Skip to content

Cause 2's forcing function was about to vanish: record the executed false-green as a typed stall row - #9494

Closed
gunbai-bot[bot] wants to merge 4 commits into
mainfrom
fix/cause2-removal-false-green
Closed

gunbai-bot[bot] wants to merge 4 commits into
mainfrom
fix/cause2-removal-false-green

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Aug 27, 2026

Copy link
Copy Markdown
Contributor

…alse-green as a typed stall row

THE CLASS. `02_parse` `field_to_child_node` parks a DECLARED field type in the `inferred` slot
with a fabricated `Resolved` stamp, and `declaration_index` `for_each_node` deliberately skips
`inferred`. So a declared field type is a real reference that no authored-name reader can reach.

THE EXECUTED CONSEQUENCE, which is why this is a row and not a note. On the REMOVAL side of
namespace wave admission:

  base:  import probe.payload { Wrapper }   type Holder = Held { w: Wrapper }
  head:  (import dropped)                   type Holder = Held { w: Wrapper }
  ->     dispositions=[UnusedSubjectMembershipRemoved]

The gate answers "removed; no name in this module bound through it" about an import whose name
is still referenced in the tree it just examined. That is a GREEN, and it is worse than the
add-side false refusal repaired in #9490. A refusal is loud -- it stopped a lane, and that is how
this whole class got found. A false "unused, safely removed" stops nothing and actively invites
the deletion, so the wall meant to catch unsound namespace motion is the thing recommending it.

WHY THE ROW EXISTS AT ALL, and it is the part worth reading. #9490 routed the ADD direction
around this blind position by reading the authored import claim, which is correct for ADD and
impossible for REMOVAL -- an import claim cannot tell you whether anything was bound through it.
That repair unblocked the one lane that felt the defect. A deficit whose only complainant gets
routed around has its frequency driven to zero BY CONSTRUCTION and stops ranking for work, which
is DESIGN section 5's absorbing-fallback shape wearing a scheduling label rather than a runtime
one. sharp-ram-84 flagged exactly this and they were right: the class was about to lose its only
forcing function. A measurement replaces it, because a measurement does not get unblocked.

THE BLOCKER IS AwaitsOneGrounding, NOT ClimbableButUnbuilt, for the reason the
import-eligibility row above already states: three candidate shapes are visible from here and
none is decidable from the consumer side, so the work is UNSPECIFIABLE rather than merely
unstarted, and filing it as unbuilt would send someone to build at a moment when the contract is
undecided. The bar is higher because it is a v1 seed parse-level contract.

THE TRIGGER NAMES THE CAPABILITY, not an artifact that would contribute to one -- a declared
field type reachable from an authored-name reader over the Node tree, such that
`membership_bound_through` answers correctly WITHOUT being told about field types. Explicitly not
satisfied by a reader special-casing `inferred` for this one consumer: that leaves every other
authored-name walker blind and converts one blind position into a per-consumer exemption roster.

Population is bounded and enumerated: the one producer and its five callers.

Verified by the parse sweep CI runs: 4194 files parse-clean, the only finding being main's
existing `contention.dag` breakage from #9397, which is unrelated and separately owned.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013crMNyLvjKC2Q5UF851PKy
@gunbai-bot

gunbai-bot Bot commented Aug 27, 2026

Copy link
Copy Markdown
Contributor Author

This is main's breakage, not this diff's. Investigated rather than re-run, since a re-run over the same base reproduces it.

The failing job's step signature:

Required CI: witnesses lane (parse, witness floor)   FAIL
Upload the floor's admission roster                  FAIL  (no files found)
Upload the expected-red roster join                  FAIL  (no files found)
Upload the long-home storage agreement               FAIL  (no files found)
Upload the floor's per-claim cost receipt            FAIL  (no files found)

Four roster uploads finding no files is the specific signature of the floor refusing at strict-preparation — the ledger is never written because the prepared subject cannot be built. It is not a witness failing; it is zero witnesses executing. deep-dove-394 measured six consecutive main runs in this state, with eleven commits landed behind it.

Cause is b20ac7ad44f (#9397), which renamed grant_duration_seconds → grant_duration_bound_seconds and made it partial, missing its consumer in dag/product/fabric/contention.dag. Five repair sites, and the repair is open as #9488.

This PR adds one GuaranteeStall row to an existing .dag carrier. It was verified through the same parse sweep CI runs: 4194 files parse-clean, the only finding being contention.dag. A single data row in a carrier that already holds two siblings of the same type cannot produce a strict-preparation refusal.

No action here. This will go green once #9488 lands; re-running before that only reproduces main's refusal.

— sent from snappy-dove-250

gunbai-bot Bot pushed a commit that referenced this pull request Aug 27, 2026
… the one authored name it does not carry (#9494)

Rebuilt on the operator ruling: authored references come from the parser's
`OccurrenceTransport`, never from re-reading the final `Node`, because the
parser already stamps the fact exactly and a Node-reading projection is a
SECOND AUTHORITY free to diverge from it.

That is exact for a DECLARED FIELD TYPE. `stamp_parsed_inferred` stamps a
`Resolved` inferred node as `ParsedOccurrenceReference { TypeOccurrence }`, and
the stamp is on the SLOT -- so the "generic over the form" property the first
construction gained was precisely the property the transport already owned. It
was reimplementing `stamp_parsed_inferred` from its own output. The seam is one
argument wide: `CensusFillParse` already carries `occurrence_transport` and both
callers already hold one at the line they call `record_from_module`, so the fact
was PRODUCED AND DISCARDED at a return boundary rather than absent.

THE VARIANT PATTERN HEAD STILL READS AN AUTHORED STRING, and that is a scope
finding rather than an exception taken. The ruling's rationale has no referent
there: `VariantPattern.name` is a `String`, `stamp_parsed_pattern` stamps
`field_bindings` only, `ConstructorOccurrence` is stamped NOWHERE in the parser,
and occurrence ids are minted per `Node`. The parser mints nothing for that
position, so there is no first authority to be second to -- reading the String
is not re-derivation, it is the only derivation. The transport repair for that
half is blocked on a RULING, not a RISK: the allocator objection is answered
(`content_hash` folds no occurrence id; `legacy_binding_delta` declares an
`OccurrenceId` unstable BECAUSE the counter encodes DFS position), and what
remains is that stamping a new occurrence is a parser change.

A PEER FIELD, not a widened `referenced`: the two have different authorities and
different precision, and fusing them hides which is which. The consumer takes
the union.

THE IMPORT-MEMBER FILTER IS LOAD-BEARING. The transport stamps an import member
name as a `TypeOccurrence` enclosed by the import target, so consuming every
`TypeOccurrence` makes each import bound-through by its own member and
`UnusedSubjectMembershipRemoved` becomes UNREACHABLE -- a disposition going
permanently quiet, which is worse than the false green this closes. Caught by a
PRE-EXISTING arm, not by review.

Seven arms, removal side, with a three-way mutation receipt re-taken against
this construction (2 / 3 / 2 failing per isolated mutation, 27 passing
unmutated) -- not carried over from the deleted one, since a receipt about code
that no longer exists reads as evidence for what is there.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This standing is superseded by the measured parser carrier and must not merge as written.

ParseWithTableResult already carries OccurrenceTransport; the parser stamps the declared field-type node as a TypeOccurrence. The fact is therefore not OutsideTheLadder, not capped at StructurallyImpossible, and not blocked on choosing between moving storage to type_annotation or selectively traversing inferred. The missing relation is produced and discarded before declaration_index consumes the parse result.

Reframe the row (or replace it in the reader repair) as ProducerAvailableConsumerUnwired: namespace-wave removal/binding must consume the parser-issued authored-reference transport, joining OccurrenceTransport.references to its index by exact OccurrenceId. The trigger must explicitly refuse Node-span/name reconstruction and traversal of inferred. Keep the separate parser-storage cleanup as a discriminator-first GuaranteeStall; it is not this namespace-wave blocker.

The executed false-green remains valuable evidence. The present cause, ceiling, blocker, bounded population, and next-rung trigger assert a design question that has already been answered, so this is a false machine-consumed authority row despite green CI and provider review.

…sted

Operator REQUEST_CHANGES (review 5046011328). The objection is correct and I
verified it in source before encoding it, rather than on the relay.

WHAT THE ROW GOT WRONG. It carried ceiling StructurallyImpossible and blocker
AwaitsOneGrounding, and described the repair direction as an undecided choice
among moving the type out of `inferred`, reading `inferred` selectively, or some
third shape. That premise is refuted by the parser itself:

  v1.02_parse stamp_parsed_inferred stamps the resolved inferred node with
  ParsedOccurrenceReference { category: TypeOccurrence }

so the exact fact -- a type occurrence with parser-minted identity, containment
and an authored-name projection -- IS produced. And ParsedNodeStampResult returns
`node: node` UNCHANGED, so the stamps live only in the threaded ParseContext and
the tree the declaration index walks never carried them. Produced, then discarded
before any consumer sees it. Not structurally impossible, and not undecided.

WHY THIS IS THE HARDER FAILURE. This session had already established the
OccurrenceTransport producer. The row then asserted the direction was UNSPECIFIABLE.
That is not a missing measurement -- it is a row contradicting a measurement already
taken, so nothing was left to go and check and no gap invited anyone to look.

THE AMENDMENT:

  ceiling      StructurallyImpossible -> StructurallyGuaranteed
  blocker      AwaitsOneGrounding     -> ClimbableButUnbuilt
  population   six PRODUCER sites     -> four CONSUMER symbols
  trigger      "reachable from an authored-name reader"
               -> consume the parser-issued transport, never by traversing
                  Node.inferred, moving the type into type_annotation, or
                  reconstructing identity from an authored name or a span

`current: OutsideTheLadder` is deliberately unchanged: the live consumer still emits
a false-green deletion disposition, and an available upstream fact changes the
attainable CEILING without improving today's guarantee.

The population move is the substantive half. Naming the six parser sites said the
producer was the defect and sent the reader to the wrong artifact; the parser is doing
its job and the defect begins where consumers discard the fact and rebuild a weaker
population from the unchanged tree.

I did not take the top rung. StructurallyImpossible would need a carrier whose accepted
removal arm cannot be constructed without consuming proof that the authored-reference
population was considered; this repair does not provide that, so a verdict can still be
miscomputed. Correcting an inflated row by inflating it the other way is the same defect.

MEASURED: live_stall_is_below_its_ceiling => true, stall_permanence_follows_the_blocker
=> true, and the corpus parses clean.

NOT CLAIMED: those witnesses do not discriminate this ceiling CHOICE. The first compares
current < ceiling, which holds for any ceiling above OutsideTheLadder, so it establishes
the row is coherent and not that StructurallyGuaranteed is the right value. That choice
rests on the argument above.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013crMNyLvjKC2Q5UF851PKy
briansrls pushed a commit that referenced this pull request Aug 27, 2026
…, and the false green they produced (#9504)

* Recover two authored references the reference channel could not reach, and the false green they produced (#9494)

`collect_reference_occurrences` walks a Node through seven child slots. Two
authored references are reachable through NEITHER, and the consequence is a
GREEN rather than a refusal, which is why it stood.

A VARIANT PATTERN HEAD is a raw `String` on `MatchPattern`, not a `Node`, so a
module whose only use of an imported coproduct is naming its variants in match
arms contributed nothing to `referenced`. A DECLARED FIELD TYPE is parked by
`v1.02_parse` `field_to_child_node` in the `inferred` slot, and every authored-
name reader correctly declines to read a slot whose contract says DERIVED.

With either invisible, `membership_bound_through` answered NO about an import
whose name is still referenced in the very tree it examined, and the wave wall
reported a live import as `UnusedSubjectMembershipRemoved` -- a verdict whose
natural next action is to delete the import the wall just failed to see.

WHAT IS DELIBERATELY NOT COLLECTED, because the ruling forbids minting
membership from a compiler consequence and the danger arrives through the field
least likely to be checked. NOT `parent_enum`: the parser writes `none` and
INFERENCE fills it in, so it is not an authored name at all. NOT
`field_bindings`: those are binders, and collecting them would report a
pattern's own bound variables as references into whatever module spells them
the same way.

WHY THE `inferred` PROJECTION IS EXACT AND NOT A WALK OF INFERENCE OUTPUT: this
index is built in the PARSE phase, before inference runs, so the only things any
`inferred` slot can hold are the ones the parser put there. That is a statement
about this reader's pipeline position, not a licence to widen -- on a
post-inference tree the same recursion is the forbidden shape, and a consumer
that moves this reader must revisit the block rather than inherit it.

EVIDENCE, SIX ARMS AT THE FIXTURE BOUNDARY, ON THE REMOVAL SIDE DELIBERATELY.
The add side cannot test this any more: #9490 made an import claim answer
membership outright for ADD, so an add-side fixture goes green with the repair
AND with it reverted. Measured -- with channel one deleted in isolation 2 arms
fail, with channel two deleted in isolation 2 arms fail, with both present 26
pass -- and under BOTH mutations the pre-existing add-side arm stayed green,
which is the measurement that chose the placement.

The scope question was settled by execution rather than by reading the ruling: a
type alias's RHS reproduces the same false green and is enrolled as a sixth arm;
a function's return type does not reproduce, is already reachable through an
ordinary slot, and is recorded as a measured negative rather than enrolled --
an arm there would pass either way and carry no information.

Hand-item delta: zero. Both blocks are inside a function the seed-growth roster
already enumerates.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Consume the parser's transport for authored type references, and read the one authored name it does not carry (#9494)

Rebuilt on the operator ruling: authored references come from the parser's
`OccurrenceTransport`, never from re-reading the final `Node`, because the
parser already stamps the fact exactly and a Node-reading projection is a
SECOND AUTHORITY free to diverge from it.

That is exact for a DECLARED FIELD TYPE. `stamp_parsed_inferred` stamps a
`Resolved` inferred node as `ParsedOccurrenceReference { TypeOccurrence }`, and
the stamp is on the SLOT -- so the "generic over the form" property the first
construction gained was precisely the property the transport already owned. It
was reimplementing `stamp_parsed_inferred` from its own output. The seam is one
argument wide: `CensusFillParse` already carries `occurrence_transport` and both
callers already hold one at the line they call `record_from_module`, so the fact
was PRODUCED AND DISCARDED at a return boundary rather than absent.

THE VARIANT PATTERN HEAD STILL READS AN AUTHORED STRING, and that is a scope
finding rather than an exception taken. The ruling's rationale has no referent
there: `VariantPattern.name` is a `String`, `stamp_parsed_pattern` stamps
`field_bindings` only, `ConstructorOccurrence` is stamped NOWHERE in the parser,
and occurrence ids are minted per `Node`. The parser mints nothing for that
position, so there is no first authority to be second to -- reading the String
is not re-derivation, it is the only derivation. The transport repair for that
half is blocked on a RULING, not a RISK: the allocator objection is answered
(`content_hash` folds no occurrence id; `legacy_binding_delta` declares an
`OccurrenceId` unstable BECAUSE the counter encodes DFS position), and what
remains is that stamping a new occurrence is a parser change.

A PEER FIELD, not a widened `referenced`: the two have different authorities and
different precision, and fusing them hides which is which. The consumer takes
the union.

THE IMPORT-MEMBER FILTER IS LOAD-BEARING. The transport stamps an import member
name as a `TypeOccurrence` enclosed by the import target, so consuming every
`TypeOccurrence` makes each import bound-through by its own member and
`UnusedSubjectMembershipRemoved` becomes UNREACHABLE -- a disposition going
permanently quiet, which is worse than the false green this closes. Caught by a
PRE-EXISTING arm, not by review.

Seven arms, removal side, with a three-way mutation receipt re-taken against
this construction (2 / 3 / 2 failing per isolated mutation, 27 passing
unmutated) -- not carried over from the deleted one, since a receipt about code
that no longer exists reads as evidence for what is there.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Aug 27, 2026

Copy link
Copy Markdown
Contributor Author

Closing this PR. Its row describes a defect that no longer exists, and I am the one who let it go stale.

#9504 landed on main at 2026-08-27 18:48. I amended this row at ~22:45 — nearly four hours later — against a branch whose last merge of main predated it, and never re-measured. A review approved the amendment at 22:5x, praising it for "an executed RED". That approval read the row's prose; the tree says otherwise.

Measured against origin/main, not against this branch:

  • record_from_module takes a fourth parameter transport: &Rc<OccurrenceTransport>, and both call sites pass fill.occurrence_transport
  • authored_type_references_from_transport reads transport.references and filters to OccurrenceCategory::TypeOccurrence
  • membership_bound_through chains record.referenced with record.authored_type_references and asks both

So every one of the four population members I named as not ingesting the transport now ingests it. The row's current: OutsideTheLadder — justified on the grounds that "the live consumer still emits a false-green deletion disposition" — is false.

The forcing function is already enrolled, which is the part that settles closure rather than amendment. §4b(4) requires a climb to keep its discriminating evidence, and #9504 kept it: a_removed_import_whose_name_survives_only_as_a_declared_field_type_is_not_reported_unused. Executed on the merged tree just now:

test a_removed_import_whose_name_survives_only_as_a_declared_field_type_is_not_reported_unused ... ok
test result: ok. 32 passed; 0 failed

The measurement this row existed to preserve is a passing regression control in the tree. A stall row beside it would be a second authority for one fact (§3) asserting the opposite of what the fact is.

Why closing beats amending again. An amendment would have to say the class is closed — which is a stall row with no stall, i.e. a row whose only content is that it has no content. Worse, it is machine-consumed: it sits in all_guarantee_stalls and is folded by every_stall_is_below_its_ceiling. A row asserting a live gap that is closed is exactly the false diagnosis the operator's review warned against minting, arrived at from the opposite direction.

The mechanism, since it is the reusable part. I measured the call sites on my own worktree and read a three-parameter record_from_module, concluded the transport "is sitting at the call site and simply isn't passed in", and dispatched a work item on it. sleek-koi-379 reported back that the brief was satisfied before it was written. Every reading I took was accurate about my branch and false about main. This is the same class I spent the session naming in other people's work — a correct measurement of the wrong subject — and the branch/main axis is the one I did not vary.

The genuinely open remainder is not this row: referenced still walks the tree for the variant-pattern constructor head, because MatchPattern::VariantPattern.name is a raw String and ConstructorOccurrence is stamped nowhere in the parser. That is a parser ruling, not unbuilt work, and it belongs in its own item rather than under a stall row that misdescribes its neighbour.

— sent from snappy-dove-250

@gunbai-bot gunbai-bot Bot closed this Aug 27, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant