Skip to content
Merged
17 changes: 17 additions & 0 deletions dag/gunbc/ci_layer_roots.dag
Original file line number Diff line number Diff line change
Expand Up @@ -195,6 +195,23 @@ data required_v2_emission_dissolution: DissolutionCondition = unbound_dissolutio
// sized against a TEMPORARY CONDITION: emitter repairs that clear a widely-reached site return
// many entries to admissibility at once.
//
// THE FAULT GOES INTO THE ENTRY'S OWN EMITTED MODULE, AND THAT IS A LOAD-BEARING CHOICE RATHER
// THAN AN IMPLEMENTATION DETAIL. The selector first shipped preferring any declared member OTHER
// than the entry, on the reasoning that a dependency is the stronger subject because it proves
// the verdict reaches past the entry's own bytes. Measured over this whole roster, that rule
// mutated a SHARED-CORE module for every single entry -- the emitted runtime in one case, which
// is in every closure there is. Each verdict was honestly discriminating and each one established
// `cargo refused when the shared core was broken`, never `THIS entry's closure is what was
// compiled`: total at the level examined, blind one level down.
//
// The entry's own module is the one member NOTHING ELSE REFERENCES -- the others are its
// dependencies, and a dependency does not import the root -- so it is exactly the file a faulty
// emission can DROP while the crate still compiles. A drop that breaks a reference is already
// caught by the baseline; the uncaught case is a REFERENCE-CLOSED drop, and the entry's own leaf
// is the canonical one. Its ABSENCE is therefore a typed refusal naming the entry, never a
// fallback to some other member: falling back would hand the phase a discriminating verdict
// computed over precisely the tree that is broken.
//
// A FAILED RESTORE IS TERMINAL FOR THE RUN. If the mutation arm's byte-exact restore does not
// hold, the phase stops at that entry and reports every later one as NotExecuted; it is not a
// per-entry finding the siblings continue past, and it is not recoverable by re-running the
Expand Down
14 changes: 11 additions & 3 deletions dag/gunbc/emitted_closure_compile_seed_growth.dag
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,7 @@ import gunbc.seed_growth { SeedGrowthJustification }
// the obligation it declares, rather than inside gunbc.seed_growth_admission, which owns the
// ROSTER and the join and would otherwise accumulate every lane's rows in the module that
// adjudicates them.
data emitted_closure_compile_seed_growth_note: String = "Seed-growth obligation for the host behind the required emit-compile phase.\n\nWHAT THE CHANGE IS. The v2-emission phase emits one entry's closure and stops at the emitter. Its own header in cli_run.rs enumerates what it therefore cannot see, and the first item is 'a rustc error in the emitted tree (nothing here compiles the emission)'. DESIGN's Building-&-checks section carries a declared rung drop headed 'A BLOCKING EMIT-STAGE DIAGNOSTIC CAN SIT ON MAIN INDEFINITELY WITH NO REQUIRED PHASE THAT FAILS', whose restoration trigger reads: this row retires when a required phase EMITS over a closure that reaches call sites -- the compile re-add on the queue the floor cut created. This host is that phase: same producer (compile_entry_emission), the emitted files written as a crate, cargo run over it.\n\nWHY IT IS NOT A SECOND EMITTER. The phase calls the SAME transaction the emission phase calls and adds one stage after it. A green there and a green here cannot be two facts about two emissions, which is exactly the property a separately-authored probe would have given up.\n\nWHY THE MANIFEST IS DERIVED AND NOT AUTHORED. The corpus already carries a hand-concatenated probe manifest (tools.self_host_curated_seed_linked_harness cssl_v1_compiled_probe_lib_cargo_toml), marked scaffold debt in its own module for being concat-authored TOML. Consuming it from a merge-blocking gate would have pinned that debt open on the required path, and authoring a second one would have been new scaffolding the operator declined on 2026-08-25. The manifest here is rendered from the modeled cargo authorities instead -- extdeps.rust.version render_cargo_package_header_prefix for the package header, v1.compiler.stage0_crates stage0_foundation_runtime_dependencies for the seed's own runtime dependency set, and render_stage0_crate_dep per row -- so no new markup is authored at all.\n\nNO IMPL BLOCK, AND THAT IS DELIBERATE. Every item in the file is a free function or a type, because an impl method has no DeclarationRef spelling -- std.decl_ref offers WholeDeclaration or NamedField and neither names a method on an impl block -- so methods would have grown the class gunbc.seed_growth_admission reports as seed_growth_uncitable_item_keys. v1_compiler.declaration_index took the same route for the same reason. Uncitable items added by this change: ZERO.\n\nHAND-ITEM DELTA: enumerated below rather than counted. src/v1/stage0/src/cli_run.rs adds no declaration -- one #[path] mod line and one re-export list -- and src/v1/stage0/src/bin/claim_executor.rs adds one variant to an existing exhaustive enum and one phase body inside an existing function; both dispositions are ExistingSeedItemModified, and listing them would net a modification into an addition census.\n\nWHY THIS ROSTER DRIFTED ONCE, RECORDED SO IT IS NOT REPEATED. Review 56685 found it citing PROBE_PACKAGE_NAME, which resolves to nothing: an earlier revision carried a package-name CONSTANT, the cargo-fingerprint-aliasing repair replaced it with the per-entry function probe_package_name, and the receipt was not updated with the code. An audit of the whole roster then found 1 stale name and 16 unaccounted declarations -- every one of the 16 added by a LATER repair in this same PR (probe_root, the selection digests, retention, the probe-line attribution fix, two tests), each of which grew the file without growing its receipt. That is the exact failure the carrier exists to catch, committed inside the carrier. The roster is now exact against the file: 47 rows, 47 declarations, zero stale, zero unaccounted. THE STANDING HAZARD IS THAT IT IS A HAND ROSTER BESIDE ITS SUBJECT, so it can only be re-verified, never trusted: it drifts silently on the next declaration added, and nothing in the required run compares the two. Its dissolution is the same v1-hand-queue-drain lane this obligation already names.\n\nWHAT THE EXECUTED EVIDENCE IS, because the seed's own unit tests are not it. The Rust suite was removed from CI on 2026-07-11, so nothing under #[cfg(test)] executes on the merge path and none of it may be cited as coverage. The executed evidence is the phase itself: establish_discriminating_red injects one type error into one emitted file on EVERY required run, requires it to fail alone, restores the bytes and requires the green back -- and a mutation that fails to go red is a PHASE FAILURE, not a note. That is DESIGN 4b's authorable-RED question answered by execution rather than by inspection, and it is why a green from this phase carries information that a bare cargo-exit-status phase would not."
data emitted_closure_compile_seed_growth_note: String = "Seed-growth obligation for the host behind the required emit-compile phase.\n\nWHAT THE CHANGE IS. The v2-emission phase emits one entry's closure and stops at the emitter. Its own header in cli_run.rs enumerates what it therefore cannot see, and the first item is 'a rustc error in the emitted tree (nothing here compiles the emission)'. DESIGN's Building-&-checks section carries a declared rung drop headed 'A BLOCKING EMIT-STAGE DIAGNOSTIC CAN SIT ON MAIN INDEFINITELY WITH NO REQUIRED PHASE THAT FAILS', whose restoration trigger reads: this row retires when a required phase EMITS over a closure that reaches call sites -- the compile re-add on the queue the floor cut created. This host is that phase: same producer (compile_entry_emission), the emitted files written as a crate, cargo run over it.\n\nWHY IT IS NOT A SECOND EMITTER. The phase calls the SAME transaction the emission phase calls and adds one stage after it. A green there and a green here cannot be two facts about two emissions, which is exactly the property a separately-authored probe would have given up.\n\nWHY THE MANIFEST IS DERIVED AND NOT AUTHORED. The corpus already carries a hand-concatenated probe manifest (tools.self_host_curated_seed_linked_harness cssl_v1_compiled_probe_lib_cargo_toml), marked scaffold debt in its own module for being concat-authored TOML. Consuming it from a merge-blocking gate would have pinned that debt open on the required path, and authoring a second one would have been new scaffolding the operator declined on 2026-08-25. The manifest here is rendered from the modeled cargo authorities instead -- extdeps.rust.version render_cargo_package_header_prefix for the package header, v1.compiler.stage0_crates stage0_foundation_runtime_dependencies for the seed's own runtime dependency set, and render_stage0_crate_dep per row -- so no new markup is authored at all.\n\nNO IMPL BLOCK, AND THAT IS DELIBERATE. Every item in the file is a free function, a type, or the one private MODULE that carries the mutation subject's privacy boundary, because an impl method has no DeclarationRef spelling -- std.decl_ref offers WholeDeclaration or NamedField and neither names a method on an impl block -- so methods would have grown the class gunbc.seed_growth_admission reports as seed_growth_uncitable_item_keys. v1_compiler.declaration_index took the same route for the same reason. Uncitable items added by this change: ZERO.\n\nTHE ONE `mod` ITEM, DISPOSITIONED RATHER THAN GLOSSED. `entry_own_subject` is a private module and is the only item in this file that is neither a free function nor a type. It exists because Rust privacy is MODULE-scoped: a private field on a struct declared beside its constructor is a wall against other modules and mere convention within the declaring one, so the carrier and its single constructor sit inside a submodule and everything else in the file is outside that boundary. Without it, `MutationSubject { rust_module: ... }` compiles anywhere in the file and the shared-core substitution this phase exists to prevent is unwritable only by agreement. IT IS CITABLE and it is enumerated: a module is a whole declaration, so `WholeDeclaration` names it and the uncitable-item count stays ZERO. Its members are enumerated beside it -- the type, the constructor, and the accessor -- which is why the accessor is a free function inside the boundary rather than an impl method.\n\nHAND-ITEM DELTA: enumerated below rather than counted. src/v1/stage0/src/cli_run.rs adds no declaration -- one #[path] mod line and one re-export list -- and src/v1/stage0/src/bin/claim_executor.rs adds one variant to an existing exhaustive enum and one phase body inside an existing function; both dispositions are ExistingSeedItemModified, and listing them would net a modification into an addition census.\n\nWHY THIS ROSTER DRIFTED ONCE, RECORDED SO IT IS NOT REPEATED. Review 56685 found it citing PROBE_PACKAGE_NAME, which resolves to nothing: an earlier revision carried a package-name CONSTANT, the cargo-fingerprint-aliasing repair replaced it with the per-entry function probe_package_name, and the receipt was not updated with the code. An audit of the whole roster then found 1 stale name and 16 unaccounted declarations -- every one of the 16 added by a LATER repair in this same PR (probe_root, the selection digests, retention, the probe-line attribution fix, two tests), each of which grew the file without growing its receipt. That is the exact failure the carrier exists to catch, committed inside the carrier. The roster is now exact against the file: 55 rows, 55 declarations, zero stale, zero unaccounted. THE CENSUS COUNTS EVERY ITEM KIND AT EVERY INDENT -- const, static, fn, struct, enum, type and mod -- with exactly one stated exclusion, the `#[cfg(test)] mod tests` harness itself, whose member tests ARE enumerated individually. The exclusion is written down because an unstated narrowing is how the two preceding defects survived: a scan of only column-0 and 4-space indents could not see an impl method, and a scan omitting `mod` could not see the privacy boundary. THE STANDING HAZARD IS THAT IT IS A HAND ROSTER BESIDE ITS SUBJECT, so it can only be re-verified, never trusted: it drifts silently on the next declaration added, and nothing in the required run compares the two. Its dissolution is the same v1-hand-queue-drain lane this obligation already names.\n\nWHAT THE EXECUTED EVIDENCE IS, because the seed's own unit tests are not it. The Rust suite was removed from CI on 2026-07-11, so nothing under #[cfg(test)] executes on the merge path and none of it may be cited as coverage. The executed evidence is the phase itself: establish_discriminating_red injects one type error into one emitted file on EVERY required run, requires it to fail alone, restores the bytes and requires the green back -- and a mutation that fails to go red is a PHASE FAILURE, not a note. That is DESIGN 4b's authorable-RED question answered by execution rather than by inspection, and it is why a green from this phase carries information that a bare cargo-exit-status phase would not."

data emitted_closure_compile_seed_growth_justification: SeedGrowthJustification = SeedGrowthJustification {
hand_authored_declarations: [
Expand All @@ -23,9 +23,13 @@ data emitted_closure_compile_seed_growth_justification: SeedGrowthJustification
DeclarationRef { module_path: "v1_compiler.emitted_closure_compile_host", decl_name: "cargo_verdict_summary", field: WholeDeclaration },
DeclarationRef { module_path: "v1_compiler.emitted_closure_compile_host", decl_name: "cargo_verdict_probe_line", field: WholeDeclaration },
DeclarationRef { module_path: "v1_compiler.emitted_closure_compile_host", decl_name: "cargo_verdict_stderr_tail", field: WholeDeclaration },
DeclarationRef { module_path: "v1_compiler.emitted_closure_compile_host", decl_name: "entry_own_subject", field: WholeDeclaration },
DeclarationRef { module_path: "v1_compiler.emitted_closure_compile_host", decl_name: "MutationSubject", field: WholeDeclaration },
DeclarationRef { module_path: "v1_compiler.emitted_closure_compile_host", decl_name: "MutationSubjectRefusal", field: WholeDeclaration },
DeclarationRef { module_path: "v1_compiler.emitted_closure_compile_host", decl_name: "mutation_subject_rust_module", field: WholeDeclaration },
DeclarationRef { module_path: "v1_compiler.emitted_closure_compile_host", decl_name: "subject_rust_module", field: WholeDeclaration },
DeclarationRef { module_path: "v1_compiler.emitted_closure_compile_host", decl_name: "mutation_subject_name", field: WholeDeclaration },
DeclarationRef { module_path: "v1_compiler.emitted_closure_compile_host", decl_name: "mutation_subject_refusal_summary", field: WholeDeclaration },
DeclarationRef { module_path: "v1_compiler.emitted_closure_compile_host", decl_name: "MutationVerdict", field: WholeDeclaration },
DeclarationRef { module_path: "v1_compiler.emitted_closure_compile_host", decl_name: "mutation_verdict_discriminated", field: WholeDeclaration },
DeclarationRef { module_path: "v1_compiler.emitted_closure_compile_host", decl_name: "mutation_verdict_summary", field: WholeDeclaration },
Expand Down Expand Up @@ -54,8 +58,12 @@ data emitted_closure_compile_seed_growth_justification: SeedGrowthJustification
DeclarationRef { module_path: "v1_compiler.emitted_closure_compile_host", decl_name: "acquire_probe_root_lock", field: WholeDeclaration },
DeclarationRef { module_path: "v1_compiler.emitted_closure_compile_host", decl_name: "run_required_emit_compile", field: WholeDeclaration },
DeclarationRef { module_path: "v1_compiler.emitted_closure_compile_host", decl_name: "manifest_carries_the_modeled_dependency_rows", field: WholeDeclaration },
DeclarationRef { module_path: "v1_compiler.emitted_closure_compile_host", decl_name: "mutation_prefers_a_closure_member_over_the_entry", field: WholeDeclaration },
DeclarationRef { module_path: "v1_compiler.emitted_closure_compile_host", decl_name: "mutation_falls_back_to_the_entry_and_names_it", field: WholeDeclaration },
DeclarationRef { module_path: "v1_compiler.emitted_closure_compile_host", decl_name: "probe_tree", field: WholeDeclaration },
DeclarationRef { module_path: "v1_compiler.emitted_closure_compile_host", decl_name: "the_subject_is_the_entry_own_module_past_a_leading_shared_member", field: WholeDeclaration },
DeclarationRef { module_path: "v1_compiler.emitted_closure_compile_host", decl_name: "the_subject_is_the_entry_own_module_when_it_is_declared_first", field: WholeDeclaration },
DeclarationRef { module_path: "v1_compiler.emitted_closure_compile_host", decl_name: "an_entry_module_missing_from_the_closure_refuses_rather_than_substituting", field: WholeDeclaration },
DeclarationRef { module_path: "v1_compiler.emitted_closure_compile_host", decl_name: "an_entry_module_declared_without_a_file_refuses_as_a_write_defect", field: WholeDeclaration },
DeclarationRef { module_path: "v1_compiler.emitted_closure_compile_host", decl_name: "an_unreadable_closure_manifest_refuses_on_its_own_cause", field: WholeDeclaration },
DeclarationRef { module_path: "v1_compiler.emitted_closure_compile_host", decl_name: "an_unreached_entry_is_not_a_pass", field: WholeDeclaration },
DeclarationRef { module_path: "v1_compiler.emitted_closure_compile_host", decl_name: "the_probe_root_name_is_composed_in_exactly_one_place", field: WholeDeclaration },
DeclarationRef { module_path: "v1_compiler.emitted_closure_compile_host", decl_name: "a_failed_restore_is_not_masked_by_a_non_terminal_fault_verdict", field: WholeDeclaration },
Expand Down
2 changes: 0 additions & 2 deletions src/v1/stage0/src/bin/claim_executor.rs
Original file line number Diff line number Diff line change
Expand Up @@ -3,8 +3,6 @@
use std::fs;
use std::path::PathBuf;
use std::process::ExitCode;
#[cfg(test)]
use v1_compiler::cli_run::workspace_root;
use v1_compiler::cli_run::PhaseProfile;

fn require_value(args: &[String], idx: usize, flag: &str) -> Result<String, ExitCode> {
Expand Down
Loading
Loading