Skip to content

Give the infer-semantics witness bin the TypeEnv field it has been missing, so cargo build --bins stops failing on main - #9205

Merged
briansrls merged 1 commit into
mainfrom
fix/infer-semantics-witness-typeenv
Aug 25, 2026
Merged

briansrls merged 1 commit into
mainfrom
fix/infer-semantics-witness-typeenv

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Aug 25, 2026 •

Copy link
Copy Markdown
Contributor

A declared [[bin]] does not compile on main

src/v1/stage0/Cargo.toml declares [[bin]] infer_semantics_witness, and cargo build --bins fails:

error[E0063]: missing field `authored_import_names` in initializer of `TypeEnv`   x6
  src/v1/stage0/src/bin/infer_semantics_witness.rs at 317, 1040, 1068, 1096, 1226, 1929

Both files involved are byte-identical to origin/main — the bin, and v1_compiler_infer_env.rs where TypeEnv is declared — so this is determined entirely by main's own content.

TypeEnv is generated (from 04_env.dag) and gained authored_import_names. This bin is hand-authored Rust, and its struct literals fell behind.

Why nothing caught it

This is the class DESIGN's 2026-08-25 row declares — no required phase compiles the Rust workspace — but by a mode that row does not enumerate.

The .dag side is entirely clean: 04_env.dag compiles, the generated mirror compiles, the corpus compiles at 0 blocking. What drifted is a hand-authored Rust consumer of a generated type, which nothing in the .dag world can observe. CI has no cargo build, no cargo test (removed 2026-07-11), and no clippy (removed 2026-07-08).

It also survives the incoming required-job split: #9203's sibling work builds exactly the two bins the jobs run, not --bins. That PR states the boundary rather than widening it, which is correct — widening the required check is an operator decision, and it would land red on a defect that change did not cause. This PR is the separately-filed repair that boundary asks for.

The value, and the wrong one I tried first

authored_import_names: Rc::new(im::HashMap::new()),

matching this bin's own idiom for its sibling map fields (bindings, str_bindings, …).

Not v1_rt::rc_empty_map::<String, bool>(), which is what the library modules use (v1_compiler_infer_env.rs:163, v1_compiler_emit.rs:583) and what I tried first. v1_rt is not in scope in a bin crate root, so that attempt traded six E0063 for six E0433. Recorded because the sibling-file idiom looks obviously correct and is not — the fact that a construction is used elsewhere in the crate says nothing about whether its path resolves from a bin.

Receipt — by execution, not by the edit looking right

cargo build --release --bins   ->  EXIT=0, infer_semantics_witness linked (15,965,168 bytes)
./infer_semantics_witness      ->  runs to completion, EXIT=0

The bin is silent on success and carries 126 assert / panic! / process::exit sites, so exit 0 is its passing verdict rather than an absence of checking. That distinction is the point: a bin that merely linked would prove nothing.

Not claimed

That the witness's assertions are the right ones, or that an empty authored-import universe is semantically what each of the six call sites wants. This restores a declared bin to compiling and passing. It does not audit what it asserts, and it does not close the class — only a required phase that compiles the workspace does that.


WHAT THE SIX EMPTY MAPS CLAIM, STATED BECAUSE THE BYTES DO NOT SAY IT

This fix fills a TypeEnv field, authored_import_names: Rc<im::HashMap<..>>, with an empty map at six construction sites. An empty map here is a claim that THIS WITNESS DOES NOT MODEL AUTHORED IMPORTS. It is NOT a claim that the modules under test have no imports. The two are the same bytes and this sentence is the only thing separating them.

That distinction is load-bearing rather than pedantic. v1_compiler_infer_lookup author_named_visibility returns a three-valued answer — AuthorNamedThisName | AuthorNamedNothingForThisName | VisibilityUnobservable — and synthesizes the third state from emptiness, if map_is_empty(authored_import_names) { VisibilityUnobservable }. The carrier is two-valued at that grain and the answer is three-valued, so observed, and the author named nothing and nothing populated this are indistinguishable. A reader who takes these six lines as "no imports" has read a claim of UNOBSERVABLE as a claim of NONE. Mechanism identified by snappy-dove-250, who owns that seam.

WHY THE EMPTY MAP IS INERT HERE, AT THE DEPTH ACTUALLY CHECKED. author_named_visibility has exactly one consumer, callable_lookup_over_candidates, reached from exactly one caller, lookup_func_sig. This bin references neither. Its surface into the inference crate is narrow and enumerable: it calls annotate_pattern_parent_enums (the only v1_compiler_infer entry point it uses), plus lookup_structural_method, pattern_subject_from_node, lookup_variant_in_type, check_match_exhaustiveness, check_index_access_node and keyed_collection_parts. Of the nine functions in v1_compiler_infer that do contain a lookup_func_sig call, none is among them, and annotate_pattern_parent_enums's own direct callees contain none of them either.

WHAT THAT ARGUMENT DOES NOT COVER, SAID PLAINLY: it is two hops from the bin, not a full transitive closure — I did not walk every descendant of resolve_pattern_subject or lookup_variant_in_type. The claim is that no direct or one-hop path reaches the field's only reader, not a proof that none exists at any depth.

AND ONE ARGUMENT THAT WAS HERE AND IS WITHDRAWN, because a wrong leg is worse than a missing one. An earlier revision of this section also claimed the field's reader sits behind name_resolution_policy_is_namespace_only(), "a thread-local that is false unless armed host-side". THAT IS FALSE. v1_rt.rs declares it Cell::new(true) — namespace-only is the PRODUCTION policy, ratified 2026-07-21, and false is the bracket. I misread it because the comment saying "default false = production fail-open path" sits immediately after that function's closing brace and heads the next declaration, TYPE_REF_HIT_NE_BIND_MEASURE, whose own first words name it as the N1a measurement arm. Prose attached to the wrong subject, believed because it was adjacent — §4c with a bill attached. Caught by snappy-dove-250. The inertness argument now rests on the structural leg alone.

What this PR does NOT do is decide what the field SHOULD contain. That is a semantic question on snappy-dove-250's side of the proof/semantics seam, and filling it in on the theory that empty is neutral is exactly the move this section exists to refuse.

…ssing, so cargo build --bins stops failing on main

src/v1/stage0/Cargo.toml declares [[bin]] infer_semantics_witness, and it
does not compile:

  error[E0063]: missing field `authored_import_names`
                in initializer of `TypeEnv`      x6
  at 317, 1040, 1068, 1096, 1226, 1929

TypeEnv is generated (v1_compiler_infer_env.rs, from 04_env.dag) and gained
authored_import_names; this bin is HAND-AUTHORED Rust and its struct
literals fell behind. Both files are byte-identical to main, so `cargo build
--bins` fails on main today.

WHY NOTHING CAUGHT IT. This is the class DESIGN's 2026-08-25 row declares --
no required phase compiles the Rust workspace -- but by a mode that row does
not enumerate. The .dag side is clean: 04_env.dag compiles, the generated
mirror compiles, the corpus compiles. What drifted is a hand-authored Rust
consumer of a generated type, which nothing in the .dag world can observe.
CI has no cargo build, no cargo test (removed 2026-07-11) and no clippy
(removed 2026-07-08), and cool-hawk-324's incoming required job builds
exactly the two bins the jobs run, not --bins -- a boundary that PR states
rather than widens, correctly, since widening the required check is an
operator decision.

THE VALUE IS Rc::new(im::HashMap::new()), matching this bin's own idiom for
its sibling map fields, NOT v1_rt::rc_empty_map -- which is what the library
modules use and what I tried first. v1_rt is not in scope in a bin crate
root, so that attempt traded six E0063 for six E0433. Recorded because the
sibling-file idiom looks obviously correct and is not.

RECEIPT, by execution rather than by the edit looking right:

  cargo build --release --bins   ->  EXIT=0, infer_semantics_witness linked
  ./infer_semantics_witness      ->  runs to completion, EXIT=0

The bin is silent on success and carries 126 assert/panic/exit sites, so
exit 0 is its passing verdict rather than an absence of checking.

NOT CLAIMED: that the witness's assertions are the right ones, or that an
empty authored-import universe is semantically what each of the six call
sites wants. This restores a declared bin to compiling and passing; it does
not audit what it asserts.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DRMbwdtHZxTiMNZD5WLS3P
gunbai-bot Bot pushed a commit that referenced this pull request Aug 25, 2026
witnesses.yml builds 2 of the 16 bin targets v1-compiler declares, so 14 are absent from the
build selection and nothing required compiles them. Combined with the Rust suite removed from CI
2026-07-11, clippy 2026-07-08, and the compile-clean gate deleted in the floor cut, a bin can go
stale silently -- and one had: #8952 added authored_import_names to TypeEnv without updating
infer_semantics_witness, leaving main red at 'cargo check -p v1-compiler'. That specimen is being
repaired separately in #9205; this is the standing that stops the next one.

Two populations were answered by one roster:
  RuntimeArtifactPopulation -- the executables this job RUNS (claim_executor, gunbc)
  BinaryCompilePopulation   -- every bin target the manifest DECLARES
witness_floor_required_bins is correct as the first and is left alone.

Derived, not a second roster: the step calls repo_self_build_command(bins: []), whose no-selector
form gunbc.repo_self_build already documents as cargo's meaning for 'build every target'. A new
[[bin]] joins the standing with no edit anywhere, and no new argv word is minted.

Build rather than check, decided by measurement: from a cold target dir with the two-bin build
already paid, building every target cost 12s against 52s for 'cargo check --release --bins', and
it additionally links.

Placed LAST, after the fold and the roster uploads, guarded by !cancelled(): ahead of the fold it
would be a preparation mask, and an auxiliary compile error would take the floor's ledger with it.
@gunbai-bot

gunbai-bot Bot commented Aug 25, 2026

Copy link
Copy Markdown
Contributor Author

REVIEW (manager, smart-ram-730) — no blocking defect.

The build break is real and this closes it: TypeEnv gained authored_import_names and five hand-written literals in this bin did not, so cargo build --bins fails on main. Every added value is Rc::new(im::HashMap::new()), matching the empty initialisation of every sibling map field, so nothing here changes what any witness asserts.

ONE FOLLOW-UP, NOT A BLOCK, because it is the reason this PR exists rather than a defect in it. Three of the five patched sites — the optional_match_exhaustiveness_* trio — are now byte-identical to the body of empty_type_env(), which is defined at the top of this same file and already called 13 times in it. Those three edits were only necessary because the sites hand-rolled a constructor that was sitting right there.

That is the §5 tell: the invalid state (a literal missing a field) stayed writable, so the field addition had to be re-applied by hand at each site, and it will have to be again on the next field. Collapsing those three to empty_type_env() makes the class unwritable at those sites rather than re-caught by the compiler every time. The remaining two carry non-empty bindings and genuinely need a literal.

Not asking for it here: main is broken and this unbreaks it at the right grain.

— sent from smart-ram-730

@briansrls
briansrls merged commit fa31aae into main Aug 25, 2026
1 check passed
@briansrls
briansrls deleted the fix/infer-semantics-witness-typeenv branch August 25, 2026 19:06
gunbai-bot Bot pushed a commit that referenced this pull request Aug 25, 2026
…ted-symbol row, take main's updated emit-stage row
briansrls pushed a commit that referenced this pull request Aug 25, 2026
…ch was masking this branch's test-target observation
briansrls pushed a commit that referenced this pull request Aug 26, 2026
…9196)

witnesses.yml builds 2 of the 16 bin targets v1-compiler declares, so 14 are absent from the
build selection and nothing required compiles them. Combined with the Rust suite removed from CI
2026-07-11, clippy 2026-07-08, and the compile-clean gate deleted in the floor cut, a bin can go
stale silently -- and one had: #8952 added authored_import_names to TypeEnv without updating
infer_semantics_witness, leaving main red at 'cargo check -p v1-compiler'. That specimen is being
repaired separately in #9205; this is the standing that stops the next one.

Two populations were answered by one roster:
  RuntimeArtifactPopulation -- the executables this job RUNS (claim_executor, gunbc)
  BinaryCompilePopulation   -- every bin target the manifest DECLARES
witness_floor_required_bins is correct as the first and is left alone.

Derived, not a second roster: the step calls repo_self_build_command(bins: []), whose no-selector
form gunbc.repo_self_build already documents as cargo's meaning for 'build every target'. A new
[[bin]] joins the standing with no edit anywhere, and no new argv word is minted.

Build rather than check, decided by measurement: from a cold target dir with the two-bin build
already paid, building every target cost 12s against 52s for 'cargo check --release --bins', and
it additionally links.

Placed LAST, after the fold and the roster uploads, guarded by !cancelled(): ahead of the fold it
would be a preparation mask, and an auxiliary compile error would take the floor's ledger with it.

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
gunbai-bot Bot pushed a commit that referenced this pull request Aug 26, 2026
…ugh the grammar (#9242)

* Split the required run into two parallel jobs, and correct the ruling the split supersedes

The required run's four phases are mutually independent and were also SERIAL,
because one process runs them one after another. That is the expensive
combination: the witness floor costs ~30-40 minutes and every other phase waited
behind it for no reason a data dependency names, so the required check's wall
clock was a SUM of things that could have been a MAX.

Operator ruling 2026-08-25 ("we can add it as a parallel job in github actions -
we can do the same for regen now, we have more runners" / "basically i would put
regen + v2 full compile in one job, and witnesses into another one"). Two jobs,
no `needs` edge:

  build      regen first-generation comparison + the v2 emission compile
  witnesses  the .dag parse sweep + the witness floor fold

Each job makes ONE invocation of claim_executor and names a LANE. It does not
name phases, order them, or wire one phase's precondition to another step's
outcome -- which phases a lane owns is `RequiredCiPhase::lane`, an exhaustive
match, so a phase belonging to no job fails to compile rather than going
silently unmeasured. Every run prints a ROUTED line for each phase it does not
own, so one job's log names the whole roster and where the rest is measured.

THE 2026-08-20 CONSOLIDATION DIRECTIVE IS CORRECTED, NOT SILENTLY CONTRADICTED.
It has two halves and only one is superseded. SURVIVES -- "within the gunbc
binary": the phases still live in the binary and the step-ladder defect the
consolidation fixed cannot return. SUPERSEDED -- "not at a github actions job
level": parallelism is not expressible in one process, so the lane boundary is a
job boundary of necessity, and what the directive protected against (sequencing
and preconditions leaking into YAML) is exactly what does not cross it. Both
halves are now stated in DESIGN's CI clause, in `gunbc.fabric_witness_run`, in
`gunbc.witness_floor_workflow` and in the consolidation witness file.

THE v2-EMISSION SUBJECT WIDENED in the same change, from `dag/std/abi.dag` to
`src/v2/compiler/00_compile.dag`. The cost that argued for the smallest entry
was a cost against a SERIAL run; the build lane's cost is now free up to the
floor's duration. Measured by emitting both closures and differencing the file
sets, the widening gives up exactly one file of coverage, `src/std_abi.rs`, and
the row says so rather than claiming total subsumption.

Executed evidence:
  - both lanes run, and route correctly: `lane=witnesses` runs parse and floor
    and routes regen and v2-emission; `lane=build` runs regen and v2-emission
    and routes parse and floor
  - an unknown lane word refuses with exit 2, it does not default
  - the v2 compiler entry compiles clean under the phase's own producer and
    pinned pool index (0 blocking)
  - six consolidation witnesses pass, including two new ones for the split
  - both new REDs flip under mutation and restore: adding a `needs` edge reds
    the parallel claim; collapsing to one job reds the two-lane claim
  - the lane-command claims verified through a scratch probe with a control
    that returns false

NOT DONE, named rather than absorbed: no ratchet over the v2 compile's advisory
population (a count pinned to the current tree is the oracle DESIGN §5 rejects;
the honest form is an identity-grain monotone debt contract, a separate
construction). Nothing else is restored from the deleted floor machinery. And
the build step still compiles only the two bins the jobs run -- a declared
`[[bin]]` outside that set is uncovered, with a live specimen on main today
(`infer_semantics_witness`, six E0063s); widening to `--bins` changes what the
required check covers and is an operator decision, so it is declared here rather
than taken.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SAQiYQiQ7SsdxvotAFbUFc

* Correct the workflow module's own stale recital of the consolidation directive

The supersession was recorded in DESIGN, in gunbc.fabric_witness_run, in the
consolidation witness file and in the binary's own roster block -- and NOT in the
paragraph inside gunbc.witness_floor_workflow that quotes the 2026-08-20
directive and describes the job as ONE INVOCATION, FOUR PHASES. That paragraph
sits directly above the run step the split changed, so it is the one a reader
reaches first, and leaving it standing would be the premise contamination this
change exists to remove -- one document corrected while its own subject still
recited the superseded ruling in the present tense.

It now states both halves: 'within the gunbc binary' survives, 'not at a github
actions job level' is superseded because parallelism is not expressible in one
process. The step-ladder paragraphs below it are kept rather than rewritten,
because what they establish is unchanged by the split and deleting them would
take the reasoning with them. Also corrected: the step no longer passes 'the
source roots and nothing else' (it passes a lane word), and the phase roster is
four across two lanes rather than the 2026-08-21 three.

Comment-only in emission terms: witnesses.yml regenerates byte-identical.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SAQiYQiQ7SsdxvotAFbUFc

* Make the split fail-closed: the required context now gates on both lanes

Review of #9203 (review 55786, codex/gpt-5.6-sol) found the split fail-open, and
it was right. Verified against the live ruleset rather than against the workflow,
which is the only place the fact is visible: `passing CI` is active, carries NO
bypass actors, and names exactly ONE required status check -- `witnesses`. A
GitHub required context is produced by the JOB, not the workflow, so moving regen
and v2-emission into a second job made them NON-BLOCKING: the required check
would go green over a regen drift or a v2 emission break and the PR would be
mergeable. That is strictly worse than the serial run it replaced, because the
serial job carried every phase into the one context that gates.

THE REPAIR, and why it is an aggregation job rather than a ruleset edit. The
floor lane is renamed `floor`; the name `witnesses` moves to a job whose only
step reads both lanes' results and exits nonzero unless both succeeded. The two
lane jobs still carry no `needs` edge on each other and still start together --
only the aggregator waits, and it does nothing but read two results. A ruleset
edit would also have worked and was rejected on a boundary DESIGN already
records: the ruleset is not a `.dag` fact, so landing a change whose safety
depends on someone editing a setting afterwards is a coverage gap with a promise
attached and a real window in which the lane is unguarded.

`if: always()` IS LOAD-BEARING, and its absence would have been the same
fail-open one level in: a step with no `if` inherits `success()`, so it would be
SKIPPED exactly when a lane failed, the job would report success, and a skipped
required check does not stop a merge.

The aggregator is the only place in this workflow that authors shell text, and
that is stated on the carrier: there is no modeled value to render, because
GitHub has no declarative "this job fails unless those jobs succeeded", and the
nearest declarative form is the skip that fails open. The script is built from
the job-id declarations rather than spelling `needs.build.result`, so a rename
moves both sides together instead of rendering an unknown context as the empty
string.

WITNESS CORRECTION, not just an addition. `w_RED_neither_lane_waits_on_the_other`
asserted the file contained no `needs:` at all -- the right claim for a workflow
shape that was wrong, and a row that would have made this repair unrepresentable.
It now forbids each single-lane edge and REQUIRES the aggregator's two-lane one,
which distinguishes the serialization being forbidden from the aggregation being
demanded. A third row asserts the gate runs and refuses.

Executed evidence: all seven consolidation witnesses pass, and three mutations
red the right rows and restore -- serializing floor onto build reds the parallel
claim, dropping `always()` reds the gate claim, and deleting the aggregator reds
the parallel claim.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SAQiYQiQ7SsdxvotAFbUFc

* The aggregator's guard belongs at the JOB level: a skipped job never reaches its step

Review 55795 and a peer session independently found, within minutes of each
other, that the fail-closed repair was itself fail-open one level in.

`needs` carries an IMPLICIT JOB-LEVEL CONDITION. A job that declares `needs` and
no `if` is SKIPPED when any needed job fails, is skipped, or is cancelled. A
skipped job never starts, so it never reaches its steps, so the step-level
`always()` could not fire -- and a skipped required check does not stop a merge.
The aggregator introduced to close the fail-open would have gone
skipped-and-mergeable over precisely the failed lane it was there to catch, with
the guard present in the file and reading as correct.

`always()` AT JOB LEVEL, AND THIS IS THE ONE PLACE THAT DEPARTS FROM THE FILE'S
`!cancelled()` HOUSE GUARD -- said in the carrier, in DESIGN and in the witness,
because a reader who knows the convention will otherwise correct it back and
reopen the hole. Every other guard here decides whether a STEP runs inside a job
that is already running, where `!cancelled()` is right. This one decides whether
the REQUIRED CONTEXT EXISTS AT ALL, and under `!cancelled()` a cancelled run
leaves it skipped rather than answered. That would turn the outcome on a question
about GitHub nobody here has executed -- does a skipped or cancelled required
check block a merge -- and the response is not to go measure it but to make the
answer not matter. Under `always()` the job always runs, always reads both
results, and always reports on its own terms; SKIPPED disappears from the
required context. Cost, named: a lawfully superseded run now reports this context
red rather than cancelled. That is the correct reading, not a regression -- a
superseded run's evidence must not admit a merge.

THE WITNESS WAS WRONG IN THE SAME WAY AND IS FIXED WITH IT. It asserted
`if: always()` appeared SOMEWHERE in the file. It did -- on the step -- so it
went green over the defect. That is DESIGN's total-at-the-level-examined failure:
true, and about the wrong level. It now discriminates on emitted INDENTATION,
which is the only thing in the text that separates the two levels (a job key at
four spaces, a step key at eight), and asserts both.

Executed: the strengthened row PASSES on the fix and FAILS on a mutation that
removes the job-level guard -- i.e. it catches the exact defect that shipped.
All seven consolidation witnesses pass.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SAQiYQiQ7SsdxvotAFbUFc

* Say what the v2-emission phase actually covers: 24 of 42 compiler modules, measured

Operator clarification, 2026-08-25: "the intention is to v2 build ALL of the .dag
compiler files, and then ratchet THAT count in CI". Measuring against that ask
showed this PR's own prose overclaims, so the claim is corrected before anything
is built on it.

MEASURED, by emitting the entry and joining the emitted file names against the
module line of every src/v2/compiler/**.dag: of the 42 modules under
src/v2/compiler/, 00_compile's closure emits 24. Eighteen are absent, including
ingest, emit_module, emit_host, emit_produced, emit_semantic_decl,
program_partition and self_host. Counting the self_host/ subtree the compiler
namespace is 69 modules, so the shortfall is larger again.

"The widest closure one entry names" was true and is kept; "full v2 compile"
invites the reading that the phase covers the compiler, and it does not. That
reading is exactly the premise contamination this repository keeps paying for, so
the row now states the covered population rather than leaving a reader to assume
it.

AND A METHOD NOTE THAT COST A MEASUREMENT: a static import-closure estimate
CANNOT substitute here. It reports ZERO compiler coverage for this entry, because
this corpus resolves most cross-module references without import lines. Only the
compiler's own reference-derived closure is the truth, which means a covering
entry set cannot be derived from the import graph either -- it has to be measured
by emission.

The widening itself is NOT taken here: it needs either a measured covering entry
set or a whole-tree emission whose cost has to be known before it is enrolled in
a required lane. This row makes that widening a change to a known number instead
of an assumed one.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SAQiYQiQ7SsdxvotAFbUFc

* Receipt: the gate refused two cancelled lanes, and 'abandoned' is a state nobody knew about

Run 32883390033 (2026-08-25) ended BOTH lanes by a fleet event with no push
involved. The aggregator ran anyway under its job-level always(), read the two
results, refused, and published the required context witnesses as a FAILURE. That
is this gate's first executing receipt and it is the behaviour the pre-repair
shape could not produce -- there, the aggregator would have been skipped.

AND THE RUN SURFACED A needs RESULT VALUE NOBODY HERE KNEW WAS REACHABLE:

    BUILD="cancelled"   FLOOR="abandoned"

The gate handles 'abandoned' correctly only because it compares != "success"
rather than enumerating bad states. The form a reader's instinct reaches for --
== "failure" || == "cancelled" -- would have admitted it and reported the
required context GREEN over two lanes that never ran. So the strict inequality is
now recorded on the carrier as a measured fact rather than left as a style
choice, because the obvious 'improvement' to an explicit list is a fail-open.

That is the difference between a closed vocabulary and a remembered one: the
inequality admits exactly one state and refuses every other, including the ones
the author has never heard of.

Comment-only in emission terms: witnesses.yml regenerates byte-identical.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SAQiYQiQ7SsdxvotAFbUFc

* Record the argument against always() beside the decision to keep it

A peer session raised the strongest objection to the job-level always() guard,
from GitHub's documented semantics rather than from a measurement, and it is
correct on every fact it asserts: always() is the one condition that survives
workflow cancellation, cancel-in-progress is armed on every pull_request so this
fires on the MODAL event, and it destroys the cancelled/failed distinction at the
RECORD level where nothing can recover it. That ambiguity cost that session hours
in one day, diagnosing 38 lawful supersessions as a false-red epidemic. The
file's house guard really is !cancelled() everywhere else.

It is not taken, and the reason is an asymmetry about WHICH HEAD PAYS. Checks are
tracked per head SHA, so a superseded run's red lands on a head that by
construction is never merged -- the push that superseded it created the head that
will be. always() is noisy on ABANDONED heads. !cancelled() moves the cost onto
the LIVE one: a lane killed with no replacement run coming, observed twice on
2026-08-25 (once with runner_name empty and zero steps, once with both lanes
ended at 18:43 and no push involved), leaves the required context SKIPPED on the
head that is still the merge candidate -- which is precisely the unmeasured
GitHub behaviour the guard exists to stop depending on.

Quiet-and-unknown on a live head is worse than loud-and-definite on a dead one.

The mechanism half of the objection is now MEASURED rather than documented: run
32883390033 had both lanes ended by a fleet event, and this job published
failure while the run conclusion was cancelled. So the behaviour the objection
predicts is real; what is disputed is only whether it is the wrong trade.

Recorded in the carrier rather than answered away, so the next person who wants
!cancelled() finds the case already made instead of rediscovering it.

Comment-only in emission terms: witnesses.yml regenerates byte-identical.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SAQiYQiQ7SsdxvotAFbUFc

* One compilation transaction, subject-parameterized; the gate emitted as nodes

Four things, in the order the operator's dispatch puts them.

ONE. The build lane bootstraps `cargo build --release -p v1-compiler --bins`.
Host-Rust coverage of the whole declared bin roster is a fact somebody has to
establish, and a bin no consumer selects is precisely the one that rots
unobserved -- #9205 repaired one such bin after it had drifted with nothing
building it. The floor lane keeps the two bins it executes; the lanes are
runtime-independent, so their bootstraps are independent CPU rather than a
shared prerequisite one could save.

TWO. THE DAGLANG COMPILATION FORK IS CLOSED. `cli_run` now carries
`CompileSubject{Entry|PrimaryRoot}`, `CompileRequest` and `compile_emission`,
and the transaction owns indexing and precedence, subject source-set
construction, census fill, memory admission, resolution and compilation, the
blocking/advisory split, silent-pick capture and the disposition.
`compile_entry_emission` survives as a wrapper with no semantics of its own.

Before this, `gunbc compile` without `--entry` implemented a SECOND
index/load/resolve/admit/compile/refuse pipeline in `main.rs`, beside the
transaction rather than through it. They differed in ways nobody had decided:
the whole-root arm applied the memory-admission gate and the entry arm did not,
the entry arm ran the silent-pick gate inside the transaction and the whole-root
arm ran it around the outside, and their refusal subjects were spelled
differently. That is DESIGN section 3's two-authorities-for-one-fact, and it is
the reason a whole-tree ratchet could not be built on the existing phase: the
ratchet would have observed a different producer from the gate beside it.

The arms' real differences are KEPT, which is why this is a coproduct and not a
flag: admission is asked of the whole root and not of an entry (an entry's
working set is its closure, measured to fit on the runner that SIGKILLed a
whole-tree run -- an unasked question, not an all-clear), and the closure
derivation genuinely differs (reference-derived for an entry, import-edge for a
root where every module is already an entry). A `PrimaryRoot` matching no module
refuses at `subject-discovery` rather than reporting `Completed { 0 }`, which
would be the empty-observation narrow.

THE DELETION WAS THE CENSUS. Routing the whole-root subject through the
transaction left ~200 lines in `main.rs` with no caller, and rustc then found
seven more private copies of module indexing and import walking --
`extract_module_path`, `report_moduleless_dag_entry_skips`,
`extract_import_paths`, `insert_module_path`, `index_source_root`,
`build_module_index`, `resolve_transitively_with_seen`. All deleted; their two
tests re-pointed at the surviving `cli_run` authority rather than retired with
the function, per DESIGN section 4b(4). Multi-target (`--target a,b`) still walks
the old loop and is named rather than exempted.

THREE. `pr_owner` AND `cycle_owner` REFUSED FOR A REASON THAT IS NOT IN
`review_codex.dag`. `owner` has TWO declarations in the flat whole-tree
namespace -- `data owner` in `gunbc.tools.review_codex` and
`fn owner(uid, gid)` in a srv3 path-ownership test -- and the winner is fold
order. When the function won, the CLI defaults resolved to it and refused with
`must be a string, int, float, bool literal, or data reference`: two blocking
diagnostics in a file that had not changed, produced by a test helper in another
directory.

The discriminating pair is what establishes that, and it was measured rather
than reasoned. `repo` is declared beside `owner` in the same module, has no
`fn repo` anywhere in the corpus, and does not refuse. `default_model` IS
declared twice -- `tools.review` and `tools.review_codex` -- and does not refuse
either, because both declarations are data, so either winner satisfies the
default's requirement. Collision alone is not the fault; collision ACROSS
DECLARATION KINDS is. Fixed by renaming the test helper to `owner_spec`.

The class is untouched and the annotation says so: a bare cross-kind homonym is
still writable and still resolves by fold order. Its next-rung trigger is a
refusal at name resolution when one flat name carries declarations of different
kinds -- decidable from the index the compiler already builds -- not a roster of
forbidden names.

FOUR. THE REQUIRED-LANES GATE IS BUILT AS NODES, NOT SPELLED AS TEXT.
`gunbc.required_lanes_gate` constructs it through
`v2.extdeps.languages.bash_build` and `witness_floor_workflow` serializes it
through `v2.workflow.bash_command_fold_serialize` -- the
`tools.build_step` -> `v2.workflow.build_step_emit` precedent. Raised as review
55836's medium-as-string finding, which was correct: I had argued no modeled
value existed to render, and the language was fully modeled the whole time.
Declaring a language-layer gap without enumerating the language is the failure
DESIGN records in its own section 6 receipt.

The Rejected arm REFUSES rather than rendering nothing, because an empty `run`
exits 0 and would make the required context green over two lanes it never read.
The emitted text was executed against all three arms: success/success passes,
success/failure and cancelled/abandoned each print the error and exit 1.

ALSO LANDED, NOT YET WIRED: `gunbc.v2_rustc_debt` models the monotone identity
ledger -- key (emitted-crate-relative path, rustc code), admission iff observed
equals the current ledger AND the current ledger is a multiplicity-wise subset
of the baseline's -- with eleven fixture arms that author both input and
expectation. Both totals are receipt-only and reach no verdict. Its host
observation is deliberately absent: an observer built before a whole-tree
emission can be produced would be an observer with no subject.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SAQiYQiQ7SsdxvotAFbUFc

* The subject is a field, the precedence root is a refusal, and the fork is three callers wide

FOUR CORRECTIONS, three of them from an operator ruling on the measured report
and one from the census that ruling asked for.

ONE. THE ALIAS DIRECTION WAS BACKWARDS. It read
`pub type CompileRun = EntryEmissionRun`, which makes the generic name an alias
of the entry-named authority -- so the canonical carrier stays the one named for
a subject it no longer describes, and every reader is sent to a type whose name
contradicts two of its three uses. `CompileRun` and `CompileDisposition` are now
the types; the entry-named spellings are the compatibility aliases that
disappear with their last caller.

TWO. `run.entry` SILENTLY WIDENED TO HOLD A DIRECTORY. A consumer reading it
after a `PrimaryRoot` compile got a root from a field promising a file -- one
name, two meanings, which is the section 3 violation the fork closure exists to
remove, reintroduced one field down. It is now `subject: CompileSubject`, and
the receipt names the ARM rather than the path: `subject=primary-root:src/v2`,
not `subject=src/v2`. The two read identically to a human and differently to
anyone deciding whether a run measured what it was asked for, which is the whole
reason the field exists.

THREE. THE SUBJECT AND THE PRECEDENCE ROOT NOW HAVE TO AGREE, AND DISAGREEING
REFUSES. The trap is entirely in argv order and invisible from the receipt: the
live workflow passes `--source-root dag --source-root src/v2`, and the no-entry
CLI law is `PrimaryRoot(source_roots[0])`, so THAT argv asks for
`PrimaryRoot(dag)` with `src/v2` as a pool. A caller who means "compile v2" and
writes the roots in the workflow's habitual order gets the other subject,
compiles ~2000 different modules, and is told the compile completed.

This is not a scope difference, it is a RESOLUTION difference, and it already
cost a measurement: `dag`-primary refuses on two `review_codex` CLI defaults
that `src/v2`-primary never reaches, and `src/v2`-primary refuses on 36
diagnostics `dag`-primary never sees. The 9.06 GiB peak and the `owner`
diagnostics reported earlier are the `dag` subject; they were reported under a
heading that implied the v2 one. A ledger bootstrapped from the wrong subject is
not a coarser ledger, it is a ledger about another population.

`primary_root_agrees_with_precedence` makes the disagreement unwritable rather
than merely detectable.

FOUR. THE FORK IS THREE PRODUCTION CALLERS WIDE, NOT ONE. The census over
`compile_sources`, `compile_sources_with_options`,
`compile_to_resolved_with_options`, `emit_resolved_for_target` and
`stage0_self_compile_refusal_message` classifies every caller:

  46  compiler_tests / compiler_tests_rust     kernel test, legitimate
   2  v1_probe_emit_interp                     generated kernel probe, legitimate
   2  v1_compiler_emit_rust                    compiler implementation, legitimate
   9  cli_run                                  compile_emission implementation
   5  main.rs                                  DECLARED VIOLATION (multi-target loop)
   2  required_regen_host                      DECLARED VIOLATION (needs ExactSourceSet)
   2  bin/bootstrap_witness                    DECLARED VIOLATION (not previously named)

`bootstrap_witness.rs` compiles EVERY `.dag` file under `dag/` to Rust, which is
exactly the invariant's subject -- a repository source population producing an
artifact tree -- so it is a production route and not a kernel probe. It carries
its own `build_module_index`, `build_module_index_for_roots` and
`resolve_imports_transitively`: a FOURTH private copy of the machinery this
branch deleted from `main.rs`, in a 1289-line binary the floor lane builds and
runs. It can disagree with the transaction about what the `dag/` population IS,
and nothing would say so.

None of the three violations is closed here. They are named, classified, and
ordered: multi-target into the request as a target set, then regen and
bootstrap_witness through an exact-source-set subject, both of which select a
population by their own authority rather than by directory.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SAQiYQiQ7SsdxvotAFbUFc

* Hoist two §4c-illegal in-body annotations, and restore the module-less skip report the consolidation dropped

Two fixes, both of them corrections to my own work on this branch.

§4c: `v2_rustc_debt_ratchet_test.dag` carried two `//` lines INSIDE a `test fn` body.
Only module-item grain is modeled, so strict preparation refused and the build lane
went red on #9242. Hoisted above the declaration. An awk brace-depth census over every
file this branch touches confirms no in-body annotation remains.

Module-less visibility: the deletion note in `main.rs` claimed the module-less-entry
skip report was "the one behaviour with no counterpart" in `cli_run`. That was FALSE --
`report_moduleless_dag_entry_skips` and `moduleless_dag_entry_paths` are both `pub`
there with tests, and were never deleted. The note asserted an absence without grepping
for it, which is the one claim a later reader will not re-check.

The behaviour is now wired into the transaction's `PrimaryRoot` arm through those same
two functions. It matters there specifically: the subject is discovered from
`index.source_files`, keyed by module path, so a `.dag` under the root with no `module`
declaration is absent from the subject and the transaction would report `Completed`
over a population that silently excluded it. The empty-root refusal cannot catch this,
because a root holding one good file and one forgotten one is not empty.

It REPORTS rather than refuses, declared as the weaker arm: a module-less `.dag` is a
legitimate parse fixture today, so refusing would break real callers. Terminal form is
a total role classification under which an unclassified `.dag` refuses.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SAQiYQiQ7SsdxvotAFbUFc

* Route multi-target compiles through the one transaction, validate all three debt populations, and read the verdict as itself

Six review findings, each fixed rather than answered.

MULTI-TARGET REGRESSION (blocking). `--source-root X --target rust+dag` fell past the
routing gate -- which conjoined the subject with `render_targets.len() == 1` -- into a
branch whose only remaining subject is `--source-dir`, and exited "provide --source-root
or --source-dir" over an argv that provided one. `CompileRequest` now carries a target
VECTOR: resolve once, emit per target, and materialize NOTHING until every target has
completed, so one target's tree is never left on disk beside another's refusal. The
disposition, the blocking count and the refusal are over the whole emission set, not the
first target. Single-target callers -- every required one -- run the identical
computation, because `compile_sources_with_options` IS
`emit_resolved_for_target ∘ compile_to_resolved_with_options`.
Two discriminating arms: two targets produce two named emissions from one resolution,
and a request naming NO target refuses at its own `target-admission` phase rather than
reporting `Completed { emitted_count: 0 }`.

DEBT LEDGER FAIL-OPEN (blocking). Positivity and uniqueness were asked of the LEDGER
only. A duplicated key in the OBSERVATION makes the multiplicity lookup answer with
whichever row the fold reaches first, so the comparison silently compares the wrong
quantity and the run reads as held. All three populations are now validated -- positivity,
uniqueness, and strictly ascending canonical order -- through one
`DebtPopulationMalformed { population, cause, keys }`, with `population` a closed
coproduct because the three have different owners and different repairs. Order refuses
rather than sorts: sorting would make two textually different ledgers compare equal and
stop a ledger diff being reviewable.

THE BLIND-SPOT FIXTURE AUTHORED NO SUBSTITUTION. It passed `one_error()` on both sides
and CLAIMED in prose that the two were different errors, which made it a tautology
wearing a substitution's name. It now authors `SyntheticRustcDiagnostic` values carrying
a latent site, asserts FIRST that the two populations differ, and then that bucketization
erases the difference.

NO BOOLEAN COLLAPSE OF THE VERDICT (review 55911). `rustc_debt_verdict_admits` matched
every variant and returned one bit, so a consumer refusing on it prints "the ratchet
refused" and the author re-derives the cause by hand. Deleted. Every test arm now asserts
WHICH verdict, which is strictly stronger: an arm authored to provoke
`LedgerExceedsBaseline` used to stay green when the contract refused it as malformed for
an unrelated reason.

VOCABULARY. `admitted_multiplicity` -> `multiplicity`; `identities` -> `buckets`, in the
model, the receipt and the test names -- the count is per (path, code) bucket and calling
it an identity is the inflation the blind-spot arm exists to deny.

RENAME FINISHED. The entry-named aliases are deleted, not merely re-pointed; two
spellings for one type is the same §3 violation one layer out.

Also: the census behind "one compilation concept" is now stated at CALL-SITE grain with
its forks named, the `CompileSubject` comment no longer calls the import walk "the
authority" (it under-pulls by construction -- the namespace is flat -- and the census fill
covers the difference), the precedence check declares its rung and its terminal
`SourcePool` form, and a `TypeEnv` field missing at one test site is filled so
`cargo test --lib` builds at all.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SAQiYQiQ7SsdxvotAFbUFc

* Build the unrenderable-gate refusal from the Bash grammar too, and split the unwired debt model out of this PR

Review 55923, both findings, neither deflected.

THE RAW SHELL FALLBACK IS DISSOLVED, NOT MARKED. `required_lanes_gate_unrenderable_script`
was an executable program spelled as a String and handed to a RunStep -- the
medium-as-string violation this PR otherwise removes, surviving in the one arm nobody
reads, inside the module whose own header argues against exactly that. The refusal is now
Nodes in `gunbc.required_lanes_gate`, beside the gate it stands in for, serialized through
the same fold.

The outcome is three-state rather than two, and the third state is what removes the last
fabricated value: the gate serializes -> the gate; the gate rejects but the refusal
serializes -> the refusal, which stops every run loudly; both reject -> Absent, and
`expected_witness_floor_yml` returns `WitnessFloorGenerationRefused` so no yaml exists at
all. A Rejected fold can no longer reach a published step. The one remaining `""` is not a
program and is reachable only when emission has already refused -- Daglang is total, so
some value must inhabit the arm; what matters is that it is not a second spelling of a
shell program and that no emission path reaches it.

Verified rather than asserted: `required_lanes_gate_is_renderable` returns true by
execution, and regen exits 0 with the workflow yaml BYTE-IDENTICAL -- only the unreachable
arm moved.

ON THE "on-carrier bash-emission scaffold marker": no such convention exists in this tree.
A whole-tree search finds no `bash_emission`, `hand_shell` or `model_vs_runner` carrier.
Removing the raw string makes the marker moot either way, which is the stronger repair.

THE DEBT MODEL LEAVES THIS PR. `dag/gunbc/v2_rustc_debt.dag` and its fixture are removed
and travel to the change that lands their consumer. The earlier review from the same
provider offered keeping this PR open as the integration vehicle and I took that; a
measurement since has changed the calculus. A whole-repo emission REFUSES ON MEMORY
ADMISSION on the current runner class -- measured on BuildBuddy: budget 6.58 GiB against
the modeled 7.00 GiB demand, `WholeCorpusCompileBudgetBelowMeasuredDemand`, zero files
emitted. So the observer cannot be built until the resource-grant boundary is decided, and
that decision is the operator's. Holding a foundational compilation PR open behind someone
else's decision is worse than either option the review named.

What remains here is the compilation consolidation and the gate repair: coherent, with
consumers, mergeable on its own.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SAQiYQiQ7SsdxvotAFbUFc

* A target name carried beside its target can disagree with it; derive it. And the fork census omitted a fork

Two remarks from the side-channel review, both verified against the code, both real.

THE (NAME, TARGET) PAIR IS COLLAPSED TO A TARGET. `CompileRequest.render_targets` carried
`Vec<(String, RenderTarget)>`, so `("dag", RenderTarget::Rust)` was constructible: two
spellings of one fact, free to disagree, with the NAME deciding which directory a target
is written to while the TARGET decided the bytes written into it. That is the §3 violation
this transaction exists to remove, reintroduced one field down and in the same PR that
removes it elsewhere. The name is now DERIVED through `render_target_name`, which is the
CLI parse's inverse, so the disagreement has no representation rather than being checked
for. `parse_render_targets` discards the authored spelling deliberately, because it is
recoverable.

THE CALL-SITE CENSUS OMITTED `required_regen_host`. `compile_stage0` calls
`compile_sources` directly over `regen_input_sources` -- a fourth fork, and the census
whose entire purpose is to enumerate forks reported it as absent. The file appeared in the
file-level count I ran and did not survive into the call-site list I wrote from it, which
is the incomplete-enumeration class this repository has recorded against itself twice
before: a list transcribed from a wider measurement is not the measurement. It is now
listed with its subject (an EXACT SOURCE SET from the regen roster -- neither a root nor an
entry, so neither existing subject describes it), its terminal form, and the hardcoded
refusal subject it still passes. The omission is recorded in the census itself rather than
quietly corrected, because a census that has been wrong once should say so.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SAQiYQiQ7SsdxvotAFbUFc

* The refusal arm the PR defends was the wrong shape, and nothing executed could have caught it

Review 55928, plus four findings from the thread review that survive at this head.

THE MIDDLE RUNG WAS DEAD. `required_lanes_gate_unrenderable_stmts` was declared
`-> List<Node>` and returned `bash_build_stmt_list_from_nodes(...)`, which is a single
`Node`. Its caller passes it as `stmts: List<Node>`. So the arm this PR argues must stay
executable -- gate rejects, the refusal still serializes, the run stops loudly -- was the
wrong shape in exactly the place the argument is about, while the in-file receipt said it
was Nodes through the same fold. Returns the raw list now, like `required_lanes_gate_stmts`
beside it.

THE REASON IT WAS POSSIBLE IS THE REAL REPAIR: the claim lived in prose, so nothing could
contradict it. `the_unrenderable_gate_refusal_serializes_and_stops_the_line` now runs the
fold over the refusal and reads the program back -- it must serialize, and must carry both
the `::error::` annotation the operator sees and the `exit 1` that stops the line.

THE CONTROL FLIPS, MEASURED RATHER THAN ASSUMED. Fixed shape: true. Defect restored:
`PatternMatchFailure`, the fold choking on a Node where the list belonged. ONE HONEST
QUALIFICATION: the red arrives as a RUNTIME ERROR, not a returned false, which is a weaker
red than a clean false -- an erroring probe stops rather than asserting anything about its
subject. Recorded because "the control flips" alone would overstate it.

DUPLICATE TARGETS REFUSED. `--target rust+rust` parses to two targets, and each emission's
directory is derived from the target, so both land in `output_dir/rust` -- the second
overwriting the first while the run reports two completions. Refused at `target-admission`,
not deduplicated: collapsing it silently answers a request nobody made and destroys the
signal that the argv is wrong.

THE MODULE-LESS WALK NO LONGER DROPS READ FAILURES. `if let Ok(content)` narrowed "every
`.dag` under the root" to "every READABLE one" while still reporting under the wider name --
the empty-observation narrow inside the population whose entire job is to report what got
dropped from the subject. Now a typed refusal at a `subject-read` phase.

DOCUMENTATION THAT LIED. The root-order ruling sat immediately above
`names_at_least_one_target`, so Rust attached the precedence contract to target admission;
moved. "One entry, one render target" and "One entry's emission transaction" corrected
beside code that handles two subjects and a target vector. The alias note's history example
read `pub type CompileRun = CompileRun`, which is not a direction. And "reference derivation
is not used here and that is not an oversight" sat directly above the fixpoint call that
falsifies it -- it is used, because an import edge is weaker than a reference in a flat
namespace and the walk under-pulls across the pool boundary.

Regen exits 0 with no artifact drift.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SAQiYQiQ7SsdxvotAFbUFc

* Restore the entry-scope marker as a typed receipt: I deleted a consumer's evidence while tidying a sentence

Three findings from the thread review, verified against the code before acting.

THE SCOPE MARKER WAS MINE TO LOSE AND I LOST IT. Main prints "resolved N sources
(reference-derived closure), M indexed modules"; consolidating the two CLI pipelines into
one generic line dropped the parenthetical. It existed at the merge-base, so this is a
regression on this branch and not a collision. `gunbc.emit_diagnostic_observation`
`emit_entry_scope_marker` (landed on main via #9190, AFTER my change) matches that exact
text and returns `EmitScopeUnconfirmed` when it is absent -- specifically so a whole-root
compile cannot be reported as one entry's measurement. Merging main unchanged would have
made every per-entry emission measurement refuse, from an edit that reads as prose cleanup.

RESTORED AS A VALUE, NOT AN ADJECTIVE. `CompileScopeReceipt` is derived from
`CompileSubject`, so the receipt cannot disagree with the run and cannot be lost by
rewording. The entry arm carries the marker; the primary-root arm now STATES what it
measured instead of being silent, so a consumer no longer has to infer scope from argv or
file counts. The Rust literal and the `.dag` `data` row are two spellings of one fact --
unavoidable while that authority is `.dag` and this seed cannot read it -- so the constant
is named `EMIT_ENTRY_SCOPE_MARKER` and cites its authority, making the pair greppable.

THE TEST ASSERTS BOTH HALVES. Marker present on the entry arm, ABSENT on the primary-root
arm. A receipt that carried it on both would be worse than one that carried it on neither:
the marker exists to make the substitution refusable.

THE PANICKING TRAVERSAL. My earlier "typed refusal" fixed the per-FILE read and left the
DIRECTORY walk calling `collect_dag_files`, which is
`collect_dag_files_result(..).unwrap_or_else(|e| panic!(..))`. A missing root, a regular
file as root, or any `read_dir` failure bypassed `CompileDisposition` entirely. That was
half a repair wearing the whole one's name; the walk is fallible now.

TARGET ADMISSION ORDERING, PROVEN RATHER THAN ASSERTED. The new arm passes a subject that
CANNOT be discovered, so if the duplicate-target refusal came after subject discovery the
run would refuse at `entry-read` instead and the arm would fail. It proves the ordering,
not merely the refusal.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SAQiYQiQ7SsdxvotAFbUFc

* The all-or-nothing materialization proof, with a RED that is actually authorable

The CLI writes a tree only after the AGGREGATE disposition is `Completed`, so one target's
refusal must withhold another target's finished files. That claim was asserted by the arm's
structure and by nothing executable.

BEFORE WRITING THE TEST I CHECKED WHETHER ITS RED CAN BE PRODUCED AT ALL, because a check
whose red is unauthorable is a decoration -- permanently green by construction and worse than
absent, since it gets cited as coverage (DESIGN §4b). It can: `file_emission_refusal` applies
`target_renders_file_transport` FIRST and separately from `file_binding_refusal`, and that
gate answers `Rust => true` with Python, Go and Dag all false. So a WELL-FORMED file-transport
operation emits clean on Rust and refuses `FileTargetNotModeled` on Go.

MEASURED on the new fixture root before any assertion was authored: `--target rust` emits 7
files with 0 diagnostics; `--target go` refuses, naming target 'go' and the missing file
realization handler. The fixture is deliberately well-formed -- renderable path, product
output shape, only modeled channels -- because a fixture with a real defect would refuse on
BOTH targets and the test would pass for the wrong reason.

Also measured, and it corrects the assumption I would have coded against: ordinary modules
complete on every target (rust 6 files, go 3, dag 1, python 3, zero diagnostics each), so the
refusal genuinely has to come from the transport gate rather than from picking an
"unsupported" target.

The test carries a single-target control (rust alone completes with a non-empty tree, so a
future change that breaks the fixture cannot leave the test quietly asserting nothing), pins
the refusal to the target-gate cause rather than any refusal, and asserts the refused run
still holds the SAME file count the control emitted -- unwritten. That last assertion is the
whole content: it distinguishes "the arm withheld a finished tree" from "there was nothing to
write", and without it the property is vacuous.

Also collapses `authored_import_names`, which the merge from main left specified THREE times
in one `#[cfg(test)]` struct literal, breaking the entire lib-test target. A clean merge with
no conflict, and no gate could see it: CI builds the binary and the Rust suite left CI on
2026-07-11.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SAQiYQiQ7SsdxvotAFbUFc

* The five transaction tests were unexecutable as written; they now execute, 5 passed

The PR body said these arms were "type-checked only". That was too kind to them. They were
not merely unexecuted -- they were UNEXECUTABLE: a test binary's cwd is the PACKAGE root while
the fixtures live at the repo root, so every one of them panicked in
`index_source_root_into_module_index` with `source root does not exist` before reaching a
single assertion. Discovered by running the new atomic-materialization test, not by reading.

FIRST FIX WAS WRONG AND THE WRONGNESS IS THE POINT. `set_current_dir(workspace_root())` looks
correct and greened four of five. It is a race: cwd is process-global and cargo runs these
tests in parallel, so a DIFFERENT PAIR failed on each run -- 4 passed/1 failed, then 3 passed/
2 failed, with identical code. A flaky green here would have been worse than the original
failure because it would have read as proof. Replaced with absolute paths derived from
`workspace_root()`, which has no shared mutable state to race on.

Also reads the `Refused` arm rather than routing it through `cause_of`, which destructures
`NotExecuted` only. The first draft panicked on its own success: the run WAS
`Refused { phase: "emit", cause: "... target 'go' ... transport emission is not modeled" }`,
which is exactly what the test asserts.

MEASURED: `cargo test --lib -p v1-compiler` over the five, remote: 5 passed, 0 failed.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SAQiYQiQ7SsdxvotAFbUFc

* Assert the withheld tree BYTE FOR BYTE, not by file count

The atomicity test compared the refused run's rust emission to the control by
`files.len()`. That is weaker than the property the test exists to establish: a
refusal that silently substituted DIFFERENT bytes at an equal count would have passed,
and "the refusal also changed the output" is exactly the failure the all-or-nothing
claim rules out.

The control now captures (path, content) for every rust file and the refused run is
compared against it verbatim. Raised by review rather than found here, and conceded
rather than argued -- an equal-count assertion is not a cheaper version of the right
one, it is a different and weaker claim.

MEASURED after the change, remote: 5 passed, 0 failed over the five transaction tests.

UNCHANGED AND STILL DECLARED: this proves the TRANSACTION refuses while holding a
complete tree. It does not observe the filesystem, because `write_output_files` lives
in main.rs -- an edit moving it back inside the target loop would still pass. The
test's own comment and the PR body both say so.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SAQiYQiQ7SsdxvotAFbUFc

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
briansrls pushed a commit that referenced this pull request Aug 26, 2026
… identically by both readers who implemented it (#9324)

* Split the required run into two parallel jobs, and correct the ruling the split supersedes

The required run's four phases are mutually independent and were also SERIAL,
because one process runs them one after another. That is the expensive
combination: the witness floor costs ~30-40 minutes and every other phase waited
behind it for no reason a data dependency names, so the required check's wall
clock was a SUM of things that could have been a MAX.

Operator ruling 2026-08-25 ("we can add it as a parallel job in github actions -
we can do the same for regen now, we have more runners" / "basically i would put
regen + v2 full compile in one job, and witnesses into another one"). Two jobs,
no `needs` edge:

  build      regen first-generation comparison + the v2 emission compile
  witnesses  the .dag parse sweep + the witness floor fold

Each job makes ONE invocation of claim_executor and names a LANE. It does not
name phases, order them, or wire one phase's precondition to another step's
outcome -- which phases a lane owns is `RequiredCiPhase::lane`, an exhaustive
match, so a phase belonging to no job fails to compile rather than going
silently unmeasured. Every run prints a ROUTED line for each phase it does not
own, so one job's log names the whole roster and where the rest is measured.

THE 2026-08-20 CONSOLIDATION DIRECTIVE IS CORRECTED, NOT SILENTLY CONTRADICTED.
It has two halves and only one is superseded. SURVIVES -- "within the gunbc
binary": the phases still live in the binary and the step-ladder defect the
consolidation fixed cannot return. SUPERSEDED -- "not at a github actions job
level": parallelism is not expressible in one process, so the lane boundary is a
job boundary of necessity, and what the directive protected against (sequencing
and preconditions leaking into YAML) is exactly what does not cross it. Both
halves are now stated in DESIGN's CI clause, in `gunbc.fabric_witness_run`, in
`gunbc.witness_floor_workflow` and in the consolidation witness file.

THE v2-EMISSION SUBJECT WIDENED in the same change, from `dag/std/abi.dag` to
`src/v2/compiler/00_compile.dag`. The cost that argued for the smallest entry
was a cost against a SERIAL run; the build lane's cost is now free up to the
floor's duration. Measured by emitting both closures and differencing the file
sets, the widening gives up exactly one file of coverage, `src/std_abi.rs`, and
the row says so rather than claiming total subsumption.

Executed evidence:
  - both lanes run, and route correctly: `lane=witnesses` runs parse and floor
    and routes regen and v2-emission; `lane=build` runs regen and v2-emission
    and routes parse and floor
  - an unknown lane word refuses with exit 2, it does not default
  - the v2 compiler entry compiles clean under the phase's own producer and
    pinned pool index (0 blocking)
  - six consolidation witnesses pass, including two new ones for the split
  - both new REDs flip under mutation and restore: adding a `needs` edge reds
    the parallel claim; collapsing to one job reds the two-lane claim
  - the lane-command claims verified through a scratch probe with a control
    that returns false

NOT DONE, named rather than absorbed: no ratchet over the v2 compile's advisory
population (a count pinned to the current tree is the oracle DESIGN §5 rejects;
the honest form is an identity-grain monotone debt contract, a separate
construction). Nothing else is restored from the deleted floor machinery. And
the build step still compiles only the two bins the jobs run -- a declared
`[[bin]]` outside that set is uncovered, with a live specimen on main today
(`infer_semantics_witness`, six E0063s); widening to `--bins` changes what the
required check covers and is an operator decision, so it is declared here rather
than taken.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SAQiYQiQ7SsdxvotAFbUFc

* Correct the workflow module's own stale recital of the consolidation directive

The supersession was recorded in DESIGN, in gunbc.fabric_witness_run, in the
consolidation witness file and in the binary's own roster block -- and NOT in the
paragraph inside gunbc.witness_floor_workflow that quotes the 2026-08-20
directive and describes the job as ONE INVOCATION, FOUR PHASES. That paragraph
sits directly above the run step the split changed, so it is the one a reader
reaches first, and leaving it standing would be the premise contamination this
change exists to remove -- one document corrected while its own subject still
recited the superseded ruling in the present tense.

It now states both halves: 'within the gunbc binary' survives, 'not at a github
actions job level' is superseded because parallelism is not expressible in one
process. The step-ladder paragraphs below it are kept rather than rewritten,
because what they establish is unchanged by the split and deleting them would
take the reasoning with them. Also corrected: the step no longer passes 'the
source roots and nothing else' (it passes a lane word), and the phase roster is
four across two lanes rather than the 2026-08-21 three.

Comment-only in emission terms: witnesses.yml regenerates byte-identical.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SAQiYQiQ7SsdxvotAFbUFc

* Make the split fail-closed: the required context now gates on both lanes

Review of #9203 (review 55786, codex/gpt-5.6-sol) found the split fail-open, and
it was right. Verified against the live ruleset rather than against the workflow,
which is the only place the fact is visible: `passing CI` is active, carries NO
bypass actors, and names exactly ONE required status check -- `witnesses`. A
GitHub required context is produced by the JOB, not the workflow, so moving regen
and v2-emission into a second job made them NON-BLOCKING: the required check
would go green over a regen drift or a v2 emission break and the PR would be
mergeable. That is strictly worse than the serial run it replaced, because the
serial job carried every phase into the one context that gates.

THE REPAIR, and why it is an aggregation job rather than a ruleset edit. The
floor lane is renamed `floor`; the name `witnesses` moves to a job whose only
step reads both lanes' results and exits nonzero unless both succeeded. The two
lane jobs still carry no `needs` edge on each other and still start together --
only the aggregator waits, and it does nothing but read two results. A ruleset
edit would also have worked and was rejected on a boundary DESIGN already
records: the ruleset is not a `.dag` fact, so landing a change whose safety
depends on someone editing a setting afterwards is a coverage gap with a promise
attached and a real window in which the lane is unguarded.

`if: always()` IS LOAD-BEARING, and its absence would have been the same
fail-open one level in: a step with no `if` inherits `success()`, so it would be
SKIPPED exactly when a lane failed, the job would report success, and a skipped
required check does not stop a merge.

The aggregator is the only place in this workflow that authors shell text, and
that is stated on the carrier: there is no modeled value to render, because
GitHub has no declarative "this job fails unless those jobs succeeded", and the
nearest declarative form is the skip that fails open. The script is built from
the job-id declarations rather than spelling `needs.build.result`, so a rename
moves both sides together instead of rendering an unknown context as the empty
string.

WITNESS CORRECTION, not just an addition. `w_RED_neither_lane_waits_on_the_other`
asserted the file contained no `needs:` at all -- the right claim for a workflow
shape that was wrong, and a row that would have made this repair unrepresentable.
It now forbids each single-lane edge and REQUIRES the aggregator's two-lane one,
which distinguishes the serialization being forbidden from the aggregation being
demanded. A third row asserts the gate runs and refuses.

Executed evidence: all seven consolidation witnesses pass, and three mutations
red the right rows and restore -- serializing floor onto build reds the parallel
claim, dropping `always()` reds the gate claim, and deleting the aggregator reds
the parallel claim.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SAQiYQiQ7SsdxvotAFbUFc

* The aggregator's guard belongs at the JOB level: a skipped job never reaches its step

Review 55795 and a peer session independently found, within minutes of each
other, that the fail-closed repair was itself fail-open one level in.

`needs` carries an IMPLICIT JOB-LEVEL CONDITION. A job that declares `needs` and
no `if` is SKIPPED when any needed job fails, is skipped, or is cancelled. A
skipped job never starts, so it never reaches its steps, so the step-level
`always()` could not fire -- and a skipped required check does not stop a merge.
The aggregator introduced to close the fail-open would have gone
skipped-and-mergeable over precisely the failed lane it was there to catch, with
the guard present in the file and reading as correct.

`always()` AT JOB LEVEL, AND THIS IS THE ONE PLACE THAT DEPARTS FROM THE FILE'S
`!cancelled()` HOUSE GUARD -- said in the carrier, in DESIGN and in the witness,
because a reader who knows the convention will otherwise correct it back and
reopen the hole. Every other guard here decides whether a STEP runs inside a job
that is already running, where `!cancelled()` is right. This one decides whether
the REQUIRED CONTEXT EXISTS AT ALL, and under `!cancelled()` a cancelled run
leaves it skipped rather than answered. That would turn the outcome on a question
about GitHub nobody here has executed -- does a skipped or cancelled required
check block a merge -- and the response is not to go measure it but to make the
answer not matter. Under `always()` the job always runs, always reads both
results, and always reports on its own terms; SKIPPED disappears from the
required context. Cost, named: a lawfully superseded run now reports this context
red rather than cancelled. That is the correct reading, not a regression -- a
superseded run's evidence must not admit a merge.

THE WITNESS WAS WRONG IN THE SAME WAY AND IS FIXED WITH IT. It asserted
`if: always()` appeared SOMEWHERE in the file. It did -- on the step -- so it
went green over the defect. That is DESIGN's total-at-the-level-examined failure:
true, and about the wrong level. It now discriminates on emitted INDENTATION,
which is the only thing in the text that separates the two levels (a job key at
four spaces, a step key at eight), and asserts both.

Executed: the strengthened row PASSES on the fix and FAILS on a mutation that
removes the job-level guard -- i.e. it catches the exact defect that shipped.
All seven consolidation witnesses pass.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SAQiYQiQ7SsdxvotAFbUFc

* Say what the v2-emission phase actually covers: 24 of 42 compiler modules, measured

Operator clarification, 2026-08-25: "the intention is to v2 build ALL of the .dag
compiler files, and then ratchet THAT count in CI". Measuring against that ask
showed this PR's own prose overclaims, so the claim is corrected before anything
is built on it.

MEASURED, by emitting the entry and joining the emitted file names against the
module line of every src/v2/compiler/**.dag: of the 42 modules under
src/v2/compiler/, 00_compile's closure emits 24. Eighteen are absent, including
ingest, emit_module, emit_host, emit_produced, emit_semantic_decl,
program_partition and self_host. Counting the self_host/ subtree the compiler
namespace is 69 modules, so the shortfall is larger again.

"The widest closure one entry names" was true and is kept; "full v2 compile"
invites the reading that the phase covers the compiler, and it does not. That
reading is exactly the premise contamination this repository keeps paying for, so
the row now states the covered population rather than leaving a reader to assume
it.

AND A METHOD NOTE THAT COST A MEASUREMENT: a static import-closure estimate
CANNOT substitute here. It reports ZERO compiler coverage for this entry, because
this corpus resolves most cross-module references without import lines. Only the
compiler's own reference-derived closure is the truth, which means a covering
entry set cannot be derived from the import graph either -- it has to be measured
by emission.

The widening itself is NOT taken here: it needs either a measured covering entry
set or a whole-tree emission whose cost has to be known before it is enrolled in
a required lane. This row makes that widening a change to a known number instead
of an assumed one.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SAQiYQiQ7SsdxvotAFbUFc

* Receipt: the gate refused two cancelled lanes, and 'abandoned' is a state nobody knew about

Run 32883390033 (2026-08-25) ended BOTH lanes by a fleet event with no push
involved. The aggregator ran anyway under its job-level always(), read the two
results, refused, and published the required context witnesses as a FAILURE. That
is this gate's first executing receipt and it is the behaviour the pre-repair
shape could not produce -- there, the aggregator would have been skipped.

AND THE RUN SURFACED A needs RESULT VALUE NOBODY HERE KNEW WAS REACHABLE:

    BUILD="cancelled"   FLOOR="abandoned"

The gate handles 'abandoned' correctly only because it compares != "success"
rather than enumerating bad states. The form a reader's instinct reaches for --
== "failure" || == "cancelled" -- would have admitted it and reported the
required context GREEN over two lanes that never ran. So the strict inequality is
now recorded on the carrier as a measured fact rather than left as a style
choice, because the obvious 'improvement' to an explicit list is a fail-open.

That is the difference between a closed vocabulary and a remembered one: the
inequality admits exactly one state and refuses every other, including the ones
the author has never heard of.

Comment-only in emission terms: witnesses.yml regenerates byte-identical.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SAQiYQiQ7SsdxvotAFbUFc

* Record the argument against always() beside the decision to keep it

A peer session raised the strongest objection to the job-level always() guard,
from GitHub's documented semantics rather than from a measurement, and it is
correct on every fact it asserts: always() is the one condition that survives
workflow cancellation, cancel-in-progress is armed on every pull_request so this
fires on the MODAL event, and it destroys the cancelled/failed distinction at the
RECORD level where nothing can recover it. That ambiguity cost that session hours
in one day, diagnosing 38 lawful supersessions as a false-red epidemic. The
file's house guard really is !cancelled() everywhere else.

It is not taken, and the reason is an asymmetry about WHICH HEAD PAYS. Checks are
tracked per head SHA, so a superseded run's red lands on a head that by
construction is never merged -- the push that superseded it created the head that
will be. always() is noisy on ABANDONED heads. !cancelled() moves the cost onto
the LIVE one: a lane killed with no replacement run coming, observed twice on
2026-08-25 (once with runner_name empty and zero steps, once with both lanes
ended at 18:43 and no push involved), leaves the required context SKIPPED on the
head that is still the merge candidate -- which is precisely the unmeasured
GitHub behaviour the guard exists to stop depending on.

Quiet-and-unknown on a live head is worse than loud-and-definite on a dead one.

The mechanism half of the objection is now MEASURED rather than documented: run
32883390033 had both lanes ended by a fleet event, and this job published
failure while the run conclusion was cancelled. So the behaviour the objection
predicts is real; what is disputed is only whether it is the wrong trade.

Recorded in the carrier rather than answered away, so the next person who wants
!cancelled() finds the case already made instead of rediscovering it.

Comment-only in emission terms: witnesses.yml regenerates byte-identical.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SAQiYQiQ7SsdxvotAFbUFc

* One compilation transaction, subject-parameterized; the gate emitted as nodes

Four things, in the order the operator's dispatch puts them.

ONE. The build lane bootstraps `cargo build --release -p v1-compiler --bins`.
Host-Rust coverage of the whole declared bin roster is a fact somebody has to
establish, and a bin no consumer selects is precisely the one that rots
unobserved -- #9205 repaired one such bin after it had drifted with nothing
building it. The floor lane keeps the two bins it executes; the lanes are
runtime-independent, so their bootstraps are independent CPU rather than a
shared prerequisite one could save.

TWO. THE DAGLANG COMPILATION FORK IS CLOSED. `cli_run` now carries
`CompileSubject{Entry|PrimaryRoot}`, `CompileRequest` and `compile_emission`,
and the transaction owns indexing and precedence, subject source-set
construction, census fill, memory admission, resolution and compilation, the
blocking/advisory split, silent-pick capture and the disposition.
`compile_entry_emission` survives as a wrapper with no semantics of its own.

Before this, `gunbc compile` without `--entry` implemented a SECOND
index/load/resolve/admit/compile/refuse pipeline in `main.rs`, beside the
transaction rather than through it. They differed in ways nobody had decided:
the whole-root arm applied the memory-admission gate and the entry arm did not,
the entry arm ran the silent-pick gate inside the transaction and the whole-root
arm ran it around the outside, and their refusal subjects were spelled
differently. That is DESIGN section 3's two-authorities-for-one-fact, and it is
the reason a whole-tree ratchet could not be built on the existing phase: the
ratchet would have observed a different producer from the gate beside it.

The arms' real differences are KEPT, which is why this is a coproduct and not a
flag: admission is asked of the whole root and not of an entry (an entry's
working set is its closure, measured to fit on the runner that SIGKILLed a
whole-tree run -- an unasked question, not an all-clear), and the closure
derivation genuinely differs (reference-derived for an entry, import-edge for a
root where every module is already an entry). A `PrimaryRoot` matching no module
refuses at `subject-discovery` rather than reporting `Completed { 0 }`, which
would be the empty-observation narrow.

THE DELETION WAS THE CENSUS. Routing the whole-root subject through the
transaction left ~200 lines in `main.rs` with no caller, and rustc then found
seven more private copies of module indexing and import walking --
`extract_module_path`, `report_moduleless_dag_entry_skips`,
`extract_import_paths`, `insert_module_path`, `index_source_root`,
`build_module_index`, `resolve_transitively_with_seen`. All deleted; their two
tests re-pointed at the surviving `cli_run` authority rather than retired with
the function, per DESIGN section 4b(4). Multi-target (`--target a,b`) still walks
the old loop and is named rather than exempted.

THREE. `pr_owner` AND `cycle_owner` REFUSED FOR A REASON THAT IS NOT IN
`review_codex.dag`. `owner` has TWO declarations in the flat whole-tree
namespace -- `data owner` in `gunbc.tools.review_codex` and
`fn owner(uid, gid)` in a srv3 path-ownership test -- and the winner is fold
order. When the function won, the CLI defaults resolved to it and refused with
`must be a string, int, float, bool literal, or data reference`: two blocking
diagnostics in a file that had not changed, produced by a test helper in another
directory.

The discriminating pair is what establishes that, and it was measured rather
than reasoned. `repo` is declared beside `owner` in the same module, has no
`fn repo` anywhere in the corpus, and does not refuse. `default_model` IS
declared twice -- `tools.review` and `tools.review_codex` -- and does not refuse
either, because both declarations are data, so either winner satisfies the
default's requirement. Collision alone is not the fault; collision ACROSS
DECLARATION KINDS is. Fixed by renaming the test helper to `owner_spec`.

The class is untouched and the annotation says so: a bare cross-kind homonym is
still writable and still resolves by fold order. Its next-rung trigger is a
refusal at name resolution when one flat name carries declarations of different
kinds -- decidable from the index the compiler already builds -- not a roster of
forbidden names.

FOUR. THE REQUIRED-LANES GATE IS BUILT AS NODES, NOT SPELLED AS TEXT.
`gunbc.required_lanes_gate` constructs it through
`v2.extdeps.languages.bash_build` and `witness_floor_workflow` serializes it
through `v2.workflow.bash_command_fold_serialize` -- the
`tools.build_step` -> `v2.workflow.build_step_emit` precedent. Raised as review
55836's medium-as-string finding, which was correct: I had argued no modeled
value existed to render, and the language was fully modeled the whole time.
Declaring a language-layer gap without enumerating the language is the failure
DESIGN records in its own section 6 receipt.

The Rejected arm REFUSES rather than rendering nothing, because an empty `run`
exits 0 and would make the required context green over two lanes it never read.
The emitted text was executed against all three arms: success/success passes,
success/failure and cancelled/abandoned each print the error and exit 1.

ALSO LANDED, NOT YET WIRED: `gunbc.v2_rustc_debt` models the monotone identity
ledger -- key (emitted-crate-relative path, rustc code), admission iff observed
equals the current ledger AND the current ledger is a multiplicity-wise subset
of the baseline's -- with eleven fixture arms that author both input and
expectation. Both totals are receipt-only and reach no verdict. Its host
observation is deliberately absent: an observer built before a whole-tree
emission can be produced would be an observer with no subject.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SAQiYQiQ7SsdxvotAFbUFc

* The subject is a field, the precedence root is a refusal, and the fork is three callers wide

FOUR CORRECTIONS, three of them from an operator ruling on the measured report
and one from the census that ruling asked for.

ONE. THE ALIAS DIRECTION WAS BACKWARDS. It read
`pub type CompileRun = EntryEmissionRun`, which makes the generic name an alias
of the entry-named authority -- so the canonical carrier stays the one named for
a subject it no longer describes, and every reader is sent to a type whose name
contradicts two of its three uses. `CompileRun` and `CompileDisposition` are now
the types; the entry-named spellings are the compatibility aliases that
disappear with their last caller.

TWO. `run.entry` SILENTLY WIDENED TO HOLD A DIRECTORY. A consumer reading it
after a `PrimaryRoot` compile got a root from a field promising a file -- one
name, two meanings, which is the section 3 violation the fork closure exists to
remove, reintroduced one field down. It is now `subject: CompileSubject`, and
the receipt names the ARM rather than the path: `subject=primary-root:src/v2`,
not `subject=src/v2`. The two read identically to a human and differently to
anyone deciding whether a run measured what it was asked for, which is the whole
reason the field exists.

THREE. THE SUBJECT AND THE PRECEDENCE ROOT NOW HAVE TO AGREE, AND DISAGREEING
REFUSES. The trap is entirely in argv order and invisible from the receipt: the
live workflow passes `--source-root dag --source-root src/v2`, and the no-entry
CLI law is `PrimaryRoot(source_roots[0])`, so THAT argv asks for
`PrimaryRoot(dag)` with `src/v2` as a pool. A caller who means "compile v2" and
writes the roots in the workflow's habitual order gets the other subject,
compiles ~2000 different modules, and is told the compile completed.

This is not a scope difference, it is a RESOLUTION difference, and it already
cost a measurement: `dag`-primary refuses on two `review_codex` CLI defaults
that `src/v2`-primary never reaches, and `src/v2`-primary refuses on 36
diagnostics `dag`-primary never sees. The 9.06 GiB peak and the `owner`
diagnostics reported earlier are the `dag` subject; they were reported under a
heading that implied the v2 one. A ledger bootstrapped from the wrong subject is
not a coarser ledger, it is a ledger about another population.

`primary_root_agrees_with_precedence` makes the disagreement unwritable rather
than merely detectable.

FOUR. THE FORK IS THREE PRODUCTION CALLERS WIDE, NOT ONE. The census over
`compile_sources`, `compile_sources_with_options`,
`compile_to_resolved_with_options`, `emit_resolved_for_target` and
`stage0_self_compile_refusal_message` classifies every caller:

  46  compiler_tests / compiler_tests_rust     kernel test, legitimate
   2  v1_probe_emit_interp                     generated kernel probe, legitimate
   2  v1_compiler_emit_rust                    compiler implementation, legitimate
   9  cli_run                                  compile_emission implementation
   5  main.rs                                  DECLARED VIOLATION (multi-target loop)
   2  required_regen_host                      DECLARED VIOLATION (needs ExactSourceSet)
   2  bin/bootstrap_witness                    DECLARED VIOLATION (not previously named)

`bootstrap_witness.rs` compiles EVERY `.dag` file under `dag/` to Rust, which is
exactly the invariant's subject -- a repository source population producing an
artifact tree -- so it is a production route and not a kernel probe. It carries
its own `build_module_index`, `build_module_index_for_roots` and
`resolve_imports_transitively`: a FOURTH private copy of the machinery this
branch deleted from `main.rs`, in a 1289-line binary the floor lane builds and
runs. It can disagree with the transaction about what the `dag/` population IS,
and nothing would say so.

None of the three violations is closed here. They are named, classified, and
ordered: multi-target into the request as a target set, then regen and
bootstrap_witness through an exact-source-set subject, both of which select a
population by their own authority rather than by directory.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SAQiYQiQ7SsdxvotAFbUFc

* Hoist two §4c-illegal in-body annotations, and restore the module-less skip report the consolidation dropped

Two fixes, both of them corrections to my own work on this branch.

§4c: `v2_rustc_debt_ratchet_test.dag` carried two `//` lines INSIDE a `test fn` body.
Only module-item grain is modeled, so strict preparation refused and the build lane
went red on #9242. Hoisted above the declaration. An awk brace-depth census over every
file this branch touches confirms no in-body annotation remains.

Module-less visibility: the deletion note in `main.rs` claimed the module-less-entry
skip report was "the one behaviour with no counterpart" in `cli_run`. That was FALSE --
`report_moduleless_dag_entry_skips` and `moduleless_dag_entry_paths` are both `pub`
there with tests, and were never deleted. The note asserted an absence without grepping
for it, which is the one claim a later reader will not re-check.

The behaviour is now wired into the transaction's `PrimaryRoot` arm through those same
two functions. It matters there specifically: the subject is discovered from
`index.source_files`, keyed by module path, so a `.dag` under the root with no `module`
declaration is absent from the subject and the transaction would report `Completed`
over a population that silently excluded it. The empty-root refusal cannot catch this,
because a root holding one good file and one forgotten one is not empty.

It REPORTS rather than refuses, declared as the weaker arm: a module-less `.dag` is a
legitimate parse fixture today, so refusing would break real callers. Terminal form is
a total role classification under which an unclassified `.dag` refuses.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SAQiYQiQ7SsdxvotAFbUFc

* Route multi-target compiles through the one transaction, validate all three debt populations, and read the verdict as itself

Six review findings, each fixed rather than answered.

MULTI-TARGET REGRESSION (blocking). `--source-root X --target rust+dag` fell past the
routing gate -- which conjoined the subject with `render_targets.len() == 1` -- into a
branch whose only remaining subject is `--source-dir`, and exited "provide --source-root
or --source-dir" over an argv that provided one. `CompileRequest` now carries a target
VECTOR: resolve once, emit per target, and materialize NOTHING until every target has
completed, so one target's tree is never left on disk beside another's refusal. The
disposition, the blocking count and the refusal are over the whole emission set, not the
first target. Single-target callers -- every required one -- run the identical
computation, because `compile_sources_with_options` IS
`emit_resolved_for_target ∘ compile_to_resolved_with_options`.
Two discriminating arms: two targets produce two named emissions from one resolution,
and a request naming NO target refuses at its own `target-admission` phase rather than
reporting `Completed { emitted_count: 0 }`.

DEBT LEDGER FAIL-OPEN (blocking). Positivity and uniqueness were asked of the LEDGER
only. A duplicated key in the OBSERVATION makes the multiplicity lookup answer with
whichever row the fold reaches first, so the comparison silently compares the wrong
quantity and the run reads as held. All three populations are now validated -- positivity,
uniqueness, and strictly ascending canonical order -- through one
`DebtPopulationMalformed { population, cause, keys }`, with `population` a closed
coproduct because the three have different owners and different repairs. Order refuses
rather than sorts: sorting would make two textually different ledgers compare equal and
stop a ledger diff being reviewable.

THE BLIND-SPOT FIXTURE AUTHORED NO SUBSTITUTION. It passed `one_error()` on both sides
and CLAIMED in prose that the two were different errors, which made it a tautology
wearing a substitution's name. It now authors `SyntheticRustcDiagnostic` values carrying
a latent site, asserts FIRST that the two populations differ, and then that bucketization
erases the difference.

NO BOOLEAN COLLAPSE OF THE VERDICT (review 55911). `rustc_debt_verdict_admits` matched
every variant and returned one bit, so a consumer refusing on it prints "the ratchet
refused" and the author re-derives the cause by hand. Deleted. Every test arm now asserts
WHICH verdict, which is strictly stronger: an arm authored to provoke
`LedgerExceedsBaseline` used to stay green when the contract refused it as malformed for
an unrelated reason.

VOCABULARY. `admitted_multiplicity` -> `multiplicity`; `identities` -> `buckets`, in the
model, the receipt and the test names -- the count is per (path, code) bucket and calling
it an identity is the inflation the blind-spot arm exists to deny.

RENAME FINISHED. The entry-named aliases are deleted, not merely re-pointed; two
spellings for one type is the same §3 violation one layer out.

Also: the census behind "one compilation concept" is now stated at CALL-SITE grain with
its forks named, the `CompileSubject` comment no longer calls the import walk "the
authority" (it under-pulls by construction -- the namespace is flat -- and the census fill
covers the difference), the precedence check declares its rung and its terminal
`SourcePool` form, and a `TypeEnv` field missing at one test site is filled so
`cargo test --lib` builds at all.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SAQiYQiQ7SsdxvotAFbUFc

* Build the unrenderable-gate refusal from the Bash grammar too, and split the unwired debt model out of this PR

Review 55923, both findings, neither deflected.

THE RAW SHELL FALLBACK IS DISSOLVED, NOT MARKED. `required_lanes_gate_unrenderable_script`
was an executable program spelled as a String and handed to a RunStep -- the
medium-as-string violation this PR otherwise removes, surviving in the one arm nobody
reads, inside the module whose own header argues against exactly that. The refusal is now
Nodes in `gunbc.required_lanes_gate`, beside the gate it stands in for, serialized through
the same fold.

The outcome is three-state rather than two, and the third state is what removes the last
fabricated value: the gate serializes -> the gate; the gate rejects but the refusal
serializes -> the refusal, which stops every run loudly; both reject -> Absent, and
`expected_witness_floor_yml` returns `WitnessFloorGenerationRefused` so no yaml exists at
all. A Rejected fold can no longer reach a published step. The one remaining `""` is not a
program and is reachable only when emission has already refused -- Daglang is total, so
some value must inhabit the arm; what matters is that it is not a second spelling of a
shell program and that no emission path reaches it.

Verified rather than asserted: `required_lanes_gate_is_renderable` returns true by
execution, and regen exits 0 with the workflow yaml BYTE-IDENTICAL -- only the unreachable
arm moved.

ON THE "on-carrier bash-emission scaffold marker": no such convention exists in this tree.
A whole-tree search finds no `bash_emission`, `hand_shell` or `model_vs_runner` carrier.
Removing the raw string makes the marker moot either way, which is the stronger repair.

THE DEBT MODEL LEAVES THIS PR. `dag/gunbc/v2_rustc_debt.dag` and its fixture are removed
and travel to the change that lands their consumer. The earlier review from the same
provider offered keeping this PR open as the integration vehicle and I took that; a
measurement since has changed the calculus. A whole-repo emission REFUSES ON MEMORY
ADMISSION on the current runner class -- measured on BuildBuddy: budget 6.58 GiB against
the modeled 7.00 GiB demand, `WholeCorpusCompileBudgetBelowMeasuredDemand`, zero files
emitted. So the observer cannot be built until the resource-grant boundary is decided, and
that decision is the operator's. Holding a foundational compilation PR open behind someone
else's decision is worse than either option the review named.

What remains here is the compilation consolidation and the gate repair: coherent, with
consumers, mergeable on its own.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SAQiYQiQ7SsdxvotAFbUFc

* A target name carried beside its target can disagree with it; derive it. And the fork census omitted a fork

Two remarks from the side-channel review, both verified against the code, both real.

THE (NAME, TARGET) PAIR IS COLLAPSED TO A TARGET. `CompileRequest.render_targets` carried
`Vec<(String, RenderTarget)>`, so `("dag", RenderTarget::Rust)` was constructible: two
spellings of one fact, free to disagree, with the NAME deciding which directory a target
is written to while the TARGET decided the bytes written into it. That is the §3 violation
this transaction exists to remove, reintroduced one field down and in the same PR that
removes it elsewhere. The name is now DERIVED through `render_target_name`, which is the
CLI parse's inverse, so the disagreement has no representation rather than being checked
for. `parse_render_targets` discards the authored spelling deliberately, because it is
recoverable.

THE CALL-SITE CENSUS OMITTED `required_regen_host`. `compile_stage0` calls
`compile_sources` directly over `regen_input_sources` -- a fourth fork, and the census
whose entire purpose is to enumerate forks reported it as absent. The file appeared in the
file-level count I ran and did not survive into the call-site list I wrote from it, which
is the incomplete-enumeration class this repository has recorded against itself twice
before: a list transcribed from a wider measurement is not the measurement. It is now
listed with its subject (an EXACT SOURCE SET from the regen roster -- neither a root nor an
entry, so neither existing subject describes it), its terminal form, and the hardcoded
refusal subject it still passes. The omission is recorded in the census itself rather than
quietly corrected, because a census that has been wrong once should say so.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SAQiYQiQ7SsdxvotAFbUFc

* The refusal arm the PR defends was the wrong shape, and nothing executed could have caught it

Review 55928, plus four findings from the thread review that survive at this head.

THE MIDDLE RUNG WAS DEAD. `required_lanes_gate_unrenderable_stmts` was declared
`-> List<Node>` and returned `bash_build_stmt_list_from_nodes(...)`, which is a single
`Node`. Its caller passes it as `stmts: List<Node>`. So the arm this PR argues must stay
executable -- gate rejects, the refusal still serializes, the run stops loudly -- was the
wrong shape in exactly the place the argument is about, while the in-file receipt said it
was Nodes through the same fold. Returns the raw list now, like `required_lanes_gate_stmts`
beside it.

THE REASON IT WAS POSSIBLE IS THE REAL REPAIR: the claim lived in prose, so nothing could
contradict it. `the_unrenderable_gate_refusal_serializes_and_stops_the_line` now runs the
fold over the refusal and reads the program back -- it must serialize, and must carry both
the `::error::` annotation the operator sees and the `exit 1` that stops the line.

THE CONTROL FLIPS, MEASURED RATHER THAN ASSUMED. Fixed shape: true. Defect restored:
`PatternMatchFailure`, the fold choking on a Node where the list belonged. ONE HONEST
QUALIFICATION: the red arrives as a RUNTIME ERROR, not a returned false, which is a weaker
red than a clean false -- an erroring probe stops rather than asserting anything about its
subject. Recorded because "the control flips" alone would overstate it.

DUPLICATE TARGETS REFUSED. `--target rust+rust` parses to two targets, and each emission's
directory is derived from the target, so both land in `output_dir/rust` -- the second
overwriting the first while the run reports two completions. Refused at `target-admission`,
not deduplicated: collapsing it silently answers a request nobody made and destroys the
signal that the argv is wrong.

THE MODULE-LESS WALK NO LONGER DROPS READ FAILURES. `if let Ok(content)` narrowed "every
`.dag` under the root" to "every READABLE one" while still reporting under the wider name --
the empty-observation narrow inside the population whose entire job is to report what got
dropped from the subject. Now a typed refusal at a `subject-read` phase.

DOCUMENTATION THAT LIED. The root-order ruling sat immediately above
`names_at_least_one_target`, so Rust attached the precedence contract to target admission;
moved. "One entry, one render target" and "One entry's emission transaction" corrected
beside code that handles two subjects and a target vector. The alias note's history example
read `pub type CompileRun = CompileRun`, which is not a direction. And "reference derivation
is not used here and that is not an oversight" sat directly above the fixpoint call that
falsifies it -- it is used, because an import edge is weaker than a reference in a flat
namespace and the walk under-pulls across the pool boundary.

Regen exits 0 with no artifact drift.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SAQiYQiQ7SsdxvotAFbUFc

* Restore the entry-scope marker as a typed receipt: I deleted a consumer's evidence while tidying a sentence

Three findings from the thread review, verified against the code before acting.

THE SCOPE MARKER WAS MINE TO LOSE AND I LOST IT. Main prints "resolved N sources
(reference-derived closure), M indexed modules"; consolidating the two CLI pipelines into
one generic line dropped the parenthetical. It existed at the merge-base, so this is a
regression on this branch and not a collision. `gunbc.emit_diagnostic_observation`
`emit_entry_scope_marker` (landed on main via #9190, AFTER my change) matches that exact
text and returns `EmitScopeUnconfirmed` when it is absent -- specifically so a whole-root
compile cannot be reported as one entry's measurement. Merging main unchanged would have
made every per-entry emission measurement refuse, from an edit that reads as prose cleanup.

RESTORED AS A VALUE, NOT AN ADJECTIVE. `CompileScopeReceipt` is derived from
`CompileSubject`, so the receipt cannot disagree with the run and cannot be lost by
rewording. The entry arm carries the marker; the primary-root arm now STATES what it
measured instead of being silent, so a consumer no longer has to infer scope from argv or
file counts. The Rust literal and the `.dag` `data` row are two spellings of one fact --
unavoidable while that authority is `.dag` and this seed cannot read it -- so the constant
is named `EMIT_ENTRY_SCOPE_MARKER` and cites its authority, making the pair greppable.

THE TEST ASSERTS BOTH HALVES. Marker present on the entry arm, ABSENT on the primary-root
arm. A receipt that carried it on both would be worse than one that carried it on neither:
the marker exists to make the substitution refusable.

THE PANICKING TRAVERSAL. My earlier "typed refusal" fixed the per-FILE read and left the
DIRECTORY walk calling `collect_dag_files`, which is
`collect_dag_files_result(..).unwrap_or_else(|e| panic!(..))`. A missing root, a regular
file as root, or any `read_dir` failure bypassed `CompileDisposition` entirely. That was
half a repair wearing the whole one's name; the walk is fallible now.

TARGET ADMISSION ORDERING, PROVEN RATHER THAN ASSERTED. The new arm passes a subject that
CANNOT be discovered, so if the duplicate-target refusal came after subject discovery the
run would refuse at `entry-read` instead and the arm would fail. It proves the ordering,
not merely the refusal.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SAQiYQiQ7SsdxvotAFbUFc

* The all-or-nothing materialization proof, with a RED that is actually authorable

The CLI writes a tree only after the AGGREGATE disposition is `Completed`, so one target's
refusal must withhold another target's finished files. That claim was asserted by the arm's
structure and by nothing executable.

BEFORE WRITING THE TEST I CHECKED WHETHER ITS RED CAN BE PRODUCED AT ALL, because a check
whose red is unauthorable is a decoration -- permanently green by construction and worse than
absent, since it gets cited as coverage (DESIGN §4b). It can: `file_emission_refusal` applies
`target_renders_file_transport` FIRST and separately from `file_binding_refusal`, and that
gate answers `Rust => true` with Python, Go and Dag all false. So a WELL-FORMED file-transport
operation emits clean on Rust and refuses `FileTargetNotModeled` on Go.

MEASURED on the new fixture root before any assertion was authored: `--target rust` emits 7
files with 0 diagnostics; `--target go` refuses, naming target 'go' and the missing file
realization handler. The fixture is deliberately well-formed -- renderable path, product
output shape, only modeled channels -- because a fixture with a real defect would refuse on
BOTH targets and the test would pass for the wrong reason.

Also measured, and it corrects the assumption I would have coded against: ordinary modules
complete on every target (rust 6 files, go 3, dag 1, python 3, zero diagnostics each), so the
refusal genuinely has to come from the transport gate rather than from picking an
"unsupported" target.

The test carries a single-target control (rust alone completes with a non-empty tree, so a
future change that breaks the fixture cannot leave the test quietly asserting nothing), pins
the refusal to the target-gate cause rather than any refusal, and asserts the refused run
still holds the SAME file count the control emitted -- unwritten. That last assertion is the
whole content: it distinguishes "the arm withheld a finished tree" from "there was nothing to
write", and without it the property is vacuous.

Also collapses `authored_import_names`, which the merge from main left specified THREE times
in one `#[cfg(test)]` struct literal, breaking the entire lib-test target. A clean merge with
no conflict, and no gate could see it: CI builds the binary and the Rust suite left CI on
2026-07-11.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SAQiYQiQ7SsdxvotAFbUFc

* The five transaction tests were unexecutable as written; they now execute, 5 passed

The PR body said these arms were "type-checked only". That was too kind to them. They were
not merely unexecuted -- they were UNEXECUTABLE: a test binary's cwd is the PACKAGE root while
the fixtures live at the repo root, so every one of them panicked in
`index_source_root_into_module_index` with `source root does not exist` before reaching a
single assertion. Discovered by running the new atomic-materialization test, not by reading.

FIRST FIX WAS WRONG AND THE WRONGNESS IS THE POINT. `set_current_dir(workspace_root())` looks
correct and greened four of five. It is a race: cwd is process-global and cargo runs these
tests in parallel, so a DIFFERENT PAIR failed on each run -- 4 passed/1 failed, then 3 passed/
2 failed, with identical code. A flaky green here would have been worse than the original
failure because it would have read as proof. Replaced with absolute paths derived from
`workspace_root()`, which has no shared mutable state to race on.

Also reads the `Refused` arm rather than routing it through `cause_of`, which destructures
`NotExecuted` only. The first draft panicked on its own success: the run WAS
`Refused { phase: "emit", cause: "... target 'go' ... transport emission is not modeled" }`,
which is exactly what the test asserts.

MEASURED: `cargo test --lib -p v1-compiler` over the five, remote: 5 passed, 0 failed.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SAQiYQiQ7SsdxvotAFbUFc

* Assert the withheld tree BYTE FOR BYTE, not by file count

The atomicity test compared the refused run's rust emission to the control by
`files.len()`. That is weaker than the property the test exists to establish: a
refusal that silently substituted DIFFERENT bytes at an equal count would have passed,
and "the refusal also changed the output" is exactly the failure the all-or-nothing
claim rules out.

The control now captures (path, content) for every rust file and the refused run is
compared against it verbatim. Raised by review rather than found here, and conceded
rather than argued -- an equal-count assertion is not a cheaper version of the right
one, it is a different and weaker claim.

MEASURED after the change, remote: 5 passed, 0 failed over the five transaction tests.

UNCHANGED AND STILL DECLARED: this proves the TRANSACTION refuses while holding a
complete tree. It does not observe the filesystem, because `write_output_files` lives
in main.rs -- an edit moving it back inside the target loop would still pass. The
test's own comment and the PR body both say so.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SAQiYQiQ7SsdxvotAFbUFc

* Name the third arm: a two-way rule over a three-state domain misread by both readers who implemented it

The comment beside the /proc/vmstat reads in `floor_resource_sample` documents a
discrimination with two arms -- pswpin rising with pgmajfault is swap and not this
lane's problem, pgmajfault rising with pswpin flat is file-backed mapping churn and
IS this lane's defect. The domain has three states. Zero-and-zero has no arm.

THIS IS NOT A HYPOTHETICAL. Two readers implemented the documented rule
independently while investigating the floor-lane cancellations, and BOTH classified
zero-and-zero as mapping churn -- 26 intervals in one reading, 6 in the other. That
inverts the conclusion: churn is a defect this lane owns, quiet is the absence of
one. A rule stated as a dichotomy over three states hands every faithful
implementer the same misreading, which is why the fix belongs in the comment rather
than in either reader's script.

The mechanism of the misread is worth the extra sentence, because it is what makes
the two-arm form actively misleading rather than merely incomplete: `pgmajfault
rises` and `pswpin flat` are two conditions, and only their CONJUNCTION is churn.
Both readers selected the arm on the second condition alone -- pswpin flat -- which
is exactly what zero-and-zero satisfies.

MEASURED, remote: `cargo check -p v1-compiler` Finished, exit 0, against a
`-Z definitely-not-a-real-flag` control that exits 101, so a real compiler was
reached. `cargo fmt --all --check` exit 0.

v1 is frozen with maintenance active; the admission test since 2026-08-20 is
PURPOSE -- in support of the v2 self-host program -- and this is a defect repair to
a diagnostic the self-host floor emits on every required run. Authority:
`gunbc.v1_maintenance_standing` `v1_seed_standing`. cli_run.rs is hand-Rust by
declared seed deferral, not an emitted mirror, so no regeneration is involved:
`std.realization_schedule` `walk_plan_run_stage_claim_executor_seed_deferral`.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* The tell is worth more than the specimen: two independent implementers producing the SAME wrong answer

The state-space conflation entry names one form -- not-applicable rendered as
malformed -- with a recognition rule keyed on an arm downstream of a search that
returned `Absent`. The specimen in this PR does not match that shape and is the same
class, so this records a second form: A DICHOTOMY STATED OVER A DOMAIN WITH THREE
STATES.

WHAT MAKES IT WORTH A SEPARATE FORM IS NOT THE SPECIMEN, IT IS THE TELL. A genuine
gap produces divergent readings or an error. A dichotomy over a larger domain
produces CONVERGENT WRONG ONES, because every reader matches on whichever condition
is cheapest to evaluate and the neglected state satisfies it -- here `pswpin flat`,
which zero-and-zero also satisfies, so the arm was selected on one of the two
conditions whose CONJUNCTION was meant to define it.

Receipt: 26 intervals so classified by one reader, 6 by another, neither having
compared notes.

The convergence is what made it invisible, since agreement reads as confirmation.
So the operative rule points the other way from the usual one: when two independent
readers of one rule agree on something surprising, suspect THE RULE of being a
dichotomy over a larger domain rather than treating the agreement as corroboration.
That is the lineage law from the other direction -- agreement is not evidence when
the readers share a defect, and here the shared defect is in the thing they both
read.

Lands beside the comment fix rather than in a separate PR because it is the same
finding and the same receipt; separating them would put the rule in one review and
its evidence in another.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* The tell claimed more than n=2 on one specimen can establish; it is a prompt to re-derive, not a diagnostic

Review 56194 (codex) is right and this is conceded rather than argued. The text read
that a genuine gap yields divergent readings while a dichotomy over a larger domain
yields convergent wrong ones -- stated as canonical guidance, that invites a future
reader to INFER a specific modeling defect from evidence that does not uniquely
identify it.

WHAT THE RECEIPT ACTUALLY SUPPORTS: two readers made the same mistake, once. It does
not support the converse direction, and I had no evidence at all for the half about
what a genuine gap produces -- that clause was invented to make the contrast
symmetrical.

CONVERGENCE HAS COMPETING CAUSES THE RECEIPT CANNOT SEPARATE: shared assumptions, a
common heuristic, ambiguity in the subject, or one reader having anchored on the
other. n=2 on one specimen distinguishes none of them from a defect in the rule.

The irony is worth recording rather than smoothing, because it is the same shape I
refuted in myself four hours ago: a perfectly agreeing n=2 read as a mechanism. There
it was two runs inverted on both axes and it did not replicate at n=34. Here it was
two readers agreeing, and I wrote it into the authority document.

WHAT SURVIVES, and it is the concrete half codex asked to keep:
  - the three-state specimen and why the two-arm form misleads
  - a recognition rule keyed on STRUCTURE rather than on reader behaviour: for every
    arm of a stated dichotomy, enumerate the domain and check that each arm's
    conditions are required jointly
  - the weaker and defensible direction only -- agreement between readers of one rule
    is not INDEPENDENT evidence about that rule, since the shared input is a shared
    potential defect, so it licenses re-deriving from the domain and never a
    conclusion about which cause produced it

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* The comment carried the same overclaim this PR corrects in DESIGN, one file away

Review 56201 (codex) caught an internal contradiction and is right. The previous
commit narrowed the DESIGN entry to say convergence has several possible causes and
is a prompt to re-derive rather than a diagnostic -- and left the cli_run.rs comment
asserting that a dichotomy over a three-state domain "hands every faithful
implementer the same misreading."

Two readers do not establish a universal. So the PR corrected the overclaim in the
canonical document while shipping it in the source comment, which is worse than
either alone: the two artifacts now disagreed, and a reader who found only the
comment would take the stronger claim as current.

WHAT REPLACES IT is the structural half, which is what was actually established:
zero-and-zero satisfies `pswpin flat` and not `pgmajfault rises`, so a reader
matching on the cheaper condition alone selects churn for it. That is a fact about
the RULE's shape, checkable by reading the rule, and it does not depend on how many
readers were surveyed. The sentence now says explicitly that it is an observation
about this rule and these two readings, not a prediction about future readers.

This is the second time in this PR that the concrete structural claim survived and
the generalisation layered on top of it did not.

MEASURED, remote: `cargo check -p v1-compiler` Finished, exit 0, against a
`-Z nope-not-real` control that exits 101. `cargo fmt --all --check` exit 0.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant