Repository navigation
Give the infer-semantics witness bin the TypeEnv field it has been missing, so cargo build --bins stops failing on main - #9205
Conversation
…ssing, so cargo build --bins stops failing on main
src/v1/stage0/Cargo.toml declares [[bin]] infer_semantics_witness, and it
does not compile:
error[E0063]: missing field `authored_import_names`
in initializer of `TypeEnv` x6
at 317, 1040, 1068, 1096, 1226, 1929
TypeEnv is generated (v1_compiler_infer_env.rs, from 04_env.dag) and gained
authored_import_names; this bin is HAND-AUTHORED Rust and its struct
literals fell behind. Both files are byte-identical to main, so `cargo build
--bins` fails on main today.
WHY NOTHING CAUGHT IT. This is the class DESIGN's 2026-08-25 row declares --
no required phase compiles the Rust workspace -- but by a mode that row does
not enumerate. The .dag side is clean: 04_env.dag compiles, the generated
mirror compiles, the corpus compiles. What drifted is a hand-authored Rust
consumer of a generated type, which nothing in the .dag world can observe.
CI has no cargo build, no cargo test (removed 2026-07-11) and no clippy
(removed 2026-07-08), and cool-hawk-324's incoming required job builds
exactly the two bins the jobs run, not --bins -- a boundary that PR states
rather than widens, correctly, since widening the required check is an
operator decision.
THE VALUE IS Rc::new(im::HashMap::new()), matching this bin's own idiom for
its sibling map fields, NOT v1_rt::rc_empty_map -- which is what the library
modules use and what I tried first. v1_rt is not in scope in a bin crate
root, so that attempt traded six E0063 for six E0433. Recorded because the
sibling-file idiom looks obviously correct and is not.
RECEIPT, by execution rather than by the edit looking right:
cargo build --release --bins -> EXIT=0, infer_semantics_witness linked
./infer_semantics_witness -> runs to completion, EXIT=0
The bin is silent on success and carries 126 assert/panic/exit sites, so
exit 0 is its passing verdict rather than an absence of checking.
NOT CLAIMED: that the witness's assertions are the right ones, or that an
empty authored-import universe is semantically what each of the six call
sites wants. This restores a declared bin to compiling and passing; it does
not audit what it asserts.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DRMbwdtHZxTiMNZD5WLS3P
witnesses.yml builds 2 of the 16 bin targets v1-compiler declares, so 14 are absent from the build selection and nothing required compiles them. Combined with the Rust suite removed from CI 2026-07-11, clippy 2026-07-08, and the compile-clean gate deleted in the floor cut, a bin can go stale silently -- and one had: #8952 added authored_import_names to TypeEnv without updating infer_semantics_witness, leaving main red at 'cargo check -p v1-compiler'. That specimen is being repaired separately in #9205; this is the standing that stops the next one. Two populations were answered by one roster: RuntimeArtifactPopulation -- the executables this job RUNS (claim_executor, gunbc) BinaryCompilePopulation -- every bin target the manifest DECLARES witness_floor_required_bins is correct as the first and is left alone. Derived, not a second roster: the step calls repo_self_build_command(bins: []), whose no-selector form gunbc.repo_self_build already documents as cargo's meaning for 'build every target'. A new [[bin]] joins the standing with no edit anywhere, and no new argv word is minted. Build rather than check, decided by measurement: from a cold target dir with the two-bin build already paid, building every target cost 12s against 52s for 'cargo check --release --bins', and it additionally links. Placed LAST, after the fold and the roster uploads, guarded by !cancelled(): ahead of the fold it would be a preparation mask, and an auxiliary compile error would take the floor's ledger with it.
|
REVIEW (manager, smart-ram-730) — no blocking defect. The build break is real and this closes it: ONE FOLLOW-UP, NOT A BLOCK, because it is the reason this PR exists rather than a defect in it. Three of the five patched sites — the That is the §5 tell: the invalid state (a literal missing a field) stayed writable, so the field addition had to be re-applied by hand at each site, and it will have to be again on the next field. Collapsing those three to Not asking for it here: main is broken and this unbreaks it at the right grain. — sent from smart-ram-730 |
…ted-symbol row, take main's updated emit-stage row
…ch was masking this branch's test-target observation
…9196) witnesses.yml builds 2 of the 16 bin targets v1-compiler declares, so 14 are absent from the build selection and nothing required compiles them. Combined with the Rust suite removed from CI 2026-07-11, clippy 2026-07-08, and the compile-clean gate deleted in the floor cut, a bin can go stale silently -- and one had: #8952 added authored_import_names to TypeEnv without updating infer_semantics_witness, leaving main red at 'cargo check -p v1-compiler'. That specimen is being repaired separately in #9205; this is the standing that stops the next one. Two populations were answered by one roster: RuntimeArtifactPopulation -- the executables this job RUNS (claim_executor, gunbc) BinaryCompilePopulation -- every bin target the manifest DECLARES witness_floor_required_bins is correct as the first and is left alone. Derived, not a second roster: the step calls repo_self_build_command(bins: []), whose no-selector form gunbc.repo_self_build already documents as cargo's meaning for 'build every target'. A new [[bin]] joins the standing with no edit anywhere, and no new argv word is minted. Build rather than check, decided by measurement: from a cold target dir with the two-bin build already paid, building every target cost 12s against 52s for 'cargo check --release --bins', and it additionally links. Placed LAST, after the fold and the roster uploads, guarded by !cancelled(): ahead of the fold it would be a preparation mask, and an auxiliary compile error would take the floor's ledger with it. Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
…ugh the grammar (#9242) * Split the required run into two parallel jobs, and correct the ruling the split supersedes The required run's four phases are mutually independent and were also SERIAL, because one process runs them one after another. That is the expensive combination: the witness floor costs ~30-40 minutes and every other phase waited behind it for no reason a data dependency names, so the required check's wall clock was a SUM of things that could have been a MAX. Operator ruling 2026-08-25 ("we can add it as a parallel job in github actions - we can do the same for regen now, we have more runners" / "basically i would put regen + v2 full compile in one job, and witnesses into another one"). Two jobs, no `needs` edge: build regen first-generation comparison + the v2 emission compile witnesses the .dag parse sweep + the witness floor fold Each job makes ONE invocation of claim_executor and names a LANE. It does not name phases, order them, or wire one phase's precondition to another step's outcome -- which phases a lane owns is `RequiredCiPhase::lane`, an exhaustive match, so a phase belonging to no job fails to compile rather than going silently unmeasured. Every run prints a ROUTED line for each phase it does not own, so one job's log names the whole roster and where the rest is measured. THE 2026-08-20 CONSOLIDATION DIRECTIVE IS CORRECTED, NOT SILENTLY CONTRADICTED. It has two halves and only one is superseded. SURVIVES -- "within the gunbc binary": the phases still live in the binary and the step-ladder defect the consolidation fixed cannot return. SUPERSEDED -- "not at a github actions job level": parallelism is not expressible in one process, so the lane boundary is a job boundary of necessity, and what the directive protected against (sequencing and preconditions leaking into YAML) is exactly what does not cross it. Both halves are now stated in DESIGN's CI clause, in `gunbc.fabric_witness_run`, in `gunbc.witness_floor_workflow` and in the consolidation witness file. THE v2-EMISSION SUBJECT WIDENED in the same change, from `dag/std/abi.dag` to `src/v2/compiler/00_compile.dag`. The cost that argued for the smallest entry was a cost against a SERIAL run; the build lane's cost is now free up to the floor's duration. Measured by emitting both closures and differencing the file sets, the widening gives up exactly one file of coverage, `src/std_abi.rs`, and the row says so rather than claiming total subsumption. Executed evidence: - both lanes run, and route correctly: `lane=witnesses` runs parse and floor and routes regen and v2-emission; `lane=build` runs regen and v2-emission and routes parse and floor - an unknown lane word refuses with exit 2, it does not default - the v2 compiler entry compiles clean under the phase's own producer and pinned pool index (0 blocking) - six consolidation witnesses pass, including two new ones for the split - both new REDs flip under mutation and restore: adding a `needs` edge reds the parallel claim; collapsing to one job reds the two-lane claim - the lane-command claims verified through a scratch probe with a control that returns false NOT DONE, named rather than absorbed: no ratchet over the v2 compile's advisory population (a count pinned to the current tree is the oracle DESIGN §5 rejects; the honest form is an identity-grain monotone debt contract, a separate construction). Nothing else is restored from the deleted floor machinery. And the build step still compiles only the two bins the jobs run -- a declared `[[bin]]` outside that set is uncovered, with a live specimen on main today (`infer_semantics_witness`, six E0063s); widening to `--bins` changes what the required check covers and is an operator decision, so it is declared here rather than taken. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01SAQiYQiQ7SsdxvotAFbUFc * Correct the workflow module's own stale recital of the consolidation directive The supersession was recorded in DESIGN, in gunbc.fabric_witness_run, in the consolidation witness file and in the binary's own roster block -- and NOT in the paragraph inside gunbc.witness_floor_workflow that quotes the 2026-08-20 directive and describes the job as ONE INVOCATION, FOUR PHASES. That paragraph sits directly above the run step the split changed, so it is the one a reader reaches first, and leaving it standing would be the premise contamination this change exists to remove -- one document corrected while its own subject still recited the superseded ruling in the present tense. It now states both halves: 'within the gunbc binary' survives, 'not at a github actions job level' is superseded because parallelism is not expressible in one process. The step-ladder paragraphs below it are kept rather than rewritten, because what they establish is unchanged by the split and deleting them would take the reasoning with them. Also corrected: the step no longer passes 'the source roots and nothing else' (it passes a lane word), and the phase roster is four across two lanes rather than the 2026-08-21 three. Comment-only in emission terms: witnesses.yml regenerates byte-identical. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01SAQiYQiQ7SsdxvotAFbUFc * Make the split fail-closed: the required context now gates on both lanes Review of #9203 (review 55786, codex/gpt-5.6-sol) found the split fail-open, and it was right. Verified against the live ruleset rather than against the workflow, which is the only place the fact is visible: `passing CI` is active, carries NO bypass actors, and names exactly ONE required status check -- `witnesses`. A GitHub required context is produced by the JOB, not the workflow, so moving regen and v2-emission into a second job made them NON-BLOCKING: the required check would go green over a regen drift or a v2 emission break and the PR would be mergeable. That is strictly worse than the serial run it replaced, because the serial job carried every phase into the one context that gates. THE REPAIR, and why it is an aggregation job rather than a ruleset edit. The floor lane is renamed `floor`; the name `witnesses` moves to a job whose only step reads both lanes' results and exits nonzero unless both succeeded. The two lane jobs still carry no `needs` edge on each other and still start together -- only the aggregator waits, and it does nothing but read two results. A ruleset edit would also have worked and was rejected on a boundary DESIGN already records: the ruleset is not a `.dag` fact, so landing a change whose safety depends on someone editing a setting afterwards is a coverage gap with a promise attached and a real window in which the lane is unguarded. `if: always()` IS LOAD-BEARING, and its absence would have been the same fail-open one level in: a step with no `if` inherits `success()`, so it would be SKIPPED exactly when a lane failed, the job would report success, and a skipped required check does not stop a merge. The aggregator is the only place in this workflow that authors shell text, and that is stated on the carrier: there is no modeled value to render, because GitHub has no declarative "this job fails unless those jobs succeeded", and the nearest declarative form is the skip that fails open. The script is built from the job-id declarations rather than spelling `needs.build.result`, so a rename moves both sides together instead of rendering an unknown context as the empty string. WITNESS CORRECTION, not just an addition. `w_RED_neither_lane_waits_on_the_other` asserted the file contained no `needs:` at all -- the right claim for a workflow shape that was wrong, and a row that would have made this repair unrepresentable. It now forbids each single-lane edge and REQUIRES the aggregator's two-lane one, which distinguishes the serialization being forbidden from the aggregation being demanded. A third row asserts the gate runs and refuses. Executed evidence: all seven consolidation witnesses pass, and three mutations red the right rows and restore -- serializing floor onto build reds the parallel claim, dropping `always()` reds the gate claim, and deleting the aggregator reds the parallel claim. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01SAQiYQiQ7SsdxvotAFbUFc * The aggregator's guard belongs at the JOB level: a skipped job never reaches its step Review 55795 and a peer session independently found, within minutes of each other, that the fail-closed repair was itself fail-open one level in. `needs` carries an IMPLICIT JOB-LEVEL CONDITION. A job that declares `needs` and no `if` is SKIPPED when any needed job fails, is skipped, or is cancelled. A skipped job never starts, so it never reaches its steps, so the step-level `always()` could not fire -- and a skipped required check does not stop a merge. The aggregator introduced to close the fail-open would have gone skipped-and-mergeable over precisely the failed lane it was there to catch, with the guard present in the file and reading as correct. `always()` AT JOB LEVEL, AND THIS IS THE ONE PLACE THAT DEPARTS FROM THE FILE'S `!cancelled()` HOUSE GUARD -- said in the carrier, in DESIGN and in the witness, because a reader who knows the convention will otherwise correct it back and reopen the hole. Every other guard here decides whether a STEP runs inside a job that is already running, where `!cancelled()` is right. This one decides whether the REQUIRED CONTEXT EXISTS AT ALL, and under `!cancelled()` a cancelled run leaves it skipped rather than answered. That would turn the outcome on a question about GitHub nobody here has executed -- does a skipped or cancelled required check block a merge -- and the response is not to go measure it but to make the answer not matter. Under `always()` the job always runs, always reads both results, and always reports on its own terms; SKIPPED disappears from the required context. Cost, named: a lawfully superseded run now reports this context red rather than cancelled. That is the correct reading, not a regression -- a superseded run's evidence must not admit a merge. THE WITNESS WAS WRONG IN THE SAME WAY AND IS FIXED WITH IT. It asserted `if: always()` appeared SOMEWHERE in the file. It did -- on the step -- so it went green over the defect. That is DESIGN's total-at-the-level-examined failure: true, and about the wrong level. It now discriminates on emitted INDENTATION, which is the only thing in the text that separates the two levels (a job key at four spaces, a step key at eight), and asserts both. Executed: the strengthened row PASSES on the fix and FAILS on a mutation that removes the job-level guard -- i.e. it catches the exact defect that shipped. All seven consolidation witnesses pass. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01SAQiYQiQ7SsdxvotAFbUFc * Say what the v2-emission phase actually covers: 24 of 42 compiler modules, measured Operator clarification, 2026-08-25: "the intention is to v2 build ALL of the .dag compiler files, and then ratchet THAT count in CI". Measuring against that ask showed this PR's own prose overclaims, so the claim is corrected before anything is built on it. MEASURED, by emitting the entry and joining the emitted file names against the module line of every src/v2/compiler/**.dag: of the 42 modules under src/v2/compiler/, 00_compile's closure emits 24. Eighteen are absent, including ingest, emit_module, emit_host, emit_produced, emit_semantic_decl, program_partition and self_host. Counting the self_host/ subtree the compiler namespace is 69 modules, so the shortfall is larger again. "The widest closure one entry names" was true and is kept; "full v2 compile" invites the reading that the phase covers the compiler, and it does not. That reading is exactly the premise contamination this repository keeps paying for, so the row now states the covered population rather than leaving a reader to assume it. AND A METHOD NOTE THAT COST A MEASUREMENT: a static import-closure estimate CANNOT substitute here. It reports ZERO compiler coverage for this entry, because this corpus resolves most cross-module references without import lines. Only the compiler's own reference-derived closure is the truth, which means a covering entry set cannot be derived from the import graph either -- it has to be measured by emission. The widening itself is NOT taken here: it needs either a measured covering entry set or a whole-tree emission whose cost has to be known before it is enrolled in a required lane. This row makes that widening a change to a known number instead of an assumed one. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01SAQiYQiQ7SsdxvotAFbUFc * Receipt: the gate refused two cancelled lanes, and 'abandoned' is a state nobody knew about Run 32883390033 (2026-08-25) ended BOTH lanes by a fleet event with no push involved. The aggregator ran anyway under its job-level always(), read the two results, refused, and published the required context witnesses as a FAILURE. That is this gate's first executing receipt and it is the behaviour the pre-repair shape could not produce -- there, the aggregator would have been skipped. AND THE RUN SURFACED A needs RESULT VALUE NOBODY HERE KNEW WAS REACHABLE: BUILD="cancelled" FLOOR="abandoned" The gate handles 'abandoned' correctly only because it compares != "success" rather than enumerating bad states. The form a reader's instinct reaches for -- == "failure" || == "cancelled" -- would have admitted it and reported the required context GREEN over two lanes that never ran. So the strict inequality is now recorded on the carrier as a measured fact rather than left as a style choice, because the obvious 'improvement' to an explicit list is a fail-open. That is the difference between a closed vocabulary and a remembered one: the inequality admits exactly one state and refuses every other, including the ones the author has never heard of. Comment-only in emission terms: witnesses.yml regenerates byte-identical. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01SAQiYQiQ7SsdxvotAFbUFc * Record the argument against always() beside the decision to keep it A peer session raised the strongest objection to the job-level always() guard, from GitHub's documented semantics rather than from a measurement, and it is correct on every fact it asserts: always() is the one condition that survives workflow cancellation, cancel-in-progress is armed on every pull_request so this fires on the MODAL event, and it destroys the cancelled/failed distinction at the RECORD level where nothing can recover it. That ambiguity cost that session hours in one day, diagnosing 38 lawful supersessions as a false-red epidemic. The file's house guard really is !cancelled() everywhere else. It is not taken, and the reason is an asymmetry about WHICH HEAD PAYS. Checks are tracked per head SHA, so a superseded run's red lands on a head that by construction is never merged -- the push that superseded it created the head that will be. always() is noisy on ABANDONED heads. !cancelled() moves the cost onto the LIVE one: a lane killed with no replacement run coming, observed twice on 2026-08-25 (once with runner_name empty and zero steps, once with both lanes ended at 18:43 and no push involved), leaves the required context SKIPPED on the head that is still the merge candidate -- which is precisely the unmeasured GitHub behaviour the guard exists to stop depending on. Quiet-and-unknown on a live head is worse than loud-and-definite on a dead one. The mechanism half of the objection is now MEASURED rather than documented: run 32883390033 had both lanes ended by a fleet event, and this job published failure while the run conclusion was cancelled. So the behaviour the objection predicts is real; what is disputed is only whether it is the wrong trade. Recorded in the carrier rather than answered away, so the next person who wants !cancelled() finds the case already made instead of rediscovering it. Comment-only in emission terms: witnesses.yml regenerates byte-identical. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01SAQiYQiQ7SsdxvotAFbUFc * One compilation transaction, subject-parameterized; the gate emitted as nodes Four things, in the order the operator's dispatch puts them. ONE. The build lane bootstraps `cargo build --release -p v1-compiler --bins`. Host-Rust coverage of the whole declared bin roster is a fact somebody has to establish, and a bin no consumer selects is precisely the one that rots unobserved -- #9205 repaired one such bin after it had drifted with nothing building it. The floor lane keeps the two bins it executes; the lanes are runtime-independent, so their bootstraps are independent CPU rather than a shared prerequisite one could save. TWO. THE DAGLANG COMPILATION FORK IS CLOSED. `cli_run` now carries `CompileSubject{Entry|PrimaryRoot}`, `CompileRequest` and `compile_emission`, and the transaction owns indexing and precedence, subject source-set construction, census fill, memory admission, resolution and compilation, the blocking/advisory split, silent-pick capture and the disposition. `compile_entry_emission` survives as a wrapper with no semantics of its own. Before this, `gunbc compile` without `--entry` implemented a SECOND index/load/resolve/admit/compile/refuse pipeline in `main.rs`, beside the transaction rather than through it. They differed in ways nobody had decided: the whole-root arm applied the memory-admission gate and the entry arm did not, the entry arm ran the silent-pick gate inside the transaction and the whole-root arm ran it around the outside, and their refusal subjects were spelled differently. That is DESIGN section 3's two-authorities-for-one-fact, and it is the reason a whole-tree ratchet could not be built on the existing phase: the ratchet would have observed a different producer from the gate beside it. The arms' real differences are KEPT, which is why this is a coproduct and not a flag: admission is asked of the whole root and not of an entry (an entry's working set is its closure, measured to fit on the runner that SIGKILLed a whole-tree run -- an unasked question, not an all-clear), and the closure derivation genuinely differs (reference-derived for an entry, import-edge for a root where every module is already an entry). A `PrimaryRoot` matching no module refuses at `subject-discovery` rather than reporting `Completed { 0 }`, which would be the empty-observation narrow. THE DELETION WAS THE CENSUS. Routing the whole-root subject through the transaction left ~200 lines in `main.rs` with no caller, and rustc then found seven more private copies of module indexing and import walking -- `extract_module_path`, `report_moduleless_dag_entry_skips`, `extract_import_paths`, `insert_module_path`, `index_source_root`, `build_module_index`, `resolve_transitively_with_seen`. All deleted; their two tests re-pointed at the surviving `cli_run` authority rather than retired with the function, per DESIGN section 4b(4). Multi-target (`--target a,b`) still walks the old loop and is named rather than exempted. THREE. `pr_owner` AND `cycle_owner` REFUSED FOR A REASON THAT IS NOT IN `review_codex.dag`. `owner` has TWO declarations in the flat whole-tree namespace -- `data owner` in `gunbc.tools.review_codex` and `fn owner(uid, gid)` in a srv3 path-ownership test -- and the winner is fold order. When the function won, the CLI defaults resolved to it and refused with `must be a string, int, float, bool literal, or data reference`: two blocking diagnostics in a file that had not changed, produced by a test helper in another directory. The discriminating pair is what establishes that, and it was measured rather than reasoned. `repo` is declared beside `owner` in the same module, has no `fn repo` anywhere in the corpus, and does not refuse. `default_model` IS declared twice -- `tools.review` and `tools.review_codex` -- and does not refuse either, because both declarations are data, so either winner satisfies the default's requirement. Collision alone is not the fault; collision ACROSS DECLARATION KINDS is. Fixed by renaming the test helper to `owner_spec`. The class is untouched and the annotation says so: a bare cross-kind homonym is still writable and still resolves by fold order. Its next-rung trigger is a refusal at name resolution when one flat name carries declarations of different kinds -- decidable from the index the compiler already builds -- not a roster of forbidden names. FOUR. THE REQUIRED-LANES GATE IS BUILT AS NODES, NOT SPELLED AS TEXT. `gunbc.required_lanes_gate` constructs it through `v2.extdeps.languages.bash_build` and `witness_floor_workflow` serializes it through `v2.workflow.bash_command_fold_serialize` -- the `tools.build_step` -> `v2.workflow.build_step_emit` precedent. Raised as review 55836's medium-as-string finding, which was correct: I had argued no modeled value existed to render, and the language was fully modeled the whole time. Declaring a language-layer gap without enumerating the language is the failure DESIGN records in its own section 6 receipt. The Rejected arm REFUSES rather than rendering nothing, because an empty `run` exits 0 and would make the required context green over two lanes it never read. The emitted text was executed against all three arms: success/success passes, success/failure and cancelled/abandoned each print the error and exit 1. ALSO LANDED, NOT YET WIRED: `gunbc.v2_rustc_debt` models the monotone identity ledger -- key (emitted-crate-relative path, rustc code), admission iff observed equals the current ledger AND the current ledger is a multiplicity-wise subset of the baseline's -- with eleven fixture arms that author both input and expectation. Both totals are receipt-only and reach no verdict. Its host observation is deliberately absent: an observer built before a whole-tree emission can be produced would be an observer with no subject. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01SAQiYQiQ7SsdxvotAFbUFc * The subject is a field, the precedence root is a refusal, and the fork is three callers wide FOUR CORRECTIONS, three of them from an operator ruling on the measured report and one from the census that ruling asked for. ONE. THE ALIAS DIRECTION WAS BACKWARDS. It read `pub type CompileRun = EntryEmissionRun`, which makes the generic name an alias of the entry-named authority -- so the canonical carrier stays the one named for a subject it no longer describes, and every reader is sent to a type whose name contradicts two of its three uses. `CompileRun` and `CompileDisposition` are now the types; the entry-named spellings are the compatibility aliases that disappear with their last caller. TWO. `run.entry` SILENTLY WIDENED TO HOLD A DIRECTORY. A consumer reading it after a `PrimaryRoot` compile got a root from a field promising a file -- one name, two meanings, which is the section 3 violation the fork closure exists to remove, reintroduced one field down. It is now `subject: CompileSubject`, and the receipt names the ARM rather than the path: `subject=primary-root:src/v2`, not `subject=src/v2`. The two read identically to a human and differently to anyone deciding whether a run measured what it was asked for, which is the whole reason the field exists. THREE. THE SUBJECT AND THE PRECEDENCE ROOT NOW HAVE TO AGREE, AND DISAGREEING REFUSES. The trap is entirely in argv order and invisible from the receipt: the live workflow passes `--source-root dag --source-root src/v2`, and the no-entry CLI law is `PrimaryRoot(source_roots[0])`, so THAT argv asks for `PrimaryRoot(dag)` with `src/v2` as a pool. A caller who means "compile v2" and writes the roots in the workflow's habitual order gets the other subject, compiles ~2000 different modules, and is told the compile completed. This is not a scope difference, it is a RESOLUTION difference, and it already cost a measurement: `dag`-primary refuses on two `review_codex` CLI defaults that `src/v2`-primary never reaches, and `src/v2`-primary refuses on 36 diagnostics `dag`-primary never sees. The 9.06 GiB peak and the `owner` diagnostics reported earlier are the `dag` subject; they were reported under a heading that implied the v2 one. A ledger bootstrapped from the wrong subject is not a coarser ledger, it is a ledger about another population. `primary_root_agrees_with_precedence` makes the disagreement unwritable rather than merely detectable. FOUR. THE FORK IS THREE PRODUCTION CALLERS WIDE, NOT ONE. The census over `compile_sources`, `compile_sources_with_options`, `compile_to_resolved_with_options`, `emit_resolved_for_target` and `stage0_self_compile_refusal_message` classifies every caller: 46 compiler_tests / compiler_tests_rust kernel test, legitimate 2 v1_probe_emit_interp generated kernel probe, legitimate 2 v1_compiler_emit_rust compiler implementation, legitimate 9 cli_run compile_emission implementation 5 main.rs DECLARED VIOLATION (multi-target loop) 2 required_regen_host DECLARED VIOLATION (needs ExactSourceSet) 2 bin/bootstrap_witness DECLARED VIOLATION (not previously named) `bootstrap_witness.rs` compiles EVERY `.dag` file under `dag/` to Rust, which is exactly the invariant's subject -- a repository source population producing an artifact tree -- so it is a production route and not a kernel probe. It carries its own `build_module_index`, `build_module_index_for_roots` and `resolve_imports_transitively`: a FOURTH private copy of the machinery this branch deleted from `main.rs`, in a 1289-line binary the floor lane builds and runs. It can disagree with the transaction about what the `dag/` population IS, and nothing would say so. None of the three violations is closed here. They are named, classified, and ordered: multi-target into the request as a target set, then regen and bootstrap_witness through an exact-source-set subject, both of which select a population by their own authority rather than by directory. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01SAQiYQiQ7SsdxvotAFbUFc * Hoist two §4c-illegal in-body annotations, and restore the module-less skip report the consolidation dropped Two fixes, both of them corrections to my own work on this branch. §4c: `v2_rustc_debt_ratchet_test.dag` carried two `//` lines INSIDE a `test fn` body. Only module-item grain is modeled, so strict preparation refused and the build lane went red on #9242. Hoisted above the declaration. An awk brace-depth census over every file this branch touches confirms no in-body annotation remains. Module-less visibility: the deletion note in `main.rs` claimed the module-less-entry skip report was "the one behaviour with no counterpart" in `cli_run`. That was FALSE -- `report_moduleless_dag_entry_skips` and `moduleless_dag_entry_paths` are both `pub` there with tests, and were never deleted. The note asserted an absence without grepping for it, which is the one claim a later reader will not re-check. The behaviour is now wired into the transaction's `PrimaryRoot` arm through those same two functions. It matters there specifically: the subject is discovered from `index.source_files`, keyed by module path, so a `.dag` under the root with no `module` declaration is absent from the subject and the transaction would report `Completed` over a population that silently excluded it. The empty-root refusal cannot catch this, because a root holding one good file and one forgotten one is not empty. It REPORTS rather than refuses, declared as the weaker arm: a module-less `.dag` is a legitimate parse fixture today, so refusing would break real callers. Terminal form is a total role classification under which an unclassified `.dag` refuses. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01SAQiYQiQ7SsdxvotAFbUFc * Route multi-target compiles through the one transaction, validate all three debt populations, and read the verdict as itself Six review findings, each fixed rather than answered. MULTI-TARGET REGRESSION (blocking). `--source-root X --target rust+dag` fell past the routing gate -- which conjoined the subject with `render_targets.len() == 1` -- into a branch whose only remaining subject is `--source-dir`, and exited "provide --source-root or --source-dir" over an argv that provided one. `CompileRequest` now carries a target VECTOR: resolve once, emit per target, and materialize NOTHING until every target has completed, so one target's tree is never left on disk beside another's refusal. The disposition, the blocking count and the refusal are over the whole emission set, not the first target. Single-target callers -- every required one -- run the identical computation, because `compile_sources_with_options` IS `emit_resolved_for_target ∘ compile_to_resolved_with_options`. Two discriminating arms: two targets produce two named emissions from one resolution, and a request naming NO target refuses at its own `target-admission` phase rather than reporting `Completed { emitted_count: 0 }`. DEBT LEDGER FAIL-OPEN (blocking). Positivity and uniqueness were asked of the LEDGER only. A duplicated key in the OBSERVATION makes the multiplicity lookup answer with whichever row the fold reaches first, so the comparison silently compares the wrong quantity and the run reads as held. All three populations are now validated -- positivity, uniqueness, and strictly ascending canonical order -- through one `DebtPopulationMalformed { population, cause, keys }`, with `population` a closed coproduct because the three have different owners and different repairs. Order refuses rather than sorts: sorting would make two textually different ledgers compare equal and stop a ledger diff being reviewable. THE BLIND-SPOT FIXTURE AUTHORED NO SUBSTITUTION. It passed `one_error()` on both sides and CLAIMED in prose that the two were different errors, which made it a tautology wearing a substitution's name. It now authors `SyntheticRustcDiagnostic` values carrying a latent site, asserts FIRST that the two populations differ, and then that bucketization erases the difference. NO BOOLEAN COLLAPSE OF THE VERDICT (review 55911). `rustc_debt_verdict_admits` matched every variant and returned one bit, so a consumer refusing on it prints "the ratchet refused" and the author re-derives the cause by hand. Deleted. Every test arm now asserts WHICH verdict, which is strictly stronger: an arm authored to provoke `LedgerExceedsBaseline` used to stay green when the contract refused it as malformed for an unrelated reason. VOCABULARY. `admitted_multiplicity` -> `multiplicity`; `identities` -> `buckets`, in the model, the receipt and the test names -- the count is per (path, code) bucket and calling it an identity is the inflation the blind-spot arm exists to deny. RENAME FINISHED. The entry-named aliases are deleted, not merely re-pointed; two spellings for one type is the same §3 violation one layer out. Also: the census behind "one compilation concept" is now stated at CALL-SITE grain with its forks named, the `CompileSubject` comment no longer calls the import walk "the authority" (it under-pulls by construction -- the namespace is flat -- and the census fill covers the difference), the precedence check declares its rung and its terminal `SourcePool` form, and a `TypeEnv` field missing at one test site is filled so `cargo test --lib` builds at all. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01SAQiYQiQ7SsdxvotAFbUFc * Build the unrenderable-gate refusal from the Bash grammar too, and split the unwired debt model out of this PR Review 55923, both findings, neither deflected. THE RAW SHELL FALLBACK IS DISSOLVED, NOT MARKED. `required_lanes_gate_unrenderable_script` was an executable program spelled as a String and handed to a RunStep -- the medium-as-string violation this PR otherwise removes, surviving in the one arm nobody reads, inside the module whose own header argues against exactly that. The refusal is now Nodes in `gunbc.required_lanes_gate`, beside the gate it stands in for, serialized through the same fold. The outcome is three-state rather than two, and the third state is what removes the last fabricated value: the gate serializes -> the gate; the gate rejects but the refusal serializes -> the refusal, which stops every run loudly; both reject -> Absent, and `expected_witness_floor_yml` returns `WitnessFloorGenerationRefused` so no yaml exists at all. A Rejected fold can no longer reach a published step. The one remaining `""` is not a program and is reachable only when emission has already refused -- Daglang is total, so some value must inhabit the arm; what matters is that it is not a second spelling of a shell program and that no emission path reaches it. Verified rather than asserted: `required_lanes_gate_is_renderable` returns true by execution, and regen exits 0 with the workflow yaml BYTE-IDENTICAL -- only the unreachable arm moved. ON THE "on-carrier bash-emission scaffold marker": no such convention exists in this tree. A whole-tree search finds no `bash_emission`, `hand_shell` or `model_vs_runner` carrier. Removing the raw string makes the marker moot either way, which is the stronger repair. THE DEBT MODEL LEAVES THIS PR. `dag/gunbc/v2_rustc_debt.dag` and its fixture are removed and travel to the change that lands their consumer. The earlier review from the same provider offered keeping this PR open as the integration vehicle and I took that; a measurement since has changed the calculus. A whole-repo emission REFUSES ON MEMORY ADMISSION on the current runner class -- measured on BuildBuddy: budget 6.58 GiB against the modeled 7.00 GiB demand, `WholeCorpusCompileBudgetBelowMeasuredDemand`, zero files emitted. So the observer cannot be built until the resource-grant boundary is decided, and that decision is the operator's. Holding a foundational compilation PR open behind someone else's decision is worse than either option the review named. What remains here is the compilation consolidation and the gate repair: coherent, with consumers, mergeable on its own. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01SAQiYQiQ7SsdxvotAFbUFc * A target name carried beside its target can disagree with it; derive it. And the fork census omitted a fork Two remarks from the side-channel review, both verified against the code, both real. THE (NAME, TARGET) PAIR IS COLLAPSED TO A TARGET. `CompileRequest.render_targets` carried `Vec<(String, RenderTarget)>`, so `("dag", RenderTarget::Rust)` was constructible: two spellings of one fact, free to disagree, with the NAME deciding which directory a target is written to while the TARGET decided the bytes written into it. That is the §3 violation this transaction exists to remove, reintroduced one field down and in the same PR that removes it elsewhere. The name is now DERIVED through `render_target_name`, which is the CLI parse's inverse, so the disagreement has no representation rather than being checked for. `parse_render_targets` discards the authored spelling deliberately, because it is recoverable. THE CALL-SITE CENSUS OMITTED `required_regen_host`. `compile_stage0` calls `compile_sources` directly over `regen_input_sources` -- a fourth fork, and the census whose entire purpose is to enumerate forks reported it as absent. The file appeared in the file-level count I ran and did not survive into the call-site list I wrote from it, which is the incomplete-enumeration class this repository has recorded against itself twice before: a list transcribed from a wider measurement is not the measurement. It is now listed with its subject (an EXACT SOURCE SET from the regen roster -- neither a root nor an entry, so neither existing subject describes it), its terminal form, and the hardcoded refusal subject it still passes. The omission is recorded in the census itself rather than quietly corrected, because a census that has been wrong once should say so. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01SAQiYQiQ7SsdxvotAFbUFc * The refusal arm the PR defends was the wrong shape, and nothing executed could have caught it Review 55928, plus four findings from the thread review that survive at this head. THE MIDDLE RUNG WAS DEAD. `required_lanes_gate_unrenderable_stmts` was declared `-> List<Node>` and returned `bash_build_stmt_list_from_nodes(...)`, which is a single `Node`. Its caller passes it as `stmts: List<Node>`. So the arm this PR argues must stay executable -- gate rejects, the refusal still serializes, the run stops loudly -- was the wrong shape in exactly the place the argument is about, while the in-file receipt said it was Nodes through the same fold. Returns the raw list now, like `required_lanes_gate_stmts` beside it. THE REASON IT WAS POSSIBLE IS THE REAL REPAIR: the claim lived in prose, so nothing could contradict it. `the_unrenderable_gate_refusal_serializes_and_stops_the_line` now runs the fold over the refusal and reads the program back -- it must serialize, and must carry both the `::error::` annotation the operator sees and the `exit 1` that stops the line. THE CONTROL FLIPS, MEASURED RATHER THAN ASSUMED. Fixed shape: true. Defect restored: `PatternMatchFailure`, the fold choking on a Node where the list belonged. ONE HONEST QUALIFICATION: the red arrives as a RUNTIME ERROR, not a returned false, which is a weaker red than a clean false -- an erroring probe stops rather than asserting anything about its subject. Recorded because "the control flips" alone would overstate it. DUPLICATE TARGETS REFUSED. `--target rust+rust` parses to two targets, and each emission's directory is derived from the target, so both land in `output_dir/rust` -- the second overwriting the first while the run reports two completions. Refused at `target-admission`, not deduplicated: collapsing it silently answers a request nobody made and destroys the signal that the argv is wrong. THE MODULE-LESS WALK NO LONGER DROPS READ FAILURES. `if let Ok(content)` narrowed "every `.dag` under the root" to "every READABLE one" while still reporting under the wider name -- the empty-observation narrow inside the population whose entire job is to report what got dropped from the subject. Now a typed refusal at a `subject-read` phase. DOCUMENTATION THAT LIED. The root-order ruling sat immediately above `names_at_least_one_target`, so Rust attached the precedence contract to target admission; moved. "One entry, one render target" and "One entry's emission transaction" corrected beside code that handles two subjects and a target vector. The alias note's history example read `pub type CompileRun = CompileRun`, which is not a direction. And "reference derivation is not used here and that is not an oversight" sat directly above the fixpoint call that falsifies it -- it is used, because an import edge is weaker than a reference in a flat namespace and the walk under-pulls across the pool boundary. Regen exits 0 with no artifact drift. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01SAQiYQiQ7SsdxvotAFbUFc * Restore the entry-scope marker as a typed receipt: I deleted a consumer's evidence while tidying a sentence Three findings from the thread review, verified against the code before acting. THE SCOPE MARKER WAS MINE TO LOSE AND I LOST IT. Main prints "resolved N sources (reference-derived closure), M indexed modules"; consolidating the two CLI pipelines into one generic line dropped the parenthetical. It existed at the merge-base, so this is a regression on this branch and not a collision. `gunbc.emit_diagnostic_observation` `emit_entry_scope_marker` (landed on main via #9190, AFTER my change) matches that exact text and returns `EmitScopeUnconfirmed` when it is absent -- specifically so a whole-root compile cannot be reported as one entry's measurement. Merging main unchanged would have made every per-entry emission measurement refuse, from an edit that reads as prose cleanup. RESTORED AS A VALUE, NOT AN ADJECTIVE. `CompileScopeReceipt` is derived from `CompileSubject`, so the receipt cannot disagree with the run and cannot be lost by rewording. The entry arm carries the marker; the primary-root arm now STATES what it measured instead of being silent, so a consumer no longer has to infer scope from argv or file counts. The Rust literal and the `.dag` `data` row are two spellings of one fact -- unavoidable while that authority is `.dag` and this seed cannot read it -- so the constant is named `EMIT_ENTRY_SCOPE_MARKER` and cites its authority, making the pair greppable. THE TEST ASSERTS BOTH HALVES. Marker present on the entry arm, ABSENT on the primary-root arm. A receipt that carried it on both would be worse than one that carried it on neither: the marker exists to make the substitution refusable. THE PANICKING TRAVERSAL. My earlier "typed refusal" fixed the per-FILE read and left the DIRECTORY walk calling `collect_dag_files`, which is `collect_dag_files_result(..).unwrap_or_else(|e| panic!(..))`. A missing root, a regular file as root, or any `read_dir` failure bypassed `CompileDisposition` entirely. That was half a repair wearing the whole one's name; the walk is fallible now. TARGET ADMISSION ORDERING, PROVEN RATHER THAN ASSERTED. The new arm passes a subject that CANNOT be discovered, so if the duplicate-target refusal came after subject discovery the run would refuse at `entry-read` instead and the arm would fail. It proves the ordering, not merely the refusal. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01SAQiYQiQ7SsdxvotAFbUFc * The all-or-nothing materialization proof, with a RED that is actually authorable The CLI writes a tree only after the AGGREGATE disposition is `Completed`, so one target's refusal must withhold another target's finished files. That claim was asserted by the arm's structure and by nothing executable. BEFORE WRITING THE TEST I CHECKED WHETHER ITS RED CAN BE PRODUCED AT ALL, because a check whose red is unauthorable is a decoration -- permanently green by construction and worse than absent, since it gets cited as coverage (DESIGN §4b). It can: `file_emission_refusal` applies `target_renders_file_transport` FIRST and separately from `file_binding_refusal`, and that gate answers `Rust => true` with Python, Go and Dag all false. So a WELL-FORMED file-transport operation emits clean on Rust and refuses `FileTargetNotModeled` on Go. MEASURED on the new fixture root before any assertion was authored: `--target rust` emits 7 files with 0 diagnostics; `--target go` refuses, naming target 'go' and the missing file realization handler. The fixture is deliberately well-formed -- renderable path, product output shape, only modeled channels -- because a fixture with a real defect would refuse on BOTH targets and the test would pass for the wrong reason. Also measured, and it corrects the assumption I would have coded against: ordinary modules complete on every target (rust 6 files, go 3, dag 1, python 3, zero diagnostics each), so the refusal genuinely has to come from the transport gate rather than from picking an "unsupported" target. The test carries a single-target control (rust alone completes with a non-empty tree, so a future change that breaks the fixture cannot leave the test quietly asserting nothing), pins the refusal to the target-gate cause rather than any refusal, and asserts the refused run still holds the SAME file count the control emitted -- unwritten. That last assertion is the whole content: it distinguishes "the arm withheld a finished tree" from "there was nothing to write", and without it the property is vacuous. Also collapses `authored_import_names`, which the merge from main left specified THREE times in one `#[cfg(test)]` struct literal, breaking the entire lib-test target. A clean merge with no conflict, and no gate could see it: CI builds the binary and the Rust suite left CI on 2026-07-11. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01SAQiYQiQ7SsdxvotAFbUFc * The five transaction tests were unexecutable as written; they now execute, 5 passed The PR body said these arms were "type-checked only". That was too kind to them. They were not merely unexecuted -- they were UNEXECUTABLE: a test binary's cwd is the PACKAGE root while the fixtures live at the repo root, so every one of them panicked in `index_source_root_into_module_index` with `source root does not exist` before reaching a single assertion. Discovered by running the new atomic-materialization test, not by reading. FIRST FIX WAS WRONG AND THE WRONGNESS IS THE POINT. `set_current_dir(workspace_root())` looks correct and greened four of five. It is a race: cwd is process-global and cargo runs these tests in parallel, so a DIFFERENT PAIR failed on each run -- 4 passed/1 failed, then 3 passed/ 2 failed, with identical code. A flaky green here would have been worse than the original failure because it would have read as proof. Replaced with absolute paths derived from `workspace_root()`, which has no shared mutable state to race on. Also reads the `Refused` arm rather than routing it through `cause_of`, which destructures `NotExecuted` only. The first draft panicked on its own success: the run WAS `Refused { phase: "emit", cause: "... target 'go' ... transport emission is not modeled" }`, which is exactly what the test asserts. MEASURED: `cargo test --lib -p v1-compiler` over the five, remote: 5 passed, 0 failed. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01SAQiYQiQ7SsdxvotAFbUFc * Assert the withheld tree BYTE FOR BYTE, not by file count The atomicity test compared the refused run's rust emission to the control by `files.len()`. That is weaker than the property the test exists to establish: a refusal that silently substituted DIFFERENT bytes at an equal count would have passed, and "the refusal also changed the output" is exactly the failure the all-or-nothing claim rules out. The control now captures (path, content) for every rust file and the refused run is compared against it verbatim. Raised by review rather than found here, and conceded rather than argued -- an equal-count assertion is not a cheaper version of the right one, it is a different and weaker claim. MEASURED after the change, remote: 5 passed, 0 failed over the five transaction tests. UNCHANGED AND STILL DECLARED: this proves the TRANSACTION refuses while holding a complete tree. It does not observe the filesystem, because `write_output_files` lives in main.rs -- an edit moving it back inside the target loop would still pass. The test's own comment and the PR body both say so. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01SAQiYQiQ7SsdxvotAFbUFc --------- Co-authored-by: Brian Searls <briansearls1@gmail.com> Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
… identically by both readers who implemented it (#9324) * Split the required run into two parallel jobs, and correct the ruling the split supersedes The required run's four phases are mutually independent and were also SERIAL, because one process runs them one after another. That is the expensive combination: the witness floor costs ~30-40 minutes and every other phase waited behind it for no reason a data dependency names, so the required check's wall clock was a SUM of things that could have been a MAX. Operator ruling 2026-08-25 ("we can add it as a parallel job in github actions - we can do the same for regen now, we have more runners" / "basically i would put regen + v2 full compile in one job, and witnesses into another one"). Two jobs, no `needs` edge: build regen first-generation comparison + the v2 emission compile witnesses the .dag parse sweep + the witness floor fold Each job makes ONE invocation of claim_executor and names a LANE. It does not name phases, order them, or wire one phase's precondition to another step's outcome -- which phases a lane owns is `RequiredCiPhase::lane`, an exhaustive match, so a phase belonging to no job fails to compile rather than going silently unmeasured. Every run prints a ROUTED line for each phase it does not own, so one job's log names the whole roster and where the rest is measured. THE 2026-08-20 CONSOLIDATION DIRECTIVE IS CORRECTED, NOT SILENTLY CONTRADICTED. It has two halves and only one is superseded. SURVIVES -- "within the gunbc binary": the phases still live in the binary and the step-ladder defect the consolidation fixed cannot return. SUPERSEDED -- "not at a github actions job level": parallelism is not expressible in one process, so the lane boundary is a job boundary of necessity, and what the directive protected against (sequencing and preconditions leaking into YAML) is exactly what does not cross it. Both halves are now stated in DESIGN's CI clause, in `gunbc.fabric_witness_run`, in `gunbc.witness_floor_workflow` and in the consolidation witness file. THE v2-EMISSION SUBJECT WIDENED in the same change, from `dag/std/abi.dag` to `src/v2/compiler/00_compile.dag`. The cost that argued for the smallest entry was a cost against a SERIAL run; the build lane's cost is now free up to the floor's duration. Measured by emitting both closures and differencing the file sets, the widening gives up exactly one file of coverage, `src/std_abi.rs`, and the row says so rather than claiming total subsumption. Executed evidence: - both lanes run, and route correctly: `lane=witnesses` runs parse and floor and routes regen and v2-emission; `lane=build` runs regen and v2-emission and routes parse and floor - an unknown lane word refuses with exit 2, it does not default - the v2 compiler entry compiles clean under the phase's own producer and pinned pool index (0 blocking) - six consolidation witnesses pass, including two new ones for the split - both new REDs flip under mutation and restore: adding a `needs` edge reds the parallel claim; collapsing to one job reds the two-lane claim - the lane-command claims verified through a scratch probe with a control that returns false NOT DONE, named rather than absorbed: no ratchet over the v2 compile's advisory population (a count pinned to the current tree is the oracle DESIGN §5 rejects; the honest form is an identity-grain monotone debt contract, a separate construction). Nothing else is restored from the deleted floor machinery. And the build step still compiles only the two bins the jobs run -- a declared `[[bin]]` outside that set is uncovered, with a live specimen on main today (`infer_semantics_witness`, six E0063s); widening to `--bins` changes what the required check covers and is an operator decision, so it is declared here rather than taken. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01SAQiYQiQ7SsdxvotAFbUFc * Correct the workflow module's own stale recital of the consolidation directive The supersession was recorded in DESIGN, in gunbc.fabric_witness_run, in the consolidation witness file and in the binary's own roster block -- and NOT in the paragraph inside gunbc.witness_floor_workflow that quotes the 2026-08-20 directive and describes the job as ONE INVOCATION, FOUR PHASES. That paragraph sits directly above the run step the split changed, so it is the one a reader reaches first, and leaving it standing would be the premise contamination this change exists to remove -- one document corrected while its own subject still recited the superseded ruling in the present tense. It now states both halves: 'within the gunbc binary' survives, 'not at a github actions job level' is superseded because parallelism is not expressible in one process. The step-ladder paragraphs below it are kept rather than rewritten, because what they establish is unchanged by the split and deleting them would take the reasoning with them. Also corrected: the step no longer passes 'the source roots and nothing else' (it passes a lane word), and the phase roster is four across two lanes rather than the 2026-08-21 three. Comment-only in emission terms: witnesses.yml regenerates byte-identical. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01SAQiYQiQ7SsdxvotAFbUFc * Make the split fail-closed: the required context now gates on both lanes Review of #9203 (review 55786, codex/gpt-5.6-sol) found the split fail-open, and it was right. Verified against the live ruleset rather than against the workflow, which is the only place the fact is visible: `passing CI` is active, carries NO bypass actors, and names exactly ONE required status check -- `witnesses`. A GitHub required context is produced by the JOB, not the workflow, so moving regen and v2-emission into a second job made them NON-BLOCKING: the required check would go green over a regen drift or a v2 emission break and the PR would be mergeable. That is strictly worse than the serial run it replaced, because the serial job carried every phase into the one context that gates. THE REPAIR, and why it is an aggregation job rather than a ruleset edit. The floor lane is renamed `floor`; the name `witnesses` moves to a job whose only step reads both lanes' results and exits nonzero unless both succeeded. The two lane jobs still carry no `needs` edge on each other and still start together -- only the aggregator waits, and it does nothing but read two results. A ruleset edit would also have worked and was rejected on a boundary DESIGN already records: the ruleset is not a `.dag` fact, so landing a change whose safety depends on someone editing a setting afterwards is a coverage gap with a promise attached and a real window in which the lane is unguarded. `if: always()` IS LOAD-BEARING, and its absence would have been the same fail-open one level in: a step with no `if` inherits `success()`, so it would be SKIPPED exactly when a lane failed, the job would report success, and a skipped required check does not stop a merge. The aggregator is the only place in this workflow that authors shell text, and that is stated on the carrier: there is no modeled value to render, because GitHub has no declarative "this job fails unless those jobs succeeded", and the nearest declarative form is the skip that fails open. The script is built from the job-id declarations rather than spelling `needs.build.result`, so a rename moves both sides together instead of rendering an unknown context as the empty string. WITNESS CORRECTION, not just an addition. `w_RED_neither_lane_waits_on_the_other` asserted the file contained no `needs:` at all -- the right claim for a workflow shape that was wrong, and a row that would have made this repair unrepresentable. It now forbids each single-lane edge and REQUIRES the aggregator's two-lane one, which distinguishes the serialization being forbidden from the aggregation being demanded. A third row asserts the gate runs and refuses. Executed evidence: all seven consolidation witnesses pass, and three mutations red the right rows and restore -- serializing floor onto build reds the parallel claim, dropping `always()` reds the gate claim, and deleting the aggregator reds the parallel claim. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01SAQiYQiQ7SsdxvotAFbUFc * The aggregator's guard belongs at the JOB level: a skipped job never reaches its step Review 55795 and a peer session independently found, within minutes of each other, that the fail-closed repair was itself fail-open one level in. `needs` carries an IMPLICIT JOB-LEVEL CONDITION. A job that declares `needs` and no `if` is SKIPPED when any needed job fails, is skipped, or is cancelled. A skipped job never starts, so it never reaches its steps, so the step-level `always()` could not fire -- and a skipped required check does not stop a merge. The aggregator introduced to close the fail-open would have gone skipped-and-mergeable over precisely the failed lane it was there to catch, with the guard present in the file and reading as correct. `always()` AT JOB LEVEL, AND THIS IS THE ONE PLACE THAT DEPARTS FROM THE FILE'S `!cancelled()` HOUSE GUARD -- said in the carrier, in DESIGN and in the witness, because a reader who knows the convention will otherwise correct it back and reopen the hole. Every other guard here decides whether a STEP runs inside a job that is already running, where `!cancelled()` is right. This one decides whether the REQUIRED CONTEXT EXISTS AT ALL, and under `!cancelled()` a cancelled run leaves it skipped rather than answered. That would turn the outcome on a question about GitHub nobody here has executed -- does a skipped or cancelled required check block a merge -- and the response is not to go measure it but to make the answer not matter. Under `always()` the job always runs, always reads both results, and always reports on its own terms; SKIPPED disappears from the required context. Cost, named: a lawfully superseded run now reports this context red rather than cancelled. That is the correct reading, not a regression -- a superseded run's evidence must not admit a merge. THE WITNESS WAS WRONG IN THE SAME WAY AND IS FIXED WITH IT. It asserted `if: always()` appeared SOMEWHERE in the file. It did -- on the step -- so it went green over the defect. That is DESIGN's total-at-the-level-examined failure: true, and about the wrong level. It now discriminates on emitted INDENTATION, which is the only thing in the text that separates the two levels (a job key at four spaces, a step key at eight), and asserts both. Executed: the strengthened row PASSES on the fix and FAILS on a mutation that removes the job-level guard -- i.e. it catches the exact defect that shipped. All seven consolidation witnesses pass. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01SAQiYQiQ7SsdxvotAFbUFc * Say what the v2-emission phase actually covers: 24 of 42 compiler modules, measured Operator clarification, 2026-08-25: "the intention is to v2 build ALL of the .dag compiler files, and then ratchet THAT count in CI". Measuring against that ask showed this PR's own prose overclaims, so the claim is corrected before anything is built on it. MEASURED, by emitting the entry and joining the emitted file names against the module line of every src/v2/compiler/**.dag: of the 42 modules under src/v2/compiler/, 00_compile's closure emits 24. Eighteen are absent, including ingest, emit_module, emit_host, emit_produced, emit_semantic_decl, program_partition and self_host. Counting the self_host/ subtree the compiler namespace is 69 modules, so the shortfall is larger again. "The widest closure one entry names" was true and is kept; "full v2 compile" invites the reading that the phase covers the compiler, and it does not. That reading is exactly the premise contamination this repository keeps paying for, so the row now states the covered population rather than leaving a reader to assume it. AND A METHOD NOTE THAT COST A MEASUREMENT: a static import-closure estimate CANNOT substitute here. It reports ZERO compiler coverage for this entry, because this corpus resolves most cross-module references without import lines. Only the compiler's own reference-derived closure is the truth, which means a covering entry set cannot be derived from the import graph either -- it has to be measured by emission. The widening itself is NOT taken here: it needs either a measured covering entry set or a whole-tree emission whose cost has to be known before it is enrolled in a required lane. This row makes that widening a change to a known number instead of an assumed one. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01SAQiYQiQ7SsdxvotAFbUFc * Receipt: the gate refused two cancelled lanes, and 'abandoned' is a state nobody knew about Run 32883390033 (2026-08-25) ended BOTH lanes by a fleet event with no push involved. The aggregator ran anyway under its job-level always(), read the two results, refused, and published the required context witnesses as a FAILURE. That is this gate's first executing receipt and it is the behaviour the pre-repair shape could not produce -- there, the aggregator would have been skipped. AND THE RUN SURFACED A needs RESULT VALUE NOBODY HERE KNEW WAS REACHABLE: BUILD="cancelled" FLOOR="abandoned" The gate handles 'abandoned' correctly only because it compares != "success" rather than enumerating bad states. The form a reader's instinct reaches for -- == "failure" || == "cancelled" -- would have admitted it and reported the required context GREEN over two lanes that never ran. So the strict inequality is now recorded on the carrier as a measured fact rather than left as a style choice, because the obvious 'improvement' to an explicit list is a fail-open. That is the difference between a closed vocabulary and a remembered one: the inequality admits exactly one state and refuses every other, including the ones the author has never heard of. Comment-only in emission terms: witnesses.yml regenerates byte-identical. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01SAQiYQiQ7SsdxvotAFbUFc * Record the argument against always() beside the decision to keep it A peer session raised the strongest objection to the job-level always() guard, from GitHub's documented semantics rather than from a measurement, and it is correct on every fact it asserts: always() is the one condition that survives workflow cancellation, cancel-in-progress is armed on every pull_request so this fires on the MODAL event, and it destroys the cancelled/failed distinction at the RECORD level where nothing can recover it. That ambiguity cost that session hours in one day, diagnosing 38 lawful supersessions as a false-red epidemic. The file's house guard really is !cancelled() everywhere else. It is not taken, and the reason is an asymmetry about WHICH HEAD PAYS. Checks are tracked per head SHA, so a superseded run's red lands on a head that by construction is never merged -- the push that superseded it created the head that will be. always() is noisy on ABANDONED heads. !cancelled() moves the cost onto the LIVE one: a lane killed with no replacement run coming, observed twice on 2026-08-25 (once with runner_name empty and zero steps, once with both lanes ended at 18:43 and no push involved), leaves the required context SKIPPED on the head that is still the merge candidate -- which is precisely the unmeasured GitHub behaviour the guard exists to stop depending on. Quiet-and-unknown on a live head is worse than loud-and-definite on a dead one. The mechanism half of the objection is now MEASURED rather than documented: run 32883390033 had both lanes ended by a fleet event, and this job published failure while the run conclusion was cancelled. So the behaviour the objection predicts is real; what is disputed is only whether it is the wrong trade. Recorded in the carrier rather than answered away, so the next person who wants !cancelled() finds the case already made instead of rediscovering it. Comment-only in emission terms: witnesses.yml regenerates byte-identical. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01SAQiYQiQ7SsdxvotAFbUFc * One compilation transaction, subject-parameterized; the gate emitted as nodes Four things, in the order the operator's dispatch puts them. ONE. The build lane bootstraps `cargo build --release -p v1-compiler --bins`. Host-Rust coverage of the whole declared bin roster is a fact somebody has to establish, and a bin no consumer selects is precisely the one that rots unobserved -- #9205 repaired one such bin after it had drifted with nothing building it. The floor lane keeps the two bins it executes; the lanes are runtime-independent, so their bootstraps are independent CPU rather than a shared prerequisite one could save. TWO. THE DAGLANG COMPILATION FORK IS CLOSED. `cli_run` now carries `CompileSubject{Entry|PrimaryRoot}`, `CompileRequest` and `compile_emission`, and the transaction owns indexing and precedence, subject source-set construction, census fill, memory admission, resolution and compilation, the blocking/advisory split, silent-pick capture and the disposition. `compile_entry_emission` survives as a wrapper with no semantics of its own. Before this, `gunbc compile` without `--entry` implemented a SECOND index/load/resolve/admit/compile/refuse pipeline in `main.rs`, beside the transaction rather than through it. They differed in ways nobody had decided: the whole-root arm applied the memory-admission gate and the entry arm did not, the entry arm ran the silent-pick gate inside the transaction and the whole-root arm ran it around the outside, and their refusal subjects were spelled differently. That is DESIGN section 3's two-authorities-for-one-fact, and it is the reason a whole-tree ratchet could not be built on the existing phase: the ratchet would have observed a different producer from the gate beside it. The arms' real differences are KEPT, which is why this is a coproduct and not a flag: admission is asked of the whole root and not of an entry (an entry's working set is its closure, measured to fit on the runner that SIGKILLed a whole-tree run -- an unasked question, not an all-clear), and the closure derivation genuinely differs (reference-derived for an entry, import-edge for a root where every module is already an entry). A `PrimaryRoot` matching no module refuses at `subject-discovery` rather than reporting `Completed { 0 }`, which would be the empty-observation narrow. THE DELETION WAS THE CENSUS. Routing the whole-root subject through the transaction left ~200 lines in `main.rs` with no caller, and rustc then found seven more private copies of module indexing and import walking -- `extract_module_path`, `report_moduleless_dag_entry_skips`, `extract_import_paths`, `insert_module_path`, `index_source_root`, `build_module_index`, `resolve_transitively_with_seen`. All deleted; their two tests re-pointed at the surviving `cli_run` authority rather than retired with the function, per DESIGN section 4b(4). Multi-target (`--target a,b`) still walks the old loop and is named rather than exempted. THREE. `pr_owner` AND `cycle_owner` REFUSED FOR A REASON THAT IS NOT IN `review_codex.dag`. `owner` has TWO declarations in the flat whole-tree namespace -- `data owner` in `gunbc.tools.review_codex` and `fn owner(uid, gid)` in a srv3 path-ownership test -- and the winner is fold order. When the function won, the CLI defaults resolved to it and refused with `must be a string, int, float, bool literal, or data reference`: two blocking diagnostics in a file that had not changed, produced by a test helper in another directory. The discriminating pair is what establishes that, and it was measured rather than reasoned. `repo` is declared beside `owner` in the same module, has no `fn repo` anywhere in the corpus, and does not refuse. `default_model` IS declared twice -- `tools.review` and `tools.review_codex` -- and does not refuse either, because both declarations are data, so either winner satisfies the default's requirement. Collision alone is not the fault; collision ACROSS DECLARATION KINDS is. Fixed by renaming the test helper to `owner_spec`. The class is untouched and the annotation says so: a bare cross-kind homonym is still writable and still resolves by fold order. Its next-rung trigger is a refusal at name resolution when one flat name carries declarations of different kinds -- decidable from the index the compiler already builds -- not a roster of forbidden names. FOUR. THE REQUIRED-LANES GATE IS BUILT AS NODES, NOT SPELLED AS TEXT. `gunbc.required_lanes_gate` constructs it through `v2.extdeps.languages.bash_build` and `witness_floor_workflow` serializes it through `v2.workflow.bash_command_fold_serialize` -- the `tools.build_step` -> `v2.workflow.build_step_emit` precedent. Raised as review 55836's medium-as-string finding, which was correct: I had argued no modeled value existed to render, and the language was fully modeled the whole time. Declaring a language-layer gap without enumerating the language is the failure DESIGN records in its own section 6 receipt. The Rejected arm REFUSES rather than rendering nothing, because an empty `run` exits 0 and would make the required context green over two lanes it never read. The emitted text was executed against all three arms: success/success passes, success/failure and cancelled/abandoned each print the error and exit 1. ALSO LANDED, NOT YET WIRED: `gunbc.v2_rustc_debt` models the monotone identity ledger -- key (emitted-crate-relative path, rustc code), admission iff observed equals the current ledger AND the current ledger is a multiplicity-wise subset of the baseline's -- with eleven fixture arms that author both input and expectation. Both totals are receipt-only and reach no verdict. Its host observation is deliberately absent: an observer built before a whole-tree emission can be produced would be an observer with no subject. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01SAQiYQiQ7SsdxvotAFbUFc * The subject is a field, the precedence root is a refusal, and the fork is three callers wide FOUR CORRECTIONS, three of them from an operator ruling on the measured report and one from the census that ruling asked for. ONE. THE ALIAS DIRECTION WAS BACKWARDS. It read `pub type CompileRun = EntryEmissionRun`, which makes the generic name an alias of the entry-named authority -- so the canonical carrier stays the one named for a subject it no longer describes, and every reader is sent to a type whose name contradicts two of its three uses. `CompileRun` and `CompileDisposition` are now the types; the entry-named spellings are the compatibility aliases that disappear with their last caller. TWO. `run.entry` SILENTLY WIDENED TO HOLD A DIRECTORY. A consumer reading it after a `PrimaryRoot` compile got a root from a field promising a file -- one name, two meanings, which is the section 3 violation the fork closure exists to remove, reintroduced one field down. It is now `subject: CompileSubject`, and the receipt names the ARM rather than the path: `subject=primary-root:src/v2`, not `subject=src/v2`. The two read identically to a human and differently to anyone deciding whether a run measured what it was asked for, which is the whole reason the field exists. THREE. THE SUBJECT AND THE PRECEDENCE ROOT NOW HAVE TO AGREE, AND DISAGREEING REFUSES. The trap is entirely in argv order and invisible from the receipt: the live workflow passes `--source-root dag --source-root src/v2`, and the no-entry CLI law is `PrimaryRoot(source_roots[0])`, so THAT argv asks for `PrimaryRoot(dag)` with `src/v2` as a pool. A caller who means "compile v2" and writes the roots in the workflow's habitual order gets the other subject, compiles ~2000 different modules, and is told the compile completed. This is not a scope difference, it is a RESOLUTION difference, and it already cost a measurement: `dag`-primary refuses on two `review_codex` CLI defaults that `src/v2`-primary never reaches, and `src/v2`-primary refuses on 36 diagnostics `dag`-primary never sees. The 9.06 GiB peak and the `owner` diagnostics reported earlier are the `dag` subject; they were reported under a heading that implied the v2 one. A ledger bootstrapped from the wrong subject is not a coarser ledger, it is a ledger about another population. `primary_root_agrees_with_precedence` makes the disagreement unwritable rather than merely detectable. FOUR. THE FORK IS THREE PRODUCTION CALLERS WIDE, NOT ONE. The census over `compile_sources`, `compile_sources_with_options`, `compile_to_resolved_with_options`, `emit_resolved_for_target` and `stage0_self_compile_refusal_message` classifies every caller: 46 compiler_tests / compiler_tests_rust kernel test, legitimate 2 v1_probe_emit_interp generated kernel probe, legitimate 2 v1_compiler_emit_rust compiler implementation, legitimate 9 cli_run compile_emission implementation 5 main.rs DECLARED VIOLATION (multi-target loop) 2 required_regen_host DECLARED VIOLATION (needs ExactSourceSet) 2 bin/bootstrap_witness DECLARED VIOLATION (not previously named) `bootstrap_witness.rs` compiles EVERY `.dag` file under `dag/` to Rust, which is exactly the invariant's subject -- a repository source population producing an artifact tree -- so it is a production route and not a kernel probe. It carries its own `build_module_index`, `build_module_index_for_roots` and `resolve_imports_transitively`: a FOURTH private copy of the machinery this branch deleted from `main.rs`, in a 1289-line binary the floor lane builds and runs. It can disagree with the transaction about what the `dag/` population IS, and nothing would say so. None of the three violations is closed here. They are named, classified, and ordered: multi-target into the request as a target set, then regen and bootstrap_witness through an exact-source-set subject, both of which select a population by their own authority rather than by directory. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01SAQiYQiQ7SsdxvotAFbUFc * Hoist two §4c-illegal in-body annotations, and restore the module-less skip report the consolidation dropped Two fixes, both of them corrections to my own work on this branch. §4c: `v2_rustc_debt_ratchet_test.dag` carried two `//` lines INSIDE a `test fn` body. Only module-item grain is modeled, so strict preparation refused and the build lane went red on #9242. Hoisted above the declaration. An awk brace-depth census over every file this branch touches confirms no in-body annotation remains. Module-less visibility: the deletion note in `main.rs` claimed the module-less-entry skip report was "the one behaviour with no counterpart" in `cli_run`. That was FALSE -- `report_moduleless_dag_entry_skips` and `moduleless_dag_entry_paths` are both `pub` there with tests, and were never deleted. The note asserted an absence without grepping for it, which is the one claim a later reader will not re-check. The behaviour is now wired into the transaction's `PrimaryRoot` arm through those same two functions. It matters there specifically: the subject is discovered from `index.source_files`, keyed by module path, so a `.dag` under the root with no `module` declaration is absent from the subject and the transaction would report `Completed` over a population that silently excluded it. The empty-root refusal cannot catch this, because a root holding one good file and one forgotten one is not empty. It REPORTS rather than refuses, declared as the weaker arm: a module-less `.dag` is a legitimate parse fixture today, so refusing would break real callers. Terminal form is a total role classification under which an unclassified `.dag` refuses. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01SAQiYQiQ7SsdxvotAFbUFc * Route multi-target compiles through the one transaction, validate all three debt populations, and read the verdict as itself Six review findings, each fixed rather than answered. MULTI-TARGET REGRESSION (blocking). `--source-root X --target rust+dag` fell past the routing gate -- which conjoined the subject with `render_targets.len() == 1` -- into a branch whose only remaining subject is `--source-dir`, and exited "provide --source-root or --source-dir" over an argv that provided one. `CompileRequest` now carries a target VECTOR: resolve once, emit per target, and materialize NOTHING until every target has completed, so one target's tree is never left on disk beside another's refusal. The disposition, the blocking count and the refusal are over the whole emission set, not the first target. Single-target callers -- every required one -- run the identical computation, because `compile_sources_with_options` IS `emit_resolved_for_target ∘ compile_to_resolved_with_options`. Two discriminating arms: two targets produce two named emissions from one resolution, and a request naming NO target refuses at its own `target-admission` phase rather than reporting `Completed { emitted_count: 0 }`. DEBT LEDGER FAIL-OPEN (blocking). Positivity and uniqueness were asked of the LEDGER only. A duplicated key in the OBSERVATION makes the multiplicity lookup answer with whichever row the fold reaches first, so the comparison silently compares the wrong quantity and the run reads as held. All three populations are now validated -- positivity, uniqueness, and strictly ascending canonical order -- through one `DebtPopulationMalformed { population, cause, keys }`, with `population` a closed coproduct because the three have different owners and different repairs. Order refuses rather than sorts: sorting would make two textually different ledgers compare equal and stop a ledger diff being reviewable. THE BLIND-SPOT FIXTURE AUTHORED NO SUBSTITUTION. It passed `one_error()` on both sides and CLAIMED in prose that the two were different errors, which made it a tautology wearing a substitution's name. It now authors `SyntheticRustcDiagnostic` values carrying a latent site, asserts FIRST that the two populations differ, and then that bucketization erases the difference. NO BOOLEAN COLLAPSE OF THE VERDICT (review 55911). `rustc_debt_verdict_admits` matched every variant and returned one bit, so a consumer refusing on it prints "the ratchet refused" and the author re-derives the cause by hand. Deleted. Every test arm now asserts WHICH verdict, which is strictly stronger: an arm authored to provoke `LedgerExceedsBaseline` used to stay green when the contract refused it as malformed for an unrelated reason. VOCABULARY. `admitted_multiplicity` -> `multiplicity`; `identities` -> `buckets`, in the model, the receipt and the test names -- the count is per (path, code) bucket and calling it an identity is the inflation the blind-spot arm exists to deny. RENAME FINISHED. The entry-named aliases are deleted, not merely re-pointed; two spellings for one type is the same §3 violation one layer out. Also: the census behind "one compilation concept" is now stated at CALL-SITE grain with its forks named, the `CompileSubject` comment no longer calls the import walk "the authority" (it under-pulls by construction -- the namespace is flat -- and the census fill covers the difference), the precedence check declares its rung and its terminal `SourcePool` form, and a `TypeEnv` field missing at one test site is filled so `cargo test --lib` builds at all. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01SAQiYQiQ7SsdxvotAFbUFc * Build the unrenderable-gate refusal from the Bash grammar too, and split the unwired debt model out of this PR Review 55923, both findings, neither deflected. THE RAW SHELL FALLBACK IS DISSOLVED, NOT MARKED. `required_lanes_gate_unrenderable_script` was an executable program spelled as a String and handed to a RunStep -- the medium-as-string violation this PR otherwise removes, surviving in the one arm nobody reads, inside the module whose own header argues against exactly that. The refusal is now Nodes in `gunbc.required_lanes_gate`, beside the gate it stands in for, serialized through the same fold. The outcome is three-state rather than two, and the third state is what removes the last fabricated value: the gate serializes -> the gate; the gate rejects but the refusal serializes -> the refusal, which stops every run loudly; both reject -> Absent, and `expected_witness_floor_yml` returns `WitnessFloorGenerationRefused` so no yaml exists at all. A Rejected fold can no longer reach a published step. The one remaining `""` is not a program and is reachable only when emission has already refused -- Daglang is total, so some value must inhabit the arm; what matters is that it is not a second spelling of a shell program and that no emission path reaches it. Verified rather than asserted: `required_lanes_gate_is_renderable` returns true by execution, and regen exits 0 with the workflow yaml BYTE-IDENTICAL -- only the unreachable arm moved. ON THE "on-carrier bash-emission scaffold marker": no such convention exists in this tree. A whole-tree search finds no `bash_emission`, `hand_shell` or `model_vs_runner` carrier. Removing the raw string makes the marker moot either way, which is the stronger repair. THE DEBT MODEL LEAVES THIS PR. `dag/gunbc/v2_rustc_debt.dag` and its fixture are removed and travel to the change that lands their consumer. The earlier review from the same provider offered keeping this PR open as the integration vehicle and I took that; a measurement since has changed the calculus. A whole-repo emission REFUSES ON MEMORY ADMISSION on the current runner class -- measured on BuildBuddy: budget 6.58 GiB against the modeled 7.00 GiB demand, `WholeCorpusCompileBudgetBelowMeasuredDemand`, zero files emitted. So the observer cannot be built until the resource-grant boundary is decided, and that decision is the operator's. Holding a foundational compilation PR open behind someone else's decision is worse than either option the review named. What remains here is the compilation consolidation and the gate repair: coherent, with consumers, mergeable on its own. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01SAQiYQiQ7SsdxvotAFbUFc * A target name carried beside its target can disagree with it; derive it. And the fork census omitted a fork Two remarks from the side-channel review, both verified against the code, both real. THE (NAME, TARGET) PAIR IS COLLAPSED TO A TARGET. `CompileRequest.render_targets` carried `Vec<(String, RenderTarget)>`, so `("dag", RenderTarget::Rust)` was constructible: two spellings of one fact, free to disagree, with the NAME deciding which directory a target is written to while the TARGET decided the bytes written into it. That is the §3 violation this transaction exists to remove, reintroduced one field down and in the same PR that removes it elsewhere. The name is now DERIVED through `render_target_name`, which is the CLI parse's inverse, so the disagreement has no representation rather than being checked for. `parse_render_targets` discards the authored spelling deliberately, because it is recoverable. THE CALL-SITE CENSUS OMITTED `required_regen_host`. `compile_stage0` calls `compile_sources` directly over `regen_input_sources` -- a fourth fork, and the census whose entire purpose is to enumerate forks reported it as absent. The file appeared in the file-level count I ran and did not survive into the call-site list I wrote from it, which is the incomplete-enumeration class this repository has recorded against itself twice before: a list transcribed from a wider measurement is not the measurement. It is now listed with its subject (an EXACT SOURCE SET from the regen roster -- neither a root nor an entry, so neither existing subject describes it), its terminal form, and the hardcoded refusal subject it still passes. The omission is recorded in the census itself rather than quietly corrected, because a census that has been wrong once should say so. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01SAQiYQiQ7SsdxvotAFbUFc * The refusal arm the PR defends was the wrong shape, and nothing executed could have caught it Review 55928, plus four findings from the thread review that survive at this head. THE MIDDLE RUNG WAS DEAD. `required_lanes_gate_unrenderable_stmts` was declared `-> List<Node>` and returned `bash_build_stmt_list_from_nodes(...)`, which is a single `Node`. Its caller passes it as `stmts: List<Node>`. So the arm this PR argues must stay executable -- gate rejects, the refusal still serializes, the run stops loudly -- was the wrong shape in exactly the place the argument is about, while the in-file receipt said it was Nodes through the same fold. Returns the raw list now, like `required_lanes_gate_stmts` beside it. THE REASON IT WAS POSSIBLE IS THE REAL REPAIR: the claim lived in prose, so nothing could contradict it. `the_unrenderable_gate_refusal_serializes_and_stops_the_line` now runs the fold over the refusal and reads the program back -- it must serialize, and must carry both the `::error::` annotation the operator sees and the `exit 1` that stops the line. THE CONTROL FLIPS, MEASURED RATHER THAN ASSUMED. Fixed shape: true. Defect restored: `PatternMatchFailure`, the fold choking on a Node where the list belonged. ONE HONEST QUALIFICATION: the red arrives as a RUNTIME ERROR, not a returned false, which is a weaker red than a clean false -- an erroring probe stops rather than asserting anything about its subject. Recorded because "the control flips" alone would overstate it. DUPLICATE TARGETS REFUSED. `--target rust+rust` parses to two targets, and each emission's directory is derived from the target, so both land in `output_dir/rust` -- the second overwriting the first while the run reports two completions. Refused at `target-admission`, not deduplicated: collapsing it silently answers a request nobody made and destroys the signal that the argv is wrong. THE MODULE-LESS WALK NO LONGER DROPS READ FAILURES. `if let Ok(content)` narrowed "every `.dag` under the root" to "every READABLE one" while still reporting under the wider name -- the empty-observation narrow inside the population whose entire job is to report what got dropped from the subject. Now a typed refusal at a `subject-read` phase. DOCUMENTATION THAT LIED. The root-order ruling sat immediately above `names_at_least_one_target`, so Rust attached the precedence contract to target admission; moved. "One entry, one render target" and "One entry's emission transaction" corrected beside code that handles two subjects and a target vector. The alias note's history example read `pub type CompileRun = CompileRun`, which is not a direction. And "reference derivation is not used here and that is not an oversight" sat directly above the fixpoint call that falsifies it -- it is used, because an import edge is weaker than a reference in a flat namespace and the walk under-pulls across the pool boundary. Regen exits 0 with no artifact drift. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01SAQiYQiQ7SsdxvotAFbUFc * Restore the entry-scope marker as a typed receipt: I deleted a consumer's evidence while tidying a sentence Three findings from the thread review, verified against the code before acting. THE SCOPE MARKER WAS MINE TO LOSE AND I LOST IT. Main prints "resolved N sources (reference-derived closure), M indexed modules"; consolidating the two CLI pipelines into one generic line dropped the parenthetical. It existed at the merge-base, so this is a regression on this branch and not a collision. `gunbc.emit_diagnostic_observation` `emit_entry_scope_marker` (landed on main via #9190, AFTER my change) matches that exact text and returns `EmitScopeUnconfirmed` when it is absent -- specifically so a whole-root compile cannot be reported as one entry's measurement. Merging main unchanged would have made every per-entry emission measurement refuse, from an edit that reads as prose cleanup. RESTORED AS A VALUE, NOT AN ADJECTIVE. `CompileScopeReceipt` is derived from `CompileSubject`, so the receipt cannot disagree with the run and cannot be lost by rewording. The entry arm carries the marker; the primary-root arm now STATES what it measured instead of being silent, so a consumer no longer has to infer scope from argv or file counts. The Rust literal and the `.dag` `data` row are two spellings of one fact -- unavoidable while that authority is `.dag` and this seed cannot read it -- so the constant is named `EMIT_ENTRY_SCOPE_MARKER` and cites its authority, making the pair greppable. THE TEST ASSERTS BOTH HALVES. Marker present on the entry arm, ABSENT on the primary-root arm. A receipt that carried it on both would be worse than one that carried it on neither: the marker exists to make the substitution refusable. THE PANICKING TRAVERSAL. My earlier "typed refusal" fixed the per-FILE read and left the DIRECTORY walk calling `collect_dag_files`, which is `collect_dag_files_result(..).unwrap_or_else(|e| panic!(..))`. A missing root, a regular file as root, or any `read_dir` failure bypassed `CompileDisposition` entirely. That was half a repair wearing the whole one's name; the walk is fallible now. TARGET ADMISSION ORDERING, PROVEN RATHER THAN ASSERTED. The new arm passes a subject that CANNOT be discovered, so if the duplicate-target refusal came after subject discovery the run would refuse at `entry-read` instead and the arm would fail. It proves the ordering, not merely the refusal. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01SAQiYQiQ7SsdxvotAFbUFc * The all-or-nothing materialization proof, with a RED that is actually authorable The CLI writes a tree only after the AGGREGATE disposition is `Completed`, so one target's refusal must withhold another target's finished files. That claim was asserted by the arm's structure and by nothing executable. BEFORE WRITING THE TEST I CHECKED WHETHER ITS RED CAN BE PRODUCED AT ALL, because a check whose red is unauthorable is a decoration -- permanently green by construction and worse than absent, since it gets cited as coverage (DESIGN §4b). It can: `file_emission_refusal` applies `target_renders_file_transport` FIRST and separately from `file_binding_refusal`, and that gate answers `Rust => true` with Python, Go and Dag all false. So a WELL-FORMED file-transport operation emits clean on Rust and refuses `FileTargetNotModeled` on Go. MEASURED on the new fixture root before any assertion was authored: `--target rust` emits 7 files with 0 diagnostics; `--target go` refuses, naming target 'go' and the missing file realization handler. The fixture is deliberately well-formed -- renderable path, product output shape, only modeled channels -- because a fixture with a real defect would refuse on BOTH targets and the test would pass for the wrong reason. Also measured, and it corrects the assumption I would have coded against: ordinary modules complete on every target (rust 6 files, go 3, dag 1, python 3, zero diagnostics each), so the refusal genuinely has to come from the transport gate rather than from picking an "unsupported" target. The test carries a single-target control (rust alone completes with a non-empty tree, so a future change that breaks the fixture cannot leave the test quietly asserting nothing), pins the refusal to the target-gate cause rather than any refusal, and asserts the refused run still holds the SAME file count the control emitted -- unwritten. That last assertion is the whole content: it distinguishes "the arm withheld a finished tree" from "there was nothing to write", and without it the property is vacuous. Also collapses `authored_import_names`, which the merge from main left specified THREE times in one `#[cfg(test)]` struct literal, breaking the entire lib-test target. A clean merge with no conflict, and no gate could see it: CI builds the binary and the Rust suite left CI on 2026-07-11. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01SAQiYQiQ7SsdxvotAFbUFc * The five transaction tests were unexecutable as written; they now execute, 5 passed The PR body said these arms were "type-checked only". That was too kind to them. They were not merely unexecuted -- they were UNEXECUTABLE: a test binary's cwd is the PACKAGE root while the fixtures live at the repo root, so every one of them panicked in `index_source_root_into_module_index` with `source root does not exist` before reaching a single assertion. Discovered by running the new atomic-materialization test, not by reading. FIRST FIX WAS WRONG AND THE WRONGNESS IS THE POINT. `set_current_dir(workspace_root())` looks correct and greened four of five. It is a race: cwd is process-global and cargo runs these tests in parallel, so a DIFFERENT PAIR failed on each run -- 4 passed/1 failed, then 3 passed/ 2 failed, with identical code. A flaky green here would have been worse than the original failure because it would have read as proof. Replaced with absolute paths derived from `workspace_root()`, which has no shared mutable state to race on. Also reads the `Refused` arm rather than routing it through `cause_of`, which destructures `NotExecuted` only. The first draft panicked on its own success: the run WAS `Refused { phase: "emit", cause: "... target 'go' ... transport emission is not modeled" }`, which is exactly what the test asserts. MEASURED: `cargo test --lib -p v1-compiler` over the five, remote: 5 passed, 0 failed. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01SAQiYQiQ7SsdxvotAFbUFc * Assert the withheld tree BYTE FOR BYTE, not by file count The atomicity test compared the refused run's rust emission to the control by `files.len()`. That is weaker than the property the test exists to establish: a refusal that silently substituted DIFFERENT bytes at an equal count would have passed, and "the refusal also changed the output" is exactly the failure the all-or-nothing claim rules out. The control now captures (path, content) for every rust file and the refused run is compared against it verbatim. Raised by review rather than found here, and conceded rather than argued -- an equal-count assertion is not a cheaper version of the right one, it is a different and weaker claim. MEASURED after the change, remote: 5 passed, 0 failed over the five transaction tests. UNCHANGED AND STILL DECLARED: this proves the TRANSACTION refuses while holding a complete tree. It does not observe the filesystem, because `write_output_files` lives in main.rs -- an edit moving it back inside the target loop would still pass. The test's own comment and the PR body both say so. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01SAQiYQiQ7SsdxvotAFbUFc * Name the third arm: a two-way rule over a three-state domain misread by both readers who implemented it The comment beside the /proc/vmstat reads in `floor_resource_sample` documents a discrimination with two arms -- pswpin rising with pgmajfault is swap and not this lane's problem, pgmajfault rising with pswpin flat is file-backed mapping churn and IS this lane's defect. The domain has three states. Zero-and-zero has no arm. THIS IS NOT A HYPOTHETICAL. Two readers implemented the documented rule independently while investigating the floor-lane cancellations, and BOTH classified zero-and-zero as mapping churn -- 26 intervals in one reading, 6 in the other. That inverts the conclusion: churn is a defect this lane owns, quiet is the absence of one. A rule stated as a dichotomy over three states hands every faithful implementer the same misreading, which is why the fix belongs in the comment rather than in either reader's script. The mechanism of the misread is worth the extra sentence, because it is what makes the two-arm form actively misleading rather than merely incomplete: `pgmajfault rises` and `pswpin flat` are two conditions, and only their CONJUNCTION is churn. Both readers selected the arm on the second condition alone -- pswpin flat -- which is exactly what zero-and-zero satisfies. MEASURED, remote: `cargo check -p v1-compiler` Finished, exit 0, against a `-Z definitely-not-a-real-flag` control that exits 101, so a real compiler was reached. `cargo fmt --all --check` exit 0. v1 is frozen with maintenance active; the admission test since 2026-08-20 is PURPOSE -- in support of the v2 self-host program -- and this is a defect repair to a diagnostic the self-host floor emits on every required run. Authority: `gunbc.v1_maintenance_standing` `v1_seed_standing`. cli_run.rs is hand-Rust by declared seed deferral, not an emitted mirror, so no regeneration is involved: `std.realization_schedule` `walk_plan_run_stage_claim_executor_seed_deferral`. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * The tell is worth more than the specimen: two independent implementers producing the SAME wrong answer The state-space conflation entry names one form -- not-applicable rendered as malformed -- with a recognition rule keyed on an arm downstream of a search that returned `Absent`. The specimen in this PR does not match that shape and is the same class, so this records a second form: A DICHOTOMY STATED OVER A DOMAIN WITH THREE STATES. WHAT MAKES IT WORTH A SEPARATE FORM IS NOT THE SPECIMEN, IT IS THE TELL. A genuine gap produces divergent readings or an error. A dichotomy over a larger domain produces CONVERGENT WRONG ONES, because every reader matches on whichever condition is cheapest to evaluate and the neglected state satisfies it -- here `pswpin flat`, which zero-and-zero also satisfies, so the arm was selected on one of the two conditions whose CONJUNCTION was meant to define it. Receipt: 26 intervals so classified by one reader, 6 by another, neither having compared notes. The convergence is what made it invisible, since agreement reads as confirmation. So the operative rule points the other way from the usual one: when two independent readers of one rule agree on something surprising, suspect THE RULE of being a dichotomy over a larger domain rather than treating the agreement as corroboration. That is the lineage law from the other direction -- agreement is not evidence when the readers share a defect, and here the shared defect is in the thing they both read. Lands beside the comment fix rather than in a separate PR because it is the same finding and the same receipt; separating them would put the rule in one review and its evidence in another. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * The tell claimed more than n=2 on one specimen can establish; it is a prompt to re-derive, not a diagnostic Review 56194 (codex) is right and this is conceded rather than argued. The text read that a genuine gap yields divergent readings while a dichotomy over a larger domain yields convergent wrong ones -- stated as canonical guidance, that invites a future reader to INFER a specific modeling defect from evidence that does not uniquely identify it. WHAT THE RECEIPT ACTUALLY SUPPORTS: two readers made the same mistake, once. It does not support the converse direction, and I had no evidence at all for the half about what a genuine gap produces -- that clause was invented to make the contrast symmetrical. CONVERGENCE HAS COMPETING CAUSES THE RECEIPT CANNOT SEPARATE: shared assumptions, a common heuristic, ambiguity in the subject, or one reader having anchored on the other. n=2 on one specimen distinguishes none of them from a defect in the rule. The irony is worth recording rather than smoothing, because it is the same shape I refuted in myself four hours ago: a perfectly agreeing n=2 read as a mechanism. There it was two runs inverted on both axes and it did not replicate at n=34. Here it was two readers agreeing, and I wrote it into the authority document. WHAT SURVIVES, and it is the concrete half codex asked to keep: - the three-state specimen and why the two-arm form misleads - a recognition rule keyed on STRUCTURE rather than on reader behaviour: for every arm of a stated dichotomy, enumerate the domain and check that each arm's conditions are required jointly - the weaker and defensible direction only -- agreement between readers of one rule is not INDEPENDENT evidence about that rule, since the shared input is a shared potential defect, so it licenses re-deriving from the domain and never a conclusion about which cause produced it Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * The comment carried the same overclaim this PR corrects in DESIGN, one file away Review 56201 (codex) caught an internal contradiction and is right. The previous commit narrowed the DESIGN entry to say convergence has several possible causes and is a prompt to re-derive rather than a diagnostic -- and left the cli_run.rs comment asserting that a dichotomy over a three-state domain "hands every faithful implementer the same misreading." Two readers do not establish a universal. So the PR corrected the overclaim in the canonical document while shipping it in the source comment, which is worse than either alone: the two artifacts now disagreed, and a reader who found only the comment would take the stronger claim as current. WHAT REPLACES IT is the structural half, which is what was actually established: zero-and-zero satisfies `pswpin flat` and not `pgmajfault rises`, so a reader matching on the cheaper condition alone selects churn for it. That is a fact about the RULE's shape, checkable by reading the rule, and it does not depend on how many readers were surveyed. The sentence now says explicitly that it is an observation about this rule and these two readings, not a prediction about future readers. This is the second time in this PR that the concrete structural claim survived and the generalisation layered on top of it did not. MEASURED, remote: `cargo check -p v1-compiler` Finished, exit 0, against a `-Z nope-not-real` control that exits 101. `cargo fmt --all --check` exit 0. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Brian Searls <briansearls1@gmail.com> Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
A declared
[[bin]]does not compile on mainsrc/v1/stage0/Cargo.tomldeclares[[bin]] infer_semantics_witness, andcargo build --binsfails:Both files involved are byte-identical to
origin/main— the bin, andv1_compiler_infer_env.rswhereTypeEnvis declared — so this is determined entirely by main's own content.TypeEnvis generated (from04_env.dag) and gainedauthored_import_names. This bin is hand-authored Rust, and its struct literals fell behind.Why nothing caught it
This is the class DESIGN's 2026-08-25 row declares — no required phase compiles the Rust workspace — but by a mode that row does not enumerate.
The
.dagside is entirely clean:04_env.dagcompiles, the generated mirror compiles, the corpus compiles at 0 blocking. What drifted is a hand-authored Rust consumer of a generated type, which nothing in the.dagworld can observe. CI has nocargo build, nocargo test(removed 2026-07-11), and no clippy (removed 2026-07-08).It also survives the incoming required-job split: #9203's sibling work builds exactly the two bins the jobs run, not
--bins. That PR states the boundary rather than widening it, which is correct — widening the required check is an operator decision, and it would land red on a defect that change did not cause. This PR is the separately-filed repair that boundary asks for.The value, and the wrong one I tried first
matching this bin's own idiom for its sibling map fields (
bindings,str_bindings, …).Not
v1_rt::rc_empty_map::<String, bool>(), which is what the library modules use (v1_compiler_infer_env.rs:163,v1_compiler_emit.rs:583) and what I tried first.v1_rtis not in scope in a bin crate root, so that attempt traded sixE0063for sixE0433. Recorded because the sibling-file idiom looks obviously correct and is not — the fact that a construction is used elsewhere in the crate says nothing about whether its path resolves from a bin.Receipt — by execution, not by the edit looking right
The bin is silent on success and carries 126
assert/panic!/process::exitsites, so exit 0 is its passing verdict rather than an absence of checking. That distinction is the point: a bin that merely linked would prove nothing.Not claimed
That the witness's assertions are the right ones, or that an empty authored-import universe is semantically what each of the six call sites wants. This restores a declared bin to compiling and passing. It does not audit what it asserts, and it does not close the class — only a required phase that compiles the workspace does that.
WHAT THE SIX EMPTY MAPS CLAIM, STATED BECAUSE THE BYTES DO NOT SAY IT
This fix fills a
TypeEnvfield,authored_import_names: Rc<im::HashMap<..>>, with an empty map at six construction sites. An empty map here is a claim that THIS WITNESS DOES NOT MODEL AUTHORED IMPORTS. It is NOT a claim that the modules under test have no imports. The two are the same bytes and this sentence is the only thing separating them.That distinction is load-bearing rather than pedantic.
v1_compiler_infer_lookupauthor_named_visibilityreturns a three-valued answer —AuthorNamedThisName | AuthorNamedNothingForThisName | VisibilityUnobservable— and synthesizes the third state from emptiness,if map_is_empty(authored_import_names) { VisibilityUnobservable }. The carrier is two-valued at that grain and the answer is three-valued, so observed, and the author named nothing and nothing populated this are indistinguishable. A reader who takes these six lines as "no imports" has read a claim of UNOBSERVABLE as a claim of NONE. Mechanism identified bysnappy-dove-250, who owns that seam.WHY THE EMPTY MAP IS INERT HERE, AT THE DEPTH ACTUALLY CHECKED.
author_named_visibilityhas exactly one consumer,callable_lookup_over_candidates, reached from exactly one caller,lookup_func_sig. This bin references neither. Its surface into the inference crate is narrow and enumerable: it callsannotate_pattern_parent_enums(the onlyv1_compiler_inferentry point it uses), pluslookup_structural_method,pattern_subject_from_node,lookup_variant_in_type,check_match_exhaustiveness,check_index_access_nodeandkeyed_collection_parts. Of the nine functions inv1_compiler_inferthat do contain alookup_func_sigcall, none is among them, andannotate_pattern_parent_enums's own direct callees contain none of them either.WHAT THAT ARGUMENT DOES NOT COVER, SAID PLAINLY: it is two hops from the bin, not a full transitive closure — I did not walk every descendant of
resolve_pattern_subjectorlookup_variant_in_type. The claim is that no direct or one-hop path reaches the field's only reader, not a proof that none exists at any depth.AND ONE ARGUMENT THAT WAS HERE AND IS WITHDRAWN, because a wrong leg is worse than a missing one. An earlier revision of this section also claimed the field's reader sits behind
name_resolution_policy_is_namespace_only(), "a thread-local that is false unless armed host-side". THAT IS FALSE.v1_rt.rsdeclares itCell::new(true)— namespace-only is the PRODUCTION policy, ratified 2026-07-21, andfalseis the bracket. I misread it because the comment saying "default false = production fail-open path" sits immediately after that function's closing brace and heads the next declaration,TYPE_REF_HIT_NE_BIND_MEASURE, whose own first words name it as the N1a measurement arm. Prose attached to the wrong subject, believed because it was adjacent — §4c with a bill attached. Caught bysnappy-dove-250. The inertness argument now rests on the structural leg alone.What this PR does NOT do is decide what the field SHOULD contain. That is a semantic question on
snappy-dove-250's side of the proof/semantics seam, and filling it in on the theory that empty is neutral is exactly the move this section exists to refuse.