diff --git a/dag/test/claim/algebra_carrier_roster_witness_test.dag b/dag/test/claim/algebra_carrier_roster_witness_test.dag index 9a7a85c2fe9..75b5bbaa80b 100644 --- a/dag/test/claim/algebra_carrier_roster_witness_test.dag +++ b/dag/test/claim/algebra_carrier_roster_witness_test.dag @@ -11,7 +11,28 @@ import v2.std.live_tree { LiveTreeDisposition, SubstrateInputsOnly } data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data carrier_alias_surface_invariant_note: String = "WHAT WENT WRONG ONCE, STATED AS A PROPERTY OF THE ROSTER RATHER THAN AS A MISSING MAP ROW. A spelling that resolves as a declared container alias is returned by resolve_method_receiver_type AS AUTHORED, and method existence is then decided by looking its CANONICAL alias spelling up in kernel_algebra_profile -- container_kind_canonical does exactly that. So a carrier that resolves as a container and whose canonical alias spelling carries no profile has a receiver the compiler admits and a method surface it cannot decide: tree.facts.lookup(node) refused on a PartialFunction receiver while the byte-identical call on Map resolved. One concept, two answers, decided by which spelling the author wrote.\n\nUnder the five hand-authored spelling maps that preceded the roster, that state was not expressible as a violated invariant at all -- it was a row nobody had written, in one of five places, and the only way to find it was for a declaration to refuse. The roster makes the two facts fields on the same spelling row, so the join below is authorable, and this witness asserts it: for every carrier that declares any container_alias_row spelling, the ASCII-least such spelling declares RowPresent method_surface. container_alias_canonical_spelling picks the first sorted key, so the ASCII-least spelling is exactly the one the lookup will land on.\n\nTHE RED IS AUTHORABLE AND IS AUTHORED HERE. carrier_missing_its_alias_surface() is a fixture carrier shaped exactly like the PartialFunction row before its repair -- alias rows declared, method surface absent -- and the same predicate returns false on it. Without that control the invariant would be permanently green over a roster that happens to satisfy it, which DESIGN.md section 4b calls a decoration rather than a wall." +// WHAT WENT WRONG ONCE, STATED AS A PROPERTY OF THE ROSTER RATHER THAN AS A MISSING MAP ROW. A +// spelling that resolves as a declared container alias is returned by resolve_method_receiver_type +// AS AUTHORED, and method existence is then decided by looking its CANONICAL alias spelling up in +// kernel_algebra_profile -- container_kind_canonical does exactly that. So a carrier that resolves +// as a container and whose canonical alias spelling carries no profile has a receiver the compiler +// admits and a method surface it cannot decide: tree.facts.lookup(node) refused on a +// PartialFunction receiver while the byte-identical call on Map resolved. One concept, two answers, +// decided by which spelling the author wrote. +// +// Under the five hand-authored spelling maps that preceded the roster, that state was not +// expressible as a violated invariant at all -- it was a row nobody had written, in one of five +// places, and the only way to find it was for a declaration to refuse. The roster makes the two +// facts fields on the same spelling row, so the join below is authorable, and this witness asserts +// it: for every carrier that declares any container_alias_row spelling, the ASCII-least such +// spelling declares RowPresent method_surface. container_alias_canonical_spelling picks the first +// sorted key, so the ASCII-least spelling is exactly the one the lookup will land on. +// +// THE RED IS AUTHORABLE AND IS AUTHORED HERE. carrier_missing_its_alias_surface() is a fixture +// carrier shaped exactly like the PartialFunction row before its repair -- alias rows declared, +// method surface absent -- and the same predicate returns false on it. Without that control the +// invariant would be permanently green over a roster that happens to satisfy it, which DESIGN.md +// section 4b calls a decoration rather than a wall. // The ASCII-least spelling is taken through `sorted_map_keys` rather than through a hand-written // comparison, because `sorted_map_keys` is the same primitive `container_alias_canonical_spelling` diff --git a/dag/test/claim/altra_attachment_stack_witness_test.dag b/dag/test/claim/altra_attachment_stack_witness_test.dag index 43f3d33623e..9f1cf31bc6f 100644 --- a/dag/test/claim/altra_attachment_stack_witness_test.dag +++ b/dag/test/claim/altra_attachment_stack_witness_test.dag @@ -68,9 +68,9 @@ fn count_of(xs: List) -> Int { } // THE COMPLETENESS AUTHORITY CROSS-FOOTS. 1960 signal plus 2927 power and ground plus 39 reserved -// is 4926, and that total must equal the socket's declared contact count reached through a -// different path — the CPU catalog row. Two independent routes to one population is what makes -// this a join rather than a number someone typed twice. +// is 4926, which must equal the socket's declared contact count reached through a different path +// — the CPU catalog row. Two independent routes to one population make this a join rather than a +// number typed twice. test fn w_the_contact_population_cross_foots_at_4926() -> Bool { altra_pin_summary_total() == 4926 && altra_declared_contact_count() == 4926 @@ -84,20 +84,17 @@ test fn w_the_board_side_termination_population_follows_the_package() -> Bool { board_side_termination_population() == 4926 } -// THE CENTRAL CLAIM, AND THE SPLIT MADE IT SHARPER RATHER THAN WEAKER. It used to read that -// NEITHER the package nor the land pattern was established, which was true only because the fused -// type filed a publicly documented dimension under "redistribution undecided" and called that not -// established. Now the package IS established and the land pattern still is not — which is the -// claim this test was always trying to make. The package sitting in an already-cited datasheet is -// exactly what makes the conflation tempting, and asserting it from the established side is a -// stronger statement than asserting it from two unknowns. -// INVERTED 2026-08-23 BY THE SOCKET-BODY DRAWING, AND THE CLAIM IT DEFENDS IS UNCHANGED. This -// witness never asserted that the land pattern is unobtainable; it asserted that the PROCESSOR -// PACKAGE does not establish it. Both facts are established now, so the discriminating content -// moved to where it always belonged: they are established by DIFFERENT authorities. A future edit -// that derives the board land pattern from the package's underside -- the exact category error -// this module's header exists to make unwritable -- collapses those two authorities into one and -// fails here. +// THE CENTRAL CLAIM, AND THE SPLIT MADE IT SHARPER. It used to read that NEITHER the package nor +// the land pattern was established, true only because the fused type filed a publicly documented +// dimension under "redistribution undecided". Now the package IS established and the land pattern +// still is not — the claim this test always made. The package sitting in an already-cited +// datasheet is what makes the conflation tempting, and asserting from the established side is +// stronger than asserting from two unknowns. +// INVERTED 2026-08-23 BY THE SOCKET-BODY DRAWING; THE CLAIM IT DEFENDS IS UNCHANGED. This witness +// never asserted the land pattern is unobtainable, only that the PROCESSOR PACKAGE does not +// establish it. Both are established now, by DIFFERENT authorities. A future edit deriving the +// board land pattern from the package's underside — the category error this module's header makes +// unwritable — collapses those authorities into one and fails here. test fn w_a_public_package_does_not_establish_the_board_land_pattern() -> Bool { fact_is_established(f: processor_package_standing.fact) && fact_is_established(f: board_land_pattern_standing.fact) @@ -117,9 +114,9 @@ test fn w_a_public_package_does_not_establish_the_board_land_pattern() -> Bool { // THE TWO AXES ARE INDEPENDENT, asserted on the one row where both are decided. The package's // fact is established AND its carriage admits normalized facts — a pair the earlier type could -// not represent at all, since it required choosing between "publicly cited" and "redistribution -// undecided". This is the regression control for the fusion: if the axes are ever collapsed -// again, one of these two conjuncts becomes unsayable. +// not represent, since it forced a choice between "publicly cited" and "redistribution +// undecided". Regression control for the fusion: collapse the axes again and one conjunct becomes +// unsayable. test fn w_an_established_fact_and_a_decided_carriage_coexist() -> Bool { fact_is_established(f: processor_package_standing.fact) && match processor_package_standing.carriage { @@ -149,19 +146,18 @@ test fn w_an_unresolved_fact_carries_no_carriage_decision() -> Bool { // THREE CATEGORIES, DISTINGUISHED BY WHO ACTS. An unresolved authority is someone reading a // datasheet, a redistribution question is a legal decision, an NDA gate is a commercial -// relationship. If these collapsed to one "not ready" state the tractable blockers would be -// indistinguishable from the intractable one — which is precisely the error that once had this -// repository declaring a public pin map NDA-only. -// THE SUBJECT AND THE ROUTE ARE DIFFERENT FACTS, and this asserts they have not been -// swapped. An earlier revision put the subject label into the route field, so a consumer -// asking WHERE to obtain the collateral was told WHAT it is. Both are checked, and the -// route is checked as an authority rather than as text — which is what makes the swap -// unwritable now rather than merely absent. +// relationship. Collapsed to one "not ready" state, the tractable blockers would be +// indistinguishable from the intractable one — the error that once had this repository declaring +// a public pin map NDA-only. +// THE SUBJECT AND THE ROUTE ARE DIFFERENT FACTS, asserted not swapped. An earlier revision put the +// subject label into the route field, so a consumer asking WHERE to obtain the collateral was told +// WHAT it is. Both are checked, the route as an authority rather than text — which makes the swap +// unwritable rather than merely absent. // // The land-pattern blocker went from "commercial" to "none" on 2026-08-23 when the socket vendor -// supplied the drawing. The witness still discriminates all three blocker KINDS -- that is what it -// is named for -- and the reference-board collateral below still carries the commercial one, so -// no arm of blocker_kind lost its coverage when this layer stopped being blocked. +// supplied the drawing. The witness still discriminates all three blocker KINDS, and the +// reference-board collateral below still carries the commercial one, so no arm of blocker_kind +// lost coverage. test fn w_the_three_blocker_kinds_are_distinct() -> Bool { let package_blocker = match layer_blocker(row: processor_package_standing) { Absent => "none" @@ -184,11 +180,10 @@ test fn w_the_three_blocker_kinds_are_distinct() -> Bool { } } -// THE REDISTRIBUTION BLOCKER NEEDS A CONTROLLED FIXTURE NOW, and that is a improvement rather -// than a workaround. It used to be demonstrated by the processor package row, whose carriage the -// legal ruling has since decided — so the production row stopped being a specimen of the blocker -// and the test would have quietly measured nothing. A planted row keeps the arm executed and -// keeps it independent of any decision made about a real subject. +// THE REDISTRIBUTION BLOCKER NEEDS A CONTROLLED FIXTURE NOW — an improvement, not a workaround. It +// was demonstrated by the processor package row, whose carriage the legal ruling has since +// decided, so that row stopped being a specimen and the test would have measured nothing. A +// planted row keeps the arm executed and independent of decisions about real subjects. fn undecided_carriage_blocker() -> String { let planted = AttachmentLayerStanding { layer: board_land_pattern_standing.layer, @@ -203,16 +198,14 @@ fn undecided_carriage_blocker() -> String { // NO ATTACHMENT LAYER IS BEHIND THE NDA BOUNDARY ANY MORE, AND THAT IS THE POINT OF THE RENAME. // This asserted "exactly one" while the board land pattern's only route ran through Ampere -// Customer Connect. The socket vendor answered on 2026-08-23, so the count is now zero and the -// witness is renamed rather than edited in place: a witness whose name says ONE while it asserts -// ZERO is a stale claim that greps as a live one, which is the positional-citation failure applied -// to test names. +// Customer Connect. The socket vendor answered on 2026-08-23, so the count is zero and the witness +// is renamed rather than edited in place: a name saying ONE over an assertion of ZERO is a stale +// claim that greps as live — the positional-citation failure applied to test names. // -// The claim it defends survives intact and is still executed rather than asserted in prose: the -// land pattern is reached through a route this repository can publish, so the layer that was -// gated is now established. If any layer regresses to FactAccessGated -- a future part whose only -// geometry sits behind Customer Connect -- the count goes non-zero and this fails, which is -// exactly the alarm the original witness existed to raise. +// The claim survives and is still executed: the land pattern is reached through a route this +// repository can publish, so the gated layer is established. If any layer regresses to +// FactAccessGated — a future part whose only geometry sits behind Customer Connect — the count +// goes non-zero and this fails, the alarm the original witness existed to raise. test fn w_no_attachment_layer_is_behind_the_nda_boundary() -> Bool { let nda_layers = fold(attachment_stack, init: 0, f: fn(acc, row) { match row.fact { @@ -231,9 +224,9 @@ test fn w_no_attachment_layer_is_behind_the_nda_boundary() -> Bool { } } -// SIX LAYERS, SIX BLOCKERS, NONE ESTABLISHED — and this is the honest state of the attachment -// stack today rather than a target. It is asserted by count so that establishing one layer moves -// the number instead of silently satisfying a name. +// SIX LAYERS, SIX BLOCKERS, NONE ESTABLISHED — the honest state of the attachment stack today, not +// a target. Asserted by count so establishing one layer moves the number instead of silently +// satisfying a name. test fn w_every_attachment_layer_is_open_and_says_why() -> Bool { let layers = fold(attachment_stack, init: 0, f: fn(acc, _r) { acc + 1 }) let package_resolved = match layer_blocker(row: processor_package_standing) { @@ -261,10 +254,9 @@ test fn w_the_layers_are_named_distinctly() -> Bool { && (attachment_layer_name(l: ProcessorPackageLayer) as String) != (attachment_layer_name(l: BoardLandPatternLayer) as String) } -// EVERY LAYER THIS BOARD CARRIES IS A COHERENT PAIR. This runs over the live population rather than -// a fixture, so it is the claim that the six standings authored in this module actually mean -// something -- and it is the one that would have caught the defect if it had existed when the axes -// were split. +// EVERY LAYER THIS BOARD CARRIES IS A COHERENT PAIR. Runs over the live population rather than a +// fixture, so it is the claim that the six standings authored here mean something — and the one +// that would have caught the defect had it existed when the axes were split. test fn w_every_layer_standing_is_a_coherent_pair() -> Bool { fold(attachment_stack, init: true, f: fn(acc, st) { acc && standing_pair_is_admitted(fact: st.fact, carriage: st.carriage) @@ -272,9 +264,9 @@ test fn w_every_layer_standing_is_a_coherent_pair() -> Bool { } // THE THREE DISCRIMINATING REDS, one per incoherent combination, each authored here rather than -// found in the tree. Without these the claim above is satisfied by a refusal function that never -// fires -- which is exactly what subject_blocker was doing before this change: answering an -// established fact with inapplicable carriage as though nothing blocked it. +// found in the tree. Without them the claim above is satisfied by a refusal function that never +// fires — what subject_blocker did before this change: answering an established fact with +// inapplicable carriage as though nothing blocked it. test fn w_an_established_fact_cannot_have_inapplicable_carriage() -> Bool { match authority_standing_refusal( fact: processor_package_standing.fact, @@ -321,13 +313,12 @@ test fn w_the_coherent_pairs_are_admitted() -> Bool { ) } -// THE DISCRIMINATING CONTROL FOR THE JOINT CHECK. This row is planted, not live: an established -// fact whose carriage says the question does not apply, which is precisely the pair -// authority_standing_refusal names EstablishedFactHasInapplicableCarriage. Before the projection -// consulted that refusal, the coherence check called this row refused while layer_blocker answered -// Absent, so a consumer reading the blockers saw a settled layer -- two answers about one row, -// disagreeing, with the reassuring one on the path everything downstream reads. Both directions -// are asserted here so neither half can quietly stop firing. +// THE DISCRIMINATING CONTROL FOR THE JOINT CHECK. Planted, not live: an established fact whose +// carriage says the question does not apply — the pair authority_standing_refusal names +// EstablishedFactHasInapplicableCarriage. Before the projection consulted that refusal, the +// coherence check called this row refused while layer_blocker answered Absent: two disagreeing +// answers about one row, the reassuring one on the path everything downstream reads. Both +// directions are asserted so neither half can quietly stop firing. fn incoherent_row() -> AttachmentLayerStanding { AttachmentLayerStanding { layer: BoardLandPatternLayer, diff --git a/dag/test/claim/annotation_erasure_emission_witness_test.dag b/dag/test/claim/annotation_erasure_emission_witness_test.dag index 22348ce9fc9..e40b1cdc786 100644 --- a/dag/test/claim/annotation_erasure_emission_witness_test.dag +++ b/dag/test/claim/annotation_erasure_emission_witness_test.dag @@ -1,6 +1,17 @@ module test.claim.annotation_erasure_emission_witness_test -data annotation_erasure_emission_migration_note: String = "Migrated from src/v1/tests/claim/v1_annotation_target_emission_test.dag (dead witness tree triage, dashboard node adhoc-9b80ec49-d63). That file's own NEXT TRIGGER named exactly what was missing: 'a .dag-reachable surface returning emitted files for a synthetic source... then all three arms enroll together in this file and this receipt dissolves.' compile_dag_rust_emit_check is that surface: it compiles a synthetic source through the real v1 pipeline and lets a witness assert on the emitted Rust text via includes/excludes. It does not hand back raw bytes for a diff, so this is not a byte-identical replay of the 2026-08-05 host-execution receipt (annotated vs bare fixtures, `diff -r` reporting zero difference) — that receipt stands as historical evidence and is not restated as a live claim. What migrates is the same D-C property 4 argument (prose reaches the target program nowhere) using excludes on the literal prose strings, paired with a non-vacuity control proving the check tracks real emitted content rather than passing on any input." +// Migrated from src/v1/tests/claim/v1_annotation_target_emission_test.dag (dead witness tree +// triage, dashboard node adhoc-9b80ec49-d63). That file's own NEXT TRIGGER named exactly what was +// missing: 'a .dag-reachable surface returning emitted files for a synthetic source... then all +// three arms enroll together in this file and this receipt dissolves.' compile_dag_rust_emit_check +// is that surface: it compiles a synthetic source through the real v1 pipeline and lets a witness +// assert on the emitted Rust text via includes/excludes. It does not hand back raw bytes for a +// diff, so this is not a byte-identical replay of the 2026-08-05 host-execution receipt (annotated +// vs bare fixtures, `diff -r` reporting zero difference) — that receipt stands as historical +// evidence and is not restated as a live claim. What migrates is the same D-C property 4 argument +// (prose reaches the target program nowhere) using excludes on the literal prose strings, paired +// with a non-vacuity control proving the check tracks real emitted content rather than passing on +// any input. data annotated_source_alpha_marker_a: String = "module emit_probe_one\n\n// prose about alpha\ndata alpha: Int = 424242\n\n// prose about probe\nfn probe(x: Int) -> Int {\n x + alpha\n}\n" diff --git a/dag/test/claim/anomaly_evidence_witness_test.dag b/dag/test/claim/anomaly_evidence_witness_test.dag index 0622de34f48..fb606903256 100644 --- a/dag/test/claim/anomaly_evidence_witness_test.dag +++ b/dag/test/claim/anomaly_evidence_witness_test.dag @@ -6,9 +6,37 @@ import v2.std.live_tree { LiveTreeDisposition, SubstrateInputsOnly } data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data anomaly_evidence_witness_note: String = "Composition slice 4: anomaly evidence is a SURFACE, not a tooltip. The loud band's located reason (step: detail, or the wire reason) renders as the first line of the row's disclosure — persistent and inspectable in the DOM — while the title attribute stays a convenience channel, never the only carrier. The predicate below defines what 'is a surface' means mechanically; the RED feeds it the title-only shape (yesterday's program) and it must refuse." - -data reason_surface_roster_note: String = "THE PREDICATE HAD ONE SUBJECT AND THE CORPUS GREW THREE MORE, which is how a rule stays stated and stops being enforced. Slice 4 established 'a located reason is a surface' and checked it against the dispatch answer. The row then acquired the workflow strip, whose failed and refused segments carry a detail from /workflow.json, and the click's own catch arm — and both wrote their reason to a title attribute only, which is precisely the shape anomaly_reason_red_on_title_only plants as the RED. The witness was green the whole time because it was asked about one producer.\\n\\nSo the roster is now named explicitly and each producer is asserted separately. That is the difference between a rule and a check on a rule: a check whose subject set is a single hand-picked site cannot notice the second site, and the second site is where the defect actually landed. A new refusal surface that writes only a tooltip has to green THIS file to merge, and it cannot.\\n\\nreason_is_a_disclosure_surface no longer scans for one inline insertion, because there is no longer one — the upsert is a single emitted helper the producers share. That is the point: the predicate now asks whether a shared surface EXISTS and whether each producer reaches it, rather than pattern-matching one caller's inlined copy, which is what made it un-reusable and therefore un-reused.\\n\\nTHIS IS VALIDATION, NOT A CONSTRUCTION WALL, and the difference is worth stating rather than letting a green witness imply more than it proves (DESIGN section 5). A scan over emitted text concedes that the bad state is writable: nothing stops a fifth producer from assigning a reason to a title attribute, it only stops that producer from doing so WITHOUT this file going red, and only for producers this roster names. The construction shape exists and is not cheap: a located reason would have to be a typed value whose only sink is the surface, so that assigning one to a title is a type error rather than a missing assertion. Every producer here builds its reason as untyped JavaScript text through ts_binop, so that carrier does not exist yet and minting it is a real design rather than a follow-up edit. dissolve-on: feature:located-reason-carrier — a reason is a value with one sink, and this predicate becomes redundant with the type." +// Composition slice 4: anomaly evidence is a SURFACE, not a tooltip. The loud band's located reason +// (step: detail, or the wire reason) renders as the first line of the row's disclosure — persistent +// and inspectable in the DOM — while the title attribute stays a convenience channel, never the +// only carrier. The predicate below defines what 'is a surface' means mechanically; the RED feeds +// it the title-only shape (yesterday's program) and it must refuse. + +// THE PREDICATE HAD ONE SUBJECT AND THE CORPUS GREW THREE MORE, which is how a rule stays stated +// and stops being enforced. Slice 4 established 'a located reason is a surface' and checked it +// against the dispatch answer. The row then acquired the workflow strip, whose failed and refused +// segments carry a detail from /workflow.json, and the click's own catch arm — and both wrote their +// reason to a title attribute only, which is precisely the shape anomaly_reason_red_on_title_only +// plants as the RED. The witness was green the whole time because it was asked about one +// producer.\n\nSo the roster is now named explicitly and each producer is asserted separately. That +// is the difference between a rule and a check on a rule: a check whose subject set is a single +// hand-picked site cannot notice the second site, and the second site is where the defect actually +// landed. A new refusal surface that writes only a tooltip has to green THIS file to merge, and it +// cannot.\n\nreason_is_a_disclosure_surface no longer scans for one inline insertion, because there +// is no longer one — the upsert is a single emitted helper the producers share. That is the point: +// the predicate now asks whether a shared surface EXISTS and whether each producer reaches it, +// rather than pattern-matching one caller's inlined copy, which is what made it un-reusable and +// therefore un-reused.\n\nTHIS IS VALIDATION, NOT A CONSTRUCTION WALL, and the difference is worth +// stating rather than letting a green witness imply more than it proves (DESIGN section 5). A scan +// over emitted text concedes that the bad state is writable: nothing stops a fifth producer from +// assigning a reason to a title attribute, it only stops that producer from doing so WITHOUT this +// file going red, and only for producers this roster names. The construction shape exists and is +// not cheap: a located reason would have to be a typed value whose only sink is the surface, so +// that assigning one to a title is a type error rather than a missing assertion. Every producer +// here builds its reason as untyped JavaScript text through ts_binop, so that carrier does not +// exist yet and minting it is a real design rather than a follow-up edit. dissolve-on: +// feature:located-reason-carrier — a reason is a value with one sink, and this predicate becomes +// redundant with the type. fn reason_surface_helper_exists(js: String) -> Bool { string_contains(s: js, pattern: "const gunbcReasonSurface = (dt, source, text) =>") @@ -38,7 +66,12 @@ test fn anomaly_reason_empty_text_removes_the_line() -> Bool { return string_contains(s: js, pattern: "if (!text) { rl && rl.remove();") } -data producer_roster_note: String = "The three producers that must reach the surface, asserted one by one so a regression names which one regressed. The dispatch answer writes under the 'dispatch' source on the loud band and clears it otherwise; the catch arm writes under the same source, because an unreadable answer and a loud answer are the same row's dispatch verdict; each workflow segment writes under its own 'workflow:' source, so a row refused at Verify and refused at dispatch shows both lines instead of one silently overwriting the other." +// The three producers that must reach the surface, asserted one by one so a regression names which +// one regressed. The dispatch answer writes under the 'dispatch' source on the loud band and clears +// it otherwise; the catch arm writes under the same source, because an unreadable answer and a loud +// answer are the same row's dispatch verdict; each workflow segment writes under its own +// 'workflow:' source, so a row refused at Verify and refused at dispatch shows both lines +// instead of one silently overwriting the other. test fn anomaly_dispatch_answer_reaches_the_surface() -> Bool { return producer_reaches_the_surface( @@ -62,7 +95,9 @@ test fn anomaly_workflow_segment_reaches_the_surface() -> Bool { source_arg: "gunbcRowDisclosure(act), 'workflow:' + seg.kind, bad ? seg.short_label + ' · ' + seg.state + ' — ' + sd : ''") } -data workflow_segment_fallback_note: String = "A refused segment whose wire detail is empty still gets a true line rather than a bare label — the same fall-closed phrasing the dispatch band uses, shared as one row rather than spelled twice." +// A refused segment whose wire detail is empty still gets a true line rather than a bare label — +// the same fall-closed phrasing the dispatch band uses, shared as one row rather than spelled +// twice. test fn anomaly_workflow_segment_falls_closed_on_empty_detail() -> Bool { return string_contains( @@ -110,7 +145,14 @@ test fn anomaly_reason_surface_is_styled() -> Bool { return string_contains(s: roadmap_css(), pattern: ".disclosure-reason { font-size: var(--text-12); color: var(--text); border-left: var(--border-2) solid var(--band-loud); padding-left: var(--space-6); margin: var(--space-2) var(--space-0) var(--space-2) }") } -data accessible_name_note: String = "The accessible name is the THIRD reason channel and it was silently broken, which is why it is pinned here rather than left to the markup witnesses. `seg.label + ': ' + seg.state + (seg.detail ? ' — ' + seg.detail : '')` was emitted without the group, so it parsed as `(label + state + detail) ? ' — ' + detail : ''` — always true, since a concatenation is never the empty string — and a screen reader was told the detail alone with no label and no state. The model always said the right thing; the printer dropped the group (extdeps.languages.typescript.program.ts_operator_precedence_note). Asserting the parenthesized text here means the row's accessible name cannot silently lose its subject again." +// The accessible name is the THIRD reason channel and it was silently broken, which is why it is +// pinned here rather than left to the markup witnesses. `seg.label + ': ' + seg.state + (seg.detail +// ? ' — ' + seg.detail : '')` was emitted without the group, so it parsed as `(label + state + +// detail) ? ' — ' + detail : ''` — always true, since a concatenation is never the empty string — +// and a screen reader was told the detail alone with no label and no state. The model always said +// the right thing; the printer dropped the group +// (extdeps.languages.typescript.program.ts_operator_precedence_note). Asserting the parenthesized +// text here means the row's accessible name cannot silently lose its subject again. // Re-pointed at A2: the stage chips carried label+state in an aria-label because their visible face was a compressed chip; the activity ledger row IS its accessible name — one text node carrying label, state, and detail, readable by any client without attribute decoding. The class this guards (an obligation's state never lives in border style or attributes alone) is unchanged; the carrier moved from attribute to content. test fn anomaly_stage_accessible_name_keeps_label_and_state() -> Bool { @@ -125,7 +167,12 @@ test fn anomaly_workflow_refusal_reason_survives_concatenation() -> Bool { pattern: "const why = 'workflow observation refused: ' + (wj.reason || 'no located reason on the wire');") } -data absent_reason_phrase_single_authority_note: String = "One phrase, one row. 'the wire carried no reason' was spelled two ways at four sites — 'no located reason on the wire' in the dispatch band, 'no reason on the wire' in the sessions, attempts, and workflow observation banners — for one fact, which is the nickname §3 forbids at the smallest possible scale. It is worth fixing at this scale precisely because it is small: a phrase that means the same thing should not tell the operator it might not, and four literals is where a fifth comes from. This witness pins that no site spells it independently." +// One phrase, one row. 'the wire carried no reason' was spelled two ways at four sites — 'no +// located reason on the wire' in the dispatch band, 'no reason on the wire' in the sessions, +// attempts, and workflow observation banners — for one fact, which is the nickname §3 forbids at +// the smallest possible scale. It is worth fixing at this scale precisely because it is small: a +// phrase that means the same thing should not tell the operator it might not, and four literals is +// where a fifth comes from. This witness pins that no site spells it independently. test fn anomaly_absent_reason_phrase_has_one_spelling() -> Bool { let js = dispatch_client_js_source() diff --git a/dag/test/claim/anonymous_record_head_use_line_witness_test.dag b/dag/test/claim/anonymous_record_head_use_line_witness_test.dag index ade0d4694b3..73d767f874e 100644 --- a/dag/test/claim/anonymous_record_head_use_line_witness_test.dag +++ b/dag/test/claim/anonymous_record_head_use_line_witness_test.dag @@ -1,6 +1,25 @@ module test.claim.anonymous_record_head_use_line_witness_test -data anonymous_record_head_use_line_witness_note: String = "Board row 3 (root K, materialization_carriers 51-site census): an ANONYMOUS record literal — no authored type name at the literal — is rendered by emit_typed_record_lit with a head the emitter decides from the inferred/resolved type, so the emitted Rust spells a name the authored source never does. The authored-source attestation gate (reference_derived_candidate_authored) refused exactly that candidate, no use-line was synthesized, and rustc reported E0422/E0433 on the head the emitter itself wrote (live specimens: extdeps.realization.compile_stage_memo / parse_table_memo `retention: \{...\}` rendering `ProviderRetention \{ .. \}` with no import). This witness reproduces the mechanism through the real emit pipeline against the minimal provider fixture test.fixture.anonhead_provider (smallest crossing specimen — the first landing imported the real std.cache_interface and paid its whole import closure, 61.7s CPU against the 1552ms floor budget, BUDGET-REFUSED on run 32226586721; the mechanism needs only a provider module with a record type reached solely through an anonymous literal, so the fixture shrank to one importless three-type module and the live corpus specimens stay pinned by the board receipt, not by this witness): the fixture references AnonheadRetention ONLY through an anonymous literal in argument position (the name is spelled nowhere in the fixture source), and asserts the emitted module carries both the emitter-decided head and its synthesized use-line. RED against the pre-fix emitter (use-line absent), green with collect_anonymous_record_lit_heads (emitter_attested_anonymous_head_note, 05_emit_rust.dag). The negative assertion pins the over-collection boundary: a name from the provider module the fixture never constructs must not gain a use-line. dissolve-on: never — permanent regression control for the emitter-attested anonymous-head arm." +// Board row 3 (root K, materialization_carriers 51-site census): an ANONYMOUS record literal — no +// authored type name at the literal — is rendered by emit_typed_record_lit with a head the emitter +// decides from the inferred/resolved type, so the emitted Rust spells a name the authored source +// never does. The authored-source attestation gate (reference_derived_candidate_authored) refused +// exactly that candidate, no use-line was synthesized, and rustc reported E0422/E0433 on the head +// the emitter itself wrote (live specimens: extdeps.realization.compile_stage_memo / +// parse_table_memo `retention: {...}` rendering `ProviderRetention { .. }` with no import). This +// witness reproduces the mechanism through the real emit pipeline against the minimal provider +// fixture test.fixture.anonhead_provider (the first landing imported the real std.cache_interface +// and paid its whole import closure, 61.7s CPU against the 1552ms floor budget, BUDGET-REFUSED on +// run 32226586721; the mechanism needs only a provider module with a record type reached solely +// through an anonymous literal, so the fixture shrank to one importless three-type module and the +// live corpus specimens stay pinned by the board receipt, not by this witness): the fixture +// references AnonheadRetention ONLY through an anonymous literal in argument position (the name is +// spelled nowhere in the fixture source), and asserts the emitted module carries both the +// emitter-decided head and its synthesized use-line. RED against the pre-fix emitter (use-line +// absent), green with collect_anonymous_record_lit_heads (emitter_attested_anonymous_head_note, +// 05_emit_rust.dag). The negative assertion pins the over-collection boundary: a name from the +// provider module the fixture never constructs must not gain a use-line. dissolve-on: never — +// permanent regression control for the emitter-attested anonymous-head arm. fn w_anonymous_record_head_gets_use_line() -> Bool { compile_dag_rust_emit_check( diff --git a/dag/test/claim/argv_command_render_witness_test.dag b/dag/test/claim/argv_command_render_witness_test.dag index a9eb6c390cc..5e1929f02ae 100644 --- a/dag/test/claim/argv_command_render_witness_test.dag +++ b/dag/test/claim/argv_command_render_witness_test.dag @@ -5,17 +5,16 @@ import extdeps.exec.command { shell_command_render } import extdeps.storage.nbd { nbd_client_disconnect_command, nbd_client_program } import extdeps.tools.gnu_coreutils { cat_command, printf_command } -// THESE WITNESSES NOW BUILD THEIR SUBJECT THROUGH PRODUCTION BUILDERS, and that is a consequence of -// the wall rather than a preference about test style: extdeps.exec.command ArgvCommand is -// sole_constructor, so a witness cannot hand-author one, exactly as extdeps.shell.exec's -// TransportScript admits no test declaration. What is asserted is unchanged -- rendering quotes each -// argv word, and an embedded apostrophe closes and reopens the quoting context rather than -// terminating it. +// THESE WITNESSES BUILD THEIR SUBJECT THROUGH PRODUCTION BUILDERS, a consequence of the wall: +// extdeps.exec.command ArgvCommand is sole_constructor, so a witness cannot hand-author one, as +// extdeps.shell.exec's TransportScript admits no test declaration. The assertion is unchanged -- +// rendering quotes each argv word, and an embedded apostrophe closes and reopens the quoting +// context rather than terminating it. // -// THE EXPECTATIONS ARE DERIVED, NOT TRANSCRIBED, for the first one: the program's path is a fact of -// extdeps.storage.nbd, and a golden string repeating it would go red on a path correction that -// changed nothing about quoting. What this file is a witness FOR is the quoting, so the quoting is -// what it states literally. +// THE EXPECTATIONS ARE DERIVED, NOT TRANSCRIBED, for the first: the program's path is a fact of +// extdeps.storage.nbd, and a golden string repeating it would red on a path correction that changed +// nothing about quoting. This file witnesses the quoting, so the quoting is what it states +// literally. test fn shell_quote_plain_args_single_quoted() -> Bool { shell_command_render(command: nbd_client_disconnect_command(device: "/dev/nbd0")) == join(["'", nbd_client_program as String, "' '-d' '/dev/nbd0'"], "") diff --git a/dag/test/claim/artifact_store_witness_test.dag b/dag/test/claim/artifact_store_witness_test.dag index 93ab9893d3c..59dbed4d687 100644 --- a/dag/test/claim/artifact_store_witness_test.dag +++ b/dag/test/claim/artifact_store_witness_test.dag @@ -51,7 +51,14 @@ import v2.std.live_tree { LiveTreeDisposition, SubstrateInputsOnly } data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data artifact_store_witness_note: String = "P2 pure-spec ACCEPT witnesses: put/get/evict receipts with discriminating REDs - a mutated key input never serves the old artifact (stale-never-served), identical files and argv under a changed resolved build toolchain OR changed admitted environment select different effective native workspaces, budget breach evicts least-recent WITH the eviction counted in the receipt, and a store cannot be constructed over a provider that did not declare the byte ceiling it is being sized by (the retention field's first behavioral reader, audit F5). The budget is DERIVED from the provider, so the fixtures can no longer declare an unobserved ceiling and be handed an exact number anyway; each refusal names its own cause because the remedies differ." +// P2 pure-spec ACCEPT witnesses: put/get/evict receipts with discriminating REDs - a mutated key +// input never serves the old artifact (stale-never-served), identical files and argv under a +// changed resolved build toolchain OR changed admitted environment select different effective +// native workspaces, budget breach evicts least-recent WITH the eviction counted in the receipt, +// and a store cannot be constructed over a provider that did not declare the byte ceiling it is +// being sized by (the retention field's first behavioral reader, audit F5). The budget is DERIVED +// from the provider, so the fixtures can no longer declare an unobserved ceiling and be handed an +// exact number anyway; each refusal names its own cause because the remedies differ. data byte_bounded_provider: CacheProvider = provider_row( id: "artifact-store-test", @@ -436,8 +443,13 @@ test fn store_no_eviction_under_budget_holds() -> Bool { ) == [] } - -data store_put_totality_witness_note: String = "The discriminating receipt for store_put's totality repair: an artifact larger than the whole budget must be a DidNotFit VALUE and must leave the store untouched. Before the repair these assertions were all false in the same direction - the oversized put reported success, its evicted list named the key just put, and against a warm store it had already discarded the valid rows. The warm case is asserted separately from the cold one because only the warm case exposes the DESTRUCTION: a cold oversized put merely returned an empty store it had also started with, so a cold-only witness would have gone green against the destructive implementation." +// The discriminating receipt for store_put's totality repair: an artifact larger than the whole +// budget must be a DidNotFit VALUE and must leave the store untouched. Before the repair these +// assertions were all false in the same direction - the oversized put reported success, its evicted +// list named the key just put, and against a warm store it had already discarded the valid rows. +// The warm case is asserted separately from the cold one because only the warm case exposes the +// DESTRUCTION: a cold oversized put merely returned an empty store it had also started with, so a +// cold-only witness would have gone green against the destructive implementation. fn oversize_store() -> ArtifactStore { ArtifactStore { budget: byte_size(count: 100), next_ordinal: 1, rows: [] } diff --git a/dag/test/claim/asrock_live_probe_witness_test.dag b/dag/test/claim/asrock_live_probe_witness_test.dag index 1fc98f898d2..447e0852dde 100644 --- a/dag/test/claim/asrock_live_probe_witness_test.dag +++ b/dag/test/claim/asrock_live_probe_witness_test.dag @@ -22,7 +22,17 @@ import extdeps.bmc.capability { import extdeps.bmc.webui.nbd_proxy { VmSlotIndexEndpoint } import extdeps.firmware.types { firmware_semantic_version } -data asrock_live_probe_binding_note: String = "gunbc#7398 collateral repair. This file declared NO imports and bound every cross-module name by bare reference, which resolves only when some unrelated module elsewhere in the assembled closure happens to drag extdeps.boards.asrock_rack into the pool — the Class B pool-membership coincidence measured as arm (3) of test.claim.import_admission_closure_membership_witness_test import_admission_closure_membership_note, which records it as blocking further import-stripping. Adding one witness root in an unrelated lane re-shaped witness_layer_roots and ProbeAbsent stopped resolving, while every other name in this same file still bound by luck. MEASURED: merged roadmap PRs #7393 and #7395 hit the same whole-tree baseline and passed, so the baseline is not generally broken — a NEW witness root is what perturbs it. The imports above make the binding closure-independent, which is the remedy that thread names; they restore explicit dependency edges rather than removing any." +// gunbc#7398 collateral repair. This file declared NO imports and bound every cross-module name by +// bare reference, which resolves only when some unrelated module elsewhere in the assembled closure +// happens to drag extdeps.boards.asrock_rack into the pool — the Class B pool-membership +// coincidence measured as arm (3) of test.claim.import_admission_closure_membership_witness_test +// import_admission_closure_membership_note, which records it as blocking further import-stripping. +// Adding one witness root in an unrelated lane re-shaped witness_layer_roots and ProbeAbsent +// stopped resolving, while every other name in this same file still bound by luck. MEASURED: merged +// roadmap PRs #7393 and #7395 hit the same whole-tree baseline and passed, so the baseline is not +// generally broken — a NEW witness root is what perturbs it. The imports above make the binding +// closure-independent, which is the remedy that thread names; they restore explicit dependency +// edges rather than removing any. data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly diff --git a/dag/test/claim/behavioral_receipt_standing_witness_test.dag b/dag/test/claim/behavioral_receipt_standing_witness_test.dag index 0a209622000..50c6ab2652c 100644 --- a/dag/test/claim/behavioral_receipt_standing_witness_test.dag +++ b/dag/test/claim/behavioral_receipt_standing_witness_test.dag @@ -15,7 +15,24 @@ import v2.compiler.self_host.promotion_admission { data live_tree_disposition: v2.std.live_tree.LiveTreeDisposition = v2.std.live_tree.SubstrateInputsOnly -data behavioral_receipt_standing_witness_doc: String = "FIXTURE CONTROL for behavioral_receipt_standing, following the house pattern of build_cache_placement_observation_test: construct the observation directly and assert its classification, rather than performing the emit-compile-run the observation describes. That is what makes these arms authorable at all -- the wet path is refused by the hermetic floor by construction, so a control that had to RUN a comparison could never execute here, and the distinction being checked would be tested only where it is USED and never where it is DECIDED.\n\nWHAT IT GUARDS. slb_behavioral_receipt_holds collapsed seven authored causes to one bit at three sites, each spelled `ObservationUnavailable { cause: _ } => false`. Exhaustive over ObservationUnavailable, no missing arm, no warning: total at the level examined and blind one level down. The arms below pin that the causes do NOT share a remedy and therefore must not share a rendering -- an unobserved build means the compile never ran, an unobserved equivalence means it ran and reported nothing, an unobserved fault means the fault arm never executed. Three owners.\n\nWHY THIS IS NOT A RESTATEMENT OF THE Bool. Every arm below is false under behavioral_receipt_standing_holds, so a witness over the Bool alone could not tell any of them apart -- which is precisely the defect. The discriminating question is which STANDING each observation produces, and only the standing can answer it." +// FIXTURE CONTROL for behavioral_receipt_standing, following the house pattern of +// build_cache_placement_observation_test: construct the observation directly and assert its +// classification rather than performing the emit-compile-run it describes. That makes these arms +// authorable at all — the wet path is refused by the hermetic floor by construction, so a control +// that had to RUN a comparison could never execute here, and the distinction would be tested only +// where it is USED, never where it is DECIDED. +// +// WHAT IT GUARDS. slb_behavioral_receipt_holds collapsed seven authored causes to one bit at three +// sites, each spelled `ObservationUnavailable { cause: _ } => false`. Exhaustive over +// ObservationUnavailable, no missing arm, no warning: total at the level examined and blind one +// level down. The arms below pin that the causes do NOT share a remedy and so must not share a +// rendering — an unobserved build means the compile never ran, an unobserved equivalence means it +// ran and reported nothing, an unobserved fault means the fault arm never executed. Three owners. +// +// WHY THIS IS NOT A RESTATEMENT OF THE Bool. Every arm below is false under +// behavioral_receipt_standing_holds, so a witness over the Bool alone could not tell them apart — +// precisely the defect. The discriminating question is which STANDING each observation produces, +// and only the standing can answer it. data corpus_fixture: BehavioralCorpus = BehavioralCorpus { identity: "fixture truth table", @@ -73,7 +90,7 @@ fn standing_is_fault_unobserved(s: BehavioralReceiptStanding) -> Bool { } // THE THREE ARMS THE COLLAPSE MADE INDISTINGUISHABLE. Each is a DIFFERENT stage failing to be -// observed, and under the old predicate all three were one `false`. +// observed; under the old predicate all three were one `false`. test fn unobserved_build_is_not_an_unobserved_comparison() -> Bool { let s = behavioral_receipt_standing( o: observation( @@ -107,9 +124,9 @@ test fn unobserved_fault_over_an_agreeing_comparison_names_the_fault() -> Bool { standing_is_fault_unobserved(s: s) && !standing_is_equivalence_unobserved(s: s) } -// THE CAUSAL ORDER IS LOAD-BEARING. With the build unobserved, the downstream verdicts are -// meaningless rather than false, so reporting a fault cause here would name a symptom as the -// finding. This arm pins that an unobserved build wins over a POSITIVE downstream verdict. +// THE CAUSAL ORDER IS LOAD-BEARING. With the build unobserved, downstream verdicts are meaningless +// rather than false, so reporting a fault cause here would name a symptom as the finding. This arm +// pins that an unobserved build wins over a POSITIVE downstream verdict. test fn an_unobserved_build_is_reported_over_downstream_agreement() -> Bool { let s = behavioral_receipt_standing( o: observation( @@ -121,9 +138,9 @@ test fn an_unobserved_build_is_reported_over_downstream_agreement() -> Bool { standing_is_build_unobserved(s: s) } -// EVERY ONE OF THE ABOVE IS false UNDER THE Bool. This is the arm that proves the witnesses above -// are not restatements of the predicate they replace: the Bool cannot separate them, which is -// exactly why the collapse was invisible. +// EVERY ONE OF THE ABOVE IS false UNDER THE Bool — the arm proving the witnesses above are not +// restatements of the predicate they replace: the Bool cannot separate them, which is why the +// collapse was invisible. test fn the_bool_cannot_separate_what_the_standing_separates() -> Bool { let a = behavioral_receipt_standing( o: observation( @@ -145,8 +162,8 @@ test fn the_bool_cannot_separate_what_the_standing_separates() -> Bool { && standing_is_fault_unobserved(s: b) } -// THE POSITIVE CONTROL. A fully observed, fully agreeing run holds -- so the standing is not a -// mechanism that refuses everything. +// THE POSITIVE CONTROL. A fully observed, fully agreeing run holds — the standing does not refuse +// everything. test fn a_fully_observed_agreeing_run_holds() -> Bool { let s = behavioral_receipt_standing( o: observation( @@ -158,9 +175,9 @@ test fn a_fully_observed_agreeing_run_holds() -> Bool { behavioral_receipt_standing_holds(s: s) } -// A CAUGHT FAULT IS REQUIRED, NOT OPTIONAL. A run that built, agreed, and did NOT catch its -// planted fault has not established the receipt -- it has established that the comparison cannot -// tell right from wrong, which is the claim-entailing-evidence rule at the receipt level. +// A CAUGHT FAULT IS REQUIRED, NOT OPTIONAL. A run that built, agreed, and did NOT catch its planted +// fault has not established the receipt — it established that the comparison cannot tell right from +// wrong, the claim-entailing-evidence rule at receipt level. test fn agreement_without_a_caught_fault_does_not_hold() -> Bool { let s = behavioral_receipt_standing( o: observation( diff --git a/dag/test/claim/bmc/bmc_firmware_thermal_witness_test.dag b/dag/test/claim/bmc/bmc_firmware_thermal_witness_test.dag index c6b8f7a1f84..9e6b0313b3b 100644 --- a/dag/test/claim/bmc/bmc_firmware_thermal_witness_test.dag +++ b/dag/test/claim/bmc/bmc_firmware_thermal_witness_test.dag @@ -613,7 +613,14 @@ data lazy_onboarding_drift_curve: BmcFanCurve = BmcFanCurve { ), } -data lazy_onboarding_drift_curve_note: String = "The stripped onboarding-overwrite curve (fleet incident 2026-07-30): minimum 30 percent held through 90C, then a late panic ramp to 55/70/85/100 percent at 93/95/97/98C. It is deliberately NOT the fleet intent, which is now the srv3 2.07.00 vendor stock aggressive curve (byte-equal to asrock_altrad8ud_factory_temp_soc_fan_curve). This is the witness's genuine drift fixture: a BMC carrying it is drifted from fleet intent and must receive a typed apply plan back to the stock curve. The prior model instead carried the lazy curve AS the fleet intent, so its drift fixture was the factory aggressive curve and its apply plan would have converted srv4's factory default INTO this lazy curve." +// The stripped onboarding-overwrite curve (fleet incident 2026-07-30): minimum 30 percent held +// through 90C, then a late panic ramp to 55/70/85/100 percent at 93/95/97/98C. It is deliberately +// NOT the fleet intent, which is now the srv3 2.07.00 vendor stock aggressive curve (byte-equal to +// asrock_altrad8ud_factory_temp_soc_fan_curve). This is the witness's genuine drift fixture: a BMC +// carrying it is drifted from fleet intent and must receive a typed apply plan back to the stock +// curve. The prior model instead carried the lazy curve AS the fleet intent, so its drift fixture +// was the factory aggressive curve and its apply plan would have converted srv4's factory default +// INTO this lazy curve. test fn srv4_flash_overlay_is_observed_writable_and_live_overridden() -> Bool { match srv4_bmc_config_persistence_observation { diff --git a/dag/test/claim/bmc/bmc_typed_operations_witness_test.dag b/dag/test/claim/bmc/bmc_typed_operations_witness_test.dag index 104916408e9..4ba93e07591 100644 --- a/dag/test/claim/bmc/bmc_typed_operations_witness_test.dag +++ b/dag/test/claim/bmc/bmc_typed_operations_witness_test.dag @@ -86,11 +86,10 @@ test fn failed_threshold_transport_cannot_become_threshold_unstated() -> Bool { } // These two took `success: Bool` and an untyped `value`/`stderr` triple until the sensor path moved -// onto the jq invocation layer. They now state the SAME two requirements against the typed jq -// outcome: a refusal must not decay into absence, and an empty successful projection must not decay -// into a refusal. The requirement is unchanged; only what carries it is, which is why these are -// re-enrolled rather than retired (DESIGN section 3 -- evidence for a surviving claim survives the -// representation that used to hold it). +// onto the jq invocation layer. They state the SAME two requirements against the typed jq outcome: +// a refusal must not decay into absence, and an empty successful projection must not decay into a +// refusal. Only the carrier changed, so they are re-enrolled rather than retired (DESIGN section 3 +// -- evidence for a surviving claim survives the representation that used to hold it). test fn failed_sensor_projection_cannot_become_absent() -> Bool { match openbmc_sensor_integer_projection_result( outcome: JqExecutionRefused { exit_code: 2, stderr: "malformed OpenBMC JSON" }, diff --git a/dag/test/claim/build_artifact_corruption_probe_witness_test.dag b/dag/test/claim/build_artifact_corruption_probe_witness_test.dag index d469c69ef2c..3ec549890b8 100644 --- a/dag/test/claim/build_artifact_corruption_probe_witness_test.dag +++ b/dag/test/claim/build_artifact_corruption_probe_witness_test.dag @@ -9,9 +9,17 @@ import tools.build_step_transport { witness_nonempty_executable_accepted_by_execution } -data build_artifact_corruption_probe_doc: String = "Wet bin-witness execution probes for tools.build_step_transport. The typed corruption-probe harness (shell.Mktemp, Filesystem.Write, gunbc.WitnessBin.Run on claim_executor --verify-build-artifacts) exercises live host effects, so it runs in the declared bin-witness wet batch, not hermetic discovery. The substrate serialize-shape checks stay in build_artifact_verification_witness_test." +// Wet bin-witness execution probes for tools.build_step_transport. The typed corruption-probe +// harness (shell.Mktemp, Filesystem.Write, gunbc.WitnessBin.Run on claim_executor +// --verify-build-artifacts) exercises live host effects, so it runs in the declared bin-witness wet +// batch, not hermetic discovery. The substrate serialize-shape checks stay in +// build_artifact_verification_witness_test. -data witness_bin_readiness_claim_doc: String = "Discriminating controls for the typed witness-binary readiness carrier (tools.host_prelude). Each arm is asserted against a distinct real on-disk state AND against the path it must carry, so the carrier cannot regress to a single constant verdict — the arm-by-arm equivalent of the comparator controls that closed review 39735. Enrolled here rather than in a new file because these are wet bin-witness probes with the same effects and cadence as the corruption probes above them." +// Discriminating controls for the typed witness-binary readiness carrier (tools.host_prelude). Each +// arm is asserted against a distinct real on-disk state AND against the path it must carry, so the +// carrier cannot regress to a single constant verdict — the arm-by-arm equivalent of the comparator +// controls that closed review 39735. Enrolled here, not in a new file, because these are wet +// bin-witness probes with the same effects and cadence as the corruption probes above. test fn build_artifact_corruption_probe_holds() -> Bool { witness_zero_byte_artifact_rejected_by_execution() diff --git a/dag/test/claim/build_cache_configuration_observation_witness_test.dag b/dag/test/claim/build_cache_configuration_observation_witness_test.dag index 429bd06dd3c..8d150da421d 100644 --- a/dag/test/claim/build_cache_configuration_observation_witness_test.dag +++ b/dag/test/claim/build_cache_configuration_observation_witness_test.dag @@ -13,7 +13,14 @@ import gunbc.build_cache_instance { ci_cache_instance, session_cache_instance, } -data configuration_observation_witness_note: String = "THE DISCRIMINATING PAIRS protect the distinction the carriers exist to express. A successful process-environment read with no assignment is positive evidence that the setting is unset; an unavailable read says the host never answered. Collapsing them to an Option would make the empty-observation narrow writable. The subject-binding witness separately proves the observations retain both which of two same-implementation instances was read and which endpoint-owning process supplied the environment, so a session server's 50 GiB setting cannot stand in for the CI server on the same host. The suffixed-capacity control keeps configured text representable without fabricating its byte magnitude." +// THE DISCRIMINATING PAIRS protect the distinction the carriers exist to express. A successful +// process-environment read with no assignment is positive evidence that the setting is unset; an +// unavailable read says the host never answered. Collapsing them to an Option would make the +// empty-observation narrow writable. The subject-binding witness separately proves the observations +// retain both which of two same-implementation instances was read and which endpoint-owning process +// supplied the environment, so a session server's 50 GiB setting cannot stand in for the CI server +// on the same host. The suffixed-capacity control keeps configured text representable without +// fabricating its byte magnitude. fn owner_fixture(pid: Nat) -> ProcessIdentity { ProcessIdentity { diff --git a/dag/test/claim/build_cache_endpoint_observe_test.dag b/dag/test/claim/build_cache_endpoint_observe_test.dag index f93ac2996a2..55b6a66d49c 100644 --- a/dag/test/claim/build_cache_endpoint_observe_test.dag +++ b/dag/test/claim/build_cache_endpoint_observe_test.dag @@ -3,11 +3,37 @@ module test.claim.build_cache_endpoint_observe import gunbc.build_cache_instance { ProcessIdentity } import extdeps.systemd.unit_file { systemd_unit_file_lines } -data ambiguous_type_name_import_note: String = "THIS MODULE IMPORTS ProcessIdentity EXPLICITLY BECAUSE THE BARE NAME IS AMBIGUOUS CORPUS-WIDE, AND THE AMBIGUITY RESOLVES SILENTLY. Two types carry that name -- gunbc.build_cache_instance ProcessIdentity (boot_id, pid, start_time) and extdeps.posix ProcessIdentity (id, command, parent) -- and a module with no import block resolves the bare name by last-import-wins rather than refusing, which is one of the three confirmed source-path construction holes DESIGN names beside the sole_constructor wall. The observable cost was measured here rather than reasoned about: a targeted compile of this entry resolved a closure that never loaded extdeps.posix and reported zero blocking diagnostics, while the whole-corpus witness floor loaded both and refused with `no field 'pid' on type 'ProcessIdentity'` at the assertion below. The import is therefore not decoration -- it is the only thing that makes this module's meaning independent of which other modules happen to be in the resolver's population. A green targeted compile is not evidence that a bare name is unambiguous; only a run whose population contains every homonym is." +// THIS MODULE IMPORTS ProcessIdentity EXPLICITLY BECAUSE THE BARE NAME IS AMBIGUOUS CORPUS-WIDE, +// AND THE AMBIGUITY RESOLVES SILENTLY. Two types carry that name -- gunbc.build_cache_instance +// ProcessIdentity (boot_id, pid, start_time) and extdeps.posix ProcessIdentity (id, command, +// parent) -- and a module with no import block resolves the bare name by last-import-wins rather +// than refusing, which is one of the three confirmed source-path construction holes DESIGN names +// beside the sole_constructor wall. The observable cost was measured here rather than reasoned +// about: a targeted compile of this entry resolved a closure that never loaded extdeps.posix and +// reported zero blocking diagnostics, while the whole-corpus witness floor loaded both and refused +// with `no field 'pid' on type 'ProcessIdentity'` at the assertion below. The import is therefore +// not decoration -- it is the only thing that makes this module's meaning independent of which +// other modules happen to be in the resolver's population. A green targeted compile is not evidence +// that a bare name is unambiguous; only a run whose population contains every homonym is. data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data endpoint_observe_witness_doc: String = "THE CONTROLS FOR THE PRODUCER THAT WAS MISSING. Every fixture below is READ TEXT in the shape the live commands emit, and every assertion runs the same decode the realize path runs -- gunbc.build_cache_endpoint_observe survey_build_cache_endpoint, then gunbc.build_cache_ensure admit_ensure_build_cache_instance -- so what is witnessed is the decision realization now makes, not a restatement of the fold's arms. The specimen text is authored from the receipts in docs/plans/build-cache-placement-receipt.md and from proc(5); the two host-only controls (that a second observation does not perturb the subject, and that no read starts a server) remain live receipts rather than witnesses here, because a hermetic fixture cannot falsify them.\n\nTHE DISCRIMINATING RED IS witness_unreadable_listener_refuses_rather_than_admitting. A decoder that treated 'the fd-holder walk printed nothing' and 'the fd-holder walk could not be run' as one state would answer 'no listener' to a question it never got an answer to, and the admission would then ADMIT -- writing a unit and restarting it on a host whose current state was never read. That witness and witness_absent_endpoint_is_admitted differ in exactly one input field and must land on opposite arms; if the HostRead coproduct were collapsed to a String, they would both go green on the admitted arm and the wall would be gone." +// THE CONTROLS FOR THE PRODUCER THAT WAS MISSING. Every fixture below is READ TEXT in the shape the +// live commands emit, and every assertion runs the same decode the realize path runs -- +// gunbc.build_cache_endpoint_observe survey_build_cache_endpoint, then gunbc.build_cache_ensure +// admit_ensure_build_cache_instance -- so what is witnessed is the decision realization now makes, +// not a restatement of the fold's arms. The specimen text is authored from the receipts in +// docs/plans/build-cache-placement-receipt.md and from proc(5); the two host-only controls (that a +// second observation does not perturb the subject, and that no read starts a server) remain live +// receipts rather than witnesses here, because a hermetic fixture cannot falsify them. +// +// THE DISCRIMINATING RED IS witness_unreadable_listener_refuses_rather_than_admitting. A decoder +// that treated 'the fd-holder walk printed nothing' and 'the fd-holder walk could not be run' as +// one state would answer 'no listener' to a question it never got an answer to, and the admission +// would then ADMIT -- writing a unit and restarting it on a host whose current state was never +// read. That witness and witness_absent_endpoint_is_admitted differ in exactly one input field and +// must land on opposite arms; if the HostRead coproduct were collapsed to a String, they would both +// go green on the admitted arm and the wall would be gone. fn observe_srv1_ci_instance() -> BuildCacheInstance { ci_cache_instance(host: "srv1") @@ -247,7 +273,17 @@ test fn witness_absent_endpoint_is_admitted() -> Bool { } } -data unreadable_listener_red_note: String = "THE DISCRIMINATING RED, AND WHAT IT IS DISCRIMINATING AGAINST. This witness and witness_absent_endpoint_is_admitted differ in ONE input: whether the fd-holder walk succeeded with empty output or failed. The first must be admitted (nothing holds the endpoint, a bind is clear) and the second must refuse (we do not know what holds it). Collapse gunbc.build_cache_endpoint_observe's HostRead coproduct to a bare String -- the shape this producer would have had if the reads were plumbed as text -- and both inputs become the empty string, both witnesses land on the admitted arm, and a host whose state could not be read gets a unit written and restarted on it. That is the empty-observation narrow, and this pair is what keeps it unwritable rather than merely unwritten. It is sharper under the /proc chain than it was under ss, because here the walk's EMPTY result is itself the evidence that licenses an unlink -- so the failed-versus-empty distinction is load-bearing twice over." +// THE DISCRIMINATING RED, AND WHAT IT IS DISCRIMINATING AGAINST. This witness and +// witness_absent_endpoint_is_admitted differ in ONE input: whether the fd-holder walk succeeded +// with empty output or failed. The first must be admitted (nothing holds the endpoint, a bind is +// clear) and the second must refuse (we do not know what holds it). Collapse +// gunbc.build_cache_endpoint_observe's HostRead coproduct to a bare String -- the shape this +// producer would have had if the reads were plumbed as text -- and both inputs become the empty +// string, both witnesses land on the admitted arm, and a host whose state could not be read gets a +// unit written and restarted on it. That is the empty-observation narrow, and this pair is what +// keeps it unwritable rather than merely unwritten. It is sharper under the /proc chain than it was +// under ss, because here the walk's EMPTY result is itself the evidence that licenses an unlink -- +// so the failed-versus-empty distinction is load-bearing twice over. test fn witness_unreadable_listener_refuses_rather_than_admitting() -> Bool { admission_is_refused_with_placement_unknown( @@ -262,7 +298,13 @@ test fn witness_unreadable_listener_refuses_rather_than_admitting() -> Bool { ) } -data sibling_instance_red_note: String = "THE SECOND DISCRIMINATING RED: srv1 AND srv2 EACH RUN TWO CACHE INSTANCES. /var/lib/ctrl/sccache-ci/server.sock is the CI instance and /var/lib/ctrl/sccache/server.sock is the session instance, and the second is a PREFIX-ADJACENT path of the first's parent directory. A decode matching the path column by prefix or by `contains` would read the session server as the CI endpoint's owner and derive placement from the wrong process entirely. This fixture presents a table in which ONLY the sibling is listening; the CI endpoint must come back with no listen entry." +// THE SECOND DISCRIMINATING RED: srv1 AND srv2 EACH RUN TWO CACHE INSTANCES. +// /var/lib/ctrl/sccache-ci/server.sock is the CI instance and /var/lib/ctrl/sccache/server.sock is +// the session instance, and the second is a PREFIX-ADJACENT path of the first's parent directory. A +// decode matching the path column by prefix or by `contains` would read the session server as the +// CI endpoint's owner and derive placement from the wrong process entirely. This fixture presents a +// table in which ONLY the sibling is listening; the CI endpoint must come back with no listen +// entry. test fn witness_sibling_instance_is_not_read_as_this_endpoint() -> Bool { match observe_listen_inode(unix_text: observe_proc_net_unix_sibling_instance_only_text) { @@ -322,7 +364,18 @@ test fn witness_one_owner_yields_its_pid() -> Bool { } } -data srv4_stale_socket_note: String = "srv4's SHAPE, AND IT IS NOW AN ADMITTED UNLINK RATHER THAN A PERMANENT REFUSAL. Observed 2026-08-01: a socket file present, no listener, no process holding it, and every bind failing with 'Address in use (os error 98)' -- srv4 uncached for roughly a week for that reason alone. All four clauses of the stale-socket observer contract are established by this producer's reads (stat says socket; no LISTEN entry for the exact path; the fd walk resolves no holder for the file's inode; one boot id across the pass), so the path axis returns EndpointStaleSocket and the admission returns Admitted behind an EndpointClearedByUnlink preflight.\n\nThe PAIRED witness below is what makes this safe rather than merely permissive: the same fixture with a HOLDER present must NOT unlink. Without that pair this witness would pass equally well against a producer that never checked clause (3) at all, which is precisely the producer this PR replaced." +// srv4's SHAPE, AND IT IS NOW AN ADMITTED UNLINK RATHER THAN A PERMANENT REFUSAL. Observed +// 2026-08-01: a socket file present, no listener, no process holding it, and every bind failing +// with 'Address in use (os error 98)' -- srv4 uncached for roughly a week for that reason alone. +// All four clauses of the stale-socket observer contract are established by this producer's reads +// (stat says socket; no LISTEN entry for the exact path; the fd walk resolves no holder for the +// file's inode; one boot id across the pass), so the path axis returns EndpointStaleSocket and the +// admission returns Admitted behind an EndpointClearedByUnlink preflight. +// +// The PAIRED witness below is what makes this safe rather than merely permissive: the same fixture +// with a HOLDER present must NOT unlink. Without that pair this witness would pass equally well +// against a producer that never checked clause (3) at all, which is precisely the producer this PR +// replaced. test fn witness_stale_socket_is_admitted_behind_an_unlink() -> Bool { match observe_admission_full( @@ -341,7 +394,32 @@ test fn witness_stale_socket_is_admitted_behind_an_unlink() -> Bool { } } -data held_without_listening_fixture_note: String = "THE CGROUP IN THE NEXT WITNESS IS THE RETIRED SLOT, NOT OUR UNIT, AND THE SUBSTITUTION IS THE FINDING THAT PRODUCED A CONTRACT CHANGE. Written first with observe_managed_unit_cgroup_text it FAILED, and the failure was not in the decode: a holder pid whose cgroup IS gunbc-build-cache-ci.service made placement_already_converged true, and gunbc.build_cache_ensure admit_ensure_build_cache_instance answered EnsureAlreadyConverged from the placement axis WITHOUT ever consulting the path. So the path-conflict property this witness exists to pin was unobservable through a converged placement, and the fixture had to name an owner that is not ours to reach the arm at all.\n\nTHAT SHORT-CIRCUIT IS NOW REPAIRED (2026-08-22), and this paragraph is rewritten rather than annotated because it previously said the opposite in the present tense -- that the gap was recorded here rather than closed -- which is the stale claim a carrier recording a measured boundary must never keep. EnsureAlreadyConverged now requires BOTH axes: the endpoint owner is our intended managed unit AND the path is being LISTENED on. Our own unit holding its socket open while not listening on it therefore REFUSES with the unit named, where it previously converged over an unreachable cache. The discriminating pair for that decision lives with the admission it constrains, in test.claim.build_cache_ensure converged_means_serving_doc, rather than here.\n\nWHAT THIS FIXTURE STILL PINS IS UNCHANGED, and it is a different property from the one above: a socket held open by a WRONG owner that is not listening REFUSES with a path conflict and is NOT unlinked. Its sibling witness_stale_socket_is_admitted_behind_an_unlink differs in exactly one input -- the fd-holder walk is empty rather than naming a pid -- and lands on the admitted-unlink arm. The pair is the same-run empty/non-empty control the unlink licence requires: the EMPTY walk is what authorizes destroying a file, so it is only readable as evidence beside a non-empty walk that provably refuses. The foreign-owner cgroup is now a deliberate choice about WHICH property this witness holds, not a workaround for an axis that swallowed it." +// THE CGROUP IN THE NEXT WITNESS IS THE RETIRED SLOT, NOT OUR UNIT, AND THE SUBSTITUTION IS THE +// FINDING THAT PRODUCED A CONTRACT CHANGE. Written first with observe_managed_unit_cgroup_text it +// FAILED, and the failure was not in the decode: a holder pid whose cgroup IS +// gunbc-build-cache-ci.service made placement_already_converged true, and gunbc.build_cache_ensure +// admit_ensure_build_cache_instance answered EnsureAlreadyConverged from the placement axis WITHOUT +// ever consulting the path. So the path-conflict property this witness exists to pin was +// unobservable through a converged placement, and the fixture had to name an owner that is not ours +// to reach the arm at all. +// +// THAT SHORT-CIRCUIT IS NOW REPAIRED (2026-08-22), and this paragraph is rewritten rather than +// annotated because it previously said the opposite in the present tense -- that the gap was +// recorded here rather than closed -- which is the stale claim a carrier recording a measured +// boundary must never keep. EnsureAlreadyConverged now requires BOTH axes: the endpoint owner is +// our intended managed unit AND the path is being LISTENED on. Our own unit holding its socket open +// while not listening on it therefore REFUSES with the unit named, where it previously converged +// over an unreachable cache. The discriminating pair for that decision lives with the admission it +// constrains, in test.claim.build_cache_ensure converged_means_serving_doc, rather than here. +// +// WHAT THIS FIXTURE STILL PINS IS UNCHANGED, and it is a different property from the one above: a +// socket held open by a WRONG owner that is not listening REFUSES with a path conflict and is NOT +// unlinked. Its sibling witness_stale_socket_is_admitted_behind_an_unlink differs in exactly one +// input -- the fd-holder walk is empty rather than naming a pid -- and lands on the admitted-unlink +// arm. The pair is the same-run empty/non-empty control the unlink licence requires: the EMPTY walk +// is what authorizes destroying a file, so it is only readable as evidence beside a non-empty walk +// that provably refuses. The foreign-owner cgroup is now a deliberate choice about WHICH property +// this witness holds, not a workaround for an axis that swallowed it. test fn witness_socket_held_open_without_listening_is_not_unlinked() -> Bool { match observe_admission_full( @@ -364,7 +442,26 @@ test fn witness_socket_held_open_without_listening_is_not_unlinked() -> Bool { } } -data inverted_pinning_witness_note: String = "THIS WITNESS CHANGED DIRECTION ON 2026-08-22, AND THE FILE SAYS SO RATHER THAN THE HISTORY. It was authored by the wiring PR as witness_our_own_unit_holding_an_unlistened_socket_reads_converged, and it asserted EnsureAlreadyConverged over EXACTLY THIS FIXTURE: our own unit holding the endpoint socket open with no LISTEN entry for it. That PR pinned the behaviour deliberately and said in its own note that pinning is not endorsement -- changing what ALREADY-CONVERGED means was a decision about the admission contract, not a decision a consumer PR takes on its way past.\n\nThe decision was taken here: converged requires a LISTENING path, so the same fixture must now REFUSE, and the assertion is inverted rather than deleted. Deleting it would have removed the only end-to-end evidence for this exact host state -- read text in, admission arm out -- and left the new contract asserted only against hand-built placement and path values. It is now the regression control for the contract it used to contradict: if the placement-first short-circuit is ever reintroduced, this witness reds first and reds from the producer side.\n\nITS SAME-RUN NONZERO IS witness_managed_unit_owner_is_already_converged. That witness runs the identical fixture with ONE field changed -- observe_proc_net_unix_listening_text instead of observe_proc_net_unix_no_listen_text -- and must still converge. Without it this witness would pass equally well against an admission that had simply stopped converging at all, which is a wall that refuses everything and establishes nothing." +// THIS WITNESS CHANGED DIRECTION ON 2026-08-22, AND THE FILE SAYS SO RATHER THAN THE HISTORY. It +// was authored by the wiring PR as +// witness_our_own_unit_holding_an_unlistened_socket_reads_converged, and it asserted +// EnsureAlreadyConverged over EXACTLY THIS FIXTURE: our own unit holding the endpoint socket open +// with no LISTEN entry for it. That PR pinned the behaviour deliberately and said in its own note +// that pinning is not endorsement -- changing what ALREADY-CONVERGED means was a decision about the +// admission contract, not a decision a consumer PR takes on its way past. +// +// The decision was taken here: converged requires a LISTENING path, so the same fixture must now +// REFUSE, and the assertion is inverted rather than deleted. Deleting it would have removed the +// only end-to-end evidence for this exact host state -- read text in, admission arm out -- and left +// the new contract asserted only against hand-built placement and path values. It is now the +// regression control for the contract it used to contradict: if the placement-first short-circuit +// is ever reintroduced, this witness reds first and reds from the producer side. +// +// ITS SAME-RUN NONZERO IS witness_managed_unit_owner_is_already_converged. That witness runs the +// identical fixture with ONE field changed -- observe_proc_net_unix_listening_text instead of +// observe_proc_net_unix_no_listen_text -- and must still converge. Without it this witness would +// pass equally well against an admission that had simply stopped converging at all, which is a wall +// that refuses everything and establishes nothing. test fn witness_our_own_unit_holding_an_unlistened_socket_refuses_as_not_serving() -> Bool { match observe_admission_full( @@ -387,7 +484,40 @@ test fn witness_our_own_unit_holding_an_unlistened_socket_refuses_as_not_serving } } -data transitional_states_note: String = "WHAT THE CONTRACT DOES WITH THE STATES BETWEEN PRESENT AND SERVING, measured through the decode rather than reasoned about, because the obvious objection to requiring a LISTENING path is that a unit seconds from serving gets rewritten and restarted -- the non-idempotence this vertical exists to remove, reintroduced from the other side. It does not happen, and the reason is structural rather than lucky: the tightened axis produces only REFUSALS, and a refusal writes nothing and restarts nothing. No arm anywhere in the change turns a converge into a write.\n\nTHE THREE TRANSITIONAL HOST STATES, and where each lands. (1) The unit has started and its process has not yet created the socket: the path does not exist and the fd walk resolves no holder, so the observation is EndpointAbsent, placement is ServerPlacementAbsent, and the admission ADMITS a write -- exactly as it did before this change, because placement is not ours and the tightened axis is never consulted. (2) A restart is in flight, the old process is gone and its socket file remains: no LISTEN entry and no holder, which is the stale-socket shape, so the admission admits behind an unlink -- again unchanged, again on a not-ours placement. Both of those are pre-existing write arms on a transitional state and neither is this change to fix; naming them is the point, since a reader looking for thrash will find it there and should not attribute it here. (3) The one state this change does move: a live process of OUR unit holds the socket open with no LISTEN entry -- the bind-before-listen window, and equally the wedged server that motivated the change. It converged silently before and refuses now.\n\nWHY (3) IS NOT THRASH EVEN WHEN IT IS A RACE. The window between bind and listen inside one process is microseconds and closes on its own; a refusal in it costs one loud, located diagnostic on a pass that mutated nothing, and the next convergence pass converges. The wedged server holds the same shape indefinitely. The two are indistinguishable from outside -- which is precisely why the arm must refuse rather than guess: refusing is correct for the wedged case and merely early for the race, while converging is wrong for the wedged case and only accidentally right for the race. Under DESIGN section 5 that asymmetry decides it, and the residual cost is one bounded false refusal rather than a host mutation.\n\nEach of the three is decoded by a witness in this file rather than argued for here: state (1) by witness_absent_endpoint_is_admitted, state (2) by witness_stale_socket_is_admitted_behind_an_unlink, state (3) by witness_our_own_unit_holding_an_unlistened_socket_refuses_as_not_serving above -- so the claim that only (3) moved is checked by the same run that checks the contract." +// WHAT THE CONTRACT DOES WITH THE STATES BETWEEN PRESENT AND SERVING, measured through the decode +// rather than reasoned about, because the obvious objection to requiring a LISTENING path is that a +// unit seconds from serving gets rewritten and restarted -- the non-idempotence this vertical +// exists to remove, reintroduced from the other side. It does not happen, and the reason is +// structural rather than lucky: the tightened axis produces only REFUSALS, and a refusal writes +// nothing and restarts nothing. No arm anywhere in the change turns a converge into a write. +// +// THE THREE TRANSITIONAL HOST STATES, and where each lands. (1) The unit has started and its +// process has not yet created the socket: the path does not exist and the fd walk resolves no +// holder, so the observation is EndpointAbsent, placement is ServerPlacementAbsent, and the +// admission ADMITS a write -- exactly as it did before this change, because placement is not ours +// and the tightened axis is never consulted. (2) A restart is in flight, the old process is gone +// and its socket file remains: no LISTEN entry and no holder, which is the stale-socket shape, so +// the admission admits behind an unlink -- again unchanged, again on a not-ours placement. Both of +// those are pre-existing write arms on a transitional state and neither is this change to fix; +// naming them is the point, since a reader looking for thrash will find it there and should not +// attribute it here. (3) The one state this change does move: a live process of OUR unit holds the +// socket open with no LISTEN entry -- the bind-before-listen window, and equally the wedged server +// that motivated the change. It converged silently before and refuses now. +// +// WHY (3) IS NOT THRASH EVEN WHEN IT IS A RACE. The window between bind and listen inside one +// process is microseconds and closes on its own; a refusal in it costs one loud, located diagnostic +// on a pass that mutated nothing, and the next convergence pass converges. The wedged server holds +// the same shape indefinitely. The two are indistinguishable from outside -- which is precisely why +// the arm must refuse rather than guess: refusing is correct for the wedged case and merely early +// for the race, while converging is wrong for the wedged case and only accidentally right for the +// race. Under DESIGN section 5 that asymmetry decides it, and the residual cost is one bounded +// false refusal rather than a host mutation. +// +// Each of the three is decoded by a witness in this file rather than argued for here: state (1) by +// witness_absent_endpoint_is_admitted, state (2) by +// witness_stale_socket_is_admitted_behind_an_unlink, state (3) by +// witness_our_own_unit_holding_an_unlistened_socket_refuses_as_not_serving above -- so the claim +// that only (3) moved is checked by the same run that checks the contract. test fn witness_stale_socket_path_axis_is_stale_not_absent() -> Bool { match observe_path_state_full( @@ -449,7 +579,12 @@ test fn witness_stat_type_word_decodes_socket_and_absence() -> Bool { } } -data starttime_parse_red_note: String = "THE ADVERSARIAL COMM IS THE POINT OF THIS WITNESS. /proc/PID/stat field 2 is the executable name in parentheses and it may contain spaces AND parentheses, so a decoder that split the whole line on spaces reads the wrong field for exactly the processes whose names are hostile. proc(5) fixes the shape -- fields 3 onward follow the FINAL ')' -- and the second fixture below carries a comm of '(sc cache (x) )' whose naive split lands three tokens off. Both fixtures must yield their own start time, so the witness reds if the parse ever regresses to splitting the line." +// THE ADVERSARIAL COMM IS THE POINT OF THIS WITNESS. /proc/PID/stat field 2 is the executable name +// in parentheses and it may contain spaces AND parentheses, so a decoder that split the whole line +// on spaces reads the wrong field for exactly the processes whose names are hostile. proc(5) fixes +// the shape -- fields 3 onward follow the FINAL ')' -- and the second fixture below carries a comm +// of '(sc cache (x) )' whose naive split lands three tokens off. Both fixtures must yield their own +// start time, so the witness reds if the parse ever regresses to splitting the line. test fn witness_starttime_reads_after_the_final_paren() -> Bool { gunbc.build_cache_endpoint_observe.starttime_of_proc_stat_text(text: observe_proc_stat_text) == "79870020" @@ -484,7 +619,30 @@ test fn witness_unreachable_host_reaches_placement_unknown_through_the_ordinary_ ) } -data empty_licensing_probe_rule_note: String = "STANDING RULE FOR THIS LANE (eager-crane-282, 2026-08-21): EVERY PROBE THAT LICENSES AN ACTION ON AN EMPTY RESULT CARRIES A SAME-RUN NON-EMPTY CONTROL. The fd-holder walk is the specimen that produced the rule. Its EMPTY result is the evidence that licenses unlinking a socket file, so a walk that silently matches nothing does not produce a refusal, it produces a DATA-LOSS defect: it authorizes deleting a live process's socket while reporting that nothing holds it. That is a strictly worse failure class than the refusal defects this module's other arms guard, and it is not hypothetical -- it is exactly what the bracketed find pattern does, and it is what made an earlier revision of this lane conclude the walk was impossible.\n\nTHE PAIRS THAT DISCHARGE THE RULE HERE, each two witnesses over one fixture differing in one field: witness_stale_socket_is_admitted_behind_an_unlink (walk empty -> unlink admitted) against witness_socket_held_open_without_listening_is_not_unlinked (walk non-empty -> refused); and witness_absent_endpoint_is_admitted (walk empty -> admitted) against witness_unreadable_listener_refuses_rather_than_admitting (walk FAILED -> refused). The first pair proves the empty result is read, the second proves empty and failed are different states. Below them sits the construction check on the emitted pattern itself, because both pairs run against fixture text and neither can see the argv that produces it on a real host." +// STANDING RULE FOR THIS LANE (eager-crane-282, 2026-08-21): EVERY PROBE THAT LICENSES AN ACTION ON +// AN EMPTY RESULT CARRIES A SAME-RUN NON-EMPTY CONTROL. The fd-holder walk is the specimen that +// produced the rule. Its EMPTY result is the evidence that licenses unlinking a socket file, so a +// walk that silently matches nothing does not produce a refusal, it produces a DATA-LOSS defect: it +// authorizes deleting a live process's socket while reporting that nothing holds it. That is a +// strictly worse failure class than the refusal defects this module's other arms guard, and it is +// not hypothetical -- it is exactly what the bracketed find pattern does, and it is what made an +// earlier revision of this lane conclude the walk was impossible. +// +// THE PAIRS THAT DISCHARGE THE RULE HERE, each two witnesses over one fixture differing in one +// field: witness_stale_socket_is_admitted_behind_an_unlink (walk empty -> unlink admitted) against +// witness_socket_held_open_without_listening_is_not_unlinked (walk non-empty -> refused); and +// witness_absent_endpoint_is_admitted (walk empty -> admitted) against +// witness_unreadable_listener_refuses_rather_than_admitting (walk FAILED -> refused). The first +// pair proves the empty result is read, the second proves empty and failed are different states. +// Below them sits the construction check on the emitted pattern itself, because both pairs run +// against fixture text and neither can see the argv that produces it on a real host. + +// WHY THE ARGV IS ASSERTED AND NOT ONLY THE DECODE. Every other witness in this file runs the +// decode against fixture text, so all of them stay green if the argv that gathers that text on a +// real host regresses to `-lname "socket:[N]"` -- which silently matches nothing, which the decode +// then reads as a licensed unlink. The fixtures cannot see that; only the argv can. Asserting the +// exact pattern also pins the two shapes that would reintroduce a shell (an `sh -c` wrapper), +// because a shell would expand the glob itself and this lane may not grow emitted shell. test fn witness_holder_argv_cannot_regress_to_the_bracket_form() -> Bool { let argv = argv_words(command: gunbc.host_effect_realize.socket_inode_holder_command(inode: "3894042" as NonEmptyStr)) @@ -498,5 +656,3 @@ test fn witness_holder_argv_cannot_regress_to_the_bracket_form() -> Bool { && !string_list_contains(xs: argv, wanted: "sh") && !string_list_contains(xs: argv, wanted: "-c") } - -data holder_argv_construction_note: String = "WHY THE ARGV IS ASSERTED AND NOT ONLY THE DECODE. Every other witness in this file runs the decode against fixture text, so all of them stay green if the argv that gathers that text on a real host regresses to `-lname \"socket:[N]\"` -- which silently matches nothing, which the decode then reads as a licensed unlink. The fixtures cannot see that; only the argv can. Asserting the exact pattern also pins the two shapes that would reintroduce a shell (an `sh -c` wrapper), because a shell would expand the glob itself and this lane may not grow emitted shell." diff --git a/dag/test/claim/build_cache_endpoint_path_test.dag b/dag/test/claim/build_cache_endpoint_path_test.dag index 8c761e1cc98..543c47fdfe4 100644 --- a/dag/test/claim/build_cache_endpoint_path_test.dag +++ b/dag/test/claim/build_cache_endpoint_path_test.dag @@ -2,7 +2,12 @@ module test.claim.build_cache_endpoint_path data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data endpoint_path_wall_doc: String = "THE UNLINK ADMISSION'S ACCEPTANCE SET. The subject is srv4, observed 2026-08-01: a stale server.sock with no listener behind it, every new server failing with 'Address in use (os error 98)', the host uncached since roughly 2026-07-26. Exactly one of the five path states licenses removing that file, and the controls below assert the other four refuse — but the load-bearing ones are the two that assert a DIFFERENCE from ExecStartPre=rm -f, because a wall that refuses where the naive fix would also have been harmless has not been shown to be worth anything." +// THE UNLINK ADMISSION'S ACCEPTANCE SET. The subject is srv4, observed 2026-08-01: a stale +// server.sock with no listener behind it, every new server failing with 'Address in use (os error +// 98)', the host uncached since roughly 2026-07-26. Exactly one of the five path states licenses +// removing that file, and the controls below assert the other four refuse — but the load-bearing +// ones are the two that assert a DIFFERENCE from ExecStartPre=rm -f, because a wall that refuses +// where the naive fix would also have been harmless has not been shown to be worth anything. fn srv4_instance() -> BuildCacheInstance { ci_cache_instance(host: "srv4") @@ -80,7 +85,11 @@ test fn witness_a_stale_read_cannot_license_an_unlink() -> Bool { (stale_read == false) && (unknown_currency == false) } -data currency_arms_are_not_graded_doc: String = "ObservationStale and ObservationCurrencyUnknown must BOTH refuse, and they are asserted together rather than separately because the tempting shape is to grade them — to treat 'I do not know if this read is current' as weaker evidence than 'I know it is old' and let it through. It is the same evidence. An arm that admitted Unknown would be the absorbing fallback, and it would fire exactly when /proc is least readable, which is when a bind race is most likely." +// ObservationStale and ObservationCurrencyUnknown must BOTH refuse, and they are asserted together +// rather than separately because the tempting shape is to grade them — to treat 'I do not know if +// this read is current' as weaker evidence than 'I know it is old' and let it through. It is the +// same evidence. An arm that admitted Unknown would be the absorbing fallback, and it would fire +// exactly when /proc is least readable, which is when a bind race is most likely. test fn witness_a_tcp_endpoint_has_no_stale_socket_state() -> Bool { let tcp = BuildCacheInstance { @@ -102,7 +111,11 @@ test fn witness_a_tcp_endpoint_has_no_stale_socket_state() -> Bool { ) == false } -data red_control_doc: String = "The RED control asserted as a whole rather than per-state. unconditional_unlink_sketch is ExecStartPre=rm -f written as a predicate; it answers true in all five path states. This witness asserts that it disagrees with the admission in at least the two destructive states, so if someone later 'simplifies' the admission into an unconditional yes, this reds. Asserting the sketch alone would not: a control that only describes the bad behaviour never fails." +// The RED control asserted as a whole rather than per-state. unconditional_unlink_sketch is +// ExecStartPre=rm -f written as a predicate; it answers true in all five path states. This witness +// asserts that it disagrees with the admission in at least the two destructive states, so if +// someone later 'simplifies' the admission into an unconditional yes, this reds. Asserting the +// sketch alone would not: a control that only describes the bad behaviour never fails. test fn witness_the_unconditional_sketch_differs_where_it_is_destructive() -> Bool { let states = [ diff --git a/dag/test/claim/build_cache_ensure_test.dag b/dag/test/claim/build_cache_ensure_test.dag index 58d80ac12b6..3a7028f3e55 100644 --- a/dag/test/claim/build_cache_ensure_test.dag +++ b/dag/test/claim/build_cache_ensure_test.dag @@ -6,7 +6,19 @@ import gunbc.build_cache_ensure { data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data ensure_acceptance_doc: String = "THE ACCEPTANCE SET FOR UNIT GENERATION AND THE ENSURE ADMISSION. Two of these are grounded on a live sudo capture of srv1 taken 2026-08-01 rather than on invented fixtures: the rendered unit is asserted against the environment the CI server running THAT DAY actually carried, and the two hosts' observed states as of that capture are asserted to reach opposite admissions. The capture also independently confirmed the model: BuildCacheInstance already declared intended_principal ghrunner for CI and briansrls for the session instance, and the servers running then ran as exactly those users.\n\nEVERY SENTENCE ABOVE IS PAST TENSE ON PURPOSE, AND THAT IS A REPAIR RATHER THAN A STYLE CHOICE. Measured 2026-08-25T18:43Z, no sccache process runs on any of the four hosts and the CI socket on each is present with zero listeners, so a row asserting what `the running CI server carries` would have no subject at all. The fixtures stay exactly as captured: they are a dated specimen of a real host state, which is what makes them a stronger acceptance set than invented ones, and re-capturing them against today's empty hosts would delete the discriminating input rather than refresh it." +// THE ACCEPTANCE SET FOR UNIT GENERATION AND THE ENSURE ADMISSION. Two of these are grounded on a +// live sudo capture of srv1 taken 2026-08-01, not invented fixtures: the rendered unit is asserted +// against the environment the CI server running THAT DAY carried, and the two hosts' observed +// states as of that capture are asserted to reach opposite admissions. The capture also confirmed +// the model: BuildCacheInstance already declared intended_principal ghrunner for CI and briansrls +// for the session instance, and the servers then ran as exactly those users. +// +// EVERY SENTENCE ABOVE IS PAST TENSE ON PURPOSE, A REPAIR RATHER THAN A STYLE CHOICE. Measured +// 2026-08-25T18:43Z, no sccache process runs on any of the four hosts and each CI socket is present +// with zero listeners, so a row asserting what `the running CI server carries` would have no +// subject. The fixtures stay as captured: a dated specimen of a real host state is a stronger +// acceptance set than invented ones, and re-capturing against today's empty hosts would delete the +// discriminating input rather than refresh it. fn ci() -> BuildCacheInstance { ci_cache_instance(host: "srv1") } fn session() -> BuildCacheInstance { session_cache_instance(host: "srv1") } @@ -25,7 +37,17 @@ fn srv1_stranded_owner() -> ProcessIdentity { } } -data captured_base_doc: String = "Asserted against the 2026-08-01 live capture, line for line. srv1's CI server carried SCCACHE_DIR=/var/lib/ctrl/sccache-ci, SCCACHE_ERROR_LOG under the same directory, SCCACHE_IDLE_TIMEOUT=0, SCCACHE_SERVER_UDS=/var/lib/ctrl/sccache-ci/server.sock and SCCACHE_START_SERVER=1, and ran as ghrunner. The generated unit must reproduce that environment, and the REASON given here has changed even though the requirement has not. It was: the cutover replaces a server that is currently working -- wrongly parented, but working -- so changing the cache directory or the socket path would cold-start every consumer rather than re-parenting the one they already use. Measured 2026-08-25T18:43Z there is no server left to re-parent on any host, so what the paths now protect is the CACHE TREE and the endpoint every client is already configured against, not a live process. The pinned values are unchanged because the reason weakened rather than reversed: a unit that invents a new directory strands whatever the old one holds either way." +// Asserted against the 2026-08-01 live capture, line for line. srv1's CI server carried +// SCCACHE_DIR=/var/lib/ctrl/sccache-ci, SCCACHE_ERROR_LOG under the same directory, +// SCCACHE_IDLE_TIMEOUT=0, SCCACHE_SERVER_UDS=/var/lib/ctrl/sccache-ci/server.sock and +// SCCACHE_START_SERVER=1, and ran as ghrunner. The generated unit must reproduce that environment; +// the REASON has changed though the requirement has not. It was: the cutover replaces a server +// that is working -- wrongly parented, but working -- so changing the cache directory or socket +// path would cold-start every consumer rather than re-parent the one they use. Measured +// 2026-08-25T18:43Z there is no server left to re-parent on any host, so the paths now protect the +// CACHE TREE and the endpoint every client is configured against, not a live process. The pinned +// values are unchanged because the reason weakened rather than reversed: a unit that invents a new +// directory strands whatever the old one holds either way. test fn witness_the_generated_unit_reproduces_the_captured_environment() -> Bool { let u = ci_unit() @@ -39,17 +61,17 @@ test fn witness_the_generated_unit_reproduces_the_captured_environment() -> Bool && unit_declares_line(lines: u, needle: "Environment=SCCACHE_ERROR_LOG=/var/lib/ctrl/sccache-ci/sccache-server.log") } -// THE Slice= LINE LEFT THIS WITNESS BECAUSE IT WAS NEVER PART OF THE CAPTURE. This witness is named for -// what the 2026-08-01 srv1 capture contained, and that capture was an ENVIRONMENT: SCCACHE_DIR, +// THE Slice= LINE LEFT THIS WITNESS BECAUSE IT WAS NEVER PART OF THE CAPTURE. This witness is named +// for what the 2026-08-01 srv1 capture contained, and that was an ENVIRONMENT: SCCACHE_DIR, // SCCACHE_ERROR_LOG, SCCACHE_IDLE_TIMEOUT, SCCACHE_SERVER_UDS, SCCACHE_START_SERVER and a -// SCCACHE_STARTUP_NOTIFY temp path whose presence is the tell that NO UNIT EXISTED on that host at all. -// A Slice= assertion was therefore never reproducing a captured line -- it was pinning our own declared -// intent inside a fidelity witness, which is why it broke the moment that intent correctly became -// conditional on the topology. +// SCCACHE_STARTUP_NOTIFY temp path whose presence is the tell that NO UNIT EXISTED on that host. +// A Slice= assertion never reproduced a captured line -- it pinned our own declared intent inside +// a fidelity witness, which is why it broke the moment that intent correctly became conditional +// on the topology. // -// It is not deleted, it is moved to the both-arms form beside it, mirroring the capacity idiom this file -// already uses: an assertion that only ever checks one arm cannot see a render that emits the line -// unconditionally, which is exactly the defect the placement carrier was introduced to make unwritable. +// It is moved, not deleted, to the both-arms form beside it, mirroring the capacity idiom this file +// uses: an assertion checking only one arm cannot see a render that emits the line unconditionally, +// the defect the placement carrier was introduced to make unwritable. test fn witness_the_slice_line_follows_the_declared_placement_both_ways() -> Bool { let undeclared = render_build_cache_unit( instance: instance_with_pool(base: ci(), placement: CompilePoolInRunnerSlots), @@ -77,7 +99,13 @@ fn instance_with_pool(base: BuildCacheInstance, placement: CompilePoolPlacement) } } -data absent_capacity_doc: String = "THE LOAD-BEARING PAIR. CI's intended_capacity is Absent and the 2026-08-01 live capture is why: srv1's CI server carried NO SCCACHE_CACHE_SIZE at all, so the 10 GiB it ran under was sccache's built-in default rather than a decision. Rendering a default here would fabricate a decision nobody made AND freeze it -- once written into a generated unit it is indistinguishable from an intended value, and the tracked gap closes silently. Both halves are asserted: Absent must omit the line, Present must emit it, because a render that omitted it unconditionally would pass the first assertion while silently dropping the session instance's real 50G cap." +// THE LOAD-BEARING PAIR. CI's intended_capacity is Absent because the 2026-08-01 live capture +// showed srv1's CI server carried NO SCCACHE_CACHE_SIZE, so the 10 GiB it ran under was sccache's +// built-in default, not a decision. Rendering a default would fabricate a decision nobody made AND +// freeze it -- once in a generated unit it is indistinguishable from an intended value, and the +// tracked gap closes silently. Both halves are asserted: Absent must omit the line, Present must +// emit it, because an unconditional omission would pass the first while silently dropping the +// session instance's real 50G cap. test fn witness_an_absent_capacity_omits_the_line_and_a_present_one_emits_it() -> Bool { let ci_lines = ci_unit() @@ -94,7 +122,12 @@ test fn witness_two_instances_on_one_host_render_different_principals() -> Bool && (unit_declares_line(lines: session_lines, needle: "User=ghrunner") == false) } -data differing_principals_doc: String = "One host, two instances, two uids -- the fact that makes intended_principal a field rather than a host constant. The captured srv1 runs its CI server as ghrunner and its session server as briansrls. This matters beyond tidiness: ctrl-sccache.service's own header records that the UDS is srwxr-xr-x, so only the owning uid can connect() and a cross-uid client fails SILENTLY, falling back to a per-container server. A render that collapsed the principal to one per host would produce a unit that starts cleanly and serves nobody." +// One host, two instances, two uids -- why intended_principal is a field rather than a host +// constant. The captured srv1 runs its CI server as ghrunner and its session server as briansrls. +// ctrl-sccache.service's own header records that the UDS is srwxr-xr-x, so only the owning uid +// can connect() and a cross-uid client fails SILENTLY, falling back to a per-container server. A +// render collapsing the principal to one per host would produce a unit that starts cleanly and +// serves nobody. test fn witness_the_slice_is_sized_from_the_supplied_authority() -> Bool { let s = render_compile_pool_slice( @@ -111,7 +144,11 @@ test fn witness_the_runner_dropin_orders_after_the_cache_unit() -> Bool { && unit_declares_line(lines: d, needle: "After=gunbc-build-cache-ci.service") } -data ensure_admission_doc: String = "The ensure admission over the four states the fleet was actually in on 2026-08-01. srv1: a live server in RETIRED slot srv1-10 holding the endpoint -- refuses, because evicting a live wrong owner strands the in-flight compiles that are its children and is a different operation from ensuring a unit exists. srv4: a stale socket with no listener -- admitted, with the unlink required first. Neither is a constructed example." +// The ensure admission over the states the fleet was actually in on 2026-08-01. srv1: a live +// server in RETIRED slot srv1-10 holding the endpoint -- refuses, because evicting a live wrong +// owner strands the in-flight compiles that are its children and is a different operation from +// ensuring a unit exists. srv4: a stale socket with no listener -- admitted, unlink required first. +// Neither is a constructed example. fn ensure_for(placement: BuildCacheServerPlacement, path: EndpointPathState) -> EnsureBuildCacheAdmission { admit_ensure_build_cache_instance( @@ -148,7 +185,11 @@ test fn witness_a_clear_path_is_admitted_without_an_unlink() -> Bool { ensure_yields_unit(admission: a) && (ensure_requires_unlink_first(admission: a) == false) } -data idempotence_doc: String = "The reconcile property. If the intended unit already owns the endpoint there is no hunk, and re-rendering plus restarting would tear down a healthy cache and re-cold every compile on the host to reach the state it was already in -- the most expensive possible no-op, firing on every convergence pass. Asserted as BOTH converged AND not-yields-unit, because an arm that reported converged while still emitting a unit would read as idempotent and behave destructively." +// The reconcile property. If the intended unit already owns the endpoint there is no hunk; +// re-rendering plus restarting would tear down a healthy cache and re-cold every compile on the +// host to reach the state it was already in -- the most expensive possible no-op, on every +// convergence pass. Asserted as BOTH converged AND not-yields-unit, because an arm reporting +// converged while still emitting a unit would read as idempotent and behave destructively. test fn witness_an_already_managed_endpoint_is_converged_and_emits_nothing() -> Bool { let a = ensure_for( @@ -158,7 +199,23 @@ test fn witness_an_already_managed_endpoint_is_converged_and_emits_nothing() -> build_cache_ensure_is_converged(admission: a) && (ensure_yields_unit(admission: a) == false) } -data converged_means_serving_doc: String = "THE DISCRIMINATING PAIR FOR THE CONTRACT DECISION. witness_an_already_managed_endpoint_is_converged_and_emits_nothing above and witness_our_unit_holding_a_dead_socket_is_not_converged below differ in exactly ONE input -- the path state under an identical ServerManagedUnitOwned placement -- and must land on opposite arms. That is the whole content of the decision: ownership answers WHO holds the endpoint, the path answers WHETHER IT IS SERVED, and a converged verdict needs both. Under the placement-first short-circuit that preceded this, the second witness went green on the CONVERGED arm, which is a host with a wedged server and an unreachable cache reported as needing nothing done. The specimen is not hypothetical: gunbc.build_cache_endpoint_observe socket_owner_path_state produces exactly this state -- a socket held open by a live fd-holder with no listen entry at the path -- and test.claim.build_cache_endpoint_observe held_without_listening_fixture_note recorded that its own fixture had to name a FOREIGN owner to reach the path-conflict arm at all, because the ownership of our own unit swallowed it.\n\nThe pair is stated as three assertions rather than one because an arm that refused while still emitting a unit, or that named no unit in its reason, would satisfy a bare not-converged check while being useless to the operator who has to act on it." +// THE DISCRIMINATING PAIR FOR THE CONTRACT DECISION. +// witness_an_already_managed_endpoint_is_converged_and_emits_nothing above and +// witness_our_unit_holding_a_dead_socket_is_not_converged below differ in exactly ONE input -- the +// path state under an identical ServerManagedUnitOwned placement -- and must land on opposite arms. +// That is the whole decision: ownership answers WHO holds the endpoint, the path answers WHETHER IT +// IS SERVED, and a converged verdict needs both. Under the preceding placement-first short-circuit +// the second witness went green on the CONVERGED arm: a host with a wedged server and an +// unreachable cache reported as needing nothing. The specimen is real: +// gunbc.build_cache_endpoint_observe socket_owner_path_state produces exactly this state -- a +// socket held open by a live fd-holder with no listen entry at the path -- and +// test.claim.build_cache_endpoint_observe held_without_listening_fixture_note recorded that its +// own fixture had to name a FOREIGN owner to reach the path-conflict arm at all, because the +// ownership of our own unit swallowed it. +// +// Three assertions rather than one, because an arm that refused while still emitting a unit, or +// named no unit in its reason, would satisfy a bare not-converged check while being useless to the +// operator who must act on it. test fn witness_our_unit_holding_a_dead_socket_is_not_converged() -> Bool { let a = ensure_for( @@ -175,7 +232,11 @@ test fn witness_our_unit_holding_a_dead_socket_is_not_converged() -> Bool { ) } -data unreadable_path_under_our_own_placement_doc: String = "The second half of the same wall, and the one that fails toward the wrong answer if it is left out. A path that could not be READ is not a path that is being served; answering converged from ownership alone here would report a host converged on evidence never obtained, which is the fabricated plausible output DESIGN section 5 forbids rather than merely a weaker check. Its sibling above differs in one field: a path state that WAS read and says not-listening." +// The second half of the same wall, the one that fails toward the wrong answer if left out. A +// path that could not be READ is not a path being served; answering converged from ownership +// alone would report a host converged on evidence never obtained -- the fabricated plausible +// output DESIGN section 5 forbids, not merely a weaker check. Its sibling above differs in one +// field: a path state that WAS read and says not-listening. test fn witness_an_unreadable_path_under_our_own_unit_is_not_converged() -> Bool { let a = ensure_for( @@ -195,7 +256,15 @@ test fn witness_a_managed_unit_that_is_not_ours_is_not_converged() -> Bool { build_cache_ensure_is_converged(admission: a) == false } -data wrong_managed_unit_doc: String = "ctrl-sccache.service was a real specimen and not a hypothetical: it existed on srv1 and srv2 at the 2026-08-01 capture, managing the SESSION instance. IT NO LONGER EXISTS ANYWHERE -- measured 2026-08-25T18:43Z, is-enabled returns not-found on all four hosts and no unit file matches -- and the fixture is kept because a red control does not need its subject to be currently installed, only to be the shape a wrong acceptance would admit. gunbc.build_cache_instance build_cache_desired_instances_note carries what that disappearance costs elsewhere: the session rows' 50G capacity was set from this unit. A convergence check that accepted any managed unit as satisfying the CI instance would report srv1 converged on the strength of a unit serving a different cache directory, a different uid and a different socket." +// ctrl-sccache.service was a real specimen: it existed on srv1 and srv2 at the 2026-08-01 +// capture, managing the SESSION instance. IT NO LONGER EXISTS ANYWHERE -- measured +// 2026-08-25T18:43Z, is-enabled returns not-found on all four hosts and no unit file matches -- +// and the fixture is kept because a red control needs only to be the shape a wrong acceptance +// would admit, not a currently installed subject. gunbc.build_cache_instance +// build_cache_desired_instances_note carries what that disappearance costs elsewhere: the session +// rows' 50G capacity was set from this unit. A convergence check accepting any managed unit as +// satisfying the CI instance would report srv1 converged on a unit serving a different cache +// directory, uid and socket. test fn witness_unknown_placement_refuses_before_reading_the_path() -> Bool { let a = ensure_for( @@ -205,7 +274,11 @@ test fn witness_unknown_placement_refuses_before_reading_the_path() -> Bool { (ensure_yields_unit(admission: a) == false) && (build_cache_ensure_is_converged(admission: a) == false) } -data unknown_before_path_doc: String = "The discriminating case for the ordering. The path here is ABSENT -- the one state that would otherwise be admitted immediately -- so this witness fails if placement is consulted after the path rather than before. Unknown means the observer could not classify the owner, and proceeding would mean writing and starting a unit on a host whose current state we failed to read: an absorbing fallback whose widen is a host mutation rather than a rerun." +// The discriminating case for the ordering. The path here is ABSENT -- the one state otherwise +// admitted immediately -- so this witness fails if placement is consulted after the path rather +// than before. Unknown means the observer could not classify the owner, and proceeding would write +// and start a unit on a host whose current state we failed to read: an absorbing fallback whose +// widen is a host mutation rather than a rerun. test fn witness_a_path_conflict_is_never_admitted() -> Bool { let a = ensure_for( @@ -225,7 +298,13 @@ test fn witness_a_stale_read_cannot_license_the_ensure() -> Bool { ensure_yields_unit(admission: a) == false } -data foreground_supervision_doc: String = "The render must produce a unit systemd can actually supervise, and the failure mode is silent: --start-server daemonizes and returns 0, so under Type=simple the unit is marked dead the instant it starts while sccache survives only through its own per-invocation auto-start. Proven live on srv3 2026-07-25. An earlier draft of this render emitted exactly that form and would have generated a no-op unit; it was caught by gunbc.host_build_cache_provision_script's existing construction check, which refuses a body containing --start-server. This witness pins the corrected form here too, so the render cannot regress independently of that check." +// The render must produce a unit systemd can supervise, and the failure mode is silent: +// --start-server daemonizes and returns 0, so under Type=simple the unit is marked dead the instant +// it starts while sccache survives only through its own per-invocation auto-start. Proven live on +// srv3 2026-07-25. An earlier draft of this render emitted exactly that form and would have +// generated a no-op unit; gunbc.host_build_cache_provision_script's existing construction check, +// which refuses a body containing --start-server, caught it. This witness pins the corrected form +// here too, so the render cannot regress independently of that check. test fn witness_the_rendered_unit_is_foreground_supervised() -> Bool { let u = ci_unit() diff --git a/dag/test/claim/build_cache_latency_probe_witness_test.dag b/dag/test/claim/build_cache_latency_probe_witness_test.dag index 4c29db449b7..efbe5767f13 100644 --- a/dag/test/claim/build_cache_latency_probe_witness_test.dag +++ b/dag/test/claim/build_cache_latency_probe_witness_test.dag @@ -24,7 +24,18 @@ import v2.std.live_tree { LiveTreeDisposition, SubstrateInputsOnly } data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data witness_subject_is_the_derivation_note: String = "THESE ROWS TEST THE DERIVATION, NOT THE FLEET, and the distinction is the 2026-08-01 test-oracle ruling applied to a probe. A witness asserting 'srv1 is currently slow' would compare a live population to a number read off that same population — a change detector whose entire content is whoever last updated the literal, and one that would go red the moment the defect is FIXED, which is the opposite of what a fix should do to a test.\n\nSo the fixtures below are CONTROLLED: populations authored here with known answers, exercising the median selection, the even/odd split, the empty refusal, and both sides of the policy ratio. The one row that touches recorded data asserts only INTERNAL CONSISTENCY of the 2026-08-05 receipt — that its stored verdict equals what the derivation produces from its stored samples — which stays true forever regardless of what the fleet does next, and would red only if someone edited the receipt's numbers without re-deriving its verdict." +// THESE ROWS TEST THE DERIVATION, NOT THE FLEET, and the distinction is the 2026-08-01 test-oracle +// ruling applied to a probe. A witness asserting 'srv1 is currently slow' would compare a live +// population to a number read off that same population — a change detector whose entire content is +// whoever last updated the literal, and one that would go red the moment the defect is FIXED, which +// is the opposite of what a fix should do to a test. +// +// So the fixtures below are CONTROLLED: populations authored here with known answers, exercising +// the median selection, the even/odd split, the empty refusal, and both sides of the policy ratio. +// The one row that touches recorded data asserts only INTERNAL CONSISTENCY of the 2026-08-05 +// receipt — that its stored verdict equals what the derivation produces from its stored samples — +// which stays true forever regardless of what the fleet does next, and would red only if someone +// edited the receipt's numbers without re-deriving its verdict. data odd_population: BuildLatencyPopulation = BuildLatencyPopulation { host: operator_host_srv2, @@ -91,7 +102,11 @@ test fn empty_population_refuses_rather_than_passing() -> Bool { && !build_latency_verdict_is_diverged(v: v) } -data policy_boundary_note: String = "THE DISCRIMINATING PAIR for the ratio, straddling it by one millisecond on either side so the boundary is pinned rather than approximated. At exactly 2x the reference the verdict is CONVERGED — the policy reads 'more than 2x diverges', so equality passes — and one millisecond above it diverges. A witness that only tested a wildly-divergent population would pass against a policy of 10x, or 100x, or any ratio at all, which would make the declared budget decorative." +// THE DISCRIMINATING PAIR for the ratio, straddling it by one millisecond on either side so the +// boundary is pinned rather than approximated. At exactly 2x the reference the verdict is CONVERGED +// — the policy reads 'more than 2x diverges', so equality passes — and one millisecond above it +// diverges. A witness that only tested a wildly-divergent population would pass against a policy of +// 10x, or 100x, or any ratio at all, which would make the declared budget decorative. data at_exactly_two_x: BuildLatencyPopulation = BuildLatencyPopulation { host: operator_host_srv2, @@ -125,7 +140,12 @@ test fn RED_ratio_boundary_diverges_one_millisecond_over() -> Bool { ) } -data receipt_internal_consistency_note: String = "The recorded 2026-08-05 receipt is checked for INTERNAL CONSISTENCY only: its stored verdict must equal the verdict its stored samples derive. That claim is time-invariant — it is about the receipt, not about srv1 — so it does not go red when the fleet is repaired, and it is not a snapshot pin. What it catches is the failure mode a hand-collected receipt actually has: someone editing the durations, or the reference, or the policy, without re-deriving the verdict beside them, leaving a row whose conclusion no longer follows from its own evidence." +// The recorded 2026-08-05 receipt is checked for INTERNAL CONSISTENCY only: its stored verdict must +// equal the verdict its stored samples derive. That claim is time-invariant — it is about the +// receipt, not about srv1 — so it does not go red when the fleet is repaired, and it is not a +// snapshot pin. What it catches is the failure mode a hand-collected receipt actually has: someone +// editing the durations, or the reference, or the policy, without re-deriving the verdict beside +// them, leaving a row whose conclusion no longer follows from its own evidence. test fn recorded_receipt_verdict_follows_from_its_own_samples() -> Bool { let rederived = build_latency_verdict( diff --git a/dag/test/claim/build_cache_placement_observation_test.dag b/dag/test/claim/build_cache_placement_observation_test.dag index c5f794506ec..ddee93ac84a 100644 --- a/dag/test/claim/build_cache_placement_observation_test.dag +++ b/dag/test/claim/build_cache_placement_observation_test.dag @@ -2,7 +2,12 @@ module test.claim.build_cache_placement_observation data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data placement_observation_witness_doc: String = "The step-1 controls for the endpoint-owner observer, at the MODEL grain. Every fixture below is synthetic; the live counterparts were captured read-only against srv1, srv2 and srv3 on 2026-08-01 and are recorded in docs/plans/build-cache-placement-receipt.md. The controls that can only be executed against a real host — that --show-stats does not manufacture a server, that a compile does, and that two consecutive observations do not perturb the subject — are live receipts rather than witnesses here, because a hermetic fixture cannot falsify them." +// The step-1 controls for the endpoint-owner observer, at the MODEL grain. Every fixture below is +// synthetic; the live counterparts were captured read-only against srv1, srv2 and srv3 on +// 2026-08-01 and are recorded in docs/plans/build-cache-placement-receipt.md. The controls that can +// only be executed against a real host — that --show-stats does not manufacture a server, that a +// compile does, and that two consecutive observations do not perturb the subject — are live +// receipts rather than witnesses here, because a hermetic fixture cannot falsify them. fn srv1_ci_instance_fixture() -> BuildCacheInstance { ci_cache_instance(host: "srv1") @@ -129,7 +134,20 @@ test fn witness_ambiguous_ownership_refuses() -> Bool { } } -data unreachable_is_not_absent_doc: String = "THE srv4 CONTROL, and the one most likely to be got wrong by a sweep that reports per-host health. A host that could not be reached has NOT been observed to have no server; recording it as EndpointAbsent would be the absorbing fallback (DESIGN section 5) — ignorance rendered as an answer. srv4 was genuinely unreachable when the 2026-08-01 receipt was taken (ssh to 192.168.1.196 returned 'Permission denied (publickey)' from the srv2 jump host), so it was carried as EndpointObservationUnavailable { ReachRefused }, which derives ServerPlacementUnknown and REFUSES — distinct from ServerPlacementAbsent, which is a positive finding that the endpoint has no listener. srv4 HAS SINCE BEEN OBSERVED (2026-08-01, over the fleet-automation key the roster always intended), and the outcome vindicates the distinction rather than retiring the control: srv4 turned out to be genuinely EndpointAbsent — no listener, no process, no unit — with a stale socket making every new server fail to bind. Had the unreachable read been recorded as Absent it would have produced the RIGHT answer for the WRONG reason, and nobody would have learned that the two states had never been distinguished. The control keeps its subject because the next unreachable host is not owed srv4's luck." +// THE srv4 CONTROL, and the one most likely to be got wrong by a sweep that reports per-host +// health. A host that could not be reached has NOT been observed to have no server; recording it as +// EndpointAbsent would be the absorbing fallback (DESIGN section 5) — ignorance rendered as an +// answer. srv4 was genuinely unreachable when the 2026-08-01 receipt was taken (ssh to +// 192.168.1.196 returned 'Permission denied (publickey)' from the srv2 jump host), so it was +// carried as EndpointObservationUnavailable { ReachRefused }, which derives ServerPlacementUnknown +// and REFUSES — distinct from ServerPlacementAbsent, which is a positive finding that the endpoint +// has no listener. srv4 HAS SINCE BEEN OBSERVED (2026-08-01, over the fleet-automation key the +// roster always intended), and the outcome vindicates the distinction rather than retiring the +// control: srv4 turned out to be genuinely EndpointAbsent — no listener, no process, no unit — with +// a stale socket making every new server fail to bind. Had the unreachable read been recorded as +// Absent it would have produced the RIGHT answer for the WRONG reason, and nobody would have +// learned that the two states had never been distinguished. The control keeps its subject because +// the next unreachable host is not owed srv4's luck. test fn witness_unreachable_host_is_unknown_never_absent() -> Bool { let p = placement_of_endpoint_observation( @@ -147,7 +165,18 @@ test fn witness_unreachable_host_is_unknown_never_absent() -> Bool { } } -data owner_context_coupling_doc: String = "THE CONTROL FOR THE COUPLING FIX (review 46217). The classification of an endpoint owner's cgroup was once three loose fields — a unit beside an optional slot beside an optional lifecycle — and the combination that mattered was slot-Absent with lifecycle-Present: the derivation matched the slot first, so that state skipped the runner arm entirely and reached the unit comparison, where a cgroup whose unit happened to equal intended_unit would return ServerManagedUnitOwned. A runner-owned endpoint could therefore be reported as correctly placed because two fields disagreed. There is deliberately NO witness asserting that state refuses, and its absence is the claim: EndpointOwnerContext has no arm that can express it, so it is unwritable rather than checked, and a test would have to construct a value the type does not admit (DESIGN section 4b, construction over validation). What IS witnessed below is the arm that replaced the half-filled record — a cgroup the observer could not classify is a positive OwnerContextUndecided carrying its own located reason, and it refuses." +// THE CONTROL FOR THE COUPLING FIX (review 46217). The classification of an endpoint owner's cgroup +// was once three loose fields — a unit beside an optional slot beside an optional lifecycle — and +// the combination that mattered was slot-Absent with lifecycle-Present: the derivation matched the +// slot first, so that state skipped the runner arm entirely and reached the unit comparison, where +// a cgroup whose unit happened to equal intended_unit would return ServerManagedUnitOwned. A +// runner-owned endpoint could therefore be reported as correctly placed because two fields +// disagreed. There is deliberately NO witness asserting that state refuses, and its absence is the +// claim: EndpointOwnerContext has no arm that can express it, so it is unwritable rather than +// checked, and a test would have to construct a value the type does not admit (DESIGN section 4b, +// construction over validation). What IS witnessed below is the arm that replaced the half-filled +// record — a cgroup the observer could not classify is a positive OwnerContextUndecided carrying +// its own located reason, and it refuses. test fn witness_undecided_owner_context_refuses_and_keeps_the_located_reason() -> Bool { let detail = "cgroup names actions-runner@srv1-XX.service; slot index did not parse" as NonEmptyStr @@ -169,7 +198,14 @@ test fn witness_undecided_owner_context_refuses_and_keeps_the_located_reason() - } } -data client_false_positive_doc: String = "THE CLIENT FALSE-POSITIVE CONTROL, expressed as a construction property rather than a fixture count. A name-based probe would have to take 'how many processes are called sccache' as an input; this model has no such input anywhere — BuildCacheEndpointObservation is indexed by the ENDPOINT, and its ambiguity arm counts candidate ENDPOINT OWNERS, not same-named processes. So the srv1 reality at receipt time (four ghrunner sccache processes: one endpoint owner plus three transient clients under live slots 01/04/05) classifies from the owner alone and the three clients cannot perturb it. A probe that refused on 'multiple sccache processes' would have produced a FALSE refusal on all three hosts simultaneously." +// THE CLIENT FALSE-POSITIVE CONTROL, expressed as a construction property rather than a fixture +// count. A name-based probe would have to take 'how many processes are called sccache' as an input; +// this model has no such input anywhere — BuildCacheEndpointObservation is indexed by the ENDPOINT, +// and its ambiguity arm counts candidate ENDPOINT OWNERS, not same-named processes. So the srv1 +// reality at receipt time (four ghrunner sccache processes: one endpoint owner plus three transient +// clients under live slots 01/04/05) classifies from the owner alone and the three clients cannot +// perturb it. A probe that refused on 'multiple sccache processes' would have produced a FALSE +// refusal on all three hosts simultaneously. test fn witness_placement_is_indexed_by_owner_not_by_process_count() -> Bool { let a = placement_of_endpoint_observation(observed: observed_in_slot(slot: RunnerSlotIdentity { host: "srv1", slot_index: 10 }, lifecycle: RetiredRunnerSlot)) diff --git a/dag/test/claim/cache_retention_axes_witness_test.dag b/dag/test/claim/cache_retention_axes_witness_test.dag index 2c508d08f0f..3c6950c2b3f 100644 --- a/dag/test/claim/cache_retention_axes_witness_test.dag +++ b/dag/test/claim/cache_retention_axes_witness_test.dag @@ -26,9 +26,29 @@ import std.cache_interface { retention_has_exact_byte_bound, } -data cache_retention_axes_note: String = "THE DISCRIMINATING CONTROLS for the retention axis split (operator ruling 2026-08-06). Every cell here is a PLANTED retention value, not a live corpus row, so a red is attributable to the algebra rather than to a catalog edit; the per-row dispositions are checked by each row consumer. Two cells prove the shape the old sum could not express AT ALL - scope release AND a capacity bound carried in one value - which is the whole reason the axis was split. One cell keeps the two negative states apart, because known-unbounded and not-established have different remedies and only the second is closed by a citation. One cell keeps refuse-new-store distinct from replacement, the distinction PR 2 rests on. The LRU and TTL halves are deliberately NOT tested here and the note below says why: both became unrepresentable rather than merely false, and an unrepresentable state has no value a predicate could be handed." - -data lru_ttl_unrepresentability_note: String = "WHERE THE LRU AND TTL HALVES ARE ACTUALLY CLOSED, stated here because an earlier draft of this file got it wrong in a way worth recording. That draft carried two functions named lru_without_capacity and ttl_without_capacity whose bodies were BYTE-IDENTICAL - both just CapacityUnobserved - so the names claimed a property no value in the test carried, and neither test could have failed for the reason its name gave. The real closure is at two different layers and NEITHER is a predicate over a planted retention value. (1) LRU is unrepresentable as a capacity claim: at_capacity nests inside the CapacityBounded arm, so ReplaceExisting { strategy: LeastRecentlyUsed } cannot be stated beside CapacityUnobserved or CapacityUnbounded at all - a type-level property, which is exactly why no test here exercises it and why the old fused axis needed one. (2) TTL is not on this axis: TtlExpiry lives on KeyDerivationFacts invalidation_triggers, so a TTL fact cannot reach a capacity verdict by any path. What remains testable is the predicate below - that an unobserved capacity does not satisfy a bounded role - plus the per-row dispositions, which are checked by each row consumer rather than restated here." +// THE DISCRIMINATING CONTROLS for the retention axis split (operator ruling 2026-08-06). Every cell +// is a PLANTED retention value, not a live corpus row, so a red is attributable to the algebra +// rather than a catalog edit; per-row dispositions are checked by each row consumer. Two cells +// prove the shape the old sum could not express AT ALL - scope release AND a capacity bound in one +// value - the whole reason the axis was split. One cell keeps the two negative states apart: +// known-unbounded and not-established have different remedies and only the second is closed by a +// citation. One cell keeps refuse-new-store distinct from replacement, the distinction PR 2 rests +// on. The LRU and TTL halves are deliberately NOT tested here; the note below says why: both became +// unrepresentable rather than merely false, and an unrepresentable state has no value a predicate +// could be handed. + +// WHERE THE LRU AND TTL HALVES ARE ACTUALLY CLOSED, recorded because an earlier draft got it wrong. +// That draft carried lru_without_capacity and ttl_without_capacity with BYTE-IDENTICAL bodies - +// both just CapacityUnobserved - so the names claimed a property no value in the test carried, and +// neither test could fail for the reason its name gave. The real closure is at two layers and +// NEITHER is a predicate over a planted retention value. (1) LRU is unrepresentable as a capacity +// claim: at_capacity nests inside the CapacityBounded arm, so ReplaceExisting { strategy: +// LeastRecentlyUsed } cannot be stated beside CapacityUnobserved or CapacityUnbounded at all - a +// type-level property, which is why no test here exercises it and why the old fused axis needed +// one. (2) TTL is not on this axis: TtlExpiry lives on KeyDerivationFacts invalidation_triggers, +// so a TTL fact cannot reach a capacity verdict by any path. What remains testable is the +// predicate below - an unobserved capacity does not satisfy a bounded role - plus the per-row +// dispositions, checked by each row consumer rather than restated here. fn capacity_not_established() -> ProviderRetention { ProviderRetention { @@ -70,7 +90,10 @@ test fn unobserved_capacity_never_satisfies_a_bounded_role() -> Bool { !capacity_is_bounded(c: r.capacity) && !retention_growth_is_bounded(r: r) } -data scope_release_bounds_growth_note: String = "Scope release bounds GROWTH because storage ends with the frame; it says nothing about the peak reached INSIDE that frame, which is why the 2026-07-10 20GiB incident happened under a live scope. retention_growth_is_bounded is the growth predicate, deliberately not a peak-memory guarantee, and a role that needs a peak bound asks the capacity axis." +// Scope release bounds GROWTH because storage ends with the frame; it says nothing about the peak +// reached INSIDE that frame, which is why the 2026-07-10 20GiB incident happened under a live +// scope. retention_growth_is_bounded is the growth predicate, deliberately not a peak-memory +// guarantee, and a role that needs a peak bound asks the capacity axis. test fn scope_release_and_a_byte_ceiling_are_one_value() -> Bool { let r = scope_exit_byte_bounded_refuse_new() @@ -125,7 +148,12 @@ test fn unbounded_and_unobserved_capacity_are_different_states() -> Bool { neither_is_bounded && they_are_distinguishable } -data scope_exit_role_discrimination_note: String = "THE CONTROL THE FIRST CUT LACKED (operator ruling 2026-08-06). Its only negative cell used ReleasedNever, so it never exercised the case that actually matters: a scope-released provider whose capacity is unbounded or unobserved. That value satisfies GROWTH boundedness - the frame ends, so storage ends - and satisfies CAPACITY boundedness not at all. One overloaded predicate would have admitted it to a byte-budget role, which is exactly the promoted-eval-memo obligation PR 2 owes. These two cells hold the predicates apart at the one point they disagree." +// THE CONTROL THE FIRST CUT LACKED (operator ruling 2026-08-06). Its only negative cell used +// ReleasedNever, so it never exercised the case that matters: a scope-released provider whose +// capacity is unbounded or unobserved. That value satisfies GROWTH boundedness - the frame ends, +// so storage ends - and CAPACITY boundedness not at all. One overloaded predicate would have +// admitted it to a byte-budget role, exactly the promoted-eval-memo obligation PR 2 owes. These two +// cells hold the predicates apart at the one point they disagree. test fn scope_release_with_unbounded_capacity_bounds_growth_but_not_capacity() -> Bool { let r = ProviderRetention { diff --git a/dag/test/claim/capability_binding_witness_test.dag b/dag/test/claim/capability_binding_witness_test.dag index 8a42dd88b0c..e9a8e3a33e0 100644 --- a/dag/test/claim/capability_binding_witness_test.dag +++ b/dag/test/claim/capability_binding_witness_test.dag @@ -61,7 +61,11 @@ import gunbc.capability_binding { data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data capability_binding_witness_note: String = "The four-layer separation and the derived per-capability verdict, each law beside the control that reds it. The claims are mostly about what the model REFUSES to say: that an operating system supports something, that a readable sensor is a fit one, that a caller may declare a tap qualified, that a degradation needs no resolvable alternative, and that a synthetic source may stand in for hardware without saying so." +// The four-layer separation and the derived per-capability verdict, each law beside the control +// that reds it. The claims are mostly about what the model REFUSES to say: that an operating system +// supports something, that a readable sensor is a fit one, that a caller may declare a tap +// qualified, that a degradation needs no resolvable alternative, and that a synthetic source may +// stand in for hardware without saying so. fn a_host(container: ApplicationContainerKind, renderer: RendererKind) -> HostRealization { HostRealization { @@ -94,7 +98,10 @@ fn a_host(container: ApplicationContainerKind, renderer: RendererKind) -> HostRe } } -data orthogonality_note: String = "Container and renderer are independent axes, so every pairing is constructible and none is a variant of website. A native desktop process rendering DOM is the first native architecture worth building; a browser document rendering a WebGPU scene is a realization of the same projection. Fusing the axes would make both unspellable and the product would have silently become a website." +// Container and renderer are independent axes, so every pairing is constructible and none is a +// variant of website. A native desktop process rendering DOM is the first native architecture worth +// building; a browser document rendering a WebGPU scene is a realization of the same projection. +// Fusing the axes would make both unspellable and the product would have silently become a website. fn witness_container_and_renderer_are_independent_axes() -> Bool { let native_dom = a_host(container: NativeDesktopProcess, renderer: DomCssRenderer) @@ -108,7 +115,9 @@ fn witness_container_and_renderer_are_independent_axes() -> Bool { && renderer_kind_key(r: mobile_native.renderer) == "native-widget" } -data role_is_not_container_note: String = "A companion phone still runs its process somewhere. Role and container are orthogonal, so the same container kind carries both roles and a companion input host is expressible without inventing a container for it." +// A companion phone still runs its process somewhere. Role and container are orthogonal, so the +// same container kind carries both roles and a companion input host is expressible without +// inventing a container for it. fn witness_host_role_is_orthogonal_to_container() -> Bool { let primary = a_host(container: NativeMobileProcess, renderer: NativeWidgetRenderer) @@ -118,7 +127,9 @@ fn witness_host_role_is_orthogonal_to_container() -> Bool { && container_kind_key(c: BrowserDocument) != container_kind_key(c: EmbeddedWebView) } -data continuity_note: String = "Continuity is a capability with independent parts, not a property assigned to a container by type. A shell may make some parts easier to realize; it does not make them different requirements, and a partial continuity is visibly partial." +// Continuity is a capability with independent parts, not a property assigned to a container by +// type. A shell may make some parts easier to realize; it does not make them different +// requirements, and a partial continuity is visibly partial. fn witness_continuity_is_a_capability_not_a_container_property() -> Bool { continuity_is_complete(c: InstrumentContinuity { @@ -135,7 +146,10 @@ fn witness_continuity_is_a_capability_not_a_container_property() -> Bool { }) } -data product_engine_note: String = "The Chrome receipt names Chrome as its product and Chromium as its separately resolved engine. The repository already ruled that a Chromium build is not a Google Chrome identity, and an earlier revision of this fixture reopened exactly that conflation by pointing the container at the Chromium project while carrying Chrome's version string." +// The Chrome receipt names Chrome as its product and Chromium as its separately resolved engine. +// The repository already ruled that a Chromium build is not a Google Chrome identity, and an +// earlier revision of this fixture reopened exactly that conflation by pointing the container at +// the Chromium project while carrying Chrome's version string. fn witness_the_browser_product_is_not_its_engine() -> Bool { let h = a_host(container: BrowserDocument, renderer: DomCssRenderer) @@ -224,7 +238,11 @@ fn signed_verdict_of(s: BindingStreamState) -> String { capability_verdict_key(v: derive_capability_verdict(o: a_signed_observation(s: s))) } -data qualification_is_minted_witness_note: String = "THE CENTRAL RED OF THIS FILE, AND IT EXISTS BECAUSE THE EARLIER MODEL FAILED IT. A caller used to be able to author a coproduct arm named qualified and receive a supported verdict, while the function that checked the requirement was never called by the verdict and checked only two of five dimensions. These claims plant a receipt that FAILS on each dimension in turn and assert that none of them qualifies — so a supported verdict is now reachable only through a total check." +// THE CENTRAL RED OF THIS FILE, AND IT EXISTS BECAUSE THE EARLIER MODEL FAILED IT. A caller used to +// be able to author a coproduct arm named qualified and receive a supported verdict, while the +// function that checked the requirement was never called by the verdict and checked only two of +// five dimensions. These claims plant a receipt that FAILS on each dimension in turn and assert +// that none of them qualifies — so a supported verdict is now reachable only through a total check. fn qualifies(r: SampleReceipt) -> Bool { match qualify_tap(r: bob_impulse_requirement_candidate, s: r) { @@ -260,7 +278,9 @@ fn witness_red_latency_above_the_budget_cannot_qualify() -> Bool { && causes_contain(cs: rejection_causes(r: slow), c: LatencyAboveBudget) } -data all_five_dimensions_note: String = "The three dimensions the earlier helper ignored entirely — axes, sample rate and gravity handling — each reject on their own, which is what makes the check total rather than a pair of comparisons wearing a requirement's name." +// The three dimensions the earlier helper ignored entirely — axes, sample rate and gravity handling +// — each reject on their own, which is what makes the check total rather than a pair of comparisons +// wearing a requirement's name. fn witness_red_too_few_axes_cannot_qualify() -> Bool { let flat = SampleReceipt { @@ -304,7 +324,10 @@ fn witness_red_gravity_left_in_cannot_qualify() -> Bool { !qualifies(r: heavy) && causes_contain(cs: rejection_causes(r: heavy), c: GravityNotHandledAsRequired) } -data unobserved_dimension_note: String = "A dimension nobody measured REFUSES rather than passing, which is the whole reason unobserved is distinct from zero. The web route supplies no noise floor and no axis count today, so a web sample receipt cannot qualify a tap on its own — exactly the honest result, and the reason the qualification must run over samples rather than being projected from a stream arm." +// A dimension nobody measured REFUSES rather than passing, which is the whole reason unobserved is +// distinct from zero. The web route supplies no noise floor and no axis count today, so a web +// sample receipt cannot qualify a tap on its own — exactly the honest result, and the reason the +// qualification must run over samples rather than being projected from a stream arm. fn witness_red_an_unobserved_dimension_refuses_rather_than_passing() -> Bool { let partial = SampleReceipt { @@ -321,7 +344,8 @@ fn witness_red_an_unobserved_dimension_refuses_rather_than_passing() -> Bool { && causes_contain(cs: rejection_causes(r: partial), c: RequirementDimensionUnobserved) } -data negative_control_witness_note: String = "A threshold with no negative control is sensitivity, not discrimination: nobody has checked that typing stays below it. An unrun control therefore rejects, and a failed one rejects too." +// A threshold with no negative control is sensitivity, not discrimination: nobody has checked that +// typing stays below it. An unrun control therefore rejects, and a failed one rejects too. fn witness_red_a_missing_negative_control_refuses() -> Bool { let unrun = SampleReceipt { @@ -349,7 +373,10 @@ fn witness_red_a_missing_negative_control_refuses() -> Bool { && !qualifies(r: failed) } -data signed_requirement_note: String = "A signed twin of the candidate requirement, identical in every threshold, differing only in standing. It exists so the two verdicts can be compared on ONE variable: the same receipt against the same numbers reaches supported when the thresholds are signed and qualified-against-provisional when they are not." +// A signed twin of the candidate requirement, identical in every threshold, differing only in +// standing. It exists so the two verdicts can be compared on ONE variable: the same receipt against +// the same numbers reaches supported when the thresholds are signed and +// qualified-against-provisional when they are not. data a_signed_requirement: PhysicalImpulseRequirement = PhysicalImpulseRequirement { axis_count: 3, @@ -366,7 +393,10 @@ data a_signed_requirement: PhysicalImpulseRequirement = PhysicalImpulseRequireme }, } -data supported_needs_a_receipt_note: String = "The seam claim, and it is now a claim about DERIVATION rather than about routing: the stream hands the verdict a raw requirement and a raw receipt, the verdict qualifies them itself, and there is no qualified value anyone could have authored instead. A rejected measurement degrades with its typed causes carried through rather than flattened to a sentence." +// The seam claim, and it is now a claim about DERIVATION rather than about routing: the stream +// hands the verdict a raw requirement and a raw receipt, the verdict qualifies them itself, and +// there is no qualified value anyone could have authored instead. A rejected measurement degrades +// with its typed causes carried through rather than flattened to a sentence. fn witness_only_a_derived_qualification_reaches_supported() -> Bool { signed_verdict_of(s: TapOutcome { receipt: a_receipt(peak: 3100, latency: 40) }) == "supported" @@ -395,7 +425,12 @@ fn witness_a_rejected_tap_carries_its_typed_causes() -> Bool { } } -data provisional_cannot_authorize_note: String = "The two blocking bypasses this file previously could not see, planted as the RED they need. A negative control whose observed idle peak sits ABOVE the discriminating floor must reject — under the old shape it passed because it was named Passed. And the live candidate requirement, whose own standing says its numbers are unproven, must NOT reach supported no matter how good the measurement is: the same receipt that reaches supported against signed thresholds lands on the provisional arm against unsigned ones, and its key is not the one the durable-claim gate reads." +// The two blocking bypasses this file previously could not see, planted as the RED they need. A +// negative control whose observed idle peak sits ABOVE the discriminating floor must reject — under +// the old shape it passed because it was named Passed. And the live candidate requirement, whose +// own standing says its numbers are unproven, must NOT reach supported no matter how good the +// measurement is: the same receipt that reaches supported against signed thresholds lands on the +// provisional arm against unsigned ones, and its key is not the one the durable-claim gate reads. fn witness_red_a_negative_control_above_the_floor_rejects() -> Bool { let noisy = SampleReceipt { @@ -476,7 +511,8 @@ fn witness_red_an_unexercised_binding_is_not_a_failure() -> Bool { verdict_of(s: NoSamplesObserved { lifecycle: LifecycleActivationUnobserved }) } -data lifecycle_carried_note: String = "The two silences stay distinguishable in the neutral layer: an activated sensor that never read is a different key from a stream whose activation was never observed." +// The two silences stay distinguishable in the neutral layer: an activated sensor that never read +// is a different key from a stream whose activation was never observed. fn witness_silence_carries_its_lifecycle() -> Bool { binding_stream_key(s: NoSamplesObserved { lifecycle: LifecycleActivated }) != @@ -484,7 +520,8 @@ fn witness_silence_carries_its_lifecycle() -> Bool { && sample_lifecycle_key(l: LifecycleActivated) == "activated" } -data alternative_is_resolvable_note: String = "The degradation's alternative is a REFERENCE to the declared synthetic binding, so that an alternative exists is a resolvable fact rather than a sentence asserting one." +// The degradation's alternative is a REFERENCE to the declared synthetic binding, so that an +// alternative exists is a resolvable fact rather than a sentence asserting one. fn degraded_alternative_module(s: BindingStreamState) -> String { match derive_capability_verdict(o: an_observation(s: s)) { @@ -527,7 +564,8 @@ fn witness_red_a_reduced_host_cannot_carry_a_durable_support_claim() -> Bool { && fold(rows, init: false, f: (acc, r) => acc || capability_verdict_key(v: r.verdict) == "supported") } -data provisional_note: String = "The thresholds are audition candidates and say so in the type. They become a signed requirement only after the three auditions run, so a reader cannot mistake reasoning for measurement." +// The thresholds are audition candidates and say so in the type. They become a signed requirement +// only after the three auditions run, so a reader cannot mistake reasoning for measurement. fn witness_the_bob_requirement_is_still_provisional() -> Bool { !requirement_is_signed(s: bob_impulse_requirement_candidate.standing) @@ -589,7 +627,12 @@ fn witness_no_coverage_state_is_a_support_claim() -> Bool { && witness_the_coverage_roster_claims_nothing_it_has_not_earned() } -data roster_predicates_had_no_consumer_note: String = "THREE ROSTER PREDICATES EXISTED AND NOTHING RAN THEM. coverage_targets_asserting_support and deferred_targets_all_name_a_trigger were written to hold the roster honest and had zero executing consumers, which is the specification-without-execution trap in its plainest form: the rule was authored, the corpus was never measured against it, and a row that broke it would have landed green. They execute here, over the live roster rather than over a fixture, together with the receipt rule that is the actual repair for the misnamed field." +// THREE ROSTER PREDICATES EXISTED AND NOTHING RAN THEM. coverage_targets_asserting_support and +// deferred_targets_all_name_a_trigger were written to hold the roster honest and had zero executing +// consumers, which is the specification-without-execution trap in its plainest form: the rule was +// authored, the corpus was never measured against it, and a row that broke it would have landed +// green. They execute here, over the live roster rather than over a fixture, together with the +// receipt rule that is the actual repair for the misnamed field. fn witness_the_coverage_roster_claims_nothing_it_has_not_earned() -> Bool { coverage_targets_asserting_support() == 0 diff --git a/dag/test/claim/caret_syntax_witness_test.dag b/dag/test/claim/caret_syntax_witness_test.dag index 0ed791df37f..4dbde32bea9 100644 --- a/dag/test/claim/caret_syntax_witness_test.dag +++ b/dag/test/claim/caret_syntax_witness_test.dag @@ -1,6 +1,21 @@ module test.claim.caret_syntax_witness_test -data caret_syntax_migration_note: String = "Migrated from src/v1/tests/claim/caret_parse_smoke_test.dag (dead witness tree triage, dashboard node adhoc-9b80ec49-d63). That file's tokenizer/token-stream/parse-tree tests (w_caret_tokenizes_as_sh_caret, w_caret_paren_tokenizes_as_caret_then_lparen, w_parse_caret_ident_produces_literal, w_parse_caret_paren_produces_discriminant_call, w_parse_expr_caret_paren_full_pipeline, w_parse_expr_caret_var_arg_produces_discriminant_call, w_parse_module_let_caret_paren) were white-box tokenizer/parser-internals checks with no black-box equivalent and are RETIRED with this migration — they never executed (the file lived under src/v1/tests/claim, whose only historical consumer, v1_claim_scoped_witness_batch, was deleted 2026-08-15) and their claims (caret lexes as ShCaret, ^(expr) parses to a discriminant call, ^ident parses to a symbol literal) are covered black-box below by the three ALREADY-UNENROLLED plain fns the source file itself sketched (w_compile_to_resolved_caret_probe5b_has_no_caret_function_error, w_emit_caret_ident_symbol_literal, w_emit_caret_paren_discriminant_sugar) and never promoted to 'test fn': this file promotes that exact pattern onto compile_dag_rust_emit_check, the same production v1 compile path the old scoped batch used, but reachable from ordinary per-PR discovery (source roots dag + src/v2, no v1 import needed)." +// Migrated from src/v1/tests/claim/caret_parse_smoke_test.dag (dead witness tree triage, dashboard +// node adhoc-9b80ec49-d63). That file's tokenizer/token-stream/parse-tree tests +// (w_caret_tokenizes_as_sh_caret, w_caret_paren_tokenizes_as_caret_then_lparen, +// w_parse_caret_ident_produces_literal, w_parse_caret_paren_produces_discriminant_call, +// w_parse_expr_caret_paren_full_pipeline, w_parse_expr_caret_var_arg_produces_discriminant_call, +// w_parse_module_let_caret_paren) were white-box tokenizer/parser-internals checks with no +// black-box equivalent and are RETIRED with this migration — they never executed (the file lived +// under src/v1/tests/claim, whose only historical consumer, v1_claim_scoped_witness_batch, was +// deleted 2026-08-15) and their claims (caret lexes as ShCaret, ^(expr) parses to a discriminant +// call, ^ident parses to a symbol literal) are covered black-box below by the three +// ALREADY-UNENROLLED plain fns the source file itself sketched +// (w_compile_to_resolved_caret_probe5b_has_no_caret_function_error, +// w_emit_caret_ident_symbol_literal, w_emit_caret_paren_discriminant_sugar) and never promoted to +// 'test fn': this file promotes that exact pattern onto compile_dag_rust_emit_check, the same +// production v1 compile path the old scoped batch used, but reachable from ordinary per-PR +// discovery (source roots dag + src/v2, no v1 import needed). fn caret_probe5b_source() -> String { "module caret.probe5b\n\nfn probe() -> Bool {\n let sugar = ^(1)\n true\n}\n" diff --git a/dag/test/claim/cargo_artifact_selection_witness_test.dag b/dag/test/claim/cargo_artifact_selection_witness_test.dag index fb6fc03192e..1bce458706b 100644 --- a/dag/test/claim/cargo_artifact_selection_witness_test.dag +++ b/dag/test/claim/cargo_artifact_selection_witness_test.dag @@ -2,7 +2,15 @@ module test.claim.cargo_artifact_selection_witness data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data cargo_artifact_selection_witness_note: String = "These claims exist because service cargo.Build reports success, stdout and stderr and NEVER the path of the artifact it produced, so a consumer had to assemble that path by convention — and a stale binary at the conventional location satisfies a convention-derived observation completely, giving a digest honestly computed over the wrong bytes. The decode under test reads the path cargo itself reported. The discriminating claims are the refusals, not the happy path: a first-wins selector, a last-wins member lookup, and a decoder that skips lines it cannot read all pass the selection claim below while being exactly the defects that would let a wrong or absent artifact read as a good one. Line numbers in the refusals are asserted as EXACT values rather than merely non-selection, because a decoder that refuses with the wrong location sends the reader to the wrong line of a build log." +// These claims exist because service cargo.Build reports success, stdout and stderr and NEVER the +// path of the artifact it produced, so a consumer assembled that path by convention — and a stale +// binary at the conventional location satisfies a convention-derived observation completely, giving +// a digest honestly computed over the wrong bytes. The decode under test reads the path cargo +// itself reported. The discriminating claims are the refusals, not the happy path: a first-wins +// selector, a last-wins member lookup, and a decoder that skips unreadable lines all pass the +// selection claim below while being exactly the defects that let a wrong or absent artifact read as +// good. Line numbers in the refusals are asserted as EXACT values, because a decoder refusing with +// the wrong location sends the reader to the wrong line of a build log. data artifact_line_gunbc: String = "\{\"reason\":\"compiler-artifact\",\"package_id\":\"v1-compiler 0.1.0\",\"target\":\{\"name\":\"gunbc\",\"kind\":[\"bin\"]\},\"executable\":\"/w/target/debug/gunbc\",\"fresh\":false\}" @@ -290,7 +298,22 @@ test fn an_empty_stream_is_absent_rather_than_a_parse_refusal() -> Bool { } } -data recorded_real_stream_note: String = "The fixtures above are hand-authored, which proves the decode logic and proves nothing about whether it matches what cargo actually emits — a decoder can be perfectly self-consistent against a shape its upstream never produces. The rows below are RECORDED from a real run of `cargo build -p v1-compiler --bin claim_batch --message-format=json` (143 messages) and are verbatim except that absolute paths were rewritten to a neutral root, because the recording machine's home directory is not a fact about cargo and would make the claim environment-specific. Every structural property cargo produced is preserved: member names and their order, the nine members a real compiler-artifact carries against the three this module reads, the eight members inside target, and executable as a string on the binary while the libraries carry it as null. TWO THINGS THE RECORDING TAUGHT, both of which the hand fixtures had only guessed at. The real artifact carries SIX members this module ignores entirely (package_id, manifest_path, profile, features, filenames, fresh), so the claim that unmodelled members are skipped is now tested against the real member set rather than an imagined one. And the same-target-name collision is NOT hypothetical: one ordinary build emitted EIGHTEEN compiler-artifact messages all naming the target build-script-build, one per package with a build script. A first-wins selector would answer that with a confident wrong artifact on any workspace build; the ambiguity refusal fires on real bytes, which is why it is a refusal and not a preference." +// The fixtures above are hand-authored, which proves the decode logic and nothing about whether it +// matches what cargo emits — a decoder can be self-consistent against a shape its upstream never +// produces. The rows below are RECORDED from a real run of `cargo build -p v1-compiler --bin +// claim_batch --message-format=json` (143 messages), verbatim except that absolute paths were +// rewritten to a neutral root, because the recording machine's home directory is not a fact about +// cargo and would make the claim environment-specific. Every structural property cargo produced is +// preserved: member names and order, the nine members a real compiler-artifact carries against the +// three this module reads, the eight members inside target, and executable as a string on the +// binary while the libraries carry null. TWO THINGS THE RECORDING TAUGHT that the hand fixtures had +// only guessed at. The real artifact carries SIX members this module ignores (package_id, +// manifest_path, profile, features, filenames, fresh), so the skipped-unmodelled-members claim is +// now tested against the real member set. And the same-target-name collision is NOT hypothetical: +// one ordinary build emitted EIGHTEEN compiler-artifact messages all naming the target +// build-script-build, one per package with a build script. A first-wins selector would answer that +// with a confident wrong artifact on any workspace build; the ambiguity refusal fires on real +// bytes, which is why it is a refusal and not a preference. data real_cargo_artifact_claim_batch: String = "\{\"reason\":\"compiler-artifact\",\"package_id\":\"path+file:///w/src/v1/stage0#v1-compiler@0.1.0\",\"manifest_path\":\"/w/src/v1/stage0/Cargo.toml\",\"target\":\{\"kind\":[\"bin\"],\"crate_types\":[\"bin\"],\"name\":\"claim_batch\",\"src_path\":\"/w/src/v1/stage0/src/bin/claim_batch.rs\",\"edition\":\"2021\",\"doc\":true,\"doctest\":false,\"test\":true\},\"profile\":\{\"opt_level\":\"2\",\"debuginfo\":0,\"debug_assertions\":false,\"overflow_checks\":true,\"test\":false\},\"features\":[\"default\"],\"filenames\":[\"/w/target/debug/claim_batch\"],\"executable\":\"/w/target/debug/claim_batch\",\"fresh\":true\}" @@ -363,7 +386,16 @@ test fn a_real_library_artifact_reports_no_executable() -> Bool { } } -data absent_versus_null_executable_note: String = "THE DISCRIMINATING PAIR for the absent-vs-null split. Cargo documents executable as present-and-null for a target with no runnable binary, so an explicit null is a legitimate result while an absent member means the message does not satisfy the compiler-artifact shape at all. An earlier revision collapsed both into no-executable, which let a drifted or truncated message answer confidently as `this target has no binary` — this module's own thesis failing inside the module, since the point is that the path must be the one cargo NAMED. These two claims are stated together deliberately: either one alone passes under the collapse, and only the pair distinguishes the two upstream facts. Grounded in the recording rather than in argument: all 124 compiler-artifact messages in the 143-message capture carry the executable key (123 explicit null, one string), so absence is not a shape a healthy build produces." +// THE DISCRIMINATING PAIR for the absent-vs-null split. Cargo documents executable as +// present-and-null for a target with no runnable binary, so an explicit null is a legitimate result +// while an absent member means the message does not satisfy the compiler-artifact shape at all. An +// earlier revision collapsed both into no-executable, letting a drifted or truncated message answer +// confidently as `this target has no binary` — this module's own thesis failing inside the module, +// since the path must be the one cargo NAMED. The two claims are stated together deliberately: +// either alone passes under the collapse; only the pair distinguishes the two upstream facts. +// Grounded in the recording: all 124 compiler-artifact messages in the 143-message capture carry +// the executable key (123 explicit null, one string), so absence is not a shape a healthy build +// produces. test fn an_artifact_message_with_no_executable_member_refuses() -> Bool { match select_from( diff --git a/dag/test/claim/carrier_derivation_baseline_witness_test.dag b/dag/test/claim/carrier_derivation_baseline_witness_test.dag index a6368dc765f..10c4770a483 100644 --- a/dag/test/claim/carrier_derivation_baseline_witness_test.dag +++ b/dag/test/claim/carrier_derivation_baseline_witness_test.dag @@ -8,7 +8,30 @@ import v2.std.live_tree { LiveTreeDisposition, SubstrateInputsOnly } data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data carrier_derivation_baseline_note: String = "THE ORACLE IS THE COMMITTED PRIOR AUTHORITY, NOT A MEASUREMENT OF THE CURRENT TREE. Every literal below is the exact content of the five hand-authored spelling maps as they stood before the carrier roster replaced them -- kernel_algebra_profile in std.algebra and container_template_algebra_rows, container_template_alias_rows, container_type_arity and canonical_container_names in std.types, at gunbc main 9180ecb174. That is a versioned prior authority in the sense DESIGN.md section 5 requires of a merge-blocking literal, and the assertion is an identity join over key/value pairs rather than a count: a derivation that produced the right NUMBER of rows with a wrong key still fails here.\n\nWHAT IT IS FOR. The roster change is a refactor whose entire claim is that nothing observable moved -- the five maps are now folds over one AlgebraCarrier list instead of five literals, and the compiler consumes them at method-existence, container-arity, alias-resolution and coercion-inhabitant decisions. Those consumers are spread across 04_types, 04_infer and coercion, so a silent one-key drift would surface as an unrelated refusal somewhere else entirely, or not at all. This witness is the join that makes the equality the change asserts an executed fact.\n\nIT IS EXPECTED TO CHANGE WHEN A CARRIER IS ADDED, and that is the point rather than a defect in it. An eleventh carrier legitimately alters these maps; a red here says the author must state which maps it joins, which is exactly the question the five literals let an author skip. What it refuses is a carrier row edited in a way that moves a derived map WITHOUT the author intending it -- a membership flipped while adjusting a neighbouring field, a spelling renamed on one row and not another. The baseline is not a snapshot of whatever the tree currently produces; re-deriving it from the current tree would collapse it to measure() == measure(), which is the change detector DESIGN.md section 5 names and rejects." +// THE ORACLE IS THE COMMITTED PRIOR AUTHORITY, NOT A MEASUREMENT OF THE CURRENT TREE. Every literal +// below is the exact content of the five hand-authored spelling maps as they stood before the +// carrier roster replaced them -- kernel_algebra_profile in std.algebra and +// container_template_algebra_rows, container_template_alias_rows, container_type_arity and +// canonical_container_names in std.types, at gunbc main 9180ecb174. That is a versioned prior +// authority in the sense DESIGN.md section 5 requires of a merge-blocking literal, and the +// assertion is an identity join over key/value pairs rather than a count: a derivation that +// produced the right NUMBER of rows with a wrong key still fails here. +// +// WHAT IT IS FOR. The roster change is a refactor whose entire claim is that nothing observable +// moved -- the five maps are now folds over one AlgebraCarrier list instead of five literals, and +// the compiler consumes them at method-existence, container-arity, alias-resolution and +// coercion-inhabitant decisions. Those consumers are spread across 04_types, 04_infer and coercion, +// so a silent one-key drift would surface as an unrelated refusal somewhere else entirely, or not +// at all. This witness is the join that makes the equality the change asserts an executed fact. +// +// IT IS EXPECTED TO CHANGE WHEN A CARRIER IS ADDED, and that is the point rather than a defect in +// it. An eleventh carrier legitimately alters these maps; a red here says the author must state +// which maps it joins, which is exactly the question the five literals let an author skip. What it +// refuses is a carrier row edited in a way that moves a derived map WITHOUT the author intending it +// -- a membership flipped while adjusting a neighbouring field, a spelling renamed on one row and +// not another. The baseline is not a snapshot of whatever the tree currently produces; re-deriving +// it from the current tree would collapse it to measure() == measure(), which is the change +// detector DESIGN.md section 5 names and rejects. fn expected_profile_keys() -> List { ["Bool", "FinitePowerSet", "FinitelySupportedFunction", "Float", "Int", "List", "Map", "PartialFunction", "Set", "String"] diff --git a/dag/test/claim/change_realization_witness_test.dag b/dag/test/claim/change_realization_witness_test.dag index 7731b725829..4567294f5ee 100644 --- a/dag/test/claim/change_realization_witness_test.dag +++ b/dag/test/claim/change_realization_witness_test.dag @@ -54,7 +54,11 @@ fn is_realized(c: ChangeRealizationClassification, expected_in_place: Bool) -> B } } -data w_scm_ref_is_cas_note: String = "An SCM ref update classifies as a compare-and-swap because git update-ref NAMES the expected prior — the from side of MemberChanged. This is the row that shows the from side UNLOCKS a realization rather than merely documenting one: with only `to` in hand the sole reachable realization is the unconditional write, and a concurrent update would be silently overwritten instead of losing." +// An SCM ref update classifies as a compare-and-swap because git update-ref NAMES +// the expected prior — the from side of MemberChanged. This is the row that shows the from side +// UNLOCKS a realization rather than merely documenting one: with only `to` in hand the sole +// reachable realization is the unconditional write, and a concurrent update would be silently +// overwritten instead of losing. test fn w_scm_ref_update_is_compare_and_swap() -> Bool { match classify_change(subject: ScmRefSubject, subject_label: "refs/heads/main" as NonEmptyStr, continuity: AddressPreserved, declared_intermediates: none) { @@ -69,7 +73,12 @@ test fn w_scm_ref_update_is_compare_and_swap() -> Bool { } } -data w_source_move_is_not_host_migration_note: String = "THE CONFLATION THIS TABLE KILLS. A .dag module re-home is an atomic SCM TREE TRANSFORMATION: it changes no runtime address, unlinks no socket, restarts no unit, and needs no intermediates. Treating it as a host migration is what made an ordinary source cleanup look like it required an operational migration plan. Discriminating against the host row below: the SAME AddressChanged input yields a tree transformation for a source declaration and a staged replacement for a host resource — so the subject, not the address delta alone, decides." +// THE CONFLATION THIS TABLE KILLS. A .dag module re-home is an atomic SCM TREE TRANSFORMATION: it +// changes no runtime address, unlinks no socket, restarts no unit, and needs no intermediates. +// Treating it as a host migration is what made an ordinary source cleanup look like it required an +// operational migration plan. Discriminating against the host row below: the SAME AddressChanged +// input yields a tree transformation for a source declaration and a staged replacement for a host +// resource — so the subject, not the address delta alone, decides. test fn w_source_declaration_move_is_tree_transformation_not_migration() -> Bool { let moved = classify_change( @@ -90,7 +99,11 @@ test fn w_source_declaration_move_is_tree_transformation_not_migration() -> Bool } } -data w_host_address_decides_note: String = "For a host resource the deciding fact is whether the RUNTIME ADDRESS survived. Same unit name / socket / FIFO means the running thing absorbs a new value in place. A changed address means two addresses exist during the transition and the old one must be retired — a staged operation with observable intermediate states. Both directions asserted from the same subject, so the address axis is proven to decide rather than being incidentally true." +// For a host resource the deciding fact is whether the RUNTIME ADDRESS survived. Same unit name / +// socket / FIFO means the running thing absorbs a new value in place. A changed address means two +// addresses exist during the transition and the old one must be retired — a staged operation with +// observable intermediate states. Both directions asserted from the same subject, so the address +// axis is proven to decide rather than being incidentally true. test fn w_host_resource_address_preserved_is_in_place() -> Bool { is_realized( @@ -117,7 +130,15 @@ test fn w_host_resource_address_changed_is_staged_replacement() -> Bool { ) } -data w_srv4_undeclared_intermediates_refuses_note: String = "THE srv4 SPECIMEN, made executable. srv4's build-cache server died with its cgroup, never unlinked its socket, and ran uncached for weeks because nobody modeled the intermediate state. gunbc.build_cache_instance says in PROSE that a managed unit must clear a stale endpoint on start, and a sentence in prose is the one place no machine can read it (DESIGN §4c). This row is the machine reading it: a staged replacement whose intermediates were never declared REFUSES, typed and located. It does NOT silently degrade to an in-place update and it does NOT proceed with an empty plan — the first is the absorbing fallback DESIGN §5 forbids, and the second IS the srv4 outcome. The discriminating half is that the ONLY difference from the accepted row above is the missing declaration." +// THE srv4 SPECIMEN, made executable. srv4's build-cache server died with its cgroup, never +// unlinked its socket, and ran uncached for weeks because nobody modeled the intermediate state. +// gunbc.build_cache_instance says in PROSE that a managed unit must clear a stale endpoint on +// start, and a sentence in prose is the one place no machine can read it (DESIGN §4c). This row is +// the machine reading it: a staged replacement whose intermediates were never declared REFUSES, +// typed and located. It does NOT silently degrade to an in-place update and it does NOT proceed +// with an empty plan — the first is the absorbing fallback DESIGN §5 forbids, and the second IS the +// srv4 outcome. The discriminating half is that the ONLY difference from the accepted row above is +// the missing declaration. test fn w_staged_replacement_without_declared_intermediates_refuses() -> Bool { match classify_change( @@ -135,7 +156,11 @@ test fn w_staged_replacement_without_declared_intermediates_refuses() -> Bool { } } -data w_intermediates_nonempty_by_construction_note: String = "StagedIntermediates is head + tail, not a List that could be []. So the srv4 state — a staged replacement that believed it had nothing to retire — is UNREPRESENTABLE rather than validated against (DESIGN §5 construction-over-validation, §4b: the invalid state has no constructor). This row asserts the floor that construction guarantees: every StagedIntermediates yields at least one step, so a count of zero cannot be built to be tested for." +// StagedIntermediates is head + tail, not a List that could be []. So the srv4 state — a staged +// replacement that believed it had nothing to retire — is UNREPRESENTABLE rather than validated +// against (DESIGN §5 construction-over-validation, §4b: the invalid state has no constructor). This +// row asserts the floor that construction guarantees: every StagedIntermediates yields at least one +// step, so a count of zero cannot be built to be tested for. test fn w_staged_intermediates_are_never_empty() -> Bool { let single = one_intermediate(step: StopPriorUnit { unit: "sccache.service" as NonEmptyStr }) @@ -152,7 +177,13 @@ test fn w_staged_intermediates_are_never_empty() -> Bool { && count(staged_intermediates_all(steps: many)) == 3 } -data w_identity_minted_not_derived_note: String = "Identity is MINTED BY THE ALLOCATOR, never derived from content, path, or unit name. This is what makes a rename ONE change rather than a delete-plus-create that some key function has to be clever enough to re-pair: git does not track renames, it INFERS them from content similarity after the fact, and DESIGN §4 rules a heuristic never necessary in a closed system. The row asserts the property that inference cannot give you — a resource whose unit name AND storage path both changed still compares as the SAME occurrence, because the occurrence was allocated, not computed." +// Identity is MINTED BY THE ALLOCATOR, never derived from content, path, or unit name. This is what +// makes a rename ONE change rather than a delete-plus-create that some key function has to be +// clever enough to re-pair: git does not track renames, it INFERS them from content similarity +// after the fact, and DESIGN §4 rules a heuristic never necessary in a closed system. The row +// asserts the property that inference cannot give you — a resource whose unit name AND storage path +// both changed still compares as the SAME occurrence, because the occurrence was allocated, not +// computed. test fn w_occurrence_survives_total_value_change() -> Bool { let a0 = resource_occurrence_allocator_initial() @@ -171,7 +202,11 @@ test fn w_occurrence_survives_total_value_change() -> Bool { && !resource_occurrence_eq(left: first.id, right: second.id) } -data w_identity_is_host_scoped_note: String = "The occurrence is scoped BY HOST: HostResourceIdentity pairs a HostIdentity with the occurrence, so the same occurrence ordinal on two different hosts is two different resources. Without the host component a per-host allocator's ordinals would collide across the fleet and two unrelated resources would compare equal — the same numeric-coincidence failure that keeps this carrier separate from std.occurrence_identity in the first place." +// The occurrence is scoped BY HOST: HostResourceIdentity pairs a HostIdentity with the occurrence, +// so the same occurrence ordinal on two different hosts is two different resources. Without the +// host component a per-host allocator's ordinals would collide across the fleet and two unrelated +// resources would compare equal — the same numeric-coincidence failure that keeps this carrier +// separate from std.occurrence_identity in the first place. test fn w_same_occurrence_different_host_is_different_identity() -> Bool { let a0 = resource_occurrence_allocator_initial() diff --git a/dag/test/claim/char_at_unicode_witness_test.dag b/dag/test/claim/char_at_unicode_witness_test.dag index dc81dc041ef..e8aa6849a16 100644 --- a/dag/test/claim/char_at_unicode_witness_test.dag +++ b/dag/test/claim/char_at_unicode_witness_test.dag @@ -2,7 +2,9 @@ module test.claim.char_at_unicode_witness data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data char_at_unicode_witness_note: String = "CHARAT-0 discriminating control: char_at indexes Unicode code points, not UTF-8 bytes. A byte-offset implementation returns the wrong character at index 1 on \"aéb\" (continuation byte U+00A9 misread as ©) while code-point indexing returns U+00E9." +// CHARAT-0 discriminating control: char_at indexes Unicode code points, not UTF-8 bytes. A +// byte-offset implementation returns the wrong character at index 1 on "aéb" (continuation byte +// U+00A9 misread as ©) while code-point indexing returns U+00E9. fn ae_b_sample() -> String { concat("a", concat(from_code_point(cp: 233), "b")) @@ -24,7 +26,15 @@ test fn string_length_counts_code_points_not_bytes() -> Bool { string_length(s: ae_b_sample()) == 3 } -data char_at_ascii_prefix_fast_path_note: String = "STRING-INDEX-0 discriminating control for the prefix-bounded ASCII fast path. char_at/substring no longer rescan the whole string for ASCII-ness; they test only the bytes up to the requested position, so a string whose ASCII PREFIX is followed by a multibyte char now takes the byte-indexed path for positions inside that prefix and the code-point path beyond it. On \"ab\" + U+00E9 + \"c\" (5 bytes, 4 code points) a byte-offset implementation returns U+00A9 at index 3 and \"c\" at index 4; code-point indexing returns \"c\" at index 3 and nothing at index 4. These two claims cover char_at only: substring takes the same prefix-bounded fast path, but removing its prefix check left every witness green, so no discriminating control for it is asserted here rather than one that has never been seen to fail." +// STRING-INDEX-0 discriminating control for the prefix-bounded ASCII fast path. char_at/substring +// no longer rescan the whole string for ASCII-ness; they test only the bytes up to the requested +// position, so a string whose ASCII PREFIX is followed by a multibyte char now takes the +// byte-indexed path for positions inside that prefix and the code-point path beyond it. On "ab" + +// U+00E9 + "c" (5 bytes, 4 code points) a byte-offset implementation returns U+00A9 at index 3 and +// "c" at index 4; code-point indexing returns "c" at index 3 and nothing at index 4. These two +// claims cover char_at only: substring takes the same prefix-bounded fast path, but removing its +// prefix check left every witness green, so no discriminating control for it is asserted here +// rather than one that has never been seen to fail. fn ab_e_c_sample() -> String { concat("ab", concat(from_code_point(cp: 233), "c")) diff --git a/dag/test/claim/check_coverage_admission_witness_test.dag b/dag/test/claim/check_coverage_admission_witness_test.dag index 83e4ee3c070..70db4cc5446 100644 --- a/dag/test/claim/check_coverage_admission_witness_test.dag +++ b/dag/test/claim/check_coverage_admission_witness_test.dag @@ -173,6 +173,13 @@ test fn duplicate_required_gate_refuses() -> Bool { }) } +// The green has exactly two required gates, each executed once and successful on the exact head and +// roster. Each RED varies one axis: no observation, running, stopped with a named unexecuted gate, +// stale identities, old head, old roster, empty universe, missing execution, duplicate execution, +// or failed execution. The stopped witness inspects the refusal payload rather than merely +// asserting false, so the unexecuted population and remedy-bearing cause cannot be dropped while +// the test stays green. + test fn required_gate_failure_refuses() -> Bool { !admits(coverage: CheckCoverageComplete { head: required_head, @@ -180,5 +187,3 @@ test fn required_gate_failure_refuses() -> Bool { conclusions: [passed(gate: gate_a), failed(gate: gate_b)] }) } - -data coverage_discrimination_note: String = "The green has exactly two required gates, each executed once and successful on the exact head and roster. Each RED varies one axis: no observation, running, stopped with a named unexecuted gate, stale identities, old head, old roster, empty universe, missing execution, duplicate execution, or failed execution. The stopped witness inspects the refusal payload rather than merely asserting false, so the unexecuted population and remedy-bearing cause cannot be dropped while the test stays green." diff --git a/dag/test/claim/ci/ci_budget_tree_witness_test.dag b/dag/test/claim/ci/ci_budget_tree_witness_test.dag index a239ad5892b..5679ff2e3f5 100644 --- a/dag/test/claim/ci/ci_budget_tree_witness_test.dag +++ b/dag/test/claim/ci/ci_budget_tree_witness_test.dag @@ -113,12 +113,29 @@ test fn witness_hard_cap_is_runner_cgroup_cap() -> Bool { byte_size_count(b: srv1_ci_run_container_hard_cap()) == byte_size_count(b: gunbc_ci_runner_cgroup_memory_cap) } - test fn witness_floor_budget_equals_selected_target_budget_holds() -> Bool { witness_floor_budget_equals_selected_target_budget() } -data srv3_asymmetry_supersedes_symmetry_note: String = "THIS WITNESS ASSERTED THE OPPOSITE UNTIL 2026-08-05 and the inversion is the change, not a broken test. witness_srv3_symmetric_to_srv1 held that srv1 and srv3 derive the SAME runner pool from the same session slice, which was true while every host shared one fixed-overhead number, and it was worth asserting then: srv3 had just been stood up and the claim being defended was that a FreshStandup host is budgeted identically to an established one rather than getting a special case.\n\nWhat changed is not the claim's importance but its truth. gunbc.ci_floor_measurement now carries a MEASURED overhead bound for the managed hosts (srv3/srv4) and an operator ALLOWANCE for the legacy pair (srv1/srv2), because srv1 and srv2 host hand-built deployments the corpus does not model and srv3 does not. Same board, same RAM, same per-slot row — different unmodeled residents, so different allocatable memory. Asserting equality now would require charging srv3 for srv1's mess, which is exactly the 10.4GiB per host this split exists to stop spending.\n\nWhat is asserted instead is STRICTLY STRONGER than the old equality: not merely that the two differ, but that they differ in the right DIRECTION and by exactly the overhead gap. A witness that only checked p1 != p3 would pass if the numbers were swapped — srv1 handed the measured bound and srv3 the legacy allowance — which is the same bug with the hosts transposed and is precisely the failure a bare inequality cannot see." +// THIS WITNESS ASSERTED THE OPPOSITE UNTIL 2026-08-05 and the inversion is the change, not a broken +// test. witness_srv3_symmetric_to_srv1 held that srv1 and srv3 derive the SAME runner pool from the +// same session slice, which was true while every host shared one fixed-overhead number, and it was +// worth asserting then: srv3 had just been stood up and the claim being defended was that a +// FreshStandup host is budgeted identically to an established one rather than getting a special +// case. +// +// What changed is not the claim's importance but its truth. gunbc.ci_floor_measurement now carries +// a MEASURED overhead bound for the managed hosts (srv3/srv4) and an operator ALLOWANCE for the +// legacy pair (srv1/srv2), because srv1 and srv2 host hand-built deployments the corpus does not +// model and srv3 does not. Same board, same RAM, same per-slot row — different unmodeled residents, +// so different allocatable memory. Asserting equality now would require charging srv3 for srv1's +// mess, which is exactly the 10.4GiB per host this split exists to stop spending. +// +// What is asserted instead is STRICTLY STRONGER than the old equality: not merely that the two +// differ, but that they differ in the right DIRECTION and by exactly the overhead gap. A witness +// that only checked p1 != p3 would pass if the numbers were swapped — srv1 handed the measured +// bound and srv3 the legacy allowance — which is the same bug with the hosts transposed and is +// precisely the failure a bare inequality cannot see. test fn witness_srv3_outbudgets_srv1_by_exactly_the_overhead_gap() -> Bool { let s1 = host_budget_tree_at(name: "srv1", offer: srv1_offer, session_slice: byte_size(fitting_slice())) diff --git a/dag/test/claim/ci/ci_cost_arc_closeout_receipt_witness_test.dag b/dag/test/claim/ci/ci_cost_arc_closeout_receipt_witness_test.dag index cbf42d5d26c..85cae146ca7 100644 --- a/dag/test/claim/ci/ci_cost_arc_closeout_receipt_witness_test.dag +++ b/dag/test/claim/ci/ci_cost_arc_closeout_receipt_witness_test.dag @@ -117,7 +117,19 @@ test fn witness_native_fleet_rate_open() -> Bool { } } -data witness_warm_hit_skip_proof_landed_note: String = "UPDATED 2026-08-11 (gunbc#8146): warm_hit_settle now reads SkipProofWithdrawn, because the module carrying cross_process_hit_skips_semantic_recompute was executed for the first time and reports 3 failures in 1321s, so the skip proof has no executing consumer. The assertion below tracks the withdrawal EXPLICITLY rather than being deleted — per DESIGN §4b(4) the control stays enrolled, and it must flip back to ClosedSkipProofLanded only when the evidence executes again. HISTORY — renamed from witness_warm_hit_partial (DESIGN §4b(4) — a probe that expected an open state and then closed flips to a permanent regression control, it does not retire): cross_process_hit_skips_semantic_recompute (v1_compiler_tests.resolve_cross_process_cache_test) now asserts TYPECHECK_COMPUTE_COUNT stays 0 on a warm cross-process disk-tier hit, green by execution. warm_hit_settle therefore reads ClosedSkipProofLanded, not PartiallyDeliveredSkipProofOpen. A future regression that reopens the skip-proof gap (or reverts this settle without re-landing the counter proof) must flip this assertion back, which is exactly the signal this test now exists to catch." +// UPDATED 2026-08-11 (gunbc#8146): warm_hit_settle now reads SkipProofWithdrawn, because the module +// carrying cross_process_hit_skips_semantic_recompute was executed for the first time and reports 3 +// failures in 1321s, so the skip proof has no executing consumer. The assertion below tracks the +// withdrawal EXPLICITLY rather than being deleted — per DESIGN §4b(4) the control stays enrolled, +// and it must flip back to ClosedSkipProofLanded only when the evidence executes again. HISTORY — +// renamed from witness_warm_hit_partial (DESIGN §4b(4) — a probe that expected an open state and +// then closed flips to a permanent regression control, it does not retire): +// cross_process_hit_skips_semantic_recompute (v1_compiler_tests.resolve_cross_process_cache_test) +// now asserts TYPECHECK_COMPUTE_COUNT stays 0 on a warm cross-process disk-tier hit, green by +// execution. warm_hit_settle therefore reads ClosedSkipProofLanded, not +// PartiallyDeliveredSkipProofOpen. A future regression that reopens the skip-proof gap (or reverts +// this settle without re-landing the counter proof) must flip this assertion back, which is exactly +// the signal this test now exists to catch. test fn witness_warm_hit_skip_proof_landed() -> Bool { match warm_hit_settle() { diff --git a/dag/test/claim/ci/ci_deploy_observed_wet_test.dag b/dag/test/claim/ci/ci_deploy_observed_wet_test.dag index a957cb2ea17..67e46929fe2 100644 --- a/dag/test/claim/ci/ci_deploy_observed_wet_test.dag +++ b/dag/test/claim/ci/ci_deploy_observed_wet_test.dag @@ -1,7 +1,14 @@ module test.claim.ci_deploy_observed_wet - -data ci_deploy_observed_wet_note: String = "OFFLINE wet integration witness (hermetic-floor split, operator posture 2026-07-11: integration-style witnesses do not run regularly; CI runs hermetic/mocked variants). deploy_access_check_observed shells live whoami + sudo -n, so this half of test.claim.ci_deploy_witness moved here when the discovery corpus flipped Hermetic; the pure half (script pins, enrollment pins, and the mock-shaped deploy_access_check(access, actor) dual) stays discovered. Local recipe: claim_batch --wet --source-root dag --source-root src/v2 --entry dag/test/claim/ci/ci_deploy_observed_wet_test.dag. Dissolve-on: the scheduled (nightly) lane un-darkens and admits wet integration rows under its own budget — then enroll this entry there as a declared execution row." +// OFFLINE wet integration witness (hermetic-floor split, operator posture 2026-07-11: +// integration-style witnesses do not run regularly; CI runs hermetic/mocked variants). +// deploy_access_check_observed shells live whoami + sudo -n, so this half of +// test.claim.ci_deploy_witness moved here when the discovery corpus flipped Hermetic; the pure half +// (script pins, enrollment pins, and the mock-shaped deploy_access_check(access, actor) dual) stays +// discovered. Local recipe: claim_batch --wet --source-root dag --source-root src/v2 --entry +// dag/test/claim/ci/ci_deploy_observed_wet_test.dag. Dissolve-on: the scheduled (nightly) lane +// un-darkens and admits wet integration rows under its own budget — then enroll this entry there as +// a declared execution row. fn ci_deploy_observed_runner_principal_name() -> String { grounded_posix_principal_name(p: ci_deploy_srv1_access.principal) as String diff --git a/dag/test/claim/ci/ci_deploy_target_host_witness_test.dag b/dag/test/claim/ci/ci_deploy_target_host_witness_test.dag index ed25141f348..5c5904c3962 100644 --- a/dag/test/claim/ci/ci_deploy_target_host_witness_test.dag +++ b/dag/test/claim/ci/ci_deploy_target_host_witness_test.dag @@ -60,15 +60,16 @@ test fn witness_ssh_transport_mismatch_refused() -> Bool { ) } -// deploy_runner_label_list_contains carries a qualified name because the bare one was a homonym and this -// module declares no imports, so every reference it makes is resolved out of whatever pool the run assembled. -// gunbc.design.component declares a byte-identical label_list_contains under different parameter names -// (xs, x), and a run whose pool contained that module bound THIS module's own call sites to it — the witness -// failed with "no parameter named 'labels' (declared: [xs, x])", a local declaration losing to a pool member. -// The rename removes the collision at this site. It does not fix the underlying class twice over: one concept -// (membership in a List) still has three declarations in the corpus — the component one, this one, and -// std.materialization_ladder string_list_contains — and reference binding still varies with which unrelated -// files a run happens to load. Both are recorded on the namespace lane, neither is repaired here. +// deploy_runner_label_list_contains carries a qualified name because the bare one was a homonym +// and this module declares no imports, so every reference resolves out of whatever pool the run +// assembled. gunbc.design.component declares a byte-identical label_list_contains under different +// parameter names (xs, x), and a run whose pool contained that module bound THIS module's call +// sites to it — the witness failed with "no parameter named 'labels' (declared: [xs, x])", a local +// declaration losing to a pool member. The rename removes the collision at this site. It does not +// fix the underlying class: one concept (membership in a List) still has three +// declarations in the corpus — the component one, this one, and std.materialization_ladder +// string_list_contains — and reference binding still varies with which unrelated files a run +// loads. Both are recorded on the namespace lane; neither is repaired here. fn deploy_runner_label_list_contains(labels: List, needle: String) -> Bool { fold(labels, init: false, f: (acc, l) => acc || (l == needle)) } diff --git a/dag/test/claim/ci/ci_floor_on_success_materialization_receipt_hand_rust_witness_test.dag b/dag/test/claim/ci/ci_floor_on_success_materialization_receipt_hand_rust_witness_test.dag index ba9fee6cd16..6eb59f4af57 100644 --- a/dag/test/claim/ci/ci_floor_on_success_materialization_receipt_hand_rust_witness_test.dag +++ b/dag/test/claim/ci/ci_floor_on_success_materialization_receipt_hand_rust_witness_test.dag @@ -11,7 +11,11 @@ import gunbc.ci_materialization { import std.disposition { Scaffold, SingleAuthority } import std.types { Bool, String } -data ci_floor_on_success_materialization_receipt_hand_rust_witness_note: String = "HAND-RUST checkable receipt for #7499 blocker 6: pins the seed-retained scaffold bind, attempt-scoped path authority, and the bounded deferral (plan anchor + ROADMAP lane). Behavioral population separation (ordinary vs on-success) is cross-checked by cargo test on_success_materialization_receipt_separates_from_ordinary_floor in claim_executor.rs (PROCESS_EVAL_RECOMPUTE_TEST_LOCK)." +// HAND-RUST checkable receipt for #7499 blocker 6: pins the seed-retained scaffold bind, +// attempt-scoped path authority, and the bounded deferral (plan anchor + ROADMAP lane). Behavioral +// population separation (ordinary vs on-success) is cross-checked by cargo test +// on_success_materialization_receipt_separates_from_ordinary_floor in claim_executor.rs +// (PROCESS_EVAL_RECOMPUTE_TEST_LOCK). test fn scaffold_is_seed_retained_on_path_authority() -> Bool { match ci_floor_on_success_materialization_receipt_claim_executor_seed_disposition { diff --git a/dag/test/claim/claim_entailing_evidence_cause_swap_witness_test.dag b/dag/test/claim/claim_entailing_evidence_cause_swap_witness_test.dag index 89aff8b7f4b..2ed2603ad2e 100644 --- a/dag/test/claim/claim_entailing_evidence_cause_swap_witness_test.dag +++ b/dag/test/claim/claim_entailing_evidence_cause_swap_witness_test.dag @@ -8,9 +8,33 @@ import tools.self_host_curated_seed_linked_harness { data live_tree_disposition: v2.std.live_tree.LiveTreeDisposition = v2.std.live_tree.SubstrateInputsOnly -data cause_swap_witness_doc: String = "THE CAUSE-SWAP CONTROL for tools.self_host_curated_seed_linked_harness cssl_fault_run_detected_the_planted_fault. It is an unusual control and the shape is the point: it is a probe the OLD mechanism PASSES and the NEW one must REFUSE. A conventional discriminating red cannot detect this class at all, because the subject is fine -- the EVIDENCE ABOUT the subject is what was invalid, so the control has to test the carrier rather than the subject. The rule it enforces: an evidence standing may establish a proposition only when EVERY execution path that constructs it proves the subject reached the relevant phase and entails the proposition. The old predicate fault_run.success == false was true when the planted fault was detected AND when the binary never existed, so its truth set was strictly wider than the proposition it was cited for. Both arms below hold the OLD predicate constant at true and vary only the CAUSE; the new carrier must admit the first and refuse the second." - -data cause_swap_discriminating_subset_note: String = "FOUR OF THESE EIGHT ARMS DISCRIMINATE FOR THE REPAIR, NOT EIGHT, and the difference matters to anyone counting green arms as coverage. Measured by mutation 2026-08-26 -- collapsing cssl_fault_run_detected_the_planted_fault back to the old single conjunct reds exactly absent_binary_is_refused_not_treated_as_detection, killed_before_comparison_is_refused, fault_run_that_agreed_is_refused and malformed_pass_marker_establishes_nothing. Every one of those is a run that never reached its comparison being cited as a comparison that disagreed, which is the class the repair closes.\n\nThe other four stay green under that mutation and are not thereby idle. old_predicate_cannot_tell_the_two_causes_apart is the control that proves the two arms were genuinely indistinguishable to the mechanism being replaced; detected_fault_is_admitted pins that the repair did not narrow past the case it must admit; stem_is_derived_from_the_pass_marker pins the derivation; and zero_exit_is_still_refused guards a DIFFERENT hole -- both predicates refuse it, so it is a real arm and not a discriminating one here. Recording which arms flip is what stops eight greens being read as eight walls." +// THE CAUSE-SWAP CONTROL for tools.self_host_curated_seed_linked_harness +// cssl_fault_run_detected_the_planted_fault. It is an unusual control and the shape is the point: +// it is a probe the OLD mechanism PASSES and the NEW one must REFUSE. A conventional discriminating +// red cannot detect this class at all, because the subject is fine -- the EVIDENCE ABOUT the +// subject is what was invalid, so the control has to test the carrier rather than the subject. The +// rule it enforces: an evidence standing may establish a proposition only when EVERY execution path +// that constructs it proves the subject reached the relevant phase and entails the proposition. The +// old predicate fault_run.success == false was true when the planted fault was detected AND when +// the binary never existed, so its truth set was strictly wider than the proposition it was cited +// for. Both arms below hold the OLD predicate constant at true and vary only the CAUSE; the new +// carrier must admit the first and refuse the second. + +// FOUR OF THESE EIGHT ARMS DISCRIMINATE FOR THE REPAIR, NOT EIGHT, and the difference matters to +// anyone counting green arms as coverage. Measured by mutation 2026-08-26 -- collapsing +// cssl_fault_run_detected_the_planted_fault back to the old single conjunct reds exactly +// absent_binary_is_refused_not_treated_as_detection, killed_before_comparison_is_refused, +// fault_run_that_agreed_is_refused and malformed_pass_marker_establishes_nothing. Every one of +// those is a run that never reached its comparison being cited as a comparison that disagreed, +// which is the class the repair closes. +// +// The other four stay green under that mutation and are not thereby idle. +// old_predicate_cannot_tell_the_two_causes_apart is the control that proves the two arms were +// genuinely indistinguishable to the mechanism being replaced; detected_fault_is_admitted pins that +// the repair did not narrow past the case it must admit; stem_is_derived_from_the_pass_marker pins +// the derivation; and zero_exit_is_still_refused guards a DIFFERENT hole -- both predicates refuse +// it, so it is a real arm and not a discriminating one here. Recording which arms flip is what +// stops eight greens being read as eight walls. data cause_swap_pass_marker: String = "SELF_HOST_00_COMPILE_BEHAVIORAL_RECEIPT: PASS" diff --git a/dag/test/claim/class_b_import_closure_binding_refusal_witness_test.dag b/dag/test/claim/class_b_import_closure_binding_refusal_witness_test.dag index 389bfc27449..93c5d11c19c 100644 --- a/dag/test/claim/class_b_import_closure_binding_refusal_witness_test.dag +++ b/dag/test/claim/class_b_import_closure_binding_refusal_witness_test.dag @@ -13,7 +13,12 @@ import gunbc.compile_clean_diagnostic_policy { ListedImport } import v2.std.optional { Present, Absent } import std.types { Bool, NonEmptyStr } -data class_b_binding_predicate_note: String = "Per-PR discovery-admitted unit controls for gunbc.declared_import_closure_binding verdict predicates (#7835 P1). Pure folds over typed observation/outcome variants — not path-excluded and not explicit_witness_admission enrolled. binding_refused_at_seam_rejects_unrelated_hard_diagnostic exercises the fold predicate only; producer-level hard-diagnostic refusal is tested in cli_run.rs unrelated_hard_diagnostic_observation_is_not_runnable_at_producer." +// Per-PR discovery-admitted unit controls for gunbc.declared_import_closure_binding verdict +// predicates (#7835 P1). Pure folds over typed observation/outcome variants — not path-excluded and +// not explicit_witness_admission enrolled. +// binding_refused_at_seam_rejects_unrelated_hard_diagnostic exercises the fold predicate only; +// producer-level hard-diagnostic refusal is tested in cli_run.rs +// unrelated_hard_diagnostic_observation_is_not_runnable_at_producer. test fn binding_refused_at_seam_not_runnable_is_false() -> Bool { !binding_refused_at_intended_seam(obs: BindingNotRunnable { cause: "could-not-measure" as NonEmptyStr }) diff --git a/dag/test/claim/class_b_strip_receipt_witness_test.dag b/dag/test/claim/class_b_strip_receipt_witness_test.dag index fe78d5b348e..70886ae98af 100644 --- a/dag/test/claim/class_b_strip_receipt_witness_test.dag +++ b/dag/test/claim/class_b_strip_receipt_witness_test.dag @@ -7,7 +7,9 @@ import gunbc.class_b_import_closure_overlay { } import std.types { Bool } -data class_b_strip_receipt_note: String = "Per-PR discovery-admitted unit controls for gunbc.class_b_import_closure_overlay strip receipt (#7835 P1). Pure string-literal folds — not path-excluded and not explicit_witness_admission enrolled." +// Per-PR discovery-admitted unit controls for gunbc.class_b_import_closure_overlay strip receipt +// (#7835 P1). Pure string-literal folds — not path-excluded and not explicit_witness_admission +// enrolled. test fn strip_receipt_accepts_one_closed_block() -> Bool { match strip_rust_test_fixtures_import_block(content: "module m\nimport v2.extdeps.languages.rust {\n a\n}\ndata x: Int = 1\n") { diff --git a/dag/test/claim/claude_sdk_parser_drop_witness_test.dag b/dag/test/claim/claude_sdk_parser_drop_witness_test.dag index 1b37537b614..e1eb7b4ad01 100644 --- a/dag/test/claim/claude_sdk_parser_drop_witness_test.dag +++ b/dag/test/claim/claude_sdk_parser_drop_witness_test.dag @@ -17,7 +17,14 @@ import v2.std.live_tree { LiveTreeDisposition, SubstrateInputsOnly } data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data claude_sdk_parser_drop_witness_note: String = "Hermetic half of audit §4.1 parser-drop evidence: fixture positive control, RED parsed-surface control, RED forgery controls over claude_sdk_parser_drop_receipt_standing on inline JSON (dropped-array shortcut refuted, absent sdk_parsed_event_types unevidenced, unreadable bytes distinguished from both). The wet half that read the committed receipt is RETIRED, not relocated: the receipt and the instruments that produced it were deleted with docs/probes/claude_paired_entitlement_probe/, so these controls are now the whole of this evidence -- see the annotation on claude_sdk_parser_drop_witness_fixture_note in extdeps.llm.claude_agent_sdk_stream for what that costs." +// Hermetic half of audit §4.1 parser-drop evidence: fixture positive control, RED parsed-surface +// control, RED forgery controls over claude_sdk_parser_drop_receipt_standing on inline JSON +// (dropped-array shortcut refuted, absent sdk_parsed_event_types unevidenced, unreadable bytes +// distinguished from both). The wet half that read the committed receipt is RETIRED, not relocated: +// the receipt and the instruments that produced it were deleted with +// docs/probes/claude_paired_entitlement_probe/, so these controls are now the whole of this +// evidence -- see the annotation on claude_sdk_parser_drop_witness_fixture_note in +// extdeps.llm.claude_agent_sdk_stream for what that costs. test fn witness_control_response_parser_drop_fixture_holds() -> Bool { claude_sdk_control_response_parser_drop_holds( diff --git a/dag/test/claim/cli_run_hand_rust_area_ledger_witness_test.dag b/dag/test/claim/cli_run_hand_rust_area_ledger_witness_test.dag index 83bdf030497..fdd42cfe6e1 100644 --- a/dag/test/claim/cli_run_hand_rust_area_ledger_witness_test.dag +++ b/dag/test/claim/cli_run_hand_rust_area_ledger_witness_test.dag @@ -19,7 +19,22 @@ import v2.std.live_tree { LiveTreeDisposition, SubstrateInputsOnly } data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data ledger_witness_scope_note: String = "WHAT REPLACED THE PREVIOUS SHAPE, AND WHY IT IS NOT AN EQUIVALENT CHECK. This file used to assert that a prose row CONTAINED the substring 'scripts/rust_item_census.py'. That is the prose-self-match antipattern in its purest form -- the assertion's only content was that someone had written a path into a string -- and it was worse than empty, because the path it pinned had been DELETED from the tree by gunbc#9132 and this witness was the thing keeping the dead citation green. A check whose sole failure mode is 'the sentence was edited' cannot tell a repair from a regression, and here it actively defended the regression.\n\nWHAT IS ASSERTED NOW IS STRUCTURE OVER THE ROWS. The load-bearing one is that the LIVE ledger carries no GenerateNow row, because GenerateNow now carries the entry point that emits the area and no such entry point can be named for any of the sixteen. Its RED IS AUTHORABLE and is authored below rather than argued for: the fixture arm constructs a GenerateNow row and requires the counter to see it. Without that arm the live assertion would be a decoration -- permanently green because the counter could be broken in a way that returns zero for every input, which is exactly the shape DESIGN section 4b calls worse than absent. The two arms together are the check: one says the counter can count, the other says the tree has nothing to count." +// WHAT REPLACED THE PREVIOUS SHAPE, AND WHY IT IS NOT AN EQUIVALENT CHECK. This file used to assert +// that a prose row CONTAINED the substring 'scripts/rust_item_census.py'. That is the +// prose-self-match antipattern in its purest form -- the assertion's only content was that someone +// had written a path into a string -- and it was worse than empty, because the path it pinned had +// been DELETED from the tree by gunbc#9132 and this witness was the thing keeping the dead citation +// green. A check whose sole failure mode is 'the sentence was edited' cannot tell a repair from a +// regression, and here it actively defended the regression. +// +// WHAT IS ASSERTED NOW IS STRUCTURE OVER THE ROWS. The load-bearing one is that the LIVE ledger +// carries no GenerateNow row, because GenerateNow now carries the entry point that emits the area +// and no such entry point can be named for any of the sixteen. Its RED IS AUTHORABLE and is +// authored below rather than argued for: the fixture arm constructs a GenerateNow row and requires +// the counter to see it. Without that arm the live assertion would be a decoration -- permanently +// green because the counter could be broken in a way that returns zero for every input, which is +// exactly the shape DESIGN section 4b calls worse than absent. The two arms together are the check: +// one says the counter can count, the other says the tree has nothing to count. data fixture_generate_now_row: CliRunHandRustAreaRow = CliRunHandRustAreaRow { area_id: "fixture", diff --git a/dag/test/claim/cli_run_repo_grant_hand_rust_equivalence_witness_test.dag b/dag/test/claim/cli_run_repo_grant_hand_rust_equivalence_witness_test.dag index a84c88e7a60..91bb3f0c5ec 100644 --- a/dag/test/claim/cli_run_repo_grant_hand_rust_equivalence_witness_test.dag +++ b/dag/test/claim/cli_run_repo_grant_hand_rust_equivalence_witness_test.dag @@ -21,7 +21,11 @@ import v2.std.live_tree { LiveTreeDisposition, SubstrateInputsOnly } data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data cli_run_repo_grant_hand_rust_equivalence_note: String = "Pins the HAND-RUST repo_relative_path gate (src/v1/stage0/src/cli_run.rs) against gunbc.cli_run_repo_grant on the SAME fixture spellings — parallel-representation drift guard until Chunk F dissolves the Rust gate. The .dag side asserts admit_effect verdicts; the Rust side is proven by cli_run.rs cli_run_repo_grant_equivalence_tests (named discriminators below). Both must agree: contained rel admits, absolute-outside refuses, parent-segment refuses." +// Pins the HAND-RUST repo_relative_path gate (src/v1/stage0/src/cli_run.rs) against +// gunbc.cli_run_repo_grant on the SAME fixture spellings — parallel-representation drift guard +// until Chunk F dissolves the Rust gate. The .dag side asserts admit_effect verdicts; the Rust side +// is proven by cli_run.rs cli_run_repo_grant_equivalence_tests (named discriminators below). Both +// must agree: contained rel admits, absolute-outside refuses, parent-segment refuses. data fixture_contained_rel: String = "dag/std/effect_grant.dag" data fixture_escaping_rel: String = "../outside.dag" diff --git a/dag/test/claim/cli_run_repo_grant_witness_test.dag b/dag/test/claim/cli_run_repo_grant_witness_test.dag index 2aa89c43882..51b6adb0ccd 100644 --- a/dag/test/claim/cli_run_repo_grant_witness_test.dag +++ b/dag/test/claim/cli_run_repo_grant_witness_test.dag @@ -14,7 +14,11 @@ import v2.std.live_tree { LiveTreeDisposition, SubstrateInputsOnly } data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data cli_run_repo_grant_witness_note: String = "P-B discriminating witnesses for gunbc.cli_run_repo_grant (docs/plans/effect-namespace-grants.md 6). Repo-relative paths under the abstract repo subtree Permit Read+Write; escaping paths (`..` segment or absolute outside repo projection) are located std.access.Deny refusals from EffectRequest — the modeled authority the src/v1/stage0/src/cli_run.rs repo_relative_path HAND-RUST gate derives from." +// P-B discriminating witnesses for gunbc.cli_run_repo_grant (docs/plans/effect-namespace-grants.md +// 6). Repo-relative paths under the abstract repo subtree Permit Read+Write; escaping paths (`..` +// segment or absolute outside repo projection) are located std.access.Deny refusals from +// EffectRequest — the modeled authority the src/v1/stage0/src/cli_run.rs repo_relative_path +// HAND-RUST gate derives from. data in_repo_rel: String = "dag/std/effect_grant.dag" data escaping_rel: String = "../outside.dag" diff --git a/dag/test/claim/climbing_hold_witness_roster_test.dag b/dag/test/claim/climbing_hold_witness_roster_test.dag index 27bf3642fad..b4c5c9556c9 100644 --- a/dag/test/claim/climbing_hold_witness_roster_test.dag +++ b/dag/test/claim/climbing_hold_witness_roster_test.dag @@ -17,19 +17,17 @@ import test.claim.climbing_hold_catalog_witness { // WHY THIS MODULE EXISTS: a measured harness cost, not a style preference. // -// Each witness was being executed by its own `gunbc run --function` invocation. Measured on one -// witness: 146,352 ms wall, against 472 ms of logged compile phases (frontend 129, normalize 11, -// reconcile 324, analyses 8). That is 99.7 percent of the run unattributed to compilation and -// unattributed to the Boolean body. The cost is per-PROCESS: every invocation rebuilds the module -// path index across the whole source root before the entry graph narrows anything, so a suite of -// N witnesses paid that index N times. Sixteen witnesses cost about 35 minutes to evaluate -// predicates that are, individually, arithmetic on small lists. +// Each witness ran under its own `gunbc run --function` invocation. Measured on one witness: +// 146,352 ms wall against 472 ms of logged compile phases (frontend 129, normalize 11, reconcile +// 324, analyses 8) -- 99.7 percent unattributed to compilation or the Boolean body. The cost is +// per-PROCESS: every invocation rebuilds the module path index across the whole source root before +// the entry graph narrows anything, so N witnesses paid it N times; sixteen cost about 35 minutes +// to evaluate predicates that are arithmetic on small lists. // -// The program's own policy puts the migration threshold at 500 ms and the executor cutoff at -// 5,000 ms. Two-minute witnesses are far outside it, and "the witnesses take two minutes" was the -// wrong conclusion to draw: the witnesses do not take two minutes. The HARNESS takes two minutes -// and the witnesses take milliseconds. Reporting a single wall-clock number hid that distinction -// and made an addressable harness defect look like an inherent property of the claims. +// Policy puts the migration threshold at 500 ms and the executor cutoff at 5,000 ms. "The +// witnesses take two minutes" was the wrong conclusion: the HARNESS takes two minutes and the +// witnesses take milliseconds. One wall-clock number hid that and made an addressable harness +// defect look inherent to the claims. // // This roster calls every witness body from ONE entry, so the index is built once. data roster_cost_note: NonEmptyStr = "Per-invocation cost is source-root index construction, not claim evaluation: 146,352 ms wall against 472 ms of logged compile phases on a single witness. Running N witnesses as N processes pays that index N times. This roster pays it once." @@ -39,10 +37,10 @@ type WitnessOutcome { passed: Bool } -// The roster is EXACT and hand-listed rather than globbed. A glob cannot be checked: it silently -// covers whatever happens to be present, so a witness deleted by an edit disappears from the suite -// without any signal. A hand-listed roster with a declared expected count refuses that -- drop a -// row and the count check reds, naming the discrepancy rather than quietly narrowing coverage. +// The roster is EXACT and hand-listed, not globbed. A glob silently covers whatever is present, so +// a witness deleted by an edit leaves the suite without signal. A hand-listed roster with a +// declared expected count refuses that -- drop a row and the count check reds, naming the +// discrepancy. data climbing_hold_witness_outcomes: List = [ WitnessOutcome { name: "witness_mounting_axis_needs_no_shape_or_envelope", @@ -100,9 +98,8 @@ fn roster_count_matches() -> Bool { count(climbing_hold_witness_outcomes) == climbing_hold_witness_expected_count } -// Duplicate detection is not decoration. A copy-pasted row that names one witness twice while -// silently dropping another keeps the count correct and reduces real coverage by one, which is -// precisely the failure a count-only check cannot see. +// Duplicate detection is not decoration: a copy-pasted row naming one witness twice while dropping +// another keeps the count correct and reduces coverage by one, which a count-only check cannot see. fn roster_names_are_unique() -> Bool { all( climbing_hold_witness_outcomes, @@ -111,17 +108,15 @@ fn roster_names_are_unique() -> Bool { } -// THE RECEIPT. One invocation proves: the expected number of witnesses ran, each exactly once, -// under its own name, and every body returned true. A green here is a stronger statement than -// nine separate green exit codes, because those nine could not detect a tenth witness that was -// never invoked. +// THE RECEIPT. One invocation proves the expected number of witnesses ran, each exactly once under +// its own name, and every body returned true -- stronger than nine separate green exit codes, which +// cannot detect a tenth witness never invoked. test fn witness_roster_is_complete_unique_and_green() -> Bool { roster_count_matches() && roster_names_are_unique() && roster_all_green() } -// Discriminating control for the roster machinery itself. If roster_names_are_unique were -// hard-wired true, this would not catch it -- so the check is exercised against a deliberately -// duplicated list, where it must report false. +// Discriminating control for the roster machinery: roster_names_are_unique is exercised against a +// deliberately duplicated list, where it must report false, so a hard-wired true is caught. data duplicate_probe: List = [ WitnessOutcome { name: "a", passed: true }, WitnessOutcome { name: "a", passed: true }, diff --git a/dag/test/claim/codex_app_server_press_witness_test.dag b/dag/test/claim/codex_app_server_press_witness_test.dag index 3087710edec..4da7c897710 100644 --- a/dag/test/claim/codex_app_server_press_witness_test.dag +++ b/dag/test/claim/codex_app_server_press_witness_test.dag @@ -89,7 +89,6 @@ data fixture_live_exhausted_multibucket_path: String = "dag/test/fixture/provide data fixture_digest_hex: String = "c86dec3d635d6bfd980084080eaf4caeb8e8093210eebc5833921ab2b1b754172e8422d39207a0fc9cea989ab557df11138309e630b10d75d094e8eb762b4547" - fn fixture_digest() -> Sha512Digest? { sha512_hex_digest(hex: fixture_digest_hex) } @@ -481,7 +480,13 @@ test fn quota_refusal_caption_is_quota_exhausted_not_accepted() -> Bool { } } -data rate_limit_id_witness_note: String = "Discriminating controls for the limitId absorbing-fallback repair (review 50532). The fabrication these pin is NOT cosmetic: buckets are read downstream BY limit_id, so a malformed id emitted under the synthesized default would put a sibling bucket's numbers on the codex bucket. The sibling-only control is the one that fails loudest against the old code — it carries a REAL id (codex_bengalfox), so a reader that defaults on anything other than absence reports it as codex. The absence control is the positive: the legacy mirror legitimately has no limitId and must still yield codex, so this pair proves the split rather than a blanket refusal." +// Discriminating controls for the limitId absorbing-fallback repair (review 50532). The fabrication +// these pin is NOT cosmetic: buckets are read downstream BY limit_id, so a malformed id emitted +// under the synthesized default would put a sibling bucket's numbers on the codex bucket. The +// sibling-only control is the one that fails loudest against the old code — it carries a REAL id +// (codex_bengalfox), so a reader that defaults on anything other than absence reports it as codex. +// The absence control is the positive: the legacy mirror legitimately has no limitId and must still +// yield codex, so this pair proves the split rather than a blanket refusal. fn rate_limit_bucket_ids_for_stdout(line: String) -> List { let evidence = parse_account_trip_stdout_for_tests( diff --git a/dag/test/claim/codex_device_prompt_witness_test.dag b/dag/test/claim/codex_device_prompt_witness_test.dag index 50efb7cd66a..7cef01671a6 100644 --- a/dag/test/claim/codex_device_prompt_witness_test.dag +++ b/dag/test/claim/codex_device_prompt_witness_test.dag @@ -21,7 +21,23 @@ import v2.std.live_tree { LiveTreeDisposition, SubstrateInputsOnly } data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data device_prompt_witness_note: String = "THE CONSUMER THE LANE SHIPPED WITHOUT (review, 2026-07-30). codex_device_prompt_parse, TmuxCaptureFidelity, the capture shaper and both fixtures landed with zero callers — production or witness — so a parser written against real bytes was never once run against them. That is the specification-without-execution trap DESIGN 5 names: it typechecked, it read plausibly, and nothing established that it extracts anything.\\n\\nThe two fixtures are a DISCRIMINATING PAIR rather than two samples, which is why this claim can be stated at all. Both are the same codex prompt captured two ways on 2026-07-30: the direct rendering wraps the URL and the one-time code in SGR sequences, and the tmux capture-pane rendering carries none, because tmux's renderer consumed them before storing the grid. They therefore carry DIFFERENT one-time codes, being separate login attempts, and the claim pins each to its own fixture so a witness that silently read the wrong file cannot pass.\\n\\nThe escape-carrying case is the reason the brand exists, and it is asserted as a real defect rather than described: parsed directly, the code comes out with escape bytes still inside it. An operator pastes that, OpenAI rejects it, and nothing indicates the dashboard mangled the code rather than the code being wrong. The construction wall is that those bytes cannot reach the parser at all — tmux_captured_pane_rendering refuses to brand a CaptureWithEscapes capture — so this file proves both that the plain path works and that the unsafe path is closed." +// THE CONSUMER THE LANE SHIPPED WITHOUT (review, 2026-07-30). codex_device_prompt_parse, +// TmuxCaptureFidelity, the capture shaper and both fixtures landed with zero callers — production +// or witness — so a parser written against real bytes was never once run against them. That is the +// specification-without-execution trap DESIGN 5 names: it typechecked, it read plausibly, and +// nothing established that it extracts anything.\n\nThe two fixtures are a DISCRIMINATING PAIR +// rather than two samples, which is why this claim can be stated at all. Both are the same codex +// prompt captured two ways on 2026-07-30: the direct rendering wraps the URL and the one-time code +// in SGR sequences, and the tmux capture-pane rendering carries none, because tmux's renderer +// consumed them before storing the grid. They therefore carry DIFFERENT one-time codes, being +// separate login attempts, and the claim pins each to its own fixture so a witness that silently +// read the wrong file cannot pass.\n\nThe escape-carrying case is the reason the brand exists, and +// it is asserted as a real defect rather than described: parsed directly, the code comes out with +// escape bytes still inside it. An operator pastes that, OpenAI rejects it, and nothing indicates +// the dashboard mangled the code rather than the code being wrong. The construction wall is that +// those bytes cannot reach the parser at all — tmux_captured_pane_rendering refuses to brand a +// CaptureWithEscapes capture — so this file proves both that the plain path works and that the +// unsafe path is closed. data device_prompt_plain_fixture: String = "dag/test/fixture/codex_device_login/device_auth_prompt_tmux_2026-07-30.txt" data device_prompt_escaped_fixture: String = "dag/test/fixture/codex_device_login/device_auth_prompt_2026-07-30.txt" @@ -48,7 +64,12 @@ test fn tmux_captured_prompt_parses_to_a_pasteable_code() -> Bool { } } -data escape_carrying_capture_cannot_reach_the_parser_note: String = "THE WALL, stated as the thing that is unwritable rather than as a check that fires. There is no way to hand an escape-carrying capture to codex_device_prompt_parse, because the only producer of RenderedTerminalText refuses the fidelity that retains escapes — so this claim asserts the refusal arm is reached, which is the whole of the guarantee.\\n\\nIt is a distinct claim from the plain-path one because they fail differently. A regression that branded every capture regardless of fidelity would leave the plain path green and only this one red." +// THE WALL, stated as the thing that is unwritable rather than as a check that fires. There is no +// way to hand an escape-carrying capture to codex_device_prompt_parse, because the only producer of +// RenderedTerminalText refuses the fidelity that retains escapes — so this claim asserts the +// refusal arm is reached, which is the whole of the guarantee.\n\nIt is a distinct claim from the +// plain-path one because they fail differently. A regression that branded every capture regardless +// of fidelity would leave the plain path green and only this one red. test fn escape_retaining_capture_refuses_to_render() -> Bool { let read = Filesystem.Read(path: device_prompt_escaped_fixture) @@ -62,7 +83,15 @@ test fn escape_retaining_capture_refuses_to_render() -> Bool { } } -data escaped_bytes_are_a_real_defect_note: String = "THE RED CONTROL, and it is a measurement rather than a hypothetical. It reads the escape-carrying fixture and asserts that its raw text does NOT contain the bare code — because in that rendering the code is split by SGR sequences, so a parser reading the stream directly extracts something an operator cannot paste.\\n\\nWithout this conjunct the pair above proves only that one file parses and another is refused, which a witness would also show if the escapes were harmless and the brand pointless. Asserting the damage is what makes the wall load-bearing rather than ceremonial. It also pins that the two fixtures are genuinely different renderings and not a duplicated file: the plain fixture carries its code bare, the escaped one does not carry the plain fixture's code at all." +// THE RED CONTROL, and it is a measurement rather than a hypothetical. It reads the escape-carrying +// fixture and asserts that its raw text does NOT contain the bare code — because in that rendering +// the code is split by SGR sequences, so a parser reading the stream directly extracts something an +// operator cannot paste.\n\nWithout this conjunct the pair above proves only that one file parses +// and another is refused, which a witness would also show if the escapes were harmless and the +// brand pointless. Asserting the damage is what makes the wall load-bearing rather than ceremonial. +// It also pins that the two fixtures are genuinely different renderings and not a duplicated file: +// the plain fixture carries its code bare, the escaped one does not carry the plain fixture's code +// at all. test fn escape_carrying_rendering_would_yield_an_unpasteable_code() -> Bool { let escaped = Filesystem.Read(path: device_prompt_escaped_fixture) diff --git a/dag/test/claim/codex_supervised_turn_wet_witness_test.dag b/dag/test/claim/codex_supervised_turn_wet_witness_test.dag index 2d7a00352c7..3a3b3cabc99 100644 --- a/dag/test/claim/codex_supervised_turn_wet_witness_test.dag +++ b/dag/test/claim/codex_supervised_turn_wet_witness_test.dag @@ -70,13 +70,31 @@ data live_tree_disposition: LiveTreeDisposition = ReadsLiveTree data witness_note: String = "WET BISECT REPRODUCTION (NOT ENROLLED WITNESSES). Bisect entrypoints are plain fn, not test fn — they cannot execute anywhere today (materialize leak on main) so enrolled-and-unrunnable would be false coverage (Phase 0(b) admission). Operator runs via gunbc run --function under MemoryMax caps on srv1 only. Hermetic coverage lives in codex_supervised_turn_witness_test.dag. Re-enroll through gunbc.explicit_witness_admission after materialize_codex_runtime_bundle is fixed." -data wet_non_witness_enrollment_note: String = "Admission gate 2026-08-14: OfflineLocalRecipe exclusion + enrolled test fn produced UnclassifiedPathDeferral (five rows, zero executing consumers). Fix: bisect arms are fn not test fn; no witness enrollment until explicit admission with declared envelope after production fix." - -data wet_supervised_turn_memory_envelope_note: String = "MEMORY ENVELOPE (srv1 bisect 2026-08-14). LOCATED: finish_after_install PINS 8G; pair-acquire and npm-ci-offline PASS 2G. Finish observe rungs (install + one observe each, order matches finish): wet_finish_observe_set_identity_only — 2G; wet_finish_observe_manifest_digest_only — 2G; wet_finish_observe_lock_digest_only — 2G; wet_finish_observe_native_digest_only — 2G; wet_finish_observe_toolchain_only — 2G; wet_finish_observe_protocol_schema_only — 2G; wet_finish_observe_package_tree_only — 2G/8G; wet_finish_observe_receipt_identity_only — 8G; wet_finish_observe_package_tree_tiny_fixture — 2G (two-file tree, no install). INTERPRETER BISECT: wet_finish_parse_canonicalize_largest_protocol_schema_only — install + generate-json-schema + parse_json/canonicalize_json_value on codex_app_server_protocol.schemas.json only (507 KB); no fold/manifest/sha512. Control: wet_materialize_finish_after_install_only — 8G; wet_materialize_codex_runtime_bundle_only — 8G." - -data wet_bisect_ladder_receipt_note: String = "srv1 ladder (eager-koi-458): construct/closure/prepare/wrapper-acquire/platform-acquire/through-prepare PASS; full materialize PINS 8G. Next: pair acquire together, npm ci offline install path, finish after install (tree walk / release)." - -data wet_supervised_turn_oom_receipt_note: String = "srv1 bisect 2026-08-14: step2b closure PASS 2G; instrumented materialize ~2GB/min to 8G cap, zero children 4.5min, decl eval stuck — not tarball bytes. Production defect in interpreter eval of materialize_codex_runtime_bundle pre-shell region. Fix production path; do not enlarge witness envelope." +// Admission gate 2026-08-14: OfflineLocalRecipe exclusion + enrolled test fn produced +// UnclassifiedPathDeferral (five rows, zero executing consumers). Fix: bisect arms are fn not test +// fn; no witness enrollment until explicit admission with declared envelope after production fix. + +// MEMORY ENVELOPE (srv1 bisect 2026-08-14). LOCATED: finish_after_install PINS 8G; pair-acquire and +// npm-ci-offline PASS 2G. Finish observe rungs (install + one observe each, order matches finish): +// wet_finish_observe_set_identity_only — 2G; wet_finish_observe_manifest_digest_only — 2G; +// wet_finish_observe_lock_digest_only — 2G; wet_finish_observe_native_digest_only — 2G; +// wet_finish_observe_toolchain_only — 2G; wet_finish_observe_protocol_schema_only — 2G; +// wet_finish_observe_package_tree_only — 2G/8G; wet_finish_observe_receipt_identity_only — 8G; +// wet_finish_observe_package_tree_tiny_fixture — 2G (two-file tree, no install). INTERPRETER +// BISECT: wet_finish_parse_canonicalize_largest_protocol_schema_only — install + +// generate-json-schema + parse_json/canonicalize_json_value on +// codex_app_server_protocol.schemas.json only (507 KB); no fold/manifest/sha512. Control: +// wet_materialize_finish_after_install_only — 8G; wet_materialize_codex_runtime_bundle_only — 8G. + +// srv1 ladder (eager-koi-458): +// construct/closure/prepare/wrapper-acquire/platform-acquire/through-prepare PASS; full materialize +// PINS 8G. Next: pair acquire together, npm ci offline install path, finish after install (tree +// walk / release). + +// srv1 bisect 2026-08-14: step2b closure PASS 2G; instrumented materialize ~2GB/min to 8G cap, zero +// children 4.5min, decl eval stuck — not tarball bytes. Production defect in interpreter eval of +// materialize_codex_runtime_bundle pre-shell region. Fix production path; do not enlarge witness +// envelope. data wet_supervised_turn_probe_key: ProviderProbeKey = "wet-supervised-turn-1" as ProviderProbeKey diff --git a/dag/test/claim/commit_witness_claim_roster_witness_test.dag b/dag/test/claim/commit_witness_claim_roster_witness_test.dag index 9bbbd5046a6..ed76ec451d4 100644 --- a/dag/test/claim/commit_witness_claim_roster_witness_test.dag +++ b/dag/test/claim/commit_witness_claim_roster_witness_test.dag @@ -9,7 +9,12 @@ data live_tree_disposition: LiveTreeDisposition = ReadsLiveTree data synthetic_stale_entry: String = "dag/test/claim/synthetic_missing_roster_witness_test.dag" data synthetic_stale_fn: String = "this_witness_function_does_not_exist" -data commit_witness_claim_roster_fast_lane_note: String = "PR-time roster detector fast lane (operator brief 2026-07-22, class 3): synthetic stale (entry, check_fn) RED proves the resolvability machinery fires — typed COMMIT_WITNESS_CLAIM_ROSTER_REFUSAL on live defects. Full-corpus roster resolvability receipt moved to dag/test/claim/long/commit_witness_claim_roster_witness_test.dag (~210s eval; exceeds 5s fast-lane budget). Detection-only: never auto-delete enrollments. Dissolve-on: enrollment derived from discovery (module-identity Phase-0 admission invariant)." +// PR-time roster detector fast lane (operator brief 2026-07-22, class 3): synthetic stale (entry, +// check_fn) RED proves the resolvability machinery fires — typed +// COMMIT_WITNESS_CLAIM_ROSTER_REFUSAL on live defects. Full-corpus roster resolvability receipt +// moved to dag/test/claim/long/commit_witness_claim_roster_witness_test.dag (~210s eval; exceeds 5s +// fast-lane budget). Detection-only: never auto-delete enrollments. Dissolve-on: enrollment derived +// from discovery (module-identity Phase-0 admission invariant). fn witness_commit_witness_claim_roster_red_holds() -> Bool { !commit_witness_claim_pair_resolvable( diff --git a/dag/test/claim/commit_writer_admission_witness_test.dag b/dag/test/claim/commit_writer_admission_witness_test.dag index c3d840b1e91..b260feace71 100644 --- a/dag/test/claim/commit_writer_admission_witness_test.dag +++ b/dag/test/claim/commit_writer_admission_witness_test.dag @@ -65,7 +65,15 @@ import v2.compiler.source_authority { import v2.std.cross_tree.import_model { DagTree } import v2.std.provenance { span_index_empty } -data commit_writer_admission_witness_note: String = "Executable reproduction for commit 218dea61248d plus complete-population controls. The unmerged index carries Base/Ours/Theirs. The independent stage-0 observation carries the exact three committed marker blocks and refuses at their line locations. Every normal index entry must have exactly one observed blob, no extra or duplicate blob may appear, the index/object/content identities must agree, and decode/classification must be available. Artifact classification is projected from ModuleStorageIndex and bound to the same GitPath and indexed object; a naked or mismatched TestClaimArtifact cannot exempt source text. Isolated and out-of-order marker tokens admit, while the effective per-path conflict-marker-size fact drives the real begin/separator/end grammar." +// Executable reproduction for commit 218dea61248d plus complete-population controls. The unmerged +// index carries Base/Ours/Theirs. The independent stage-0 observation carries the exact three +// committed marker blocks and refuses at their line locations. Every normal index entry must have +// exactly one observed blob, no extra or duplicate blob may appear, the index/object/content +// identities must agree, and decode/classification must be available. Artifact classification is +// projected from ModuleStorageIndex and bound to the same GitPath and indexed object; a naked or +// mismatched TestClaimArtifact cannot exempt source text. Isolated and out-of-order marker tokens +// admit, while the effective per-path conflict-marker-size fact drives the real begin/separator/end +// grammar. fn publication_grant_path() -> GitPath { match git_decode_path_octets(octets: [ diff --git a/dag/test/claim/commit_writer_index_selection_witness_test.dag b/dag/test/claim/commit_writer_index_selection_witness_test.dag index 8dfe12e9547..7ac63911989 100644 --- a/dag/test/claim/commit_writer_index_selection_witness_test.dag +++ b/dag/test/claim/commit_writer_index_selection_witness_test.dag @@ -27,7 +27,25 @@ import gunbc.commit_workflow { commit_writer_index_entries_for_path } data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data commit_writer_index_selection_note: String = "BEHAVIOURAL CONTROL for gunbc.commit_workflow commit_writer_index_entries_for_path, owed by the operator verdict on gunbc#7480 (2026-08-02). That function selects index entries by path, and its body is a DECLARED SCAFFOLD: it spells the selection with flat_map because the bare name filter is captured in that module by v2.std.algebra's filter over FreeMonoid, which enters the resolution population through the semantically-required v2.compiler.source_authority import and cannot reconcile with List. The scaffold's own note in commit_workflow carries the root cause and the dissolve-on. THIS file is the other half: the whole-tree compile is the discriminating red for the CAPTURE, while these rows prove the interim spelling did not change commit-writer SEMANTICS. They must therefore keep executing after the resolver fix restores the filter spelling -- a control that proves the two spellings agree is exactly what makes that restoration safe, so it does not retire with the scaffold. The closure is deliberately live rather than synthetic: importing gunbc.commit_workflow pulls v2.compiler.source_authority, and therefore v2.std.algebra, into this test's population too, so these rows execute under the same capture conditions as production rather than in a closure where the defect could not arise. Coverage is the verdict's list: two or more entries, matching AND nonmatching paths, and preservation of both the ORDER and the STAGE of matching entries -- order and stage are asserted rather than counted because a selection that returned the right NUMBER of entries while reordering them, dropping a duplicate-path stage, or rewriting a stage would still be wrong, and a count alone cannot see any of that." +// BEHAVIOURAL CONTROL for gunbc.commit_workflow commit_writer_index_entries_for_path, owed by the +// operator verdict on gunbc#7480 (2026-08-02). That function selects index entries by path, and its +// body is a DECLARED SCAFFOLD: it spells the selection with flat_map because the bare name filter +// is captured in that module by v2.std.algebra's filter over FreeMonoid, which enters the +// resolution population through the semantically-required v2.compiler.source_authority import and +// cannot reconcile with List. The scaffold's own note in commit_workflow carries the +// root cause and the dissolve-on. THIS file is the other half: the whole-tree compile is the +// discriminating red for the CAPTURE, while these rows prove the interim spelling did not change +// commit-writer SEMANTICS. They must therefore keep executing after the resolver fix restores the +// filter spelling -- a control that proves the two spellings agree is exactly what makes that +// restoration safe, so it does not retire with the scaffold. The closure is deliberately live +// rather than synthetic: importing gunbc.commit_workflow pulls v2.compiler.source_authority, and +// therefore v2.std.algebra, into this test's population too, so these rows execute under the same +// capture conditions as production rather than in a closure where the defect could not arise. +// Coverage is the verdict's list: two or more entries, matching AND nonmatching paths, and +// preservation of both the ORDER and the STAGE of matching entries -- order and stage are asserted +// rather than counted because a selection that returned the right NUMBER of entries while +// reordering them, dropping a duplicate-path stage, or rewriting a stage would still be wrong, and +// a count alone cannot see any of that. fn oid_of(hex: String) -> GitObjectId { GitSha1ObjectId { digest: Sha1Digest { hex: hex as Sha1DigestHex } } diff --git a/dag/test/claim/compile_accepted_unevaluable_program_control_test.dag b/dag/test/claim/compile_accepted_unevaluable_program_control_test.dag index 7979cbc9321..33a75846195 100644 --- a/dag/test/claim/compile_accepted_unevaluable_program_control_test.dag +++ b/dag/test/claim/compile_accepted_unevaluable_program_control_test.dag @@ -30,11 +30,23 @@ import v2.std.live_tree { LiveTreeDisposition, ReadsLiveTree } // fixture written on either surface would therefore be permanently green while the production path // stays open, and would be cited as coverage of the class it never touches. Its next-rung trigger // is a compile-observation surface that resolves names by the witness loader's rule. -data compile_accepted_unevaluable_program_note: String = "The subject is the v1 compile path reached through compile_dag_rust_emit_check, which returns false on any hard diagnostic. Each RED below asserts REFUSAL of a program the host will refuse at evaluation anyway, so the assertion is that the refusal moves from evaluation to compile — not that the program changes meaning. All three RED rows return false today and are enrolled in v2.workflow.floor_expected_red; when the argument contract for host primitives is checked at compile they PASS, the enrolled-but-passing arm reds the build naming them, and they stay here afterwards as the regression control that the wall is still real (DESIGN 4b(4): the climb deletes the redundant production handling, never the evidence)." +// The subject is the v1 compile path reached through compile_dag_rust_emit_check, which returns +// false on any hard diagnostic. Each RED below asserts REFUSAL of a program the host will refuse at +// evaluation anyway, so the assertion is that the refusal moves from evaluation to compile — not +// that the program changes meaning. All three RED rows return false today and are enrolled in +// v2.workflow.floor_expected_red; when the argument contract for host primitives is checked at +// compile they PASS, the enrolled-but-passing arm reds the build naming them, and they stay here +// afterwards as the regression control that the wall is still real (DESIGN 4b(4): the climb deletes +// the redundant production handling, never the evidence). data live_tree_disposition: LiveTreeDisposition = ReadsLiveTree -data live_tree_note: String = "ReadsLiveTree, for the same reason the two sibling files on this surface declare it: compile_dag_rust_emit_check resolves its virtual source against build_module_path_index_from_witness_roots, which walks the live tree. The declaration is honest rather than convenient — it costs floor admission under the DeclinedLiveTree arm rather than buying it, and that arm's deletion (gunbc#8977, gunbc#8982) is what admits this file to execution." +// ReadsLiveTree, for the same reason the two sibling files on this surface declare it: +// compile_dag_rust_emit_check resolves its virtual source against +// build_module_path_index_from_witness_roots, which walks the live tree. The declaration is honest +// rather than convenient — it costs floor admission under the DeclinedLiveTree arm rather than +// buying it, and that arm's deletion (gunbc#8977, gunbc#8982) is what admits this file to +// execution. // Positive control 1 of 2. A trivial well-formed source compiles: the surface is not always-false, // so a false below is a refusal rather than a harness that cannot say yes. diff --git a/dag/test/claim/compile_clean_shard_entry_paths_fast_hand_rust_witness_test.dag b/dag/test/claim/compile_clean_shard_entry_paths_fast_hand_rust_witness_test.dag index 2812a4f59be..862de768106 100644 --- a/dag/test/claim/compile_clean_shard_entry_paths_fast_hand_rust_witness_test.dag +++ b/dag/test/claim/compile_clean_shard_entry_paths_fast_hand_rust_witness_test.dag @@ -16,9 +16,33 @@ import std.disposition { Scaffold, SingleAuthority } import std.types { Bool } import v2.std.algebra { length } -data compile_clean_shard_entry_paths_fast_hand_rust_witness_note: String = "HAND-RUST receipt for src/v1/stage0/src/cli_run.rs compile_clean_shard_entry_paths_from_decl_facts / compile_clean_shard_entry_paths_fast (review 47271): host floor-CI mirror of tools.dag_compile_clean_shard_roster.compile_clean_shard_entry_paths_from via std.keyed_roster.keyed_roster_build — not a parallel authority. Rust duplicate-refusal semantics must stay aligned with witness_roster_build_refuses_synthetic_duplicate_facts (dag/test/claim/dag_compile_clean_shard_totality_witness_test.dag, via tools.dag_compile_clean_shard_roster) on the same fixture." +// HAND-RUST receipt for src/v1/stage0/src/cli_run.rs +// compile_clean_shard_entry_paths_from_decl_facts / compile_clean_shard_entry_paths_fast (review +// 47271): host floor-CI mirror of +// tools.dag_compile_clean_shard_roster.compile_clean_shard_entry_paths_from via +// std.keyed_roster.keyed_roster_build — not a parallel authority. Rust duplicate-refusal semantics +// must stay aligned with witness_roster_build_refuses_synthetic_duplicate_facts +// (dag/test/claim/dag_compile_clean_shard_totality_witness_test.dag, via +// tools.dag_compile_clean_shard_roster) on the same fixture. -data compile_clean_shard_entry_paths_fast_hand_rust_duplicate_semantics_dedup_note: String = "Witness cost class: aggregate-only/duplicate coverage (session calm-ram-80, 2026-08-19). This file used to carry test fn compile_clean_shard_entry_paths_fast_hand_rust_fixture_duplicate_semantics_align() -> Bool { witness_roster_build_refuses_synthetic_duplicate_facts() } — a bare re-invocation of a witness already discovered and executed as part of test fn compile_clean_shard_roster_is_well_formed() in dag/test/claim/dag_compile_clean_shard_totality_witness_test.dag. The deleted wrapper asserted nothing of its own: it neither exercised the hand-Rust seam this file exists to receipt nor added a distinct fixture, so every CI run paid witness_roster_build_refuses_synthetic_duplicate_facts's fixture-construction and assertion cost twice for one observation. The claim this row named — that this file's hand-Rust duplicate-refusal semantics stay aligned with the .dag fixture — is grouped here by cross-reference (this note, and the sibling reference on compile_clean_shard_entry_paths_fast_hand_rust_witness_note) rather than by re-executing the shared witness: the alignment obligation is discharged by the single execution already enrolled at compile_clean_shard_roster_is_well_formed, and this file's roster is one witness shorter for it. DISSOLVE-ON: if this file's hand-Rust seam grows an observation witness_roster_build_refuses_synthetic_duplicate_facts cannot make (e.g. a Rust-side fixture the .dag roster construction never exercises), that observation gets its own witness here rather than reviving this wrapper." +// Witness cost class: aggregate-only/duplicate coverage (session calm-ram-80, 2026-08-19). This +// file used to carry test fn +// compile_clean_shard_entry_paths_fast_hand_rust_fixture_duplicate_semantics_align() -> Bool { +// witness_roster_build_refuses_synthetic_duplicate_facts() } — a bare re-invocation of a witness +// already discovered and executed as part of test fn compile_clean_shard_roster_is_well_formed() in +// dag/test/claim/dag_compile_clean_shard_totality_witness_test.dag. The deleted wrapper asserted +// nothing of its own: it neither exercised the hand-Rust seam this file exists to receipt nor added +// a distinct fixture, so every CI run paid witness_roster_build_refuses_synthetic_duplicate_facts's +// fixture-construction and assertion cost twice for one observation. The claim this row named — +// that this file's hand-Rust duplicate-refusal semantics stay aligned with the .dag fixture — is +// grouped here by cross-reference (this note, and the sibling reference on +// compile_clean_shard_entry_paths_fast_hand_rust_witness_note) rather than by re-executing the +// shared witness: the alignment obligation is discharged by the single execution already enrolled +// at compile_clean_shard_roster_is_well_formed, and this file's roster is one witness shorter for +// it. DISSOLVE-ON: if this file's hand-Rust seam grows an observation +// witness_roster_build_refuses_synthetic_duplicate_facts cannot make (e.g. a Rust-side fixture the +// .dag roster construction never exercises), that observation gets its own witness here rather than +// reviving this wrapper. test fn compile_clean_shard_entry_paths_fast_hand_rust_scaffold_is_seed_retained() -> Bool { match compile_clean_shard_entry_paths_fast_hand_rust_scaffold { diff --git a/dag/test/claim/compile_diagnostic_census_witness_test.dag b/dag/test/claim/compile_diagnostic_census_witness_test.dag index 4f4334785dc..fd22d0942d8 100644 --- a/dag/test/claim/compile_diagnostic_census_witness_test.dag +++ b/dag/test/claim/compile_diagnostic_census_witness_test.dag @@ -20,7 +20,41 @@ data live_tree_disposition: LiveTreeDisposition = ReadsLiveTree data census_live_tree_note: String = "ReadsLiveTree, and the divergence from the sibling is deliberate. compile_dag_diagnostic_census resolves the synthetic source against build_module_path_index_from_witness_roots, which walks the live tree - so the read is real. RESOLVED 2026-08-19 (FIRSTTOUCH-1, dashboard adhoc-c5b4375f-4cb): dag/test/claim/transport_script_wall_compile_red_test.dag previously declared SubstrateInputsOnly while calling compile_dag_rust_emit_check, which takes the SAME build_module_path_index_from_witness_roots host path as this file; that was flagged here as 'either a latent mis-declaration or a judgment call' pending the falsifier cadence, which is since deleted (2026-08-15 floor cut, DESIGN.md CI section) and never adjudicated it. Tracing the call confirmed it reads the live tree, so it was the mis-declaration, not a judgment call; that file now declares ReadsLiveTree. This file does not copy claims it cannot verify: undeclared is ReadsLiveTree by the fail-closed default and the honest declaration costs only selection-eligibility." -data census_scope_note: String = "WHAT THESE WITNESSES PROVE, and what they do not. They prove the observation SURFACE reports the three facts a Bool discards - which class fired, whether it blocks, and how many times - on the v1-pipeline / Rust-target / synthetic-single-module path, and that a clean source is distinguishable from a refusing one so the harness is not always-refusing. They prove NOTHING about the walls themselves: a wall's own regression control is its migrated probe pair, not this file. BOTH SEVERITY DIRECTIONS HAVE LIVE SPECIMENS, and the way the advisory one was found is worth recording because the first answer was wrong. An earlier pass concluded no advisory specimen could be conjured synthetically: a where-refinement alias, an unlisted-import shape, and an unresolved method on a bare type parameter each either compiled silent or refused BLOCKING. That conclusion was an artifact of the PROBE, not the compiler - and the first diagnosis of why was ALSO wrong, which is the part worth carrying. The initial account blamed the closure: those probes ran through a fixture-only CLI compile with no std in its single source root, so the refinement supposedly never resolved to a refinement. A discriminating control refuted that. Under the full dag + src/v2 pool the where-refinement ALIAS shape (type Tight = String where non_empty) is STILL silent - zero diagnostics with std fully available - while the shape asserted below, a cast to std's refined brand, fires WhereRefinementUnenforced as a counted advisory on the same harness. So the closure was not the discriminator; the probe SHAPE was. A 2x2 pins the real axis, and it is not what either explanation guessed: crossing declaration site (local alias vs std brand - structurally identical declarations, same predicate) against cast subject (literal vs unknown parameter), local+parameter FIRES, local+literal silent, std+parameter FIRES, std+literal silent. Declaration site is irrelevant; the diagnostic names the axis itself - non-literal value at refined position. The original probe cast the literal x, and a literal at a refined position is deliberately EXEMPT, so its silence is CORRECT BEHAVIOUR and it is a dead probe rather than a finding: it looked like it exercised the judgment (it casts, at a fn boundary) while the judgment exempts its exact form. The intermediate guess that its predicate resolves nowhere is also retired - the predicate resolves fine, as local+parameter firing proves. The corpus reading that prompted the recheck: a whole-tree compile carries 1981 where-refinement advisories, so the class was demonstrably reachable and a probe finding none was evidence against the probe. CONSEQUENCE: AcceptedCounted has a producer - the surface does not merely REPRESENT a counted-advisory observation, a probe PRODUCES one. They also do not prove the host EMITS CensusNotRunnable on a real infrastructural failure - the last witness asserts only that the coproduct keeps the two arms distinct, which is the property that lets a caller map could-not-measure to ProbeNotRunnable without guessing; provoking a genuine host panic on demand is not something a synthetic source can do, and asserting it as though it were measured would be the fabrication this corpus exists to count." +// WHAT THESE WITNESSES PROVE, and what they do not. They prove the observation SURFACE reports the +// three facts a Bool discards - which class fired, whether it blocks, and how many times - on the +// v1-pipeline / Rust-target / synthetic-single-module path, and that a clean source is +// distinguishable from a refusing one so the harness is not always-refusing. They prove NOTHING +// about the walls themselves: a wall's own regression control is its migrated probe pair, not this +// file. BOTH SEVERITY DIRECTIONS HAVE LIVE SPECIMENS, and the way the advisory one was found is +// worth recording because the first answer was wrong. An earlier pass concluded no advisory +// specimen could be conjured synthetically: a where-refinement alias, an unlisted-import shape, and +// an unresolved method on a bare type parameter each either compiled silent or refused BLOCKING. +// That conclusion was an artifact of the PROBE, not the compiler - and the first diagnosis of why +// was ALSO wrong, which is the part worth carrying. The initial account blamed the closure: those +// probes ran through a fixture-only CLI compile with no std in its single source root, so the +// refinement supposedly never resolved to a refinement. A discriminating control refuted that. +// Under the full dag + src/v2 pool the where-refinement ALIAS shape (type Tight = String where +// non_empty) is STILL silent - zero diagnostics with std fully available - while the shape asserted +// below, a cast to std's refined brand, fires WhereRefinementUnenforced as a counted advisory on +// the same harness. So the closure was not the discriminator; the probe SHAPE was. A 2x2 pins the +// real axis, and it is not what either explanation guessed: crossing declaration site (local alias +// vs std brand - structurally identical declarations, same predicate) against cast subject (literal +// vs unknown parameter), local+parameter FIRES, local+literal silent, std+parameter FIRES, +// std+literal silent. Declaration site is irrelevant; the diagnostic names the axis itself - +// non-literal value at refined position. The original probe cast the literal x, and a literal at a +// refined position is deliberately EXEMPT, so its silence is CORRECT BEHAVIOUR and it is a dead +// probe rather than a finding: it looked like it exercised the judgment (it casts, at a fn +// boundary) while the judgment exempts its exact form. The intermediate guess that its predicate +// resolves nowhere is also retired - the predicate resolves fine, as local+parameter firing proves. +// The corpus reading that prompted the recheck: a whole-tree compile carries 1981 where-refinement +// advisories, so the class was demonstrably reachable and a probe finding none was evidence against +// the probe. CONSEQUENCE: AcceptedCounted has a producer - the surface does not merely REPRESENT a +// counted-advisory observation, a probe PRODUCES one. They also do not prove the host EMITS +// CensusNotRunnable on a real infrastructural failure - the last witness asserts only that the +// coproduct keeps the two arms distinct, which is the property that lets a caller map +// could-not-measure to ProbeNotRunnable without guessing; provoking a genuine host panic on demand +// is not something a synthetic source can do, and asserting it as though it were measured would be +// the fabrication this corpus exists to count. fn census_of(source: String) -> CompileDiagnosticCensus { compile_dag_diagnostic_census(source) @@ -92,7 +126,17 @@ test fn census_not_runnable_is_not_an_empty_observation() -> Bool { not_runnable != empty_observed && cause_readable && observed_is_empty } -data scaffold_trigger_citation_note: String = "THE SCAFFOLD'S TRIGGER IS ITSELF CHECKED, because a dissolution trigger that nobody executes rots exactly like any other prose claim (DESIGN 3: a cited name is decidable, so decide it). This asserts the hand-Rust dissolve-trigger row names the concrete roadmap row it defers to, so an edit that reopens the trigger into an unevaluable disjunction reds here rather than passing review twice. The precedent is stage0_rust_source_lifecycle_scaffold_witness_test scaffold_note_cites_zero_hand_maintained_rust_roadmap_row, which is where the convention comes from. ONE DELIBERATE DIVERGENCE from that precedent: it also asserts the note contains the literal ROADMAP.md:24, and this file does NOT copy that half. A line offset into a generated artifact is the positional citation DESIGN 3 rules out - it decays silently when anything above line 24 changes, and nothing about the roadmap row moving would red it. The row id is the symbol the namespace already names, so the id alone is asserted here." +// THE SCAFFOLD'S TRIGGER IS ITSELF CHECKED, because a dissolution trigger that nobody executes rots +// exactly like any other prose claim (DESIGN 3: a cited name is decidable, so decide it). This +// asserts the hand-Rust dissolve-trigger row names the concrete roadmap row it defers to, so an +// edit that reopens the trigger into an unevaluable disjunction reds here rather than passing +// review twice. The precedent is stage0_rust_source_lifecycle_scaffold_witness_test +// scaffold_note_cites_zero_hand_maintained_rust_roadmap_row, which is where the convention comes +// from. ONE DELIBERATE DIVERGENCE from that precedent: it also asserts the note contains the +// literal ROADMAP.md:24, and this file does NOT copy that half. A line offset into a generated +// artifact is the positional citation DESIGN 3 rules out - it decays silently when anything above +// line 24 changes, and nothing about the roadmap row moving would red it. The row id is the symbol +// the namespace already names, so the id alone is asserted here. test fn scaffold_trigger_cites_the_concrete_roadmap_row() -> Bool { string_contains(s: dissolution_description(condition: compile_diagnostic_census_hand_rust_dissolve_trigger), pattern: "v1-zero-hand-maintained-rust") diff --git a/dag/test/claim/component_dispatch_button_witness_test.dag b/dag/test/claim/component_dispatch_button_witness_test.dag index 44431a3a171..f367d770d8a 100644 --- a/dag/test/claim/component_dispatch_button_witness_test.dag +++ b/dag/test/claim/component_dispatch_button_witness_test.dag @@ -18,7 +18,12 @@ import v2.std.live_tree { LiveTreeDisposition, SubstrateInputsOnly } data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data component_dispatch_button_witness_note: String = "P0 keystone: the component concept, executable. The dispatch button's terminal states are DERIVED from the belt wire vocabulary and cross-checked total both directions; the RED control resurrects the exact drift the dispatch-button incident was — a wire label with no state row — and proves the totality check LOCATES it (returns the missing label), not vacuously passes. The role split (ok -> figure, refusal -> boundary) is proven derived from the ok-label authority, so a label moving across the ok line moves its chip material by derivation." +// P0 keystone: the component concept, executable. The dispatch button's terminal states are DERIVED +// from the belt wire vocabulary and cross-checked total both directions; the RED control resurrects +// the exact drift the dispatch-button incident was — a wire label with no state row — and proves +// the totality check LOCATES it (returns the missing label), not vacuously passes. The role split +// (ok -> figure, refusal -> boundary) is proven derived from the ok-label authority, so a label +// moving across the ok line moves its chip material by derivation. test fn witness_scale_well_formed() -> Bool { scale_well_formed() @@ -48,7 +53,19 @@ test fn witness_no_fabricated_state() -> Bool { states_missing_label(c: dispatch_button_component(), wire_labels: belt_dispatch_all_status_labels()).length() == 0 } -data dwell_witness_scope_note: String = "THIS ASSERTION WAS LOOSENED AND THE REASON MATTERS, because loosening a witness to green your own change is the exact move a pinned oracle exists to prevent. It compared the WHOLE preamble to one line — `emitted == 'const gunbcDwellMs = 300;'` — so it failed the moment the preamble gained a second statement, which happened when the reason-surface helpers were added (2026-07-30). Nothing about the dwell had changed.\\n\\nThe over-specification was never the claim. The name says what is being tested: a Milliseconds-branded duration must reach the emitted program as a BARE INTEGER, not as `300ms`, not as a record, not as a quoted string — that is the property with a real failure mode, and whole-preamble equality only tested it incidentally while also asserting an unrelated fact nobody stated (that the preamble holds exactly one statement).\\n\\nSo the replacement is deliberately STRONGER on the property and silent on the incidental one: the dwell's exact statement must be present, and the three ways a brand leaks into emitted text are each refused by name. A version that rendered the brand would have passed the old equality only by accident of being the sole statement; it cannot pass this." +// THIS ASSERTION WAS LOOSENED AND THE REASON MATTERS, because loosening a witness to green your own +// change is the exact move a pinned oracle exists to prevent. It compared the WHOLE preamble to one +// line — `emitted == 'const gunbcDwellMs = 300;'` — so it failed the moment the preamble gained a +// second statement, which happened when the reason-surface helpers were added (2026-07-30). Nothing +// about the dwell had changed.\n\nThe over-specification was never the claim. The name says what is +// being tested: a Milliseconds-branded duration must reach the emitted program as a BARE INTEGER, +// not as `300ms`, not as a record, not as a quoted string — that is the property with a real +// failure mode, and whole-preamble equality only tested it incidentally while also asserting an +// unrelated fact nobody stated (that the preamble holds exactly one statement).\n\nSo the +// replacement is deliberately STRONGER on the property and silent on the incidental one: the +// dwell's exact statement must be present, and the three ways a brand leaks into emitted text are +// each refused by name. A version that rendered the brand would have passed the old equality only +// by accident of being the sole statement; it cannot pass this. test fn witness_dwell_emits_as_a_branded_duration() -> Bool { let emitted = serialize_ts_stmts_indented(stmts: dispatch_preamble_statements(), indent: "") diff --git a/dag/test/claim/computation_demand_duplication_witness_test.dag b/dag/test/claim/computation_demand_duplication_witness_test.dag index 393365afac0..298bd614262 100644 --- a/dag/test/claim/computation_demand_duplication_witness_test.dag +++ b/dag/test/claim/computation_demand_duplication_witness_test.dag @@ -37,10 +37,19 @@ test fn replicated_oracle_pair_is_declared_and_admissible() -> Bool { ) } +// The live subject is the typed-argv projection: both facts are projected from +// synthetic_replicated_invocation (same tool+args except the --output-dir placement flag), and the +// two distinct --output-dir values prove the placement-flag stripping keeps the pair's +// computation_key equal — a declared ReplicatedOracle (runs 2) pair is admissible, SingleRun reds. +// Formerly keyed on tools.emit_determinism_transport.ed_typed_compile_invocation (the x2 +// full-corpus emit oracle); re-homed to a self-contained synthetic fixture when the x2 +// emit-determinism gate and transport were deleted (Phase D, 2026-07-14 — determinism became a +// construction gate, v2.lens.determinism enrolled in always_required_root_lenses). The lens's +// ShellProgram walker keeps its synthetic lens-unit subjects in v2.test.duplicate_computation and +// the not-yet-migrated bash-program transports as its domain; it dissolves with the sidecar. + test fn replicated_pair_without_declaration_reds() -> Bool { return v2.lens.duplicate_computation.duplicate_computation_violation_count( facts: replicated_pair_demand_facts(replication: v2.lens.duplicate_computation.SingleRun) ) == 1 } - -data typed_projection_subject_note: String = "The live subject is the typed-argv projection: both facts are projected from synthetic_replicated_invocation (same tool+args except the --output-dir placement flag), and the two distinct --output-dir values prove the placement-flag stripping keeps the pair's computation_key equal — a declared ReplicatedOracle (runs 2) pair is admissible, SingleRun reds. Formerly keyed on tools.emit_determinism_transport.ed_typed_compile_invocation (the x2 full-corpus emit oracle); re-homed to a self-contained synthetic fixture when the x2 emit-determinism gate and transport were deleted (Phase D, 2026-07-14 — determinism became a construction gate, v2.lens.determinism enrolled in always_required_root_lenses). The lens's ShellProgram walker keeps its synthetic lens-unit subjects in v2.test.duplicate_computation and the not-yet-migrated bash-program transports as its domain; it dissolves with the sidecar." diff --git a/dag/test/claim/compute_board_emission_entry_witness_test.dag b/dag/test/claim/compute_board_emission_entry_witness_test.dag index 87faaebe3a5..eb8802bca54 100644 --- a/dag/test/claim/compute_board_emission_entry_witness_test.dag +++ b/dag/test/claim/compute_board_emission_entry_witness_test.dag @@ -53,7 +53,7 @@ data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly // to answer a refused article with the literal string "REFUSED: article not admitted", which a // caller receives as an ordinary result — the fabricated plausible output DESIGN section 5 // forbids, at the seam furthest from the model. The arms are typed now, and this witness executes -// all three of them, because an arm nothing calls is a claim rather than a behaviour. +// all three, because an arm nothing calls is a claim rather than a behaviour. fn is_emitted(e: BoardEmission) -> Bool { match e { @@ -124,18 +124,17 @@ test fn w_the_admission_causes_cross_the_boundary_intact() -> Bool { } // A COHERENT BOARD THIS TARGET CANNOT RENDER reaches the target arm. The floating terminal is -// admitted — netting is a SPICE requirement rather than a fact about the board — so this is the -// fixture that separates the two refusal arms by execution rather than by argument. +// admitted — netting is a SPICE requirement, not a fact about the board — so this fixture separates +// the two refusal arms by execution rather than by argument. // // THE NETS ARE DERIVED FROM THE PRODUCTION INTENT RATHER THAN RE-AUTHORED, and that is the whole // construction. An earlier revision hand-wrote them, naming a component "pg_cond"; the divider -// rebuild then moved that name from the COMPONENT population to the NET population, so the -// fixture went on naming something real while naming the wrong kind of thing. Its nets referenced -// a component that did not exist, the article stopped being admitted, and the two tests below -// stopped measuring the target arm at all — they failed against the admission arm instead, which -// is the fixture measuring nothing dressed as the fixture disagreeing. Derived, the only way to -// break it is to delete the terminal it drops, and that fails loudly: nothing floats, SPICE -// renders, and the test reports BoardEmitted where it demanded a refusal. +// rebuild moved that name from the COMPONENT population to the NET population, so the fixture +// named something real of the wrong kind: its nets referenced a nonexistent component, the article +// stopped being admitted, and the two tests below failed against the admission arm instead of +// measuring the target arm — the fixture measuring nothing, dressed as disagreeing. Derived, the +// only way to break it is to delete the terminal it drops, and that fails loudly: nothing floats, +// SPICE renders, and the test reports BoardEmitted where it demanded a refusal. fn without_filter_high_terminal(nets: List) -> List { fold(nets, init: [], f: fn(acc, net) { concat(acc, [ElectricalNet { @@ -175,11 +174,10 @@ data floating_article: BoardPowerInterfaceArticle = BoardPowerInterfaceArticle { manufacturing: power_interlock_article.manufacturing, } -// THE FIXTURE'S OWN PREMISE, EXECUTED. The two tests below are only about the target arm if the -// fixture actually floats a terminal; if it drops nothing they still pass or fail for reasons -// that have nothing to do with what they claim to measure. This asserts the drop happened, at -// identity grain rather than by trusting the name: exactly one terminal member fewer than the -// production intent, every component retained. +// THE FIXTURE'S OWN PREMISE, EXECUTED. The two tests below are about the target arm only if the +// fixture actually floats a terminal; if it drops nothing they pass or fail for unrelated reasons. +// This asserts the drop at identity grain rather than by trusting the name: exactly one terminal +// member fewer than the production intent, every component retained. test fn w_the_floating_fixture_actually_floats_exactly_one_terminal() -> Bool { let produced = terminal_member_count(nets: power_interlock_article.analog.nets) let floated = terminal_member_count(nets: floating_analog.nets) @@ -209,12 +207,12 @@ test fn w_the_same_board_still_emits_for_a_target_that_can_render_it() -> Bool { } } -// THE MIRROR OF THE ADMISSION-CAUSES TEST, and it is here because the entry used to fail it. The -// pin chain reports a SET of causes and the entry passed cs.first, so a board with two independent -// defects crossed the host boundary carrying one — the second was not refused, not deferred, just -// absent, and a caller had no way to learn it existed. These assignments plant exactly two: pin 5 -// is not on the TQ144 package, and reset_release is left with no pin at all. Counting is what -// makes the fix visible; matching the arm passed before and after. +// THE MIRROR OF THE ADMISSION-CAUSES TEST, here because the entry used to fail it. The pin chain +// reports a SET of causes and the entry passed cs.first, so a board with two independent defects +// crossed the host boundary carrying one — the second was not refused or deferred, just absent, +// and a caller could not learn it existed. These assignments plant exactly two: pin 5 is not on +// the TQ144 package, and reset_release is left with no pin. Counting makes the fix visible; +// matching the arm passed before and after. test fn w_every_target_cause_crosses_the_boundary() -> Bool { match emit_pin_constraints_for( article: power_interlock_article, diff --git a/dag/test/claim/content_hash_family_grounded_witness_test.dag b/dag/test/claim/content_hash_family_grounded_witness_test.dag index 5709258935e..f564a952f60 100644 --- a/dag/test/claim/content_hash_family_grounded_witness_test.dag +++ b/dag/test/claim/content_hash_family_grounded_witness_test.dag @@ -289,7 +289,24 @@ test fn oci_content_digest_accepts_other_algorithm_wire() -> Bool { } } -data oci_other_digest_roundtrip_witness_note: String = "Operator review (2026-07-31) found that oci_content_digest_accepts_other_algorithm_wire above reads ONLY body.algorithm — it never reads body.encoded and never calls render_oci_content_digest_wire, so the entire encoded-carrier and render half of the OciOtherDigest path had no executing consumer. Two real defects hid in exactly that gap and shipped green: OciOtherDigestEncoded was declared as a NESTED refinement (NonEmptyStr where oci_other_digest_encoded), which is a carrier composition the emitter cannot lower, so the generated Rust carried panic!(\"unsupported cast from String to NonEmptyStr\") on the parse side and panic!(\"unsupported cast from NonEmptyStr to String\") on the render side. The first broke the build; the SECOND WAS MASKED BY THE FIRST and would have panicked at runtime whenever an accepted non-SHA OCI digest was rendered — a compiling build would still have paniced. The carrier is now a SINGLE refinement (String where oci_other_digest_encoded), which is not a weakening: oci_other_digest_encoded already establishes non-emptiness AND the OCI encoded grammar, so the NonEmptyStr layer was a second representation of a fact the predicate independently proves (DESIGN section 2 — one concept, one authority). This witness is the durable control for that whole path: wire String -> algorithm validation -> encoded validation -> refined carrier construction -> OciOtherDigestBody -> projection -> wire rendering. It reds on either panic reappearing and on any projection that fails to round-trip. dissolve-on: never — permanent regression alarm for the OciOtherDigest carrier and its emission." +// Operator review (2026-07-31) found that oci_content_digest_accepts_other_algorithm_wire above +// reads ONLY body.algorithm — it never reads body.encoded and never calls +// render_oci_content_digest_wire, so the entire encoded-carrier and render half of the +// OciOtherDigest path had no executing consumer. Two real defects hid in exactly that gap and +// shipped green: OciOtherDigestEncoded was declared as a NESTED refinement (NonEmptyStr where +// oci_other_digest_encoded), which is a carrier composition the emitter cannot lower, so the +// generated Rust carried panic!("unsupported cast from String to NonEmptyStr") on the parse side +// and panic!("unsupported cast from NonEmptyStr to String") on the render side. The first broke the +// build; the SECOND WAS MASKED BY THE FIRST and would have panicked at runtime whenever an accepted +// non-SHA OCI digest was rendered — a compiling build would still have paniced. The carrier is now +// a SINGLE refinement (String where oci_other_digest_encoded), which is not a weakening: +// oci_other_digest_encoded already establishes non-emptiness AND the OCI encoded grammar, so the +// NonEmptyStr layer was a second representation of a fact the predicate independently proves +// (DESIGN section 2 — one concept, one authority). This witness is the durable control for that +// whole path: wire String -> algorithm validation -> encoded validation -> refined carrier +// construction -> OciOtherDigestBody -> projection -> wire rendering. It reds on either panic +// reappearing and on any projection that fails to round-trip. dissolve-on: never — permanent +// regression alarm for the OciOtherDigest carrier and its emission. test fn oci_other_digest_wire_roundtrips() -> Bool { match parse_oci_content_digest_wire(raw: "sha384:abc") { diff --git a/dag/test/claim/cooling_qualification_witness_test.dag b/dag/test/claim/cooling_qualification_witness_test.dag index c39365d2e15..e734da14dab 100644 --- a/dag/test/claim/cooling_qualification_witness_test.dag +++ b/dag/test/claim/cooling_qualification_witness_test.dag @@ -265,7 +265,13 @@ test fn catalog_verdict_cannot_stand_in_for_runtime_thermal_evidence() -> Bool { } } -data ambiguity_witness_note: String = "installed_cooling_verdict_for_host previously returned on the FIRST row whose host matched, so two cooler rows bound to one host were resolved by authoring order: one won silently and the other sat in the inventory affecting nothing. It presented as a clean Compatible. A host carries at most one heat-pickup realization, so two rows are an inventory error and must refuse rather than resolve. The control below is ORDER-INDEPENDENT on purpose - it asserts the same refusal with the duplicate pair in both orders, because a witness using a single ordering would pass just as well against the first-match-wins implementation it exists to refuse." +// installed_cooling_verdict_for_host previously returned on the FIRST row whose host matched, so +// two cooler rows bound to one host were resolved by authoring order: one won silently and the +// other sat in the inventory affecting nothing. It presented as a clean Compatible. A host carries +// at most one heat-pickup realization, so two rows are an inventory error and must refuse rather +// than resolve. The control below is ORDER-INDEPENDENT on purpose - it asserts the same refusal +// with the duplicate pair in both orders, because a witness using a single ordering would pass just +// as well against the first-match-wins implementation it exists to refuse. data duplicate_cooling_ab: List = [ srv3_installed_cooling, diff --git a/dag/test/claim/cross_file_binding_assembly_witness_test.dag b/dag/test/claim/cross_file_binding_assembly_witness_test.dag index 886625980e7..63802a8a9f2 100644 --- a/dag/test/claim/cross_file_binding_assembly_witness_test.dag +++ b/dag/test/claim/cross_file_binding_assembly_witness_test.dag @@ -49,7 +49,13 @@ import std.occurrence_binding_candidates { data live_tree_disposition: LiveTreeDisposition = ReadsLiveTree -data cfba_witness_note: String = "N3-B0 acceptance witness: one exposure authority (DeclarationExposureGrounding, all three variants pairwise-discriminated across module-root and single-ancestor containment shapes) plus the collision-free cross-file assembly substrate (assemble_cross_file_binding_closure) in std.occurrence_binding_candidates. Structural controls at the bottom prove the two former duplicate helpers (gunbc.type_reference_binding_context's local exposure walk, v1.gunbc.occurrence_binding_parser_walk's local exposure walk + StructuralBindingWalk copy) are deleted from their old homes and the single authority is present where claimed." +// N3-B0 acceptance witness: one exposure authority (DeclarationExposureGrounding, all three +// variants pairwise-discriminated across module-root and single-ancestor containment shapes) plus +// the collision-free cross-file assembly substrate (assemble_cross_file_binding_closure) in +// std.occurrence_binding_candidates. Structural controls at the bottom prove the two former +// duplicate helpers (gunbc.type_reference_binding_context's local exposure walk, +// v1.gunbc.occurrence_binding_parser_walk's local exposure walk + StructuralBindingWalk copy) are +// deleted from their old homes and the single authority is present where claimed. fn cfba_path(dotted: String) -> NonEmptyStr { dotted as NonEmptyStr diff --git a/dag/test/claim/css_grain_witness_test.dag b/dag/test/claim/css_grain_witness_test.dag index b5bb97f1a94..0a79874f9ed 100644 --- a/dag/test/claim/css_grain_witness_test.dag +++ b/dag/test/claim/css_grain_witness_test.dag @@ -11,7 +11,13 @@ import v2.std.live_tree { LiveTreeDisposition, SubstrateInputsOnly } data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data css_grain_witness_note: String = "D5 keystone: the CSS grain (extdeps.languages.css) is the typed authority for the register's property names and selector subjects — the last stringly medium in the served stack, now typed. The serializers reproduce the emitted strings byte-exact (the register's whole-stylesheet byte-identity is proven by the lift-parity + register witnesses; here the grain's OWN serializers are pinned with RED controls). RawSelector is the COUNTED frontier: raw_selector_count is the honest residue number (selectors still expressed as raw text — descendant/compound/functional-pseudo, awaiting the combinator grammar), and RawProperty is the same escape for a non-standard property name." +// D5 keystone: the CSS grain (extdeps.languages.css) is the typed authority for the register's +// property names and selector subjects — the last stringly medium in the served stack, now typed. +// The serializers reproduce the emitted strings byte-exact (whole-stylesheet byte-identity is +// proven by the lift-parity + register witnesses; here the grain's OWN serializers are pinned with +// RED controls). RawSelector is the COUNTED frontier: raw_selector_count is the honest residue +// (selectors still raw text — descendant/compound/functional-pseudo, awaiting the combinator +// grammar); RawProperty is the same escape for a non-standard property name. test fn witness_property_wire_byte_exact() -> Bool { css_property_wire(p: FontSize) == "font-size" @@ -22,7 +28,8 @@ test fn witness_property_wire_byte_exact() -> Bool { && css_property_wire(p: RawProperty { name: "code-spacing" }) == "code-spacing" } -// RED control: css_property_wire must produce the upstream hyphenated spelling; a camelCase or underscored mis-serialization reds the byte-exact pin above (browsers are the consumer). +// RED control: css_property_wire must produce the upstream hyphenated spelling; a camelCase or +// underscored mis-serialization reds the byte-exact pin above (browsers are the consumer). test fn witness_property_wire_red() -> Bool { css_property_wire(p: FontSize) != "fontSize" && css_property_wire(p: FontSize) != "font_size" @@ -35,7 +42,8 @@ test fn witness_selector_wire_byte_exact() -> Bool { && selector_subject_wire(s: RawSelector { text: ".frontier-bucket h2" }) == ".frontier-bucket h2" } -// RED control: a ClassSelector must serialize with its leading dot; dropping it reds. RawSelector carries the exact text so a complex selector emits byte-identical. +// RED control: a ClassSelector must serialize with its leading dot; dropping it reds. RawSelector +// carries the exact text so a complex selector emits byte-identical. test fn witness_selector_wire_red() -> Bool { selector_subject_wire(s: ClassSelector { name: "x" }) != "x" && selector_subject_wire(s: ClassSelector { name: "x" }) == ".x" diff --git a/dag/test/claim/cursor_cli_invocation_witness_test.dag b/dag/test/claim/cursor_cli_invocation_witness_test.dag index 8b4f07d1041..4c03823c6ed 100644 --- a/dag/test/claim/cursor_cli_invocation_witness_test.dag +++ b/dag/test/claim/cursor_cli_invocation_witness_test.dag @@ -26,7 +26,9 @@ import extdeps.llm.cursor_cli { data witness_purpose_note: String = "THE AUTH FIELD WAS NEVER READ, so these two invocations used to be the same value. shape_cursor_agent_argv took a CursorInvocation, ignored inv.auth, and returned an argv — which meant the environment arm bound nothing and the argument arm leaked nothing, and the module's note explaining why the key stays out of argv described a property that held because the key went nowhere at all.\\n\\nThese claims are written so that reverting to an auth-blind shaper fails them in both directions: the environment arm must actually bind CURSOR_API_KEY, and the argument arm must actually put the key in argv. A shaper that ignores auth cannot satisfy both, and one that ignores auth while omitting the key entirely — the previous behaviour — fails the first." -data secret_key_is_synthetic_note: String = "The key below is a literal fixture and not a credential. A witness needs a value to trace through the shaping, and the whole point of the claims is that the value lands in different places depending on the arm — so it has to be present and it has to be recognizable in the output." +// The key below is a literal fixture, not a credential. A witness needs a value to trace through +// the shaping, and the claims are that it lands in different places per arm — so it must be +// present and recognizable in the output. data witness_key: NonEmptyStr = "synthetic-not-a-real-key" as NonEmptyStr @@ -63,7 +65,9 @@ test fn argument_arm_places_the_key_in_argv_and_binds_nothing() -> Bool { && count(shaped.environment) == 0 } -// The direct statement of the defect: the two arms produce different processes. Under the auth-blind shaper this claim was false — not subtly, but exactly false, because the function never looked at the field that distinguishes them. +// The direct statement of the defect: the two arms produce different processes. Under the +// auth-blind shaper this was exactly false — the function never looked at the distinguishing +// field. test fn the_two_auth_arms_produce_different_processes() -> Bool { let env_shaped = shape_cursor_invocation( inv: witness_invocation(auth: CursorApiKeyEnvironment { key: witness_key }), @@ -75,7 +79,9 @@ test fn the_two_auth_arms_produce_different_processes() -> Bool { && !(count(env_shaped.environment) == count(arg_shaped.environment)) } -// The automation path cannot reach the leaky arm, because it has no parameter that selects one. This asserts the property through the shaped output rather than by matching the auth field, so it stays true of what the process actually receives rather than of how the value was labelled. +// The automation path cannot reach the leaky arm: it has no parameter selecting one. Asserted +// through the shaped output rather than by matching the auth field, so it stays true of what the +// process actually receives, not how the value was labelled. test fn automation_constructor_only_materializes_into_the_env_var() -> Bool { let shaped = shape_cursor_invocation( inv: cursor_automation_invocation( diff --git a/dag/test/claim/cursor_sdk_stream_witness_test.dag b/dag/test/claim/cursor_sdk_stream_witness_test.dag index ec332c8ca2b..af02c9d0c7b 100644 --- a/dag/test/claim/cursor_sdk_stream_witness_test.dag +++ b/dag/test/claim/cursor_sdk_stream_witness_test.dag @@ -170,7 +170,16 @@ test fn cursor_sdk_stream_witness_keystone_holds() -> Bool { && agent_report_text_does_not_classify_as_terminal_error() } -data cursor_line_reading_discrimination_note: String = "THE COLLAPSE THIS CHANGE REMOVES, AND WHY A CLASSIFIER IS THE WORST PLACE FOR IT. Both classifiers returned an Optional whose `none` answered four different facts, and a classifier is asked about EVERY line of a stream -- so `none` is its ordinary answer and nothing about it looks wrong. A stream that became malformed halfway through (truncated write, interleaved writer, crash mid-line) was therefore indistinguishable from a stream of lines the classifier simply had nothing to say about. The witnesses below assert that an unreadable line and a well-formed line missing its type member are now different values, and the untouched unknown_event_stays_unclassified control is what keeps them honest: an UNRECOGNISED KIND is a CLASSIFIED answer, not a reading failure, and a decoder that refused it would break the classifier while satisfying a naive refusal test." +// THE COLLAPSE THIS CHANGE REMOVES, AND WHY A CLASSIFIER IS THE WORST PLACE FOR IT. Both +// classifiers returned an Optional whose `none` answered four different facts, and a classifier is +// asked about EVERY line of a stream -- so `none` is its ordinary answer and nothing about it looks +// wrong. A stream that became malformed halfway through (truncated write, interleaved writer, crash +// mid-line) was therefore indistinguishable from a stream of lines the classifier simply had +// nothing to say about. The witnesses below assert that an unreadable line and a well-formed line +// missing its type member are now different values, and the untouched +// unknown_event_stays_unclassified control is what keeps them honest: an UNRECOGNISED KIND is a +// CLASSIFIED answer, not a reading failure, and a decoder that refused it would break the +// classifier while satisfying a naive refusal test. test fn RED_unreadable_cursor_line_is_not_a_missing_type_member() -> Bool { match cursor_sdk_stream_classify_message_line(raw: "{ truncated mid-lin") { diff --git a/dag/test/claim/dag_compile_clean_perturb_receipts_test.dag b/dag/test/claim/dag_compile_clean_perturb_receipts_test.dag index 0bbf264b0a8..c102b107e3d 100644 --- a/dag/test/claim/dag_compile_clean_perturb_receipts_test.dag +++ b/dag/test/claim/dag_compile_clean_perturb_receipts_test.dag @@ -9,7 +9,12 @@ import v2.std.live_tree { LiveTreeDisposition, SubstrateInputsOnly } data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data dag_compile_clean_perturb_fixture_note: String = "Class C decomposition: per-PR mechanism RED arms on a fixture-only compile closure (dcc_fixture_only_compile_args — one module, no compile_clean_source_roots). perturb_fixture_green_holds is the discriminating GREEN control — a no-import valid module must compile on the same path, proving the fixture transport is not always-fail. Corpus-grain legs re-homed to falsifier_rehomed_bin_wet_rows via dag/test/claim/long/dag_compile_clean_perturb_corpus_witness_test.dag." +// Class C decomposition: per-PR mechanism RED arms on a fixture-only compile closure +// (dcc_fixture_only_compile_args — one module, no compile_clean_source_roots). +// perturb_fixture_green_holds is the discriminating GREEN control — a no-import valid module must +// compile on the same path, proving the fixture transport is not always-fail. Corpus-grain legs +// re-homed to falsifier_rehomed_bin_wet_rows via +// dag/test/claim/long/dag_compile_clean_perturb_corpus_witness_test.dag. test fn perturb_optional_skew_fixture_red_holds() -> Bool { run_perturb_optional_skew_fixture_red_receipt() diff --git a/dag/test/claim/dag_compile_clean_shard_totality_witness_test.dag b/dag/test/claim/dag_compile_clean_shard_totality_witness_test.dag index 5850d8bba47..48b3634b0af 100644 --- a/dag/test/claim/dag_compile_clean_shard_totality_witness_test.dag +++ b/dag/test/claim/dag_compile_clean_shard_totality_witness_test.dag @@ -6,22 +6,22 @@ import v2.std.live_tree { LiveTreeDisposition, ReadsLiveTree } // THIS FILE IS NOW SINGLE-GRAIN: ONE TEST FN, AND IT GENUINELY READS THE TREE. // // Its closure reaches tools.dag_compile_clean_shard_totality_transport run_live_dag_entry_glob and -// through it git.Inspect.Toplevel, so ReadsLiveTree is this file's own property rather than a value -// forced on it by a neighbour. A SubstrateInputsOnly row is predict-skip-eligible and a wrongly -// skipped live-tree row is a selection fail-open, so the stamp stays. +// through it git.Inspect.Toplevel, so ReadsLiveTree is this file's own property, not forced by a +// neighbour. A SubstrateInputsOnly row is predict-skip-eligible and a wrongly skipped live-tree row +// is a selection fail-open, so the stamp stays. // -// WHAT CHANGED, AND WHY THE PREVIOUS NOTE HERE WAS WRONG ON ITS FACTS. The 2026-07-29 correction -// note this replaces reached the right verdict by the wrong route: it said the file's closure -// reaches "the live-read carrier home tools.dag_compile_clean_shard_roster". That module contains -// no live read at all -- measured by call-reachability, it has zero shell effects, as does -// tools.dag_compile_clean_partition. The live read was always in the totality transport named above. -// The note's two-grain diagnosis was correct and its carrier attribution was not, and because it sat -// beside the code asserting a mechanism, two readers took it as evidence and neither reached for the -// call graph. A prose row naming the wrong carrier is more expensive than no note. +// WHY THE PREVIOUS NOTE HERE WAS WRONG ON ITS FACTS. The 2026-07-29 correction note it replaces +// reached the right verdict by the wrong route: it said the closure reaches "the live-read carrier +// home tools.dag_compile_clean_shard_roster". Measured by call-reachability that module has zero +// shell effects, as does tools.dag_compile_clean_partition; the live read was always in the +// totality transport named above. The two-grain diagnosis was correct, the carrier attribution +// was not, and because it sat beside the code asserting a mechanism, two readers took it as +// evidence and neither reached for the call graph. A prose row naming the wrong carrier costs more +// than no note. // // The nine assertions that shared this file and needed no live tree now live in // test.claim.dag_compile_clean_shard_hermetic_witness under SubstrateInputsOnly. They were -// discovered, counted and never executed for as long as they were stamped by their neighbour. +// discovered, counted and never executed while stamped by their neighbour. data live_tree_disposition: LiveTreeDisposition = ReadsLiveTree // NOT A PER-PR ROW: falsifier-rehomed (gunbc.ci_layer_roots falsifier frontier). The rehoming diff --git a/dag/test/claim/dag_line_comment_annotation_channel_test.dag b/dag/test/claim/dag_line_comment_annotation_channel_test.dag index ea2ff6ce2ca..b3b1f37c0e4 100644 --- a/dag/test/claim/dag_line_comment_annotation_channel_test.dag +++ b/dag/test/claim/dag_line_comment_annotation_channel_test.dag @@ -15,7 +15,20 @@ import v2.std.compilers.lexing { import v2.compiler.tokenize { lex_walk_artifact } import v2.extdeps.languages.dag { dag_lex_rules } -data dag_line_comment_annotation_channel_note: String = "THE PRODUCTION '//' CHANNEL, asserted against the LexArtifact rather than against Accepted. Before this rule was registered, dag_lex_rules carried NO annotation rule at all, so a '//' line was not lexed as a comment: it tokenized as two dag_token_slash tokens followed by whatever its payload happened to lex as. A comment therefore 'lexed' BY ACCIDENT, exactly when every character in its payload had a semantic rule, and refused at the first character that did not — measured: '-' passed while the em-dash, the backtick and '@' each refused, and the em-dash passed inside a string literal where it is string content.\n\nThat is why an Accepted-only control is a FALSE CONTROL for this capability: 'module m // a b' lexing proves that slash-slash-ident-ident is lexable, not that a comment was recognised. Every claim below therefore reads the artifact — the annotation the channel captured, and the semantic stream it must NOT have polluted. The payload controls use characters with no semantic lex rule precisely because under the accidental route they were the refusing cases; under a real channel the payload is opaque and they are ordinary text." +// THE PRODUCTION '//' CHANNEL, asserted against the LexArtifact rather than against Accepted. +// Before this rule was registered, dag_lex_rules carried NO annotation rule at all, so a '//' line +// was not lexed as a comment: it tokenized as two dag_token_slash tokens followed by whatever its +// payload happened to lex as. A comment therefore 'lexed' BY ACCIDENT, exactly when every character +// in its payload had a semantic rule, and refused at the first character that did not — measured: +// '-' passed while the em-dash, the backtick and '@' each refused, and the em-dash passed inside a +// string literal where it is string content. +// +// That is why an Accepted-only control is a FALSE CONTROL for this capability: 'module m // a b' +// lexing proves that slash-slash-ident-ident is lexable, not that a comment was recognised. Every +// claim below therefore reads the artifact — the annotation the channel captured, and the semantic +// stream it must NOT have polluted. The payload controls use characters with no semantic lex rule +// precisely because under the accidental route they were the refusing cases; under a real channel +// the payload is opaque and they are ordinary text. fn artifact_of(source: String) -> LexArtifact? { match lex_walk_artifact(source: source, file: ^annotation_probe, rules: dag_lex_rules()) { diff --git a/dag/test/claim/decl_facts_initializer_projection_witness_test.dag b/dag/test/claim/decl_facts_initializer_projection_witness_test.dag index 7ce8e1a35c4..ac28bd883e1 100644 --- a/dag/test/claim/decl_facts_initializer_projection_witness_test.dag +++ b/dag/test/claim/decl_facts_initializer_projection_witness_test.dag @@ -42,7 +42,10 @@ data mechanism_single_authority_qn: String = "test.fixture.decl_facts_reflection data mechanism_realization_dispatch_qn: String = "test.fixture.decl_facts_reflection.specimens.mechanism_realization_dispatch" data missing_variant_specimen_qn: String = "test.fixture.decl_facts_reflection.specimens.missing_variant_specimen" -data structured_application_mismatch_wall_regression_note: String = "The compile-clean fixture uses SingleAuthority at dissolves_to; the pre-wall Terminal-at-ConstructionMechanism specimen is pinned as a permanent compile-refusal regression control in test.claim.structured_application_mismatch_wall_witness (review 52087 §4b dissolution-on-climb)." +// The compile-clean fixture uses SingleAuthority at dissolves_to; the pre-wall +// Terminal-at-ConstructionMechanism specimen is pinned as a permanent compile-refusal regression +// control in test.claim.structured_application_mismatch_wall_witness (review 52087 §4b +// dissolution-on-climb). data ambiguous_arm_specimen_qn: String = "test.fixture.decl_facts_reflection.ambiguous_specimen.ambiguous_arm_specimen" data ambiguous_b_arm_specimen_qn: String = "test.fixture.decl_facts_reflection.ambiguous_b_specimen.ambiguous_b_arm_specimen" data duplicate_shadowed_specimen_qn: String = "test.fixture.decl_facts_reflection_duplicate_qn.shadowed_module.shadowed_specimen" diff --git a/dag/test/claim/decl_facts_reflection_witness_test.dag b/dag/test/claim/decl_facts_reflection_witness_test.dag index 8fd9150f8e4..8ab9ae46d4c 100644 --- a/dag/test/claim/decl_facts_reflection_witness_test.dag +++ b/dag/test/claim/decl_facts_reflection_witness_test.dag @@ -22,7 +22,15 @@ import v2.std.data_initializer_identity { } import v2.std.algebra { length } -data decl_facts_reflection_witness_note: String = "Step-1 prerequisite (#7796), PARTIAL: outer record-constructor SPELLING (OuterRecordConstructorLexeme) is reflected and tested via executing witnesses. Nullary variant VALUE parent/arm identity is exercised through decl_facts() on the lookup_fn_node marshal seam (w_nullary_variant_value_absent_without_infer_stamping_top_level, w_nullary_variant_value_absent_without_infer_stamping_nested, and decl_facts_initializer_projection_witness_test explicit-import rows). Exact parent-variant occurrence identity remains open — see decl_facts_nullary_variant_value_identity_gap_note. Rust tests in v1-compiler-tests are developer convenience only (compile-only in CI; nextest retired 2026-07-11)." +// Step-1 prerequisite (#7796), PARTIAL: outer record-constructor SPELLING +// (OuterRecordConstructorLexeme) is reflected and tested via executing witnesses. Nullary variant +// VALUE parent/arm identity is exercised through decl_facts() on the lookup_fn_node marshal seam +// (w_nullary_variant_value_absent_without_infer_stamping_top_level, +// w_nullary_variant_value_absent_without_infer_stamping_nested, and +// decl_facts_initializer_projection_witness_test explicit-import rows). Exact parent-variant +// occurrence identity remains open — see decl_facts_nullary_variant_value_identity_gap_note. Rust +// tests in v1-compiler-tests are developer convenience only (compile-only in CI; nextest retired +// 2026-07-11). data qn_planted_scaffold_specimen: String = "test.fixture.decl_facts_reflection.specimens.planted_scaffold_specimen" data qn_planted_terminal_specimen: String = "test.fixture.decl_facts_reflection.specimens.planted_terminal_specimen" diff --git a/dag/test/claim/declared_type_inhabitance_direct_call_witness_test.dag b/dag/test/claim/declared_type_inhabitance_direct_call_witness_test.dag index ed15091c39f..e63d38d3311 100644 --- a/dag/test/claim/declared_type_inhabitance_direct_call_witness_test.dag +++ b/dag/test/claim/declared_type_inhabitance_direct_call_witness_test.dag @@ -282,9 +282,9 @@ test fn w_a_type_variable_type_argument_is_not_read_as_a_disagreement() -> Bool // standing between that and a silent false match. data phantom_distinct_type_argument_source: String = "module probe_inhabit_phantom\nimport std.types { String }\ntype DemandKey { v: String }\ntype WorkKey { v: String }\ntype FabricIdentity { principal: P, key: String }\nfn mk_work() -> FabricIdentity { FabricIdentity { principal: \"p\", key: \"k\" } }\nfn takes_demand(x: FabricIdentity) -> String { x.key }\nfn probe() -> String { takes_demand(x: mk_work()) }\n" -test fn w_a_phantom_type_argument_with_identical_representation_is_still_separated() -> Bool { - violation_count(source: phantom_distinct_type_argument_source, wanted: "DeclaredTypeNotInhabited") > 0 -} +// examples.nominal_distinctness_witness and examples.nominal_distinctness_twin were deleted when +// this arm landed: the RED half was a corpus module that must not compile, and its discrimination +// is carried by the enrolled fixture arms in this file. // WHERE THE examples.nominal_distinctness_witness PAIR WENT, recorded here because deleting a // module takes its evidence with it unless the evidence is named first. That pair was @@ -305,4 +305,6 @@ test fn w_a_phantom_type_argument_with_identical_representation_is_still_separat // _call_are_refused above plus w_matching_applied_product_at_a_direct_call_argument_is_admitted, // both of which EXECUTE on every floor run. So the evidence did not move to a weaker home; it // moved from a home where it could never fire to one where it fires every run. -data nominal_distinctness_example_disposition: String = "examples.nominal_distinctness_witness and examples.nominal_distinctness_twin were deleted when this arm landed: the RED half was a corpus module that must not compile, and its discrimination is carried by the enrolled fixture arms in this file." +test fn w_a_phantom_type_argument_with_identical_representation_is_still_separated() -> Bool { + violation_count(source: phantom_distinct_type_argument_source, wanted: "DeclaredTypeNotInhabited") > 0 +} diff --git a/dag/test/claim/deleted_cadence_reference_census_witness_test.dag b/dag/test/claim/deleted_cadence_reference_census_witness_test.dag index d8a71123bd5..ffb5a194308 100644 --- a/dag/test/claim/deleted_cadence_reference_census_witness_test.dag +++ b/dag/test/claim/deleted_cadence_reference_census_witness_test.dag @@ -40,16 +40,16 @@ import gunbc.legacy_test_behavior_disposition { // that ignored its argument, or answered a constant, agrees with the control and is caught. // THE FIXTURE SITE REFERENCES NAME THIS MODULE'S OWN ROWS, and the first cut of this file did -// not -- it invented `test.fixture.red` and `test.fixture.green`, modules that do not exist. -// The citation wall refused all eleven with CITED-MODULE-ABSENT, which is the defect class this -// whole change exists to enforce, committed by the change enforcing it and caught by execution -// rather than by its author. Recorded here rather than quietly corrected, because a wall that -// catches its own advocate is the best evidence available that it is real. +// not -- it invented `test.fixture.red` and `test.fixture.green`, modules that do not exist. The +// citation wall refused all eleven with CITED-MODULE-ABSENT: the defect class this change exists +// to enforce, committed by the change enforcing it and caught by execution rather than by its +// author. Recorded rather than quietly corrected, because a wall that catches its own advocate is +// the best evidence available that it is real. // // The honest repair is to make the citation TRUE, never to exempt a fixture from the rule: a -// fixture row IS a declaration in a real module, so it cites itself. The `site` field is not -// what any predicate below reads -- they match on `standing` alone -- which is exactly why a -// false value there would have sat unnoticed forever. +// fixture row IS a declaration in a real module, so it cites itself. The `site` field is not what +// any predicate below reads -- they match on `standing` alone -- which is exactly why a false +// value there would have sat unnoticed forever. data red_rebound_to_dark_cadence: DeletedCadenceReference = DeletedCadenceReference { site: decl_ref(module_path: "test.claim.deleted_cadence_reference_census_witness_test", decl_name: "red_rebound_to_dark_cadence"), standing: ReboundToExecutingConsumer { diff --git a/dag/test/claim/design_palette_witness_test.dag b/dag/test/claim/design_palette_witness_test.dag index 5d18246a58d..126a28ab08b 100644 --- a/dag/test/claim/design_palette_witness_test.dag +++ b/dag/test/claim/design_palette_witness_test.dag @@ -169,7 +169,10 @@ test fn witness_ivory_refused_despite_near_achromatic_oklch() -> Bool { !quiet_envelope_srgb8(c: island_ivory.color) } -data ivory_hsl_proxy_defect_note: String = "Teaching case: ivory (255,255,250) is refused by the HSL quiet_envelope despite perceptual near-achromatic OKLCH chroma (~0.007) — documents the HSL-proxy defect that design-register-library.md sect 10 schedules for OKLCH reground; this witness pins the defect, it does not fix it." +// Teaching case: ivory (255,255,250) is refused by the HSL quiet_envelope despite perceptual +// near-achromatic OKLCH chroma (~0.007) — documents the HSL-proxy defect that +// design-register-library.md sect 10 schedules for OKLCH reground; this witness pins the defect, it +// does not fix it. test fn witness_cited_palette_counts() -> Bool { swatches_of(s: okabe_ito).length() == 8 diff --git a/dag/test/claim/design_register_lift_parity_witness_test.dag b/dag/test/claim/design_register_lift_parity_witness_test.dag index 99655070f0f..c526bbb0896 100644 --- a/dag/test/claim/design_register_lift_parity_witness_test.dag +++ b/dag/test/claim/design_register_lift_parity_witness_test.dag @@ -9,7 +9,10 @@ import v2.std.live_tree { LiveTreeDisposition, SubstrateInputsOnly } data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data lift_parity_note: String = "Phase-A emission-identical witness (design-register-library.md sect 5): pins content digests of site + roadmap CSS/HTML emissions after the gunbc.design.* lift. Pre-lift golden = post-lift output (lift-not-fork); drift reds. site_register_keystone and roadmap_register_keystone remain the behavioral receipts; this witness is the digest receipt." +// Phase-A emission-identical witness (design-register-library.md sect 5): pins content digests of +// site + roadmap CSS/HTML emissions after the gunbc.design.* lift. Pre-lift golden = post-lift +// output (lift-not-fork); drift reds. site_register_keystone and roadmap_register_keystone remain +// the behavioral receipts; this witness is the digest receipt. data transition_carrier_repin_note: String = "Re-pinned for the transition-carrier restructure (the tactile exemplar's PR-A). A transition used to be emitted INSIDE a response's base block; it is now accumulated per carrier selector and emitted once, because the shorthand cannot express one property at several weights and a naive union of property names silently drops the durations of all but the last. That moves bytes on every surface with response rules, including the site's — so the site digests are re-pinned, and the re-pin is justified BY EXECUTION rather than by assertion. @@ -18,62 +21,310 @@ The proof, run 2026-07-24: old and new moodboard CSS were both emitted and compa Two digests deliberately did NOT move, which is itself evidence the change is scoped as described: accent_study_html declares no response rules, so it has no transition carriers and its bytes are untouched; moodboard_digest covers the thesis/theme rows rather than the stylesheet. A change that had leaked past the transition machinery would have moved those too." data moodboard_css_lift_parity_digest: String = "deaf2b36826760c2" -data moodboard_repin_s1_selective_spectacle_note: String = "Re-pinned 2026-08-02 for the S1 selective-spectacle amendment (operator recalibration): the moodboard HTML, thesis/themes, and accent-study HTML digests move intentionally because the thesis string is revised (calm field; luminous focus; physical response; every response true) — both pages render register_thesis — and the principles table gains the three salience rows (selective-spectacle, emission-over-material, bounded-attraction, each carried by a gunbc.design.salience declaration). moodboard_css deliberately did NOT move (re-derived deaf2b36826760c2, equal to its pin) — the amendment is model-layer only, no stylesheet change, which is itself the scope evidence. Behavioral receipts: test.claim.salience_witness (budget table, focal budget refusal, emission refusals incl. sole-discriminator, attraction envelope). All three digests derived by execution (moodboard_html_derived_digest / moodboard_digest / accent_study_html_derived_digest run 2026-08-02), never chosen." - -data moodboard_repin_physical_enclosure_note: String = "Re-pinned 2026-08-05 for the PhysicalEnclosure amendment (the first v1-deletion instrument): the moodboard renders register_principles as a table, so the twelfth principle row and the restated StillUntilTouched law move its HTML bytes. Derived by execution (moodboard_html_derived_digest, run 2026-08-05), never chosen. FOUR PINS DELIBERATELY DID NOT MOVE, and CI is what established that rather than an assertion here: of the five digest witnesses in this file, exactly one went red on the amendment. moodboard_css did not move because the amendment is model-layer and adds no stylesheet rule; moodboard_thesis_themes did not move because register_thesis is untouched — the amendment adds a principle, it does not revise the thesis, which is the difference from the S1 re-pin above; accent_study_html did not move because it renders the thesis and not the principles table; and roadmap_css did not move even though gunbc.roadmap_style band_root_css was rewritten to call the new theme_scoped_blocks, which is the emission-identity proof for that consolidation — the same three selector blocks, byte for byte, from one authority instead of two copies. Behavioral receipt: test.claim.salience_witness (principle keys distinct, all carried, physical-enclosure present) and test.claim.instrument_physical_witness (the composed displacement budget the new principle names as its carrier)." +// Re-pinned 2026-08-02 for the S1 selective-spectacle amendment (operator recalibration): the +// moodboard HTML, thesis/themes, and accent-study HTML digests move intentionally because the +// thesis string is revised (calm field; luminous focus; physical response; every response true) — +// both pages render register_thesis — and the principles table gains the three salience rows +// (selective-spectacle, emission-over-material, bounded-attraction, each carried by a +// gunbc.design.salience declaration). moodboard_css deliberately did NOT move (re-derived +// deaf2b36826760c2, equal to its pin) — the amendment is model-layer only, no stylesheet change, +// which is itself the scope evidence. Behavioral receipts: test.claim.salience_witness (budget +// table, focal budget refusal, emission refusals incl. sole-discriminator, attraction envelope). +// All three digests derived by execution (moodboard_html_derived_digest / moodboard_digest / +// accent_study_html_derived_digest run 2026-08-02), never chosen. + +// Re-pinned 2026-08-05 for the PhysicalEnclosure amendment (the first v1-deletion instrument): the +// moodboard renders register_principles as a table, so the twelfth principle row and the restated +// StillUntilTouched law move its HTML bytes. Derived by execution (moodboard_html_derived_digest, +// run 2026-08-05), never chosen. FOUR PINS DELIBERATELY DID NOT MOVE, and CI is what established +// that rather than an assertion here: of the five digest witnesses in this file, exactly one went +// red on the amendment. moodboard_css did not move because the amendment is model-layer and adds no +// stylesheet rule; moodboard_thesis_themes did not move because register_thesis is untouched — the +// amendment adds a principle, it does not revise the thesis, which is the difference from the S1 +// re-pin above; accent_study_html did not move because it renders the thesis and not the principles +// table; and roadmap_css did not move even though gunbc.roadmap_style band_root_css was rewritten +// to call the new theme_scoped_blocks, which is the emission-identity proof for that consolidation +// — the same three selector blocks, byte for byte, from one authority instead of two copies. +// Behavioral receipt: test.claim.salience_witness (principle keys distinct, all carried, +// physical-enclosure present) and test.claim.instrument_physical_witness (the composed displacement +// budget the new principle names as its carrier). data moodboard_html_lift_parity_digest: String = "4041adc0584f8c45" data accent_study_html_lift_parity_digest: String = "013dfb213ad0128f" -data roadmap_css_digest_repin_note: String = "Re-pinned across the UI-model migration and the #7104 (SupersededLine) merge. P2 (token migration, px/font -> gunbc.design.scale var tokens) was proven visually-neutral by execution: resolving every var(--scale-token) reproduced the pre-P2 CSS byte-for-byte. P3 (presentation mapping) then INTENTIONALLY adds styling: the dispatch button's reserved min-width (derived from the longest wire label, in ch) and the ok/refusal/requested chip material rules (each painting the P0 state's role). D5 (typed CSS grain) is a pure re-grounding — property names and selector subjects become typed, bytes unchanged. The #7104 merge folds in the .status-superseded / .node-superseded / .superseded-by rules, RE-GROUNDED here onto the same typed+tokenized grain (their raw 11px/6px/font-family literals routed through the scale tokens so the untokened-length census stays green), which shifts the bytes off main's hardcoded emission — hence this digest re-pin. The behavioral receipts (roadmap_register_keystone, dispatch_presentation_keystone) and the untokened-length census remain the substance; this digest only pins bytes. Re-pinned again for #7169 (roadmap workspace UX): roadmap_style gained centered .roadmap/.daily-workspace auto side margins and related layout rules — bytes shift, behavioral receipts (roadmap_register_keystone, dispatch_presentation_keystone) unchanged." - -data roadmap_css_repin_tactile_note: String = "The roadmap's own bytes move for a second, intentional reason beyond the carrier restructure: the dashboard gained physical motion. Hover lift, press depression, the latched requested position, the settle spring, the sound toggle's rules and the reduced-motion collapse over all of them are new emission. The behavioural receipts are roadmap_tactile_keystone_holds (which walls the mechanics with planted REDs) and roadmap_register_keystone_holds; this digest only pins bytes." - -data roadmap_css_repin_remodel_w1_note: String = "Re-pinned 2026-07-24 (remodel W1c/W1d/W1g): the roadmap bytes move intentionally — the band var family (band_root_css: instrument fills under the same :root/[data-theme]/media grammar the theme vars use), the dispatch state rules re-painted from role borders to band fill/ink vars, the dispatch-loud rule, and the theme-toggle control's rule. Behavioral receipts: roadmap_register_keystone (census + both-ways archetype demand, BoundaryRole demand dissolved with its stylesheet consumer), dispatch_presentation_keystone (band-paint blocks + caption-projection width), roadmap_tactile_keystone (mechanics unchanged). This digest only pins bytes." - -data roadmap_css_repin_merge_note: String = "Merge resolution 2026-07-25 (main into the remodel branch). Both parents re-pinned this row off the same base value 947686b5dbaab2b0 for disjoint reasons: main via #7193 (namespace-flip emission drift, reaching roadmap_css through std.markup rather than through any design/ or roadmap_*/ file — none of those changed on main since the branch point), the branch via remodel W1 (band var family, dispatch rules re-painted from role borders to band fill/ink). The merged value is DERIVED, never chosen: roadmap_css() was emitted from the merged worktree and its content_hash_atom read off. Three-point control, all run against the same binary: origin/main emits d788728c4745ba48 (reproduces main's pin), the pre-merge branch tip d1d2fd954 emits 50410951147178f6 (reproduces the branch's pin), the merged tree emits 50410951147178f6. The merged value coinciding with the branch's is a real result, not a dropped merge: main's std.markup drift reaches an emission region the branch's W1 rewrite replaces, so the branch's bytes supersede it — and merge faithfulness is a separate receipt (of the 327 paths main touched since the base, 324 are byte-identical to main in the merged tree and 3 are the co-edited files, zero unexplained). Resolving this conflict by keeping either side's literal would have pinned bytes no tree emits." - -data roadmap_css_repin_row_archetype_note: String = "Re-pinned for composition slice 2 (the RoadmapRow archetype): the roadmap bytes move intentionally — the node-head flex rules become the archetype-derived grid (template from roadmap_row_grid_template, density on h-row and the row gutter), the node-mid cell rule and the chip-scale row actuator override are new emission, the margin-left:auto pusher rule deletes (the grid's third track places the actuator), and scale_root_css gains --h-row. Slice 1's re-derivation was proven byte-identical against the PREVIOUS pin (50410951147178f6, zero re-pin) before this slice moved bytes, so the two changes are separately attested. Behavioral receipts: the row archetype witness (grid-derived template + derived-not-set actuator + planted RED), roadmap_register_keystone, dispatch_presentation_keystone, roadmap_tactile_keystone (press physics unchanged at both scales). This digest only pins bytes; derived by execution from the merged tree." - -data roadmap_css_repin_altitude_note: String = "Re-pinned for composition slice 3 (page altitude): new emission for the section band — the fold summary rules (marker suppressed, pointer), the band strip (surface fill, baseline flex, tokened gap/padding/radius), the in-band h2 margin reset, and the counts chip (mono, dim, tabular). Behavioral receipts: the altitude witness (derivation totality, fold/open by statuses, counts wire, client expand chain with planted REDs), roadmap_page_keystone. Derived by execution; this digest only pins bytes." - -data roadmap_css_repin_anomaly_evidence_note: String = "Re-pinned for composition slice 4 (anomaly evidence is a surface): one new rule — .disclosure-reason, the loud reason's persistent line in the row's disclosure (loud's own hue as the edge mark, tokened lengths, theme ink). Behavioral receipts: the anomaly-evidence witness (surface predicate + title-only RED + styled block pinned verbatim). Derived by execution; this digest only pins bytes." - -data roadmap_css_repin_gutter_split_note: String = "Re-pinned for the operator's pass flips (2026-07-25, signed at the pass on #7234's live page): the row's column gutter splits from the badge-flow gutter — the node-head grid gap moves to space-8 (roadmap_row_column_gutter) while node-mid's flow keeps space-4. One decl's value changes; the row witness's expected head block moved with it (it reds on this change by design). Derived by execution; this digest only pins bytes." - -data roadmap_css_repin_sessions_note: String = "Re-pinned for U2 (sessions panel v0): one new rule — .observe-refused, the client-inserted loud banner for a refused session observation (loud's own hue as the edge mark, mono, tokened lengths — the disclosure-reason family). Derived by execution on the merged tree; this digest only pins bytes." - -data roadmap_css_repin_attempts_note: String = "Re-pinned for U3 (result surfacing v0): one new rule — .dispatch-attempts, the mono dim attempts line in the row disclosure. Derived by execution; this digest only pins bytes." - -data roadmap_css_repin_stop_note: String = "Re-pinned 2026-07-28 for independent process and cleanup presentation: .process-chip renders running/exited/absent/unobserved pane evidence beside the narrow session-present control; .cleanup-chip renders the separately derived stop/clear/unavailable action, and its disabled arm is explicit. Derived by execution; this digest only pins bytes." - -data roadmap_css_repin_workflow_lamps_note: String = "Re-pinned 2026-07-28 after correcting the workflow-lamp vocabulary: .workflow-controls remains the row archetype's third grid occupant while .workflow-strip and .workflow-lamp render independent Session and Attempt observations. Session means only container presence; process lifecycle is a separate chip. Pending, observed-off, observed-on, and refused each have explicit flat presentation; the compact-width realization moves the same wrapper across the second row so the actuator cluster does not overflow. Behavioral receipts: workflow_lamps_witness_test (including both symmetric refusal REDs and compact-layout receipt), sessions_panel_witness_test, dispatch_stop_witness_test, and roadmap_row_witness_test. Derived by execution; this digest only pins bytes." - -data roadmap_css_repin_workflow_progress_note: String = "Re-pinned 2026-07-27 for modeled dispatch progress: each dispatched row gains seven ordered, evidence-projected obligations (environment, workspace, agent, verification, publication, review, goal audit), with explicit pending, active, complete, failed, and refused presentations plus a provider-activity line. The stages are not a second stored workflow state: roadmap_workflow_progress derives observed facts from admission, attempt-state publication, provider JSONL, retained process exit, and future independent verification/publication/review/audit receipts, then reconciles them against the shared desired roster through workflow_reconcile. Behavioral receipts: roadmap_workflow_progress_keystone_holds, workflow_reconcile_keystone_holds, the workflow route witness, and the page client/markup witnesses. Derived by execution; this digest only pins bytes." - -data roadmap_css_repin_lifecycle_truth_note: String = "Re-pinned 2026-07-27 for dispatch lifecycle truth: the stylesheet changes only because the dispatch button's already-modeled reserved width is re-derived from the new truthful caption set (`dispatch · accepted` and `session · present`) instead of provider process-result words. The observation polling itself is client behavior and adds no CSS rule. Behavioral receipts: provider_lifecycle_witness_test, sessions_panel_witness_test, dispatch_presentation_keystone, and roadmap_tactile_keystone. Derived by execution from this tree; this digest only pins bytes." - -data roadmap_css_repin_a1_presentation_note: String = "Re-pinned 2026-08-01 for A1 of the presentation recon (damage removal, operator-signed): the roadmap bytes move intentionally — the .mark rule is deleted with the header's unselected site mark (replaced by the .wordmark rule), the thirteen retired gate/brick rules delete (.three-gate-progress ×2, .gate-row/.gate-head/.gate-name/.gate-count/.gate-bar, .bar-fill, ul.bricks, li.brick, .brick-state ×3 — discharging the 2026-07-28 finish-line stylesheet-debt scaffold, whose dissolve-on was exactly this styling pass in a seed-building environment), the .finish-line-* family lands on the tokened grain, the compact .program-progress-* family lands for the daily workspace, .item-facts and .dependencies land for the A1 row reduction, the page-stack rhythm rule replaces the per-section .roadmap-section / dashboard-instance bottom margins, the unreachable '.node-superseded > .title' child combinator becomes the reachable descendant selector, and scale_root_css loses the four tokens whose last consumers were the deleted rules (h-mark, h-bar, radius-5, w-brick-state). Behavioral receipts: the A1 witnesses in test.claim.long.roadmap_page_witness (header pins, daily-leads-operational, supporting-facts-in-disclosure, finish-line variant fixtures), witness_header_carries_wordmark, and the tactile/frontier header amendments. Derived by execution from this tree (roadmap_css_derived_digest run 2026-08-01); this digest only pins bytes." - -data roadmap_css_repin_a2_activity_note: String = "Re-pinned 2026-08-01 for the A2 presentation seam: the roadmap bytes move intentionally — the workflow lamp/strip/stage-chip rule family is DELETED with its DOM (the mechanism dissolved into the decided ActivityView), replaced by the under-head activity-region rules (.node-activity container with the loud-border anomaly variant, .activity-summary, the ledger/evidence/located-reason rows painting obligation state by text color from the same band vocabulary the chips used) and the .session-facts disclosure line that re-homes the former process-chip content; the dead .process-chip rule is deleted with it. Behavioral receipts: roadmap_register_keystone (censuses — every new rule is role-routed or band-var, every length tokened), the roadmap_presentation witnesses (the decided view the styles materialize), and the A1-carried moodboard/accent digests below did not move (the change is roadmap-scoped). This digest only pins bytes; derived by execution, never chosen." - -data roadmap_css_repin_a2_workspace_note: String = "Re-pinned 2026-08-01 for the A2 blocker rework (operator blocker 6, composed workspace): three additions — .workspace-observation with its summary/reason spans (the ONE workspace-level banner for a refused workflow observation channel, loud-border mono in the disclosure-reason family), and the .frontier-active > h2 in-progress ink for the active band that now surfaces above the ready queue. Behavioral receipts: witness_workspace_impact_narrates_once and witness_daily_workspace_surfaces_active_above_ready in test.claim.roadmap_presentation_witness, plus the daily-workspace markup witnesses. Moodboard/accent digests below stay unmoved (roadmap-scoped change). This digest only pins bytes; derived by execution (roadmap_css_derived_digest run 2026-08-01), never chosen." - -data roadmap_css_repin_a3_family_collapse_note: String = "Re-pinned 2026-08-01 for A3 (family-once grouping + routine-state collapse): the roadmap bytes move intentionally — the family group rules land (.family-group/.family-head/.family-claim/.family-count, tokened, role-routed), and each head cell gains an explicit grid-column DERIVED from the archetype's HeadTrack order (roadmap_row_head_column — needed because the open chip no longer renders, so implicit auto-placement would slide the title into the chip track; the new .node-head > .status rule carries the chip's derived column). Behavioral receipts: the family witnesses and witness_lifecycle_chip_only_when_discriminating in test.claim.roadmap_presentation_witness, roadmap_row_head_columns_derive_from_archetype in test.claim.roadmap_row_witness. Moodboard/accent digests below stay unmoved. This digest only pins bytes; derived by execution (roadmap_css_derived_digest run 2026-08-01), never chosen." - -data roadmap_css_repin_a2_hierarchy_note: String = "Re-pinned 2026-08-02 for the A2 hierarchy closeout (operator gap ruling), and again the same day for the S0 amendments (operator recalibration): the action-prominence pair (.dispatch-btn.action-primary/.action-secondary resting quiet on surface/border/text-dim, .dispatch-btn.action-focal — renamed from action-live, which nicknamed liveness — restoring the family's rest band via its derived vars), emitted BEFORE the state-family paints so a status class always outvotes prominence at equal specificity; the li.node:focus-visible outline (keyboard selection parity — rows are focusable and keyboard focus is visible on the register's focus token); and .header-inner, the header's content frame on the same measure_page/auto-margin tokens as the content columns (header_composition_frame_note). Behavioral receipts: the axis pins in test.claim.long.roadmap_page_witness (ready renders action-primary/available, review and out-of-order render action-secondary/override). This digest only pins bytes; derived by execution (roadmap_css_derived_digest run 2026-08-02), never chosen." - -data lift_parity_merge_resolution_note: String = "MERGE RESOLUTION, RE-DERIVED NOT RECONCILED (S1 x A2-hierarchy, 2026-08-03). Both branches edited this row block and each moved a DIFFERENT digest: #7701 (A2 hierarchy closeout) moved roadmap_css because it changed the stylesheet, and S1 moved moodboard_thesis_themes because it revised register_thesis. Neither touched the other's surface, so the semantic union is the resolution and no value is a compromise between two claims. The union was nonetheless not TRUSTED: both digests were re-run by execution on the merged tree, because a digest pins emitted bytes and a merge is the one moment when the bytes belong to a tree neither side ever built — picking a side by reasoning about scope is exactly the copied-measurement-as-oracle failure this file's own repin notes disclaim ('derived by execution, never chosen'). The re-run is the oracle; the reasoning above only explains why the re-run was expected to agree." - -data roadmap_css_repin_fleet_hardware_axis_width_note: String = "Re-pinned again 2026-08-23 for review 55065: .hardware-axis was taking hardware_subject_reserved_width — copied from the column beside it — so a column carrying the axis words memory and processor was reserved to the width of the longest HOST LABEL (6ch). It now takes hardware_axis_reserved_width, derived from a single hardware_axis_labels authority that the rendered rows read too, and emits 11ch. Behavioral receipt: each_column_reserves_its_own_population, which asserts the two reservations DIFFER and that the subject population cannot hold the axis one — the discriminating fact, since a witness merely re-deriving the axis width from the axis labels would be measure() == measure(). Derived by execution (roadmap_css_derived_digest run 2026-08-23), never chosen." - -data roadmap_css_repin_fleet_hardware_standing_note: String = "Re-pinned 2026-08-23 for the daily-workspace fleet hardware standing panel (operator request: live fleet info on the workspace): the roadmap bytes move intentionally — the .fleet-hardware-standing family lands (panel surface, .hardware-heading, .hardware-summary, .hardware-outstanding, .hardware-row, .hardware-subject, .hardware-axis, .hardware-cell and the four standing variants .hardware-confirmed / .hardware-refused / .hardware-misfiled / .hardware-unread, plus .hardware-detail), all role-routed and tokened. The two column reservations are NOT pixels: .hardware-subject/.hardware-axis and .hardware-cell take min-width from gunbc.fleet_hardware_standing_panel hardware_subject_reserved_width and hardware_standing_reserved_width, which derive the longest label each column can wear plus a gutter — emitted as 6ch and 11ch, the latter being the width of 'confirmed', the longest of the four standing words. The refused and misfiled variants reuse the EXISTING var(--band-loud) refused-state vocabulary rather than minting a role: an earlier revision of this change wrote role_decl(r: SalienceRole), which compiled clean and then failed evaluation with NoSuchVariable — SalienceRole is a type in gunbc.design.salience, not a theme role role_decl can take — and it was caught only by serializing the whole page, not by any panel-level witness. Behavioral receipts: test.claim.fleet_hardware_standing_panel_witness_test — every processor row is unread and none confirmed, the memory axis is confirmed on every host as the positive control, the four verdict shapes map to four distinct standings, the summary reports each axis separately and never one fraction, and no outstanding line renders while nothing contradicts. Derived by execution from this tree (roadmap_css_derived_digest run 2026-08-23); this digest only pins bytes, never chosen." - -data roadmap_css_consolidation_repin_note: String = "RE-DERIVED, NOT RECONCILED (consolidation of eight branches, 2026-08-23). The hardware-standing panel and the capacity panel were authored on separate branches and each re-pinned this digest against a stylesheet containing its own rules and not the other's. Neither prior value describes the merged stylesheet, so taking either side would have pinned a digest no emission produces. The value below was obtained by running roadmap_css_derived_digest against the merged tree - the same function the witness compares - and is therefore a measurement of this stylesheet rather than a transcription from either parent." - -data roadmap_css_repin_capacity_held_width_note: String = "Re-pinned 2026-08-27 for the host-keyed session reservation: the roadmap bytes move intentionally, and they move for a DERIVED reason rather than a stylesheet edit. No CSS rule was added, removed or retyped. .capacity-metric takes its min-width from gunbc.fleet_capacity_panel capacity_metric_reserved_width, which reserves the longest label that column can wear; the fleet capacity panel's binding-axis label changed, so the reservation changed, so the emitted length changed. That is the projection discipline working exactly as roadmap_css_repin_fleet_capacity_panel_note describes it -- a longer binding-axis phrase moves the reservation by derivation and there is no pixel to maintain -- and this re-pin is the receipt that it did. WHY THE LABEL CHANGED: srv2's memory admission was computed by subtracting a session reservation that is UNESTABLISHED on that host, so its AxisAdmits { memory, 5 } was never a measured bound. With the axis honestly AxisUnmeasured, NO axis sits at srv2's committed width, and host_width_binding_label -- which joined a constant 'bound by ' prefix onto the binding set -- rendered 'bound by ' followed by nothing onto the operator's panel. It now names three states whose remedies differ: an axis binds, the width is HELD (re-ground the denominator; no purchase helps), or nothing binds and nothing is held. srv2 reads 'width held, no axis binds · memory+disk unmeasured'. Behavioral receipts: test.claim.fleet_capacity_panel_witness_test srv1_is_axis_bound_while_srv2_is_held and the_panel_renders_a_width_provenance_for_every_host, whose final negative control is 'bound by' with two trailing spaces -- a string ONLY an empty binding set can produce, so it reds on exactly this regression. Measured alongside: srv3 and srv4 are core-bound, so srv2 was the fleet's only memory-bound host and 'bound by memory' now appears nowhere in the rendered page; the conjunct asserting it was unsatisfiable rather than stale, which is why that witness was restated and not retuned. Derived by execution from this tree (roadmap_css_derived_digest run 2026-08-27); this digest only pins bytes, never chosen." +// Re-pinned across the UI-model migration and the #7104 (SupersededLine) merge. P2 (token +// migration, px/font -> gunbc.design.scale var tokens) was proven visually-neutral by execution: +// resolving every var(--scale-token) reproduced the pre-P2 CSS byte-for-byte. P3 (presentation +// mapping) then INTENTIONALLY adds styling: the dispatch button's reserved min-width (derived from +// the longest wire label, in ch) and the ok/refusal/requested chip material rules (each painting +// the P0 state's role). D5 (typed CSS grain) is a pure re-grounding — property names and selector +// subjects become typed, bytes unchanged. The #7104 merge folds in the .status-superseded / +// .node-superseded / .superseded-by rules, RE-GROUNDED here onto the same typed+tokenized grain +// (their raw 11px/6px/font-family literals routed through the scale tokens so the untokened-length +// census stays green), which shifts the bytes off main's hardcoded emission — hence this digest +// re-pin. The behavioral receipts (roadmap_register_keystone, dispatch_presentation_keystone) and +// the untokened-length census remain the substance; this digest only pins bytes. Re-pinned again +// for #7169 (roadmap workspace UX): roadmap_style gained centered .roadmap/.daily-workspace auto +// side margins and related layout rules — bytes shift, behavioral receipts +// (roadmap_register_keystone, dispatch_presentation_keystone) unchanged. + +// The roadmap's own bytes move for a second, intentional reason beyond the carrier restructure: the +// dashboard gained physical motion. Hover lift, press depression, the latched requested position, +// the settle spring, the sound toggle's rules and the reduced-motion collapse over all of them are +// new emission. The behavioural receipts are roadmap_tactile_keystone_holds (which walls the +// mechanics with planted REDs) and roadmap_register_keystone_holds; this digest only pins bytes. + +// Re-pinned 2026-07-24 (remodel W1c/W1d/W1g): the roadmap bytes move intentionally — the band var +// family (band_root_css: instrument fills under the same :root/[data-theme]/media grammar the theme +// vars use), the dispatch state rules re-painted from role borders to band fill/ink vars, the +// dispatch-loud rule, and the theme-toggle control's rule. Behavioral receipts: +// roadmap_register_keystone (census + both-ways archetype demand, BoundaryRole demand dissolved +// with its stylesheet consumer), dispatch_presentation_keystone (band-paint blocks + +// caption-projection width), roadmap_tactile_keystone (mechanics unchanged). This digest only pins +// bytes. + +// Merge resolution 2026-07-25 (main into the remodel branch). Both parents re-pinned this row off +// the same base value 947686b5dbaab2b0 for disjoint reasons: main via #7193 (namespace-flip +// emission drift, reaching roadmap_css through std.markup rather than through any design/ or +// roadmap_*/ file — none of those changed on main since the branch point), the branch via remodel +// W1 (band var family, dispatch rules re-painted from role borders to band fill/ink). The merged +// value is DERIVED, never chosen: roadmap_css() was emitted from the merged worktree and its +// content_hash_atom read off. Three-point control, all run against the same binary: origin/main +// emits d788728c4745ba48 (reproduces main's pin), the pre-merge branch tip d1d2fd954 emits +// 50410951147178f6 (reproduces the branch's pin), the merged tree emits 50410951147178f6. The +// merged value coinciding with the branch's is a real result, not a dropped merge: main's +// std.markup drift reaches an emission region the branch's W1 rewrite replaces, so the branch's +// bytes supersede it — and merge faithfulness is a separate receipt (of the 327 paths main touched +// since the base, 324 are byte-identical to main in the merged tree and 3 are the co-edited files, +// zero unexplained). Resolving this conflict by keeping either side's literal would have pinned +// bytes no tree emits. + +// Re-pinned for composition slice 2 (the RoadmapRow archetype): the roadmap bytes move +// intentionally — the node-head flex rules become the archetype-derived grid (template from +// roadmap_row_grid_template, density on h-row and the row gutter), the node-mid cell rule and the +// chip-scale row actuator override are new emission, the margin-left:auto pusher rule deletes (the +// grid's third track places the actuator), and scale_root_css gains --h-row. Slice 1's +// re-derivation was proven byte-identical against the PREVIOUS pin (50410951147178f6, zero re-pin) +// before this slice moved bytes, so the two changes are separately attested. Behavioral receipts: +// the row archetype witness (grid-derived template + derived-not-set actuator + planted RED), +// roadmap_register_keystone, dispatch_presentation_keystone, roadmap_tactile_keystone (press +// physics unchanged at both scales). This digest only pins bytes; derived by execution from the +// merged tree. + +// Re-pinned for composition slice 3 (page altitude): new emission for the section band — the fold +// summary rules (marker suppressed, pointer), the band strip (surface fill, baseline flex, tokened +// gap/padding/radius), the in-band h2 margin reset, and the counts chip (mono, dim, tabular). +// Behavioral receipts: the altitude witness (derivation totality, fold/open by statuses, counts +// wire, client expand chain with planted REDs), roadmap_page_keystone. Derived by execution; this +// digest only pins bytes. + +// Re-pinned for composition slice 4 (anomaly evidence is a surface): one new rule — +// .disclosure-reason, the loud reason's persistent line in the row's disclosure (loud's own hue as +// the edge mark, tokened lengths, theme ink). Behavioral receipts: the anomaly-evidence witness +// (surface predicate + title-only RED + styled block pinned verbatim). Derived by execution; this +// digest only pins bytes. + +// Re-pinned for the operator's pass flips (2026-07-25, signed at the pass on #7234's live page): +// the row's column gutter splits from the badge-flow gutter — the node-head grid gap moves to +// space-8 (roadmap_row_column_gutter) while node-mid's flow keeps space-4. One decl's value +// changes; the row witness's expected head block moved with it (it reds on this change by design). +// Derived by execution; this digest only pins bytes. + +// Re-pinned for U2 (sessions panel v0): one new rule — .observe-refused, the client-inserted loud +// banner for a refused session observation (loud's own hue as the edge mark, mono, tokened lengths +// — the disclosure-reason family). Derived by execution on the merged tree; this digest only pins +// bytes. + +// Re-pinned for U3 (result surfacing v0): one new rule — .dispatch-attempts, the mono dim attempts +// line in the row disclosure. Derived by execution; this digest only pins bytes. + +// Re-pinned 2026-07-28 for independent process and cleanup presentation: .process-chip renders +// running/exited/absent/unobserved pane evidence beside the narrow session-present control; +// .cleanup-chip renders the separately derived stop/clear/unavailable action, and its disabled arm +// is explicit. Derived by execution; this digest only pins bytes. + +// Re-pinned 2026-07-28 after correcting the workflow-lamp vocabulary: .workflow-controls remains +// the row archetype's third grid occupant while .workflow-strip and .workflow-lamp render +// independent Session and Attempt observations. Session means only container presence; process +// lifecycle is a separate chip. Pending, observed-off, observed-on, and refused each have explicit +// flat presentation; the compact-width realization moves the same wrapper across the second row so +// the actuator cluster does not overflow. Behavioral receipts: workflow_lamps_witness_test +// (including both symmetric refusal REDs and compact-layout receipt), sessions_panel_witness_test, +// dispatch_stop_witness_test, and roadmap_row_witness_test. Derived by execution; this digest only +// pins bytes. + +// Re-pinned 2026-07-27 for modeled dispatch progress: each dispatched row gains seven ordered, +// evidence-projected obligations (environment, workspace, agent, verification, publication, review, +// goal audit), with explicit pending, active, complete, failed, and refused presentations plus a +// provider-activity line. The stages are not a second stored workflow state: +// roadmap_workflow_progress derives observed facts from admission, attempt-state publication, +// provider JSONL, retained process exit, and future independent +// verification/publication/review/audit receipts, then reconciles them against the shared desired +// roster through workflow_reconcile. Behavioral receipts: roadmap_workflow_progress_keystone_holds, +// workflow_reconcile_keystone_holds, the workflow route witness, and the page client/markup +// witnesses. Derived by execution; this digest only pins bytes. + +// Re-pinned 2026-07-27 for dispatch lifecycle truth: the stylesheet changes only because the +// dispatch button's already-modeled reserved width is re-derived from the new truthful caption set +// (`dispatch · accepted` and `session · present`) instead of provider process-result words. The +// observation polling itself is client behavior and adds no CSS rule. Behavioral receipts: +// provider_lifecycle_witness_test, sessions_panel_witness_test, dispatch_presentation_keystone, and +// roadmap_tactile_keystone. Derived by execution from this tree; this digest only pins bytes. + +// Re-pinned 2026-08-01 for A1 of the presentation recon (damage removal, operator-signed): the +// roadmap bytes move intentionally — the .mark rule is deleted with the header's unselected site +// mark (replaced by the .wordmark rule), the thirteen retired gate/brick rules delete +// (.three-gate-progress ×2, .gate-row/.gate-head/.gate-name/.gate-count/.gate-bar, .bar-fill, +// ul.bricks, li.brick, .brick-state ×3 — discharging the 2026-07-28 finish-line stylesheet-debt +// scaffold, whose dissolve-on was exactly this styling pass in a seed-building environment), the +// .finish-line-* family lands on the tokened grain, the compact .program-progress-* family lands +// for the daily workspace, .item-facts and .dependencies land for the A1 row reduction, the +// page-stack rhythm rule replaces the per-section .roadmap-section / dashboard-instance bottom +// margins, the unreachable '.node-superseded > .title' child combinator becomes the reachable +// descendant selector, and scale_root_css loses the four tokens whose last consumers were the +// deleted rules (h-mark, h-bar, radius-5, w-brick-state). Behavioral receipts: the A1 witnesses in +// test.claim.long.roadmap_page_witness (header pins, daily-leads-operational, +// supporting-facts-in-disclosure, finish-line variant fixtures), witness_header_carries_wordmark, +// and the tactile/frontier header amendments. Derived by execution from this tree +// (roadmap_css_derived_digest run 2026-08-01); this digest only pins bytes. + +// Re-pinned 2026-08-01 for the A2 presentation seam: the roadmap bytes move intentionally — the +// workflow lamp/strip/stage-chip rule family is DELETED with its DOM (the mechanism dissolved into +// the decided ActivityView), replaced by the under-head activity-region rules (.node-activity +// container with the loud-border anomaly variant, .activity-summary, the +// ledger/evidence/located-reason rows painting obligation state by text color from the same band +// vocabulary the chips used) and the .session-facts disclosure line that re-homes the former +// process-chip content; the dead .process-chip rule is deleted with it. Behavioral receipts: +// roadmap_register_keystone (censuses — every new rule is role-routed or band-var, every length +// tokened), the roadmap_presentation witnesses (the decided view the styles materialize), and the +// A1-carried moodboard/accent digests below did not move (the change is roadmap-scoped). This +// digest only pins bytes; derived by execution, never chosen. + +// Re-pinned 2026-08-01 for the A2 blocker rework (operator blocker 6, composed workspace): three +// additions — .workspace-observation with its summary/reason spans (the ONE workspace-level banner +// for a refused workflow observation channel, loud-border mono in the disclosure-reason family), +// and the .frontier-active > h2 in-progress ink for the active band that now surfaces above the +// ready queue. Behavioral receipts: witness_workspace_impact_narrates_once and +// witness_daily_workspace_surfaces_active_above_ready in test.claim.roadmap_presentation_witness, +// plus the daily-workspace markup witnesses. Moodboard/accent digests below stay unmoved +// (roadmap-scoped change). This digest only pins bytes; derived by execution +// (roadmap_css_derived_digest run 2026-08-01), never chosen. + +// Re-pinned 2026-08-01 for A3 (family-once grouping + routine-state collapse): the roadmap bytes +// move intentionally — the family group rules land +// (.family-group/.family-head/.family-claim/.family-count, tokened, role-routed), and each head +// cell gains an explicit grid-column DERIVED from the archetype's HeadTrack order +// (roadmap_row_head_column — needed because the open chip no longer renders, so implicit +// auto-placement would slide the title into the chip track; the new .node-head > .status rule +// carries the chip's derived column). Behavioral receipts: the family witnesses and +// witness_lifecycle_chip_only_when_discriminating in test.claim.roadmap_presentation_witness, +// roadmap_row_head_columns_derive_from_archetype in test.claim.roadmap_row_witness. +// Moodboard/accent digests below stay unmoved. This digest only pins bytes; derived by execution +// (roadmap_css_derived_digest run 2026-08-01), never chosen. + +// Re-pinned 2026-08-02 for the A2 hierarchy closeout (operator gap ruling), and again the same day +// for the S0 amendments (operator recalibration): the action-prominence pair +// (.dispatch-btn.action-primary/.action-secondary resting quiet on surface/border/text-dim, +// .dispatch-btn.action-focal — renamed from action-live, which nicknamed liveness — restoring the +// family's rest band via its derived vars), emitted BEFORE the state-family paints so a status +// class always outvotes prominence at equal specificity; the li.node:focus-visible outline +// (keyboard selection parity — rows are focusable and keyboard focus is visible on the register's +// focus token); and .header-inner, the header's content frame on the same measure_page/auto-margin +// tokens as the content columns (header_composition_frame_note). Behavioral receipts: the axis pins +// in test.claim.long.roadmap_page_witness (ready renders action-primary/available, review and +// out-of-order render action-secondary/override). This digest only pins bytes; derived by execution +// (roadmap_css_derived_digest run 2026-08-02), never chosen. + +// MERGE RESOLUTION, RE-DERIVED NOT RECONCILED (S1 x A2-hierarchy, 2026-08-03). Both branches edited +// this row block and each moved a DIFFERENT digest: #7701 (A2 hierarchy closeout) moved roadmap_css +// because it changed the stylesheet, and S1 moved moodboard_thesis_themes because it revised +// register_thesis. Neither touched the other's surface, so the semantic union is the resolution and +// no value is a compromise between two claims. The union was nonetheless not TRUSTED: both digests +// were re-run by execution on the merged tree, because a digest pins emitted bytes and a merge is +// the one moment when the bytes belong to a tree neither side ever built — picking a side by +// reasoning about scope is exactly the copied-measurement-as-oracle failure this file's own repin +// notes disclaim ('derived by execution, never chosen'). The re-run is the oracle; the reasoning +// above only explains why the re-run was expected to agree. + +// Re-pinned again 2026-08-23 for review 55065: .hardware-axis was taking +// hardware_subject_reserved_width — copied from the column beside it — so a column carrying the +// axis words memory and processor was reserved to the width of the longest HOST LABEL (6ch). It now +// takes hardware_axis_reserved_width, derived from a single hardware_axis_labels authority that the +// rendered rows read too, and emits 11ch. Behavioral receipt: +// each_column_reserves_its_own_population, which asserts the two reservations DIFFER and that the +// subject population cannot hold the axis one — the discriminating fact, since a witness merely +// re-deriving the axis width from the axis labels would be measure() == measure(). Derived by +// execution (roadmap_css_derived_digest run 2026-08-23), never chosen. + +// Re-pinned 2026-08-23 for the daily-workspace fleet hardware standing panel (operator request: +// live fleet info on the workspace): the roadmap bytes move intentionally — the +// .fleet-hardware-standing family lands (panel surface, .hardware-heading, .hardware-summary, +// .hardware-outstanding, .hardware-row, .hardware-subject, .hardware-axis, .hardware-cell and the +// four standing variants .hardware-confirmed / .hardware-refused / .hardware-misfiled / +// .hardware-unread, plus .hardware-detail), all role-routed and tokened. The two column +// reservations are NOT pixels: .hardware-subject/.hardware-axis and .hardware-cell take min-width +// from gunbc.fleet_hardware_standing_panel hardware_subject_reserved_width and +// hardware_standing_reserved_width, which derive the longest label each column can wear plus a +// gutter — emitted as 6ch and 11ch, the latter being the width of 'confirmed', the longest of the +// four standing words. The refused and misfiled variants reuse the EXISTING var(--band-loud) +// refused-state vocabulary rather than minting a role: an earlier revision of this change wrote +// role_decl(r: SalienceRole), which compiled clean and then failed evaluation with NoSuchVariable — +// SalienceRole is a type in gunbc.design.salience, not a theme role role_decl can take — and it was +// caught only by serializing the whole page, not by any panel-level witness. Behavioral receipts: +// test.claim.fleet_hardware_standing_panel_witness_test — every processor row is unread and none +// confirmed, the memory axis is confirmed on every host as the positive control, the four verdict +// shapes map to four distinct standings, the summary reports each axis separately and never one +// fraction, and no outstanding line renders while nothing contradicts. Derived by execution from +// this tree (roadmap_css_derived_digest run 2026-08-23); this digest only pins bytes, never chosen. + +// RE-DERIVED, NOT RECONCILED (consolidation of eight branches, 2026-08-23). The hardware-standing +// panel and the capacity panel were authored on separate branches and each re-pinned this digest +// against a stylesheet containing its own rules and not the other's. Neither prior value describes +// the merged stylesheet, so taking either side would have pinned a digest no emission produces. The +// value below was obtained by running roadmap_css_derived_digest against the merged tree - the same +// function the witness compares - and is therefore a measurement of this stylesheet rather than a +// transcription from either parent. + +// Re-pinned 2026-08-27 for the host-keyed session reservation: the roadmap bytes move +// intentionally, and they move for a DERIVED reason rather than a stylesheet edit. No CSS rule was +// added, removed or retyped. .capacity-metric takes its min-width from gunbc.fleet_capacity_panel +// capacity_metric_reserved_width, which reserves the longest label that column can wear; the fleet +// capacity panel's binding-axis label changed, so the reservation changed, so the emitted length +// changed. That is the projection discipline working exactly as +// roadmap_css_repin_fleet_capacity_panel_note describes it -- a longer binding-axis phrase moves +// the reservation by derivation and there is no pixel to maintain -- and this re-pin is the receipt +// that it did. WHY THE LABEL CHANGED: srv2's memory admission was computed by subtracting a session +// reservation that is UNESTABLISHED on that host, so its AxisAdmits { memory, 5 } was never a +// measured bound. With the axis honestly AxisUnmeasured, NO axis sits at srv2's committed width, +// and host_width_binding_label -- which joined a constant 'bound by ' prefix onto the binding set +// -- rendered 'bound by ' followed by nothing onto the operator's panel. It now names three states +// whose remedies differ: an axis binds, the width is HELD (re-ground the denominator; no purchase +// helps), or nothing binds and nothing is held. srv2 reads 'width held, no axis binds · memory+disk +// unmeasured'. Behavioral receipts: test.claim.fleet_capacity_panel_witness_test +// srv1_is_axis_bound_while_srv2_is_held and the_panel_renders_a_width_provenance_for_every_host, +// whose final negative control is 'bound by' with two trailing spaces -- a string ONLY an empty +// binding set can produce, so it reds on exactly this regression. Measured alongside: srv3 and srv4 +// are core-bound, so srv2 was the fleet's only memory-bound host and 'bound by memory' now appears +// nowhere in the rendered page; the conjunct asserting it was unsatisfiable rather than stale, +// which is why that witness was restated and not retuned. Derived by execution from this tree +// (roadmap_css_derived_digest run 2026-08-27); this digest only pins bytes, never chosen. data roadmap_css_lift_parity_digest: String = "62e20cacdf06f99f" -data roadmap_css_repin_fleet_capacity_panel_note: String = "Re-pinned 2026-08-23 for the daily-workspace fleet capacity panel (operator request: live fleet info on the workspace): the roadmap bytes move intentionally — the .fleet-capacity-panel family lands (panel surface, .capacity-title, .capacity-summary, .capacity-row with its active/withdrawn variants, .capacity-subject, .capacity-metric, .capacity-standing, .capacity-withdrawn-total, .capacity-declared-note), all role-routed and tokened. The two column reservations are NOT pixels: .capacity-subject and .capacity-metric take min-width from gunbc.fleet_capacity_panel capacity_subject_reserved_width and capacity_metric_reserved_width, which derive the longest label each column can wear plus a gutter — the same projection discipline roadmap_component dispatch_reserved_width uses, so a new host or a longer binding-axis phrase moves the reservation by derivation. An earlier revision of this change wrote raw 5rem/9rem, which would have been the only untokened lengths in the stylesheet. Behavioral receipts: test.claim.fleet_capacity_panel_witness_test — the panel reaches the serialized daily workspace, its widths are labelled committed rather than observed, the slot total sums the allocation authority as a relation, an unmeasured axis is not reported as binding, and the withdrawn line is absent when nothing is withdrawn. Derived by execution from this tree (roadmap_css_derived_digest run 2026-08-23); this digest only pins bytes, never chosen." +// Re-pinned 2026-08-23 for the daily-workspace fleet capacity panel (operator request: live fleet +// info on the workspace): the roadmap bytes move intentionally — the .fleet-capacity-panel family +// lands (panel surface, .capacity-title, .capacity-summary, .capacity-row with its active/withdrawn +// variants, .capacity-subject, .capacity-metric, .capacity-standing, .capacity-withdrawn-total, +// .capacity-declared-note), all role-routed and tokened. The two column reservations are NOT +// pixels: .capacity-subject and .capacity-metric take min-width from gunbc.fleet_capacity_panel +// capacity_subject_reserved_width and capacity_metric_reserved_width, which derive the longest +// label each column can wear plus a gutter — the same projection discipline roadmap_component +// dispatch_reserved_width uses, so a new host or a longer binding-axis phrase moves the reservation +// by derivation. An earlier revision of this change wrote raw 5rem/9rem, which would have been the +// only untokened lengths in the stylesheet. Behavioral receipts: +// test.claim.fleet_capacity_panel_witness_test — the panel reaches the serialized daily workspace, +// its widths are labelled committed rather than observed, the slot total sums the allocation +// authority as a relation, an unmeasured axis is not reported as binding, and the withdrawn line is +// absent when nothing is withdrawn. Derived by execution from this tree (roadmap_css_derived_digest +// run 2026-08-23); this digest only pins bytes, never chosen. data moodboard_thesis_themes_lift_parity_digest: String = "98f0513aebb0dcb3" diff --git a/dag/test/claim/devboot_subject_identity_witness_test.dag b/dag/test/claim/devboot_subject_identity_witness_test.dag index 2c673957734..a03d898344d 100644 --- a/dag/test/claim/devboot_subject_identity_witness_test.dag +++ b/dag/test/claim/devboot_subject_identity_witness_test.dag @@ -96,7 +96,15 @@ import gunbc.devboot.outcome { ReuseUnavailable, } -data witness_grounding_doc: String = "The tree object ids below are REAL, read out of this repository during the DEVBOOT re-observation rather than invented to look plausible. clean_tree_hex is `git write-tree` over a temp index holding HEAD's content and equals the tree HEAD points at; parent_tree_hex is the tree of HEAD~1; dirty_tree_hex is the same index with one untracked file staged. blob_hex and pack_sha256_hex are the object id and content digest of an actual downloaded release pack.\\n\\nUsing measured values matters here beyond tidiness: the claim under test is that this identity scheme distinguishes and collapses the RIGHT things, and a fixture invented to satisfy it could not have falsified it. These three trees really do stand in the relations the tests assert -- same content same id, different content different id." +// The tree object ids below are REAL, read out of this repository during the DEVBOOT re-observation +// rather than invented to look plausible. clean_tree_hex is `git write-tree` over a temp index +// holding HEAD's content and equals the tree HEAD points at; parent_tree_hex is the tree of HEAD~1; +// dirty_tree_hex is the same index with one untracked file staged. blob_hex and pack_sha256_hex are +// the object id and content digest of an actual downloaded release pack.\n\nUsing measured values +// matters here beyond tidiness: the claim under test is that this identity scheme distinguishes and +// collapses the RIGHT things, and a fixture invented to satisfy it could not have falsified it. +// These three trees really do stand in the relations the tests assert -- same content same id, +// different content different id. data clean_tree_hex: String = "4a712980497e1d0a45374185b2184a094cca4c8f" data parent_tree_hex: String = "96817c95aa43c3aead837ca3a8f37d77f6fc2d61" @@ -121,7 +129,9 @@ fn witness_oid(hex: String) -> GitObjectId? { git_object_id_from_untagged_hex(hex: hex) } -data witness_subject_builder_doc: String = "One builder every row goes through, so a test that means to vary ONE axis cannot accidentally vary another. Each parameter is an axis of the subject identity, and the defaults are the same on both sides of every comparison below." +// One builder every row goes through, so a test that means to vary ONE axis cannot accidentally +// vary another. Each parameter is an axis of the subject identity, and the defaults are the same on +// both sides of every comparison below. fn witness_subject_full( tree_hex: String, @@ -174,7 +184,19 @@ fn witness_subject_digest(tree_hex: String, gnu_abi: Bool, features: List Bool { } } -data comparison_control_doc: String = "THE CONTROL THAT PROVES THE FIX IS REAL. An unconstructable subject must satisfy neither polarity -- not equal AND not different -- which is exactly what the broken two-valued helper could not express. If this row ever goes red, the three-valued comparison has collapsed back into a boolean and every negative test above has quietly stopped discriminating." +// THE CONTROL THAT PROVES THE FIX IS REAL. An unconstructable subject must satisfy neither polarity +// -- not equal AND not different -- which is exactly what the broken two-valued helper could not +// express. If this row ever goes red, the three-valued comparison has collapsed back into a boolean +// and every negative test above has quietly stopped discriminating. test fn an_unconstructable_digest_satisfies_neither_polarity() -> Bool { let broken = witness_subject_digest(tree_hex: "not-a-valid-object-id", gnu_abi: true, features: []) @@ -241,7 +266,11 @@ test fn different_trees_never_collide() -> Bool { ) } -data abi_false_share_red_doc: String = "THE DISCRIMINATING RED FOR THE FALSE-SHARE CLASS. Gnu and Musl builds of one tree differ in exactly the property that decides whether the artifact runs on a given host, and a subject key blind to the ABI axis would report them as one subject -- handing a requester a binary its libc cannot load while every record claimed a hit. This test goes red the moment the ABI identity tag stops reaching the digest, which is the failure a reviewer cannot see by reading the fold." +// THE DISCRIMINATING RED FOR THE FALSE-SHARE CLASS. Gnu and Musl builds of one tree differ in +// exactly the property that decides whether the artifact runs on a given host, and a subject key +// blind to the ABI axis would report them as one subject -- handing a requester a binary its libc +// cannot load while every record claimed a hit. This test goes red the moment the ABI identity tag +// stops reaching the digest, which is the failure a reviewer cannot see by reading the fold. test fn gnu_and_musl_are_different_subjects() -> Bool { digests_are_different( @@ -257,7 +286,12 @@ test fn features_participate_in_identity() -> Bool { ) } -data product_axis_red_doc: String = "THE RED FOR THE MISSING-PRODUCT CLASS. One tree at one toolchain, target, profile and feature set can still produce entirely different bytes depending on WHICH artifact was asked for -- the CLI binary, another binary, or the library. Before the product axis existed these were one subject, so a request for one could be answered with another's bytes while every modeled axis agreed. Both rows must differ, and they differ on the two distinct ways a product can vary: the target KIND, and the target NAME at one kind." +// THE RED FOR THE MISSING-PRODUCT CLASS. One tree at one toolchain, target, profile and feature set +// can still produce entirely different bytes depending on WHICH artifact was asked for -- the CLI +// binary, another binary, or the library. Before the product axis existed these were one subject, +// so a request for one could be answered with another's bytes while every modeled axis agreed. Both +// rows must differ, and they differ on the two distinct ways a product can vary: the target KIND, +// and the target NAME at one kind. test fn the_product_being_built_participates_in_identity() -> Bool { let cli = witness_subject_full( @@ -304,7 +338,13 @@ fn optional_digest(subject: BuildSubject?) -> ContentHash? { } } -data environment_axis_red_doc: String = "THE RED FOR THE BUILD-ENVIRONMENT CLASS. A codegen flag changes the emitted bytes while leaving source, toolchain, target, profile, features and product all identical, so a key blind to it would serve an optimized artifact against a request that asked for a debuggable one and vice versa -- with every visible axis agreeing.\\n\\nThe second row is the one that would be easy to get wrong: rustc resolves repeated codegen options last-one-wins, so the SAME flags in a different ORDER are genuinely a different build. A digest that folded flags order-insensitively would report these two as one subject." +// THE RED FOR THE BUILD-ENVIRONMENT CLASS. A codegen flag changes the emitted bytes while leaving +// source, toolchain, target, profile, features and product all identical, so a key blind to it +// would serve an optimized artifact against a request that asked for a debuggable one and vice +// versa -- with every visible axis agreeing.\n\nThe second row is the one that would be easy to get +// wrong: rustc resolves repeated codegen options last-one-wins, so the SAME flags in a different +// ORDER are genuinely a different build. A digest that folded flags order-insensitively would +// report these two as one subject. test fn build_environment_participates_in_identity() -> Bool { let bare = witness_subject_full( @@ -406,7 +446,11 @@ test fn empty_feature_name_refuses() -> Bool { } } -data admission_wall_doc: String = "THE ADMISSION IS THE ONLY DOOR, asserted per field rather than assumed from one sample. Each of these strings is non-empty by TYPE inside BuildSubject, so an empty one arriving from a request must be refused at admission or it becomes a cast that asserts what was never checked -- the fabrication class this carrier was reworked to remove. A field that stopped being scanned would show up here and nowhere else." +// THE ADMISSION IS THE ONLY DOOR, asserted per field rather than assumed from one sample. Each of +// these strings is non-empty by TYPE inside BuildSubject, so an empty one arriving from a request +// must be refused at admission or it becomes a cast that asserts what was never checked -- the +// fabrication class this carrier was reworked to remove. A field that stopped being scanned would +// show up here and nowhere else. test fn every_required_string_is_refused_when_empty() -> Bool { empty_profile_refuses() && empty_rustflag_refuses() @@ -495,7 +539,13 @@ fn witness_record(for_subject: BuildSubject) -> StoredArtifactRecord? { } } -data structural_equality_red_doc: String = "THE RULING'S REUSE ORDER, ASSERTED AS BEHAVIOUR. A stored record is offered against a request naming a different tree; it must answer SubjectDiffers and the reuse path must refuse, no matter that bytes were sitting right there and available. This is the 'use what's there' failure the hard stop forbids, and it is the arm a cache is most tempted to take.\\n\\nThe row also pins the ORDER the ruling fixed: the mismatch arm is reached with availability set to Available, so a reuse that consulted only the digest and the bytes would grant here. Only a comparison of the full retrieved subject refuses." +// THE RULING'S REUSE ORDER, ASSERTED AS BEHAVIOUR. A stored record is offered against a request +// naming a different tree; it must answer SubjectDiffers and the reuse path must refuse, no matter +// that bytes were sitting right there and available. This is the 'use what's there' failure the +// hard stop forbids, and it is the arm a cache is most tempted to take.\n\nThe row also pins the +// ORDER the ruling fixed: the mismatch arm is reached with availability set to Available, so a +// reuse that consulted only the digest and the bytes would grant here. Only a comparison of the +// full retrieved subject refuses. test fn a_record_built_for_another_subject_is_refused_even_when_bytes_are_available() -> Bool { match witness_subject(tree_hex: clean_tree_hex, gnu_abi: true, features: []) { @@ -541,7 +591,10 @@ test fn a_record_built_for_the_request_reuses_when_bytes_are_available() -> Bool } } -data reuse_requires_all_three_doc: String = "REUSE NEEDS A CANDIDATE, AN EXACT MATCH, AND PRESENT BYTES -- never two out of three. The matching record with MISSING bytes is the row that matters: every identity check passes, and reuse must still refuse, because the contract law is about retrievability rather than about records. A service that granted here would report success for bytes nobody can fetch." +// REUSE NEEDS A CANDIDATE, AN EXACT MATCH, AND PRESENT BYTES -- never two out of three. The +// matching record with MISSING bytes is the row that matters: every identity check passes, and +// reuse must still refuse, because the contract law is about retrievability rather than about +// records. A service that granted here would report success for bytes nobody can fetch. test fn a_matching_record_without_bytes_does_not_reuse() -> Bool { match witness_subject(tree_hex: clean_tree_hex, gnu_abi: true, features: []) { @@ -568,7 +621,12 @@ test fn a_matching_record_without_bytes_does_not_reuse() -> Bool { } } -data split_axes_doc: String = "THE STATE THE FUSED SUM COULD NOT SAY. Execution Produced with artifact Missing is a real and common situation -- the build ran and succeeded, the bytes were later pruned -- and under a single outcome sum it could only be expressed by overwriting the success, destroying the record that the build had ever run.\\n\\nBoth halves are asserted here: the status is simultaneously a settled Produced execution AND not retrievable. A collapse back into one axis makes one of the two conjuncts unrepresentable and this row goes red." +// THE STATE THE FUSED SUM COULD NOT SAY. Execution Produced with artifact Missing is a real and +// common situation -- the build ran and succeeded, the bytes were later pruned -- and under a +// single outcome sum it could only be expressed by overwriting the success, destroying the record +// that the build had ever run.\n\nBoth halves are asserted here: the status is simultaneously a +// settled Produced execution AND not retrievable. A collapse back into one axis makes one of the +// two conjuncts unrepresentable and this row goes red. fn witness_status( subject: BuildSubject, @@ -602,7 +660,10 @@ test fn produced_yesterday_with_missing_bytes_today_is_representable() -> Bool { } } -data retrievability_law_doc: String = "THE CONTRACT LAW ASSERTED OVER EVERY ARM: only observed-available bytes permit a caller to believe it holds an artifact. Corrupt bytes are the arm most likely to be mishandled -- they exist, they are the right length, and they are the wrong content -- so a service that treated presence as availability would serve them." +// THE CONTRACT LAW ASSERTED OVER EVERY ARM: only observed-available bytes permit a caller to +// believe it holds an artifact. Corrupt bytes are the arm most likely to be mishandled -- they +// exist, they are the right length, and they are the wrong content -- so a service that treated +// presence as availability would serve them. test fn only_observed_available_bytes_permit_retrieval() -> Bool { match witness_subject(tree_hex: clean_tree_hex, gnu_abi: true, features: []) { @@ -651,7 +712,14 @@ test fn an_interrupted_build_is_not_settled() -> Bool { !execution_is_settled(execution: ExecutionInterrupted { detail: "producer died" }) } -data devboot_membership_witness_doc: String = "THE STORE ROOT IS ENSURED, AND THESE ROWS SAY WHAT THAT BUYS. It projects the gunbc.host_layout authority rather than respelling the path; it reaches the apply order, so a deploy converges it; and its teardown REFUSES, so no retract can remove it.\\n\\nThe third row is the one the incident earned. Wiring this root into the OWNED roster made a lab twin's retract remove the production artifact store -- caught by the twin disjointness claims, which is why those claims were left exactly as they were. A hazard caught once by a claim about something else deserves a control of its own, so the refusal is asserted directly here rather than left to depend on two tests that are really about twins." +// THE STORE ROOT IS ENSURED, AND THESE ROWS SAY WHAT THAT BUYS. It projects the gunbc.host_layout +// authority rather than respelling the path; it reaches the apply order, so a deploy converges it; +// and its teardown REFUSES, so no retract can remove it.\n\nThe third row is the one the incident +// earned. Wiring this root into the OWNED roster made a lab twin's retract remove the production +// artifact store -- caught by the twin disjointness claims, which is why those claims were left +// exactly as they were. A hazard caught once by a claim about something else deserves a control of +// its own, so the refusal is asserted directly here rather than left to depend on two tests that +// are really about twins. fn devboot_ensured_step_projects_layout(acc: Int, step: DeploymentDependencyStep) -> Int { match step.subject { @@ -684,7 +752,11 @@ test fn the_devboot_store_root_reaches_the_deploy_apply_path() -> Bool { fold(spec.steps, init: false, f: (acc, step) => acc || step_is_devboot_root(step: step)) } -data devboot_teardown_refusal_red_doc: String = "THE CONTROL FOR THE HAZARD THAT WAS ACTUALLY HIT. A retract must not be able to remove the artifact store, and this asserts it at the step level: the devboot root's teardown disposition refuses with TeardownOutsideOwnership. If someone moves this root back into the owned roster, TeardownActs replaces the refusal and this row goes red -- which is exactly the edit that, last time, would have let a lab twin's retract delete production's artifacts." +// THE CONTROL FOR THE HAZARD THAT WAS ACTUALLY HIT. A retract must not be able to remove the +// artifact store, and this asserts it at the step level: the devboot root's teardown disposition +// refuses with TeardownOutsideOwnership. If someone moves this root back into the owned roster, +// TeardownActs replaces the refusal and this row goes red -- which is exactly the edit that, last +// time, would have let a lab twin's retract delete production's artifacts. test fn no_retract_can_remove_the_devboot_store_root() -> Bool { let spec = deployment_spec_srv1() diff --git a/dag/test/claim/direct_rust_door_write_compile_witness_test.dag b/dag/test/claim/direct_rust_door_write_compile_witness_test.dag index efc6f8900ee..b3d957d1cad 100644 --- a/dag/test/claim/direct_rust_door_write_compile_witness_test.dag +++ b/dag/test/claim/direct_rust_door_write_compile_witness_test.dag @@ -6,7 +6,10 @@ import v2.std.logic { Bool } data live_tree_disposition: LiveTreeDisposition = ReadsLiveTree -data direct_rust_door_write_compile_witness_note: String = "Lane B wet compile receipt (wise-ram-22 PR1 containment): v2-emitted rust add source is written through mint_written_synthetic_emitted_artifact_from_fixture_inferred to a temp lib crate and compiles via cargo.Build.BuildManifest; FixtureCargoGreen only — no production ProducerEmissionReceipt on this path." +// Lane B wet compile receipt (wise-ram-22 PR1 containment): v2-emitted rust add source is written +// through mint_written_synthetic_emitted_artifact_from_fixture_inferred to a temp lib crate and +// compiles via cargo.Build.BuildManifest; FixtureCargoGreen only — no production +// ProducerEmissionReceipt on this path. test fn direct_rust_door_emit_write_compile_holds() -> Bool { run_direct_rust_door_emit_write_compile_smoke() diff --git a/dag/test/claim/dispatch_attempts_witness_test.dag b/dag/test/claim/dispatch_attempts_witness_test.dag index a8069ba2980..f93508cdc65 100644 --- a/dag/test/claim/dispatch_attempts_witness_test.dag +++ b/dag/test/claim/dispatch_attempts_witness_test.dag @@ -20,7 +20,12 @@ import v2.std.live_tree { LiveTreeDisposition, SubstrateInputsOnly } data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data dispatch_attempts_witness_note: String = "U3's receipts: the attempt-branch parse proven on real shapes (an attempt-grain branch round-trips node and key; a LEGACY pre-attempt-grain branch — the operator's accidental spawn class — parses with an empty key rather than filtering as noise; garbage refuses), the wire projection proven on synthetic observations both arms, and the client machinery pinned in the served asset. The round-trip witness closes the loop with U1: a branch MINTED by dispatch_branch_name must parse back to its own node and key — the two authorities cannot drift." +// U3's receipts: the attempt-branch parse proven on real shapes (an attempt-grain branch +// round-trips node and key; a LEGACY pre-attempt-grain branch — the operator's accidental spawn +// class — parses with an empty key rather than filtering as noise; garbage refuses), the wire +// projection proven on synthetic observations both arms, and the client machinery pinned in the +// served asset. The round-trip witness closes the loop with U1: a branch MINTED by +// dispatch_branch_name must parse back to its own node and key — the two authorities cannot drift. fn attempt_fixture() -> DispatchAttemptRef { DispatchAttemptRef { node_id: "5-regen-cutover", branch: "dispatch/5-regen-cutover-afeedfacefeedface", attempt_key: "feedfacefeedface" } diff --git a/dag/test/claim/dispatch_preflight_witness_test.dag b/dag/test/claim/dispatch_preflight_witness_test.dag index f76331be850..2c0b7d2c8cb 100644 --- a/dag/test/claim/dispatch_preflight_witness_test.dag +++ b/dag/test/claim/dispatch_preflight_witness_test.dag @@ -39,7 +39,13 @@ import v2.std.live_tree { LiveTreeDisposition, SubstrateInputsOnly } data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data dispatch_preflight_witness_note: String = "The preflight's DECISION layer is pure and is witnessed here; the observation layer is the shared capability observer and the shared fleet-revision observer, each already covered where it lives, so nothing is re-observed. The discriminating reds are the two ways this carrier could lie in the dangerous direction: a report carrying a refused axis rendering as PreflightAdmitted, and a drifted-revision refusal that names only one side of the comparison — the belt's own receipt names both, and a preflight that dropped either would tell an operator a tree had drifted without saying to what." +// The preflight's DECISION layer is pure and is witnessed here; the observation layer is the shared +// capability observer and the shared fleet-revision observer, each already covered where it lives, +// so nothing is re-observed. The discriminating reds are the two ways this carrier could lie in the +// dangerous direction: a report carrying a refused axis rendering as PreflightAdmitted, and a +// drifted-revision refusal that names only one side of the comparison — the belt's own receipt +// names both, and a preflight that dropped either would tell an operator a tree had drifted without +// saying to what. data desired_hex: String = "7c079cd39c6c58ef201d6949189384019f1576d0" data local_hex: String = "517fdac4ddf92d0dd636c1f66fdb95b508525067" diff --git a/dag/test/claim/dispatch_presentation_witness_test.dag b/dag/test/claim/dispatch_presentation_witness_test.dag index 5d968889534..fedc82224c4 100644 --- a/dag/test/claim/dispatch_presentation_witness_test.dag +++ b/dag/test/claim/dispatch_presentation_witness_test.dag @@ -21,7 +21,11 @@ import v2.std.live_tree { LiveTreeDisposition, SubstrateInputsOnly } data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data dispatch_presentation_witness_note: String = "P3 keystone, re-grounded by remodel W1d (2026-07-24) and lifecycle correction (2026-07-27): the dispatch button's presentation is a projection of modeled rows, not hand pixels/colors. Reserved width derives from every caption it can wear, including dispatch receipts and observed-session presence; each state class paints its BAND's exact fill/ink vars; located fields surface in the title; and client plus stylesheet share one class vocabulary." +// P3 keystone, re-grounded by remodel W1d (2026-07-24) and lifecycle correction (2026-07-27): the +// dispatch button's presentation is a projection of modeled rows, not hand pixels/colors. Reserved +// width derives from every caption it can wear, including dispatch receipts and observed-session +// presence; each state class paints its BAND's exact fill/ink vars; located fields surface in the +// title; and client plus stylesheet share one class vocabulary. fn role_var_for_label(wire_label: String) -> String { fold(component_state_for_label(c: dispatch_button_component(), wire_label: wire_label), diff --git a/dag/test/claim/dispatch_stop_witness_test.dag b/dag/test/claim/dispatch_stop_witness_test.dag index 8a042cfe8d4..bdb8cddff73 100644 --- a/dag/test/claim/dispatch_stop_witness_test.dag +++ b/dag/test/claim/dispatch_stop_witness_test.dag @@ -37,7 +37,16 @@ import v2.std.live_tree { LiveTreeDisposition, SubstrateInputsOnly } data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data dispatch_stop_witness_note: String = "Cleanup receipts separate a present tmux container from its provider process. dispatch_codex_process_fingerprint remains the 2026-07-27 npm-shim live receipt (node) until bundled-native tmux observation updates it. The shared lifecycle path proves three independent conclusions: an owned running node process may be stopped, a retained dead pane may be cleared regardless of its historical env command, and a foreign running process refuses. The wire distinguishes process_stopped from session_cleared and carries ok explicitly; the client renders process evidence beside a stop/clear/unavailable cleanup control. scope() uses dispatch_codex_process_fingerprint directly — stop-contract witnesses prove tmux ownership classification, not production selection standing; production dispatch_actuator_selection refuses until observation wires inventory standing." +// Cleanup receipts separate a present tmux container from its provider process. +// dispatch_codex_process_fingerprint remains the 2026-07-27 npm-shim live receipt (node) until +// bundled-native tmux observation updates it. The shared lifecycle path proves three independent +// conclusions: an owned running node process may be stopped, a retained dead pane may be cleared +// regardless of its historical env command, and a foreign running process refuses. The wire +// distinguishes process_stopped from session_cleared and carries ok explicitly; the client renders +// process evidence beside a stop/clear/unavailable cleanup control. scope() uses +// dispatch_codex_process_fingerprint directly — stop-contract witnesses prove tmux ownership +// classification, not production selection standing; production dispatch_actuator_selection refuses +// until observation wires inventory standing. fn scope() -> TmuxSessionScope { TmuxSessionScope { @@ -180,7 +189,12 @@ test fn stop_client_carries_the_chip() -> Bool { && !string_contains(s: js, pattern: "sess.process_detail") } -data stop_chip_decided_facts_note: String = "A2 flip (operator blockers 4/5): the chip's action identity and availability come from the wire's DECIDED session action (sact.label onto dataset.cleanupAction, disabled when sact.availability is not 'available') — the client never reads the raw admission fields. The four former positives (sess.cleanup_action/cleanup_allowed/process_state/process_detail) are now discriminating NEGATIVES: any reappearing in the emitted source is the client re-deriving cleanup or process presentation from raw facts, a second authority beside session_facts_view." +// A2 flip (operator blockers 4/5): the chip's action identity and availability come from the wire's +// DECIDED session action (sact.label onto dataset.cleanupAction, disabled when sact.availability is +// not 'available') — the client never reads raw admission fields. The four former positives +// (sess.cleanup_action/cleanup_allowed/process_state/process_detail) are now discriminating +// NEGATIVES: any reappearing in the emitted source is the client re-deriving cleanup or process +// presentation from raw facts, a second authority beside session_facts_view. test fn stop_chip_is_styled() -> Bool { return string_contains(s: roadmap_css(), pattern: ".cleanup-chip { font-size: var(--text-10);") diff --git a/dag/test/claim/doc_graph_reference_partition_witness_test.dag b/dag/test/claim/doc_graph_reference_partition_witness_test.dag index cc1924e8e72..29d58058fe8 100644 --- a/dag/test/claim/doc_graph_reference_partition_witness_test.dag +++ b/dag/test/claim/doc_graph_reference_partition_witness_test.dag @@ -6,11 +6,57 @@ import gunbc.doc_graph_roots { hand_authored_production_doc_declaration_refs, } -data doc_graph_reference_partition_witness_note: String = "REGROUNDED ON ITS ACTUAL SUBJECT 2026-08-26, and the rename is the finding rather than tidying. This file was called cited_symbol_resolution_witness_test and contains one claim: the three-term bucket partition over gunbc.doc_graph_roots' authored references. It never imported v2.lens.cited_symbol_resolution and it asserts nothing about resolution.\n\nTHE NAME PRODUCED A WRONG INFERENCE TWICE, INDEPENDENTLY, on the change that deleted the lens: two readers saw 'a cited-symbol witness executes on every push' and concluded the citation-resolution law was enforced per-PR. It was not — a bucket identity was, and the resolution law was enforced by nothing between 2026-08-23 and the ingestion wall landing on 2026-08-25. Under the old name that misreading got STRICTLY MORE likely after the cut, because this became the only surviving thing in the tree whose name says cited-symbol: it would have read as the residue of the deleted law rather than as a claim about doc_graph_roots.\n\nThe property is unchanged. Same borrowed-authority shape as the fixture specimens rehomed in #9252, one layer over: there the property was fine and the HOME was borrowed, here the property was fine and the NAME was." +// REGROUNDED ON ITS ACTUAL SUBJECT 2026-08-26, and the rename is the finding rather than tidying. +// This file was called cited_symbol_resolution_witness_test and contains one claim: the three-term +// bucket partition over gunbc.doc_graph_roots' authored references. It never imported +// v2.lens.cited_symbol_resolution and it asserts nothing about resolution. +// +// THE NAME PRODUCED A WRONG INFERENCE TWICE, INDEPENDENTLY, on the change that deleted the lens: +// two readers saw 'a cited-symbol witness executes on every push' and concluded the +// citation-resolution law was enforced per-PR. It was not — a bucket identity was, and the +// resolution law was enforced by nothing between 2026-08-23 and the ingestion wall landing on +// 2026-08-25. Under the old name that misreading got STRICTLY MORE likely after the cut, because +// this became the only surviving thing in the tree whose name says cited-symbol: it would have read +// as the residue of the deleted law rather than as a claim about doc_graph_roots. +// +// The property is unchanged. Same borrowed-authority shape as the fixture specimens rehomed in +// #9252, one layer over: there the property was fine and the HOME was borrowed, here the property +// was fine and the NAME was. -data cited_symbol_witness_shadowing_finding_note: String = "FINDING (2026-08-03, G1 planted ambiguous control, namespace-resolution relative): a test fn may silently SHADOW an imported fn of the same bare name — cited_symbol_planted_ambiguous_control_refuses imported from v2.lens.cited_symbol_resolution while a local test fn carried the identical name, so the call inside the test resolved to itself, not the import. Failure mode: call depth exceeded 100000 (divergence), not a name-collision diagnostic and not a multiply-resolved corpus row. Same unqualified-name resolution hazard as prior resolver-environment collisions; this instance is notable because shadowing masquerades as resolver divergence and misattributes the defect. Fix in G1: delete the wrapper, call resolve_declaration_ref directly on planted ref + duplicate decl_facts fixtures; ambiguous witnesses must not share names with imported helpers. Namespace lane owns structural refusal for this shape." +// FINDING (2026-08-03, G1 planted ambiguous control, namespace-resolution relative): a test fn may +// silently SHADOW an imported fn of the same bare name — +// cited_symbol_planted_ambiguous_control_refuses imported from v2.lens.cited_symbol_resolution +// while a local test fn carried the identical name, so the call inside the test resolved to itself, +// not the import. Failure mode: call depth exceeded 100000 (divergence), not a name-collision +// diagnostic and not a multiply-resolved corpus row. Same unqualified-name resolution hazard as +// prior resolver-environment collisions; this instance is notable because shadowing masquerades as +// resolver divergence and misattributes the defect. Fix in G1: delete the wrapper, call +// resolve_declaration_ref directly on planted ref + duplicate decl_facts fixtures; ambiguous +// witnesses must not share names with imported helpers. Namespace lane owns structural refusal for +// this shape. -data cited_symbol_partition_third_bucket_note: String = "THE PARTITION IS BACK TO TWO BUCKETS AND THE REASON IS A REHOME, NOT A RELAXATION. The planted-control bucket left this carrier on 2026-08-25: the three g1 controls are machine discriminators for v2.lens.cited_symbol_resolution, not documents, and they now live there as cited_symbol_planted_controls, so no authored document work is a planted control any more and the term measuring them would be a constant zero. The property below is unchanged -- NO AUTHORED WORK MAY FALL OUT OF EVERY BUCKET -- and it is still an exact sum rather than an inequality, so a bucket added later reds here again. The account of how the third bucket arrived is kept because it is the receipt for why the identity is exact:\n\nTHE PARTITION GAINED A THIRD BUCKET AND THIS WITNESS IS WHAT NOTICED. It read all-works == production + planted-controls, which held while every authored work was in exactly one of two buckets. Marking the four references that decl_facts cannot index as OutsideDeclIndexTestWitnessModule removed them from the production projection, so the two-term identity went short by exactly four and this row went red on the required floor — a fail-closed report of a real change to the population, not a stale assertion.\n\nWHY IT IS RESTATED AS THREE TERMS RATHER THAN RELAXED. The property being protected is that NO AUTHORED WORK FALLS OUT OF EVERY BUCKET: a reference silently dropped from the production population is exactly how a census greens over something nobody checked, which is the failure this lens exists to catch. Loosening the equality to an inequality, or subtracting the outside-index rows from the left side, would both make that unrepresentable-to-detect. The three-term identity keeps the sum exact, so a fourth bucket added later reds here too." +// THE PARTITION IS BACK TO TWO BUCKETS AND THE REASON IS A REHOME, NOT A RELAXATION. The +// planted-control bucket left this carrier on 2026-08-25: the three g1 controls are machine +// discriminators for v2.lens.cited_symbol_resolution, not documents, and they now live there as +// cited_symbol_planted_controls, so no authored document work is a planted control any more and the +// term measuring them would be a constant zero. The property below is unchanged -- NO AUTHORED WORK +// MAY FALL OUT OF EVERY BUCKET -- and it is still an exact sum rather than an inequality, so a +// bucket added later reds here again. The account of how the third bucket arrived is kept because +// it is the receipt for why the identity is exact: +// +// THE PARTITION GAINED A THIRD BUCKET AND THIS WITNESS IS WHAT NOTICED. It read all-works == +// production + planted-controls, which held while every authored work was in exactly one of two +// buckets. Marking the four references that decl_facts cannot index as +// OutsideDeclIndexTestWitnessModule removed them from the production projection, so the two-term +// identity went short by exactly four and this row went red on the required floor — a fail-closed +// report of a real change to the population, not a stale assertion. +// +// WHY IT IS RESTATED AS THREE TERMS RATHER THAN RELAXED. The property being protected is that NO +// AUTHORED WORK FALLS OUT OF EVERY BUCKET: a reference silently dropped from the production +// population is exactly how a census greens over something nobody checked, which is the failure +// this lens exists to catch. Loosening the equality to an inequality, or subtracting the +// outside-index rows from the left side, would both make that unrepresentable-to-detect. The +// three-term identity keeps the sum exact, so a fourth bucket added later reds here too. test fn doc_graph_production_population_loses_nothing() -> Bool { length(xs: hand_authored_doc_declaration_refs()) diff --git a/dag/test/claim/doc_reachability_witness_test.dag b/dag/test/claim/doc_reachability_witness_test.dag index eab7beeae7c..8acc8c5a573 100644 --- a/dag/test/claim/doc_reachability_witness_test.dag +++ b/dag/test/claim/doc_reachability_witness_test.dag @@ -29,9 +29,22 @@ import std.decl_ref { DeclarationRef, WholeDeclaration } data live_tree_disposition: LiveTreeDisposition = ReadsLiveTree -data live_tree_disposition_correction_note: String = "Corrected 2026-07-15: the 2026-07-12 machine-stamped SubstrateInputsOnly row (#6479 batch, entry-text classifier) was FALSE — every test fn below reads the live docs/ tree through the doc_graph_* host builtins (cli_run.rs build_doc_graph_report), the exact hidden-behind-a-builtin blind spot live_tree.dag:5 declares for that classifier. ReadsLiveTree restores the never-skip tooth so the orphan wall runs on every full floor; the false stamp let a docs-only PR (gunbc#6654) mint an orphan with green CI. #7023 recurrence: the shell documentation_only_skip shortcut exited before claim_executor, bypassing this lane entirely on docs-only PRs — retired proud-cat-517; floor_skip_discovery_witness proves by execution that docs-only diffs RUN this entry." - -data hand_authored_bind_keyed_roster_note: String = "HandAuthoredDocBind rows are keyed by hand_authored_bind_key (home + slug). std.keyed_roster keyed_roster_build refuses a repeated key at construction — the wall that makes a colliding bind identity unwritable rather than detectable only after merge. keyed_roster_union models the git clean-merge failure mode: two branches each append disjoint binds admit; overlapping bind keys refuse at per-PR admission instead of stalling main with duplicate slugs no per-branch uniqueness check can see." +// Corrected 2026-07-15: the 2026-07-12 machine-stamped SubstrateInputsOnly row (#6479 batch, +// entry-text classifier) was FALSE — every test fn below reads the live docs/ tree through the +// doc_graph_* host builtins (cli_run.rs build_doc_graph_report), the exact hidden-behind-a-builtin +// blind spot live_tree.dag:5 declares for that classifier. ReadsLiveTree restores the never-skip +// tooth so the orphan wall runs on every full floor; the false stamp let a docs-only PR +// (gunbc#6654) mint an orphan with green CI. #7023 recurrence: the shell documentation_only_skip +// shortcut exited before claim_executor, bypassing this lane entirely on docs-only PRs — retired +// proud-cat-517; floor_skip_discovery_witness proves by execution that docs-only diffs RUN this +// entry. + +// HandAuthoredDocBind rows are keyed by hand_authored_bind_key (home + slug). std.keyed_roster +// keyed_roster_build refuses a repeated key at construction — the wall that makes a colliding bind +// identity unwritable rather than detectable only after merge. keyed_roster_union models the git +// clean-merge failure mode: two branches each append disjoint binds admit; overlapping bind keys +// refuse at per-PR admission instead of stalling main with duplicate slugs no per-branch uniqueness +// check can see. test fn doc_graph_has_no_orphan_docs() -> Bool { return doc_graph_floor_orphan_clean_holds() @@ -59,7 +72,17 @@ test fn doc_graph_slug_wall_reds_on_registered_slug() -> Bool { }) == false } -data works_construction_wall_note: String = "The empty-works RED control and the binds-works-all-nonempty witness that stood here were DELETED WITH the validation they backed (2026-07-31 verdict on gunbc#7489): primary_work is now a required scalar on HandAuthoredDocBind, so the zero-anchor bind the RED constructed no longer compiles — the wall moved from predicate to type, and asserting a predicate over an unwritable state is dead evidence. The residual discriminating probe (a compile-refusal probe proving a missing-primary_work row refuses) is named on the carrier note as ladder-probe-corpus record-completeness work. refs-carry-symbols below survives as honest validation ONLY until NonEmptyStr refinement is enforced at data positions (declared-conformance-general-wall's dissolution trigger — the 2026-08-01 recut retired the floor-inhabitance-wall slug this note formerly named; refinement enforcement sits on the general wall, not the accepted ground fragment)." +// The empty-works RED control and the binds-works-all-nonempty witness that stood here were DELETED +// WITH the validation they backed (2026-07-31 verdict on gunbc#7489): primary_work is now a +// required scalar on HandAuthoredDocBind, so the zero-anchor bind the RED constructed no longer +// compiles — the wall moved from predicate to type, and asserting a predicate over an unwritable +// state is dead evidence. The residual discriminating probe (a compile-refusal probe proving a +// missing-primary_work row refuses) is named on the carrier note as ladder-probe-corpus +// record-completeness work. refs-carry-symbols below survives as honest validation ONLY until +// NonEmptyStr refinement is enforced at data positions (declared-conformance-general-wall's +// dissolution trigger — the 2026-08-01 recut retired the floor-inhabitance-wall slug this note +// formerly named; refinement enforcement sits on the general wall, not the accepted ground +// fragment). test fn doc_graph_works_refs_carry_symbols() -> Bool { return hand_authored_works_refs_all_carry_symbols() diff --git a/dag/test/claim/documentary_refs_witness_test.dag b/dag/test/claim/documentary_refs_witness_test.dag index cf0022a383d..4dff7de0270 100644 --- a/dag/test/claim/documentary_refs_witness_test.dag +++ b/dag/test/claim/documentary_refs_witness_test.dag @@ -16,7 +16,13 @@ import gunbc.documentary_refs { import gunbc.doc_graph_roots { hand_authored_doc_declaration_refs } import gunbc.design_document { expected_design_md } -data documentary_refs_witness_note: String = "THE PERTURBATIONS ARE THE POINT, AND EACH RUNS AGAINST THE SAME RESOLVER PRODUCTION USES. cited_declaration_ref_refusal_count is v2.std.decl_ref_resolution's own counter -- the one the required cited-symbol gate calls -- so a refusal proved here is a refusal on the real acceptance path rather than a second algorithm agreeing with it. The fact populations below are planted rather than live because the SUBJECT of these claims is the mechanism: that a reference which cannot resolve refuses, and that the same reference against an intact population does not. The smallest crossing specimen is the requirement plus one." +// THE PERTURBATIONS ARE THE POINT, AND EACH RUNS AGAINST THE SAME RESOLVER PRODUCTION USES. +// cited_declaration_ref_refusal_count is v2.std.decl_ref_resolution's own counter -- the one the +// required cited-symbol gate calls -- so a refusal proved here is a refusal on the real acceptance +// path rather than a second algorithm agreeing with it. The fact populations below are planted +// rather than live because the SUBJECT of these claims is the mechanism: that a reference which +// cannot resolve refuses, and that the same reference against an intact population does not. The +// smallest crossing specimen is the requirement plus one. fn fixture_modules() -> List { [ @@ -37,7 +43,9 @@ fn fixture_fact(qualified_name: String, name: String, path: String) -> DeclFact } } -data intact_population_note: String = "The four declarations the generated document names, present exactly once each. This is the control that proves the refusals below are caused by the perturbation rather than by a fixture that never resolved anything." +// The four declarations the generated document names, present exactly once each. This is the +// control that proves the refusals below are caused by the perturbation rather than by a fixture +// that never resolved anything. fn intact_facts() -> List { [ @@ -49,7 +57,6 @@ fn intact_facts() -> List { ] } - fn refusals_against(facts: List) -> Int { cited_declaration_ref_refusal_count( refs: generated_document_declaration_refs(), @@ -62,7 +69,12 @@ test fn documentary_refs_intact_population_resolves_clean() -> Bool { refusals_against(facts: intact_facts()) == 0 } -data rename_control_note: String = "THE PRODUCT RED. A referenced system is renamed -- here by removing the declaration the document names and leaving the rest of the population intact -- and NO DOCUMENT SOURCE IS EDITED. The refusal count rises, which is the whole claim: the generated paragraph names its systems through typed rows, so the rename reaches the required gate rather than leaving a sentence quietly describing a declaration that no longer exists. Before this change that same rename moved nothing, because the name lived inside a string literal." +// THE PRODUCT RED. A referenced system is renamed -- here by removing the declaration the document +// names and leaving the rest of the population intact -- and NO DOCUMENT SOURCE IS EDITED. The +// refusal count rises, which is the whole claim: the generated paragraph names its systems through +// typed rows, so the rename reaches the required gate rather than leaving a sentence quietly +// describing a declaration that no longer exists. Before this change that same rename moved +// nothing, because the name lived inside a string literal. fn facts_without(qualified_name: String) -> List { fold(intact_facts(), init: [], f: fn(acc, f) { @@ -78,7 +90,11 @@ test fn documentary_refs_renamed_system_refuses() -> Bool { clean == 0 && renamed == 1 } -data ambiguous_control_note: String = "THE SECOND PERTURBATION, AND IT IS A DIFFERENT FAILURE FROM THE FIRST. A system forked into two same-named declarations still EXISTS -- an existence check passes and a grep passes -- so only a resolver that answers zero/one/many catches it. The document's reference no longer identifies one system, which is exactly the §3 fork the citation rule is about, and it must refuse rather than pick the first." +// THE SECOND PERTURBATION, AND IT IS A DIFFERENT FAILURE FROM THE FIRST. A system forked into two +// same-named declarations still EXISTS -- an existence check passes and a grep passes -- so only a +// resolver that answers zero/one/many catches it. The document's reference no longer identifies one +// system, which is exactly the §3 fork the citation rule is about, and it must refuse rather than +// pick the first. test fn documentary_refs_ambiguous_system_refuses() -> Bool { let forked = concat( @@ -94,14 +110,37 @@ test fn documentary_refs_ambiguous_system_refuses() -> Bool { refusals_against(facts: forked) == 1 } -data rendered_from_rows_note: String = "THE BYTES COME FROM THE ROWS, WHICH IS WHAT MAKES THE ROWS LOAD-BEARING RATHER THAN DECORATIVE. A typed reference sitting beside a paragraph that independently spells the same name is two representations of one fact -- the rename would move the row and leave the sentence, and the enrolled population would resolve while the document lied. This claim asserts the rendered symbol text of each row appears in the generated document, so the row and the printed name cannot diverge." +// THE BYTES COME FROM THE ROWS, WHICH IS WHAT MAKES THE ROWS LOAD-BEARING RATHER THAN DECORATIVE. A +// typed reference sitting beside a paragraph that independently spells the same name is two +// representations of one fact -- the rename would move the row and leave the sentence, and the +// enrolled population would resolve while the document lied. This claim asserts the rendered symbol +// text of each row appears in the generated document, so the row and the printed name cannot +// diverge. test fn documentary_refs_generated_document_renders_the_rows() -> Bool { let md = expected_design_md() string_contains(s: md, pattern: documentary_ref_symbol_text(reference: v1_maintenance_standing_ref)) } -data population_union_note: String = "The widened denominator is asserted directly, because a union that silently dropped one side would leave exactly the exemption this change removes: the generated refs must all be present in the combined population, and the combined population must be larger than the hand-authored one alone." +// The widened denominator is asserted directly, because a union that silently dropped one side +// would leave exactly the exemption this change removes: the generated refs must all be present in +// the combined population, and the combined population must be larger than the hand-authored one +// alone. + +// A NEGATIVE PROSE CHECK STOOD HERE AND WAS DELETED RATHER THAN REPAIRED. It asserted the generated +// document no longer contains the substring 'six-step', to show the superseded numbered sequence is +// gone. It failed -- and it failed CORRECTLY, because the replacement sentence explains that the +// paragraph previously carried a numbered six-step copy, so the words survive while the copy does +// not. The check could not tell a restatement from an explanation of its removal. +// +// THAT IS THE WHOLE ARGUMENT AGAINST THIS SHAPE, and it is already on record: +// gunbc.roadmap_authority witness_authority_contains_no_mutable_execution_ledger blacklists +// substrings in a status field and is structurally unable to catch a stale claim spelled without +// them. Repairing the needle would have produced a check that passes for this one spelling and +// decides nothing in general -- validation standing where nothing decidable was available. The +// positive claim survives instead, in documentary_refs_generated_document_renders_the_rows: the +// roadmap authority is cited by rendering its typed row, which is a fact a mechanism can actually +// decide. test fn documentary_refs_population_is_the_union() -> Bool { let all_refs = all_documentary_declaration_refs() @@ -110,6 +149,3 @@ test fn documentary_refs_population_is_the_union() -> Bool { length(xs: all_refs) == length(xs: hand) + length(xs: generated) && length(xs: generated) == 1 } - -data retired_prose_substring_control_note: String = "A NEGATIVE PROSE CHECK STOOD HERE AND WAS DELETED RATHER THAN REPAIRED. It asserted the generated document no longer contains the substring 'six-step', to show the superseded numbered sequence is gone. It failed -- and it failed CORRECTLY, because the replacement sentence explains that the paragraph previously carried a numbered six-step copy, so the words survive while the copy does not. The check could not tell a restatement from an explanation of its removal.\n\nTHAT IS THE WHOLE ARGUMENT AGAINST THIS SHAPE, and it is already on record: gunbc.roadmap_authority witness_authority_contains_no_mutable_execution_ledger blacklists substrings in a status field and is structurally unable to catch a stale claim spelled without them. Repairing the needle would have produced a check that passes for this one spelling and decides nothing in general -- validation standing where nothing decidable was available. The positive claim survives instead, in documentary_refs_generated_document_renders_the_rows: the roadmap authority is cited by rendering its typed row, which is a fact a mechanism can actually decide." - diff --git a/dag/test/claim/duplicate_declaration_wall_witness_test.dag b/dag/test/claim/duplicate_declaration_wall_witness_test.dag index fa49f336328..e1cda8615a6 100644 --- a/dag/test/claim/duplicate_declaration_wall_witness_test.dag +++ b/dag/test/claim/duplicate_declaration_wall_witness_test.dag @@ -17,24 +17,22 @@ data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly // WHY THE RED IS AUTHORABLE HERE AND NOWHERE ELSE (DESIGN 4b): no `Accepted` module may now carry // the state, so the refusal is unreachable from the corpus -- but a fixture hands the compiler // source text, and a compiler's regression probes are invalid programs by definition. Declining to -// author it because the accepted tree cannot hold it would be the specification-without-execution -// failure, not a saving. +// author it because the accepted tree cannot hold it would be specification-without-execution. // -// THE BOUND THIS ROW EXISTS TO STATE, and it is about the repository's evidence discipline rather -// than about the compiler: where two definitions of one name are semantically EQUIVALENT, no -// behavioural witness can discriminate them whichever one wins. Green-by-execution proves -// BEHAVIOUR and is structurally blind to duplicate AUTHORSHIP. That is why this row is a -// compile-seam refusal and not a runtime probe, and it is why the live specimens this wall's -// landing repaired had passed every witness over them. +// THE BOUND THIS ROW STATES, about the repository's evidence discipline rather than the compiler: +// where two definitions of one name are semantically EQUIVALENT, no behavioural witness can +// discriminate them whichever wins. Green-by-execution proves BEHAVIOUR and is structurally blind +// to duplicate AUTHORSHIP. Hence a compile-seam refusal, not a runtime probe, and hence the live +// specimens this wall's landing repaired had passed every witness over them. // -// WHAT THIS SURFACE OBSERVES, stated so no receipt reads more coverage than it has: +// WHAT THIS SURFACE OBSERVES, so no receipt reads more coverage than it has: // `compile_dag_rust_emit_check` answers false when the compile carries ANY hard diagnostic, so a // red row alone does not establish WHICH judgment refused. The discrimination is carried by the -// PAIR: each red fixture and its green control differ by exactly the duplicated declaration and -// nothing else, so a red that survives its control's green is a red caused by the duplication. -// The path measured is source -> `.dag` acceptance through the v1 pipeline to the Rust render -// target, single module. NOT measured here: the interpreter's disposition of the same source, and -// cross-module name collisions, which are a different class (two keys, not one). +// PAIR: each red fixture and its green control differ by exactly the duplicated declaration, so a +// red that survives its control's green is a red caused by the duplication. The path measured is +// source -> `.dag` acceptance through the v1 pipeline to the Rust render target, single module. +// NOT measured: the interpreter's disposition of the same source, and cross-module name +// collisions, a different class (two keys, not one). fn duplicate_fn_source() -> String { "module test.claim.duplicate_declaration_wall_duplicate_fn\nimport std.types { Int }\n\nfn which_one() -> Int { 1 }\n\nfn which_one() -> Int { 2 }\n" @@ -79,7 +77,7 @@ test fn a_data_and_a_function_sharing_one_name_are_refused() -> Bool { // THE POSITIVE CONTROLS. Each is its red's fixture with the duplication removed and nothing else // changed, so a red above cannot pass by its fixture being broken some other way. Per DESIGN 4b(4) -// these stay enrolled after the wall lands: they are the executing evidence that the rung is real, +// they stay enrolled after the wall lands: they are the executing evidence that the rung is real, // and deleting them would recreate specification-without-execution one rung up. test fn one_function_declaration_compiles_clean() -> Bool { diff --git a/dag/test/claim/e0599_emitter_decision_census_witness_test.dag b/dag/test/claim/e0599_emitter_decision_census_witness_test.dag index 81a8ddd8dc4..6f5c7e980e6 100644 --- a/dag/test/claim/e0599_emitter_decision_census_witness_test.dag +++ b/dag/test/claim/e0599_emitter_decision_census_witness_test.dag @@ -23,7 +23,22 @@ import tools.e0599_emitter_decision_census { } import tools.e0599_probe_census { e0599_mechanistic_root_family_labels_blob } -data e0599_emitter_decision_census_witness_note: String = "Witness for tools.e0599_emitter_decision_census: the operation selection and the operation->cause decision that docs/probes/e0599_emitter_decision_census.sh (SCAFFOLD realization) consumes over the real compilation path. Each GREEN pins one measured (method, receiver_expr) shape observed in the P-fn Phase B0 census to the lowering operation and typed cause it must select. The REDs are the load-bearing half: they hold the fail-closed arm open, so a future row that widens the classifier into a catch-all is caught. RED family 1 — an out-of-scope method (as_deref, root family R5) must NOT acquire a cause. RED family 2 — a receiver shape no lowering row names must NOT acquire a cause. RED family 3 (ROUTING, added 2026-07-29 on warm-dove-316 / calm-badger-682 review) — a tuple projection is a structurally distinct emitter shape from a named field access: v1.compiler.emit_rust emit_typed_field_access applies clone_value unconditionally in its TupleFirst, TupleSecond, and anonymous-record projection arms, while its StoredField arm gates clone_value by base_is_owned, so they differ on the ownership axis. These controls perturb the ROUTING rather than the destination: the absorbing-default control below proves the fail-closed arm CAN fire, but only a routing control proves an unclassifiable shape REACHES it. RED family 4 — the three causes must stay distinct, so a collapse of the TargetApi/OwnedDeconstruction/CloneShared split (the whole point of the B0 measurement) reds here." +// Witness for tools.e0599_emitter_decision_census: the operation selection and operation->cause +// decision that docs/probes/e0599_emitter_decision_census.sh (SCAFFOLD realization) consumes over +// the real compilation path. Each GREEN pins one measured (method, receiver_expr) shape from the +// P-fn Phase B0 census to the lowering operation and typed cause it must select. The REDs are the +// load-bearing half: they hold the fail-closed arm open against a row widening the classifier into +// a catch-all. RED family 1 — an out-of-scope method (as_deref, root family R5) must NOT acquire a +// cause. RED family 2 — a receiver shape no lowering row names must NOT acquire a cause. RED family +// 3 (ROUTING, added 2026-07-29 on warm-dove-316 / calm-badger-682 review) — a tuple projection is a +// structurally distinct emitter shape from a named field access: v1.compiler.emit_rust +// emit_typed_field_access applies clone_value unconditionally in its TupleFirst, TupleSecond, and +// anonymous-record projection arms, while its StoredField arm gates clone_value by base_is_owned, +// so they differ on the ownership axis. These controls perturb the ROUTING, not the destination: +// the absorbing-default control below proves the fail-closed arm CAN fire; only a routing control +// proves an unclassifiable shape REACHES it. RED family 4 — the three causes stay distinct, so a +// collapse of the TargetApi/OwnedDeconstruction/CloneShared split (the point of the B0 measurement) +// reds here. test fn e0599_b0_freemonoid_empty_test_is_target_api() -> Bool { e0599_lowering_operation_label(operation: e0599_lowering_operation_for(method: "is_empty", receiver_expr: "__fm")) == "FreeMonoidEmptyTest" diff --git a/dag/test/claim/e0599_probe_census_witness_test.dag b/dag/test/claim/e0599_probe_census_witness_test.dag index 26944958981..2882091b26f 100644 --- a/dag/test/claim/e0599_probe_census_witness_test.dag +++ b/dag/test/claim/e0599_probe_census_witness_test.dag @@ -17,7 +17,11 @@ import tools.e0599_probe_census { e0599_root_family_labels_from_blob, } -data e0599_probe_census_witness_note: String = "Witness for tools.e0599_probe_census authority: pattern row census, canonical-seven roster blob, and root-family rollup used by docs/probes/e0599_census_extract.sh (SCAFFOLD realization). Aggregate path refuses unless inputs match e0599_canonical_seven_modules exactly (missing/duplicate/extra). Export boundary refuses unknown failure-shape labels (fail-closed). RED: misclassified GlobalBare or type-parameter clone tuple; drifted shape_str." +// Witness for tools.e0599_probe_census authority: pattern row census, canonical-seven roster blob, +// and root-family rollup used by docs/probes/e0599_census_extract.sh (SCAFFOLD realization). +// Aggregate path refuses unless inputs match e0599_canonical_seven_modules exactly +// (missing/duplicate/extra). Export boundary refuses unknown failure-shape labels (fail-closed). +// RED: misclassified GlobalBare or type-parameter clone tuple; drifted shape_str. test fn e0599_message_pattern_rows_blob_first_row_is_missing_method() -> Bool { match e0599_message_pattern_rows_blob() |> split(delimiter: "\n") |> first { diff --git a/dag/test/claim/effect_grant_witness_test.dag b/dag/test/claim/effect_grant_witness_test.dag index e8e34a2e623..0af5f4622d9 100644 --- a/dag/test/claim/effect_grant_witness_test.dag +++ b/dag/test/claim/effect_grant_witness_test.dag @@ -18,7 +18,11 @@ import v2.std.live_tree { LiveTreeDisposition, SubstrateInputsOnly } data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -// P-A discriminating witnesses for std.effect_grant. The core claim is fail-closed admissibility (DESIGN 5): an effect whose target is not under any grant root for its verb is REFUSED, never widened. Every positive arm is paired with a negative arm that goes RED if the refusal is dropped (empty envelope admits, wrong verb admits, wrong tree admits, sibling path admits, a child envelope widens past its parent). +// P-A discriminating witnesses for std.effect_grant. Core claim: fail-closed admissibility (DESIGN +// 5) — an effect whose target is under no grant root for its verb is REFUSED, never widened. Every +// positive arm pairs with a negative arm that REDs if the refusal is dropped (empty envelope +// admits, wrong verb admits, wrong tree admits, sibling path admits, a child envelope widens past +// its parent). fn frame_named(name: String) -> Frame { Frame { name: name, kind: SharedStateFrame } } diff --git a/dag/test/claim/effect_plan_bash_materialize_real_execution_witness_test.dag b/dag/test/claim/effect_plan_bash_materialize_real_execution_witness_test.dag index 1d6fb5fc0e9..4303e0fff57 100644 --- a/dag/test/claim/effect_plan_bash_materialize_real_execution_witness_test.dag +++ b/dag/test/claim/effect_plan_bash_materialize_real_execution_witness_test.dag @@ -20,7 +20,11 @@ import v2.workflow.effect_plan_bash_materialize { data live_tree_disposition: LiveTreeDisposition = ReadsLiveTree -data effect_plan_bash_real_execution_note: String = "T1/T2 wet model evidence only, not the Wave-B gate consumer or policy activation. The controls execute emitted carriers through Bash using read-only test/id operations over fixed paths: no file write, environment mutation, network, repo state, or cleanup obligation. They prove two typed declared operations run, metachar/newline arguments stay one word, and grammar-owned && enforces FailFast by preventing the observable second command after the first fails." +// T1/T2 wet model evidence only, not the Wave-B gate consumer or policy activation. The controls +// execute emitted carriers through Bash using read-only test/id operations over fixed paths: no +// file write, environment mutation, network, repo state, or cleanup obligation. They prove two +// typed declared operations run, metachar/newline arguments stay one word, and grammar-owned && +// enforces FailFast by preventing the observable second command after the first fails. fn wet_ref(path: String, service: String, operation: String) -> OperationRef { OperationRef { path: path, service: service, operation: operation } diff --git a/dag/test/claim/effects_witness_test.dag b/dag/test/claim/effects_witness_test.dag index e25e244fba4..8c00c58df70 100644 --- a/dag/test/claim/effects_witness_test.dag +++ b/dag/test/claim/effects_witness_test.dag @@ -106,7 +106,12 @@ fn is_create(shape: EffectShape) -> Bool { } } -data keyless_fallback_witness_note: String = "Discriminating control for the PostAlways state-space conflation (std.effects.keyless_fallback_cause_note). Pre-fix, derive_effect_shape answered CreateEffect{PostAlways} for a real POST AND for a keyless PUT/PATCH/DELETE, so this projection was inexpressible and the originating method was lost. These rows go RED if the two causes ever collapse back together, and the negative arms prove the method is genuinely carried rather than defaulted." +// Discriminating control for the PostAlways state-space conflation +// (std.effects.keyless_fallback_cause_note). Pre-fix, derive_effect_shape answered +// CreateEffect{PostAlways} for a real POST AND for a keyless PUT/PATCH/DELETE, so this projection +// was inexpressible and the originating method was lost. These rows go RED if the two causes ever +// collapse back together, and the negative arms prove the method is genuinely carried rather than +// defaulted. fn derived_cause_is_keyless_with_method(shape: EffectShape, expected: HttpMethod) -> Bool { match shape { diff --git a/dag/test/claim/emit_host_gate_verdicts_test.dag b/dag/test/claim/emit_host_gate_verdicts_test.dag index 07142a94619..8fd0feda184 100644 --- a/dag/test/claim/emit_host_gate_verdicts_test.dag +++ b/dag/test/claim/emit_host_gate_verdicts_test.dag @@ -1,7 +1,11 @@ module test.claim.emit_host_gate_verdicts_test - -data emit_host_gate_verdicts_red_doc: String = "Discriminating controls for the per-smoke verdict line (tools.emit_host_gate.per_smoke_verdict_note): the refusal reason must NAME each failing smoke — the defect this dissolves is a five-smokes-into-one-Bool fold whose failure was unnameable from the receipt (2026-07-13 srv3 forensics receipt). A regression that drops a smoke from the line, swaps pass/FAIL polarity, or degenerates the join to empty goes RED on the exact-string pins below." +// Discriminating controls for the per-smoke verdict line +// (tools.emit_host_gate.per_smoke_verdict_note): the refusal reason must NAME each failing smoke — +// the defect this dissolves is a five-smokes-into-one-Bool fold whose failure was unnameable from +// the receipt (2026-07-13 srv3 forensics receipt). A regression that drops a smoke from the line, +// swaps pass/FAIL polarity, or degenerates the join to empty goes RED on the exact-string pins +// below. test fn verdict_line_names_failing_smokes() -> Bool { let got = smoke_verdict_line(rust: true, python: true, go: false, ts: false, node_http: true, c: true) diff --git a/dag/test/claim/emit_host_typed_smoke_test.dag b/dag/test/claim/emit_host_typed_smoke_test.dag index 5afc3d50aaa..9e3c9f88eb4 100644 --- a/dag/test/claim/emit_host_typed_smoke_test.dag +++ b/dag/test/claim/emit_host_typed_smoke_test.dag @@ -1,7 +1,11 @@ module test.claim.emit_host_typed_smoke_test - -data emit_host_typed_smoke_red_doc: String = "Discriminating controls for the typed emit-host smokes (tools.emit_host_transport). The smokes assert CONTENT equality against the in-substrate NUL golden; the control below emits five SPACES - byte-count-identical to the golden - and asserts inequality, so a regression of the mechanism back to count comparison (the old wc -c check) or an equality that fabricates true goes RED here. The pure shape tests pin the golden itself so repeat_string/from_code_point cannot silently degenerate to the empty string (which trailing-whitespace trims would then match)." +// Discriminating controls for the typed emit-host smokes (tools.emit_host_transport). The smokes +// assert CONTENT equality against the in-substrate NUL golden; the control below emits five SPACES +// - byte-count-identical to the golden - and asserts inequality, so a regression of the mechanism +// back to count comparison (the old wc -c check) or an equality that fabricates true goes RED here. +// The pure shape tests pin the golden itself so repeat_string/from_code_point cannot silently +// degenerate to the empty string (which trailing-whitespace trims would then match). data five_space_python_fixture: String = "import sys\nsys.stdout.write(' ' * 5)\n" diff --git a/dag/test/claim/emitter_bare_variant_expected_adoption_witness_test.dag b/dag/test/claim/emitter_bare_variant_expected_adoption_witness_test.dag index 8cce91a2340..08f7641b8d0 100644 --- a/dag/test/claim/emitter_bare_variant_expected_adoption_witness_test.dag +++ b/dag/test/claim/emitter_bare_variant_expected_adoption_witness_test.dag @@ -1,6 +1,74 @@ module test.claim.emitter_bare_variant_expected_adoption_witness_test -data emitter_bare_variant_expected_adoption_witness_note: String = "PERMANENT REGRESSION CONTROL for the cardinality half of bare-variant expected-type adoption.\n\nTHE UNDERLYING DEFECT, measured on the emitted v2.compiler.05_eval closure: a bare variant reference infers as its OWNER COPRODUCT'S DECLARATION NODE, whose children are the coproduct's ARMS rather than type arguments. `type Optional = Absent | Present { value: T }` declares Absent as child 0, so a generic owner reaching the renderer uninstantiated renders `Option` -- a constructor in type position, not a Rust type. Measured baseline on current main: 21 such sites (17 v2_compiler_body_lowering_fold, 2 v2_compiler_infer, 2 v2_std_cardinality) and 494 rustc errors; after the repair 0 sites and 473 errors, the delta being -19 E0425 and -2 E0573 (expected type, found variant) with NO rustc code increasing. The repair is in v1.compiler.infer: when the context supplies an expected type that owns the variant, that expected node IS the instantiated owner, so it is adopted in place of the declaration node.\n\nWHAT THIS FILE GUARDS, AND WHY IT IS THE CARDINALITY HALF RATHER THAN THE HEADLINE DEFECT. Adoption must be refused when the variant is reached through an OPTIONAL COERCION rather than owned at the expected type's own level. Optionality is not a wrapper type in this model -- `BinOp?` is a BinOp node whose return_cardinality is CardOptional (v1.compiler.core with_optional_cardinality) -- so a head-name comparison cannot see it. For a record field `binop: BinOp?` initialised with the bare arm `Mod`, the head IS BinOp and the arm IS found, but the constructor's own type is BinOp and the optionality is a coercion the emitter performs by wrapping. Adopting the expected node there makes the value look already-optional, the wrap is skipped, and `binop: BinOp::Mod` is emitted where `Some(BinOp::Mod)` is owed.\n\nTHAT IS NOT HYPOTHETICAL: two successive drafts of the repair shipped it. The first adopted whenever the PEELED coproduct matched (expand_scrut_type_for_variant_lookup peels to find the arm-bearing coproduct); the second compared the UNPEELED head, on the incorrect assumption that `BinOp?` is a wrapper named Optional. Both dropped the wrapper across four extdeps.languages.*_syntax modules and std.effects. The admitted form additionally requires the expected node to be Required.\n\nWHY THE SELF-HOST FIXED POINT FOUND THIS AND NOTHING ELSE DID, recorded because it is the transferable part: the Option count, the whole-artifact diff of the emitted eval closure, and the rustc error census ALL stayed green across both wrong drafts, because all three measure the eval closure and the regression lived in v1's OWN emitted sources. A population that could not have disagreed cannot falsify. regen_stage0 --verify re-emits the seed and was the only instrument whose subject included the damage.\n\nWHY THE HEADLINE Option CASE HAS NO ROW HERE, established by execution rather than asserted: it is UNREACHABLE through this harness. It requires the v2 `Optional` coproduct as a declared generic type AND the variant name Absent to be AMBIGUOUSLY owned across the closure (the emitter's derive_variant_to_enum sentinel is what suppresses the collapse-to-unit that would otherwise render `_`). `Optional` is not declared anywhere in the dag corpus -- it is the built-in `T?` sugar, and the named coproduct lives in v2.std.optional -- so a dag-rooted single source cannot construct the subject, and two coproducts claiming one arm name inside ONE module are refused outright by the compiler. The evidence for that half is the executed corpus measurement recorded above, which is a discriminating before/after but is NOT enrolled as a recurring control. That asymmetry is stated rather than papered over: the cardinality half below is protected on every run, the instantiation half is not.\n\nAND THE ASYMMETRY IS SHARPER THAN 'ONE HALF IS UNCOVERED', PROVEN LIVE RATHER THAN REASONED: BOTH ROWS BELOW PASS ON THE UNREPAIRED BASELINE. They are one-directional -- they detect the repair OVER-REACHING (adopting where it must not, which is what two abandoned drafts did) and they CANNOT detect the repair ceasing to work. That was demonstrated twice during this change. A draft that tightened the owner check to declaration identity by span silently reverted the repair to its full 21-site baseline; every row here stayed green and only re-measuring the emitted corpus noticed. A further draft that normalised both sides through lookup_type_for before comparing identity restored the 21 sites BUT introduced 16 incompatible-type errors elsewhere in the corpus (measured: origin/main 0, that draft 16, through one whole-corpus compile with 32 pre-existing undefined-variable rows as the control) -- because resolving to declarations makes the guard match through aliases and qualified spellings where the authored-name comparison declines, so it adopts in cases it must not. Neither failure was visible to any row here, nor to the emitted-eval-closure measurements, nor to the self-host fixed point. Do not read a green here as evidence the instantiation works; read it as evidence nothing was wrapped that should not have been.\n\ndissolve-on: constructor ownership and constructor VALUE TYPE become separate facts, so a coproduct declaration node has no route into a type position at all (a NeedsContext / Refused arm instead of a declaration-shaped fallback). At that point adoption is not a heuristic to guard and this row is replaced by the unwritability of the state." +// PERMANENT REGRESSION CONTROL for the cardinality half of bare-variant expected-type adoption. +// +// THE UNDERLYING DEFECT, measured on the emitted v2.compiler.05_eval closure: a bare variant +// reference infers as its OWNER COPRODUCT'S DECLARATION NODE, whose children are the coproduct's +// ARMS rather than type arguments. `type Optional = Absent | Present { value: T }` declares +// Absent as child 0, so a generic owner reaching the renderer uninstantiated renders +// `Option` -- a constructor in type position, not a Rust type. Measured baseline on current +// main: 21 such sites (17 v2_compiler_body_lowering_fold, 2 v2_compiler_infer, 2 +// v2_std_cardinality) and 494 rustc errors; after the repair 0 sites and 473 errors, the delta +// being -19 E0425 and -2 E0573 (expected type, found variant) with NO rustc code increasing. The +// repair is in v1.compiler.infer: when the context supplies an expected type that owns the variant, +// that expected node IS the instantiated owner, so it is adopted in place of the declaration node. +// +// WHAT THIS FILE GUARDS, AND WHY IT IS THE CARDINALITY HALF RATHER THAN THE HEADLINE DEFECT. +// Adoption must be refused when the variant is reached through an OPTIONAL COERCION rather than +// owned at the expected type's own level. Optionality is not a wrapper type in this model -- +// `BinOp?` is a BinOp node whose return_cardinality is CardOptional (v1.compiler.core +// with_optional_cardinality) -- so a head-name comparison cannot see it. For a record field `binop: +// BinOp?` initialised with the bare arm `Mod`, the head IS BinOp and the arm IS found, but the +// constructor's own type is BinOp and the optionality is a coercion the emitter performs by +// wrapping. Adopting the expected node there makes the value look already-optional, the wrap is +// skipped, and `binop: BinOp::Mod` is emitted where `Some(BinOp::Mod)` is owed. +// +// THAT IS NOT HYPOTHETICAL: two successive drafts of the repair shipped it. The first adopted +// whenever the PEELED coproduct matched (expand_scrut_type_for_variant_lookup peels to find the +// arm-bearing coproduct); the second compared the UNPEELED head, on the incorrect assumption that +// `BinOp?` is a wrapper named Optional. Both dropped the wrapper across four +// extdeps.languages.*_syntax modules and std.effects. The admitted form additionally requires the +// expected node to be Required. +// +// WHY THE SELF-HOST FIXED POINT FOUND THIS AND NOTHING ELSE DID, recorded because it is the +// transferable part: the Option count, the whole-artifact diff of the emitted eval closure, +// and the rustc error census ALL stayed green across both wrong drafts, because all three measure +// the eval closure and the regression lived in v1's OWN emitted sources. A population that could +// not have disagreed cannot falsify. regen_stage0 --verify re-emits the seed and was the only +// instrument whose subject included the damage. +// +// WHY THE HEADLINE Option CASE HAS NO ROW HERE, established by execution rather than +// asserted: it is UNREACHABLE through this harness. It requires the v2 `Optional` coproduct as a +// declared generic type AND the variant name Absent to be AMBIGUOUSLY owned across the closure (the +// emitter's derive_variant_to_enum sentinel is what suppresses the collapse-to-unit that would +// otherwise render `_`). `Optional` is not declared anywhere in the dag corpus -- it is the +// built-in `T?` sugar, and the named coproduct lives in v2.std.optional -- so a dag-rooted single +// source cannot construct the subject, and two coproducts claiming one arm name inside ONE module +// are refused outright by the compiler. The evidence for that half is the executed corpus +// measurement recorded above, which is a discriminating before/after but is NOT enrolled as a +// recurring control. That asymmetry is stated rather than papered over: the cardinality half below +// is protected on every run, the instantiation half is not. +// +// AND THE ASYMMETRY IS SHARPER THAN 'ONE HALF IS UNCOVERED', PROVEN LIVE RATHER THAN REASONED: BOTH +// ROWS BELOW PASS ON THE UNREPAIRED BASELINE. They are one-directional -- they detect the repair +// OVER-REACHING (adopting where it must not, which is what two abandoned drafts did) and they +// CANNOT detect the repair ceasing to work. That was demonstrated twice during this change. A draft +// that tightened the owner check to declaration identity by span silently reverted the repair to +// its full 21-site baseline; every row here stayed green and only re-measuring the emitted corpus +// noticed. A further draft that normalised both sides through lookup_type_for before comparing +// identity restored the 21 sites BUT introduced 16 incompatible-type errors elsewhere in the corpus +// (measured: origin/main 0, that draft 16, through one whole-corpus compile with 32 pre-existing +// undefined-variable rows as the control) -- because resolving to declarations makes the guard +// match through aliases and qualified spellings where the authored-name comparison declines, so it +// adopts in cases it must not. Neither failure was visible to any row here, nor to the +// emitted-eval-closure measurements, nor to the self-host fixed point. Do not read a green here as +// evidence the instantiation works; read it as evidence nothing was wrapped that should not have +// been. +// +// dissolve-on: constructor ownership and constructor VALUE TYPE become separate facts, so a +// coproduct declaration node has no route into a type position at all (a NeedsContext / Refused arm +// instead of a declaration-shaped fallback). At that point adoption is not a heuristic to guard and +// this row is replaced by the unwritability of the state. // A record field whose declared type is OPTIONAL, initialised with a bare arm of the // INNER coproduct. The arm is owned by Sign, not by the optional; the wrap is the diff --git a/dag/test/claim/emitter_callable_field_capture_witness_test.dag b/dag/test/claim/emitter_callable_field_capture_witness_test.dag index c86f2534710..7cfbfc37a19 100644 --- a/dag/test/claim/emitter_callable_field_capture_witness_test.dag +++ b/dag/test/claim/emitter_callable_field_capture_witness_test.dag @@ -1,6 +1,37 @@ module test.claim.emitter_callable_field_capture_witness_test -data emitter_callable_field_capture_note: String = "PERMANENT REGRESSION CONTROL for the arrow-typed record-field callable position (gunbc#8799). THE DEFECT, now repaired: v1.compiler.emit_rust wrap_rust_record_field_value wrapped an arrow-typed field with the GENERIC SHARING ctor (rust_shared_wrap_ctor, Rc::new(\{0\})) instead of the Rust row that exists for a callable position (callable_value_wrap_template, Rc::new(move \{0\}), already consumed at the arrow-typed fn RETURN by rust_callable_return_wrap). An arrow realizes as Rc ..>, a dyn trait object defaults to 'static, so a non-move closure captured the enclosing locals BY REFERENCE and rustc refused every coercion. Population at d72ffe8708 on the src/v2/compiler/03_ingest.dag closure: 27 E0597 sites, and the measurement is what establishes the population is ONE mechanism rather than the description asserting it -- 27 of 27 blocks carry the same 'due to object lifetime defaults' note and every specimen is a lambda in an arrow-typed record-literal field, eight of them NodeFold \{ init, step \}. WHY THIS FILE CARRIES TWO FAILURE MODES AND NOT ONE: `move` ALONE IS A DIFFERENT REFUSAL, NOT A REPAIR. The shape that produces these sites is one record with SEVERAL arrow fields over the SAME enclosing locals (v2_compiler_compile.rs run_required_lens_gates_on_subtree captures `inferred` and `lenses` in one closure; v2_compiler_infer.rs infer_gather_fold_algebra captures `partials` in two sibling closures), so wrapping siblings in bare `move` moves one local twice -- E0382 in place of E0597. A witness that could not distinguish those two would pass for the wrong repair, so the assertions below refuse BOTH: the capture-preamble text cannot be produced by the pre-fix shape (no `move`) NOR by the naive-move shape (no preamble). Three arms pinned at rustc directly, each discriminating: the pre-fix emission refuses E0597 x3, the naive-move emission refuses E0382, the landed emission compiles clean. THE PROPERTY THAT MAKES THE CLONE SAFE RATHER THAN A DODGE, and the reason derived_capture_set_excludes_unnamed_local is a load-bearing row rather than a nicety: the capture set is DERIVED -- expr_var_occurrence_names over the lambda subtree intersected with scope.body_locals, the strict body-grain binder set -- and never widened to every local in scope. A widened set would be correct at every site, unbounded in cost, and INDISTINGUISHABLE FROM A PRECISE ONE by any assertion that only checks the build is green; asserting that `init` does not clone `scale` is what makes the precision executable. KNOWN NARROWING, stated rather than implied covered: the wrap fires on a lambda appearing SYNTACTICALLY at the field-init position. A non-lambda value, and a lambda behind a block / if / match, take the unchanged path -- that is the measured 27-site population and no more. It is the same residue rust_callable_return_wrap already declares at the arrow-typed RETURN, and closing either is a tail-position walk rather than a wider predicate here." +// PERMANENT REGRESSION CONTROL for the arrow-typed record-field callable position (gunbc#8799). THE +// DEFECT, now repaired: v1.compiler.emit_rust wrap_rust_record_field_value wrapped an arrow-typed +// field with the GENERIC SHARING ctor (rust_shared_wrap_ctor, Rc::new({0})) instead of the Rust row +// that exists for a callable position (callable_value_wrap_template, Rc::new(move {0}), already +// consumed at the arrow-typed fn RETURN by rust_callable_return_wrap). An arrow realizes as Rc ..>, a dyn trait object defaults to 'static, so a non-move closure captured the +// enclosing locals BY REFERENCE and rustc refused every coercion. Population at d72ffe8708 on the +// src/v2/compiler/03_ingest.dag closure: 27 E0597 sites, and the measurement is what establishes +// the population is ONE mechanism rather than the description asserting it -- 27 of 27 blocks carry +// the same 'due to object lifetime defaults' note and every specimen is a lambda in an arrow-typed +// record-literal field, eight of them NodeFold { init, step }. WHY THIS FILE CARRIES TWO FAILURE +// MODES AND NOT ONE: `move` ALONE IS A DIFFERENT REFUSAL, NOT A REPAIR. The shape that produces +// these sites is one record with SEVERAL arrow fields over the SAME enclosing locals +// (v2_compiler_compile.rs run_required_lens_gates_on_subtree captures `inferred` and `lenses` in +// one closure; v2_compiler_infer.rs infer_gather_fold_algebra captures `partials` in two sibling +// closures), so wrapping siblings in bare `move` moves one local twice -- E0382 in place of E0597. +// A witness that could not distinguish those two would pass for the wrong repair, so the assertions +// below refuse BOTH: the capture-preamble text cannot be produced by the pre-fix shape (no `move`) +// NOR by the naive-move shape (no preamble). Three arms pinned at rustc directly, each +// discriminating: the pre-fix emission refuses E0597 x3, the naive-move emission refuses E0382, the +// landed emission compiles clean. THE PROPERTY THAT MAKES THE CLONE SAFE RATHER THAN A DODGE, and +// the reason derived_capture_set_excludes_unnamed_local is a load-bearing row rather than a nicety: +// the capture set is DERIVED -- expr_var_occurrence_names over the lambda subtree intersected with +// scope.body_locals, the strict body-grain binder set -- and never widened to every local in scope. +// A widened set would be correct at every site, unbounded in cost, and INDISTINGUISHABLE FROM A +// PRECISE ONE by any assertion that only checks the build is green; asserting that `init` does not +// clone `scale` is what makes the precision executable. KNOWN NARROWING, stated rather than implied +// covered: the wrap fires on a lambda appearing SYNTACTICALLY at the field-init position. A +// non-lambda value, and a lambda behind a block / if / match, take the unchanged path -- that is +// the measured 27-site population and no more. It is the same residue rust_callable_return_wrap +// already declares at the arrow-typed RETURN, and closing either is a tail-position walk rather +// than a wider predicate here. fn w_arrow_field_lambda_owns_its_captures() -> Bool { compile_dag_rust_emit_check( diff --git a/dag/test/claim/emitter_nested_refinement_cast_witness_test.dag b/dag/test/claim/emitter_nested_refinement_cast_witness_test.dag index cdb91060f79..27cb4c409ef 100644 --- a/dag/test/claim/emitter_nested_refinement_cast_witness_test.dag +++ b/dag/test/claim/emitter_nested_refinement_cast_witness_test.dag @@ -1,6 +1,27 @@ module test.claim.emitter_nested_refinement_cast_witness_test -data emitter_nested_refinement_cast_witness_note: String = "Emission-level control for the carrier class that broke gunbc#7480: a where-refinement whose BASE is itself a refined type (NonEmptyStr where pred) is a carrier composition the v1 Rust emitter cannot lower, so instead of refusing at emit time it emits panic!(\"unsupported cast from String to NonEmptyStr\") into the generated Rust. The round-trip witness in content_hash_family_grounded_witness_test.dag does NOT discriminate this class — it was proven green against both the defective and the repaired carrier, because the defect is emission-only and never reaches R0 evaluation. This file is the emission-level evidence the round-trip witness cannot supply. Two poles, both executed: single_refinement is the accepted positive control (the repaired shape, String where pred, emits no unsupported cast), and nested_refinement is a KNOWN-RED RECEIPT, not a RED control: it PASSES while the deficit remains, so its polarity is inverted from a conventional control -- it goes red when the emitter is fixed, which is the signal to rewrite both poles. The deficit is deliberately asserted as PRESENT rather than fixed: repairing the emitter to lower nested refinements is an emitter feature outside this PR's scope, so the deficit is recorded here as a typed, counted, executing fact instead of an unmarked silence (DESIGN section 4b — no untracked stall; the reported rung must equal the rung executed evidence establishes). NOTE the emitter arm itself is a section 5 fail-open: an unsupported cast should be a located refusal at emit time, never a panic fabricated into generated code — in gunbc#7480 exactly one such panic masked a second one, and the masked one would have paniced at runtime on any accepted non-SHA OCI digest. dissolve-on: feature:emitter-nested-refinement-lowering — when the emitter either lowers nested refinements or refuses them at emit time, the known-red receipt flips and BOTH poles are rewritten to assert the refusal." +// Emission-level control for the carrier class that broke gunbc#7480: a where-refinement whose BASE +// is itself a refined type (NonEmptyStr where pred) is a carrier composition the v1 Rust emitter +// cannot lower, so instead of refusing at emit time it emits panic!("unsupported cast from String +// to NonEmptyStr") into the generated Rust. The round-trip witness in +// content_hash_family_grounded_witness_test.dag does NOT discriminate this class — it was proven +// green against both the defective and the repaired carrier, because the defect is emission-only +// and never reaches R0 evaluation. This file is the emission-level evidence the round-trip witness +// cannot supply. Two poles, both executed: single_refinement is the accepted positive control (the +// repaired shape, String where pred, emits no unsupported cast), and nested_refinement is a +// KNOWN-RED RECEIPT, not a RED control: it PASSES while the deficit remains, so its polarity is +// inverted from a conventional control -- it goes red when the emitter is fixed, which is the +// signal to rewrite both poles. The deficit is deliberately asserted as PRESENT rather than fixed: +// repairing the emitter to lower nested refinements is an emitter feature outside this PR's scope, +// so the deficit is recorded here as a typed, counted, executing fact instead of an unmarked +// silence (DESIGN section 4b — no untracked stall; the reported rung must equal the rung executed +// evidence establishes). NOTE the emitter arm itself is a section 5 fail-open: an unsupported cast +// should be a located refusal at emit time, never a panic fabricated into generated code — in +// gunbc#7480 exactly one such panic masked a second one, and the masked one would have paniced at +// runtime on any accepted non-SHA OCI digest. dissolve-on: +// feature:emitter-nested-refinement-lowering — when the emitter either lowers nested refinements or +// refuses them at emit time, the known-red receipt flips and BOTH poles are rewritten to assert the +// refusal. fn w_single_refinement_emits_no_unsupported_cast() -> Bool { compile_dag_rust_emit_check( diff --git a/dag/test/claim/emitter_optional_payload_cast_witness_test.dag b/dag/test/claim/emitter_optional_payload_cast_witness_test.dag index d10e650acfd..959f539f354 100644 --- a/dag/test/claim/emitter_optional_payload_cast_witness_test.dag +++ b/dag/test/claim/emitter_optional_payload_cast_witness_test.dag @@ -1,6 +1,31 @@ module test.claim.emitter_optional_payload_cast_witness_test -data emitter_optional_payload_cast_witness_note: String = "Permanent regression control for optional-payload cast lowering (gunbc#7480). THE DEFECT, now repaired: a cast reaching an optional-variant payload -- Present { value: as T } -- gave the record literal a concrete resolved type, which made the concrete-type peel in v1.compiler.emit_rust emit_rust_expr_record_lit overwrite the AUTHORED name `Present` with the payload's concrete type name. emit_typed_record_lit then no longer recognised the literal as an optional constructor, fell through to the generic arm, and fabricated `Optional::String { value: .. }` -- not a Rust constructor -- so the emitted crate failed to compile with E0433 (use of undeclared type `Optional`). THE CONFIRMED NAME-LOSS POINT is that peel in the CALLER, established by INSTRUMENTATION rather than by reading: a probe printed variant_name/tn/peeled at the call site and showed the authored name arriving intact and then being replaced. It was NOT emit_typed_record_lit's variant_surface_name fallback, which was the standing hypothesis. That fallback is nonetheless a real SECOND contributor -- with the peel fixed, optional_variant still keyed off the resolved struct name until variant_surface_name was in the seed -- so BOTH were required and neither alone sufficed; the single-cause hypothesis was wrong in both directions. POLARITY: poles 2 and 3 were known-red receipts asserting the deficit was PRESENT; the repair flipped them, and per DESIGN section 4b a probe that greens when its wall lands becomes a PERMANENT regression control rather than retiring, which is what they are now. Pole 3 is the one that refuted the obvious workaround -- hoisting the cast to a `let` did NOT avoid the defect, so no respelling could have dodged it and the emitter repair was required rather than optional. The two negative controls are the load-bearing half of the gate: user_enum_cast_payload proves an ordinary enum variant still peels to Wrap::Holds, and user_defined_present proves an enum declaring its OWN `Present` variant is unaffected -- the suppression keys on the resolved parent genuinely being the built-in Optional, because variant_belongs_to_enum finds a user-declared Present and lets the peel proceed, never on the spelling alone. This file does NOT cover nested-refinement lowering, a separate open deficit tracked by emitter_nested_refinement_cast_witness_test.dag." +// Permanent regression control for optional-payload cast lowering (gunbc#7480). THE DEFECT, now +// repaired: a cast reaching an optional-variant payload -- Present { value: as T } -- gave +// the record literal a concrete resolved type, which made the concrete-type peel in +// v1.compiler.emit_rust emit_rust_expr_record_lit overwrite the AUTHORED name `Present` with the +// payload's concrete type name. emit_typed_record_lit then no longer recognised the literal as an +// optional constructor, fell through to the generic arm, and fabricated `Optional::String { value: +// .. }` -- not a Rust constructor -- so the emitted crate failed to compile with E0433 (use of +// undeclared type `Optional`). THE CONFIRMED NAME-LOSS POINT is that peel in the CALLER, +// established by INSTRUMENTATION rather than by reading: a probe printed variant_name/tn/peeled at +// the call site and showed the authored name arriving intact and then being replaced. It was NOT +// emit_typed_record_lit's variant_surface_name fallback, which was the standing hypothesis. That +// fallback is nonetheless a real SECOND contributor -- with the peel fixed, optional_variant still +// keyed off the resolved struct name until variant_surface_name was in the seed -- so BOTH were +// required and neither alone sufficed; the single-cause hypothesis was wrong in both directions. +// POLARITY: poles 2 and 3 were known-red receipts asserting the deficit was PRESENT; the repair +// flipped them, and per DESIGN section 4b a probe that greens when its wall lands becomes a +// PERMANENT regression control rather than retiring, which is what they are now. Pole 3 is the one +// that refuted the obvious workaround -- hoisting the cast to a `let` did NOT avoid the defect, so +// no respelling could have dodged it and the emitter repair was required rather than optional. The +// two negative controls are the load-bearing half of the gate: user_enum_cast_payload proves an +// ordinary enum variant still peels to Wrap::Holds, and user_defined_present proves an enum +// declaring its OWN `Present` variant is unaffected -- the suppression keys on the resolved parent +// genuinely being the built-in Optional, because variant_belongs_to_enum finds a user-declared +// Present and lets the peel proceed, never on the spelling alone. This file does NOT cover +// nested-refinement lowering, a separate open deficit tracked by +// emitter_nested_refinement_cast_witness_test.dag. fn w_optional_payload_cast_lowers_to_some() -> Bool { compile_dag_rust_emit_check( diff --git a/dag/test/claim/emitter_optional_present_branded_scalar_witness_test.dag b/dag/test/claim/emitter_optional_present_branded_scalar_witness_test.dag index d96d57b01b6..ac4e9d1ffcb 100644 --- a/dag/test/claim/emitter_optional_present_branded_scalar_witness_test.dag +++ b/dag/test/claim/emitter_optional_present_branded_scalar_witness_test.dag @@ -1,6 +1,12 @@ module test.claim.emitter_optional_present_branded_scalar_witness_test -data emitter_optional_present_branded_scalar_witness_note: String = "Emitter regression control for Present { value: text as NonEmptyStr } inside a NonEmptyStr? return: the erased payload type is String, so optional detection must use the variant surface name (Present) and fn_returns_optional, not the erased tn. Without that, the emitter falls through to Optional::String { value: ... } in the body (return types may still mention Optional::String). Incidental coverage via extdeps.container.oci.digest seed membership is Class B accidental coverage (#6985); this witness is the declared durable control. dissolve-on: never — permanent regression alarm for the emitter arm." +// Emitter regression control for Present { value: text as NonEmptyStr } inside a NonEmptyStr? +// return: the erased payload type is String, so optional detection must use the variant surface +// name (Present) and fn_returns_optional, not the erased tn; otherwise the emitter falls through to +// Optional::String { value: ... } in the body (return types may still mention Optional::String). +// Incidental coverage via extdeps.container.oci.digest seed membership is Class B accidental +// coverage (#6985); this witness is the declared durable control. dissolve-on: never — permanent +// regression alarm for the emitter arm. fn w_present_branded_scalar_cast_emits_some() -> Bool { compile_dag_rust_emit_check( diff --git a/dag/test/claim/emitter_sole_constructor_seal_witness_test.dag b/dag/test/claim/emitter_sole_constructor_seal_witness_test.dag index 9b794ae0b82..683e4d5f16d 100644 --- a/dag/test/claim/emitter_sole_constructor_seal_witness_test.dag +++ b/dag/test/claim/emitter_sole_constructor_seal_witness_test.dag @@ -1,30 +1,27 @@ module test.claim.emitter_sole_constructor_seal_witness_test -// Permanent regression control for the sole_constructor emission seal. THE DEFECT, now -// repaired: `sole_constructor` is parsed onto a type declaration and consumed by inference -// to refuse a cross-module record literal, but the RUST EMITTER read the fact zero times, -// so the model's seal did not survive lowering. DESIGN section 4b carries the executed -// receipt for the specimen -- `extdeps.uri` `UriValidatedScalar` emitted byte-identical to -// the plain record beside it, public field and derived Deserialize, and both a direct -// struct literal and serde_json admitted values its mint refuses, two of which reached -// output as invalid percent-encoding. That was the single BELOW-FLOOR item in that -// paragraph, and this file is the control that keeps it closed. +// Permanent regression control for the sole_constructor emission seal. THE DEFECT, now repaired: +// `sole_constructor` is parsed onto a type declaration and consumed by inference to refuse a +// cross-module record literal, but the RUST EMITTER read the fact zero times, so the model's seal +// did not survive lowering. DESIGN section 4b carries the executed receipt for the specimen -- +// `extdeps.uri` `UriValidatedScalar` emitted byte-identical to the plain record beside it, public +// field and derived Deserialize, and both a direct struct literal and serde_json admitted values +// its mint refuses, two of which reached output as invalid percent-encoding. That was the single +// BELOW-FLOOR item in that paragraph; this file is the control that keeps it closed. // -// WHAT THE SEAL IS AND IS NOT. It confines CONSTRUCTION, not ACCESS: the model lets any -// module read a sole_constructor value, so the emitted shape is a private field PLUS a -// public accessor, and a shape that also confined reading would refuse programs the model -// accepts. Serialize is retained for the same reason -- writing a value out is a read. -// Deserialize is not, because a derived Deserialize is a second, unsealed mint standing -// beside the declared one. +// WHAT THE SEAL IS AND IS NOT. It confines CONSTRUCTION, not ACCESS: the model lets any module +// read a sole_constructor value, so the emitted shape is a private field PLUS a public accessor; a +// shape that also confined reading would refuse programs the model accepts. Serialize is retained +// for the same reason -- writing a value out is a read. Deserialize is not, because a derived +// Deserialize is a second, unsealed mint beside the declared one. // -// THE NEGATIVE CONTROLS ARE THE LOAD-BEARING HALF. A plain record in the same fixture must -// keep its public field and its Deserialize, or this witness would pass equally over an -// emitter that sealed everything -- which is a different realization, not a faithful one. -// The two rustc receipts behind the repair (E0451 on a cross-module literal, E0277 on -// serde_json::from_str) are compile-time facts about the emitted crate that this -// byte-level instrument cannot itself execute; they are recorded in the PR that landed -// this file. What this witness holds is the emitted SHAPE those receipts depend on, which -// is the part an emitter regression would silently move. +// THE NEGATIVE CONTROLS ARE THE LOAD-BEARING HALF. A plain record in the same fixture must keep +// its public field and its Deserialize, or this witness would pass equally over an emitter that +// sealed everything -- a different realization, not a faithful one. The two rustc receipts behind +// the repair (E0451 on a cross-module literal, E0277 on serde_json::from_str) are compile-time +// facts about the emitted crate that this byte-level instrument cannot execute; they are recorded +// in the PR that landed this file. What this witness holds is the emitted SHAPE those receipts +// depend on -- the part an emitter regression would silently move. // // dissolve-on: never -- permanent regression alarm for the emitter arm. diff --git a/dag/test/claim/emitter_variant_tag_reference_witness_test.dag b/dag/test/claim/emitter_variant_tag_reference_witness_test.dag index 70cb995713d..7e705f8789f 100644 --- a/dag/test/claim/emitter_variant_tag_reference_witness_test.dag +++ b/dag/test/claim/emitter_variant_tag_reference_witness_test.dag @@ -1,6 +1,37 @@ module test.claim.emitter_variant_tag_reference_witness_test -data emitter_variant_tag_reference_witness_note: String = "PERMANENT REGRESSION CONTROL for the variant-tag-reference lowering in v1.compiler.emit_rust (emit_discriminant_call_lowering / discriminant_zero_field_variant_tag).\n\nTHE DEFECT. `discriminant(v: X {})` is the corpus-wide idiom for naming a coproduct variant to obtain its stable tag identity; the frontend sanctions exactly this shape as a TAG REFERENCE rather than a construction (v1.compiler.infer zero_field_variant_tag_reference_frontier_note, operator Ruling 1a, 2026-07-15). The Rust lowering did not honour the same reading: it emitted the argument as an ordinary expression and matched over it, so a fieldless variant lowered to a valid empty struct literal and compiled, while a variant carrying required fields lowered to `Parent::X {}` -- unwritable in Rust, rustc E0063. Measured population at the repair: 162 sites of the idiom corpus-wide, of which 145 name a FIELDLESS variant (the six ModelCorePrimitiveFactAxis arms) and 17 name a FIELDED one (CanonicalOperation and TargetOperatorShape, all in src/v2/std/compilers/target_model.dag). The 17 were the visible tip; the class was the idiom, not the file.\n\nTHE REPAIR IS A FOLD, NOT A RENDERING FIX. The variant is named statically at every one of the 162 sites, so its discriminant is a compile-time constant. The lowering now folds to that name and emits NO construction at all -- which is why it is stated as a DESIGN section 2 point rather than a section 5 one: constructing an instance to read a name the source already wrote is a second representation of that name, and it is only for a FIELDED variant that the redundancy also happens to be unwritable. The 145 fieldless sites are repaired in the same motion; they were never broken, they were paying for a construction and a match to recover a constant.\n\nWHAT THESE ROWS DO AND DO NOT ESTABLISH. Row one is the discriminating RED: it is red on the unrepaired emitter (which emits `Fielded {` and no folded literal) and green after. Row two is the negative control that keeps the fold from being satisfiable by folding EVERY discriminant call: a discriminant over a runtime VALUE has no static tag and must still lower to a match over the scrutinee, so it requires the match and forbids a folded literal. Without row two a lowering that answered every discriminant with the first variant name it could find would pass row one.\n\nNeither row observes the 162 production sites; they exercise the lowering through a controlled fixture, which is what makes them a control rather than a snapshot of the corpus." +// PERMANENT REGRESSION CONTROL for the variant-tag-reference lowering in v1.compiler.emit_rust +// (emit_discriminant_call_lowering / discriminant_zero_field_variant_tag). +// +// THE DEFECT. `discriminant(v: X {})` is the corpus-wide idiom for naming a coproduct variant to +// obtain its stable tag identity; the frontend sanctions exactly this shape as a TAG REFERENCE +// rather than a construction (v1.compiler.infer zero_field_variant_tag_reference_frontier_note, +// operator Ruling 1a, 2026-07-15). The Rust lowering did not honour the same reading: it emitted +// the argument as an ordinary expression and matched over it, so a fieldless variant lowered to a +// valid empty struct literal and compiled, while a variant carrying required fields lowered to +// `Parent::X {}` -- unwritable in Rust, rustc E0063. Measured population at the repair: 162 sites +// of the idiom corpus-wide, of which 145 name a FIELDLESS variant (the six +// ModelCorePrimitiveFactAxis arms) and 17 name a FIELDED one (CanonicalOperation and +// TargetOperatorShape, all in src/v2/std/compilers/target_model.dag). The 17 were the visible tip; +// the class was the idiom, not the file. +// +// THE REPAIR IS A FOLD, NOT A RENDERING FIX. The variant is named statically at every one of the +// 162 sites, so its discriminant is a compile-time constant. The lowering now folds to that name +// and emits NO construction at all -- which is why it is stated as a DESIGN section 2 point rather +// than a section 5 one: constructing an instance to read a name the source already wrote is a +// second representation of that name, and it is only for a FIELDED variant that the redundancy also +// happens to be unwritable. The 145 fieldless sites are repaired in the same motion; they were +// never broken, they were paying for a construction and a match to recover a constant. +// +// WHAT THESE ROWS DO AND DO NOT ESTABLISH. Row one is the discriminating RED: it is red on the +// unrepaired emitter (which emits `Fielded {` and no folded literal) and green after. Row two is +// the negative control that keeps the fold from being satisfiable by folding EVERY discriminant +// call: a discriminant over a runtime VALUE has no static tag and must still lower to a match over +// the scrutinee, so it requires the match and forbids a folded literal. Without row two a lowering +// that answered every discriminant with the first variant name it could find would pass row one. +// +// Neither row observes the 162 production sites; they exercise the lowering through a controlled +// fixture, which is what makes them a control rather than a snapshot of the corpus. // THE DISCRIMINATING RED, and BOTH ARMS ARE MEASURED rather than one measured and one // assumed. The forbidden spelling is the CONSTRUCTOR WITH EMPTY BRACES, and it is that diff --git a/dag/test/claim/endpoint_authority_replacement_cut_witness_test.dag b/dag/test/claim/endpoint_authority_replacement_cut_witness_test.dag index a621b191fa0..d4bda06386f 100644 --- a/dag/test/claim/endpoint_authority_replacement_cut_witness_test.dag +++ b/dag/test/claim/endpoint_authority_replacement_cut_witness_test.dag @@ -24,7 +24,21 @@ import gunbc.endpoint_authority_replacement_cut { } import gunbc.replacement_cut_registry { production_registry_standing } -data endpoint_authority_replacement_cut_witness_note: String = "THE PRODUCTION ROWS, EXECUTED. The generic carrier suite exercises synthetic cuts and synthetic registries; whole-tree compilation proves these declarations typecheck. Neither establishes what the REAL endpoint cut and the REAL registry answer, so before this file the production rows could acquire a duplicate relation, an authoring-defect cause, a malformed region or a wrong evidence disposition while every reported suite stayed green. That is the specification-without-execution trap applied to the one part of the change that is not a mechanism but a claim about this repository.\n\nWHAT THE REFUSAL MUST AND MUST NOT CONTAIN is the whole point of the first two rows. The plan is EXPECTED to refuse -- Y does not exist, so every surviving consumer is CoverageOpen -- but it must refuse for exactly that reason and no other. An authoring defect (a duplicated relation, a coverage claim naming the old root, an undispositioned row, an empty region) would also produce PlanRefused, so asserting `refuses` alone would pass over a broken row. The partition is therefore asserted in both directions: every cause is UncoveredSurvivingConsumer, and the count equals the census." +// THE PRODUCTION ROWS, EXECUTED. The generic carrier suite exercises synthetic cuts and synthetic +// registries; whole-tree compilation proves these declarations typecheck. Neither establishes what +// the REAL endpoint cut and the REAL registry answer, so before this file the production rows could +// acquire a duplicate relation, an authoring-defect cause, a malformed region or a wrong evidence +// disposition while every reported suite stayed green. That is the specification-without-execution +// trap applied to the one part of the change that is not a mechanism but a claim about this +// repository. +// +// WHAT THE REFUSAL MUST AND MUST NOT CONTAIN is the whole point of the first two rows. The plan is +// EXPECTED to refuse -- Y does not exist, so every surviving consumer is CoverageOpen -- but it +// must refuse for exactly that reason and no other. An authoring defect (a duplicated relation, a +// coverage claim naming the old root, an undispositioned row, an empty region) would also produce +// PlanRefused, so asserting `refuses` alone would pass over a broken row. The partition is +// therefore asserted in both directions: every cause is UncoveredSurvivingConsumer, and the count +// equals the census. fn causes_of(admission: PlanAdmission) -> List { match admission { diff --git a/dag/test/claim/env_execution_authority_witness_test.dag b/dag/test/claim/env_execution_authority_witness_test.dag index f15a287ff7a..6f812348556 100644 --- a/dag/test/claim/env_execution_authority_witness_test.dag +++ b/dag/test/claim/env_execution_authority_witness_test.dag @@ -21,7 +21,8 @@ data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly // prove that any call site uses these producers -- a hand-spelled ["env", ...] elsewhere in the // corpus is invisible to this file, and the instrument for that is a construction wall, not an // assertion in a module that must compile. -data env_execution_authority_witness_scope_note: String = "Serialization witness for extdeps.tools.env. Call-site adoption is not in scope and is not evidenced here." +// Serialization witness for extdeps.tools.env. Call-site adoption is not in scope and is not +// evidenced here. test fn an_assignment_occupies_one_argv_element() -> Bool { env_binding_argv(binding: EnvSet { name: "A", value: "b" }) == ["A=b"] diff --git a/dag/test/claim/evaluation_budget_witness_test.dag b/dag/test/claim/evaluation_budget_witness_test.dag index 4fec0493de1..2fa248f8ead 100644 --- a/dag/test/claim/evaluation_budget_witness_test.dag +++ b/dag/test/claim/evaluation_budget_witness_test.dag @@ -57,7 +57,11 @@ test fn witness_over_budget_exceeds_and_names_its_clock() -> Bool { } } -data unset_limit_note: String = "THE DISCRIMINATING HALF. An elapsed value astronomically past any plausible budget must still be WITHIN budget when no limit is declared, because LimitUnset is a policy state rather than a missing number. If this returned exceeded, an unbounded caller would refuse every evaluation the moment the carrier was introduced — the exact regression that makes landing the mechanism unset-by-default unsafe." +// THE DISCRIMINATING HALF. An elapsed value astronomically past any plausible budget must still be +// WITHIN budget when no limit is declared, because LimitUnset is a policy state rather than a +// missing number. If this returned exceeded, an unbounded caller would refuse every evaluation the +// moment the carrier was introduced — the exact regression that makes landing the mechanism +// unset-by-default unsafe. test fn witness_unset_limit_never_exceeds() -> Bool { match evaluation_budget_verdict( @@ -83,7 +87,10 @@ test fn witness_boundary_equal_elapsed_is_within() -> Bool { } } -data nesting_law_note: String = "EARLIEST-DEADLINE-WINS, ASSERTED IN BOTH DIRECTIONS. A one-sided check would pass against the seed's current inverted behavior: arm_eval_deadline overwrites with a fresh baseline, so an inner scope requesting a LONGER limit currently wins and extends its caller's bound. The second conjunct is what fails against that." +// EARLIEST-DEADLINE-WINS, ASSERTED IN BOTH DIRECTIONS. A one-sided check would pass against the +// seed's current inverted behavior: arm_eval_deadline overwrites with a fresh baseline, so an inner +// scope requesting a LONGER limit currently wins and extends its caller's bound. The second +// conjunct is what fails against that. test fn witness_nested_limit_takes_the_smaller() -> Bool { effective_nested_limit_nanos(outer_remaining_nanos: 3000000, inner_limit_nanos: 9000000) == 3000000 diff --git a/dag/test/claim/exact_witness_admission_witness_test.dag b/dag/test/claim/exact_witness_admission_witness_test.dag index 37b89f12d5c..820736d54f0 100644 --- a/dag/test/claim/exact_witness_admission_witness_test.dag +++ b/dag/test/claim/exact_witness_admission_witness_test.dag @@ -61,7 +61,38 @@ import std.dissolution { unbound_dissolution } data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data exact_witness_admission_witness_note: String = "Executes the walls over gunbc.explicit_witness_admission, the one function-grain authority for exact witness admission. THE DISCRIMINATING RED is admission_reaches_the_admitted_function_and_not_its_sibling, and it runs against a SYNTHETIC fixture that this witness authors itself: one admission over a fixture entry holding an expected-red function and an ordinary green one. It asserts the admission reaches the first and NOT the second. Under the representation this lane replaced - a file-grain WitnessExclusionRow beside a probe_red row - the second half was FALSE by construction: the file-level exclusion hid every function in the file while the schedule named one, so the green sibling executed nowhere and the reconciliation still passed, because it only ever asked whether some scheduled row's entry CONTAINED the exclusion pattern. THE FIXTURE IS DELIBERATE AND THE ALTERNATIVE WAS TRIED. The first draft anchored this assertion to the real live instance instead, on the reasoning that a wall is better evidenced by a defect that actually happened. That is normally the stronger move, and here it was the wrong one: it binds the evidence to the defect's CONTINUED EXISTENCE, which is the one thing a wall exists to end. Caught in review before merge - gunbc#7688 dissolves that very quarantine tonight (the operator recorded the seed-honesty verdict, the closing contract greened, and the row climbs out under DESIGN 4b(4)), which would have left this assertion with no subject: passing vacuously or redding for a reason that has nothing to do with the wall. Evidence that must survive a climb has to be constructed so the climb cannot delete it. DESIGN 4b(4) says the climb deletes the production machinery and keeps the evidence enrolled; a live-anchored assertion cannot satisfy that clause because the machinery and the subject are the same rows. THE HISTORICAL RECEIPT, past tense and no longer load-bearing: when this lane opened, the bad state had exactly one live instance, measured on the pre-change tree - seed_honesty_discharge_unavailable_test.dag, 8 of whose 9 functions had no probe row while the file's classification named the whole file QuarantineProbeExpectRed, absorbed as OfflineLocalRecipe by the test/claim/execution/ path policy so the Phase 0(b) orphan refusal never saw them. Everywhere else the file-grain roster form or that refusal already covered it. That instance is a provenance note for why the wall was built, not the thing the wall is tested against. THE REMAINING CLAIMS are the walls over the live rows, and they are population-independent by construction - each is a universal over the admission rows plus a projection identity, so they stay meaningful at any roster size including zero, and none of them is where the discrimination lives. Synthetic RED controls cover the duplicate row, the non-executing cadence, and the file-grain shape that does reach the sibling." +// Executes the walls over gunbc.explicit_witness_admission, the one function-grain authority for +// exact witness admission. THE DISCRIMINATING RED is +// admission_reaches_the_admitted_function_and_not_its_sibling, and it runs against a SYNTHETIC +// fixture that this witness authors itself: one admission over a fixture entry holding an +// expected-red function and an ordinary green one. It asserts the admission reaches the first and +// NOT the second. Under the representation this lane replaced - a file-grain WitnessExclusionRow +// beside a probe_red row - the second half was FALSE by construction: the file-level exclusion hid +// every function in the file while the schedule named one, so the green sibling executed nowhere +// and the reconciliation still passed, because it only ever asked whether some scheduled row's +// entry CONTAINED the exclusion pattern. THE FIXTURE IS DELIBERATE AND THE ALTERNATIVE WAS TRIED. +// The first draft anchored this assertion to the real live instance instead, on the reasoning that +// a wall is better evidenced by a defect that actually happened. That is normally the stronger +// move, and here it was the wrong one: it binds the evidence to the defect's CONTINUED EXISTENCE, +// which is the one thing a wall exists to end. Caught in review before merge - gunbc#7688 dissolves +// that very quarantine tonight (the operator recorded the seed-honesty verdict, the closing +// contract greened, and the row climbs out under DESIGN 4b(4)), which would have left this +// assertion with no subject: passing vacuously or redding for a reason that has nothing to do with +// the wall. Evidence that must survive a climb has to be constructed so the climb cannot delete it. +// DESIGN 4b(4) says the climb deletes the production machinery and keeps the evidence enrolled; a +// live-anchored assertion cannot satisfy that clause because the machinery and the subject are the +// same rows. THE HISTORICAL RECEIPT, past tense and no longer load-bearing: when this lane opened, +// the bad state had exactly one live instance, measured on the pre-change tree - +// seed_honesty_discharge_unavailable_test.dag, 8 of whose 9 functions had no probe row while the +// file's classification named the whole file QuarantineProbeExpectRed, absorbed as +// OfflineLocalRecipe by the test/claim/execution/ path policy so the Phase 0(b) orphan refusal +// never saw them. Everywhere else the file-grain roster form or that refusal already covered it. +// That instance is a provenance note for why the wall was built, not the thing the wall is tested +// against. THE REMAINING CLAIMS are the walls over the live rows, and they are +// population-independent by construction - each is a universal over the admission rows plus a +// projection identity, so they stay meaningful at any roster size including zero, and none of them +// is where the discrimination lives. Synthetic RED controls cover the duplicate row, the +// non-executing cadence, and the file-grain shape that does reach the sibling. test fn exact_witness_admission_walls_hold() -> Bool { explicit_witness_admission_uniqueness_holds() @@ -193,12 +224,26 @@ test fn red_control_file_grain_admission_would_reach_the_sibling() -> Bool { ) } -data red_control_file_grain_note: String = "red_control_file_grain_admission_would_reach_the_sibling is what keeps the discriminating claim from passing vacuously: it runs the SAME predicate over the file-grain shape and shows it DOES reach the sibling, so the false in the primary assertion is a decision about grain rather than a predicate that never matches. Both arms are synthetic, so neither can lose its subject when a live quarantine climbs out." +// red_control_file_grain_admission_would_reach_the_sibling is what keeps the discriminating claim +// from passing vacuously: it runs the SAME predicate over the file-grain shape and shows it DOES +// reach the sibling, so the false in the primary assertion is a decision about grain rather than a +// predicate that never matches. Both arms are synthetic, so neither can lose its subject when a +// live quarantine climbs out. -data live_row_claims_are_population_independent_note: String = "every_live_admission_is_reached_by_its_own_row, every_admission_is_projected_into_exactly_one_cadence_roster and ci_layer_roots_probe_roster_is_the_corpus_projection are universals and identities over the live rows. They hold at any roster size, including zero, and they are deliberately NOT where the discrimination lives - a check whose strength depends on the live population having members is a check that goes quietly vacuous the moment the lane it guards succeeds." +// every_live_admission_is_reached_by_its_own_row, +// every_admission_is_projected_into_exactly_one_cadence_roster and +// ci_layer_roots_probe_roster_is_the_corpus_projection are universals and identities over the live +// rows. They hold at any roster size, including zero, and they are deliberately NOT where the +// discrimination lives - a check whose strength depends on the live population having members is a +// check that goes quietly vacuous the moment the lane it guards succeeds. - -data axis_separation_witness_note: String = "THE AXIS-SEPARATION CLAIM, and the synthetic pair is the whole content of it. Polarity used to be read off the cadence, so the two facts could not disagree and any assertion about them was a tautology. These rows make them disagree on purpose: one row is expected-RED on a NON-quarantine cadence, the other is expected-HOLDS on the quarantine cadence. If anything still derives polarity from the cadence, exactly one of the two assertions below flips. The live-population claims that follow are universals and hold at any roster size — the discrimination lives here, in rows nobody can green by fixing a lane." +// THE AXIS-SEPARATION CLAIM, and the synthetic pair is the whole content of it. Polarity used to be +// read off the cadence, so the two facts could not disagree and any assertion about them was a +// tautology. These rows make them disagree on purpose: one row is expected-RED on a NON-quarantine +// cadence, the other is expected-HOLDS on the quarantine cadence. If anything still derives +// polarity from the cadence, exactly one of the two assertions below flips. The live-population +// claims that follow are universals and hold at any roster size — the discrimination lives here, in +// rows nobody can green by fixing a lane. fn synthetic_long_lane_cadence_but_expected_red() -> ExplicitWitnessAdmission { ExplicitWitnessAdmission { @@ -246,7 +291,14 @@ test fn eval_budget_is_independent_of_cadence_and_of_expected_verdict() -> Bool ) } -data long_budget_union_note: String = "The scheduler ceiling reads the UNION, so a row that declares its own long budget is covered without appearing on the long-lane BATCH roster. The second clause is what makes that a real separation rather than a renaming: a declared-long row is genuinely absent from the batch roster, so it occupies one schedule position, not two. The union is an IDENTITY SET, and the counting clause below is stated as one-occurrence-per-declared-row rather than as a sum of the two input lengths — a sum is only correct while the inputs happen to be disjoint, which is a property of today's population and not of the mechanism, so it would go quietly wrong exactly when a row starts reaching the ceiling through both inputs." +// The scheduler ceiling reads the UNION, so a row that declares its own long budget is covered +// without appearing on the long-lane BATCH roster. The second clause is what makes that a real +// separation rather than a renaming: a declared-long row is genuinely absent from the batch roster, +// so it occupies one schedule position, not two. The union is an IDENTITY SET, and the counting +// clause below is stated as one-occurrence-per-declared-row rather than as a sum of the two input +// lengths — a sum is only correct while the inputs happen to be disjoint, which is a property of +// today's population and not of the mechanism, so it would go quietly wrong exactly when a row +// starts reaching the ceiling through both inputs. fn long_budget_union_occurrences(w: ScheduleWitnessEntry) -> Int { fold(witness_long_eval_budget_entries(), init: 0, f: fn(n, x) { @@ -266,7 +318,15 @@ test fn declared_long_budget_reaches_the_ceiling_roster_without_the_batch_roster && fold(batch, init: true, f: fn(ok, b) { ok && (long_budget_union_occurrences(w: b) == 1) }) } -data long_budget_identity_set_control_note: String = "THE DISCRIMINATING CONTROL FOR THE DEDUP, and it drives the union fold with PLANTED inputs rather than observing the live one. A control that reads only the live union cannot see the dedup at all: today's two inputs are disjoint, so deleting the membership check changes nothing observable and the control passes either way — measured, not assumed (removing the check left both live clauses green). The plant supplies the overlap the population does not currently have, so the first clause fails the moment the fold stops joining on identity. Third clause is the negative pole: a row on neither input is absent, so membership is not answering true for everything. Fourth: a genuinely distinct row is kept, so the dedup is not collapsing on something coarser than identity." +// THE DISCRIMINATING CONTROL FOR THE DEDUP, and it drives the union fold with PLANTED inputs rather +// than observing the live one. A control that reads only the live union cannot see the dedup at +// all: today's two inputs are disjoint, so deleting the membership check changes nothing observable +// and the control passes either way — measured, not assumed (removing the check left both live +// clauses green). The plant supplies the overlap the population does not currently have, so the +// first clause fails the moment the fold stops joining on identity. Third clause is the negative +// pole: a row on neither input is absent, so membership is not answering true for everything. +// Fourth: a genuinely distinct row is kept, so the dedup is not collapsing on something coarser +// than identity. fn synthetic_union_row(f: String) -> ScheduleWitnessEntry { ScheduleWitnessEntry { @@ -317,9 +377,19 @@ test fn declared_long_budget_row_is_known_red_or_executing_green() -> Bool { }) } -data both_axes_on_one_row_note: String = "RETIRED CLAIM: every_declared_long_budget_row_is_also_expected_red_today observed that every SubstrateLongLaneEvalBudget row was also known-red — true until #8395 landed infer_transform_add_vertical_witness_holds (ExpectWitnessHolds). Replacement: declared_long_budget_row_is_known_red_or_executing_green — a declared-long row is either known-red OR an executing green witness on explicit_witness_admission_executing_witness_roster, never batch-roster-only." +// RETIRED CLAIM: every_declared_long_budget_row_is_also_expected_red_today observed that every +// SubstrateLongLaneEvalBudget row was also known-red — true until #8395 landed +// infer_transform_add_vertical_witness_holds (ExpectWitnessHolds). Replacement: +// declared_long_budget_row_is_known_red_or_executing_green — a declared-long row is either +// known-red OR an executing green witness on explicit_witness_admission_executing_witness_roster, +// never batch-roster-only. -data budget_partition_witness_note: String = "THE RECUT CLAIM. Two facts have to hold together and neither alone is enough: the two batches must PARTITION the lane (every known-red corpus row on exactly one side, nothing invented, nothing dropped) and each side must be HOMOGENEOUS in declared budget. A partition alone would be satisfied by any split, including the mixed batch this replaces; homogeneity alone would be satisfied by dropping every row that does not fit. The population is derived, so these hold at any roster size including an empty long side." +// THE RECUT CLAIM. Two facts have to hold together and neither alone is enough: the two batches +// must PARTITION the lane (every known-red corpus row on exactly one side, nothing invented, +// nothing dropped) and each side must be HOMOGENEOUS in declared budget. A partition alone would be +// satisfied by any split, including the mixed batch this replaces; homogeneity alone would be +// satisfied by dropping every row that does not fit. The population is derived, so these hold at +// any roster size including an empty long side. fn budget_partition_side_count(xs: List) -> Int { length(xs: xs) @@ -380,7 +450,13 @@ test fn each_budget_roster_is_homogeneous_in_declared_budget() -> Bool { }) } -data pre_verdict_roster_witness_note: String = "known_red_pre_verdict_refusal_roster must be a STRICT SUBSET of the known-red roster and must not swallow it, because it is the only population allowed to turn a corpus-level refuse — which carries no per-witness outcome — into agreement. If it ever equals the known-red roster, the narrowing this claim exists to hold has been undone and any resolve failure in a known-red batch reports every quarantine as holding again. The synthetic pair below is the discrimination: the same predicate answers true for a declared pre-verdict row and false for an ordinary known-red row, so the live subset relation is a decision rather than a predicate that never matches." +// known_red_pre_verdict_refusal_roster must be a STRICT SUBSET of the known-red roster and must not +// swallow it, because it is the only population allowed to turn a corpus-level refuse — which +// carries no per-witness outcome — into agreement. If it ever equals the known-red roster, the +// narrowing this claim exists to hold has been undone and any resolve failure in a known-red batch +// reports every quarantine as holding again. The synthetic pair below is the discrimination: the +// same predicate answers true for a declared pre-verdict row and false for an ordinary known-red +// row, so the live subset relation is a decision rather than a predicate that never matches. fn synthetic_pre_verdict_row() -> ExplicitWitnessAdmission { known_red_probe_expecting( diff --git a/dag/test/claim/exec_arg_limit_witness_test.dag b/dag/test/claim/exec_arg_limit_witness_test.dag index a39461f2c07..0fc8e8918e9 100644 --- a/dag/test/claim/exec_arg_limit_witness_test.dag +++ b/dag/test/claim/exec_arg_limit_witness_test.dag @@ -14,7 +14,12 @@ import v2.std.live_tree { LiveTreeDisposition, ReadsLiveTree } data live_tree_disposition: LiveTreeDisposition = ReadsLiveTree -// Single-authority closure for the Linux per-argument exec ceiling. host_exec_arg_max_strlen is derived (32 * PAGE_SIZE from x86_64_linux_architecture_profile); shell.Exec.Check is the argv-embedding consumer; dispatch_shell in v1_interpreter realizes the typed refusal. witness_rust_const_mirrors_authority cross-checks the Rust seed const against the derived authority; argv_arg_limit_test::dispatch_shell_wiring_refuses_oversized_argv proves the dispatch path in-crate. +// Single-authority closure for the Linux per-argument exec ceiling. host_exec_arg_max_strlen is +// derived (32 * PAGE_SIZE from x86_64_linux_architecture_profile); shell.Exec.Check is the +// argv-embedding consumer; dispatch_shell in v1_interpreter realizes the typed refusal. +// witness_rust_const_mirrors_authority cross-checks the Rust seed const against the derived +// authority; argv_arg_limit_test::dispatch_shell_wiring_refuses_oversized_argv proves the dispatch +// path in-crate. data v1_interpreter_source_path: String = "src/v1/stage0/src/v1_interpreter.rs" test fn witness_host_exec_arg_max_strlen_is_execve_formula() -> Bool { diff --git a/dag/test/claim/external_model_scope_live_cover_witness_test.dag b/dag/test/claim/external_model_scope_live_cover_witness_test.dag index c4a7e4eef35..e2220daa2f6 100644 --- a/dag/test/claim/external_model_scope_live_cover_witness_test.dag +++ b/dag/test/claim/external_model_scope_live_cover_witness_test.dag @@ -12,7 +12,17 @@ import v2.std.live_tree { LiveTreeDisposition, ReadsLiveTree } data live_tree_disposition: LiveTreeDisposition = ReadsLiveTree -data live_cover_witness_note: String = "The WET half of the ExternalModelScope enrollment wall (split out of external_model_scope_witness_test after the d4bef96 floor red: hermetic discovery executed these fns against the mock corpus, where Filesystem.List directory walks and git.Core.DiffNameStatus have no published operations, so they refused — correct hermetic behavior, wrong lane). This file performs genuinely live host effects (a real directory walk of dag/extdeps; a real git diff freeze..HEAD) and is discovery-excluded via the gunbc.ci_layer_roots wet-integration posture with a documented local recipe. The pure decision fns it executes (scope_cover_holds, manifest_freeze_holds) live on gunbc.extdeps_scope_frontier and keep their hermetic RED controls discovery-enrolled in external_model_scope_witness_test, where the carrier-content check (filesystem_read carve-out, hermetic-safe) also stays per-PR — the discriminating logic runs per-PR; only the live observations (directory walk, git diff) run on the wet lane." +// The WET half of the ExternalModelScope enrollment wall (split out of +// external_model_scope_witness_test after the d4bef96 floor red: hermetic discovery executed these +// fns against the mock corpus, where Filesystem.List directory walks and git.Core.DiffNameStatus +// have no published operations, so they refused — correct hermetic behavior, wrong lane). This file +// performs genuinely live host effects (a real directory walk of dag/extdeps; a real git diff +// freeze..HEAD) and is discovery-excluded via the gunbc.ci_layer_roots wet-integration posture with +// a documented local recipe. The pure decision fns it executes (scope_cover_holds, +// manifest_freeze_holds) live on gunbc.extdeps_scope_frontier and keep their hermetic RED controls +// discovery-enrolled in external_model_scope_witness_test, where the carrier-content check +// (filesystem_read carve-out, hermetic-safe) also stays per-PR — the discriminating logic runs +// per-PR; only the live observations (directory walk, git diff) run on the wet lane. fn read_manifest_rows_live() -> List { let r = filesystem_read(path: legacy_extdeps_scope_frontier_manifest_path) diff --git a/dag/test/claim/external_model_scope_witness_test.dag b/dag/test/claim/external_model_scope_witness_test.dag index f15036ce793..0ef6ebcabdc 100644 --- a/dag/test/claim/external_model_scope_witness_test.dag +++ b/dag/test/claim/external_model_scope_witness_test.dag @@ -34,7 +34,14 @@ import v2.std.live_tree { LiveTreeDisposition, ReadsLiveTree } data live_tree_disposition: LiveTreeDisposition = ReadsLiveTree -data external_model_scope_witness_note: String = "RED and GREEN controls for the external_model_scope_decision KERNEL, in exactly the operator-verdict shapes (gunbc#7556): RED = a generic browser module declaring a Chromium subject scope while carrying Chrome | Firefox | Safari concrete rows is incoherent; GREEN = a shared navigation shape plus separate Chromium and Firefox modules plus a downstream support roster is coherent. These are controls of the decision kernel over DECLARED facts — not proof of an admission wall (the kernel's honesty boundary is external_model_scope_decision_kernel_note; the mechanical wall witnessed here is scope PRESENCE: the frozen-manifest cover accounting below). Plus the staged-enrollment accounting for gunbc.extdeps_scope_frontier's frozen legacy manifest." +// RED and GREEN controls for the external_model_scope_decision KERNEL, in exactly the +// operator-verdict shapes (gunbc#7556): RED = a generic browser module declaring a Chromium subject +// scope while carrying Chrome | Firefox | Safari concrete rows is incoherent; GREEN = a shared +// navigation shape plus separate Chromium and Firefox modules plus a downstream support roster is +// coherent. These are controls of the decision kernel over DECLARED facts — not proof of an +// admission wall (the kernel's honesty boundary is external_model_scope_decision_kernel_note; the +// mechanical wall witnessed here is scope PRESENCE: the frozen-manifest cover accounting below). +// Plus the staged-enrollment accounting for gunbc.extdeps_scope_frontier's frozen legacy manifest. fn subject(module_path: String, decl_name: String) -> ExternalSubjectRef { ExternalSubjectRef { @@ -211,7 +218,9 @@ fn strings_contain(xs: List, s: String) -> Bool { fold(xs, init: false, f: fn(acc, x) { acc || x == s }) } -data manifest_read_note: String = "The frozen legacy manifest is a live-tree input of this witness (one path per line; row count DERIVED by parse_frontier_manifest, never hand-declared). A manifest read failure is a red, never an empty frontier — an unreadable manifest must not widen into 'everything is enrolled'." +// The frozen legacy manifest is a live-tree input of this witness (one path per line; row count +// DERIVED by parse_frontier_manifest, never hand-declared). A manifest read failure is a red, never +// an empty frontier — an unreadable manifest must not widen into 'everything is enrolled'. fn read_manifest_rows() -> List { let r = filesystem_read(path: legacy_extdeps_scope_frontier_manifest_path) @@ -251,7 +260,23 @@ test fn green_scope_placement_admits_carrier_and_machinery_additions() -> Bool { (refused |> count) == 0 } -data base_split_witness_note: String = "Controls for the placement KERNEL, and an explicit statement of what they do NOT cover. They exercise scope_placement_membership_verdict and scope_placement_freeze_verdict over hand-authored observations, so they pin the verdict shape in both directions: an unrostered path in the judged set refuses and names itself, a rostered one admits, and every unreadable-observation arm refuses rather than skipping. WHAT THEY CANNOT SEE (stated because an earlier draft of this note claimed otherwise): these fns are pure in the observation handed to them, so no assertion here can distinguish WHICH BASE produced that observation — the base is bound one frame above, in run_extdeps_scope_placement_gate_body, and a regression that fed the membership arm scope_placement_added_paths (the freeze base) instead of scope_placement_change_added_paths would leave every witness in this file green. The base wiring is covered by EXECUTION of the wet gate, not from here: with the session_dashboard roster row removed so the freeze population carries an unrostered file while the change adds none, the gate returns ExitSuccess under the split wiring and refuses under the old single-base wiring — that perturbation is the discriminating receipt, and it is recorded in the PR rather than encoded here because it requires mutating the roster and a live git observation. Closing that hole in-corpus needs a structural reader over the call graph (a lens asserting which observation fn feeds which arm), which is the honest next step and is not built." +// Controls for the placement KERNEL, and an explicit statement of what they do NOT cover. They +// exercise scope_placement_membership_verdict and scope_placement_freeze_verdict over hand-authored +// observations, so they pin the verdict shape in both directions: an unrostered path in the judged +// set refuses and names itself, a rostered one admits, and every unreadable-observation arm refuses +// rather than skipping. WHAT THEY CANNOT SEE (stated because an earlier draft of this note claimed +// otherwise): these fns are pure in the observation handed to them, so no assertion here can +// distinguish WHICH BASE produced that observation — the base is bound one frame above, in +// run_extdeps_scope_placement_gate_body, and a regression that fed the membership arm +// scope_placement_added_paths (the freeze base) instead of scope_placement_change_added_paths would +// leave every witness in this file green. The base wiring is covered by EXECUTION of the wet gate, +// not from here: with the session_dashboard roster row removed so the freeze population carries an +// unrostered file while the change adds none, the gate returns ExitSuccess under the split wiring +// and refuses under the old single-base wiring — that perturbation is the discriminating receipt, +// and it is recorded in the PR rather than encoded here because it requires mutating the roster and +// a live git observation. Closing that hole in-corpus needs a structural reader over the call graph +// (a lens asserting which observation fn feeds which arm), which is the honest next step and is not +// built. fn exit_reason_of(e: ProcessExit) -> String { scope_placement_failure_reason(exit: e) @@ -409,7 +434,18 @@ test fn frontier_rosters_are_disjoint() -> Bool { && all(scope_machinery_exempt_paths, p => !strings_contain(xs: manifest, s: p)) } -data wet_half_split_note: String = "The live observations (Filesystem.List directory walk of dag/extdeps; git.Core.DiffNameStatus freeze..HEAD) run in dag/test/claim/external_model_scope_live_cover_witness_test.dag — a wet-integration row, discovery-excluded per gunbc.ci_layer_roots (the d4bef96 floor red: hermetic discovery executed those service ops against the mock corpus, which publishes no operation for them). THIS file keeps everything hermetic-safe per-PR: the kernel RED/GREEN controls, the manifest/roster accounting via the filesystem_read carve-out, the carrier-content verification, roster_paths_resolve_on_disk (per-PR roster-to-disk direction: every rostered path across all three rosters must resolve in the checkout — a stale or fabricated row reds via the interpreter's typed hermetic Read refusal, 'no mock_response for operation Read', verified by execution on a nonexistent probe path during development), and the RED controls of the shared pure decision fns (scope_cover_holds, manifest_freeze_holds on gunbc.extdeps_scope_frontier) that the wet file executes against live observations." +// The live observations (Filesystem.List directory walk of dag/extdeps; git.Core.DiffNameStatus +// freeze..HEAD) run in dag/test/claim/external_model_scope_live_cover_witness_test.dag — a +// wet-integration row, discovery-excluded per gunbc.ci_layer_roots (the d4bef96 floor red: hermetic +// discovery executed those service ops against the mock corpus, which publishes no operation for +// them). THIS file keeps everything hermetic-safe per-PR: the kernel RED/GREEN controls, the +// manifest/roster accounting via the filesystem_read carve-out, the carrier-content verification, +// roster_paths_resolve_on_disk (per-PR roster-to-disk direction: every rostered path across all +// three rosters must resolve in the checkout — a stale or fabricated row reds via the interpreter's +// typed hermetic Read refusal, 'no mock_response for operation Read', verified by execution on a +// nonexistent probe path during development), and the RED controls of the shared pure decision fns +// (scope_cover_holds, manifest_freeze_holds on gunbc.extdeps_scope_frontier) that the wet file +// executes against live observations. test fn red_cover_check_refuses_unrostered_file() -> Bool { scope_cover_holds( diff --git a/dag/test/claim/fabric/fabric_cell_evidence_algebra_witness_test.dag b/dag/test/claim/fabric/fabric_cell_evidence_algebra_witness_test.dag index 954b208b2af..1bd9545bd33 100644 --- a/dag/test/claim/fabric/fabric_cell_evidence_algebra_witness_test.dag +++ b/dag/test/claim/fabric/fabric_cell_evidence_algebra_witness_test.dag @@ -23,16 +23,16 @@ import v2.std.live_tree { LiveTreeDisposition, SubstrateInputsOnly } data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly // THE JOIN IS TESTED AS AN ALGEBRA, NOT AS A LIST OF SCENARIOS, AND THE DIFFERENCE IS WHAT THIS -// FAMILY KEEPS PAYING FOR. A scenario row asserts that one input produces one output; it can only -// catch a defect someone already imagined. A law quantifies over EVERY ordering of an atom set, so -// it catches the orderings nobody thought to write -- and every defect this family has had was an +// FAMILY KEEPS PAYING FOR. A scenario row asserts one input produces one output; it catches only +// a defect someone already imagined. A law quantifies over EVERY ordering of an atom set, so it +// catches the orderings nobody thought to write -- and every defect this family has had was an // ordering or a population nobody thought to write. // -// The atoms below are the complete inhabitance of what one address can report: nothing, an explicit -// absence, a positive reading, a DIFFERENT positive reading, and two refusals that differ only in -// their cause text. The last pair is deliberate: it is the only pair whose two members are -// semantically identical and textually distinct, which is exactly where an order-dependent value -// hides from a class-level assertion. +// The atoms below are the complete inhabitance of what one address can report: nothing, an +// explicit absence, a positive reading, a DIFFERENT positive reading, and two refusals that differ +// only in cause text. The last pair is deliberate: it is the only pair whose members are +// semantically identical and textually distinct, exactly where an order-dependent value hides from +// a class-level assertion. fn algebra_slot() -> RunnerSlotIdentity { RunnerSlotIdentity { host: operator_host_srv3, slot_index: 6 } @@ -74,9 +74,9 @@ fn algebra_atoms() -> List { // TWO PROJECTIONS, AND THE GAP BETWEEN THEM IS THE MEASUREMENT. The class projection is what the // plan identity and the routing consume; the full projection is the complete semantic value. A -// safety fold is not order-independent merely because every permutation reaches the same coproduct -// arm -- the value inside the arm must satisfy the law too, or a later consumer that reads it -// reintroduces the order dependence the class-level assertion said was gone. +// safety fold is not order-independent merely because every permutation reaches the same +// coproduct arm -- the value inside the arm must satisfy the law too, or a later consumer reading +// it reintroduces the order dependence the class-level assertion said was gone. fn evidence_class_wire(e: FabricCellAddressEvidence) -> String { match e { NoEvidence => "none" @@ -106,9 +106,9 @@ fn full_of(observations: List) -> String { } // EVERY ORDERING IS QUANTIFIED OVER, NOT LISTED. The laws below fold over the atom set itself, so -// every ordered pair and every ordered triple is visited -- including the ones with repeats, which -// is where idempotence lives. Adding an atom widens every law here with no other edit, which is the -// property a hand-listed scenario table can never have. +// every ordered pair and triple is visited -- including those with repeats, where idempotence +// lives. Adding an atom widens every law with no other edit, which a hand-listed scenario table +// can never have. // THE PARAMETER IS NOT NAMED `project`, AND THE RENAME IS A DEFECT RECEIPT RATHER THAN A STYLE // CHOICE. It was, and these rows passed under `gunbc run --entry ` and FAILED under the // required floor with `call contract mismatch calling 'project': missing required argument @@ -119,8 +119,8 @@ fn full_of(observations: List) -> String { // // THE ARITY IS WHY THIS ONE WAS LOUD. Where the shadowing symbol takes a different number of // arguments the call refuses; where it takes the same number it returns the wrong value silently -// (gunbc#9187, a parameter named `p` against `gunbc.plans.md_helpers` `p`). Same defect, and only -// the arity decides whether you find out. +// (gunbc#9187, a parameter named `p` against `gunbc.plans.md_helpers` `p`). Same defect; only the +// arity decides whether you find out. fn all_pairs_agree(observation_wire: fn(List) -> String) -> Bool { fold(algebra_atoms(), init: true, f: (acc_a, a) => acc_a && fold(algebra_atoms(), init: true, f: (acc_b, b) => @@ -160,18 +160,18 @@ test fn evidence_join_is_idempotent() -> Bool { // observations arrive in, the plan must not change. // // THE NAME IS NARROWER THAN COMMUTATIVITY-AND-ASSOCIATIVITY AND THE NARROWING IS THE POINT. An -// earlier revision of this comment claimed both. It was false of associativity: these rows permute -// a THREE-ELEMENT LIST through one left fold, and never compare `join(join(a, b), c)` against -// `join(a, join(b, c))` -- different parenthesizations, not different orders. No binary -// evidence-to-evidence join is exposed to compare, so that law is not testable from here at all, -// and a comment claiming it would be the same overclaim this file exists to refuse: evidence named -// for a stronger property than it establishes. +// earlier revision of this comment claimed both. It was false of associativity: these rows +// permute a THREE-ELEMENT LIST through one left fold, and never compare `join(join(a, b), c)` +// against `join(a, join(b, c))` -- different parenthesizations, not different orders. No binary +// evidence-to-evidence join is exposed to compare, so that law is not testable from here, and a +// comment claiming it would be the overclaim this file exists to refuse: evidence named for a +// stronger property than it establishes. // // WHY THE MISSING LAW IS WORTH ITS OWN CHANGE RATHER THAN A SHRUG: associativity is exactly what -// licenses combining probe batches INCREMENTALLY. An observer that reads a host in chunks and folds -// each chunk into a running evidence value is relying on it, and permutation invariance over one -// monolithic list does not establish it. The next-step trigger is a pure binary join the list fold -// consumes; until that exists this file states the weaker property it can actually measure. +// licenses combining probe batches INCREMENTALLY. An observer that reads a host in chunks and +// folds each into a running evidence value relies on it, and permutation invariance over one +// monolithic list does not establish it. The next-step trigger is a pure binary join the list +// fold consumes; until that exists this file states the weaker property it can measure. test fn evidence_class_is_order_independent_over_pairs() -> Bool { all_pairs_agree(observation_wire: class_of) } @@ -198,26 +198,26 @@ test fn evidence_domain_laws_hold() -> Bool { // AND THE ONE THAT IS RED TODAY, ASSERTING THE PROPERTY WE WANT RATHER THAN THE ONE WE HAVE. The // class projection above is order-independent; the FULL semantic value is not, because the fold -// keeps the FIRST refusal cause it saw. Two refusals that differ only in cause text are -// semantically identical and textually distinct, so `[c1, c2]` and `[c2, c1]` reach the same arm -// carrying different payloads. +// keeps the FIRST refusal cause it saw. Two refusals differing only in cause text are semantically +// identical and textually distinct, so `[c1, c2]` and `[c2, c1]` reach the same arm carrying +// different payloads. // // THIS ROW ASSERTS EQUALITY AND IS ENROLLED AS EXPECTED-RED, and the direction is the whole point // (codex review 55693). An earlier cut asserted the INEQUALITY -- that reversed refusals must stay -// unequal -- and it passed, which made the defect part of the green contract: whoever canonicalized -// the join would have been met by a red row whose obvious repair is to DELETE the row protecting -// the property. That is a witness pinning a defect and thereby acquiring a defender, which is the -// exact class this lane named one PR earlier and then re-committed here. Asserted this way round -// the row goes GREEN when the join is fixed, and the floor's known-red-now-passing arm is what -// tells the fixer to retire the enrolment. +// unequal -- and it passed, making the defect part of the green contract: whoever canonicalized +// the join would meet a red row whose obvious repair is to DELETE the row protecting the property. +// That is a witness pinning a defect and thereby acquiring a defender, the exact class this lane +// named one PR earlier and then re-committed here. Asserted this way round the row goes GREEN when +// the join is fixed, and the floor's known-red-now-passing arm tells the fixer to retire the +// enrolment. // -// WHY IT IS NOT FIXED IN THIS PR, stated rather than left as an omission: canonicalizing the -// refusal changes `EvidenceRefused`'s payload and therefore `AddressUnreadable.cause` and every -// consumer of it, in a file #9167 is already restructuring. It is a production change belonging in -// its own diff with its own mutation receipt, not a rider on a witness-only PR. What is NOT true -// is that it is harmless: the plan identity consumes the CLASS, so the wording does not move the -// member-set fingerprint today, but it sits one consumer away -- whoever routes on `cause` or -// renders it into anything content-addressed reopens the CAS defect this family already fixed once. +// WHY IT IS NOT FIXED IN THIS PR: canonicalizing the refusal changes `EvidenceRefused`'s payload +// and therefore `AddressUnreadable.cause` and every consumer of it, in a file #9167 is already +// restructuring. It is a production change belonging in its own diff with its own mutation +// receipt, not a rider on a witness-only PR. It is NOT harmless: the plan identity consumes the +// CLASS, so the wording does not move the member-set fingerprint today, but it sits one consumer +// away -- whoever routes on `cause` or renders it into anything content-addressed reopens the CAS +// defect this family already fixed once. test fn evidence_full_value_is_order_independent() -> Bool { full_of(observations: [atom_refused(cause: "transport reset"), atom_refused(cause: "permission denied")]) == full_of(observations: [atom_refused(cause: "permission denied"), atom_refused(cause: "transport reset")]) diff --git a/dag/test/claim/fabric/fabric_envelope_witness_test.dag b/dag/test/claim/fabric/fabric_envelope_witness_test.dag index 2204d7c5003..79d108ba9b6 100644 --- a/dag/test/claim/fabric/fabric_envelope_witness_test.dag +++ b/dag/test/claim/fabric/fabric_envelope_witness_test.dag @@ -35,8 +35,8 @@ fn six_gib() -> Int { 6442450944 } // else. That is a routing decision, not a missing annotation: the broker sends work to a machine // that cannot run it and nothing downstream refuses, because fungibility already said yes. // -// The assertion names BOTH failing axes rather than merely that it refuses -- a fold that caught -// only memory would pass a "does it refuse" check while still routing arm work to an x64 request. +// The assertion names BOTH failing axes, not merely that it refuses -- a fold catching only memory +// would pass a "does it refuse" check while still routing arm work to an x64 request. test fn an_eight_gib_x64_need_is_not_covered_by_a_six_gib_arm_offer() -> Bool { let needed = shape_of(threads: 2, arch: Present { value: X86_64 }, bytes: eight_gib()) let offered = shape_of(threads: 2, arch: Present { value: Aarch64 }, bytes: six_gib()) @@ -70,10 +70,9 @@ test fn a_larger_same_arch_offer_still_covers() -> Bool { // ARCHITECTURE IS EQUALITY, NOT ORDER, AND THE ASYMMETRY PROVES IT. // -// A bigger arm machine does not "cover" an x64 need in the way more memory covers less memory: a -// binary built for one does not run on the other. If architecture were folded into an at-least -// comparison this witness goes green in one direction and the model silently starts routing across -// ABIs. +// A bigger arm machine does not "cover" an x64 need the way more memory covers less: a binary +// built for one does not run on the other. Folded into an at-least comparison, this witness goes +// green in one direction and the model silently routes across ABIs. test fn a_larger_arm_offer_does_not_cover_an_x64_need() -> Bool { let needed = shape_of(threads: 2, arch: Present { value: X86_64 }, bytes: six_gib()) let offered = shape_of(threads: 64, arch: Present { value: Aarch64 }, bytes: eight_gib()) @@ -82,9 +81,9 @@ test fn a_larger_arm_offer_does_not_cover_an_x64_need() -> Bool { // AN UNSTATED AXIS IS SKIPPED, NOT REPORTED AS CHECKED. // -// Work that states no memory requirement must not be refused by an offer that states none either, -// and must not be recorded as having had memory verified. Unstated is nothing-to-check; treating -// it as satisfied-by-everything is the same conflation, one step further along. +// Work stating no memory requirement must not be refused by an offer that states none either, and +// must not be recorded as having had memory verified. Unstated is nothing-to-check; treating it as +// satisfied-by-everything is the same conflation, one step further along. test fn an_unstated_requirement_neither_refuses_nor_claims_a_check() -> Bool { let needed = Shape { hard: HardRequirements { threads: hardware_thread_count(count: 2) }, @@ -102,8 +101,8 @@ test fn an_unstated_requirement_neither_refuses_nor_claims_a_check() -> Bool { // // shape_material hand-renders fields, so a new axis is included only if someone remembers. Two // works differing ONLY in memory must not derive the same key: fungibility compares the envelope, -// so if identity ignored it, deduplication and matching would disagree about whether two things -// are the same work -- exactly the divergence that module's own note records for threads. +// so if identity ignored it, deduplication and matching would disagree about whether two things are +// the same work -- the divergence that module's own note records for threads. test fn two_shapes_differing_only_in_memory_do_not_share_material() -> Bool { let small = shape_of(threads: 2, arch: Present { value: X86_64 }, bytes: six_gib()) let large = shape_of(threads: 2, arch: Present { value: X86_64 }, bytes: eight_gib()) diff --git a/dag/test/claim/fabric/fabric_isolation_witness_test.dag b/dag/test/claim/fabric/fabric_isolation_witness_test.dag index 9a413c31b61..2bf88a2920e 100644 --- a/dag/test/claim/fabric/fabric_isolation_witness_test.dag +++ b/dag/test/claim/fabric/fabric_isolation_witness_test.dag @@ -48,8 +48,8 @@ test fn a_shared_kernel_offer_satisfies_a_shared_kernel_requirement() -> Bool { // -- runs in the host's process namespace, and shares /home/ghrunner with every other slot on the // machine, which has already produced two independent mid-run file deletions under running jobs. // So all four tenant guarantees are missing, and the witness asserts the COUNT so that providing -// one of them turns it red: the correct trigger to revisit the profile, rather than a green that -// survives partial progress. +// one turns it red: the trigger to revisit the profile, rather than a green surviving partial +// progress. // // THE FLOOR IS DELIBERATELY NOT THE SUBJECT HERE. Our own work requires none of these and runs // green today; measuring the fleet against the floor's requirement would report a gap that does @@ -78,9 +78,9 @@ test fn todays_slots_still_satisfy_our_own_floor() -> Bool { // EVERY GUARANTEE HAS ITS OWN WIRE WORD. // -// The discriminating half: a label function that collapsed two members would still render a -// plausible refusal, and the collapse would only surface as an operator provisioning the wrong -// thing. Asserted as distinctness across the whole closed set rather than by spot-checking one. +// The discriminating half: a label function collapsing two members would still render a plausible +// refusal, surfacing only as an operator provisioning the wrong thing. Asserted as distinctness +// across the whole closed set rather than by spot-checking one. test fn the_seven_guarantees_do_not_share_a_wire_word() -> Bool { let all = [ FreshWritableRoot, PrivateProcessNamespace, PrivateNetworkNamespace, @@ -94,10 +94,9 @@ test fn the_seven_guarantees_do_not_share_a_wire_word() -> Bool { // AN EMPTY REQUIREMENT IS SATISFIED BY AN EMPTY OFFER, WHICH IS NOT VACUOUS BUT LOAD-BEARING. // -// It states that the empty missing-list means SATISFIED and never "could not ask". The fold -// derives its answer by filtering the REQUIRED set, so an empty result can only mean every -// required guarantee was found -- if it could also mean the question failed, every unsatisfiable -// offer in the fleet would read as fungible. +// The empty missing-list means SATISFIED and never "could not ask". The fold filters the REQUIRED +// set, so an empty result can only mean every required guarantee was found -- if it could also +// mean the question failed, every unsatisfiable offer in the fleet would read as fungible. test fn requiring_nothing_is_satisfied_rather_than_unanswerable() -> Bool { isolation_profile_satisfies( required: IsolationProfile { guarantees: [] }, diff --git a/dag/test/claim/fabric/fabric_sanitation_witness_test.dag b/dag/test/claim/fabric/fabric_sanitation_witness_test.dag index 36d6674fe2c..61cc8c66123 100644 --- a/dag/test/claim/fabric/fabric_sanitation_witness_test.dag +++ b/dag/test/claim/fabric/fabric_sanitation_witness_test.dag @@ -35,11 +35,11 @@ test fn a_fully_proven_teardown_returns_the_cell() -> Bool { // AN OMITTED OBSERVATION DOES NOT PASS, WHICH IS THE LOAD-BEARING WITNESS IN THIS FILE. // -// A readback confirming five facts and simply not mentioning the sixth is the empty-observation -// narrow in its most dangerous form: the reader concludes "nothing was reported wrong" from a -// report that never covered the subject. A fold that walked the OBSERVED list instead of the -// REQUIRED list passes this readback and returns a cell with the previous tenant's writable layer -// still on it. That fold passes every other witness here. +// A readback confirming five facts and not mentioning the sixth is the empty-observation narrow in +// its most dangerous form: "nothing was reported wrong" concluded from a report that never covered +// the subject. A fold walking the OBSERVED list instead of the REQUIRED list passes this readback +// and returns a cell with the previous tenant's writable layer still on it — and passes every other +// witness here. test fn five_confirmations_and_a_silence_do_not_return_the_cell() -> Bool { let five = filter(all_confirmed(), o => match o { FactConfirmed { fact: f } => f != WritableLayersDeleted @@ -59,10 +59,9 @@ test fn five_confirmations_and_a_silence_do_not_return_the_cell() -> Bool { // UNOBSERVABLE IS NOT CONFIRMED, AND IT IS ALSO NOT REFUTED. // // The discriminating pair: a fact the readback could not reach must refuse reuse exactly as a -// refuted one does, while remaining distinguishable from it — the two have different operator -// remedies (teardown failed, versus we could not tell). A model collapsing Unobservable into -// Confirmed lets residue through; one collapsing it into Refuted is safe but reports a failure that -// did not happen. +// refuted one does, while remaining distinguishable from it — the operator remedies differ +// (teardown failed, versus we could not tell). Collapsing Unobservable into Confirmed lets residue +// through; collapsing it into Refuted is safe but reports a failure that did not happen. test fn an_unobservable_fact_refuses_reuse_without_claiming_teardown_failed() -> Bool { let with_unobservable = concat( filter(all_confirmed(), o => match o { @@ -101,8 +100,8 @@ test fn a_refused_teardown_names_the_fact_and_its_detail() -> Bool { // A LOST HOST AGENT QUARANTINES THE CELL RATHER THAN RETURNING IT. // // No readback at all is the tempting place to answer "nothing to clean". It is the same narrow one -// level out — no observation becoming no problem — and it is the case where the cell is MOST likely -// to be dirty, since the agent vanished mid-attempt. Every required fact comes back unobserved. +// level out — no observation becoming no problem — and the case where the cell is MOST likely +// dirty, since the agent vanished mid-attempt. Every required fact comes back unobserved. test fn a_lost_host_agent_quarantines_with_every_fact_unproven() -> Bool { let readiness = readiness_without_readback(cell: a_cell(), sandbox: a_sandbox()) let unproven = unproven_facts(readback: readback_of(obs: [])) diff --git a/dag/test/claim/filesystem_absence_establishment_witness_test.dag b/dag/test/claim/filesystem_absence_establishment_witness_test.dag index 8ae72f2e557..b98b57d7bce 100644 --- a/dag/test/claim/filesystem_absence_establishment_witness_test.dag +++ b/dag/test/claim/filesystem_absence_establishment_witness_test.dag @@ -27,7 +27,19 @@ import extdeps.filesystem.filesystem_io { data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data filesystem_absence_establishment_construction_justification: String = "Pure folds over authored listing text and an authored read outcome, run in the ordinary floor because the subject is the FOLD -- a total function of what a host reported, with no filesystem, no subprocess and no host. The listing strings are the newline-joined encoding Filesystem.List's own output channel declares, so the membership question under test is asked over the real wire format rather than an invention. What these deliberately do NOT establish is that Filesystem.List EMITS those bytes for any given directory: that is a transport claim, it cannot execute inside the hermetic fold, and reporting these as coverage for it would be the rung inflation DESIGN section 4b forbids. What they also do not establish is the CONSTRUCTION wall -- that a record literal for FilesystemEstablishedAbsence outside its home module is refused. That claim is about compiler acceptance, its subject is source text rather than a value, and its only enrolled home is the guarantee-probe corpus, which DESIGN records as declined by the floor; it is measured by execution and cited in filesystem_absence_establishment_receipt instead of asserted here as a permanently-green arm." +// Pure folds over authored listing text and an authored read outcome, run in the ordinary floor +// because the subject is the FOLD -- a total function of what a host reported, with no filesystem, +// no subprocess and no host. The listing strings are the newline-joined encoding Filesystem.List's +// own output channel declares, so the membership question under test is asked over the real wire +// format rather than an invention. What these deliberately do NOT establish is that Filesystem.List +// EMITS those bytes for any given directory: that is a transport claim, it cannot execute inside +// the hermetic fold, and reporting these as coverage for it would be the rung inflation DESIGN +// section 4b forbids. What they also do not establish is the CONSTRUCTION wall -- that a record +// literal for FilesystemEstablishedAbsence outside its home module is refused. That claim is about +// compiler acceptance, its subject is source text rather than a value, and its only enrolled home +// is the guarantee-probe corpus, which DESIGN records as declined by the floor; it is measured by +// execution and cited in filesystem_absence_establishment_receipt instead of asserted here as a +// permanently-green arm. fn listed(entries: String) -> FilesystemListingObservation { filesystem_listing_observation( diff --git a/dag/test/claim/firmware_applicability_and_loop_cause_witness_test.dag b/dag/test/claim/firmware_applicability_and_loop_cause_witness_test.dag index 2d47b586719..6c0be141b61 100644 --- a/dag/test/claim/firmware_applicability_and_loop_cause_witness_test.dag +++ b/dag/test/claim/firmware_applicability_and_loop_cause_witness_test.dag @@ -26,12 +26,11 @@ import v2.std.live_tree { LiveTreeDisposition, SubstrateInputsOnly } data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -// These bind the PRODUCTION release rows, not fixtures, so the gate is -// exercised against the prerequisite the catalog actually declares. +// These bind the PRODUCTION release rows, not fixtures, so the gate is exercised against the +// prerequisite the catalog actually declares. -// THE FAIL-CLOSED ARM, and the case that justified it: srv3 reports its BIOS -// version as null through Redfish. "We could not read it" must refuse rather -// than collapse into either pole. +// THE FAIL-CLOSED ARM, and the case that justified it: srv3 reports its BIOS version as null +// through Redfish. "We could not read it" must refuse rather than collapse into either pole. test fn unreadable_target_version_refuses_rather_than_assuming() -> Bool { match firmware_release_applicability( prerequisite: asrock_altrad8ud_bios_3_10_openbmc_release.prerequisite, @@ -44,9 +43,8 @@ test fn unreadable_target_version_refuses_rather_than_assuming() -> Bool { } } -// The srv3 push that actually happened: BMC 2.07.00 against a row requiring -// 3.22.00. Unmet, and the verdict carries the observed version so the refusal -// can say what it saw rather than only that it refused. +// The srv3 push that actually happened: BMC 2.07.00 against a row requiring 3.22.00. Unmet, and the +// verdict carries the observed version so the refusal says what it saw, not only that it refused. test fn the_srv3_push_is_refused_by_the_catalog() -> Bool { match firmware_release_applicability( prerequisite: asrock_altrad8ud_bios_3_10_openbmc_release.prerequisite, @@ -73,10 +71,9 @@ test fn the_srv4_push_is_admitted_by_the_catalog() -> Bool { } } -// RED control on the COMPARISON, not on the arms. 3.06.00 exceeds the minimum -// on major and fails on minor; a naive major-only compare would admit it. The -// version is also a real catalogued image for this board, so this is a push -// someone could actually attempt. +// RED control on the COMPARISON, not on the arms. 3.06.00 exceeds the minimum on major and fails on +// minor; a naive major-only compare would admit it. The version is also a real catalogued image for +// this board, so this is a push someone could actually attempt. test fn a_higher_major_with_lower_minor_is_still_unmet() -> Bool { match firmware_release_applicability( prerequisite: asrock_altrad8ud_bios_3_10_openbmc_release.prerequisite, @@ -90,10 +87,10 @@ test fn a_higher_major_with_lower_minor_is_still_unmet() -> Bool { } } -// The packaging asymmetry, exercised rather than asserted: the Instant Flash -// ROM never passes through the BMC, so it is applicable even when the BMC -// version is unreadable — the exact input that refuses on the tar row above. -// Same observation, opposite verdict, because the packaging differs. +// The packaging asymmetry, exercised rather than asserted: the Instant Flash ROM never passes +// through the BMC, so it is applicable even when the BMC version is unreadable — the exact input +// that refuses on the tar row above. Same observation, opposite verdict, because the packaging +// differs. test fn the_rom_packaging_is_applicable_with_no_readable_bmc_version() -> Bool { match firmware_release_applicability( prerequisite: asrock_altrad8ud_bios_3_10_instant_flash_release.prerequisite, @@ -112,11 +109,10 @@ data srv4_e588_signature: HostBootStallSignature = HostBootStallSignature { observed_at: 1786580000000, } -// THE POWERMON REFUTATION, as an executing check rather than a prose receipt. -// power-monitor.service was stopped on srv4 and the loop PERSISTED, which is -// what moves the cause to the host itself. Note the shape of the argument: the -// loop's PERIOD never decides this — a 306-second cycle looks identical whether -// or not a 306-second timeout causes it. Only the intervention discriminates. +// THE POWERMON REFUTATION, as an executing check rather than a prose receipt. power-monitor.service +// was stopped on srv4 and the loop PERSISTED, which moves the cause to the host itself. The loop's +// PERIOD never decides this — a 306-second cycle looks identical whether or not a 306-second timeout +// causes it. Only the intervention discriminates. test fn loop_persisting_after_supervisor_stop_is_host_self_reset() -> Bool { match host_boot_loop_cause( signature: srv4_e588_signature, @@ -128,10 +124,9 @@ test fn loop_persisting_after_supervisor_stop_is_host_self_reset() -> Bool { } } -// RED control: the SAME signature with the supervisor still running is -// CONFOUNDED, not attributed. This is the state the incident was in for hours -// while the watchdog theory looked plausible, and the function must not -// resolve it — the discriminating fact is the intervention, not the signature. +// RED control: the SAME signature with the supervisor still running is CONFOUNDED, not attributed. +// This is the state the incident sat in for hours while the watchdog theory looked plausible, and +// the function must not resolve it — the discriminating fact is the intervention, not the signature. test fn the_same_signature_without_the_intervention_is_confounded() -> Bool { match host_boot_loop_cause( signature: srv4_e588_signature, @@ -145,10 +140,9 @@ test fn the_same_signature_without_the_intervention_is_confounded() -> Bool { } } -// Stopping the supervisor and observing the loop STOP does not attribute the -// cause either — it removes one candidate, and with no error code there is -// nothing left to attribute to, so the answer is Unobserved rather than a -// supervisor verdict inferred from silence. +// Stopping the supervisor and observing the loop STOP does not attribute the cause either — it +// removes one candidate, and with no error code nothing is left to attribute to, so the answer is +// Unobserved rather than a supervisor verdict inferred from silence. test fn no_error_code_after_a_clean_stop_is_unobserved_not_attributed() -> Bool { match host_boot_loop_cause( signature: HostBootStallSignature { diff --git a/dag/test/claim/fleet/fleet_intent_network_witness_test.dag b/dag/test/claim/fleet/fleet_intent_network_witness_test.dag index e8c8206fd8d..c1f1183f6ae 100644 --- a/dag/test/claim/fleet/fleet_intent_network_witness_test.dag +++ b/dag/test/claim/fleet/fleet_intent_network_witness_test.dag @@ -1,6 +1,5 @@ module test.claim.fleet_intent_network - data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly test fn fleet_intent_network_container_to_bmc_allowed() -> Bool { @@ -20,7 +19,14 @@ test fn fleet_intent_network_srv1_addresses_holds() -> Bool { && srv1_bmc_endpoint.address == "192.168.1.183" } -data fleet_intent_network_srv3_host_witness_note: String = "The count row above is a tripwire, not a fact about srv3 — it reds on ANY topology edit and says nothing about WHICH endpoint appeared. This row is the discriminating half for the 2026-07-24 srv3 host addition, mirroring fleet_intent_network_srv1_addresses_holds: srv3 must be modeled with BOTH of its interfaces distinguished by role (its BMC at .192 was modeled since the srv3 onboarding lane; its host OS at .221 was not, so a model that named srv3 could still not name the machine). Asserting both addresses AND the role split is what makes a regression that collapses host onto BMC — the exact confusion this row was added to end — go red rather than merely shifting a count." +// The count row above is a tripwire, not a fact about srv3 — it reds on ANY topology edit and says +// nothing about WHICH endpoint appeared. This row is the discriminating half for the 2026-07-24 +// srv3 host addition, mirroring fleet_intent_network_srv1_addresses_holds: srv3 must be modeled +// with BOTH of its interfaces distinguished by role (its BMC at .192 was modeled since the srv3 +// onboarding lane; its host OS at .221 was not, so a model that named srv3 could still not name the +// machine). Asserting both addresses AND the role split is what makes a regression that collapses +// host onto BMC — the exact confusion this row was added to end — go red rather than merely +// shifting a count. test fn fleet_intent_network_srv3_addresses_holds() -> Bool { srv3_host_lan_endpoint.address == "192.168.1.221" @@ -29,7 +35,13 @@ test fn fleet_intent_network_srv3_addresses_holds() -> Bool { && srv3_bmc_endpoint.role == BmcOutOfBand } -data fleet_intent_network_srv5_srv6_reserved_not_enrolled_note: String = "SPARK-LANE-A. srv5/srv6 are named here as HostIdentity slots for the two ordered DGX Spark units, and naming is deliberately NOT enrollment. The count tripwire above cannot see that distinction — it would stay green if a fabricated srv5 endpoint replaced another — so this row asserts the separation directly at the enrollment authority: both identities exist, and NO endpoint in the topology is bound to either. It reds the moment someone authors an address for a machine that has not arrived, which is the exact fabrication the procurement lane's router-binding wall refuses on the other side." +// SPARK-LANE-A. srv5/srv6 are named here as HostIdentity slots for the two ordered DGX Spark units, +// and naming is deliberately NOT enrollment. The count tripwire above cannot see that distinction — +// it would stay green if a fabricated srv5 endpoint replaced another — so this row asserts the +// separation directly at the enrollment authority: both identities exist, and NO endpoint in the +// topology is bound to either. It reds the moment someone authors an address for a machine that has +// not arrived, which is the exact fabrication the procurement lane's router-binding wall refuses on +// the other side. test fn fleet_intent_network_srv5_srv6_named_but_not_enrolled() -> Bool { operator_host_srv5 == "srv5" diff --git a/dag/test/claim/fleet/fleet_observation_producers_witness_test.dag b/dag/test/claim/fleet/fleet_observation_producers_witness_test.dag index 66cfa45385b..23dd62f5559 100644 --- a/dag/test/claim/fleet/fleet_observation_producers_witness_test.dag +++ b/dag/test/claim/fleet/fleet_observation_producers_witness_test.dag @@ -41,25 +41,24 @@ data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly // EVERY FRONTIER BELOW IS A SET OF NAMED HOSTS, NOT A TALLY. The four fleet counts these replaced -// were deleted from production entirely: they had no production consumer at all, and a function -// whose only consumer is evidence is the no-final-consumer tell. The evidence itself stays, rebuilt -// here at identity grain -- DESIGN 4b(4) dissolves the lower-rung machinery a climb obsoletes and -// keeps the evidence that the rung is real, and here the two were separable because a witness can -// fold the enrolled population itself. +// were deleted from production entirely: they had no production consumer, and a function whose only +// consumer is evidence is the no-final-consumer tell. The evidence stays, rebuilt here at identity +// grain -- DESIGN 4b(4) dissolves the lower-rung machinery a climb obsoletes and keeps the evidence +// that the rung is real; the two were separable because a witness can fold the enrolled population +// itself. // // WHAT IDENTITY GRAIN BUYS OVER THE COUNTS. DESIGN section 5 requires completeness to be an identity -// join rather than a count equality. A count says six hosts are unobserved but never WHICH, so a -// producer arriving moves a number and the diff cannot say what acquired one. Named sets make that -// readable. The sharper reason is that a count and its own prose cannot contradict each other -// detectably -- a count has no members, so no review, execution or lens can check a sentence about -// it against it; the sibling witness in test.claim.host_swap_backing carries the specimen, where a -// note saying "all four enrolled hosts" sat beside a fold over six for as long as it took someone to -// read both. +// join, not a count equality. A count says six hosts are unobserved but never WHICH, so a producer +// arriving moves a number and the diff cannot say what acquired one. The sharper reason: a count +// and its own prose cannot contradict each other detectably -- a count has no members, so nothing +// can check a sentence about it against it; the sibling witness in test.claim.host_swap_backing +// carries the specimen, where a note saying "all four enrolled hosts" sat beside a fold over six +// until someone read both. // -// NOT A CLAIM THAT ANY HOST HERE IS FICTIONAL, stated because an earlier revision of this block said -// so and was wrong: all six enrolled hosts are real machines. srv5 and srv6 are the two DGX Spark -// units, live on the operator LAN with ARP-confirmed MACs and measured SSH host keys; counting them -// as unobserved is correct, because nobody has measured their disk, swap or endpoint yet. +// NOT A CLAIM THAT ANY HOST HERE IS FICTIONAL (an earlier revision said so and was wrong): all six +// enrolled hosts are real machines. srv5 and srv6 are the two DGX Spark units, live on the operator +// LAN with ARP-confirmed MACs and measured SSH host keys; counting them as unobserved is correct +// because nobody has measured their disk, swap or endpoint yet. // // THE UNIVERSE IS THE ENROLLED POPULATION and never a roster typed into this file: a list pinned to // nothing is the same defect as a count pinned to a population, with more typing. diff --git a/dag/test/claim/fleet/fleet_revision_acceptance_witness_test.dag b/dag/test/claim/fleet/fleet_revision_acceptance_witness_test.dag index 3f6fdca913c..90bd30c267d 100644 --- a/dag/test/claim/fleet/fleet_revision_acceptance_witness_test.dag +++ b/dag/test/claim/fleet/fleet_revision_acceptance_witness_test.dag @@ -45,11 +45,11 @@ data sha_b: String = "b2b2b2b2b2b2b2b2b2b2b2b2b2b2b2b2b2b2b2b2" data github_evidence: String = "workflow_run event, run 17000000001" -// ONE BUILDER, AND EVERY WITNESS BREAKS EXACTLY ONE FACT, so a red row names the fact it broke -// rather than the shape of a hand-copied record. The workflow path defaults through the real -// artifact authority rather than a literal: a fixture hardcoding it would keep passing after a -// rename while production refused every genuine run -- and that failure is SILENT, because a -// too-strict wall simply stops the fleet advancing with nothing red anywhere. +// ONE BUILDER, AND EVERY WITNESS BREAKS EXACTLY ONE FACT, so a red row names the fact it broke, not +// the shape of a hand-copied record. The workflow path defaults through the real artifact +// authority, not a literal: a hardcoded fixture would keep passing after a rename while production +// refused every genuine run -- SILENTLY, since a too-strict wall just stops the fleet advancing +// with nothing red anywhere. fn ev( activity: String, workflow_path: String, @@ -119,10 +119,9 @@ fn branch_admits(e: WorkflowRunEvent) -> Bool { fn oid(hex: String) -> GitObjectId? { git_object_id_from_untagged_hex(hex: hex) } -// POSITIVE CONTROL, load-bearing rather than ceremonial. Almost every other row asserts a REFUSAL, -// and a pair of producers that refused unconditionally would satisfy all of them. This is the row -// that fails when a wall is TOO STRICT -- the failure mode a wall-shaped change actually has, and -// the one that is invisible in production. +// POSITIVE CONTROL, load-bearing: almost every other row asserts a REFUSAL, which unconditionally +// refusing producers would satisfy. This row fails when a wall is TOO STRICT -- the failure mode a +// wall-shaped change actually has, and the one invisible in production. test fn an_eligible_trunk_push_satisfies_both_propositions_and_the_join_accepts() -> Bool { match accept_required_ci_workflow_run(event: trunk_push(head_sha: sha_a), evidence: github_evidence) { RequiredCiAdmitted { succeeded: ci } => @@ -144,14 +143,13 @@ test fn an_eligible_trunk_push_satisfies_both_propositions_and_the_join_accepts( // THE ASYMMETRY, AND IT IS THE WHOLE REASON THE TWO PROPOSITIONS ARE SEPARATE CARRIERS. // -// A PR's merge-subject run genuinely ran the Required CI contract and genuinely passed on that -// tree. Refusing it as a CI failure would be a lie about a real result -- so this producer ADMITS -// it, and that admission is correct. What the run cannot prove is that the revision entered the -// default branch, and that is exactly where it is refused. +// A PR's merge-subject run genuinely ran and passed the Required CI contract on that tree; refusing +// it as a CI failure would lie about a real result, so this producer correctly ADMITS it. What the +// run cannot prove is that the revision entered the default branch, and there it is refused. // -// Had the two been folded into one predicate, either fact could stand in for the pair, and the -// fleet would follow a revision main never had. This row is the executable form of that argument: -// the SAME event, admitted by one producer and refused by the other. +// Folded into one predicate, either fact could stand in for the pair and the fleet would follow a +// revision main never had. This row is that argument executed: the SAME event, admitted by one +// producer and refused by the other. test fn a_pull_request_run_proves_required_ci_but_not_the_default_branch() -> Bool { ci_admits(e: pull_request_run(head_sha: sha_a)) && match observe_default_branch_revision( @@ -163,9 +161,9 @@ test fn a_pull_request_run_proves_required_ci_but_not_the_default_branch() -> Bo } } -// A push to a topic branch is the other half of the same asymmetry: the event IS a push, so the -// event-kind arm passes and the BRANCH arm must be the one that refuses. Without this row a -// producer checking only the originating event would pass every branch row above. +// A push to a topic branch is the other half of the asymmetry: the event IS a push, so the +// event-kind arm passes and the BRANCH arm must refuse. Without this row a producer checking only +// the originating event would pass every branch row above. test fn a_push_to_a_topic_branch_is_refused_by_the_branch_fact() -> Bool { match observe_default_branch_revision( event: ev( @@ -187,10 +185,10 @@ test fn a_push_to_a_topic_branch_is_refused_by_the_branch_fact() -> Bool { } // THE MISMATCH ARM. Required CI proving revision A and the default branch carrying revision B is -// not a contradiction in the data -- both facts can be perfectly true, about different revisions, -// and they arrive together whenever a push lands while a run is in flight. What is false is the -// CONJUNCTION anyone would infer from holding both, and the refusal carries BOTH revisions because -// "which two" is the entire content of the finding. +// no contradiction -- both facts can be true about different revisions, and arrive together +// whenever a push lands while a run is in flight. What is false is the CONJUNCTION anyone would +// infer from holding both; the refusal carries BOTH revisions because "which two" is the entire +// content of the finding. test fn required_ci_for_one_revision_and_a_branch_at_another_refuses_naming_both() -> Bool { match accept_required_ci_workflow_run(event: trunk_push(head_sha: sha_a), evidence: github_evidence) { RequiredCiAdmitted { succeeded: ci } => @@ -221,7 +219,7 @@ test fn required_ci_for_one_revision_and_a_branch_at_another_refuses_naming_both // THE REVISION IS DECODED BEFORE ANY POSITIVE CARRIER EXISTS. GitHub says head_sha is a SHA; // nothing on the wire establishes it. Both producers refuse an undecodable value rather than -// constructing a carrier around it, so no consumer can be handed a revision that is not one. +// building a carrier around it, so no consumer is handed a revision that is not one. test fn an_undecodable_head_sha_refuses_on_both_producers() -> Bool { match accept_required_ci_workflow_run( event: trunk_push(head_sha: "not-a-sha"), @@ -240,8 +238,8 @@ test fn an_undecodable_head_sha_refuses_on_both_producers() -> Bool { } // Each CI identity fact refuses with ITS OWN cause. Asserting only "refused" would let every arm -// collapse into one and still pass -- and the collapse is what makes a refusal undebuggable, since -// the remedies differ: wrong producer, wrong repo, an untrusted fork's head, not finished. +// collapse into one and still pass, making refusals undebuggable since the remedies differ: wrong +// producer, wrong repo, an untrusted fork's head, not finished. test fn each_required_ci_identity_fact_refuses_with_its_own_cause() -> Bool { match accept_required_ci_workflow_run( event: ev( @@ -313,9 +311,9 @@ test fn each_required_ci_identity_fact_refuses_with_its_own_cause() -> Bool { } // A run that did not conclude Success is refused and the OBSERVED conclusion is carried. Cancelled -// is exercised beside Failure deliberately: a cancelled run produces no failure to investigate, so -// it is the state most likely to be read as "nothing happened" -- and it is exactly the state that -// must not be mistaken for a floor that ran. +// is exercised beside Failure deliberately: it produces no failure to investigate, so it is the +// state most likely read as "nothing happened" -- and exactly the state that must not be mistaken +// for a floor that ran. test fn only_a_successful_conclusion_admits_and_the_others_are_named() -> Bool { match accept_required_ci_workflow_run( event: ev( @@ -359,10 +357,10 @@ test fn only_a_successful_conclusion_admits_and_the_others_are_named() -> Bool { } } -// IDENTITY BEFORE OUTCOME, as a claim under test rather than an accident of how the ifs nest. A -// FAILED run of the WRONG workflow must refuse as the wrong workflow: reporting "the floor was not -// green" about a run that was never the floor sends a reader to investigate a failure that does -// not exist, and that investigation terminates in confusion rather than in a fix. +// IDENTITY BEFORE OUTCOME, as a claim under test, not an accident of how the ifs nest. A FAILED run +// of the WRONG workflow must refuse as the wrong workflow: reporting "the floor was not green" +// about a run that was never the floor sends a reader to investigate a failure that does not +// exist, ending in confusion rather than a fix. test fn a_failed_run_of_the_wrong_workflow_refuses_as_the_wrong_workflow() -> Bool { match accept_required_ci_workflow_run( event: ev( @@ -383,9 +381,9 @@ test fn a_failed_run_of_the_wrong_workflow_refuses_as_the_wrong_workflow() -> Bo } // The contract identity is DERIVED from the artifact authority that emits the workflow, never -// re-typed. If this row and the emitter disagree, the fixture is lying rather than the wall. It -// carries no phase roster: the fleet asks whether the exact contract succeeded for the exact -// revision, and adding a phase to the floor must not be a breaking change to fleet admission. +// re-typed: if this row and the emitter disagree, the fixture lies, not the wall. It carries no +// phase roster: the fleet asks whether the exact contract succeeded for the exact revision, and +// adding a phase to the floor must not break fleet admission. test fn the_contract_identity_is_the_emitted_workflow_not_a_phase_roster() -> Bool { required_ci_contract().workflow_path == artifact_path(a: WitnessFloorYamlArtifact) && required_ci_contract().workflow_path == ".github/workflows/witnesses.yml" diff --git a/dag/test/claim/fleet/fleet_runner_connectivity_witness_test.dag b/dag/test/claim/fleet/fleet_runner_connectivity_witness_test.dag index cf9c21213a0..c200c97d7c7 100644 --- a/dag/test/claim/fleet/fleet_runner_connectivity_witness_test.dag +++ b/dag/test/claim/fleet/fleet_runner_connectivity_witness_test.dag @@ -44,7 +44,9 @@ import v2.std.live_tree { LiveTreeDisposition, SubstrateInputsOnly } data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data acceptance_corpus_note: String = "These rows pin the 2026-08-06 broker-session incident exactly. Fifteen registrations are offline, one is online and busy, and local systemd units stayed active throughout — the wedge shape PR B's repair loop must not misread as detached on a roster API blip." +// These rows pin the 2026-08-06 broker-session incident exactly. Fifteen registrations are offline, +// one is online and busy, and local systemd units stayed active throughout — the wedge shape PR B's +// repair loop must not misread as detached on a roster API blip. test fn srv1_01_is_healthy_while_busy() -> Bool { match runner_slot_connectivity_verdict( @@ -79,7 +81,9 @@ test fn active_without_registration_is_orphaned() -> Bool { } } -data roster_unavailable_is_unknown_not_detached_note: String = "THE FAIL-CLOSED ROW PR B'S SAFETY DEPENDS ON: a roster read failure must render UNKNOWN on every active slot, never detached. Zero-width achieved fields must stay unobserved rather than fabricated as zero registrations." +// THE FAIL-CLOSED ROW PR B'S SAFETY DEPENDS ON: a roster read failure must render UNKNOWN on every +// active slot, never detached. Zero-width achieved fields must stay unobserved rather than +// fabricated as zero registrations. test fn roster_unavailable_yields_unknown_on_every_active_slot() -> Bool { let roster = RosterReadUnavailable { reason: "GitHub org runners API returned 503" } @@ -172,7 +176,6 @@ fn count_matching( ) } - // --------------------------------------------------------------------------- // TRUNCATED ROSTER: the discriminating pair for the paginated-read repair. // diff --git a/dag/test/claim/fleet/fleet_show_effective_read_witness_test.dag b/dag/test/claim/fleet/fleet_show_effective_read_witness_test.dag index fc051458dd5..40fa54df58f 100644 --- a/dag/test/claim/fleet/fleet_show_effective_read_witness_test.dag +++ b/dag/test/claim/fleet/fleet_show_effective_read_witness_test.dag @@ -75,7 +75,30 @@ test fn witness_srv1_slice_cap_infinity_drifts_against_pool_budget() -> Bool { } } -data srv2_slice_cap_drift_note: String = "THIS WITNESS HAS FLIPPED TWICE AND BOTH FLIPS ARE FACTS RATHER THAN BROKEN TESTS. The srv2 fixture is a real 2026-07-03 readback of system-actions-runner.slice MemoryMax = 85899345920 (80GiB), and it has never been edited.\n\nFLIP ONE (2026-08-05): the per-host ruling derived srv2's cap as 5 x 14GiB = 75161927680 (70GiB), so the untouched observation legitimately disagreed with the declaration and the correct verdict became Drifted.\n\nFLIP TWO (2026-08-17): the 16GiB ruling derives srv2's cap as 5 x 16GiB = 85899345920, which is the fixture value EXACTLY. srv2's live slice and the declaration agree again, so the correct verdict is Converged once more.\n\nWHAT MADE THE SECOND FLIP LEGITIMATE, because it is not the dissolve-on the prior revision of this note predicted. That note expected convergence to return via a post-apply readback replacing the fixture. It did not: the fixture is untouched and NOTHING was applied to srv2. The DECLARATION moved back to meet a slice that had been carved at 80GiB since before either ruling — which is also why srv2 never needed converging on this axis and never got it.\n\nTHE DISCIPLINE HELD IN BOTH DIRECTIONS: at no point was the fixture edited to keep a test green, and at no point was the declaration reconciled toward the readback (gunbc.runner_slot_allocation forbids that in terms). The declaration moved on a floor-peak measurement; agreeing with srv2's slice is a consequence, not a motive. Dissolve-on: a fresh readback of srv2's slice replaces the 2026-07-03 row, at which point this witness asserts against an observation contemporary with the declaration rather than one fourteen months older." +// THIS WITNESS HAS FLIPPED TWICE AND BOTH FLIPS ARE FACTS RATHER THAN BROKEN TESTS. The srv2 +// fixture is a real 2026-07-03 readback of system-actions-runner.slice MemoryMax = 85899345920 +// (80GiB), and it has never been edited. +// +// FLIP ONE (2026-08-05): the per-host ruling derived srv2's cap as 5 x 14GiB = 75161927680 (70GiB), +// so the untouched observation legitimately disagreed with the declaration and the correct verdict +// became Drifted. +// +// FLIP TWO (2026-08-17): the 16GiB ruling derives srv2's cap as 5 x 16GiB = 85899345920, which is +// the fixture value EXACTLY. srv2's live slice and the declaration agree again, so the correct +// verdict is Converged once more. +// +// WHAT MADE THE SECOND FLIP LEGITIMATE, because it is not the dissolve-on the prior revision of +// this note predicted. That note expected convergence to return via a post-apply readback replacing +// the fixture. It did not: the fixture is untouched and NOTHING was applied to srv2. The +// DECLARATION moved back to meet a slice that had been carved at 80GiB since before either ruling — +// which is also why srv2 never needed converging on this axis and never got it. +// +// THE DISCIPLINE HELD IN BOTH DIRECTIONS: at no point was the fixture edited to keep a test green, +// and at no point was the declaration reconciled toward the readback (gunbc.runner_slot_allocation +// forbids that in terms). The declaration moved on a floor-peak measurement; agreeing with srv2's +// slice is a consequence, not a motive. Dissolve-on: a fresh readback of srv2's slice replaces the +// 2026-07-03 row, at which point this witness asserts against an observation contemporary with the +// declaration rather than one fourteen months older. test fn witness_srv2_slice_cap_converges_after_the_16_gib_ruling() -> Bool { let read = runner_slice_cap_live_read_typed(row: gunbc_srv2_runner_slice_cap_fixture_row) @@ -115,7 +138,15 @@ test fn witness_srv1_01_per_slot_infinity_drifts() -> Bool { } } -data srv1_width_drift_note: String = "The 2026-07-03 srv1 snapshot (10 active runner units) CONVERGED against the pre-carve declaration; the 2026-07-11 slot re-carve (16GiB memory.max slots, gunbc.ci_floor_measurement live row) shrank declared_runner_count to floor(pool/16GiB) = 5, so the same observation now DRIFTS - and that drift is the real fact: the hosts still run the pre-carve width, the same oversubscription the falsifier exit-137 receipts located. The parse-typing claim above deliberately pins the literal (a parse fixture must not depend on a live-derived count - that fusion is why this witness went latent-red when the re-carve landed). Dissolve-on: a post-re-carve width readback replaces the fixture row and this witness flips back to asserting convergence." +// The 2026-07-03 srv1 snapshot (10 active runner units) CONVERGED against the pre-carve +// declaration; the 2026-07-11 slot re-carve (16GiB memory.max slots, gunbc.ci_floor_measurement +// live row) shrank declared_runner_count to floor(pool/16GiB) = 5, so the same observation now +// DRIFTS - and that drift is the real fact: the hosts still run the pre-carve width, the same +// oversubscription the falsifier exit-137 receipts located. The parse-typing claim above +// deliberately pins the literal (a parse fixture must not depend on a live-derived count - that +// fusion is why this witness went latent-red when the re-carve landed). Dissolve-on: a +// post-re-carve width readback replaces the fixture row and this witness flips back to asserting +// convergence. test fn witness_srv1_width_drifts_from_declared_count_after_recarve() -> Bool { match runner_width_live_read_typed(row: gunbc_srv1_runner_width_fixture_row) { diff --git a/dag/test/claim/floor/floor_component_receipt_witness_test.dag b/dag/test/claim/floor/floor_component_receipt_witness_test.dag index 527a5e573c5..6d50b87b0d5 100644 --- a/dag/test/claim/floor/floor_component_receipt_witness_test.dag +++ b/dag/test/claim/floor/floor_component_receipt_witness_test.dag @@ -25,7 +25,13 @@ import gunbc.floor_component_receipt { data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data fcr_witness_note: String = "Executing consumer for gunbc.floor_component_receipt. THE PAIR IS THE PROOF: the receipt built from run 30509024051's real component states must report the affected-set cold control VERIFIED (it concluded Done over 5217 witnesses) while still naming the silent-pick gate as the failed component — and the same projection must report NOT verified when that control itself is red, absent, or ambiguous. Either direction alone is satisfiable by a broken projection: always-verified reproduces the alert defect this module exists to kill, always-unverified reproduces the hardcoded 'cold control is dark' story it replaces." +// Executing consumer for gunbc.floor_component_receipt. THE PAIR IS THE PROOF: the receipt built +// from run 30509024051's real component states must report the affected-set cold control VERIFIED +// (it concluded Done over 5217 witnesses) while still naming the silent-pick gate as the failed +// component — and the same projection must report NOT verified when that control itself is red, +// absent, or ambiguous. Either direction alone is satisfiable by a broken projection: +// always-verified reproduces the alert defect this module exists to kill, always-unverified +// reproduces the hardcoded 'cold control is dark' story it replaces. data fcr_run_id: NonEmptyStr = "30509024051" as NonEmptyStr @@ -235,7 +241,10 @@ test fn fcr_not_reached_mode_is_skipped_not_failed() -> Bool { fcr_mode_outcome_is(mode: "not_reached" as NonEmptyStr, expected_outcome: "skipped") } -data fcr_run_incomplete_note: String = "run_incomplete rows are pending (ComponentNotConcluded), not skipped. Skipped claims the walk produced a verdict of none; pending claims no verdict exists yet because the receipt was written mid-run. not_reached remains skipped: the plan concluded and deliberately skipped the tail. The modes must stay distinct so a SIGKILL checkpoint is not misread as a stop-policy skip." +// run_incomplete rows are pending (ComponentNotConcluded), not skipped. Skipped claims the walk +// produced a verdict of none; pending claims no verdict exists yet because the receipt was written +// mid-run. not_reached remains skipped: the plan concluded and deliberately skipped the tail. The +// modes must stay distinct so a SIGKILL checkpoint is not misread as a stop-policy skip. test fn fcr_run_incomplete_mode_is_pending_not_skipped() -> Bool { fcr_not_concluded_outcome_is(mode: "run_incomplete" as NonEmptyStr, expected_outcome: "pending") @@ -272,7 +281,18 @@ test fn fcr_red_control_unmodelled_failure_mode_refuses_never_widens() -> Bool { && (match budget { Absent => false Present { value: _ } => true }) } -data fcr_failure_mode_edge_note: String = "The row-grain failure-mode edge, and the collapse it exists to undo. floor_component_outcome_of_failure_mode maps Infra and WitnessRed onto the SAME ObservationOutcome (Failed), which is right for the observation record and wrong for anyone deciding what to do next: a dead runner and a genuinely false claim are different faults with different owners. Before the edge, a consumer holding the Failed arm could only tell them apart by reading the diagnostic prose — the string classification the seed boundary already refuses. The pair below asserts BOTH halves of the property, because either alone is satisfiable by a broken projection: the outcomes must still agree (both Failed — the edge did not fork the observation record) AND the modes must differ (Infra vs WitnessRed — the edge actually recovers the distinction). A projection that renamed the outcomes apart would pass a modes-differ check while breaking the record; one that dropped the mode would pass an outcomes-agree check while restoring the blindness." +// The row-grain failure-mode edge, and the collapse it exists to undo. +// floor_component_outcome_of_failure_mode maps Infra and WitnessRed onto the SAME +// ObservationOutcome (Failed), which is right for the observation record and wrong for anyone +// deciding what to do next: a dead runner and a genuinely false claim are different faults with +// different owners. Before the edge, a consumer holding the Failed arm could only tell them apart +// by reading the diagnostic prose — the string classification the seed boundary already refuses. +// The pair below asserts BOTH halves of the property, because either alone is satisfiable by a +// broken projection: the outcomes must still agree (both Failed — the edge did not fork the +// observation record) AND the modes must differ (Infra vs WitnessRed — the edge actually recovers +// the distinction). A projection that renamed the outcomes apart would pass a modes-differ check +// while breaking the record; one that dropped the mode would pass an outcomes-agree check while +// restoring the blindness. fn fcr_mode_of(mode: NonEmptyStr) -> String { let rows = fcr_rows_of(opts: [fcr_mode_row(mode: mode)]) @@ -303,7 +323,13 @@ test fn fcr_failure_mode_edge_agrees_with_the_outcome_mapping() -> Bool { && fcr_mode_of(mode: "not_reached" as NonEmptyStr) == "not_reached" } -data fcr_stale_known_red_note: String = "A known-red witness that starts PASSING and a witness that regresses are opposite events with opposite remedies — delete the now-stale admission row, versus fix the code. This asserts the receipt keeps them apart in BOTH directions: StaleKnownRed carries its own mode AND its own outcome, so it can neither be read as an ordinary WitnessRed in the alert's class signature nor be mistaken for a component that is fine. The Done clause is the load-bearing half: an expected-red row that silently went green must not be admitted as success, or the roster accumulates rows nobody revisits." +// A known-red witness that starts PASSING and a witness that regresses are opposite events with +// opposite remedies — delete the now-stale admission row, versus fix the code. This asserts the +// receipt keeps them apart in BOTH directions: StaleKnownRed carries its own mode AND its own +// outcome, so it can neither be read as an ordinary WitnessRed in the alert's class signature nor +// be mistaken for a component that is fine. The Done clause is the load-bearing half: an +// expected-red row that silently went green must not be admitted as success, or the roster +// accumulates rows nobody revisits. test fn fcr_stale_known_red_is_a_refusal_distinct_from_witness_red_and_from_done() -> Bool { let stale_rows = fcr_rows_of(opts: [fcr_mode_row(mode: "StaleKnownRed" as NonEmptyStr)]) @@ -318,7 +344,14 @@ test fn fcr_stale_known_red_is_a_refusal_distinct_from_witness_red_and_from_done && !(stale_doc == red_doc) } -data fcr_pre_verdict_unverified_note: String = "The THIRD arm on this axis, and it must be distinguishable from BOTH of the others because all three demand different actions. StaleKnownRed says an executed row passed — DELETE the admission. ExpectedRedEvidenceAbsent says a rostered row produced no observation — make it RUN. ExpectedRedPreVerdictUnverified says the row stopped as declared, before any verdict, and nothing yet proves it stopped for the DECLARED REASON — the remedy is neither delete nor rerun but carrying the typed phase and cause across the execution boundary. It renders as refused, never done: a declaration classifies a stop, it does not verify one, and rendering it green was the defect this arm replaces." +// The THIRD arm on this axis, and it must be distinguishable from BOTH of the others because all +// three demand different actions. StaleKnownRed says an executed row passed — DELETE the admission. +// ExpectedRedEvidenceAbsent says a rostered row produced no observation — make it RUN. +// ExpectedRedPreVerdictUnverified says the row stopped as declared, before any verdict, and nothing +// yet proves it stopped for the DECLARED REASON — the remedy is neither delete nor rerun but +// carrying the typed phase and cause across the execution boundary. It renders as refused, never +// done: a declaration classifies a stop, it does not verify one, and rendering it green was the +// defect this arm replaces. test fn fcr_pre_verdict_unverified_is_a_refusal_distinct_from_both_siblings() -> Bool { let unverified_rows = fcr_rows_of(opts: [fcr_mode_row(mode: "ExpectedRedPreVerdictUnverified" as NonEmptyStr)]) @@ -335,7 +368,12 @@ test fn fcr_pre_verdict_unverified_is_a_refusal_distinct_from_both_siblings() -> && !(unverified_doc == stale_doc) } -data fcr_expected_red_evidence_absent_note: String = "The COVERAGE half of the same axis, and the discrimination is that it is neither of its neighbours: not done (a batch whose admitted red control produced no observation is not a batch that is fine), and not StaleKnownRed (nobody observed the witness passing — nobody observed it at all), so the two refusals must render differently or the alert cannot tell delete-the-row from make-the-row-run. Absence establishing neither agreement nor failure is exactly why it needs its own mode rather than being folded into either verdict arm." +// The COVERAGE half of the same axis, and the discrimination is that it is neither of its +// neighbours: not done (a batch whose admitted red control produced no observation is not a batch +// that is fine), and not StaleKnownRed (nobody observed the witness passing — nobody observed it at +// all), so the two refusals must render differently or the alert cannot tell delete-the-row from +// make-the-row-run. Absence establishing neither agreement nor failure is exactly why it needs its +// own mode rather than being folded into either verdict arm. test fn fcr_expected_red_evidence_absent_is_a_refusal_distinct_from_stale_and_from_done() -> Bool { let absent_rows = fcr_rows_of(opts: [fcr_mode_row(mode: "ExpectedRedEvidenceAbsent" as NonEmptyStr)]) @@ -359,7 +397,16 @@ test fn fcr_red_control_tag_built_row_records_no_mode_rather_than_guessing() -> && !string_contains(s: doc, pattern: "\"failure_mode\": \"none\"") } -data receipt_round_trip_note: String = "THE WRITER'S OUTPUT DECODES THROUGH THE STRICT READER, and this witness exists because that once stopped being true. The writer emitted a selection_degradation member only when a selection snapshot existed, while the reader REQUIRED it, so the no-selection path produced a document the reader refused (review 49594). Both members are now deleted with affected-set selection itself — the writer no longer emits them and the reader no longer requires them — so the specific break is gone. The round trip is still witnessed, because what made that defect possible is structural rather than incidental: the writer and the reader are two hand-maintained member lists, and nothing but this execution joins them. Dissolve-on: the document type derives both projections, at which point a writer that omits a required member is unrepresentable and this witness becomes redundant with the type." +// THE WRITER'S OUTPUT DECODES THROUGH THE STRICT READER, and this witness exists because that once +// stopped being true. The writer emitted a selection_degradation member only when a selection +// snapshot existed, while the reader REQUIRED it, so the no-selection path produced a document the +// reader refused (review 49594). Both members are now deleted with affected-set selection itself — +// the writer no longer emits them and the reader no longer requires them — so the specific break is +// gone. The round trip is still witnessed, because what made that defect possible is structural +// rather than incidental: the writer and the reader are two hand-maintained member lists, and +// nothing but this execution joins them. Dissolve-on: the document type derives both projections, +// at which point a writer that omits a required member is unrepresentable and this witness becomes +// redundant with the type. test fn fcr_receipt_decodes_through_the_strict_reader() -> Bool { let doc = floor_component_receipt_document( @@ -374,7 +421,9 @@ test fn fcr_receipt_decodes_through_the_strict_reader() -> Bool { } } -data fcr_run_terminal_legacy_absent_note: String = "Pre-PR receipts under artifact retention omit run_terminal entirely. receipt_run_terminal_at maps absent to null so the alert decoder does not refuse them (review 51856); same transitional pattern as component_outcome_wire_legacy_pending_tag_note." +// Pre-PR receipts under artifact retention omit run_terminal entirely. receipt_run_terminal_at maps +// absent to null so the alert decoder does not refuse them (review 51856); same transitional +// pattern as component_outcome_wire_legacy_pending_tag_note. data fcr_legacy_receipt_without_run_terminal: String = "{\"schema\":\"floor-component-receipt/v1\",\"workflow_name\":\"affected-set-falsifier\",\"run_id\":\"30509024051\",\"head_sha\":\"0123456789abcdef0123456789abcdef01234567\",\"component_count\":0,\"unsuccessful_components\":[],\"components\":[]}" @@ -390,7 +439,14 @@ test fn fcr_legacy_receipt_without_run_terminal_member_decodes() -> Bool { } } -data fcr_incomplete_checkpoint_round_trip_note: String = "The incomplete checkpoint envelope is what claim_executor writes on SIGKILL/step-cap death: run_terminal.disposition=incomplete and pending tail rows (outcome=pending, failure_mode=run_incomplete). The concluded-path round trip was already witnessed; this arm exercises the path this PR exists to fix. SUBJECT IDENTITY IS NOT ON THIS RECEIPT (operator ruling 2026-08-13, #8239 → #8163): in-flight witness identity is a temporary GUNBC_FLOOR_PHASE_JOURNAL projection until measurements and subjects emit on the #8163 RecordedObservation ledger; see floor_component_resource_checkpoint_note and floor_component_phase_journal_scaffold_note." +// The incomplete checkpoint envelope is what claim_executor writes on SIGKILL/step-cap death: +// run_terminal.disposition=incomplete and pending tail rows (outcome=pending, +// failure_mode=run_incomplete). The concluded-path round trip was already witnessed; this arm +// exercises the path this PR exists to fix. SUBJECT IDENTITY IS NOT ON THIS RECEIPT (operator +// ruling 2026-08-13, #8239 → #8163): in-flight witness identity is a temporary +// GUNBC_FLOOR_PHASE_JOURNAL projection until measurements and subjects emit on the #8163 +// RecordedObservation ledger; see floor_component_resource_checkpoint_note and +// floor_component_phase_journal_scaffold_note. test fn fcr_incomplete_checkpoint_receipt_decodes_through_the_strict_reader() -> Bool { let rows = fcr_rows_of(opts: [ diff --git a/dag/test/claim/floor/floor_discovery_hand_rust_equivalence_witness_test.dag b/dag/test/claim/floor/floor_discovery_hand_rust_equivalence_witness_test.dag index 5fdde679232..f1c238428c1 100644 --- a/dag/test/claim/floor/floor_discovery_hand_rust_equivalence_witness_test.dag +++ b/dag/test/claim/floor/floor_discovery_hand_rust_equivalence_witness_test.dag @@ -58,7 +58,12 @@ import v2.std.live_tree { LiveTreeDisposition, SubstrateInputsOnly } data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data floor_discovery_hand_rust_equivalence_note: String = "Executes floor_discovery_producer.dag on fixtures (owned-data transport projection, filename hygiene, test-decl scan, wire-contract scan/sidecar, sidecar placement) with RED perturbation controls. Producer authority is exercised here; Rust bridge cross-checks (discover_floor_witness_roster, scan_wire_contract_decl_names) are named in gunbc.floor_discovery_scaffold and proven by cargo test sidecar_placement_hygiene_tests in cli_run.rs on the same fixture spellings." +// Executes floor_discovery_producer.dag on fixtures (owned-data transport projection, filename +// hygiene, test-decl scan, wire-contract scan/sidecar, sidecar placement) with RED perturbation +// controls. Producer authority is exercised here; Rust bridge cross-checks +// (discover_floor_witness_roster, scan_wire_contract_decl_names) are named in +// gunbc.floor_discovery_scaffold and proven by cargo test sidecar_placement_hygiene_tests in +// cli_run.rs on the same fixture spellings. test fn floor_entry_resolution_host_boundary_is_declared() -> Bool { floor_entry_resolution_host_boundary_discriminator == "resolve_workspace_entry" @@ -219,7 +224,6 @@ test fn floor_discovery_surface_text_scan_scaffold_on_carrier() -> Bool { } } - test fn floor_discovery_producer_entry_is_canonical() -> Bool { floor_discovery_producer_entry == "src/v2/workflow/floor_discovery_producer.dag" } diff --git a/dag/test/claim/floor/floor_preparation_shared_build_witness_test.dag b/dag/test/claim/floor/floor_preparation_shared_build_witness_test.dag index 0588e5663c3..4ffc822c434 100644 --- a/dag/test/claim/floor/floor_preparation_shared_build_witness_test.dag +++ b/dag/test/claim/floor/floor_preparation_shared_build_witness_test.dag @@ -28,9 +28,9 @@ import std.measure { millisecond, byte_size, millisecond_count } data receipt_note: String = "THE MEASURED RECEIPT THIS WITNESS DERIVES FROM, and the one number in it that is NOT a threshold. test.claim.qualified_spelling_identity_witness_test.qualified_spelling_takes_the_shared_layer was charged 57193ms CPU against a 5000ms required_floor_claim_cpu_safety_limit_ms while its sibling, reaching the identical shared computation milliseconds later, measured 5ms. The shared bare-reference edge index build behind that charge is memoized once per index (edge_index_construction { builds: 1 }, two census misses over two roots against ONE index address), so the defect was never duplication -- it was that a subject-level artifact was billed to whichever claim touched it first. The figures used below are OCCURRENCE observations exercising each branch of the derivation; the LIMITS are read from v2.workflow.required_floor, which derives them from the resource each protects (CI job budget, host memory cap), never from what any build was measured to cost." -// The ordinary case: a shared build inside all three of its limits is not refused, and says so -// while carrying its observations. A phase that reported nothing would be indistinguishable from -// a phase that did not run. +// The ordinary case: a shared build inside all three limits is not refused, and says so while +// carrying its observations. A phase reporting nothing would be indistinguishable from one that did +// not run. test fn w_shared_build_within_limits_does_not_block() -> Bool { match floor_preparation_outcome( phase: BareReferenceEdgeIndexBuild, @@ -47,7 +47,12 @@ test fn w_shared_build_within_limits_does_not_block() -> Bool { } } -data three_axis_note: String = "THE THREE AXES ARE INDEPENDENT BOUNDS ON ONE UNIT, NEVER TIERS. Each arm below crosses exactly ONE axis and leaves the other two comfortably inside, so a derivation that had fused the axes -- or that had let a later axis overwrite an earlier refusal -- goes red here on the arm it dropped rather than passing on the strength of the other two. The RSS axis is the one the two clocks cannot see at all: a build can stay inside both time limits while retaining gigabytes, and with swap disabled that is an immediate kill rather than a spill." +// THE THREE AXES ARE INDEPENDENT BOUNDS ON ONE UNIT, NEVER TIERS. Each arm below crosses exactly +// ONE axis and leaves the other two comfortably inside, so a derivation that fused the axes — or +// let a later axis overwrite an earlier refusal — reds on the arm it dropped rather than passing on +// the other two. The RSS axis is the one the two clocks cannot see: a build can stay inside both +// time limits while retaining gigabytes, and with swap disabled that is an immediate kill, not a +// spill. test fn w_cpu_axis_alone_refuses() -> Bool { floor_preparation_outcome_blocks( @@ -91,7 +96,10 @@ test fn w_rss_axis_alone_refuses() -> Bool { ) == true } -data phase_is_carried_note: String = "THE REFUSAL MUST NAME WHICH SHARED BUILD CROSSED. A refusal that lost the phase would report that preparation exceeded its limits without saying which of the three artifacts did it, which is the located half of a typed, located diagnostic. This is asserted directly rather than inferred from the arms above, all of which discard the phase." +// THE REFUSAL MUST NAME WHICH SHARED BUILD CROSSED. A refusal that lost the phase would say +// preparation exceeded its limits without saying which of the three artifacts did — the located +// half of a typed, located diagnostic. Asserted directly rather than inferred from the arms above, +// which all discard the phase. test fn w_refusal_carries_its_phase() -> Bool { match floor_preparation_outcome( @@ -114,7 +122,12 @@ test fn w_refusal_carries_its_phase() -> Bool { } } -data not_the_claim_limit_note: String = "THE ONE ASSERTION THAT KEEPS THE UNITS APART. The whole defect was a shared build judged by a per-claim ceiling, so the repair is empty if the preparation limits are ever set to the claim figures. This asserts the preparation CPU limit is strictly greater than the measured cold build of the largest current member -- not as a ratification of that measurement, but because a preparation limit at or below it would refuse every healthy run and force the exit the quarantine row's dissolution trigger forbids: raising the per-claim ceiling until it admits the defect." +// THE ONE ASSERTION THAT KEEPS THE UNITS APART. The defect was a shared build judged by a per-claim +// ceiling, so the repair is empty if the preparation limits are ever set to the claim figures. This +// asserts the preparation CPU limit is strictly greater than the measured cold build of the largest +// current member — not ratifying that measurement, but because a limit at or below it would refuse +// every healthy run and force the exit the quarantine row's dissolution trigger forbids: raising +// the per-claim ceiling until it admits the defect. test fn w_preparation_limit_is_not_the_claim_limit() -> Bool { floor_preparation_outcome_blocks( @@ -130,7 +143,11 @@ test fn w_preparation_limit_is_not_the_claim_limit() -> Bool { ) == false } -data independence_note: String = "THE TWO TERMS BLOCK INDEPENDENTLY AND NEITHER SUBSUMES THE OTHER. This is the pair that makes 'independent' an executed fact rather than a word in a comment: a refused shared build blocks while every claim is healthy, and a claim past its deadline blocks while preparation sat well inside its envelope. A derivation that had let either outcome excuse the other -- a precedence rule, or an arm that reads only one -- goes red on exactly one of these two, which is why they are separate rows rather than one conjunction." +// THE TWO TERMS BLOCK INDEPENDENTLY AND NEITHER SUBSUMES THE OTHER — the pair that makes +// 'independent' an executed fact: a refused shared build blocks while every claim is healthy, and a +// claim past its deadline blocks while preparation sat well inside its envelope. A derivation +// letting either outcome excuse the other — a precedence rule, or an arm reading only one — reds on +// exactly one of these two, which is why they are separate rows, not one conjunction. test fn w_refused_preparation_blocks_though_every_claim_is_healthy() -> Bool { floor_run_blocks( @@ -172,14 +189,16 @@ test fn w_both_within_their_own_limits_does_not_block() -> Bool { ) == false } -data provenance_note: String = "TRIGGERED_BY IS NOT OWNED_BY, and this is the row that keeps the distinction from decaying back into a Bool. The AlreadyWarmOnEntry arm CANNOT be constructed without naming what got there first: a carrier that recorded only 'someone else went first' would discard the one fact an attribution model exists to keep, and this asserts the name survives the round trip rather than that the arm merely exists." +// TRIGGERED_BY IS NOT OWNED_BY, and this row keeps the distinction from decaying back into a Bool. +// The AlreadyWarmOnEntry arm CANNOT be constructed without naming what got there first: a carrier +// recording only 'someone else went first' would discard the one fact an attribution model exists +// to keep. This asserts the name survives the round trip, not merely that the arm exists. -// THE SPECIMENS ARE BUILT BY HELPERS, NOT INLINE, AND THAT IS A GRAMMAR FACT RATHER THAN A STYLE -// CHOICE. `match BuiltByPreparation {` parses as a RECORD LITERAL whose body then hits `=>` -// ("expected expression, found FatArrow"), because a bare variant name followed by `{` is exactly -// the record-construction form. Naming the specimen first removes the ambiguity at the source -// rather than working around it, and it is why both arms are constructed the same way even though -// only the record-carrying one strictly needs it. +// THE SPECIMENS ARE BUILT BY HELPERS, NOT INLINE — A GRAMMAR FACT, NOT A STYLE CHOICE. `match +// BuiltByPreparation {` parses as a RECORD LITERAL whose body then hits `=>` ("expected expression, +// found FatArrow"), because a bare variant name followed by `{` is the record-construction form. +// Naming the specimen first removes the ambiguity at the source; both arms are constructed the same +// way though only the record-carrying one strictly needs it. fn already_warm_specimen() -> SharedBuildProvenance { AlreadyWarmOnEntry { triggered_by: "a-site-ahead-of-floor-preparation" } } diff --git a/dag/test/claim/floor/floor_resolve_realization_witness_test.dag b/dag/test/claim/floor/floor_resolve_realization_witness_test.dag index 3ac31397ef4..f0bd28b0adf 100644 --- a/dag/test/claim/floor/floor_resolve_realization_witness_test.dag +++ b/dag/test/claim/floor/floor_resolve_realization_witness_test.dag @@ -29,7 +29,11 @@ import v2.std.collection { List } import v2.std.logic { Bool } import std.measure { nanosecond } -data floor_resolve_realization_witness_note: String = "Eight required controls for 0B resolve realization (operator ruling 2026-08-04). ADMIT: anchor cold + native cold; anchor cold + native warm. REFUSE: native absent; unknown third obligation; duplicate identity; warm without provider receipt; cold without resolve receipt; unattributed physical resolve. Authority: gunbc.ci_materialization; claim_executor observes; ci_floor_plan transports only." +// Eight required controls for 0B resolve realization (operator ruling 2026-08-04). ADMIT: anchor +// cold + native cold; anchor cold + native warm. REFUSE: native absent; unknown third obligation; +// duplicate identity; warm without provider receipt; cold without resolve receipt; unattributed +// physical resolve. Authority: gunbc.ci_materialization; claim_executor observes; ci_floor_plan +// transports only. fn cold_main_realizations() -> List { [ diff --git a/dag/test/claim/fn_equality_bound_witness_test.dag b/dag/test/claim/fn_equality_bound_witness_test.dag index 87aba4d1054..2c7dabeb32e 100644 --- a/dag/test/claim/fn_equality_bound_witness_test.dag +++ b/dag/test/claim/fn_equality_bound_witness_test.dag @@ -4,7 +4,29 @@ import v2.std.live_tree { LiveTreeDisposition, SubstrateInputsOnly } data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data fn_equality_bound_witness_note: String = "Executing floor witness for the FN-level PartialEq bound trigger (v1.compiler.emit_rust v1_fn_body_equality_bound_param_names, deciding via v1.compiler.trait_bound_witness v1_equality_bound_param_name). The emitter derives Clone bounds on generic fn params ~30-48 references deep but derived NOTHING for equality, so a generic fn comparing two values of its own type param emitted bare and rustc refused with E0369 'binary operation == cannot be applied to type K'. GROUNDING FOR THE EXPECTED SPELLING, so it is not a measurement copied from this tree: quick-lynx-620 measured the requirement against rustc on the real emission -- hand-adding the bound to the emitted mirror and rebuilding the seed gave zero errors, and the required rendering is `K: Clone + PartialEq`, the equality bound COMPOSING with the separately-derived Clone bound on the same parameter rather than replacing it. THE DISCRIMINATOR IS TYPE RESOLUTION, NOT THE == SPELLING, and the two rows below exist to prove the trigger cannot be satisfied by matching on the operator. earning_comparison_bounds_its_generic_param carries BOTH comparisons in one body, exactly the shape of the real specimen: a concrete closed-enum comparison that must earn nothing, and a comparison of two K values that must earn the bound -- rustc emits exactly ONE E0369 on that real shape, at the second comparison, so the first provably compiles unbounded today. concrete_only_comparison_leaves_generic_param_bare is the sharper negative: a fn that HAS a generic param and HAS a comparison, where the comparison involves only concrete types. A predicate keyed on the presence of == bounds K there and breaks every caller instantiating K with a non-PartialEq type; the type-resolving predicate must leave it bare. That row is what makes the pair discriminating rather than two positives, and it is why the refusals below assert the bounded spelling is ABSENT rather than merely asserting some other spelling is present. Over-approximation is not free here: adding a bound TIGHTENS the emitted signature, so a spurious bound is a real break, while a missed bound only leaves the pre-existing E0369 in place." +// Executing floor witness for the FN-level PartialEq bound trigger (v1.compiler.emit_rust +// v1_fn_body_equality_bound_param_names, deciding via v1.compiler.trait_bound_witness +// v1_equality_bound_param_name). The emitter derives Clone bounds on generic fn params ~30-48 +// references deep but derived NOTHING for equality, so a generic fn comparing two values of its own +// type param emitted bare and rustc refused with E0369 'binary operation == cannot be applied to +// type K'. GROUNDING FOR THE EXPECTED SPELLING, so it is not a measurement copied from this tree: +// quick-lynx-620 measured the requirement against rustc on the real emission -- hand-adding the +// bound to the emitted mirror and rebuilding the seed gave zero errors, and the required rendering +// is `K: Clone + PartialEq`, the equality bound COMPOSING with the separately-derived Clone bound +// on the same parameter rather than replacing it. THE DISCRIMINATOR IS TYPE RESOLUTION, NOT THE == +// SPELLING, and the two rows below exist to prove the trigger cannot be satisfied by matching on +// the operator. earning_comparison_bounds_its_generic_param carries BOTH comparisons in one body, +// exactly the shape of the real specimen: a concrete closed-enum comparison that must earn nothing, +// and a comparison of two K values that must earn the bound -- rustc emits exactly ONE E0369 on +// that real shape, at the second comparison, so the first provably compiles unbounded today. +// concrete_only_comparison_leaves_generic_param_bare is the sharper negative: a fn that HAS a +// generic param and HAS a comparison, where the comparison involves only concrete types. A +// predicate keyed on the presence of == bounds K there and breaks every caller instantiating K with +// a non-PartialEq type; the type-resolving predicate must leave it bare. That row is what makes the +// pair discriminating rather than two positives, and it is why the refusals below assert the +// bounded spelling is ABSENT rather than merely asserting some other spelling is present. +// Over-approximation is not free here: adding a bound TIGHTENS the emitted signature, so a spurious +// bound is a real break, while a missed bound only leaves the pre-existing E0369 in place. test fn earning_comparison_bounds_its_generic_param() -> Bool { compile_dag_rust_emit_check( @@ -24,7 +46,24 @@ test fn concrete_only_comparison_leaves_generic_param_bare() -> Bool { ) } -data fn_equality_forwarding_note: String = "Executing floor witness for the CALL-FORWARDING half of the same trigger (v1.compiler.emit_rust v1_call_forwarding_equality_bound_param_names). The seed synthesized the bound only on the fn whose OWN body compares, which is a program that does not typecheck one hop up: a caller instantiating that fn's K with its own generic param is obliged by rustc to prove a bound it never states, and rustc refuses with E0277. MEASURED, not assumed: the real specimen is gunbc#8605's std.trait_derive_shape, where repr_grounding_derive_shape_has_trait compares k == capability_key and earns the bound while repr_grounding_derive_completeness_predicate forwards its own K into that parameter; the reduction below was emitted through the seed before the fix and produced `pub fn cap_table_complete` -- the Clone bound present, the PartialEq bound absent -- which is why the refusal asserts that exact spelling is gone rather than merely asserting the fixed one is present. THE FORWARDED CALL IS NOT AT THE BODY'S ROOT: it sits inside a lambda inside a pipelined all(), the shape the pre-existing Clone forwarding structurally cannot reach, so a row whose caller body IS the call would pass without exercising the recursive walk this row exists to hold. forwarding_into_unbounded_callee_leaves_generic_param_bare is the discriminator: same wrapper shape, same generic param, same pipeline, but the callee compares only concrete types and so earns nothing -- a derivation keyed on 'my callee is generic' rather than on the callee's own resolved-type verdict bounds K there and breaks every caller instantiating K with a non-PartialEq type." +// Executing floor witness for the CALL-FORWARDING half of the same trigger (v1.compiler.emit_rust +// v1_call_forwarding_equality_bound_param_names). The seed synthesized the bound only on the fn +// whose OWN body compares, which is a program that does not typecheck one hop up: a caller +// instantiating that fn's K with its own generic param is obliged by rustc to prove a bound it +// never states, and rustc refuses with E0277. MEASURED, not assumed: the real specimen is +// gunbc#8605's std.trait_derive_shape, where repr_grounding_derive_shape_has_trait compares k == +// capability_key and earns the bound while repr_grounding_derive_completeness_predicate forwards +// its own K into that parameter; the reduction below was emitted through the seed before the fix +// and produced `pub fn cap_table_complete` -- the Clone bound present, the PartialEq +// bound absent -- which is why the refusal asserts that exact spelling is gone rather than merely +// asserting the fixed one is present. THE FORWARDED CALL IS NOT AT THE BODY'S ROOT: it sits inside +// a lambda inside a pipelined all(), the shape the pre-existing Clone forwarding structurally +// cannot reach, so a row whose caller body IS the call would pass without exercising the recursive +// walk this row exists to hold. forwarding_into_unbounded_callee_leaves_generic_param_bare is the +// discriminator: same wrapper shape, same generic param, same pipeline, but the callee compares +// only concrete types and so earns nothing -- a derivation keyed on 'my callee is generic' rather +// than on the callee's own resolved-type verdict bounds K there and breaks every caller +// instantiating K with a non-PartialEq type. test fn forwarding_caller_inherits_callee_equality_bound() -> Bool { compile_dag_rust_emit_check( diff --git a/dag/test/claim/frame_boundary_witness_test.dag b/dag/test/claim/frame_boundary_witness_test.dag index 4131bf60c83..b3bebf583ea 100644 --- a/dag/test/claim/frame_boundary_witness_test.dag +++ b/dag/test/claim/frame_boundary_witness_test.dag @@ -13,7 +13,14 @@ import std.frame_boundary { boundary_admits, } -// Discriminating witnesses for the frame-boundary SPEC (std.frame_boundary). The claim is fail-closed boundary admission (DESIGN 5): a frame runs only when every layer it requires closed is covered by the provided materialization; an uncovered required layer is a located BoundaryUnmaterialized naming that tree, never a silent pass. The build's common case: require the network layer (UriTree) closed; the Simulated/mock handler closes it at LifecycleByConvention (admissible, honestly weaker). RED control = refuses_uncovered_layer: if the coverage check were dropped, an uncovered UriTree would admit. Grade is the MEET across covered layers (only as strong as the weakest), pinned by grade_is_meet. +// Discriminating witnesses for the frame-boundary SPEC (std.frame_boundary). Claim: fail-closed +// boundary admission (DESIGN 5) — a frame runs only when every layer it requires closed is covered +// by the provided materialization; an uncovered required layer is a located BoundaryUnmaterialized +// naming that tree, never a silent pass. Common case: require the network layer (UriTree) closed; +// the Simulated/mock handler closes it at LifecycleByConvention (admissible, honestly weaker). RED +// control = refuses_uncovered_layer: with the coverage check dropped, an uncovered UriTree would +// admit. Grade is the MEET across covered layers (as strong as the weakest), pinned by +// grade_is_meet. data net_convention_provided: BoundaryMaterialization = BoundaryMaterialization { closures: [BoundaryClosure { tree: UriTree, grade: LifecycleByConvention }] } diff --git a/dag/test/claim/frontend_literal_and_compile_witness_test.dag b/dag/test/claim/frontend_literal_and_compile_witness_test.dag index ba699afac38..9c489bd92a0 100644 --- a/dag/test/claim/frontend_literal_and_compile_witness_test.dag +++ b/dag/test/claim/frontend_literal_and_compile_witness_test.dag @@ -1,6 +1,15 @@ module test.claim.frontend_literal_and_compile_witness_test -data frontend_literal_and_compile_migration_note: String = "Migrated from src/v1/tests/claim/ordinary_frontend_observation_test.dag (dead witness tree triage, dashboard node adhoc-9b80ec49-d63). That file mixed two unrelated subjects under one v1 import: two pure interpreter-literal-semantics tests that never actually called any v1 symbol (moved here unchanged, needing no v1 import and no special source roots), and two black-box compile-and-observe tests built on v1.compiler.frontend_observation's observe_ordinary_frontend, which required a v1-scoped root to execute and never actually ran (its only historical consumer, v1_claim_scoped_witness_batch, was deleted 2026-08-15). Those two convert directly to compile_dag_rust_emit_check: a tiny valid subject must compile clean, a syntactically broken one must not — the same 'runs, and reports a broken subject rather than fabricating success' claim, proven through the production compile path instead of the v1-internal receipt shape." +// Migrated from src/v1/tests/claim/ordinary_frontend_observation_test.dag (dead witness tree +// triage, dashboard node adhoc-9b80ec49-d63). That file mixed two unrelated subjects under one v1 +// import: two pure interpreter-literal-semantics tests that never actually called any v1 symbol +// (moved here unchanged, needing no v1 import and no special source roots), and two black-box +// compile-and-observe tests built on v1.compiler.frontend_observation's observe_ordinary_frontend, +// which required a v1-scoped root to execute and never actually ran (its only historical consumer, +// v1_claim_scoped_witness_batch, was deleted 2026-08-15). Those two convert directly to +// compile_dag_rust_emit_check: a tiny valid subject must compile clean, a syntactically broken one +// must not — the same 'runs, and reports a broken subject rather than fabricating success' claim, +// proven through the production compile path instead of the v1-internal receipt shape. // The map-literal representation, on a CONTROLLED fixture: this module // authors both the input and the expected key population, so the assertion diff --git a/dag/test/claim/function_derive_alias_hop_witness_test.dag b/dag/test/claim/function_derive_alias_hop_witness_test.dag index f3919470724..cda5d2b2194 100644 --- a/dag/test/claim/function_derive_alias_hop_witness_test.dag +++ b/dag/test/claim/function_derive_alias_hop_witness_test.dag @@ -4,7 +4,14 @@ import v2.std.live_tree { LiveTreeDisposition, SubstrateInputsOnly } data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data function_derive_alias_hop_witness_note: String = "Executing regression control for function-valued carrier derive admissibility through a type-alias hop. A function value implements Clone through the Rust Rc realization, but it implements neither Debug nor serde Serialize/Deserialize; changing Rc therefore cannot repair those impossible derives. The positive fixture makes a record reach a callable through a structural alias and requires Clone-only emission. The Bytes fixture is the discriminating native-realization control: Bytes has a Rust checkpoint, so the alias RHS is not the emitted representation and must not narrow its holder. The plain structural alias proves the walk does not narrow every alias. All rows cross the real emitter through compile_dag_rust_emit_check." +// Executing regression control for function-valued carrier derive admissibility through a +// type-alias hop. A function value implements Clone through the Rust Rc realization, but it +// implements neither Debug nor serde Serialize/Deserialize; changing Rc therefore cannot repair +// those impossible derives. The positive fixture makes a record reach a callable through a +// structural alias and requires Clone-only emission. The Bytes fixture is the discriminating +// native-realization control: Bytes has a Rust checkpoint, so the alias RHS is not the emitted +// representation and must not narrow its holder. The plain structural alias proves the walk does +// not narrow every alias. All rows cross the real emitter through compile_dag_rust_emit_check. test fn structural_alias_to_callable_derives_clone_only() -> Bool { compile_dag_rust_emit_check( diff --git a/dag/test/claim/gate_receipt_witness_test.dag b/dag/test/claim/gate_receipt_witness_test.dag index 70a5d4b36eb..5527975822f 100644 --- a/dag/test/claim/gate_receipt_witness_test.dag +++ b/dag/test/claim/gate_receipt_witness_test.dag @@ -12,9 +12,26 @@ import v2.std.live_tree { LiveTreeDisposition, SubstrateInputsOnly } data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data gate_receipt_witness_scope_note: String = "SubstrateInputsOnly, and that is the honest declaration rather than a convenience: every subject here is a hand-constructed GateReceipt, and the projections under test are pure folds over it. Nothing calls the host builtins that PRODUCE a receipt. WHAT THESE PROVE: that the three arms reach three DIFFERENT places, in both the exit projection and the detail projection. WHAT THEY DO NOT PROVE: that the host maps its own states onto the right arms -- that half is asserted by the cargo tests beside the globals in cli_run.rs (floor_compile_clean_gate_separates_not_applicable_from_clean and generated_artifact_drift_gate_separates_unrecorded_from_clean), because only there can a receipt fixture be installed into the process global the builtin reads. The two halves are complementary and neither is the other's substitute: a host that mapped every state to GateNotRun would pass every witness in this file." +// SubstrateInputsOnly, and that is the honest declaration rather than a convenience: every subject +// here is a hand-constructed GateReceipt, and the projections under test are pure folds over it. +// Nothing calls the host builtins that PRODUCE a receipt. WHAT THESE PROVE: that the three arms +// reach three DIFFERENT places, in both the exit projection and the detail projection. WHAT THEY DO +// NOT PROVE: that the host maps its own states onto the right arms -- that half is asserted by the +// cargo tests beside the globals in cli_run.rs +// (floor_compile_clean_gate_separates_not_applicable_from_clean and +// generated_artifact_drift_gate_separates_unrecorded_from_clean), because only there can a receipt +// fixture be installed into the process global the builtin reads. The two halves are complementary +// and neither is the other's substitute: a host that mapped every state to GateNotRun would pass +// every witness in this file. -data gate_receipt_discrimination_note: String = "THE ASSERTIONS ARE WRITTEN AS DISCRIMINATIONS, not as arm-by-arm value checks, because an arm-by-arm check greens on a projection that collapses two arms as long as each row is read separately. The predecessor of this carrier answered Bool, where NotApplicable and Clean were BOTH true and NotRun and Failed were BOTH false; the pairs asserted below are exactly those two collapses, so each one goes red against the shape this retype replaced. That is the discriminating RED this evidence is enrolled for, and it stays enrolled after the climb rather than retiring with it (DESIGN 4b meta-obligation 4: a climb dissolves the redundant production machinery, never the evidence that the higher rung is still real)." +// THE ASSERTIONS ARE WRITTEN AS DISCRIMINATIONS, not as arm-by-arm value checks, because an +// arm-by-arm check greens on a projection that collapses two arms as long as each row is read +// separately. The predecessor of this carrier answered Bool, where NotApplicable and Clean were +// BOTH true and NotRun and Failed were BOTH false; the pairs asserted below are exactly those two +// collapses, so each one goes red against the shape this retype replaced. That is the +// discriminating RED this evidence is enrolled for, and it stays enrolled after the climb rather +// than retiring with it (DESIGN 4b meta-obligation 4: a climb dissolves the redundant production +// machinery, never the evidence that the higher rung is still real). data clean_receipt: GateReceipt = GateObserved { outcome: GateClean } data failed_receipt: GateReceipt = GateObserved { diff --git a/dag/test/claim/generated_artifact_merge_driver_real_execution_witness_test.dag b/dag/test/claim/generated_artifact_merge_driver_real_execution_witness_test.dag index 061c7c208f6..dd9c2843b98 100644 --- a/dag/test/claim/generated_artifact_merge_driver_real_execution_witness_test.dag +++ b/dag/test/claim/generated_artifact_merge_driver_real_execution_witness_test.dag @@ -32,7 +32,13 @@ data witness_base_content: String = "base\n" data witness_ours_content: String = "ours\n" data witness_theirs_content: String = "theirs\n" -data witness_driver_script_home_note: String = "The driver script sits at the repository root here, not under .githooks/, because Filesystem.Write carries no directory-creation fact and a witness that quietly depended on one would be proving something about the harness. The location is a parameter of the modeled config value (generated_artifact_merge_driver_config_value_at), so the committed binding and this witness still shape their value through one authority; only the path differs. Git runs a low-level merge driver from the top of the worktree, so the relative spelling is what the committed binding also relies on." +// The driver script sits at the repository root here, not under .githooks/, because +// Filesystem.Write carries no directory-creation fact and a witness that quietly depended on one +// would be proving something about the harness. The location is a parameter of the modeled config +// value (generated_artifact_merge_driver_config_value_at), so the committed binding and this +// witness still shape their value through one authority; only the path differs. Git runs a +// low-level merge driver from the top of the worktree, so the relative spelling is what the +// committed binding also relies on. fn witness_repo_file(repo: FilePath, name: String) -> String { concat(concat(repo as String, "/"), name) diff --git a/dag/test/claim/generic_item_clone_bound_witness_test.dag b/dag/test/claim/generic_item_clone_bound_witness_test.dag index 560253f64e1..4155bf5f8f3 100644 --- a/dag/test/claim/generic_item_clone_bound_witness_test.dag +++ b/dag/test/claim/generic_item_clone_bound_witness_test.dag @@ -4,7 +4,26 @@ import v2.std.live_tree { LiveTreeDisposition, SubstrateInputsOnly } data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data generic_item_clone_bound_witness_note: String = "Executing floor witness for v1.compiler.trait_derive_emit item-level Clone bounds. compile_dag_rust_emit_check is the per-PR enrolled consumer here; it compiles inline fixtures and asserts emitted Rust spellings. Per-PR rustc evidence is the build job cargo-checking the whole stage0 crate (generated std modules compile only when bounds are correct). TWO INDEPENDENT TRIGGERS, and the negative controls below are what keep them from collapsing into one widening rule. DERIVE trigger (structs only): bound P when P is a bare field type or a container/FreeMonoid element; enum items keep bare params, because derive emits per-impl bounds. WELL-FORMEDNESS trigger (structs AND enums): naming a declared generic type G requires satisfying G's own declared bounds, so if G's i-th parameter already carries `: Clone` and the i-th argument's Clone impl needs P, the declaring item is ill-formed without P: Clone -- rustc E0277 at the field, before any derive is considered. The second trigger is a LEAST FIXPOINT over the declared-type graph, so it propagates along a chain and saturates on a recursive type. Unused phantom-only params stay bare under both triggers. Two rows exist specifically to prove the triggers do not collapse into a dual representation: both_triggers_render_single_bound emits an item where BOTH triggers fire and asserts the bound renders exactly ONCE (the union is a guarded set-insert, so it is idempotent by construction, and the refusals assert the doubled spellings never appear); unbounded_declared_container_negative_control emits an item reached ONLY through a declared generic type whose own parameter the fixpoint leaves unbounded (FreeMonoid) and asserts no bound propagates, which is the case where trigger 2 must stay silent while trigger 1 alone carries ContainmentPath. That row locks in existing behavior rather than asserting new behavior." +// Executing floor witness for v1.compiler.trait_derive_emit item-level Clone bounds. +// compile_dag_rust_emit_check is the per-PR enrolled consumer here; it compiles inline fixtures and +// asserts emitted Rust spellings. Per-PR rustc evidence is the build job cargo-checking the whole +// stage0 crate (generated std modules compile only when bounds are correct). TWO INDEPENDENT +// TRIGGERS, and the negative controls below are what keep them from collapsing into one widening +// rule. DERIVE trigger (structs only): bound P when P is a bare field type or a +// container/FreeMonoid element; enum items keep bare params, because derive emits per-impl bounds. +// WELL-FORMEDNESS trigger (structs AND enums): naming a declared generic type G requires +// satisfying G's own declared bounds, so if G's i-th parameter already carries `: Clone` and the +// i-th argument's Clone impl needs P, the declaring item is ill-formed without P: Clone -- rustc +// E0277 at the field, before any derive is considered. The second trigger is a LEAST FIXPOINT over +// the declared-type graph, so it propagates along a chain and saturates on a recursive type. Unused +// phantom-only params stay bare under both triggers. Two rows exist specifically to prove the +// triggers do not collapse into a dual representation: both_triggers_render_single_bound emits an +// item where BOTH triggers fire and asserts the bound renders exactly ONCE (the union is a guarded +// set-insert, so it is idempotent by construction, and the refusals assert the doubled spellings +// never appear); unbounded_declared_container_negative_control emits an item reached ONLY through a +// declared generic type whose own parameter the fixpoint leaves unbounded (FreeMonoid) and asserts +// no bound propagates, which is the case where trigger 2 must stay silent while trigger 1 alone +// carries ContainmentPath. That row locks in existing behavior rather than asserting new behavior. fn w_containment_path_emits_clone_bound() -> Bool { compile_dag_rust_emit_check( @@ -132,7 +151,22 @@ test fn unbounded_declared_container_negative_control() -> Bool { w_unbounded_declared_container_propagates_nothing() } -data fn_clone_bound_wf_witness_note: String = "THIRD site, same fixpoint: naming a Clone-bounded declared type in a FN value-param or return type is exactly as ill-formed as naming it in a field (v1_fn_param_wf_needs_clone, extending the same well-formedness trigger onto v1_generic_params_needing_clone_bound rather than a second fixpoint). w_fn_wf_bound_propagates_to_bare_generic is the occurrence_binding_from_candidates specimen shape (deep-heron's honest regen of dag/std/occurrence_binding.dag) reduced to a discriminating fixture: N is named only inside BindingOccurrence (value-param position) and OccurrenceBindingResult (return position), never as a bare N itself, so the structural trigger (v1_type_param_needs_clone_bound) alone would leave it unbounded and only the WF trigger renders `` -- this is the RED-on-pre-fix / GREEN-on-fix witness. w_fn_no_wf_trigger_stays_bare is the negative control: a fn naming only unbounded declared types keeps its generic param bare, proving the WF trigger does not widen to every fn touching a declared type. w_impl_accessor_inherits_item_bound_once locks in the already-correct IMPL-side behavior (accessor impl blocks read the struct's own item-level clone_bounded_type_params via emit_item_type_params_with_clone_bounds, not a fn-grain re-derivation) by asserting the accessor impl header carries the bound exactly once, with doubled-spelling refusals mirroring both_triggers_render_single_bound above." +// THIRD site, same fixpoint: naming a Clone-bounded declared type in a FN value-param or return +// type is exactly as ill-formed as naming it in a field (v1_fn_param_wf_needs_clone, extending the +// same well-formedness trigger onto v1_generic_params_needing_clone_bound rather than a second +// fixpoint). w_fn_wf_bound_propagates_to_bare_generic is the occurrence_binding_from_candidates +// specimen shape (deep-heron's honest regen of dag/std/occurrence_binding.dag) reduced to a +// discriminating fixture: N is named only inside BindingOccurrence (value-param position) and +// OccurrenceBindingResult (return position), never as a bare N itself, so the structural trigger +// (v1_type_param_needs_clone_bound) alone would leave it unbounded and only the WF trigger renders +// `` -- this is the RED-on-pre-fix / GREEN-on-fix witness. w_fn_no_wf_trigger_stays_bare +// is the negative control: a fn naming only unbounded declared types keeps its generic param bare, +// proving the WF trigger does not widen to every fn touching a declared type. +// w_impl_accessor_inherits_item_bound_once locks in the already-correct IMPL-side behavior +// (accessor impl blocks read the struct's own item-level clone_bounded_type_params via +// emit_item_type_params_with_clone_bounds, not a fn-grain re-derivation) by asserting the accessor +// impl header carries the bound exactly once, with doubled-spelling refusals mirroring +// both_triggers_render_single_bound above. fn w_fn_wf_bound_propagates_to_bare_generic() -> Bool { compile_dag_rust_emit_check( @@ -256,7 +290,73 @@ test fn fn_nested_value_wrapper_positive_control() -> Bool { w_fn_nested_value_wrapper_gets_clone() } -data freemonoid_supplemental_impl_witness_note: String = "Row 1a target shapes (FreeMonoidUniqueState, ListTailResult in src/v2/std/algebra.dag), exercising v1_emit_struct_from_capability_table / v1_emit_enum_supplemental_impls end to end rather than the pre-existing structural/WF fixpoint above: a struct or enum whose only Clone-requiring field is FreeMonoid keeps a BARE item-level header (the derive/WF triggers above never fire for an undeclared external container), Debug and PartialEq are realized as hand-written impls instead of #[derive(..)] (v1_exclude_hand_written_freemonoid_traits drops them from the derive list), each impl header carrying the UNION of the supplemental T: Clone bound and the structural bound its own body needs (T: Clone + std::fmt::Debug for the hand-written Debug impl, T: Clone + PartialEq for the hand-written PartialEq impl). Clone and PartialEq are bare, not path-qualified, because both are prelude traits (std::prelude::v1 re-exports std::clone::Clone and std::cmp::PartialEq by their trait names -- confirmed against doc.rust-lang.org/std/prelude/index.html's prelude-contents listing). Debug is NOT: that page's listing has no std::fmt::Debug entry at all, and the only `Debug` the prelude brings into scope is the derive macro std::prelude::v1::Debug -- a distinct namespace citizen from the trait. A bare `T: Debug` bound in a module with no explicit `use std::fmt::Debug;` therefore resolves the name to the macro and rustc refuses with error[E0404]: expected trait, found derive macro `Debug`, on every hand-written Debug impl this mechanism emits -- independent of and prior to any emitter's behavior. The bound is path-qualified (T: Clone + std::fmt::Debug) for exactly this reason, matching the `for` clause's existing std::fmt::Debug qualification rather than leaving the bound and the `for` position spelled two different ways for the same trait. Serialize/Deserialize stay #[derive(..)] with a #[serde(bound(..))] override naming every item generic param against the fully-qualified serde::Serialize / serde::Deserialize<'de> paths (serde's traits are not in the emitted module's scope by bare name either, so an unqualified bound string would fail to resolve). The struct row's derive list carries Clone but never Copy: FreeMonoid is a shared type and realizes as Rc> (v1_emit_struct_derives selects the heap roster over the copy roster on exactly that membership), and std::rc::Rc does not implement Copy for any T regardless of T's own bounds -- confirmed against doc.rust-lang.org/std/rc/struct.Rc.html's trait-implementation list (Clone present, Copy absent) and doc.rust-lang.org/std/marker/trait.Copy.html's field requirement (every field's type must implement Copy). #[derive(Copy)] on a type with an Rc field is therefore not a spelling choice but rustc E0277/E0204 (\"the trait Copy cannot be implemented for this type\", naming the Rc-realized field) on every instantiation of T, independent of and prior to any emitter's behavior -- the corrected list is the ONLY one a correct implementation of the mechanism under test could produce. w_freemonoid_supplemental_struct_hand_written_impls and w_freemonoid_supplemental_enum_hand_written_impls assert all four facts positively (bare item header, hand-written impl headers carrying the full bound union with Debug path-qualified in the bound, fully-qualified serde bound attr) and negatively (no bounded item header, no naive #[derive(Debug...)] reintroducing the excluded traits, no bare-Debug-in-bound spelling that would resolve to the derive macro, no Copy in the struct's derive list). The struct witness additionally asserts both impl BODIES, not only their headers: correct headers over an empty or wrong body would otherwise satisfy every other assertion here -- a PartialEq whose body is literally `true` passes a header-only witness, and the enum witness's body assertions would catch that only by being the more thorough of the pair, which is luck rather than coverage wherever the struct and enum emission paths can diverge. The body spellings are grounded independently of this emitter: the `&self.` access form and the `fn eq(&self, other: &Self) -> bool` signature come from the pre-existing NonEmptyVec hand-written impls the runtime prelude already emits . That same precedent independently corroborates the two impl HEADERS asserted above, which is worth stating separately because it was not the reason the precedent was consulted: the runtime prelude emits `impl std::fmt::Debug for NonEmptyVec`, character-for-character the shape of the third include here, authored before this change existed and by a different mechanism -- so those two header assertions are precedent-backed rather than author-chosen, which matters because every other assertion in this witness was authored by the same session that authored the emitter under test. And `debug_struct(..).field(..).finish()` is the std::fmt::Formatter builder documented for named-field structs, the named-field counterpart of the debug_tuple form NonEmptyVec uses for its tuple field. If this emitter disagrees with those spellings the emitter is what changes, not these strings. Two known limits of this witness, recorded so neither is mistaken for coverage: the include assertions are SPELLING-sensitive, so a semantically identical `impl Debug for X where T: Clone + Debug` would fail include 3 -- normal for a golden, but it means a red here is not by itself evidence of a semantic defect; and the `#[derive(Debug` exclude matches anywhere in the emitted file, which is safe only because this fixture declares a single type -- a future fixture carrying two types would silently weaken it to a file-wide rather than per-item assertion. Finally, on this row's own representation: the bulk of it is CITATIONS, which section 4c places in a typed carrier rather than in prose, so its eventual destination is not a leading // block either -- a comment is exactly as unreadable to a machine as this String, and both are the same deferral in different syntax. It is left as-is deliberately: converting this row alone, while the other rows in this file and the rest of the corpus keep the String form, would author a third representation rather than remove one." +// Row 1a target shapes (FreeMonoidUniqueState, ListTailResult in src/v2/std/algebra.dag), +// exercising v1_emit_struct_from_capability_table / v1_emit_enum_supplemental_impls end to end +// rather than the pre-existing structural/WF fixpoint above: a struct or enum whose only +// Clone-requiring field is FreeMonoid keeps a BARE item-level header (the derive/WF triggers +// above never fire for an undeclared external container), Debug and PartialEq are realized as +// hand-written impls instead of #[derive(..)] (v1_exclude_hand_written_freemonoid_traits drops them +// from the derive list), each impl header carrying the UNION of the supplemental T: Clone bound and +// the structural bound its own body needs (T: Clone + std::fmt::Debug for the hand-written Debug +// impl, T: Clone + PartialEq for the hand-written PartialEq impl). Clone and PartialEq are bare, +// not path-qualified, because both are prelude traits (std::prelude::v1 re-exports +// std::clone::Clone and std::cmp::PartialEq by their trait names -- confirmed against +// doc.rust-lang.org/std/prelude/index.html's prelude-contents listing). Debug is NOT: that page's +// listing has no std::fmt::Debug entry at all, and the only `Debug` the prelude brings into scope +// is the derive macro std::prelude::v1::Debug -- a distinct namespace citizen from the trait. A +// bare `T: Debug` bound in a module with no explicit `use std::fmt::Debug;` therefore resolves the +// name to the macro and rustc refuses with error[E0404]: expected trait, found derive macro +// `Debug`, on every hand-written Debug impl this mechanism emits -- independent of and prior to any +// emitter's behavior. The bound is path-qualified (T: Clone + std::fmt::Debug) for exactly this +// reason, matching the `for` clause's existing std::fmt::Debug qualification rather than leaving +// the bound and the `for` position spelled two different ways for the same trait. +// Serialize/Deserialize stay #[derive(..)] with a #[serde(bound(..))] override naming every item +// generic param against the fully-qualified serde::Serialize / serde::Deserialize<'de> paths +// (serde's traits are not in the emitted module's scope by bare name either, so an unqualified +// bound string would fail to resolve). The struct row's derive list carries Clone but never Copy: +// FreeMonoid is a shared type and realizes as Rc> (v1_emit_struct_derives selects the +// heap roster over the copy roster on exactly that membership), and std::rc::Rc does not +// implement Copy for any T regardless of T's own bounds -- confirmed against +// doc.rust-lang.org/std/rc/struct.Rc.html's trait-implementation list (Clone present, Copy absent) +// and doc.rust-lang.org/std/marker/trait.Copy.html's field requirement (every field's type must +// implement Copy). #[derive(Copy)] on a type with an Rc field is therefore not a spelling choice +// but rustc E0277/E0204 ("the trait Copy cannot be implemented for this type", naming the +// Rc-realized field) on every instantiation of T, independent of and prior to any emitter's +// behavior -- the corrected list is the ONLY one a correct implementation of the mechanism under +// test could produce. w_freemonoid_supplemental_struct_hand_written_impls and +// w_freemonoid_supplemental_enum_hand_written_impls assert all four facts positively (bare item +// header, hand-written impl headers carrying the full bound union with Debug path-qualified in the +// bound, fully-qualified serde bound attr) and negatively (no bounded item header, no naive +// #[derive(Debug...)] reintroducing the excluded traits, no bare-Debug-in-bound spelling that would +// resolve to the derive macro, no Copy in the struct's derive list). The struct witness +// additionally asserts both impl BODIES, not only their headers: correct headers over an empty or +// wrong body would otherwise satisfy every other assertion here -- a PartialEq whose body is +// literally `true` passes a header-only witness, and the enum witness's body assertions would catch +// that only by being the more thorough of the pair, which is luck rather than coverage wherever the +// struct and enum emission paths can diverge. The body spellings are grounded independently of this +// emitter: the `&self.` access form and the `fn eq(&self, other: &Self) -> bool` signature +// come from the pre-existing NonEmptyVec hand-written impls the runtime prelude already emits . +// That same precedent independently corroborates the two impl HEADERS asserted above, which is +// worth stating separately because it was not the reason the precedent was consulted: the runtime +// prelude emits `impl std::fmt::Debug for NonEmptyVec`, +// character-for-character the shape of the third include here, authored before this change existed +// and by a different mechanism -- so those two header assertions are precedent-backed rather than +// author-chosen, which matters because every other assertion in this witness was authored by the +// same session that authored the emitter under test. And `debug_struct(..).field(..).finish()` is +// the std::fmt::Formatter builder documented for named-field structs, the named-field counterpart +// of the debug_tuple form NonEmptyVec uses for its tuple field. If this emitter disagrees with +// those spellings the emitter is what changes, not these strings. Two known limits of this witness, +// recorded so neither is mistaken for coverage: the include assertions are SPELLING-sensitive, so a +// semantically identical `impl Debug for X where T: Clone + Debug` would fail include 3 -- +// normal for a golden, but it means a red here is not by itself evidence of a semantic defect; and +// the `#[derive(Debug` exclude matches anywhere in the emitted file, which is safe only because +// this fixture declares a single type -- a future fixture carrying two types would silently weaken +// it to a file-wide rather than per-item assertion. Finally, on this row's own representation: the +// bulk of it is CITATIONS, which section 4c places in a typed carrier rather than in prose, so its +// eventual destination is not a leading // block either -- a comment is exactly as unreadable to a +// machine as this String, and both are the same deferral in different syntax. It is left as-is +// deliberately: converting this row alone, while the other rows in this file and the rest of the +// corpus keep the String form, would author a third representation rather than remove one. fn w_freemonoid_supplemental_struct_hand_written_impls() -> Bool { compile_dag_rust_emit_check( diff --git a/dag/test/claim/generic_item_ord_bound_witness_test.dag b/dag/test/claim/generic_item_ord_bound_witness_test.dag index 61467cba353..cd862e01293 100644 --- a/dag/test/claim/generic_item_ord_bound_witness_test.dag +++ b/dag/test/claim/generic_item_ord_bound_witness_test.dag @@ -4,7 +4,24 @@ import v2.std.live_tree { LiveTreeDisposition, SubstrateInputsOnly } data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data generic_item_ord_bound_witness_note: String = "Executing floor witness for v1.compiler.trait_derive_emit's per-derive-impl Ord routing (trait_derive_emit_set_ord_supplemental_note's direct-field enum case, plus trait_derive_emit_ord_propagation_note's one-hop transitive struct case). This file replaces an earlier revision (PR #8770's orphaned predecessor commit) that asserted a header-level P: Ord bound (v1_ord_bounded_type_params / v1_emit_type_params_with_clone_and_ord_bounds) — that machinery was discarded per parent-session review (adhoc-a407cd3d-840): it would have re-opened the over-bounding trait_derive_emit_set_ord_supplemental_note already rejected Debug/PartialEq unioning Ord onto every reachable item's own HEADER, never the derive-impl. compile_dag_rust_emit_check is the per-PR enrolled consumer, compiling inline fixtures through the real emitter and asserting emitted Rust spellings. Every positive witness here asserts BOTH that the item's own header/declaration stays bare (never P: Ord) AND that a hand-written impl carries the Ord bound instead. The corpus shape (std.authorization_profile PublicationContext { audience: AudienceSet

, context: C }) is a struct whose field names a DECLARED coproduct (AudienceSet

) that itself carries the direct Set

field — one hop, not a bare Set

field on the struct itself. A struct with a DIRECT Set

field (no coproduct hop) is UNHANDLED by this lane, same scope boundary trait_derive_emit_set_ord_supplemental_note already drew for the enum case (\"no struct in the corpus carries a generic Set

field today, so struct-side wiring would be speculative\") — no corpus specimen needs it and no witness here asserts a behavior for it." +// Executing floor witness for v1.compiler.trait_derive_emit's per-derive-impl Ord routing +// (trait_derive_emit_set_ord_supplemental_note's direct-field enum case, plus +// trait_derive_emit_ord_propagation_note's one-hop transitive struct case). This file replaces an +// earlier revision (PR #8770's orphaned predecessor commit) that asserted a header-level P: Ord +// bound (v1_ord_bounded_type_params / v1_emit_type_params_with_clone_and_ord_bounds) — that +// machinery was discarded per parent-session review (adhoc-a407cd3d-840): it would have re-opened +// the over-bounding trait_derive_emit_set_ord_supplemental_note already rejected Debug/PartialEq +// unioning Ord onto every reachable item's own HEADER, never the derive-impl. +// compile_dag_rust_emit_check is the per-PR enrolled consumer, compiling inline fixtures through +// the real emitter and asserting emitted Rust spellings. Every positive witness here asserts BOTH +// that the item's own header/declaration stays bare (never P: Ord) AND that a hand-written impl +// carries the Ord bound instead. The corpus shape (std.authorization_profile PublicationContext { audience: AudienceSet

, context: C }) is a struct whose field names a DECLARED coproduct +// (AudienceSet

) that itself carries the direct Set

field — one hop, not a bare Set

field +// on the struct itself. A struct with a DIRECT Set

field (no coproduct hop) is UNHANDLED by this +// lane, same scope boundary trait_derive_emit_set_ord_supplemental_note already drew for the enum +// case ("no struct in the corpus carries a generic Set

field today, so struct-side wiring would +// be speculative") — no corpus specimen needs it and no witness here asserts a behavior for it. fn w_enum_direct_set_field_stays_header_bare_gets_hand_written_impl() -> Bool { compile_dag_rust_emit_check( diff --git a/dag/test/claim/gha_job_projection_witness_test.dag b/dag/test/claim/gha_job_projection_witness_test.dag index ec3e49570ba..84e38b6b7b2 100644 --- a/dag/test/claim/gha_job_projection_witness_test.dag +++ b/dag/test/claim/gha_job_projection_witness_test.dag @@ -16,7 +16,22 @@ import v2.std.live_tree { LiveTreeDisposition, SubstrateInputsOnly } data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data gha_job_projection_witness_note: String = "THE CONSTRUCTION-LEVEL WALL AGAINST FUTURE INERT Job FIELDS, and the reason it is one synthetic all-fields job rather than a per-field assertion against ci.yml. job_yaml silently dropped four of the Job type's emittable fields (see job_field_projection_completeness_note); a per-field check against the real workflows could not have caught any of them, because every Job in the corpus sets those fields to none — so the real artifacts are indistinguishable from an emitter that ignores the fields entirely. The only discriminating subject is a job that POPULATES every optional field, which is why one is constructed here. Two directions are asserted and both are load-bearing: all_fields_job proves each populated fact reaches the emitted yaml (a new dropped field reds), and minimal_job proves an absent field emits NO key (a projection that started emitting an empty `outputs: {}` or a bare `name:` also reds). Without the second direction the first is satisfiable by unconditionally emitting every key. This is validation, not construction — DESIGN §5's preference is a model from which the projection is derived so a dropped field is unwritable, and that is not reachable while job_yaml is a hand-written fold over named fields; until it is, this witness is the residue mechanism and it is enrolled rather than inert. A field ADDED to Job without being added here and to job_yaml is the gap this cannot close: it fails open on additions, which is why the note on the emitter side carries the field roster explicitly." +// THE CONSTRUCTION-LEVEL WALL AGAINST FUTURE INERT Job FIELDS, and the reason it is one synthetic +// all-fields job rather than a per-field assertion against ci.yml. job_yaml silently dropped four +// of the Job type's emittable fields (see job_field_projection_completeness_note); a per-field +// check against the real workflows could not have caught any of them, because every Job in the +// corpus sets those fields to none — so the real artifacts are indistinguishable from an emitter +// that ignores the fields entirely. The only discriminating subject is a job that POPULATES every +// optional field, which is why one is constructed here. Two directions are asserted and both are +// load-bearing: all_fields_job proves each populated fact reaches the emitted yaml (a new dropped +// field reds), and minimal_job proves an absent field emits NO key (a projection that started +// emitting an empty `outputs: {}` or a bare `name:` also reds). Without the second direction the +// first is satisfiable by unconditionally emitting every key. This is validation, not construction +// — DESIGN §5's preference is a model from which the projection is derived so a dropped field is +// unwritable, and that is not reachable while job_yaml is a hand-written fold over named fields; +// until it is, this witness is the residue mechanism and it is enrolled rather than inert. A field +// ADDED to Job without being added here and to job_yaml is the gap this cannot close: it fails open +// on additions, which is why the note on the emitter side carries the field roster explicitly. fn probe_step() -> Step { RunStep { @@ -106,7 +121,15 @@ test fn every_populated_job_field_reaches_the_emitted_yaml() -> Bool { && string_contains(s: y, pattern: "continue-on-error: true") } -data absent_field_adjacency_note: String = "Asserted as ADJACENCY rather than as per-key absence, because a bare !contains(\"name:\") is unsound here: the probe STEP carries `name: probe`, so a key-name absence check over the whole document conflates job-level keys with step-level ones and reds on a correct emitter (observed — this witness failed that way first). Adjacency is also the stronger claim: runs-on is the first key when name is absent and steps is the first key after the optional block, so requiring them CONTIGUOUS proves that none of name/needs/timeout-minutes/if/permissions/concurrency/outputs emitted anything at all — one assertion covering the whole optional block, and it breaks if any single one starts emitting an empty key. The trailing keys (env, continue-on-error) sit after steps and are checked separately at top-level indent." +// Asserted as ADJACENCY rather than as per-key absence, because a bare !contains("name:") is +// unsound here: the probe STEP carries `name: probe`, so a key-name absence check over the whole +// document conflates job-level keys with step-level ones and reds on a correct emitter (observed — +// this witness failed that way first). Adjacency is also the stronger claim: runs-on is the first +// key when name is absent and steps is the first key after the optional block, so requiring them +// CONTIGUOUS proves that none of name/needs/timeout-minutes/if/permissions/concurrency/outputs +// emitted anything at all — one assertion covering the whole optional block, and it breaks if any +// single one starts emitting an empty key. The trailing keys (env, continue-on-error) sit after +// steps and are checked separately at top-level indent. test fn absent_job_fields_emit_no_key() -> Bool { let y = minimal_yaml() diff --git a/dag/test/claim/gigabyte_mp72_board_profile_witness_test.dag b/dag/test/claim/gigabyte_mp72_board_profile_witness_test.dag index 598d74b1e57..21a7a7901a8 100644 --- a/dag/test/claim/gigabyte_mp72_board_profile_witness_test.dag +++ b/dag/test/claim/gigabyte_mp72_board_profile_witness_test.dag @@ -13,9 +13,22 @@ import extdeps.boards.gigabyte { board_profile_max_socket_power, } -data mp72_witness_note: String = "Three witnesses over a CANDIDATE board row that no fleet asset cites. They exist to keep a reading honest, not to admit hardware: the profile must agree with the vendor page on the fields the physical design actually consumes, the procurement standing must not silently advance past what a stock photograph can establish, and the architectural claim that motivated the candidate must be the true claim rather than the flattering one." +// Three witnesses over a CANDIDATE board row that no fleet asset cites. They exist to keep a +// reading honest, not to admit hardware: the profile must agree with the vendor page on the fields +// the physical design actually consumes, the procurement standing must not silently advance past +// what a stock photograph can establish, and the architectural claim that motivated the candidate +// must be the true claim rather than the flattering one. -data header_witness_retraction_note: String = "RETRACTED AND REPLACED 2026-08-11. The previous witness asserted that the two boards have an IDENTICAL power-header inventory - one 24-pin and two 8-pin EPS each - and used that equality as the headline reason a dual-socket board would drop into the existing tile harness. It was green, and it was false: the ALTRAD8UD has no 24-pin socket at all. It carries three 8-pin ATX12V inputs plus a 4-pin Micro-Fit signal connector, and an ATX supply reaches it through a bundled 24-pin-to-4-pin converter. The error originated in this session, was carried as a SEED DEBT marked pending pin-verification, and then had a witness built on it before the verification happened - a witness cannot launder an unverified reading into a fact, and this one did. The replacement asserts the DIFFERENCE, which is the true and more useful statement: both boards can be fed by an ATX supply, but their board-side interfaces and connection rituals are not the same." +// RETRACTED AND REPLACED 2026-08-11. The previous witness asserted that the two boards have an +// IDENTICAL power-header inventory - one 24-pin and two 8-pin EPS each - and used that equality as +// the headline reason a dual-socket board would drop into the existing tile harness. It was green, +// and it was false: the ALTRAD8UD has no 24-pin socket at all. It carries three 8-pin ATX12V inputs +// plus a 4-pin Micro-Fit signal connector, and an ATX supply reaches it through a bundled +// 24-pin-to-4-pin converter. The error originated in this session, was carried as a SEED DEBT +// marked pending pin-verification, and then had a witness built on it before the verification +// happened - a witness cannot launder an unverified reading into a fact, and this one did. The +// replacement asserts the DIFFERENCE, which is the true and more useful statement: both boards can +// be fed by an ATX supply, but their board-side interfaces and connection rituals are not the same. test fn witness_board_power_interfaces_differ() -> Bool { asrock_altrad8ud_1l2t_physical_profile.atx_24pin_count == 0 @@ -28,7 +41,10 @@ test fn witness_board_power_interfaces_differ() -> Bool { ) } -data required_population_witness_note: String = "How many of the three 8-pin inputs must be populated is UNRESOLVED, and the model must keep saying so. A cable diagram that draws a specific number of connected inputs before a vendor statement or fixture measurement closes this would repeat the exact mistake above: a plausible number rendered as a fact." +// How many of the three 8-pin inputs must be populated is UNRESOLVED, and the model must keep +// saying so. A cable diagram that draws a specific number of connected inputs before a vendor +// statement or fixture measurement closes this would repeat the exact mistake above: a plausible +// number rendered as a fact. test fn witness_required_input_population_stays_unresolved() -> Bool { match asrock_altrad8ud_required_input_population { @@ -37,7 +53,9 @@ test fn witness_required_input_population_stays_unresolved() -> Bool { } } -data standing_witness_note: String = "A stock photograph cannot advance procurement standing. This holds the row at ListingObserved and requires the gate to be non-empty, so a later edit cannot quietly promote the board to UnitReceiptHeld without the receipts that word implies." +// A stock photograph cannot advance procurement standing. This holds the row at ListingObserved and +// requires the gate to be non-empty, so a later edit cannot quietly promote the board to +// UnitReceiptHeld without the receipts that word implies. test fn witness_candidate_board_standing_is_listing_only() -> Bool { match gigabyte_mp72_hb0_procurement_standing { @@ -48,7 +66,12 @@ test fn witness_candidate_board_standing_is_listing_only() -> Bool { && count(gigabyte_mp72_hb0_purchase_gate) >= 8 } -data density_witness_note: String = "The architectural claim, stated as the TRUE one rather than the flattering one. Two dual-socket boards carry the same socket count as four single-socket boards in materially less area, and the E-ATX board doubles the power a single carrier must deliver. Both are checked, because the seductive framing - half as many tiles is automatically better - hides that each tile becomes a heavier, hotter, larger failure domain. Area falls by roughly 23 percent for equal sockets; it does not halve." +// The architectural claim, stated as the TRUE one rather than the flattering one. Two dual-socket +// boards carry the same socket count as four single-socket boards in materially less area, and the +// E-ATX board doubles the power a single carrier must deliver. Both are checked, because the +// seductive framing - half as many tiles is automatically better - hides that each tile becomes a +// heavier, hotter, larger failure domain. Area falls by roughly 23 percent for equal sockets; it +// does not halve. test fn witness_dual_socket_density_claim_is_the_true_one() -> Bool { let dual_area = square_millimeter_count(m: board_profile_area(p: gigabyte_mp72_hb0_physical_profile)) * 3 diff --git a/dag/test/claim/git_ls_remote_witness_test.dag b/dag/test/claim/git_ls_remote_witness_test.dag index bd35f456068..c7c76d84225 100644 --- a/dag/test/claim/git_ls_remote_witness_test.dag +++ b/dag/test/claim/git_ls_remote_witness_test.dag @@ -61,7 +61,12 @@ test fn an_empty_advertisement_is_zero_rows_not_a_refusal() -> Bool { scanned_count(scan: scan_advertised_refs(lines: [])) == 0 } -data refuse_not_skip_note: String = "The discriminating claim. A scan that DROPPED the unreadable line would still answer AdvertisedRefsRead with the two good rows, and every count-based assertion above would stay green while the answer silently became a partial advertisement. That is the absorbing fallback: the consumer cannot distinguish a complete listing from a truncated one, so a branch that IS published reads as absent. The refusal carries the offending line and its index so the deficit is located rather than merely counted." +// The discriminating claim. A scan that DROPPED the unreadable line would still answer +// AdvertisedRefsRead with the two good rows, and every count-based assertion above would stay green +// while the answer silently became a partial advertisement. That is the absorbing fallback: the +// consumer cannot distinguish a complete listing from a truncated one, so a branch that IS +// published reads as absent. The refusal carries the offending line and its index so the deficit is +// located rather than merely counted. test fn an_unreadable_line_refuses_rather_than_being_skipped() -> Bool { let scan = scan_advertised_refs(lines: [ diff --git a/dag/test/claim/git_plumbing_ref_mutation_witness_test.dag b/dag/test/claim/git_plumbing_ref_mutation_witness_test.dag index af934561154..8e5e6c69ac1 100644 --- a/dag/test/claim/git_plumbing_ref_mutation_witness_test.dag +++ b/dag/test/claim/git_plumbing_ref_mutation_witness_test.dag @@ -106,7 +106,11 @@ test fn a_create_that_succeeded_and_reads_back_is_applied() -> Bool { } } -data zero_exit_is_not_a_receipt_note: String = "THE DISCRIMINATING CLAIM FOR THE APPLIED ARM. A decision that read only the exit code would answer Applied here too, because the process ended zero - and the ref holds something else. That is the fabricated plausible output at its shortest: the caller is told the store holds a commit it does not hold. The read-back is what makes Applied a receipt rather than a restatement of the exit status, and this arm is the input on which the two disagree." +// THE DISCRIMINATING CLAIM FOR THE APPLIED ARM. A decision that read only the exit code would +// answer Applied here too, because the process ended zero - and the ref holds something else. That +// is the fabricated plausible output at its shortest: the caller is told the store holds a commit +// it does not hold. The read-back is what makes Applied a receipt rather than a restatement of the +// exit status, and this arm is the input on which the two disagree. test fn a_zero_exit_whose_ref_holds_something_else_is_a_read_back_mismatch() -> Bool { match oid_a() { @@ -190,7 +194,11 @@ test fn a_stale_advance_is_a_precondition_failure_and_an_exact_one_applies() -> } } -data delete_desires_absence_note: String = "A DELETE'S DESIRED STATE IS ABSENCE, WHICH IS THE ONE ARM AN OBSERVED-OID COMPARISON CANNOT EXPRESS. The three arms of GitRefObservation exist so that absence is a value rather than a missing one; if a read-back returned an optional oid, `no oid` would have to stand for both `the ref is gone` and `the read said nothing`, and a delete would then be confirmed by the failure to observe it." +// A DELETE'S DESIRED STATE IS ABSENCE, WHICH IS THE ONE ARM AN OBSERVED-OID COMPARISON CANNOT +// EXPRESS. The three arms of GitRefObservation exist so that absence is a value rather than a +// missing one; if a read-back returned an optional oid, `no oid` would have to stand for both `the +// ref is gone` and `the read said nothing`, and a delete would then be confirmed by the failure to +// observe it. test fn an_exact_delete_that_left_the_ref_absent_is_applied() -> Bool { match oid_a() { @@ -226,7 +234,12 @@ test fn a_stale_delete_whose_ref_moved_is_a_precondition_failure() -> Bool { } } -data unreadable_is_not_unapplied_note: String = "AN UNREADABLE STORE IS NOT AN ANSWER ABOUT THE REF. If the read-back itself refused, this decision knows nothing about what happened - not that the mutation failed, and not that it succeeded - so it says so rather than folding the ignorance into either verdict. Folding it into ExecutionRefused would report a mutation as not applied when it may well have been, which is the state-space conflation an absorbing fallback commits on the answer lattice. It holds on BOTH exit codes, which is why both are claimed here." +// AN UNREADABLE STORE IS NOT AN ANSWER ABOUT THE REF. If the read-back itself refused, this +// decision knows nothing about what happened - not that the mutation failed, and not that it +// succeeded - so it says so rather than folding the ignorance into either verdict. Folding it into +// ExecutionRefused would report a mutation as not applied when it may well have been, which is the +// state-space conflation an absorbing fallback commits on the answer lattice. It holds on BOTH exit +// codes, which is why both are claimed here. test fn an_unreadable_read_back_refuses_on_either_exit_code() -> Bool { match oid_a() { @@ -274,7 +287,10 @@ test fn only_the_applied_arm_reports_applied() -> Bool { } } -data address_is_one_axis_note: String = "THE TWO REPOSITORY READINGS ARE NOT INTERCHANGEABLE, which is why they are a parameter and not a default. `-C ` changes directory and discovers a repository from there; `--git-dir=` names the store directly and is the only one that reaches a bare repository with no worktree. An operation family that hardcoded either would be unusable on one side of devboot's exchange." +// THE TWO REPOSITORY READINGS ARE NOT INTERCHANGEABLE, which is why they are a parameter and not a +// default. `-C ` changes directory and discovers a repository from there; `--git-dir=` +// names the store directly and is the only one that reaches a bare repository with no worktree. An +// operation family that hardcoded either would be unusable on one side of devboot's exchange. test fn each_repository_reading_produces_its_own_spelling() -> Bool { git_repository_address_argv(address: GitWorktreeAt { path: "/repo" }) @@ -288,7 +304,9 @@ test fn the_index_override_is_an_environment_prefix_not_a_flag() -> Bool { == ["env", "GIT_INDEX_FILE=/work/scratch.index"] } -data parentless_is_not_an_empty_list_note: String = "A PARENTLESS COMMIT IS A ROOT ON PURPOSE. devboot builds them so a client can clone one commit shallowly, so `no parents` is an intended shape rather than a caller who had none to give - and the argv it produces carries no `-p` at all, which is the observable difference." +// A PARENTLESS COMMIT IS A ROOT ON PURPOSE. devboot builds them so a client can clone one commit +// shallowly, so `no parents` is an intended shape rather than a caller who had none to give - and +// the argv it produces carries no `-p` at all, which is the observable difference. test fn commit_parents_spell_one_dash_p_per_parent_and_none_for_a_root() -> Bool { git_commit_parents_argv(parents: GitNoParents) == [] diff --git a/dag/test/claim/git_ref_set_decoder_witness_test.dag b/dag/test/claim/git_ref_set_decoder_witness_test.dag index aaa68b241ce..2104cd85826 100644 --- a/dag/test/claim/git_ref_set_decoder_witness_test.dag +++ b/dag/test/claim/git_ref_set_decoder_witness_test.dag @@ -13,7 +13,14 @@ import extdeps.git.enumeration { data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data git_ref_set_decoder_construction_justification: String = "Pure decoder controls over authored wire text. These run in the ordinary floor because the subject is the DECODE, which is a total function of bytes the test supplies -- no repository, no subprocess, no host. What they deliberately do NOT establish is that git.Core.ForEachRefIn EMITS these bytes for any given repository state; that is a transport claim, it cannot execute inside the hermetic fold (a shell operation is refused at shell.Test.IsExecutable before the subprocess is reached, and mocking the result would fabricate the very observation the claim is about), and it is owned by a separate wet record/replay matrix. Reporting these controls as coverage for the transport would be exactly the rung inflation DESIGN section 4b forbids." +// Pure decoder controls over authored wire text. These run in the ordinary floor because the +// subject is the DECODE, which is a total function of bytes the test supplies -- no repository, no +// subprocess, no host. What they deliberately do NOT establish is that git.Core.ForEachRefIn EMITS +// these bytes for any given repository state; that is a transport claim, it cannot execute inside +// the hermetic fold (a shell operation is refused at shell.Test.IsExecutable before the subprocess +// is reached, and mocking the result would fabricate the very observation the claim is about), and +// it is owned by a separate wet record/replay matrix. Reporting these controls as coverage for the +// transport would be exactly the rung inflation DESIGN section 4b forbids. data a_oid: String = "1111111111111111111111111111111111111111" data b_oid: String = "2222222222222222222222222222222222222222" diff --git a/dag/test/claim/git_upstream_model_witness_test.dag b/dag/test/claim/git_upstream_model_witness_test.dag index 4276e282718..39e542d7afc 100644 --- a/dag/test/claim/git_upstream_model_witness_test.dag +++ b/dag/test/claim/git_upstream_model_witness_test.dag @@ -132,7 +132,9 @@ import std.types { Bytes } import std.bytes { bytes_octets, octets_bytes, utf8_encode_bytes } import std.algebra { Cons, Empty } -data git_upstream_witness_lit_note: String = "Witness-corpus Git object ids are constructed only through git_sha1_object_id / git_sha256_object_id (review 45376). The Absent arm below is unreachable for pinned corpus literals; it exists only because data initializers require a total GitObjectId." +// Witness-corpus Git object ids are constructed only through git_sha1_object_id / +// git_sha256_object_id (review 45376). The Absent arm below is unreachable for pinned corpus +// literals; it exists only because data initializers require a total GitObjectId. fn witness_lit_git_sha1(hex: String) -> GitObjectId { match git_sha1_object_id(hex: hex) { diff --git a/dag/test/claim/git_worktree_set_decoder_witness_test.dag b/dag/test/claim/git_worktree_set_decoder_witness_test.dag index b9fddde867a..4c110220cb6 100644 --- a/dag/test/claim/git_worktree_set_decoder_witness_test.dag +++ b/dag/test/claim/git_worktree_set_decoder_witness_test.dag @@ -17,7 +17,15 @@ import extdeps.git.worktree_enumeration { data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data git_worktree_set_decoder_construction_justification: String = "Pure decoder controls over authored wire text, run in the ordinary floor because the subject is the DECODE -- a total function of bytes the test supplies, with no repository, no subprocess and no host. The authored strings are TRANSCRIBED FROM REAL `git worktree list --porcelain -z` OUTPUT observed on a constructed repository (a primary on a branch, a linked worktree on a branch, a detached worktree, a locked worktree, and a bare clone), so the framing under test is git's and not an invention. What these deliberately do NOT establish is that git.Core.WorktreeListIn EMITS these bytes for any given repository state: that is a transport claim, it cannot execute inside the hermetic fold, and it is owned by the separate wet record/replay matrix. Reporting these as coverage for the transport would be the rung inflation DESIGN section 4b forbids." +// Pure decoder controls over authored wire text, run in the ordinary floor because the subject is +// the DECODE -- a total function of bytes the test supplies, with no repository, no subprocess and +// no host. The authored strings are TRANSCRIBED FROM REAL `git worktree list --porcelain -z` OUTPUT +// observed on a constructed repository (a primary on a branch, a linked worktree on a branch, a +// detached worktree, a locked worktree, and a bare clone), so the framing under test is git's and +// not an invention. What these deliberately do NOT establish is that git.Core.WorktreeListIn EMITS +// these bytes for any given repository state: that is a transport claim, it cannot execute inside +// the hermetic fold, and it is owned by the separate wet record/replay matrix. Reporting these as +// coverage for the transport would be the rung inflation DESIGN section 4b forbids. data oid_a: String = "b0940967fc5128891bb289985b3e2a0714a88773" data oid_b: String = "1111111111111111111111111111111111111111" diff --git a/dag/test/claim/githooks_pre_push_emit_test.dag b/dag/test/claim/githooks_pre_push_emit_test.dag index 865d8453eb6..fe882ff23bd 100644 --- a/dag/test/claim/githooks_pre_push_emit_test.dag +++ b/dag/test/claim/githooks_pre_push_emit_test.dag @@ -44,13 +44,17 @@ test fn witness_no_corpus_or_witness_run() -> Bool { && !has(s: sh, p: "run_generated_artifact_drift_gate_body") } -test fn witness_no_tree_mutation() -> Bool { - let sh = expected_githooks_pre_push_sh() - !has(s: sh, p: "chore: apply cargo fmt") - && !has(s: sh, p: "chore: regenerate committed projections") - && !has(s: sh, p: "git add") - && !has(s: sh, p: "git commit") -} +// The budget exists to catch RE-HEAVYING — a roster edit that puts a corpus run, an in-hook cargo +// build, or a claim_batch exec back on the push path (gunbc.githooks_pre_push_emit +// pre_push_fmt_only_note). It is a proxy for that property, and the four witnesses above assert the +// property directly, which is why raising the ceiling here does not weaken the gate. It moved 700 +// -> 1000 when the fmt failure arm was split three ways: the could-not-run branch carries a +// ~230-character diagnostic that names cargo and proposes no cargo-dependent remedy, which is the +// whole point of the split and is not weight on the push path (it is a message, not work). It moved +// 1000 -> 1500 when lane-2 added idempotent repo-local git config convergence on the push path +// (~350 characters of gunbc run argv and failure text — still no cargo build or claim_batch exec; +// the structural witnesses remain authoritative). A hook that re-acquires actual work still trips +// the structural witnesses regardless of this number. // witness_line_budget (length(sh) < N) DELETED 2026-08-09: it was a tree-measured // numeric oracle — a merge-blocking literal grounded in a measurement of the current @@ -61,6 +65,10 @@ test fn witness_no_tree_mutation() -> Bool { // witness_no_in_hook_build, witness_no_corpus_or_witness_run, // witness_no_claim_batch_dependency, and witness_no_tree_mutation — none of which is a // tree-measured literal. A byte count added nothing those do not already bound (DESIGN §2). -data pre_push_line_budget_note: String = "The budget exists to catch RE-HEAVYING — a roster edit that puts a corpus run, an in-hook cargo build, or a claim_batch exec back on the push path (gunbc.githooks_pre_push_emit pre_push_fmt_only_note). It is a proxy for that property, and the four witnesses above assert the property directly, which is why raising the ceiling here does not weaken the gate. It moved 700 -> 1000 when the fmt failure arm was split three ways: the could-not-run branch carries a ~230-character diagnostic that names cargo and proposes no cargo-dependent remedy, which is the whole point of the split and is not weight on the push path (it is a message, not work). It moved 1000 -> 1500 when lane-2 added idempotent repo-local git config convergence on the push path (~350 characters of gunbc run argv and failure text — still no cargo build or claim_batch exec; the structural witnesses remain authoritative). A hook that re-acquires actual work still trips the structural witnesses regardless of this number." - - +test fn witness_no_tree_mutation() -> Bool { + let sh = expected_githooks_pre_push_sh() + !has(s: sh, p: "chore: apply cargo fmt") + && !has(s: sh, p: "chore: regenerate committed projections") + && !has(s: sh, p: "git add") + && !has(s: sh, p: "git commit") +} diff --git a/dag/test/claim/githooks_repo_local_git_config_emit_witness_test.dag b/dag/test/claim/githooks_repo_local_git_config_emit_witness_test.dag index 3288b927778..b4e2ef6a951 100644 --- a/dag/test/claim/githooks_repo_local_git_config_emit_witness_test.dag +++ b/dag/test/claim/githooks_repo_local_git_config_emit_witness_test.dag @@ -46,7 +46,13 @@ test fn witness_converge_shell_uses_reconcile_install_command() -> Bool { && string_contains(s: shell, pattern: hooks_cmd) } -data converge_shell_quoting_witness_note: String = "THE DISCRIMINATING HALF. The witness above compares the emitted block against the same renderer it is built from, so it moves with any renderer and cannot by itself tell a quoted line from an unquoted one — a change detector, not a check (DESIGN section 5). This one asserts the property the value actually needs: the driver key is followed by its value as ONE shell word. Under the unquoted join this emitter used until the driver value became multi-word, the text after the key is a bare `bash .githooks/generated-artifact-merge %O %A %B %P`, so this claim goes red exactly on the defect it exists to catch." +// THE DISCRIMINATING HALF. The witness above compares the emitted block against the renderer it is +// built from, so it moves with any renderer and cannot tell a quoted line from an unquoted one — a +// change detector, not a check (DESIGN section 5). This one asserts the property the value needs: +// the driver key is followed by its value as ONE shell word. Under the unquoted join this emitter +// used until the driver value became multi-word, the text after the key is a bare +// `bash .githooks/generated-artifact-merge %O %A %B %P`, so this claim goes red exactly on the +// defect it exists to catch. test fn witness_converge_shell_quotes_multiword_binding_value_as_one_word() -> Bool { let shell = emit_repo_local_git_config_converge_shell() diff --git a/dag/test/claim/guarantee_floor_class_probe_witness_test.dag b/dag/test/claim/guarantee_floor_class_probe_witness_test.dag index b266c263b41..32bcafaf51c 100644 --- a/dag/test/claim/guarantee_floor_class_probe_witness_test.dag +++ b/dag/test/claim/guarantee_floor_class_probe_witness_test.dag @@ -52,13 +52,40 @@ import v2.std.optional { Present, Absent } data live_tree_disposition: LiveTreeDisposition = ReadsLiveTree -data guarantee_floor_class_probe_execution_status_note: String = "READ THIS BEFORE THE SCOPE NOTE BELOW. THIS FILE DOES NOT RUN IN CI. It declares ReadsLiveTree -- truthfully, because compile_dag_diagnostic_census resolves its synthetic sources against the live checkout -- and the required floor DECLINES every ReadsLiveTree module before the fold sees it (v2.workflow.required_floor DeclinedLiveTree). So every probe here is AUTHORED evidence, green under a local gunbc run --claim-run on 2026-08-22 and executing nowhere else. That is strictly weaker than enrolment and the six gap-analysis rows it serves say so in line. The distinction is not pedantry in this file of all files: a witness that cannot execute is exactly the defect these probes exist to count, and it applies to them first. DISSOLVES with the DeclinedLiveTree arm deletion (gap analysis section 11 item 28), at which point these become executing evidence with no further authorship. Do NOT dissolve it by relabelling this file SubstrateInputsOnly." +// READ THIS BEFORE THE SCOPE NOTE BELOW. THIS FILE DOES NOT RUN IN CI. It declares ReadsLiveTree — +// truthfully, since compile_dag_diagnostic_census resolves its synthetic sources against the live +// checkout — and the required floor DECLINES every ReadsLiveTree module before the fold sees it +// (v2.workflow.required_floor DeclinedLiveTree). So every probe here is AUTHORED evidence, green +// under a local gunbc run --claim-run on 2026-08-22 and executing nowhere else — strictly weaker +// than enrolment, and the six gap-analysis rows it serves say so in line. In this file of all files +// the distinction matters: a witness that cannot execute is exactly the defect these probes count, +// and it applies to them first. DISSOLVES with the DeclinedLiveTree arm deletion (gap analysis +// section 11 item 28), at which point these become executing evidence with no further authorship. +// Do NOT dissolve it by relabelling this file SubstrateInputsOnly. data guarantee_floor_class_probe_scope_note: String = "WHAT THIS FILE IS. Five floor classes in docs/plans/compiler-guarantee-recovery-gap-analysis.md carried rungs established by a ONE-OFF hand execution of compile_dag_diagnostic_census on 2026-08-01 (four of them said NOT ENROLLED in their own Evidence cell; the parse-separator row cited a session's throwaway probe). A SIXTH class was authored here and REMOVED before merge: the v2.-module direct-call argument-type exemption, which gunbc#8902 landed on main as direct_call_argument_type_class while this change was in flight. One concept, one authority (DESIGN 3) — that seam is theirs, this file carries no second name for it, and the gap-analysis row for it cites their rows. Nothing re-ran any of them, so each rung was honest about the day it was measured and silent about today -- the shape DESIGN 4b meta-obligation 4 forbids. This file is the enrolment: every one of those measurements now executes on every required-floor run, and every one of them reds if the compiler's behaviour changes in either direction. FOUR OF THE FIVE ARE BELOW-FLOOR HOLES AND THEIR PROBES ARE GREEN BY DESIGN. Do not read those greens as guarantees: they pin a DEFECT (ExpectSilentAcceptanceHole, whose note explains why it is a separate variant from ExpectZeroDiagnostics) and they flip RED on the day the wall lands, which is the signal to rewrite the row as ExpectBlockingRefusal rather than to delete the probe. PROBE ADEQUACY, per the operator-adopted 2026-08-01 mandate that every below-floor row carry closure AND shape evidence: each hole ships beside a control that DOES refuse on this same harness and this same run -- the monomorphic record for generic instantiation, the declared-record field access for field-through-generics, the doubled separator for the omitted one, so a zero on the hole is the compiler's silence and never the harness failing to reach the judgment. The exhaustiveness hole's adequacy control is not re-authored here: the coproduct-scrutinee arm is already enrolled and executing at test.claim.match_exhaustiveness_coproduct_witness w_missing_coproduct_arm_reports_one_non_exhaustive, on this same harness, and duplicating it would be a second authority for one fact." -data guarantee_floor_class_probe_instrument_note: String = "THE INSTRUMENT THAT PRODUCED EVERY NUMBER BELOW IS A LOCALLY BUILT gunbc, AND ITS VINTAGE WAS TESTED RATHER THAN ASSUMED. Because this file is declined by the floor (see the execution-status note above), CI never re-runs these probes, so a single local binary is the ONLY execution evidence they have -- which makes that binary a variable, not a given. CROSS-CHECK, 2026-08-22: two independently built binaries roughly fifteen hours apart were run over the same four probes -- both silent holes and both refusing controls -- and returned identical verdicts, PASS on all eight. The pairs stay DISCRIMINATING in both, which is the part that matters: a binary that refused everything or refused nothing would show up as a control flipping, and neither did. So the verdicts here are not an artifact of one build. What this does NOT establish is that any binary in this family agrees with the seed CI would use, because CI does not execute this file at all; that question dissolves with the DeclinedLiveTree arm and not before." - -data guarantee_floor_class_probe_measurement_note: String = "MEASURED 2026-08-22 on this harness, full dag + src/v2 pool, before these probes were authored -- the numbers the rows below encode. generic-instantiation hole 0 rows; monomorphic control 1 blocking TypeMismatch; generic green 0. field-through-generics hole 0 rows; declared-record control 1 blocking InternalError; green 0. exhaustiveness type-variable hole 0 rows. record completeness red 1 blocking MissingField; green 0. parse list separator hole 0 rows; doubled-separator control 1 blocking ParseError; green 0. THE InternalError ROW IS PINNED AS OBSERVED, NOT AS ENDORSED: a field access naming no declared field refuses, which is the property the control exists to establish, but it refuses under a class name that says nothing about what went wrong. That is its own diagnostic-quality defect and it is recorded here rather than laundered into a nicer-sounding assertion; improving the class is a change that reds this probe, which is the correct place for the conversation to happen." +// THE INSTRUMENT THAT PRODUCED EVERY NUMBER BELOW IS A LOCALLY BUILT gunbc, AND ITS VINTAGE WAS +// TESTED RATHER THAN ASSUMED. Because the floor declines this file (see above), CI never re-runs +// these probes; a single local binary is their ONLY execution evidence, so that binary is a +// variable, not a given. CROSS-CHECK, 2026-08-22: two independently built binaries roughly fifteen +// hours apart ran the same four probes — both silent holes and both refusing controls — and +// returned identical verdicts, PASS on all eight. The pairs stay DISCRIMINATING in both, which is +// what matters: a binary refusing everything or nothing would show as a control flipping, and +// neither did. So the verdicts are not an artifact of one build. NOT established: that any binary +// in this family agrees with the seed CI would use, because CI does not execute this file; that +// question dissolves with the DeclinedLiveTree arm and not before. + +// MEASURED 2026-08-22 on this harness, full dag + src/v2 pool, before these probes were authored — +// the numbers the rows below encode. generic-instantiation hole 0 rows; monomorphic control 1 +// blocking TypeMismatch; generic green 0. field-through-generics hole 0 rows; declared-record +// control 1 blocking InternalError; green 0. exhaustiveness type-variable hole 0 rows. record +// completeness red 1 blocking MissingField; green 0. parse list separator hole 0 rows; +// doubled-separator control 1 blocking ParseError; green 0. THE InternalError ROW IS PINNED AS +// OBSERVED, NOT AS ENDORSED: a field access naming no declared field refuses, the property the +// control exists to establish, but under a class name that says nothing about what went wrong. That +// is its own diagnostic-quality defect, recorded here rather than laundered into a nicer-sounding +// assertion; improving the class reds this probe, the correct place for the conversation. fn census_of(source: String) -> CompileDiagnosticCensus { compile_dag_diagnostic_census(source) @@ -145,7 +172,6 @@ data parse_list_separator_hole_source: String = "module probe_floor_list_sep\nty data parse_list_separator_double_source: String = "module probe_floor_list_sep_double\ntype Cell { n: Int }\nfn f() -> List { [ Cell { n: 1 }, , Cell { n: 3 } ] }\n" data parse_list_separator_green_source: String = "module probe_floor_list_sep_green\ntype Cell { n: Int }\nfn f() -> List { [ Cell { n: 1 }, Cell { n: 2 }, Cell { n: 3 } ] }\n" - test fn floor_generic_instantiation_is_still_silently_accepted() -> Bool { silent_hole_holds(probe: floor_generic_instantiation_hole_probe, source: generic_instantiation_hole_source) } diff --git a/dag/test/claim/guarantee_measurement_witness_test.dag b/dag/test/claim/guarantee_measurement_witness_test.dag index a012cf3f872..add1013d311 100644 --- a/dag/test/claim/guarantee_measurement_witness_test.dag +++ b/dag/test/claim/guarantee_measurement_witness_test.dag @@ -20,7 +20,15 @@ import gunbc.guarantee_measurement { probe_set_digest, } -data guarantee_measurement_witness_scope_note: String = "SYNTHETIC ROWS ONLY, by the Stage 0 charter: these witnesses prove the protocol - construction, exactly-one resolution, the refusing joins, digest determinism, and the verdict/ignorance separation - against rows invented here. No probe executes, no real class population exists yet, and nothing below says anything about the compiler. When ladder-probe-corpus lands real rows, its receipts execute through THIS vocabulary and these synthetic witnesses stay as the protocol's regression controls. The unwritability half of the node's red_control (a receipt missing an identity component) is construction-by-required-fields: it cannot be witnessed from inside a compiling program, and its corpus-wide enforcement measurement belongs to the record-construction census class, stated in the module's receipt_identity_note rather than faked here." +// SYNTHETIC ROWS ONLY, by the Stage 0 charter: these witnesses prove the protocol - construction, +// exactly-one resolution, the refusing joins, digest determinism, and the verdict/ignorance +// separation - against rows invented here. No probe executes, no real class population exists yet, +// and nothing below says anything about the compiler. When ladder-probe-corpus lands real rows, its +// receipts execute through THIS vocabulary and these synthetic witnesses stay as the protocol's +// regression controls. The unwritability half of the node's red_control (a receipt missing an +// identity component) is construction-by-required-fields: it cannot be witnessed from inside a +// compiling program, and its corpus-wide enforcement measurement belongs to the record-construction +// census class, stated in the module's receipt_identity_note rather than faked here. fn synth_path(id: String) -> GuaranteePath { GuaranteePath { diff --git a/dag/test/claim/guarantee_probe_corpus_witness_test.dag b/dag/test/claim/guarantee_probe_corpus_witness_test.dag index 2762460cddb..483a28622ea 100644 --- a/dag/test/claim/guarantee_probe_corpus_witness_test.dag +++ b/dag/test/claim/guarantee_probe_corpus_witness_test.dag @@ -98,9 +98,29 @@ import v2.std.optional { Present, Absent } data live_tree_disposition: LiveTreeDisposition = ReadsLiveTree -data guarantee_probe_corpus_witness_execution_status_note: String = "THIS FILE IS DISCOVERED BY THE REQUIRED FLOOR AND NEVER EXECUTED (measured 2026-08-22; gap analysis section 11 item 28, and gunbc.guarantee_probe_corpus guarantee_probe_corpus_execution_status_note carries the population and the specimen). Its ReadsLiveTree declaration is HONEST and must not be retyped to make it run; the floor's DeclinedLiveTree arm is the stale half, and its deletion is the dissolution trigger. Until then these 50 identities are AUTHORED evidence, not EXECUTING evidence, and the six classes above are cited that way wherever a rung reads from them: bare-none field admission, call label and surplus, method established surface, declared-conformance ground fragment, sole-constructor cross-module, v2 self-grounding frontier." - -data guarantee_probe_corpus_witness_scope_note: String = "SLICE 1 MIGRATION RECEIPT: the landed wall controls from the THREE MERGED PRs gunbc#7519 (call-label-and-surplus), gunbc#7484 (method-established-surface + declared-conformance-ground-fragment), and gunbc#7485 (InferToEval self-grounding frontier) execute through gunbc.guarantee_measurement identities. gunbc#7555 (InferToTranslate) is OPEN and introduces no identities in this slice — that lane lands its own registry rows when it merges. Each v1 probe compiles synthetic source via compile_dag_diagnostic_census, asserts the class-specific expectation through probe_observation_fold (never hand-matching ProbeObservation arms), and builds a GuaranteeMeasurementReceipt that joins its declared path. Mutation controls below prove the expectations discriminate — a green witness asserting the wrong contract would defend the defect (census_rows [] incident). The dark-suite originals in compiler_tests.rs remain until gap analysis sec 11 item 9 dispositiones them — this file is the durable enrolled copy keyed by identity, not a second test family. v2 InferToEval executing evidence joins the registry from src/v2/test/claim/infer_self_grounding_wall_test.dag." +// THIS FILE IS DISCOVERED BY THE REQUIRED FLOOR AND NEVER EXECUTED (measured 2026-08-22; gap +// analysis section 11 item 28; gunbc.guarantee_probe_corpus +// guarantee_probe_corpus_execution_status_note carries the population and the specimen). Its +// ReadsLiveTree declaration is HONEST and must not be retyped to make it run; the floor's +// DeclinedLiveTree arm is the stale half, and its deletion is the dissolution trigger. Until then +// these 50 identities are AUTHORED evidence, not EXECUTING evidence, and the six classes above are +// cited that way wherever a rung reads from them: bare-none field admission, call label and +// surplus, method established surface, declared-conformance ground fragment, sole-constructor +// cross-module, v2 self-grounding frontier. + +// SLICE 1 MIGRATION RECEIPT: the landed wall controls from the THREE MERGED PRs gunbc#7519 +// (call-label-and-surplus), gunbc#7484 (method-established-surface + +// declared-conformance-ground-fragment), and gunbc#7485 (InferToEval self-grounding frontier) +// execute through gunbc.guarantee_measurement identities. gunbc#7555 (InferToTranslate) is OPEN and +// introduces no identities in this slice — it lands its own registry rows when it merges. Each v1 +// probe compiles synthetic source via compile_dag_diagnostic_census, asserts the class-specific +// expectation through probe_observation_fold (never hand-matching ProbeObservation arms), and +// builds a GuaranteeMeasurementReceipt joining its declared path. Mutation controls below prove the +// expectations discriminate — a green witness asserting the wrong contract would defend the defect +// (census_rows [] incident). The dark-suite originals in compiler_tests.rs remain until gap +// analysis sec 11 item 9 dispositions them — this file is the durable enrolled copy keyed by +// identity, not a second test family. v2 InferToEval executing evidence joins the registry from +// src/v2/test/claim/infer_self_grounding_wall_test.dag. fn census_of(source: String) -> CompileDiagnosticCensus { compile_dag_diagnostic_census(source) @@ -150,9 +170,40 @@ data bare_none_green_source: String = "module probe_bare_none_green\ntype Diags data bare_none_generic_parameter_boundary_source: String = "module probe_bare_none_generic\ntype Maybe = None | Some { n: Int }\ntype Box { v: T }\nfn red_generic() -> Box { Box { v: None } }\nfn green_generic() -> Box { Box { v: None } }\n" -data bare_none_generic_parameter_boundary_note: String = "THIS TEST ASSERTS A MISS, DELIBERATELY, AND IT IS SUPPOSED TO FLIP. The wall decides admissibility from the DECLARED side, so it can only fire where the declared field type resolves at the construction site. Where the field is declared as a type PARAMETER, generic substitution has not happened at the node the check reads, so `Box \{ v: None }` — a bare `None` in a field that cannot carry absence — is ACCEPTED. That is a genuine miss, and this is its specimen. WHY IT IS ENROLLED RATHER THAN DESCRIBED: a boundary written only in prose is invisible to every gate — nothing reds if the miss widens, and nothing announces the day it closes. This witness does both. It goes RED if a future change makes the wall refuse the generic position, which is the moment the boundary DISSOLVES and this test must be inverted to an ordinary refusal assertion beside the other REDs. It is therefore a dissolution trigger with a mechanism, not a contract blessing the gap. WHY THE OBVIOUS FIX DOES NOT REACH IT, tested rather than reasoned: infer_record_lit_structural already prefers record_lit_instantiated_fields, but that helper requires `expected` Present with children, and a `data d: Box = ...` annotation does not flow through as `expected`, so the fallback yields the uninstantiated template fields. Swapping the wall's identity guard from authored-name-nonempty to type-shape-not-Primitive() was built and run: the generic site was STILL missed, which is the discriminating evidence that no substituted node arrives here at all. NEXT-RUNG TRIGGER, named as the mechanism rather than the symptom: the declaration annotation reaching the record-literal position as `expected`, which is what would let the existing instantiation helper answer." - -data bare_none_field_admission_scope_note: String = "THE CLASS: a bare `None` reference carries absence and nothing else, so a construction position whose declared field type cannot carry absence must refuse it. MEASURED ON THE PRE-WALL BINARY (the discriminating fact, not a prediction): bare_none_scalar_red_source and bare_none_collection_red_source both compiled with ZERO blocking diagnostics and emitted `n: Rc::new(Diags::None)` for `n: Int` — a Rust program the declared type refutes, produced silently, which is the below-floor class DESIGN 4b names (values inhabit declared types). THE GREEN CONTROL IS TWO-ARMED ON PURPOSE, because a wall that refuses every bare `None` would be indistinguishable from this one on the REDs alone: optional_field is the `T?` carrier and none_variant_field is a coproduct declaring its own `None` variant at its own level (the shape std.cache_interface AuthScope and v2.std.diagnostic Diagnostics both have, and the reason ~561 corpus sites are legitimate). some_variant_field holds the sibling arm green so the control cannot pass by the field type being unresolved. WHY A SYNTACTIC SLICE RATHER THAN THE GENERAL CONFORMANCE RULE: v1.compiler.infer conformance_unjudged_live_hole_note records five attempts at a general named-vs-named refusal, each of which red correct code because the produced side carries no separable type identity; a bare `None` needs none, since admissibility is decided entirely from the declared side." +// THIS TEST ASSERTS A MISS, DELIBERATELY, AND IT IS SUPPOSED TO FLIP. The wall decides +// admissibility from the DECLARED side, so it fires only where the declared field type resolves at +// the construction site. Where the field is a type PARAMETER, generic substitution has not happened +// at the node the check reads, so `Box { v: None }` — a bare `None` in a field that cannot +// carry absence — is ACCEPTED. A genuine miss; this is its specimen. WHY IT IS ENROLLED RATHER THAN +// DESCRIBED: a boundary written only in prose is invisible to every gate — nothing reds if the miss +// widens, nothing announces the day it closes. This goes RED if a future change makes the wall +// refuse the generic position — the moment the boundary DISSOLVES and this test must be inverted to +// an ordinary refusal assertion beside the other REDs: a dissolution trigger with a mechanism, not +// a contract blessing the gap. WHY THE OBVIOUS FIX DOES NOT REACH IT, tested: +// infer_record_lit_structural already prefers record_lit_instantiated_fields, but that helper +// requires `expected` Present with children, and a `data d: Box = ...` annotation does not +// flow through as `expected`, so the fallback yields the uninstantiated template fields. Swapping +// the wall's identity guard from authored-name-nonempty to type-shape-not-Primitive() was built and +// run: the generic site was STILL missed — discriminating evidence that no substituted node arrives +// here at all. NEXT-RUNG TRIGGER, named as mechanism not symptom: the declaration annotation +// reaching the record-literal position as `expected`, which would let the existing instantiation +// helper answer. + +// THE CLASS: a bare `None` reference carries absence and nothing else, so a construction position +// whose declared field type cannot carry absence must refuse it. MEASURED ON THE PRE-WALL BINARY +// (the discriminating fact, not a prediction): bare_none_scalar_red_source and +// bare_none_collection_red_source both compiled with ZERO blocking diagnostics and emitted `n: +// Rc::new(Diags::None)` for `n: Int` — a Rust program the declared type refutes, produced silently, +// the below-floor class DESIGN 4b names (values inhabit declared types). THE GREEN CONTROL IS +// TWO-ARMED ON PURPOSE: a wall refusing every bare `None` would be indistinguishable from this one +// on the REDs alone. optional_field is the `T?` carrier and none_variant_field is a coproduct +// declaring its own `None` variant at its own level (the shape std.cache_interface AuthScope and +// v2.std.diagnostic Diagnostics both have, and why ~561 corpus sites are legitimate). +// some_variant_field holds the sibling arm green so the control cannot pass by the field type being +// unresolved. WHY A SYNTACTIC SLICE RATHER THAN THE GENERAL CONFORMANCE RULE: v1.compiler.infer +// conformance_unjudged_live_hole_note records five attempts at a general named-vs-named refusal, +// each of which red correct code because the produced side carries no separable type identity; a +// bare `None` needs none, since admissibility is decided entirely from the declared side. data call_mislabel_source: String = "module probe_call_mislabel\nfn sub(a: Int, b: Int) -> Int { a - b }\nfn f() -> Int { sub(a: 10, bb: 3) }\n" @@ -176,9 +227,42 @@ data formal_selection_declaration_order_green_source: String = "module probe_for data formal_selection_named_then_positional_green_source: String = "module probe_formal_selection_named_then_positional\nfn f(a: Int, b: Int) -> Int { a }\nfn g() -> Int { f(b: 2, 1) }\n" -data formal_selection_mixed_call_note: String = "A NAMED ARGUMENT PRECEDING AN UNLABELLED ONE IS ACCEPTED, and this row exists because an earlier revision of the selector REFUSED it. f(b: 2, 1) against fn f(a: Int, b: Int) binds b by name and 1 to a; the interpreter agrees, returning a == 1, measured. The first selector took the positional fallback from the argument's RAW SOURCE INDEX, so argument 1 selected formal index 1 -- the formal b had already claimed by name -- and the new formal-identity injectivity wall refused a program main accepts. That is a FABRICATED REFUSAL introduced by the very change that exists to remove one, and it was caught in review rather than by any control here, because the controls covered POSITIONAL-THEN-NAMED (already refused upstream) and never the reverse order. THE REPAIR: the positional fallback now selects the k-th formal NOT CLAIMED BY ANY LABEL in the call, where k counts unlabelled arguments before this one -- a running rank, computed inside the selector rather than by routing through call_arg_bound_param_at, which answers a different question and whose underscore handling must not be disturbed. THIS WITNESS IS THE ENROLLED REGRESSION CONTROL for that arm and goes red if the fallback ever returns to a raw index. WHAT IT DOES NOT COVER, stated so the green is not over-read: EMISSION ORDERING for this same call is still wrong on main AND on this branch -- order_typed_call_args returns arguments in SOURCE ORDER whenever any argument is unlabelled, so f(b: 2, 1) emits f(2, 1) and the emitted program computes a different answer than the interpreted one. That is a fourth consumer of the argument-to-formal question with its own third rule, it is pre-existing, and it is out of this carrier's scope; a census counting this witness as covering mixed calls would be counting the source-language half only." - -data formal_selection_note: String = "THE CLASS: which declared formal a call argument binds to was answered in TWO places with DIFFERENT rules. build_call_application_plan matched by AUTHORED LABEL with a positional fallback -- the rule call_function_inner uses -- while the ExprCall inference fold, which chooses the EXPECTED type each argument is inferred under, selected purely by SOURCE POSITION. A call passing named arguments in a different order than declared therefore inferred each argument against its NEIGHBOUR's formal, while the type check ran the other rule and reported nothing. MEASURED ON THE PRE-FIX BINARY, and this is the discriminating fact rather than a prediction: formal_selection_out_of_order_green_source is CORRECT code that main REFUSES with a hard `empty list literal: expected type is not a collection`, because the `[]` sits at source position 1 and was handed `label: String`'s formal. That is a FABRICATED REFUSAL, which DESIGN 5 forbids exactly as it forbids fabricated success, and it is a second, independent symptom of the same fork that produced wrong Rust lambda annotations under the typed-lambda emission route. THE GREEN CONTROL IS TWO-ARMED ON PURPOSE: the declaration-order sibling compiles clean on the pre-fix binary too and emits byte-identical Rust, so a wall that simply admitted every empty list would be indistinguishable from the repair on the out-of-order arm alone -- the pair is what attributes the flip to argument ORDER and to nothing else. Both arms assert GREEN because the defect is a fabricated refusal; the out-of-order arm is the enrolled regression control and goes red again if the two selection rules ever diverge." +// A NAMED ARGUMENT PRECEDING AN UNLABELLED ONE IS ACCEPTED, and this row exists because an earlier +// revision of the selector REFUSED it. f(b: 2, 1) against fn f(a: Int, b: Int) binds b by name and +// 1 to a; the interpreter agrees, returning a == 1, measured. The first selector took the +// positional fallback from the argument's RAW SOURCE INDEX, so argument 1 selected formal index 1 +// -- already claimed by name -- and the new formal-identity injectivity wall refused a program main +// accepts: a FABRICATED REFUSAL introduced by the change meant to remove one, caught in review +// rather than by any control here, because the controls covered POSITIONAL-THEN-NAMED (already +// refused upstream) and never the reverse. THE REPAIR: the positional fallback selects the k-th +// formal NOT CLAIMED BY ANY LABEL in the call, k counting unlabelled arguments before this one -- a +// running rank computed inside the selector, not routed through call_arg_bound_param_at, which +// answers a different question and whose underscore handling must not be disturbed. THIS WITNESS IS +// THE ENROLLED REGRESSION CONTROL for that arm and goes red if the fallback returns to a raw index. +// WHAT IT DOES NOT COVER, so the green is not over-read: EMISSION ORDERING for this same call is +// still wrong on main AND on this branch -- order_typed_call_args returns arguments in SOURCE ORDER +// whenever any argument is unlabelled, so f(b: 2, 1) emits f(2, 1) and the emitted program computes +// a different answer than the interpreted one. That is a fourth consumer of the argument-to-formal +// question with its own third rule, pre-existing, and out of this carrier's scope; a census +// counting this witness as covering mixed calls would be counting the source-language half only. + +// THE CLASS: which declared formal a call argument binds to was answered in TWO places with +// DIFFERENT rules. build_call_application_plan matched by AUTHORED LABEL with a positional fallback +// -- the rule call_function_inner uses -- while the ExprCall inference fold, which chooses the +// EXPECTED type each argument is inferred under, selected purely by SOURCE POSITION. A call passing +// named arguments out of declared order therefore inferred each argument against its NEIGHBOUR's +// formal, while the type check ran the other rule and reported nothing. MEASURED ON THE PRE-FIX +// BINARY, the discriminating fact rather than a prediction: +// formal_selection_out_of_order_green_source is CORRECT code that main REFUSES with a hard `empty +// list literal: expected type is not a collection`, because the `[]` sits at source position 1 and +// was handed `label: String`'s formal. A FABRICATED REFUSAL, which DESIGN 5 forbids exactly as it +// forbids fabricated success, and a second, independent symptom of the fork that produced wrong +// Rust lambda annotations under the typed-lambda emission route. THE GREEN CONTROL IS TWO-ARMED ON +// PURPOSE: the declaration-order sibling compiles clean on the pre-fix binary too and emits +// byte-identical Rust, so a wall simply admitting every empty list would be indistinguishable from +// the repair on the out-of-order arm alone -- the pair attributes the flip to argument ORDER and +// nothing else. Both arms assert GREEN because the defect is a fabricated refusal; the out-of-order +// arm is the enrolled regression control and goes red if the two selection rules ever diverge. data method_missing_source: String = "module probe_method_red\nfn f(xs: List) -> List { xs |> filter_map(x => x) }\nfn g(xs: List) -> Bool { xs |> starts_with(\"x\") }\nfn h(xs: List) -> String { xs |> to_upper() }\n" @@ -811,23 +895,21 @@ test fn canonical_probe_resolution_refuses_duplicate_population() -> Bool { // known_v1_migration_gap_ids below names sole_ctor_mint_fn_hole_probe: its own row's declared // expectation does not yet hold (sole_constructor_probe_scope_note, -// sole_constructor_mint_fn_hole_still_compile_clean) — a tracked open compile gap from #7790, -// never a retired Rust dark-suite witness — so its absence from every disposition is named here, -// not silently unaccounted for in either direction of the join. -// Named residue (DESIGN §4c): known_v1_migration_gap_ids is a hand-authored allowlist and its -// one entry's justification lives only in this prose annotation, which no Accepted program can -// read — the completeness join below cannot itself verify the exception is warranted, only that -// it is the sole one taken. Dissolution trigger: when #7790 closes and -// sole_constructor_mint_fn_hole_still_compile_clean's expectation holds, remove this probe from -// known_v1_migration_gap_ids so it is covered by disposition or registry retirement instead. -// Probes authored directly against the v1 compile path with no Rust witness behind them. The -// migration law below quantifies over every v1-compile row on the assumption that each descends -// from a Rust witness that must be disposed; these do not, so disposing them would assert a -// migration that never happened and listing them as gaps would assert a hole that is not there. -// Both are the rung-inflation failure in miniature, one in each direction, so they get their own -// arm. Membership here is not an exemption from evidence: each row still carries a discriminating -// RED or a positive control executed by a test in this file. -// The three arms must partition, or a row could claim two contradictory standings at once. +// sole_constructor_mint_fn_hole_still_compile_clean) — a tracked open compile gap from #7790, never +// a retired Rust dark-suite witness — so its absence from every disposition is named here, not +// silently unaccounted for in either direction of the join. Named residue (DESIGN §4c): +// known_v1_migration_gap_ids is a hand-authored allowlist whose one entry's justification lives +// only in this annotation, which no Accepted program can read — the completeness join below cannot +// verify the exception is warranted, only that it is the sole one taken. Dissolution trigger: when +// #7790 closes and sole_constructor_mint_fn_hole_still_compile_clean's expectation holds, remove +// this probe from known_v1_migration_gap_ids so it is covered by disposition or registry retirement +// instead. Probes authored directly against the v1 compile path with no Rust witness behind them: +// the migration law below quantifies over every v1-compile row assuming each descends from a Rust +// witness that must be disposed; these do not, so disposing them would assert a migration that +// never happened and listing them as gaps a hole that is not there — rung inflation in miniature, +// one in each direction, so they get their own arm. Membership is not an exemption from evidence: +// each row still carries a discriminating RED or a positive control executed by a test in this +// file. The three arms must partition, or a row could claim two contradictory standings at once. test fn dark_suite_dispositions_cover_migrated_v1_probes() -> Bool { let dispositions = guarantee_probe_dark_suite_dispositions() let disposition_probes: List = dispositions diff --git a/dag/test/claim/gunbc_invoke_witness_test.dag b/dag/test/claim/gunbc_invoke_witness_test.dag index f346b938c4e..7dbef9b4d2a 100644 --- a/dag/test/claim/gunbc_invoke_witness_test.dag +++ b/dag/test/claim/gunbc_invoke_witness_test.dag @@ -24,7 +24,10 @@ import v2.std.live_tree { LiveTreeDisposition, SubstrateInputsOnly } data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data gunbc_invoke_deploy_srv1_pre_migration_golden_note: String = "Hand-frozen pre-Phase-3a bytes from origin/main gunbc_ci_deploy_invoke(gunbc_ci_deploy_srv1_stage) before gunbc.cli_invoke consolidation. Independent of gunbc_run_shell so a helper drift cannot green both sides (PR #6467 ci_cargo_eagain_retry_core_golden pattern)." +// Hand-frozen pre-Phase-3a bytes from origin/main +// gunbc_ci_deploy_invoke(gunbc_ci_deploy_srv1_stage) before gunbc.cli_invoke consolidation. +// Independent of gunbc_run_shell so a helper drift cannot green both sides (PR #6467 +// ci_cargo_eagain_retry_core_golden pattern). data gunbc_ci_deploy_invoke_srv1_pre_migration_golden: String = concat( concat("ROOT=$(git rev-parse --show-toplevel 2>/dev/null || pwd)\n"), @@ -48,7 +51,24 @@ data gunbc_ci_deploy_invoke_srv1_wrong_entry_golden: String = concat( ) ) -data gunbc_invoke_deploy_golden_trailing_newline_note: String = "THE GOLDEN IS UNEDITED AND THE ASSERTION MOVED INSTEAD, which is the opposite of the tempting fix and the reason this row exists. gunbc_ci_deploy_invoke_srv1_pre_migration_golden is a hand-frozen byte string authored before the orchestration-emit binding, deliberately independent of the helper so that a helper change cannot green both sides. After the binding it FAILED, and the cheap move -- repaste the new output into the golden -- would have destroyed exactly the independence that makes it worth having: a golden derived from the thing it checks asserts nothing. So the golden keeps its original bytes and the assertion below states the measured relationship instead. MEASURED, not assumed: concat(new output, newline) == the golden, exactly. The migration is byte-preserving for this invocation apart from one trailing newline. WHERE THAT NEWLINE WENT AND WHY IT IS NOT RESTORED: the deleted gunbc_run_shell appended a newline to every invocation it built, so a caller that added a receipt cat after it got the newline as a SEPARATOR and a caller that did not got it as a trailing byte -- one spelling doing two jobs. v2.std.orchestration joins pipeline steps with newlines and emits none after the last, so separation is now structural and the trailing byte simply has no author. Restoring it would mean re-introducing a per-site concat to reproduce an artifact of the mechanism this change deletes, which is DESIGN section 7's warts-for-byte-identity trap. The emitted workflows are unaffected either way: the YAML block-scalar emitter normalizes the block body, and the measured fleet-converge.yml diff carries no whitespace change at any bound step." +// THE GOLDEN IS UNEDITED AND THE ASSERTION MOVED INSTEAD, which is the opposite of the tempting fix +// and the reason this row exists. gunbc_ci_deploy_invoke_srv1_pre_migration_golden is a hand-frozen +// byte string authored before the orchestration-emit binding, deliberately independent of the +// helper so that a helper change cannot green both sides. After the binding it FAILED, and the +// cheap move -- repaste the new output into the golden -- would have destroyed exactly the +// independence that makes it worth having: a golden derived from the thing it checks asserts +// nothing. So the golden keeps its original bytes and the assertion below states the measured +// relationship instead. MEASURED, not assumed: concat(new output, newline) == the golden, exactly. +// The migration is byte-preserving for this invocation apart from one trailing newline. WHERE THAT +// NEWLINE WENT AND WHY IT IS NOT RESTORED: the deleted gunbc_run_shell appended a newline to every +// invocation it built, so a caller that added a receipt cat after it got the newline as a SEPARATOR +// and a caller that did not got it as a trailing byte -- one spelling doing two jobs. +// v2.std.orchestration joins pipeline steps with newlines and emits none after the last, so +// separation is now structural and the trailing byte simply has no author. Restoring it would mean +// re-introducing a per-site concat to reproduce an artifact of the mechanism this change deletes, +// which is DESIGN section 7's warts-for-byte-identity trap. The emitted workflows are unaffected +// either way: the YAML block-scalar emitter normalizes the block body, and the measured +// fleet-converge.yml diff carries no whitespace change at any bound step. test fn gunbc_invoke_deploy_matches_pre_migration_golden_holds() -> Bool { concat(gunbc_ci_deploy_invoke(stage: gunbc_ci_deploy_srv1_stage), "\n") == @@ -79,7 +99,15 @@ test fn gunbc_invoke_verify_artifacts_shell_nonempty_holds() -> Bool { ) } -data gunbc_invoke_word_wall_note: String = "THE EXECUTING EVIDENCE that v2.workflow.gunbc_invoke_step_emit's fail-closed word wall is real rather than declared. The positive control is gunbc_invoke_deploy_matches_pre_migration_golden_holds above -- a hand-frozen golden authored before the migration, so the binding must reproduce bytes it did not author. The discriminating RED is below: an entry carrying a shell metacharacter must NOT reach the emitted command, and the refusal must be a marker that is not valid workflow shell so the committed workflow drift gate goes red. These two stay enrolled after the wall lands; deleting them would recreate specification-without-execution one rung up (DESIGN section 4b, dissolution-on-climb applies to production handling only, never the evidence)." +// THE EXECUTING EVIDENCE that v2.workflow.gunbc_invoke_step_emit's fail-closed word wall is real +// rather than declared. The positive control is +// gunbc_invoke_deploy_matches_pre_migration_golden_holds above -- a hand-frozen golden authored +// before the migration, so the binding must reproduce bytes it did not author. The discriminating +// RED is below: an entry carrying a shell metacharacter must NOT reach the emitted command, and the +// refusal must be a marker that is not valid workflow shell so the committed workflow drift gate +// goes red. These two stay enrolled after the wall lands; deleting them would recreate +// specification-without-execution one rung up (DESIGN section 4b, dissolution-on-climb applies to +// production handling only, never the evidence). test fn gunbc_invoke_word_wall_refuses_metacharacter_entry_holds() -> Bool { let refused = gunbc_run_step_script( diff --git a/dag/test/claim/heal_revalidation_witness_test.dag b/dag/test/claim/heal_revalidation_witness_test.dag index 0aa2a3cf0c0..599a9df4667 100644 --- a/dag/test/claim/heal_revalidation_witness_test.dag +++ b/dag/test/claim/heal_revalidation_witness_test.dag @@ -176,6 +176,14 @@ test fn manual_dispatch_without_expected_sha_cannot_masquerade_as_heal_revalidat } } +// These executing witnesses enumerate every current HealOutcome arm (including +// HealAuthorCommitRequired) and every HealDispatchOutcome arm through exhaustive matches. A newly +// added heal path or dispatch classification makes this file and the admission folds fail to +// compile until it is explicitly classified; unclassified cannot become success. The RED controls +// discriminate dispatch accepted from coverage complete, refused dispatch from an in-flight run, +// old-head green from healed-head green, ordinary manual dispatch from heal revalidation, and +// author-commit-required workflow drift from produced heal heads. + test fn expected_sha_preflight_binds_run_subject_and_checkout_exactly() -> Bool { let matched = classify_workflow_dispatch_preflight( expected_healed_head: Present { value: healed_head }, @@ -211,5 +219,3 @@ test fn expected_sha_preflight_binds_run_subject_and_checkout_exactly() -> Bool HealWorkflowDispatchCheckoutMismatch { expected_head: _, checkout_head: _, run_subject_head: _ } => false } } - -data heal_revalidation_closed_denominator_witness_note: String = "These executing witnesses enumerate every current HealOutcome arm (including HealAuthorCommitRequired) and every HealDispatchOutcome arm through exhaustive matches. A newly added heal path or dispatch classification makes this file and the admission folds fail to compile until it is explicitly classified; unclassified cannot become success. The RED controls discriminate dispatch accepted from coverage complete, refused dispatch from an in-flight run, old-head green from healed-head green, ordinary manual dispatch from heal revalidation, and author-commit-required workflow drift from produced heal heads." diff --git a/dag/test/claim/homomorphism_trait_derive_emit_witness_test.dag b/dag/test/claim/homomorphism_trait_derive_emit_witness_test.dag index 0bbf60a6690..13adf1497e8 100644 --- a/dag/test/claim/homomorphism_trait_derive_emit_witness_test.dag +++ b/dag/test/claim/homomorphism_trait_derive_emit_witness_test.dag @@ -4,7 +4,12 @@ import v2.std.live_tree { LiveTreeDisposition, SubstrateInputsOnly } data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data homomorphism_trait_derive_emit_witness_note: String = "Discriminating controls for trait_derive_emit item-own generic parameters used as type-application heads. Homomorphism applies C to Source and Target; C is the declaring item's own type parameter, not a declared type in scope, so v1_type_expr_clone_undecided_head must recurse through C instead of refusing at C. Positive: emission succeeds without trait_derive_emit / compile_error! refusal. Negative: genuinely unknown heads still refuse with a located name." +// Discriminating controls for trait_derive_emit item-own generic parameters used as +// type-application heads. Homomorphism applies C to Source and Target; C is the +// declaring item's own type parameter, not a declared type in scope, so +// v1_type_expr_clone_undecided_head must recurse through C instead of refusing at C. +// Positive: emission succeeds without trait_derive_emit / compile_error! refusal. Negative: +// genuinely unknown heads still refuse with a located name. fn w_item_own_generic_param_applied_type_emits() -> Bool { compile_dag_rust_emit_check( diff --git a/dag/test/claim/host/host_allocation_conservation_test.dag b/dag/test/claim/host/host_allocation_conservation_test.dag index 91ad146024b..5a45f361b10 100644 --- a/dag/test/claim/host/host_allocation_conservation_test.dag +++ b/dag/test/claim/host/host_allocation_conservation_test.dag @@ -1,6 +1,5 @@ module test.claim.host_allocation_conservation - // THIS MODULE PREVIOUSLY DECLARED NO IMPORTS AT ALL and resolved every name by bare whole-tree // lookup, which the flat namespace permits. The cost is that it could not be run under an entry // scope -- every witness in it died on NoSuchFunction locally, independent of any change here -- so @@ -102,7 +101,22 @@ test fn allocation_conserves_when_pools_fit() -> Bool { ) } -data per_host_width_red_controls_note: String = "THE FOUR CONTROLS BELOW ARE THE POINT OF THE PER-HOST SPLIT, and each one goes red against a specific way of getting this wrong rather than against a changed number. Every input is the live authority except the WIDTH under test, which is perturbed by exactly one slot — so a control cannot pass by coincidence and cannot be repaired by editing a literal.\n\nThe pair matters more than either half. Asserting only that the committed widths fit would be satisfied by a wall that returns true for everything, which is exactly the wall this change replaced (it charged session_pool: 0 on every host and would have passed srv1 at seven slots). Asserting only the refusals would be satisfied by a wall that refuses everything. Together they pin the boundary at the slot, in both directions, on both host classes.\n\nWhy srv1 refuses at 6 and srv3 refuses at 7 (srv3's boundary moved down one slot with the 2026-08-17 16GiB ruling): srv1 owes the sessions reservation its roster entry declares and carries the legacy overhead allowance, srv3 owes neither and carries the measured bound. Same per-slot ceiling, same host RAM, different admissible width — which is the whole claim, stated as arithmetic that fails if either per-host fact is wrong." +// THE FOUR CONTROLS BELOW ARE THE POINT OF THE PER-HOST SPLIT, and each one goes red against a +// specific way of getting this wrong rather than against a changed number. Every input is the live +// authority except the WIDTH under test, which is perturbed by exactly one slot — so a control +// cannot pass by coincidence and cannot be repaired by editing a literal. +// +// The pair matters more than either half. Asserting only that the committed widths fit would be +// satisfied by a wall that returns true for everything, which is exactly the wall this change +// replaced (it charged session_pool: 0 on every host and would have passed srv1 at seven slots). +// Asserting only the refusals would be satisfied by a wall that refuses everything. Together they +// pin the boundary at the slot, in both directions, on both host classes. +// +// Why srv1 refuses at 6 and srv3 refuses at 7 (srv3's boundary moved down one slot with the +// 2026-08-17 16GiB ruling): srv1 owes the sessions reservation its roster entry declares and +// carries the legacy overhead allowance, srv3 owes neither and carries the measured bound. Same +// per-slot ceiling, same host RAM, different admissible width — which is the whole claim, stated as +// arithmetic that fails if either per-host fact is wrong. fn usable_ram_of(host: HostIdentity) -> ByteSize { match host_usable_ram_or_refusal(host: host, r: gunbc_ci_host_usable_ram_for(host: host)) { @@ -248,7 +262,11 @@ test fn an_unsized_host_yields_no_committed_width_verdict() -> Bool { } } -data boundary_is_pinned_on_the_memory_axis_note: String = "THE +1 CONTROL RUNS AGAINST host_memory_admitted_width, NOT AGAINST THE COMMITTED WIDTH, because this wall answers a question about RAM and the committed width is a minimum over more axes than RAM. srv4 no longer binds disk at allocation — disk is gated at apply via gunbc.runner_lifecycle runner_width_disk_preflight — so memory admission and committed width both read 7; the control stays on the memory axis where it belongs." +// THE +1 CONTROL RUNS AGAINST host_memory_admitted_width, NOT AGAINST THE COMMITTED WIDTH, because +// this wall answers a question about RAM and the committed width is a minimum over more axes than +// RAM. srv4 no longer binds disk at allocation — disk is gated at apply via gunbc.runner_lifecycle +// runner_width_disk_preflight — so memory admission and committed width both read 7; the control +// stays on the memory axis where it belongs. test fn one_more_slot_than_memory_admits_refuses_on_every_host() -> Bool { all( @@ -257,7 +275,10 @@ test fn one_more_slot_than_memory_admits_refuses_on_every_host() -> Bool { ) } -data committed_width_never_exceeds_memory_admission_note: String = "The minimum cannot exceed either of its arguments, and this row is the executable form of that: no host may commit a width its RAM does not admit. It goes red if a future axis is folded into gunbc_runner_slots_per_host with the comparison inverted, which is the one edit that would turn a constraint into a grant." +// The minimum cannot exceed either of its arguments, and this row is the executable form of that: +// no host may commit a width its RAM does not admit. It goes red if a future axis is folded into +// gunbc_runner_slots_per_host with the comparison inverted, which is the one edit that would turn a +// constraint into a grant. test fn committed_width_never_exceeds_memory_admission() -> Bool { all( @@ -266,7 +287,18 @@ test fn committed_width_never_exceeds_memory_admission() -> Bool { ) } -data srv4_disk_gated_at_apply_not_allocation_note: String = "srv4 COMMITS THE CPU WIDTH LIKE srv3, AND MEMORY IS NO LONGER THE BINDING AXIS ON EITHER (2026-08-22 DIMM upgrade, 2026-08-23 CPU axis). Memory admits 29 and CPU admits 21, so both commit 21; before the upgrade memory admitted 6 and bound the commitment. The retired disk row-pin still does not lower allocation. Disk binding is apply-time via gunbc.runner_lifecycle runner_width_disk_preflight (~38GB/slot). host_disk_admitted_width stays DiskWidthUnconstrained at allocation so provisioning cannot silently skip the gate; unobservable disk at apply refuses rather than falling back to a lower width.\n\nTHIS ROW ASSERTS THE MEMORY VERDICT AND THE COMMITMENT SEPARATELY AND ON PURPOSE. They were equal when it was written and are not equal now, so a row checking only one of them would have gone on passing while the other moved -- which is exactly how the srv4 roster-versus-prose disagreement this test exists to prevent got started." +// srv4 COMMITS THE CPU WIDTH LIKE srv3, AND MEMORY IS NO LONGER THE BINDING AXIS ON EITHER +// (2026-08-22 DIMM upgrade, 2026-08-23 CPU axis). Memory admits 29 and CPU admits 21, so both +// commit 21; before the upgrade memory admitted 6 and bound the commitment. The retired disk +// row-pin still does not lower allocation. Disk binding is apply-time via gunbc.runner_lifecycle +// runner_width_disk_preflight (~38GB/slot). host_disk_admitted_width stays DiskWidthUnconstrained +// at allocation so provisioning cannot silently skip the gate; unobservable disk at apply refuses +// rather than falling back to a lower width. +// +// THIS ROW ASSERTS THE MEMORY VERDICT AND THE COMMITMENT SEPARATELY AND ON PURPOSE. They were equal +// when it was written and are not equal now, so a row checking only one of them would have gone on +// passing while the other moved -- which is exactly how the srv4 roster-versus-prose disagreement +// this test exists to prevent got started. test fn srv4_commits_memory_width_disk_gated_at_apply() -> Bool { host_memory_admitted_width(host: operator_host_srv4) == 29 @@ -306,8 +338,23 @@ test fn session_hosts_refuse_the_managed_width() -> Bool { // KEEPING srv1 HERE WOULD HAVE BEEN THE WORSE FAILURE: the row would have gone red and the obvious // repair -- relax the assertion until it passes -- would have silently retired a live claim because // its example had grown out of it. -data sessions_charge_decisive_on_srv2_superseded_note: String = "sessions_charge_is_decisive_on_srv2 IS DELETED, AND IT WAS PASSING WHEN IT WAS DELETED -- which is the reason, not an objection to it. It asserted that srv2 conserves at width 6 with no session charge and refuses with one, and its refusing half was `!conserves_at_width(srv2, 6)`. Once srv2's session denominator became unestablished that conjunct went true because NO VERDICT IS MINTED for an unsized host, not because the session charge was decisive. The witness therefore reported a green for a claim it had stopped testing, which is worse than a red: a red is a question, a vacuous green is counted as coverage.\n\nTHE LAW IT CARRIED IS NOT RETIRED WITH IT. the_live_session_charge_is_decisive_on_a_derived_boundary carries the same claim on srv1, deriving both widths from current policy instead of pinning one, so it follows the boundary rather than aging out the way this row's width 6 did. sessions_subtract_from_the_same_budget independently keeps the arithmetic relation on an authored fixture, which is a different guarantee and is deliberately not merged into it.\n\nWHAT WOULD HAVE HIDDEN THIS: nothing in the diff. The witness compiled, ran, and passed. It was found by asking why a row the operator ruling had called correctly dead was reporting alive." - +// sessions_charge_is_decisive_on_srv2 IS DELETED, AND IT WAS PASSING WHEN IT WAS DELETED -- which +// is the reason, not an objection to it. It asserted that srv2 conserves at width 6 with no session +// charge and refuses with one, and its refusing half was `!conserves_at_width(srv2, 6)`. Once +// srv2's session denominator became unestablished that conjunct went true because NO VERDICT IS +// MINTED for an unsized host, not because the session charge was decisive. The witness therefore +// reported a green for a claim it had stopped testing, which is worse than a red: a red is a +// question, a vacuous green is counted as coverage. +// +// THE LAW IT CARRIED IS NOT RETIRED WITH IT. +// the_live_session_charge_is_decisive_on_a_derived_boundary carries the same claim on srv1, +// deriving both widths from current policy instead of pinning one, so it follows the boundary +// rather than aging out the way this row's width 6 did. sessions_subtract_from_the_same_budget +// independently keeps the arithmetic relation on an authored fixture, which is a different +// guarantee and is deliberately not merged into it. +// +// WHAT WOULD HAVE HIDDEN THIS: nothing in the diff. The witness compiled, ran, and passed. It was +// found by asking why a row the operator ruling had called correctly dead was reporting alive. test fn allocation_unsound_when_runner_pool_overcommits() -> Bool { !witness_allocation_conserves( @@ -338,11 +385,46 @@ test fn sessions_subtract_from_the_same_budget() -> Bool { && !sessions_fixture_at(session_pool: byte_size(42949672960)) } -data sessions_subtract_fixture_note: String = "THIS WITNESS WAS NOT TESTING SESSIONS, and the repair matters more than the deletion that surfaced it. It asserted a single negative while mixing a LIVE authority (gunbc_runner_pool_budget_for(srv1)) into an otherwise authored 125 GiB fixture host. Executed with the session term at ZERO it STILL PASSES — measured, not inferred — because srv1 is now a ~502 GiB host whose live runner pool alone exceeds the fixture. The sessions term contributed nothing to the verdict, so the witness has been green-by-coincidence since that memory upgrade.\n\nMIXING A LIVE AUTHORITY INTO A FIXTURE IS THE ROOT: the two sides drifted independently, so a fleet hardware change silently redefined what the witness meant without anyone editing it. Both sides are authored constants now, and the assertion is two-sided — the SAME configuration must conserve at session_pool 0 and fail at 40 GiB, so only the session term moves. An always-conserving wall fails the second arm; an always-refusing wall fails the first.\n\nEXECUTED, both arms load-bearing: as authored true; session fixture shrunk to 2 GiB false; runner pool inflated to 192 GiB false; restored control true. The pre-repair form returned true with the session term at zero, which is the measurement that condemned it." - -data per_host_usable_ram_controls_note: String = "THE GRAIN IS THE CLAIM, so these controls test the SPLIT rather than the number. Every host still resolves to the same substitution figure today — that is deliberate, and committed_width_fits_on_every_host above already pins that the derived widths did not move. What these add is that the lookup is genuinely per-host and that an unclassified host REFUSES instead of borrowing, which is the property the old fleet-level read could not have.\n\nThe refusal control is the load-bearing one. The function it replaces took no host argument at all and summed a synthetic ComputeHost that is not a member of the fold it served, so there was no unclassified-host case to get wrong — and correspondingly no way to notice one. An unknown host reaching this wall now produces a located refusal, the same shape the overhead axis beside it already had." - -data differential_witness_note: String = "ASSERTING THAT FOUR LOOKUPS RETURN A POSITIVE NUMBER DOES NOT TEST A PER-HOST GRAIN, which is what the first version of this witness did. Four branches returning one shared declaration satisfy it exactly as well as four independent host facts do, so it would have passed unchanged against the fleet constant this change replaces — a witness that cannot fail for the reason it exists.\n\nThe grain is only observable DIFFERENTIALLY: perturb one host and prove that host's answer moves while the others hold. Since all four rows deliberately carry the same figure today, the perturbation has to come from a synthetic lookup rather than the live rows, so what is pinned is the SHAPE of the dispatch — that it is keyed by host at all — which is precisely the property the old signature could not have had, since it took no host argument." +// THIS WITNESS WAS NOT TESTING SESSIONS, and the repair matters more than the deletion that +// surfaced it. It asserted a single negative while mixing a LIVE authority +// (gunbc_runner_pool_budget_for(srv1)) into an otherwise authored 125 GiB fixture host. Executed +// with the session term at ZERO it STILL PASSES — measured, not inferred — because srv1 is now a +// ~502 GiB host whose live runner pool alone exceeds the fixture. The sessions term contributed +// nothing to the verdict, so the witness has been green-by-coincidence since that memory upgrade. +// +// MIXING A LIVE AUTHORITY INTO A FIXTURE IS THE ROOT: the two sides drifted independently, so a +// fleet hardware change silently redefined what the witness meant without anyone editing it. Both +// sides are authored constants now, and the assertion is two-sided — the SAME configuration must +// conserve at session_pool 0 and fail at 40 GiB, so only the session term moves. An +// always-conserving wall fails the second arm; an always-refusing wall fails the first. +// +// EXECUTED, both arms load-bearing: as authored true; session fixture shrunk to 2 GiB false; runner +// pool inflated to 192 GiB false; restored control true. The pre-repair form returned true with the +// session term at zero, which is the measurement that condemned it. + +// THE GRAIN IS THE CLAIM, so these controls test the SPLIT rather than the number. Every host still +// resolves to the same substitution figure today — that is deliberate, and +// committed_width_fits_on_every_host above already pins that the derived widths did not move. What +// these add is that the lookup is genuinely per-host and that an unclassified host REFUSES instead +// of borrowing, which is the property the old fleet-level read could not have. +// +// The refusal control is the load-bearing one. The function it replaces took no host argument at +// all and summed a synthetic ComputeHost that is not a member of the fold it served, so there was +// no unclassified-host case to get wrong — and correspondingly no way to notice one. An unknown +// host reaching this wall now produces a located refusal, the same shape the overhead axis beside +// it already had. + +// ASSERTING THAT FOUR LOOKUPS RETURN A POSITIVE NUMBER DOES NOT TEST A PER-HOST GRAIN, which is +// what the first version of this witness did. Four branches returning one shared declaration +// satisfy it exactly as well as four independent host facts do, so it would have passed unchanged +// against the fleet constant this change replaces — a witness that cannot fail for the reason it +// exists. +// +// The grain is only observable DIFFERENTIALLY: perturb one host and prove that host's answer moves +// while the others hold. Since all four rows deliberately carry the same figure today, the +// perturbation has to come from a synthetic lookup rather than the live rows, so what is pinned is +// the SHAPE of the dispatch — that it is keyed by host at all — which is precisely the property the +// old signature could not have had, since it took no host argument. fn synthetic_usable_ram_for(host: HostIdentity) -> HostUsableRam { if (host as String) == (operator_host_srv3 as String) { @@ -452,7 +534,23 @@ test fn every_enrolled_host_carries_its_own_measured_reading() -> Bool { ) } -data derived_width_probe_note: String = "WHAT THIS PROBE IS FOR, stated plainly because it asserts about a function that does not exist yet. host_memory_admitted_width returns hand-authored literals 5/5/6/6 (5/5/7/7 before the 2026-08-17 16GiB ruling), while gunbc.runner_slot_allocation gunbc_runner_slot_width_ruling_note describes those numbers as falling out of the conservation arithmetic — 'neither number is authored here as a target; both are the largest width the wall will pass'. That is a claim about a derivation nobody wrote: the arithmetic was run by hand once and its answers were typed in beside the wall that checks them, which is the second-representation shape DESIGN 5 names, and it is why raising a host's RAM does not raise its width.\n\nThis probe runs the derivation the note describes and asserts it reproduces every literal exactly. It is evidence for replacing them with the derivation, and until then it is a live consumer that reds if the two ever disagree — which is the failure the current arrangement cannot detect, because nothing recomputes the literals.\n\nIt lives in a test module deliberately: the production derivation needs the overhead, session and headroom charges, and those sit downstream of runner_slot_allocation, so writing it in place would close an import cycle. Resolving that is a structural change, not a line edit." +// WHAT THIS PROBE IS FOR, stated plainly because it asserts about a function that does not exist +// yet. host_memory_admitted_width returns hand-authored literals 5/5/6/6 (5/5/7/7 before the +// 2026-08-17 16GiB ruling), while gunbc.runner_slot_allocation gunbc_runner_slot_width_ruling_note +// describes those numbers as falling out of the conservation arithmetic — 'neither number is +// authored here as a target; both are the largest width the wall will pass'. That is a claim about +// a derivation nobody wrote: the arithmetic was run by hand once and its answers were typed in +// beside the wall that checks them, which is the second-representation shape DESIGN 5 names, and it +// is why raising a host's RAM does not raise its width. +// +// This probe runs the derivation the note describes and asserts it reproduces every literal +// exactly. It is evidence for replacing them with the derivation, and until then it is a live +// consumer that reds if the two ever disagree — which is the failure the current arrangement cannot +// detect, because nothing recomputes the literals. +// +// It lives in a test module deliberately: the production derivation needs the overhead, session and +// headroom charges, and those sit downstream of runner_slot_allocation, so writing it in place +// would close an import cycle. Resolving that is a structural change, not a line edit. type DerivedAdmittedWidth = DerivedWidth { host: HostIdentity, slots: Int } diff --git a/dag/test/claim/host/host_budget_source_witness_test.dag b/dag/test/claim/host/host_budget_source_witness_test.dag index 410e544c0b0..e7cdf8cf775 100644 --- a/dag/test/claim/host/host_budget_source_witness_test.dag +++ b/dag/test/claim/host/host_budget_source_witness_test.dag @@ -50,9 +50,36 @@ data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly // These rows are about the RELATION between a kernel family and a budget source, not about the machine running them, so they are SubstrateInputsOnly and give the same verdict on every platform. That is deliberate and is the point: the defect being walled is a claim the code makes about a platform, and a check that could only run on the affected platform would be untestable from the fleet's own Linux CI — which is how the fabricated label survived in the first place. data all_kernels: List = [Linux, Darwin, WindowsNt, LinuxGuestOnWindows] -data import_widening_shadowed_contains_note: String = "WHY THESE CALLS SAY string_contains RATHER THAN contains, and it is a receipt rather than a style choice. Deriving the declared_high expectation from its authority row required importing gunbc.runner_slot_allocation into this module. v1-seed fn names are NOT module-scoped, so widening the import closure pulled v2.std.algebra into it, and that module's contains(xs, item, eq) over FreeMonoid captured the bare name these lines were using for the STRING contains(haystack, needle). Four calls on lines unrelated to the change refused with 'no parameter named haystack', and the floor fold aborted during preparation -- so the whole 9782-witness roster failed to run over a two-line edit elsewhere in the file.\n\nTHE COST SHAPE IS THE POINT: an import added for one declaration silently re-resolved a bare name used by different declarations in the same module, and nothing local to those lines changed. string_contains is the unambiguous builtin and does not collide, so the calls are pinned to it. The gunbc.runner_slot_allocation import that first widened the closure is gone with the arm it fed, and the pinning deliberately stays: the hazard is the import closure, not that one import, so unpinning would only re-arm it for whoever widens the closure next. The general hazard is the same one std.decl_ref decl_ref_constructor_authority_note records for duplicated constructors -- unqualified seed names make an import closure a name-capture surface -- and it dissolves when v1 name resolution is namespace-scoped rather than bare." +// WHY THESE CALLS SAY string_contains RATHER THAN contains, and it is a receipt rather than a style +// choice. Deriving the declared_high expectation from its authority row required importing +// gunbc.runner_slot_allocation into this module. v1-seed fn names are NOT module-scoped, so +// widening the import closure pulled v2.std.algebra into it, and that module's contains(xs, item, +// eq) over FreeMonoid captured the bare name these lines were using for the STRING +// contains(haystack, needle). Four calls on lines unrelated to the change refused with 'no +// parameter named haystack', and the floor fold aborted during preparation -- so the whole +// 9782-witness roster failed to run over a two-line edit elsewhere in the file. +// +// THE COST SHAPE IS THE POINT: an import added for one declaration silently re-resolved a bare name +// used by different declarations in the same module, and nothing local to those lines changed. +// string_contains is the unambiguous builtin and does not collide, so the calls are pinned to it. +// The gunbc.runner_slot_allocation import that first widened the closure is gone with the arm it +// fed, and the pinning deliberately stays: the hazard is the import closure, not that one import, +// so unpinning would only re-arm it for whoever widens the closure next. The general hazard is the +// same one std.decl_ref decl_ref_constructor_authority_note records for duplicated constructors -- +// unqualified seed names make an import closure a name-capture surface -- and it dissolves when v1 +// name resolution is namespace-scoped rather than bare. -data declared_high_is_derived_not_retyped_note: String = "THIS ROW USED TO RETYPE THE MIRROR VALUE IT WAS MEASURING, and the arm it measured is now deleted, so the receipt is kept without the row. Both call sites constructed BudgetSourceMemAvailableCappedAtDeclaredHigh with byte_size(13958643712) -- the seed constant's own number, copied into the expectation -- so the witness greened whichever way the mirror went and could not have caught the eleven-day drift it sat next to. A measurement copied from the tree under test is not an oracle (2026-08-01 ruling).\n\nThe arm went away for a different reason than this note: capping a host-shared reading at one fleet's declared slot line was a substitution, not a bound (gunbc.host_budget_source host_budget_unreadable_cgroup_receipt_note). The lesson survives the arm, which is why this row does — a fixture derived from the tree under test is inert whatever it is measuring." +// THIS ROW USED TO RETYPE THE MIRROR VALUE IT WAS MEASURING, and the arm it measured is now +// deleted, so the receipt is kept without the row. Both call sites constructed +// BudgetSourceMemAvailableCappedAtDeclaredHigh with byte_size(13958643712) -- the seed constant's +// own number, copied into the expectation -- so the witness greened whichever way the mirror went +// and could not have caught the eleven-day drift it sat next to. A measurement copied from the tree +// under test is not an oracle (2026-08-01 ruling). +// +// The arm went away for a different reason than this note: capping a host-shared reading at one +// fleet's declared slot line was a substitution, not a bound (gunbc.host_budget_source +// host_budget_unreadable_cgroup_receipt_note). The lesson survives the arm, which is why this row +// does — a fixture derived from the tree under test is inert whatever it is measuring. data all_sources: List = [ BudgetSourceEnvOverride, @@ -84,7 +111,12 @@ test fn every_procfs_path_renders_an_absolute_proc_path() -> Bool { ) } -data degraded_is_private_limit_note: String = "The degraded axis is asserted as a PARTITION of the arms rather than arm-by-arm, so adding a source cannot leave the question unanswered: degraded is asserted to be exactly the complement of host_budget_source_bounds_this_process over all_sources, so the two axes cannot drift apart and a new arm must answer both. A witness that listed only the degraded arms would still pass if a new arm defaulted to non-degraded, which is the direction that actually costs something — a host-shared signal silently trusted as a private limit is the 2026-07-21 srv3 exit-137 shape." +// The degraded axis is asserted as a PARTITION of the arms rather than arm-by-arm, so adding a +// source cannot leave the question unanswered: degraded is asserted to be exactly the complement of +// host_budget_source_bounds_this_process over all_sources, so the two axes cannot drift apart and a +// new arm must answer both. A witness that listed only the degraded arms would still pass if a new +// arm defaulted to non-degraded, which is the direction that actually costs something — a +// host-shared signal silently trusted as a private limit is the 2026-07-21 srv3 exit-137 shape. test fn degraded_is_exactly_the_non_private_sources() -> Bool { all( @@ -97,7 +129,21 @@ test fn degraded_is_exactly_the_non_private_sources() -> Bool { && host_budget_source_is_degraded(s: BudgetSourceDarwinPhysicalMemory) } -data buildbuddy_substitution_red_note: String = "THE DISCRIMINATING PAIR FOR THE 2026-08-30 BUILDBUDDY SIGKILL, and it is a pair for the same reason the platform-wall pair below is: either half alone is satisfied by a degenerate predicate. The RED asserts that on a kernel WITH a private-limit mechanism, no source that fails to bound this process may serve as the budget — the sentence the deleted MemAvailable arm violated on every Linux runner whose cgroup files it could not read. The control asserts those same sources stay admissible on the kernels that have no such mechanism, which is what keeps hw.memsize legitimate on a Mac; without it, a predicate that refused everything would pass the RED and leave macOS unable to name any budget at all.\n\nA note on what the RED can and cannot catch now. The three meminfo arms are DELETED, so today the only source with a false bounds_this_process is the Darwin one and this row's Linux arm is carried by it. That is deliberate rather than incidental: the deletion is the wall (no constructor, so no substitution is authorable), and this predicate is the wall for the NEXT arm someone adds — it goes red the moment a host-shared reading is reintroduced and pointed at Linux, which is exactly how the deleted arm entered." +// THE DISCRIMINATING PAIR FOR THE 2026-08-30 BUILDBUDDY SIGKILL, and it is a pair for the same +// reason the platform-wall pair below is: either half alone is satisfied by a degenerate predicate. +// The RED asserts that on a kernel WITH a private-limit mechanism, no source that fails to bound +// this process may serve as the budget — the sentence the deleted MemAvailable arm violated on +// every Linux runner whose cgroup files it could not read. The control asserts those same sources +// stay admissible on the kernels that have no such mechanism, which is what keeps hw.memsize +// legitimate on a Mac; without it, a predicate that refused everything would pass the RED and leave +// macOS unable to name any budget at all. +// +// A note on what the RED can and cannot catch now. The three meminfo arms are DELETED, so today the +// only source with a false bounds_this_process is the Darwin one and this row's Linux arm is +// carried by it. That is deliberate rather than incidental: the deletion is the wall (no +// constructor, so no substitution is authorable), and this predicate is the wall for the NEXT arm +// someone adds — it goes red the moment a host-shared reading is reintroduced and pointed at Linux, +// which is exactly how the deleted arm entered. test fn RED_a_non_bounding_source_is_inadmissible_where_a_private_limit_exists() -> Bool { all( @@ -128,7 +174,16 @@ test fn cgroup_v2_provision_follows_the_kernel_not_the_name() -> Bool { && !kernel_provides_cgroup_v2(kernel: WindowsNt) } -data cgroup_kernels_promise_nothing_statically_note: String = "THE ROW THAT WOULD HAVE CAUGHT THE OLD SHAPE. host_budget_source_for_kernel answered BudgetSourceMemTotal for Linux: a declaration-time promise that a Linux host always has a budget, redeemable only by reading the whole machine. This asserts the opposite — a kernel that CAN express a private limit makes no static promise, because whether it does express one is a runtime fact — and it is red for any future edit that hands a procfs kernel a static source again.\n\nIts control is the Darwin arm: a kernel with no private-limit mechanism MUST answer statically, because there is nothing to wait for and refusing a Mac outright would be an over-refusal rather than a wall. WindowsNt answers UnmodeledPlatform, which is a third state and must not be reachable by either of the other two." +// THE ROW THAT WOULD HAVE CAUGHT THE OLD SHAPE. host_budget_source_for_kernel answered +// BudgetSourceMemTotal for Linux: a declaration-time promise that a Linux host always has a budget, +// redeemable only by reading the whole machine. This asserts the opposite — a kernel that CAN +// express a private limit makes no static promise, because whether it does express one is a runtime +// fact — and it is red for any future edit that hands a procfs kernel a static source again. +// +// Its control is the Darwin arm: a kernel with no private-limit mechanism MUST answer statically, +// because there is nothing to wait for and refusing a Mac outright would be an over-refusal rather +// than a wall. WindowsNt answers UnmodeledPlatform, which is a third state and must not be +// reachable by either of the other two. test fn RED_a_kernel_with_a_private_limit_promises_no_static_source() -> Bool { all( @@ -161,7 +216,17 @@ test fn darwin_sources_statically_and_windows_is_unmodeled() -> Bool { } } -data platform_wall_red_control_note: String = "THE DISCRIMINATING PAIR, and it is the whole reason this file exists. The live defect is that read_host_budget_bytes reports BudgetSourceMemTotal on a Darwin host — a procfs-reading source named on a kernel that provides no procfs. The first witness asserts every procfs-reading arm is INADMISSIBLE on both non-procfs kernels; the second asserts those same arms stay admissible on both procfs kernels.\n\nOne without the other proves nothing. Asserting only inadmissibility is satisfied by a predicate that refuses everything, which would make the governor unable to name a legitimate cgroup read on Linux; asserting only admissibility is satisfied by the predicate that returns true unconditionally, which is the behaviour today. Together they pin the boundary exactly at 'reads procfs AND kernel lacks procfs', which is the sentence the bug violates." +// THE DISCRIMINATING PAIR, and it is the whole reason this file exists. The live defect is that +// read_host_budget_bytes reports BudgetSourceMemTotal on a Darwin host — a procfs-reading source +// named on a kernel that provides no procfs. The first witness asserts every procfs-reading arm is +// INADMISSIBLE on both non-procfs kernels; the second asserts those same arms stay admissible on +// both procfs kernels. +// +// One without the other proves nothing. Asserting only inadmissibility is satisfied by a predicate +// that refuses everything, which would make the governor unable to name a legitimate cgroup read on +// Linux; asserting only admissibility is satisfied by the predicate that returns true +// unconditionally, which is the behaviour today. Together they pin the boundary exactly at 'reads +// procfs AND kernel lacks procfs', which is the sentence the bug violates. test fn RED_procfs_sources_are_inadmissible_on_kernels_without_procfs() -> Bool { all( @@ -199,7 +264,13 @@ test fn each_kernel_selects_a_source_admissible_on_itself() -> Bool { ) } -data refusal_is_not_a_number_note: String = "THE REFUSAL WITNESS, and it is the one that pins the operator ruling rather than restating it. HostBudgetUnreadable must yield NO bytes — not a ceiling, not a floor, not a zero. Each of those is a number a consumer would happily admit against, and the ceiling in particular is what cli_run's unwrap_or produced and what OOM-killed this corpus twice on the developer's machine. Asserting the absence of a value is the only form of this claim that a permissive default cannot satisfy: a fallback that returned ANY number would red this row, which is precisely the discrimination the previous shape could not express." +// THE REFUSAL WITNESS, and it is the one that pins the operator ruling rather than restating it. +// HostBudgetUnreadable must yield NO bytes — not a ceiling, not a floor, not a zero. Each of those +// is a number a consumer would happily admit against, and the ceiling in particular is what +// cli_run's unwrap_or produced and what OOM-killed this corpus twice on the developer's machine. +// Asserting the absence of a value is the only form of this claim that a permissive default cannot +// satisfy: a fallback that returned ANY number would red this row, which is precisely the +// discrimination the previous shape could not express. test fn RED_unreadable_budget_yields_no_number_at_all() -> Bool { all( @@ -221,7 +292,10 @@ test fn a_resolved_budget_does_yield_its_bytes() -> Bool { } } -data label_carries_no_unread_path_note: String = "The label is the surface a human actually reads, so the wall has to hold there too and not only on the discriminant. This asserts the unavailable arm's rendering never claims a /proc path — the exact text `/proc/meminfo MemTotal` is what ships today on a machine with no /proc, and a typed source whose label still said that would have fixed nothing a reader can see." +// The label is the surface a human actually reads, so the wall has to hold there too and not only +// on the discriminant. This asserts the unavailable arm's rendering never claims a /proc path — the +// exact text `/proc/meminfo MemTotal` is what ships today on a machine with no /proc, and a typed +// source whose label still said that would have fixed nothing a reader can see. test fn no_selected_source_label_claims_a_path_its_kernel_lacks() -> Bool { all( @@ -245,7 +319,12 @@ test fn procfs_reading_labels_do_name_their_path() -> Bool { && string_contains(s: host_budget_source_label(s: BudgetSourceEnvOverride) as String, pattern: "GUNBC_MEMORY_BUDGET_BYTES") } -data unreadable_reason_names_the_remedy_note: String = "The refusal above proves the resolution carries no NUMBER; this proves it carries the two things a stopped operator needs, because a line-stop that does not say how to restart the line is a stop nobody can analyze (DESIGN section 5, the factory model). The reason must name what was unreadable — the cgroup limit files — and the env var that supplies the bound. On the BuildBuddy runner that motivated this change those are the only two facts that separate a rc=137 with no output from a run that completes." +// The refusal above proves the resolution carries no NUMBER; this proves it carries the two things +// a stopped operator needs, because a line-stop that does not say how to restart the line is a stop +// nobody can analyze (DESIGN section 5, the factory model). The reason must name what was +// unreadable — the cgroup limit files — and the env var that supplies the bound. On the BuildBuddy +// runner that motivated this change those are the only two facts that separate a rc=137 with no +// output from a run that completes. test fn the_unreadable_reason_names_both_the_missing_bound_and_the_remedy() -> Bool { all( diff --git a/dag/test/claim/host/host_build_cache_provision_design_witness_test.dag b/dag/test/claim/host/host_build_cache_provision_design_witness_test.dag index 1c6c08d5f54..a7556bad049 100644 --- a/dag/test/claim/host/host_build_cache_provision_design_witness_test.dag +++ b/dag/test/claim/host/host_build_cache_provision_design_witness_test.dag @@ -248,7 +248,19 @@ test fn design_witness_install_is_cited_not_package_manager() -> Bool { build_cache_install_is_cited_not_package_manager() } -data build_cache_unit_construction_checks_superseded_note: String = "The unit-body-specific construction checks formerly here (execstart-matches-install-path, foreground-supervised, daemon-runs-until-stopped, plus the RED-control unit_self_exiting_sketch fixture reproducing #7206's self-exiting unit) are DROPPED, not relocated, per the A5 grain swap (ProvisionBuildCache -> EnsureBuildCacheInstance): they asserted properties of gunbc.host_build_cache_provision_script's hand-rolled build_cache_systemd_user_unit_body, which no longer exists. The same properties are now independently regression-tested against the real render, gunbc.build_cache_unit render_build_cache_unit, in test.claim.build_cache_ensure (witness_the_rendered_unit_is_foreground_supervised, witness_the_generated_unit_reproduces_the_captured_environment) — asserted against a live srv1 capture (2026-08-01) rather than a hand-authored sketch, which is a stronger oracle than this file's own string-matching RED control ever was. The incident history (#7206, srv3 2026-07-25, Duration 10min 8.215s status 0) is preserved in gunbc.build_cache_unit's own foreground_supervision_note, not duplicated here a second time." +// The unit-body-specific construction checks formerly here (execstart-matches-install-path, +// foreground-supervised, daemon-runs-until-stopped, plus the RED-control unit_self_exiting_sketch +// fixture reproducing #7206's self-exiting unit) are DROPPED, not relocated, per the A5 grain swap +// (ProvisionBuildCache -> EnsureBuildCacheInstance): they asserted properties of +// gunbc.host_build_cache_provision_script's hand-rolled build_cache_systemd_user_unit_body, which +// no longer exists. The same properties are now independently regression-tested against the real +// render, gunbc.build_cache_unit render_build_cache_unit, in test.claim.build_cache_ensure +// (witness_the_rendered_unit_is_foreground_supervised, +// witness_the_generated_unit_reproduces_the_captured_environment) — asserted against a live srv1 +// capture (2026-08-01) rather than a hand-authored sketch, which is a stronger oracle than this +// file's own string-matching RED control ever was. The incident history (#7206, srv3 2026-07-25, +// Duration 10min 8.215s status 0) is preserved in gunbc.build_cache_unit's own +// foreground_supervision_note, not duplicated here a second time. fn unsupervised_observation_fixture() -> BuildCacheDaemonObservation { DaemonUnsupervised { unit: "sccache.service", unit_state: "inactive (dead)" } diff --git a/dag/test/claim/host/host_compile_pool_test.dag b/dag/test/claim/host/host_compile_pool_test.dag index aec2ea02229..97ef630f147 100644 --- a/dag/test/claim/host/host_compile_pool_test.dag +++ b/dag/test/claim/host/host_compile_pool_test.dag @@ -2,7 +2,11 @@ module test.claim.host_compile_pool data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data compile_pool_producer_doc: String = "THE DERIVATION'S ACCEPTANCE SET. The load-bearing witness is the first one: against the fleet's ACTUAL declared topology, the derivation refuses on every host, which is the correct answer today and the one a hand-written all-true receipt would have silently contradicted. The rest assert that each not-ready reason is reachable and distinct, because five reasons that cannot be told apart are one reason with five names." +// THE DERIVATION'S ACCEPTANCE SET. The load-bearing witness is the first one: against the fleet's +// ACTUAL declared topology, the derivation refuses on every host, which is the correct answer today +// and the one a hand-written all-true receipt would have silently contradicted. The rest assert +// that each not-ready reason is reachable and distinct, because five reasons that cannot be told +// apart are one reason with five names. fn observed_slice(name: String) -> CompilePoolObservation { CompilePoolSliceObserved { @@ -89,7 +93,13 @@ test fn witness_a_differently_named_slice_is_not_the_intended_pool() -> Bool { ) == false } -data not_declared_versus_absent_doc: String = "The two reasons whose collapse this asserts against. Both are not-ready and both would project to the same pair of Bools if pool_declared did not distinguish them, so the receipt carries the distinction: an undeclared topology yields pool_declared false, while a declared topology whose host lacks the slice yields pool_declared TRUE with pool_observed false. Their remedies differ — one is a fleet-wide topology change that must shrink runner_pool in the same motion, the other is provisioning one host — so a reader that could not tell them apart would treat a fleet decision as a per-host chore." +// The two reasons whose collapse this asserts against. Both are not-ready and both would project to +// the same pair of Bools if pool_declared did not distinguish them, so the receipt carries the +// distinction: an undeclared topology yields pool_declared false, while a declared topology whose +// host lacks the slice yields pool_declared TRUE with pool_observed false. Their remedies differ — +// one is a fleet-wide topology change that must shrink runner_pool in the same motion, the other is +// provisioning one host — so a reader that could not tell them apart would treat a fleet decision +// as a per-host chore. test fn witness_undeclared_and_unprovisioned_are_distinguishable_in_the_receipt() -> Bool { let undeclared = compile_pool_ready_receipt( @@ -116,7 +126,14 @@ test fn witness_undeclared_and_unprovisioned_are_distinguishable_in_the_receipt( && (unprovisioned.pool_observed == false) } -data undersized_slice_doc: String = "The control review 46655 forced. The previous observed_slice fixture carried all-zero limits and witness_a_declared_and_observed_slice_is_ready passed anyway, because the derivation discarded the observed ceilings and reported the JOBSERVER-derived size as though it had been checked against the host. So the acceptance set was certifying the hole rather than catching it. The fixture now carries a ceiling that can hold the derived size, and this witness pins the case it used to admit: a slice observed strictly below the required pool refuses. Both halves are needed -- without the positive fixture the derivation could refuse everything and still pass, and without this one it could admit everything." +// The control review 46655 forced. The previous observed_slice fixture carried all-zero limits and +// witness_a_declared_and_observed_slice_is_ready passed anyway, because the derivation discarded +// the observed ceilings and reported the JOBSERVER-derived size as though it had been checked +// against the host. So the acceptance set was certifying the hole rather than catching it. The +// fixture now carries a ceiling that can hold the derived size, and this witness pins the case it +// used to admit: a slice observed strictly below the required pool refuses. Both halves are needed +// -- without the positive fixture the derivation could refuse everything and still pass, and +// without this one it could admit everything. test fn witness_a_slice_below_the_derived_size_is_not_ready() -> Bool { readiness_for( diff --git a/dag/test/claim/host/host_disk_reclaim_units_witness_test.dag b/dag/test/claim/host/host_disk_reclaim_units_witness_test.dag index 7cfb11a8581..09a71201fec 100644 --- a/dag/test/claim/host/host_disk_reclaim_units_witness_test.dag +++ b/dag/test/claim/host/host_disk_reclaim_units_witness_test.dag @@ -14,9 +14,9 @@ import extdeps.systemd.unit_file { } // THE THREE RESOURCE DIRECTIVES ARE WHY THE EXTDEPS COPRODUCT WAS EXTENDED, SO THEY ARE WITNESSED -// TOGETHER. Before the extension a rendered unit could carry none of them, and the failure was -// invisible in the output: the unit still parsed, still ran, and simply contended with live CI for -// CPU and disk. This asserts the rendered text, which is the only surface systemd reads. +// TOGETHER. Before the extension a rendered unit could carry none of them and the failure was +// invisible: the unit still parsed and ran, and simply contended with live CI for CPU and disk. +// This asserts the rendered text, the only surface systemd reads. test fn the_service_renders_its_resource_discipline() -> Bool { let text = reclaim_service_unit_text() string_contains(s: text, pattern: "Nice=15") @@ -43,10 +43,10 @@ test fn the_derived_timeout_reaches_the_rendered_unit() -> Bool { // // The incumbent unit sources /etc/default/ctrl-runner-reclaim, whose variables include one that // disables the repack outright and one that moves the fragmentation gate. Those gates are data -// rows in gunbc.host_disk_reclaim; a unit that lets a file override them has two authorities for -// one policy and no observation that would reveal which one a host obeys. Re-adding the directive -// is a one-line edit that looks like a fidelity improvement, which is exactly why it needs a -// standing witness rather than only the annotation explaining it. +// rows in gunbc.host_disk_reclaim; a unit letting a file override them has two authorities for +// one policy and no observation revealing which one a host obeys. Re-adding the directive is a +// one-line edit that looks like a fidelity improvement, which is why it needs a standing witness +// rather than only the annotation explaining it. test fn the_service_carries_no_environment_override_hatch() -> Bool { let text = reclaim_service_unit_text() !string_contains(s: text, pattern: "EnvironmentFile") diff --git a/dag/test/claim/host/host_effect_plan_witness_test.dag b/dag/test/claim/host/host_effect_plan_witness_test.dag index 01dbc3ac2c4..275d7b54ef0 100644 --- a/dag/test/claim/host/host_effect_plan_witness_test.dag +++ b/dag/test/claim/host/host_effect_plan_witness_test.dag @@ -26,7 +26,9 @@ import v2.std.live_tree { LiveTreeDisposition, SubstrateInputsOnly } data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data hermetic_witness_home_doc: String = "Hermetic-safe Wave A2 host_effect_plan_apply witnesses: control-flow and empty-plan refusal arms only (no shell.Exec.Run). Shell converge/failure/sequential poles live in host_effect_plan_real_execution_witness_test.dag (Wet bin batch)." +// Hermetic-safe Wave A2 host_effect_plan_apply witnesses: control-flow and empty-plan refusal arms +// only (no shell.Exec.Run). Shell converge/failure/sequential poles live in +// host_effect_plan_real_execution_witness_test.dag (Wet bin batch). fn witness_host_os_target() -> NodeControlPlane { HostOs { node: srv1_host } @@ -73,5 +75,3 @@ test fn witness_control_flow_step_refuses_fail_closed() -> Bool { )) } - - diff --git a/dag/test/claim/host/host_hygiene_liveness_test.dag b/dag/test/claim/host/host_hygiene_liveness_test.dag index b252105cb0a..e3b3b21a6ff 100644 --- a/dag/test/claim/host/host_hygiene_liveness_test.dag +++ b/dag/test/claim/host/host_hygiene_liveness_test.dag @@ -80,7 +80,16 @@ test fn unknown_listener_also_flips_the_fleet_verdict_red() -> Bool { !fleet_green_from_listening(verdicts: verdicts) } -data nrestarts_signal_exclusion_doc: String = "review 40975: the prior test here (nrestarts_style_signal_is_not_consulted_by_the_verdict) only pattern-matched that the fixture was shaped ListeningObserved\{..\} - true by construction of the data declaration two lines above it - and never called slot_listening_verdict, so it could never go red (DESIGN section 5, specification-without-execution). The real guarantee is structural, not testable by a running check: SlotListeningObservation (host_hygiene_liveness.dag) has exactly three variants - ListeningObserved\{unit,age\}, ListeningNeverSeen\{unit\}, ListeningReadInaccessible\{unit,detail\} - none carrying an NRestarts-shaped field, so slot_listening_verdict cannot consult a signal the type does not have. Adding a bogus NRestarts field to the type just to give a test something to assert would be construction-over-validation working in reverse - manufacturing writable state solely to prove a checker catches it." +// review 40975: the prior test here (nrestarts_style_signal_is_not_consulted_by_the_verdict) only +// pattern-matched that the fixture was shaped ListeningObserved{..} - true by construction of the +// data declaration two lines above it - and never called slot_listening_verdict, so it could never +// go red (DESIGN section 5, specification-without-execution). The real guarantee is structural, not +// testable by a running check: SlotListeningObservation (host_hygiene_liveness.dag) has exactly +// three variants - ListeningObserved{unit,age}, ListeningNeverSeen{unit}, +// ListeningReadInaccessible{unit,detail} - none carrying an NRestarts-shaped field, so +// slot_listening_verdict cannot consult a signal the type does not have. Adding a bogus NRestarts +// field to the type just to give a test something to assert would be construction-over-validation +// working in reverse - manufacturing writable state solely to prove a checker catches it. test fn ground_fleet_listening_converges_when_all_fresh() -> Bool { let verdicts = [ diff --git a/dag/test/claim/host/host_network_diagnosis_witness_test.dag b/dag/test/claim/host/host_network_diagnosis_witness_test.dag index 21e42000cbd..f223f7e4591 100644 --- a/dag/test/claim/host/host_network_diagnosis_witness_test.dag +++ b/dag/test/claim/host/host_network_diagnosis_witness_test.dag @@ -2,7 +2,12 @@ module test.claim.host_network_diagnosis data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data witness_srv4_hinge_note: String = "THE conjunct, and it is the srv4 outage of 2026-07-25 replayed on the readings taken live from the host. cloud-init disabled by the Ubuntu live installer, netplan present and correct, interface administratively up with no carrier. The fold must blame the PHYSICAL layer and name the interface and MAC an engineer needs in order to look at the right cable — and it must NOT blame configuration, which is the answer that was actually given at the time and that sent the diagnosis down a false path." +// THE conjunct, and it is the srv4 outage of 2026-07-25 replayed on the readings taken live from +// the host. cloud-init disabled by the Ubuntu live installer, netplan present and correct, +// interface administratively up with no carrier. The fold must blame the PHYSICAL layer and name +// the interface and MAC an engineer needs in order to look at the right cable — and it must NOT +// blame configuration, which is the answer that was actually given at the time and that sent the +// diagnosis down a false path. fn witness_srv4_diagnoses_physical_not_config() -> Bool { let d = diagnose_host_network( @@ -109,7 +114,16 @@ fn witness_persistence_bar_discriminates() -> Bool { && !diagnosis_is_reboot_stable(config: Present { value: srv4_netplan_config }, observed: srv4_lan_interface) } -data witness_axis_cell_note: String = "The axis conjunct: the fold is reachable as a per-host status cell, and the cell REFUSES rather than guessing while no producer exists. Every enrolled host answers UnknownRefused, and the frontier is asserted as the SET of those hosts rather than as a tally — a deficit that is named, and therefore rankable and diffable, instead of one whose frequency is zero by construction. The set is joined against the enrolled host list rather than a literal, so enrolling a host moves it without editing this witness, and a producer landing removes a NAMED host instead of decrementing a number. The last two conjuncts are the non-vacuity: the verdict projection is not constant — a healthy observation reaches Converged and a dead link reaches Drifted through the same projection the cell uses — so the all-UnknownRefused tally above is the producer's absence and not a fold that answers UnknownRefused to everything." +// The axis conjunct: the fold is reachable as a per-host status cell, and the cell REFUSES rather +// than guessing while no producer exists. Every enrolled host answers UnknownRefused, and the +// frontier is asserted as the SET of those hosts rather than as a tally — a deficit that is named, +// and therefore rankable and diffable, instead of one whose frequency is zero by construction. The +// set is joined against the enrolled host list rather than a literal, so enrolling a host moves it +// without editing this witness, and a producer landing removes a NAMED host instead of decrementing +// a number. The last two conjuncts are the non-vacuity: the verdict projection is not constant — a +// healthy observation reaches Converged and a dead link reaches Drifted through the same projection +// the cell uses — so the all-UnknownRefused tally above is the producer's absence and not a fold +// that answers UnknownRefused to everything. // The frontier is asserted as a SET OF NAMED HOSTS rather than a count (DESIGN section 5: // completeness is an identity join, not a count equality). The count this replaces could say six diff --git a/dag/test/claim/host/host_phase_status_witness_test.dag b/dag/test/claim/host/host_phase_status_witness_test.dag index 0e284a9fd6c..53a4e3e81c6 100644 --- a/dag/test/claim/host/host_phase_status_witness_test.dag +++ b/dag/test/claim/host/host_phase_status_witness_test.dag @@ -31,7 +31,12 @@ fn cell_fixture( } } -data witness_no_producer_is_unknown_note: String = "THE fail-closed conjunct. A phase with no live observation producer must derive UnknownRefused — the arm that says 'we have no way to ask this host'. If it ever derives Converged, the status matrix reports a subsumption that was never observed, and every count built on it (remaining work, coverage) silently becomes fiction. This is the same defect class as a stats probe that auto-starts the server it is measuring (#7213 Finding 2): evidence manufactured by the act of looking." +// THE fail-closed conjunct. A phase with no live observation producer must derive UnknownRefused — +// the arm that says 'we have no way to ask this host'. If it ever derives Converged, the status +// matrix reports a subsumption that was never observed, and every count built on it (remaining +// work, coverage) silently becomes fiction. This is the same defect class as a stats probe that +// auto-starts the server it is measuring (#7213 Finding 2): evidence manufactured by the act of +// looking. test fn witness_no_producer_derives_unknown_not_converged() -> Bool { match host_phase_verdict_from(observation: none) { @@ -44,7 +49,15 @@ test fn witness_no_producer_derives_unknown_not_converged() -> Bool { } } -data witness_orthogonality_note: String = "The two axes must stay independent, and this is the conjunct that CAUGHT them being fused. The cell type was first written as a sum (StatusUnmodeled | StatusObserved), so a DeclaredGap phase discarded its observation — and the one cell CARRYING AN OBSERVATION today, (srv3, prefix:os-install-actuated), is a DeclaredGap phase, so coverage computed as zero with a real Converged verdict one branch away. Four combinations must all be representable and distinct: modeled+converged (done), modeled+inaccessible (srv1/srv2 build-cache — a finished model the host refuses to answer for), unmodeled+unknown (ordinary remaining work), and unmodeled+converged (the host is in the desired condition by means the model cannot reproduce — srv3's OS install). A fused enum has to round the middle two to something false." +// The two axes must stay independent, and this is the conjunct that CAUGHT them being fused. The +// cell type was first written as a sum (StatusUnmodeled | StatusObserved), so a DeclaredGap phase +// discarded its observation — and the one cell CARRYING AN OBSERVATION today, (srv3, +// prefix:os-install-actuated), is a DeclaredGap phase, so coverage computed as zero with a real +// Converged verdict one branch away. Four combinations must all be representable and distinct: +// modeled+converged (done), modeled+inaccessible (srv1/srv2 build-cache — a finished model the host +// refuses to answer for), unmodeled+unknown (ordinary remaining work), and unmodeled+converged (the +// host is in the desired condition by means the model cannot reproduce — srv3's OS install). A +// fused enum has to round the middle two to something false. test fn witness_modeled_and_observed_axes_are_independent() -> Bool { let modeled_inaccessible = cell_fixture( @@ -73,7 +86,11 @@ test fn witness_modeled_and_observed_axes_are_independent() -> Bool { && !host_phase_cell_has_live_producer(c: unmodeled_unknown) } -data witness_producer_refusal_is_coverage_note: String = "A producer that RAN and honestly refused is coverage; no producer at all is not. The distinction is load-bearing because the two have different owners — a refusing producer is a reach or observation defect to fix, an absent producer is a model to build — and the first version of this module conflated them by reading coverage off the verdict instead of off the observation's presence." +// A producer that RAN and honestly refused is coverage; no producer at all is not. The distinction +// is load-bearing because the two have different owners — a refusing producer is a reach or +// observation defect to fix, an absent producer is a model to build — and the first version of this +// module conflated them by reading coverage off the verdict instead of off the observation's +// presence. test fn witness_refusing_producer_still_counts_as_coverage() -> Bool { let refused = cell_fixture( @@ -95,7 +112,13 @@ test fn witness_unreachable_and_unknown_stay_distinct() -> Bool { && observation_verdict_eq(a: std.upsert_decision.Inaccessible, b: std.upsert_decision.Inaccessible) } -data witness_widen_red_control_note: String = "The discriminating RED control, built on the PATH-shadow / DaemonUnsupervised precedent: the forbidden absorbing fallback is modeled as its own sketch (host_phase_verdict_absorbing_fallback_widen_sketch fabricates Converged when no observation exists), the gate REJECTS the sketch's output, and the authority's output PASSES the same gate. The perturbation is independent of the property checked, so this cannot pass tautologically — an authority that quietly acquired the widen arm would be rejected by the gate it currently satisfies." +// The discriminating RED control, built on the PATH-shadow / DaemonUnsupervised precedent: the +// forbidden absorbing fallback is modeled as its own sketch +// (host_phase_verdict_absorbing_fallback_widen_sketch fabricates Converged when no observation +// exists), the gate REJECTS the sketch's output, and the authority's output PASSES the same gate. +// The perturbation is independent of the property checked, so this cannot pass tautologically — an +// authority that quietly acquired the widen arm would be rejected by the gate it currently +// satisfies. test fn witness_red_control_widen_on_absent_rejected_by_gate() -> Bool { let widened = host_phase_verdict_absorbing_fallback_widen_sketch(observation: none) @@ -107,7 +130,12 @@ test fn witness_red_control_widen_on_absent_rejected_by_gate() -> Bool { data departed_host_fixture: HostIdentity = "srv-departed" as HostIdentity -data witness_reconcile_non_vacuous_note: String = "The membership instantiation must be exercised on a NON-DEGENERATE diff, or it is an instantiation nobody has tested. The live fleet produces only Modified and Unchanged hunks today (no host has left), so the Removed arm — a cell observed for a host absent from fleet_intent — is supplied synthetically here. All three outcomes are asserted in one reconcile: a departed host's cell tears down (cells are Owned, so R5 permits it rather than refusing), an unconverged cell upserts, and a cell already at the desired state produces no hunk at all." +// The membership instantiation must be exercised on a NON-DEGENERATE diff, or it is an +// instantiation nobody has tested. The live fleet produces only Modified and Unchanged hunks today +// (no host has left), so the Removed arm — a cell observed for a host absent from fleet_intent — is +// supplied synthetically here. All three outcomes are asserted in one reconcile: a departed host's +// cell tears down (cells are Owned, so R5 permits it rather than refusing), an unconverged cell +// upserts, and a cell already at the desired state produces no hunk at all. test fn witness_reconcile_covers_upsert_teardown_and_noop() -> Bool { let at_desired = cell_fixture( @@ -140,7 +168,19 @@ test fn witness_reconcile_covers_upsert_teardown_and_noop() -> Bool { && membership_refusal_count(plan: plan) == 0 } -data witness_matrix_shape_note: String = "Shape assertions over the derived matrix, pinned to the spine and the enrolled fleet rather than to hand-copied numbers: the matrix is an exact identity join over (host x the obligations that host's participation selects), duplicate-free and covering exactly the enrolled roster, so it cannot silently drop a phase or a host — nor hand a host an obligation its participation does not own, which the former rectangle count could not see. The coverage count is the frontier's CURRENT measure, and it is not yet an honest one — corrected 2026-08-09 in the same change that landed witness_covered_cell_verdict_is_selected_by_authorship_alone below. Exactly one cell carries an observation today, (srv3, prefix:os-install-actuated), and that observation is AUTHORED rather than execution-backed: it derives from srv3_post_install_lease_table_fixture, and no effect in the tree produces a DhcpLeaseTableObservation. So the count reads one where the executed population is zero, and raising it is what items 2 and 3 of the lane exist to do. Pinning it means adding a producer is a VISIBLE, counted event that must update this witness, never a silent improvement nobody can point at." +// Shape assertions over the derived matrix, pinned to the spine and the enrolled fleet rather than +// to hand-copied numbers: the matrix is an exact identity join over (host x the obligations that +// host's participation selects), duplicate-free and covering exactly the enrolled roster, so it +// cannot silently drop a phase or a host — nor hand a host an obligation its participation does not +// own, which the former rectangle count could not see. The coverage count is the frontier's CURRENT +// measure, and it is not yet an honest one — corrected 2026-08-09 in the same change that landed +// witness_covered_cell_verdict_is_selected_by_authorship_alone below. Exactly one cell carries an +// observation today, (srv3, prefix:os-install-actuated), and that observation is AUTHORED rather +// than execution-backed: it derives from srv3_post_install_lease_table_fixture, and no effect in +// the tree produces a DhcpLeaseTableObservation. So the count reads one where the executed +// population is zero, and raising it is what items 2 and 3 of the lane exist to do. Pinning it +// means adding a producer is a VISIBLE, counted event that must update this witness, never a silent +// improvement nobody can point at. // An exact identity join, not a product. Every enrollment contributes exactly the obligations its // own participation selects — program_step_count over assimilation_program_for — so a host whose @@ -184,7 +224,11 @@ test fn witness_unmodeled_cells_track_spine_gaps() -> Bool { host_phase_unmodeled_count(enrollments: fleet_subsumption_enrollments) == gap_cells.length() } -data witness_remaining_work_note: String = "Remaining work is the reconcile's own upsert count, and it must equal every cell that is not already at the FULL desired state — modeled AND converged. Asserting it against an independently computed count is what stops the reconcile from silently retiring cells: if desired ever weakened to 'converged, disposition ignored', srv3's installed-but-unmodeled OS cell would drop out of the count and the lane would look one item closer to done than it is." +// Remaining work is the reconcile's own upsert count, and it must equal every cell that is not +// already at the FULL desired state — modeled AND converged. Asserting it against an independently +// computed count is what stops the reconcile from silently retiring cells: if desired ever weakened +// to 'converged, disposition ignored', srv3's installed-but-unmodeled OS cell would drop out of the +// count and the lane would look one item closer to done than it is. test fn witness_remaining_work_counts_every_unfinished_cell() -> Bool { let remaining = host_phase_remaining_work_count(enrollments: fleet_subsumption_enrollments) @@ -193,8 +237,12 @@ test fn witness_remaining_work_counts_every_unfinished_cell() -> Bool { remaining == total - finished } - -data witness_program_scoping_note: String = "HOST-0 acceptance. The refactor's whole risk is that program scoping quietly CHANGES the runner fleet while looking tidy, so the identity conjunct is asserted rather than argued: a CI-participation enrollment must select the entire spine, because every phase authored to date exists to serve runner hosts. The complementary conjunct is the one the refactor exists for -- an inference enrollment must not carry a single runner or BMC obligation. Both are needed: the first alone would pass a no-op, the second alone would pass a refactor that broke srv1 through srv4." +// HOST-0 acceptance. The refactor's whole risk is that program scoping quietly CHANGES the runner +// fleet while looking tidy, so the identity conjunct is asserted rather than argued: a +// CI-participation enrollment must select the entire spine, because every phase authored to date +// exists to serve runner hosts. The complementary conjunct is the one the refactor exists for -- an +// inference enrollment must not carry a single runner or BMC obligation. Both are needed: the first +// alone would pass a no-op, the second alone would pass a refactor that broke srv1 through srv4. data synthetic_inference_enrollment: HostEnrollmentIntent = HostEnrollmentIntent { host: operator_host_srv3, @@ -241,7 +289,13 @@ data synthetic_duplicated_enrollment: HostEnrollmentIntent = HostEnrollmentInten participation: [CiRunnerParticipation, CiRunnerParticipation, InferenceServingParticipation], } -data witness_participation_set_semantics_note: String = "Participation is a set wearing a list's carrier, so the three enrollments below must be one program under BOTH readings -- the steps they select and the identity they derive. Selection was already order-blind and duplicate-blind because step_serves_any asks only whether SOME participation claims a step; identity was not, and joined whatever the caller happened to write. These conjuncts are the discriminating controls for that repair: each one reds against the pre-repair identity derivation, which is what distinguishes a real construction wall from a canonicalization function nobody calls." +// Participation is a set wearing a list's carrier, so the three enrollments below must be one +// program under BOTH readings -- the steps they select and the identity they derive. Selection was +// already order-blind and duplicate-blind because step_serves_any asks only whether SOME +// participation claims a step; identity was not, and joined whatever the caller happened to write. +// These conjuncts are the discriminating controls for that repair: each one reds against the +// pre-repair identity derivation, which is what distinguishes a real construction wall from a +// canonicalization function nobody calls. test fn witness_participation_order_does_not_change_program_identity() -> Bool { let forward = assimilation_program_for(intent: synthetic_forward_order_enrollment) @@ -266,7 +320,15 @@ test fn witness_distinct_participation_changes_identity_and_obligations() -> Boo && program_step_count(program: inference) < program_step_count(program: ci) } -data witness_identity_is_exactly_canonical_note: String = "The DISCRIMINATING control, and the reason the three conjuncts above are not satisfied by any function that merely returns a constant. It pins the derived identity to an independently authored literal rather than to another projection of the same computation, and the literal is what the canonical roster REQUIRES it to be, not what the current code was measured to emit. Pre-repair, the duplicated enrollment joined its raw list and derived 'ci-runner+ci-runner+inference-serving'; this conjunct asserts that exact string is NOT the identity while the canonical two-label form IS. So it reds against the derivation this change replaced, which is what makes the repair a wall rather than a canonicalization helper sitting beside a still-writable path." +// The DISCRIMINATING control, and the reason the three conjuncts above are not satisfied by any +// function that merely returns a constant. It pins the derived identity to an independently +// authored literal rather than to another projection of the same computation, and the literal is +// what the canonical roster REQUIRES it to be, not what the current code was measured to emit. +// Pre-repair, the duplicated enrollment joined its raw list and derived +// 'ci-runner+ci-runner+inference-serving'; this conjunct asserts that exact string is NOT the +// identity while the canonical two-label form IS. So it reds against the derivation this change +// replaced, which is what makes the repair a wall rather than a canonicalization helper sitting +// beside a still-writable path. test fn witness_program_identity_is_exactly_the_canonical_projection() -> Bool { let duplicated = assimilation_program_for(intent: synthetic_duplicated_enrollment) @@ -410,7 +472,21 @@ test fn witness_runner_only_obligations_exist_on_runner_hosts() -> Bool { runner_only.length() > 0 && on_sparks.length() == 0 } -data witness_authored_observation_note: String = "THE SIBLING OF THE NOTE ABOVE, and the one the frontier does not yet catch. That note forbids evidence manufactured by the ACT OF LOOKING; this pair catches evidence manufactured by AUTHORING. host_phase_observation_coverage_count is designated by the frontier note as the number that measures the observation debt, and it counts a cell as covered exactly when host_phase_cell_has_live_producer holds -- which tests only that the observation is Present, never that anything executed to produce it. The single Present cell today, (srv3, prefix:os-install-actuated), derives its Converged verdict from srv3_post_install_lease_table_fixture, a data constant in gunbc.network_identity_subsumption whose one dynamic row carries the placeholder MAC 00:00:00:00:00:00. So the metric that measures the debt currently overstates coverage by its entire population. The frontier note states the rule this violates in its own words -- 'a cell earns a row here when an effect produces its verdict by execution' -- which is why the defect is worth an executing control rather than a correction in prose: the rule was already written down and was not enforceable, and no lens or witness would have reddened if a second host were wired in the same way. That is the exact move Spark collector-fact enrollment would have made for srv5 and srv6, which is how this was found." +// THE SIBLING OF THE NOTE ABOVE, and the one the frontier does not yet catch. That note forbids +// evidence manufactured by the ACT OF LOOKING; this pair catches evidence manufactured by +// AUTHORING. host_phase_observation_coverage_count is designated by the frontier note as the number +// that measures the observation debt, and it counts a cell as covered exactly when +// host_phase_cell_has_live_producer holds -- which tests only that the observation is Present, +// never that anything executed to produce it. The single Present cell today, (srv3, +// prefix:os-install-actuated), derives its Converged verdict from +// srv3_post_install_lease_table_fixture, a data constant in gunbc.network_identity_subsumption +// whose one dynamic row carries the placeholder MAC 00:00:00:00:00:00. So the metric that measures +// the debt currently overstates coverage by its entire population. The frontier note states the +// rule this violates in its own words -- 'a cell earns a row here when an effect produces its +// verdict by execution' -- which is why the defect is worth an executing control rather than a +// correction in prose: the rule was already written down and was not enforceable, and no lens or +// witness would have reddened if a second host were wired in the same way. That is the exact move +// Spark collector-fact enrollment would have made for srv5 and srv6, which is how this was found. // THE DISCRIMINATING CONTROL. Both lease tables are authored data constants, and the verdict is a // pure function of WHICH ONE is wired into the frontier: the pre-install table (BMC row only) diff --git a/dag/test/claim/host/host_run_boundary_admission_witness_test.dag b/dag/test/claim/host/host_run_boundary_admission_witness_test.dag index 0175fd9c865..8ea59b46f99 100644 --- a/dag/test/claim/host/host_run_boundary_admission_witness_test.dag +++ b/dag/test/claim/host/host_run_boundary_admission_witness_test.dag @@ -15,7 +15,16 @@ import v2.compiler.host_run_boundary_admission { host_run_boundary_is_admitted, } -data host_run_boundary_admission_witness_note: String = "Discriminating witnesses for the hermetic-native host-run network-boundary precondition (v2.compiler.host_run_boundary_admission). The admit path EXISTS and is reachable -- a boundary that closes the UriTree layer at LifecycleByConstruction (as a netns/container handler would) is HostRunBoundaryAdmitted (the GREEN control). The in-container reality is the RED: the always-available Simulated handler closes UriTree only at LifecycleByConvention (offline flag, not a kernel wall), so it is HostRunBoundaryUnderConstructed -- REFUSED for a native run, never laundered into Admitted (operator Option 1 fail-closed 2026-07-20); if grade_is_construction accepted convention, admits_construction_only would flip. A boundary that does not cover the network layer at all is HostRunBoundaryRefused naming UriTree -- located, distinct from the under-constructed state (DESIGN 5: three states, not a conflated 2-valued pass/fail)." +// Discriminating witnesses for the hermetic-native host-run network-boundary precondition +// (v2.compiler.host_run_boundary_admission). The admit path EXISTS and is reachable -- a boundary +// that closes the UriTree layer at LifecycleByConstruction (as a netns/container handler would) is +// HostRunBoundaryAdmitted (the GREEN control). The in-container reality is the RED: the +// always-available Simulated handler closes UriTree only at LifecycleByConvention (offline flag, +// not a kernel wall), so it is HostRunBoundaryUnderConstructed -- REFUSED for a native run, never +// laundered into Admitted (operator Option 1 fail-closed 2026-07-20); if grade_is_construction +// accepted convention, admits_construction_only would flip. A boundary that does not cover the +// network layer at all is HostRunBoundaryRefused naming UriTree -- located, distinct from the +// under-constructed state (DESIGN 5: three states, not a conflated 2-valued pass/fail). fn construction_network_boundary() -> BoundaryMaterialization { BoundaryMaterialization { diff --git a/dag/test/claim/host/host_swap_backing_witness_test.dag b/dag/test/claim/host/host_swap_backing_witness_test.dag index 15fe6190ffd..9f590e4089a 100644 --- a/dag/test/claim/host/host_swap_backing_witness_test.dag +++ b/dag/test/claim/host/host_swap_backing_witness_test.dag @@ -10,7 +10,11 @@ fn stats_fixture(total_bytes: Int) -> SwapStats { } } -data witness_requirement_derivation_note: String = "The requirement must come from the DECLARED cap, not from a number typed into this witness, or the module is asserting its own invention. So the assertion is a relationship: the derived min_total equals gunbc_runner_slot_desired().memory_swap_max exactly, which means editing that one declaration moves the requirement and this witness together, and a hand-written swap size anywhere would break it." +// The requirement must come from the DECLARED cap, not from a number typed into this witness, or +// the module is asserting its own invention. So the assertion is a relationship: the derived +// min_total equals gunbc_runner_slot_desired().memory_swap_max exactly, which means editing that +// one declaration moves the requirement and this witness together, and a hand-written swap size +// anywhere would break it. test fn witness_requirement_is_derived_from_the_declared_cap() -> Bool { match host_swap_backing_requirement() { diff --git a/dag/test/claim/host/host_toolchain_components_witness_test.dag b/dag/test/claim/host/host_toolchain_components_witness_test.dag index f03168204ce..b1ec223fb67 100644 --- a/dag/test/claim/host/host_toolchain_components_witness_test.dag +++ b/dag/test/claim/host/host_toolchain_components_witness_test.dag @@ -2,7 +2,13 @@ module test.claim.host_toolchain_components data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data witness_incident_hinge_note: String = "THE conjunct this module exists for, and it is the srv2 floor failure replayed on the toolchain state read live from the host. The pinned toolchain 1.93.0 carried rustfmt the entire time, so any check keyed on 'does this host have rustfmt' answered yes throughout. The toolchain the shim actually resolved — ghrunner's default, stable — did not, and the gate failed every run. The verdict on the resolving toolchain must be Absent, and the presence of rustfmt in the OTHER toolchain must not soften it: under that state the gate fails every time, so it is not a partial success." +// THE conjunct this module exists for, and it is the srv2 floor failure replayed on the toolchain +// state read live from the host. The pinned toolchain 1.93.0 carried rustfmt the entire time, so +// any check keyed on 'does this host have rustfmt' answered yes throughout. The toolchain the shim +// actually resolved — ghrunner's default, stable — did not, and the gate failed every run. The +// verdict on the resolving toolchain must be Absent, and the presence of rustfmt in the OTHER +// toolchain must not soften it: under that state the gate fails every time, so it is not a partial +// success. test fn witness_component_in_another_toolchain_does_not_satisfy() -> Bool { let resolved_missing = toolchain_completeness_verdict( @@ -18,7 +24,9 @@ test fn witness_component_in_another_toolchain_does_not_satisfy() -> Bool { && !resolved_toolchain_has(t: srv2_ghrunner_toolchain_before_fix, c: Rustfmt) } -data witness_fix_note: String = "The other direction, and the receipt for the operator-directed hand-install: the same principal and the same toolchain, with rustfmt added, converges. Without this the module would satisfy every other conjunct while being a verdict that never says yes." +// The other direction, and the receipt for the operator-directed hand-install: the same principal +// and the same toolchain, with rustfmt added, converges. Without this the module would satisfy +// every other conjunct while being a verdict that never says yes. test fn witness_after_fix_converges() -> Bool { observation_verdict_eq( @@ -34,7 +42,12 @@ test fn witness_after_fix_converges() -> Bool { ) } -data witness_no_probe_note: String = "No probe, no verdict. srv1, srv3 and srv4 have no toolchain reading — srv1 refuses every credential this session holds, and no component-listing producer runs anywhere in the tree — so their verdict is UnknownRefused and the module does not invent one. The frontier is asserted as the SET of hosts without a reading, joined against the enrolled population by identity, so landing a probe or fabricating a fixture to make the matrix look greener both show up as a NAMED host leaving that set rather than as a number moving." +// No probe, no verdict. srv1, srv3 and srv4 have no toolchain reading — srv1 refuses every +// credential this session holds, and no component-listing producer runs anywhere in the tree — so +// their verdict is UnknownRefused and the module does not invent one. The frontier is asserted as +// the SET of hosts without a reading, joined against the enrolled population by identity, so +// landing a probe or fabricating a fixture to make the matrix look greener both show up as a NAMED +// host leaving that set rather than as a number moving. // THE FRONTIER IS THE SET OF HOSTS WITHOUT A READING, AND IT NAMES THE ONE THAT HAS ONE. The count // this replaces asserted enrolled-minus-one, which is true and says nothing about WHICH host is the @@ -65,7 +78,9 @@ test fn witness_unobserved_hosts_are_unknown_not_converged() -> Bool { == filter(fleet_subsumption_hosts, h => h != operator_host_srv2) } -data witness_missing_set_note: String = "The refusal must be able to say WHICH component is missing and which gate wanted it, or the remedy is a search. The missing set is computed against the requirement rows, so it carries the DeclarationRef of the gate that required it rather than a bare label." +// The refusal must be able to say WHICH component is missing and which gate wanted it, or the +// remedy is a search. The missing set is computed against the requirement rows, so it carries the +// DeclarationRef of the gate that required it rather than a bare label. test fn witness_missing_set_names_the_requiring_gate() -> Bool { let missing = resolved_toolchain_missing( @@ -110,7 +125,16 @@ test fn witness_component_names_match_rustup() -> Bool { && rustup_component_eq(a: Rustfmt, b: Rustfmt) } -data witness_reachability_note: String = "The correction, pinned so it cannot quietly regress into the fused reading. Installing the component and the gate being able to FIND it are two conditions, and srv2 satisfies the first while the second is unobserved — the runner unit inherits a PATH with no cargo bin directory, and whether the gate's spawn sees that PATH or a login shell's is only answerable from inside a job. So the component cell is Converged, the combined 'will the gate find it' verdict is UnknownRefused, and they are DIFFERENT VALUES on the same host. A module that reported the first as the answer would be committing the error its own opening paragraph describes. The third conjunct is the RED direction: an observed-unreachable component is Absent even when the toolchain is complete, so a complete toolchain can never by itself produce a green combined verdict." +// The correction, pinned so it cannot quietly regress into the fused reading. Installing the +// component and the gate being able to FIND it are two conditions, and srv2 satisfies the first +// while the second is unobserved — the runner unit inherits a PATH with no cargo bin directory, and +// whether the gate's spawn sees that PATH or a login shell's is only answerable from inside a job. +// So the component cell is Converged, the combined 'will the gate find it' verdict is +// UnknownRefused, and they are DIFFERENT VALUES on the same host. A module that reported the first +// as the answer would be committing the error its own opening paragraph describes. The third +// conjunct is the RED direction: an observed-unreachable component is Absent even when the +// toolchain is complete, so a complete toolchain can never by itself produce a green combined +// verdict. test fn witness_completeness_does_not_imply_the_gate_finds_it() -> Bool { let completeness = host_toolchain_completeness_verdict(host: operator_host_srv2) diff --git a/dag/test/claim/http_serve_route_witness_test.dag b/dag/test/claim/http_serve_route_witness_test.dag index 5613a316c7b..539ec7be7be 100644 --- a/dag/test/claim/http_serve_route_witness_test.dag +++ b/dag/test/claim/http_serve_route_witness_test.dag @@ -115,7 +115,14 @@ test fn witness_first_match_wins_on_overlap() -> Bool { selected_dynamic_is(sel: serve_select_route(table: overlap, method: GET, path: "/a/b"), want_dispatch: false) } -data regex_parity_note: String = "The one-grammar-both-directions agreement witness (parent review note 2, 2026-07-20): the BACKWARD reading (emit_path_template_regex_source) is re-ingested by a test-local interpreter of exactly the restricted regex language that emitter produces (anchors ^ $, segments joined by escaped slash, literal segments with JS metachar escapes, param segments as the nonempty [^/]+ class), and both directions are executed over one shared path corpus asserting IDENTICAL accept verdicts per path. If either direction drifts (the emitter changes its segment grammar, or match_path_template changes normalization), this witness reds — the agreement is proven by execution, not by the two functions reading the same-looking rows." +// The one-grammar-both-directions agreement witness (parent review note 2, 2026-07-20): the +// BACKWARD reading (emit_path_template_regex_source) is re-ingested by a test-local interpreter of +// exactly the restricted regex language that emitter produces (anchors ^ $, segments joined by +// escaped slash, literal segments with JS metachar escapes, param segments as the nonempty [^/]+ +// class), and both directions run over one shared path corpus asserting IDENTICAL accept verdicts +// per path. If either drifts (the emitter changes its segment grammar, or match_path_template +// changes normalization) this witness reds — agreement proven by execution, not by two functions +// reading the same-looking rows. fn regex_unescape_literal(s: String) -> String { let s1 = join(split(s: s, delimiter: "\\."), ".") diff --git a/dag/test/claim/import_shadowed_by_local_definition_witness_test.dag b/dag/test/claim/import_shadowed_by_local_definition_witness_test.dag index 341087e93db..3457df9b03b 100644 --- a/dag/test/claim/import_shadowed_by_local_definition_witness_test.dag +++ b/dag/test/claim/import_shadowed_by_local_definition_witness_test.dag @@ -30,7 +30,9 @@ module test.claim.import_shadowed_by_local_definition_witness_test import std.types { Bool, String } -data import_shadow_witness_note: String = "Fixtures shadow a real std symbol because the harness compiles ONE source: a two-module collision is not authorable here, and importing from the live corpus expresses the same collision in one module." +// Fixtures shadow a real std symbol because the harness compiles ONE source: a two-module collision +// is not authorable here, and importing from the live corpus expresses the same collision in one +// module. fn import_shadow_negative_fixture_source() -> String { "module ish.probe\n\nimport std.types { String }\nimport std.algebra { trim }\n\nfn trim(value: String) -> String {\n trim(value)\n}\n" diff --git a/dag/test/claim/instrument_bob_witness_test.dag b/dag/test/claim/instrument_bob_witness_test.dag index b8046a189c7..e6b078e0c56 100644 --- a/dag/test/claim/instrument_bob_witness_test.dag +++ b/dag/test/claim/instrument_bob_witness_test.dag @@ -33,7 +33,10 @@ import gunbc.design.instrument_bob { data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data instrument_bob_witness_note: String = "The three properties that make the bob a modelled behaviour rather than an animation — bounded, settling, inert — each with the control that reds it. The settle claim is the one worth reading closely: it is carried as descent evidence over the advance function, so a retune that made the envelope grow would not merely look wrong, it would fail a claim about termination." +// The three properties that make the bob a modelled behaviour rather than an animation — bounded, +// settling, inert — each with the control that reds it. The settle claim is the one worth reading +// closely: it is carried as descent evidence over the advance function, so a retune that made the +// envelope grow would not merely look wrong, it would fail a claim about termination. fn an_impulse(magnitude: Int) -> PhysicalImpulse { PhysicalImpulse { @@ -48,7 +51,10 @@ fn an_impulse(magnitude: Int) -> PhysicalImpulse { } } -data clamp_is_the_load_bearing_half_note: String = "A hand can deliver an order of magnitude more acceleration than a fingertip. The reference magnitude maps a firm knock onto the full envelope, and everything above it clamps — so a violent smack and an absurd one produce the SAME travel, and the plate cannot be thrown off the screen by a large input. This is the claim that a linear scaling would fail." +// A hand can deliver an order of magnitude more acceleration than a fingertip. The reference +// magnitude maps a firm knock onto the full envelope, and everything above it clamps — so a violent +// smack and an absurd one produce the SAME travel, and the plate cannot be thrown off the screen by +// a large input. This is the claim that a linear scaling would fail. fn witness_a_harder_smack_never_travels_further_than_the_bound() -> Bool { amplitude_for_impulse(magnitude_milli_m_per_s2: impulse_reference_magnitude_milli) == bob_max_travel_px * 1000 @@ -66,7 +72,10 @@ fn witness_a_gentler_knock_travels_proportionally_less() -> Bool { && amplitude_for_impulse(magnitude_milli_m_per_s2: impulse_reference_magnitude_milli / 2) > 0 } -data register_bound_note: String = "The bob's ceiling sits strictly under the register's attraction travel, so instrument character can never move a subject as far as a real response does. Asserted as a relationship between the two authorities rather than as two independent numbers, which is what makes a later retune of either one red rather than silently violating the law." +// The bob's ceiling sits strictly under the register's attraction travel, so instrument character +// can never move a subject as far as a real response does. Asserted as a relationship between the +// two authorities rather than as two independent numbers, which is what makes a later retune of +// either one red rather than silently violating the law. fn witness_the_bob_stays_under_the_registers_attraction_travel() -> Bool { bob_max_travel_px < attraction_travel_max_px @@ -86,7 +95,13 @@ fn witness_red_every_advanced_state_stays_bounded() -> Bool { && bob_is_within_register_bound(s: a3) } -data step_size_independence_note: String = "THE DEFECT THIS CONTROL EXISTS FOR. Decaying by each step's duration made the envelope a function of how a caller chose to advance rather than of elapsed time, and at the production interval — sixteen milliseconds against a one-hundred-and-eighty-millisecond half-life — it decayed by nothing at all. So this asserts the property directly: reaching one instant in many small steps and reaching it in one large step produce the SAME amplitude, and the production interval genuinely reduces it. A model that regressed to per-step decay fails the first conjunct AND the second." +// THE DEFECT THIS CONTROL EXISTS FOR. Decaying by each step's duration made the envelope a function +// of how a caller chose to advance rather than of elapsed time, and at the production interval — +// sixteen milliseconds against a one-hundred-and-eighty-millisecond half-life — it decayed by +// nothing at all. So this asserts the property directly: reaching one instant in many small steps +// and reaching it in one large step produce the SAME amplitude, and the production interval +// genuinely reduces it. A model that regressed to per-step decay fails the first conjunct AND the +// second. fn advance_n(s: BobState, dt_ms: Int, n: Int) -> BobState { if n <= 0 { s } else { advance_n(s: bob_advance(s: s, dt_ms: dt_ms), dt_ms: dt_ms, n: n - 1) } @@ -102,7 +117,10 @@ fn witness_decay_is_independent_of_how_the_caller_steps() -> Bool { && bob_amplitude_milli(s: advance_n(s: hit, dt_ms: 16, n: 60)) == 0 } -data settling_note: String = "The bob always comes to rest, and the claim is carried as descent evidence rather than as a sentence. Advancing a ringing bob past a half-life STRICTLY decreases the envelope; a shorter advance is non-increasing; neither is ever Unknown. A model whose envelope could grow would fail here rather than merely looking wrong on screen." +// The bob always comes to rest, and the claim is carried as descent evidence rather than as a +// sentence. Advancing a ringing bob past a half-life STRICTLY decreases the envelope; a shorter +// advance is non-increasing; neither is ever Unknown. A model whose envelope could grow would fail +// here rather than merely looking wrong on screen. fn witness_the_bob_always_settles_with_strict_descent() -> Bool { let hit = apply_impulse(i: an_impulse(magnitude: impulse_reference_magnitude_milli), m: MotionFull) @@ -123,7 +141,10 @@ fn witness_the_envelope_strictly_decays_and_reaches_rest() -> Bool { && bob_amplitude_milli(s: bob_advance(s: hit, dt_ms: bob_half_life_ms * 20)) == 0 } -data derived_settle_bound_note: String = "The settle time is derived from the bound, the floor and the half-life rather than declared, so retuning any of the three moves it and no second number goes stale. The largest admissible knock rings for a little over a second, which is the interval a bobber on water actually takes and is why the number reads as correct rather than as arbitrary." +// The settle time is derived from the bound, the floor and the half-life rather than declared, so +// retuning any of the three moves it and no second number goes stale. The largest admissible knock +// rings for a little over a second, which is the interval a bobber on water actually takes and is +// why the number reads as correct rather than as arbitrary. fn witness_the_settle_time_is_derived_and_finite() -> Bool { half_lives_to_settle(initial_milli: bob_max_travel_px * 1000) > 0 @@ -164,7 +185,10 @@ fn witness_the_bob_carries_no_domain_fact() -> Bool { bob_carries_no_domain_fact() } -data platform_blindness_note: String = "The physics never learns where the knock came from. Two impulses with the same magnitude from different bindings — one synthetic, one a hardware reading — produce identical states, which is what makes a new platform binding a new producer rather than a physics edit. The binding identity survives on the impulse for the receipt to render; it simply has no influence on travel." +// The physics never learns where the knock came from. Two impulses with the same magnitude from +// different bindings — one synthetic, one a hardware reading — produce identical states, which is +// what makes a new platform binding a new producer rather than a physics edit. The binding identity +// survives on the impulse for the receipt to render; it simply has no influence on travel. fn witness_the_physics_is_blind_to_which_binding_produced_the_impulse() -> Bool { let synthetic = an_impulse(magnitude: 3000) @@ -183,15 +207,27 @@ fn witness_the_physics_is_blind_to_which_binding_produced_the_impulse() -> Bool && synthetic.source_provider.module_path != hardware.source_provider.module_path } -data frame_sequence_witness_note: String = "The deterministic frame sequence is what makes the bob judgeable without a browser: the whole response is a finite list computed with no clock and no host, so a physics regression is a diff over a list rather than something someone has to watch for. These claims assert the four properties a renderer relies on — it is deterministic, it terminates exactly once, every frame stays inside the envelope in BOTH directions, and it actually crosses rest rather than sagging." +// The deterministic frame sequence is what makes the bob judgeable without a browser: the whole +// response is a finite list computed with no clock and no host, so a physics regression is a diff +// over a list rather than something someone has to watch for. These claims assert the four +// properties a renderer relies on — it is deterministic, it terminates exactly once, every frame +// stays inside the envelope in BOTH directions, and it actually crosses rest rather than sagging. fn a_knock_sequence() -> BobSequence { bob_sequence(i: an_impulse(magnitude: impulse_reference_magnitude_milli), m: MotionFull, interval_ms: 16) } -data no_or_empty_helper_note: String = "THE FRAMES ARE REACHED ONLY THROUGH THE SETTLED ARM (review finding, 2026-08-07). This file used to call a helper that answered a refused sequence with an empty list, and five claims below then asserted properties of that empty list — every one of which a vacuous fold or an empty-list predicate can satisfy. The helper is deleted at its authority; here the consequence is that each frame claim takes the frames as a parameter, and the single match in the keystone is the one place a refusal is answered, with false." +// THE FRAMES ARE REACHED ONLY THROUGH THE SETTLED ARM (review finding, 2026-08-07). This file used +// to call a helper that answered a refused sequence with an empty list, and five claims below then +// asserted properties of that empty list — every one of which a vacuous fold or an empty-list +// predicate can satisfy. The helper is deleted at its authority; here the consequence is that each +// frame claim takes the frames as a parameter, and the single match in the keystone is the one +// place a refusal is answered, with false. -data settled_arm_note: String = "The sequence a consumer receives is the SETTLED arm or nothing. This asserts the arm itself rather than inspecting a list that might have been truncated, which is the whole point of making exhaustion a refusal: a consumer that matched only the settled arm cannot accidentally render a bob that never came to rest." +// The sequence a consumer receives is the SETTLED arm or nothing. This asserts the arm itself +// rather than inspecting a list that might have been truncated, which is the whole point of making +// exhaustion a refusal: a consumer that matched only the settled arm cannot accidentally render a +// bob that never came to rest. fn witness_the_production_sequence_is_admitted_not_truncated() -> Bool { match a_knock_sequence() { @@ -240,7 +276,10 @@ fn witness_the_sequence_terminates_exactly_once_and_is_bounded(fs: List) -> Bool { frames_cross_rest(fs: fs) @@ -249,7 +288,11 @@ fn witness_the_plate_bobs_rather_than_sagging(fs: List) -> Bool { && frames_last_displacement(fs: fs) == 0 } -data waveform_note: String = "The waveform read directly, because the crossing claim above can be satisfied by a shape nobody would accept. It starts at rest, reaches full reach downward a quarter-period in, returns THROUGH rest at the half-period, and reaches full reach upward at three quarters — and the value a sixteenth of a period in is strictly between rest and the extreme, which is the conjunct a two-valued sign function cannot pass." +// The waveform read directly, because the crossing claim above can be satisfied by a shape nobody +// would accept. It starts at rest, reaches full reach downward a quarter-period in, returns THROUGH +// rest at the half-period, and reaches full reach upward at three quarters — and the value a +// sixteenth of a period in is strictly between rest and the extreme, which is the conjunct a +// two-valued sign function cannot pass. fn witness_the_waveform_passes_through_rest_rather_than_jumping() -> Bool { oscillation_milli(elapsed_ms: 0) == 0 @@ -260,7 +303,10 @@ fn witness_the_waveform_passes_through_rest_rather_than_jumping() -> Bool { && oscillation_milli(elapsed_ms: 16) > (0 - oscillation_unit_milli) } -data reach_falls_note: String = "The reach of the SHIPPED frames diminishes: the largest displacement in the first third of the settle window strictly exceeds the largest in the last third. Stated over the emitted list rather than over the envelope function, because the defect this replaces left the envelope function correct in isolation while the sequence it produced never fell." +// The reach of the SHIPPED frames diminishes: the largest displacement in the first third of the +// settle window strictly exceeds the largest in the last third. Stated over the emitted list rather +// than over the envelope function, because the defect this replaces left the envelope function +// correct in isolation while the sequence it produced never fell. fn witness_the_shipped_reach_actually_falls(fs: List) -> Bool { let settle = max_settle_time_ms() diff --git a/dag/test/claim/instrument_camera_witness_test.dag b/dag/test/claim/instrument_camera_witness_test.dag index 7a4b89afdb5..4e7208ef8fa 100644 --- a/dag/test/claim/instrument_camera_witness_test.dag +++ b/dag/test/claim/instrument_camera_witness_test.dag @@ -35,7 +35,14 @@ import gunbc.v1_deletion_plan { data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data instrument_camera_witness_note: String = "First v1-deletion instrument, model layer. Each claim is a decided law with the control that reds when it breaks: the camera cannot write a program fact and cannot skip a detent; the salience role is DERIVED from selection rather than handed in (firing salience_note's dissolve-on); and the derived assignments are judged by the same focal-admission fold that judges hand-authored ones, so the projection is checked by the register's own authority instead of by a second copy of its rule. The subjects are V0's four real v1-deletion finish lines read from gunbc.v1_deletion_plan, not a demo roster, so a fifth line reaches the instrument by being declared once." +// First v1-deletion instrument, model layer. Each claim is a decided law with the control that reds +// when it breaks: the camera cannot write a program fact and cannot skip a detent; the salience +// role is DERIVED from selection rather than handed in (firing salience_note's dissolve-on); and +// the derived assignments are judged by the same focal-admission fold that judges hand-authored +// ones, so the projection is checked by the register's own authority instead of by a second copy of +// its rule. The subjects are V0's four real v1-deletion finish lines read from +// gunbc.v1_deletion_plan, not a demo roster, so a fifth line reaches the instrument by being +// declared once. fn role_key_for(assignments: List, subject: String) -> String { salience_key(role: assignment_role_for(assignments: assignments, subject: subject)) diff --git a/dag/test/claim/instrument_motion_page_witness_test.dag b/dag/test/claim/instrument_motion_page_witness_test.dag index f6ac014fff0..d5d1ef08a7e 100644 --- a/dag/test/claim/instrument_motion_page_witness_test.dag +++ b/dag/test/claim/instrument_motion_page_witness_test.dag @@ -72,7 +72,13 @@ test fn witness_motion_page_renders_through_its_route() -> Bool { && string_contains(s: html, pattern: instrument_motion_asset_path) } -data nonempty_wire_note: String = "EVERY WIRE ASSERTION CHECKS THE WIRE IS NON-EMPTY BEFORE CHECKING THE PAGE CARRIES IT (review finding, 2026-08-07). string_contains(anything, \"\") is true, so a control written as contains(html, wire) passes on a page that ships nothing the moment the wire collapses to the empty string. That is not a hypothetical: the helper this file used to call answered a refused sequence with an empty list, and these three claims would all have gone green over an empty attribute. Each claim now reaches the wire only through a settled sequence, and asserts the wire is non-empty in the same breath." +// EVERY WIRE ASSERTION CHECKS THE WIRE IS NON-EMPTY BEFORE CHECKING THE PAGE CARRIES IT (review +// finding, 2026-08-07). string_contains(anything, "") is true, so a control written as +// contains(html, wire) passes on a page that ships nothing the moment the wire collapses to the +// empty string. That is not a hypothetical: the helper this file used to call answered a refused +// sequence with an empty list, and these three claims would all have gone green over an empty +// attribute. Each claim now reaches the wire only through a settled sequence, and asserts the wire +// is non-empty in the same breath. fn page_ships_full_wire(t: SyntheticTapStrength) -> Bool { match sequence_for(t: t, m: MotionFull) { @@ -141,7 +147,9 @@ test fn witness_the_shipped_sequence_moves_decays_and_settles() -> Bool { } } -data first_movement_note: String = "The first NON-ZERO displacement in the sequence, because a knock pushes the plate away from the hand. Reading the first non-zero rather than the second frame keeps the claim about the physics rather than about how many frames precede the first visible pixel." +// The first NON-ZERO displacement in the sequence, because a knock pushes the plate away from the +// hand. Reading the first non-zero rather than the second frame keeps the claim about the physics +// rather than about how many frames precede the first visible pixel. fn frames_first_movement_is_downward(fs: List) -> Bool { fold(fs, init: 0, f: (acc, x) => if acc == 0 { x.displacement_px } else { acc }) < 0 @@ -171,7 +179,10 @@ test fn witness_the_shipped_probes_count_any_axis_as_a_value() -> Bool { && string_contains(s: js, pattern: " carrying values, over ") } -data client_manufactures_no_zero_note: String = "The renderer used to set translateY(0) after consuming the frames, which supplied the ending a non-settling model had failed to reach. That line is gone, and this asserts its absence directly rather than trusting the diff: the client contains no translateY built from a literal zero, and the sequence it replays ends at zero because the model proved it does." +// The renderer used to set translateY(0) after consuming the frames, which supplied the ending a +// non-settling model had failed to reach. That line is gone, and this asserts its absence directly +// rather than trusting the diff: the client contains no translateY built from a literal zero, and +// the sequence it replays ends at zero because the model proved it does. test fn witness_client_computes_no_physics_and_manufactures_no_ending() -> Bool { let js = motion_asset_body() @@ -189,8 +200,16 @@ test fn witness_receipt_starts_unanswered() -> Bool { && !string_contains(s: html, pattern: "supported") } - -data shared_note_class_note: String = "THE NOTE CLASS IS A WIRE VALUE, NOT A SYMBOL. A repo-wide rename of the fn homonym note matched inside the string literal too, because in \"instrument-note\" the token sits between a hyphen and a quote and neither is a word character. The declaration kept compiling, both pages kept rendering, and the motion page's notes silently stopped matching the stylesheet rule that styles them — a class name is resolved by the browser against CSS text, so nothing in this repository could refuse it. There is now ONE helper: motion imported the sandbox's instrument_note rather than carrying a second copy, so the two cannot drift apart at all. This pins the remaining fact the type system still cannot see — that the emitted class equals the selector the stylesheet defines. The controls are the two exact corrupted spellings: either one reappearing reds this, which the rename that caused it would not have." +// THE NOTE CLASS IS A WIRE VALUE, NOT A SYMBOL. A repo-wide rename of the fn homonym note matched +// inside the string literal too, because in "instrument-note" the token sits between a hyphen and a +// quote and neither is a word character. The declaration kept compiling, both pages kept rendering, +// and the motion page's notes silently stopped matching the stylesheet rule that styles them — a +// class name is resolved by the browser against CSS text, so nothing in this repository could +// refuse it. There is now ONE helper: motion imported the sandbox's instrument_note rather than +// carrying a second copy, so the two cannot drift apart at all. This pins the remaining fact the +// type system still cannot see — that the emitted class equals the selector the stylesheet defines. +// The controls are the two exact corrupted spellings: either one reappearing reds this, which the +// rename that caused it would not have. test fn witness_note_class_wire_matches_stylesheet_selector() -> Bool { let css = instrument_css() diff --git a/dag/test/claim/instrument_physical_witness_test.dag b/dag/test/claim/instrument_physical_witness_test.dag index 11e3c7741cf..b0517f77bf0 100644 --- a/dag/test/claim/instrument_physical_witness_test.dag +++ b/dag/test/claim/instrument_physical_witness_test.dag @@ -37,10 +37,15 @@ import gunbc.design.salience { SalienceRole, SalienceFocal, SalienceSupporting, attraction_travel_max_px, } - data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data instrument_physical_witness_note: String = "The physical-character amendment and the focal audition, each law with the control that reds it. Three of these claims exist because a review found the corresponding hole: an amplitude was a signed Int so two channels could cancel and pass the budget; the enclosure and the focal plate were admitted by SEPARATE gates so each passed while the plate moved farther than either bound described; and the composed law said below while the arithmetic admitted equality. The reading claims that used to live here moved to the sandbox witness when the camera was rewired to read gunbc.roadmap_program_view instead of authored rows." +// The physical-character amendment and the focal audition, each law with the control that reds it. +// Three of these claims exist because a review found the corresponding hole: an amplitude was a +// signed Int so two channels could cancel and pass the budget; the enclosure and the focal plate +// were admitted by SEPARATE gates so each passed while the plate moved farther than either bound +// described; and the composed law said below while the arithmetic admitted equality. The reading +// claims that used to live here moved to the sandbox witness when the camera was rewired to read +// gunbc.roadmap_program_view instead of authored rows. fn preference_over_budget() -> InstrumentPreference { InstrumentPreference { diff --git a/dag/test/claim/instrument_sandbox_witness_test.dag b/dag/test/claim/instrument_sandbox_witness_test.dag index 2985ccb5cf8..c844a941669 100644 --- a/dag/test/claim/instrument_sandbox_witness_test.dag +++ b/dag/test/claim/instrument_sandbox_witness_test.dag @@ -35,9 +35,27 @@ import v2.std.optional { Absent } data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data instrument_sandbox_witness_note: String = "RESHAPED AROUND THE PRODUCTION JOINS, because the first set proved less than it claimed (review finding, 2026-08-05). Three of its claims were substring theatre: the role witness searched the page for the words focal / supporting / ground / critical, which any page mentioning salience contains whether or not a single role was derived; the theme-block helper checked that one variable existed somewhere and that three selectors existed somewhere, never that the variable appeared INSIDE each block; and the press witness equated one translateY rule with a realized CRT glitch. Worst of all, nothing tested the property that turned out to be broken — that a REFUSED audition cannot paint." - -data mechanism_half_note: String = "THE MECHANISM HALF, and the split is measured rather than aesthetic. Every claim below is a property of the register's own gates — which role the projection derives, whether emission is granted, whether a refused role can paint, whether the emission variable lands inside each theme block — and each measured 0-2ms by execution (claim_batch attribution, 2026-08-05). None of them renders the served page or reads the live program view, which is why they are cheap and why they belong per-PR: the 2026-08-04 admission ruling holds that the mechanism half of a live-population subject is NEVER the part that gets deferred. The page-rendering and live-view claims measured 5074ms thread-CPU together, exceeded the fast-lane budget, and moved to dag/test/claim/long/instrument_sandbox_live_witness_test.dag with a declared ceiling and a named executing consumer — not deleted, and not left in a directory that quietly removes them from discovery. Read that file's header for the cost attribution and the dissolve-on that brings these back together." +// RESHAPED AROUND THE PRODUCTION JOINS, because the first set proved less than it claimed (review +// finding, 2026-08-05). Three of its claims were substring theatre: the role witness searched the +// page for the words focal / supporting / ground / critical, which any page mentioning salience +// contains whether or not a single role was derived; the theme-block helper checked that one +// variable existed somewhere and that three selectors existed somewhere, never that the variable +// appeared INSIDE each block; and the press witness equated one translateY rule with a realized CRT +// glitch. Worst of all, nothing tested the property that turned out to be broken — that a REFUSED +// audition cannot paint. + +// THE MECHANISM HALF, and the split is measured rather than aesthetic. Every claim below is a +// property of the register's own gates — which role the projection derives, whether emission is +// granted, whether a refused role can paint, whether the emission variable lands inside each theme +// block — and each measured 0-2ms by execution (claim_batch attribution, 2026-08-05). None of them +// renders the served page or reads the live program view, which is why they are cheap and why they +// belong per-PR: the 2026-08-04 admission ruling holds that the mechanism half of a live-population +// subject is NEVER the part that gets deferred. The page-rendering and live-view claims measured +// 5074ms thread-CPU together, exceeded the fast-lane budget, and moved to +// dag/test/claim/long/instrument_sandbox_live_witness_test.dag with a declared ceiling and a named +// executing consumer — not deleted, and not left in a directory that quietly removes them from +// discovery. Read that file's header for the cost attribution and the dissolve-on that brings these +// back together. fn emission_var_ref(i: AuditionIntensity) -> String { concat("--", concat(audition_emission_var(i: i), ":")) @@ -82,7 +100,10 @@ fn witness_emission_is_present_exactly_when_the_admission_grants_it() -> Bool { && emission_is_none_for(role: role, i: AuditionRestrained) } -data refused_cannot_paint_note: String = "THE CONTROL THE FIRST WITNESS SET DID NOT HAVE. Render the same study at a role the register refuses emission for; no emission may appear in the emitted CSS at all. This is the property that was actually broken — the glow painted while the verdict printed refused underneath it — so it is the one claim here whose failure would have caught the original defect." +// THE CONTROL THE FIRST WITNESS SET DID NOT HAVE. Render the same study at a role the register +// refuses emission for; no emission may appear in the emitted CSS at all. This is the property that +// was actually broken — the glow painted while the verdict printed refused underneath it — so it is +// the one claim here whose failure would have caught the original defect. fn witness_red_a_refused_audition_paints_nothing() -> Bool { !admission_grants(role: SalienceSupporting, i: AuditionHero) @@ -108,7 +129,10 @@ fn witness_the_emission_var_occurs_inside_every_theme_block() -> Bool { && string_contains(s: media_block, pattern: ":root:not([data-theme])") } -data press_css_note: String = "The CSS half of the press specimen — the bounded translation on the focusable control and the displacement budget behind it. The markup half (that the rendered page actually carries a button) needs the page, so it lives with the live claims; keeping the two halves apart is what lets the cheap half stay per-PR instead of riding the expensive one's budget." +// The CSS half of the press specimen — the bounded translation on the focusable control and the +// displacement budget behind it. The markup half (that the rendered page actually carries a button) +// needs the page, so it lives with the live claims; keeping the two halves apart is what lets the +// cheap half stay per-PR instead of riding the expensive one's budget. fn witness_the_press_response_is_a_bounded_translation() -> Bool { let css = instrument_css() @@ -117,7 +141,14 @@ fn witness_the_press_response_is_a_bounded_translation() -> Bool { && instrument_displacement_px(p: preference_default) == 6 } -data program_grain_fixture_note: String = "A PLANTED VIEW, because this claim's oracle must be independent of the live roadmap. The fixture's PROGRAM remaining and its one FINISH LINE's remaining are deliberately different numbers (open_fronts 7 versus 1, startable_now 5 versus 0), so a reader that collapses program grain onto outcome grain is caught by VALUE and not merely by variant — asserting the variant alone would still pass if some future arm returned a program-shaped reading built from the line's own shape. Cheap by construction: the record is built directly rather than derived through program_view, so this mechanism claim costs microseconds and stays per-PR while the live half runs on the falsifier lane." +// A PLANTED VIEW, because this claim's oracle must be independent of the live roadmap. The +// fixture's PROGRAM remaining and its one FINISH LINE's remaining are deliberately different +// numbers (open_fronts 7 versus 1, startable_now 5 versus 0), so a reader that collapses program +// grain onto outcome grain is caught by VALUE and not merely by variant — asserting the variant +// alone would still pass if some future arm returned a program-shaped reading built from the line's +// own shape. Cheap by construction: the record is built directly rather than derived through +// program_view, so this mechanism claim costs microseconds and stays per-PR while the live half +// runs on the falsifier lane. fn fixture_line_remaining() -> RemainingShape { RemainingShape { @@ -158,7 +189,12 @@ fn focused_camera(m: ProgramMode, d: ProgramDepth) -> ProgramCamera { ProgramCamera { depth: d, mode: m, focus: FinishLineFocused { line_key: "compiler-fixed-point" } } } -data program_grain_witness_note: String = "The claim review 48719 found missing. With a subject FOCUSED, the program detent must still read the whole program's shape — before the fix read_camera_at routed a focused DepthProgram into read_line_view, whose DepthProgram arm was byte-identical to its DepthOutcome one, so the page rendered outcome-grain numbers under a program label. This reds on that exact behaviour: it demands the program's own remaining (open_fronts 7), which the collapsed reader could not produce because it only ever saw the line's 1." +// The claim review 48719 found missing. With a subject FOCUSED, the program detent must still read +// the whole program's shape — before the fix read_camera_at routed a focused DepthProgram into +// read_line_view, whose DepthProgram arm was byte-identical to its DepthOutcome one, so the page +// rendered outcome-grain numbers under a program label. This reds on that exact behaviour: it +// demands the program's own remaining (open_fronts 7), which the collapsed reader could not produce +// because it only ever saw the line's 1. fn witness_the_program_detent_reads_program_grain_even_when_focused() -> Bool { let status = read_camera(camera: focused_camera(m: ModeStatus, d: DepthProgram), view: fixture_view()) @@ -185,7 +221,9 @@ fn witness_the_program_detent_reads_program_grain_even_when_focused() -> Bool { } } -data outcome_grain_still_line_scoped_note: String = "The other half of the same law, so the fix cannot be satisfied by making EVERY depth answer program-grain: at outcome depth the reading must still be the LINE's shape (open_fronts 1), not the program's 7." +// The other half of the same law, so the fix cannot be satisfied by making EVERY depth answer +// program-grain: at outcome depth the reading must still be the LINE's shape (open_fronts 1), not +// the program's 7. fn witness_red_the_outcome_detent_still_reads_the_line() -> Bool { match read_camera(camera: focused_camera(m: ModeRemaining, d: DepthOutcome), view: fixture_view()) { diff --git a/dag/test/claim/instrument_tuner_witness_test.dag b/dag/test/claim/instrument_tuner_witness_test.dag index 711640f1998..f2f34dcf813 100644 --- a/dag/test/claim/instrument_tuner_witness_test.dag +++ b/dag/test/claim/instrument_tuner_witness_test.dag @@ -25,7 +25,11 @@ import extdeps.languages.html_fragment { serialize_fragment } data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data instrument_tuner_witness_note: String = "The operable follow-on to the static study: a modeled TsProgram client, a served asset, pre-rendered reading rows keyed by camera_wire, and witnesses that join camera population to v1_exit_finish_lines rather than pinning a census literal. Model-layer detent integrator and seek-depth claims live in instrument_camera_witness; this file pins the client seam and HTML pre-render shape." +// The operable follow-on to the static study: a modeled TsProgram client, a served asset, +// pre-rendered reading rows keyed by camera_wire, and witnesses that join camera population to +// v1_exit_finish_lines rather than pinning a census literal. Model-layer detent integrator and +// seek-depth claims live in instrument_camera_witness; this file pins the client seam and HTML +// pre-render shape. fn fixture_view() -> V1DeletionProgramView { V1DeletionProgramView { diff --git a/dag/test/claim/interpreter_dispatch_bijection_real_roster_witness_test.dag b/dag/test/claim/interpreter_dispatch_bijection_real_roster_witness_test.dag index dc0f29a5fc2..ca2bcf4f93d 100644 --- a/dag/test/claim/interpreter_dispatch_bijection_real_roster_witness_test.dag +++ b/dag/test/claim/interpreter_dispatch_bijection_real_roster_witness_test.dag @@ -8,7 +8,15 @@ import v2.std.logic { Bool } data live_tree_disposition: LiveTreeDisposition = ReadsLiveTree -data interpreter_dispatch_bijection_real_roster_witness_note: String = "R1 real-crate roster<->handler bijection evidence (gunbc#7825 / Lane D): falsifier_self_host_wet enrollment for the two integration tests that clone the real workspace, perturb gunbc.v1_interpreter_primitive_surface or src/v1/stage0/src/v1_interpreter.rs, run dag/gunbc/instruments/generated_artifact_gate.dag main_wet, and require real cargo build refusal (E0004 / macro expansion). Distinct from interpreter_dispatch_bijection_compile_red.rs (isolated temp fixture, per-PR-local cargo test) and from v1_interpreter_primitive_dispatch_authority_acceptance_test.dag (structural .dag contract). Memory envelope prediction: tools.interpreter_dispatch_bijection_real_roster_transport interpreter_dispatch_bijection_real_roster_memory_envelope_note." +// R1 real-crate roster<->handler bijection evidence (gunbc#7825 / Lane D): falsifier_self_host_wet +// enrollment for the two integration tests that clone the real workspace, perturb +// gunbc.v1_interpreter_primitive_surface or src/v1/stage0/src/v1_interpreter.rs, run +// dag/gunbc/instruments/generated_artifact_gate.dag main_wet, and require real cargo build refusal +// (E0004 / macro expansion). Distinct from interpreter_dispatch_bijection_compile_red.rs (isolated +// temp fixture, per-PR-local cargo test) and from +// v1_interpreter_primitive_dispatch_authority_acceptance_test.dag (structural .dag contract). +// Memory envelope prediction: tools.interpreter_dispatch_bijection_real_roster_transport +// interpreter_dispatch_bijection_real_roster_memory_envelope_note. test fn interpreter_dispatch_bijection_real_roster_red_holds() -> Bool { run_interpreter_dispatch_bijection_real_roster_red() diff --git a/dag/test/claim/interpreter_replacement_cut_witness_test.dag b/dag/test/claim/interpreter_replacement_cut_witness_test.dag index 8f2ae42b4df..e9653cb9e3b 100644 --- a/dag/test/claim/interpreter_replacement_cut_witness_test.dag +++ b/dag/test/claim/interpreter_replacement_cut_witness_test.dag @@ -18,7 +18,26 @@ import gunbc.interpreter_replacement_cut { interpreter_cut_why_not_higher, } -data interpreter_replacement_cut_witness_note: String = "RECAST 2026-08-28 WITH THE ROW IT WITNESSES. This suite previously asserted that the interpreter ReplacementCut refuses with exactly the two open-decision cause classes. That claim no longer has a subject: the carrier re-grounded its boundary relation onto declaration-grain consumer x consumed-authority, the interpreter value was authored at module-or-binary grain over a ten-of-125 sample, and it is therefore now a LegacyReplacementSurvey plus a registered remeasurement obligation rather than an exact plan.\n\nTHE OLD ASSERTION IS NOT PRESERVED, AND THAT IS DELIBERATE RATHER THAN A LOSS. Its subject was the admission verdict of a plan that no longer exists in the exact carrier, so re-enrolling it would require reconstructing the coarse plan purely to keep asserting something about it -- the shape DESIGN §4b(4) forbids, where evidence is retained beside the machinery it was supposed to dissolve with. What survives is the pair below: the survey's measured content stays identity-bound so the historical record cannot drift, and the registration cannot be read as an admitted exact plan.\n\nWHY THE SECOND ONE IS THE LOAD-BEARING ONE: the whole risk of keeping a coarse survey in the tree is that some later consumer treats it as an exact census. RegisteredCutRemeasureRequired has no arm that yields a ReplacementCut, so that misreading is unwritable rather than merely discouraged -- but a control is enrolled anyway, because the arm could be widened by a later edit and the cost of that edit is exactly this class of laundering." +// RECAST 2026-08-28 WITH THE ROW IT WITNESSES. This suite previously asserted that the interpreter +// ReplacementCut refuses with exactly the two open-decision cause classes. That claim no longer has +// a subject: the carrier re-grounded its boundary relation onto declaration-grain consumer x +// consumed-authority, the interpreter value was authored at module-or-binary grain over a +// ten-of-125 sample, and it is therefore now a LegacyReplacementSurvey plus a registered +// remeasurement obligation rather than an exact plan. +// +// THE OLD ASSERTION IS NOT PRESERVED, AND THAT IS DELIBERATE RATHER THAN A LOSS. Its subject was +// the admission verdict of a plan that no longer exists in the exact carrier, so re-enrolling it +// would require reconstructing the coarse plan purely to keep asserting something about it -- the +// shape DESIGN §4b(4) forbids, where evidence is retained beside the machinery it was supposed to +// dissolve with. What survives is the pair below: the survey's measured content stays +// identity-bound so the historical record cannot drift, and the registration cannot be read as an +// admitted exact plan. +// +// WHY THE SECOND ONE IS THE LOAD-BEARING ONE: the whole risk of keeping a coarse survey in the tree +// is that some later consumer treats it as an exact census. RegisteredCutRemeasureRequired has no +// arm that yields a ReplacementCut, so that misreading is unwritable rather than merely discouraged +// -- but a control is enrolled anyway, because the arm could be widened by a later edit and the +// cost of that edit is exactly this class of laundering. // --------------------------------------------------------------------------- // 1. The historical survey stays identity-bound. diff --git a/dag/test/claim/inventory_ledger_witness_test.dag b/dag/test/claim/inventory_ledger_witness_test.dag index d615f5ad19c..4c92bd012a0 100644 --- a/dag/test/claim/inventory_ledger_witness_test.dag +++ b/dag/test/claim/inventory_ledger_witness_test.dag @@ -123,7 +123,11 @@ fn balance_of(lot: ProcurementLot, events: List) -> InventoryBal // --- WALL 1: no event sequence yields a negative balance ------------------------------------------ -data w_no_negative_balance_note: String = "The wall is structural rather than checked: transfer_stock is the only mutation, it refuses when the source position holds less than the requested quantity, and a refusal stops the fold. So the assertion here is that a deliberately over-drawing sequence produces a LOCATED refusal naming the position, the requested quantity and the quantity actually held — not a clamped result and not a wrapped Nat." +// The wall is structural rather than checked: transfer_stock is the only mutation, it refuses when +// the source position holds less than the requested quantity, and a refusal stops the fold. So the +// assertion here is that a deliberately over-drawing sequence produces a LOCATED refusal naming the +// position, the requested quantity and the quantity actually held — not a clamped result and not a +// wrapped Nat. test fn w_over_draw_refuses_with_located_shortfall() -> Bool { let events = append(acquire_and_receive_all(), [ @@ -182,7 +186,15 @@ test fn w_long_lifecycle_never_leaves_a_bucket_short() -> Bool { // --- WALL 2: every bucket reconciles to the acquired total ------------------------------------------ -data w_reconciliation_note: String = "Every bucket is pinned to an INDEPENDENTLY STATED number, never compared to another derived field. An earlier revision called a balance_reconciles_to_acquired helper here, and review 53543 showed that helper reduced to total == total and could not fail — so this row was asserting a tautology and passing on it. Hand-computing the expected partition from the event list is what makes the assertion discriminating: ten acquired, all received and qualified, then three reserved, two installed from available, one disposed from available, leaving four available. Every one of those numbers comes from reading the events, not from the balance. The aggregates are pinned the same way, so a derived field that drifted from the partition reds against a constant rather than agreeing with its own sibling." +// Every bucket is pinned to an INDEPENDENTLY STATED number, never compared to another derived +// field. An earlier revision called a balance_reconciles_to_acquired helper here, and review 53543 +// showed that helper reduced to total == total and could not fail — so this row was asserting a +// tautology and passing on it. Hand-computing the expected partition from the event list is what +// makes the assertion discriminating: ten acquired, all received and qualified, then three +// reserved, two installed from available, one disposed from available, leaving four available. +// Every one of those numbers comes from reading the events, not from the balance. The aggregates +// are pinned the same way, so a derived field that drifted from the partition reds against a +// constant rather than agreeing with its own sibling. test fn w_all_buckets_reconcile_to_acquired() -> Bool { let events = append(acquire_and_receive_all(), [ @@ -274,7 +286,9 @@ test fn w_over_request_refuses_and_reports_both_numbers() -> Bool { } } -data w_partial_fulfilment_is_absent_note: String = "The RED control for the absorbing fallback: a request one unit past available must refuse, NOT return available_after 0 having quietly served ten of the eleven. Asserting the refusal arm is what keeps a future partial-fulfilment convenience from landing silently." +// The RED control for the absorbing fallback: a request one unit past available must refuse, NOT +// return available_after 0 having quietly served ten of the eleven. Asserting the refusal arm is +// what keeps a future partial-fulfilment convenience from landing silently. test fn w_one_past_available_still_refuses() -> Bool { match admit_consumption( @@ -455,7 +469,12 @@ fn reading_is_micros(reading: LandedCostReading, expected: Int) -> Bool { } } -data w_basis_survives_consumption_note: String = "Two projections, one fact. The basis is read from the lot and takes no event list, so consumption cannot reach it; the incremental purchase cash is read from the ledger and only LotAcquired contributes to it. The assertion runs both readings over a SHORT ledger and over the same ledger with a full consumption tail appended, and requires all four numbers to agree pairwise — a consumption event that contributed cash, or a fold that recomputed the basis from what remains on the shelf, would break it." +// Two projections, one fact. The basis is read from the lot and takes no event list, so consumption +// cannot reach it; the incremental purchase cash is read from the ledger and only LotAcquired +// contributes to it. The assertion runs both readings over a SHORT ledger and over the same ledger +// with a full consumption tail appended, and requires all four numbers to agree pairwise — a +// consumption event that contributed cash, or a fold that recomputed the basis from what remains on +// the shelf, would break it. test fn w_consumption_leaves_basis_and_cash_untouched() -> Bool { let lot = ten_unit_lot() @@ -488,7 +507,10 @@ test fn w_consumption_leaves_basis_and_cash_untouched() -> Bool { } } -data w_no_per_unit_average_note: String = "The RED control for the per-unit average: 1,000,003 micros over 10 units has no exact quotient at money-micro grain. This row asserts the ledger reports the aggregate the lot actually cost and that ten times any floor of the quotient does NOT reproduce it — which is the arithmetic reason a stored per-unit field would be a fabricated number rather than a convenience." +// The RED control for the per-unit average: 1,000,003 micros over 10 units has no exact quotient at +// money-micro grain. This row asserts the ledger reports the aggregate the lot actually cost and +// that ten times any floor of the quotient does NOT reproduce it — which is the arithmetic reason a +// stored per-unit field would be a fabricated number rather than a convenience. test fn w_aggregate_basis_is_not_recoverable_from_a_per_unit_floor() -> Bool { let lot = ten_unit_lot() @@ -538,7 +560,11 @@ test fn w_landed_cost_sums_within_one_currency_and_refuses_across() -> Bool { } } -data w_empty_sum_is_not_a_refusal_note: String = "The control for review 53528: summing no lots must report the EMPTY arm, not a refusal. The two states have different remedies — supply lots versus reconcile currencies — and an earlier revision returned a refusal carrying the sentinel string 'no_lots' for the first, which a consumer could only tell from a genuine mismatch by parsing prose. This row asserts the empty and the refusing cases land on different constructors, so collapsing them back into one reds here." +// The control for review 53528: summing no lots must report the EMPTY arm, not a refusal. The two +// states have different remedies — supply lots versus reconcile currencies — and an earlier +// revision returned a refusal carrying the sentinel string 'no_lots' for the first, which a +// consumer could only tell from a genuine mismatch by parsing prose. This row asserts the empty and +// the refusing cases land on different constructors, so collapsing them back into one reds here. test fn w_summing_no_lots_is_empty_not_refused() -> Bool { let lot = ten_unit_lot() @@ -574,7 +600,11 @@ test fn w_summing_no_lots_is_empty_not_refused() -> Bool { // --- WALL 5: lot identity is not inferable from display labels -------------------------------------- -data w_identity_not_from_labels_note: String = "Two lots that agree on EVERY authored string — receipt aside, the same catalog row, the same display label, the same quantity, the same landed cost — are still two lots, because identity was minted rather than computed. And a lot whose display label is replaced wholesale is still the SAME lot. Those are exactly the two facts a label-derived key cannot deliver at once: it would fuse the first pair and split the second." +// Two lots that agree on EVERY authored string — receipt aside, the same catalog row, the same +// display label, the same quantity, the same landed cost — are still two lots, because identity was +// minted rather than computed. And a lot whose display label is replaced wholesale is still the +// SAME lot. Those are exactly the two facts a label-derived key cannot deliver at once: it would +// fuse the first pair and split the second. test fn w_identical_labels_are_still_two_lots() -> Bool { let a = ten_unit_lot() @@ -629,7 +659,10 @@ test fn w_unread_catalog_yields_no_exact_row_and_names_its_obligation() -> Bool // --- landed-cost and receipt three-state controls ---------------------------------------------- -data w_landed_cost_states_note: String = "The three landed-cost arms are asserted by CONSTRUCTOR, in both directions, because the whole point of splitting them is that a consumer can tell them apart. A test that only checked 'not a number' would pass just as well against the single Withheld arm this split replaced, and would therefore be evidence for nothing." +// The three landed-cost arms are asserted by CONSTRUCTOR, in both directions, because the whole +// point of splitting them is that a consumer can tell them apart. A test that only checked 'not a +// number' would pass just as well against the single Withheld arm this split replaced, and would +// therefore be evidence for nothing. fn unsettled_lot() -> ProcurementLot { ProcurementLot { diff --git a/dag/test/claim/json_emit_witness_test.dag b/dag/test/claim/json_emit_witness_test.dag index d6d32420197..d3206e0ba90 100644 --- a/dag/test/claim/json_emit_witness_test.dag +++ b/dag/test/claim/json_emit_witness_test.dag @@ -135,8 +135,12 @@ test fn witness_unicode_escape_hex4_boundary_ffff() -> Bool { json_unicode_escape_hex4(cp: 65535) == "FFFF" } - -data json_text_exponent_regression_note: String = "review 44043 RED. RFC 8259's exp production requires 1*DIGIT, but json_text_parse_number consumed the marker and optional sign without demanding one, so `1e` parsed as a complete number and json_text_parseable called the document well-formed. That is the fail-open the admission receipt check now sits on top of. These witnesses pin both directions and, critically, the AGREEMENT between the two readings of one RFC production: the text parser and the json_number_lexeme_valid lexeme surface had forked, and only the lexeme surface was correct." +// review 44043 RED. RFC 8259's exp production requires 1*DIGIT, but json_text_parse_number consumed +// the marker and optional sign without demanding one, so `1e` parsed as a complete number and +// json_text_parseable called the document well-formed. That is the fail-open the admission receipt +// check now sits on top of. These witnesses pin both directions and, critically, the AGREEMENT +// between the two readings of one RFC production: the text parser and the json_number_lexeme_valid +// lexeme surface had forked, and only the lexeme surface was correct. test fn witness_json_text_bare_exponent_refused() -> Bool { !extdeps.languages.json.parse.json_text_parseable(s: "1e") diff --git a/dag/test/claim/json_parse_witness_test.dag b/dag/test/claim/json_parse_witness_test.dag index f82bb8cc14c..abb37dbf36f 100644 --- a/dag/test/claim/json_parse_witness_test.dag +++ b/dag/test/claim/json_parse_witness_test.dag @@ -1,9 +1,14 @@ module test.claim.json_parse_witness - data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data json_parse_witness_note: String = "parse_json is the forward reading of RFC 8259 and serialize_json is the backward one, so the claims below are stated as round-trips over one JsonValue rather than against golden bytes (DESIGN 4). The escape claims are the discriminating ones: three plain round-trips pass without the escape decoding being right at all, which is exactly how a plausible-but-wrong unescaper survives. The \\u claims fail against an unescaper that passes \\u through, which is what this parser did before it carried json_hex4_at - a receipt detail field carrying a control character would have silently gained four literal hex characters and lost the character itself." +// parse_json is the forward reading of RFC 8259 and serialize_json is the backward one, so the +// claims below are stated as round-trips over one JsonValue rather than against golden bytes +// (DESIGN 4). The escape claims are the discriminating ones: three plain round-trips pass without +// the escape decoding being right at all, which is exactly how a plausible-but-wrong unescaper +// survives. The \u claims fail against an unescaper that passes \u through, which is what this +// parser did before it carried json_hex4_at - a receipt detail field carrying a control character +// would have silently gained four literal hex characters and lost the character itself. fn parsed_string_of(text: String) -> String { match parse_json_document(s: text) { @@ -118,7 +123,15 @@ fn parses(text: String) -> Bool { } } -data trailing_comma_regression_note: String = "These exist because the recovered parser accepted a trailing comma and the roadmap_provider_events witness caught it, not this file. The accumulator checked for the closing bracket at the top of each round, so after consuming a separator it reached the empty-container case again and closed the container. Nothing in a round-trip claim can see this: serialize_json never EMITS a trailing comma, so emitter-to-parser round-trips stay green over exactly the documents that cannot expose it. The defect is only reachable from foreign text, which is what json_text_parseable guards - the Codex JSONL reader refuses a malformed provider line with it, and a truncated-then-closed event would have read as well-formed. The last claim names the fixture that failed." +// These exist because the recovered parser accepted a trailing comma and the +// roadmap_provider_events witness caught it, not this file. The accumulator checked for the closing +// bracket at the top of each round, so after consuming a separator it reached the empty-container +// case again and closed the container. Nothing in a round-trip claim can see this: serialize_json +// never EMITS a trailing comma, so emitter-to-parser round-trips stay green over exactly the +// documents that cannot expose it. The defect is only reachable from foreign text, which is what +// json_text_parseable guards - the Codex JSONL reader refuses a malformed provider line with it, +// and a truncated-then-closed event would have read as well-formed. The last claim names the +// fixture that failed. test fn a_trailing_comma_is_refused_in_objects_and_arrays() -> Bool { parses(text: "\{\"a\": 1}") @@ -146,7 +159,14 @@ test fn the_provider_event_line_that_caught_the_trailing_comma_is_refused() -> B && parses(text: "\{\"type\":\"turn.completed\"}") } -data unknown_escape_note: String = "review 45642 RED. RFC 8259 section 7 closes the escape set, and the scanner used to consume the backslash and whatever followed without deciding whether it named an escape - so the unescaper's unknown arm dropped the backslash and `p\\assed` became `passed`. The first claim is the reviewer's exact case and it is the one that matters, because the fabricated string is not merely wrong: it equals a verdict the receipt reader accepts, so a malformed document produced a pass. The rest pin the boundary in both directions - every escape the RFC lists still decodes, and every shape it does not list refuses - because a fix that simply refused more would also have broken the emitter's own output." +// review 45642 RED. RFC 8259 section 7 closes the escape set, and the scanner used to consume the +// backslash and whatever followed without deciding whether it named an escape - so the unescaper's +// unknown arm dropped the backslash and `p\assed` became `passed`. The first claim is the +// reviewer's exact case and it is the one that matters, because the fabricated string is not merely +// wrong: it equals a verdict the receipt reader accepts, so a malformed document produced a pass. +// The rest pin the boundary in both directions - every escape the RFC lists still decodes, and +// every shape it does not list refuses - because a fix that simply refused more would also have +// broken the emitter's own output. test fn an_unknown_escape_refuses_rather_than_dropping_the_backslash() -> Bool { !parses(text: "\"p\\assed\"") diff --git a/dag/test/claim/jwt_oidc_claims_witness_test.dag b/dag/test/claim/jwt_oidc_claims_witness_test.dag index c6a73427535..57a86e0ac19 100644 --- a/dag/test/claim/jwt_oidc_claims_witness_test.dag +++ b/dag/test/claim/jwt_oidc_claims_witness_test.dag @@ -50,7 +50,11 @@ import extdeps.llm.codex_auth { data witness_purpose_note: String = "THESE MODULES HAD NO CONSUMER AT ALL, which is why their claims went unchecked long enough to encode one token as a specification. extdeps.auth.jwt, extdeps.auth.oidc and their codex composition typechecked, cited real RFCs, and were never executed by anything — the specification-without-execution tier exactly. A grep would have found the RFC numbers and concluded the modeling was grounded.\\n\\nSo this file is the first consumer, and it is written to go RED on the specific overclaims that were there rather than to restate the types. Each claim below names the wrong behaviour it discriminates against: mandatory registered claims, a normalized audience, an integer-only NumericDate, an unenforced colon rule, a provenance inference from URI shape, and required OIDC optional claims. Reverting any one of those corrections fails a claim here." -// THE CLAIM THAT WAS IMPOSSIBLE TO WRITE BEFORE. Every field of JwtRegisteredClaims was required, so a JWT carrying none of the registered claims — which RFC 7519 section 4.1 explicitly permits, since none of them are mandatory — could not be expressed at all. This constructs exactly that value. Under the previous shape this file would not compile, which is the sharpest available discrimination: the red is a type error, not a false assertion. +// THE CLAIM THAT WAS IMPOSSIBLE TO WRITE BEFORE. Every field of JwtRegisteredClaims was required, +// so a JWT carrying none of the registered claims — which RFC 7519 section 4.1 permits, none being +// mandatory — could not be expressed. This constructs exactly that value. Under the previous shape +// this file would not compile — the sharpest discrimination: the red is a type error, not a false +// assertion. fn empty_registered_claims() -> JwtRegisteredClaims { JwtRegisteredClaims { issuer: none, @@ -79,7 +83,14 @@ test fn registered_claims_are_all_optional() -> Bool { } } -// THE COLON RULE IS NOW CHECKED, AND THE REFUSAL IS THE POINT. RFC 7519 section 2 requires that a StringOrURI containing a colon be a URI; the previous brand accepted any NonEmptyStr, so the rule was documented and unenforced.\n\nThe discriminating input is 9:30 — it contains a colon and its scheme position starts with a digit, which RFC 3986 forbids. A brand admits it silently. The decoder refuses it. The two positive cases bracket the refusal: a bare name with no colon is admissible and stays bare, and urn:openai:amr:passkey is admissible and decodes its scheme as urn, which extdeps.uri's closed scheme enum could not have represented. +// THE COLON RULE IS NOW CHECKED, AND THE REFUSAL IS THE POINT. RFC 7519 section 2 requires a +// StringOrURI containing a colon to be a URI; the previous brand accepted any NonEmptyStr, so the +// rule was documented and unenforced. +// +// The discriminating input is 9:30 — a colon with a scheme position starting with a digit, which +// RFC 3986 forbids. A brand admits it silently; the decoder refuses it. The two positive cases +// bracket the refusal: a bare name with no colon stays bare, and urn:openai:amr:passkey decodes its +// scheme as urn, which extdeps.uri's closed scheme enum could not have represented. test fn bare_string_without_colon_is_admitted() -> Bool { match jwt_string_or_uri_of_wire(raw: "pop" as NonEmptyStr) { StringOrUriRefused { raw: _, reason: _ } => false @@ -119,7 +130,14 @@ test fn string_or_uri_round_trips_to_its_wire_form() -> Bool { } } -// THE SINGLE FORM AND THE ARRAY FORM ARE DIFFERENT VALUES, which is what normalizing aud to a list destroyed. RFC 7519 section 4.1.3 permits both, and a verifier re-serializing a token must emit the form it received or the signature stops covering the bytes.\n\nThe discrimination is structural: both audiences below project to the same one-element value list, so a claim written only against jwt_audience_values cannot tell them apart — and that is exactly the collapse the previous model performed at ingest. Matching the constructor distinguishes them, so the encoding survives. +// THE SINGLE FORM AND THE ARRAY FORM ARE DIFFERENT VALUES, which normalizing aud to a list +// destroyed. RFC 7519 section 4.1.3 permits both, and a verifier re-serializing a token must emit +// the form it received or the signature stops covering the bytes. +// +// The discrimination is structural: both audiences below project to the same one-element value +// list, so a claim written only against jwt_audience_values cannot tell them apart — exactly the +// collapse the previous model performed at ingest. Matching the constructor distinguishes them, so +// the encoding survives. fn single_audience() -> JwtAudience { JwtAudienceSingle { value: JwtBareString { value: "client-a" as NonEmptyStr } } } @@ -144,7 +162,16 @@ test fn audience_keeps_its_wire_encoding() -> Bool { same_values && distinguishable } -data numeric_date_note: String = "A FRACTIONAL NumericDate REFUSES INSTEAD OF ROUNDING. RFC 7519 section 2 admits non-integer values; an Int carrier silently rounds them, and rounding an expiry moves the instant the issuer named in one direction or the other without ever reporting that it did.\\n\\nThe positive claim pins the observed codex pair — iat and exp exactly 3600 seconds apart — so the arithmetic is still exercised on the case that actually occurs, and it compares through std.measure.Second rather than through a bare Int, so a lifetime returned in the wrong unit cannot satisfy it. The two negative claims are the discriminating ones: a fractional expiry produces a typed refusal where a truncating model would return a number and pass, and an expiry preceding issuance refuses where a clamp would report zero and look like an expired credential." +// A FRACTIONAL NumericDate REFUSES INSTEAD OF ROUNDING. RFC 7519 section 2 admits non-integer +// values; an Int carrier silently rounds them, moving the instant the issuer named without +// reporting it. +// +// The positive claim pins the observed codex pair — iat and exp exactly 3600 seconds apart — so the +// arithmetic is exercised on the case that occurs, comparing through std.measure.Second rather than +// a bare Int, so a lifetime in the wrong unit cannot satisfy it. The two negative claims +// discriminate: a fractional expiry produces a typed refusal where a truncating model would return +// a number and pass, and an expiry preceding issuance refuses where a clamp would report zero and +// look like an expired credential. test fn whole_second_lifetime_is_exact() -> Bool { match numeric_date_lifetime( @@ -184,7 +211,14 @@ test fn expiry_before_issuance_refuses_rather_than_clamping() -> Bool { } } -// THE URI ARM NAMES A SHAPE, NOT AN OWNER. RFC 8176 registers short names and says nothing about who may use a URI, so classifying every colon-bearing amr value as PRIVATE was an inference the specification does not license.\n\nAll four values observed in the codex token are decoded here through the shared StringOrURI rule: two registered short names and two URI-valued methods. The refusal case is the one the old local colon test could not produce — a colon-bearing value that is not a valid URI was previously filed as a vendor method, and is now refused. +// THE URI ARM NAMES A SHAPE, NOT AN OWNER. RFC 8176 registers short names and says nothing about +// who may use a URI, so classifying every colon-bearing amr value as PRIVATE was an inference the +// specification does not license. +// +// All four values observed in the codex token decode through the shared StringOrURI rule: two +// registered short names and two URI-valued methods. The refusal case is the one the old local +// colon test could not produce — a colon-bearing value that is not a valid URI was filed as a +// vendor method, and is now refused. fn amr_is_uri_valued(raw: NonEmptyStr) -> Bool { match oidc_amr_of_wire(raw: raw) { AmrRefused { raw: _, reason: _ } => false @@ -232,7 +266,14 @@ test fn malformed_colon_amr_refuses() -> Bool { } } -// OIDC REQUIRES FIVE CLAIMS AND THE FIRST CUT REQUIRED ELEVEN. This constructs the minimal conforming ID Token: the five section-2 required claims present, and auth_time, nonce, acr, amr, azp, sid and every standard claim absent. None of those seven is universally required by any specification, and under the previous shape this value was unrepresentable.\n\nThe projection claim checks the direction that is safe — an ID Token's required core reads cleanly as RFC 7519 registered claims — while the reverse embedding, which is what the earlier model did, is what made the base type unable to describe a plain JWT. +// OIDC REQUIRES FIVE CLAIMS AND THE FIRST CUT REQUIRED ELEVEN. This constructs the minimal +// conforming ID Token: the five section-2 required claims present; auth_time, nonce, acr, amr, azp, +// sid and every standard claim absent. None of those seven is universally required by any +// specification, and under the previous shape this value was unrepresentable. +// +// The projection claim checks the safe direction — an ID Token's required core reads cleanly as RFC +// 7519 registered claims — while the reverse embedding, which the earlier model did, made the base +// type unable to describe a plain JWT. fn minimal_id_token() -> OidcIdTokenClaims { OidcIdTokenClaims { issuer: JwtUriString { @@ -291,7 +332,15 @@ test fn id_token_projects_onto_registered_claims() -> Bool { } } -data observation_is_not_requirement_note: String = "THE PROFILE RECORDS PRESENCE; THE TYPE RECORDS OPTIONALITY, and this claim proves they are now separate rather than fused. Every claim the codex token was observed to carry is marked present in the profile, AND every one of those claims is optional in OidcIdTokenClaims — which is exactly the combination the previous model could not express, because it read observed presence as mandatory shape.\\n\\nThe minimal token above is the proof of the second half: it omits every claim this profile marks present and is still a well-typed ID Token. If any of those fields were re-required, that constructor stops compiling while this profile stays green — the two would have to be reconciled by hand, which is the fork this split removes." +// THE PROFILE RECORDS PRESENCE; THE TYPE RECORDS OPTIONALITY, and this claim proves they are now +// separate. Every claim the codex token was observed to carry is marked present in the profile, AND +// every one is optional in OidcIdTokenClaims — the combination the previous model could not +// express, because it read observed presence as mandatory shape. +// +// The minimal token above proves the second half: it omits every claim this profile marks present +// and is still a well-typed ID Token. If any of those fields were re-required, that constructor +// stops compiling while this profile stays green — the two would have to be reconciled by hand, the +// fork this split removes. fn profile_marks_present(claim: String) -> Bool { any( diff --git a/dag/test/claim/keyed_roster_witness_test.dag b/dag/test/claim/keyed_roster_witness_test.dag index a415baf6b40..8f0c41344b1 100644 --- a/dag/test/claim/keyed_roster_witness_test.dag +++ b/dag/test/claim/keyed_roster_witness_test.dag @@ -19,7 +19,14 @@ import v2.std.live_tree { LiveTreeDisposition, SubstrateInputsOnly } data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data keyed_roster_witness_note: String = "Lane 4 witnesses (generated-file conflict policy charter, docs/plans/generated-file-conflict-policy.md on session/crisp-bat-830): construction refuses a repeated path key with a typed KeyedRosterDuplicateKey / KeyedRosterBuildDuplicateKey carrying key + both colliding rows (located, not a bare Bool). keyed_roster_union models the git clean-merge failure mode: two branches each append disjoint rows admit; overlapping path keys refuse. keyed_merge_row_lists is the deliberate contrast (silent first-wins, reconcile grain). Per-PR admission: enrolled on commit_gate_roster (GithubActionsCiJob) plus affected-set discovery when dag/std/ or enrolled roster carriers change." +// Lane 4 witnesses (generated-file conflict policy charter, +// docs/plans/generated-file-conflict-policy.md on session/crisp-bat-830): construction refuses a +// repeated path key with a typed KeyedRosterDuplicateKey / KeyedRosterBuildDuplicateKey carrying +// key + both colliding rows (located, not a bare Bool). keyed_roster_union models the git +// clean-merge failure mode: two branches each append disjoint rows admit; overlapping path keys +// refuse. keyed_merge_row_lists is the deliberate contrast (silent first-wins, reconcile grain). +// Per-PR admission: enrolled on commit_gate_roster (GithubActionsCiJob) plus affected-set discovery +// when dag/std/ or enrolled roster carriers change. type FixtureGrant { path: String diff --git a/dag/test/claim/lambda_capture_clone_required_witness_test.dag b/dag/test/claim/lambda_capture_clone_required_witness_test.dag index f2acc9a6fb0..49a635c3871 100644 --- a/dag/test/claim/lambda_capture_clone_required_witness_test.dag +++ b/dag/test/claim/lambda_capture_clone_required_witness_test.dag @@ -4,7 +4,41 @@ import v2.std.live_tree { LiveTreeDisposition, SubstrateInputsOnly } data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data lambda_capture_clone_required_witness_note: String = "Executing floor witness, discriminating causation (not population), for v1.compiler.ownership walk_expr's ExprLambda arm: every captured binding's real inner usage is collapsed into exactly one synthetic Read edge at the enclosing scope before make_decision/build_movable_set ever see it, so a binding used only inside a returned closure's body can never reach SoleOwner and is unconditionally excluded from emit_info.movable regardless of its lexical single-use shape. THIS WAS FIRST FRAMED AS A GAP AND HAS SINCE BEEN REFUTED AS A DEFECT BY EXECUTION (Arm C, 2026-08-19, SHA 12e326028282e35c3b8fddde1c94a1259b3e7fe9): a returned Fn closure capturing a non-Copy Widget\{tag: String\} and invoked twice compiled clean with .clone() present (control build, 22.28s); hand-deleting the .clone() from the identical emitted crate and rebuilding failed with rustc error[E0507] 'cannot move out of `w`, a captured variable in an `Fn` closure' ('Fn and FnMut closures require captured values to be able to be consumed multiple times, but FnOnce closures may consume them only once'). The Copy-trap is why this receipt is trustworthy rather than vacuous: a Copy-eligible capture field (Int) would let Rust perform an implicit bitwise copy regardless of the clone, so removing the clone would compile either way and produce a false 'unnecessary' verdict -- only a non-Copy capture makes the experiment discriminate the real question. So the collapse this fixture exercises is PROVABLY REQUIRED for this shape, not provably lossy: closure invocation count is not observable from a lexical walk over the body, and emitting the identifier bare here would be an unsound optimization removing load-bearing correctness, not a redundancy. This file therefore now DEFENDS the clone rather than indicting it -- it guards against a future change that 'optimizes' the clone away for this shape. Scope, stated so it is not overclaimed by this control's passing: Arm C measured exactly one shape (a returned Fn closure over a non-Copy capture, invoked twice); a FnOnce closure invoked exactly once, and the ExprForEach arm at src/v1/ownership.dag:276, remain UNMEASURED and are not asserted safe or unsafe by this witness. Two-arm fixture through compile_dag_rust_emit_check (the per-PR enrolled real-emitter consumer, per generic_item_clone_bound_witness_test.dag's pattern): ARM A returns a param directly (no lambda) and must emit it BARE (moves_by_value true, no .clone()) -- the control that the clone is not simply blanket-emitted; ARM B returns the identical single-use param from inside a returned closure and must emit .clone() -- the behavior Arm C proved necessary. Each arm also asserts a positive structural string (the function/struct header) so a .clone()-absent zero in Arm A is paired with a confirmed nonzero emission, per DESIGN §5/4b: compile_dag_rust_emit_check returns false for both a real refusal and a not-found file, so a clean negative alone would be indistinguishable from the harness silently producing nothing. Subject is emit_var_ref's clone_value at the emitter (v1.compiler.emit_rust), NOT deref_clone and NOT the inner Rc clone at deref_clone call sites (deep-swift-570's territory, disjoint mechanism and disjoint lowering site)." +// Executing floor witness, discriminating causation (not population), for v1.compiler.ownership +// walk_expr's ExprLambda arm: every captured binding's real inner usage is collapsed into exactly +// one synthetic Read edge at the enclosing scope before make_decision/build_movable_set ever see +// it, so a binding used only inside a returned closure's body can never reach SoleOwner and is +// unconditionally excluded from emit_info.movable regardless of its lexical single-use shape. THIS +// WAS FIRST FRAMED AS A GAP AND HAS SINCE BEEN REFUTED AS A DEFECT BY EXECUTION (Arm C, 2026-08-19, +// SHA 12e326028282e35c3b8fddde1c94a1259b3e7fe9): a returned Fn closure capturing a non-Copy +// Widget{tag: String} and invoked twice compiled clean with .clone() present (control build, +// 22.28s); hand-deleting the .clone() from the identical emitted crate and rebuilding failed with +// rustc error[E0507] 'cannot move out of `w`, a captured variable in an `Fn` closure' ('Fn and +// FnMut closures require captured values to be able to be consumed multiple times, but FnOnce +// closures may consume them only once'). The Copy-trap is why this receipt is trustworthy rather +// than vacuous: a Copy-eligible capture field (Int) would let Rust perform an implicit bitwise copy +// regardless of the clone, so removing the clone would compile either way and produce a false +// 'unnecessary' verdict -- only a non-Copy capture makes the experiment discriminate the real +// question. So the collapse this fixture exercises is PROVABLY REQUIRED for this shape, not +// provably lossy: closure invocation count is not observable from a lexical walk over the body, and +// emitting the identifier bare here would be an unsound optimization removing load-bearing +// correctness, not a redundancy. This file therefore now DEFENDS the clone rather than indicting it +// -- it guards against a future change that 'optimizes' the clone away for this shape. Scope, +// stated so it is not overclaimed by this control's passing: Arm C measured exactly one shape (a +// returned Fn closure over a non-Copy capture, invoked twice); a FnOnce closure invoked exactly +// once, and the ExprForEach arm at src/v1/ownership.dag:276, remain UNMEASURED and are not asserted +// safe or unsafe by this witness. Two-arm fixture through compile_dag_rust_emit_check (the per-PR +// enrolled real-emitter consumer, per generic_item_clone_bound_witness_test.dag's pattern): ARM A +// returns a param directly (no lambda) and must emit it BARE (moves_by_value true, no .clone()) -- +// the control that the clone is not simply blanket-emitted; ARM B returns the identical single-use +// param from inside a returned closure and must emit .clone() -- the behavior Arm C proved +// necessary. Each arm also asserts a positive structural string (the function/struct header) so a +// .clone()-absent zero in Arm A is paired with a confirmed nonzero emission, per DESIGN §5/4b: +// compile_dag_rust_emit_check returns false for both a real refusal and a not-found file, so a +// clean negative alone would be indistinguishable from the harness silently producing nothing. +// Subject is emit_var_ref's clone_value at the emitter (v1.compiler.emit_rust), NOT deref_clone and +// NOT the inner Rc clone at deref_clone call sites (deep-swift-570's territory, disjoint mechanism +// and disjoint lowering site). fn w_direct_single_use_param_moves_bare() -> Bool { compile_dag_rust_emit_check( diff --git a/dag/test/claim/lambda_receiver_type_witness_test.dag b/dag/test/claim/lambda_receiver_type_witness_test.dag index 7a6c713051e..097cdbca22e 100644 --- a/dag/test/claim/lambda_receiver_type_witness_test.dag +++ b/dag/test/claim/lambda_receiver_type_witness_test.dag @@ -2,13 +2,49 @@ module test.claim.lambda_receiver_type_witness_test import gunbc.compile_diagnostic_census { CompileDiagnosticCensus, CensusObserved, CensusNotRunnable, census_blocking_rows } -data lambda_receiver_type_note: String = "A LAMBDA PARAMETER MUST RECEIVE THE TYPE ITS DECLARED CALLABLE GIVES IT. When a record field is declared fn(A) -> B and a lambda is supplied for it, the lambda's unannotated parameter is bound to A. That binding already existed; what did not exist was A being RESOLVED. MECHANISM: v1.compiler.infer_resolve resolve_node_bounded dispatches on connective, and a callable type node is Arrow -- carrying its parameter types in params and its return type in inferred, with children empty. Every arm of that dispatch passed params through verbatim, and Arrow fell into the coproduct arm, which walks children, so the arm was a no-op and neither the parameter types nor the return type were ever resolved. A parameter type that is a plain LEAF survived that anyway, because a leaf grounds through its own name downstream; a type APPLICATION -- a head with argument children and no resolved target -- did not, because resolve_scrutinee_type_node has an arm for children-with-inferred and an arm for no-children and none for children-present-inferred-absent. So the receiver reached lookup with no surface at all. MEASURED, and the arm that separates cause from symptom: the SAME receiver type reached through an ANNOTATED fn parameter compiled with 0 blocking while the callable-field spelling refused, so the defect is the callable-parameter POSITION and not the lambda binding the diagnostic names. THE FIX IS AN ARROW ARM in that same dispatch, at depth + 1 and inheriting masked, and the rendered-use-site rule resolve_param already applied to a parameterized head -- keep the authored head and args, attach the resolved target as inferred -- is extracted so both consume one authority rather than two copies (DESIGN section 3). THE DISCRIMINATING RED IS THESE TWO ARMS THEMSELVES, MEASURED, not a third arm asserting a refusal. Both were RED on the pre-fix binary -- the method probe's shape refused with 1 blocking, receiver type Node(..) -- and both are green on the post-fix binary, with the whole-closure advisory total unchanged at 536 either way, so nothing was widened to buy the green. They go red again if the propagation regresses, because each asserts a SUCCESS that requires resolution to have happened rather than the absence of a refusal from a wall; a weakened wall cannot make alg.unit produce a conforming type. TWO ABSENT-MEMBER ARMS WERE DESIGNED AND BOTH REJECTED BY READING THE PRODUCER, which is recorded because each would have been a decoration that a reviewer would have read as coverage. An absent METHOD cannot assert MethodNotFound: the wall's decidability predicate is kernel_profile_lookup, so a resolved USER product still answers MethodExistenceUndecided and the class is identical before and after. An absent FIELD cannot assert FieldNotFound either: that variant is produced only for record-literal unknown fields and pattern bindings, never for field ACCESS, which raises an InternalError carrying `no field 'x' on type 'y'` -- and the type it names is the receiver's AUTHORED name, which is the same string whether or not the receiver resolved. Both arms would have been permanently green in the wrong direction, which is worse than absent because they would have been cited as evidence the surface is established. CensusNotRunnable is a FAILURE with its own cause, never the expected red: could-not-measure and measured-nothing are different states and only one is evidence, which is why the helpers answer a negative sentinel there rather than a zero. dissolve-on: never -- permanent regression control for callable-type resolution." +// A LAMBDA PARAMETER MUST RECEIVE THE TYPE ITS DECLARED CALLABLE GIVES IT. When a record field is +// declared fn(A) -> B and a lambda is supplied for it, the lambda's unannotated parameter is bound +// to A. That binding already existed; what did not exist was A being RESOLVED. MECHANISM: +// v1.compiler.infer_resolve resolve_node_bounded dispatches on connective, and a callable type node +// is Arrow -- carrying its parameter types in params and its return type in inferred, with children +// empty. Every arm of that dispatch passed params through verbatim, and Arrow fell into the +// coproduct arm, which walks children, so the arm was a no-op and neither the parameter types nor +// the return type were ever resolved. A parameter type that is a plain LEAF survived that anyway, +// because a leaf grounds through its own name downstream; a type APPLICATION -- a head with +// argument children and no resolved target -- did not, because resolve_scrutinee_type_node has an +// arm for children-with-inferred and an arm for no-children and none for +// children-present-inferred-absent. So the receiver reached lookup with no surface at all. +// MEASURED, and the arm that separates cause from symptom: the SAME receiver type reached through +// an ANNOTATED fn parameter compiled with 0 blocking while the callable-field spelling refused, so +// the defect is the callable-parameter POSITION and not the lambda binding the diagnostic names. +// THE FIX IS AN ARROW ARM in that same dispatch, at depth + 1 and inheriting masked, and the +// rendered-use-site rule resolve_param already applied to a parameterized head -- keep the authored +// head and args, attach the resolved target as inferred -- is extracted so both consume one +// authority rather than two copies (DESIGN section 3). THE DISCRIMINATING RED IS THESE TWO ARMS +// THEMSELVES, MEASURED, not a third arm asserting a refusal. Both were RED on the pre-fix binary -- +// the method probe's shape refused with 1 blocking, receiver type Node(..) -- and both are green on +// the post-fix binary, with the whole-closure advisory total unchanged at 536 either way, so +// nothing was widened to buy the green. They go red again if the propagation regresses, because +// each asserts a SUCCESS that requires resolution to have happened rather than the absence of a +// refusal from a wall; a weakened wall cannot make alg.unit produce a conforming type. TWO +// ABSENT-MEMBER ARMS WERE DESIGNED AND BOTH REJECTED BY READING THE PRODUCER, which is recorded +// because each would have been a decoration that a reviewer would have read as coverage. An absent +// METHOD cannot assert MethodNotFound: the wall's decidability predicate is kernel_profile_lookup, +// so a resolved USER product still answers MethodExistenceUndecided and the class is identical +// before and after. An absent FIELD cannot assert FieldNotFound either: that variant is produced +// only for record-literal unknown fields and pattern bindings, never for field ACCESS, which raises +// an InternalError carrying `no field 'x' on type 'y'` -- and the type it names is the receiver's +// AUTHORED name, which is the same string whether or not the receiver resolved. Both arms would +// have been permanently green in the wrong direction, which is worse than absent because they would +// have been cited as evidence the surface is established. CensusNotRunnable is a FAILURE with its +// own cause, never the expected red: could-not-measure and measured-nothing are different states +// and only one is evidence, which is why the helpers answer a negative sentinel there rather than a +// zero. dissolve-on: never -- permanent regression control for callable-type resolution. data lamrecv_method_probe_source: String = "module lamrecv_method_probe_mod\n\nimport test.fixture.lambda_receiver_provider \{ LamrecvPayload, LamrecvAlgebra, LamrecvHolder }\n\nfn lamrecv_method(x: LamrecvPayload, y: LamrecvPayload) -> LamrecvHolder \{\n LamrecvHolder \{ run: fn(alg) \{ (alg.combine)(x, y) } }\n}\n" data lamrecv_field_probe_source: String = "module lamrecv_field_probe_mod\n\nimport test.fixture.lambda_receiver_provider \{ LamrecvPayload, LamrecvAlgebra, LamrecvHolder }\n\nfn lamrecv_field(x: LamrecvPayload) -> LamrecvHolder \{\n LamrecvHolder \{ run: fn(alg) \{ alg.unit } }\n}\n" - fn lamrecv_blocking_count(source: String) -> Int { match compile_dag_diagnostic_census(source) { CensusObserved { rows: rows } => count(census_blocking_rows(rows: rows)) @@ -16,7 +52,6 @@ fn lamrecv_blocking_count(source: String) -> Int { } } - test fn method_call_on_a_lambda_parameter_receiver_resolves() -> Bool { lamrecv_blocking_count(source: lamrecv_method_probe_source) == 0 } diff --git a/dag/test/claim/language_module_home_test.dag b/dag/test/claim/language_module_home_test.dag index c3cffd8b211..04e006e379f 100644 --- a/dag/test/claim/language_module_home_test.dag +++ b/dag/test/claim/language_module_home_test.dag @@ -85,7 +85,17 @@ test fn every_declared_home_carries_a_canonical_prefix() -> Bool { all(language_target_homes, h => h.canonical_prefix != "") } -data gate_predicate_note: String = "The gate predicate's controls. The one that matters most in practice is that THIS change's own added carriers are ADMITTED — a wall that refuses the change introducing it is a self-inflicted outage, and the only way to know is to run the real added-path list through the real predicate. THE RELATIONAL CONTROLS THAT USED TO SIT HERE WERE DELETED WITH THE PREDICATES THEY EXERCISED (operator REQUEST_CHANGES, 2026-08-05). One of them asserted that dag/extdeps/languages/html/verilog_emit.dag is admitted under the HTML home — associating that path with HTML by reading html/ OUT OF THE PATH, which is the path-to-identity fusion the module forbids, performed by the control meant to prove it never happens. A correct control names verilog_language_subject_ref and demands the Verilog prefix, and it cannot be written against a gate that receives only strings. The unregistered-directory control inverted for the same reason: gpu/ and simd/ were exceptions that bought nothing for existing files and licensed unlimited future ones, so a new file under them must now REFUSE and force the target registration." +// The gate predicate's controls. The one that matters most is that THIS change's own added +// carriers are ADMITTED — a wall refusing the change that introduces it is a self-inflicted outage, +// and only running the real added-path list through the real predicate can tell. +// THE RELATIONAL CONTROLS THAT USED TO SIT HERE WERE DELETED WITH THE PREDICATES THEY EXERCISED +// (operator REQUEST_CHANGES, 2026-08-05). One asserted that dag/extdeps/languages/html/verilog_emit.dag +// is admitted under the HTML home — reading html/ OUT OF THE PATH, the path-to-identity fusion the +// module forbids, performed by the control meant to prove it never happens. A correct control names +// verilog_language_subject_ref and demands the Verilog prefix, and cannot be written against a gate +// that receives only strings. The unregistered-directory control inverted for the same reason: gpu/ +// and simd/ were exceptions that bought nothing for existing files and licensed unlimited future +// ones, so a new file under them must now REFUSE and force the target registration. test fn this_changes_own_carriers_are_admitted() -> Bool { (added_language_paths_refused(added: [ diff --git a/dag/test/claim/language_source_scaffold_index_test.dag b/dag/test/claim/language_source_scaffold_index_test.dag index ce4f07a76e1..627da8b207d 100644 --- a/dag/test/claim/language_source_scaffold_index_test.dag +++ b/dag/test/claim/language_source_scaffold_index_test.dag @@ -17,7 +17,24 @@ import gunbc.language_source_scaffold_index { data live_tree_disposition: LiveTreeDisposition = ReadsLiveTree -data language_source_scaffold_index_test_note: String = "B2/B4/B5 control for the language-source scaffold inventory. Two distinct obligations are asserted separately. (1) DISPOSITION: every rostered blob carries a Disposition that names something — a Scaffold binding the construction that subsumes it, or a Terminal stating why it is irreducible. Because Disposition has no prose arm, an unmarked row is unwritable, so the discriminating case is a Scaffold with an empty bind. A Terminal WITH a reason is legitimate (fnv1a64 is a named irreducible kernel), so the control is deliberately not 'Terminal is bad'. The empty-bind RED control moved to dag/test/claim/where_refinement_enforcement_witness_test.dag once NonEmptyStr where non_empty is construction-enforced — an empty DeclarationRef module_path/decl_name is now unwritable at compile time rather than caught only by language_source_scaffold_row_is_dispositioned. (2) COVERAGE: the roster must actually cover its carriers. Asserting hardcoded census counts alone would let a new rt_/ct_ blob land unmarked and stay green until someone bumped the number by hand (review 43161), so coverage is read from the LIVE TREE: the rt_ and ct_ declaration counts in the carrier sources are compared against the roster, and a newly added blob reds this witness instead of sitting unrostered. The comparison is EXACT equality with no offset: an earlier version used declared == rostered + 1 to absorb ct_coercion_tests, which was itself an absorbing fallback (review 43177) — that blob is a hybrid (row-driven core via extract_coercion_tests, but it still emits a hand-authored header and aggregates three hand blobs), so it is rostered like any other and the fudge is gone." +// B2/B4/B5 control for the language-source scaffold inventory. Two distinct obligations are +// asserted separately. (1) DISPOSITION: every rostered blob carries a Disposition that names +// something — a Scaffold binding the construction that subsumes it, or a Terminal stating why it is +// irreducible. Because Disposition has no prose arm, an unmarked row is unwritable, so the +// discriminating case is a Scaffold with an empty bind. A Terminal WITH a reason is legitimate +// (fnv1a64 is a named irreducible kernel), so the control is deliberately not 'Terminal is bad'. +// The empty-bind RED control moved to dag/test/claim/where_refinement_enforcement_witness_test.dag +// once NonEmptyStr where non_empty is construction-enforced — an empty DeclarationRef +// module_path/decl_name is now unwritable at compile time rather than caught only by +// language_source_scaffold_row_is_dispositioned. (2) COVERAGE: the roster must actually cover its +// carriers. Asserting hardcoded census counts alone would let a new rt_/ct_ blob land unmarked and +// stay green until someone bumped the number by hand (review 43161), so coverage is read from the +// LIVE TREE: the rt_ and ct_ declaration counts in the carrier sources are compared against the +// roster, and a newly added blob reds this witness instead of sitting unrostered. The comparison is +// EXACT equality with no offset: an earlier version used declared == rostered + 1 to absorb +// ct_coercion_tests, which was itself an absorbing fallback (review 43177) — that blob is a hybrid +// (row-driven core via extract_coercion_tests, but it still emits a hand-authored header and +// aggregates three hand blobs), so it is rostered like any other and the fudge is gone. data runtime_rust_source_path: String = "src/v1/runtime_rust.dag" data compiler_tests_rust_source_path: String = "src/v1/compiler_tests_rust.dag" diff --git a/dag/test/claim/language_target_identity_witness_test.dag b/dag/test/claim/language_target_identity_witness_test.dag index 24b2e1a886f..da9ec434c66 100644 --- a/dag/test/claim/language_target_identity_witness_test.dag +++ b/dag/test/claim/language_target_identity_witness_test.dag @@ -59,7 +59,17 @@ import std.language_target_identity { integrity_violation_count, } -data language_target_identity_witness_note: String = "GREEN and discriminating RED controls for the language-target join kernel (operator verdict 2026-08-04). Every RED here is a state the census would otherwise report as a resolved target, which is the failure this join exists to make unwritable: a surface with no identity, a surface naming a subject nobody registered, two registrations of one subject, and a surface two rows disagree about. The Bash subject is the live specimen and is referenced SYMBOLICALLY through extdeps.languages.bash.subject rather than by spelling its module path in a string, so a rename of that declaration breaks this witness rather than silently passing (DESIGN section 3 cite-the-symbol). WHAT THIS WITNESS DOES NOT COVER, stated rather than implied: these fns are pure in the rows handed to them, so nothing here proves the surface census is COMPLETE — a target-bearing surface nobody authored a row for is invisible to every assertion below. Population completeness is the registry totality wall's job and is not established here." +// GREEN and discriminating RED controls for the language-target join kernel (operator verdict +// 2026-08-04). Every RED here is a state the census would otherwise report as a resolved target, +// which is the failure this join exists to make unwritable: a surface with no identity, a surface +// naming a subject nobody registered, two registrations of one subject, and a surface two rows +// disagree about. The Bash subject is the live specimen and is referenced SYMBOLICALLY through +// extdeps.languages.bash.subject rather than by spelling its module path in a string, so a rename +// of that declaration breaks this witness rather than silently passing (DESIGN section 3 +// cite-the-symbol). WHAT THIS WITNESS DOES NOT COVER, stated rather than implied: these fns are +// pure in the rows handed to them, so nothing here proves the surface census is COMPLETE — a +// target-bearing surface nobody authored a row for is invisible to every assertion below. +// Population completeness is the registry totality wall's job and is not established here. fn ref_of(module_path: String, decl_name: String) -> DeclarationRef { DeclarationRef { @@ -127,7 +137,15 @@ test fn green_clean_join_reports_no_violations() -> Bool { ) } -data neutral_key_note: String = "THE NEUTRAL-KEY CONTROL, and it is the discriminating one for the P0 the review relayed on 2026-08-04. The kernel previously keyed every surface row, resolution outcome, tally and projection on an EXTERNAL subject reference while its own target_grounding_law concluded canonical identity is a DeclarationRef — so a project-grounded target had to be wrapped in a carrier documented as pointing at an independently governed upstream subject, asserting a governance it does not have. The observable consequence was that project targets could not be projected at all. This control joins a PROJECT-grounded registration through the same fold as the external one, so the two arms are proven to share one key by execution rather than by the types merely lining up." +// THE NEUTRAL-KEY CONTROL, and it is the discriminating one for the P0 the review relayed on +// 2026-08-04. The kernel previously keyed every surface row, resolution outcome, tally and +// projection on an EXTERNAL subject reference while its own target_grounding_law concluded +// canonical identity is a DeclarationRef — so a project-grounded target had to be wrapped in a +// carrier documented as pointing at an independently governed upstream subject, asserting a +// governance it does not have. The observable consequence was that project targets could not be +// projected at all. This control joins a PROJECT-grounded registration through the same fold as the +// external one, so the two arms are proven to share one key by execution rather than by the types +// merely lining up. test fn green_project_grounded_target_joins_through_the_same_key() -> Bool { let row = LanguageTargetSurfaceRow { @@ -214,7 +232,14 @@ test fn red_duplicate_registration_refuses() -> Bool { }) } -data duplicate_registration_grain_control_note: String = "The grain control for review 48205's first finding. red_duplicate_registration_refuses above proves the class is EMITTED, which stayed true while the count was wrong — three registrations of one subject produced three violations for one defect, because the fold reported per ROW rather than per SUBJECT. Emission and grain are different properties and only the first had a control, which is exactly how the surface-side version of this bug survived until it was fixed in the same module. Three rather than two registrations is deliberate: a per-row implementation returns 2 for two rows and 3 for three, so pinning at three discriminates against both the old shape and an off-by-one dedup." +// The grain control for review 48205's first finding. red_duplicate_registration_refuses above +// proves the class is EMITTED, which stayed true while the count was wrong — three registrations of +// one subject produced three violations for one defect, because the fold reported per ROW rather +// than per SUBJECT. Emission and grain are different properties and only the first had a control, +// which is exactly how the surface-side version of this bug survived until it was fixed in the same +// module. Three rather than two registrations is deliberate: a per-row implementation returns 2 for +// two rows and 3 for three, so pinning at three discriminates against both the old shape and an +// off-by-one dedup. test fn duplicate_registration_reported_once_not_per_row() -> Bool { let thrice = [bash_registration(), bash_registration(), bash_registration()] @@ -267,7 +292,13 @@ test fn red_two_rows_disagreeing_about_one_surface_refuse_as_ambiguous() -> Bool } } -data outcome_naming_note: String = "This arm was called TargetSubjectUnresolvable while the fold that produces it performs NO declaration resolution — it tests registry membership. So 'names a valid subject nobody registered' and 'names a DeclarationRef that resolves nowhere on disk' were one arm wearing the second's name, and the law claimed the second reached it. Renamed to TargetNotRegistered, which is what is actually decided. The on-disk resolution outcome is deliberately NOT minted as an empty variant beside it: a typed arm with no producer is the inert-carrier defect this same PR already had to close once, and disk resolution belongs to the extdeps roster machinery." +// This arm was called TargetSubjectUnresolvable while the fold that produces it performs NO +// declaration resolution — it tests registry membership. So 'names a valid subject nobody +// registered' and 'names a DeclarationRef that resolves nowhere on disk' were one arm wearing the +// second's name, and the law claimed the second reached it. Renamed to TargetNotRegistered, which +// is what is actually decided. The on-disk resolution outcome is deliberately NOT minted as an +// empty variant beside it: a typed arm with no producer is the inert-carrier defect this same PR +// already had to close once, and disk resolution belongs to the extdeps roster machinery. test fn red_surface_naming_subject_absent_from_registry_is_not_registered() -> Bool { let rows = [ @@ -357,7 +388,13 @@ test fn multi_target_surface_reported_once_not_per_row() -> Bool { }) == 1 } -data distinct_target_dedup_note: String = "THE CONTROL THE SUITE WAS MISSING (review relayed 2026-08-04). surface_named_targets pushed every occurrence with no deduplication, so two rows naming the SAME target reached TallyMany and were reported as a surface joining multiple targets — false, because that surface has one target and a duplicated row. The old suite covered two genuinely different targets and a three-row case, both of which pass either way, so nothing distinguished 'two identities' from 'two rows'. These two controls pin both halves: same locus plus same subject twice must NOT be ambiguity, and must instead be reported as the duplication it is." +// THE CONTROL THE SUITE WAS MISSING (review relayed 2026-08-04). surface_named_targets pushed every +// occurrence with no deduplication, so two rows naming the SAME target reached TallyMany and were +// reported as a surface joining multiple targets — false, because that surface has one target and a +// duplicated row. The old suite covered two genuinely different targets and a three-row case, both +// of which pass either way, so nothing distinguished 'two identities' from 'two rows'. These two +// controls pin both halves: same locus plus same subject twice must NOT be ambiguity, and must +// instead be reported as the duplication it is. fn duplicated_same_target_rows() -> List { [ @@ -411,7 +448,14 @@ test fn red_duplicated_surface_row_emits_duplicate_locus_not_multi_target() -> B dup && !multi } -data accounting_discrimination_note: String = "THE CONTROLS THAT MAKE THE ACCOUNTING PREDICATE MEAN SOMETHING. Its predecessor compared TOTAL violations to census rows with a <=, so it held for any census and would have held against an empty violation list. The replacement is an exact equality between identified rows plus reported missing-identity rows and the census, and these controls plant each way it can break: a row naming an unregistered subject is in NEITHER class, so the sum falls short; and the integrity wall is asserted separately so the two cannot mask each other. The second control is the one that would have caught the original defect — under the old predicate it passes, under this one it fails." +// THE CONTROLS THAT MAKE THE ACCOUNTING PREDICATE MEAN SOMETHING. Its predecessor compared TOTAL +// violations to census rows with a <=, so it held for any census and would have held against an +// empty violation list. The replacement is an exact equality between identified rows plus reported +// missing-identity rows and the census, and these controls plant each way it can break: a row +// naming an unregistered subject is in NEITHER class, so the sum falls short; and the integrity +// wall is asserted separately so the two cannot mask each other. The second control is the one that +// would have caught the original defect — under the old predicate it passes, under this one it +// fails. fn clean_population() -> List { [ diff --git a/dag/test/claim/language_target_registry_totality_test.dag b/dag/test/claim/language_target_registry_totality_test.dag index 064f5419f51..c76ceb6e1ff 100644 --- a/dag/test/claim/language_target_registry_totality_test.dag +++ b/dag/test/claim/language_target_registry_totality_test.dag @@ -48,7 +48,19 @@ import gunbc.language_target_registry { registry_integrity_holds, } -data registry_totality_witness_note: String = "Controls for the registry ACCOUNTING ratchet and the separate INTEGRITY wall — the no-invisible-remainder property, not a completion claim. The ratchet's whole content is that every declared surface is either joined to a registered subject or reported as an exact unidentified row, as an EXACT equality; the wall's is that malformed join input is exactly zero. They are asserted separately because summing them is precisely what made the predecessor undiscriminating: it compared total violations to census rows with a <=, which held for any census and would have held against an empty violation list. WHAT NO ASSERTION HERE ESTABLISHES, restated from the registry's own maximum-conclusion row because a witness is exactly where that gets forgotten: the DECLARED population is not proven complete against the repository, and a declared row is not proven to name a real surface — three census rows were found on 2026-08-04 to be file paths transcribed as module paths. All six authorities are hand-declared, so a target-bearing surface nobody wrote a row for is invisible here. These are ratchet controls; none of them is completion evidence for any target." +// Controls for the registry ACCOUNTING ratchet and the separate INTEGRITY wall — the +// no-invisible-remainder property, not a completion claim. The ratchet's whole content is that +// every declared surface is either joined to a registered subject or reported as an exact +// unidentified row, as an EXACT equality; the wall's is that malformed join input is exactly zero. +// They are asserted separately because summing them is precisely what made the predecessor +// undiscriminating: it compared total violations to census rows with a <=, which held for any +// census and would have held against an empty violation list. WHAT NO ASSERTION HERE ESTABLISHES, +// restated from the registry's own maximum-conclusion row because a witness is exactly where that +// gets forgotten: the DECLARED population is not proven complete against the repository, and a +// declared row is not proven to name a real surface — three census rows were found on 2026-08-04 to +// be file paths transcribed as module paths. All six authorities are hand-declared, so a +// target-bearing surface nobody wrote a row for is invisible here. These are ratchet controls; none +// of them is completion evidence for any target. test fn registry_census_is_nonempty_and_accounting_is_exact() -> Bool { registry_accounting_total() && surface_census_row_count() > 0 @@ -58,7 +70,11 @@ test fn registry_integrity_wall_holds_with_zero_malformed_rows() -> Bool { registry_integrity_holds() && registry_integrity_violation_count() == 0 } -data accounting_partition_note: String = "The exact equality restated on the live registry: identified plus unidentified equals the census, with both parts strictly positive. Strict positivity on BOTH sides is what stops either arm from being vacuously satisfied — an all-unidentified census would make the join look total while joining nothing, and an all-identified one would hide the remainder the ratchet exists to display." +// The exact equality restated on the live registry: identified plus unidentified equals the census, +// with both parts strictly positive. Strict positivity on BOTH sides is what stops either arm from +// being vacuously satisfied — an all-unidentified census would make the join look total while +// joining nothing, and an all-identified one would hide the remainder the ratchet exists to +// display. test fn identified_and_unidentified_partition_the_census_exactly() -> Bool { identified_surface_count() + unidentified_surface_count() == surface_census_row_count() @@ -79,7 +95,17 @@ test fn bash_vocabulary_surface_joins_the_bash_subject() -> Bool { } } -data vocabulary_surface_premise_inversion_note: String = "THIS TEST'S PREMISE INVERTED WHEN THE SUBJECTS LANDED, AND BOTH ARMS ARE KEPT LIVE. It previously asserted that extdeps.languages.typescript.program is visibly UNIDENTIFIED, which was true and worth pinning while Bash was the only registered subject — the TypeScript target vocabulary was confined by a lens around a module prefix with no upstream authority behind it. TypeScript is now a registered, cited subject, so that surface resolves, and asserting it is still unidentified would be asserting the registry had not done its job. The assertion is therefore re-aimed at the join it now makes. The unidentified arm is NOT retired with it — DESIGN section 4b's dissolution rule keeps the discriminating control enrolled when a class climbs — so machine_code takes over that duty in the test below, and it is a better control than the old one because its unidentified status is PERMANENT until the surface is decomposed, rather than pending someone authoring a citation." +// THIS TEST'S PREMISE INVERTED WHEN THE SUBJECTS LANDED, AND BOTH ARMS ARE KEPT LIVE. It previously +// asserted that extdeps.languages.typescript.program is visibly UNIDENTIFIED, which was true and +// worth pinning while Bash was the only registered subject — the TypeScript target vocabulary was +// confined by a lens around a module prefix with no upstream authority behind it. TypeScript is now +// a registered, cited subject, so that surface resolves, and asserting it is still unidentified +// would be asserting the registry had not done its job. The assertion is therefore re-aimed at the +// join it now makes. The unidentified arm is NOT retired with it — DESIGN section 4b's dissolution +// rule keeps the discriminating control enrolled when a class climbs — so machine_code takes over +// that duty in the test below, and it is a better control than the old one because its unidentified +// status is PERMANENT until the surface is decomposed, rather than pending someone authoring a +// citation. test fn typescript_vocabulary_surface_resolves_to_the_typescript_subject() -> Bool { match resolve_target_for_surface( @@ -130,10 +156,25 @@ type GroundingArmsSeen { project: Bool } -data both_arms_oracle_note: String = "This asserts what the test's NAME claims — that both grounding arms are inhabited — and is true at 3 targets or 300. It previously asserted registered_target_count() == 3, a literal copied from the tree standing in for the property, which DESIGN section 5 names directly: automating that literal collapses it to measure() == measure(), so the manual update was the test's entire content, and it would have gone red the moment the registry grew rather than when the property broke. Caught by fierce-heron-301 on the stacked PR and by cursor review 48132 here." - -data projection_direction_note: String = "Requirement D's controls, and the property they pin is DIRECTION rather than content: a projection FROM a registered subject is total, while a lookup INTO the registry by a legacy key REFUSES when nothing claims it. That asymmetry is what demotes LanguageId from an identity to an attribute. THIS NOTE PREVIOUSLY SAID 'rust, go, python and typescript all resolve nowhere, because none of them has a canonical subject yet' — true when written, false as of the D0 registrations, and it contradicted the rewritten assertions a few lines below in this same file (caught by review 48113). All four now resolve, because all four are registered subjects carrying a legacy id. The refusal arm is NOT weakened by that: it is now exercised by two live cases instead of a vacuous one — an id no projection claims at all, and the sharper case of 'bash', which refuses even though GNU Bash is a fully registered, cited subject, because std.languages has no bash row. A key that cannot name a registered subject is definitionally not that subject's identity, and that is now demonstrated on the corpus rather than asserted from an empty table." +// This asserts what the test's NAME claims — that both grounding arms are inhabited — and is true +// at 3 targets or 300. It previously asserted registered_target_count() == 3, a literal copied from +// the tree standing in for the property, which DESIGN section 5 names directly: automating that +// literal collapses it to measure() == measure(), so the manual update was the test's entire +// content, and it would have gone red the moment the registry grew rather than when the property +// broke. Caught by fierce-heron-301 on the stacked PR and by cursor review 48132 here. +// Requirement D's controls, and the property they pin is DIRECTION rather than content: a +// projection FROM a registered subject is total, while a lookup INTO the registry by a legacy key +// REFUSES when nothing claims it. That asymmetry is what demotes LanguageId from an identity to an +// attribute. THIS NOTE PREVIOUSLY SAID 'rust, go, python and typescript all resolve nowhere, +// because none of them has a canonical subject yet' — true when written, false as of the D0 +// registrations, and it contradicted the rewritten assertions a few lines below in this same file +// (caught by review 48113). All four now resolve, because all four are registered subjects carrying +// a legacy id. The refusal arm is NOT weakened by that: it is now exercised by two live cases +// instead of a vacuous one — an id no projection claims at all, and the sharper case of 'bash', +// which refuses even though GNU Bash is a fully registered, cited subject, because std.languages +// has no bash row. A key that cannot name a registered subject is definitionally not that subject's +// identity, and that is now demonstrated on the corpus rather than asserted from an empty table. test fn projection_from_registered_subject_is_total() -> Bool { match bash_display_name() { @@ -161,7 +202,16 @@ test fn every_projection_hangs_off_a_registered_subject() -> Bool { every_projection_subject_is_registered() } -data legacy_id_direction_note: String = "THE SHARPEST AVAILABLE STATEMENT OF 'A LanguageId IS NOT AN IDENTITY', and it only became provable on a real row when the subjects landed. This test used to look up 'rust' and assert it REFUSED — true only because no projection claimed any legacy id yet, so it was really asserting the projection table was empty. Now rust IS claimed, and asserting refusal would assert the projection table is still broken. The two assertions below state the actual direction law from language_target_projection_law instead, and the second is the load-bearing one: GNU Bash is a fully registered, cited subject, and looking up 'bash' STILL REFUSES — because std.languages carries rust, go, python and typescript rows and no bash row, so the target this repository emits most has no legacy id at all. A key that cannot name a registered subject is definitionally not that subject's identity. That is a live corpus fact doing the work a fixture used to fake." +// THE SHARPEST AVAILABLE STATEMENT OF 'A LanguageId IS NOT AN IDENTITY', and it only became +// provable on a real row when the subjects landed. This test used to look up 'rust' and assert it +// REFUSED — true only because no projection claimed any legacy id yet, so it was really asserting +// the projection table was empty. Now rust IS claimed, and asserting refusal would assert the +// projection table is still broken. The two assertions below state the actual direction law from +// language_target_projection_law instead, and the second is the load-bearing one: GNU Bash is a +// fully registered, cited subject, and looking up 'bash' STILL REFUSES — because std.languages +// carries rust, go, python and typescript rows and no bash row, so the target this repository emits +// most has no legacy id at all. A key that cannot name a registered subject is definitionally not +// that subject's identity. That is a live corpus fact doing the work a fixture used to fake. test fn claimed_legacy_language_id_projects_to_its_subject() -> Bool { match lookup_language_id(language_id: "rust") { diff --git a/dag/test/claim/language_target_subject_registration_test.dag b/dag/test/claim/language_target_subject_registration_test.dag index 6c0223d723a..e383eb4e082 100644 --- a/dag/test/claim/language_target_subject_registration_test.dag +++ b/dag/test/claim/language_target_subject_registration_test.dag @@ -39,7 +39,18 @@ import gunbc.language_target_registry { } import gunbc.extdeps_scope_frontier { scope_carrier_paths, scope_frontier_strings_contain } -data subject_registration_witness_note: String = "D0's executed evidence: the ~20 external language-target subjects exist as CITED scope carriers and are registered. The assertions below are deliberately about STRUCTURAL properties that a hand-authored row cannot fake into truth — every grounding carries at least one citation, every registration's subject is DERIVED from its grounding rather than authored beside it, no subject is registered twice, and every carrier path is enrolled in the roster the placement gate reads. WHAT NO ASSERTION HERE ESTABLISHES, stated because a witness is where this gets forgotten: that a cited locator is the CORRECT authority for its subject is not machine-checkable — it was established by fetching each locator live on 2026-08-04 and confirming its title and publisher, and it is recorded in each carrier's subject note. A test can prove a citation EXISTS; only that fetch could prove it is the right one. The three targets whose upstreams could not be read are asserted ABSENT from the registry and PRESENT in the findings, which is the executable half of verify-or-refuse." +// D0's executed evidence: the ~20 external language-target subjects exist as CITED scope carriers +// and are registered. The assertions below are deliberately about STRUCTURAL properties that a +// hand-authored row cannot fake into truth — every grounding carries at least one citation, every +// registration's subject is DERIVED from its grounding rather than authored beside it, no subject +// is registered twice, and every carrier path is enrolled in the roster the placement gate reads. +// WHAT NO ASSERTION HERE ESTABLISHES, stated because a witness is where this gets forgotten: that a +// cited locator is the CORRECT authority for its subject is not machine-checkable — it was +// established by fetching each locator live on 2026-08-04 and confirming its title and publisher, +// and it is recorded in each carrier's subject note. A test can prove a citation EXISTS; only that +// fetch could prove it is the right one. The three targets whose upstreams could not be read are +// asserted ABSENT from the registry and PRESENT in the findings, which is the executable half of +// verify-or-refuse. fn registration_citation_count(r: LanguageTargetRegistration) -> Int { match r.grounding { @@ -71,7 +82,12 @@ test fn no_subject_is_registered_twice() -> Bool { }) } -data roster_enrollment_note: String = "The placement gate refuses any dag/extdeps .dag file a change ADDS that is in neither scope_carrier_paths nor scope_machinery_exempt_paths, and it is per-PR merge-gated. This asserts the roster rows for the new subject carriers are present, which is the half that can be checked without a live tree walk; that each path RESOLVES on disk is roster_paths_resolve_on_disk's job in the scope witness, and that every file on disk is rostered is the wet live-cover witness's. Three separate questions, three separate homes, none of them widened to cover another." +// The placement gate refuses any dag/extdeps .dag file a change ADDS that is in neither +// scope_carrier_paths nor scope_machinery_exempt_paths, and it is per-PR merge-gated. This asserts +// the roster rows for the new subject carriers are present, which is the half that can be checked +// without a live tree walk; that each path RESOLVES on disk is roster_paths_resolve_on_disk's job +// in the scope witness, and that every file on disk is rostered is the wet live-cover witness's. +// Three separate questions, three separate homes, none of them widened to cover another. data expected_subject_carrier_paths: List = [ "dag/extdeps/languages/bash/subject.dag", @@ -106,7 +122,12 @@ test fn every_subject_carrier_is_enrolled_in_the_scope_roster() -> Bool { scope_frontier_strings_contain(xs: scope_carrier_paths, s: p)) } -data disposition_coverage_note: String = "Every arm of TargetDisposition is inhabited by a real registered target, so no arm is dead code: Active (the P0/P1 targets under way), GovernedByContract (Rust, whose status this registry REFERENCES from the self-host frontier rather than recomputing), DecisionPending (ECMAScript and C++, the two targets DESIGN lists as open operator decisions), MaintenanceOnly (the structured media), and Parked (everything with a stated reason and no work in progress). An unexercised coproduct arm is untested code." +// Every arm of TargetDisposition is inhabited by a real registered target, so no arm is dead code: +// Active (the P0/P1 targets under way), GovernedByContract (Rust, whose status this registry +// REFERENCES from the self-host frontier rather than recomputing), DecisionPending (ECMAScript and +// C++, the two targets DESIGN lists as open operator decisions), MaintenanceOnly (the structured +// media), and Parked (everything with a stated reason and no work in progress). An unexercised +// coproduct arm is untested code. fn disposition_arm_present(pick: fn(LanguageTargetRegistration) -> Bool) -> Bool { fold(registered_language_targets, init: false, f: fn(acc, r) { acc || pick(r) }) @@ -196,7 +217,11 @@ test fn filed_legacy_label_findings_are_populated() -> Bool { }) } -data runtime_binding_split_note: String = "The SPICE split, asserted as a PROPERTY rather than as two names. The medium and the runtime must be DISTINCT subjects, the binding must relate exactly those two, and — the discriminating part — the runtime must NOT be registered as a language target. If someone re-registers ngspice as a target, the last assertion reds; that is the regression this witness exists to catch, because re-fusing them would look harmless row by row." +// The SPICE split, asserted as a PROPERTY rather than as two names. The medium and the runtime must +// be DISTINCT subjects, the binding must relate exactly those two, and — the discriminating part — +// the runtime must NOT be registered as a language target. If someone re-registers ngspice as a +// target, the last assertion reds; that is the regression this witness exists to catch, because +// re-fusing them would look harmless row by row. test fn spice_medium_and_ngspice_runtime_are_distinct_subjects() -> Bool { !declaration_ref_eq(a: spice_netlist_language_subject_ref, b: ngspice_simulator_subject_ref) diff --git a/dag/test/claim/legacy_baseline_capture_witness_test.dag b/dag/test/claim/legacy_baseline_capture_witness_test.dag index 4ca48d66b86..c65a142d3bf 100644 --- a/dag/test/claim/legacy_baseline_capture_witness_test.dag +++ b/dag/test/claim/legacy_baseline_capture_witness_test.dag @@ -52,11 +52,11 @@ type LbcTestOutcome = LbcObserved | LbcUnobserved -// THE FIXTURE CANNOT NAME A COMMIT WITHOUT GOING THROUGH THE VALIDATING CONSTRUCTOR, which is the -// regrounding working rather than a nuisance: there is no cast from text to GitObjectId, so an -// arm below cannot smuggle in a malformed base to see what happens. The transport and the git id -// both refuse, so every arm carries a fixture-refused branch -- collapsing those into a capture -// verdict would let a fixture that never reached the capture read like one that reached it. +// THE FIXTURE CANNOT NAME A COMMIT WITHOUT GOING THROUGH THE VALIDATING CONSTRUCTOR — the +// regrounding working, not a nuisance: there is no cast from text to GitObjectId, so an arm below +// cannot smuggle in a malformed base. The transport and the git id both refuse, so every arm +// carries a fixture-refused branch -- collapsing those into a capture verdict would let a fixture +// that never reached the capture read like one that did. type LbcOutcome = LbcComputed { verdict: String } | LbcFixtureRefused diff --git a/dag/test/claim/legacy_binding_tap_coverage_witness_test.dag b/dag/test/claim/legacy_binding_tap_coverage_witness_test.dag index 5068591ae80..60ed9680be6 100644 --- a/dag/test/claim/legacy_binding_tap_coverage_witness_test.dag +++ b/dag/test/claim/legacy_binding_tap_coverage_witness_test.dag @@ -18,7 +18,26 @@ import gunbc.legacy_binding_tap_coverage_census { tap_coverage_census, tap_coverage_standing, tap_coverage_sites, tap_coverage_refusals, } -data legacy_binding_tap_coverage_witness_note: String = "THE DERIVATION AND THE MEASURED ROSTER. The mechanism half matters more than usual here because the standing's four counts are DERIVED from two axes rather than stored: tappable, the two REMEDY counts and answers-nothing are computed at read time from occurrence identity and target identity, so nothing can transcribe a verdict that disagrees with the facts beside it. A suite that only executed the production roster would leave that derivation untested in exactly the direction that matters -- a site becoming tappable, or ceasing to be, without the count moving.\n\nTHE FOUR-CORNER CONTROL IS THE LOAD-BEARING ONE. Tappable requires BOTH halves at the SAME site, and either half alone is worthless: an exact target with no occurrence identity cannot be attributed to the reference that asked for it, and an exact occurrence with an erased target records that something was selected without recording what. Three of the four corners must therefore be non-tappable, and a conjunction written as a disjunction passes every single-axis test.\n\nTHE REMEDY COUNTS ARE ASSERTED SEPARATELY AND THEY OVERLAP. This suite first asserted ONE not-tappable count of three over those same corners, which permanently ratified a conflation the census exists to refuse: an occurrence-exact site whose target was erased owes OUTCOME WIDENING, not occurrence threading. Two counts of two read the same corners correctly, and they deliberately do not sum to the non-tappable total -- a site deficient on both axes owes both repairs, so forcing a partition would be the same collapse in a tidier shape." +// THE DERIVATION AND THE MEASURED ROSTER. The mechanism half matters more than usual here because +// the standing's four counts are DERIVED from two axes rather than stored: tappable, the two REMEDY +// counts and answers-nothing are computed at read time from occurrence identity and target +// identity, so nothing can transcribe a verdict that disagrees with the facts beside it. A suite +// that only executed the production roster would leave that derivation untested in exactly the +// direction that matters -- a site becoming tappable, or ceasing to be, without the count moving. +// +// THE FOUR-CORNER CONTROL IS THE LOAD-BEARING ONE. Tappable requires BOTH halves at the SAME site, +// and either half alone is worthless: an exact target with no occurrence identity cannot be +// attributed to the reference that asked for it, and an exact occurrence with an erased target +// records that something was selected without recording what. Three of the four corners must +// therefore be non-tappable, and a conjunction written as a disjunction passes every single-axis +// test. +// +// THE REMEDY COUNTS ARE ASSERTED SEPARATELY AND THEY OVERLAP. This suite first asserted ONE +// not-tappable count of three over those same corners, which permanently ratified a conflation the +// census exists to refuse: an occurrence-exact site whose target was erased owes OUTCOME WIDENING, +// not occurrence threading. Two counts of two read the same corners correctly, and they +// deliberately do not sum to the non-tappable total -- a site deficient on both axes owes both +// repairs, so forcing a partition would be the same collapse in a tidier shape. fn nes(s: String) -> NonEmptyStr { s as NonEmptyStr } diff --git a/dag/test/claim/legacy_test_behavior_disposition_acceptance_test.dag b/dag/test/claim/legacy_test_behavior_disposition_acceptance_test.dag index e7fc2e27e1d..7b415e288d1 100644 --- a/dag/test/claim/legacy_test_behavior_disposition_acceptance_test.dag +++ b/dag/test/claim/legacy_test_behavior_disposition_acceptance_test.dag @@ -8,7 +8,13 @@ import v2.std.live_tree { LiveTreeDisposition, ReadsLiveTree } data live_tree_disposition: LiveTreeDisposition = ReadsLiveTree -data legacy_test_behavior_acceptance_note: String = "THE CLOSING VALIDATION FOR v1-test-migration. It is RED on purpose while any discovered legacy #[test] function lacks exactly one admitted behavior disposition. Unlike the diff-scoped deletion guard, doing no migration work cannot make this pass: the live legacy-function population is independently discovered, unclassified is its set difference from the disposition graph, CoveredByWitness references must resolve to discovered floor `test fn`s, and stale or duplicate dispositions refuse. The numeric live count is observation only; zero set difference is the contract." +// THE CLOSING VALIDATION FOR v1-test-migration. It is RED on purpose while any discovered legacy +// #[test] function lacks exactly one admitted behavior disposition. Unlike the diff-scoped deletion +// guard, doing no migration work cannot make this pass: the live legacy-function population is +// independently discovered, unclassified is its set difference from the disposition graph, +// CoveredByWitness references must resolve to discovered floor `test fn`s, and stale or duplicate +// dispositions refuse. The numeric live count is observation only; zero set difference is the +// contract. data legacy_test_behavior_acceptance_dissolution_note: String = "DISSOLVES BY GREENING, never deletion. When the last discovered legacy behavior receives an admitted disposition, this witness becomes green and its QuarantineProbeExpectRed exclusion and known-red probe rows must be removed in the same change. The witness then joins ordinary DiscoverySelection as the permanent regression wall." diff --git a/dag/test/claim/live_deploy/candidate_checkout_witness_test.dag b/dag/test/claim/live_deploy/candidate_checkout_witness_test.dag index 96ce050a52a..b4208e47f41 100644 --- a/dag/test/claim/live_deploy/candidate_checkout_witness_test.dag +++ b/dag/test/claim/live_deploy/candidate_checkout_witness_test.dag @@ -227,7 +227,28 @@ test fn no_ignored_files_yields_no_deployed_paths() -> Bool { // ---------------------------------------------------------------- the boundary, executed once by hand -data ignored_deployed_wet_receipt: String = "EXECUTED 2026-08-07 AGAINST HEAD 094c44b ON THE REAL DEPLOYING CHECKOUT, BECAUSE THE WITNESSES ABOVE CANNOT CATCH A WRONG GIT FLAG. Everything above this line feeds synthetic fields to scan_ignored_deployed_paths; it proves the parser and the scope filter, and it would have passed just as green while the operation asked Git the wrong question — which is exactly the defect this axis exists to repair, one level up.\\n\\nRECIPE. A .dag file was written under a source root, added to .git/info/exclude so Git classified it as ignored rather than untracked, and observe_candidate_release() was evaluated through `gunbc run` against that checkout.\\n\\nOBSERVED, in one refusal: `untracked-deployed=(none) ignored-deployed=dag/test/claim/manual_candidate_wet_probe.dag`. The same file was confirmed ABSENT from `git status --porcelain=v1 -z --untracked-files=all` in the same tree — so before this axis existed the admission read that tree as clean and would have returned CandidateObserved, and the deploy would have installed a .dag file inside a source root that HEAD does not name. The positive and negative halves fell out of the same run at real scale: the checkout carried 1368 ignored paths, 1367 of them under target/, and exactly one reached the refusal.\\n\\nWHAT IS STILL OWED, so this is not read as more than it is: the run was performed by hand and is not enrolled. An enrolled control needs the Git inspection operations to accept a working directory so they can be pointed at a constructed temporary repository — today they run in the process cwd, which is the deploying checkout itself, so a test cannot author its own dirty state without dirtying the tree it runs in. That is a modeling change to extdeps.git.inspect, not a test-harness trick, and it is the dissolution trigger for this receipt. Until then the axis is established by this receipt at one head plus the unit controls above, and is not defended against regression by execution." +// EXECUTED 2026-08-07 AGAINST HEAD 094c44b ON THE REAL DEPLOYING CHECKOUT, BECAUSE THE WITNESSES +// ABOVE CANNOT CATCH A WRONG GIT FLAG. Everything above this line feeds synthetic fields to +// scan_ignored_deployed_paths; it proves the parser and the scope filter, and it would have passed +// just as green while the operation asked Git the wrong question — which is exactly the defect this +// axis exists to repair, one level up.\n\nRECIPE. A .dag file was written under a source root, +// added to .git/info/exclude so Git classified it as ignored rather than untracked, and +// observe_candidate_release() was evaluated through `gunbc run` against that checkout.\n\nOBSERVED, +// in one refusal: `untracked-deployed=(none) +// ignored-deployed=dag/test/claim/manual_candidate_wet_probe.dag`. The same file was confirmed +// ABSENT from `git status --porcelain=v1 -z --untracked-files=all` in the same tree — so before +// this axis existed the admission read that tree as clean and would have returned +// CandidateObserved, and the deploy would have installed a .dag file inside a source root that HEAD +// does not name. The positive and negative halves fell out of the same run at real scale: the +// checkout carried 1368 ignored paths, 1367 of them under target/, and exactly one reached the +// refusal.\n\nWHAT IS STILL OWED, so this is not read as more than it is: the run was performed by +// hand and is not enrolled. An enrolled control needs the Git inspection operations to accept a +// working directory so they can be pointed at a constructed temporary repository — today they run +// in the process cwd, which is the deploying checkout itself, so a test cannot author its own dirty +// state without dirtying the tree it runs in. That is a modeling change to extdeps.git.inspect, not +// a test-harness trick, and it is the dissolution trigger for this receipt. Until then the axis is +// established by this receipt at one head plus the unit controls above, and is not defended against +// regression by execution. // ---------------------------------------------------------------- the refusal carries the location diff --git a/dag/test/claim/live_deploy/deploy_release_fixture.dag b/dag/test/claim/live_deploy/deploy_release_fixture.dag index 9504f4d5e03..fc155bf3322 100644 --- a/dag/test/claim/live_deploy/deploy_release_fixture.dag +++ b/dag/test/claim/live_deploy/deploy_release_fixture.dag @@ -2,12 +2,31 @@ module test.claim.live_deploy.deploy_release_fixture import std.types { CommitSha, String } -data deploy_release_fixture_note: String = "ONE FIXTURE REVISION FOR EVERY DEPLOY WITNESS, DECLARED HERE AND NOWHERE ELSE. The launch revision is now an input to the emitted unit, the readiness comparison, and the apply fold, so every deploy witness needs one — and a per-file constant would be the same fact spelled once per test file, which is the dual representation DESIGN section 3 forbids applied to the witness corpus. A golden that pins ExecStart would then be pinned against one file's spelling while a sibling asserted another, and the two could drift without either failing.\\n\\nIT LIVES UNDER dag/test/ SO IT CANNOT REACH PRODUCTION. A fixture sha declared beside the emitter would sit on the same import surface the deploy path uses; here the only modules that can name it are witnesses. The production path has no constant revision at all — it observes one — which is the property that keeps a plausible-looking placeholder from ever being emitted at a real host.\\n\\nTHE VALUES ARE VALID BY SHAPE AND OBVIOUSLY SYNTHETIC BY CONTENT. Each is 40 lowercase hex digits, so it passes the same validation a real object name does and the witnesses exercise the accepting path rather than a shape the validator would reject for the wrong reason. None of them is a commit in this repository, so a receipt quoting one cannot be mistaken for a real deploy." +// ONE FIXTURE REVISION FOR EVERY DEPLOY WITNESS, DECLARED HERE AND NOWHERE ELSE. The launch +// revision is now an input to the emitted unit, the readiness comparison, and the apply fold, so +// every deploy witness needs one — and a per-file constant would be the same fact spelled once per +// test file, which is the dual representation DESIGN section 3 forbids applied to the witness +// corpus. A golden that pins ExecStart would then be pinned against one file's spelling while a +// sibling asserted another, and the two could drift without either failing.\n\nIT LIVES UNDER +// dag/test/ SO IT CANNOT REACH PRODUCTION. A fixture sha declared beside the emitter would sit on +// the same import surface the deploy path uses; here the only modules that can name it are +// witnesses. The production path has no constant revision at all — it observes one — which is the +// property that keeps a plausible-looking placeholder from ever being emitted at a real +// host.\n\nTHE VALUES ARE VALID BY SHAPE AND OBVIOUSLY SYNTHETIC BY CONTENT. Each is 40 lowercase +// hex digits, so it passes the same validation a real object name does and the witnesses exercise +// the accepting path rather than a shape the validator would reject for the wrong reason. None of +// them is a commit in this repository, so a receipt quoting one cannot be mistaken for a real +// deploy. data deploy_witness_release_revision: CommitSha = "0123456789abcdef0123456789abcdef01234567" data deploy_witness_other_release_revision: CommitSha = "89abcdef0123456789abcdef0123456789abcdef" -data deploy_witness_third_release_revision: CommitSha = "fedcba9876543210fedcba9876543210fedcba98" +// THREE, BECAUSE THE DISCRIMINATING CASES NEED THREE. Two suffice for 'the process reports a +// different release than the one I installed'; the third is for the ordered case the ruling names — +// launched as A, disk becomes B, a later candidate C — where a witness must show that the process +// still answers A while two other revisions are in play. Reusing one revision for two roles would +// let a witness pass because the values happened to coincide rather than because the mechanism +// held. -data deploy_witness_distinct_revisions_note: String = "THREE, BECAUSE THE DISCRIMINATING CASES NEED THREE. Two suffice for 'the process reports a different release than the one I installed'; the third is for the ordered case the ruling names — launched as A, disk becomes B, a later candidate C — where a witness must show that the process still answers A while two other revisions are in play. Reusing one revision for two roles would let a witness pass because the values happened to coincide rather than because the mechanism held." +data deploy_witness_third_release_revision: CommitSha = "fedcba9876543210fedcba9876543210fedcba98" diff --git a/dag/test/claim/local_tidy_fmt_outcome_test.dag b/dag/test/claim/local_tidy_fmt_outcome_test.dag index 2789eb2e5cf..4c4434cc904 100644 --- a/dag/test/claim/local_tidy_fmt_outcome_test.dag +++ b/dag/test/claim/local_tidy_fmt_outcome_test.dag @@ -29,7 +29,13 @@ import gunbc.githooks_pre_push_fmt_transport_scaffold { githooks_pre_push_fmt_transport_test_discriminator, } -data local_tidy_fmt_outcome_test_note: String = "The defect under witness: a tool that COULD NOT RUN was reported as a negative finding about the work, so a missing cargo printed 'rustfmt drift — run: cargo fmt --all' — a remedy that runs the very binary whose absence produced the message. The discriminating controls are the ones that go RED if the arms are collapsed back together: witness_unavailable_recipe_never_says_drift and witness_unavailable_recipe_proposes_no_cargo_remedy fail the moment FmtToolUnavailable can reach a drift recipe, and the emitted-hook witnesses fail if either hook stops branching on the exit status." +// The defect under witness: a tool that COULD NOT RUN was reported as a negative finding about the +// work, so a missing cargo printed 'rustfmt drift — run: cargo fmt --all' — a remedy that runs the +// very binary whose absence produced the message. The discriminating controls are the ones that go +// RED if the arms are collapsed back together: witness_unavailable_recipe_never_says_drift and +// witness_unavailable_recipe_proposes_no_cargo_remedy fail the moment FmtToolUnavailable can reach +// a drift recipe, and the emitted-hook witnesses fail if either hook stops branching on the exit +// status. fn has(s: String, p: String) -> Bool { string_contains(s: s, pattern: p) diff --git a/dag/test/claim/long/commit_witness_claim_roster_witness_test.dag b/dag/test/claim/long/commit_witness_claim_roster_witness_test.dag index be80cd2ec2e..0627697e7bd 100644 --- a/dag/test/claim/long/commit_witness_claim_roster_witness_test.dag +++ b/dag/test/claim/long/commit_witness_claim_roster_witness_test.dag @@ -9,7 +9,16 @@ import v2.std.text { String } data live_tree_disposition: LiveTreeDisposition = ReadsLiveTree -data commit_witness_claim_roster_long_note: String = "Full CommitWitnessClaim roster resolvability receipt exceeds the per-PR 5s fast-lane eval budget (gunbc_ci_fast_lane_rule_note; measured ~210s eval on 2026-07-23). Projects via ci_floor_commit_witness_claim_schedule and resolves every enrolled (entry, check_fn) pair — the #7060 stale-roster class. Fast-lane per-PR coverage: dag/test/claim/commit_witness_claim_roster_witness_test.dag synthetic stale-pair RED only. Excluded from discovery at test/claim/long/ dir grain (gunbc.ci_layer_roots). NOT roster-enrolled on GithubActionsCiJob — dissolve-on: long-lane scheduled falsifier follow-on enrolls this row. Local recipe until then: claim_batch --source-root dag --source-root src/v2 --entry dag/test/claim/long/commit_witness_claim_roster_witness_test.dag --function commit_witness_claim_roster_holds." +// Full CommitWitnessClaim roster resolvability receipt exceeds the per-PR 5s fast-lane eval budget +// (gunbc_ci_fast_lane_rule_note; measured ~210s eval on 2026-07-23). Projects via +// ci_floor_commit_witness_claim_schedule and resolves every enrolled (entry, check_fn) pair — the +// #7060 stale-roster class. Fast-lane per-PR coverage: +// dag/test/claim/commit_witness_claim_roster_witness_test.dag synthetic stale-pair RED only. +// Excluded from discovery at test/claim/long/ dir grain (gunbc.ci_layer_roots). NOT roster-enrolled +// on GithubActionsCiJob — dissolve-on: long-lane scheduled falsifier follow-on enrolls this row. +// Local recipe until then: claim_batch --source-root dag --source-root src/v2 --entry +// dag/test/claim/long/commit_witness_claim_roster_witness_test.dag --function +// commit_witness_claim_roster_holds. fn witness_commit_witness_claim_roster_live_holds() -> Bool { commit_witness_claim_roster_live_unresolvable_count() == 0 diff --git a/dag/test/claim/long/dag_arrow_lambda_witness_test.dag b/dag/test/claim/long/dag_arrow_lambda_witness_test.dag index b43c52c60bc..81d2c48648f 100644 --- a/dag/test/claim/long/dag_arrow_lambda_witness_test.dag +++ b/dag/test/claim/long/dag_arrow_lambda_witness_test.dag @@ -14,7 +14,17 @@ import v2.extdeps.languages.dag { dag_grammar_nonterminal } -data arrow_lambda_witness_note: String = "CI2-0 grammar-extension proof obligation (operator repair sequencing msg_7152180b item a; premise corrected by direct probe 2026-08-10): the v2 grammar already admits |> — the measured corpus-wide parse wall in dag/std/algebra.dag, a dependency the v2 compiler itself imports, is the ARROW LAMBDA, v1-only surface syntax. This witness admits it parse-only, mirroring the v1 frontend's exact admission (single bare ident, or parenthesized >=2 idents; () and (x) are NOT lambdas in v1 and stay refused). The rule-removed RED rebuilds the grammar with the EXPR production's expression swapped back to the pre-repair shape, selected by DECLARED production identity with the replacement count asserted, so the discrimination is single-variable at the production grain. Non-interference rows pin the neighbors that share tokens with the new arm: match-arm fat arrows, named args, parenthesized arithmetic, and the recently-landed leading-pipe sum admission." +// CI2-0 grammar-extension proof obligation (operator repair sequencing msg_7152180b item a; premise +// corrected by direct probe 2026-08-10): the v2 grammar already admits |> — the measured +// corpus-wide parse wall in dag/std/algebra.dag, a dependency the v2 compiler itself imports, is +// the ARROW LAMBDA, v1-only surface syntax. This witness admits it parse-only, mirroring the v1 +// frontend's exact admission (single bare ident, or parenthesized >=2 idents; () and (x) are NOT +// lambdas in v1 and stay refused). The rule-removed RED rebuilds the grammar with the EXPR +// production's expression swapped back to the pre-repair shape, selected by DECLARED production +// identity with the replacement count asserted, so the discrimination is single-variable at the +// production grain. Non-interference rows pin the neighbors that share tokens with the new arm: +// match-arm fat arrows, named args, parenthesized arithmetic, and the recently-landed leading-pipe +// sum admission. fn parse_accepts_with(source: String, grammar: ParseGrammar) -> Bool { match lex_walk_artifact(source: source, file: ^lambda_probe, rules: dag_lex_rules()) { diff --git a/dag/test/claim/long/dag_compile_clean_scope_disposition_witness_test.dag b/dag/test/claim/long/dag_compile_clean_scope_disposition_witness_test.dag index 1b63458f430..3320bbdc1cc 100644 --- a/dag/test/claim/long/dag_compile_clean_scope_disposition_witness_test.dag +++ b/dag/test/claim/long/dag_compile_clean_scope_disposition_witness_test.dag @@ -5,7 +5,17 @@ import v2.std.live_tree { LiveTreeDisposition, ReadsLiveTree } data live_tree_disposition: LiveTreeDisposition = ReadsLiveTree -data dag_compile_clean_scope_disposition_long_note: String = "THE FIXTURE-GRAIN DISPOSITION ROW RECEIPT, re-homed off per-PR discovery (fast-lane BudgetExceeded, run 31077616566, 5002ms thread-CPU against the 5000ms budget on the seven-row fold). Mechanism stays pinned fixture pool + roster (scope_disposition_witness_roster_note) — NOT live compile_clean_shard_entry_paths. WHY NOT SPLIT: two per-PR halves each still paid a cold module_declaration_facts_live scan and failed at 5002ms and 5001ms — total cost unchanged, admission doubled. Cheap scope witnesses (empty-touched, partition authority, admission duplicates, path-grain dissolve trigger) stay per-PR in dag/test/claim/dag_compile_clean_scope_witness_test.dag. Local recipe: claim_batch --source-root dag --source-root src/v2 --entry dag/test/claim/long/dag_compile_clean_scope_disposition_witness_test.dag --function dag_compile_clean_scope_all_disposition_rows_hold." +// THE FIXTURE-GRAIN DISPOSITION ROW RECEIPT, re-homed off per-PR discovery (fast-lane +// BudgetExceeded, run 31077616566, 5002ms thread-CPU against the 5000ms budget on the seven-row +// fold). Mechanism stays pinned fixture pool + roster (scope_disposition_witness_roster_note) — NOT +// live compile_clean_shard_entry_paths. WHY NOT SPLIT: two per-PR halves each still paid a cold +// module_declaration_facts_live scan and failed at 5002ms and 5001ms — total cost unchanged, +// admission doubled. Cheap scope witnesses (empty-touched, partition authority, admission +// duplicates, path-grain dissolve trigger) stay per-PR in +// dag/test/claim/dag_compile_clean_scope_witness_test.dag. Local recipe: claim_batch --source-root +// dag --source-root src/v2 --entry +// dag/test/claim/long/dag_compile_clean_scope_disposition_witness_test.dag --function +// dag_compile_clean_scope_all_disposition_rows_hold. test fn dag_compile_clean_scope_all_disposition_rows_hold() -> Bool { witness_touched_path_dispositions_hold() diff --git a/dag/test/claim/long/decl_ref_resolution_witness_test.dag b/dag/test/claim/long/decl_ref_resolution_witness_test.dag index ffa66bfa810..8eb4a7f1ed7 100644 --- a/dag/test/claim/long/decl_ref_resolution_witness_test.dag +++ b/dag/test/claim/long/decl_ref_resolution_witness_test.dag @@ -17,7 +17,35 @@ import v2.std.live_tree { LiveTreeDisposition, ReadsLiveTree } data live_tree_disposition: LiveTreeDisposition = ReadsLiveTree -data decl_ref_resolution_witness_note: String = "THE EXECUTING EVIDENCE FOR v2.std.decl_ref_resolution, REHOMED 2026-08-26 OFF A CARRIER THAT DIED UNDER IT.\n\nThese six rows lived in test.claim.long.cited_symbol_resolution_witness_test until v2.lens.cited_symbol_resolution was deleted. They were never the lens's: measured against the seven symbols that file imported FROM the lens, none of these six touches one. They call resolve_declaration_ref directly, and that function lives in v2.std.decl_ref_resolution, which SURVIVES with four other consumers — gunbc.doc_graph_roots, gunbc.dissolution_observation, test.claim.documentary_refs_witness_test and test.claim.long.v1_complexity_capability_census_resolution_test.\n\nSO DELETING THEM WITH THE LENS WOULD HAVE BEEN A DESIGN 4b(4) VIOLATION, not a tidy-up. That clause says a climb deletes the redundant lower-rung PRODUCTION machinery and that the class's discriminating RED and positive control REMAIN ENROLLED, because deleting the evidence recreates specification-without-execution one rung up. The corpus-wide citation census climbed into v1_compiler.declaration_index at ingestion; the resolver's own five-arm refusal did not climb anywhere, and these are the only rows in the tree that execute it.\n\nTHE PAIR IS THE POINT. Two positive controls establish that the resolver RESOLVES a real authority and a real constructor; four reds establish that each refusal arm fires for the reason its variant names. Either half alone is satisfiable by a resolver that answers one way for everything.\n\nWHAT THIS IS NOT: enforcement. Long lane, executes nowhere today — the cited-symbol CI job was removed 2026-08-23 and the required floor declines this home; each row pays a full witness-layer decl_facts scan (operator 5s fast-lane rule 2026-07-12). The evidence is PRESERVED AND UNRUN, and saying otherwise would be the rung inflation DESIGN 4b(1) calls worse than sitting low. What the rehome buys is that when a route returns, the controls are still here and still attached to their real subject." +// THE EXECUTING EVIDENCE FOR v2.std.decl_ref_resolution, REHOMED 2026-08-26 OFF A CARRIER THAT DIED +// UNDER IT. +// +// These six rows lived in test.claim.long.cited_symbol_resolution_witness_test until +// v2.lens.cited_symbol_resolution was deleted. They were never the lens's: measured against the +// seven symbols that file imported FROM the lens, none of these six touches one. They call +// resolve_declaration_ref directly, and that function lives in v2.std.decl_ref_resolution, which +// SURVIVES with four other consumers — gunbc.doc_graph_roots, gunbc.dissolution_observation, +// test.claim.documentary_refs_witness_test and +// test.claim.long.v1_complexity_capability_census_resolution_test. +// +// SO DELETING THEM WITH THE LENS WOULD HAVE BEEN A DESIGN 4b(4) VIOLATION, not a tidy-up. That +// clause says a climb deletes the redundant lower-rung PRODUCTION machinery and that the class's +// discriminating RED and positive control REMAIN ENROLLED, because deleting the evidence recreates +// specification-without-execution one rung up. The corpus-wide citation census climbed into +// v1_compiler.declaration_index at ingestion; the resolver's own five-arm refusal did not climb +// anywhere, and these are the only rows in the tree that execute it. +// +// THE PAIR IS THE POINT. Two positive controls establish that the resolver RESOLVES a real +// authority and a real constructor; four reds establish that each refusal arm fires for the reason +// its variant names. Either half alone is satisfiable by a resolver that answers one way for +// everything. +// +// WHAT THIS IS NOT: enforcement. Long lane, executes nowhere today — the cited-symbol CI job was +// removed 2026-08-23 and the required floor declines this home; each row pays a full witness-layer +// decl_facts scan (operator 5s fast-lane rule 2026-07-12). The evidence is PRESERVED AND UNRUN, and +// saying otherwise would be the rung inflation DESIGN 4b(1) calls worse than sitting low. What the +// rehome buys is that when a route returns, the controls are still here and still attached to their +// real subject. data decl_ref_witness_layer_facts: List = decl_facts(pool_roots: witness_layer_roots) diff --git a/dag/test/claim/long/dissolution_census_witness_test.dag b/dag/test/claim/long/dissolution_census_witness_test.dag index bb1b5f76ca2..1ce90637690 100644 --- a/dag/test/claim/long/dissolution_census_witness_test.dag +++ b/dag/test/claim/long/dissolution_census_witness_test.dag @@ -26,7 +26,28 @@ import v2.std.live_tree { LiveTreeDisposition, SubstrateInputsOnly } data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data dissolution_census_cost_class_note: String = "unbound_dissolution_empty_literal_refuses (below) was investigated as a possible third import-closure-pollution exemplar for the witness-cost-class lane (gunbc.roadmap_authority adhoc-0e6f8ea5-158) and FALSIFIED -- NOT import-closure pollution, and not fixable by closure-narrowing. w_unbound_dissolution_empty_literal_red / w_unbound_dissolution_nonempty_literal_green both call compile_dag_rust_emit_check, whose uncached path (compile_dag_rust_emit_check_uncached, src/v1/stage0/src/cli_run.rs) rebuilds a FULL corpus-rooted module index (build_module_path_index_from_witness_roots) and compiles the supplied virtual source against it on every call -- a cost driven entirely by that helper's own corpus-wide work, unrelated to this witness ENTRY's own transitive import closure. The helper is memoized (COMPILE_DAG_RUST_EMIT_CHECK_MEMO) but the memo is only consulted when floor_prepared_inventory_digest() returns Some, i.e. only under a real claim_executor --required-floor run; a standalone claim run never populates or reads it. This produces a first-toucher shared-fill signature within the same module: whichever of this module's compile_dag_rust_emit_check-calling rows the floor visits first under a given inventory pays the uncached full rebuild, and its sibling(s) hit the warm memo -- confirmed against the floor's own [floor-witness-slow] line, 42129ms vs 825ms for two same-module sibling rows, a ~51x gap with no import-closure difference between them. This is the same underlying mechanism as the Class B and loop/bind falsifications in spirit (a fixed corpus-wide cost masquerading as an entry-closure cost) but a DIFFERENT mechanism in kind -- a per-call memo gated on the floor guard, not a witness entry's own static import graph -- so it belongs to the class-2 per-claim deterministic-reconstruction/memoization bucket, not this lane's closure-narrowing scope. No repair attempted here; this module is left as-is." +// unbound_dissolution_empty_literal_refuses (below) was investigated as a possible third +// import-closure-pollution exemplar for the witness-cost-class lane (gunbc.roadmap_authority +// adhoc-0e6f8ea5-158) and FALSIFIED -- NOT import-closure pollution, and not fixable by +// closure-narrowing. w_unbound_dissolution_empty_literal_red / +// w_unbound_dissolution_nonempty_literal_green both call compile_dag_rust_emit_check, whose +// uncached path (compile_dag_rust_emit_check_uncached, src/v1/stage0/src/cli_run.rs) rebuilds a +// FULL corpus-rooted module index (build_module_path_index_from_witness_roots) and compiles the +// supplied virtual source against it on every call -- a cost driven entirely by that helper's own +// corpus-wide work, unrelated to this witness ENTRY's own transitive import closure. The helper is +// memoized (COMPILE_DAG_RUST_EMIT_CHECK_MEMO) but the memo is only consulted when +// floor_prepared_inventory_digest() returns Some, i.e. only under a real claim_executor +// --required-floor run; a standalone claim run never populates or reads it. This produces a +// first-toucher shared-fill signature within the same module: whichever of this module's +// compile_dag_rust_emit_check-calling rows the floor visits first under a given inventory pays the +// uncached full rebuild, and its sibling(s) hit the warm memo -- confirmed against the floor's own +// [floor-witness-slow] line, 42129ms vs 825ms for two same-module sibling rows, a ~51x gap with no +// import-closure difference between them. This is the same underlying mechanism as the Class B and +// loop/bind falsifications in spirit (a fixed corpus-wide cost masquerading as an entry-closure +// cost) but a DIFFERENT mechanism in kind -- a per-call memo gated on the floor guard, not a +// witness entry's own static import graph -- so it belongs to the class-2 per-claim +// deterministic-reconstruction/memoization bucket, not this lane's closure-narrowing scope. No +// repair attempted here; this module is left as-is. // THE VERDICT IS THE SUBJECT NOW, NOT A REPORT. The census used to fold against // `present_decls: []`, under which no forward trigger could be found and diff --git a/dag/test/claim/long/extdeps_scope_placement_gate_loudness_witness_test.dag b/dag/test/claim/long/extdeps_scope_placement_gate_loudness_witness_test.dag index 05d135eebd5..3a5c8c52fac 100644 --- a/dag/test/claim/long/extdeps_scope_placement_gate_loudness_witness_test.dag +++ b/dag/test/claim/long/extdeps_scope_placement_gate_loudness_witness_test.dag @@ -17,7 +17,81 @@ import gunbc.test_module_hygiene { failure_receipt_companion } import std.process { ProcessExit, ExitSuccess } import std.types { String, Bool, List } -data loudness_witness_note: String = "Floor loudness for tools.extdeps_scope_placement_gate (gunbc#7644): lands the seed-runner loudness path + extdeps_scope_placement_gate production companion only; six other production _passes gates remain mute (counted frontier in tools.floor_effect_gate_witness floor_gate_failure_receipt_note). Per-arm fixtures exercise gate REASON GENERATION with synthetic observations (supporting evidence). Executed RED: red_seed_runner_failure_detail_projects_located_receipt calls production seed_runner_bool_false_failure_detail against seed_runner_loudness_probe_passes, an always-false _passes probe declared IN THIS ENTRY beside its _failure_receipt companion. THE PROBE PAIR MOVED HERE (2026-08-18) AND THAT MOVE IS THE POINT: claim_executor evaluates the derived companion in the WITNESS entry's context, so the pair has to be reachable from here — and reaching it by importing tools.floor_effect_gate_witness dragged that entry's whole gate closure (ci_gates, the compile-clean, generated-artifact and regen-verify gates) into a witness that asserts none of them. Measured import closure: 718 modules / 10.1 MB of source before, 62 modules / 0.49 MB after; the witness was the floor's second most expensive row at 78.6s. Nothing about the claim changed — the same production fn is called against the same located receipt text, and the probe pair is deleted from tools.floor_effect_gate_witness rather than duplicated. It is a func (not test fn), so floor discovery, which selects TestMarkedDecl only, does not enroll it. MUTATION CONTROL RE-EXECUTED AGAINST THE MOVED PAIR (2026-08-18, remote sandbox at 3abc17b54c9): renaming seed_runner_loudness_probe_failure_receipt so the companion derivation misses it makes this row FAIL (rc=1) while all seven rows of this entry pass at head (rc=0) — so the claim still discriminates on the production path after the move, and does not merely assert its own literal. Mutation control executed 2026-08-05 at b0a17f608a, when the probe pair still lived on tools.floor_effect_gate_witness: disposable detached worktree, removed _passes handling from production failure_receipt_companion (holds-only), rebuilt claim_batch, re-ran witness — FAIL red_seed_runner_failure_detail_projects_located_receipt (eval_self 0ms, resolved; not resolution); detail collapsed to bare returned Bool(false) without THIS CHANGE or dag/extdeps/browser/opera.dag. Current head PASS; head detail includes returned Bool(false) | extdeps scope placement gate: THIS CHANGE ... dag/extdeps/browser/opera.dag. Guarantee rung: observed validation on the production seed_runner path; no construction wall claimed for seed/.dag mirror parity (DESIGN section 7 seed retention). REMEASURED AGAINST THE FLOOR'S OWN LINE (witness-cost-class lane, gunbc.roadmap_authority adhoc-0e6f8ea5-158, 2026-08-19) AND FALSIFIED AS A WITNESS-COST REPAIR: the narrowing's own commit measured import closure (718 modules/10.1MB -> 62/0.49MB) and standalone entry-resolve time (30.726s -> 1.005s), but standalone resolve time is not the number the floor's ceiling judges. Run 32177951514 (head 59653f569e, which git merge-base --is-ancestor confirms is a descendant of this repair's ff56305b731) is the last floor observation of this identity before #8457 quarantined the module by name (test.claim.long. prefix) out of required_floor's discovery entirely -- there is no floor line for it after that quarantine, and none will exist until the module returns to floor scope. That last, post-repair line: [floor-witness-slow] red_seed_runner_failure_detail_projects_located_receipt 75926ms, BUDGET-REFUSED against the 1552ms ceiling (an exact measured cost, not a bound -- the witness ran to completion), and [floor-claim-memory] recorded this as the single worst claim in that run, growing RSS by 1.00GB to 10.12GB. 75926ms is statistically the same order as this identity's own PRE-repair floor history (42983-97260ms across four earlier CI runs, docs/plans/measurements/floor-slow-rows-2026-08-17.tsv) -- the 718-to-62-module import-closure narrowing left the floor cost effectively unchanged. EXEMPLAR 1 IS THEREFORE UNCONFIRMED, joining the Class B and loop/bind candidates as this lane's third falsification: import-closure pollution, as a witness-cost class with a demonstrated fixable member, tested empty across all three candidates this lane investigated. What is NOT retracted: the closure narrowing itself is real and DESIGN.md §3-legitimate (fewer modules genuinely load faster in isolation), it is retained as a correctness improvement, and it may have cut cold standalone resolve time as measured -- what is refuted is that it moved the FLOOR's own per-row cost, which is the only number the 1552ms ceiling enforces. Same shape as this lane's Class B correction: the right repair, the wrong quantity measured. All three falsifications point at the same underlying object: a fixed, corpus-wide load/index cost paid once per MultiEntryIndex rather than once per entry's import closure (DESIGN.md's floor-shared-compute-memoization open thread on build_both_closure_edge_index, whose closure-size-independence claim this lane's measurements corroborate rather than re-derive). DECIDED (ATTRIBUTION-3 lane, dashboard adhoc-68d59f0c-bc2, 2026-08-19): 'the same underlying object' above named a suspect, not a verdict -- this identity was checked directly against the typed shared_fill ledger (#8455), landed after #8457 quarantined this module, so like the sibling witness it was renamed for exactly one CI pass to test.claim.probe_extdeps_scope_placement_gate_loudness_witness (fn body unchanged) on the same throwaway, never-merged probe (#8563, run 32291153434 / job 96192007757), then discarded. Result: this claim appears in ZERO of that run's 17 shared_fill rows, neither as payer nor as consumer. The standard-pool module_path_index/module_graph_facts/reference_edges fills its own entry resolution would touch (the dag+src/v2 and dag-alone keys) are ALL paid_by= in that run -- pre-warmed during floor preparation before any claim executes, per the documented WARMING precedent in run_required_floor, and so free to every claim including this one. So the shared-fill mechanism is REFUTED as this identity's cost source: there is no first-consumer artifact here to attribute, exclusive or shared. Its ~54-76s cost (this run: 54144ms; run 32177951514: 75926ms) and its RSS growth (this run: +0.96GB, worst single claim; run 32177951514: +1.00GB, also worst) sit entirely outside the shared_fill ledger's instrumented surface -- real per-claim cost, most plausibly still build_both_closure_edge_index (per-MultiEntryIndex-memoized, confirmed never wrapped in the shared_fill API), but this note asserts only what the ledger showed (unattributed), not that unproven mechanism, per the standing denominator-honesty bar." +// Floor loudness for tools.extdeps_scope_placement_gate (gunbc#7644): lands the seed-runner +// loudness path + extdeps_scope_placement_gate production companion only; six other production +// _passes gates remain mute (counted frontier in tools.floor_effect_gate_witness +// floor_gate_failure_receipt_note). Per-arm fixtures exercise gate REASON GENERATION with synthetic +// observations (supporting evidence). Executed RED: +// red_seed_runner_failure_detail_projects_located_receipt calls production +// seed_runner_bool_false_failure_detail against seed_runner_loudness_probe_passes, an always-false +// _passes probe declared IN THIS ENTRY beside its _failure_receipt companion. THE PROBE PAIR MOVED +// HERE (2026-08-18) AND THAT MOVE IS THE POINT: claim_executor evaluates the derived companion in +// the WITNESS entry's context, so the pair has to be reachable from here — and reaching it by +// importing tools.floor_effect_gate_witness dragged that entry's whole gate closure (ci_gates, the +// compile-clean, generated-artifact and regen-verify gates) into a witness that asserts none of +// them. Measured import closure: 718 modules / 10.1 MB of source before, 62 modules / 0.49 MB +// after; the witness was the floor's second most expensive row at 78.6s. Nothing about the claim +// changed — the same production fn is called against the same located receipt text, and the probe +// pair is deleted from tools.floor_effect_gate_witness rather than duplicated. It is a func (not +// test fn), so floor discovery, which selects TestMarkedDecl only, does not enroll it. MUTATION +// CONTROL RE-EXECUTED AGAINST THE MOVED PAIR (2026-08-18, remote sandbox at 3abc17b54c9): renaming +// seed_runner_loudness_probe_failure_receipt so the companion derivation misses it makes this row +// FAIL (rc=1) while all seven rows of this entry pass at head (rc=0) — so the claim still +// discriminates on the production path after the move, and does not merely assert its own literal. +// Mutation control executed 2026-08-05 at b0a17f608a, when the probe pair still lived on +// tools.floor_effect_gate_witness: disposable detached worktree, removed _passes handling from +// production failure_receipt_companion (holds-only), rebuilt claim_batch, re-ran witness — FAIL +// red_seed_runner_failure_detail_projects_located_receipt (eval_self 0ms, resolved; not +// resolution); detail collapsed to bare returned Bool(false) without THIS CHANGE or +// dag/extdeps/browser/opera.dag. Current head PASS; head detail includes returned Bool(false) | +// extdeps scope placement gate: THIS CHANGE ... dag/extdeps/browser/opera.dag. Guarantee rung: +// observed validation on the production seed_runner path; no construction wall claimed for +// seed/.dag mirror parity (DESIGN section 7 seed retention). REMEASURED AGAINST THE FLOOR'S OWN +// LINE (witness-cost-class lane, gunbc.roadmap_authority adhoc-0e6f8ea5-158, 2026-08-19) AND +// FALSIFIED AS A WITNESS-COST REPAIR: the narrowing's own commit measured import closure (718 +// modules/10.1MB -> 62/0.49MB) and standalone entry-resolve time (30.726s -> 1.005s), but +// standalone resolve time is not the number the floor's ceiling judges. Run 32177951514 (head +// 59653f569e, which git merge-base --is-ancestor confirms is a descendant of this repair's +// ff56305b731) is the last floor observation of this identity before #8457 quarantined the module +// by name (test.claim.long. prefix) out of required_floor's discovery entirely -- there is no floor +// line for it after that quarantine, and none will exist until the module returns to floor scope. +// That last, post-repair line: [floor-witness-slow] +// red_seed_runner_failure_detail_projects_located_receipt 75926ms, BUDGET-REFUSED against the +// 1552ms ceiling (an exact measured cost, not a bound -- the witness ran to completion), and +// [floor-claim-memory] recorded this as the single worst claim in that run, growing RSS by 1.00GB +// to 10.12GB. 75926ms is statistically the same order as this identity's own PRE-repair floor +// history (42983-97260ms across four earlier CI runs, +// docs/plans/measurements/floor-slow-rows-2026-08-17.tsv) -- the 718-to-62-module import-closure +// narrowing left the floor cost effectively unchanged. EXEMPLAR 1 IS THEREFORE UNCONFIRMED, joining +// the Class B and loop/bind candidates as this lane's third falsification: import-closure +// pollution, as a witness-cost class with a demonstrated fixable member, tested empty across all +// three candidates this lane investigated. What is NOT retracted: the closure narrowing itself is +// real and DESIGN.md §3-legitimate (fewer modules genuinely load faster in isolation), it is +// retained as a correctness improvement, and it may have cut cold standalone resolve time as +// measured -- what is refuted is that it moved the FLOOR's own per-row cost, which is the only +// number the 1552ms ceiling enforces. Same shape as this lane's Class B correction: the right +// repair, the wrong quantity measured. All three falsifications point at the same underlying +// object: a fixed, corpus-wide load/index cost paid once per MultiEntryIndex rather than once per +// entry's import closure (DESIGN.md's floor-shared-compute-memoization open thread on +// build_both_closure_edge_index, whose closure-size-independence claim this lane's measurements +// corroborate rather than re-derive). DECIDED (ATTRIBUTION-3 lane, dashboard adhoc-68d59f0c-bc2, +// 2026-08-19): 'the same underlying object' above named a suspect, not a verdict -- this identity +// was checked directly against the typed shared_fill ledger (#8455), landed after #8457 quarantined +// this module, so like the sibling witness it was renamed for exactly one CI pass to +// test.claim.probe_extdeps_scope_placement_gate_loudness_witness (fn body unchanged) on the same +// throwaway, never-merged probe (#8563, run 32291153434 / job 96192007757), then discarded. Result: +// this claim appears in ZERO of that run's 17 shared_fill rows, neither as payer nor as consumer. +// The standard-pool module_path_index/module_graph_facts/reference_edges fills its own entry +// resolution would touch (the dag+src/v2 and dag-alone keys) are ALL paid_by= in that +// run -- pre-warmed during floor preparation before any claim executes, per the documented WARMING +// precedent in run_required_floor, and so free to every claim including this one. So the +// shared-fill mechanism is REFUTED as this identity's cost source: there is no first-consumer +// artifact here to attribute, exclusive or shared. Its ~54-76s cost (this run: 54144ms; run +// 32177951514: 75926ms) and its RSS growth (this run: +0.96GB, worst single claim; run 32177951514: +// +1.00GB, also worst) sit entirely outside the shared_fill ledger's instrumented surface -- real +// per-claim cost, most plausibly still build_both_closure_edge_index (per-MultiEntryIndex-memoized, +// confirmed never wrapped in the shared_fill API), but this note asserts only what the ledger +// showed (unattributed), not that unproven mechanism, per the standing denominator-honesty bar. fn read_manifest_rows() -> List { parse_frontier_manifest( diff --git a/dag/test/claim/long/instrument_sandbox_live_witness_test.dag b/dag/test/claim/long/instrument_sandbox_live_witness_test.dag index eeb77c26a34..d186f2a2de3 100644 --- a/dag/test/claim/long/instrument_sandbox_live_witness_test.dag +++ b/dag/test/claim/long/instrument_sandbox_live_witness_test.dag @@ -20,7 +20,33 @@ import extdeps.http.server { ServeHttpRequest, ServeHttpResponse, GET, media_typ data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data instrument_sandbox_live_long_note: String = "THE LIVE HALF OF THE INSTRUMENT SANDBOX WITNESS, re-homed off per-PR discovery (fast-lane BudgetExceeded, run 30986055960, 5074ms thread-CPU against the 5000ms budget). WHERE THE COST IS: post_7822_attribution_note below, which is the ONLY attribution in this file. This note used to carry one of its own — the render and live_program_view_result named as the dominant term, a 263ms-inputs / 5132ms-derivation split, and n=25 declared nodes — and every part of that is retracted: the cost location was wrong, and the node count was never right. It is deleted rather than disclaimed, because a superseded attribution sitting in the first note a reader reaches steers the next worker at the wrong file however many corrections sit below it, and two live cost stories in one carrier is the dual representation DESIGN section 3 forbids. WHAT SPLIT AND WHY, which is structural and does not move with the measurements: every claim here renders the served page or reads the live program view, and the mechanism claims — the derived salience role, the emission/admission join, the refused-role controls, the theme-block position check — measured 0-2ms each and are NOT here. They stay per-PR in the parent file, because the 2026-08-04 admission ruling says a live-population subject decomposes into small discriminating mechanism fixtures per PR plus the irreducible live half on a cadence, and the mechanism half is never the part that moves. HONEST COST CLASSIFICATION, because the precedent rows on this lane each declare theirs: this row is enrolled with its cost declared and measured, not relabelled as irreducible — see deferral_floor_note for what would have to get cheaper and whose lane owns it. WHAT WAS NOT DONE, named because the diagnostic that produced this split names it: the file was not moved to remove it from discovery and left unexecuted, and the keystone was not split into two per-PR test fns to draw two budgets — total cost would be unchanged and that is the relocation evasion wearing a different hat. Local recipe: claim_batch --source-root dag --source-root src/v2 --entry dag/test/claim/long/instrument_sandbox_live_witness_test.dag --function instrument_sandbox_live_keystone_holds. Dissolve-on: carried once, on this witness's row in gunbc.ci_layer_roots falsifier_substrate_long_lane_rows — the original condition here (restructure the derivation onto keyed lookup) was MET by #7822 and did not dissolve the row, so a second copy of it would now be doubly wrong." +// THE LIVE HALF OF THE INSTRUMENT SANDBOX WITNESS, re-homed off per-PR discovery (fast-lane +// BudgetExceeded, run 30986055960, 5074ms thread-CPU against the 5000ms budget). WHERE THE COST IS: +// post_7822_attribution_note below, which is the ONLY attribution in this file. This note used to +// carry one of its own — the render and live_program_view_result named as the dominant term, a +// 263ms-inputs / 5132ms-derivation split, and n=25 declared nodes — and every part of that is +// retracted: the cost location was wrong, and the node count was never right. It is deleted rather +// than disclaimed, because a superseded attribution sitting in the first note a reader reaches +// steers the next worker at the wrong file however many corrections sit below it, and two live cost +// stories in one carrier is the dual representation DESIGN section 3 forbids. WHAT SPLIT AND WHY, +// which is structural and does not move with the measurements: every claim here renders the served +// page or reads the live program view, and the mechanism claims — the derived salience role, the +// emission/admission join, the refused-role controls, the theme-block position check — measured +// 0-2ms each and are NOT here. They stay per-PR in the parent file, because the 2026-08-04 +// admission ruling says a live-population subject decomposes into small discriminating mechanism +// fixtures per PR plus the irreducible live half on a cadence, and the mechanism half is never the +// part that moves. HONEST COST CLASSIFICATION, because the precedent rows on this lane each declare +// theirs: this row is enrolled with its cost declared and measured, not relabelled as irreducible — +// see deferral_floor_note for what would have to get cheaper and whose lane owns it. WHAT WAS NOT +// DONE, named because the diagnostic that produced this split names it: the file was not moved to +// remove it from discovery and left unexecuted, and the keystone was not split into two per-PR test +// fns to draw two budgets — total cost would be unchanged and that is the relocation evasion +// wearing a different hat. Local recipe: claim_batch --source-root dag --source-root src/v2 --entry +// dag/test/claim/long/instrument_sandbox_live_witness_test.dag --function +// instrument_sandbox_live_keystone_holds. Dissolve-on: carried once, on this witness's row in +// gunbc.ci_layer_roots falsifier_substrate_long_lane_rows — the original condition here +// (restructure the derivation onto keyed lookup) was MET by #7822 and did not dissolve the row, so +// a second copy of it would now be doubly wrong. fn fixture_request(path: String) -> ServeHttpRequest { ServeHttpRequest { method: GET, path: path, body: "" } @@ -40,7 +66,13 @@ fn last_segment(s: String, marker: String) -> String { fold(split(s: s, delimiter: marker), init: "", f: (acc, part) => part) } -data study_not_instrument_note: String = "The page must not describe itself as the operable instrument, and the header must not carry controls it cannot operate. The dead-control claim is checked against the MARKUP, not the whole document: the register stylesheet is inlined in a style element and legitimately contains .theme-toggle and .sound-toggle rules, so searching the raw body for those words finds the CSS and reds on a page that has no such buttons. The first version of this claim did exactly that and was wrong for a reason worth keeping — a negative substring assertion over a document that embeds its own stylesheet is testing the stylesheet." +// The page must not describe itself as the operable instrument, and the header must not carry +// controls it cannot operate. The dead-control claim is checked against the MARKUP, not the whole +// document: the register stylesheet is inlined in a style element and legitimately contains +// .theme-toggle and .sound-toggle rules, so searching the raw body for those words finds the CSS +// and reds on a page that has no such buttons. The first version of this claim did exactly that and +// was wrong for a reason worth keeping — a negative substring assertion over a document that embeds +// its own stylesheet is testing the stylesheet. fn body_markup(r: ServeHttpResponse) -> String { last_segment(s: r.body, marker: "") @@ -64,7 +96,10 @@ data post_7822_attribution_note: String = "THE FILE'S ONE ATTRIBUTION, AND WHAT data deferral_floor_note: String = "WHAT THIS MEANS FOR THE DEFERRAL, stated because the enrollment row's remaining condition was written against the retracted attribution and pointed at work in this file. There is no change confined to this file that lands this witness under a 500ms per-witness line: constructing declared_roadmap_nodes alone is 1105ms, 2.2x that line, before this page renders a single element, and the whole projection side is 1641ms, 3.3x it. Driving this file's own ~203ms to zero would not close the gap and would delete the claims the split exists to keep. The cost is also not this witness's private problem — it is paid by every witness that reads the live roadmap authority, so it belongs to that authority's lane and not to this one. Recorded here rather than left to inference because a stale measurement in a carrier whose only job is to justify a deferral is the citation-rot class DESIGN section 3 names, and this carrier had already grown one." -data live_world_note: String = "The page reads the world V0 derives, live. If the projection refuses, the page renders the located causes rather than a smaller program. This is the claim the whole split exists to preserve: it is the one that cannot be proven on a planted fixture, because its subject is the real declared roadmap." +// The page reads the world V0 derives, live. If the projection refuses, the page renders the +// located causes rather than a smaller program. This is the claim the whole split exists to +// preserve: it is the one that cannot be proven on a planted fixture, because its subject is the +// real declared roadmap. fn witness_the_page_reads_the_live_derived_program_view() -> Bool { match live_program_view_result() { @@ -82,7 +117,11 @@ fn witness_the_page_renders_real_remaining_and_constraint_readings(body: String) && string_contains(s: body, pattern: "open fronts") } -data front_grain_witness_note: String = "The claim review 48579 found missing: the front grain renders the FIRST contributing front. The oracle is independent of the code under test — V0 derives the exemplar's contributing set as namespace-pderive then v2-generation, so the page must name the first front's own title and must NOT name the second's. A last-wins fold renders the second, which is exactly what the page did before the fix, so this claim reds on the real defect rather than on a restatement of the fix." +// The claim review 48579 found missing: the front grain renders the FIRST contributing front. The +// oracle is independent of the code under test — V0 derives the exemplar's contributing set as +// namespace-pderive then v2-generation, so the page must name the first front's own title and must +// NOT name the second's. A last-wins fold renders the second, which is exactly what the page did +// before the fix, so this claim reds on the real defect rather than on a restatement of the fix. fn witness_the_front_grain_shows_the_first_contributing_front(body: String, markup: String) -> Bool { string_contains(s: body, pattern: "front / status") @@ -90,14 +129,19 @@ fn witness_the_front_grain_shows_the_first_contributing_front(body: String, mark && !string_contains(s: markup, pattern: "V2 generation and admission") } -data evidence_refusal_note: String = "Evidence depth refuses, and unlike the previous Why refusal this one is real: gunbc.roadmap_program_view records that the verification-receipt join is test-only, so no carrier can answer it yet. The witness pins the cause text so a future reader can tell this refusal from the fabricated one it replaced." +// Evidence depth refuses, and unlike the previous Why refusal this one is real: +// gunbc.roadmap_program_view records that the verification-receipt join is test-only, so no carrier +// can answer it yet. The witness pins the cause text so a future reader can tell this refusal from +// the fabricated one it replaced. fn witness_red_evidence_depth_refuses_with_its_real_cause(body: String) -> Bool { string_contains(s: body, pattern: "evidence / status · compiler-fixed-point — unavailable:") && string_contains(s: body, pattern: "verification-receipt join is test-only") } -data press_markup_note: String = "The markup half of the press specimen. Its CSS half — the :active rule, the bounded translation, the displacement budget — is cheap and stays per-PR in the parent file; only the assertion that the rendered page carries a real button lives here, because that one needs the page." +// The markup half of the press specimen. Its CSS half — the :active rule, the bounded translation, +// the displacement budget — is cheap and stays per-PR in the parent file; only the assertion that +// the rendered page carries a real button lives here, because that one needs the page. fn witness_the_press_specimen_is_reachable_without_a_pointer(body: String) -> Bool { string_contains(s: body, pattern: " ParseTree { artifact.tree } // The graft rejection flows through rejected_with_pending, which PREPENDS the pending -// accepted-carrier diagnostics (wrapper-retained bodies) to the rejection — the same -// head-masking shape the sweep's first_located_cause already skips. The assertion is -// therefore containment: the refusal CARRIES the guard's typed reason, wherever the -// pending carriers put it. +// accepted-carrier diagnostics (wrapper-retained bodies) to the rejection — the head-masking shape +// the sweep's first_located_cause already skips. The assertion is therefore containment: the +// refusal CARRIES the guard's typed reason, wherever the pending carriers put it. fn rejection_reasons(source: String) -> List { match lex_walk_artifact(source: source, file: ^graft_guard_probe, rules: dag_lex_rules()) { v2.std.diagnostic.Rejected { diagnostics: _ } => no_reasons() diff --git a/dag/test/claim/long/qualified_declaration_reference_emit_cross_module_witness_test.dag b/dag/test/claim/long/qualified_declaration_reference_emit_cross_module_witness_test.dag index beab12aed89..feb57986b53 100644 --- a/dag/test/claim/long/qualified_declaration_reference_emit_cross_module_witness_test.dag +++ b/dag/test/claim/long/qualified_declaration_reference_emit_cross_module_witness_test.dag @@ -4,7 +4,16 @@ import v2.std.live_tree { LiveTreeDisposition, SubstrateInputsOnly } data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data qualified_declaration_reference_emit_cross_module_witness_note: String = "Long-lane half of qualified_declaration_reference_emit_witness_test.dag: w_cross_module_qualified_reference_emits_call exercises a genuine cross-module qualified data reference (std.unicode.types.unicode_scalar_max_code_point — minimal std closure, not the heavy std.emit_on_demand roster the prior fixture dragged in) through compile_dag_rust_emit_check. Re-homed to test/claim/long/ after falsifier discovery batch 3 BudgetExceeded kills (5436-5544ms thread-CPU vs 5000ms fast-lane cap on srv_fleet_arm64; chronic on main, unrelated to decl_facts work). Same-module control stays per-PR in dag/test/claim/qualified_declaration_reference_emit_witness_test.dag. dissolve-on: eval under gunbc_ci_fast_lane_witness_eval_budget on fleet hardware, then row re-enrolls per-PR and this file deletes." +// Long-lane half of qualified_declaration_reference_emit_witness_test.dag: +// w_cross_module_qualified_reference_emits_call exercises a genuine cross-module qualified data +// reference (std.unicode.types.unicode_scalar_max_code_point — minimal std closure, not the heavy +// std.emit_on_demand roster the prior fixture dragged in) through compile_dag_rust_emit_check. +// Re-homed to test/claim/long/ after falsifier discovery batch 3 BudgetExceeded kills (5436-5544ms +// thread-CPU vs 5000ms fast-lane cap on srv_fleet_arm64; chronic on main, unrelated to decl_facts +// work). Same-module control stays per-PR in +// dag/test/claim/qualified_declaration_reference_emit_witness_test.dag. dissolve-on: eval under +// gunbc_ci_fast_lane_witness_eval_budget on fleet hardware, then row re-enrolls per-PR and this +// file deletes. fn w_cross_module_qualified_reference_emits_call() -> Bool { compile_dag_rust_emit_check( diff --git a/dag/test/claim/long/realization_sweep_test.dag b/dag/test/claim/long/realization_sweep_test.dag index 3e2d18100b7..bdc972eec57 100644 --- a/dag/test/claim/long/realization_sweep_test.dag +++ b/dag/test/claim/long/realization_sweep_test.dag @@ -17,7 +17,16 @@ import v2.std.algebra { fold_list, length } import v2.std.logic { Bool } import std.types { Int, List, String } -data sweep_test_note: String = "CI2-0 Commit B sweep laws (roster authority per operator verdict msg_6305b900): identities come from the canonical enrolled floor population, not a source-text scan — the mechanism witnesses here drive sweep_rows_with_identities with a PLANTED identity roster over a planted two-module closure (fixture-controlled: the same author writes the input and the expected population), and the join law is the independent both-directions identity join sweep_rows_join_canonical, duplicate-free. The canonical derivation itself (entry_canonical_identities = the floor_discovery_producer walk filtered to the entry) is witnessed against THIS file's own enrolled roster — a fixture-controlled identity join, not a tree-copied count. The witness-absent arm is the RED: an entry not present in its own closure ingest is a located refusal row, never an empty (silently uncovered) roster." +// CI2-0 Commit B sweep laws (roster authority per operator verdict msg_6305b900): identities come +// from the canonical enrolled floor population, not a source-text scan — the mechanism witnesses +// here drive sweep_rows_with_identities with a PLANTED identity roster over a planted two-module +// closure (fixture-controlled: the same author writes the input and the expected population), and +// the join law is the independent both-directions identity join sweep_rows_join_canonical, +// duplicate-free. The canonical derivation itself (entry_canonical_identities = the +// floor_discovery_producer walk filtered to the entry) is witnessed against THIS file's own +// enrolled roster — a fixture-controlled identity join, not a tree-copied count. The witness-absent +// arm is the RED: an entry not present in its own closure ingest is a located refusal row, never an +// empty (silently uncovered) roster. data sweep_entry_path: String = "src/v2/test/fixture/ks_entry.dag" diff --git a/dag/test/claim/long/reference_closure_equivalence_test.dag b/dag/test/claim/long/reference_closure_equivalence_test.dag index 87ed816e609..150bfa97b35 100644 --- a/dag/test/claim/long/reference_closure_equivalence_test.dag +++ b/dag/test/claim/long/reference_closure_equivalence_test.dag @@ -33,7 +33,16 @@ data conformance_import_envelope_dissolution_note: String = "conformance_imports data bogus_never_referenced: String = "src/v2/std/__bogus_never_referenced__.dag" -data reference_closure_equivalence_note: String = "B2 safety wall (operator, sharp-bee-290): resolution RESULTS are preserved when the module graph is derived from parsed-tree qualified-name use sites instead of import declarations. On the import-only corpus reference_closure_live delegates to import_closure_live_excluding (no fact re-materialization); must match the declared golden (witnessed here) and import_closure_live (witnessed in import_closure_live_test.dag on the same golden). reference_parsed_tree_facts_match_import_facts_at_path on the conformance entry exercises the parsed census path; reference_parsed_tree_matches_import_facts_on_closure and reference_closure_parsed_live remain scaffold-only until interpreter parse-per-member cost is bounded (CI witness avoids them). Drift control and import/reference mismatch RED controls are folded into reference_closure_b2_safety_wall_holds." +// B2 safety wall (operator, sharp-bee-290): resolution RESULTS are preserved when the module graph +// is derived from parsed-tree qualified-name use sites instead of import declarations. On the +// import-only corpus reference_closure_live delegates to import_closure_live_excluding (no fact +// re-materialization); must match the declared golden (witnessed here) and import_closure_live +// (witnessed in import_closure_live_test.dag on the same golden). +// reference_parsed_tree_facts_match_import_facts_at_path on the conformance entry exercises the +// parsed census path; reference_parsed_tree_matches_import_facts_on_closure and +// reference_closure_parsed_live remain scaffold-only until interpreter parse-per-member cost is +// bounded (CI witness avoids them). Drift control and import/reference mismatch RED controls are +// folded into reference_closure_b2_safety_wall_holds. fn string_eq(a: String, b: String) -> Bool { a == b diff --git a/dag/test/claim/long/rust_test_fixtures_import_closure_witness_test.dag b/dag/test/claim/long/rust_test_fixtures_import_closure_witness_test.dag index 4fedf61c3d3..bc2f3cefce1 100644 --- a/dag/test/claim/long/rust_test_fixtures_import_closure_witness_test.dag +++ b/dag/test/claim/long/rust_test_fixtures_import_closure_witness_test.dag @@ -6,7 +6,84 @@ import v2.workflow.class_b_import_closure_probe { } import std.types { Bool } -data class_b_witness_note: String = "Rows 1-2 of the Class B rust_test_fixtures control (#6985), delegated to v2.workflow.class_b_import_closure_probe for single authority. QUARANTINED, not path-excluded: this module is excluded from the required floor by its AUTHORED NAME — required_floor.dag matches long_home_prefixes against the module name, and test.claim.long. is one — so the exclusion is the rename #8457 performed, and the directory is for humans. The FalsifierSubstrateLongLane WitnessExclusionRow that this note once cited is deleted with it: the required floor never consulted witness_exclusion_frontier at all (floor_discovery_path_excluded is reached only from claim_batch and a cfg(test) module), and the falsifier cadence those long-lane rows enrolled was deleted outright in the floor cut, so neither mechanism had an executing consumer. WHY IT WAS HERE: both rows PASSED and exceeded the 1552ms ceiling (Cpu 25816ms and 36536ms, run 32179249889) while this file imported v2.workflow.class_b_import_closure_transport, whose module-level extdeps.git / extdeps.git.inspect / gunbc.ci_layer_roots imports (needed only by that module's separate rows 3-4) inflated this entry's resolve closure — the same signature extdeps_scope_placement_gate_loudness_witness's 718-to-62-module repair fixed. This module now imports v2.workflow.class_b_import_closure_probe instead, which carries only what rows 1-2 need (gunbc.class_b_import_closure_overlay's class_b_entry_rel/class_b_declared_import_pool_roots and gunbc.declared_import_closure_binding), never the heavy transport module. The narrowing does not change what class_b_declared_import_closure_lists_rust_import/class_b_ambient_pool_provider_preserves_listed_import compute — same fn bodies, same DeclaredImportClosureBindingObservation calls, only the entry's own import graph shrank. Splitting a witness's own test file to dodge the ceiling is refused as a measurement artifact (gunbc.witness_row_cost witness_decomposition_does_not_reduce_entry_cost_note); this is not that — the fix narrows what the SAME entry's assertions actually depend on, by fixing the imported dependency's shape (relocation-not-refork per DESIGN.md §3), not by moving these test fns to a new file. Rows 3-4 stay in class_b_import_closure_binding_refusal_witness_test.dag and class_b_strip_receipt_witness_test.dag; wet integration remains run_class_b_import_closure_gate on source_root_ingest_gate. MEASURED 2026-08-19, and the result is NEGATIVE — this narrowing is FALSIFIED as an import-closure-pollution repair, not confirmed. The two-sided test (a paired same-host comparison, per the standing acceptance bar: cost must collapse when the closure narrows AND not collapse under mere repetition) was run via gunbc run --claim-run against a fresh release build in one remote dispatch: declared_import_closure_lists_rust_import through this narrow probe-backed entry measured 70.0s and 69.4s wall (two independent process calls, back to back); the SAME function reached through v2.workflow.class_b_import_closure_transport directly (the heavy module, still carrying its module-level extdeps.git / extdeps.git.inspect / gunbc.ci_layer_roots imports) measured 69.98s in the identical dispatch, on the identical host, moments apart. Narrow and heavy are statistically indistinguishable. ambient_pool_provider_preserves_listed_import (which itself calls the observe function twice in one process) measured 80.8s, consistent with the same fixed floor rather than a per-import-closure charge. CORRECTED MAGNITUDE (per-row floor line, supplied against the required floor's own [floor-witness-slow] output for these same two identities, not the standalone harness): declared_import_closure_lists_rust_import 24674ms and ambient_pool_provider_preserves_listed_import 31603ms -- the standalone --claim-run figures above (70.0s/80.8s) are ~2-3x inflated relative to the floor's own amortized accounting, because a standalone claim run pays the corpus-wide load/index term once per claim while the floor pays that same fixed term once per MultiEntryIndex, amortized across the whole discovered roster (see DESIGN.md's floor-shared-compute-memoization open thread on build_both_closure_edge_index, whose central size-independence claim these figures corroborate on a different subject rather than re-derive). The paired-comparison DESIGN of the standalone measurement is still the right instrument for detecting a closure-size effect (narrow vs heavy, same process shape) -- only its absolute magnitude needs the floor's own line as the citable number. Both the standalone pair and the floor's per-row numbers agree on the same verdict: narrow and heavy did not diverge, and both sit far over the 1552ms ceiling. None of these approach the printed compile.frontend/normalize/reconcile/analyses phase timings (~1-2s total each), meaning the ~25-32s floor-line cost is spent somewhere the entry-closure resolution does not reach. DECIDED (ATTRIBUTION-3 lane, dashboard adhoc-68d59f0c-bc2, 2026-08-19): the hedge above is now a typed SharedFillDisposition verdict, not a guess. #8455 landed the shared_fill ledger AFTER #8457 quarantined this module by name, so no floor run ever had both simultaneously -- to observe one, this module was renamed for exactly one CI pass to test.claim.probe_rust_test_fixtures_import_closure_witness (fn bodies byte-identical, only the module line changed) on a throwaway, never-merged PR (#8563, run 32291153434 / job 96192007757), then discarded. Result: both rows are SharedFillExclusiveToOneModule. Every module_graph_facts/module_path_index/reference_edges fill either row touches is keyed on class_b_declared_import_pool_roots (this witness's own narrow 4-root pool, unique in the corpus) and is paid_by exactly this module's own fn, consumer_modules=1, disposition=exclusive: declared_import_closure_lists_rust_import pays module_graph_facts fill_ms=731 (inclusive_ms=17441, nesting module_path_index fill_ms=11328 + reference_edges fill_ms=5381); ambient_pool_provider_preserves_listed_import's perturbed-key call pays its own fresh module_graph_facts fill_ms=764 (inclusive_ms=18479, nesting module_path_index fill_ms=12463 + reference_edges fill_ms=5252), while its baseline call reuses declared's fill for free (declared's row shows consumer_claims=1, the recorded hit). That run's TOTAL line: fills=17, shared_fill_ms=0 -- zero SharedFillSharedAcrossModules exemplars existed anywhere in that floor pass, corroborating that this pool's exclusivity is not an artifact of a thin probe. Denominator honesty: the attributed fill accounts for ~17.4s of declared's ~27s probe-run cost and ~18.5s of ambient's ~37.8s -- the remainder is real per-call cost the shared_fill ledger does not instrument (candidate: build_both_closure_edge_index, confirmed not shared_fill-wrapped; not asserted further than that here). CONCLUSION: the module split (v2.workflow.class_b_import_closure_probe) is a legitimate DESIGN.md §3 relocation-not-refork decomposition and stays -- rows 1-2's shape genuinely does not need git/git.inspect/ci_layer_roots -- but it is NOT a witness-cost fix and this file does NOT leave long/ on its account; 24.7-31.6s (floor line) / 70-80s (standalone) both remain far over the 1552ms ceiling. This is the second candidate this lane has falsified as import-closure pollution (after the loop/bind witnesses), not confirmed as a second exemplar; see the lane's PR description for the full delta." +// Rows 1-2 of the Class B rust_test_fixtures control (#6985), delegated to +// v2.workflow.class_b_import_closure_probe for single authority. QUARANTINED, not path-excluded: +// this module is excluded from the required floor by its AUTHORED NAME — required_floor.dag matches +// long_home_prefixes against the module name, and test.claim.long. is one — so the exclusion is the +// rename #8457 performed, and the directory is for humans. The FalsifierSubstrateLongLane +// WitnessExclusionRow this note once cited is deleted with it: the required floor never consulted +// witness_exclusion_frontier (floor_discovery_path_excluded is reached only from claim_batch and a +// cfg(test) module), and the falsifier cadence those long-lane rows enrolled was deleted in the +// floor cut, so neither mechanism had an executing consumer. WHY IT WAS HERE: both rows PASSED and +// exceeded the 1552ms ceiling (Cpu 25816ms and 36536ms, run 32179249889) while this file imported +// v2.workflow.class_b_import_closure_transport, whose module-level extdeps.git / +// extdeps.git.inspect / gunbc.ci_layer_roots imports (needed only by that module's rows 3-4) +// inflated this entry's resolve closure — the signature +// extdeps_scope_placement_gate_loudness_witness's 718-to-62-module repair fixed. This module now +// imports v2.workflow.class_b_import_closure_probe, which carries only what rows 1-2 need +// (gunbc.class_b_import_closure_overlay's class_b_entry_rel/class_b_declared_import_pool_roots and +// gunbc.declared_import_closure_binding), never the heavy transport module. The narrowing does not +// change what +// class_b_declared_import_closure_lists_rust_import/class_b_ambient_pool_provider_preserves_listed_import +// compute — same fn bodies, same DeclaredImportClosureBindingObservation calls; only the entry's +// import graph shrank. Splitting a witness's test file to dodge the ceiling is refused as a +// measurement artifact (gunbc.witness_row_cost +// witness_decomposition_does_not_reduce_entry_cost_note); this is not that — it narrows what the +// SAME entry's assertions depend on by fixing the imported dependency's shape (relocation-not-refork +// per DESIGN.md §3), not by moving test fns to a new file. Rows 3-4 stay in +// class_b_import_closure_binding_refusal_witness_test.dag and +// class_b_strip_receipt_witness_test.dag; wet integration remains run_class_b_import_closure_gate +// on source_root_ingest_gate. MEASURED 2026-08-19, NEGATIVE — the narrowing is FALSIFIED as an +// import-closure-pollution repair. Two-sided test (paired same-host comparison, per the standing +// acceptance bar: cost must collapse when the closure narrows AND not collapse under mere +// repetition), via gunbc run --claim-run against a fresh release build in one remote dispatch: +// declared_import_closure_lists_rust_import through this narrow probe-backed entry measured 70.0s +// and 69.4s wall (two independent process calls, back to back); the SAME function through +// v2.workflow.class_b_import_closure_transport directly (still carrying its module-level +// extdeps.git / extdeps.git.inspect / gunbc.ci_layer_roots imports) measured 69.98s in the identical +// dispatch, identical host, moments apart. Narrow and heavy are statistically indistinguishable. +// ambient_pool_provider_preserves_listed_import (which calls the observe function twice in one +// process) measured 80.8s, consistent with the same fixed floor rather than a per-import-closure +// charge. CORRECTED MAGNITUDE (per-row floor line, from the required floor's own +// [floor-witness-slow] output for these two identities, not the standalone harness): +// declared_import_closure_lists_rust_import 24674ms and +// ambient_pool_provider_preserves_listed_import 31603ms -- the standalone --claim-run figures +// (70.0s/80.8s) are ~2-3x inflated because a standalone claim run pays the corpus-wide load/index +// term once per claim while the floor pays it once per MultiEntryIndex, amortized across the whole +// discovered roster (see DESIGN.md's floor-shared-compute-memoization open thread on +// build_both_closure_edge_index, whose size-independence claim these figures corroborate on a +// different subject rather than re-derive). The paired standalone comparison remains the right +// instrument for detecting a closure-size effect (narrow vs heavy, same process shape); only its +// absolute magnitude needs the floor's line as the citable number. Both agree: narrow and heavy did +// not diverge, and both sit far over the 1552ms ceiling. Neither approaches the printed +// compile.frontend/normalize/reconcile/analyses phase timings (~1-2s total each), so the ~25-32s +// floor-line cost is spent where entry-closure resolution does not reach. DECIDED (ATTRIBUTION-3 +// lane, dashboard adhoc-68d59f0c-bc2, 2026-08-19): the hedge above is now a typed +// SharedFillDisposition verdict. #8455 landed the shared_fill ledger AFTER #8457 quarantined this +// module by name, so no floor run had both -- to observe one, this module was renamed for exactly +// one CI pass to test.claim.probe_rust_test_fixtures_import_closure_witness (fn bodies +// byte-identical, only the module line changed) on a throwaway, never-merged PR (#8563, run +// 32291153434 / job 96192007757), then discarded. Result: both rows are +// SharedFillExclusiveToOneModule. Every module_graph_facts/module_path_index/reference_edges fill +// either row touches is keyed on class_b_declared_import_pool_roots (this witness's own narrow +// 4-root pool, unique in the corpus) and paid_by exactly this module's own fn, consumer_modules=1, +// disposition=exclusive: declared_import_closure_lists_rust_import pays module_graph_facts +// fill_ms=731 (inclusive_ms=17441, nesting module_path_index fill_ms=11328 + reference_edges +// fill_ms=5381); ambient_pool_provider_preserves_listed_import's perturbed-key call pays its own +// fresh module_graph_facts fill_ms=764 (inclusive_ms=18479, nesting module_path_index fill_ms=12463 +// + reference_edges fill_ms=5252), while its baseline call reuses declared's fill for free +// (declared's row shows consumer_claims=1, the recorded hit). That run's TOTAL line: fills=17, +// shared_fill_ms=0 -- zero SharedFillSharedAcrossModules exemplars anywhere in that floor pass, so +// this pool's exclusivity is not an artifact of a thin probe. Denominator honesty: the attributed +// fill accounts for ~17.4s of declared's ~27s probe-run cost and ~18.5s of ambient's ~37.8s -- the +// remainder is real per-call cost the shared_fill ledger does not instrument (candidate: +// build_both_closure_edge_index, confirmed not shared_fill-wrapped; not asserted further). +// CONCLUSION: the module split (v2.workflow.class_b_import_closure_probe) is a legitimate DESIGN.md +// §3 relocation-not-refork decomposition and stays -- rows 1-2 genuinely do not need +// git/git.inspect/ci_layer_roots -- but it is NOT a witness-cost fix and this file does NOT leave +// long/ on its account; 24.7-31.6s (floor line) / 70-80s (standalone) both remain far over the +// 1552ms ceiling. Second candidate this lane has falsified as import-closure pollution (after the +// loop/bind witnesses), not a second exemplar; see the lane's PR description for the full delta. test fn declared_import_closure_lists_rust_import() -> Bool { class_b_declared_import_closure_lists_rust_import() diff --git a/dag/test/claim/long/where_refinement_enforcement_witness_test.dag b/dag/test/claim/long/where_refinement_enforcement_witness_test.dag index 6b0ef67a71c..66f500ac732 100644 --- a/dag/test/claim/long/where_refinement_enforcement_witness_test.dag +++ b/dag/test/claim/long/where_refinement_enforcement_witness_test.dag @@ -13,7 +13,47 @@ import gunbc.compile_diagnostic_census { data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data where_refinement_enforcement_witness_note: String = "PR #7438 where-refinement witnesses via compile_dag_rust_emit_check, which uses the same compile-clean HARD authority as CI (compile_clean_diagnostic_is_hard — review 45010). CONSTRUCTION WALL (hard TypeMismatch, compile-clean red): decidable predicates at LITERAL sites — gt_zero/range/non_empty on int/string literals including unary-negated int literals (review 45131), record fields, direct returns, data inits, call args, as-casts (review 45036); inherited predicates compose through refined-alias chains at ARBITRARY depth (review 45121 — NonEmptyStr where brand; corrected node://adhoc-2ccd029d-c1d, 2026-08-18 — the prior wording was true only for predicate composition, not for base-type-mismatch detection, which silently degraded past depth 1). CORRECTED (node://adhoc-2ccd029d-c1d): two absorbing-fallback defects fixed at their single authority, both now proven at depth 2 and depth 3, generic over depth by construction (no depth-specific code). (a) kernel_value_declared_type_mismatch (record fields, call args) carried its own duplicate one-level peel of the formal's refinement wrapper instead of reusing the already-correct arbitrary-depth peel_where_refinement_base; past depth 1 it landed on an intermediate alias name and an overly-permissive decl_is_refinement_over_actual check silently deferred to the advisory arm instead of refusing a genuine base-kernel-type mismatch — now it calls peel_where_refinement_base directly (DESIGN §3 single authority), fixing both call sites (record-field init and call-arg checking) from one change. (b) where_refinement_diags_for_predicate (direct returns, data inits — which never reach kernel_value_declared_type_mismatch at all, so this was the only wall there) used expr_literal_int_optional/expr_literal_string_optional's Absent arm to mean 'non-literal, defer to advisory' — but Absent also fires for a literal of the WRONG kind (a String literal at an Int-refined position, or vice versa), so a wrong-kind literal was misclassified as non-literal and silently deferred rather than refused; a new expr_is_any_literal(expr) predicate (00_core.dag) now distinguishes 'any literal, of any kind' (refuse) from 'genuinely not a literal' (unchanged advisory), checked identically in both the int- and string-predicate branches. Emit-side symptom: the generic nested-record data-literal emit template in 05_emit_rust.dag (serde_json::from_value(...).expect(\"valid data definition\")) is correct-by-construction for any literal this wall actually admits; the previously-reachable panic on a type-mismatched literal was a downstream consequence of (a)/(b) admitting bad state, not an independent emit defect, and needed no separate code change once the admission wall closed. DEFERRAL (WhereRefinementUnenforced advisory, compile-clean green): genuinely non-literal values at refined positions and deferred predicates (brand, Pattern) — wall after grounding (decidable, evidence carrier missing); counted via compile_clean_diagnostic_histogram, not silently widened. dissolve-on: feature:refinement-evidence-at-non-literal-positions. Centralized via with_expected_where_refinement_diags (review 44949). Seed-retained host seam (review 45103): src/v1/stage0/src/cli_run.rs compile_dag_rust_emit_check + compile_clean_diagnostic_is_advisory + histogram key — wires the existing builtin consumer to compile_clean_diagnostic_is_hard / WhereRefinementUnenforced counting; no new policy. Witness scaffold dissolves when the v1 compile-clean witness layer can assert diagnostic shape without the seed host bin (docs/plans/witness-realization-plan.md P0 lane). Predicate-kind strings: dissolve-on feature:where-refinement-predicate-coproduct." +// PR #7438 where-refinement witnesses via compile_dag_rust_emit_check, which uses the same +// compile-clean HARD authority as CI (compile_clean_diagnostic_is_hard — review 45010). +// CONSTRUCTION WALL (hard TypeMismatch, compile-clean red): decidable predicates at LITERAL sites — +// gt_zero/range/non_empty on int/string literals including unary-negated int literals (review +// 45131), record fields, direct returns, data inits, call args, as-casts (review 45036); inherited +// predicates compose through refined-alias chains at ARBITRARY depth (review 45121 — NonEmptyStr +// where brand; corrected node://adhoc-2ccd029d-c1d, 2026-08-18 — the prior wording was true only +// for predicate composition, not for base-type-mismatch detection, which silently degraded past +// depth 1). CORRECTED (node://adhoc-2ccd029d-c1d): two absorbing-fallback defects fixed at their +// single authority, both now proven at depth 2 and depth 3, generic over depth by construction (no +// depth-specific code). (a) kernel_value_declared_type_mismatch (record fields, call args) carried +// its own duplicate one-level peel of the formal's refinement wrapper instead of reusing the +// already-correct arbitrary-depth peel_where_refinement_base; past depth 1 it landed on an +// intermediate alias name and an overly-permissive decl_is_refinement_over_actual check silently +// deferred to the advisory arm instead of refusing a genuine base-kernel-type mismatch — now it +// calls peel_where_refinement_base directly (DESIGN §3 single authority), fixing both call sites +// (record-field init and call-arg checking) from one change. (b) +// where_refinement_diags_for_predicate (direct returns, data inits — which never reach +// kernel_value_declared_type_mismatch at all, so this was the only wall there) used +// expr_literal_int_optional/expr_literal_string_optional's Absent arm to mean 'non-literal, defer +// to advisory' — but Absent also fires for a literal of the WRONG kind (a String literal at an +// Int-refined position, or vice versa), so a wrong-kind literal was misclassified as non-literal +// and silently deferred rather than refused; a new expr_is_any_literal(expr) predicate +// (00_core.dag) now distinguishes 'any literal, of any kind' (refuse) from 'genuinely not a +// literal' (unchanged advisory), checked identically in both the int- and string-predicate +// branches. Emit-side symptom: the generic nested-record data-literal emit template in +// 05_emit_rust.dag (serde_json::from_value(...).expect("valid data definition")) is +// correct-by-construction for any literal this wall actually admits; the previously-reachable panic +// on a type-mismatched literal was a downstream consequence of (a)/(b) admitting bad state, not an +// independent emit defect, and needed no separate code change once the admission wall closed. +// DEFERRAL (WhereRefinementUnenforced advisory, compile-clean green): genuinely non-literal values +// at refined positions and deferred predicates (brand, Pattern) — wall after grounding (decidable, +// evidence carrier missing); counted via compile_clean_diagnostic_histogram, not silently widened. +// dissolve-on: feature:refinement-evidence-at-non-literal-positions. Centralized via +// with_expected_where_refinement_diags (review 44949). Seed-retained host seam (review 45103): +// src/v1/stage0/src/cli_run.rs compile_dag_rust_emit_check + compile_clean_diagnostic_is_advisory + +// histogram key — wires the existing builtin consumer to compile_clean_diagnostic_is_hard / +// WhereRefinementUnenforced counting; no new policy. Witness scaffold dissolves when the v1 +// compile-clean witness layer can assert diagnostic shape without the seed host bin +// (docs/plans/witness-realization-plan.md P0 lane). Predicate-kind strings: dissolve-on +// feature:where-refinement-predicate-coproduct. fn w_positive_int_direct_return_red() -> Bool { compile_dag_rust_emit_check( @@ -303,7 +343,18 @@ fn w_depth2_wrong_base_type_data_init_green() -> Bool { ) } -data where_refinement_cause_pinning_note: String = "node://adhoc-2ccd029d-c1d follow-up (parent review, 2026-08-19): every red/green pair above asserts only compile_dag_rust_emit_check's coarse Bool — false on ANY hard diagnostic, true on none — which cannot distinguish this wall's own TypeMismatch from an unrelated hard diagnostic an unrecognized-regression fixture might trip instead ('a negative control satisfied by an unrelated harness accident passes invisibly'). The four depth-2/3 base-type-mismatch specimens below additionally pin CAUSE via compile_dag_diagnostic_census: the red source must produce exactly one BLOCKING TypeMismatch row (not merely 'something blocking'), and the green source must produce zero. This is deliberately scoped to the base-type-mismatch specimens this PR introduces (root cause (a), and (b)'s data-init path) rather than retrofitted across all 38 pre-existing tests in this file, which is a larger, separately-scoped census migration (dag/test/claim/compile_diagnostic_census_witness_test.dag already establishes the pattern for other walls) and not this PR's fix." +// node://adhoc-2ccd029d-c1d follow-up (parent review, 2026-08-19): every red/green pair above +// asserts only compile_dag_rust_emit_check's coarse Bool — false on ANY hard diagnostic, true on +// none — which cannot distinguish this wall's own TypeMismatch from an unrelated hard diagnostic an +// unrecognized-regression fixture might trip instead ('a negative control satisfied by an unrelated +// harness accident passes invisibly'). The four depth-2/3 base-type-mismatch specimens below +// additionally pin CAUSE via compile_dag_diagnostic_census: the red source must produce exactly one +// BLOCKING TypeMismatch row (not merely 'something blocking'), and the green source must produce +// zero. This is deliberately scoped to the base-type-mismatch specimens this PR introduces (root +// cause (a), and (b)'s data-init path) rather than retrofitted across all 38 pre-existing tests in +// this file, which is a larger, separately-scoped census migration +// (dag/test/claim/compile_diagnostic_census_witness_test.dag already establishes the pattern for +// other walls) and not this PR's fix. fn depth_wrong_base_type_mismatch_count(source: String) -> Int { match compile_dag_diagnostic_census(source) { @@ -565,9 +616,81 @@ test fn where_refinement_wrong_kind_literal_direct_return_accepts() -> Bool { w_wrong_kind_literal_direct_return_green() } -data where_refinement_promotion_is_not_execution_note: String = "MY OWN DISSOLUTION COMMIT CLAIMED SOMETHING THIS FILE'S HOME MAKES FALSE, AND THE CORRECTION BELONGS HERE RATHER THAN IN THE COMMIT THAT CANNOT BE READ FROM THE TREE. gunbc#8619 deleted the known-red row for where_refinement_lower_hex_40_implies_non_empty_credits_evidence once its trigger was satisfied (the 04_infer stage0 mirror regenerated, so the compiled harness carries the min-length implication), and said the witness thereby PROMOTES TO ORDINARY DiscoverySelection AS THE PERMANENT REGRESSION CONTROL. THAT SECOND HALF IS FALSE FOR A FILE UNDER dag/test/claim/long/. That prefix is excluded from witness discovery AT DIR GRAIN (gunbc.ci_layer_roots long_lane_exclusion_note), so ordinary discovery never reaches this module. Deleting the row removed the only thing that NAMED these witnesses; the home ensures nothing else does. The honest state is therefore not promoted-to-executing but EXECUTED NOWHERE. CORRECTED, SAME DAY, BEFORE ANYONE ACTED ON IT: an earlier revision of this row added that this is 'strictly worse than the quarantine it replaced, because a known-red row is at least counted'. THAT IS FALSE and the correction matters because it changes what is owed. v2.workflow.required_floor is explicit that EVERY DISCOVERED SITE gets exactly one RequiredFloorDisposition keyed by its qualified module.function identity (operator ruling 2026-08-19), and the long home is one of its Declined arms rather than an absence. So these identities ARE discovered and ARE counted at identity grain as declined, and aggregate into the floor's declined_long figure. What was lost by deleting the known-red row is not counting; it is the row's own reason string and owner. Counted-and-declined is a weaker protection than executed, and a better one than silence. A SECOND CORRECTION IN THE SAME BREATH, because it changes the remedy: admission is tested against the module's AUTHORED NAME, not its file path -- long_home_prefixes() holds 'test.claim.long.' and this module's first line declares test.claim.long.where_refinement_enforcement_witness. Moving the FILE while keeping the module name would therefore change nothing, and the next-rung options below must be read as renaming the module (with its file), never as relocating a file. WORTH STATING BLUNTLY BECAUSE IT IS THE WHOLE LESSON: required_floor's own header records that the previous host tested a PATH, which 'made a directory the admission authority', and names that as the root cause the 2026-08-04 ruling identifies. I proposed to fix this by moving a directory. I reproduced the exact mistake the mechanism was built to stop, inside the mechanism that stops it, while reading the file that says so. WHY THE ROW WAS STILL RIGHT TO DELETE: it asserted a RED that is no longer red, and re-adding it would be a false claim about the current tree. The defect is not the deletion, it is that promotion presumes a discovering consumer this file does not have. RUNG: this file's witnesses sit at MITIGATABLE, protected by the local recipe and by review diligence, not by any executing gate -- claim_batch --source-root dag --source-root src/v2 --entry dag/test/claim/long/where_refinement_enforcement_witness_test.dag --functions . NEXT-RUNG TRIGGER, and it is a decision I did not take unilaterally because it trades one real cost for another: either this module is RENAMED out of the test.claim.long. prefix (and its file moved with it) so the floor admits it -- which puts its per-witness eval cost into the executed roster, the exact thing the home exists to keep out, and with the per-witness eval deadline dropped in the 2026-08-15 floor cut nothing would REFUSE an over-budget witness, so the cost would land silently on every run -- or the long home acquires an executing consumer, which the same floor cut deleted with falsifier.yml and has not re-added. The first is not this lane's to take unilaterally and the second is not this lane's to build. NOT A ROUTE: v2.workflow.floor_route_gap, which landed 2026-08-20 for unexecuted witnesses, is scoped to identities the floor EXECUTES that reach a host effect with no hermetic arm. These identities do not execute at all, and that roster's own reverse join reds the build on an enrolled identity that did not execute -- so enrolling here would be a false claim, not a shortcut. THE PROVENANCE OF THAT SENTENCE, marked because this corpus was burned by exactly this today: it is READ FROM THAT MODULE'S CONTRACT PROSE, not observed. A carrier's description of its own mechanism is not evidence the mechanism behaves that way -- a gate that never executed and a lens reading a file that exists nowhere were both fully described in prose. It is accepted here on two narrow grounds: the claim is about a REFUSAL rather than a green, so trusting it wrongly yields a weaker refusal rather than a silent accept; and exercising it would mean authoring a knowingly-false row to red a build. If a free way to exercise that join appears, take it; do not manufacture one. WHAT MUST NOT HAPPEN MEANWHILE: nobody should read the absence of red here as evidence that the min-length implication holds. Nothing has executed these assertions on CI. See gunbc.explicit_witness_admission known_red_class_note for the trigger-discipline rule this same episode produced." - -data where_refinement_min_length_implication_witness_note: String = "WHY THESE ASSERT A COUNT AND NOT A Bool, which is the whole reason this block exists. WhereRefinementUnenforced is ADVISORY — compile-clean GREEN. So compile_dag_rust_emit_check returns true for the implication sites both BEFORE and AFTER the fix, and a Bool-shaped witness pair over them would have passed identically against the unfixed compiler: a green control satisfied by the fact that nothing ever refused. That is the specification-without-execution trap in its exact local form, and the only instrument that escapes it is the one that can see a diagnostic the severity filter discards. These therefore go through compile_dag_diagnostic_census and assert the ADVISORY WhereRefinementUnenforced count at each site, which moves 1 -> 0 for a credited implication and STAYS 1 for an uncredited one. THE THIRD WITNESS IS THE ONE THAT MATTERS MOST and it is a fail-open control, not a feature: a formal lower_hex_64 position fed a lower_hex_128 value must REMAIN advisory. If where_predicate_required_min_length ever grows a lower_hex_* row — the single most natural-looking edit anyone will propose to this table, since it already sits beside a guaranteed-length table carrying exactly those names — then 128 >= 64 credits a 128-digit string as a valid sha256 hex and this witness goes red. It is a permanent regression control on the asymmetry, not a probe of a landed behavior, and it does not retire when the wall lands (DESIGN 4b meta-obligation 4: a climb deletes the redundant production machinery, never the evidence)." +// MY OWN DISSOLUTION COMMIT CLAIMED SOMETHING THIS FILE'S HOME MAKES FALSE, AND THE CORRECTION +// BELONGS HERE RATHER THAN IN THE COMMIT THAT CANNOT BE READ FROM THE TREE. gunbc#8619 deleted the +// known-red row for where_refinement_lower_hex_40_implies_non_empty_credits_evidence once its +// trigger was satisfied (the 04_infer stage0 mirror regenerated, so the compiled harness carries +// the min-length implication), and said the witness thereby PROMOTES TO ORDINARY DiscoverySelection +// AS THE PERMANENT REGRESSION CONTROL. THAT SECOND HALF IS FALSE FOR A FILE UNDER +// dag/test/claim/long/. That prefix is excluded from witness discovery AT DIR GRAIN +// (gunbc.ci_layer_roots long_lane_exclusion_note), so ordinary discovery never reaches this module. +// Deleting the row removed the only thing that NAMED these witnesses; the home ensures nothing else +// does. The honest state is therefore not promoted-to-executing but EXECUTED NOWHERE. CORRECTED, +// SAME DAY, BEFORE ANYONE ACTED ON IT: an earlier revision of this row added that this is 'strictly +// worse than the quarantine it replaced, because a known-red row is at least counted'. THAT IS +// FALSE and the correction matters because it changes what is owed. v2.workflow.required_floor is +// explicit that EVERY DISCOVERED SITE gets exactly one RequiredFloorDisposition keyed by its +// qualified module.function identity (operator ruling 2026-08-19), and the long home is one of its +// Declined arms rather than an absence. So these identities ARE discovered and ARE counted at +// identity grain as declined, and aggregate into the floor's declined_long figure. What was lost by +// deleting the known-red row is not counting; it is the row's own reason string and owner. +// Counted-and-declined is a weaker protection than executed, and a better one than silence. A +// SECOND CORRECTION IN THE SAME BREATH, because it changes the remedy: admission is tested against +// the module's AUTHORED NAME, not its file path -- long_home_prefixes() holds 'test.claim.long.' +// and this module's first line declares test.claim.long.where_refinement_enforcement_witness. +// Moving the FILE while keeping the module name would therefore change nothing, and the next-rung +// options below must be read as renaming the module (with its file), never as relocating a file. +// WORTH STATING BLUNTLY BECAUSE IT IS THE WHOLE LESSON: required_floor's own header records that +// the previous host tested a PATH, which 'made a directory the admission authority', and names that +// as the root cause the 2026-08-04 ruling identifies. I proposed to fix this by moving a directory. +// I reproduced the exact mistake the mechanism was built to stop, inside the mechanism that stops +// it, while reading the file that says so. WHY THE ROW WAS STILL RIGHT TO DELETE: it asserted a RED +// that is no longer red, and re-adding it would be a false claim about the current tree. The defect +// is not the deletion, it is that promotion presumes a discovering consumer this file does not +// have. RUNG: this file's witnesses sit at MITIGATABLE, protected by the local recipe and by review +// diligence, not by any executing gate -- claim_batch --source-root dag --source-root src/v2 +// --entry dag/test/claim/long/where_refinement_enforcement_witness_test.dag --functions . +// NEXT-RUNG TRIGGER, and it is a decision I did not take unilaterally because it trades one real +// cost for another: either this module is RENAMED out of the test.claim.long. prefix (and its file +// moved with it) so the floor admits it -- which puts its per-witness eval cost into the executed +// roster, the exact thing the home exists to keep out, and with the per-witness eval deadline +// dropped in the 2026-08-15 floor cut nothing would REFUSE an over-budget witness, so the cost +// would land silently on every run -- or the long home acquires an executing consumer, which the +// same floor cut deleted with falsifier.yml and has not re-added. The first is not this lane's to +// take unilaterally and the second is not this lane's to build. NOT A ROUTE: +// v2.workflow.floor_route_gap, which landed 2026-08-20 for unexecuted witnesses, is scoped to +// identities the floor EXECUTES that reach a host effect with no hermetic arm. These identities do +// not execute at all, and that roster's own reverse join reds the build on an enrolled identity +// that did not execute -- so enrolling here would be a false claim, not a shortcut. THE PROVENANCE +// OF THAT SENTENCE, marked because this corpus was burned by exactly this today: it is READ FROM +// THAT MODULE'S CONTRACT PROSE, not observed. A carrier's description of its own mechanism is not +// evidence the mechanism behaves that way -- a gate that never executed and a lens reading a file +// that exists nowhere were both fully described in prose. It is accepted here on two narrow +// grounds: the claim is about a REFUSAL rather than a green, so trusting it wrongly yields a weaker +// refusal rather than a silent accept; and exercising it would mean authoring a knowingly-false row +// to red a build. If a free way to exercise that join appears, take it; do not manufacture one. +// WHAT MUST NOT HAPPEN MEANWHILE: nobody should read the absence of red here as evidence that the +// min-length implication holds. Nothing has executed these assertions on CI. See +// gunbc.explicit_witness_admission known_red_class_note for the trigger-discipline rule this same +// episode produced. + +// WHY THESE ASSERT A COUNT AND NOT A Bool, which is the whole reason this block exists. +// WhereRefinementUnenforced is ADVISORY — compile-clean GREEN. So compile_dag_rust_emit_check +// returns true for the implication sites both BEFORE and AFTER the fix, and a Bool-shaped witness +// pair over them would have passed identically against the unfixed compiler: a green control +// satisfied by the fact that nothing ever refused. That is the specification-without-execution trap +// in its exact local form, and the only instrument that escapes it is the one that can see a +// diagnostic the severity filter discards. These therefore go through compile_dag_diagnostic_census +// and assert the ADVISORY WhereRefinementUnenforced count at each site, which moves 1 -> 0 for a +// credited implication and STAYS 1 for an uncredited one. THE THIRD WITNESS IS THE ONE THAT MATTERS +// MOST and it is a fail-open control, not a feature: a formal lower_hex_64 position fed a +// lower_hex_128 value must REMAIN advisory. If where_predicate_required_min_length ever grows a +// lower_hex_* row — the single most natural-looking edit anyone will propose to this table, since +// it already sits beside a guaranteed-length table carrying exactly those names — then 128 >= 64 +// credits a 128-digit string as a valid sha256 hex and this witness goes red. It is a permanent +// regression control on the asymmetry, not a probe of a landed behavior, and it does not retire +// when the wall lands (DESIGN 4b meta-obligation 4: a climb deletes the redundant production +// machinery, never the evidence). fn where_refinement_advisory_count(source: String) -> Int { match compile_dag_diagnostic_census(source) { diff --git a/dag/test/claim/machine_shape_construction_wall_test.dag b/dag/test/claim/machine_shape_construction_wall_test.dag index e951269e91b..846f631c035 100644 --- a/dag/test/claim/machine_shape_construction_wall_test.dag +++ b/dag/test/claim/machine_shape_construction_wall_test.dag @@ -20,7 +20,9 @@ import v2.std.witness { Witness } data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data machine_shape_wall_witness_note: String = "RED/GREEN controls for MachineShape single-constructor compile gate (synthetic fixtures). A Transform call with callee Atom ^MachineShape is unsanctioned outside std.machine_shape and extdeps.*.machine_shape; ^shape_from_catalog is the sanctioned producer path." +// RED/GREEN controls for MachineShape single-constructor compile gate (synthetic fixtures). A +// Transform call with callee Atom ^MachineShape is unsanctioned outside std.machine_shape and +// extdeps.*.machine_shape; ^shape_from_catalog is the sanctioned producer path. fn ms_atom(id: Symbol) -> Node { Node { diff --git a/dag/test/claim/managed_directory_witness_test.dag b/dag/test/claim/managed_directory_witness_test.dag index fa0a4bc7efb..9121af4feb0 100644 --- a/dag/test/claim/managed_directory_witness_test.dag +++ b/dag/test/claim/managed_directory_witness_test.dag @@ -21,7 +21,16 @@ import v2.std.live_tree { LiveTreeDisposition, SubstrateInputsOnly } data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data managed_directory_witness_note: String = "The derivation is witnessed on SYNTHETIC principals rather than on the fleet roster, so these stay true when srv1's service account changes — which it is scheduled to, when the dashboard runtime stops being the operator's personal account. What is under test is the RULE (dependents plus uid/gid comparison determine the mode), not srv1's current answer; the srv1 answer is witnessed separately in test.claim.live_deploy.emit against the emitted script. The three class witnesses are the load-bearing ones: they prove the mode WIDENS when a dependent is genuinely added and only then, which is the property that makes deriving better than choosing. The octal witnesses cover the serializer independently, including the special-bits digit that no caller sets today — an unset digit rendered by computation rather than by assumption is the difference between 0750 and 2750 the day setgid is needed." +// The derivation is witnessed on SYNTHETIC principals rather than on the fleet roster, so these +// stay true when srv1's service account changes — which it is scheduled to, when the dashboard +// runtime stops being the operator's personal account. What is under test is the RULE (dependents +// plus uid/gid comparison determine the mode), not srv1's current answer; the srv1 answer is +// witnessed separately in test.claim.live_deploy.emit against the emitted script. The three class +// witnesses are the load-bearing ones: they prove the mode WIDENS when a dependent is genuinely +// added and only then, which is the property that makes deriving better than choosing. The octal +// witnesses cover the serializer independently, including the special-bits digit that no caller +// sets today — an unset digit rendered by computation rather than by assumption is the difference +// between 0750 and 2750 the day setgid is needed. fn owner_user() -> PosixUser { PosixUser { name: "svc", uid: 4000, gid: 4000, diff --git a/dag/test/claim/map_lookup_dual_dispatch_witness_test.dag b/dag/test/claim/map_lookup_dual_dispatch_witness_test.dag index 22363435497..6aae645207a 100644 --- a/dag/test/claim/map_lookup_dual_dispatch_witness_test.dag +++ b/dag/test/claim/map_lookup_dual_dispatch_witness_test.dag @@ -1,6 +1,5 @@ module test.claim.map_lookup_dual_dispatch_witness_test - data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly test fn map_get_method_routes_through_dual_dispatch_chokepoint() -> Bool { @@ -21,7 +20,11 @@ test fn lookup_builtin_routes_through_dual_dispatch_chokepoint() -> Bool { } } -data lookup_witness_contract_note: String = "lookup routes through the dual-dispatch chokepoint, which wraps the hit in the Optional coproduct (Present { value } | Absent) — the v1_rt Witness carrier was deleted (v1_rt-witness-diagnostic-carrier-decouple-design.md); lookup now returns Option natively. Matching Present is still the discriminating form — a raw 7 here would mean the bare builtin BYPASSED the chokepoint, and Present/Absent proves the modeled dispatch runs." +// lookup routes through the dual-dispatch chokepoint, which wraps the hit in the Optional coproduct +// (Present { value } | Absent) — the v1_rt Witness carrier was deleted +// (v1_rt-witness-diagnostic-carrier-decouple-design.md); lookup now returns Option natively. +// Matching Present is still the discriminating form — a raw 7 here would mean the bare builtin +// BYPASSED the chokepoint, and Present/Absent proves the modeled dispatch runs. test fn std_graph_build_adjacency_views_evaluates() -> Bool { let names = ["a", "b"] diff --git a/dag/test/claim/map_lookup_key_generic_realization_witness_test.dag b/dag/test/claim/map_lookup_key_generic_realization_witness_test.dag index 549800c2bfe..80127530cac 100644 --- a/dag/test/claim/map_lookup_key_generic_realization_witness_test.dag +++ b/dag/test/claim/map_lookup_key_generic_realization_witness_test.dag @@ -21,7 +21,10 @@ data live_tree_disposition: LiveTreeDisposition = ReadsLiveTree // v2 closure — and it is pinned here at signature grain rather than by name, because the // three-file name agreement that runtime_rust_seed_bootstrap_sync_witness_test already checks // stayed green through the entire life of the defect. -data map_lookup_key_generic_realization_note: String = "v1_rt::lookup realizes the ReceiverKey-generic PartialFunction lookup row and must be generic over the key type, like every sibling map builtin. A String-pinned realization type-errors at every non-String-keyed Map in emitted Rust while the interpreter accepts it, and no .dag-side check can see the difference." +// v1_rt::lookup realizes the ReceiverKey-generic PartialFunction lookup row and must be generic +// over the key type, like every sibling map builtin. A String-pinned realization type-errors at +// every non-String-keyed Map in emitted Rust while the interpreter accepts it, and no .dag-side +// check can see the difference. data runtime_rust_dag_path: String = "src/v1/runtime_rust.dag" data runtime_rust_seed_path: String = "src/v1/stage0/src/v1_compiler_runtime_rust.rs" diff --git a/dag/test/claim/match_arm_pattern_identity_emission_witness_test.dag b/dag/test/claim/match_arm_pattern_identity_emission_witness_test.dag index 4c2d786d8a7..0af3f7d2307 100644 --- a/dag/test/claim/match_arm_pattern_identity_emission_witness_test.dag +++ b/dag/test/claim/match_arm_pattern_identity_emission_witness_test.dag @@ -1,6 +1,28 @@ module test.claim.match_arm_pattern_identity_emission_witness_test -data match_arm_pattern_identity_emission_migration_note: String = "Migrated (partial) from src/v1/tests/claim/v1_match_pattern_identity_test.dag (dead witness tree triage, dashboard node adhoc-9b80ec49-d63; that file's only historical consumer, v1_claim_scoped_witness_batch, was deleted 2026-08-15, so none of its 5 tests had ever executed). The source file's own note names the exact defect class this witness protects: Node.match_pattern was once missing from both v1 identity readers (dag_collect_support.dag_node_surface_fingerprint_rec, the content fingerprint; and dag_collect.dag_collect_node_tree, the DAG artifact collector), so two Match arms differing ONLY in their pattern aliased to the same cache identity and the second arm was silently treated as a duplicate of the first anywhere that key drove deduplication -- compile.dag's DAG artifact node table. That is an emitter-behaviour defect class: a real fixed instance of it would manifest as a missing or duplicated arm body in the emitted Rust text. Two of the four original assertions (distinct-literal-pattern and distinct-variant-name fingerprints) migrate directly onto compile_dag_rust_emit_check as a black-box 'both arm bodies survive to emission, distinctly' check -- compiling a match with differently-patterned, differently-bodied arms and requiring every arm's distinguishing marker string to appear in the emitted program. The remaining two assertions (w_variant_pattern_field_bindings_are_registered_as_dag_artifacts, w_unrelated_field_binding_is_not_registered) test dag_collect_insert_slots/dag_node_key directly against a hand-built Node -- DAG-artifact-table registration bookkeeping with no representation in single-shot emitted Rust text, since compile_dag_rust_emit_check observes one compiled program's output and not the incremental artifact table's membership. Those two are RETIRED with this note as their receipt rather than migrated: v1 is semantics-frozen with active maintenance per gunbc.v1_maintenance_standing, and a v1-compiler-local cargo test remains the correct restoration path if that registration surface needs a live regression check again." +// Migrated (partial) from src/v1/tests/claim/v1_match_pattern_identity_test.dag (dead witness tree +// triage, dashboard node adhoc-9b80ec49-d63; that file's only historical consumer, +// v1_claim_scoped_witness_batch, was deleted 2026-08-15, so none of its 5 tests had ever executed). +// The source file's own note names the exact defect class this witness protects: Node.match_pattern +// was once missing from both v1 identity readers +// (dag_collect_support.dag_node_surface_fingerprint_rec, the content fingerprint; and +// dag_collect.dag_collect_node_tree, the DAG artifact collector), so two Match arms differing ONLY +// in their pattern aliased to the same cache identity and the second arm was silently treated as a +// duplicate of the first anywhere that key drove deduplication -- compile.dag's DAG artifact node +// table. That is an emitter-behaviour defect class: a real fixed instance of it would manifest as a +// missing or duplicated arm body in the emitted Rust text. Two of the four original assertions +// (distinct-literal-pattern and distinct-variant-name fingerprints) migrate directly onto +// compile_dag_rust_emit_check as a black-box 'both arm bodies survive to emission, distinctly' +// check -- compiling a match with differently-patterned, differently-bodied arms and requiring +// every arm's distinguishing marker string to appear in the emitted program. The remaining two +// assertions (w_variant_pattern_field_bindings_are_registered_as_dag_artifacts, +// w_unrelated_field_binding_is_not_registered) test dag_collect_insert_slots/dag_node_key directly +// against a hand-built Node -- DAG-artifact-table registration bookkeeping with no representation +// in single-shot emitted Rust text, since compile_dag_rust_emit_check observes one compiled +// program's output and not the incremental artifact table's membership. Those two are RETIRED with +// this note as their receipt rather than migrated: v1 is semantics-frozen with active maintenance +// per gunbc.v1_maintenance_standing, and a v1-compiler-local cargo test remains the correct +// restoration path if that registration surface needs a live regression check again. fn arm_reaches_emission(source: String, path: String, markers: List) -> Bool { compile_dag_rust_emit_check(source, path, markers, []) diff --git a/dag/test/claim/match_exhaustiveness_coproduct_witness_test.dag b/dag/test/claim/match_exhaustiveness_coproduct_witness_test.dag index 89f71a2fa82..8c694863c1d 100644 --- a/dag/test/claim/match_exhaustiveness_coproduct_witness_test.dag +++ b/dag/test/claim/match_exhaustiveness_coproduct_witness_test.dag @@ -17,7 +17,11 @@ import tools.multi_module_compile_fixture { data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data match_exhaustiveness_coproduct_witness_note: String = "Paired control for v1 coproduct match exhaustiveness via compile_dag_diagnostic_census. An exhaustive Trio match must observe zero NonExhaustiveMatch rows; a match omitting Blue must refuse with exactly one counted NonExhaustiveMatch diagnostic — not merely 'refuses', which would pass today when the checker lists the full declared roster. Precision of the missing variant list is pinned in infer_semantics_witness (check_match_exhaustiveness missing.len == 1)." +// Paired control for v1 coproduct match exhaustiveness via compile_dag_diagnostic_census. An +// exhaustive Trio match must observe zero NonExhaustiveMatch rows; a match omitting Blue must +// refuse with exactly one counted NonExhaustiveMatch diagnostic — not merely 'refuses', which would +// pass today when the checker lists the full declared roster. Precision of the missing variant list +// is pinned in infer_semantics_witness (check_match_exhaustiveness missing.len == 1). data exhaustive_coproduct_source: String = "module exhaust_exhaustive\ntype Trio = Red | Green | Blue\nfn f(c: Trio) -> Bool {\n match c {\n Red => true\n Green => false\n Blue => true\n }\n}\n" diff --git a/dag/test/claim/materialization_kernel_closing_frontier_audit_witness_test.dag b/dag/test/claim/materialization_kernel_closing_frontier_audit_witness_test.dag index 13252f7496b..035ac3eddbf 100644 --- a/dag/test/claim/materialization_kernel_closing_frontier_audit_witness_test.dag +++ b/dag/test/claim/materialization_kernel_closing_frontier_audit_witness_test.dag @@ -13,7 +13,14 @@ import gunbc.materialization_kernel_closing_frontier_audit { import std.types { Bool } import v2.std.algebra { length } -data materialization_kernel_closing_frontier_audit_witness_note: String = "Discriminating RED for the v1-materialization-kernel closing-frontier audit (brief origin: parent session still-bat-561, Lane F; RENAMED from materialization_kernel_closing_contract_witness per still-bat-561 operator ruling 2026-08-02, msg_9609b3a3 — this module audits the frontier, it is not the roadmap node's closing contract). materialization_kernel_audit_not_all_delivered_today is an EXPECT-RED control (DESIGN §4b): it asserts the AND-fold is false over the seven audited clauses, proving the audit summary can genuinely read false rather than being a vacuous always-true wrapper. It stays enrolled after any clause climbs to Delivered — a later regression that silently reverts a clause to NotDelivered is caught by this same assertion flipping true, not by a fresh test someone forgot to add." +// Discriminating RED for the v1-materialization-kernel closing-frontier audit (brief origin: parent +// session still-bat-561, Lane F; RENAMED from materialization_kernel_closing_contract_witness per +// still-bat-561 operator ruling 2026-08-02, msg_9609b3a3 — this module audits the frontier, not the +// roadmap node's closing contract). materialization_kernel_audit_not_all_delivered_today is an +// EXPECT-RED control (DESIGN §4b): it asserts the AND-fold is false over the seven audited clauses, +// proving the audit summary can read false rather than being a vacuous always-true wrapper. It +// stays enrolled after any clause climbs to Delivered — a silent revert to NotDelivered is caught +// by this assertion flipping true, not by a fresh test someone forgot to add. test fn materialization_kernel_audit_not_all_delivered_today() -> Bool { materialization_kernel_all_clauses_delivered(clauses: closing_frontier_clauses()) == false @@ -24,7 +31,14 @@ test fn materialization_kernel_seven_clauses_enrolled() -> Bool { && length(xs: closing_frontier_clauses()) == 7 } -data materialization_kernel_progress_pin_note: String = "No count literal here (review 47541, DESIGN §5 — a measurement copied from the same hand-authored clause list is not an independent oracle; drop == 4 rather than let editing a verdict row require editing this pin too). The exact-count fact this test previously duplicated is already established at identity grain by the per-id clause_delivered_by_id tests below (as of 2026-08-11: contract_exists and hand_rust_tracking Delivered; warm_hit, refusal and eviction demoted to NotDelivered with their evidence withdrawn; lookup_reorder and production_invocation not delivered) — DESIGN §5's own rule: completeness is an identity join, not a count equality. This test keeps only the two derived properties an id-grain test cannot state: progress is nonzero, and progress has not yet reached the clause count." +// No count literal here (review 47541, DESIGN §5 — a measurement copied from the same hand-authored +// clause list is not an independent oracle; drop == 4 rather than make editing a verdict row edit +// this pin too). The exact count is established at identity grain by the per-id +// clause_delivered_by_id tests below (as of 2026-08-11: contract_exists and hand_rust_tracking +// Delivered; warm_hit, refusal and eviction demoted to NotDelivered with evidence withdrawn; +// lookup_reorder and production_invocation not delivered) — DESIGN §5: completeness is an identity +// join, not a count equality. This test keeps the two derived properties an id-grain test cannot +// state: progress is nonzero and has not yet reached the clause count. test fn materialization_kernel_progress_is_nonzero_and_incomplete() -> Bool { materialization_kernel_progress_count(clauses: closing_frontier_clauses()) > 0 @@ -54,7 +68,17 @@ test fn contract_exists_clause_delivered() -> Bool { clause_delivered_by_id(clauses: closing_frontier_clauses(), id: "contract-exists-and-can-fail") } -data warm_hit_clause_delivered_note: String = "FLIPPED TO NOT-DELIVERED 2026-08-11 (gunbc#8146, review 51152). The three assertions below asserted Delivered while the carrier was demoted to NotDelivered in the same PR — they would have failed on execution, which is the review finding. They are FLIPPED rather than deleted: per DESIGN §4b(4) the control stays enrolled, so each now REQUIRES the demoted state and reds if a clause silently returns to Delivered without its evidence executing again. HISTORY — renamed from warm_hit_clause_partially_delivered_not_falsely_green (DESIGN §4b(4) — an expecting-red probe that greens when its wall lands flips to a permanent regression control, it does not retire). cross_process_hit_skips_semantic_recompute now lands and greens (v1_compiler_tests.resolve_cross_process_cache_test), so the clause reached Delivered; this test's assertion flips from false to true and the test itself becomes the regression control catching a future silent revert." +// FLIPPED TO NOT-DELIVERED 2026-08-11 (gunbc#8146, review 51152). The three assertions below +// asserted Delivered while the carrier was demoted to NotDelivered in the same PR — they would have +// failed on execution, the review finding. FLIPPED rather than deleted: per DESIGN §4b(4) the +// control stays enrolled, so each REQUIRES the demoted state and reds if a clause silently returns +// to Delivered without its evidence executing again. HISTORY — renamed from +// warm_hit_clause_partially_delivered_not_falsely_green (DESIGN §4b(4): an expecting-red probe that +// greens when its wall lands flips to a permanent regression control, it does not retire). +// cross_process_hit_skips_semantic_recompute landed and greens +// (v1_compiler_tests.resolve_cross_process_cache_test), so the clause reached Delivered; the +// assertion flipped from false to true and the test became the regression control against a +// future silent revert. test fn warm_hit_clause_not_delivered_evidence_withdrawn() -> Bool { clause_delivered_by_id(clauses: closing_frontier_clauses(), id: "warm-hit-skips-semantic-recompute") == false diff --git a/dag/test/claim/materialization_ladder_witness_test.dag b/dag/test/claim/materialization_ladder_witness_test.dag index fccab95156b..a007e07b23a 100644 --- a/dag/test/claim/materialization_ladder_witness_test.dag +++ b/dag/test/claim/materialization_ladder_witness_test.dag @@ -1,9 +1,13 @@ module test.claim.materialization_ladder_witness - data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data ladder_witness_note: String = "Each test is one cell of the operator's state x decision table (2026-07-09): the decision is a function of WHEN the redundancy is knowable and WHETHER what was knowable was prepared for. Errors fire only on knowable-but-unprepared; genuine emergence and declared triviality are typed acceptances, never silence. Fixtures mirror the live worked example: a workflow (isolated children) over jobs (shared-state steps), a retry frame (declared replay), a fleet frame (unbounded sibling runs over time)." +// Each test is one cell of the operator's state x decision table (2026-07-09): the decision is a +// function of WHEN the redundancy is knowable and WHETHER what was knowable was prepared for. +// Errors fire only on knowable-but-unprepared; genuine emergence and declared triviality are typed +// acceptances, never silence. Fixtures mirror the live worked example: a workflow (isolated +// children) over jobs (shared-state steps), a retry frame (declared replay), a fleet frame +// (unbounded sibling runs over time). fn wf() -> std.materialization_ladder.Frame { std.materialization_ladder.Frame { name: "workflow", kind: IsolatedChildrenFrame } } fn job(name: String) -> std.materialization_ladder.Frame { std.materialization_ladder.Frame { name: name, kind: SharedStateFrame } } @@ -266,7 +270,12 @@ test fn zero_demand_effect_is_the_use_not_dead() -> Bool { deploy_ok && measure_ok } -data value_tier_witness_note: String = "Value-tier mirror witnesses: each asserts the refactored ladder verdict agrees cell-by-cell with v1.compiler.ownership semantics — make_decision (take_count = semantic_consumer_count: Consumed only), build_read_only_params (plurality = binding_fan_out: CarryAccess excluded; all access readonly), build_movable_set (borrows = whole_value_borrow_count: Read + Carry, NOT Project). The fold-accumulator case (carries + one take → demoted, v1 re-earns the move via FoldAccUnwrapProof) is asserted at the conservative pre-unwrap semantics." +// Value-tier mirror witnesses: each asserts the refactored ladder verdict agrees cell-by-cell with +// v1.compiler.ownership semantics — make_decision (take_count = semantic_consumer_count: Consumed +// only), build_read_only_params (plurality = binding_fan_out: CarryAccess excluded; all access +// readonly), build_movable_set (borrows = whole_value_borrow_count: Read + Carry, NOT Project). The +// fold-accumulator case (carries + one take → demoted, v1 re-earns the move via FoldAccUnwrapProof) +// is asserted at the conservative pre-unwrap semantics. fn rust_value_providers() -> List { [rust_reference_provider(), rust_clone_provider()] diff --git a/dag/test/claim/materialization_provider_witness_test.dag b/dag/test/claim/materialization_provider_witness_test.dag index 97d0fe672a4..21c20a7d2f5 100644 --- a/dag/test/claim/materialization_provider_witness_test.dag +++ b/dag/test/claim/materialization_provider_witness_test.dag @@ -56,7 +56,24 @@ import v2.std.live_tree { LiveTreeDisposition, SubstrateInputsOnly } data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data materialization_provider_witness_note: String = "Model-scoped witnesses for the std.materialization_provider contract (parent mandate 6B + rework blockers, PR 7385): every outcome arm exercised by execution on BOTH doors. RED directions covered: wrong-content refusal (poisoned payload must refuse, never hit/admit), declared-input miss (a changed declared input keys apart, and a stale artifact a sloppy backend returns anyway refuses as wrong-artifact — on serve AND on admit), kind-mismatch refusal on both doors (blocker 2 — a matching key with a mismatched kind is a malformed pre-contract artifact), identity DERIVED not asserted (blocker 3 plus review 44265 — the doors take no ComputationIdentity parameter at all, so a caller cannot assert a grade; the served grade comes from the binding, and every non-Ok binding derives IdentityUnknown with a located cause), and admission-weakening (blocker 1 — provider_admit derives required outputs from the request; the v1-shape incomplete artifact cannot be admitted against ResolveClosureRequest). Post-44175 the request is a coproduct, so the witnesses construct request VARIANTS and read kind/outputs through the derivations — an under-specified obligation roster is unrepresentable, which is why no witness can even express the weakened-roster attack any more; the chained-eviction witness folds the first admission instead of projecting a store from its refusal arms (the deleted admission_store). The v1-shape incomplete artifact (graph+source_indices, no compile-clean diagnostic union) is the modeled form of extdeps.realization.resolved_graph's live disk-hit refuse arm — the contract's first named consumer target." +// Model-scoped witnesses for the std.materialization_provider contract (parent mandate 6B + rework +// blockers, PR 7385): every outcome arm exercised by execution on BOTH doors. RED directions +// covered: wrong-content refusal (poisoned payload must refuse, never hit/admit), declared-input +// miss (a changed declared input keys apart, and a stale artifact a sloppy backend returns anyway +// refuses as wrong-artifact — on serve AND on admit), kind-mismatch refusal on both doors (blocker +// 2 — a matching key with a mismatched kind is a malformed pre-contract artifact), identity DERIVED +// not asserted (blocker 3 plus review 44265 — the doors take no ComputationIdentity parameter at +// all, so a caller cannot assert a grade; the served grade comes from the binding, and every non-Ok +// binding derives IdentityUnknown with a located cause), and admission-weakening (blocker 1 — +// provider_admit derives required outputs from the request; the v1-shape incomplete artifact cannot +// be admitted against ResolveClosureRequest). Post-44175 the request is a coproduct, so the +// witnesses construct request VARIANTS and read kind/outputs through the derivations — an +// under-specified obligation roster is unrepresentable, which is why no witness can even express +// the weakened-roster attack any more; the chained-eviction witness folds the first admission +// instead of projecting a store from its refusal arms (the deleted admission_store). The v1-shape +// incomplete artifact (graph+source_indices, no compile-clean diagnostic union) is the modeled form +// of extdeps.realization.resolved_graph's live disk-hit refuse arm — the contract's first named +// consumer target. fn witness_compiler() -> DeclaredInput { compiler_identity_input(digest: content_hash_atom(value: "compiler-identity-1")) @@ -308,9 +325,6 @@ test fn incomplete_v1_shape_artifact_refuses_naming_the_diagnostic_union() -> Bo && (lookup_is_hit(l: refused) == false) } - - - test fn admission_within_budget_is_admitted_without_eviction() -> Bool { let a = provider_admit( store: witness_empty_store(budget_count: 1000), @@ -418,9 +432,16 @@ test fn red_admission_wrong_content_is_refused() -> Bool { admission_is_refused_wrong_content_write(a: a) && (admission_is_admitted(a: a) == false) } - - -data forged_roster_witness_note: String = "The attack codex review 44278 named, now closed by construction and exercised on BOTH doors: the bytes at the key are the v1 shape (graph + source_indices, NO compile-clean diagnostic union), so the realization's read-back is witness_v1_shape_digest. The caller submits an artifact whose carried roster claims all three outputs — under the old label-beside-digest shape that roster satisfied artifact_completeness and the door answered BindingOk, admitting bytes that could green a red. Because the content digest is now DERIVED from the carried parts, claiming a part the bytes do not hold changes the derivation, so the forgery is no longer self-consistent and lands on the wrong-content refusal instead. The paired positive control below (same artifact, its OWN derived digest) shows the refusal is discriminating rather than a blanket red: the honest complete artifact still serves and still admits." +// The attack codex review 44278 named, now closed by construction and exercised on BOTH doors: the +// bytes at the key are the v1 shape (graph + source_indices, NO compile-clean diagnostic union), so +// the realization's read-back is witness_v1_shape_digest. The caller submits an artifact whose +// carried roster claims all three outputs — under the old label-beside-digest shape that roster +// satisfied artifact_completeness and the door answered BindingOk, admitting bytes that could green +// a red. Because the content digest is now DERIVED from the carried parts, claiming a part the +// bytes do not hold changes the derivation, so the forgery is no longer self-consistent and lands +// on the wrong-content refusal instead. The paired positive control below (same artifact, its OWN +// derived digest) shows the refusal is discriminating rather than a blanket red: the honest +// complete artifact still serves and still admits. test fn red_forged_output_roster_refuses_as_wrong_content_on_serve() -> Bool { let forged = provider_serve( @@ -448,7 +469,15 @@ test fn carried_roster_is_the_content_digest_preimage() -> Bool { && (witness_closure_digest() == artifact_content_digest(artifact: witness_complete_closure_artifact())) } -data size_authentication_witness_note: String = "codex review 44300, and it is a distinct attack from the one below: keep every part DIGEST identical and understate only the BYTE COUNTS. Under the earlier preimage — (id, digest) per part — the derived content digest was unchanged, so the read-back still matched, BindingOk was returned, and the understated size was trusted by the budget check and handed to store_put. The earlier witness did not reach this: it varied the parts themselves, so it exercised a different path. These vary bytes ALONE, holding every digest fixed, which is the discriminating input the previous test set lacked. With bytes inside the preimage the understated artifact is refused wrong-content; the honest one at the same budget is admitted, so the pair discriminates rather than going blanket red." +// codex review 44300, and it is a distinct attack from the one below: keep every part DIGEST +// identical and understate only the BYTE COUNTS. Under the earlier preimage — (id, digest) per part +// — the derived content digest was unchanged, so the read-back still matched, BindingOk was +// returned, and the understated size was trusted by the budget check and handed to store_put. The +// earlier witness did not reach this: it varied the parts themselves, so it exercised a different +// path. These vary bytes ALONE, holding every digest fixed, which is the discriminating input the +// previous test set lacked. With bytes inside the preimage the understated artifact is refused +// wrong-content; the honest one at the same budget is admitted, so the pair discriminates rather +// than going blanket red. fn witness_size_understated_closure_artifact() -> MaterializedArtifact { ResolvedGraphArtifact { @@ -550,7 +579,14 @@ test fn red_typecheck_key_tracks_the_authority_when_an_import_changes() -> Bool && ((request_key(req: witness_typecheck_request()) == independently_changed) == false) } -data artifact_construction_witness_note: String = "Blocker 2 (operator review): omission, not forgery. The digest-preimage work made lying impossible; these show omitting is now impossible too. A complete resolved-graph artifact reaches its union through a REQUIRED field, so the v1 shape can no longer be spelled as a ResolvedGraphArtifact at all — it is only expressible as the named LegacyIncompleteArtifact variant, which is exactly the extdeps.realization.resolved_graph disk-hit refuse arm this contract's first consumer target retires. The completeness check is therefore still LIVE rather than inert: it is what measures that legacy variant, and the refusal below is reached by execution." +// Blocker 2 (operator review): omission, not forgery. The digest-preimage work made lying +// impossible; these show omitting is now impossible too. A complete resolved-graph artifact reaches +// its union through a REQUIRED field, so the v1 shape can no longer be spelled as a +// ResolvedGraphArtifact at all — it is only expressible as the named LegacyIncompleteArtifact +// variant, which is exactly the extdeps.realization.resolved_graph disk-hit refuse arm this +// contract's first consumer target retires. The completeness check is therefore still LIVE rather +// than inert: it is what measures that legacy variant, and the refusal below is reached by +// execution. test fn complete_artifact_reaches_its_union_through_a_required_field() -> Bool { let ids = artifact_carried_outputs(artifact: witness_complete_closure_artifact()) |> map(o => o.id) @@ -580,7 +616,6 @@ test fn consumer_target_frontier_names_seven_caches_with_typed_binds() -> Bool { && materialization_provider_targets_all_bound() } - test fn served_hit_carries_a_derived_structural_grade() -> Bool { let served = provider_serve(req: witness_closure_request(), probe: witness_good_probe()) lookup_is_hit(l: served) && identity_grade_is_known(ci: lookup_served_identity(l: served)) diff --git a/dag/test/claim/materialized_secret_witness_test.dag b/dag/test/claim/materialized_secret_witness_test.dag index 3ba2d226cd9..4f4d602a3ce 100644 --- a/dag/test/claim/materialized_secret_witness_test.dag +++ b/dag/test/claim/materialized_secret_witness_test.dag @@ -4,7 +4,9 @@ import gunbc.runner_host_deploy { gunbc_ci_github_app } data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data incident_secret_note: String = "The witness uses the ACTUAL credential from the A3 incident — gunbc_ci_github_app.app_pem_secret, ci-github-app-private-key — rather than a synthetic fixture, so the conjuncts below are statements about the thing that 401'd srv4 and not about a stand-in that resembles it." +// The witness uses the ACTUAL credential from the A3 incident — gunbc_ci_github_app.app_pem_secret, +// ci-github-app-private-key — rather than a synthetic fixture, so the conjuncts below are +// statements about the thing that 401'd srv4 and not about a stand-in that resembles it. fn incident_secret_ref() -> SecretRef { gunbc_ci_github_app.app_pem_secret @@ -14,7 +16,11 @@ fn use_marker(m: MaterializedSecret) -> Int { 1 } -data witness_a3_hinge_note: String = "THE conjunct A3 exists for, and it is the srv4 incident replayed. Secret Manager says SmEnabled — every existence check the model can perform is green, and it stayed green through the entire incident — while NO liveness observation exists. The materialization must REFUSE. If it completes, the model has certified a credential on the strength of the store's opinion about its own contents, which is exactly the state that produced the 401, and it would do so on the same inputs that produced it." +// THE conjunct A3 exists for: the srv4 incident replayed. Secret Manager says SmEnabled — every +// existence check the model can perform is green, and stayed green through the entire incident — +// while NO liveness observation exists. The materialization must REFUSE. If it completes, the +// model has certified a credential on the strength of the store's opinion about its own contents, +// exactly the state that produced the 401, on the same inputs that produced it. test fn witness_enabled_but_unprobed_refuses() -> Bool { let outcome = with_materialized_secret( @@ -38,7 +44,10 @@ test fn witness_enabled_but_unprobed_refuses() -> Bool { } } -data witness_revoked_note: String = "The incident's other half: the store is enabled AND a probe ran AND the upstream rejected the key. The refusal must carry the probe's own verdict rather than collapsing to a generic failure, because 'GitHub does not accept this key' and 'nobody asked GitHub' are different pieces of work — reconcile the credential versus build the probe — and this lane already paid for conflating them once." +// The incident's other half: the store is enabled AND a probe ran AND the upstream rejected the +// key. The refusal must carry the probe's own verdict rather than collapse to a generic failure: +// 'GitHub does not accept this key' and 'nobody asked GitHub' are different work — reconcile the +// credential versus build the probe — and this lane already paid for conflating them once. test fn witness_enabled_but_revoked_refuses() -> Bool { let outcome = with_materialized_secret( @@ -79,7 +88,16 @@ test fn witness_live_secret_materializes_and_runs_the_use() -> Bool { } } -data witness_store_state_note: String = "Store state refuses on its OWN axis and must name its OWN cause, and this conjunct was strengthened in review (review 42890) because its earlier form asserted only that materialization refused. That was too weak to see the defect it was supposed to guard: the authority folded both axes into one verdict and refused everything as SecretNotLive, so SecretVersionUnusable was declared and unreachable, and a destroyed store version was indistinguishable from an upstream-revoked key — same shape, different remedy, which is the state-space conflation this whole lane exists to refuse. The conjunct now pins the CAUSE variant on both axes and asserts they DIFFER on the same secret, so the two can never collapse again without reddening. Note the store axis is checked first on purpose: a destroyed version is unusable whatever a probe says about the key it used to hold, so a live probe result must not rescue it." +// Store state refuses on its OWN axis and must name its OWN cause; this conjunct was strengthened +// in review (review 42890) because its earlier form asserted only that materialization refused -- +// too weak to see the defect it guards: the authority folded both axes into one verdict and refused +// everything as SecretNotLive, so SecretVersionUnusable was declared and unreachable, and a +// destroyed store version was indistinguishable from an upstream-revoked key — same shape, +// different remedy, the state-space conflation this lane exists to refuse. The conjunct now pins +// the CAUSE variant on both axes and asserts they DIFFER on the same secret, so the two cannot +// collapse again without reddening. The store axis is checked first on purpose: a destroyed +// version is unusable whatever a probe says about the key it used to hold, so a live probe result +// must not rescue it. fn refusal_cause_is_store_axis(outcome: MaterializationOutcome) -> Bool { match outcome { @@ -136,7 +154,11 @@ test fn witness_destroyed_version_refuses_even_when_probe_says_live() -> Bool { && !refusal_cause_is_store_axis(outcome: revoked) } -// A probe that repairs what it tests cannot certify it. The self-repairing sketch is the automation of the exact hand reconciliation the A3 gap row describes — mint, and on failure add a fresh key version — so its Converged may be reporting the version the probe itself just wrote. The bracket refuses on the probe's CLASSIFICATION before it ever looks at the verdict, and the refusal names the probe so the remedy is 'replace this probe' rather than 'the credential is bad'. +// A probe that repairs what it tests cannot certify it. The self-repairing sketch automates the +// exact hand reconciliation the A3 gap row describes — mint, and on failure add a fresh key version +// — so its Converged may be reporting the version the probe itself just wrote. The bracket refuses +// on the probe's CLASSIFICATION before it looks at the verdict, and the refusal names the probe so +// the remedy is 'replace this probe' rather than 'the credential is bad'. test fn witness_self_repairing_probe_is_refused_by_classification() -> Bool { let outcome = with_materialized_secret( ref: incident_secret_ref(), @@ -191,7 +213,10 @@ test fn witness_red_control_existence_only_rejected_by_gate() -> Bool { ) } -// Liveness qualification is a presupposition check and not a meet, pinned the same way the swap axis pins its own. A DISABLED store version under a live probe stays Drifted — the probe does not repair the store — while an ENABLED version under an absent probe becomes UnknownRefused. Under a symmetric meet those two would be indistinguishable and the direction of the check would be lost. +// Liveness qualification is a presupposition check, not a meet, pinned the same way the swap axis +// pins its own. A DISABLED store version under a live probe stays Drifted — the probe does not +// repair the store — while an ENABLED version under an absent probe becomes UnknownRefused. Under a +// symmetric meet those two would be indistinguishable and the direction of the check lost. test fn witness_liveness_qualification_is_asymmetric() -> Bool { let store_drifted = secret_liveness_qualified_verdict( existence: secret_existence_verdict(state: SmDisabled), diff --git a/dag/test/claim/measurement_provenance_witness_test.dag b/dag/test/claim/measurement_provenance_witness_test.dag index d2ac62dc48a..56e9cb70761 100644 --- a/dag/test/claim/measurement_provenance_witness_test.dag +++ b/dag/test/claim/measurement_provenance_witness_test.dag @@ -63,7 +63,13 @@ import gunbc.measurement_provenance { // observation. That second claim is why the rows below carry BuildSubjects at all; before this // revision the bound arm had no subject to compare and the discriminating row was unwritable. -data tree_hex_provenance_doc: String = "The two tree object ids below are REAL git tree oids, taken from the measured set in test.claim.devboot_subject_identity_witness rather than invented here — that witness read them out of this repository and records how. What these rows need of them is weaker than what that witness needs: only that they are two DISTINCT admissible tree oids, standing for an instrument built from one tree and an instrument built from another. Reusing measured values rather than minting plausible hex keeps the fixture falsifiable — an invented pair could not have failed to differ." +// The two tree object ids below are REAL git tree oids, taken from the measured set in +// test.claim.devboot_subject_identity_witness rather than invented here — that witness read them +// out of this repository and records how. What these rows need of them is weaker than what that +// witness needs: only that they are two DISTINCT admissible tree oids, standing for an instrument +// built from one tree and an instrument built from another. Reusing measured values rather than +// minting plausible hex keeps the fixture falsifiable — an invented pair could not have failed to +// differ. data current_tree_hex: String = "4a712980497e1d0a45374185b2184a094cca4c8f" diff --git a/dag/test/claim/membership_reconcile_witness_test.dag b/dag/test/claim/membership_reconcile_witness_test.dag index c4730293306..0bea94b8f19 100644 --- a/dag/test/claim/membership_reconcile_witness_test.dag +++ b/dag/test/claim/membership_reconcile_witness_test.dag @@ -130,7 +130,11 @@ test fn w_unchanged_noop() -> Bool { && membership_refusal_count(plan: plan) == 0 } -data w_modified_changes_note: String = "A Modified hunk is a MemberChanged carrying BOTH sides, NOT an add of the `to` side. The from-side assertion is the discriminating half: it reds if anyone reintroduces the collapse that discarded `from`, which is the fact every safe realization of a change needs (an SCM compare-and-swap names the expected prior; a moved host address needs the prior endpoint to retire). Asserted at the ACTION grain — a tally alone cannot tell a change from an add." +// A Modified hunk is a MemberChanged carrying BOTH sides, NOT an add of the `to` side. The +// from-side assertion is the discriminating half: it reds if anyone reintroduces the collapse that +// discarded `from`, which is the fact every safe realization of a change needs (an SCM +// compare-and-swap names the expected prior; a moved host address needs the prior endpoint to +// retire). Asserted at the ACTION grain — a tally alone cannot tell a change from an add. test fn w_modified_is_change_carrying_both_sides() -> Bool { let plan = t_reconcile( @@ -146,7 +150,17 @@ test fn w_modified_is_change_carrying_both_sides() -> Bool { && membership_refusal_count(plan: plan) == 0 } -data w_ensured_converges_note: String = "REGRESSION CONTROL for a wall that was BUILT AND WITHDRAWN during this change (DESIGN §4b(4): the evidence stays enrolled after the reasoning settles; §4c: prose is never evidence a machine claim holds). An earlier draft refused a Modified hunk whose `from` was not Owned, reading replacement as destruction. That is wrong, and this row is what makes it stay wrong out loud. WHAT IT PROVES, precisely: gunbc.ownership defines Ensured as 'requires present but does NOT own (never torn down)' — a constraint on REMOVAL. Ensured says NOTHING about update, and treating it as if it did breaks the module whose entire job is re-installing drifted pins (tool_readiness classifies every pin Ensured; repo_local_git_config every binding). So the SAME Ensured member must CONVERGE when its value drifts and REFUSE when it is removed — one member, both arms, in one plan, so the asymmetry is asserted rather than assumed. Reintroducing the change-refusal arm turns the first conjunct red." +// REGRESSION CONTROL for a wall that was BUILT AND WITHDRAWN during this change (DESIGN §4b(4): the +// evidence stays enrolled after the reasoning settles; §4c: prose is never evidence a machine claim +// holds). An earlier draft refused a Modified hunk whose `from` was not Owned, reading replacement +// as destruction. That is wrong, and this row is what makes it stay wrong out loud. WHAT IT PROVES, +// precisely: gunbc.ownership defines Ensured as 'requires present but does NOT own (never torn +// down)' — a constraint on REMOVAL. Ensured says NOTHING about update, and treating it as if it did +// breaks the module whose entire job is re-installing drifted pins (tool_readiness classifies every +// pin Ensured; repo_local_git_config every binding). So the SAME Ensured member must CONVERGE when +// its value drifts and REFUSE when it is removed — one member, both arms, in one plan, so the +// asymmetry is asserted rather than assumed. Reintroducing the change-refusal arm turns the first +// conjunct red. test fn w_ensured_member_converges_but_refuses_removal() -> Bool { let plan = t_reconcile( @@ -188,7 +202,9 @@ fn effects_has_teardown(es: List>, mid: String) -> Bool { ) } -data w_effect_replace_note: String = "EffectReplace carries BOTH sides into apply, which is the point of the split: a handler that replaces a member must be able to retire the prior realization, and `from` is the only place the prior endpoint survives. An EffectAdd carries one side because there is nothing there to retire." +// EffectReplace carries BOTH sides into apply, which is the point of the split: a handler that +// replaces a member must be able to retire the prior realization, and `from` is the only place the +// prior endpoint survives. An EffectAdd carries one side because there is nothing there to retire. test fn w_change_projects_to_effect_replace_with_both_sides() -> Bool { let plan = t_reconcile( @@ -208,7 +224,12 @@ test fn w_change_projects_to_effect_replace_with_both_sides() -> Bool { } } -data w_effects_wholesale_refuse_note: String = "DISCRIMINATING (§5): a plan carrying any Refused MUST refuse WHOLESALE — membership_effects returns ApplyRefused (o's owned teardown NOT surfaced as an effect), never EffectsReady with the refused sibling silently filtered out. If membership_effects is ever broken to drop-the-refused and return the effects, this hits the EffectsReady arm and returns false = RED. The degenerate apply/retract poles never produce a Refused, so only this synthetic mixed observed set exercises the wall." +// DISCRIMINATING (§5): a plan carrying any Refused MUST refuse WHOLESALE — membership_effects +// returns ApplyRefused (o's owned teardown NOT surfaced as an effect), never EffectsReady with the +// refused sibling silently filtered out. If membership_effects is ever broken to drop-the-refused +// and return the effects, this hits the EffectsReady arm and returns false = RED. The degenerate +// apply/retract poles never produce a Refused, so only this synthetic mixed observed set exercises +// the wall. test fn w_effects_refuses_wholesale_on_any_refusal() -> Bool { let plan = t_reconcile( @@ -296,7 +317,9 @@ data scoped_witness_resource: KeyedResourceRelation Bool { let a = ScopedWitnessMember { node: "host-a", mid: "route", ver: "1" } @@ -347,7 +370,8 @@ test fn w_duplicate_plain_key_refuses_with_roster_cause() -> Bool { } } -data w_duplicate_scoped_key_refuses_note: String = "DISCRIMINATING: two desired members sharing one scoped key must refuse at roster build — MembershipReconcileDuplicateScopedKey on the desired roster, never a 1:1 diff." +// DISCRIMINATING: two desired members sharing one scoped key must refuse at roster build — +// MembershipReconcileDuplicateScopedKey on the desired roster, never a 1:1 diff. test fn w_duplicate_scoped_key_refuses() -> Bool { let a = ScopedWitnessMember { node: "host-a", mid: "route", ver: "1" } diff --git a/dag/test/claim/merge_admission_attempt_witness_test.dag b/dag/test/claim/merge_admission_attempt_witness_test.dag index be86b642324..7d3c1a79953 100644 --- a/dag/test/claim/merge_admission_attempt_witness_test.dag +++ b/dag/test/claim/merge_admission_attempt_witness_test.dag @@ -123,7 +123,21 @@ fn synthetic_changed_roster_hash() -> ContentHash { gate_roster_content_hash(roster: reverse(commit_gate_roster)) } -data roster_staleness_control_recut_note: String = "RECUT AFTER #7591 INVALIDATED #7583. The 2026-08-01 incident motivates the roster-identity law, but this control does not reconstruct that incident by execution. Its alternative revision reverses the exact live enrollments: identical members and surfaces, still unique and otherwise valid, but with a different order-sensitive roster hash. Order participates in roster identity even though it does not affect roster validity, so a source-only reordering is a real roster revision that refuses every in-flight admission minted under the prior order. It names no particular production gate and asserts no historical roster content. The prior control named PublicationPlacementGate; that coupled the regression control to one volatile roster member's continued existence, and the member's operator-ordered deletion invalidated the entire PR from a direction its original evidence did not watch. A control for a roster-identity law must exercise the SHAPE of a roster change, never a particular member, or its lifetime is bounded by the least stable thing it mentions. A description of a control's shape must live with that control or derive from it, so an implementation change cannot leave a remote carrier describing evidence that no longer executes. The discriminator proves staleness rather than malformedness: the alternative-revision receipt refuses against the live revision and the identical receipt admits when that alternative revision is supplied as current. The live-revision receipt also admits, so an always-admit or always-refuse implementation fails a control." +// RECUT AFTER #7591 INVALIDATED #7583. The 2026-08-01 incident motivates the roster-identity law +// but is not reconstructed here. The alternative revision reverses the exact live enrollments: +// same members and surfaces, still unique and valid, but a different order-sensitive roster hash. +// Order participates in roster identity though not validity, so a source-only reordering is a +// real revision refusing every in-flight admission minted under the prior order. No production +// gate is named and no historical roster content asserted: the prior control named +// PublicationPlacementGate, coupling itself to one volatile member's existence, and that member's +// operator-ordered deletion invalidated the whole PR from a direction its evidence did not watch. +// A control for a roster-identity law must exercise the SHAPE of a roster change, never a member, +// or its lifetime is bounded by the least stable thing it mentions; and a control's shape +// description must live with or derive from the control, so an implementation change cannot +// leave a remote carrier describing evidence that no longer executes. The discriminator proves +// staleness, not malformedness: the alternative-revision receipt refuses against the live +// revision and admits when that revision is supplied as current. The live-revision receipt also +// admits, so always-admit and always-refuse implementations each fail a control. fn synthetic_changed_roster_receipt() -> MergeAdmissionReceiptV2 { MergeAdmissionReceiptV2 { @@ -208,13 +222,12 @@ test fn foreign_attempt_refuses_as_wrong_attempt() -> Bool { } // EVERY OTHER REFUSAL IS STACKED HERE ON PURPOSE, so "precedes" is measured against a receipt that -// would trip all of them: foreign attempt, a head and base commit that disagree with the captured -// subject, a base that has moved under the target, a stale roster, and a failing conclusion. -// tested_base_commit_sha is other_base_commit_fx, NOT base_commit_fx: a receipt carrying the -// CURRENT base would be fresh, and the stale-base half of the precedence claim would silently -// vanish while the row stayed green -- which is what a blanket fixture rewrite did to this row -// before review caught it. Precedence ordering is exactly the property that rots invisibly, since -// a reordering regression leaves a row like this green unless every dominated arm is really armed. +// would trip all of them: foreign attempt, head and base disagreeing with the captured subject, a +// base moved under the target, a stale roster, a failing conclusion. tested_base_commit_sha is +// other_base_commit_fx, NOT base_commit_fx: with the CURRENT base the receipt would be fresh and +// the stale-base half of the claim would vanish while the row stayed green -- which a blanket +// fixture rewrite did to this row before review caught it. Precedence ordering rots invisibly: a +// reordering regression leaves this row green unless every dominated arm is really armed. test fn wrong_attempt_precedes_every_other_refusal() -> Bool { let r = MergeAdmissionReceiptV2 { attempt_id: attempt_b(), @@ -233,18 +246,17 @@ test fn wrong_attempt_precedes_every_other_refusal() -> Bool { ) { MergeDeniedWrongAttempt => true _ => false } } -// THE ANCESTRY OPERAND'S OWN DISCRIMINATING PAIR, and the second row is the false ADMIT that -// existed before it. A three-way merge reads the MERGE BASE, which ancestry fixes and a tree does -// not, so a base that cherry-picks the PR and reverts it returns to the SAME TREE at a DIFFERENT -// COMMIT, moves the merge base, and changes what the merge produces. Demonstrated in real git: -// merging the same head into two same-tree base commits yielded trees e5c2c751 and 4b6c9a11, the -// PR's own file present in one and absent in the other. +// THE ANCESTRY OPERAND'S OWN DISCRIMINATING PAIR; the second row is the false ADMIT that preceded +// it. A three-way merge reads the MERGE BASE, which ancestry fixes and a tree does not, so a base +// that cherry-picks the PR and reverts it returns to the SAME TREE at a DIFFERENT COMMIT, moves +// the merge base, and changes the merge result. Demonstrated in real git: merging one head into +// two same-tree base commits yielded trees e5c2c751 and 4b6c9a11, the PR's file present in one +// and absent in the other. // -// Each row varies exactly ONE field from the admitting case, and both rows classified MergeAdmitted -// before the operand existed. A regression dropping either comparison turns that row green while -// the other stays red, so they cannot both be satisfied by an always-refuse implementation either -- -// matching_attempt_and_subject_with_fresh_base_admits is the positive control they are measured -// against. +// Each row varies exactly ONE field from the admitting case, and both classified MergeAdmitted +// before the operand existed. Dropping either comparison turns that row green while the other +// stays red; matching_attempt_and_subject_with_fresh_base_admits is the positive control, so an +// always-refuse implementation cannot satisfy them either. test fn receipt_base_commit_that_differs_from_the_captured_subject_refuses() -> Bool { let v = classify_merge_admission_verdict_v2( current_attempt_id: attempt_a(), @@ -256,19 +268,22 @@ test fn receipt_base_commit_that_differs_from_the_captured_subject_refuses() -> match v { MergeDeniedSubjectMismatch => merge_admission_verdict_would_block(v: v) _ => false } } -// a_base_that_moved_to_a_same_tree_commit_refuses_as_stale WAS DRAFTED HERE and is NOT KEPT, because -// once the tree operand is gone "same tree, different commit" is not a state this model can express -// -- there is no tree to hold equal. What it asserted reduces exactly to "the base moved, so the -// receipt is stale", which subject_bound_receipt_on_an_advanced_target_is_stale_not_mismatched below -// already asserts on the surviving operand. Two rows for one property would be the duplication this -// change removed from the carrier, re-introduced in the tests. +// a_base_that_moved_to_a_same_tree_commit_refuses_as_stale WAS DRAFTED HERE and is NOT KEPT: with +// the tree operand gone, "same tree, different commit" is inexpressible -- there is no tree to +// hold equal. It reduces to "the base moved, so the receipt is stale", which +// subject_bound_receipt_on_an_advanced_target_is_stale_not_mismatched below already asserts on the +// surviving operand; two rows for one property would re-introduce in the tests the duplication +// this change removed from the carrier. // -// The false admit it was written for is now STRUCTURALLY unreachable rather than merely detected: -// with no tree comparison, there is no comparison left that a same-tree-different-commit base could -// pass. The demonstration that motivated it is recorded on TestedSubject in -// gunbc.merge_admission_subject, where the operand it justifies lives. +// The false admit it targeted is now STRUCTURALLY unreachable, not merely detected: with no tree +// comparison, nothing remains for a same-tree-different-commit base to pass. The motivating +// demonstration is recorded on TestedSubject in gunbc.merge_admission_subject, with the operand. -data subject_binding_discriminating_note: String = "The two rows below are the ones the receipt could previously LIE past. Before the gate consumed the captured subject, a receipt in the right attempt could restate any head SHA or any base tree and be classified purely on its own say-so; both cases here classified MergeAdmitted under the old signature and are refusals now. They are the discriminating pair for the binding, not decoration: each varies exactly ONE field away from the admitting case above, so a regression that drops either comparison turns that row green while the other stays red." +// The two rows below are the ones the receipt could previously LIE past: before the gate consumed +// the captured subject, a receipt in the right attempt could restate any head SHA or base tree and +// be classified on its own say-so; both classified MergeAdmitted under the old signature and refuse +// now. They are the binding's discriminating pair: each varies exactly ONE field from the admitting +// case above, so dropping either comparison turns that row green while the other stays red. test fn receipt_head_that_differs_from_the_captured_subject_refuses() -> Bool { let v = classify_merge_admission_verdict_v2( @@ -282,12 +297,11 @@ test fn receipt_head_that_differs_from_the_captured_subject_refuses() -> Bool { } // receipt_base_tree_that_differs_from_the_captured_subject_refuses WAS HERE and is DELETED, not -// repointed. Its subject was the receipt's base TREE disagreeing with the captured subject's, and -// the tree operand no longer exists -- a claim whose subject is gone cannot be kept alive by -// aiming it at a different field, which would be a witness named for one fact asserting another. -// The property it guarded is subsumed with room to spare by +// repointed: its subject was the receipt's base TREE disagreeing with the captured subject's, and +// the tree operand no longer exists -- aiming a claim whose subject is gone at another field makes +// a witness named for one fact assert another. Its property is subsumed by // receipt_base_commit_that_differs_from_the_captured_subject_refuses above: a differing commit -// implies a differing tree, so the commit comparison refuses strictly more than the tree one did. +// implies a differing tree, so the commit comparison refuses strictly more. test fn subject_from_another_attempt_refuses_even_with_a_matching_receipt() -> Bool { match classify_merge_admission_verdict_v2( @@ -301,10 +315,10 @@ test fn subject_from_another_attempt_refuses_even_with_a_matching_receipt() -> B // THE FALSE-ADMIT ARM'S SURVIVING CONTROL. The receipt is correctly bound to its captured subject // and the BASE HAS MOVED, so the answer must be StaleBase (the world moved after a correct -// measurement) and not SubjectMismatch (the receipt describes something else). Its operand used to -// be an advanced base TREE; it is now an advanced base COMMIT, which is a strictly stronger subject -// -- a base that moves to a commit with an identical tree is now caught here, and that is exactly -// the cherry-pick-then-revert case that classified MergeAdmitted before this change. +// measurement), not SubjectMismatch (the receipt describes something else). The operand was an +// advanced base TREE and is now an advanced base COMMIT, strictly stronger: a base moving to a +// commit with an identical tree is caught here -- the cherry-pick-then-revert case that classified +// MergeAdmitted before this change. test fn subject_bound_receipt_on_an_advanced_target_is_stale_not_mismatched() -> Bool { match classify_merge_admission_verdict_v2( current_attempt_id: attempt_a(), @@ -358,7 +372,10 @@ test fn v1_wire_refused_by_v2_parser() -> Bool { } } -data wire_arity_red_note: String = "Every row below was ACCEPTED by the first cut of these parsers. A trailing line rode along unread (the `>= n` superset), and a malformed seventh line silently became pr_number: none — supplied-but-unreadable collapsing into not-supplied. Each row varies one thing from a wire that parses, so a regression that relaxes arity back to a superset turns exactly that row green." +// Every row below was ACCEPTED by the first cut of these parsers. A trailing line rode along unread +// (the `>= n` superset), and a malformed seventh line silently became pr_number: none — +// supplied-but-unreadable collapsing into not-supplied. Each row varies one thing from a wire that +// parses, so a regression that relaxes arity back to a superset turns exactly that row green. test fn receipt_wire_with_a_trailing_line_refuses() -> Bool { let good = render_receipt_wire_v2(receipt: receipt_fx(attempt: attempt_a(), head: head_sha_fx)) @@ -403,9 +420,18 @@ test fn tested_subject_wire_roundtrips() -> Bool { } } -data tested_subject_wire_move_byte_lock_note: String = "MOVE-not-fork control for the gunbc.merge_admission_subject de-fusion: this is the exact five-line byte sequence the subject wire emits. It was five lines before the tested-ancestry change and is five lines after, but NOT the same five: the base-tree line was replaced by a base-commit line and the schema tag moved v1 -> v2 in the same step, so an unchanged arity is not evidence of an unchanged format here. A round-trip alone would miss a coordinated writer/reader drift; this literal makes any schema, ordering, object-family prefix, newline, or field-byte change red." +// MOVE-not-fork control for the gunbc.merge_admission_subject de-fusion: the exact five-line byte +// sequence the subject wire emits. Five lines before and after the tested-ancestry change, but NOT +// the same five: the base-tree line became a base-commit line and the schema tag moved v1 -> v2 in +// the same step, so unchanged arity is not evidence of an unchanged format. A round-trip alone +// would miss coordinated writer/reader drift; this literal makes any schema, ordering, +// object-family prefix, newline, or field-byte change red. -data merge_admission_fetch_deadline_evaluation_witness_note: String = "Forces the live stage-2 deadline row to evaluate. A direct Int-to-Seconds cast typechecks but the interpreter cannot evaluate it; that defect reached the first production on-success run and refused refresh_current_target_and_gate before FetchNoTags. Reading the branded scalar here makes the unevaluable authoring shape red in the focused admission witness instead of after the ordinary floor." +// Forces the live stage-2 deadline row to evaluate. A direct Int-to-Seconds cast typechecks but the +// interpreter cannot evaluate it; that defect reached the first production on-success run and +// refused refresh_current_target_and_gate before FetchNoTags. Reading the branded scalar here turns +// the unevaluable authoring shape red in the focused admission witness, not after the ordinary +// floor. test fn merge_admission_fetch_deadline_is_a_usable_duration() -> Bool { merge_admission_fetch_stall_deadline_seconds == 240 @@ -413,10 +439,9 @@ test fn merge_admission_fetch_deadline_is_a_usable_duration() -> Bool { // THE PIN MOVED WITH THE FORMAT, AND THAT IS THE POINT OF PINNING IT. This row asserted the exact // v1 bytes to prove the defusion MOVE changed no bytes; adding tested ancestry is a deliberate -// format change, so the expected bytes change with it and the schema tag goes to v2. Updating a -// golden pin is only legitimate when the change it reports is intended and stated -- here the -// sixth line and the tag are exactly the intended change, and had either moved WITHOUT the other -// this row would still be red. +// format change, so the expected bytes and schema tag (v2) change with it. Updating a golden pin +// is legitimate only when the change is intended and stated -- the sixth line and the tag are +// exactly that change, and had either moved WITHOUT the other this row would still be red. test fn tested_subject_wire_bytes_are_pinned_including_the_base_commit_line() -> Bool { render_tested_subject_wire( subject: subject_fx(attempt: attempt_a(), head: head_sha_fx) @@ -436,7 +461,11 @@ test fn subject_wire_refused_by_receipt_parser_and_vice_versa() -> Bool { && match parse_tested_subject_wire(text: rec) { Present { value: _ } => false Absent => true } } -data object_id_validation_red_note: String = "Every raw value below PARSED before the wire parser consumed a validating constructor: it checked one colon, a recognized family prefix and a nonempty suffix, then cast the suffix straight into the brand. So sha1:x was a Git object id, and so was a 64-digit value labelled sha1 — family without length and syntax is not identification, and a receipt binding such a value would compare equal to nothing real while typechecking perfectly." +// Every raw value below PARSED before the wire parser consumed a validating constructor: one colon, +// a recognized family prefix, a nonempty suffix, then the suffix cast straight into the brand. So +// sha1:x was a Git object id, as was a 64-digit value labelled sha1 -- family without length and +// syntax is not identification, and a receipt binding such a value would compare equal to nothing +// real while typechecking perfectly. test fn object_id_wire_refuses_wrong_length_and_nonhex() -> Bool { let sha256_hex = "3333333333333333333333333333333333333333333333333333333333333333" @@ -462,7 +491,9 @@ test fn object_id_wire_carries_its_format_and_refuses_an_anonymous_hex() -> Bool && match parse_git_object_id_wire(raw: "md5:1111") { Present { value: _ } => false Absent => true } } -data gate_roster_hash_validation_red_note: String = "Before review 45474, parse_gate_roster_hash_wire cast any nonempty string to GateRosterHash. Blank, non-hex, uppercase, and wrong-length fingerprints all bound into receipts that typechecked while comparing equal to nothing real." +// Before review 45474, parse_gate_roster_hash_wire cast any nonempty string to GateRosterHash. +// Blank, non-hex, uppercase, and wrong-length fingerprints all bound into receipts that typechecked +// while comparing equal to nothing real. test fn gate_roster_hash_wire_refuses_blank_malformed_and_wrong_length() -> Bool { match parse_gate_roster_hash_wire(line: "") { Present { value: _ } => false Absent => true } @@ -494,7 +525,12 @@ test fn attempt_id_refuses_any_empty_part() -> Bool { && match compose_explicit_walk_attempt_id(explicit: "") { Present { value: _ } => false Absent => true } } -data attempt_id_path_safety_red_note: String = "Each raw value below was ACCEPTED as an attempt id before walk_attempt_id existed, and each one breaks something specific once concatenated into /.gunbc/merge-admission//: `../other-attempt` reads another attempt's receipt, `a/b` invents a directory level, `.` and `..` alias the parent, and an embedded newline splits the line-oriented receipt written beneath it. They are checked through BOTH constructors because both read operator-controlled environment strings." +// Each raw value below was ACCEPTED as an attempt id before walk_attempt_id existed, and each one +// breaks something specific once concatenated into /.gunbc/merge-admission//: +// `../other-attempt` reads another attempt's receipt, `a/b` invents a directory level, `.` and `..` +// alias the parent, and an embedded newline splits the line-oriented receipt written beneath it. +// They are checked through BOTH constructors because both read operator-controlled environment +// strings. test fn attempt_id_refuses_path_traversal_and_separators() -> Bool { match compose_explicit_walk_attempt_id(explicit: "../other-attempt") { Present { value: _ } => false Absent => true } @@ -523,19 +559,19 @@ test fn attempt_paths_are_attempt_scoped_and_distinct() -> Bool { } // THE TAGS ARE PINNED EXACTLY, NOT MATCHED LOOSELY, AND THE PIN IS THE POINT. This row asserted -// `contains ".v2"`, which made it a test of the CURRENT version rather than of versioning -- so -// bumping the receipt tag to v3 (this change) turned it red for doing exactly what -// gunbc.merge_admission_produce wire_exact_arity_note REQUIRES on a field addition. Relaxing it to -// "contains .v" would have removed the red and the meaning together: any tag would pass, including -// a tag that failed to move when its arity did. +// `contains ".v2"`, a test of the CURRENT version rather than of versioning -- so bumping the +// receipt tag to v3 (this change) turned it red for doing exactly what +// gunbc.merge_admission_produce wire_exact_arity_note REQUIRES on a field addition. Relaxing to +// "contains .v" would remove the red and the meaning together: any tag would pass, including one +// that failed to move when its arity did. // -// Pinning both literals instead makes a bump DELIBERATE and visible: the tags cannot drift silently, -// and a future field addition that forgets to move its tag turns this row red with the arity change -// -- which is the pairing the arity note exists to enforce. The two literals are the authority's own -// declared values, not a measurement copied from the tree. +// Pinning both literals makes a bump DELIBERATE and visible: tags cannot drift silently, and a +// field addition that forgets its tag turns this row red with the arity change -- the pairing the +// arity note enforces. The literals are the authority's own declared values, not a measurement +// copied from the tree. // -// The distinctness conjunct stays and is doing separate work: the subject and receipt wires are -// parsed by different readers, and a shared tag would let each accept the other's bytes. +// The distinctness conjunct does separate work: the subject and receipt wires are parsed by +// different readers, and a shared tag would let each accept the other's bytes. test fn schemas_are_distinct_and_pinned_to_their_declared_versions() -> Bool { !(merge_admission_receipt_schema_v2 == merge_admission_tested_subject_schema) && (merge_admission_receipt_schema_v2 == "gunbc.merge_admission_receipt.v3") diff --git a/dag/test/claim/merge_lifecycle_interleaving_witness_test.dag b/dag/test/claim/merge_lifecycle_interleaving_witness_test.dag index 0bc2f324c64..2d942e0b4f2 100644 --- a/dag/test/claim/merge_lifecycle_interleaving_witness_test.dag +++ b/dag/test/claim/merge_lifecycle_interleaving_witness_test.dag @@ -19,7 +19,11 @@ import v2.std.live_tree { LiveTreeDisposition, SubstrateInputsOnly } data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data incident_fixture_note: String = "The two PRs of the 2026-07-16 main-red, as symbolic identities (real receipts cited in gunbc.merge_lifecycle.merge_lifecycle_incident_note: #6663 green run 29459154549, first union red run 29461044828, root fix #6701). pr_a is #6663 (the P0 field wall), pr_b is #6686 (the std.types import edge). Zero file overlap, both green in isolation, union red — the judge-x-evidence squash race." +// The two PRs of the 2026-07-16 main-red, as symbolic identities (real receipts cited in +// gunbc.merge_lifecycle.merge_lifecycle_incident_note: #6663 green run 29459154549, first union red +// run 29461044828, root fix #6701). pr_a is #6663 (the P0 field wall), pr_b is #6686 (the std.types +// import edge). Zero file overlap, both green in isolation, union red — the judge-x-evidence squash +// race. data pr_a: PrIdentity = PrIdentity { number: 6663, @@ -91,9 +95,16 @@ test fn healed_head_lands_after_exact_head_revalidation() -> Bool { && end_state.main_tip == squash_result_tree(pr: pr_a_healed, base: initial_lifecycle_state().main_tip) } -data heal_exact_head_discrimination_note: String = "The pair above differs only by the revalidation event. A receipt selected by PR number alone makes healed_head_cannot_reuse_old_head_evidence fail: the healed tree lands on the old head's green. Requiring the exact head refuses that trace, while RunPrCi(pr_a_healed) makes the paired trace land — proving the repair does not reject every healed head." +// The pair above differs only by the revalidation event. A receipt selected by PR number alone +// fails healed_head_cannot_reuse_old_head_evidence: the healed tree lands on the old head's green. +// Requiring the exact head refuses that trace, while RunPrCi(pr_a_healed) lands the paired trace — +// the repair does not reject every healed head. -data interleaving_alphabet_note: String = "Alphabet = both incident PRs' RunPrCi and MergePr, a same-number/different-head healed MergePr, plus RosterBump (criteria drift). MergePr(pr_b) is enabled only by pr_b's own receipts, and MergePr(pr_a_healed) only by evidence for that exact head, so the enumeration exercises fresh merges, stale merges, re-runs, double-merges, roster drift, and an auto-heal head transition in every order of length 4 — 6^4 = 1296 sequences, all enumerated, none sampled." +// Alphabet = both incident PRs' RunPrCi and MergePr, a same-number/different-head healed MergePr, +// plus RosterBump (criteria drift). MergePr(pr_b) is enabled only by pr_b's own receipts and +// MergePr(pr_a_healed) only by evidence for that exact head, so the enumeration covers fresh +// merges, stale merges, re-runs, double-merges, roster drift, and an auto-heal head transition in +// every order of length 4 — 6^4 = 1296 sequences, all enumerated, none sampled. fn interleaving_alphabet() -> List { [ @@ -122,8 +133,15 @@ test fn per_pr_gate_only_admits_unverified_tips_in_window_4() -> Bool { count_unverified_admitting_sequences(policy: PerPrGateOnly, seqs: window_4_sequences()) > 0 } +// The three counts quantify gunbc.plans.branch_merge_admission_model section 4 over EVERY length-4 +// lifecycle, not authored scenarios: PerPrGateOnly (the live policy — GitHub strict flag false, no +// queue) admits unverified tips; RequireUpToDateBase (GitHub's strict boolean, tree axis only) +// still admits a tree verified under a superseded gate roster; KeyedReceipt admits zero across the +// window, including the same-PR healed-head transition — green-stays-green as a +// bounded-exhaustive theorem. The positive PerPrGateOnly count proves the enumerator can see +// violations; the paired heal witnesses locate the exact-head discrimination rather than relying +// on the aggregate zero. + test fn require_up_to_date_base_misses_the_roster_axis_in_window_4() -> Bool { count_unverified_admitting_sequences(policy: RequireUpToDateBase, seqs: window_4_sequences()) > 0 } - -data policy_discrimination_note: String = "The three counts quantify gunbc.plans.branch_merge_admission_model section 4 over EVERY length-4 lifecycle instead of authored scenarios: PerPrGateOnly (the live policy — GitHub strict flag false, no queue) admits unverified tips; RequireUpToDateBase (GitHub's strict boolean, tree axis only) still admits landing a tree verified under a superseded gate roster; KeyedReceipt admits zero across the whole window, including the same-PR healed-head transition — green-stays-green as a bounded-exhaustive theorem, not a scenario. The positive PerPrGateOnly count proves the enumerator can see violations, while the paired heal witnesses locate the exact-head discrimination rather than relying only on the aggregate zero." diff --git a/dag/test/claim/method_arg_declared_contract_cross_module_alias_witness_test.dag b/dag/test/claim/method_arg_declared_contract_cross_module_alias_witness_test.dag index 227a1f66482..b9c96e84819 100644 --- a/dag/test/claim/method_arg_declared_contract_cross_module_alias_witness_test.dag +++ b/dag/test/claim/method_arg_declared_contract_cross_module_alias_witness_test.dag @@ -1,6 +1,49 @@ module test.claim.method_arg_declared_contract_cross_module_alias_witness_test -data method_arg_declared_contract_cross_module_alias_note: String = "PERMANENT REGRESSION CONTROL, companion to method_arg_declared_contract_witness_test.dag (#8592). Landed per dashboard node adhoc-28a6f804-3cd, reconciling #8572 and #8579, handoff repair from deep-ant-102.\n\nCORRECTED UNDERSTANDING FROM DIRECT EXECUTION. ContractUnavailable is not a silent-accept path: lookup_structural_method's Absent arm produces a hard, blocking diagnostic (\"no declared argument contract is available for this method call; refusing rather than substituting the receiver element type\") unconditionally, regardless of whether the actual call argument would have type-checked -- confirmed by direct compile of a genuinely-unavailable-contract fixture (a non-callable field called with call syntax), which refuses today with exactly that diagnostic. So the defect this repair closes is an OVER-REFUSAL, not a silent accept: a receiver's method exposed via a field whose declared type is an alias to a fn type, where the alias's declaring module differs from the call site's module, wrongly hit ContractUnavailable and refused a well-typed call outright, because declared_arg_types_for_method had no expand_field_type parameter and so never expanded the still-unexpanded alias-reference node (params.count == 0 on the raw field type) before reading its params. Fixed, expand_field_type resolves the cross-module alias to its real fn(Int) -> Int shape, params.count becomes > 0, and a well-typed call against that real contract compiles clean instead of being wrongly refused.\n\nWHAT IS ASSERTED. test.fixture.cross_module_alias_handler.definer (dag/test/fixture/cross_module_alias_handler/definer.dag, a real on-disk fixture module, following the sole_constructor_sealed fixture-pair pattern -- compile_dag_rust_emit_check resolves a single virtual module against the real corpus, so the alias's declaring module must be real, not inline) declares `type Handler = fn(Int) -> Int` and `type Boxed { handler: Handler }`. The virtual fixture module fixture.cross_module_call, a DIFFERENT module from definer, imports Boxed and calls `.handler(...)` on a Boxed value with a well-typed Int argument. compile_dag_rust_emit_check must SUCCEED (return true, no blocking diagnostic) on this fixture: the cross-module alias must actually expand to its real Int parameter so the well-typed call is accepted rather than wrongly refused as ContractUnavailable. Confirmed by direct execution against the repaired stage0 mirror: this fixture compiles clean.\n\nCOMPANION CONTROL, UNCHANGED BEHAVIOR. The genuinely-unavailable case is untouched by this repair and must keep refusing: a receiver whose method resolves to neither an algebra template nor a callable field (an ordinary non-callable field accessed with call syntax) must still hit ContractUnavailable and still produce the hard diagnostic -- the ContractUnavailable refusal ITSELF is not relaxed, only its mis-triggering on genuinely-expandable cross-module aliases. Confirmed by direct execution: this companion fixture refuses today with the same ContractUnavailable diagnostic, both before and after this repair, because it never reaches expand_field_type in either version (the field is not fn-typed at all, so callable.params is never the trigger).\n\ndissolve-on: none -- executing evidence DESIGN section 4b requires stay enrolled permanently once a class climbs a rung, so a future edit to declared_arg_types_for_method or expand_field_type cannot silently regress this class." +// PERMANENT REGRESSION CONTROL, companion to method_arg_declared_contract_witness_test.dag (#8592). +// Landed per dashboard node adhoc-28a6f804-3cd, reconciling #8572 and #8579, handoff repair from +// deep-ant-102. +// +// CORRECTED UNDERSTANDING FROM DIRECT EXECUTION. ContractUnavailable is not a silent-accept path: +// lookup_structural_method's Absent arm produces a hard, blocking diagnostic ("no declared argument +// contract is available for this method call; refusing rather than substituting the receiver +// element type") unconditionally, regardless of whether the actual call argument would have +// type-checked -- confirmed by direct compile of a genuinely-unavailable-contract fixture (a +// non-callable field called with call syntax), which refuses today with exactly that diagnostic. So +// the defect this repair closes is an OVER-REFUSAL, not a silent accept: a receiver's method +// exposed via a field whose declared type is an alias to a fn type, where the alias's declaring +// module differs from the call site's module, wrongly hit ContractUnavailable and refused a +// well-typed call outright, because declared_arg_types_for_method had no expand_field_type +// parameter and so never expanded the still-unexpanded alias-reference node (params.count == 0 on +// the raw field type) before reading its params. Fixed, expand_field_type resolves the cross-module +// alias to its real fn(Int) -> Int shape, params.count becomes > 0, and a well-typed call against +// that real contract compiles clean instead of being wrongly refused. +// +// WHAT IS ASSERTED. test.fixture.cross_module_alias_handler.definer +// (dag/test/fixture/cross_module_alias_handler/definer.dag, a real on-disk fixture module, +// following the sole_constructor_sealed fixture-pair pattern -- compile_dag_rust_emit_check +// resolves a single virtual module against the real corpus, so the alias's declaring module must be +// real, not inline) declares `type Handler = fn(Int) -> Int` and `type Boxed { handler: Handler }`. +// The virtual fixture module fixture.cross_module_call, a DIFFERENT module from definer, imports +// Boxed and calls `.handler(...)` on a Boxed value with a well-typed Int argument. +// compile_dag_rust_emit_check must SUCCEED (return true, no blocking diagnostic) on this fixture: +// the cross-module alias must actually expand to its real Int parameter so the well-typed call is +// accepted rather than wrongly refused as ContractUnavailable. Confirmed by direct execution +// against the repaired stage0 mirror: this fixture compiles clean. +// +// COMPANION CONTROL, UNCHANGED BEHAVIOR. The genuinely-unavailable case is untouched by this repair +// and must keep refusing: a receiver whose method resolves to neither an algebra template nor a +// callable field (an ordinary non-callable field accessed with call syntax) must still hit +// ContractUnavailable and still produce the hard diagnostic -- the ContractUnavailable refusal +// ITSELF is not relaxed, only its mis-triggering on genuinely-expandable cross-module aliases. +// Confirmed by direct execution: this companion fixture refuses today with the same +// ContractUnavailable diagnostic, both before and after this repair, because it never reaches +// expand_field_type in either version (the field is not fn-typed at all, so callable.params is +// never the trigger). +// +// dissolve-on: none -- executing evidence DESIGN section 4b requires stay enrolled permanently once +// a class climbs a rung, so a future edit to declared_arg_types_for_method or expand_field_type +// cannot silently regress this class. fn method_arg_cross_module_alias_fixture_source() -> String { "module fixture.cross_module_call\n\nimport test.fixture.cross_module_alias_handler.definer { Boxed }\n\nfn probe(b: Boxed, good_arg: Int) -> Int {\n b.handler(good_arg)\n}\n" diff --git a/dag/test/claim/method_arg_declared_contract_witness_test.dag b/dag/test/claim/method_arg_declared_contract_witness_test.dag index 569869b527e..acfd0015659 100644 --- a/dag/test/claim/method_arg_declared_contract_witness_test.dag +++ b/dag/test/claim/method_arg_declared_contract_witness_test.dag @@ -1,6 +1,51 @@ module test.claim.method_arg_declared_contract_witness_test -data method_arg_declared_contract_witness_note: String = "PERMANENT REGRESSION CONTROL for #8592 (infer_method_args_with_fold: infer each argument against the declared parameter contract, never the receiver element type). Landed per dashboard node adhoc-28a6f804-3cd, reconciling #8572 and #8579.\n\nWHY THIS FIXTURE DISCRIMINATES, ON THE .dag AUTHORITY. List.get is declared ReceiverSelf, NamedTemplate{\"Int\"} in dag/std/algebra.dag free_monoid_collection_templates -- the index argument's declared type is always Int, independent of T. `get` is deliberately NOT one of #8579's hardcoded skip/take/at/nth/index special cases (confirmed against scalar_shaped_builtin_method_arg_type at 98d7147f9e~1, src/v1/04_infer.dag), so on that pre-#8592 baseline `get`'s argument fell through to the Absent arm, which substituted the RECEIVER's element type (NonEmptyStr) as the expected type for the index argument instead of refusing or consulting a per-method contract. Passing an argument of the receiver's element type where Int is required is therefore silently ACCEPTED pre-#8592 on the authority (the expected-type check trivially matches its own substitution) and would be correctly REFUSED post-#8592, once declared_arg_types_for_method (04_lookup.dag) supplies the real per-position Int contract and the mismatch against a NonEmptyStr argument becomes a real, located type error. A literal integer argument does not discriminate here (integer-literal inference does not fail against either expected type), which is why this fixture instead passes a NonEmptyStr-typed value at the Int position.\n\nWHY IT IS RED ON THE COMMITTED BINARY TODAY. compile_dag_rust_emit_check executes the compiled stage0 Rust mirror (src/v1/stage0/src/*.rs), not the .dag authority directly, and #8592 never regenerated that mirror -- its own commit message records that required-regen's v2 self-compile refused with 11 source-annotation diagnostics, blocking the regen. Confirmed by direct execution against gunbc built from both 98d7147f9e and its parent: both compile this fixture clean with zero diagnostics, byte-identical emitted output, and grep on src/v1/stage0/src/v1_compiler_infer.rs shows declared_arg_types_for_method absent and the pre-fix scalar_shaped_builtin_method_arg_type whitelist still present and still called. This is the same authority/mirror drift class documented in dag/gunbc/generated_artifact_merge_driver.dag, and it is quarantined via gunbc.explicit_witness_admission (known_red_probe on this witness) rather than asserted here, so this file states only the discriminating claim, not its current disposition.\n\nWHAT IS ASSERTED. compile_dag_rust_emit_check must be REFUSED (return false) on this fixture once the fix is actually live in the executing binary -- i.e. the corrected inference must produce a hard, blocking type diagnostic for the ill-typed call, not silently accept it. This is a black-box, per-PR-discoverable witness on the same compile_dag_rust_emit_check production path used by the caret-syntax family (dag/test/claim/caret_syntax_witness_test.dag), not a white-box call into 04_infer.dag/04_lookup.dag internals -- there was no existing mechanism anywhere in the corpus that compiled an inline .dag fixture and asserted on its diagnostic/refusal behavior for a 04_infer contract question; this file is that mechanism, built because #8592 landed without one.\n\ndissolve-on: none -- this is not scaffold, it is the executing evidence DESIGN section 4b requires stay enrolled permanently once a class climbs a rung, so a future edit to infer_method_args_with_fold or declared_arg_types_for_method cannot silently regress this class. Its quarantine row in gunbc.explicit_witness_admission dissolves separately, once the stage0 mirror is regenerated." +// PERMANENT REGRESSION CONTROL for #8592 (infer_method_args_with_fold: infer each argument against +// the declared parameter contract, never the receiver element type). Landed per dashboard node +// adhoc-28a6f804-3cd, reconciling #8572 and #8579. +// +// WHY THIS FIXTURE DISCRIMINATES, ON THE .dag AUTHORITY. List.get is declared ReceiverSelf, +// NamedTemplate{"Int"} in dag/std/algebra.dag free_monoid_collection_templates -- the index +// argument's declared type is always Int, independent of T. `get` is deliberately NOT one of +// #8579's hardcoded skip/take/at/nth/index special cases (confirmed against +// scalar_shaped_builtin_method_arg_type at 98d7147f9e~1, src/v1/04_infer.dag), so on that pre-#8592 +// baseline `get`'s argument fell through to the Absent arm, which substituted the RECEIVER's +// element type (NonEmptyStr) as the expected type for the index argument instead of refusing or +// consulting a per-method contract. Passing an argument of the receiver's element type where Int is +// required is therefore silently ACCEPTED pre-#8592 on the authority (the expected-type check +// trivially matches its own substitution) and would be correctly REFUSED post-#8592, once +// declared_arg_types_for_method (04_lookup.dag) supplies the real per-position Int contract and the +// mismatch against a NonEmptyStr argument becomes a real, located type error. A literal integer +// argument does not discriminate here (integer-literal inference does not fail against either +// expected type), which is why this fixture instead passes a NonEmptyStr-typed value at the Int +// position. +// +// WHY IT IS RED ON THE COMMITTED BINARY TODAY. compile_dag_rust_emit_check executes the compiled +// stage0 Rust mirror (src/v1/stage0/src/*.rs), not the .dag authority directly, and #8592 never +// regenerated that mirror -- its own commit message records that required-regen's v2 self-compile +// refused with 11 source-annotation diagnostics, blocking the regen. Confirmed by direct execution +// against gunbc built from both 98d7147f9e and its parent: both compile this fixture clean with +// zero diagnostics, byte-identical emitted output, and grep on +// src/v1/stage0/src/v1_compiler_infer.rs shows declared_arg_types_for_method absent and the pre-fix +// scalar_shaped_builtin_method_arg_type whitelist still present and still called. This is the same +// authority/mirror drift class documented in dag/gunbc/generated_artifact_merge_driver.dag, and it +// is quarantined via gunbc.explicit_witness_admission (known_red_probe on this witness) rather than +// asserted here, so this file states only the discriminating claim, not its current disposition. +// +// WHAT IS ASSERTED. compile_dag_rust_emit_check must be REFUSED (return false) on this fixture once +// the fix is actually live in the executing binary -- i.e. the corrected inference must produce a +// hard, blocking type diagnostic for the ill-typed call, not silently accept it. This is a +// black-box, per-PR-discoverable witness on the same compile_dag_rust_emit_check production path +// used by the caret-syntax family (dag/test/claim/caret_syntax_witness_test.dag), not a white-box +// call into 04_infer.dag/04_lookup.dag internals -- there was no existing mechanism anywhere in the +// corpus that compiled an inline .dag fixture and asserted on its diagnostic/refusal behavior for a +// 04_infer contract question; this file is that mechanism, built because #8592 landed without one. +// +// dissolve-on: none -- this is not scaffold, it is the executing evidence DESIGN section 4b +// requires stay enrolled permanently once a class climbs a rung, so a future edit to +// infer_method_args_with_fold or declared_arg_types_for_method cannot silently regress this class. +// Its quarantine row in gunbc.explicit_witness_admission dissolves separately, once the stage0 +// mirror is regenerated. fn method_arg_declared_contract_fixture_source() -> String { "module argfix.probe\n\nimport std.types { List, NonEmptyStr }\n\nfn probe(items: List, bad_index: NonEmptyStr) -> NonEmptyStr? {\n items.get(n: bad_index)\n}\n" diff --git a/dag/test/claim/module_filename_collision_witness_test.dag b/dag/test/claim/module_filename_collision_witness_test.dag index ef14e97ed1a..b0eefaf69d7 100644 --- a/dag/test/claim/module_filename_collision_witness_test.dag +++ b/dag/test/claim/module_filename_collision_witness_test.dag @@ -19,17 +19,17 @@ data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly // THE SUBJECT. v1.compiler.emit_core_support module_to_filename maps '.' to '_', so it is // MANY-TO-ONE: `mmfc.a_b` and `mmfc_a.b` both render `mmfc_a_b`. Every target emitter names one -// emitted file per module by that mapping, so before this wall the two modules wrote the same -// path and whichever was emitted second silently replaced the first -- a wrong artifact with no -// diagnostic anywhere. The mapping cannot be made injective without changing every emitted path -// and every cross-module reference derived from one, so the residue is REFUSED rather than -// absorbed, and this file is its executing evidence. +// emitted file per module by that mapping, so before this wall the two modules wrote the same path +// and whichever was emitted second silently replaced the first -- a wrong artifact with no +// diagnostic. The mapping cannot be made injective without changing every emitted path and every +// cross-module reference derived from one, so the residue is REFUSED rather than absorbed, and this +// file is its executing evidence. // // WHY THE MULTI-MODULE FIXTURE AND NOT THE SINGLE-MODULE CENSUS. The subject IS a relationship // between two modules: no one-module source can express it, and gunbc.compile_diagnostic_census // resolves its one synthetic module against the live checkout, so a second module cannot be -// authored there at all. tools.multi_module_compile_fixture compiles a caller-authored manifest -// in isolation, which is exactly the boundary at which this RED is authorable. +// authored there. tools.multi_module_compile_fixture compiles a caller-authored manifest in +// isolation, exactly the boundary at which this RED is authorable. data collide_peer_source: String = "module mmfc_a.b\nfn collide_peer_answer() -> Int { 7 }\n" data collide_entry_source: String = "module mmfc.a_b\nimport mmfc_a.b { collide_peer_answer }\nfn collide_entry_answer() -> Int { collide_peer_answer() }\n" diff --git a/dag/test/claim/module_graph_edge_source_witness_test.dag b/dag/test/claim/module_graph_edge_source_witness_test.dag index ce25633a16c..92cf9bb171b 100644 --- a/dag/test/claim/module_graph_edge_source_witness_test.dag +++ b/dag/test/claim/module_graph_edge_source_witness_test.dag @@ -61,7 +61,10 @@ fn contains_str(xs: List, want: String) -> Bool { count_of(xs: xs, want: want) > 0 } -data two_source_note: String = "The discriminating half: provider_referenced is reachable ONLY through the reference producer. If the call site's reference arm were replaced by a second copy of the import arm, this edge would be absent and this reds — which is precisely the regression that reached main-adjacent review unnoticed." +// The discriminating half: provider_referenced is reachable ONLY through the reference producer. If +// the call site's reference arm were replaced by a second copy of the import arm, this edge would +// be absent and this reds — which is precisely the regression that reached main-adjacent review +// unnoticed. test fn witness_reference_only_dependency_reaches_the_union() -> Bool { let ref_targets = fact_targets(facts: fixture_reference_facts()) diff --git a/dag/test/claim/module_impact_query_witness_test.dag b/dag/test/claim/module_impact_query_witness_test.dag index ac54689d400..9c7279a8422 100644 --- a/dag/test/claim/module_impact_query_witness_test.dag +++ b/dag/test/claim/module_impact_query_witness_test.dag @@ -51,7 +51,15 @@ import v2.lens.module_impact_query { changed_surface_skip_authority, } -data module_impact_query_witness_note: String = "Controlled fixtures: every input population and every expected population is authored here, so no assertion is a measurement of the current tree copied back onto itself (DESIGN 5 oracle rule). Three discriminating families. (1) The cycle pair - all_import vs mixed - has identical topology and different provenance, so a union-grain classifier reds on one while passing the other. (2) The two-disjoint-cycles fixture is the regression control for review 50459: the pre-fix union-level verdict greened its own suite while suppressing a real violation. (3) The pool-mismatch fixture is the control for the operator's F3 finding: an edge whose target is declared-but-absent from the pool used to vanish silently while the reading still answered complete." +// Controlled fixtures: every input population and every expected population is authored here, so no +// assertion is a measurement of the current tree copied back onto itself (DESIGN 5 oracle rule). +// Three discriminating families. (1) The cycle pair - all_import vs mixed - has identical topology +// and different provenance, so a union-grain classifier reds on one while passing the other. (2) +// The two-disjoint-cycles fixture is the regression control for review 50459: the pre-fix +// union-level verdict greened its own suite while suppressing a real violation. (3) The +// pool-mismatch fixture is the control for the operator's F3 finding: an edge whose target is +// declared-but-absent from the pool used to vanish silently while the reading still answered +// complete. data fixture_nodes: List = [ ModuleDeclarationFact { module: "m.a", path: "fixture/a.dag" }, @@ -71,7 +79,10 @@ data pool_independence_unavailable: List = [ }, ] -data pool_independence_established_note: String = "ReferenceDerivedClosureAcceptanceReceipt is sole_constructor, so a consumer CANNOT fabricate an Established capability from outside the admission module - the wall refused this witness's first attempt to hand-build the receipt, which is exactly the point of the wall. The admission module's own `established` constructor is the only legitimate route, so the witness goes through it." +// ReferenceDerivedClosureAcceptanceReceipt is sole_constructor, so a consumer CANNOT fabricate an +// Established capability from outside the admission module - the wall refused this witness's first +// attempt to hand-build the receipt, which is exactly the point of the wall. The admission module's +// own `established` constructor is the only legitimate route, so the witness goes through it. data pool_independence_established: List = [ established(capability: UnrelatedLoadedFileExcluded), @@ -226,7 +237,13 @@ data declared_but_absent_edges: List = [ ModuleDependencyEdge { path: "fixture/b.dag", target_module: "m.ghost", target_declared: true }, ] -data pool_mismatch_note: String = "F3 control (operator ruling 2026-08-08). m.ghost is target_declared TRUE but has no ModuleDeclarationFact in fixture_nodes - the producer believed it declared, the supplied pool does not carry it. The pre-recut implementation resolved that edge to zero rows, dropped it from adjacency/closure/cycles, and computed completeness from the raw declared flag alone, so the reading answered CLOSED on an inconsistent pool. The two observations are now independent, so this must surface as DeclaredTargetAbsentFromPool and must NOT be reported as an undeclared target." +// F3 control (operator ruling 2026-08-08). m.ghost is target_declared TRUE but has no +// ModuleDeclarationFact in fixture_nodes - the producer believed it declared, the supplied pool +// does not carry it. The pre-recut implementation resolved that edge to zero rows, dropped it from +// adjacency/closure/cycles, and computed completeness from the raw declared flag alone, so the +// reading answered CLOSED on an inconsistent pool. The two observations are now independent, so +// this must surface as DeclaredTargetAbsentFromPool and must NOT be reported as an undeclared +// target. test fn witness_declared_but_absent_target_is_not_silently_dropped() -> Bool { let reading = module_impact_reading( @@ -388,10 +405,13 @@ test fn witness_no_component_merges_modules_from_distinct_cycles() -> Bool { }) == false } - - - -data changed_surface_witness_note: String = "CAPSULE 2 acceptance, REWORKED under the operator ruling 2026-08-08. The earlier revision's five controls were good for what they tested but the SELECTED contract was not the PRODUCT contract: deletions were discarded, every subject resolved against head, an unresolved subject did not contaminate the typed result, and nothing stopped a partial answer authorizing a skip. These witnesses pin the reworked contract, including the two the operator named explicitly: an unresolved subject makes the WHOLE outcome Partial, and a Partial outcome can never yield a skip authority." +// CAPSULE 2 acceptance, REWORKED under the operator ruling 2026-08-08. The earlier revision's five +// controls were good for what they tested but the SELECTED contract was not the PRODUCT contract: +// deletions were discarded, every subject resolved against head, an unresolved subject did not +// contaminate the typed result, and nothing stopped a partial answer authorizing a skip. These +// witnesses pin the reworked contract, including the two the operator named explicitly: an +// unresolved subject makes the WHOLE outcome Partial, and a Partial outcome can never yield a skip +// authority. data no_departed: List = [] @@ -526,7 +546,13 @@ test fn witness_a_complete_but_pool_relative_outcome_withholds_skip_authority() } } -data differential_control_note: String = "OPERATOR ruling item 6. The production selector asks, per entry, whether any touched path lies in that entry's FORWARD dependency closure; this lane answers it once in reverse. The two must agree exactly over the same edge population: entry E's forward closure contains M if and only if E is among the reverse consumers of M. This witness asserts that biconditional in BOTH directions over every module in a fixture population — a one-directional check would pass on a reverse answer that silently narrows, which is the failure mode that matters when a selector decides what NOT to run." +// OPERATOR ruling item 6. The production selector asks, per entry, whether any touched path lies in +// that entry's FORWARD dependency closure; this lane answers it once in reverse. The two must agree +// exactly over the same edge population: entry E's forward closure contains M if and only if E is +// among the reverse consumers of M. This witness asserts that biconditional in BOTH directions over +// every module in a fixture population — a one-directional check would pass on a reverse answer +// that silently narrows, which is the failure mode that matters when a selector decides what NOT to +// run. fn forward_closure_of(entry: ModuleIdentity) -> List { module_impact_reading( @@ -583,8 +609,11 @@ test fn witness_the_differential_control_can_fail() -> Bool { && count_where(xs: forward_closure_of(entry: mod_c), predicate: fn(_) { true }) == 1 } - -data fully_unresolved_witness_note: String = "Addendum to the operator ruling (verification pass, 2026-08-08). The earlier fully-unresolved case asserted only that nothing was reached, which INSTITUTIONALISED the exact bug item 3 names: a surface where NO input resolved produced reached=0 and a result a machine consumer would read as affects-nothing. Reaching nothing and knowing nothing are different states. This asserts the whole-result arm." +// Addendum to the operator ruling (verification pass, 2026-08-08). The earlier fully-unresolved +// case asserted only that nothing was reached, which INSTITUTIONALISED the exact bug item 3 names: +// a surface where NO input resolved produced reached=0 and a result a machine consumer would read +// as affects-nothing. Reaching nothing and knowing nothing are different states. This asserts the +// whole-result arm. test fn witness_a_fully_unresolved_surface_is_partial_not_an_empty_answer() -> Bool { let outcome = surface_outcome(changed: ["README.md", "docs/plans/x.md"], departed: no_departed) @@ -598,8 +627,12 @@ test fn witness_a_fully_unresolved_surface_is_partial_not_an_empty_answer() -> B } } - -data departed_overlap_witness_note: String = "The earlier fixtures authored changed_paths and departed_paths as DISJOINT lists, which is not how git reports a deletion: touched_paths carries every entry's path including deleted ones, so a deleted path appears in both. The fixture was therefore not a model of the real observation, and the bug it hid - one deletion producing two subjects, a spurious NoModuleDeclaredAtPath beside the correct BaseGraphUnavailable - was found by a real-diff receipt instead. This witness authors the overlap the way git actually produces it." +// The earlier fixtures authored changed_paths and departed_paths as DISJOINT lists, which is not +// how git reports a deletion: touched_paths carries every entry's path including deleted ones, so a +// deleted path appears in both. The fixture was therefore not a model of the real observation, and +// the bug it hid - one deletion producing two subjects, a spurious NoModuleDeclaredAtPath beside +// the correct BaseGraphUnavailable - was found by a real-diff receipt instead. This witness authors +// the overlap the way git actually produces it. test fn witness_a_deleted_path_present_in_both_lists_yields_one_base_subject() -> Bool { let outcome = surface_outcome( diff --git a/dag/test/claim/multi_module_compile_fixture_witness_test.dag b/dag/test/claim/multi_module_compile_fixture_witness_test.dag index f90258f41c9..70d2388d7ad 100644 --- a/dag/test/claim/multi_module_compile_fixture_witness_test.dag +++ b/dag/test/claim/multi_module_compile_fixture_witness_test.dag @@ -29,7 +29,30 @@ data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly // asks about -- the question that field owns is affected-set selection eligibility, which is a // property of which SOURCES a witness's verdict depends on. -data multi_module_compile_fixture_witness_note: String = "WHAT THESE SEVEN CONTROLS PROVE, and what they do not. They prove the instrument compiles a caller-authored MANIFEST in genuine isolation from the corpus, keeps harness-refused separate from subject-refused, reports a module count derived from the RESOLVE stage rather than from the input list, and stamps both digests on every arm that measured something. They prove NOTHING about any wall a consumer then builds on it: a wall's own regression control is its own probe pair, not this file. CONTROL 6 IS THE LOAD-BEARING ONE AND IS WRITTEN FIRST DELIBERATELY -- without it every other control can pass vacuously, because an instrument that silently answers 'compiled clean, zero diagnostics' whenever it fails to run satisfies control 1 by construction and control 2 only by accident. Its executable face is that a manifest the instrument cannot form at all lands in FixtureInstrumentRefused, which is a different variant from every arm carrying a diagnostic list, so a caller matching for a clean compile cannot receive one. CONTROLS 4 AND 5 ARE ONE QUESTION FROM TWO SIDES and neither alone decides it: 4 shows a corpus module NOT supplied is unreachable (an entry importing std.types refuses UnresolvedImport, so no default root was loaded), and 5 shows a corpus SPELLING that IS supplied binds the fixture's own declaration (a fixture module spelled std.logic exports a symbol the real std.logic does not have, and the entry importing it compiles clean). Together they establish that the pool is exactly the manifest -- neither wider nor narrower. THE OPEN QUESTION UPSTREAM COULD NOT ANSWER, recorded because it was asked as a real design question rather than rhetorically: whether a fixture can be corpus-isolated at all under whole-corpus floor preparation, where the required floor folds every witness through ONE prepared subject so that a witness and the corpus share a name pool unconditionally. It can. That preparation governs how the WITNESS is compiled and is consulted by unrelated censuses; the nested compile this instrument performs never reads it. Controls 4 and 5 measure that rather than assuming it, and they run on the floor -- which is what makes the answer evidence instead of an argument." +// WHAT THESE SEVEN CONTROLS PROVE, and what they do not. They prove the instrument compiles a +// caller-authored MANIFEST in genuine isolation from the corpus, keeps harness-refused separate +// from subject-refused, reports a module count derived from the RESOLVE stage rather than from the +// input list, and stamps both digests on every arm that measured something. They prove NOTHING +// about any wall a consumer then builds on it: a wall's own regression control is its own probe +// pair, not this file. CONTROL 6 IS THE LOAD-BEARING ONE AND IS WRITTEN FIRST DELIBERATELY -- +// without it every other control can pass vacuously, because an instrument that silently answers +// 'compiled clean, zero diagnostics' whenever it fails to run satisfies control 1 by construction +// and control 2 only by accident. Its executable face is that a manifest the instrument cannot form +// at all lands in FixtureInstrumentRefused, which is a different variant from every arm carrying a +// diagnostic list, so a caller matching for a clean compile cannot receive one. CONTROLS 4 AND 5 +// ARE ONE QUESTION FROM TWO SIDES and neither alone decides it: 4 shows a corpus module NOT +// supplied is unreachable (an entry importing std.types refuses UnresolvedImport, so no default +// root was loaded), and 5 shows a corpus SPELLING that IS supplied binds the fixture's own +// declaration (a fixture module spelled std.logic exports a symbol the real std.logic does not +// have, and the entry importing it compiles clean). Together they establish that the pool is +// exactly the manifest -- neither wider nor narrower. THE OPEN QUESTION UPSTREAM COULD NOT ANSWER, +// recorded because it was asked as a real design question rather than rhetorically: whether a +// fixture can be corpus-isolated at all under whole-corpus floor preparation, where the required +// floor folds every witness through ONE prepared subject so that a witness and the corpus share a +// name pool unconditionally. It can. That preparation governs how the WITNESS is compiled and is +// consulted by unrelated censuses; the nested compile this instrument performs never reads it. +// Controls 4 and 5 measure that rather than assuming it, and they run on the floor -- which is what +// makes the answer evidence instead of an argument. // --------------------------------------------------------------------------- // The authored manifests. Every byte here is fixture-owned: nothing is borrowed from a corpus diff --git a/dag/test/claim/namespace_clause_e_projection_law_witness_test.dag b/dag/test/claim/namespace_clause_e_projection_law_witness_test.dag index 0ffa25ca836..5d183366b6d 100644 --- a/dag/test/claim/namespace_clause_e_projection_law_witness_test.dag +++ b/dag/test/claim/namespace_clause_e_projection_law_witness_test.dag @@ -29,7 +29,11 @@ import std.occurrence_binding_candidates { } import std.types { Bool, FilePath, List, NonEmptyStr } -data namespace_clause_e_projection_law_witness_note: String = "Planted controls for gunbc.namespace_clause_e_projection_law assess_controlled_two_mention_provenance_projection. Each NamespaceClauseEProjectionFailure variant is exercised on a hand-built ReferenceDerivedClauseEProductionReady carrier using the full projection fields. B2 row-closure over OrdinaryLoadedCompilationClosure is excluded from this witness file." +// Planted controls for gunbc.namespace_clause_e_projection_law +// assess_controlled_two_mention_provenance_projection. Each NamespaceClauseEProjectionFailure +// variant is exercised on a hand-built ReferenceDerivedClauseEProductionReady carrier using the +// full projection fields. B2 row-closure over OrdinaryLoadedCompilationClosure is excluded from +// this witness file. fn contract_witness_consumer_file() -> FilePath { "app/consumer.dag" diff --git a/dag/test/claim/namespace_cut_subject_observation_witness_test.dag b/dag/test/claim/namespace_cut_subject_observation_witness_test.dag index 800560c36d7..7bb73c15192 100644 --- a/dag/test/claim/namespace_cut_subject_observation_witness_test.dag +++ b/dag/test/claim/namespace_cut_subject_observation_witness_test.dag @@ -33,11 +33,11 @@ import gunbc.namespace_cut_subject_observation { probe_is_host, } -// ReadsLiveTree by G1 carrier-closure honesty, exactly as v2.test.lens_enforcement.gate_test -// records for itself: every arm below feeds AUTHORED values, but the loader closure imports the -// observation module, which is a declared live-read carrier home, so a SubstrateInputsOnly stamp -// would be a lying stamp. The LIVE execution evidence for this instrument is its own runnable -// report (subject_roster_report), exercised by the manager rather than by the floor. +// ReadsLiveTree by G1 carrier-closure honesty, as v2.test.lens_enforcement.gate_test records for +// itself: every arm below feeds AUTHORED values, but the loader closure imports the observation +// module, a declared live-read carrier home, so a SubstrateInputsOnly stamp would lie. The LIVE +// execution evidence for this instrument is its own runnable report (subject_roster_report), +// exercised by the manager rather than by the floor. data live_tree_disposition: LiveTreeDisposition = ReadsLiveTree fn fixture_probe() -> NamespaceCutSubjectProbe { @@ -77,15 +77,14 @@ test fn a_host_probe_refuses_rather_than_answering_from_the_declaration_route() } // --------------------------------------------------------------------------------------------- -// THE HOST JOIN, ALL FOUR ARMS, AUTHORED. This is the arm set that makes the join safe to trust, -// and it is authorable in full because observe_host_probe takes the observation as a parameter -- -// no tree state moves any of these. +// THE HOST JOIN, ALL FOUR ARMS, AUTHORED. This arm set makes the join safe to trust, and it is +// authorable in full because observe_host_probe takes the observation as a parameter -- no tree +// state moves any of these. // -// The load-bearing pair is the last two. A scanned file with no matching item is ABSENT (the -// cut's success state), and a file the population never covered is UNOBSERVABLE. Collapsing the -// second into the first is the absorbing fallback DESIGN section 5 forbids -- an unread file -// silently joining the deleted -- and it is exactly one `else` away at all times, so it is -// asserted rather than argued. +// The load-bearing pair is the last two. A scanned file with no matching item is ABSENT (the cut's +// success state); a file the population never covered is UNOBSERVABLE. Collapsing the second into +// the first is the absorbing fallback DESIGN section 5 forbids -- an unread file silently joining +// the deleted -- and it is one `else` away at all times, so it is asserted rather than argued. // --------------------------------------------------------------------------------------------- fn host_fixture_probe() -> NamespaceCutSubjectProbe { HostRustItemProbe { crate_relative_file: "src/v1/stage0/src/cli_run.rs", item_name: "extract_import_paths" } diff --git a/dag/test/claim/namespace_import_closure_witness_test.dag b/dag/test/claim/namespace_import_closure_witness_test.dag index 7d2f2614718..93f1c177765 100644 --- a/dag/test/claim/namespace_import_closure_witness_test.dag +++ b/dag/test/claim/namespace_import_closure_witness_test.dag @@ -2,7 +2,13 @@ module test.claim.namespace_import_closure_witness import tools.namespace_import_closure_behavioral_transport { nic_behavioral_receipt_holds } -data namespace_import_closure_witness_doc: String = "Wet receipt for the Gate-1 emit import-closure derivation (emit_import_closure_root): tools.namespace_import_closure_behavioral_transport emits an import-free namespace module that references a sibling cross-module, via the real gunbc binary, and cargo-builds the emitted crate. Green arm must compile; the red arm — same layout, same chain, provider defining unrelated names — must refuse, so the receipt is an A/B on cross-module name availability rather than a lone green (DESIGN section 5). Live host effects (real emit, cargo build), so it runs in the nightly falsifier Wet follow-on batch (falsifier_self_host_wet_entries), not per-PR hermetic discovery." +// Wet receipt for the Gate-1 emit import-closure derivation (emit_import_closure_root): +// tools.namespace_import_closure_behavioral_transport emits an import-free namespace module that +// references a sibling cross-module, via the real gunbc binary, and cargo-builds the emitted crate. +// Green arm must compile; the red arm — same layout, same chain, provider defining unrelated names +// — must refuse, so the receipt is an A/B on cross-module name availability rather than a lone +// green (DESIGN section 5). Live host effects (real emit, cargo build), so it runs in the nightly +// falsifier Wet follow-on batch (falsifier_self_host_wet_entries), not per-PR hermetic discovery. test fn namespace_import_closure_receipt_holds() -> Bool { nic_behavioral_receipt_holds() diff --git a/dag/test/claim/namespace_occurrence_transport_test.dag b/dag/test/claim/namespace_occurrence_transport_test.dag index 568ab6572af..382dd526ff5 100644 --- a/dag/test/claim/namespace_occurrence_transport_test.dag +++ b/dag/test/claim/namespace_occurrence_transport_test.dag @@ -28,7 +28,10 @@ import std.occurrence_identity { occurrence_transport_refusal, } -data namespace_occurrence_transport_shared_witness_note: String = "Shared-authority claims only: this normal dag/src-v2 witness proves graph-scoped allocation, equal-text identity independence, typed occurrence categories and roles, and missing/duplicate/wrong-role refusal. Parser, inference, ModuleGraph-to-TypedModule preservation, serde, and linear resource receipts live in the v1 Rust production-path test." +// Shared-authority claims only: this normal dag/src-v2 witness proves graph-scoped allocation, +// equal-text identity independence, typed occurrence categories and roles, and +// missing/duplicate/wrong-role refusal. Parser, inference, ModuleGraph-to-TypedModule preservation, +// serde, and linear resource receipts live in the v1 Rust production-path test. fn fixture_span(file: String, start: Int, end: Int) -> std.types.SourceSpan { std.types.SourceSpan { file: file, start: start, end: end } @@ -408,7 +411,13 @@ test fn namespace_occurrence_validator_large_population_holds() -> Bool { (large.index.entries |> count) == 512 } -data namespace_occurrence_transport_superseded_extract_note: String = "Extracted from superseded PR 7383 (session/valiant-cat-127), re-expressed at this file's shared-authority layer per namespace_occurrence_transport_shared_witness_note: the parser realization of these claims lives in v1.tests.claim.pattern_binder_declaration_node_test, and the serde round-trip lives in src/v1/stage0/tests/namespace_occurrence_serde.rs. The residue carried here: a populated declarations-plus-references transport that validates green, equal-text minting at four occurrences, allocator-scope continuation through occurrence_id_allocator_advance_to over AuthoredTokenOrdinalSpace, and green nonempty-ancestor containment for every pattern binder form." +// Extracted from superseded PR 7383 (session/valiant-cat-127), re-expressed at this file's +// shared-authority layer per namespace_occurrence_transport_shared_witness_note: the parser +// realization of these claims lives in v1.tests.claim.pattern_binder_declaration_node_test, and the +// serde round-trip lives in src/v1/stage0/tests/namespace_occurrence_serde.rs. The residue carried +// here: a populated declarations-plus-references transport that validates green, equal-text minting +// at four occurrences, allocator-scope continuation through occurrence_id_allocator_advance_to over +// AuthoredTokenOrdinalSpace, and green nonempty-ancestor containment for every pattern binder form. data namespace_occurrence_serde_seed_test_dissolution: DissolutionCondition = unbound_dissolution(description: "Seed-growth mark (v1-test class): src/v1/stage0/tests/namespace_occurrence_serde.rs is today the ONLY serde coverage of the occurrence sidecar's seed realization (std_occurrence_identity.rs) — the ParseWithTableResult round-trip, plus filename and layout independence of occurrence identity and containment: a whitespace-perturbed source twin whose declaration spans provably move (an executed span-shift control guards against a vacuous reparse) must reproduce identical occurrence ids, categories, and containment paths. DISSOLVE-ON: the v1 terminal deletion path — before src/v1 deletes, its behavior must be carried per the v1-test-migration coverage bar (discriminating floor-witness coverage), at which point the file deletes with the tree; the three shared-authority witnesses in this file (w_namespace_occurrence_transport_mints_distinct_equal_text, w_namespace_occurrence_transport_preserves_graph_allocator, w_namespace_occurrence_transport_covers_pattern_binder_forms) already carry the shared-authority semantics and survive.") diff --git a/dag/test/claim/namespace_pool_independence_witness_test.dag b/dag/test/claim/namespace_pool_independence_witness_test.dag index 6cd6914ae27..20d8257bebf 100644 --- a/dag/test/claim/namespace_pool_independence_witness_test.dag +++ b/dag/test/claim/namespace_pool_independence_witness_test.dag @@ -41,11 +41,32 @@ import test.fixture.cross_file_clause_e_fixture { cross_file_clause_e_fixture_provider_file, } -data namespace_pool_independence_witness_note: String = "N3-C witnesses for gunbc.namespace_pool_independence. Pool independence proper: unrelated_loaded_unrelated_spellings_preserves_full_carrier_holds assembles baseline vs perturbed (+unrelated loaded file, different spelling) via B0+B1 and compares full carriers. Class B silent-reselection discriminator: colliding_root_exported_homonym_refuses_ambiguity_holds — adding a colliding root-exported homonym must typed-refuse (ReferenceBindingProjectionAmbiguous on both consumer references), never produce Ready, never alternate-select, never add a dependency edge. Load-bearing RED: same-file reselection with unchanged file-deps. Per-clause RED controls exercise each PoolIndependenceFailure arm." +// N3-C witnesses for gunbc.namespace_pool_independence. Pool independence proper: +// unrelated_loaded_unrelated_spellings_preserves_full_carrier_holds assembles baseline vs perturbed +// (+unrelated loaded file, different spelling) via B0+B1 and compares full carriers. Class B +// silent-reselection discriminator: colliding_root_exported_homonym_refuses_ambiguity_holds — +// adding a colliding root-exported homonym must typed-refuse (ReferenceBindingProjectionAmbiguous +// on both consumer references), never produce Ready, never alternate-select, never add a dependency +// edge. Load-bearing RED: same-file reselection with unchanged file-deps. Per-clause RED controls +// exercise each PoolIndependenceFailure arm. -data npi_decoy_same_spelled_substrate_finding_note: String = "EXECUTED CONCLUSION (loyal-ram-550 routing 2026-08-07): colliding decoy fixture (app.provider + app.decoy both root-export helper) — perturbed B1 projection is AssembledClosureDependencyProjectionBindingRefused with ReferenceBindingProjectionAmbiguous on BOTH consumer references; no Ready projection, no alternate selection, no extra dependency edge. Substrate behaviour is CORRECT under namespace-only double-bound-is-error; prior equality expectation was wrong. Stronger Class B control: proves silent pool-driven reselection does NOT occur. OPEN (operator, non-blocking): CrossFileProviderExportedExposure => RootExposure may be wrong exposure model if cross-module access is projection (provider.helper) not bare-name root injection — if exposure model changes later this control remains as regression evidence." +// EXECUTED CONCLUSION (loyal-ram-550 routing 2026-08-07): colliding decoy fixture (app.provider + +// app.decoy both root-export helper) — perturbed B1 projection is +// AssembledClosureDependencyProjectionBindingRefused with ReferenceBindingProjectionAmbiguous on +// BOTH consumer references; no Ready projection, no alternate selection, no extra dependency edge. +// Substrate behaviour is CORRECT under namespace-only double-bound-is-error; prior equality +// expectation was wrong. Stronger Class B control: proves silent pool-driven reselection does NOT +// occur. OPEN (operator, non-blocking): CrossFileProviderExportedExposure => RootExposure may be +// wrong exposure model if cross-module access is projection (provider.helper) not bare-name root +// injection — if exposure model changes later this control remains as regression evidence. -data npi_cross_file_export_exposure_open_question_note: String = "OPEN QUESTION (loyal-ram-550 escalation 2026-08-07, operator-signed territory): fixture models cross-file provider export as CrossFileProviderExportedExposure => RootExposure, injecting helper into root scope. Namespace-only design says cross-module access is projection — sibling module visible, members reached as provider.helper, not bare-name injection. If projection governs, app.provider.helper and app.decoy.helper never collide at root and the decoy collision may be a fixture exposure artifact. Does not block N3-C; colliding_root_exported_homonym_refuses_ambiguity_holds stays enrolled regardless." +// OPEN QUESTION (loyal-ram-550 escalation 2026-08-07, operator-signed territory): fixture models +// cross-file provider export as CrossFileProviderExportedExposure => RootExposure, injecting helper +// into root scope. Namespace-only design says cross-module access is projection — sibling module +// visible, members reached as provider.helper, not bare-name injection. If projection governs, +// app.provider.helper and app.decoy.helper never collide at root and the decoy collision may be a +// fixture exposure artifact. Does not block N3-C; +// colliding_root_exported_homonym_refuses_ambiguity_holds stays enrolled regardless. fn npi_witness_consumer_file() -> FilePath { "app/consumer.dag" diff --git a/dag/test/claim/namespace_reference_derived_closure_acceptance_test.dag b/dag/test/claim/namespace_reference_derived_closure_acceptance_test.dag index bfc7a6b9c9a..63a6b835627 100644 --- a/dag/test/claim/namespace_reference_derived_closure_acceptance_test.dag +++ b/dag/test/claim/namespace_reference_derived_closure_acceptance_test.dag @@ -9,7 +9,15 @@ import v2.std.live_tree { LiveTreeDisposition, SubstrateInputsOnly } data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data namespace_reference_derived_closure_acceptance_note: String = "THE DISCRIMINATING CLOSING VALIDATION for roadmap node namespace-reference-derived-closure. It is RED ON PURPOSE and enrolled QuarantineProbeExpectRed. The validation consumes only the production-admission seam, never the controlled fixtures that prove the fold itself: today that seam carries one typed unavailable status per clause, so the derived six-capability frontier cannot green on zero work. Clauses (a-d) name P2aStructuralCandidateProducer7515; (e) names P2aReferenceDependencyProjection7515; (f), the Class-B pool-membership-coincidence wall, names P2aPoolIndependentDependencyProjection7515. The gated implementation must run the real candidate producer and dependency projection for all six scenarios, feed those observations through the sole-constructor assessment boundary, and leave this predicate unchanged." +// THE DISCRIMINATING CLOSING VALIDATION for roadmap node namespace-reference-derived-closure. It is +// RED ON PURPOSE and enrolled QuarantineProbeExpectRed. The validation consumes only the +// production-admission seam, never the controlled fixtures that prove the fold itself: today that +// seam carries one typed unavailable status per clause, so the derived six-capability frontier +// cannot green on zero work. Clauses (a-d) name P2aStructuralCandidateProducer7515; (e) names +// P2aReferenceDependencyProjection7515; (f), the Class-B pool-membership-coincidence wall, names +// P2aPoolIndependentDependencyProjection7515. The gated implementation must run the real candidate +// producer and dependency projection for all six scenarios, feed those observations through the +// sole-constructor assessment boundary, and leave this predicate unchanged. test fn witness_namespace_reference_derived_closure_closing_contract_holds() -> Bool { reference_derived_closure_closing_contract_holds( diff --git a/dag/test/claim/namespace_reference_derived_closure_contract_test.dag b/dag/test/claim/namespace_reference_derived_closure_contract_test.dag index 23cc62acb0b..a222f80ee54 100644 --- a/dag/test/claim/namespace_reference_derived_closure_contract_test.dag +++ b/dag/test/claim/namespace_reference_derived_closure_contract_test.dag @@ -53,7 +53,13 @@ import std.occurrence_binding_resolve { } import std.types { Bool, Int, List, SourceSpan, String } -data namespace_reference_derived_closure_contract_witness_note: String = "CONTROLLED FIXTURES for the six-clause closing fold. The positive population independently authors one satisfying observation per roadmap clause. Each RED changes only the discriminating output: remove the same-file neighbour, leak the sibling branch, leak the later declaration, collapse one distinct homonym, duplicate one provider dependency, or admit one unrelated loaded file. These tests prove the contract rejects every bad state; they do not claim the gated production candidate producer exists. The quarantined acceptance witness imports no fixture from this module." +// CONTROLLED FIXTURES for the six-clause closing fold. The positive population independently +// authors one satisfying observation per roadmap clause. Each RED changes only the discriminating +// output: remove the same-file neighbour, leak the sibling branch, leak the later declaration, +// collapse one distinct homonym, duplicate one provider dependency, or admit one unrelated loaded +// file. These tests prove the contract rejects every bad state; they do not claim the gated +// production candidate producer exists. The quarantined acceptance witness imports no fixture from +// this module. fn oid(value: Int) -> OccurrenceId { OccurrenceId { value: value } } diff --git a/dag/test/claim/namespace_structural_observations_acceptance_test.dag b/dag/test/claim/namespace_structural_observations_acceptance_test.dag index 470071668d1..fab43469602 100644 --- a/dag/test/claim/namespace_structural_observations_acceptance_test.dag +++ b/dag/test/claim/namespace_structural_observations_acceptance_test.dag @@ -43,7 +43,11 @@ data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly // set is EXACTLY the one capability whose rule was broken. A control that only asserted "the // contract is false" would pass just as well if the bridge returned nothing at all, and that is // the failure the production-refused arms of the observation carrier exist to make visible. -data namespace_structural_observations_acceptance_note: String = "Closing validation for namespace-structural-observations. One ordinary compiled subject produces all four in-file visibility observations through the production bridge; four single-edit mutants of that same subject each break exactly one rule and refuse exactly that capability; one mutant changes only the declared module and refuses on subject provenance with every capability still established." +// Closing validation for namespace-structural-observations. One ordinary compiled subject produces +// all four in-file visibility observations through the production bridge; four single-edit mutants +// of that same subject each break exactly one rule and refuse exactly that capability; one mutant +// changes only the declared module and refuses on subject provenance with every capability still +// established. fn nso_subject_with_source(source: String) -> StructuralObservationSubject { let subject = namespace_structural_observations_subject() diff --git a/dag/test/claim/native_witness_transition_receipt_witness_test.dag b/dag/test/claim/native_witness_transition_receipt_witness_test.dag index e1cc97130d6..f41d7f38f55 100644 --- a/dag/test/claim/native_witness_transition_receipt_witness_test.dag +++ b/dag/test/claim/native_witness_transition_receipt_witness_test.dag @@ -16,9 +16,47 @@ import v2.test.execution.native_selected_witness_bundle { native_selected_witness_bundle_cutover_evidence_holds, } -data native_witness_transition_witness_note: String = "THE TWO STANDING ARMS ARE ASSERTED TOGETHER ON PURPOSE. Either arm alone would pass against a fold that ignored its inputs and returned a constant; asserting both means no constant implementation survives, which is what makes the pair discriminating rather than decorative. The subject join is the second independent question -- a receipt naming a node identity nothing declares is evidence about nobody -- and its RED plants a fabricated identity so the join is proven capable of returning zero. That control is not hypothetical: drafting this receipt first transcribed the node identity as rn_2I5K7M9O1Q3S5T8V0W2X4Y7Z9A1C, one character off the declared rn_2I5K7M9O1Q3R6T8V0W2X4Y7Z9A1C, and the join is what catches that class." - -data cited_evidence_resolution_note: String = "THE RECEIPT'S OWN CITATION HAD TO BE PROVEN, OR THE FIX FOR DUAL REPRESENTATION REINTRODUCES THE STALE-CITATION CLASS AT THE POINT EVERYTHING NOW CITES (operator gap finding on gunbc#7718, 2026-08-03). executed_evidence is an AUTHORED DeclarationRef. #7718 witnessed the node identity and both standing arms but never established that the cited declaration resolves at all -- and this repository had just repaired seven typed DeclarationRef rows pointing at nothing. A receipt whose whole purpose is to be the single citable home for execution evidence must not itself carry an unverified citation.\n\nTHE MECHANISM IS THE LANGUAGE'S OWN RESOLVER, NOT A SECOND CENSUS. This module IMPORTS native_selected_witness_bundle_cutover_evidence_holds. An import is resolved by the namespace authority, which refuses an unbound name and refuses a double-bound one, so 'resolves to EXACTLY ONE declaration' is discharged by compilation rather than by a fold this file would have to author -- construction over validation (DESIGN 5), and no fork of the G1 resolver. If the cited declaration is renamed or deleted, this module stops compiling; the citation cannot rot silently. The string equality below is what binds that compile-time fact to the AUTHORED field: if the receipt's module_path or decl_name drifts away from the symbol actually imported, the equality reds even though the import still resolves.\n\nEXECUTING, NOT MERELY PRESENT. Resolution alone would prove the name exists, not that it names an executing witness -- the proxy-assertion failure where a present-in-source symbol is mistaken for a CI-exercised one. Calling it closes that: the cited declaration is invoked and must hold. It is cheap and hermetic to call (family_has_discriminating_red over selected_logic_sample_cutover_evidence, a constructed fixture -- the expensive emit_family path lives in a different declaration), so this does not smuggle real compute into a per-PR row.\n\nCONFIRMED OUT OF SCOPE FOR G1 rather than assumed: crisp-owl-732 answered at #7707 head that the G1 denominator is only the static HandAuthoredDocBind primary_work/additional_works rows in doc_graph_roots, so a decl_ref constructed inside a fn body is NOT censused and G1 landing green would NOT have closed this. DISSOLVE-ON: G1 widening to every structural DeclarationRef carrier via a Node-tree reader; at that point this pair is superseded as the general wall, and per the DESIGN 4b dissolution rule the evidence stays enrolled as the regression control while the bespoke machinery goes." +// THE TWO STANDING ARMS ARE ASSERTED TOGETHER ON PURPOSE. Either arm alone would pass against a +// fold that ignored its inputs and returned a constant; asserting both means no constant +// implementation survives, which is what makes the pair discriminating rather than decorative. The +// subject join is the second independent question -- a receipt naming a node identity nothing +// declares is evidence about nobody -- and its RED plants a fabricated identity so the join is +// proven capable of returning zero. That control is not hypothetical: drafting this receipt first +// transcribed the node identity as rn_2I5K7M9O1Q3S5T8V0W2X4Y7Z9A1C, one character off the declared +// rn_2I5K7M9O1Q3R6T8V0W2X4Y7Z9A1C, and the join is what catches that class. + +// THE RECEIPT'S OWN CITATION HAD TO BE PROVEN, OR THE FIX FOR DUAL REPRESENTATION REINTRODUCES THE +// STALE-CITATION CLASS AT THE POINT EVERYTHING NOW CITES (operator gap finding on gunbc#7718, +// 2026-08-03). executed_evidence is an AUTHORED DeclarationRef. #7718 witnessed the node identity +// and both standing arms but never established that the cited declaration resolves at all -- and +// this repository had just repaired seven typed DeclarationRef rows pointing at nothing. A receipt +// whose whole purpose is to be the single citable home for execution evidence must not itself carry +// an unverified citation. +// +// THE MECHANISM IS THE LANGUAGE'S OWN RESOLVER, NOT A SECOND CENSUS. This module IMPORTS +// native_selected_witness_bundle_cutover_evidence_holds. An import is resolved by the namespace +// authority, which refuses an unbound name and refuses a double-bound one, so 'resolves to EXACTLY +// ONE declaration' is discharged by compilation rather than by a fold this file would have to +// author -- construction over validation (DESIGN 5), and no fork of the G1 resolver. If the cited +// declaration is renamed or deleted, this module stops compiling; the citation cannot rot silently. +// The string equality below is what binds that compile-time fact to the AUTHORED field: if the +// receipt's module_path or decl_name drifts away from the symbol actually imported, the equality +// reds even though the import still resolves. +// +// EXECUTING, NOT MERELY PRESENT. Resolution alone would prove the name exists, not that it names an +// executing witness -- the proxy-assertion failure where a present-in-source symbol is mistaken for +// a CI-exercised one. Calling it closes that: the cited declaration is invoked and must hold. It is +// cheap and hermetic to call (family_has_discriminating_red over +// selected_logic_sample_cutover_evidence, a constructed fixture -- the expensive emit_family path +// lives in a different declaration), so this does not smuggle real compute into a per-PR row. +// +// CONFIRMED OUT OF SCOPE FOR G1 rather than assumed: crisp-owl-732 answered at #7707 head that the +// G1 denominator is only the static HandAuthoredDocBind primary_work/additional_works rows in +// doc_graph_roots, so a decl_ref constructed inside a fn body is NOT censused and G1 landing green +// would NOT have closed this. DISSOLVE-ON: G1 widening to every structural DeclarationRef carrier +// via a Node-tree reader; at that point this pair is superseded as the general wall, and per the +// DESIGN 4b dissolution rule the evidence stays enrolled as the regression control while the +// bespoke machinery goes. fn planted_receipt( identity: String, diff --git a/dag/test/claim/network_grounding_witness_test.dag b/dag/test/claim/network_grounding_witness_test.dag index 092b52667c4..2f032138702 100644 --- a/dag/test/claim/network_grounding_witness_test.dag +++ b/dag/test/claim/network_grounding_witness_test.dag @@ -1,11 +1,21 @@ module test.claim.network_grounding - data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data network_grounding_witness_home_note: String = "Consolidated green-by-execution proofs for the extdeps.network grounding leaves — the structured IPv4 address, the IpAddress/NetworkHost/SocketAddress surfaces, and the reach model. These were three witness files (ipv4_address / network_address_host / network_reach) until 2026-07-25; each was its own floor entry resolve, so consolidating them into one entry is a §6 cost-shape fix (fewer whole-tree closure resolves, zero coverage lost) — all three prove the same extdeps.network module family. The three original witness notes are preserved verbatim below." - -data ipv4_address_witness_note: String = "Green-by-execution proof for the structured IPv4 leaf (extdeps.network.ipv4), the witness the dissolution trigger dissolve_on_ipv4_address_anemic_brand requires. Proves parse recovers the four octets from wire text, render is its inverse (round-trip both ways), and — the fail-closed half — malformed input REFUSES with a typed, located Ipv4ParseError (wrong octet count, out-of-range, non-numeric), never a fabricated address. The discriminating controls are the three distinct refusal shapes: a parser that fabricated on bad input would return Ipv4Parsed and red these." +// Consolidated green-by-execution proofs for the extdeps.network grounding leaves — the structured +// IPv4 address, the IpAddress/NetworkHost/SocketAddress surfaces, and the reach model. These were +// three witness files (ipv4_address / network_address_host / network_reach) until 2026-07-25; each +// was its own floor entry resolve, so consolidating them into one entry is a §6 cost-shape fix +// (fewer whole-tree closure resolves, zero coverage lost) — all three prove the same +// extdeps.network module family. The three original witness notes are preserved verbatim below. + +// Green-by-execution proof for the structured IPv4 leaf (extdeps.network.ipv4), the witness the +// dissolution trigger dissolve_on_ipv4_address_anemic_brand requires. Proves parse recovers the +// four octets from wire text, render is its inverse (round-trip both ways), and — the fail-closed +// half — malformed input REFUSES with a typed, located Ipv4ParseError (wrong octet count, +// out-of-range, non-numeric), never a fabricated address. The discriminating controls are the three +// distinct refusal shapes: a parser that fabricated on bad input would return Ipv4Parsed and red +// these. fn ipv4_or_none(text: String) -> Ipv4Address? { match parse_ipv4_address(text: text) { @@ -69,7 +79,12 @@ test fn ipv4_valid_and_invalid_discriminate() -> Bool { } } -data network_address_host_witness_note: String = "Green-by-execution proof for the address+host leaves of extdeps/network: the IpAddress = V4 | V6 coproduct, NetworkHost = ByName | ByAddress (reusing the grounded HostName + IpAddress), and SocketAddress (reusing std.types.Port). The load-bearing control is ip_v6_render_refuses_not_fabricates: the v6 string codec is staged, so render_ip_address on a v6 value must return Absent — a parser/renderer that fabricated a v6 string would red this. Loopback is checked on both arms (127.0.0.1 and ::1) so the coproduct's two arms are both exercised." +// Green-by-execution proof for the address+host leaves of extdeps/network: the IpAddress = V4 | V6 +// coproduct, NetworkHost = ByName | ByAddress (reusing the grounded HostName + IpAddress), and +// SocketAddress (reusing std.types.Port). The load-bearing control is +// ip_v6_render_refuses_not_fabricates: the v6 string codec is staged, so render_ip_address on a v6 +// value must return Absent — a parser/renderer that fabricated a v6 string would red this. Loopback +// is checked on both arms (127.0.0.1 and ::1) so the coproduct's two arms are both exercised. fn srv2_hostname() -> HostName { HostName { @@ -130,7 +145,14 @@ test fn socket_address_pairs_host_and_port() -> Bool { sa.port == 22 && ip_address_is_v4(addr: match sa.host { HostByAddress { address: a } => a HostByName { name: _ } => ip_v4(addr: ipv4_address(octet1: 0, octet2: 0, octet3: 0, octet4: 0)) }) } -data network_reach_witness_note: String = "Green-by-execution proof for extdeps.network.reach — the network-reach model independent of shell transport. The load-bearing §5 control is fabric_tunnel_refuses_realization: FabricTunnel is the intended long-term reach that does NOT work yet, so its realizability MUST be ReachRefused{FabricTunnelNotOperational}; a model that let it fall through as realizable would red this. DirectLan and a non-empty ProxyJump are realizable; an empty-chain ProxyJump refuses by construction (a jump with no hops is a modeling error, not a direct reach). reach_target extracts the ultimate target across all three arms. Together these prove the interim srv3-via-srv2 ProxyJump is a realizable, cited config while the fabric it stands in for stays honestly refused." +// Green-by-execution proof for extdeps.network.reach — the network-reach model independent of shell +// transport. The load-bearing §5 control is fabric_tunnel_refuses_realization: FabricTunnel is the +// intended long-term reach that does NOT work yet, so its realizability MUST be +// ReachRefused{FabricTunnelNotOperational}; a model that let it fall through as realizable would +// red this. DirectLan and a non-empty ProxyJump are realizable; an empty-chain ProxyJump refuses by +// construction (a jump with no hops is a modeling error, not a direct reach). reach_target extracts +// the ultimate target across all three arms. Together these prove the interim srv3-via-srv2 +// ProxyJump is a realizable, cited config while the fabric it stands in for stays honestly refused. fn reach_srv2() -> NetworkHost { host_by_ipv4(addr: ipv4_address(octet1: 192, octet2: 168, octet3: 1, octet4: 188)) diff --git a/dag/test/claim/network_mac_witness_test.dag b/dag/test/claim/network_mac_witness_test.dag index 5243007f1f6..211e4eb9c29 100644 --- a/dag/test/claim/network_mac_witness_test.dag +++ b/dag/test/claim/network_mac_witness_test.dag @@ -12,18 +12,17 @@ import extdeps.network.mac { } // THE ROUND TRIP AND THE TWO FLAG BITS. The round trip is the standard grounding witness for a -// parsed carrier and it is asserted in both directions. The flag bits get more rows than their -// size suggests because they are the reason this module exists rather than a validated brand: a -// consumer keying a host interface needs to know whether the address it holds is BURNED IN or was -// chosen by software, and the U/L bit is the only thing that says so. +// parsed carrier, asserted in both directions. The flag bits get more rows than their size +// suggests because they are why this module exists rather than a validated brand: a consumer +// keying a host interface needs to know whether the address is BURNED IN or chosen by software, +// and the U/L bit is the only thing that says so. // -// THE INVERTED SENSE IS THE TRAP. U/L SET means LOCALLY administered -- the bit reads opposite to -// how the name sounds -- so a control fixes each direction against a concrete address rather than -// trusting the predicate to be self-evidently right. srv3's real burned-in address is used as the -// universally-administered specimen so the rows are anchored to a fact from the fleet rather than -// to an invented one. +// THE INVERTED SENSE IS THE TRAP. U/L SET means LOCALLY administered -- opposite to how the name +// sounds -- so a control fixes each direction against a concrete address rather than trusting the +// predicate. srv3's real burned-in address is the universally-administered specimen, anchoring the +// rows to a fleet fact rather than an invented one. // -// WHAT IS DELIBERATELY REFUSED: hyphen and dotted spellings. They are common in vendor output and +// WHAT IS DELIBERATELY REFUSED: hyphen and dotted spellings. They are common in vendor output; // accepting them would make the round trip untrue and erase which spelling a source produced, so // each is asserted to refuse with a NAMED cause rather than merely to fail. diff --git a/dag/test/claim/non_fold_residue_frontier_test.dag b/dag/test/claim/non_fold_residue_frontier_test.dag index 3688e6f32e5..60f826b9e9b 100644 --- a/dag/test/claim/non_fold_residue_frontier_test.dag +++ b/dag/test/claim/non_fold_residue_frontier_test.dag @@ -11,7 +11,12 @@ import std.roster_frontier { FrontierRow, PathSubject, frontier_row_well_formed, import std.dissolution { DissolutionCondition, unbound_dissolution } import std.keyed_roster { KeyedRosterBuilt, KeyedRosterBuildDuplicateKey } -data non_fold_residue_frontier_test_note: String = "GREEN: every enrolled non-fold-residue row is well-formed (nonempty subject, reason, trigger), path keys are unique via keyed_roster_build construction (lane 4), and the roster is populated. RED controls: a synthetic row with an empty trigger fails well-formedness; a synthetic duplicate path key yields KeyedRosterBuildDuplicateKey. The host-side equivalence receipt (nfr_roster_receipt: unrostered=0, stale=0 against the live corpus scan) lives in cli_run.rs nfr_tests and the always-on witness enrollment on src/v2/lens/non_fold_residue_test.dag." +// GREEN: every enrolled non-fold-residue row is well-formed (nonempty subject, reason, trigger), +// path keys are unique via keyed_roster_build construction (lane 4), and the roster is populated. +// RED controls: a synthetic row with an empty trigger fails well-formedness; a synthetic duplicate +// path key yields KeyedRosterBuildDuplicateKey. The host-side equivalence receipt +// (nfr_roster_receipt: unrostered=0, stale=0 against the live corpus scan) lives in cli_run.rs +// nfr_tests and the always-on witness enrollment on src/v2/lens/non_fold_residue_test.dag. test fn non_fold_residue_frontier_rows_well_formed_holds() -> Bool { non_fold_residue_frontier_well_formed() @@ -28,13 +33,12 @@ test fn non_fold_residue_frontier_is_populated() -> Bool { length(xs: non_fold_residue_frontier_units()) >= 100 } -// Constructs the empty condition through the NON-LITERAL path deliberately. -// The literal form `unbound_dissolution(description: "")` is now refused at -// compile (the parameter is NonEmptyStr), which is the wall. Refinement at -// non-literal positions is still deferred, so that gap is exactly what the -// downstream well-formedness guard defends -- and this control has to reach it -// through the gap in order to keep proving the guard works (DESIGN 4b(4): -// production machinery dissolves on a climb, the evidence stays enrolled). +// Constructs the empty condition through the NON-LITERAL path deliberately: the literal form +// `unbound_dissolution(description: "")` is refused at compile (the parameter is NonEmptyStr) -- +// the wall. Refinement at non-literal positions is still deferred, so that gap is exactly what the +// downstream well-formedness guard defends, and this control must reach it through the gap to keep +// proving the guard works (DESIGN 4b(4): production machinery dissolves on a climb, the evidence +// stays enrolled). fn synthetic_nonliteral_text(text: String) -> NonEmptyStr { concat(text, "") } diff --git a/dag/test/claim/normalize_retention_contract_probe_test.dag b/dag/test/claim/normalize_retention_contract_probe_test.dag index cb93bad16e8..007a576a58e 100644 --- a/dag/test/claim/normalize_retention_contract_probe_test.dag +++ b/dag/test/claim/normalize_retention_contract_probe_test.dag @@ -38,13 +38,70 @@ import gunbc.tools.frontier_ingestion_probe { reasons_contain, } -data permanent_witness_scope_note: String = "WHAT THIS WITNESS MAY ASSERT, and why the live-corpus rows are NOT here. A required witness whose success depends on the current defects continuing to exist inverts the moment the defect is repaired: it would go RED on the repair and GREEN on a regression. So the assertions below validate the STAGE CLASSIFIER, the containment-read discipline, and the roster join on specimens whose stage is a property of the specimen rather than of the frontier. The per-member live population is a revision-scoped OBSERVATION recorded in docs/plans/v2-frontend-std-ingestion-frontier-exact-head.md and reproducible from gunbc.tools.frontier_ingestion_probe, which is deliberately NOT a test module for exactly this reason. Every classifier and roster symbol is imported from that one authority rather than restated here, so the thing under test and the thing used for measurement cannot drift apart." - -data census_execution_not_enrolled_note: String = "THE CENSUS STILL DOES NOT EXECUTE HERE, and this increment did not change that — it changed what executing would COST. take_frontend_census prepares the lex rules and the parse grammar once and classifies all fifteen members through that one prepared world, instead of rebuilding the grammar per member as the previous shape did; 02_parse's own prepared_grammar_carrier_note is the authority for why that seam exists.\n\nWhat is NOT claimed: that the result now fits the per-PR fast lane. No claim below runs take_frontend_census, because doing so reads fifteen live files and builds the grammar once, and the accepted-classification path was previously measured over the five-second budget, with no span isolating which of its stages owns that cost. Preparing once removes a fifteen-times multiplier from a cost that may still exceed the budget by itself, and I have not measured the result — the local container has no claim_batch binary, so any number stated here would be invented rather than observed.\n\nSo the enrollment decision is deferred to a measurement, not to an opinion, and the arithmetic that makes it a real question is what landed. If the prepared census is still over budget, the answer is realization or materialization, not a long/ directory and not silence." - -data stage_separation_cost_note: String = "WHY TWO STAGE-SEPARATION CLAIMS ARE NOT HERE, stated rather than hidden. classify_source reaching the parser exercises the whole accepted path, and the accepted-classification path measured 5002-5003ms thread-CPU against the 5000ms fast-lane budget on CI. ATTRIBUTION CORRECTION (2026-08-12): earlier revisions of this note called that figure the cost of building dag_grammar() alone. It is not established at that grain. What was timed is a claim calling classify_source on a source that REACHES the parser, so the number covers lexing, grammar-value construction, grammar-to-Node conversion, well_formed, the five validation checks, the nullable fixed point, FIRST-set derivation, ambiguity residue construction, the prepared parse and normalize — prepare_grammar's own carrier note enumerates most of those as its contents. No nested span isolated any one of them. Naming a single step as the owner of an aggregate is the same over-precision this instrument exists to remove, and it matters practically: if preparation rather than construction dominates, #8193 already hoisted it and the remaining cost is a different repair — so an ACCEPTED claim and a PARSE claim cannot execute per-PR, while the LEX claim below can, because a lex refusal returns before any grammar is built.\n\nThey are DELETED, not relocated. Moving them under a long/ directory would remove them from per-PR discovery without giving them an executing consumer, which deletes the coverage while retaining the source — the gunbc#7762 specimen the 2026-08-04 admission ruling exists to forbid. Nothing here claims those two stages are covered.\n\nWHAT IS OWED, and to which lane: the 15-member census needs a batched or realized instrument precisely because the interpreted path also exceeds budget on the larger members. Closing the result space and reconciling the census against the roster (this increment) does not discharge that; it only means the instrument those two claims return to now has a total verdict type and a denominator to join against." - -data empty_reason_set_control_retirement_note: String = "WHERE THE EMPTY-REASON-SET RED WENT. A previous revision asserted classify_normalize_reasons(rs: []) == NORM_REASON_SET_INVALID_EMPTY, guarding the collapse in which a missing observation reads as an accepted stage. The classifier now takes NonEmptyDiagnostics, whose head field is not optional, so that input has no representation and the arm it exercised has no subject.\n\nThis is the one case where the dissolution rule's keep-the-evidence clause does not apply, and the distinction is worth being exact about: the rule preserves a discriminating control when the invalid state stays WRITABLE and a mechanism keeps it out. Here the state became unwritable, so the control cannot be authored at all — not because it was judged redundant, but because it has no input. Retaining it would require re-widening the parameter type to admit the value it tests, which is the wall itself run backwards. The class did not stop being guarded; it stopped being expressible." +// WHAT THIS WITNESS MAY ASSERT, and why the live-corpus rows are NOT here. A required witness +// whose success depends on current defects continuing to exist inverts when the defect is +// repaired: RED on the repair, GREEN on a regression. So the assertions below validate the STAGE +// CLASSIFIER, the containment-read discipline, and the roster join on specimens whose stage is a +// property of the specimen rather than of the frontier. The per-member live population is a +// revision-scoped OBSERVATION recorded in +// docs/plans/v2-frontend-std-ingestion-frontier-exact-head.md and reproducible from +// gunbc.tools.frontier_ingestion_probe, deliberately NOT a test module for exactly this reason. +// Every classifier and roster symbol is imported from that one authority rather than restated, so +// the thing under test and the thing used for measurement cannot drift apart. + +// THE CENSUS STILL DOES NOT EXECUTE HERE; this increment changed what executing would COST. +// take_frontend_census prepares the lex rules and the parse grammar once and classifies all +// fifteen members through that one prepared world, instead of rebuilding the grammar per member as +// the previous shape did; 02_parse's prepared_grammar_carrier_note is the authority for that seam. +// +// NOT claimed: that the result now fits the per-PR fast lane. No claim below runs +// take_frontend_census, because doing so reads fifteen live files and builds the grammar once, and +// the accepted-classification path was previously measured over the five-second budget, with no +// span isolating which stage owns that cost. Preparing once removes a fifteen-times multiplier +// from a cost that may still exceed the budget by itself, and I have not measured the result — the +// local container has no claim_batch binary, so any number stated here would be invented. +// +// So the enrollment decision is deferred to a measurement, not an opinion, and the arithmetic that +// makes it a real question is what landed. If the prepared census is still over budget, the +// answer is realization or materialization, not a long/ directory and not silence. + +// WHY TWO STAGE-SEPARATION CLAIMS ARE NOT HERE, stated rather than hidden. classify_source +// reaching the parser exercises the whole accepted path, and the accepted-classification path +// measured 5002-5003ms thread-CPU against the 5000ms fast-lane budget on CI. ATTRIBUTION +// CORRECTION (2026-08-12): earlier revisions called that figure the cost of building dag_grammar() +// alone. It is not established at that grain. What was timed is a claim calling classify_source on +// a source that REACHES the parser, so the number covers lexing, grammar-value construction, +// grammar-to-Node conversion, well_formed, the five validation checks, the nullable fixed point, +// FIRST-set derivation, ambiguity residue construction, the prepared parse and normalize — +// prepare_grammar's own carrier note enumerates most of those. No nested span isolated any one. +// Naming a single step as owner of an aggregate is the over-precision this instrument exists to +// remove, and it matters: if preparation rather than construction dominates, #8193 already hoisted +// it and the remaining cost is a different repair — so an ACCEPTED claim and a PARSE claim cannot +// execute per-PR, while the LEX claim below can, because a lex refusal returns before any grammar +// is built. +// +// They are DELETED, not relocated. Moving them under long/ would remove them from per-PR discovery +// without an executing consumer, deleting the coverage while retaining the source — the gunbc#7762 +// specimen the 2026-08-04 admission ruling forbids. Nothing here claims those two stages are +// covered. +// +// WHAT IS OWED, and to which lane: the 15-member census needs a batched or realized instrument +// precisely because the interpreted path also exceeds budget on the larger members. Closing the +// result space and reconciling the census against the roster (this increment) does not discharge +// that; it only means the instrument those two claims return to now has a total verdict type and +// a denominator to join against. + +// WHERE THE EMPTY-REASON-SET RED WENT. A previous revision asserted classify_normalize_reasons(rs: +// []) == NORM_REASON_SET_INVALID_EMPTY, guarding the collapse in which a missing observation reads +// as an accepted stage. The classifier now takes NonEmptyDiagnostics, whose head field is not +// optional, so that input has no representation and the arm it exercised has no subject. +// +// This is the one case where the dissolution rule's keep-the-evidence clause does not apply: the +// rule preserves a discriminating control when the invalid state stays WRITABLE and a mechanism +// keeps it out. Here the state became unwritable, so the control cannot be authored at all — not +// judged redundant, but without an input. Retaining it would require re-widening the parameter +// type to admit the value it tests, the wall itself run backwards. The class did not stop being +// guarded; it stopped being expressible. data unterminated_string_source: String = "module frontier_probe\n\ndata d: String = \"unterminated\n" @@ -63,7 +120,6 @@ fn classify_reasons(first: Symbol, rest: List) -> FrontendStage { ) } - // classify_source now returns an Outcome, because grammar preparation can refuse and that is a // fact about the world rather than about this source. The claim matches the Accepted arm // explicitly: collapsing it would let a refused preparation satisfy a claim about lexing. @@ -101,7 +157,6 @@ test fn roster_identity_separates_reordered_rows_RED() -> Bool { (c == ContentHashEqual) == false } - // The normalize classifier is exercised DIRECTLY. Testing reasons_contain alone would not stop // classify_normalize_diagnostics reverting to a head read: each pair below puts an unrelated // diagnostic FIRST, so a head read returns the wrong verdict while a containment read does not. @@ -142,7 +197,6 @@ test fn classifier_does_not_call_retention_alone_retained_RED() -> Bool { ) } - test fn containment_read_finds_reason_behind_prepended_carrier() -> Bool { reasons_contain( reasons: [ @@ -160,7 +214,6 @@ test fn containment_read_refuses_absent_reason_RED() -> Bool { ) == false } - // Every stage renders to a distinct label. frontend_stage_eq is defined over the label, so a // collision would silently make two stages compare equal and every classifier claim above would // hold for the wrong reason. @@ -180,7 +233,6 @@ test fn stage_labels_are_pairwise_distinct() -> Bool { }) } - // The roster join, exercised on SYNTHETIC observations so it never reads the live tree. The // covering direction is below; the two directions it alone accepts — a stray observation and a // doubled member — are exercised further down, because each is a census containing every roster @@ -217,7 +269,6 @@ test fn census_of_the_right_size_but_wrong_members_is_incomplete_RED() -> Bool { census_is_complete(obs: wrong) == false } - // THE TWO DIRECTIONS THE COVERING HALF ALONE ACCEPTED. Both censuses below contain every roster // member, so a per-label existence check passes on each. They are the discriminating inputs for // reconciliation, and each names its own offending label rather than reporting a bare false. @@ -257,7 +308,6 @@ test fn whole_roster_census_reconciles_exactly() -> Bool { } } - // THE DENOMINATOR'S OWN VALIDITY. The observation-side join cannot see either failure below. // A duplicated LABEL is satisfied by one observation counted once for both rows, so a roster of // fifteen rows and fourteen labels reconciles exactly against fourteen observations. A duplicated diff --git a/dag/test/claim/observation_emit_census_witness_test.dag b/dag/test/claim/observation_emit_census_witness_test.dag index 6bf33064598..6181d795949 100644 --- a/dag/test/claim/observation_emit_census_witness_test.dag +++ b/dag/test/claim/observation_emit_census_witness_test.dag @@ -32,7 +32,34 @@ import gunbc.observation_emit_census { data live_tree_disposition: LiveTreeDisposition = ReadsLiveTree -data w_required_floor_standing_note: String = "THIS SUITE IS NOT AN EXECUTING REQUIRED-FLOOR WALL, and saying so here is the point of the row: it is locally executable and discriminating, and it is DECLINED by the floor it would otherwise guard. The declaration above is honest -- this module reads the seed through filesystem_read -- and under the floor's live-tree arm every identity in a file declaring ReadsLiveTree is declined before execution, which is where the 830 in the run summary's declined_live comes from. So the roster-to-source and source-to-roster checks below have no continuous consumer; review is the only mechanism that reaches them. DO NOT RELABEL THIS MODULE TO GET IT ADMITTED: the disposition is a true statement about what the code does, and editing the declaration to change the routing is the §5 tell that a check was satisfied by editing its declaration rather than its subject. THE INCENTIVE THIS CREATES IS THE LOAD-BEARING PART, and it is inverted: the zero-target acceptance (test.claim.observation_raw_print_retirement_acceptance_test) declares SubstrateInputsOnly, DOES execute on the required floor, and asks only whether observation_emit_frontier_count is zero -- so deleting a roster row moves the executing metric TOWARD green while the only check that could object is declined. That is not hypothetical: on 2026-08-22 a live roster row was deleted on a false premise, the frontier count improved, CI stayed green, and the row was recovered by review rather than by any wall. The deeper defect is that this suite's source-to-roster half is a HAND-MAINTAINED CONJUNCTION over the same roster it checks, so it cannot object to its own deletion -- removing an assertion and removing the fact it protected are one diff shape. THE DURABLE FIX IS A SOURCE-DERIVED DENOMINATOR: the seed's raw tagged emits discovered at occurrence grain from syntax (never a string-literal grep, which cannot tell an emit from a comment or a retired example), reconciled against the roster as an exact identity join reporting live-but-unrostered, rostered-but-absent and duplicates SIMULTANEOUSLY, so one removed row and one duplicated row cannot cancel; and the zero-target acceptance consuming that reconciliation rather than the roster's own count. Both are unbuilt. NEXT-RUNG TRIGGER: the floor's live-tree decline arm is deleted at the root (v2.workflow.required_floor carries that deletion trigger and its 782-site cost measurement), after which this suite executes and the standing recorded here is rewritten in one pass rather than amended. Until then this class sits at MITIGATABLE and its rung is declared here rather than left to be inferred from the suite's existence." +// THIS SUITE IS NOT AN EXECUTING REQUIRED-FLOOR WALL, and saying so here is the point of the row: +// it is locally executable and discriminating, and it is DECLINED by the floor it would otherwise +// guard. The declaration above is honest -- this module reads the seed through filesystem_read -- +// and under the floor's live-tree arm every identity in a file declaring ReadsLiveTree is declined +// before execution, which is where the 830 in the run summary's declined_live comes from. So the +// roster-to-source and source-to-roster checks below have no continuous consumer; review is the +// only mechanism that reaches them. DO NOT RELABEL THIS MODULE TO GET IT ADMITTED: the disposition +// is a true statement about what the code does, and editing the declaration to change the routing +// is the §5 tell that a check was satisfied by editing its declaration rather than its subject. THE +// INCENTIVE THIS CREATES IS THE LOAD-BEARING PART, and it is inverted: the zero-target acceptance +// (test.claim.observation_raw_print_retirement_acceptance_test) declares SubstrateInputsOnly, DOES +// execute on the required floor, and asks only whether observation_emit_frontier_count is zero -- +// so deleting a roster row moves the executing metric TOWARD green while the only check that could +// object is declined. That is not hypothetical: on 2026-08-22 a live roster row was deleted on a +// false premise, the frontier count improved, CI stayed green, and the row was recovered by review +// rather than by any wall. The deeper defect is that this suite's source-to-roster half is a +// HAND-MAINTAINED CONJUNCTION over the same roster it checks, so it cannot object to its own +// deletion -- removing an assertion and removing the fact it protected are one diff shape. THE +// DURABLE FIX IS A SOURCE-DERIVED DENOMINATOR: the seed's raw tagged emits discovered at occurrence +// grain from syntax (never a string-literal grep, which cannot tell an emit from a comment or a +// retired example), reconciled against the roster as an exact identity join reporting +// live-but-unrostered, rostered-but-absent and duplicates SIMULTANEOUSLY, so one removed row and +// one duplicated row cannot cancel; and the zero-target acceptance consuming that reconciliation +// rather than the roster's own count. Both are unbuilt. NEXT-RUNG TRIGGER: the floor's live-tree +// decline arm is deleted at the root (v2.workflow.required_floor carries that deletion trigger and +// its 782-site cost measurement), after which this suite executes and the standing recorded here is +// rewritten in one pass rather than amended. Until then this class sits at MITIGATABLE and its rung +// is declared here rather than left to be inferred from the suite's existence. data witness_note: String = "P3 census hygiene, executable against the live seed (docs/plans/progress-observation-design.md section 5). A census that is not checked against the code it censuses is coverage-by-illusion — an inert lens is itself a lie. So every rostered marker is held against the SEED (seed_emit_sources, folded): a marker that has vanished from every seed source reds (the roster went stale, the site was renamed or deleted without re-census), and a frontier row must carry a real, non-empty dissolve-on so the debt stays prioritizable rather than open-ended. Migrated sites keep their marker strings so the roster cannot go stale, and each has a RED that the raw byte shape is gone from the seed." @@ -41,7 +68,14 @@ fn census_source(path: String) -> String { r.content } -data seed_search_note: String = "PRESENCE IS ASKED OF THE SEED, NOT OF ONE FILE. Every check below folds seed_emit_sources, so a marker that MOVES between seed files is still present and a marker that LEAVES the seed is absent -- which is the question the census actually asks. The per-row source_file pin this replaced answered `did the code move`, and on 2026-08-26 it answered it five times at once for #9228's claim_executor shrink, of which one was a real census event and four were noise. The seed-set fold is fail-closed on its own denominator: w_every_seed_emit_source_reads_non_empty below reds if any listed source stops reading non-empty, so a path that ceases to exist cannot quietly contribute nothing to a search that then reports absence." +// PRESENCE IS ASKED OF THE SEED, NOT OF ONE FILE. Every check below folds seed_emit_sources, so a +// marker that MOVES between seed files is still present and a marker that LEAVES the seed is absent +// -- which is the question the census actually asks. The per-row source_file pin this replaced +// answered `did the code move`, and on 2026-08-26 it answered it five times at once for #9228's +// claim_executor shrink, of which one was a real census event and four were noise. The seed-set +// fold is fail-closed on its own denominator: w_every_seed_emit_source_reads_non_empty below reds +// if any listed source stops reading non-empty, so a path that ceases to exist cannot quietly +// contribute nothing to a search that then reports absence. fn seed_marker_present(marker: String) -> Bool { fold(seed_emit_sources, init: false, f: (acc, path) => @@ -133,8 +167,51 @@ test fn w_witness_claim_result_has_migrated() -> Bool { string_contains(s: emit_site_dissolve_on(site: witness_claim_result_site), pattern: "render_witness_claim_result_text_mirror") } - -data w_post_snapshot_live_tags_are_rostered_bidirectional_note: String = "Operator finding 3 (run 30142403230): hygiene is bidirectional — growth tags born after the initial census snapshot must appear on the roster, not only the reverse (rostered markers still exist). Extended for #7205 resolve/assembly split tags. It covered #7284's witness-row-cost and witness-row-cost-drift and the migration-disclosure gate's own [witness-row-cost-migration-disclosure] marker. On 2026-08-22 the batch-fed materialization was deleted at the root and witness-row-cost-drift and witness-row-cost-migration-disclosure went with it, so those two rows are gone. WITNESS-ROW-COST DID NOT GO, and this file is the receipt for why that matters: its assertion was removed in that same change on the premise that the marker was gone, and live refusals survive on a path with production callers (the symbol that sentence named, `claim_executor discovery_claim_result`, resolves to nothing and was fabricated; the emits are the witness_cost_* helpers in cli_run.rs, corrected 2026-08-26). The assertion is restored above. The removal was reviewed and the review agreed the marker was gone -- so the only mechanism that could have caught it was this conjunction, which the same diff had deleted. That is the sharpest possible illustration of the gap this note already describes: a hand-maintained conjunction cannot object to its own deletion, so removing an assertion and removing the fact it protected look identical in the diff. The durable fix is unchanged and is now better motivated -- a source-level census that DISCOVERS print markers in the seed and joins them against the roster would have refused this edit without anyone remembering the tag.\n\nA [compile-clean-cost-drift] row was added here on 2026-08-11 and RETIRED hours later in the same lane, when that tag's emit was deleted outright rather than gated — so the row is gone and this list is shorter, not longer. The WAY the hole was found is still the finding: it was not caught by this test, because a manually enumerated conjunction can only assert the rows somebody remembered to write down. [compile-clean-cost-drift] and [compile-clean-cost] had been live in the seed and absent from the roster since they were introduced, so the bidirectional rule was stated but not enforced for them — an unrostered tag is invisible to a check whose subject list IS the roster. That makes this test's own shape the residue: the durable fix is a source-level census that DISCOVERS print markers in the seed and joins them against the roster, at which point a new tag cannot escape by not being remembered. Until that lands, this conjunction is a hand-maintained approximation of a discovery it cannot perform, and every row added to it is evidence of the gap rather than closure of it.\n\nTWO ROWS WERE ADDED ON 2026-08-26 -- floor_heartbeat_site and floor_claim_memory_site -- and by that rule they are evidence, not closure. They are the raw successors to the RETIRED [floor-memory] MIGRATION, and the census could not see them: it noticed floor-memory's marker was gone, which is equally consistent with a retirement and with a projection being deleted and replaced by raw emits under new names. It was the second. NOTHING HERE ASKED THE QUESTION THAT DISTINGUISHES THEM -- what now does that job -- and nothing here can, because the successor's tag was not on the roster and the roster is this check's entire subject list. That is the same hole this note already records for [compile-clean-cost], arriving in its most expensive form: not a new family escaping enrolment, but a MIGRATED row silently reverting. gunbc.observation_emit_census observation_emit_roster_understatement_finding measures the standing gap and names its next-rung trigger, which is a substrate capability rather than effort -- the interpreter registers string_contains and string_length and nothing that can enumerate occurrences." +// Operator finding 3 (run 30142403230): hygiene is bidirectional — growth tags born after the +// initial census snapshot must appear on the roster, not only the reverse (rostered markers still +// exist). Extended for #7205 resolve/assembly split tags. It covered #7284's witness-row-cost and +// witness-row-cost-drift and the migration-disclosure gate's own +// [witness-row-cost-migration-disclosure] marker. On 2026-08-22 the batch-fed materialization was +// deleted at the root and witness-row-cost-drift and witness-row-cost-migration-disclosure went +// with it, so those two rows are gone. WITNESS-ROW-COST DID NOT GO, and this file is the receipt +// for why that matters: its assertion was removed in that same change on the premise that the +// marker was gone, and live refusals survive on a path with production callers (the symbol that +// sentence named, `claim_executor discovery_claim_result`, resolves to nothing and was fabricated; +// the emits are the witness_cost_* helpers in cli_run.rs, corrected 2026-08-26). The assertion is +// restored above. The removal was reviewed and the review agreed the marker was gone -- so the only +// mechanism that could have caught it was this conjunction, which the same diff had deleted. That +// is the sharpest possible illustration of the gap this note already describes: a hand-maintained +// conjunction cannot object to its own deletion, so removing an assertion and removing the fact it +// protected look identical in the diff. The durable fix is unchanged and is now better motivated -- +// a source-level census that DISCOVERS print markers in the seed and joins them against the roster +// would have refused this edit without anyone remembering the tag. +// +// A [compile-clean-cost-drift] row was added here on 2026-08-11 and RETIRED hours later in the same +// lane, when that tag's emit was deleted outright rather than gated — so the row is gone and this +// list is shorter, not longer. The WAY the hole was found is still the finding: it was not caught +// by this test, because a manually enumerated conjunction can only assert the rows somebody +// remembered to write down. [compile-clean-cost-drift] and [compile-clean-cost] had been live in +// the seed and absent from the roster since they were introduced, so the bidirectional rule was +// stated but not enforced for them — an unrostered tag is invisible to a check whose subject list +// IS the roster. That makes this test's own shape the residue: the durable fix is a source-level +// census that DISCOVERS print markers in the seed and joins them against the roster, at which point +// a new tag cannot escape by not being remembered. Until that lands, this conjunction is a +// hand-maintained approximation of a discovery it cannot perform, and every row added to it is +// evidence of the gap rather than closure of it. +// +// TWO ROWS WERE ADDED ON 2026-08-26 -- floor_heartbeat_site and floor_claim_memory_site -- and by +// that rule they are evidence, not closure. They are the raw successors to the RETIRED +// [floor-memory] MIGRATION, and the census could not see them: it noticed floor-memory's marker was +// gone, which is equally consistent with a retirement and with a projection being deleted and +// replaced by raw emits under new names. It was the second. NOTHING HERE ASKED THE QUESTION THAT +// DISTINGUISHES THEM -- what now does that job -- and nothing here can, because the successor's tag +// was not on the roster and the roster is this check's entire subject list. That is the same hole +// this note already records for [compile-clean-cost], arriving in its most expensive form: not a +// new family escaping enrolment, but a MIGRATED row silently reverting. +// gunbc.observation_emit_census observation_emit_roster_understatement_finding measures the +// standing gap and names its next-rung trigger, which is a substrate capability rather than effort +// -- the interpreter registers string_contains and string_length and nothing that can enumerate +// occurrences. test fn w_post_snapshot_live_tags_are_rostered_bidirectional() -> Bool { census_marker_present(site: floor_heartbeat_site) && @@ -161,11 +238,50 @@ test fn w_the_floor_heartbeat_projection_is_absent_from_the_seed() -> Bool { seed_marker_present(marker: "[floor-heartbeat]") } -data w_floor_heartbeat_probe_note: String = "THE DISCRIMINATING PROBE FOR THE REVERSAL, and it is stated as three conjuncts because two of them alone are the trap. `[floor-memory]` absent and `render_heartbeat_line_mirror` absent are equally true of a retirement and of a regression; only the third conjunct -- a raw successor emitting in the seed -- tells them apart. THIS PROBE IS EXPECTED TO GO RED WHEN THE DEBT IS PAID, and that is its design rather than a defect: when the heartbeat projection is restored, seed_marker_absent(render_heartbeat_line_mirror) goes false and this probe reds, forcing the reclassification of floor_heartbeat_site and floor_claim_memory_site in the same change. A probe whose green means `the regression is still here` must red when it stops being here, or it is a decoration that outlives its subject -- which is exactly what the deleted floor-memory raw-shape probe became. THE MIRROR CONJUNCT ASKS FOR THE CALL FORM -- `render_heartbeat_line_mirror(` WITH THE OPEN PAREN -- AND THAT IS NOT COSMETIC, IT IS THIS PROBE'S OWN LIMITATION CAUGHT BY EXECUTION. Written against the bare name it returned false, because cli_run.rs still carries one doc comment naming the deleted mirror in backticks. A substring test cannot tell a call from a mention, which is the same limitation this suite's residue note already states in general; the open paren is the cheapest available approximation of `a call site, not a mention`, and it is an approximation rather than a fix. It fails in the direction that reds rather than greens if the corpus ever writes the name followed by a paren in prose, which is the right direction for a probe. THE FIRST DRAFT OF THIS PROBE WAS GREEN BY SHELL GREP OVER src/ AND RED WHEN EXECUTED, and the difference was entirely the denominator: src/ excludes nothing, seed_emit_sources includes cli_run.rs where the comment lives. A measurement taken with a different instrument than the check runs is not evidence about the check." - -data w_floor_memory_raw_shape_test_deleted_note: String = "w_the_raw_byte_dump_shape_is_gone_from_the_seed WAS HERE AND IS DELETED WITH ITS SUBJECT (2026-08-26). It asserted the floor-memory heartbeat's raw byte shape was gone from claim_executor AND that render_heartbeat_line_mirror was present there -- the migrated row's evidence that a projection had replaced a dump. #9228 deleted both: measured across all of src/, there is no [floor-memory] occurrence and no render_heartbeat_line_mirror occurrence, only one doc comment naming the mirror. So the negative half is now vacuously true and the positive half is false, and neither states anything about a site that exists. THIS IS NOT THE §4b(4) CASE THAT KEEPS EVIDENCE AFTER A CLIMB: nothing climbed. The site left the seed, so there is no rung to hold and no production machinery whose dissolution this evidence would witness -- keeping a probe over a deleted subject is a permanently-green decoration, which is the failure §4b names as worse than absent." - -data w_raw_shape_scope_note: String = "THE TWO HALVES OF A RAW-SHAPE PROBE HAVE DIFFERENT SCOPES, AND CONFLATING THEM IS WHAT ROTTED. The POSITIVE half -- the mirror function that carries the projection -- is a fact about the SEED: which file holds it is not a census fact, and pinning it to one file is what went false when #9228 moved claim_executor's contents. Those are folded over seed_emit_sources. The NEGATIVE half is not always seed-wide, and this is measured rather than assumed: `t_ms=`, `current={}` and `bytes (VmHWM)` are substrings that occur in unrelated live emits elsewhere in the seed (4, 3 and 2 occurrences respectively), so widening them would manufacture false reds. Those negatives stay scoped to the file whose raw shape they describe, and a negative that IS unambiguous seed-wide (a full bracket-tagged prefix) is folded. The rule: a negative is widened only when its pattern is specific enough to name one shape." +// THE DISCRIMINATING PROBE FOR THE REVERSAL, and it is stated as three conjuncts because two of +// them alone are the trap. `[floor-memory]` absent and `render_heartbeat_line_mirror` absent are +// equally true of a retirement and of a regression; only the third conjunct -- a raw successor +// emitting in the seed -- tells them apart. THIS PROBE IS EXPECTED TO GO RED WHEN THE DEBT IS PAID, +// and that is its design rather than a defect: when the heartbeat projection is restored, +// seed_marker_absent(render_heartbeat_line_mirror) goes false and this probe reds, forcing the +// reclassification of floor_heartbeat_site and floor_claim_memory_site in the same change. A probe +// whose green means `the regression is still here` must red when it stops being here, or it is a +// decoration that outlives its subject -- which is exactly what the deleted floor-memory raw-shape +// probe became. THE MIRROR CONJUNCT ASKS FOR THE CALL FORM -- `render_heartbeat_line_mirror(` WITH +// THE OPEN PAREN -- AND THAT IS NOT COSMETIC, IT IS THIS PROBE'S OWN LIMITATION CAUGHT BY +// EXECUTION. Written against the bare name it returned false, because cli_run.rs still carries one +// doc comment naming the deleted mirror in backticks. A substring test cannot tell a call from a +// mention, which is the same limitation this suite's residue note already states in general; the +// open paren is the cheapest available approximation of `a call site, not a mention`, and it is an +// approximation rather than a fix. It fails in the direction that reds rather than greens if the +// corpus ever writes the name followed by a paren in prose, which is the right direction for a +// probe. THE FIRST DRAFT OF THIS PROBE WAS GREEN BY SHELL GREP OVER src/ AND RED WHEN EXECUTED, and +// the difference was entirely the denominator: src/ excludes nothing, seed_emit_sources includes +// cli_run.rs where the comment lives. A measurement taken with a different instrument than the +// check runs is not evidence about the check. + +// w_the_raw_byte_dump_shape_is_gone_from_the_seed WAS HERE AND IS DELETED WITH ITS SUBJECT +// (2026-08-26). It asserted the floor-memory heartbeat's raw byte shape was gone from +// claim_executor AND that render_heartbeat_line_mirror was present there -- the migrated row's +// evidence that a projection had replaced a dump. #9228 deleted both: measured across all of src/, +// there is no [floor-memory] occurrence and no render_heartbeat_line_mirror occurrence, only one +// doc comment naming the mirror. So the negative half is now vacuously true and the positive half +// is false, and neither states anything about a site that exists. THIS IS NOT THE §4b(4) CASE THAT +// KEEPS EVIDENCE AFTER A CLIMB: nothing climbed. The site left the seed, so there is no rung to +// hold and no production machinery whose dissolution this evidence would witness -- keeping a probe +// over a deleted subject is a permanently-green decoration, which is the failure §4b names as worse +// than absent. + +// THE TWO HALVES OF A RAW-SHAPE PROBE HAVE DIFFERENT SCOPES, AND CONFLATING THEM IS WHAT ROTTED. +// The POSITIVE half -- the mirror function that carries the projection -- is a fact about the SEED: +// which file holds it is not a census fact, and pinning it to one file is what went false when +// #9228 moved claim_executor's contents. Those are folded over seed_emit_sources. The NEGATIVE half +// is not always seed-wide, and this is measured rather than assumed: `t_ms=`, `current={}` and +// `bytes (VmHWM)` are substrings that occur in unrelated live emits elsewhere in the seed (4, 3 and +// 2 occurrences respectively), so widening them would manufacture false reds. Those negatives stay +// scoped to the file whose raw shape they describe, and a negative that IS unambiguous seed-wide (a +// full bracket-tagged prefix) is folded. The rule: a negative is widened only when its pattern is +// specific enough to name one shape. test fn w_the_raw_gantt_shape_is_gone_from_the_seed() -> Bool { let rt = census_source(path: "src/v1/stage0/src/v1_rt.rs") diff --git a/dag/test/claim/observation_raw_print_retirement_acceptance_test.dag b/dag/test/claim/observation_raw_print_retirement_acceptance_test.dag index a83b11cb4fa..6a56b088a3a 100644 --- a/dag/test/claim/observation_raw_print_retirement_acceptance_test.dag +++ b/dag/test/claim/observation_raw_print_retirement_acceptance_test.dag @@ -7,7 +7,63 @@ import v2.std.live_tree { LiveTreeDisposition, SubstrateInputsOnly } data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data acceptance_witness_note: String = "THE ACCEPTANCE TEST FOR observation-raw-print-retirement, and it is RED ON PURPOSE — enrolled QuarantineProbeExpectRed, which is the cadence for exactly this: a known-red row whose greening is a counted un-quarantine event. It is not a broken witness and it must not be 'fixed' by relaxing the assertion; the only edit that may turn it green is migrating the emit sites it counts.\n\nWhat it asserts is that node's own handback verbatim — 'the classified zero-residue progress census'. gunbc.observation_emit_census classifies every seed emit site as exactly one of MigratedToObservation or CountedFrontierSite (a closed sum, so a site cannot be half-classified), and observation_emit_frontier_count is the population of the second arm. The roster shrank by ONE on 2026-08-22 when the batch-fed witness-cost materialization was deleted at the root: witness-row-cost-migration-disclosure is GONE, because its emit site is gone, not because it was reclassified. THIS SENTENCE SAID TWO AND NAMED witness-row-cost AS THE OTHER, and it was wrong: live [witness-row-cost] refusals survive on a path with production callers, so that family is still on the roster and still counted. (IT GROUNDED THEM ON `claim_executor discovery_claim_result`, A SYMBOL THAT RESOLVES TO NOTHING -- fabricated in gunbc.observation_emit_census on 2026-08-22 and copied here, so one invented citation became two files' evidence; the emits are the witness_cost_* helpers in cli_run.rs, corrected 2026-08-26.) THE FRONTIER MARKERS ARE NOT ENUMERATED HERE, and the deletion of that enumeration is this note's own rule applied to itself for the third time: the list that stood here went stale AGAIN on 2026-08-26, when floor-memory's projection was found deleted from the seed with raw [floor-heartbeat] and [floor-claim-memory] emits doing its job, adding two frontier rows this sentence did not know about. observation_emit_roster names them and observation_emit_frontier_count folds it; a recital here is the second naming scheme, and it has now rotted every time it has been written. selection-degradation was named here as a frontier marker and is NOT one -- it has no emit in the seed and has never been on the roster, so this enumeration was carrying a family that does not exist alongside a count computed from families that do. THIS ENUMERATION IS DELIBERATELY NOT RESTATED AS A NUMBER: the paragraph below records that this list once went false while the count beside it stayed correct, so writing the count here again would rebuild the exact trap it warns about -- observation_emit_frontier_count folds the roster and is the only authority for how many there are. ENUMERATION CORRECTED 2026-08-11 (review 51078), and the shape of the error is the reason it is worth recording rather than quietly fixing: this list previously named gate-warm-cost and witness-row-cost-drift, whose emits were deleted when the receipts gained an artifact transport, and omitted witness-row-cost-migration-disclosure and selection-degradation, which were on the roster. Two wrong, two missing — so the COUNT stayed 8 and was still correct while the enumeration beside it had become false. A count-based check cannot catch that; only a join between this prose and the roster can, which is the same source-level marker census observation_emit_census_witness_test names as its own residue. Zero is the ticket being finished, so the count IS the completion condition rather than a proxy for it, and every site migrated moves it monotonically toward green.\n\nWhy it exists as a separate row rather than an assertion inside observation_emit_census_witness_test: that suite states what the census HOLDS -- that every rostered marker still exists in the seed it names, that every frontier row carries a real dissolve-on, and that the classification is bidirectional -- while this one states what the WORK OWES (== 0). THE `== 8` RECITAL THAT STOOD HERE IS DELETED, and its failure mode is the one this row already warns about, arriving from the other side: the paragraph above records an enumeration going false while the count beside it stayed right, and this sentence was the mirror -- a count recited as `a fact about today` that outlived both the population it named AND the assertion it attributed to that suite, since the frontier assertions were removed from the census witness when the two batch-fed sites retired (2026-08-22). A recital of another file's assertion is a second, positional naming of something that file already states; there is no count here to correct, because observation_emit_frontier_count folds the roster and is the only authority for how many there are. Both are true statements and they disagree by construction — putting them in one file would force the roster's own hygiene check into the same quarantine as an unfinished deliverable, which would stop the roster from reding when it should." +// THE ACCEPTANCE TEST FOR observation-raw-print-retirement, and it is RED ON PURPOSE — enrolled +// QuarantineProbeExpectRed, which is the cadence for exactly this: a known-red row whose greening +// is a counted un-quarantine event. It is not a broken witness and it must not be 'fixed' by +// relaxing the assertion; the only edit that may turn it green is migrating the emit sites it +// counts. +// +// What it asserts is that node's own handback verbatim — 'the classified zero-residue progress +// census'. gunbc.observation_emit_census classifies every seed emit site as exactly one of +// MigratedToObservation or CountedFrontierSite (a closed sum, so a site cannot be half-classified), +// and observation_emit_frontier_count is the population of the second arm. The roster shrank by ONE +// on 2026-08-22 when the batch-fed witness-cost materialization was deleted at the root: +// witness-row-cost-migration-disclosure is GONE, because its emit site is gone, not because it was +// reclassified. THIS SENTENCE SAID TWO AND NAMED witness-row-cost AS THE OTHER, and it was wrong: +// live [witness-row-cost] refusals survive on a path with production callers, so that family is +// still on the roster and still counted. (IT GROUNDED THEM ON `claim_executor +// discovery_claim_result`, A SYMBOL THAT RESOLVES TO NOTHING -- fabricated in +// gunbc.observation_emit_census on 2026-08-22 and copied here, so one invented citation became two +// files' evidence; the emits are the witness_cost_* helpers in cli_run.rs, corrected 2026-08-26.) +// THE FRONTIER MARKERS ARE NOT ENUMERATED HERE, and the deletion of that enumeration is this note's +// own rule applied to itself for the third time: the list that stood here went stale AGAIN on +// 2026-08-26, when floor-memory's projection was found deleted from the seed with raw +// [floor-heartbeat] and [floor-claim-memory] emits doing its job, adding two frontier rows this +// sentence did not know about. observation_emit_roster names them and +// observation_emit_frontier_count folds it; a recital here is the second naming scheme, and it has +// now rotted every time it has been written. selection-degradation was named here as a frontier +// marker and is NOT one -- it has no emit in the seed and has never been on the roster, so this +// enumeration was carrying a family that does not exist alongside a count computed from families +// that do. THIS ENUMERATION IS DELIBERATELY NOT RESTATED AS A NUMBER: the paragraph below records +// that this list once went false while the count beside it stayed correct, so writing the count +// here again would rebuild the exact trap it warns about -- observation_emit_frontier_count folds +// the roster and is the only authority for how many there are. ENUMERATION CORRECTED 2026-08-11 +// (review 51078), and the shape of the error is the reason it is worth recording rather than +// quietly fixing: this list previously named gate-warm-cost and witness-row-cost-drift, whose emits +// were deleted when the receipts gained an artifact transport, and omitted +// witness-row-cost-migration-disclosure and selection-degradation, which were on the roster. Two +// wrong, two missing — so the COUNT stayed 8 and was still correct while the enumeration beside it +// had become false. A count-based check cannot catch that; only a join between this prose and the +// roster can, which is the same source-level marker census observation_emit_census_witness_test +// names as its own residue. Zero is the ticket being finished, so the count IS the completion +// condition rather than a proxy for it, and every site migrated moves it monotonically toward +// green. +// +// Why it exists as a separate row rather than an assertion inside +// observation_emit_census_witness_test: that suite states what the census HOLDS -- that every +// rostered marker still exists in the seed it names, that every frontier row carries a real +// dissolve-on, and that the classification is bidirectional -- while this one states what the WORK +// OWES (== 0). THE `== 8` RECITAL THAT STOOD HERE IS DELETED, and its failure mode is the one this +// row already warns about, arriving from the other side: the paragraph above records an enumeration +// going false while the count beside it stayed right, and this sentence was the mirror -- a count +// recited as `a fact about today` that outlived both the population it named AND the assertion it +// attributed to that suite, since the frontier assertions were removed from the census witness when +// the two batch-fed sites retired (2026-08-22). A recital of another file's assertion is a second, +// positional naming of something that file already states; there is no count here to correct, +// because observation_emit_frontier_count folds the roster and is the only authority for how many +// there are. Both are true statements and they disagree by construction — putting them in one file +// would force the roster's own hygiene check into the same quarantine as an unfinished deliverable, +// which would stop the roster from reding when it should. data acceptance_dissolution_note: String = "DISSOLVES BY GREENING, not by deletion. When the frontier reaches zero this witness passes and its QuarantineProbeExpectRed row in gunbc.ci_layer_roots.witness_exclusion_frontier becomes wrong — a still-red expectation against a green witness — so the un-quarantine is forced rather than optional: the roster row must be removed in the same change that lands the last migration, and the witness then joins ordinary DiscoverySelection as a standing ratchet against regression. That is the counted un-quarantine event the admission authority describes." diff --git a/dag/test/claim/observation_rollup_witness_test.dag b/dag/test/claim/observation_rollup_witness_test.dag index c212ae2e879..110d79911a0 100644 --- a/dag/test/claim/observation_rollup_witness_test.dag +++ b/dag/test/claim/observation_rollup_witness_test.dag @@ -24,7 +24,14 @@ import v2.std.live_tree { LiveTreeDisposition, SubstrateInputsOnly } data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data rollup_witness_home_doc: String = "S1 of the display-grain lane: the fold that accumulates routine leaf events into their ancestor at a declared grain, so a batch emits one conclusion instead of one line per witness. These claims pin the two properties the fold exists for and the two it must NOT have. What it exists for: routine and anomaly classes both COUNT (a summary claiming `0 failed` is only trustworthy if failures were tallied on the same pass), and the ancestor is located by the containment path rather than by a second taxonomy. What it must not have: an event outside the rollup's subject is REFUSED rather than folded (which would inflate a batch with foreign work) or dropped (which would report an incomplete total as if it were complete), and a subject with no segment at the requested grain answers Absent rather than substituting the root." +// S1 of the display-grain lane: the fold that accumulates routine leaf events into their ancestor +// at a declared grain, so a batch emits one conclusion instead of one line per witness. These +// claims pin what the fold exists for and what it must NOT do. Exists for: routine and anomaly +// classes both COUNT (a `0 failed` summary is trustworthy only if failures were tallied on the same +// pass), and the ancestor is located by containment path, not a second taxonomy. Must not: an event +// outside the rollup's subject is REFUSED, neither folded (inflating a batch with foreign work) nor +// dropped (reporting an incomplete total as complete); a subject with no segment at the requested +// grain answers Absent rather than substituting the root. fn batch_subject() -> ObservationSubject { ObservationSubject { diff --git a/dag/test/claim/occurrence_binding_candidates_witness_test.dag b/dag/test/claim/occurrence_binding_candidates_witness_test.dag index 747be3fc9d5..5ea93d53829 100644 --- a/dag/test/claim/occurrence_binding_candidates_witness_test.dag +++ b/dag/test/claim/occurrence_binding_candidates_witness_test.dag @@ -198,7 +198,12 @@ fn obc_fixture_reference( } } -data occurrence_binding_candidates_witness_module_note: String = "Module rule 1 fixture: two module-level functions declared as direct siblings (neither's occurrence id is an ancestor of the other's body) inside one module. fn_a = 10, fn_b's call-site reference to fn_a = 30, both rows carrying module_path \"app.sibling_module\". The reference's own containment ancestors are just fn_b's own occurrence (20) -- there is no lexical nesting between fn_a and the reference at all, so occurrence_containment_path_is_prefix_of alone can never expose fn_a to it; only the module-sibling rule can." +// Module rule 1 fixture: two module-level functions declared as direct siblings (neither's +// occurrence id is an ancestor of the other's body) inside one module. fn_a = 10, fn_b's call-site +// reference to fn_a = 30, both rows carrying module_path "app.sibling_module". The reference's own +// containment ancestors are just fn_b's own occurrence (20) -- there is no lexical nesting between +// fn_a and the reference at all, so occurrence_containment_path_is_prefix_of alone can never expose +// fn_a to it; only the module-sibling rule can. fn obc_module_sibling_transport() -> OccurrenceTransport { let fn_a = OccurrenceId { value: 10 } @@ -267,7 +272,13 @@ test fn module_scope_sibling_is_visible_holds() -> Bool { } } -data occurrence_binding_candidates_witness_sibling_arm_note: String = "Rule 2 fixture: match arm 1 binds pattern variable y at occurrence 11 under containment ancestors [1, 2] (module=1, arm1=2); arm 2 binds a distinct y at occurrence 12 under ancestors [1, 3] (arm2=3) and its body references y at occurrence 21 under ancestors [1, 3, 12] (nested inside arm2's own pattern scope). Both binders are LexicalValueOccurrence, so the module-sibling rule never admits either; only occurrence 12 is a genuine containment ancestor of the reference, so occurrence 11 (the sibling arm's binder) must never appear in the exposed population despite identical spelling." +// Rule 2 fixture: match arm 1 binds pattern variable y at occurrence 11 under containment ancestors +// [1, 2] (module=1, arm1=2); arm 2 binds a distinct y at occurrence 12 under ancestors [1, 3] +// (arm2=3) and its body references y at occurrence 21 under ancestors [1, 3, 12] (nested inside +// arm2's own pattern scope). Both binders are LexicalValueOccurrence, so the module-sibling rule +// never admits either; only occurrence 12 is a genuine containment ancestor of the reference, so +// occurrence 11 (the sibling arm's binder) must never appear in the exposed population despite +// identical spelling. fn obc_sibling_arm_transport() -> OccurrenceTransport { let module_id = OccurrenceId { value: 1 } @@ -347,7 +358,10 @@ test fn sibling_match_arm_not_visible_holds() -> Bool { } } -data occurrence_binding_candidates_witness_nested_lexical_note: String = "Rule 3 fixture: a let binder x at occurrence 41 nests a body under it (ancestors include 41); a reference to x sitting OUTSIDE that let's subtree (occurrence 51, ancestors just [module]) must see zero candidates -- containment enclosure only reaches descendants of the let, never siblings of it, and x's LexicalValueOccurrence category earns it no module-sibling exposure either." +// Rule 3 fixture: a let binder x at occurrence 41 nests a body under it (ancestors include 41); a +// reference to x sitting OUTSIDE that let's subtree (occurrence 51, ancestors just [module]) must +// see zero candidates -- containment enclosure only reaches descendants of the let, never siblings +// of it, and x's LexicalValueOccurrence category earns it no module-sibling exposure either. fn obc_nested_lexical_transport() -> OccurrenceTransport { let module_id = OccurrenceId { value: 4 } @@ -410,7 +424,10 @@ test fn nested_lexical_only_inside_scope_holds() -> Bool { } } -data occurrence_binding_candidates_witness_source_order_note: String = "Rule 4 fixture: fn_later is declared AFTER the reference in authored source order (ordinal 70 > ordinal 60), both ModuleExposure in the same module. AuthoredTokenOrdinal comparison must keep fn_later out of the candidate population even when it is otherwise an eligible module sibling, so the reference is Unbound." +// Rule 4 fixture: fn_later is declared AFTER the reference in authored source order (ordinal 70 > +// ordinal 60), both ModuleExposure in the same module. AuthoredTokenOrdinal comparison must keep +// fn_later out of the candidate population even when it is otherwise an eligible module sibling, so +// the reference is Unbound. fn obc_source_order_inputs() -> OccurrenceBindingCandidateInputs { obc_fixture_inputs( @@ -468,7 +485,10 @@ test fn declaration_below_occurrence_not_visible_holds() -> Bool { } } -data occurrence_binding_candidates_witness_ambiguous_note: String = "Rule 5 fixture: two distinct module-level CallableOccurrence declarations named helper (occurrence 80 and 81), both declared before the reference (occurrence 90) in the same module. Same authored spelling must never collapse to one candidate -- the producer supplies both distinct OccurrenceIds and P1's fold reports OccurrenceAmbiguous." +// Rule 5 fixture: two distinct module-level CallableOccurrence declarations named helper +// (occurrence 80 and 81), both declared before the reference (occurrence 90) in the same module. +// Same authored spelling must never collapse to one candidate -- the producer supplies both +// distinct OccurrenceIds and P1's fold reports OccurrenceAmbiguous. fn obc_ambiguous_transport() -> OccurrenceTransport { let helper_a = OccurrenceId { value: 80 } @@ -533,7 +553,11 @@ test fn same_text_distinct_identities_is_ambiguous_holds() -> Bool { } } -data occurrence_binding_candidates_witness_production_note: String = "Production control: an ordinary two-function module (gunbc.example.greeter) where greet() calls format_greeting() declared earlier in the same file -- the exact shape the pre-strip prefix-only bug rejected. No authored import list participates; the candidate producer resolves the call purely from structural sibling exposure plus source order, and the resulting BoundReferenceProvider/DirectModuleDependency projections are asserted directly." +// Production control: an ordinary two-function module (gunbc.example.greeter) where greet() calls +// format_greeting() declared earlier in the same file -- the exact shape the pre-strip prefix-only +// bug rejected. No authored import list participates; the candidate producer resolves the call +// purely from structural sibling exposure plus source order, and the resulting +// BoundReferenceProvider/DirectModuleDependency projections are asserted directly. fn obc_production_transport() -> OccurrenceTransport { let format_greeting = OccurrenceId { value: 100 } @@ -602,7 +626,10 @@ test fn production_module_call_to_earlier_sibling_binds_holds() -> Bool { } } -data occurrence_binding_candidates_witness_dependency_order_note: String = "RED control: direct_module_dependencies_from_bound_population must preserve first-seen provider-traversal order for cross-module edges and must project NO same-module self-edge (BoundReferenceProvider retained; M→M omitted). A hash-ordered map readback would permute the cross-module list and turn the witness red." +// RED control: direct_module_dependencies_from_bound_population must preserve first-seen +// provider-traversal order for cross-module edges and must project NO same-module self-edge +// (BoundReferenceProvider retained; M→M omitted). A hash-ordered map readback would permute the +// cross-module list and turn the witness red. test fn direct_module_dependency_dedupes_by_module_pair_holds() -> Bool { let same_module_provider = BoundReferenceProvider { @@ -638,7 +665,10 @@ test fn direct_module_dependency_dedupes_by_module_pair_holds() -> Bool { } } -data occurrence_binding_candidates_witness_refused_population_never_empty_edges_note: String = "Blocker-3 residual RED (PR 7515): a ReferencePopulationRefused population must project as DirectModuleDependencyPopulationRefused — never DirectModuleDependencyListReady with an empty edge list. Empty edges are reachable only from AllReferencesBound with zero cross-module providers." +// Blocker-3 residual RED (PR 7515): a ReferencePopulationRefused population must project as +// DirectModuleDependencyPopulationRefused — never DirectModuleDependencyListReady with an empty +// edge list. Empty edges are reachable only from AllReferencesBound with zero cross-module +// providers. test fn refused_population_never_projects_empty_edge_list_holds() -> Bool { match direct_module_dependencies_from_bound_population( @@ -654,7 +684,9 @@ test fn refused_population_never_projects_empty_edge_list_holds() -> Bool { } } -data occurrence_binding_candidates_witness_file_dependency_note: String = "Clause (e) projection law: repeated cross-file BoundReferenceProvider rows for one provider module collapse to one provider-file dependency for the consumer file. Same-file self-edges are omitted from the projection." +// Clause (e) projection law: repeated cross-file BoundReferenceProvider rows for one provider +// module collapse to one provider-file dependency for the consumer file. Same-file self-edges are +// omitted from the projection. test fn repeated_cross_file_mentions_collapse_provider_file_holds() -> Bool { let provider_one = BoundReferenceProvider { @@ -744,7 +776,9 @@ test fn reference_derived_dependency_projection_preserves_provenance_and_collaps } } -data occurrence_binding_candidates_witness_missing_module_path_note: String = "Fail-closed RED: a ModuleExposure declaration without an OccurrenceModulePathRow must refuse at index build — never silently drop from the sibling-exposure population and masquerade as OccurrenceUnbound." +// Fail-closed RED: a ModuleExposure declaration without an OccurrenceModulePathRow must refuse at +// index build — never silently drop from the sibling-exposure population and masquerade as +// OccurrenceUnbound. test fn module_scope_declaration_missing_module_path_refuses_holds() -> Bool { match resolve_reference_binding_via_structural_candidates( @@ -776,7 +810,8 @@ test fn module_scope_declaration_missing_module_path_refuses_holds() -> Bool { } } -data occurrence_binding_candidates_witness_duplicate_module_path_note: String = "Fail-closed RED: conflicting OccurrenceModulePathRow values for the same occurrence must refuse at index build — never pick the last row and change exposure." +// Fail-closed RED: conflicting OccurrenceModulePathRow values for the same occurrence must refuse +// at index build — never pick the last row and change exposure. test fn duplicate_module_path_row_refuses_holds() -> Bool { match resolve_reference_binding_via_structural_candidates( @@ -818,7 +853,8 @@ test fn duplicate_module_path_row_refuses_holds() -> Bool { } } -data occurrence_binding_candidates_witness_duplicate_exposure_note: String = "Fail-closed RED: conflicting DeclarationExposureRow values for the same occurrence must refuse at index build — never pick the last row and change visibility." +// Fail-closed RED: conflicting DeclarationExposureRow values for the same occurrence must refuse at +// index build — never pick the last row and change visibility. test fn duplicate_declaration_exposure_row_refuses_holds() -> Bool { match resolve_reference_binding_via_structural_candidates( @@ -864,7 +900,8 @@ test fn duplicate_declaration_exposure_row_refuses_holds() -> Bool { } } -data occurrence_binding_candidates_witness_duplicate_authored_order_note: String = "Fail-closed RED: conflicting AuthoredOrderRow values for the same occurrence must refuse at index build — never pick the last row and change source-order gating." +// Fail-closed RED: conflicting AuthoredOrderRow values for the same occurrence must refuse at index +// build — never pick the last row and change source-order gating. test fn duplicate_authored_order_row_refuses_holds() -> Bool { match resolve_reference_binding_via_structural_candidates( @@ -905,7 +942,9 @@ test fn duplicate_authored_order_row_refuses_holds() -> Bool { } } -data occurrence_binding_candidates_witness_missing_exposure_note: String = "Fail-closed RED (PR 7515 blocker 2): a declaration with no DeclarationExposureRow must refuse MissingDeclarationExposure at index build — never silently fail the Bool visibility predicate and masquerade as OccurrenceUnbound." +// Fail-closed RED (PR 7515 blocker 2): a declaration with no DeclarationExposureRow must refuse +// MissingDeclarationExposure at index build — never silently fail the Bool visibility predicate and +// masquerade as OccurrenceUnbound. test fn missing_declaration_exposure_refuses_holds() -> Bool { match resolve_reference_binding_via_structural_candidates( @@ -934,7 +973,8 @@ test fn missing_declaration_exposure_refuses_holds() -> Bool { } } -data occurrence_binding_candidates_witness_missing_authored_order_note: String = "Fail-closed RED (PR 7515 blocker 2): a reference (or declaration) with no AuthoredOrderRow must refuse MissingAuthoredOrderRow at index build — never treat missing ordinal as ordinary Unbound." +// Fail-closed RED (PR 7515 blocker 2): a reference (or declaration) with no AuthoredOrderRow must +// refuse MissingAuthoredOrderRow at index build — never treat missing ordinal as ordinary Unbound. test fn missing_authored_order_row_refuses_holds() -> Bool { match resolve_reference_binding_via_structural_candidates( @@ -963,7 +1003,10 @@ test fn missing_authored_order_row_refuses_holds() -> Bool { } } -data occurrence_binding_candidates_witness_raw_containment_not_parallel_note: String = "Fail-closed RED (PR 7515 blocker 1): a declaration whose containment is a prefix of the reference but whose DeclarationExposure is ModuleExposure for a DIFFERENT module must NOT bind via raw containment. Exposure carrier alone decides — missing/wrong ModuleExposure is not rescued by declaration.containment." +// Fail-closed RED (PR 7515 blocker 1): a declaration whose containment is a prefix of the reference +// but whose DeclarationExposure is ModuleExposure for a DIFFERENT module must NOT bind via raw +// containment. Exposure carrier alone decides — missing/wrong ModuleExposure is not rescued by +// declaration.containment. test fn raw_containment_without_matching_exposure_does_not_bind_holds() -> Bool { let nested_decl = OccurrenceId { value: 10 } @@ -1016,7 +1059,9 @@ test fn raw_containment_without_matching_exposure_does_not_bind_holds() -> Bool } } -data occurrence_binding_candidates_witness_root_exposure_note: String = "RootExposure authority control: a declaration carrying RootExposure binds on every candidate lookup regardless of containment ancestry or module siblinghood — visibility comes from RootExposure's own semantics, not raw containment." +// RootExposure authority control: a declaration carrying RootExposure binds on every candidate +// lookup regardless of containment ancestry or module siblinghood — visibility comes from +// RootExposure's own semantics, not raw containment. test fn root_exposure_is_visible_holds() -> Bool { let root_decl = OccurrenceId { value: 10 } @@ -1064,7 +1109,9 @@ test fn root_exposure_is_visible_holds() -> Bool { } } -data occurrence_binding_candidates_witness_declarations_by_name_refuse_note: String = "Fail-closed RED (operator finding 3): declarations_by_name_build refuses MissingDeclarationIndexEntry when a declaration is absent from entries_by_id — never silent-skips and shrinks the candidate population." +// Fail-closed RED (operator finding 3): declarations_by_name_build refuses +// MissingDeclarationIndexEntry when a declaration is absent from entries_by_id — never silent-skips +// and shrinks the candidate population. test fn declarations_by_name_missing_index_entry_refuses_holds() -> Bool { let decl = OccurrenceId { value: 10 } @@ -1103,7 +1150,10 @@ fn obc_section13_joined_observations() -> List Bool { section13_population_law_roster_denominator_holds( diff --git a/dag/test/claim/occurrence_identity_acceptance_closure_witness_test.dag b/dag/test/claim/occurrence_identity_acceptance_closure_witness_test.dag index 95d844471d5..f8055dcc98a 100644 --- a/dag/test/claim/occurrence_identity_acceptance_closure_witness_test.dag +++ b/dag/test/claim/occurrence_identity_acceptance_closure_witness_test.dag @@ -26,7 +26,11 @@ import gunbc.occurrence_identity_acceptance_closure { } import std.dissolution { unbound_dissolution } -data occurrence_identity_consumer_red_debt_witness_note: String = "The expected owner and required receipt are PARAMETERS, not shared constants. Four receipts are green by local execution but retain consumer debt until parser_transport_witness_entries exists on main and executes them per PR. The census pins all six debts to their distinct acceptance nodes and exact required_receipt text, preventing a row from staying counted while silently weakening what execution must make RED." +// The expected owner and required receipt are PARAMETERS, not shared constants. Four receipts are +// green by local execution but retain consumer debt until parser_transport_witness_entries exists +// on main and executes them per PR. The census pins all six debts to their distinct acceptance +// nodes and exact required_receipt text, preventing a row from staying counted while silently +// weakening what execution must make RED. fn occurrence_identity_consumer_red_debt_has( id: String, @@ -93,7 +97,13 @@ test fn occurrence_identity_receipt_enrollment_debt_is_counted_holds() -> Bool { ] } -data occurrence_identity_closing_check_witness_note: String = "Synthetic controls for the validation/workflow closing fold, not production behavior receipts and not grounds for deleting debt. The positive control constructs Passed rows only to test the fold; it does not assert that any production consumer executed. The deferral control proves covered-with-deferral is not completion; the open control removes one law's coverage; and the refusal controls independently plant unknown, duplicate, stale, non-green, and receipt-plus-deferral rows. Production integration must replace these fixtures with observations decoded from the live scoped execution receipt." +// Synthetic controls for the validation/workflow closing fold, not production behavior receipts and +// not grounds for deleting debt. The positive control constructs Passed rows only to test the fold; +// it does not assert that any production consumer executed. The deferral control proves +// covered-with-deferral is not completion; the open control removes one law's coverage; and the +// refusal controls independently plant unknown, duplicate, stale, non-green, and +// receipt-plus-deferral rows. Production integration must replace these fixtures with observations +// decoded from the live scoped execution receipt. fn occurrence_identity_closing_receipt( law: OccurrenceIdentityAcceptanceLaw diff --git a/dag/test/claim/offline_local_recipe_witness_test.dag b/dag/test/claim/offline_local_recipe_witness_test.dag index 3a4ee79f370..ea077c62e65 100644 --- a/dag/test/claim/offline_local_recipe_witness_test.dag +++ b/dag/test/claim/offline_local_recipe_witness_test.dag @@ -51,7 +51,11 @@ data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly // Every RED control plants its own two-row fixtures and moves exactly ONE fact between // the refusing and admitting halves, so a green half can never be an accident of the // live population's size. -data offline_local_recipe_witness_note: String = "Shape-and-join walls over gunbc.offline_local_recipe. Live claims fold the real rosters (cheap: two substrate lists, no corpus acquisition, no host read). Discriminating REDs are fixture pairs holding the recipe fixed and moving one fact: the exclusion frontier that covers the subject, the function list a RecipeFunctions selection names, and whether a defect row's entry is a subject some recipe carries." +// Shape-and-join walls over gunbc.offline_local_recipe. Live claims fold the real rosters (cheap: +// two substrate lists, no corpus acquisition, no host read). Discriminating REDs are fixture pairs +// holding the recipe fixed and moving one fact: the exclusion frontier that covers the subject, the +// function list a RecipeFunctions selection names, and whether a defect row's entry is a subject +// some recipe carries. fn probe_recipe(path: NonEmptyStr) -> OfflineLocalRecipeRow { OfflineLocalRecipeRow { @@ -134,7 +138,6 @@ test fn recipe_functions_selection_naming_a_function_admits() -> Bool { ) } - fn probe_defect_row(entry: NonEmptyStr) -> OfflineRecipeDefectRow { OfflineRecipeDefectRow { policy: "probe_policy", @@ -237,8 +240,6 @@ test fn home_recipe_renders_no_argv_until_a_resident_is_chosen() -> Bool { ) } - - // The one defect-row rule a refinement cannot decide, and its RED is still authorable // precisely because it is about a JOIN rather than a shape: a measurement filed against a // policy this carrier does not declare would sit here asserting a defect nobody owns. diff --git a/dag/test/claim/operation_argv_binding_wall_witness_test.dag b/dag/test/claim/operation_argv_binding_wall_witness_test.dag index 7896ac26495..c44ccc314f2 100644 --- a/dag/test/claim/operation_argv_binding_wall_witness_test.dag +++ b/dag/test/claim/operation_argv_binding_wall_witness_test.dag @@ -13,7 +13,15 @@ import v2.std.operation_argv { data live_tree_disposition: LiveTreeDisposition = ReadsLiveTree -data operation_argv_binding_wall_note: String = "What EARNS the genericity. A binder that reads the declaration could have become a wider channel than the fixed list it replaces, so two classes are walled, both proven here by execution against real corpus declarations. (1) UNDECLARED NAMES ARE REFUSED, not injected: the seed's previous materializer inserted package, bin, args, unit and property into the binding environment of EVERY operation unconditionally -- a live hole, not a hypothetical one, since any operation whose argv referenced one of those names took the caller's value whether or not it declared the input. (2) THE EXECUTABLE POSITION IS NOT BINDABLE (see the corpus witness and dag/test/fixture/argv_executable_position_probe.dag). Each refusal is typed and located and has no arm that proceeds -- nothing is sanitized, escaped, or dropped (DESIGN 5)." +// What EARNS the genericity. A binder that reads the declaration could become a wider channel than +// the fixed list it replaces, so two classes are walled, both proven here by execution against real +// corpus declarations. (1) UNDECLARED NAMES ARE REFUSED, not injected: the seed's previous +// materializer inserted package, bin, args, unit and property into the binding environment of EVERY +// operation unconditionally -- a live hole, since any operation whose argv referenced one of those +// names took the caller's value whether or not it declared the input. (2) THE EXECUTABLE POSITION +// IS NOT BINDABLE (see the corpus witness and dag/test/fixture/argv_executable_position_probe.dag). +// Each refusal is typed and located with no arm that proceeds -- nothing is sanitized, escaped, or +// dropped (DESIGN 5). data systemctl_path: String = "dag/extdeps/systemd/systemctl.dag" data systemctl_service: String = "systemd.Systemctl" diff --git a/dag/test/claim/operation_argv_corpus_witness_test.dag b/dag/test/claim/operation_argv_corpus_witness_test.dag index 6adb7107c20..6db89db5fbc 100644 --- a/dag/test/claim/operation_argv_corpus_witness_test.dag +++ b/dag/test/claim/operation_argv_corpus_witness_test.dag @@ -21,7 +21,16 @@ import v2.std.operation_argv { data live_tree_disposition: LiveTreeDisposition = ReadsLiveTree -data operation_argv_corpus_note: String = "The RED corpus for argv materializer route (b), DERIVED rather than rostered: shell_transport_operation_rows() enumerates every shell-transport operation declared under dag/ and src/v2/ from the declarations themselves, so a newly authored operation enrolls by existing and coverage is a corpus fact rather than a claim (DESIGN 3 and 6 -- a hand roster would be the parallel-ledger form of exactly this fact). Each row is bound GENERICALLY: every input the operation declares, and nothing else. Measured at authoring time by execution: 141 rows (139 corpus operations plus the 2 executable-position fixture operations), of which 133 materialize, 96 reference at least one input outside the seed's prior five-name vocabulary (package, bin, args, unit, property) and so could not be materialized AT ALL before this change, and 92 of those 96 now materialize -- the remaining 4 are in the counted expression residue below." +// The RED corpus for argv materializer route (b), DERIVED rather than rostered: +// shell_transport_operation_rows() enumerates every shell-transport operation declared under dag/ +// and src/v2/ from the declarations themselves, so a newly authored operation enrolls by existing +// and coverage is a corpus fact rather than a claim (DESIGN 3 and 6 -- a hand roster would be the +// parallel-ledger form of exactly this fact). Each row is bound GENERICALLY: every input the +// operation declares, and nothing else. Measured at authoring time by execution: 141 rows (139 +// corpus operations plus the 2 executable-position fixture operations), of which 133 materialize, +// 96 reference at least one input outside the seed's prior five-name vocabulary (package, bin, +// args, unit, property) and so could not be materialized AT ALL before this change, and 92 of those +// 96 now materialize -- the remaining 4 are in the counted expression residue below. data operation_argv_expression_residue_note: String = "The residue is a DEFICIT HELD CONSTANT, not a regression: 7 operations carry an argv element that is a call or a field access, which materialization does not evaluate. Established by execution against the OLD builtin before this change -- all 7 refused there too (4 with `unsupported expr`, 3 with `unbound param` reached first), so no operation that materialized before refuses now. What changed is the shape of the refusal: an untyped host error string became a typed, located, counted ArgvExpressionUnsupported. The count is pinned so the deficit can only shrink deliberately; the operations are git.Core.DiffUnified0, git.Core.DiffNameStatus, http.Client.GetLocalhostBounded, sudo.NopasswdExecuteProbe.Check, gunbc.Cli.Run, claim_executor.Executor.RunPlan and claim_executor.Executor.VerifyBuildArtifacts. Dissolves when argv element evaluation lands, which is a separate lane." diff --git a/dag/test/claim/optional_carrier_signature_test.dag b/dag/test/claim/optional_carrier_signature_test.dag index 1797db99cb4..add8fa0460e 100644 --- a/dag/test/claim/optional_carrier_signature_test.dag +++ b/dag/test/claim/optional_carrier_signature_test.dag @@ -4,7 +4,22 @@ import v2.std.live_tree { LiveTreeDisposition, SubstrateInputsOnly } data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data optional_carrier_signature_witness_note: String = "THE SIGNATURE HALF OF THE v1-EMITTER OPTIONAL-RENDERING FAMILY, migrated from src/v1/tests/src/optional_carrier_signature_test.rs (v1-test-migration). The behavior: a declared optional return renders its Rust signature wrapped — `-> String?` becomes `-> Option` and, on a shared (recursive) type, `-> Node?` becomes `-> Option>` — and the wrap is CARDINALITY-DERIVED rather than blanket, so a non-optional return of the same carrier stays bare. The defect this family exists to catch was the text-carrier early return short-circuiting the Optional template, which emitted a bare `String` while the body already produced Some/None: the dominant E0308 cluster in the faithful Route-A seed.\\n\\nEACH WITNESS PINS THE WHOLE SIGNATURE, NOT A SUBSTRING OF IT. The Rust module had to slice the emitted text from `fn ` to the body opener before asserting `contains(\\\"Option<\\\")`, because the runtime's own types legitimately mention Option and a whole-file scan would pass on them. Naming the entire expected signature removes the need for that scoping and is strictly stronger: it fixes parameter spelling and carrier rendering too, so a change that kept `Option<` while altering the rest still reds. The negative controls exclude the SPECIFIC wrapped signature rather than the bare token `Option<`, for the same reason — an unscoped exclusion would red on unrelated runtime code and would be a guard that fires for the wrong reason." +// THE SIGNATURE HALF OF THE v1-EMITTER OPTIONAL-RENDERING FAMILY, migrated from +// src/v1/tests/src/optional_carrier_signature_test.rs (v1-test-migration). The behavior: a declared +// optional return renders its Rust signature wrapped — `-> String?` becomes `-> Option` +// and, on a shared (recursive) type, `-> Node?` becomes `-> Option>` — and the wrap is +// CARDINALITY-DERIVED rather than blanket, so a non-optional return of the same carrier stays bare. +// The defect this family exists to catch was the text-carrier early return short-circuiting the +// Optional template, which emitted a bare `String` while the body already produced Some/None: the +// dominant E0308 cluster in the faithful Route-A seed.\n\nEACH WITNESS PINS THE WHOLE SIGNATURE, +// NOT A SUBSTRING OF IT. The Rust module had to slice the emitted text from `fn ` to the body +// opener before asserting `contains(\"Option<\")`, because the runtime's own types legitimately +// mention Option and a whole-file scan would pass on them. Naming the entire expected signature +// removes the need for that scoping and is strictly stronger: it fixes parameter spelling and +// carrier rendering too, so a change that kept `Option<` while altering the rest still reds. The +// negative controls exclude the SPECIFIC wrapped signature rather than the bare token `Option<`, +// for the same reason — an unscoped exclusion would red on unrelated runtime code and would be a +// guard that fires for the wrong reason. fn optional_string_return_source() -> String { "module optcarrierstr\n\nimport std.types { Bool, String }\n\nfn maybe_label(flag: Bool) -> String? {\n if flag { Present { value: \"x\" } } else { none }\n}\n" diff --git a/dag/test/claim/optional_consumer_fail_closed_test.dag b/dag/test/claim/optional_consumer_fail_closed_test.dag index 333617c4c3d..6299e86fb0c 100644 --- a/dag/test/claim/optional_consumer_fail_closed_test.dag +++ b/dag/test/claim/optional_consumer_fail_closed_test.dag @@ -4,7 +4,20 @@ import v2.std.live_tree { LiveTreeDisposition, SubstrateInputsOnly } data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data optional_consumer_fail_closed_witness_note: String = "THE CALL-SITE HALF OF THE v1-EMITTER OPTIONAL-RENDERING FAMILY, migrated from src/v1/tests/src/optional_consumer_fail_closed_test.rs (v1-test-migration). The behavior: an optional value flowing into a NON-optional parameter is the model hole the signature repair exposed rather than hid, and the emitter closes it by construction at exactly those call sites with a located `.expect(\\\"fail-closed: ...\\\")` naming the consumer. The choice is the whole point (DESIGN 5): on an empty Optional the emitted code must ABORT loudly, never fabricate, so `unwrap_or_default` and `unwrap_or_else()` are the rejected shapes, not merely unused ones.\\n\\nTHE EXCLUSION IS THE LOAD-BEARING ASSERTION, and it is why the fabricating alternative is named here rather than assumed absent: emitting the located expect AND a fabricating fallback elsewhere on the same path would satisfy an inclusion-only witness while re-opening the fail-open arm. The unwrap being TYPE-DERIVED is proven by the discriminating control: the same required parameter fed a non-optional argument must emit no unwrap at all, so a blanket unwrap-every-argument implementation passes the first witness and fails the second." +// THE CALL-SITE HALF OF THE v1-EMITTER OPTIONAL-RENDERING FAMILY, migrated from +// src/v1/tests/src/optional_consumer_fail_closed_test.rs (v1-test-migration). An optional value +// flowing into a NON-optional parameter is the model hole the signature repair exposed, and the +// emitter closes it by construction at exactly those call sites with a located +// `.expect(\"fail-closed: ...\")` naming the consumer. DESIGN 5: on an empty Optional the emitted +// code must ABORT loudly, never fabricate, so `unwrap_or_default` and +// `unwrap_or_else()` are rejected shapes, not merely unused ones. +// +// THE EXCLUSION IS THE LOAD-BEARING ASSERTION, which is why the fabricating alternative is named +// rather than assumed absent: emitting the located expect AND a fabricating fallback elsewhere on +// the same path satisfies an inclusion-only witness while re-opening the fail-open arm. The +// discriminating control proves the unwrap is TYPE-DERIVED: the same required parameter fed a +// non-optional argument must emit no unwrap, so a blanket unwrap-every-argument implementation +// passes the first witness and fails the second. fn optional_arg_into_required_param_source() -> String { "module failclosedoptarg\n\nimport std.types { Bool, Int }\n\nfn maybe(flag: Bool) -> Int? {\n if flag { Present { value: 1 } } else { none }\n}\n\nfn consume(x: Int) -> Int {\n x\n}\n\nfn drive(flag: Bool) -> Int {\n consume(x: maybe(flag: flag))\n}\n" diff --git a/dag/test/claim/orchestration_if_emit_test.dag b/dag/test/claim/orchestration_if_emit_test.dag index 9fcffa0cbf7..8040365831d 100644 --- a/dag/test/claim/orchestration_if_emit_test.dag +++ b/dag/test/claim/orchestration_if_emit_test.dag @@ -25,7 +25,9 @@ import v2.std.orchestration { import v2.std.collection { Absent, Present } import v2.std.diagnostic { Accepted, None, Rejected } -data orch_if_golden_note: String = "Hand-authored goldens below are independent of the orch_* grammar row spellings in src/v2/extdeps/languages/bash.dag: byte tests compare the emitter against these literals so a row/segment/emitter regression cannot go green by perturbing both sides at once (#6467 pattern)." +// Hand-authored goldens below are independent of the orch_* grammar row spellings in +// src/v2/extdeps/languages/bash.dag: byte tests compare the emitter against these literals so a +// row/segment/emitter regression cannot go green by perturbing both sides at once (#6467 pattern). fn orch_if_streq_empty_then_golden() -> String { "if [ -z \"$1\" ]; then verdict=absent; fi" diff --git a/dag/test/claim/orthogonal_topology_witness_test.dag b/dag/test/claim/orthogonal_topology_witness_test.dag index 713198e1eda..e4119b8e301 100644 --- a/dag/test/claim/orthogonal_topology_witness_test.dag +++ b/dag/test/claim/orthogonal_topology_witness_test.dag @@ -255,11 +255,11 @@ test fn stacked_floors_touch_without_interpenetrating() -> Bool { overlaps(ca: l_space(), cb: space_ctor(vertices: l_shape(), low: 2400, high: 4800)) == 0 } -// TWO SPACES AT THE SAME PLACE. This is the case the first version of the overlap predicate got -// wrong: with coincident boundaries no vertex of either is STRICTLY inside the other and no pair of -// edges crosses transversally, so a vertex-and-crossing test answers "disjoint" for two rooms -// occupying one volume. It reached review-quality green because nothing exercised it; the mutation -// that should have flipped stacked_floors did not, which is what exposed it. +// TWO SPACES AT THE SAME PLACE. The case the first overlap predicate got wrong: with coincident +// boundaries no vertex of either is STRICTLY inside the other and no pair of edges crosses +// transversally, so a vertex-and-crossing test answers "disjoint" for two rooms occupying one +// volume. It reached review-quality green because nothing exercised it; the mutation that should +// have flipped stacked_floors did not, which exposed it. test fn identical_spaces_interpenetrate() -> Bool { overlaps(ca: l_space(), cb: l_space()) == 1 && match sequence_spaces(cs: [l_space(), l_space()]) { @@ -363,13 +363,13 @@ fn micro_registry() -> SpatialFrameRegistry { } } -// THE VOLUME PATH REFUSES TOO - and it reaches that refusal through the AREA guard, not -// through the height projection. The first version of this comment claimed the second, and -// mutating both height arms to fabricate a zero left this witness green, which is how the -// claim was caught: space_volume consults the area fold first and it refuses on exactly the -// frames that would break the height projection. So what this establishes is that a volume -// over an unlabelable frame refuses rather than returning zero. It does NOT establish that -// the height projection refuses, and the module records that those arms are defensive. +// THE VOLUME PATH REFUSES TOO - and it reaches that refusal through the AREA guard, not the height +// projection. The first version of this comment claimed the second, and mutating both height arms +// to fabricate a zero left this witness green, which caught the claim: space_volume consults the +// area fold first and it refuses on exactly the frames that would break the height projection. So +// this establishes that a volume over an unlabelable frame refuses rather than returning zero. It +// does NOT establish that the height projection refuses; the module records those arms as +// defensive. test fn w_metric_folds_refuse_a_frame_they_cannot_label() -> Bool { match l_space() { OrthogonalRefused { cause: _ } => false diff --git a/dag/test/claim/output_policy_witness_test.dag b/dag/test/claim/output_policy_witness_test.dag index 49f60cefd70..b53ca639372 100644 --- a/dag/test/claim/output_policy_witness_test.dag +++ b/dag/test/claim/output_policy_witness_test.dag @@ -1,5 +1,7 @@ module test.claim.output_policy_witness +import gunbc.output_policy { ExpectedOutcome } + data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly fn dec_is(d: OutputDecision, suppressed: Bool, condensed: Bool, full: Bool) -> Bool { @@ -137,7 +139,9 @@ test fn w_neutralization_is_the_only_route_to_surfaced_text() -> Bool { subject_text_line_guard == "| " } -data w_quiet_ambient_silent_but_divergence_still_surfaces_note: String = "Observation dissolve: Quiet suppresses Ambient ShellTrace scaffolding, but stream disposition follows divergence — Anomaly is never silenced by channel Suppressed (DESIGN section 5). Verbose still surfaces every stream (Full)." +// Observation dissolve: Quiet suppresses Ambient ShellTrace scaffolding, but stream disposition +// follows divergence — Anomaly is never silenced by channel Suppressed (DESIGN section 5). Verbose +// still surfaces every stream (Full). test fn w_quiet_ambient_silent_but_divergence_still_surfaces() -> Bool { disp_is(d: shell_stream(verbosity: Quiet, expected: ExpectFailure, observed: ObservedSuccess), @@ -190,7 +194,6 @@ test fn w_outcome_is_data_is_exit_invariant() -> Bool { es_flips && ef_flips && oid_still } - // The display grain is the fact Suppressed | Condensed | Full structurally cannot carry: those three // decide what becomes of one line, while the rollup grain decides whether a line exists at all. // Verbose keeps leaf grain because the operator asked to see the individual work; Normal and Quiet diff --git a/dag/test/claim/pcb_capability_established_witness_test.dag b/dag/test/claim/pcb_capability_established_witness_test.dag index 799468355f9..5e74aee335c 100644 --- a/dag/test/claim/pcb_capability_established_witness_test.dag +++ b/dag/test/claim/pcb_capability_established_witness_test.dag @@ -43,10 +43,10 @@ test fn w_red_pending_and_refused_still_produce_refusals() -> Bool { } } -// THE ARM IS READ BY MATCHING, not through an is_established predicate. review 52611 noted that -// such a predicate had no production consumer and only its own witness read it -- a bool over a -// coproduct that exists to be tested. The three arms are distinguished here directly, which is -// what any real consumer will do, so nothing in the module is kept alive by evidence alone. +// THE ARM IS READ BY MATCHING, not through an is_established predicate. review 52611 noted such a +// predicate had no production consumer and only its own witness read it -- a bool over a +// coproduct that exists to be tested. The three arms are distinguished directly, as any real +// consumer will do, so nothing in the module is kept alive by evidence alone. test fn w_the_three_standings_are_distinguishable_by_match() -> Bool { (match capability_established(authority: a_stackup_authority) { CapabilityEstablished { authority: _ } => true diff --git a/dag/test/claim/pcb_copper_witness_test.dag b/dag/test/claim/pcb_copper_witness_test.dag index 0065b6a986c..37093ca80c2 100644 --- a/dag/test/claim/pcb_copper_witness_test.dag +++ b/dag/test/claim/pcb_copper_witness_test.dag @@ -92,17 +92,17 @@ data gnd_net: NetIdentity = net_identity(design: fixture_design, local_identity: data absent_net: NetIdentity = net_identity(design: fixture_design, local_identity: "SPI_CLK") // THE FIXTURE IS A BARE NET ROSTER, AND THAT IS THE POINT. Copper takes the nets, not a circuit -// intent, so this witness hands it a roster belonging to no analog article at all. If the carrier -// still required an AnalogCircuitIntent this file would not compile, which makes the decoupling a -// fact the suite depends on rather than a claim in a comment. +// intent, so this witness hands it a roster belonging to no analog article. If the carrier still +// required an AnalogCircuitIntent this file would not compile, so the decoupling is a fact the suite +// depends on rather than a claim in a comment. data board_nets: List = [ ElectricalNet { identity: vcc, members: [] }, ElectricalNet { identity: gnd_net, members: [] }, ] -// A SECOND, DIFFERENT BOARD. Same layer count and same functions at every ordinal, differing only -// in copper thickness and in the declaration admission judged - so an ordinal alone cannot tell the -// two apart, which is exactly the confusion the binding has to catch. +// A SECOND, DIFFERENT BOARD. Same layer count and functions at every ordinal, differing only in +// copper thickness and in the declaration admission judged - so an ordinal alone cannot tell them +// apart, which is exactly the confusion the binding has to catch. data thick: CopperLayer = CopperLayer { function: SignalLayer, thickness: micrometer(count: 35) } data thick_gnd: CopperLayer = CopperLayer { function: GroundPlane, thickness: micrometer(count: 35) } @@ -138,9 +138,9 @@ fn admitted_three_layer_selection(ordinal: Int) -> Bool { } } -// A layer reference reports the ordinal asked for AND the function of the layer that is actually -// there — the second is what makes the reference a read of the stackup rather than a restatement of -// the request. Ordinal 1 is the ground plane, and the reference knows it. +// A layer reference reports the ordinal asked for AND the function of the layer actually there — +// the second makes the reference a read of the stackup rather than a restatement of the request. +// Ordinal 1 is the ground plane, and the reference knows it. test fn w_a_selected_layer_carries_the_function_it_found() -> Bool { match admit_stackup(s: three_layer, authority: board_authority) { StackupRefused { causes: _ } => false @@ -319,8 +319,8 @@ test fn w_coverage_completes_only_when_every_net_is_realized() -> Bool { } // RED control: THE CROSS-STACKUP CLASS. Both boards have three layers with identical functions at -// every ordinal, so the layer reference selected against other_board is indistinguishable from one -// selected against three_layer by ordinal or function - only the bound declaration separates them. +// every ordinal, so a layer reference selected against other_board is indistinguishable by ordinal +// or function from one selected against three_layer - only the bound declaration separates them. // Admitting it against three_layer must refuse, or the seal proved the ref came from SOME admitted // stackup and never which one. test fn w_red_copper_selected_against_another_stackup_is_refused() -> Bool { @@ -492,10 +492,10 @@ test fn w_red_a_via_selected_against_another_stackup_is_refused() -> Bool { } } -// RED control: TWO CONDUCTORS ON ONE LAYER, WITH A VIA PRESENT. This is the case the split refusal -// stopped catching when it narrowed to via-reachability: both rows sit on layer 0, a vcc via touches -// layer 0, so every realized layer IS via-reached and the routing question is satisfied. It is still -// two rows claiming one net on one layer. Confirmed admitted by a probe before this refusal existed. +// RED control: TWO CONDUCTORS ON ONE LAYER, WITH A VIA PRESENT. The case the split refusal stopped +// catching when it narrowed to via-reachability: both rows sit on layer 0, a vcc via touches layer +// 0, so every realized layer IS via-reached and the routing question is satisfied. It is still two +// rows claiming one net on one layer. Confirmed admitted by a probe before this refusal existed. test fn w_red_two_conductors_on_one_layer_are_refused_even_with_a_via() -> Bool { match admitted_board(s: three_layer, authority: board_authority) { Absent => false @@ -532,10 +532,10 @@ test fn w_red_two_conductors_on_one_layer_are_refused_even_with_a_via() -> Bool // THE CASE THE WEAK FORM ADMITTED. VCC realized on all four layers, joined 0-1 and 2-3: every // realized layer is touched by a connection of its own net, so the previous reachability question -// answered yes, and the board admitted with two electrically separate VCC islands. This asserts the -// refusal, and w_islands_joined_into_one_conductor_admits asserts the same population admits once -// the two halves are bridged — both directions in one run, so a refusal that stopped firing cannot -// read as success. +// answered yes and the board admitted with two electrically separate VCC islands. This asserts the +// refusal; w_islands_joined_into_one_conductor_admits asserts the same population admits once the +// halves are bridged — both directions in one run, so a refusal that stopped firing cannot read as +// success. test fn w_two_islands_of_one_net_refuse() -> Bool { match admitted_board(s: four_layer, authority: board_authority) { Absent => false @@ -633,9 +633,9 @@ test fn w_islands_joined_into_one_conductor_admits() -> Bool { } // THE EVIDENCE MUST SURVIVE ADMISSION. Two connection populations that both admit must produce -// admitted values that DIFFER, or the carrier has dropped the evidence it judged. Asserting the -// count alone would be satisfied by a carrier that stored the number and discarded the rows, so this -// also reads a connection back out and checks it names the net it was authored with. +// admitted values that DIFFER, or the carrier dropped the evidence it judged. A count alone would +// be satisfied by a carrier that stored the number and discarded the rows, so this also reads a +// connection back out and checks it names the net it was authored with. test fn w_admitted_copper_retains_the_connections_it_judged() -> Bool { match admitted_board(s: three_layer, authority: board_authority) { Absent => false @@ -663,10 +663,10 @@ test fn w_admitted_copper_retains_the_connections_it_judged() -> Bool { } // AN ENDPOINT ON A LAYER THE NET DOES NOT OCCUPY. VCC is realized on 0 and 2 and the connection runs -// 0 to 1 — layer 1 exists on this board and the connection names a real net, so every stackup and -// identity check it faces passes. What it does not do is land on VCC copper, and before this refusal -// the board admitted. The net is still split, so the connectivity refusal fires too; this asserts -// the endpoint cause specifically, which is the one that names WHERE the hole goes nowhere. +// 0 to 1 — layer 1 exists and the connection names a real net, so every stackup and identity check +// passes. It does not land on VCC copper, and before this refusal the board admitted. The net is +// still split, so the connectivity refusal fires too; this asserts the endpoint cause specifically, +// the one that names WHERE the hole goes nowhere. test fn w_a_connection_endpoint_with_no_conductor_refuses() -> Bool { match admitted_board(s: three_layer, authority: board_authority) { Absent => false diff --git a/dag/test/claim/peak_resident_measured_witness_test.dag b/dag/test/claim/peak_resident_measured_witness_test.dag index a257d89bbd9..f386ba98dca 100644 --- a/dag/test/claim/peak_resident_measured_witness_test.dag +++ b/dag/test/claim/peak_resident_measured_witness_test.dag @@ -14,9 +14,15 @@ import v2.std.live_tree { LiveTreeDisposition, ReadsLiveTree } data live_tree_disposition: LiveTreeDisposition = ReadsLiveTree -data live_tree_disposition_reason: String = "peak_resident_measured_holds reads /proc/self/status (VmHWM) through the observed_peak_resident_bytes host builtin - host state outside the resolved substrate closure, the exact hidden-behind-a-builtin class the entry-text classifier cannot see (live_tree.dag) - so this row declares ReadsLiveTree and never predict-skips." +// peak_resident_measured_holds reads /proc/self/status (VmHWM) through the +// observed_peak_resident_bytes host builtin - host state outside the resolved substrate closure, +// the exact hidden-behind-a-builtin class the entry-text classifier cannot see (live_tree.dag) - so +// this row declares ReadsLiveTree and never predict-skips. -data peak_resident_witness_note: String = "Witness-realization plan P1 ACCEPT: the first CostAccount.space with basis Measured produced BY EXECUTION (memory-control audit F2: RealizationMeasureEffect previously had no space-observing variant, so a Measured space fact was unproducible). The builtin fails closed when VmHWM is unavailable - the witness then errors rather than fabricating." +// Witness-realization plan P1 ACCEPT: the first CostAccount.space with basis Measured produced BY +// EXECUTION (memory-control audit F2: RealizationMeasureEffect previously had no space-observing +// variant, so a Measured space fact was unproducible). The builtin fails closed when VmHWM is +// unavailable - the witness then errors rather than fabricating. data peak_resident_platform_precondition_retired_note: String = "A ProcSelfStatus PRECONDITION STOOD HERE FOR ONE COMMIT AND IS RETIRED BY ITS OWN TRIGGER, which is the outcome it predicted for itself. It declared that this witness could not pass without procfs, on the evidence that observed_peak_resident_bytes read VmHWM from /proc/self/status and errored on Darwin. The declaration was accurate about the code and wrong about the world: peak resident set is not a Linux fact, it is a POSIX one, and getrusage(RUSAGE_SELF).ru_maxrss reports it on every conforming implementation. The builtin now routes through that call and this witness passes on macOS — verified by execution on the operator's machine, where it had failed minutes earlier.\n\nWHY THE WRONG DECLARATION WAS STILL WORTH MAKING: writing down 'this cannot work here, and here is exactly why' is what made the claim checkable, and checking it is what showed the constraint was a TRANSPORT limit wearing a capability's clothes. The precondition would have hardened into permanent scaffolding — a platform the corpus had quietly agreed not to cover — precisely because it was true of the code and nobody re-examined the premise.\n\nWHAT REPLACED IT is not a weaker check but a de-fork: the interpreter arm carried its own inline copy of the procfs parse, separate from cli_run's, so the observation had TWO implementations and only one of them ran for witnesses. Both now route through one portable reader whose per-implementation units are cited (extdeps.posix.rusage, with extdeps.linux.rusage and extdeps.darwin.rusage answering the unit POSIX leaves unspecified)." diff --git a/dag/test/claim/posix_principal_allocation_witness_test.dag b/dag/test/claim/posix_principal_allocation_witness_test.dag index 31d92decbf7..42305cee8e8 100644 --- a/dag/test/claim/posix_principal_allocation_witness_test.dag +++ b/dag/test/claim/posix_principal_allocation_witness_test.dag @@ -8,7 +8,11 @@ data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly // were never evaluated, and the probe spellings they carried would have FAILED the module's own // invariant had anything called it. A test population that cannot reach the code under test is not // weak evidence; it is no evidence, and it reads exactly like success. -data posix_principal_allocation_control_note: String = "Every control here names an arm the legacy witnesses cannot reach: the two new semantic principals, the allocation standing, and the grounding outcome. The central claim under test is that one fleet principal may wear different host-local labels and different numeric identities on two hosts while remaining one principal with one policy -- and that nothing can present an unallocated or unobserved account as grounded." +// Every control here names an arm the legacy witnesses cannot reach: the two new semantic +// principals, the allocation standing, and the grounding outcome. The central claim under test is +// that one fleet principal may wear different host-local labels and different numeric identities on +// two hosts while remaining one principal with one policy -- and that nothing can present an +// unallocated or unobserved account as grounded. data spark5: HostIdentity = "srv5" as HostIdentity data spark6: HostIdentity = "srv6" as HostIdentity @@ -55,7 +59,6 @@ fn grounded_name(o: GroundedPosixPrincipalOutcome) -> NonEmptyStr? { } } - fn outcome_is_drift(o: GroundedPosixPrincipalOutcome) -> Bool { match o { PrincipalDrifted { allocation: _, first: _, more: _ } => true diff --git a/dag/test/claim/preemption_reachability_witness_test.dag b/dag/test/claim/preemption_reachability_witness_test.dag index e8bfa5ad9b6..56fefa066b0 100644 --- a/dag/test/claim/preemption_reachability_witness_test.dag +++ b/dag/test/claim/preemption_reachability_witness_test.dag @@ -16,8 +16,32 @@ import v2.workflow.required_floor { required_floor_claim_wall_safety_limit_ms, } -data root_d_receipt_note: String = "PREEMPTION-1 (gunbc#8584 REWORK): floor run 32301212975 recorded root_d_checkpoint_scalar_declared_arity_witness_holds reaching a verdict at 60317ms CPU against the then-current 5000ms required_floor_claim_cpu_safety_limit_ms, dominated by one compile_dag_rust_emit_check call. THE MEASURED RECEIPT IS THE CPU FIGURE AND THE VerdictReached/not-SafetyInterrupted FACT, AND NOTHING ELSE. The floor log did not report a wall figure for this occurrence, so there is no measured wall number to carry and this fixture does not invent one: observed_wall_ms is set to 100, a value that cannot trip any wall limit this repository has carried, so the CPU arm is the sole cause of the classification under test.\n\nTHIS SENTENCE HAS NOW ROTTED TWICE, WHICH IS WHY THE FIXTURE WAS CHANGED RATHER THAN THE PROSE CORRECTED A SECOND TIME. It first read comfortably inside the 10000ms wall limit; the 2026-08-27 ceiling work invalidated that, and the correction then asserted the limit had moved to 2000ms and that the fixture value exercised the wall branch. BOTH HALVES WERE FALSE ON THE DAY THEY LANDED: the wall limit was NOT 2000, it was whatever required_floor_claim_wall_safety_limit_ms held, and the fixture value EQUALLED it -- and int_gt is strict, so it never exercised the wall branch at all. THE THIRD ROT IS PRE-EMPTED HERE RATHER THAN REPAIRED LATER: this sentence carried the live figure, which is the same transcription that produced rots one and two, so the number is dropped and the constant named. A reader who needs the value reads the function. The witness stayed green throughout because the CPU figure trips the same arm on its own, so nothing measured ever changed and only the sentence was wrong. Found by review 57138.\n\nTHE STRUCTURAL DEFECT BEHIND BOTH ROTS, and it is the reason for the 100: a fixture input equal to a live constant is coupled to that constant silently. Holding the limit's own value, this fixture sat one edit away from changing its own subject -- lower the wall limit below that value and the wall arm starts firing, the classification is reached for a different reason, and every assertion here still passes. A fixture chosen to isolate one clock must carry a value for the other that cannot participate at any setting, which is what 100 buys and what any value near the limit cannot." - +// PREEMPTION-1 (gunbc#8584 REWORK): floor run 32301212975 recorded +// root_d_checkpoint_scalar_declared_arity_witness_holds reaching a verdict at 60317ms CPU against +// the then-current 5000ms required_floor_claim_cpu_safety_limit_ms, dominated by one +// compile_dag_rust_emit_check call. THE MEASURED RECEIPT IS THE CPU FIGURE AND THE +// VerdictReached/not-SafetyInterrupted FACT, AND NOTHING ELSE. The floor log reported no wall +// figure for this occurrence, so this fixture invents none: observed_wall_ms is set to 100, a +// value that cannot trip any wall limit this repository has carried, so the CPU arm is the sole +// cause of the classification under test. +// +// THIS SENTENCE HAS NOW ROTTED TWICE, WHICH IS WHY THE FIXTURE WAS CHANGED RATHER THAN THE PROSE +// CORRECTED A SECOND TIME. It first read comfortably inside the 10000ms wall limit; the 2026-08-27 +// ceiling work invalidated that, and the correction asserted the limit had moved to 2000ms and that +// the fixture value exercised the wall branch. BOTH HALVES WERE FALSE ON THE DAY THEY LANDED: the +// wall limit was whatever required_floor_claim_wall_safety_limit_ms held, not 2000, and the fixture +// value EQUALLED it -- int_gt is strict, so it never exercised the wall branch. THE THIRD ROT IS +// PRE-EMPTED HERE: this sentence carried the live figure, the same transcription that produced rots +// one and two, so the number is dropped and the constant named; a reader who needs the value reads +// the function. The witness stayed green throughout because the CPU figure trips the same arm on +// its own; only the sentence was wrong. Found by review 57138. +// +// THE STRUCTURAL DEFECT BEHIND BOTH ROTS, and the reason for the 100: a fixture input equal to a +// live constant is coupled to that constant silently. Holding the limit's own value, this fixture +// sat one edit away from changing its own subject -- lower the wall limit below that value and the +// wall arm starts firing, the classification is reached for a different reason, and every +// assertion here still passes. A fixture chosen to isolate one clock must carry a value for the +// other that cannot participate at any setting, which 100 buys and any value near the limit cannot. test fn w_root_d_shape_derives_completed_past_safety_limit_with_opaque_host_preemption() -> Bool { match claim_safety_outcome( @@ -40,7 +64,11 @@ test fn w_root_d_shape_derives_completed_past_safety_limit_with_opaque_host_pree } } -data blocking_control_note: String = "BINDING CONSTRAINT: a completed-past-limit occurrence blocks exactly as an interrupt does -- no amount of later completion converts a missed interrupt into successful enforcement. This is the discriminating half: it would pass if claim_safety_outcome_blocks silently returned false for CompletedPastSafetyLimit, so it is asserted directly rather than folded into the shape test above." +// BINDING CONSTRAINT: a completed-past-limit occurrence blocks exactly as an interrupt does -- no +// amount of later completion converts a missed interrupt into successful enforcement. This is the +// discriminating half: it would pass if claim_safety_outcome_blocks silently returned false for +// CompletedPastSafetyLimit, so it is asserted directly rather than folded into the shape test +// above. test fn w_completed_past_safety_limit_blocks() -> Bool { claim_safety_outcome_blocks( @@ -52,7 +80,11 @@ test fn w_completed_past_safety_limit_blocks() -> Bool { ) == true } -data no_relabel_control_note: String = "BINDING CONSTRAINT: root_d was terminal -- it completed -- and must never be relabelled SafetyInterrupted. reached_verdict is the one fact the derivation switches on; this asserts that a claim which never reached a verdict (a genuine interrupt) is classified SafetyInterrupted and NOT CompletedPastSafetyLimit, so the two terminal-but-over-limit and non-terminal cases cannot be silently swapped by an edit to claim_safety_outcome." +// BINDING CONSTRAINT: root_d was terminal -- it completed -- and must never be relabelled +// SafetyInterrupted. reached_verdict is the one fact the derivation switches on; this asserts that +// a claim which never reached a verdict (a genuine interrupt) is classified SafetyInterrupted and +// NOT CompletedPastSafetyLimit, so the two terminal-but-over-limit and non-terminal cases cannot be +// silently swapped by an edit to claim_safety_outcome. test fn w_genuine_interrupt_is_not_relabelled_completed() -> Bool { match claim_safety_outcome( @@ -99,7 +131,10 @@ test fn w_within_limits_does_not_block() -> Bool { } && (claim_safety_outcome_blocks(CompletedWithinSafetyLimits) == false) } -data migration_wall_note: String = "THE MIGRATION WALL, both arms. compile_dag_rust_emit_check is the one grandfathered opaque host operation and is admitted; a hypothetical second operation that has never been measured reaching this shape is refused; and cooperative reachability is always admitted, because it is the case the safety limits genuinely protect." +// THE MIGRATION WALL, both arms. compile_dag_rust_emit_check is the one grandfathered opaque host +// operation and is admitted; a hypothetical second operation never measured reaching this shape is +// refused; cooperative reachability is always admitted, the case the safety limits genuinely +// protect. test fn w_grandfathered_operation_is_admitted() -> Bool { claim_preemption_admission(OpaqueHostCallUnbounded { operation: "compile_dag_rust_emit_check" }) == true diff --git a/dag/test/claim/primitive_identity_join_witness_test.dag b/dag/test/claim/primitive_identity_join_witness_test.dag index 305944f4a62..21b1118b0bd 100644 --- a/dag/test/claim/primitive_identity_join_witness_test.dag +++ b/dag/test/claim/primitive_identity_join_witness_test.dag @@ -53,7 +53,13 @@ import gunbc.v1_interpreter_primitive_surface { import std.primitives { builtin_registry_surface_names } import std.types { Bool, List, String } -data primitive_identity_join_witness_note: String = "D0/D1 slice (NOT closing contract): join mechanism + five refusal variants typed, three detectors executing on census plus two scaffold detectors on planted RED inputs (primitive_d0_refusal_execution_note); subject universe derived across all five surfaces including InterpreterDispatch from gunbc.v1_interpreter_primitive_surface. D1: measurement scaffold deleted, primitive_surface_census_derived absorbs interpreter roster. Open denominator counted by primitive_d0_open_denominator_receipt_holds and primitive_d0_derived_rows_missing_identity_count." +// D0/D1 slice (NOT closing contract): join mechanism + five refusal variants typed, three detectors +// executing on census plus two scaffold detectors on planted RED inputs +// (primitive_d0_refusal_execution_note); subject universe derived across all five surfaces +// including InterpreterDispatch from gunbc.v1_interpreter_primitive_surface. D1: measurement +// scaffold deleted, primitive_surface_census_derived absorbs interpreter roster. Open denominator +// counted by primitive_d0_open_denominator_receipt_holds and +// primitive_d0_derived_rows_missing_identity_count. test fn w_open_denominator_counted_receipt() -> Bool { primitive_d0_open_denominator_receipt_holds() diff --git a/dag/test/claim/primitive_projection_authority_witness_test.dag b/dag/test/claim/primitive_projection_authority_witness_test.dag index 6ea9e52d59b..6cb69631d59 100644 --- a/dag/test/claim/primitive_projection_authority_witness_test.dag +++ b/dag/test/claim/primitive_projection_authority_witness_test.dag @@ -46,7 +46,12 @@ import std.primitive_identity { } import std.types { Bool, List, String } -data primitive_projection_authority_witness_note: String = "Executes the question a candidate collector asks of this carrier: given a DECLARATION, is it the modeled surface of a PRIMITIVE, and are the two one authority or two. The discriminating control is the DivergentProjection row -- v2.std.collection map_get -- which must answer NOT one authority while the seam and modeled rows answer that they are. A carrier that collapsed the three fidelities into a boolean suppress flag reds w_divergent_projection_is_not_one_authority, which is the whole reason the third variant exists." +// Executes the question a candidate collector asks of this carrier: given a DECLARATION, is it the +// modeled surface of a PRIMITIVE, and are the two one authority or two. The discriminating control +// is the DivergentProjection row -- v2.std.collection map_get -- which must answer NOT one +// authority while the seam and modeled rows answer that they are. A carrier that collapsed the +// three fidelities into a boolean suppress flag reds w_divergent_projection_is_not_one_authority, +// which is the whole reason the third variant exists. fn projection_declaration(module_path: String, decl_name: String) -> DeclarationRef { decl_ref(module_path: module_path, decl_name: decl_name) @@ -246,7 +251,12 @@ test fn w_every_census_symbol_lands_in_exactly_one_disposition_arm() -> Bool { && primitive_surface_distinct_symbol_count() > 0 } -data primitive_runtime_coverage_witness_note: String = "The opposite direction from the projection query, and it catches the class the projection query is blind to by construction: a symbol registered on the typecheck surface with no row on any runtime-bearing surface. The three planted controls are a controlled fixture -- the population and the expected answer are authored here, not copied from the tree -- so the detector is exercised in all three arms rather than only in whichever arm the live corpus happens to occupy today." +// The opposite direction from the projection query, and it catches the class the projection query +// is blind to by construction: a symbol registered on the typecheck surface with no row on any +// runtime-bearing surface. The three planted controls are a controlled fixture -- the population +// and the expected answer are authored here, not copied from the tree -- so the detector is +// exercised in all three arms rather than only in whichever arm the live corpus happens to occupy +// today. fn planted_registry_row(authority: PrimitiveSurfaceAuthority, sym: String) -> PrimitiveSurfaceRow { surface_row( diff --git a/dag/test/claim/primitive_signature_grounding_witness_test.dag b/dag/test/claim/primitive_signature_grounding_witness_test.dag index 56a54890887..b2d02517d6c 100644 --- a/dag/test/claim/primitive_signature_grounding_witness_test.dag +++ b/dag/test/claim/primitive_signature_grounding_witness_test.dag @@ -31,7 +31,12 @@ import std.primitive_identity { } import std.types { Bool, Int, List, NonEmptyStr, String } -data primitive_signature_grounding_witness_note: String = "Executing evidence that a primitive's arity and parameter types are GROUNDED -- read back through one authority -- rather than transcribed beside it. There is deliberately no witness asserting that the semantic contract AGREES with the algebra template: under projection there is one set of bytes, so disagreement has no spelling and such a check would be permanently green by construction, which DESIGN 4b names as worse than absent because it gets cited as coverage. The claims below are the ones whose RED an author can actually produce." +// Executing evidence that a primitive's arity and parameter types are GROUNDED -- read back through +// one authority -- rather than transcribed beside it. There is deliberately no witness asserting +// that the semantic contract AGREES with the algebra template: under projection there is one set of +// bytes, so disagreement has no spelling and such a check would be permanently green by +// construction, which DESIGN 4b names as worse than absent because it gets cited as coverage. The +// claims below are the ones whose RED an author can actually produce. // --------------------------------------------------------------------------- // (a) TOTALITY. Every derived contract resolves to exactly one signature. diff --git a/dag/test/claim/probed_at_word_witness_test.dag b/dag/test/claim/probed_at_word_witness_test.dag index 773486df5dc..a168c6a9b47 100644 --- a/dag/test/claim/probed_at_word_witness_test.dag +++ b/dag/test/claim/probed_at_word_witness_test.dag @@ -4,25 +4,25 @@ import std.types { String, NonEmptyStr } import gunbc.clock_read { probed_at_word } // A PERMANENT regression control for the leaked-Optional rendering, not a check that a match -// statement has two arms. The defect these assert against was live in production receipts on -// 2026-08-20: fourteen sites cast `NonEmptyStr?` to String directly, which renders the OPTIONAL, -// so srv5 and srv6 receipts carried `probed_at=Present { value: 2026-08-20T21:11:38Z }`. The -// discriminating half is the wrapper-name search: an assertion that the present arm merely CONTAINS -// the instant would pass on the leaked spelling too, because the leaked spelling contains it. +// statement has two arms. The defect was live in production receipts on 2026-08-20: fourteen +// sites cast `NonEmptyStr?` to String directly, which renders the OPTIONAL, so srv5 and srv6 +// receipts carried `probed_at=Present { value: 2026-08-20T21:11:38Z }`. The discriminating half is +// the wrapper-name search: asserting the present arm merely CONTAINS the instant would pass on the +// leaked spelling too, because the leaked spelling contains it. // // RUNG: structurally guaranteed on the source -> .dag-acceptance path, and NOT by these witnesses. // They guard what the rendering authority DOES; they never guarded that the fourteen call sites -// route through it, and they still do not -- reverting one of those sites leaves both of these -// green. What changed is that the reverted spelling no longer compiles: the declared next-rung -// trigger below landed as `OptionalCastNotEliminated`, a typed located refusal fired from the -// ExprCast arm of inference (src/v1/04_infer.dag `optional_cast_diags`), so a cast off an optional -// source is refused for every target rather than detected after the fact. These two witnesses stay -// enrolled as the permanent controls on the rendering authority's own behavior (DESIGN section 4b(4): -// a climb deletes the redundant production machinery, never the evidence); the refusal itself is -// executed by `test.claim.optional_cast_wall_witness_test`, whose RED arm is the reverted call site. -// WHAT IS STILL WRITABLE, so this note is not inflation: an optional reaching a text position by a -// route other than a cast -- string interpolation, or an argument at a String-typed parameter -- is -// a different site with a different judgment and is not covered here. +// route through it, and still do not -- reverting one of those sites leaves both green. What +// changed is that the reverted spelling no longer compiles: the declared next-rung trigger below +// landed as `OptionalCastNotEliminated`, a typed located refusal fired from the ExprCast arm of +// inference (src/v1/04_infer.dag `optional_cast_diags`), so a cast off an optional source is +// refused for every target rather than detected after the fact. These two witnesses stay enrolled +// as the permanent controls on the rendering authority's own behavior (DESIGN section 4b(4): a +// climb deletes the redundant production machinery, never the evidence); the refusal itself is +// executed by `test.claim.optional_cast_wall_witness_test`, whose RED arm is the reverted call +// site. WHAT IS STILL WRITABLE, so this note is not inflation: an optional reaching a text position +// by a route other than a cast -- string interpolation, or an argument at a String-typed parameter +// -- is a different site with a different judgment and is not covered here. test fn w_probed_at_word_renders_the_instant_and_not_its_wrapper() -> Bool { let rendered = probed_at_word(reading: Present { value: "2026-08-20T21:11:38Z" as NonEmptyStr }) as String diff --git a/dag/test/claim/proc_self_cgroup_witness_test.dag b/dag/test/claim/proc_self_cgroup_witness_test.dag index 4bc6efd2e44..2a40eceb31c 100644 --- a/dag/test/claim/proc_self_cgroup_witness_test.dag +++ b/dag/test/claim/proc_self_cgroup_witness_test.dag @@ -62,9 +62,17 @@ data cgroup_mount_root: FilePathParts = FilePathParts { segments: ["sys", "fs", data cgroup_walk_var: NonEmptyStr = "d" as NonEmptyStr -data cgroup_shell_witness_note: String = "Compile-time witnesses route through v2.extdeps.languages.bash_proc_self_cgroup bash_membership_assign_from_content (read_unified_cgroup_membership then outcome lowering). Executing shell fixtures for missing/ambiguous/malformed/observed live in test.claim.proc_self_cgroup_real_execution_witness (bin_witness_wet_entries). PERMANENT CROSS-REALIZATION FIXTURE LAW: unified_membership_outcome_tag_from_content(fixture) must equal the executed Bash realization outcome tag for the same fixture; mutation sketches below prove drift in either implementation reds." - -data cross_realization_fixture_law_note: String = "The four canonical fixtures are the closed subject universe for parser-vs-bash agreement. Each law row asserts only the parser-side tag; the wet execution witnesses in proc_self_cgroup_real_execution_witness join the same tags after shell.Exec.Run." +// Compile-time witnesses route through v2.extdeps.languages.bash_proc_self_cgroup +// bash_membership_assign_from_content (read_unified_cgroup_membership then outcome lowering). +// Executing shell fixtures for missing/ambiguous/malformed/observed live in +// test.claim.proc_self_cgroup_real_execution_witness (bin_witness_wet_entries). PERMANENT +// CROSS-REALIZATION FIXTURE LAW: unified_membership_outcome_tag_from_content(fixture) must equal +// the executed Bash realization outcome tag for the same fixture; mutation sketches below prove +// drift in either implementation reds. + +// The four canonical fixtures are the closed subject universe for parser-vs-bash agreement. Each +// law row asserts only the parser-side tag; the wet execution witnesses in +// proc_self_cgroup_real_execution_witness join the same tags after shell.Exec.Run. test fn cross_realization_fixture_law_missing_holds() -> Bool { match unified_membership_outcome_tag_from_content(content: fixture_missing_unified) { diff --git a/dag/test/claim/provider_account_admission_witness_test.dag b/dag/test/claim/provider_account_admission_witness_test.dag index b7cdeff2744..b8ce56b40da 100644 --- a/dag/test/claim/provider_account_admission_witness_test.dag +++ b/dag/test/claim/provider_account_admission_witness_test.dag @@ -53,7 +53,14 @@ import gunbc.roadmap_dashboard_instance { data witness_purpose_note: String = "THE ADMISSION USED TO HAVE NO CONSUMER, so every claim its note made about unwritability was unfalsifiable. admit_account_binding returned a value nothing received while instance construction wrote DashboardExistingProviderState directly, which meant the wall and the traffic were in different places. These claims exist to make both halves checkable: that the admission actually decides, and that a provider state cannot exist without one." -data concurrency_carrier_note: String = "THE TWO VALUES THE OLD Int GUARD ADMITTED. concurrent_sessions was a bare Int and ExclusiveBinding refused only when it exceeded one, so zero and negative sailed through into BindingAdmitted — a successfully admitted binding of a deployment that cannot run. ConcurrentBindingSafe did not look at the number at all.\\n\\nThese are the discriminating inputs: both refuse at the decoder, and neither can reach an admission because the admission no longer accepts an Int. A model that kept the Int and added a check would still admit a hand-passed zero; a model that made the count a shape has nowhere to put one." +// THE TWO VALUES THE OLD Int GUARD ADMITTED. concurrent_sessions was a bare Int and +// ExclusiveBinding refused only above one, so zero and negative reached BindingAdmitted — an +// admitted binding of a deployment that cannot run. ConcurrentBindingSafe never looked at the +// number. +// +// The discriminating inputs: both refuse at the decoder, and neither can reach an admission +// because the admission no longer accepts an Int. Keeping the Int plus a check would still admit a +// hand-passed zero; making the count a shape leaves nowhere to put one. test fn zero_and_negative_session_counts_refuse() -> Bool { let zero = match session_concurrency_of_count(raw: 0) { @@ -90,7 +97,16 @@ test fn many_decodes_and_keeps_its_total() -> Bool { } } -data observation_does_not_promote_note: String = "THE PROMOTION THIS CLAIM EXISTS TO PREVENT. CodexPersistenceObservedLoginOnly used to map to ConcurrentBindingSafe, which admits any session count whatsoever, on the strength of seventeen sessions observed on one host for three days. The observation's own note in extdeps.llm.codex_auth says in the same paragraph that it establishes neither that a refresh exchange happens at all nor how simultaneous cold starts behave.\\n\\nSo the discriminating pair is: a binding AT the observed ceiling is admitted, and a binding ONE ABOVE it is refused with the ceiling named. Under the old mapping both were admitted and the second was the unearned one. The third conjunct pins that ConcurrentBindingSafe is not reachable from any codex persistence value, which is what keeps the proven-safe arm honest until the two-host experiment discharges it." +// THE PROMOTION THIS CLAIM EXISTS TO PREVENT. CodexPersistenceObservedLoginOnly used to map to +// ConcurrentBindingSafe, which admits any session count, on the strength of seventeen sessions +// observed on one host for three days — while the observation's own note in +// extdeps.llm.codex_auth says it establishes neither that a refresh exchange happens nor how +// simultaneous cold starts behave. +// +// The discriminating pair: a binding AT the observed ceiling is admitted, one ABOVE it is refused +// with the ceiling named. The old mapping admitted both; the second was unearned. The third +// conjunct pins that ConcurrentBindingSafe is unreachable from any codex persistence value, keeping +// the proven-safe arm honest until the two-host experiment discharges it. fn admission_for(count: Int) -> AccountBindingAdmission { match session_concurrency_of_count(raw: count) { @@ -166,7 +182,10 @@ test fn exclusive_credential_admits_one_and_refuses_two() -> Bool { one && two } -data evidence_row_tracks_the_observation_note: String = "codex_roadmap_account_evidence restates the observed ceiling, so it can drift from codex_observed_concurrent_sessions_per_root the moment either moves. This pins them together: a re-measurement that updates the observation without updating the evidence row reds here rather than leaving the fleet bound against a number nobody measured." +// codex_roadmap_account_evidence restates the observed ceiling, so it can drift from +// codex_observed_concurrent_sessions_per_root when either moves. This pins them: a re-measurement +// updating the observation but not the evidence row reds here rather than binding the fleet +// against a number nobody measured. test fn fleet_evidence_row_matches_the_observation() -> Bool { match codex_roadmap_account_evidence { @@ -176,7 +195,14 @@ test fn fleet_evidence_row_matches_the_observation() -> Bool { } } -// THE CLAIM THAT WOULD NOT COMPILE BEFORE, AND THE ONE THAT WOULD NOT COMPILE AFTER. Every instance's provider state now carries an admitted binding, so reading one back is possible at all — under the previous shape there was no field to read. And the wall works in the other direction too: a DashboardExistingProviderState written without a binding is a type error, which is the construction property stated as a compile fact rather than as a note.\n\nAll three live instances are checked rather than one, because the bypass was in the SHARED constructor and a claim against a single instance would pass while a second declaration wrote the field by hand. +// THE CLAIM THAT WOULD NOT COMPILE BEFORE, AND THE ONE THAT WOULD NOT COMPILE AFTER. Every +// instance's provider state now carries an admitted binding, so reading one back is possible — +// the previous shape had no field to read. The wall holds the other way too: a +// DashboardExistingProviderState written without a binding is a type error, the construction +// property as a compile fact rather than a note. +// +// All three live instances are checked, not one: the bypass was in the SHARED constructor, and a +// single-instance claim would pass while a second declaration wrote the field by hand. fn instance_binding_is_single_session(instance: HostDashboardInstance) -> Bool { match instance.provider_state { DashboardExistingProviderState { root: _, executable: _, binding } => diff --git a/dag/test/claim/provider_standing_probe_bridge_witness_test.dag b/dag/test/claim/provider_standing_probe_bridge_witness_test.dag index 67280a4358e..29b1bb36661 100644 --- a/dag/test/claim/provider_standing_probe_bridge_witness_test.dag +++ b/dag/test/claim/provider_standing_probe_bridge_witness_test.dag @@ -294,8 +294,10 @@ test fn provider_standing_probe_bridge_keystone_holds() -> Bool { && witness_credential_liveness_splits_from_realm() } - -data codex_press_limit_bridge_witness_note: String = "The sibling-bucket case is the whole point: an exhausted `codex` bucket and an available `codex_bengalfox` bucket must produce DIFFERENT verdicts under draws that name them. A projection that routed either through ProviderAccountLimit would collapse both to one account verdict and refuse — or admit — work for the wrong reason." +// The sibling-bucket case is the whole point: an exhausted `codex` bucket and an available +// `codex_bengalfox` bucket must produce DIFFERENT verdicts under draws that name them. A projection +// that routed either through ProviderAccountLimit would collapse both to one account verdict and +// refuse — or admit — work for the wrong reason. fn press_bucket_credential() -> LimitCredentialLabel { LimitCredentialLabel { label: "srv1-codex" as NonEmptyStr } @@ -381,7 +383,8 @@ test fn witness_no_buckets_is_a_located_unobserved_not_an_empty_list() -> Bool { match o { LimitObservationUnobserved { reason: _ } => true _ => false }) } -data mixed_decode_witness_note: String = "Over-refusal reads as caution while it prices out capacity the observation proved was there. The producer held the limit_id and threw it away; carrying it is the whole fix." +// Over-refusal reads as caution while it prices out capacity the observation proved was there. The +// producer held the limit_id and threw it away; carrying it is the whole fix. fn undecoded_codex_bucket() -> CodexRateLimitBucketVerdict { CodexBucketCapacityUnknown { limit_id: "codex" as NonEmptyStr } @@ -436,8 +439,11 @@ test fn witness_credential_identity_tracks_the_observed_codex_home() -> Bool { }) } - -data entitlement_realm_witness_note: String = "THE TWO NEGATIVES ARE DIFFERENT NEGATIVES. A Bedrock account is REJECTED — read successfully, wrong realization, the answer is no. An unrecognized plan string is UNOBSERVED — upstream moved and our pin is stale, the answer is not yet. Both refuse dispatch today, which is exactly why a witness that only checked `not available` would pass while the model conflated them: the first is permanent until the credential changes, the second is repaired by updating a roster." +// THE TWO NEGATIVES ARE DIFFERENT NEGATIVES. A Bedrock account is REJECTED — read successfully, +// wrong realization, the answer is no. An unrecognized plan string is UNOBSERVED — upstream moved +// and our pin is stale, the answer is not yet. Both refuse dispatch today, which is exactly why a +// witness that only checked `not available` would pass while the model conflated them: the first is +// permanent until the credential changes, the second is repaired by updating a roster. fn chatgpt_realm_on(plan_wire: String) -> CodexAccountRealm { match parse_json_document(s: plan_wire) { @@ -524,7 +530,15 @@ test fn witness_chatgpt_account_without_plan_type_is_malformed_not_unnamed() -> } } -data native_cause_fallback_witness_note: String = "THIS FILE USED TO ASSERT THE DEFECT. witness_codex_bucket_projects_to_native_bucket_never_account_scope checked `t == \"codex\"` against a fixture declaring `reached_type: none` — so the value it pinned was the projection substituting the bucket id for a cause the wire never gave. A green witness was holding the fallback in place as the contract, which is the shape DESIGN §5 names when a degradation gets enshrined by the test that was supposed to catch it.\n\nThe pair below is what the old fixture could not distinguish: one bucket reports a cause and a reset, one reports neither, and they must not project to the same thing." +// THIS FILE USED TO ASSERT THE DEFECT. +// witness_codex_bucket_projects_to_native_bucket_never_account_scope checked `t == "codex"` against +// a fixture declaring `reached_type: none` — so the value it pinned was the projection substituting +// the bucket id for a cause the wire never gave. A green witness was holding the fallback in place +// as the contract, which is the shape DESIGN §5 names when a degradation gets enshrined by the test +// that was supposed to catch it. +// +// The pair below is what the old fixture could not distinguish: one bucket reports a cause and a +// reset, one reports neither, and they must not project to the same thing. fn exhausted_codex_bucket_with_reported_cause() -> CodexRateLimitBucketVerdict { CodexBucketUnavailableUntilReset { diff --git a/dag/test/claim/qualified_arm_start_witness_test.dag b/dag/test/claim/qualified_arm_start_witness_test.dag index 5a0758ca812..a9a01a129ec 100644 --- a/dag/test/claim/qualified_arm_start_witness_test.dag +++ b/dag/test/claim/qualified_arm_start_witness_test.dag @@ -1,6 +1,25 @@ module test.claim.qualified_arm_start_witness_test -data qualified_arm_start_witness_note: String = "WHERE AN UNBRACED MATCH-ARM BODY ENDS. parse_match_arm_stmts consumes statements until looks_like_arm_start reports that the next tokens open a new arm, and that predicate recognised only a bare `_` and an UPPERCASE-start leaf. A NAMESPACE-QUALIFIED pattern begins with its lowercase module head, so it answered false: the body kept consuming, swallowed the next arm pattern as one more statement, and the parse died on the FatArrow that followed. The reported span is that ARROW -- several lines below the arm that actually ended -- which is why the trigger had to be bisected rather than read off the diagnostic. MINIMAL REPRODUCTION, every clause load-bearing: an unbraced arm body containing a `let`, followed by an arm whose pattern is DOTTED. Drop the let and the body is a single expression that never enters the statement loop; make the following pattern `_` or an uppercase leaf and the predicate already answered true. Four separate reproductions of the neighbouring shapes all parsed. MEASURED: on the namespace-cut branch, where qualifying every pattern turns this from rare into ordinary, exactly one corpus file of 3875 reaches it (src/v1/05_emit.dag) -- and that file is invalid under the parser its own branch carries, surviving only because the built binary there predates its own committed mirror. So this is a grammar gap the cut made REACHABLE rather than a cut-branch accommodation. ZERO-DRIFT: the new scan runs only where the old predicate already answered false, and requires the TERMINAL segment to be uppercase with the arrow following the path or its brace group, so no previously-accepted parse changes -- receipt, a full required-regen drifted only v1_compiler_parse.rs, this repair itself. dissolve-on: never -- permanent regression control for qualified arm starts." +// WHERE AN UNBRACED MATCH-ARM BODY ENDS. parse_match_arm_stmts consumes statements until +// looks_like_arm_start reports that the next tokens open a new arm, and that predicate recognised +// only a bare `_` and an UPPERCASE-start leaf. A NAMESPACE-QUALIFIED pattern begins with its +// lowercase module head, so it answered false: the body kept consuming, swallowed the next arm +// pattern as one more statement, and the parse died on the FatArrow that followed. The reported +// span is that ARROW -- several lines below the arm that actually ended -- which is why the trigger +// had to be bisected rather than read off the diagnostic. MINIMAL REPRODUCTION, every clause +// load-bearing: an unbraced arm body containing a `let`, followed by an arm whose pattern is +// DOTTED. Drop the let and the body is a single expression that never enters the statement loop; +// make the following pattern `_` or an uppercase leaf and the predicate already answered true. Four +// separate reproductions of the neighbouring shapes all parsed. MEASURED: on the namespace-cut +// branch, where qualifying every pattern turns this from rare into ordinary, exactly one corpus +// file of 3875 reaches it (src/v1/05_emit.dag) -- and that file is invalid under the parser its own +// branch carries, surviving only because the built binary there predates its own committed mirror. +// So this is a grammar gap the cut made REACHABLE rather than a cut-branch accommodation. +// ZERO-DRIFT: the new scan runs only where the old predicate already answered false, and requires +// the TERMINAL segment to be uppercase with the arrow following the path or its brace group, so no +// previously-accepted parse changes -- receipt, a full required-regen drifted only +// v1_compiler_parse.rs, this repair itself. dissolve-on: never -- permanent regression control for +// qualified arm starts. fn w_qualified_arm_start_ends_the_previous_body() -> Bool { compile_dag_rust_emit_check( diff --git a/dag/test/claim/qualified_declaration_reference_emit_witness_test.dag b/dag/test/claim/qualified_declaration_reference_emit_witness_test.dag index 0aa935ce05f..22c05280ce7 100644 --- a/dag/test/claim/qualified_declaration_reference_emit_witness_test.dag +++ b/dag/test/claim/qualified_declaration_reference_emit_witness_test.dag @@ -1,6 +1,18 @@ module test.claim.qualified_declaration_reference_emit_witness_test -data qualified_declaration_reference_emit_witness_note: String = "Regression control for the qualified-declaration-reference emitter defect formerly worked around in dag/extdeps/container/oci/digest.dag (deleted qualified_self_reference_emit_defect_note): a fully qualified reference to a declaration in a data initializer previously resolved through a bare-name registry (last-write-wins across every module sharing that leaf), so a SAME-MODULE qualified reference could land on an unrelated module's declaration and render as a plain fn-item value instead of a call. The fix normalizes a self-qualified reference to its bare spelling before registry lookup (reusing the already-correct bare-name path) and keys the general dotted-reference registry lookup on the leaf name so the is_data call-suffix decision fires for every qualified reference, same-module or cross-module. Per-PR fixture: w_same_module_qualified_reference_emits_call. Cross-module fixture lives on the long lane: dag/test/claim/long/qualified_declaration_reference_emit_cross_module_witness_test.dag (compile_dag_rust_emit_check exceeds per-PR fast-lane budget). dissolve-on: never -- permanent regression alarm for the emitter arm on the same-module arm." +// Regression control for the qualified-declaration-reference emitter defect formerly worked around +// in dag/extdeps/container/oci/digest.dag (deleted qualified_self_reference_emit_defect_note): a +// fully qualified reference to a declaration in a data initializer previously resolved through a +// bare-name registry (last-write-wins across every module sharing that leaf), so a SAME-MODULE +// qualified reference could land on an unrelated module's declaration and render as a plain fn-item +// value instead of a call. The fix normalizes a self-qualified reference to its bare spelling +// before registry lookup (reusing the already-correct bare-name path) and keys the general +// dotted-reference registry lookup on the leaf name so the is_data call-suffix decision fires for +// every qualified reference, same-module or cross-module. Per-PR fixture: +// w_same_module_qualified_reference_emits_call. Cross-module fixture lives on the long lane: +// dag/test/claim/long/qualified_declaration_reference_emit_cross_module_witness_test.dag +// (compile_dag_rust_emit_check exceeds per-PR fast-lane budget). dissolve-on: never -- permanent +// regression alarm for the emitter arm on the same-module arm. fn w_same_module_qualified_reference_emits_call() -> Bool { compile_dag_rust_emit_check( diff --git a/dag/test/claim/qualified_leaf_registry_collision_emit_witness_test.dag b/dag/test/claim/qualified_leaf_registry_collision_emit_witness_test.dag index 1dd648a9764..98b5d461b5f 100644 --- a/dag/test/claim/qualified_leaf_registry_collision_emit_witness_test.dag +++ b/dag/test/claim/qualified_leaf_registry_collision_emit_witness_test.dag @@ -1,6 +1,12 @@ module test.claim.qualified_leaf_registry_collision_emit_witness_test -data qualified_leaf_registry_collision_emit_witness_note: String = "Discriminating regression control for the post-#7685 leaf-keyed qualified lookup collision class. Same-kind homonyms (homonym_value data/data) prove crate-path disambiguation; cross-kind homonyms (result data vs fn) prove the exact qualified registry row decides BOTH declaration kind (foo vs foo()) AND declaring module — the defect that broke was a kind decision keyed on the wrong module's ItemInfo. Each cross-kind scenario runs with both import orders so qualification wins over last-write registry order. dissolve-on: never — permanent regression alarm for qualified-path disambiguation at emit time." +// Discriminating regression control for the post-#7685 leaf-keyed qualified lookup collision class. +// Same-kind homonyms (homonym_value data/data) prove crate-path disambiguation; cross-kind homonyms +// (result data vs fn) prove the exact qualified registry row decides BOTH declaration kind (foo vs +// foo()) AND declaring module — the defect that broke was a kind decision keyed on the wrong +// module's ItemInfo. Each cross-kind scenario runs with both import orders so qualification wins +// over last-write registry order. dissolve-on: never — permanent regression alarm for +// qualified-path disambiguation at emit time. fn w_cross_module_same_leaf_binds_qualifier_module() -> Bool { compile_dag_rust_emit_check( diff --git a/dag/test/claim/qualified_pattern_head_witness_test.dag b/dag/test/claim/qualified_pattern_head_witness_test.dag index a8fb8d708b0..7e44fbd4ed1 100644 --- a/dag/test/claim/qualified_pattern_head_witness_test.dag +++ b/dag/test/claim/qualified_pattern_head_witness_test.dag @@ -2,7 +2,38 @@ module test.claim.qualified_pattern_head_witness_test import gunbc.compile_diagnostic_census { CompileDiagnosticCensus, CensusObserved, CensusNotRunnable, census_blocking_rows } -data qualified_pattern_head_note: String = "A QUALIFIED PATTERN HEAD MUST BIND WHAT THE BARE SPELLING BINDS. Two spellings of one pattern name the same declaration, so they must bind the same node; only the authored string differs. MECHANISM: lookup_variant_in_type forks on whether the head contains a dot. The bare branch answers from the SCRUTINEE, which carries the instantiation. The dotted branch answered from the SYMBOL INDEX, which returns the coproduct's DECLARATION -- uninstantiated -- so the payload bound to the declaration's type PARAMETER instead of the scrutinee's type ARGUMENT. THE FIX PRESERVES ADMISSION: the index lookup still runs first and still decides whether the head names a variant of this coproduct at all; only the bound node's source changes once admission succeeds, and the fallback arm reproduces the previous answer. WHY THE CENSUS GRAIN AND NOT AN EMIT CHECK, which is the part worth reading. The subject here is a BINDING fact, and a binding fact is decided at typecheck. The first revision of this witness asked it through compile_dag_rust_emit_check, which parses, resolves, typechecks, EMITS RUST, and then -- per compile_dag_diagnostic_census_row_note -- collapses the whole result to a Bool, discarding WHICH judgment fired. So it measured emission for a proposition about resolution, and the enrolled claim duly cost 58579ms CPU against a 5000ms budget with 1.21GB RSS growth while its bare control passed. compile_dag_diagnostic_census reports the causal judgment directly as typed rows, which makes this witness narrower in subject, MORE discriminating (it names the diagnostic instead of collapsing to false), and cheaper for a principled reason rather than a convenient one -- emission is downstream of the fact being tested, so removing it removes work, not evidence. THE COST OBSERVATION IS NOT REPAIRED BY THIS CHANGE AND IS NOT CLAIMED TO BE; it is carried forward as a separate finding in the pull request that lands this, with its ruled-out causes and its next discriminator. MEASURED, all four cells, one fixture, both probe sources carrying IDENTICAL imports so the only difference is the two pattern heads -- pre-fix binary: qualified census OBSERVED[1] InternalError | no field 'root' on type 'T' | blocking=true | n=1, bare census OBSERVED[0]; post-fix binary: qualified OBSERVED[0], bare OBSERVED[0]. The earlier revision's arms differed in their import lists as well as in the head spelling, which made them a controlled experiment for the semantic discriminator and not for anything else; that is fixed here and was fixed before this grain change. A NON-GENERIC coproduct cannot discriminate this at all -- declaration and instantiation coincide there -- which is why the fixture is generic. CensusNotRunnable is a FAILURE with its own cause, never the expected red: could-not-measure and measured-nothing are different states and only one of them is evidence. dissolve-on: never -- permanent regression control for the spelling-identity law in pattern position." +// A QUALIFIED PATTERN HEAD MUST BIND WHAT THE BARE SPELLING BINDS. Two spellings of one pattern +// name the same declaration, so they must bind the same node; only the authored string differs. +// MECHANISM: lookup_variant_in_type forks on whether the head contains a dot. The bare branch +// answers from the SCRUTINEE, which carries the instantiation. The dotted branch answered from the +// SYMBOL INDEX, which returns the coproduct's DECLARATION -- uninstantiated -- so the payload bound +// to the declaration's type PARAMETER instead of the scrutinee's type ARGUMENT. THE FIX PRESERVES +// ADMISSION: the index lookup still runs first and still decides whether the head names a variant +// of this coproduct at all; only the bound node's source changes once admission succeeds, and the +// fallback arm reproduces the previous answer. WHY THE CENSUS GRAIN AND NOT AN EMIT CHECK, which is +// the part worth reading. The subject here is a BINDING fact, and a binding fact is decided at +// typecheck. The first revision of this witness asked it through compile_dag_rust_emit_check, which +// parses, resolves, typechecks, EMITS RUST, and then -- per compile_dag_diagnostic_census_row_note +// -- collapses the whole result to a Bool, discarding WHICH judgment fired. So it measured emission +// for a proposition about resolution, and the enrolled claim duly cost 58579ms CPU against a 5000ms +// budget with 1.21GB RSS growth while its bare control passed. compile_dag_diagnostic_census +// reports the causal judgment directly as typed rows, which makes this witness narrower in subject, +// MORE discriminating (it names the diagnostic instead of collapsing to false), and cheaper for a +// principled reason rather than a convenient one -- emission is downstream of the fact being +// tested, so removing it removes work, not evidence. THE COST OBSERVATION IS NOT REPAIRED BY THIS +// CHANGE AND IS NOT CLAIMED TO BE; it is carried forward as a separate finding in the pull request +// that lands this, with its ruled-out causes and its next discriminator. MEASURED, all four cells, +// one fixture, both probe sources carrying IDENTICAL imports so the only difference is the two +// pattern heads -- pre-fix binary: qualified census OBSERVED[1] InternalError | no field 'root' on +// type 'T' | blocking=true | n=1, bare census OBSERVED[0]; post-fix binary: qualified OBSERVED[0], +// bare OBSERVED[0]. The earlier revision's arms differed in their import lists as well as in the +// head spelling, which made them a controlled experiment for the semantic discriminator and not for +// anything else; that is fixed here and was fixed before this grain change. A NON-GENERIC coproduct +// cannot discriminate this at all -- declaration and instantiation coincide there -- which is why +// the fixture is generic. CensusNotRunnable is a FAILURE with its own cause, never the expected +// red: could-not-measure and measured-nothing are different states and only one of them is +// evidence. dissolve-on: never -- permanent regression control for the spelling-identity law in +// pattern position. data qualpat_qualified_probe_source: String = "module qualpat_qual_probe_mod\n\nimport test.fixture.qualpat_provider \{ QualpatResult, QualpatPayload, QualpatOk, QualpatErr \}\n\nfn qualpat_qual_read(r: QualpatResult) -> String \{\n match r \{\n test.fixture.qualpat_provider.QualpatOk \{ value: v \} => v.root\n test.fixture.qualpat_provider.QualpatErr \{ code: _ \} => \"\"\n \}\n\}\n" diff --git a/dag/test/claim/qualified_spelling_identity_witness_test.dag b/dag/test/claim/qualified_spelling_identity_witness_test.dag index 2641628fb1e..55051067d34 100644 --- a/dag/test/claim/qualified_spelling_identity_witness_test.dag +++ b/dag/test/claim/qualified_spelling_identity_witness_test.dag @@ -1,6 +1,41 @@ module test.claim.qualified_spelling_identity_witness_test -data qualified_spelling_identity_note: String = "THE EMITTER CONTRACT, IN THE DIRECTION THE CORPUS IS MOVING. Same resolved declaration, different authored spelling, must produce the same Rust. Its converse is the container-head law already recorded in this repository -- same leaf, different resolved identity, must produce different Rust -- and both are one principle: emission is decided from RESOLVED IDENTITY, never from the authored string. MECHANISM: emit_field_value_with_context decided the shared reference layer of a record-literal FIELD VALUE with set_contains(shared_types, rc_name) where rc_name is the name AS AUTHORED, while shared_types is keyed on the bare declared name (the same mismatch alias_rhs_qualified_name_routing_note records for every other lookup on that path). A qualified spelling matched nothing, so the field value was emitted UNWRAPPED into a field whose declared type is Rc -- not a style difference but a type error rustc reports as E0308, and one that no amount of correct declaration can compensate for. needs_box_wrapping read the same authored spelling for the same decision and is repaired with it. MEASURED, minimal, both arms in one fixture: the qualified consumer emitted `uri: QualspellUri \{` where the bare consumer emitted `uri: Rc::new(QualspellUri \{`, against one provider both consumers reference. WHY MAIN IS GREEN WITHOUT THIS: the measured v1 seed closure contains almost no qualified type reference, so an ordinary green regen exercises the bare arm only -- which is exactly why this witness authors the qualified arm rather than relying on the corpus to contain one. 4066 qualified dotted type references already exist corpus-wide (555 files, 2314 of them in src/v2) and enter the seed closure as v2 self-hosting advances, so the population that reaches this path grows with the roadmap. ZERO-DRIFT: qualified_last_segment is the identity on an unqualified name, so every bare spelling emits exactly as before -- receipt, a full required-regen over the 132-module subject drifted only v1_compiler_emit_rust.rs, this repair itself. DECLARED RESIDUE, not covered here and not claimed: a qualified reference to a zero-parameter ALIAS is still peeled to its target, and where that target lives in a THIRD module the peeled name reaches the output with no use-line (E0412). Located cause: a qualified reference parses as a module-projection spine, so it fails the NoConnective-and-childless guard on the alias-preserving branch of render_rust_fn_sig_type and never reaches the alias lookup at all. The fixture already carries that shape (QualspellFloor aliases into test.fixture.qualspell_target) so the next repair has its RED waiting. dissolve-on: never -- permanent regression control for the spelling-identity law. COST, MEASURED ON THE FIRST CI RUN RATHER THAN PREDICTED: as a single conjoined claim this witness was the floor worst single claim at 1.22GB RSS growth, against 0.12GB for the whole rest of the roster on the same-day main run -- both compile_dag_rust_emit_check calls are live inside one claim and each builds a corpus-wide scope. The two arms are therefore separate test fns: they are independent propositions (the RED and its regression control), a failure now names WHICH arm broke instead of one conjoined false, and each compile is evaluated and collected on its own. DESIGN section 6 bare-minimum-cost -- a proven cost-shape defect is fixed regardless of the realized n, and this one measured 10x the roster worst." +// THE EMITTER CONTRACT, IN THE DIRECTION THE CORPUS IS MOVING. Same resolved declaration, different +// authored spelling, must produce the same Rust. Its converse is the container-head law already +// recorded here — same leaf, different resolved identity, different Rust — and both are one +// principle: emission is decided from RESOLVED IDENTITY, never the authored string. MECHANISM: +// emit_field_value_with_context decided the shared reference layer of a record-literal FIELD VALUE +// with set_contains(shared_types, rc_name) where rc_name is the name AS AUTHORED, while +// shared_types is keyed on the bare declared name (the mismatch +// alias_rhs_qualified_name_routing_note records for every other lookup on that path). A qualified +// spelling matched nothing, so the field value was emitted UNWRAPPED into a field whose declared +// type is Rc — a type error rustc reports as E0308, which no correct declaration can compensate +// for. needs_box_wrapping read the same authored spelling for the same decision and is repaired +// with it. MEASURED, minimal, both arms in one fixture: the qualified consumer emitted `uri: +// QualspellUri {` where the bare consumer emitted `uri: Rc::new(QualspellUri {`, against one +// provider both reference. WHY MAIN IS GREEN WITHOUT THIS: the measured v1 seed closure contains +// almost no qualified type reference, so an ordinary green regen exercises the bare arm only — +// which is why this witness authors the qualified arm rather than relying on the corpus. 4066 +// qualified dotted type references already exist corpus-wide (555 files, 2314 in src/v2) and enter +// the seed closure as v2 self-hosting advances, so the population reaching this path grows with the +// roadmap. ZERO-DRIFT: qualified_last_segment is the identity on an unqualified name, so every bare +// spelling emits exactly as before — receipt, a full required-regen over the 132-module subject +// drifted only v1_compiler_emit_rust.rs, this repair itself. DECLARED RESIDUE, not covered or +// claimed here: a qualified reference to a zero-parameter ALIAS is still peeled to its target, and +// where that target lives in a THIRD module the peeled name reaches the output with no use-line +// (E0412). Located cause: a qualified reference parses as a module-projection spine, so it fails +// the NoConnective-and-childless guard on the alias-preserving branch of render_rust_fn_sig_type +// and never reaches the alias lookup. The fixture already carries that shape (QualspellFloor +// aliases into test.fixture.qualspell_target) so the next repair has its RED waiting. dissolve-on: +// never — permanent regression control for the spelling-identity law. COST, MEASURED ON THE FIRST +// CI RUN RATHER THAN PREDICTED: as a single conjoined claim this witness was the floor worst single +// claim at 1.22GB RSS growth, against 0.12GB for the whole rest of the roster on the same-day main +// run — both compile_dag_rust_emit_check calls are live inside one claim and each builds a +// corpus-wide scope. So the two arms are separate test fns: independent propositions (the RED and +// its regression control), a failure names WHICH arm broke instead of one conjoined false, and each +// compile is evaluated and collected on its own. DESIGN section 6 bare-minimum-cost — a proven +// cost-shape defect is fixed regardless of the realized n, and this one measured 10x the roster +// worst. fn w_qualified_field_value_takes_the_shared_layer() -> Bool { compile_dag_rust_emit_check( diff --git a/dag/test/claim/quarantine_probe_disposition_witness_test.dag b/dag/test/claim/quarantine_probe_disposition_witness_test.dag index 4d6bcebe2ab..3d2d463372e 100644 --- a/dag/test/claim/quarantine_probe_disposition_witness_test.dag +++ b/dag/test/claim/quarantine_probe_disposition_witness_test.dag @@ -40,7 +40,14 @@ import v2.std.text { String } // declaring SubstrateInputsOnly would be false. Undeclared remains the fail-closed affected-set // selection position; the required floor now executes it and lets the interpreter classify the // actual effects. -data quarantine_probe_disposition_witness_note: String = "Live claim plus controls for the total quarantine-probe disposition join. THE LIVE CLAIM IS DELIBERATELY NOT WHERE THE DISCRIMINATION LIVES: it is a universal over the live admission rows, so it stays meaningful at any population size including zero, and it would pass vacuously on an empty roster. The discrimination is carried by the synthetic controls below, which are authored here and cannot lose their subject when a live quarantine dissolves -- each of the five holder arms is shown to derive HeldByExactlyOne on its own, held-by-nothing is shown to derive the alarm, and held-by-two is shown to refuse. The controls therefore prove the fold DISCRIMINATES rather than merely agreeing with today's tree." +// Live claim plus controls for the total quarantine-probe disposition join. THE LIVE CLAIM IS +// DELIBERATELY NOT WHERE THE DISCRIMINATION LIVES: it is a universal over the live admission rows, +// so it stays meaningful at any population size including zero, and it would pass vacuously on an +// empty roster. The discrimination is carried by the synthetic controls below, which are authored +// here and cannot lose their subject when a live quarantine dissolves -- each of the five holder +// arms is shown to derive HeldByExactlyOne on its own, held-by-nothing is shown to derive the +// alarm, and held-by-two is shown to refuse. The controls therefore prove the fold DISCRIMINATES +// rather than merely agreeing with today's tree. fn witness_pool_roots() -> List { ["dag", "src/v2"] diff --git a/dag/test/claim/rack_power_witness_test.dag b/dag/test/claim/rack_power_witness_test.dag index 244ccb3b8af..b0ee96bafc0 100644 --- a/dag/test/claim/rack_power_witness_test.dag +++ b/dag/test/claim/rack_power_witness_test.dag @@ -79,9 +79,9 @@ fn refusal_of(rack: RackInstance?, loads: List, percent: Int) -> Powe } } -// The cited RS-1215 states 120 V and 15 A, and their product is what the unit can deliver: 1800 -// volt-amperes. It is derived from the two datasheet figures rather than authored, so no third -// number can disagree with them. +// The cited RS-1215 states 120 V and 15 A; their product is what the unit can deliver: 1800 +// volt-amperes. Derived from the two datasheet figures, not authored, so no third number can +// disagree with them. test fn the_feed_capacity_is_the_product_of_the_two_cited_figures() -> Bool { volt_ampere_count(v: feed_capacity(f: feed())) == 1800 } @@ -101,9 +101,9 @@ test fn two_measured_hosts_inside_the_rating_produce_a_budget() -> Bool { } } -// THE POWER FACTOR IS LOAD-BEARING, and this pair is what proves it rather than the type name. 1700 -// watts at a factor of 100 is 1700 volt-amperes and fits; the SAME load at 90 needs about 1889 and -// does not. A module that quietly assumed unity would admit both. +// THE POWER FACTOR IS LOAD-BEARING, and this pair proves it rather than the type name. 1700 watts +// at a factor of 100 is 1700 volt-amperes and fits; the SAME load at 90 needs about 1889 and does +// not. A module quietly assuming unity would admit both. test fn the_declared_power_factor_decides_a_marginal_load() -> Bool { match budget(rack: two_host_rack(), loads: [ObservedRealPower { asset: host_a(), draw: watt(1700) }, ObservedRealPower { asset: host_b(), draw: watt(0) }], percent: 100) { Absent => false @@ -125,9 +125,9 @@ test fn the_declared_power_factor_decides_a_marginal_load() -> Bool { } } -// A nameplate figure is already apparent power and is NOT converted: the power factor applies to the -// real-power arm only. Mixing the two in one rack is ordinary, and the totals stay separate so a -// reader can see which half rests on the declared assumption. +// A nameplate figure is already apparent power and is NOT converted: the power factor applies to +// the real-power arm only. Mixing the two in one rack is ordinary; the totals stay separate so a +// reader sees which half rests on the declared assumption. test fn a_nameplate_load_is_counted_as_apparent_power_unconverted() -> Bool { match budget( rack: two_host_rack(), @@ -140,8 +140,8 @@ test fn a_nameplate_load_is_counted_as_apparent_power_unconverted() -> Bool { } } -// An unmeasured machine is not a machine drawing nothing. This is the arm that keeps an unmeasured -// rack from reporting comfortable headroom. +// An unmeasured machine is not a machine drawing nothing; this arm keeps an unmeasured rack from +// reporting comfortable headroom. test fn an_unobserved_load_refuses_rather_than_counting_as_zero() -> Bool { match refusal_of(rack: two_host_rack(), loads: [ObservedRealPower { asset: host_a(), draw: watt(400) }, LoadUnobserved { asset: host_b() }], percent: 95) { Absent => false @@ -158,9 +158,9 @@ test fn an_unobserved_load_refuses_rather_than_counting_as_zero() -> Bool { } } -// COMPLETENESS IS AN IDENTITY JOIN, and this is the arrangement that proves it: two rows for two -// mounted assets, so any count-based check passes, while one asset is measured twice and the other -// not at all. +// COMPLETENESS IS AN IDENTITY JOIN, and this arrangement proves it: two rows for two mounted +// assets, so any count-based check passes, while one asset is measured twice and the other not at +// all. test fn two_rows_for_one_asset_do_not_stand_in_for_the_other() -> Bool { match refusal_of( rack: two_host_rack(), @@ -182,7 +182,7 @@ test fn two_rows_for_one_asset_do_not_stand_in_for_the_other() -> Bool { } // The other direction of the join: a row naming a machine this rack does not carry is a stale -// inventory, and it is its own refusal because its remedy is a different one. +// inventory — its own refusal, because its remedy is different. test fn a_load_for_an_unmounted_asset_refuses() -> Bool { match refusal_of( rack: two_host_rack(), diff --git a/dag/test/claim/readback_independence_witness_test.dag b/dag/test/claim/readback_independence_witness_test.dag index 374e9c47a59..18bb4908830 100644 --- a/dag/test/claim/readback_independence_witness_test.dag +++ b/dag/test/claim/readback_independence_witness_test.dag @@ -2,7 +2,10 @@ module test.claim.readback_independence data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data witness_cited_incident_note: String = "The conjunct is the incident itself, replayed through the criterion. On srv3 2026-07-25 `sccache --show-stats` returned a full stats table — a Converged read — over a host whose modeled unit had been dead for six hours. The criterion must turn that exact input into UnknownRefused, and it must do so because of what the PROBE can do, not because of anything about the value it returned." +// The conjunct is the incident itself, replayed through the criterion. On srv3 2026-07-25 `sccache +// --show-stats` returned a full stats table — a Converged read — over a host whose modeled unit had +// been dead for six hours. The criterion must turn that exact input into UnknownRefused, and it +// must do so because of what the PROBE can do, not because of anything about the value it returned. test fn witness_self_establishing_probe_cannot_report_converged() -> Bool { observation_verdict_eq( @@ -14,7 +17,12 @@ test fn witness_self_establishing_probe_cannot_report_converged() -> Bool { ) } -data witness_negatives_survive_note: String = "The asymmetry, and it is the conjunct that stops the criterion from being a blunt discard. A self-establishing probe that reports a NEGATIVE is still telling the truth: it had every opportunity to bring the subject into existence and still could not report it, so Absent stays Absent, Drifted stays Drifted, Inaccessible stays Inaccessible. Only the positive is rewritten. A fold that returned UnknownRefused for every verdict from a non-independent probe would pass the conjunct above and destroy real evidence here." +// The asymmetry, and it is the conjunct that stops the criterion from being a blunt discard. A +// self-establishing probe that reports a NEGATIVE is still telling the truth: it had every +// opportunity to bring the subject into existence and still could not report it, so Absent stays +// Absent, Drifted stays Drifted, Inaccessible stays Inaccessible. Only the positive is rewritten. A +// fold that returned UnknownRefused for every verdict from a non-independent probe would pass the +// conjunct above and destroy real evidence here. test fn witness_negative_results_from_a_tainted_probe_survive() -> Bool { observation_verdict_eq( @@ -85,7 +93,12 @@ test fn witness_red_control_trusting_probe_rejected_by_gate() -> Bool { && readback_evidence_gate_accepts(p: systemd_is_active_probe, verdict: std.upsert_decision.Converged) } -data witness_live_consumer_note: String = "The criterion has a live consumer, or it is an inert lens — a thing DESIGN §6 calls a lie in its own right. gunbc.host_swap_backing routes every host verdict through it. The routing is a no-op today because /proc/swaps is inert, so the conjunct proves it by SUBSTITUTION: the same swap verdict carried by the sccache probe instead would be refused. That is what makes the classification load-bearing rather than decorative — swapping the transport for an ensure-shaped one changes the answer." +// The criterion has a live consumer, or it is an inert lens — a thing DESIGN §6 calls a lie in its +// own right. gunbc.host_swap_backing routes every host verdict through it. The routing is a no-op +// today because /proc/swaps is inert, so the conjunct proves it by SUBSTITUTION: the same swap +// verdict carried by the sccache probe instead would be refused. That is what makes the +// classification load-bearing rather than decorative — swapping the transport for an ensure-shaped +// one changes the answer. test fn witness_swap_axis_consumes_the_criterion() -> Bool { let inert_route = readback_evidence_verdict( @@ -104,15 +117,32 @@ test fn witness_swap_axis_consumes_the_criterion() -> Bool { ) } -data witness_roster_ratchet_note: String = "The roster length is pinned on purpose: adding a probe must be a VISIBLE edit to this witness rather than something that slides in with a green run, because the roster's whole value is being an honest inventory of what this lane has actually reasoned about. It moved 4 → 5 when ip_link_carrier_read_probe was added for the network axis (reading a link's carrier cannot bring the link up, so it classifies Inert). The load-bearing conjunct is the other one — exactly one probe in the roster is non-independent, still sccache_show_stats, the cited instance the module exists for — and it is the conjunct that would red if a newly added probe were quietly classified to make a consumer green." +// The roster length is pinned on purpose: adding a probe must be a VISIBLE edit to this witness +// rather than something that slides in with a green run, because the roster's whole value is being +// an honest inventory of what this lane has actually reasoned about. It moved 4 → 5 when +// ip_link_carrier_read_probe was added for the network axis (reading a link's carrier cannot bring +// the link up, so it classifies Inert). The load-bearing conjunct is the other one — exactly one +// probe in the roster is non-independent, still sccache_show_stats, the cited instance the module +// exists for — and it is the conjunct that would red if a newly added probe were quietly classified +// to make a consumer green. test fn witness_roster_names_the_cited_incident() -> Bool { readback_non_independent_probe_count() == 1 && readback_probe_roster.length() == 5 } - -data answers_without_subject_control_doc: String = "THE CONTROL FOR THE FOURTH ARM (operator review, post-merge). sccache --show-stats was classified ProbeMayEstablish on a diagnosis that was later measured false: the claim was that any sccache invocation auto-starts a server, so the read created the subject it reported. Private-endpoint controls took the listener count 0 to 0 across --show-stats while a real compile took it 0 to 1. The first correction rewrote the mechanism prose but LEFT THE ARM, bridging the gap with the phrase 'still may-establish in the sense that matters here' — which is the state-space conflation this module exists to forbid, committed inside the module itself. Subject-creation and answer-without-subject are different facts about a transport and they carry different remedies: the first is a probe to REPLACE, the second is a probe to GROUND behind an independent existence check. The two witnesses below pin both halves — that the new arm still corrects a positive verdict (so the safety property did not regress with the reclassification), and that the arms remain DISTINGUISHABLE (so a future edit cannot quietly collapse them back)." +// THE CONTROL FOR THE FOURTH ARM (operator review, post-merge). sccache --show-stats was classified +// ProbeMayEstablish on a diagnosis that was later measured false: the claim was that any sccache +// invocation auto-starts a server, so the read created the subject it reported. Private-endpoint +// controls took the listener count 0 to 0 across --show-stats while a real compile took it 0 to 1. +// The first correction rewrote the mechanism prose but LEFT THE ARM, bridging the gap with the +// phrase 'still may-establish in the sense that matters here' — which is the state-space conflation +// this module exists to forbid, committed inside the module itself. Subject-creation and +// answer-without-subject are different facts about a transport and they carry different remedies: +// the first is a probe to REPLACE, the second is a probe to GROUND behind an independent existence +// check. The two witnesses below pin both halves — that the new arm still corrects a positive +// verdict (so the safety property did not regress with the reclassification), and that the arms +// remain DISTINGUISHABLE (so a future edit cannot quietly collapse them back). test fn witness_answers_without_subject_still_corrects_a_positive() -> Bool { let probe = ReadBackProbe { diff --git a/dag/test/claim/realization_attempt_keystone_test.dag b/dag/test/claim/realization_attempt_keystone_test.dag index 300dc26fc4e..4a5f26c9480 100644 --- a/dag/test/claim/realization_attempt_keystone_test.dag +++ b/dag/test/claim/realization_attempt_keystone_test.dag @@ -28,7 +28,14 @@ import std.types { String, Int } data live_tree_disposition: LiveTreeDisposition = ReadsLiveTree -data keystone_note: String = "CI2-0 Commit B keystone (operator mandate): the realization-attempt harness proven by execution in both directions BEFORE the sweep consumes it. Positive control: a planted minimal module emits through the canonical pipeline (tokenize->parse->normalize->resolve->emit against rust_target_model_staging) and reports V2TranslateSerialized with nonzero bytes. Negative control: planted garbage refuses at PhaseFrontend with a typed cause — the harness cannot report green on input the pipeline rejects. Live keystone: a REAL corpus entry produces a typed standing (either arm) with a nonempty phase label — the attempt never absorbs, never defaults, and bundle membership appears nowhere in the computation." +// CI2-0 Commit B keystone (operator mandate): the realization-attempt harness proven by execution +// in both directions BEFORE the sweep consumes it. Positive control: a planted minimal module emits +// through the canonical pipeline (tokenize->parse->normalize->resolve->emit against +// rust_target_model_staging) and reports V2TranslateSerialized with nonzero bytes. Negative +// control: planted garbage refuses at PhaseFrontend with a typed cause — the harness cannot report +// green on input the pipeline rejects. Live keystone: a REAL corpus entry produces a typed standing +// (either arm) with a nonempty phase label — the attempt never absorbs, never defaults, and bundle +// membership appears nowhere in the computation. data planted_minimal_source: String = "module m\n\nfn add(x: Int, y: Int) -> Int { x + y }\n" diff --git a/dag/test/claim/realization_vocab_confinement_census_test.dag b/dag/test/claim/realization_vocab_confinement_census_test.dag index 6f1d5f5c67e..40ba54c9166 100644 --- a/dag/test/claim/realization_vocab_confinement_census_test.dag +++ b/dag/test/claim/realization_vocab_confinement_census_test.dag @@ -65,7 +65,12 @@ import v2.std.live_tree { LiveTreeDisposition, SubstrateInputsOnly } data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data confinement_census_witness_note: String = "THE SUBJECT ROSTERS ARE READ FROM THE REAL LENS MODULE, not restated here. Every expected key in this file is taken from v2.lens.realization_vocabulary_containment's own declared data, so a roster edit moves both the census and its expectation together and this file never becomes a second copy of the confinement surface. What it does independently is COUNT and CROSS-CHECK: the arithmetic below sums the four rosters, which is a different assembly than either the census enumeration or its classification performs." +// THE SUBJECT ROSTERS ARE READ FROM THE REAL LENS MODULE, not restated here. Every expected key in +// this file is taken from v2.lens.realization_vocabulary_containment's own declared data, so a +// roster edit moves both the census and its expectation together and this file never becomes a +// second copy of the confinement surface. What it does independently is COUNT and CROSS-CHECK: the +// arithmetic below sums the four rosters, which is a different assembly than either the census +// enumeration or its classification performs. data confinement_census_witness_revision_commit: String = "0000000000000000000000000000000000000b0b" @@ -109,7 +114,14 @@ test fn witness_the_real_confinement_surface_reconciles_exactly() -> Bool { confinement_witness_coverage_established() } -data confinement_self_join_separability_note: String = "THIS WITNESS IS AN IMPLICATION, NOT A CONJUNCTION, and the difference is the separability rule applied to itself. Written as 'a receipt exists AND its denominator is independent' it cannot be individually falsified: a mutation that removes the receipt entirely reds it without saying anything about independence, so independence would be licensed by a red that never examined it. Split, the two halves land on their own witnesses — receipt existence is witness_the_real_confinement_surface_reconciles_exactly, and what remains here is the conditional. The refusal arm is therefore vacuously true rather than false, which is only sound BECAUSE existence is asserted separately; on its own it would be a hole." +// THIS WITNESS IS AN IMPLICATION, NOT A CONJUNCTION, and the difference is the separability rule +// applied to itself. Written as 'a receipt exists AND its denominator is independent' it cannot be +// individually falsified: a mutation that removes the receipt entirely reds it without saying +// anything about independence, so independence would be licensed by a red that never examined it. +// Split, the two halves land on their own witnesses — receipt existence is +// witness_the_real_confinement_surface_reconciles_exactly, and what remains here is the +// conditional. The refusal arm is therefore vacuously true rather than false, which is only sound +// BECAUSE existence is asserted separately; on its own it would be a hole. test fn witness_the_confinement_receipt_if_present_has_an_independent_denominator() -> Bool { match confinement_surface_coverage(revision: confinement_witness_revision()) { @@ -123,7 +135,11 @@ test fn witness_the_confinement_receipt_if_present_has_an_independent_denominato } } -data confinement_conformance_witness_note: String = "THE CONFORMANCE CONTROLS ARE ASSERTED SEPARATELY FROM THE CEILING THEY FEED, so a red says whether the classifier stopped discriminating or whether something downstream broke. The discriminating half is the load-bearing one: it asserts that the census REFUSES a classification with one axis dropped, which is probe 5 turned into an enrolled control that re-runs on every affected change rather than a mutation in a worktree that no longer exists." +// THE CONFORMANCE CONTROLS ARE ASSERTED SEPARATELY FROM THE CEILING THEY FEED, so a red says +// whether the classifier stopped discriminating or whether something downstream broke. The +// discriminating half is the load-bearing one: it asserts that the census REFUSES a classification +// with one axis dropped, which is probe 5 turned into an enrolled control that re-runs on every +// affected change rather than a mutation in a worktree that no longer exists. test fn witness_the_discriminating_control_is_refused_by_the_census() -> Bool { census_coverage_is_refused( @@ -250,7 +266,12 @@ test fn witness_an_undeclared_key_is_absent_from_the_claimed_population() -> Boo } } -data confinement_prefix_grain_witness_note: String = "THE GRAIN CHECK, RUN AGAINST THE REAL ROSTER. 'v2.workflow.bash' is a declared confinement key and 'v2.workflow.bash_command_fold_serialize' is a real module the bash lane names — the second is matched by the first as a STRING PREFIX while being no namespace descendant of it at all. This witness asserts that relationship holds on the live roster rather than on a fixture, because a sweep that read those keys as namespace containment is precisely how a phantom was manufactured in this lane." +// THE GRAIN CHECK, RUN AGAINST THE REAL ROSTER. 'v2.workflow.bash' is a declared confinement key +// and 'v2.workflow.bash_command_fold_serialize' is a real module the bash lane names — the second +// is matched by the first as a STRING PREFIX while being no namespace descendant of it at all. This +// witness asserts that relationship holds on the live roster rather than on a fixture, because a +// sweep that read those keys as namespace containment is precisely how a phantom was manufactured +// in this lane. test fn witness_a_confinement_prefix_key_matches_a_non_descendant_by_string_prefix() -> Bool { let prefix = "v2.workflow.bash" diff --git a/dag/test/claim/realize_pack_witness_test.dag b/dag/test/claim/realize_pack_witness_test.dag index ca09660ba3c..21c0e4e82dc 100644 --- a/dag/test/claim/realize_pack_witness_test.dag +++ b/dag/test/claim/realize_pack_witness_test.dag @@ -13,7 +13,14 @@ import v2.std.live_tree { LiveTreeDisposition, SubstrateInputsOnly } data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data realize_pack_witness_note: String = "P4 v0 ACCEPT: memory-safe realize packing. width = min(independence, budget/derived_bound); packing NEVER exceeds budget by construction (the exit-137 control); a BoundUnknown (underivable) bound -> width-1 maturation reserve; an unreadable budget REFUSES rather than fabricating a width (retires realization_width conservative_fallback_width, the §5 finding). NOTE on realize_packs_within_budget: budget 100 / bound 25 = 4 naive, but memory_bounded_shard_count reserves 20% headroom (effective 80 -> floor(80/25) = 3) — the maturation-reserve margin (admitted demand grows post-admission); the safe pack is 3, and 3*25 = 75 <= 100 leaves the headroom by construction." +// P4 v0 ACCEPT: memory-safe realize packing. width = min(independence, budget/derived_bound); +// packing NEVER exceeds budget by construction (the exit-137 control); a BoundUnknown (underivable) +// bound -> width-1 maturation reserve; an unreadable budget REFUSES rather than fabricating a width +// (retires realization_width conservative_fallback_width, the §5 finding). NOTE on +// realize_packs_within_budget: budget 100 / bound 25 = 4 naive, but memory_bounded_shard_count +// reserves 20% headroom (effective 80 -> floor(80/25) = 3) — the maturation-reserve margin +// (admitted demand grows post-admission); the safe pack is 3, and 3*25 = 75 <= 100 leaves the +// headroom by construction. data budget_100: HostBudget = BudgetReadable { bytes: byte_size(count: 100) } diff --git a/dag/test/claim/record_construction_census_witness_test.dag b/dag/test/claim/record_construction_census_witness_test.dag index 40db11e49e4..b8a325872f3 100644 --- a/dag/test/claim/record_construction_census_witness_test.dag +++ b/dag/test/claim/record_construction_census_witness_test.dag @@ -7,7 +7,32 @@ import v2.std.integer { Int } import v2.std.logic { Bool } import v2.std.text { String } -data record_construction_census_witness_note: String = "Executing consumer for the decl-fact skeleton's record_construction_spelling edge (the marshal capability that grounded the BoundedPoll deletion census, adhoc-429f6982-280). The edge carries the AUTHORED CONSTRUCTOR SPELLING — the AST node's authored lexeme, NOT a resolved declaration identity: no qualified name is resolved, no parent-enum identity is carried, and two same-spelled record types in different modules are indistinguishable at this grain. A census over it is therefore a conservative OVER-APPROXIMATION of construction sites for a spelling, sound for an emptiness verdict ONLY over declarations with at least one field (zero spelling occurrences implies zero record-literal constructions of every declaration with that spelling) and NOT an exact per-declaration authority. A FIELDLESS declaration is INVISIBLE to this edge: bare nullary-variant construction is not an ExprRecordLit — it is a bare atom on a positional edge — so the census returns a VACUOUS zero for it no matter how often it is constructed (nullary_variant_construction_invisible_at_this_edge executes that limit), and a zero over a fieldless declaration must never ground a deletion. BoundedPoll carried fields, so its zero is the sound kind — same_spelling_other_module_counts_toward_bare_target below exposes that over-approximation deliberately rather than papering it. What the named edge does discriminate, structurally: a construction occurrence from a string literal or callee atom spelling the same lexeme (those ride positional edges) and from a match pattern (which marshals no construction spelling at all). Counting is suffix-aware (census_spelling_names_target) because a qualified construction marshals its FULL DOTTED authored spelling — qualified_construction_cannot_hide_target is the executed positive control that qualified syntax cannot hide the target from the count. Resolved constructor identity — the edge carrying the resolved qualified declaration and, for variants, the parent declaration identity — is separate future work, not claimed here. The BoundedPoll deletion itself needs no standing corpus census: with the variant deleted, any future construction is an unresolved name the compile-clean gate refuses, so unwritability is structural and this witness guards the census MECHANISM, not the deleted symbol." +// Executing consumer for the decl-fact skeleton's record_construction_spelling edge (the marshal +// capability that grounded the BoundedPoll deletion census, adhoc-429f6982-280). The edge carries +// the AUTHORED CONSTRUCTOR SPELLING — the AST node's authored lexeme, NOT a resolved declaration +// identity: no qualified name is resolved, no parent-enum identity is carried, and two same-spelled +// record types in different modules are indistinguishable at this grain. A census over it is +// therefore a conservative OVER-APPROXIMATION of construction sites for a spelling, sound for an +// emptiness verdict ONLY over declarations with at least one field (zero spelling occurrences +// implies zero record-literal constructions of every declaration with that spelling) and NOT an +// exact per-declaration authority. A FIELDLESS declaration is INVISIBLE to this edge: bare +// nullary-variant construction is not an ExprRecordLit — it is a bare atom on a positional edge — +// so the census returns a VACUOUS zero for it no matter how often it is constructed +// (nullary_variant_construction_invisible_at_this_edge executes that limit), and a zero over a +// fieldless declaration must never ground a deletion. BoundedPoll carried fields, so its zero is +// the sound kind — same_spelling_other_module_counts_toward_bare_target below exposes that +// over-approximation deliberately rather than papering it. What the named edge does discriminate, +// structurally: a construction occurrence from a string literal or callee atom spelling the same +// lexeme (those ride positional edges) and from a match pattern (which marshals no construction +// spelling at all). Counting is suffix-aware (census_spelling_names_target) because a qualified +// construction marshals its FULL DOTTED authored spelling — +// qualified_construction_cannot_hide_target is the executed positive control that qualified syntax +// cannot hide the target from the count. Resolved constructor identity — the edge carrying the +// resolved qualified declaration and, for variants, the parent declaration identity — is separate +// future work, not claimed here. The BoundedPoll deletion itself needs no standing corpus census: +// with the variant deleted, any future construction is an unresolved name the compile-clean gate +// refuses, so unwritability is structural and this witness guards the census MECHANISM, not the +// deleted symbol. type CensusConstructionCount { constructions: Int diff --git a/dag/test/claim/record_decl_spelling_identity_witness_test.dag b/dag/test/claim/record_decl_spelling_identity_witness_test.dag index f632c2502fe..64bb3664866 100644 --- a/dag/test/claim/record_decl_spelling_identity_witness_test.dag +++ b/dag/test/claim/record_decl_spelling_identity_witness_test.dag @@ -13,7 +13,24 @@ import v2.std.node { Node, Symbol } import v2.std.node_query { find_named_child } import gunbc.compile_diagnostic_census { CensusObserved, CensusNotRunnable, census_blocking_rows } -data record_decl_spelling_identity_note: String = "TWO SPELLINGS OF ONE DECLARATION MUST CARRY ONE SHAPE. `type X { a: A, b: B }` and `type X = \{ a: A, b: B \}` both declare a named record, and before the parse fix this witness defends they produced two different item shapes: the brace form hoisted the fields onto the declaration (Conj, children = fields), the `=` form left them inside an ANONYMOUS record type-expression and gave the declaration no children at all. Downstream that anonymous 2-child Conj is indistinguishable from a positional pair, which is what the Rust emitter rendered it as -- `pub type TranslateFoldAcc = (Rc, Rc)` -- while the SAME emitter kept writing `TranslateFoldAcc \{ source: .., rebuilt: .. \}` at construction and `.source`/`.rebuilt` at every read. Accepted with 0 diagnostics; refused by rustc as E0071 plus six E0609 on the 03_ingest board of 2026-08-23. WHY THIS GRAIN AND NOT AN EMIT CHECK: the defect emits no diagnostic, so `compile_dag_rust_emit_check` (which collapses a compile to a count of hard diagnostics) is green on both arms and cannot see it; and no builtin returns emitted target text. `decl_facts` returns the parsed declaration itself, which is exactly where the fork lived, so the assertion is made at the grain of the fix rather than two stages downstream of it. WHAT MAKES IT DISCRIMINATING: `concept_decl_node` marshals a NoConnective item to a UNIT node, so on the pre-fix parser the `=` arm resolves its fact and then finds no named child `first` -- red -- while the brace arm is green, and the alias control below is red-if-widened. dissolve-on: never -- permanent regression control for the spelling-identity law in type-declaration position." +// TWO SPELLINGS OF ONE DECLARATION MUST CARRY ONE SHAPE. `type X { a: A, b: B }` and `type X = { a: +// A, b: B }` both declare a named record, and before the parse fix this witness defends they +// produced two different item shapes: the brace form hoisted the fields onto the declaration (Conj, +// children = fields), the `=` form left them inside an ANONYMOUS record type-expression and gave +// the declaration no children at all. Downstream that anonymous 2-child Conj is indistinguishable +// from a positional pair, which is what the Rust emitter rendered it as -- `pub type +// TranslateFoldAcc = (Rc, Rc)` -- while the SAME emitter kept writing `TranslateFoldAcc +// { source: .., rebuilt: .. }` at construction and `.source`/`.rebuilt` at every read. Accepted +// with 0 diagnostics; refused by rustc as E0071 plus six E0609 on the 03_ingest board of +// 2026-08-23. WHY THIS GRAIN AND NOT AN EMIT CHECK: the defect emits no diagnostic, so +// `compile_dag_rust_emit_check` (which collapses a compile to a count of hard diagnostics) is green +// on both arms and cannot see it; and no builtin returns emitted target text. `decl_facts` returns +// the parsed declaration itself, which is exactly where the fork lived, so the assertion is made at +// the grain of the fix rather than two stages downstream of it. WHAT MAKES IT DISCRIMINATING: +// `concept_decl_node` marshals a NoConnective item to a UNIT node, so on the pre-fix parser the `=` +// arm resolves its fact and then finds no named child `first` -- red -- while the brace arm is +// green, and the alias control below is red-if-widened. dissolve-on: never -- permanent regression +// control for the spelling-identity law in type-declaration position. data qn_brace_spelling: String = "test.fixture.record_decl_spelling.specimens.RecordDeclBraceSpelling" data qn_equals_spelling: String = "test.fixture.record_decl_spelling.specimens.RecordDeclEqualsSpelling" @@ -52,9 +69,27 @@ test fn leaf_alias_is_not_read_as_a_record() -> Bool { !record_decl_spelling_has_named_field(qn: qn_leaf_alias, field: ^first) } - - -data record_decl_spelling_sole_constructor_note: String = "THE FIELDS ARE NOT THE WHOLE DECLARATION, and unifying them left one thing still forked. `parse_type_body_from_prefix` reads the `sole_constructor` modifier and consumes its tokens BEFORE it branches on `\{` versus `=`; the brace branch then builds the property and the `=` branch called `parse_type_body_after_eq`, which did not take the flag at all. Before the fields were hoisted that cost nothing -- the `=` form produced an alias, and nobody expects a construction wall on an alias. After the hoist it produced a record declaration identical to the brace form in every observable respect EXCEPT the missing wall, so `type X sole_constructor = \{ .. \}` would parse to an unsealed record while its source says sealed: a modifier written, consumed and silently dropped, which is the fabricated-plausible-output shape at the source boundary and precisely the mechanism DESIGN section 4b names as the live capability for carrier-borne invariants. Live exposure was zero -- no `type ... sole_constructor = \{` is authored anywhere in dag/ or src/v2/ -- so this is a hole closed before anything fell in it, not a repair of an observed loss. The flag is now threaded through to `type_item_from_alias_rhs`, which builds the same property, rather than the `=` form refusing the modifier: refusing would have re-introduced a spelling-dependent rule two lines after one was deleted. WHY THESE ROWS AND NOT A decl_facts ROW like their siblings above: `concept_decl_node` marshals a declaration's CHILDREN and not its properties, so the seal is invisible at that grain -- the wall is observable only where it fires, which is a cross-module record literal. `nominal_opaque` rides the same modifier path and is ALSO dropped, but it is dropped for BOTH spellings and is recorded nowhere by either, so it is not a fork this change opens and is not repaired here. dissolve-on: never -- permanent regression control." +// THE FIELDS ARE NOT THE WHOLE DECLARATION, and unifying them left one thing still forked. +// `parse_type_body_from_prefix` reads the `sole_constructor` modifier and consumes its tokens +// BEFORE it branches on `{` versus `=`; the brace branch then builds the property and the `=` +// branch called `parse_type_body_after_eq`, which did not take the flag at all. Before the fields +// were hoisted that cost nothing -- the `=` form produced an alias, and nobody expects a +// construction wall on an alias. After the hoist it produced a record declaration identical to the +// brace form in every observable respect EXCEPT the missing wall, so `type X sole_constructor = { +// .. }` would parse to an unsealed record while its source says sealed: a modifier written, +// consumed and silently dropped, which is the fabricated-plausible-output shape at the source +// boundary and precisely the mechanism DESIGN section 4b names as the live capability for +// carrier-borne invariants. Live exposure was zero -- no `type ... sole_constructor = {` is +// authored anywhere in dag/ or src/v2/ -- so this is a hole closed before anything fell in it, not +// a repair of an observed loss. The flag is now threaded through to `type_item_from_alias_rhs`, +// which builds the same property, rather than the `=` form refusing the modifier: refusing would +// have re-introduced a spelling-dependent rule two lines after one was deleted. WHY THESE ROWS AND +// NOT A decl_facts ROW like their siblings above: `concept_decl_node` marshals a declaration's +// CHILDREN and not its properties, so the seal is invisible at that grain -- the wall is observable +// only where it fires, which is a cross-module record literal. `nominal_opaque` rides the same +// modifier path and is ALSO dropped, but it is dropped for BOTH spellings and is recorded nowhere +// by either, so it is not a fork this change opens and is not repaired here. dissolve-on: never -- +// permanent regression control. data qn_sealed_brace_probe_source: String = "module record_decl_sealed_brace_probe\n\nimport test.fixture.record_decl_spelling.sealed \{ SealedBraceSpelling \}\n\nfn forge() -> SealedBraceSpelling \{\n SealedBraceSpelling \{ n: 1 \}\n\}\n" diff --git a/dag/test/claim/record_literal_call_arg_handoff_witness_test.dag b/dag/test/claim/record_literal_call_arg_handoff_witness_test.dag index df1189a7658..dd030362011 100644 --- a/dag/test/claim/record_literal_call_arg_handoff_witness_test.dag +++ b/dag/test/claim/record_literal_call_arg_handoff_witness_test.dag @@ -4,7 +4,18 @@ import v2.std.live_tree { LiveTreeDisposition, SubstrateInputsOnly } data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data record_literal_call_arg_handoff_witness_note: String = "Permanent regression control for PR #8262 record-literal call-arg handoff. direct_call_arg_mismatch_diags skips record-literal actuals; direct_call_structured_application_mismatch_diags must still refuse every mismatch the legacy path refused for that shape. Pair 1 (nominal-at-literal): Box at Node param — diagnostics_witness record_literal_field_walls carries it on the production compile path. Pair 2 (resolved-type legacy): warm-fox Cons/FreeMonoid at inline sole_constructor NormalizedTree in compile_dag_rust_emit_check — the shape main's legacy path refused before the skip. On the current base v2.compiler.normalized_tree is still type NormalizedTree = Node, so the same call on the production compile path stays green because it is Node-at-Node, not because the check is complete; when gunbc#8256 lands the sealed carrier (type NormalizedTree sole_constructor { root: Node }), that call becomes a genuine nominal mismatch and warm-fox measured it compile-clean on the production path — open BL-1 typecheck residue, not enrolled as correct behavior here." +// Permanent regression control for PR #8262 record-literal call-arg handoff. +// direct_call_arg_mismatch_diags skips record-literal actuals; +// direct_call_structured_application_mismatch_diags must still refuse every mismatch the legacy +// path refused for that shape. Pair 1 (nominal-at-literal): Box at Node param — diagnostics_witness +// record_literal_field_walls carries it on the production compile path. Pair 2 (resolved-type +// legacy): warm-fox Cons/FreeMonoid at inline sole_constructor NormalizedTree in +// compile_dag_rust_emit_check — the shape main's legacy path refused before the skip. On the +// current base v2.compiler.normalized_tree is still type NormalizedTree = Node, so the same call on +// the production compile path stays green because it is Node-at-Node, not because the check is +// complete; when gunbc#8256 lands the sealed carrier (type NormalizedTree sole_constructor { root: +// Node }), that call becomes a genuine nominal mismatch and warm-fox measured it compile-clean on +// the production path — open BL-1 typecheck residue, not enrolled as correct behavior here. fn w_nominal_record_at_call_arg_red() -> Bool { compile_dag_rust_emit_check( diff --git a/dag/test/claim/reference_derived_authored_source_gate_witness_test.dag b/dag/test/claim/reference_derived_authored_source_gate_witness_test.dag index e4acf930e55..4412468f2ed 100644 --- a/dag/test/claim/reference_derived_authored_source_gate_witness_test.dag +++ b/dag/test/claim/reference_derived_authored_source_gate_witness_test.dag @@ -1,6 +1,26 @@ module test.claim.reference_derived_authored_source_gate_witness_test -data reference_derived_authored_source_gate_witness_note: String = "Discriminating controls for the authored-source gate law inside reference_derived_use_lines (production authority: v1.compiler.emit_rust.reference_derived_candidate_spelled_in_module). Floor compile-clean's witness_layer_roots do not close over src/v1, so this witness cannot import that module without an unresolved-import hard diagnostic; the oracle below is the same total predicate (module_source != \"\" && string_contains) and must stay identical to the production fn. SCOPE, so this file is not read as the whole gate: reference_derived_candidate_spelled_in_module is the DIRECT arm only. Since Root K the gate decision is reference_derived_candidate_authored, a disjunction of this arm and a variant-induced arm that admits a unit-only enum whose variant is spelled and binds unambiguously back to it; that second arm and its homonym refusal are witnessed separately in reference_derived_variant_induced_parent_gate_witness_test.dag. Extending THIS oracle to cover it would fork the second witness rather than complete this one. GREEN: a name spelled in module source is admitted. RED: AuthoredTokenOrdinal-shaped over-collection against an http_path-like source that never mentions it is refused — the exact fabrication that previously emitted pub use crate::std_occurrence_binding_candidates::AuthoredTokenOrdinal from std.http_path with no .dag authority. Empty source refuses all (fail-closed). Integration receipt (quiet-hawk): regen without hand-pinning std_http_path.rs on a tree that enrolls occurrence-binding candidates must leave AuthoredTokenOrdinal absent, and the generated stage0 crate must build green. Dissolve-on: (1) derive use-lines from BoundReferenceProvider / P2a candidate-producer — this text-presence gate is interim; (2) floor compile-clean closes over src/v1 for this import OR the predicate lives in a dag-reachable shared module — then delete the local oracle and import the production symbol." +// Discriminating controls for the authored-source gate law inside reference_derived_use_lines +// (production authority: v1.compiler.emit_rust.reference_derived_candidate_spelled_in_module). +// Floor compile-clean's witness_layer_roots do not close over src/v1, so this witness cannot import +// that module without an unresolved-import hard diagnostic; the oracle below is the same total +// predicate (module_source != "" && string_contains) and must stay identical to the production fn. +// SCOPE, so this file is not read as the whole gate: reference_derived_candidate_spelled_in_module +// is the DIRECT arm only. Since Root K the gate decision is reference_derived_candidate_authored, a +// disjunction of this arm and a variant-induced arm that admits a unit-only enum whose variant is +// spelled and binds unambiguously back to it; that second arm and its homonym refusal are witnessed +// separately in reference_derived_variant_induced_parent_gate_witness_test.dag. Extending THIS +// oracle to cover it would fork the second witness rather than complete this one. GREEN: a name +// spelled in module source is admitted. RED: AuthoredTokenOrdinal-shaped over-collection against an +// http_path-like source that never mentions it is refused — the exact fabrication that previously +// emitted pub use crate::std_occurrence_binding_candidates::AuthoredTokenOrdinal from std.http_path +// with no .dag authority. Empty source refuses all (fail-closed). Integration receipt (quiet-hawk): +// regen without hand-pinning std_http_path.rs on a tree that enrolls occurrence-binding candidates +// must leave AuthoredTokenOrdinal absent, and the generated stage0 crate must build green. +// Dissolve-on: (1) derive use-lines from BoundReferenceProvider / P2a candidate-producer — this +// text-presence gate is interim; (2) floor compile-clean closes over src/v1 for this import OR the +// predicate lives in a dag-reachable shared module — then delete the local oracle and import the +// production symbol. fn authored_source_gate_oracle(module_source: String, name: String) -> Bool { module_source != "" && string_contains(s: module_source, pattern: name) diff --git a/dag/test/claim/reference_instrument_witness_test.dag b/dag/test/claim/reference_instrument_witness_test.dag index 42aee0bd55d..ad1e20f8b41 100644 --- a/dag/test/claim/reference_instrument_witness_test.dag +++ b/dag/test/claim/reference_instrument_witness_test.dag @@ -33,7 +33,14 @@ import extdeps.instrument.pip_boy_3000_mk_v { data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data reference_instrument_witness_note: String = "Receipts for the two cited Pip-Boy products and the join over them, RECUT against a direct read of both manuals (2026-08-04). The prior witness set was ten green claims over an inverted attribution, and it is the reason these claims are shaped differently: they read the product rosters and the evidence rows, and the evidence rows point INTO the product modules, so a wrong setting can no longer be consistent with a right attribution. What no in-repo witness can establish is that a quoted wording matches the upstream document — that is a read-path fact, carried as a SourceReadReceipt, and the lesson recorded rather than papered over is that ten structural greens did not make the upstream claim true." +// Receipts for the two cited Pip-Boy products and the join over them, RECUT against a direct read +// of both manuals (2026-08-04). The prior witness set was ten green claims over an inverted +// attribution, and it is the reason these claims are shaped differently: they read the product +// rosters and the evidence rows, and the evidence rows point INTO the product modules, so a wrong +// setting can no longer be consistent with a right attribution. What no in-repo witness can +// establish is that a quoted wording matches the upstream document — that is a read-path fact, +// carried as a SourceReadReceipt, and the lesson recorded rather than papered over is that ten +// structural greens did not make the upstream claim true. fn setting_present(wanted: String) -> Bool { fold(pip_boy_3000_settings, init: false, f: (acc, row) => @@ -129,7 +136,12 @@ test fn witness_buoyant_drift_is_originated_not_cited() -> Bool { && !axis_is_cited_on(axis: BuoyantDrift, subject: pip_boy_mk_v_subject) } -data provenance_control_note: String = "PERMANENT REGRESSION CONTROL, not a validator. The XOR that this claim's predecessor checked is now unwritable — axis_provenance is an exhaustive match over a closed coproduct, so an axis with both provenance kinds or with none has no constructor — and DESIGN section 4b(4) keeps the evidence enrolled when the production check dissolves, because deleting it would recreate specification-without-execution one rung up. What it asserts now is the READ: which arm each axis actually lands on." +// PERMANENT REGRESSION CONTROL, not a validator. The XOR that this claim's predecessor checked is +// now unwritable — axis_provenance is an exhaustive match over a closed coproduct, so an axis with +// both provenance kinds or with none has no constructor — and DESIGN section 4b(4) keeps the +// evidence enrolled when the production check dissolves, because deleting it would recreate +// specification-without-execution one rung up. What it asserts now is the READ: which arm each axis +// actually lands on. test fn witness_each_axis_lands_on_its_expected_provenance_arm() -> Bool { return provenance_is_cited(a: OpticalInstability) diff --git a/dag/test/claim/reference_realization_witness_test.dag b/dag/test/claim/reference_realization_witness_test.dag index 99c8a55c044..a996b6b013b 100644 --- a/dag/test/claim/reference_realization_witness_test.dag +++ b/dag/test/claim/reference_realization_witness_test.dag @@ -37,12 +37,12 @@ data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly // // reference_realization_from_ground answering Derived{InlineTargetRepresentation} for // ProviderIsOpaque -> w_opaque_provider_preserves_the_provider_declaration and -// w_mode_is_derived_from_the_ground_and_never_authored_beside_it. Two rows, and they are not -// redundant: the first asserts the roster's opaque row reaches the preserve arm through the -// whole join, the second asserts the derivation itself, with no roster in the picture. +// w_mode_is_derived_from_the_ground_and_never_authored_beside_it. Two rows, not redundant: +// the first asserts the roster's opaque row reaches the preserve arm through the whole join, +// the second asserts the derivation itself, with no roster in the picture. // // the ReferenceRealizationUndeclared arm of reference_position_rendering answering -// RenderTargetRepresentation instead of refusing -- which is precisely what the emitter does today +// RenderTargetRepresentation instead of refusing -- precisely what the emitter does today // -> only w_undeclared_provider_refuses_instead_of_inlining and // w_a_second_declaration_of_the_same_spelling_does_not_inherit_the_row // @@ -55,18 +55,18 @@ data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly // deleting the std.integer Int row from reference_realization_policy_rows // -> only w_target_primitive_provider_inlines_the_checkpoints_own_spelling // -// A perturbation that turns nothing red means the row agrees with the shape rather than testing the -// decision; one that turns several red means the rows are not independent, unless the two rows are -// asserting the same decision at two altitudes and the entry above says which. +// A perturbation that turns nothing red means the row agrees with the shape rather than testing +// the decision; one that turns several red means the rows are not independent, unless the two rows +// assert the same decision at two altitudes and the entry above says which. // // THE PROCEDURE WAS RUN, in one dispatch, on this branch: the unperturbed tree exits 0 with no -// output, and each of the five perturbations above exits 1 naming exactly the rows written beside -// it. That is stated as a receipt for the arms below, not as a standing measurement -- rerun the -// procedure rather than trusting this sentence, which is why it is written as one. +// output, and each of the five perturbations exits 1 naming exactly the rows written beside it. A +// receipt for the arms below, not a standing measurement -- rerun the procedure rather than +// trusting this sentence. -// A FIXTURE CHECKPOINT, not a claim about any target's table. It exists so a Realized decision can be -// handed to the join with a spelling that is visibly the fixture's own, which is what lets the -// inline row assert that the SPELLING TRAVELLED rather than that some inline arm was taken. +// A FIXTURE CHECKPOINT, not a claim about any target's table. It lets a Realized decision be handed +// to the join with a spelling that is visibly the fixture's own, so the inline row can assert that +// the SPELLING TRAVELLED rather than that some inline arm was taken. fn fixture_checkpoint(dag_name: String, target_type: String) -> TypeCheckpoint { TypeCheckpoint { dag_name: dag_name, @@ -82,10 +82,9 @@ fn fixture_realized(dag_name: String, target_type: String) -> TypeRealizationDec Realized { checkpoint: fixture_checkpoint(dag_name: dag_name, target_type: target_type) } } -// One tag per rendering arm, so a row asserts WHICH arm was taken rather than merely that some -// non-refusal happened. The refusal arms carry their own cause in the tag for the same reason: the -// three refusals have three owners and a row that could not tell them apart would pass on the wrong -// one. +// One tag per rendering arm, so a row asserts WHICH arm was taken rather than that some non-refusal +// happened. The refusal arms carry their cause in the tag for the same reason: three refusals have +// three owners, and a row that could not tell them apart would pass on the wrong one. fn rendering_tag(rendering: ReferencePositionRendering) -> String { match rendering { RenderProviderDeclarationByPolicy => "preserve-by-policy" @@ -129,8 +128,8 @@ test fn w_target_primitive_provider_inlines_the_checkpoints_own_spelling() -> Bo == "inline:i64" } -// THE CONTROL FOR WHAT THE EMITTER DOES TODAY. A provider with no authored row is handed a perfectly -// good Realized decision, and the answer is a refusal naming the provider rather than the checkpoint +// THE CONTROL FOR WHAT THE EMITTER DOES TODAY. A provider with no authored row is handed a good +// Realized decision, and the answer is a refusal naming the provider rather than the checkpoint // spelling. If this row ever reads inline:..., the model has adopted the artifact's silent policy. test fn w_undeclared_provider_refuses_instead_of_inlining() -> Bool { policy_tag(module_path: "v2.std.diagnostic", decl_name: "Diagnostics", dag_name: "Diagnostics", target_type: "String") @@ -148,8 +147,8 @@ test fn w_a_second_declaration_of_the_same_spelling_does_not_inherit_the_row() - // THE THIRD GROUND STATE, authored here because no corpus row carries it: a provider examined and // found to hold neither deciding ground. The refusal is its own arm, distinct from the undeclared -// refusal above -- somebody looked and neither ground held is not the same fact as nobody having -// looked, and the two have different remedies. +// refusal above -- somebody looked and neither held is not the same fact as nobody having looked, +// and the two have different remedies. test fn w_examined_ground_that_decides_neither_mode_refuses_as_its_own_state() -> Bool { rendering_tag( rendering: reference_position_rendering( diff --git a/dag/test/claim/regen_receipt_prior_reference_witness_test.dag b/dag/test/claim/regen_receipt_prior_reference_witness_test.dag index 082d8706815..eec17380e6e 100644 --- a/dag/test/claim/regen_receipt_prior_reference_witness_test.dag +++ b/dag/test/claim/regen_receipt_prior_reference_witness_test.dag @@ -6,20 +6,19 @@ import gunbc.regen_receipt { RegenReceipt, PriorReceiptRef, FirstGeneration, Fix // WHAT THIS WITNESS COVERS, AND WHAT IT DOES NOT — stated first because the gap is the point. // // COVERS: the model predicate. A FixedPoint receipt whose prior reference names a DIFFERENT tree -// is distinguishable from one that names the same tree, decidably, from the carrier alone. +// is distinguishable from one naming the same tree, decidably, from the carrier alone. // // DOES NOT COVER: the host refusal arm in required_regen_host run_required_regen_fixed_point. -// That arm compares the on-disk prior receipt against git HEAD and returns an Err, and reaching it +// That arm compares the on-disk prior receipt against git HEAD and returns an Err; reaching it // requires planting a receipt file at target/stage0-regen-receipt.json with a chosen commit_sha -// before invoking the binary. No witness form available here writes a file before running a -// process, so the host arm has no executing evidence and I am not claiming otherwise. Its -// next-rung trigger is a witness form that can stage a fixture file for a wet run; until then the -// host arm rests on review, which is strictly weaker than this predicate does. +// before invoking the binary. No witness form here writes a file before running a process, so the +// host arm has no executing evidence and none is claimed. Its next-rung trigger is a witness form +// that can stage a fixture file for a wet run; until then the host arm rests on review, strictly +// weaker than this predicate. // -// The reason the predicate is worth having anyway is that it is the SAME question the host asks. -// If the model says a cross-tree reference is detectable and the host later stops checking, the -// disagreement is between two things that both exist, rather than a rule that lives only in one -// unexecuted comment. +// The predicate is worth having anyway because it is the SAME question the host asks. If the model +// says a cross-tree reference is detectable and the host later stops checking, the disagreement is +// between two things that both exist, not a rule living only in one unexecuted comment. data same_tree_sha: String = "bd239370923f0000000000000000000000000000" @@ -45,9 +44,9 @@ fn a_fixed_point_receipt(ran_at: String, referenced_at: String) -> RegenReceipt } } -// POSITIVE CONTROL. Without this, the RED below is satisfied by a predicate that returns false -// unconditionally — which is the failure mode that cost me a broken instrument earlier today, one -// that printed the right answer while being incapable of printing any other. +// POSITIVE CONTROL. Without this, the RED below is satisfied by a predicate returning false +// unconditionally — the failure mode that cost a broken instrument earlier today, one that +// printed the right answer while being incapable of printing any other. test fn a_fixed_point_receipt_referencing_its_own_tree_is_same_tree() -> Bool { prior_reference_is_same_tree( receipt: a_fixed_point_receipt(ran_at: same_tree_sha, referenced_at: same_tree_sha) @@ -83,15 +82,14 @@ test fn a_first_generation_receipt_has_no_cross_tree_reference() -> Bool { // THE REFUSED VARIANT, AND WHAT THESE TWO WITNESSES CAN AND CANNOT ESTABLISH. // -// The wall itself is the TYPE's shape, not these tests: Refused declares no digest fields and no +// The wall is the TYPE's shape, not these tests: Refused declares no digest fields and no // first_generation_equal, so a refusal has nothing to invent and the invalid receipt has no -// constructor. That is DESIGN 4b structural impossibility and it needs no witness to hold — an -// attempt to write the fabricated Bool does not typecheck, so there is no runtime state for an -// assertion to catch. +// constructor -- DESIGN 4b structural impossibility, needing no witness: writing the fabricated +// Bool does not typecheck, so there is no runtime state for an assertion to catch. // -// What these witnesses ARE for is the thing the shape alone does not give: executing evidence -// that the shape is the one claimed, so a later edit that quietly restores an equality field to -// this variant has to pass something that runs. They are enrolled where the host's own unit tests +// What these witnesses ARE for is what the shape alone does not give: executing evidence that the +// shape is the one claimed, so a later edit that quietly restores an equality field to this +// variant has to pass something that runs. They are enrolled where the host's own unit tests // currently are not. fn a_refused_receipt() -> RegenReceipt { diff --git a/dag/test/claim/remote_shell_command_witness_test.dag b/dag/test/claim/remote_shell_command_witness_test.dag index 1f85cd06de8..be0afae2070 100644 --- a/dag/test/claim/remote_shell_command_witness_test.dag +++ b/dag/test/claim/remote_shell_command_witness_test.dag @@ -12,7 +12,16 @@ import gunbc.remote_shell_command { Unknown, } -data remote_shell_command_witness_note: String = "Hermetic proof that emit_remote_shell matches the cited IEEE 1003.1-2017 section 2.2.2 single-quote encoding exactly on fixtures, per gunbc.remote_shell_command remote_shell_command_single_quote_encoding_law_note -- an exact-string structural check against each fixture's known-correct encoding, not a round trip through a hand-rolled parser (that design was replaced: it was a self-consistent oracle over this module's own two halves). Fixtures cover a word containing a single quote (exercises the quote-backslash-quote-quote escape), a word containing a space, and a word containing shell metacharacters (both trivial under single-quote wrapping -- the point of the restricted encoding is that these stop being distinct hazards). No live SSH target is touched here -- see remote_exec_command_live_confirmation for the declared, unexecuted remote-side receipt." +// Hermetic proof that emit_remote_shell matches the cited IEEE 1003.1-2017 section 2.2.2 +// single-quote encoding exactly on fixtures, per gunbc.remote_shell_command +// remote_shell_command_single_quote_encoding_law_note -- an exact-string structural check against +// each fixture's known-correct encoding, not a round trip through a hand-rolled parser (that design +// was replaced: it was a self-consistent oracle over this module's own two halves). Fixtures cover +// a word containing a single quote (exercises the quote-backslash-quote-quote escape), a word +// containing a space, and a word containing shell metacharacters (both trivial under single-quote +// wrapping -- the point of the restricted encoding is that these stop being distinct hazards). No +// live SSH target is touched here -- see remote_exec_command_live_confirmation for the declared, +// unexecuted remote-side receipt. fn emitted(argv: List) -> String { match simple_command(argv: argv) { diff --git a/dag/test/claim/render_glyphs_ansi_witness_test.dag b/dag/test/claim/render_glyphs_ansi_witness_test.dag index 8d4a029b4d1..e5517f07236 100644 --- a/dag/test/claim/render_glyphs_ansi_witness_test.dag +++ b/dag/test/claim/render_glyphs_ansi_witness_test.dag @@ -49,7 +49,13 @@ test fn w_success_ansi_is_256_green() -> Bool { } } -data ansi_escape_is_a_real_byte_note: String = "w_success_ansi_is_256_green above compares one \\x1b literal against another, so it agreed with itself for as long as the tokenizer left BOTH undecoded — it passed throughout the period when every colour this repo authored rendered as the literal text backslash-x-1-b (seen in CI run 30167957464's TOP SLOWEST WITNESSES table). Equality against a same-source literal can never discriminate a decode defect. The two witnesses below do: they read the CODE POINT of the first character (27 = ESC, never 92 = backslash) and pin the decoded length, both of which are properties of the decode rather than of the spelling." +// w_success_ansi_is_256_green above compares one \x1b literal against another, so it agreed with +// itself for as long as the tokenizer left BOTH undecoded — it passed throughout the period when +// every colour this repo authored rendered as the literal text backslash-x-1-b (seen in CI run +// 30167957464's TOP SLOWEST WITNESSES table). Equality against a same-source literal can never +// discriminate a decode defect. The two witnesses below do: they read the CODE POINT of the first +// character (27 = ESC, never 92 = backslash) and pin the decoded length, both of which are +// properties of the decode rather than of the spelling. test fn w_ansi_first_char_is_escape_byte() -> Bool { match ansi_code(c: Success) { diff --git a/dag/test/claim/repo_atlas_projection_witness_test.dag b/dag/test/claim/repo_atlas_projection_witness_test.dag index 84b5180e1c8..5ffc254448f 100644 --- a/dag/test/claim/repo_atlas_projection_witness_test.dag +++ b/dag/test/claim/repo_atlas_projection_witness_test.dag @@ -66,7 +66,12 @@ import extdeps.git { TwoDot } -data repo_atlas_witness_note: String = "THE FIXTURES ARE AUTHORED, THE POPULATIONS ARE CONTROLLED, AND THE ORACLES ARE INDEPENDENT OF THE MEASUREMENT. Every count asserted below comes from a planted input — one planted collision, one path planted at two modules, one departed path — not from measuring the live tree and pinning what it happened to say (DESIGN 5, the test-oracle ruling). The live corpus appears in exactly one claim, and there the subject IS the live population's breadth, which is the one case that ruling admits." +// THE FIXTURES ARE AUTHORED, THE POPULATIONS ARE CONTROLLED, AND THE ORACLES ARE INDEPENDENT OF THE +// MEASUREMENT. Every count asserted below comes from a planted input — one planted collision, one +// path planted at two modules, one departed path — not from measuring the live tree and pinning +// what it happened to say (DESIGN 5, the test-oracle ruling). The live corpus appears in exactly +// one claim, and there the subject IS the live population's breadth, which is the one case that +// ruling admits. fn atlas_fixture_comparison() -> AtlasComparison { AtlasComparison { base: "HEAD^", head: "HEAD", relation: TwoDot } @@ -104,7 +109,10 @@ test fn atlas_address_is_a_pure_function_of_identity() -> Bool { atlas_address_eq(a: once, b: twice) } -data atlas_shuffle_note: String = "ACCEPTANCE 2. The same three identities in two different input orders must produce identical addresses. This is the discriminating claim for the whole stability property: a layout pass, a probing collision scheme, or any address that read the population would break here, and nothing else in the suite would notice." +// ACCEPTANCE 2. The same three identities in two different input orders must produce identical +// addresses. This is the discriminating claim for the whole stability property: a layout pass, a +// probing collision scheme, or any address that read the population would break here, and nothing +// else in the suite would notice. test fn atlas_address_is_invariant_under_input_order() -> Bool { let forward = map( @@ -129,7 +137,11 @@ test fn atlas_address_is_invariant_under_input_order() -> Bool { && atlas_address_eq(a: g, b: atlas_address_of_module(identity: ModuleIdentity { name: "fixture.gamma" })) } -data atlas_unrelated_addition_note: String = "ACCEPTANCE 3. Adding an unrelated module to the population must move no existing module. Asserted by computing an address from a one-module world and again from a three-module world: the address function never receives the population at all, so this holds by construction — and the claim exists so that a future refactor which STARTS passing the population reds here instead of silently re-addressing the atlas." +// ACCEPTANCE 3. Adding an unrelated module to the population must move no existing module. Asserted +// by computing an address from a one-module world and again from a three-module world: the address +// function never receives the population at all, so this holds by construction — and the claim +// exists so that a future refactor which STARTS passing the population reds here instead of +// silently re-addressing the atlas. test fn adding_an_unrelated_module_moves_no_existing_module() -> Bool { let alone = atlas_address_of_module(identity: ModuleIdentity { name: "fixture.alpha" }) @@ -159,7 +171,12 @@ test fn two_distinct_identities_colliding_share_one_cell() -> Bool { && atlas_cell_occupant_count(cell: c) == 2) } -data atlas_duplicate_fact_note: String = "THE SEPARATE DUPLICATE-FACT QUESTION, decided and recorded rather than left implicit. Two ModuleDeclarationFact rows naming the SAME ModuleIdentity are one semantic subject observed twice, not two subjects, so they must not raise a cell's occupant count and make the dot read denser. atlas_module_identities deduplicates by identity before cells are built, and this claim pins that: the same identity twice yields one occupant, while the two DISTINCT colliding identities above yield two." +// THE SEPARATE DUPLICATE-FACT QUESTION, decided and recorded rather than left implicit. Two +// ModuleDeclarationFact rows naming the SAME ModuleIdentity are one semantic subject observed +// twice, not two subjects, so they must not raise a cell's occupant count and make the dot read +// denser. atlas_module_identities deduplicates by identity before cells are built, and this claim +// pins that: the same identity twice yields one occupant, while the two DISTINCT colliding +// identities above yield two. test fn a_duplicated_module_fact_does_not_inflate_density() -> Bool { let dup_nodes = [ @@ -171,7 +188,9 @@ test fn a_duplicated_module_fact_does_not_inflate_density() -> Bool { && all(cells, c => atlas_cell_occupant_count(cell: c) == 1) } -data atlas_not_observed_note: String = "THE ARM THAT WAS MISSING. An authored empty diff used to be indistinguishable from no comparison at all; both produced a projection with zero marks. These two claims assert the arms differ, which is the only way the page can honestly say changes not observed." +// THE ARM THAT WAS MISSING. An authored empty diff used to be indistinguishable from no comparison +// at all; both produced a projection with zero marks. These two claims assert the arms differ, +// which is the only way the page can honestly say changes not observed. test fn no_observation_is_not_the_same_state_as_an_empty_comparison() -> Bool { let unobserved = atlas_change_overlay( @@ -209,7 +228,8 @@ test fn an_unbound_head_refuses_the_overlay_with_a_located_cause() -> Bool { } } -data atlas_comparison_identity_claim_note: String = "A projected overlay must carry the endpoints it was computed from, so the readout can print exact provenance rather than the phrase a named revision." +// A projected overlay must carry the endpoints it was computed from, so the readout can print exact +// provenance rather than the phrase a named revision. test fn a_projected_overlay_carries_its_comparison_endpoints() -> Bool { let overlay = atlas_change_overlay( @@ -250,7 +270,8 @@ test fn every_address_falls_inside_the_ring_table() -> Bool { all(addresses, a => a.ring >= 0 && a.ring < 16 && a.slot >= 0) } -data atlas_multi_seed_claim_note: String = "ACCEPTANCE 5. One changed path resolving to SEVERAL modules marks ALL of them. The pool plants two modules at one path; a first-wins projection would mark one and this reds." +// ACCEPTANCE 5. One changed path resolving to SEVERAL modules marks ALL of them. The pool plants +// two modules at one path; a first-wins projection would mark one and this reds. test fn one_path_resolving_to_several_modules_marks_all_of_them() -> Bool { let overlay = atlas_change_overlay( @@ -269,7 +290,10 @@ test fn one_path_resolving_to_several_modules_marks_all_of_them() -> Bool { } } -data atlas_departed_claim_note: String = "ACCEPTANCE 6. A deleted path, and a renamed entry's OLD path, are never resolved against the head. The renamed case is the sharper one: its new path legitimately projects while its old path must land in the readout, so a claim asserting only 'nothing was marked' would pass on a projection that dropped the rename entirely." +// ACCEPTANCE 6. A deleted path, and a renamed entry's OLD path, are never resolved against the +// head. The renamed case is the sharper one: its new path legitimately projects while its old path +// must land in the readout, so a claim asserting only 'nothing was marked' would pass on a +// projection that dropped the rename entirely. test fn a_deleted_path_is_never_resolved_against_the_head() -> Bool { let overlay = atlas_change_overlay( @@ -337,7 +361,11 @@ test fn a_path_declaring_no_module_is_counted_not_dropped() -> Bool { } } -data atlas_refusal_claim_note: String = "ACCEPTANCE 7. Each untrustworthy observation refuses the WHOLE overlay. Every claim below plants the bad entry BESIDE a good one, so a projection that dropped the bad entry and drew the rest would produce AtlasChangesProjected with one mark — visibly different from the refusal asserted here. Without the good neighbour these would pass against an implementation that simply produced an empty projection." +// ACCEPTANCE 7. Each untrustworthy observation refuses the WHOLE overlay. Every claim below plants +// the bad entry BESIDE a good one, so a projection that dropped the bad entry and drew the rest +// would produce AtlasChangesProjected with one mark — visibly different from the refusal asserted +// here. Without the good neighbour these would pass against an implementation that simply produced +// an empty projection. test fn an_unmerged_entry_refuses_the_whole_overlay() -> Bool { let overlay = atlas_change_overlay( @@ -413,7 +441,9 @@ test fn a_truncated_diff_observation_refuses_the_whole_overlay() -> Bool { } } -data atlas_ordinary_statuses_note: String = "The refusal arms above are only honest if the ORDINARY statuses still project. Copied and type-changed are the two that carry no dedicated arm in the projection, so they are the ones a totality mistake would silently swallow." +// The refusal arms above are only honest if the ORDINARY statuses still project. Copied and +// type-changed are the two that carry no dedicated arm in the projection, so they are the ones a +// totality mistake would silently swallow. test fn copied_and_type_changed_entries_still_project() -> Bool { let overlay = atlas_change_overlay( @@ -437,9 +467,12 @@ test fn copied_and_type_changed_entries_still_project() -> Bool { } } -data atlas_copied_source_note: String = "A COPIED entry's old_path still exists at head — the source was not removed — so it must NOT be reported as departed. The claim above asserts zero unprojected changes over a copy carrying an old_path, which is what discriminates 'has an old_path' from 'has a DEPARTED old_path'." +// A COPIED entry's old_path still exists at head — the source was not removed — so it must NOT be +// reported as departed. The claim above asserts zero unprojected changes over a copy carrying an +// old_path, which is what discriminates 'has an old_path' from 'has a DEPARTED old_path'. -data atlas_impact_claim_note: String = "ACCEPTANCE 8 and 9. No impact mark exists without a reading, and a provisional reading cannot present as exact." +// ACCEPTANCE 8 and 9. No impact mark exists without a reading, and a provisional reading cannot +// present as exact. fn atlas_fixture_reading(standing_is_exact: Bool) -> ImpactReading { ImpactReading { @@ -472,7 +505,10 @@ test fn a_provisional_reading_cannot_render_as_exact() -> Bool { && atlas_impact_is_exact(overlay: exact) } -data atlas_empty_reached_note: String = "The discriminating pair for the empty-observation narrow: a reading whose reached set is empty is NOT the same state as no reading at all. Both mark nothing, so a Bool-only consumer cannot tell them apart — which is exactly why the arms are distinct and why this claim asserts the ARM rather than the marking." +// The discriminating pair for the empty-observation narrow: a reading whose reached set is empty is +// NOT the same state as no reading at all. Both mark nothing, so a Bool-only consumer cannot tell +// them apart — which is exactly why the arms are distinct and why this claim asserts the ARM rather +// than the marking. test fn an_empty_reached_set_is_not_the_same_state_as_no_reading() -> Bool { let empty_reading = ImpactReading { @@ -517,7 +553,9 @@ test fn a_snapshot_composes_the_four_facts_without_substitution() -> Bool { structure_present && changes_present && impact_absent } -data atlas_refusal_does_not_erase_structure_note: String = "A refused change overlay must not take the STRUCTURE plane down with it. The four facts are independent, so an untrustworthy diff leaves the atlas drawable with no change marks — which is the honest presentation — rather than blanking the page." +// A refused change overlay must not take the STRUCTURE plane down with it. The four facts are +// independent, so an untrustworthy diff leaves the atlas drawable with no change marks — which is +// the honest presentation — rather than blanking the page. test fn a_refused_overlay_leaves_the_structure_plane_intact() -> Bool { let snapshot = repo_atlas_snapshot( diff --git a/dag/test/claim/repo_ruleset_witness_test.dag b/dag/test/claim/repo_ruleset_witness_test.dag index 1fcd0c94fda..489b43b990f 100644 --- a/dag/test/claim/repo_ruleset_witness_test.dag +++ b/dag/test/claim/repo_ruleset_witness_test.dag @@ -37,20 +37,20 @@ import extdeps.github.rulesets { required_status_check_row, } -// WHAT THESE WITNESSES COVER AND WHAT THEY DO NOT, stated first because the gap is the whole -// reason to read them carefully. The subject here is the PURE half of gunbc.repo_ruleset: the -// desired declaration, the wire projections, and the divergence fold that turns an observation -// into a verdict. Every one of these runs over values authored in this file, so they are -// SubstrateInputsOnly and they execute in the hermetic floor. +// WHAT THESE WITNESSES COVER AND WHAT THEY DO NOT, stated first because the gap is the reason to +// read them carefully. The subject is the PURE half of gunbc.repo_ruleset: the desired +// declaration, the wire projections, and the divergence fold turning an observation into a +// verdict. Every one runs over values authored in this file, so they are SubstrateInputsOnly and +// execute in the hermetic floor. // // THEY SAY NOTHING ABOUT THE LIVE RULESET. Whether GitHub's ruleset currently agrees with desired -// is a fact about the world, answerable only by the read that gunbc.repo_ruleset `verify` performs, -// and a witness asserting it from here would be asserting a value it never observed. That read was -// executed by hand while landing this change -- green against the live ruleset, and RED with a -// planted extra desired context, refusing with `required context missing:` and exit 1 -- and it is -// a route somebody runs, not a gate, exactly as the module's own annotation says. Conflating the -// two would be the rung inflation DESIGN section 4b forbids: these witnesses establish that the -// verdict fold is correct, never that the ruleset is. +// is a fact about the world, answerable only by the read gunbc.repo_ruleset `verify` performs, and +// a witness asserting it from here would assert a value it never observed. That read was executed +// by hand while landing this change -- green against the live ruleset, and RED with a planted +// extra desired context, refusing with `required context missing:` and exit 1 -- and it is a route +// somebody runs, not a gate, as the module's own annotation says. Conflating the two would be the +// rung inflation DESIGN section 4b forbids: these witnesses establish that the verdict fold is +// correct, never that the ruleset is. // THE FACT THE WHOLE CHANGE EXISTS FOR. If this ever goes red, the required context and the job // that publishes it have forked, which is the failure that leaves a check permanently pending @@ -154,12 +154,12 @@ test fn w_RED_a_reader_that_may_bypass_is_a_divergence() -> Bool { && length(divergences_for_bypass(bypass: BypassPullRequestsOnly)) == 1 } -// THE THREE NON-`never` STANDINGS DO NOT RENDER ALIKE, and this is the assertion review 56496's -// finding needed: before the split, all three produced one static sentence, so a witness counting +// THE THREE NON-`never` STANDINGS DO NOT RENDER ALIKE, the assertion review 56496's finding +// needed: before the split, all three produced one static sentence, so a witness counting // divergences stayed green over the collapse. Counting is what a wildcard defeats; DISCRIMINATING -// is what catches it. The two documented grants must name WHICH grant, and an unrecognized -// standing must carry the raw string GitHub sent -- it is the only thing that says what to extend -// the parser with, and a static sentence discards it. +// catches it. The two documented grants must name WHICH grant, and an unrecognized standing must +// carry the raw string GitHub sent -- the only thing that says what to extend the parser with, and +// a static sentence discards it. test fn w_RED_the_three_non_never_bypass_standings_render_differently() -> Bool { let always = render_divergences(ds: divergences_for_bypass(bypass: BypassAlways)) let prs = render_divergences(ds: divergences_for_bypass(bypass: BypassPullRequestsOnly)) diff --git a/dag/test/claim/repository_census_coverage_witness_test.dag b/dag/test/claim/repository_census_coverage_witness_test.dag index 830cfd1025d..a907e0db669 100644 --- a/dag/test/claim/repository_census_coverage_witness_test.dag +++ b/dag/test/claim/repository_census_coverage_witness_test.dag @@ -90,7 +90,13 @@ import v2.std.live_tree { LiveTreeDisposition, SubstrateInputsOnly } data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data coverage_witness_separability_note: String = "EVERY WITNESS HERE ASSERTS ONE PROPERTY, and that is a rule this file was built under rather than a style preference (operator refinement 2026-08-04). A conjunction can only be licensed one conjunct at a time — a discriminating RED credits exactly the conjunct it trips, so one live conjunct can launder several dead ones and the result is indistinguishable from an all-live conjunction. That is only mechanically checkable when the conjuncts are SEPARABLE: a witness whose arms cannot be individually falsified cannot be individually licensed. Splitting them also makes a red self-locating, so a guard that fires is never read as a failure of the property the witness is named for." +// EVERY WITNESS HERE ASSERTS ONE PROPERTY -- a rule this file was built under, not a style +// preference (operator refinement 2026-08-04). A conjunction is licensed one conjunct at a time: a +// discriminating RED credits exactly the conjunct it trips, so one live conjunct can launder +// several dead ones indistinguishably from an all-live conjunction. That is mechanically checkable +// only when conjuncts are SEPARABLE: arms that cannot be individually falsified cannot be +// individually licensed. Splitting also makes a red self-locating, so a firing guard is never read +// as a failure of the named property. fn coverage_witness_decl(name: String) -> DeclarationRef { decl_ref(module_path: "test.claim.repository_census_coverage_witness", decl_name: name) @@ -246,7 +252,10 @@ test fn witness_an_aligned_exact_join_yields_a_receipt() -> Bool { ) } -data coverage_blocker_one_note: String = "BLOCKER 1 WITNESSES. The two populations below differ only in their source roots and the two revisions only in their commit, while the subject keys are spelled IDENTICALLY. Under the first cut both pairs reconciled and the receipt then recorded the mismatched identities beside the exhaustive status. Each of the two mismatch axes gets its own witness so a red names which one broke." +// BLOCKER 1 WITNESSES. The two populations below differ only in source roots and the two revisions +// only in commit, with subject keys spelled IDENTICALLY. Under the first cut both pairs reconciled +// and the receipt recorded the mismatched identities beside the exhaustive status. Each mismatch +// axis gets its own witness so a red names which one broke. test fn witness_a_population_mismatch_refuses_before_any_key_is_compared() -> Bool { match census_resolve_coverage_subjects( @@ -332,7 +341,10 @@ test fn witness_an_aligned_pair_carries_the_identities_the_join_established() -> } } -data coverage_blocker_two_note: String = "BLOCKER 2 WITNESSES. A denominator of A, A against an observation of A has no missing key, no unexpected key and no duplicate among the OBSERVED keys — which is the whole population the first cut looked at. It reconciled. The denominator side is now resolved with its own arm, and the three duplicate shapes each get a witness." +// BLOCKER 2 WITNESSES. A denominator of A, A against an observation of A has no missing, unexpected +// or duplicate key among the OBSERVED keys -- the whole population the first cut looked at -- so it +// reconciled. The denominator side now has its own arm, and the three duplicate shapes each get a +// witness. test fn witness_a_denominator_duplicate_is_located_on_its_own_side() -> Bool { match census_resolve_duplicate_subjects( @@ -439,7 +451,11 @@ test fn witness_an_unexpected_subject_is_located_not_counted() -> Bool { } } -data coverage_cancelling_totals_note: String = "THE CASE A COUNT EQUALITY CANNOT SEE, and the reason this stage reconciles identities instead of totals. A denominator of two subjects against an observation carrying one subject TWICE has equal totals — two against two — while one subject is missing entirely and another is duplicated. The two failures cancel exactly in a sum. Any check comparing sizes reports coverage as complete; the identity join reports both failures, located, and refuses the receipt." +// THE CASE A COUNT EQUALITY CANNOT SEE, and why this stage reconciles identities, not totals. A +// denominator of two subjects against an observation carrying one subject TWICE has equal totals +// -- two against two -- while one subject is missing and another duplicated; the failures cancel +// in a sum. A size check reports complete coverage; the identity join reports both failures, +// located, and refuses the receipt. test fn witness_a_duplicate_and_a_missing_subject_cancel_in_a_total() -> Bool { let denominator_subjects = coverage_witness_ab_subjects @@ -471,7 +487,10 @@ test fn witness_a_duplicate_and_a_missing_subject_do_not_cancel_in_the_join() -> } } -data coverage_blocker_five_note: String = "BLOCKER 5 WITNESSES. Independence is decided from the two runs and then ACTED ON. Three shapes: one run used twice, two invocations of one classifier declaration, and two different classifier declarations. Only the last establishes independence, and the first two still permit a population floor." +// BLOCKER 5 WITNESSES. Independence is decided from the two runs and then ACTED ON. Three shapes: +// one run used twice, two invocations of one classifier declaration, two different classifier +// declarations. Only the last establishes independence; the first two still permit a population +// floor. test fn witness_one_run_used_twice_is_a_shared_run() -> Bool { match census_resolve_independence( @@ -518,13 +537,21 @@ test fn witness_two_distinct_classifiers_establish_independence() -> Bool { ) } -data coverage_blocker_four_note: String = "BLOCKER 4 WITNESSES. A capability receipt exists only when its contract names the classifier that actually ran, checked at identity grain, and when any conformance control it carries names the same classifier at the same revision under a DIFFERENT invocation. Each of those three refusals gets its own witness." +// BLOCKER 4 WITNESSES. A capability receipt exists only when its contract names the classifier that +// actually ran, at identity grain, and any conformance control it carries names the same classifier +// at the same revision under a DIFFERENT invocation. Each of the three refusals gets its own +// witness. fn coverage_witness_capability_for(contract_name: String) -> CensusMethodCapability { ClassifiesDeclaredStructure { contract: coverage_witness_decl(name: contract_name) } } -// THE CONFORMANCE FIXTURES BUILD REAL CONTROL OUTCOMES, because the carrier no longer accepts an assertion about them. Each control here is an actual census_establish_coverage run against a denominator: the discriminating control observes rows that do NOT reconcile with the declared subjects and must come back CoverageRefused, the positive control observes rows that DO and must come back CoverageEstablished. A fixture that simply claimed those two results is no longer expressible, which is the point of the recut. +// THE CONFORMANCE FIXTURES BUILD REAL CONTROL OUTCOMES, because the carrier no longer accepts an +// assertion about them. Each control is an actual census_establish_coverage run against a +// denominator: the discriminating control observes rows that do NOT reconcile with the declared +// subjects and must return CoverageRefused; the positive control observes rows that DO and must +// return CoverageEstablished. A fixture merely claiming those results is no longer expressible, +// which is the point of the recut. fn coverage_witness_control_outcome( subjects: List, rows: List, @@ -794,8 +821,21 @@ test fn witness_a_contract_naming_another_declaration_yields_no_capability_recei ) } - -data coverage_cost_receipt_note: String = "THE COST RECEIPT COMPARES TWO REAL POPULATIONS AND COUNTS OPERATIONS, NOT MILLISECONDS. Wall-clock at two sizes is a change detector dominated by host load; an operation count is a property of the code that produced it and reproduces exactly on any machine. The counters are incremented by the production fold itself, so this witness reads back what the real reconciliation did rather than what a mirror of it would have done.\n\nWHY 24 AND 240. 24 is the live confinement-roster population, so the small case is the one this repository actually reconciles today; 240 is ten times it. A quadratic reconciliation answers the tenfold population with roughly a HUNDREDFOLD operation count, a linear one with roughly tenfold, and those two predictions are far enough apart that no tolerance argument is needed to tell them apart. The assertion is on the RATIO rather than on either absolute count, because an absolute count copied out of a current run is a tree-copied literal and would be a change detector in exactly the way DESIGN section 5 rejects.\n\nThe generator is deliberately dull — one distinct key per index, no duplicates — so the ratio measures the reconciliation and not a fixture's own shape." +// THE COST RECEIPT COMPARES TWO REAL POPULATIONS AND COUNTS OPERATIONS, NOT MILLISECONDS. +// Wall-clock at two sizes is a change detector dominated by host load; an operation count is a +// property of the code and reproduces exactly on any machine. The counters are incremented by the +// production fold itself, so this witness reads back what the real reconciliation did, not what a +// mirror would have done. +// +// WHY 24 AND 240. 24 is the live confinement-roster population, the case this repository actually +// reconciles today; 240 is ten times it. A quadratic reconciliation answers tenfold population +// with roughly a HUNDREDFOLD operation count, a linear one with roughly tenfold -- far enough apart +// that no tolerance argument is needed. The assertion is on the RATIO, not either absolute count: +// an absolute count copied from a current run is a tree-copied literal, the change detector DESIGN +// section 5 rejects. +// +// The generator is deliberately dull -- one distinct key per index, no duplicates -- so the ratio +// measures the reconciliation, not the fixture's shape. data coverage_cost_six: List = ["a", "b", "c", "d", "e", "f"] data coverage_cost_four: List = ["p", "q", "r", "s"] @@ -848,7 +888,13 @@ test fn witness_reconciliation_operations_are_nowhere_near_quadratic() -> Bool { large * 4 < small * 100 } -// THE RED CONTROL IS THE QUADRATIC THE RECUT REMOVED, RE-EXPRESSED HERE AND ASSERTED TO FAIL THE SAME TEST. Without it, the ratio assertions above are satisfied by any fixture whose two populations happen to be close in cost, including a broken generator that returns the same list twice — they would be green because nothing varied, not because the reconciliation is linear. This control counts the pairwise scans the old implementation performed, runs it at the same two sizes, and asserts it BREACHES the same tenfold band the real path stays inside. If someone reintroduces the scan, the real assertions red; if the instrument stops discriminating, this one reds. +// THE RED CONTROL IS THE QUADRATIC THE RECUT REMOVED, RE-EXPRESSED HERE AND ASSERTED TO FAIL THE +// SAME TEST. Without it the ratio assertions above are satisfied by any fixture whose two +// populations happen to be close in cost, including a broken generator returning the same list +// twice -- green because nothing varied, not because reconciliation is linear. This control counts +// the pairwise scans the old implementation performed, runs at the same two sizes, and asserts it +// BREACHES the tenfold band the real path stays inside. Reintroduce the scan and the real +// assertions red; if the instrument stops discriminating, this one reds. type CoverageScanTally { matched: Int passed_over: Int @@ -883,9 +929,17 @@ test fn witness_the_pairwise_scan_control_breaches_the_linear_band() -> Bool { large > small * 12 } -data coverage_blocker_three_note: String = "BLOCKER 3 WITNESSES. The ceiling takes no observation parameter, so there is no separately supplied observation that could disagree with the coverage receipt; the observation identity is derived from the outcome. What remains joinable is the capability receipt, and it must name the same classification run the coverage outcome carries or no ceiling exists at all." +// BLOCKER 3 WITNESSES. The ceiling takes no observation parameter, so no separately supplied +// observation can disagree with the coverage receipt; observation identity derives from the +// outcome. What remains joinable is the capability receipt, which must name the same +// classification run the coverage outcome carries or no ceiling exists. -data coverage_conformance_per_observation_note: String = "THE CONFORMANCE IS DERIVED AGAINST THE OBSERVATION'S OWN RUN, and this fixture had to change for that reason. It previously reused one conforming control for every observation, which the carrier now refuses: a conformance receipt records the method run it was derived against, and the capability receipt re-joins on that identity, so a receipt earned against run A cannot be attached to an observation produced by run B. Deriving per observation is what an honest caller does; the fixture was relying on the borrowed-evidence shape the re-join closes." +// THE CONFORMANCE IS DERIVED AGAINST THE OBSERVATION'S OWN RUN, which is why this fixture changed. +// It previously reused one conforming control for every observation; the carrier now refuses that: +// a conformance receipt records the method run it was derived against and the capability receipt +// re-joins on that identity, so a receipt earned against run A cannot attach to an observation from +// run B. Deriving per observation is what an honest caller does; the fixture relied on the +// borrowed-evidence shape the re-join closes. fn coverage_witness_conformance_for( observation: RepositoryCensusObservation, diff --git a/dag/test/claim/repository_convergence_wet_witness_test.dag b/dag/test/claim/repository_convergence_wet_witness_test.dag index e297e3341c6..d412f654bc1 100644 --- a/dag/test/claim/repository_convergence_wet_witness_test.dag +++ b/dag/test/claim/repository_convergence_wet_witness_test.dag @@ -10,22 +10,24 @@ import v2.std.live_tree { LiveTreeDisposition, SubstrateInputsOnly } data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -// FIRST REAL EXECUTION EVIDENCE FOR repository_converge_wet. The fixture is rebuilt for each row -// from ordinary git commands in a fresh mktemp directory. The function under test then performs its -// own ForEachRef/WorktreeList/rev-parse/reflog/write-tree/diff/fetch/update-ref/reset/readback chain; +// FIRST REAL EXECUTION EVIDENCE FOR repository_converge_wet. The fixture is rebuilt per row from +// ordinary git commands in a fresh mktemp directory; the function under test then performs its own +// ForEachRef/WorktreeList/rev-parse/reflog/write-tree/diff/fetch/update-ref/reset/readback chain — // none of those answers is authored by this witness. Hermetic execution must refuse this file. // Local recipe: claim_batch --wet --source-root dag --source-root src/v2 --entry -// dag/test/claim/repository_convergence_wet_witness_test.dag --functions -// detached_primary_transition_executes_and_preserves_packed_loose_refs_and_linked_worktree,already_at_candidate_repairs_a_stale_index,cas_race_is_observed_after_fetch,reset_refusal_after_successful_cas_is_nonzero -data repository_convergence_wet_witness_note: String = "Scratch-repository WET matrix over the real git transport." - -// Record/replay receipt recipe (the setup invocation is stable and its recorded stdout carries the -// original mktemp path into every subsequent operation key): run the function roster above with -// `--wet --record --fixture-store target/repository-convergence-fixtures`; replay the same roster -// with `--hermetic`; then replay against an EMPTY store. The populated replay must pass all rows and -// the empty-store control must refuse every row with `missing recorded fixture`. That asymmetry is -// the proof that replay consumed the recorded observations instead of silently reaching live git. -data repository_convergence_record_replay_control_note: String = "Populated replay passes; empty-store replay refuses every effectful row." +// dag/test/claim/repository_convergence_wet_witness_test.dag --functions : +// detached_primary_transition_executes_and_preserves_packed_loose_refs_and_linked_worktree, +// already_at_candidate_repairs_a_stale_index, cas_race_is_observed_after_fetch, +// reset_refusal_after_successful_cas_is_nonzero +// Scratch-repository WET matrix over the real git transport. + +// Record/replay receipt recipe (the setup invocation is stable; its recorded stdout carries the +// original mktemp path into every subsequent operation key): run the roster above with `--wet +// --record --fixture-store target/repository-convergence-fixtures`; replay the same roster with +// `--hermetic`; then replay against an EMPTY store. The populated replay must pass all rows and the +// empty-store control must refuse every row with `missing recorded fixture` — the asymmetry proving +// replay consumed the recorded observations instead of silently reaching live git. +// Populated replay passes; empty-store replay refuses every effectful row. type ScratchRepository { root: String @@ -92,13 +94,14 @@ fn run_scratch(s: ScratchRepository) -> ProcessExit { repository_converge_wet(repo: s.repo, remote: "origin", base_ref: "refs/remotes/origin/main", candidate: s.candidate) } -// THE WET BOUNDARY RETURNS ProcessExit, NOT RepositoryConvergenceOutcome. These witnesses therefore -// discriminate refusal ownership through repository_convergence_detail's rendered cause. That +// THE WET BOUNDARY RETURNS ProcessExit, NOT RepositoryConvergenceOutcome, so these witnesses +// discriminate refusal ownership through repository_convergence_detail's rendered cause. The // coupling is deliberate: repository_converge_wet consumes the typed outcome internally and exposes -// only the process contract production receives. Pure witnesses separately match the coproduct arms; -// changing human-facing text can red these integration witnesses even when adjudication is intact, -// because the exposed process diagnostic is part of the end-to-end contract being executed here. -data wet_process_exit_discrimination_note: String = "WET assertions inspect the only refusal carrier repository_converge_wet exposes: ProcessExit.reason." +// only the process contract production receives. Pure witnesses separately match the coproduct +// arms; changing human-facing text can red these integration witnesses even with adjudication +// intact, because the exposed process diagnostic is part of the end-to-end contract executed here. +// WET assertions inspect the only refusal carrier repository_converge_wet exposes: +// ProcessExit.reason. fn mutate_scratch(s: ScratchRepository, body: String) -> Bool { shell.Exec.Run( diff --git a/dag/test/claim/required_record_field_omission_witness_test.dag b/dag/test/claim/required_record_field_omission_witness_test.dag index 6554386f06f..f2f9b6f02fd 100644 --- a/dag/test/claim/required_record_field_omission_witness_test.dag +++ b/dag/test/claim/required_record_field_omission_witness_test.dag @@ -15,7 +15,14 @@ import tools.multi_module_compile_fixture { data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data required_record_field_omission_witness_note: String = "Construction control for the v1 NodeOccurrenceIdentity carrier. The negative and positive manifests differ only in whether the required `occurrence_identity` field is supplied. The negative reaches the isolated v1-to-Rust compiler and observes exactly one blocking MissingField row naming occurrence_identity; FixtureInstrumentRefused cannot impersonate that refusal. The positive reaches Rust emission with no diagnostics and a nonempty artifact population. Both measured arms carry nonempty source and compiler digests, binding the receipt to the ordered manifest and running transform. This instrument does not assert interpreter behavior or any non-Rust render target." +// Construction control for the v1 NodeOccurrenceIdentity carrier. The negative and positive +// manifests differ only in whether the required `occurrence_identity` field is supplied. The +// negative reaches the isolated v1-to-Rust compiler and observes exactly one blocking MissingField +// row naming occurrence_identity; FixtureInstrumentRefused cannot impersonate that refusal. The +// positive reaches Rust emission with no diagnostics and a nonempty artifact population. Both +// measured arms carry nonempty source and compiler digests, binding the receipt to the ordered +// manifest and running transform. This instrument does not assert interpreter behavior or any +// non-Rust render target. fn required_record_field_fixture(source: String) -> MultiModuleCompileFixtureOutcome { compile_fixture(MultiModuleCompileFixture { diff --git a/dag/test/claim/required_regen_admission_witness_test.dag b/dag/test/claim/required_regen_admission_witness_test.dag index d677e20b69e..581c4b8d1a0 100644 --- a/dag/test/claim/required_regen_admission_witness_test.dag +++ b/dag/test/claim/required_regen_admission_witness_test.dag @@ -31,13 +31,14 @@ import v2.workflow.required_regen { data witness_note: String = "Discriminating RED controls for the required-regen admission wall: zero planned or executed populations must refuse rather than vacuously agree; a genuine match with independent denominators may admit." -// The population arms above answer 'did the fold compare anything'. These answer -// 'does the fold refuse what it was built to catch' — a committed surface whose -// bytes disagree with the emitter is the stale-mirror class that let main's -// v1_compiler_infer.rs sit behind its own .dag authority through #8513..#8579. -// The refusal must NAME the drifted path, because a bare refusal cannot be -// distinguished from a refusal fired by any of the other seven variants. -data drift_witness_note: String = "Discriminating RED controls for the drift arms: a drifted surface, an emitted/committed population asymmetry, and an unverifiable hand-maintained row must each refuse and name their subject; hand-maintained DRIFT alone must still admit, which is what separates this wall from one that refuses on any non-match." +// The population arms above answer 'did the fold compare anything'; these answer 'does the fold +// refuse what it was built to catch' — a committed surface whose bytes disagree with the emitter +// is the stale-mirror class that let main's v1_compiler_infer.rs sit behind its own .dag authority +// through #8513..#8579. The refusal must NAME the drifted path; a bare refusal is +// indistinguishable from one fired by any of the other seven variants. Discriminating RED controls +// for the drift arms: a drifted surface, an emitted/committed population asymmetry, and an +// unverifiable hand-maintained row must each refuse and name their subject; hand-maintained DRIFT +// alone must still admit — what separates this wall from one refusing on any non-match. test fn witness_zero_planned_population_refuses() -> Bool { match required_regen_sync_admission( @@ -124,13 +125,12 @@ test fn witness_drifted_surface_refuses_naming_the_path() -> Bool { } } -// THE CONFLATION CONTROL. This test used to ASSERT the defect: it required both an -// emitted-with-no-mirror path and a committed-no-longer-emitted path to land in one -// GeneratedDrift list, which is exactly the union refusal that made a module's first landing -// indistinguishable from the emitter losing a surface. It now asserts the opposite — three -// states, three refusals, and no path under a remedy that does not apply to it. Written as a -// separation check rather than a membership check: it fails if ANY of the three lists contains -// a path belonging to another state, which is what a re-fusion would look like. +// THE CONFLATION CONTROL. This test used to ASSERT the defect: it required an emitted-with-no-mirror +// path and a committed-no-longer-emitted path to land in one GeneratedDrift list — the union +// refusal that made a module's first landing indistinguishable from the emitter losing a surface. +// It now asserts the opposite: three states, three refusals, no path under a remedy that does not +// apply to it. Written as a separation check, not membership: it fails if ANY of the three lists +// contains a path belonging to another state, which is what a re-fusion would look like. test fn witness_three_population_states_refuse_separately() -> Bool { match required_regen_sync_admission( generated_outcomes: [ @@ -173,12 +173,11 @@ test fn witness_three_population_states_refuse_separately() -> Bool { } } -// THE ANTI-ADMISSION CONTROL, and it is the one that must never flip. A new surface with no -// committed mirror REFUSES, alone, with nothing else wrong in the run. If someone later decides -// a first mirror should be admitted automatically because the author obviously just added a -// module, this goes red — which is the point, because that same population is what the emitter -// inventing a surface nobody authored looks like, and the two are indistinguishable from the -// populations alone. +// THE ANTI-ADMISSION CONTROL, the one that must never flip. A new surface with no committed mirror +// REFUSES, alone, with nothing else wrong. If a first mirror is later admitted automatically +// because the author obviously just added a module, this goes red — the point, because that same +// population is what the emitter inventing an unauthored surface looks like; the two are +// indistinguishable from the populations alone. test fn witness_new_surface_alone_still_refuses() -> Bool { match required_regen_sync_admission( generated_outcomes: [ @@ -200,15 +199,14 @@ test fn witness_new_surface_alone_still_refuses() -> Bool { } } -// THE DAMAGING-REMEDY CONTROL, and it has two halves that must hold TOGETHER. -// An emitted basename that collides with hand-authored source under a hand-maintained directory -// refuses under its OWN cause, naming the directory -- because the two remedies attached to -// MirrorMissingForEmittedSurface (install the mirror, or investigate an invented surface) both -// destroy hand-authored code when applied to this class. -// The RED half is the second assertion: a genuine orphan mirror in the SAME run must STILL refuse -// as MirrorMissingForEmittedSurface. A fix that silenced the collision by excluding it from the -// compared population would take the orphan with it, and this test would go green on a wall that -// no longer stands. Separation, not membership: neither path may appear under the other's cause. +// THE DAMAGING-REMEDY CONTROL; two halves that must hold TOGETHER. An emitted basename colliding +// with hand-authored source under a hand-maintained directory refuses under its OWN cause, naming +// the directory — both remedies attached to MirrorMissingForEmittedSurface (install the mirror, or +// investigate an invented surface) destroy hand-authored code when applied here. The RED half is +// the second assertion: a genuine orphan mirror in the SAME run must STILL refuse as +// MirrorMissingForEmittedSurface. A fix silencing the collision by excluding it from the compared +// population would take the orphan with it, and this test would green on a fallen wall. +// Separation, not membership: neither path may appear under the other's cause. test fn witness_hand_maintained_collision_refuses_under_its_own_remedy() -> Bool { match required_regen_sync_admission( generated_outcomes: [ @@ -271,10 +269,9 @@ test fn witness_hand_unverifiable_refuses_naming_the_entry() -> Bool { } } -// The near-miss positive control. HandDrifted is one variant away from -// HandUnverifiable and must NOT refuse: hand-maintained drift is expected on a -// clean tree, so a wall that refused here would be refusing on any non-match and -// the RED above would prove nothing about which distinction it draws. +// The near-miss positive control. HandDrifted is one variant from HandUnverifiable and must NOT +// refuse: hand-maintained drift is expected on a clean tree, so a wall refusing here would refuse +// on any non-match and the RED above would prove nothing about which distinction it draws. test fn witness_hand_drift_alone_admits() -> Bool { match required_regen_sync_admission( generated_outcomes: [SurfaceMatches { relative_path: "std_algebra.rs" }], @@ -292,13 +289,18 @@ test fn witness_hand_drift_alone_admits() -> Bool { } } -data production_ordering_witness_note: String = "Discriminating RED controls for the production-before-adjudication ordering. The subject is the one population asymmetry an author can actually cause: a module added to the v1 seed closure emits a mirror the committed tree does not have, so the run REFUSES — and the author's only remedy is the very file the refusing run produced. The pre-#8663 host sequenced that refusal ahead of the write and returned with the tree unwritten, while regen_stage0 (the binary that used to write it unconditionally) had been deleted at the root, so the refusal named a file no route in the repository produced. These controls go red against a carrier whose refusal arms can omit the tree." +// Discriminating RED controls for the production-before-adjudication ordering. The subject is the +// one population asymmetry an author can actually cause: a module added to the v1 seed closure +// emits a mirror the committed tree lacks, so the run REFUSES — and the author's only remedy is the +// very file the refusing run produced. The pre-#8663 host sequenced that refusal ahead of the write +// and returned with the tree unwritten, while regen_stage0 (which used to write it unconditionally) +// had been deleted at the root, so the refusal named a file no route in the repository produced. +// These controls go red against a carrier whose refusal arms can omit the tree. -// THE DISCRIMINATING RED. It is not enough that the asymmetry refuses — the -// pre-existing witness above already proves that. What must hold is that the refusal -// arrives WITH the candidate tree, and that the tree contains the mirror the committed -// population lacks. A carrier that permitted a bare `RequiredRegenSyncRefused` here -// would fail to typecheck this test at all, which is the wall being asserted. +// THE DISCRIMINATING RED. That the asymmetry refuses is already proven above; what must hold is +// that the refusal arrives WITH the candidate tree, containing the mirror the committed population +// lacks. A carrier permitting a bare `RequiredRegenSyncRefused` here would fail to typecheck this +// test at all — the wall being asserted. test fn witness_new_seed_module_refuses_and_carries_the_first_mirror() -> Bool { match required_regen_run( production: CandidateTreeProduced { @@ -328,10 +330,9 @@ test fn witness_new_seed_module_refuses_and_carries_the_first_mirror() -> Bool { } } -// The near-miss control on the other side: emit itself producing nothing is NOT a -// verdict about a tree, so it must land on the one arm that carries none. Without this, -// the test above would be satisfied by a carrier that simply always carries a tree, -// including one it fabricated for a run that produced no files. +// The near-miss control on the other side: emit producing nothing is NOT a verdict about a tree, +// so it lands on the one arm carrying none. Without this, the test above would be satisfied by a +// carrier that always carries a tree, including one fabricated for a run that produced no files. test fn witness_unproduced_run_carries_no_tree_and_names_its_cause() -> Bool { match required_regen_run( production: CandidateTreeUnproduced { cause: EmptyEmitResult }, diff --git a/dag/test/claim/required_regen_obligation_disposition_witness_test.dag b/dag/test/claim/required_regen_obligation_disposition_witness_test.dag index 5c7c1c4e823..aeb2c2bc110 100644 --- a/dag/test/claim/required_regen_obligation_disposition_witness_test.dag +++ b/dag/test/claim/required_regen_obligation_disposition_witness_test.dag @@ -85,9 +85,8 @@ test fn witness_transfer_admits_host_deletion_but_not_carrier_deletion() -> Bool // successor AUTHORITY whose carrier deletion answered false, so the carrier's own terminal state // left two definitions answering for one operation. Asserting the authority arm's admission alone // would stay green if the arms were re-fused with carrier deletion widened to both; asserting the -// realization arm's refusal alone would stay green if they were re-fused the other way. Only the -// arms DIFFERING distinguishes the split from either fusion, which is why the two are compared -// rather than checked. +// realization arm's refusal alone would stay green if re-fused the other way. Only the arms +// DIFFERING distinguishes the split from either fusion, so the two are compared, not checked. test fn witness_the_two_transfers_disagree_on_carrier_deletion() -> Bool { carrier_deletion_admitted(lifecycle: authority_transferred_example) != carrier_deletion_admitted(lifecycle: realization_transferred_example) @@ -107,9 +106,9 @@ test fn witness_fully_discharged_retirement_admits_both_deletions() -> Bool { // A RETIREMENT WHOSE OBLIGATIONS ARE NOT ALL DISCHARGED ADMITS NOTHING, and it is now a separate // ARM rather than a Retired value that has to be inspected. Two earlier revisions could not test -// this at all: a String receipt could claim discharge without exhibiting it, and a discharge LIST -// made "retired" and "not actually retired" the same constructor. It is the exact shape the -// finding is about -- naming a disposition is not proving it. +// this: a String receipt could claim discharge without exhibiting it, and a discharge LIST made +// "retired" and "not actually retired" the same constructor -- the exact shape the finding is +// about: naming a disposition is not proving it. test fn witness_partial_retirement_admits_neither_deletion() -> Bool { host_deletion_admitted(lifecycle: partially_retired_example) == false && carrier_deletion_admitted(lifecycle: partially_retired_example) == false @@ -131,9 +130,9 @@ test fn witness_active_admits_neither_deletion() -> Bool { // GUARD AGAINST THIS RECUT'S OWN FAILURE MODE. An earlier revision concluded the class could not // climb on the strength of ONE refuted route. If routes are marked refuted one at a time, each -// step looking locally reasonable, that impossibility claim returns silently -- so the census must -// go red instead. The exact count also keeps the receipts honest in the other direction: dropping -// the refuted route would erase real measured evidence. +// step locally reasonable, that impossibility claim returns silently -- so the census must go red +// instead. The exact count also keeps the receipts honest the other way: dropping the refuted +// route would erase real measured evidence. test fn witness_no_impossibility_claim_is_reachable() -> Bool { some_derivation_route_remains_unexamined() } @@ -143,11 +142,11 @@ test fn witness_exactly_one_route_is_refuted() -> Bool { } // THE FINDING ITSELF, ASSERTED SO IT EXPIRES LOUDLY. If a conformance relation later lands, this -// goes RED and the census must be revisited rather than standing as a claim about a state that has -// ended. A prior revision asserted this over five transcribed counts; the counts are gone, and the -// claim they were supposed to support is unchanged -- which is the evidence they were not carrying -// it. What replaces them is not a smaller number but a state that cannot go stale, because it -// asserts that nothing relates the two realizations rather than describing how far apart they are. +// goes RED and the census must be revisited rather than stand as a claim about an ended state. A +// prior revision asserted this over five transcribed counts; the counts are gone and the claim +// they supported is unchanged -- evidence they were not carrying it. What replaces them is a state +// that cannot go stale: it asserts that nothing relates the two realizations rather than +// describing how far apart they are. test fn witness_conformance_relation_remains_unobserved() -> Bool { conformance_is_observed(c: required_regen_realization_conformance) == false } @@ -180,9 +179,9 @@ test fn witness_control_table_populates_both_arms() -> Bool { && length(xs: required_regen_closure_membership_controls |> filter(o => o.seed_reachable)) > 0 } -// ABSORPTION'S PREPARED ARM IS WHAT MAKES THE SPLIT A WALL, and this is the witness that would -// have gone red against the naive version. A COMPLETED absorption shares its deletion truth table -// with an authority transfer -- both files go -- so no assertion over the completed arm alone can +// ABSORPTION'S PREPARED ARM IS WHAT MAKES THE SPLIT A WALL, and this witness would have gone red +// against the naive version. A COMPLETED absorption shares its deletion truth table with an +// authority transfer -- both files go -- so no assertion over the completed arm alone can // discriminate the two. The INCOMPLETE arm does: an absorption whose coverage is not demonstrated // admits neither deletion, which authority transfer never does. Asserted as a disagreement for the // same reason the two transfers are: a pair answering false to everything would satisfy separate @@ -218,9 +217,9 @@ test fn witness_no_absorption_gap_admits_any_deletion() -> Bool { // signature written as `fn g()` then ` -> Bool {` refuses with "expected return type annotation // (-> Type)", and the whole module goes unparseable. Executed both ways by warm-hawk-909 on a // controlled pair -- a ONE-CHARACTER name with the break refuses, and the same name with the arrow -// on one line compiles clean -- so LENGTH IS NOT THE TRIGGER, the break is. The name is therefore -// short in order to keep the ARROW on one line, which is the only fact that makes this form parse; -// stating it as "keep names short" would be false and would send the next author looking at naming. +// on one line compiles clean -- so LENGTH IS NOT THE TRIGGER, the break is. The name is short to +// keep the ARROW on one line, the only fact that makes this form parse; "keep names short" would +// be false and would send the next author looking at naming. test fn witness_unproven_and_refuted_absorption_differ_only_on_refutation() -> Bool { host_deletion_admitted(lifecycle: absorption_unproven_example) == host_deletion_admitted(lifecycle: absorption_refuted_example) diff --git a/dag/test/claim/resolved_call_emission_identity_witness_test.dag b/dag/test/claim/resolved_call_emission_identity_witness_test.dag index 2921d33472b..b3fa82a06b5 100644 --- a/dag/test/claim/resolved_call_emission_identity_witness_test.dag +++ b/dag/test/claim/resolved_call_emission_identity_witness_test.dag @@ -4,7 +4,24 @@ import v2.std.live_tree { LiveTreeDisposition, SubstrateInputsOnly } data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data resolved_call_emission_identity_witness_note: String = "PERMANENT REGRESSION CONTROL for post-resolution callable identity at Rust emission (v1.std.core CallTargetIdentity, v1.compiler.infer_lookup resolved_plain_call_target, v1.compiler.emit_rust emit_typed_call). THE DEFECT: a call's target was decided TWICE. Inference resolved the callee with the module's imports in hand; emission then re-decided it from the authored LEAF SPELLING -- map_contains_key(rt_functions(), func) -- at a grain where those imports no longer exist. An explicitly imported v2 declaration whose name collides with a v1_rt bridge name was therefore emitted as the unrelated primitive. That is DESIGN's authority-substitution class: resolution held the answer and a second mechanism answered for it. THE REPAIR: the resolver records what it chose, and emission reads it. WHAT MAKES THESE ROWS DISCRIMINATING RATHER THAN A SNAPSHOT: the positive traps and the negative traps differ only in whether the called name resolves to a declaration, so an emitter that reverted to name matching would flip the imported-declaration rows red while leaving the runtime-primitive rows green, and an emitter that stopped consulting the primitive projection roster at all would do the opposite. Neither direction can be satisfied by editing one arm. map_insert is deliberately unclassified here: v2.std.collection carries both a host-binding row and an authored modeled body and no authority decides which owns a call, so this control consumes the existing projection roster and does not reclassify that specimen. dissolve-on: never -- emission may change target SPELLING, but it may never reintroduce name lookup after source resolution." +// PERMANENT REGRESSION CONTROL for post-resolution callable identity at Rust emission (v1.std.core +// CallTargetIdentity, v1.compiler.infer_lookup resolved_plain_call_target, v1.compiler.emit_rust +// emit_typed_call). THE DEFECT: a call's target was decided TWICE. Inference resolved the callee +// with the module's imports in hand; emission then re-decided it from the authored LEAF SPELLING -- +// map_contains_key(rt_functions(), func) -- at a grain where those imports no longer exist. An +// explicitly imported v2 declaration whose name collides with a v1_rt bridge name was therefore +// emitted as the unrelated primitive. That is DESIGN's authority-substitution class: resolution +// held the answer and a second mechanism answered for it. THE REPAIR: the resolver records what it +// chose, and emission reads it. WHAT MAKES THESE ROWS DISCRIMINATING RATHER THAN A SNAPSHOT: the +// positive traps and the negative traps differ only in whether the called name resolves to a +// declaration, so an emitter that reverted to name matching would flip the imported-declaration +// rows red while leaving the runtime-primitive rows green, and an emitter that stopped consulting +// the primitive projection roster at all would do the opposite. Neither direction can be satisfied +// by editing one arm. map_insert is deliberately unclassified here: v2.std.collection carries both +// a host-binding row and an authored modeled body and no authority decides which owns a call, so +// this control consumes the existing projection roster and does not reclassify that specimen. +// dissolve-on: never -- emission may change target SPELLING, but it may never reintroduce name +// lookup after source resolution. // BOUNDARY CONTROL 1. The real two-String substring primitive has no declaration to resolve to, // so it stays runtime-bound. This is the arm that would go red if the repair had made emission diff --git a/dag/test/claim/resolved_graph_cache_hand_rust_witness_test.dag b/dag/test/claim/resolved_graph_cache_hand_rust_witness_test.dag index 724b0804644..d4160b9fddd 100644 --- a/dag/test/claim/resolved_graph_cache_hand_rust_witness_test.dag +++ b/dag/test/claim/resolved_graph_cache_hand_rust_witness_test.dag @@ -19,7 +19,12 @@ import std.types { Bool, String } import v2.std.algebra { length } import extdeps.filesystem.filesystem_io -data resolved_graph_cache_hand_rust_witness_note: String = "HAND-RUST checkable receipt (reviews 46781/46990): scaffold bind on lookup_verified_probe; full #7534 Rust census (four paths after the #8146 test-suite cutover removed three; per-path net deltas summing to loc_delta_net); consumer bridge defers to materialization_provider_consumer_hand_rust_witness_test.dag. Discriminator rows deleted 2026-08-11 (review 51152) — the module they named was removed by the test-suite cutover and a substring check over the constants proved nothing." +// HAND-RUST checkable receipt (reviews 46781/46990): scaffold bind on lookup_verified_probe; full +// #7534 Rust census (four paths after the #8146 test-suite cutover removed three; per-path net +// deltas summing to loc_delta_net); consumer bridge defers to +// materialization_provider_consumer_hand_rust_witness_test.dag. Discriminator rows deleted +// 2026-08-11 (review 51152) — the module they named was removed by the test-suite cutover and a +// substring check over the constants proved nothing. test fn resolved_graph_cache_hand_rust_scaffold_is_seed_retained() -> Bool { match resolved_graph_cache_hand_rust_scaffold { diff --git a/dag/test/claim/roadmap/roadmap_altitude_witness_test.dag b/dag/test/claim/roadmap/roadmap_altitude_witness_test.dag index 0c2e908e749..3debf6aea87 100644 --- a/dag/test/claim/roadmap/roadmap_altitude_witness_test.dag +++ b/dag/test/claim/roadmap/roadmap_altitude_witness_test.dag @@ -17,7 +17,10 @@ import v2.std.live_tree { LiveTreeDisposition, SubstrateInputsOnly } data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data roadmap_altitude_witness_note: String = "Composition slice 3's receipts: the attention law's derivations proven total and fail-closed, the fold/open decision proven over RENDERED fixtures (a routine section folds, one working member holds it open), the counts wire pinned, and the client expand chain proven derived — each by execution, with the REDs planted as fixtures the same predicates must refuse." +// Composition slice 3's receipts: the attention law's derivations proven total and fail-closed, the +// fold/open decision proven over RENDERED fixtures (a routine section folds, one working member +// holds it open), the counts wire pinned, and the client expand chain proven derived — each by +// execution, with the REDs planted as fixtures the same predicates must refuse. // The law's arms, pinned: finished work is routine, the working set holds, fail and loud expand — and the fail-closed arms are load-bearing, so they are asserted as REDs would be: an unmodeled status and an unmodeled band key must be anomalies, never quietly routine (the absorbing-fallback shape, refused). fn attention_key(a: RowAttention) -> String { @@ -92,7 +95,15 @@ fn open_node() -> RoadmapNode { authored(identity: "rnfx_140ZV0QZTY3R9PTENK99", id: "alt-open", done: false, content: "working item") } -data fold_by_statuses_note: String = "The fold decision proven over the RENDERED page, not the predicate alone: an all-routine section serializes its details WITHOUT the open attribute (folded — the summary band still carries the counts, so nothing is hidden silently), and adding one working member to the same section flips the SAME serialization to open. The two fixtures differ by exactly that member, so the discrimination is located in the status data — hand-curation has no input to reach. Fixture lesson, kept: a done-but-UNSIGNED node renders review (the sign-off gate), and review is WORKING under the law — the operator's pending gesture holds a section open, which is the attention law agreeing with the sign-off discipline rather than a coincidence. Routine therefore requires the signed fixture." +// The fold decision proven over the RENDERED page, not the predicate alone: an all-routine section +// serializes its details WITHOUT the open attribute (folded — the summary band still carries the +// counts, so nothing is hidden silently), and adding one working member to the same section flips +// the SAME serialization to open. The two fixtures differ by exactly that member, so the +// discrimination is located in the status data — hand-curation has no input to reach. Fixture +// lesson, kept: a done-but-UNSIGNED node renders review (the sign-off gate), and review is WORKING +// under the law — the operator's pending gesture holds a section open, which is the attention law +// agreeing with the sign-off discipline rather than a coincidence. Routine therefore requires the +// signed fixture. test fn altitude_routine_section_folds() -> Bool { let folded = doc_html(nodes: [done_signed_node()]) diff --git a/dag/test/claim/roadmap/roadmap_belt_actuate_witness_test.dag b/dag/test/claim/roadmap/roadmap_belt_actuate_witness_test.dag index 76710669117..b1e9145e17c 100644 --- a/dag/test/claim/roadmap/roadmap_belt_actuate_witness_test.dag +++ b/dag/test/claim/roadmap/roadmap_belt_actuate_witness_test.dag @@ -532,12 +532,12 @@ test fn witness_find_node_first_wins_on_duplicate() -> Bool { } // LIVENESS IS DERIVED FROM PROCESS EVIDENCE, NOT FROM A SESSION NAME. The prior pair of -// witnesses asserted that a session row matching the node id IS live, over a helper whose -// worker evidence is the placeholder whose own reason reads "tmux name presence does not -// observe pane liveness or exit". They therefore pinned the defect: a retained dead pane -// answered live, DispatchAlreadyLive returned through the accepted band, and the operator -// got a positive acknowledgement with no agent. RLM-1 re-homed the per-node verdict into the -// shared launch admission's no-live-attempt gate (launch_gate_live); these witnesses follow it. +// witnesses asserted that a session row matching the node id IS live, over a helper whose worker +// evidence is the placeholder whose own reason reads "tmux name presence does not observe pane +// liveness or exit". They pinned the defect: a retained dead pane answered live, DispatchAlreadyLive +// returned through the accepted band, and the operator got a positive acknowledgement with no +// agent. RLM-1 re-homed the per-node verdict into the shared launch admission's no-live-attempt +// gate (launch_gate_live); these witnesses follow it. fn live_gate(live: List, node_id: String) -> LaunchGateVerdict { launch_gate_live(sessions: LaunchSessionsObserved { live: live }, node_id: node_id) } @@ -740,7 +740,15 @@ test fn witness_label_band_cover_reds_on_missing_row() -> Bool { && !label_band_rows_cover(rows: truncated, labels: labels) } -data d4_exemplar_reconcile_note: String = "D4: belt_dispatch_result_exemplars is a HAND roster (one exemplar per BeltDispatchResult arm), enrolled DeclaredFrontier in gunbc.roster_registry. belt_dispatch_status_label's total match walls a new VARIANT at compile time, but nothing ties the exemplar LIST to the variant set — a missed exemplar silently narrows belt_dispatch_all_status_labels AND the component wire-total that reads it, while the live server emits the unmodeled label. This reconciles the exemplar-derived label set against the independent wire-contract pin (the same labels witness_dispatch_status_labels_pin_wire_contract pins), and the RED control proves a missing-variant list reds. Dissolves when inhabitance enumeration or the serve-JSON total match replaces the hand list." +// D4: belt_dispatch_result_exemplars is a HAND roster (one exemplar per BeltDispatchResult arm), +// enrolled DeclaredFrontier in gunbc.roster_registry. belt_dispatch_status_label's total match +// walls a new VARIANT at compile time, but nothing ties the exemplar LIST to the variant set: a +// missed exemplar silently narrows belt_dispatch_all_status_labels AND the component wire-total +// reading it, while the live server emits the unmodeled label. This reconciles the exemplar-derived +// label set against the independent wire-contract pin (the labels +// witness_dispatch_status_labels_pin_wire_contract pins); the RED control proves a missing-variant +// list reds. Dissolves when inhabitance enumeration or the serve-JSON total match replaces the +// hand list. fn d4_wire_contract_labels() -> List { [ @@ -992,7 +1000,15 @@ test fn codex_provider_v0_preflight_keystone_holds() -> Bool { && witness_fresh_spawn_wire_names_selected_provider() } -data oracle_refs_execution_note: String = "This witness exists because its subject SHIPPED BROKEN and a whole-tree compile with 0 blocking errors said otherwise. belt_oracle_refs_for_contract called filter_map, a primitive std.primitives declares a contract for and the seed implements nothing for, so the call type-checked and died as `not yet implemented` the first time a real dispatch reached it — a 500, found on the lab. The lane's other witnesses covered the pure oracle carrier thoroughly and never drove THIS function, which is the whole lesson: a projection that only the effectful path calls needs a witness even when it is itself pure, because purity is what makes it cheap to witness, not what makes it covered. The assertions deliberately RUN the fold and read its output rather than checking a type: a version calling any unregistered primitive fails here at execution, which is the only place that class of defect is observable." +// This witness exists because its subject SHIPPED BROKEN while a whole-tree compile reported 0 +// blocking errors. belt_oracle_refs_for_contract called filter_map, a primitive std.primitives +// declares a contract for and the seed implements nothing for, so the call type-checked and died +// as `not yet implemented` the first time a real dispatch reached it — a 500, found on the lab. +// The lane's other witnesses covered the pure oracle carrier and never drove THIS function: a +// projection only the effectful path calls needs a witness even when pure, because purity makes it +// cheap to witness, not covered. The assertions RUN the fold and read its output rather than +// checking a type: a version calling any unregistered primitive fails here at execution, the only +// place that defect class is observable. test fn oracle_refs_projection_runs_and_selects_pinnable_scopes() -> Bool { let claim_contract = gunbc_claim_execution_contract( @@ -1017,7 +1033,11 @@ test fn oracle_refs_projection_runs_and_selects_pinnable_scopes() -> Bool { } } -data unreadable_receipt_refuses_note: String = "review 45271, updated for exact-head wiring. The belt now observes the worktree head before reading a receipt, so an instance with no attempt filesystem cannot reach the unreadable-receipt arm through a failed legacy read alone. This witness instead drives the real fn against srv2 preview where neither the node nor the worktree exist, and asserts verification defers with an exact-head or missing-node reason rather than actuating against an unobserved subject." +// review 45271, updated for exact-head wiring. The belt now observes the worktree head before +// reading a receipt, so an instance with no attempt filesystem cannot reach the unreadable-receipt +// arm through a failed legacy read alone. This witness drives the real fn against srv2 preview, +// where neither node nor worktree exist, and asserts verification defers with an exact-head or +// missing-node reason rather than actuating against an unobserved subject. data fixture_verification_head: CommitSha = "cafecafecafecafecafecafecafecafecafecafe" as CommitSha @@ -1075,7 +1095,14 @@ fn completed_attempt_progress(node_id: String) -> WorkflowAttemptProgress { }) } -data attempt_wire_carries_decided_activity_note: String = "The A2 single-projection-authority receipt at the wire: each attempt object on /workflow.json carries the DECIDED activity view beside the progress members, so the client paints without composing. The fixture is a completed agent turn with process exited and four pending obligations — the falsifier's own shape — and the assertions pin the decided fields (arm, the consequence-first summary composed by gunbc.roadmap_presentation, the reconcile-derived remaining count, the evidence rows) landing as JSON, plus the progress members surviving beside them. A client that had to rebuild any of these from segments would have nothing to rebuild them FROM being asserted here — the decided strings are the contract." +// The A2 single-projection-authority receipt at the wire: each attempt object on /workflow.json +// carries the DECIDED activity view beside the progress members, so the client paints without +// composing. The fixture is a completed agent turn with process exited and four pending obligations +// — the falsifier's own shape. The assertions pin the decided fields (arm, the consequence-first +// summary composed by gunbc.roadmap_presentation, the reconcile-derived remaining count, the +// evidence rows) landing as JSON, plus the progress members surviving beside them. The decided +// strings are the contract; a client rebuilding any of them from segments has nothing asserted +// here to rebuild FROM. test fn attempt_wire_carries_decided_activity() -> Bool { let j = serialize_json(v: belt_workflow_attempt_presentation_json( @@ -1093,7 +1120,6 @@ test fn attempt_wire_carries_decided_activity() -> Bool { && string_contains(s: j, pattern: "\"segments\": [") } - test fn verify_without_observable_subject_defers_instead_of_rerunning() -> Bool { match belt_verify_attempt_for_instance( instance: srv2_preview_dashboard_instance(), @@ -1197,19 +1223,17 @@ test fn unknown_spawn_workdir_refuses_instance_resolution() -> Bool { } } -// NARROWED, and the first attempt at this was wrong in a way worth recording. The claim used to -// assert that two known spawn workdirs resolve to DIFFERENT instances, with the deleted green slot -// as the second one. Re-enrolling it against srv1-lab looked right and failed by execution: the -// lookup's population is the instances this belt actuates, and the lab was never in it, so the lab -// root resolves to DashboardInstanceRootUnknown. Distinctness is not something the lookup can be asked about -// any more -- it knows exactly one workdir -- and that is a consequence of the single deployment -// rather than a guarantee that was dropped. +// NARROWED; the first attempt was wrong in a way worth recording. The claim used to assert that two +// known spawn workdirs resolve to DIFFERENT instances, with the deleted green slot as the second. +// Re-enrolled against srv1-lab it failed by execution: the lookup's population is the instances +// this belt actuates, the lab was never in it, so the lab root resolves to +// DashboardInstanceRootUnknown. The lookup knows exactly one workdir, so distinctness can no longer +// be asked of it — a consequence of the single deployment, not a dropped guarantee. // -// So this asserts the arm that still exists: the known workdir resolves, and it resolves to the -// instance that owns it. Retiring outright would have left only -// unknown_spawn_workdir_refuses_instance_resolution enrolled, and a lookup that refused EVERY -// workdir would then pass the file -- the resolved arm needs its own claim precisely because the -// refusal arm cannot detect its absence. +// So this asserts the arm that still exists: the known workdir resolves, to the instance that owns +// it. Retiring outright would have left only unknown_spawn_workdir_refuses_instance_resolution +// enrolled, and a lookup refusing EVERY workdir would pass the file — the resolved arm needs its +// own claim because the refusal arm cannot detect its absence. test fn the_known_spawn_workdir_resolves_to_its_own_instance() -> Bool { let live = srv1_live_dashboard_instance() match dashboard_instance_for_repo_root(repo_root: live.repo_root as String) { @@ -1219,7 +1243,11 @@ test fn the_known_spawn_workdir_resolves_to_its_own_instance() -> Bool { } } -data belt_tick_decouple_witness_note: String = "RED control (operator P1, 2026-08-02): a tmux-list refusal must NOT zero the verify pass. The defect class was belt_tick returning empty verify_outcomes on ObserveRefused — an absorbing fallback that made the whole tick look like verification never ran. The witness constructs the post-fix shape synthetically: spawn_pass is Refused while verify_pass is still Recorded when verify outcomes exist." +// RED control (operator P1, 2026-08-02): a tmux-list refusal must NOT zero the verify pass. The +// defect class was belt_tick returning empty verify_outcomes on ObserveRefused — an absorbing +// fallback that made the whole tick look like verification never ran. The witness constructs the +// post-fix shape synthetically: spawn_pass Refused while verify_pass is still Recorded when verify +// outcomes exist. test fn observe_refused_spawn_does_not_zero_verify_pass() -> Bool { let result = BeltTickResult { @@ -1277,7 +1305,11 @@ test fn observe_refused_with_empty_verify_is_deferred_not_recorded() -> Bool { } } -data verification_presentation_witness_note: String = "review 47210 spec-without-execution: decoupling is witnessed at the receipt layer but the presentation join had no executing consumer. These rows execute belt_verification_presentation_detail and the wire join against synthetic tick reads so the headline strings ('Verification queued - next belt tick', 'Verification blocked · …', observe-refusal vs verify-recorded at the UI layer) cannot drift without going red." +// review 47210 spec-without-execution: decoupling was witnessed at the receipt layer but the +// presentation join had no executing consumer. These rows execute +// belt_verification_presentation_detail and the wire join against synthetic tick reads so the +// headline strings ('Verification queued - next belt tick', 'Verification blocked · …', +// observe-refusal vs verify-recorded at the UI layer) cannot drift without going red. test fn verification_presentation_absent_receipt_is_queued() -> Bool { belt_verification_presentation_detail( @@ -1404,9 +1436,20 @@ test fn belt_tick_receipt_io_failure_read_is_unreadable() -> Bool { } } -data attempt_grain_home_note: String = "The attempt-grain claim (U1) is PURE — content hashes and string derivations, no host reach — so it lives in dag/test/claim/dispatch_attempts_witness_test.dag, which discovery scans on every affected PR. This file is BinWitnessWet-excluded because its witnesses execute real host commands; a pure row parked here is enrolled with zero executing consumers, which is exactly what the Phase 0(b) admission invariant refused (CI 30184138800). Deferral is a property of the EXECUTION the row needs, never of the module it happens to name." +// The attempt-grain claim (U1) is PURE — content hashes and string derivations, no host reach — so +// it lives in dag/test/claim/dispatch_attempts_witness_test.dag, which discovery scans on every +// affected PR. This file is BinWitnessWet-excluded because its witnesses execute real host +// commands; a pure row parked here would be enrolled with zero executing consumers, which the +// Phase 0(b) admission invariant refused (CI 30184138800). Deferral is a property of the EXECUTION +// the row needs, never of the module it names. -data observe_only_posture_behavioral_note: String = "review 44039/44043 predicate dissolution. dashboard_instance_can_actuate was a Bool nickname for a two-variant coproduct test, so both belt entrypoints now match DashboardActuationPosture directly. Deleting the predicate would have deleted its only assertions with it, and those assertions never proved the wiring anyway — they restated the posture field. This proves the behaviour instead: an observe-only instance REFUSES at both entrypoints, before any observation, provider preflight, or worktree creation. Only the refusing arm is exercised because it short-circuits; the actuating arm would reach live tmux." +// review 44039/44043 predicate dissolution. dashboard_instance_can_actuate was a Bool nickname for +// a two-variant coproduct test, so both belt entrypoints now match DashboardActuationPosture +// directly. Deleting the predicate would have deleted its only assertions, which never proved the +// wiring anyway — they restated the posture field. This proves the behaviour: an observe-only +// instance REFUSES at both entrypoints, before any observation, provider preflight, or worktree +// creation. Only the refusing arm is exercised because it short-circuits; the actuating arm would +// reach live tmux. test fn observe_only_instance_refuses_dispatch_and_stop() -> Bool { let preview = srv2_preview_dashboard_instance() @@ -1435,7 +1478,15 @@ test fn observe_only_instance_refuses_dispatch_and_stop() -> Bool { } } -data footprint_admission_witness_note: String = "Every arm of belt_footprint_admission_decision is exercised on SYNTHETIC observations, the same discipline belt_claude_preflight_decision and belt_observe_from_result already follow: the decision is a pure fn over facts, so its arms are witnessable without a host, and the live half (belt_footprint_observe) only threads real probe results into it. The arms are not interchangeable and the tests say why — absent, unwritable, and unsearchable name three different remedies (converge the member, fix ownership drift, fix the mode), which is the whole point of not collapsing them into one `unusable` Bool. The short-circuit witness is the load-bearing one for operator experience: with two bad roots the FIRST is reported rather than the last, so the refusal names the member a human should look at first rather than whichever happened to sort last." +// Every arm of belt_footprint_admission_decision is exercised on SYNTHETIC observations, as +// belt_claude_preflight_decision and belt_observe_from_result already are: the decision is a pure +// fn over facts, so its arms are witnessable without a host, and the live half +// (belt_footprint_observe) only threads real probe results into it. The arms are not +// interchangeable and the tests say why — absent, unwritable, and unsearchable name three different +// remedies (converge the member, fix ownership drift, fix the mode), which is why they are not +// collapsed into one `unusable` Bool. The short-circuit witness is the load-bearing one for +// operator experience: with two bad roots the FIRST is reported, so the refusal names the member a +// human should look at first rather than whichever sorted last. fn footprint_obs( member: String, @@ -1511,7 +1562,22 @@ test fn witness_footprint_roots_cover_both_belt_write_targets() -> Bool { has_worktrees && has_attempt_state } -data belt_publish_producer_witness_note: String = "THE PRODUCER'S DECISION, EXERCISED WITHOUT A NETWORK OR A FILESYSTEM. belt_publish_attempt_for_instance performs three effects - read the existing receipt, observe the two remote surfaces, write the judgment - and every branch it takes is decided by belt_publish_gate and belt_publish_write_outcome, both pure. That split is what makes these claims possible at all: an arm that fires when a receipt on disk turns out to be about another attempt would otherwise be reachable only by arranging that state on a real host.\\n\\nTHE GATE'S JOB IS TO DECIDE WHETHER TO OBSERVE. Three of the five outcomes are settled by what is already on disk, and none of them should cost a GitHub read or risk overwriting evidence. The claims below pin each: a receipt for this exact subject halts as already-recorded, an undecodable one halts rather than being replaced, one about another subject halts rather than being corrected, and only genuine absence proceeds.\\n\\nTHE SUBJECT IS BUILT FROM AN OBSERVED HEAD OR NOT AT ALL. An attempt whose worktree head cannot be read has no subject, so the producer defers with the reason rather than adjudicating against a branch name - which is the lookup this whole lane replaced." +// THE PRODUCER'S DECISION, EXERCISED WITHOUT A NETWORK OR A FILESYSTEM. +// belt_publish_attempt_for_instance performs three effects - read the existing receipt, observe the +// two remote surfaces, write the judgment - and every branch is decided by belt_publish_gate and +// belt_publish_write_outcome, both pure. That split makes these claims possible: an arm that fires +// when a receipt on disk is about another attempt would otherwise be reachable only by arranging +// that state on a real host. +// +// THE GATE'S JOB IS TO DECIDE WHETHER TO OBSERVE. Three of the five outcomes are settled by what is +// already on disk, and none should cost a GitHub read or risk overwriting evidence. The claims pin +// each: a receipt for this exact subject halts as already-recorded, an undecodable one halts rather +// than being replaced, one about another subject halts rather than being corrected, and only +// genuine absence proceeds. +// +// THE SUBJECT IS BUILT FROM AN OBSERVED HEAD OR NOT AT ALL. An attempt whose worktree head cannot +// be read has no subject, so the producer defers with the reason rather than adjudicating against +// a branch name - the lookup this lane replaced. data belt_pub_head: CommitSha = "1111111111111111111111111111111111111111" data belt_pub_other_head: CommitSha = "2222222222222222222222222222222222222222" @@ -1629,7 +1695,14 @@ test fn a_receipt_about_another_subject_is_not_overwritten() -> Bool { } } -data unreadable_is_not_absent_note: String = "THE DEFECT THIS REFUSES, from review 46148: an I/O failure reading an existing receipt used to arrive at the gate as `readable=false`, which the evidence layer classified as EvidenceAbsent and the gate turned into PublishProceed - so a transient read fault would have OVERWRITTEN a receipt the belt could not read. Absent and unreadable have opposite correct actions, so the two are now distinct constructors and there is no spelling for the conflation.\\n\\nThese two claims are the pair, and only the pair discriminates: absent proceeds, unreadable halts. Asserting either alone would pass under the defect - the old code proceeded on both." +// THE DEFECT THIS REFUSES, from review 46148: an I/O failure reading an existing receipt reached +// the gate as `readable=false`, which the evidence layer classified as EvidenceAbsent and the gate +// turned into PublishProceed - so a transient read fault would have OVERWRITTEN a receipt the belt +// could not read. Absent and unreadable have opposite correct actions, so they are now distinct +// constructors and the conflation has no spelling. +// +// Only the pair discriminates: absent proceeds, unreadable halts. Either alone would pass under the +// defect - the old code proceeded on both. test fn an_unreadable_receipt_halts_rather_than_being_overwritten() -> Bool { match belt_publish_gate( @@ -1692,7 +1765,11 @@ test fn an_undecodable_receipt_is_not_overwritten_either() -> Bool { } } -data write_failure_is_not_a_judgment_note: String = "A JUDGMENT REACHED AND THEN LOST IS NOT A JUDGMENT RECORDED. The write is the only thing that makes the adjudication durable, so a failed write must not report the outcome it computed - the next tick will find nothing on disk, and a caller told the head was published would be reading a fact that exists nowhere. The pair below asserts the same receipt produces different producer outcomes purely on whether the write succeeded." +// A JUDGMENT REACHED AND THEN LOST IS NOT A JUDGMENT RECORDED. Only the write makes the +// adjudication durable, so a failed write must not report the outcome it computed - the next tick +// finds nothing on disk, and a caller told the head was published would be reading a fact that +// exists nowhere. The pair below asserts the same receipt produces different producer outcomes +// purely on whether the write succeeded. test fn a_failed_write_reports_loss_rather_than_the_outcome_it_computed() -> Bool { let subject = belt_pub_subject(head: belt_pub_head, node_id: "belt-pub-node") @@ -1781,7 +1858,11 @@ test fn an_unreadable_worktree_head_yields_no_publication_subject() -> Bool { } } -data zero_exit_empty_stdout_is_unobserved_note: String = "THE DISCRIMINATING CONTROL FOR THE HEAD READ, and the reason the exit code alone is not the test. git rev-parse HEAD exits zero and prints nothing on a worktree whose branch carries no commit yet, which a freshly created dispatch worktree is until the worker commits. A reader that trusted the exit code would cast an empty string into a CommitSha, producing a subject whose head matches no commit and compares equal to every other empty head - so a receipt written for it would be evidence for any attempt in the same state." +// THE DISCRIMINATING CONTROL FOR THE HEAD READ, and why the exit code alone is not the test. git +// rev-parse HEAD exits zero and prints nothing on a worktree whose branch carries no commit yet, +// which a freshly created dispatch worktree is until the worker commits. A reader trusting the exit +// code would cast an empty string into a CommitSha: a subject matching no commit and equal to every +// other empty head, so a receipt written for it would be evidence for any attempt in that state. test fn a_zero_exit_with_no_revision_is_unobserved_not_an_empty_head() -> Bool { match worktree_head_observation_of(outcome: ExecOk { stdout: "\n" }) { @@ -1791,7 +1872,15 @@ test fn a_zero_exit_with_no_revision_is_unobserved_not_an_empty_head() -> Bool { } } -data unsettled_receipt_must_not_freeze_the_row_note: String = "THE CLAIM THAT PINS THE IDEMPOTENCE KEY, and the defect it would have caught. The obvious key is `a receipt exists for this head`, and under it the belt's FIRST observation of a head - which normally happens before the worker has pushed - records branch-not-published and then halts on its own record forever. The row would report `not published` for the rest of the attempt's life, and the halt would be caused by the very receipt that observed the absence.\\n\\nSo the pair below drives the gate with two receipts for the SAME subject, differing only in what the remote showed: a bound one halts, an unpublished one proceeds. A gate keyed on existence rather than on settlement returns already-recorded for both, and this goes red." +// THE CLAIM THAT PINS THE IDEMPOTENCE KEY, and the defect it would have caught. The obvious key is +// `a receipt exists for this head`; under it the belt's FIRST observation of a head - normally +// before the worker has pushed - records branch-not-published and then halts on its own record +// forever: `not published` for the rest of the attempt's life, the halt caused by the very receipt +// that observed the absence. +// +// So the pair drives the gate with two receipts for the SAME subject, differing only in what the +// remote showed: a bound one halts, an unpublished one proceeds. A gate keyed on existence rather +// than settlement returns already-recorded for both, and this goes red. fn belt_pub_unpublished_receipt(head: CommitSha, node_id: String) -> String { publication_receipt_json( @@ -1830,20 +1919,17 @@ test fn an_unsettled_receipt_is_re_observed_rather_than_halting_the_row() -> Boo // --------------------------------------------------------------------------- // PRESS-0 step 1 — the deployed-revision gate, at the grain it is actually proven. // -// SCOPE, STATED FIRST because the honest rung is the point: these witness the -// PROJECTION of the two new arms, not the live gate. `fleet_revision_standing` -// reads a real git tree, so whether the gate FIRES on a drifted srv1 is a wet -// fact and is owed a wet receipt — it is not established here and must not be -// read as established. What IS established by execution: neither arm can reach -// the ok band, both carry a loud band, the drifted receipt names BOTH revisions, -// and the unobserved receipt names its cause. +// SCOPE FIRST, because the honest rung is the point: these witness the PROJECTION of the two new +// arms, not the live gate. `fleet_revision_standing` reads a real git tree, so whether the gate +// FIRES on a drifted srv1 is a wet fact owed a wet receipt — not established here. What IS +// established by execution: neither arm can reach the ok band, both carry a loud band, the drifted +// receipt names BOTH revisions, and the unobserved receipt names its cause. // -// The `desired`/`local` assertion is the discriminating one. A refusal that -// dropped one side would still refuse, still label correctly, still be loud — -// and would be useless to the operator who has to decide whether to catch the -// host up or roll it back. The membership-diff `from` ruling is exactly this: -// a receipt must name what it observed, not merely that it disagreed. -data revision_gate_witness_scope_note: String = "Projection-grain only; the live gate is owed a wet srv1 receipt." +// The `desired`/`local` assertion is the discriminating one. A refusal that dropped one side would +// still refuse, label correctly and be loud — and be useless to the operator deciding whether to +// catch the host up or roll it back. The membership-diff `from` ruling is exactly this: a receipt +// must name what it observed, not merely that it disagreed. Projection-grain only; the live gate +// is owed a wet srv1 receipt. test fn witness_revision_refusals_are_never_ok() -> Bool { !belt_dispatch_result_ok(r: not_admitted(r: LaunchRevisionDrift { desired: "aaa", local: "bbb" })) @@ -1947,14 +2033,12 @@ test fn witness_revision_admission_fold_drives_all_three_arms() -> Bool { } } -// THE BELT-GRAIN CONTROL (review artifact 51237, P0 #2). The previous -// dead-pane witness proved a helper Boolean and said nothing about the -// continuously running reconciler, which received the whole session list and -// counted every present row as an occupied member. This asserts the partition -// the tick actually feeds to belt_reconcile: a stale pane is NOT running, so it -// neither occupies capacity nor reads as Unchanged, and an unobserved pane is -// in neither bucket — it is a counted refusal, because tearing it down could -// kill live work and spawning beside it could double-run the node. +// THE BELT-GRAIN CONTROL (review artifact 51237, P0 #2). The previous dead-pane witness proved a +// helper Boolean and said nothing about the continuously running reconciler, which received the +// whole session list and counted every present row as an occupied member. This asserts the +// partition the tick feeds to belt_reconcile: a stale pane is NOT running, so it neither occupies +// capacity nor reads as Unchanged; an unobserved pane is in neither bucket — a counted refusal, +// because tearing it down could kill live work and spawning beside it could double-run the node. test fn witness_tick_partition_is_lifecycle_aware_not_presence_aware() -> Bool { let part = belt_tick_classify_sessions(live: [ live_session_with_process( @@ -2008,10 +2092,10 @@ test fn witness_tick_multiplicity_is_a_node_fact() -> Bool { // only durable record, so the cause was computed and erased every time. On srv1 that turned a // missing provider binary into weeks of a dashboard saying "belt fault" with no way to ask why — // and the obvious host probes answer about a different object than the preflight tests, so the -// available evidence pointed away from the cause rather than at it. +// available evidence pointed away from the cause. // -// Each conjunct names one of the four facts, so a fold that dropped any single field reds here -// rather than passing on the other three. +// Each conjunct names one of the four facts, so a fold dropping any single field reds here rather +// than passing on the other three. test fn a_failed_spawn_names_its_node_gate_and_detail_in_the_receipt() -> Bool { match belt_spawn_pass_outcome_from( host_refusal: none, @@ -2097,7 +2181,13 @@ test fn an_observation_refusal_still_outranks_the_spawn_summary() -> Bool { } } -data review_5059681676_controls_note: String = "Controls for review 5059681676 on #9696. (1) A transition-halted tick writes a receipt whose FOUR passes are Refused with the transition reason -- never Recorded for the verify/publish passes the driver did not run; a non-transition host refusal (revision drift) withholds only the launch passes and verification still records on its own evidence. (2) The route's decision path after the staged observation refuses an unknown node and a contractless node WITHOUT listing tmux: under the hermetic route a tmux effect is a route refusal rather than a verdict, so the green verdict is the effect-order receipt." +// Controls for review 5059681676 on #9696. (1) A transition-halted tick writes a receipt whose FOUR +// passes are Refused with the transition reason -- never Recorded for the verify/publish passes the +// driver did not run; a non-transition host refusal (revision drift) withholds only the launch +// passes and verification still records on its own evidence. (2) The route's decision path after +// the staged observation refuses an unknown node and a contractless node WITHOUT listing tmux: +// under the hermetic route a tmux effect is a route refusal, not a verdict, so the green verdict is +// the effect-order receipt. fn pass_refused_with(o: BeltPassOutcome, pattern: String) -> Bool { match o { @@ -2180,10 +2270,10 @@ fn staged_post_over_canary(graph: LaunchGraphStanding, standing: LaunchHostStand ) } -// The route's real decision path (belt_dispatch_node_staged_over is what belt_dispatch_node_staged -// calls with the live projection) over the RLM-0 canary graph and a pending session set. Each of -// these refuses at a model-only gate, so tmux is never listed: under claim_batch's hermetic route a -// tmux effect would be a route refusal, not a verdict. +// The route's real decision path (belt_dispatch_node_staged_over, which belt_dispatch_node_staged +// calls with the live projection) over the RLM-0 canary graph and a pending session set. Each +// refuses at a model-only gate, so tmux is never listed: under claim_batch's hermetic route a tmux +// effect would be a route refusal, not a verdict. test fn staged_post_refuses_unknown_node_without_listing_tmux() -> Bool { match staged_post_over_canary(graph: launch_fixture_canary_graph(), standing: launch_fixture_standing_pending(mode: ManualReady), node_id: "no-such-node-anywhere") { SpawnNotAdmitted { node_id, refusal: LaunchNodeUnknown } => node_id == "no-such-node-anywhere" diff --git a/dag/test/claim/roadmap/roadmap_closing_contract_authoring_witness_test.dag b/dag/test/claim/roadmap/roadmap_closing_contract_authoring_witness_test.dag index cfd0fc4c7f6..dd432f4f472 100644 --- a/dag/test/claim/roadmap/roadmap_closing_contract_authoring_witness_test.dag +++ b/dag/test/claim/roadmap/roadmap_closing_contract_authoring_witness_test.dag @@ -43,7 +43,14 @@ import gunbc.roadmap_closing_contract_authoring { data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data closing_contract_authoring_witness_note: String = "EVERY REFUSAL ARM FIRES ON A PLANTED INPUT, and the arms are planted rather than found because the point of this predicate is that it discriminates. The oracle observations are supplied as a parameter to closing_contract_verdict_for_observed, so a missing oracle and an ambiguous one are authored here rather than depending on a file that happens to be absent from the tree — which would be a fixture whose red is a property of the checkout instead of the predicate. The one arm read against the LIVE authority is ClosingContractTargetNotDeclared, because a name no node carries cannot be planted any other way, and its positive control sits beside it so the pair cannot both be satisfied by a predicate that always refuses." +// EVERY REFUSAL ARM FIRES ON A PLANTED INPUT, and the arms are planted rather than found because +// the point of this predicate is that it discriminates. The oracle observations are supplied as a +// parameter to closing_contract_verdict_for_observed, so a missing oracle and an ambiguous one are +// authored here rather than depending on a file that happens to be absent from the tree — which +// would be a fixture whose red is a property of the checkout instead of the predicate. The one arm +// read against the LIVE authority is ClosingContractTargetNotDeclared, because a name no node +// carries cannot be planted any other way, and its positive control sits beside it so the pair +// cannot both be satisfied by a predicate that always refuses. fn target() -> RoadmapNodeId { "example-node" as RoadmapNodeId } diff --git a/dag/test/claim/roadmap/roadmap_dashboard_instance_apply_witness_test.dag b/dag/test/claim/roadmap/roadmap_dashboard_instance_apply_witness_test.dag index bcf4df8ed32..a1ff7f227bb 100644 --- a/dag/test/claim/roadmap/roadmap_dashboard_instance_apply_witness_test.dag +++ b/dag/test/claim/roadmap/roadmap_dashboard_instance_apply_witness_test.dag @@ -81,7 +81,20 @@ import gunbc.roadmap_dashboard_instance_apply { import gunbc.roadmap_serve { dashboard_instance_json } import extdeps.languages.json.emit { serialize_json } -data dashboard_target_preflight_platform_drift_note: String = "The preflight roster count is a no-silent-growth ratchet over a hand-authored base list, so it is stated as a literal. The recurring drift it must not re-absorb: adding a dispatch-platform capability (ProviderEventProjectionCapability/jq, c37e4505d2) changes the derived half of the roster and silently reds the literal. The all(platform executables are required) law states that half structurally, so a new platform capability moves the derived side and the literal only guards the base list it actually describes.\\n\\nTHE SERVE BINARY LEFT THIS ROSTER AND ITS ABSENCE IS NOW ASSERTED, which is the substantive half of the 15-to-16 move. This branch gives apply an ensure-serve-binary step, so the binary is something the deployment INSTALLS rather than a precondition it demands — and a roster that still required it would refuse every first apply to a host that does not yet have one, which is the exact bootstrap this change exists to perform. dirname and chmod entered for the same reason: they are what installing it costs.\\n\\nThe negative conjunct is the one that would catch the regression. Re-adding the binary as a required executable keeps the count at 16 by displacing something else, so the literal alone cannot see it; asserting the binary is NOT required states the precondition/product distinction directly." +// The preflight roster count is a no-silent-growth ratchet over a hand-authored base list, so it is +// stated as a literal. The recurring drift it must not re-absorb: adding a dispatch-platform +// capability (ProviderEventProjectionCapability/jq, c37e4505d2) changes the derived half of the +// roster and silently reds the literal. The all(platform executables are required) law states that +// half structurally, so a new platform capability moves the derived side and the literal only +// guards the base list it actually describes.\n\nTHE SERVE BINARY LEFT THIS ROSTER AND ITS ABSENCE +// IS NOW ASSERTED, which is the substantive half of the 15-to-16 move. This branch gives apply an +// ensure-serve-binary step, so the binary is something the deployment INSTALLS rather than a +// precondition it demands — and a roster that still required it would refuse every first apply to a +// host that does not yet have one, which is the exact bootstrap this change exists to perform. +// dirname and chmod entered for the same reason: they are what installing it costs.\n\nThe negative +// conjunct is the one that would catch the regression. Re-adding the binary as a required +// executable keeps the count at 16 by displacing something else, so the literal alone cannot see +// it; asserting the binary is NOT required states the precondition/product distinction directly. test fn dashboard_source_transport_argv_is_exact_and_atomic() -> Bool { let lab = srv1_lab_dashboard_instance() @@ -312,7 +325,14 @@ test fn dashboard_target_preflight_derives_dispatch_platform_dependencies() -> B ) } -data dashboard_poll_interval_witness_note: String = "This witness exists because a data row can typecheck and still fail to EVALUATE: dashboard_health_poll_seconds was authored as `2 as Seconds` and no single-entry witness run forced the row, so it went green locally and reded only in CI's affected-set re-eval leg, which evaluates changed data items (`cannot cast Int to Seconds` — the interpreter has no cast into a branded scalar; the corpus idiom is a bare literal, as in srv3_install_hang_no_installer_progress_ms: Milliseconds). Reading the value here forces the evaluation locally, so the same authoring mistake reds in the witness run rather than 15 minutes into the floor." +// This witness exists because a data row can typecheck and still fail to EVALUATE: +// dashboard_health_poll_seconds was authored as `2 as Seconds` and no single-entry witness run +// forced the row, so it went green locally and reded only in CI's affected-set re-eval leg, which +// evaluates changed data items (`cannot cast Int to Seconds` — the interpreter has no cast into a +// branded scalar; the corpus idiom is a bare literal, as in +// srv3_install_hang_no_installer_progress_ms: Milliseconds). Reading the value here forces the +// evaluation locally, so the same authoring mistake reds in the witness run rather than 15 minutes +// into the floor. test fn dashboard_poll_interval_is_a_usable_duration() -> Bool { dashboard_health_poll_seconds == 2 @@ -320,7 +340,11 @@ test fn dashboard_poll_interval_is_a_usable_duration() -> Bool { && dashboard_health_poll_attempts == 31 } -data dashboard_health_identity_witness_note: String = "review 44058. The served document is the oracle, so the green arm feeds dashboard_instance_json's real output rather than a hand-spelled stub — a stub is exactly what let the previous scan look correct while accepting anything. The REDs are the two ways a wrong server passes a scan but must fail positional identity: a different instance, and a document that merely MENTIONS the wanted id in a nested value." +// review 44058. The served document is the oracle, so the green arm feeds dashboard_instance_json's +// real output rather than a hand-spelled stub — a stub is exactly what let the previous scan look +// correct while accepting anything. The REDs are the two ways a wrong server passes a scan but must +// fail positional identity: a different instance, and a document that merely MENTIONS the wanted id +// in a nested value. fn health_result(body: String) -> DashboardExecResult { DashboardExecResult { success: true, stdout: body, stderr: "" } @@ -560,7 +584,16 @@ test fn dashboard_dirty_controller_source_refuses_before_apply() -> Bool { ) } -data bootstrap_unobserved_discriminates_note: String = "THE THIRD CASE IS THE POINT OF THIS CLAIM (review 45213). The first two arms passed before the fix and pass after it, so on their own they cannot tell the two versions apart — the collapse was invisible to them precisely because absent and unobservable both arrived as the same Bool.\\n\\nThe unobserved case is the discriminator: against the predecessor it is unconstructible, because there was no third value to pass, and against a regression that re-collapses the observation it lands in DashboardBootstrapRefused carrying not writable — which this claim asserts it does NOT. The transport reason must survive into the verdict, so the assertion checks the reason text reaches the operator rather than merely that some refusal occurred.\\n\\nThe reason string is a realistic transport failure rather than a placeholder, because the failure mode being guarded is an unreachable host being described as a permissions problem on a directory." +// THE THIRD CASE IS THE POINT OF THIS CLAIM (review 45213). The first two arms passed before the +// fix and pass after it, so on their own they cannot tell the two versions apart — the collapse was +// invisible to them precisely because absent and unobservable both arrived as the same Bool.\n\nThe +// unobserved case is the discriminator: against the predecessor it is unconstructible, because +// there was no third value to pass, and against a regression that re-collapses the observation it +// lands in DashboardBootstrapRefused carrying not writable — which this claim asserts it does NOT. +// The transport reason must survive into the verdict, so the assertion checks the reason text +// reaches the operator rather than merely that some refusal occurred.\n\nThe reason string is a +// realistic transport failure rather than a placeholder, because the failure mode being guarded is +// an unreachable host being described as a permissions problem on a directory. test fn dashboard_bootstrap_parent_writability_is_a_preflight_fact() -> Bool { let lab = srv1_lab_dashboard_instance() diff --git a/dag/test/claim/roadmap/roadmap_dashboard_instance_witness_test.dag b/dag/test/claim/roadmap/roadmap_dashboard_instance_witness_test.dag index 45727e34a58..419acf2e878 100644 --- a/dag/test/claim/roadmap/roadmap_dashboard_instance_witness_test.dag +++ b/dag/test/claim/roadmap/roadmap_dashboard_instance_witness_test.dag @@ -541,7 +541,14 @@ fn witness_synthetic_instance() -> HostDashboardInstance { ) } -data anchor_ref_witness_note: String = "THE LITERAL THAT WOULD HAVE SERVED THE WRONG BRANCH SILENTLY. Every isolated instance inherited the constructor's hardcoded refs/heads/session/codex-provider-feedback-v0, so a new lab provisioned itself from another lane's stale feedback branch while its instance id, posture and page all read correctly — no refusal, just unintended content rendered plausibly. Unlike the host facts, which produced identical values on both hosts and therefore no wrong output at all, this one produces a page that looks right and is not.\\n\\nThe claim asserts the anchors are per-instance and DIFFER, so collapsing them back to one shared literal fails whichever way it collapses." +// THE LITERAL THAT WOULD HAVE SERVED THE WRONG BRANCH SILENTLY. Every isolated instance inherited +// the constructor's hardcoded refs/heads/session/codex-provider-feedback-v0, so a new lab +// provisioned itself from another lane's stale feedback branch while its instance id, posture and +// page all read correctly — no refusal, just unintended content rendered plausibly. Unlike the host +// facts, which produced identical values on both hosts and therefore no wrong output at all, this +// one produces a page that looks right and is not.\n\nThe claim asserts the anchors are +// per-instance and DIFFER, so collapsing them back to one shared literal fails whichever way it +// collapses. test fn source_anchor_is_per_instance_not_one_shared_literal() -> Bool { let synthetic = instance_anchor_ref(i: witness_synthetic_instance()) @@ -553,7 +560,17 @@ test fn source_anchor_is_per_instance_not_one_shared_literal() -> Bool { && !(srv2_lab == srv1_lab) } -data layout_no_longer_supplies_the_binary_note: String = "serve_binary MOVED OFF THE LAYOUT AND THIS CLAIM CAUGHT IT, which is the whole reason it exists. It used to assert the synthetic layout's /witness/bin/gunbc reached the instance; once binaries became instance-derived it asserts /witness/root/bin/gunbc instead — derived from the instance ROOT, not from the host row. The claim went red on the change rather than quietly continuing to pass, so the behaviour shift was visible at the point it happened instead of at the point something downstream broke.\\n\\nThe remaining conjuncts still prove the original property for the two fields the layout genuinely still supplies — provider state root and controller repo — and still assert non-equality with the srv1 rows, so re-pinning either to a host literal fails here. GunbcHostLayout.gunbc_serve_binary now has exactly one consumer left, srv1-live's own declaration, which is the dissolution trigger recorded on that row: it is a per-instance fact wearing a per-host name." +// serve_binary MOVED OFF THE LAYOUT AND THIS CLAIM CAUGHT IT, which is the whole reason it exists. +// It used to assert the synthetic layout's /witness/bin/gunbc reached the instance; once binaries +// became instance-derived it asserts /witness/root/bin/gunbc instead — derived from the instance +// ROOT, not from the host row. The claim went red on the change rather than quietly continuing to +// pass, so the behaviour shift was visible at the point it happened instead of at the point +// something downstream broke.\n\nThe remaining conjuncts still prove the original property for the +// two fields the layout genuinely still supplies — provider state root and controller repo — and +// still assert non-equality with the srv1 rows, so re-pinning either to a host literal fails here. +// GunbcHostLayout.gunbc_serve_binary now has exactly one consumer left, srv1-live's own +// declaration, which is the dissolution trigger recorded on that row: it is a per-instance fact +// wearing a per-host name. test fn isolated_instance_carries_the_layout_it_was_given() -> Bool { let i = witness_synthetic_instance() @@ -830,7 +847,20 @@ test fn a_production_slot_keeping_its_own_dispatch_state_is_refused() -> Bool { && !dashboard_instances_dispatch_state_is_consistent(a: live, b: own_state) } -data lab_shared_root_became_unrepresentable_note: String = "THIS PAIR USED TO CONSTRUCT THE INVALID STATE AND ASSERT THE LAW CAUGHT IT. It no longer can, and that is the climb rather than a gap: an instance-owned scope carries only CHILD NAMES, so its roots are derived beneath its own instance_root and there is no way to author a lab pointing at the host-shared roots. The DESIGN §4b rule is that a climb deletes the lower-rung production machinery but keeps the evidence enrolled, so these assert the DERIVATION that makes the old red unwritable instead of pretending to still construct it — a witness whose invalid input became unrepresentable must change what it asserts, not keep a name that no longer describes it.\\n\\nWHAT REMAINS LAW-CAUGHT, stated so the residue is not mistaken for a wall: a host-shared scope still carries two free FilePath values, so a production slot CAN be authored with roots that are not the layout rows. That state is representable and dashboard_instances_dispatch_state_is_consistent is what refuses it — rung two, not rung four — and a_production_slot_keeping_its_own_dispatch_state_is_refused is its live discriminating red. Closing it needs host-shared roots DERIVED from a total host-identity-to-layout lookup rather than carried, which is a host_layout change; dissolve-on: feature:host-dispatch-roots-derived." +// THIS PAIR USED TO CONSTRUCT THE INVALID STATE AND ASSERT THE LAW CAUGHT IT. It no longer can, and +// that is the climb rather than a gap: an instance-owned scope carries only CHILD NAMES, so its +// roots are derived beneath its own instance_root and there is no way to author a lab pointing at +// the host-shared roots. The DESIGN §4b rule is that a climb deletes the lower-rung production +// machinery but keeps the evidence enrolled, so these assert the DERIVATION that makes the old red +// unwritable instead of pretending to still construct it — a witness whose invalid input became +// unrepresentable must change what it asserts, not keep a name that no longer describes it.\n\nWHAT +// REMAINS LAW-CAUGHT, stated so the residue is not mistaken for a wall: a host-shared scope still +// carries two free FilePath values, so a production slot CAN be authored with roots that are not +// the layout rows. That state is representable and dashboard_instances_dispatch_state_is_consistent +// is what refuses it — rung two, not rung four — and +// a_production_slot_keeping_its_own_dispatch_state_is_refused is its live discriminating red. +// Closing it needs host-shared roots DERIVED from a total host-identity-to-layout lookup rather +// than carried, which is a host_layout change; dissolve-on: feature:host-dispatch-roots-derived. test fn an_instance_owned_scope_cannot_reach_the_shared_roots() -> Bool { let lab = srv1_lab_dashboard_instance() @@ -869,7 +899,11 @@ test fn host_shared_slots_are_exempt_from_containment_but_labs_are_not() -> Bool ) } -data different_host_shared_slots_are_valid_note: String = "The finding-3 red: two host-shared instances on DIFFERENT hosts carry byte-identical layout paths, and the first cut routed them into path-disjointness where identical strings refuse. Same-host disagreement must still refuse, so this asserts both directions off one pair — collapsing the different-host arm back into disjointness reds the first conjunct, and dropping the same-host equality check reds the second." +// The finding-3 red: two host-shared instances on DIFFERENT hosts carry byte-identical layout +// paths, and the first cut routed them into path-disjointness where identical strings refuse. +// Same-host disagreement must still refuse, so this asserts both directions off one pair — +// collapsing the different-host arm back into disjointness reds the first conjunct, and dropping +// the same-host equality check reds the second. test fn host_shared_slots_on_different_hosts_are_consistent() -> Bool { let live = srv1_live_dashboard_instance() diff --git a/dag/test/claim/roadmap/roadmap_dispatch_actuator_witness_test.dag b/dag/test/claim/roadmap/roadmap_dispatch_actuator_witness_test.dag index 6add5500fd7..2ebc54dc4ae 100644 --- a/dag/test/claim/roadmap/roadmap_dispatch_actuator_witness_test.dag +++ b/dag/test/claim/roadmap/roadmap_dispatch_actuator_witness_test.dag @@ -500,7 +500,12 @@ test fn witness_tmux_attempt_panes_malformed_row_refuses() -> Bool { } } -data event_pipe_emission_witness_note: String = "review 44063. The claim is no longer 'the caller remembered to quote' — quoting is the lit-word production's job now, so the exact emitted spelling is the oracle: every word single-quoted, and an embedded quote closed/escaped/reopened as '\\''. The metacharacter fixture stays because it is what a spelling regression would smuggle: a $(...) inside the events path must be inert text in the payload, never a command substitution. The poison RED holds the serializer-refusal arm dead in corpus." +// review 44063. The claim is no longer 'the caller remembered to quote' — quoting is the lit-word +// production's job now, so the exact emitted spelling is the oracle: every word single-quoted, and +// an embedded quote closed/escaped/reopened as '\''. The metacharacter fixture stays because it is +// what a spelling regression would smuggle: a $(...) inside the events path must be inert text in +// the payload, never a command substitution. The poison RED holds the serializer-refusal arm dead +// in corpus. fn emitted_pipe_body_matches(body: String) -> Bool { body == "'exec' '/usr/bin/tee' '-a' '--' '/tmp/a'\\'';$(touch nope)'" diff --git a/dag/test/claim/roadmap/roadmap_dispatch_environment_witness_test.dag b/dag/test/claim/roadmap/roadmap_dispatch_environment_witness_test.dag index fdc7da8118d..8e3d52d3c64 100644 --- a/dag/test/claim/roadmap/roadmap_dispatch_environment_witness_test.dag +++ b/dag/test/claim/roadmap/roadmap_dispatch_environment_witness_test.dag @@ -195,7 +195,12 @@ test fn admission_receipt_is_structured_and_located() -> Bool { && string_contains(s: wire, pattern: "\"grounded\": true") } -data empty_validation_contract_refusal_note: String = "review 44043 predicate dissolution. execution_contract_is_specified collapsed the WorkItemExecutionContract coproduct to a Bool, and its two false cases carried ONE refusal reason: an unspecified contract and a specified contract declaring zero validations are different states with different remedies (declare a contract vs. fix the one you declared). The decision now matches the coproduct directly and each state gets its own located diagnostic. This is the arm that had no witness at all before, because the predicate hid it." +// review 44043 predicate dissolution. execution_contract_is_specified collapsed the +// WorkItemExecutionContract coproduct to a Bool, and its two false cases carried ONE refusal +// reason: an unspecified contract and a specified contract declaring zero validations are different +// states with different remedies (declare a contract vs. fix the one you declared). The decision +// now matches the coproduct directly and each state gets its own located diagnostic. This is the +// arm that had no witness at all before, because the predicate hid it. test fn empty_validation_contract_refuses_with_its_own_reason() -> Bool { match dispatch_environment_admission_decision( diff --git a/dag/test/claim/roadmap/roadmap_focus_witness_test.dag b/dag/test/claim/roadmap/roadmap_focus_witness_test.dag index 760ef8fc664..e8373549398 100644 --- a/dag/test/claim/roadmap/roadmap_focus_witness_test.dag +++ b/dag/test/claim/roadmap/roadmap_focus_witness_test.dag @@ -33,7 +33,18 @@ import v2.std.live_tree { LiveTreeDisposition, SubstrateInputsOnly } data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data focus_witness_note: String = "Focus is a VIEW, so the property that matters is not what it shows but what it cannot do: it must never be able to lose work. These claims pin the two ways a filtered projection goes wrong. First, the filter must be a partition and not an edit — visible plus hidden equals the whole declared set, so a node cannot fall out of both and vanish from the roadmap entirely; that is checked by arithmetic against the same list the filter runs over, not by trusting the filter. Second, the page must not read as a shorter roadmap — the notice carries a DERIVED count, so a reader who forgot the focus was set is told what is missing rather than shown a plausible-looking complete page.\n\nThe RED control is the one that would otherwise rot: clearing the focus must restore every node. Without it, a filter that silently dropped nodes on BOTH paths would still satisfy an is-subset check and still look correct on the focused page." +// Focus is a VIEW, so the property that matters is not what it shows but what it cannot do: it must +// never be able to lose work. These claims pin the two ways a filtered projection goes wrong. +// First, the filter must be a partition and not an edit — visible plus hidden equals the whole +// declared set, so a node cannot fall out of both and vanish from the roadmap entirely; that is +// checked by arithmetic against the same list the filter runs over, not by trusting the filter. +// Second, the page must not read as a shorter roadmap — the notice carries a DERIVED count, so a +// reader who forgot the focus was set is told what is missing rather than shown a plausible-looking +// complete page. +// +// The RED control is the one that would otherwise rot: clearing the focus must restore every node. +// Without it, a filter that silently dropped nodes on BOTH paths would still satisfy an is-subset +// check and still look correct on the focused page. fn all_nodes() -> List { match accepted_roadmap_node_ids_projection() { diff --git a/dag/test/claim/roadmap/roadmap_identity_witness_test.dag b/dag/test/claim/roadmap/roadmap_identity_witness_test.dag index eef0d86047d..c5c14f75f61 100644 --- a/dag/test/claim/roadmap/roadmap_identity_witness_test.dag +++ b/dag/test/claim/roadmap/roadmap_identity_witness_test.dag @@ -27,7 +27,17 @@ import v2.std.live_tree { LiveTreeDisposition, SubstrateInputsOnly } data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data identity_witness_scope_note: String = "WHAT THESE PROVE, AND THE ONE THING THEY CANNOT. They prove the registry is well formed here and now — identities unique across active and tombstoned rows, active slugs unique, the index total over declared nodes, resolution exactly-one in all three outcomes. They CANNOT prove permanence: an identity silently REPLACED between the base revision and this head produces a tree satisfying every claim below, because a snapshot cannot see history. Claiming otherwise would be the coverage-by-illusion this repository names, so the base-versus-head gate is declared owed on the carrier rather than implied here.\\n\\nThe rename claim is the discriminating one. Identity's whole purpose is surviving a slug change, and nothing else in this file would notice if identity silently tracked the slug — every uniqueness and totality claim holds just as well for a registry where identity IS the slug. Constructing a node, renaming its slug, and asserting the identity is unchanged is the only claim here that fails if the separation collapses." +// WHAT THESE PROVE, AND THE ONE THING THEY CANNOT. They prove the registry is well formed here and +// now — identities unique across active and tombstoned rows, active slugs unique, the index total +// over declared nodes, resolution exactly-one in all three outcomes. They CANNOT prove permanence: +// an identity silently REPLACED between the base revision and this head produces a tree satisfying +// every claim below, because a snapshot cannot see history. Claiming otherwise would be the +// coverage-by-illusion this repository names, so the base-versus-head gate is declared owed on the +// carrier rather than implied here.\n\nThe rename claim is the discriminating one. Identity's whole +// purpose is surviving a slug change, and nothing else in this file would notice if identity +// silently tracked the slug — every uniqueness and totality claim holds just as well for a registry +// where identity IS the slug. Constructing a node, renaming its slug, and asserting the identity is +// unchanged is the only claim here that fails if the separation collapses. fn declared_identities() -> List { declared_roadmap_nodes() |> map(n => n.identity as String) @@ -90,7 +100,13 @@ test fn identity_survives_a_slug_rename() -> Bool { } } -data tombstone_witness_note: String = "These claims are shaped to stay honest as the tombstone roster grows (written when it was empty; the first retirement landed 2026-07-31 and the 2026-08-01 spine recut added four more — the note's original 'empty today' opening rotted within a day, which is its own small receipt for why nothing here pins a population). The first asserts the registry equals active plus tombstoned — arithmetic that holds at zero and keeps holding as retirements land. The second asserts every tombstoned record reports itself inactive, load-bearing since the first row. Neither asserts a count, because pinning one would red on the next legitimate retirement." +// These claims are shaped to stay honest as the tombstone roster grows (written when it was empty; +// the first retirement landed 2026-07-31 and the 2026-08-01 spine recut added four more — the +// note's original 'empty today' opening rotted within a day, which is its own small receipt for why +// nothing here pins a population). The first asserts the registry equals active plus tombstoned — +// arithmetic that holds at zero and keeps holding as retirements land. The second asserts every +// tombstoned record reports itself inactive, load-bearing since the first row. Neither asserts a +// count, because pinning one would red on the next legitimate retirement. test fn registry_is_active_plus_tombstoned() -> Bool { identity_count() == active_identity_count() + count(roadmap_tombstoned_identities()) diff --git a/dag/test/claim/roadmap/roadmap_launch_admission_fixture.dag b/dag/test/claim/roadmap/roadmap_launch_admission_fixture.dag index 2d080ccb021..c977ef8348f 100644 --- a/dag/test/claim/roadmap/roadmap_launch_admission_fixture.dag +++ b/dag/test/claim/roadmap/roadmap_launch_admission_fixture.dag @@ -20,7 +20,12 @@ import gunbc.roadmap_launch_admission { launch_host_halt_transition, launch_host_stage_revision, HostRevisionHalted, HostRevisionConverged, } -data launch_fixture_note: String = "Synthetic HOST facts for the launch-admission witnesses (RLM-1). The admission is pure over LaunchHostStanding, so a witness fabricates exactly the host it wants to talk about -- an actuating instance, a clear transition, a converged (or drifted, or unobserved) revision, a chosen live-session set, a capacity and a spawn mode -- and the graph it wants, and asks the same decision production asks. Nothing here touches a host; the two object ids are literal hex pinned by the fixture, never read from git." +// Synthetic HOST facts for the launch-admission witnesses (RLM-1). The admission is pure over +// LaunchHostStanding, so a witness fabricates exactly the host it wants -- an actuating instance, a +// clear transition, a converged (or drifted, or unobserved) revision, a chosen live-session set, a +// capacity and a spawn mode -- and the graph it wants, and asks the same decision production asks. +// Nothing here touches a host; the two object ids are literal hex pinned by the fixture, never read +// from git. fn launch_fixture_instance_id() -> NonEmptyStr { "fixture-actuating-instance" as NonEmptyStr } @@ -118,7 +123,10 @@ fn launch_fixture_doc(nodes: List, edges: List) -> Roa } } -data launch_fixture_contract_note: String = "A closing execution contract for fixture nodes that must pass the contract gate: the same producer the canary binds (gunbc_claim_execution_contract), pointed at a fixture claim identity. The entry is not read by the admission -- contract_closure only asks whether validations exist -- so the fixture never runs it." +// A closing execution contract for fixture nodes that must pass the contract gate: the same +// producer the canary binds (gunbc_claim_execution_contract), pointed at a fixture claim identity. +// The entry is not read by the admission -- contract_closure only asks whether validations exist -- +// so the fixture never runs it. fn launch_fixture_contract() -> WorkItemExecutionContract { gunbc_claim_execution_contract( @@ -140,7 +148,11 @@ fn launch_fixture_with_contract(rn: RoadmapNode) -> RoadmapNode { } } -data launch_fixture_staged_note: String = "Staged standings for the real-driver controls (review 5059520727 finding 2): the halted arms are built by the SAME producers the production observer uses (launch_host_halt_transition, launch_host_stage_revision), so a witness that hands one to belt_tick_launch_pass runs the timer's real decision on a standing the observer could have produced -- and a standing that has no later fields, which is the effect-order claim itself." +// Staged standings for the real-driver controls (review 5059520727 finding 2): the halted arms are +// built by the SAME producers the production observer uses (launch_host_halt_transition, +// launch_host_stage_revision), so a witness handing one to belt_tick_launch_pass runs the timer's +// real decision on a standing the observer could have produced -- one with no later fields, which +// is the effect-order claim itself. fn launch_fixture_standing_halt_transition() -> LaunchHostStanding { launch_host_halt_transition(instance_id: launch_fixture_instance_id(), reason: "fixture: deployment transition in force") diff --git a/dag/test/claim/roadmap/roadmap_launch_admission_witness_test.dag b/dag/test/claim/roadmap/roadmap_launch_admission_witness_test.dag index 1228c07ec2f..d2ca541d744 100644 --- a/dag/test/claim/roadmap/roadmap_launch_admission_witness_test.dag +++ b/dag/test/claim/roadmap/roadmap_launch_admission_witness_test.dag @@ -71,7 +71,19 @@ import v2.std.live_tree { LiveTreeDisposition, SubstrateInputsOnly } data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data roadmap_launch_admission_witness_note: String = "RLM-1 red controls (docs/plans/roadmap-launch-mvp-plan.md section 3, RLM-1 falsifiers), each enrolled as a permanent regression control over the RLM-0 synthetic canary graph and the fixture host: (a) the blocked child is refused DependenciesBlocked and the tick fold over it produces no actuation outcome at all -- SpawnNotAdmitted is the only arm a refusal can reach, and Spawned / SpawnFailed are what actuation returns, so their absence IS the effect-ordering receipt; POST /dispatch shares the same LaunchAdmitted guard (gunbc.roadmap_belt_actuate belt_dispatch_node_for_instance); (b) a Timer in ManualReady over a Ready node is CauseNotPermitted and the fold starts nothing; (c) the mutation control: the blocked child's ledger with its dependency verdict replaced by GatePassed ADMITS, so the dependency gate is the load-bearing one; (d) revision drift refuses the page action and the backend outcome with one label and one reason; (e) a second Operator admission beside a running session is AlreadyLive. Every refusal here is a value the pure decision produced from fabricated facts; no witness reaches a host." +// RLM-1 red controls (docs/plans/roadmap-launch-mvp-plan.md section 3, RLM-1 falsifiers), each +// enrolled as a permanent regression control over the RLM-0 synthetic canary graph and the fixture +// host: (a) the blocked child is refused DependenciesBlocked and the tick fold over it produces no +// actuation outcome at all -- SpawnNotAdmitted is the only arm a refusal can reach, and Spawned / +// SpawnFailed are what actuation returns, so their absence IS the effect-ordering receipt; POST +// /dispatch shares the same LaunchAdmitted guard (gunbc.roadmap_belt_actuate +// belt_dispatch_node_for_instance); (b) a Timer in ManualReady over a Ready node is +// CauseNotPermitted and the fold starts nothing; (c) the mutation control: the blocked child's +// ledger with its dependency verdict replaced by GatePassed ADMITS, so the dependency gate is the +// load-bearing one; (d) revision drift refuses the page action and the backend outcome with one +// label and one reason; (e) a second Operator admission beside a running session is AlreadyLive. +// Every refusal here is a value the pure decision produced from fabricated facts; no witness +// reaches a host. fn graph() -> LaunchGraphStanding { launch_graph_of_document(doc: canary_doc(nodes: [canary_parent(signoff: Unsigned), canary_child()], edges: [roadmap_launch_canary_edge()])) @@ -471,7 +483,18 @@ test fn witness_contract_text_carries_gate_order_and_digest_is_hex16() -> Bool { && count(launch_gate_names()) == 9 } -data review_5059520727_controls_note: String = "Controls for the four production-boundary findings of review 5059520727 on #9696, each enrolled RED FIRST against the head the review named. (1) three Ready rows against one slot: the timer's fold reaches the admission for ALL of them -- AutomaticReady admits the first and answers LaunchNoCapacity for the rest, ManualReady answers LaunchCauseNotPermitted for all three; the reconcile no longer truncates. (2) the real timer decision (belt_tick_launch_pass) over STAGED host standings built by the production observer's own producers: a transition halt, a revision drift and an unobservable session set each refuse every desired node through the shared vocabulary, with the page and the route naming the same label and reason; a halted standing has no later fields, so the effect order is structural. (3) a present-but-unobserved session occupies its slot; a proven-exited or process-absent one frees it. (4) page, POST and timer bind one identity (node, mode, instance, revision), differing only in cause; the route's JSON and the durable tick receipt carry it whole and the receipt round-trips." +// Controls for the four production-boundary findings of review 5059520727 on #9696, each enrolled +// RED FIRST against the head the review named. (1) three Ready rows against one slot: the timer's +// fold reaches the admission for ALL of them -- AutomaticReady admits the first and answers +// LaunchNoCapacity for the rest, ManualReady answers LaunchCauseNotPermitted for all three; the +// reconcile no longer truncates. (2) the real timer decision (belt_tick_launch_pass) over STAGED +// host standings built by the production observer's own producers: a transition halt, a revision +// drift and an unobservable session set each refuse every desired node through the shared +// vocabulary, with the page and the route naming the same label and reason; a halted standing has +// no later fields, so the effect order is structural. (3) a present-but-unobserved session occupies +// its slot; a proven-exited or process-absent one frees it. (4) page, POST and timer bind one +// identity (node, mode, instance, revision), differing only in cause; the route's JSON and the +// durable tick receipt carry it whole and the receipt round-trips. fn rlm_ready_node(id: String) -> RoadmapNode { canary_node( @@ -749,7 +772,11 @@ test fn witness_tick_receipt_round_trips_launch_identities() -> Bool { } } -data pre_session_stage_note: String = "Review 5059681676 finding 2: the decision is staged so session observation sits behind the node, contract and dependency gates. A PENDING session set answers every model-only refusal WITHOUT sessions (LaunchStageDecided), answers LaunchStageNeedsSessions only for a node that passed every pre-session gate, and a pending standing that reaches the full decision refuses fail-closed at the live gate rather than reading pending as empty." +// Review 5059681676 finding 2: the decision is staged so session observation sits behind the node, +// contract and dependency gates. A PENDING session set answers every model-only refusal WITHOUT +// sessions (LaunchStageDecided), answers LaunchStageNeedsSessions only for a node that passed every +// pre-session gate, and a pending standing that reaches the full decision refuses fail-closed at +// the live gate rather than reading pending as empty. fn staged(standing: LaunchHostStanding, g: LaunchGraphStanding, node_id: String) -> LaunchStagedAdmission { launch_admission_staged(cause: Operator, standing: standing, graph: g, merged: [], node_id: node_id, reserved: 0) @@ -793,7 +820,10 @@ test fn witness_pending_sessions_reaching_full_decision_refuses_live_gate() -> B refused_as(a: decide(cause: Operator, standing: launch_fixture_standing_pending(mode: ManualReady), g: graph(), node_id: parent_id()), label: "gate_not_evaluated") } -data stage_boundary_mutation_note: String = "Review 5060354380 mutation control: the session-observation boundary in the frozen contract is a projection of the typed LaunchGateRow.stage marks over the canonical row roster, so reclassifying one row across the boundary, or reordering the roster, changes the serialized contract (and therefore the digest). A literal could not fail this." +// Review 5060354380 mutation control: the session-observation boundary in the frozen contract is a +// projection of the typed LaunchGateRow.stage marks over the canonical row roster, so reclassifying +// one row across the boundary, or reordering the roster, changes the serialized contract (and +// therefore the digest). A literal could not fail this. fn flip_stage(row: LaunchGateRow) -> LaunchGateRow { LaunchGateRow { diff --git a/dag/test/claim/roadmap/roadmap_launch_canary_witness_test.dag b/dag/test/claim/roadmap/roadmap_launch_canary_witness_test.dag index f760af7db44..f7d41698b88 100644 --- a/dag/test/claim/roadmap/roadmap_launch_canary_witness_test.dag +++ b/dag/test/claim/roadmap/roadmap_launch_canary_witness_test.dag @@ -45,7 +45,19 @@ import v2.std.live_tree { LiveTreeDisposition, SubstrateInputsOnly } data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data roadmap_launch_canary_witness_note: String = "RLM-0 (docs/plans/roadmap-launch-mvp-plan.md): the two-node canary in a SYNTHETIC roadmap graph, decided by the same predicates the live page and belt consume -- gunbc.roadmap_spawner spawn_frontier / next_spawnable / node_unmet_parent_ids and gunbc.roadmap_presentation work_scheduling -- never a readiness re-implemented here. Nothing in this file touches gunbc.roadmap_authority; the canary joins the live authority at RLM-3. Every falsifier is enrolled as a permanent regression control, not a one-off: (a) deleting the edge changes the child's decision, so the edge is shown load-bearing; (b) the blocker is the exact parent identity and a different identity is refused; (c) the oracle predicate is red on the pending sentinel, red on a wrong or missing nonce, green only on the exact expected value; (d) the admission finding, recorded rather than patched because admission is RLM-1's gate: gunbc.roadmap_spawner's Ready frontier admits a node whose execution contract is ExecutionContractUnspecified, and only gunbc.roadmap_dispatch_environment refuses it later -- two answers to one question, which RLM-1's single LaunchAdmission (ExecutionContractMissing) is scoped to collapse." +// RLM-0 (docs/plans/roadmap-launch-mvp-plan.md): the two-node canary in a SYNTHETIC roadmap graph, +// decided by the same predicates the live page and belt consume -- gunbc.roadmap_spawner +// spawn_frontier / next_spawnable / node_unmet_parent_ids and gunbc.roadmap_presentation +// work_scheduling -- never a readiness re-implemented here. Nothing in this file touches +// gunbc.roadmap_authority; the canary joins the live authority at RLM-3. Every falsifier is +// enrolled as a permanent regression control, not a one-off: (a) deleting the edge changes the +// child's decision, so the edge is shown load-bearing; (b) the blocker is the exact parent identity +// and a different identity is refused; (c) the oracle predicate is red on the pending sentinel, red +// on a wrong or missing nonce, green only on the exact expected value; (d) the admission finding, +// recorded rather than patched because admission is RLM-1's gate: gunbc.roadmap_spawner's Ready +// frontier admits a node whose execution contract is ExecutionContractUnspecified, and only +// gunbc.roadmap_dispatch_environment refuses it later -- two answers to one question, which RLM-1's +// single LaunchAdmission (ExecutionContractMissing) is scoped to collapse. fn canary_node( identity: RoadmapNodeIdentity, diff --git a/dag/test/claim/roadmap/roadmap_presentation_witness_test.dag b/dag/test/claim/roadmap/roadmap_presentation_witness_test.dag index 7553a376f1f..35dea7f328c 100644 --- a/dag/test/claim/roadmap/roadmap_presentation_witness_test.dag +++ b/dag/test/claim/roadmap/roadmap_presentation_witness_test.dag @@ -61,7 +61,12 @@ import gunbc.roadmap_presentation { data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data presentation_witness_fixture_note: String = "Every witness here runs against CONSTRUCTED fixtures, never the live roadmap population — a live count or a live row is a moving target that turns a semantic claim into a snapshot transcription (the A1 lesson, and the standing fixtures-not-live-counts rule). The specimen fixture is the operator's falsifier row (docs/plans/roadmap-presentation-seam-design.md section 1): seven obligations with Environment/Workspace/Agent complete, four pending, worker process exited, session container present." +// Every witness here runs against CONSTRUCTED fixtures, never the live roadmap population — a live +// count or row is a moving target that turns a semantic claim into a snapshot transcription (the A1 +// lesson, and the standing fixtures-not-live-counts rule). The specimen fixture is the operator's +// falsifier row (docs/plans/roadmap-presentation-seam-design.md section 1): seven obligations with +// Environment/Workspace/Agent complete, four pending, worker process exited, session container +// present. fn fx_specimen_segments() -> List { [ @@ -84,7 +89,13 @@ fn fx_specimen_activity() -> ActivityView { ) } -data specimen_consequence_note: String = "The operator's worked example verbatim: 'session container present' beside 'process exited' must not ship as an uninterpreted evidence pair. The routine specimen summary must (a) state the consequence sentence, (b) name the NEXT obligation rather than implying a percentage, and (c) carry the ledger's remaining count — while the raw container/process facts appear only as labeled evidence rows. The RED control: a summary that merely relabels the evidence ('process exited') or asserts a scalar ('43%') has no arm that could produce it — the discriminating assertions below fail if the consequence, the next obligation, or the derived count is dropped." +// The operator's worked example verbatim: 'session container present' beside 'process exited' must +// not ship as an uninterpreted evidence pair. The routine specimen summary must (a) state the +// consequence sentence, (b) name the NEXT obligation rather than implying a percentage, and (c) +// carry the ledger's remaining count — the raw container/process facts appear only as labeled +// evidence rows. The RED control: a summary that merely relabels the evidence ('process exited') or +// asserts a scalar ('43%') has no arm that could produce it — the discriminating assertions below +// fail if the consequence, the next obligation, or the derived count is dropped. test fn witness_specimen_summary_states_consequence_and_next_obligation() -> Bool { match fx_specimen_activity() { @@ -138,7 +149,12 @@ test fn witness_agent_running_reads_as_working_not_completed() -> Bool { } } -// A refusal is a first-class presentation state with its LOCATED reason, never a styling variant of progress (DESIGN 5: typed, located; the attention rule auto-expands it). The discriminating fixture puts the refusal mid-ledger; the view must surface the refusing obligation's own detail string, and a failed segment must rank as anomalous ActiveWork — the two are distinct states with distinct remedies, and a refused ledger outranks a failed one because the refusal names an evidence gap the failure count cannot explain. +// A refusal is a first-class presentation state with its LOCATED reason, never a styling variant of +// progress (DESIGN 5: typed, located; the attention rule auto-expands it). The discriminating +// fixture puts the refusal mid-ledger; the view must surface the refusing obligation's own detail +// string, and a failed segment must rank as anomalous ActiveWork — distinct states with distinct +// remedies, and a refused ledger outranks a failed one because the refusal names an evidence gap +// the failure count cannot explain. test fn witness_refused_segment_projects_located_reason() -> Bool { let segments = [ WorkflowSegment { kind: EnvironmentWorkflowSegment, state: WorkflowSegmentComplete, detail: "" }, @@ -182,7 +198,11 @@ test fn witness_failed_segment_is_anomalous_active_work() -> Bool { } } -// The ticket headline is ONE typed field read end-to-end. The discriminating input is a headline that CONTAINS the legacy separators (an em-dash clause and a sentence break): under the deleted recompose-and-reparse round trip ('**headline** — brief' then split at punctuation) this headline would come back truncated at its own dash. The legacy residue is asserted separately on an AuthoredLine, where the lead heuristic is the declared residue of this projection. +// The ticket headline is ONE typed field read end-to-end. The discriminating input is a headline +// that CONTAINS the legacy separators (an em-dash clause and a sentence break): under the deleted +// recompose-and-reparse round trip ('**headline** — brief' then split at punctuation) it would come +// back truncated at its own dash. The legacy residue is asserted separately on an AuthoredLine, +// where the lead heuristic is the declared residue of this projection. test fn witness_ticket_headline_survives_own_punctuation() -> Bool { let t = gunbc.roadmap_authority.fields( headline: "Close the wall — phase 2. Cleanly", @@ -210,7 +230,14 @@ test fn witness_summary_is_absent_until_typed_source_exists() -> Bool { } } -data exact_constructor_note: String = "The exact-constructor discrimination (operator constraint 3): 'active' is never a disjunction of narrower facts. NoActiveAttempt projects to NoActiveWork with zero furniture; an unreadable evidence situation projects to ActivityUnobservable PRESERVING its located reason — distinct from both refusal and absence; and a fully-complete ledger projects to CompletedWork (the receipt-backed outcome), never to a routine ActiveWork whose summary happens to say complete. The RED controls are the cross-arm assertions: if unobservable collapsed into absence, the reason would be dropped and the second witness fails; if terminal collapsed into active, the third witness's CompletedWork arm never matches." +// The exact-constructor discrimination (operator constraint 3): 'active' is never a disjunction of +// narrower facts. NoActiveAttempt projects to NoActiveWork with zero furniture; an unreadable +// evidence situation projects to ActivityUnobservable PRESERVING its located reason — distinct from +// both refusal and absence; a fully-complete ledger projects to CompletedWork (the receipt-backed +// outcome), never to a routine ActiveWork whose summary happens to say complete. The RED controls +// are the cross-arm assertions: if unobservable collapsed into absence the reason would be dropped +// and the second witness fails; if terminal collapsed into active the third witness's CompletedWork +// arm never matches. test fn witness_no_attempt_projects_zero_furniture() -> Bool { match activity_view_of(facts: NoActiveAttempt) { @@ -267,9 +294,10 @@ fn fx_blocked() -> LaunchAdmission { LaunchRefused { refusal: LaunchDependenciesBlocked { blockers: ["a2-parent-1"] } } } -// RLM-1: the dispatch action is the launch admission's projection. An admitted row's dispatch is Available AND -// Primary; a refused row's dispatch is Unavailable and Secondary, carrying the refusal's wire label and reason -// -- there is no override arm left to render a blocked row as operable. +// RLM-1: the dispatch action is the launch admission's projection. An admitted row's dispatch is +// Available AND Primary; a refused row's dispatch is Unavailable and Secondary, carrying the +// refusal's wire label and reason -- there is no override arm left to render a blocked row as +// operable. test fn witness_admitted_dispatch_is_primary_refused_is_unavailable() -> Bool { let ready_view = action_view(lifecycle: OpenLifecycle, admission: fx_admitted(node_id: "a2-row")) let blocked_view = action_view(lifecycle: OpenLifecycle, admission: fx_blocked()) @@ -298,7 +326,15 @@ test fn witness_done_and_superseded_rows_offer_no_dispatch() -> Bool { && count(dispatch_action(lifecycle: SupersededLifecycle, admission: fx_admitted(node_id: "a2-row"))) == 0 } -data cleanup_from_admission_note: String = "The session action derives from the OBSERVED cleanup admission and from nothing else (operator blocker 4, 2026-08-01). The prior constructor minted an ActionAvailable ClearSessionAction whenever the activity arm looked active/refused/completed — availability inferred from presentation state, exactly the fabrication the two-axis note forbids in the other direction. The discriminating trio: an allowed observed cleanup is Available and Diagnostic; an observed-but-disallowed cleanup is ActionUnavailable (this arm's first real consumer) while KEEPING its label and detail so the refusal is legible; no observed cleanup action is NoSessionAction, not an empty-labeled button. The RED: the deleted arm — action_view over any activity yields no ClearSessionAction — is asserted directly, so reintroducing the fabrication reds." +// The session action derives from the OBSERVED cleanup admission and nothing else (operator blocker +// 4, 2026-08-01). The prior constructor minted an ActionAvailable ClearSessionAction whenever the +// activity arm looked active/refused/completed — availability inferred from presentation state, the +// fabrication the two-axis note forbids in the other direction. The discriminating trio: an allowed +// observed cleanup is Available and Diagnostic; an observed-but-disallowed cleanup is +// ActionUnavailable (this arm's first real consumer) while KEEPING its label and detail so the +// refusal is legible; no observed cleanup action is NoSessionAction, not an empty-labeled button. +// The RED: the deleted arm — action_view over any activity yields no ClearSessionAction — is +// asserted directly, so reintroducing the fabrication reds. test fn witness_session_action_derives_from_observed_admission() -> Bool { let allowed = session_action_view(cleanup_action: "clear", cleanup_allowed: true, cleanup_detail: "only retained tmux session metadata will be removed") @@ -340,7 +376,10 @@ test fn witness_action_view_never_fabricates_cleanup() -> Bool { && action_view_has_no_clear(v: action_view(lifecycle: ReviewLifecycle, admission: fx_blocked())) } -data session_facts_decided_note: String = "The decided session line and title detail (operator blocker 5): the client formerly concatenated 'session · present — ' + process_state and its own provider-facts title in TypeScript — a second prose authority. Both strings are now decided here and the witness pins them, including the empty-process-detail arm (no dangling separator)." +// The decided session line and title detail (operator blocker 5): the client formerly concatenated +// 'session · present — ' + process_state and its own provider-facts title in TypeScript — a second +// prose authority. Both strings are now decided here and the witness pins them, including the +// empty-process-detail arm (no dangling separator). test fn witness_session_facts_line_and_detail_are_decided() -> Bool { let v = session_facts_view( @@ -369,7 +408,10 @@ test fn witness_session_facts_line_and_detail_are_decided() -> Bool { && bare.detail == "provider codex (configured codex, readiness ready) — gunbc-belt-a2-row" } -data lifecycle_axis_note: String = "Lifecycle discriminates on the node's own facts, distinct from frontier scheduling: an Unsigned node with unmerged evidence is open; merged evidence without signoff is review — implementation artifacts never accept (roadmap_acceptance_boundary_note); an accepting signoff is done; a superseded line outranks everything and carries its forwarding pointer." +// Lifecycle discriminates on the node's own facts, distinct from frontier scheduling: an Unsigned +// node with unmerged evidence is open; merged evidence without signoff is review — implementation +// artifacts never accept (roadmap_acceptance_boundary_note); an accepting signoff is done; a +// superseded line outranks everything and carries its forwarding pointer. test fn witness_lifecycle_axes_discriminate() -> Bool { let open_node = gunbc.roadmap_authority.authored(identity: "rnfx_A2PRES0000000000000003", id: "a2-open", done: false, content: "open work") @@ -386,7 +428,11 @@ test fn witness_lifecycle_axes_discriminate() -> Bool { && work_lifecycle_key(l: work_lifecycle(rn: superseded_node, merged: [])) == "superseded" } -data supporting_facts_demotion_note: String = "Owner, sizing, and carriers are supporting facts for the disclosure region — present when declared, absent (not empty-labeled) when not. The integration witness drives work_row_view end-to-end on a fixture node and asserts the composed row: typed headline, honest Absent summary, the typed scheduling position with its complete blocker set, and the actions/facts composed from the same fixture." +// Owner, sizing, and carriers are supporting facts for the disclosure region — present when +// declared, absent (not empty-labeled) when not. The integration witness drives work_row_view +// end-to-end on a fixture node and asserts the composed row: typed headline, honest Absent summary, +// the typed scheduling position with its complete blocker set, and the actions/facts composed from +// the same fixture. fn fx_row_nodes() -> List { [ @@ -446,7 +492,12 @@ test fn witness_work_row_view_composes_from_fixture() -> Bool { && match row.activity { NoActiveWork => true ActiveWork { summary: _, obligations: _, remaining_obligation_count: _, current_activity: _, attention: _, evidence: _ } => false ActiveWorkRefused { summary: _, located_reason: _, evidence: _ } => false LegacySupersedableAttempt { summary: _, located_reason: _, attempt_key: _, evidence: _ } => false CompletedWork { outcome: _, evidence: _ } => false ActivityUnobservable { reason: _ } => false } } -// The scheduling axis discriminates by the SAME predicates spawn_frontier filters (operator blocker 2: ready was a caller-assertable Bool; now the position is projected, not asserted). The fixtures cover the five arms: a sized dependency-met node is Ready; a sized node under an open parent is Upcoming CARRYING that blocker; an unsized node is Unplanned (never conflated with Upcoming — it has no blockers to fabricate); a superseded line is Superseded whatever else holds; and the dependency line renders only for an Upcoming row with more than one blocker. +// The scheduling axis discriminates by the SAME predicates spawn_frontier filters (operator blocker +// 2: ready was a caller-assertable Bool; now the position is projected, not asserted). The fixtures +// cover the five arms: a sized dependency-met node is Ready; a sized node under an open parent is +// Upcoming CARRYING that blocker; an unsized node is Unplanned (never conflated with Upcoming — it +// has no blockers to fabricate); a superseded line is Superseded whatever else holds; and the +// dependency line renders only for an Upcoming row with more than one blocker. test fn witness_scheduling_projects_typed_positions() -> Bool { let nodes = fx_row_nodes() let edges = fx_row_edges() @@ -470,7 +521,10 @@ test fn witness_dependency_line_only_for_multi_blocker_upcoming() -> Bool { && (match ready { Absent => true Present { value: _ } => false }) } -data active_before_ready_note: String = "The workspace grouping (operator blocker 6): a row with active or refused work belongs to the operator's attention band above every idle Ready row; CompletedWork stays in its scheduling bucket because a finished receipt is not work in flight; unobservable rows do not join the active band — unknowable never rounds to active any more than to absent." +// The workspace grouping (operator blocker 6): a row with active or refused work belongs to the +// operator's attention band above every idle Ready row; CompletedWork stays in its scheduling +// bucket because a finished receipt is not work in flight; unobservable rows do not join the active +// band — unknowable never rounds to active any more than to absent. fn band_entry_row_count(entries: List) -> Int { fold(entries, init: 0, f: (acc, e) => match e { @@ -497,7 +551,15 @@ test fn witness_daily_workspace_surfaces_active_above_ready() -> Bool { && !band_entry_has_active(entries: ws.upcoming) } -// The family-once receipts, all against constructed facts. Stated-once: two listed members plus one UNLISTED lookalike (its headline literally starts with the family claim prose) produce ONE BandFamily carrying the claim, member rows whose headlines are the typed SUBJECTS verbatim, and the lookalike as an ungrouped BandRow with its fused headline untouched — proving membership is the typed fact list, never a prefix scan, in both directions (a subject CONTAINING claim prose is not stripped; a headline MATCHING claim prose is not captured). Attention-outranks-taxonomy: a member with active work leaves for the Active band as an individual row while the group keeps only its remaining member. Missing decl: a member fact naming an undeclared family renders as its own ungrouped row (no fabricated header). +// The family-once receipts, all against constructed facts. Stated-once: two listed members plus one +// UNLISTED lookalike (its headline literally starts with the family claim prose) produce ONE +// BandFamily carrying the claim, member rows whose headlines are the typed SUBJECTS verbatim, and +// the lookalike as an ungrouped BandRow with its fused headline untouched — membership is the typed +// fact list, never a prefix scan, in both directions (a subject CONTAINING claim prose is not +// stripped; a headline MATCHING claim prose is not captured). Attention-outranks-taxonomy: a member +// with active work leaves for the Active band as an individual row while the group keeps only its +// remaining member. Missing decl: a member fact naming an undeclared family renders as its own +// ungrouped row (no fabricated header). fn fx_family_member_row(node_id: String, headline: String, activity: ActivityView) -> WorkRowView { let base = fx_row(activity: activity) WorkRowView { @@ -591,7 +653,9 @@ test fn witness_undeclared_family_member_stays_ungrouped_row() -> Bool { }) } -data lifecycle_chip_witness_note: String = "Routine-state collapse both directions: the open default derives chip-hidden (the band and the node class still carry the state), and every departing lifecycle derives chip-shown. A future lifecycle arm added without a chip decision fails compile at the match, not silently." +// Routine-state collapse both directions: the open default derives chip-hidden (the band and the +// node class still carry the state), and every departing lifecycle derives chip-shown. A future +// lifecycle arm added without a chip decision fails compile at the match, not silently. test fn witness_lifecycle_chip_only_when_discriminating() -> Bool { !lifecycle_chip_renders(l: OpenLifecycle) @@ -600,7 +664,12 @@ test fn witness_lifecycle_chip_only_when_discriminating() -> Bool { && lifecycle_chip_renders(l: SupersededLifecycle) } -// The one-failure-once discrimination: a workspace-level refusal produces ONE banner (the impact view carries the located reason) and covers each row's unobservable narration — but only the unobservable arm, and only while the workspace impact is present. The REDs: an active row is never covered (a live attempt's narration must survive a broken observation channel claim), and with a nominal workspace observation a row-specific unobservable reason narrates on its own row (coverage false). +// The one-failure-once discrimination: a workspace-level refusal produces ONE banner (the impact +// view carries the located reason) and covers each row's unobservable narration — only the +// unobservable arm, and only while the workspace impact is present. The REDs: an active row is +// never covered (a live attempt's narration must survive a broken observation channel claim), and +// with a nominal workspace observation a row-specific unobservable reason narrates on its own row +// (coverage false). test fn witness_workspace_impact_narrates_once() -> Bool { let impact = observation_impact_view(workflow_refused: Present { value: "GET /workflow.json refused: connection refused" }) let nominal = observation_impact_view(workflow_refused: none) diff --git a/dag/test/claim/roadmap/roadmap_program_view_live_corpus_receipt_test.dag b/dag/test/claim/roadmap/roadmap_program_view_live_corpus_receipt_test.dag index ec9b3b90b55..fd1b000194c 100644 --- a/dag/test/claim/roadmap/roadmap_program_view_live_corpus_receipt_test.dag +++ b/dag/test/claim/roadmap/roadmap_program_view_live_corpus_receipt_test.dag @@ -18,7 +18,16 @@ import gunbc.roadmap_authority { data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data live_corpus_receipt_note: String = "LIVE-AUTHORITY INTEGRATION RECEIPT (operator verdict 2026-08-05, PR #7822; oracle corrected per operator REQUEST_CHANGES): ONE receipt proving the live roadmap authority closure (declared_roadmap_nodes, projected_roadmap_dependency_edges_projection, roadmap_acceptance_receipts) projects through gunbc.roadmap_program_view without unresolved references — ProgramViewDerived, not tree-copied population literals. View cardinality is joined to the program spec authorities (v1_exit_finish_lines, v1_convergence_fronts), not numbers copied from today's tree. This is evidentiary integration wiring, not ordinary business logic; it rides the falsifier substrate long lane (gunbc.ci_layer_roots falsifier_substrate_long_lane_rows), excluded from per-PR discovery. Business algebra stays on planted fixtures in test.claim.roadmap_program_view_witness." +// LIVE-AUTHORITY INTEGRATION RECEIPT (operator verdict 2026-08-05, PR #7822; oracle corrected per +// operator REQUEST_CHANGES): ONE receipt proving the live roadmap authority closure +// (declared_roadmap_nodes, projected_roadmap_dependency_edges_projection, +// roadmap_acceptance_receipts) projects through gunbc.roadmap_program_view without unresolved +// references — ProgramViewDerived, not tree-copied population literals. View cardinality is joined +// to the program spec authorities (v1_exit_finish_lines, v1_convergence_fronts), not numbers copied +// from today's tree. This is evidentiary integration wiring, not ordinary business logic; it rides +// the falsifier substrate long lane (gunbc.ci_layer_roots falsifier_substrate_long_lane_rows), +// excluded from per-PR discovery. Business algebra stays on planted fixtures in +// test.claim.roadmap_program_view_witness. test fn live_roadmap_program_view_corpus_projection_receipt() -> Bool { match roadmap_acceptance_receipts() { diff --git a/dag/test/claim/roadmap/roadmap_program_view_witness_test.dag b/dag/test/claim/roadmap/roadmap_program_view_witness_test.dag index 55a7d7bddc4..deae4cf1606 100644 --- a/dag/test/claim/roadmap/roadmap_program_view_witness_test.dag +++ b/dag/test/claim/roadmap/roadmap_program_view_witness_test.dag @@ -28,7 +28,16 @@ import gunbc.roadmap_program_view { program_view, } -data roadmap_program_view_witness_note: String = "SMALL SYNTHETIC BUSINESS WITNESSES for gunbc.roadmap_program_view (operator verdict 2026-08-05): every oracle is PLANTED on a hand-authored fixture graph — never copied from the live roadmap tree (DESIGN section 5). Covers acceptance algebra (receipt moves primary constraint; accepted mid-chain collapses depth), dependency hold (unmet parents block startability), duplicate receipt and duplicate node identity refusal, in-flight overlay, merged-PR and contract non-acceptance, misspelled finish-line/gate refusal, proposed-plane absence, and derived front/constraint facts on the fixture. Live-corpus wiring — that the real roadmap authority projects and every finish line and gate resolves — is ONE separately classified receipt in test.claim.roadmap_program_view_live_corpus_receipt (falsifier substrate long lane), not counted here." +// SMALL SYNTHETIC BUSINESS WITNESSES for gunbc.roadmap_program_view (operator verdict 2026-08-05): +// every oracle is PLANTED on a hand-authored fixture graph — never copied from the live roadmap +// tree (DESIGN section 5). Covers acceptance algebra (receipt moves primary constraint; accepted +// mid-chain collapses depth), dependency hold (unmet parents block startability), duplicate receipt +// and duplicate node identity refusal, in-flight overlay, merged-PR and contract non-acceptance, +// misspelled finish-line/gate refusal, proposed-plane absence, and derived front/constraint facts +// on the fixture. Live-corpus wiring — that the real roadmap authority projects and every finish +// line and gate resolves — is ONE separately classified receipt in +// test.claim.roadmap_program_view_live_corpus_receipt (falsifier substrate long lane), not counted +// here. fn fx_ticket(headline: String) -> TicketFields { TicketFields { diff --git a/dag/test/claim/roadmap/roadmap_provider_events_witness_test.dag b/dag/test/claim/roadmap/roadmap_provider_events_witness_test.dag index b64c0b65480..3a6f309dc37 100644 --- a/dag/test/claim/roadmap/roadmap_provider_events_witness_test.dag +++ b/dag/test/claim/roadmap/roadmap_provider_events_witness_test.dag @@ -174,7 +174,10 @@ test fn refusal_marks_prior_activity_as_historical() -> Bool { } } -data codex_budget_row_evaluation_witness_note: String = "Forces the three CharacterCount budget rows to EVALUATE, not merely typecheck. A data row can pass every single-entry witness and still fail in CI's affected-set re-eval leg, which evaluates changed data items — that is exactly how `2 as Seconds` shipped green from this branch. Reading the values here makes an unevaluable budget row red locally." +// Forces the three CharacterCount budget rows to EVALUATE, not merely typecheck. A data row can +// pass every single-entry witness and still fail in CI's affected-set re-eval leg, which evaluates +// changed data items — that is exactly how `2 as Seconds` shipped green from this branch. Reading +// the values here makes an unevaluable budget row red locally. test fn codex_character_budgets_are_measured_counts() -> Bool { character_count_value(c: codex_provider_event_line_observation_budget) == 65536 @@ -186,7 +189,17 @@ test fn codex_character_budgets_are_measured_counts() -> Bool { ) } -data codex_item_activity_anchor_witness_note: String = "review 44058. The activity read used to scan the WHOLE projected line for a \"type\":\"…\" fragment, so a sibling or nested object carrying another item type reclassified the pane — the same shape the top-level classifier is already anchored against (nested_type_token_cannot_fabricate_terminal_success, right above). The pair is discriminating in both directions: the forged line puts item.type = agent_message beside a sibling object spelling file_change, and the old scan answered \"editing files\" on it because file_change is tested before agent_message; the genuine line proves the anchored walk still finds a real file_change rather than having simply stopped working. Reachability: today the projector emits only a top-level type plus an item object carrying only its own type, so the sibling shape arrives on projector drift or on any future direct read of the raw stream — this is the defense-in-depth the top-level anchor already carries, applied to the member beneath it." +// review 44058. The activity read used to scan the WHOLE projected line for a "type":"…" fragment, +// so a sibling or nested object carrying another item type reclassified the pane — the same shape +// the top-level classifier is already anchored against +// (nested_type_token_cannot_fabricate_terminal_success, right above). The pair is discriminating in +// both directions: the forged line puts item.type = agent_message beside a sibling object spelling +// file_change, and the old scan answered "editing files" on it because file_change is tested before +// agent_message; the genuine line proves the anchored walk still finds a real file_change rather +// than having simply stopped working. Reachability: today the projector emits only a top-level type +// plus an item object carrying only its own type, so the sibling shape arrives on projector drift +// or on any future direct read of the raw stream — this is the defense-in-depth the top-level +// anchor already carries, applied to the member beneath it. fn activity_of(text: String) -> String { match provider_execution_state(parsed: parse_codex_jsonl(text: text)) { @@ -234,7 +247,17 @@ test fn roadmap_provider_events_keystone_holds() -> Bool { && refusal_marks_prior_activity_as_historical() } -data agent_report_projection_witness_note: String = "The agent REPORT members of the projection filter, pinned as a string contract because the filter is a jq program the substrate assembles but does not itself interpret (codex_projection_filter_scaffold_note). Nothing downstream of the shell can prove what the projector emitted, so the claims that matter here are: the report bound is the MESSAGE budget and not the detail budget beside it (a copy-paste of the wrong bound would still emit valid jq and still look fine on a short message, failing only on the day a long one arrived); the truncation flag is computed with a length comparison against the ORIGINAL text, so it describes the provider output rather than the slice; and the anchored item.type walk is untouched, since the report is emitted as a member AFTER item.type and the walk depends on that position. The behavioural half — real captured events through real jq — is dag/test/fixture/codex_provider_events, whose third line carries the item.text this filter reads." +// The agent REPORT members of the projection filter, pinned as a string contract because the filter +// is a jq program the substrate assembles but does not itself interpret +// (codex_projection_filter_scaffold_note). Nothing downstream of the shell can prove what the +// projector emitted, so the claims that matter here are: the report bound is the MESSAGE budget and +// not the detail budget beside it (a copy-paste of the wrong bound would still emit valid jq and +// still look fine on a short message, failing only on the day a long one arrived); the truncation +// flag is computed with a length comparison against the ORIGINAL text, so it describes the provider +// output rather than the slice; and the anchored item.type walk is untouched, since the report is +// emitted as a member AFTER item.type and the walk depends on that position. The behavioural half — +// real captured events through real jq — is dag/test/fixture/codex_provider_events, whose third +// line carries the item.text this filter reads. fn projection_filter_text() -> String { codex_provider_event_projection_filter as String } diff --git a/dag/test/claim/roadmap/roadmap_publish_observe_witness_test.dag b/dag/test/claim/roadmap/roadmap_publish_observe_witness_test.dag index 4fcf9419780..cada130dfe0 100644 --- a/dag/test/claim/roadmap/roadmap_publish_observe_witness_test.dag +++ b/dag/test/claim/roadmap/roadmap_publish_observe_witness_test.dag @@ -94,7 +94,14 @@ test fn a_failed_ref_advertisement_refuses_rather_than_reading_empty() -> Bool { } } -data renderer_is_a_projection_note: String = "THE RENDERER IS CLAIMED SEPARATELY FROM THE CAUSE, and the split is the point of typing the cause at all. The claims above assert the FIELDS - which failure, which remote, which exit code, which stderr - so they hold whatever sentence is produced from them. This claim asserts that the sentence is derived from those fields and names the OPERATION rather than the argv spelling, which is the property the transport-anemia plan asks for.\\n\\nThe previous cut could only assert substrings of a flattened String, so it could not distinguish a renderer that lost a field from one that never had it. Splitting the two means a rendering regression and a modeling regression now fail different claims." +// THE RENDERER IS CLAIMED SEPARATELY FROM THE CAUSE, and the split is the point of typing the cause +// at all. The claims above assert the FIELDS - which failure, which remote, which exit code, which +// stderr - so they hold whatever sentence is produced from them. This claim asserts that the +// sentence is derived from those fields and names the OPERATION rather than the argv spelling, +// which is the property the transport-anemia plan asks for.\n\nThe previous cut could only assert +// substrings of a flattened String, so it could not distinguish a renderer that lost a field from +// one that never had it. Splitting the two means a rendering regression and a modeling regression +// now fail different claims. test fn the_renderer_names_the_operation_and_not_the_argv_spelling() -> Bool { let rendered = render_remote_branch_read_failure( @@ -171,7 +178,12 @@ test fn the_empty_projection_filter_returns_only_the_degenerate_ref() -> Bool { && count(advertised_refs_projecting_empty_branch(refs: [])) == 0 } -data end_to_end_note: String = "The observation is only worth building if it composes with the judgment it was built for, so this claim runs an advertisement all the way to a PublicationOutcome. It is the first place the two halves meet: extdeps.git reads the ref advertisement, gunbc.roadmap_publish_observe turns it into observations, gunbc.roadmap_publish adjudicates. Before this slice roadmap_publish had no producer at all - adjudicate_publication was called only from its own witness - so the adjudicator was a judgment nothing could ask." +// The observation is only worth building if it composes with the judgment it was built for, so this +// claim runs an advertisement all the way to a PublicationOutcome. It is the first place the two +// halves meet: extdeps.git reads the ref advertisement, gunbc.roadmap_publish_observe turns it into +// observations, gunbc.roadmap_publish adjudicates. Before this slice roadmap_publish had no +// producer at all - adjudicate_publication was called only from its own witness - so the +// adjudicator was a judgment nothing could ask. fn branches_of(o: RemoteBranchObservation) -> List { match o { @@ -215,7 +227,12 @@ test fn an_advertisement_at_another_head_adjudicates_as_diverged() -> Bool { data divergence_is_the_point_note: String = "The two claims above are the same advertisement differing only in which commit the branch points at, and they must not produce the same answer. A name-shaped publication check reports both as published, which is precisely the defect the exact-head rewrite exists to remove: the ordinary state after a worker pushes a revision while a review is in flight is a branch whose name still matches and whose head no longer does." -data worktree_binding_witness_note: String = "THESE ARE CONSTRUCTED, NOT OBSERVED, which is the property the observer/adjudicator split in gunbc.roadmap_publish_observe exists to buy. worktree_repository_binding_of takes the four facts a `git remote get-url` produces and decides; observe_worktree_repository_binding only feeds it. So every arm - including the two failure arms - is reachable here with no git, no worktree and no network, and a witness that needed a real misconfigured checkout to exercise the mismatch arm would never have been written." +// THESE ARE CONSTRUCTED, NOT OBSERVED, which is the property the observer/adjudicator split in +// gunbc.roadmap_publish_observe exists to buy. worktree_repository_binding_of takes the four facts +// a `git remote get-url` produces and decides; observe_worktree_repository_binding only feeds it. +// So every arm - including the two failure arms - is reachable here with no git, no worktree and no +// network, and a witness that needed a real misconfigured checkout to exercise the mismatch arm +// would never have been written. test fn worktree_bound_to_the_subject_repository_is_recognized() -> Bool { match worktree_repository_binding_of( diff --git a/dag/test/claim/roadmap/roadmap_publish_witness_test.dag b/dag/test/claim/roadmap/roadmap_publish_witness_test.dag index 0a68d2e9b24..8f73b7e531a 100644 --- a/dag/test/claim/roadmap/roadmap_publish_witness_test.dag +++ b/dag/test/claim/roadmap/roadmap_publish_witness_test.dag @@ -209,7 +209,11 @@ test fn a_pull_request_against_another_base_does_not_bind() -> Bool { } } -// THE HOLE THE PREVIOUS CUT LEFT. With no pull request to compare against, an earlier version established only that a ref with the right NAME existed — abandoning the exact-head thesis on the one path where nothing else would reveal the mismatch. A stale branch from an earlier attempt satisfied it. Both directions are asserted: at the expected head is its own arm, and diverged names both shas. +// THE HOLE THE PREVIOUS CUT LEFT. With no pull request to compare against, an earlier version +// established only that a ref with the right NAME existed — abandoning the exact-head thesis on the +// one path where nothing else would reveal the mismatch; a stale branch from an earlier attempt +// satisfied it. Both directions are asserted: at the expected head is its own arm, and diverged +// names both shas. test fn a_remote_branch_at_the_expected_head_without_a_pull_request_is_its_own_arm() -> Bool { let outcome = adjudicate_with( pulls: PullRequestsRead { pulls: [] }, @@ -255,7 +259,12 @@ test fn a_stale_remote_branch_diverges_rather_than_counting_as_published() -> Bo } } -// The pull-request fold got 0/1/many in the first cut of that correction and the remote-ref fold beside it did not - it handled zero and then took the first of the rest, which is the same silent pick one screen below the note forbidding it. This is stated in BOTH orders on purpose: with the expected head first, the old code answered RemoteBranchAtExpectedHeadWithoutPullRequest, and with the stale ref first it answered RemoteBranchHeadDiverged, so a single-order claim would have been satisfied by list position rather than by a decision. Two orders over one observation make the answer order-independent, which is the property that was actually missing. +// The pull-request fold got 0/1/many in the first cut of that correction; the remote-ref fold +// beside it handled zero and then took the first of the rest — the silent pick one screen below the +// note forbidding it. Stated in BOTH orders on purpose: expected head first, the old code answered +// RemoteBranchAtExpectedHeadWithoutPullRequest; stale ref first, RemoteBranchHeadDiverged — so a +// single-order claim would be satisfied by list position, not a decision. Two orders over one +// observation assert order-independence, the property that was missing. fn ambiguous_over_two_refs(outcome: PublicationOutcome) -> Bool { match outcome { RemoteBranchBindingAmbiguous { branch: _, remote: _, refs_matched } => @@ -420,8 +429,13 @@ test fn the_bound_detail_distinguishes_draft_from_ready() -> Bool { && string_contains(s: as_ready, pattern: "pull request #22") } -data receipt_witness_scope_note: String = "What is claimed here is the RECEIPT ROUND TRIP - that what publication_receipt_json writes, publication_receipt_decode reads back with the same outcome AND the same subject, and that a document this emitter did not write refuses rather than decoding to something plausible.\\n\\nThe discriminating pair is deliberate: two receipts that differ ONLY in expected_head must decode to different subjects. A receipt format that dropped the subject would pass every positive claim above and fail that one, which is why it is here rather than left to inspection." - +// What is claimed here is the RECEIPT ROUND TRIP: what publication_receipt_json writes, +// publication_receipt_decode reads back with the same outcome AND subject, and a document this +// emitter did not write refuses rather than decoding to something plausible. +// +// The discriminating pair: two receipts differing ONLY in expected_head must decode to different +// subjects. A format that dropped the subject would pass every positive claim above and fail that +// one. data fixture_repository: Repository = Repository { owner: "gunb-ai", @@ -492,7 +506,14 @@ test fn a_receipt_round_trips_its_outcome_and_its_subject() -> Bool { } } -data receipt_preserves_the_binding_note: String = "THIS IS THE CLAIM THE EARLIER RECEIPT FORMAT COULD NOT MAKE, and the reason the schema went to v2. Review's entire input is the pull-request binding publication established: a number and a head. The previous format serialized an outcome key and a rendered English sentence, so a Review producer could recover the number only by parsing prose or by asking GitHub a second time - and a second query can disagree with the first, which is the divergence this lane exists to catch, reintroduced by the carrier meant to record it.\\n\\nSo this asserts the FIELDS survive the round trip, not that a string mentions them." +// THIS IS THE CLAIM THE EARLIER RECEIPT FORMAT COULD NOT MAKE, and why the schema went to v2. +// Review's entire input is the pull-request binding publication established: a number and a head. +// The previous format serialized an outcome key and a rendered English sentence, so a Review +// producer could recover the number only by parsing prose or asking GitHub a second time — and a +// second query can disagree with the first, the divergence this lane exists to catch, reintroduced +// by the carrier meant to record it. +// +// So this asserts the FIELDS survive the round trip, not that a string mentions them. test fn a_bound_receipt_preserves_the_pull_request_binding() -> Bool { match publication_receipt_decode( @@ -556,7 +577,22 @@ test fn a_receipt_records_the_head_that_was_asked_about() -> Bool { } } -data one_head_per_bound_receipt_note: String = "THE DEFECT THIS REFUSES, stated as the shape of the document rather than as a rule: a receipt that names THIS subject and simultaneously binds a DIFFERENT pull-request head. Under the earlier cut ReceiptBound carried its own pr_head and the decoder read it independently of the subject, so such a document decoded cleanly, matched the subject on all six subject fields, and completed publication for a head no pull request offered - the exact class this lane exists to catch, walked in through the carrier meant to record it. Reported by review 46116.\\n\\nWHY THERE IS NO CHECK TO TEST: the field is gone. A bound receipt has exactly one head, subject.expected_head, so the contradictory document cannot be constructed in this language at all - the fix is DESIGN section 5 construction, not validation, and the state is unwritable rather than rejected.\\n\\nWHAT THIS CLAIM THEREFORE ASSERTS, since an unwritable state cannot be handed to a decoder: a document carrying a STRAY pr_head inside its bound outcome - the doctored shape the old encoder would have produced - answers with the SUBJECT's head and never the stray one. Under the old code this returned the stray head; under this one the stray member has no meaning to read. The stray sha here is deliberately the other fixture, so the claim goes red if any reading of the outcome's head is ever restored." +// THE DEFECT THIS REFUSES, stated as the shape of the document: a receipt naming THIS subject while +// binding a DIFFERENT pull-request head. Under the earlier cut ReceiptBound carried its own +// pr_head, read independently of the subject, so such a document decoded cleanly, matched all six +// subject fields, and completed publication for a head no pull request offered — the exact class +// this lane exists to catch, walked in through the carrier meant to record it. Reported by review +// 46116. +// +// WHY THERE IS NO CHECK TO TEST: the field is gone. A bound receipt has exactly one head, +// subject.expected_head, so the contradictory document cannot be constructed in this language — +// DESIGN section 5 construction, not validation; unwritable rather than rejected. +// +// WHAT THIS CLAIM THEREFORE ASSERTS, since an unwritable state cannot be handed to a decoder: a +// document carrying a STRAY pr_head inside its bound outcome — the doctored shape the old encoder +// would have produced — answers with the SUBJECT's head, never the stray one. The old code returned +// the stray head; now the stray member has no meaning to read. The stray sha is deliberately the +// other fixture, so the claim goes red if any reading of the outcome's head is restored. fn doctored_bound_receipt_carrying_a_stray_head() -> String { serialize_json(v: json_object(members: [ @@ -605,7 +641,13 @@ test fn a_foreign_schema_refuses_rather_than_decoding() -> Bool { } } -data v1_receipt_is_refused_note: String = "THE VERSION IS A WALL, NOT A HINT, and this is the claim that makes it one. A v1 document carries an outcome key and a rendered sentence; the fields Review needs were never written into it, so there is no reading of a v1 receipt as a v2 receipt with absent optional members. Accepting one would hand a consumer a receipt whose pull-request binding does not exist while looking entirely well-formed.\\n\\nThe schema string in the fixture below is the real v1 spelling, so this claim goes red the moment the decoder is loosened to accept it." +// THE VERSION IS A WALL, NOT A HINT, and this is the claim that makes it one. A v1 document carries +// an outcome key and a rendered sentence; the fields Review needs were never written, so there is +// no reading of a v1 receipt as a v2 receipt with absent optional members. Accepting one would hand +// a consumer a well-formed-looking receipt whose pull-request binding does not exist. +// +// The schema string in the fixture below is the real v1 spelling, so this goes red the moment the +// decoder is loosened to accept it. test fn a_v1_receipt_refuses_rather_than_decoding_without_its_binding() -> Bool { match publication_receipt_decode( @@ -637,7 +679,10 @@ test fn a_bound_outcome_missing_its_pull_request_number_refuses() -> Bool { } } -data ambiguous_set_round_trips_note: String = "AN AMBIGUITY WHOSE MEMBERS ARE GONE IS NOT AN AMBIGUITY ANYONE CAN RESOLVE, and the decoder used to answer this arm with an empty list - discarding the very numbers the encoder had written. A receipt recording that two pull requests matched decoded to one recording that none did, reporting the same outcome kind, and every claim that checked only the kind stayed green." +// AN AMBIGUITY WHOSE MEMBERS ARE GONE IS NOT AN AMBIGUITY ANYONE CAN RESOLVE, and the decoder used +// to answer this arm with an empty list — discarding the numbers the encoder wrote. A receipt +// recording two matching pull requests decoded to one recording none, with the same outcome kind, +// and every claim checking only the kind stayed green. test fn an_ambiguous_binding_round_trips_its_pull_request_numbers() -> Bool { match publication_receipt_decode( @@ -685,7 +730,11 @@ test fn an_ambiguous_binding_round_trips_its_pull_request_numbers() -> Bool { } } -// THE DECODER USED TO REBUILD THE REPOSITORY IT DID NOT STORE - full_name by concatenation, private as false, and default_branch from the subject's expected_base. For this repository the base IS the default branch, so the round trip compared equal and nothing looked wrong. This claim uses a subject whose base is NOT the default branch, which is the case that would have produced a repository nobody recorded and a false wrong-subject refusal in the one function whose job is to tell those apart. +// THE DECODER USED TO REBUILD THE REPOSITORY IT DID NOT STORE — full_name by concatenation, private +// as false, default_branch from the subject's expected_base. For this repository the base IS the +// default branch, so the round trip compared equal. This claim uses a subject whose base is NOT the +// default branch — the case that would have produced a repository nobody recorded and a false +// wrong-subject refusal in the one function whose job is to tell those apart. test fn a_subject_against_a_non_default_base_still_round_trips_its_repository() -> Bool { let subject = RoadmapPublicationSubject { node_id: "some-node", @@ -726,16 +775,16 @@ test fn a_receipt_missing_its_subject_refuses() -> Bool { } // THIS WITNESS CAUGHT THE parse_json TYPE CUT, WHICH IS WHY IT IS STRENGTHENED RATHER THAN PATCHED. -// It asserted that the refusal reason contained "complete JSON value" -- prose that this decoder -// used to spell for EVERY unreadable receipt. The cut replaced that one sentence with a LOCATED gap, -// so the phrase survives only on the trailing-content arm, and the witness went red on main. That is -// the migration working: a consumer depending on a fabricated summary refused the moment the summary -// became a fact. +// It asserted the refusal reason contained "complete JSON value" — prose this decoder used to spell +// for EVERY unreadable receipt. The cut replaced that sentence with a LOCATED gap, so the phrase +// survives only on the trailing-content arm, and the witness went red on main: the migration +// working, a consumer depending on a fabricated summary refused the moment the summary became a +// fact. // -// It now asserts the located refusal EXACTLY rather than by substring. The offset is derived, not -// copied from a run: "not a receipt" is not a JSON value at its very first byte, so a parser that -// reports where the document stopped being readable must say offset 0. A substring claim would pass -// against a decoder that located everything at 0 by accident. +// It now asserts the located refusal EXACTLY, not by substring. The offset is derived, not copied +// from a run: "not a receipt" is not a JSON value at its first byte, so a parser reporting where +// the document stopped being readable must say offset 0. A substring claim would pass a decoder +// that located everything at 0 by accident. test fn a_receipt_that_is_not_json_refuses() -> Bool { match publication_receipt_decode(receipt: "not a receipt") { ReceiptDecoded { receipt: _ } => false @@ -744,11 +793,11 @@ test fn a_receipt_that_is_not_json_refuses() -> Bool { } } -// THE ARM THE OLD PROSE COULD NOT DISTINGUISH, and the reason the cut was worth making here. This -// receipt PARSES COMPLETELY into a valid value and is refused only by full consumption -- under the +// THE ARM THE OLD PROSE COULD NOT DISTINGUISH, and why the cut was worth making here. This receipt +// PARSES COMPLETELY into a valid value and is refused only by full consumption — under the // predecessor it produced the identical sentence as the garbage above, so a reader could not tell -// "these bytes are damaged" from "a writer appended to this receipt, or two were concatenated". -// Those have opposite remedies. +// "these bytes are damaged" from "a writer appended, or two were concatenated". Those have opposite +// remedies. test fn a_receipt_with_trailing_content_refuses_as_trailing_not_as_garbage() -> Bool { match publication_receipt_decode(receipt: "\{} tail") { ReceiptDecoded { receipt: _ } => false @@ -757,7 +806,15 @@ test fn a_receipt_with_trailing_content_refuses_as_trailing_not_as_garbage() -> } } -data subject_check_witness_note: String = "THE NEGATIVE HALF IS THE POINT. A claim that a bound receipt paints the lamp green proves only that the happy path works; it would stay green under the exact defect this rewrite exists to remove, which is a consumer that finds a receipt at a path and trusts it.\\n\\nSo each claim below pairs one receipt with TWO expectations - the subject it was written for, and a subject differing in exactly one field - and asserts that the first is evidence and the second is not. Six fields, six ways to be about the wrong question, and heads are only one of them: attempt keys and node ids collide far more readily than shas do, so a head-only comparison would pass these claims and still be wrong." +// THE NEGATIVE HALF IS THE POINT. A claim that a bound receipt paints the lamp green proves only +// the happy path; it stays green under the exact defect this rewrite removes — a consumer that +// finds a receipt at a path and trusts it. +// +// So each claim below pairs one receipt with TWO expectations — the subject it was written for, and +// one differing in exactly one field — and asserts the first is evidence and the second is not. Six +// fields, six ways to be about the wrong question; heads are only one: attempt keys and node ids +// collide far more readily than shas, so a head-only comparison would pass these claims and still +// be wrong. fn evidence_for_subject_of(expected: RoadmapPublicationSubject, receipt: String) -> PublicationEvidence { publication_evidence_for( @@ -833,7 +890,11 @@ test fn a_receipt_for_another_attempt_of_this_node_is_not_evidence() -> Bool { !is_evidence(e: e) && differing_field(e: e) == "attempt_key" } -data repository_identity_is_owner_and_name_note: String = "THE REPOSITORY IS COMPARED BY ITS IDENTITY, WHICH IS OWNER AND NAME, and the refusal names which half differs rather than saying `repository`. Those are different situations for a reader: a different owner usually means a fork or another organization, while a different name under the same owner usually means the receipt is about a sibling repository - and the remedies diverge from there. The receipt also records full_name, private and default_branch, which are ATTRIBUTES the judgment was made against rather than identity, so they round trip and are not part of the match." +// THE REPOSITORY IS COMPARED BY ITS IDENTITY, WHICH IS OWNER AND NAME, and the refusal names which +// half differs rather than saying `repository`: a different owner usually means a fork or another +// organization, a different name under the same owner a sibling repository, and the remedies +// diverge. full_name, private and default_branch are ATTRIBUTES the judgment was made against, not +// identity, so they round trip and are not part of the match. test fn a_receipt_about_a_repository_of_another_name_is_not_evidence() -> Bool { let expected = RoadmapPublicationSubject { @@ -889,7 +950,12 @@ test fn a_receipt_against_another_base_is_not_evidence() -> Bool { !is_evidence(e: e) && differing_field(e: e) == "expected_base" } -data three_worlds_note: String = "Three inputs that a Bool carrier collapsed into one answer, and the correct answers are not the same. Absent means nothing was ever written for this head - go observe. Present-and-empty means somebody wrote a file and its content is gone, which is a fault, not a report that nothing was published. Present-and-garbage is the same fault with different bytes. Only the first permits the producer to write, so this claim asserts the FIRST is absent and the other two are refusals - it is the discriminator for review 46148 at the pure layer, and it goes red if empty ever reads as absent again." +// Three inputs a Bool carrier collapsed into one answer, with different correct answers. Absent +// means nothing was written for this head — go observe. Present-and-empty means somebody wrote a +// file and its content is gone: a fault, not a report of nothing published. Present-and-garbage is +// the same fault with different bytes. Only the first permits the producer to write, so this +// asserts the FIRST is absent and the other two are refusals — the discriminator for review 46148 +// at the pure layer; red if empty ever reads as absent again. test fn an_absent_receipt_is_absent_and_present_but_unusable_ones_refuse() -> Bool { let absent = publication_evidence_for( @@ -923,7 +989,22 @@ fn evidence_key(e: PublicationEvidence) -> String { } } -data four_causes_stay_four_note: String = "THE COLLAPSE THIS FILE MUST KEEP FAILING TO PRODUCE. PullRequestsUnreadable used to carry a single detail String, and the four failures that reach it were flattened into prose at the point of construction. A caller could then only re-derive which one it held by matching on substrings, which is the classifier-by-substring move DESIGN removes - and the case that matters most is the most decidable one: a 401 is the single clearest failure in this path and would have arrived as the least tractable kind of value.\\n\\nWHAT THIS ASSERTS, and why the key projection rather than the sentence: render_pull_request_read_failure is a PROJECTION of the cause, so asserting only its text would let a future edit collapse two arms into one sentence while both still typechecked, and the claim would stay green. Matching the coproduct gives four distinct keys, so a collapse is a compile error rather than a silently identical string. The rendering is asserted SEPARATELY below, for the facts a reader of the refusal actually needs.\\n\\nWHY NO ARM IS OMITTED: each is reachable from a different producer state - a credential decided locally before any request, a status a remote authority chose, an exchange that never produced a status, and a payload that arrived and could not be decoded. Three of the four were unreachable through the real transport until the REST outcome became data, which is why they are witnessed here rather than assumed." +// THE COLLAPSE THIS FILE MUST KEEP FAILING TO PRODUCE. PullRequestsUnreadable used to carry a +// single detail String, flattening its four failures into prose at construction; a caller could +// re-derive which one it held only by substring matching — the classifier-by-substring move DESIGN +// removes — and the most decidable case suffered most: a 401, the clearest failure in this path, +// arrived as the least tractable value. +// +// WHAT THIS ASSERTS, and why the key projection rather than the sentence: +// render_pull_request_read_failure is a PROJECTION of the cause, so asserting only its text would +// let an edit collapse two arms into one sentence while both typechecked and the claim stayed +// green. Matching the coproduct gives four distinct keys, so a collapse is a compile error. The +// rendering is asserted SEPARATELY below, for the facts a reader of the refusal needs. +// +// WHY NO ARM IS OMITTED: each is reachable from a different producer state — a credential decided +// locally before any request, a status the remote chose, an exchange that produced no status, and a +// payload that arrived undecodable. Three of the four were unreachable through the real transport +// until the REST outcome became data, which is why they are witnessed rather than assumed. fn pull_request_failure_key(cause: PullRequestReadFailure) -> String { match cause { @@ -968,7 +1049,17 @@ test fn four_pull_request_read_failures_stay_four_distinct_causes() -> Bool { && count(filter(keys, k => k == "body")) == 1 } -// THE RENDERER NAMES github.Pulls.List THROUGH ITS OperationRef, following the discipline ls_remote_operation_ref_note derives for the sibling reader: a path-and-query spelling is ONE realization of an operation and changes when the invocation is derived, while the operation identity does not. So a refusal that quoted /repos/OWNER/REPO/pulls would carry a fact with a shorter shelf life than the failure it describes.\n\nEACH ARM MUST ALSO CARRY WHAT ITS OWN REMEDY NEEDS, which is why this asserts fields rather than just the operation label. A status refusal is actionable only with the status AND the body - the body is usually the only place the remote says why, and 401 alone does not distinguish a missing scope from a revoked token. A transport refusal has no status to carry, and asserting its absence is the point: a sentinel zero would be a plausible-looking value standing where the honest answer is that the question does not apply. +// THE RENDERER NAMES github.Pulls.List THROUGH ITS OperationRef, following the discipline +// ls_remote_operation_ref_note derives for the sibling reader: a path-and-query spelling is ONE +// realization of an operation and changes when the invocation is derived; the operation identity +// does not. A refusal quoting /repos/OWNER/REPO/pulls would carry a fact with a shorter shelf life +// than the failure it describes. +// +// EACH ARM MUST ALSO CARRY WHAT ITS OWN REMEDY NEEDS, hence fields rather than just the operation +// label. A status refusal is actionable only with status AND body — the body is usually the only +// place the remote says why, and 401 alone does not distinguish a missing scope from a revoked +// token. A transport refusal has no status, and asserting its absence is the point: a sentinel zero +// would be a plausible value standing where the question does not apply. test fn a_status_refusal_renders_operation_repository_status_and_body() -> Bool { let rendered = render_pull_request_read_failure( cause: PullRequestStatusRefused { @@ -997,7 +1088,15 @@ test fn a_transport_refusal_carries_no_status_at_all() -> Bool { && !string_contains(s: rendered, pattern: "status 0") } -data every_cause_refuses_note: String = "TOTALITY OVER THE ADJUDICATOR, ASSERTED RATHER THAN ASSUMED. adjudicate_publication answers a PullRequestObservation, and the arm that matters is that NONE of the four causes may produce an ordinary negative result. BranchNotPublished and a refusal are both negative, so a collapse in that direction passes any claim asserting only 'it did not conclude bound' - and it points the operator at the wrong action entirely, since the remedy for 'not published' is to push and the remedy for 'we could not find out' is not.\\n\\nThe remotes are deliberately READ-and-empty here rather than unreadable, so the only thing that can produce a refusal is the pull-request side. If a cause were ever handled by falling through to the remote branch reading, this witness would see BranchNotPublished and red." +// TOTALITY OVER THE ADJUDICATOR, ASSERTED RATHER THAN ASSUMED. adjudicate_publication answers a +// PullRequestObservation, and NONE of the four causes may produce an ordinary negative result. +// BranchNotPublished and a refusal are both negative, so a collapse passes any claim asserting only +// 'it did not conclude bound' — and points the operator at the wrong action: the remedy for 'not +// published' is to push; for 'we could not find out' it is not. +// +// The remotes are deliberately READ-and-empty rather than unreadable, so only the pull-request side +// can produce a refusal. If a cause were handled by falling through to the remote branch reading, +// this witness would see BranchNotPublished and go red. test fn every_pull_request_read_failure_refuses_rather_than_reporting_unpublished() -> Bool { all( diff --git a/dag/test/claim/roadmap/roadmap_receipt_continuity_live_witness_test.dag b/dag/test/claim/roadmap/roadmap_receipt_continuity_live_witness_test.dag index e141a9fe562..d29c9764c3e 100644 --- a/dag/test/claim/roadmap/roadmap_receipt_continuity_live_witness_test.dag +++ b/dag/test/claim/roadmap/roadmap_receipt_continuity_live_witness_test.dag @@ -9,9 +9,18 @@ import gunbc.roadmap_model { acceptance_history_integrity_verdict_detail } data live_tree_disposition: LiveTreeDisposition = ReadsLiveTree -data live_witness_split_note: String = "SPLIT OUT OF roadmap_receipt_continuity_acceptance_test.dag AND roadmap_authority_test.dag SO THE HERMETIC DISCOVERY CORPUS CAN RUN. roadmap_acceptance_history_integrity_holds reaches git.Inspect.HeadCommit, git.Inspect.MergeBase, and git.Core.Show without mock_response, so under the hermetic envelope the observation REFUSES rather than skipping — and a planted git refusal must refuse integrity rather than fabricate prior_history = current. The hermetic contract keeps planted red controls only; this file executes the live git-observed integrity path on the wet corpora batch." +// SPLIT OUT OF roadmap_receipt_continuity_acceptance_test.dag AND roadmap_authority_test.dag SO THE +// HERMETIC DISCOVERY CORPUS CAN RUN. roadmap_acceptance_history_integrity_holds reaches +// git.Inspect.HeadCommit, git.Inspect.MergeBase, and git.Core.Show without mock_response, so under +// the hermetic envelope the observation REFUSES rather than skipping — and a planted git refusal +// must refuse integrity rather than fabricate prior_history = current. The hermetic contract keeps +// planted red controls only; this file executes the live git-observed integrity path on the wet +// corpora batch. -data live_witness_failure_receipt_note: String = "claim_executor invokes live_roadmap_acceptance_history_integrity_failure_receipt on Bool(false) via the _holds → _failure_receipt naming convention (gunbc#7644 / v2.std.native_agreement pattern). The verdict detail names the refusing arm so a live-tree integrity failure is diagnosable without re-running git by hand." +// claim_executor invokes live_roadmap_acceptance_history_integrity_failure_receipt on Bool(false) +// via the _holds → _failure_receipt naming convention (gunbc#7644 / v2.std.native_agreement +// pattern). The verdict detail names the refusing arm so a live-tree integrity failure is +// diagnosable without re-running git by hand. test fn live_roadmap_acceptance_history_integrity_holds() -> Bool { roadmap_acceptance_history_integrity_holds() diff --git a/dag/test/claim/roadmap/roadmap_register_witness_test.dag b/dag/test/claim/roadmap/roadmap_register_witness_test.dag index b4691b79dfa..e2aceccb64b 100644 --- a/dag/test/claim/roadmap/roadmap_register_witness_test.dag +++ b/dag/test/claim/roadmap/roadmap_register_witness_test.dag @@ -36,7 +36,28 @@ import v2.std.live_tree { LiveTreeDisposition, SubstrateInputsOnly } data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data roadmap_register_witness_note: String = "The roadmap dashboard as a register SITE INSTANCE (slice 1 of the roadmap-onto-register refactor, parent-acked 2026-07-21): the instance inherits the register laws by executing them over its own emission — themes_coherent over the exact Theme rows roadmap_css projects (totality, area coherence, chroma admissibility, WCAG contrast — one law set, N surfaces, never a roadmap fork); the unthemed-color census over the exact BuildRule rows the page serializes, with the RED a resurrection of the precise historical regression this refactor deleted (the hand-hex #0969da link blue) proving the census discriminates rather than vacuously passing; the shared Confluence mark consumed at nav depth from the one render authority (favicon/nav/hero cannot disagree, mark.dag). Slice 2 (manager-signed) flipped the response pin deliberately: the dispatch button's behaviors are declared rows (Approach->Brighten, Dispatch->Receipt) REALIZED through roadmap_realize_behavior — coverage total, unrealized census empty, both with located REDs (a dropped row NAMES its gap; a row with no realize arm is counted, never silently skipped) — and the reduced-motion collapse ships derived from the same rules. The Dashboard archetype rows are cross-checked BOTH directions against the shipped stylesheet: demanded-but-unused and used-but-undeclared each red (names-not-values made executable). Slice 3 is the PROPAGATION PROOF (the operator-named deliverable): one in-memory perturbation of a day-theme material moves the shared theme_root_css derivation both pages embed verbatim (embedding proven by string containment against each page's shipped css), and both surfaces consume the perturbed role — one authority edit, every site moves, by derivation not by hand-hunt. The scoped control: a FigureLitRole perturbation moves the shared var block but reaches PAINT only on the site (moodboard consumes var(--figure-lit); the roadmap's archetype demand excludes it and its rules carry no such var) — the demand profile executes as a real propagation boundary, not paperwork." +// The roadmap dashboard as a register SITE INSTANCE (slice 1 of the roadmap-onto-register refactor, +// parent-acked 2026-07-21): the instance inherits the register laws by executing them over its own +// emission — themes_coherent over the exact Theme rows roadmap_css projects (totality, area +// coherence, chroma admissibility, WCAG contrast — one law set, N surfaces, never a roadmap fork); +// the unthemed-color census over the exact BuildRule rows the page serializes, with the RED a +// resurrection of the precise historical regression this refactor deleted (the hand-hex #0969da +// link blue) proving the census discriminates rather than vacuously passing; the shared Confluence +// mark consumed at nav depth from the one render authority (favicon/nav/hero cannot disagree, +// mark.dag). Slice 2 (manager-signed) flipped the response pin deliberately: the dispatch button's +// behaviors are declared rows (Approach->Brighten, Dispatch->Receipt) REALIZED through +// roadmap_realize_behavior — coverage total, unrealized census empty, both with located REDs (a +// dropped row NAMES its gap; a row with no realize arm is counted, never silently skipped) — and +// the reduced-motion collapse ships derived from the same rules. The Dashboard archetype rows are +// cross-checked BOTH directions against the shipped stylesheet: demanded-but-unused and +// used-but-undeclared each red (names-not-values made executable). Slice 3 is the PROPAGATION PROOF +// (the operator-named deliverable): one in-memory perturbation of a day-theme material moves the +// shared theme_root_css derivation both pages embed verbatim (proven by string containment against +// each page's shipped css), and both surfaces consume the perturbed role — one authority edit, +// every site moves, by derivation not hand-hunt. The scoped control: a FigureLitRole perturbation +// moves the shared var block but reaches PAINT only on the site (moodboard consumes +// var(--figure-lit); the roadmap's archetype demand excludes it and its rules carry no such var) — +// the demand profile executes as a real propagation boundary, not paperwork. test fn witness_roadmap_theme_set_coherent() -> Bool { themes_coherent(themes: [day_theme, night_theme], roles: theme_roles) @@ -90,7 +111,13 @@ test fn witness_roadmap_coverage_complete() -> Bool { && roadmap_unrealized_behaviors(rows: roadmap_behaviors).length() == 0 } -data dropped_row_witness_scope_note: String = "The drop is scoped to ONE element's ONE verb so the assertion stays a LOCATED-gap check as the roster grows. The earlier form dropped every dispatch row tree-wide and asserted exactly one gap, which was only true while one element declared that verb — adding the sound toggle made it two and the witness reddened for a reason that had nothing to do with the property under test. A count that tracks the roster is a count that has to be re-tuned on every unrelated addition, and a witness re-tuned that often stops being read. Dropping the dispatch button's dispatch rows specifically keeps the claim exactly what it was meant to be: a missing row names its own element and verb." +// The drop is scoped to ONE element's ONE verb so the assertion stays a LOCATED-gap check as the +// roster grows. The earlier form dropped every dispatch row tree-wide and asserted exactly one gap, +// true only while one element declared that verb — adding the sound toggle made it two and the +// witness reddened for a reason unrelated to the property under test. A count that tracks the +// roster must be re-tuned on every unrelated addition, and a witness re-tuned that often stops +// being read. Dropping the dispatch button's dispatch rows specifically keeps the claim what it +// was meant to be: a missing row names its own element and verb. fn rows_without(element: ElementId, verb_label: String) -> List { fold(roadmap_behaviors, init: [], f: (acc, r) => @@ -132,7 +159,12 @@ test fn witness_archetype_verbs_match_declared_elements() -> Bool { all(e.verbs, w => archetype_admits_verb(a: dashboard_archetype, v: w))) } -data header_wordmark_witness_note: String = "Replaced witness_header_carries_shared_mark at A1 (presentation recon, operator-signed 2026-08-01): the header's brand element is the TEXT wordmark, not the site mark — the mark that stood here was gunbc.site.mark candidate A, an unselected brand experiment whose aria-label said gunb.ai on a gunbc tool surface (rationale on gunbc.roadmap_page.roadmap_wordmark_note). The structural claim is the same shape as before: the header Fragment contains the exact wordmark node, on both page instantiations." +// Replaced witness_header_carries_shared_mark at A1 (presentation recon, operator-signed +// 2026-08-01): the header's brand element is the TEXT wordmark, not the site mark — the mark that +// stood here was gunbc.site.mark candidate A, an unselected brand experiment whose aria-label said +// gunb.ai on a gunbc tool surface (rationale on gunbc.roadmap_page.roadmap_wordmark_note). The +// structural claim is the same shape as before: the header Fragment contains the exact wordmark +// node, on both page instantiations. data header_frame_scan_note: String = "Amended for the A2 hierarchy closeout: the header's children now sit inside one div.header-inner composition frame (header_composition_frame_note — header and content share the page measure), so the wordmark no longer sits at direct-child depth. The scan is a RECURSIVE descent over the header's Fragment subtree, not a depth-pinned adjacency check: the CLAIM is 'the header carries the wordmark', and a fixed depth constant would only be the accidental nesting pinned one level looser — the same re-pin the A1 header note warns against, and it would red spuriously the next time a wrapper lands. Descent is on the Fragment sub-value relation (a node's children), so it terminates on the tree it walks (the std.layout render_go shape)." @@ -165,7 +197,11 @@ test fn witness_header_carries_wordmark() -> Bool { && header_subtree_carries_wordmark(h: roadmap_header(page: "daily workspace")) } -data header_scan_discrimination_note: String = "An unbounded subtree search buys depth-independence at the cost of being easy to satisfy, so it owes a control proving the two bounds it still holds. Arm 1: the scan matches the wordmark NODE, not its text — a header carrying the bare string 'gunbc' at any depth is not a wordmark. Arm 2: the header tag guard still bites — the exact wordmark node under a non-header root does not satisfy 'the HEADER carries it'. Without both arms an always-true search would read identically to the real claim." +// An unbounded subtree search buys depth-independence at the cost of being easy to satisfy, so it +// owes a control proving the two bounds it still holds. Arm 1: the scan matches the wordmark NODE, +// not its text — a header carrying the bare string 'gunbc' at any depth is not a wordmark. Arm 2: +// the header tag guard still bites — the exact wordmark node under a non-header root does not +// satisfy 'the HEADER carries it'. Without both, an always-true search reads like the real claim. test fn witness_header_wordmark_scan_discriminates() -> Bool { !header_subtree_carries_wordmark(h: Element { diff --git a/dag/test/claim/roadmap/roadmap_repo_atlas_sandbox_witness_test.dag b/dag/test/claim/roadmap/roadmap_repo_atlas_sandbox_witness_test.dag index 501f4a1485a..3566453acfb 100644 --- a/dag/test/claim/roadmap/roadmap_repo_atlas_sandbox_witness_test.dag +++ b/dag/test/claim/roadmap/roadmap_repo_atlas_sandbox_witness_test.dag @@ -42,9 +42,17 @@ import extdeps.git { GitDiffNameStatusComplete } -data repo_atlas_served_shape_witness_note: String = "EVERY PAGE CLAIM BELOW SERIALIZES repo_atlas_document — THE SHAPE THE ROUTE ACTUALLY SERVES. The first revision serialized repo_atlas_section instead, so the twelve claims covered a fragment the handler never returns and a headless, unstyled page stayed green through all of them (review 50752). A claim aimed at the wrong subject is not a weak claim, it is not a claim about the product at all." - -data repo_atlas_page_witness_note: String = "THE PAGE CLAIMS READ EMITTED TEXT, WHICH IS WEAKER THAN READING STRUCTURE AND IS USED ONLY WHERE THE SUBJECT GENUINELY IS THE EMITTED BYTES. Every claim that asserts an ABSENCE first asserts the presence of something comparable, so a serializer returning empty text cannot make an absence claim vacuously true — the failure mode that made three earlier instrument-lane claims pass over nothing." +// EVERY PAGE CLAIM BELOW SERIALIZES repo_atlas_document — THE SHAPE THE ROUTE ACTUALLY SERVES. The +// first revision serialized repo_atlas_section instead, so the twelve claims covered a fragment the +// handler never returns and a headless, unstyled page stayed green through all of them (review +// 50752). A claim aimed at the wrong subject is not a weak claim, it is not a claim about the +// product at all. + +// THE PAGE CLAIMS READ EMITTED TEXT, WHICH IS WEAKER THAN READING STRUCTURE AND IS USED ONLY WHERE +// THE SUBJECT GENUINELY IS THE EMITTED BYTES. Every claim that asserts an ABSENCE first asserts the +// presence of something comparable, so a serializer returning empty text cannot make an absence +// claim vacuously true — the failure mode that made three earlier instrument-lane claims pass over +// nothing. fn atlas_page_fixture_nodes() -> List { [ @@ -109,7 +117,8 @@ fn atlas_page_html(snapshot: RepoAtlasSnapshot) -> String { } } -data atlas_page_non_vacuity_note: String = "The guard every other claim leans on: the page must serialize to non-empty text carrying a known marker. Without this, an absence assertion over an empty string would pass while proving nothing." +// The guard every other claim leans on: the page must serialize to non-empty text carrying a known +// marker. Without this, an absence assertion over an empty string would pass while proving nothing. test fn the_page_serializes_to_non_empty_html() -> Bool { let html = atlas_page_html(snapshot: atlas_page_snapshot_plain()) @@ -125,7 +134,8 @@ test fn the_page_carries_no_agent_occupancy_channel() -> Bool { && string_contains(haystack: html, needle: "working") == false } -data atlas_page_no_script_note: String = "ACCEPTANCE: no client script. Asserted against a page proven to contain real content, so this is a statement about what the page omits rather than about whether it rendered." +// ACCEPTANCE: no client script. Asserted against a page proven to contain real content, so this is +// a statement about what the page omits rather than about whether it rendered. test fn the_page_carries_no_client_script() -> Bool { let html = atlas_page_html(snapshot: atlas_page_snapshot_plain()) @@ -133,7 +143,8 @@ test fn the_page_carries_no_client_script() -> Bool { && string_contains(haystack: html, needle: " Bool { let html = atlas_page_html(snapshot: atlas_page_snapshot_plain()) @@ -149,7 +160,8 @@ test fn an_impact_plane_is_emitted_from_a_real_reading() -> Bool { && string_contains(haystack: html, needle: "impact not computed") == false } -data atlas_page_standing_note: String = "ACCEPTANCE 9. A provisional reading must not present as exact. The pair is asserted in BOTH directions so a readout that printed one fixed word would fail one side." +// ACCEPTANCE 9. A provisional reading must not present as exact. The pair is asserted in BOTH +// directions so a readout that printed one fixed word would fail one side. test fn a_provisional_reading_is_labelled_provisional_on_the_page() -> Bool { let provisional = atlas_page_html(snapshot: atlas_page_snapshot_impacted(exact: false)) @@ -160,7 +172,8 @@ test fn a_provisional_reading_is_labelled_provisional_on_the_page() -> Bool { && string_contains(haystack: exact, needle: "provisional") == false } -data atlas_page_refusal_note: String = "A refused change overlay must show its cause in words AND still draw the structure plane — the four facts are independent, so an untrustworthy diff does not blank the atlas." +// A refused change overlay must show its cause in words AND still draw the structure plane — the +// four facts are independent, so an untrustworthy diff does not blank the atlas. test fn a_refused_overlay_states_its_cause_and_keeps_the_structure() -> Bool { let html = atlas_page_html(snapshot: atlas_page_snapshot_refused()) @@ -169,7 +182,11 @@ test fn a_refused_overlay_states_its_cause_and_keeps_the_structure() -> Bool { && string_contains(haystack: html, needle: "atlas-plane-structure") } -data repo_atlas_mark_needle_note: String = "THE NEEDLE IS THE EMITTED CLASS ATTRIBUTE, NOT THE BARE CLASS NAME, and the difference is not pedantry. Once the page began embedding its own stylesheet, the string .atlas-dot-changed appeared in every document as a CSS RULE, so the negative half of this claim matched the stylesheet and failed against a page whose marks were correct. Matching the attribute form distinguishes a rule that exists from a mark that was applied — which is the whole question." +// THE NEEDLE IS THE EMITTED CLASS ATTRIBUTE, NOT THE BARE CLASS NAME, and the difference is not +// pedantry. Once the page began embedding its own stylesheet, the string .atlas-dot-changed +// appeared in every document as a CSS RULE, so the negative half of this claim matched the +// stylesheet and failed against a page whose marks were correct. Matching the attribute form +// distinguishes a rule that exists from a mark that was applied — which is the whole question. test fn a_changed_module_is_marked_on_the_page() -> Bool { let changed = atlas_page_html(snapshot: atlas_page_snapshot_changed()) @@ -179,7 +196,10 @@ test fn a_changed_module_is_marked_on_the_page() -> Bool { && string_contains(haystack: plain, needle: "atlas-plane-structure") } -data atlas_page_geometry_note: String = "ACCEPTANCE 11. The renderer receives an ADDRESS and lowers it with nested transforms. These claims pin the lowering itself — that ring 0 slot 0 sits at the top of the inner ring with no rotation, and that a half-way slot turns 180 degrees — so a geometry change is a visible diff rather than a silent re-layout." +// ACCEPTANCE 11. The renderer receives an ADDRESS and lowers it with nested transforms. These +// claims pin the lowering itself — that ring 0 slot 0 sits at the top of the inner ring with no +// rotation, and that a half-way slot turns 180 degrees — so a geometry change is a visible diff +// rather than a silent re-layout. test fn ring_zero_slot_zero_lowers_to_an_unrotated_inner_transform() -> Bool { let lowered = atlas_cell_transform(address: AtlasAddress { ring: 0, slot: 0 }) @@ -203,7 +223,9 @@ test fn the_ring_slot_probe_reads_the_declared_table() -> Bool { && atlas_ring_slot_count(ring: 15) == 392 } -data repo_atlas_document_shape_note: String = "ACCEPTANCE: the served route returns a COMPLETE document, like every sibling on the same serve table. Each element is asserted individually rather than through one composite check, so a page missing only its charset or only its stylesheet fails on the missing part and names it." +// ACCEPTANCE: the served route returns a COMPLETE document, like every sibling on the same serve +// table. Each element is asserted individually rather than through one composite check, so a page +// missing only its charset or only its stylesheet fails on the missing part and names it. test fn the_served_page_is_a_complete_document() -> Bool { let html = atlas_page_html(snapshot: atlas_page_snapshot_plain()) @@ -222,7 +244,10 @@ test fn the_served_page_embeds_its_stylesheet() -> Bool { && string_contains(haystack: html, needle: "atlas-dot") } -data repo_atlas_channel_distinguishable_note: String = "THE CLAIM THE CARRIER'S NOTE USED TO ASSERT WITHOUT EVIDENCE. A structural dot and a changed dot must not resolve to the same paint. Asserted on the STYLESHEET rather than on prose: the change channel must bind a different role variable than the structure channel, and the impact channel must be a stroke rather than a fill, so deleting a rule reds here." +// THE CLAIM THE CARRIER'S NOTE USED TO ASSERT WITHOUT EVIDENCE. A structural dot and a changed dot +// must not resolve to the same paint. Asserted on the STYLESHEET rather than on prose: the change +// channel must bind a different role variable than the structure channel, and the impact channel +// must be a stroke rather than a fill, so deleting a rule reds here. test fn the_change_channel_is_painted_differently_from_structure() -> Bool { let css = repo_atlas_css() @@ -237,7 +262,10 @@ data atlas_live_page_is_wet_note: String = "THE LIVE-PAGE CLAIM WAS DELETED FROM WHAT STILL COVERS THE SERVED SHAPE: every claim here drives repo_atlas_document, which IS the function the handler renders, with controlled snapshots. What is NOT covered by any hermetic claim is the live observation itself — whether the tree is clean, whether the comparison resolves — and that is precisely what the browser and latency receipt has to establish by execution, not something to assert here with a mock." -data atlas_plane_split_note: String = "ACCEPTANCE: the change plane is a SEPARATE group, and the paired control proves the structure group is untouched by it. The claim compares the two documents rather than merely asserting the group appears — if a change were still expressed by classing the structural circle, the changes group would be absent and the structure group would differ, and both halves red." +// ACCEPTANCE: the change plane is a SEPARATE group, and the paired control proves the structure +// group is untouched by it. The claim compares the two documents rather than merely asserting the +// group appears — if a change were still expressed by classing the structural circle, the changes +// group would be absent and the structure group would differ, and both halves red. fn atlas_occurrence_count(haystack: String, needle: String) -> Int { split(s: haystack, delimiter: needle).length() - 1 @@ -272,7 +300,8 @@ test fn the_slot_pairs_that_collapsed_now_separate() -> Bool { && atlas_slot_pair_separates(ring: 0, low: 0, high: 1) } -data atlas_fraction_render_note: String = "The serializer must keep three decimals and PAD them, or 918 and 18 millidegrees would both render as a fraction beginning with 1 and two different addresses would print the same text." +// The serializer must keep three decimals and PAD them, or 918 and 18 millidegrees would both +// render as a fraction beginning with 1 and two different addresses would print the same text. test fn millidegrees_render_with_padded_fraction() -> Bool { atlas_millidegrees_text(millidegrees: 918) == "0.918" @@ -281,7 +310,9 @@ test fn millidegrees_render_with_padded_fraction() -> Bool { && atlas_millidegrees_text(millidegrees: 360000) == "360.000" } -data atlas_focus_note: String = "ACCEPTANCE: the atlas is ONE keyboard stop, not one per cell. The live page has 2168 occupied cells; a tabindex on each would have made the study a two-thousand-stop keyboard trap. Titles remain on every dot for pointer inspection." +// ACCEPTANCE: the atlas is ONE keyboard stop, not one per cell. The live page has 2168 occupied +// cells; a tabindex on each would have made the study a two-thousand-stop keyboard trap. Titles +// remain on every dot for pointer inspection. test fn the_atlas_is_a_single_keyboard_stop() -> Bool { let html = atlas_page_html(snapshot: atlas_page_snapshot_plain()) @@ -289,7 +320,7 @@ test fn the_atlas_is_a_single_keyboard_stop() -> Bool { && atlas_occurrence_count(haystack: html, needle: "tabindex") == 1 } -data atlas_changes_not_observed_page_note: String = "The page must distinguish an unrun comparison from one that found nothing, in words." +// The page must distinguish an unrun comparison from one that found nothing, in words. test fn the_page_says_changes_were_not_observed() -> Bool { let html = atlas_page_html(snapshot: atlas_page_snapshot_plain()) diff --git a/dag/test/claim/roadmap/roadmap_row_witness_test.dag b/dag/test/claim/roadmap/roadmap_row_witness_test.dag index e1992a8977a..d5131365308 100644 --- a/dag/test/claim/roadmap/roadmap_row_witness_test.dag +++ b/dag/test/claim/roadmap/roadmap_row_witness_test.dag @@ -13,7 +13,13 @@ import v2.std.live_tree { LiveTreeDisposition, SubstrateInputsOnly } data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data roadmap_row_witness_note: String = "Composition slice 2's receipts: the RoadmapRow archetype's grid asserted over the SERVED surfaces (the emitted stylesheet and the rendered page), the actuator's scale proven derived-not-set, and the density consumption pinned — the expected blocks are assembled from the archetype's own derivation fns and asserted verbatim against the emission, the same full-block pattern the page witness set. Declared bound: contains-grain cannot count occurrences, so a ROGUE duplicate block for the same selector is outside this file's reach — the register and tactile suites scan the wider sheet." +// Composition slice 2's receipts: the RoadmapRow archetype's grid asserted over the SERVED surfaces +// (the emitted stylesheet and the rendered page), the actuator's scale proven derived-not-set, and +// the density consumption pinned — the expected blocks are assembled from the archetype's own +// derivation fns and asserted verbatim against the emission, the same full-block pattern the page +// witness set. Declared bound: contains-grain cannot count occurrences, so a ROGUE duplicate block +// for the same selector is outside this file's reach — the register and tactile suites scan the +// wider sheet. fn expected_node_head_block() -> String { join([ @@ -32,7 +38,12 @@ fn expected_node_mid_block() -> String { ], "") } -data head_column_derivation_note: String = "A3 routine-state collapse receipts: once the status chip renders only when discriminating, head children can be fewer than tracks, so each cell carries an explicit grid-column DERIVED from the archetype's HeadTrack order (roadmap_row_head_column — the same authority the template folds). The expected blocks embed the derivation, so a hand-drifted column or an archetype edit the stylesheet misses reds; the column witness pins the three derived positions and refuses the 0 an off-head region would derive." +// A3 routine-state collapse receipts: once the status chip renders only when discriminating, head +// children can be fewer than tracks, so each cell carries an explicit grid-column DERIVED from the +// archetype's HeadTrack order (roadmap_row_head_column — the same authority the template folds). +// The expected blocks embed the derivation, so a hand-drifted column or an archetype edit the +// stylesheet misses reds; the column witness pins the three derived positions and refuses the 0 an +// off-head region would derive. fn expected_status_column_block() -> String { join([ @@ -67,7 +78,11 @@ fn expected_row_actuator_block() -> String { ], "") } -data grid_structure_note: String = "The template the stylesheet carries must be the one DERIVED from the archetype's placements — the expected block embeds roadmap_row_grid_template(), so an archetype edit the stylesheet misses, or a hand template the archetype never declared, reds. The head-track count remains 3: chip auto, title 1fr, ActuatorRegion auto. Workflow lamps v0 realizes that last region as one workflow-controls wrapper rather than adding strip/button/Stop as grid siblings." +// The template the stylesheet carries must be the one DERIVED from the archetype's placements — the +// expected block embeds roadmap_row_grid_template(), so an archetype edit the stylesheet misses, or +// a hand template the archetype never declared, reds. The head-track count remains 3: chip auto, +// title 1fr, ActuatorRegion auto. Workflow lamps v0 realizes that last region as one +// workflow-controls wrapper rather than adding strip/button/Stop as grid siblings. fn head_track_count() -> Int { count(roadmap_row_archetype |> filter(r => match r.placement { @@ -117,7 +132,9 @@ test fn roadmap_row_actuator_red_on_hand_scale() -> Bool { return !actuator_block_derived(block: hand_scaled) } -data density_census_note: String = "The density cells of this slice's own emission, pinned tokened: the three expected blocks carry only var() lengths (the reservation's ch value is a typed derivation, not a bare pixel). The module-wide untokened-length census walls the class; this locates the row's own blocks." +// The density cells of this slice's own emission, pinned tokened: the three expected blocks carry +// only var() lengths (the reservation's ch value is a typed derivation, not a bare pixel). The +// module-wide untokened-length census walls the class; this locates the row's own blocks. test fn roadmap_row_density_all_tokened() -> Bool { return !string_contains(s: expected_node_head_block(), pattern: "px") diff --git a/dag/test/claim/roadmap/roadmap_sandbox_witness_test.dag b/dag/test/claim/roadmap/roadmap_sandbox_witness_test.dag index e35fdc48208..bd7e099b71b 100644 --- a/dag/test/claim/roadmap/roadmap_sandbox_witness_test.dag +++ b/dag/test/claim/roadmap/roadmap_sandbox_witness_test.dag @@ -20,7 +20,13 @@ import v2.std.live_tree { LiveTreeDisposition, SubstrateInputsOnly } data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data roadmap_sandbox_witness_note: String = "P4 keystone: /sandbox is the register at every depth plus every component in every state, and it doubles as the visual witness. Gallery totality is the wire vocabulary re-witnessed as coverage (one static instance per wire label; drop one -> RED). The echo answers ANY wire arm on demand with the SAME belt JSON shape production sends (proven per label; unknown label refuses 400). The live instances are one pressable button per arm, all driven by the shared client program. The register depths (roles under both themes, scales) render from the authorities, so the sandbox cannot drift from the live surfaces." +// P4 keystone: /sandbox is the register at every depth plus every component in every state, and it +// doubles as the visual witness. Gallery totality is the wire vocabulary re-witnessed as coverage +// (one static instance per wire label; drop one -> RED). The echo answers ANY wire arm on demand +// with the SAME belt JSON shape production sends (proven per label; unknown label refuses 400). The +// live instances are one pressable button per arm, all driven by the shared client program. The +// register depths (roles under both themes, scales) render from the authorities, so the sandbox +// cannot drift from the live surfaces. fn sandbox_html() -> String { match try_serialize_html_source(node: sandbox_page()) { @@ -109,8 +115,20 @@ test fn witness_sandbox_gallery_and_live_render() -> Bool { && all(belt_dispatch_all_status_labels(), l => string_contains(s: h, pattern: join(["data-status=\"", l, "\""], ""))) } - -data family_fixture_witness_note: String = "The A3 exhibit's discriminating pins, strengthened per review 46754 (the containment-only draft would have survived a duplicated claim, a '13 nodes' count, the neighbour absorbed into the family, or chips reappearing). Three layers: (1) the TYPED band_entries output is pinned by exact list equality — exactly one BandFamily (claim exact, member count exactly 3, member headlines exactly the three subjects in order) followed by exactly one BandRow (the neighbour's full headline) — so claim duplication, count drift, membership drift, and the subject swap are all caught at the structure the renderer consumes; (2) ONE serialized frame carries exact occurrence counts (family-claim/family-count/family-group/family-rows spans each render exactly once, the count span is exactly '>3 nodes<' so a '13 nodes' regression cannot hide inside a containment check, the member's full task headline occurs zero times — the RED control for family_subject_row — and the A3 chip collapse holds: zero 'status status-open' and zero activity markup, routine state earns no ink); (3) the PAGE contains all three width frames verbatim, so the frame-level pins transfer to the page without scanning it. Occurrence counting walks an index over the ~2KB frame (the std.encoding base64_collect_values shape), never the full page." +// The A3 exhibit's discriminating pins, strengthened per review 46754 (the containment-only draft +// would have survived a duplicated claim, a '13 nodes' count, the neighbour absorbed into the +// family, or chips reappearing). Three layers: (1) the TYPED band_entries output is pinned by exact +// list equality — exactly one BandFamily (claim exact, member count exactly 3, member headlines +// exactly the three subjects in order) followed by exactly one BandRow (the neighbour's full +// headline) — so claim duplication, count drift, membership drift, and the subject swap are all +// caught at the structure the renderer consumes; (2) ONE serialized frame carries exact occurrence +// counts (family-claim/family-count/family-group/family-rows spans each render exactly once, the +// count span is exactly '>3 nodes<' so a '13 nodes' regression cannot hide inside a containment +// check, the member's full task headline occurs zero times — the RED control for family_subject_row +// — and the A3 chip collapse holds: zero 'status status-open' and zero activity markup, routine +// state earns no ink); (3) the PAGE contains all three width frames verbatim, so the frame-level +// pins transfer to the page without scanning it. Occurrence counting walks an index over the ~2KB +// frame (the std.encoding base64_collect_values shape), never the full page. fn frame_occurrence_count_go(s: String, pattern: String, i: Int, len: Int, plen: Int, acc: Int) -> Int { if i + plen > len { diff --git a/dag/test/claim/roadmap/roadmap_serve_witness_test.dag b/dag/test/claim/roadmap/roadmap_serve_witness_test.dag index 2af4422f67f..5b25ee9eb8b 100644 --- a/dag/test/claim/roadmap/roadmap_serve_witness_test.dag +++ b/dag/test/claim/roadmap/roadmap_serve_witness_test.dag @@ -50,7 +50,9 @@ import extdeps.http.server { import extdeps.uri_path { PathParamBinding, path_param_value } import std.types { String, Int, Bool, List, HttpMethod, GET, POST, PUT } -data live_table_or_empty_note: String = "Test-local extraction: a Refused build yields the EMPTY table, so every selection witness below goes RED (nothing selects) — the discriminating direction; the production path never does this (roadmap_serve_respond answers 500 on Refused)." +// Test-local extraction: a Refused build yields the EMPTY table, so every selection witness below +// goes RED (nothing selects) — the discriminating direction; the production path never does this +// (roadmap_serve_respond answers 500 on Refused). fn live_table_or_empty() -> ServedRouteTable { match roadmap_serve_route_table_build() { @@ -93,7 +95,6 @@ test fn witness_serve_table_selection() -> Bool { && selects(method: POST, path: "/publish/some-node", want: BeltPublishHandler) } - test fn witness_asset_route_serves_modeled_js() -> Bool { let r = roadmap_serve_invoke( handler: DispatchAssetHandler, @@ -112,7 +113,11 @@ test fn witness_asset_route_serves_modeled_js() -> Bool { && string_contains(s: r.body, pattern: "fetch('/cleanup/' + sess.node_id") } -data lab_nav_resolves_note: String = "The shared header renders its links from instrument_lab_links, and the route table builds its specs from the same declarations. This claim is what makes that ONE authority rather than two that happen to agree: every rendered link is required to select a route, so a roster row without a route reds here rather than shipping a header link to a 404. The RED direction is a row added to the roster with no matching route spec." +// The shared header renders its links from instrument_lab_links, and the route table builds its +// specs from the same declarations. This claim is what makes that ONE authority rather than two +// that happen to agree: every rendered link is required to select a route, so a roster row without +// a route reds here rather than shipping a header link to a 404. The RED direction is a row added +// to the roster with no matching route spec. fn lab_link_selects_something(path: String) -> Bool { match serve_select_route(table: live_table_or_empty(), method: GET, path: path) { @@ -161,7 +166,21 @@ test fn witness_405_response_carries_allowed() -> Bool { r.status == 405 && string_contains(s: r.body, pattern: "POST") } -data status_map_red_note: String = "The 404/409/503/502 rows are the REDs a lazy 200-or-500 collapse would fail (parent review 2026-07-20): each refusal variant must map to ITS status, so a collapse of any arm reds exactly one witness row below.\n\nTHIS PIN WENT STALE WHILE THE PROTECTION IT DESCRIBES READ AS INTACT (review artifact 51368). Five arms were added with explicit status mappings — stale session, revision drift, multiplicity conflict, liveness unobserved, revision unobserved — and this witness still pinned the original eight, so a regression mapping any new arm to 200 would have stayed green. The note claimed a total protection the assertion no longer provided, which is worse than an absent pin: a reader checking whether the mapping is guarded finds a sentence saying yes.\n\nThe label, band, exemplar and button rosters were all swept when those arms landed. This one was missed because it lives in a different witness module and is keyed by CONSTRUCTED variants rather than by a roster the compiler counts — nothing here goes non-exhaustive when an arm appears. That asymmetry is the actual defect; until belt_dispatch_status_total is derived from the exemplar roster the way the label set is, this assertion has to be swept by hand alongside it." +// The 404/409/503/502 rows are the REDs a lazy 200-or-500 collapse would fail (parent review +// 2026-07-20): each refusal variant must map to ITS status, so a collapse of any arm reds exactly +// one witness row below. +// +// THIS PIN WENT STALE WHILE THE PROTECTION IT DESCRIBES READ AS INTACT (review artifact 51368). +// Five arms were added with explicit status mappings — stale session, revision drift, multiplicity +// conflict, liveness unobserved, revision unobserved — while this witness still pinned the original +// eight, so a regression mapping any new arm to 200 stayed green. The note claimed a protection the +// assertion no longer provided, worse than an absent pin. +// +// The label, band, exemplar and button rosters were all swept when those arms landed; this one was +// missed because it lives in a different witness module and is keyed by CONSTRUCTED variants rather +// than a roster the compiler counts — nothing here goes non-exhaustive when an arm appears. That +// asymmetry is the actual defect; until belt_dispatch_status_total is derived from the exemplar +// roster the way the label set is, this assertion must be swept by hand alongside it. fn na(r: LaunchRefusal) -> BeltSpawnOutcome { SpawnNotAdmitted { node_id: "n", refusal: r } } @@ -202,7 +221,6 @@ test fn witness_preview_dispatch_refuses_before_effects() -> Bool { && string_contains(s: r.body, pattern: "before observation, provider preflight, or worktree creation") } - test fn witness_instance_route_names_posture_and_paths() -> Bool { let r = roadmap_serve_respond_for_instance( instance: srv2_preview_dashboard_instance(), @@ -224,7 +242,18 @@ test fn witness_instance_route_names_posture_and_paths() -> Bool { && string_contains(s: r.body, pattern: "\"dispatch_attempt_state_root\": \"/home/briansrls/.local/share/gunbc-dashboard-instances/codex-provider-feedback-preview-v0/attempt-state\"") } -data route_table_drops_nothing_note: String = "THE ROUTE COUNT STOPPED BEING A LITERAL, and what replaces it is the claim the literal was standing in for. Sixteen was read off the live route roster, so adding /provider.json — a correct route this PR needed — reds a witness that has nothing to say about which routes exist. That is the live-state count-transcription class ruled against on 2026-07-29 and swept in #7464, and this was a third instance of it (review, 2026-07-30, found by the full floor rather than by any targeted run).\\n\\nThe replacement is strictly stronger, not weaker. What this witness is actually for is that the live table BUILDS — the refusing arm below is the other half — and the interesting failure is a build that silently drops a route rather than refusing. serve_page_response_note in this module names exactly that hazard: the EmitRejected => [] route-drop in node_http_server_emit is a silent widen this path deliberately does not copy. A literal count cannot tell a dropped route from a roster that legitimately grew; comparing against the roster can, and it never needs editing again.\\n\\nThe non-emptiness conjunct stays because equality between two empty lists would hold vacuously." +// THE ROUTE COUNT STOPPED BEING A LITERAL, replaced by the claim the literal stood in for. Sixteen +// was read off the live route roster, so adding /provider.json — a correct route this PR needed — +// reds a witness with nothing to say about which routes exist: the live-state count-transcription +// class ruled against on 2026-07-29 and swept in #7464, a third instance (review, 2026-07-30, found +// by the full floor rather than any targeted run).\n\nThe replacement is strictly stronger. This +// witness is for the live table BUILDING — the refusing arm below is the other half — and the +// interesting failure is a build that silently drops a route rather than refusing. +// serve_page_response_note in this module names that hazard: the EmitRejected => [] route-drop in +// node_http_server_emit is a silent widen this path deliberately does not copy. A literal count +// cannot tell a dropped route from a roster that legitimately grew; comparing against the roster +// can, and never needs editing again.\n\nThe non-emptiness conjunct stays because equality +// between two empty lists would hold vacuously. test fn witness_live_table_builds_ready_routes() -> Bool { match roadmap_serve_route_table_build() { @@ -234,7 +263,9 @@ test fn witness_live_table_builds_ready_routes() -> Bool { } } -data malformed_literal_red_note: String = "The RED control for review 40286's section-5 catch: a malformed route literal through the SAME build fold must REFUSE the whole table (typed, carrying the broken raw), never fabricate an empty template that would silently match '/'." +// The RED control for review 40286's section-5 catch: a malformed route literal through the SAME +// build fold must REFUSE the whole table (typed, carrying the broken raw), never fabricate an empty +// template that would silently match '/'. test fn witness_malformed_route_literal_refuses_table() -> Bool { let specs = [ @@ -254,7 +285,10 @@ test fn witness_unknown_method_refuses() -> Bool { } } -data unknown_method_501_note: String = "review 40359: an unrecognized method label is 501 Not Implemented (RFC 9110 section 15.6.2 — the server does not implement the method at all), NEVER 405 (405 means the ROUTE exists but this method is not in its allowed set, and carries the allowed set — the MethodNotAllowed arm). The two arms must stay distinct statuses; collapsing them reds this row." +// review 40359: an unrecognized method label is 501 Not Implemented (RFC 9110 section 15.6.2 — the +// server does not implement the method at all), NEVER 405 (405 means the ROUTE exists but this +// method is not in its allowed set, and carries the allowed set — the MethodNotAllowed arm). The +// two arms must stay distinct statuses; collapsing them reds this row. test fn witness_unknown_method_folds_501_response() -> Bool { let r = roadmap_serve_respond(method_label: "BREW", path: "/", body: "", release_revision: deploy_witness_release_revision) diff --git a/dag/test/claim/roadmap/roadmap_tactile_witness_test.dag b/dag/test/claim/roadmap/roadmap_tactile_witness_test.dag index 137208ec31f..8c0f20af6b1 100644 --- a/dag/test/claim/roadmap/roadmap_tactile_witness_test.dag +++ b/dag/test/claim/roadmap/roadmap_tactile_witness_test.dag @@ -50,7 +50,12 @@ import v2.std.live_tree { LiveTreeDisposition, SubstrateInputsOnly } data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data roadmap_tactile_witness_note: String = "The exemplar's walls, executed. Checkpoints 1, 2 and 7a are things a person verifies by clicking, so what a witness can honestly hold is the layer underneath them: that the vocabulary is real, that it is CONSUMED, that the mechanics are the ones the analog law requires, and that each claim has an input which makes it fail. Every witness in this file is reachable from the single test fn below — the orphaned-enrollment defect this repo just paid for once is not worth paying for twice." +// The exemplar's walls, executed. Checkpoints 1, 2 and 7a are things a person verifies by clicking, +// so what a witness can honestly hold is the layer underneath them: that the vocabulary is real, +// that it is CONSUMED, that the mechanics are the ones the analog law requires, and that each claim +// has an input which makes it fail. Every witness in this file is reachable from the single test fn +// below — the orphaned-enrollment defect this repo just paid for once is not worth paying for +// twice. fn css() -> String { roadmap_css() @@ -334,7 +339,12 @@ test fn witness_sound_toggle_scan_discriminates() -> Bool { }) } -data sound_toggle_name_vs_state_note: String = "Amended at A1 (presentation recon, 2026-08-01): the markup ships the control's NAME ('sound') so the button has visible content and an accessible name before the client program runs — the former empty-button pin enshrined blankness as the wire contract, which was the defect, not the honesty. The claim that MATTERS is unchanged and still asserted: the markup never ships a STATE label (sound_toggle_label_on), because the state lives in this browser's storage and only the client program may paint it." +// Amended at A1 (presentation recon, 2026-08-01): the markup ships the control's NAME ('sound') so +// the button has visible content and an accessible name before the client program runs — the former +// empty-button pin enshrined blankness as the wire contract, which was the defect, not the honesty. +// The claim that MATTERS is unchanged and still asserted: the markup never ships a STATE label +// (sound_toggle_label_on), because the state lives in this browser's storage and only the client +// program may paint it. test fn witness_sound_toggle_label_is_painted_by_the_program_not_the_markup() -> Bool { match try_serialize_html_source(node: roadmap_page_for_authority()) { diff --git a/dag/test/claim/roadmap/roadmap_validation_oracle_witness_test.dag b/dag/test/claim/roadmap/roadmap_validation_oracle_witness_test.dag index 4516b0f1d6b..809cd926f64 100644 --- a/dag/test/claim/roadmap/roadmap_validation_oracle_witness_test.dag +++ b/dag/test/claim/roadmap/roadmap_validation_oracle_witness_test.dag @@ -95,7 +95,11 @@ import gunbc.roadmap_validation_oracle { ValidationReceiptUndecodable, } -data oracle_fixture_note: String = "The fixtures model the exact situation this lane exists for: ONE attempt, whose diff touches a subject file and — in the discriminating case — the witness that judges it. The oracle entry and function are held constant across every case below, so the only thing that varies is the witness SOURCE. That is what makes the pair of cases discriminating rather than merely different: a mechanism that greened both would be reading the contract, not the oracle." +// The fixtures model the exact situation this lane exists for: ONE attempt, whose diff touches a +// subject file and — in the discriminating case — the witness that judges it. The oracle entry and +// function are held constant across every case below, so the only thing that varies is the witness +// SOURCE. That is what makes the pair of cases discriminating rather than merely different: a +// mechanism that greened both would be reading the contract, not the oracle. data oracle_entry_path: FilePath = "src/v2/compiler/self_host/frontier_witness_test.dag" as FilePath @@ -163,7 +167,13 @@ fn observe_witness(source_readable: Bool, source: String) -> List ContentHash { match validation_oracle_set_observe( @@ -203,7 +213,12 @@ fn gate_refusal_key(gate: ValidationOracleGate) -> String { } } -data subject_only_diff_note: String = "The green half of the discriminating pair. The attempt's diff edited the SUBJECT the witness tests, not the witness, so the oracle source at verification time is byte-identical to the source pinned at dispatch and the gate admits. Nothing about the subject enters the identity — that is deliberate and is the whole reason a closure-wide pin would be wrong: the subject is IN the witness's import closure, so pinning the closure would refuse exactly this case, which is the case the node exists to produce." +// The green half of the discriminating pair. The attempt's diff edited the SUBJECT the witness +// tests, not the witness, so the oracle source at verification time is byte-identical to the source +// pinned at dispatch and the gate admits. Nothing about the subject enters the identity — that is +// deliberate and is the whole reason a closure-wide pin would be wrong: the subject is IN the +// witness's import closure, so pinning the closure would refuse exactly this case, which is the +// case the node exists to produce. test fn diff_touching_only_the_subject_verifies_clean() -> Bool { match gate_for( @@ -215,7 +230,14 @@ test fn diff_touching_only_the_subject_verifies_clean() -> Bool { } } -data self_edited_witness_note: String = "The RED control, and the reason the whole lane exists. The attempt edited its own witness — here by collapsing the assertion body to `true`, the cheapest way for an agent to make its own verification pass — and BOTH receipts still pass when run: the weakened witness returns true, and the declared command exits 0. A verification that only ran the command would report green. The gate refuses because the oracle it would have run against is not the oracle that was pinned before the agent started. Flip the expected identity to be recomputed at verification time instead of read from the dispatch pin and this witness goes green while the one above stays green, which is exactly the version that has proven nothing." +// The RED control, and the reason the whole lane exists. The attempt edited its own witness — here +// by collapsing the assertion body to `true`, the cheapest way for an agent to make its own +// verification pass — and BOTH receipts still pass when run: the weakened witness returns true, and +// the declared command exits 0. A verification that only ran the command would report green. The +// gate refuses because the oracle it would have run against is not the oracle that was pinned +// before the agent started. Flip the expected identity to be recomputed at verification time +// instead of read from the dispatch pin and this witness goes green while the one above stays +// green, which is exactly the version that has proven nothing. test fn diff_editing_its_own_witness_refuses_with_oracle_moved() -> Bool { match gate_for( @@ -236,7 +258,11 @@ test fn diff_editing_its_own_witness_refuses_with_oracle_moved() -> Bool { } } -data pin_must_be_sensitive_note: String = "Non-vacuity for the pair above. If validation_oracle_source_identity collapsed every input to one value — the failure a digest silently degrading to a constant would produce — the clean case would still admit and the self-edit case would ALSO admit, so the pair would agree while proving nothing. This asserts the identity actually separates the two sources, so the discrimination above rests on a measured difference rather than on the arms happening to be written differently." +// Non-vacuity for the pair above. If validation_oracle_source_identity collapsed every input to one +// value — the failure a digest silently degrading to a constant would produce — the clean case +// would still admit and the self-edit case would ALSO admit, so the pair would agree while proving +// nothing. This asserts the identity actually separates the two sources, so the discrimination +// above rests on a measured difference rather than on the arms happening to be written differently. test fn oracle_identity_separates_the_two_witness_sources() -> Bool { let pinned = validation_oracle_source_identity( @@ -248,7 +274,12 @@ test fn oracle_identity_separates_the_two_witness_sources() -> Bool { pinned != weakened } -data deleted_witness_note: String = "The second oracle control from the brief, and it is about the DIFFERENCE between two answers rather than about refusing. A deleted witness must answer that the oracle is missing — not that the witness failed. The remedies are opposite: a red witness means fix the subject, a missing oracle means find out who removed the thing that was judging it. Collapsing the first into the second is the state-space conflation that would send a human to debug a subject that was never tested." +// The second oracle control from the brief, and it is about the DIFFERENCE between two answers +// rather than about refusing. A deleted witness must answer that the oracle is missing — not that +// the witness failed. The remedies are opposite: a red witness means fix the subject, a missing +// oracle means find out who removed the thing that was judging it. Collapsing the first into the +// second is the state-space conflation that would send a human to debug a subject that was never +// tested. test fn deleted_witness_answers_oracle_missing_not_red() -> Bool { let gate = gate_for(source_readable: false, source: "") @@ -267,7 +298,11 @@ test fn deleted_witness_answers_oracle_missing_not_red() -> Bool { && gate_refusal_key(gate: gate) != "failed" } -data present_file_missing_declaration_note: String = "The other producer of the missing arm, kept because it is the likelier real case: the witness FILE survives and the declaration the contract names does not, which a whole-file read reports as a successful read of a document that no longer contains the oracle. A mechanism that only checked readability would run the claim runner against a function that is not there and adjudicate whatever the runner said about that." +// The other producer of the missing arm, kept because it is the likelier real case: the witness +// FILE survives and the declaration the contract names does not, which a whole-file read reports as +// a successful read of a document that no longer contains the oracle. A mechanism that only checked +// readability would run the claim runner against a function that is not there and adjudicate +// whatever the runner said about that. test fn readable_source_without_the_declaration_is_also_missing() -> Bool { gate_refusal_key(gate: gate_for( @@ -310,7 +345,15 @@ test fn declaration_scan_ignores_the_name_inside_a_note() -> Bool { ) == 1 } -data unpinned_dependency_note: String = "review 45278. The entry-file pin closes the direct attack but leaves a witness's IMPORTED test modules — fixtures and shared assertions, which are oracle rather than subject — outside the digest. The fixture below is the reviewer's own measured specimen reproduced in shape: dag/test/claim/scm/scm_compatibility_shape_witness_test.dag imports four test.claim modules, so weakening one of them would green Verify without moving the pinned entry's digest. The residue is therefore made unreachable rather than deferred: such an oracle refuses. The paired green is what keeps this from being a blanket rejection — a witness importing only subject and std modules still verifies, so the refusal discriminates on the oracle-side dependency rather than on having imports at all." +// review 45278. The entry-file pin closes the direct attack but leaves a witness's IMPORTED test +// modules — fixtures and shared assertions, which are oracle rather than subject — outside the +// digest. The fixture below is the reviewer's own measured specimen reproduced in shape: +// dag/test/claim/scm/scm_compatibility_shape_witness_test.dag imports four test.claim modules, so +// weakening one of them would green Verify without moving the pinned entry's digest. The residue is +// therefore made unreachable rather than deferred: such an oracle refuses. The paired green is what +// keeps this from being a blanket rejection — a witness importing only subject and std modules +// still verifies, so the refusal discriminates on the oracle-side dependency rather than on having +// imports at all. fn witness_source_importing_test_helpers() -> String { join([ @@ -454,7 +497,9 @@ test fn attempt_without_a_recorded_pin_refuses() -> Bool { } } -data refusal_is_not_a_red_note: String = "The refusal/red separation carried through to the persisted verdict, because the receipt is what a human and the Verify lamp both read. A refused verdict and a failed verdict must not serialize to the same word, or the distinction the arms establish is lost at the seam where it matters." +// The refusal/red separation carried through to the persisted verdict, because the receipt is what +// a human and the Verify lamp both read. A refused verdict and a failed verdict must not serialize +// to the same word, or the distinction the arms establish is lost at the seam where it matters. test fn refused_and_failed_verdicts_are_distinct_on_the_wire() -> Bool { let refused = ValidationRefused { @@ -476,7 +521,12 @@ test fn refused_and_failed_verdicts_are_distinct_on_the_wire() -> Bool { && refused_key != failed_key } -data receipt_positional_identity_note: String = "The same defect the environment-admission receipt already closed, asserted here before this receipt can repeat it. The verdict is read back from disk by a different process, so nothing guarantees the bytes came from this emitter; a reader that SCANNED the document for `passed` would be satisfied by a refusal whose detail quotes the word — and a refusal detail quotes plenty. The emitter always writes schema then verdict first, so the passed document's prefix is derivable from the emitter itself and no nested value can occupy it." +// The same defect the environment-admission receipt already closed, asserted here before this +// receipt can repeat it. The verdict is read back from disk by a different process, so nothing +// guarantees the bytes came from this emitter; a reader that SCANNED the document for `passed` +// would be satisfied by a refusal whose detail quotes the word — and a refusal detail quotes +// plenty. The emitter always writes schema then verdict first, so the passed document's prefix is +// derivable from the emitter itself and no nested value can occupy it. test fn refusal_quoting_passed_does_not_decode_as_passed() -> Bool { let forgery = validation_receipt_json( @@ -510,7 +560,11 @@ test fn refusal_quoting_passed_does_not_decode_as_passed() -> Bool { } } -data truncated_receipt_note: String = "Self-review catch, mirroring the control the admission receipt already carries: a prefix match alone was never the claim. A receipt truncated mid-write — the ordinary outcome of a belt killed while writing it — carries the passed prefix verbatim and is still not a passed receipt, because the document does not parse. Without the parse guard this fixture decodes as passed, which is a fabricated green produced by an interrupted write rather than by any validation." +// Self-review catch, mirroring the control the admission receipt already carries: a prefix match +// alone was never the claim. A receipt truncated mid-write — the ordinary outcome of a belt killed +// while writing it — carries the passed prefix verbatim and is still not a passed receipt, because +// the document does not parse. Without the parse guard this fixture decodes as passed, which is a +// fabricated green produced by an interrupted write rather than by any validation. test fn truncated_receipt_with_passed_prefix_is_not_passed() -> Bool { let genuine = receipt_for(verdict: ValidationPassed { @@ -527,7 +581,15 @@ test fn truncated_receipt_with_passed_prefix_is_not_passed() -> Bool { && exact_head_receipt_is_undecodable(receipt: truncated) } -data structural_decode_note: String = "These pin what the byte-prefix reader structurally COULD NOT decide, which is why they are the receipt for replacing it rather than decoration on top of it. A prefix reader answers one question - does the document open with these exact bytes - so it necessarily conflates `the members are in a different order` with `this is not our receipt`, and it cannot see a second verdict member at all because a duplicate sits past the prefix it compares. Reading the document as a value makes member ORDER irrelevant and member COUNT decidable, and the pair below is stated as a control: the same document decodes when its identity members occur once and refuses when one of them occurs twice, so duplication is isolated as the cause rather than inferred from a refusal that could have come from anywhere." +// These pin what the byte-prefix reader structurally COULD NOT decide, which is why they are the +// receipt for replacing it rather than decoration on top of it. A prefix reader answers one +// question - does the document open with these exact bytes - so it necessarily conflates `the +// members are in a different order` with `this is not our receipt`, and it cannot see a second +// verdict member at all because a duplicate sits past the prefix it compares. Reading the document +// as a value makes member ORDER irrelevant and member COUNT decidable, and the pair below is stated +// as a control: the same document decodes when its identity members occur once and refuses when one +// of them occurs twice, so duplication is isolated as the cause rather than inferred from a refusal +// that could have come from anywhere. fn decodes_as(receipt: String, expected: String) -> Bool { match validation_receipt_decode(receipt: receipt) { @@ -611,7 +673,11 @@ test fn members_after_the_identity_pair_do_not_disturb_the_decode() -> Bool { ) } -data forged_escape_note: String = "review 45642, stated at the boundary that would have been fooled rather than only at the parser. `p\\assed` is not JSON, but the unescaper's unknown-escape arm dropped the backslash and produced exactly the string this reader accepts as a verdict - so a malformed receipt decoded as a pass. The positive control beside it is what makes the claim about the FORGERY rather than about the decoder refusing things generally." +// review 45642, stated at the boundary that would have been fooled rather than only at the parser. +// `p\assed` is not JSON, but the unescaper's unknown-escape arm dropped the backslash and produced +// exactly the string this reader accepts as a verdict - so a malformed receipt decoded as a pass. +// The positive control beside it is what makes the claim about the FORGERY rather than about the +// decoder refusing things generally. test fn a_verdict_forged_with_an_unknown_escape_is_undecodable() -> Bool { is_undecodable( @@ -623,7 +689,16 @@ test fn a_verdict_forged_with_an_unknown_escape_is_undecodable() -> Bool { ) } -data verdict_key_agreement_note: String = "validation_verdict_key is the emitter's authority for a verdict's wire key, and validation_receipt_verdict_keys is the reader's list of the keys it accepts. Those are two surfaces over one fact and they can drift: adding a fifth ValidationVerdict variant updates the emitter by exhaustiveness, because the match must gain an arm, but the reader's list is an ordinary data row that nothing forces anyone to extend - so the emitter would write a receipt its own reader refuses, and the failure would surface as an undecodable verdict rather than as a missing case. This pins them to each other by round-tripping every verdict the emitter can produce, which is the same shape as witness_json_text_parse_agrees_with_lexeme_surface_on_exponents: the forked surfaces are the thing under test, not either surface alone." +// validation_verdict_key is the emitter's authority for a verdict's wire key, and +// validation_receipt_verdict_keys is the reader's list of the keys it accepts. Those are two +// surfaces over one fact and they can drift: adding a fifth ValidationVerdict variant updates the +// emitter by exhaustiveness, because the match must gain an arm, but the reader's list is an +// ordinary data row that nothing forces anyone to extend - so the emitter would write a receipt its +// own reader refuses, and the failure would surface as an undecodable verdict rather than as a +// missing case. This pins them to each other by round-tripping every verdict the emitter can +// produce, which is the same shape as +// witness_json_text_parse_agrees_with_lexeme_surface_on_exponents: the forked surfaces are the +// thing under test, not either surface alone. fn verdict_round_trips(verdict: ValidationVerdict) -> Bool { decodes_as( @@ -672,7 +747,10 @@ test fn moved_oracle_detail_locates_both_identities() -> Bool { && string_contains(s: detail, pattern: "proves nothing") } -data cross_family_pin_refusal_note: String = "Cross-family incomparable is NOT oracle drift. Collapsing it into ValidationOracleMoved would send a human to re-run CI against a moved witness when the real fault is that the pin channel stored one hash family and the observation carried another — a modeling error upstream, not staleness." +// Cross-family incomparable is NOT oracle drift. Collapsing it into ValidationOracleMoved would +// send a human to re-run CI against a moved witness when the real fault is that the pin channel +// stored one hash family and the observation carried another — a modeling error upstream, not +// staleness. test fn cross_family_pin_refusal_is_distinct_from_oracle_moved() -> Bool { let expected = content_hash_of_value(value: "pinned-structural-oracle") @@ -701,7 +779,11 @@ test fn cross_family_pin_refusal_is_distinct_from_oracle_moved() -> Bool { } } -data verify_lamp_note: String = "The lamp is the seam where the distinction has to survive, because it is what a human actually looks at. These assert the three verdicts land on three DIFFERENT segment states and that an absent receipt still reads pending — the last one being the property the old hardcoded lamp had for free and that a receipt-reading lamp could easily lose, since the tempting shortcut is to paint Verify from the agent's own completion." +// The lamp is the seam where the distinction has to survive, because it is what a human actually +// looks at. These assert the three verdicts land on three DIFFERENT segment states and that an +// absent receipt still reads pending — the last one being the property the old hardcoded lamp had +// for free and that a receipt-reading lamp could easily lose, since the tempting shortcut is to +// paint Verify from the agent's own completion. data verify_fixture_head: CommitSha = "cafecafecafecafecafecafecafecafecafecafe" as CommitSha @@ -870,7 +952,14 @@ test fn verify_lamp_shows_cross_family_refusal_as_refused_not_moved() -> Bool { )) == "refused" } -data not_run_receipt_note: String = "review 45271. The receipt-presence seam used to ask whether the receipt TEXT was empty, which answered the same way for three different worlds — no file, an unreadable file, an empty one — and then ran the validation and overwrote whatever was there. Absent and unreadable have opposite correct actions, so dispatch now writes a not-run receipt and absence stops being a state the seam has to interpret. These assert the two halves that makes true: a not-run receipt is DISTINGUISHABLE from every recorded verdict (so the belt can tell 'never ran' from 'already ran' without consulting the filesystem's error string), and it reads as pending at the lamp rather than as a verdict." +// review 45271. The receipt-presence seam used to ask whether the receipt TEXT was empty, which +// answered the same way for three different worlds — no file, an unreadable file, an empty one — +// and then ran the validation and overwrote whatever was there. Absent and unreadable have opposite +// correct actions, so dispatch now writes a not-run receipt and absence stops being a state the +// seam has to interpret. These assert the two halves that makes true: a not-run receipt is +// DISTINGUISHABLE from every recorded verdict (so the belt can tell 'never ran' from 'already ran' +// without consulting the filesystem's error string), and it reads as pending at the lamp rather +// than as a verdict. test fn not_run_receipt_is_distinct_from_every_recorded_verdict() -> Bool { let not_run = receipt_for(verdict: ValidationNotRun) diff --git a/dag/test/claim/roadmap/roadmap_verification_receipt_witness_test.dag b/dag/test/claim/roadmap/roadmap_verification_receipt_witness_test.dag index b72e1969a97..dd132566be5 100644 --- a/dag/test/claim/roadmap/roadmap_verification_receipt_witness_test.dag +++ b/dag/test/claim/roadmap/roadmap_verification_receipt_witness_test.dag @@ -46,7 +46,12 @@ import gunbc.roadmap_dispatch_actuator { dispatch_attempt_verification_receipt_path_for_instance, } -data verification_receipt_witness_note: String = "GREEN-BY-CONSTRUCTION witness for the exact-head verification model. The fixture supplies every required subject field, one structural validation operation, one realized program-plus-argv command, and separated exit/stdout/stderr evidence. The discriminating RED changes only head_sha: the old receipt remains readable and passed, but verification_evidence_moves_lamp refuses it for the new head. The legacy control supplies the old decoder's most favourable value, passed, and still cannot move the lamp because no subject can be recovered from it." +// GREEN-BY-CONSTRUCTION witness for the exact-head verification model. The fixture supplies every +// required subject field, one structural validation operation, one realized program-plus-argv +// command, and separated exit/stdout/stderr evidence. The discriminating RED changes only head_sha: +// the old receipt remains readable and passed, but verification_evidence_moves_lamp refuses it for +// the new head. The legacy control supplies the old decoder's most favourable value, passed, and +// still cannot move the lamp because no subject can be recovered from it. fn subject_at(head: CommitSha) -> VerificationSubject { VerificationSubject { diff --git a/dag/test/claim/roadmap/roadmap_verify_witness_test.dag b/dag/test/claim/roadmap/roadmap_verify_witness_test.dag index 255d017a523..453db16a9a3 100644 --- a/dag/test/claim/roadmap/roadmap_verify_witness_test.dag +++ b/dag/test/claim/roadmap/roadmap_verify_witness_test.dag @@ -70,7 +70,14 @@ test fn the_two_lab_instances_really_do_straddle_the_transport_split() -> Bool { remote && local } -data binding_law_note: String = "THE THREE-SITE DISAGREEMENT, pinned at the one authority that now decides it. gunbc.roadmap_authority read any ExecutionContract as bound; gunbc.roadmap_verify read an empty validation list as unbound; gunbc.roadmap_dispatch_environment refused it. Empty contracts are constructible, so the disagreement was reachable — a node bound to one would leave the acceptance frontier while remaining unverifiable and undispatchable.\\n\\nThe empty contract is the discriminating input, and the closure keeps it distinct from the unspecified one because their remedies differ: author a contract, versus fix the one you authored. A Bool-only authority would have collapsed them and taken dispatch_environment's located diagnostics with it." +// THE THREE-SITE DISAGREEMENT, pinned at the one authority that now decides it. +// gunbc.roadmap_authority read any ExecutionContract as bound; gunbc.roadmap_verify read an empty +// validation list as unbound; gunbc.roadmap_dispatch_environment refused it. Empty contracts are +// constructible, so the disagreement was reachable — a node bound to one would leave the acceptance +// frontier while remaining unverifiable and undispatchable.\n\nThe empty contract is the +// discriminating input, and the closure keeps it distinct from the unspecified one because their +// remedies differ: author a contract, versus fix the one you authored. A Bool-only authority would +// have collapsed them and taken dispatch_environment's located diagnostics with it. fn empty_contract() -> WorkItemExecutionContract { ExecutionContract { validations: [], extra_capabilities: [] } @@ -149,7 +156,13 @@ test fn refusal_and_failure_and_unbound_all_exit_failure() -> Bool { refused && failed && unbound } -data receipt_binds_the_facts_note: String = "THE FOUR FACTS THAT MAKE A VERIFICATION CHECKABLE, and none of which the first cut carried. An outcome says pass or fail; it does not say which tree, at which revision, on which machine, running which realized command — so a verification that ran on the wrong host against the wrong tree produced a value indistinguishable from a correct one. That is exactly what happened.\\n\\nThe receipt is asserted through its serialized form rather than field by field, because the serialization is what a Publication step or an operator actually reads. A field that exists in the type and is dropped by the projection would pass a field-wise claim and fail this one." +// THE FOUR FACTS THAT MAKE A VERIFICATION CHECKABLE, and none of which the first cut carried. An +// outcome says pass or fail; it does not say which tree, at which revision, on which machine, +// running which realized command — so a verification that ran on the wrong host against the wrong +// tree produced a value indistinguishable from a correct one. That is exactly what happened.\n\nThe +// receipt is asserted through its serialized form rather than field by field, because the +// serialization is what a Publication step or an operator actually reads. A field that exists in +// the type and is dropped by the projection would pass a field-wise claim and fail this one. fn sample_receipt() -> LegacySingleValidationVerificationReceipt { LegacySingleValidationVerificationReceipt { @@ -175,7 +188,11 @@ test fn receipt_projection_carries_host_worktree_revision_and_command() -> Bool && string_contains(s: j, pattern: "gunbc-claim") } -data unobserved_exit_note: String = "A process that never ran has no exit code, and zero is the wrong answer for it in the most dangerous direction. The receipt keeps the distinction as a coproduct, and this claim checks that the serialized form does not quietly render an unobserved exit as a success — a receipt reading exit 0 for a command the transport never delivered is the fabricated verdict the whole split exists to prevent." +// A process that never ran has no exit code, and zero is the wrong answer for it in the most +// dangerous direction. The receipt keeps the distinction as a coproduct, and this claim checks that +// the serialized form does not quietly render an unobserved exit as a success — a receipt reading +// exit 0 for a command the transport never delivered is the fabricated verdict the whole split +// exists to prevent. test fn unobserved_exit_never_serializes_as_zero() -> Bool { let j = legacy_single_validation_verification_receipt_json( diff --git a/dag/test/claim/roadmap/roadmap_workflow_progress_witness_test.dag b/dag/test/claim/roadmap/roadmap_workflow_progress_witness_test.dag index fff6e04c91d..f272827b9ab 100644 --- a/dag/test/claim/roadmap/roadmap_workflow_progress_witness_test.dag +++ b/dag/test/claim/roadmap/roadmap_workflow_progress_witness_test.dag @@ -233,7 +233,11 @@ test fn completed_event_and_nonzero_exit_refuse_contradiction() -> Bool { } } -data agent_completion_requires_compatible_exit_note: String = "review 44032 REDs. The Agent obligation's design contract requires a compatible process exit, so turn.completed alone must never paint agent complete. These three witnesses pin the arms that previously preserved ProviderCompleted from incomplete evidence: still-running stays active, absent refuses, unobserved refuses. Each is the discriminating control for one arm — flipping any back to `provider` reds exactly one of them." +// review 44032 REDs. The Agent obligation's design contract requires a compatible process exit, so +// turn.completed alone must never paint agent complete. These three witnesses pin the arms that +// previously preserved ProviderCompleted from incomplete evidence: still-running stays active, +// absent refuses, unobserved refuses. Each is the discriminating control for one arm — flipping any +// back to `provider` reds exactly one of them. test fn completed_event_while_process_runs_is_not_complete() -> Bool { let progress = workflow_attempt_progress(evidence: fixture_evidence( @@ -274,7 +278,17 @@ test fn completed_event_with_unobserved_process_refuses() -> Bool { } } -data admission_receipt_positional_identity_note: String = "review 44032 RED. The admission receipt is READ BACK FROM DISK, so nothing guarantees the bytes came from dispatch_environment_admission_json — a corrupt, truncated, or foreign file is exactly the case the projection must survive. The forgery below is well-formed JSON that declares status refused at the top level while carrying an admitted status in a nested member; the former two-string_contains scan matched both fragments and read it as admitted. Note the emitter's own escaping already prevented the narrower attack (a quoted reason cannot reproduce a raw fragment), which is why the fixture is a raw document rather than a round-trip: the vulnerability was never in the emitter, it was in identifying a document by scanning it. Positional identity refuses this because a nested value cannot occupy the document prefix, and the paired green keeps the real emitter's admitted receipt admitted so the witness discriminates rather than rejecting everything." +// review 44032 RED. The admission receipt is READ BACK FROM DISK, so nothing guarantees the bytes +// came from dispatch_environment_admission_json — a corrupt, truncated, or foreign file is exactly +// the case the projection must survive. The forgery below is well-formed JSON that declares status +// refused at the top level while carrying an admitted status in a nested member; the former +// two-string_contains scan matched both fragments and read it as admitted. Note the emitter's own +// escaping already prevented the narrower attack (a quoted reason cannot reproduce a raw fragment), +// which is why the fixture is a raw document rather than a round-trip: the vulnerability was never +// in the emitter, it was in identifying a document by scanning it. Positional identity refuses this +// because a nested value cannot occupy the document prefix, and the paired green keeps the real +// emitter's admitted receipt admitted so the witness discriminates rather than rejecting +// everything. fn admission_receipt_for(admission: DispatchEnvironmentAdmission) -> String { dispatch_environment_admission_json(admission: admission) @@ -312,7 +326,10 @@ test fn refused_receipt_quoting_admitted_fragments_is_not_admitted() -> Bool { && receipt_records_admission(receipt: genuine) } -data receipt_decode_witness_note: String = "review 44094. The decode splits what the old Bool merged: a receipt that RECORDS a refusal is a different state from a document this reader cannot decode, and each now has its own arm. The truncated fixture is the discriminating one — it carries the admitted prefix verbatim and still fails, because a prefix match alone was never the claim; the whole document must also parse." +// review 44094. The decode splits what the old Bool merged: a receipt that RECORDS a refusal is a +// different state from a document this reader cannot decode, and each now has its own arm. The +// truncated fixture is the discriminating one — it carries the admitted prefix verbatim and still +// fails, because a prefix match alone was never the claim; the whole document must also parse. test fn receipt_decode_separates_refusal_from_undecodable() -> Bool { let refused = admission_receipt_for(admission: EnvironmentRefused { @@ -543,7 +560,17 @@ test fn roadmap_workflow_progress_keystone_holds() -> Bool { && failed_or_refused_stage_is_visible_without_decoding_border_style() } -data publication_projection_witness_note: String = "THE VERTICAL SPECIMEN, WITH ITS NEGATIVE HALF, AND THE NEGATIVE HALF IS WHY IT EXISTS. A claim that a bound receipt paints the lamp green proves the happy path and nothing else; it stays green under the exact defect this lane was rewritten to remove, which is a consumer that finds a receipt at a path and trusts what it finds.\\n\\nSO THE SPECIMEN IS ONE RECEIPT READ TWICE. Written for head H, it completes the row whose subject is H, and it does NOT complete the row whose subject is H2 - it refuses there, naming expected_head as the field that differs. That is the review loop's real shape: a worker pushes a correction while a receipt for the earlier head is still on disk, and every downstream obligation is about the new commit.\\n\\nAND THE SUBJECT ITSELF CAN BE MISSING, which is a fifth reading rather than a phrasing of pending. An attempt whose head could not be read has nothing to compare a receipt against, so the lamp refuses and says so - never `pending`, which a reader would take for `not published yet`." +// THE VERTICAL SPECIMEN, WITH ITS NEGATIVE HALF, AND THE NEGATIVE HALF IS WHY IT EXISTS. A claim +// that a bound receipt paints the lamp green proves the happy path and nothing else; it stays green +// under the exact defect this lane was rewritten to remove, which is a consumer that finds a +// receipt at a path and trusts what it finds.\n\nSO THE SPECIMEN IS ONE RECEIPT READ TWICE. Written +// for head H, it completes the row whose subject is H, and it does NOT complete the row whose +// subject is H2 - it refuses there, naming expected_head as the field that differs. That is the +// review loop's real shape: a worker pushes a correction while a receipt for the earlier head is +// still on disk, and every downstream obligation is about the new commit.\n\nAND THE SUBJECT ITSELF +// CAN BE MISSING, which is a fifth reading rather than a phrasing of pending. An attempt whose head +// could not be read has nothing to compare a receipt against, so the lamp refuses and says so - +// never `pending`, which a reader would take for `not published yet`. data pub_head: CommitSha = "cafecafecafecafecafecafecafecafecafecafe" data pub_other: CommitSha = "d00dd00dd00dd00dd00dd00dd00dd00dd00dd00d" @@ -673,7 +700,11 @@ test fn a_receipt_for_the_previous_head_cannot_complete_the_current_one() -> Boo && string_contains(s: detail_at_h2, pattern: "expected_head") } -data bound_sentence_names_one_head_note: String = "The completed sentence an operator reads must name the head that was actually judged. ReceiptBound no longer carries a head of its own, so this projection renders subject.expected_head - the single copy in the document. The claim asserts BOTH directions: the judged head appears, and the other fixture sha does not, because a sentence that could name a second head is the same defect one layer out from the one review 46116 found in the carrier." +// The completed sentence an operator reads must name the head that was actually judged. +// ReceiptBound no longer carries a head of its own, so this projection renders +// subject.expected_head - the single copy in the document. The claim asserts BOTH directions: the +// judged head appears, and the other fixture sha does not, because a sentence that could name a +// second head is the same defect one layer out from the one review 46116 found in the carrier. test fn the_completed_sentence_names_the_head_that_was_judged() -> Bool { let detail = publication_segment_of( @@ -684,7 +715,9 @@ test fn the_completed_sentence_names_the_head_that_was_judged() -> Bool { && !string_contains(s: detail, pattern: pub_other as String) } -data unreadable_lamp_is_not_pending_note: String = "A receipt the projection could not READ is not a row nobody has published (review 46148). Pending invites a reader to wait; refused tells them something is broken. Both directions are asserted here because the defect made them the same lamp." +// A receipt the projection could not READ is not a row nobody has published (review 46148). Pending +// invites a reader to wait; refused tells them something is broken. Both directions are asserted +// here because the defect made them the same lamp. test fn an_unreadable_receipt_refuses_rather_than_reading_as_not_yet_published() -> Bool { let unreadable = publication_state_at( diff --git a/dag/test/claim/root4_measure_missing_generics_witness_test.dag b/dag/test/claim/root4_measure_missing_generics_witness_test.dag index 7f0bd15d75f..ea7d1f52ccd 100644 --- a/dag/test/claim/root4_measure_missing_generics_witness_test.dag +++ b/dag/test/claim/root4_measure_missing_generics_witness_test.dag @@ -5,7 +5,43 @@ import v2.std.live_tree { LiveTreeDisposition, SubstrateInputsOnly } data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data root4_measure_missing_generics_witness_note: String = "Root-4 measure_missing_generics family: a function-generic container argument must preserve its applied arguments through render_rust_decl_type overlay resolution. The executable emitter-level fixtures use deliberately synthetic Root4AppliedCarrier, Root4AliasCarrier, and Root4ZeroArityCarrier names, so they exercise the structural shape without re-declaring the canonical std.measure.Measure authority; canonical Measure behavior is covered by the stamped canonical-seven receipt. The decision is structural (__applied_type_args or resolved-type children), never a type-name check. The combined-state fixture proves that an explicitly empty applied-argument property does not suppress non-empty resolved children. RED controls: w_zero_param_alias_use_site_stays_bare pins the closed-alias use site to the bare alias name; w_unrelated_zero_param_leaf_unchanged proves a bare leaf without applied or resolved children does not gain arguments. w_zero_param_alias_use_site_stays_bare previously asserted the OPPOSITE shape -- Rc>>, an alias declared in Rust with no parameters and then applied to three arguments, which rustc refuses as E0107. It was enrolled and green, so the defect had a defender: the emitted declaration pub type ClosedCarrierAlias = Rc>; already carries the substitution, and a use site that re-supplies the definition arguments cannot compile under any reading. The witness now asserts the declaration and the bare use site together, and excludes the applied spelling, so the emitted pair is checked for agreement rather than either half alone.\n\nw_positive_int_refined_alias_rhs_stays_bare_nat REQUIRED SPELLING CHANGED (eager-deer-389, Root B cutover): it required 'pub type PositiveInt = crate::std_nat::Nat' and now requires 'pub type PositiveInt = i64;'. This is a deliberate model change, not a red made to go away, and the reason is recorded here rather than in a commit message because the next reader of this row will ask. Root B deletes the global RustCorpusRepr emission mode and keys Rust primitive realization on the DECLARING MODULE of the type. Under the deleted mode this fixture emitted the std_nat path only because its synthetic single-module closure happened to contain no v1 sources -- the SAME declaration realized differently depending on which other sources shared the closure, which is precisely the defect the cut removes. Under declaration keying, dag/std/nat.dag's Nat realizes natively everywhere, so the refined alias RHS renders as the native spelling. MEASURED, not assumed: emitting this exact source on the post-cut emitter produces 'pub type PositiveInt = i64;' AND emits std_nat.rs containing 'pub type Nat = i64;', so the two spellings denote the SAME Rust type and the old required string would still have compiled -- what changed is which of two equivalent spellings the emitter chooses, not the type. The row's actual subject is unaffected: it exists to prove the refined alias RHS stays BARE rather than gaining phantom type arguments (the E0107 class), and both exclusions -- 'Nat' and 'Nat<' -- are unchanged and still hold, with the native spelling satisfying bareness at least as strongly. If a future cut makes Nat structural again this row flips back, and that flip is a real signal rather than noise." +// Root-4 measure_missing_generics family: a function-generic container argument must preserve its +// applied arguments through render_rust_decl_type overlay resolution. The executable emitter-level +// fixtures use deliberately synthetic Root4AppliedCarrier, Root4AliasCarrier, and +// Root4ZeroArityCarrier names, so they exercise the structural shape without re-declaring the +// canonical std.measure.Measure authority; canonical Measure behavior is covered by the stamped +// canonical-seven receipt. The decision is structural (__applied_type_args or resolved-type +// children), never a type-name check. The combined-state fixture proves that an explicitly empty +// applied-argument property does not suppress non-empty resolved children. RED controls: +// w_zero_param_alias_use_site_stays_bare pins the closed-alias use site to the bare alias name; +// w_unrelated_zero_param_leaf_unchanged proves a bare leaf without applied or resolved children +// does not gain arguments. w_zero_param_alias_use_site_stays_bare previously asserted the OPPOSITE +// shape -- Rc>>, an alias +// declared in Rust with no parameters and then applied to three arguments, which rustc refuses as +// E0107. It was enrolled and green, so the defect had a defender: the emitted declaration pub type +// ClosedCarrierAlias = Rc>; already carries the substitution, and a use site +// that re-supplies the definition arguments cannot compile under any reading. The witness now +// asserts the declaration and the bare use site together, and excludes the applied spelling, so the +// emitted pair is checked for agreement rather than either half alone. +// +// w_positive_int_refined_alias_rhs_stays_bare_nat REQUIRED SPELLING CHANGED (eager-deer-389, Root B +// cutover): it required 'pub type PositiveInt = crate::std_nat::Nat' and now requires 'pub type +// PositiveInt = i64;'. This is a deliberate model change, not a red made to go away, and the reason +// is recorded here rather than in a commit message because the next reader of this row will ask. +// Root B deletes the global RustCorpusRepr emission mode and keys Rust primitive realization on the +// DECLARING MODULE of the type. Under the deleted mode this fixture emitted the std_nat path only +// because its synthetic single-module closure happened to contain no v1 sources -- the SAME +// declaration realized differently depending on which other sources shared the closure, which is +// precisely the defect the cut removes. Under declaration keying, dag/std/nat.dag's Nat realizes +// natively everywhere, so the refined alias RHS renders as the native spelling. MEASURED, not +// assumed: emitting this exact source on the post-cut emitter produces 'pub type PositiveInt = +// i64;' AND emits std_nat.rs containing 'pub type Nat = i64;', so the two spellings denote the SAME +// Rust type and the old required string would still have compiled -- what changed is which of two +// equivalent spellings the emitter chooses, not the type. The row's actual subject is unaffected: +// it exists to prove the refined alias RHS stays BARE rather than gaining phantom type arguments +// (the E0107 class), and both exclusions -- 'Nat' and 'Nat<' -- are unchanged and still +// hold, with the native spelling satisfying bareness at least as strongly. If a future cut makes +// Nat structural again this row flips back, and that flip is a real signal rather than noise. // ONE WITNESS PER SUBJECT, WHERE THERE USED TO BE ONE CONJUNCTION OVER FIVE. // diff --git a/dag/test/claim/run_verdict_exit_status_fixture.dag b/dag/test/claim/run_verdict_exit_status_fixture.dag index 88d68c71a1e..488648993d4 100644 --- a/dag/test/claim/run_verdict_exit_status_fixture.dag +++ b/dag/test/claim/run_verdict_exit_status_fixture.dag @@ -4,15 +4,19 @@ import std.process { ProcessExit, ExitSuccess, ExitFailure } // The minimum crossing specimen for "a run's verdict reaches the process status". // -// Three entries, each the requirement plus nothing: one per arm of the driver's -// verdict map. They exist to be INVOKED AS SUBPROCESSES by -// run_verdict_exit_status_witness_test, because the property under test is the exit -// status of the `gunbc` process, and no in-process assertion can observe that. +// Three entries, one per arm of the driver's verdict map, INVOKED AS SUBPROCESSES by +// run_verdict_exit_status_witness_test, because the property under test is the exit status of the +// `gunbc` process, which no in-process assertion can observe. // -// Deliberately trivial. The subject is the seam, not the computation — a realistic-looking -// body would add cost that proves nothing about the boundary being crossed. +// Deliberately trivial: the subject is the seam, not the computation — a realistic body would add +// cost that proves nothing about the boundary. -data fixture_subject_note: String = "The driver seam maps a returned std.process.ProcessExit to the process exit status. Before the cli-run cut this mapping lived in one deleted function body and was asserted nowhere in the repository: it was CORRECT AND UNWITNESSED, which is why a reimplementation dropped it in silence with every instrument green. The dropped version printed ExitFailure and exited 0, so every consumer of `gunbc run` — the generated-artifact drift gate, the floor, and every witness invocation — would have reported success regardless of content. These three entries are the enrolled evidence that the boundary still holds." +// The driver seam maps a returned std.process.ProcessExit to the process exit status. Before the +// cli-run cut this mapping lived in one deleted function body, asserted nowhere: CORRECT AND +// UNWITNESSED, so a reimplementation dropped it silently with every instrument green. The dropped +// version printed ExitFailure and exited 0, so every consumer of `gunbc run` — the +// generated-artifact drift gate, the floor, every witness invocation — would have reported success +// regardless of content. These three entries are the enrolled evidence the boundary holds. func verdict_failure() -> ProcessExit { ExitFailure { @@ -25,9 +29,9 @@ func verdict_success() -> ProcessExit { ExitSuccess } -// NOT a ProcessExit. The driver must REFUSE this rather than print it and exit 0 — -// a value that carries no verdict cannot yield one, and defaulting to success is the -// same fabrication one type over. +// NOT a ProcessExit. The driver must REFUSE this rather than print it and exit 0 — a value +// carrying no verdict cannot yield one, and defaulting to success is the same fabrication one type +// over. func verdict_not_process_exit() -> Bool { true } diff --git a/dag/test/claim/run_verdict_exit_status_witness_test.dag b/dag/test/claim/run_verdict_exit_status_witness_test.dag index 68e070d961f..aa9d3a20a7f 100644 --- a/dag/test/claim/run_verdict_exit_status_witness_test.dag +++ b/dag/test/claim/run_verdict_exit_status_witness_test.dag @@ -17,7 +17,17 @@ import extdeps.gunbc // arm of the driver's verdict map. The smallest crossing specimen is the requirement plus // one; a realistic-looking entry would add cost that proves nothing about the boundary. -data run_verdict_wet_subject_note: String = "Enrolled because the property was CORRECT AND UNWITNESSED and a reimplementation therefore dropped it in silence. The cli-run cut deleted handle_run_with_options and rebuilt the seam; the first version printed the returned ExitFailure and exited 0. A planted-drift control caught it — the generated-artifact gate returned ExitFailure with code 1 naming the exact drifted file, and the driver exited 0. Every consumer of `gunbc run` would have reported green regardless of content, across the drift gate, the floor and every witness invocation, while the located diagnostic scrolled past in stdout looking like information. Neither a clean run nor a malformed-argv refusal could have detected it: both are satisfiable by a seam that always exits 0 on anything that parses. These rows are the executing evidence that the arm stays real, and they do not retire when they green — per DESIGN section 4b they become the permanent regression control for the class." +// Enrolled because the property was CORRECT AND UNWITNESSED and a reimplementation therefore +// dropped it in silence. The cli-run cut deleted handle_run_with_options and rebuilt the seam; the +// first version printed the returned ExitFailure and exited 0. A planted-drift control caught it — +// the generated-artifact gate returned ExitFailure with code 1 naming the exact drifted file, and +// the driver exited 0. Every consumer of `gunbc run` would have reported green regardless of +// content, across the drift gate, the floor and every witness invocation, while the located +// diagnostic scrolled past in stdout looking like information. Neither a clean run nor a +// malformed-argv refusal could have detected it: both are satisfiable by a seam that always exits 0 +// on anything that parses. These rows are the executing evidence that the arm stays real, and they +// do not retire when they green — per DESIGN section 4b they become the permanent regression +// control for the class. data run_verdict_wall_note: String = "The measured wall of the ORIGINAL planted-drift control was 143s, because it ran the whole generated-artifact gate over roughly seventy artifacts. These rows do not: they invoke a three-function fixture whose bodies are a constructor each. diff --git a/dag/test/claim/runner/runner_activation_wall_test.dag b/dag/test/claim/runner/runner_activation_wall_test.dag index 846f24e721c..3b30e727c31 100644 --- a/dag/test/claim/runner/runner_activation_wall_test.dag +++ b/dag/test/claim/runner/runner_activation_wall_test.dag @@ -2,23 +2,28 @@ module test.claim.runner_activation_wall data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data runner_activation_wall_doc: String = "The acceptance controls for the activation wall. Each one names a state the fleet was actually in on 2026-08-01 and asserts that it cannot yield an enable command: srv1's endpoint owned from a RETIRED slot, srv2's and srv3's from ACTIVE ones, srv4's absent behind a stale socket, and every host's placement unknown before it was read. The point of the set is that a runner may be activated only against an exact desired instance whose endpoint is held by the managed unit — not against a responsive daemon, not against a host that merely enrolled." +// The acceptance controls for the activation wall. Each names a state the fleet was actually in on +// 2026-08-01 and asserts it cannot yield an enable command: srv1's endpoint owned from a RETIRED +// slot, srv2's and srv3's from ACTIVE ones, srv4's absent behind a stale socket, and every host's +// placement unknown before it was read. A runner may be activated only against an exact desired +// instance whose endpoint is held by the managed unit — not a responsive daemon, not a host that +// merely enrolled. fn srv1_deploy_fixture() -> RunnerHostDeploy { srv4_runner_host_deploy } -// A FIXTURE MUST CONSTRUCT THE WORLD IT CLAIMS TO TEST. These witnesses assert what the ACTIVATION FOLD -// does for a fully ready host, so every input has to be a fixture -- and the instance was not one: it -// came from the production ci_cache_instance, whose intended_compile_pool is now the live -// gunbc_compile_pool_placement row rather than a bare slice name. The moment that row became the -// carrier, "a ready host activates" silently turned into a claim about THIS FLEET'S TOPOLOGY, and since -// the row is CompilePoolInRunnerSlots the fold correctly refused and the witness reds. +// A FIXTURE MUST CONSTRUCT THE WORLD IT CLAIMS TO TEST. These witnesses assert what the ACTIVATION +// FOLD does for a fully ready host, so every input has to be a fixture -- and the instance was not: +// it came from the production ci_cache_instance, whose intended_compile_pool is now the live +// gunbc_compile_pool_placement row rather than a bare slice name. Once that row became the carrier, +// "a ready host activates" silently became a claim about THIS FLEET'S TOPOLOGY, and since the row is +// CompilePoolInRunnerSlots the fold correctly refused and the witness reds. // -// Declaring the pool on the fixture restores the intended subject. It does not weaken the wall: the -// refusal paths are asserted by the negative witnesses beside these, and the live-topology answer has -// its own tripwire (test.claim.host_compile_pool live_topology_doc, and the fleet-wide refusal witness -// below) rather than being asserted here by accident. +// Declaring the pool on the fixture restores the intended subject without weakening the wall: the +// refusal paths are asserted by the negative witnesses beside these, and the live-topology answer +// has its own tripwire (test.claim.host_compile_pool live_topology_doc, and the fleet-wide refusal +// witness below) rather than being asserted here by accident. fn pool_declared_instance_fixture(host: HostIdentity) -> BuildCacheInstance { let base = ci_cache_instance(host: host) BuildCacheInstance { @@ -40,10 +45,11 @@ fn ready_instance_fixture(host: HostIdentity) -> BuildCacheInstance { } // THE LIVE ANSWER, ASSERTED ON PURPOSE RATHER THAN INHERITED BY ACCIDENT. On this fleet -// gunbc_compile_pool_placement is CompilePoolInRunnerSlots, so no instance declares a managed pool and -// activation refuses for every host. That is the designed state -- gunbc.host_compile_pool's producer -// note and gunbc.runner_activation's pool-readiness note both say so -- and it was previously invisible -// here because the fixture read the production row without anyone noticing it had become the subject. +// gunbc_compile_pool_placement is CompilePoolInRunnerSlots, so no instance declares a managed pool +// and activation refuses for every host. That is the designed state -- gunbc.host_compile_pool's +// producer note and gunbc.runner_activation's pool-readiness note both say so -- previously +// invisible here because the fixture read the production row without anyone noticing it had become +// the subject. test fn witness_live_topology_refuses_activation_fleet_wide() -> Bool { let d = srv1_deploy_fixture() let live = ci_cache_instance(host: d.host_label as HostIdentity) @@ -68,10 +74,10 @@ fn fully_verified_ready(host: HostIdentity, unit: NonEmptyStr) -> BuildCacheInst } // TAKES THE INSTANCE RATHER THAN DERIVING IT, so a witness can choose whether its subject is the -// fixture world or the live fleet. Without this split the two are indistinguishable at the call site: -// the live-topology witness below was written against fully_verified_ready and silently received the -// POOL-DECLARED fixture, so it asserted a refusal that could never happen and returned false. Caught by -// running it -- an assertion whose subject is chosen by a helper two calls away is exactly the kind that +// fixture world or the live fleet. Without this split the two are indistinguishable at the call +// site: the live-topology witness below was written against fully_verified_ready and silently +// received the POOL-DECLARED fixture, so it asserted a refusal that could never happen and returned +// false. Caught by running it -- an assertion whose subject is chosen by a helper two calls away // reads correct and measures something else. fn fully_verified_ready_for(instance: BuildCacheInstance, unit: NonEmptyStr) -> BuildCacheInstanceReady { BuildCacheInstanceReady { @@ -207,7 +213,10 @@ test fn witness_unready_compile_pool_refuses_even_with_a_managed_owner() -> Bool yields_command(outcome: declared_not_observed) == false } -data materialization_does_not_activate_doc: String = "The split's own control. Materializing a slot must remain possible on nothing more than host enrollment — that is the whole point of separating it — while activation must not. If this witness ever fails because the installer command started demanding a readiness receipt, the split has collapsed in the other direction and materialization has become impossible to perform first, which would make the ordering unsatisfiable rather than enforced." +// The split's own control. Materializing a slot must remain possible on host enrollment alone — +// the point of separating it — while activation must not. If this witness fails because the +// installer command started demanding a readiness receipt, the split has collapsed the other way: +// materialization cannot be performed first, and the ordering is unsatisfiable rather than enforced. test fn witness_materializing_a_slot_does_not_activate_it() -> Bool { let d = srv1_deploy_fixture() @@ -223,7 +232,13 @@ test fn witness_materializing_a_slot_does_not_activate_it() -> Bool { yields_command(outcome: install) && (yields_command(outcome: activate) == false) } -data pool_receipt_binding_doc: String = "The controls review 46581 forced. The cache receipt was bound to the activation two ways -- host and intended unit -- and the pool receipt beside it was gated on two Booleans alone, so a pool observed on a DIFFERENT host, or a correctly-observed slice with some other name, admitted activation. Both are asserted here rather than only the host case, because they fail for different reasons: one receipt is about the wrong machine, the other is about the wrong cgroup on the right machine, and a wall that caught only the first would still activate a runner whose compiles are charged outside the intended pool." +// The controls review 46581 forced. The cache receipt was bound to the activation two ways -- host +// and intended unit -- while the pool receipt beside it was gated on two Booleans alone, so a pool +// observed on a DIFFERENT host, or a correctly-observed slice with some other name, admitted +// activation. Both are asserted, not only the host case, because they fail for different reasons: +// one receipt is about the wrong machine, the other about the wrong cgroup on the right machine, +// and a wall catching only the first would still activate a runner whose compiles are charged +// outside the intended pool. test fn witness_a_pool_receipt_from_another_host_is_refused() -> Bool { let d = srv1_deploy_fixture() diff --git a/dag/test/claim/runner/runner_host_deploy_witness_test.dag b/dag/test/claim/runner/runner_host_deploy_witness_test.dag index 543b59de763..f9956fbfe7b 100644 --- a/dag/test/claim/runner/runner_host_deploy_witness_test.dag +++ b/dag/test/claim/runner/runner_host_deploy_witness_test.dag @@ -143,7 +143,11 @@ data unenrolled_host_fixture: RunnerHostDeploy = RunnerHostDeploy { runner_count: 5, } -data witness_enrollment_wall_note: String = "The srv4 host-convergence OOM class, made unwritable. A host absent from fleet_intent_known_hosts yields an admission whose refusal arm carries NO command, so neither builder can hand back something runnable. The fixture is srv9 — a plausible next fleet host that nobody has enrolled — which is exactly the shape the incident took: real hardware, real ssh target, no intent row, and therefore no RAM figure for the conservation wall to check slot caps against." +// The srv4 host-convergence OOM class, made unwritable. A host absent from fleet_intent_known_hosts +// yields an admission whose refusal arm carries NO command, so neither builder can hand back +// something runnable. The fixture is srv9 — a plausible next fleet host that nobody has enrolled — +// which is exactly the shape the incident took: real hardware, real ssh target, no intent row, and +// therefore no RAM figure for the conservation wall to check slot caps against. test fn unenrolled_host_cannot_produce_an_installer_command() -> Bool { match runner_host_installer_command( @@ -175,7 +179,10 @@ test fn enrolled_host_still_admits() -> Bool { } } -data witness_admission_red_control_note: String = "Discriminating RED control on the PATH-shadow precedent: the admission-blind sketch (what this module was before the wall) DOES hand back a runnable command for the unenrolled host, the gate rejects it, and the authority's refusal passes the same gate. The perturbation is independent of the property checked, so the conjunct cannot pass tautologically." +// Discriminating RED control on the PATH-shadow precedent: the admission-blind sketch (what this +// module was before the wall) DOES hand back a runnable command for the unenrolled host, the gate +// rejects it, and the authority's refusal passes the same gate. The perturbation is independent of +// the property checked, so the conjunct cannot pass tautologically. test fn red_control_admission_blind_builder_rejected_by_gate() -> Bool { let adm = admit_runner_host(deploy: unenrolled_host_fixture) @@ -189,7 +196,12 @@ test fn red_control_admission_blind_builder_rejected_by_gate() -> Bool { && runner_host_admission_gate_accepts(outcome: authority, admission: adm) } -data activation_moved_note: String = "runner_enable_command was deleted with the materialization/activation split; these rows now drive runner_activate_command through a readiness receipt. The receipt below is a fixture, and the enrollment assertions it supports are unchanged: an unenrolled host still refuses, and the refusal still carries no command. What changed is that enrollment alone is no longer sufficient, which is the whole point of the split — so these witnesses now assert the WEAKER half of a stronger wall, and the wall's own controls live in test.claim.runner_activation_wall." +// runner_enable_command was deleted with the materialization/activation split; these rows now drive +// runner_activate_command through a readiness receipt. The receipt below is a fixture, and the +// enrollment assertions it supports are unchanged: an unenrolled host still refuses, and the +// refusal still carries no command. What changed is that enrollment alone is no longer sufficient, +// which is the whole point of the split — so these witnesses now assert the WEAKER half of a +// stronger wall, and the wall's own controls live in test.claim.runner_activation_wall. // DEFINED LOCALLY RATHER THAN SHARED WITH runner_activation_wall_test, which carries the same fixture // and the full reasoning for it. A cross-test-module reference resolves under the floor -- it prepares diff --git a/dag/test/claim/runner/runner_placement_witness_test.dag b/dag/test/claim/runner/runner_placement_witness_test.dag index 33c5b943b8b..01daf63c3bd 100644 --- a/dag/test/claim/runner/runner_placement_witness_test.dag +++ b/dag/test/claim/runner/runner_placement_witness_test.dag @@ -186,12 +186,12 @@ test fn the_live_manifest_json_reports_incompleteness_and_names_the_refused_host // OVERSUBSCRIBED host from an UNCHARGEABLE one, and gunbc.ci_runner_placement previously projected // both to false through host_allocation_conserves and rendered one string for the pair: "host // allocation over-committed ... exceeds host RAM". Both paths refuse, so the collapse read as -// cautious -- but the two have OPPOSITE remedies. Over-committed means take capacity away; -// unchargeable means go and measure the resident. Reporting the first when the second is true sends -// the reader to shrink a pool that was never the problem. +// cautious -- but the two have OPPOSITE remedies: over-committed means take capacity away; +// unchargeable means go and measure the resident. Reporting the first when the second is true +// sends the reader to shrink a pool that was never the problem. // A witness asserting only that an unmeasured claim refuses would have passed against the defect, -// because the defective code also refused. The pair is what discriminates: each arm must produce -// its OWN cause and must NOT produce the other's. +// because the defective code also refused. The pair discriminates: each arm must produce its OWN +// cause and NOT the other's. fn control_plane_unmeasured_placement() -> FabricControlPlanePlacement { ControlPlaneStaticPinned { host: operator_host_srv1, @@ -233,12 +233,12 @@ test fn an_oversized_control_plane_reports_over_commitment_and_not_unmeasured() } // AN UNPLACED CONTROL PLANE ADDS NO REFUSAL OF ITS OWN, which is what this row has always meant. -// It used to say so by asserting the whole fleet reason is empty, and that stopped being a -// statement about the control plane the moment per-host refusal let a host decline for an unrelated -// cause: srv2 now refuses because its session reservation is unestablished, under every placement, -// so the old form reds on a fact it was never testing. The claim is restated RELATIVELY -- the -// unplaced arm refuses exactly what the baseline already refuses -- which isolates the control -// plane's contribution instead of requiring the rest of the fleet to be clean. +// It used to assert the whole fleet reason is empty, which stopped being a statement about the +// control plane once per-host refusal let a host decline for an unrelated cause: srv2 now refuses +// because its session reservation is unestablished, under every placement, so the old form reds +// on a fact it never tested. The claim is restated RELATIVELY -- the unplaced arm refuses exactly +// what the baseline already refuses -- isolating the control plane's contribution instead of +// requiring the rest of the fleet to be clean. test fn the_unplaced_control_plane_adds_no_refusal_of_its_own() -> Bool { let unplaced = plan_reason_under(p: ControlPlaneUnplaced) !unplaced.contains("unchargeable") @@ -247,24 +247,24 @@ test fn the_unplaced_control_plane_adds_no_refusal_of_its_own() -> Bool { } // THIS IS THE CONTROL, AND IT IS WRITTEN AS AN INEQUALITY ON PURPOSE. The two witnesses above each -// assert a substring, and a substring assertion can pass for the wrong reason -- if some unrelated -// edit made every refusal recite both words, both would still be green. What the collapsed code -// actually did was emit ONE string for two causes, so the property that falsifies it directly is -// that the two causes are DISTINGUISHABLE AT ALL. Under host_allocation_conserves these two reasons -// were byte-identical and this witness returns false; it is the red that the pair above cannot be -// green without, and it stays enrolled rather than retiring now that the arm is split (DESIGN 4b: -// a climb dissolves the production machinery it obsoletes, never the evidence that the rung is real). +// assert a substring, which can pass for the wrong reason -- if an unrelated edit made every +// refusal recite both words, both would still be green. The collapsed code emitted ONE string for +// two causes, so the property that falsifies it directly is that the two causes are +// DISTINGUISHABLE AT ALL. Under host_allocation_conserves these two reasons were byte-identical +// and this witness returns false; it is the red the pair above cannot be green without, and it +// stays enrolled now that the arm is split (DESIGN 4b: a climb dissolves the production machinery +// it obsoletes, never the evidence that the rung is real). test fn the_two_control_plane_refusals_do_not_share_one_reason() -> Bool { plan_reason_under(p: control_plane_unmeasured_placement()) != plan_reason_under(p: control_plane_oversized_placement()) } -// THE DIRECT RED FOR THE DEFECT THIS CARRIER REPLACES. On the shape that preceded it, srv2's +// THE DIRECT RED FOR THE DEFECT THIS CARRIER REPLACES. On the preceding shape, srv2's // unestablished session reservation set one fleet-level unsound_reason and runner_deployment_plan -// discarded EVERY host that had derived correctly -- 44 witnesses across six files went red, nine of -// them existing only to verify srv3. This asserts the two facts together: srv2 refuses for its own -// reason, and srv3 derives ANYWAY. On the old carrier the second half was unwritable, because there -// was no derived srv3 left in the result to ask about. +// discarded EVERY host that had derived correctly -- 44 witnesses across six files went red, nine +// existing only to verify srv3. This asserts both facts: srv2 refuses for its own reason, and srv3 +// derives ANYWAY. On the old carrier the second half was unwritable, because no derived srv3 was +// left in the result to ask about. test fn a_refused_host_does_not_erase_a_derived_one() -> Bool { let srv2_refused = match runner_host_deployment_for(p: live_plan(), host: operator_host_srv2) { HostRunnerDeploymentRefused { refusal: r } => diff --git a/dag/test/claim/runner/runner_slot_allocation_witness_test.dag b/dag/test/claim/runner/runner_slot_allocation_witness_test.dag index 278d7675af9..867e4c1fd63 100644 --- a/dag/test/claim/runner/runner_slot_allocation_witness_test.dag +++ b/dag/test/claim/runner/runner_slot_allocation_witness_test.dag @@ -76,7 +76,20 @@ test fn runner_slot_allocation_committed_hosts_cover_the_fleet_exactly_once() -> && committed_allocation_for(host: "srv-does-not-exist") == 0 } -data widths_are_pinned_on_both_axes_note: String = "MEMORY ADMISSIONS AND COMMITTED WIDTHS ARE PINNED SEPARATELY, AND AS OF 2026-08-23 THEY FINALLY DISAGREE. The two rows below asserted the same four numbers twice for this module's entire history, because memory bound every host and the minimum had nothing else to choose from. That made the separation look like ceremony. It was not: the 2026-08-22 DIMM upgrade plus the CPU axis separated them, and the host-keyed session reservation then separated them further -- memory admission now reads 25 on srv1, 29 on srv3 and srv4, and NO WIDTH AT ALL on srv2, whose session denominator is unestablished so its axis is AxisUnmeasured rather than a number, while committed width is 21/5/21/21, and a single row pinning only one of them would now be silently blind to the other.\n\nWHICH IS THE POINT THIS PAIR WAS MAKING ALL ALONG. Asserting only committed width would miss a reintroduced disk pin or a memory regression hidden behind a CPU ceiling; asserting only memory admission would miss provisioning that skips the apply gate. srv4's historical disk row-pin stays retired and disk binding stays at apply-time gunbc.runner_lifecycle runner_width_disk_preflight." +// MEMORY ADMISSIONS AND COMMITTED WIDTHS ARE PINNED SEPARATELY, AND AS OF 2026-08-23 THEY FINALLY +// DISAGREE. The two rows below asserted the same four numbers twice for this module's entire +// history, because memory bound every host and the minimum had nothing else to choose from. That +// made the separation look like ceremony. It was not: the 2026-08-22 DIMM upgrade plus the CPU axis +// separated them, and the host-keyed session reservation then separated them further -- memory +// admission now reads 25 on srv1, 29 on srv3 and srv4, and NO WIDTH AT ALL on srv2, whose session +// denominator is unestablished so its axis is AxisUnmeasured rather than a number, while committed +// width is 21/5/21/21, and a single row pinning only one of them would now be silently blind to the +// other. +// +// WHICH IS THE POINT THIS PAIR WAS MAKING ALL ALONG. Asserting only committed width would miss a +// reintroduced disk pin or a memory regression hidden behind a CPU ceiling; asserting only memory +// admission would miss provisioning that skips the apply gate. srv4's historical disk row-pin stays +// retired and disk binding stays at apply-time gunbc.runner_lifecycle runner_width_disk_preflight. // srv1 MOVED 27 -> 25 AND srv2 NO LONGER STATES A MEMORY ADMISSION AT ALL. The first is the // synchronization of a derived literal after its input changed: srv1's ungrounded 20 GiB fleet-wide @@ -170,13 +183,32 @@ test fn runner_slot_allocation_minimum_viable_armed_budget_is_12_gib() -> Bool { byte_size_count(b: gunbc_floor_minimum_viable_armed_budget_bytes()) == byte_size_count(b: byte_size(12884901888)) } -data srv2_03_effective_cap_drift_note: String = "SUBJECT B (effective cap on srv2-03): binds 16GiB/15GiB and the declaration now MATCHES it, so the 2GiB drift this subject was written for is dissolved (gunbc.runner_slot_allocation gunbc_srv2_03_drift_dissolved_by_ruling_note). The witness below asserts the ABSENCE of drift; the readback-refusal predicate keeps its discriminating input from gunbc_synthetic_drifted_cap_observation instead, deliberately synthetic so no convergence can green it. Dissolve-on: post-apply readback replaces gunbc_srv2_03_effective_cap_observation." - -data declared_row_floor_peak_derivation_note: String = "SUBJECT A (declared row): 16GiB/15GiB derives from the 2026-08-17 floor-peak ruling superseding the 2026-08-05 calibration (gunbc_runner_slot_memory_max_ruling_note), NOT from srv2-03 live readback — that the two now coincide is a coincidence recorded as one in that ruling. This witness pins only the declared constants." - -data srv2_03_readback_refusal_note: String = "SUBJECT C (refusal): gunbc_runner_slot_allocation_refuses_effective_readback_reconciliation is the structural predicate — effective readback must not become declaration authority when drift exists. Its discriminating input is now gunbc_synthetic_drifted_cap_observation, srv2-03 having stopped drifting; a synthetic fixture is used precisely so that a future converge cannot silently retire this predicate's only witness." - -data srv2_03_converge_floor_fit_note: String = "SUBJECT D (converge consequence): ANSWERED, not pending. Modeled-budget compliance under the superseded 14GiB/13GiB row is now MEASURED and it failed — an uncensored 15509315584-byte floor peak above that max, plus srv1 pinned at exactly 13.00GiB with 829 and 44803 memory.high events once it was actually converged there. The floor cgroup leaf events at T5 entry remain zero as the baseline they always were, and srv2-03 has no envelope left to enforce because the declaration moved to meet it. Superseded detail retained: converge would first enforce the modeled envelope against the CI floor consumer (gunbc_srv2_03_converge_floor_fit_note). No OOM outcome and no floor byte figure are asserted." +// SUBJECT B (effective cap on srv2-03): binds 16GiB/15GiB and the declaration now MATCHES it, so +// the 2GiB drift this subject was written for is dissolved (gunbc.runner_slot_allocation +// gunbc_srv2_03_drift_dissolved_by_ruling_note). The witness below asserts the ABSENCE of drift; +// the readback-refusal predicate keeps its discriminating input from +// gunbc_synthetic_drifted_cap_observation instead, deliberately synthetic so no convergence can +// green it. Dissolve-on: post-apply readback replaces gunbc_srv2_03_effective_cap_observation. + +// SUBJECT A (declared row): 16GiB/15GiB derives from the 2026-08-17 floor-peak ruling superseding +// the 2026-08-05 calibration (gunbc_runner_slot_memory_max_ruling_note), NOT from srv2-03 live +// readback — that the two now coincide is a coincidence recorded as one in that ruling. This +// witness pins only the declared constants. + +// SUBJECT C (refusal): gunbc_runner_slot_allocation_refuses_effective_readback_reconciliation is +// the structural predicate — effective readback must not become declaration authority when drift +// exists. Its discriminating input is now gunbc_synthetic_drifted_cap_observation, srv2-03 having +// stopped drifting; a synthetic fixture is used precisely so that a future converge cannot silently +// retire this predicate's only witness. + +// SUBJECT D (converge consequence): ANSWERED, not pending. Modeled-budget compliance under the +// superseded 14GiB/13GiB row is now MEASURED and it failed — an uncensored 15509315584-byte floor +// peak above that max, plus srv1 pinned at exactly 13.00GiB with 829 and 44803 memory.high events +// once it was actually converged there. The floor cgroup leaf events at T5 entry remain zero as the +// baseline they always were, and srv2-03 has no envelope left to enforce because the declaration +// moved to meet it. Superseded detail retained: converge would first enforce the modeled envelope +// against the CI floor consumer (gunbc_srv2_03_converge_floor_fit_note). No OOM outcome and no +// floor byte figure are asserted. test fn witness_declared_row_pins_16_15_gib_from_floor_peak_ruling() -> Bool { byte_size_count(b: gunbc_runner_slot_desired().memory_max) == byte_size_count(b: byte_size(17179869184)) diff --git a/dag/test/claim/runner/runner_slot_provision_witness_test.dag b/dag/test/claim/runner/runner_slot_provision_witness_test.dag index dc112d64140..c2ffd5ea954 100644 --- a/dag/test/claim/runner/runner_slot_provision_witness_test.dag +++ b/dag/test/claim/runner/runner_slot_provision_witness_test.dag @@ -220,7 +220,11 @@ test fn an_authored_count_enumerates_exactly_that_many_indexed_names() -> Bool { // --- converge seam: the refusal must be real, not decorative ---------------------------------- -data converge_seam_witness_note: String = "THESE FOUR ROWS EXIST BECAUSE THE REFUSAL ARM IS THE ENTIRE POINT OF THE SEAM. An observation type with an Unobserved arm that nothing can drive is a decoration -- permanently green by construction and worse than absent, because it gets cited as coverage. The fixture below authors the unobserved state directly, so the arm has a RED that a fixture may produce, and the planned control beside it stops the refusal being satisfied by refusing always." +// THESE FOUR ROWS EXIST BECAUSE THE REFUSAL ARM IS THE ENTIRE POINT OF THE SEAM. An observation +// type with an Unobserved arm that nothing can drive is a decoration -- permanently green by +// construction and worse than absent, because it gets cited as coverage. The fixture below authors +// the unobserved state directly, so the arm has a RED that a fixture may produce, and the planned +// control beside it stops the refusal being satisfied by refusing always. data unobserved_fixture: RunnerSlotObservation = RunnerSlotsUnobserved { reason: "FIXTURE: the base-directory listing refused" as NonEmptyStr, @@ -316,7 +320,6 @@ test fn no_deploy_row_out_commits_the_memory_budget() -> Bool { ) } - // --- the fabric carve reaches the provisioning target -------------------------------------------- // THE DESIRED SET MUST NOT CONTAIN srv3-06, AND THIS IS THE ROW THAT SAYS SO. diff --git a/dag/test/claim/runtime_rust_seed_bootstrap_sync_witness_test.dag b/dag/test/claim/runtime_rust_seed_bootstrap_sync_witness_test.dag index 7fe72b245d7..f4196dc254d 100644 --- a/dag/test/claim/runtime_rust_seed_bootstrap_sync_witness_test.dag +++ b/dag/test/claim/runtime_rust_seed_bootstrap_sync_witness_test.dag @@ -6,7 +6,17 @@ import v2.std.live_tree { LiveTreeDisposition, ReadsLiveTree } data live_tree_disposition: LiveTreeDisposition = ReadsLiveTree -data runtime_rust_seed_bootstrap_sync_witness_note: String = "Regression control for a two-hop bootstrap-lag class: `regen_stage0 --emit-fresh` renders v1_rt.rs by running the CURRENTLY-COMPILED `rt_hash_ops()`, which is compiled from the checked-in seed src/v1/stage0/src/v1_compiler_runtime_rust.rs — not derived live from src/v1/runtime_rust.dag at emit time. Editing the .dag authority alone (as happened for `pub fn obs_human_elapsed`, added so `crate::v1_rt::obs_human_elapsed` in cli_run.rs would resolve — E0425 previously) updates the fresh-emit projection of the seed file but leaves the CHECKED-IN seed, and therefore the compiled binary's output, stale. This witness pins the three-file agreement directly: the .dag authority, its checked-in Rust-translation seed, and the final generated runtime all name the same functions. A regression that repeats this class (author edits runtime_rust.dag, forgets to sync+recompile the seed) reds here without requiring a live regen_stage0 run." +// Regression control for a two-hop bootstrap-lag class: `regen_stage0 --emit-fresh` renders +// v1_rt.rs by running the CURRENTLY-COMPILED `rt_hash_ops()`, which is compiled from the checked-in +// seed src/v1/stage0/src/v1_compiler_runtime_rust.rs — not derived live from +// src/v1/runtime_rust.dag at emit time. Editing the .dag authority alone (as happened for `pub fn +// obs_human_elapsed`, added so `crate::v1_rt::obs_human_elapsed` in cli_run.rs would resolve — +// E0425 previously) updates the fresh-emit projection of the seed file but leaves the CHECKED-IN +// seed, and therefore the compiled binary's output, stale. This witness pins the three-file +// agreement directly: the .dag authority, its checked-in Rust-translation seed, and the final +// generated runtime all name the same functions. A regression that repeats this class (author edits +// runtime_rust.dag, forgets to sync+recompile the seed) reds here without requiring a live +// regen_stage0 run. data runtime_rust_dag_path: String = "src/v1/runtime_rust.dag" data runtime_rust_seed_path: String = "src/v1/stage0/src/v1_compiler_runtime_rust.rs" diff --git a/dag/test/claim/salience_witness_test.dag b/dag/test/claim/salience_witness_test.dag index 4432db8bf95..03ff967529d 100644 --- a/dag/test/claim/salience_witness_test.dag +++ b/dag/test/claim/salience_witness_test.dag @@ -20,7 +20,13 @@ import extdeps.languages.css.values { css_px, CssLength, Rem } data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data salience_witness_note: String = "S1 selective-spectacle receipts (operator recalibration 2026-08-02), each a decided law with its RED control: the budget table grants energy to focus only; a second ordinary focal subject in one region is a typed refusal while Critical coexists; emission refuses for the wrong role, outside the envelope, and without a non-emission discriminator (so reduced-motion/no-emission renderings keep every distinction by construction); attraction is bounded and borrows the register's one spring rather than minting a second; and the principles carrier holds the revised thesis with the three new laws carried by real salience declarations." +// S1 selective-spectacle receipts (operator recalibration 2026-08-02), each a decided law with its +// RED control: the budget table grants energy to focus only; a second ordinary focal subject in one +// region is a typed refusal while Critical coexists; emission refuses for the wrong role, outside +// the envelope, and without a non-emission discriminator (so reduced-motion/no-emission renderings +// keep every distinction by construction); attraction is bounded and borrows the register's one +// spring rather than minting a second; and the principles carrier holds the revised thesis with the +// three new laws carried by real salience declarations. fn fx_emission_ok() -> EmissionSpec { EmissionSpec { @@ -145,7 +151,14 @@ test fn witness_red_viewport_scale_attraction_is_outside_the_envelope() -> Bool !attraction_envelope(f: evasive) } -// THE DISCRIMINATING PART IS THE NUMBER, NOT THE SIZE. Both controls below are authored to satisfy EVERY numeric constraint in their envelope and differ from an accepted specimen ONLY in unit, so they cannot pass by being small and cannot fail by being large — the sole reason either refuses is that a rem magnitude is not comparable to a px bound. A corona of 40rem satisfies 40 <= 48 and 40 > 4 while denoting roughly 640px, and an attraction field of 12rem travel inside a 150rem radius satisfies every one of the four numeric bounds; before the unit check both were admitted. The emission arm additionally pins WHICH refusal fires: EmissionUnitNotComparable carrying both offending unit tokens, never EmissionOutsideEnvelope, whose corona_radius_px field would report a rem magnitude under a px name. +// THE DISCRIMINATING PART IS THE NUMBER, NOT THE SIZE. Both controls below satisfy EVERY numeric +// constraint in their envelope and differ from an accepted specimen ONLY in unit, so they cannot +// pass by being small nor fail by being large — the sole reason either refuses is that a rem +// magnitude is not comparable to a px bound. A corona of 40rem satisfies 40 <= 48 and 40 > 4 while +// denoting roughly 640px; an attraction field of 12rem travel inside a 150rem radius satisfies all +// four numeric bounds; before the unit check both were admitted. The emission arm additionally pins +// WHICH refusal fires: EmissionUnitNotComparable carrying both offending unit tokens, never +// EmissionOutsideEnvelope, whose corona_radius_px field would report a rem magnitude under a px name. test fn witness_red_rem_emission_is_not_comparable_to_a_px_bound() -> Bool { let rem_spec = EmissionSpec { core_radius: CssLength { n: 4, unit: Rem }, diff --git a/dag/test/claim/scaffold_disposition_census_fixture_witness_test.dag b/dag/test/claim/scaffold_disposition_census_fixture_witness_test.dag index da03a175f8f..86c1d57e6cb 100644 --- a/dag/test/claim/scaffold_disposition_census_fixture_witness_test.dag +++ b/dag/test/claim/scaffold_disposition_census_fixture_witness_test.dag @@ -16,7 +16,17 @@ import test.fixture.scaffold_disposition_census.expected_classification { ScaffoldDecodeRefused, } -data scaffold_disposition_census_fixture_witness_note: String = "Fixture-and-oracle witness for the exact scaffold disposition census (adhoc-220d7fd9-374, dashboard node). Proves only what is decidable TODAY, without the blocked exact constructor/variant-value identity prerequisite (owned elsewhere): the fixture pool and its independently authored oracle agree by identity join in both directions (not count equality alone, per DESIGN 'completeness is an identity join'), the oracle is duplicate-free and exhausts all four states with Terminal kept distinct from ScaffoldDecodeRefused, kind-based exclusion of fn declarations is real, and the two identity-adversarial controls (ambiguous / missing subject identity) genuinely exhibit the property they claim. It does NOT assert that a census classifies each specimen into its expected state -- that consumer does not exist yet; this witness proves the fixtures and oracle it will consume are well-formed and non-vacuous, so the oracle counts are a true oracle rather than a measurement copied from the tree." +// Fixture-and-oracle witness for the exact scaffold disposition census (adhoc-220d7fd9-374, +// dashboard node). Proves only what is decidable TODAY, without the blocked exact +// constructor/variant-value identity prerequisite (owned elsewhere): the fixture pool and its +// independently authored oracle agree by identity join in both directions (not count equality +// alone, per DESIGN 'completeness is an identity join'), the oracle is duplicate-free and exhausts +// all four states with Terminal kept distinct from ScaffoldDecodeRefused, kind-based exclusion of +// fn declarations is real, and the two identity-adversarial controls (ambiguous / missing subject +// identity) genuinely exhibit the property they claim. It does NOT assert that a census classifies +// each specimen into its expected state -- that consumer does not exist yet; this witness proves +// the fixtures and oracle it will consume are well-formed and non-vacuous, so the oracle counts are +// a true oracle rather than a measurement copied from the tree. data scaffold_disposition_census_pool_facts: List = decl_facts(pool_roots: scaffold_disposition_census_fixture_pool_roots) @@ -74,7 +84,9 @@ test fn scaffold_disposition_census_oracle_names_no_extra_declarations() -> Bool ) } -data scaffold_disposition_census_deliberately_incomplete_oracle_names_note: String = "RED control: the identity join above is not vacuously true because both sides happen to be large -- a smaller, deliberately incomplete name list fails the exact same containment check the real oracle passes, proving the check discriminates rather than trivially succeeding." +// RED control: the identity join above is not vacuously true because both sides happen to be large +// -- a smaller, deliberately incomplete name list fails the exact same containment check the real +// oracle passes, proving the check discriminates rather than trivially succeeding. data scaffold_disposition_census_deliberately_incomplete_oracle_names: List = [ "test.fixture.scaffold_disposition_census.pool.specimens.plain_int_specimen" diff --git a/dag/test/claim/sccache_local_content_verified_on_read_test.dag b/dag/test/claim/sccache_local_content_verified_on_read_test.dag index 3f33d34a6c1..9c2ced15e3a 100644 --- a/dag/test/claim/sccache_local_content_verified_on_read_test.dag +++ b/dag/test/claim/sccache_local_content_verified_on_read_test.dag @@ -2,7 +2,17 @@ module test.claim.sccache_local_content_verified_on_read data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data sccache_content_verified_on_read_doc: String = "sccache's local-disk backend (src/cache/disk.rs DiskCache::get/get_raw) reads whatever bytes sit under the key's path and returns them as a Cache::Hit with no hash/checksum/size check against the key or a stored digest; WriteThenRename atomicity covers only the write path. The prior declared row said content_verified_on_read: true, which CI falsified directly: runs 29855292758 et al served a zero-byte artifact on a reported sccache cache hit. This witness is discriminating on that declared fact — perturbing extdeps.cache.sccache.sccache_local_facts.key_derivation.content_verified_on_read back to true turns witness_sccache_local_not_content_verified_on_read RED; the corpus-level, application-side catch for the resulting corruption (build_artifact_corruption_probe_holds, tools/build_step.dag) is a SEPARATE mechanism this witness does not duplicate — it targets only the declared-vs-effective gap in the catalog row itself." +// sccache's local-disk backend (src/cache/disk.rs DiskCache::get/get_raw) reads whatever bytes sit +// under the key's path and returns them as a Cache::Hit with no hash/checksum/size check against +// the key or a stored digest; WriteThenRename atomicity covers only the write path. The prior +// declared row said content_verified_on_read: true, which CI falsified directly: runs 29855292758 +// et al served a zero-byte artifact on a reported sccache cache hit. This witness is discriminating +// on that declared fact — perturbing +// extdeps.cache.sccache.sccache_local_facts.key_derivation.content_verified_on_read back to true +// turns witness_sccache_local_not_content_verified_on_read RED; the corpus-level, application-side +// catch for the resulting corruption (build_artifact_corruption_probe_holds, tools/build_step.dag) +// is a SEPARATE mechanism this witness does not duplicate — it targets only the +// declared-vs-effective gap in the catalog row itself. test fn witness_sccache_local_not_content_verified_on_read() -> Bool { !sccache_local_facts.key_derivation.content_verified_on_read diff --git a/dag/test/claim/sccache_pin_witness_test.dag b/dag/test/claim/sccache_pin_witness_test.dag index c74ded28879..2bcc8759c10 100644 --- a/dag/test/claim/sccache_pin_witness_test.dag +++ b/dag/test/claim/sccache_pin_witness_test.dag @@ -44,7 +44,11 @@ data sccache_x86_64_artifact: SccacheBinaryArtifact = SccacheBinaryArtifact { data sccache_aarch64_pin: SubjectProjectedPin = sccache_binary_artifact_pin(artifact: sccache_aarch64_artifact) -data sccache_pin_grain_family_note: String = "Discriminating witness for feature:pin-artifact-grain. SubjectProjectedPin pins ONE cited musl tarball per row with no restated expected_identity field — identity projected via sha256_digest_content_hash bridge (review 44999). RED CONTROL reconcile_bridge_projects_identity_and_version fails if subject_projected_pin_as_pin does not project both ContentHash and VersionIdentity onto Pin." +// Discriminating witness for feature:pin-artifact-grain. SubjectProjectedPin +// pins ONE cited musl tarball per row with no restated expected_identity field — identity projected +// via sha256_digest_content_hash bridge (review 44999). RED CONTROL +// reconcile_bridge_projects_identity_and_version fails if subject_projected_pin_as_pin does not +// project both ContentHash and VersionIdentity onto Pin. test fn sccache_pin_subject_carries_release_version() -> Bool { sccache_aarch64_artifact.binary_release.version == sccache_release_0_15_0.version diff --git a/dag/test/claim/scm/scm_agentic_stress_witness_test.dag b/dag/test/claim/scm/scm_agentic_stress_witness_test.dag index dcc5868615b..bedf733e669 100644 --- a/dag/test/claim/scm/scm_agentic_stress_witness_test.dag +++ b/dag/test/claim/scm/scm_agentic_stress_witness_test.dag @@ -46,7 +46,15 @@ import v2.std.live_tree { LiveTreeDisposition, SubstrateInputsOnly } data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data stress_note: String = "Stressing the profile toward agent-driven development, because the human-authored numbers load the wrong axis. Human baseline: 200 object reads and 20 writes per user-month. Agent-autonomous baseline below: 2,000,000 logical NODE reads and 200,000 node writes per user-month -- four orders of magnitude, which is roughly one agent working continuously at a few thousand node reads an hour, and still conservative for a fleet of agents. Storage and egress are also raised (500 MB held, 2 GB moved) but only by single-digit multiples, because dedup flattens what agents store far more than it flattens what they touch. The finding this witness pins: at these rates operations stop being a rounding error and become the entire bill on request-metered vendors, which INVERTS the provider ranking computed on the human profile." +// Stressing the profile toward agent-driven development, because the human-authored numbers load +// the wrong axis. Human baseline: 200 object reads and 20 writes per user-month. Agent-autonomous +// baseline below: 2,000,000 logical NODE reads and 200,000 node writes per user-month -- four +// orders of magnitude, which is roughly one agent working continuously at a few thousand node reads +// an hour, and still conservative for a fleet of agents. Storage and egress are also raised (500 MB +// held, 2 GB moved) but only by single-digit multiples, because dedup flattens what agents store +// far more than it flattens what they touch. The finding this witness pins: at these rates +// operations stop being a rounding error and become the entire bill on request-metered vendors, +// which INVERTS the provider ranking computed on the human profile. data stress_basis_assumption: ByteBasisAssumption = BasisAssumed { basis: DecimalGigabyte, diff --git a/dag/test/claim/scm/scm_log_witness_test.dag b/dag/test/claim/scm/scm_log_witness_test.dag index 06e4b9dd79a..06e5cc6491f 100644 --- a/dag/test/claim/scm/scm_log_witness_test.dag +++ b/dag/test/claim/scm/scm_log_witness_test.dag @@ -153,9 +153,9 @@ test fn row_references_are_the_commits_intrinsic_keys() -> Bool { // THE DUPLICATE-ROOT CASE, WHICH IS WHY THE REFERENCE IS DERIVED FROM POSITION RATHER THAN BY // LOOKING THE ROOT UP. repository_envelope's header states that two commits may share a root and // differ only in message -- they name the same program, "which is the point of content addressing -// and not a collision". An identity lookup answers the FIRST match, so both rows would advertise the -// first row's reference and the second commit would be unreachable through the identifier its own -// row carries. +// and not a collision". An identity lookup answers the FIRST match, so both rows would advertise +// the first row's reference and the second commit would be unreachable through its own row's +// identifier. test fn two_commits_sharing_a_root_still_get_distinct_references() -> Bool { let a = log_witness_store_one(store: empty_store(), name: ^shared) let first = log_witness_mint(repo: log_witness_empty(store: a.store), root: a.identity, message: "relabelled once", parent: none) diff --git a/dag/test/claim/scm/scm_provider_matrix_witness_test.dag b/dag/test/claim/scm/scm_provider_matrix_witness_test.dag index 04124a7741a..0ad1a319739 100644 --- a/dag/test/claim/scm/scm_provider_matrix_witness_test.dag +++ b/dag/test/claim/scm/scm_provider_matrix_witness_test.dag @@ -66,7 +66,11 @@ import v2.std.live_tree { LiveTreeDisposition, SubstrateInputsOnly } data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -// The provider x magnitude matrix. One profile (100 MB stored, 500 MB egress, 200 reads, 20 writes per user-month) scaled to 10k / 100k / 1M users against every provider whose storage AND egress AND request pricing is cited, with progressive tier application so the crossings are real: at 1M users the workload holds 100 TB (past the 50 TB storage step) and moves 500 TB a month (past all three egress steps). +// The provider x magnitude matrix: one profile (100 MB stored, 500 MB egress, 200 reads, 20 writes +// per user-month) scaled to 10k / 100k / 1M users against every provider whose storage AND egress +// AND request pricing is cited, with progressive tier application so the crossings are real: at 1M +// users the workload holds 100 TB (past the 50 TB storage step) and moves 500 TB a month (past all +// three egress steps). data matrix_basis_assumption: ByteBasisAssumption = BasisAssumed { basis: DecimalGigabyte, rationale: "Declared for the vendors that do not state a basis (AWS, Azure, Cloudflare, Wasabi, Storj). Google states gibibyte and is therefore priced on its own stated basis regardless of this assumption.", diff --git a/dag/test/claim/scm_repository_save_witness_test.dag b/dag/test/claim/scm_repository_save_witness_test.dag index 35976952db6..375e4d48e84 100644 --- a/dag/test/claim/scm_repository_save_witness_test.dag +++ b/dag/test/claim/scm_repository_save_witness_test.dag @@ -2,12 +2,12 @@ module test.claim.scm_repository_save_witness // THE SAVE BOUNDARY'S ORDER PROPERTY, PROVED WITHOUT PERFORMING A WRITE. // -// The claim that matters about `save_repository` is not that it can write a file. It is that an -// unrepresentable repository is refused BEFORE any bytes exist -- because a write that succeeds and -// is later found corrupt reports the fault to whoever LOADS it rather than to whoever caused it. +// What matters about `save_repository` is not that it can write a file but that an unrepresentable +// repository is refused BEFORE any bytes exist -- a write that succeeds and is later found corrupt +// reports the fault to whoever LOADS it rather than to whoever caused it. // -// HOW THAT IS ESTABLISHED HERE WITHOUT A HOST WRITE, which is the reason this file can execute at -// all: on the refusal path `Filesystem.Write` is never reached, so the operation is pure. Asking +// HOW THAT IS ESTABLISHED WITHOUT A HOST WRITE, which is why this file can execute at all: on the +// refusal path `Filesystem.Write` is never reached, so the operation is pure. Asking // `load_repository` about the same path afterwards is a READ, and a read of a path under the // checkout root is an INPUT under the interpreter's hermetic carve-out. So the pair -- refuse, then // observe the path is still unreadable -- establishes that nothing was written, using only the @@ -17,21 +17,19 @@ module test.claim.scm_repository_save_witness // failed write is reported. Both need a real host write, and the frame that would run them is not // established. What IS established, by execution: under `gunbc run` a write DOES occur -- the // mutation receipt below produced an actual file. Whether the required floor's hermetic frame -// admits the same write is a DIFFERENT question and was not measured; a write has no input -// carve-out the way a read of a checkout path does. Asserting either answer here without measuring -// the floor would be the rung claim DESIGN forbids, so neither is asserted. Authoring the two write -// arms as claims before that is settled would risk two permanently-unexecuted claims in a file -// whose other claims run -- the decoration DESIGN calls worse than absent, because the file would -// be cited as covering a boundary it only half covers. Closing the gap needs a measured route, not -// another claim in this file. +// admits the same write is a DIFFERENT question, not measured; a write has no input carve-out the +// way a read of a checkout path does. Asserting either answer without measuring the floor would be +// the rung claim DESIGN forbids. Authoring the two write arms as claims before that is settled +// would risk two permanently-unexecuted claims in a file whose other claims run -- the decoration +// DESIGN calls worse than absent, because the file would be cited as covering a boundary it half +// covers. Closing the gap needs a measured route, not another claim here. // -// THE MUTATION RECEIPT, and it is stronger than a passing pair. Replacing the checked encoder with -// an unchecked one -- i.e. removing the adjudication from ahead of the write -- reds BOTH claims, -// and the second one STAYS red after the source is restored. That is not a flaky control: the -// mutated save really did write `this_file_is_never_written.json`, so the file now exists and the -// claim correctly keeps reporting that it does. The order property is observed against a real -// filesystem, not asserted about one. In CI each run is a fresh checkout, so the sticky red is -// self-healing there and load-bearing here. +// THE MUTATION RECEIPT, stronger than a passing pair. Replacing the checked encoder with an +// unchecked one -- removing the adjudication from ahead of the write -- reds BOTH claims, and the +// second STAYS red after the source is restored. Not flaky: the mutated save really wrote +// `this_file_is_never_written.json`, so the file exists and the claim correctly keeps reporting it. +// The order property is observed against a real filesystem, not asserted. In CI each run is a fresh +// checkout, so the sticky red is self-healing there and load-bearing here. import std.types { Bool, Int, String } import std.minted_identity { MintedId, MintedIdAllocator } diff --git a/dag/test/claim/sec_edgar_rollins_chemed_witness_test.dag b/dag/test/claim/sec_edgar_rollins_chemed_witness_test.dag index fd303bc5ad1..c16492b6dc6 100644 --- a/dag/test/claim/sec_edgar_rollins_chemed_witness_test.dag +++ b/dag/test/claim/sec_edgar_rollins_chemed_witness_test.dag @@ -22,7 +22,11 @@ import extdeps.sec.edgar { cik_padded_digits } data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data sec_edgar_witness_note: String = "Rollins and Chemed both tag a CostOfGoodsAndService variant instead of GrossProfit on their FY2025 10-Ks (see rollins_facts / chemed_facts provenance notes), so the profitability witness here derives OPERATING margin (OperatingIncomeLoss / revenue) rather than gross margin. derive_gross_margin_ratio_from_facts is reused as-is — the ratio math (profit / revenue, revenue > 0) is agnostic to which profit line is passed in; no new facts.dag function is needed for this." +// Rollins and Chemed both tag a CostOfGoodsAndService variant instead of GrossProfit on their +// FY2025 10-Ks (see rollins_facts / chemed_facts provenance notes), so the profitability witness +// here derives OPERATING margin (OperatingIncomeLoss / revenue) rather than gross margin. +// derive_gross_margin_ratio_from_facts is reused as-is — the ratio math (profit / revenue, revenue +// > 0) is agnostic to which profit line is passed in; no new facts.dag function is needed for this. data rollins_fy2025_operating_margin_ratio_low: Float = 0.1930 diff --git a/dag/test/claim/seed_growth_admission_witness_test.dag b/dag/test/claim/seed_growth_admission_witness_test.dag index f9a4de4ffa4..a60ab291a5a 100644 --- a/dag/test/claim/seed_growth_admission_witness_test.dag +++ b/dag/test/claim/seed_growth_admission_witness_test.dag @@ -20,12 +20,12 @@ test fn seed_growth_roster_mechanical_checks_hold() -> Bool { seed_growth_roster_mechanical_checks_holds() } -// THE JOIN IS SPLIT AND THE SPLIT IS THE ASSERTION, not an implementation detail beside it. Under -// the single-candidate-set form these two calls were one, so the population that found an -// unjustified addition was the same one that declared every untouched roster row stale. Here the -// SAME candidate list is passed to both functions and they must answer differently: the rogue is an -// unjustified addition, and passing it as the live population makes every real roster row stale -// rather than none. A reimplementation that collapsed them again reds on the second conjunct. +// THE JOIN IS SPLIT AND THE SPLIT IS THE ASSERTION. Under the single-candidate-set form these two +// calls were one, so the population that found an unjustified addition was the same one that +// declared every untouched roster row stale. Here the SAME candidate list goes to both functions +// and they must answer differently: the rogue is an unjustified addition, and passing it as the live +// population makes every real roster row stale rather than none. A reimplementation that collapsed +// them again reds on the second conjunct. test fn seed_growth_join_refuses_unknown_declaration() -> Bool { let rogue = DeclarationRef { module_path: "v1_compiler.cli_run", @@ -54,14 +54,13 @@ test fn witness_seed_growth_roster_well_formed_gate_holds() -> Bool { } // WHAT REPLACED THE TWO SCAFFOLD WITNESSES, AND WHY THIS IS NOT AN EQUIVALENT CHECK IN A NEW -// SPELLING. Two arms here asserted that seed_growth_admission_join_scaffold and -// seed_growth_g0_census_host_scaffold were Scaffold dispositions, and a third asserted that a prose -// row CONTAINED two substrings. All three are gone with their subjects: the scaffolds retired when -// their triggers fired, and the prose assertion was the prose-self-match antipattern -- its only -// content was that someone had written a sentence, so it could not tell a repair from a regression. -// The g0 population note is now asserted through the mechanism it describes rather than through its -// own text: the census host it names is a function, and the arms above and in -// rust_item_host_observation_witness_test execute it. +// SPELLING. Two arms asserted that seed_growth_admission_join_scaffold and +// seed_growth_g0_census_host_scaffold were Scaffold dispositions; a third asserted a prose row +// CONTAINED two substrings. All three are gone with their subjects: the scaffolds retired when their +// triggers fired, and the prose assertion was the prose-self-match antipattern -- its only content +// was that someone had written a sentence, so it could not tell a repair from a regression. The g0 +// population note is now asserted through the mechanism it describes: the census host it names is a +// function, and the arms above and in rust_item_host_observation_witness_test execute it. test fn the_g0_population_note_names_a_host_that_resolves_to_a_function() -> Bool { string_contains(s: seed_growth_admission_g0_population_note, pattern: "gunbc.rust_item_host_observation") && seed_growth_roster_well_formed_gate_holds() diff --git a/dag/test/claim/seed_honesty_discharge_unavailable_test.dag b/dag/test/claim/seed_honesty_discharge_unavailable_test.dag index bc8a33b69cc..89aff73c66c 100644 --- a/dag/test/claim/seed_honesty_discharge_unavailable_test.dag +++ b/dag/test/claim/seed_honesty_discharge_unavailable_test.dag @@ -22,7 +22,55 @@ import v2.std.witness { Holds, Violates, Witness } import v2.std.logic { Bool } import v2.std.diagnostic { Accepted, Rejected, None } -data seed_honesty_discharge_unavailable_offline_recipe_note: String = "MOVED OUT OF src/v2/test/claim/execution/ INTO dag/test/claim/ (review 47620), and the move is the substance rather than tidying. That directory carries a dir-grain OfflineLocalRecipe exclusion whose stated reason is the emit-vs-eval execution corpus home, and dag/gunbc/ci_layer_roots witness_discovery_scan_dirs does not list that tree at all. These witnesses are hermetic -- constructed DiverseCompilationRun fixtures, no host read anywhere -- so they never belonged in an emit-vs-eval execution home; they sat there incidentally. Deleting the seed-honesty QuarantineProbeExpectRed enrollment while leaving the file there would have removed the only thing scheduling it and left BOTH the closing contract and its permanent control running nowhere on the merge-gating path: a one-time RedControlExecuted receipt backing a regression wall that never executes again, which is specification-without-execution for the exact wall this change claims to keep. WHAT ACTUALLY MAKES THE MOVE THE REPAIR, corrected after reading the executor rather than the roster names. An earlier revision of this note justified the move as gaining positive membership in witness_discovery_scan_dirs. That justification was WRONG, and the mechanism is worth stating because the name misleads: claim_executor invoke_floor_discovery_producer_over_corpus uses scan_dirs for EXACTLY ONE thing, the discover_owned_data_decls loop, and hands the witness producer discover_floor_corpus_rows_from_host_facts only source_roots and exclude_substrings. So witness discovery is a SOURCE-ROOT walk for *_test.dag minus exclusions; witness_discovery_scan_dirs is the owned-data-decl scope, not the witness scope. The old location was therefore already reachable by the walk. What excluded it was the exclusion substring test/claim/execution/, which the walk does honor -- so the operative repair is leaving a path that matches an exclusion pattern, and the scan-dir half of the earlier justification named a mechanism that does not govern witnesses at all. v1_seed_honesty_decision_closing_contract_holds WAS enrolled QuarantineProbeExpectRed while seed_honesty_decision was SeedHonestyUndecided; the operator verdict of 2026-08-02 recorded FixedPointTrustSufficient, the aggregate greened, and the quarantine enrollment was deleted in the same change. The closing contract executes five conjuncts: a reflexive claim/check artifact refuses with a located bootstrap_self_verify_same_artifact diagnostic, a separately identified planted divergence refuses with bootstrap_self_verify_diverged, mismatched source/compiler/hash-pin provenance refuses with bootstrap_self_verify_provenance_mismatch, a distinct equal-content pair with equal provenance passes so none of the refusals is a blanket red, and the decision carries a NonEmptyStr rationale in one of the two decided arms.\n\nWHY THE EXPECT-RED PROBE WAS FLIPPED RATHER THAN DELETED. DESIGN 4b(4) rules that a climb dissolves the redundant lower-rung PRODUCTION machinery and keeps the discriminating evidence enrolled, because deleting the evidence recreates specification-without-execution one rung up. seed_honesty_undecided_keeps_closing_contract_red read the live decision constant, so once the verdict landed it could only assert the state that no longer exists -- it had to either go red or be deleted, and both are wrong. The conjunction is therefore now a FUNCTION of the decision, seed_honesty_closing_contract_over, applied to the live constant by the contract and to SeedHonestyUndecided by the permanent control seed_honesty_undecided_would_keep_closing_contract_red. That control keeps the fifth conjunct load-bearing: if someone weakened the decision arm so an undecided value satisfied the contract, the contract itself would stay green and only this control would red. Without it the aggregate would pass on four conjuncts that were already passing before the verdict.\n\nThe unavailable-evidence witnesses keep the larger DDC discharge fail-closed independently of the verdict, which is deliberate -- the verdict removes the DDC prerequisite edge from the v1-exit finish lines, it does not admit unavailable evidence." +// MOVED OUT OF src/v2/test/claim/execution/ INTO dag/test/claim/ (review 47620), and the move is +// the substance rather than tidying. That directory carries a dir-grain OfflineLocalRecipe +// exclusion whose stated reason is the emit-vs-eval execution corpus home, and +// dag/gunbc/ci_layer_roots witness_discovery_scan_dirs does not list that tree at all. These +// witnesses are hermetic -- constructed DiverseCompilationRun fixtures, no host read anywhere -- so +// they never belonged in an emit-vs-eval execution home; they sat there incidentally. Deleting the +// seed-honesty QuarantineProbeExpectRed enrollment while leaving the file there would have removed +// the only thing scheduling it and left BOTH the closing contract and its permanent control running +// nowhere on the merge-gating path: a one-time RedControlExecuted receipt backing a regression wall +// that never executes again, which is specification-without-execution for the exact wall this +// change claims to keep. WHAT ACTUALLY MAKES THE MOVE THE REPAIR, corrected after reading the +// executor rather than the roster names. An earlier revision of this note justified the move as +// gaining positive membership in witness_discovery_scan_dirs. That justification was WRONG, and the +// mechanism is worth stating because the name misleads: claim_executor +// invoke_floor_discovery_producer_over_corpus uses scan_dirs for EXACTLY ONE thing, the +// discover_owned_data_decls loop, and hands the witness producer +// discover_floor_corpus_rows_from_host_facts only source_roots and exclude_substrings. So witness +// discovery is a SOURCE-ROOT walk for *_test.dag minus exclusions; witness_discovery_scan_dirs is +// the owned-data-decl scope, not the witness scope. The old location was therefore already +// reachable by the walk. What excluded it was the exclusion substring test/claim/execution/, which +// the walk does honor -- so the operative repair is leaving a path that matches an exclusion +// pattern, and the scan-dir half of the earlier justification named a mechanism that does not +// govern witnesses at all. v1_seed_honesty_decision_closing_contract_holds WAS enrolled +// QuarantineProbeExpectRed while seed_honesty_decision was SeedHonestyUndecided; the operator +// verdict of 2026-08-02 recorded FixedPointTrustSufficient, the aggregate greened, and the +// quarantine enrollment was deleted in the same change. The closing contract executes five +// conjuncts: a reflexive claim/check artifact refuses with a located +// bootstrap_self_verify_same_artifact diagnostic, a separately identified planted divergence +// refuses with bootstrap_self_verify_diverged, mismatched source/compiler/hash-pin provenance +// refuses with bootstrap_self_verify_provenance_mismatch, a distinct equal-content pair with equal +// provenance passes so none of the refusals is a blanket red, and the decision carries a +// NonEmptyStr rationale in one of the two decided arms. +// +// WHY THE EXPECT-RED PROBE WAS FLIPPED RATHER THAN DELETED. DESIGN 4b(4) rules that a climb +// dissolves the redundant lower-rung PRODUCTION machinery and keeps the discriminating evidence +// enrolled, because deleting the evidence recreates specification-without-execution one rung up. +// seed_honesty_undecided_keeps_closing_contract_red read the live decision constant, so once the +// verdict landed it could only assert the state that no longer exists -- it had to either go red or +// be deleted, and both are wrong. The conjunction is therefore now a FUNCTION of the decision, +// seed_honesty_closing_contract_over, applied to the live constant by the contract and to +// SeedHonestyUndecided by the permanent control +// seed_honesty_undecided_would_keep_closing_contract_red. That control keeps the fifth conjunct +// load-bearing: if someone weakened the decision arm so an undecided value satisfied the contract, +// the contract itself would stay green and only this control would red. Without it the aggregate +// would pass on four conjuncts that were already passing before the verdict. +// +// The unavailable-evidence witnesses keep the larger DDC discharge fail-closed independently of the +// verdict, which is deliberate -- the verdict removes the DDC prerequisite edge from the v1-exit +// finish lines, it does not admit unavailable evidence. data seed_honesty_primary_compiler: Symbol = ^seed_honesty_primary_compiler data seed_honesty_secondary_compiler: Symbol = ^seed_honesty_secondary_compiler diff --git a/dag/test/claim/seed_mirror_constant_lens_witness_test.dag b/dag/test/claim/seed_mirror_constant_lens_witness_test.dag index 44cb7ef53e0..b7fd040ccb8 100644 --- a/dag/test/claim/seed_mirror_constant_lens_witness_test.dag +++ b/dag/test/claim/seed_mirror_constant_lens_witness_test.dag @@ -16,21 +16,111 @@ import v2.std.live_tree { LiveTreeDisposition, ReadsLiveTree } data live_tree_disposition: LiveTreeDisposition = ReadsLiveTree -data seed_mirror_constant_lens_note: String = "THE MECHANISM TWO SEED-MIRROR NOTES NAMED AND NOBODY BUILT. gunbc.typed_module_cache_capacity typed_module_cache_capacity_seed_mirror_note and gunbc.host_budget_source host_budget_source_seed_mirror_note each asked for 'one lens reading the seed's constants against their cited rows', and each scoped it slightly differently -- neither subset was the union, which is two partial specifications of one mechanism and the section 3 shape in its own right. This module is the union.\n\nWHY IT IS NOT A CHANGE DETECTOR. The expected value is never written here. Every assertion derives its literal from the imported authority row and renders it, so editing this file cannot satisfy it and editing the authority row moves the expectation automatically. That is the distinction the 2026-08-01 test-oracle ruling draws: the oracle is an independently governed authority, not a measurement copied from the tree under test. The failure mode it replaces is live in this very corpus -- host_budget_source_witness_test constructed its expectation with the mirror value retyped, so it greened whichever way the mirror went.\n\nWHY THE SEED LITERALS ARE CANONICAL DECIMAL. A mirror constant's whole job is to equal its authority, and an equality that a reader cannot decide by looking is not one. 3 * 1024 * 1024 and 13_958_643_712 are the same values written so that no join can reach them, so the in-scope constants are written as plain decimal and the lens refuses any it cannot parse rather than skipping it.\n\nWHY CITATION IS THE ENROLLMENT ACT. Of the five constants in scope exactly one carried no citation, and that one is the one that drifted eleven days (DECLARED_RUNNER_SLOT_MEMORY_HIGH_BYTES, seed 13958643712 against an authority of 16106127360 since 936f451446 / #8388, 2026-08-17). An uncited constant is not merely unchecked, it is unreachable: nothing joins it to anything. So the marker is what enrolls a constant, and seed_mirror_reach_note states exactly how far that reaches and where it stops -- read that row before citing this one for coverage.\n\nWHY THERE IS NO PLANTED CONTROL. Four of the five rows matched at authorship and one did not, so the discriminating RED and its positive control are the same table read at the same commit, from live data. A synthetic mismatch would prove only that the lens can fire; this proves the class is not hypothetical as well. If a future reading shows all five green, the four matching rows remain the control -- perturb any authority row and its assertion must go red." - -data seed_read_has_no_success_arm_note: String = "WHY THERE IS NO READ-FAILURE ARM, and why its absence is not a narrow. The seed's filesystem_read primitive returns FilesystemReadResult, declared in v1_method filesystem_read_result_type and emitted by v1.runtime_rust rt_filesystem, and that record carries EXACTLY ONE field: content. There is no success or error field to branch on -- the service-level Filesystem.Read operation is a different carrier with a different shape, and reading its three-field contract onto this primitive would cite the wrong authority. This module learned that by refusing: an earlier revision branched on r.success and the compiler answered 'no field success on type FilesystemReadResult', which is the fail-closed refusal working.\n\nWHAT HAPPENS ON FAILURE: rt_filesystem calls read_to_string with unwrap_or_else(|e| panic!), so an absent or unreadable seed file aborts the run loudly rather than presenting as a passing check. Empty content fails every assertion here, since no expected literal is the empty string. So both failure modes are non-green without a guard, and adding one would be machinery with no producer -- a scaffold defending a state the type cannot express. The reasoning and the owed modeling gap (a caller cannot distinguish absent from unreadable from empty, and that dissolves when the primitive returns an outcome instead of panicking) are dag/gunbc/instruments/frontier_ingestion_probe frontier_read_refusal_disposition_note's, cited rather than re-derived." +// THE MECHANISM TWO SEED-MIRROR NOTES NAMED AND NOBODY BUILT. gunbc.typed_module_cache_capacity +// typed_module_cache_capacity_seed_mirror_note and gunbc.host_budget_source +// host_budget_source_seed_mirror_note each asked for 'one lens reading the seed's constants against +// their cited rows', and each scoped it slightly differently -- neither subset was the union, which +// is two partial specifications of one mechanism and the section 3 shape in its own right. This +// module is the union. +// +// WHY IT IS NOT A CHANGE DETECTOR. The expected value is never written here. Every assertion +// derives its literal from the imported authority row and renders it, so editing this file cannot +// satisfy it and editing the authority row moves the expectation automatically. That is the +// distinction the 2026-08-01 test-oracle ruling draws: the oracle is an independently governed +// authority, not a measurement copied from the tree under test. The failure mode it replaces is +// live in this very corpus -- host_budget_source_witness_test constructed its expectation with the +// mirror value retyped, so it greened whichever way the mirror went. +// +// WHY THE SEED LITERALS ARE CANONICAL DECIMAL. A mirror constant's whole job is to equal its +// authority, and an equality that a reader cannot decide by looking is not one. 3 * 1024 * 1024 and +// 13_958_643_712 are the same values written so that no join can reach them, so the in-scope +// constants are written as plain decimal and the lens refuses any it cannot parse rather than +// skipping it. +// +// WHY CITATION IS THE ENROLLMENT ACT. Of the five constants in scope exactly one carried no +// citation, and that one is the one that drifted eleven days +// (DECLARED_RUNNER_SLOT_MEMORY_HIGH_BYTES, seed 13958643712 against an authority of 16106127360 +// since 936f451446 / #8388, 2026-08-17). An uncited constant is not merely unchecked, it is +// unreachable: nothing joins it to anything. So the marker is what enrolls a constant, and +// seed_mirror_reach_note states exactly how far that reaches and where it stops -- read that row +// before citing this one for coverage. +// +// WHY THERE IS NO PLANTED CONTROL. Four of the five rows matched at authorship and one did not, so +// the discriminating RED and its positive control are the same table read at the same commit, from +// live data. A synthetic mismatch would prove only that the lens can fire; this proves the class is +// not hypothetical as well. If a future reading shows all five green, the four matching rows remain +// the control -- perturb any authority row and its assertion must go red. + +// WHY THERE IS NO READ-FAILURE ARM, and why its absence is not a narrow. The seed's filesystem_read +// primitive returns FilesystemReadResult, declared in v1_method filesystem_read_result_type and +// emitted by v1.runtime_rust rt_filesystem, and that record carries EXACTLY ONE field: content. +// There is no success or error field to branch on -- the service-level Filesystem.Read operation is +// a different carrier with a different shape, and reading its three-field contract onto this +// primitive would cite the wrong authority. This module learned that by refusing: an earlier +// revision branched on r.success and the compiler answered 'no field success on type +// FilesystemReadResult', which is the fail-closed refusal working. +// +// WHAT HAPPENS ON FAILURE: rt_filesystem calls read_to_string with unwrap_or_else(|e| panic!), so +// an absent or unreadable seed file aborts the run loudly rather than presenting as a passing +// check. Empty content fails every assertion here, since no expected literal is the empty string. +// So both failure modes are non-green without a guard, and adding one would be machinery with no +// producer -- a scaffold defending a state the type cannot express. The reasoning and the owed +// modeling gap (a caller cannot distinguish absent from unreadable from empty, and that dissolves +// when the primitive returns an outcome instead of panicking) are +// dag/gunbc/instruments/frontier_ingestion_probe frontier_read_refusal_disposition_note's, cited +// rather than re-derived. data cli_run_seed_path: String = "src/v1/stage0/src/cli_run.rs" data memory_governor_seed_path: String = "src/v1/stage0/src/memory_governor.rs" data seed_mirror_marker: String = "SEED MIRROR of `" -data seed_mirror_reach_note: String = "THE ROSTER IS FOLDED, NOT RE-LISTED, AND THAT IS THE CORRECTION THAT MATTERS. An earlier revision of this module enumerated five assertions by hand and conjoined five hardcoded symbol names, and its PR claimed that an uncited in-scope constant REFUSES rather than skips. That claim was false in the direction that matters: 'in scope' was whatever someone had remembered to type here, so a new seed mirror constant was neither checked NOR refused -- invisible, exactly like the drift this module exists to catch. neat-bee-14 read the diff and refuted the sentence; the defect is the same shape they had just repaired in seed_growth_roster_all_declarations, where re-listed rows made a third justification's declarations invisible to the duplicate check while every other reading called them enrolled.\n\nWHAT MAKES THE REACH REAL NOW is a two-way join rather than a count. Forward: every row in seed_mirror_constant_rows must find its declaration and its authority symbol in the seed. Backward: the number of marker occurrences in each seed file must equal the number of roster rows homed in that file. Rows are distinct and each must be present, so counts agreeing means no marked constant exists that the roster does not carry -- set equality, not a count comparison standing in for one. The backward count is not the tree-copied literal the 2026-08-01 oracle ruling forbids either: it is derived by folding this module's own roster, so automating it does not collapse the assertion to measure() == measure(). Add a sixth marked constant without a row and the backward arm reds.\n\nWHAT IS STILL NOT REACHED, stated rather than left to be discovered: a seed constant carrying NO marker at all is invisible to both arms. The marker is the enrollment act, so this raises the bar from 'someone remembered to edit a list in another file' to 'someone marked the declaration where they wrote it' -- a real climb, and not the same as a census of every const in the seed. NEXT-RUNG TRIGGER: a Rust-declaration-level census that enumerates candidate mirror constants from the seed's own syntax instead of from a marker convention, at which point the marker becomes redundant and this roster derives rather than being authored." +// THE ROSTER IS FOLDED, NOT RE-LISTED, AND THAT IS THE CORRECTION THAT MATTERS. An earlier revision +// of this module enumerated five assertions by hand and conjoined five hardcoded symbol names, and +// its PR claimed that an uncited in-scope constant REFUSES rather than skips. That claim was false +// in the direction that matters: 'in scope' was whatever someone had remembered to type here, so a +// new seed mirror constant was neither checked NOR refused -- invisible, exactly like the drift +// this module exists to catch. neat-bee-14 read the diff and refuted the sentence; the defect is +// the same shape they had just repaired in seed_growth_roster_all_declarations, where re-listed +// rows made a third justification's declarations invisible to the duplicate check while every other +// reading called them enrolled. +// +// WHAT MAKES THE REACH REAL NOW is a two-way join rather than a count. Forward: every row in +// seed_mirror_constant_rows must find its declaration and its authority symbol in the seed. +// Backward: the number of marker occurrences in each seed file must equal the number of roster rows +// homed in that file. Rows are distinct and each must be present, so counts agreeing means no +// marked constant exists that the roster does not carry -- set equality, not a count comparison +// standing in for one. The backward count is not the tree-copied literal the 2026-08-01 oracle +// ruling forbids either: it is derived by folding this module's own roster, so automating it does +// not collapse the assertion to measure() == measure(). Add a sixth marked constant without a row +// and the backward arm reds. +// +// WHAT IS STILL NOT REACHED, stated rather than left to be discovered: a seed constant carrying NO +// marker at all is invisible to both arms. The marker is the enrollment act, so this raises the bar +// from 'someone remembered to edit a list in another file' to 'someone marked the declaration where +// they wrote it' -- a real climb, and not the same as a census of every const in the seed. +// NEXT-RUNG TRIGGER: a Rust-declaration-level census that enumerates candidate mirror constants +// from the seed's own syntax instead of from a marker convention, at which point the marker becomes +// redundant and this roster derives rather than being authored. data seed_mirror_lens_floor_execution_note: String = "THIS LENS IS STILL DISCOVERED AND DECLINED, AND ITS STATED REASON FOR BEING SO IS FALSE. Those are two different corrections and only the second one has landed. What the paragraph this replaces said: THIS LENS IS DISCOVERED AND DECLINED, IT DOES NOT RUN IN CI, and a live-tree reader cannot participate in the hermetic fold BY CONSTRUCTION. The first two are STILL TRUE. The third was already false when written, and it is the reason the first two were true -- so the fact survives and the mechanism it was attributed to does not.\n\nTHE MEASUREMENT IS PRESERVED BECAUSE IT IS STILL THE RECEIPT, and it is what made this module's own situation decidable at all. Measured on gunbc#8638, floor run 32337765205 at 4806220c04 against run 32333231183 at the same base: site-projection reported claims=9782 declined_long=538 declined_live=782, and the base reported claims=9782 declined_long=538 declined_live=778. Adding this module moved declined_live by exactly +4 -- its four witnesses -- and moved claims by ZERO. That 778 is the population the 2026-08-20 witness-execution-closure change addresses, and this note's own four rows were four of it.\n\nWHY THE BY-CONSTRUCTION CLAIM WAS FALSE. Hermetic mode carries the checkout-read carve-out (v1_interpreter, the Filesystem.Read arm guarded by hermetic_checkout_read_disposition): a read whose path the disposition CONFIRMS sits under the checkout root, with no .git or target component below it, dispatches to a REAL read -- the commit is the run's deterministic input, so it is input access and not a host effect. Reading committed .rs files is exactly that case. So a live-tree reader of committed sources could always have participated; what excluded it was not the hermetic fold but a separate, file-grain prediction in the floor's site projection (RequiredFloorDisposition.DeclinedLiveTree, fed by a text scan for this file's own live_tree_disposition row) that had stopped agreeing with what the interpreter actually does. That arm is deleted at the root.\n\nTHE DECLARATION BELOW STAYS ReadsLiveTree AND IS STILL NOT A LIE. It is read by reads_live_tree_effective for AFFECTED-SET SELECTION ELIGIBILITY, which asks whether this entry's result depends on live tree state -- a different question from whether it can execute, and one this module genuinely answers yes to. The old note's dilemma (declare SubstrateInputsOnly to buy execution, or stay honest and lose it) was created entirely by the floor conflating those two questions. With the conflation gone the dilemma is gone: the honest declaration no longer costs execution, and nothing is bought by a false one.\n\nTHE RUNG DOES NOT CLIMB YET, AND SAYING OTHERWISE WOULD BE THE INFLATION SECTION 4b CALLS WORSE THAN SITTING LOW. It stays MITIGATABLE. The old note's next-rung trigger -- an executing consumer for the declined-live population -- is now known to be reachable by deleting one stale prediction rather than by building a lane, and it has been demonstrated by execution on a branch (floor run 32345970386: the decline deleted, ~783 identities admitted, 626 PASS, these four rows among the executing population). But the deletion is NOT on main: it also admits 55 blockers, 6 witnesses that do not resolve and 49 in a cost tail, which are staged behind their own owners. A rung claimed on a change that has not landed is exactly the inflation that keeps a class from ranking for climbing, so this note reports the trigger as REACHABLE AND MEASURED, not as fired. WHAT THE FIRST EXECUTION DOES NOT ESTABLISH, recorded by this module's author (stern-heron-695) rather than inferred by the session that ran it, because the distinction is about evidence GRADE and is easy to lose. When these four rows first executed they PASSED -- and that is not evidence the lens catches drift. The drift it was built for (DECLARED_RUNNER_SLOT_MEMORY_HIGH_BYTES, 13958643712 -> 16106127360) had already been corrected in gunbc#8635, and the lens was authored BEHIND that correction. So the pass is the lens agreeing with a tree that had just been made to agree with itself.\n\nThe lens's discriminating power therefore rests on its AUTHORED NEGATIVE CONTROL -- perturb the value and the forward arm reds, add a marked constant with no roster row and the backward arm reds, each failing exactly one assertion and a different one -- and NOT on any live catch. A check that has only ever agreed with a tree its author had just reconciled has been tested against itself and not yet against the world. That is the same shape this module was built to flag one layer down, so it is stated here rather than left for a reader to discover that `first execution: PASS` was doing no work. The first execution on MAIN, when the decline is deleted, is the run that would begin to answer it.\n\nThe residual survives untouched: a seed constant carrying NO marker at all remains invisible to both arms, so the next-rung trigger stays a Rust-declaration-level census enumerating candidate mirror constants from the seed's own syntax rather than from a marker convention. The eleven-day drift these rows were built for would be caught the day the decline is deleted; an unmarked constant's drift still would not.\n\nONE RESIDUAL RISK THE CLIMB CREATES, recorded because it is the honest rung rather than the flattering one (stern-heron-695, verifying this correction at symbol grain rather than accepting it). The carve-out this lens now executes through binds its root to the PROCESS CWD -- hermetic_checkout_read_disposition passes the cwd to hermetic_checkout_read_disposition_under, justified by a runner contract stated in a doc comment (claim_batch and claim_executor both run from the repo root), not by anything structural. These four rows carry repo-relative literal paths. If any executor ever folds witnesses from a cwd that is NOT the checkout root, the reads stop being confirmed checkout inputs, fall through to the mock and fail-closed machinery, and these rows red for a reason that has nothing to do with seed drift. So the mechanically-preventable rung above is conditional on that contract holding, and the contract is a comment rather than a wall. Its own next-rung trigger: the input root is derived from the discovered checkout rather than from the process cwd, at which point the condition disappears instead of being remembered." - -data seed_mirror_sixth_row_enrollment_note: String = "THE SIXTH ROW LANDED WITH ITS MARKER, WHICH IS THE COUPLING THIS MODULE'S OWN MECHANISM REQUIRES. DECLARED_WHOLE_CORPUS_COMPILE_MEASURED_DEMAND_BYTES in memory_governor, authority gunbc.whole_corpus_compile_admission whole_corpus_compile_measured_peak_demand, is now enrolled in seed_mirror_constant_rows and carries the SEED MIRROR marker. It was deliberately unmarked and unrostered between gunbc#8635 and gunbc#8638 because the BACKWARD arm reds when a MARKED constant has no roster row, so a marker landing first would have red main for the interval between the two merges. Both have merged, so the pair lands together here. WHY THIS NOTE REPLACES THE PENDING ONE RATHER THAN ANNOTATING IT: every load-bearing sentence of the pending note was a statement about an obligation that no longer exists, and a reader finding the old text beside a correction has to work out which half is live. WHAT SURVIVES FROM IT, because it was never about this one constant: the residual is that a seed constant with a real authority row and NO marker is invisible to both arms, so coverage is bounded by who remembers to mark. This constant was the live specimen of that residual and is no longer one; the residual itself is untouched. Its next rung is unchanged and is stated in seed_mirror_reach_note: a census taken from the Rust declaration's own syntax rather than from a marker convention, at which point an unmarked in-scope constant becomes detectable instead of merely undetected." +// THE SIXTH ROW LANDED WITH ITS MARKER, WHICH IS THE COUPLING THIS MODULE'S OWN MECHANISM REQUIRES. +// DECLARED_WHOLE_CORPUS_COMPILE_MEASURED_DEMAND_BYTES in memory_governor, authority +// gunbc.whole_corpus_compile_admission whole_corpus_compile_measured_peak_demand, is now enrolled +// in seed_mirror_constant_rows and carries the SEED MIRROR marker. It was deliberately unmarked and +// unrostered between gunbc#8635 and gunbc#8638 because the BACKWARD arm reds when a MARKED constant +// has no roster row, so a marker landing first would have red main for the interval between the two +// merges. Both have merged, so the pair lands together here. WHY THIS NOTE REPLACES THE PENDING ONE +// RATHER THAN ANNOTATING IT: every load-bearing sentence of the pending note was a statement about +// an obligation that no longer exists, and a reader finding the old text beside a correction has to +// work out which half is live. WHAT SURVIVES FROM IT, because it was never about this one constant: +// the residual is that a seed constant with a real authority row and NO marker is invisible to both +// arms, so coverage is bounded by who remembers to mark. This constant was the live specimen of +// that residual and is no longer one; the residual itself is untouched. Its next rung is unchanged +// and is stated in seed_mirror_reach_note: a census taken from the Rust declaration's own syntax +// rather than from a marker convention, at which point an unmarked in-scope constant becomes +// detectable instead of merely undetected. type SeedMirrorRow { seed_path: String diff --git a/dag/test/claim/self_host_00_compile_behavioral_witness_test.dag b/dag/test/claim/self_host_00_compile_behavioral_witness_test.dag index c9a075eac7c..3afe7cafbb2 100644 --- a/dag/test/claim/self_host_00_compile_behavioral_witness_test.dag +++ b/dag/test/claim/self_host_00_compile_behavioral_witness_test.dag @@ -2,7 +2,11 @@ module test.claim.self_host_00_compile_behavioral_witness import tools.self_host_module_behavioral_transport_roster { compiler_module_behavioral_receipt_for } -data self_host_00_compile_behavioral_witness_doc: String = "Wet self-host behavioral receipt probe for Wave 2 Gate-A flip (00_compile): compares gunbc-emitted vs seed required_lens_grain_note (00_compile.dag module authority constant); --inject-fault perturbs emitted comparison (not driver flag). Full compile-tree walk deferred until emit surface greens (#6775). Live host effects — enroll when frontier flips SelfEmitted with binding." +// Wet self-host behavioral receipt probe for Wave 2 Gate-A flip (00_compile): compares +// gunbc-emitted vs seed required_lens_grain_note (00_compile.dag module authority constant); +// --inject-fault perturbs emitted comparison (not driver flag). Full compile-tree walk deferred +// until emit surface greens (#6775). Live host effects — enroll when frontier flips SelfEmitted +// with binding. test fn self_host_00_compile_behavioral_receipt_holds() -> Bool { compiler_module_behavioral_receipt_for(module_path: "src/v2/compiler/00_compile.dag") diff --git a/dag/test/claim/self_host_01_tokenize_behavioral_witness_test.dag b/dag/test/claim/self_host_01_tokenize_behavioral_witness_test.dag index 0b61666bb6d..301b71006c3 100644 --- a/dag/test/claim/self_host_01_tokenize_behavioral_witness_test.dag +++ b/dag/test/claim/self_host_01_tokenize_behavioral_witness_test.dag @@ -2,7 +2,11 @@ module test.claim.self_host_01_tokenize_behavioral_witness import tools.self_host_module_behavioral_transport_roster { compiler_module_behavioral_receipt_for } -data self_host_01_tokenize_behavioral_witness_doc: String = "Wet self-host behavioral receipt probe for Wave 2 Gate-A flip lane (01_tokenize): compares gunbc-emitted vs seed tokenize_module_authority_note (01_tokenize.dag module authority constant); --inject-fault perturbs emitted comparison (not driver flag). Full token-stream walk deferred until emit surface greens (#6775). Live host effects — enroll when frontier flips SelfEmitted with binding." +// Wet self-host behavioral receipt probe for Wave 2 Gate-A flip lane (01_tokenize): compares +// gunbc-emitted vs seed tokenize_module_authority_note (01_tokenize.dag module authority constant); +// --inject-fault perturbs emitted comparison (not driver flag). Full token-stream walk deferred +// until emit surface greens (#6775). Live host effects — enroll when frontier flips SelfEmitted +// with binding. test fn self_host_01_tokenize_behavioral_receipt_holds() -> Bool { compiler_module_behavioral_receipt_for(module_path: "src/v2/compiler/01_tokenize.dag") diff --git a/dag/test/claim/self_host_02_parse_behavioral_witness_test.dag b/dag/test/claim/self_host_02_parse_behavioral_witness_test.dag index d6d5fb08d1a..1b47c6be877 100644 --- a/dag/test/claim/self_host_02_parse_behavioral_witness_test.dag +++ b/dag/test/claim/self_host_02_parse_behavioral_witness_test.dag @@ -2,7 +2,16 @@ module test.claim.self_host_02_parse_behavioral_witness import tools.self_host_module_behavioral_transport_roster { compiler_module_behavioral_receipt_for } -data self_host_02_parse_behavioral_witness_doc: String = "Wet self-host behavioral receipt probe for Gate-A flip wave (02_parse): compares gunbc-emitted vs seed prepared_grammar_carrier_note (02_parse.dag module authority constant); --inject-fault perturbs emitted comparison (not driver flag). ROUTE STANDING (2026-08-26): this row previously said it was enrolled on the nightly falsifier when its frontier row was SelfEmitted. Both things it named are gone -- falsifier.yml was deleted at 611fd02770/#8283 on 2026-08-15 and the self-host frontier roster no longer exists -- so the sentence cited two dead authorities for one live fact. The route standing for this receipt is now derived at ROW grain by v2.compiler.self_host.wet_receipt_route_standing wet_receipt_route_standings, which says whether the row can be run and, when it cannot, the exact missing fact: a revoked binding is not the same cause as one never established, and a cadence-grain Boolean could not tell them apart." +// Wet self-host behavioral receipt probe for Gate-A flip wave (02_parse): compares gunbc-emitted vs +// seed prepared_grammar_carrier_note (02_parse.dag module authority constant); --inject-fault +// perturbs emitted comparison (not driver flag). ROUTE STANDING (2026-08-26): this row previously +// said it was enrolled on the nightly falsifier when its frontier row was SelfEmitted. Both things +// it named are gone -- falsifier.yml was deleted at 611fd02770/#8283 on 2026-08-15 and the +// self-host frontier roster no longer exists -- so the sentence cited two dead authorities for one +// live fact. The route standing for this receipt is now derived at ROW grain by +// v2.compiler.self_host.wet_receipt_route_standing wet_receipt_route_standings, which says whether +// the row can be run and, when it cannot, the exact missing fact: a revoked binding is not the same +// cause as one never established, and a cadence-grain Boolean could not tell them apart. test fn self_host_02_parse_behavioral_receipt_holds() -> Bool { compiler_module_behavioral_receipt_for(module_path: "src/v2/compiler/02_parse.dag") diff --git a/dag/test/claim/self_host_03_ingest_behavioral_witness_test.dag b/dag/test/claim/self_host_03_ingest_behavioral_witness_test.dag index 9215882a01a..63d9d80feac 100644 --- a/dag/test/claim/self_host_03_ingest_behavioral_witness_test.dag +++ b/dag/test/claim/self_host_03_ingest_behavioral_witness_test.dag @@ -2,7 +2,16 @@ module test.claim.self_host_03_ingest_behavioral_witness import tools.self_host_module_behavioral_transport_roster { compiler_module_behavioral_receipt_for } -data self_host_03_ingest_behavioral_witness_doc: String = "Wet self-host behavioral receipt probe for Gate-A flip wave (03_ingest): compares gunbc-emitted vs seed ingest_module_note (03_ingest.dag module authority constant); --inject-fault perturbs emitted comparison (not driver flag). ROUTE STANDING (2026-08-26): this row previously said it was enrolled on the nightly falsifier when its frontier row was SelfEmitted. Both things it named are gone -- falsifier.yml was deleted at 611fd02770/#8283 on 2026-08-15 and the self-host frontier roster no longer exists -- so the sentence cited two dead authorities for one live fact. The route standing for this receipt is now derived at ROW grain by v2.compiler.self_host.wet_receipt_route_standing wet_receipt_route_standings, which says whether the row can be run and, when it cannot, the exact missing fact: a revoked binding is not the same cause as one never established, and a cadence-grain Boolean could not tell them apart." +// Wet self-host behavioral receipt probe for Gate-A flip wave (03_ingest): compares gunbc-emitted +// vs seed ingest_module_note (03_ingest.dag module authority constant); --inject-fault perturbs +// emitted comparison (not driver flag). ROUTE STANDING (2026-08-26): this row previously said it +// was enrolled on the nightly falsifier when its frontier row was SelfEmitted. Both things it named +// are gone -- falsifier.yml was deleted at 611fd02770/#8283 on 2026-08-15 and the self-host +// frontier roster no longer exists -- so the sentence cited two dead authorities for one live fact. +// The route standing for this receipt is now derived at ROW grain by +// v2.compiler.self_host.wet_receipt_route_standing wet_receipt_route_standings, which says whether +// the row can be run and, when it cannot, the exact missing fact: a revoked binding is not the same +// cause as one never established, and a cadence-grain Boolean could not tell them apart. test fn self_host_03_ingest_behavioral_receipt_holds() -> Bool { compiler_module_behavioral_receipt_for(module_path: "src/v2/compiler/03_ingest.dag") diff --git a/dag/test/claim/self_host_03_normalize_behavioral_witness_test.dag b/dag/test/claim/self_host_03_normalize_behavioral_witness_test.dag index d9023aa5312..7e6117a1e56 100644 --- a/dag/test/claim/self_host_03_normalize_behavioral_witness_test.dag +++ b/dag/test/claim/self_host_03_normalize_behavioral_witness_test.dag @@ -8,7 +8,21 @@ import v2.std.logic { Bool } data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data self_host_03_normalize_behavioral_witness_doc: String = "Wet self-host behavioral receipt probe for Gate-A flip (03_normalize): tools.self_host_module_behavioral_transport_roster's compiler_module_behavioral_receipt_for emits src/v2/compiler/03_normalize.dag via gunbc --entry, assembles curated seed-linked v1_compiled (emitted entry + dep shims + v1-compiler path dep), runs cargo build + witness (plain + --inject-fault). ROUTE STANDING (2026-08-26): this row previously said it was enrolled on the nightly falsifier when its frontier row was SelfEmitted. Both things it named are gone -- falsifier.yml was deleted at 611fd02770/#8283 on 2026-08-15 and the self-host frontier roster no longer exists -- so the sentence cited two dead authorities for one live fact. The route standing for this receipt is now derived at ROW grain by v2.compiler.self_host.wet_receipt_route_standing wet_receipt_route_standings, which says whether the row can be run and, when it cannot, the exact missing fact: a revoked binding is not the same cause as one never established, and a cadence-grain Boolean could not tell them apart. Selection: tools.self_host_03_normalize_declared_source_refs's declared_source_refs (hand-verified complete per docs/plans/declared-source-ref-selection-design.md §5.1, imported here so it lands in this entry's closure only) — selected on emitter-touch, skipped on unrelated diffs." +// Wet self-host behavioral receipt probe for Gate-A flip (03_normalize): +// tools.self_host_module_behavioral_transport_roster's compiler_module_behavioral_receipt_for emits +// src/v2/compiler/03_normalize.dag via gunbc --entry, assembles curated seed-linked v1_compiled +// (emitted entry + dep shims + v1-compiler path dep), runs cargo build + witness (plain + +// --inject-fault). ROUTE STANDING (2026-08-26): this row previously said it was enrolled on the +// nightly falsifier when its frontier row was SelfEmitted. Both things it named are gone -- +// falsifier.yml was deleted at 611fd02770/#8283 on 2026-08-15 and the self-host frontier roster no +// longer exists -- so the sentence cited two dead authorities for one live fact. The route standing +// for this receipt is now derived at ROW grain by v2.compiler.self_host.wet_receipt_route_standing +// wet_receipt_route_standings, which says whether the row can be run and, when it cannot, the exact +// missing fact: a revoked binding is not the same cause as one never established, and a +// cadence-grain Boolean could not tell them apart. Selection: +// tools.self_host_03_normalize_declared_source_refs's declared_source_refs (hand-verified complete +// per docs/plans/declared-source-ref-selection-design.md §5.1, imported here so it lands in this +// entry's closure only) — selected on emitter-touch, skipped on unrelated diffs. test fn self_host_03_normalize_behavioral_receipt_holds() -> Bool { compiler_module_behavioral_receipt_for(module_path: "src/v2/compiler/03_normalize.dag") diff --git a/dag/test/claim/self_host_03_resolve_behavioral_witness_test.dag b/dag/test/claim/self_host_03_resolve_behavioral_witness_test.dag index 01806cd5f72..86d842204d5 100644 --- a/dag/test/claim/self_host_03_resolve_behavioral_witness_test.dag +++ b/dag/test/claim/self_host_03_resolve_behavioral_witness_test.dag @@ -2,7 +2,11 @@ module test.claim.self_host_03_resolve_behavioral_witness import tools.self_host_module_behavioral_transport_roster { compiler_module_behavioral_receipt_for } -data self_host_03_resolve_behavioral_witness_doc: String = "Wet self-host behavioral receipt probe for Wave 2 parallel flip (03_resolve): compares gunbc-emitted vs seed arrow_domain_param_scoping_note (03_resolve.dag module authority constant); --inject-fault perturbs emitted comparison (not driver flag). Full resolve-tree walk deferred until emit surface greens (#6775). Live host effects — enroll when frontier flips SelfEmitted with binding." +// Wet self-host behavioral receipt probe for Wave 2 parallel flip (03_resolve): compares +// gunbc-emitted vs seed arrow_domain_param_scoping_note (03_resolve.dag module authority constant); +// --inject-fault perturbs emitted comparison (not driver flag). Full resolve-tree walk deferred +// until emit surface greens (#6775). Live host effects — enroll when frontier flips SelfEmitted +// with binding. test fn self_host_03_resolve_behavioral_receipt_holds() -> Bool { compiler_module_behavioral_receipt_for(module_path: "src/v2/compiler/03_resolve.dag") diff --git a/dag/test/claim/self_host_04_infer_behavioral_witness_test.dag b/dag/test/claim/self_host_04_infer_behavioral_witness_test.dag index b3e6400edd9..e2456092c61 100644 --- a/dag/test/claim/self_host_04_infer_behavioral_witness_test.dag +++ b/dag/test/claim/self_host_04_infer_behavioral_witness_test.dag @@ -2,7 +2,11 @@ module test.claim.self_host_04_infer_behavioral_witness import tools.self_host_module_behavioral_transport_roster { compiler_module_behavioral_receipt_for } -data self_host_04_infer_behavioral_witness_doc: String = "Wet self-host behavioral receipt probe for Gate-A flip prep (04_infer): compares gunbc-emitted vs seed infer_arrow_domain_binding_heuristic_note (04_infer.dag module authority constant); --inject-fault perturbs emitted comparison (not driver flag). Full infer-tree walk deferred until emit surface greens (#6775). Live host effects — enroll when frontier flips SelfEmitted with binding." +// Wet self-host behavioral receipt probe for Gate-A flip prep (04_infer): compares gunbc-emitted vs +// seed infer_arrow_domain_binding_heuristic_note (04_infer.dag module authority constant); +// --inject-fault perturbs emitted comparison (not driver flag). Full infer-tree walk deferred until +// emit surface greens (#6775). Live host effects — enroll when frontier flips SelfEmitted with +// binding. test fn self_host_04_infer_behavioral_receipt_holds() -> Bool { compiler_module_behavioral_receipt_for(module_path: "src/v2/compiler/04_infer.dag") diff --git a/dag/test/claim/self_host_artifact_materialization_witness_test.dag b/dag/test/claim/self_host_artifact_materialization_witness_test.dag index 016c10c4bf5..01a0c5ba952 100644 --- a/dag/test/claim/self_host_artifact_materialization_witness_test.dag +++ b/dag/test/claim/self_host_artifact_materialization_witness_test.dag @@ -2,7 +2,13 @@ module test.claim.self_host_artifact_materialization_witness data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data artifact_materialization_witness_note: String = "These claims execute the two PURE folds that carry every decision in gunbc.self_host_artifact_materialization, which is why the decisions are witnessed on every PR instead of behind a wet cadence. The discriminating claims are not the happy path: they are that a build failure never reads as a path refusal, that no failure arm produces ArtifactMaterialized, and that the executable carried out of the fold is the one the cargo stream NAMED. That last one is the whole lane in a single assertion — a convention-derived path would satisfy every other claim here while pointing at a different file than the one digested." +// These claims execute the two PURE folds that carry every decision in +// gunbc.self_host_artifact_materialization, which is why the decisions are witnessed on every PR +// instead of behind a wet cadence. The discriminating claims are not the happy path: they are that +// a build failure never reads as a path refusal, that no failure arm produces ArtifactMaterialized, +// and that the executable carried out of the fold is the one the cargo stream NAMED. That last one +// is the whole lane in a single assertion — a convention-derived path would satisfy every other +// claim here while pointing at a different file than the one digested. data valid_hex: String = "cf03d459f24df996cd9f067bb9ef1eb98b4110a3566bc0db54d6949e5371e7861511488e25a86c5177a6940af6e97e7a337e987ce464b55408fe325df9993be9" @@ -10,7 +16,15 @@ data artifact_stream: String = "\{\"reason\":\"compiler-artifact\",\"target\":\{ data ambiguous_stream: String = "\{\"reason\":\"compiler-artifact\",\"target\":\{\"name\":\"gunbc\",\"kind\":[\"bin\"]\},\"executable\":\"/w/target/release/gunbc\"\}\n\{\"reason\":\"compiler-artifact\",\"target\":\{\"name\":\"gunbc\",\"kind\":[\"bin\"]\},\"executable\":\"/w/target/release/other\"\}" -data observed_digest_note: String = "valid_hex is the REAL sha512 of the ASCII string gunbc-artifact-materialization-fixture, reproducible with printf | sha512sum, rather than hand-typed hex. The first draft here WAS hand-typed and was 130 characters instead of 128; the refinement rejected it, good_observation became a refusal, and the three positive claims went red — which is the wall doing its job and is why this note exists. Built through the validating mint rather than by labelling text a digest: sha512_hex_digest applies the length and lowercase-hex refinement, so if this fixture hex is ever wrong the observation becomes a REFUSAL and the positive claims below go red, rather than a bad digest silently flowing into the carrier. That is the same construction wall the artifact axis relies on, exercised by the witness that depends on it." +// valid_hex is the REAL sha512 of the ASCII string gunbc-artifact-materialization-fixture, +// reproducible with printf | sha512sum, rather than hand-typed hex. The first draft here WAS +// hand-typed and was 130 characters instead of 128; the refinement rejected it, good_observation +// became a refusal, and the three positive claims went red — which is the wall doing its job and is +// why this note exists. Built through the validating mint rather than by labelling text a digest: +// sha512_hex_digest applies the length and lowercase-hex refinement, so if this fixture hex is ever +// wrong the observation becomes a REFUSAL and the positive claims below go red, rather than a bad +// digest silently flowing into the carrier. That is the same construction wall the artifact axis +// relies on, exercised by the witness that depends on it. fn good_observation() -> Sha512FileObservation { match std.content_hash.sha512_hex_digest(hex: valid_hex) { diff --git a/dag/test/claim/self_host_body_producer_behavioral_witness_test.dag b/dag/test/claim/self_host_body_producer_behavioral_witness_test.dag index 1911e5a070a..8658f2c35a5 100644 --- a/dag/test/claim/self_host_body_producer_behavioral_witness_test.dag +++ b/dag/test/claim/self_host_body_producer_behavioral_witness_test.dag @@ -2,7 +2,12 @@ module test.claim.self_host_body_producer_behavioral_witness import tools.self_host_module_behavioral_transport_roster { compiler_module_behavioral_receipt_for } -data self_host_body_producer_behavioral_witness_doc: String = "Wet self-host behavioral receipt probe for Wave 2 easy-flip lane (03_body_producer): tools.self_host_module_behavioral_transport_roster's compiler_module_behavioral_receipt_for emits src/v2/compiler/03_body_producer.dag via gunbc --entry, assembles a seed-linked v1_compiled crate (gunbc-emitted entry + dep shims + v1-compiler path dep), runs cargo build + witness (plain + --inject-fault), and claim-run on structured_body_dispatch. Live host effects — nightly falsifier Wet batch when frontier row is SelfEmitted with binding." +// Wet self-host behavioral receipt probe for Wave 2 easy-flip lane (03_body_producer): +// tools.self_host_module_behavioral_transport_roster's compiler_module_behavioral_receipt_for emits +// src/v2/compiler/03_body_producer.dag via gunbc --entry, assembles a seed-linked v1_compiled crate +// (gunbc-emitted entry + dep shims + v1-compiler path dep), runs cargo build + witness (plain + +// --inject-fault), and claim-run on structured_body_dispatch. Live host effects — nightly falsifier +// Wet batch when frontier row is SelfEmitted with binding. test fn self_host_body_producer_behavioral_receipt_holds() -> Bool { compiler_module_behavioral_receipt_for(module_path: "src/v2/compiler/03_body_producer.dag") diff --git a/dag/test/claim/self_host_discovery_enumeration_behavioral_witness_test.dag b/dag/test/claim/self_host_discovery_enumeration_behavioral_witness_test.dag index 6c984c7f5bb..aaabdac1cfd 100644 --- a/dag/test/claim/self_host_discovery_enumeration_behavioral_witness_test.dag +++ b/dag/test/claim/self_host_discovery_enumeration_behavioral_witness_test.dag @@ -2,7 +2,12 @@ module test.claim.self_host_discovery_enumeration_behavioral_witness import tools.self_host_module_behavioral_transport_roster { compiler_module_behavioral_receipt_for } -data self_host_discovery_enumeration_behavioral_witness_doc: String = "Wet self-host behavioral receipt probe for Wave 2 Band A (discovery_enumeration): tools.self_host_module_behavioral_transport_roster's compiler_module_behavioral_receipt_for emits src/v2/compiler/discovery_enumeration.dag via gunbc --entry, assembles a shim-free v1_compiled crate (emitted lib.rs + seed-linked v1-compiler path dep), runs cargo build + witness (plain + --inject-fault), and claim-run on discovery_enumeration_test. Live host effects — nightly falsifier Wet batch when frontier row is SelfEmitted with binding." +// Wet self-host behavioral receipt probe for Wave 2 Band A (discovery_enumeration): +// tools.self_host_module_behavioral_transport_roster's compiler_module_behavioral_receipt_for emits +// src/v2/compiler/discovery_enumeration.dag via gunbc --entry, assembles a shim-free v1_compiled +// crate (emitted lib.rs + seed-linked v1-compiler path dep), runs cargo build + witness (plain + +// --inject-fault), and claim-run on discovery_enumeration_test. Live host effects — nightly +// falsifier Wet batch when frontier row is SelfEmitted with binding. test fn self_host_discovery_enumeration_behavioral_receipt_holds() -> Bool { compiler_module_behavioral_receipt_for(module_path: "src/v2/compiler/discovery_enumeration.dag") diff --git a/dag/test/claim/self_host_emitted_call_target_realization_witness_test.dag b/dag/test/claim/self_host_emitted_call_target_realization_witness_test.dag index 838251cd222..0ea8026f640 100644 --- a/dag/test/claim/self_host_emitted_call_target_realization_witness_test.dag +++ b/dag/test/claim/self_host_emitted_call_target_realization_witness_test.dag @@ -4,7 +4,27 @@ import v2.std.live_tree { LiveTreeDisposition, SubstrateInputsOnly } data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data emitted_call_target_realization_witness_note: String = "PERMANENT REGRESSION CONTROLS for the three emission defects that stood between the v2 compiler closure and a Rust crate rustc would accept (gunbc#9664 milestones 1 and 2). All three are one family -- emission ASSERTING a realization it had not established -- and each row here is the discriminating RED for one of them, paired with a boundary control that would go red if the repair had over-reached in the opposite direction.\n\nMEASURED POPULATIONS on the emitted closure at main 6447dd4, by `gunbc compile --entry src/v2/compiler/00_compile.dag --target rust` then `cargo check`: 260 coded errors, 254 of them E0425. Class C 102 (98 `v2` + 4 `std`), length 73, class B 65 (member 11, apply 11, is_empty 5, allocate_literal 4, step 3, init 3, and a tail of ones and twos).\n\nWHY THESE ARE NOT A SNAPSHOT. Each class's positive and negative assertion differ only in the fact the repair added, so no single edit satisfies both directions. The C rows would flip if decl_name reverted to the authored spelling; the length rows would flip if the registry membership gate were removed OR if the declaration fallback were extended to seams; the B rows would flip if runtime_bridge went back to a literal. The boundary controls (empty_map, a real bridge method) would flip if any of the three repairs had instead stopped emission reaching v1_rt at all.\n\nDISSOLVE-ON: never. Emission may change target SPELLING, but it may never again name a runtime symbol it has not established exists." +// PERMANENT REGRESSION CONTROLS for the three emission defects that stood between the v2 compiler +// closure and a Rust crate rustc would accept (gunbc#9664 milestones 1 and 2). All three are one +// family -- emission ASSERTING a realization it had not established -- and each row here is the +// discriminating RED for one of them, paired with a boundary control that would go red if the +// repair had over-reached in the opposite direction. +// +// MEASURED POPULATIONS on the emitted closure at main 6447dd4, by `gunbc compile --entry +// src/v2/compiler/00_compile.dag --target rust` then `cargo check`: 260 coded errors, 254 of them +// E0425. Class C 102 (98 `v2` + 4 `std`), length 73, class B 65 (member 11, apply 11, is_empty 5, +// allocate_literal 4, step 3, init 3, and a tail of ones and twos). +// +// WHY THESE ARE NOT A SNAPSHOT. Each class's positive and negative assertion differ only in the +// fact the repair added, so no single edit satisfies both directions. The C rows would flip if +// decl_name reverted to the authored spelling; the length rows would flip if the registry +// membership gate were removed OR if the declaration fallback were extended to seams; the B rows +// would flip if runtime_bridge went back to a literal. The boundary controls (empty_map, a real +// bridge method) would flip if any of the three repairs had instead stopped emission reaching v1_rt +// at all. +// +// DISSOLVE-ON: never. Emission may change target SPELLING, but it may never again name a runtime +// symbol it has not established exists. // THE PROBE IMPORTS v2.std.collection AND THEN CALLS IT BY ITS QUALIFIED NAME, which looks // redundant and is not. compile_dag_rust_emit_check compiles through the witness harness's diff --git a/dag/test/claim/self_host_generation_identity_witness_test.dag b/dag/test/claim/self_host_generation_identity_witness_test.dag index 9a5c09ffbd6..b7f2ff8e77e 100644 --- a/dag/test/claim/self_host_generation_identity_witness_test.dag +++ b/dag/test/claim/self_host_generation_identity_witness_test.dag @@ -136,12 +136,11 @@ test fn generation_identity_agrees_with_itself() -> Bool { generation_identity_agrees(left: gi_baseline(), right: gi_baseline()) } -// THE KEYSTONE DISCRIMINATING RED, stated as a conjunction rather than as six -// separate greens so a silently-dropped arm cannot pass unnoticed. For every one of -// the six axes: perturbing that axis alone must (a) break overall agreement, (b) -// report exactly ONE mismatched axis, and (c) report THAT axis by name. Clause (c) -// is what a single opaque compiler_identity scalar cannot satisfy — it would fail -// (b) and (c) together by reporting an undifferentiated mismatch. +// THE KEYSTONE DISCRIMINATING RED, stated as a conjunction rather than six separate greens so a +// silently-dropped arm cannot pass unnoticed. For each of the six axes, perturbing it alone must +// (a) break overall agreement, (b) report exactly ONE mismatched axis, and (c) name THAT axis. +// Clause (c) is what a single opaque compiler_identity scalar cannot satisfy — it fails (b) and +// (c) together with an undifferentiated mismatch. test fn each_axis_perturbation_names_exactly_its_own_axis() -> Bool { for_all( xs: generation_axes, @@ -205,12 +204,11 @@ fn gi_unbuilt() -> GenerationIdentity { } } -// THE EMPTY-OBSERVATION NARROW CONTROL. Two generations that were never built do -// NOT agree on the artifact axis. Neither side carries an observed artifact, so -// answering `true` would render "we could not observe either artifact" as "the -// artifacts agree" — ⊥-as-ignorance reported as ⊥-as-answer. This is the arm most -// likely to be quietly relaxed later, which is why it is asserted in both -// directions: unbuilt-vs-unbuilt and unbuilt-vs-built. +// THE EMPTY-OBSERVATION NARROW CONTROL. Two generations never built do NOT agree on the artifact +// axis: neither side carries an observed artifact, so `true` would render "we could not observe +// either artifact" as "the artifacts agree" — ⊥-as-ignorance reported as ⊥-as-answer. The arm most +// likely to be quietly relaxed later, so asserted in both directions: unbuilt-vs-unbuilt and +// unbuilt-vs-built. test fn two_unmaterialized_artifacts_do_not_agree() -> Bool { !generation_axis_agrees( left: gi_unbuilt(), @@ -369,11 +367,10 @@ fn gi_ordered(roster: SourceClosureRoster) -> Bool { } } -// FORGERY CONTROL. Text that is not a valid SHA-512 digest cannot become a -// materialized artifact. Before ObservedArtifactDigest was sole_constructor over a -// validated digest, the axis was typed as the structural Hash that -// symbol_identity_digest mints from ANY symbol, so an artifact identity could be -// authored with no build, no file and no observation behind it. +// FORGERY CONTROL. Text that is not a valid SHA-512 digest cannot become a materialized artifact. +// Before ObservedArtifactDigest was sole_constructor over a validated digest, the axis was typed as +// the structural Hash symbol_identity_digest mints from ANY symbol, so an artifact identity could be +// authored with no build, file or observation behind it. test fn unobserved_text_cannot_become_a_materialized_artifact() -> Bool { match gi_artifact(hex: "not-a-digest") { ArtifactMaterialized { digest: _ } => false diff --git a/dag/test/claim/self_host_logic_behavioral_witness_test.dag b/dag/test/claim/self_host_logic_behavioral_witness_test.dag index 68ddf669754..e48b1cc60a1 100644 --- a/dag/test/claim/self_host_logic_behavioral_witness_test.dag +++ b/dag/test/claim/self_host_logic_behavioral_witness_test.dag @@ -2,7 +2,13 @@ module test.claim.self_host_logic_behavioral_witness import tools.self_host_logic_behavioral_transport { slb_behavioral_receipt_holds } -data self_host_logic_behavioral_witness_doc: String = "Wet self-host behavioral receipt probe for Wave 1 Gate 4 (weak self-host behavioral receipt): tools.self_host_logic_behavioral_transport emits dag/std/logic.dag via the real gunbc binary, compiles the emitted Rust against the v1-compiler seed crate, and runs the resulting witness binary (plain + --inject-fault) to prove emit -> compile -> run -> equals-seed behavioral equivalence by execution. Live host effects (cargo build, process execution), so it runs in the nightly falsifier Wet follow-on batch (falsifier_self_host_wet_entries), not per-PR hermetic discovery or bin_witness_wet — the proven template lane for Wave 2 self-host receipts." +// Wet self-host behavioral receipt probe for Wave 1 Gate 4 (weak self-host behavioral receipt): +// tools.self_host_logic_behavioral_transport emits dag/std/logic.dag via the real gunbc binary, +// compiles the emitted Rust against the v1-compiler seed crate, and runs the resulting witness +// binary (plain + --inject-fault) to prove emit -> compile -> run -> equals-seed behavioral +// equivalence by execution. Live host effects (cargo build, process execution), so it runs in the +// nightly falsifier Wet follow-on batch (falsifier_self_host_wet_entries), not per-PR hermetic +// discovery or bin_witness_wet — the proven template lane for Wave 2 self-host receipts. test fn self_host_logic_behavioral_receipt_holds() -> Bool { slb_behavioral_receipt_holds() diff --git a/dag/test/claim/self_host_materialization_carriers_behavioral_witness_test.dag b/dag/test/claim/self_host_materialization_carriers_behavioral_witness_test.dag index 56c21334cfa..1396e3640ae 100644 --- a/dag/test/claim/self_host_materialization_carriers_behavioral_witness_test.dag +++ b/dag/test/claim/self_host_materialization_carriers_behavioral_witness_test.dag @@ -2,7 +2,15 @@ module test.claim.self_host_materialization_carriers_behavioral_witness import tools.self_host_module_behavioral_transport_roster { compiler_module_behavioral_receipt_for } -data self_host_materialization_carriers_behavioral_witness_doc: String = "Wet self-host behavioral receipt probe for Gate-A flip wave (materialization_carriers): compares gunbc-emitted vs seed v2_compiler_materialization_note; --inject-fault perturbs emitted comparison (not driver flag). ROUTE STANDING (2026-08-26): this row previously said it was enrolled on the nightly falsifier when its frontier row was SelfEmitted. Both things it named are gone -- falsifier.yml was deleted at 611fd02770/#8283 on 2026-08-15 and the self-host frontier roster no longer exists -- so the sentence cited two dead authorities for one live fact. The route standing for this receipt is now derived at ROW grain by v2.compiler.self_host.wet_receipt_route_standing wet_receipt_route_standings, which says whether the row can be run and, when it cannot, the exact missing fact: a revoked binding is not the same cause as one never established, and a cadence-grain Boolean could not tell them apart." +// Wet self-host behavioral receipt probe for Gate-A flip wave (materialization_carriers): compares +// gunbc-emitted vs seed v2_compiler_materialization_note; --inject-fault perturbs emitted +// comparison (not driver flag). ROUTE STANDING (2026-08-26): this row previously claimed nightly +// falsifier enrollment while its frontier row was SelfEmitted; both are gone — falsifier.yml was +// deleted at 611fd02770/#8283 on 2026-08-15 and the self-host frontier roster no longer exists — so +// it cited two dead authorities for one live fact. Route standing is now derived at ROW grain by +// v2.compiler.self_host.wet_receipt_route_standing wet_receipt_route_standings, which says whether +// the row can run and, when not, the exact missing fact: a revoked binding is not the same cause as +// one never established, and a cadence-grain Boolean could not tell them apart. test fn self_host_materialization_carriers_behavioral_receipt_holds() -> Bool { compiler_module_behavioral_receipt_for(module_path: "src/v2/compiler/materialization_carriers.dag") diff --git a/dag/test/claim/self_host_parse_engine_hooks_behavioral_witness_test.dag b/dag/test/claim/self_host_parse_engine_hooks_behavioral_witness_test.dag index 9e71e9449ca..df926ecebd5 100644 --- a/dag/test/claim/self_host_parse_engine_hooks_behavioral_witness_test.dag +++ b/dag/test/claim/self_host_parse_engine_hooks_behavioral_witness_test.dag @@ -2,7 +2,12 @@ module test.claim.self_host_parse_engine_hooks_behavioral_witness import tools.self_host_module_behavioral_transport_roster { compiler_module_behavioral_receipt_for } -data self_host_parse_engine_hooks_behavioral_witness_doc: String = "Wet self-host behavioral receipt probe for Wave 2 Band A (parse_engine_hooks): tools.self_host_module_behavioral_transport_roster's compiler_module_behavioral_receipt_for emits src/v2/compiler/parse_engine_hooks.dag via gunbc --entry, assembles a seed-linked v1_compiled crate (shim-free — gunbc-emitted lib.rs + v1-compiler path dep), runs cargo build + witness (plain + --inject-fault), and equals-eval on parse_engine_hooks_test. Live host effects — nightly falsifier Wet batch when frontier row is SelfEmitted with binding." +// Wet self-host behavioral receipt probe for Wave 2 Band A (parse_engine_hooks): +// tools.self_host_module_behavioral_transport_roster's compiler_module_behavioral_receipt_for emits +// src/v2/compiler/parse_engine_hooks.dag via gunbc --entry, assembles a seed-linked v1_compiled +// crate (shim-free — gunbc-emitted lib.rs + v1-compiler path dep), runs cargo build + witness +// (plain + --inject-fault), and equals-eval on parse_engine_hooks_test. Live host effects — nightly +// falsifier Wet batch when frontier row is SelfEmitted with binding. test fn self_host_parse_engine_hooks_behavioral_receipt_holds() -> Bool { compiler_module_behavioral_receipt_for(module_path: "src/v2/compiler/parse_engine_hooks.dag") diff --git a/dag/test/claim/self_host_program_assembly_behavioral_witness_test.dag b/dag/test/claim/self_host_program_assembly_behavioral_witness_test.dag index ca6f4c874d8..c9881e2c7c7 100644 --- a/dag/test/claim/self_host_program_assembly_behavioral_witness_test.dag +++ b/dag/test/claim/self_host_program_assembly_behavioral_witness_test.dag @@ -2,7 +2,11 @@ module test.claim.self_host_program_assembly_behavioral_witness import tools.self_host_module_behavioral_transport_roster { compiler_module_behavioral_receipt_for } -data self_host_program_assembly_behavioral_witness_doc: String = "Wet self-host behavioral receipt probe for Gate-A flip lane (program_assembly): compares gunbc-emitted vs seed program_assembly_prepare_once_note (program_assembly.dag module authority constant); --inject-fault perturbs emitted comparison (not driver flag). Full assembly-tree walk deferred until emit surface greens (#6775). Live host effects — enroll when frontier flips SelfEmitted with binding." +// Wet self-host behavioral receipt probe for Gate-A flip lane (program_assembly): compares +// gunbc-emitted vs seed program_assembly_prepare_once_note (program_assembly.dag module authority +// constant); --inject-fault perturbs emitted comparison (not driver flag). Full assembly-tree walk +// deferred until emit surface greens (#6775). Live host effects — enroll when frontier flips +// SelfEmitted with binding. test fn self_host_program_assembly_behavioral_receipt_holds() -> Bool { compiler_module_behavioral_receipt_for(module_path: "src/v2/compiler/program_assembly.dag") diff --git a/dag/test/claim/self_host_program_partition_behavioral_witness_test.dag b/dag/test/claim/self_host_program_partition_behavioral_witness_test.dag index 2e04dbf2bbb..628f2951cf1 100644 --- a/dag/test/claim/self_host_program_partition_behavioral_witness_test.dag +++ b/dag/test/claim/self_host_program_partition_behavioral_witness_test.dag @@ -2,7 +2,11 @@ module test.claim.self_host_program_partition_behavioral_witness import tools.self_host_module_behavioral_transport_roster { compiler_module_behavioral_receipt_for } -data self_host_program_partition_behavioral_witness_doc: String = "Wet self-host behavioral receipt probe for Wave 2 parallel flip (program_partition): compares gunbc-emitted vs seed partition_structural_value_carriers_dissolution_trigger (program_partition.dag module authority constant); --inject-fault perturbs emitted comparison (not driver flag). Full partition-tree walk deferred until emit surface greens (#6775). Live host effects — enroll when frontier flips SelfEmitted with binding." +// Wet self-host behavioral receipt probe for Wave 2 parallel flip (program_partition): compares +// gunbc-emitted vs seed partition_structural_value_carriers_dissolution_trigger +// (program_partition.dag module authority constant); --inject-fault perturbs emitted comparison +// (not driver flag). Full partition-tree walk deferred until emit surface greens (#6775). Live host +// effects — enroll when frontier flips SelfEmitted with binding. test fn self_host_program_partition_behavioral_receipt_holds() -> Bool { compiler_module_behavioral_receipt_for(module_path: "src/v2/compiler/program_partition.dag") diff --git a/dag/test/claim/self_host_source_authority_behavioral_witness_test.dag b/dag/test/claim/self_host_source_authority_behavioral_witness_test.dag index 709ebfaebfa..8b815b68051 100644 --- a/dag/test/claim/self_host_source_authority_behavioral_witness_test.dag +++ b/dag/test/claim/self_host_source_authority_behavioral_witness_test.dag @@ -2,7 +2,11 @@ module test.claim.self_host_source_authority_behavioral_witness import tools.self_host_module_behavioral_transport_roster { compiler_module_behavioral_receipt_for } -data self_host_source_authority_behavioral_witness_doc: String = "Wet self-host behavioral receipt probe for Wave 2 Gate-A flip lane (source_authority): compares gunbc-emitted vs seed source_authority_module_note (source_authority.dag module authority constant); --inject-fault perturbs emitted comparison (not driver flag). Full source-authority tree walk deferred until emit surface greens (#6775). Live host effects — enroll when frontier flips SelfEmitted with binding." +// Wet self-host behavioral receipt probe for Wave 2 Gate-A flip lane (source_authority): compares +// gunbc-emitted vs seed source_authority_module_note (source_authority.dag module authority +// constant); --inject-fault perturbs emitted comparison (not driver flag). Full source-authority +// tree walk deferred until emit surface greens (#6775). Live host effects — enroll when frontier +// flips SelfEmitted with binding. test fn self_host_source_authority_behavioral_receipt_holds() -> Bool { compiler_module_behavioral_receipt_for(module_path: "src/v2/compiler/source_authority.dag") diff --git a/dag/test/claim/self_host_target_carriers_behavioral_witness_test.dag b/dag/test/claim/self_host_target_carriers_behavioral_witness_test.dag index 46123552ef3..f7f2005a73d 100644 --- a/dag/test/claim/self_host_target_carriers_behavioral_witness_test.dag +++ b/dag/test/claim/self_host_target_carriers_behavioral_witness_test.dag @@ -2,7 +2,12 @@ module test.claim.self_host_target_carriers_behavioral_witness import tools.self_host_module_behavioral_transport_roster { compiler_module_behavioral_receipt_for } -data self_host_target_carriers_behavioral_witness_doc: String = "Wet self-host behavioral receipt probe for Wave 2 Band A (07_target_carriers): tools.self_host_module_behavioral_transport_roster's compiler_module_behavioral_receipt_for emits src/v2/compiler/07_target_carriers.dag via gunbc --entry, assembles a shim-free v1_compiled crate (emitted lib.rs + seed-linked v1-compiler path dep), runs cargo build + witness (plain + --inject-fault), and claim-run on target_carriers_fidelity_test. Live host effects — nightly falsifier Wet batch when frontier row is SelfEmitted with binding." +// Wet self-host behavioral receipt probe for Wave 2 Band A (07_target_carriers): +// tools.self_host_module_behavioral_transport_roster's compiler_module_behavioral_receipt_for emits +// src/v2/compiler/07_target_carriers.dag via gunbc --entry, assembles a shim-free v1_compiled crate +// (emitted lib.rs + seed-linked v1-compiler path dep), runs cargo build + witness (plain + +// --inject-fault), and claim-run on target_carriers_fidelity_test. Live host effects — nightly +// falsifier Wet batch when frontier row is SelfEmitted with binding. test fn self_host_target_carriers_behavioral_receipt_holds() -> Bool { compiler_module_behavioral_receipt_for(module_path: "src/v2/compiler/07_target_carriers.dag") diff --git a/dag/test/claim/self_host_use_site_verdict_behavioral_witness_test.dag b/dag/test/claim/self_host_use_site_verdict_behavioral_witness_test.dag index 65c5094bc79..22d12168d9c 100644 --- a/dag/test/claim/self_host_use_site_verdict_behavioral_witness_test.dag +++ b/dag/test/claim/self_host_use_site_verdict_behavioral_witness_test.dag @@ -2,7 +2,13 @@ module test.claim.self_host_use_site_verdict_behavioral_witness import tools.self_host_module_behavioral_transport_roster { compiler_module_behavioral_receipt_for } -data self_host_use_site_verdict_behavioral_witness_doc: String = "Wet self-host behavioral receipt probe for Wave 2 Band A pilot (use_site_verdict): tools.self_host_module_behavioral_transport_roster's compiler_module_behavioral_receipt_for emits src/v2/compiler/use_site_verdict.dag via gunbc --entry, assembles a seed-linked v1_compiled crate (entry self-emitted + seed-retained dep shim + v1-compiler path dep), runs cargo build + witness (plain + --inject-fault), and equals-eval on use_site_verdict_test claims (the two supplementary claim_runs the roster row declares). Live host effects — nightly falsifier Wet batch when frontier row is SelfEmitted with binding." +// Wet self-host behavioral receipt probe for Wave 2 Band A pilot (use_site_verdict): +// tools.self_host_module_behavioral_transport_roster's compiler_module_behavioral_receipt_for emits +// src/v2/compiler/use_site_verdict.dag via gunbc --entry, assembles a seed-linked v1_compiled crate +// (entry self-emitted + seed-retained dep shim + v1-compiler path dep), runs cargo build + witness +// (plain + --inject-fault), and equals-eval on use_site_verdict_test claims (the two supplementary +// claim_runs the roster row declares). Live host effects — nightly falsifier Wet batch when +// frontier row is SelfEmitted with binding. test fn self_host_use_site_verdict_behavioral_receipt_holds() -> Bool { compiler_module_behavioral_receipt_for(module_path: "src/v2/compiler/use_site_verdict.dag") diff --git a/dag/test/claim/session_reservation_policy_witness_test.dag b/dag/test/claim/session_reservation_policy_witness_test.dag index 13e3842c0fd..8e250e27ee0 100644 --- a/dag/test/claim/session_reservation_policy_witness_test.dag +++ b/dag/test/claim/session_reservation_policy_witness_test.dag @@ -3,15 +3,14 @@ module test.claim.session_reservation_policy_witness_test // THESE TWELVE WERE AUTHORED AS PLAIN `fn` AND THEREFORE NEVER EXECUTED IN CI. // // The floor discovers witnesses by scanning source lines for the `test fn ` / `test data ` prefix -// (v1_compiler cli_run scan_test_decl_lines); a plain `fn name() -> Bool` in a file named -// *_witness_test.dag is invisible to it. So this file passed by hand under claim_batch and was -// never once folded by the required floor -- a file that reads as coverage and carries none, which -// is worse than an absent file because it is cited as coverage. Measured at the promotion: 990 -// corpus witness files use `test fn` and 9 did not, this being one of them. +// (v1_compiler cli_run scan_test_decl_lines); a plain `fn name() -> Bool` in a *_witness_test.dag +// file is invisible to it. So this file passed by hand under claim_batch and was never folded by the +// required floor -- reads as coverage, carries none, and is cited as coverage. Measured at the +// promotion: 990 corpus witness files use `test fn` and 9 did not, this among them. // -// Promoted 2026-08-27 with the session-container cut. The assertions are unchanged; only their -// discoverability is. The eight remaining plain-fn files are a pre-existing population, not -// repaired here, and are named in the cut's PR body rather than silently swept in. +// Promoted 2026-08-27 with the session-container cut; assertions unchanged, only discoverability. +// The eight remaining plain-fn files are a pre-existing population, not repaired here, named in +// the cut's PR body rather than silently swept in. import std.types { Bool, String, Int } import std.measure { byte_size, byte_size_count } @@ -50,9 +49,9 @@ data fleet: List = [ ] // THE SIZING TABLE HOLDS ROWS ONLY FOR HOSTS SOMEONE HAS TRIED TO SIZE. srv3 and srv4 are absent by -// construction rather than enumerated as not-applicable, which is the whole point of removing that -// arm: a sizing authority has no standing to answer the residency question, and an earlier cut -// answered it anyway on the strength of an ABSENT aggregate reading. +// construction rather than enumerated as not-applicable — the point of removing that arm: a sizing +// authority has no standing to answer the residency question, and an earlier cut answered it anyway +// on the strength of an ABSENT aggregate reading. test fn the_sizing_table_answers_only_how_much() -> Bool { let srv1_allows = match session_reservation_sizing_for(host: operator_host_srv1) { ReservationAllowance { bytes: b, evidence_floor: _, operator_reason: _ } => @@ -80,9 +79,9 @@ test fn the_sizing_table_answers_only_how_much() -> Bool { // AN ALLOWANCE AUTHORED FOR A SESSION-FREE HOST MUST REFUSE, and this direction was previously // UNINSPECTED: the old shape read the sizing table only inside the residency-true branch, so a row -// contradicting residency was silently ignored rather than surfaced. This is the discriminating RED -// for that hole -- it drives an allowance through the absent-residency join and requires a -// disagreement, which the old code could not have produced at all. +// contradicting residency was silently ignored. This is the discriminating RED for that hole -- it +// drives an allowance through the absent-residency join and requires a disagreement the old code +// could not have produced. test fn an_allowance_on_a_session_free_host_refuses() -> Bool { let planted = ReservationAllowance { bytes: byte_size(55834574848), @@ -131,10 +130,10 @@ test fn the_two_absences_are_distinguishable() -> Bool { srv1_bytes && srv2_unestablished && srv3_not_applicable } -// THE INTEGRATION CONTROL, AND IT IS THE ONE WHOSE ABSENCE LET THE AUTHORITY FORK THROUGH. Six -// green witnesses over the policy TABLE said nothing about whether any production projection -// consumed it, so placement could answer 52 GiB while the budget tree charged a flat 20 GiB and -// every test stayed green. This asserts the projections AGREE, host by host, over the whole fleet. +// THE INTEGRATION CONTROL, WHOSE ABSENCE LET THE AUTHORITY FORK THROUGH. Six green witnesses over +// the policy TABLE said nothing about whether any production projection consumed it, so placement +// could answer 52 GiB while the budget tree charged a flat 20 GiB with every test green. This +// asserts the projections AGREE, host by host, over the whole fleet. fn resolution_agrees_with_bytes(host: HostIdentity) -> Bool { match host_session_slice_resolution(host: host) { SessionSliceCharged { bytes: a } => @@ -230,10 +229,10 @@ test fn session_reservation_policy_holds() -> Bool { && the_evidence_names_its_execution() } -// THE TWO EMPTY ANSWERS ARE NOW DISTINGUISHABLE, AND THIS IS THE ARM THAT PROVES IT. Asserting only -// that srv2 and srv3 both yield no knobs passes against the collapsed form this replaces -- both -// returned the same empty list. The standing separates them: srv3 owes nothing, srv2's reservation -// could not be grounded, and those have opposite remedies. +// THE TWO EMPTY ANSWERS ARE NOW DISTINGUISHABLE, AND THIS ARM PROVES IT. Asserting only that srv2 +// and srv3 both yield no knobs passes against the collapsed form this replaces -- both returned the +// same empty list. The standing separates them: srv3 owes nothing, srv2's reservation could not be +// grounded, and those have opposite remedies. test fn the_two_empty_knob_answers_are_distinguishable() -> Bool { match session_knob_standing_for(host: operator_host_srv3) { SessionKnobsNotOwed { cause: _ } => true @@ -255,8 +254,8 @@ test fn the_two_empty_knob_answers_are_distinguishable() -> Bool { // AN ALLOWANCE BELOW ITS OWN EVIDENCE FLOOR CANNOT LEAVE THE SIZING FUNCTION AS AN ALLOWANCE. The // coverage predicate was consumed by a fixture against srv1 only; admit_sizing puts it on the // production path, so a row authored below its floor degrades to ReservationUnestablished instead of -// being charged. This drives the wall with a constructed violation rather than the live rows, which -// all pass -- otherwise the arm would be green by never being reached. +// being charged. This drives the wall with a constructed violation, since the live rows all pass -- +// otherwise the arm would be green by never being reached. test fn an_allowance_below_its_evidence_floor_is_refused_not_charged() -> Bool { match admit_sizing(s: ReservationAllowance { bytes: byte_size(1073741824), diff --git a/dag/test/claim/session_residency_witness_test.dag b/dag/test/claim/session_residency_witness_test.dag index 9b691345f4b..27465789a90 100644 --- a/dag/test/claim/session_residency_witness_test.dag +++ b/dag/test/claim/session_residency_witness_test.dag @@ -53,7 +53,11 @@ test fn residency_and_bool_projection_agree() -> Bool { ) } -data observation_supports_the_positive_rows_note: String = "The recorded container counts must actually support the hosts they are cited for: an observed-present arm carrying zero containers would be evidence contradicting its own conclusion, which is the shape a stale receipt takes when a host's role changes and only part of the row is updated. The verdict is projected from the evidence, so the two cannot disagree about DIRECTION; this row checks that the evidence is internally coherent." +// The recorded container counts must actually support the hosts they are cited for: an +// observed-present arm carrying zero containers would be evidence contradicting its own conclusion, +// which is the shape a stale receipt takes when a host's role changes and only part of the row is +// updated. The verdict is projected from the evidence, so the two cannot disagree about DIRECTION; +// this row checks that the evidence is internally coherent. test fn observed_present_arms_carry_a_positive_count() -> Bool { all( @@ -69,7 +73,18 @@ test fn observed_present_arms_carry_a_positive_count() -> Bool { ) } -data evidence_grade_of_the_capacity_granting_rows_note: String = "THE TWO ROWS THAT GRANT CAPACITY ARE ASSERTED TO BE OPERATOR-DECLARED, NOT OBSERVED, and this witness exists so that the distinction cannot quietly change in either direction. srv3 and srv4 are classified session-free, which is what admits them seven runner slots instead of five; that classification rests on the operator's statement plus fleet history, because neither host was reachable from the session that wrote it (srv3 refused a key login, srv4 failed host-key verification).\n\nIf someone upgrades those rows to SessionsObservedAbsent without an actual observation, this reds — which is the point, since a fabricated receipt is worse than an honest declaration. If a real observation lands and the count drops to zero, this also reds, and that failure is the scaffold gunbc.session_residency session_residency_negative_rows_dissolve_on telling its owner to dissolve it." +// THE TWO ROWS THAT GRANT CAPACITY ARE ASSERTED TO BE OPERATOR-DECLARED, NOT OBSERVED, and this +// witness exists so that the distinction cannot quietly change in either direction. srv3 and srv4 +// are classified session-free, which is what admits them seven runner slots instead of five; that +// classification rests on the operator's statement plus fleet history, because neither host was +// reachable from the session that wrote it (srv3 refused a key login, srv4 failed host-key +// verification). +// +// If someone upgrades those rows to SessionsObservedAbsent without an actual observation, this reds +// — which is the point, since a fabricated receipt is worse than an honest declaration. If a real +// observation lands and the count drops to zero, this also reds, and that failure is the scaffold +// gunbc.session_residency session_residency_negative_rows_dissolve_on telling its owner to dissolve +// it. test fn managed_host_absence_is_declared_not_observed() -> Bool { host_absence_is_operator_declared(host: operator_host_srv3) diff --git a/dag/test/claim/sessions_panel_witness_test.dag b/dag/test/claim/sessions_panel_witness_test.dag index 5f85564c553..f3cea17105d 100644 --- a/dag/test/claim/sessions_panel_witness_test.dag +++ b/dag/test/claim/sessions_panel_witness_test.dag @@ -25,7 +25,13 @@ import v2.std.live_tree { LiveTreeDisposition, SubstrateInputsOnly } data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data sessions_panel_witness_note: String = "Sessions receipts keep five axes mechanically distinct on the wire and client: session-container presence, pane/process lifecycle, configured provider versus provider observation, readiness/phase, and cleanup eligibility. A retained dead pane remains session present, projects process exited, and offers clear; the unprobed fixture projects process unobserved and cleanup unavailable. Session-list refusal remains LOUD/503 and can never become an empty successful set. Production standing refusal omits tmux rows from admission (fixture_projection_standing_refusal_tmux_entry) — the wire must not fabricate a partial session row." +// Sessions receipts keep five axes mechanically distinct on the wire and client: session-container +// presence, pane/process lifecycle, configured provider versus provider observation, +// readiness/phase, and cleanup eligibility. A retained dead pane stays session present, projects +// process exited, and offers clear; the unprobed fixture projects process unobserved and cleanup +// unavailable. Session-list refusal stays LOUD/503, never an empty successful set. Production +// standing refusal omits tmux rows from admission (fixture_projection_standing_refusal_tmux_entry) +// — the wire must not fabricate a partial session row. test fn witness_projection_standing_refusal_specimen_omits_wire_row() -> Bool { let o = Observed { @@ -106,7 +112,12 @@ test fn sessions_refusal_is_loud_on_the_wire() -> Bool { && !string_contains(s: j, pattern: "\"sessions\"") } -data sessions_client_decided_facts_note: String = "The A2 flip of this witness's pins (operator blocker 5): the client no longer composes any session prose — it paints the wire's DECIDED facts verbatim (sfx.line into the visible text, sfx.detail into the title, sact.label/detail/availability onto the cleanup chip). The former positives (sess.process_state, sess.cleanup_action, sess.cleanup_allowed, the composed 'session · present' literal) are now the discriminating NEGATIVES: any of them reappearing in the emitted source is a second session presentation authority standing back up." +// The A2 flip of this witness's pins (operator blocker 5): the client composes no session prose — +// it paints the wire's DECIDED facts verbatim (sfx.line into the visible text, sfx.detail into the +// title, sact.label/detail/availability onto the cleanup chip). The former positives +// (sess.process_state, sess.cleanup_action, sess.cleanup_allowed, the composed 'session · present' +// literal) are now the discriminating NEGATIVES: any reappearing in the emitted source is a second +// session presentation authority standing back up. test fn sessions_client_marks_presence_reobserves_and_shouts_refusal() -> Bool { let js = dispatch_client_js_source() @@ -154,7 +165,11 @@ test fn sessions_client_serializes_each_observation_source() -> Bool { && string_contains(s: js, pattern: "gunbcAttemptsObservationPending = true") } -data sessions_button_is_action_note: String = "Strengthened at A2 (the action/observation split): the sessions observer may never write the dispatch button's text at all — the former guarded caption flip ('session · present' on the button when idle) was the observation-in-the-control-position defect the falsifier exposed. Presence is recorded as a dataset fact for admission logic; the visible claim lives in the disclosure's session-facts line. The discriminating negatives are the exact strings the old mechanism emitted." +// Strengthened at A2 (the action/observation split): the sessions observer may never write the +// dispatch button's text — the former guarded caption flip ('session · present' on the button when +// idle) was the observation-in-the-control-position defect the falsifier exposed. Presence is a +// dataset fact for admission logic; the visible claim lives in the disclosure's session-facts line. +// The discriminating negatives are the exact strings the old mechanism emitted. test fn sessions_presence_does_not_overwrite_dispatch_presentation() -> Bool { let js = dispatch_client_js_source() diff --git a/dag/test/claim/shared_pool_encoding_control_test.dag b/dag/test/claim/shared_pool_encoding_control_test.dag index 23bd9cbd569..2c799a61045 100644 --- a/dag/test/claim/shared_pool_encoding_control_test.dag +++ b/dag/test/claim/shared_pool_encoding_control_test.dag @@ -42,9 +42,18 @@ data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly // The requirement, stated at the strength the evidence supports: GB10 derivation is blocked until // one canonical shared-pool construction exists AND the duplicate-pool encoding is either // unwritable or refused. -data shared_pool_repair_requirement_note: String = "Blocking condition, not a design verdict. GB10 derivation stays blocked until a single canonical shared-pool construction exists and the duplicated encoding is unwritable or refused. Which construction achieves that is undecided by these controls, and naming one here would be a terminal shape asserted from evidence that only shows the present one is ambiguous." - -data shared_pool_encoding_control_note: String = "Executed control, not an argument from reading. Three encodings of ONE physical machine -- a CPU domain and a GPU domain sharing one 128 GiB pool -- are constructed and validated. Encodings A and B differ only in which domain the pool is authored under, which is arbitrary when the pool is system-owned. Encoding C is the shape an unwary author reaches for when SharedLevelEdge is not used at all: the pool appears under BOTH domains. If C validates, the carrier permits counting one physical pool twice, and nothing in the type forces the shared-pool encoding over the duplicated one." +// Blocking condition, not a design verdict. GB10 derivation stays blocked until a single canonical +// shared-pool construction exists and the duplicated encoding is unwritable or refused. Which +// construction achieves that is undecided by these controls, and naming one here would be a +// terminal shape asserted from evidence that only shows the present one is ambiguous. + +// Executed control, not an argument from reading. Three encodings of ONE physical machine -- a CPU +// domain and a GPU domain sharing one 128 GiB pool -- are constructed and validated. Encodings A +// and B differ only in which domain the pool is authored under, which is arbitrary when the pool is +// system-owned. Encoding C is the shape an unwary author reaches for when SharedLevelEdge is not +// used at all: the pool appears under BOTH domains. If C validates, the carrier permits counting +// one physical pool twice, and nothing in the type forces the shared-pool encoding over the +// duplicated one. data cpu_domain: DomainId = "cpu" as DomainId data gpu_domain: DomainId = "gpu" as DomainId @@ -124,12 +133,12 @@ test fn witness_duplicated_pool_encoding_is_writable_and_double_counts() -> Bool shape_validates(s: dup) && summed_capacity_bytes(s: dup) == pool_bytes + pool_bytes } -// CONTROL 3: the honest shared encodings sum to the pool ONCE. Paired with control 2 this shows the -// carrier can express the correct answer and does not require it. -test fn witness_shared_encodings_sum_the_pool_once() -> Bool { - summed_capacity_bytes(s: encoding_pool_under_cpu()) == pool_bytes - && summed_capacity_bytes(s: encoding_pool_under_gpu()) == pool_bytes -} +// Removed, not weakened: a control over machine_shape_device_level_capacity compared two one-level +// specimens whose single level is necessarily the pool, so it asserted an identity rather than a +// selection property. Recorded here because a silently deleted control is indistinguishable from +// one that never existed, and because the property it seemed to cover -- that pool selection is +// stable and cannot be satisfied by a cache or register level -- is a real obligation on the +// repair. // WITHDRAWN CONTROL, recorded rather than silently dropped. An orientation-stability check over // machine_shape_device_level_capacity was authored here and removed: it looked reassuring and @@ -144,4 +153,9 @@ test fn witness_shared_encodings_sum_the_pool_once() -> Bool { // cannot change the selected pool, and that cache and register levels cannot satisfy a // model-residency demand. None of those are provable against the present carrier, which is the // finding itself. -data withdrawn_orientation_control_note: String = "Removed, not weakened: a control over machine_shape_device_level_capacity compared two one-level specimens whose single level is necessarily the pool, so it asserted an identity rather than a selection property. Recorded here because a silently deleted control is indistinguishable from one that never existed, and because the property it seemed to cover -- that pool selection is stable and cannot be satisfied by a cache or register level -- is a real obligation on the repair." +// CONTROL 3: the honest shared encodings sum to the pool ONCE. Paired with control 2 this shows the +// carrier can express the correct answer and does not require it. +test fn witness_shared_encodings_sum_the_pool_once() -> Bool { + summed_capacity_bytes(s: encoding_pool_under_cpu()) == pool_bytes + && summed_capacity_bytes(s: encoding_pool_under_gpu()) == pool_bytes +} diff --git a/dag/test/claim/shell_dag_census_5a_typed_ops_witness_test.dag b/dag/test/claim/shell_dag_census_5a_typed_ops_witness_test.dag index 1afa8962d68..33ea2b9ca60 100644 --- a/dag/test/claim/shell_dag_census_5a_typed_ops_witness_test.dag +++ b/dag/test/claim/shell_dag_census_5a_typed_ops_witness_test.dag @@ -9,7 +9,11 @@ import v2.std.live_tree { LiveTreeDisposition, SubstrateInputsOnly } data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data shell_dag_census_5a_scope_note: String = "Hermetic witnesses for the shell->dag census §5.A finite new-op list: os.Hostname.Set, systemd.Systemctl.ListUnits, systemd.Systemctl.Status, extdeps.tools.id (Uid/Gid/Lookup). Model-before-implement only (D1) — each op's mock_response proves the typed exit{}/output shape realizes hermetically; call-site migration (§5.B) is a separate, later lane. Each op cites its upstream authority in its home file's extdeps_external_authority_anchor." +// Hermetic witnesses for the shell->dag census §5.A finite new-op list: os.Hostname.Set, +// systemd.Systemctl.ListUnits, systemd.Systemctl.Status, extdeps.tools.id (Uid/Gid/Lookup). +// Model-before-implement only (D1) — each op's mock_response proves the typed exit{}/output shape +// realizes hermetically; call-site migration (§5.B) is a separate, later lane. Each op cites its +// upstream authority in its home file's extdeps_external_authority_anchor. test fn witness_hostname_set_argv_is_typed_not_concat() -> Bool { join(hostname_set_argv(desired: "srv9" as DnsLabel), " ") == "hostnamectl set-hostname srv9" diff --git a/dag/test/claim/shell_exec_run_argv_embed_witness_test.dag b/dag/test/claim/shell_exec_run_argv_embed_witness_test.dag index 7f7cbecb4f0..3e3892ba59f 100644 --- a/dag/test/claim/shell_exec_run_argv_embed_witness_test.dag +++ b/dag/test/claim/shell_exec_run_argv_embed_witness_test.dag @@ -18,7 +18,15 @@ fn src_has(path: String, needle: String) -> Bool { string_contains(s: r.content, pattern: needle) } -data apply_script_budget_flip_note: String = "FLIPPED with belt B (PR 6940): pre-B this clause asserted script_len > budget — the incident receipt that the live apply script (which embedded the whole emitted server.js) genuinely exceeded MAX_ARG_STRLEN, making the stdin transport load-bearing. Belt B removed the frozen program from deploy (gunbc serve renders live; no emitted JS in the apply script), so the live-exceedance premise is dissolved and the clause becomes the REGRESSION WALL for exactly that class: the apply script must stay UNDER the argv embed budget — re-freezing any program payload into apply reds this row. The stdin transport stays pinned by the sibling witnesses (correct for arbitrary script sizes; the general wall is dispatch_shell's ArgvExceedsHostArgMax refusal on the host_exec_arg_max_strlen authority)." +// FLIPPED with belt B (PR 6940): pre-B this clause asserted script_len > budget — the incident +// receipt that the live apply script (which embedded the whole emitted server.js) genuinely +// exceeded MAX_ARG_STRLEN, making the stdin transport load-bearing. Belt B removed the frozen +// program from deploy (gunbc serve renders live; no emitted JS in the apply script), so the +// live-exceedance premise is dissolved and the clause becomes the REGRESSION WALL for exactly that +// class: the apply script must stay UNDER the argv embed budget — re-freezing any program payload +// into apply reds this row. The stdin transport stays pinned by the sibling witnesses (correct for +// arbitrary script sizes; the general wall is dispatch_shell's ArgvExceedsHostArgMax refusal on the +// host_exec_arg_max_strlen authority). test fn witness_apply_script_stays_under_argv_embed_budget() -> Bool { let script_len = length(live_deploy_apply_script_for(spec: deployment_spec_srv1(), revision: RevisionBoundAtEmission { revision: deploy_witness_release_revision })) diff --git a/dag/test/claim/shell_stream_capture_witness_test.dag b/dag/test/claim/shell_stream_capture_witness_test.dag index 857e0bbef88..876378bf338 100644 --- a/dag/test/claim/shell_stream_capture_witness_test.dag +++ b/dag/test/claim/shell_stream_capture_witness_test.dag @@ -12,7 +12,8 @@ data witness_seed_stdout_complete_max_bytes_fixture: ByteSize = byte_size(count: data witness_seed_stderr_tail_bytes_fixture: ByteSize = byte_size(count: 16384) -data witness_seed_limit_authority_note: String = "Fixture limits mirror v1_interpreter bounded_shell_host_drain DEFAULT_SHELL_* — enforced in Rust only; this witness exercises predicate shape, not a second constant authority." +// Fixture limits mirror v1_interpreter bounded_shell_host_drain DEFAULT_SHELL_* — enforced in Rust +// only; this witness exercises predicate shape, not a second constant authority. test fn stderr_tail_within_bound_holds_for_incident_scale() -> Bool { seed_host_stderr_tail_within_bound( diff --git a/dag/test/claim/shell_target_conformance_witness_test.dag b/dag/test/claim/shell_target_conformance_witness_test.dag index a4461a763ab..36ba4ed4930 100644 --- a/dag/test/claim/shell_target_conformance_witness_test.dag +++ b/dag/test/claim/shell_target_conformance_witness_test.dag @@ -16,7 +16,16 @@ import gunbc.shell_target_conformance { implementation_and_specification_are_distinct_subjects, } -data conformance_witness_note: String = "Controls for the Bash/POSIX decomposition (DESIGN section 3, external upstream decomposition; review relayed through the operator 2026-08-04). The defect these pin: the POSIX Shell Command Language was stored as a further_citation on GNU Bash's ExternalModelScope, so one independently governed subject was recorded as a source ABOUT another. The rule is that multiple citations may ground one subject while a second governed subject is never a citation of the first. The discriminating assertion is the citation count — under the old shape Bash carried two citations and POSIX had no subject of its own, so asserting that Bash's further_citations is EMPTY goes red against the previous tree and green against this one. The rest pin the replacement: POSIX is a subject with its own scope and its own citation, and the conformance relation is a product-layer fact naming two DISTINCT subjects." +// Controls for the Bash/POSIX decomposition (DESIGN section 3, external upstream decomposition; +// review relayed through the operator 2026-08-04). The defect these pin: the POSIX Shell Command +// Language was stored as a further_citation on GNU Bash's ExternalModelScope, so one independently +// governed subject was recorded as a source ABOUT another. The rule is that multiple citations may +// ground one subject while a second governed subject is never a citation of the first. The +// discriminating assertion is the citation count — under the old shape Bash carried two citations +// and POSIX had no subject of its own, so asserting that Bash's further_citations is EMPTY goes red +// against the previous tree and green against this one. The rest pin the replacement: POSIX is a +// subject with its own scope and its own citation, and the conformance relation is a product-layer +// fact naming two DISTINCT subjects. fn citation_count_of_bash_scope() -> Int { fold(gnu_bash_model_scope.further_citations, init: 0, f: fn(acc, _c) { acc + 1 }) diff --git a/dag/test/claim/site_accent_study_witness_test.dag b/dag/test/claim/site_accent_study_witness_test.dag index 8b920bbf86b..a3051ab3797 100644 --- a/dag/test/claim/site_accent_study_witness_test.dag +++ b/dag/test/claim/site_accent_study_witness_test.dag @@ -48,7 +48,13 @@ test fn witness_g_class_is_the_live_night_figure() -> Bool { && render_label(r: g_render) == "G — yellow · 5300–6000 K" } -data signed_accent_selection_witness_note: String = "WHAT IS LEFT TO CHECK ONCE THE SIGNATURE IS A REFERENCE. This claim used to repeat the three field comparisons in witness_g_class_is_the_live_night_figure verbatim, because signed_accent_render was a second literal that could drift from g_render. It is now g_render, so those comparisons are the same expression twice and prove nothing the sibling does not — §2. What survives is the part that is still falsifiable: WHICH class the signature selects. That is a real claim about the cited classification rather than about a copy, and it reds if the selection is re-pointed at another class." +// WHAT IS LEFT TO CHECK ONCE THE SIGNATURE IS A REFERENCE. This claim used to repeat the three +// field comparisons in witness_g_class_is_the_live_night_figure verbatim, because +// signed_accent_render was a second literal that could drift from g_render. It is now g_render, so +// those comparisons are the same expression twice and prove nothing the sibling does not — §2. What +// survives is the part that is still falsifiable: WHICH class the signature selects. That is a real +// claim about the cited classification rather than about a copy, and it reds if the selection is +// re-pointed at another class. test fn witness_signed_accent_selects_the_g_class() -> Bool { signed_accent_render.spectral.code as String == "G" diff --git a/dag/test/claim/sorted_map_keys_interpreter_order_witness_test.dag b/dag/test/claim/sorted_map_keys_interpreter_order_witness_test.dag index 459fb5e64f2..52aa089c1e2 100644 --- a/dag/test/claim/sorted_map_keys_interpreter_order_witness_test.dag +++ b/dag/test/claim/sorted_map_keys_interpreter_order_witness_test.dag @@ -1,9 +1,48 @@ module test.claim.sorted_map_keys_interpreter_order_witness_test - data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data sorted_map_keys_order_contract_note: String = "sorted_map_keys HAD NO INTERPRETER ARM. It was declared in std.primitives, typed in 04_method/04_infer, registered as a Rust emit bridge, and realized in v1_rt -- but eval_builtin_inner and eval_algebra_method_inner had no handler, so the primitive existed in every realization except the one that runs .dag directly. The arm now exists (free_call.sorted_map_keys and method_call.sorted_map_keys in gunbc.v1_interpreter_primitive_surface).\n\nEXISTING IS NOT THE BAR; THE ORDER IS. Two realizations of one primitive that disagree on order are worse than one missing realization: sorted_map_keys is called precisely to make a fold deterministic (04_types container_template_alias_rows, 05_emit_rust's export and field folds), so a different-but-plausible permutation produces a stable WRONG artifact instead of a loud refusal -- the fabricated-plausible-output failure of DESIGN.md section 5.\n\nWHAT THE EMITTED REALIZATION DOES, exactly: v1_rt::sorted_map_keys is map_keys(m) followed by Vec::sort(), i.e. K's own Ord. For the String keys every corpus call site uses, that is UTF-8 byte-lexicographic order. The expected list below is that order and nothing else, and each adjacent pair separates it from an order a 'sorted' implementation could plausibly produce instead: B before a reds under case-insensitive collation, Z10 before Z9 reds under natural/numeric sorting, and the two-byte code point last reds under a Unicode collation that files it next to e. An arm that merely returns something sorted does not pass this.\n\nTHE WITNESS IS GATED ON THE ARM, MEASURED RATHER THAN ASSUMED. Deleting the two sorted_map_keys routing lines from the generated dispatch (observed before=2 after=0) and rebuilding turns this witness into NoSuchFunction { name: sorted_map_keys } -- so its green is CAUSED by the arm, not merely coincident with it. The same mutation left claim_executor --required-regen passing unchanged (first_generation_equal=true, planned=132 executed=132), which is the useful negative: the required regen phase does NOT reach any sorted_map_keys call site, so it is not evidence for this primitive and is not cited as such. This witness is.\n\nINSERTION ORDER IS NOT AN INPUT. The output must be a function of the key SET alone -- map iteration order is unspecified in both realizations -- so the same seven keys are also inserted in reverse and must yield the identical list. Without that control, an arm that returned the map traversal unchanged could pass on whichever insertion order the author happened to write.\n\nTHIS WITNESS RUNS IN THE INTERPRETER, so it pins the interpreter side of that agreement. The other side is pinned where the two implementations can actually be compared in one process: sorted_map_keys_order_tests in src/v1/stage0/src/v1_interpreter.rs asserts this arm's output EQUALS v1_rt::sorted_map_keys on the same key set -- the emitted function itself as the oracle, not a transcribed golden -- and carries the refusal controls for the key kinds that have no emitted ordering to agree with (Float, whose f64 has no Ord at all, and a mixed key set, for which no single emitted K exists)." +// sorted_map_keys HAD NO INTERPRETER ARM. It was declared in std.primitives, typed in +// 04_method/04_infer, registered as a Rust emit bridge, and realized in v1_rt -- but +// eval_builtin_inner and eval_algebra_method_inner had no handler, so the primitive existed in +// every realization except the one that runs .dag directly. The arm now exists +// (free_call.sorted_map_keys and method_call.sorted_map_keys in +// gunbc.v1_interpreter_primitive_surface). +// +// EXISTING IS NOT THE BAR; THE ORDER IS. Two realizations of one primitive that disagree on order +// are worse than one missing realization: sorted_map_keys is called precisely to make a fold +// deterministic (04_types container_template_alias_rows, 05_emit_rust's export and field folds), so +// a different-but-plausible permutation produces a stable WRONG artifact instead of a loud refusal +// -- the fabricated-plausible-output failure of DESIGN.md section 5. +// +// WHAT THE EMITTED REALIZATION DOES, exactly: v1_rt::sorted_map_keys is +// map_keys(m) followed by Vec::sort(), i.e. K's own Ord. For the String keys every corpus call site +// uses, that is UTF-8 byte-lexicographic order. The expected list below is that order and nothing +// else, and each adjacent pair separates it from an order a 'sorted' implementation could plausibly +// produce instead: B before a reds under case-insensitive collation, Z10 before Z9 reds under +// natural/numeric sorting, and the two-byte code point last reds under a Unicode collation that +// files it next to e. An arm that merely returns something sorted does not pass this. +// +// THE WITNESS IS GATED ON THE ARM, MEASURED RATHER THAN ASSUMED. Deleting the two sorted_map_keys +// routing lines from the generated dispatch (observed before=2 after=0) and rebuilding turns this +// witness into NoSuchFunction { name: sorted_map_keys } -- so its green is CAUSED by the arm, not +// merely coincident with it. The same mutation left claim_executor --required-regen passing +// unchanged (first_generation_equal=true, planned=132 executed=132), which is the useful negative: +// the required regen phase does NOT reach any sorted_map_keys call site, so it is not evidence for +// this primitive and is not cited as such. This witness is. +// +// INSERTION ORDER IS NOT AN INPUT. The output must be a function of the key SET alone -- map +// iteration order is unspecified in both realizations -- so the same seven keys are also inserted +// in reverse and must yield the identical list. Without that control, an arm that returned the map +// traversal unchanged could pass on whichever insertion order the author happened to write. +// +// THIS WITNESS RUNS IN THE INTERPRETER, so it pins the interpreter side of that agreement. The +// other side is pinned where the two implementations can actually be compared in one process: +// sorted_map_keys_order_tests in src/v1/stage0/src/v1_interpreter.rs asserts this arm's output +// EQUALS v1_rt::sorted_map_keys on the same key set -- the emitted function itself as the oracle, +// not a transcribed golden -- and carries the refusal controls for the key kinds that have no +// emitted ordering to agree with (Float, whose f64 has no Ord at all, and a mixed key set, for +// which no single emitted K exists). fn discriminating_key_map() -> Map { empty_map() diff --git a/dag/test/claim/source_annotation_attachment_witness_test.dag b/dag/test/claim/source_annotation_attachment_witness_test.dag index 8e59af12d91..aa722d87ca3 100644 --- a/dag/test/claim/source_annotation_attachment_witness_test.dag +++ b/dag/test/claim/source_annotation_attachment_witness_test.dag @@ -18,7 +18,9 @@ import std.source_annotation { source_annotation_graph_rows } -data source_annotation_attachment_offline_recipe: String = "OFFLINE LOCAL RECIPE: target/debug/claim_batch --source-root dag --entry dag/test/claim/source_annotation_attachment_witness_test.dag --functions w_leading_block_attaches_to_the_following_subject,w_consecutive_leading_captures_merge_into_one_block,w_distinct_subjects_produce_distinct_rows,w_body_grain_capture_refuses_rather_than_attaching_to_the_next_subject,w_body_grain_capture_would_otherwise_have_attached,w_trailing_capture_refuses_and_lands_no_row,w_capture_after_the_last_subject_refuses_unattached,w_attachment_refers_to_supplied_identities_and_mints_none,w_no_captures_yields_an_empty_graph_and_no_refusals" +// OFFLINE LOCAL RECIPE: target/debug/claim_batch --source-root dag --entry +// dag/test/claim/source_annotation_attachment_witness_test.dag --functions +// w_leading_block_attaches_to_the_following_subject,w_consecutive_leading_captures_merge_into_one_block,w_distinct_subjects_produce_distinct_rows,w_body_grain_capture_refuses_rather_than_attaching_to_the_next_subject,w_body_grain_capture_would_otherwise_have_attached,w_trailing_capture_refuses_and_lands_no_row,w_capture_after_the_last_subject_refuses_unattached,w_attachment_refers_to_supplied_identities_and_mints_none,w_no_captures_yields_an_empty_graph_and_no_refusals data source_annotation_attachment_note: String = "Exercises attach_annotations directly on a synthetic roster, so the attachment RULE is proven independently of either tokenizer. That separation is the point: a test that reached the fold only through the v1 lexer would pass on a fold that was wrong in a way the .dag grammar happens never to produce, and the same fold is what the v2 realization will call. diff --git a/dag/test/claim/source_integration_proof_kernel_acceptance_test.dag b/dag/test/claim/source_integration_proof_kernel_acceptance_test.dag index b992af2cbcb..79521632ddd 100644 --- a/dag/test/claim/source_integration_proof_kernel_acceptance_test.dag +++ b/dag/test/claim/source_integration_proof_kernel_acceptance_test.dag @@ -9,9 +9,26 @@ import test.claim.source_integration_proof_kernel_model_witness { data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data p1_acceptance_witness_note: String = "THE DISCRIMINATING CLOSING VALIDATION FOR roadmap node 2-scm-p1-proof-kernel. It is RED ON PURPOSE and enrolled QuarantineProbeExpectRed. The predicate is the node's complete bar, represented by the closed KernelAcceptanceCapability population: one public reconciliation fold, bounded candidate generation, occurrence dedup, context transport, commuting squares, batch-partition invariance, grounded/frame-preserving deltas, n-way invariants, order honesty, all seven semantic closure certificates, and data-only invariant extension. This first slice supplies only the bounded-candidate-generation receipt: the candidate fold derives finite combination classes and the receipt requires executing an admitted control plus proposal, delta, inference-round, and candidate-class bound refusals. KernelAcceptanceReceipt is sole-constructor, so no caller-authored Boolean can claim a capability. Generator completeness remains separately missing as KernelCandidateGenerationClosureExecutes. The derived frontier remains nonzero, cannot green on zero progress, and duplicate admissions cannot erase missing capabilities. Later slices add scenario-derived receipt constructors; they must not relax this predicate or manually decrement a count." +// THE DISCRIMINATING CLOSING VALIDATION FOR roadmap node 2-scm-p1-proof-kernel. It is RED ON +// PURPOSE and enrolled QuarantineProbeExpectRed. The predicate is the node's complete bar, +// represented by the closed KernelAcceptanceCapability population: one public reconciliation fold, +// bounded candidate generation, occurrence dedup, context transport, commuting squares, +// batch-partition invariance, grounded/frame-preserving deltas, n-way invariants, order honesty, +// all seven semantic closure certificates, and data-only invariant extension. This first slice +// supplies only the bounded-candidate-generation receipt: the candidate fold derives finite +// combination classes and the receipt requires executing an admitted control plus proposal, delta, +// inference-round, and candidate-class bound refusals. KernelAcceptanceReceipt is sole-constructor, +// so no caller-authored Boolean can claim a capability. Generator completeness remains separately +// missing as KernelCandidateGenerationClosureExecutes. The derived frontier remains nonzero, cannot +// green on zero progress, and duplicate admissions cannot erase missing capabilities. Later slices +// add scenario-derived receipt constructors; they must not relax this predicate or manually +// decrement a count. -data p1_acceptance_dissolution_note: String = "DISSOLVES BY GREENING, never deletion. When every closed capability has a passing executing scenario, this witness becomes green and the QuarantineProbeExpectRed exclusion plus known-red roster entry become wrong; the completing change must remove those two quarantine rows so this file joins ordinary DiscoverySelection as the permanent P1 regression wall. P2 capture, P3 target effects, and P0 primary projection are absent from the capability population by construction." +// DISSOLVES BY GREENING, never deletion. When every closed capability has a passing executing +// scenario, this witness becomes green and the QuarantineProbeExpectRed exclusion plus known-red +// roster entry become wrong; the completing change must remove those two quarantine rows so this +// file joins ordinary DiscoverySelection as the permanent P1 regression wall. P2 capture, P3 target +// effects, and P0 primary projection are absent from the capability population by construction. test fn witness_p1_proof_kernel_acceptance_contract_holds() -> Bool { kernel_closing_contract_holds(admissions: p1_first_slice_acceptance_admissions()) diff --git a/dag/test/claim/source_integration_proof_kernel_model_witness_test.dag b/dag/test/claim/source_integration_proof_kernel_model_witness_test.dag index 6661dc3df8e..bb645e459fb 100644 --- a/dag/test/claim/source_integration_proof_kernel_model_witness_test.dag +++ b/dag/test/claim/source_integration_proof_kernel_model_witness_test.dag @@ -41,7 +41,16 @@ import gunbc.source_integration_proof_kernel { data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data proof_kernel_model_witness_note: String = "The green first-slice witnesses exercise the candidate-generation fold from finite declared generators rather than a caller-supplied CandidateSet: one transformation plus one scheduled inference generator derives four combination classes from the accepted seed. Tightening inference_rounds or candidate_classes changes the disposition to a typed, located, counted refusal; proposal, grounding, and frame controls remain distinct. Acceptance is derived from those executed positive and negative scenarios into a sole-constructor receipt, so callers cannot assert a passing Boolean or construct the receipt outside the proof-kernel module. The capability frontier is closed and derived by set difference, so duplicate admissions cannot erase missing work and a refused admission is missing like an absent one. This suite does not claim generator completeness or the public reconciliation fold exists; those remain live capabilities in the separate quarantined closing witness." +// The green first-slice witnesses exercise the candidate-generation fold from finite declared +// generators rather than a caller-supplied CandidateSet: one transformation plus one scheduled +// inference generator derives four combination classes from the accepted seed. Tightening +// inference_rounds or candidate_classes yields a typed, located, counted refusal; proposal, +// grounding, and frame controls stay distinct. Acceptance is derived from the executed positive and +// negative scenarios into a sole-constructor receipt, so callers cannot assert a passing Boolean or +// construct the receipt outside the proof-kernel module. The capability frontier is closed and +// derived by set difference, so duplicate admissions cannot erase missing work and a refused +// admission is missing like an absent one. Not claimed here: generator completeness, or that the +// public reconciliation fold exists; both remain live in the separate quarantined closing witness. fn p1_transformation() -> KernelDirectAuthoredTransformation { KernelDirectAuthoredTransformation { diff --git a/dag/test/claim/spark/spark_bootstrap_provision_witness_test.dag b/dag/test/claim/spark/spark_bootstrap_provision_witness_test.dag index 428b34eb5a3..9a13b4800a4 100644 --- a/dag/test/claim/spark/spark_bootstrap_provision_witness_test.dag +++ b/dag/test/claim/spark/spark_bootstrap_provision_witness_test.dag @@ -52,7 +52,11 @@ data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly // constrained no longer exists and a control retained past its subject is a green assertion about // nothing. What replaces them constrains the population and the classification of legacy state. -data spark_witness_scope_note: String = "These controls cover the credential population, the pending state of every external allocation, and the refusal of the two legacy containers as authorities. They do not cover actuation, which this module no longer performs. The prior least-privilege controls were deleted with the binding set they described rather than kept: they would have continued passing while constraining code that had been removed." +// These controls cover the credential population, the pending state of every external allocation, +// and the refusal of the two legacy containers as authorities. They do not cover actuation, which +// this module no longer performs. The prior least-privilege controls were deleted with the binding +// set they described rather than kept: they would have continued passing while constraining code +// that had been removed. fn spark_population_has(host: HostIdentity, kind: SparkCredentialKind) -> Bool { fold(spark_credential_population(), init: false, f: (acc, o) => diff --git a/dag/test/claim/spark/spark_cell_role_retirement_witness_test.dag b/dag/test/claim/spark/spark_cell_role_retirement_witness_test.dag index 28a73b86397..c359a2e7ba5 100644 --- a/dag/test/claim/spark/spark_cell_role_retirement_witness_test.dag +++ b/dag/test/claim/spark/spark_cell_role_retirement_witness_test.dag @@ -128,7 +128,10 @@ import gunbc.membership_reconcile { MemberRosterDuplicateKeyRefused, } -data spark_cell_role_retirement_witness_note: String = "SPARK-PAIR-0 P0. The discriminating evidence for role separation and real serving retirement. Every claim here is written so that reverting the role assignment, or restoring the empty removal remedy, turns it red — an assertion that passes under both the old and the new model would be measuring nothing." +// SPARK-PAIR-0 P0. The discriminating evidence for role separation and real serving retirement. +// Every claim here is written so that reverting the role assignment, or restoring the empty removal +// remedy, turns it red — an assertion that passes under both the old and the new model would be +// measuring nothing. fn w_serving_addresses() -> List { [ diff --git a/dag/test/claim/spark/spark_serving_membership_witness_test.dag b/dag/test/claim/spark/spark_serving_membership_witness_test.dag index 1c09b3dc065..30bd3f261a5 100644 --- a/dag/test/claim/spark/spark_serving_membership_witness_test.dag +++ b/dag/test/claim/spark/spark_serving_membership_witness_test.dag @@ -132,7 +132,9 @@ fn plan_has_refused_address( ) } -data w_noop_note: String = "Already-correct host converging to ZERO effects is the claim most likely to be quietly false — reinstall-every-time is indistinguishable from correct from the outside. Asserts plan AND membership_effects both empty." +// Already-correct host converging to ZERO effects is the claim most likely to be quietly false — +// reinstall-every-time is indistinguishable from correct from the outside. Asserts plan AND +// membership_effects both empty. test fn w_spark_serving_desired_release_admits_for_admission_backed_witnesses() -> Bool { match spark_serving_desired_release_admission() { diff --git a/dag/test/claim/spark/spark_serving_observe_witness_test.dag b/dag/test/claim/spark/spark_serving_observe_witness_test.dag index 94096afb3af..a0a453483fc 100644 --- a/dag/test/claim/spark/spark_serving_observe_witness_test.dag +++ b/dag/test/claim/spark/spark_serving_observe_witness_test.dag @@ -174,7 +174,8 @@ test fn absent_readback_derives_absent_observation() -> Bool { } } -data unreachable_host_red_control_note: String = "RED CONTROL: an unreachable host or any probe leg that did not run must refuse observation, never license SparkServingAbsent (empty-observation narrow)." +// RED CONTROL: an unreachable host or any probe leg that did not run must refuse observation, never +// license SparkServingAbsent (empty-observation narrow). test fn unreachable_readback_does_not_derive_absent_observation() -> Bool { match derive_spark_serving_observation(readback: readback_unreachable()) { @@ -223,7 +224,8 @@ test fn load_state_probe_leg_absent_refuses_unit_outcome() -> Bool { } } -data version_parse_positive_control_note: String = "POSITIVE CONTROL: a real ollama /api/version payload must parse to the reported version string, never the desired pin." +// POSITIVE CONTROL: a real ollama /api/version payload must parse to the reported version string, +// never the desired pin. test fn version_json_positive_parses_reported_version() -> Bool { match spark_serving_parse_version_json(stdout: witness_version_json_positive) { @@ -313,7 +315,7 @@ test fn runtime_receipt_probe_words_target_executor_receipt_path() -> Bool { ) } -data version_parse_malformed_red_control_note: String = "RED CONTROL: malformed /api/version output must refuse rather than return any version." +// RED CONTROL: malformed /api/version output must refuse rather than return any version. test fn malformed_version_json_refuses_parse() -> Bool { match spark_serving_parse_version_json(stdout: "{\"version\":") { @@ -323,7 +325,8 @@ test fn malformed_version_json_refuses_parse() -> Bool { } } -data version_drift_red_control_note: String = "RED CONTROL: a different reported runtime version must not converge to the pinned release identity." +// RED CONTROL: a different reported runtime version must not converge to the pinned release +// identity. test fn different_runtime_version_refuses_loaded_identity() -> Bool { match derive_loaded_spark_serving_release_identity(readback: SparkServingReadback { @@ -648,7 +651,8 @@ test fn driver_too_old_report_is_not_success() -> Bool { } } -data p0_6_loaded_release_note: String = "P0-6: SparkServingReadback carries no configuration_digest or capacity fields; derive_loaded_spark_serving_release builds SparkServingRelease from runtime closure + model only." +// P0-6: SparkServingReadback carries no configuration_digest or capacity fields; +// derive_loaded_spark_serving_release builds SparkServingRelease from runtime closure + model only. test fn loaded_release_derivation_excludes_desired_policy_fields() -> Bool { match derive_loaded_spark_serving_release_identity(readback: readback_active_complete()) { @@ -1178,7 +1182,6 @@ test fn undecodable_key_file_output_keeps_the_account_and_reports_unread() -> Bo } } - // ═══════════════════════════════════════════════════════════════════════════════════════ // CURRENT-BOOT DURABILITY STANDING // ═══════════════════════════════════════════════════════════════════════════════════════ diff --git a/dag/test/claim/spark/spark_serving_runtime_receipt_witness_test.dag b/dag/test/claim/spark/spark_serving_runtime_receipt_witness_test.dag index 89f9b81a2e0..b4367dd6521 100644 --- a/dag/test/claim/spark/spark_serving_runtime_receipt_witness_test.dag +++ b/dag/test/claim/spark/spark_serving_runtime_receipt_witness_test.dag @@ -16,7 +16,10 @@ import gunbc.package_delivery { spark_serving_ollama_runtime_materialization_receipt_write_path, } -data witness_real_execution_split_note: String = "Filesystem write/read round-trip for the receipt is not witnessed here: shell.Mktemp.Dir and Filesystem.Write/Read have no mock_response in hermetic discovery (dag/extdeps/shell/shell.dag). JSON serialize/parse and writer/reader path identity are witnessed hermetically below; wet filesystem integration belongs in a follow-on real-execution witness if needed." +// Filesystem write/read round-trip for the receipt is not witnessed here: shell.Mktemp.Dir and +// Filesystem.Write/Read have no mock_response in hermetic discovery (dag/extdeps/shell/shell.dag). +// JSON serialize/parse and writer/reader path identity are witnessed hermetically below; wet +// filesystem integration belongs in a follow-on real-execution witness if needed. data witness_required_release_asset_digest_hex: String = "79617139521db251c716d6229505d7530171ff4d68e476d0c22dabc15726a237" diff --git a/dag/test/claim/spark/spark_serving_write_unit_operation_witness_test.dag b/dag/test/claim/spark/spark_serving_write_unit_operation_witness_test.dag index 456e6bf637e..826797efd55 100644 --- a/dag/test/claim/spark/spark_serving_write_unit_operation_witness_test.dag +++ b/dag/test/claim/spark/spark_serving_write_unit_operation_witness_test.dag @@ -37,9 +37,8 @@ import gunbc.file_access { FileTreeScope } import gunbc.spark.serving_unit_render { spark_serving_desired_user_unit_text } import gunbc.spark.serving_install_paths { spark_serving_user_unit_path, spark_serving_user_unit_dir } -// Position-wise kind, so an ordering claim asserts WHERE each kind sits rather than only how many -// of each exist. A count-only claim is satisfied by any permutation, including the one that puts the -// write before its own directory. +// Position-wise kind, so an ordering claim asserts WHERE each kind sits, not only how many exist. A +// count-only claim is satisfied by any permutation, including the write before its own directory. fn kind_at(ops: List, i: Int) -> String { match ops[i] { Absent => "" @@ -60,9 +59,9 @@ fn realize(effects: List) -> SparkServingInstallRemoteComm // ── The defect this closes ────────────────────────────────────────────────────────────────────── -// THE KEYSTONE. `WriteUserUnitFile` refused for as long as the realizer could only produce argv, and -// that refusal was reporting a MISSING TYPE rather than missing work: a file write is bytes, and -// bytes ride stdin, so no argv-shaped verdict could ever express it. It now realizes. +// THE KEYSTONE. `WriteUserUnitFile` refused as long as the realizer could only produce argv, and +// that refusal reported a MISSING TYPE, not missing work: a file write is bytes, bytes ride stdin, +// so no argv-shaped verdict could express it. It now realizes. test fn write_user_unit_file_realizes_instead_of_refusing() -> Bool { match realize(effects: [WriteUserUnitFile]) { SparkServingInstallRemoteCommandsPresent { steps: sts } => @@ -73,9 +72,9 @@ test fn write_user_unit_file_realizes_instead_of_refusing() -> Bool { } // THE BARE-HOST KEYSTONE. `~/.config/systemd/user` does not exist on a machine that has never run a -// user unit, and the file convergence opens a staging sibling with `dd` -- it does not create missing -// parents. So the mkdir must come FIRST; reversed, the write refuses on exactly the host this effect -// exists to restore. Order is asserted by position, which is the only thing that distinguishes a +// user unit, and the file convergence opens a staging sibling with `dd` — it does not create +// missing parents. So the mkdir must come FIRST; reversed, the write refuses on exactly the host +// this effect exists to restore. Order is asserted by position, the only thing distinguishing a // correct sequence from one containing the same two operations. test fn the_unit_write_is_preceded_by_a_non_privileged_mkdir() -> Bool { match realize(effects: [WriteUserUnitFile]) { @@ -94,8 +93,8 @@ test fn the_unit_write_is_preceded_by_a_non_privileged_mkdir() -> Bool { } // The mkdir targets the executor's OWN home, so sudo would be an unnecessary privilege escalation -// for a write the account can already perform. Asserted rather than assumed, because a stray sudo -// here would silently require a sudoers grant that does not exist. +// for a write the account can already perform. Asserted, because a stray sudo would silently +// require a sudoers grant that does not exist. test fn the_unit_directory_mkdir_is_not_privileged() -> Bool { match realize(effects: [WriteUserUnitFile]) { SparkServingInstallRemoteCommandsPresent { steps: sts } => @@ -112,7 +111,7 @@ test fn the_unit_directory_mkdir_is_not_privileged() -> Bool { } // It is a FILE WRITE, not an argv. A file write with an argv projection would mean bytes had been -// routed onto a command line, which is exactly what the typed-write module exists to prevent. +// routed onto a command line, exactly what the typed-write module exists to prevent. test fn the_unit_write_carries_no_argv_projection() -> Bool { match realize(effects: [WriteUserUnitFile]) { SparkServingInstallRemoteCommandsPresent { steps: sts } => @@ -122,9 +121,8 @@ test fn the_unit_write_carries_no_argv_projection() -> Bool { } } -// The bytes are the ones the renderer produces, and the path is the modeled unit path. Asserting the -// exact content is what makes this a claim about delivering the right unit rather than delivering -// something. +// The bytes are the renderer's and the path is the modeled unit path. Asserting exact content makes +// this a claim about delivering the right unit rather than delivering something. test fn the_unit_write_carries_the_rendered_bytes_at_the_modeled_path() -> Bool { match realize(effects: [WriteUserUnitFile]) { SparkServingInstallRemoteCommandsPresent { steps: sts } => @@ -144,10 +142,10 @@ test fn the_unit_write_carries_the_rendered_bytes_at_the_modeled_path() -> Bool // ── The two kinds coexist in one ordered sequence ─────────────────────────────────────────────── -// Ordering is load-bearing: the unit file must exist before the manager reloads it. A mixed sequence -// must therefore keep both kinds in order rather than partitioning them, and the counts must -// disagree — one operation of each, but only one argv — which is what proves the argv projection is -// a genuine subset and not the whole population. +// Ordering is load-bearing: the unit file must exist before the manager reloads it. A mixed +// sequence must keep both kinds in order rather than partitioning them, and the counts must +// disagree — one operation of each, but only one argv — proving the argv projection is a genuine +// subset, not the whole population. test fn a_mixed_sequence_keeps_both_kinds_and_their_order() -> Bool { match realize(effects: [WriteUserUnitFile, EnableLingerForOwnAccount]) { SparkServingInstallRemoteCommandsPresent { steps: sts } => @@ -163,9 +161,9 @@ test fn a_mixed_sequence_keeps_both_kinds_and_their_order() -> Bool { // ── What still refuses, so the widening did not become an absorbing arm ───────────────────────── -// Widening the representation must not turn unimplemented effects into successes. `RunContainerAsOwnUser` -// has no realization, and a sequence containing it still refuses whole rather than silently -// realizing the part it understands. +// Widening the representation must not turn unimplemented effects into successes. +// `RunContainerAsOwnUser` has no realization, and a sequence containing it still refuses whole +// rather than silently realizing the part it understands. test fn an_unrealized_effect_still_refuses_the_whole_sequence() -> Bool { match realize(effects: [WriteUserUnitFile, RunContainerAsOwnUser]) { SparkServingInstallRemoteCommandsRefused { reason: _ } => true @@ -187,13 +185,13 @@ test fn an_argv_effect_is_still_an_argv_operation() -> Bool { // ── The frozen operations are inside the hash, not merely inside the row ───────────────────────── // THE DEFECT THIS CLOSES, and it was mine. Freezing the operations into the typed row stopped apply -// from re-deriving the unit bytes -- but the row's wire serialized kind, member key and EFFECT NAMES +// from re-deriving the unit bytes — but the row's wire serialized kind, member key and EFFECT NAMES // only, and the bundle hash is computed over that wire. So the bytes were frozen and unverified: an -// artifact whose unit content had been swapped wholesale still hashed identically and still admitted. -// I claimed the hash covered the bytes when it did not. It does now, and this is what says so. +// artifact whose unit content had been swapped wholesale still hashed identically and admitted. I +// claimed the hash covered the bytes when it did not. It does now, and this says so. // -// Two operations differing ONLY in content must produce different wires. Same path, same mode, same -// kind, same count -- so nothing but the bytes can be doing the work. +// Two operations differing ONLY in content must produce different wires. Same path, mode, kind, +// count — nothing but the bytes can be doing the work. test fn two_writes_differing_only_in_content_have_different_wires() -> Bool { match typed_remote_file_write_seal( path: spark_serving_user_unit_path(), @@ -217,9 +215,9 @@ test fn two_writes_differing_only_in_content_have_different_wires() -> Bool { } } -// And the LABEL does not discriminate them -- which is the whole reason the wire had to exist rather -// than reusing the human rendering. This is asserted directly above; stated separately so a reader -// sees that the label collapsing is intentional, not a second bug. +// And the LABEL does not discriminate them — the whole reason the wire had to exist rather than +// reusing the human rendering. Stated separately so a reader sees the label collapsing is +// intentional, not a second bug. test fn the_wire_discriminates_where_the_label_does_not() -> Bool { match realize(effects: [WriteUserUnitFile]) { SparkServingInstallRemoteCommandsRefused { reason: _ } => false diff --git a/dag/test/claim/spark/spark_training_ready_witness_test.dag b/dag/test/claim/spark/spark_training_ready_witness_test.dag index 0558bf1533f..f842a8624c5 100644 --- a/dag/test/claim/spark/spark_training_ready_witness_test.dag +++ b/dag/test/claim/spark/spark_training_ready_witness_test.dag @@ -32,7 +32,14 @@ import gunbc.spark.training_ready { SparkUnifiedPoolUnread, } -data spark_training_ready_witness_note: String = "SPARK-PAIR-0 P0. The readiness gate's discriminating evidence. Every red here is a state the corpus can still author — an unreached probe read as absence, a reading paired with an unestablished retirement, a capture whose body is not a count, a serving cell presented as trainable — so none of these claims is green by construction. Three states that USED to be authorable are absent from this file rather than asserted: a pool measured before the retirement, a pool naming a different host than its retirement, and a capacity passed beside the capture instead of parsed from it. Each lost its constructor when the carrier absorbed the fact, and the refusals they used to prove moved into the producer's claims." +// SPARK-PAIR-0 P0. The readiness gate's discriminating evidence. Every red here is a state the +// corpus can still author — an unreached probe read as absence, a reading paired with an +// unestablished retirement, a capture whose body is not a count, a serving cell presented as +// trainable — so none of these claims is green by construction. Three states that USED to be +// authorable are absent from this file rather than asserted: a pool measured before the retirement, +// a pool naming a different host than its retirement, and a capacity passed beside the capture +// instead of parsed from it. Each lost its constructor when the carrier absorbed the fact, and the +// refusals they used to prove moved into the producer's claims. // THE FIXTURES GO THROUGH THE PRODUCERS, BECAUSE THE CARRIERS REFUSED TO BE FABRICATED. // diff --git a/dag/test/claim/spatial_frame_scale_witness_test.dag b/dag/test/claim/spatial_frame_scale_witness_test.dag index 7c3deda841b..a7fcf9bbbb6 100644 --- a/dag/test/claim/spatial_frame_scale_witness_test.dag +++ b/dag/test/claim/spatial_frame_scale_witness_test.dag @@ -84,10 +84,10 @@ test fn w_an_unregistered_frame_has_no_unit_rather_than_a_default() -> Bool { } } -// THE DEFECT THIS SLICE EXISTS TO CLOSE, asserted as a refusal rather than as a number. A TQ144 -// contact pitch is 500 um. Rounded into whole millimetres it is 0 or 1: zero puts two adjacent -// pins at the same coordinate, one doubles the package. Both are wrong and neither is visible -// downstream, so the projection has no answer and says so. +// THE DEFECT THIS SLICE EXISTS TO CLOSE, asserted as a refusal, not a number. A TQ144 contact pitch +// is 500 um. Rounded into whole millimetres it is 0 or 1: zero puts two adjacent pins at the same +// coordinate, one doubles the package. Both are wrong and neither is visible downstream, so the +// projection has no answer and says so. test fn w_a_half_millimetre_pitch_refuses_to_be_read_as_millimetres() -> Bool { let pitch = frame_length(scale: Micro, count: 500) match frame_length_as_millimeter(l: pitch) { @@ -109,9 +109,9 @@ test fn w_the_same_pitch_projects_in_its_own_unit() -> Bool { } // AND THE LOSSLESS DIRECTION IS REFUSED TOO, deliberately. 3 mm is exactly 3000 um, so a converter -// could answer this one without losing anything — which is precisely why it is worth pinning: the -// moment this function converts in the easy direction it is a unit converter, and the caller who -// wanted one received it as a side effect of asking what something measures. +// could answer this one losslessly — which is why it is worth pinning: the moment this function +// converts in the easy direction it is a unit converter, and the caller who wanted one received it +// as a side effect of asking what something measures. test fn w_a_lossless_widening_is_still_not_this_function() -> Bool { match frame_length_as_micrometer(l: frame_length(scale: Milli, count: 3)) { LengthProjected { value: _ } => false @@ -119,14 +119,12 @@ test fn w_a_lossless_widening_is_still_not_this_function() -> Bool { } } -// Scale carries members that are not decimal length steps at all. Admitting one would register a -// frame whose coordinates measure degrees or rack units while every length operation kept treating -// them as an extent. -// BINARY PREFIXES ARE NOT LENGTH UNITS, and they are the members that slipped through when -// admissibility was a fold over scale_exponent: Kibi reports Present there, so a frame could -// have registered a kibimetre. Kilo is admitted beside it because a kilometre is a real -// length — which is what makes this pair discriminating rather than a blanket refusal of -// everything above Milli. +// Scale carries members that are not decimal length steps. Admitting one would register a frame +// whose coordinates measure degrees or rack units while every length operation treated them as an +// extent. BINARY PREFIXES ARE NOT LENGTH UNITS, and they slipped through when admissibility was a +// fold over scale_exponent: Kibi reports Present there, so a frame could have registered a +// kibimetre. Kilo is admitted beside it because a kilometre is a real length — which makes this +// pair discriminating rather than a blanket refusal of everything above Milli. test fn w_a_scale_that_is_not_a_length_step_cannot_register_a_frame() -> Bool { length_scale_is_decimal(s: Nano) && !length_scale_is_decimal(s: DegreeAngle) @@ -158,7 +156,7 @@ test fn w_one_frame_cannot_be_registered_at_two_units() -> Bool { // The registration path itself, not only the predicate. A frame whose declared length unit is a // binary memory prefix must be unregistrable, and the arm it lands on must say the scale is not a -// length step rather than some generic refusal. +// length step, not some generic refusal. test fn w_a_binary_memory_prefix_cannot_register_a_frame() -> Bool { match register_frame(r: empty_frame_registry(), identity: board_frame_id(), length_scale: Kibi) { FrameRegistered { frame: _ } => false diff --git a/dag/test/claim/spatial_placement_witness_test.dag b/dag/test/claim/spatial_placement_witness_test.dag index f7b259be634..b5aa0d2bf75 100644 --- a/dag/test/claim/spatial_placement_witness_test.dag +++ b/dag/test/claim/spatial_placement_witness_test.dag @@ -155,10 +155,10 @@ test fn same_rack_unobserved_is_absent_not_false() -> Bool { } } -// Three arms, discriminating: needed is Present(true), not-needed is Present(false), and -// unobserved is Absent. The RED this pins is the collapse review 50391 found — mapping -// BootstrapNeedUnobserved to false made an unlooked-at target report "does not need -// bootstrap", so a witness asserting Present{value:false} on the third arm must fail. +// Three arms, discriminating: needed is Present(true), not-needed is Present(false), unobserved is +// Absent. The RED this pins is the collapse review 50391 found — mapping BootstrapNeedUnobserved to +// false made an unlooked-at target report "does not need bootstrap", so a witness asserting +// Present{value:false} on the third arm must fail. test fn bootstrap_need_discriminates_unobserved_from_not_needed() -> Bool { match wifi_target_needs_bootstrap(need: BootstrapNeeded) { Absent => false diff --git a/dag/test/claim/srv3/srv3_subsumption_witness_test.dag b/dag/test/claim/srv3/srv3_subsumption_witness_test.dag index b81ab0a761b..f8c5f25beb9 100644 --- a/dag/test/claim/srv3/srv3_subsumption_witness_test.dag +++ b/dag/test/claim/srv3/srv3_subsumption_witness_test.dag @@ -1,11 +1,26 @@ module test.claim.srv3_subsumption - data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data srv3_subsumption_witness_home_note: String = "Consolidated green-by-execution proofs for the gunbc-layer srv3 subsumption facts — the reach row, the authorized-keys reconcile, and the toolchain target/access pairing. These three were separate witness files (fleet_reach / host_authorized_keys_reconcile / host_toolchain_reach_pairing) until 2026-07-25; each paid a full whole-tree closure resolve in the floor as its own entry, and three gunbc-closure resolves pushed batch 3 over its wall budget. They share one closure, so they are one floor entry here — a §6 cost-shape fix (fewer entry resolves, zero coverage lost), not a merge of unrelated concerns: all three are the srv3 subsumption lane. The three original witness notes are preserved verbatim below." - -data fleet_reach_witness_note: String = "Green-by-execution proof for the CONCRETE gunbc srv3 reach row (gunbc.fleet_reach.srv3_reach), distinct from the extdeps model mechanics that test.claim.network_grounding already proves. These pin the FLEET fact: srv3_reach is the ProxyJump-through-srv2 interim (exactly one hop), its network reach is realizable (grounded live 2026-07-25 — a Permission-denied handshake from srv2 proves packets reach srv3), and its target renders to srv3's grounded address 192.168.1.221 (consuming extdeps.network.ipv4, one of the sites the fleet_intent_network bare-string residual dissolves onto). The load-bearing §5 control is srv3_fabric_intended_refuses: the dissolution TARGET (srv3_reach_fabric_intended, the FabricTunnel srv3_reach retires to when the fabric works) is a real value that HONESTLY refuses realization today, so the dissolution trigger is not just prose — a model that let the intended fabric reach fall through as realizable would red this." +// Consolidated green-by-execution proofs for the gunbc-layer srv3 subsumption facts — the reach +// row, the authorized-keys reconcile, and the toolchain target/access pairing. These three were +// separate witness files (fleet_reach / host_authorized_keys_reconcile / +// host_toolchain_reach_pairing) until 2026-07-25; each paid a full whole-tree closure resolve in +// the floor as its own entry, and three gunbc-closure resolves pushed batch 3 over its wall budget. +// They share one closure, so they are one floor entry here — a §6 cost-shape fix (fewer entry +// resolves, zero coverage lost), not a merge of unrelated concerns: all three are the srv3 +// subsumption lane. The three original witness notes are preserved verbatim below. + +// Green-by-execution proof for the CONCRETE gunbc srv3 reach row (gunbc.fleet_reach.srv3_reach), +// distinct from the extdeps model mechanics that test.claim.network_grounding already proves. These +// pin the FLEET fact: srv3_reach is the ProxyJump-through-srv2 interim (exactly one hop), its +// network reach is realizable (grounded live 2026-07-25 — a Permission-denied handshake from srv2 +// proves packets reach srv3), and its target renders to srv3's grounded address 192.168.1.221 +// (consuming extdeps.network.ipv4, one of the sites the fleet_intent_network bare-string residual +// dissolves onto). The load-bearing §5 control is srv3_fabric_intended_refuses: the dissolution +// TARGET (srv3_reach_fabric_intended, the FabricTunnel srv3_reach retires to when the fabric works) +// is a real value that HONESTLY refuses realization today, so the dissolution trigger is not just +// prose — a model that let the intended fabric reach fall through as realizable would red this. test fn srv3_reach_is_single_hop_proxy_jump() -> Bool { match srv3_reach { @@ -47,7 +62,16 @@ test fn srv3_fabric_intended_refuses_realization() -> Bool { } } -data host_authorized_keys_reconcile_witness_note: String = "Green-by-execution proof of the SSH-authorized-keys reconcile on REAL observed data (operator macbook reads of srv3/srv4, 2026-07-24). The load-bearing discriminations: srv3 (installed pre-#7027, missing the fleet key) yields exactly ONE upsert — the fleet-automation key, named specifically, not just a count — and TWO refusals, both the out-of-band keys the fleet does not own, REFUSED (not torn down). srv4 (installed with the fleet key in the seed) yields the empty converged plan — the negative control that proves the reconcile does not fabricate work. The R5-wall RED control (reconcile_would_teardown_only_if_ownership_claimed_it) reconstructs the wall's hinge: feed a ownership fn that lies 'Owned' about the foreign keys and the SAME spine WOULD emit teardowns — so the refusal is caused by ownership_of returning Absent, not by the spine being unable to teardown. That makes the wall discriminating rather than asserted." +// Green-by-execution proof of the SSH-authorized-keys reconcile on REAL observed data (operator +// macbook reads of srv3/srv4, 2026-07-24). The load-bearing discriminations: srv3 (installed +// pre-#7027, missing the fleet key) yields exactly ONE upsert — the fleet-automation key, named +// specifically, not just a count — and TWO refusals, both the out-of-band keys the fleet does not +// own, REFUSED (not torn down). srv4 (installed with the fleet key in the seed) yields the empty +// converged plan — the negative control that proves the reconcile does not fabricate work. The +// R5-wall RED control (reconcile_would_teardown_only_if_ownership_claimed_it) reconstructs the +// wall's hinge: feed a ownership fn that lies 'Owned' about the foreign keys and the SAME spine +// WOULD emit teardowns — so the refusal is caused by ownership_of returning Absent, not by the +// spine being unable to teardown. That makes the wall discriminating rather than asserted. fn srv3_plan() -> MembershipPlan { host_authorized_keys_reconcile(observed: srv3_observed_authorized_keys) @@ -131,7 +155,15 @@ test fn comment_only_drift_is_one_change_not_remove_add() -> Bool { tally.changes == 1 && tally.adds == 0 && tally.removals == 0 && tally.refusals == 0 } -data host_toolchain_reach_pairing_witness_note: String = "Discriminating witnesses for the 2026-07-24 target/access pairing in gunbc.host_toolchain_ensure. The defect being walled: access used to be looked up from the REQUESTED host while the target was resolved kind-aware, so a BuildCache request for srv3 targeted srv3 and authenticated to srv1 — the effect lands on the wrong machine and reports success. A test that merely asserts the reach resolves would pass under the old code too, so the load-bearing row here is reach_access_host_is_the_target_host, which compares the two sides of the pair and is red exactly when they disagree. Its negative control is reach_wrong_machine_pairing_is_unwritable: the old behaviour is reconstructed by hand and shown to violate the same predicate, so the predicate is proven to discriminate rather than assumed to." +// Discriminating witnesses for the 2026-07-24 target/access pairing in gunbc.host_toolchain_ensure. +// The defect being walled: access used to be looked up from the REQUESTED host while the target was +// resolved kind-aware, so a BuildCache request for srv3 targeted srv3 and authenticated to srv1 — +// the effect lands on the wrong machine and reports success. A test that merely asserts the reach +// resolves would pass under the old code too, so the load-bearing row here is +// reach_access_host_is_the_target_host, which compares the two sides of the pair and is red exactly +// when they disagree. Its negative control is reach_wrong_machine_pairing_is_unwritable: the old +// behaviour is reconstructed by hand and shown to violate the same predicate, so the predicate is +// proven to discriminate rather than assumed to. fn reach_or_absent(kind: HostToolchainKind, host: HostIdentity) -> HostToolchainReach? { match host_toolchain_ensure_reach(kind: kind, host: host) { diff --git a/dag/test/claim/srv3/srv3_token_subject_witness_test.dag b/dag/test/claim/srv3/srv3_token_subject_witness_test.dag index 4aa8e47f0c2..afabaf9fedb 100644 --- a/dag/test/claim/srv3/srv3_token_subject_witness_test.dag +++ b/dag/test/claim/srv3/srv3_token_subject_witness_test.dag @@ -22,7 +22,8 @@ data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly // admission check, so its discriminating red is a source that FAILS TO COMPILE and therefore // cannot be an assertion in a module that must compile. The wall's evidence is the required floor // refusing such a caller, which is a different instrument from this one. -data srv3_token_subject_witness_scope_note: String = "Serialization witness for Srv3TokenSubject. The admission wall on srv3_transport_token is evidenced by the floor's own refusal, not here." +// Serialization witness for Srv3TokenSubject. The admission wall on srv3_transport_token is +// evidenced by the floor's own refusal, not here. fn expected_uid_argv() -> List { ["/usr/bin/id", "-u"] diff --git a/dag/test/claim/ssh_transport_witness_test.dag b/dag/test/claim/ssh_transport_witness_test.dag index b18d4008240..86c265e3377 100644 --- a/dag/test/claim/ssh_transport_witness_test.dag +++ b/dag/test/claim/ssh_transport_witness_test.dag @@ -13,7 +13,11 @@ data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly data ssh_exec_script_remote_receiver: NonEmptyStr = "bash -s" -data ssh_apply_script_budget_flip_note: String = "FLIPPED with belt B (PR 6940), same move as test.claim.shell_exec_run_argv_embed_witness: the live apply script no longer embeds a frozen program (server.js is gone; gunbc serve renders live), so the pre-B exceedance receipt is dissolved and the clause becomes the regression wall — apply must stay UNDER the argv embed budget. The ssh ExecScript stdin transport stays pinned by the sibling witnesses regardless of script size." +// FLIPPED with belt B (PR 6940), same move as test.claim.shell_exec_run_argv_embed_witness: the +// live apply script no longer embeds a frozen program (server.js is gone; gunbc serve renders +// live), so the pre-B exceedance receipt is dissolved and the clause becomes the regression wall — +// apply must stay UNDER the argv embed budget. The ssh ExecScript stdin transport stays pinned by +// the sibling witnesses regardless of script size. test fn witness_apply_script_stays_under_argv_embed_budget() -> Bool { let script_len = length(live_deploy_apply_script_for(spec: deployment_spec_srv1(), revision: RevisionBoundAtEmission { revision: deploy_witness_release_revision })) diff --git a/dag/test/claim/stage0_regen_convergence_real_execution_witness_test.dag b/dag/test/claim/stage0_regen_convergence_real_execution_witness_test.dag index 9c8a956f151..9a7231547c0 100644 --- a/dag/test/claim/stage0_regen_convergence_real_execution_witness_test.dag +++ b/dag/test/claim/stage0_regen_convergence_real_execution_witness_test.dag @@ -6,9 +6,26 @@ import extdeps.cargo_build data live_tree_disposition: LiveTreeDisposition = ReadsLiveTree -data stage0_regen_convergence_home_doc: String = "Wet execution witness for the drift-fix's actual claim: 'the tree builds after regen', not a symbol/substring proxy for it (smart-ram-730 requirement; DESIGN witness-cost ruling — the smallest specimen that crosses the real boundary, not a realistic-looking one). cargo.Build.Run has no mock_response, so the hermetic discovery corpus refuses this file by construction; it is excluded from discovery (gunbc.ci_layer_roots witness_exclusion_frontier) and enrolled in bin_witness_wet_entries, same lane as self_host_artifact_materialization_real_execution_witness_test.dag." +// Wet execution witness for the drift-fix's actual claim: 'the tree builds after regen', not a +// symbol/substring proxy for it (smart-ram-730 requirement; DESIGN witness-cost ruling — the +// smallest specimen that crosses the real boundary, not a realistic-looking one). cargo.Build.Run +// has no mock_response, so the hermetic discovery corpus refuses this file by construction; it is +// excluded from discovery (gunbc.ci_layer_roots witness_exclusion_frontier) and enrolled in +// bin_witness_wet_entries, same lane as +// self_host_artifact_materialization_real_execution_witness_test.dag. -data why_run_verify_alone_suffices_doc: String = "One invocation, `cargo run -p v1-compiler --bin regen_stage0 -- --verify`, crosses BOTH root-cause boundaries this drift fix closed, because of the crate topology (measured, not assumed): src/v1/stage0/src/lib.rs declares `pub mod coproduct_reflection;` inside the SAME package (name = \"v1-compiler\", src/v1/stage0/Cargo.toml) that owns the `regen_stage0` bin target, so `cargo run` cannot even start without first compiling coproduct_reflection.rs — the exact file whose `StdHashMap<(Vec, ItemKind), ..>` key type required `ItemKind: Hash` and E0599'd when a regen dropped that derive (root cause 2). And `--verify` itself is the self-compile comparison that catches a checked-in seed drifted from its .dag authority without a live rebuild (root cause 1, the obs_human_elapsed two-hop bootstrap-lag class). A build failure refuses before regen ever prints its marker line; a stale-seed divergence prints regen_divergence_count > 0. Only a tree that both compiles AND self-agrees prints regen_divergence_count=0, so that exact string is the one thing this witness may accept as success — nothing weaker proves the claim." +// One invocation, `cargo run -p v1-compiler --bin regen_stage0 -- --verify`, crosses BOTH +// root-cause boundaries this drift fix closed, because of the crate topology (measured, not +// assumed): src/v1/stage0/src/lib.rs declares `pub mod coproduct_reflection;` inside the SAME +// package (name = "v1-compiler", src/v1/stage0/Cargo.toml) that owns the `regen_stage0` bin target, +// so `cargo run` cannot even start without first compiling coproduct_reflection.rs — the exact file +// whose `StdHashMap<(Vec, ItemKind), ..>` key type required `ItemKind: Hash` and E0599'd +// when a regen dropped that derive (root cause 2). And `--verify` itself is the self-compile +// comparison that catches a checked-in seed drifted from its .dag authority without a live rebuild +// (root cause 1, the obs_human_elapsed two-hop bootstrap-lag class). A build failure refuses before +// regen ever prints its marker line; a stale-seed divergence prints regen_divergence_count > 0. +// Only a tree that both compiles AND self-agrees prints regen_divergence_count=0, so that exact +// string is the one thing this witness may accept as success — nothing weaker proves the claim. data regen_stage0_success_marker: String = "regen_divergence_count=0" diff --git a/dag/test/claim/stage0_rust_source_lifecycle_scaffold_witness_test.dag b/dag/test/claim/stage0_rust_source_lifecycle_scaffold_witness_test.dag index 1a338e66e03..02f97cfddc0 100644 --- a/dag/test/claim/stage0_rust_source_lifecycle_scaffold_witness_test.dag +++ b/dag/test/claim/stage0_rust_source_lifecycle_scaffold_witness_test.dag @@ -74,7 +74,10 @@ import v2.std.collection { List } import v2.std.text { String } import std.dissolution { DissolutionCondition, dissolution_description, unbound_dissolution } -data stage0_rust_source_lifecycle_scaffold_witness_note: String = "Stage0 lifecycle scaffold witnesses after the PR B host activation. The live observation must inhabit RustManifestObserved with path evidence; typed host refusals remain distinct inputs to the existing verdict. The lifecycle classification is still an honest scaffold and may remain red on the repository-wide unclassified population." +// Stage0 lifecycle scaffold witnesses after the PR B host activation. The live observation must +// inhabit RustManifestObserved with path evidence; typed host refusals remain distinct inputs to +// the existing verdict. The lifecycle classification is still an honest scaffold and may remain red +// on the repository-wide unclassified population. test fn scaffold_note_declares_scaffold_not_live_instrument() -> Bool { string_contains(s: stage0_rust_source_lifecycle_scaffold_note, pattern: "SCAFFOLD") @@ -100,7 +103,6 @@ test fn scaffold_note_cites_zero_hand_maintained_rust_roadmap_row() -> Bool { && string_contains(s: stage0_rust_source_lifecycle_scaffold_note, pattern: "v1-honest-frontier") } - test fn scaffold_host_observation_hand_rust_receipt_is_bounded() -> Bool { let refs = stage0_rust_observation_seed_growth_justification.hand_authored_declarations let named = refs |> map(r => r.decl_name) @@ -134,7 +136,6 @@ test fn scaffold_host_observation_hand_rust_receipt_is_bounded() -> Bool { } } - test fn scaffold_join_mechanical_checks_holds() -> Bool { stage0_rust_lifecycle_scaffold_join_mechanical_checks_holds() } diff --git a/dag/test/claim/state_response_totality_witness_test.dag b/dag/test/claim/state_response_totality_witness_test.dag index 0096e5c6ef0..ecdc8afa83e 100644 --- a/dag/test/claim/state_response_totality_witness_test.dag +++ b/dag/test/claim/state_response_totality_witness_test.dag @@ -17,7 +17,12 @@ import v2.std.live_tree { LiveTreeDisposition, SubstrateInputsOnly } data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data state_response_totality_witness_note: String = "Composition slice 1's census consumer (the interaction-totality law): every (dispatch state x stateful channel) cell resolves in-family over the EMITTED stylesheet or sits under a declared ConstantByLaw ruling; cells counted, zero undeclared, cross-family and dropped-member REDs live below as planted fixtures. Shaped for later StandingIntent enrollment per gunbc.design.state_response.state_response_census_note; the registry is deliberately not built here." +// Composition slice 1's census consumer (the interaction-totality law): every (dispatch state x +// stateful channel) cell resolves in-family over the EMITTED stylesheet or sits under a declared +// ConstantByLaw ruling; cells counted, zero undeclared, cross-family and dropped-member REDs live +// below as planted fixtures. Shaped for later StandingIntent enrollment per +// gunbc.design.state_response.state_response_census_note; the registry is deliberately not built +// here. test fn state_response_family_census_clean_on_live_emission() -> Bool { return family_census_clean(css: roadmap_css(), f: dispatch_state_family, channels: dispatch_stateful_channels) @@ -30,7 +35,13 @@ test fn state_response_census_counts_hold() -> Bool { && constant_rulings_all_located(channels: dispatch_stateful_channels) } -data cross_wired_family_note: String = "The planted cross-family fixture: the ok member's selector bound to the FAIL band key — the round-5 flash class, synthesized at the roster grain. Emitting this family through the same realize folds and running the census with the TRUE roster must locate the ok cells as CrossFamilyValue naming fail. The var roots come from the real band_root_css. The fixture is selector-scoped (no base rule in the synthetic emission), so the rest member's cells also count ChannelValueMissing there — the assertion targets the located cross-family defect, never a defect-count of one." +// The planted cross-family fixture: the ok member's selector bound to the FAIL band key — the +// round-5 flash class, synthesized at the roster grain. Emitting this family through the same +// realize folds and running the census with the TRUE roster must locate the ok cells as +// CrossFamilyValue naming fail. The var roots come from the real band_root_css. The fixture is +// selector-scoped (no base rule in the synthetic emission), so the rest member's cells also count +// ChannelValueMissing there — the assertion targets the located cross-family defect, never a +// defect-count of one. data cross_wired_family: StateFamily = StateFamily { component_class: "dispatch-btn", @@ -67,7 +78,11 @@ test fn state_response_census_reds_on_cross_family_press() -> Bool { && count(defects |> filter(d => defect_is_cross_family_ok_to_fail(d: d))) > 0 } -data dropped_member_family_note: String = "The planted dropped-member fixture: the loud member absent from the roster the emission was realized from. The census with the TRUE roster must count every loud cell ChannelValueMissing — the totality question the round-5 defect never got asked (one pressed var presenting as total), now a standing red. Same selector-scoped caveat as the cross-wired fixture: rest cells also count Missing in the synthetic; the assertion targets the located loud defect." +// The planted dropped-member fixture: the loud member absent from the roster the emission was +// realized from. The census with the TRUE roster must count every loud cell ChannelValueMissing — +// the totality question the round-5 defect never got asked (one pressed var presenting as total), +// now a standing red. Same selector-scoped caveat as the cross-wired fixture: rest cells also count +// Missing in the synthetic; the assertion targets the located loud defect. data dropped_member_family: StateFamily = StateFamily { component_class: "dispatch-btn", @@ -95,7 +110,9 @@ test fn state_response_census_reds_on_dropped_member() -> Bool { && count(defects |> filter(d => defect_is_loud_missing(d: d))) > 0 } -data receipt_totality_note: String = "The fold-totality claim proven structurally, not by reading: the receipt realization must yield exactly one response rule per roster member — the shape whose absence let one pressed var present as total. This reds if the fold ever gains a filter or an arm that skips a member." +// The fold-totality claim proven structurally, not by reading: the receipt realization must yield +// exactly one response rule per roster member — the shape whose absence let one pressed var present +// as total. This reds if the fold ever gains a filter or an arm that skips a member. test fn state_response_receipt_rules_cover_the_roster() -> Bool { return count(dispatch_btn_receipt_rules(timing: respond_fast)) == count(dispatch_state_family.members) diff --git a/dag/test/claim/string_brace_escape_witness_test.dag b/dag/test/claim/string_brace_escape_witness_test.dag index 598326ea89c..92e6251b987 100644 --- a/dag/test/claim/string_brace_escape_witness_test.dag +++ b/dag/test/claim/string_brace_escape_witness_test.dag @@ -1,13 +1,26 @@ module test.claim.string_brace_escape_witness_test -data string_brace_escape_note: String = "Locks the literal-brace escape semantics (operator-directed fix 2026-07-24, the ${...}-in-strings gotcha): a '\{' escape inside a string literal produces ONE literal brace character and never starts interpolation, so shell-form strings are written \"$\\\{VAR:-default}\" — the principled form, no bare-dollar workaround. The length witnesses are the discriminators: if the escape ever leaked the backslash into the value, or interpolation ever consumed the brace, the counted lengths change and this file reds (it also fails to PARSE at all if the escape is removed from the tokenizer, which is the loudest red of the three)." +// Locks the literal-brace escape semantics (operator-directed fix 2026-07-24, the ${...}-in-strings +// gotcha): a '{' escape inside a string literal produces ONE literal brace character and never +// starts interpolation, so shell-form strings are written "$\{VAR:-default}" — the principled form, +// no bare-dollar workaround. The length witnesses are the discriminators: if the escape ever leaked +// the backslash into the value, or interpolation ever consumed the brace, the counted lengths +// change and this file reds (it also fails to PARSE at all if the escape is removed from the +// tokenizer, which is the loudest red of the three). data shell_default_form: String = "fetch $\{GITHUB_BASE_REF:-origin/main} head" data lone_escaped_brace: String = "\{" data backslash_then_brace: String = "\\\{" data escaped_pair: String = "\{x}" -data string_escape_refusal_wall_note: String = "CI enforcement for the v1 tokenizer's closed escape vocabulary. Each probe constructs its source at runtime so the witness module itself remains tokenizable, then sends that virtual module through compile_dag_rust_emit_check — the production v1 compile path. A malformed or unsupported escape must yield a hard, located tokenizer diagnostic, so compilation returns false; literal passthrough would make the virtual module compile and red the witness. The Rust tokenize_escape_receipt tests retain the finer exactly-one-ShUnknown, source identity, spelling, and full-span assertions; these discovery-enrolled .dag witnesses are their executing refusal wall." +// CI enforcement for the v1 tokenizer's closed escape vocabulary. Each probe constructs its source +// at runtime so the witness module itself remains tokenizable, then sends that virtual module +// through compile_dag_rust_emit_check — the production v1 compile path. A malformed or unsupported +// escape must yield a hard, located tokenizer diagnostic, so compilation returns false; literal +// passthrough would make the virtual module compile and red the witness. The Rust +// tokenize_escape_receipt tests retain the finer exactly-one-ShUnknown, source identity, spelling, +// and full-span assertions; these discovery-enrolled .dag witnesses are their executing refusal +// wall. fn string_escape_probe_source(body_after_backslash: String) -> String { concat( diff --git a/dag/test/claim/structured_application_mismatch_wall_witness_test.dag b/dag/test/claim/structured_application_mismatch_wall_witness_test.dag index 41db95a1e16..6c2266a0c67 100644 --- a/dag/test/claim/structured_application_mismatch_wall_witness_test.dag +++ b/dag/test/claim/structured_application_mismatch_wall_witness_test.dag @@ -4,7 +4,14 @@ import v2.std.live_tree { LiveTreeDisposition, SubstrateInputsOnly } data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data structured_application_mismatch_wall_witness_note: String = "Permanent regression controls for the structured application mismatch wall (PR #8262). The pre-wall decl_facts missing_variant specimen inlined Terminal at a ConstructionMechanism field (dissolves_to); compile-clean now refuses that state, so reflection MissingProjection probes were converted per DESIGN §4b dissolution-on-climb — not deleted without replacement. compile_dag_rust_emit_check pins the old specimen source; if the wall loosens, the RED greens and this witness fails. Record-literal call-arg handoff controls live in record_literal_call_arg_handoff_witness_test.dag plus diagnostics_witness record_literal_field_walls." +// Permanent regression controls for the structured application mismatch wall (PR #8262). The +// pre-wall decl_facts missing_variant specimen inlined Terminal at a ConstructionMechanism field +// (dissolves_to); compile-clean now refuses that state, so reflection MissingProjection probes were +// converted per DESIGN §4b dissolution-on-climb — not deleted without replacement. +// compile_dag_rust_emit_check pins the old specimen source; if the wall loosens, the RED greens and +// this witness fails. Record-literal call-arg handoff controls live in +// record_literal_call_arg_handoff_witness_test.dag plus diagnostics_witness +// record_literal_field_walls. fn w_missing_variant_terminal_at_mechanism_field_red() -> Bool { compile_dag_rust_emit_check( diff --git a/dag/test/claim/systemd_property_directive_overlap_test.dag b/dag/test/claim/systemd_property_directive_overlap_test.dag index d34fd32b56c..2ddeae7afc4 100644 --- a/dag/test/claim/systemd_property_directive_overlap_test.dag +++ b/dag/test/claim/systemd_property_directive_overlap_test.dag @@ -14,7 +14,16 @@ import std.dissolution { dissolution_trigger_ref, DissolutionCondition, BoundDis data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data overlap_witness_doc: String = "WHAT THESE WITNESSES ARE FOR, given the carrier they cover records a defect rather than repairing one. The risk with a recorded-and-not-repaired finding is that the record rots into prose nobody can check: someone splits the coproduct, or widens it, and the row still says what it said. So the claims below are about the TYPE, not about the note. The classification is asserted on both sides at named members, the mixing predicate is asserted to be currently TRUE, and the dissolution is asserted to name the declaration whose disappearance is the completion.\n\nThe mixing predicate is the one that will change, and its going FALSE is the intended future event rather than a regression -- at which point this witness and the carrier retire together, which is exactly what the DeclarationRetires trigger describes." +// WHAT THESE WITNESSES ARE FOR, given the carrier they cover records a defect rather than repairing +// one. The risk with a recorded-and-not-repaired finding is that the record rots into prose nobody +// can check: someone splits the coproduct, or widens it, and the row still says what it said. So +// the claims below are about the TYPE, not about the note. The classification is asserted on both +// sides at named members, the mixing predicate is asserted to be currently TRUE, and the +// dissolution is asserted to name the declaration whose disappearance is the completion. +// +// The mixing predicate is the one that will change, and its going FALSE is the intended future +// event rather than a regression -- at which point this witness and the carrier retire together, +// which is exactly what the DeclarationRetires trigger describes. // THE CLASSIFICATION IS ASSERTED AT NAMED MEMBERS ON BOTH SIDES, not by counting. A member on the // wrong side is the defect that would make the whole carrier misleading -- it would license writing diff --git a/dag/test/claim/tailscale_serve_route_key_witness_test.dag b/dag/test/claim/tailscale_serve_route_key_witness_test.dag index 5609a33112c..2c17e19bc05 100644 --- a/dag/test/claim/tailscale_serve_route_key_witness_test.dag +++ b/dag/test/claim/tailscale_serve_route_key_witness_test.dag @@ -56,7 +56,10 @@ type TailscaleEnableArgvMemberAt = ScopedKey TailscaleServeRouteSubject { tailscale_serve_route_subject( @@ -130,7 +133,9 @@ fn root_endpoint(backend: String) -> TailscaleServeEndpoint { } } -data w_route_key_backend_repoint_note: String = "THE STEP-1 POSITIVE CONTROL. Same listener x mount, different backend: TailscaleServeRouteKey is unchanged, so membership_reconcile must emit exactly one MemberChanged carrying both sides — a re-point, not teardown+reinstall." +// THE STEP-1 POSITIVE CONTROL. Same listener x mount, different backend: TailscaleServeRouteKey is +// unchanged, so membership_reconcile must emit exactly one MemberChanged carrying both sides — a +// re-point, not teardown+reinstall. test fn w_route_key_backend_repoint_is_modified_not_remove_add() -> Bool { let observed = [tailscale_route_subject(endpoint: root_endpoint(backend: "8080"))] @@ -165,7 +170,10 @@ data tailscale_enable_argv_resource_relation: KeyedResourceRelation Bool { let observed = [tailscale_route_subject(endpoint: root_endpoint(backend: "8080"))] @@ -184,7 +192,12 @@ test fn w_enable_argv_key_backend_repoint_is_remove_add_not_modified() -> Bool { && membership_removal_count(plan: plan) == 1 } -data w_retired_flags_key_same_route_note: String = "The deleted tailscale_serve_endpoint_key joined endpoint FLAGS only (listener + mount argv), so it did NOT trigger Remove+Add on backend drift — it shares the route key's listener x mount axis. Its defect class is argv-as-locator/path (design note 3a), not backend-as-identity. This row pins that the retired carrier is route-stable across backend re-point, so the step-1 Modified law is about structured route keys vs keys that embed mutable content (enable argv), not about flags-only flattening alone." +// The deleted tailscale_serve_endpoint_key joined endpoint FLAGS only (listener + mount argv), so +// it did NOT trigger Remove+Add on backend drift — it shares the route key's listener x mount axis. +// Its defect class is argv-as-locator/path (design note 3a), not backend-as-identity. This row pins +// that the retired carrier is route-stable across backend re-point, so the step-1 Modified law is +// about structured route keys vs keys that embed mutable content (enable argv), not about +// flags-only flattening alone. test fn w_retired_flags_key_is_route_stable_across_backend_repoint() -> Bool { let a = tailscale_route_subject(endpoint: root_endpoint(backend: "8080")) @@ -223,7 +236,10 @@ test fn membership_label_is_not_rendered_argv() -> Bool { label != argv } -data w_per_device_scope_preserves_distinct_nodes_note: String = "THE SCOPE DEFECT NO EXISTING WITNESS COULD SEE. Two tailnet devices may each own the same listener×mount route; GlobalKeyScope collapses them into one ScopedKey — the identity-collapse class the twin witnesses name when one deployment's teardown deletes another's live resource. This control must go red against GlobalKeyScope and green only after TailscaleServeScope lands." +// THE SCOPE DEFECT NO EXISTING WITNESS COULD SEE. Two tailnet devices may each own the same +// listener×mount route; GlobalKeyScope collapses them into one ScopedKey — the identity-collapse +// class the twin witnesses name when one deployment's teardown deletes another's live resource. +// This control must go red against GlobalKeyScope and green only after TailscaleServeScope lands. fn srv1_root_route_subject() -> TailscaleServeRouteSubject { tailscale_serve_route_subject( diff --git a/dag/test/claim/terminal_wire_projection_witness_test.dag b/dag/test/claim/terminal_wire_projection_witness_test.dag index 24dc032d190..d046e453bef 100644 --- a/dag/test/claim/terminal_wire_projection_witness_test.dag +++ b/dag/test/claim/terminal_wire_projection_witness_test.dag @@ -101,7 +101,14 @@ fn terminal_control_scan() -> TerminalControlScan { } } -data content_admissible_scan_note: String = "The roster fold previously asserted that EVERY one of the 65 C0/C1 members refuses, and that assertion is what encoded the defect: LF and TAB are roster members, so a multi-line diagnostic was refused and the srv1 ServiceNotReady refusal rendered as a complaint about cursor-control bytes instead of itself. The fold now skips exactly the two content-admissible members and still requires refusal for the other 63, so the wall against smuggled overwrite/erase payloads is unchanged in strength — only its extent is corrected. The admissions are asserted POSITIVELY below rather than merely un-asserted, and the discriminating RED is line-feed-on-an-open-line: a regression to blanket-allow greens the admissions but reds that control." +// The roster fold previously asserted that EVERY one of the 65 C0/C1 members refuses, and that +// assertion is what encoded the defect: LF and TAB are roster members, so a multi-line diagnostic +// was refused and the srv1 ServiceNotReady refusal rendered as a complaint about cursor-control +// bytes instead of itself. The fold now skips exactly the two content-admissible members and still +// requires refusal for the other 63, so the wall against smuggled overwrite/erase payloads is +// unchanged in strength — only its extent is corrected. The admissions are asserted POSITIVELY +// below rather than merely un-asserted, and the discriminating RED is line-feed-on-an-open-line: a +// regression to blanket-allow greens the admissions but reds that control. fn admissible_control_is_projected(rendered: String) -> Bool { match project_terminal_write( diff --git a/dag/test/claim/tool_pin_witness_test.dag b/dag/test/claim/tool_pin_witness_test.dag index 3b05980fee9..ef58bf09b48 100644 --- a/dag/test/claim/tool_pin_witness_test.dag +++ b/dag/test/claim/tool_pin_witness_test.dag @@ -62,7 +62,12 @@ data tracked_pin: Pin = Pin { }, } -data currency_family_note: String = "Currency family, REWRITTEN after review 44274 found that ExactPin returned PinFresh unconditionally — a fabricated positive. Authorship proves reproducibility, not currency: an exact pin authored three years ago is exactly as reproducible and exactly as rotten. pin_currency_gap is now TOTAL and never returns a positive verdict for either variant. RED CONTROLS are the two below: each fails if its variant ever reports anything other than a named gap, which is exactly the 'pinned and never updated' silence the refresh axis exists to break." +// Currency family, REWRITTEN after review 44274 found that ExactPin returned PinFresh +// unconditionally — a fabricated positive. Authorship proves reproducibility, not currency: an +// exact pin authored three years ago is exactly as reproducible and exactly as rotten. +// pin_currency_gap is now TOTAL and never returns a positive verdict for either variant. RED +// CONTROLS are the two below: each fails if its variant ever reports anything other than a named +// gap, which is exactly the 'pinned and never updated' silence the refresh axis exists to break. test fn exact_pin_currency_is_an_unfilled_gap() -> Bool { match pin_currency_gap(pin: authored_pin) { @@ -78,7 +83,14 @@ test fn tracked_pin_currency_is_an_unfilled_gap() -> Bool { } } -data integrity_family_note: String = "Integrity family: admission establishes ONLY that the observed binary is the one the pin declares, and is named admit_pin_integrity so it cannot be misread as a currency verdict (review 44274). RED CONTROL mismatched_identity_refuses covers what a location-based resolver cannot see at all — it finds 'a cargo' at the declared version and proceeds, where digest comparison refuses. RED CONTROL tracked_pin_refuses_even_when_identity_matches is the standing regression control for review 44242: a tracked pin whose observed digest matches EXACTLY is still refused, because its expected_identity was resolved from a moving reference with no record of that resolution." +// Integrity family: admission establishes ONLY that the observed binary is the one the pin +// declares, and is named admit_pin_integrity so it cannot be misread as a currency verdict (review +// 44274). RED CONTROL mismatched_identity_refuses covers what a location-based resolver cannot see +// at all — it finds 'a cargo' at the declared version and proceeds, where digest comparison +// refuses. RED CONTROL tracked_pin_refuses_even_when_identity_matches is the standing regression +// control for review 44242: a tracked pin whose observed digest matches EXACTLY is still refused, +// because its expected_identity was resolved from a moving reference with no record of that +// resolution. test fn matching_identity_admits_integrity() -> Bool { match admit_pin_integrity(pin: authored_pin, observed_identity: cargo_identity) { @@ -130,7 +142,14 @@ data legacy_unversioned_tool: CliTool = CliTool { installable_via: [SourceApt { package: "jq" }], } -data legacy_ingest_family_note: String = "Migration-frontier family, and the load-bearing RED for P1: EVERY CliTool row in the corpus today refuses conversion, which is the correct answer rather than a gap. ranged_legacy_tool_refuses_as_not_an_identity fails if a range is silently promoted to an identity — two hosts satisfying '>= 7.68' run different binaries, exactly the variance a pin removes, so widening here would be the absorbing fallback DESIGN section 5 forbids. unversioned_legacy_tool_refuses_as_absent keeps 'no version stated' a DISTINCT cause from 'a range stated'; collapsing the two would be a state-space conflation and would hide which deficit a given row actually has." +// Migration-frontier family, and the load-bearing RED for P1: EVERY CliTool row in the corpus today +// refuses conversion, which is the correct answer rather than a gap. +// ranged_legacy_tool_refuses_as_not_an_identity fails if a range is silently promoted to an +// identity — two hosts satisfying '>= 7.68' run different binaries, exactly the variance a pin +// removes, so widening here would be the absorbing fallback DESIGN section 5 forbids. +// unversioned_legacy_tool_refuses_as_absent keeps 'no version stated' a DISTINCT cause from 'a +// range stated'; collapsing the two would be a state-space conflation and would hide which deficit +// a given row actually has. test fn ranged_legacy_tool_refuses_as_not_an_identity() -> Bool { match admit_legacy_cli_tool(tool: legacy_ranged_tool) { @@ -184,7 +203,13 @@ test fn value_eq_covers_digest_not_only_version() -> Bool { !pin_value_eq(a: authored_pin, b: same_version_new_binary) } -data selection_is_reconcile_content_note: String = "Added after review 44329, which found pin_value_eq comparing only version and expected_identity while ignoring selection. That was a real reconcile gap, not a style point: membership_reconcile treats value_eq as presence-plus-content, so a pin whose refresh POLICY changed — ExactPin flipped to TrackedChannel, a different channel, a different window — produced no Modified hunk and would never re-upsert. The refresh policy is exactly the content this lane exists to carry, so omitting it from equality silently exempted the feature from reconciliation. RED CONTROLS below cover all three shapes of that change; each fails if value_eq ignores selection again." +// Added after review 44329, which found pin_value_eq comparing only version and expected_identity +// while ignoring selection. That was a real reconcile gap, not a style point: membership_reconcile +// treats value_eq as presence-plus-content, so a pin whose refresh POLICY changed — ExactPin +// flipped to TrackedChannel, a different channel, a different window — produced no Modified hunk +// and would never re-upsert. The refresh policy is exactly the content this lane exists to carry, +// so omitting it from equality silently exempted the feature from reconciliation. RED CONTROLS +// below cover all three shapes of that change; each fails if value_eq ignores selection again. test fn value_eq_detects_exact_to_tracked_flip() -> Bool { let flipped = Pin { @@ -227,21 +252,97 @@ test fn value_eq_still_holds_for_identical_pins() -> Bool { && (tracked_pin.selection == same.selection) } -data pin_composes_over_a_second_subject_note: String = "THE DISCRIMINATING EVIDENCE that Pin is a DIMENSION and not a renamed ToolPin (operator, 2026-07-29). A generic type proves nothing by existing — it earns the claim only when a structurally DIFFERENT subject instantiates it with zero edits to the dimension. ActionRef is that subject and it is deliberately unlike CliTool: three plain String fields (owner, repo, ref) against CliTool's NonEmptyStr name, optional VersionConstraint and List — no name, no version field, no optional, no list. It instantiates Pin, pin_value_eq and admit_pin_integrity unchanged: extdeps.pin was not touched to admit it. Under the old ToolPin shape this was unrepresentable, because the carrier demanded a tool_name string, so an action reference would have been given a fabricated name or a second pin type would have been minted — the N-types-for-one-axis failure the re-model removes. The subject is CONSUMED, not minted: checkout_action is the live row already in dag/extdeps/github/actions.dag, so this witness re-spells no fact that has a home (DESIGN section 3). It is also the lane's own documented next step rather than a synthetic exercise — hermetic-tool-provisioning-design.md section 2 records that GHA actions are tag-pinned and that a mutable tag makes SHA-pinning the hermetic form, which is exactly Pin." - -data pin_subject_soundness_pointer_note: String = "review 44850. The soundness condition this proof has to satisfy — A PIN SUBJECT MUST NOT DETERMINE ITS OWN IDENTITY — is stated in full at extdeps.pin pin_subject_must_not_be_self_identifying_note, because it is a fact about the DIMENSION rather than about any one proof of it. It is named here only to say which condition ActionRef was chosen to satisfy: an ActionRef declares no ContentHash, so expected_identity is new information with exactly one home, and the two-writable-authorities divergence the reviewer found in the previous OciDescriptor version cannot be written." - -data pin_second_subject_soundness_note: String = "review 44662, the FIRST unsound attempt at this same proof, kept because the failure repeated and the pattern is the lesson. That version instantiated Pin and was unsound two ways. (1) GRAIN: one release carries TWO architecture-specific digests while Pin carries ONE expected_identity, so the model could associate either artifact's digest with the undifferentiated release. I had recorded that as a dissolve-on trigger and treated the deferral as sufficient; it is not, and the reason is specific to what this row IS — a trigger-only deferral is legitimate on a PRODUCTION row, but this row's whole job is to prove the dimension composes, and a proof built on an ambiguous instantiation demonstrates ambiguity. (2) PARALLEL AUTHORITY: it re-minted the aarch64 hex already owned by dag/extdeps/cache/sccache.dag and re-spelled the release version as a second literal. Note that SourceGitHubRelease in extdeps.tools carries the SAME two-artifact grain (asset_aarch64 and asset_x86_64), so it was rejected here for reason (1) as well rather than reached for as the obvious neighbour. Both attempts were fixed by CHOOSING A SOUND SUBJECT instead of defending an unsound one, and the third choice is sound on the condition the note above states: an ActionRef declares no identity of its own, so there is one authority by construction, and it describes exactly one commit so the grain question cannot arise. One consequence of not routing through sccache is worth keeping: extdeps.crypto.hash.Digest and std.types.ContentHash are two digest concepts in this corpus and that route would have needed a conversion between them, laundering the fork into this witness. That fork is an unfixed section 3 candidate belonging to no lane here." - -data second_subject_double_bound_row_finding_note: String = "review 44886, and it surfaced a live CORPUS defect that has nothing to do with pinning. The first version of this proof consumed upload_artifact_action, and the reviewer reported its ref as v4 while I had read v2. Both readings are correct, which is the defect: dag/extdeps/github/actions.dag declares upload_artifact_action TWICE at module top level — ref v2 and ref v4 — and download_artifact_action twice likewise. A double-bound name in one module is an ERROR under the namespace-resolution authority (unbound/double-bound = error), but nothing refuses it today; resolution is silently last-wins, which is why actions/upload-artifact@v4 is what reaches the emitted .github/workflows/ci.yml while the v2 rows sit dead and shadowed. Introduced 2026-07-11 by #6472. It has a PRODUCTION consumer, dag/gunbc/ci_workflow.dag, so the workflow that runs this repo's CI is generated from an ambiguously bound name and no reader of the source can tell which binding won. That is reported separately rather than fixed here: it is a different lane, ci_workflow.dag is load-bearing, and a witness PR is the wrong vehicle for it. What this witness owes is only to not REST on the ambiguity, so it consumes checkout_action instead — grep-verified as the single binding of that name, along with setup_rust_action, cache_action and google_auth_action." - -data pin_channel_restates_subject_reference_finding_note: String = "THE FINDING THIS SECOND SUBJECT EARNED, which is the actual argument for having one. A generic's second consumer is supposed to expose where the dimension was shaped around its first consumer, and it did. ActionRef.ref is a moving GitHub major tag (v5 tracks the latest 5.x), so it is a CONSTRAINT-like reference, not an identity — which is why Pin is sound where Pin was not, and why version 5.0.1 above is a SELECTION satisfying that reference rather than a restatement of it. That is the same requirement-versus-selection distinction already defended for CliTool.min_version, and it holds here for the same reason. But it does NOT extend to the selection axis: had this pin been written with TrackedChannel { channel: \"v5\" }, the channel string would RESTATE subject.ref, two writable fields holding one fact — the same duplication shape review 44850 rejected on the identity axis, one axis over. The tell is that PinSelection.TrackedChannel.channel is subject-agnostic while the channel it names may already live ON the subject: for a CliTool the channel is external (latest), for an ActionRef it IS subject.ref. So channel is arguably a subject PROJECTION wearing the shape of a generic field. Not fixed here, and deliberately not papered over with a caveat: the fix is either a projection on each instantiation (the cli_tool_pin_key_of shape, which is where subject-specific projections already belong) or a selection variant that names no channel of its own, and choosing between those is dimension surgery that wants its own review rather than a rider on a witness. dissolve-on: feature:pin-selection-channel-projection. Until then this witness uses ExactPin, which has no channel field and therefore cannot exhibit the duplication." +// THE DISCRIMINATING EVIDENCE that Pin is a DIMENSION and not a renamed ToolPin (operator, +// 2026-07-29). A generic type proves nothing by existing — it earns the claim only when a +// structurally DIFFERENT subject instantiates it with zero edits to the dimension. ActionRef is +// that subject and it is deliberately unlike CliTool: three plain String fields (owner, repo, ref) +// against CliTool's NonEmptyStr name, optional VersionConstraint and List — no name, +// no version field, no optional, no list. It instantiates Pin, pin_value_eq and admit_pin_integrity +// unchanged: extdeps.pin was not touched to admit it. Under the old ToolPin shape this was +// unrepresentable, because the carrier demanded a tool_name string, so an action reference would +// have been given a fabricated name or a second pin type would have been minted — the +// N-types-for-one-axis failure the re-model removes. The subject is CONSUMED, not minted: +// checkout_action is the live row already in dag/extdeps/github/actions.dag, so this witness +// re-spells no fact that has a home (DESIGN section 3). It is also the lane's own documented next +// step rather than a synthetic exercise — hermetic-tool-provisioning-design.md section 2 records +// that GHA actions are tag-pinned and that a mutable tag makes SHA-pinning the hermetic form, which +// is exactly Pin. + +// review 44850. The soundness condition this proof has to satisfy — A PIN SUBJECT MUST NOT +// DETERMINE ITS OWN IDENTITY — is stated in full at extdeps.pin +// pin_subject_must_not_be_self_identifying_note, because it is a fact about the DIMENSION rather +// than about any one proof of it. It is named here only to say which condition ActionRef was chosen +// to satisfy: an ActionRef declares no ContentHash, so expected_identity is new information with +// exactly one home, and the two-writable-authorities divergence the reviewer found in the previous +// OciDescriptor version cannot be written. + +// review 44662, the FIRST unsound attempt at this same proof, kept because the failure repeated and +// the pattern is the lesson. That version instantiated Pin and was unsound +// two ways. (1) GRAIN: one release carries TWO architecture-specific digests while Pin carries ONE +// expected_identity, so the model could associate either artifact's digest with the +// undifferentiated release. I had recorded that as a dissolve-on trigger and treated the deferral +// as sufficient; it is not, and the reason is specific to what this row IS — a trigger-only +// deferral is legitimate on a PRODUCTION row, but this row's whole job is to prove the dimension +// composes, and a proof built on an ambiguous instantiation demonstrates ambiguity. (2) PARALLEL +// AUTHORITY: it re-minted the aarch64 hex already owned by dag/extdeps/cache/sccache.dag and +// re-spelled the release version as a second literal. Note that SourceGitHubRelease in +// extdeps.tools carries the SAME two-artifact grain (asset_aarch64 and asset_x86_64), so it was +// rejected here for reason (1) as well rather than reached for as the obvious neighbour. Both +// attempts were fixed by CHOOSING A SOUND SUBJECT instead of defending an unsound one, and the +// third choice is sound on the condition the note above states: an ActionRef declares no identity +// of its own, so there is one authority by construction, and it describes exactly one commit so the +// grain question cannot arise. One consequence of not routing through sccache is worth keeping: +// extdeps.crypto.hash.Digest and std.types.ContentHash are two digest concepts in this corpus and +// that route would have needed a conversion between them, laundering the fork into this witness. +// That fork is an unfixed section 3 candidate belonging to no lane here. + +// review 44886, and it surfaced a live CORPUS defect that has nothing to do with pinning. The first +// version of this proof consumed upload_artifact_action, and the reviewer reported its ref as v4 +// while I had read v2. Both readings are correct, which is the defect: +// dag/extdeps/github/actions.dag declares upload_artifact_action TWICE at module top level — ref v2 +// and ref v4 — and download_artifact_action twice likewise. A double-bound name in one module is an +// ERROR under the namespace-resolution authority (unbound/double-bound = error), but nothing +// refuses it today; resolution is silently last-wins, which is why actions/upload-artifact@v4 is +// what reaches the emitted .github/workflows/ci.yml while the v2 rows sit dead and shadowed. +// Introduced 2026-07-11 by #6472. It has a PRODUCTION consumer, dag/gunbc/ci_workflow.dag, so the +// workflow that runs this repo's CI is generated from an ambiguously bound name and no reader of +// the source can tell which binding won. That is reported separately rather than fixed here: it is +// a different lane, ci_workflow.dag is load-bearing, and a witness PR is the wrong vehicle for it. +// What this witness owes is only to not REST on the ambiguity, so it consumes checkout_action +// instead — grep-verified as the single binding of that name, along with setup_rust_action, +// cache_action and google_auth_action. + +// THE FINDING THIS SECOND SUBJECT EARNED, which is the actual argument for having one. A generic's +// second consumer is supposed to expose where the dimension was shaped around its first consumer, +// and it did. ActionRef.ref is a moving GitHub major tag (v5 tracks the latest 5.x), so it is a +// CONSTRAINT-like reference, not an identity — which is why Pin is sound where +// Pin was not, and why version 5.0.1 above is a SELECTION satisfying that reference +// rather than a restatement of it. That is the same requirement-versus-selection distinction +// already defended for CliTool.min_version, and it holds here for the same reason. But it does NOT +// extend to the selection axis: had this pin been written with TrackedChannel { channel: "v5" }, +// the channel string would RESTATE subject.ref, two writable fields holding one fact — the same +// duplication shape review 44850 rejected on the identity axis, one axis over. The tell is that +// PinSelection.TrackedChannel.channel is subject-agnostic while the channel it names may already +// live ON the subject: for a CliTool the channel is external (latest), for an ActionRef it IS +// subject.ref. So channel is arguably a subject PROJECTION wearing the shape of a generic field. +// Not fixed here, and deliberately not papered over with a caveat: the fix is either a projection +// on each instantiation (the cli_tool_pin_key_of shape, which is where subject-specific projections +// already belong) or a selection variant that names no channel of its own, and choosing between +// those is dimension surgery that wants its own review rather than a rider on a witness. +// dissolve-on: feature:pin-selection-channel-projection. Until then this witness uses ExactPin, +// which has no channel field and therefore cannot exhibit the duplication. data action_ref_pinned_identity: ContentHash = content_hash_of_value(value: "sha256-checkout-v5-commit" as NonEmptyStr) data action_ref_other_identity: ContentHash = content_hash_of_value(value: "sha256-checkout-v5-other-commit" as NonEmptyStr) -data action_ref_synthetic_identity_note: String = "The two identities above are OBVIOUSLY synthetic and deliberately so, in the same style as cargo_identity at the top of this module. Writing a real 40-hex commit SHA here and calling it actions/upload-artifact@v2 would fabricate an upstream fact inside a fail-closed carrier — the failure admit_legacy_cli_tool's own note forbids — and it would ALSO create a second authority for that SHA the day the lane pins the action for real. What this witness proves is structural (the dimension admits the subject, and refuses on mismatch); it makes no claim about upstream truth, so a value that could never be mistaken for a real digest is the honest fixture." +// The two identities above are OBVIOUSLY synthetic and deliberately so, in the same style as +// cargo_identity at the top of this module. Writing a real 40-hex commit SHA here and calling it +// actions/upload-artifact@v2 would fabricate an upstream fact inside a fail-closed carrier — the +// failure admit_legacy_cli_tool's own note forbids — and it would ALSO create a second authority +// for that SHA the day the lane pins the action for real. What this witness proves is structural +// (the dimension admits the subject, and refuses on mismatch); it makes no claim about upstream +// truth, so a value that could never be mistaken for a real digest is the honest fixture. data checkout_pin: Pin = Pin { subject: checkout_action, @@ -280,7 +381,18 @@ test fn second_subject_identity_is_the_pins_own_fact_not_the_subjects() -> Bool } } -data second_subject_identity_test_rationale_note: String = "WHAT THE TEST ABOVE REPLACED, and why the replacement discriminates where the original did not. The previous version asserted that Pin.expected_identity equalled the subject's own digest — a check that could only fail if someone edited the literal beside it, so it validated a value this file hand-wrote rather than any behavior of the dimension. Worse, it asserted the very duplication review 44850 identified as the defect. The test above instead pins two DIFFERENT identities to the SAME subject value and shows three things at once: the subject halves are identical (same mutable ref), the pins are nevertheless not value-equal, and admission REFUSES the disagreeing pin against the first identity. So expected_identity is load-bearing and independent — the pin supplies what the subject lacks — and there is no shadow copy inside the subject for admission to fall back on. This goes red on a real change (drop expected_identity from pin_value_eq, or make admission read a subject field, and it fails), which the original could not." +// WHAT THE TEST ABOVE REPLACED, and why the replacement discriminates where the original did not. +// The previous version asserted that Pin.expected_identity equalled the subject's own digest — a +// check that could only fail if someone edited the literal beside it, so it validated a value this +// file hand-wrote rather than any behavior of the dimension. Worse, it asserted the very +// duplication review 44850 identified as the defect. The test above instead pins two DIFFERENT +// identities to the SAME subject value and shows three things at once: the subject halves are +// identical (same mutable ref), the pins are nevertheless not value-equal, and admission REFUSES +// the disagreeing pin against the first identity. So expected_identity is load-bearing and +// independent — the pin supplies what the subject lacks — and there is no shadow copy inside the +// subject for admission to fall back on. This goes red on a real change (drop expected_identity +// from pin_value_eq, or make admission read a subject field, and it fails), which the original +// could not. test fn second_subject_refuses_on_identity_mismatch_too() -> Bool { match admit_pin_integrity(pin: checkout_pin, observed_identity: action_ref_other_identity) { diff --git a/dag/test/claim/tool_readiness_witness_test.dag b/dag/test/claim/tool_readiness_witness_test.dag index f310e7b285a..0465859abc7 100644 --- a/dag/test/claim/tool_readiness_witness_test.dag +++ b/dag/test/claim/tool_readiness_witness_test.dag @@ -98,7 +98,15 @@ fn context(rows: List) -> ResolvedBuildContext { } } -data tool_readiness_reconcile_family_note: String = "The executing consumer for the first tool-readiness slice. Matching and mismatching pins both pass through tool_pin_reconcile, the CliTool instantiation of the one gunbc.membership_reconcile spine. A mismatch is one Modified -> upsert plan and ToolMembershipNotConverged gates readiness, so the plan cannot become decorative evidence or a spawn/path effect. Trust remains a separate conjunct: the tracked-channel witness has zero reconcile hunks but still refuses through admit_pin_integrity. Removing an Ensured system tool exercises R5 and refuses. The unrelated-tool test is the discriminating aggregate-grain control: changing cargo changes the derived toolchain aggregate, but rustfmt readiness stays admitted because the decision reads only observed_tool_identity(rustfmt)." +// The executing consumer for the first tool-readiness slice. Matching and mismatching pins both +// pass through tool_pin_reconcile, the CliTool instantiation of the one gunbc.membership_reconcile +// spine. A mismatch is one Modified -> upsert plan and ToolMembershipNotConverged gates readiness, +// so the plan cannot become decorative evidence or a spawn/path effect. Trust remains a separate +// conjunct: the tracked-channel witness has zero reconcile hunks but still refuses through +// admit_pin_integrity. Removing an Ensured system tool exercises R5 and refuses. The unrelated-tool +// test is the discriminating aggregate-grain control: changing cargo changes the derived toolchain +// aggregate, but rustfmt readiness stays admitted because the decision reads only +// observed_tool_identity(rustfmt). test fn matching_pinned_tool_is_admitted_with_zero_hunks() -> Bool { match tool_readiness( @@ -214,7 +222,9 @@ test fn ensured_system_tool_teardown_refuses_through_shared_spine() -> Bool { membership_refusal_count(plan: plan) == 1 } -data tool_observation_refusal_family_note: String = "Missing and Duplicate are not collapsed into Option, match failure, or a widened resolver retry. Each upstream observed_tool_identity arm maps to its own located readiness refusal and the refusal list makes the occurrence count explicit." +// Missing and Duplicate are not collapsed into Option, match failure, or a widened resolver retry. +// Each upstream observed_tool_identity arm maps to its own located readiness refusal and the +// refusal list makes the occurrence count explicit. test fn missing_observed_tool_identity_refuses_located_and_counted() -> Bool { let readiness = tool_readiness( @@ -263,7 +273,11 @@ test fn duplicate_observed_tool_identity_refuses_located_and_counted() -> Bool { } } -data tool_frontier_family_note: String = "The current rustfmt handler is retained through one declared per-tool frontier row because its PATH shell can establish presence but hermetic provisioning has not yet made an expected executable identity stable across hosts. This is closed, counted migration state, not a fallback: an unlisted unpinned tool refuses, duplicate declarations refuse, and providing a pin selects the pinned path even when a frontier row exists (the mismatch witness above)." +// The current rustfmt handler is retained through one declared per-tool frontier row because its +// PATH shell can establish presence but hermetic provisioning has not yet made an expected +// executable identity stable across hosts. This is closed, counted migration state, not a fallback: +// an unlisted unpinned tool refuses, duplicate declarations refuse, and providing a pin selects the +// pinned path even when a frontier row exists (the mismatch witness above). test fn declared_unpinned_rustfmt_frontier_is_explicit() -> Bool { match tool_readiness( diff --git a/dag/test/claim/toolchain_coherence_witness_test.dag b/dag/test/claim/toolchain_coherence_witness_test.dag index 770ad318d2a..8e33ee63bf3 100644 --- a/dag/test/claim/toolchain_coherence_witness_test.dag +++ b/dag/test/claim/toolchain_coherence_witness_test.dag @@ -92,12 +92,11 @@ test fn one_spawn_is_single() -> Bool { } } -// PRODUCER-ABSENT AND NEVER-OBSERVED MUST NOT BE THE SAME VALUE. This is the distinction the -// carrier is most likely to lose later: the first wired producer that cannot observe its subject -// will be tempted to report the empty fold, and that renders its own absence as "we checked and -// found no pair". Asserting they are distinct constructions keeps the eventual producer honest. +// PRODUCER-ABSENT AND NEVER-OBSERVED MUST NOT BE THE SAME VALUE -- the distinction this carrier is +// most likely to lose later: the first wired producer that cannot observe its subject will be +// tempted to report the empty fold, rendering its own absence as "we checked and found no pair". // The fold cannot RETURN ProducerAbsent -- it speaks only about the list it was handed -- so this -// arm is authored directly, which is exactly how a real observation transaction would raise it. +// arm is authored directly, exactly how a real observation transaction would raise it. test fn producer_absent_is_not_never_observed() -> Bool { let absent = ToolchainCoherenceNotEvaluated { cause: SpawnObservationProducerAbsent { cause: "nothing observes spawns" } @@ -126,10 +125,9 @@ test fn producer_absent_is_not_never_observed() -> Bool { } // THE FINDING MUST CARRY ENOUGH GRAIN TO PICK THE REMEDY. Two spawns diverging at ONE resolved -// path means the binary was replaced under us; two spawns diverging at DIFFERENT paths means we -// ran two different binaries. Those have opposite repairs, so a finding that reported only -// "differed" would hand the consumer a verdict it cannot act on. Both directions are asserted so -// the evidence does the work rather than the arm's name. +// path means the binary was replaced under us; at DIFFERENT paths, we ran two different binaries. +// Opposite repairs, so a finding reporting only "differed" is a verdict the consumer cannot act on. +// Both directions are asserted so the evidence does the work rather than the arm's name. test fn divergence_carries_the_paths_that_pick_the_remedy() -> Bool { let one_path = toolchain_coherence_of(spawns: [ spawn_at(pass: "p1", bytes: "A", exe: "/usr/local/bin/rustfmt"), diff --git a/dag/test/claim/training_readback_witness_test.dag b/dag/test/claim/training_readback_witness_test.dag index 27b91f55fd2..204b0c1da98 100644 --- a/dag/test/claim/training_readback_witness_test.dag +++ b/dag/test/claim/training_readback_witness_test.dag @@ -193,9 +193,9 @@ fn other_subject(d: TrainingRunDesired) -> TrainingRunSubject TrainingRunSubject? { match dp(n: 50) { none => none @@ -257,11 +257,11 @@ test fn a_subject_differing_only_in_the_work_identity_is_refused() -> Bool { } } -// ONE REFUSAL CONTROL PER AXIS. The binder compares five subjects, and a suite that exercised one -// of them would establish nothing about the other four: the failure is per-field -- a comparison -// omitted for a single axis compiles, looks complete, and lets that axis carry another run's -// evidence. The axis is read back from the refusal, so a binder that refused on the wrong axis -// fails here rather than passing as a generic refusal. +// ONE REFUSAL CONTROL PER AXIS. The binder compares five subjects, and exercising one establishes +// nothing about the other four: the failure is per-field -- a comparison omitted for one axis +// compiles, looks complete, and lets that axis carry another run's evidence. The axis is read back +// from the refusal, so a binder refusing on the wrong axis fails here rather than passing as a +// generic refusal. fn mismatch_axis_for(which: Nat) -> NonEmptyStr { match desired_fixture(demand_work_key_override: none) { none => "fixture-failed" @@ -329,12 +329,12 @@ test fn five_readings_of_the_same_subject_are_admitted() -> Bool { } } -// SIMULTANEOUS MISMATCHES ARE CONSERVED, and this is the witness the earlier suite could not -// express. One control per axis proves each comparison EXISTS; it says nothing about what happens -// when two axes are foreign at once, and the binder that passed all five of those returned on the -// first mismatch -- so a readback with foreign execution AND foreign outputs reported only -// execution, and the hidden defect would have read as a new regression the moment the visible one -// was fixed. Per-axis controls and this one are not redundant: they fail on different bugs. +// SIMULTANEOUS MISMATCHES ARE CONSERVED, the witness the earlier suite could not express. One +// control per axis proves each comparison EXISTS but says nothing about two foreign axes at once, +// and the binder that passed all five returned on the first mismatch -- so a readback with foreign +// execution AND foreign outputs reported only execution, and the hidden defect would have read as a +// new regression the moment the visible one was fixed. Per-axis controls and this one fail on +// different bugs. test fn two_foreign_axes_are_both_reported() -> Bool { match desired_fixture(demand_work_key_override: none) { none => false @@ -372,10 +372,10 @@ test fn two_foreign_axes_are_both_reported() -> Bool { } } -// THE THREE EPISTEMIC STATES ARE INDEPENDENTLY REPRESENTABLE AND DO NOT READ AS EACH OTHER. This is -// the witness that would go red if an absent arm were reintroduced, or if a read that found nothing -// were folded into the not-attempted arm: an unread population becoming an empty one licenses a -// conclusion -- restart the run -- that ignorance does not license. +// THE THREE EPISTEMIC STATES ARE INDEPENDENTLY REPRESENTABLE AND DO NOT READ AS EACH OTHER. Goes +// red if an absent arm were reintroduced, or a read that found nothing were folded into the +// not-attempted arm: an unread population becoming an empty one licenses a conclusion -- restart +// the run -- that ignorance does not. fn checkpoint_state(o: TrainingPopulationObservation>) -> NonEmptyStr { match o { TrainingPopulationObserved { members: m, enumeration_receipt: _ } => @@ -403,9 +403,9 @@ test fn a_complete_read_finding_nothing_is_not_an_unread_population() -> Bool { } // EVERY AXIS IS A POPULATION, AND THE CASES BELOW ARE THE ONES A SINGLETON FIELD WOULD HAVE MADE -// UNREPRESENTABLE. Each is a state the fabric's own execution model produces: retry and capability +// UNREPRESENTABLE. Each is a state the fabric's execution model produces: retry and capability // escalation create new attempts rather than mutating an earlier one, so contradictory terminals -// and conflicting outputs are ordinary, not pathological. +// and conflicting outputs are ordinary. test fn a_failed_attempt_and_a_later_successful_attempt_both_survive() -> Bool { let terminals: List> = [ TrainingAttemptTerminalReceipt { @@ -449,9 +449,9 @@ test fn two_attempts_producing_different_artifacts_stay_representable() -> Bool } // AXIS INDEPENDENCE. A running process WITH published checkpoints, and a terminally failed attempt -// that nonetheless left a resumable checkpoint, are both real and have different remedies. A single -// coproduct over the run's state -- Absent | Running | Checkpointed | Completed -- cannot spell -// either one, which is why the readback keeps five fields rather than one verdict. +// that left a resumable checkpoint, are both real with different remedies. A single coproduct over +// the run's state -- Absent | Running | Checkpointed | Completed -- cannot spell either, which is +// why the readback keeps five fields rather than one verdict. test fn a_terminally_failed_run_may_still_hold_a_checkpoint() -> Bool { match desired_fixture(demand_work_key_override: none) { none => false @@ -500,9 +500,8 @@ test fn a_terminally_failed_run_may_still_hold_a_checkpoint() -> Bool { } } -// THE EFFECTIVE MANIFEST IS THE TYPED MANIFEST, so a disagreement can name its coordinate. This -// witness is the one that would go red if the axis were narrowed back to a bare hash: a hash can -// answer same-or-different and cannot answer WHICH. +// THE EFFECTIVE MANIFEST IS THE TYPED MANIFEST, so a disagreement can name its coordinate. Goes red +// if the axis were narrowed back to a bare hash: a hash answers same-or-different, never WHICH. test fn an_effective_manifest_disagreement_names_the_coordinate() -> Bool { match desired_fixture(demand_work_key_override: none) { none => false diff --git a/dag/test/claim/trait_bound_witness_test.dag b/dag/test/claim/trait_bound_witness_test.dag index d349f533850..b6c8e3fc1bf 100644 --- a/dag/test/claim/trait_bound_witness_test.dag +++ b/dag/test/claim/trait_bound_witness_test.dag @@ -4,7 +4,58 @@ import v2.std.live_tree { LiveTreeDisposition, SubstrateInputsOnly } data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data trait_bound_witness_test_note: String = "gunbc dashboard node://adhoc-d30225a0-531. This witness does NOT import v1.compiler.trait_bound_witness (src/v1/trait_bound_witness.dag): the required-floor's module resolution only scans --source-root dag and --source-root src/v2 (.github/workflows/witnesses.yml), never src/v1, so a .dag-level `import v1.compiler.X { ... }` from a dag/-rooted witness is structurally unresolvable regardless of the imported module's correctness -- confirmed by a corpus-wide check finding zero other dag/ or src/v2/ files importing any v1.compiler.* module. An earlier revision of this file imported v1.compiler.trait_bound_witness directly and unit-tested its pure decision core with plain literals; that revision failed CI with `unresolved import: module 'v1.compiler.trait_bound_witness' not found`, which is what this note now documents rather than repeats. The fix is not a broader source-root (a shared CI-workflow change, out of this PR's scope) but to rely on the SAME pattern the sibling Clone-bound witness already uses: dag/test/claim/generic_item_clone_bound_witness_test.dag imports nothing beyond v2.std.live_tree and proves its v1 trait-derive-emit behavior entirely through compile_dag_rust_emit_check, a host builtin that runs the real v1 emit pipeline without requiring a static import of any v1.compiler module. w_current_defect_reproduces_bare_generic_no_clone_impl below is that same shape: it compiles the minimal Choice/describe fixture (traced to reproduce the same shape as the real materialization_carriers E0599 specimens, dag/std/cache_interface.dag realize_route/classify_write -- a function whose body is directly a match on an Rc-wrapped, data-carrying, generic coproduct) through the REAL emit pipeline via compile_dag_rust_emit_check and asserts the FIXED emitted shape now that emit_fn_def is wired: `fn describe` rather than a bare `fn describe`, per DESIGN.md S4b's expecting-red-flips-to-permanent-regression-control pattern -- this specimen previously asserted the defect (bare signature) before the consumer wiring landed and now asserts the fix, not deleted. This remains a real executing consumer, not an inert function (DESIGN.md S5 specification-without-execution): it drives the actual wired src/v1/05_emit_rust.dag emit_fn_def code path end to end, which is a stronger proof than unit-testing the decision core in isolation would have been. TRADEOFF, named rather than left silent (smart-ram-730 review): dropping the 4 unit tests over v1_rc_match_scrutinee_clone_bound_param_names is not a rung downgrade -- end-to-end through the real acceptance path is the stronger evidence class -- but it IS a loss of discriminating power over the decision core specifically: this one specimen proves the pipeline produces the right emitted shape, not which branch of the core (needs_deref gate, generic-param-name match, or the union step) would regress. The core has exactly two branches worth distinguishing (deref-needed vs not; matching vs non-matching type-arg name) and only one is exercised by this fixture; a future specimen adding a second Choice-shaped fixture with a non-generic scrutinee type argument (proving the arg-name-match branch stays silent) would close that gap through the same builtin, still with no v1.compiler import. NOT DONE HERE because it is additive scope beyond the single defect this PR retires, named as a follow-up rather than silently absorbed. THIRD-TRIGGER QUESTION (smart-ram-730 review, re: trait_derive_emit_fn_clone_bound_wf_propagation_note): this fn-level trigger is NOT folded into v1_generic_params_needing_clone_bound's existing well-formedness-propagation fixpoint (v1_clone_bounded_type_params / v1_clone_bound_fixpoint_loop) because it answers a structurally different question -- that fixpoint asks whether naming a Clone-bounded DECLARED TYPE requires the bound (a graph-closure fact independent of any one function body), while this trigger asks whether a function BODY's control flow (a top-level match on an Rc-deref'd generic scrutinee) requires it -- the same usage-shape category as the pre-existing structural fn trigger (v1_type_param_needs_clone_bound: bare-generic return or direct container-element usage), which is likewise computed independently of the fixpoint. Both usage-shape triggers already union into the same List at their one point of consumption (v1_generic_params_needing_clone_bound's caller in emit_fn_def), which is the single-authority union DESIGN.md S3 asks for; moving this trigger's body into the fixpoint's own predicate set would be a scope-widening refactor of an unrelated, working mechanism to save one union call, not a genuine fork closed by union." +// gunbc dashboard node://adhoc-d30225a0-531. This witness does NOT import +// v1.compiler.trait_bound_witness (src/v1/trait_bound_witness.dag): the required-floor's module +// resolution only scans --source-root dag and --source-root src/v2 +// (.github/workflows/witnesses.yml), never src/v1, so a .dag-level `import v1.compiler.X { ... }` +// from a dag/-rooted witness is structurally unresolvable regardless of the imported module's +// correctness -- confirmed by a corpus-wide check finding zero other dag/ or src/v2/ files +// importing any v1.compiler.* module. An earlier revision of this file imported +// v1.compiler.trait_bound_witness directly and unit-tested its pure decision core with plain +// literals; that revision failed CI with `unresolved import: module +// 'v1.compiler.trait_bound_witness' not found`, which is what this note now documents rather than +// repeats. The fix is not a broader source-root (a shared CI-workflow change, out of this PR's +// scope) but to rely on the SAME pattern the sibling Clone-bound witness already uses: +// dag/test/claim/generic_item_clone_bound_witness_test.dag imports nothing beyond v2.std.live_tree +// and proves its v1 trait-derive-emit behavior entirely through compile_dag_rust_emit_check, a host +// builtin that runs the real v1 emit pipeline without requiring a static import of any v1.compiler +// module. w_current_defect_reproduces_bare_generic_no_clone_impl below is that same shape: it +// compiles the minimal Choice/describe fixture (traced to reproduce the same shape as the +// real materialization_carriers E0599 specimens, dag/std/cache_interface.dag +// realize_route/classify_write -- a function whose body is directly a match on an Rc-wrapped, +// data-carrying, generic coproduct) through the REAL emit pipeline via compile_dag_rust_emit_check +// and asserts the FIXED emitted shape now that emit_fn_def is wired: `fn describe` rather +// than a bare `fn describe`, per DESIGN.md S4b's +// expecting-red-flips-to-permanent-regression-control pattern -- this specimen previously asserted +// the defect (bare signature) before the consumer wiring landed and now asserts the fix, not +// deleted. This remains a real executing consumer, not an inert function (DESIGN.md S5 +// specification-without-execution): it drives the actual wired src/v1/05_emit_rust.dag emit_fn_def +// code path end to end, which is a stronger proof than unit-testing the decision core in isolation +// would have been. TRADEOFF, named rather than left silent (smart-ram-730 review): dropping the 4 +// unit tests over v1_rc_match_scrutinee_clone_bound_param_names is not a rung downgrade -- +// end-to-end through the real acceptance path is the stronger evidence class -- but it IS a loss of +// discriminating power over the decision core specifically: this one specimen proves the pipeline +// produces the right emitted shape, not which branch of the core (needs_deref gate, +// generic-param-name match, or the union step) would regress. The core has exactly two branches +// worth distinguishing (deref-needed vs not; matching vs non-matching type-arg name) and only one +// is exercised by this fixture; a future specimen adding a second Choice-shaped fixture with a +// non-generic scrutinee type argument (proving the arg-name-match branch stays silent) would close +// that gap through the same builtin, still with no v1.compiler import. NOT DONE HERE because it is +// additive scope beyond the single defect this PR retires, named as a follow-up rather than +// silently absorbed. THIRD-TRIGGER QUESTION (smart-ram-730 review, re: +// trait_derive_emit_fn_clone_bound_wf_propagation_note): this fn-level trigger is NOT folded into +// v1_generic_params_needing_clone_bound's existing well-formedness-propagation fixpoint +// (v1_clone_bounded_type_params / v1_clone_bound_fixpoint_loop) because it answers a structurally +// different question -- that fixpoint asks whether naming a Clone-bounded DECLARED TYPE requires +// the bound (a graph-closure fact independent of any one function body), while this trigger asks +// whether a function BODY's control flow (a top-level match on an Rc-deref'd generic scrutinee) +// requires it -- the same usage-shape category as the pre-existing structural fn trigger +// (v1_type_param_needs_clone_bound: bare-generic return or direct container-element usage), which +// is likewise computed independently of the fixpoint. Both usage-shape triggers already union into +// the same List at their one point of consumption (v1_generic_params_needing_clone_bound's +// caller in emit_fn_def), which is the single-authority union DESIGN.md S3 asks for; moving this +// trigger's body into the fixpoint's own predicate set would be a scope-widening refactor of an +// unrelated, working mechanism to save one union call, not a genuine fork closed by union. fn w_current_defect_reproduces_bare_generic_no_clone_impl() -> Bool { compile_dag_rust_emit_check( @@ -19,7 +70,30 @@ test fn current_defect_reproduces_bare_generic_no_clone_impl() -> Bool { w_current_defect_reproduces_bare_generic_no_clone_impl() } -data call_forwarding_clone_bound_witness_note: String = "gunbc dashboard node://adhoc-574e999b-39c, Row 1b. Proves v1_call_forwarding_clone_bound_param_names / v1_call_forwarding_bound_wrapper_param_names (src/v1/trait_bound_witness.dag, TraitBoundWitnessScope BoundedToDirectSingleCallLambdaBody) through the real emit pipeline via compile_dag_rust_emit_check, same discipline as the sibling RC-match witness above -- no v1.compiler import. Fixture is traced to reproduce src/v2/std/staging.dag's real cached_stage shape (compound-arity CacheProbe forwarded from a wrapper's lambda body directly into an already-derived-Clone-bounded callee, resolve_probe), one of the census's 51-error board rows (docs/probes/materialization_carriers_rebaseline_2026-08-19.md). w_call_forwarding_derives_clone_bound_from_callee asserts the fixed emitted shape `fn cached_stage(` and the absence of the pre-fix bare `fn cached_stage(`, confirmed against a live gunbc compile of the real staging.dag module this session (v2_std_staging.rs). w_call_forwarding_scope_excludes_match_wrapped_body is the declared-boundary negative control (DESIGN.md S4b rung honesty, S6 no hypothetical generality): a function whose body is a lambda wrapping a MATCH whose arm is the call (not a lambda whose body IS directly the call) stays bare -- reproducing src/v2/compiler/materialization_carriers.dag's real cached_stage_governed shape, confirmed unbounded against a live compile this session. That residual gap does not manifest as a rustc error in the census entrypoint's dependency closure (cached_stage_governed has zero callers there, and its own generic body never itself requires A: Clone / B: Clone to typecheck), so it is recorded here as a declared, non-silent scope boundary rather than fixed -- fixing it would require the same recursive body-walker (mirroring emit_rust_expr_if/emit_rust_expr_let's accessor shapes) that BoundedToDirectSingleCallLambdaBody's own note already names as its next-rung trigger, and is deliberately not built in this PR (DESIGN.md S6)." +// gunbc dashboard node://adhoc-574e999b-39c, Row 1b. Proves +// v1_call_forwarding_clone_bound_param_names / v1_call_forwarding_bound_wrapper_param_names +// (src/v1/trait_bound_witness.dag, TraitBoundWitnessScope BoundedToDirectSingleCallLambdaBody) +// through the real emit pipeline via compile_dag_rust_emit_check, same discipline as the sibling +// RC-match witness above -- no v1.compiler import. Fixture is traced to reproduce +// src/v2/std/staging.dag's real cached_stage shape (compound-arity CacheProbe forwarded +// from a wrapper's lambda body directly into an already-derived-Clone-bounded callee, +// resolve_probe), one of the census's 51-error board rows +// (docs/probes/materialization_carriers_rebaseline_2026-08-19.md). +// w_call_forwarding_derives_clone_bound_from_callee asserts the fixed emitted shape `fn +// cached_stage(` and the absence of the pre-fix bare `fn cached_stage(`, +// confirmed against a live gunbc compile of the real staging.dag module this session +// (v2_std_staging.rs). w_call_forwarding_scope_excludes_match_wrapped_body is the declared-boundary +// negative control (DESIGN.md S4b rung honesty, S6 no hypothetical generality): a function whose +// body is a lambda wrapping a MATCH whose arm is the call (not a lambda whose body IS directly the +// call) stays bare -- reproducing src/v2/compiler/materialization_carriers.dag's real +// cached_stage_governed shape, confirmed unbounded against a live compile this session. That +// residual gap does not manifest as a rustc error in the census entrypoint's dependency closure +// (cached_stage_governed has zero callers there, and its own generic body never itself requires A: +// Clone / B: Clone to typecheck), so it is recorded here as a declared, non-silent scope boundary +// rather than fixed -- fixing it would require the same recursive body-walker (mirroring +// emit_rust_expr_if/emit_rust_expr_let's accessor shapes) that +// BoundedToDirectSingleCallLambdaBody's own note already names as its next-rung trigger, and is +// deliberately not built in this PR (DESIGN.md S6). fn w_call_forwarding_derives_clone_bound_from_callee() -> Bool { compile_dag_rust_emit_check( diff --git a/dag/test/claim/transport_emission_not_modeled_witness_test.dag b/dag/test/claim/transport_emission_not_modeled_witness_test.dag index eda001fe7e8..9ee7825728e 100644 --- a/dag/test/claim/transport_emission_not_modeled_witness_test.dag +++ b/dag/test/claim/transport_emission_not_modeled_witness_test.dag @@ -33,7 +33,14 @@ data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly // The two shell/rest rows are NOT decoration. Without them this file cannot distinguish "the file // arm behaves" from "the transport dispatch is broken for everything", which is the failure mode // that would make a green suite defend a total outage. -data transport_emission_not_modeled_witness_note: String = "Paired control for the file-transport emission wall via compile_dag_diagnostic_census (rust target). A service whose operations declare `transport file` with a modeled verb, a renderable path and modeled output channels must now EMIT with zero TransportEmissionNotModeled rows; an operation declaring an unmodeled verb, an unmodeled output channel, or a payload verb with no `content` input must refuse with exactly one counted row. The mixed row is the discriminator: it pins both the emission and the refusal to the OPERATION rather than to the service or the module, so a wall that poisoned every sibling operation -- or a handler that emitted every sibling regardless of its declaration -- would go red here while the single-operation rows stayed green." +// Paired control for the file-transport emission wall via compile_dag_diagnostic_census (rust +// target). A service whose operations declare `transport file` with a modeled verb, a renderable +// path and modeled output channels must now EMIT with zero TransportEmissionNotModeled rows; an +// operation declaring an unmodeled verb, an unmodeled output channel, or a payload verb with no +// `content` input must refuse with exactly one counted row. The mixed row is the discriminator: it +// pins both the emission and the refusal to the OPERATION rather than to the service or the module, +// so a wall that poisoned every sibling operation -- or a handler that emitted every sibling +// regardless of its declaration -- would go red here while the single-operation rows stayed green. data file_transport_source: String = "module tfx_file\nservice Fs \{\n operation Write \{\n input \{ path: String, content: String \}\n output \{ success: Bool from \"write_success\" \}\n transport file \{ path: \"\{path\}\" \}\n \}\n operation Read \{\n input \{ path: String \}\n output \{ content: String from \"content\", success: Bool from \"read_success\" \}\n readonly\n transport file \{ path: \"\{path\}\" \}\n \}\n operation Delete \{\n input \{ path: String \}\n output \{ success: Bool from \"delete_success\" \}\n transport file \{ path: \"\{path\}\", verb: \"delete\" \}\n \}\n operation List \{\n input \{ path: String \}\n output \{ entries: String from \"entries\", success: Bool from \"list_success\" \}\n readonly\n transport file \{ path: \"\{path\}\", verb: \"list\" \}\n \}\n\}\n" diff --git a/dag/test/claim/transport_script_wall_compile_red_test.dag b/dag/test/claim/transport_script_wall_compile_red_test.dag index f05cdf87ee1..a01ad09c339 100644 --- a/dag/test/claim/transport_script_wall_compile_red_test.dag +++ b/dag/test/claim/transport_script_wall_compile_red_test.dag @@ -2,7 +2,17 @@ module test.claim.transport_script_wall_compile_red import v2.std.live_tree { LiveTreeDisposition, ReadsLiveTree } -data transport_script_wall_compile_red_note: String = "§5.E wall REDs (operator acceptance 2026-07-24): the two documented transport-script fake patterns, reconstructed AS WRITTEN, must FAIL TO COMPILE — not merely fail review. Each fake is compiled as an inline virtual source through compile_dag_rust_emit_check, which returns false on any hard diagnostic; the tests assert refusal (!compile). The construction wall — ShellOnHost.script retyped to the RetainedShellScript RECORD, and the free minter extdeps.shell.exec.transport_script_from_body DELETED — is what makes both fakes non-compiling. The host_language_transport_script lens never caught these (a computed concat is ComputedApplication, deliberately green); only construction closes the class. If either wall is ever loosened (record widened back to String, or the free minter reintroduced), the corresponding fake starts compiling clean, compile_dag_rust_emit_check flips to true, and the RED goes red — the wall's regression alarm." +// §5.E wall REDs (operator acceptance 2026-07-24): the two documented transport-script fake +// patterns, reconstructed AS WRITTEN, must FAIL TO COMPILE — not merely fail review. Each fake is +// compiled as an inline virtual source through compile_dag_rust_emit_check, which returns false on +// any hard diagnostic; the tests assert refusal (!compile). The construction wall — +// ShellOnHost.script retyped to the RetainedShellScript RECORD, and the free minter +// extdeps.shell.exec.transport_script_from_body DELETED — makes both fakes non-compiling. The +// host_language_transport_script lens never caught these (a computed concat is +// ComputedApplication, deliberately green); only construction closes the class. If either wall is +// loosened (record widened back to String, or the free minter reintroduced), the corresponding fake +// compiles clean, compile_dag_rust_emit_check flips to true, and the RED goes red — the wall's +// regression alarm. data firsttouch_1_restoration_note: String = "FIRSTTOUCH-1 (dashboard adhoc-c5b4375f-4cb, 2026-08-19) -- a finding and a disposition correction, NOT a restoration; corrected 2026-08-19 after this note's first version wrongly read a green floor run as evidence the witness now executes cheaply. This module was quarantined out of test.claim.long. and back in, twice, on two different readings of one artifact. First quarantined by #8457's blanket over-budget sweep. RESTORE WAVE A un-quarantined it, then 021d17e6a7 dropped it straight back after observing it cost 1394ms pre-quarantine (docs/plans/measurements/floor-slow-rows-2026-08-17.tsv, CI run ci) but 48963ms in the restore run with nothing about the witness changed -- 35.1x, and the commit named the mechanism without yet fixing it: compile_dag_rust_emit_check_uncached calls build_module_path_index_from_witness_roots (src/v1/stage0/src/cli_run.rs), a THREAD-LOCAL memo keyed on the default source roots -- exactly the module_path_index shared fill of the #8455 ledger (docs/plans/floor-shared-fill-ledger.md). #8470 (7e4871be86, already on this branch's main ancestry) DID fix that exact call site, warming build_module_path_index_from_witness_roots during floor preparation and naming this witness's own two RED rows in its measurement table -- but fixing a cost and being ADMITTED to pay it are two different facts, and this note's first version conflated them. @@ -26,7 +36,10 @@ THE SCALE NOTE'S POINT IS ACCEPTED AND ACTED ON: 778 identities in the larger po data live_tree_disposition: LiveTreeDisposition = ReadsLiveTree -// Positive control: a clean shell service source compiles and emits src/wallctl.rs containing the argv-shaped Command invocation, so compile_dag_rust_emit_check returns true. Proves the harness is discriminating — the two false results below are genuine refusals of the fakes, not a harness that always returns false. +// Positive control: a clean shell service source compiles and emits src/wallctl.rs containing the +// argv-shaped Command invocation, so compile_dag_rust_emit_check returns true. Proves the harness +// discriminates — the two false results below are genuine refusals, not a harness that always +// returns false. fn w_control_clean_shell_service() -> Bool { compile_dag_rust_emit_check( "module wallctl\n\nservice shell.Run {\n operation Exec {\n input { script: String }\n output { result: String }\n transport shell { argv: [\"sh\", \"-lc\", \"\{script\}\"] }\n mock_response {\n 0 => \"done\" \"result\"\n }\n }\n}\n", @@ -36,7 +49,12 @@ fn w_control_clean_shell_service() -> Bool { ) } -data red_a_note: String = "RED A — the #7064 / vivid-wolf 'build the argv properly, then join it back into a string and feed the realization edge' class. The fake hands a computed String (argv join + \" 2>/dev/null || true\") to retained_shell_script_to_transport, whose parameter is the RetainedShellScript RECORD. A String cannot fill a record position, so infer refuses (hard diagnostic) and the source does not compile. The only sanctioned route is to author a counted RetainedShellScript row (retained_srvn / retained_transport), which forces a reason + dissolve-on." +// RED A — the #7064 / vivid-wolf 'build the argv properly, then join it back into a string and feed +// the realization edge' class. The fake hands a computed String (argv join + " 2>/dev/null || +// true") to retained_shell_script_to_transport, whose parameter is the RetainedShellScript RECORD. +// A String cannot fill a record position, so infer refuses (hard diagnostic) and the source does +// not compile. The only sanctioned route is to author a counted RetainedShellScript row +// (retained_srvn / retained_transport), which forces a reason + dissolve-on. fn w_red_a_string_join_into_retained_record() -> Bool { compile_dag_rust_emit_check( @@ -47,7 +65,10 @@ fn w_red_a_string_join_into_retained_record() -> Bool { ) } -data red_b_note: String = "RED B — #7064's exact textual pattern: transport_script_from_body(argv_join(...) + \" 2>/dev/null || true\"). The free minter is deleted from extdeps.shell.exec, so the import resolves nothing and the call is unresolved (hard diagnostic) — the source does not compile. Reintroducing the free minter would make this fake compile again and red this control." +// RED B — #7064's exact textual pattern: transport_script_from_body(argv_join(...) + " 2>/dev/null +// || true"). The free minter is deleted from extdeps.shell.exec, so the import resolves nothing and +// the call is unresolved (hard diagnostic) — the source does not compile. Reintroducing the free +// minter would make this fake compile again and red this control. fn w_red_b_deleted_free_minter() -> Bool { compile_dag_rust_emit_check( diff --git a/dag/test/claim/type_reference_binding_context_witness_test.dag b/dag/test/claim/type_reference_binding_context_witness_test.dag index e05edffba8a..2ab397f70f7 100644 --- a/dag/test/claim/type_reference_binding_context_witness_test.dag +++ b/dag/test/claim/type_reference_binding_context_witness_test.dag @@ -35,7 +35,13 @@ import gunbc.type_reference_binding_context { build_type_reference_binding_context, } -data type_reference_binding_context_witness_note: String = "N2 slice 2 PR-A builder witnesses (quiet-hawk-219): RESOLVE-path only — see gunbc.type_reference_binding_context type_reference_binding_context_path_scope_note (emit-side #7705 RED control is LIVE, separate instance, warm-wolf-814). TypeReferenceBindingContext input projection + containment-tree exposure derivation for the v1 typecheck masked-leaf changeover. Cross-module kernel bind uses builder-produced inputs with RootExposure from module-root containment. Pool-coincidence refusal uses explicit ModuleExposure override on slice-1 control-3. PR-B wires resolve_node_bounded after 7515." +// N2 slice 2 PR-A builder witnesses (quiet-hawk-219): RESOLVE-path only — see +// gunbc.type_reference_binding_context type_reference_binding_context_path_scope_note (emit-side +// #7705 RED control is LIVE, separate instance, warm-wolf-814). TypeReferenceBindingContext input +// projection + containment-tree exposure derivation for the v1 typecheck masked-leaf changeover. +// Cross-module kernel bind uses builder-produced inputs with RootExposure from module-root +// containment. Pool-coincidence refusal uses explicit ModuleExposure override on slice-1 control-3. +// PR-B wires resolve_node_bounded after 7515. fn trbc_module_path(dotted: String) -> NonEmptyStr { dotted as NonEmptyStr diff --git a/dag/test/claim/type_reference_resolve_changeover_equivalence_witness_test.dag b/dag/test/claim/type_reference_resolve_changeover_equivalence_witness_test.dag index 37b602b6482..dcfe7215a75 100644 --- a/dag/test/claim/type_reference_resolve_changeover_equivalence_witness_test.dag +++ b/dag/test/claim/type_reference_resolve_changeover_equivalence_witness_test.dag @@ -17,7 +17,16 @@ import v2.std.live_tree { LiveTreeDisposition, ReadsLiveTree } data live_tree_disposition: LiveTreeDisposition = ReadsLiveTree -data type_reference_resolve_changeover_equivalence_witness_note: String = "PR-B equivalence receipt scaffold (quiet-hawk-219 hardening condition 1): cross-module production corpus where legacy masked-leaf resolve and containment-switched resolve both run and agree. Disagreement arms must be enumerated — each explained as a fixed defect of the old path (pool-membership coincidence, Product() peel). Cross-module required: provider module exposes type via containment root exposure; consumer references without import reachability; pool-present homonym in unrelated module must not decide binding. Fail-closed (condition 2): new path refuses — never silent lookup_type_for fallback. Emit path (item_registry leaf-key) is OUT OF SCOPE — see type_reference_binding_context_path_scope_note. DISSOLVE-ON: resolve_node_bounded changeover lands and both-path compile equivalence holds on this corpus — then promote from scaffold to enrolled regression control." +// PR-B equivalence receipt scaffold (quiet-hawk-219 hardening condition 1): cross-module production +// corpus where legacy masked-leaf resolve and containment-switched resolve both run and agree. +// Disagreement arms must be enumerated — each explained as a fixed defect of the old path +// (pool-membership coincidence, Product() peel). Cross-module required: provider module +// exposes type via containment root exposure; consumer references without import reachability; +// pool-present homonym in unrelated module must not decide binding. Fail-closed (condition 2): new +// path refuses — never silent lookup_type_for fallback. Emit path (item_registry leaf-key) is OUT +// OF SCOPE — see type_reference_binding_context_path_scope_note. DISSOLVE-ON: resolve_node_bounded +// changeover lands and both-path compile equivalence holds on this corpus — then promote from +// scaffold to enrolled regression control. fn census_of(source: String) -> CompileDiagnosticCensus { compile_dag_diagnostic_census(source) diff --git a/dag/test/claim/typed_argv_exec_realization_witness_test.dag b/dag/test/claim/typed_argv_exec_realization_witness_test.dag index 94ae52c7791..fd33a16a553 100644 --- a/dag/test/claim/typed_argv_exec_realization_witness_test.dag +++ b/dag/test/claim/typed_argv_exec_realization_witness_test.dag @@ -40,7 +40,13 @@ import v2.std.live_tree { LiveTreeDisposition, SubstrateInputsOnly } data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data typed_argv_exec_realization_note: String = "Wave C5 receipt: deploy-preflight probe effects realize through typed argv service operations (access.PosixEffectivePrincipal.Read, sudo.NopasswdExecuteProbe.Check, sudo.NopasswdGrantList.Read) on LocalShell and gunbc.typed_argv_exec_over_ssh on SshShell — one argv shape per op, N transport handlers, no concat-shell. Package-managed binaries that may be absent use the grant-list read plus exact NOPASSWD-row parser rather than an execute check. The list query's exit status alone is never treated as authorization. Argv tokens outside the portable allowlist fail closed before ssh spawn." +// Wave C5 receipt: deploy-preflight probe effects realize through typed argv service operations +// (access.PosixEffectivePrincipal.Read, sudo.NopasswdExecuteProbe.Check, +// sudo.NopasswdGrantList.Read) on LocalShell and gunbc.typed_argv_exec_over_ssh on SshShell — one +// argv shape per op, N transport handlers, no concat-shell. Package-managed binaries that may be +// absent use the grant-list read plus exact NOPASSWD-row parser rather than an execute check. The +// list query's exit status alone is never treated as authorization. Argv tokens outside the +// portable allowlist fail closed before ssh spawn. test fn witness_posix_effective_principal_read_typed_argv_holds() -> Bool { let result = access.PosixEffectivePrincipal.Read(read: EffectivePosixPrincipalRead {}) diff --git a/dag/test/claim/typed_module_cache_capacity_witness_test.dag b/dag/test/claim/typed_module_cache_capacity_witness_test.dag index 044b884b030..340a9a5c05c 100644 --- a/dag/test/claim/typed_module_cache_capacity_witness_test.dag +++ b/dag/test/claim/typed_module_cache_capacity_witness_test.dag @@ -23,7 +23,13 @@ import v2.std.live_tree { LiveTreeDisposition, SubstrateInputsOnly } data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data typed_module_cache_capacity_witness_note: String = "Executes the modelled cap derivation that extdeps.realization.reconcile_in_process now cites as its RuntimeDerivedLimit authority. The load-bearing cell is unreadable_budget_refuses_rather_than_defaulting: the seed's previous unwrap_or(CEIL) turned an unknown budget into the MOST PERMISSIVE cap available and OOM-killed the full witness corpus twice, so the discriminating question is not whether a cap is produced but whether the refusal survives. Both clamp directions are pinned because a one-sided clamp would look correct on the ordinary budget and fail exactly at the extremes the clamp exists for." +// Executes the modelled cap derivation that extdeps.realization.reconcile_in_process now cites as +// its RuntimeDerivedLimit authority. The load-bearing cell is +// unreadable_budget_refuses_rather_than_defaulting: the seed's previous unwrap_or(CEIL) turned an +// unknown budget into the MOST PERMISSIVE cap available and OOM-killed the full witness corpus +// twice, so the discriminating question is not whether a cap is produced but whether the refusal +// survives. Both clamp directions are pinned because a one-sided clamp would look correct on the +// ordinary budget and fail exactly at the extremes the clamp exists for. // 300 entries exactly: 300 * 3 MiB = 943718400 bytes, comfortably inside the band. fn ordinary_budget() -> HostBudgetResolution { diff --git a/dag/test/claim/typed_remote_file_write_witness_test.dag b/dag/test/claim/typed_remote_file_write_witness_test.dag index 19415cc5274..ccb223f3d25 100644 --- a/dag/test/claim/typed_remote_file_write_witness_test.dag +++ b/dag/test/claim/typed_remote_file_write_witness_test.dag @@ -26,7 +26,11 @@ import v2.std.live_tree { LiveTreeDisposition, SubstrateInputsOnly } data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data witness_hermetic_execution_split_note: String = "Filesystem write/read round-trip is not witnessed here: Filesystem.Write/Read have no mock_response in hermetic discovery (dag/extdeps/filesystem/filesystem_io.dag). Byte preservation at the substrate seam is witnessed via stdin_payload equality and typed_remote_file_write_over_fleet_ssh hermetic SSH mock routing below; wet remote byte landing belongs on fleet converge apply." +// Filesystem write/read round-trip is not witnessed here: Filesystem.Write/Read have no +// mock_response in hermetic discovery (dag/extdeps/filesystem/filesystem_io.dag). Byte preservation +// at the substrate seam is witnessed via stdin_payload equality and +// typed_remote_file_write_over_fleet_ssh hermetic SSH mock routing below; wet remote byte landing +// belongs on fleet converge apply. data witness_tmp_scope: FileTreeScope = FileTreeScope { root_path: "/tmp" as NonEmptyStr, diff --git a/dag/test/claim/typed_witness_invocation_test.dag b/dag/test/claim/typed_witness_invocation_test.dag index e0ee0d587c5..a68fb968d91 100644 --- a/dag/test/claim/typed_witness_invocation_test.dag +++ b/dag/test/claim/typed_witness_invocation_test.dag @@ -56,7 +56,13 @@ test fn typed_run_witness_bin_unbuildable_red_control_holds() -> Bool { run_witness_bin(var_name: "NO_SUCH", bin_name: "no_such_witness_bin_zzz", args: []) == false } -data typed_witness_bin_run_loud_failure_red_control_note: String = "Deliberate unannotated gunbc.WitnessBin.Run of /bin/false (no ExpectFailure / OutcomeIsData) so the observation layer paints an anomaly glyph. Kept as the cheap producer for no_fake_anomalies_witness_test's RED control after WitnessBinNotEnrolled closed the mid-floor cargo path that typed_run_witness_bin_unbuildable_red_control_holds used to exercise. A cargo.BuildInheritEnv of a missing --bin also works but costs ~90s child wall and blew the per-PR wet batch clamp (FLOOR-BATCH-OVER-BUDGET batch=4); /bin/false keeps the discrimination without the corpus-denominated cost." +// Deliberate unannotated gunbc.WitnessBin.Run of /bin/false (no ExpectFailure / OutcomeIsData) so +// the observation layer paints an anomaly glyph. Kept as the cheap producer for +// no_fake_anomalies_witness_test's RED control after WitnessBinNotEnrolled closed the mid-floor +// cargo path that typed_run_witness_bin_unbuildable_red_control_holds used to exercise. A +// cargo.BuildInheritEnv of a missing --bin also works but costs ~90s child wall and blew the per-PR +// wet batch clamp (FLOOR-BATCH-OVER-BUDGET batch=4); /bin/false keeps the discrimination without +// the corpus-denominated cost. test fn typed_witness_bin_run_loud_failure_red_control_holds() -> Bool { let result = gunbc.WitnessBin.Run(workdir: "/", bin_path: "/bin/false") diff --git a/dag/test/claim/typescript_program_serializer_test.dag b/dag/test/claim/typescript_program_serializer_test.dag index 25a43656e9e..8d1fee05059 100644 --- a/dag/test/claim/typescript_program_serializer_test.dag +++ b/dag/test/claim/typescript_program_serializer_test.dag @@ -1,6 +1,5 @@ module test.claim.typescript_program_serializer - data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly fn minimal_add_program() -> TsProgram { @@ -94,7 +93,14 @@ test fn typescript_program_serialize_create_server_fragment_holds() -> Bool { && string_contains(s: src, pattern: "require('http')") } -data operator_precedence_witness_note: String = "The printer's grouping proven by SERIALIZED TEXT, not by reading the table, because the defect these witnesses close was invisible in the model and visible only in the output. Each assertion is a whole-string equality, which is the strongest available discrimination here: a printer that stopped grouping reds the three grouping witnesses, and a printer that grouped indiscriminately reds the three bare witnesses, so neither direction of regression can pass. The two grouping shapes are the exact shapes found live in gunbc.roadmap_component on 2026-07-30 — a conditional and a disjunction as the right operand of a concatenation — rather than invented ones, so the RED is the real defect rather than a strawman." +// The printer's grouping proven by SERIALIZED TEXT, not by reading the table, because the defect +// these witnesses close was invisible in the model and visible only in the output. Each assertion +// is a whole-string equality, which is the strongest available discrimination here: a printer that +// stopped grouping reds the three grouping witnesses, and a printer that grouped indiscriminately +// reds the three bare witnesses, so neither direction of regression can pass. The two grouping +// shapes are the exact shapes found live in gunbc.roadmap_component on 2026-07-30 — a conditional +// and a disjunction as the right operand of a concatenation — rather than invented ones, so the RED +// is the real defect rather than a strawman. fn precedence_const_program(value: TsExpr) -> TsProgram { TsProgram { @@ -169,7 +175,13 @@ test fn typescript_precedence_leaves_tighter_child_bare() -> Bool { serialize_typescript_program(p: precedence_const_program(value: e)) == "const x = a === b && c === d;" } -data unrecognized_operator_note: String = "An operator the table does not know claims the tightest binding as a parent, so any COMPOUND operand under it is grouped — `b + c` here — while an atom is left bare, because an identifier has nothing to re-associate and parenthesizing it would be noise with no property behind it. The first version of this witness asserted `(a) ?? (b + c)` and was simply wrong about the printer; it is recorded because the correction is the interesting part. Over-parenthesizing is the safe direction for an unknown operator, but 'safe direction' is not a licence to group things that cannot be misgrouped." +// An operator the table does not know claims the tightest binding as a parent, so any COMPOUND +// operand under it is grouped — `b + c` here — while an atom is left bare, because an identifier +// has nothing to re-associate and parenthesizing it would be noise with no property behind it. The +// first version of this witness asserted `(a) ?? (b + c)` and was simply wrong about the printer; +// it is recorded because the correction is the interesting part. Over-parenthesizing is the safe +// direction for an unknown operator, but 'safe direction' is not a licence to group things that +// cannot be misgrouped. test fn typescript_precedence_groups_unrecognized_operator_operands() -> Bool { let e = ts_binop( @@ -187,7 +199,13 @@ test fn typescript_precedence_groups_unrecognized_operator_as_child() -> Bool { serialize_typescript_program(p: precedence_const_program(value: e)) == "const x = 'a' + (b ?? c);" } -data receiver_grouping_witness_note: String = "The receiver arm of the precedence family, added on a live silent defect (2026-08-01): ts_member over a `||` binop serialized as `a || [].forEach(cb)` — valid JavaScript that never runs the callback when `a` is truthy, discovered as an empty obligation ledger with zero console errors. The discriminating pair: an operator receiver GROUPS (member, index, and call each asserted); an atom receiver (call result, plain member chain) stays bare, so the fix cannot hide behind blanket parentheses. The RED is the exact live shape: the ungrouped spelling must not be what the printer emits." +// The receiver arm of the precedence family, added on a live silent defect (2026-08-01): ts_member +// over a `||` binop serialized as `a || [].forEach(cb)` — valid JavaScript that never runs the +// callback when `a` is truthy, discovered as an empty obligation ledger with zero console errors. +// The discriminating pair: an operator receiver GROUPS (member, index, and call each asserted); an +// atom receiver (call result, plain member chain) stays bare, so the fix cannot hide behind blanket +// parentheses. The RED is the exact live shape: the ungrouped spelling must not be what the printer +// emits. test fn typescript_receiver_binop_groups_under_member() -> Bool { let e = ts_call( diff --git a/dag/test/claim/v1_complexity_capability_census_witness_test.dag b/dag/test/claim/v1_complexity_capability_census_witness_test.dag index 3c8cd7f2f2c..a75a66edf79 100644 --- a/dag/test/claim/v1_complexity_capability_census_witness_test.dag +++ b/dag/test/claim/v1_complexity_capability_census_witness_test.dag @@ -72,10 +72,60 @@ import gunbc.v1_complexity_capability_census { data witness_note: String = "FAST-LANE structural hygiene for the C0(b1) v1 complexity INVENTORY. Exact DeclarationRef resolution against live decl_facts is deliberately NOT here — it costs a full witness-layer decl_facts scan and would breach the 5s fast-lane budget, the same reason test.claim.cited_symbol_resolution_witness_test keeps its resolution census in the long lane. That census is this roster's companion in test.claim.long.v1_complexity_capability_census_resolution_test. What this file proves is what is cheap and structural: every arm lands in exactly one work-state, EVERY arm has a controlled fixture including the ones no row inhabits, and routing metadata is drawn from typed vocabularies. The vacuity control moved to the long-lane companion with the lens imports it needed — see closure_cost_note." -data closure_cost_note: String = "COST FINDING, measured on this PR (2026-08-05), stated with its clock basis. An earlier revision of this file imported v2.lens.complexity, v2.lens.cost and v2.std.refinement to execute the vacuity control. No other witness under dag/test/claim imports them, so this file was the FIRST to drag the v2 lens closure into the per-PR witness layer — and the floor measured the consequence on an unrelated witness: roadmap_program_view_witness_test witness_live_constraint_present_iff_line_unaccepted recorded 3901.9ms on green main and 5019ms here, without its own semantic work changing. BASIS, per gunbc.witness_row_cost witness_row_cost_clock_basis_note (landed on main 2026-08-05, gunbc#7820): both figures are WALL and the fast-lane cap is enforced on thread CPU. The 3901.9ms baseline is therefore a real reading — eval is single-threaded, so a wall figure under the cap proves cpu under it. The 5019ms figure is NOT a cost: it is a CENSORED measurement whose value is where the kill landed, so the true figure is unbounded above. MEASURED AFTERWARD, which supersedes the weaker claim this note first carried. Three readings per side, all wall: main 3728.8 / 3901.9 / 3964.4 (mean 3865.0, spread 235.6) and this branch 4106.4 / 4179.0 / 4191.9 (mean 4159.1, spread 85.5). The ranges are DISJOINT with a 142.0ms gap between main slowest and this branch fastest, and main spread is the WIDER of the two — so the roughly 294ms increase is a real cost this change imposes, not host noise, and the earlier its-size-is-unknown wording is retired rather than left standing. The likely cause is not mysterious and is worth naming: this change adds content to the two design-note carriers that the roadmap program view projects, so the witness folding over that view genuinely does more work. It remains about 800ms under the cap. What is still NOT established is the censored 5019ms figure, which stays a lower bound by construction: a killed run reports where the kill landed, never what it would have cost. RECONCILED ON MERGE WITH MAIN: gunbc#7762 independently moved this same witness OUT of the per-PR fast lane into falsifier_substrate_long_lane_rows, on the ground that it flaked at 5004ms under host contention and was declared not caused by that PR diff. Both readings can hold and this branch does not contest that row: a witness can be contention-sensitive AND diff-sensitive, and the measurement above is evidence for its borderline status rather than against it — but it does refute the general form of the attribution, because here a diff moved it about 294ms with disjoint ranges. The practical consequence is that this branch cost no longer lands on anyone per-PR budget, since the witness now runs on the long lane. The cost finding is retained rather than deleted because the mechanism it records — a witness import closure landing on an unrelated witness budget — is unchanged by where the victim happens to run. SUBJECT DECOMPOSED AFTER MEASUREMENT (gunbc#7822, merged 2026-08-05, after every reading above was taken): roadmap_program_view_witness_test witness_live_constraint_present_iff_line_unaccepted NO LONGER EXISTS. The index-backed projection work decomposed it, and its long-lane row is replaced by roadmap_program_view_live_corpus_receipt_test live_roadmap_program_view_corpus_projection_receipt. Every figure above is therefore a historical measurement of a function that is gone, and the name is retained ONLY because it identifies what was measured — it is not a live citation and must not be treated as one. This is worth writing down rather than quietly deleting, because it is this census own subject happening to this census: a symbol cited in prose stopped resolving without anyone touching the sentence that cited it. The mechanism the finding records is unaffected, since it concerns import closures landing on a neighbour budget, not that particular neighbour. Recorded rather than silently fixed because it is a measured instance of this program's own subject twice over — a per-witness cost invisible until it lands on somebody else's budget, and a threshold that reports the victim rather than the cause on a clock other than the one it enforces. The lens imports moved to the long-lane companion with the control that needed them." - - -data green_by_vacancy_note: String = "The operator finding this file exists to answer. The previous revision's exhaustiveness check was green only because no row inhabited the DeliberatelyRetired arm — a check that would have failed the first time that declared arm was used. Fixtures below inhabit ALL SIX arms independently of the roster, so the partition is proven total over the type rather than over today's row set. Retired and SupersededByBetterModel have no roster row at all; they are proven here and nowhere else." +// COST FINDING, measured on this PR (2026-08-05), stated with its clock basis. An earlier revision +// of this file imported v2.lens.complexity, v2.lens.cost and v2.std.refinement to execute the +// vacuity control. No other witness under dag/test/claim imports them, so this file was the FIRST +// to drag the v2 lens closure into the per-PR witness layer — and the floor measured the +// consequence on an unrelated witness: roadmap_program_view_witness_test +// witness_live_constraint_present_iff_line_unaccepted recorded 3901.9ms on green main and 5019ms +// here, without its own semantic work changing. BASIS, per gunbc.witness_row_cost +// witness_row_cost_clock_basis_note (landed on main 2026-08-05, gunbc#7820): both figures are WALL +// and the fast-lane cap is enforced on thread CPU. The 3901.9ms baseline is therefore a real +// reading — eval is single-threaded, so a wall figure under the cap proves cpu under it. The 5019ms +// figure is NOT a cost: it is a CENSORED measurement whose value is where the kill landed, so the +// true figure is unbounded above. MEASURED AFTERWARD, which supersedes the weaker claim this note +// first carried. Three readings per side, all wall: main 3728.8 / 3901.9 / 3964.4 (mean 3865.0, +// spread 235.6) and this branch 4106.4 / 4179.0 / 4191.9 (mean 4159.1, spread 85.5). The ranges are +// DISJOINT with a 142.0ms gap between main slowest and this branch fastest, and main spread is the +// WIDER of the two — so the roughly 294ms increase is a real cost this change imposes, not host +// noise, and the earlier its-size-is-unknown wording is retired rather than left standing. The +// likely cause is not mysterious and is worth naming: this change adds content to the two +// design-note carriers that the roadmap program view projects, so the witness folding over that +// view genuinely does more work. It remains about 800ms under the cap. What is still NOT +// established is the censored 5019ms figure, which stays a lower bound by construction: a killed +// run reports where the kill landed, never what it would have cost. RECONCILED ON MERGE WITH MAIN: +// gunbc#7762 independently moved this same witness OUT of the per-PR fast lane into +// falsifier_substrate_long_lane_rows, on the ground that it flaked at 5004ms under host contention +// and was declared not caused by that PR diff. Both readings can hold and this branch does not +// contest that row: a witness can be contention-sensitive AND diff-sensitive, and the measurement +// above is evidence for its borderline status rather than against it — but it does refute the +// general form of the attribution, because here a diff moved it about 294ms with disjoint ranges. +// The practical consequence is that this branch cost no longer lands on anyone per-PR budget, since +// the witness now runs on the long lane. The cost finding is retained rather than deleted because +// the mechanism it records — a witness import closure landing on an unrelated witness budget — is +// unchanged by where the victim happens to run. SUBJECT DECOMPOSED AFTER MEASUREMENT (gunbc#7822, +// merged 2026-08-05, after every reading above was taken): roadmap_program_view_witness_test +// witness_live_constraint_present_iff_line_unaccepted NO LONGER EXISTS. The index-backed projection +// work decomposed it, and its long-lane row is replaced by +// roadmap_program_view_live_corpus_receipt_test +// live_roadmap_program_view_corpus_projection_receipt. Every figure above is therefore a historical +// measurement of a function that is gone, and the name is retained ONLY because it identifies what +// was measured — it is not a live citation and must not be treated as one. This is worth writing +// down rather than quietly deleting, because it is this census own subject happening to this +// census: a symbol cited in prose stopped resolving without anyone touching the sentence that cited +// it. The mechanism the finding records is unaffected, since it concerns import closures landing on +// a neighbour budget, not that particular neighbour. Recorded rather than silently fixed because it +// is a measured instance of this program's own subject twice over — a per-witness cost invisible +// until it lands on somebody else's budget, and a threshold that reports the victim rather than the +// cause on a clock other than the one it enforces. The lens imports moved to the long-lane +// companion with the control that needed them. + +// The operator finding this file exists to answer. The previous revision's exhaustiveness check was +// green only because no row inhabited the DeliberatelyRetired arm — a check that would have failed +// the first time that declared arm was used. Fixtures below inhabit ALL SIX arms independently of +// the roster, so the partition is proven total over the type rather than over today's row set. +// Retired and SupersededByBetterModel have no roster row at all; they are proven here and nowhere +// else. fn fixture_complete() -> V1ComplexityInventoryRow { V1ComplexityInventoryRow { @@ -233,7 +283,13 @@ test fn w_work_kind_counts_exhaust_the_roster() -> Bool { retirement > 0 } -data w_destinations_are_signed_vocabulary_note: String = "Routing metadata is drawn from the signed C0(a) ruling's closed vocabulary rather than spelled freehand — and the ruling is carried on THREE axes, not one (operator review 2026-08-05). The discriminating half is the SECOND assertion: the role axis names the legacy oracle because the ruling assigns it a role, while the destination axis does not, so a row migrating INTO the deletion target has no constructor. Fusing the two, as the previous revision did, made that state writable. This control asserts each axis maps to exactly the module paths its own axis is allowed to name." +// Routing metadata is drawn from the signed C0(a) ruling's closed vocabulary rather than spelled +// freehand — and the ruling is carried on THREE axes, not one (operator review 2026-08-05). The +// discriminating half is the SECOND assertion: the role axis names the legacy oracle because the +// ruling assigns it a role, while the destination axis does not, so a row migrating INTO the +// deletion target has no constructor. Fusing the two, as the previous revision did, made that state +// writable. This control asserts each axis maps to exactly the module paths its own axis is allowed +// to name. test fn w_role_and_destination_are_separate_axes() -> Bool { cost_program_role_module_path(r: RoleMigrationAuthority) == "v2.lens.cost" && @@ -247,7 +303,11 @@ test fn w_role_and_destination_are_separate_axes() -> Bool { acc || cost_migration_destination_module_path(d: d) == "v1.compiler.complexity") } -data w_producer_is_independent_of_destination_note: String = "The live specimen that forced the third axis. Parser-progress facts are produced by the v2 PARSER and joined through std.termination; their accounting still lands in the cost authority. With one enum the row had to name v2.lens.cost as producer, contradicting its own explanation. This asserts the two axes actually differ on that row — if a future edit re-fuses them, the inequality reds." +// The live specimen that forced the third axis. Parser-progress facts are produced by the v2 PARSER +// and joined through std.termination; their accounting still lands in the cost authority. With one +// enum the row had to name v2.lens.cost as producer, contradicting its own explanation. This +// asserts the two axes actually differ on that row — if a future edit re-fuses them, the inequality +// reds. test fn w_parser_progress_producer_differs_from_its_destination() -> Bool { match parser_progress_fact_production.disposition { @@ -257,7 +317,15 @@ test fn w_parser_progress_producer_differs_from_its_destination() -> Bool { } } -data w_residues_are_not_capabilities_note: String = "The operator's peer-inflation finding, pinned. SummaryEviction and ParserProgressV1Walker previously sat as variants of the capability vocabulary, so counting capabilities counted two things that are not capabilities. They are now residue items carrying the capability they belong to. ORACLE SHAPE, stated because an earlier revision of this very test got it wrong: the population assertion is the IDENTITY JOIN semantic + residues == rows, with both terms derived — not semantic + 2 == rows, whose literal 2 was measured from the same tree it checks and would have needed a manual edit the first time a third residue landed. DESIGN §5 names that shape a change detector. The identity-grained half — WHICH rows are residues and which capability each belongs to — is asserted separately below, where naming them is the point rather than a count." +// The operator's peer-inflation finding, pinned. SummaryEviction and ParserProgressV1Walker +// previously sat as variants of the capability vocabulary, so counting capabilities counted two +// things that are not capabilities. They are now residue items carrying the capability they belong +// to. ORACLE SHAPE, stated because an earlier revision of this very test got it wrong: the +// population assertion is the IDENTITY JOIN semantic + residues == rows, with both terms derived — +// not semantic + 2 == rows, whose literal 2 was measured from the same tree it checks and would +// have needed a manual edit the first time a third residue landed. DESIGN §5 names that shape a +// change detector. The identity-grained half — WHICH rows are residues and which capability each +// belongs to — is asserted separately below, where naming them is the point rather than a count. test fn w_legacy_residues_are_not_semantic_capabilities() -> Bool { let rows = length(xs: v1_complexity_inventory_roster) @@ -277,7 +345,11 @@ test fn w_legacy_residues_are_not_semantic_capabilities() -> Bool { }) } -data w_identity_distinctness_is_validated_note: String = "Stated as validation, not construction, because that is what it is (operator review 2026-08-05). A closed coproduct makes an identity outside the vocabulary unrepresentable; it does not stop a List from carrying one identity twice. This executes the distinctness fold over the live roster, and the paired control proves the fold is discriminating — a list with a planted duplicate must come back false, otherwise the green above would mean nothing." +// Stated as validation, not construction, because that is what it is (operator review 2026-08-05). +// A closed coproduct makes an identity outside the vocabulary unrepresentable; it does not stop a +// List from carrying one identity twice. This executes the distinctness fold over the live roster, +// and the paired control proves the fold is discriminating — a list with a planted duplicate must +// come back false, otherwise the green above would mean nothing. test fn w_roster_identities_are_distinct() -> Bool { inventory_identity_keys_distinct() && @@ -300,8 +372,9 @@ test fn w_distinctness_fold_reds_on_a_planted_duplicate() -> Bool { inventory_item_key(item: LegacyHazardItem { hazard: SummaryEvictionHazard, of_capability: CallGraphAndScc }) } - -data w_every_row_cites_the_seed_module_note: String = "Every row's v1_carrier must be a DeclarationRef into the seed module the census is about. This is the cheap structural half of citation hygiene; that the referenced declaration actually EXISTS is the long-lane resolution census's job, because deciding it requires the decl_facts scan." +// Every row's v1_carrier must be a DeclarationRef into the seed module the census is about. This is +// the cheap structural half of citation hygiene; that the referenced declaration actually EXISTS is +// the long-lane resolution census's job, because deciding it requires the decl_facts scan. test fn w_every_v1_carrier_targets_the_seed_module() -> Bool { fold(v1_complexity_inventory_roster, init: true, f: (acc, c) => diff --git a/dag/test/claim/v1_complexity_decl_classification_witness_test.dag b/dag/test/claim/v1_complexity_decl_classification_witness_test.dag index eb7194bff4c..44cd7000522 100644 --- a/dag/test/claim/v1_complexity_decl_classification_witness_test.dag +++ b/dag/test/claim/v1_complexity_decl_classification_witness_test.dag @@ -37,7 +37,17 @@ test fn w_classification_roster_is_nonempty() -> Bool { v1_complexity_decl_classification_roster_count(roster: v1_complexity_decl_classification_roster) > 0 } -data population_key_mechanism_note: String = "The MECHANISM half of the bare-name join precondition, deliberately here and not in the long-lane companion. classification_matches_fact joins a roster row to a DeclFact on bare name, which is sound only while the derived population's top-level names are distinct; population_names_distinct executes that instead of assuming it. The two witnesses below are synthetic two-element fixtures — they author their own input and their own expected answer, pay no decl_facts scan, and so belong in the per-PR lane where a regression reds immediately. Only the REAL-population reading is irreducible, and that one alone stays long-lane. This is the decomposition DESIGN requires of a live-population claim: small discriminating mechanism fixtures per PR plus the irreducible census on an enrolled cadence — the census may be irreducible, the mechanism never is. Note roster_names_distinct does NOT cover this: it constrains the AUTHORED side, and a duplicate on the DERIVED side is invisible to it." +// The MECHANISM half of the bare-name join precondition, deliberately here and not in the long-lane +// companion. classification_matches_fact joins a roster row to a DeclFact on bare name, which is +// sound only while the derived population's top-level names are distinct; population_names_distinct +// executes that instead of assuming it. The two witnesses below are synthetic two-element fixtures +// — they author their own input and their own expected answer, pay no decl_facts scan, and so +// belong in the per-PR lane where a regression reds immediately. Only the REAL-population reading +// is irreducible, and that one alone stays long-lane. This is the decomposition DESIGN requires of +// a live-population claim: small discriminating mechanism fixtures per PR plus the irreducible +// census on an enrolled cadence — the census may be irreducible, the mechanism never is. Note +// roster_names_distinct does NOT cover this: it constrains the AUTHORED side, and a duplicate on +// the DERIVED side is invisible to it. data planted_duplicate_population: List = [ DeclFact { diff --git a/dag/test/claim/v1_interpreter_primitive_surface_witness_test.dag b/dag/test/claim/v1_interpreter_primitive_surface_witness_test.dag index 62f3806a7c8..fae76ffa970 100644 --- a/dag/test/claim/v1_interpreter_primitive_surface_witness_test.dag +++ b/dag/test/claim/v1_interpreter_primitive_surface_witness_test.dag @@ -152,6 +152,17 @@ test fn an_unrecognised_form_label_refuses_rather_than_defaulting() -> Bool { form_is_unknown(form: decode_dispatch_form(label: "NotAFormLabel")) && !form_is_unknown(form: decode_dispatch_form(label: "FreeCall")) } +// THE CONTROLS ARE PAIRS AND NEITHER HALF IS OPTIONAL. Each detector has a discriminating RED and a +// positive control: an always-clean detector would pass every live-corpus witness and establish +// nothing, and one refusing legitimate structure would refuse the language, not the defect. +// shadow_detector_catches_a_planted_duplicate pairs with shadow_detector_admits_a_real_alias_pair +// -- two spellings under ONE arm identity is a legitimate alias, exactly why length, count and +// size cannot disagree. duplicate_detector_catches_a_row_repeated_under_one_identity pairs with +// duplicate_detector_admits_one_spelling_at_two_distinct_sites -- one spelling reached at two +// dispatch symbols is the real structure of map_insert and lookup, not a defect. +// an_unrecognised_form_label_refuses_rather_than_defaulting asserts BOTH directions so a decode +// answering UnknownForm for everything fails. The live witnesses execute against DERIVED rows +// projected from the interpreter's own dispatch tokens, reading the tree, not a transcript of it. test fn the_declared_residue_is_exactly_the_two_non_match_arm_sites() -> Bool { let expected = ["eval_method_call", "eval_service_call"] @@ -159,5 +170,3 @@ test fn the_declared_residue_is_exactly_the_two_non_match_arm_sites() -> Bool { count(actual |> filter(s => !expected |> any(e => e == s))) == 0 && count(expected |> filter(e => !actual |> any(s => s == e))) == 0 } - -data witness_control_pairing_note: String = "THE CONTROLS ARE PAIRS AND NEITHER HALF IS OPTIONAL. Each detector here has a discriminating RED and a positive control, because a detector that always answered clean would pass every live-corpus witness and establish nothing, and a detector that refused legitimate structure would be refusing the language rather than the defect. shadow_detector_catches_a_planted_duplicate is paired with shadow_detector_admits_a_real_alias_pair -- two spellings under ONE arm identity is a legitimate alias, which is exactly why length, count and size cannot disagree. duplicate_detector_catches_a_row_repeated_under_one_identity is paired with duplicate_detector_admits_one_spelling_at_two_distinct_sites -- one spelling reached at two different dispatch symbols is the real structure of map_insert and lookup, not a defect. an_unrecognised_form_label_refuses_rather_than_defaulting asserts BOTH directions so that a decode which answered UnknownForm for everything would fail. The live witnesses execute against DERIVED rows projected from the interpreter's own dispatch tokens, so they read the tree rather than a transcript of it." diff --git a/dag/test/claim/v1_source_audit_witness_test.dag b/dag/test/claim/v1_source_audit_witness_test.dag index f7d954065ae..21b7dcb0a93 100644 --- a/dag/test/claim/v1_source_audit_witness_test.dag +++ b/dag/test/claim/v1_source_audit_witness_test.dag @@ -276,15 +276,15 @@ test fn compile_gate_keeps_infer_errors_blocking_in_stage0() -> Bool { && src_has(compile_stage0_path, "stage0_self_compile_refusal_message") } -// REPOINTED AT THE SUCCESSOR, NOT RETIRED. The subject moved rather than being removed: 3b431f34a9e -// (#8406) deleted the `regen_stage0` binary and `claim_executor --required-regen` took over both its -// write and its verify halves, so from that commit until this one the witness read a path that no -// longer existed. What it asserts still has a home, and the negative conjunct still has an authored -// RED behind it -- at 268919db21e^ the deleted binary carried `let hard_errors: Vec`, its own -// forked hard-diagnostic classification, and #6293 is the commit that removed it in favour of the -// shared authority. The successor is stronger than the subject this witness was written against: -// `run_required_regen` (write) and `run_required_regen_fixed_point` (verify) do not merely share the -// authority, they share the single `compile_stage0` call that consults it. +// REPOINTED AT THE SUCCESSOR, NOT RETIRED. The subject moved: 3b431f34a9e (#8406) deleted the +// `regen_stage0` binary and `claim_executor --required-regen` took over its write and verify +// halves, so from that commit until this one the witness read a path that no longer existed. The +// assertion still has a home, and the negative conjunct still has an authored RED: at 268919db21e^ +// the deleted binary carried `let hard_errors: Vec`, its own forked hard-diagnostic +// classification, and #6293 removed it in favour of the shared authority. The successor is +// stronger than the original subject: `run_required_regen` (write) and +// `run_required_regen_fixed_point` (verify) share not just the authority but the single +// `compile_stage0` call that consults it. test fn required_regen_write_and_verify_share_compile_refusal() -> Bool { src_has(required_regen_host_path, "stage0_self_compile_refusal_message") && src_lacks(required_regen_host_path, "hard_errors: Vec") diff --git a/dag/test/claim/web_motion_binding_witness_test.dag b/dag/test/claim/web_motion_binding_witness_test.dag index 8239e5d1f82..12e923b3c44 100644 --- a/dag/test/claim/web_motion_binding_witness_test.dag +++ b/dag/test/claim/web_motion_binding_witness_test.dag @@ -77,7 +77,9 @@ import gunbc.design.instrument_physical { data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -data web_motion_binding_witness_note: String = "The web realization's own axes, the exact providers, and the projection outward — each law beside the control that reds it. The central claim stays negative: an observation that did not look cannot conclude. Its specimen is the 2026-08-05 capability probe, reconstructed field by field." +// The web realization's own axes, the exact providers, and the projection outward — each law beside +// the control that reds it. The central claim stays negative: an observation that did not look +// cannot conclude. Its specimen is the 2026-08-05 capability probe, reconstructed field by field. fn probe_subject() -> HostRealization { HostRealization { @@ -110,7 +112,10 @@ fn probe_subject() -> HostRealization { } } -data discredited_probe_note: String = "THE 2026-08-05 PROBE, RECONSTRUCTED FIELD BY FIELD. It ran inside an embedding context it never inspected, over a secure context it did read, with DeviceMotionEvent exposed, the standard permission method absent, the permission STATE never established, both feature policies unread, zero events, and no recorded window." +// THE 2026-08-05 PROBE, RECONSTRUCTED FIELD BY FIELD. It ran inside an embedding context it never +// inspected, over a secure context it did read, with DeviceMotionEvent exposed, the standard +// permission method absent, the permission STATE never established, both feature policies unread, +// zero events, and no recorded window. fn discredited_probe_observation() -> WebMotionObservation { WebMotionObservation { @@ -138,7 +143,12 @@ fn witness_the_discredited_probe_resolves_nothing() -> Bool { } } -data six_not_five_note: String = "SIX UNREAD AXES, NOT FIVE — and the sixth is the one the earlier model hid. Splitting permission-method exposure from permission STATE moved this count, because the probe observed that the standard asking route was absent and never established whether readings were actually permitted. The old carrier counted that as a fully read axis, so the count said decisive while the prose said unknown. The count now agrees with the prose: browsing context, visibility, focus, both feature policies, and the permission state." +// SIX UNREAD AXES, NOT FIVE — and the sixth is the one the earlier model hid. Splitting +// permission-method exposure from permission STATE moved this count, because the probe observed +// that the standard asking route was absent and never established whether readings were actually +// permitted. The old carrier counted that as a fully read axis, so the count said decisive while +// the prose said unknown. The count now agrees with the prose: browsing context, visibility, focus, +// both feature policies, and the permission state. fn witness_the_probe_left_six_axes_unread_and_no_window() -> Bool { let o = discredited_probe_observation() @@ -177,7 +187,11 @@ fn reachability_of(s: MotionStreamState) -> String { motion_reachability_key(r: derive_reachability(o: observation_with_stream(s: s))) } -data refused_connection_note: String = "A REFUSED CONNECTION DESCRIBES ONE ATTEMPT, NOT A MACHINE — and an earlier revision derived unreachable from it while this file's own note said the opposite. The note had the stronger reading and the code now matches it: NotReadableError leaves hardware reachability unresolved. A binding-attempt verdict may still say that THIS attempt was refused, which is a different question at a different grain." +// A REFUSED CONNECTION DESCRIBES ONE ATTEMPT, NOT A MACHINE — and an earlier revision derived +// unreachable from it while this file's own note said the opposite. The note had the stronger +// reading and the code now matches it: NotReadableError leaves hardware reachability unresolved. A +// binding-attempt verdict may still say that THIS attempt was refused, which is a different +// question at a different grain. fn witness_only_named_obstacles_are_unreachable() -> Bool { reachability_of(s: StreamInterfaceNotExposed) == "unreachable" @@ -260,7 +274,9 @@ fn witness_red_activation_without_a_reading_is_not_success() -> Bool { && sensor_lifecycle_key(s: SensorActivated) == "activated" } -data exact_provider_witness_note: String = "The provider is the exact interface, not a family. GenericSensorApi could not say which constructor was tried nor whether gravity would have been included; the three concrete sensors differ on precisely that, and only one of them suits a knock detector." +// The provider is the exact interface, not a family. GenericSensorApi could not say which +// constructor was tried nor whether gravity would have been included; the three concrete sensors +// differ on precisely that, and only one of them suits a knock detector. fn witness_the_provider_is_an_exact_interface() -> Bool { web_provider_key(p: DeviceMotionEventProvider) == "DeviceMotionEvent" @@ -272,14 +288,20 @@ fn witness_the_provider_is_an_exact_interface() -> Bool { && accelerometer_interface_name(i: LinearAccelerationSensor) == "LinearAccelerationSensor" } -data upstream_route_note: String = "The Accelerometer extension itself says it is maintained for existing deployments and points new projects at Device Orientation and Motion for cross-engine support. That is why both routes are probed rather than either: DeviceMotion for breadth, LinearAccelerationSensor because a Generic Sensor lifecycle names its failure where a silent event stream names nothing." +// The Accelerometer extension itself says it is maintained for existing deployments and points new +// projects at Device Orientation and Motion for cross-engine support. That is why both routes are +// probed rather than either: DeviceMotion for breadth, LinearAccelerationSensor because a Generic +// Sensor lifecycle names its failure where a silent event stream names nothing. fn witness_the_upstream_names_device_motion_the_cross_engine_route() -> Bool { maintained_for_existing_deployments && upstream_recommends_device_orientation_for_new_projects } -data projection_honesty_note: String = "THE THREE FABRICATIONS THIS CONTROL CLOSES. No events must not become an activation; an unmeasured frequency must not become zero hertz; an unmeasured noise floor must not become a perfect signal. The neutral silence arm now carries a lifecycle that says activation was never observed, and the sample receipt carries unobserved on every axis the web route does not supply." +// THE THREE FABRICATIONS THIS CONTROL CLOSES. No events must not become an activation; an +// unmeasured frequency must not become zero hertz; an unmeasured noise floor must not become a +// perfect signal. The neutral silence arm now carries a lifecycle that says activation was never +// observed, and the sample receipt carries unobserved on every axis the web route does not supply. fn witness_the_web_stream_projects_without_inventing_facts() -> Bool { binding_stream_key(s: project_binding_stream(o: discredited_probe_observation())) == @@ -304,7 +326,10 @@ fn witness_red_an_unmeasured_frequency_is_not_zero_hertz() -> Bool { } } -data web_cannot_self_qualify_note: String = "The RED that keeps readability from becoming fitness across the seam: no web stream arm projects to a qualified tap. A browser reports events and samples; whether a knock was distinguishable is a judgement made over those samples against a declared requirement, and the web receipt leaves the noise floor and axis count unobserved, so it could not qualify even if it tried." +// The RED that keeps readability from becoming fitness across the seam: no web stream arm projects +// to a qualified tap. A browser reports events and samples; whether a knock was distinguishable is +// a judgement made over those samples against a declared requirement, and the web receipt leaves +// the noise floor and axis count unobserved, so it could not qualify even if it tried. fn witness_red_no_web_arm_can_project_to_a_qualified_tap() -> Bool { binding_stream_key(s: project_binding_stream(o: observation_with_stream( @@ -312,7 +337,10 @@ fn witness_red_no_web_arm_can_project_to_a_qualified_tap() -> Bool { "tap-qualified" } -data contradiction_note: String = "An observation can be complete and still be impossible, and the earlier derivation read only the stream. Readings under an insecure context, a blocked policy, or a denied permission are each refused by the cited contracts, so they are located contradictions rather than verdicts — named separately because their remedies differ." +// An observation can be complete and still be impossible, and the earlier derivation read only the +// stream. Readings under an insecure context, a blocked policy, or a denied permission are each +// refused by the cited contracts, so they are located contradictions rather than verdicts — named +// separately because their remedies differ. fn contradicted_observation(c: ObservationContradiction) -> WebMotionObservation { let base = observation_with_stream(s: StreamReadingsObserved { count: 10, peak_milli_m_per_s2: 3000, sample_interval_ms: 16 }) @@ -367,13 +395,23 @@ fn is_contradicted(o: WebMotionObservation) -> Bool { } } -data admission_on_path_note: String = "THE CLAIM THAT WAS MISSING. The old control proved admit_web_observation NOTICES a contradiction; nothing proved a contradicted observation could not reach a verdict, and both consumers matched the stream arm alone. So this asserts the consumers directly: a contradicted record derives unresolved rather than reachable, and projects to unobserved rather than to samples — the two routes a caller who never called admission would have taken." +// THE CLAIM THAT WAS MISSING. The old control proved admit_web_observation NOTICES a contradiction; +// nothing proved a contradicted observation could not reach a verdict, and both consumers matched +// the stream arm alone. So this asserts the consumers directly: a contradicted record derives +// unresolved rather than reachable, and projects to unobserved rather than to samples — the two +// routes a caller who never called admission would have taken. fn reachability_of_observation(o: WebMotionObservation) -> String { motion_reachability_key(r: derive_reachability(o: o)) } -data gyroscope_is_per_provider_note: String = "THE SAME BLOCKED POLICY IS A CONTRADICTION FOR ONE PROVIDER AND SILENCE FOR ANOTHER, which is what makes the per-provider derivation a real distinction rather than a widened check. devicemotion dispatches only when both named permissions are granted, so readings under a blocked gyroscope policy are impossible there; a LinearAccelerationSensor is admitted by its own feature and a gyroscope policy says nothing about it. The fixture for the gyroscope contradiction therefore switches the provider, and this control asserts BOTH directions — otherwise the check would pass by being applied everywhere." +// THE SAME BLOCKED POLICY IS A CONTRADICTION FOR ONE PROVIDER AND SILENCE FOR ANOTHER, which is +// what makes the per-provider derivation a real distinction rather than a widened check. +// devicemotion dispatches only when both named permissions are granted, so readings under a blocked +// gyroscope policy are impossible there; a LinearAccelerationSensor is admitted by its own feature +// and a gyroscope policy says nothing about it. The fixture for the gyroscope contradiction +// therefore switches the provider, and this control asserts BOTH directions — otherwise the check +// would pass by being applied everywhere. fn readings_with_blocked_gyroscope(p: WebMotionProvider) -> WebMotionObservation { let base = observation_with_stream(s: StreamReadingsObserved { count: 10, peak_milli_m_per_s2: 3000, sample_interval_ms: 16 }) diff --git a/dag/test/claim/wet_receipt_route_standing_witness_test.dag b/dag/test/claim/wet_receipt_route_standing_witness_test.dag index 3e07e8a76f8..c56681a584e 100644 --- a/dag/test/claim/wet_receipt_route_standing_witness_test.dag +++ b/dag/test/claim/wet_receipt_route_standing_witness_test.dag @@ -18,7 +18,19 @@ import v2.compiler.self_host.wet_receipt_route_standing { data live_tree_disposition: v2.std.live_tree.LiveTreeDisposition = v2.std.live_tree.SubstrateInputsOnly -data wet_receipt_route_standing_witness_doc: String = "THE CONTROL FOR THE ROW-GRAIN ROUTE AUTHORITY, and what it asserts is deliberately NOT a census. A witness that pinned `exactly 6 revoked, exactly 10 never-established, exactly 1 executable` would be a count copied from the current tree, which DESIGN section 5 rules out as an oracle: restoring one binding would red it, and automating its update would collapse it to measure() == measure(). Completeness here is an IDENTITY JOIN over a closed universe, not a count equality.\n\nSo the arms below assert the DERIVATION instead: that a receipt which IS a known-red entry derives BindingRevokedOnMeasuredRed and one that is not derives BindingNeverEstablished; that the partition is total; and that the fault marker equals the exact string the driver source prints, which is an external oracle (dag/gunbc/instruments/self_host_00_compile_shims/witness_main.rs) rather than a measurement of this tree. Restoring a binding changes the standings and must NOT red this file -- that is the correct behaviour, because the roster is meant to move and the derivation is not." +// THE CONTROL FOR THE ROW-GRAIN ROUTE AUTHORITY, and what it asserts is deliberately NOT a census. +// A witness that pinned `exactly 6 revoked, exactly 10 never-established, exactly 1 executable` +// would be a count copied from the current tree, which DESIGN section 5 rules out as an oracle: +// restoring one binding would red it, and automating its update would collapse it to measure() == +// measure(). Completeness here is an IDENTITY JOIN over a closed universe, not a count equality. +// +// So the arms below assert the DERIVATION instead: that a receipt which IS a known-red entry +// derives BindingRevokedOnMeasuredRed and one that is not derives BindingNeverEstablished; that the +// partition is total; and that the fault marker equals the exact string the driver source prints, +// which is an external oracle (dag/gunbc/instruments/self_host_00_compile_shims/witness_main.rs) +// rather than a measurement of this tree. Restoring a binding changes the standings and must NOT +// red this file -- that is the correct behaviour, because the roster is meant to move and the +// derivation is not. // AN EXTERNAL ORACLE, NOT A TREE MEASUREMENT. The expected string is what the 00_compile driver // actually prints on its inject-fault path. If the derivation ever produced a different marker, the diff --git a/dag/test/claim/whole_corpus_compile_admission_witness_test.dag b/dag/test/claim/whole_corpus_compile_admission_witness_test.dag index 78b8de4c4d4..686e061c2a8 100644 --- a/dag/test/claim/whole_corpus_compile_admission_witness_test.dag +++ b/dag/test/claim/whole_corpus_compile_admission_witness_test.dag @@ -96,7 +96,27 @@ test fn the_budget_the_superseded_figure_admitted_is_now_refused() -> Bool { })) == false } -data runner_slot_refusal_note: String = "THIS ROW WAS INVERTED, NOT EDITED TO STAY GREEN, and the distinction is the whole reason it carries a note. It asserted the_runner_ci_actually_uses_is_admitted. Raising the declared demand to cover the highest measured COMPLETING peak (gunbc.whole_corpus_compile_admission whole_corpus_compile_measured_demand_note, review 57202 on gunbc#9545) put the threshold above the runner slot's reported budget, so the previous assertion became false about the tree. The two available responses were to change what the row asserts or to change the threshold until the row stayed true; the second is the failure this whole module exists to refuse, since it derives a safety literal from the outcome someone wanted.\n\nWHAT IT NOW ASSERTS AND WHY THAT IS THE CORRECT VERDICT RATHER THAN A CONCESSION. The budget resolved from a slot is memory_high -- the line the host has agreed to give before it throttles -- and the demand exceeds it. A completing run would in fact survive there, degrading into swap below the 16 GiB memory_max kill line, so this is an over-refusal measured against SURVIVAL and an exact refusal measured against the BUDGET. An admission arm that admits on the grounds that a host tolerates breaches past its own stated line is not fail-closed, so the refusal is the modelled answer and the survival margin is a fact about the host, not a licence.\n\nWHAT WOULD MAKE THIS ROW FLIP BACK: a slot provisioned above the demand, or a re-measured demand that is genuinely lower under this module's own re-measure trigger -- which only fires on a HIGHER reading, so the second path requires the trigger to be changed on its own argument and not as a side effect of wanting this green." +// THIS ROW WAS INVERTED, NOT EDITED TO STAY GREEN, and the distinction is the whole reason it +// carries a note. It asserted the_runner_ci_actually_uses_is_admitted. Raising the declared demand +// to cover the highest measured COMPLETING peak (gunbc.whole_corpus_compile_admission +// whole_corpus_compile_measured_demand_note, review 57202 on gunbc#9545) put the threshold above +// the runner slot's reported budget, so the previous assertion became false about the tree. The two +// available responses were to change what the row asserts or to change the threshold until the row +// stayed true; the second is the failure this whole module exists to refuse, since it derives a +// safety literal from the outcome someone wanted. +// +// WHAT IT NOW ASSERTS AND WHY THAT IS THE CORRECT VERDICT RATHER THAN A CONCESSION. The budget +// resolved from a slot is memory_high -- the line the host has agreed to give before it throttles +// -- and the demand exceeds it. A completing run would in fact survive there, degrading into swap +// below the 16 GiB memory_max kill line, so this is an over-refusal measured against SURVIVAL and +// an exact refusal measured against the BUDGET. An admission arm that admits on the grounds that a +// host tolerates breaches past its own stated line is not fail-closed, so the refusal is the +// modelled answer and the survival margin is a fact about the host, not a licence. +// +// WHAT WOULD MAKE THIS ROW FLIP BACK: a slot provisioned above the demand, or a re-measured demand +// that is genuinely lower under this module's own re-measure trigger -- which only fires on a +// HIGHER reading, so the second path requires the trigger to be changed on its own argument and not +// as a side effect of wanting this green. test fn the_runner_ci_actually_uses_is_refused_at_the_completing_peak_demand() -> Bool { whole_corpus_compile_admits(a: whole_corpus_compile_admission(budget: fleet_runner_slot_budget())) == false diff --git a/dag/test/claim/witness_deferral_freeze_witness_test.dag b/dag/test/claim/witness_deferral_freeze_witness_test.dag index c1a897b03c9..efedc35db53 100644 --- a/dag/test/claim/witness_deferral_freeze_witness_test.dag +++ b/dag/test/claim/witness_deferral_freeze_witness_test.dag @@ -115,7 +115,13 @@ test fn witness_deferral_freeze_unfrozen_offline_row_refuses() -> Bool { ) } -data frozen_is_tolerated_not_covered_note: String = "THE CLAIM THIS PAIR SEPARATES, and the defect it exists to prevent from returning. A frozen row is TOLERATED by the migration ratchet and is NOT COVERED, and those are answered by two different gates over the same standing. The first shape of this wall returned one success arm for both, so a frozen row was indistinguishable from a witness with a real cadence and the live gate going green read as evidence that every current row is admitted — while every one of those rows still executed nowhere. Here the same standing answers NO to coverage and YES to the floor, and a third claim shows the floor's YES is conditional on the baseline axis rather than unconditional." +// THE CLAIM THIS PAIR SEPARATES, and the defect it exists to prevent from returning. A frozen row +// is TOLERATED by the migration ratchet and is NOT COVERED, and those are answered by two different +// gates over the same standing. The first shape of this wall returned one success arm for both, so +// a frozen row was indistinguishable from a witness with a real cadence and the live gate going +// green read as evidence that every current row is admitted — while every one of those rows still +// executed nowhere. Here the same standing answers NO to coverage and YES to the floor, and a third +// claim shows the floor's YES is conditional on the baseline axis rather than unconditional. test fn witness_deferral_freeze_frozen_row_is_not_covered() -> Bool { !witness_has_executing_consumer( @@ -256,7 +262,14 @@ test fn witness_deferral_freeze_live_roster_is_well_formed() -> Bool { frozen_path_deferrals_well_formed() } -data commit_roster_consumer_control_note: String = "THE FALSE-POSITIVE CONTROL, and it caught a real one. A CommitWitnessClaim enrollment on an executing surface makes a witness run as an explicit entry, and explicit rows merge after discovery with no exclusion filter — so an enrolled witness under an offline path executes even though the path excludes it. The first revision of this wall did not read that authority and would have refused 31 such identities: fail-closed, and still a wrong answer. This pair is the discriminator, on a LIVE row rather than a fixture, because the defect was precisely that the live authority was unread: the identity below is admitted while being absent from the frozen population, so its admission can only be coming from its enrollment." +// THE FALSE-POSITIVE CONTROL, and it caught a real one. A CommitWitnessClaim enrollment on an +// executing surface makes a witness run as an explicit entry, and explicit rows merge after +// discovery with no exclusion filter — so an enrolled witness under an offline path executes even +// though the path excludes it. The first revision of this wall did not read that authority and +// would have refused 31 such identities: fail-closed, and still a wrong answer. This pair is the +// discriminator, on a LIVE row rather than a fixture, because the defect was precisely that the +// live authority was unread: the identity below is admitted while being absent from the frozen +// population, so its admission can only be coming from its enrollment. test fn witness_deferral_freeze_commit_roster_enrollment_admits() -> Bool { witness_has_executing_consumer_for_row( @@ -272,7 +285,13 @@ test fn witness_deferral_freeze_commit_roster_row_is_not_frozen() -> Bool { ) } -data rust_realization_disposition_note: String = "THE REALIZATION IS ACCOUNTED FOR, not just the policy. The .dag carriers above are the authority, but the seed realization in cli_run.rs is several hundred hand-maintained lines in the largest such wall in the program, and a modeled policy does not exempt its realization. gunbc.cli_run_witness_deferral_freeze_scaffold carries the typed Scaffold disposition, the measured landing LOC delta and the ordered dissolution sequence; this pair keeps that registration from becoming a file nobody reads by requiring the disposition to exist and to name a dissolution." +// THE REALIZATION IS ACCOUNTED FOR, not just the policy. The .dag carriers above are the authority, +// but the seed realization in cli_run.rs is several hundred hand-maintained lines in the largest +// such wall in the program, and a modeled policy does not exempt its realization. +// gunbc.cli_run_witness_deferral_freeze_scaffold carries the typed Scaffold disposition, the +// measured landing LOC delta and the ordered dissolution sequence; this pair keeps that +// registration from becoming a file nobody reads by requiring the disposition to exist and to name +// a dissolution. test fn witness_deferral_freeze_rust_realization_is_declared_scaffold() -> Bool { match cli_run_witness_deferral_freeze_scaffold { diff --git a/dag/test/claim/witness_execution_class_live_census_test.dag b/dag/test/claim/witness_execution_class_live_census_test.dag index eb370b2cb1f..d63f52a29d3 100644 --- a/dag/test/claim/witness_execution_class_live_census_test.dag +++ b/dag/test/claim/witness_execution_class_live_census_test.dag @@ -45,9 +45,34 @@ import gunbc.witness_execution_class { data live_tree_disposition: LiveTreeDisposition = ReadsLiveTree -data live_census_note: String = "CI-0 live-roster consumer (operator bar, msg_be57b9db; disposition fabrication corrected per review 50716): the classifier is exercised against the LIVE enrolled discovery roster — the same floor_discovery_producer walk over the same witness_discovery_scan_dirs the floor's corpus batch scans, PLUS the enrolled bundle entry's home dir (src/v2/test/claim/execution, outside the discovery dirs), so every classified identity's LiveTreeDisposition comes from the WALKED file-grain declaration, never a hand-supplied constant. An earlier revision passed SubstrateInputsOnly for the enrolled bundle members while their entry file declares ReadsLiveTree — a fabricated input that forced NativeRequired; under declared_class_precedence their honest class is NativeLiveObservation (LiveObservationAxis precedes CarriageAxis). Carriage joins from the plan two ways, neither fabricating a disposition: a walked test-fn identity that is an enrolled member gets CarriedInEnrolledBundle on its own walk row; an enrolled member that is NOT an authored test fn (the three logic members are emitted-tree names, not test declarations — the fn-grain vs plan-grain reconciliation Commit D owns) gets a plan-grain row whose disposition is derived by the walk's own resolution authority applied to its entry file (plan_entry_disposition -> floor_discovery_resolve_entry_live_tree over Filesystem.Read), so the bundle file's ReadsLiveTree comes from its authored declaration. Assertions are structural laws and identity joins, never tree-copied count literals (DESIGN §5 oracle rule): partition exactness, exactly-once at identity grain, and every enrolled plan member joining exactly one row whose class is a carried class (NativeRequired or NativeLiveObservation — a carried member never classifies as blocked). Residue, declared: the floor also walks source-root *_test.dag files outside these dirs; classifying that wider universe from .dag awaits the module-identity walk (the same wider-universe residue the discovery flip note carries)." +// CI-0 live-roster consumer (operator bar, msg_be57b9db; disposition fabrication corrected per +// review 50716): the classifier is exercised against the LIVE enrolled discovery roster — the same +// floor_discovery_producer walk over the same witness_discovery_scan_dirs the floor's corpus batch +// scans, PLUS the enrolled bundle entry's home dir (src/v2/test/claim/execution, outside the +// discovery dirs), so every classified identity's LiveTreeDisposition comes from the WALKED +// file-grain declaration, never a hand-supplied constant. An earlier revision passed +// SubstrateInputsOnly for the enrolled bundle members while their entry file declares ReadsLiveTree +// — a fabricated input that forced NativeRequired; under declared_class_precedence their honest +// class is NativeLiveObservation (LiveObservationAxis precedes CarriageAxis). Carriage joins from +// the plan two ways, neither fabricating a disposition: a walked test-fn identity that is an +// enrolled member gets CarriedInEnrolledBundle on its own walk row; an enrolled member that is NOT +// an authored test fn (the three logic members are emitted-tree names, not test declarations — the +// fn-grain vs plan-grain reconciliation Commit D owns) gets a plan-grain row whose disposition is +// derived by the walk's own resolution authority applied to its entry file (plan_entry_disposition +// -> floor_discovery_resolve_entry_live_tree over Filesystem.Read), so the bundle file's +// ReadsLiveTree comes from its authored declaration. Assertions are structural laws and identity +// joins, never tree-copied count literals (DESIGN §5 oracle rule): partition exactness, +// exactly-once at identity grain, and every enrolled plan member joining exactly one row whose +// class is a carried class (NativeRequired or NativeLiveObservation — a carried member never +// classifies as blocked). Residue, declared: the floor also walks source-root *_test.dag files +// outside these dirs; classifying that wider universe from .dag awaits the module-identity walk +// (the same wider-universe residue the discovery flip note carries). -data bundle_disposition_note: String = "The bundle entry lives outside witness_discovery_scan_dirs and its home dir is not a test-row home (floor_test_marked_decl_allowed_in_entry restricts row production to the enrolled discovery dirs), so its file-grain disposition is derived by applying the walk's OWN resolution authority — floor_discovery_resolve_entry_live_tree over a real Filesystem.Read of the entry — never a hand-supplied constant (review 50716) and never a second disposition parser." +// The bundle entry lives outside witness_discovery_scan_dirs and its home dir is not a test-row +// home (floor_test_marked_decl_allowed_in_entry restricts row production to the enrolled discovery +// dirs), so its file-grain disposition is derived by applying the walk's OWN resolution authority — +// floor_discovery_resolve_entry_live_tree over a real Filesystem.Read of the entry — never a +// hand-supplied constant (review 50716) and never a second disposition parser. fn live_discovery_state() -> FloorDiscoveryWalkState { fold_list( diff --git a/dag/test/claim/witness_floor_workflow_consolidation_witness_test.dag b/dag/test/claim/witness_floor_workflow_consolidation_witness_test.dag index ed0431fd22b..556ae393705 100644 --- a/dag/test/claim/witness_floor_workflow_consolidation_witness_test.dag +++ b/dag/test/claim/witness_floor_workflow_consolidation_witness_test.dag @@ -36,7 +36,12 @@ import extdeps.github.actions { PullRequestActivity, Opened, Synchronize, Reopen // // Stated so a reader does not over-read the green: this is the CHEAP half of the pair. -data consolidation_note: String = "The step ladder these replace was four steps: parse, regen, regen-fixed-point, floor. Each was its own process, the ORDER was a YAML list, each precondition was an `if:` naming another step's `outcome`, and the fixed-point step received pass 1's digest by re-reading the receipt FILE the regen process had written — a process boundary standing where a function call belonged, since run_required_regen_fixed_point has taken pass1_digest: Option all along and CI passed None." +// The step ladder these replace was four steps: parse, regen, regen-fixed-point, floor. Each was +// its own process, the ORDER was a YAML list, each precondition was an `if:` naming another step's +// `outcome`, and the fixed-point step received pass 1's digest by re-reading the receipt FILE the +// regen process had written — a process boundary standing where a function call belonged, since +// run_required_regen_fixed_point has taken pass1_digest: Option all along and CI passed +// None. // NO RETIRED INVOCATION HAS GROWN BACK, and the required mode token is present. That is the // whole of what this row proves, and the heading is narrowed to say so: the two positive @@ -310,7 +315,6 @@ test fn w_RED_aggregate_runs_on_a_cancelled_lane_and_refuses_a_failed_one() -> B data witness_live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly - // THE UNRENDERABLE-GATE REFUSAL IS EXECUTED, NOT DESCRIBED. // // This arm exists because the receipt was once WRONG about it in a way nothing executed could @@ -334,7 +338,6 @@ test fn the_unrenderable_gate_refusal_serializes_and_stops_the_line() -> Bool { } } - // THE PULL-REQUEST ACTIVITY SET IS EXACTLY THE THREE THAT CAN CARRY A NEW SUBJECT. // // gunbc#9361 deleted `ready_for_review` from this workflow's trigger. Nothing in the tree diff --git a/dag/test/claim/witness_row_cost_drift_witness_test.dag b/dag/test/claim/witness_row_cost_drift_witness_test.dag index 9be1ebb67d6..f1cc8165a10 100644 --- a/dag/test/claim/witness_row_cost_drift_witness_test.dag +++ b/dag/test/claim/witness_row_cost_drift_witness_test.dag @@ -16,7 +16,19 @@ import v2.std.optional { Absent, Present } import std.measure { ClockBasis, CpuClock, WallClock, clock_basis_eq } import v2.std.text { String } -data witness_row_cost_drift_note: String = "Executing consumer for the per-witness cost drift comparator (gunbc.witness_row_cost, placement #5 spine). THE PAIR IS THE PROOF: a synthetic row exceeding 2× its dated basis MUST produce DriftExceeded, and one within basis MUST NOT — either alone is satisfiable by a broken comparator. BasisAbsent is a third arm: no dated basis is typed and counted, never assume fine. Structural claims only here — every ms basis value in production rows must cite an arm64 fleet run id (witness_row_cost_basis_host_class_note). Consumers match WitnessRowCostVerdict directly (no Bool predicate dissolution). THE CROSS-CLOCK PAIR IS THE DISCRIMINATING CONTROL for the clock-basis wall (operator ruling 2026-08-05), and it takes TWO cases rather than one because a single case is satisfiable by a comparator that happens to be answering DriftExceeded for the wrong reason: 21 CPU against a 10 wall basis would exceed the 2x ratio and 20 CPU against the same basis would not, so the pair asserts that the SAME refusal arrives on both sides of the threshold and therefore that the refusal is decided by the clock rather than by the magnitude. Before this wall both cases returned a confident verdict about two different quantities." +// Executing consumer for the per-witness cost drift comparator (gunbc.witness_row_cost, placement +// #5 spine). THE PAIR IS THE PROOF: a synthetic row exceeding 2× its dated basis MUST produce +// DriftExceeded, and one within basis MUST NOT — either alone is satisfiable by a broken +// comparator. BasisAbsent is a third arm: no dated basis is typed and counted, never assume fine. +// Structural claims only here — every ms basis value in production rows must cite an arm64 fleet +// run id (witness_row_cost_basis_host_class_note). Consumers match WitnessRowCostVerdict directly +// (no Bool predicate dissolution). THE CROSS-CLOCK PAIR IS THE DISCRIMINATING CONTROL for the +// clock-basis wall (operator ruling 2026-08-05), and it takes TWO cases rather than one because a +// single case is satisfiable by a comparator that happens to be answering DriftExceeded for the +// wrong reason: 21 CPU against a 10 wall basis would exceed the 2x ratio and 20 CPU against the +// same basis would not, so the pair asserts that the SAME refusal arrives on both sides of the +// threshold and therefore that the refusal is decided by the clock rather than by the magnitude. +// Before this wall both cases returned a confident verdict about two different quantities. fn dated_basis(clock: ClockBasis, eval_ms: Nat, run_ref: String) -> WitnessRowCostDatedBasis { WitnessRowCostDatedBasis { diff --git a/dag/test/claim/witness_row_cost_migration_disclosure_witness_test.dag b/dag/test/claim/witness_row_cost_migration_disclosure_witness_test.dag index 8fc3aa37279..932c4b518a0 100644 --- a/dag/test/claim/witness_row_cost_migration_disclosure_witness_test.dag +++ b/dag/test/claim/witness_row_cost_migration_disclosure_witness_test.dag @@ -22,7 +22,11 @@ import std.observation { Done, observation_durations_wall } import v2.std.algebra { count_where, for_all } import v2.std.text { String } -// Executing consumer for the mandatory-migration disclosure (gunbc.witness_row_cost). THE PAIR IS THE PROOF, per the drift comparator's own discipline: a synthetic row at-or-above the derived threshold MUST produce MandatoryMigration, and a row comfortably below MUST NOT — either alone is satisfiable by a broken comparator. The derivation itself is pinned so the 500ms figure can never silently drift from the fast-lane authority: this test asserts the threshold IS gunbc_ci_fast_lane_eval_budget_ms()/10, never a hand-typed 500 literal. +// Executing consumer for the mandatory-migration disclosure (gunbc.witness_row_cost). THE PAIR IS +// THE PROOF, per the drift comparator's discipline: a synthetic row at-or-above the derived threshold +// MUST produce MandatoryMigration and a row comfortably below MUST NOT — either alone is satisfiable +// by a broken comparator. The derivation is pinned so the 500ms figure cannot drift from the +// fast-lane authority: the threshold IS gunbc_ci_fast_lane_eval_budget_ms()/10, never a 500 literal. fn derived_threshold_is_500ms_holds() -> Bool { witness_row_cost_migration_threshold_ms() == 500 } diff --git a/dag/test/claim/witness_row_cost_projection_witness_test.dag b/dag/test/claim/witness_row_cost_projection_witness_test.dag index 20bfa643d21..64511e3a975 100644 --- a/dag/test/claim/witness_row_cost_projection_witness_test.dag +++ b/dag/test/claim/witness_row_cost_projection_witness_test.dag @@ -65,7 +65,14 @@ import gunbc.observation_ci_render { } import v2.std.text { String } -data witness_row_cost_projection_note: String = "Executing REDs for the #5 ObservationEvent join projection (N+1 per entry). (1) DeclarationSegment key/grain totality lives in observation_model_witness_test. (2) Two modeled events → one exact TSV row. (3) Missing or multiple parent resolve events REFUSE the row set. (4) W2 Ambient suppress does not delete the complete receipt row. (5) Declaration-/module-nested resolve phases do NOT count as the entry-level parent (collision RED — review 43409). Resolve wall is entry-level/shared — repeated as a column, never divided, never summed N times as a corpus total. Role classification is witness_cost_event_role (typed extract), not is_* Bool filters." +// Executing REDs for the #5 ObservationEvent join projection (N+1 per entry). (1) +// DeclarationSegment key/grain totality lives in observation_model_witness_test. (2) Two modeled +// events → one exact TSV row. (3) Missing or multiple parent resolve events REFUSE the row set. (4) +// W2 Ambient suppress does not delete the complete receipt row. (5) Declaration-/module-nested +// resolve phases do NOT count as the entry-level parent (collision RED — review 43409). Resolve +// wall is entry-level/shared — repeated as a column, never divided, never summed N times as a +// corpus total. Role classification is witness_cost_event_role (typed extract), not is_* Bool +// filters. fn sample_decl(name: String) -> DeclarationRef { DeclarationRef { diff --git a/dag/test/claim/workload_simulation_witness_test.dag b/dag/test/claim/workload_simulation_witness_test.dag index f6a5be1e57e..cdd6a715ccc 100644 --- a/dag/test/claim/workload_simulation_witness_test.dag +++ b/dag/test/claim/workload_simulation_witness_test.dag @@ -47,13 +47,11 @@ fn rented_lane() -> SupplyLane { } // A SECOND RENTED LANE THAT BILLS PER SLOT, SO ONE WITNESS MOVES ONE AXIS. -// rented_lane above bills a 60-slot minimum increment, and that increment is so much larger -// than a one-slot job that it dominates every total it appears in -- owning wins under every -// arrival shape simply because renting wastes fifty-nine slots per job. That is a real and -// important effect, and it is exactly why it gets its own witness instead of being left to -// contaminate the shape witnesses: a test whose fixture moves two axes cannot say which one -// produced its answer. The lanes below hold billing continuous so that demand shape is the -// only thing left varying. +// rented_lane above bills a 60-slot minimum increment, which dominates every total it appears in +// -- owning wins under every arrival shape because renting wastes fifty-nine slots per job. That +// real effect gets its own witness instead of contaminating the shape witnesses: a fixture that +// moves two axes cannot say which produced its answer. The lanes below hold billing continuous so +// demand shape is the only thing varying. fn rented_lane_per_slot() -> SupplyLane { SupplyLane { label: "rented-per-slot", @@ -110,29 +108,27 @@ test fn flat_demand_at_committed_width_makes_the_commitment_pay() -> Bool { } // THE SAME COMMITMENT, THE SAME TOTAL WORK, ARRIVING IN BURSTS -- AND THE VERDICT FLIPS. -// One slot in sixty carries 600 concurrent jobs and the other fifty-nine carry none. Mean -// demand is 10 -- identical to the flat case above -- so the owned lane is idle almost -// always while its commitment accrues every slot, and the burst overflows it 60x over. Rent -// pays only for the ten burst slots it is used in; the commitment pays for all 600. This is -// the peak-to-average axis deciding the -// answer, which is the whole reason the model sweeps shapes instead of fitting one curve. -// If this ever agreed with the flat case, the simulation would have collapsed into a unit -// price comparison and this test goes red. +// One slot in sixty carries 600 concurrent jobs and the other fifty-nine carry none. Mean demand +// is 10 -- identical to the flat case -- so the owned lane is idle almost always while its +// commitment accrues every slot, and the burst overflows it 60x. Rent pays only for the ten burst +// slots it is used in; the commitment pays for all 600. The peak-to-average axis decides the +// answer, which is why the model sweeps shapes instead of fitting one curve. If this ever agreed +// with the flat case, the simulation would have collapsed into a unit price comparison and this +// test goes red. test fn bursty_demand_of_equal_mean_makes_the_same_commitment_lose() -> Bool { verdict_costs_more(v: run_for(shape: BurstyArrival { base: 0, burst: 600, every_slots: 60, burst_width: 1, })) } -// The two verdicts above must not merely differ in wording -- they must be opposite arms -// reached from the SAME commitment and the SAME mean demand. Asserting the pair together -// is what makes either one load-bearing. -// MEAN DEMAND IS HELD AT TEN ON BOTH SIDES AND ONLY THE SHAPE MOVES. Flat ten every slot -// and six hundred once in sixty are the same 6000 job-slots of work; the verdicts are -// opposite arms. An earlier revision of this test asserted the same arm on both sides while -// its own comment claimed a flip, and it went red the first time it was executed -- the -// assertion, not the model, was wrong. If these two ever agree again, the simulation has -// collapsed into a unit-price comparison and this witness is the thing that says so. +// The two verdicts above must be opposite arms reached from the SAME commitment and the SAME +// mean demand, not merely different wording; asserting the pair together makes either one +// load-bearing. +// MEAN DEMAND IS HELD AT TEN ON BOTH SIDES AND ONLY THE SHAPE MOVES. Flat ten every slot and six +// hundred once in sixty are the same 6000 job-slots of work; the verdicts are opposite arms. An +// earlier revision asserted the same arm on both sides while its comment claimed a flip, and went +// red on first execution -- the assertion, not the model, was wrong. If these ever agree again, +// the simulation has collapsed into a unit-price comparison and this witness says so. test fn demand_shape_alone_flips_the_acquisition_verdict() -> Bool { let flat = run_for(shape: FlatArrival { concurrent: 10 }) let bursty = run_for(shape: BurstyArrival { base: 0, burst: 600, every_slots: 60, burst_width: 1 }) @@ -140,11 +136,11 @@ test fn demand_shape_alone_flips_the_acquisition_verdict() -> Bool { } // BILLING QUANTUM IS VISIBLE IN THE TOTAL, NOT JUST IN THE TYPE, AND IT ROUNDS DURATION. -// A supplier's minimum increment applies to each job's runtime, so one one-slot job on a -// 60-slot increment bills sixty and continuous capacity bills one. The second pair is the -// discriminating half: sixty concurrent jobs bill sixty EACH, not sixty between them. An -// earlier revision billed the slot's concurrency instead of each job's duration, which -// passed typechecking because both are Nat and produced 60 where 3600 is correct. +// A supplier's minimum increment applies to each job's runtime, so one one-slot job on a 60-slot +// increment bills sixty and continuous capacity bills one. The discriminating half: sixty +// concurrent jobs bill sixty EACH, not sixty between them. An earlier revision billed the slot's +// concurrency instead of each job's duration -- both Nat, so it typechecked -- and produced 60 +// where 3600 is correct. test fn quantum_rounding_bills_a_partial_increment_as_a_whole_one() -> Bool { billed_slots_per_job(quantum_slots: 60) == 60 && billed_slots_per_job(quantum_slots: 0) == 1 @@ -152,10 +148,9 @@ test fn quantum_rounding_bills_a_partial_increment_as_a_whole_one() -> Bool { } // THE INCREMENT ALONE, WITH DEMAND HELD FLAT, IS WORTH A WITNESS OF ITS OWN. -// Same rate, same work, same shape: the only difference is that one rented lane bills a -// 60-slot minimum and the other bills per slot. Sixty-fold on the rented total is the waste -// that makes short CI jobs favour owned capacity regardless of headline rate, and it is the -// arbitrage the product exists to find. +// Same rate, work and shape; one rented lane bills a 60-slot minimum, the other per slot. +// Sixty-fold on the rented total is the waste that makes short CI jobs favour owned capacity +// regardless of headline rate -- the arbitrage the product exists to find. test fn a_coarse_billing_increment_multiplies_the_rented_total() -> Bool { let flat = FlatArrival { concurrent: 5 } let coarse = simulate(shape: flat, lanes: [rented_lane()], slots: 600) diff --git a/dag/test/fixture/codex_device_login/README.md b/dag/test/fixture/codex_device_login/README.md index 899637840d9..c4bbeca0375 100644 --- a/dag/test/fixture/codex_device_login/README.md +++ b/dag/test/fixture/codex_device_login/README.md @@ -15,30 +15,30 @@ run on srv2 on 2026-07-30 against codex-cli **0.145.0**, captured before the `codex login` has **no structured output mode**. `--help` lists only `-c/--config`, `--with-api-key` and `--device-auth`; there is no `--json` on either `login` or `login status`. So the URL and one-time code can only be read -from a text surface, and a parser over that surface is the honest realization -rather than a shortcut — the richer source does not exist to be read. +from a text surface, and a parser over it is the honest realization — the richer +source does not exist. That makes this capture load-bearing. A parser written against remembered or -re-typed output is untested against the bytes the tool actually emits, and the -first thing such a parser gets wrong is the ANSI wrapping: the code is -`ESC[94mYWCU-V8ESC ESC[0m`, not `YWCU-V8ESC`, so a naive line-trim yields a code -with escape bytes in it that the user then pastes and OpenAI rejects. +re-typed output is untested against the bytes the tool emits, and the first +thing it gets wrong is the ANSI wrapping: the code is `ESC[94mYWCU-V8ESC ESC[0m`, +not `YWCU-V8ESC`, so a naive line-trim yields a code with escape bytes that +OpenAI rejects when pasted. ## Why `--device-auth` and not plain `codex login` Plain `codex login` starts a callback server and prints `redirect_uri=http://localhost:1455/auth/callback`. On a headless host that redirect **can never resolve from the operator's browser** — localhost is the -server, not their machine. codex says so itself in its final line: +server, not their machine. codex's own final line says so: > On a remote or headless machine? Use `codex login --device-auth` instead. -The device flow needs no inbound port and no browser on the host: a URL and a -short code, entered anywhere. It is the only flow a remote dashboard can +The device flow needs no inbound port and no browser on the host — a URL and a +short code, entered anywhere — so it is the only flow a remote dashboard can usefully surface. ## Non-goal The code in this file is **expired and consumed**; it authenticates nothing. -It is retained as a parse fixture, not as a credential — which is why it may -live in the repository at all. +It is retained as a parse fixture, not a credential, which is why it may live in +the repository. diff --git a/dag/test/fixture/codex_provider_events/README.md b/dag/test/fixture/codex_provider_events/README.md index 66ba8f87e69..d2d435815e4 100644 --- a/dag/test/fixture/codex_provider_events/README.md +++ b/dag/test/fixture/codex_provider_events/README.md @@ -4,13 +4,12 @@ 2026-07-29 against `@openai/codex` **0.145.0** (`codex-linux-arm64`, aarch64-unknown-linux-musl) authenticated via ChatGPT, with the prompt `Reply with exactly: ok` under `--sandbox read-only`. -It exists because the `agent_message` item's text field could not be cited from anywhere else. -Nothing in the repository recorded it, the shipped CLI is a stripped native binary rather than -readable source, and `learn.chatgpt.com/docs/non-interactive-mode` — the locator -`extdeps.llm.cli` already cites — documents the mode, not the per-item event schema. Modeling -the field from memory would have been exactly the guess DESIGN §3 forbids for an `extdeps` -surface ("model what the API actually returns"), and the #7368 design note makes the same rule -explicit for provider grammars: a vocabulary is admitted only "after an actual provider receipt +It exists because the `agent_message` item's text field could not be cited from anywhere else: +nothing in the repository recorded it, the shipped CLI is a stripped native binary, and +`learn.chatgpt.com/docs/non-interactive-mode` — the locator `extdeps.llm.cli` already cites — +documents the mode, not the per-item event schema. Modeling the field from memory would be the +guess DESIGN §3 forbids for an `extdeps` surface ("model what the API actually returns"), and +the #7368 design note admits a provider vocabulary only "after an actual provider receipt demonstrates its grammar." So one was produced. The load-bearing line is the third: @@ -22,15 +21,14 @@ The load-bearing line is the third: `item.text` is therefore evidence, not inference, and `codex_provider_event_projection_filter` reads that member on that authority. -Two incidental facts the capture also settles, recorded because they are cheap to keep and -expensive to re-derive: `turn.completed` carries a `usage` object with token counts (unread by -the projection today — a candidate carrier if attempt cost ever wants modeling), and -`thread.started` carries `thread_id`, which is the provider-session identity the resume/follow-up -lane will need. +Two incidental facts the capture settles, kept because they are expensive to re-derive: +`turn.completed` carries a `usage` object with token counts (unread by the projection today — a +candidate carrier if attempt cost is ever modeled), and `thread.started` carries `thread_id`, the +provider-session identity the resume/follow-up lane will need. The `thread_id` is scrubbed to a zero UUID: it identifies a real provider session and is not a -fact this fixture is asserting. Every other byte is as captured. +fact this fixture asserts. Every other byte is as captured. -**Re-capture on:** a Codex major/minor version bump that changes the event envelope. This receipt -is version-stamped precisely so a schema change is a visible re-capture rather than a silent -drift in what the projection believes. +**Re-capture on:** a Codex major/minor version bump that changes the event envelope. The receipt +is version-stamped so a schema change is a visible re-capture, not silent drift in what the +projection believes. diff --git a/dag/test/manual/git_upstream_model_execution_test.dag b/dag/test/manual/git_upstream_model_execution_test.dag index d4a5629e157..38577cba658 100644 --- a/dag/test/manual/git_upstream_model_execution_test.dag +++ b/dag/test/manual/git_upstream_model_execution_test.dag @@ -62,7 +62,16 @@ import v2.std.live_tree { LiveTreeDisposition, ReadsLiveTree } data live_tree_disposition: LiveTreeDisposition = ReadsLiveTree -data git_r0_execution_receipt_note: String = "Offline wet T1 receipt for the bounded Git R0 fixture. This is a runtime-present typed effect graph: shell.Mktemp, Filesystem.Write, shell.Mkdir, shell.Test, shell.Remove, and individual gunbc.WitnessBin.Run argv invocations. No shell program is serialized. Real Git hashes SHA-1 and SHA-256 blobs, writes the tree, commits and annotated tag, validates five tree modes plus a non-ASCII path, checks the index/worktree, runs fsck, performs exact-old-OID compare-and-swap through symbolic HEAD while retaining its target, proves stale and nonexistent-object updates refuse, and independently reads the ref/tag/tree state back. Local recipe: claim_batch --wet --source-root dag --source-root src/v2 --entry dag/test/manual/git_upstream_model_execution_test.dag --function witness_git_cli_fixture_hashes_projects_and_independently_reads_back." +// Offline wet T1 receipt for the bounded Git R0 fixture. This is a runtime-present typed effect +// graph: shell.Mktemp, Filesystem.Write, shell.Mkdir, shell.Test, shell.Remove, and individual +// gunbc.WitnessBin.Run argv invocations. No shell program is serialized. Real Git hashes SHA-1 and +// SHA-256 blobs, writes the tree, commits and annotated tag, validates five tree modes plus a +// non-ASCII path, checks the index/worktree, runs fsck, performs exact-old-OID compare-and-swap +// through symbolic HEAD while retaining its target, proves stale and nonexistent-object updates +// refuse, and independently reads the ref/tag/tree state back. Local recipe: claim_batch --wet +// --source-root dag --source-root src/v2 --entry +// dag/test/manual/git_upstream_model_execution_test.dag --function +// witness_git_cli_fixture_hashes_projects_and_independently_reads_back. type GitR0LiveFixtureOutcome = GitR0LiveFixtureObserved { diff --git a/dag/test/manual/mercurial_upstream_model_execution_test.dag b/dag/test/manual/mercurial_upstream_model_execution_test.dag index 899b91ed11f..c216df98134 100644 --- a/dag/test/manual/mercurial_upstream_model_execution_test.dag +++ b/dag/test/manual/mercurial_upstream_model_execution_test.dag @@ -52,7 +52,17 @@ import v2.std.live_tree { LiveTreeDisposition, ReadsLiveTree } data live_tree_disposition: LiveTreeDisposition = ReadsLiveTree -data mercurial_r0_execution_receipt_note: String = "Offline wet T1 receipt for the bounded Mercurial R0 fixture. This is a runtime-present typed effect graph: shell.Mktemp/Mkdir/Test/Remove, Filesystem.Write, and individual gunbc.WitnessBin.Run argv invocations. No shell program is serialized. A real Mercurial CLI creates three changesets on two heads, observes portable node identities separately from clone-local revision numbers, reads a bookmark and local tag, checks public/draft/secret phases, copy metadata, manifest executable/symlink flags, repository requirements, and runs `hg verify`. Changeset identities are computed by Mercurial and checked as distinct 40-character upstream identities rather than embedded constants. Local recipe: put a real `hg` on PATH, then run claim_batch --wet --source-root dag --source-root src/v2 --entry dag/test/manual/mercurial_upstream_model_execution_test.dag --function witness_mercurial_cli_fixture_projects_and_independently_reads_back." +// Offline wet T1 receipt for the bounded Mercurial R0 fixture. This is a runtime-present typed +// effect graph: shell.Mktemp/Mkdir/Test/Remove, Filesystem.Write, and individual +// gunbc.WitnessBin.Run argv invocations. No shell program is serialized. A real Mercurial CLI +// creates three changesets on two heads, observes portable node identities separately from +// clone-local revision numbers, reads a bookmark and local tag, checks public/draft/secret phases, +// copy metadata, manifest executable/symlink flags, repository requirements, and runs `hg verify`. +// Changeset identities are computed by Mercurial and checked as distinct 40-character upstream +// identities rather than embedded constants. Local recipe: put a real `hg` on PATH, then run +// claim_batch --wet --source-root dag --source-root src/v2 --entry +// dag/test/manual/mercurial_upstream_model_execution_test.dag --function +// witness_mercurial_cli_fixture_projects_and_independently_reads_back. fn mercurial_decode_live_node_ids_step( state: List?, diff --git a/dag/test/manual/pijul_upstream_model_execution_test.dag b/dag/test/manual/pijul_upstream_model_execution_test.dag index dd6f7e07ab2..5c6189b6636 100644 --- a/dag/test/manual/pijul_upstream_model_execution_test.dag +++ b/dag/test/manual/pijul_upstream_model_execution_test.dag @@ -34,7 +34,18 @@ import v2.std.live_tree { LiveTreeDisposition, ReadsLiveTree } data live_tree_disposition: LiveTreeDisposition = ReadsLiveTree -data pijul_r0_execution_receipt_note: String = "Offline wet T1 receipt for the bounded Pijul R0 fixture. The typed effect graph creates an isolated PIJUL_CONFIG_DIR and ephemeral SSH agent/key, observes the implicit Root add change introduced with Pijul's first record, records one authored base and two concurrent signed changes with Pijul 1.0.0-beta.20, applies the changes in both orders, and independently decodes each real `pijul log --state`/`--hash-only` read-back through extdeps.pijul. The receipt proves channel state and change-set invariance, duplicate-delivery idempotence, channel-independent change identity, an observed dependency section, a clean pristine-to-working-copy projection, and a retained rendered order conflict. It does not infer the conflict's unobserved internal vertex and does not promote Pijul conditional advance. Local recipe: put `pijul` 1.0.0-beta.20 on PATH, then run claim_batch --wet --source-root dag --source-root src/v2 --entry dag/test/manual/pijul_upstream_model_execution_test.dag --function witness_pijul_cli_fixture_reads_channel_sets_and_retained_conflict." +// Offline wet T1 receipt for the bounded Pijul R0 fixture. The typed effect graph creates an +// isolated PIJUL_CONFIG_DIR and ephemeral SSH agent/key, observes the implicit Root add change +// introduced with Pijul's first record, records one authored base and two concurrent signed changes +// with Pijul 1.0.0-beta.20, applies the changes in both orders, and independently decodes each real +// `pijul log --state`/`--hash-only` read-back through extdeps.pijul. The receipt proves channel +// state and change-set invariance, duplicate-delivery idempotence, channel-independent change +// identity, an observed dependency section, a clean pristine-to-working-copy projection, and a +// retained rendered order conflict. It does not infer the conflict's unobserved internal vertex and +// does not promote Pijul conditional advance. Local recipe: put `pijul` 1.0.0-beta.20 on PATH, then +// run claim_batch --wet --source-root dag --source-root src/v2 --entry +// dag/test/manual/pijul_upstream_model_execution_test.dag --function +// witness_pijul_cli_fixture_reads_channel_sets_and_retained_conflict. type PijulR0LiveReceipt { state: PijulStateHash diff --git a/dag/test/manual/process_argv_expansion_receipt_test.dag b/dag/test/manual/process_argv_expansion_receipt_test.dag index 99d6bd4b2f1..0e2610fa020 100644 --- a/dag/test/manual/process_argv_expansion_receipt_test.dag +++ b/dag/test/manual/process_argv_expansion_receipt_test.dag @@ -27,31 +27,30 @@ import extdeps.tools.jq { jq_argv_expansion_probe } // 4 ProcessArgvExpansion -> splices (the claim itself) // // Cases 2 and 3 are why a branch reorder is not the repair: both are FreeMonoid at runtime, and -// the two readings both succeed, so no ordering recovers the erased intent. +// both readings succeed, so no ordering recovers the erased intent. // -// ONLY CASE 4 IS COMMITTED, DELIBERATELY, and this note is here so the gap does not read as an -// omission. Cases 1-3 were executed live against a real jq while the defect was being isolated -- -// their receipts are quoted in the design note (open question 9-ter) with the exact commands and -// exit codes. They are not enrolled here because each ASSERTS THE OLD BEHAVIOR: case 2 in -// particular pins the concatenating read as the expected outcome, and an enrolled test asserting a -// defect is how that defect acquires immortality (DESIGN section 4b -- evidence whose only subject -// is behavior the model rejects is retired with a receipt, not left standing). What survives -// enrolled is the claim the carrier makes: case 4 is red unless jq receives exactly two words. +// ONLY CASE 4 IS COMMITTED, DELIBERATELY, so the gap does not read as an omission. Cases 1-3 were +// executed live against a real jq while the defect was isolated -- their receipts, with exact +// commands and exit codes, are in the design note (open question 9-ter). They are not enrolled +// because each ASSERTS THE OLD BEHAVIOR: case 2 pins the concatenating read as expected, and an +// enrolled test asserting a defect is how that defect acquires immortality (DESIGN section 4b -- +// evidence whose only subject is behavior the model rejects is retired with a receipt, not left +// standing). What survives enrolled is the carrier's claim: case 4 is red unless jq receives +// exactly two words. // // WET: this executes a real jq process, so it is EXCLUDED from hermetic discovery and ENROLLED in -// gunbc.ci_layer_roots bin_witness_wet_entries. Both rows are required and they answer different +// gunbc.ci_layer_roots bin_witness_wet_entries. Both rows are required and answer different // questions: the exclusion keeps it off a batch it cannot pass (jq.Process.RunWithStdin carries no -// mock_response, and the envelope refuses rather than skipping), while the enrollment is what gives -// it an executing consumer. Exclusion alone would be deletion-with-the-file-retained -- DESIGN's +// mock_response, and the envelope refuses rather than skipping); the enrollment gives it an +// executing consumer. Exclusion alone would be deletion-with-the-file-retained -- DESIGN's // witness-cost ruling, whose specimen is exactly that. // // Its home under test/manual/ decides NOTHING: the file was swept into unshrunk discovery by path -// regardless, which is the same ruling's point that a directory cannot answer an admission -// question. The rows are the admission; the path is only where it lives. +// regardless -- the same ruling's point that a directory cannot answer an admission question. The +// rows are the admission; the path is only where it lives. // -// AND A MOCK IS NOT THE REPAIR. Mocking RunWithStdin would make this pass without any process -// running, while its entire content is that a REAL jq exits 0 only on two argv words -- a green -// that cannot fail. +// AND A MOCK IS NOT THE REPAIR. Mocking RunWithStdin would pass without any process running, while +// the entire content is that a REAL jq exits 0 only on two argv words -- a green that cannot fail. fn probe_lex() -> ModeledLexRules { ModeledLexRules {