Repository navigation
The live extdeps scope cover was false over 59 files: enroll every one as a carrier that actually declares its scope - #9276
Conversation
…e as a carrier that actually declares its scope (#adhoc) `frontier_cover_of_live_extdeps_tree_holds` executed to FALSE. Measured cause: 59 of the 636 `.dag` files under `dag/extdeps` were in none of the three rosters the frontier admits — not carriers, not machinery, not manifest rows. The manifest is frozen (`legacy_manifest_freeze_sha`), so none of them could join it; the only landing state a new file has is scope carrier or genuine machinery, and `scope_machinery_exempt_paths` is exactly the citation vocabulary plus the mock corpora, which none of these are. So all 59 are carriers, and the repair is the one the frontier's own law prescribes rather than a widened exemption. 27 of the 59 already declared `extdeps_model_scope` and were simply missing from `scope_carrier_paths` — roster repair. The other 32 declared no scope at all, so the roster row alone would have been path assertion of a fact the file does not carry, which `carrier_content_verification_note` records as the defect closed by codex review 46215. Each of those 32 now declares one `ExternalModelScope` whose subject is a `DeclarationRef` to a real declaration in its own module, per the `extdeps.firmware.types` / `extdeps.land_pattern.types` precedent. Three cite the module's `service` declaration (`posix.Signal`, `systemd.Journalctl`, `rustc.Check`), which is what those modules actually model. `extdeps.languages.rust.capabilities` additionally carried NO `extdeps_external_authority_anchor` at all, so it was outside the mandatory-tag region-1 wall as well; it gets the anchor (the Rust derive-attribute reference) and a second citation to the serde derive reference, since its own note already records that Serialize/Deserialize are serde names — one alphabet attested by two upstreams, not two subjects fused into one row. EXECUTED EVIDENCE, both directions: - `claim_batch --wet ... --functions frontier_cover_of_live_extdeps_tree_holds,red_cover_walker_refuses_missing_root` → PASS on both. The subject witness was the failing one; its RED control still refuses a missing root. - `v1_src_dag_parse` (the `--required-ci` parse phase's own walk, one dispatch): 4019 files parse-clean, citations 1441 → 1503, ZERO integrity findings — so every one of the new `DeclarationRef`s resolves under the cited-symbol wall. - DISCRIMINATING RED for that half: `tar_program` → `tar_program_definitely_not_declared` yields exit 1 and `CITED-DECLARATION-ABSENT ... which that module does not declare`, restored before commit. NOT TOUCHED: the frozen manifest gains no row and loses none, so `manifest_rows_all_predate_freeze_sha` and the remove-only line gate are unaffected by construction. No exemption channel is widened and no roster row names a file that is not on disk (all three rosters stay disjoint and fully resolve, checked before and after). Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…anded inside the v1 seed closure CI's build lane refused: `required-regen: FAIL generated surface drift: extdeps_languages_rust_capabilities.rs`. One of the 32 modules that gained an `extdeps_model_scope` declaration — `extdeps.languages.rust.capabilities`, which also gained its missing `extdeps_external_authority_anchor` — is inside the v1 seed's regen closure, so its emitted mirror is a DERIVED artifact of the `.dag` source and was stale the moment the source changed. The other 31 are outside the closure and emit nothing, which is why exactly one file drifted. The mirror is REGENERATED, not hand-edited: taken verbatim from `target/stage0-regen-candidate` produced by `claim_executor --required-regen`. The delta is exactly the three new declarations (`extdeps_external_authority_anchor`, `rust_serde_derive_external_authority_anchor`, `extdeps_model_scope`) plus the imports they pull in — nothing else moved. EXECUTED EVIDENCE, one remote dispatch after installing it: - `cargo fmt --all --check` → FMT_OK (the emitted artifact is already the formatter's fixed point, so the two consumers of it agree). - `claim_executor --required-regen --source-root dag --source-root src/v2` → `first_generation_equal=true planned=136 executed=136`, exit 0. The same command was `first_generation_equal=false` with the FAIL line before the install, which is this fix's discriminating red. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…ite ONE upstream on the capabilities scope Three things, all consequences of re-verifying against a main that moved. 1. MAIN MERGED (tip 0aa09c1, the post-#9343 tree). Clean, no conflicts. The prior green predated main breaking and being fixed, so it was unverified rather than passing. 2. TWO NEW EXTDEPS FILES ENROLLED. `dag/extdeps/linux/cgroup_v2.dag` and `cgroup_v2_memory.dag` landed on main after my last push and were in none of the three rosters, so the merge re-falsified the cover this PR exists to repair. Both now declare an `extdeps_model_scope` (subjects `linux.CgroupV2` and `CgroupMemoryInterfaceFile`) and join `scope_carrier_paths` — the same treatment as the other 59, no widened exemption. 3. THE CAPABILITIES SCOPE NOW CITES ONE UPSTREAM (review 56339). An earlier revision listed serde.rs beside the Rust derive reference in `further_citations`. That is wrong on DESIGN §3 and the reviewer is right: `further_citations` attests ONE subject, so listing an independently governed upstream there asserts serde governs the same subject rather than recording that the module mentions it. The citation and its now-unreferenced anchor row are deleted; the annotation records where the serde spellings ARE attested (`extdeps.languages.rust.derive_contracts` carries versioned serde trait authorities). NOT DONE, deliberately: the review's prescribed remedy was to split `RustCapability` into two module authorities. Declined, with reasons on the PR — it is a modeling change to a load-bearing seed-closure carrier consumed by `v1.compiler.trait_derive_emit`, resting on the recorded 2026-08-19 operator ruling that re-homed the closed alphabet here, and the module's own note records that dissolving the coproduct trades an exhaustive match for a runtime refusal. DESIGN additionally names subject-content coherence as the UNENFORCED frontier `feature:extdeps-subject-content-derived`; what the scope frontier enforces is scope PRESENCE at storage grain. EXECUTED EVIDENCE on the merged, corrected tree (cold remote builds, binary and tree the same generation by construction — no stale-binary skew): - `v1_src_dag_parse`: 4080 files parse-clean, ZERO integrity findings, exit 0. - `claim_executor --required-regen`: the serde-anchor removal drifted the mirror (`FAIL generated surface drift: extdeps_languages_rust_capabilities.rs`); the mirror is REGENERATED from `target/stage0-regen-candidate`, delta exactly the deleted anchor fn and `further_citations` vec![serde] -> vec![]. After installing it: `cargo fmt --all --check` FMT_OK and `first_generation_equal=true planned=136 executed=136`, exit 0. The drift FAIL before the install is that fix's discriminating red. - Cover re-checked over the merged tree by set comparison: 647 files on disk, three rosters disjoint, zero unrostered, zero rostered-not-on-disk, zero carriers lacking the declaration. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
Re review 56339 — the §3 half is accepted and fixed in Fixed. Declined: splitting
If the split is wanted, it is a separate PR against that operator ruling with its own review surface, and I would want the ruling revisited rather than reversed by a review comment. — sent from quiet-fox-377 |
|
Re review 56347 — the finding is factually right, and read together with review 56339 it is stronger than either alone. I have declared it rather than papered over it, and escalated the remedy. Both reviews are correct, and they are mutually exclusive. Review 56339 said two citations fuse two independently governed upstreams into one scope. Review 56347 says that after removing serde, a Rust-only scope over Why that is not a citation edit. The §3 remedy is separate module authorities, i.e. a remodel of a carrier consumed by Why the module cannot simply be left out. It is one of the files that were in none of the three frontier rosters. The manifest is frozen ( What I did instead of choosing a shape and calling it coherent. Escalated. I have asked the operator, through my parent session, to rule between (a) landing this enrolment with the declared debt and opening the split as its own PR against the 2026-08-19 ruling, or (b) blocking this cover repair behind that split. I took (a) provisionally so the other 60 enrolments are not held hostage. If the ruling is (b) I will switch. — sent from quiet-fox-377 |
…onesty statement rather than a debt admission Reviews 56339 and 56347 on this PR rejected OPPOSITE citation shapes on one declaration: two citations fuse two independently governed upstreams into one scope; one citation leaves RustSerialize and RustDeserialize unattested by the subject that claims them. Both findings are correct, and being mutually exclusive is what they establish together — no citation shape over `RustCapability` is a coherent single-subject attestation, because the alphabet mixes derive names the Rust reference governs with two serde governs. The §3 defect is in the CARRIER, not in any scope edit. WHAT LANDS: the scope keeps its single Rust citation, and the annotation above it now says what the scope does not cover. It does not assert the scope is truthful; it states that the citation names the Rust reference while the declaration it covers carries two serde-governed members, and says to read it that way. `rust_capabilities_note` and `rust_capability_alphabet_note` are cited as the authority for WHY the mixture stands (the operator ruling of 2026-08-19, option b, and its reason: an open TargetCapabilityKey brand cannot be matched exhaustively, so rust_trait_derive_spelling stays TOTAL only while the alphabet is closed). Both review ids are carried so the finding is reconstructible. FRAMING CORRECTED, and it changes the words rather than the change. An earlier revision wrote this as DECLARED DEBT with "not permission for it (§5)" beside it, which imports the scaffold-admission doctrine into a place it does not reach: that doctrine governs artifacts authored in order to be deleted, and nothing here is created — the incoherence pre-dates this PR and rests on a recorded operator ruling. This is a §4b(1) rung-honesty statement about a state that already exists, which DESIGN requires; declining to write it would be the inflation §4b names as worse than sitting low. So it describes the carrier and promises nothing about it. Bounded population (one declaration, two of sixteen variants) and both dissolution triggers are unchanged. THE SPLIT IS NOT OPENED AS A PR, and that is now the stronger position rather than a narrow-brief decline. The 2026-08-19 ruling is not an oversight: its reason is a safety argument, and reversing it trades an exhaustive match for a runtime refusal — a §4b rung drop, which requires a declared previous rung, reason, bounded population and restoration trigger that no PR author can supply against a ruling that went the other way. It is a question for the operator, escalated as one with the mutually-exclusive review pair as its evidence. EXECUTED EVIDENCE (cold remote build, merged tree): - `v1_src_dag_parse`: 4080 files parse-clean, ZERO integrity findings, exit 0 — so the §4c annotation form is admitted (standalone leading `//` block attached to a module-scope declaration). - `claim_executor --required-regen`: `first_generation_equal=true planned=136 executed=136`, exit 0. An annotation-only change does NOT drift the emitted mirror, which is §4c's erasure property measured rather than assumed. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
Follow-up on reviews 56339 / 56347 — ruled, and one thing I said earlier is now wrong. Ruling: land the enrolment with the incoherence stated, do not block on the split. Landed in Correcting my previous comment. I offered to open the split as its own PR. I am not going to, and that is the stronger position rather than a narrower one. The 2026-08-19 operator ruling recorded in One framing correction in the annotation itself, because it was wrong in a way worth naming. I first wrote it as declared debt with a §5 "not permission for it" caveat. That imports the scaffold-admission doctrine into a place it does not reach: that doctrine governs artifacts authored in order to be deleted, and nothing here is created — the incoherence pre-dates this PR and rests on the recorded ruling. It is a §4b(1) rung-honesty statement about a state that already exists, which DESIGN requires; declining to write it would have been the inflation §4b calls worse than sitting low. The annotation now describes the carrier and promises nothing about it: it says the citation names the Rust reference while the declaration it covers carries two serde-governed members, cites Measured, not assumed: — sent from quiet-fox-377 |
frontier_cover_of_live_extdeps_tree_holdsexecuted to FALSE. Measured cause: 59of the 636
.dagfiles underdag/extdepswere in none of the three rosters thefrontier admits — not carriers, not machinery, not manifest rows. The manifest is
frozen (
legacy_manifest_freeze_sha), so none of them could join it; the onlylanding state a new file has is scope carrier or genuine machinery, and
scope_machinery_exempt_pathsis exactly the citation vocabulary plus the mockcorpora, which none of these are. So all 59 are carriers, and the repair is the
one the frontier's own law prescribes rather than a widened exemption.
27 of the 59 already declared
extdeps_model_scopeand were simply missing fromscope_carrier_paths— roster repair. The other 32 declared no scope at all, sothe roster row alone would have been path assertion of a fact the file does not
carry, which
carrier_content_verification_noterecords as the defect closed bycodex review 46215. Each of those 32 now declares one
ExternalModelScopewhosesubject is a
DeclarationRefto a real declaration in its own module, per theextdeps.firmware.types/extdeps.land_pattern.typesprecedent. Three cite themodule's
servicedeclaration (posix.Signal,systemd.Journalctl,rustc.Check), which is what those modules actually model.extdeps.languages.rust.capabilitiesadditionally carried NOextdeps_external_authority_anchorat all, so it was outside the mandatory-tagregion-1 wall as well; it gets the anchor (the Rust derive-attribute reference)
and a second citation to the serde derive reference, since its own note already
records that Serialize/Deserialize are serde names — one alphabet attested by two
upstreams, not two subjects fused into one row.
EXECUTED EVIDENCE, both directions:
claim_batch --wet ... --functions frontier_cover_of_live_extdeps_tree_holds,red_cover_walker_refuses_missing_root→ PASS on both. The subject witness was the failing one; its RED control still
refuses a missing root.
v1_src_dag_parse(the--required-ciparse phase's own walk, one dispatch):4019 files parse-clean, citations 1441 → 1503, ZERO integrity findings — so
every one of the new
DeclarationRefs resolves under the cited-symbol wall.tar_program→tar_program_definitely_not_declaredyields exit 1 and
CITED-DECLARATION-ABSENT ... which that module does not declare,restored before commit.
NOT TOUCHED: the frozen manifest gains no row and loses none, so
manifest_rows_all_predate_freeze_shaand the remove-only line gate areunaffected by construction. No exemption channel is widened and no roster row
names a file that is not on disk (all three rosters stay disjoint and fully
resolve, checked before and after).
Co-Authored-By: Claude Opus 5 (1M context) noreply@anthropic.com
🤖 Generated with Claude Code