Skip to content

F-0: truthful namespace control plane — phase roster, NamespaceCutStage chain, deletion-subject roster, derived wave-wall enrolment - #9698

Merged
briansrls merged 5 commits into
mainfrom
session/fierce-otter-338
Aug 30, 2026
Merged

briansrls merged 5 commits into
mainfrom
session/fierce-otter-338

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Aug 29, 2026 •

Copy link
Copy Markdown
Contributor

F-0 of the NAMESPACE-XL chain (node://adhoc-efba48c4-797): make the namespace-cut control plane derive its standings from executing populations instead of declaring them, and enumerate every authority the cut will delete at stable identity grain.

What lands

1. gunbc.required_ci_phase_roster — substrate authority for required-CI phase identity (RequiredCiPhase = ParsePhase | NamespaceWaveAdmissionPhase | RegenPhase | FloorPhase) and lane ownership (RequiredCiLane moved here from the census, not duplicated). It is load-bearing from both directions:

Declared residue: lane-ownership parity between host phase_lane() and required_ci_phase_lane is not joined per-run. It cannot un-enrol a phase (both lanes execute every required run); terminal is the census's own required_ci_phase_roster_next_rung (atomic deletion of the Rust parallel).

2. gunbc.namespace_cut_stage — the serial chain F-0, XL-0..XL-7, ACT-0 as a closed variant (StageF0..StageXL7GrammarDeletion, namespaced to avoid the self-host XL-N vocabulary in #9669/#9675) with TOTAL stage_prerequisites and stage_milestone_prerequisites. A new stage with no prerequisite arm refuses to compile (falsifier F2 below). ACT-0 is modeled as a receipt-bearing activation gate per operator ruling: four ActivationReceiptKinds, held_activation_receipts = [] by construction, standing derives Blocked-on-absent-receipts rather than NotDerivable.

3. gunbc.namespace_cut_subject_roster + live sibling gunbc.namespace_cut_subject_observation — 11 deletion subjects, each carrying ≥1 probe by construction and a TOTAL subject_deleted_at_stage. Probes are string identities, not decl_ref literals — an authored citation would refuse at ingestion the moment a wave deletes its target, killing the instrument exactly when it must report Absent. Observation is total and fail-closed: Present/Absent via resolve_declaration_ref over live decl facts; SubjectProbeUnobservable{why} for host-Rust items (no item-grain observation authority yet — the typed trigger, and XL-0's starting population) and for Ambiguous (collapsing ambiguity into Absent would fabricate a completed deletion out of a corpus defect). The live half is a registered live-read carrier home (live_read.dag + Rust superset mirror), keeping the pure roster importable from SubstrateInputsOnly witnesses.

Executed instrument: gunbc run --source-root dag --source-root src/v2 --entry dag/gunbc/namespace/namespace_cut_subject_observation.dag --function subject_roster_report --arg out=… — green, 1m49s; all substrate probes PRESENT, host probes UNOBSERVABLE by honest refusal. Acquisition is per-root (v1/v2 pools split by probe_is_v1) after the union walk over three roots was measured to OOM an 883MB runner.

4. compiler_frontend_program_status derives instead of declares

  • NamespaceWaveAdmissionEnrolled → Clear, derived from roster membership (never a status row).
  • NamespaceBaselineObservationComplete → Outstanding, derived from capture_blocked_reason on the capture capability; flips to NotDerivable(PersistedLegacyBaselineObservation) when capture becomes available (witness pins the contract on both arms).
  • The three deletion milestones derive Outstanding from declared stage-subject probe renders at declared-row grain.
  • New stage section in where_are_we: per-stage standing + startability over both prerequisite edge kinds; instruments awaited joined across milestones and stages; conditionally_awaited_instruments names the CaptureAvailable-arm contract so awaited-by-zero-while-blocked is not read as death.

5. Plan repoints — import_namespace_program §9's "CI gap" bullet closed by carrier citation; docs/plans/namespace-cut-replacement-plan.md gets a CURRENT-STATE AUTHORITY banner naming the four carriers, demoting the stale pre-#9365 enrolment prose to dated record.

Exit shape (by execution of where_are_we)

WaveAdmission [CLEAR] · Baseline [OUTSTANDING] (blocked at repair-census, reason quoted from the capability) · F-0 [CLEAR]/startable · XL-0..XL-2 Outstanding with serial blockers · XL-3 NOT-DERIVABLE naming DeclaringIdentitySpellingCensus (and blocked on XL-2) · ACT-0 blocked on the interlock triple + receipts · XL-5/6/7 Blocked with full subject enumerations.

One honest deviation from the brief's exit sentence: XL-4 renders "startability not derivable — unanswerable prerequisite: XL-3" rather than literally "Blocked", because XL-3's standing is NotDerivable pending the spelling census and the status module's startability law refuses to call an unanswerable prerequisite "blocking". Fail-closed by the module's own law; flagged rather than papered.

Falsifier receipts (mutate → red → byte-restore → green)

Verification

  • parse sweep: 4328 files clean (annotation-placement wall required hoisting in-body comment blocks to module-item grain — the wall working as designed)
  • status witnesses 30/30 PASS, new observation witnesses 4/4 PASS (remote)
  • cargo fmt --all --check clean; clippy clean except a pre-existing examples/prep_profile.rs E0603 (floor_prepared_subject_exclusions private) present on the base commit, untouched here.

🤖 Generated with Claude Code

https://claude.ai/code/session_01GpYEk9gSYmMkwL1489D79U

…ge chain, deletion-subject roster, derived wave-wall enrolment

The manager ledger said the wave-admission wall was unbuilt while #9365 had
landed it as a required phase. This makes the control plane derive instead of
declare:

- gunbc.required_ci_phase_roster: substrate authority for required-CI phase
  identity and lane ownership (the census's own named next rung). The workflow
  emission consumes its lane vocabulary (fabric_witness_run lane words are now
  derived), and every --required-ci run joins the host RequiredCiPhase enum
  against the declaration's variant set in both directions and refuses on
  divergence (claim_executor phase_roster_findings, the vocabulary_findings
  shape). Lane-match parity is declared residue under the census's
  atomic-deletion trigger.
- gunbc.namespace_cut_stage: the NAMESPACE-XL serial chain (F-0, XL-0..XL-7,
  ACT-0) as a closed variant with TOTAL stage_prerequisites and
  stage_milestone_prerequisites (ACT-0 carries the interlock triple, by
  operator ruling), plus the activation-receipt gate carrier.
- gunbc.namespace_cut_subject_roster (+ live sibling
  gunbc.namespace_cut_subject_observation): every authority scheduled to
  disappear as string-identity probes (authored decl_ref literals would refuse
  at ingestion the moment a wave deletes a target), each with a total
  observation rule: Present/Absent by runtime declaration-ref resolution,
  Unobservable (typed, with trigger) for host Rust items and ambiguity.
  Executed: all substrate probes PRESENT, per-root acquisition after a
  measured union-walk OOM.
- compiler_frontend_program_status: NamespaceWaveAdmissionEnrolled derived
  from the phase roster (CLEAR); NamespaceBaselineObservationComplete
  Outstanding from the capture capability's blocked reasons; the three
  deletion milestones derived from the subject roster at declared-row grain;
  the stage chain rendered in where_are_we with standings and startability;
  instrument roster updated (three rows retired by delivery, cargo-execution
  fact and XL-3 spelling census added, conditionally-awaited roster for the
  CaptureAvailable contract).
- plan repoints: import_namespace_program section 9 gap closed by carrier
  citation; namespace-cut-replacement-plan.md carries a current-state
  authority banner instead of stale enrolment prose.

Verified by execution (BuildBuddy + local): parse sweep 4328 files clean;
where_are_we renders the exit shape (wall CLEAR, baseline OUTSTANDING, later
stages blocked on named prerequisites); subject_roster_report green in 1m49s;
falsifiers executed mutate/red/restore/green (roster row removal reads
Outstanding; planted stage and subject variants refuse to compile at every
total match); status witnesses 30/30 PASS, observation witnesses 4/4 PASS.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GpYEk9gSYmMkwL1489D79U
@gunbai-bot gunbai-bot Bot changed the title F-0: truthful namespace control plane (NamespaceCutStage, subject roster, derived wave-wall enrolment) F-0: truthful namespace control plane — phase roster, NamespaceCutStage chain, deletion-subject roster, derived wave-wall enrolment Aug 29, 2026
@gunbai-bot
gunbai-bot Bot marked this pull request as ready for review August 29, 2026 22:18
gunbc-ci-auto-heal and others added 4 commits August 29, 2026 22:38
The required namespace-wave-admission phase refused #9698 with exactly two
unadjudicated deltas: BuildLane and WitnessesLane in the census's
required_ci_host_verdict_rows now bind through gunbc.required_ci_phase_roster
instead of the census itself — the declaration move this PR performs on
purpose, at the census's own named next rung. Two exact-identity admission
rows adjudicate them, per the roster's rule (enumerated identity, never a
predicate). They go stale when this PR merges and are owed removal in the
follow-up, exactly as the roster's three prior shrinks record.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GpYEk9gSYmMkwL1489D79U
…ix rows by their fired trigger

Both sides authored NAMESPACE_TRANSITION_ADMISSIONS rows: this branch's two
TargetChanged rows for the RequiredCiLane move, main's six for the
DeclaredCallableIdentity hoist (#9665). The resolution unions the rosters —
and then removes the six immediately, because #9665 is merged: the merge base
and head of any run from here both carry the hoist, no run can produce those
deltas, and stale admissions refuse every PR. Removed by their own DISSOLVE-ON
trigger, recorded as the fourth shrink. This branch's two rows still match
live deltas (main lacks the phase roster) and stay until #9698 merges.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GpYEk9gSYmMkwL1489D79U
…red record and this branch's two live rows

Both sides removed #9665's six stale admission rows — this branch in its
previous merge commit, main in #9705 with the measured receipt. The resolution
keeps main's richer shrink record verbatim and re-seats this branch's two
RequiredCiLane rows, which still match live deltas until #9698 merges.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GpYEk9gSYmMkwL1489D79U
…ix relocation rows by their fired trigger

Main's six rust-source-prefix-relocation rows dissolved the moment #9675
merged — every run from here carries the relocation on both sides, so they
report stale and refuse every PR, the same shape as the four prior shrinks.
Their doc is kept verbatim, the shrink recorded as the fifth, and this
branch's two RequiredCiLane rows (still matching live deltas until #9698
merges) renumbered as the sixth population.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GpYEk9gSYmMkwL1489D79U
@briansrls
briansrls merged commit fa03a01 into main Aug 30, 2026
4 checks passed
@briansrls
briansrls deleted the session/fierce-otter-338 branch August 30, 2026 04:13
gunbai-bot Bot pushed a commit that referenced this pull request Aug 30, 2026
…tural discriminators; union the parser's type-reference channel at every wall consumer; sixth admission shrink

The wave wall's reference collector still reported four declaring/labelling
roles as references — a record TYPE declaration's field labels, a named call
argument's label, a parameter binder, and a coproduct declaration's variant
names — each able to fabricate the same false refusal the record-literal case
did (#9106), and each now excluded by its own structural discriminator rather
than a guessed parent rule:

- a declared field label is the field_to_child_node shape (declared type in
  `inferred`, no children/params, no expr data, no connective, an authored
  ident) — a refinement base type has `inferred: None` and stays collected;
- ExprCall joins ExprRecordLit in the parent-kind rule: argument labels are
  suppressed, argument values still walked, the callee spelling untouched;
- everything directly on the params edge declares a name, so the edge passes
  the binder flag, consumed at one level — the param's declared type in
  children[0] is still collected;
- Connective::Disj is set only by the coproduct item builders, so a Disj
  parent's direct children are variant declarations (already exported via
  `variants`); their payload fields are still walked.

The complementary defect is closed in the same change: `direct_membership`
and `binding_rows` now union `authored_type_references` exactly as
`membership_bound_through` already did — a declared type is parked in
`inferred`, which the walk never visits, so a module whose only reach into
another was a declared field or payload type produced no membership edge and
no binding row, and a cut repointing a declared type moved nothing on either
side of the wall. The exclusions above make this union more load-bearing, not
less: the genuine reference beside each suppressed label lives in the
parser-stamped channel.

Eight test pairs, every one verified BOTH directions by execution on
BuildBuddy: green with the fix, red against the unfixed collector — including
two measured decorations discarded on the way (a same-module variant supplier
only ever produced the self-candidate; an unimported cross-module supplier
never entered the candidate set), before the blanket-import fixture made the
variant arm's RED reachable.

Also the sixth admission shrink: #9698 merged, so its two RequiredCiLane rows
report stale on every run from here and are removed by the trigger they were
authored with. The roster is empty again.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GpYEk9gSYmMkwL1489D79U
gunbai-bot Bot added a commit that referenced this pull request Aug 30, 2026
…tural discriminators; union the parser's type-reference channel at every wall consumer; sixth admission shrink (#9714)

The wave wall's reference collector still reported four declaring/labelling
roles as references — a record TYPE declaration's field labels, a named call
argument's label, a parameter binder, and a coproduct declaration's variant
names — each able to fabricate the same false refusal the record-literal case
did (#9106), and each now excluded by its own structural discriminator rather
than a guessed parent rule:

- a declared field label is the field_to_child_node shape (declared type in
  `inferred`, no children/params, no expr data, no connective, an authored
  ident) — a refinement base type has `inferred: None` and stays collected;
- ExprCall joins ExprRecordLit in the parent-kind rule: argument labels are
  suppressed, argument values still walked, the callee spelling untouched;
- everything directly on the params edge declares a name, so the edge passes
  the binder flag, consumed at one level — the param's declared type in
  children[0] is still collected;
- Connective::Disj is set only by the coproduct item builders, so a Disj
  parent's direct children are variant declarations (already exported via
  `variants`); their payload fields are still walked.

The complementary defect is closed in the same change: `direct_membership`
and `binding_rows` now union `authored_type_references` exactly as
`membership_bound_through` already did — a declared type is parked in
`inferred`, which the walk never visits, so a module whose only reach into
another was a declared field or payload type produced no membership edge and
no binding row, and a cut repointing a declared type moved nothing on either
side of the wall. The exclusions above make this union more load-bearing, not
less: the genuine reference beside each suppressed label lives in the
parser-stamped channel.

Eight test pairs, every one verified BOTH directions by execution on
BuildBuddy: green with the fix, red against the unfixed collector — including
two measured decorations discarded on the way (a same-module variant supplier
only ever produced the self-candidate; an unimported cross-module supplier
never entered the candidate set), before the blanket-import fixture made the
variant arm's RED reachable.

Also the sixth admission shrink: #9698 merged, so its two RequiredCiLane rows
report stale on every run from here and are removed by the trigger they were
authored with. The roster is empty again.


Claude-Session: https://claude.ai/code/session_01GpYEk9gSYmMkwL1489D79U

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
gunbai-bot Bot pushed a commit that referenced this pull request Aug 30, 2026
…merging -- this refuses EVERY pull request, not just this one

Not this lane's subject, taken because it stands between every branch and a
green. #9698 (fa03a01) moved BuildLane and WitnessesLane from
gunbc.required_ci_host_verdict_census to the new gunbc.required_ci_phase_roster.
The two TransitionAdmission rows that adjudicated that move were authored with
the trigger "they go STALE the moment #9698 merges and MUST be removed then" --
their own words -- and #9698 is merged, so no pull_request build can produce the
deltas they name and the phase refuses on the stale rows alone.

Measured, run 33292088803: FAILED PHASE namespace-wave-admission (0 unadjudicated
delta(s), 2 stale admission(s)), naming both rows. This branch's own namespace
delta -- the gunbc.repo_self_build -> gunbc.stage0_crate_partition_generated
import the roster fix adds -- was adjudicated ExplicitlyEvaluatedZeroDelta and
passed, so the refusal is entirely the two stale rows.

Emptying the array to &[] is the proven form: the fourth shrink (#9705) did
exactly that and shipped green. That shrink was a standalone PR and that remains
the normal shape; it rides here only because main was already red.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01RTvKD3J3pnUzXmUascawfQ
briansrls pushed a commit that referenced this pull request Aug 30, 2026
…, and the required build lane gains the partition crates as the wall (#9711)

* Stage0 partition roster: the three modules #9689 added, the phantom row, and the required gate that can see them

The authority edits only; generated artifacts follow in the next commit.

- v2.workflow.rust_crate_partition: std_target_representation into the std-core
  unit, extdeps_languages_rust_representation into the extdeps-languages unit,
  and gunbc_rust_source_type_bindings into the v1-infer unit through its own
  named list, because its layer is neither the v1_compiler pipeline nor the
  extdeps one and the grouping is physical rather than nominal. Placement is
  forced by each module's own crate:: references, not chosen.
- The same authority drops std_lens_verdict, which named a file stage0 lib.rs
  deliberately does not declare (has_pub_mod false in the crate-layout
  registration), so the partition crates were compiling a module the monolith
  does not. The FILE's disposition is deliberately not settled here.
- gunbc.repo_self_build gains repo_self_build_partition_crates_command, whose
  package list is read from the partition roster rather than restated, and the
  build lane runs it beside the all-bins build. That is the executing wall for
  the E0432 class, with rustc as the oracle.
- One witness for the class a hermetic join CAN reach, with its discriminating
  RED authored as a fixture because the live corpus cannot express the refused
  state once the phantom row is gone.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01RTvKD3J3pnUzXmUascawfQ

* Move the roster witness inside the required gate's prefix; convert the v1-infer count literal to an identity join

Run 33290382542 measured both of these rather than my guessing at them.

- The new witness sat at `test.claim.stage0_partition_roster_layout_join_witness`,
  which matches none of v2.workflow.required_floor required_gate_prefixes, so the
  floor discovered it, classified it DeclinedOutsideRequiredGate and never ran it
  -- while it was RED on the live corpus. A wall that reds and is declined is an
  inert lens, so the module path is part of the wall and the file now lives at
  v2.test.claim.*, which the `v2.test.` prefix admits.
- witness_v1_infer_unit_members_holds was the run's single unexpected failure:
  `(unit.members |> count) == 9`, stale the moment the roster gained a module. It
  is now an identity join between the declared roster and what came back through
  the assignment map and partition_fold, so it cannot be repaired by retyping a
  number. Its blind spot -- an error in the roster itself -- is stated in place
  and belongs to the build lane, where rustc is the oracle.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01RTvKD3J3pnUzXmUascawfQ

* Sixth admission shrink: the two RequiredCiLane rows dissolved on #9698 merging -- this refuses EVERY pull request, not just this one

Not this lane's subject, taken because it stands between every branch and a
green. #9698 (fa03a01) moved BuildLane and WitnessesLane from
gunbc.required_ci_host_verdict_census to the new gunbc.required_ci_phase_roster.
The two TransitionAdmission rows that adjudicated that move were authored with
the trigger "they go STALE the moment #9698 merges and MUST be removed then" --
their own words -- and #9698 is merged, so no pull_request build can produce the
deltas they name and the phase refuses on the stale rows alone.

Measured, run 33292088803: FAILED PHASE namespace-wave-admission (0 unadjudicated
delta(s), 2 stale admission(s)), naming both rows. This branch's own namespace
delta -- the gunbc.repo_self_build -> gunbc.stage0_crate_partition_generated
import the roster fix adds -- was adjudicated ExplicitlyEvaluatedZeroDelta and
passed, so the refusal is entirely the two stale rows.

Emptying the array to &[] is the proven form: the fourth shrink (#9705) did
exactly that and shipped green. That shrink was a standalone PR and that remains
the normal shape; it rides here only because main was already red.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01RTvKD3J3pnUzXmUascawfQ

* Regenerated: the partition roster, its stage0 mirror, the three crate lib.rs files, and the build lane that now compiles them

Produced by the generators, not by hand. main_wet (dag/gunbc/instruments/
generated_artifact_gate.dag) rewrote exactly two artifacts -- the generated
partition .dag and .github/workflows/witnesses.yml -- and nothing else in the
corpus moved. --required-regen then reported one drifted mirror,
gunbc_stage0_crate_partition_generated.rs, and --emit-partition-crates rendered
14 files and wrote 3: the std-core, extdeps-languages and v1-infer lib.rs, which
are precisely the three crates the roster change touches.

The emitted build step, read off the emitted bytes rather than assumed:

    run: |
      cargo build --release -p v1-compiler --bins
      cargo build --release -p v1-stage0-runtime -p v1-stage0-std-core ...

Both commands under one literal block scalar, the package list derived from the
partition roster rather than restated, so a crate added to the partition joins
the gate with no edit at the gate.

REGEN NOTE FOR THE NEXT AUTHOR: main_wet is OOM-killed on a BuildBuddy runner
under the default budget (SIGKILL, rc=137). /sys/fs/cgroup/memory.max and
memory.high are unreadable there, so memory_governor read_host_budget_bytes
falls through to MemAvailable -- which reports the HOST's memory, not the slot's
-- and caps at the 15 GiB declared slot line, which can exceed what the slot
actually has. Setting GUNBC_MEMORY_BUDGET_BYTES explicitly (10 GiB used here,
peak RSS 7.7 GiB) makes it complete. The kill is silent through a `cmd | grep |
tail` pipeline, because the pipeline reports the last stage's status.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01RTvKD3J3pnUzXmUascawfQ

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant