Skip to content

REWORK #9684 after review 57430 (REQUEST_CHANGES): bound the full-corpus retention or declare its payment; add the hand-Rust receipt - #9688

Closed
briansrls wants to merge 9 commits into
mainfrom
rework-9684
Closed

briansrls wants to merge 9 commits into
mainfrom
rework-9684

Conversation

@briansrls

Copy link
Copy Markdown
Contributor

Auto-opened by session-dashboard for session calm-dove-891.
Pushing to rework-9684 advances this PR.

Worker attestation

Before flipping this PR to ready for review, confirm each item:

  • Title describes the change (not the session id or branch).
  • PR body summarises what and why (replace the TODO below).
  • Tests run: name the command (e.g. npm test, cargo test) and the result.
  • If this closes a work item, the body contains a Closes #N directive.
  • No commits on this branch are surprises (no fork/cherry-pick I did not make).
  • No secrets / credentials / large binaries staged.

Summary

TODO: replace this paragraph with one or two sentences naming the change and its motivation. Reviewers read this first.

Test plan

  • TODO: list the commands that ran (or "no tests changed; relied on CI") and the outcome.

Brian Searls and others added 9 commits August 29, 2026 17:40
…ly one disposition

The partition over the site projection was a COUNT equality — offered == routed +
declined_long + declined_fixture + declined_outside_gate + declined_cost_debt — over a
denominator that had itself already narrowed. DESIGN §5 names both halves: completeness is
an identity join, not a count equality; and a population removed before the partition is one
the partition cannot speak for.

Three changes, one seam:

1. THE UNIVERSE IS THE DECLARED POPULATION. Preparation drops modules two ways — the
   exclusion substrings, and (since the 2026-08-29 gate cut) every module the gate closure
   does not reach — and a witness declared in a dropped module was neither planned nor
   declined. It now carries a disposition row, in the authority that already existed:
   DeclinedDiscoveryExcluded { matched_substring } and DeclinedOutsideGateClosure. The
   closure arm is kept distinct from DeclinedOutsideRequiredGate because they are removed by
   different mechanisms, restored by different triggers, and differ by two orders of
   magnitude — the closure population is the subject of the §4b rung drop "Required gate
   reduced to the compiler floor", and one label over both would report it as a rounding
   error on a nearby count.

2. THE CHECK IS AN IDENTITY JOIN. FloorDispositionJoinInexact reconciles the declared
   identities against the rows they produced and names the offending identities in three
   sets, through the SAME function the terminal ledger join uses
   (reconcile_identity_population, generalized from reconcile_terminal_ledger to take
   identities rather than one seam's row type). Duplicate detection moves from the planned
   subset to the whole declared population: a duplicate whose first site declined used to
   pass unnoticed. The four decline counters are derived from the rows instead of
   accumulated beside them.

3. THE ARTIFACT CARRIES TWO AXES, NEVER FOLDED. The disposition TSV gains an outcome column
   joined from the terminal ledger through claim_disposition; an identity that never ran
   reads not_executed, which is a statement rather than a blank.

Evidence: the calibration pair is enrolled beside the terminal-ledger one — a population
that drops one identity and duplicates another, over which every count of the deleted form
is still exactly equal, and the join names both. Rung honesty: that suite is the local Rust
suite, removed from CI 2026-07-11, so the executing evidence on a push is the floor's own
run, whose announcement now carries declared= beside offered=.

Found on the way: gunbc.discovery_census claims twice in prose that a new
RequiredFloorDisposition arm must fail to compile in its wildcard-free matches.
DeclinedOutsideRequiredGate had already been added with neither match acquiring an arm and
nothing refused — its witness sits outside the gate closure, so no executing path typechecks
it. The arms are added and the claim is restated at its honest rung with its trigger.

Not built, and named as this join's next-rung triggers rather than improvised: the semantic
producer axis (no authority maps a witness to its producer) and the Rust #[ignore] roster (a
different universe with no roster authority). → docs/plans/witness-execution-closure.md

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WmatNuCFnqTdE2KoiwEcm4
# Conflicts:
#	src/v1/stage0/src/bin/claim_executor.rs
#	src/v1/stage0/src/cli_run.rs
…ons to match it

The CI auto-heal bot resolved the #9685 conflict by reimplementing the declared-population
enumeration on the producer itself — folded over preparation's FULL module index, with the
prepared closure and exclusion map classifying the returned identities. That is a better §3
answer than the split this branch carried (producer for the prepared subject, naming-hygiene
scan for the removed sources), so it is kept and mine is dropped rather than restored.

What it left describing something the code no longer does, corrected here:

- the receipt line still cited BarrenTestSidecar, a refusal the producer replaced, and said
  'offered' where the guarantee is now over every DECLARED entry;
- the site loop's own comment still said the population is 'the identities preparation
  dropped', which is the deleted design;
- the plan doc's item 1 described preparation emitting the rows.

And one consequence neither the bot nor this branch had stated: folding the producer over the
full index means its per-file refusals — misplaced test decl, barren sidecar, misplaced wire
contract, malformed live_tree_disposition — now stop the REQUIRED floor for any module under
the source roots. That is a real widening of this lane's subject. It is survivable today
(measured: zero misplaced decls, zero barren sidecars tree-wide) and the first violation
authored anywhere will red this lane rather than the one owning the file, so it is written
into the doc rather than left for that run to discover.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WmatNuCFnqTdE2KoiwEcm4
@gunbai-bot

gunbai-bot Bot commented Aug 29, 2026

Copy link
Copy Markdown
Contributor

Superseded: the rework landed directly on PR #9684's branch (session/nimble-ibex-902) at ab96850 — this draft was auto-opened from the working branch and duplicates it.

@gunbai-bot gunbai-bot Bot closed this Aug 29, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant