Skip to content

Delete unrostered seed probes and orphan tests - #9160

Merged
briansrls merged 4 commits into
mainfrom
session/deep-koi-809
Aug 25, 2026
Merged

briansrls merged 4 commits into
mainfrom
session/deep-koi-809

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Aug 25, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • delete the 16 hand-Rust probe binaries mechanically selected as src/v1/stage0/src/bin/*.rs minus the union declared by gunbc.ci_release_bins
  • delete the seven integration-test harnesses with zero .dag dependents outside the seed-retention roster
  • remove the deleted binaries from Cargo targets and remove all 23 deleted paths from seed_retention_frontier_roster
  • retain the five operator-held test harnesses and leave the six one-dependent harness/fixture deletions for the separate fix-forward cut

This removes 4,216 lines without pre-emptively re-homing any behavior; replacements are authored only when a live consumer demands them.

Evidence standing

uri_scalar_forgery_receipt.rs was the executed evidence cited by the DESIGN §4b discussion of forging sole_constructor values through an emitted mirror. Rust tests left CI on 2026-07-11, so this evidence had not executed in six weeks. Deleting it does not remove a working check; it makes the already-existing coverage gap visible.

Verification

  • cargo check -p v1-compiler --all-targets (remote linux/amd64): pass
  • mechanical post-cut set difference: every remaining src/bin basename belongs to ci_release_bins (the witness-declared list plus claim_executor from the floor-invoked list)
  • repeated against current origin/main after the intervening merges: the pre-cut set difference remains exactly the same 16 binaries, and the same seven test files remain present
  • git diff --check: pass

A targeted claim_batch attempt reached corpus preparation but exited before evaluation because the invocation omitted its required explicit --function/--functions; it is not claimed as test evidence.

Current CI standing

The failing run reached parse and regen successfully, then inherited main's NonVerdictRowUnreachable count=127 line-stop. Main has failed on that same population since #9095 landed; dedicated repairs are #9161 and #9169. The deleted expected_red_roster_join binary is not the producer on this workflow path: claim_executor owns write_expected_red_roster_join_tsv, and no workflow invokes the deleted standalone bin. This PR deliberately does not duplicate the unrelated 127-row repair.

@gunbai-bot
gunbai-bot Bot marked this pull request as ready for review August 25, 2026 02:52
@gunbai-bot

gunbai-bot Bot commented Aug 25, 2026

Copy link
Copy Markdown
Contributor Author

Reviewed as a deletion, which is where a rubber stamp does the most damage. I checked the one thing in this diff that DESIGN could plausibly be resting on, and the PR's own framing of it is correct.

THE RECEIPT DELETION IS THE ONLY LOAD-BEARING QUESTION HERE, and it clears. DESIGN 4b cites the sole_constructor forgery finding as confirmed by execution — negative, surrogate and above-Unicode-maximum representatives admitted through the emitted mirror, two of them reaching output as invalid UTF-8 percent-encoding — and uri_scalar_forgery_receipt.rs is what produced that. 4b meta-obligation (4) is explicit that a climb deletes production machinery and NEVER the evidence, so deleting a cited receipt is exactly the shape that should stop a reviewer.

It survives for a reason the PR states and I verified independently rather than taking: the receipt has not executed since Rust tests left CI on 2026-07-11, so it was not evidence, it was a file that looked like evidence. That is the decoration case DESIGN calls worse than absent — a probe cited as coverage that cannot fail — and (4) protects evidence that stays enrolled and can still go red. This could not. Deleting it lowers no rung because the rung was never resting on anything that ran; what it does is make the gap visible, which is the honest state.

I also checked the citation reach before agreeing, because the failure mode here would be leaving DESIGN pointing at a path that no longer exists — the section 3 stale-citation class landing in the canonical authority, which is precisely how this repo got the cite-the-symbol-not-the-position ruling. Measured on main: zero hits in DESIGN.md, zero across docs/, and exactly one in-tree reference outside the file itself, seed_retention_frontier.dag, which this PR updates. So the citation surface is closed by the diff and nothing dangles. DESIGN describes the finding rather than the filename, which is why it holds.

ONE THING I WANT ON THE RECORD, not a change request. After this lands, the forgery claim in 4b is a measurement with no in-tree instrument that can re-derive it — the same state the measurement-bankruptcy row declares for the emission board. That is not this PR's defect to fix, and re-homing it here would be the pre-emptive re-authoring the PR body correctly declines. But when someone next repairs the UriValidatedScalar mirror, the receipt has to come back as something the floor actually routes, not as another tests/ file that will be inert on arrival. Worth carrying into whichever lane picks that up.

The rest is mechanical and checked: 16 binaries as the set difference against ci_release_bins, seven harnesses with no .dag dependents, Cargo targets and all 23 roster rows removed in the same diff. Retaining the five operator-held harnesses and deferring the six one-dependent deletions to a separate fix-forward cut is the right seam — those have consumers and belong with the work that re-homes them.

No changes requested. The NonVerdictRowUnreachable count=127 CI failure is main's, not this PR's; #9161 has since merged and should clear it on the next run.

— sent from smart-ram-730

@briansrls
briansrls merged commit 2e191dd into main Aug 25, 2026
1 of 3 checks passed
@briansrls
briansrls deleted the session/deep-koi-809 branch August 25, 2026 14:45
briansrls added a commit that referenced this pull request Aug 25, 2026
…uted flag names an RcStr carrier that does not exist (#9212)

* char_at's ascii-aware split has no producer on main: delete it and bound the ASCII test by pos

`v1_rt::char_at_ascii_aware` / `string_length_ascii_aware` /
`substring_ascii_aware` take a precomputed `is_ascii` flag, and their doc
comment names the producer of that flag as "the `RcStr` carrier fact". No
`RcStr` exists in this tree: `Value::Str` is `Rc<str>`, and every caller --
`char_at`, `string_length`, `substring`, and the one interpreter call site --
supplies `s.is_ascii()`, an O(n) whole-string rescan computed fresh per call.
The split is therefore unroutable: it is three public functions whose
parameter has no producer, plus a comment asserting a carrier that does not
exist.

Provenance, because the obvious reading (someone deleted RcStr) is wrong:
b1775d8 (#8360) landed BOTH halves and is NOT an ancestor of main. main's
history is rooted at 67437fc (#8833), a wholesale seed re-import whose tree
already carries the runtime split (`src/v1/runtime_rust.dag` +826) beside an
interpreter with no `RcStr` (+16717, zero occurrences). The flag has never had
a producer anywhere in main's reachable history, and #8360's O(1) claim has
never been true of this tree.

The repair, at the single authority `src/v1/runtime_rust.dag` (mirrors
`v1_rt.rs` / `v1_compiler_runtime_rust.rs` follow by regen):

- Delete the `_ascii_aware` triplet. Nothing supplies a flag other than
  `s.is_ascii()`, so the parameter is a second representation of a fact the
  function can read itself (DESIGN §2/§3), and the comment on it is the §4b
  inflation case -- a carrier named for a rung the tree does not occupy.
- Bound the ASCII test by the requested position instead of by the whole
  string. A leading run of ASCII bytes makes the byte offset equal the
  code-point offset, so `char_at` examines `bytes[..=pos]` and `substring`
  examines `bytes[..end]`, never the tail. Cost drops from
  O(n) + O(pos) to O(min(pos, n)) -- the fallback's own cost. Semantics are
  unchanged: where the old form fell back to `chars()` because the STRING
  contained a multibyte char, the new form takes the byte path only when the
  PREFIX up to the requested index is ASCII, which is exactly the condition
  under which byte index equals code-point index.
- Route the interpreter's `native_len` `Value::Str` arm through
  `v1_rt::string_length` and fix its doc comment, which named the deleted
  helper.
- Delete `gunbc.char_at_scaling_probe_support`. Its `DissolutionCondition`
  names `src/v1/stage0/src/bin/char_at_scaling_probe.rs`, deleted by #9160,
  and its trigger is "when char_at's O(1) property is floor-enrolled" -- a
  property this tree does not have. It is unconsumed (census row in
  docs/plans/unconsumed-module-residue-disposition.md) and its subject is gone.

RESIDUAL, DECLARED RATHER THAN CLAIMED CLOSED: a left-to-right walk of a
string is still O(n^2), now with a smaller constant rather than a different
shape. A single call cannot be O(1) without the whole-string ASCII fact, which
needs a carrier on the string value; that carrier -- or a cursor surface that
does not re-index from zero -- is this class's next-rung trigger, and it is
recorded in the `char_at` doc comment rather than left to be rediscovered.
This change lowers no rung: the deleted split was inert, so nothing it
guaranteed is lost.

Evidence: dag/test/claim/char_at_unicode_witness_test.dag (SubstrateInputsOnly,
floor-routed) gains the discriminating control for the prefix-bounded path --
"ab" + U+00E9 + "c" is 5 bytes and 4 code points, so a byte-offset
implementation returns U+00A9 at index 3 and "c" at index 4 where code-point
indexing returns "c" at 3 and "" at 4, with the same split applied to
`substring`.

* Regen: converge v1_compiler_runtime_rust.rs with the edited runtime_rust.dag authority (pass 1)

Pass 1 of the stage0 two-pass convergence. `--required-regen` regenerated
`v1_compiler_runtime_rust.rs` -- the stage0 transliteration of
`src/v1/runtime_rust.dag` -- from the edited authority; this installs that
candidate byte-for-byte. `v1_rt.rs` is emitted BY this mirror, so its pass-1
candidate was still the old `_ascii_aware` text and converges only on pass 2,
after a rebuild against the mirror installed here.

* Drop the substring assertion: its RED was never observed, so it is not coverage

The witness gained three assertions for the prefix-bounded fast path. Two of
them are demonstrated discriminating: with `char_at`'s prefix check removed and
the binary rebuilt from scratch (perturbation confirmed present in source),
`char_at_agrees_across_the_ascii_prefix_boundary`,
`char_at_past_the_multibyte_char_is_not_a_byte_offset` and the pre-existing
`char_at_indexes_code_points_on_multibyte_text` all go RED.

The third, `substring_agrees_across_the_ascii_prefix_boundary`, does not. Its
own perturbation -- `if bytes[..out_end].is_ascii()` replaced by `if true`, so
the byte-slice path is taken unconditionally -- left it GREEN, twice, the
second time with the binary deleted first, the build failure-checked rather
than piped through `tail`, and the edit grep-proven in source. A follow-up
probe that would have printed the returned values panicked in `cli_run.rs` on
BOTH arms, so it measured nothing: identical output across arms is the
signature of an instrument that did not run, not of agreement.

So the mechanism is unexplained. What is NOT in doubt is the assertion's
status: a check whose RED has never been observed is not evidence, and
shipping it would put it in the worst class DESIGN §4b names -- permanently
green as far as anyone can show, and cited as coverage precisely because it is
named after the thing it does not test. It is removed rather than kept with a
caveat, because a caveat in a PR body does not travel with the test.

The `substring` code change stands: it is the same prefix-bounding as
`char_at`, semantics-preserving by the same argument (the byte path is taken
only when the prefix up to the requested index is ASCII, which is exactly when
byte index equals code-point index), and substring is exercised heavily by the
existing corpus. What it does not have is a discriminating control of its own,
and the witness note now says so in the module rather than leaving a reader to
infer coverage from the file's name.

OPEN QUESTION, recorded rather than routed around: `substring(s, 0, 3)` on
"ab" + U+00E9 + "c" under the unconditional byte path slices `s[0..3]`, which
lands inside the two-byte U+00E9 and should panic on a non-char-boundary. It
did not. Either that path is not reached by a named-argument `.dag` call, or
the panic is absorbed somewhere between the interpreter arm and the claim
runner's exit status. The second would be the more serious finding -- a witness
that cannot go red because failures are swallowed would affect every witness,
not this one -- and it is worth its own lane.

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant