-RUNG TRIGGER, NAMED SO THIS READS AS NOBODY-BUILT-IT AND NOT AS CANNOT-COVER (DESIGN -// section 4b(2)). This order becomes falsifiable again when a decline exists whose subject CAN -// collide with an existing one — a site that legitimately satisfies two decline reasons at once, -// so which reason it reports is a decision some input can get wrong. At that point the -// discriminating witness is authorable and is owed. Until then the gap is that no such subject -// exists, not that the property is unprovable, and the correct response to the absence is to -// build the third decline's collision case rather than to re-point a witness at a subject that -// cannot disagree with itself. A re-pointed discriminator here would be permanently green BY -// CONSTRUCTION, which is worse than none: it would be cited as coverage. -// -// THE LIVE-TREE INPUT IS THE DECLARED `LiveTreeDisposition`, NOT A `Bool`. The host currently -// hands this decision a `reads_live_tree` boolean it computed one level up; taking the declared -// coproduct here means a third live-tree state added upstream fails to compile in this match -// rather than being silently folded into whichever side of a boolean it was coerced to. +// `RequiredFloorDisposition` above names the three arms. The ordering is long home, then fixture +// home, then planned. This decision previously lived only in the host loop that walks the +// discovered files +// (`v1_compiler.cli_run` `run_required_floor`). That made the type an authority over the +// vocabulary and not over the decision, and a second walker (the .dag census this function was +// added for) would have had to re-author the order and could have re-authored it differently. +// +// THE ORDER IS THE ONE THE HOST REALIZES AND IT IS LOAD-BEARING, not alphabetical: a fixture +// member inside a long home reports the long-home storage disposition first; every other fixture +// member reports the ownership fact that its own recipe already executes it. Live-tree standing +// is absent from this API because the root cut makes it irrelevant to floor admission. type ModulePrefixMatch = ModulePrefixUnmatched | ModulePrefixMatched { prefix: String } @@ -308,14 +331,13 @@ fn first_module_prefix_match(module_path: String, prefixes: List) -> Mod fn required_floor_site_disposition( module_path: String, - reads_live_tree: LiveTreeDisposition, ) -> RequiredFloorDisposition { match first_module_prefix_match(module_path: module_path, prefixes: long_home_prefixes()) { ModulePrefixMatched { prefix: p } => DeclinedLongModule { matched_prefix: p } ModulePrefixUnmatched => - match reads_live_tree { - ReadsLiveTree => DeclinedLiveTree {} - SubstrateInputsOnly => Planned {} + match first_module_prefix_match(module_path: module_path, prefixes: fixture_home_prefixes()) { + ModulePrefixMatched { prefix: p } => DeclinedFixtureMember { matched_prefix: p } + ModulePrefixUnmatched => Planned {} } } } @@ -325,7 +347,7 @@ fn required_floor_site_disposition( // rest of this branch dissolved three of (review 55984). Its only consumer filtered a roster with // it, keeping the routed side and discarding the declined one, which is the fact the census // exists to carry. `gunbc.discovery_census` `census_partition` now descends over these arms in one -// pass and returns both sides, so a fourth arm must be classified rather than absorbed into +// pass and returns both sides, so a fifth arm must be classified rather than absorbed into // `false`, and the roster cannot be produced without its exclusions.