Skip to content

XL-4 model: receipt-backed generation admission — the changed successor, and an ActiveCompiler only an admission can mint - #9674

Closed
gunbai-bot[bot] wants to merge 30 commits into
mainfrom
session/quiet-moth-491
Closed

gunbai-bot[bot] wants to merge 30 commits into
mainfrom
session/quiet-moth-491

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Aug 29, 2026 •

Copy link
Copy Markdown
Contributor

Program: gunbc#9664 XL-N v1-bankruptcy, lane XL-4. MODEL-WORK ONLY per the XL-N brief (lane not yet RELEASED): carriers, admission decision procedure, and the executable falsifier battery. No transport, no corpus-wide measurement, no collision-zone or src/v1 edits, no hand-authored current hashes.

What this adds

v2.compiler.self_host.promotion_admission already admits a candidate that reproduces the seed's behavior. That is silent about the only capability that makes a prior generation releasable: consuming an input the compiler was not built from. This PR adds the second half in v2.workflow.bootstrap (the module whose generation-admission program the 2026-08-02 operator verdict already places there) and joins it to the first by consuming promotion_refusal_causes — one authority, promotion_admission keeps reproduction only and gains the 14 new PromotionRefusalCause arms.

  • CompilerRequirementRevision — source_tree: FloorDiscoveryTreeId is the join key for the delta and for the upstream cross-checks; source_revision: CommitSha rides beside it, informational only (squash-merge rewrites commits — ruling msg_120bdb6d; witness ga_commit_only_difference_is_not_a_requirement_change). Six axes (source_tree, language_model_revision, target_model_revision, effect_closure_digest, conformance_roster_digest, toolchain_context); the delta is derived (requirement_revision_changed_axes), never authored. toolchain_context is joined against the generation identity's toolchain axis, so "toolchain moved, receipt did not" is decidable.
  • RequirementBindingReceipt, ConformanceReceipt (measured against the new roster digest, not against a parent — a changed successor is expected to disagree with its parent), ChangedOutputOutcome (ChangedOutputAbsent is its own refusal, distinct from unavailable), ChangedSuccessorReceipt (incl. compiled_further: "binary exists" ≠ "consumed a further input").
  • FixedPointReceipt + DeterminismWitness — stage digests are consulted only under witnessed determinism (gunbc#8181: debug binaries embed build dir); the gate can add a refusal, never supply an admission.
  • RecoveryGeneration, FallbackObservation, AdmissionAuthority, GenerationAdmissionRequest.
  • GenerationAdmission (sole_constructor, minted at exactly one site) → PromotionDecision → ActiveCompiler (sole_constructor, constructible only from an admitted decision) and ActiveCompilerStanding (unavailable is a located state, not an Absent that tells a consumer to look elsewhere).
  • 14 new PromotionRefusalCause arms; admit_generation is the absence of every cause, computed in full (all causes reported, not first-cause).

v2.workflow.bootstrap also carries the binding: BootstrapGenerationChainObservation and bootstrap_active_compiler_standing, currently BootstrapChainNotExecuted — the true state, which refuses. No second bootstrap ledger; the admission rules live in one module.

Evidence

dag/test/claim/self_host_generation_admission_changed_successor_witness_test.dag — named under the required gate's test.claim.self_host_ seed prefix so the gate executes it (the first name was declined_outside_gate_closure × 26 in run 33286941839's disposition artifact: green locally, executed nowhere). 1 positive control (+ zero-causes check + ActiveCompiler reachability) and one witness per brief falsifier, each perturbing exactly one field of the admissible fixture and asserting the named cause:

reproduction-only · declared change with unobserved output · comparison never ran (unavailable, not absent) · successor cannot build · builds but fails conformance · builds+conforms but compiles nothing · conformance credited against another roster · toolchain moved without receipt · candidate as own authority · successor as authority · recovery unavailable · recovery is a promotion subject · recovery ≠ previous active · v1 fallback after G0 · artifact not rehashable · successor spliced from a foreign parent · witnessed-determinism digest disagreement (and its two controls: unwitnessed does not consult; witnessed+agreeing admits) · stale receipt subject.

Run: claim_batch --source-root dag --source-root src/v2 --entry <file> --functions … (results below).

Rung honesty (DESIGN §4b)

  • self-authorized promotion / unadmitted active compiler: rung 4 (no constructor).
  • receipt contents: rung 2–3 — a receipt reports an observation made outside the model.
  • bootstrap→consumer binding: rung 1; next-rung trigger is the capability that compile/test/execute/CI each resolve their compiler through an ActiveCompiler value (not any single call site).

Upstream evidence (rulings msg_b27d9e01 / msg_120bdb6d / msg_c205c352)

GenerationReceipt carries upstream admissions as typed evidence, consumed never restated, joined on source_tree (commit informational):

Not in this PR (post-RELEASE)

The executed chain (pinned v1 seed → G0 → G1 → G2 → changed G3), the observers that fill Sha512Digest/roster digests from real artifacts, and the consumer cutover.

🤖 Generated with Claude Code

https://claude.ai/code/session_01A37WtqPwoQ1vj55d8yQMty

Brian Searls and others added 16 commits August 29, 2026 12:48
…or, and an ActiveCompiler only an admission can mint

Reproduction proves a compiler can read the source it was built from; it says nothing about reading a source it was not. v2.workflow.bootstrap gains the second half: CompilerRequirementRevision (six digest axes, delta DERIVED never authored, toolchain joined to the generation identity), ChangedSuccessorReceipt (changed output observed, builds, conforms to the NEW roster, compiles a further input), FixedPointReceipt gated on a DeterminismWitness, RecoveryGeneration, FallbackObservation, AdmissionAuthority. GenerationAdmission and ActiveCompiler are sole_constructor and reachable only from an admitted decision; 14 new PromotionRefusalCause arms; admission is the absence of every cause. The bootstrap chain binding is BootstrapChainNotExecuted, which refuses — the true state.

Evidence: dag/test/claim/generation_admission_changed_successor_witness_test.dag, 25 witnesses (positive control + one per brief falsifier + a fixture-mint guard), claim_batch green on the closure alongside the 19 reproduction witnesses.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01A37WtqPwoQ1vj55d8yQMty
Squash-merge rewrites every commit id, so CommitSha is not a stable identity across the merge. CompilerRequirementRevision gains source_tree: FloorDiscoveryTreeId as the only source join key (SourceTreeAxis, compared through git_object_id_eq); source_revision stays as the informational head. One new witness: a commit rewritten over the same tree reports zero changed axes and still refuses as reproduction-only. Ruling msg_120bdb6d; same pair adopted by XL-1 and XL-3.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01A37WtqPwoQ1vj55d8yQMty
Pure synthetic fixtures; entry-grain row per v2.std.live_tree after #9684. 26/26 green remote.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01A37WtqPwoQ1vj55d8yQMty
@gunbai-bot

gunbai-bot Bot commented Aug 30, 2026

Copy link
Copy Markdown
Contributor Author

CI red at b4cde1d is inherited, not this diff: required-floor reached verdict=FloorClean unexpected_failures=0 failed=0 (2842/2842 executed), then phase namespace-wave-admission failed with 6 STALE ADMISSION rows — DeclaredCallableIdentity hoist to v1.std.core 2026-08-29 in src/v1/stage0/src/namespace_wave_admission.rs, consumed by #9665's merge and now matching no delta from any post-#9665 base. The 5 deltas this PR introduces (v2.workflow.bootstrap → extdeps.git.object_store / self_host.generation / self_host.promotion_admission / v2.std.integer / floor_discovery) are all ExplicitlyEvaluatedZeroDelta. #9705 (head 9200ce7) already removes the six rows; this PR will re-green by merging main once it lands. Not touching src/v1 here per the XL-4 brief.

@gunbai-bot

gunbai-bot Bot commented Aug 30, 2026

Copy link
Copy Markdown
Contributor Author

Rerun at ff52fb1 (base 6d879e1, post-#9705): namespace-wave-admission ADMITTED, floor failed=0 unexpected_failures=0 (2842/2842), verdict FloorRefused solely on completed_over_cost_requirement=1: v2.test.emit.rust_produced_decl_emit.rust_produced_decl_name_discriminates cpu=510ms vs 500ms budget — an unrelated witness 2% over its cost line under runner contention (the row is a cost debt, not a defect, per the floor's own diagnostic). Re-running the failed jobs; no change to this diff.

Brian Searls and others added 3 commits August 30, 2026 02:30
…t_ prefix

The 2026-08-29 gate cut seeds the required floor by module-name prefix (v2.workflow.required_floor.required_gate_prefixes); test.claim.self_host_ is a seed, test.claim.generation_admission_* is not, so run 33286941839's disposition artifact carried all 26 identities as declined_outside_gate_closure — passing locally, executing nowhere. Same file, same 26 witnesses, now a seed like the reproduction battery beside it.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01A37WtqPwoQ1vj55d8yQMty
@gunbai-bot

gunbai-bot Bot commented Aug 30, 2026

Copy link
Copy Markdown
Contributor Author

Enrollment evidence (run 33288807938, head 502b38d): required-floor-disposition artifact carries all 26 test.claim.self_host_generation_admission_changed_successor_witness.* identities as planned/passed. The earlier name (test.claim.generation_admission_changed_successor_witness) matched no required_gate_prefixes seed and was declined_outside_gate_closure × 26 in run 33286941839 despite a green check — the gate closure is seeded by module NAME, not by imports.

Brian Searls and others added 2 commits August 30, 2026 03:35
) as typed evidence on the candidate's GenerationReceipt

GenerationReceipt { requirements, producer, subject, build, conformance_evidence: ConformanceAdmission, fallback }, joined on source_tree; the request carries it and the sole constructor records it. Seven causes name each way the evidence can fail to be about THIS candidate: refused, other tree, off the promoted route, omitted-arm failed open / unobserved / judged over another generation, and a candidate receipt whose requirements disagree with the parent binding. Fixtures derive every admission through admit_conformance + omitted_arm_triple, so the battery cannot author an admitted arm. effect_evidence stays absent by name until #9669's carrier is on main (the HOLD's reason). 34/34 green remote.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01A37WtqPwoQ1vj55d8yQMty
@gunbai-bot

gunbai-bot Bot commented Aug 30, 2026

Copy link
Copy Markdown
Contributor Author

Run on e6da3ab: floor verdict=FloorClean failed=0 (2938/2938; this PR's 34 identities planned/passed in the disposition artifact). The red is again phase namespace-wave-admission — 6 STALE ADMISSION rows rust-source-prefix-relocation-01..06 in src/v1/stage0/src/namespace_wave_admission.rs, consumed by their own merge and matching no delta from a post-merge base. Retirement is already open as #9713; this PR re-greens by merging main after it lands. Not touching src/v1 here.

@gunbai-bot

gunbai-bot Bot commented Aug 30, 2026

Copy link
Copy Markdown
Contributor Author

Run on 3c0f8b6: floor verdict=FloorClean failed=0 (2942/2942). Red is namespace-wave-admission again — now the 2 rows #9698 itself carried (required-ci lane vocabulary moved to its declared next-rung authority (#9698), bindings BuildLane/WitnessesLane in gunbc.required_ci_host_verdict_census), stale from any post-#9698 base. Third instance of the same class tonight (#9665→#9705, relocation→#9698, now #9698 itself). Nothing in this diff; re-greens on merging main after the retirement lands.

@gunbai-bot

gunbai-bot Bot commented Aug 30, 2026

Copy link
Copy Markdown
Contributor Author

Handoff (lane parked by XL-N Manager, msg_64f540d1; branch session/quiet-moth-491 @ d0b179c, clean, current with main).

State: CI green; 34 witnesses planned/passed in the required-floor disposition artifact; XL-3 ConformanceAdmission bound; PR HELD per msg_c3cd9c47 until XL-1's field is on main. Keep DRAFT until the manager says RELEASED.

Remaining work — one commit when src/v2/compiler/effect_demand.dag (#9669, EffectDemandEvidenceStanding) is on main:

  1. src/v2/workflow/bootstrap.dag: import v2.compiler.effect_demand { EffectDemandEvidenceAdmitted, EffectDemandEvidenceRefused, EffectDemandEvidenceStanding }; add effect_evidence: EffectDemandEvidenceStanding to GenerationReceipt (delete the "NOT yet a field" comment); add
    fn effect_evidence_causes(e: EffectDemandEvidenceStanding, tree: FloorDiscoveryTreeId) -> List<PromotionRefusalCause> {
      match e {
        EffectDemandEvidenceAdmitted { source_revision: _, source_tree: t } =>
          if git_object_id_eq(left: t.object_id, right: tree.object_id) { freemonoid_empty() } else { [EffectEvidenceTreeMismatch] }
        EffectDemandEvidenceRefused { source_revision: _, source_tree: _, conjunct: c } => [EffectEvidenceRefused { conjunct: c }]
      }
    }
    
    and call it from generation_receipt_causes with tree.
  2. promotion_admission.dag: arms EffectEvidenceRefused { conjunct: Symbol }, EffectEvidenceTreeMismatch + symbols ^refusal_effect_evidence_refused, ^refusal_effect_evidence_tree_mismatch.
  3. Witnesses (self_host_generation_admission_changed_successor_witness_test.dag, keep the self_host_ prefix — it is what enrolls the file in the required gate): admitted-on-candidate-tree admits (extend ga_candidate_receipt_with); refused → ^refusal_effect_evidence_refused; other tree → ^refusal_effect_evidence_tree_mismatch; commit-only difference over the same tree still admits. Build Admitted only through effect_demand_local_gate(...) if it is the sole constructor (XL-1's message says every live population currently yields Refused — a fixture-level admitted arm may need XL-1's own fixture helpers).
  4. Rerun: claim_batch --source-root dag --source-root src/v2 --entry <file> --functions <all test fns> remote, then confirm the disposition artifact shows all identities planned/passed.

Pitfalls met on this lane: hand-typed sha512 hex must be exactly 128 chars (a 130-char literal silently refuses the positive control); a witness module not under a required_gate_prefixes seed is declined_outside_gate_closure with no log line; namespace-wave-admission stale rows from a just-merged PR red every downstream PR until the retirement lands — merge main, don't repair.

@gunbai-bot

gunbai-bot Bot commented Aug 30, 2026

Copy link
Copy Markdown
Contributor Author

Parked by XL-N Manager to free lane capacity; XL-4 is held until XL-1's typed evidence field is on main. Branch retained; a successor lane resumes from it.

@gunbai-bot gunbai-bot Bot closed this Aug 30, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants