Repository navigation
XL-R-4A: derive the rebuild scope of one changed mirror — the reverse package closure of its unique owning partition crate, with the next-pass executable assembly typed as unavailable rather than faked - #9765
Merged
Conversation
added 4 commits
August 30, 2026 18:23
added 3 commits
August 30, 2026 20:22
# Conflicts: # src/v1/stage0/src/v1_compiler_stage0_crates.rs
gunbai-bot Bot
pushed a commit
that referenced
this pull request
Aug 31, 2026
…, XL-R-4A rebuild scope #9765, DESIGN placement plan #9769). Conflicts: 5 regen-owned stage0 mirrors taken ours from the ef328db8 converged tree — regen fixes forward; main's hand-maintained required_regen_host.rs auto-merged from main. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
XL-R-4A (rebuild-scope derivation). The partitioned next-pass executable cut is XL-R-4B, a separate approved lane. Production
rebuild_from_installedis unchanged by this PR and stays the monolithic build until R-4B.What this lands
gunbc.regen_affected_setbounds which mirrors one edit can change. This lands the other half: which cargo packages those changed mirrors force the next-pass compiler to rebuild.They are different questions over different graphs — one over
.dagmodule references, one over cargo packages — and the second is the larger cost. Measured on this branch (BuildBuddy, tree69e6df8):rebuild_from_installed223s againstcompile.emit158s.New:
gunbc.stage0_partition_rebuild_scope,gunbc.stage0_partition_package_graph, and the witnessv2.test.claim.stage0_partition_rebuild_scope_witness.The claim is not "one mirror, one crate." A foundation edit legitimately rebuilds several downstream packages. The guarantee is that an unrelated package stays uncompiled.
One package graph, two consumers
gunbc.stage0_partition_package_graphis now the single authority for the partition's package edges.v1.compiler.stage0_cratesrenders every partitionCargo.tomlfrom it; this selector walks it in reverse. If the renderer kept its own copy the selector could compute a closure over edges cargo was never handed — and the failure direction is the dangerous one: a missing edge narrows the closure, so a package that must recompile is skipped and the next pass runs stale code.The collapse is byte-neutral: the three per-kind dependency arms in
stage0_partition_row_dependencies_outcomebecame one graph lookup, and amain_wetregen produced zero drift across every generated artifact. It also deleted a dead second emit-shell registry roster.Refuse, never widen
Five typed refusals, each naming what it could not answer for:
ChangedMirrorUnlocatable,MirrorHasNoOwningPackage,MirrorHasMultipleOwningPackages,PackageDependencyClosureUnderivable,ExecutableAssemblyNotCovered.WholeCompilerRebuildRequiredis reachable only by naming a positively modeled whole-build input, never by failing to name something else.Rung honesty: the scope is derived, the actuation is not available
stage0_next_pass_executable_assembly()isExecutableAssemblyUnavailable { trigger: PartitionedClaimExecutorAssembly }.claim_executoris a[[bin]]of the monolithicv1-compiler, whose library declares the partition-owned mirrors a second time; compiling an owning partition crate and then running that binary would build one subset for validation and run a compiler built from a second declaration of the same mirrors — not the fixed-point proof.So the scope is a real derived answer (it says exactly which packages would be compiled) while
stage0_partition_rebuild_is_actuatableis false for every live decision. That predicate is the typed question a host must ask, rather than a comment a host is trusted to have read.The projection is live, not a fixture
The round-cost receipt now carries a
partition-rebuild:line derived from the regen's own drift answer. From a real round on this branch (tree69e6df8):Correct: that round's own edit was to the partition generation authority. In an ordinary round the line will often read
MirrorHasNoOwningPackage— the partition owns 81 of the ~188 stage0 modules — and that is the intended reading, the coverage signal R-4B closes.Controls (all executing;
required-witnesses-floorgreen)witness_leaf_edit_compiles_owner_and_downstream_holdsv1-stage0-runtime,v1-stage0-std-core)witness_leaf_edit_excludes_unrelated_packages_holdswitness_foundation_edit_widens_to_derived_closure_holdswitness_leaf_closure_is_narrower_than_foundation_holdswitness_partition_generation_edit_requires_whole_rebuild_holdswitness_shared_build_input_edit_requires_whole_rebuild_holdscli_run.rs) refuses before cargowitness_unowned_mirror_refuses_holdswitness_duplicate_owner_refuses_holdswitness_unlocatable_changed_path_refuses_holdswitness_unreached_executable_package_refuses_holdswitness_today_derives_scope_with_unavailable_assembly_holdswitness_today_scope_is_not_actuatable_holdswitness_assembled_executable_scope_is_actuatable_holdswitness_next_pass_executable_assembly_is_unavailable_holdsa_receipt_renders_provenance_marks_totals_and_changed_pathsTwo independent byte oracles for the projection: that
.dagwitness and therender_round_cost_receiptunit test.Host surface touched
Only
render_round_cost_receipt(one parameter, one receipt field) andrun_regen_round_cost(keeps the drift answer past the install). No phase ordering, no install/rebuild boundary, norun_required_regen_scoped— agreed with deep-bat-536, who owns that spine for R-3.Not in scope
Partition rows for the ~107 hand-authored host modules, the monolith cut in
v2.compiler.self_host.stage0_crate_layout, and controls 6–8 (second-pass provenance, A/B byte equivalence) all belong to R-4B, which must land atomically. This PR does not fake the proof it cannot yet perform.