Repository navigation
XL-4 model: receipt-backed generation admission — the changed successor, and an ActiveCompiler only an admission can mint - #9674
gunbai-bot[bot] wants to merge 30 commits into
Conversation
…or, and an ActiveCompiler only an admission can mint Reproduction proves a compiler can read the source it was built from; it says nothing about reading a source it was not. v2.workflow.bootstrap gains the second half: CompilerRequirementRevision (six digest axes, delta DERIVED never authored, toolchain joined to the generation identity), ChangedSuccessorReceipt (changed output observed, builds, conforms to the NEW roster, compiles a further input), FixedPointReceipt gated on a DeterminismWitness, RecoveryGeneration, FallbackObservation, AdmissionAuthority. GenerationAdmission and ActiveCompiler are sole_constructor and reachable only from an admitted decision; 14 new PromotionRefusalCause arms; admission is the absence of every cause. The bootstrap chain binding is BootstrapChainNotExecuted, which refuses — the true state. Evidence: dag/test/claim/generation_admission_changed_successor_witness_test.dag, 25 witnesses (positive control + one per brief falsifier + a fixture-mint guard), claim_batch green on the closure alongside the 19 reproduction witnesses. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01A37WtqPwoQ1vj55d8yQMty
Squash-merge rewrites every commit id, so CommitSha is not a stable identity across the merge. CompilerRequirementRevision gains source_tree: FloorDiscoveryTreeId as the only source join key (SourceTreeAxis, compared through git_object_id_eq); source_revision stays as the informational head. One new witness: a commit rewritten over the same tree reports zero changed axes and still refuses as reproduction-only. Ruling msg_120bdb6d; same pair adopted by XL-1 and XL-3. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01A37WtqPwoQ1vj55d8yQMty
Pure synthetic fixtures; entry-grain row per v2.std.live_tree after #9684. 26/26 green remote. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01A37WtqPwoQ1vj55d8yQMty
|
CI red at b4cde1d is inherited, not this diff: required-floor reached |
|
Rerun at ff52fb1 (base 6d879e1, post-#9705): |
…t_ prefix The 2026-08-29 gate cut seeds the required floor by module-name prefix (v2.workflow.required_floor.required_gate_prefixes); test.claim.self_host_ is a seed, test.claim.generation_admission_* is not, so run 33286941839's disposition artifact carried all 26 identities as declined_outside_gate_closure — passing locally, executing nowhere. Same file, same 26 witnesses, now a seed like the reproduction battery beside it. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01A37WtqPwoQ1vj55d8yQMty
|
Enrollment evidence (run 33288807938, head 502b38d): |
) as typed evidence on the candidate's GenerationReceipt GenerationReceipt { requirements, producer, subject, build, conformance_evidence: ConformanceAdmission, fallback }, joined on source_tree; the request carries it and the sole constructor records it. Seven causes name each way the evidence can fail to be about THIS candidate: refused, other tree, off the promoted route, omitted-arm failed open / unobserved / judged over another generation, and a candidate receipt whose requirements disagree with the parent binding. Fixtures derive every admission through admit_conformance + omitted_arm_triple, so the battery cannot author an admitted arm. effect_evidence stays absent by name until #9669's carrier is on main (the HOLD's reason). 34/34 green remote. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01A37WtqPwoQ1vj55d8yQMty
|
Run on e6da3ab: floor |
|
Run on 3c0f8b6: floor |
|
Handoff (lane parked by XL-N Manager, msg_64f540d1; branch State: CI green; 34 witnesses Remaining work — one commit when
Pitfalls met on this lane: hand-typed sha512 hex must be exactly 128 chars (a 130-char literal silently refuses the positive control); a witness module not under a |
|
Parked by XL-N Manager to free lane capacity; XL-4 is held until XL-1's typed evidence field is on main. Branch retained; a successor lane resumes from it. |
Program: gunbc#9664 XL-N v1-bankruptcy, lane XL-4. MODEL-WORK ONLY per the XL-N brief (lane not yet RELEASED): carriers, admission decision procedure, and the executable falsifier battery. No transport, no corpus-wide measurement, no collision-zone or
src/v1edits, no hand-authored current hashes.What this adds
v2.compiler.self_host.promotion_admissionalready admits a candidate that reproduces the seed's behavior. That is silent about the only capability that makes a prior generation releasable: consuming an input the compiler was not built from. This PR adds the second half inv2.workflow.bootstrap(the module whose generation-admission program the 2026-08-02 operator verdict already places there) and joins it to the first by consumingpromotion_refusal_causes— one authority,promotion_admissionkeeps reproduction only and gains the 14 newPromotionRefusalCausearms.CompilerRequirementRevision—source_tree: FloorDiscoveryTreeIdis the join key for the delta and for the upstream cross-checks;source_revision: CommitSharides beside it, informational only (squash-merge rewrites commits — ruling msg_120bdb6d; witnessga_commit_only_difference_is_not_a_requirement_change). Six axes (source_tree,language_model_revision,target_model_revision,effect_closure_digest,conformance_roster_digest,toolchain_context); the delta is derived (requirement_revision_changed_axes), never authored.toolchain_contextis joined against the generation identity's toolchain axis, so "toolchain moved, receipt did not" is decidable.RequirementBindingReceipt,ConformanceReceipt(measured against the new roster digest, not against a parent — a changed successor is expected to disagree with its parent),ChangedOutputOutcome(ChangedOutputAbsentis its own refusal, distinct from unavailable),ChangedSuccessorReceipt(incl.compiled_further: "binary exists" ≠ "consumed a further input").FixedPointReceipt+DeterminismWitness— stage digests are consulted only under witnessed determinism (gunbc#8181: debug binaries embed build dir); the gate can add a refusal, never supply an admission.RecoveryGeneration,FallbackObservation,AdmissionAuthority,GenerationAdmissionRequest.GenerationAdmission(sole_constructor, minted at exactly one site) →PromotionDecision→ActiveCompiler(sole_constructor, constructible only from an admitted decision) andActiveCompilerStanding(unavailable is a located state, not anAbsentthat tells a consumer to look elsewhere).PromotionRefusalCausearms;admit_generationis the absence of every cause, computed in full (all causes reported, not first-cause).v2.workflow.bootstrapalso carries the binding:BootstrapGenerationChainObservationandbootstrap_active_compiler_standing, currentlyBootstrapChainNotExecuted— the true state, which refuses. No second bootstrap ledger; the admission rules live in one module.Evidence
dag/test/claim/self_host_generation_admission_changed_successor_witness_test.dag— named under the required gate'stest.claim.self_host_seed prefix so the gate executes it (the first name wasdeclined_outside_gate_closure× 26 in run 33286941839's disposition artifact: green locally, executed nowhere). 1 positive control (+ zero-causes check + ActiveCompiler reachability) and one witness per brief falsifier, each perturbing exactly one field of the admissible fixture and asserting the named cause:reproduction-only · declared change with unobserved output · comparison never ran (unavailable, not absent) · successor cannot build · builds but fails conformance · builds+conforms but compiles nothing · conformance credited against another roster · toolchain moved without receipt · candidate as own authority · successor as authority · recovery unavailable · recovery is a promotion subject · recovery ≠ previous active · v1 fallback after G0 · artifact not rehashable · successor spliced from a foreign parent · witnessed-determinism digest disagreement (and its two controls: unwitnessed does not consult; witnessed+agreeing admits) · stale receipt subject.
Run:
claim_batch --source-root dag --source-root src/v2 --entry <file> --functions …(results below).Rung honesty (DESIGN §4b)
ActiveCompilervalue (not any single call site).Upstream evidence (rulings msg_b27d9e01 / msg_120bdb6d / msg_c205c352)
GenerationReceiptcarries upstream admissions as typed evidence, consumed never restated, joined onsource_tree(commit informational):gunbc.semantic_conformance.ConformanceAdmission— landed (XL-3 model-work: normative v2 semantic conformance — v1 is a probe, never the judge #9672) and bound. Causes:ConformanceEvidenceRefused,ConformanceEvidenceTreeMismatch,ConformanceJudgedOffPromotedRoute,ConformanceOmittedArmFailedOpen/…Unobserved/…JudgedOtherGeneration,CandidateReceiptRequirementsDisagree. Fixtures derive every admission throughadmit_conformance+omitted_arm_triple— the fixture cannot author an admitted arm. 8 new witnesses.v2.compiler.effect_demand.EffectDemandEvidenceStanding— pending XL-1 deliverable 1: derived effect demand — and no host effect observed on the compiler's compile path (a lower bound, not a zero) #9669.effect_evidenceis deliberately absent and named in the carrier comment: until it lands,admit_generationcan mint anActiveCompilerwithout effect evidence, which is exactly why this PR is HELD (msg_c3cd9c47). Field + tree join + refused/absent/mismatch causes land in the commit that imports the carrier.Not in this PR (post-RELEASE)
The executed chain (pinned v1 seed → G0 → G1 → G2 → changed G3), the observers that fill
Sha512Digest/roster digests from real artifacts, and the consumer cutover.🤖 Generated with Claude Code
https://claude.ai/code/session_01A37WtqPwoQ1vj55d8yQMty