Skip to content

Kernel-precedence repair: one shared type-env producer; kernel overlay independent of import cardinality - #9813

Merged
briansrls merged 8 commits into
mainfrom
repair/kernel-precedence
Aug 31, 2026
Merged

briansrls merged 8 commits into
mainfrom
repair/kernel-precedence

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Aug 31, 2026 •

Copy link
Copy Markdown
Contributor

Standalone uniform kernel-precedence repair (queue slot 1 per the side-chat ruling). Single producer repair in src/v1/04_infer.dag; no residuals riding along.

The defect

build_type_env and build_type_env_unresolved both skipped the kernel cache overlay when a module had exactly one import (resolved_imports |> count == 1 → the import's flattened cache alone). With one import, kernel identity won or lost by ancestry occupancy — a leak-dependent resolution regime: identical imports, different realizations, resolution by accident rather than by the declared precedence. The authority note (direct_import_export_precedence_note) already stated locals > kernel > direct-selected > transitive union; the realization didn't implement it.

The repair

One shared producer, build_ancestry_precedence, consumed by both builders:
import union (fork ledger unchanged — conflicts still recorded) → kernel overlay UNCONDITIONALLY → direct-selected overlay with kernel names skipped (overlay_direct_import_exports, unchanged) → locals kept above by the existing str_bindings-first lookup. No downstream kernel checks added anywhere; the is_kernel_type census over 04_types/04_resolve/04_infer/04_env found only conformance/brand/qualification guards, none compensating for the closed hole. The unresolved builder gains the direct-selected overlay it previously lacked — same one-producer boundary. The authority note is updated in this PR: kernel installation independent of import cardinality.

v1 PURPOSE admission (gunbc.v1_maintenance_standing v1_seed_standing)

T's four conditions (accepted, satisfied)

  1. String/Char stay in the kernel skip set: overlay_skips_kernel_name untouched; a direct v2.std.text.String import still binds deterministically via the direct-selected overlay's kernel-name skip.
  2. Total means total: the leak-dependent arm (count == 1 skip) is deleted, not guarded — no arm survives beside the rule.
  3. Their negative controls executed on this build: self_host_structural_text_witness_test (12 rows, materialized from their pinned head c14f7fe) run in the validation cycle — results recorded below when the cycle lands.
  4. Sequencing: superseded by the manager's queue ruling — this repair is slot 1, XL-0T: structural v2.std.text.String (FreeMonoid<Char>) -- literal-to-Unicode-scalar inhabitance carried into emission, text/list op realization by operand representation, no RustStdString row #9720 last; based on main@320e48c5b2 (post-XL-0-PH: model rustc phases + error-code->phase rows in extdeps/languages/rust, derive the per-phase board from the emitted-crate census, and enroll the phase-monotone ratchet as a required witness on #9710 #9745), merge-commit integration.

Validation (updated when the cycle lands)

Regen to byte fixed point on the merged head (the seed changed, so the mirror regenerates — the current draft-head CI red is exactly regen FAIL generated surface drift: v1_compiler_infer.rs, the expected pre-regen state); identity diff vs the 158-row post-#9808 baseline with every moved row classified under the adjudicated precedence-flip disposition (coordinated with PH — one deliberate corpus-wide event, not N unadmitted additions); full witness batteries + T's controls.

🤖 Generated with Claude Code

https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU

Why the kernel-Bool commit is part of this repair (not a rider)

The floor caught it first: at head 8f371a67 — precedence flip only, no kernel-Bool commit in existence — bcp_foreign_coproduct_where_bool_required_must_refuse returned false. Mechanism: coproduct_payload_where_parent_required reads the formal's resolved declaration via lookup_type_by_name. The fixture (module bcp.probe, one import, std.types { Int, Bool }) previously resolved Bool through the import cache to std.types' concrete type Bool = True | False and judged. Under the unconditional kernel overlay the formal resolves to the synthetic kernel binding — scalar, NoConnective, no children — so decl_is_concrete_coproduct goes false and the wall abstains. An abstaining wall accepts: the refusal silently became a decoration as a side effect of the precedence fix. f2e89e5a4b repairs it by construction at the producer: the kernel Bool binding carries the coproduct structure its cited declaration has (the existing kernel_optional precedent, applied in all three kernel-env constructors), no downstream kernel check. Splitting it out would land the precedence repair minus a refusal — exactly what §5 forbids ("the minimum Y must preserve every required refusal"). The bcp witness itself is untouched; the only re-pinned row is the separate peano emission row, whose old expectation encoded the ancestry-occupancy accident the ruling lists as unchanged semantics ("bare direct import of a kernel spelling cannot displace kernel") — re-pinned with Rule-1 as the flip-back trigger so it reds if leak-dependence is ever reintroduced.

The in-cycle proof that ships with the final head: the full 10-row coproduct-payload battery and the full peano battery run against the compiler built from the committed mirror — the artifact that ships, not sources the seed hasn't caught up to.

gunbc-ci-auto-heal and others added 2 commits August 31, 2026 12:24
…el overlay unconditional

build_type_env and build_type_env_unresolved both skipped the kernel cache
overlay when a module had exactly one import — with one import the environment
was that import's flattened cache alone, so kernel identity won or lost by
ancestry occupancy (leak-dependent resolution: identical imports, different
realizations). Both builders now consume one build_ancestry_precedence
producer: import union (fork ledger unchanged) -> kernel overlay
UNCONDITIONALLY -> direct-selected overlay with kernel names skipped ->
locals kept above by str_bindings-first lookup. The unresolved builder gains
the direct-selected overlay it previously lacked, per the same one-producer
boundary. direct_import_export_precedence_note updated: kernel installation
independent of import cardinality.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU
@gunbai-bot gunbai-bot Bot changed the title XL-0 Kernel-precedence repair: one shared type-env producer; kernel overlay independent of import cardinality Aug 31, 2026
…3, byte-converged)

v1_compiler_infer.rs carries the build_ancestry_precedence projection; the
round-2 compiler (carrying the precedence) additionally re-emitted
extdeps_languages_{go,python,rust}_emit.rs and v1_compiler_stage0_crates.rs:
lambda parameters that previously emitted as _ now emit their resolved types
(Rc<SimpleMethodSpec>, Rc<GeneratedPartitionCrateRow>) — single-import modules
now build kernel-complete environments, so inference names types it previously
abandoned. Every changed line explained by the precedence disposition.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU
@gunbai-bot

gunbai-bot Bot commented Aug 31, 2026

Copy link
Copy Markdown
Contributor Author

Validation receipts (cycle xl0b36, pre-#9745-merge tree e311e90; authoritative merged-head cycle running at 8f371a6):

— sent from bold-carp-449

@gunbai-bot
gunbai-bot Bot marked this pull request as ready for review August 31, 2026 14:34
gunbc-ci-auto-heal and others added 5 commits August 31, 2026 15:11
…ctural-Bool-spelling emission row

Under the unconditional kernel overlay the scalar synthetic Bool binding
erased std.types' declared True|False structure, deleting the
coproduct-payload refusal at kernel-Bool formals (floor red:
bcp_foreign_coproduct_where_bool_required_must_refuse). The kernel binding
now carries the structure its cited declaration has, in all three kernel-env
constructors — the model repaired at the producer, no downstream kernel check.
The peano Bool emission row is re-pinned: a bare direct import of the kernel
spelling cannot displace kernel identity (the old expectation held only by
ancestry occupancy); Rule-1 is the flip-back trigger, and the row now reds if
leak-dependent resolution is reintroduced.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU
…odule-item-grain annotations

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU
…view 57892)

Three kernel-environment producers each constructed the same
Bool = True | False binding; one kernel_bool_type_node now serves all three,
so the fact cannot fork.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU
… point (round 3, byte-converged)

27 files, two mechanical classes: the 04_infer projection
(build_ancestry_precedence, kernel_bool_type_node consolidated per review
57892), and lambda-parameter annotations toggling with rustfmt reflow
wherever Bool-typed accumulators participate — the annotation logic sees
kernel Bool as a variant-carrying coproduct and declines the spelling
(governed by the green w_lambda_param_annotation_declines_a_spurious_generic
row). In-cycle proof at this tree: all 10 coproduct-payload rows PASS
(bcp_foreign_coproduct_where_bool_required_must_refuse restored), all 12
peano rows PASS, board 160->155 (-5/+0), 604 lib tests, byte fixed point.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU
@gunbai-bot

gunbai-bot Bot commented Aug 31, 2026

Copy link
Copy Markdown
Contributor Author

Answering review 57892 (REQUEST_CHANGES at 8c3db57) on the record: the finding — the kernel Bool = True | False fact constructed independently in three environment producers — is addressed by commit bf783845f41: one canonical kernel_bool_type_node() constructor now serves all three kernel-env sites (build_type_env, build_type_env_unresolved, compiler_kernel_type_env), so the fact cannot fork (§§2–3). The current head 170ff7aeed carries that consolidation plus the regenerated stage0 mirror at byte fixed point; review 57913 approves that exact head. In-cycle proof at this tree: all 10 coproduct-payload rows and all 12 peano rows pass against the compiler built from the committed mirror.

— sent from bold-carp-449

@briansrls
briansrls merged commit 02814e5 into main Aug 31, 2026
5 checks passed
@briansrls
briansrls deleted the repair/kernel-precedence branch August 31, 2026 18:49
@briansrls
briansrls restored the repair/kernel-precedence branch August 31, 2026 18:52
gunbai-bot Bot pushed a commit that referenced this pull request Aug 31, 2026
…y, not reachability — the fixture boundary reds with the exact claimed diagnostic

A two-module fixture (recursive carrier sharing the bare spelling Nat +
a std.nat consumer) is accepted by gunbc and refuses in cargo with
expected-i64-found-Rc<i64>: the numeric guard hits while the bare-string-keyed
layer sets are polluted by the unrelated recursive declaration. Section 23
now records the retraction, the executed reproducer, and restates the #9813
attribution as a hypothesis with its discriminator, since the whole-corpus
attribution boundary has not published.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VdQphfzTtHwuDqdNyuQQTC
gunbai-bot Bot added a commit that referenced this pull request Aug 31, 2026
…e Rc<i64> span-stamping arm is not live on main (#9842)

* XL-0N-RC: subject-present measurement replaces the retracted REFUTED verdict; stale two-Nat citation repaired

Positive control first, as the brief ordered: std.checked_arithmetic IS inside
the measured census closure (v2.std.integer -> std.integer -> std.induction ->
std.checked_arithmetic), both Nat authorities present, and the instrument
discriminates -- disabling decl_file_realizes_natively reds the victim itself.
On current main no arm reproduces the claimed expected-Rc<i64>-found-i64: the
decl_file key hits through the alias, and the un-peeled authored_name_at in
field_access_field_is_boxed has no authorable RED at field grain because
needs_box_wrapping peels and boxes only recursive carriers. Recorded as
section 23 of the shared coordination surface; no emitter edit ships without a
discriminating red.

Also repairs the doc's citation of nat_max_two_nat_authorities_note (deleted
by #9794) to the stall row gunbc.guarantee_rung_drop two_nat_authorities_stall.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VdQphfzTtHwuDqdNyuQQTC

* XL-0N-RC amendment: the 'no authorable RED' verdict measured occupancy, not reachability — the fixture boundary reds with the exact claimed diagnostic

A two-module fixture (recursive carrier sharing the bare spelling Nat +
a std.nat consumer) is accepted by gunbc and refuses in cargo with
expected-i64-found-Rc<i64>: the numeric guard hits while the bare-string-keyed
layer sets are polluted by the unrelated recursive declaration. Section 23
now records the retraction, the executed reproducer, and restates the #9813
attribution as a hypothesis with its discriminator, since the whole-corpus
attribution boundary has not published.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VdQphfzTtHwuDqdNyuQQTC

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
gunbai-bot Bot pushed a commit that referenced this pull request Sep 1, 2026
…t survives resolution (FreeMonoid+Char), natively reads the destination's own declaring file, witnesses re-anchor on the qualified boundary

The #9813 kernel-precedence landing exposed that the text row was keyed on
information resolution deliberately discards: String is a container-alias
spelling, so every 'type X = FreeMonoid<Char>' boundary peels to the bare
structural carrier and no module spelling survives to key on. The row now
keys on that surviving structure — destination std.algebra.FreeMonoid with
element std.types.Char (LiteralHomomorphism gains an element field,
threaded through literal_homomorphism_for/elaborate_literal_at; peano and
bool rows carry element: none).

Second repair on the same boundary: destination_realizes_natively was read
from the RESOLVED NODE's ident_span file, and a substituted alias RHS is a
kernel-minted node whose pseudo-file <kernel:std.algebra.FreeMonoid>
string-matched the '<kernel:' native-numeric roster row, so the peeled
structural boundary answered natively=true and took DirectLiteral with the
matching row present. natively is now read from the DESTINATION
declaration's own census file (declaration_file_of in 04_env), per
numeric_realization_identity_note's own rule that realization is a fact
about the declaration.

Witness battery re-anchored per the division ruling: the seven positive
rows probe the QUALIFIED v2.std.text.String boundary (each probe imports
string_is_empty so the harness's import-following closure loads the text
module), and a new control pins bare String + text import = host,
deterministically, under uniform kernel precedence. 12/12 text rows and
29/29 peano rows green by execution; stage0 mirrors regenerated to
first-generation byte fixed point on the merged tree.

Also: recurring_failure_mode row mistyped_body_radiates_nonlocal_diagnostics
(the phantom-diagnostic specimen, layer stated), DESIGN.md and
docs/design-ledgers.md regenerated via generated_artifact_gate main_wet_one,
stale rust_host_string_seam_fn_emit comment fixed (review 57929).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01R4A6MRdzeYxNr7dRbugcUC
gunbai-bot Bot added a commit that referenced this pull request Sep 1, 2026
…-Unicode-scalar inhabitance carried into emission, text/list op realization by operand representation, no RustStdString row (#9720)

* Emitted v2 compiler crate: a declaration's identity is its last segment, and a primitive with no realization refuses instead of inventing one

Two roots behind 175 of the 260 rustc errors on the emitted v2 compiler
closure (issue #9664, milestones 1 and 2):

- 102 x E0425: the four DeclaredCallableIdentity constructions in
  v1.compiler.infer_lookup took decl_name from the AUTHORED spelling, so a
  qualified call carried the whole dotted path as the declaration name and
  emission rendered crate::v2_std_grammar::v2.std.grammar.f(..).

- 73 x E0425: v2.std.algebra length is a ModeledProjection of the `length`
  primitive and rt_function_registry has no `length` row, so emission took
  rust_runtime_bridge_name's identity arm and wrote v1_rt::length -- a symbol
  the seed does not define. A primitive's identity and its per-target
  realization are two facts; CallTargetIdentity carried only the first, so
  every emitter had to ASSUME a bridge exists.

RuntimePrimitiveCall now carries projected_from, the declaration the roster
projected it from, and emit_rust routes to the bridge only when its own
registry holds the primitive, falls back to the declaration otherwise, and
refuses when neither exists. DeclaredCallableIdentity moves to v1.std.core so
the target type can carry it without forking the pair.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU

* Class B: the algebra method fallback asserted a v1_rt bridge it had not checked

tier0 method resolution resolves an ordinary fn-typed RECORD FIELD through
lookup_field_in_product, so `algebra.step(..)` arrives as AlgebraMethodSemantics
carrying the field node as its method_def. The fallback at the end of that arm
hardcoded runtime_bridge: true, which emitted `v1_rt::step` -- and made
emit_rust_generic_method_call's own callable-field arm, guarded on
runtime_bridge == false, unreachable for the exact receiver it was written for.
65 E0425s on the emitted v2 compiler closure (member, apply, is_empty, step,
init, allocate_literal, ...) were that one literal.

It now passes the realization question keyed on the same registry as the
plain-call seam, so a real bridge method still lowers to a bridge, a callable
field lowers as a field, and a name that is neither reaches the existing loud
refusal rather than a fabricated symbol.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU

* Only ModeledProjection carries projected_from: a HostRealizedSeam body is a self-call, so falling back to it would emit a nonterminating function

The declaration fallback is sound only where the declaration's body is real
code. HostRealizedSeam means the body IS a self-call, so emitting it compiles
and then loops forever -- silent wrongness, strictly worse than the unresolved
symbol it would have replaced. A seam whose target has no realization has no
honest lowering, so it carries nothing and reaches emission's refusal.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU

* M1: realize the two symbol bridges, which were host seams nothing declared to be host seams

v2.std.compilers.lexing symbol_lexeme and symbol_intern_lexeme have self-call
bodies -- the HostRealizedSeam shape exactly -- and the interpreter has carried
real arms for both (v4_bridge.symbol_lexeme, v4_bridge.symbol_intern_lexeme).
With no projection roster row the resolver saw ordinary declarations, so Rust
emission emitted the declaration, and

    pub fn symbol_lexeme(sym: String) -> String { symbol_lexeme(sym) }

COMPILES. The emitted closure carried two functions that type-check, pass every
gate we own, and diverge from the interpreter by not terminating. Unlike the
sibling seams (decl_facts and friends, which at least refuse loudly as
unresolved v1_rt symbols) nothing anywhere reported this one -- it is absent
from the E0425 census precisely because it is silent.

extdeps.languages.rust.types already declares Symbol's target type as String,
so on this target both bridges are the identity. That is a realization of the
declared row, not a second opinion about it.

Residue named, not closed: a self-call body is a DECIDABLE structural marker of
a host seam, so the compiler could refuse an unrealized one rather than emit it.
It does not yet; that check is the class's next-rung trigger.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU

* Regenerate the stage0 mirror for the emitter repairs (fixed point at round 2)

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU

* test.claim fixtures: one discriminating RED per closed emission class, with boundary controls

Six rows over the three emitter defects plus the two symbol bridges. Each
class's positive and negative assertion differ only in the fact the repair
added, so no single edit satisfies both directions, and each repair carries a
boundary control that would go red had it over-reached the other way (empty_map
for the registry gate, a registered bridge method for the class-B gate).

The symbol-bridge row is deliberately not an error-count assertion: that class
COMPILED throughout the defect and diverged by not terminating, so a row
asserting 'no error' would have been green the whole time.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU

* Fix the class-B boundary control: count has a method template, so it never reaches the seam under repair

count is answered by rust_simple_method_specs before the algebra fallback, so
the row would have gone red while executing none of the code the repair
touched. trim is in rt_function_registry and has no template, so it is one of
the few names that actually reaches that fallback.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU

* Unbreak the fixture parse: a trailing semicolon on the note declaration

The module index refused the file outright, so none of the six witnesses were
discovered. .dag item declarations carry no terminator.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU

* The self-call seam wall: an unrealized host seam refuses instead of emitting compiling recursion

A whole-body self-call is the decidable structural marker of a host seam. In the
interpreter the shape is safe -- reaching it recurses to the evaluation-budget
refusal -- but emitted to Rust the same shape COMPILES and returns to no caller.
Nothing reported it: not the module index, not the compile-clean gate, not cargo
check. That is why the two symbol bridges were invisible until someone read the
emitted bytes.

emit_fn_def now asks the realization registry -- the same authority the call
sites ask, so the two cannot drift -- and suppresses the declaration when the
seam is realized, refuses with a located message when it is not. Suppression
rather than delegation is deliberate: a forwarding body would make this seam
reconstruct signatures in target types, which is the cementing the existing
suppressed-seam precedent avoids, and a realized primitive's calls all route to
the bridge anyway.

The predicate is whole-body identity, not 'contains a self-call'. Ordinary
recursion has a match, an if or a let between the head and the call, so it never
matches; expr_has_self_call walks children and would have refused most of the
compiler. Both directions carry a fixture.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU

* The seam wall must resolve realization through the roster's primitive, not the declaration name

Measured, not predicted: the wall refused six seams in the emitted closure and
one of them -- v2.std.collection empty_map_primitive_delegate -- is realized.
Its roster row names the empty_map primitive, whose bridge is rc_empty_map, but
rt_function_registry holds 'empty_map' and the wall looked up
'empty_map_primitive_delegate'. A declaration's name and the primitive it
realizes are two facts; the roster is the authority that joins them, and the
declaration name is only the fallback for a seam nobody has rostered.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU

* The seam wall's realized arm must not suppress the declaration: suppression created 10 dangling imports

Measured on the emitted closure with the wall finally in the mirror: removing a
realized seam's item left 10 unresolved imports (E0432) for symbol_lexeme,
symbol_intern_lexeme and resolve_type_node. Other modules import these
declarations; the suppression created that breakage rather than finding it.

And the reasoning that made suppression look safe is what makes it unnecessary.
A realized seam's body IS a call to itself, and resolution already routes that
call through the roster to the bridge -- so ordinary emission writes
v1_rt::symbol_lexeme(sym) as the body without help. The wall's whole job is the
UNREALIZED arm.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU

* The seam refusal is a generated body, not a crate-wide compile_error!: rustc's denominator is larger than the demand denominator

compile_error! fails the WHOLE crate, and that form silently assumes every seam
it refuses is one somebody calls. It is not. rustc type-checks the entire
emitted crate including declarations imported but never invoked, so the refusal
denominator is strictly larger than the entry-reachable execution closure --
five unreachable seams took the crate down.

The refusal is now a panic body with the declaration's real signature: dependent
modules resolve, the crate compiles, and only an actual invocation fails loudly.
That moves the refusal from the crate to the one declaration that earned it, and
leaves reachability to a separate instrument. An entry-rooted pruner can replace
the body later without revisiting this.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU

* Two obligations the required floor found, both real consequences of this change

DETERMINISM DENOMINATOR (9 reach_witness rows red, including
determinism_denominator_is_closed_on_declared_primitives, whose entire job is to
notice this). v2.lens.determinism closes its denominator over
primitive_declared_definitions, so adding two canonical names without traversal
facts made the closure false. Both bridges are scalar -- symbol_lexeme maps one
Symbol to its text and symbol_intern_lexeme is its inverse -- so there is no
collection to walk and OrderFreeResult is the honest arm. HostUnspecifiedOrder
would claim a real traversal whose order the host does not pin, fabricating a
leak the primitive cannot have.

NAMESPACE WAVE ADMISSION (6 unadjudicated deltas). Four are TargetChanged for
DeclaredCallableIdentity moving v1.compiler.infer_sigs -> v1.std.core, which is
what lets CallTargetIdentity carry the declaration a runtime target was
projected from. infer_sigs imports v1.std.core, so the type could not stay put
without a cycle. Four enumerated rows, one per binding site; the two membership
deltas auto-admit as ExplicitlyEvaluatedZeroDelta. Dissolve-on: this PR merging,
by the same trigger the three prior shrinks record.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU

* Class-C fixture was broken, not the repair: the witness pool is smaller than the corpus

The row FAILED while the mechanism was green. The probe used the qualified
spelling without importing v2.std.collection, which resolves against the real
4261-module corpus but not against compile_dag_rust_emit_check's 2973-module
witness pool. Measured both ways: emitted against the corpus the same probe
produces crate::v2_std_collection::map_get(m.clone(), "key".to_string()),
exactly what the row asserts.

The import restores module presence and does not answer the call -- decl_name
comes from the authored spelling at the call site regardless of imports -- so
the negative assertion still discriminates. Falsifier 2 is what proves that
rather than argues it.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU

* is_empty: a conversion is not a repair -- give it the Rust realization it never had

Before the class-B change, xs |> is_empty emitted v1_rt::is_empty, a symbol the
seed does not define: 5 x E0425. After it, the same 5 sites became typed
refusals -- correct in kind, still 5 errors. The class-B repair made the gap
visible; it did not close it.

is_empty is an algebra template over FreeMonoid whose Rust realization is
Vec::is_empty, exactly as count's is Vec::len, so the fix is one row in
rust_simple_method_specs beside count. Nothing in 05_emit_rust learns a new
name: realization is a target fact and lives in the target's registry.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU

* A receiver's own callable field outranks every name-keyed table: class B survived one layer up

The requested is_empty negative control found a live hole rather than confirming
a safe one. Both rust_method_templates lookups are keyed on the bare method
spelling with no receiver check, so a fn-typed record field named is_empty was
captured by the target template and emitted as recv.is_empty() instead of
(recv.is_empty)(..). The class-B repair fixed the algebra FALLBACK and left the
two tables sitting in front of it.

The hole is not new and is not specific to is_empty: count, first, join, split,
take, skip, last, chars and enumerate have carried it for as long as they have
had templates. Adding is_empty made it urgent by putting the spelling most
likely to name a predicate field in front of that table.

One helper, consulted at the top of both arms before every name-keyed special
case, so the two cannot drift. Two controls: the new spelling and a pre-existing
one.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU

* Two more wave admissions: the declaring module rebinds too

v1.compiler.infer_sigs used to DECLARE DeclaredCallableIdentity, so its own two
construction sites resolved locally and produced no delta. Now that the
declaration lives in v1.std.core and infer_sigs imports it, those sites rebind
exactly like the consumers in infer_lookup. An enumeration error on my part, not
a second transition: same subject, same trigger, same dissolve.

Floor is now green on this branch (passed=2754 failed=0) -- the OrderFreeResult
traversal facts closed all nine determinism rows.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU

* The callable-field tier was consuming the algebra profile's identity domain, not the receiver's: 202 refusals on the first compile of the converged seed

rust_receiver_has_callable_method_field asked rust_record_field_needs_fn_rc,
which sweeps rust_struct_field_lookup_candidates -- and that list deliberately
widens a receiver's name to its container template algebra. An algebra declares
its operations as arrow-typed members, so under that widening every Map receiver
"has a callable field" named map_keys, map_values, lookup or get, and the tier
captured the very bridge calls it sits in front of.

Measured at the first compile of the round-3 converged mirror: 202 rustc
refusals, one class -- 164 E0609 (no field `map_keys` on
Rc<im::HashMap<String, Rc<ItemInfo>>> and friends), 48 E0282, 4 E0615 on `get`.
It is the same defect the tier was built to close, one level up: a name-keyed
lookup consuming an identity domain that is not its own.

The predicate now consults only the receiver's own declared record.
w_map_receiver_operation_is_not_read_as_a_callable_field is the discriminating
red: restore the candidate sweep and its must_not_contain clause fires.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU

* Regenerate the stage0 mirror at the merge-equivalent tree: byte fixed point at round 3, six paths, each explained by an authority change

Convergence transaction on srv1 (/tmp/xl0c.sh -> /tmp/xl0g.log), on
952ffa6 = main b726547 merged with the branch. Criterion is BYTE equality
(sha256 over the whole candidate tree vs the whole installed tree), never
first_generation_equal and never the changed-path list; the full workspace
is rebuilt inside every round so a non-compiling mirror stops the line.

  round 1  cand e212fe74 inst 6f55cf3e  installed, compiles
  round 2  cand 932b0543 inst e212fe74  drift = v1_rt.rs only (the two-hop:
           v1_rt.rs is rendered by the previously compiled rt_hash_ops)
  round 3  cand 932b0543 inst 932b0543  BYTE FIXED POINT -- produced by a
           compiler rebuilt from the round-2 installed tree

Changed paths and their authority:
  extdeps_languages_rust_emit.rs  <- rt_function_registry / rust_simple_method_specs rows
  std_primitive_projection.rs     <- symbol_lexeme / symbol_intern_lexeme roster rows
  v1_compiler_emit_rust.rs        <- 05_emit_rust.dag (seam wall, callable-field tier, class B/C)
  v1_compiler_infer.rs            <- 04_infer.dag projected_from on RuntimePrimitiveCall
  v1_compiler_runtime_rust.rs     <- runtime_rust.dag symbol bridges
  v1_rt.rs                        <- same, one hop later

On these bytes: function_value_named_application_controls_witness PASSES
(the d805243 / 952ffa6 rust-unit-tests red was the merge-driver-refused
stale v1_compiler_infer.rs, not a semantic regression); emit 175 files;
cargo check 15 errors: 9 E0425 (filesystem 2, V 2, K 2, Determinism 2, T 1),
2 E0728, 2 E0107, 1 E0391, 1 UNRESOLVED_CompilerError. No hand edit to any
generated file.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU

* WIP tail classes

* WIP: if-equals-variant parses as a record literal; name the predicate

* WIP: annotations at module-item grain

* Regen round 1 (BuildBuddy invocation ebbdffc5, compiler gunbc=9830014a4e965ddb built from the committed mirror): v1_compiler_emit_rust.rs regenerated; candidate patch sha 05ce734c52890571

* Regen round 2 (BuildBuddy, compiler gunbc=75d74698aebcdb6e built from installed ce959e40604ffdd5): std_algebra.rs, std_nat.rs -- arrow returns now render through the Rust renderer (Rc<Vec<K>> for List<K>, Nat preserved); candidate patch sha b5b409aeebbeb6c4

* Arrow positions deviate from the generic renderer only for the two defect shapes: the unconditioned route emitted 2790 refusals where 15 stood; fix the arrow probe's variant spelling

* B: the init turbofish declines a declaration's own formals by the lambda's admission; F: a qualified type reference earns its use-line from the qualifier under export proof; both earlier cuts were measured non-events and are deleted

* Regenerate the stage0 mirror at the 0773184 freeze: byte fixed point at round 3, three paths, each explained by an authority change

srv1 (/tmp/xl0e.sh -> /tmp/xl0j.log), criterion = every regen-population
file byte-equal to installed; full workspace rebuilt as the gate each round.

  round 1  gunbc=1dc61ba198c6750b from installed 0479b0df9fc5598e  -> v1_compiler_emit_rust.rs
  round 2  gunbc=909aa212f353bd03 from installed 8ebedc7445fadbaa  -> std_algebra.rs, v1_compiler_trait_derive_emit.rs
  round 3  gunbc=0d0cd70ec5b20db9 from installed 8713cb43f8ad848c  -> <none>  BYTE FIXED POINT

  v1_compiler_emit_rust.rs        <- 05_emit_rust.dag (gated arrow position, init turbofish admission, qualified-type use-lines)
  std_algebra.rs                  <- the gated arrow route restores the pre-e9900e2 spelling of the two arrow-typed fields
  v1_compiler_trait_derive_emit.rs <- one use-line synthesized for a qualified std.types.List reference under export proof

Final installed tree 8713cb43f8ad848c. No hand edit to any generated file.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU

* One renderer for every arrow position; a type position never takes the variant arm; the qualified route synthesizes use-lines only for types the emitted source names

Four regressions the 0773184 fixed point put on the closure, each with its discriminating row:

- E0603 x16: the qualified-type route synthesized `pub use crate::v2_std_nat::Succ;` for every
  `v2.std.nat.Succ { prev: .. }` record literal. A qualified name reaches the surface walk in the
  same dotted spelling whether it is a type or a variant head; the route now asks the registry
  whether the leaf is a TYPE declared in the named qualifier, records each decision as a census
  row, and considers only leaves the emitted source actually names (it had also synthesized an
  unused `DeclarationRef` import from a variant payload).
  w_qualified_variant_head_earns_no_type_use_line.

- `Outcome<compile_error!("UNRESOLVED_CompilerError")>` x3 and `Rc<Medium>` E0107: two cuts had
  each introduced a second per-position renderer for arrow types beside the one fn parameters use.
  An arrow's return is not a different kind of type from its parameter: both positions now render
  through render_rust_fn_sig_type, and render_rust_type_with_applied_binding -- which rebuilt its
  EmitGraphInfo with an empty generic scope, so a fn-scope `C` rendered `_` (E0121) -- carries the
  fn's generic names through that hop. The measured gate over the second renderer is deleted.
  w_generic_arrow_return_renders_the_fn_scope_generic; w_arrow_return_type_keeps_its_applied_binding
  (its fixture was an invalid program: Accepted lacked `diagnostics`).

- v2.std.determinism E0425 x2: traced to the bare-name disposition, not the qualified route --
  `Determinism` is a type in std.determinism and a variant of v2.lens.registry LensIdV0, and
  is_known_variant is corpus-wide by spelling, so a TYPE-position reference was delegated to an enum
  it never named. A name in one of the module's type positions never takes the variant arm.
  a_known_variant_spelling_in_a_type_position_takes_the_registry_arm (red by construction on the
  old arm); the harness row is a positive control and says so, because the witness harness refuses
  any pool carrying the colliding variant with NoSuchVariable.

Verified on a test binary built from the self-emitted emitter (not a regeneration): witnesses
23/24 -> 24/24 after the harness row was reshaped; closure instrument 2799 -> 2779. The regeneration
that binds these to the mirror follows as its own commit after the freeze merge.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU

* Regenerate the stage0 mirror at the 49482b0 freeze: byte fixed point at round 3, three paths, each explained by an authority change

srv1 (/tmp/xl0e2.sh -> /tmp/xl0j2.log, launched 2026-08-29T19:52:56Z), criterion = every
regen-population file byte-equal to installed; the full workspace rebuilt as the gate each round.

  round 1  gunbc=14967ca810cb6609 from installed db46176cc5cf5861  -> v1_compiler_emit_rust.rs, v1_tests_claim_reference_derived_disposition_census_witness_test.rs
  round 2  gunbc=5378a516528a6e0c from installed efa440bc86734f53  -> v1_compiler_trait_derive_emit.rs
  round 3  gunbc=974aafe864f743f6 from installed b1a0409ce9fc79d4  -> <none>  BYTE FIXED POINT

  v1_compiler_emit_rust.rs                                          <- 05_emit_rust.dag (arrow positions via the fn-signature renderer, generic scope through the applied-binding hop, type-position exemption, qualified rows with the registry type gate and token filter)
  v1_tests_claim_reference_derived_disposition_census_witness_test.rs <- its .dag (in_type_position at 5 callers + the type-position control)
  v1_compiler_trait_derive_emit.rs                                  <- retracts the unused `pub use crate::std_types::List;` the earlier qualified route synthesized (token filter)

Final installed tree b1a0409ce9fc79d4; merged tree 89c55a0e7e8d949047b5d92864dfc9fe306aebc0 at the
freeze; main parent 5e80671. No hand edit to any generated file.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU

* Witness fixture only: the qualified-type positive control moves to a provider the harness pool can carry

Post-freeze, fixture-only (dag/test/claim is not a regen-population path; a no-drift regen run on
this head is recorded in the PR). Two harness facts, both measured on the fixed-point artifact
gunbc=974aafe864f743f6: a `{Determinism}` inside a .dag string literal is read as an interpolation
of that name (the row failed in the interpreter before any compile ran), and the harness pool is the
probe's DECLARED import closure, so a provider referenced only by a dotted name is absent -- and
std.determinism cannot enter it because its own body references std.perturbation the same way. The
row now uses std.decl_ref with a sibling import and says plainly that it is a positive control; the
class's discriminating red stays at the disposition grain
(a_known_variant_spelling_in_a_type_position_takes_the_registry_arm) and in the closure count.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU

* WIP XL-0B commit 1: thread DeclarationRef into the checkpoint-spelling callers; exact binding first; delete the redundant expression-position alias arm

* Enroll the two emission batteries under the required-gate seed prefix (test.claim.self_host_*)

* XL-0B commit 1: exact spelling at the fn-signature and declaration-type leaves; alias-rhs site reads scope.type_env

* alias-rhs leaf site reads scope.type_env

* Regenerate the stage0 mirror at the XL-0B commit-1 tree: byte fixed point at round 3

Cycle on srv1 over a1c9dde (authority tree bc2ae136138ac4aa), gate bins built each round:
  round 1: compiler e33c998203b59217 from installed df30d05facfa6307 -> drift v1_compiler_emit_rust.rs
  round 2: compiler ad9914da781db28d from installed c475b249666c3ba5 -> drift std_nat.rs, std_types.rs
  round 3: compiler c7ac6e91c1e07861 from installed be968e441d3a2a43 -> every regen-population file byte-equal
CHANGED paths, each explained by the authority change: v1_compiler_emit_rust.rs (the threading);
std_types.rs (Bytes/Secret/SecretValue declaration sites now spell the exact grounding
std::vec::Vec<u8> / std::string::String); std_nat.rs (List<Nat> in container-argument position
renders the closed alias's resolved numeric realization i64 -- type-identical to Nat = i64).
Unit tests on the converged bytes: 552 passed, 0 failed, 140 ignored.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU

* XL-0B commit 2 (source): declared callees imported over builtin capture; dead RebuildEmittedFail variant; Accepted diagnostics bound and threaded; WallNow carries its fields; evaluator binding-miss answers the PartialFunction codomain; Optional-nested variant qualified by its own enum; Clone for generics forwarded by a returned closure

* Regenerate the stage0 mirror for commit 2 (mechanical residue): byte fixed point at round 2

Cycle on 8781269 (main parent d35cda54): round 1 drift on v1_compiler_emit_rust.rs and
v1_compiler_trait_derive_emit.rs (the two files commit 2 edits), round 2 byte fixed point;
installed tree 7fcf44b9f5c9df97, gunbc 2146d1f1844dea92. Unit 552/0. Emitted closure
cargo check 420 -> 392; line-insensitive identity diff vs the merged-tree base: 28 removed,
0 added (E0061 x6 vocab arity, E0599 GlobalBare* x4, E0004 x7, E0533, E0271, E0618 x2,
returned-closure Clone x7).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU

* A1: relocate the import-admission helpers to their consumer layer; C: one storage representation for Map at every position

A1 (closure prune). Counting fully qualified code references as declared edges, the declared
closure from v2.compiler.compile equals the emitted set: no module enters by bare-name binding.
The carrier was 03_name_resolve importing v2.lens.reference_deps for admission_from_module_root /
import_rows_from_parsed_module / collect_import_decl_nodes / ImportRowsState, consumed only by
v2.workflow.compile_door_ledger and self_host.frontier_probe (both outside the closure, both already
importing reference_deps). They now live in reference_deps; the two consumers import them there.
Emitted closure drops 8 modules (lens.coverage, enforcement.{grammar_coverage,standing_intent,vocab},
registry, module_graph, reference_deps, std.decl_index) and all 6 host-primitive panic sites.

C (Map). The six PartialFunction<..> positions (InferredTree.facts, EvaluationEnvironment.bindings,
four signatures) are Map<..>; the four PartialFunction { lookup: .. } constructions are empty_map()
or a first-wins map_insert fold; map_insert routes through a rostered map_insert_primitive_delegate
(closure body deleted); slots.lookup -> map_lookup. Emitter: the alias RHS renders a keyed/element
collection through the host template (type X = Map<A, B> -> Rc<HashMap<..>>), and a generic in map-key
position carries std::cmp::Eq + std::hash::Hash from the signature. Two witness rows added.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU

* XL-0N: generic LiteralElaboration/OperatorRealization authority — typed literal-to-Zero/Succ homomorphism at every boundary, operator realization by exact operand structure, structural Peano Nat operations (no i64 row)

* XL-0N: the Peano-Nat inhabitance witness asserts the ruled admission through its homomorphism; its expected-red row is retired by its trigger

* XL-0T commit 1 (source): UnicodeScalarSequenceUnfold arm + text homomorphism row; scalar-sequence literal image as the canonical list introduction; identity wall on the spelling-compatibility fallback; delete the four host string-op body overrides and the inert host_string_text seam pair; structural-text witness battery

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM

* C corrected: InferredTree.facts stays the open PartialFunction; PartialFunction realizes as its algebra struct everywhere (HashMap rows deleted); frontier row dissolved; two TargetChanged admissions

The CI floor on 4da6059 showed the facts retyping over-reached: about 120 test and fixture sites
plus program.dag / 05_emit_orchestration define InferredTree.facts by a predicate closure, which
is exactly what the open carrier is for. inferred_tree / 04_infer / program_partition are restored.
The fork was the emitter realizing PartialFunction as HashMap in signature position and as the
algebra struct in field position; the PartialFunction HashMap rows in extdeps.languages.rust
(types.dag row, the partial_function template) are deleted so one representation stands.
EvaluationEnvironment.bindings stays Map (built by map_insert); v2_effect_io_pure's empty
environment is empty_map(). The v1 unresolved_method_frontier row for target_model lookup /
Primitive(T) is deleted: the slots.lookup -> map_lookup rewrite dissolved its one occurrence.
The two TargetChanged binding deltas for admission_from_module_root (frontier_probe,
compile_door_ledger) are admitted by exact subject in namespace_wave_admission.rs.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU

* XL-0N: operand realization hops alias/refinement declarations to their target (NonEmptyStr, Char, VersionIdentity compare/add as their host targets)

* Regen round 1: install the stage0 candidate at the XL-0T commit-1 tree (BuildBuddy, old-compiler bootstrap round; three new mirrors: std_literal_elaboration, std_operator_realization, gunbc_structural_realization_bindings)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM

* Regen round 1 fixup: restore the three hand-maintained ExprElaboratedLiteral interpreter arms the bootstrap revert had carried into the round-1 install

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM

* Regenerate the stage0 mirror for A1 + C (aa373f9): byte fixed point at round 3

Round 1 changed the five authority mirrors (extdeps_languages_rust_emit, extdeps_languages_rust_types,
std_primitive_projection, v1_compiler_emit_rust, v1_compiler_infer), round 2 only compiler_tests.rs,
round 3 byte-identical; installed tree f53efd0d0173a43e, gunbc 1a2d53dd15920cf1. Unit 552/0.
Emitted closure cargo check 392 -> 278; line-insensitive identity diff vs commit 2: 112 removed,
0 added. Batteries on the converged binary: 29/29 (the two C rows red on the pre-fix compiler by
fixture emit), 14/14, 20/20.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU

* Regen round 2: extdeps_version_semver.rs and std_unicode_types.rs converge under the round-1 compiler

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM

* XL-0N: Bool row -- KernelBoolLiteral into v2.std.logic.Bool via BooleanUnfold (True/False); interpreter evaluates an elaborated literal as its kernel value; falsifier pair (row found/removed in the interpreter, constructor image vs host keyword on the emitted path)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013koFunEtpLQCnvUiz85k7Y

* Back out the round-2 convergence of extdeps_version_semver.rs / std_unicode_types.rs: the round-1 compiler's operator-realization wall refuses < on NonEmptyStr/VersionIdentity and + on Char despite the 657010b alias-hop, so the converged mirrors carry compile_error! and the lib does not build; XL-0N owns the hop

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM

* XL-0N: operand realization hops alias items by is_type_alias_item/resolved_type (the derive lane's own test) -- the structural condition on the declaration node never held, so NonEmptyStr/Char/VersionIdentity host ops were refused in the regenerated compiler

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013koFunEtpLQCnvUiz85k7Y

* Regen round: converge the union tree (semver/unicode mirrors regenerate under the alias-hop; elaboration authorities and emit/infer mirrors carry both lanes' arms)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM

* Commit 3 of the #9664 closure: six emitter mechanisms, the null keyword by path, and map_insert back to its .dag body under the gate's ruling

Emitter (src/v1/05_emit_rust.dag, trait_derive_emit.dag), each with a discriminating row in
self_host_emitted_call_target_realization_witness_test (pre-fix bytes observed on the seed):
- an argument into a parameter spelled Optional<T> is not unwrapped (the cardinality flag marks
  only the T? sugar; the applied spelling is asked too)
- the shared-field accessor impl of a generic coproduct carries T: Clone
- a Violates literal in a record field takes the field's Witness carrier before the fn return
- a record pattern over a shared carrier derefs like a shared enum's variant pattern
- a fn returning an arrow-field record carries 'static on its generics (same gate as impl Fn)
- the fn-field record header prints well-formedness bounds asked per parameter instead of the
  bounded set minus the seed set (FalsificationReceipt<Subj, A> lost A behind ValueDiff<A: Clone>)
- extdeps.languages.rust emit: the null keyword is std::option::Option::None, because a module
  declaring a nullary variant named None emits pub struct None; at module scope (std.cache_interface)

v2.std.collection: map_insert is its .dag body again and map_insert_primitive_delegate with its
primitive_projection row is deleted. The delegate tripped map_carrier_shape_gate on CI at c6d9b22
(record_shaped_map_reaches_map_insert BUDGET-REFUSED): the interpreter's free_call.map_insert arm
answers Ok(None) for a non-native shape and the grounding falls through to the delegate's own
body, a self-call -- the deferred-refusal class #8887 filed. The closing move is a host fact
(a typed refusal in try_v2_std_collection_map_primitive_grounding) and is ledgered in the PR body,
not landed here, by the manager's ruling.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU

* Bootstrap ordering: back out the refusal-bearing semver/unicode mirrors once more — round 4's candidate was emitted by the pre-hop compiler; the hop-carrying emit_rust mirror is installed, so the next round regenerates them clean

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM

* Hoist commit-3 rationale annotations to module-item grain (§4c refuses in-body // blocks; 17 regen refusals on 780b394)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU

* XL-0N: operand realization reads the RESOLVED structure -- a NoConnective childless leaf whose structural name is a kernel type is a host operand (the resolver collapses NonEmptyStr/Char/VersionIdentity to their primitive RHS under the alias identity, so no resolved node is ever an alias item); refusal temporarily carries the operand's shape facts for the regen diagnosis

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013koFunEtpLQCnvUiz85k7Y

* Regen: install the hop-3-bearing emit_rust mirror only; semver/unicode stay at pre-wall bytes until a hop-3 compiler emits them (bootstrap ordering)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM

* Revert "Regen: install the hop-3-bearing emit_rust mirror only; semver/unicode stay at pre-wall bytes until a hop-3 compiler emits them (bootstrap ordering)"

This reverts commit c83e528a108c8834e19a72976b611642033497ed.

* XL-0N: shape-facts suffix spells Int counts with to_string (the seed runtime has no Int-as-String cast; the cast panicked the emitter under regen)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013koFunEtpLQCnvUiz85k7Y

* XL-0N: operand realization hops a where-refinement wrapper to its base (is_where_refinement_type, the type renderer's own route) -- measured under regen: NonEmptyStr/Char/VersionIdentity operands resolve to the one-child Conj refinement node, not a leaf or an alias item

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013koFunEtpLQCnvUiz85k7Y

* XL-0N: operator realization matches over BinOp are total (14 closed variants enumerated) -- no non-fold residue rows for the new module

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013koFunEtpLQCnvUiz85k7Y

* Commit 3 correction after the first regen: withdraw the Violates field-carrier arm (the literal resolves to the Witness declaration, spelling Witness::<Holds> at 87 sites), 'static on generics only for fn-field record returns (compose<A, B, C> stays bare), re-pin the optional and shared-record rows

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU

* Revert the identity wall in the corpus-wide compatibility relation: its first floor execution refused grounded-identity code (roadmap_page if-join, Ruling 3); the non-literal refusal is blocked on the peeling declared-boundary conformance capability and recorded as such

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM

* Enroll std_literal_elaboration in the stage0 std-core partition roster (v2.workflow.rust_crate_partition): v1_std_core imports it, so the layered crate must own the module ahead of v1_std_core

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM

* XL-0N: retire the regen-diagnosis shape-facts suffix -- the where-refinement hop is confirmed at byte fixed point (6ba83b3 regen, round 2 equal)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013koFunEtpLQCnvUiz85k7Y

* XL-0N: regenerated stage0 mirrors at byte fixed point (070a203 source, BuildBuddy regen round 3 first_generation_equal=true; partition crates rendered=14 written=0)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013koFunEtpLQCnvUiz85k7Y

* Regen: mirrors catch up with the wall revert (infer_types, emit_rust, lib, emitted_population); semver/unicode held at pre-wall bytes until the where-refinement hop merges

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM

* XL-0N: register std.literal_elaboration and std.operator_realization in the std-core partition and gunbc.structural_realization_bindings in the v1-infer binding unit (v2.workflow.rust_crate_partition), with their module-dag edges

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013koFunEtpLQCnvUiz85k7Y

* Regen: merged-tree round — emit_rust re-carries both lanes; std_nat/std_types/std_operator_realization converge; semver/unicode byte-equal to pre-wall under the where-refinement hop

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM

* XL-0N: type_reference_declaration_ref resolves an in-place (recursive) type reference through its env binding before matching the declaration span -- v2.std.nat.Nat is recursive and answered Absent, so its literal boundary and operand identity fell to the unavailable arms while v2.std.logic.Bool worked

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013koFunEtpLQCnvUiz85k7Y

* Regen: std_nat/std_types converge to the exact-grounding spellings (i64 container args, std::vec::Vec<u8>/std::string::String)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM

* Rung drop: non-literal kernel-String refusal at the structural text boundary (text_boundary_identity_wall)

Rosters the reverted identity wall as a DESIGN 4b(3) declared drop: previous
rung (the wall as landed), temporary rung, the roadmap_page grounded-identity
refusal that forced the revert, population, and a restoration trigger naming
the declared-boundary conformance peeling capability with its sufficiency.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM

* Projection regen: partition roster gains std_literal_elaboration; rung-drop roster projects text_boundary_identity_wall into DESIGN.md and design-ledgers

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM

* Partition mirror + std-core crate carry std_literal_elaboration; rung-drop row per ruling (two-path standing, identity-census population, A/B trigger); planted non-literal restoration probe

The roster edit only reaches the crate renderer through its compiled-in mirror
(gunbc_stage0_crate_partition_generated.rs), so the sequence is projection ->
regen -> rebuilt claim_executor -> emit-partition-crates, which wrote the
std-core lib.rs row that clears the partition E0432.

The rung-drop row is reworked to the ruling's grain: no rung claimed for the
withdrawn wall, emitted-Rust path mechanically preventable vs source-acceptance
path unguarded (never averaged), population bounded by identity with the wall
re-applied as the named producer, and the two-direction A/B restoration
trigger. The witness battery gains the planted non-literal probe asserting the
present acceptance.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM

* Projection: design-ledgers carries the reworked text_boundary_identity_wall row

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM

* Total the two LiteralUnfolding producer matches in peano_nat_structural_realization_test over UnicodeScalarSequenceUnfold

The floor refused at 216a7d4 on the two non-exhaustive matches once the new
producer arm entered the coproduct.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM

* XL-0N: regenerated stage0 mirrors at byte fixed point on e51aff9 (BuildBuddy regen round 3 first_generation_equal=true; includes the merged #9710 commit-3 null-keyword-by-path drift and the new-module mirrors)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013koFunEtpLQCnvUiz85k7Y

* Bootstrap: reset stage0 mirror tree to origin/main's self-consistent set; the next regen round re-derives the session's authority changes

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM

* XL-0N: type_reference_declaration_ref falls back to the module-visible name binding when the reference carries no ident-keyed binding (the emitter's scope env) -- the found declaration is still span-matched against the global roster, so a by-name hit only confirms an exact declaration; measured: Peano literal rows passed while the operator rows still lost Nat's identity

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013koFunEtpLQCnvUiz85k7Y

* Regen round on the merged tree: re-derive session mirrors from main bootstrap (new std_literal_elaboration/std_operator_realization/structural_realization_bindings mirrors, partition std-core row) and restore the four hand-maintained ExprElaboratedLiteral interpreter arms

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM

* Interpreter hand roster: EXPR_VARIANT_COUNT 23 with the ExprElaboratedLiteral arm restored

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM

* Exact identity for a resolved alias destination: type_reference_declaration_ref falls back to the reference's env binding when the resolver's substitution carries the occurrence span

The resolved-alias case (v2.std.text String = FreeMonoid<Char>) answered none
from the census because the substituted node's ident_span is the annotation
site, so every text.String literal boundary elaborated as DirectLiteral while
the declared coproducts Bool and Nat worked. Second hop = the same env-binding
read e51aff9 added for in-place recursive references; both hops answer by
declaration span from the census, never by spelling. Also carries the
partition std-core lib.rs write from the converged round.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM

* Third identity hop: a resolver-qualified authored name joins the census by (module_path, name)

Modules that reference a type with no import resolve it by the resolver's
qualification, so lookup_type_for has no binding and both span hops answer
none while the emitter still realizes the structural carrier -- the literal
boundary stayed DirectLiteral exactly there (measured: the data prose rows in
v2.compiler.source_authority and extdeps.languages.dag, which import no
String). The qualified prefix is joined against the census row, never trusted
as a spelling.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM

* Regen: infer_env mirror carries the two identity hops

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM

* Cached-data emission renders an elaborated literal through the typed-expression emitter

The JSON mock route serializes nested-record VALUES and has no spelling for
the elaborated image; its wildcard refused every structural-text data row
with 'unsupported mock expression' after the elaboration fired (measured on
the anchor probe). The image is ordinary constructor nodes and renders like
any expression.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM

* Move the elaborated-literal data-arm rationale out of the fn body (4c: module-item grain only)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM

* Regen: emit_rust mirror carries the elaborated-literal data arm

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM

* XL-0T: host-text carrier spelling chosen by declaration identity -- a known non-structural String reference renders the grounding spelling std::string::String, unshadowable by the generated structural use line

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM

* Unescaped interpolation braces in render_rust_text_carrier_identity_note quoted the generated use line verbatim; regenerated mirror emitted string.clone() -- quote it without braces

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM

* Class row generated_binding_shadows_bare_render: a generated use line rebinding a bare-spelled render composes into silent wrong realization; fix is declaration-identity-keyed rendering with the grounding spelling

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM

* Route all six type-renderer host-text short-circuits through the identity-keyed render_rust_text_carrier -- the first-line bare-String renders at render_rust_type/without_applied_binding/applied/decl/fn_sig/in_scope were still spelling-keyed

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM

* Reference-binding hop precedes the resolved-node hop in type_reference_declaration_ref: alias expansion is closure-dependent, so the inferred node names the realization the alias peels to (std.algebra.FreeMonoid) while the boundary identity is the declaration the author named (v2.std.text.String); measured pd/pe/pf probes flip on std.types presence alone

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM

* Regen: mirrors converged at first-generation byte fixed point over the identity-split emitter and reordered identity hops (fixed point re-verified with the final binary)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM

* Projections: DESIGN.md/design-ledgers.md carry generated_binding_shadows_bare_render; stage0 partition roster regenerated

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM

* Regen: mirrors re-converged on the merged tree (first-generation fixed point verified with the rebuilt binary)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM

* Projections: DESIGN.md re-projected on the merged tree

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM

* Identity answers guarded by the authored leaf name (rejects the alias-expansion artifact without letting name-keyed hops outrank the exact resolved-node hop -- the reorder regressed the Peano battery on the Nat homonym); grounding spelling scoped to modules whose bare String binding is structural (corpus-wide grounding redded two witnesses pinning the bare kernel spelling)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM

* A rejected expansion artifact re-derives its destination from the module-level name binding, not the per-node one: lookup_type_by_name is import-driven and uniform across the module, so one module cannot split into structural annotations beside host values (measured 108->174 board regression under the per-node fallback)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM

* Terminal census hop: when the annotation is unresolved and no env binding names it, a UNIQUE global_bare declaration of the authored leaf is the destination (the documented global-uniqueness resolution rule); ambiguity stays Absent, fail closed. Measured: pd anchor reads expected present, n=String rtn=noresolve bare=unique:v2.std.text -- every existing hop declined while the census carried the answer

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM

* The unique-census hop is the terminal fallback for EVERY Absent outcome of the identity hops, not only the by-name arm -- the measured failing path was lookup_type_for answering a binding whose census read fails, which returned Absent without ever consulting the census

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM

* One subject, one answer at the literal boundary: the natively-realizes fact is read from the DESTINATION declaration's census file, not re-derived from the reference node's span -- a kernel-minted annotation span (<kernel:String>) answered natively=TRUE against a v2.std.text.String destination, keeping the literal direct at a structural boundary; node-span file remains the fallback when the census has no row

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM

* Type repair: route the census-file read through span_file_string so the FilePath product coerces at a String return boundary (the inline if/else mixed Product(FilePath) with a String literal and regen refused, invalidating the prior round's probes)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM

* One authority for the text spelling: render_rust_text_carrier consults type_reference_declaration_ref + the destination census file -- the same reader the literal boundary uses -- rendering a structural destination as the qualified crate path and everything else bare; the module-binding heuristic and grounding spelling are deleted (both measured wrong in opposite directions)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM

* Retract the terminal unique-census hop: a corpus-unique declaration is not the destination of a reference the module never bound -- it invented structural identities for the whole kernel corpus (census 108->569/437 measured). The census read survives only where a module-level binding EXISTS and its own census read fails, and as the natively-coherence file source. Consistency now rests on the one-authority renderer: infer and emit consult the same reader, so whichever answer identity gives, annotation and value agree

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM

* Mirror reset to main's self-consistent set (the ours-side merge resolution mixed pre-main mirrors with main consumers of compile_sources_selected -- E0432 on round 1); hand-maintained interpreter arms re-inserted (4 ExprElaboratedLiteral arms, EXPR_VARIANT_COUNT 23)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM

* Interpreter mirror back to main's for bootstrap round 1 (the hand arms reference ExprElaboratedLiteral, which only regen adds to v1_std_core); the arms are re-inserted mid-convergence and land with the regen commit

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM

* Revert the identity-reader widenings and emitter spelling experiments to the c7b8056-compatible three-hop state, recording each measured failure in place: leaf-name guard 108->174, terminal census hop ->569, module-binding rederivation ->437, one-authority renderer ->745. The shadowed-module class stays open under the boundary-lane declared drop with its fix shape on the class row; natively-coherence (destination census file) is kept

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM

* Parse repair: orphaned closing brace left by the renderer revert

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM

* Complete the revert: natively back to the node-derived decl_file (the census-file coherence read was deleted with the census hops and its consumer refused regen)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM

* Merge repair: the row-union dropped my class row's evidence/closing lines when the conflict markers were stripped mechanically -- both rows now well-formed (this parse error silently refused regen, which my capture filters then hid)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM

* Regen: mirrors converged at first-generation byte fixed point on the merged tree (rounds 2, 3 and the final rebuilt-binary check all equal); interpreter hand arms restored; DESIGN/design-ledgers projections carry both new recurring-failure class rows

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM

* Round-1 bootstrap coherence: stage0_std_core lib.rs taken from main alongside main's stage0 mirror set (regen re-derives the literal-elaboration rows)

* Regen: converged at first-generation byte fixed point on the round-1 bootstrap tree — literal-elaboration/operator-realization/structural-bindings mirrors re-derived and installed, partition lib rows and the four ExprElaboratedLiteral interpreter hand arms restored (EXPR_VARIANT_COUNT 23)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01R4A6MRdzeYxNr7dRbugcUC

* Regen: converged at first-generation byte fixed point on the re-cut tree (round 2 equal) — the mirror delta vs main is exactly the four text-family files the re-added UnicodeScalarSequenceUnfold row touches

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01R4A6MRdzeYxNr7dRbugcUC

* Floor fixes for the re-cut head: totalize the two LiteralUnfolding matches in peano_nat_structural_realization_test over the re-added UnicodeScalarSequenceUnfold variant (both witnesses PASS scoped), and retire the XL-0N #9719 wave-admission row by its own dissolve-on trigger (base and head both carry the relocation; the run on bc74b2e reported it stale)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01R4A6MRdzeYxNr7dRbugcUC

* Re-cut floor recovery: restore the literal-destination identity hops (declaration_ref_of_type_node with by-name + qualified-census fallback, scoped to the elaboration destination read; XL-0N's operand reader untouched), delete the resurrected name-keyed text op overrides and host_string_text seam arms from 05_emit_rust, restore the ExprElaboratedLiteral arm in data-value emission, and narrow the ops witness excludes to the overrides' exact receiver forms (bare .is_empty() red the structural Vec lowering — substring-oracle over-match). Text battery 11/11, peano 29/29, regen at byte fixed point

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01R4A6MRdzeYxNr7dRbugcUC

* Post-merge repair: rebuild rung_drop.dag from main's version plus the text_boundary_identity_wall row intact (the union regex had split on a '=======' line inside an authored string — parse error at the module index), retake main's stage0 set (the generated-artifact merge driver had left ours-bytes marker-less on namespace_wave_admission.rs), regen re-derives the six text-family mirrors to the byte fixed point (round 2 equal); text battery 11/11, peano 29/29

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01R4A6MRdzeYxNr7dRbugcUC

* Structural key for the text literal homomorphism: the row keys on what survives resolution (FreeMonoid+Char), natively reads the destination's own declaring file, witnesses re-anchor on the qualified boundary

The #9813 kernel-precedence landing exposed that the text row was keyed on
information resolution deliberately discards: String is a container-alias
spelling, so every 'type X = FreeMonoid<Char>' boundary peels to the bare
structural carrier and no module spelling survives to key on. The row now
keys on that surviving structure — destination std.algebra.FreeMonoid with
element std.types.Char (LiteralHomomorphism gains an element field,
threaded through literal_homomorphism_for/elaborate_literal_at; peano and
bool rows carry element: none).

Second repair on the same boundary: destination_realizes_natively was read
from the RESOLVED NODE's ident_span file, and a substituted alias RHS is a
kernel-minted node whose pseudo-file <kernel:std.algebra.FreeMonoid>
string-matched the '<kernel:' native-numeric roster row, so the peeled
structural boundary answered natively=true and took DirectLiteral with the
matching row present. natively is now read from the DESTINATION
declaration's own census file (declaration_file_of in 04_env), per
numeric_realization_identity_note's own rule that realization is a fact
about the declaration.

Witness battery re-anchored per the division ruling: the seven positive
rows probe the QUALIFIED v2.std.text.String boundary (each probe imports
string_is_empty so the harness's import-following closure loads the text
module), and a new control pins bare String + text import = host,
deterministically, under uniform kernel precedence. 12/12 text rows and
29/29 peano rows green by execution; stage0 mirrors regenerated to
first-generation byte fixed point on the merged tree.

Also: recurring_failure_mode row mistyped_body_radiates_nonlocal_diagnostics
(the phantom-diagnostic specimen, layer stated), DESIGN.md and
docs/design-ledgers.md regenerated via generated_artifact_gate main_wet_one,
stale rust_host_string_seam_fn_emit comment fixed (review 57929).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01R4A6MRdzeYxNr7dRbugcUC

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Sep 3, 2026
…ence from the containment authority — and retire #9813's module-wide precedence at the root. AUTHORING AUTHORIZED by ruling, MERGE HELD for root-cut receipts. Local use-line/qualification repairs are DEAD. (#10236)

* The candidate index built once, then revalidated the whole transport per reference

std.occurrence_binding_candidates resolve_reference_via_structural_candidates
documents that it builds the candidate index exactly once per transport, and it
does. Per reference it then called std.occurrence_binding_resolve
resolve_reference_occurrence_binding, whose first act is
occurrence_transport_validate over the WHOLE transport -- three full folds across
every index entry, declaration and reference. So the once-built index was defeated
one layer below itself and the path was O(references x population).

MEASURED, NOT REASONED, on the same subject in both directions: the census
instrument added here resolving dag/std -- 142 files, 9672 type-occurrence
references -- ran past a 45-minute wall producing nothing. After the repair the
same run over the same subject completes in 8 seconds.

THE REPAIR IS FEWER REPRESENTATIONS OF ONE FACT, NOT A CACHE.
occurrence_candidate_index_build already validates exactly once and already held
the whole ValidatedOccurrenceTransport; it kept entries_by_id and discarded the
other four fields, which is precisely what left the resolver unable to hand a
validated transport down. OccurrenceCandidateIndex now carries the
ValidatedOccurrenceTransport itself -- entries_by_id is reached through it, so
there is no second copy to drift -- and the resolver calls the ALREADY-EXISTING
resolve_reference_occurrence_binding_validated. This is DESIGN section 2's
demand-graph move (carry the value to the shared ancestor), not a memoization, and
DESIGN section 6's bare-minimum-cost standing rule settles it independently: a
proven cost-shape defect is always fixed regardless of realized n. Here n is every
type occurrence in the corpus.

BOTH SITES, because one fact with two homes is what lets a repaired path sit beside
an unrepaired one answering the same question.
std.reference_binding_observation structural_binding_resolution_from_candidates had
the identical shape and is repaired with it.

THE `transport` PARAMETER IS GONE from both entry points rather than left unused: a
second unvalidated OccurrenceTransport beside the validated one is two
representations with nothing forcing them to be the same transport, and a caller
handing in a different one would resolve silently against whichever arm read it.

BEHAVIOUR IS PRESERVED BY THE EXISTING WITNESSES, which is why this carries no new
behavioural test. resolve_type_reference_containment_binding and
structural_binding_walk keep their signatures, so
test.claim.type_reference_containment_binding_witness_test,
test.claim.type_reference_binding_context_witness_test and
test.claim.occurrence_binding_candidates_witness_test assert the same bindings
through the changed code. What changed is cost, and the instrument -- not a
transcribed number -- is what re-derives it.

WHY IT IS NOT BUNDLED WITH THE XL-0T CUTOVER IT WAS FOUND UNDER: the cut routes
every type occurrence in the corpus through this path, so switching type-position
consumers to it while it revalidates per occurrence would ship a regression even if
every binding answer were right. It is a prerequisite of that cut, and a cost
repair and an authority cutover are two subjects.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01KLXA6u6f3UK8PR5VEJoUwm

* The parser never stamped a type DECLARATION, so every type reference in the corpus was unbindable

MEASURED FIRST, over dag/std (142 files) with the census instrument's --denominator
mode: 9672 TypeOccurrence REFERENCES against type_occurrence_declarations=0.
TypeOccurrence appeared four times in v1.compiler.parse -- the enum member and three
ParsedOccurrenceReference sites -- and ParsedOccurrenceDeclaration was produced with
FieldOccurrence, LexicalValueOccurrence, CallableOccurrence and
NamespaceSegmentOccurrence, never with TypeOccurrence.

std.occurrence_binding_candidates buckets candidates by authored spelling and
std.occurrence_binding_resolve admits a TypeOccurrence reference against a
TypeOccurrence declaration only, so an empty declaration side made EVERY type
reference in the corpus Unbound -- not mis-bound, UNBINDABLE. The containment
authority the namespace cut resolves through was correct, executing, and had never
been fed a production population.

THE DISCRIMINATING CONTROL that located it upstream of visibility: all three
DeclarationExposureGrounding values returned BYTE-IDENTICAL partitions. Exposure
decides visibility and is the variable the census varies; a zero insensitive to it
cannot be a visibility result.

WHY NO FIXTURE COULD HAVE SHOWN THIS.
test.claim.type_reference_containment_binding_witness_test hand-builds its
declarations with `category: TypeOccurrence` -- exactly the shape production never
emitted -- so the suite supplied the missing side itself and stayed green. DESIGN
section 5's specification-without-execution boundary, sitting on the DESTINATION
authority of a migration, where a green suite is not weak evidence but zero
evidence. Those fixtures are untouched here: they test the authority's logic
correctly, they were never SUFFICIENT, and nothing in the tree said so.

THE RULE IS STATED POSITIVELY rather than as "not a function": a module item
declares a type when it has no body, no transport and no type annotation. That
admits the three authored forms -- `type X { .. }` (Conj), `type X = A | B` (Disj),
and the bare alias `type X` -- and excludes by construction the items that are
values or effects: a function has a body, a `data x: T = v` has a body AND an
annotation, a service carries a transport. Imports cannot be caught by it: they live
in the module node's params and are stamped on a different path from its children.

RESULT, same instrument, same subject, dag/std:
  type_occurrence_declarations   0 -> 1243
  Y bindings                     0 -> 3057
  partition still closes at 9672, zero unclassifiable
and the five-way census the cut needs has content for the first time: 2786
OldAndNewAgree, 2203 OldBinds_NewUnresolved, 3136 OldKernel_NewUnresolved, 909
OldSynthetic_NewUnresolved, 367 OldUnresolved_NewUnresolved, 250
OldSynthetic_NewBinds, and 21 OldAndNewDisagree -- the first real binding deltas
anyone can adjudicate.

SCOPE IS DECLARED SO THE NEXT INCREMENT IS DRIVEN BY MEASUREMENT. This stamps
MODULE-LEVEL type declarations. Coproduct VARIANTS in type position and TYPE
PARAMETERS are reachable from this walk and are NOT stamped, so references to them
stay Unbound and the census names them rather than passing over them in silence. The
same run also shows MethodOccurrence at 382 references against 0 declarations --
an independent gap in the same collector, not addressed here.

Stage0 mirror regenerated; the emitted drift is exactly v1_compiler_parse.rs.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01KLXA6u6f3UK8PR5VEJoUwm

* Census bin: satisfy the clippy gate that is the only step compiling bin targets

CI red on the merge-blocking `cargo clippy --all-targets -- -D warnings` step: six
lints in the census binary added by the parent commit -- one very-complex-type on
the three-vector return of `inputs_for_module`, and five `clone()` calls on
`OccurrenceId` and `DeclarationExposureGrounding`, both of which are `Copy`.

The return triple is now the named `ModuleInputRows`, because a bare tuple of three
vectors says nothing about which list is which, and the five clones are dropped.
Behaviour is unchanged: cloning a Copy type and copying it are the same value.

WHY IT REACHED CI AT ALL, recorded because the tree already warns about exactly this
and I walked into it anyway. I verified the new binary with `cargo build`, and
DESIGN's Building & checks section states that
`cargo clippy --all-targets -- -D warnings` is "the only command that compiles the
integration-test and example targets, so a red there is invisible to every other
step". A new `[[bin]]` target sits in precisely that blind spot: every check I ran
was green and none of them compiled the file under the gate's lint set. The lesson is
not "run clippy too" -- it is that a named gate command is the thing to run, and a
proxy for it establishes nothing about the gate.

Verified by running the gate command itself rather than a proxy: CLIPPY_STATUS=0.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01KLXA6u6f3UK8PR5VEJoUwm

* Stamp type declarations at the parser, and refuse the shapes the rule cannot decide

v1.compiler.parse stamped type REFERENCES as TypeOccurrence and never stamped a
type DECLARATION as one. Measured over dag/std (142 files) the production
transport carried 9672 TypeOccurrence references and ZERO TypeOccurrence
declarations, so every type reference in the corpus was UNBINDABLE -- not
mis-bound -- because occurrence_binding_resolve admits a TypeOccurrence
reference against a TypeOccurrence declaration only.

Every existing fixture stayed green through that because each hand-builds its
declarations with `category: TypeOccurrence` -- the shape production never
emitted -- so the suite supplied the missing side of the join itself. Those
fixtures are correct about the authority's logic and nothing here weakens them;
they were never SUFFICIENT, and nothing in the tree said so.

THE PARSE TREE CARRIES NO POSITIVE TYPE-DECLARATION MARKER. The parser
dispatches on the `type`/`fn`/`data`/`service` keyword and then discards which
one it saw: Node has no item-kind field, so the kind survives only as which
optional fields happen to be absent. A bare predicate over three absent fields
fails open by construction at the parser, so the rule is written as an
exhaustive ParsedModuleItemKind match whose ModuleItemUnrecognized arm REFUSES
with a located diagnostic rather than defaulting into the type bucket
(DESIGN section 5: a failure arm refuses, never widens). The terminal fix is a
construction, named in the annotation: parse constructors carry the kind they
already know, at which point the emit-side shape predicates dissolve into it.

Enrolled with a PRODUCTION-FED control -- not another hand-built transport --
whose third conjunct is the state that was red before this change: a subject
with type references and an empty declaration side. It executes on no required
run (the required floor's source roots are dag and src/v2, and this subject is
only reachable through v1.compiler.parse); rung mitigatable, next-rung trigger
stated in the file.

Scope, so the next increment is driven by measurement: MODULE-LEVEL type
declarations only. Coproduct variants and type parameters in type position stay
unstamped, and MethodOccurrence stands at 382 references against 0
declarations -- an independent gap in the same collector.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01KLXA6u6f3UK8PR5VEJoUwm

* Gate the census behind an established declaration population, and stop stamping resources as types

THE CENSUS NOW HAS AN OUTER STATE, and building it found a live fail-open in the
change that introduced it.

TypeOccurrenceBindingCensusOutcome = CensusUnavailable { cause:
ProductionTypeDeclarationPopulationUnestablished } | CensusReady {
joined_declarations }. The thirteen classes are constructible inside CensusReady
and nowhere else. Before the stamping landed, Y never RECEIVED a declaration
population, and reporting that as OldBinds_NewUnresolved turns PRODUCER ABSENT
into a SEMANTIC RESOLUTION ANSWER -- a partition that closes over an absent input
closes over nothing.

CensusReady is constructible only after an exact-set join at OCCURRENCE-ID grain,
with uniqueness on both sides and no extra members. Not count equality, which a
compensating pair of errors satisfies. The join is against an INDEPENDENT reader:
v1.compiler.emit_core_support decides "is this item a type declaration" from
CONNECTIVE, PARAMS and CHILDREN, while the stamper decides it from the ABSENCE of
body, transport and type annotation. Different facts about the same item, so
agreement is evidence rather than measure() == measure(). New parse-only mode
`--establish` answers the obligation over the whole corpus at parse cost.

WHAT IT FOUND ON ITS FIRST RUN. Over dag + src/v2 + src/v1, exactly one diverging
module and three items: Filesystem, Clock and Entropy in std.resources. A
`resource` carries no body, no transport and no type annotation, so the
three-negatives rule stamped all three as TYPE DECLARATIONS, silently, at the
parser. The refusal arm could not fire: a resource is not merely unrecognised, it
is INDISTINGUISHABLE from a type under that rule. The parser's own item error
names TEN keywords -- alias, type, fn, func, service, resource, data, extern,
pattern, interface -- so the four-kind premise was wrong and its falsifier was in
the same file. Fixed with a ModuleItemResource arm keyed on the properties the
resource grammar attaches; the corpus-wide join now reports CensusReady.

Recorded in the annotation as a class and not a specimen: a discriminator built
from ABSENCE is only as complete as the enumeration of kinds it was derived from,
and it fails silently toward the DEFAULT BUCKET rather than toward the refusal
arm, so the refusal reads as coverage and is not.

TWO INSTRUMENT DEFECTS CAUGHT BEFORE BEING REPORTED AS PRODUCTION ONES, both
named in the annotation. The join first read the post-typecheck item list, whose
rebuilt copies carry OccurrenceSynthetic (1077 phantom "no minted occurrence"
rows); and it compared per-file parse ids against the whole-program index, two
different id spaces (40 phantom absences).

EXPOSURE DISCRIMINATION, PRODUCTION-FED. New control: one parsed source, the same
occurrences and the same resolver; under ModuleLocalMemberExposure a module-root
declaration is ModuleExposure and a consumer-module reference is UNBOUND, under
CrossFileProviderExportedExposure it is RootExposure and the same reference
BINDS. Three identical grounding columns are the signature of an absent input,
and this is what makes that signature impossible to mistake for agreement.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01KLXA6u6f3UK8PR5VEJoUwm

* Three census states, the ruled recognition rule, and the seed mirrors regenerated on the merge

CENSUS OUTER STATE IS NOW THREE, because two conflated two different facts.
"The join agrees on today's tree" and "the classifier is a durable authority" are
not the same claim, so:

  CensusUnavailable { DeclarationDomainAbsent | DeclarationDomainDisagrees }
  CensusObservedOnCurrentTree { joined_declarations }
  CensusAdmissibleForCut { parser_carried_item_kind, joined_declarations }

DeclarationDomainDisagrees CARRIES the missing and extra sets, so a resource
silently stamped as a type reads as a typed, located cause rather than a generic
unavailability. CensusObservedOnCurrentTree is enough to scope work and discover
disagreements. CensusAdmissibleForCut is UNCONSTRUCTIBLE on this tree and is
modeled anyway: the alternative -- leaving the distinction unmodeled -- is exactly
what would let "the join agrees" be read as "the cut is authorized". Its arm
refuses rather than falling through, so nothing quietly starts answering for it.

THE RECOGNITION RULE, carried into the annotation in the words it was ruled in:
A RESIDUAL REFUSAL DOES NOT PROTECT A CLASSIFIER WHOSE ACCEPTED BUCKET IS DEFINED
BY ABSENCE; A NEW KIND CAN SILENTLY RESEMBLE THE DEFAULT. ModuleItemResource
repairs the KNOWN collision and does not turn absence into a positive authority,
which is why the parser-carried item kind is required before anything is cut over
on this classifier rather than being an improvement to schedule later.

SEED MIRRORS REGENERATED ON THE MERGE, not hand-merged. Resolving the generated
conflicts to "ours" dropped main's authority-derived bytes and produced a stage0
crate whose root referenced modules that no longer existed there -- the four build
errors CI reported. The mirrors here are emitted from the merged authority. Two
rounds, as separate invocations with source roots on each: required-regen
first_generation_equal=true (155/155/155, main.rs declared divergent) then
required-regen-fixed-point fixed_point_equal=true. One round can report success
while the old content still stands.

AN OPEN INCOMPLETENESS, REPORTED RATHER THAN SWEPT, and the gate is what surfaced
it: over the merged corpus the join no longer closes. 202 grammar-owned type
declarations across 100 modules -- ArgvCommand, NozzleDiameter, BuildEnvelope and
others, all genuine type names in files main introduced -- are read as type
declarations by the emit-side reader and are NOT stamped. The census therefore
reports CensusUnavailable { DeclarationDomainDisagrees } and refuses to print a
partition, which is the behaviour it was built for. Which reader is right for
these shapes is NOT yet determined and is not guessed at here.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01KLXA6u6f3UK8PR5VEJoUwm

* Stop classifying sole-constructor types as resources, and file the class both polarities came from

THE RESOURCE ARM I ADDED TO FIX THE FIRST FAIL-OPEN CREATED THE SECOND ONE. It
keyed on `properties` being non-empty, and `type X sole_constructor { .. }`
carries a property too -- so 202 sole-constructor type declarations across 100
modules classified as RESOURCES and vanished from the declaration population.
Over-stamping resources as types, then under-stamping types as resources: same
classifier, opposite polarity, one root -- an absence-and-presence heuristic
standing where a positive kind belongs.

THE EXCLUSION IS COMPLETE BY ENUMERATION OF MINTING SITES, not by grep. Module
items have exactly two property sources in v1.compiler.parse:
parsed_sole_constructor_properties, which mints one field-init named
sole_constructor and is the only source every type-item constructor passes along
(four call sites); and parse_resource_entries. `nominal_opaque`, the other
authored type modifier, is dropped lexically by drop_leading_type_modifier and
mints nothing. mint_parsed_optional_int_property is confined to nested
where-predicate nodes and never reaches a module item's own properties. So the
modifier set mintable as a property on a type declaration is a CLOSED SET OF ONE.
A one-member set established by construction is worth more than a longer list
found by search -- and the annotation states what breaks it: a second modifier
that MINTS a property reintroduces this silently and in the same direction, which
no longer list can prevent.

MEASURED, corpus-wide over dag + src/v2 + src/v1 with
`type_occurrence_binding_census --establish`: modules_diverging 100 -> 1, absent
declarations 202 -> 2, zero extras, zero duplicates, zero index absences, zero
parse failures. Both remaining absences are in the one diverging module.

THE RESIDUE IS NOT THIS CLASSIFIER'S DEFECT AND IS FILED RATHER THAN REPAIRED.
`resource Network` and `resource AuthContext` declare no capabilities, so with no
children, body, params or connective they satisfy
v1.compiler.emit_core_support is_bare_leaf_item and the INDEPENDENT reader calls
them type declarations. That is the same class in a different authority;
repairing it there is a separate subject and is not smuggled into a parser change.

AND THE COUNTERMEASURE, which is the transferable part. Those two were invisible
while one classifier answered, because both readers AGREED they were types -- the
agreed-wrong pair a disagreement census cannot see by construction. Splitting the
question across two INDEPENDENTLY DERIVED readers converted their agreement into
a disagreement, which is the only form the census can report. Filed as
gunbc.recurring_failure_mode absence_classifier_default_bucket with both
polarities, both specimens, and the rule: WHERE A CENSUS COMPARES TWO READERS, A
THIRD INDEPENDENTLY-DERIVED READER IS THE ONLY THING THAT CAN FALSIFY THEIR
AGREEMENT.

Receipts: required-regen first_generation_equal=true 155/155/155 (main.rs
declared divergent); generated_artifact_gate main_wet for the ledger projection;
clippy --all-targets -D warnings clean; fmt clean.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01KLXA6u6f3UK8PR5VEJoUwm

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
cursor Bot pushed a commit that referenced this pull request Sep 7, 2026
… -> 28 errors

A field authored v2.std.text.String reached the Rust emitter as an overlay-less
resolved reference leaf and rendered the bare terminal name, which binds the
prelude String cross-module (#9813: kernel names are never overridden by
imports, so the use-line is dropped) while every value position renders the
structural carrier Rc<Vec<i64>> -- the v2_compiler_tokenize.rs E0308 family,
41 of 72 errors on the XL-N phase board.

The new rust_overlayless_alias_leaf_requires_peel arm in
render_rust_type_without_applied_binding detects the population (overlay-less
zero-parameter alias leaf, qualified spelling, String terminal segment,
closed_alias_peel_verdict agrees) and renders the alias declaration's resolved
right-hand side, projecting the same realization the fn-signature positions
already produce.

The qualified gate is load-bearing: inside the declaring module the bare name
is the correct render (the emitted module carries the alias declaration), and
the local binding's resolved_type drops the RHS type argument, so an ungated
peel rendered Rc<FreeMonoid> there (E0107 x13, E0282 x2 on the probe). Bare
String keeps denoting the kernel scalar through the host-carrier arm.

Measured: probe specimen (qualified/bare/direct-FreeMonoid/container/variant/
local-alias positions) compiles clean; XL-N compiler closure cargo check
72 -> 28 errors with the residual census dominated by the declared
text_boundary_identity_wall class (kernel String vs structural carrier at
bare-authored boundaries, 17 of 20 E0308s); v1-corpus fixed point holds
(first_generation_equal=true, 158/158 adjudicated).
cursor Bot pushed a commit that referenced this pull request Sep 7, 2026
Inference substitutes the resolved declaration into a data annotation's
type-argument position, so BooleanAlgebra<v2.std.logic.Bool> reaches the
emitter with the arg BEING the type Bool = True | False declaration itself
(Disj connective, ident_span in src/v2/std/logic.dag, no Resolved wrapper).
type_reference_provenance_in_env's bare-leaf arm re-resolved that leaf in the
REFERENCING module's scope, where post-#9813 a kernel-shadowed spelling
answers the kernel declaration -- so the structural enum rendered as host
bool against a value of BooleanAlgebra<Bool> (the python.rs:328 /
typescript.rs:177 E0308 pair on the XL-N compile-phase frontier).

The connective is the discriminator: a reference node is a bare name
(NoConnective); a node carrying Conj/Disj structure IS the declaration, and
type_reference_provenance's own-span fallback already answers that shape
correctly. The guard routes declaration-shaped nodes there directly, bypassing
the scope lookup that #9813 makes answer the kernel.

Mirror regenerated via the regen round; fixed-point verified
(claim_executor --required-regen PASS).
briansrls added a commit that referenced this pull request Sep 9, 2026
…0692)

* Land the add-slice per-stage verdict instrument named as the floor_expected_red note's producer

The add-slice roster note in v2.workflow.floor_expected_red carried a dated
receipt (main 3a8344b5c: infer accepts dag_add_emitted_root; the
infer-then-translate composition refuses headed by infer_grounding_not_derived)
and named its own next-rung trigger: a .dag entry returning the per-stage
verdicts for one root, so the paragraph can name a producer instead of a
commit.

v2.compiler.self_host.candidate_generation_stage_verdicts is that entry,
parameterized over root and target: the receipt's verdict vocabulary
(infer_accepted / infer_rejected; candidate_accepted or the rejection head
reason) plus the carried-reasons lists -- the half the verdict symbols cannot
say, namely that infer accepts while carrying the frontier diagnostic on its
accepted path, so the enrolled witness's d == None conjunct fails even where
the composition reaches acceptance.

v2.test.execution.self_host_candidate_generation_stage_verdicts binds the
instrument to the slice's own fixture, with add_slice_stage_verdicts_entry the
runnable gunbc run --function form (ExitSuccess only when infer accepts clean
and the composition accepts clean). Two witnesses: infer-accepts as a
permanent positive control, and the frontier-state pin that is expected to red
the day the add-slice stall's trigger lands, flipping to a permanent
regression control in the same change that removes the roster row (DESIGN
4b(4)).

Measured by execution on this branch: the entry exits 1 printing
infer=infer_accepted, infer_carried=[infer_grounding_not_derived x10],
composition=infer_grounding_not_derived, composition_carried=[x11] -- the
receipt reproduced, with bind_outcome's pending-plus-gate chain counted. Both
witnesses PASS; the enrolled semantic witness still fails as enrolled.

Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>

* Derive grounding for dag declared inhabitants: the add slice greens end-to-end

infer gains the declared-inhabitant membership derivation: a node declared in
the dag language authority's declared-inhabitants roster derives its grounding
by lookup, with the roster as evidence -- the namespacing answer to the atom
authority question, at specimen scope. The add slice's ten type-spine nodes
(Arrow, Conj, Atom) are all roster members, so:

- candidate_generation_translate_self_emit_dag_add_slice_holds passes; its
  floor_expected_red roster row and per-row note delete per the roster's own
  stale-quarantine arm
- the dag same-language ingest path compiles end-to-end: cross_language_compile
  accepts, byte-equal to the authority's own serialization, no carried
  diagnostics
- the add-slice stall narrows to its four python/typescript round-trip members;
  the original trigger's causal clause was refuted by execution and is restated
  against the grammar parse-product population
- the instrument's frontier guard flips to add_slice_composition_accepts_holds
  (DESIGN 4b(4): frontier guard to permanent regression control)
- five manual witnesses flip with it: two root flips rewritten to assert the
  green state, three transitive conjunctions updated

The kinds stay frontier: non-member Arrow/Conj/Atom specimens carry
GroundingNotDerived exactly as before, and all fourteen enrolled
refusal/acceptance controls pass unchanged. The door's production path still
reds inside rust emission, untouched by this rule.

Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>

* Derive grounding for canonical binding atoms: dag_binding_denotation joins binding to inhabitant once

The resolver already binds the surface spelling Int to the canonical binding
symbol dag_binding_type_int; what that binding DENOTES is the Int inhabitant
declared at dag_declared_inhabitants_core. Every hand-rolled fixture facts
lookup re-authored that join (dag_add_canonical_grounding_for,
record_construct_canonical_grounding_for). The language authority now declares
it once as dag_binding_denotation, and infer_node_facts consumes it: an Atom
whose identity is a canonical dag binding with a declared denotation derives
with that denotation as its grounding evidence.

Direct-rust-door specimen census: 14 underived -> 10 underived (the four
dag_binding_type_int atoms derive; grammar-production atoms, algebra atoms,
bare operand atoms, and the arrow/conj spine stay on the frontier unchanged).

Specimen-scope interim in the same frame as
infer_node_declared_in_dag_inhabitants: both delete in favor of consuming
resolution output when the resolver hands infer declaration-resolved
identities directly (the namespace migration's completed state).

Witness: v2.test.execution.dag_binding_denotation — all four Int binding
atoms in the door specimen derive with dag_int_inhabitant_node() as
structural evidence, and the two bare operand atoms stay GroundingNotDerived
(boundary control). Refusal suite 14/14, ingest bridge 7/7, add-slice
instruments 2/2 green; every remaining red in the at-risk population
reproduces identically on the pre-change tree and is enrolled in
floor_expected_red.

Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>

* Add v2 self-host direct-path orientation: axes, sequence, autonomy contract

A point-in-time orientation that defers to the existing authorities
(DESIGN section 7, the four-wave self-host program, the roadmap node
chain, the three frontier carriers, the guarantee-stall roster, XL-N)
rather than restating them: state is re-derived by the named
instruments, never transcribed here. Sequences the remaining work in
roadmap order (door, parse-product grounding, first behavioral module,
XL-N milestones, native bootstrap, fixed point, v1 deletion) and states
which decisions stay operator-gated.

Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>

* Derive grounding for fully-evidenced Conj and Arrow products

The sixth and seventh kind rules: a non-roster Conj or Arrow whose every
child carries DerivedGrounding derives, its evidence the same shape
re-formed over the children's grounding evidence (a fresh
OccurrenceSynthetic node, never the source — the self-evidence wall holds
by construction). A product with any frontier or absent child stays on the
frontier with its typed diagnostic; a childless product has no evidence to
compose and stays frontier. Roster members keep their roster evidence.

Measured on the direct-rust-door specimen (scratch probe, uncommitted):
10 underived of 15 -> 6. The parameter conj, the module-structure conjs,
and the bodied add arrow derive; what remains is the algebra atoms from
the + operation (AlgebraPrimitive, ring_field_add), the module atom
(dag_surface_module), the parameter references (x, y), and the
grammar-projection root conj that cascades once they land.

Enrolled witnesses (src/v2/test/claim/execution/infer_product_introduction_test.dag):
- product_introduction_derives_fully_evidenced_products_holds — census:
  4 Conj (3 derived, 1 frontier-by-frontier-child) + 1 Arrow (derived).
- product_introduction_composed_evidence_carries_child_groundings_holds —
  the params conj's evidence is a Conj whose x/y children target the dag
  authority's Int inhabitant.
- product_introduction_leaves_childless_conj_on_the_frontier_holds —
  boundary control via direct infer over a hand-built childless Conj.

Flip census (pre- and post-change, zero unexpected flips):
translate_underived_refusal 14/14, infer_self_grounding_wall 12/12,
branch_infer_if_then_else 2/2, compile_eval_thesis_proof 6/6,
ingest_bridge 9/9, cross_language_add_python_to_typescript 4/4,
inhabitant_neutralization 6/6 + e2e 6/6, emit_host_classical_not 14/14,
dag_binding_denotation 2/2, stage-verdicts instrument 2/2,
dag_add_emit_round_trip 4/6 (the 2 enrolled reds unchanged), door
production group still enrolled-red (unchanged).

Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>

* Ground canonical-operation and grammar-production atoms by authority roster membership

Two more specimen-scope derivations in infer_node_facts, both lookups into
declared authorities, never inventions:

- Canonical-operations roster (target_model.dag): every CanonicalOperation
  the target-model authority declares, rendered by
  target_model_canonical_operation_wire_node and gathered under one Conj
  root. The resolver canonicalizes surface operators (e.g. +) to those
  declared operations, so the wire atoms -- the operation discriminant and
  its field references -- derive by membership with the roster root as
  evidence. General over all 14 declared operations, not add-narrow.

- Grammar-productions roster (dag.dag): every production in
  dag_grammar_root() projected to its emitted surface atom under one Conj
  root keyed by production name. The bridge projects a production's parse
  into (identity atom, captured content) pairs, so the identity atom
  (dag_surface_module) derives by membership with the roster root as
  evidence. The roster derives from the grammar root, so a production
  added to the grammar joins by construction.

Both roster roots are Conj nodes, never structurally equal to any member
atom, so the self-evidence wall holds by construction (the first attempt
at the operations rule used the wire node itself as evidence and was
refused by grounding_evidence_is_source -- the wall doing its work).

Measured on the direct-rust-door specimen (scratch probe, uncommitted):
6 underived of 15 -> 2 (only the operand atoms x and y remain; the
grammar-projection root conj cascades once the module atom grounds).

Enrolled witnesses (infer_atom_grounding_rules_test.dag): each roster rule
pins derivation + evidence identity + census; a boundary control pins that
a bare atom with no authority membership stays frontier; the closing
control pins the 2-of-15 state.

Flip census: the product-introduction census witness updates 3->4 derived
conjs (the top conj now cascades) and gains a hand-built
partially-evidenced boundary control to replace the in-specimen one the
cascade consumed. Full battery otherwise unchanged: refusal suite 14/14,
grounding wall 12/12, instrument 2/2, binding-denotation 2/2, round-trips,
bridge, cross-language, neutralization, emit-host all green; enrolled reds
unchanged.

Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>

* Ground binding-reference atoms from the enclosing arrow's domain declaration

The fifth specimen-scope derivation, closing the direct-rust-door
specimen's inference frontier: an Atom whose binding an enclosing arrow's
domain declares derives with the declared domain type as its evidence --
the declaration-site annotation, itself derived (x: Int grounds the x
reference). This is the same lookup the branch-operand path already
performs (infer_find_arrow_domain_type_in_tree), now written to the
operand atom's own facts; it is scope-naive (whole-tree, first match),
recorded in the frontier note, and deletes with the other specimen-scope
rules when the resolver hands infer declaration-resolved identities. The
tree is threaded through the fold's init chain to reach infer_node_facts;
the helper had exactly one caller.

Measured on the door specimen (scratch probe, uncommitted): 2 underived
of 15 -> 0. The specimen's inference frontier is fully closed, and the
production observation advances from InferenceRejected
(infer_grounding_not_derived) to EmissionRejected
(target_use_site_ownership_lookup_miss) -- a new, typed, located deficit
in the emitter, the next gate on the path.

Flip census (all three rewrites verified by execution):
- dag_binding_denotation_leaves_unbound_operand_atoms_on_the_frontier_holds
  -> dag_binding_denotation_declares_no_denotation_for_operand_bindings_holds:
  the boundary moves to the authority itself (the denotation table returns
  Absent for x/y), true regardless of infer's other rules.
- The three emit_host classical-not refusal guards (canonical, staging,
  staging-swapped) flip to acceptance witnesses pinning the emitted text's
  shape -- the real-infer tree now fully derives, and the emission is the
  same one the equals-eval witness proves behaviorally correct. The
  translate-refuses-underived behavior stays enrolled on hand-staged
  fixtures in translate_underived_refusal_test.dag (14/14 green). The
  renames are carried into the commit_workflow and witness_deferral_freeze
  rosters.
- New witnesses: binding_reference_derives_parameter_atoms_holds (evidence
  is the domain's Int binding atom, census 2) and
  door_specimen_fully_derives_holds (0 frontier of 15).

Full battery at this state: refusal suite 14/14, grounding wall 12/12,
instrument 2/2, binding-denotation 2/2, product-introduction 4/4,
atom-rules 5/5, emit_host 14/14, round-trips 4/6 (2 enrolled reds
unchanged), bridge 9/9, cross-language 4/4, neutralization 6/6 + e2e 6/6,
branch 2/2, eval-thesis 6/6; door production group still enrolled-red
(unchanged).

Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>

* Green the direct-rust-door: route emission through produced-decl composition and decode canonical operator wires

The door specimen's inference frontier is fully closed, so its production
observation now reaches the emission stage. Two defects surfaced there, both
fixed here:

Emission composition. generate_rust_emission_candidate served two lanes with
one root shape: the door's production path (a dag module shell) and a fixture
lane (a bare rust Arrow). The translate ownership gate queried the module
atom's ownership at a struct-field use site and refused with
target_use_site_ownership_lookup_miss, because the module's grammar-projection
conj was misread as a type record. The door's real composition is the
produced-decl path: collect declaration conjuncts from the inferred tree and
emit via emit_produced_decl. A new generate_rust_module_emission_candidate does
exactly that, enforcing an exactly-one-declaration admission policy
(rust_module_emission_decl_absent / _ambiguous). The observation and production
mint paths switch to it; the fixture-lane candidate is retained with a note
that it is fixture-only. A pure collector, produced_decl_conjs_in_tree, finds
nodes of produced-decl shape (a Conj whose first child is a Named edge to an
Arrow). Its decl-head match routes through a declared FreeMonoid<Edge>
parameter because the v1 seed stamps pattern variables from a declared
parameter type, not from a field-access scrutinee.

Operator decode. With composition fixed, source fidelity still refused: the
door emitted fn add(x: i32, y: i32) -> i32 { AlgebraPrimitive(x, y) } instead
of { x + y }. Resolution canonicalizes a surface operator atom into a
canonical-operation wire node, so a production tree's transform operator
position carries the wire, while fixture trees that bypass resolution still
carry the surface token atom. translate_project_transform_in_arrow_scope only
knew the surface-token table, so the wire missed and fell to callable apply,
rendering the discriminant identity. The projection now tries the wire decode
first (canonical_operation_from_wire_node) and only on a wire miss falls to
the surface-token table, then to callable apply; the arms are disjoint, so the
dispatch adds no fallback widening. target_transform_operator_child extracts
the operator child safely.

The door's closing expectation now greens by execution, so its known_red_probe
row in explicit_witness_admission is deleted per its own dissolution condition,
and the roadmap authority note, the door contract note, and the direct-path
plan are updated to record the green state. realized_closure_for_v2_direct_
rust_door_emit_run's module list reflects the produced-decl route.

Verified by execution: the door witness greens; the fixture, containment,
algebra, produced-decl, add-slice, and classical-not witnesses stay green;
claim_executor required-ci lanes build and witnesses both exit 0; cargo fmt and
clippy --all-targets -D warnings are clean. One pre-existing red,
witness_projection_is_active_only in the floor_cost_debt containment roster,
reproduces on the base revision and is unrelated to this change.

Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>

* Close the parse-product grounding frontier: widen declared-inhabitant membership to the closed ingest set

The declared-inhabitant roster-membership derivation in 04_infer generalized
from the dag roster to the closed ingest set (dag, python, typescript):
infer_node_declared_in_language_inhabitants returns the declaring authority's
roster root as evidence, with deep subtree membership so a declared
inhabitant's leaf fact atoms derive exactly as the inhabitant node itself.

Measured: the python fixture's 19-node frontier and the typescript fixture's
28-node frontier both close to zero; all four add-slice stall population
round-trip witnesses green; the python->typescript cross-language compile
accepts, byte-identical to ts_source_text.

Section 4b(4) flips (expecting-red probes becoming permanent regression
controls for the acceptances):
- cross_language_compile_refuses_canonical_underived_holds ->
  cross_language_compile_python_to_typescript_round_trip_holds
- inhabitant_neutralization_emit_after_neutralize / same_flavor_python /
  go_int64_to_ts refusal helpers -> round-trip controls
- inhabitant_neutralization_python_to_ts_cross_language_compile (e2e) ->
  round-trip control; python->go members stay refusal guards (go is outside
  the closed ingest set)
- cross_language_emit_inhabitant_neutralization_refuses_underived_holds ->
  round-trip control; the python->typescript emit-matrix row reads ChainProven

The add-slice stall's next-rung trigger fired, so it retired per DESIGN
4b(4): removed from all_guarantee_stalls, row file deleted, witnesses stay
enrolled.

Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>

* Promote the add family to SelfEmittedNative: native-only verdict witness for the emitted add crate

First InterpreterRetained -> SelfEmittedNative promotion after classical_not,
executing the v2-emitter-first-behavioral-module first slice at the
coverage-frontier grain: the add family (fewest dependencies — integer
literals plus one canonical operation) now carries a native-only verdict
witness, so its behavior is established by the emitted crate's own stdout
with eval() unreachable from the verdict path.

- emit_host_native_only_add_holds: real emit -> cargo build -> native run,
  stdout pinned to the family's expected octet, sharing the kernel family's
  one-build cache key exactly as the classical_not arm shares its family's
  key (no duplicated cold build).
- emit_host_native_only_add_wrong_octet_mismatch_detected_holds: the broken
  control — a no-eval verdict has no oracle leg to break, so the expectation
  side breaks (an octet the run never produces must not match); program-side
  discrimination stays with the family's equals_eval primitive-five/six pair.
- The add coverage row flips disposition with its backing citation enrolled
  by construction (the verdict entry is file-grain enrolled in
  falsifier_self_host_wet_template_entries).
- Frontier census tests updated at identity grain: natives are exactly
  {classical_not, add}; split 2/13.

Verified by execution: all six native-only verdict tests green locally
(real wet legs — compile_skipped receipts show cold builds and native runs);
all eight emit_coverage_frontier tests green, including the unbacked-claim
RED control.

Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>

* Record the add-slice defect's repair in the declined-live-tree classification

The row classified candidate_generation_translate_self_emit_dag_add_slice_holds
as RealDefect/CompilerBehaviourRefusal with measured evidence that translate
refuses infer_grounding_not_derived. The owner lane (v2 self-host) repaired the
subject: the declared-inhabitant roster-membership derivation grounds the
slice's type spine by lookup, and the witness passes under claim_batch
--hermetic on the merged tree. The dated classification is kept verbatim; the
disposition flips RoutedToOwner -> RepairedInThisChange with the repair
measurement appended to the evidence, so the routing carrier stops dispatching
a fixed defect. Structural witnesses (count 13, no NotReproduced, exact
partition) are untouched and pass.

* Hoist two in-body annotation blocks to module-item grain

Main's annotation-placement wall (source annotations admit only standalone
leading blocks attached to module-scope declarations; in-body forms refuse)
reached this branch through the merge and refused 8 blocking errors on the
00_compile closure: the add-family promotion note inside the
emit_coverage_frontier_roster list and the python->typescript row note inside
the cross_language_emit_matrix list. Both blocks move above their enclosing
declarations, rephrased to name their subject row. Measured: gunbc compile of
src/v2/compiler/00_compile.dag now emits 172 files with 0 blocking errors;
both files' suites stay green (8/8 and 4/4).

* Promote the complement family to SelfEmittedNative: native-only verdict witness for the emitted logic family crate

The complement family's native execution runs family-grain per the
witness_family_build_grain_ruling (one crate for meet + join + complement,
argv-dispatched), so the native-only arm emits the logic family crate and
runs the complement member through the family dispatcher, sharing the
family witness's one-build cache key. The verdict is decided solely by the
emitted native run's stdout (expected octet 0, complement(True) = False);
the broken control flips the expectation side (octet 1 can never match),
with the comparator pinned by the stdout mock pair. Program-side
discrimination stays with the equals_eval agreement pair and the family
witness's all-alt leg.

The frontier row's backing citation lands in the already
file-grain-enrolled native-only verdict entry, so it is enrolled by
construction; the roster comment is rephrased to cover both 2026-09-07
promotions (add and complement). The frontier test's split and native
membership assertions move to 3 native / 12 retained.

Verified by execution: claim_batch --hermetic on
emit_host_native_only_verdict_test.dag passes all 8 witnesses (the two
new complement arms included), and emit_coverage_frontier_test.dag
passes all 8.

* Key the emitter's host-String arm on declaration provenance, not spelling

is_host_text_carrier_type answered true for any type expression whose
authored name reads "String", including references to the structural
alias v2.std.text.String (type String = FreeMonoid<Char>) that the
namespace lane (gunbc#9907) requalified the v2 corpus's text-carrier
fields to. The emitter rendered every one of those references as the
host String while value-position consumers rendered the structure -- the
E0308 family dominating the self-host compile-phase frontier (41 of 64
in v2_compiler_tokenize.rs on the post-merge board).

The String arm now consults the resolved declaration's provenance
against v1.compiler.coercion structural_declaration_modules_for -- the
same roster type_realization_decision reads -- so the legacy arm and the
strict decision cannot diverge on one node (DESIGN section 3, and
gunbc.recurring_failure_mode alias_resolution_collides_with_kernel_spelling).
Kernel mints and unresolved references keep the host answer exactly as
before.

Regen: the only drifted stage0 mirror is v1_compiler_emit_rust.rs
itself (no module in the stage0 closure references a structurally
declared String -- verified by the whole-population candidate tree),
installed from target/stage0-regen-candidate after the priced round's
partitioned rebuild refused MirrorHasNoOwningPackage on the emitter
(the emitter is monolith-shell, not partition-owned). Fixed point
verified by execution: claim_executor --required-regen on the rebuilt
seed reports first_generation_equal=true over 158 adjudicated mirrors.

* Peel qualified String alias leaves in field position: XL-N closure 72 -> 28 errors

A field authored v2.std.text.String reached the Rust emitter as an overlay-less
resolved reference leaf and rendered the bare terminal name, which binds the
prelude String cross-module (#9813: kernel names are never overridden by
imports, so the use-line is dropped) while every value position renders the
structural carrier Rc<Vec<i64>> -- the v2_compiler_tokenize.rs E0308 family,
41 of 72 errors on the XL-N phase board.

The new rust_overlayless_alias_leaf_requires_peel arm in
render_rust_type_without_applied_binding detects the population (overlay-less
zero-parameter alias leaf, qualified spelling, String terminal segment,
closed_alias_peel_verdict agrees) and renders the alias declaration's resolved
right-hand side, projecting the same realization the fn-signature positions
already produce.

The qualified gate is load-bearing: inside the declaring module the bare name
is the correct render (the emitted module carries the alias declaration), and
the local binding's resolved_type drops the RHS type argument, so an ungated
peel rendered Rc<FreeMonoid> there (E0107 x13, E0282 x2 on the probe). Bare
String keeps denoting the kernel scalar through the host-carrier arm.

Measured: probe specimen (qualified/bare/direct-FreeMonoid/container/variant/
local-alias positions) compiles clean; XL-N compiler closure cargo check
72 -> 28 errors with the residual census dominated by the declared
text_boundary_identity_wall class (kernel String vs structural carrier at
bare-authored boundaries, 17 of 20 E0308s); v1-corpus fixed point holds
(first_generation_equal=true, 158/158 adjudicated).

* Resolve the 12 non-hop XL-N closure errors at source: text-wall conversions + witness_violates helper

Four clusters, all measured non-hop additions between receipt_1 (155) and the
post-peel census (28); the live gate now measures 15 with zero unadmitted
regressions:

- integer.dag: integer_string_to_decimal_digits_step takes v2.std.text.String;
  the public boundary converts with chars() (text_boundary_identity_wall
  specimen discharged at this site).
- 01_tokenize.dag: Token/UnboundSourceAnnotation lexemes convert structural
  -> host String with chars_to_string() at construction, mirroring the v1
  tokenizer's host-lexeme carrier.
- target_model.dag + bash.dag: EmitSpellingEscape.from/to and
  apply_emit_spelling_escapes go structural (v2.std.text.String); the
  EmitSpellingQuote arm converts host->structural->host at its boundary;
  bash's escape rows wrap their kernel String literals with chars().
- witness.dag + 3 call sites (collection list_nth, provenance
  span_index_resolve_textual_locus_from_ids, compile outcome_with_diagnostics):
  new witness_violates<C> helper puts Violates constructions in a
  Witness-headed position so the emitter resolves the carrier type argument;
  dissolves once inference records per-call substitutions.

Verified: 48 targeted claim witnesses green (tokenize behavioral, shell
conformance, string brace escape, string length, map-lookup violates, source
text ingress, bash materialize x12, int literal smoke x6, provenance span
index x2).

* Record receipt_2 on the self-host compile-phase frontier: 15-error census at 66765317ec

The census at the XL-N lane tip: 155 -> 15 net, credited to the qualified-alias
peel (60cbd7b697, 72 -> 28) and the twelve-error source cluster (66765317ec,
28 -> 15). The epoch changes on the instrument's target pinning (found by
review on gunbc#9857), admitted with receipt_1's board as the reclassified
predecessor under the identity map. Nine added identities are hop relocations
admitted by the hop index; four sit in python/typescript modules newly entered
into the emitted closure, admitted as ExposedByNewEmittedModule.

Validated: all 36 self_host_compile_phase_frontier_witness claims PASS,
including current_persisted_compile_phase_frontier_holds.

* Emitter: a substituted declaration node carries its own provenance

Inference substitutes the resolved declaration into a data annotation's
type-argument position, so BooleanAlgebra<v2.std.logic.Bool> reaches the
emitter with the arg BEING the type Bool = True | False declaration itself
(Disj connective, ident_span in src/v2/std/logic.dag, no Resolved wrapper).
type_reference_provenance_in_env's bare-leaf arm re-resolved that leaf in the
REFERENCING module's scope, where post-#9813 a kernel-shadowed spelling
answers the kernel declaration -- so the structural enum rendered as host
bool against a value of BooleanAlgebra<Bool> (the python.rs:328 /
typescript.rs:177 E0308 pair on the XL-N compile-phase frontier).

The connective is the discriminator: a reference node is a bare name
(NoConnective); a node carrying Conj/Disj structure IS the declaration, and
type_reference_provenance's own-span fallback already answers that shape
correctly. The guard routes declaration-shaped nodes there directly, bypassing
the scope lookup that #9813 makes answer the kernel.

Mirror regenerated via the regen round; fixed-point verified
(claim_executor --required-regen PASS).

* Clear the remaining XL-N closure errors at source: carrier conversions at the boundaries

The receipt_2 census's fifteen identities, resolved at their sources:

- lexing.dag, dag.dag, python.dag, typescript.dag: LexPattern.text is the
  structural carrier (v2.std.text.String); the construction sites held host
  Strings. Convert at construction with chars() -- the #9907 ingress pattern.
- python.dag / typescript.dag bool groundings: qualify the annotation as
  BooleanAlgebra<v2.std.logic.Bool>; with the emitter's substituted-
  declaration provenance guard the qualified arg now renders structural.
- target_model.dag: target_lex_rule_literal_step returns the host carrier
  (chars_to_string over the structural pattern text); TargetText.source
  converts at the is_empty boundary; the unicode-scalar symbol intern converts
  its single-codepoint list to the host carrier.
- qualified_name.dag: qualified_name_from_dotted_string uses the host-carrier
  emptiness check (string_length == 0) instead of routing through the
  structural string_is_empty.
- 02_parse.dag: parse_looks_like_match_arm_start rewritten on host-carrier
  operations (string_length, char_at, code_point) rather than converting to
  the structural carrier for a two-character lookahead;
  parse_char_is_arm_pattern_lead takes the codepoint Int directly.
- v1_interpreter_primitive_surface.dag row_key: the concat pipeline lowered
  to a .concat() method call on std::string::String (E0599); rewritten as
  nested concat calls.

Measured: the 00_compile closure emits 172 files and cargo check reports
cargo_clean=true, cargo_error_population=0 under the pinned 1.93.0 toolchain.

* Pin the cargo half's toolchain channel by construction

The cargo half runs with cwd = a fresh mktemp directory; with no
rust-toolchain.toml there, rustup resolves the host's DEFAULT toolchain, so a
census under cargo 1.83 and one under cargo 1.93 would compare as equal epochs
while different compilers did the measuring -- the fabricated comparability
the target pin (gunbc#9857) excludes, one level up. Measured 2026-09-07: a
host default of 1.83.0 met a crates.io index whose freshly published
dependency manifests require edition2024, resolution failed before any
diagnostic existed, and the zero-diagnostic refusal fired on an unmeasured
tree.

The pin is propagated by copying the repo's rust-toolchain.toml into out_dir:
the file remains the sole in-repo channel authority (its header forbids a
second pinned literal), and the copy makes the measured channel true by
construction on any host. The gate's read_live_toolchain observes the same
channel because every documented actuator invokes from the repository root,
which the same file governs.

* Record receipt_3 on the self-host compile-phase frontier: the emitted closure's cargo census is empty

Measured at 5ee4892b70 by the one-entry instrument: the 172-file emitted crate
reports zero cargo error diagnostics, so the board attributes every phase a
count of zero and furthest_phase_reached stands at Borrowck. The fifteen
removals against receipt_2 need no disposition; nothing was added.

The epoch does not change: the cargo half now pins the toolchain channel by
copying the repo's rust-toolchain.toml into the scratch crate, and every
recorded comparison field is identical to receipt_2 (whose census the
fingerprint evidence shows the same 1.93.0 toolchain already compiled), so the
same-epoch arm carries no reclassified predecessor.

The frontier-state pin flips per DESIGN 4b(4):
the_published_frontier_standing_does_not_claim_typeck_or_borrowck_passed
becomes the_published_frontier_standing_claims_typeck_and_borrowck_passed, the
permanent regression control over the green state.

Validated: all 36 self_host_compile_phase_frontier_witness claims PASS,
including current_persisted_compile_phase_frontier_holds.

* chore: regenerate drifted generated artifacts (ci auto-heal)

Ledger-Repair-Judged: docs/design-failure-modes.md
Ledger-Repair-Judged: docs/design-rung-drops.md

* Remove the stale PointwisePower inhabitant rows from the four language rosters

First native-parity divergence class found by running the emitted closure on a
discriminating fixture: the algebra inhabitant rosters still carried
PointwisePower after its authority row was cut, so the emitted compiler panicked
at 12 record-shaped carrier sites while the interpreted seed refused cleanly.
The roster rows are removed in rust/python/go/typescript types.dag, the derived
coercion assertions in compiler_tests.rs regenerate without them, and two
witnesses pin the boundary: the record shape constructs its structural carrier,
and FinitePowerSet still refuses while its row stands.

Mirrors regenerated by a converged regen round (fixed point Reached, stage-1
PromoteGenerationInputs over the three language types mirrors).

* Regen gen-2 gate: compare executable digests in one spelling

The admitted side of run_built_seed_regen carries the executable-digest
spelling (current_exe_digest, next_pass_executable_digest) while the observed
side hashed the file through path_digest, which prepends the fnv1a64: tag.
Same bytes, two spellings, so the gate could never pass -- unpassable since
fa2d403dc8 (#9771). Factor current_exe_on_disk as the single path authority
and read the observed digest through current_exe_digest so both sides spell
the same bytes the same way.

* Model ReleaseScopeEmpty for release-excluded mirrors, end to end

A regen round whose only stage-2 drift was compiler_tests.rs (the PointwisePower
roster removal rewrote its derived coercion assertions) refused the rebuild
MirrorHasNoOwningPackage: the mirror is owned by no partition package, because
every item it defines is #[cfg(test)] and no release unit elaborates it. The
refusal conflated two different states -- unowned (a coverage hole) and excluded
from the release build by construction (a precise empty scope).

The model now names the class: rebuild_scope_release_excluded_mirrors rosters
its members (compiler_tests.rs, cited to emit_compiler_tests_module), the
decision answers ReleaseScopeEmpty when the whole change set is excluded, and
the actuation shape is actuatable with an empty package closure and every
partition package excluded -- the build still runs as verification, and a
compiled partition package refuses the stage. The host admits the empty closure
only when the new stage0_partition_rebuild_release_scope_empty_today query
answers true; any other empty closure still refuses. A mixed change set scopes
on its release-visible members alone.

Verified by execution: the 2026-09-08 round converged (fixed point Reached)
with stage-2 installing compiler_tests.rs alone; cargo recompiled the shell
crate on its fingerprint (the outer mod line is ungated, so rustc reads the
file) while the produced executable was byte-identical -- stage input seed
digest == output seed digest. Four new witnesses pin the arm, its actuation
shape, the mixed set, and the host-facing query's two arms; the boundary
witness (unowned cli_run.rs still refuses) keeps the roster from decaying into
the absorbing fallback.

* Round-cost receipt: project installed mirrors to the model's vocabulary

The receipt's partition-rebuild line is rendered by the model over
receipt.installed_mirrors, which the host populated from the stages'
projected_paths -- full paths -- while the partition rows and rosters key on
basenames. Every drifted round's receipt therefore rendered a spurious
RebuildScopeRefused MirrorHasNoOwningPackage line naming a full path, a false
claim on the round's own receipt. Route the projection through
emit_path_basename, the module's single path-to-basename bridge, so the field
carries the mirror names the model's vocabulary means.

* Hoist ReleaseScopeEmpty annotations to module-item grain

The ReleaseScopeEmpty modeling commit placed three // blocks inside
declaration bodies (stage0_partition_rebuild_is_actuatable,
stage0_partition_rebuild_decision, stage0_partition_rebuild_excluded_today).
The .dag realization admits annotations at module-item grain only, so the
floor lane's parse phase refused the file with 12 located errors and the
run ended floor refused. The prose is unchanged; each block now sits above
the declaration it describes.

* Spell the PointwisePower witness's finite-set exclusion as the applied realization

The witness added with the fossil-row removal excluded the bare spelling
"BTreeSet", but every emitted file's preamble imports OrdSet as BTreeSet,
so the row could never green. The exclusion's subject is the finite-set
REALIZATION the fossil row would have asserted; spell it applied
(BTreeSet<i64), which the preamble's import line does not contain.

* Emit fieldless-record data values as null for the unit-struct carrier

The second native-parity divergence class, measured 2026-09-08 on the
native run of the emitted 00_compile closure: emit_data_value_json spelled
EVERY record literal as a JSON map, including the zero-field record, while
emit_struct_from_children renders that same declaration as a Rust unit
struct (pub struct BoolEncodingFact;). serde's derived unit-struct
Deserialize reads null and rejects {}, so the emitted compiler panicked at
first touch of v2.std.logic's bool_primitive_facts: "invalid type: map,
expected unit struct BoolEncodingFact". The JSON spelling of a data value
must deserialize into the Rust type the same declaration emitted; the
record arm now spells the zero-field value null and keeps the map spelling
for non-empty records.

The mirror is taken from the required-regen candidate, not hand-edited.
Two witnesses enroll: the discriminating red (zero-field record spells
null, never {}) and the boundary control (a record with fields keeps the
map spelling).

* Bind the duplicate-definition filter ahead of its branch condition

Main's FilterInBranchCondition wall (#10699) refuses to publish a module
whose filter call sits in a branch condition, and the v2 00_compile closure
emission names primitive_duplicate_semantic_definition_violation as such a
site. The filter is pure and total; binding it with a let ahead of the
branch is the authored remediation the wall exists to force, and the
emitted closure is unchanged in behavior.

* chore: regenerate drifted generated artifacts (ci auto-heal)

Ledger-Repair-Judged: docs/design-rung-drops.md
Ledger-Rows-Repaired: docs/design-rung-drops.md rust_unit_tests_off_the_merge_path
Ledger-Rows-Repaired: docs/design-rung-drops.md determinism_transitive_reachability
Ledger-Rows-Repaired: docs/design-rung-drops.md transitional_admission_exception

* Emitter: three native-parity repairs for the post-merge 00_compile closure build

Three divergence classes measured as the 21 rustc errors on the natively
emitted 00_compile closure after the main merge, each repaired at the .dag
source with a discriminating witness:

- Locality wins over a foreign ambiguity (12 E0433 in v2_std_integer.rs):
  alias_rhs_base_module_filename asked the global leaf index, saw
  LeafAmbiguous for Compose, and emitted the poison marker even inside
  v2.std.integer itself, where source resolution binds the local
  declaration before any cross-module lookup. The local physical
  declaration now shadows foreign declarers; the poison marker still
  stands for a leaf two FOREIGN modules declare.
- The qualifier is the disambiguator (8 E0425/E0433 in
  v2_lens_fact_density.rs): the qualified use-line route declined any
  globally-ambiguous leaf, but a qualified reference names its provider
  in its own spelling. The route now resolves by DeclaredCallableIdentity
  at the qualifier, keeping the type-declared and export-proof walls.
  The dotted spelling reaches the route through the value surface (a
  qualified value projection's borrowed type stamps the match patterns'
  parent_enum); the witness reproduces that chain exactly, and its
  exclude half pins the E0603 boundary (the dotted VARIANT head must
  still be declined).
- Clone-bound forwarding is transitive (1 E0277 in
  std_realization_measurement.rs): the call-forwarding derivation
  re-derived only each callee's SELF-derived half, so a callee whose
  bound is itself forwarded re-derived to empty. The derivation now
  recurses over the call graph with the module's visited-set
  termination; the equality half stays one-hop as declared.

Witnesses: 56/56 PASS on the rebuilt seed; regen fixed point holds.

* Refuse variant record literals on the serde_json data path fail-closed

A record literal with parent_enum present is a variant construction whose
wire spelling is the parent coproduct's declared VariantEncoding policy --
a module-local fact of the parent's home module that emit_data_value_json
does not carry. The zero-field arm's null and the map arm's untagged fields
are both measured to fail serde deserialization under the internal-tag
default, so the arm now refuses and the caller renders compile_error!, a
build-time located refusal where a runtime panic on the data definition's
expect was the latent alternative. The refusal names its trigger: a
closure-wide wire-policy index beside EmitGraphInfo.type_decl_items.

Witness: w_variant_record_lit_on_the_json_data_path_refuses_fail_closed
forces the JSON path with a nested-record Holder and asserts the
compile_error! spelling while excluding the former null mis-serialization.

* Spell variant record literals on the serde_json data path from a closure-wide wire-policy index

The fail-closed refusal landed in 73b582dea6 fired on 5 real corpus sites
(SugarKey x2, CopiedPortCitationFrontierDisposition x3), proving variant
record literals reach the JSON data path in the 00_compile closure. This
change replaces the refusal with the correct spelling, driven by a new
closure-wide index:

- v1.compiler.infer_emit_info gains DataVariantWireSpelling, the
  language-general projection of a coproduct's Rust wire serde policy
  for one variant (InternalTagged { tag_field, tag } | BareString { tag }
  | Untagged | SpellingRefused { reason }), and EmitGraphInfo carries
  data_variant_wire_spellings: Map<String, DataVariantWireSpelling>
  keyed by coproduct.variant.
- v1.compiler.emit_rust builds the index once per emission root via
  build_data_variant_wire_spellings, resolving each coproduct's policy
  through the new shared resolve_emission_coproduct_wire_policy (the
  same function the type-emission side now calls, so the two cannot
  drift), projecting each variant through data_path_wire_variant_tag
  (rename_all and StripAffix aware), and poisoning collisions as
  SpellingRefused so ambiguity stays fail-closed.
- v1.compiler.emit's emit_data_value_json variant arm reads the index:
  internal-tagged spells {"_variant": tag, ...fields}, bare-string
  spells "tag" for nullary and refuses fielded, untagged spells the
  bare fields or null; unindexed keys and stored refusals remain
  compile-time errors. The service mock-property chain threads
  emit_info through so dry-run data spells identically.

Witnesses: w_variant_record_lit_on_the_json_data_path_refuses_fail_closed
is rewritten as ..._spells_the_internal_tag (asserts the internal-tag
map, excludes the former null mis-serialization and the refusal), and
w_fielded_variant_record_lit_on_the_json_data_path_spells_tag_and_fields
pins the fielded case. 57/57 witnesses pass; regen fixed-point holds.

* Promote field_access to SelfEmittedNative on the emit coverage frontier

Fourth native-eval construct promotion, after classical_not, add, and
complement. The native-only verdict arm pair lands in the already
file-grain-enrolled long/ entry, so the backing citation is enrolled by
construction:

- emit_host_native_only_field_access_holds pins the family one-build
  cache run's stdout to octet 9 (the byte the family witness's warm leg
  pins on the same build), eval() never called.
- emit_host_native_only_field_access_wrong_octet_mismatch_detected_holds
  breaks the expectation side with octet 1, the alt tree's byte.

Both arms verified wet locally (real cargo build + native run, sharing
the field_access family one-build cache key). The roster row flips to
SelfEmittedNative; the two census guards update per 4b(4) — the split
moves to 4 native / 11 retained and the identity-grain membership guard
is renamed to name the four-member population. The family's equals_eval
agreement pair stays enrolled as its program-side discrimination leg.

* Drop the scratch parity probe from the tree

The probe is a manual parity-loop instrument (the interpreted leg of the
native-vs-interpreted comparison), not a corpus declaration with an
executing consumer (DESIGN 6 experimental residue). It stays in use
locally as an untracked file.

* Promote match, loop, and fold_closure to SelfEmittedNative

Fifth, sixth, and seventh native-eval construct promotions. The three
match_loop_fold family rows flip together on one shared family-crate
arm shape, per the witness_family_build_grain_ruling: each arm emits
the three-member family crate once and runs its own member through the
argv dispatcher against the family one-build cache key.

- emit_host_native_only_{match,loop,fold_closure}_holds pin the warm
  legs' stdout to the family's declared octet lists (match/loop
  [0,1,0,0,0], fold [0,7,0,0,0]), eval() never called.
- The wrong-octet controls break the expectation side with each
  member's own alt octets (match/loop [0,2,0,0,0], fold
  [0,255,255,255,255]).

All six arms verified wet locally. The census guards update per 4b(4):
7 native / 8 retained, and the identity-grain membership guard is
renamed to witness_native_rows_closed_membership_holds so the name
stops encoding the volatile population.

* Promote meet_join to SelfEmittedNative on the emit coverage frontier

The meet_join family's native-only verdict arms land on the complement arm's
helper, generalized to take the family member_id: meet and join run through
the same argv-dispatched logic family crate (one-build cache key shared with
complement, per the witness_family_build_grain_ruling), eval() never called,
verdict decoded from stdout. Octets meet=1 join=1 are the bytes the family
witness's warm legs pin on this same build; the wrong-octet control expects
each member's alt byte (0), which the primary runs can never produce.

Both arms verified wet: cold build then warm hits, PASS/PASS. The roster row
flips InterpreterRetained -> SelfEmittedNative (eighth promotion); census
guards move to 8 native / 7 retained with meet_join_eval_subject named in the
closed membership.

* Promote variant_construct to SelfEmittedNative on the emit coverage frontier

The variant_construct family's native-only verdict arms follow the
field_access arm shape exactly: the tree is the family's own equals_eval
tree value (emit_variant_construct_eval_tree, no eval leg reachable), the
run shares the family one-build cache key that
emit_on_demand_variant_construct_native_one_build_holds colds, and the
expected octet 9 is the byte the family witness's warm leg pins on this
same build. The wrong-octet control expects the alt tree's byte (1), which
the primary run can never produce; the wrong-value alt leg in the family
witness keeps the program-side discrimination.

Both arms verified wet: cold build then warm hit, PASS/PASS. The roster row
flips InterpreterRetained -> SelfEmittedNative (ninth promotion); census
guards move to 9 native / 6 retained with
emit_variant_construct_eval_subgraph_node named in the closed membership.

* Close the emit coverage frontier: final six rows to SelfEmittedNative

The last six InterpreterRetained rows flip to SelfEmittedNative, taking the
roster to 15 native / 0 retained:

- filesystem_read and shell_exec_run (host-effect transport families, no
  translated arrow body): the arms reuse each family's own native leg with
  the expectation pinned as a literal grounded by the family's enrolled
  fixture pin (dag/extdeps/shell/exec.dag contains bash; its shell.Exec.Run
  argv materializes to exactly [bash, -s]), run through the families' fixed
  witness workspaces.
- module and produced_module: the arms execute the exact sources the
  equals_eval pairs run (emit_module over the add fixture tree;
  produced_add_module_source's ingested two-fn module), octet 5 pinned
  against the add family's primitive-five/six oracle leg.
- call and record_construct: the arms emit the families' own producer trees
  against their target models, octets 7 and 9 pinned against the
  primitive-seven/eight and wrong-field oracle legs.

The four families without a one-build cache witness run under per-family
fixed workspace roots; content-safety comes from the realization-digest
nesting in run_host_process_admitted (changed source colds, never serves
stale), the same mechanism the filesystem_read fixed workspace relies on.
All twelve arms verified wet: PASS/PASS each, cold builds then warm hits.

With zero retained rows the retained_via_eval_agreement constructor loses
its last consumer and is deleted (DESIGN 3c); the InterpreterRetained
variant stays as the disposition authority's other state. Census guards
move to 15 native / 0 retained with all fifteen decl names in the closed
membership.

* Record the emit coverage frontier closure in the direct-path plan

Axis C line: all fifteen roster rows are SelfEmittedNative as of
2026-09-08, interpreter_retained_rows() is empty, and the row constructor
was deleted with the last flip. Notes explicitly that this closes axis (a)
(witness-body-runs-native) only; axis (b) (the regen-grain production
flip) remains operator-gated.

* Restore structural text reads in 02_parse: the chars(String) <- Variant cluster

Commit 285b02eed2 converted three structural-text reads in the parser to
host-string builtins (chars(s:), string_length, char_at, code_point) while
chasing emitted-closure compile errors. Lexeme is v2.std.text.String, which
interprets as a Variant value, so every claim that parses tokens failed at
runtime with 'chars expects a string argument, got Variant' — 10 claims in
the required floor lane.

parse_lexeme_digest folds the Lexeme list directly again,
parse_char_is_arm_pattern_lead takes Char again, and
parse_looks_like_match_arm_start matches string_head's CharFound/CharAbsent
again. Verified locally: all 10 claims of the cluster pass.

Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>

* Close the prepare_grammar shared-fill cost class: portable nullable carrier + preparation-time warming

Two defects composed into the required floor's twelve FillBudgetExceeded
refusals, both repaired at source:

(1) GrammarFirstAnalysis.nullable_set was a PointwisePower<Symbol>
characteristic function — a nested closure tower the cross-claim pure tier's
publication walk refuses totally (ServeCacheValueNotPortable), so the one
fill every parse of .dag source demands could never store and every
demanding claim recomputed it. The carrier is now the enumeration it always
was (List<Symbol>, the GrammarRoot.sync_tokens repair's own precedent):
set_symbol_insert de-duplicates over symbol_list_contains (first_list_contains
renamed, it was never first-specific), the fixpoint's convergence measure is
the list's own length, and nullable_member_count dissolves into it.

(2) The fill costs more than one claim's CPU budget on the lane's runner, so
an in-fold first touch could never complete. The nullary
v2.compiler.program_assembly.dag_prepared_grammar producer moves that first
touch to strict preparation via floor_cross_claim_pure_producers_warm —
outside every per-claim budget — and every claim then serves the landed fill.

Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>

* Split the meet/join native-only arms: one member per claim under the 500ms line

The two-member shape put two native-run verdicts inside one claim's 500ms
CPU budget — emit of the family crate plus the cached-run receipt walk,
twice over — and the required floor measured both meet_join arms over the
line. The ceiling is the floor's own and does not move to admit a claim
shape; the arm splits by member instead, the grain the family's equals_eval
pair already claims at (emit_host_meet_equals_eval_holds /
emit_host_join_equals_eval_holds). Each claim now pays one native run; the
family crate build stays shared through the same one-build cache key. The
coverage frontier's meet_join row re-cites emit_host_native_only_meet_holds;
the join claim carries the family's other half.

Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>

* Adjudicate the five structural-text/logic requalification deltas at their exact subjects

The branch's required-witnesses lane reports five TargetChanged binding
deltas, all one change class: three String sites (EmitSpellingEscape,
apply_emit_spelling_escapes, integer_string_to_decimal_digits_step)
requalified to v2.std.text and two Bool grounding sites (py_bool_grounding,
ts_bool_grounding) requalified to v2.std.logic — the gunbc#9907
namespace-lane requalification reaching the sites the XL-N closure repair
and the chars(String) <- Variant cluster repair touched. The spelling is
identical on both sides in every row; only the declarer moved, from the
ambient kernel type set to the named authority. Five exact-subject
TransitionAdmission rows, enumerated never patterned, with the dissolution
trigger on gunbc#10692's merge.

Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>

* Share the ingested-fixture pipelines across claims: three warm producers for the five over-ceiling claims

The prepare_grammar warm-store unmasked five changed witnesses over the
500ms per-claim ceiling: the classical_not family's three emit claims
(marginal 474-501ms, each re-running the full tokenize->resolve pipeline
on a module-constant source) and the produced_module pair (505-542ms,
each re-assembling the same two-decl module). CI's runner is ~1.8x this
lane's local host (median ratio over the 25 claims present in both
ledgers), so these project to ~900ms there — structurally over, not
variance.

The repair is the roster's own named one — stop recomputing a pure
function of program content — in its WARM arm, because a ~370-382ms
claim-forced fill leaves under 130ms of headroom and would die
mid-flight on the lane exactly as prepare_grammar's did:

- produced_add_module_source (already nullary) is enrolled directly.
- ingested_classical_not_arrow_with_body and its swapped sibling are new
  nullary producers in the ingested_fixture_arrows idiom; the three
  failing claims' tree helpers now take the arrow outcome, with the
  source-taking staging variant delegating so unselected claims keep
  their spans untouched. The arrow is the deepest pipeline stage whose
  value is closure-free and therefore portable; the InferredTree above
  it carries the facts PartialFunction and can never store.

claim_batch: 14/14 classical_not claims pass with identical verdicts.

Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>

* Share the door-specimen resolved tree across claims: one warm producer for the seven unmasked over-ceiling grounding claims

Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>

* Share the family-crate emitted pairs across claims: two warm producers for the twelve ceiling-band native-only verdict claims

Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>

---------

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>
Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
briansrls added a commit that referenced this pull request Sep 10, 2026
… named before native bootstrap (#10886)

* Land the add-slice per-stage verdict instrument named as the floor_expected_red note's producer

The add-slice roster note in v2.workflow.floor_expected_red carried a dated
receipt (main 3a8344b5c: infer accepts dag_add_emitted_root; the
infer-then-translate composition refuses headed by infer_grounding_not_derived)
and named its own next-rung trigger: a .dag entry returning the per-stage
verdicts for one root, so the paragraph can name a producer instead of a
commit.

v2.compiler.self_host.candidate_generation_stage_verdicts is that entry,
parameterized over root and target: the receipt's verdict vocabulary
(infer_accepted / infer_rejected; candidate_accepted or the rejection head
reason) plus the carried-reasons lists -- the half the verdict symbols cannot
say, namely that infer accepts while carrying the frontier diagnostic on its
accepted path, so the enrolled witness's d == None conjunct fails even where
the composition reaches acceptance.

v2.test.execution.self_host_candidate_generation_stage_verdicts binds the
instrument to the slice's own fixture, with add_slice_stage_verdicts_entry the
runnable gunbc run --function form (ExitSuccess only when infer accepts clean
and the composition accepts clean). Two witnesses: infer-accepts as a
permanent positive control, and the frontier-state pin that is expected to red
the day the add-slice stall's trigger lands, flipping to a permanent
regression control in the same change that removes the roster row (DESIGN
4b(4)).

Measured by execution on this branch: the entry exits 1 printing
infer=infer_accepted, infer_carried=[infer_grounding_not_derived x10],
composition=infer_grounding_not_derived, composition_carried=[x11] -- the
receipt reproduced, with bind_outcome's pending-plus-gate chain counted. Both
witnesses PASS; the enrolled semantic witness still fails as enrolled.

Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>

* Derive grounding for dag declared inhabitants: the add slice greens end-to-end

infer gains the declared-inhabitant membership derivation: a node declared in
the dag language authority's declared-inhabitants roster derives its grounding
by lookup, with the roster as evidence -- the namespacing answer to the atom
authority question, at specimen scope. The add slice's ten type-spine nodes
(Arrow, Conj, Atom) are all roster members, so:

- candidate_generation_translate_self_emit_dag_add_slice_holds passes; its
  floor_expected_red roster row and per-row note delete per the roster's own
  stale-quarantine arm
- the dag same-language ingest path compiles end-to-end: cross_language_compile
  accepts, byte-equal to the authority's own serialization, no carried
  diagnostics
- the add-slice stall narrows to its four python/typescript round-trip members;
  the original trigger's causal clause was refuted by execution and is restated
  against the grammar parse-product population
- the instrument's frontier guard flips to add_slice_composition_accepts_holds
  (DESIGN 4b(4): frontier guard to permanent regression control)
- five manual witnesses flip with it: two root flips rewritten to assert the
  green state, three transitive conjunctions updated

The kinds stay frontier: non-member Arrow/Conj/Atom specimens carry
GroundingNotDerived exactly as before, and all fourteen enrolled
refusal/acceptance controls pass unchanged. The door's production path still
reds inside rust emission, untouched by this rule.

Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>

* Derive grounding for canonical binding atoms: dag_binding_denotation joins binding to inhabitant once

The resolver already binds the surface spelling Int to the canonical binding
symbol dag_binding_type_int; what that binding DENOTES is the Int inhabitant
declared at dag_declared_inhabitants_core. Every hand-rolled fixture facts
lookup re-authored that join (dag_add_canonical_grounding_for,
record_construct_canonical_grounding_for). The language authority now declares
it once as dag_binding_denotation, and infer_node_facts consumes it: an Atom
whose identity is a canonical dag binding with a declared denotation derives
with that denotation as its grounding evidence.

Direct-rust-door specimen census: 14 underived -> 10 underived (the four
dag_binding_type_int atoms derive; grammar-production atoms, algebra atoms,
bare operand atoms, and the arrow/conj spine stay on the frontier unchanged).

Specimen-scope interim in the same frame as
infer_node_declared_in_dag_inhabitants: both delete in favor of consuming
resolution output when the resolver hands infer declaration-resolved
identities directly (the namespace migration's completed state).

Witness: v2.test.execution.dag_binding_denotation — all four Int binding
atoms in the door specimen derive with dag_int_inhabitant_node() as
structural evidence, and the two bare operand atoms stay GroundingNotDerived
(boundary control). Refusal suite 14/14, ingest bridge 7/7, add-slice
instruments 2/2 green; every remaining red in the at-risk population
reproduces identically on the pre-change tree and is enrolled in
floor_expected_red.

Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>

* Add v2 self-host direct-path orientation: axes, sequence, autonomy contract

A point-in-time orientation that defers to the existing authorities
(DESIGN section 7, the four-wave self-host program, the roadmap node
chain, the three frontier carriers, the guarantee-stall roster, XL-N)
rather than restating them: state is re-derived by the named
instruments, never transcribed here. Sequences the remaining work in
roadmap order (door, parse-product grounding, first behavioral module,
XL-N milestones, native bootstrap, fixed point, v1 deletion) and states
which decisions stay operator-gated.

Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>

* Derive grounding for fully-evidenced Conj and Arrow products

The sixth and seventh kind rules: a non-roster Conj or Arrow whose every
child carries DerivedGrounding derives, its evidence the same shape
re-formed over the children's grounding evidence (a fresh
OccurrenceSynthetic node, never the source — the self-evidence wall holds
by construction). A product with any frontier or absent child stays on the
frontier with its typed diagnostic; a childless product has no evidence to
compose and stays frontier. Roster members keep their roster evidence.

Measured on the direct-rust-door specimen (scratch probe, uncommitted):
10 underived of 15 -> 6. The parameter conj, the module-structure conjs,
and the bodied add arrow derive; what remains is the algebra atoms from
the + operation (AlgebraPrimitive, ring_field_add), the module atom
(dag_surface_module), the parameter references (x, y), and the
grammar-projection root conj that cascades once they land.

Enrolled witnesses (src/v2/test/claim/execution/infer_product_introduction_test.dag):
- product_introduction_derives_fully_evidenced_products_holds — census:
  4 Conj (3 derived, 1 frontier-by-frontier-child) + 1 Arrow (derived).
- product_introduction_composed_evidence_carries_child_groundings_holds —
  the params conj's evidence is a Conj whose x/y children target the dag
  authority's Int inhabitant.
- product_introduction_leaves_childless_conj_on_the_frontier_holds —
  boundary control via direct infer over a hand-built childless Conj.

Flip census (pre- and post-change, zero unexpected flips):
translate_underived_refusal 14/14, infer_self_grounding_wall 12/12,
branch_infer_if_then_else 2/2, compile_eval_thesis_proof 6/6,
ingest_bridge 9/9, cross_language_add_python_to_typescript 4/4,
inhabitant_neutralization 6/6 + e2e 6/6, emit_host_classical_not 14/14,
dag_binding_denotation 2/2, stage-verdicts instrument 2/2,
dag_add_emit_round_trip 4/6 (the 2 enrolled reds unchanged), door
production group still enrolled-red (unchanged).

Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>

* Ground canonical-operation and grammar-production atoms by authority roster membership

Two more specimen-scope derivations in infer_node_facts, both lookups into
declared authorities, never inventions:

- Canonical-operations roster (target_model.dag): every CanonicalOperation
  the target-model authority declares, rendered by
  target_model_canonical_operation_wire_node and gathered under one Conj
  root. The resolver canonicalizes surface operators (e.g. +) to those
  declared operations, so the wire atoms -- the operation discriminant and
  its field references -- derive by membership with the roster root as
  evidence. General over all 14 declared operations, not add-narrow.

- Grammar-productions roster (dag.dag): every production in
  dag_grammar_root() projected to its emitted surface atom under one Conj
  root keyed by production name. The bridge projects a production's parse
  into (identity atom, captured content) pairs, so the identity atom
  (dag_surface_module) derives by membership with the roster root as
  evidence. The roster derives from the grammar root, so a production
  added to the grammar joins by construction.

Both roster roots are Conj nodes, never structurally equal to any member
atom, so the self-evidence wall holds by construction (the first attempt
at the operations rule used the wire node itself as evidence and was
refused by grounding_evidence_is_source -- the wall doing its work).

Measured on the direct-rust-door specimen (scratch probe, uncommitted):
6 underived of 15 -> 2 (only the operand atoms x and y remain; the
grammar-projection root conj cascades once the module atom grounds).

Enrolled witnesses (infer_atom_grounding_rules_test.dag): each roster rule
pins derivation + evidence identity + census; a boundary control pins that
a bare atom with no authority membership stays frontier; the closing
control pins the 2-of-15 state.

Flip census: the product-introduction census witness updates 3->4 derived
conjs (the top conj now cascades) and gains a hand-built
partially-evidenced boundary control to replace the in-specimen one the
cascade consumed. Full battery otherwise unchanged: refusal suite 14/14,
grounding wall 12/12, instrument 2/2, binding-denotation 2/2, round-trips,
bridge, cross-language, neutralization, emit-host all green; enrolled reds
unchanged.

Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>

* Ground binding-reference atoms from the enclosing arrow's domain declaration

The fifth specimen-scope derivation, closing the direct-rust-door
specimen's inference frontier: an Atom whose binding an enclosing arrow's
domain declares derives with the declared domain type as its evidence --
the declaration-site annotation, itself derived (x: Int grounds the x
reference). This is the same lookup the branch-operand path already
performs (infer_find_arrow_domain_type_in_tree), now written to the
operand atom's own facts; it is scope-naive (whole-tree, first match),
recorded in the frontier note, and deletes with the other specimen-scope
rules when the resolver hands infer declaration-resolved identities. The
tree is threaded through the fold's init chain to reach infer_node_facts;
the helper had exactly one caller.

Measured on the door specimen (scratch probe, uncommitted): 2 underived
of 15 -> 0. The specimen's inference frontier is fully closed, and the
production observation advances from InferenceRejected
(infer_grounding_not_derived) to EmissionRejected
(target_use_site_ownership_lookup_miss) -- a new, typed, located deficit
in the emitter, the next gate on the path.

Flip census (all three rewrites verified by execution):
- dag_binding_denotation_leaves_unbound_operand_atoms_on_the_frontier_holds
  -> dag_binding_denotation_declares_no_denotation_for_operand_bindings_holds:
  the boundary moves to the authority itself (the denotation table returns
  Absent for x/y), true regardless of infer's other rules.
- The three emit_host classical-not refusal guards (canonical, staging,
  staging-swapped) flip to acceptance witnesses pinning the emitted text's
  shape -- the real-infer tree now fully derives, and the emission is the
  same one the equals-eval witness proves behaviorally correct. The
  translate-refuses-underived behavior stays enrolled on hand-staged
  fixtures in translate_underived_refusal_test.dag (14/14 green). The
  renames are carried into the commit_workflow and witness_deferral_freeze
  rosters.
- New witnesses: binding_reference_derives_parameter_atoms_holds (evidence
  is the domain's Int binding atom, census 2) and
  door_specimen_fully_derives_holds (0 frontier of 15).

Full battery at this state: refusal suite 14/14, grounding wall 12/12,
instrument 2/2, binding-denotation 2/2, product-introduction 4/4,
atom-rules 5/5, emit_host 14/14, round-trips 4/6 (2 enrolled reds
unchanged), bridge 9/9, cross-language 4/4, neutralization 6/6 + e2e 6/6,
branch 2/2, eval-thesis 6/6; door production group still enrolled-red
(unchanged).

Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>

* Green the direct-rust-door: route emission through produced-decl composition and decode canonical operator wires

The door specimen's inference frontier is fully closed, so its production
observation now reaches the emission stage. Two defects surfaced there, both
fixed here:

Emission composition. generate_rust_emission_candidate served two lanes with
one root shape: the door's production path (a dag module shell) and a fixture
lane (a bare rust Arrow). The translate ownership gate queried the module
atom's ownership at a struct-field use site and refused with
target_use_site_ownership_lookup_miss, because the module's grammar-projection
conj was misread as a type record. The door's real composition is the
produced-decl path: collect declaration conjuncts from the inferred tree and
emit via emit_produced_decl. A new generate_rust_module_emission_candidate does
exactly that, enforcing an exactly-one-declaration admission policy
(rust_module_emission_decl_absent / _ambiguous). The observation and production
mint paths switch to it; the fixture-lane candidate is retained with a note
that it is fixture-only. A pure collector, produced_decl_conjs_in_tree, finds
nodes of produced-decl shape (a Conj whose first child is a Named edge to an
Arrow). Its decl-head match routes through a declared FreeMonoid<Edge>
parameter because the v1 seed stamps pattern variables from a declared
parameter type, not from a field-access scrutinee.

Operator decode. With composition fixed, source fidelity still refused: the
door emitted fn add(x: i32, y: i32) -> i32 { AlgebraPrimitive(x, y) } instead
of { x + y }. Resolution canonicalizes a surface operator atom into a
canonical-operation wire node, so a production tree's transform operator
position carries the wire, while fixture trees that bypass resolution still
carry the surface token atom. translate_project_transform_in_arrow_scope only
knew the surface-token table, so the wire missed and fell to callable apply,
rendering the discriminant identity. The projection now tries the wire decode
first (canonical_operation_from_wire_node) and only on a wire miss falls to
the surface-token table, then to callable apply; the arms are disjoint, so the
dispatch adds no fallback widening. target_transform_operator_child extracts
the operator child safely.

The door's closing expectation now greens by execution, so its known_red_probe
row in explicit_witness_admission is deleted per its own dissolution condition,
and the roadmap authority note, the door contract note, and the direct-path
plan are updated to record the green state. realized_closure_for_v2_direct_
rust_door_emit_run's module list reflects the produced-decl route.

Verified by execution: the door witness greens; the fixture, containment,
algebra, produced-decl, add-slice, and classical-not witnesses stay green;
claim_executor required-ci lanes build and witnesses both exit 0; cargo fmt and
clippy --all-targets -D warnings are clean. One pre-existing red,
witness_projection_is_active_only in the floor_cost_debt containment roster,
reproduces on the base revision and is unrelated to this change.

Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>

* Close the parse-product grounding frontier: widen declared-inhabitant membership to the closed ingest set

The declared-inhabitant roster-membership derivation in 04_infer generalized
from the dag roster to the closed ingest set (dag, python, typescript):
infer_node_declared_in_language_inhabitants returns the declaring authority's
roster root as evidence, with deep subtree membership so a declared
inhabitant's leaf fact atoms derive exactly as the inhabitant node itself.

Measured: the python fixture's 19-node frontier and the typescript fixture's
28-node frontier both close to zero; all four add-slice stall population
round-trip witnesses green; the python->typescript cross-language compile
accepts, byte-identical to ts_source_text.

Section 4b(4) flips (expecting-red probes becoming permanent regression
controls for the acceptances):
- cross_language_compile_refuses_canonical_underived_holds ->
  cross_language_compile_python_to_typescript_round_trip_holds
- inhabitant_neutralization_emit_after_neutralize / same_flavor_python /
  go_int64_to_ts refusal helpers -> round-trip controls
- inhabitant_neutralization_python_to_ts_cross_language_compile (e2e) ->
  round-trip control; python->go members stay refusal guards (go is outside
  the closed ingest set)
- cross_language_emit_inhabitant_neutralization_refuses_underived_holds ->
  round-trip control; the python->typescript emit-matrix row reads ChainProven

The add-slice stall's next-rung trigger fired, so it retired per DESIGN
4b(4): removed from all_guarantee_stalls, row file deleted, witnesses stay
enrolled.

Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>

* Promote the add family to SelfEmittedNative: native-only verdict witness for the emitted add crate

First InterpreterRetained -> SelfEmittedNative promotion after classical_not,
executing the v2-emitter-first-behavioral-module first slice at the
coverage-frontier grain: the add family (fewest dependencies — integer
literals plus one canonical operation) now carries a native-only verdict
witness, so its behavior is established by the emitted crate's own stdout
with eval() unreachable from the verdict path.

- emit_host_native_only_add_holds: real emit -> cargo build -> native run,
  stdout pinned to the family's expected octet, sharing the kernel family's
  one-build cache key exactly as the classical_not arm shares its family's
  key (no duplicated cold build).
- emit_host_native_only_add_wrong_octet_mismatch_detected_holds: the broken
  control — a no-eval verdict has no oracle leg to break, so the expectation
  side breaks (an octet the run never produces must not match); program-side
  discrimination stays with the family's equals_eval primitive-five/six pair.
- The add coverage row flips disposition with its backing citation enrolled
  by construction (the verdict entry is file-grain enrolled in
  falsifier_self_host_wet_template_entries).
- Frontier census tests updated at identity grain: natives are exactly
  {classical_not, add}; split 2/13.

Verified by execution: all six native-only verdict tests green locally
(real wet legs — compile_skipped receipts show cold builds and native runs);
all eight emit_coverage_frontier tests green, including the unbacked-claim
RED control.

Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>

* Record the add-slice defect's repair in the declined-live-tree classification

The row classified candidate_generation_translate_self_emit_dag_add_slice_holds
as RealDefect/CompilerBehaviourRefusal with measured evidence that translate
refuses infer_grounding_not_derived. The owner lane (v2 self-host) repaired the
subject: the declared-inhabitant roster-membership derivation grounds the
slice's type spine by lookup, and the witness passes under claim_batch
--hermetic on the merged tree. The dated classification is kept verbatim; the
disposition flips RoutedToOwner -> RepairedInThisChange with the repair
measurement appended to the evidence, so the routing carrier stops dispatching
a fixed defect. Structural witnesses (count 13, no NotReproduced, exact
partition) are untouched and pass.

* Hoist two in-body annotation blocks to module-item grain

Main's annotation-placement wall (source annotations admit only standalone
leading blocks attached to module-scope declarations; in-body forms refuse)
reached this branch through the merge and refused 8 blocking errors on the
00_compile closure: the add-family promotion note inside the
emit_coverage_frontier_roster list and the python->typescript row note inside
the cross_language_emit_matrix list. Both blocks move above their enclosing
declarations, rephrased to name their subject row. Measured: gunbc compile of
src/v2/compiler/00_compile.dag now emits 172 files with 0 blocking errors;
both files' suites stay green (8/8 and 4/4).

* Promote the complement family to SelfEmittedNative: native-only verdict witness for the emitted logic family crate

The complement family's native execution runs family-grain per the
witness_family_build_grain_ruling (one crate for meet + join + complement,
argv-dispatched), so the native-only arm emits the logic family crate and
runs the complement member through the family dispatcher, sharing the
family witness's one-build cache key. The verdict is decided solely by the
emitted native run's stdout (expected octet 0, complement(True) = False);
the broken control flips the expectation side (octet 1 can never match),
with the comparator pinned by the stdout mock pair. Program-side
discrimination stays with the equals_eval agreement pair and the family
witness's all-alt leg.

The frontier row's backing citation lands in the already
file-grain-enrolled native-only verdict entry, so it is enrolled by
construction; the roster comment is rephrased to cover both 2026-09-07
promotions (add and complement). The frontier test's split and native
membership assertions move to 3 native / 12 retained.

Verified by execution: claim_batch --hermetic on
emit_host_native_only_verdict_test.dag passes all 8 witnesses (the two
new complement arms included), and emit_coverage_frontier_test.dag
passes all 8.

* Key the emitter's host-String arm on declaration provenance, not spelling

is_host_text_carrier_type answered true for any type expression whose
authored name reads "String", including references to the structural
alias v2.std.text.String (type String = FreeMonoid<Char>) that the
namespace lane (gunbc#9907) requalified the v2 corpus's text-carrier
fields to. The emitter rendered every one of those references as the
host String while value-position consumers rendered the structure -- the
E0308 family dominating the self-host compile-phase frontier (41 of 64
in v2_compiler_tokenize.rs on the post-merge board).

The String arm now consults the resolved declaration's provenance
against v1.compiler.coercion structural_declaration_modules_for -- the
same roster type_realization_decision reads -- so the legacy arm and the
strict decision cannot diverge on one node (DESIGN section 3, and
gunbc.recurring_failure_mode alias_resolution_collides_with_kernel_spelling).
Kernel mints and unresolved references keep the host answer exactly as
before.

Regen: the only drifted stage0 mirror is v1_compiler_emit_rust.rs
itself (no module in the stage0 closure references a structurally
declared String -- verified by the whole-population candidate tree),
installed from target/stage0-regen-candidate after the priced round's
partitioned rebuild refused MirrorHasNoOwningPackage on the emitter
(the emitter is monolith-shell, not partition-owned). Fixed point
verified by execution: claim_executor --required-regen on the rebuilt
seed reports first_generation_equal=true over 158 adjudicated mirrors.

* Peel qualified String alias leaves in field position: XL-N closure 72 -> 28 errors

A field authored v2.std.text.String reached the Rust emitter as an overlay-less
resolved reference leaf and rendered the bare terminal name, which binds the
prelude String cross-module (#9813: kernel names are never overridden by
imports, so the use-line is dropped) while every value position renders the
structural carrier Rc<Vec<i64>> -- the v2_compiler_tokenize.rs E0308 family,
41 of 72 errors on the XL-N phase board.

The new rust_overlayless_alias_leaf_requires_peel arm in
render_rust_type_without_applied_binding detects the population (overlay-less
zero-parameter alias leaf, qualified spelling, String terminal segment,
closed_alias_peel_verdict agrees) and renders the alias declaration's resolved
right-hand side, projecting the same realization the fn-signature positions
already produce.

The qualified gate is load-bearing: inside the declaring module the bare name
is the correct render (the emitted module carries the alias declaration), and
the local binding's resolved_type drops the RHS type argument, so an ungated
peel rendered Rc<FreeMonoid> there (E0107 x13, E0282 x2 on the probe). Bare
String keeps denoting the kernel scalar through the host-carrier arm.

Measured: probe specimen (qualified/bare/direct-FreeMonoid/container/variant/
local-alias positions) compiles clean; XL-N compiler closure cargo check
72 -> 28 errors with the residual census dominated by the declared
text_boundary_identity_wall class (kernel String vs structural carrier at
bare-authored boundaries, 17 of 20 E0308s); v1-corpus fixed point holds
(first_generation_equal=true, 158/158 adjudicated).

* Resolve the 12 non-hop XL-N closure errors at source: text-wall conversions + witness_violates helper

Four clusters, all measured non-hop additions between receipt_1 (155) and the
post-peel census (28); the live gate now measures 15 with zero unadmitted
regressions:

- integer.dag: integer_string_to_decimal_digits_step takes v2.std.text.String;
  the public boundary converts with chars() (text_boundary_identity_wall
  specimen discharged at this site).
- 01_tokenize.dag: Token/UnboundSourceAnnotation lexemes convert structural
  -> host String with chars_to_string() at construction, mirroring the v1
  tokenizer's host-lexeme carrier.
- target_model.dag + bash.dag: EmitSpellingEscape.from/to and
  apply_emit_spelling_escapes go structural (v2.std.text.String); the
  EmitSpellingQuote arm converts host->structural->host at its boundary;
  bash's escape rows wrap their kernel String literals with chars().
- witness.dag + 3 call sites (collection list_nth, provenance
  span_index_resolve_textual_locus_from_ids, compile outcome_with_diagnostics):
  new witness_violates<C> helper puts Violates constructions in a
  Witness-headed position so the emitter resolves the carrier type argument;
  dissolves once inference records per-call substitutions.

Verified: 48 targeted claim witnesses green (tokenize behavioral, shell
conformance, string brace escape, string length, map-lookup violates, source
text ingress, bash materialize x12, int literal smoke x6, provenance span
index x2).

* Record receipt_2 on the self-host compile-phase frontier: 15-error census at 66765317ec

The census at the XL-N lane tip: 155 -> 15 net, credited to the qualified-alias
peel (60cbd7b697, 72 -> 28) and the twelve-error source cluster (66765317ec,
28 -> 15). The epoch changes on the instrument's target pinning (found by
review on gunbc#9857), admitted with receipt_1's board as the reclassified
predecessor under the identity map. Nine added identities are hop relocations
admitted by the hop index; four sit in python/typescript modules newly entered
into the emitted closure, admitted as ExposedByNewEmittedModule.

Validated: all 36 self_host_compile_phase_frontier_witness claims PASS,
including current_persisted_compile_phase_frontier_holds.

* Emitter: a substituted declaration node carries its own provenance

Inference substitutes the resolved declaration into a data annotation's
type-argument position, so BooleanAlgebra<v2.std.logic.Bool> reaches the
emitter with the arg BEING the type Bool = True | False declaration itself
(Disj connective, ident_span in src/v2/std/logic.dag, no Resolved wrapper).
type_reference_provenance_in_env's bare-leaf arm re-resolved that leaf in the
REFERENCING module's scope, where post-#9813 a kernel-shadowed spelling
answers the kernel declaration -- so the structural enum rendered as host
bool against a value of BooleanAlgebra<Bool> (the python.rs:328 /
typescript.rs:177 E0308 pair on the XL-N compile-phase frontier).

The connective is the discriminator: a reference node is a bare name
(NoConnective); a node carrying Conj/Disj structure IS the declaration, and
type_reference_provenance's own-span fallback already answers that shape
correctly. The guard routes declaration-shaped nodes there directly, bypassing
the scope lookup that #9813 makes answer the kernel.

Mirror regenerated via the regen round; fixed-point verified
(claim_executor --required-regen PASS).

* Clear the remaining XL-N closure errors at source: carrier conversions at the boundaries

The receipt_2 census's fifteen identities, resolved at their sources:

- lexing.dag, dag.dag, python.dag, typescript.dag: LexPattern.text is the
  structural carrier (v2.std.text.String); the construction sites held host
  Strings. Convert at construction with chars() -- the #9907 ingress pattern.
- python.dag / typescript.dag bool groundings: qualify the annotation as
  BooleanAlgebra<v2.std.logic.Bool>; with the emitter's substituted-
  declaration provenance guard the qualified arg now renders structural.
- target_model.dag: target_lex_rule_literal_step returns the host carrier
  (chars_to_string over the structural pattern text); TargetText.source
  converts at the is_empty boundary; the unicode-scalar symbol intern converts
  its single-codepoint list to the host carrier.
- qualified_name.dag: qualified_name_from_dotted_string uses the host-carrier
  emptiness check (string_length == 0) instead of routing through the
  structural string_is_empty.
- 02_parse.dag: parse_looks_like_match_arm_start rewritten on host-carrier
  operations (string_length, char_at, code_point) rather than converting to
  the structural carrier for a two-character lookahead;
  parse_char_is_arm_pattern_lead takes the codepoint Int directly.
- v1_interpreter_primitive_surface.dag row_key: the concat pipeline lowered
  to a .concat() method call on std::string::String (E0599); rewritten as
  nested concat calls.

Measured: the 00_compile closure emits 172 files and cargo check reports
cargo_clean=true, cargo_error_population=0 under the pinned 1.93.0 toolchain.

* Pin the cargo half's toolchain channel by construction

The cargo half runs with cwd = a fresh mktemp directory; with no
rust-toolchain.toml there, rustup resolves the host's DEFAULT toolchain, so a
census under cargo 1.83 and one under cargo 1.93 would compare as equal epochs
while different compilers did the measuring -- the fabricated comparability
the target pin (gunbc#9857) excludes, one level up. Measured 2026-09-07: a
host default of 1.83.0 met a crates.io index whose freshly published
dependency manifests require edition2024, resolution failed before any
diagnostic existed, and the zero-diagnostic refusal fired on an unmeasured
tree.

The pin is propagated by copying the repo's rust-toolchain.toml into out_dir:
the file remains the sole in-repo channel authority (its header forbids a
second pinned literal), and the copy makes the measured channel true by
construction on any host. The gate's read_live_toolchain observes the same
channel because every documented actuator invokes from the repository root,
which the same file governs.

* Record receipt_3 on the self-host compile-phase frontier: the emitted closure's cargo census is empty

Measured at 5ee4892b70 by the one-entry instrument: the 172-file emitted crate
reports zero cargo error diagnostics, so the board attributes every phase a
count of zero and furthest_phase_reached stands at Borrowck. The fifteen
removals against receipt_2 need no disposition; nothing was added.

The epoch does not change: the cargo half now pins the toolchain channel by
copying the repo's rust-toolchain.toml into the scratch crate, and every
recorded comparison field is identical to receipt_2 (whose census the
fingerprint evidence shows the same 1.93.0 toolchain already compiled), so the
same-epoch arm carries no reclassified predecessor.

The frontier-state pin flips per DESIGN 4b(4):
the_published_frontier_standing_does_not_claim_typeck_or_borrowck_passed
becomes the_published_frontier_standing_claims_typeck_and_borrowck_passed, the
permanent regression control over the green state.

Validated: all 36 self_host_compile_phase_frontier_witness claims PASS,
including current_persisted_compile_phase_frontier_holds.

* chore: regenerate drifted generated artifacts (ci auto-heal)

Ledger-Repair-Judged: docs/design-failure-modes.md
Ledger-Repair-Judged: docs/design-rung-drops.md

* Remove the stale PointwisePower inhabitant rows from the four language rosters

First native-parity divergence class found by running the emitted closure on a
discriminating fixture: the algebra inhabitant rosters still carried
PointwisePower after its authority row was cut, so the emitted compiler panicked
at 12 record-shaped carrier sites while the interpreted seed refused cleanly.
The roster rows are removed in rust/python/go/typescript types.dag, the derived
coercion assertions in compiler_tests.rs regenerate without them, and two
witnesses pin the boundary: the record shape constructs its structural carrier,
and FinitePowerSet still refuses while its row stands.

Mirrors regenerated by a converged regen round (fixed point Reached, stage-1
PromoteGenerationInputs over the three language types mirrors).

* Regen gen-2 gate: compare executable digests in one spelling

The admitted side of run_built_seed_regen carries the executable-digest
spelling (current_exe_digest, next_pass_executable_digest) while the observed
side hashed the file through path_digest, which prepends the fnv1a64: tag.
Same bytes, two spellings, so the gate could never pass -- unpassable since
fa2d403dc8 (#9771). Factor current_exe_on_disk as the single path authority
and read the observed digest through current_exe_digest so both sides spell
the same bytes the same way.

* Model ReleaseScopeEmpty for release-excluded mirrors, end to end

A regen round whose only stage-2 drift was compiler_tests.rs (the PointwisePower
roster removal rewrote its derived coercion assertions) refused the rebuild
MirrorHasNoOwningPackage: the mirror is owned by no partition package, because
every item it defines is #[cfg(test)] and no release unit elaborates it. The
refusal conflated two different states -- unowned (a coverage hole) and excluded
from the release build by construction (a precise empty scope).

The model now names the class: rebuild_scope_release_excluded_mirrors rosters
its members (compiler_tests.rs, cited to emit_compiler_tests_module), the
decision answers ReleaseScopeEmpty when the whole change set is excluded, and
the actuation shape is actuatable with an empty package closure and every
partition package excluded -- the build still runs as verification, and a
compiled partition package refuses the stage. The host admits the empty closure
only when the new stage0_partition_rebuild_release_scope_empty_today query
answers true; any other empty closure still refuses. A mixed change set scopes
on its release-visible members alone.

Verified by execution: the 2026-09-08 round converged (fixed point Reached)
with stage-2 installing compiler_tests.rs alone; cargo recompiled the shell
crate on its fingerprint (the outer mod line is ungated, so rustc reads the
file) while the produced executable was byte-identical -- stage input seed
digest == output seed digest. Four new witnesses pin the arm, its actuation
shape, the mixed set, and the host-facing query's two arms; the boundary
witness (unowned cli_run.rs still refuses) keeps the roster from decaying into
the absorbing fallback.

* Round-cost receipt: project installed mirrors to the model's vocabulary

The receipt's partition-rebuild line is rendered by the model over
receipt.installed_mirrors, which the host populated from the stages'
projected_paths -- full paths -- while the partition rows and rosters key on
basenames. Every drifted round's receipt therefore rendered a spurious
RebuildScopeRefused MirrorHasNoOwningPackage line naming a full path, a false
claim on the round's own receipt. Route the projection through
emit_path_basename, the module's single path-to-basename bridge, so the field
carries the mirror names the model's vocabulary means.

* Hoist ReleaseScopeEmpty annotations to module-item grain

The ReleaseScopeEmpty modeling commit placed three // blocks inside
declaration bodies (stage0_partition_rebuild_is_actuatable,
stage0_partition_rebuild_decision, stage0_partition_rebuild_excluded_today).
The .dag realization admits annotations at module-item grain only, so the
floor lane's parse phase refused the file with 12 located errors and the
run ended floor refused. The prose is unchanged; each block now sits above
the declaration it describes.

* Spell the PointwisePower witness's finite-set exclusion as the applied realization

The witness added with the fossil-row removal excluded the bare spelling
"BTreeSet", but every emitted file's preamble imports OrdSet as BTreeSet,
so the row could never green. The exclusion's subject is the finite-set
REALIZATION the fossil row would have asserted; spell it applied
(BTreeSet<i64), which the preamble's import line does not contain.

* Emit fieldless-record data values as null for the unit-struct carrier

The second native-parity divergence class, measured 2026-09-08 on the
native run of the emitted 00_compile closure: emit_data_value_json spelled
EVERY record literal as a JSON map, including the zero-field record, while
emit_struct_from_children renders that same declaration as a Rust unit
struct (pub struct BoolEncodingFact;). serde's derived unit-struct
Deserialize reads null and rejects {}, so the emitted compiler panicked at
first touch of v2.std.logic's bool_primitive_facts: "invalid type: map,
expected unit struct BoolEncodingFact". The JSON spelling of a data value
must deserialize into the Rust type the same declaration emitted; the
record arm now spells the zero-field value null and keeps the map spelling
for non-empty records.

The mirror is taken from the required-regen candidate, not hand-edited.
Two witnesses enroll: the discriminating red (zero-field record spells
null, never {}) and the boundary control (a record with fields keeps the
map spelling).

* Bind the duplicate-definition filter ahead of its branch condition

Main's FilterInBranchCondition wall (#10699) refuses to publish a module
whose filter call sits in a branch condition, and the v2 00_compile closure
emission names primitive_duplicate_semantic_definition_violation as such a
site. The filter is pure and total; binding it with a let ahead of the
branch is the authored remediation the wall exists to force, and the
emitted closure is unchanged in behavior.

* chore: regenerate drifted generated artifacts (ci auto-heal)

Ledger-Repair-Judged: docs/design-rung-drops.md
Ledger-Rows-Repaired: docs/design-rung-drops.md rust_unit_tests_off_the_merge_path
Ledger-Rows-Repaired: docs/design-rung-drops.md determinism_transitive_reachability
Ledger-Rows-Repaired: docs/design-rung-drops.md transitional_admission_exception

* Emitter: three native-parity repairs for the post-merge 00_compile closure build

Three divergence classes measured as the 21 rustc errors on the natively
emitted 00_compile closure after the main merge, each repaired at the .dag
source with a discriminating witness:

- Locality wins over a foreign ambiguity (12 E0433 in v2_std_integer.rs):
  alias_rhs_base_module_filename asked the global leaf index, saw
  LeafAmbiguous for Compose, and emitted the poison marker even inside
  v2.std.integer itself, where source resolution binds the local
  declaration before any cross-module lookup. The local physical
  declaration now shadows foreign declarers; the poison marker still
  stands for a leaf two FOREIGN modules declare.
- The qualifier is the disambiguator (8 E0425/E0433 in
  v2_lens_fact_density.rs): the qualified use-line route declined any
  globally-ambiguous leaf, but a qualified reference names its provider
  in its own spelling. The route now resolves by DeclaredCallableIdentity
  at the qualifier, keeping the type-declared and export-proof walls.
  The dotted spelling reaches the route through the value surface (a
  qualified value projection's borrowed type stamps the match patterns'
  parent_enum); the witness reproduces that chain exactly, and its
  exclude half pins the E0603 boundary (the dotted VARIANT head must
  still be declined).
- Clone-bound forwarding is transitive (1 E0277 in
  std_realization_measurement.rs): the call-forwarding derivation
  re-derived only each callee's SELF-derived half, so a callee whose
  bound is itself forwarded re-derived to empty. The derivation now
  recurses over the call graph with the module's visited-set
  termination; the equality half stays one-hop as declared.

Witnesses: 56/56 PASS on the rebuilt seed; regen fixed point holds.

* Refuse variant record literals on the serde_json data path fail-closed

A record literal with parent_enum present is a variant construction whose
wire spelling is the parent coproduct's declared VariantEncoding policy --
a module-local fact of the parent's home module that emit_data_value_json
does not carry. The zero-field arm's null and the map arm's untagged fields
are both measured to fail serde deserialization under the internal-tag
default, so the arm now refuses and the caller renders compile_error!, a
build-time located refusal where a runtime panic on the data definition's
expect was the latent alternative. The refusal names its trigger: a
closure-wide wire-policy index beside EmitGraphInfo.type_decl_items.

Witness: w_variant_record_lit_on_the_json_data_path_refuses_fail_closed
forces the JSON path with a nested-record Holder and asserts the
compile_error! spelling while excluding the former null mis-serialization.

* Spell variant record literals on the serde_json data path from a closure-wide wire-policy index

The fail-closed refusal landed in 73b582dea6 fired on 5 real corpus sites
(SugarKey x2, CopiedPortCitationFrontierDisposition x3), proving variant
record literals reach the JSON data path in the 00_compile closure. This
change replaces the refusal with the correct spelling, driven by a new
closure-wide index:

- v1.compiler.infer_emit_info gains DataVariantWireSpelling, the
  language-general projection of a coproduct's Rust wire serde policy
  for one variant (InternalTagged { tag_field, tag } | BareString { tag }
  | Untagged | SpellingRefused { reason }), and EmitGraphInfo carries
  data_variant_wire_spellings: Map<String, DataVariantWireSpelling>
  keyed by coproduct.variant.
- v1.compiler.emit_rust builds the index once per emission root via
  build_data_variant_wire_spellings, resolving each coproduct's policy
  through the new shared resolve_emission_coproduct_wire_policy (the
  same function the type-emission side now calls, so the two cannot
  drift), projecting each variant through data_path_wire_variant_tag
  (rename_all and StripAffix aware), and poisoning collisions as
  SpellingRefused so ambiguity stays fail-closed.
- v1.compiler.emit's emit_data_value_json variant arm reads the index:
  internal-tagged spells {"_variant": tag, ...fields}, bare-string
  spells "tag" for nullary and refuses fielded, untagged spells the
  bare fields or null; unindexed keys and stored refusals remain
  compile-time errors. The service mock-property chain threads
  emit_info through so dry-run data spells identically.

Witnesses: w_variant_record_lit_on_the_json_data_path_refuses_fail_closed
is rewritten as ..._spells_the_internal_tag (asserts the internal-tag
map, excludes the former null mis-serialization and the refusal), and
w_fielded_variant_record_lit_on_the_json_data_path_spells_tag_and_fields
pins the fielded case. 57/57 witnesses pass; regen fixed-point holds.

* Promote field_access to SelfEmittedNative on the emit coverage frontier

Fourth native-eval construct promotion, after classical_not, add, and
complement. The native-only verdict arm pair lands in the already
file-grain-enrolled long/ entry, so the backing citation is enrolled by
construction:

- emit_host_native_only_field_access_holds pins the family one-build
  cache run's stdout to octet 9 (the byte the family witness's warm leg
  pins on the same build), eval() never called.
- emit_host_native_only_field_access_wrong_octet_mismatch_detected_holds
  breaks the expectation side with octet 1, the alt tree's byte.

Both arms verified wet locally (real cargo build + native run, sharing
the field_access family one-build cache key). The roster row flips to
SelfEmittedNative; the two census guards update per 4b(4) — the split
moves to 4 native / 11 retained and the identity-grain membership guard
is renamed to name the four-member population. The family's equals_eval
agreement pair stays enrolled as its program-side discrimination leg.

* Drop the scratch parity probe from the tree

The probe is a manual parity-loop instrument (the interpreted leg of the
native-vs-interpreted comparison), not a corpus declaration with an
executing consumer (DESIGN 6 experimental residue). It stays in use
locally as an untracked file.

* Promote match, loop, and fold_closure to SelfEmittedNative

Fifth, sixth, and seventh native-eval construct promotions. The three
match_loop_fold family rows flip together on one shared family-crate
arm shape, per the witness_family_build_grain_ruling: each arm emits
the three-member family crate once and runs its own member through the
argv dispatcher against the family one-build cache key.

- emit_host_native_only_{match,loop,fold_closure}_holds pin the warm
  legs' stdout to the family's declared octet lists (match/loop
  [0,1,0,0,0], fold [0,7,0,0,0]), eval() never called.
- The wrong-octet controls break the expectation side with each
  member's own alt octets (match/loop [0,2,0,0,0], fold
  [0,255,255,255,255]).

All six arms verified wet locally. The census guards update per 4b(4):
7 native / 8 retained, and the identity-grain membership guard is
renamed to witness_native_rows_closed_membership_holds so the name
stops encoding the volatile population.

* Promote meet_join to SelfEmittedNative on the emit coverage frontier

The meet_join family's native-only verdict arms land on the complement arm's
helper, generalized to take the family member_id: meet and join run through
the same argv-dispatched logic family crate (one-build cache key shared with
complement, per the witness_family_build_grain_ruling), eval() never called,
verdict decoded from stdout. Octets meet=1 join=1 are the bytes the family
witness's warm legs pin on this same build; the wrong-octet control expects
each member's alt byte (0), which the primary runs can never produce.

Both arms verified wet: cold build then warm hits, PASS/PASS. The roster row
flips InterpreterRetained -> SelfEmittedNative (eighth promotion); census
guards move to 8 native / 7 retained with meet_join_eval_subject named in the
closed membership.

* Promote variant_construct to SelfEmittedNative on the emit coverage frontier

The variant_construct family's native-only verdict arms follow the
field_access arm shape exactly: the tree is the family's own equals_eval
tree value (emit_variant_construct_eval_tree, no eval leg reachable), the
run shares the family one-build cache key that
emit_on_demand_variant_construct_native_one_build_holds colds, and the
expected octet 9 is the byte the family witness's warm leg pins on this
same build. The wrong-octet control expects the alt tree's byte (1), which
the primary run can never produce; the wrong-value alt leg in the family
witness keeps the program-side discrimination.

Both arms verified wet: cold build then warm hit, PASS/PASS. The roster row
flips InterpreterRetained -> SelfEmittedNative (ninth promotion); census
guards move to 9 native / 6 retained with
emit_variant_construct_eval_subgraph_node named in the closed membership.

* Close the emit coverage frontier: final six rows to SelfEmittedNative

The last six InterpreterRetained rows flip to SelfEmittedNative, taking the
roster to 15 native / 0 retained:

- filesystem_read and shell_exec_run (host-effect transport families, no
  translated arrow body): the arms reuse each family's own native leg with
  the expectation pinned as a literal grounded by the family's enrolled
  fixture pin (dag/extdeps/shell/exec.dag contains bash; its shell.Exec.Run
  argv materializes to exactly [bash, -s]), run through the families' fixed
  witness workspaces.
- module and produced_module: the arms execute the exact sources the
  equals_eval pairs run (emit_module over the add fixture tree;
  produced_add_module_source's ingested two-fn module), octet 5 pinned
  against the add family's primitive-five/six oracle leg.
- call and record_construct: the arms emit the families' own producer trees
  against their target models, octets 7 and 9 pinned against the
  primitive-seven/eight and wrong-field oracle legs.

The four families without a one-build cache witness run under per-family
fixed workspace roots; content-safety comes from the realization-digest
nesting in run_host_process_admitted (changed source colds, never serves
stale), the same mechanism the filesystem_read fixed workspace relies on.
All twelve arms verified wet: PASS/PASS each, cold builds then warm hits.

With zero retained rows the retained_via_eval_agreement constructor loses
its last consumer and is deleted (DESIGN 3c); the InterpreterRetained
variant stays as the disposition authority's other state. Census guards
move to 15 native / 0 retained with all fifteen decl names in the closed
membership.

* Record the emit coverage frontier closure in the direct-path plan

Axis C line: all fifteen roster rows are SelfEmittedNative as of
2026-09-08, interpreter_retained_rows() is empty, and the row constructor
was deleted with the last flip. Notes explicitly that this closes axis (a)
(witness-body-runs-native) only; axis (b) (the regen-grain production
flip) remains operator-gated.

* Restore structural text reads in 02_parse: the chars(String) <- Variant cluster

Commit 285b02eed2 converted three structural-text reads in the parser to
host-string builtins (chars(s:), string_length, char_at, code_point) while
chasing emitted-closure compile errors. Lexeme is v2.std.text.String, which
interprets as a Variant value, so every claim that parses tokens failed at
runtime with 'chars expects a string argument, got Variant' — 10 claims in
the required floor lane.

parse_lexeme_digest folds the Lexeme list directly again,
parse_char_is_arm_pattern_lead takes Char again, and
parse_looks_like_match_arm_start matches string_head's CharFound/CharAbsent
again. Verified locally: all 10 claims of the cluster pass.

Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>

* Close the prepare_grammar shared-fill cost class: portable nullable carrier + preparation-time warming

Two defects composed into the required floor's twelve FillBudgetExceeded
refusals, both repaired at source:

(1) GrammarFirstAnalysis.nullable_set was a PointwisePower<Symbol>
characteristic function — a nested closure tower the cross-claim pure tier's
publication walk refuses totally (ServeCacheValueNotPortable), so the one
fill every parse of .dag source demands could never store and every
demanding claim recomputed it. The carrier is now the enumeration it always
was (List<Symbol>, the GrammarRoot.sync_tokens repair's own precedent):
set_symbol_insert de-duplicates over symbol_list_contains (first_list_contains
renamed, it was never first-specific), the fixpoint's convergence measure is
the list's own length, and nullable_member_count dissolves into it.

(2) The fill costs more than one claim's CPU budget on the lane's runner, so
an in-fold first touch could never complete. The nullary
v2.compiler.program_assembly.dag_prepared_grammar producer moves that first
touch to strict preparation via floor_cross_claim_pure_producers_warm —
outside every per-claim budget — and every claim then serves the landed fill.

Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>

* Split the meet/join native-only arms: one member per claim under the 500ms line

The two-member shape put two native-run verdicts inside one claim's 500ms
CPU budget — emit of the family crate plus the cached-run receipt walk,
twice over — and the required floor measured both meet_join arms over the
line. The ceiling is the floor's own and does not move to admit a claim
shape; the arm splits by member instead, the grain the family's equals_eval
pair already claims at (emit_host_meet_equals_eval_holds /
emit_host_join_equals_eval_holds). Each claim now pays one native run; the
family crate build stays shared through the same one-build cache key. The
coverage frontier's meet_join row re-cites emit_host_native_only_meet_holds;
the join claim carries the family's other half.

Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>

* Adjudicate the five structural-text/logic requalification deltas at their exact subjects

The branch's required-witnesses lane reports five TargetChanged binding
deltas, all one change class: three String sites (EmitSpellingEscape,
apply_emit_spelling_escapes, integer_string_to_decimal_digits_step)
requalified to v2.std.text and two Bool grounding sites (py_bool_grounding,
ts_bool_grounding) requalified to v2.std.logic — the gunbc#9907
namespace-lane requalification reaching the sites the XL-N closure repair
and the chars(String) <- Variant cluster repair touched. The spelling is
identical on both sides in every row; only the declarer moved, from the
ambient kernel type set to the named authority. Five exact-subject
TransitionAdmission rows, enumerated never patterned, with the dissolution
trigger on gunbc#10692's merge.

Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>

* Share the ingested-fixture pipelines across claims: three warm producers for the five over-ceiling claims

The prepare_grammar warm-store unmasked five changed witnesses over the
500ms per-claim ceiling: the classical_not family's three emit claims
(marginal 474-501ms, each re-running the full tokenize->resolve pipeline
on a module-constant source) and the produced_module pair (505-542ms,
each re-assembling the same two-decl module). CI's runner is ~1.8x this
lane's local host (median ratio over the 25 claims present in both
ledgers), so these project to ~900ms there — structurally over, not
variance.

The repair is the roster's own named one — stop recomputing a pure
function of program content — in its WARM arm, because a ~370-382ms
claim-forced fill leaves under 130ms of headroom and would die
mid-flight on the lane exactly as prepare_grammar's did:

- produced_add_module_source (already nullary) is enrolled directly.
- ingested_classical_not_arrow_with_body and its swapped sibling are new
  nullary producers in the ingested_fixture_arrows idiom; the three
  failing claims' tree helpers now take the arrow outcome, with the
  source-taking staging variant delegating so unselected claims keep
  their spans untouched. The arrow is the deepest pipeline stage whose
  value is closure-free and therefore portable; the InferredTree above
  it carries the facts PartialFunction and can never store.

claim_batch: 14/14 classical_not claims pass with identical verdicts.

Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>

* Share the door-specimen resolved tree across claims: one warm producer for the seven unmasked over-ceiling grounding claims

Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>

* Stage0 emission boundary as a target profile: visibility and integer carrier selected, measured over the disk route

The regen-grain flip's presumptive subject (std.integer) is not producible by the
v2 generator, and neither is any other real corpus mirror. Measured, not assumed:
of the 152 committed stage0 mirrors joined to their .dag sources, exactly one
module carries a single declaration -- the shape the production composition
admits -- and that module's body stops emission. So this change lands the two
BOUNDARY selections the flip needs, and names the remainder.

The two selections are not emitter generalization. Rust owns what Rust is; this
adds what the stage0 SEED CRATE requires of a module emitted into it:

  visibility -- every committed mirror is `pub`, because the crate calls across
  module boundaries (gunbc_rust_decl_type_overlay's function is called from
  v1_compiler_emit_rust). The .dag source spells no visibility and Rust emission
  in general must not: a private item is correct at a boundary with no external
  consumer. The keyword is a Rust row; the SELECTION is the profile's.

  integer carrier -- the language's Int is unbounded and a Rust realization picks
  a primitive. The committed stage0 ABI is i64; the direct-door fixtures are
  organized around i32 and stay that way. rust_binding_spellings_for_int takes
  the carrier as a parameter rather than the base target being relabelled, which
  would have fused two boundaries into one row (DESIGN section 3).

Evidence, all three PASS by execution (claim_batch, wet -- the specimen is read
off disk, not carried inline): the profile emits
`pub fn probe_add(x: i64, y: i64) -> i64 { x + y }` through
source_ref_for_observed_storage_path -> ingest -> assemble -> infer -> the
production single-declaration composition; and two controls, one per capability
class, observe the base target emitting no `pub` and emitting i32 at the exact
positions the crate fixes. Each fails for its own reason, so a regression in one
cannot be masked by the other. No enrolled claim exercised the disk-backed
production seam before this one -- the door's own specimen carries its module
source inline.

THE REMAINDER, measured per form over real files rather than predicted. The
overlay module's body needs five further capabilities, and three of them are
inference frontier, not emission:

  x > y          EMIT refuses (transform shape invalid at the first operand)
  !a             EMIT refuses (same site)
  x + 1          INFER refuses -- integer literals are Value-kind, no rule
  let z = ...    INFER refuses -- Bind-kind, no rule
  Int? param     EMIT refuses -- type ref renders only Atom shapes
  match v {...}  ASSEMBLE refuses -- Present/Absent unbound with no import

04_infer's node_grounding_frontier_note already states this: v2 derives six of
twelve node kinds, "Transform add-shape only". So the production-compatible
corpus module is gated on that open frontier, not on a handful of spellings, and
a > b working while a && b works is a resolution/layout question rather than a
missing operator row (the canonicalization table already carries op_gt).

Also noted, unfixed and deliberately so: an unspelled type binding prints its
symbol lexeme (`bool_node_symbol`) instead of refusing, and the Rust bool
spelling exists twice -- once as a TargetAtomRealization, once as a
binding-spellings row. The repair is for produced-decl type refs to consult the
atom realization catalog, which is the first missing join rather than a new row.

One roadmap transition added between the direct door and the flip
(v2-emitter-production-compatible-corpus-module), so the flip node keeps its own
different fact: that production regeneration actually selected v2 and could not
reach the old generator.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_011X5tyxfVrw3chDNbQ3sVD3

* Share the family-crate emitted pairs across claims: two warm producers for the twelve ceiling-band native-only verdict claims

Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>

* Keep the base Rust spelling map byte-identical, and share the two stage0-boundary emissions

The floor refused this branch's first head two ways, and both are cost, not
content. Fixed at the cause rather than by raising a line.

FIRST: twelve of #10692's native-only rows tipped 6-118ms over the 500ms
per-claim ceiling. They sit deliberately just under it -- the parent's last two
commits are about keeping them there -- and this branch had re-parameterized
rust_binding_spellings, which every one of them evaluates. The profile now
OVERLAYS the single key it changes (map_insert over the Rust map) instead, so the
base map is byte-for-byte what it was and every claim already sharing one
evaluation of it keeps sharing exactly that one. A profile's delta belongs to the
profile; charging every other witness for it was the defect.

SECOND: this branch's own three claims were INTERRUPTED BEFORE VERDICT at
~1200ms each -- a full ingest-assemble-infer-emit walk per claim. Split by an
ingest-only/assemble-only probe pair, the disk read and its content-hash
verification cost 0ms and assembly costs 878ms, so the recompute was assembly,
three times, of a pure function of one file's content. Two repairs, both the
roster's own named one:

  The emission claims now run over direct_rust_door_specimen_resolved, the
  already-warm-enrolled producer of a resolved add-shaped module. A second
  producer for a specimen of the same shape would have been the duplication that
  roster exists to end.

  The two emissions themselves (profile target, base target) are nullary
  producers enrolled warm, the same shape as produced_add_module_source. Each
  claim is then a string comparison, and infer+emit is evaluated once at
  preparation rather than three times inside three budgets.

THE READ IS CLAIMED SEPARATELY, because it is a separate fact and it is free
(0-5ms): the committed fixture reaches source_ref_for_observed_storage_path and
source_root_ingest_from_source_refs, whose content-hash verification is the seam
no enrolled claim covered -- the door's specimen carries its module source
inline. The assertion is a containment, not a whole-text golden, so editing the
fixture's prose is not a test failure (a change detector, not a check).

claim_batch over the entry: 5/5 PASS. The emission claims read the door
specimen, so the expected sources name its declaration (`add`) rather than the
fixture's.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_011X5tyxfVrw3chDNbQ3sVD3

* The probe file states the seam it is actually the subject of

Review 62939 is right, and the gap is exactly where it says: the fixture's own
annotation still described the enrolled fact as disk -> ingest -> assemble ->
infer -> emit. That was true when written and stopped being true one commit
later, when the three emission claims moved onto the door's warm-shared resolved
specimen to fit the floor's per-claim ceiling. An annotation describing a route
no claim executes is DESIGN section 5's specification-without-execution, and it
is worse than absent because it reads as coverage.

The file now states what it is the subject of -- the storage-read seam, claimed
by the two read claims over the bytes actually on disk -- and says outright that
no claim ingests, assembles, infers or emits it, with the reason the split
happened. The two facts stay separate on purpose: the READ is claimed over a real
file, the two target-profile SELECTIONS over the shared specimen, and neither
claim covers the other.

No behavior changes; the claims are unchanged and still PASS.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_011X5tyxfVrw3chDNbQ3sVD3

* One measurement, one home: the claim file names the instrument and stops transcribing it

Review 62942 caught the drift as it happened. The same measurement -- these three
claims against the per-claim ceiling -- was transcribed twice in one diff, into
the test file and into the enrolment row, and the two copies already disagreed
(713-805 against 713-834). DESIGN section 6 forbids exactly this: name the
producer that re-derives a measurement, never copy its numbers into prose,
because a transcribed number is unreachable from the run that owns it and rots
without either end being touched. The disagreement is that rot arriving on day
zero.

The figures now live once, at the enrolment row in
v2.workflow.floor_pure_producer_share, which is where the ceiling arithmetic is
argued and where every neighbouring row already argues its own. The test file
names the instrument -- claim_batch's [witness] receipt over this entry, with the
ingest-only / assemble-only probe pair that splits the pipeline -- and states the
shape of the fact (unshared, each claim costs multiples of the ceiling; the read
pair is the cheapest in the file) without restating a number beside it.

Claims unchanged: 5/5 PASS.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_011X5tyxfVrw3chDNbQ3sVD3

* The…
briansrls added a commit that referenced this pull request Sep 10, 2026
… taxonomy, admission, enrolment gate (#10882)

* Land the add-slice per-stage verdict instrument named as the floor_expected_red note's producer

The add-slice roster note in v2.workflow.floor_expected_red carried a dated
receipt (main 3a8344b5c: infer accepts dag_add_emitted_root; the
infer-then-translate composition refuses headed by infer_grounding_not_derived)
and named its own next-rung trigger: a .dag entry returning the per-stage
verdicts for one root, so the paragraph can name a producer instead of a
commit.

v2.compiler.self_host.candidate_generation_stage_verdicts is that entry,
parameterized over root and target: the receipt's verdict vocabulary
(infer_accepted / infer_rejected; candidate_accepted or the rejection head
reason) plus the carried-reasons lists -- the half the verdict symbols cannot
say, namely that infer accepts while carrying the frontier diagnostic on its
accepted path, so the enrolled witness's d == None conjunct fails even where
the composition reaches acceptance.

v2.test.execution.self_host_candidate_generation_stage_verdicts binds the
instrument to the slice's own fixture, with add_slice_stage_verdicts_entry the
runnable gunbc run --function form (ExitSuccess only when infer accepts clean
and the composition accepts clean). Two witnesses: infer-accepts as a
permanent positive control, and the frontier-state pin that is expected to red
the day the add-slice stall's trigger lands, flipping to a permanent
regression control in the same change that removes the roster row (DESIGN
4b(4)).

