Skip to content

XL-R-4A: derive the rebuild scope of one changed mirror — the reverse package closure of its unique owning partition crate, with the next-pass executable assembly typed as unavailable rather than faked - #9765

Merged
gunbai-bot[bot] merged 11 commits into
mainfrom
session/royal-raven-413
Aug 31, 2026

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Aug 30, 2026 •

Copy link
Copy Markdown
Contributor

XL-R-4A (rebuild-scope derivation). The partitioned next-pass executable cut is XL-R-4B, a separate approved lane. Production rebuild_from_installed is unchanged by this PR and stays the monolithic build until R-4B.

What this lands

gunbc.regen_affected_set bounds which mirrors one edit can change. This lands the other half: which cargo packages those changed mirrors force the next-pass compiler to rebuild.

They are different questions over different graphs — one over .dag module references, one over cargo packages — and the second is the larger cost. Measured on this branch (BuildBuddy, tree 69e6df8): rebuild_from_installed 223s against compile.emit 158s.

New: gunbc.stage0_partition_rebuild_scope, gunbc.stage0_partition_package_graph, and the witness v2.test.claim.stage0_partition_rebuild_scope_witness.

PartitionRebuildScopeDerived { changed_mirrors, owning_packages, package_closure, executable_assembly }
| WholeCompilerRebuildRequired { cause }
| RebuildScopeRefused { cause }

The claim is not "one mirror, one crate." A foundation edit legitimately rebuilds several downstream packages. The guarantee is that an unrelated package stays uncompiled.

One package graph, two consumers

gunbc.stage0_partition_package_graph is now the single authority for the partition's package edges. v1.compiler.stage0_crates renders every partition Cargo.toml from it; this selector walks it in reverse. If the renderer kept its own copy the selector could compute a closure over edges cargo was never handed — and the failure direction is the dangerous one: a missing edge narrows the closure, so a package that must recompile is skipped and the next pass runs stale code.

The collapse is byte-neutral: the three per-kind dependency arms in stage0_partition_row_dependencies_outcome became one graph lookup, and a main_wet regen produced zero drift across every generated artifact. It also deleted a dead second emit-shell registry roster.

Refuse, never widen

Five typed refusals, each naming what it could not answer for: ChangedMirrorUnlocatable, MirrorHasNoOwningPackage, MirrorHasMultipleOwningPackages, PackageDependencyClosureUnderivable, ExecutableAssemblyNotCovered. WholeCompilerRebuildRequired is reachable only by naming a positively modeled whole-build input, never by failing to name something else.

Rung honesty: the scope is derived, the actuation is not available

stage0_next_pass_executable_assembly() is ExecutableAssemblyUnavailable { trigger: PartitionedClaimExecutorAssembly }. claim_executor is a [[bin]] of the monolithic v1-compiler, whose library declares the partition-owned mirrors a second time; compiling an owning partition crate and then running that binary would build one subset for validation and run a compiler built from a second declaration of the same mirrors — not the fixed-point proof.

So the scope is a real derived answer (it says exactly which packages would be compiled) while stage0_partition_rebuild_is_actuatable is false for every live decision. That predicate is the typed question a host must ask, rather than a comment a host is trusted to have read.

The projection is live, not a fixture

The round-cost receipt now carries a partition-rebuild: line derived from the regen's own drift answer. From a real round on this branch (tree 69e6df8):

regen-round-cost: changed_paths=3 [emitted_population.rs, lib.rs, v1_compiler_stage0_crates.rs]
partition-rebuild: WholeCompilerRebuildRequired partition_generation_authority=[v1_compiler_stage0_crates.rs]

Correct: that round's own edit was to the partition generation authority. In an ordinary round the line will often read MirrorHasNoOwningPackage — the partition owns 81 of the ~188 stage0 modules — and that is the intended reading, the coverage signal R-4B closes.

Controls (all executing; required-witnesses-floor green)

control test
leaf edit compiles owner + real downstream closure + executable witness_leaf_edit_compiles_owner_and_downstream_holds
named unrelated packages stay uncompiled (v1-stage0-runtime, v1-stage0-std-core) witness_leaf_edit_excludes_unrelated_packages_holds
foundation edit widens to the derived closure witness_foundation_edit_widens_to_derived_closure_holds
leaf closure strictly narrower than foundation closure witness_leaf_closure_is_narrower_than_foundation_holds
partition-generation input → whole rebuild witness_partition_generation_edit_requires_whole_rebuild_holds
shared build input → whole rebuild, distinct cause witness_shared_build_input_edit_requires_whole_rebuild_holds
unowned mirror (cli_run.rs) refuses before cargo witness_unowned_mirror_refuses_holds
duplicate owner refuses with its own cause witness_duplicate_owner_refuses_holds
unlocatable changed path refuses, does not widen witness_unlocatable_changed_path_refuses_holds
executable the changed bytes do not reach refuses witness_unreached_executable_package_refuses_holds
live decision derives scope with unavailable assembly witness_today_derives_scope_with_unavailable_assembly_holds
live decision is not actuatable witness_today_scope_is_not_actuatable_holds
positive actuatability control (so the predicate is not constant-false) witness_assembled_executable_scope_is_actuatable_holds
declared assembly state is unavailable witness_next_pass_executable_assembly_is_unavailable_holds
receipt renders the new line byte-for-byte a_receipt_renders_provenance_marks_totals_and_changed_paths

Two independent byte oracles for the projection: that .dag witness and the render_round_cost_receipt unit test.

Host surface touched

Only render_round_cost_receipt (one parameter, one receipt field) and run_regen_round_cost (keeps the drift answer past the install). No phase ordering, no install/rebuild boundary, no run_required_regen_scoped — agreed with deep-bat-536, who owns that spine for R-3.

Not in scope

Partition rows for the ~107 hand-authored host modules, the monolith cut in v2.compiler.self_host.stage0_crate_layout, and controls 6–8 (second-pass provenance, A/B byte equivalence) all belong to R-4B, which must land atomically. This PR does not fake the proof it cannot yet perform.

@gunbai-bot gunbai-bot Bot changed the title XL-R-4: partition-scoped rebuild_from_installed -- one changed mirror rebuilds the reverse package closure of its unique owning partition crate plus the executable link package, actual next-pass claim_executor assembled from partition artifacts, refuse never widen XL-R-4A: derive the rebuild scope of one changed mirror — the reverse package closure of its unique owning partition crate, with the next-pass executable assembly typed as unavailable rather than faked Aug 30, 2026
@gunbai-bot
gunbai-bot Bot merged commit 22ab698 into main Aug 31, 2026
5 checks passed
@gunbai-bot
gunbai-bot Bot deleted the session/royal-raven-413 branch August 31, 2026 02:23
gunbai-bot Bot pushed a commit that referenced this pull request Aug 31, 2026
gunbai-bot Bot pushed a commit that referenced this pull request Aug 31, 2026
…, XL-R-4A rebuild scope #9765, DESIGN placement plan #9769). Conflicts: 5 regen-owned stage0 mirrors taken ours from the ef328db8 converged tree — regen fixes forward; main's hand-maintained required_regen_host.rs auto-merged from main.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU
@briansrls
briansrls restored the session/royal-raven-413 branch August 31, 2026 03:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants