Skip to content

Give filesystem operations truthful wire channels - #9265

Merged
briansrls merged 3 commits into
mainfrom
session/zesty-newt-651
Aug 26, 2026
Merged

briansrls merged 3 commits into
mainfrom
session/zesty-newt-651

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Aug 26, 2026 •

Copy link
Copy Markdown
Contributor

Seed admission:

Three implementation files are in the maintenance-active v1 seed: src/v1/05_emit.dag, its generated src/v1/stage0/src/v1_compiler_emit.rs mirror, and src/v1/stage0/src/v1_interpreter.rs. This is a defect-repair rename of existing channel projections, not a new exported declaration or capability. Its purpose is to keep the v1 seed correctly supporting v2 self-hosting, so it satisfies the seed purpose test without PublicSurfaceGrowth.

Compatibility:

The authored from keys are consumed while binding and interpreting an operation. The binder resolves them immediately to existing FileResultChannel variants, and the renderer emits the same file_success or file_content expressions as before. A grep of the encode/decode sites found no persistence or version boundary for these key strings; serde derives exist on the internal bound carrier, but there is no serialization call for it.

Outcome:

  • Gives Filesystem Read, Delete, and List operation-specific success channels instead of borrowing write_success.
  • Gives List.entries its own entries channel instead of borrowing scalar content. This fixes the second nickname while leaving the separate String-versus-list cardinality migration to the referred fleet cut.
  • Derives emitter and interpreter projections from the expanded file-channel authority.
  • Extends the discriminating file-transport emission fixture across Read, Delete, and List.

Remaining-name disposition:

All remaining write_success occurrences were inspected. roadmap_belt_actuate is a real consumer of Filesystem.Write, and its witness follows that subject; the pathless transport fixture also declares Write. The synthetic Chmod fixture intentionally uses an already-modeled success channel so its stage-discriminating oracle isolates the unmodeled verb rather than introducing a second unmodeled output-key cause. The stale src/v1/05_emit_rust.dag annotation was updated to read_success.

Scope:

This intentionally does not perform the referred corpus-wide replacement of Read flat result with a typed Result. That atomic fleet migration has separate ownership and a consumer census.

Validation:

  • v1 source DAG parse sweep: 4,003 files parse-clean.
  • Required build lane: v2 full-closure emission completed with zero blocking diagnostics.
  • Required regen initially reported only v1_compiler_emit.rs; the committed mirror was replaced with the exact candidate diff.
  • cargo fmt --all --check and git diff --check pass.
  • Workspace cargo check reaches a pre-existing stage0_extdeps_languages missing extdeps_languages_rust_capabilities import on main.

@gunbai-bot
gunbai-bot Bot marked this pull request as ready for review August 26, 2026 01:30
@briansrls
briansrls merged commit 37bb097 into main Aug 26, 2026
3 checks passed
@briansrls
briansrls deleted the session/zesty-newt-651 branch August 26, 2026 05:16
@briansrls
briansrls restored the session/zesty-newt-651 branch August 26, 2026 05:25
gunbai-bot Bot pushed a commit that referenced this pull request Aug 26, 2026
…ed content

Same shape as the previous merge and the same cause: #9231 squash-merged, so its branch
history is not an ancestor of main and git offered these files as add/add against a merge
base predating all of them. Resolved by three-way merging each against the last shared
content (60ce9ed) rather than picking a side -- main carries the dual denominator and
the closed hole 2, this branch carries the subject-identity split, and both are wanted.
`sha256sum.dag` taken whole from main; this branch made no change to it after that point.

ONE PROSE FACT WENT STALE AS SOON AS #9231 LANDED. Hole 2's block read "CLOSED BY THIS
CHANGE" -- true while it sat on the branch that closed it, false the moment that branch
merged and the sentence was inherited by a different PR. "This change" is a positional
citation in prose: it names its referent by where it sits rather than by what it is, so it
rots the instant the text moves. Both occurrences now name gunbc#9231 directly, which is
the citation that survives being merged, cherry-picked or read from main.

THREE BLOCKING DIAGNOSTICS IN THIS ENTRY'S CLOSURE ARE INHERITED FROM MAIN AND ARE NOT
THIS PR'S. Reproduced from a pristine origin/main worktree at 730d226: the same three,
all in `extdeps.filesystem.filesystem_io` (`Filesystem.Read`/`Delete`/`List` -- file
transport output keys with no modeled channel), landed by #9265. This branch adds none and
removes none. That is a live instance of the class DESIGN declares in Building-&-checks: a
blocking emit-stage diagnostic standing on main with no required phase that fails, because
nothing in required CI emits over a closure reaching it.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
gunbai-bot Bot pushed a commit that referenced this pull request Aug 26, 2026
…ree inherited blockers

The remote branch had already merged the denominator branch while I was merging main, so
both sides carry the dual denominator by different routes and the only conflict is my
prose repair against the wording it repairs. Took the repair.

WHAT THE REPAIR IS. Hole 2's block read "CLOSED BY THIS CHANGE" -- true while it sat on the
branch that closed it, false the moment that branch merged and the sentence was inherited
by a different PR. "This change" is a positional citation in prose: it names its referent
by WHERE IT SITS rather than by WHAT IT IS, so it rots the instant the text moves, without
anyone touching it or the thing it names. Both occurrences now name gunbc#9231 directly,
which is the citation that survives being merged, cherry-picked, or read from main. Hole 3
likewise stops saying the denominator "landed in this same change".

THREE BLOCKING DIAGNOSTICS IN THIS ENTRY'S CLOSURE ARE INHERITED FROM MAIN AND ARE NOT
THIS PR'S -- reproduced from a pristine origin/main worktree at 730d226, the same three
by identity, all in `extdeps.filesystem.filesystem_io` (`Read`/`Delete`/`List`: file
transport output keys with no modeled channel), landed by #9265. This branch adds none and
removes none.

That is a live instance of the class DESIGN declares in Building-&-checks: a blocking
emit-stage diagnostic standing on main with no required phase that fails, because nothing
in required CI emits over a closure that reaches it. It is named here rather than fixed
here -- the repair belongs to the transport's owner, and this PR's subject is the emit
ratchet's subject identity.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
gunbai-bot Bot pushed a commit that referenced this pull request Aug 26, 2026
…ommit message were my stale compiler

The commit message on f495de5 reports that main carries three blocking emit
diagnostics in `extdeps.filesystem.filesystem_io` (`Read`/`Delete`/`List`, file transport
output keys with no modeled channel), landed by #9265. THAT IS FALSE and this commit
withdraws it. No carrier was touched by the claim -- it lived only in that message and in
one message to a peer, both corrected.

RE-MEASURED, not merely conceded. Rebuilt the compiler from THIS tree, which contains
37bb097, and compiled the same entry: 0 blocking. The binary I used originally was
tree-built but from a1856a5, and `git merge-base --is-ancestor 37bb097
a1856a5` is FALSE -- so its source predated the change by construction, not by clock.

WHAT #9265 ACTUALLY DID: it ADDED `read_success`, `delete_success`, `list_success` and
`entries` to the modeled-channel set. It is the fix. My compiler was old enough to be the
last version that refused them, and it reported main as broken in exactly the way it had
just been repaired.

WHY THIS IS WORTH A COMMIT RATHER THAN A QUIET DELETION. The output was not obviously
wrong: one specific, typed, correctly-located semantic diagnostic naming three real output
keys in a real module -- indistinguishable from a true finding, and I nearly queued it for
a transport owner who would have spent a morning fixing something that already worked. A
stale instrument does not announce itself; it produces a plausible measurement of a tree it
has never seen. The instrument's age is a property of the SOURCE it was built from, and
that is checkable (`merge-base --is-ancestor`) where a file timestamp is not -- my binary's
mtime was LATER than the commit it lacked.

THE STANDING CHANGE: a compile result about main is only evidence if the compiler contains
main. I check that with merge-base before reporting a diagnostic as a finding, not after.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Aug 26, 2026
…and membership is observed beside it rather than folded into it (#9238)

* Rebuild the per-entry emission instrument as a .dag entry point

DESIGN's Building-&-checks section carries a declared rung drop titled THE
MEASUREMENT BANKRUPTCY DELETED A CAPABILITY, NOT ONLY ARTIFACTS. It states its
own restoration trigger: a .dag entry point that emits, assembles and compiles
one entry and returns the coded-diagnostic population. This is that entry point.
It is the INSTRUMENT, not a board -- it produces numbers and stores none.

tools.emission_entry_instrument  measure_entry_emission runs the spine the
deleted probe script ran (gunbc compile --entry -> cssl_assemble -> cargo under
--message-format=json) and returns EmissionMeasurement, in which "refused before
the emitter ran" has no spelling in the same shape as "emitted with zero
diagnostics": an unreached stage is its own variant naming the stage. That is
DESIGN's execution-provenance-loss row applied to the instrument that most
needed it.

extdeps.cargo_diagnostic decodes the rustc coded-diagnostic population -- one
member per finding, identity (E-code or the named uncoded state) and location
(the primary span, selected by is_primary rather than by position), so two runs
can be joined rather than only differenced. A line it cannot read, and an empty
stream, refuse with a located cause instead of reporting an empty population.
It is a sibling of extdeps.cargo_message rather than a widening of it, which
that module's own boundary note asks for.

gunbc.emit_diagnostic_observation decodes the emit-stage population from what
the CLI already prints. No v1 capability is added: emission is 05_emit territory
and the seed is frozen with maintenance active, so this reads the existing
surface rather than widening the seed for an instrument's convenience. What
makes a prose decode admissible is the cross-check -- the compiler states its
own total on the `compiled:` line and again in the renderer's severity summary,
and a population disagreeing with either, or the two disagreeing with each
other, refuses and names both numbers.

NOT A GATE. No workflow invokes it, no phase enrols it, and the exit status
reports whether the INSTRUMENT completed, never whether the subject was clean.

Evidence: witness claims carry greens and discriminating reds for both decoders
and for the carrier's own distinction. Measured at c271b75: the entry compile
of the instrument itself is 0 blocking / 138 files emitted, and
dag/extdeps/cpu/ampere.dag refuses at emit with 9 blocking / 119 advisory --
re-derived here, not carried from a brief.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Bind the execution subject, and require cargo's terminal message

Two corrections from review on #9190, both narrowing.

ONE -- THE CARRIER NAMED ITS STAGES AND NOT ITS COMPILER. Splitting the phase
states is state-space de-conflation; it is not provenance, and the prose claimed
provenance. DESIGN separates the two deliberately: conflation is repaired by
splitting states, execution-provenance loss by BINDING A RECEIPT to the value.
Without one, the carrier could report the same-looking population from two
different compilers -- the same defect one level down from the one the stage
split closes.

Every outcome that carries a population now carries an
EmissionMeasurementSubject: entry, source revision, working-tree standing, and
the sha256 of the two binaries actually invoked. It is established BEFORE the
emitter runs, and a component that cannot be observed refuses the run rather
than being recorded as absent -- an unobserved digest is not the digest of
nothing. The one arm without a subject, EmissionSubjectUnestablished, is the one
that took no measurement, so an unattributable population has no representation.

The identity vocabulary is REUSED, not re-coined: CommitSha from
extdeps.git.inspect, Digest from extdeps.crypto.hash. Minting a parallel
identity vocabulary inside the instrument built to enforce single authority
would be the violation it exists to measure. extdeps.tools.sha256sum gains one
operation, DigestFile: CheckFile answers "does this file match this digest",
which cannot be used to LEARN one.

TWO -- A KILLED BUILD'S PREFIX READ AS A POPULATION. The decoder returned a
population from any nonempty parseable prefix, so cargo emitting seventeen
messages and then being SIGKILLed reported those seventeen as the answer. That
is the truncated-observation-rendered-as-complete failure that created this
lane, reproduced inside the instrument built to end it. cargo closes every run
it performed with build-finished; a stream without one now refuses and says how
far it got. Its `success` member is also now the authority on whether the build
was clean, replacing the transport exit status observed beside the stream -- the
terminal message is emitted BY the run being measured.

Executed: PASS on the truncated-stream red, the terminal-message verdict in both
polarities, and both provenance claims (a measurement names its compiler; an
unestablished subject carries neither provenance nor population), with an
existing green re-run as a regression control. Entry compile of the instrument
after both corrections: 0 blocking, 145 files emitted.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* The emit population states whether it is the whole population

Requirement from smart-ram-730, relayed from deep-ant-102's finding, and it is a
level finer than the phase split already in the carrier.

THE FINDING, verified here by reading the emitter rather than taken on report:
v1.05_emit_rust emit_rust is a sequence of early returns. Measured on the live
file there are exactly two, both `return EmitResult { files: [], diagnostics }`,
and while the first fires the checks after it NEVER EXECUTE -- two
workflow-parameter diagnostics were observed masking eight anonymous-record
ones, which had been standing the whole time. So any count taken over emit can
be a PREFIX of the truth rather than the truth: not an undercount anyone can
bound, but a count that stops silently at whichever earlier check fired.

WHY THE EXISTING ARMS DID NOT COVER IT. They distinguish WHICH PHASE the
instrument reached. This is finer: within one EmissionMeasured, emit itself may
have returned before a later check ran, so two results that both honestly report
"emit ran" can differ in whether a check even executed. A consumer reading the
first concludes the entry has two blocking diagnostics; it has at least ten.

THE DERIVATION IS EXACT, not a guess, which is what makes this a construction
rather than a warning. Both early returns write NO FILES, and the CLI prints its
`compiled:` line only where a tree was written. So a compile reporting emitted
files ran the emit body to its end and its population is Complete; one reporting
none is CompletenessUnestablished. That second arm is named for IGNORANCE rather
than truncation on purpose: a refusal caused outside emit also lands there, and
claiming such a population IS truncated would answer a question this observation
cannot answer. Over-stating ignorance is safe; the opposite is the defect.

AND THE COUNT NEVER TRAVELS ALONE. The size and the extent are rendered by ONE
expression, so a report stating a population size always states the standing of
the set it counted -- a separate optional row would let the number travel by
itself, which is the entire failure.

Executed: PASS on a refused population never reported as complete, a completed
one reported as complete (so the extent is a real discriminator and not a
constant), no report stating a population without its extent, and the existing
carrier claim re-run as a regression control. Entry compile: 0 blocking.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* The ratchet consumer: an emit-clean frontier over a discovered roster, where an unmeasured subject is neither clean nor suspect

tools.emission_entry_instrument answers one question about one entry and stores
nothing -- it says so itself, and says gating is a separate decision with a
separate argument. This is the consumer half of that sentence, and it is still
not that gate: nothing here is enrolled in the required run.

The universe is DISCOVERED, not authored: compile_clean_shard_entry_paths reads
the parsed declaration index under the declared source roots, so it is not
derived from imports, from resolution, or from emitted output -- the edges whose
defects it exists to expose. The live specimen is gunbc.auth.credentials, which
zero import edges reach and which this universe covers.

Debt is carried at IDENTITY grain as admission rows, never as a count. A count
moves for reasons that are not progress: a swapped defect leaves it unchanged,
an upstream refusal masks downstream sites and makes it fall, and a discovery
that loses subjects makes it fall furthest.

The third standing is the point. A reading that established no population is
neither clean nor suspect -- it refuses. Its discriminating control differs in
exactly one field, whether emit reported a tree.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Hash the discovery policy into the roster digest; avoid two corpus-wide name collisions

* Give the verdict-entry accessor its consumer: every verdict names its subject

* Fix the one blocking diagnostic: a renamed fixture binding missed inside a list literal

* Adopt the superseded contract: three-valued outcome, the enrolment wall as a construction, and both holes pinned by execution

The clean-frontier ratchet has a hole deep-ant-102 named and I had not:
Blocked{A} -> Blocked{A,B} never moves the frontier, so debt grows silently
inside already-blocked subjects. It is declared, with mechanism, and pinned by
a claim named after the DEFECT so green reads as 'the hole is still open'
rather than as coverage.

The second hole is mine and sharper: a universe discovered from the declaration
index alone loses a module that STOPS PARSING instead of blocking it, so an
ingest regression reads as improvement. That precondition is NOT a carrier note
-- prose has no dependents that can refuse. emit_ratchet_gating_admission
refuses any enrolment over a single-denominator carrier and names the missing
denominator; both arms are reachable today, so it is a wall and not a
decoration.

Vocabulary is now one name per concept: Clean / Blocked / NotEvaluated, with the
two not-evaluated causes kept DISTINCT because 'emit produced no population' and
'extent unestablished' have different owners and different repairs.

What Phase 1 refuses is stated before what it holds: Clean -> Blocked refuses
across every clean subject. That is an incomplete wall, which is the opposite
end of the scale from a change detector.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Hole 2's mechanism was wrong: a parse failure under a recognized header refuses LOUDLY

I wrote that a module which stops parsing vanishes from the universe. Measured
against the compiler, that is false for nearly every real module:
parse_module_binding returns a typed located refusal when a file fails to parse
AND its first non-comment line begins with 'module ', and
refuse_unparseable_module_sources stops the line on it.

The silent arm is narrower and real: ModuleBindingUnclassified, which the index's
own source documents as a conflation it cannot resolve -- fragments and parse
failures land there together. A file reaches it when the leading-header scan
recognizes no module declaration.

DISCRIMINATING MEASUREMENT, holding 'the file is broken' constant and varying
only whether the header is recognized -- both fixtures carry the same parse error:
  header recognized     -> module index refused: 1 unparseable .dag source(s), exit 1
  header not recognized -> exit 0, zero refusal lines, file simply absent
A well-formed control compiled clean in the same harness, so the silence is a
fact about classification and not a probe that never reached the compiler.

The pinned claim is renamed to what it actually pins. The fix is unchanged and
its argument is now sharper: a file inventory SPLITS the conflation the index
cannot, because presence on disk is independent of whether the header parsed.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* The dual denominator: a file the index cannot classify blocks instead of vanishing

Closes hole 2. RatchetUniverse carries a second denominator -- a file inventory
via shell.Find.FilesByNameSorted -- and a .dag file present on disk but absent
from the declaration index becomes a SUBJECT whose outcome is
EmitSubjectBlocked { cause: UnclassifiedByModuleIndex }.

THE INVENTORY IS NOT A MORE CAREFUL INDEX. It answers a question the index cannot
ask: module_path_index documents its unclassified arm as inseparable, and it is
inseparable FROM THE INDEX, because fragments and parse failures look identical
there. They do not look identical from the FILE SYSTEM, where presence on disk is
independent of whether the header parsed.

THE DENOMINATOR IS NOW DERIVED, NOT PASSED. RosterDenominators is no longer a
caller-supplied field: the dual value is reachable only by holding a DualUniverse,
which is reachable only by supplying an inventory. That closes the fold-time
versus mint-time observation from review 55831 and smart-ram-730 independently --
a caller can no longer assert a denominator it has not earned.

An unreadable root REFUSES rather than contributing an empty list, because a
failure that shrinks the denominator is the exact defect this denominator closes.

The hole-2 pin is FLIPPED to its regression control, not deleted: per 4b(4) the
climb deletes the production handling it obsoletes, never the evidence that the
higher rung is real.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Four stale sentences, not one: the corrected mechanism had not reached the strings that render it

Review 55852 caught roster_denominators_text still saying 'a module that stops
parsing vanishes' -- the claim the hole-2 correction in the same file had already
established as false. Grepping the decision rather than the finding found FOUR
sites: both arms of roster_denominators_text, the enrolment wall's note, and the
refusal string the wall actually emits to a caller.

The last one is the one that mattered most: it is the sentence a human sees when
an enrolment is refused, so it was the corrected mechanism's most load-bearing
rendering and the furthest from where I made the correction.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* A zero-file tree is not a clean entry: do not rest the load-bearing arm on the seed's printing discipline

deep-ant-102 relayed a finding from bold-stag-236, who owns the producer:
EmittedFileCount does not ASSERT the emitted/not-written distinction.
FilesNotWritten is what the ABSENCE of the compiler's 'compiled:' summary line
decodes to, and the compiler prints that line only when a tree was written. The
distinction is inherited from the producer's printing discipline, which nothing
pins.

That lands hardest here. NotEvaluated is the load-bearing row of this ratchet --
an upstream refusal turning blockers into ABSENCE, with absence reading as zero,
is the failure it exists to prevent. Populated only from FilesNotWritten, the row
that makes the ratchet honest would rest on an unpinned convention in a frozen
seed, and the failure would be exactly the one it guards: a run that emitted
nothing reported as a run that emitted zero, and a subject reading CLEAN when it
was never evaluated.

Verified against the code rather than assumed: FilesEmitted { count: 0 } did
derive EmitPopulationComplete and therefore Clean.

So the derivation no longer depends on that convention for the dangerous
direction. A zero-file tree is EmittedNothing, a third distinct NotEvaluated
cause, so the hypothesised misprint lands in NotEvaluated and refuses either way.
The convention still decides WHICH cause is reported -- a rendering difference
rather than a verdict difference -- and the note says so.

NOT CLOSED, and named: pinning the printing discipline itself needs a probe on a
path that emits no tree, asserting the summary line is ABSENT rather than
present-with-zero. That belongs beside the decoder, not inside this ratchet.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Restore the standing section my own block replacement deleted

The dual-denominator edit replaced a range running from the fold to the enrolment
wall, and the whole standing section lived between those two anchors:
ratchet_failing_verdicts, ratchet_failing_rows, EmitRatchetStanding,
emit_ratchet_standing and emit_ratchet_standing_text were deleted wholesale by an
edit that named neither of them.

Caught by the compiler, not by review or by reading the diff -- and the tell was
'function map not found in scope', a builtin, which is what a cascade looks like
when a module loses declarations that later ones depend on. The nine errors it
reported were one deletion, not nine defects.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Delete the FIPS 180-4 fork in sha256sum: consume the citation extdeps.crypto.hash owns

review 55859, REQUEST_CHANGES. sha256sum.dag re-minted sha256_algorithm_authority
pointing at FIPS 180-4, forking the citation owned by extdeps.crypto.hash
extdeps_external_authority_anchor. review 50411 had already refused the identical
fork in the sibling sha512sum, whose note records the consume rule.

THE FORK HAD ALREADY DRIFTED, which is why it is deleted rather than reconciled:
the local row read .../180-4/final, the owning row reads .../180-4/upd1/final. Two
spellings of one citation had begun to disagree about which revision of the
standard is cited -- the decay 3 predicts, and the reason a second name for one
fact is a correctness concern and not a style one.

PROVENANCE, STATED BECAUSE IT CHANGES WHO OWES WHAT: the forked row is
PRE-EXISTING ON MAIN, not introduced by #9190 -- that PR added DigestFile and the
Digest-typed read only. This is debt the stack touched rather than authored. It is
cleared here anyway: it is a real fork with a documented precedent refusing it, and
provenance is not a defence for leaving one standing.

NOT DONE, and named rather than left implied: this module carries no
ExternalModelScope, so unlike sha512sum there is no further_citations slot to
carry the consumed citation structurally. Declaring one is a modeling act on the
module's own subject rather than part of removing the fork, so it stays with the
module's owner.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* The claim asserting the refusal string went stale when I corrected the string

Renaming 'module inventory' to 'file inventory' across the corrected prose left
the one assertion that READS that string still grepping the old wording, so
a_single_denominator_carrier_refuses_enrolment_and_names_what_is_missing went red.

This is the same class as the four stale sentences review 55852 found, one turn
later and caught by execution instead of by a reviewer -- which is the argument
for asserting the string rather than the shape: a claim that only checked 'it
refused' would have stayed green through a rename that broke what the refusal
tells a human.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* The printing-discipline probe pins one path, not the compiler: correct the remedy's stated size

bold-stag-236, who owns the decoder, corrected the note I wrote naming the probe
that would pin the compiler's printing discipline. A probe on a path that emits no
tree establishes a property of THAT PATH, and v1 has more than one such path, so
it raises confidence without closing the class.

What closes it is the summary line emitted from a single site that cannot run
without a tree -- present-with-zero having no PRODUCER rather than no observed
instance. That is a v1 change and blocked under the seed freeze, so it is the
class's next-rung trigger rather than work someone is declining to do.

Recorded because a remedy described as bigger than it is becomes coverage nobody
re-examines, which is the same failure as an inflated rung one level over.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Subject identity for the emission ratchet: a key of root, kind and resolution policy, with membership observed beside it rather than folded into it

* A measurement over a subject whose boundary did not hold is not a measurement of that subject

* A sixth copy of string-list membership, differing only in parameter name, is the fork the whole-corpus prep resolves against

* roster_identity had two declarers: a per-entry compile sees one, the floor sees both, so the collision was invisible to the check an author runs

* The witness declares imports, so its disposition type must be imported too

* A keys() accessor has to answer something for the refused arm, and the only answer available launders the refusal

* The enrolment claim still asserted the pre-rename wording, so it went red on the branch where only the carrier had been swept

* Answer the dual-denominator question in the carrier, and decline the witness that would decorate it

Review asked, reasonably, whether a subject key is stable under a file the declaration
index cannot classify -- the case gunbc#9231 made block instead of vanish -- and said it
would look for that witness first.

THE ANSWER IS STRUCTURAL AND IT IS NOW IN THE CARRIER: the key's root is a SOURCE ROOT,
not a file. No file's classification can add a key, remove one, or change one, because no
key names a file -- the matrix is roots times kinds and both factors are closed and
authored. The two denominators cannot disagree at this grain.

AND NO WITNESS IS AUTHORED FOR IT, DELIBERATELY. §4b says to ask whether a check's RED is
authorable BEFORE writing the check. There is no input by which a classification outcome
could reach a key, so the claim would be permanently green BY CONSTRUCTION -- a decoration,
and worse than absent, because it would be cited as coverage for an interaction it never
tested. Writing it would have satisfied the review and weakened the evidence.

Where the denominators DO matter is one layer out, in the frontier whose roster is keyed by
ENTRY PATH and where a file is exactly what can vanish. That is hole 2, and it is closed
there -- in the carrier that can express the failure.

Entry compiles 0 blocking.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* WITHDRAWN: the three "blocking diagnostics on main" in the previous commit message were my stale compiler

The commit message on f495de5 reports that main carries three blocking emit
diagnostics in `extdeps.filesystem.filesystem_io` (`Read`/`Delete`/`List`, file transport
output keys with no modeled channel), landed by #9265. THAT IS FALSE and this commit
withdraws it. No carrier was touched by the claim -- it lived only in that message and in
one message to a peer, both corrected.

RE-MEASURED, not merely conceded. Rebuilt the compiler from THIS tree, which contains
37bb097, and compiled the same entry: 0 blocking. The binary I used originally was
tree-built but from a1856a5, and `git merge-base --is-ancestor 37bb097
a1856a5` is FALSE -- so its source predated the change by construction, not by clock.

WHAT #9265 ACTUALLY DID: it ADDED `read_success`, `delete_success`, `list_success` and
`entries` to the modeled-channel set. It is the fix. My compiler was old enough to be the
last version that refused them, and it reported main as broken in exactly the way it had
just been repaired.

WHY THIS IS WORTH A COMMIT RATHER THAN A QUIET DELETION. The output was not obviously
wrong: one specific, typed, correctly-located semantic diagnostic naming three real output
keys in a real module -- indistinguishable from a true finding, and I nearly queued it for
a transport owner who would have spent a morning fixing something that already worked. A
stale instrument does not announce itself; it produces a plausible measurement of a tree it
has never seen. The instrument's age is a property of the SOURCE it was built from, and
that is checkable (`merge-base --is-ancestor`) where a file timestamp is not -- my binary's
mtime was LATER than the commit it lacked.

THE STANDING CHANGE: a compile result about main is only evidence if the compiler contains
main. I check that with merge-base before reporting a diagnostic as a finding, not after.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Brian Searls <11205878+briansrls@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant