Skip to content

Pre-step-3: land rust_item_host_observation as the changed-item denominator and admission wall — its only prior realization (rust_item_census.py) was deleted by the bankruptcy and no route replaced it - #9515

Closed
briansrls wants to merge 3 commits into
mainfrom
session/loyal-ram-883-origin

Conversation

@briansrls

Copy link
Copy Markdown
Contributor

Auto-opened by session-dashboard for session loyal-ram-883.
Pushing to session/loyal-ram-883-origin advances this PR.

Worker attestation

Before flipping this PR to ready for review, confirm each item:

  • Title describes the change (not the session id or branch).
  • PR body summarises what and why (replace the TODO below).
  • Tests run: name the command (e.g. npm test, cargo test) and the result.
  • If this closes a work item, the body contains a Closes #N directive.
  • No commits on this branch are surprises (no fork/cherry-pick I did not make).
  • No secrets / credentials / large binaries staged.

Summary

TODO: replace this paragraph with one or two sentences naming the change and its motivation. Reviewers read this first.

Test plan

  • TODO: list the commands that ran (or "no tests changed; relied on CI") and the outcome.

Brian Searls and others added 3 commits August 27, 2026 10:32
…make it the changed-item denominator the seed-growth admission join was waiting for

The census had one realization, scripts/rust_item_census.py, and gunbc#9132 deleted
it with the measurement corpus. Nothing replaced it, so from 2026-08-24 no route in
this repository could enumerate Rust items at identity grain -- and no rung drop was
declared, because the census's consumers were lanes rather than modules and no
dependent could refuse. The scaffold protecting it is a live instance of the rule
DESIGN 4b(3) added on 2026-08-26: its trigger read "producer lands and enrolls;
Python script deleted", a conjunction whose second half an unrelated cut satisfied
while the producer never landed.

gunbc.rust_item_scan reads items from rustfmt-normalized source with its
item-keyword population taken FROM extdeps.languages.rust.syntax rust_item_forms
rather than re-coined -- the deleted script's regex ITEM_PATTERNS were exactly the
second roster this reader refuses to author, and the census predicted its own
failure from it. It is not a parser and does not claim to be: it refuses on any
structural line it cannot classify, which is what makes an incomplete recognizer
safe rather than quietly smaller.

gunbc.rust_item_host_observation supplies TWO populations from TWO functions, which
is the condition gunbc.seed_growth_admission's own forward-freeze row set on
enrolment. seed_growth_join_declarations is replaced by the split pair plus
seed_growth_admit_change; an unattributed hand-Rust change REFUSES rather than
reporting an empty delta; deletions offset nothing; ExistingSeedItemModified carries
capability_origin, with no value naming a capability originated in Rust.

Rung: mechanically preventable AS TO THE ROUTE and no higher -- the wall executes
under witnesses and no required CI phase invokes it yet. Arming it is a separate
change. The terminal seed-bridge roster is deliberately not authored here.

Hand-Rust delta: zero. Every file is .dag.
…s capability was modeled before it, and that the model constrains it

CapabilityAlreadyModeled was payload-free, so it could be satisfied by
inspecting the final candidate -- which cannot distinguish a model that
existed before its realization from a model authored beside the realization
that inspired it. That distinction is the whole question the arm existed to
ask, so the vocabulary moves to gunbc.capability_origin and grows a payload:
an authority, and where a capability introduced in this change came from.

THREE TESTS, ESTABLISHING THREE DIFFERENT THINGS. The leaf test proves Rust
owns no semantic decision. The origin test proves the semantics predate the
Rust: remove the hand-Rust delta, build E1, and the authority must still hold.
The conformance test proves the model CONSTRAINS the Rust rather than merely
agreeing with it: mutate the realization alone, and the predicted evidence must
go red while E1 stays green. A retro-described implementation passes the first
two and fails the third, because its fixtures were derived from the behavior
they check -- which is why FixtureProvenance refuses GeneratedByRealization
even when the mutation went red.

ADDITIONS ARE COVERED, NOT ONLY MODIFICATIONS. A newly added item can carry a
perfectly good justification row and still have been retro-modeled in the same
change, so the relation participates in the addition arm and roster membership
is no longer sufficient.

THE EPOCH IS IDENTIFIED AND EXPIRES. ModelEpochRef names the exact derived E1
population, and the subject carries both the base and the head it was derived
against. A probe taken against another base refuses rather than admitting --
the reversed-diff class stated as evidence rather than as advice.

RUNG: the vocabulary is structural (no arm means "the Rust behaves this way,
therefore this is the intended model", and no not-executed arm has a path to an
admitting verdict). The tests themselves are executed by nothing yet, so every
real call today refuses. The next-rung trigger names the capability.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
… the length check (review 56637)

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@briansrls
briansrls marked this pull request as ready for review August 27, 2026 21:39

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: b95c0e0107

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

}

data rust_source_namespace_rows: List<RustSourceNamespaceRow> = [
RustSourceNamespaceRow { repo_prefix: "src/v1/stage0/src/bin/", namespace_prefix: "v1_compiler.bin." },

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Map bin sources to their cited namespace

For any added item under src/v1/stage0/src/bin/, this row projects a module such as v1_compiler.bin.claim_executor, but the repository's citation vocabulary uses v1_compiler.claim_executor (for example, floor_non_verdict_gate_authority), and there are no v1_compiler.bin.* citations in the tree. Consequently, a correctly justified bin item cannot join its SeedGrowthJustification row and is falsely reported as an unjustified addition.

Useful? React with 👍 / 👎.

Comment on lines +277 to +283
let unjustified = seed_growth_unjustified_additions(
added: projected_declaration_refs(projections: projections)
)
let origin_refused = origin_refusals(
bridges: bridges,
evidence: evidence,
added: projected_declaration_refs(projections: projections)

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Refuse uncitable additions before completing admission

When a change adds an impl block or impl method, item_declaration_ref returns ItemDeclarationRefUncitable, and projected_declaration_refs removes it from the list used here. Such additions therefore participate in neither the justification check nor origin_refusals; with no other citable additions, the verdict reaches SeedGrowthAdmissionComplete and merely reports the items in uncitable_items. This lets exactly the newly added hand-Rust leaves that DeclField cannot name bypass the admission wall, so they need to refuse until the citation vocabulary can represent them.

Useful? React with 👍 / 👎.

Comment on lines +314 to +319
let conformance = conformance_verdict(
probe: conformance_probe_for_authority(
probes: evidence.conformance_probes,
authority: capability_origin_authority(origin: bridge.origin)
)
)

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Expire conformance probes with their observed epoch

When a bridge uses CapabilityPresentOnBase, the origin side admits without a model-epoch probe, while the conformance probe selected here is converted directly into a verdict without comparing its embedded epoch to AdmissionEvidence.observed_base_revision and observed_head_revision. A previously passing RealizationMutationRefused row from another base or head can therefore be reused to admit a different realization, despite the carrier's stated rule that every probe expires when either revision moves.

Useful? React with 👍 / 👎.

@gunbai-bot

gunbai-bot Bot commented Aug 27, 2026

Copy link
Copy Markdown
Contributor

Closing as already-merged. Reopen if this was deliberate — but I think merging it would actively harm main.

This PR's head is b95c0e01076, which is the exact head that #9444 squash-merged at 20:34Z. The three commits git log origin/main..HEAD reports as "not on main" are an ancestry artifact: squash-merge deliberately does not preserve the feature head as an ancestor, so ancestry is the wrong oracle here.

Verified by symbol instead — every construct the approving review (56960) credits to this diff is already on main:

symbol occurrences on main
rust_item_scan 13
rust_item_forms 9
seed_growth_unjustified_additions 5
seed_growth_stale_justifications 6
NoNewCapability 4
ModeledCapability 9
seed_growth_admit_change 20

And capability_origin.dag, rust_item_scan.dag, rust_item_host_observation.dag, rust_item_census_instrument.dag are all present.

I checked the reverse direction, since a superset claim is the easy thing to get wrong. Diffing this head against main across every file it touches yields exactly two lines, and main is the side that has them:

+import gunbc.emitted_closure_compile_seed_growth { emitted_closure_compile_seed_growth_justification }
+    emitted_closure_compile_seed_growth_justification,

So main is a strict superset of this branch. There is nothing here to land.

Why this is worth closing rather than leaving open. Re-applying a diff main already carries is precisely how a duplicate declaration gets authored — and that is not hypothetical today: one of the two breaks that took main down this afternoon was a byte-identical second declaration of srv3_wiring, repaired by #9497. An approving review is not protection against this, because the review reads the diff, which is genuinely good; it does not check whether the diff is already applied.

This is the fifth phantom PR today, by two mechanisms — three re-opened on an already-merged head (#9479, #9503, this one), and one parent silently completed by its stacked child merging first (#9426).

— sent from merry-bear-547

@gunbai-bot gunbai-bot Bot closed this Aug 27, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant