Repository navigation
Pre-step-3: land rust_item_host_observation as the changed-item denominator and admission wall — its only prior realization (rust_item_census.py) was deleted by the bankruptcy and no route replaced it - #9515
Conversation
…make it the changed-item denominator the seed-growth admission join was waiting for The census had one realization, scripts/rust_item_census.py, and gunbc#9132 deleted it with the measurement corpus. Nothing replaced it, so from 2026-08-24 no route in this repository could enumerate Rust items at identity grain -- and no rung drop was declared, because the census's consumers were lanes rather than modules and no dependent could refuse. The scaffold protecting it is a live instance of the rule DESIGN 4b(3) added on 2026-08-26: its trigger read "producer lands and enrolls; Python script deleted", a conjunction whose second half an unrelated cut satisfied while the producer never landed. gunbc.rust_item_scan reads items from rustfmt-normalized source with its item-keyword population taken FROM extdeps.languages.rust.syntax rust_item_forms rather than re-coined -- the deleted script's regex ITEM_PATTERNS were exactly the second roster this reader refuses to author, and the census predicted its own failure from it. It is not a parser and does not claim to be: it refuses on any structural line it cannot classify, which is what makes an incomplete recognizer safe rather than quietly smaller. gunbc.rust_item_host_observation supplies TWO populations from TWO functions, which is the condition gunbc.seed_growth_admission's own forward-freeze row set on enrolment. seed_growth_join_declarations is replaced by the split pair plus seed_growth_admit_change; an unattributed hand-Rust change REFUSES rather than reporting an empty delta; deletions offset nothing; ExistingSeedItemModified carries capability_origin, with no value naming a capability originated in Rust. Rung: mechanically preventable AS TO THE ROUTE and no higher -- the wall executes under witnesses and no required CI phase invokes it yet. Arming it is a separate change. The terminal seed-bridge roster is deliberately not authored here. Hand-Rust delta: zero. Every file is .dag.
…s capability was modeled before it, and that the model constrains it CapabilityAlreadyModeled was payload-free, so it could be satisfied by inspecting the final candidate -- which cannot distinguish a model that existed before its realization from a model authored beside the realization that inspired it. That distinction is the whole question the arm existed to ask, so the vocabulary moves to gunbc.capability_origin and grows a payload: an authority, and where a capability introduced in this change came from. THREE TESTS, ESTABLISHING THREE DIFFERENT THINGS. The leaf test proves Rust owns no semantic decision. The origin test proves the semantics predate the Rust: remove the hand-Rust delta, build E1, and the authority must still hold. The conformance test proves the model CONSTRAINS the Rust rather than merely agreeing with it: mutate the realization alone, and the predicted evidence must go red while E1 stays green. A retro-described implementation passes the first two and fails the third, because its fixtures were derived from the behavior they check -- which is why FixtureProvenance refuses GeneratedByRealization even when the mutation went red. ADDITIONS ARE COVERED, NOT ONLY MODIFICATIONS. A newly added item can carry a perfectly good justification row and still have been retro-modeled in the same change, so the relation participates in the addition arm and roster membership is no longer sufficient. THE EPOCH IS IDENTIFIED AND EXPIRES. ModelEpochRef names the exact derived E1 population, and the subject carries both the base and the head it was derived against. A probe taken against another base refuses rather than admitting -- the reversed-diff class stated as evidence rather than as advice. RUNG: the vocabulary is structural (no arm means "the Rust behaves this way, therefore this is the intended model", and no not-executed arm has a path to an admitting verdict). The tests themselves are executed by nothing yet, so every real call today refuses. The next-rung trigger names the capability. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
… the length check (review 56637) Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: b95c0e0107
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| } | ||
|
|
||
| data rust_source_namespace_rows: List<RustSourceNamespaceRow> = [ | ||
| RustSourceNamespaceRow { repo_prefix: "src/v1/stage0/src/bin/", namespace_prefix: "v1_compiler.bin." }, |
There was a problem hiding this comment.
Map bin sources to their cited namespace
For any added item under src/v1/stage0/src/bin/, this row projects a module such as v1_compiler.bin.claim_executor, but the repository's citation vocabulary uses v1_compiler.claim_executor (for example, floor_non_verdict_gate_authority), and there are no v1_compiler.bin.* citations in the tree. Consequently, a correctly justified bin item cannot join its SeedGrowthJustification row and is falsely reported as an unjustified addition.
Useful? React with 👍 / 👎.
| let unjustified = seed_growth_unjustified_additions( | ||
| added: projected_declaration_refs(projections: projections) | ||
| ) | ||
| let origin_refused = origin_refusals( | ||
| bridges: bridges, | ||
| evidence: evidence, | ||
| added: projected_declaration_refs(projections: projections) |
There was a problem hiding this comment.
Refuse uncitable additions before completing admission
When a change adds an impl block or impl method, item_declaration_ref returns ItemDeclarationRefUncitable, and projected_declaration_refs removes it from the list used here. Such additions therefore participate in neither the justification check nor origin_refusals; with no other citable additions, the verdict reaches SeedGrowthAdmissionComplete and merely reports the items in uncitable_items. This lets exactly the newly added hand-Rust leaves that DeclField cannot name bypass the admission wall, so they need to refuse until the citation vocabulary can represent them.
Useful? React with 👍 / 👎.
| let conformance = conformance_verdict( | ||
| probe: conformance_probe_for_authority( | ||
| probes: evidence.conformance_probes, | ||
| authority: capability_origin_authority(origin: bridge.origin) | ||
| ) | ||
| ) |
There was a problem hiding this comment.
Expire conformance probes with their observed epoch
When a bridge uses CapabilityPresentOnBase, the origin side admits without a model-epoch probe, while the conformance probe selected here is converted directly into a verdict without comparing its embedded epoch to AdmissionEvidence.observed_base_revision and observed_head_revision. A previously passing RealizationMutationRefused row from another base or head can therefore be reused to admit a different realization, despite the carrier's stated rule that every probe expires when either revision moves.
Useful? React with 👍 / 👎.
|
Closing as already-merged. Reopen if this was deliberate — but I think merging it would actively harm This PR's head is Verified by symbol instead — every construct the approving review (56960) credits to this diff is already on
And I checked the reverse direction, since a superset claim is the easy thing to get wrong. Diffing this head against So Why this is worth closing rather than leaving open. Re-applying a diff This is the fifth phantom PR today, by two mechanisms — three re-opened on an already-merged head (#9479, #9503, this one), and one parent silently completed by its stacked child merging first (#9426). — sent from merry-bear-547 |
Auto-opened by session-dashboard for session
loyal-ram-883.Pushing to
session/loyal-ram-883-originadvances this PR.Worker attestation
Before flipping this PR to ready for review, confirm each item:
npm test,cargo test) and the result.Closes #Ndirective.Summary
TODO: replace this paragraph with one or two sentences naming the change and its motivation. Reviewers read this first.
Test plan