diff --git a/dag/extdeps/accounting/encumbrance.dag b/dag/extdeps/accounting/encumbrance.dag index 1270dbb817f..9342be045c8 100644 --- a/dag/extdeps/accounting/encumbrance.dag +++ b/dag/extdeps/accounting/encumbrance.dag @@ -4,7 +4,8 @@ import std.measure { Measure, measure_add, measure_le } import std.nat { Nat } import std.types { NonEmptyStr, List, Timestamp } import extdeps.accounting.budget { Appropriation } -import extdeps.external_authority { ExternalAuthority } +import extdeps.external_authority { ExternalAuthority, ExternalModelScope, ExternalSubjectRef } +import std.decl_ref { DeclarationRef, WholeDeclaration } import extdeps.uri { Uri, Https } // Encumbrance accounting, the upstream this module models. In fund and @@ -33,6 +34,18 @@ data extdeps_external_authority_anchor: ExternalAuthority = ExternalAuthority { } } +data extdeps_model_scope: ExternalModelScope = ExternalModelScope { + subject: ExternalSubjectRef { + declaration: DeclarationRef { + module_path: "extdeps.accounting.encumbrance", + decl_name: "Encumbrance", + field: WholeDeclaration + } + }, + first_citation: extdeps_external_authority_anchor, + further_citations: [] +} + // The lifecycle is a closed three-state coproduct rather than a record with // nullable settlement fields. A reservation is held, or it settled at an exact // amount, or it was released with a reason - and no fourth state exists to be diff --git a/dag/extdeps/ci_runner/blacksmith.dag b/dag/extdeps/ci_runner/blacksmith.dag index 54e50972936..eaea6b0cf15 100644 --- a/dag/extdeps/ci_runner/blacksmith.dag +++ b/dag/extdeps/ci_runner/blacksmith.dag @@ -3,7 +3,7 @@ module extdeps.ci_runner.blacksmith import std.types { List, NonEmptyStr } import std.nat { Nat } import std.measure { hardware_thread_count } -import std.decl_ref { DeclarationRef, decl_ref } +import std.decl_ref { DeclarationRef, decl_ref, WholeDeclaration } import extdeps.toolchain.types { Aarch64, Architecture, X86_64 } import extdeps.ci_runner.types { EntitlementUnstated, @@ -13,7 +13,7 @@ import extdeps.ci_runner.types { RunnerShapesCited, } -import extdeps.external_authority { ExternalAuthority } +import extdeps.external_authority { ExternalAuthority, ExternalModelScope, ExternalSubjectRef } import extdeps.uri { Uri, Https } data extdeps_external_authority_anchor: ExternalAuthority = ExternalAuthority { @@ -23,6 +23,18 @@ data extdeps_external_authority_anchor: ExternalAuthority = ExternalAuthority { } } +data extdeps_model_scope: ExternalModelScope = ExternalModelScope { + subject: ExternalSubjectRef { + declaration: DeclarationRef { + module_path: "extdeps.ci_runner.blacksmith", + decl_name: "blacksmith_runner_catalog", + field: WholeDeclaration + } + }, + first_citation: extdeps_external_authority_anchor, + further_citations: [] +} + data blacksmith_instance_types_authority: ExternalAuthority = extdeps_external_authority_anchor data blacksmith_provider_identity: DeclarationRef = decl_ref( diff --git a/dag/extdeps/ci_runner/circleci.dag b/dag/extdeps/ci_runner/circleci.dag index 39289303d44..728e3963ab2 100644 --- a/dag/extdeps/ci_runner/circleci.dag +++ b/dag/extdeps/ci_runner/circleci.dag @@ -3,7 +3,7 @@ module extdeps.ci_runner.circleci import std.types { List, NonEmptyStr } import std.nat { Nat } import std.measure { hardware_thread_count } -import std.decl_ref { DeclarationRef, decl_ref } +import std.decl_ref { DeclarationRef, decl_ref, WholeDeclaration } import extdeps.toolchain.types { Aarch64, Architecture, X86_64 } import extdeps.ci_runner.types { EntitlementUnstated, @@ -13,7 +13,7 @@ import extdeps.ci_runner.types { RunnerShapesCited, } -import extdeps.external_authority { ExternalAuthority } +import extdeps.external_authority { ExternalAuthority, ExternalModelScope, ExternalSubjectRef } import extdeps.uri { Uri, Https } data extdeps_external_authority_anchor: ExternalAuthority = ExternalAuthority { @@ -23,6 +23,18 @@ data extdeps_external_authority_anchor: ExternalAuthority = ExternalAuthority { } } +data extdeps_model_scope: ExternalModelScope = ExternalModelScope { + subject: ExternalSubjectRef { + declaration: DeclarationRef { + module_path: "extdeps.ci_runner.circleci", + decl_name: "circleci_runner_catalog", + field: WholeDeclaration + } + }, + first_citation: extdeps_external_authority_anchor, + further_citations: [] +} + data circleci_catalog_authority: ExternalAuthority = extdeps_external_authority_anchor data circleci_provider_identity: DeclarationRef = decl_ref( diff --git a/dag/extdeps/ci_runner/depot.dag b/dag/extdeps/ci_runner/depot.dag index 43916553702..1f3dd3e21ca 100644 --- a/dag/extdeps/ci_runner/depot.dag +++ b/dag/extdeps/ci_runner/depot.dag @@ -3,7 +3,7 @@ module extdeps.ci_runner.depot import std.types { List, NonEmptyStr } import std.nat { Nat } import std.measure { hardware_thread_count } -import std.decl_ref { DeclarationRef, decl_ref } +import std.decl_ref { DeclarationRef, decl_ref, WholeDeclaration } import extdeps.toolchain.types { Aarch64, Architecture, X86_64 } import extdeps.ci_runner.types { EntitlementUnstated, @@ -13,7 +13,7 @@ import extdeps.ci_runner.types { RunnerShapesCited, } -import extdeps.external_authority { ExternalAuthority } +import extdeps.external_authority { ExternalAuthority, ExternalModelScope, ExternalSubjectRef } import extdeps.uri { Uri, Https } data extdeps_external_authority_anchor: ExternalAuthority = ExternalAuthority { @@ -23,6 +23,18 @@ data extdeps_external_authority_anchor: ExternalAuthority = ExternalAuthority { } } +data extdeps_model_scope: ExternalModelScope = ExternalModelScope { + subject: ExternalSubjectRef { + declaration: DeclarationRef { + module_path: "extdeps.ci_runner.depot", + decl_name: "depot_runner_catalog", + field: WholeDeclaration + } + }, + first_citation: extdeps_external_authority_anchor, + further_citations: [] +} + data depot_catalog_authority: ExternalAuthority = extdeps_external_authority_anchor data depot_provider_identity: DeclarationRef = decl_ref( diff --git a/dag/extdeps/ci_runner/github_actions.dag b/dag/extdeps/ci_runner/github_actions.dag index f31258e60da..e3d832753e7 100644 --- a/dag/extdeps/ci_runner/github_actions.dag +++ b/dag/extdeps/ci_runner/github_actions.dag @@ -3,7 +3,7 @@ module extdeps.ci_runner.github_actions import std.types { List, NonEmptyStr } import std.nat { Nat } import std.measure { hardware_thread_count } -import std.decl_ref { DeclarationRef, decl_ref } +import std.decl_ref { DeclarationRef, decl_ref, WholeDeclaration } import extdeps.toolchain.types { Aarch64, Architecture, X86_64 } import extdeps.ci_runner.types { EntitlementUnstated, @@ -13,7 +13,7 @@ import extdeps.ci_runner.types { RunnerShapesCited, } -import extdeps.external_authority { ExternalAuthority } +import extdeps.external_authority { ExternalAuthority, ExternalModelScope, ExternalSubjectRef } import extdeps.uri { Uri, Https } data extdeps_external_authority_anchor: ExternalAuthority = ExternalAuthority { @@ -23,6 +23,18 @@ data extdeps_external_authority_anchor: ExternalAuthority = ExternalAuthority { } } +data extdeps_model_scope: ExternalModelScope = ExternalModelScope { + subject: ExternalSubjectRef { + declaration: DeclarationRef { + module_path: "extdeps.ci_runner.github_actions", + decl_name: "github_actions_runner_catalog", + field: WholeDeclaration + } + }, + first_citation: extdeps_external_authority_anchor, + further_citations: [] +} + data github_actions_catalog_authority: ExternalAuthority = extdeps_external_authority_anchor data github_actions_provider_identity: DeclarationRef = decl_ref( diff --git a/dag/extdeps/ci_runner/types.dag b/dag/extdeps/ci_runner/types.dag index dea9328cc31..62a37a633a7 100644 --- a/dag/extdeps/ci_runner/types.dag +++ b/dag/extdeps/ci_runner/types.dag @@ -2,7 +2,7 @@ module extdeps.ci_runner.types import std.types { Bool, List, NonEmptyStr } import std.nat { Nat } -import std.decl_ref { DeclarationRef } +import std.decl_ref { DeclarationRef, WholeDeclaration } import extdeps.toolchain.types { Architecture } import std.measure { ByteSize, @@ -14,7 +14,7 @@ import std.measure { gigabyte_count, } -import extdeps.external_authority { ExternalAuthority } +import extdeps.external_authority { ExternalAuthority, ExternalModelScope, ExternalSubjectRef } import extdeps.uri { Uri, Https } data extdeps_external_authority_anchor: ExternalAuthority = ExternalAuthority { @@ -24,6 +24,18 @@ data extdeps_external_authority_anchor: ExternalAuthority = ExternalAuthority { } } +data extdeps_model_scope: ExternalModelScope = ExternalModelScope { + subject: ExternalSubjectRef { + declaration: DeclarationRef { + module_path: "extdeps.ci_runner.types", + decl_name: "RunnerShapeRow", + field: WholeDeclaration + } + }, + first_citation: extdeps_external_authority_anchor, + further_citations: [] +} + // THE AGNOSTIC SHAPE ONLY. Per DESIGN's external-upstream decomposition rule // this hub defines the contract every CI runner provider's published catalog // inhabits; it does NOT enumerate providers, dispatch among them, or hold any diff --git a/dag/extdeps/ci_runner/warpbuild.dag b/dag/extdeps/ci_runner/warpbuild.dag index d50eb10a968..43b19abbf7a 100644 --- a/dag/extdeps/ci_runner/warpbuild.dag +++ b/dag/extdeps/ci_runner/warpbuild.dag @@ -3,7 +3,7 @@ module extdeps.ci_runner.warpbuild import std.types { List, NonEmptyStr } import std.nat { Nat } import std.measure { hardware_thread_count } -import std.decl_ref { DeclarationRef, decl_ref } +import std.decl_ref { DeclarationRef, decl_ref, WholeDeclaration } import extdeps.toolchain.types { Aarch64, Architecture, X86_64 } import extdeps.ci_runner.types { EntitlementUnstated, @@ -13,7 +13,7 @@ import extdeps.ci_runner.types { RunnerShapesCited, } -import extdeps.external_authority { ExternalAuthority } +import extdeps.external_authority { ExternalAuthority, ExternalModelScope, ExternalSubjectRef } import extdeps.uri { Uri, Https } data extdeps_external_authority_anchor: ExternalAuthority = ExternalAuthority { @@ -23,6 +23,18 @@ data extdeps_external_authority_anchor: ExternalAuthority = ExternalAuthority { } } +data extdeps_model_scope: ExternalModelScope = ExternalModelScope { + subject: ExternalSubjectRef { + declaration: DeclarationRef { + module_path: "extdeps.ci_runner.warpbuild", + decl_name: "warpbuild_runner_catalog", + field: WholeDeclaration + } + }, + first_citation: extdeps_external_authority_anchor, + further_citations: [] +} + data warpbuild_catalog_authority: ExternalAuthority = extdeps_external_authority_anchor data warpbuild_provider_identity: DeclarationRef = decl_ref( diff --git a/dag/extdeps/cloud/gcp/adc_document.dag b/dag/extdeps/cloud/gcp/adc_document.dag index ba962171c12..e0b6029ac8a 100644 --- a/dag/extdeps/cloud/gcp/adc_document.dag +++ b/dag/extdeps/cloud/gcp/adc_document.dag @@ -1,6 +1,7 @@ module extdeps.cloud.gcp.adc_document -import extdeps.external_authority { ExternalAuthority } +import extdeps.external_authority { ExternalAuthority, ExternalModelScope, ExternalSubjectRef } +import std.decl_ref { DeclarationRef, WholeDeclaration } import extdeps.uri { Uri, Https } import extdeps.languages.json.emit { JsonValue, @@ -30,6 +31,18 @@ data extdeps_external_authority_anchor: ExternalAuthority = ExternalAuthority { } } +data extdeps_model_scope: ExternalModelScope = ExternalModelScope { + subject: ExternalSubjectRef { + declaration: DeclarationRef { + module_path: "extdeps.cloud.gcp.adc_document", + decl_name: "GcpApplicationDefaultCredentials", + field: WholeDeclaration + } + }, + first_citation: extdeps_external_authority_anchor, + further_citations: [] +} + // The authorized-user ADC document is a JSON object, so the seam from a file to // these three fields is read-then-decode over two authorities that already // exist. A `transport file` carries bytes and models eight channels; naming a diff --git a/dag/extdeps/colo/types.dag b/dag/extdeps/colo/types.dag index 51f832d4bc2..9fa7696ed42 100644 --- a/dag/extdeps/colo/types.dag +++ b/dag/extdeps/colo/types.dag @@ -7,7 +7,8 @@ import std.measure { Watt, Ampere, Volt, RackUnit, Bandwidth, ByteSize, } -import extdeps.external_authority { ExternalAuthority } +import extdeps.external_authority { ExternalAuthority, ExternalModelScope, ExternalSubjectRef } +import std.decl_ref { DeclarationRef, WholeDeclaration } import extdeps.uri { Uri, Https } data extdeps_external_authority_anchor: ExternalAuthority = ExternalAuthority { @@ -17,6 +18,18 @@ data extdeps_external_authority_anchor: ExternalAuthority = ExternalAuthority { } } +data extdeps_model_scope: ExternalModelScope = ExternalModelScope { + subject: ExternalSubjectRef { + declaration: DeclarationRef { + module_path: "extdeps.colo.types", + decl_name: "ColoFacilityRow", + field: WholeDeclaration + } + }, + first_citation: extdeps_external_authority_anchor, + further_citations: [] +} + // AGNOSTIC SHAPES ONLY, per the external-upstream-decomposition rule: this hub defines the // vocabulary a colocation provider's cited rows inhabit and enumerates NO concrete provider, // facility, or plan. Each independently governed operator has its own extdeps.colo module diff --git a/dag/extdeps/git/plumbing.dag b/dag/extdeps/git/plumbing.dag index 7d627484045..16c270e095a 100644 --- a/dag/extdeps/git/plumbing.dag +++ b/dag/extdeps/git/plumbing.dag @@ -1,7 +1,8 @@ module extdeps.git.plumbing import std.types { Bool, FilePath, Int, List, NonEmptyStr, String } -import extdeps.external_authority { ExternalAuthority } +import extdeps.external_authority { ExternalAuthority, ExternalModelScope, ExternalSubjectRef } +import std.decl_ref { DeclarationRef, WholeDeclaration } import extdeps.uri { Uri, Https } import extdeps.git.object_store { GitObjectId, GitRefName, git_object_id_eq, git_object_id_wire_hex } @@ -12,6 +13,18 @@ data extdeps_external_authority_anchor: ExternalAuthority = ExternalAuthority { } } +data extdeps_model_scope: ExternalModelScope = ExternalModelScope { + subject: ExternalSubjectRef { + declaration: DeclarationRef { + module_path: "extdeps.git.plumbing", + decl_name: "GitRepositoryAddress", + field: WholeDeclaration + } + }, + first_citation: extdeps_external_authority_anchor, + further_citations: [] +} + // WHY THIS MODULE EXISTS. `extdeps.git` models git's porcelain and read surface; git's // OBJECT-STORE PLUMBING surface -- hash-object, cat-file, read-tree, write-tree, // update-index, checkout-index, commit-tree, unpack-file, update-ref -- was modeled diff --git a/dag/extdeps/github/commits.dag b/dag/extdeps/github/commits.dag index 740a6c60efc..fbb2b078ae3 100644 --- a/dag/extdeps/github/commits.dag +++ b/dag/extdeps/github/commits.dag @@ -4,7 +4,8 @@ import extdeps.github.github { default_api_base, default_per_page } import extdeps.github.errors { GitHubErrorShape } import std.types { String, Int, CommitSha, NonEmptyStr, Timestamp, List } import std.credentials { EnvVar } -import extdeps.external_authority { ExternalAuthority } +import extdeps.external_authority { ExternalAuthority, ExternalModelScope, ExternalSubjectRef } +import std.decl_ref { DeclarationRef, WholeDeclaration } import extdeps.uri { Uri, Https } // The GitHub REST commits API area. Modeled here rather than folded into an existing github module @@ -20,6 +21,18 @@ data extdeps_external_authority_anchor: ExternalAuthority = ExternalAuthority { } } +data extdeps_model_scope: ExternalModelScope = ExternalModelScope { + subject: ExternalSubjectRef { + declaration: DeclarationRef { + module_path: "extdeps.github.commits", + decl_name: "CommitDetail", + field: WholeDeclaration + } + }, + first_citation: extdeps_external_authority_anchor, + further_citations: [] +} + type CommitParentRef { sha: CommitSha } diff --git a/dag/extdeps/languages/bash/invocation.dag b/dag/extdeps/languages/bash/invocation.dag index cd8523c6c26..2622562f9dc 100644 --- a/dag/extdeps/languages/bash/invocation.dag +++ b/dag/extdeps/languages/bash/invocation.dag @@ -1,7 +1,8 @@ module extdeps.languages.bash.invocation import std.types { String, NonEmptyStr } -import extdeps.external_authority { ExternalAuthority } +import extdeps.external_authority { ExternalAuthority, ExternalModelScope, ExternalSubjectRef } +import std.decl_ref { DeclarationRef, WholeDeclaration } import extdeps.uri { Uri, Https } import extdeps.exec.command { ArgvCommand, argv_command } @@ -12,6 +13,18 @@ data extdeps_external_authority_anchor: ExternalAuthority = ExternalAuthority { } } +data extdeps_model_scope: ExternalModelScope = ExternalModelScope { + subject: ExternalSubjectRef { + declaration: DeclarationRef { + module_path: "extdeps.languages.bash.invocation", + decl_name: "bash_program_name", + field: WholeDeclaration + } + }, + first_citation: extdeps_external_authority_anchor, + further_citations: [] +} + // BASH IS NOT `sh`, AND THE CALLER PICKED IT DELIBERATELY. extdeps.posix.shell_command_language // posix_sh_program_command runs a program against the POSIX specification; this runs one against GNU // Bash, whose grammar is a superset. A site using `[[`, arrays, `local`, or process substitution is diff --git a/dag/extdeps/languages/rust/capabilities.dag b/dag/extdeps/languages/rust/capabilities.dag index 986ec68caf5..1e04e2c33d7 100644 --- a/dag/extdeps/languages/rust/capabilities.dag +++ b/dag/extdeps/languages/rust/capabilities.dag @@ -17,6 +17,56 @@ import std.algebra { Cons, Empty } +import extdeps.external_authority { ExternalAuthority, ExternalModelScope, ExternalSubjectRef } +import extdeps.uri { Uri, Https } +import std.decl_ref { DeclarationRef, WholeDeclaration } + +// WHAT THIS SCOPE NAMES, AND WHAT IT DOES NOT COVER. The citation is the Rust language reference, +// which governs the `#[derive]` attribute mechanism. The alphabet the subject points at is NOT +// wholly Rust-governed: RustSerialize and RustDeserialize are serde names, and serde is an +// independently versioned upstream. So this scope names one subject while the declaration it covers +// carries members two upstreams govern, and it should be read that way rather than as a coherent +// single-subject attestation. +// +// WHY THE MIXTURE STANDS is not this declaration's decision and is recorded below: +// rust_capabilities_note carries the operator ruling of 2026-08-19 (option b) that re-homed the +// closed alphabet here, and rust_capability_alphabet_note carries its reason — an open +// TargetCapabilityKey brand cannot be matched exhaustively, so rust_trait_derive_spelling stays +// TOTAL only while the alphabet is closed. The serde spellings are separately attested where they +// are modeled: extdeps.languages.rust.derive_contracts carries versioned serde trait authorities. +// +// HOW THIS WAS FOUND, because the pair is what establishes the claim: reviews 56339 and 56347 on +// gunbc#9276 rejected OPPOSITE citation shapes here — two citations fuse two governed upstreams into +// one scope, one citation leaves the serde members unattested by the subject that claims them. Both +// are correct, so no citation shape over this declaration is coherent; the §3 remedy is separate +// module authorities, which is a remodel of the carrier and not an edit to any scope. +// +// WHAT IS MECHANICALLY ENFORCED, so the rung is not read higher than it is: gunbc.extdeps_scope_frontier +// enforces scope PRESENCE at the storage grain. Subject-content coherence — that a module's +// declarations attribute to exactly its declared subject — is the named unenforced frontier +// feature:extdeps-subject-content-derived (extdeps.external_authority +// external_model_scope_decision_kernel_note). BOUNDED POPULATION: one declaration, two of its +// sixteen variants. This annotation deletes when the alphabet is split into Rust-governed and +// serde-governed authorities, or when the subject-content projection derives DeclaredScopeFacts from +// the module tree and refuses this scope — whichever lands first. +data extdeps_external_authority_anchor: ExternalAuthority = ExternalAuthority { + uri: Uri { + scheme: Https + locator: "doc.rust-lang.org/reference/attributes/derive.html" + } +} + +data extdeps_model_scope: ExternalModelScope = ExternalModelScope { + subject: ExternalSubjectRef { + declaration: DeclarationRef { + module_path: "extdeps.languages.rust.capabilities", + decl_name: "RustCapability", + field: WholeDeclaration + } + }, + first_citation: extdeps_external_authority_anchor, + further_citations: [] +} data rust_capabilities_note: String = "Rust and serde CAPABILITY ROWS for the B1 capability-keyed model (operator ruling 2026-08-19, option b). std.trait_derive_shape holds the AGNOSTIC half -- the source-shape vocabulary and a table lookup PARAMETERIZED on the capability carrier, naming no carrier itself. THIS module holds the RUST-SPECIFIC half: the closed RustCapability alphabet, the shape-by-capability rows instantiated at K = RustCapability, and the derive-trait list builders. A new target language adds a sibling module of rows here and edits neither the fold nor std -- DESIGN section 4: a new target language is ROWS in extdeps/languages, never an edit to the fold. WHY THE COPRODUCT WAS THE WRONG CARRIER FOR THE INTERFACE: Serialize and Deserialize are serde names, not Rust language names -- an independently versioned upstream -- and their spellings were ALREADY cited in extdeps.languages.rust.emit, so the std coproduct was a redundant KEY SET forked from a key extdeps already spelled out. WHY IT IS STILL THE RIGHT CARRIER FOR THE REALIZATION: an open Symbol brand cannot be matched exhaustively, and rust_trait_derive_spelling is TOTAL by exhaustive match. So the alphabet is re-homed here rather than deleted, and because the std predicate is generic the seed path speaks the alphabet END TO END -- v1.compiler.trait_derive_emit instantiates the predicate at K = RustCapability and needs no lift into the open key space at all. An earlier revision of this migration carried rust_capability_key and rust_capability_keys to perform exactly that lift; parameterizing std deleted both, which is the usual tell that the decomposition is right. ROW FIDELITY: the rows below were extracted mechanically from the predecessor nested match and verified cell-for-cell -- 71 admitted pairs extracted against 71 in the source -- rather than re-derived by hand. WHAT IS DELIBERATELY ABSENT: sixteen one-line data rows binding each key name to its symbol literal, and a rust_capability_emission_order list, were authored in this migration and NEVER REFERENCED -- experimental residue by DESIGN section 6, deleted rather than left to read as authority. Emission order is carried by the list builders, which is where it was before this migration." diff --git a/dag/extdeps/linux/cgroup_v2.dag b/dag/extdeps/linux/cgroup_v2.dag index 4cd10dcbd4e..438890cb255 100644 --- a/dag/extdeps/linux/cgroup_v2.dag +++ b/dag/extdeps/linux/cgroup_v2.dag @@ -1,7 +1,8 @@ module extdeps.linux.cgroup_v2 import std.types { Bool, NonEmptyStr, String } -import extdeps.external_authority { ExternalAuthority } +import extdeps.external_authority { ExternalAuthority, ExternalModelScope, ExternalSubjectRef } +import std.decl_ref { DeclarationRef, WholeDeclaration } import extdeps.uri { Https, Uri } data extdeps_external_authority_anchor: ExternalAuthority = ExternalAuthority { @@ -11,6 +12,18 @@ data extdeps_external_authority_anchor: ExternalAuthority = ExternalAuthority { } } +data extdeps_model_scope: ExternalModelScope = ExternalModelScope { + subject: ExternalSubjectRef { + declaration: DeclarationRef { + module_path: "extdeps.linux.cgroup_v2", + decl_name: "linux.CgroupV2", + field: WholeDeclaration + } + }, + first_citation: extdeps_external_authority_anchor, + further_citations: [] +} + // THE UNIFIED HIERARCHY IS MOUNTED AT ONE PLACE, AND IT IS THE KERNEL'S PLACE, NOT OURS. Every // consumer that spells this path itself is a second authority for it (DESIGN 3), which is how a // mount point ends up differing by one character between the reader and the thing it reads. diff --git a/dag/extdeps/linux/cgroup_v2_memory.dag b/dag/extdeps/linux/cgroup_v2_memory.dag index 2a796670fdd..34e86fd290b 100644 --- a/dag/extdeps/linux/cgroup_v2_memory.dag +++ b/dag/extdeps/linux/cgroup_v2_memory.dag @@ -2,7 +2,8 @@ module extdeps.linux.cgroup_v2_memory import std.algebra { trim } import std.checked_arithmetic { nat_magnitude } -import extdeps.external_authority { ExternalAuthority } +import extdeps.external_authority { ExternalAuthority, ExternalModelScope, ExternalSubjectRef } +import std.decl_ref { DeclarationRef, WholeDeclaration } import extdeps.uri { Https, Uri } import std.measure { ByteSize, byte_size } import std.types { Int, NonEmptyStr, String } @@ -15,6 +16,18 @@ data extdeps_external_authority_anchor: ExternalAuthority = ExternalAuthority { } } +data extdeps_model_scope: ExternalModelScope = ExternalModelScope { + subject: ExternalSubjectRef { + declaration: DeclarationRef { + module_path: "extdeps.linux.cgroup_v2_memory", + decl_name: "CgroupMemoryInterfaceFile", + field: WholeDeclaration + } + }, + first_citation: extdeps_external_authority_anchor, + further_citations: [] +} + // THE THREE KINDS ARE THE KERNEL'S, NOT OURS. cgroup-v2 documents each memory interface file with a // distinct temporal meaning, and a carrier storing every one as a bare ByteSize would erase the // distinction that decides whether a number may be compared, summed, or differenced at all: diff --git a/dag/extdeps/posix/identity.dag b/dag/extdeps/posix/identity.dag index d3b537877b1..6df1af3e1c5 100644 --- a/dag/extdeps/posix/identity.dag +++ b/dag/extdeps/posix/identity.dag @@ -1,7 +1,8 @@ module extdeps.posix.identity import std.types { String, Int, Bool } -import extdeps.external_authority { ExternalAuthority } +import extdeps.external_authority { ExternalAuthority, ExternalModelScope, ExternalSubjectRef } +import std.decl_ref { DeclarationRef, WholeDeclaration } import extdeps.uri { Uri, Https } import v2.std.optional { Optional, Present, Absent } import v2.std.integer { integer_lexeme_to_int_optional, integer_nat_to_decimal_string } @@ -14,6 +15,18 @@ data extdeps_external_authority_anchor: ExternalAuthority = ExternalAuthority { } } +data extdeps_model_scope: ExternalModelScope = ExternalModelScope { + subject: ExternalSubjectRef { + declaration: DeclarationRef { + module_path: "extdeps.posix.identity", + decl_name: "PosixOwnerSpec", + field: WholeDeclaration + } + }, + first_citation: extdeps_external_authority_anchor, + further_citations: [] +} + // POSIX OWNS THESE TYPES; `id(1)` MERELY PRINTS THEM. extdeps.tools.id is the coreutils tool that // reports a uid and a gid, and this module is the standard those values belong to -- a separate // upstream with its own governance, per the external-upstream decomposition rule. A uid observed diff --git a/dag/extdeps/posix/path_ownership.dag b/dag/extdeps/posix/path_ownership.dag index dc754b79f50..fde9e84e6db 100644 --- a/dag/extdeps/posix/path_ownership.dag +++ b/dag/extdeps/posix/path_ownership.dag @@ -1,7 +1,8 @@ module extdeps.posix.path_ownership import std.types { String, Bool } -import extdeps.external_authority { ExternalAuthority } +import extdeps.external_authority { ExternalAuthority, ExternalModelScope, ExternalSubjectRef } +import std.decl_ref { DeclarationRef, WholeDeclaration } import extdeps.uri { Uri, Https } import extdeps.posix.identity { PosixOwnerSpec, posix_owner_spec_text } @@ -12,6 +13,18 @@ data extdeps_external_authority_anchor: ExternalAuthority = ExternalAuthority { } } +data extdeps_model_scope: ExternalModelScope = ExternalModelScope { + subject: ExternalSubjectRef { + declaration: DeclarationRef { + module_path: "extdeps.posix.path_ownership", + decl_name: "PathOwnershipIntent", + field: WholeDeclaration + } + }, + first_citation: extdeps_external_authority_anchor, + further_citations: [] +} + // OWNERSHIP CONVERGENCE, MODELED AS A DECISION RATHER THAN AS A PROCESS EXIT. // // A successful chown process is not evidence that a path is owned. It is evidence that one diff --git a/dag/extdeps/posix/sh_invocation.dag b/dag/extdeps/posix/sh_invocation.dag index d3f4a0e00ea..88111a64fee 100644 --- a/dag/extdeps/posix/sh_invocation.dag +++ b/dag/extdeps/posix/sh_invocation.dag @@ -1,7 +1,8 @@ module extdeps.posix.sh_invocation import std.types { String, NonEmptyStr } -import extdeps.external_authority { ExternalAuthority } +import extdeps.external_authority { ExternalAuthority, ExternalModelScope, ExternalSubjectRef } +import std.decl_ref { DeclarationRef, WholeDeclaration } import extdeps.uri { Uri, Https } import extdeps.exec.command { ArgvCommand, argv_command } @@ -12,6 +13,18 @@ data extdeps_external_authority_anchor: ExternalAuthority = ExternalAuthority { } } +data extdeps_model_scope: ExternalModelScope = ExternalModelScope { + subject: ExternalSubjectRef { + declaration: DeclarationRef { + module_path: "extdeps.posix.sh_invocation", + decl_name: "posix_sh_program", + field: WholeDeclaration + } + }, + first_citation: extdeps_external_authority_anchor, + further_citations: [] +} + // WHY THIS IS A SEPARATE MODULE FROM extdeps.posix.shell_command_language, AND IT IS A CYCLE, NOT A // PREFERENCE. The invocation builder was authored inside that module and the corpus refused with a // circular dependency: extdeps.exec.command imports it for posix_single_quote, so it cannot import diff --git a/dag/extdeps/posix/signal.dag b/dag/extdeps/posix/signal.dag index 03af0dd4c70..b638c29042f 100644 --- a/dag/extdeps/posix/signal.dag +++ b/dag/extdeps/posix/signal.dag @@ -1,7 +1,8 @@ module extdeps.posix.signal import std.types { NonEmptyStr, String, Bool } -import extdeps.external_authority { ExternalAuthority } +import extdeps.external_authority { ExternalAuthority, ExternalModelScope, ExternalSubjectRef } +import std.decl_ref { DeclarationRef, WholeDeclaration } import extdeps.uri { Uri, Https } data extdeps_external_authority_anchor: ExternalAuthority = ExternalAuthority { @@ -11,6 +12,18 @@ data extdeps_external_authority_anchor: ExternalAuthority = ExternalAuthority { } } +data extdeps_model_scope: ExternalModelScope = ExternalModelScope { + subject: ExternalSubjectRef { + declaration: DeclarationRef { + module_path: "extdeps.posix.signal", + decl_name: "posix.Signal", + field: WholeDeclaration + } + }, + first_citation: extdeps_external_authority_anchor, + further_citations: [] +} + // TerminateProcess sends SIGTERM only. The reaper's bound is at the CALLER (residual // reap only ever names a pid it read out of an inactive unit's own cgroup.procs, per // gunbc.host_hygiene_reaper_remediate) rather than at the signal — this service does not diff --git a/dag/extdeps/posix/test_utility.dag b/dag/extdeps/posix/test_utility.dag index 24b0d411ba9..90f1c8fcce9 100644 --- a/dag/extdeps/posix/test_utility.dag +++ b/dag/extdeps/posix/test_utility.dag @@ -1,7 +1,8 @@ module extdeps.posix.test_utility import std.types { String, NonEmptyStr } -import extdeps.external_authority { ExternalAuthority } +import extdeps.external_authority { ExternalAuthority, ExternalModelScope, ExternalSubjectRef } +import std.decl_ref { DeclarationRef, WholeDeclaration } import extdeps.uri { Uri, Https } import extdeps.exec.command { ArgvCommand, argv_command } @@ -12,6 +13,18 @@ data extdeps_external_authority_anchor: ExternalAuthority = ExternalAuthority { } } +data extdeps_model_scope: ExternalModelScope = ExternalModelScope { + subject: ExternalSubjectRef { + declaration: DeclarationRef { + module_path: "extdeps.posix.test_utility", + decl_name: "test_program", + field: WholeDeclaration + } + }, + first_citation: extdeps_external_authority_anchor, + further_citations: [] +} + // THE STANDALONE UTILITY, NOT THE SHELL BUILTIN, and that is why this module exists at all rather // than the question being answered by a shell fragment. Every shell also implements `test` as a // builtin, so a caller that reaches for a shell to ask it pays for a shell parse and inherits that diff --git a/dag/extdeps/rust/rustc.dag b/dag/extdeps/rust/rustc.dag index 53a96b24d29..cb3e35eb59c 100644 --- a/dag/extdeps/rust/rustc.dag +++ b/dag/extdeps/rust/rustc.dag @@ -1,7 +1,8 @@ module extdeps.rustc import std.types { String, Bool, Int } -import extdeps.external_authority { ExternalAuthority } +import extdeps.external_authority { ExternalAuthority, ExternalModelScope, ExternalSubjectRef } +import std.decl_ref { DeclarationRef, WholeDeclaration } import extdeps.uri { Uri, Https } data extdeps_external_authority_anchor: ExternalAuthority = ExternalAuthority { @@ -11,6 +12,18 @@ data extdeps_external_authority_anchor: ExternalAuthority = ExternalAuthority { } } +data extdeps_model_scope: ExternalModelScope = ExternalModelScope { + subject: ExternalSubjectRef { + declaration: DeclarationRef { + module_path: "extdeps.rustc", + decl_name: "rustc.Check", + field: WholeDeclaration + } + }, + first_citation: extdeps_external_authority_anchor, + further_citations: [] +} + data rustc_stdin_source_note: String = "rustc reads a crate from STANDARD INPUT when the input filename is `-`, which is the cited interface this operation binds. It matters here beyond convenience: the alternative is materializing a candidate's emitted source as a file inside the tree, and the batch executor builds its module index ONCE at startup, so a file appearing mid-run is invisible to that index at best and poisons later entries at worst. Feeding the text through stdin keeps a candidate a value rather than a tree mutation." data rustc_transport_shape_note: String = "THE SCRIPT IS A FIXED LITERAL WITH POSITIONAL PARAMETERS, WHICH IS THE PROPERTY THAT MATTERS, AND THE SIMPLER SPELLINGS WERE TRIED RATHER THAN ASSUMED AWAY (review 54507 flagged the shape). Source and edition arrive as $1 and $2 and are never spliced into the script body, so no candidate can escape a quote — the same discipline extdeps.shell already applies to its own multi-step operations (FilesAndSymlinksWithMode, FilesByNameSorted), which is the precedent this row follows rather than a new liberty.\n\nWHY EACH SHORTER FORM FAILS, MEASURED ON THIS HOST: rustc writes its temporaries BESIDE its output path, so `-o /dev/null` and `--emit=metadata=/dev/null` both fail with `could not create a temp dir` — and worse, they fail by printing an `error:` line, which an observer reading the diagnostic stream would have read as the CANDIDATE being rejected. A fixed output path under /tmp removes the temp dir but races concurrent scoring, which is the one thing a best-of-N harness does constantly. So a per-invocation directory is not decoration; it is what makes the observation attributable to the candidate.\n\nWHAT WOULD DISSOLVE IT: a modeled composition primitive over the shell surface — a pipe and a scoped temporary directory expressible as nodes — at which point this row is those nodes and the literal goes. No such primitive exists today, so this is the honest bottom transport rather than a routed-around one, and it is recorded here as an observation, not as a self-approved deferral." diff --git a/dag/extdeps/ssh/openssh_client_commands.dag b/dag/extdeps/ssh/openssh_client_commands.dag index e2e8c4c3b72..cdf419ef8b5 100644 --- a/dag/extdeps/ssh/openssh_client_commands.dag +++ b/dag/extdeps/ssh/openssh_client_commands.dag @@ -1,7 +1,8 @@ module extdeps.ssh.openssh_client_commands import std.types { String, NonEmptyStr, Int } -import extdeps.external_authority { ExternalAuthority } +import extdeps.external_authority { ExternalAuthority, ExternalModelScope, ExternalSubjectRef } +import std.decl_ref { DeclarationRef, WholeDeclaration } import extdeps.uri { Uri, Https } import extdeps.exec.command { ArgvCommand, argv_command } @@ -12,6 +13,18 @@ data extdeps_external_authority_anchor: ExternalAuthority = ExternalAuthority { } } +data extdeps_model_scope: ExternalModelScope = ExternalModelScope { + subject: ExternalSubjectRef { + declaration: DeclarationRef { + module_path: "extdeps.ssh.openssh_client_commands", + decl_name: "ssh_keygen_program", + field: WholeDeclaration + } + }, + first_citation: extdeps_external_authority_anchor, + further_citations: [ssh_keyscan_external_authority_anchor, ssh_add_external_authority_anchor] +} + data ssh_keyscan_external_authority_anchor: ExternalAuthority = ExternalAuthority { uri: Uri { scheme: Https diff --git a/dag/extdeps/sudo/elevation.dag b/dag/extdeps/sudo/elevation.dag index c00d6b8ec22..119dec45343 100644 --- a/dag/extdeps/sudo/elevation.dag +++ b/dag/extdeps/sudo/elevation.dag @@ -1,7 +1,8 @@ module extdeps.sudo.elevation import std.types { String, NonEmptyStr, List } -import extdeps.external_authority { ExternalAuthority } +import extdeps.external_authority { ExternalAuthority, ExternalModelScope, ExternalSubjectRef } +import std.decl_ref { DeclarationRef, WholeDeclaration } import extdeps.uri { Uri, Https } import v2.std.algebra { list_append } import extdeps.exec.command { ArgvCommand, argv_command } @@ -13,6 +14,18 @@ data extdeps_external_authority_anchor: ExternalAuthority = ExternalAuthority { } } +data extdeps_model_scope: ExternalModelScope = ExternalModelScope { + subject: ExternalSubjectRef { + declaration: DeclarationRef { + module_path: "extdeps.sudo.elevation", + decl_name: "ElevatedInvocation", + field: WholeDeclaration + } + }, + first_citation: extdeps_external_authority_anchor, + further_citations: [] +} + // THE ABSOLUTE PATH IS THE CLAIM THIS ONE BINARY MUST MAKE, and callers that previously spelled a // bare `sudo` now render this row -- a real change in the emitted words, stated here because the // -E row below states its own delta and this one was left implicit until review 55022 asked. diff --git a/dag/extdeps/systemd/journalctl.dag b/dag/extdeps/systemd/journalctl.dag index 8184cf3aa7b..91299da1021 100644 --- a/dag/extdeps/systemd/journalctl.dag +++ b/dag/extdeps/systemd/journalctl.dag @@ -1,7 +1,8 @@ module extdeps.systemd.journalctl import std.types { NonEmptyStr, String, Bool } -import extdeps.external_authority { ExternalAuthority } +import extdeps.external_authority { ExternalAuthority, ExternalModelScope, ExternalSubjectRef } +import std.decl_ref { DeclarationRef, WholeDeclaration } import extdeps.uri { Uri, Https } data extdeps_external_authority_anchor: ExternalAuthority = ExternalAuthority { @@ -11,6 +12,18 @@ data extdeps_external_authority_anchor: ExternalAuthority = ExternalAuthority { } } +data extdeps_model_scope: ExternalModelScope = ExternalModelScope { + subject: ExternalSubjectRef { + declaration: DeclarationRef { + module_path: "extdeps.systemd.journalctl", + decl_name: "systemd.Journalctl", + field: WholeDeclaration + } + }, + first_citation: extdeps_external_authority_anchor, + further_citations: [] +} + // UnitLog reads the raw journal, unfiltered. Filtering for a specific marker line // (gunbc.host_hygiene_liveness_observe's "Listening for Jobs" scan) and computing // freshness are pure .dag folds over stdout, not a second grep/tail spliced into the diff --git a/dag/extdeps/systemd/loginctl.dag b/dag/extdeps/systemd/loginctl.dag index fa9185955d6..9702d95047a 100644 --- a/dag/extdeps/systemd/loginctl.dag +++ b/dag/extdeps/systemd/loginctl.dag @@ -1,7 +1,8 @@ module extdeps.systemd.loginctl import std.types { NonEmptyStr, String, List } -import extdeps.external_authority { ExternalAuthority } +import extdeps.external_authority { ExternalAuthority, ExternalModelScope, ExternalSubjectRef } +import std.decl_ref { DeclarationRef, WholeDeclaration } import extdeps.uri { Uri, Https } import extdeps.systemd { systemd_binary_path } @@ -16,6 +17,18 @@ data extdeps_external_authority_anchor: ExternalAuthority = ExternalAuthority { } } +data extdeps_model_scope: ExternalModelScope = ExternalModelScope { + subject: ExternalSubjectRef { + declaration: DeclarationRef { + module_path: "extdeps.systemd.loginctl", + decl_name: "loginctl_binary_name", + field: WholeDeclaration + } + }, + first_citation: extdeps_external_authority_anchor, + further_citations: [] +} + data loginctl_authority: ExternalAuthority = extdeps_external_authority_anchor data loginctl_binary_name: NonEmptyStr = "loginctl" as NonEmptyStr diff --git a/dag/extdeps/systemd/systemd_run.dag b/dag/extdeps/systemd/systemd_run.dag index 24c23dfd4e1..c072423ddb5 100644 --- a/dag/extdeps/systemd/systemd_run.dag +++ b/dag/extdeps/systemd/systemd_run.dag @@ -2,7 +2,8 @@ module extdeps.systemd.systemd_run import std.types { NonEmptyStr, String, List, Bool } -import extdeps.external_authority { ExternalAuthority } +import extdeps.external_authority { ExternalAuthority, ExternalModelScope, ExternalSubjectRef } +import std.decl_ref { DeclarationRef, WholeDeclaration } import extdeps.uri { Uri, Https } data extdeps_external_authority_anchor: ExternalAuthority = ExternalAuthority { @@ -12,6 +13,18 @@ data extdeps_external_authority_anchor: ExternalAuthority = ExternalAuthority { } } +data extdeps_model_scope: ExternalModelScope = ExternalModelScope { + subject: ExternalSubjectRef { + declaration: DeclarationRef { + module_path: "extdeps.systemd.systemd_run", + decl_name: "systemd_run_transient_unit_argv", + field: WholeDeclaration + } + }, + first_citation: extdeps_external_authority_anchor, + further_citations: [] +} + data systemd_run_authority: ExternalAuthority = extdeps_external_authority_anchor fn systemd_run_transient_unit_argv(unit: NonEmptyStr, command_argv: List) -> List { diff --git a/dag/extdeps/tools/chmod.dag b/dag/extdeps/tools/chmod.dag index d4b4227c7a7..61f6f2e2b39 100644 --- a/dag/extdeps/tools/chmod.dag +++ b/dag/extdeps/tools/chmod.dag @@ -1,7 +1,8 @@ module extdeps.tools.chmod import std.types { String, NonEmptyStr, List } -import extdeps.external_authority { ExternalAuthority } +import extdeps.external_authority { ExternalAuthority, ExternalModelScope, ExternalSubjectRef } +import std.decl_ref { DeclarationRef, WholeDeclaration } import extdeps.uri { Uri, Https } import extdeps.exec.command { ArgvCommand, argv_command } @@ -12,6 +13,18 @@ data extdeps_external_authority_anchor: ExternalAuthority = ExternalAuthority { } } +data extdeps_model_scope: ExternalModelScope = ExternalModelScope { + subject: ExternalSubjectRef { + declaration: DeclarationRef { + module_path: "extdeps.tools.chmod", + decl_name: "chmod_path_resolved_program", + field: WholeDeclaration + } + }, + first_citation: extdeps_external_authority_anchor, + further_citations: [] +} + // The absolute path exists for the same reason it does in extdeps.tools.chown and // extdeps.tools.mkdir: a sudoers NOPASSWD rule names a command by path. chmod sits at /bin rather // than /usr/bin on the hosts this actuator targets, and that is a fact about those hosts recorded diff --git a/dag/extdeps/tools/chown.dag b/dag/extdeps/tools/chown.dag index 1ad85134fa3..ca7dfb11be2 100644 --- a/dag/extdeps/tools/chown.dag +++ b/dag/extdeps/tools/chown.dag @@ -1,7 +1,8 @@ module extdeps.tools.chown import std.types { String, NonEmptyStr, List } -import extdeps.external_authority { ExternalAuthority } +import extdeps.external_authority { ExternalAuthority, ExternalModelScope, ExternalSubjectRef } +import std.decl_ref { DeclarationRef, WholeDeclaration } import extdeps.uri { Uri, Https } import extdeps.posix.identity { PosixOwnerSpec, posix_owner_spec_text } @@ -12,6 +13,18 @@ data extdeps_external_authority_anchor: ExternalAuthority = ExternalAuthority { } } +data extdeps_model_scope: ExternalModelScope = ExternalModelScope { + subject: ExternalSubjectRef { + declaration: DeclarationRef { + module_path: "extdeps.tools.chown", + decl_name: "chown_binary_path", + field: WholeDeclaration + } + }, + first_citation: extdeps_external_authority_anchor, + further_citations: [] +} + data chown_binary_path: NonEmptyStr = "/usr/bin/chown" // THE OWNER ARGUMENT IS A TYPED PAIR, NOT A STRING THE CALLER ASSEMBLED. Callers used to pass an diff --git a/dag/extdeps/tools/env.dag b/dag/extdeps/tools/env.dag index 99b598202e5..14cb404d935 100644 --- a/dag/extdeps/tools/env.dag +++ b/dag/extdeps/tools/env.dag @@ -1,7 +1,8 @@ module extdeps.tools.env import std.types { String, NonEmptyStr, List } -import extdeps.external_authority { ExternalAuthority } +import extdeps.external_authority { ExternalAuthority, ExternalModelScope, ExternalSubjectRef } +import std.decl_ref { DeclarationRef, WholeDeclaration } import extdeps.uri { Uri, Https } import v2.std.orchestration { EnvBinding, EnvSet, EnvUnset } @@ -12,6 +13,18 @@ data extdeps_external_authority_anchor: ExternalAuthority = ExternalAuthority { } } +data extdeps_model_scope: ExternalModelScope = ExternalModelScope { + subject: ExternalSubjectRef { + declaration: DeclarationRef { + module_path: "extdeps.tools.env", + decl_name: "env_path_resolved_program", + field: WholeDeclaration + } + }, + first_citation: extdeps_external_authority_anchor, + further_citations: [env_unset_external_authority_anchor] +} + // THE UNSET FLAG IS NOT POSIX. `env -u NAME` is a GNU coreutils extension; POSIX env offers only // `-i` (empty the whole environment) and NAME=value assignments. The two anchors are separate // because the guarantee is: an EnvSet argv runs anywhere env does, an EnvUnset argv requires the diff --git a/dag/extdeps/tools/findutils.dag b/dag/extdeps/tools/findutils.dag index dd78402d89b..9c8d66e8ea2 100644 --- a/dag/extdeps/tools/findutils.dag +++ b/dag/extdeps/tools/findutils.dag @@ -1,7 +1,8 @@ module extdeps.tools.findutils import std.types { String, NonEmptyStr, Int } -import extdeps.external_authority { ExternalAuthority } +import extdeps.external_authority { ExternalAuthority, ExternalModelScope, ExternalSubjectRef } +import std.decl_ref { DeclarationRef, WholeDeclaration } import extdeps.uri { Uri, Https } import extdeps.exec.command { ArgvCommand, argv_command } @@ -12,6 +13,18 @@ data extdeps_external_authority_anchor: ExternalAuthority = ExternalAuthority { } } +data extdeps_model_scope: ExternalModelScope = ExternalModelScope { + subject: ExternalSubjectRef { + declaration: DeclarationRef { + module_path: "extdeps.tools.findutils", + decl_name: "find_program", + field: WholeDeclaration + } + }, + first_citation: extdeps_external_authority_anchor, + further_citations: [] +} + // PATH-resolved program name, deliberately: this repository has made no filesystem observation of // the host this command runs on, and an absolute path is a claim about one. The full reasoning, the // criterion for climbing to an absolute row, and the counter-example that makes the distinction diff --git a/dag/extdeps/tools/make.dag b/dag/extdeps/tools/make.dag index a8708a11285..345b59b0016 100644 --- a/dag/extdeps/tools/make.dag +++ b/dag/extdeps/tools/make.dag @@ -1,7 +1,8 @@ module extdeps.tools.make import std.types { String, NonEmptyStr, List } -import extdeps.external_authority { ExternalAuthority } +import extdeps.external_authority { ExternalAuthority, ExternalModelScope, ExternalSubjectRef } +import std.decl_ref { DeclarationRef, WholeDeclaration } import extdeps.uri { Uri, Https } import extdeps.exec.command { ArgvCommand, argv_command } @@ -12,6 +13,18 @@ data extdeps_external_authority_anchor: ExternalAuthority = ExternalAuthority { } } +data extdeps_model_scope: ExternalModelScope = ExternalModelScope { + subject: ExternalSubjectRef { + declaration: DeclarationRef { + module_path: "extdeps.tools.make", + decl_name: "make_program", + field: WholeDeclaration + } + }, + first_citation: extdeps_external_authority_anchor, + further_citations: [] +} + // PATH-resolved program name, deliberately: this repository has made no filesystem observation of // the host this command runs on, and an absolute path is a claim about one. The full reasoning, the // criterion for climbing to an absolute row, and the counter-example that makes the distinction diff --git a/dag/extdeps/tools/mkdir.dag b/dag/extdeps/tools/mkdir.dag index 3410f67bfd4..ac4b46933f4 100644 --- a/dag/extdeps/tools/mkdir.dag +++ b/dag/extdeps/tools/mkdir.dag @@ -1,7 +1,8 @@ module extdeps.tools.mkdir import std.types { String, NonEmptyStr, List } -import extdeps.external_authority { ExternalAuthority } +import extdeps.external_authority { ExternalAuthority, ExternalModelScope, ExternalSubjectRef } +import std.decl_ref { DeclarationRef, WholeDeclaration } import extdeps.uri { Uri, Https } import extdeps.exec.command { ArgvCommand, argv_command } @@ -12,6 +13,18 @@ data extdeps_external_authority_anchor: ExternalAuthority = ExternalAuthority { } } +data extdeps_model_scope: ExternalModelScope = ExternalModelScope { + subject: ExternalSubjectRef { + declaration: DeclarationRef { + module_path: "extdeps.tools.mkdir", + decl_name: "mkdir_path_resolved_program", + field: WholeDeclaration + } + }, + first_citation: extdeps_external_authority_anchor, + further_citations: [] +} + // The absolute path exists for the same reason it does in extdeps.tools.id: a sudoers NOPASSWD // rule names a command by path, so a privileged mkdir and an unprivileged one are not // interchangeable spellings. diff --git a/dag/extdeps/tools/stat.dag b/dag/extdeps/tools/stat.dag index 2ec131a5a66..405700687a8 100644 --- a/dag/extdeps/tools/stat.dag +++ b/dag/extdeps/tools/stat.dag @@ -1,7 +1,8 @@ module extdeps.tools.stat import std.types { String, NonEmptyStr, List } -import extdeps.external_authority { ExternalAuthority } +import extdeps.external_authority { ExternalAuthority, ExternalModelScope, ExternalSubjectRef } +import std.decl_ref { DeclarationRef, WholeDeclaration } import extdeps.uri { Uri, Https } import extdeps.exec.command { ArgvCommand, argv_command } @@ -12,6 +13,18 @@ data extdeps_external_authority_anchor: ExternalAuthority = ExternalAuthority { } } +data extdeps_model_scope: ExternalModelScope = ExternalModelScope { + subject: ExternalSubjectRef { + declaration: DeclarationRef { + module_path: "extdeps.tools.stat", + decl_name: "stat_binary_path", + field: WholeDeclaration + } + }, + first_citation: extdeps_external_authority_anchor, + further_citations: [] +} + // THE AUTHORITY IS GNU COREUTILS, NOT POSIX, and that is a real constraint rather than a citation // detail: -c/--format is a GNU extension. POSIX does not specify stat(1) at all, and the BSD // utility spells the same request -f with different conversion characters. This module therefore diff --git a/dag/extdeps/tools/tar.dag b/dag/extdeps/tools/tar.dag index a09ff1b556f..5ef1dfecbe9 100644 --- a/dag/extdeps/tools/tar.dag +++ b/dag/extdeps/tools/tar.dag @@ -1,7 +1,8 @@ module extdeps.tools.tar import std.types { String, NonEmptyStr, Int } -import extdeps.external_authority { ExternalAuthority } +import extdeps.external_authority { ExternalAuthority, ExternalModelScope, ExternalSubjectRef } +import std.decl_ref { DeclarationRef, WholeDeclaration } import extdeps.uri { Uri, Https } import extdeps.exec.command { ArgvCommand, argv_command } @@ -12,6 +13,18 @@ data extdeps_external_authority_anchor: ExternalAuthority = ExternalAuthority { } } +data extdeps_model_scope: ExternalModelScope = ExternalModelScope { + subject: ExternalSubjectRef { + declaration: DeclarationRef { + module_path: "extdeps.tools.tar", + decl_name: "tar_program", + field: WholeDeclaration + } + }, + first_citation: extdeps_external_authority_anchor, + further_citations: [] +} + // GNU TAR, NOT POSIX pax-format tar, and the distinction decides whether this module is correct on a // given host: --strip-components is a GNU extension that the POSIX utility does not specify. A host // shipping bsdtar answers the same request with different spellings, and that would be its own diff --git a/dag/gunbc/extdeps_scope_frontier.dag b/dag/gunbc/extdeps_scope_frontier.dag index fdca655a6c3..016424bf64d 100644 --- a/dag/gunbc/extdeps_scope_frontier.dag +++ b/dag/gunbc/extdeps_scope_frontier.dag @@ -308,7 +308,68 @@ data scope_carrier_paths: List = [ "dag/extdeps/llm/cursor_sdk_facts.dag", "dag/extdeps/llm/cursor_stream.dag", "dag/extdeps/probes/provider_interface_acquisition.dag", - "dag/extdeps/memory/samsung.dag" + "dag/extdeps/memory/samsung.dag", + "dag/extdeps/accounting/encumbrance.dag", + "dag/extdeps/ampere/mt_collins_product_brief/platform.dag", + "dag/extdeps/boards/supermicro.dag", + "dag/extdeps/ci_runner/blacksmith.dag", + "dag/extdeps/ci_runner/circleci.dag", + "dag/extdeps/ci_runner/depot.dag", + "dag/extdeps/ci_runner/github_actions.dag", + "dag/extdeps/ci_runner/types.dag", + "dag/extdeps/ci_runner/warpbuild.dag", + "dag/extdeps/cloud/gcp/adc_document.dag", + "dag/extdeps/colo/centersquare.dag", + "dag/extdeps/colo/colocation_america.dag", + "dag/extdeps/colo/coresite.dag", + "dag/extdeps/colo/dataverge.dag", + "dag/extdeps/colo/digital_realty.dag", + "dag/extdeps/colo/equinix.dag", + "dag/extdeps/colo/evocative.dag", + "dag/extdeps/colo/h5.dag", + "dag/extdeps/colo/halsey_165.dag", + "dag/extdeps/colo/hivelocity.dag", + "dag/extdeps/colo/interserver.dag", + "dag/extdeps/colo/iron_mountain.dag", + "dag/extdeps/colo/natcoweb.dag", + "dag/extdeps/colo/netrality.dag", + "dag/extdeps/colo/qts.dag", + "dag/extdeps/colo/summit.dag", + "dag/extdeps/colo/three_sixty_five.dag", + "dag/extdeps/colo/tierpoint.dag", + "dag/extdeps/colo/types.dag", + "dag/extdeps/cpu_attachment/lotes_azifa072.dag", + "dag/extdeps/energy/nj_electricity.dag", + "dag/extdeps/github/commits.dag", + "dag/extdeps/git/plumbing.dag", + "dag/extdeps/languages/bash/invocation.dag", + "dag/extdeps/languages/rust/capabilities.dag", + "dag/extdeps/memory/cisco_ucs.dag", + "dag/extdeps/ollama/model_store.dag", + "dag/extdeps/posix/identity.dag", + "dag/extdeps/posix/path_ownership.dag", + "dag/extdeps/posix/sh_invocation.dag", + "dag/extdeps/posix/signal.dag", + "dag/extdeps/posix/test_utility.dag", + "dag/extdeps/realestate/nj_industrial.dag", + "dag/extdeps/rust/cargo_diagnostic.dag", + "dag/extdeps/rust/rustc.dag", + "dag/extdeps/ssh/openssh_client_commands.dag", + "dag/extdeps/sudo/elevation.dag", + "dag/extdeps/systemd/journalctl.dag", + "dag/extdeps/systemd/loginctl.dag", + "dag/extdeps/systemd/systemd_run.dag", + "dag/extdeps/tools/chmod.dag", + "dag/extdeps/tools/chown.dag", + "dag/extdeps/tools/env.dag", + "dag/extdeps/tools/findutils.dag", + "dag/extdeps/tools/make.dag", + "dag/extdeps/tools/mkdir.dag", + "dag/extdeps/tools/stat.dag", + "dag/extdeps/tools/tar.dag", + "dag/extdeps/vendor/cisco.dag", + "dag/extdeps/linux/cgroup_v2.dag", + "dag/extdeps/linux/cgroup_v2_memory.dag" ] data scope_machinery_exempt_paths: List = [ diff --git a/src/v1/stage0/src/extdeps_languages_rust_capabilities.rs b/src/v1/stage0/src/extdeps_languages_rust_capabilities.rs index aaee448ecf0..c51f342a6b2 100644 --- a/src/v1/stage0/src/extdeps_languages_rust_capabilities.rs +++ b/src/v1/stage0/src/extdeps_languages_rust_capabilities.rs @@ -2,7 +2,14 @@ // Source module: extdeps.languages.rust.capabilities use self::RustCapability::*; +pub use crate::extdeps_external_authority::{ + ExternalAuthority, ExternalModelScope, ExternalSubjectRef, +}; +use crate::extdeps_uri::UriScheme::Https; +pub use crate::extdeps_uri::{Uri, UriScheme}; pub use crate::std_algebra::FreeMonoid; +use crate::std_decl_ref::DeclField::WholeDeclaration; +pub use crate::std_decl_ref::{DeclField, DeclarationRef}; use crate::std_trait_derive_shape::ReprGroundingDeriveElemShape::{ ReprDeriveElemKernelBool, ReprDeriveElemKernelInt, ReprDeriveElemKernelString, ReprDeriveElemKernelUnit, ReprDeriveElemNullaryEnumCopy, ReprDeriveElemPayloadCoproduct, @@ -18,6 +25,39 @@ use crate::NonEmptyVec; use im::{vector as vec, HashMap, OrdSet as BTreeSet, Vector as Vec}; use std::rc::Rc; +pub fn extdeps_external_authority_anchor() -> Rc { + thread_local! { + static CACHED: Rc = { + Rc::new(ExternalAuthority { + uri: Rc::new(Uri { + scheme: UriScheme::Https, + locator: "doc.rust-lang.org/reference/attributes/derive.html".to_string(), + }), + }) + }; + } + CACHED.with(|c: &Rc| c.clone()) +} + +pub fn extdeps_model_scope() -> Rc { + thread_local! { + static CACHED: Rc = { + Rc::new(ExternalModelScope { + subject: Rc::new(ExternalSubjectRef { + declaration: Rc::new(DeclarationRef { + module_path: "extdeps.languages.rust.capabilities".to_string(), + decl_name: "RustCapability".to_string(), + field: Rc::new(DeclField::WholeDeclaration), + }), + }), + first_citation: extdeps_external_authority_anchor(), + further_citations: Rc::new(vec![]), + }) + }; + } + CACHED.with(|c: &Rc| c.clone()) +} + pub fn rust_capabilities_note() -> String { thread_local! { static CACHED: String = {