Measured by execution on this branch: the entry exits 1 printing
infer=infer_accepted, infer_carried=[infer_grounding_not_derived x10],
composition=infer_grounding_not_derived, composition_carried=[x11] -- the
receipt reproduced, with bind_outcome's pending-plus-gate chain counted. Both
witnesses PASS; the enrolled semantic witness still fails as enrolled.

Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>

* Derive grounding for dag declared inhabitants: the add slice greens end-to-end

infer gains the declared-inhabitant membership derivation: a node declared in
the dag language authority's declared-inhabitants roster derives its grounding
by lookup, with the roster as evidence -- the namespacing answer to the atom
authority question, at specimen scope. The add slice's ten type-spine nodes
(Arrow, Conj, Atom) are all roster members, so:

- candidate_generation_translate_self_emit_dag_add_slice_holds passes; its
  floor_expected_red roster row and per-row note delete per the roster's own
  stale-quarantine arm
- the dag same-language ingest path compiles end-to-end: cross_language_compile
  accepts, byte-equal to the authority's own serialization, no carried
  diagnostics
- the add-slice stall narrows to its four python/typescript round-trip members;
  the original trigger's causal clause was refuted by execution and is restated
  against the grammar parse-product population
- the instrument's frontier guard flips to add_slice_composition_accepts_holds
  (DESIGN 4b(4): frontier guard to permanent regression control)
- five manual witnesses flip with it: two root flips rewritten to assert the
  green state, three transitive conjunctions updated

The kinds stay frontier: non-member Arrow/Conj/Atom specimens carry
GroundingNotDerived exactly as before, and all fourteen enrolled
refusal/acceptance controls pass unchanged. The door's production path still
reds inside rust emission, untouched by this rule.

Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>

* Derive grounding for canonical binding atoms: dag_binding_denotation joins binding to inhabitant once

The resolver already binds the surface spelling Int to the canonical binding
symbol dag_binding_type_int; what that binding DENOTES is the Int inhabitant
declared at dag_declared_inhabitants_core. Every hand-rolled fixture facts
lookup re-authored that join (dag_add_canonical_grounding_for,
record_construct_canonical_grounding_for). The language authority now declares
it once as dag_binding_denotation, and infer_node_facts consumes it: an Atom
whose identity is a canonical dag binding with a declared denotation derives
with that denotation as its grounding evidence.

Direct-rust-door specimen census: 14 underived -> 10 underived (the four
dag_binding_type_int atoms derive; grammar-production atoms, algebra atoms,
bare operand atoms, and the arrow/conj spine stay on the frontier unchanged).

Specimen-scope interim in the same frame as
infer_node_declared_in_dag_inhabitants: both delete in favor of consuming
resolution output when the resolver hands infer declaration-resolved
identities directly (the namespace migration's completed state).

Witness: v2.test.execution.dag_binding_denotation — all four Int binding
atoms in the door specimen derive with dag_int_inhabitant_node() as
structural evidence, and the two bare operand atoms stay GroundingNotDerived
(boundary control). Refusal suite 14/14, ingest bridge 7/7, add-slice
instruments 2/2 green; every remaining red in the at-risk population
reproduces identically on the pre-change tree and is enrolled in
floor_expected_red.

Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>

* Add v2 self-host direct-path orientation: axes, sequence, autonomy contract

A point-in-time orientation that defers to the existing authorities
(DESIGN section 7, the four-wave self-host program, the roadmap node
chain, the three frontier carriers, the guarantee-stall roster, XL-N)
rather than restating them: state is re-derived by the named
instruments, never transcribed here. Sequences the remaining work in
roadmap order (door, parse-product grounding, first behavioral module,
XL-N milestones, native bootstrap, fixed point, v1 deletion) and states
which decisions stay operator-gated.

Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>

* Derive grounding for fully-evidenced Conj and Arrow products

The sixth and seventh kind rules: a non-roster Conj or Arrow whose every
child carries DerivedGrounding derives, its evidence the same shape
re-formed over the children's grounding evidence (a fresh
OccurrenceSynthetic node, never the source — the self-evidence wall holds
by construction). A product with any frontier or absent child stays on the
frontier with its typed diagnostic; a childless product has no evidence to
compose and stays frontier. Roster members keep their roster evidence.

Measured on the direct-rust-door specimen (scratch probe, uncommitted):
10 underived of 15 -> 6. The parameter conj, the module-structure conjs,
and the bodied add arrow derive; what remains is the algebra atoms from
the + operation (AlgebraPrimitive, ring_field_add), the module atom
(dag_surface_module), the parameter references (x, y), and the
grammar-projection root conj that cascades once they land.

Enrolled witnesses (src/v2/test/claim/execution/infer_product_introduction_test.dag):
- product_introduction_derives_fully_evidenced_products_holds — census:
  4 Conj (3 derived, 1 frontier-by-frontier-child) + 1 Arrow (derived).
- product_introduction_composed_evidence_carries_child_groundings_holds —
  the params conj's evidence is a Conj whose x/y children target the dag
  authority's Int inhabitant.
- product_introduction_leaves_childless_conj_on_the_frontier_holds —
  boundary control via direct infer over a hand-built childless Conj.

Flip census (pre- and post-change, zero unexpected flips):
translate_underived_refusal 14/14, infer_self_grounding_wall 12/12,
branch_infer_if_then_else 2/2, compile_eval_thesis_proof 6/6,
ingest_bridge 9/9, cross_language_add_python_to_typescript 4/4,
inhabitant_neutralization 6/6 + e2e 6/6, emit_host_classical_not 14/14,
dag_binding_denotation 2/2, stage-verdicts instrument 2/2,
dag_add_emit_round_trip 4/6 (the 2 enrolled reds unchanged), door
production group still enrolled-red (unchanged).

Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>

* Ground canonical-operation and grammar-production atoms by authority roster membership

Two more specimen-scope derivations in infer_node_facts, both lookups into
declared authorities, never inventions:

- Canonical-operations roster (target_model.dag): every CanonicalOperation
  the target-model authority declares, rendered by
  target_model_canonical_operation_wire_node and gathered under one Conj
  root. The resolver canonicalizes surface operators (e.g. +) to those
  declared operations, so the wire atoms -- the operation discriminant and
  its field references -- derive by membership with the roster root as
  evidence. General over all 14 declared operations, not add-narrow.

- Grammar-productions roster (dag.dag): every production in
  dag_grammar_root() projected to its emitted surface atom under one Conj
  root keyed by production name. The bridge projects a production's parse
  into (identity atom, captured content) pairs, so the identity atom
  (dag_surface_module) derives by membership with the roster root as
  evidence. The roster derives from the grammar root, so a production
  added to the grammar joins by construction.

Both roster roots are Conj nodes, never structurally equal to any member
atom, so the self-evidence wall holds by construction (the first attempt
at the operations rule used the wire node itself as evidence and was
refused by grounding_evidence_is_source -- the wall doing its work).

Measured on the direct-rust-door specimen (scratch probe, uncommitted):
6 underived of 15 -> 2 (only the operand atoms x and y remain; the
grammar-projection root conj cascades once the module atom grounds).

Enrolled witnesses (infer_atom_grounding_rules_test.dag): each roster rule
pins derivation + evidence identity + census; a boundary control pins that
a bare atom with no authority membership stays frontier; the closing
control pins the 2-of-15 state.

Flip census: the product-introduction census witness updates 3->4 derived
conjs (the top conj now cascades) and gains a hand-built
partially-evidenced boundary control to replace the in-specimen one the
cascade consumed. Full battery otherwise unchanged: refusal suite 14/14,
grounding wall 12/12, instrument 2/2, binding-denotation 2/2, round-trips,
bridge, cross-language, neutralization, emit-host all green; enrolled reds
unchanged.

Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>

* Ground binding-reference atoms from the enclosing arrow's domain declaration

The fifth specimen-scope derivation, closing the direct-rust-door
specimen's inference frontier: an Atom whose binding an enclosing arrow's
domain declares derives with the declared domain type as its evidence --
the declaration-site annotation, itself derived (x: Int grounds the x
reference). This is the same lookup the branch-operand path already
performs (infer_find_arrow_domain_type_in_tree), now written to the
operand atom's own facts; it is scope-naive (whole-tree, first match),
recorded in the frontier note, and deletes with the other specimen-scope
rules when the resolver hands infer declaration-resolved identities. The
tree is threaded through the fold's init chain to reach infer_node_facts;
the helper had exactly one caller.

Measured on the door specimen (scratch probe, uncommitted): 2 underived
of 15 -> 0. The specimen's inference frontier is fully closed, and the
production observation advances from InferenceRejected
(infer_grounding_not_derived) to EmissionRejected
(target_use_site_ownership_lookup_miss) -- a new, typed, located deficit
in the emitter, the next gate on the path.

Flip census (all three rewrites verified by execution):
- dag_binding_denotation_leaves_unbound_operand_atoms_on_the_frontier_holds
  -> dag_binding_denotation_declares_no_denotation_for_operand_bindings_holds:
  the boundary moves to the authority itself (the denotation table returns
  Absent for x/y), true regardless of infer's other rules.
- The three emit_host classical-not refusal guards (canonical, staging,
  staging-swapped) flip to acceptance witnesses pinning the emitted text's
  shape -- the real-infer tree now fully derives, and the emission is the
  same one the equals-eval witness proves behaviorally correct. The
  translate-refuses-underived behavior stays enrolled on hand-staged
  fixtures in translate_underived_refusal_test.dag (14/14 green). The
  renames are carried into the commit_workflow and witness_deferral_freeze
  rosters.
- New witnesses: binding_reference_derives_parameter_atoms_holds (evidence
  is the domain's Int binding atom, census 2) and
  door_specimen_fully_derives_holds (0 frontier of 15).

Full battery at this state: refusal suite 14/14, grounding wall 12/12,
instrument 2/2, binding-denotation 2/2, product-introduction 4/4,
atom-rules 5/5, emit_host 14/14, round-trips 4/6 (2 enrolled reds
unchanged), bridge 9/9, cross-language 4/4, neutralization 6/6 + e2e 6/6,
branch 2/2, eval-thesis 6/6; door production group still enrolled-red
(unchanged).

Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>

* Green the direct-rust-door: route emission through produced-decl composition and decode canonical operator wires

The door specimen's inference frontier is fully closed, so its production
observation now reaches the emission stage. Two defects surfaced there, both
fixed here:

Emission composition. generate_rust_emission_candidate served two lanes with
one root shape: the door's production path (a dag module shell) and a fixture
lane (a bare rust Arrow). The translate ownership gate queried the module
atom's ownership at a struct-field use site and refused with
target_use_site_ownership_lookup_miss, because the module's grammar-projection
conj was misread as a type record. The door's real composition is the
produced-decl path: collect declaration conjuncts from the inferred tree and
emit via emit_produced_decl. A new generate_rust_module_emission_candidate does
exactly that, enforcing an exactly-one-declaration admission policy
(rust_module_emission_decl_absent / _ambiguous). The observation and production
mint paths switch to it; the fixture-lane candidate is retained with a note
that it is fixture-only. A pure collector, produced_decl_conjs_in_tree, finds
nodes of produced-decl shape (a Conj whose first child is a Named edge to an
Arrow). Its decl-head match routes through a declared FreeMonoid<Edge>
parameter because the v1 seed stamps pattern variables from a declared
parameter type, not from a field-access scrutinee.

Operator decode. With composition fixed, source fidelity still refused: the
door emitted fn add(x: i32, y: i32) -> i32 { AlgebraPrimitive(x, y) } instead
of { x + y }. Resolution canonicalizes a surface operator atom into a
canonical-operation wire node, so a production tree's transform operator
position carries the wire, while fixture trees that bypass resolution still
carry the surface token atom. translate_project_transform_in_arrow_scope only
knew the surface-token table, so the wire missed and fell to callable apply,
rendering the discriminant identity. The projection now tries the wire decode
first (canonical_operation_from_wire_node) and only on a wire miss falls to
the surface-token table, then to callable apply; the arms are disjoint, so the
dispatch adds no fallback widening. target_transform_operator_child extracts
the operator child safely.

The door's closing expectation now greens by execution, so its known_red_probe
row in explicit_witness_admission is deleted per its own dissolution condition,
and the roadmap authority note, the door contract note, and the direct-path
plan are updated to record the green state. realized_closure_for_v2_direct_
rust_door_emit_run's module list reflects the produced-decl route.

Verified by execution: the door witness greens; the fixture, containment,
algebra, produced-decl, add-slice, and classical-not witnesses stay green;
claim_executor required-ci lanes build and witnesses both exit 0; cargo fmt and
clippy --all-targets -D warnings are clean. One pre-existing red,
witness_projection_is_active_only in the floor_cost_debt containment roster,
reproduces on the base revision and is unrelated to this change.

Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>

* Close the parse-product grounding frontier: widen declared-inhabitant membership to the closed ingest set

The declared-inhabitant roster-membership derivation in 04_infer generalized
from the dag roster to the closed ingest set (dag, python, typescript):
infer_node_declared_in_language_inhabitants returns the declaring authority's
roster root as evidence, with deep subtree membership so a declared
inhabitant's leaf fact atoms derive exactly as the inhabitant node itself.

Measured: the python fixture's 19-node frontier and the typescript fixture's
28-node frontier both close to zero; all four add-slice stall population
round-trip witnesses green; the python->typescript cross-language compile
accepts, byte-identical to ts_source_text.

Section 4b(4) flips (expecting-red probes becoming permanent regression
controls for the acceptances):
- cross_language_compile_refuses_canonical_underived_holds ->
  cross_language_compile_python_to_typescript_round_trip_holds
- inhabitant_neutralization_emit_after_neutralize / same_flavor_python /
  go_int64_to_ts refusal helpers -> round-trip controls
- inhabitant_neutralization_python_to_ts_cross_language_compile (e2e) ->
  round-trip control; python->go members stay refusal guards (go is outside
  the closed ingest set)
- cross_language_emit_inhabitant_neutralization_refuses_underived_holds ->
  round-trip control; the python->typescript emit-matrix row reads ChainProven

The add-slice stall's next-rung trigger fired, so it retired per DESIGN
4b(4): removed from all_guarantee_stalls, row file deleted, witnesses stay
enrolled.

Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>

* Promote the add family to SelfEmittedNative: native-only verdict witness for the emitted add crate

First InterpreterRetained -> SelfEmittedNative promotion after classical_not,
executing the v2-emitter-first-behavioral-module first slice at the
coverage-frontier grain: the add family (fewest dependencies — integer
literals plus one canonical operation) now carries a native-only verdict
witness, so its behavior is established by the emitted crate's own stdout
with eval() unreachable from the verdict path.

- emit_host_native_only_add_holds: real emit -> cargo build -> native run,
  stdout pinned to the family's expected octet, sharing the kernel family's
  one-build cache key exactly as the classical_not arm shares its family's
  key (no duplicated cold build).
- emit_host_native_only_add_wrong_octet_mismatch_detected_holds: the broken
  control — a no-eval verdict has no oracle leg to break, so the expectation
  side breaks (an octet the run never produces must not match); program-side
  discrimination stays with the family's equals_eval primitive-five/six pair.
- The add coverage row flips disposition with its backing citation enrolled
  by construction (the verdict entry is file-grain enrolled in
  falsifier_self_host_wet_template_entries).
- Frontier census tests updated at identity grain: natives are exactly
  {classical_not, add}; split 2/13.

Verified by execution: all six native-only verdict tests green locally
(real wet legs — compile_skipped receipts show cold builds and native runs);
all eight emit_coverage_frontier tests green, including the unbacked-claim
RED control.

Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>

* Record the add-slice defect's repair in the declined-live-tree classification

The row classified candidate_generation_translate_self_emit_dag_add_slice_holds
as RealDefect/CompilerBehaviourRefusal with measured evidence that translate
refuses infer_grounding_not_derived. The owner lane (v2 self-host) repaired the
subject: the declared-inhabitant roster-membership derivation grounds the
slice's type spine by lookup, and the witness passes under claim_batch
--hermetic on the merged tree. The dated classification is kept verbatim; the
disposition flips RoutedToOwner -> RepairedInThisChange with the repair
measurement appended to the evidence, so the routing carrier stops dispatching
a fixed defect. Structural witnesses (count 13, no NotReproduced, exact
partition) are untouched and pass.

* Hoist two in-body annotation blocks to module-item grain

Main's annotation-placement wall (source annotations admit only standalone
leading blocks attached to module-scope declarations; in-body forms refuse)
reached this branch through the merge and refused 8 blocking errors on the
00_compile closure: the add-family promotion note inside the
emit_coverage_frontier_roster list and the python->typescript row note inside
the cross_language_emit_matrix list. Both blocks move above their enclosing
declarations, rephrased to name their subject row. Measured: gunbc compile of
src/v2/compiler/00_compile.dag now emits 172 files with 0 blocking errors;
both files' suites stay green (8/8 and 4/4).

* Promote the complement family to SelfEmittedNative: native-only verdict witness for the emitted logic family crate

The complement family's native execution runs family-grain per the
witness_family_build_grain_ruling (one crate for meet + join + complement,
argv-dispatched), so the native-only arm emits the logic family crate and
runs the complement member through the family dispatcher, sharing the
family witness's one-build cache key. The verdict is decided solely by the
emitted native run's stdout (expected octet 0, complement(True) = False);
the broken control flips the expectation side (octet 1 can never match),
with the comparator pinned by the stdout mock pair. Program-side
discrimination stays with the equals_eval agreement pair and the family
witness's all-alt leg.

The frontier row's backing citation lands in the already
file-grain-enrolled native-only verdict entry, so it is enrolled by
construction; the roster comment is rephrased to cover both 2026-09-07
promotions (add and complement). The frontier test's split and native
membership assertions move to 3 native / 12 retained.

Verified by execution: claim_batch --hermetic on
emit_host_native_only_verdict_test.dag passes all 8 witnesses (the two
new complement arms included), and emit_coverage_frontier_test.dag
passes all 8.

* Key the emitter's host-String arm on declaration provenance, not spelling

is_host_text_carrier_type answered true for any type expression whose
authored name reads "String", including references to the structural
alias v2.std.text.String (type String = FreeMonoid<Char>) that the
namespace lane (gunbc#9907) requalified the v2 corpus's text-carrier
fields to. The emitter rendered every one of those references as the
host String while value-position consumers rendered the structure -- the
E0308 family dominating the self-host compile-phase frontier (41 of 64
in v2_compiler_tokenize.rs on the post-merge board).

The String arm now consults the resolved declaration's provenance
against v1.compiler.coercion structural_declaration_modules_for -- the
same roster type_realization_decision reads -- so the legacy arm and the
strict decision cannot diverge on one node (DESIGN section 3, and
gunbc.recurring_failure_mode alias_resolution_collides_with_kernel_spelling).
Kernel mints and unresolved references keep the host answer exactly as
before.

Regen: the only drifted stage0 mirror is v1_compiler_emit_rust.rs
itself (no module in the stage0 closure references a structurally
declared String -- verified by the whole-population candidate tree),
installed from target/stage0-regen-candidate after the priced round's
partitioned rebuild refused MirrorHasNoOwningPackage on the emitter
(the emitter is monolith-shell, not partition-owned). Fixed point
verified by execution: claim_executor --required-regen on the rebuilt
seed reports first_generation_equal=true over 158 adjudicated mirrors.

* Peel qualified String alias leaves in field position: XL-N closure 72 -> 28 errors

A field authored v2.std.text.String reached the Rust emitter as an overlay-less
resolved reference leaf and rendered the bare terminal name, which binds the
prelude String cross-module (#9813: kernel names are never overridden by
imports, so the use-line is dropped) while every value position renders the
structural carrier Rc<Vec<i64>> -- the v2_compiler_tokenize.rs E0308 family,
41 of 72 errors on the XL-N phase board.

The new rust_overlayless_alias_leaf_requires_peel arm in
render_rust_type_without_applied_binding detects the population (overlay-less
zero-parameter alias leaf, qualified spelling, String terminal segment,
closed_alias_peel_verdict agrees) and renders the alias declaration's resolved
right-hand side, projecting the same realization the fn-signature positions
already produce.

The qualified gate is load-bearing: inside the declaring module the bare name
is the correct render (the emitted module carries the alias declaration), and
the local binding's resolved_type drops the RHS type argument, so an ungated
peel rendered Rc<FreeMonoid> there (E0107 x13, E0282 x2 on the probe). Bare
String keeps denoting the kernel scalar through the host-carrier arm.

Measured: probe specimen (qualified/bare/direct-FreeMonoid/container/variant/
local-alias positions) compiles clean; XL-N compiler closure cargo check
72 -> 28 errors with the residual census dominated by the declared
text_boundary_identity_wall class (kernel String vs structural carrier at
bare-authored boundaries, 17 of 20 E0308s); v1-corpus fixed point holds
(first_generation_equal=true, 158/158 adjudicated).

* Resolve the 12 non-hop XL-N closure errors at source: text-wall conversions + witness_violates helper

Four clusters, all measured non-hop additions between receipt_1 (155) and the
post-peel census (28); the live gate now measures 15 with zero unadmitted
regressions:

- integer.dag: integer_string_to_decimal_digits_step takes v2.std.text.String;
  the public boundary converts with chars() (text_boundary_identity_wall
  specimen discharged at this site).
- 01_tokenize.dag: Token/UnboundSourceAnnotation lexemes convert structural
  -> host String with chars_to_string() at construction, mirroring the v1
  tokenizer's host-lexeme carrier.
- target_model.dag + bash.dag: EmitSpellingEscape.from/to and
  apply_emit_spelling_escapes go structural (v2.std.text.String); the
  EmitSpellingQuote arm converts host->structural->host at its boundary;
  bash's escape rows wrap their kernel String literals with chars().
- witness.dag + 3 call sites (collection list_nth, provenance
  span_index_resolve_textual_locus_from_ids, compile outcome_with_diagnostics):
  new witness_violates<C> helper puts Violates constructions in a
  Witness-headed position so the emitter resolves the carrier type argument;
  dissolves once inference records per-call substitutions.

Verified: 48 targeted claim witnesses green (tokenize behavioral, shell
conformance, string brace escape, string length, map-lookup violates, source
text ingress, bash materialize x12, int literal smoke x6, provenance span
index x2).

* Record receipt_2 on the self-host compile-phase frontier: 15-error census at 66765317ec

The census at the XL-N lane tip: 155 -> 15 net, credited to the qualified-alias
peel (60cbd7b697, 72 -> 28) and the twelve-error source cluster (66765317ec,
28 -> 15). The epoch changes on the instrument's target pinning (found by
review on gunbc#9857), admitted with receipt_1's board as the reclassified
predecessor under the identity map. Nine added identities are hop relocations
admitted by the hop index; four sit in python/typescript modules newly entered
into the emitted closure, admitted as ExposedByNewEmittedModule.

Validated: all 36 self_host_compile_phase_frontier_witness claims PASS,
including current_persisted_compile_phase_frontier_holds.

* Emitter: a substituted declaration node carries its own provenance

Inference substitutes the resolved declaration into a data annotation's
type-argument position, so BooleanAlgebra<v2.std.logic.Bool> reaches the
emitter with the arg BEING the type Bool = True | False declaration itself
(Disj connective, ident_span in src/v2/std/logic.dag, no Resolved wrapper).
type_reference_provenance_in_env's bare-leaf arm re-resolved that leaf in the
REFERENCING module's scope, where post-#9813 a kernel-shadowed spelling
answers the kernel declaration -- so the structural enum rendered as host
bool against a value of BooleanAlgebra<Bool> (the python.rs:328 /
typescript.rs:177 E0308 pair on the XL-N compile-phase frontier).

The connective is the discriminator: a reference node is a bare name
(NoConnective); a node carrying Conj/Disj structure IS the declaration, and
type_reference_provenance's own-span fallback already answers that shape
correctly. The guard routes declaration-shaped nodes there directly, bypassing
the scope lookup that #9813 makes answer the kernel.

Mirror regenerated via the regen round; fixed-point verified
(claim_executor --required-regen PASS).

* Clear the remaining XL-N closure errors at source: carrier conversions at the boundaries

The receipt_2 census's fifteen identities, resolved at their sources:

- lexing.dag, dag.dag, python.dag, typescript.dag: LexPattern.text is the
  structural carrier (v2.std.text.String); the construction sites held host
  Strings. Convert at construction with chars() -- the #9907 ingress pattern.
- python.dag / typescript.dag bool groundings: qualify the annotation as
  BooleanAlgebra<v2.std.logic.Bool>; with the emitter's substituted-
  declaration provenance guard the qualified arg now renders structural.
- target_model.dag: target_lex_rule_literal_step returns the host carrier
  (chars_to_string over the structural pattern text); TargetText.source
  converts at the is_empty boundary; the unicode-scalar symbol intern converts
  its single-codepoint list to the host carrier.
- qualified_name.dag: qualified_name_from_dotted_string uses the host-carrier
  emptiness check (string_length == 0) instead of routing through the
  structural string_is_empty.
- 02_parse.dag: parse_looks_like_match_arm_start rewritten on host-carrier
  operations (string_length, char_at, code_point) rather than converting to
  the structural carrier for a two-character lookahead;
  parse_char_is_arm_pattern_lead takes the codepoint Int directly.
- v1_interpreter_primitive_surface.dag row_key: the concat pipeline lowered
  to a .concat() method call on std::string::String (E0599); rewritten as
  nested concat calls.

Measured: the 00_compile closure emits 172 files and cargo check reports
cargo_clean=true, cargo_error_population=0 under the pinned 1.93.0 toolchain.

* Pin the cargo half's toolchain channel by construction

The cargo half runs with cwd = a fresh mktemp directory; with no
rust-toolchain.toml there, rustup resolves the host's DEFAULT toolchain, so a
census under cargo 1.83 and one under cargo 1.93 would compare as equal epochs
while different compilers did the measuring -- the fabricated comparability
the target pin (gunbc#9857) excludes, one level up. Measured 2026-09-07: a
host default of 1.83.0 met a crates.io index whose freshly published
dependency manifests require edition2024, resolution failed before any
diagnostic existed, and the zero-diagnostic refusal fired on an unmeasured
tree.

The pin is propagated by copying the repo's rust-toolchain.toml into out_dir:
the file remains the sole in-repo channel authority (its header forbids a
second pinned literal), and the copy makes the measured channel true by
construction on any host. The gate's read_live_toolchain observes the same
channel because every documented actuator invokes from the repository root,
which the same file governs.

* Record receipt_3 on the self-host compile-phase frontier: the emitted closure's cargo census is empty

Measured at 5ee4892b70 by the one-entry instrument: the 172-file emitted crate
reports zero cargo error diagnostics, so the board attributes every phase a
count of zero and furthest_phase_reached stands at Borrowck. The fifteen
removals against receipt_2 need no disposition; nothing was added.

The epoch does not change: the cargo half now pins the toolchain channel by
copying the repo's rust-toolchain.toml into the scratch crate, and every
recorded comparison field is identical to receipt_2 (whose census the
fingerprint evidence shows the same 1.93.0 toolchain already compiled), so the
same-epoch arm carries no reclassified predecessor.

The frontier-state pin flips per DESIGN 4b(4):
the_published_frontier_standing_does_not_claim_typeck_or_borrowck_passed
becomes the_published_frontier_standing_claims_typeck_and_borrowck_passed, the
permanent regression control over the green state.

Validated: all 36 self_host_compile_phase_frontier_witness claims PASS,
including current_persisted_compile_phase_frontier_holds.

* chore: regenerate drifted generated artifacts (ci auto-heal)

Ledger-Repair-Judged: docs/design-failure-modes.md
Ledger-Repair-Judged: docs/design-rung-drops.md

* Remove the stale PointwisePower inhabitant rows from the four language rosters

First native-parity divergence class found by running the emitted closure on a
discriminating fixture: the algebra inhabitant rosters still carried
PointwisePower after its authority row was cut, so the emitted compiler panicked
at 12 record-shaped carrier sites while the interpreted seed refused cleanly.
The roster rows are removed in rust/python/go/typescript types.dag, the derived
coercion assertions in compiler_tests.rs regenerate without them, and two
witnesses pin the boundary: the record shape constructs its structural carrier,
and FinitePowerSet still refuses while its row stands.

Mirrors regenerated by a converged regen round (fixed point Reached, stage-1
PromoteGenerationInputs over the three language types mirrors).

* Regen gen-2 gate: compare executable digests in one spelling

The admitted side of run_built_seed_regen carries the executable-digest
spelling (current_exe_digest, next_pass_executable_digest) while the observed
side hashed the file through path_digest, which prepends the fnv1a64: tag.
Same bytes, two spellings, so the gate could never pass -- unpassable since
fa2d403dc8 (#9771). Factor current_exe_on_disk as the single path authority
and read the observed digest through current_exe_digest so both sides spell
the same bytes the same way.

* Model ReleaseScopeEmpty for release-excluded mirrors, end to end

A regen round whose only stage-2 drift was compiler_tests.rs (the PointwisePower
roster removal rewrote its derived coercion assertions) refused the rebuild
MirrorHasNoOwningPackage: the mirror is owned by no partition package, because
every item it defines is #[cfg(test)] and no release unit elaborates it. The
refusal conflated two different states -- unowned (a coverage hole) and excluded
from the release build by construction (a precise empty scope).

The model now names the class: rebuild_scope_release_excluded_mirrors rosters
its members (compiler_tests.rs, cited to emit_compiler_tests_module), the
decision answers ReleaseScopeEmpty when the whole change set is excluded, and
the actuation shape is actuatable with an empty package closure and every
partition package excluded -- the build still runs as verification, and a
compiled partition package refuses the stage. The host admits the empty closure
only when the new stage0_partition_rebuild_release_scope_empty_today query
answers true; any other empty closure still refuses. A mixed change set scopes
on its release-visible members alone.

Verified by execution: the 2026-09-08 round converged (fixed point Reached)
with stage-2 installing compiler_tests.rs alone; cargo recompiled the shell
crate on its fingerprint (the outer mod line is ungated, so rustc reads the
file) while the produced executable was byte-identical -- stage input seed
digest == output seed digest. Four new witnesses pin the arm, its actuation
shape, the mixed set, and the host-facing query's two arms; the boundary
witness (unowned cli_run.rs still refuses) keeps the roster from decaying into
the absorbing fallback.

* Round-cost receipt: project installed mirrors to the model's vocabulary

The receipt's partition-rebuild line is rendered by the model over
receipt.installed_mirrors, which the host populated from the stages'
projected_paths -- full paths -- while the partition rows and rosters key on
basenames. Every drifted round's receipt therefore rendered a spurious
RebuildScopeRefused MirrorHasNoOwningPackage line naming a full path, a false
claim on the round's own receipt. Route the projection through
emit_path_basename, the module's single path-to-basename bridge, so the field
carries the mirror names the model's vocabulary means.

* Hoist ReleaseScopeEmpty annotations to module-item grain

The ReleaseScopeEmpty modeling commit placed three // blocks inside
declaration bodies (stage0_partition_rebuild_is_actuatable,
stage0_partition_rebuild_decision, stage0_partition_rebuild_excluded_today).
The .dag realization admits annotations at module-item grain only, so the
floor lane's parse phase refused the file with 12 located errors and the
run ended floor refused. The prose is unchanged; each block now sits above
the declaration it describes.

* Spell the PointwisePower witness's finite-set exclusion as the applied realization

The witness added with the fossil-row removal excluded the bare spelling
"BTreeSet", but every emitted file's preamble imports OrdSet as BTreeSet,
so the row could never green. The exclusion's subject is the finite-set
REALIZATION the fossil row would have asserted; spell it applied
(BTreeSet<i64), which the preamble's import line does not contain.

* Emit fieldless-record data values as null for the unit-struct carrier

The second native-parity divergence class, measured 2026-09-08 on the
native run of the emitted 00_compile closure: emit_data_value_json spelled
EVERY record literal as a JSON map, including the zero-field record, while
emit_struct_from_children renders that same declaration as a Rust unit
struct (pub struct BoolEncodingFact;). serde's derived unit-struct
Deserialize reads null and rejects {}, so the emitted compiler panicked at
first touch of v2.std.logic's bool_primitive_facts: "invalid type: map,
expected unit struct BoolEncodingFact". The JSON spelling of a data value
must deserialize into the Rust type the same declaration emitted; the
record arm now spells the zero-field value null and keeps the map spelling
for non-empty records.

The mirror is taken from the required-regen candidate, not hand-edited.
Two witnesses enroll: the discriminating red (zero-field record spells
null, never {}) and the boundary control (a record with fields keeps the
map spelling).

* Bind the duplicate-definition filter ahead of its branch condition

Main's FilterInBranchCondition wall (#10699) refuses to publish a module
whose filter call sits in a branch condition, and the v2 00_compile closure
emission names primitive_duplicate_semantic_definition_violation as such a
site. The filter is pure and total; binding it with a let ahead of the
branch is the authored remediation the wall exists to force, and the
emitted closure is unchanged in behavior.

* chore: regenerate drifted generated artifacts (ci auto-heal)

Ledger-Repair-Judged: docs/design-rung-drops.md
Ledger-Rows-Repaired: docs/design-rung-drops.md rust_unit_tests_off_the_merge_path
Ledger-Rows-Repaired: docs/design-rung-drops.md determinism_transitive_reachability
Ledger-Rows-Repaired: docs/design-rung-drops.md transitional_admission_exception

* Emitter: three native-parity repairs for the post-merge 00_compile closure build

Three divergence classes measured as the 21 rustc errors on the natively
emitted 00_compile closure after the main merge, each repaired at the .dag
source with a discriminating witness:

- Locality wins over a foreign ambiguity (12 E0433 in v2_std_integer.rs):
  alias_rhs_base_module_filename asked the global leaf index, saw
  LeafAmbiguous for Compose, and emitted the poison marker even inside
  v2.std.integer itself, where source resolution binds the local
  declaration before any cross-module lookup. The local physical
  declaration now shadows foreign declarers; the poison marker still
  stands for a leaf two FOREIGN modules declare.
- The qualifier is the disambiguator (8 E0425/E0433 in
  v2_lens_fact_density.rs): the qualified use-line route declined any
  globally-ambiguous leaf, but a qualified reference names its provider
  in its own spelling. The route now resolves by DeclaredCallableIdentity
  at the qualifier, keeping the type-declared and export-proof walls.
  The dotted spelling reaches the route through the value surface (a
  qualified value projection's borrowed type stamps the match patterns'
  parent_enum); the witness reproduces that chain exactly, and its
  exclude half pins the E0603 boundary (the dotted VARIANT head must
  still be declined).
- Clone-bound forwarding is transitive (1 E0277 in
  std_realization_measurement.rs): the call-forwarding derivation
  re-derived only each callee's SELF-derived half, so a callee whose
  bound is itself forwarded re-derived to empty. The derivation now
  recurses over the call graph with the module's visited-set
  termination; the equality half stays one-hop as declared.

Witnesses: 56/56 PASS on the rebuilt seed; regen fixed point holds.

* Refuse variant record literals on the serde_json data path fail-closed

A record literal with parent_enum present is a variant construction whose
wire spelling is the parent coproduct's declared VariantEncoding policy --
a module-local fact of the parent's home module that emit_data_value_json
does not carry. The zero-field arm's null and the map arm's untagged fields
are both measured to fail serde deserialization under the internal-tag
default, so the arm now refuses and the caller renders compile_error!, a
build-time located refusal where a runtime panic on the data definition's
expect was the latent alternative. The refusal names its trigger: a
closure-wide wire-policy index beside EmitGraphInfo.type_decl_items.

Witness: w_variant_record_lit_on_the_json_data_path_refuses_fail_closed
forces the JSON path with a nested-record Holder and asserts the
compile_error! spelling while excluding the former null mis-serialization.

* Spell variant record literals on the serde_json data path from a closure-wide wire-policy index

The fail-closed refusal landed in 73b582dea6 fired on 5 real corpus sites
(SugarKey x2, CopiedPortCitationFrontierDisposition x3), proving variant
record literals reach the JSON data path in the 00_compile closure. This
change replaces the refusal with the correct spelling, driven by a new
closure-wide index:

- v1.compiler.infer_emit_info gains DataVariantWireSpelling, the
  language-general projection of a coproduct's Rust wire serde policy
  for one variant (InternalTagged { tag_field, tag } | BareString { tag }
  | Untagged | SpellingRefused { reason }), and EmitGraphInfo carries
  data_variant_wire_spellings: Map<String, DataVariantWireSpelling>
  keyed by coproduct.variant.
- v1.compiler.emit_rust builds the index once per emission root via
  build_data_variant_wire_spellings, resolving each coproduct's policy
  through the new shared resolve_emission_coproduct_wire_policy (the
  same function the type-emission side now calls, so the two cannot
  drift), projecting each variant through data_path_wire_variant_tag
  (rename_all and StripAffix aware), and poisoning collisions as
  SpellingRefused so ambiguity stays fail-closed.
- v1.compiler.emit's emit_data_value_json variant arm reads the index:
  internal-tagged spells {"_variant": tag, ...fields}, bare-string
  spells "tag" for nullary and refuses fielded, untagged spells the
  bare fields or null; unindexed keys and stored refusals remain
  compile-time errors. The service mock-property chain threads
  emit_info through so dry-run data spells identically.

Witnesses: w_variant_record_lit_on_the_json_data_path_refuses_fail_closed
is rewritten as ..._spells_the_internal_tag (asserts the internal-tag
map, excludes the former null mis-serialization and the refusal), and
w_fielded_variant_record_lit_on_the_json_data_path_spells_tag_and_fields
pins the fielded case. 57/57 witnesses pass; regen fixed-point holds.

* Promote field_access to SelfEmittedNative on the emit coverage frontier

Fourth native-eval construct promotion, after classical_not, add, and
complement. The native-only verdict arm pair lands in the already
file-grain-enrolled long/ entry, so the backing citation is enrolled by
construction:

- emit_host_native_only_field_access_holds pins the family one-build
  cache run's stdout to octet 9 (the byte the family witness's warm leg
  pins on the same build), eval() never called.
- emit_host_native_only_field_access_wrong_octet_mismatch_detected_holds
  breaks the expectation side with octet 1, the alt tree's byte.

Both arms verified wet locally (real cargo build + native run, sharing
the field_access family one-build cache key). The roster row flips to
SelfEmittedNative; the two census guards update per 4b(4) — the split
moves to 4 native / 11 retained and the identity-grain membership guard
is renamed to name the four-member population. The family's equals_eval
agreement pair stays enrolled as its program-side discrimination leg.

* Drop the scratch parity probe from the tree

The probe is a manual parity-loop instrument (the interpreted leg of the
native-vs-interpreted comparison), not a corpus declaration with an
executing consumer (DESIGN 6 experimental residue). It stays in use
locally as an untracked file.

* Promote match, loop, and fold_closure to SelfEmittedNative

Fifth, sixth, and seventh native-eval construct promotions. The three
match_loop_fold family rows flip together on one shared family-crate
arm shape, per the witness_family_build_grain_ruling: each arm emits
the three-member family crate once and runs its own member through the
argv dispatcher against the family one-build cache key.

- emit_host_native_only_{match,loop,fold_closure}_holds pin the warm
  legs' stdout to the family's declared octet lists (match/loop
  [0,1,0,0,0], fold [0,7,0,0,0]), eval() never called.
- The wrong-octet controls break the expectation side with each
  member's own alt octets (match/loop [0,2,0,0,0], fold
  [0,255,255,255,255]).

All six arms verified wet locally. The census guards update per 4b(4):
7 native / 8 retained, and the identity-grain membership guard is
renamed to witness_native_rows_closed_membership_holds so the name
stops encoding the volatile population.

* Promote meet_join to SelfEmittedNative on the emit coverage frontier

The meet_join family's native-only verdict arms land on the complement arm's
helper, generalized to take the family member_id: meet and join run through
the same argv-dispatched logic family crate (one-build cache key shared with
complement, per the witness_family_build_grain_ruling), eval() never called,
verdict decoded from stdout. Octets meet=1 join=1 are the bytes the family
witness's warm legs pin on this same build; the wrong-octet control expects
each member's alt byte (0), which the primary runs can never produce.

Both arms verified wet: cold build then warm hits, PASS/PASS. The roster row
flips InterpreterRetained -> SelfEmittedNative (eighth promotion); census
guards move to 8 native / 7 retained with meet_join_eval_subject named in the
closed membership.

* Promote variant_construct to SelfEmittedNative on the emit coverage frontier

The variant_construct family's native-only verdict arms follow the
field_access arm shape exactly: the tree is the family's own equals_eval
tree value (emit_variant_construct_eval_tree, no eval leg reachable), the
run shares the family one-build cache key that
emit_on_demand_variant_construct_native_one_build_holds colds, and the
expected octet 9 is the byte the family witness's warm leg pins on this
same build. The wrong-octet control expects the alt tree's byte (1), which
the primary run can never produce; the wrong-value alt leg in the family
witness keeps the program-side discrimination.

Both arms verified wet: cold build then warm hit, PASS/PASS. The roster row
flips InterpreterRetained -> SelfEmittedNative (ninth promotion); census
guards move to 9 native / 6 retained with
emit_variant_construct_eval_subgraph_node named in the closed membership.

* Close the emit coverage frontier: final six rows to SelfEmittedNative

The last six InterpreterRetained rows flip to SelfEmittedNative, taking the
roster to 15 native / 0 retained:

- filesystem_read and shell_exec_run (host-effect transport families, no
  translated arrow body): the arms reuse each family's own native leg with
  the expectation pinned as a literal grounded by the family's enrolled
  fixture pin (dag/extdeps/shell/exec.dag contains bash; its shell.Exec.Run
  argv materializes to exactly [bash, -s]), run through the families' fixed
  witness workspaces.
- module and produced_module: the arms execute the exact sources the
  equals_eval pairs run (emit_module over the add fixture tree;
  produced_add_module_source's ingested two-fn module), octet 5 pinned
  against the add family's primitive-five/six oracle leg.
- call and record_construct: the arms emit the families' own producer trees
  against their target models, octets 7 and 9 pinned against the
  primitive-seven/eight and wrong-field oracle legs.

The four families without a one-build cache witness run under per-family
fixed workspace roots; content-safety comes from the realization-digest
nesting in run_host_process_admitted (changed source colds, never serves
stale), the same mechanism the filesystem_read fixed workspace relies on.
All twelve arms verified wet: PASS/PASS each, cold builds then warm hits.

With zero retained rows the retained_via_eval_agreement constructor loses
its last consumer and is deleted (DESIGN 3c); the InterpreterRetained
variant stays as the disposition authority's other state. Census guards
move to 15 native / 0 retained with all fifteen decl names in the closed
membership.

* Record the emit coverage frontier closure in the direct-path plan

Axis C line: all fifteen roster rows are SelfEmittedNative as of
2026-09-08, interpreter_retained_rows() is empty, and the row constructor
was deleted with the last flip. Notes explicitly that this closes axis (a)
(witness-body-runs-native) only; axis (b) (the regen-grain production
flip) remains operator-gated.

* Model the required-v2-native lane authority: route receipt, exclusion taxonomy, admission, enrolment gate

Parallel track B (operator authorization 2026-09-09): one additional required
CI job whose subject is the compiler/test execution route itself — the
emitted-native compiler binary invoked by explicit path over a derived
v2.test.* population.

The lane is modelled in full in gunbc.witness_v2_native_route: the prefix
universe derivation, the per-member verdict rows (head + fatal reason grain),
the exclusion taxonomy delegating attribution to the door ledger's
known_frontier_causes, the counted exclusion census with a totality check,
the terminal-observation receipt carrier, the admission predicate (one
predicate per contract clause, all causes collected), and the enrolment gate
with today's standing as data.

Enrolment is BLOCKED, as data with a named capability trigger: the measured
census over the derived universe (882 members, seed withdrawn during the run)
refused every member — the emitted DirectIngestDriver admits only the
hard-coded compile_driver_subject name with empty imports, and the compile
door is at its modelled frontier — so the contracted positive population is
empty and native_route_admission over the real receipt executed to
'refused: positive_population_empty'. The exact enrolment edit (phase-roster
variants, claim_executor mirror, workflow lane, aggregate join, YAML regen)
is carried on the standing row.

The census measured five fatal-grain refusal causes the door ledger's
head-grain attribution table did not carry; they are added to
known_frontier_causes with their owning lanes (three MigrationOwned under
nimble-boar-198, two normalize/body-lowering SharedSelfHostCriticalPath).

Seventeen floor witnesses (v2.test.v2_native_route) consume the authority and
execute green through the seed interpreter.

Co-authored-by: briansrls <briansrls@gunb.ai>

* Split preparation predicates so EmittedClosureUnrecorded is reachable

Review on #10882 (briansrls, point 7): native_route_preparation_recorded
folded the seed and closure observations into one && predicate, so a
receipt with a recorded seed and an unrecorded closure misreported as
preparation_seed_unrecorded and the emitted_closure_unrecorded cause had
no reachable construction — the grain-mismatch class DESIGN 4b(3) names.

One predicate per observation, one admission clause per predicate, and
two witnesses pinning each refusal name against its own receipt shape
(including the negative: each refuses ONLY by its own name).

Co-authored-by: briansrls <briansrls@gunb.ai>

* Key cause ownership by diagnostic grain; classify native refusals at fatal grain

The door ledger's known_frontier_causes was a head-grain authority; the
native route classified fatal reasons through it, crossing grains (review
on #10882). Generalize the ownership key with DiagnosticGrain so one
table answers both grains: the door ledger's cause_is_attributed keeps
its head-grain contract, and the native route's exclusion classifier
asks the fatal-grain question of the same table. The head advisory is
live receipt data again: every refused row's head reason must be owned
at head grain (or by this lane's driver-limit roster), and an unowned
advisory blocks admission by its own clause name.

Co-authored-by: briansrls <briansrls@gunb.ai>

* Hoist known_frontier_causes row-group notes above the declaration

The grain-keyed ownership change left its row-group commentary inside the
list literal; the annotation channel admits only module-item grain, so the
emitted closure refused with nine annotation-grain diagnostics. Move the
notes to a single block above the declaration. No semantic change.

Co-authored-by: briansrls <briansrls@gunb.ai>

* Parse test fn as a contextual production in the v2 dag grammar

The emitted native compiler could not parse any v2.test.* module: the
modeled dag grammar had no test fn production, so every floor witness
module refused with parse_g0_tokens_remain (706 of 882 in the census).

test stays an ordinary identifier — typescript/program.dag models the
TypeScript compiler's Cond.test field under real-upstream-names — so the
production is the contextual sequence(ident, fn_decl): a new choice arm
in top_level_item with no FIRST overlap with the keyword-led arms, a
body-lowering arm that lifts the nested fn member after checking the
marker lexeme is literally test (a typed refusal otherwise), and a
forward-producer row for the new surface identity.

Verified against the emitted native binary: probe_testfn.dag moves from
parse_g0_tokens_remain to resolve_module_not_found (the driver's
synthetic-subject limit, identical to a plain fn), and the standing
choice-overlap residue roster is unchanged at seven rows.

Co-authored-by: briansrls <briansrls@gunb.ai>

* Add SourceRootEvalDriver: native whole-ingest test-execution route

The required-v2-native lane's terminal subject is an exact test identity
reaching a native Eval verdict, not a module accepted for translation.
DirectIngestDriver (one source, no peers, synthetic subject) stays as the
front-door census instrument; the new driver renders a main that reads a
host-derived universe of qualified test identities plus the declared
source roots, assembles the ingest once, prepares each module (resolve +
infer), and Evals each named test body -- one typed verdict row per
member, with a prepare-refusal fan-out so no member is silently dropped.

Co-authored-by: briansrls <briansrls@gunb.ai>

* Escape literal braces in SourceRootEvalDriver main.rs template

The .dag string lexer reads '{' followed by an identifier as
interpolation, so the emitted Rust use::-import lists and format!
captures must spell literal braces as \{ \}. The single parse error
desynced the file parse and cascaded into 2618 unattributed-annotation
errors; with the escapes the emitter compiles clean (0 blocking, 107
files emitted).

Co-authored-by: briansrls <briansrls@gunb.ai>

* Collect per-file front-end refusals in the native test context fold

The SourceRootEvalDriver's context fold reused program_assembly_fold_ingest,
which is wholesale fail-closed: one source hitting the v2 front-end's live
corpus frontier would deny verdict rows for every other universe member. The
fold now collects each source's tokenize/parse/normalize refusal as a
NativeTestFileRefusal row (head and fatal reason grains, matching the door
ledger's grain-keyed ownership) and keeps folding; a refused file contributes
no root, so its test identities surface as Context-stage refusal rows and
nothing is widened. The emitted main.rs prints the file-refusal rows and
counts them in the terminal marker, and prepare/eval refusals now classify at
the fatal (last diagnostic) grain consistently.

Co-authored-by: briansrls <briansrls@gunb.ai>

* Add native lane control fixtures

Two controls for the required-v2-native lane's host harness:
src/v2/native_lane_fixture/control.dag carries the live-verdict pair (a
well-formed false control and its true positive half) as plain fns outside
the v2.test. prefix, so floor discovery enrolls no universe rows for them;
fixtures/native_lane_malformed/poison.dag is a deliberately unterminating
string that any honest front-end must refuse at tokenize, kept outside every
declared source root so the broken bytes never enter an honest ingest.

Co-authored-by: briansrls <briansrls@gunb.ai>

* Fix Vec/Vector type mismatches in the SourceRootEvalDriver main.rs template

The emitted driver crate aliases im::Vector as Vec, so the template's
std Vec-typed bindings and collect calls failed to compile in the
emitted crate: universe rows and module order carry Rc<Vector<String>>,
the reads vector moves into the FreeMonoid parameter with .into(), and
the dotted module name is built from an iterator collect.

Co-authored-by: briansrls <briansrls@gunb.ai>

* Harden the v2-native route contract: test-identity grain, exact join, paired reference

Reframe the terminal subject from module-grain acceptance to the exact
test identity reaching a native verdict. The receipt's universe is a
list of qualified NativeRouteTestIdentity rows; the observed population
joins it exactly (uniqueness, no foreign rows, no omissions); every
member verdict is paired against the floor's own expected-red and
route-gap rosters for agreement, exclusion, or divergence; refusals are
classified from stage and provenance with cause ownership at fatal and
head grains; and the four controls (true, false, malformed specimen,
old-route withdrawal) are admission clauses. The 46 tests cover
universe derivation, identity qualification, reference pairing, refusal
classification, disposition, census counting, and every admission
clause.

Co-authored-by: briansrls <briansrls@gunb.ai>

* Wire the required-v2-native lane into the roster, workflow, and aggregate

Add V2NativeLane/V2NativePhase to the required-CI roster, the lane's
claim_executor command to fabric_witness_run, and the
required-v2-native job to the witness floor workflow with the aggregate
witnesses job needing it in both verdict arms. Regenerate
witnesses.yml.

Co-authored-by: briansrls <briansrls@gunb.ai>

* Add the required-v2-native host harness and phase dispatch

The lane's one phase derives the v2.test.* universe with the floor's
own discovery producer over the full module inventory, prepares the
emitted-native compiler through the emit-compile phase's crate writer
and cargo invocation, withdraws the old-route gunbc binary for the
spawn window, runs the emitted binary by explicit path over the
universe plus the named controls, reclassifies context-stage refusals
against the observed file refusals, mints the NativeRouteReceipt as the
authority's own types, and hands it to native_route_admission for the
verdict. claim_executor gains the V2Native lane and phase with the
roster sizes moved to six.

Co-authored-by: briansrls <briansrls@gunb.ai>

* Regenerate stage0 mirrors for the SourceRootEvalDriver emitter arm

std_compiler_entry.rs gains the SourceRootEvalDriver variant and
v1_compiler_emit_rust.rs the emit_source_root_eval_driver_main_rs
template with its dispatch arm, emitted by the regenerated seed and
verified at the fixed point (first_generation_equal=true over the whole
155-module population).

Co-authored-by: briansrls <briansrls@gunb.ai>

* Name the probe crate's lib target v1_compiled, the emitter's self-name contract

emit_rust_selected binds the self-emitted crate's name to v1_compiled
for every non-retained-host pipeline entry, and the SourceRootEvalDriver
and DirectIngestDriver mains reach the closure through use v1_compiled::.
The probe manifest's per-entry package name left the lib target named
after the package, so a pipeline entry's driver main failed E0433 in the
probe build -- unreachable while every probe entry was pipeline-free, and
measured on the required-v2-native lane's first preparation. The lib path
stays cargo's default; only the name is stated.

Co-authored-by: briansrls <briansrls@gunb.ai>

* Release retained emission arena before the native cargo build

The lane's first run held ~15GiB RSS from the emission's resolved graph
into the cargo build of the emitted compiler and was SIGKILLed (rc=137)
with no diagnostic. Drop the emission run and malloc_trim the retained
arena at both derivation-to-emission and emission-to-build handoffs,
reporting the reclaimed KB so a trim that cannot release live memory
shows in the lane log.

Co-authored-by: briansrls <briansrls@gunb.ai>

* Apply rustfmt to the v2-native lane host changes

Co-authored-by: briansrls <briansrls@gunb.ai>

* Lower FreeMonoid tail to im::Vector::skip — O(log n) share, not O(n) copy

The emitter lowered every cons-match tail on a FreeMonoid to
iter().skip(1).cloned().collect(), materializing the whole tail per
step: every fold over a FreeMonoid was quadratic. Measured on the
required-v2-native lane's first native run (2026-09-09): the
self-hosted lexer, which tails the remaining source per character and
per rule attempt, tokenized a 22KB file in 23.3s against 70ms for
899B, projecting a multi-hour whole-corpus context fold — the lane's
dominant term. im::Vector::skip shares the RRB tree in O(log n).

Two mirrors carry the only cons-tail sites in the stage0 corpus:
v1_compiler_emit_rust.rs (the emitter itself) and
std_occurrence_binding_candidates.rs. The e0599 emitter-decision
census and its witness tests move to the new (skip, __fm) site with
the measured rationale. Fixed-point regen green: the rebuilt seed
regenerates both mirrors byte-identically.

Co-authored-by: briansrls <briansrls@gunb.ai>

* Route FreeMonoid length/snoc through the count/list_push primitives

length folded the whole carrier per call (O(n)); the parse repeat loop
calls it on the remaining-token list twice per element — an O(elements x
tokens) quadratic measured at 40% of self-hosted parse self-time on the
required-v2-native lane's first native run (2026-09-09). list_snoc_item
routed through list_append, paying a full O(n) right-fold per snoc and
making every build-by-appending accumulator quadratic (measured on the
first-set union fold). count is O(1) and list_push amortized O(log n) on
the persistent-vector realization. Probe-measured on the emitted crate:
25s -> 6.6s parse on a 4k-element synthetic, 209s -> 33s on a 315KB
table module.

Co-authored-by: briansrls <briansrls@gunb.ai>

* Hoist first-fold knowledge into prepared grammar expressions

The parse choice dispatch recomputed expr_first_fold on both branches at
every Choice node at every token position: right-nested choice chains
made that O(k^2) per position with O(t^2) union constants — the dominant
self-hosted parse cost once the algebra carriers were fixed. The grammar
is fixed for a whole parse, so each node's first fold (and each Choice's
ambiguity verdict) is a pure function of the grammar: compute it once at
preparation, bottom-up, and carry it on a PreparedGrammarExpr tree hung
off GrammarFirstAnalysis / ParseTableRealization. parse_expr keeps its
GrammarExpr signature as a compat wrapper that prepares on the fly;
parse_nonterminal_memoized_core reads the prepared map. Forecast by a
pointer-keyed memo probe on the emitted crate: 33s -> 14s on the 315KB
table module.

parse_minted_id_list also moves off list_append-per-node (O(n^2) per
captured repeat) onto a snoc fold over the list_push primitive.

Verified by execution: 29-test battery over parse_table_claims,
grammar_validation (left-recursion suite), parse_token_first_empty_
semantics, parse_table_content_key and parse_table_memo_governed_witness
all green through the seed interpreter.

Co-authored-by: briansrls <briansrls@gunb.ai>

* Deref boxed variant fields in enum shared accessors

The storage side boxes a variant record field w…
gunbai-bot Bot added a commit that referenced this pull request Sep 12, 2026
… seed-prepared artifact (lands after #10990) (#10940)

* Land the add-slice per-stage verdict instrument named as the floor_expected_red note's producer

The add-slice roster note in v2.workflow.floor_expected_red carried a dated
receipt (main 3a8344b5c: infer accepts dag_add_emitted_root; the
infer-then-translate composition refuses headed by infer_grounding_not_derived)
and named its own next-rung trigger: a .dag entry returning the per-stage
verdicts for one root, so the paragraph can name a producer instead of a
commit.

v2.compiler.self_host.candidate_generation_stage_verdicts is that entry,
parameterized over root and target: the receipt's verdict vocabulary
(infer_accepted / infer_rejected; candidate_accepted or the rejection head
reason) plus the carried-reasons lists -- the half the verdict symbols cannot
say, namely that infer accepts while carrying the frontier diagnostic on its
accepted path, so the enrolled witness's d == None conjunct fails even where
the composition reaches acceptance.

v2.test.execution.self_host_candidate_generation_stage_verdicts binds the
instrument to the slice's own fixture, with add_slice_stage_verdicts_entry the
runnable gunbc run --function form (ExitSuccess only when infer accepts clean
and the composition accepts clean). Two witnesses: infer-accepts as a
permanent positive control, and the frontier-state pin that is expected to red
the day the add-slice stall's trigger lands, flipping to a permanent
regression control in the same change that removes the roster row (DESIGN
4b(4)).

Measured by execution on this branch: the entry exits 1 printing
infer=infer_accepted, infer_carried=[infer_grounding_not_derived x10],
composition=infer_grounding_not_derived, composition_carried=[x11] -- the
receipt reproduced, with bind_outcome's pending-plus-gate chain counted. Both
witnesses PASS; the enrolled semantic witness still fails as enrolled.

Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>

* Derive grounding for dag declared inhabitants: the add slice greens end-to-end

infer gains the declared-inhabitant membership derivation: a node declared in
the dag language authority's declared-inhabitants roster derives its grounding
by lookup, with the roster as evidence -- the namespacing answer to the atom
authority question, at specimen scope. The add slice's ten type-spine nodes
(Arrow, Conj, Atom) are all roster members, so:

- candidate_generation_translate_self_emit_dag_add_slice_holds passes; its
  floor_expected_red roster row and per-row note delete per the roster's own
  stale-quarantine arm
- the dag same-language ingest path compiles end-to-end: cross_language_compile
  accepts, byte-equal to the authority's own serialization, no carried
  diagnostics
- the add-slice stall narrows to its four python/typescript round-trip members;
  the original trigger's causal clause was refuted by execution and is restated
  against the grammar parse-product population
- the instrument's frontier guard flips to add_slice_composition_accepts_holds
  (DESIGN 4b(4): frontier guard to permanent regression control)
- five manual witnesses flip with it: two root flips rewritten to assert the
  green state, three transitive conjunctions updated

The kinds stay frontier: non-member Arrow/Conj/Atom specimens carry
GroundingNotDerived exactly as before, and all fourteen enrolled
refusal/acceptance controls pass unchanged. The door's production path still
reds inside rust emission, untouched by this rule.

Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>

* Derive grounding for canonical binding atoms: dag_binding_denotation joins binding to inhabitant once

The resolver already binds the surface spelling Int to the canonical binding
symbol dag_binding_type_int; what that binding DENOTES is the Int inhabitant
declared at dag_declared_inhabitants_core. Every hand-rolled fixture facts
lookup re-authored that join (dag_add_canonical_grounding_for,
record_construct_canonical_grounding_for). The language authority now declares
it once as dag_binding_denotation, and infer_node_facts consumes it: an Atom
whose identity is a canonical dag binding with a declared denotation derives
with that denotation as its grounding evidence.

Direct-rust-door specimen census: 14 underived -> 10 underived (the four
dag_binding_type_int atoms derive; grammar-production atoms, algebra atoms,
bare operand atoms, and the arrow/conj spine stay on the frontier unchanged).

Specimen-scope interim in the same frame as
infer_node_declared_in_dag_inhabitants: both delete in favor of consuming
resolution output when the resolver hands infer declaration-resolved
identities directly (the namespace migration's completed state).

Witness: v2.test.execution.dag_binding_denotation — all four Int binding
atoms in the door specimen derive with dag_int_inhabitant_node() as
structural evidence, and the two bare operand atoms stay GroundingNotDerived
(boundary control). Refusal suite 14/14, ingest bridge 7/7, add-slice
instruments 2/2 green; every remaining red in the at-risk population
reproduces identically on the pre-change tree and is enrolled in
floor_expected_red.

Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>

* Add v2 self-host direct-path orientation: axes, sequence, autonomy contract

A point-in-time orientation that defers to the existing authorities
(DESIGN section 7, the four-wave self-host program, the roadmap node
chain, the three frontier carriers, the guarantee-stall roster, XL-N)
rather than restating them: state is re-derived by the named
instruments, never transcribed here. Sequences the remaining work in
roadmap order (door, parse-product grounding, first behavioral module,
XL-N milestones, native bootstrap, fixed point, v1 deletion) and states
which decisions stay operator-gated.

Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>

* Derive grounding for fully-evidenced Conj and Arrow products

The sixth and seventh kind rules: a non-roster Conj or Arrow whose every
child carries DerivedGrounding derives, its evidence the same shape
re-formed over the children's grounding evidence (a fresh
OccurrenceSynthetic node, never the source — the self-evidence wall holds
by construction). A product with any frontier or absent child stays on the
frontier with its typed diagnostic; a childless product has no evidence to
compose and stays frontier. Roster members keep their roster evidence.

Measured on the direct-rust-door specimen (scratch probe, uncommitted):
10 underived of 15 -> 6. The parameter conj, the module-structure conjs,
and the bodied add arrow derive; what remains is the algebra atoms from
the + operation (AlgebraPrimitive, ring_field_add), the module atom
(dag_surface_module), the parameter references (x, y), and the
grammar-projection root conj that cascades once they land.

Enrolled witnesses (src/v2/test/claim/execution/infer_product_introduction_test.dag):
- product_introduction_derives_fully_evidenced_products_holds — census:
  4 Conj (3 derived, 1 frontier-by-frontier-child) + 1 Arrow (derived).
- product_introduction_composed_evidence_carries_child_groundings_holds —
  the params conj's evidence is a Conj whose x/y children target the dag
  authority's Int inhabitant.
- product_introduction_leaves_childless_conj_on_the_frontier_holds —
  boundary control via direct infer over a hand-built childless Conj.

Flip census (pre- and post-change, zero unexpected flips):
translate_underived_refusal 14/14, infer_self_grounding_wall 12/12,
branch_infer_if_then_else 2/2, compile_eval_thesis_proof 6/6,
ingest_bridge 9/9, cross_language_add_python_to_typescript 4/4,
inhabitant_neutralization 6/6 + e2e 6/6, emit_host_classical_not 14/14,
dag_binding_denotation 2/2, stage-verdicts instrument 2/2,
dag_add_emit_round_trip 4/6 (the 2 enrolled reds unchanged), door
production group still enrolled-red (unchanged).

Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>

* Ground canonical-operation and grammar-production atoms by authority roster membership

Two more specimen-scope derivations in infer_node_facts, both lookups into
declared authorities, never inventions:

- Canonical-operations roster (target_model.dag): every CanonicalOperation
  the target-model authority declares, rendered by
  target_model_canonical_operation_wire_node and gathered under one Conj
  root. The resolver canonicalizes surface operators (e.g. +) to those
  declared operations, so the wire atoms -- the operation discriminant and
  its field references -- derive by membership with the roster root as
  evidence. General over all 14 declared operations, not add-narrow.

- Grammar-productions roster (dag.dag): every production in
  dag_grammar_root() projected to its emitted surface atom under one Conj
  root keyed by production name. The bridge projects a production's parse
  into (identity atom, captured content) pairs, so the identity atom
  (dag_surface_module) derives by membership with the roster root as
  evidence. The roster derives from the grammar root, so a production
  added to the grammar joins by construction.

Both roster roots are Conj nodes, never structurally equal to any member
atom, so the self-evidence wall holds by construction (the first attempt
at the operations rule used the wire node itself as evidence and was
refused by grounding_evidence_is_source -- the wall doing its work).

Measured on the direct-rust-door specimen (scratch probe, uncommitted):
6 underived of 15 -> 2 (only the operand atoms x and y remain; the
grammar-projection root conj cascades once the module atom grounds).

Enrolled witnesses (infer_atom_grounding_rules_test.dag): each roster rule
pins derivation + evidence identity + census; a boundary control pins that
a bare atom with no authority membership stays frontier; the closing
control pins the 2-of-15 state.

Flip census: the product-introduction census witness updates 3->4 derived
conjs (the top conj now cascades) and gains a hand-built
partially-evidenced boundary control to replace the in-specimen one the
cascade consumed. Full battery otherwise unchanged: refusal suite 14/14,
grounding wall 12/12, instrument 2/2, binding-denotation 2/2, round-trips,
bridge, cross-language, neutralization, emit-host all green; enrolled reds
unchanged.

Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>

* Ground binding-reference atoms from the enclosing arrow's domain declaration

The fifth specimen-scope derivation, closing the direct-rust-door
specimen's inference frontier: an Atom whose binding an enclosing arrow's
domain declares derives with the declared domain type as its evidence --
the declaration-site annotation, itself derived (x: Int grounds the x
reference). This is the same lookup the branch-operand path already
performs (infer_find_arrow_domain_type_in_tree), now written to the
operand atom's own facts; it is scope-naive (whole-tree, first match),
recorded in the frontier note, and deletes with the other specimen-scope
rules when the resolver hands infer declaration-resolved identities. The
tree is threaded through the fold's init chain to reach infer_node_facts;
the helper had exactly one caller.

Measured on the door specimen (scratch probe, uncommitted): 2 underived
of 15 -> 0. The specimen's inference frontier is fully closed, and the
production observation advances from InferenceRejected
(infer_grounding_not_derived) to EmissionRejected
(target_use_site_ownership_lookup_miss) -- a new, typed, located deficit
in the emitter, the next gate on the path.

Flip census (all three rewrites verified by execution):
- dag_binding_denotation_leaves_unbound_operand_atoms_on_the_frontier_holds
  -> dag_binding_denotation_declares_no_denotation_for_operand_bindings_holds:
  the boundary moves to the authority itself (the denotation table returns
  Absent for x/y), true regardless of infer's other rules.
- The three emit_host classical-not refusal guards (canonical, staging,
  staging-swapped) flip to acceptance witnesses pinning the emitted text's
  shape -- the real-infer tree now fully derives, and the emission is the
  same one the equals-eval witness proves behaviorally correct. The
  translate-refuses-underived behavior stays enrolled on hand-staged
  fixtures in translate_underived_refusal_test.dag (14/14 green). The
  renames are carried into the commit_workflow and witness_deferral_freeze
  rosters.
- New witnesses: binding_reference_derives_parameter_atoms_holds (evidence
  is the domain's Int binding atom, census 2) and
  door_specimen_fully_derives_holds (0 frontier of 15).

Full battery at this state: refusal suite 14/14, grounding wall 12/12,
instrument 2/2, binding-denotation 2/2, product-introduction 4/4,
atom-rules 5/5, emit_host 14/14, round-trips 4/6 (2 enrolled reds
unchanged), bridge 9/9, cross-language 4/4, neutralization 6/6 + e2e 6/6,
branch 2/2, eval-thesis 6/6; door production group still enrolled-red
(unchanged).

Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>

* Green the direct-rust-door: route emission through produced-decl composition and decode canonical operator wires

The door specimen's inference frontier is fully closed, so its production
observation now reaches the emission stage. Two defects surfaced there, both
fixed here:

Emission composition. generate_rust_emission_candidate served two lanes with
one root shape: the door's production path (a dag module shell) and a fixture
lane (a bare rust Arrow). The translate ownership gate queried the module
atom's ownership at a struct-field use site and refused with
target_use_site_ownership_lookup_miss, because the module's grammar-projection
conj was misread as a type record. The door's real composition is the
produced-decl path: collect declaration conjuncts from the inferred tree and
emit via emit_produced_decl. A new generate_rust_module_emission_candidate does
exactly that, enforcing an exactly-one-declaration admission policy
(rust_module_emission_decl_absent / _ambiguous). The observation and production
mint paths switch to it; the fixture-lane candidate is retained with a note
that it is fixture-only. A pure collector, produced_decl_conjs_in_tree, finds
nodes of produced-decl shape (a Conj whose first child is a Named edge to an
Arrow). Its decl-head match routes through a declared FreeMonoid<Edge>
parameter because the v1 seed stamps pattern variables from a declared
parameter type, not from a field-access scrutinee.

Operator decode. With composition fixed, source fidelity still refused: the
door emitted fn add(x: i32, y: i32) -> i32 { AlgebraPrimitive(x, y) } instead
of { x + y }. Resolution canonicalizes a surface operator atom into a
canonical-operation wire node, so a production tree's transform operator
position carries the wire, while fixture trees that bypass resolution still
carry the surface token atom. translate_project_transform_in_arrow_scope only
knew the surface-token table, so the wire missed and fell to callable apply,
rendering the discriminant identity. The projection now tries the wire decode
first (canonical_operation_from_wire_node) and only on a wire miss falls to
the surface-token table, then to callable apply; the arms are disjoint, so the
dispatch adds no fallback widening. target_transform_operator_child extracts
the operator child safely.

The door's closing expectation now greens by execution, so its known_red_probe
row in explicit_witness_admission is deleted per its own dissolution condition,
and the roadmap authority note, the door contract note, and the direct-path
plan are updated to record the green state. realized_closure_for_v2_direct_
rust_door_emit_run's module list reflects the produced-decl route.

Verified by execution: the door witness greens; the fixture, containment,
algebra, produced-decl, add-slice, and classical-not witnesses stay green;
claim_executor required-ci lanes build and witnesses both exit 0; cargo fmt and
clippy --all-targets -D warnings are clean. One pre-existing red,
witness_projection_is_active_only in the floor_cost_debt containment roster,
reproduces on the base revision and is unrelated to this change.

Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>

* Close the parse-product grounding frontier: widen declared-inhabitant membership to the closed ingest set

The declared-inhabitant roster-membership derivation in 04_infer generalized
from the dag roster to the closed ingest set (dag, python, typescript):
infer_node_declared_in_language_inhabitants returns the declaring authority's
roster root as evidence, with deep subtree membership so a declared
inhabitant's leaf fact atoms derive exactly as the inhabitant node itself.

Measured: the python fixture's 19-node frontier and the typescript fixture's
28-node frontier both close to zero; all four add-slice stall population
round-trip witnesses green; the python->typescript cross-language compile
accepts, byte-identical to ts_source_text.

Section 4b(4) flips (expecting-red probes becoming permanent regression
controls for the acceptances):
- cross_language_compile_refuses_canonical_underived_holds ->
  cross_language_compile_python_to_typescript_round_trip_holds
- inhabitant_neutralization_emit_after_neutralize / same_flavor_python /
  go_int64_to_ts refusal helpers -> round-trip controls
- inhabitant_neutralization_python_to_ts_cross_language_compile (e2e) ->
  round-trip control; python->go members stay refusal guards (go is outside
  the closed ingest set)
- cross_language_emit_inhabitant_neutralization_refuses_underived_holds ->
  round-trip control; the python->typescript emit-matrix row reads ChainProven

The add-slice stall's next-rung trigger fired, so it retired per DESIGN
4b(4): removed from all_guarantee_stalls, row file deleted, witnesses stay
enrolled.

Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>

* Promote the add family to SelfEmittedNative: native-only verdict witness for the emitted add crate

First InterpreterRetained -> SelfEmittedNative promotion after classical_not,
executing the v2-emitter-first-behavioral-module first slice at the
coverage-frontier grain: the add family (fewest dependencies — integer
literals plus one canonical operation) now carries a native-only verdict
witness, so its behavior is established by the emitted crate's own stdout
with eval() unreachable from the verdict path.

- emit_host_native_only_add_holds: real emit -> cargo build -> native run,
  stdout pinned to the family's expected octet, sharing the kernel family's
  one-build cache key exactly as the classical_not arm shares its family's
  key (no duplicated cold build).
- emit_host_native_only_add_wrong_octet_mismatch_detected_holds: the broken
  control — a no-eval verdict has no oracle leg to break, so the expectation
  side breaks (an octet the run never produces must not match); program-side
  discrimination stays with the family's equals_eval primitive-five/six pair.
- The add coverage row flips disposition with its backing citation enrolled
  by construction (the verdict entry is file-grain enrolled in
  falsifier_self_host_wet_template_entries).
- Frontier census tests updated at identity grain: natives are exactly
  {classical_not, add}; split 2/13.

Verified by execution: all six native-only verdict tests green locally
(real wet legs — compile_skipped receipts show cold builds and native runs);
all eight emit_coverage_frontier tests green, including the unbacked-claim
RED control.

Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>

* Record the add-slice defect's repair in the declined-live-tree classification

The row classified candidate_generation_translate_self_emit_dag_add_slice_holds
as RealDefect/CompilerBehaviourRefusal with measured evidence that translate
refuses infer_grounding_not_derived. The owner lane (v2 self-host) repaired the
subject: the declared-inhabitant roster-membership derivation grounds the
slice's type spine by lookup, and the witness passes under claim_batch
--hermetic on the merged tree. The dated classification is kept verbatim; the
disposition flips RoutedToOwner -> RepairedInThisChange with the repair
measurement appended to the evidence, so the routing carrier stops dispatching
a fixed defect. Structural witnesses (count 13, no NotReproduced, exact
partition) are untouched and pass.

* Hoist two in-body annotation blocks to module-item grain

Main's annotation-placement wall (source annotations admit only standalone
leading blocks attached to module-scope declarations; in-body forms refuse)
reached this branch through the merge and refused 8 blocking errors on the
00_compile closure: the add-family promotion note inside the
emit_coverage_frontier_roster list and the python->typescript row note inside
the cross_language_emit_matrix list. Both blocks move above their enclosing
declarations, rephrased to name their subject row. Measured: gunbc compile of
src/v2/compiler/00_compile.dag now emits 172 files with 0 blocking errors;
both files' suites stay green (8/8 and 4/4).

* Promote the complement family to SelfEmittedNative: native-only verdict witness for the emitted logic family crate

The complement family's native execution runs family-grain per the
witness_family_build_grain_ruling (one crate for meet + join + complement,
argv-dispatched), so the native-only arm emits the logic family crate and
runs the complement member through the family dispatcher, sharing the
family witness's one-build cache key. The verdict is decided solely by the
emitted native run's stdout (expected octet 0, complement(True) = False);
the broken control flips the expectation side (octet 1 can never match),
with the comparator pinned by the stdout mock pair. Program-side
discrimination stays with the equals_eval agreement pair and the family
witness's all-alt leg.

The frontier row's backing citation lands in the already
file-grain-enrolled native-only verdict entry, so it is enrolled by
construction; the roster comment is rephrased to cover both 2026-09-07
promotions (add and complement). The frontier test's split and native
membership assertions move to 3 native / 12 retained.

Verified by execution: claim_batch --hermetic on
emit_host_native_only_verdict_test.dag passes all 8 witnesses (the two
new complement arms included), and emit_coverage_frontier_test.dag
passes all 8.

* Key the emitter's host-String arm on declaration provenance, not spelling

is_host_text_carrier_type answered true for any type expression whose
authored name reads "String", including references to the structural
alias v2.std.text.String (type String = FreeMonoid<Char>) that the
namespace lane (gunbc#9907) requalified the v2 corpus's text-carrier
fields to. The emitter rendered every one of those references as the
host String while value-position consumers rendered the structure -- the
E0308 family dominating the self-host compile-phase frontier (41 of 64
in v2_compiler_tokenize.rs on the post-merge board).

The String arm now consults the resolved declaration's provenance
against v1.compiler.coercion structural_declaration_modules_for -- the
same roster type_realization_decision reads -- so the legacy arm and the
strict decision cannot diverge on one node (DESIGN section 3, and
gunbc.recurring_failure_mode alias_resolution_collides_with_kernel_spelling).
Kernel mints and unresolved references keep the host answer exactly as
before.

Regen: the only drifted stage0 mirror is v1_compiler_emit_rust.rs
itself (no module in the stage0 closure references a structurally
declared String -- verified by the whole-population candidate tree),
installed from target/stage0-regen-candidate after the priced round's
partitioned rebuild refused MirrorHasNoOwningPackage on the emitter
(the emitter is monolith-shell, not partition-owned). Fixed point
verified by execution: claim_executor --required-regen on the rebuilt
seed reports first_generation_equal=true over 158 adjudicated mirrors.

* Peel qualified String alias leaves in field position: XL-N closure 72 -> 28 errors

A field authored v2.std.text.String reached the Rust emitter as an overlay-less
resolved reference leaf and rendered the bare terminal name, which binds the
prelude String cross-module (#9813: kernel names are never overridden by
imports, so the use-line is dropped) while every value position renders the
structural carrier Rc<Vec<i64>> -- the v2_compiler_tokenize.rs E0308 family,
41 of 72 errors on the XL-N phase board.

The new rust_overlayless_alias_leaf_requires_peel arm in
render_rust_type_without_applied_binding detects the population (overlay-less
zero-parameter alias leaf, qualified spelling, String terminal segment,
closed_alias_peel_verdict agrees) and renders the alias declaration's resolved
right-hand side, projecting the same realization the fn-signature positions
already produce.

The qualified gate is load-bearing: inside the declaring module the bare name
is the correct render (the emitted module carries the alias declaration), and
the local binding's resolved_type drops the RHS type argument, so an ungated
peel rendered Rc<FreeMonoid> there (E0107 x13, E0282 x2 on the probe). Bare
String keeps denoting the kernel scalar through the host-carrier arm.

Measured: probe specimen (qualified/bare/direct-FreeMonoid/container/variant/
local-alias positions) compiles clean; XL-N compiler closure cargo check
72 -> 28 errors with the residual census dominated by the declared
text_boundary_identity_wall class (kernel String vs structural carrier at
bare-authored boundaries, 17 of 20 E0308s); v1-corpus fixed point holds
(first_generation_equal=true, 158/158 adjudicated).

* Resolve the 12 non-hop XL-N closure errors at source: text-wall conversions + witness_violates helper

Four clusters, all measured non-hop additions between receipt_1 (155) and the
post-peel census (28); the live gate now measures 15 with zero unadmitted
regressions:

- integer.dag: integer_string_to_decimal_digits_step takes v2.std.text.String;
  the public boundary converts with chars() (text_boundary_identity_wall
  specimen discharged at this site).
- 01_tokenize.dag: Token/UnboundSourceAnnotation lexemes convert structural
  -> host String with chars_to_string() at construction, mirroring the v1
  tokenizer's host-lexeme carrier.
- target_model.dag + bash.dag: EmitSpellingEscape.from/to and
  apply_emit_spelling_escapes go structural (v2.std.text.String); the
  EmitSpellingQuote arm converts host->structural->host at its boundary;
  bash's escape rows wrap their kernel String literals with chars().
- witness.dag + 3 call sites (collection list_nth, provenance
  span_index_resolve_textual_locus_from_ids, compile outcome_with_diagnostics):
  new witness_violates<C> helper puts Violates constructions in a
  Witness-headed position so the emitter resolves the carrier type argument;
  dissolves once inference records per-call substitutions.

Verified: 48 targeted claim witnesses green (tokenize behavioral, shell
conformance, string brace escape, string length, map-lookup violates, source
text ingress, bash materialize x12, int literal smoke x6, provenance span
index x2).

* Record receipt_2 on the self-host compile-phase frontier: 15-error census at 66765317ec

The census at the XL-N lane tip: 155 -> 15 net, credited to the qualified-alias
peel (60cbd7b697, 72 -> 28) and the twelve-error source cluster (66765317ec,
28 -> 15). The epoch changes on the instrument's target pinning (found by
review on gunbc#9857), admitted with receipt_1's board as the reclassified
predecessor under the identity map. Nine added identities are hop relocations
admitted by the hop index; four sit in python/typescript modules newly entered
into the emitted closure, admitted as ExposedByNewEmittedModule.

Validated: all 36 self_host_compile_phase_frontier_witness claims PASS,
including current_persisted_compile_phase_frontier_holds.

* Emitter: a substituted declaration node carries its own provenance

Inference substitutes the resolved declaration into a data annotation's
type-argument position, so BooleanAlgebra<v2.std.logic.Bool> reaches the
emitter with the arg BEING the type Bool = True | False declaration itself
(Disj connective, ident_span in src/v2/std/logic.dag, no Resolved wrapper).
type_reference_provenance_in_env's bare-leaf arm re-resolved that leaf in the
REFERENCING module's scope, where post-#9813 a kernel-shadowed spelling
answers the kernel declaration -- so the structural enum rendered as host
bool against a value of BooleanAlgebra<Bool> (the python.rs:328 /
typescript.rs:177 E0308 pair on the XL-N compile-phase frontier).

The connective is the discriminator: a reference node is a bare name
(NoConnective); a node carrying Conj/Disj structure IS the declaration, and
type_reference_provenance's own-span fallback already answers that shape
correctly. The guard routes declaration-shaped nodes there directly, bypassing
the scope lookup that #9813 makes answer the kernel.

Mirror regenerated via the regen round; fixed-point verified
(claim_executor --required-regen PASS).

* Clear the remaining XL-N closure errors at source: carrier conversions at the boundaries

The receipt_2 census's fifteen identities, resolved at their sources:

- lexing.dag, dag.dag, python.dag, typescript.dag: LexPattern.text is the
  structural carrier (v2.std.text.String); the construction sites held host
  Strings. Convert at construction with chars() -- the #9907 ingress pattern.
- python.dag / typescript.dag bool groundings: qualify the annotation as
  BooleanAlgebra<v2.std.logic.Bool>; with the emitter's substituted-
  declaration provenance guard the qualified arg now renders structural.
- target_model.dag: target_lex_rule_literal_step returns the host carrier
  (chars_to_string over the structural pattern text); TargetText.source
  converts at the is_empty boundary; the unicode-scalar symbol intern converts
  its single-codepoint list to the host carrier.
- qualified_name.dag: qualified_name_from_dotted_string uses the host-carrier
  emptiness check (string_length == 0) instead of routing through the
  structural string_is_empty.
- 02_parse.dag: parse_looks_like_match_arm_start rewritten on host-carrier
  operations (string_length, char_at, code_point) rather than converting to
  the structural carrier for a two-character lookahead;
  parse_char_is_arm_pattern_lead takes the codepoint Int directly.
- v1_interpreter_primitive_surface.dag row_key: the concat pipeline lowered
  to a .concat() method call on std::string::String (E0599); rewritten as
  nested concat calls.

Measured: the 00_compile closure emits 172 files and cargo check reports
cargo_clean=true, cargo_error_population=0 under the pinned 1.93.0 toolchain.

* Pin the cargo half's toolchain channel by construction

The cargo half runs with cwd = a fresh mktemp directory; with no
rust-toolchain.toml there, rustup resolves the host's DEFAULT toolchain, so a
census under cargo 1.83 and one under cargo 1.93 would compare as equal epochs
while different compilers did the measuring -- the fabricated comparability
the target pin (gunbc#9857) excludes, one level up. Measured 2026-09-07: a
host default of 1.83.0 met a crates.io index whose freshly published
dependency manifests require edition2024, resolution failed before any
diagnostic existed, and the zero-diagnostic refusal fired on an unmeasured
tree.

The pin is propagated by copying the repo's rust-toolchain.toml into out_dir:
the file remains the sole in-repo channel authority (its header forbids a
second pinned literal), and the copy makes the measured channel true by
construction on any host. The gate's read_live_toolchain observes the same
channel because every documented actuator invokes from the repository root,
which the same file governs.

* Record receipt_3 on the self-host compile-phase frontier: the emitted closure's cargo census is empty

Measured at 5ee4892b70 by the one-entry instrument: the 172-file emitted crate
reports zero cargo error diagnostics, so the board attributes every phase a
count of zero and furthest_phase_reached stands at Borrowck. The fifteen
removals against receipt_2 need no disposition; nothing was added.

The epoch does not change: the cargo half now pins the toolchain channel by
copying the repo's rust-toolchain.toml into the scratch crate, and every
recorded comparison field is identical to receipt_2 (whose census the
fingerprint evidence shows the same 1.93.0 toolchain already compiled), so the
same-epoch arm carries no reclassified predecessor.

The frontier-state pin flips per DESIGN 4b(4):
the_published_frontier_standing_does_not_claim_typeck_or_borrowck_passed
becomes the_published_frontier_standing_claims_typeck_and_borrowck_passed, the
permanent regression control over the green state.

Validated: all 36 self_host_compile_phase_frontier_witness claims PASS,
including current_persisted_compile_phase_frontier_holds.

* chore: regenerate drifted generated artifacts (ci auto-heal)

Ledger-Repair-Judged: docs/design-failure-modes.md
Ledger-Repair-Judged: docs/design-rung-drops.md

* Remove the stale PointwisePower inhabitant rows from the four language rosters

First native-parity divergence class found by running the emitted closure on a
discriminating fixture: the algebra inhabitant rosters still carried
PointwisePower after its authority row was cut, so the emitted compiler panicked
at 12 record-shaped carrier sites while the interpreted seed refused cleanly.
The roster rows are removed in rust/python/go/typescript types.dag, the derived
coercion assertions in compiler_tests.rs regenerate without them, and two
witnesses pin the boundary: the record shape constructs its structural carrier,
and FinitePowerSet still refuses while its row stands.

Mirrors regenerated by a converged regen round (fixed point Reached, stage-1
PromoteGenerationInputs over the three language types mirrors).

* Regen gen-2 gate: compare executable digests in one spelling

The admitted side of run_built_seed_regen carries the executable-digest
spelling (current_exe_digest, next_pass_executable_digest) while the observed
side hashed the file through path_digest, which prepends the fnv1a64: tag.
Same bytes, two spellings, so the gate could never pass -- unpassable since
fa2d403dc8 (#9771). Factor current_exe_on_disk as the single path authority
and read the observed digest through current_exe_digest so both sides spell
the same bytes the same way.

* Model ReleaseScopeEmpty for release-excluded mirrors, end to end

A regen round whose only stage-2 drift was compiler_tests.rs (the PointwisePower
roster removal rewrote its derived coercion assertions) refused the rebuild
MirrorHasNoOwningPackage: the mirror is owned by no partition package, because
every item it defines is #[cfg(test)] and no release unit elaborates it. The
refusal conflated two different states -- unowned (a coverage hole) and excluded
from the release build by construction (a precise empty scope).

The model now names the class: rebuild_scope_release_excluded_mirrors rosters
its members (compiler_tests.rs, cited to emit_compiler_tests_module), the
decision answers ReleaseScopeEmpty when the whole change set is excluded, and
the actuation shape is actuatable with an empty package closure and every
partition package excluded -- the build still runs as verification, and a
compiled partition package refuses the stage. The host admits the empty closure
only when the new stage0_partition_rebuild_release_scope_empty_today query
answers true; any other empty closure still refuses. A mixed change set scopes
on its release-visible members alone.

Verified by execution: the 2026-09-08 round converged (fixed point Reached)
with stage-2 installing compiler_tests.rs alone; cargo recompiled the shell
crate on its fingerprint (the outer mod line is ungated, so rustc reads the
file) while the produced executable was byte-identical -- stage input seed
digest == output seed digest. Four new witnesses pin the arm, its actuation
shape, the mixed set, and the host-facing query's two arms; the boundary
witness (unowned cli_run.rs still refuses) keeps the roster from decaying into
the absorbing fallback.

* Round-cost receipt: project installed mirrors to the model's vocabulary

The receipt's partition-rebuild line is rendered by the model over
receipt.installed_mirrors, which the host populated from the stages'
projected_paths -- full paths -- while the partition rows and rosters key on
basenames. Every drifted round's receipt therefore rendered a spurious
RebuildScopeRefused MirrorHasNoOwningPackage line naming a full path, a false
claim on the round's own receipt. Route the projection through
emit_path_basename, the module's single path-to-basename bridge, so the field
carries the mirror names the model's vocabulary means.

* Hoist ReleaseScopeEmpty annotations to module-item grain

The ReleaseScopeEmpty modeling commit placed three // blocks inside
declaration bodies (stage0_partition_rebuild_is_actuatable,
stage0_partition_rebuild_decision, stage0_partition_rebuild_excluded_today).
The .dag realization admits annotations at module-item grain only, so the
floor lane's parse phase refused the file with 12 located errors and the
run ended floor refused. The prose is unchanged; each block now sits above
the declaration it describes.

* Spell the PointwisePower witness's finite-set exclusion as the applied realization

The witness added with the fossil-row removal excluded the bare spelling
"BTreeSet", but every emitted file's preamble imports OrdSet as BTreeSet,
so the row could never green. The exclusion's subject is the finite-set
REALIZATION the fossil row would have asserted; spell it applied
(BTreeSet<i64), which the preamble's import line does not contain.

* Emit fieldless-record data values as null for the unit-struct carrier

The second native-parity divergence class, measured 2026-09-08 on the
native run of the emitted 00_compile closure: emit_data_value_json spelled
EVERY record literal as a JSON map, including the zero-field record, while
emit_struct_from_children renders that same declaration as a Rust unit
struct (pub struct BoolEncodingFact;). serde's derived unit-struct
Deserialize reads null and rejects {}, so the emitted compiler panicked at
first touch of v2.std.logic's bool_primitive_facts: "invalid type: map,
expected unit struct BoolEncodingFact". The JSON spelling of a data value
must deserialize into the Rust type the same declaration emitted; the
record arm now spells the zero-field value null and keeps the map spelling
for non-empty records.

The mirror is taken from the required-regen candidate, not hand-edited.
Two witnesses enroll: the discriminating red (zero-field record spells
null, never {}) and the boundary control (a record with fields keeps the
map spelling).

* Bind the duplicate-definition filter ahead of its branch condition

Main's FilterInBranchCondition wall (#10699) refuses to publish a module
whose filter call sits in a branch condition, and the v2 00_compile closure
emission names primitive_duplicate_semantic_definition_violation as such a
site. The filter is pure and total; binding it with a let ahead of the
branch is the authored remediation the wall exists to force, and the
emitted closure is unchanged in behavior.

* chore: regenerate drifted generated artifacts (ci auto-heal)

Ledger-Repair-Judged: docs/design-rung-drops.md
Ledger-Rows-Repaired: docs/design-rung-drops.md rust_unit_tests_off_the_merge_path
Ledger-Rows-Repaired: docs/design-rung-drops.md determinism_transitive_reachability
Ledger-Rows-Repaired: docs/design-rung-drops.md transitional_admission_exception

* Emitter: three native-parity repairs for the post-merge 00_compile closure build

Three divergence classes measured as the 21 rustc errors on the natively
emitted 00_compile closure after the main merge, each repaired at the .dag
source with a discriminating witness:

- Locality wins over a foreign ambiguity (12 E0433 in v2_std_integer.rs):
  alias_rhs_base_module_filename asked the global leaf index, saw
  LeafAmbiguous for Compose, and emitted the poison marker even inside
  v2.std.integer itself, where source resolution binds the local
  declaration before any cross-module lookup. The local physical
  declaration now shadows foreign declarers; the poison marker still
  stands for a leaf two FOREIGN modules declare.
- The qualifier is the disambiguator (8 E0425/E0433 in
  v2_lens_fact_density.rs): the qualified use-line route declined any
  globally-ambiguous leaf, but a qualified reference names its provider
  in its own spelling. The route now resolves by DeclaredCallableIdentity
  at the qualifier, keeping the type-declared and export-proof walls.
  The dotted spelling reaches the route through the value surface (a
  qualified value projection's borrowed type stamps the match patterns'
  parent_enum); the witness reproduces that chain exactly, and its
  exclude half pins the E0603 boundary (the dotted VARIANT head must
  still be declined).
- Clone-bound forwarding is transitive (1 E0277 in
  std_realization_measurement.rs): the call-forwarding derivation
  re-derived only each callee's SELF-derived half, so a callee whose
  bound is itself forwarded re-derived to empty. The derivation now
  recurses over the call graph with the module's visited-set
  termination; the equality half stays one-hop as declared.

Witnesses: 56/56 PASS on the rebuilt seed; regen fixed point holds.

* Refuse variant record literals on the serde_json data path fail-closed

A record literal with parent_enum present is a variant construction whose
wire spelling is the parent coproduct's declared VariantEncoding policy --
a module-local fact of the parent's home module that emit_data_value_json
does not carry. The zero-field arm's null and the map arm's untagged fields
are both measured to fail serde deserialization under the internal-tag
default, so the arm now refuses and the caller renders compile_error!, a
build-time located refusal where a runtime panic on the data definition's
expect was the latent alternative. The refusal names its trigger: a
closure-wide wire-policy index beside EmitGraphInfo.type_decl_items.

Witness: w_variant_record_lit_on_the_json_data_path_refuses_fail_closed
forces the JSON path with a nested-record Holder and asserts the
compile_error! spelling while excluding the former null mis-serialization.

* Spell variant record literals on the serde_json data path from a closure-wide wire-policy index

The fail-closed refusal landed in 73b582dea6 fired on 5 real corpus sites
(SugarKey x2, CopiedPortCitationFrontierDisposition x3), proving variant
record literals reach the JSON data path in the 00_compile closure. This
change replaces the refusal with the correct spelling, driven by a new
closure-wide index:

- v1.compiler.infer_emit_info gains DataVariantWireSpelling, the
  language-general projection of a coproduct's Rust wire serde policy
  for one variant (InternalTagged { tag_field, tag } | BareString { tag }
  | Untagged | SpellingRefused { reason }), and EmitGraphInfo carries
  data_variant_wire_spellings: Map<String, DataVariantWireSpelling>
  keyed by coproduct.variant.
- v1.compiler.emit_rust builds the index once per emission root via
  build_data_variant_wire_spellings, resolving each coproduct's policy
  through the new shared resolve_emission_coproduct_wire_policy (the
  same function the type-emission side now calls, so the two cannot
  drift), projecting each variant through data_path_wire_variant_tag
  (rename_all and StripAffix aware), and poisoning collisions as
  SpellingRefused so ambiguity stays fail-closed.
- v1.compiler.emit's emit_data_value_json variant arm reads the index:
  internal-tagged spells {"_variant": tag, ...fields}, bare-string
  spells "tag" for nullary and refuses fielded, untagged spells the
  bare fields or null; unindexed keys and stored refusals remain
  compile-time errors. The service mock-property chain threads
  emit_info through so dry-run data spells identically.

Witnesses: w_variant_record_lit_on_the_json_data_path_refuses_fail_closed
is rewritten as ..._spells_the_internal_tag (asserts the internal-tag
map, excludes the former null mis-serialization and the refusal), and
w_fielded_variant_record_lit_on_the_json_data_path_spells_tag_and_fields
pins the fielded case. 57/57 witnesses pass; regen fixed-point holds.

* Promote field_access to SelfEmittedNative on the emit coverage frontier

Fourth native-eval construct promotion, after classical_not, add, and
complement. The native-only verdict arm pair lands in the already
file-grain-enrolled long/ entry, so the backing citation is enrolled by
construction:

- emit_host_native_only_field_access_holds pins the family one-build
  cache run's stdout to octet 9 (the byte the family witness's warm leg
  pins on the same build), eval() never called.
- emit_host_native_only_field_access_wrong_octet_mismatch_detected_holds
  breaks the expectation side with octet 1, the alt tree's byte.

Both arms verified wet locally (real cargo build + native run, sharing
the field_access family one-build cache key). The roster row flips to
SelfEmittedNative; the two census guards update per 4b(4) — the split
moves to 4 native / 11 retained and the identity-grain membership guard
is renamed to name the four-member population. The family's equals_eval
agreement pair stays enrolled as its program-side discrimination leg.

* Drop the scratch parity probe from the tree

The probe is a manual parity-loop instrument (the interpreted leg of the
native-vs-interpreted comparison), not a corpus declaration with an
executing consumer (DESIGN 6 experimental residue). It stays in use
locally as an untracked file.

* Promote match, loop, and fold_closure to SelfEmittedNative

Fifth, sixth, and seventh native-eval construct promotions. The three
match_loop_fold family rows flip together on one shared family-crate
arm shape, per the witness_family_build_grain_ruling: each arm emits
the three-member family crate once and runs its own member through the
argv dispatcher against the family one-build cache key.

- emit_host_native_only_{match,loop,fold_closure}_holds pin the warm
  legs' stdout to the family's declared octet lists (match/loop
  [0,1,0,0,0], fold [0,7,0,0,0]), eval() never called.
- The wrong-octet controls break the expectation side with each
  member's own alt octets (match/loop [0,2,0,0,0], fold
  [0,255,255,255,255]).

All six arms verified wet locally. The census guards update per 4b(4):
7 native / 8 retained, and the identity-grain membership guard is
renamed to witness_native_rows_closed_membership_holds so the name
stops encoding the volatile population.

* Promote meet_join to SelfEmittedNative on the emit coverage frontier

The meet_join family's native-only verdict arms land on the complement arm's
helper, generalized to take the family member_id: meet and join run through
the same argv-dispatched logic family crate (one-build cache key shared with
complement, per the witness_family_build_grain_ruling), eval() never called,
verdict decoded from stdout. Octets meet=1 join=1 are the bytes the family
witness's warm legs pin on this same build; the wrong-octet control expects
each member's alt byte (0), which the primary runs can never produce.

Both arms verified wet: cold build then warm hits, PASS/PASS. The roster row
flips InterpreterRetained -> SelfEmittedNative (eighth promotion); census
guards move to 8 native / 7 retained with meet_join_eval_subject named in the
closed membership.

* Promote variant_construct to SelfEmittedNative on the emit coverage frontier

The variant_construct family's native-only verdict arms follow the
field_access arm shape exactly: the tree is the family's own equals_eval
tree value (emit_variant_construct_eval_tree, no eval leg reachable), the
run shares the family one-build cache key that
emit_on_demand_variant_construct_native_one_build_holds colds, and the
expected octet 9 is the byte the family witness's warm leg pins on this
same build. The wrong-octet control expects the alt tree's byte (1), which
the primary run can never produce; the wrong-value alt leg in the family
witness keeps the program-side discrimination.

Both arms verified wet: cold build then warm hit, PASS/PASS. The roster row
flips InterpreterRetained -> SelfEmittedNative (ninth promotion); census
guards move to 9 native / 6 retained with
emit_variant_construct_eval_subgraph_node named in the closed membership.

* Close the emit coverage frontier: final six rows to SelfEmittedNative

The last six InterpreterRetained rows flip to SelfEmittedNative, taking the
roster to 15 native / 0 retained:

- filesystem_read and shell_exec_run (host-effect transport families, no
  translated arrow body): the arms reuse each family's own native leg with
  the expectation pinned as a literal grounded by the family's enrolled
  fixture pin (dag/extdeps/shell/exec.dag contains bash; its shell.Exec.Run
  argv materializes to exactly [bash, -s]), run through the families' fixed
  witness workspaces.
- module and produced_module: the arms execute the exact sources the
  equals_eval pairs run (emit_module over the add fixture tree;
  produced_add_module_source's ingested two-fn module), octet 5 pinned
  against the add family's primitive-five/six oracle leg.
- call and record_construct: the arms emit the families' own producer trees
  against their target models, octets 7 and 9 pinned against the
  primitive-seven/eight and wrong-field oracle legs.

The four families without a one-build cache witness run under per-family
fixed workspace roots; content-safety comes from the realization-digest
nesting in run_host_process_admitted (changed source colds, never serves
stale), the same mechanism the filesystem_read fixed workspace relies on.
All twelve arms verified wet: PASS/PASS each, cold builds then warm hits.

With zero retained rows the retained_via_eval_agreement constructor loses
its last consumer and is deleted (DESIGN 3c); the InterpreterRetained
variant stays as the disposition authority's other state. Census guards
move to 15 native / 0 retained with all fifteen decl names in the closed
membership.

* Record the emit coverage frontier closure in the direct-path plan

Axis C line: all fifteen roster rows are SelfEmittedNative as of
2026-09-08, interpreter_retained_rows() is empty, and the row constructor
was deleted with the last flip. Notes explicitly that this closes axis (a)
(witness-body-runs-native) only; axis (b) (the regen-grain production
flip) remains operator-gated.

* Model the required-v2-native lane authority: route receipt, exclusion taxonomy, admission, enrolment gate

Parallel track B (operator authorization 2026-09-09): one additional required
CI job whose subject is the compiler/test execution route itself — the
emitted-native compiler binary invoked by explicit path over a derived
v2.test.* population.

The lane is modelled in full in gunbc.witness_v2_native_route: the prefix
universe derivation, the per-member verdict rows (head + fatal reason grain),
the exclusion taxonomy delegating attribution to the door ledger's
known_frontier_causes, the counted exclusion census with a totality check,
the terminal-observation receipt carrier, the admission predicate (one
predicate per contract clause, all causes collected), and the enrolment gate
with today's standing as data.

Enrolment is BLOCKED, as data with a named capability trigger: the measured
census over the derived universe (882 members, seed withdrawn during the run)
refused every member — the emitted DirectIngestDriver admits only the
hard-coded compile_driver_subject name with empty imports, and the compile
door is at its modelled frontier — so the contracted positive population is
empty and native_route_admission over the real receipt executed to
'refused: positive_population_empty'. The exact enrolment edit (phase-roster
variants, claim_executor mirror, workflow lane, aggregate join, YAML regen)
is carried on the standing row.

The census measured five fatal-grain refusal causes the door ledger's
head-grain attribution table did not carry; they are added to
known_frontier_causes with their owning lanes (three MigrationOwned under
nimble-boar-198, two normalize/body-lowering SharedSelfHostCriticalPath).

Seventeen floor witnesses (v2.test.v2_native_route) consume the authority and
execute green through the seed interpreter.

Co-authored-by: briansrls <briansrls@gunb.ai>

* Split preparation predicates so EmittedClosureUnrecorded is reachable

Review on #10882 (briansrls, point 7): native_route_preparation_recorded
folded the seed and closure observations into one && predicate, so a
receipt with a recorded seed and an unrecorded closure misreported as
preparation_seed_unrecorded and the emitted_closure_unrecorded cause had
no reachable construction — the grain-mismatch class DESIGN 4b(3) names.

One predicate per observation, one admission clause per predicate, and
two witnesses pinning each refusal name against its own receipt shape
(including the negative: each refuses ONLY by its own name).

Co-authored-by: briansrls <briansrls@gunb.ai>

* Key cause ownership by diagnostic grain; classify native refusals at fatal grain

The door ledger's known_frontier_causes was a head-grain authority; the
native route classified fatal reasons through it, crossing grains (review
on #10882). Generalize the ownership key with DiagnosticGrain so one
table answers both grains: the door ledger's cause_is_attributed keeps
its head-grain contract, and the native route's exclusion classifier
asks the fatal-grain question of the same table. The head advisory is
live receipt data again: every refused row's head reason must be owned
at head grain (or by this lane's driver-limit roster), and an unowned
advisory blocks admission by its own clause name.

Co-authored-by: briansrls <briansrls@gunb.ai>

* Hoist known_frontier_causes row-group notes above the declaration

The grain-keyed ownership change left its row-group commentary inside the
list literal; the annotation channel admits only module-item grain, so the
emitted closure refused with nine annotation-grain diagnostics. Move the
notes to a single block above the declaration. No semantic change.

Co-authored-by: briansrls <briansrls@gunb.ai>

* Parse test fn as a contextual production in the v2 dag grammar

The emitted native compiler could not parse any v2.test.* module: the
modeled dag grammar had no test fn production, so every floor witness
module refused with parse_g0_tokens_remain (706 of 882 in the census).

test stays an ordinary identifier — typescript/program.dag models the
TypeScript compiler's Cond.test field under real-upstream-names — so the
production is the contextual sequence(ident, fn_decl): a new choice arm
in top_level_item with no FIRST overlap with the keyword-led arms, a
body-lowering arm that lifts the nested fn member after checking the
marker lexeme is literally test (a typed refusal otherwise), and a
forward-producer row for the new surface identity.

Verified against the emitted native binary: probe_testfn.dag moves from
parse_g0_tokens_remain to resolve_module_not_found (the driver's
synthetic-subject limit, identical to a plain fn), and the standing
choice-overlap residue roster is unchanged at seven rows.

Co-authored-by: briansrls <briansrls@gunb.ai>

* Add SourceRootEvalDriver: native whole-ingest test-execution route

The required-v2-native lane's terminal subject is an exact test identity
reaching a native Eval verdict, not a module accepted for translation.
DirectIngestDriver (one source, no peers, synthetic subject) stays as the
front-door census instrument; the new driver renders a main that reads a
host-derived universe of qualified test identities plus the declared
source roots, assembles the ingest once, prepares each module (resolve +
infer), and Evals each named test body -- one typed verdict row per
member, with a prepare-refusal fan-out so no member is silently dropped.

Co-authored-by: briansrls <briansrls@gunb.ai>

* Escape literal braces in SourceRootEvalDriver main.rs template

The .dag string lexer reads '{' followed by an identifier as
interpolation, so the emitted Rust use::-import lists and format!
captures must spell literal braces as \{ \}. The single parse error
desynced the file parse and cascaded into 2618 unattributed-annotation
errors; with the escapes the emitter compiles clean (0 blocking, 107
files emitted).

Co-authored-by: briansrls <briansrls@gunb.ai>

* Collect per-file front-end refusals in the native test context fold

The SourceRootEvalDriver's context fold reused program_assembly_fold_ingest,
which is wholesale fail-closed: one source hitting the v2 front-end's live
corpus frontier would deny verdict rows for every other universe member. The
fold now collects each source's tokenize/parse/normalize refusal as a
NativeTestFileRefusal row (head and fatal reason grains, matching the door
ledger's grain-keyed ownership) and keeps folding; a refused file contributes
no root, so its test identities surface as Context-stage refusal rows and
nothing is widened. The emitted main.rs prints the file-refusal rows and
counts them in the terminal marker, and prepare/eval refusals now classify at
the fatal (last diagnostic) grain consistently.

Co-authored-by: briansrls <briansrls@gunb.ai>

* Add native lane control fixtures

Two controls for the required-v2-native lane's host harness:
src/v2/native_lane_fixture/control.dag carries the live-verdict pair (a
well-formed false control and its true positive half) as plain fns outside
the v2.test. prefix, so floor discovery enrolls no universe rows for them;
fixtures/native_lane_malformed/poison.dag is a deliberately unterminating
string that any honest front-end must refuse at tokenize, kept outside every
declared source root so the broken bytes never enter an honest ingest.

Co-authored-by: briansrls <briansrls@gunb.ai>

* Fix Vec/Vector type mismatches in the SourceRootEvalDriver main.rs template

The emitted driver crate aliases im::Vector as Vec, so the template's
std Vec-typed bindings and collect calls failed to compile in the
emitted crate: universe rows and module order carry Rc<Vector<String>>,
the reads vector moves into the FreeMonoid parameter with .into(), and
the dotted module name is built from an iterator collect.

Co-authored-by: briansrls <briansrls@gunb.ai>

* Harden the v2-native route contract: test-identity grain, exact join, paired reference

Reframe the terminal subject from module-grain acceptance to the exact
test identity reaching a native verdict. The receipt's universe is a
list of qualified NativeRouteTestIdentity rows; the observed population
joins it exactly (uniqueness, no foreign rows, no omissions); every
member verdict is paired against the floor's own expected-red and
route-gap rosters for agreement, exclusion, or divergence; refusals are
classified from stage and provenance with cause ownership at fatal and
head grains; and the four controls (true, false, malformed specimen,
old-route withdrawal) are admission clauses. The 46 tests cover
universe derivation, identity qualification, reference pairing, refusal
classification, disposition, census counting, and every admission
clause.

Co-authored-by: briansrls <briansrls@gunb.ai>

* Wire the required-v2-native lane into the roster, workflow, and aggregate

Add V2NativeLane/V2NativePhase to the required-CI roster, the lane's
claim_executor command to fabric_witness_run, and the
required-v2-native job to the witness floor workflow with the aggregate
witnesses job needing it in both verdict arms. Regenerate
witnesses.yml.

Co-authored-by: briansrls <briansrls@gunb.ai>

* Add the required-v2-native host harness and phase dispatch

The lane's one phase derives the v2.test.* universe with the floor's
own discovery producer over the full module inventory, prepares the
emitted-native compiler through the emit-compile phase's crate writer
and cargo invocation, withdraws the old-route gunbc binary for the
spawn window, runs the emitted binary by explicit path over the
universe plus the named controls, reclassifies context-stage refusals
against the observed file refusals, mints the NativeRouteReceipt as the
authority's own types, and hands it to native_route_admission for the
verdict. claim_executor gains the V2Native lane and phase with the
roster sizes moved to six.

Co-authored-by: briansrls <briansrls@gunb.ai>

* Regenerate stage0 mirrors for the SourceRootEvalDriver emitter arm

std_compiler_entry.rs gains the SourceRootEvalDriver variant and
v1_compiler_emit_rust.rs the emit_source_root_eval_driver_main_rs
template with its dispatch arm, emitted by the regenerated seed and
verified at the fixed point (first_generation_equal=true over the whole
155-module population).

Co-authored-by: briansrls <briansrls@gunb.ai>

* Name the probe crate's lib target v1_compiled, the emitter's self-name contract

emit_rust_selected binds the self-emitted crate's name to v1_compiled
for every non-retained-host pipeline entry, and the SourceRootEvalDriver
and DirectIngestDriver mains reach the closure through use v1_compiled::.
The probe manifest's per-entry package name left the lib target named
after the package, so a pipeline entry's driver main failed E0433 in the
probe build -- unreachable while every probe entry was pipeline-free, and
measured on the required-v2-native lane's first preparation. The lib path
stays cargo's default; only the name is stated.

Co-authored-by: briansrls <briansrls@gunb.ai>

* Release retained emission arena before the native cargo build

The lane's first run held ~15GiB RSS from the emission's resolved graph
into the cargo build of the emitted compiler and was SIGKILLed (rc=137)
with no diagnostic. Drop the emission run and malloc_trim the retained
arena at both derivation-to-emission and emission-to-build handoffs,
reporting the reclaimed KB so a trim that cannot release live memory
shows in the lane log.

Co-authored-by: briansrls <briansrls@gunb.ai>

* Apply rustfmt to the v2-native lane host changes

Co-authored-by: briansrls <briansrls@gunb.ai>

* Lower FreeMonoid tail to im::Vector::skip — O(log n) share, not O(n) copy

The emitter lowered every cons-match tail on a FreeMonoid to
iter().skip(1).cloned().collect(), materializing the whole tail per
step: every fold over a FreeMonoid was quadratic. Measured on the
required-v2-native lane's first native run (2026-09-09): the
self-hosted lexer, which tails the remaining source per character and
per rule attempt, tokenized a 22KB file in 23.3s against 70ms for
899B, projecting a multi-hour whole-corpus context fold — the lane's
dominant term. im::Vector::skip shares the RRB tree in O(log n).

Two mirrors carry the only cons-tail sites in the stage0 corpus:
v1_compiler_emit_rust.rs (the emitter itself) and
std_occurrence_binding_candidates.rs. The e0599 emitter-decision
census and its witness tests move to the new (skip, __fm) site with
the measured rationale. Fixed-point regen green: the rebuilt seed
regenerates both mirrors byte-identically.

Co-authored-by: briansrls <briansrls@gunb.ai>

* Route FreeMonoid length/snoc through the count/list_push primitives

length folded the whole carrier per call (O(n)); the parse repeat loop
calls it on the remaining-token list twice per element — an O(elements x
tokens) quadratic measured at 40% of self-hosted parse self-time on the
required-v2-native lane's first native run (2026-09-09). list_snoc_item
routed through list_append, paying a full O(n) right-fold per snoc and
making every build-by-appending accumulator quadratic (measured on the
first-set union fold). count is O(1) and list_push amortized O(log n) on
the persistent-vector realization. Probe-measured on the emitted crate:
25s -> 6.6s parse on a 4k-element synthetic, 209s -> 33s on a 315KB
table module.

Co-authored-by: briansrls <briansrls@gunb.ai>

* Hoist first-fold knowledge into prepared grammar expressions

The parse choice dispatch recomputed expr_first_fold on both branches at
every Choice node at every token position: right-nested choice chains
made that O(k^2) per position with O(t^2) union constants — the dominant
self-hosted parse cost once the algebra carriers were fixed. The grammar
is fixed for a whole parse, so each node's first fold (and each Choice's
ambiguity verdict) is a pure function of the grammar: compute it once at
preparation, bottom-up, and carry it on a PreparedGrammarExpr tree hung
off GrammarFirstAnalysis / ParseTableRealization. parse_expr keeps its
GrammarExpr signature as a compat wrapper that prepares on the fly;
parse_nonterminal_memoized_core reads the prepared map. Forecast by a
pointer-keyed memo probe on the emitted crate: 33s -> 14s on the 315KB
table module.

parse_minted_id_list also moves off list_append-per-node (O(n^2) per
captured repeat) onto a snoc fold over the list_push primitive.

Verified by execution: 29-test battery over parse_table_claims,
grammar_validation (left-recursion suite), parse_token_first_empty_
semantics, parse_table_content_key and parse_table_memo_governed_witness
all green through the seed interpreter.

Co-authored-by: briansrls <briansrls@gunb.ai>

* Deref boxed variant fields in enum shared accessors

The storage side boxes a variant record…
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant