Skip to content

XL-0A: the emitted v2 compiler closure reaches rustc type checking (2779 typeck errors remain, one identity class dominant) - #9665

Merged
gunbai-bot[bot] merged 32 commits into
mainfrom
session/bold-carp-449
Aug 30, 2026
Merged

gunbai-bot[bot] merged 32 commits into
mainfrom
session/bold-carp-449

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Aug 29, 2026 •

Copy link
Copy Markdown
Contributor

Part of #9664 — XL-0A: the emitted v2 compiler closure (src/v2/compiler/00_compile.dag) reaches rustc type checking. A phase-frontier increment, not the XL-0 gate.

XL-0 gate (cargo check errors = 0) NOT satisfied. On the frozen tree the closure emits (175 members: 174 .rs + Cargo.toml) and rustc completes name resolution, cycle detection and generic-arity checking for the first time; 2779 type-check errors remain, one identity class dominant (below). Result carrier: RustcTypeCheckFrontierReached { emitted_members, fixed_point_receipt, closed_pre_typeck_classes, typeck_error_population } — never XL0Passed / CompilerBuildable / NativeCompilerCandidate.

Accounting rule (binding for every later XL-0 report)

Compiler progress is ordered first by the furthest rustc phase reached, then by the error relation within that phase. A cargo error total is a census of the phase rustc aborted in: resolution errors (E0425) and cycle errors (E0391) stop rustc before type checking, so a smaller total that aborts earlier ranks BELOW a larger total that reaches typeck. The history of this PR, in that order:

frontier reached instrument, aborting phase total tree
name resolution cargo check, aborted at resolution (E0425 ×254) 261 main @ 6447dd4 (the issue's baseline)
later pre-typeck aborted at resolution / async lowering (E0425, E0728, E0107) 20 ebf8dca
cycle / generic-arity aborted at E0391 variance cycle + E0107 15 443f3de
first complete type check typeck completed, all phases reported 2790 → 2799 → 2779 e9900e2 → 0773184 fixed point → c2dadc8 / 466811e fixed point

A future 12-error run that aborts pre-typeck ranks below the 2779 typeck run. I attributed the 2790 jump at e9900e2 to the change that closed the E0391 cycle and gated it; that was a measured non-event — diff -r of the 15-error and the fixed-point emitted trees is 34 files, almost all use lines. The typeck population was latent underneath every earlier number.

Frozen output

identity value
freeze (authority) head 49482b0 — nothing after it but the regeneration commit
regeneration commit c2dadc8 (the only mirror change after the freeze)
final branch head 466811e — one fixture-only commit after the regeneration (dag/test/claim witness file, outside the regen population; a regen round on this head, claim_executor --required-regen with gunbc=8eb02a1c36c8cd4d, exits 0 with first_generation_equal=true and no regen-population path changed — /tmp/xl0post.log on srv1)
main parent (merge-base) 5e80671
merged tree CI builds refs/pull/9665/merge; its tree equals the branch tree while main stays at 5e80671 — merged tree digest a6aaba27091ee193b9dc8b31fb3ade008602502f
authority tree digest (git ls-tree -r HEAD -- dag src/v2 src/v1, stage0 excluded) a79b275e332a394a
installed mirror digest (src/v1/stage0/src/*.rs, LC_ALL=C sorted, concatenated, sha256) b1a0409ce9fc79d4
compiler artifact producing the final empty round gunbc=974aafe864f743f6, built from the round-(N−1) installed tree
compiler artifact running the witnesses and falsifiers gunbc=8eb02a1c36c8cd4d — the same installed tree b1a0409ce9fc79d4 rebuilt at head 466811e; src/v1/stage0/build.rs stamps git rev-parse HEAD into the binary, so the artifact hash is a function of (mirror bytes, HEAD) and the two ids name one compiler

Any push to this branch or movement of main after this table re-opens the gate.

Generation transaction (srv1, aarch64)

Criterion: byte fixed point over the regen population — every file the regen produces is byte-equal to its installed counterpart (cmp per file; main.rs is declared divergent by the regen itself; hand-authored files are outside its population). first_generation_equal and the changed-path list are not the criterion. The full workspace is rebuilt inside every round, so a mirror that does not compile stops the line at the round that produced it. No generated file was hand-edited.

round compiler artifact built from installed tree regen-population paths changed
1 gunbc=14967ca810cb6609 db46176cc5cf5861 (the freeze's committed mirror) v1_compiler_emit_rust.rs, v1_tests_claim_reference_derived_disposition_census_witness_test.rs
2 gunbc=5378a516528a6e0c efa440bc86734f53 v1_compiler_trait_derive_emit.rs (retracts the unused pub use crate::std_types::List; the earlier qualified route synthesized)
3 gunbc=974aafe864f743f6 b1a0409ce9fc79d4 none — byte fixed point

Launched 2026-08-29T19:52:56Z (/tmp/xl0e2.sh → /tmp/xl0j2.log on srv1); regen commit c2dadc8 carries exactly the round-1 + round-2 candidate bytes (3 files, +224/−83), local digest re-derived b1a0409ce9fc79d4.

Cross-host control: the cycle from dc04b9d ran on both srv1 (aarch64) and BuildBuddy (amd64) and converged to the identical installed-tree digest 0479b0df9fc5598e through the same three rounds — the generator is host-independent.

Every changed mirror path is explained by an authority change in this PR:

mirror authority
extdeps_languages_rust_emit.rs dag/extdeps/languages/rust/emit.dag — rt_function_registry rows symbol_lexeme, symbol_intern_lexeme; rust_simple_method_specs row is_empty
std_primitive_projection.rs, std_primitive_identity.rs dag/std/primitive_projection.dag, dag/std/primitive_identity.dag — the two symbol seams rostered HostRealizedSeam, with OrderFreeResult traversal facts
v1_compiler_emit_rust.rs src/v1/05_emit_rust.dag — every emitter repair in the class table
v1_compiler_infer.rs, v1_compiler_infer_lookup.rs, v1_compiler_infer_sigs.rs, v1_std_core.rs src/v1/04_infer.dag, 04_lookup.dag, 04_sigs.dag, 00_core.dag — CallTargetIdentity.RuntimePrimitiveCall.projected_from, DeclaredCallableIdentity hoisted to v1.std.core, decl_name = last segment
v1_compiler_runtime_rust.rs, v1_rt.rs src/v1/runtime_rust.dag — symbol_lexeme / symbol_intern_lexeme identity realizations (v1_rt.rs lands one round later: it is rendered by the previously compiled rt_hash_ops)
v1_compiler_compile.rs src/v1/compile.dag — serializer arm for the widened RuntimePrimitiveCall
std_algebra.rs, std_nat.rs, v1_compiler_trait_derive_emit.rs arrow-typed fields and one qualified std.types.List reference re-rendered by the arrow-position and qualified-type routes of 05_emit_rust.dag

The instrument (#9664, verbatim)

gunbc compile --source-root dag --source-root src/v2 --entry src/v2/compiler/00_compile.dag --target rust --output-dir /tmp/v2emit
cd /tmp/v2emit && cargo check --message-format short

Over the frozen tree with gunbc=974aafe864f743f6: emit OK, 175 files emitted (the compiler's own count: 174 .rs + Cargo.toml; Cargo.lock is written by cargo check); cargo check errors = 2779 (rustc reaches and completes type checking).

Class table

Pre-typeck classes this PR closes (0 on the fixed point; each has a required-floor witness)

class baseline mechanism
C — qualified call carried the dotted path as decl_name (cannot find value v2/std) 102 04_lookup.dag: decl_name = qualified_last_segment(name) at 4 sites
length — v1_rt::length named a symbol the seed does not define 73 RuntimePrimitiveCall.projected_from; emission falls back to the declaration only for ModeledProjection, never HostRealizedSeam
B — algebra fallback asserted a bridge for a fn-typed record field / unregistered name 65 runtime_bridge = rust_runtime_primitive_has_bridge(name); is_empty template row; callable-field tier ahead of both template lookups, keyed on the receiver's OWN record (952ffa6: the first tier consumed the algebra profile and put 202 errors on the regenerated SEED, caught by the in-cycle build gate)
symbol seams — symbol_lexeme / symbol_intern_lexeme compiled as infinite recursion (silent) 0 (silent) roster rows + v1_rt identity realizations
unrealized self-call seams (resolve_type_node, coproduct_nullary_inhabitants, 3 more) 0 (silent) rust_host_seam_is_unrealized wall; generated refusal body per the seam ruling (a compile_error! cut took 20 more items down and is deleted)
witness carrier rendered an erased identity (UNRESOLVED_CompilerError) 1 rust_witness_carrier_from_type_node declines a CompilerError so the fn return decides
fold init took the Map declaration's formals (rc_empty_map::<K, V>) 4 the init turbofish asks the rendered-formal admission the lambda beside it already uses and defers unbound formals to rustc
lambda param annotated with a spurious generic (FreeMonoid<T>) 1 same rendered-string admission the fold element already uses
zero-param alias rendered with its RHS arguments (E0107 + the E0391 variance cycle — the phase-aborting class) 2 closed_alias_peels_zero_param asked at the expression-type position
arrow return dropped its applied binding (Rc<Medium>, E0107) / generic arrow return rendered its erased inference (Outcome<compile_error!>) 1 / 3 (latent) every arrow position renders through render_rust_fn_sig_type, the renderer the parameter side already used; two intermediate cuts (an unconditioned second renderer, then a measured gate over it) are deleted
qualified type reference never earned its use-line (Determinism) 2 qualified_type_reference_rows: the qualifier is the provider the author named; a line is synthesized only when the registry declares the leaf as a TYPE in that module and the export proof holds; each decision is a census row. First regeneration synthesized use lines for qualified VARIANT heads (v2.std.nat.Succ { .. }, E0603 ×16) — closed by the type gate
service op in a service-free fn (filesystem.read(..).await?: E0425 + E0728) 4 the method arm asks the SAME predicate the signature authority asks (is_typed_service_call_receiver); declined → generated refusal body naming the seam

Member roster reconciliation (by identity). The a5120f1 run and this run both report compiled: 175 files emitted and their emitted rosters are identical file-for-file (diff of the two output trees' file lists, target/ excluded, is empty: 174 .rs + Cargo.toml, plus the Cargo.lock cargo check writes). The 174 in earlier receipts counted src/*.rs only — a counting convention, not a lost member; the typeck population and XL-1's effect-demand denominator are over the same 175.

Type-check population on the fixed point (open; by rustc code)

rustc code count reading
E0308 2671 the Symbol / kernel String / v2.std.text.String identity capture (~2400 sites in both directions, plus its nested forms); a handful of unrelated mismatches (Feature by reference, Coverage<..> vs CoverageDefectAcceptanceKey, Rc<Nat> vs integer)
E0277 34 trait bounds the emitter does not derive (A: Clone on generic params, staging combinators)
E0599 16 methods on generic params without bounds; im::Vector::Empty
E0618 12 a ! where a call was expected (host-refusal bodies used as callables)
E0369 12 arithmetic on Rc<i64>
E0282 9 inference holes at list_head-style calls
E0004 9 non-exhaustive matches after the Symbol capture
E0061 6 arity mismatches (v2.lens.coverage, enforcement_vocab)
E0310 / E0271 / E0631 / E0560 / E0533 / E0223 8 singletons
E0425 / E0603 / E0121 / E0107 / E0391 / E0728 0 the classes this PR closes
total 2779

Corpus probes on the same emitted tree: rc_empty_map::<K, V> 0 · CompileLensOutcome< 0 · Rc<Medium>> 0 · pub use crate::v2_std_nat::Succ; 0 · Rc<Outcome<_>>> 0 · use crate::std_determinism::{Determinism}; in v2_std_determinism.rs 1 · UNRESOLVED_CompilerError 1 — that one occurrence is prose inside a data-string annotation in v2_compiler_materialization_carriers.rs, not a rendered type (the probe is over-broad there).

The dominant class is a modeling gap, not a Rust spelling, and this PR does not touch it (ruling: it is its own model-first lane). Three names answer one question: v2.std.node type Symbol (opaque, kernel-named, projected by the seed as pub type Symbol = String), the kernel String, and v2.std.text type String (= Rc<Vec<i64>>, code points). The emitter renders a Symbol-typed position as the bare token String; in every module that import v2.std.text { String } that token is captured — v2.std.grammar, v2.std.compilers.target_model, v2.extdeps.languages.dag and their callers — so fn f(identity: Symbol) expects Rc<Vector<i64>> while callers pass host String (E0308 ×~2400, both directions). Compounding fact: Symbol in those modules is unimported and resolves only through the whole-corpus union pick (scoped to its import closure the same module refuses unresolved type 'Symbol'). The Symbol lane's renderer change (resolved DeclarationRef → representation → fully-qualified spelling, no bare-name fallback) is a joint seam with 05_emit_rust.dag; XL-0B resumes the remaining tail on top of it.

Witnesses (dag/test/claim/emitted_call_target_realization_witness_test.dag, 24 rows, required floor)

Executed over the frozen bytes with gunbc=8eb02a1c36c8cd4d (head 466811e, same mirror): 24/24 PASS, footer 24 witness(es), verdict count equals footer.

  • w_qualified_call_emits_only_the_declaration_last_segment — PASS
  • w_unbridged_modeled_primitive_emits_its_declaration — PASS
  • w_bridged_modeled_primitive_still_lowers_to_the_bridge — PASS
  • w_callable_record_field_lowers_as_a_field_not_a_bridge — PASS
  • w_registered_bridge_method_still_reaches_the_bridge — PASS
  • w_symbol_lexeme_reaches_its_host_realization_not_its_self_call — PASS
  • w_unrealized_self_call_seam_refuses_instead_of_emitting_recursion — PASS
  • w_unrealized_seam_refusal_preserves_the_declaration_signature — PASS
  • w_ordinary_recursion_is_not_read_as_a_host_seam — PASS
  • w_rostered_seam_resolves_realization_through_its_primitive_not_its_decl_name — PASS
  • w_realized_seam_keeps_its_declaration_and_delegates_to_the_bridge — PASS
  • w_is_empty_lowers_to_its_rust_realization_not_a_refusal — PASS
  • w_callable_field_named_is_empty_is_not_captured_by_the_target_template — PASS
  • w_callable_field_named_count_is_not_captured_by_the_target_template — PASS
  • w_map_receiver_operation_is_not_read_as_a_callable_field — PASS
  • w_witness_carrier_falls_back_to_the_fn_return_when_the_value_identity_is_erased — PASS
  • w_fold_empty_map_init_renders_the_resolved_accumulator_not_the_declaration_formals — PASS
  • w_lambda_param_annotation_declines_a_spurious_generic — PASS
  • w_zero_param_alias_in_an_arrow_return_renders_without_its_rhs_arguments — PASS
  • w_arrow_return_type_keeps_its_applied_binding — PASS
  • w_qualified_type_reference_earns_the_leaf_use_line — PASS
  • w_qualified_variant_head_earns_no_type_use_line — PASS
  • w_generic_arrow_return_renders_the_fn_scope_generic — PASS
  • w_service_op_in_a_service_free_fn_refuses_instead_of_awaiting_an_unbound_binding — PASS

Disposition grain (src/v1/tests/claim/reference_derived_disposition_census_witness_test.dag, 14 rows incl. a_known_variant_spelling_in_a_type_position_takes_the_registry_arm): 14/14 PASS on gunbc=974aafe864f743f6.

Falsifiers (mirror mutations over the frozen bytes; build-only, no regen; byte restore proven after)

Instrument: the emitted bytes for the classes this PR closes — must_contain / must_not_contain on the witness probes and occurrence counts on the emitted closure — never the cargo error count. Each mutation is a regex over the regenerated mirror that must match exactly its site (a miss is reported NON-EVENT, never green). Bar: the reddened set includes the named discriminator, unrelated controls stay green, byte restore reproduces the baseline verdict population.

Run on srv1 over the frozen mirror (/tmp/xl0post.log, /tmp/xl0post2.log): each row rebuilds claim_batch + gunbc from the mutated mirror, runs the 24 harness rows (and, in the follow-up pass, the 14 disposition-grain rows), and — for the closure-observable classes — re-emits the 00_compile closure and counts the class's token. Baseline probes on the unmutated tree: rc_empty_map::<K, V> 0 · use crate::std_determinism::{Determinism}; 1 · CompileLensOutcome< 0 · Rc<Medium>> 0 · pub use crate::v2_std_nat::Succ; 0 · Rc<Outcome<_>>> 0. Lean standard (one mutation per mechanism): m03 dropped (documented non-event: the callable-field tier answers every receiver the algebra fallback used to), m06 dropped (a second mutation of class C's site), m12 dropped (a second mutation of the qualified route).

mutation mechanism reddened (everything else green) verdict
m01 symbol projection row removed symbol seams w_symbol_lexeme_reaches_its_host_realization_not_its_self_call, w_realized_seam_keeps_its_declaration_and_delegates_to_the_bridge discriminating
m02 dotted decl_name restored class C w_qualified_call_emits_only_the_declaration_last_segment discriminating
m04 length provenance removed length w_unbridged_modeled_primitive_emits_its_declaration discriminating
m05 seam wall removed unrealized self-call seams w_unrealized_self_call_seam_refuses_instead_of_emitting_recursion, w_unrealized_seam_refusal_preserves_the_declaration_signature discriminating
m07 callable-field candidate sweep restored class B tier w_map_receiver_operation_is_not_read_as_a_callable_field discriminating
m08 witness carrier admits a CompilerError witness carrier w_witness_carrier_falls_back_to_the_fn_return_when_the_value_identity_is_erased discriminating
m09 fold-init formal admission removed fold init no harness row (class observable only in the closure); corpus rc_empty_map::<K, V> 0 → 2 discriminating (closure)
m10 lambda spurious-generic admission removed lambda annotation w_lambda_param_annotation_declines_a_spurious_generic discriminating
m11 arrow arm removed arrow positions w_zero_param_alias_in_an_arrow_return_renders_without_its_rhs_arguments, w_arrow_return_type_keeps_its_applied_binding, w_generic_arrow_return_renders_the_fn_scope_generic; corpus CompileLensOutcome< 0 → 1, Rc<Medium>> 0 → 1, UNRESOLVED_CompilerError 1 → 4 discriminating
m13 service refusal removed service op w_service_op_in_a_service_free_fn_refuses_instead_of_awaiting_an_unbound_binding discriminating
m14 zero-param alias arm at the expression-type position removed — nothing, on either instrument (24/24, 14/14, CompileLensOutcome< stays 0) non-event, stated: every arrow position now renders through render_rust_fn_sig_type, which carries its own closed_alias_peels_zero_param arm, so the expression-type-position arm no longer decides this class — m11 does (CompileLensOutcome< 0 → 1, w_zero_param_alias_in_an_arrow_return_renders_without_its_rhs_arguments red). The now-redundant arm is XL-0B's first deletion (§4b dissolution on climb)
m15 arrow positions through the second renderer (render_rust_type) — nothing, on either instrument non-event, stated: with the fn generic scope threaded through the applied-binding hop (m18), the second renderer no longer reproduces the defect; the single-renderer change is a §2 consolidation, and the arrow class's repair is m11 + m18
m16 type-position exemption removed Determinism (bare-name disposition) corpus use crate::std_determinism::{Determinism}; 1 → 0; harness row unchanged (declared positive control); disposition-grain rows stay green under the MIRROR mutation because claim_batch runs src/v1/tests/claim through the interpreter over the .dag authority — so their red was taken at the .dag: reverting the exemption in 05_emit_rust.dag (1 site) reddens exactly a_known_variant_spelling_in_a_type_position_takes_the_registry_arm (13 controls green), restore 14/14 (/tmp/xl0unitmut.log) discriminating (closure + unit grain)
m17 qualified-route registry type gate removed — nothing, on either instrument non-event, stated: a variant head has no registry row, so the route declines it at the registry-absent arm; the gate decides only OtherItem rows (std.types.Map). Replaced by m19
m18 fn generic scope dropped at the applied-binding hop generic arrow return w_generic_arrow_return_renders_the_fn_scope_generic; corpus Rc<Outcome<_>>> 0 → 3 discriminating
m19 qualified route admits a registry-absent leaf as exported E0603 variant use-lines w_qualified_variant_head_earns_no_type_use_line; corpus pub use crate::v2_std_nat::Succ; 0 → 2 (the probe counts the Succ line only; the class was 16 lines over several variants) discriminating
clean control — 24/24 PASS; corpus probes identical to baseline byte restore reproduces b1a0409ce9fc79d4

The fold-K,V class is only observable in the full closure (the harness pool resolves Map to the kernel container), so its falsifier is read off the closure occurrence count.

rust-unit-tests

cargo test --release -p v1-compiler --lib over the frozen bytes: 535 passed, 0 failed, 140 ignored (gunbc=974aafe864f743f6 tree). The d805243/952ffa6 red on function_value_named_application_controls_witness is classified GeneratedMirrorIncoherent: the merge commit deliberately carried the two mirrors the generated-artifact merge driver refused, so CI compiled an older infer than the merged authority; the same test passes on the regenerated bytes with no change to its subject. Every other red on this PR's history is a required-witnesses-build regen-drift red on an intermediate authority commit, the expected state before its regeneration commit. The freeze head 49482b0 itself is one: its build lane reports FAILED PHASE regen — generated surface drift: v1_compiler_emit_rust.rs, v1_tests_claim_reference_derived_disposition_census_witness_test.rs, exactly the two paths round 1 of the transaction regenerated — and rust-unit-tests passed on it. CI on the final head is the receipt that counts.

Seam census (for XL-1's HostSeamStanding join)

Whole-body self-call seams on the closure: 14 by identity (reconciled with XL-1). Realized 9 / unrealized 5 (v2.std.node.resolve_type_node, v2.std.node.coproduct_nullary_inhabitants and 3 more, all carrying the panic refusal body). Service-op seams: v2.compiler.source_authority::source_ref_for_observed_storage_path and ::dag_source_read_result_from_ref, op Filesystem.Read, unrealized (refusal body); neither is reached from the entry compile.

Non-goals

Host effect execution / transports (XL-1); the Symbol / String identity (its own lane); bootstrap promotion of the emitted crate; CLI or CI migration; product rewiring; broad v1 cleanup. No line was added to v1_rt.rs, v1_interpreter.rs or cli_run.rs by hand — the two v1_rt.rs functions are emitted from runtime_rust.dag.

🤖 Generated with Claude Code

https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU

gunbc-ci-auto-heal and others added 10 commits August 29, 2026 04:36
…nt, and a primitive with no realization refuses instead of inventing one

Two roots behind 175 of the 260 rustc errors on the emitted v2 compiler
closure (issue #9664, milestones 1 and 2):

- 102 x E0425: the four DeclaredCallableIdentity constructions in
  v1.compiler.infer_lookup took decl_name from the AUTHORED spelling, so a
  qualified call carried the whole dotted path as the declaration name and
  emission rendered crate::v2_std_grammar::v2.std.grammar.f(..).

- 73 x E0425: v2.std.algebra length is a ModeledProjection of the `length`
  primitive and rt_function_registry has no `length` row, so emission took
  rust_runtime_bridge_name's identity arm and wrote v1_rt::length -- a symbol
  the seed does not define. A primitive's identity and its per-target
  realization are two facts; CallTargetIdentity carried only the first, so
  every emitter had to ASSUME a bridge exists.

RuntimePrimitiveCall now carries projected_from, the declaration the roster
projected it from, and emit_rust routes to the bridge only when its own
registry holds the primitive, falls back to the declaration otherwise, and
refuses when neither exists. DeclaredCallableIdentity moves to v1.std.core so
the target type can carry it without forking the pair.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU
…ot checked

tier0 method resolution resolves an ordinary fn-typed RECORD FIELD through
lookup_field_in_product, so `algebra.step(..)` arrives as AlgebraMethodSemantics
carrying the field node as its method_def. The fallback at the end of that arm
hardcoded runtime_bridge: true, which emitted `v1_rt::step` -- and made
emit_rust_generic_method_call's own callable-field arm, guarded on
runtime_bridge == false, unreachable for the exact receiver it was written for.
65 E0425s on the emitted v2 compiler closure (member, apply, is_empty, step,
init, allocate_literal, ...) were that one literal.

It now passes the realization question keyed on the same registry as the
plain-call seam, so a real bridge method still lowers to a bridge, a callable
field lowers as a field, and a name that is neither reaches the existing loud
refusal rather than a fabricated symbol.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU
…y is a self-call, so falling back to it would emit a nonterminating function

The declaration fallback is sound only where the declaration's body is real
code. HostRealizedSeam means the body IS a self-call, so emitting it compiles
and then loops forever -- silent wrongness, strictly worse than the unresolved
symbol it would have replaced. A seam whose target has no realization has no
honest lowering, so it carries nothing and reaches emission's refusal.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU
…lared to be host seams

v2.std.compilers.lexing symbol_lexeme and symbol_intern_lexeme have self-call
bodies -- the HostRealizedSeam shape exactly -- and the interpreter has carried
real arms for both (v4_bridge.symbol_lexeme, v4_bridge.symbol_intern_lexeme).
With no projection roster row the resolver saw ordinary declarations, so Rust
emission emitted the declaration, and

    pub fn symbol_lexeme(sym: String) -> String { symbol_lexeme(sym) }

COMPILES. The emitted closure carried two functions that type-check, pass every
gate we own, and diverge from the interpreter by not terminating. Unlike the
sibling seams (decl_facts and friends, which at least refuse loudly as
unresolved v1_rt symbols) nothing anywhere reported this one -- it is absent
from the E0425 census precisely because it is silent.

extdeps.languages.rust.types already declares Symbol's target type as String,
so on this target both bridges are the identity. That is a realization of the
declared row, not a second opinion about it.

Residue named, not closed: a self-call body is a DECIDABLE structural marker of
a host seam, so the compiler could refuse an unrealized one rather than emit it.
It does not yet; that check is the class's next-rung trigger.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU
…round 2)

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU
…, with boundary controls

Six rows over the three emitter defects plus the two symbol bridges. Each
class's positive and negative assertion differ only in the fact the repair
added, so no single edit satisfies both directions, and each repair carries a
boundary control that would go red had it over-reached the other way (empty_map
for the registry gate, a registered bridge method for the class-B gate).

The symbol-bridge row is deliberately not an error-count assertion: that class
COMPILED throughout the defect and diverged by not terminating, so a row
asserting 'no error' would have been green the whole time.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU
…never reaches the seam under repair

count is answered by rust_simple_method_specs before the algebra fallback, so
the row would have gone red while executing none of the code the repair
touched. trim is in rt_function_registry and has no template, so it is one of
the few names that actually reaches that fallback.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU
The module index refused the file outright, so none of the six witnesses were
discovered. .dag item declarations carry no terminator.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU
…mitting compiling recursion

A whole-body self-call is the decidable structural marker of a host seam. In the
interpreter the shape is safe -- reaching it recurses to the evaluation-budget
refusal -- but emitted to Rust the same shape COMPILES and returns to no caller.
Nothing reported it: not the module index, not the compile-clean gate, not cargo
check. That is why the two symbol bridges were invisible until someone read the
emitted bytes.

emit_fn_def now asks the realization registry -- the same authority the call
sites ask, so the two cannot drift -- and suppresses the declaration when the
seam is realized, refuses with a located message when it is not. Suppression
rather than delegation is deliberate: a forwarding body would make this seam
reconstruct signatures in target types, which is the cementing the existing
suppressed-seam precedent avoids, and a realized primitive's calls all route to
the bridge anyway.

The predicate is whole-body identity, not 'contains a self-call'. Ordinary
recursion has a match, an if or a let between the head and the call, so it never
matches; expr_has_self_call walks children and would have refused most of the
compiler. Both directions carry a fixture.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU
…, not the declaration name

Measured, not predicted: the wall refused six seams in the emitted closure and
one of them -- v2.std.collection empty_map_primitive_delegate -- is realized.
Its roster row names the empty_map primitive, whose bridge is rc_empty_map, but
rt_function_registry holds 'empty_map' and the wall looked up
'empty_map_primitive_delegate'. A declaration's name and the primitive it
realizes are two facts; the roster is the authority that joins them, and the
declaration name is only the fallback for a seam nobody has rostered.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU
@gunbai-bot

gunbai-bot Bot commented Aug 29, 2026

Copy link
Copy Markdown
Contributor Author

Specimen hand-off from XL-1 (#9669), returned rather than fixed locally — this is call-target identity and Rust lowering, which is your lane by the ownership rule.

Measured by emitting three closures at 6447dd4564 and reading the emitted Rust. The HostRealizedSeam population splits into two shapes, and one of them is silent.

1. A rostered HostRealizedSeam declaration lowers to a compiling infinite loop. Not the f(x) self-call shape that was predicted — the emitter lowers the self-call to a tail-loop:

pub fn decl_facts(mut pool_roots: Rc<Vec<String>>) -> Rc<Vec<Rc<DeclFact>>> {
    loop { { continue; } }
}

It type-checks, has no return path rustc objects to, produces no diagnostic, and never returns. Same shape for export_signature_facts and data_decl_type_facts (v2_std_decl_index.rs, from --entry src/v2/std/decl_index.dag). concept_decl_facts / concept_decl_facts_live had 0 sites in these closures.

2. Every unrostered builtin already lowers as an rt bridge call, to a symbol v1_rt does not define — so these are loud (E0425), not silent:

emitted call emitted file :: enclosing fn
v1_rt::module_declaration_facts v2_lens_module_graph.rs::module_declaration_facts_live
v1_rt::import_resolution_facts v2_lens_module_graph.rs::import_resolution_facts_live
v1_rt::reference_resolution_facts v2_lens_module_graph.rs::reference_derived_import_resolution_facts_live
v1_rt::dependency_resolution_facts v2_lens_module_graph.rs::dependency_resolution_facts_live
v1_rt::layer_import_facts v2_std_layer.rs::layer_import_facts_live
v1_rt::filesystem_read v2_lens_reference_deps.rs::reference_file_census, v2_lens_enforcement_grammar_coverage.rs::grammar_coverage_ingest_path
v1_rt::decl_facts v2_std_decl_index.rs::decl_facts_count, v2_std_decl_index.rs::decl_facts_fn_item_count

The split is not "rostered vs unrostered" — it is declaration lowering vs call-site lowering, and decl_facts exhibits both at once: the nonterminating loop { continue; } declaration and two v1_rt::decl_facts(...) call sites.

The consequence for a census: shape 1 is invisible to any error list, so absence from an E0425 population is not evidence a seam is closed. Worth checking each seam for the tail-loop shape directly.

Two notes on scope, so this does not read as a request to build the effect substrate:

  • XL-1 is not asking for these to be realized. Measured on the emitted compiler closure, the compile path reaches none of these call sites — they are import occupancy, reached only from lens/census/test consumers. Their compile-path demand is zero, so the fix here is lowering, not a transport.
  • The _live wrappers are exactly the swappable producer seam dependency_edge_source_migration_note designates, so preserving the typed seam is the right move; XL-1 owns what executes behind it.

Reproduce: gunbc compile --source-root dag --source-root src/v2 --entry src/v2/std/decl_index.dag --output-dir <dir> and grep the emitted tree for pub fn decl_facts and v1_rt::.

gunbc-ci-auto-heal and others added 9 commits August 29, 2026 08:46
…ession created 10 dangling imports

Measured on the emitted closure with the wall finally in the mirror: removing a
realized seam's item left 10 unresolved imports (E0432) for symbol_lexeme,
symbol_intern_lexeme and resolve_type_node. Other modules import these
declarations; the suppression created that breakage rather than finding it.

And the reasoning that made suppression look safe is what makes it unnecessary.
A realized seam's body IS a call to itself, and resolution already routes that
call through the roster to the bridge -- so ordinary emission writes
v1_rt::symbol_lexeme(sym) as the body without help. The wall's whole job is the
UNREALIZED arm.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU
…: rustc's denominator is larger than the demand denominator

compile_error! fails the WHOLE crate, and that form silently assumes every seam
it refuses is one somebody calls. It is not. rustc type-checks the entire
emitted crate including declarations imported but never invoked, so the refusal
denominator is strictly larger than the entry-reachable execution closure --
five unreachable seams took the crate down.

The refusal is now a panic body with the declaration's real signature: dependent
modules resolve, the crate compiles, and only an actual invocation fails loudly.
That moves the refusal from the crate to the one declaration that earned it, and
leaves reachability to a separate instrument. An entry-rooted pruner can replace
the body later without revisiting this.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU
…his change

DETERMINISM DENOMINATOR (9 reach_witness rows red, including
determinism_denominator_is_closed_on_declared_primitives, whose entire job is to
notice this). v2.lens.determinism closes its denominator over
primitive_declared_definitions, so adding two canonical names without traversal
facts made the closure false. Both bridges are scalar -- symbol_lexeme maps one
Symbol to its text and symbol_intern_lexeme is its inverse -- so there is no
collection to walk and OrderFreeResult is the honest arm. HostUnspecifiedOrder
would claim a real traversal whose order the host does not pin, fabricating a
leak the primitive cannot have.

NAMESPACE WAVE ADMISSION (6 unadjudicated deltas). Four are TargetChanged for
DeclaredCallableIdentity moving v1.compiler.infer_sigs -> v1.std.core, which is
what lets CallTargetIdentity carry the declaration a runtime target was
projected from. infer_sigs imports v1.std.core, so the type could not stay put
without a cycle. Four enumerated rows, one per binding site; the two membership
deltas auto-admit as ExplicitlyEvaluatedZeroDelta. Dissolve-on: this PR merging,
by the same trigger the three prior shrinks record.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU
…er than the corpus

The row FAILED while the mechanism was green. The probe used the qualified
spelling without importing v2.std.collection, which resolves against the real
4261-module corpus but not against compile_dag_rust_emit_check's 2973-module
witness pool. Measured both ways: emitted against the corpus the same probe
produces crate::v2_std_collection::map_get(m.clone(), "key".to_string()),
exactly what the row asserts.

The import restores module presence and does not answer the call -- decl_name
comes from the authored spelling at the call site regardless of imports -- so
the negative assertion still discriminates. Falsifier 2 is what proves that
rather than argues it.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU
…n it never had

Before the class-B change, xs |> is_empty emitted v1_rt::is_empty, a symbol the
seed does not define: 5 x E0425. After it, the same 5 sites became typed
refusals -- correct in kind, still 5 errors. The class-B repair made the gap
visible; it did not close it.

is_empty is an algebra template over FreeMonoid whose Rust realization is
Vec::is_empty, exactly as count's is Vec::len, so the fix is one row in
rust_simple_method_specs beside count. Nothing in 05_emit_rust learns a new
name: realization is a target fact and lives in the target's registry.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU
…s B survived one layer up

The requested is_empty negative control found a live hole rather than confirming
a safe one. Both rust_method_templates lookups are keyed on the bare method
spelling with no receiver check, so a fn-typed record field named is_empty was
captured by the target template and emitted as recv.is_empty() instead of
(recv.is_empty)(..). The class-B repair fixed the algebra FALLBACK and left the
two tables sitting in front of it.

The hole is not new and is not specific to is_empty: count, first, join, split,
take, skip, last, chars and enumerate have carried it for as long as they have
had templates. Adding is_empty made it urgent by putting the spelling most
likely to name a predicate field in front of that table.

One helper, consulted at the top of both arms before every name-keyed special
case, so the two cannot drift. Two controls: the new spelling and a pre-existing
one.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU
v1.compiler.infer_sigs used to DECLARE DeclaredCallableIdentity, so its own two
construction sites resolved locally and produced no delta. Now that the
declaration lives in v1.std.core and infer_sigs imports it, those sites rebind
exactly like the consumers in infer_lookup. An enumeration error on my part, not
a second transition: same subject, same trigger, same dissolve.

Floor is now green on this branch (passed=2754 failed=0) -- the OrderFreeResult
traversal facts closed all nine determinism rows.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU
# Conflicts:
#	src/v1/stage0/src/v1_compiler_emit_rust.rs
#	src/v1/stage0/src/v1_compiler_infer.rs
…domain, not the receiver's: 202 refusals on the first compile of the converged seed

rust_receiver_has_callable_method_field asked rust_record_field_needs_fn_rc,
which sweeps rust_struct_field_lookup_candidates -- and that list deliberately
widens a receiver's name to its container template algebra. An algebra declares
its operations as arrow-typed members, so under that widening every Map receiver
"has a callable field" named map_keys, map_values, lookup or get, and the tier
captured the very bridge calls it sits in front of.

Measured at the first compile of the round-3 converged mirror: 202 rustc
refusals, one class -- 164 E0609 (no field `map_keys` on
Rc<im::HashMap<String, Rc<ItemInfo>>> and friends), 48 E0282, 4 E0615 on `get`.
It is the same defect the tier was built to close, one level up: a name-keyed
lookup consuming an identity domain that is not its own.

The predicate now consults only the receiver's own declared record.
w_map_receiver_operation_is_not_read_as_a_callable_field is the discriminating
red: restore the candidate sweep and its must_not_contain clause fires.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU
gunbc-ci-auto-heal and others added 4 commits August 29, 2026 13:56
… point at round 3, six paths, each explained by an authority change

Convergence transaction on srv1 (/tmp/xl0c.sh -> /tmp/xl0g.log), on
952ffa6 = main b726547 merged with the branch. Criterion is BYTE equality
(sha256 over the whole candidate tree vs the whole installed tree), never
first_generation_equal and never the changed-path list; the full workspace
is rebuilt inside every round so a non-compiling mirror stops the line.

  round 1  cand e212fe74 inst 6f55cf3e  installed, compiles
  round 2  cand 932b0543 inst e212fe74  drift = v1_rt.rs only (the two-hop:
           v1_rt.rs is rendered by the previously compiled rt_hash_ops)
  round 3  cand 932b0543 inst 932b0543  BYTE FIXED POINT -- produced by a
           compiler rebuilt from the round-2 installed tree

Changed paths and their authority:
  extdeps_languages_rust_emit.rs  <- rt_function_registry / rust_simple_method_specs rows
  std_primitive_projection.rs     <- symbol_lexeme / symbol_intern_lexeme roster rows
  v1_compiler_emit_rust.rs        <- 05_emit_rust.dag (seam wall, callable-field tier, class B/C)
  v1_compiler_infer.rs            <- 04_infer.dag projected_from on RuntimePrimitiveCall
  v1_compiler_runtime_rust.rs     <- runtime_rust.dag symbol bridges
  v1_rt.rs                        <- same, one hop later

On these bytes: function_value_named_application_controls_witness PASSES
(the d805243 / 952ffa6 rust-unit-tests red was the merge-driver-refused
stale v1_compiler_infer.rs, not a semantic regression); emit 175 files;
cargo check 15 errors: 9 E0425 (filesystem 2, V 2, K 2, Determinism 2, T 1),
2 E0728, 2 E0107, 1 E0391, 1 UNRESOLVED_CompilerError. No hand edit to any
generated file.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU
gunbc-ci-auto-heal added 4 commits August 29, 2026 14:51
…a4e965ddb built from the committed mirror): v1_compiler_emit_rust.rs regenerated; candidate patch sha 05ce734c52890571
… installed ce959e40604ffdd5): std_algebra.rs, std_nat.rs -- arrow returns now render through the Rust renderer (Rc<Vec<K>> for List<K>, Nat preserved); candidate patch sha b5b409aeebbeb6c4
…fect shapes: the unconditioned route emitted 2790 refusals where 15 stood; fix the arrow probe's variant spelling
…bda's admission; F: a qualified type reference earns its use-line from the qualifier under export proof; both earlier cuts were measured non-events and are deleted
gunbc-ci-auto-heal and others added 5 commits August 29, 2026 17:16
…at round 3, three paths, each explained by an authority change

srv1 (/tmp/xl0e.sh -> /tmp/xl0j.log), criterion = every regen-population
file byte-equal to installed; full workspace rebuilt as the gate each round.

  round 1  gunbc=1dc61ba198c6750b from installed 0479b0df9fc5598e  -> v1_compiler_emit_rust.rs
  round 2  gunbc=909aa212f353bd03 from installed 8ebedc7445fadbaa  -> std_algebra.rs, v1_compiler_trait_derive_emit.rs
  round 3  gunbc=0d0cd70ec5b20db9 from installed 8713cb43f8ad848c  -> <none>  BYTE FIXED POINT

  v1_compiler_emit_rust.rs        <- 05_emit_rust.dag (gated arrow position, init turbofish admission, qualified-type use-lines)
  std_algebra.rs                  <- the gated arrow route restores the pre-e9900e2 spelling of the two arrow-typed fields
  v1_compiler_trait_derive_emit.rs <- one use-line synthesized for a qualified std.types.List reference under export proof

Final installed tree 8713cb43f8ad848c. No hand edit to any generated file.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU
…e variant arm; the qualified route synthesizes use-lines only for types the emitted source names

Four regressions the 0773184 fixed point put on the closure, each with its discriminating row:

- E0603 x16: the qualified-type route synthesized `pub use crate::v2_std_nat::Succ;` for every
  `v2.std.nat.Succ { prev: .. }` record literal. A qualified name reaches the surface walk in the
  same dotted spelling whether it is a type or a variant head; the route now asks the registry
  whether the leaf is a TYPE declared in the named qualifier, records each decision as a census
  row, and considers only leaves the emitted source actually names (it had also synthesized an
  unused `DeclarationRef` import from a variant payload).
  w_qualified_variant_head_earns_no_type_use_line.

- `Outcome<compile_error!("UNRESOLVED_CompilerError")>` x3 and `Rc<Medium>` E0107: two cuts had
  each introduced a second per-position renderer for arrow types beside the one fn parameters use.
  An arrow's return is not a different kind of type from its parameter: both positions now render
  through render_rust_fn_sig_type, and render_rust_type_with_applied_binding -- which rebuilt its
  EmitGraphInfo with an empty generic scope, so a fn-scope `C` rendered `_` (E0121) -- carries the
  fn's generic names through that hop. The measured gate over the second renderer is deleted.
  w_generic_arrow_return_renders_the_fn_scope_generic; w_arrow_return_type_keeps_its_applied_binding
  (its fixture was an invalid program: Accepted lacked `diagnostics`).

- v2.std.determinism E0425 x2: traced to the bare-name disposition, not the qualified route --
  `Determinism` is a type in std.determinism and a variant of v2.lens.registry LensIdV0, and
  is_known_variant is corpus-wide by spelling, so a TYPE-position reference was delegated to an enum
  it never named. A name in one of the module's type positions never takes the variant arm.
  a_known_variant_spelling_in_a_type_position_takes_the_registry_arm (red by construction on the
  old arm); the harness row is a positive control and says so, because the witness harness refuses
  any pool carrying the colliding variant with NoSuchVariable.

Verified on a test binary built from the self-emitted emitter (not a regeneration): witnesses
23/24 -> 24/24 after the harness row was reshaped; closure instrument 2799 -> 2779. The regeneration
that binds these to the mirror follows as its own commit after the freeze merge.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU
…at round 3, three paths, each explained by an authority change

srv1 (/tmp/xl0e2.sh -> /tmp/xl0j2.log, launched 2026-08-29T19:52:56Z), criterion = every
regen-population file byte-equal to installed; the full workspace rebuilt as the gate each round.

  round 1  gunbc=14967ca810cb6609 from installed db46176cc5cf5861  -> v1_compiler_emit_rust.rs, v1_tests_claim_reference_derived_disposition_census_witness_test.rs
  round 2  gunbc=5378a516528a6e0c from installed efa440bc86734f53  -> v1_compiler_trait_derive_emit.rs
  round 3  gunbc=974aafe864f743f6 from installed b1a0409ce9fc79d4  -> <none>  BYTE FIXED POINT

  v1_compiler_emit_rust.rs                                          <- 05_emit_rust.dag (arrow positions via the fn-signature renderer, generic scope through the applied-binding hop, type-position exemption, qualified rows with the registry type gate and token filter)
  v1_tests_claim_reference_derived_disposition_census_witness_test.rs <- its .dag (in_type_position at 5 callers + the type-position control)
  v1_compiler_trait_derive_emit.rs                                  <- retracts the unused `pub use crate::std_types::List;` the earlier qualified route synthesized (token filter)

Final installed tree b1a0409ce9fc79d4; merged tree 89c55a0 at the
freeze; main parent 5e80671. No hand edit to any generated file.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU
…provider the harness pool can carry

Post-freeze, fixture-only (dag/test/claim is not a regen-population path; a no-drift regen run on
this head is recorded in the PR). Two harness facts, both measured on the fixed-point artifact
gunbc=974aafe864f743f6: a `{Determinism}` inside a .dag string literal is read as an interpolation
of that name (the row failed in the interpreter before any compile ran), and the harness pool is the
probe's DECLARED import closure, so a provider referenced only by a dotted name is absent -- and
std.determinism cannot enter it because its own body references std.perturbation the same way. The
row now uses std.decl_ref with a sibling import and says plainly that it is a positive control; the
class's discriminating red stays at the disposition grain
(a_known_variant_spelling_in_a_type_position_takes_the_registry_arm) and in the closure count.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU
@gunbai-bot gunbai-bot Bot changed the title v2 on emitted rust XL-0A: the emitted v2 compiler closure reaches rustc type checking (2779 typeck errors remain, one identity class dominant) Aug 30, 2026
@gunbai-bot
gunbai-bot Bot marked this pull request as ready for review August 30, 2026 01:05
@gunbai-bot
gunbai-bot Bot merged commit ecdeb49 into main Aug 30, 2026
4 checks passed
@gunbai-bot
gunbai-bot Bot deleted the session/bold-carp-449 branch August 30, 2026 01:18
gunbai-bot Bot pushed a commit that referenced this pull request Aug 30, 2026
…ix rows by their fired trigger

Both sides authored NAMESPACE_TRANSITION_ADMISSIONS rows: this branch's two
TargetChanged rows for the RequiredCiLane move, main's six for the
DeclaredCallableIdentity hoist (#9665). The resolution unions the rosters —
and then removes the six immediately, because #9665 is merged: the merge base
and head of any run from here both carry the hoist, no run can produce those
deltas, and stale admissions refuse every PR. Removed by their own DISSOLVE-ON
trigger, recorded as the fourth shrink. This branch's two rows still match
live deltas (main lacks the phase roster) and stay until #9698 merges.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GpYEk9gSYmMkwL1489D79U
gunbai-bot Bot added a commit that referenced this pull request Aug 30, 2026
…dissolved on #9665 merging (#9705)

Every pull_request build now has ecdeb49 (or later) as its base, so base and merge
head both carry the hoist, no run can produce those six deltas, and the rows report
stale -- refusing every open PR (measured on #9689 @ bfd9524: 0 unadjudicated,
6 stale). Removed by their own dissolve-on trigger; the roster is empty and empty is
not permissive.


Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
gunbai-bot Bot pushed a commit that referenced this pull request Aug 30, 2026
…red record and this branch's two live rows

Both sides removed #9665's six stale admission rows — this branch in its
previous merge commit, main in #9705 with the measured receipt. The resolution
keeps main's richer shrink record verbatim and re-seats this branch's two
RequiredCiLane rows, which still match live deltas until #9698 merges.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GpYEk9gSYmMkwL1489D79U
gunbai-bot Bot pushed a commit that referenced this pull request Aug 30, 2026
…are String capture (#9689)

* Symbol identity: three names, one authority -- exact declaration-keyed Rust bindings with fully qualified spellings; the bare Symbol checkpoint row deleted

The first self-host typeck run (XL-0, #9665 freeze) reported 2799 refusals, ~2400 of them one defect: v2.std.node `type Symbol` (opaque) was projected by the bare-name rust_type_checkpoints row to the bare token `String`, and every module also importing v2.std.text { String } (a structural FreeMonoid<Char>) captured that token, so `fn f(identity: Symbol)` expected Rc<im::Vector<i64>> while callers passed the host string. Two independent faults in one row: keyed on a spelling, and carrying a spelling a use-line can shadow.

Model (DESIGN section 2/3, model before implement):
- std.target_representation: SourceTypeTargetBinding<R> (DeclarationRef -> representation, corpus-owned), RepresentationSpelling<R> (representation -> qualified reference/grounding spelling, target-owned), ExactBindingResolution (Resolved | Absent | Ambiguous | SourceIdentityUnavailable; no bare-name fallback), CheckpointRowDisposition (MigratedToExactBinding | ProvenUniqueKernelBinding | StillBareNameDebt).
- extdeps.languages.rust.representation: RustRepresentation and its realizations, fully qualified (std::string::String, std::vec::Vec<u8>, ...); RustSymbolNewtype / RustInternedSymbol representable but unrealized, so a binding to them refuses.
- gunbc.rust_source_type_bindings: the exact rows (v2.std.node Symbol -> RustStdString, plus every declaration the bare table answered for), a verdict on every bare row, and the capture acceptance roster by declarer identity (instrument: the freeze's emit + cargo check).
- std.symbol_semantics + gunbc.symbol_identity_census: consumer census at exact identity; decision LexemeBackedNominal (equality/order/hash/serialization by lexeme, no intern table, bijective identity seams); Rust representation std::string::String, with struct Symbol(std::string::String) the named next rung, triggered by the .dag checker distinguishing Symbol from String (the erasure is exploited at the source today: content_hash_atom(value: NonEmptyStr) receives Symbols with v1.compiler.types' blessing, so a newtype would refuse Accepted programs).
- v1.compiler.coercion: rust_lookup_exact_binding / rust_exact_realization_decision (the exact path, composing with std.reference_realization), and type_realization_decision refuses a Migrated name that reaches the spelling-keyed arm without a DeclarationRef. The bare Symbol row is deleted; the kernel `^x` literal never needed it (typed string_type, suffix from the String row).

Witnesses (24, all executing on the remote corpus): exact resolution, another-module Symbol receives no binding, missing identity refuses, ambiguity refuses, spellings never the bare token, every bare row carries a verdict and migrated names are absent from the table (control: restoring the row reds exactly those two), decision coherence, round trip and Eq/Hash/Ord laws on the live substrate. Renderer threading of DeclarationRef is XL-0B's first commit by agreement with bold-carp-449; the byte-level fixture is specified beside the witness for that instrument.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016PAyJ8DfoCKPfA7NEBLZBG

* Regenerated stage0 mirrors for the three new authorities; exhaustive match in symbol_consumer_class_blocks_decision (nfr roster)

required-regen refused with 'emitted surface has no committed mirror' for extdeps_languages_rust_representation.rs, gunbc_rust_source_type_bindings.rs and std_target_representation.rs; installed from the srv1 candidate tree along with the four drifted mirrors (lib.rs, emitted_population.rs, extdeps_languages_rust_types.rs, v1_compiler_coercion.rs) -- every changed line is the new modules' registration or the .dag change's projection. cli_run::nfr_tests::nfr_roster_receipt flagged the one wildcard arm as an unrostered non-fold residue; the match is now exhaustive over SymbolConsumerClass.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016PAyJ8DfoCKPfA7NEBLZBG

* compiler_tests: the two hand-retained assertions of the bare Symbol checkpoint answer now assert its migration

coercion_rust_checkpoint_resolves_primitives and coercion_is_copy_from_checkpoint asserted Symbol -> "String" / Some(false) at the spelling-keyed arm; with the row migrated to gunbc.rust_source_type_bindings the arm answers no checkpoint, so they now assert the fall-through spelling and None -- the incumbent evidence recorded as the deletion's positive control.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016PAyJ8DfoCKPfA7NEBLZBG

* Witness: the same-spelling falsifier cites real sibling declarations (cited-declaration gate); revert the hand edit to the generated compiler_tests.rs

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016PAyJ8DfoCKPfA7NEBLZBG

* Regenerated compiler_tests.rs: the table-derived checkpoint and is_copy assertions no longer carry the migrated Symbol row (regen fixed point after the mirror install)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016PAyJ8DfoCKPfA7NEBLZBG

* Ruling: split the symbol decision into SymbolValueSemantics (LexemeBacked) and SymbolNominalityStanding (NominalityNotEnforced, six-step trigger); total consumer-evidence classifier

Per bright-ram-778's ruling on #9689: the fused LexemeBackedNominal said nominal while the source checker and the chosen representation both erase, and the coherence law never inspected text_operations_permitted_on_symbol. The value claim and the nominality claim are now two carriers, the law checks each half over its own fields, and two witnesses mutate each half alone to prove independence. The newtype trigger is the ruled ordered chain (a)-(f), nominality true in .dag first. The census states that the identity bridges support LexemeBacked and do not prove the erasure permanently correct. Review 57460: the one-true/ten-false predicate is replaced by a total SymbolConsumerEvidenceStatus classifier the census folds.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016PAyJ8DfoCKPfA7NEBLZBG

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
@gunbai-bot gunbai-bot Bot mentioned this pull request Aug 30, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants