Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions .gitattributes
Original file line number Diff line number Diff line change
Expand Up @@ -93,6 +93,7 @@ src/v1/stage0/src/cssl_seed_linked_closure_assembly.rs !merge
src/v1/stage0/src/data_initializer_identity.rs !merge
src/v1/stage0/src/declaration_index.rs !merge
src/v1/stage0/src/derived_realization_schedule.rs !merge
src/v1/stage0/src/emitted_closure_compile_host.rs !merge
src/v1/stage0/src/main.rs !merge
src/v1/stage0/src/memory_governor.rs !merge
src/v1/stage0/src/namespace_wave_admission.rs !merge
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/witnesses.yml
Original file line number Diff line number Diff line change
Expand Up @@ -66,7 +66,7 @@ jobs:
rustup toolchain list || echo "rustup toolchain list: no answer"
rustup default || echo "rustup default: no answer"
if: "!cancelled()"
- name: "Required CI: build lane (regen, v2 emission)"
- name: "Required CI: build lane (phases named by the run, not by this label)"
run: |
ROOT=$(git rev-parse --show-toplevel 2>/dev/null || pwd)
cd "$ROOT"
Expand Down
6 changes: 3 additions & 3 deletions DESIGN.md

Large diffs are not rendered by default.

96 changes: 96 additions & 0 deletions dag/gunbc/ci_layer_roots.dag
Original file line number Diff line number Diff line change
Expand Up @@ -123,6 +123,102 @@ data required_v2_emission_entries: List<String> = ["src/v2/compiler/00_compile.d
// self-host probe, product receipt and cargo census become four answers to one question.
data required_v2_emission_dissolution: DissolutionCondition = unbound_dissolution(description: "the authentic self-host product receipt is required on every admitted candidate and carries this emission boundary (same producer, stopping before cargo); then the standalone --required-v2-emission phase, required_v2_emission_entries and their host reader delete together")

// THE ENTRIES WHOSE EMITTED CLOSURE A REQUIRED PHASE COMPILES.
//
// WHY THIS ROW IS SEPARATE FROM required_v2_emission_entries ABOVE, rather than the same list
// read twice: the two phases answer different questions and have different cost shapes. The
// emission phase asks whether the emitter produced a tree at all, and its subject is the widest
// closure one entry names because emission is cheap. This phase asks whether the tree rustc
// accepts it, and cargo over a closure is not cheap, so its subject is chosen for what it
// compiles rather than for how wide it is. Sharing one row would have forced one answer to both
// questions and, in practice, would have pinned the emission phase's subject to whatever the
// compile phase could afford.
//
// THE SAME NARROW ARRIVES THROUGH THE BUDGET, AND IT IS THE ONE MORE LIKELY TO BE WRITTEN.
// A cover computed as "the N entries that fit the window" looks like a cost decision rather
// than an observation, so it does not read as a derived cover at all -- but it drops a member
// exactly when that member becomes slow, and an entry becomes slow when it breaks. The verdict
// is then a function of the budget rather than of the emitted bytes, which is the same
// empty-observation narrow one level out. Membership is a row; cost decides whether a row is
// ADDED, and never whether a declared row is MEASURED.
//
// MEMBERSHIP IS DECLARED HERE; IT IS NEVER DERIVED AT RUN TIME. A cover computed each run as
// "whatever currently compiles" is SELF-DISARMING: it drops a member at precisely the moment
// that member becomes the defect this phase exists to catch, and reports green over a quietly
// smaller subject. That is DESIGN's empty-observation narrow -- an observation that could not
// express what changed rendered as the verdict nothing is affected -- and it is strictly worse
// than the absorbing fallback, because a widen is merely expensive and a narrow is silently
// uncovered. Measured against today's corpus rather than argued: dag/std/interval.dag does not
// compile right now, so a derived cover would exclude it and be green, while a declared cover
// containing it is RED, which is the correct answer.
//
// SO THE MEASUREMENT SITS AT THE DECISION, NOT AT THE VERDICT, and the two must not be fused:
// MEMBERSHIP is DECLARED -- this row. Adding or removing an entry is a decision a reviewer sees.
// ADMISSION is MEASURED -- an entry may not be ADDED until its emitted closure has been
// measured clean, because a member that is red on main makes the phase permanently red
// rather than discriminating.
// DEGRADATION is RED -- once declared, a member that stops compiling FAILS THE PHASE. It is
// never dropped, never skipped, never reported as not-applicable.
// THE COUNT is REPORTED EVERY RUN -- declared members with their per-entry verdicts, never a
// count of survivors.
//
// DELETING A ROW TO GET GREEN IS NOT THE REMEDY, and this sentence is here because the first
// person to hit a red member will be able to argue that it looks like maintenance. It is not:
// the red IS the finding, and removing the member deletes the finding rather than resolving it.
// The remedy is to repair the emission, or -- if the entry is genuinely no longer worth
// covering -- to remove it as a declared COVERAGE decision argued on its own terms, never as a
// way to turn a failing run green.
//
// THE ROSTER IS BOUNDED AND MUST STAY BOUNDED. gunbc.whole_corpus_compile_admission refuses a
// whole-bundle compile on the default runner and records two EXIT=137 kills behind that
// refusal, and the required path is already the fleet's dominant serialized cost. So widening
// this list is a COST DECISION taken deliberately, exactly as the row above is, and never a
// reflex -- but it is still a row, not a Rust edit.
//
// WHAT A READER MUST NOT CONCLUDE FROM IT. This is not corpus compile coverage and does not
// claim to be. A blocking emit-stage diagnostic in a closure no entry here reaches still
// escapes every required phase, which is the narrowed remainder DESIGN's emit-stage row carries.
//
// WHY THESE ENTRIES. Every one was MEASURED CLEAN before being written here -- emitted, and its
// emitted closure compiled -- which is the admission rule this row states below. They are not a
// cover in any principled sense: they are the entries whose closures were measured and found
// admissible, ordered widest first, and the list exists to be grown.
//
// WHAT BOUNDS IT IS ADMISSIBILITY, NOT COST, and that is the opposite of what the cost figures
// suggest. A warm entry costs seconds, so budget would permit hundreds. What it may not permit
// is MEMBERSHIP: entries exist today whose emitted closure does not compile -- the v2 compiler
// root, the emission phase's own subject one row up, is one of them -- and admissibility does
// NOT fail entry by entry, because closures SHARE defects. One uncompilable site in a
// widely-imported module disqualifies every entry whose closure reaches it, so the admissible
// set is a property of where broken sites sit in the import graph rather than of how many
// entries anyone can afford. This roster is therefore a BEACHHEAD on a live frontier, and it is
// sized against a TEMPORARY CONDITION: emitter repairs that clear a widely-reached site return
// many entries to admissibility at once.
//
// A FAILED RESTORE IS TERMINAL FOR THE RUN. If the mutation arm's byte-exact restore does not
// hold, the phase stops at that entry and reports every later one as NotExecuted; it is not a
// per-entry finding the siblings continue past, and it is not recoverable by re-running the
// phase. The reason is mechanical rather than procedural -- the arms share one cargo target
// directory, so after a failed restore no later baseline taken through it is attributable --
// and the effect is that a head whose restore arm did not hold has no green from this phase at
// all, rather than a green whose restore was never established (operator ruling relayed
// 2026-08-26).
//
// THE INSTRUMENT, not its output (DESIGN, the 2026-08-24 measurement ruling): the phase prints
// one `required-ci: emit-compile` line per entry carrying its own file count, baseline verdict
// and mutation verdict, and `claim_executor --required-ci --required-lane build` re-derives
// them. No figure from a run is transcribed here.
data required_emit_compile_entries: List<String> = [
"dag/gunbc/ci_layer_roots.dag",
"dag/gunbc/scm/load_standing.dag",
"dag/extdeps/uri.dag",
"dag/std/measure.dag",
"dag/std/node.dag",
"dag/std/content_hash.dag",
"dag/std/abi.dag",
"dag/std/logic.dag"
]

data frontier_probe_witness_measure_receipt_note: String = "Measured durations cited on commit_gate SpanEnrolled cost_basis rows are WallClock: claim_batch performance receipts use wall_nanos (performance_receipt_from_witness), not the thread-CPU nanos that budget_completion_outcome gates on (operator msg_e24f4cab). Do not compare these figures to the per-witness eval CPU budget without stating the clock. The arm is named in std.measure ClockBasis, which is the single clock-basis authority; this sentence said WitnessCostWallEval until 2026-08-05, naming a second carrier that std.realization_schedule declared for one day and that witness_cost_clock_note records the dissolution of. The advice the sentence gives is exactly what the surviving carrier now enforces rather than advises: witness_row_cost_verdict answers BasisClockMismatch instead of comparing across clocks."

data frontier_probe_witness_measure_receipt_read_failure: String = "target/frontier-probe-survey/matrix_readthrough_claim_batch_receipt.log"
Expand Down
4 changes: 2 additions & 2 deletions dag/gunbc/design_document.dag

Large diffs are not rendered by default.

Loading
Loading