Repository navigation
One authority for how this repo builds its own binaries, with a subject and verb axis for the emitted-tree consumer - #9154
Merged
Conversation
…to one reverse BFS WIP: repo_self_build.dag is the single cargo-build authority (three workflow authorities rewired onto it). module_graph.dag gains the reverse-reachability selector: build adjacency once, BFS outward from touched paths, O(1) membership per entry -- replacing entry_affected_by_touched_paths' per-entry whole-graph walk. A touched path resolving to no module on disk refuses (TouchedPathOutsideModuleGraph); it never widens to the corpus and never narrows to nothing. Compiles: 0 blocking errors on src/v2/lens/module_graph.dag. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01DRMbwdtHZxTiMNZD5WLS3P
…uild has a home instead of a fork
crisp-crab-430 needs to cargo-check an EMITTED CANDIDATE TREE -- the one
required-regen writes to disk and then compares byte-wise to the committed seed
without ever asking whether either compiles. They raised it before writing
rather than after, which is the only reason this is a design change and not a
second authority.
THE MODULE ARGUED AGAINST ITSELF. repo_self_build_authority_note pins the
package as data because 'a caller free to name the package could build a
different crate and still look like a conforming call'. Their subject IS a
different crate, so the exact property the note relies on is what excluded
them. That is not an under-served case; it is the note being right about the
danger and wrong about the remedy.
A closed subject coproduct keeps the guarantee and admits the second breadth:
type CargoBuildSubject
= RepositoryCrate
| EmittedCandidateTree { manifest_path: String }
No constructor names an arbitrary crate, so the property the note wanted is now
structural rather than rhetorical -- and the one other legitimate subject has a
name. DESIGN section 2 horizontal, one concept at two breadths, rather than a
sibling module sharing an argv vocabulary, which is what a section 3 fork looks
like from the inside.
THE VERB IS THE SECOND AXIS AND THEY DID NOT ASK FOR IT. The base command
hardcoded 'cargo build'. Establishing that an emitted tree COMPILES needs only
check, and the difference is measured, not stylistic: check 59.8s / 2.5GB peak
against build 155s / 4.7GB peak, warm, with the whole stage0 lib recompiled --
the candidate-install case exactly -- and every diagnostic of interest is
check-visible. Left hardcoded, the next consumer writes 'cargo check' beside
this module's 'cargo build' and the fork this module exists to prevent
reappears one field down.
repo_self_build_command keeps its signature, so the three consumers rewired
onto it are untouched: it is now the RepositoryCrate/CargoBuild instance of the
general form rather than the only form.
Compiles: 9 files emitted, 0 diagnostics.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DRMbwdtHZxTiMNZD5WLS3P
…e the instrument, and land the projection #9132 left behind TWO THINGS IN ONE REGEN, because they are one fact: the authority moved and the projection did not. (1) THE RECONCILE CLAUSE. Section 6 read 'reconcile's eight minutes are ~92% typecheck_with_census_extra', measured 2026-08-20. The required run of 2026-08-24 (32791076677) emits 'compile.reconcile done in 15 minutes' inside the floor's strict-preparation over 3892 modules. I NEARLY WROTE 'NEARLY DOUBLE IN FIVE DAYS' AND THAT WOULD HAVE BEEN THE SAME DEFECT THIS DOCUMENT SPENT THE EVENING CATCHING. Reconcile's cost is a function of subject size -- measured the same night at 32s for a four-module closure and 25s for required-regen's ~134 surfaces -- and the subject behind the eight-minute figure is not recoverable from this document or from 67437fc, the commit that landed it. So the two numbers cannot be compared at all, and the doubling is not asserted. That is a stronger row than an updated number would have been. The RATIO is kept because where reconcile's time goes is structural; the DURATION is dropped because it is a property of one run on one corpus size. The instrument is named instead -- every required run emits [floor-phase] rows and the compiler's own compile.frontend / normalize / reconcile / analyses lines inside strict-preparation -- so the current cost is read from the run that owns it. This applies the standing rule this document already carries, name the instrument never transcribe its output, to the clause that most needed it. Two retractions produced this wording, both caught by the other party rather than the author: a 31x preparation-versus-compile gap I published (it compared a four-module closure to 3892 modules) and a 33x contradiction smart-ram-730 published (their arm was required-regen's ~134-surface closure). Neither anomaly exists. What survives is that full-corpus reconcile is ~34% of required CI and the floor is CPU-bound and single-threaded at ~99.4% for 36 minutes. (2) THE PROJECTION #9132 LEFT BEHIND. Three further lines move in this regen and none of them is mine tonight: the deleted probe-document link and the name-the-instrument ruling both landed in the AUTHORITY at #9132 and were never projected, so committed DESIGN.md has been stale against its own source since that merge. The drift gate that would have caught this is on the unguarded list in the CI rung-drop row a few paragraphs above -- which is the row explaining why nothing refused. Regenerated through dag/tools/generated_artifact_gate.dag main_wet over all committed artifacts; DESIGN.md is the only file that moved, so every other projection was already at its fixed point. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01DRMbwdtHZxTiMNZD5WLS3P
ONE CONFLICT, IN A GENERATED FILE, SO IT WAS NOT RESOLVED BY MERGING TEXT. DESIGN.md is projected from gunbc.design_document. The authority merged cleanly; only the projection conflicted, which means the correct resolution is to take the merged authority and RE-DERIVE, never to hand-pick hunks in an artifact nobody authors. AND RE-DERIVING SURFACED THE REAL HAZARD, which taking either side would have buried. #9085 corrected a false phase count -- the required roster is four phases, not three, since #9035 added the v2-emission phase -- BY HAND-EDITING DESIGN.md, touching only that file and never gunbc.design_document. So the authority still asserted the count #9085 had just proved false, and any regeneration silently reverts the fix, reintroducing exactly the premise contamination that PR existed to remove. Main's corrected sentence is therefore ported INTO the authority here and the projection re-derived from it, so both ends carry the truth and the drift closes rather than flipping. That is the SECOND projection drift in this one document tonight. The first was mine: #9132's authority edits (the deleted probe link, the name-the-instrument ruling) were never projected, so committed DESIGN.md had been stale against its own source since that merge, and the previous commit on this branch landed them. Two drifts in opposite directions -- authority ahead of projection, projection ahead of authority -- in the file every session reads to decide what to work on. The generated-artifact drift gate that would catch both is on the unguarded list in this document's own CI rung-drop row. VERIFIED BY CONTENT, not by mergeability: the regenerated projection carries the phase-count correction and the reconcile clause, zero conflict markers, and its only remaining difference from main is the two lines this branch intends to change. Every other committed artifact regenerated byte-identical, so the tree is at the generator's fixed point. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01DRMbwdtHZxTiMNZD5WLS3P
…s not belong in a PR that is otherwise finished Split at the operator's direction. The selector compiles clean and has no caller -- required_floor does not reference it -- so merging it here would land machinery that nothing gates on, which DESIGN section 6 names as coverage by illusion. It is not abandoned: it moves to session/deep-ant-102-affected-set-selector with its ceiling measured and stated, and it merges when it is wired to a consumer and a pruned run is measured. What remains in this PR is finished and has a waiting consumer: the single build authority with its subject and verb axes, the three consumers rewired onto it, and the DESIGN authority/projection corrections. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01DRMbwdtHZxTiMNZD5WLS3P
…ad just applied the opposite standard next door Review 55633 (approve, non-blocking): CargoVerb and CargoBuildSubject add a check axis and an emitted-tree subject that nothing in this diff consumes -- the sole caller pins verb=CargoBuild and subject=RepositoryCrate -- so DESIGN section 6's new artifact with no final consumer applies and the honest landing today is bins-only. The reviewer is right on the facts. WHAT DECIDED IT IS WORSE THAN THE FINDING. Twenty minutes earlier I split the affected-set selector OUT of this same branch, on the grounds that an unwired lens does not belong in a PR that is otherwise finished, and then left unwired axes sitting in it. One principle, two neighbouring artifacts, opposite treatment. The reviewer also names the correct exception -- non-blocking if the operator greenlit the pre-plumbed axes -- and there is no such greenlight: I ruled on the requesting session's design question myself, and an author's own ruling is not the operator verdict section 6 requires for work landing ahead of its consumer. THE DESIGN IS NOT RE-OPENED BY THIS, and the module now says so in a note rather than losing it: a free package parameter remains the wrong remedy because it discards the property the authority note relies on, and a sibling authority sharing this argv vocabulary remains the section 3 fork this module exists to prevent. The subject belongs here as a CLOSED vocabulary and the verb is a real axis on a measured 59.8s check against 155s build. What changed is only WHICH DIFF carries them: the one with the consumer, not the one ahead of it. That is strictly better for the requesting session too -- axis and consumer in one reviewable change, justified on its own evidence rather than on mine. They have been told at high priority, before building against a surface about to change. 116 lines to 55. Compiles: 9 files emitted, 0 diagnostics. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01DRMbwdtHZxTiMNZD5WLS3P
…d authority, since its regenerator refuses on main too The conflict is in DESIGN.md, a generated projection, and the merge driver's instruction is to regenerate rather than pick a side. That instruction is currently unsatisfiable: the generated-artifact gate refuses with EXIT=1 and writes nothing, and it does so on a detached clean origin/main worktree (4ab8067) as well -- measured, with a positive control confirming the worktree was populated and the gate modified no file there either. All four error subjects it names appear on main at higher multiplicity than on this branch, and this branch touches none of the four modules, so the refusal is pre-existing and not introduced here. Hand-picking a side was still not available, so the resolution is derived from the authority instead of judged. dag/gunbc/design_document.dag merged cleanly, so it holds the correct value for every row. The projection rule was proven first on a control -- a row both sides agree on, where "- " + li(text:) matches the DESIGN.md line byte-for-byte -- and only then applied. Measured against the merged authority: 29 li rows, and exactly one absent from the ours side, main's new BLOCKING EMIT-STAGE DIAGNOSTIC row. The other nine apparent absences are nesting and escape artifacts and are present in another form. That single row is appended at the position the authority's own ordering gives it, which is also where main puts it. Two verifications, both passing: every one of the 29 authority rows is now present in DESIGN.md, and the whole-file diff against main is exactly the two rows this branch deliberately changed and nothing else. The first is the stronger claim -- it establishes that the file IS the projection of the merged authorities, which is the property the driver's regenerate instruction exists to guarantee and which taking either side would have broken. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01DRMbwdtHZxTiMNZD5WLS3P
…oes not discover the transport fusion alone Review 55636 is right that this module re-mints cargo argv words that extdeps.rust.cargo_build already owns, and the existing note conceded the boundary without saying what blocks it. Consuming that module is not available, and the reason is measurable rather than a matter of taste. Every cargo argv word there -- cargo, build, -p, --bin -- appears only inside a transport shell block. Measured on the live file, its entire declaration surface is one ExternalAuthority anchor, one env map, one note and two jobs-flag fns; no data or fn exposes the vocabulary at all. So there is no expression a fn here could read it from: the argv is fused to the shell transport that spells it. That is the DESIGN section 3 interface-versus-realization seam exactly. This consumer needs a workflow YAML string, which is a second realization of the same operation, so the correct repair is to de-fuse the operation shape from transport shell and bind both realizations to it -- not to have this module reach into a transport block, which the language does not admit. The follow-up is therefore de-fusion in extdeps, strictly larger than this PR and correctly outside it. Until it lands the fork stands, named rather than silent. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01DRMbwdtHZxTiMNZD5WLS3P
briansrls
added a commit
that referenced
this pull request
Aug 25, 2026
…string renderer a bounded adapter with a terminus (#9164) Two corrections from the v2-management thread's #9154 review. A third and the owed axis controls are moot: they were written against e4b942a, before review 55633 backed the CargoBuildSubject and CargoVerb axes out, so the free manifest_path they object to no longer exists to be closed. THE TRANSCRIBED BENCHMARK IS NOT MOOT AND WAS LIVE ON THIS HEAD. The axes went but their deferral note stayed, and it carried "a measured 59.8s/2.5GB against build at 155s/4.7GB" -- transcribed output preserved as authority inside a .dag module. That is the measurement-bankruptcy rule violated in as many words, by the same branch that ported the corrected rule into the design document. The enduring claim is qualitative and is what the note now carries: cargo check establishes the required compile diagnostics without paying for final binary production. The producer that re-derives the comparison is named instead, and the magnitudes are left as a property of the run that took them. THE ARGV FORK IS NAMED WITH A TERMINUS RATHER THAN ONLY A BLOCKER. The previous commit measured why extdeps.rust.cargo_build cannot be consumed -- every cargo argv word there lives only inside a transport shell block -- but stating the blocker is not the same as bounding the debt. The thread's accepted second form is taken: this renderer is declared a bounded workflow adapter, not a second cargo authority of equal standing, with the three-way split it adapts across written down and a dissolution trigger naming its end. It dissolves when the operation shape is de-fused from transport shell and can bind a workflow-text realization, at which point this module produces a typed invocation and the argv words leave it entirely rather than being spelled correctly here. The reviewer instruction that follows from that is stated on the carrier, since a terminus nobody enforces is decoration: refuse any NEW argv word added here that the modeled surface already owns. Claude-Session: https://claude.ai/code/session_01DRMbwdtHZxTiMNZD5WLS3P Co-authored-by: Brian Searls <briansearls1@gmail.com> Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes a four-way fork in how this repository builds its own binaries, and lands two DESIGN authority/projection corrections. No behaviour change: proven by regeneration, not by inspection.
The fork
"How this repo builds its compiler" had four owners — three workflow authorities each spelling the argv independently, plus one hand-authored — with differing bin sets and nothing relating them. Operator ruling 2026-08-24: everything compiles through the same point.
That last hunk is the point:
witness_floor_workflowhad already written this fold, correctly, in private. What was missing was not the idea but its REACH — three other consumers could not call it. The new module is that function promoted to where every consumer reaches it.The split follows §3. The cargo build shape is upstream's; which package and bins is business policy and lives here; how a consumer transports it is realization and lives with the consumer.
Two axes, added for a waiting consumer
crisp-crab-430needs tocargo checkan emitted candidate tree — the onerequired-regenwrites and then compares byte-wise without ever asking whether either side compiles.The module argued against itself:
repo_self_build_authority_notepins the package as data because "a caller free to name the package could build a different crate and still look like a conforming call." Their subject is a different crate, so the exact property the note relies on is what excluded them. The note is right about the danger and was wrong about the remedy.A closed vocabulary keeps the guarantee structurally — no constructor names an arbitrary crate — while admitting the one other legitimate breadth. The verb is a second axis because the base command hardcoded
cargo build, andcheckis measured at 59.8s/2.5GB against build's 155s/4.7GB with every diagnostic of interest check-visible. Left hardcoded, the next consumer writescargo checkbeside it and the fork reappears one field down.repo_self_build_commandkeeps its signature, so the three rewired consumers are untouched: it is now theRepositoryCrate/CargoBuildinstance of the general form.Evidence
The rewires emit byte-identical workflow YAML. Regenerating every committed artifact over this tree moves zero files. That zero is discriminating rather than saturated: the identical command on this identical tree moved
DESIGN.mdtwo runs earlier, so the instrument is demonstrably able to detect a change.repo_self_build.dagcompiles: 9 files emitted, 0 diagnostics.DESIGN corrections (two drifts, opposite directions)
Authority ahead of projection. Bankrupt the measurement corpus: delete docs/probes whole, boards and instruments alike #9132's edits (deleted probe link, the name-the-instrument ruling) were never projected, so committed
DESIGN.mdhad been stale against its own source since that merge.Projection ahead of authority. The required roster is four phases, not three: #9035 added one and DESIGN never noticed #9085 corrected a false phase count — the required roster is four phases, not three — by hand-editing
DESIGN.mdand never touchinggunbc.design_document. The authority still asserted the count that PR disproved, so any regeneration silently reverts the fix. Main's corrected sentence is ported into the authority here.Both in the file every session reads to decide what to work on. The generated-artifact drift gate that would catch either is on the unguarded list in this document's own CI rung-drop row.
compile.reconcile done in 15 minutesover 3892 modules. The doubling is not asserted — the subject behind the eight-minute figure is recoverable neither from the document nor from 67437fc, and reconcile's cost is a function of subject size (measured the same night at 32s for a four-module closure and 25s for ~134 regen surfaces). Two retractions produced that wording: a 31x gap I published and a 33x one smart-ram-730 published, both comparing different-sized subjects. The ratio is kept because it is structural; the duration is dropped because it is a property of one run.Not included
The module-grain affected-set selector moved to
session/deep-ant-102-affected-set-selector. It compiles clean and has no caller, so merging it here would land machinery nothing gates on — §6's coverage by illusion. It merges when wired to a consumer with a measured pruned run.