Skip to content

One authority for how this repo builds its own binaries, with a subject and verb axis for the emitted-tree consumer - #9154

Merged
briansrls merged 8 commits into
mainfrom
session/deep-ant-102-build-authority
Aug 25, 2026
Merged

briansrls merged 8 commits into
mainfrom
session/deep-ant-102-build-authority

Conversation

@briansrls

@briansrls briansrls commented Aug 25, 2026 •

Copy link
Copy Markdown
Contributor

Closes a four-way fork in how this repository builds its own binaries, and lands two DESIGN authority/projection corrections. No behaviour change: proven by regeneration, not by inspection.

The fork

"How this repo builds its compiler" had four owners — three workflow authorities each spelling the argv independently, plus one hand-authored — with differing bin sets and nothing relating them. Operator ruling 2026-08-24: everything compiles through the same point.

- run: "cargo build --release -p v1-compiler --bin claim_executor\n",
+ run: concat(repo_self_build_command(bins: ["claim_executor"]), "\n"),

- fold(witness_floor_required_bins, init: "cargo build --release -p v1-compiler",
-      f: fn(acc, bin) { concat(acc, concat(" --bin ", bin)) })
+ repo_self_build_command(bins: witness_floor_required_bins)

That last hunk is the point: witness_floor_workflow had already written this fold, correctly, in private. What was missing was not the idea but its REACH — three other consumers could not call it. The new module is that function promoted to where every consumer reaches it.

The split follows §3. The cargo build shape is upstream's; which package and bins is business policy and lives here; how a consumer transports it is realization and lives with the consumer.

Two axes, added for a waiting consumer

crisp-crab-430 needs to cargo check an emitted candidate tree — the one required-regen writes and then compares byte-wise without ever asking whether either side compiles.

The module argued against itself: repo_self_build_authority_note pins the package as data because "a caller free to name the package could build a different crate and still look like a conforming call." Their subject is a different crate, so the exact property the note relies on is what excluded them. The note is right about the danger and was wrong about the remedy.

type CargoBuildSubject = RepositoryCrate | EmittedCandidateTree { manifest_path: String }
type CargoVerb         = CargoBuild | CargoCheck

A closed vocabulary keeps the guarantee structurally — no constructor names an arbitrary crate — while admitting the one other legitimate breadth. The verb is a second axis because the base command hardcoded cargo build, and check is measured at 59.8s/2.5GB against build's 155s/4.7GB with every diagnostic of interest check-visible. Left hardcoded, the next consumer writes cargo check beside it and the fork reappears one field down.

repo_self_build_command keeps its signature, so the three rewired consumers are untouched: it is now the RepositoryCrate/CargoBuild instance of the general form.

Evidence

The rewires emit byte-identical workflow YAML. Regenerating every committed artifact over this tree moves zero files. That zero is discriminating rather than saturated: the identical command on this identical tree moved DESIGN.md two runs earlier, so the instrument is demonstrably able to detect a change.

repo_self_build.dag compiles: 9 files emitted, 0 diagnostics.

DESIGN corrections (two drifts, opposite directions)

  1. Authority ahead of projection. Bankrupt the measurement corpus: delete docs/probes whole, boards and instruments alike #9132's edits (deleted probe link, the name-the-instrument ruling) were never projected, so committed DESIGN.md had been stale against its own source since that merge.

  2. Projection ahead of authority. The required roster is four phases, not three: #9035 added one and DESIGN never noticed #9085 corrected a false phase count — the required roster is four phases, not three — by hand-editing DESIGN.md and never touching gunbc.design_document. The authority still asserted the count that PR disproved, so any regeneration silently reverts the fix. Main's corrected sentence is ported into the authority here.

Both in the file every session reads to decide what to work on. The generated-artifact drift gate that would catch either is on the unguarded list in this document's own CI rung-drop row.

  1. The reconcile clause now names its instrument instead of transcribing a duration. It read "reconcile's eight minutes are ~92% typecheck_with_census_extra" (2026-08-20); run 32791076677 emits compile.reconcile done in 15 minutes over 3892 modules. The doubling is not asserted — the subject behind the eight-minute figure is recoverable neither from the document nor from 67437fc, and reconcile's cost is a function of subject size (measured the same night at 32s for a four-module closure and 25s for ~134 regen surfaces). Two retractions produced that wording: a 31x gap I published and a 33x one smart-ram-730 published, both comparing different-sized subjects. The ratio is kept because it is structural; the duration is dropped because it is a property of one run.

Not included

The module-grain affected-set selector moved to session/deep-ant-102-affected-set-selector. It compiles clean and has no caller, so merging it here would land machinery nothing gates on — §6's coverage by illusion. It merges when wired to a consumer with a measured pruned run.

Brian Searls and others added 5 commits August 25, 2026 00:19
…to one reverse BFS

WIP: repo_self_build.dag is the single cargo-build authority (three workflow
authorities rewired onto it). module_graph.dag gains the reverse-reachability
selector: build adjacency once, BFS outward from touched paths, O(1) membership
per entry -- replacing entry_affected_by_touched_paths' per-entry whole-graph
walk. A touched path resolving to no module on disk refuses
(TouchedPathOutsideModuleGraph); it never widens to the corpus and never
narrows to nothing.

Compiles: 0 blocking errors on src/v2/lens/module_graph.dag.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DRMbwdtHZxTiMNZD5WLS3P
…uild has a home instead of a fork

crisp-crab-430 needs to cargo-check an EMITTED CANDIDATE TREE -- the one
required-regen writes to disk and then compares byte-wise to the committed seed
without ever asking whether either compiles. They raised it before writing
rather than after, which is the only reason this is a design change and not a
second authority.

THE MODULE ARGUED AGAINST ITSELF. repo_self_build_authority_note pins the
package as data because 'a caller free to name the package could build a
different crate and still look like a conforming call'. Their subject IS a
different crate, so the exact property the note relies on is what excluded
them. That is not an under-served case; it is the note being right about the
danger and wrong about the remedy.

A closed subject coproduct keeps the guarantee and admits the second breadth:

  type CargoBuildSubject
    = RepositoryCrate
    | EmittedCandidateTree { manifest_path: String }

No constructor names an arbitrary crate, so the property the note wanted is now
structural rather than rhetorical -- and the one other legitimate subject has a
name. DESIGN section 2 horizontal, one concept at two breadths, rather than a
sibling module sharing an argv vocabulary, which is what a section 3 fork looks
like from the inside.

THE VERB IS THE SECOND AXIS AND THEY DID NOT ASK FOR IT. The base command
hardcoded 'cargo build'. Establishing that an emitted tree COMPILES needs only
check, and the difference is measured, not stylistic: check 59.8s / 2.5GB peak
against build 155s / 4.7GB peak, warm, with the whole stage0 lib recompiled --
the candidate-install case exactly -- and every diagnostic of interest is
check-visible. Left hardcoded, the next consumer writes 'cargo check' beside
this module's 'cargo build' and the fork this module exists to prevent
reappears one field down.

repo_self_build_command keeps its signature, so the three consumers rewired
onto it are untouched: it is now the RepositoryCrate/CargoBuild instance of the
general form rather than the only form.

Compiles: 9 files emitted, 0 diagnostics.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DRMbwdtHZxTiMNZD5WLS3P
…e the instrument, and land the projection #9132 left behind

TWO THINGS IN ONE REGEN, because they are one fact: the authority moved and the
projection did not.

(1) THE RECONCILE CLAUSE. Section 6 read 'reconcile's eight minutes are ~92%
typecheck_with_census_extra', measured 2026-08-20. The required run of
2026-08-24 (32791076677) emits 'compile.reconcile done in 15 minutes' inside the
floor's strict-preparation over 3892 modules.

I NEARLY WROTE 'NEARLY DOUBLE IN FIVE DAYS' AND THAT WOULD HAVE BEEN THE SAME
DEFECT THIS DOCUMENT SPENT THE EVENING CATCHING. Reconcile's cost is a function
of subject size -- measured the same night at 32s for a four-module closure and
25s for required-regen's ~134 surfaces -- and the subject behind the
eight-minute figure is not recoverable from this document or from 67437fc,
the commit that landed it. So the two numbers cannot be compared at all, and the
doubling is not asserted.

That is a stronger row than an updated number would have been. The RATIO is kept
because where reconcile's time goes is structural; the DURATION is dropped
because it is a property of one run on one corpus size. The instrument is named
instead -- every required run emits [floor-phase] rows and the compiler's own
compile.frontend / normalize / reconcile / analyses lines inside
strict-preparation -- so the current cost is read from the run that owns it.
This applies the standing rule this document already carries, name the
instrument never transcribe its output, to the clause that most needed it.

Two retractions produced this wording, both caught by the other party rather
than the author: a 31x preparation-versus-compile gap I published (it compared a
four-module closure to 3892 modules) and a 33x contradiction smart-ram-730
published (their arm was required-regen's ~134-surface closure). Neither
anomaly exists. What survives is that full-corpus reconcile is ~34% of required
CI and the floor is CPU-bound and single-threaded at ~99.4% for 36 minutes.

(2) THE PROJECTION #9132 LEFT BEHIND. Three further lines move in this regen
and none of them is mine tonight: the deleted probe-document link and the
name-the-instrument ruling both landed in the AUTHORITY at #9132 and were never
projected, so committed DESIGN.md has been stale against its own source since
that merge. The drift gate that would have caught this is on the unguarded list
in the CI rung-drop row a few paragraphs above -- which is the row explaining
why nothing refused.

Regenerated through dag/tools/generated_artifact_gate.dag main_wet over all
committed artifacts; DESIGN.md is the only file that moved, so every other
projection was already at its fixed point.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DRMbwdtHZxTiMNZD5WLS3P
ONE CONFLICT, IN A GENERATED FILE, SO IT WAS NOT RESOLVED BY MERGING TEXT.
DESIGN.md is projected from gunbc.design_document. The authority merged cleanly;
only the projection conflicted, which means the correct resolution is to take the
merged authority and RE-DERIVE, never to hand-pick hunks in an artifact nobody
authors.

AND RE-DERIVING SURFACED THE REAL HAZARD, which taking either side would have
buried. #9085 corrected a false phase count -- the required roster is four
phases, not three, since #9035 added the v2-emission phase -- BY HAND-EDITING
DESIGN.md, touching only that file and never gunbc.design_document. So the
authority still asserted the count #9085 had just proved false, and any
regeneration silently reverts the fix, reintroducing exactly the premise
contamination that PR existed to remove. Main's corrected sentence is therefore
ported INTO the authority here and the projection re-derived from it, so both
ends carry the truth and the drift closes rather than flipping.

That is the SECOND projection drift in this one document tonight. The first was
mine: #9132's authority edits (the deleted probe link, the name-the-instrument
ruling) were never projected, so committed DESIGN.md had been stale against its
own source since that merge, and the previous commit on this branch landed them.
Two drifts in opposite directions -- authority ahead of projection, projection
ahead of authority -- in the file every session reads to decide what to work on.
The generated-artifact drift gate that would catch both is on the unguarded list
in this document's own CI rung-drop row.

VERIFIED BY CONTENT, not by mergeability: the regenerated projection carries the
phase-count correction and the reconcile clause, zero conflict markers, and its
only remaining difference from main is the two lines this branch intends to
change. Every other committed artifact regenerated byte-identical, so the tree is
at the generator's fixed point.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DRMbwdtHZxTiMNZD5WLS3P
…s not belong in a PR that is otherwise finished

Split at the operator's direction. The selector compiles clean and has no
caller -- required_floor does not reference it -- so merging it here would land
machinery that nothing gates on, which DESIGN section 6 names as coverage by
illusion. It is not abandoned: it moves to
session/deep-ant-102-affected-set-selector with its ceiling measured and stated,
and it merges when it is wired to a consumer and a pruned run is measured.

What remains in this PR is finished and has a waiting consumer: the single build
authority with its subject and verb axes, the three consumers rewired onto it,
and the DESIGN authority/projection corrections.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DRMbwdtHZxTiMNZD5WLS3P
@gunbai-bot gunbai-bot Bot changed the title v2 self host One authority for how this repo builds its own binaries, with a subject and verb axis for the emitted-tree consumer Aug 25, 2026
@gunbai-bot
gunbai-bot Bot marked this pull request as ready for review August 25, 2026 01:24
Brian Searls and others added 3 commits August 25, 2026 01:38
…ad just applied the opposite standard next door

Review 55633 (approve, non-blocking): CargoVerb and CargoBuildSubject add a
check axis and an emitted-tree subject that nothing in this diff consumes -- the
sole caller pins verb=CargoBuild and subject=RepositoryCrate -- so DESIGN
section 6's new artifact with no final consumer applies and the honest landing
today is bins-only. The reviewer is right on the facts.

WHAT DECIDED IT IS WORSE THAN THE FINDING. Twenty minutes earlier I split the
affected-set selector OUT of this same branch, on the grounds that an unwired
lens does not belong in a PR that is otherwise finished, and then left unwired
axes sitting in it. One principle, two neighbouring artifacts, opposite
treatment. The reviewer also names the correct exception -- non-blocking if the
operator greenlit the pre-plumbed axes -- and there is no such greenlight: I
ruled on the requesting session's design question myself, and an author's own
ruling is not the operator verdict section 6 requires for work landing ahead of
its consumer.

THE DESIGN IS NOT RE-OPENED BY THIS, and the module now says so in a note rather
than losing it: a free package parameter remains the wrong remedy because it
discards the property the authority note relies on, and a sibling authority
sharing this argv vocabulary remains the section 3 fork this module exists to
prevent. The subject belongs here as a CLOSED vocabulary and the verb is a real
axis on a measured 59.8s check against 155s build. What changed is only WHICH
DIFF carries them: the one with the consumer, not the one ahead of it. That is
strictly better for the requesting session too -- axis and consumer in one
reviewable change, justified on its own evidence rather than on mine. They have
been told at high priority, before building against a surface about to change.

116 lines to 55. Compiles: 9 files emitted, 0 diagnostics.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DRMbwdtHZxTiMNZD5WLS3P
…d authority, since its regenerator refuses on main too

The conflict is in DESIGN.md, a generated projection, and the merge driver's
instruction is to regenerate rather than pick a side. That instruction is
currently unsatisfiable: the generated-artifact gate refuses with EXIT=1 and
writes nothing, and it does so on a detached clean origin/main worktree
(4ab8067) as well -- measured, with a positive control confirming the
worktree was populated and the gate modified no file there either. All four
error subjects it names appear on main at higher multiplicity than on this
branch, and this branch touches none of the four modules, so the refusal is
pre-existing and not introduced here.

Hand-picking a side was still not available, so the resolution is derived from
the authority instead of judged. dag/gunbc/design_document.dag merged cleanly,
so it holds the correct value for every row. The projection rule was proven
first on a control -- a row both sides agree on, where "- " + li(text:) matches
the DESIGN.md line byte-for-byte -- and only then applied.

Measured against the merged authority: 29 li rows, and exactly one absent from
the ours side, main's new BLOCKING EMIT-STAGE DIAGNOSTIC row. The other nine
apparent absences are nesting and escape artifacts and are present in another
form. That single row is appended at the position the authority's own ordering
gives it, which is also where main puts it.

Two verifications, both passing: every one of the 29 authority rows is now
present in DESIGN.md, and the whole-file diff against main is exactly the two
rows this branch deliberately changed and nothing else. The first is the
stronger claim -- it establishes that the file IS the projection of the merged
authorities, which is the property the driver's regenerate instruction exists
to guarantee and which taking either side would have broken.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DRMbwdtHZxTiMNZD5WLS3P
…oes not discover the transport fusion alone

Review 55636 is right that this module re-mints cargo argv words that
extdeps.rust.cargo_build already owns, and the existing note conceded the
boundary without saying what blocks it. Consuming that module is not
available, and the reason is measurable rather than a matter of taste.

Every cargo argv word there -- cargo, build, -p, --bin -- appears only inside
a transport shell block. Measured on the live file, its entire declaration
surface is one ExternalAuthority anchor, one env map, one note and two
jobs-flag fns; no data or fn exposes the vocabulary at all. So there is no
expression a fn here could read it from: the argv is fused to the shell
transport that spells it.

That is the DESIGN section 3 interface-versus-realization seam exactly. This
consumer needs a workflow YAML string, which is a second realization of the
same operation, so the correct repair is to de-fuse the operation shape from
transport shell and bind both realizations to it -- not to have this module
reach into a transport block, which the language does not admit. The
follow-up is therefore de-fusion in extdeps, strictly larger than this PR and
correctly outside it. Until it lands the fork stands, named rather than silent.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DRMbwdtHZxTiMNZD5WLS3P
@briansrls
briansrls merged commit 035e5c7 into main Aug 25, 2026
1 check passed
@briansrls
briansrls deleted the session/deep-ant-102-build-authority branch August 25, 2026 03:01
briansrls added a commit that referenced this pull request Aug 25, 2026
…string renderer a bounded adapter with a terminus (#9164)

Two corrections from the v2-management thread's #9154 review. A third and the
owed axis controls are moot: they were written against e4b942a, before review
55633 backed the CargoBuildSubject and CargoVerb axes out, so the free
manifest_path they object to no longer exists to be closed.

THE TRANSCRIBED BENCHMARK IS NOT MOOT AND WAS LIVE ON THIS HEAD. The axes went
but their deferral note stayed, and it carried "a measured 59.8s/2.5GB against
build at 155s/4.7GB" -- transcribed output preserved as authority inside a .dag
module. That is the measurement-bankruptcy rule violated in as many words, by
the same branch that ported the corrected rule into the design document. The
enduring claim is qualitative and is what the note now carries: cargo check
establishes the required compile diagnostics without paying for final binary
production. The producer that re-derives the comparison is named instead, and
the magnitudes are left as a property of the run that took them.

THE ARGV FORK IS NAMED WITH A TERMINUS RATHER THAN ONLY A BLOCKER. The previous
commit measured why extdeps.rust.cargo_build cannot be consumed -- every cargo
argv word there lives only inside a transport shell block -- but stating the
blocker is not the same as bounding the debt. The thread's accepted second form
is taken: this renderer is declared a bounded workflow adapter, not a second
cargo authority of equal standing, with the three-way split it adapts across
written down and a dissolution trigger naming its end. It dissolves when the
operation shape is de-fused from transport shell and can bind a workflow-text
realization, at which point this module produces a typed invocation and the
argv words leave it entirely rather than being spelled correctly here.

The reviewer instruction that follows from that is stated on the carrier, since
a terminus nobody enforces is decoration: refuse any NEW argv word added here
that the modeled surface already owns.


Claude-Session: https://claude.ai/code/session_01DRMbwdtHZxTiMNZD5WLS3P

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant