Repository navigation
Kernel-precedence repair: one shared type-env producer; kernel overlay independent of import cardinality - #9813
Conversation
…el overlay unconditional build_type_env and build_type_env_unresolved both skipped the kernel cache overlay when a module had exactly one import — with one import the environment was that import's flattened cache alone, so kernel identity won or lost by ancestry occupancy (leak-dependent resolution: identical imports, different realizations). Both builders now consume one build_ancestry_precedence producer: import union (fork ledger unchanged) -> kernel overlay UNCONDITIONALLY -> direct-selected overlay with kernel names skipped -> locals kept above by str_bindings-first lookup. The unresolved builder gains the direct-selected overlay it previously lacked, per the same one-producer boundary. direct_import_export_precedence_note updated: kernel installation independent of import cardinality. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU
…3, byte-converged)
v1_compiler_infer.rs carries the build_ancestry_precedence projection; the
round-2 compiler (carrying the precedence) additionally re-emitted
extdeps_languages_{go,python,rust}_emit.rs and v1_compiler_stage0_crates.rs:
lambda parameters that previously emitted as _ now emit their resolved types
(Rc<SimpleMethodSpec>, Rc<GeneratedPartitionCrateRow>) — single-import modules
now build kernel-complete environments, so inference names types it previously
abandoned. Every changed line explained by the precedence disposition.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU
|
Validation receipts (cycle xl0b36, pre-#9745-merge tree e311e90; authoritative merged-head cycle running at 8f371a6):
— sent from bold-carp-449 |
…ctural-Bool-spelling emission row Under the unconditional kernel overlay the scalar synthetic Bool binding erased std.types' declared True|False structure, deleting the coproduct-payload refusal at kernel-Bool formals (floor red: bcp_foreign_coproduct_where_bool_required_must_refuse). The kernel binding now carries the structure its cited declaration has, in all three kernel-env constructors — the model repaired at the producer, no downstream kernel check. The peano Bool emission row is re-pinned: a bare direct import of the kernel spelling cannot displace kernel identity (the old expectation held only by ancestry occupancy); Rule-1 is the flip-back trigger, and the row now reds if leak-dependent resolution is reintroduced. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU
…odule-item-grain annotations Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU
…view 57892) Three kernel-environment producers each constructed the same Bool = True | False binding; one kernel_bool_type_node now serves all three, so the fact cannot fork. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU
… point (round 3, byte-converged) 27 files, two mechanical classes: the 04_infer projection (build_ancestry_precedence, kernel_bool_type_node consolidated per review 57892), and lambda-parameter annotations toggling with rustfmt reflow wherever Bool-typed accumulators participate — the annotation logic sees kernel Bool as a variant-carrying coproduct and declines the spelling (governed by the green w_lambda_param_annotation_declines_a_spurious_generic row). In-cycle proof at this tree: all 10 coproduct-payload rows PASS (bcp_foreign_coproduct_where_bool_required_must_refuse restored), all 12 peano rows PASS, board 160->155 (-5/+0), 604 lib tests, byte fixed point. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU
|
Answering review 57892 (REQUEST_CHANGES at 8c3db57) on the record: the finding — the kernel — sent from bold-carp-449 |
…y, not reachability — the fixture boundary reds with the exact claimed diagnostic A two-module fixture (recursive carrier sharing the bare spelling Nat + a std.nat consumer) is accepted by gunbc and refuses in cargo with expected-i64-found-Rc<i64>: the numeric guard hits while the bare-string-keyed layer sets are polluted by the unrelated recursive declaration. Section 23 now records the retraction, the executed reproducer, and restates the #9813 attribution as a hypothesis with its discriminator, since the whole-corpus attribution boundary has not published. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01VdQphfzTtHwuDqdNyuQQTC
…e Rc<i64> span-stamping arm is not live on main (#9842) * XL-0N-RC: subject-present measurement replaces the retracted REFUTED verdict; stale two-Nat citation repaired Positive control first, as the brief ordered: std.checked_arithmetic IS inside the measured census closure (v2.std.integer -> std.integer -> std.induction -> std.checked_arithmetic), both Nat authorities present, and the instrument discriminates -- disabling decl_file_realizes_natively reds the victim itself. On current main no arm reproduces the claimed expected-Rc<i64>-found-i64: the decl_file key hits through the alias, and the un-peeled authored_name_at in field_access_field_is_boxed has no authorable RED at field grain because needs_box_wrapping peels and boxes only recursive carriers. Recorded as section 23 of the shared coordination surface; no emitter edit ships without a discriminating red. Also repairs the doc's citation of nat_max_two_nat_authorities_note (deleted by #9794) to the stall row gunbc.guarantee_rung_drop two_nat_authorities_stall. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01VdQphfzTtHwuDqdNyuQQTC * XL-0N-RC amendment: the 'no authorable RED' verdict measured occupancy, not reachability — the fixture boundary reds with the exact claimed diagnostic A two-module fixture (recursive carrier sharing the bare spelling Nat + a std.nat consumer) is accepted by gunbc and refuses in cargo with expected-i64-found-Rc<i64>: the numeric guard hits while the bare-string-keyed layer sets are polluted by the unrelated recursive declaration. Section 23 now records the retraction, the executed reproducer, and restates the #9813 attribution as a hypothesis with its discriminator, since the whole-corpus attribution boundary has not published. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01VdQphfzTtHwuDqdNyuQQTC --------- Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com> Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
…t survives resolution (FreeMonoid+Char), natively reads the destination's own declaring file, witnesses re-anchor on the qualified boundary The #9813 kernel-precedence landing exposed that the text row was keyed on information resolution deliberately discards: String is a container-alias spelling, so every 'type X = FreeMonoid<Char>' boundary peels to the bare structural carrier and no module spelling survives to key on. The row now keys on that surviving structure — destination std.algebra.FreeMonoid with element std.types.Char (LiteralHomomorphism gains an element field, threaded through literal_homomorphism_for/elaborate_literal_at; peano and bool rows carry element: none). Second repair on the same boundary: destination_realizes_natively was read from the RESOLVED NODE's ident_span file, and a substituted alias RHS is a kernel-minted node whose pseudo-file <kernel:std.algebra.FreeMonoid> string-matched the '<kernel:' native-numeric roster row, so the peeled structural boundary answered natively=true and took DirectLiteral with the matching row present. natively is now read from the DESTINATION declaration's own census file (declaration_file_of in 04_env), per numeric_realization_identity_note's own rule that realization is a fact about the declaration. Witness battery re-anchored per the division ruling: the seven positive rows probe the QUALIFIED v2.std.text.String boundary (each probe imports string_is_empty so the harness's import-following closure loads the text module), and a new control pins bare String + text import = host, deterministically, under uniform kernel precedence. 12/12 text rows and 29/29 peano rows green by execution; stage0 mirrors regenerated to first-generation byte fixed point on the merged tree. Also: recurring_failure_mode row mistyped_body_radiates_nonlocal_diagnostics (the phantom-diagnostic specimen, layer stated), DESIGN.md and docs/design-ledgers.md regenerated via generated_artifact_gate main_wet_one, stale rust_host_string_seam_fn_emit comment fixed (review 57929). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01R4A6MRdzeYxNr7dRbugcUC
…-Unicode-scalar inhabitance carried into emission, text/list op realization by operand representation, no RustStdString row (#9720) * Emitted v2 compiler crate: a declaration's identity is its last segment, and a primitive with no realization refuses instead of inventing one Two roots behind 175 of the 260 rustc errors on the emitted v2 compiler closure (issue #9664, milestones 1 and 2): - 102 x E0425: the four DeclaredCallableIdentity constructions in v1.compiler.infer_lookup took decl_name from the AUTHORED spelling, so a qualified call carried the whole dotted path as the declaration name and emission rendered crate::v2_std_grammar::v2.std.grammar.f(..). - 73 x E0425: v2.std.algebra length is a ModeledProjection of the `length` primitive and rt_function_registry has no `length` row, so emission took rust_runtime_bridge_name's identity arm and wrote v1_rt::length -- a symbol the seed does not define. A primitive's identity and its per-target realization are two facts; CallTargetIdentity carried only the first, so every emitter had to ASSUME a bridge exists. RuntimePrimitiveCall now carries projected_from, the declaration the roster projected it from, and emit_rust routes to the bridge only when its own registry holds the primitive, falls back to the declaration otherwise, and refuses when neither exists. DeclaredCallableIdentity moves to v1.std.core so the target type can carry it without forking the pair. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU * Class B: the algebra method fallback asserted a v1_rt bridge it had not checked tier0 method resolution resolves an ordinary fn-typed RECORD FIELD through lookup_field_in_product, so `algebra.step(..)` arrives as AlgebraMethodSemantics carrying the field node as its method_def. The fallback at the end of that arm hardcoded runtime_bridge: true, which emitted `v1_rt::step` -- and made emit_rust_generic_method_call's own callable-field arm, guarded on runtime_bridge == false, unreachable for the exact receiver it was written for. 65 E0425s on the emitted v2 compiler closure (member, apply, is_empty, step, init, allocate_literal, ...) were that one literal. It now passes the realization question keyed on the same registry as the plain-call seam, so a real bridge method still lowers to a bridge, a callable field lowers as a field, and a name that is neither reaches the existing loud refusal rather than a fabricated symbol. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU * Only ModeledProjection carries projected_from: a HostRealizedSeam body is a self-call, so falling back to it would emit a nonterminating function The declaration fallback is sound only where the declaration's body is real code. HostRealizedSeam means the body IS a self-call, so emitting it compiles and then loops forever -- silent wrongness, strictly worse than the unresolved symbol it would have replaced. A seam whose target has no realization has no honest lowering, so it carries nothing and reaches emission's refusal. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU * M1: realize the two symbol bridges, which were host seams nothing declared to be host seams v2.std.compilers.lexing symbol_lexeme and symbol_intern_lexeme have self-call bodies -- the HostRealizedSeam shape exactly -- and the interpreter has carried real arms for both (v4_bridge.symbol_lexeme, v4_bridge.symbol_intern_lexeme). With no projection roster row the resolver saw ordinary declarations, so Rust emission emitted the declaration, and pub fn symbol_lexeme(sym: String) -> String { symbol_lexeme(sym) } COMPILES. The emitted closure carried two functions that type-check, pass every gate we own, and diverge from the interpreter by not terminating. Unlike the sibling seams (decl_facts and friends, which at least refuse loudly as unresolved v1_rt symbols) nothing anywhere reported this one -- it is absent from the E0425 census precisely because it is silent. extdeps.languages.rust.types already declares Symbol's target type as String, so on this target both bridges are the identity. That is a realization of the declared row, not a second opinion about it. Residue named, not closed: a self-call body is a DECIDABLE structural marker of a host seam, so the compiler could refuse an unrealized one rather than emit it. It does not yet; that check is the class's next-rung trigger. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU * Regenerate the stage0 mirror for the emitter repairs (fixed point at round 2) Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU * test.claim fixtures: one discriminating RED per closed emission class, with boundary controls Six rows over the three emitter defects plus the two symbol bridges. Each class's positive and negative assertion differ only in the fact the repair added, so no single edit satisfies both directions, and each repair carries a boundary control that would go red had it over-reached the other way (empty_map for the registry gate, a registered bridge method for the class-B gate). The symbol-bridge row is deliberately not an error-count assertion: that class COMPILED throughout the defect and diverged by not terminating, so a row asserting 'no error' would have been green the whole time. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU * Fix the class-B boundary control: count has a method template, so it never reaches the seam under repair count is answered by rust_simple_method_specs before the algebra fallback, so the row would have gone red while executing none of the code the repair touched. trim is in rt_function_registry and has no template, so it is one of the few names that actually reaches that fallback. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU * Unbreak the fixture parse: a trailing semicolon on the note declaration The module index refused the file outright, so none of the six witnesses were discovered. .dag item declarations carry no terminator. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU * The self-call seam wall: an unrealized host seam refuses instead of emitting compiling recursion A whole-body self-call is the decidable structural marker of a host seam. In the interpreter the shape is safe -- reaching it recurses to the evaluation-budget refusal -- but emitted to Rust the same shape COMPILES and returns to no caller. Nothing reported it: not the module index, not the compile-clean gate, not cargo check. That is why the two symbol bridges were invisible until someone read the emitted bytes. emit_fn_def now asks the realization registry -- the same authority the call sites ask, so the two cannot drift -- and suppresses the declaration when the seam is realized, refuses with a located message when it is not. Suppression rather than delegation is deliberate: a forwarding body would make this seam reconstruct signatures in target types, which is the cementing the existing suppressed-seam precedent avoids, and a realized primitive's calls all route to the bridge anyway. The predicate is whole-body identity, not 'contains a self-call'. Ordinary recursion has a match, an if or a let between the head and the call, so it never matches; expr_has_self_call walks children and would have refused most of the compiler. Both directions carry a fixture. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU * The seam wall must resolve realization through the roster's primitive, not the declaration name Measured, not predicted: the wall refused six seams in the emitted closure and one of them -- v2.std.collection empty_map_primitive_delegate -- is realized. Its roster row names the empty_map primitive, whose bridge is rc_empty_map, but rt_function_registry holds 'empty_map' and the wall looked up 'empty_map_primitive_delegate'. A declaration's name and the primitive it realizes are two facts; the roster is the authority that joins them, and the declaration name is only the fallback for a seam nobody has rostered. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU * The seam wall's realized arm must not suppress the declaration: suppression created 10 dangling imports Measured on the emitted closure with the wall finally in the mirror: removing a realized seam's item left 10 unresolved imports (E0432) for symbol_lexeme, symbol_intern_lexeme and resolve_type_node. Other modules import these declarations; the suppression created that breakage rather than finding it. And the reasoning that made suppression look safe is what makes it unnecessary. A realized seam's body IS a call to itself, and resolution already routes that call through the roster to the bridge -- so ordinary emission writes v1_rt::symbol_lexeme(sym) as the body without help. The wall's whole job is the UNREALIZED arm. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU * The seam refusal is a generated body, not a crate-wide compile_error!: rustc's denominator is larger than the demand denominator compile_error! fails the WHOLE crate, and that form silently assumes every seam it refuses is one somebody calls. It is not. rustc type-checks the entire emitted crate including declarations imported but never invoked, so the refusal denominator is strictly larger than the entry-reachable execution closure -- five unreachable seams took the crate down. The refusal is now a panic body with the declaration's real signature: dependent modules resolve, the crate compiles, and only an actual invocation fails loudly. That moves the refusal from the crate to the one declaration that earned it, and leaves reachability to a separate instrument. An entry-rooted pruner can replace the body later without revisiting this. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU * Two obligations the required floor found, both real consequences of this change DETERMINISM DENOMINATOR (9 reach_witness rows red, including determinism_denominator_is_closed_on_declared_primitives, whose entire job is to notice this). v2.lens.determinism closes its denominator over primitive_declared_definitions, so adding two canonical names without traversal facts made the closure false. Both bridges are scalar -- symbol_lexeme maps one Symbol to its text and symbol_intern_lexeme is its inverse -- so there is no collection to walk and OrderFreeResult is the honest arm. HostUnspecifiedOrder would claim a real traversal whose order the host does not pin, fabricating a leak the primitive cannot have. NAMESPACE WAVE ADMISSION (6 unadjudicated deltas). Four are TargetChanged for DeclaredCallableIdentity moving v1.compiler.infer_sigs -> v1.std.core, which is what lets CallTargetIdentity carry the declaration a runtime target was projected from. infer_sigs imports v1.std.core, so the type could not stay put without a cycle. Four enumerated rows, one per binding site; the two membership deltas auto-admit as ExplicitlyEvaluatedZeroDelta. Dissolve-on: this PR merging, by the same trigger the three prior shrinks record. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU * Class-C fixture was broken, not the repair: the witness pool is smaller than the corpus The row FAILED while the mechanism was green. The probe used the qualified spelling without importing v2.std.collection, which resolves against the real 4261-module corpus but not against compile_dag_rust_emit_check's 2973-module witness pool. Measured both ways: emitted against the corpus the same probe produces crate::v2_std_collection::map_get(m.clone(), "key".to_string()), exactly what the row asserts. The import restores module presence and does not answer the call -- decl_name comes from the authored spelling at the call site regardless of imports -- so the negative assertion still discriminates. Falsifier 2 is what proves that rather than argues it. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU * is_empty: a conversion is not a repair -- give it the Rust realization it never had Before the class-B change, xs |> is_empty emitted v1_rt::is_empty, a symbol the seed does not define: 5 x E0425. After it, the same 5 sites became typed refusals -- correct in kind, still 5 errors. The class-B repair made the gap visible; it did not close it. is_empty is an algebra template over FreeMonoid whose Rust realization is Vec::is_empty, exactly as count's is Vec::len, so the fix is one row in rust_simple_method_specs beside count. Nothing in 05_emit_rust learns a new name: realization is a target fact and lives in the target's registry. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU * A receiver's own callable field outranks every name-keyed table: class B survived one layer up The requested is_empty negative control found a live hole rather than confirming a safe one. Both rust_method_templates lookups are keyed on the bare method spelling with no receiver check, so a fn-typed record field named is_empty was captured by the target template and emitted as recv.is_empty() instead of (recv.is_empty)(..). The class-B repair fixed the algebra FALLBACK and left the two tables sitting in front of it. The hole is not new and is not specific to is_empty: count, first, join, split, take, skip, last, chars and enumerate have carried it for as long as they have had templates. Adding is_empty made it urgent by putting the spelling most likely to name a predicate field in front of that table. One helper, consulted at the top of both arms before every name-keyed special case, so the two cannot drift. Two controls: the new spelling and a pre-existing one. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU * Two more wave admissions: the declaring module rebinds too v1.compiler.infer_sigs used to DECLARE DeclaredCallableIdentity, so its own two construction sites resolved locally and produced no delta. Now that the declaration lives in v1.std.core and infer_sigs imports it, those sites rebind exactly like the consumers in infer_lookup. An enumeration error on my part, not a second transition: same subject, same trigger, same dissolve. Floor is now green on this branch (passed=2754 failed=0) -- the OrderFreeResult traversal facts closed all nine determinism rows. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU * The callable-field tier was consuming the algebra profile's identity domain, not the receiver's: 202 refusals on the first compile of the converged seed rust_receiver_has_callable_method_field asked rust_record_field_needs_fn_rc, which sweeps rust_struct_field_lookup_candidates -- and that list deliberately widens a receiver's name to its container template algebra. An algebra declares its operations as arrow-typed members, so under that widening every Map receiver "has a callable field" named map_keys, map_values, lookup or get, and the tier captured the very bridge calls it sits in front of. Measured at the first compile of the round-3 converged mirror: 202 rustc refusals, one class -- 164 E0609 (no field `map_keys` on Rc<im::HashMap<String, Rc<ItemInfo>>> and friends), 48 E0282, 4 E0615 on `get`. It is the same defect the tier was built to close, one level up: a name-keyed lookup consuming an identity domain that is not its own. The predicate now consults only the receiver's own declared record. w_map_receiver_operation_is_not_read_as_a_callable_field is the discriminating red: restore the candidate sweep and its must_not_contain clause fires. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU * Regenerate the stage0 mirror at the merge-equivalent tree: byte fixed point at round 3, six paths, each explained by an authority change Convergence transaction on srv1 (/tmp/xl0c.sh -> /tmp/xl0g.log), on 952ffa6 = main b726547 merged with the branch. Criterion is BYTE equality (sha256 over the whole candidate tree vs the whole installed tree), never first_generation_equal and never the changed-path list; the full workspace is rebuilt inside every round so a non-compiling mirror stops the line. round 1 cand e212fe74 inst 6f55cf3e installed, compiles round 2 cand 932b0543 inst e212fe74 drift = v1_rt.rs only (the two-hop: v1_rt.rs is rendered by the previously compiled rt_hash_ops) round 3 cand 932b0543 inst 932b0543 BYTE FIXED POINT -- produced by a compiler rebuilt from the round-2 installed tree Changed paths and their authority: extdeps_languages_rust_emit.rs <- rt_function_registry / rust_simple_method_specs rows std_primitive_projection.rs <- symbol_lexeme / symbol_intern_lexeme roster rows v1_compiler_emit_rust.rs <- 05_emit_rust.dag (seam wall, callable-field tier, class B/C) v1_compiler_infer.rs <- 04_infer.dag projected_from on RuntimePrimitiveCall v1_compiler_runtime_rust.rs <- runtime_rust.dag symbol bridges v1_rt.rs <- same, one hop later On these bytes: function_value_named_application_controls_witness PASSES (the d805243 / 952ffa6 rust-unit-tests red was the merge-driver-refused stale v1_compiler_infer.rs, not a semantic regression); emit 175 files; cargo check 15 errors: 9 E0425 (filesystem 2, V 2, K 2, Determinism 2, T 1), 2 E0728, 2 E0107, 1 E0391, 1 UNRESOLVED_CompilerError. No hand edit to any generated file. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU * WIP tail classes * WIP: if-equals-variant parses as a record literal; name the predicate * WIP: annotations at module-item grain * Regen round 1 (BuildBuddy invocation ebbdffc5, compiler gunbc=9830014a4e965ddb built from the committed mirror): v1_compiler_emit_rust.rs regenerated; candidate patch sha 05ce734c52890571 * Regen round 2 (BuildBuddy, compiler gunbc=75d74698aebcdb6e built from installed ce959e40604ffdd5): std_algebra.rs, std_nat.rs -- arrow returns now render through the Rust renderer (Rc<Vec<K>> for List<K>, Nat preserved); candidate patch sha b5b409aeebbeb6c4 * Arrow positions deviate from the generic renderer only for the two defect shapes: the unconditioned route emitted 2790 refusals where 15 stood; fix the arrow probe's variant spelling * B: the init turbofish declines a declaration's own formals by the lambda's admission; F: a qualified type reference earns its use-line from the qualifier under export proof; both earlier cuts were measured non-events and are deleted * Regenerate the stage0 mirror at the 0773184 freeze: byte fixed point at round 3, three paths, each explained by an authority change srv1 (/tmp/xl0e.sh -> /tmp/xl0j.log), criterion = every regen-population file byte-equal to installed; full workspace rebuilt as the gate each round. round 1 gunbc=1dc61ba198c6750b from installed 0479b0df9fc5598e -> v1_compiler_emit_rust.rs round 2 gunbc=909aa212f353bd03 from installed 8ebedc7445fadbaa -> std_algebra.rs, v1_compiler_trait_derive_emit.rs round 3 gunbc=0d0cd70ec5b20db9 from installed 8713cb43f8ad848c -> <none> BYTE FIXED POINT v1_compiler_emit_rust.rs <- 05_emit_rust.dag (gated arrow position, init turbofish admission, qualified-type use-lines) std_algebra.rs <- the gated arrow route restores the pre-e9900e2 spelling of the two arrow-typed fields v1_compiler_trait_derive_emit.rs <- one use-line synthesized for a qualified std.types.List reference under export proof Final installed tree 8713cb43f8ad848c. No hand edit to any generated file. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU * One renderer for every arrow position; a type position never takes the variant arm; the qualified route synthesizes use-lines only for types the emitted source names Four regressions the 0773184 fixed point put on the closure, each with its discriminating row: - E0603 x16: the qualified-type route synthesized `pub use crate::v2_std_nat::Succ;` for every `v2.std.nat.Succ { prev: .. }` record literal. A qualified name reaches the surface walk in the same dotted spelling whether it is a type or a variant head; the route now asks the registry whether the leaf is a TYPE declared in the named qualifier, records each decision as a census row, and considers only leaves the emitted source actually names (it had also synthesized an unused `DeclarationRef` import from a variant payload). w_qualified_variant_head_earns_no_type_use_line. - `Outcome<compile_error!("UNRESOLVED_CompilerError")>` x3 and `Rc<Medium>` E0107: two cuts had each introduced a second per-position renderer for arrow types beside the one fn parameters use. An arrow's return is not a different kind of type from its parameter: both positions now render through render_rust_fn_sig_type, and render_rust_type_with_applied_binding -- which rebuilt its EmitGraphInfo with an empty generic scope, so a fn-scope `C` rendered `_` (E0121) -- carries the fn's generic names through that hop. The measured gate over the second renderer is deleted. w_generic_arrow_return_renders_the_fn_scope_generic; w_arrow_return_type_keeps_its_applied_binding (its fixture was an invalid program: Accepted lacked `diagnostics`). - v2.std.determinism E0425 x2: traced to the bare-name disposition, not the qualified route -- `Determinism` is a type in std.determinism and a variant of v2.lens.registry LensIdV0, and is_known_variant is corpus-wide by spelling, so a TYPE-position reference was delegated to an enum it never named. A name in one of the module's type positions never takes the variant arm. a_known_variant_spelling_in_a_type_position_takes_the_registry_arm (red by construction on the old arm); the harness row is a positive control and says so, because the witness harness refuses any pool carrying the colliding variant with NoSuchVariable. Verified on a test binary built from the self-emitted emitter (not a regeneration): witnesses 23/24 -> 24/24 after the harness row was reshaped; closure instrument 2799 -> 2779. The regeneration that binds these to the mirror follows as its own commit after the freeze merge. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU * Regenerate the stage0 mirror at the 49482b0 freeze: byte fixed point at round 3, three paths, each explained by an authority change srv1 (/tmp/xl0e2.sh -> /tmp/xl0j2.log, launched 2026-08-29T19:52:56Z), criterion = every regen-population file byte-equal to installed; the full workspace rebuilt as the gate each round. round 1 gunbc=14967ca810cb6609 from installed db46176cc5cf5861 -> v1_compiler_emit_rust.rs, v1_tests_claim_reference_derived_disposition_census_witness_test.rs round 2 gunbc=5378a516528a6e0c from installed efa440bc86734f53 -> v1_compiler_trait_derive_emit.rs round 3 gunbc=974aafe864f743f6 from installed b1a0409ce9fc79d4 -> <none> BYTE FIXED POINT v1_compiler_emit_rust.rs <- 05_emit_rust.dag (arrow positions via the fn-signature renderer, generic scope through the applied-binding hop, type-position exemption, qualified rows with the registry type gate and token filter) v1_tests_claim_reference_derived_disposition_census_witness_test.rs <- its .dag (in_type_position at 5 callers + the type-position control) v1_compiler_trait_derive_emit.rs <- retracts the unused `pub use crate::std_types::List;` the earlier qualified route synthesized (token filter) Final installed tree b1a0409ce9fc79d4; merged tree 89c55a0e7e8d949047b5d92864dfc9fe306aebc0 at the freeze; main parent 5e80671. No hand edit to any generated file. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU * Witness fixture only: the qualified-type positive control moves to a provider the harness pool can carry Post-freeze, fixture-only (dag/test/claim is not a regen-population path; a no-drift regen run on this head is recorded in the PR). Two harness facts, both measured on the fixed-point artifact gunbc=974aafe864f743f6: a `{Determinism}` inside a .dag string literal is read as an interpolation of that name (the row failed in the interpreter before any compile ran), and the harness pool is the probe's DECLARED import closure, so a provider referenced only by a dotted name is absent -- and std.determinism cannot enter it because its own body references std.perturbation the same way. The row now uses std.decl_ref with a sibling import and says plainly that it is a positive control; the class's discriminating red stays at the disposition grain (a_known_variant_spelling_in_a_type_position_takes_the_registry_arm) and in the closure count. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU * WIP XL-0B commit 1: thread DeclarationRef into the checkpoint-spelling callers; exact binding first; delete the redundant expression-position alias arm * Enroll the two emission batteries under the required-gate seed prefix (test.claim.self_host_*) * XL-0B commit 1: exact spelling at the fn-signature and declaration-type leaves; alias-rhs site reads scope.type_env * alias-rhs leaf site reads scope.type_env * Regenerate the stage0 mirror at the XL-0B commit-1 tree: byte fixed point at round 3 Cycle on srv1 over a1c9dde (authority tree bc2ae136138ac4aa), gate bins built each round: round 1: compiler e33c998203b59217 from installed df30d05facfa6307 -> drift v1_compiler_emit_rust.rs round 2: compiler ad9914da781db28d from installed c475b249666c3ba5 -> drift std_nat.rs, std_types.rs round 3: compiler c7ac6e91c1e07861 from installed be968e441d3a2a43 -> every regen-population file byte-equal CHANGED paths, each explained by the authority change: v1_compiler_emit_rust.rs (the threading); std_types.rs (Bytes/Secret/SecretValue declaration sites now spell the exact grounding std::vec::Vec<u8> / std::string::String); std_nat.rs (List<Nat> in container-argument position renders the closed alias's resolved numeric realization i64 -- type-identical to Nat = i64). Unit tests on the converged bytes: 552 passed, 0 failed, 140 ignored. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU * XL-0B commit 2 (source): declared callees imported over builtin capture; dead RebuildEmittedFail variant; Accepted diagnostics bound and threaded; WallNow carries its fields; evaluator binding-miss answers the PartialFunction codomain; Optional-nested variant qualified by its own enum; Clone for generics forwarded by a returned closure * Regenerate the stage0 mirror for commit 2 (mechanical residue): byte fixed point at round 2 Cycle on 8781269 (main parent d35cda54): round 1 drift on v1_compiler_emit_rust.rs and v1_compiler_trait_derive_emit.rs (the two files commit 2 edits), round 2 byte fixed point; installed tree 7fcf44b9f5c9df97, gunbc 2146d1f1844dea92. Unit 552/0. Emitted closure cargo check 420 -> 392; line-insensitive identity diff vs the merged-tree base: 28 removed, 0 added (E0061 x6 vocab arity, E0599 GlobalBare* x4, E0004 x7, E0533, E0271, E0618 x2, returned-closure Clone x7). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU * A1: relocate the import-admission helpers to their consumer layer; C: one storage representation for Map at every position A1 (closure prune). Counting fully qualified code references as declared edges, the declared closure from v2.compiler.compile equals the emitted set: no module enters by bare-name binding. The carrier was 03_name_resolve importing v2.lens.reference_deps for admission_from_module_root / import_rows_from_parsed_module / collect_import_decl_nodes / ImportRowsState, consumed only by v2.workflow.compile_door_ledger and self_host.frontier_probe (both outside the closure, both already importing reference_deps). They now live in reference_deps; the two consumers import them there. Emitted closure drops 8 modules (lens.coverage, enforcement.{grammar_coverage,standing_intent,vocab}, registry, module_graph, reference_deps, std.decl_index) and all 6 host-primitive panic sites. C (Map). The six PartialFunction<..> positions (InferredTree.facts, EvaluationEnvironment.bindings, four signatures) are Map<..>; the four PartialFunction { lookup: .. } constructions are empty_map() or a first-wins map_insert fold; map_insert routes through a rostered map_insert_primitive_delegate (closure body deleted); slots.lookup -> map_lookup. Emitter: the alias RHS renders a keyed/element collection through the host template (type X = Map<A, B> -> Rc<HashMap<..>>), and a generic in map-key position carries std::cmp::Eq + std::hash::Hash from the signature. Two witness rows added. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU * XL-0N: generic LiteralElaboration/OperatorRealization authority — typed literal-to-Zero/Succ homomorphism at every boundary, operator realization by exact operand structure, structural Peano Nat operations (no i64 row) * XL-0N: the Peano-Nat inhabitance witness asserts the ruled admission through its homomorphism; its expected-red row is retired by its trigger * XL-0T commit 1 (source): UnicodeScalarSequenceUnfold arm + text homomorphism row; scalar-sequence literal image as the canonical list introduction; identity wall on the spelling-compatibility fallback; delete the four host string-op body overrides and the inert host_string_text seam pair; structural-text witness battery Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM * C corrected: InferredTree.facts stays the open PartialFunction; PartialFunction realizes as its algebra struct everywhere (HashMap rows deleted); frontier row dissolved; two TargetChanged admissions The CI floor on 4da6059 showed the facts retyping over-reached: about 120 test and fixture sites plus program.dag / 05_emit_orchestration define InferredTree.facts by a predicate closure, which is exactly what the open carrier is for. inferred_tree / 04_infer / program_partition are restored. The fork was the emitter realizing PartialFunction as HashMap in signature position and as the algebra struct in field position; the PartialFunction HashMap rows in extdeps.languages.rust (types.dag row, the partial_function template) are deleted so one representation stands. EvaluationEnvironment.bindings stays Map (built by map_insert); v2_effect_io_pure's empty environment is empty_map(). The v1 unresolved_method_frontier row for target_model lookup / Primitive(T) is deleted: the slots.lookup -> map_lookup rewrite dissolved its one occurrence. The two TargetChanged binding deltas for admission_from_module_root (frontier_probe, compile_door_ledger) are admitted by exact subject in namespace_wave_admission.rs. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU * XL-0N: operand realization hops alias/refinement declarations to their target (NonEmptyStr, Char, VersionIdentity compare/add as their host targets) * Regen round 1: install the stage0 candidate at the XL-0T commit-1 tree (BuildBuddy, old-compiler bootstrap round; three new mirrors: std_literal_elaboration, std_operator_realization, gunbc_structural_realization_bindings) Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM * Regen round 1 fixup: restore the three hand-maintained ExprElaboratedLiteral interpreter arms the bootstrap revert had carried into the round-1 install Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM * Regenerate the stage0 mirror for A1 + C (aa373f9): byte fixed point at round 3 Round 1 changed the five authority mirrors (extdeps_languages_rust_emit, extdeps_languages_rust_types, std_primitive_projection, v1_compiler_emit_rust, v1_compiler_infer), round 2 only compiler_tests.rs, round 3 byte-identical; installed tree f53efd0d0173a43e, gunbc 1a2d53dd15920cf1. Unit 552/0. Emitted closure cargo check 392 -> 278; line-insensitive identity diff vs commit 2: 112 removed, 0 added. Batteries on the converged binary: 29/29 (the two C rows red on the pre-fix compiler by fixture emit), 14/14, 20/20. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU * Regen round 2: extdeps_version_semver.rs and std_unicode_types.rs converge under the round-1 compiler Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM * XL-0N: Bool row -- KernelBoolLiteral into v2.std.logic.Bool via BooleanUnfold (True/False); interpreter evaluates an elaborated literal as its kernel value; falsifier pair (row found/removed in the interpreter, constructor image vs host keyword on the emitted path) Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013koFunEtpLQCnvUiz85k7Y * Back out the round-2 convergence of extdeps_version_semver.rs / std_unicode_types.rs: the round-1 compiler's operator-realization wall refuses < on NonEmptyStr/VersionIdentity and + on Char despite the 657010b alias-hop, so the converged mirrors carry compile_error! and the lib does not build; XL-0N owns the hop Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM * XL-0N: operand realization hops alias items by is_type_alias_item/resolved_type (the derive lane's own test) -- the structural condition on the declaration node never held, so NonEmptyStr/Char/VersionIdentity host ops were refused in the regenerated compiler Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013koFunEtpLQCnvUiz85k7Y * Regen round: converge the union tree (semver/unicode mirrors regenerate under the alias-hop; elaboration authorities and emit/infer mirrors carry both lanes' arms) Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM * Commit 3 of the #9664 closure: six emitter mechanisms, the null keyword by path, and map_insert back to its .dag body under the gate's ruling Emitter (src/v1/05_emit_rust.dag, trait_derive_emit.dag), each with a discriminating row in self_host_emitted_call_target_realization_witness_test (pre-fix bytes observed on the seed): - an argument into a parameter spelled Optional<T> is not unwrapped (the cardinality flag marks only the T? sugar; the applied spelling is asked too) - the shared-field accessor impl of a generic coproduct carries T: Clone - a Violates literal in a record field takes the field's Witness carrier before the fn return - a record pattern over a shared carrier derefs like a shared enum's variant pattern - a fn returning an arrow-field record carries 'static on its generics (same gate as impl Fn) - the fn-field record header prints well-formedness bounds asked per parameter instead of the bounded set minus the seed set (FalsificationReceipt<Subj, A> lost A behind ValueDiff<A: Clone>) - extdeps.languages.rust emit: the null keyword is std::option::Option::None, because a module declaring a nullary variant named None emits pub struct None; at module scope (std.cache_interface) v2.std.collection: map_insert is its .dag body again and map_insert_primitive_delegate with its primitive_projection row is deleted. The delegate tripped map_carrier_shape_gate on CI at c6d9b22 (record_shaped_map_reaches_map_insert BUDGET-REFUSED): the interpreter's free_call.map_insert arm answers Ok(None) for a non-native shape and the grounding falls through to the delegate's own body, a self-call -- the deferred-refusal class #8887 filed. The closing move is a host fact (a typed refusal in try_v2_std_collection_map_primitive_grounding) and is ledgered in the PR body, not landed here, by the manager's ruling. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU * Bootstrap ordering: back out the refusal-bearing semver/unicode mirrors once more — round 4's candidate was emitted by the pre-hop compiler; the hop-carrying emit_rust mirror is installed, so the next round regenerates them clean Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM * Hoist commit-3 rationale annotations to module-item grain (§4c refuses in-body // blocks; 17 regen refusals on 780b394) Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU * XL-0N: operand realization reads the RESOLVED structure -- a NoConnective childless leaf whose structural name is a kernel type is a host operand (the resolver collapses NonEmptyStr/Char/VersionIdentity to their primitive RHS under the alias identity, so no resolved node is ever an alias item); refusal temporarily carries the operand's shape facts for the regen diagnosis Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013koFunEtpLQCnvUiz85k7Y * Regen: install the hop-3-bearing emit_rust mirror only; semver/unicode stay at pre-wall bytes until a hop-3 compiler emits them (bootstrap ordering) Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM * Revert "Regen: install the hop-3-bearing emit_rust mirror only; semver/unicode stay at pre-wall bytes until a hop-3 compiler emits them (bootstrap ordering)" This reverts commit c83e528a108c8834e19a72976b611642033497ed. * XL-0N: shape-facts suffix spells Int counts with to_string (the seed runtime has no Int-as-String cast; the cast panicked the emitter under regen) Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013koFunEtpLQCnvUiz85k7Y * XL-0N: operand realization hops a where-refinement wrapper to its base (is_where_refinement_type, the type renderer's own route) -- measured under regen: NonEmptyStr/Char/VersionIdentity operands resolve to the one-child Conj refinement node, not a leaf or an alias item Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013koFunEtpLQCnvUiz85k7Y * XL-0N: operator realization matches over BinOp are total (14 closed variants enumerated) -- no non-fold residue rows for the new module Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013koFunEtpLQCnvUiz85k7Y * Commit 3 correction after the first regen: withdraw the Violates field-carrier arm (the literal resolves to the Witness declaration, spelling Witness::<Holds> at 87 sites), 'static on generics only for fn-field record returns (compose<A, B, C> stays bare), re-pin the optional and shared-record rows Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU * Revert the identity wall in the corpus-wide compatibility relation: its first floor execution refused grounded-identity code (roadmap_page if-join, Ruling 3); the non-literal refusal is blocked on the peeling declared-boundary conformance capability and recorded as such Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM * Enroll std_literal_elaboration in the stage0 std-core partition roster (v2.workflow.rust_crate_partition): v1_std_core imports it, so the layered crate must own the module ahead of v1_std_core Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM * XL-0N: retire the regen-diagnosis shape-facts suffix -- the where-refinement hop is confirmed at byte fixed point (6ba83b3 regen, round 2 equal) Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013koFunEtpLQCnvUiz85k7Y * XL-0N: regenerated stage0 mirrors at byte fixed point (070a203 source, BuildBuddy regen round 3 first_generation_equal=true; partition crates rendered=14 written=0) Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013koFunEtpLQCnvUiz85k7Y * Regen: mirrors catch up with the wall revert (infer_types, emit_rust, lib, emitted_population); semver/unicode held at pre-wall bytes until the where-refinement hop merges Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM * XL-0N: register std.literal_elaboration and std.operator_realization in the std-core partition and gunbc.structural_realization_bindings in the v1-infer binding unit (v2.workflow.rust_crate_partition), with their module-dag edges Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013koFunEtpLQCnvUiz85k7Y * Regen: merged-tree round — emit_rust re-carries both lanes; std_nat/std_types/std_operator_realization converge; semver/unicode byte-equal to pre-wall under the where-refinement hop Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM * XL-0N: type_reference_declaration_ref resolves an in-place (recursive) type reference through its env binding before matching the declaration span -- v2.std.nat.Nat is recursive and answered Absent, so its literal boundary and operand identity fell to the unavailable arms while v2.std.logic.Bool worked Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013koFunEtpLQCnvUiz85k7Y * Regen: std_nat/std_types converge to the exact-grounding spellings (i64 container args, std::vec::Vec<u8>/std::string::String) Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM * Rung drop: non-literal kernel-String refusal at the structural text boundary (text_boundary_identity_wall) Rosters the reverted identity wall as a DESIGN 4b(3) declared drop: previous rung (the wall as landed), temporary rung, the roadmap_page grounded-identity refusal that forced the revert, population, and a restoration trigger naming the declared-boundary conformance peeling capability with its sufficiency. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM * Projection regen: partition roster gains std_literal_elaboration; rung-drop roster projects text_boundary_identity_wall into DESIGN.md and design-ledgers Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM * Partition mirror + std-core crate carry std_literal_elaboration; rung-drop row per ruling (two-path standing, identity-census population, A/B trigger); planted non-literal restoration probe The roster edit only reaches the crate renderer through its compiled-in mirror (gunbc_stage0_crate_partition_generated.rs), so the sequence is projection -> regen -> rebuilt claim_executor -> emit-partition-crates, which wrote the std-core lib.rs row that clears the partition E0432. The rung-drop row is reworked to the ruling's grain: no rung claimed for the withdrawn wall, emitted-Rust path mechanically preventable vs source-acceptance path unguarded (never averaged), population bounded by identity with the wall re-applied as the named producer, and the two-direction A/B restoration trigger. The witness battery gains the planted non-literal probe asserting the present acceptance. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM * Projection: design-ledgers carries the reworked text_boundary_identity_wall row Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM * Total the two LiteralUnfolding producer matches in peano_nat_structural_realization_test over UnicodeScalarSequenceUnfold The floor refused at 216a7d4 on the two non-exhaustive matches once the new producer arm entered the coproduct. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM * XL-0N: regenerated stage0 mirrors at byte fixed point on e51aff9 (BuildBuddy regen round 3 first_generation_equal=true; includes the merged #9710 commit-3 null-keyword-by-path drift and the new-module mirrors) Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013koFunEtpLQCnvUiz85k7Y * Bootstrap: reset stage0 mirror tree to origin/main's self-consistent set; the next regen round re-derives the session's authority changes Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM * XL-0N: type_reference_declaration_ref falls back to the module-visible name binding when the reference carries no ident-keyed binding (the emitter's scope env) -- the found declaration is still span-matched against the global roster, so a by-name hit only confirms an exact declaration; measured: Peano literal rows passed while the operator rows still lost Nat's identity Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013koFunEtpLQCnvUiz85k7Y * Regen round on the merged tree: re-derive session mirrors from main bootstrap (new std_literal_elaboration/std_operator_realization/structural_realization_bindings mirrors, partition std-core row) and restore the four hand-maintained ExprElaboratedLiteral interpreter arms Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM * Interpreter hand roster: EXPR_VARIANT_COUNT 23 with the ExprElaboratedLiteral arm restored Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM * Exact identity for a resolved alias destination: type_reference_declaration_ref falls back to the reference's env binding when the resolver's substitution carries the occurrence span The resolved-alias case (v2.std.text String = FreeMonoid<Char>) answered none from the census because the substituted node's ident_span is the annotation site, so every text.String literal boundary elaborated as DirectLiteral while the declared coproducts Bool and Nat worked. Second hop = the same env-binding read e51aff9 added for in-place recursive references; both hops answer by declaration span from the census, never by spelling. Also carries the partition std-core lib.rs write from the converged round. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM * Third identity hop: a resolver-qualified authored name joins the census by (module_path, name) Modules that reference a type with no import resolve it by the resolver's qualification, so lookup_type_for has no binding and both span hops answer none while the emitter still realizes the structural carrier -- the literal boundary stayed DirectLiteral exactly there (measured: the data prose rows in v2.compiler.source_authority and extdeps.languages.dag, which import no String). The qualified prefix is joined against the census row, never trusted as a spelling. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM * Regen: infer_env mirror carries the two identity hops Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM * Cached-data emission renders an elaborated literal through the typed-expression emitter The JSON mock route serializes nested-record VALUES and has no spelling for the elaborated image; its wildcard refused every structural-text data row with 'unsupported mock expression' after the elaboration fired (measured on the anchor probe). The image is ordinary constructor nodes and renders like any expression. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM * Move the elaborated-literal data-arm rationale out of the fn body (4c: module-item grain only) Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM * Regen: emit_rust mirror carries the elaborated-literal data arm Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM * XL-0T: host-text carrier spelling chosen by declaration identity -- a known non-structural String reference renders the grounding spelling std::string::String, unshadowable by the generated structural use line Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM * Unescaped interpolation braces in render_rust_text_carrier_identity_note quoted the generated use line verbatim; regenerated mirror emitted string.clone() -- quote it without braces Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM * Class row generated_binding_shadows_bare_render: a generated use line rebinding a bare-spelled render composes into silent wrong realization; fix is declaration-identity-keyed rendering with the grounding spelling Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM * Route all six type-renderer host-text short-circuits through the identity-keyed render_rust_text_carrier -- the first-line bare-String renders at render_rust_type/without_applied_binding/applied/decl/fn_sig/in_scope were still spelling-keyed Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM * Reference-binding hop precedes the resolved-node hop in type_reference_declaration_ref: alias expansion is closure-dependent, so the inferred node names the realization the alias peels to (std.algebra.FreeMonoid) while the boundary identity is the declaration the author named (v2.std.text.String); measured pd/pe/pf probes flip on std.types presence alone Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM * Regen: mirrors converged at first-generation byte fixed point over the identity-split emitter and reordered identity hops (fixed point re-verified with the final binary) Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM * Projections: DESIGN.md/design-ledgers.md carry generated_binding_shadows_bare_render; stage0 partition roster regenerated Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM * Regen: mirrors re-converged on the merged tree (first-generation fixed point verified with the rebuilt binary) Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM * Projections: DESIGN.md re-projected on the merged tree Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM * Identity answers guarded by the authored leaf name (rejects the alias-expansion artifact without letting name-keyed hops outrank the exact resolved-node hop -- the reorder regressed the Peano battery on the Nat homonym); grounding spelling scoped to modules whose bare String binding is structural (corpus-wide grounding redded two witnesses pinning the bare kernel spelling) Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM * A rejected expansion artifact re-derives its destination from the module-level name binding, not the per-node one: lookup_type_by_name is import-driven and uniform across the module, so one module cannot split into structural annotations beside host values (measured 108->174 board regression under the per-node fallback) Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM * Terminal census hop: when the annotation is unresolved and no env binding names it, a UNIQUE global_bare declaration of the authored leaf is the destination (the documented global-uniqueness resolution rule); ambiguity stays Absent, fail closed. Measured: pd anchor reads expected present, n=String rtn=noresolve bare=unique:v2.std.text -- every existing hop declined while the census carried the answer Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM * The unique-census hop is the terminal fallback for EVERY Absent outcome of the identity hops, not only the by-name arm -- the measured failing path was lookup_type_for answering a binding whose census read fails, which returned Absent without ever consulting the census Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM * One subject, one answer at the literal boundary: the natively-realizes fact is read from the DESTINATION declaration's census file, not re-derived from the reference node's span -- a kernel-minted annotation span (<kernel:String>) answered natively=TRUE against a v2.std.text.String destination, keeping the literal direct at a structural boundary; node-span file remains the fallback when the census has no row Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM * Type repair: route the census-file read through span_file_string so the FilePath product coerces at a String return boundary (the inline if/else mixed Product(FilePath) with a String literal and regen refused, invalidating the prior round's probes) Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM * One authority for the text spelling: render_rust_text_carrier consults type_reference_declaration_ref + the destination census file -- the same reader the literal boundary uses -- rendering a structural destination as the qualified crate path and everything else bare; the module-binding heuristic and grounding spelling are deleted (both measured wrong in opposite directions) Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM * Retract the terminal unique-census hop: a corpus-unique declaration is not the destination of a reference the module never bound -- it invented structural identities for the whole kernel corpus (census 108->569/437 measured). The census read survives only where a module-level binding EXISTS and its own census read fails, and as the natively-coherence file source. Consistency now rests on the one-authority renderer: infer and emit consult the same reader, so whichever answer identity gives, annotation and value agree Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM * Mirror reset to main's self-consistent set (the ours-side merge resolution mixed pre-main mirrors with main consumers of compile_sources_selected -- E0432 on round 1); hand-maintained interpreter arms re-inserted (4 ExprElaboratedLiteral arms, EXPR_VARIANT_COUNT 23) Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM * Interpreter mirror back to main's for bootstrap round 1 (the hand arms reference ExprElaboratedLiteral, which only regen adds to v1_std_core); the arms are re-inserted mid-convergence and land with the regen commit Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM * Revert the identity-reader widenings and emitter spelling experiments to the c7b8056-compatible three-hop state, recording each measured failure in place: leaf-name guard 108->174, terminal census hop ->569, module-binding rederivation ->437, one-authority renderer ->745. The shadowed-module class stays open under the boundary-lane declared drop with its fix shape on the class row; natively-coherence (destination census file) is kept Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM * Parse repair: orphaned closing brace left by the renderer revert Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM * Complete the revert: natively back to the node-derived decl_file (the census-file coherence read was deleted with the census hops and its consumer refused regen) Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM * Merge repair: the row-union dropped my class row's evidence/closing lines when the conflict markers were stripped mechanically -- both rows now well-formed (this parse error silently refused regen, which my capture filters then hid) Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM * Regen: mirrors converged at first-generation byte fixed point on the merged tree (rounds 2, 3 and the final rebuilt-binary check all equal); interpreter hand arms restored; DESIGN/design-ledgers projections carry both new recurring-failure class rows Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Qao5PDTLMpAjCGQDUELuiM * Round-1 bootstrap coherence: stage0_std_core lib.rs taken from main alongside main's stage0 mirror set (regen re-derives the literal-elaboration rows) * Regen: converged at first-generation byte fixed point on the round-1 bootstrap tree — literal-elaboration/operator-realization/structural-bindings mirrors re-derived and installed, partition lib rows and the four ExprElaboratedLiteral interpreter hand arms restored (EXPR_VARIANT_COUNT 23) Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01R4A6MRdzeYxNr7dRbugcUC * Regen: converged at first-generation byte fixed point on the re-cut tree (round 2 equal) — the mirror delta vs main is exactly the four text-family files the re-added UnicodeScalarSequenceUnfold row touches Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01R4A6MRdzeYxNr7dRbugcUC * Floor fixes for the re-cut head: totalize the two LiteralUnfolding matches in peano_nat_structural_realization_test over the re-added UnicodeScalarSequenceUnfold variant (both witnesses PASS scoped), and retire the XL-0N #9719 wave-admission row by its own dissolve-on trigger (base and head both carry the relocation; the run on bc74b2e reported it stale) Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01R4A6MRdzeYxNr7dRbugcUC * Re-cut floor recovery: restore the literal-destination identity hops (declaration_ref_of_type_node with by-name + qualified-census fallback, scoped to the elaboration destination read; XL-0N's operand reader untouched), delete the resurrected name-keyed text op overrides and host_string_text seam arms from 05_emit_rust, restore the ExprElaboratedLiteral arm in data-value emission, and narrow the ops witness excludes to the overrides' exact receiver forms (bare .is_empty() red the structural Vec lowering — substring-oracle over-match). Text battery 11/11, peano 29/29, regen at byte fixed point Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01R4A6MRdzeYxNr7dRbugcUC * Post-merge repair: rebuild rung_drop.dag from main's version plus the text_boundary_identity_wall row intact (the union regex had split on a '=======' line inside an authored string — parse error at the module index), retake main's stage0 set (the generated-artifact merge driver had left ours-bytes marker-less on namespace_wave_admission.rs), regen re-derives the six text-family mirrors to the byte fixed point (round 2 equal); text battery 11/11, peano 29/29 Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01R4A6MRdzeYxNr7dRbugcUC * Structural key for the text literal homomorphism: the row keys on what survives resolution (FreeMonoid+Char), natively reads the destination's own declaring file, witnesses re-anchor on the qualified boundary The #9813 kernel-precedence landing exposed that the text row was keyed on information resolution deliberately discards: String is a container-alias spelling, so every 'type X = FreeMonoid<Char>' boundary peels to the bare structural carrier and no module spelling survives to key on. The row now keys on that surviving structure — destination std.algebra.FreeMonoid with element std.types.Char (LiteralHomomorphism gains an element field, threaded through literal_homomorphism_for/elaborate_literal_at; peano and bool rows carry element: none). Second repair on the same boundary: destination_realizes_natively was read from the RESOLVED NODE's ident_span file, and a substituted alias RHS is a kernel-minted node whose pseudo-file <kernel:std.algebra.FreeMonoid> string-matched the '<kernel:' native-numeric roster row, so the peeled structural boundary answered natively=true and took DirectLiteral with the matching row present. natively is now read from the DESTINATION declaration's own census file (declaration_file_of in 04_env), per numeric_realization_identity_note's own rule that realization is a fact about the declaration. Witness battery re-anchored per the division ruling: the seven positive rows probe the QUALIFIED v2.std.text.String boundary (each probe imports string_is_empty so the harness's import-following closure loads the text module), and a new control pins bare String + text import = host, deterministically, under uniform kernel precedence. 12/12 text rows and 29/29 peano rows green by execution; stage0 mirrors regenerated to first-generation byte fixed point on the merged tree. Also: recurring_failure_mode row mistyped_body_radiates_nonlocal_diagnostics (the phantom-diagnostic specimen, layer stated), DESIGN.md and docs/design-ledgers.md regenerated via generated_artifact_gate main_wet_one, stale rust_host_string_seam_fn_emit comment fixed (review 57929). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01R4A6MRdzeYxNr7dRbugcUC --------- Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com> Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
…ence from the containment authority — and retire #9813's module-wide precedence at the root. AUTHORING AUTHORIZED by ruling, MERGE HELD for root-cut receipts. Local use-line/qualification repairs are DEAD. (#10236) * The candidate index built once, then revalidated the whole transport per reference std.occurrence_binding_candidates resolve_reference_via_structural_candidates documents that it builds the candidate index exactly once per transport, and it does. Per reference it then called std.occurrence_binding_resolve resolve_reference_occurrence_binding, whose first act is occurrence_transport_validate over the WHOLE transport -- three full folds across every index entry, declaration and reference. So the once-built index was defeated one layer below itself and the path was O(references x population). MEASURED, NOT REASONED, on the same subject in both directions: the census instrument added here resolving dag/std -- 142 files, 9672 type-occurrence references -- ran past a 45-minute wall producing nothing. After the repair the same run over the same subject completes in 8 seconds. THE REPAIR IS FEWER REPRESENTATIONS OF ONE FACT, NOT A CACHE. occurrence_candidate_index_build already validates exactly once and already held the whole ValidatedOccurrenceTransport; it kept entries_by_id and discarded the other four fields, which is precisely what left the resolver unable to hand a validated transport down. OccurrenceCandidateIndex now carries the ValidatedOccurrenceTransport itself -- entries_by_id is reached through it, so there is no second copy to drift -- and the resolver calls the ALREADY-EXISTING resolve_reference_occurrence_binding_validated. This is DESIGN section 2's demand-graph move (carry the value to the shared ancestor), not a memoization, and DESIGN section 6's bare-minimum-cost standing rule settles it independently: a proven cost-shape defect is always fixed regardless of realized n. Here n is every type occurrence in the corpus. BOTH SITES, because one fact with two homes is what lets a repaired path sit beside an unrepaired one answering the same question. std.reference_binding_observation structural_binding_resolution_from_candidates had the identical shape and is repaired with it. THE `transport` PARAMETER IS GONE from both entry points rather than left unused: a second unvalidated OccurrenceTransport beside the validated one is two representations with nothing forcing them to be the same transport, and a caller handing in a different one would resolve silently against whichever arm read it. BEHAVIOUR IS PRESERVED BY THE EXISTING WITNESSES, which is why this carries no new behavioural test. resolve_type_reference_containment_binding and structural_binding_walk keep their signatures, so test.claim.type_reference_containment_binding_witness_test, test.claim.type_reference_binding_context_witness_test and test.claim.occurrence_binding_candidates_witness_test assert the same bindings through the changed code. What changed is cost, and the instrument -- not a transcribed number -- is what re-derives it. WHY IT IS NOT BUNDLED WITH THE XL-0T CUTOVER IT WAS FOUND UNDER: the cut routes every type occurrence in the corpus through this path, so switching type-position consumers to it while it revalidates per occurrence would ship a regression even if every binding answer were right. It is a prerequisite of that cut, and a cost repair and an authority cutover are two subjects. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01KLXA6u6f3UK8PR5VEJoUwm * The parser never stamped a type DECLARATION, so every type reference in the corpus was unbindable MEASURED FIRST, over dag/std (142 files) with the census instrument's --denominator mode: 9672 TypeOccurrence REFERENCES against type_occurrence_declarations=0. TypeOccurrence appeared four times in v1.compiler.parse -- the enum member and three ParsedOccurrenceReference sites -- and ParsedOccurrenceDeclaration was produced with FieldOccurrence, LexicalValueOccurrence, CallableOccurrence and NamespaceSegmentOccurrence, never with TypeOccurrence. std.occurrence_binding_candidates buckets candidates by authored spelling and std.occurrence_binding_resolve admits a TypeOccurrence reference against a TypeOccurrence declaration only, so an empty declaration side made EVERY type reference in the corpus Unbound -- not mis-bound, UNBINDABLE. The containment authority the namespace cut resolves through was correct, executing, and had never been fed a production population. THE DISCRIMINATING CONTROL that located it upstream of visibility: all three DeclarationExposureGrounding values returned BYTE-IDENTICAL partitions. Exposure decides visibility and is the variable the census varies; a zero insensitive to it cannot be a visibility result. WHY NO FIXTURE COULD HAVE SHOWN THIS. test.claim.type_reference_containment_binding_witness_test hand-builds its declarations with `category: TypeOccurrence` -- exactly the shape production never emitted -- so the suite supplied the missing side itself and stayed green. DESIGN section 5's specification-without-execution boundary, sitting on the DESTINATION authority of a migration, where a green suite is not weak evidence but zero evidence. Those fixtures are untouched here: they test the authority's logic correctly, they were never SUFFICIENT, and nothing in the tree said so. THE RULE IS STATED POSITIVELY rather than as "not a function": a module item declares a type when it has no body, no transport and no type annotation. That admits the three authored forms -- `type X { .. }` (Conj), `type X = A | B` (Disj), and the bare alias `type X` -- and excludes by construction the items that are values or effects: a function has a body, a `data x: T = v` has a body AND an annotation, a service carries a transport. Imports cannot be caught by it: they live in the module node's params and are stamped on a different path from its children. RESULT, same instrument, same subject, dag/std: type_occurrence_declarations 0 -> 1243 Y bindings 0 -> 3057 partition still closes at 9672, zero unclassifiable and the five-way census the cut needs has content for the first time: 2786 OldAndNewAgree, 2203 OldBinds_NewUnresolved, 3136 OldKernel_NewUnresolved, 909 OldSynthetic_NewUnresolved, 367 OldUnresolved_NewUnresolved, 250 OldSynthetic_NewBinds, and 21 OldAndNewDisagree -- the first real binding deltas anyone can adjudicate. SCOPE IS DECLARED SO THE NEXT INCREMENT IS DRIVEN BY MEASUREMENT. This stamps MODULE-LEVEL type declarations. Coproduct VARIANTS in type position and TYPE PARAMETERS are reachable from this walk and are NOT stamped, so references to them stay Unbound and the census names them rather than passing over them in silence. The same run also shows MethodOccurrence at 382 references against 0 declarations -- an independent gap in the same collector, not addressed here. Stage0 mirror regenerated; the emitted drift is exactly v1_compiler_parse.rs. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01KLXA6u6f3UK8PR5VEJoUwm * Census bin: satisfy the clippy gate that is the only step compiling bin targets CI red on the merge-blocking `cargo clippy --all-targets -- -D warnings` step: six lints in the census binary added by the parent commit -- one very-complex-type on the three-vector return of `inputs_for_module`, and five `clone()` calls on `OccurrenceId` and `DeclarationExposureGrounding`, both of which are `Copy`. The return triple is now the named `ModuleInputRows`, because a bare tuple of three vectors says nothing about which list is which, and the five clones are dropped. Behaviour is unchanged: cloning a Copy type and copying it are the same value. WHY IT REACHED CI AT ALL, recorded because the tree already warns about exactly this and I walked into it anyway. I verified the new binary with `cargo build`, and DESIGN's Building & checks section states that `cargo clippy --all-targets -- -D warnings` is "the only command that compiles the integration-test and example targets, so a red there is invisible to every other step". A new `[[bin]]` target sits in precisely that blind spot: every check I ran was green and none of them compiled the file under the gate's lint set. The lesson is not "run clippy too" -- it is that a named gate command is the thing to run, and a proxy for it establishes nothing about the gate. Verified by running the gate command itself rather than a proxy: CLIPPY_STATUS=0. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01KLXA6u6f3UK8PR5VEJoUwm * Stamp type declarations at the parser, and refuse the shapes the rule cannot decide v1.compiler.parse stamped type REFERENCES as TypeOccurrence and never stamped a type DECLARATION as one. Measured over dag/std (142 files) the production transport carried 9672 TypeOccurrence references and ZERO TypeOccurrence declarations, so every type reference in the corpus was UNBINDABLE -- not mis-bound -- because occurrence_binding_resolve admits a TypeOccurrence reference against a TypeOccurrence declaration only. Every existing fixture stayed green through that because each hand-builds its declarations with `category: TypeOccurrence` -- the shape production never emitted -- so the suite supplied the missing side of the join itself. Those fixtures are correct about the authority's logic and nothing here weakens them; they were never SUFFICIENT, and nothing in the tree said so. THE PARSE TREE CARRIES NO POSITIVE TYPE-DECLARATION MARKER. The parser dispatches on the `type`/`fn`/`data`/`service` keyword and then discards which one it saw: Node has no item-kind field, so the kind survives only as which optional fields happen to be absent. A bare predicate over three absent fields fails open by construction at the parser, so the rule is written as an exhaustive ParsedModuleItemKind match whose ModuleItemUnrecognized arm REFUSES with a located diagnostic rather than defaulting into the type bucket (DESIGN section 5: a failure arm refuses, never widens). The terminal fix is a construction, named in the annotation: parse constructors carry the kind they already know, at which point the emit-side shape predicates dissolve into it. Enrolled with a PRODUCTION-FED control -- not another hand-built transport -- whose third conjunct is the state that was red before this change: a subject with type references and an empty declaration side. It executes on no required run (the required floor's source roots are dag and src/v2, and this subject is only reachable through v1.compiler.parse); rung mitigatable, next-rung trigger stated in the file. Scope, so the next increment is driven by measurement: MODULE-LEVEL type declarations only. Coproduct variants and type parameters in type position stay unstamped, and MethodOccurrence stands at 382 references against 0 declarations -- an independent gap in the same collector. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01KLXA6u6f3UK8PR5VEJoUwm * Gate the census behind an established declaration population, and stop stamping resources as types THE CENSUS NOW HAS AN OUTER STATE, and building it found a live fail-open in the change that introduced it. TypeOccurrenceBindingCensusOutcome = CensusUnavailable { cause: ProductionTypeDeclarationPopulationUnestablished } | CensusReady { joined_declarations }. The thirteen classes are constructible inside CensusReady and nowhere else. Before the stamping landed, Y never RECEIVED a declaration population, and reporting that as OldBinds_NewUnresolved turns PRODUCER ABSENT into a SEMANTIC RESOLUTION ANSWER -- a partition that closes over an absent input closes over nothing. CensusReady is constructible only after an exact-set join at OCCURRENCE-ID grain, with uniqueness on both sides and no extra members. Not count equality, which a compensating pair of errors satisfies. The join is against an INDEPENDENT reader: v1.compiler.emit_core_support decides "is this item a type declaration" from CONNECTIVE, PARAMS and CHILDREN, while the stamper decides it from the ABSENCE of body, transport and type annotation. Different facts about the same item, so agreement is evidence rather than measure() == measure(). New parse-only mode `--establish` answers the obligation over the whole corpus at parse cost. WHAT IT FOUND ON ITS FIRST RUN. Over dag + src/v2 + src/v1, exactly one diverging module and three items: Filesystem, Clock and Entropy in std.resources. A `resource` carries no body, no transport and no type annotation, so the three-negatives rule stamped all three as TYPE DECLARATIONS, silently, at the parser. The refusal arm could not fire: a resource is not merely unrecognised, it is INDISTINGUISHABLE from a type under that rule. The parser's own item error names TEN keywords -- alias, type, fn, func, service, resource, data, extern, pattern, interface -- so the four-kind premise was wrong and its falsifier was in the same file. Fixed with a ModuleItemResource arm keyed on the properties the resource grammar attaches; the corpus-wide join now reports CensusReady. Recorded in the annotation as a class and not a specimen: a discriminator built from ABSENCE is only as complete as the enumeration of kinds it was derived from, and it fails silently toward the DEFAULT BUCKET rather than toward the refusal arm, so the refusal reads as coverage and is not. TWO INSTRUMENT DEFECTS CAUGHT BEFORE BEING REPORTED AS PRODUCTION ONES, both named in the annotation. The join first read the post-typecheck item list, whose rebuilt copies carry OccurrenceSynthetic (1077 phantom "no minted occurrence" rows); and it compared per-file parse ids against the whole-program index, two different id spaces (40 phantom absences). EXPOSURE DISCRIMINATION, PRODUCTION-FED. New control: one parsed source, the same occurrences and the same resolver; under ModuleLocalMemberExposure a module-root declaration is ModuleExposure and a consumer-module reference is UNBOUND, under CrossFileProviderExportedExposure it is RootExposure and the same reference BINDS. Three identical grounding columns are the signature of an absent input, and this is what makes that signature impossible to mistake for agreement. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01KLXA6u6f3UK8PR5VEJoUwm * Three census states, the ruled recognition rule, and the seed mirrors regenerated on the merge CENSUS OUTER STATE IS NOW THREE, because two conflated two different facts. "The join agrees on today's tree" and "the classifier is a durable authority" are not the same claim, so: CensusUnavailable { DeclarationDomainAbsent | DeclarationDomainDisagrees } CensusObservedOnCurrentTree { joined_declarations } CensusAdmissibleForCut { parser_carried_item_kind, joined_declarations } DeclarationDomainDisagrees CARRIES the missing and extra sets, so a resource silently stamped as a type reads as a typed, located cause rather than a generic unavailability. CensusObservedOnCurrentTree is enough to scope work and discover disagreements. CensusAdmissibleForCut is UNCONSTRUCTIBLE on this tree and is modeled anyway: the alternative -- leaving the distinction unmodeled -- is exactly what would let "the join agrees" be read as "the cut is authorized". Its arm refuses rather than falling through, so nothing quietly starts answering for it. THE RECOGNITION RULE, carried into the annotation in the words it was ruled in: A RESIDUAL REFUSAL DOES NOT PROTECT A CLASSIFIER WHOSE ACCEPTED BUCKET IS DEFINED BY ABSENCE; A NEW KIND CAN SILENTLY RESEMBLE THE DEFAULT. ModuleItemResource repairs the KNOWN collision and does not turn absence into a positive authority, which is why the parser-carried item kind is required before anything is cut over on this classifier rather than being an improvement to schedule later. SEED MIRRORS REGENERATED ON THE MERGE, not hand-merged. Resolving the generated conflicts to "ours" dropped main's authority-derived bytes and produced a stage0 crate whose root referenced modules that no longer existed there -- the four build errors CI reported. The mirrors here are emitted from the merged authority. Two rounds, as separate invocations with source roots on each: required-regen first_generation_equal=true (155/155/155, main.rs declared divergent) then required-regen-fixed-point fixed_point_equal=true. One round can report success while the old content still stands. AN OPEN INCOMPLETENESS, REPORTED RATHER THAN SWEPT, and the gate is what surfaced it: over the merged corpus the join no longer closes. 202 grammar-owned type declarations across 100 modules -- ArgvCommand, NozzleDiameter, BuildEnvelope and others, all genuine type names in files main introduced -- are read as type declarations by the emit-side reader and are NOT stamped. The census therefore reports CensusUnavailable { DeclarationDomainDisagrees } and refuses to print a partition, which is the behaviour it was built for. Which reader is right for these shapes is NOT yet determined and is not guessed at here. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01KLXA6u6f3UK8PR5VEJoUwm * Stop classifying sole-constructor types as resources, and file the class both polarities came from THE RESOURCE ARM I ADDED TO FIX THE FIRST FAIL-OPEN CREATED THE SECOND ONE. It keyed on `properties` being non-empty, and `type X sole_constructor { .. }` carries a property too -- so 202 sole-constructor type declarations across 100 modules classified as RESOURCES and vanished from the declaration population. Over-stamping resources as types, then under-stamping types as resources: same classifier, opposite polarity, one root -- an absence-and-presence heuristic standing where a positive kind belongs. THE EXCLUSION IS COMPLETE BY ENUMERATION OF MINTING SITES, not by grep. Module items have exactly two property sources in v1.compiler.parse: parsed_sole_constructor_properties, which mints one field-init named sole_constructor and is the only source every type-item constructor passes along (four call sites); and parse_resource_entries. `nominal_opaque`, the other authored type modifier, is dropped lexically by drop_leading_type_modifier and mints nothing. mint_parsed_optional_int_property is confined to nested where-predicate nodes and never reaches a module item's own properties. So the modifier set mintable as a property on a type declaration is a CLOSED SET OF ONE. A one-member set established by construction is worth more than a longer list found by search -- and the annotation states what breaks it: a second modifier that MINTS a property reintroduces this silently and in the same direction, which no longer list can prevent. MEASURED, corpus-wide over dag + src/v2 + src/v1 with `type_occurrence_binding_census --establish`: modules_diverging 100 -> 1, absent declarations 202 -> 2, zero extras, zero duplicates, zero index absences, zero parse failures. Both remaining absences are in the one diverging module. THE RESIDUE IS NOT THIS CLASSIFIER'S DEFECT AND IS FILED RATHER THAN REPAIRED. `resource Network` and `resource AuthContext` declare no capabilities, so with no children, body, params or connective they satisfy v1.compiler.emit_core_support is_bare_leaf_item and the INDEPENDENT reader calls them type declarations. That is the same class in a different authority; repairing it there is a separate subject and is not smuggled into a parser change. AND THE COUNTERMEASURE, which is the transferable part. Those two were invisible while one classifier answered, because both readers AGREED they were types -- the agreed-wrong pair a disagreement census cannot see by construction. Splitting the question across two INDEPENDENTLY DERIVED readers converted their agreement into a disagreement, which is the only form the census can report. Filed as gunbc.recurring_failure_mode absence_classifier_default_bucket with both polarities, both specimens, and the rule: WHERE A CENSUS COMPARES TWO READERS, A THIRD INDEPENDENTLY-DERIVED READER IS THE ONLY THING THAT CAN FALSIFY THEIR AGREEMENT. Receipts: required-regen first_generation_equal=true 155/155/155 (main.rs declared divergent); generated_artifact_gate main_wet for the ledger projection; clippy --all-targets -D warnings clean; fmt clean. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01KLXA6u6f3UK8PR5VEJoUwm --------- Co-authored-by: Brian Searls <briansearls1@gmail.com> Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
… -> 28 errors A field authored v2.std.text.String reached the Rust emitter as an overlay-less resolved reference leaf and rendered the bare terminal name, which binds the prelude String cross-module (#9813: kernel names are never overridden by imports, so the use-line is dropped) while every value position renders the structural carrier Rc<Vec<i64>> -- the v2_compiler_tokenize.rs E0308 family, 41 of 72 errors on the XL-N phase board. The new rust_overlayless_alias_leaf_requires_peel arm in render_rust_type_without_applied_binding detects the population (overlay-less zero-parameter alias leaf, qualified spelling, String terminal segment, closed_alias_peel_verdict agrees) and renders the alias declaration's resolved right-hand side, projecting the same realization the fn-signature positions already produce. The qualified gate is load-bearing: inside the declaring module the bare name is the correct render (the emitted module carries the alias declaration), and the local binding's resolved_type drops the RHS type argument, so an ungated peel rendered Rc<FreeMonoid> there (E0107 x13, E0282 x2 on the probe). Bare String keeps denoting the kernel scalar through the host-carrier arm. Measured: probe specimen (qualified/bare/direct-FreeMonoid/container/variant/ local-alias positions) compiles clean; XL-N compiler closure cargo check 72 -> 28 errors with the residual census dominated by the declared text_boundary_identity_wall class (kernel String vs structural carrier at bare-authored boundaries, 17 of 20 E0308s); v1-corpus fixed point holds (first_generation_equal=true, 158/158 adjudicated).
Inference substitutes the resolved declaration into a data annotation's type-argument position, so BooleanAlgebra<v2.std.logic.Bool> reaches the emitter with the arg BEING the type Bool = True | False declaration itself (Disj connective, ident_span in src/v2/std/logic.dag, no Resolved wrapper). type_reference_provenance_in_env's bare-leaf arm re-resolved that leaf in the REFERENCING module's scope, where post-#9813 a kernel-shadowed spelling answers the kernel declaration -- so the structural enum rendered as host bool against a value of BooleanAlgebra<Bool> (the python.rs:328 / typescript.rs:177 E0308 pair on the XL-N compile-phase frontier). The connective is the discriminator: a reference node is a bare name (NoConnective); a node carrying Conj/Disj structure IS the declaration, and type_reference_provenance's own-span fallback already answers that shape correctly. The guard routes declaration-shaped nodes there directly, bypassing the scope lookup that #9813 makes answer the kernel. Mirror regenerated via the regen round; fixed-point verified (claim_executor --required-regen PASS).
…0692) * Land the add-slice per-stage verdict instrument named as the floor_expected_red note's producer The add-slice roster note in v2.workflow.floor_expected_red carried a dated receipt (main 3a8344b5c: infer accepts dag_add_emitted_root; the infer-then-translate composition refuses headed by infer_grounding_not_derived) and named its own next-rung trigger: a .dag entry returning the per-stage verdicts for one root, so the paragraph can name a producer instead of a commit. v2.compiler.self_host.candidate_generation_stage_verdicts is that entry, parameterized over root and target: the receipt's verdict vocabulary (infer_accepted / infer_rejected; candidate_accepted or the rejection head reason) plus the carried-reasons lists -- the half the verdict symbols cannot say, namely that infer accepts while carrying the frontier diagnostic on its accepted path, so the enrolled witness's d == None conjunct fails even where the composition reaches acceptance. v2.test.execution.self_host_candidate_generation_stage_verdicts binds the instrument to the slice's own fixture, with add_slice_stage_verdicts_entry the runnable gunbc run --function form (ExitSuccess only when infer accepts clean and the composition accepts clean). Two witnesses: infer-accepts as a permanent positive control, and the frontier-state pin that is expected to red the day the add-slice stall's trigger lands, flipping to a permanent regression control in the same change that removes the roster row (DESIGN 4b(4)). Measured by execution on this branch: the entry exits 1 printing infer=infer_accepted, infer_carried=[infer_grounding_not_derived x10], composition=infer_grounding_not_derived, composition_carried=[x11] -- the receipt reproduced, with bind_outcome's pending-plus-gate chain counted. Both witnesses PASS; the enrolled semantic witness still fails as enrolled. Co-authored-by: Brian Searls <briansrls@users.noreply.github.com> * Derive grounding for dag declared inhabitants: the add slice greens end-to-end infer gains the declared-inhabitant membership derivation: a node declared in the dag language authority's declared-inhabitants roster derives its grounding by lookup, with the roster as evidence -- the namespacing answer to the atom authority question, at specimen scope. The add slice's ten type-spine nodes (Arrow, Conj, Atom) are all roster members, so: - candidate_generation_translate_self_emit_dag_add_slice_holds passes; its floor_expected_red roster row and per-row note delete per the roster's own stale-quarantine arm - the dag same-language ingest path compiles end-to-end: cross_language_compile accepts, byte-equal to the authority's own serialization, no carried diagnostics - the add-slice stall narrows to its four python/typescript round-trip members; the original trigger's causal clause was refuted by execution and is restated against the grammar parse-product population - the instrument's frontier guard flips to add_slice_composition_accepts_holds (DESIGN 4b(4): frontier guard to permanent regression control) - five manual witnesses flip with it: two root flips rewritten to assert the green state, three transitive conjunctions updated The kinds stay frontier: non-member Arrow/Conj/Atom specimens carry GroundingNotDerived exactly as before, and all fourteen enrolled refusal/acceptance controls pass unchanged. The door's production path still reds inside rust emission, untouched by this rule. Co-authored-by: Brian Searls <briansrls@users.noreply.github.com> * Derive grounding for canonical binding atoms: dag_binding_denotation joins binding to inhabitant once The resolver already binds the surface spelling Int to the canonical binding symbol dag_binding_type_int; what that binding DENOTES is the Int inhabitant declared at dag_declared_inhabitants_core. Every hand-rolled fixture facts lookup re-authored that join (dag_add_canonical_grounding_for, record_construct_canonical_grounding_for). The language authority now declares it once as dag_binding_denotation, and infer_node_facts consumes it: an Atom whose identity is a canonical dag binding with a declared denotation derives with that denotation as its grounding evidence. Direct-rust-door specimen census: 14 underived -> 10 underived (the four dag_binding_type_int atoms derive; grammar-production atoms, algebra atoms, bare operand atoms, and the arrow/conj spine stay on the frontier unchanged). Specimen-scope interim in the same frame as infer_node_declared_in_dag_inhabitants: both delete in favor of consuming resolution output when the resolver hands infer declaration-resolved identities directly (the namespace migration's completed state). Witness: v2.test.execution.dag_binding_denotation — all four Int binding atoms in the door specimen derive with dag_int_inhabitant_node() as structural evidence, and the two bare operand atoms stay GroundingNotDerived (boundary control). Refusal suite 14/14, ingest bridge 7/7, add-slice instruments 2/2 green; every remaining red in the at-risk population reproduces identically on the pre-change tree and is enrolled in floor_expected_red. Co-authored-by: Brian Searls <briansrls@users.noreply.github.com> * Add v2 self-host direct-path orientation: axes, sequence, autonomy contract A point-in-time orientation that defers to the existing authorities (DESIGN section 7, the four-wave self-host program, the roadmap node chain, the three frontier carriers, the guarantee-stall roster, XL-N) rather than restating them: state is re-derived by the named instruments, never transcribed here. Sequences the remaining work in roadmap order (door, parse-product grounding, first behavioral module, XL-N milestones, native bootstrap, fixed point, v1 deletion) and states which decisions stay operator-gated. Co-authored-by: Brian Searls <briansrls@users.noreply.github.com> * Derive grounding for fully-evidenced Conj and Arrow products The sixth and seventh kind rules: a non-roster Conj or Arrow whose every child carries DerivedGrounding derives, its evidence the same shape re-formed over the children's grounding evidence (a fresh OccurrenceSynthetic node, never the source — the self-evidence wall holds by construction). A product with any frontier or absent child stays on the frontier with its typed diagnostic; a childless product has no evidence to compose and stays frontier. Roster members keep their roster evidence. Measured on the direct-rust-door specimen (scratch probe, uncommitted): 10 underived of 15 -> 6. The parameter conj, the module-structure conjs, and the bodied add arrow derive; what remains is the algebra atoms from the + operation (AlgebraPrimitive, ring_field_add), the module atom (dag_surface_module), the parameter references (x, y), and the grammar-projection root conj that cascades once they land. Enrolled witnesses (src/v2/test/claim/execution/infer_product_introduction_test.dag): - product_introduction_derives_fully_evidenced_products_holds — census: 4 Conj (3 derived, 1 frontier-by-frontier-child) + 1 Arrow (derived). - product_introduction_composed_evidence_carries_child_groundings_holds — the params conj's evidence is a Conj whose x/y children target the dag authority's Int inhabitant. - product_introduction_leaves_childless_conj_on_the_frontier_holds — boundary control via direct infer over a hand-built childless Conj. Flip census (pre- and post-change, zero unexpected flips): translate_underived_refusal 14/14, infer_self_grounding_wall 12/12, branch_infer_if_then_else 2/2, compile_eval_thesis_proof 6/6, ingest_bridge 9/9, cross_language_add_python_to_typescript 4/4, inhabitant_neutralization 6/6 + e2e 6/6, emit_host_classical_not 14/14, dag_binding_denotation 2/2, stage-verdicts instrument 2/2, dag_add_emit_round_trip 4/6 (the 2 enrolled reds unchanged), door production group still enrolled-red (unchanged). Co-authored-by: Brian Searls <briansrls@users.noreply.github.com> * Ground canonical-operation and grammar-production atoms by authority roster membership Two more specimen-scope derivations in infer_node_facts, both lookups into declared authorities, never inventions: - Canonical-operations roster (target_model.dag): every CanonicalOperation the target-model authority declares, rendered by target_model_canonical_operation_wire_node and gathered under one Conj root. The resolver canonicalizes surface operators (e.g. +) to those declared operations, so the wire atoms -- the operation discriminant and its field references -- derive by membership with the roster root as evidence. General over all 14 declared operations, not add-narrow. - Grammar-productions roster (dag.dag): every production in dag_grammar_root() projected to its emitted surface atom under one Conj root keyed by production name. The bridge projects a production's parse into (identity atom, captured content) pairs, so the identity atom (dag_surface_module) derives by membership with the roster root as evidence. The roster derives from the grammar root, so a production added to the grammar joins by construction. Both roster roots are Conj nodes, never structurally equal to any member atom, so the self-evidence wall holds by construction (the first attempt at the operations rule used the wire node itself as evidence and was refused by grounding_evidence_is_source -- the wall doing its work). Measured on the direct-rust-door specimen (scratch probe, uncommitted): 6 underived of 15 -> 2 (only the operand atoms x and y remain; the grammar-projection root conj cascades once the module atom grounds). Enrolled witnesses (infer_atom_grounding_rules_test.dag): each roster rule pins derivation + evidence identity + census; a boundary control pins that a bare atom with no authority membership stays frontier; the closing control pins the 2-of-15 state. Flip census: the product-introduction census witness updates 3->4 derived conjs (the top conj now cascades) and gains a hand-built partially-evidenced boundary control to replace the in-specimen one the cascade consumed. Full battery otherwise unchanged: refusal suite 14/14, grounding wall 12/12, instrument 2/2, binding-denotation 2/2, round-trips, bridge, cross-language, neutralization, emit-host all green; enrolled reds unchanged. Co-authored-by: Brian Searls <briansrls@users.noreply.github.com> * Ground binding-reference atoms from the enclosing arrow's domain declaration The fifth specimen-scope derivation, closing the direct-rust-door specimen's inference frontier: an Atom whose binding an enclosing arrow's domain declares derives with the declared domain type as its evidence -- the declaration-site annotation, itself derived (x: Int grounds the x reference). This is the same lookup the branch-operand path already performs (infer_find_arrow_domain_type_in_tree), now written to the operand atom's own facts; it is scope-naive (whole-tree, first match), recorded in the frontier note, and deletes with the other specimen-scope rules when the resolver hands infer declaration-resolved identities. The tree is threaded through the fold's init chain to reach infer_node_facts; the helper had exactly one caller. Measured on the door specimen (scratch probe, uncommitted): 2 underived of 15 -> 0. The specimen's inference frontier is fully closed, and the production observation advances from InferenceRejected (infer_grounding_not_derived) to EmissionRejected (target_use_site_ownership_lookup_miss) -- a new, typed, located deficit in the emitter, the next gate on the path. Flip census (all three rewrites verified by execution): - dag_binding_denotation_leaves_unbound_operand_atoms_on_the_frontier_holds -> dag_binding_denotation_declares_no_denotation_for_operand_bindings_holds: the boundary moves to the authority itself (the denotation table returns Absent for x/y), true regardless of infer's other rules. - The three emit_host classical-not refusal guards (canonical, staging, staging-swapped) flip to acceptance witnesses pinning the emitted text's shape -- the real-infer tree now fully derives, and the emission is the same one the equals-eval witness proves behaviorally correct. The translate-refuses-underived behavior stays enrolled on hand-staged fixtures in translate_underived_refusal_test.dag (14/14 green). The renames are carried into the commit_workflow and witness_deferral_freeze rosters. - New witnesses: binding_reference_derives_parameter_atoms_holds (evidence is the domain's Int binding atom, census 2) and door_specimen_fully_derives_holds (0 frontier of 15). Full battery at this state: refusal suite 14/14, grounding wall 12/12, instrument 2/2, binding-denotation 2/2, product-introduction 4/4, atom-rules 5/5, emit_host 14/14, round-trips 4/6 (2 enrolled reds unchanged), bridge 9/9, cross-language 4/4, neutralization 6/6 + e2e 6/6, branch 2/2, eval-thesis 6/6; door production group still enrolled-red (unchanged). Co-authored-by: Brian Searls <briansrls@users.noreply.github.com> * Green the direct-rust-door: route emission through produced-decl composition and decode canonical operator wires The door specimen's inference frontier is fully closed, so its production observation now reaches the emission stage. Two defects surfaced there, both fixed here: Emission composition. generate_rust_emission_candidate served two lanes with one root shape: the door's production path (a dag module shell) and a fixture lane (a bare rust Arrow). The translate ownership gate queried the module atom's ownership at a struct-field use site and refused with target_use_site_ownership_lookup_miss, because the module's grammar-projection conj was misread as a type record. The door's real composition is the produced-decl path: collect declaration conjuncts from the inferred tree and emit via emit_produced_decl. A new generate_rust_module_emission_candidate does exactly that, enforcing an exactly-one-declaration admission policy (rust_module_emission_decl_absent / _ambiguous). The observation and production mint paths switch to it; the fixture-lane candidate is retained with a note that it is fixture-only. A pure collector, produced_decl_conjs_in_tree, finds nodes of produced-decl shape (a Conj whose first child is a Named edge to an Arrow). Its decl-head match routes through a declared FreeMonoid<Edge> parameter because the v1 seed stamps pattern variables from a declared parameter type, not from a field-access scrutinee. Operator decode. With composition fixed, source fidelity still refused: the door emitted fn add(x: i32, y: i32) -> i32 { AlgebraPrimitive(x, y) } instead of { x + y }. Resolution canonicalizes a surface operator atom into a canonical-operation wire node, so a production tree's transform operator position carries the wire, while fixture trees that bypass resolution still carry the surface token atom. translate_project_transform_in_arrow_scope only knew the surface-token table, so the wire missed and fell to callable apply, rendering the discriminant identity. The projection now tries the wire decode first (canonical_operation_from_wire_node) and only on a wire miss falls to the surface-token table, then to callable apply; the arms are disjoint, so the dispatch adds no fallback widening. target_transform_operator_child extracts the operator child safely. The door's closing expectation now greens by execution, so its known_red_probe row in explicit_witness_admission is deleted per its own dissolution condition, and the roadmap authority note, the door contract note, and the direct-path plan are updated to record the green state. realized_closure_for_v2_direct_ rust_door_emit_run's module list reflects the produced-decl route. Verified by execution: the door witness greens; the fixture, containment, algebra, produced-decl, add-slice, and classical-not witnesses stay green; claim_executor required-ci lanes build and witnesses both exit 0; cargo fmt and clippy --all-targets -D warnings are clean. One pre-existing red, witness_projection_is_active_only in the floor_cost_debt containment roster, reproduces on the base revision and is unrelated to this change. Co-authored-by: Brian Searls <briansrls@users.noreply.github.com> * Close the parse-product grounding frontier: widen declared-inhabitant membership to the closed ingest set The declared-inhabitant roster-membership derivation in 04_infer generalized from the dag roster to the closed ingest set (dag, python, typescript): infer_node_declared_in_language_inhabitants returns the declaring authority's roster root as evidence, with deep subtree membership so a declared inhabitant's leaf fact atoms derive exactly as the inhabitant node itself. Measured: the python fixture's 19-node frontier and the typescript fixture's 28-node frontier both close to zero; all four add-slice stall population round-trip witnesses green; the python->typescript cross-language compile accepts, byte-identical to ts_source_text. Section 4b(4) flips (expecting-red probes becoming permanent regression controls for the acceptances): - cross_language_compile_refuses_canonical_underived_holds -> cross_language_compile_python_to_typescript_round_trip_holds - inhabitant_neutralization_emit_after_neutralize / same_flavor_python / go_int64_to_ts refusal helpers -> round-trip controls - inhabitant_neutralization_python_to_ts_cross_language_compile (e2e) -> round-trip control; python->go members stay refusal guards (go is outside the closed ingest set) - cross_language_emit_inhabitant_neutralization_refuses_underived_holds -> round-trip control; the python->typescript emit-matrix row reads ChainProven The add-slice stall's next-rung trigger fired, so it retired per DESIGN 4b(4): removed from all_guarantee_stalls, row file deleted, witnesses stay enrolled. Co-authored-by: Brian Searls <briansrls@users.noreply.github.com> * Promote the add family to SelfEmittedNative: native-only verdict witness for the emitted add crate First InterpreterRetained -> SelfEmittedNative promotion after classical_not, executing the v2-emitter-first-behavioral-module first slice at the coverage-frontier grain: the add family (fewest dependencies — integer literals plus one canonical operation) now carries a native-only verdict witness, so its behavior is established by the emitted crate's own stdout with eval() unreachable from the verdict path. - emit_host_native_only_add_holds: real emit -> cargo build -> native run, stdout pinned to the family's expected octet, sharing the kernel family's one-build cache key exactly as the classical_not arm shares its family's key (no duplicated cold build). - emit_host_native_only_add_wrong_octet_mismatch_detected_holds: the broken control — a no-eval verdict has no oracle leg to break, so the expectation side breaks (an octet the run never produces must not match); program-side discrimination stays with the family's equals_eval primitive-five/six pair. - The add coverage row flips disposition with its backing citation enrolled by construction (the verdict entry is file-grain enrolled in falsifier_self_host_wet_template_entries). - Frontier census tests updated at identity grain: natives are exactly {classical_not, add}; split 2/13. Verified by execution: all six native-only verdict tests green locally (real wet legs — compile_skipped receipts show cold builds and native runs); all eight emit_coverage_frontier tests green, including the unbacked-claim RED control. Co-authored-by: Brian Searls <briansrls@users.noreply.github.com> * Record the add-slice defect's repair in the declined-live-tree classification The row classified candidate_generation_translate_self_emit_dag_add_slice_holds as RealDefect/CompilerBehaviourRefusal with measured evidence that translate refuses infer_grounding_not_derived. The owner lane (v2 self-host) repaired the subject: the declared-inhabitant roster-membership derivation grounds the slice's type spine by lookup, and the witness passes under claim_batch --hermetic on the merged tree. The dated classification is kept verbatim; the disposition flips RoutedToOwner -> RepairedInThisChange with the repair measurement appended to the evidence, so the routing carrier stops dispatching a fixed defect. Structural witnesses (count 13, no NotReproduced, exact partition) are untouched and pass. * Hoist two in-body annotation blocks to module-item grain Main's annotation-placement wall (source annotations admit only standalone leading blocks attached to module-scope declarations; in-body forms refuse) reached this branch through the merge and refused 8 blocking errors on the 00_compile closure: the add-family promotion note inside the emit_coverage_frontier_roster list and the python->typescript row note inside the cross_language_emit_matrix list. Both blocks move above their enclosing declarations, rephrased to name their subject row. Measured: gunbc compile of src/v2/compiler/00_compile.dag now emits 172 files with 0 blocking errors; both files' suites stay green (8/8 and 4/4). * Promote the complement family to SelfEmittedNative: native-only verdict witness for the emitted logic family crate The complement family's native execution runs family-grain per the witness_family_build_grain_ruling (one crate for meet + join + complement, argv-dispatched), so the native-only arm emits the logic family crate and runs the complement member through the family dispatcher, sharing the family witness's one-build cache key. The verdict is decided solely by the emitted native run's stdout (expected octet 0, complement(True) = False); the broken control flips the expectation side (octet 1 can never match), with the comparator pinned by the stdout mock pair. Program-side discrimination stays with the equals_eval agreement pair and the family witness's all-alt leg. The frontier row's backing citation lands in the already file-grain-enrolled native-only verdict entry, so it is enrolled by construction; the roster comment is rephrased to cover both 2026-09-07 promotions (add and complement). The frontier test's split and native membership assertions move to 3 native / 12 retained. Verified by execution: claim_batch --hermetic on emit_host_native_only_verdict_test.dag passes all 8 witnesses (the two new complement arms included), and emit_coverage_frontier_test.dag passes all 8. * Key the emitter's host-String arm on declaration provenance, not spelling is_host_text_carrier_type answered true for any type expression whose authored name reads "String", including references to the structural alias v2.std.text.String (type String = FreeMonoid<Char>) that the namespace lane (gunbc#9907) requalified the v2 corpus's text-carrier fields to. The emitter rendered every one of those references as the host String while value-position consumers rendered the structure -- the E0308 family dominating the self-host compile-phase frontier (41 of 64 in v2_compiler_tokenize.rs on the post-merge board). The String arm now consults the resolved declaration's provenance against v1.compiler.coercion structural_declaration_modules_for -- the same roster type_realization_decision reads -- so the legacy arm and the strict decision cannot diverge on one node (DESIGN section 3, and gunbc.recurring_failure_mode alias_resolution_collides_with_kernel_spelling). Kernel mints and unresolved references keep the host answer exactly as before. Regen: the only drifted stage0 mirror is v1_compiler_emit_rust.rs itself (no module in the stage0 closure references a structurally declared String -- verified by the whole-population candidate tree), installed from target/stage0-regen-candidate after the priced round's partitioned rebuild refused MirrorHasNoOwningPackage on the emitter (the emitter is monolith-shell, not partition-owned). Fixed point verified by execution: claim_executor --required-regen on the rebuilt seed reports first_generation_equal=true over 158 adjudicated mirrors. * Peel qualified String alias leaves in field position: XL-N closure 72 -> 28 errors A field authored v2.std.text.String reached the Rust emitter as an overlay-less resolved reference leaf and rendered the bare terminal name, which binds the prelude String cross-module (#9813: kernel names are never overridden by imports, so the use-line is dropped) while every value position renders the structural carrier Rc<Vec<i64>> -- the v2_compiler_tokenize.rs E0308 family, 41 of 72 errors on the XL-N phase board. The new rust_overlayless_alias_leaf_requires_peel arm in render_rust_type_without_applied_binding detects the population (overlay-less zero-parameter alias leaf, qualified spelling, String terminal segment, closed_alias_peel_verdict agrees) and renders the alias declaration's resolved right-hand side, projecting the same realization the fn-signature positions already produce. The qualified gate is load-bearing: inside the declaring module the bare name is the correct render (the emitted module carries the alias declaration), and the local binding's resolved_type drops the RHS type argument, so an ungated peel rendered Rc<FreeMonoid> there (E0107 x13, E0282 x2 on the probe). Bare String keeps denoting the kernel scalar through the host-carrier arm. Measured: probe specimen (qualified/bare/direct-FreeMonoid/container/variant/ local-alias positions) compiles clean; XL-N compiler closure cargo check 72 -> 28 errors with the residual census dominated by the declared text_boundary_identity_wall class (kernel String vs structural carrier at bare-authored boundaries, 17 of 20 E0308s); v1-corpus fixed point holds (first_generation_equal=true, 158/158 adjudicated). * Resolve the 12 non-hop XL-N closure errors at source: text-wall conversions + witness_violates helper Four clusters, all measured non-hop additions between receipt_1 (155) and the post-peel census (28); the live gate now measures 15 with zero unadmitted regressions: - integer.dag: integer_string_to_decimal_digits_step takes v2.std.text.String; the public boundary converts with chars() (text_boundary_identity_wall specimen discharged at this site). - 01_tokenize.dag: Token/UnboundSourceAnnotation lexemes convert structural -> host String with chars_to_string() at construction, mirroring the v1 tokenizer's host-lexeme carrier. - target_model.dag + bash.dag: EmitSpellingEscape.from/to and apply_emit_spelling_escapes go structural (v2.std.text.String); the EmitSpellingQuote arm converts host->structural->host at its boundary; bash's escape rows wrap their kernel String literals with chars(). - witness.dag + 3 call sites (collection list_nth, provenance span_index_resolve_textual_locus_from_ids, compile outcome_with_diagnostics): new witness_violates<C> helper puts Violates constructions in a Witness-headed position so the emitter resolves the carrier type argument; dissolves once inference records per-call substitutions. Verified: 48 targeted claim witnesses green (tokenize behavioral, shell conformance, string brace escape, string length, map-lookup violates, source text ingress, bash materialize x12, int literal smoke x6, provenance span index x2). * Record receipt_2 on the self-host compile-phase frontier: 15-error census at 66765317ec The census at the XL-N lane tip: 155 -> 15 net, credited to the qualified-alias peel (60cbd7b697, 72 -> 28) and the twelve-error source cluster (66765317ec, 28 -> 15). The epoch changes on the instrument's target pinning (found by review on gunbc#9857), admitted with receipt_1's board as the reclassified predecessor under the identity map. Nine added identities are hop relocations admitted by the hop index; four sit in python/typescript modules newly entered into the emitted closure, admitted as ExposedByNewEmittedModule. Validated: all 36 self_host_compile_phase_frontier_witness claims PASS, including current_persisted_compile_phase_frontier_holds. * Emitter: a substituted declaration node carries its own provenance Inference substitutes the resolved declaration into a data annotation's type-argument position, so BooleanAlgebra<v2.std.logic.Bool> reaches the emitter with the arg BEING the type Bool = True | False declaration itself (Disj connective, ident_span in src/v2/std/logic.dag, no Resolved wrapper). type_reference_provenance_in_env's bare-leaf arm re-resolved that leaf in the REFERENCING module's scope, where post-#9813 a kernel-shadowed spelling answers the kernel declaration -- so the structural enum rendered as host bool against a value of BooleanAlgebra<Bool> (the python.rs:328 / typescript.rs:177 E0308 pair on the XL-N compile-phase frontier). The connective is the discriminator: a reference node is a bare name (NoConnective); a node carrying Conj/Disj structure IS the declaration, and type_reference_provenance's own-span fallback already answers that shape correctly. The guard routes declaration-shaped nodes there directly, bypassing the scope lookup that #9813 makes answer the kernel. Mirror regenerated via the regen round; fixed-point verified (claim_executor --required-regen PASS). * Clear the remaining XL-N closure errors at source: carrier conversions at the boundaries The receipt_2 census's fifteen identities, resolved at their sources: - lexing.dag, dag.dag, python.dag, typescript.dag: LexPattern.text is the structural carrier (v2.std.text.String); the construction sites held host Strings. Convert at construction with chars() -- the #9907 ingress pattern. - python.dag / typescript.dag bool groundings: qualify the annotation as BooleanAlgebra<v2.std.logic.Bool>; with the emitter's substituted- declaration provenance guard the qualified arg now renders structural. - target_model.dag: target_lex_rule_literal_step returns the host carrier (chars_to_string over the structural pattern text); TargetText.source converts at the is_empty boundary; the unicode-scalar symbol intern converts its single-codepoint list to the host carrier. - qualified_name.dag: qualified_name_from_dotted_string uses the host-carrier emptiness check (string_length == 0) instead of routing through the structural string_is_empty. - 02_parse.dag: parse_looks_like_match_arm_start rewritten on host-carrier operations (string_length, char_at, code_point) rather than converting to the structural carrier for a two-character lookahead; parse_char_is_arm_pattern_lead takes the codepoint Int directly. - v1_interpreter_primitive_surface.dag row_key: the concat pipeline lowered to a .concat() method call on std::string::String (E0599); rewritten as nested concat calls. Measured: the 00_compile closure emits 172 files and cargo check reports cargo_clean=true, cargo_error_population=0 under the pinned 1.93.0 toolchain. * Pin the cargo half's toolchain channel by construction The cargo half runs with cwd = a fresh mktemp directory; with no rust-toolchain.toml there, rustup resolves the host's DEFAULT toolchain, so a census under cargo 1.83 and one under cargo 1.93 would compare as equal epochs while different compilers did the measuring -- the fabricated comparability the target pin (gunbc#9857) excludes, one level up. Measured 2026-09-07: a host default of 1.83.0 met a crates.io index whose freshly published dependency manifests require edition2024, resolution failed before any diagnostic existed, and the zero-diagnostic refusal fired on an unmeasured tree. The pin is propagated by copying the repo's rust-toolchain.toml into out_dir: the file remains the sole in-repo channel authority (its header forbids a second pinned literal), and the copy makes the measured channel true by construction on any host. The gate's read_live_toolchain observes the same channel because every documented actuator invokes from the repository root, which the same file governs. * Record receipt_3 on the self-host compile-phase frontier: the emitted closure's cargo census is empty Measured at 5ee4892b70 by the one-entry instrument: the 172-file emitted crate reports zero cargo error diagnostics, so the board attributes every phase a count of zero and furthest_phase_reached stands at Borrowck. The fifteen removals against receipt_2 need no disposition; nothing was added. The epoch does not change: the cargo half now pins the toolchain channel by copying the repo's rust-toolchain.toml into the scratch crate, and every recorded comparison field is identical to receipt_2 (whose census the fingerprint evidence shows the same 1.93.0 toolchain already compiled), so the same-epoch arm carries no reclassified predecessor. The frontier-state pin flips per DESIGN 4b(4): the_published_frontier_standing_does_not_claim_typeck_or_borrowck_passed becomes the_published_frontier_standing_claims_typeck_and_borrowck_passed, the permanent regression control over the green state. Validated: all 36 self_host_compile_phase_frontier_witness claims PASS, including current_persisted_compile_phase_frontier_holds. * chore: regenerate drifted generated artifacts (ci auto-heal) Ledger-Repair-Judged: docs/design-failure-modes.md Ledger-Repair-Judged: docs/design-rung-drops.md * Remove the stale PointwisePower inhabitant rows from the four language rosters First native-parity divergence class found by running the emitted closure on a discriminating fixture: the algebra inhabitant rosters still carried PointwisePower after its authority row was cut, so the emitted compiler panicked at 12 record-shaped carrier sites while the interpreted seed refused cleanly. The roster rows are removed in rust/python/go/typescript types.dag, the derived coercion assertions in compiler_tests.rs regenerate without them, and two witnesses pin the boundary: the record shape constructs its structural carrier, and FinitePowerSet still refuses while its row stands. Mirrors regenerated by a converged regen round (fixed point Reached, stage-1 PromoteGenerationInputs over the three language types mirrors). * Regen gen-2 gate: compare executable digests in one spelling The admitted side of run_built_seed_regen carries the executable-digest spelling (current_exe_digest, next_pass_executable_digest) while the observed side hashed the file through path_digest, which prepends the fnv1a64: tag. Same bytes, two spellings, so the gate could never pass -- unpassable since fa2d403dc8 (#9771). Factor current_exe_on_disk as the single path authority and read the observed digest through current_exe_digest so both sides spell the same bytes the same way. * Model ReleaseScopeEmpty for release-excluded mirrors, end to end A regen round whose only stage-2 drift was compiler_tests.rs (the PointwisePower roster removal rewrote its derived coercion assertions) refused the rebuild MirrorHasNoOwningPackage: the mirror is owned by no partition package, because every item it defines is #[cfg(test)] and no release unit elaborates it. The refusal conflated two different states -- unowned (a coverage hole) and excluded from the release build by construction (a precise empty scope). The model now names the class: rebuild_scope_release_excluded_mirrors rosters its members (compiler_tests.rs, cited to emit_compiler_tests_module), the decision answers ReleaseScopeEmpty when the whole change set is excluded, and the actuation shape is actuatable with an empty package closure and every partition package excluded -- the build still runs as verification, and a compiled partition package refuses the stage. The host admits the empty closure only when the new stage0_partition_rebuild_release_scope_empty_today query answers true; any other empty closure still refuses. A mixed change set scopes on its release-visible members alone. Verified by execution: the 2026-09-08 round converged (fixed point Reached) with stage-2 installing compiler_tests.rs alone; cargo recompiled the shell crate on its fingerprint (the outer mod line is ungated, so rustc reads the file) while the produced executable was byte-identical -- stage input seed digest == output seed digest. Four new witnesses pin the arm, its actuation shape, the mixed set, and the host-facing query's two arms; the boundary witness (unowned cli_run.rs still refuses) keeps the roster from decaying into the absorbing fallback. * Round-cost receipt: project installed mirrors to the model's vocabulary The receipt's partition-rebuild line is rendered by the model over receipt.installed_mirrors, which the host populated from the stages' projected_paths -- full paths -- while the partition rows and rosters key on basenames. Every drifted round's receipt therefore rendered a spurious RebuildScopeRefused MirrorHasNoOwningPackage line naming a full path, a false claim on the round's own receipt. Route the projection through emit_path_basename, the module's single path-to-basename bridge, so the field carries the mirror names the model's vocabulary means. * Hoist ReleaseScopeEmpty annotations to module-item grain The ReleaseScopeEmpty modeling commit placed three // blocks inside declaration bodies (stage0_partition_rebuild_is_actuatable, stage0_partition_rebuild_decision, stage0_partition_rebuild_excluded_today). The .dag realization admits annotations at module-item grain only, so the floor lane's parse phase refused the file with 12 located errors and the run ended floor refused. The prose is unchanged; each block now sits above the declaration it describes. * Spell the PointwisePower witness's finite-set exclusion as the applied realization The witness added with the fossil-row removal excluded the bare spelling "BTreeSet", but every emitted file's preamble imports OrdSet as BTreeSet, so the row could never green. The exclusion's subject is the finite-set REALIZATION the fossil row would have asserted; spell it applied (BTreeSet<i64), which the preamble's import line does not contain. * Emit fieldless-record data values as null for the unit-struct carrier The second native-parity divergence class, measured 2026-09-08 on the native run of the emitted 00_compile closure: emit_data_value_json spelled EVERY record literal as a JSON map, including the zero-field record, while emit_struct_from_children renders that same declaration as a Rust unit struct (pub struct BoolEncodingFact;). serde's derived unit-struct Deserialize reads null and rejects {}, so the emitted compiler panicked at first touch of v2.std.logic's bool_primitive_facts: "invalid type: map, expected unit struct BoolEncodingFact". The JSON spelling of a data value must deserialize into the Rust type the same declaration emitted; the record arm now spells the zero-field value null and keeps the map spelling for non-empty records. The mirror is taken from the required-regen candidate, not hand-edited. Two witnesses enroll: the discriminating red (zero-field record spells null, never {}) and the boundary control (a record with fields keeps the map spelling). * Bind the duplicate-definition filter ahead of its branch condition Main's FilterInBranchCondition wall (#10699) refuses to publish a module whose filter call sits in a branch condition, and the v2 00_compile closure emission names primitive_duplicate_semantic_definition_violation as such a site. The filter is pure and total; binding it with a let ahead of the branch is the authored remediation the wall exists to force, and the emitted closure is unchanged in behavior. * chore: regenerate drifted generated artifacts (ci auto-heal) Ledger-Repair-Judged: docs/design-rung-drops.md Ledger-Rows-Repaired: docs/design-rung-drops.md rust_unit_tests_off_the_merge_path Ledger-Rows-Repaired: docs/design-rung-drops.md determinism_transitive_reachability Ledger-Rows-Repaired: docs/design-rung-drops.md transitional_admission_exception * Emitter: three native-parity repairs for the post-merge 00_compile closure build Three divergence classes measured as the 21 rustc errors on the natively emitted 00_compile closure after the main merge, each repaired at the .dag source with a discriminating witness: - Locality wins over a foreign ambiguity (12 E0433 in v2_std_integer.rs): alias_rhs_base_module_filename asked the global leaf index, saw LeafAmbiguous for Compose, and emitted the poison marker even inside v2.std.integer itself, where source resolution binds the local declaration before any cross-module lookup. The local physical declaration now shadows foreign declarers; the poison marker still stands for a leaf two FOREIGN modules declare. - The qualifier is the disambiguator (8 E0425/E0433 in v2_lens_fact_density.rs): the qualified use-line route declined any globally-ambiguous leaf, but a qualified reference names its provider in its own spelling. The route now resolves by DeclaredCallableIdentity at the qualifier, keeping the type-declared and export-proof walls. The dotted spelling reaches the route through the value surface (a qualified value projection's borrowed type stamps the match patterns' parent_enum); the witness reproduces that chain exactly, and its exclude half pins the E0603 boundary (the dotted VARIANT head must still be declined). - Clone-bound forwarding is transitive (1 E0277 in std_realization_measurement.rs): the call-forwarding derivation re-derived only each callee's SELF-derived half, so a callee whose bound is itself forwarded re-derived to empty. The derivation now recurses over the call graph with the module's visited-set termination; the equality half stays one-hop as declared. Witnesses: 56/56 PASS on the rebuilt seed; regen fixed point holds. * Refuse variant record literals on the serde_json data path fail-closed A record literal with parent_enum present is a variant construction whose wire spelling is the parent coproduct's declared VariantEncoding policy -- a module-local fact of the parent's home module that emit_data_value_json does not carry. The zero-field arm's null and the map arm's untagged fields are both measured to fail serde deserialization under the internal-tag default, so the arm now refuses and the caller renders compile_error!, a build-time located refusal where a runtime panic on the data definition's expect was the latent alternative. The refusal names its trigger: a closure-wide wire-policy index beside EmitGraphInfo.type_decl_items. Witness: w_variant_record_lit_on_the_json_data_path_refuses_fail_closed forces the JSON path with a nested-record Holder and asserts the compile_error! spelling while excluding the former null mis-serialization. * Spell variant record literals on the serde_json data path from a closure-wide wire-policy index The fail-closed refusal landed in 73b582dea6 fired on 5 real corpus sites (SugarKey x2, CopiedPortCitationFrontierDisposition x3), proving variant record literals reach the JSON data path in the 00_compile closure. This change replaces the refusal with the correct spelling, driven by a new closure-wide index: - v1.compiler.infer_emit_info gains DataVariantWireSpelling, the language-general projection of a coproduct's Rust wire serde policy for one variant (InternalTagged { tag_field, tag } | BareString { tag } | Untagged | SpellingRefused { reason }), and EmitGraphInfo carries data_variant_wire_spellings: Map<String, DataVariantWireSpelling> keyed by coproduct.variant. - v1.compiler.emit_rust builds the index once per emission root via build_data_variant_wire_spellings, resolving each coproduct's policy through the new shared resolve_emission_coproduct_wire_policy (the same function the type-emission side now calls, so the two cannot drift), projecting each variant through data_path_wire_variant_tag (rename_all and StripAffix aware), and poisoning collisions as SpellingRefused so ambiguity stays fail-closed. - v1.compiler.emit's emit_data_value_json variant arm reads the index: internal-tagged spells {"_variant": tag, ...fields}, bare-string spells "tag" for nullary and refuses fielded, untagged spells the bare fields or null; unindexed keys and stored refusals remain compile-time errors. The service mock-property chain threads emit_info through so dry-run data spells identically. Witnesses: w_variant_record_lit_on_the_json_data_path_refuses_fail_closed is rewritten as ..._spells_the_internal_tag (asserts the internal-tag map, excludes the former null mis-serialization and the refusal), and w_fielded_variant_record_lit_on_the_json_data_path_spells_tag_and_fields pins the fielded case. 57/57 witnesses pass; regen fixed-point holds. * Promote field_access to SelfEmittedNative on the emit coverage frontier Fourth native-eval construct promotion, after classical_not, add, and complement. The native-only verdict arm pair lands in the already file-grain-enrolled long/ entry, so the backing citation is enrolled by construction: - emit_host_native_only_field_access_holds pins the family one-build cache run's stdout to octet 9 (the byte the family witness's warm leg pins on the same build), eval() never called. - emit_host_native_only_field_access_wrong_octet_mismatch_detected_holds breaks the expectation side with octet 1, the alt tree's byte. Both arms verified wet locally (real cargo build + native run, sharing the field_access family one-build cache key). The roster row flips to SelfEmittedNative; the two census guards update per 4b(4) — the split moves to 4 native / 11 retained and the identity-grain membership guard is renamed to name the four-member population. The family's equals_eval agreement pair stays enrolled as its program-side discrimination leg. * Drop the scratch parity probe from the tree The probe is a manual parity-loop instrument (the interpreted leg of the native-vs-interpreted comparison), not a corpus declaration with an executing consumer (DESIGN 6 experimental residue). It stays in use locally as an untracked file. * Promote match, loop, and fold_closure to SelfEmittedNative Fifth, sixth, and seventh native-eval construct promotions. The three match_loop_fold family rows flip together on one shared family-crate arm shape, per the witness_family_build_grain_ruling: each arm emits the three-member family crate once and runs its own member through the argv dispatcher against the family one-build cache key. - emit_host_native_only_{match,loop,fold_closure}_holds pin the warm legs' stdout to the family's declared octet lists (match/loop [0,1,0,0,0], fold [0,7,0,0,0]), eval() never called. - The wrong-octet controls break the expectation side with each member's own alt octets (match/loop [0,2,0,0,0], fold [0,255,255,255,255]). All six arms verified wet locally. The census guards update per 4b(4): 7 native / 8 retained, and the identity-grain membership guard is renamed to witness_native_rows_closed_membership_holds so the name stops encoding the volatile population. * Promote meet_join to SelfEmittedNative on the emit coverage frontier The meet_join family's native-only verdict arms land on the complement arm's helper, generalized to take the family member_id: meet and join run through the same argv-dispatched logic family crate (one-build cache key shared with complement, per the witness_family_build_grain_ruling), eval() never called, verdict decoded from stdout. Octets meet=1 join=1 are the bytes the family witness's warm legs pin on this same build; the wrong-octet control expects each member's alt byte (0), which the primary runs can never produce. Both arms verified wet: cold build then warm hits, PASS/PASS. The roster row flips InterpreterRetained -> SelfEmittedNative (eighth promotion); census guards move to 8 native / 7 retained with meet_join_eval_subject named in the closed membership. * Promote variant_construct to SelfEmittedNative on the emit coverage frontier The variant_construct family's native-only verdict arms follow the field_access arm shape exactly: the tree is the family's own equals_eval tree value (emit_variant_construct_eval_tree, no eval leg reachable), the run shares the family one-build cache key that emit_on_demand_variant_construct_native_one_build_holds colds, and the expected octet 9 is the byte the family witness's warm leg pins on this same build. The wrong-octet control expects the alt tree's byte (1), which the primary run can never produce; the wrong-value alt leg in the family witness keeps the program-side discrimination. Both arms verified wet: cold build then warm hit, PASS/PASS. The roster row flips InterpreterRetained -> SelfEmittedNative (ninth promotion); census guards move to 9 native / 6 retained with emit_variant_construct_eval_subgraph_node named in the closed membership. * Close the emit coverage frontier: final six rows to SelfEmittedNative The last six InterpreterRetained rows flip to SelfEmittedNative, taking the roster to 15 native / 0 retained: - filesystem_read and shell_exec_run (host-effect transport families, no translated arrow body): the arms reuse each family's own native leg with the expectation pinned as a literal grounded by the family's enrolled fixture pin (dag/extdeps/shell/exec.dag contains bash; its shell.Exec.Run argv materializes to exactly [bash, -s]), run through the families' fixed witness workspaces. - module and produced_module: the arms execute the exact sources the equals_eval pairs run (emit_module over the add fixture tree; produced_add_module_source's ingested two-fn module), octet 5 pinned against the add family's primitive-five/six oracle leg. - call and record_construct: the arms emit the families' own producer trees against their target models, octets 7 and 9 pinned against the primitive-seven/eight and wrong-field oracle legs. The four families without a one-build cache witness run under per-family fixed workspace roots; content-safety comes from the realization-digest nesting in run_host_process_admitted (changed source colds, never serves stale), the same mechanism the filesystem_read fixed workspace relies on. All twelve arms verified wet: PASS/PASS each, cold builds then warm hits. With zero retained rows the retained_via_eval_agreement constructor loses its last consumer and is deleted (DESIGN 3c); the InterpreterRetained variant stays as the disposition authority's other state. Census guards move to 15 native / 0 retained with all fifteen decl names in the closed membership. * Record the emit coverage frontier closure in the direct-path plan Axis C line: all fifteen roster rows are SelfEmittedNative as of 2026-09-08, interpreter_retained_rows() is empty, and the row constructor was deleted with the last flip. Notes explicitly that this closes axis (a) (witness-body-runs-native) only; axis (b) (the regen-grain production flip) remains operator-gated. * Restore structural text reads in 02_parse: the chars(String) <- Variant cluster Commit 285b02eed2 converted three structural-text reads in the parser to host-string builtins (chars(s:), string_length, char_at, code_point) while chasing emitted-closure compile errors. Lexeme is v2.std.text.String, which interprets as a Variant value, so every claim that parses tokens failed at runtime with 'chars expects a string argument, got Variant' — 10 claims in the required floor lane. parse_lexeme_digest folds the Lexeme list directly again, parse_char_is_arm_pattern_lead takes Char again, and parse_looks_like_match_arm_start matches string_head's CharFound/CharAbsent again. Verified locally: all 10 claims of the cluster pass. Co-authored-by: Brian Searls <briansrls@users.noreply.github.com> * Close the prepare_grammar shared-fill cost class: portable nullable carrier + preparation-time warming Two defects composed into the required floor's twelve FillBudgetExceeded refusals, both repaired at source: (1) GrammarFirstAnalysis.nullable_set was a PointwisePower<Symbol> characteristic function — a nested closure tower the cross-claim pure tier's publication walk refuses totally (ServeCacheValueNotPortable), so the one fill every parse of .dag source demands could never store and every demanding claim recomputed it. The carrier is now the enumeration it always was (List<Symbol>, the GrammarRoot.sync_tokens repair's own precedent): set_symbol_insert de-duplicates over symbol_list_contains (first_list_contains renamed, it was never first-specific), the fixpoint's convergence measure is the list's own length, and nullable_member_count dissolves into it. (2) The fill costs more than one claim's CPU budget on the lane's runner, so an in-fold first touch could never complete. The nullary v2.compiler.program_assembly.dag_prepared_grammar producer moves that first touch to strict preparation via floor_cross_claim_pure_producers_warm — outside every per-claim budget — and every claim then serves the landed fill. Co-authored-by: Brian Searls <briansrls@users.noreply.github.com> * Split the meet/join native-only arms: one member per claim under the 500ms line The two-member shape put two native-run verdicts inside one claim's 500ms CPU budget — emit of the family crate plus the cached-run receipt walk, twice over — and the required floor measured both meet_join arms over the line. The ceiling is the floor's own and does not move to admit a claim shape; the arm splits by member instead, the grain the family's equals_eval pair already claims at (emit_host_meet_equals_eval_holds / emit_host_join_equals_eval_holds). Each claim now pays one native run; the family crate build stays shared through the same one-build cache key. The coverage frontier's meet_join row re-cites emit_host_native_only_meet_holds; the join claim carries the family's other half. Co-authored-by: Brian Searls <briansrls@users.noreply.github.com> * Adjudicate the five structural-text/logic requalification deltas at their exact subjects The branch's required-witnesses lane reports five TargetChanged binding deltas, all one change class: three String sites (EmitSpellingEscape, apply_emit_spelling_escapes, integer_string_to_decimal_digits_step) requalified to v2.std.text and two Bool grounding sites (py_bool_grounding, ts_bool_grounding) requalified to v2.std.logic — the gunbc#9907 namespace-lane requalification reaching the sites the XL-N closure repair and the chars(String) <- Variant cluster repair touched. The spelling is identical on both sides in every row; only the declarer moved, from the ambient kernel type set to the named authority. Five exact-subject TransitionAdmission rows, enumerated never patterned, with the dissolution trigger on gunbc#10692's merge. Co-authored-by: Brian Searls <briansrls@users.noreply.github.com> * Share the ingested-fixture pipelines across claims: three warm producers for the five over-ceiling claims The prepare_grammar warm-store unmasked five changed witnesses over the 500ms per-claim ceiling: the classical_not family's three emit claims (marginal 474-501ms, each re-running the full tokenize->resolve pipeline on a module-constant source) and the produced_module pair (505-542ms, each re-assembling the same two-decl module). CI's runner is ~1.8x this lane's local host (median ratio over the 25 claims present in both ledgers), so these project to ~900ms there — structurally over, not variance. The repair is the roster's own named one — stop recomputing a pure function of program content — in its WARM arm, because a ~370-382ms claim-forced fill leaves under 130ms of headroom and would die mid-flight on the lane exactly as prepare_grammar's did: - produced_add_module_source (already nullary) is enrolled directly. - ingested_classical_not_arrow_with_body and its swapped sibling are new nullary producers in the ingested_fixture_arrows idiom; the three failing claims' tree helpers now take the arrow outcome, with the source-taking staging variant delegating so unselected claims keep their spans untouched. The arrow is the deepest pipeline stage whose value is closure-free and therefore portable; the InferredTree above it carries the facts PartialFunction and can never store. claim_batch: 14/14 classical_not claims pass with identical verdicts. Co-authored-by: Brian Searls <briansrls@users.noreply.github.com> * Share the door-specimen resolved tree across claims: one warm producer for the seven unmasked over-ceiling grounding claims Co-authored-by: Brian Searls <briansrls@users.noreply.github.com> * Share the family-crate emitted pairs across claims: two warm producers for the twelve ceiling-band native-only verdict claims Co-authored-by: Brian Searls <briansrls@users.noreply.github.com> --------- Co-authored-by: Cursor Agent <cursoragent@cursor.com> Co-authored-by: Brian Searls <briansrls@users.noreply.github.com> Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
… named before native bootstrap (#10886) * Land the add-slice per-stage verdict instrument named as the floor_expected_red note's producer The add-slice roster note in v2.workflow.floor_expected_red carried a dated receipt (main 3a8344b5c: infer accepts dag_add_emitted_root; the infer-then-translate composition refuses headed by infer_grounding_not_derived) and named its own next-rung trigger: a .dag entry returning the per-stage verdicts for one root, so the paragraph can name a producer instead of a commit. v2.compiler.self_host.candidate_generation_stage_verdicts is that entry, parameterized over root and target: the receipt's verdict vocabulary (infer_accepted / infer_rejected; candidate_accepted or the rejection head reason) plus the carried-reasons lists -- the half the verdict symbols cannot say, namely that infer accepts while carrying the frontier diagnostic on its accepted path, so the enrolled witness's d == None conjunct fails even where the composition reaches acceptance. v2.test.execution.self_host_candidate_generation_stage_verdicts binds the instrument to the slice's own fixture, with add_slice_stage_verdicts_entry the runnable gunbc run --function form (ExitSuccess only when infer accepts clean and the composition accepts clean). Two witnesses: infer-accepts as a permanent positive control, and the frontier-state pin that is expected to red the day the add-slice stall's trigger lands, flipping to a permanent regression control in the same change that removes the roster row (DESIGN 4b(4)). Measured by execution on this branch: the entry exits 1 printing infer=infer_accepted, infer_carried=[infer_grounding_not_derived x10], composition=infer_grounding_not_derived, composition_carried=[x11] -- the receipt reproduced, with bind_outcome's pending-plus-gate chain counted. Both witnesses PASS; the enrolled semantic witness still fails as enrolled. Co-authored-by: Brian Searls <briansrls@users.noreply.github.com> * Derive grounding for dag declared inhabitants: the add slice greens end-to-end infer gains the declared-inhabitant membership derivation: a node declared in the dag language authority's declared-inhabitants roster derives its grounding by lookup, with the roster as evidence -- the namespacing answer to the atom authority question, at specimen scope. The add slice's ten type-spine nodes (Arrow, Conj, Atom) are all roster members, so: - candidate_generation_translate_self_emit_dag_add_slice_holds passes; its floor_expected_red roster row and per-row note delete per the roster's own stale-quarantine arm - the dag same-language ingest path compiles end-to-end: cross_language_compile accepts, byte-equal to the authority's own serialization, no carried diagnostics - the add-slice stall narrows to its four python/typescript round-trip members; the original trigger's causal clause was refuted by execution and is restated against the grammar parse-product population - the instrument's frontier guard flips to add_slice_composition_accepts_holds (DESIGN 4b(4): frontier guard to permanent regression control) - five manual witnesses flip with it: two root flips rewritten to assert the green state, three transitive conjunctions updated The kinds stay frontier: non-member Arrow/Conj/Atom specimens carry GroundingNotDerived exactly as before, and all fourteen enrolled refusal/acceptance controls pass unchanged. The door's production path still reds inside rust emission, untouched by this rule. Co-authored-by: Brian Searls <briansrls@users.noreply.github.com> * Derive grounding for canonical binding atoms: dag_binding_denotation joins binding to inhabitant once The resolver already binds the surface spelling Int to the canonical binding symbol dag_binding_type_int; what that binding DENOTES is the Int inhabitant declared at dag_declared_inhabitants_core. Every hand-rolled fixture facts lookup re-authored that join (dag_add_canonical_grounding_for, record_construct_canonical_grounding_for). The language authority now declares it once as dag_binding_denotation, and infer_node_facts consumes it: an Atom whose identity is a canonical dag binding with a declared denotation derives with that denotation as its grounding evidence. Direct-rust-door specimen census: 14 underived -> 10 underived (the four dag_binding_type_int atoms derive; grammar-production atoms, algebra atoms, bare operand atoms, and the arrow/conj spine stay on the frontier unchanged). Specimen-scope interim in the same frame as infer_node_declared_in_dag_inhabitants: both delete in favor of consuming resolution output when the resolver hands infer declaration-resolved identities directly (the namespace migration's completed state). Witness: v2.test.execution.dag_binding_denotation — all four Int binding atoms in the door specimen derive with dag_int_inhabitant_node() as structural evidence, and the two bare operand atoms stay GroundingNotDerived (boundary control). Refusal suite 14/14, ingest bridge 7/7, add-slice instruments 2/2 green; every remaining red in the at-risk population reproduces identically on the pre-change tree and is enrolled in floor_expected_red. Co-authored-by: Brian Searls <briansrls@users.noreply.github.com> * Add v2 self-host direct-path orientation: axes, sequence, autonomy contract A point-in-time orientation that defers to the existing authorities (DESIGN section 7, the four-wave self-host program, the roadmap node chain, the three frontier carriers, the guarantee-stall roster, XL-N) rather than restating them: state is re-derived by the named instruments, never transcribed here. Sequences the remaining work in roadmap order (door, parse-product grounding, first behavioral module, XL-N milestones, native bootstrap, fixed point, v1 deletion) and states which decisions stay operator-gated. Co-authored-by: Brian Searls <briansrls@users.noreply.github.com> * Derive grounding for fully-evidenced Conj and Arrow products The sixth and seventh kind rules: a non-roster Conj or Arrow whose every child carries DerivedGrounding derives, its evidence the same shape re-formed over the children's grounding evidence (a fresh OccurrenceSynthetic node, never the source — the self-evidence wall holds by construction). A product with any frontier or absent child stays on the frontier with its typed diagnostic; a childless product has no evidence to compose and stays frontier. Roster members keep their roster evidence. Measured on the direct-rust-door specimen (scratch probe, uncommitted): 10 underived of 15 -> 6. The parameter conj, the module-structure conjs, and the bodied add arrow derive; what remains is the algebra atoms from the + operation (AlgebraPrimitive, ring_field_add), the module atom (dag_surface_module), the parameter references (x, y), and the grammar-projection root conj that cascades once they land. Enrolled witnesses (src/v2/test/claim/execution/infer_product_introduction_test.dag): - product_introduction_derives_fully_evidenced_products_holds — census: 4 Conj (3 derived, 1 frontier-by-frontier-child) + 1 Arrow (derived). - product_introduction_composed_evidence_carries_child_groundings_holds — the params conj's evidence is a Conj whose x/y children target the dag authority's Int inhabitant. - product_introduction_leaves_childless_conj_on_the_frontier_holds — boundary control via direct infer over a hand-built childless Conj. Flip census (pre- and post-change, zero unexpected flips): translate_underived_refusal 14/14, infer_self_grounding_wall 12/12, branch_infer_if_then_else 2/2, compile_eval_thesis_proof 6/6, ingest_bridge 9/9, cross_language_add_python_to_typescript 4/4, inhabitant_neutralization 6/6 + e2e 6/6, emit_host_classical_not 14/14, dag_binding_denotation 2/2, stage-verdicts instrument 2/2, dag_add_emit_round_trip 4/6 (the 2 enrolled reds unchanged), door production group still enrolled-red (unchanged). Co-authored-by: Brian Searls <briansrls@users.noreply.github.com> * Ground canonical-operation and grammar-production atoms by authority roster membership Two more specimen-scope derivations in infer_node_facts, both lookups into declared authorities, never inventions: - Canonical-operations roster (target_model.dag): every CanonicalOperation the target-model authority declares, rendered by target_model_canonical_operation_wire_node and gathered under one Conj root. The resolver canonicalizes surface operators (e.g. +) to those declared operations, so the wire atoms -- the operation discriminant and its field references -- derive by membership with the roster root as evidence. General over all 14 declared operations, not add-narrow. - Grammar-productions roster (dag.dag): every production in dag_grammar_root() projected to its emitted surface atom under one Conj root keyed by production name. The bridge projects a production's parse into (identity atom, captured content) pairs, so the identity atom (dag_surface_module) derives by membership with the roster root as evidence. The roster derives from the grammar root, so a production added to the grammar joins by construction. Both roster roots are Conj nodes, never structurally equal to any member atom, so the self-evidence wall holds by construction (the first attempt at the operations rule used the wire node itself as evidence and was refused by grounding_evidence_is_source -- the wall doing its work). Measured on the direct-rust-door specimen (scratch probe, uncommitted): 6 underived of 15 -> 2 (only the operand atoms x and y remain; the grammar-projection root conj cascades once the module atom grounds). Enrolled witnesses (infer_atom_grounding_rules_test.dag): each roster rule pins derivation + evidence identity + census; a boundary control pins that a bare atom with no authority membership stays frontier; the closing control pins the 2-of-15 state. Flip census: the product-introduction census witness updates 3->4 derived conjs (the top conj now cascades) and gains a hand-built partially-evidenced boundary control to replace the in-specimen one the cascade consumed. Full battery otherwise unchanged: refusal suite 14/14, grounding wall 12/12, instrument 2/2, binding-denotation 2/2, round-trips, bridge, cross-language, neutralization, emit-host all green; enrolled reds unchanged. Co-authored-by: Brian Searls <briansrls@users.noreply.github.com> * Ground binding-reference atoms from the enclosing arrow's domain declaration The fifth specimen-scope derivation, closing the direct-rust-door specimen's inference frontier: an Atom whose binding an enclosing arrow's domain declares derives with the declared domain type as its evidence -- the declaration-site annotation, itself derived (x: Int grounds the x reference). This is the same lookup the branch-operand path already performs (infer_find_arrow_domain_type_in_tree), now written to the operand atom's own facts; it is scope-naive (whole-tree, first match), recorded in the frontier note, and deletes with the other specimen-scope rules when the resolver hands infer declaration-resolved identities. The tree is threaded through the fold's init chain to reach infer_node_facts; the helper had exactly one caller. Measured on the door specimen (scratch probe, uncommitted): 2 underived of 15 -> 0. The specimen's inference frontier is fully closed, and the production observation advances from InferenceRejected (infer_grounding_not_derived) to EmissionRejected (target_use_site_ownership_lookup_miss) -- a new, typed, located deficit in the emitter, the next gate on the path. Flip census (all three rewrites verified by execution): - dag_binding_denotation_leaves_unbound_operand_atoms_on_the_frontier_holds -> dag_binding_denotation_declares_no_denotation_for_operand_bindings_holds: the boundary moves to the authority itself (the denotation table returns Absent for x/y), true regardless of infer's other rules. - The three emit_host classical-not refusal guards (canonical, staging, staging-swapped) flip to acceptance witnesses pinning the emitted text's shape -- the real-infer tree now fully derives, and the emission is the same one the equals-eval witness proves behaviorally correct. The translate-refuses-underived behavior stays enrolled on hand-staged fixtures in translate_underived_refusal_test.dag (14/14 green). The renames are carried into the commit_workflow and witness_deferral_freeze rosters. - New witnesses: binding_reference_derives_parameter_atoms_holds (evidence is the domain's Int binding atom, census 2) and door_specimen_fully_derives_holds (0 frontier of 15). Full battery at this state: refusal suite 14/14, grounding wall 12/12, instrument 2/2, binding-denotation 2/2, product-introduction 4/4, atom-rules 5/5, emit_host 14/14, round-trips 4/6 (2 enrolled reds unchanged), bridge 9/9, cross-language 4/4, neutralization 6/6 + e2e 6/6, branch 2/2, eval-thesis 6/6; door production group still enrolled-red (unchanged). Co-authored-by: Brian Searls <briansrls@users.noreply.github.com> * Green the direct-rust-door: route emission through produced-decl composition and decode canonical operator wires The door specimen's inference frontier is fully closed, so its production observation now reaches the emission stage. Two defects surfaced there, both fixed here: Emission composition. generate_rust_emission_candidate served two lanes with one root shape: the door's production path (a dag module shell) and a fixture lane (a bare rust Arrow). The translate ownership gate queried the module atom's ownership at a struct-field use site and refused with target_use_site_ownership_lookup_miss, because the module's grammar-projection conj was misread as a type record. The door's real composition is the produced-decl path: collect declaration conjuncts from the inferred tree and emit via emit_produced_decl. A new generate_rust_module_emission_candidate does exactly that, enforcing an exactly-one-declaration admission policy (rust_module_emission_decl_absent / _ambiguous). The observation and production mint paths switch to it; the fixture-lane candidate is retained with a note that it is fixture-only. A pure collector, produced_decl_conjs_in_tree, finds nodes of produced-decl shape (a Conj whose first child is a Named edge to an Arrow). Its decl-head match routes through a declared FreeMonoid<Edge> parameter because the v1 seed stamps pattern variables from a declared parameter type, not from a field-access scrutinee. Operator decode. With composition fixed, source fidelity still refused: the door emitted fn add(x: i32, y: i32) -> i32 { AlgebraPrimitive(x, y) } instead of { x + y }. Resolution canonicalizes a surface operator atom into a canonical-operation wire node, so a production tree's transform operator position carries the wire, while fixture trees that bypass resolution still carry the surface token atom. translate_project_transform_in_arrow_scope only knew the surface-token table, so the wire missed and fell to callable apply, rendering the discriminant identity. The projection now tries the wire decode first (canonical_operation_from_wire_node) and only on a wire miss falls to the surface-token table, then to callable apply; the arms are disjoint, so the dispatch adds no fallback widening. target_transform_operator_child extracts the operator child safely. The door's closing expectation now greens by execution, so its known_red_probe row in explicit_witness_admission is deleted per its own dissolution condition, and the roadmap authority note, the door contract note, and the direct-path plan are updated to record the green state. realized_closure_for_v2_direct_ rust_door_emit_run's module list reflects the produced-decl route. Verified by execution: the door witness greens; the fixture, containment, algebra, produced-decl, add-slice, and classical-not witnesses stay green; claim_executor required-ci lanes build and witnesses both exit 0; cargo fmt and clippy --all-targets -D warnings are clean. One pre-existing red, witness_projection_is_active_only in the floor_cost_debt containment roster, reproduces on the base revision and is unrelated to this change. Co-authored-by: Brian Searls <briansrls@users.noreply.github.com> * Close the parse-product grounding frontier: widen declared-inhabitant membership to the closed ingest set The declared-inhabitant roster-membership derivation in 04_infer generalized from the dag roster to the closed ingest set (dag, python, typescript): infer_node_declared_in_language_inhabitants returns the declaring authority's roster root as evidence, with deep subtree membership so a declared inhabitant's leaf fact atoms derive exactly as the inhabitant node itself. Measured: the python fixture's 19-node frontier and the typescript fixture's 28-node frontier both close to zero; all four add-slice stall population round-trip witnesses green; the python->typescript cross-language compile accepts, byte-identical to ts_source_text. Section 4b(4) flips (expecting-red probes becoming permanent regression controls for the acceptances): - cross_language_compile_refuses_canonical_underived_holds -> cross_language_compile_python_to_typescript_round_trip_holds - inhabitant_neutralization_emit_after_neutralize / same_flavor_python / go_int64_to_ts refusal helpers -> round-trip controls - inhabitant_neutralization_python_to_ts_cross_language_compile (e2e) -> round-trip control; python->go members stay refusal guards (go is outside the closed ingest set) - cross_language_emit_inhabitant_neutralization_refuses_underived_holds -> round-trip control; the python->typescript emit-matrix row reads ChainProven The add-slice stall's next-rung trigger fired, so it retired per DESIGN 4b(4): removed from all_guarantee_stalls, row file deleted, witnesses stay enrolled. Co-authored-by: Brian Searls <briansrls@users.noreply.github.com> * Promote the add family to SelfEmittedNative: native-only verdict witness for the emitted add crate First InterpreterRetained -> SelfEmittedNative promotion after classical_not, executing the v2-emitter-first-behavioral-module first slice at the coverage-frontier grain: the add family (fewest dependencies — integer literals plus one canonical operation) now carries a native-only verdict witness, so its behavior is established by the emitted crate's own stdout with eval() unreachable from the verdict path. - emit_host_native_only_add_holds: real emit -> cargo build -> native run, stdout pinned to the family's expected octet, sharing the kernel family's one-build cache key exactly as the classical_not arm shares its family's key (no duplicated cold build). - emit_host_native_only_add_wrong_octet_mismatch_detected_holds: the broken control — a no-eval verdict has no oracle leg to break, so the expectation side breaks (an octet the run never produces must not match); program-side discrimination stays with the family's equals_eval primitive-five/six pair. - The add coverage row flips disposition with its backing citation enrolled by construction (the verdict entry is file-grain enrolled in falsifier_self_host_wet_template_entries). - Frontier census tests updated at identity grain: natives are exactly {classical_not, add}; split 2/13. Verified by execution: all six native-only verdict tests green locally (real wet legs — compile_skipped receipts show cold builds and native runs); all eight emit_coverage_frontier tests green, including the unbacked-claim RED control. Co-authored-by: Brian Searls <briansrls@users.noreply.github.com> * Record the add-slice defect's repair in the declined-live-tree classification The row classified candidate_generation_translate_self_emit_dag_add_slice_holds as RealDefect/CompilerBehaviourRefusal with measured evidence that translate refuses infer_grounding_not_derived. The owner lane (v2 self-host) repaired the subject: the declared-inhabitant roster-membership derivation grounds the slice's type spine by lookup, and the witness passes under claim_batch --hermetic on the merged tree. The dated classification is kept verbatim; the disposition flips RoutedToOwner -> RepairedInThisChange with the repair measurement appended to the evidence, so the routing carrier stops dispatching a fixed defect. Structural witnesses (count 13, no NotReproduced, exact partition) are untouched and pass. * Hoist two in-body annotation blocks to module-item grain Main's annotation-placement wall (source annotations admit only standalone leading blocks attached to module-scope declarations; in-body forms refuse) reached this branch through the merge and refused 8 blocking errors on the 00_compile closure: the add-family promotion note inside the emit_coverage_frontier_roster list and the python->typescript row note inside the cross_language_emit_matrix list. Both blocks move above their enclosing declarations, rephrased to name their subject row. Measured: gunbc compile of src/v2/compiler/00_compile.dag now emits 172 files with 0 blocking errors; both files' suites stay green (8/8 and 4/4). * Promote the complement family to SelfEmittedNative: native-only verdict witness for the emitted logic family crate The complement family's native execution runs family-grain per the witness_family_build_grain_ruling (one crate for meet + join + complement, argv-dispatched), so the native-only arm emits the logic family crate and runs the complement member through the family dispatcher, sharing the family witness's one-build cache key. The verdict is decided solely by the emitted native run's stdout (expected octet 0, complement(True) = False); the broken control flips the expectation side (octet 1 can never match), with the comparator pinned by the stdout mock pair. Program-side discrimination stays with the equals_eval agreement pair and the family witness's all-alt leg. The frontier row's backing citation lands in the already file-grain-enrolled native-only verdict entry, so it is enrolled by construction; the roster comment is rephrased to cover both 2026-09-07 promotions (add and complement). The frontier test's split and native membership assertions move to 3 native / 12 retained. Verified by execution: claim_batch --hermetic on emit_host_native_only_verdict_test.dag passes all 8 witnesses (the two new complement arms included), and emit_coverage_frontier_test.dag passes all 8. * Key the emitter's host-String arm on declaration provenance, not spelling is_host_text_carrier_type answered true for any type expression whose authored name reads "String", including references to the structural alias v2.std.text.String (type String = FreeMonoid<Char>) that the namespace lane (gunbc#9907) requalified the v2 corpus's text-carrier fields to. The emitter rendered every one of those references as the host String while value-position consumers rendered the structure -- the E0308 family dominating the self-host compile-phase frontier (41 of 64 in v2_compiler_tokenize.rs on the post-merge board). The String arm now consults the resolved declaration's provenance against v1.compiler.coercion structural_declaration_modules_for -- the same roster type_realization_decision reads -- so the legacy arm and the strict decision cannot diverge on one node (DESIGN section 3, and gunbc.recurring_failure_mode alias_resolution_collides_with_kernel_spelling). Kernel mints and unresolved references keep the host answer exactly as before. Regen: the only drifted stage0 mirror is v1_compiler_emit_rust.rs itself (no module in the stage0 closure references a structurally declared String -- verified by the whole-population candidate tree), installed from target/stage0-regen-candidate after the priced round's partitioned rebuild refused MirrorHasNoOwningPackage on the emitter (the emitter is monolith-shell, not partition-owned). Fixed point verified by execution: claim_executor --required-regen on the rebuilt seed reports first_generation_equal=true over 158 adjudicated mirrors. * Peel qualified String alias leaves in field position: XL-N closure 72 -> 28 errors A field authored v2.std.text.String reached the Rust emitter as an overlay-less resolved reference leaf and rendered the bare terminal name, which binds the prelude String cross-module (#9813: kernel names are never overridden by imports, so the use-line is dropped) while every value position renders the structural carrier Rc<Vec<i64>> -- the v2_compiler_tokenize.rs E0308 family, 41 of 72 errors on the XL-N phase board. The new rust_overlayless_alias_leaf_requires_peel arm in render_rust_type_without_applied_binding detects the population (overlay-less zero-parameter alias leaf, qualified spelling, String terminal segment, closed_alias_peel_verdict agrees) and renders the alias declaration's resolved right-hand side, projecting the same realization the fn-signature positions already produce. The qualified gate is load-bearing: inside the declaring module the bare name is the correct render (the emitted module carries the alias declaration), and the local binding's resolved_type drops the RHS type argument, so an ungated peel rendered Rc<FreeMonoid> there (E0107 x13, E0282 x2 on the probe). Bare String keeps denoting the kernel scalar through the host-carrier arm. Measured: probe specimen (qualified/bare/direct-FreeMonoid/container/variant/ local-alias positions) compiles clean; XL-N compiler closure cargo check 72 -> 28 errors with the residual census dominated by the declared text_boundary_identity_wall class (kernel String vs structural carrier at bare-authored boundaries, 17 of 20 E0308s); v1-corpus fixed point holds (first_generation_equal=true, 158/158 adjudicated). * Resolve the 12 non-hop XL-N closure errors at source: text-wall conversions + witness_violates helper Four clusters, all measured non-hop additions between receipt_1 (155) and the post-peel census (28); the live gate now measures 15 with zero unadmitted regressions: - integer.dag: integer_string_to_decimal_digits_step takes v2.std.text.String; the public boundary converts with chars() (text_boundary_identity_wall specimen discharged at this site). - 01_tokenize.dag: Token/UnboundSourceAnnotation lexemes convert structural -> host String with chars_to_string() at construction, mirroring the v1 tokenizer's host-lexeme carrier. - target_model.dag + bash.dag: EmitSpellingEscape.from/to and apply_emit_spelling_escapes go structural (v2.std.text.String); the EmitSpellingQuote arm converts host->structural->host at its boundary; bash's escape rows wrap their kernel String literals with chars(). - witness.dag + 3 call sites (collection list_nth, provenance span_index_resolve_textual_locus_from_ids, compile outcome_with_diagnostics): new witness_violates<C> helper puts Violates constructions in a Witness-headed position so the emitter resolves the carrier type argument; dissolves once inference records per-call substitutions. Verified: 48 targeted claim witnesses green (tokenize behavioral, shell conformance, string brace escape, string length, map-lookup violates, source text ingress, bash materialize x12, int literal smoke x6, provenance span index x2). * Record receipt_2 on the self-host compile-phase frontier: 15-error census at 66765317ec The census at the XL-N lane tip: 155 -> 15 net, credited to the qualified-alias peel (60cbd7b697, 72 -> 28) and the twelve-error source cluster (66765317ec, 28 -> 15). The epoch changes on the instrument's target pinning (found by review on gunbc#9857), admitted with receipt_1's board as the reclassified predecessor under the identity map. Nine added identities are hop relocations admitted by the hop index; four sit in python/typescript modules newly entered into the emitted closure, admitted as ExposedByNewEmittedModule. Validated: all 36 self_host_compile_phase_frontier_witness claims PASS, including current_persisted_compile_phase_frontier_holds. * Emitter: a substituted declaration node carries its own provenance Inference substitutes the resolved declaration into a data annotation's type-argument position, so BooleanAlgebra<v2.std.logic.Bool> reaches the emitter with the arg BEING the type Bool = True | False declaration itself (Disj connective, ident_span in src/v2/std/logic.dag, no Resolved wrapper). type_reference_provenance_in_env's bare-leaf arm re-resolved that leaf in the REFERENCING module's scope, where post-#9813 a kernel-shadowed spelling answers the kernel declaration -- so the structural enum rendered as host bool against a value of BooleanAlgebra<Bool> (the python.rs:328 / typescript.rs:177 E0308 pair on the XL-N compile-phase frontier). The connective is the discriminator: a reference node is a bare name (NoConnective); a node carrying Conj/Disj structure IS the declaration, and type_reference_provenance's own-span fallback already answers that shape correctly. The guard routes declaration-shaped nodes there directly, bypassing the scope lookup that #9813 makes answer the kernel. Mirror regenerated via the regen round; fixed-point verified (claim_executor --required-regen PASS). * Clear the remaining XL-N closure errors at source: carrier conversions at the boundaries The receipt_2 census's fifteen identities, resolved at their sources: - lexing.dag, dag.dag, python.dag, typescript.dag: LexPattern.text is the structural carrier (v2.std.text.String); the construction sites held host Strings. Convert at construction with chars() -- the #9907 ingress pattern. - python.dag / typescript.dag bool groundings: qualify the annotation as BooleanAlgebra<v2.std.logic.Bool>; with the emitter's substituted- declaration provenance guard the qualified arg now renders structural. - target_model.dag: target_lex_rule_literal_step returns the host carrier (chars_to_string over the structural pattern text); TargetText.source converts at the is_empty boundary; the unicode-scalar symbol intern converts its single-codepoint list to the host carrier. - qualified_name.dag: qualified_name_from_dotted_string uses the host-carrier emptiness check (string_length == 0) instead of routing through the structural string_is_empty. - 02_parse.dag: parse_looks_like_match_arm_start rewritten on host-carrier operations (string_length, char_at, code_point) rather than converting to the structural carrier for a two-character lookahead; parse_char_is_arm_pattern_lead takes the codepoint Int directly. - v1_interpreter_primitive_surface.dag row_key: the concat pipeline lowered to a .concat() method call on std::string::String (E0599); rewritten as nested concat calls. Measured: the 00_compile closure emits 172 files and cargo check reports cargo_clean=true, cargo_error_population=0 under the pinned 1.93.0 toolchain. * Pin the cargo half's toolchain channel by construction The cargo half runs with cwd = a fresh mktemp directory; with no rust-toolchain.toml there, rustup resolves the host's DEFAULT toolchain, so a census under cargo 1.83 and one under cargo 1.93 would compare as equal epochs while different compilers did the measuring -- the fabricated comparability the target pin (gunbc#9857) excludes, one level up. Measured 2026-09-07: a host default of 1.83.0 met a crates.io index whose freshly published dependency manifests require edition2024, resolution failed before any diagnostic existed, and the zero-diagnostic refusal fired on an unmeasured tree. The pin is propagated by copying the repo's rust-toolchain.toml into out_dir: the file remains the sole in-repo channel authority (its header forbids a second pinned literal), and the copy makes the measured channel true by construction on any host. The gate's read_live_toolchain observes the same channel because every documented actuator invokes from the repository root, which the same file governs. * Record receipt_3 on the self-host compile-phase frontier: the emitted closure's cargo census is empty Measured at 5ee4892b70 by the one-entry instrument: the 172-file emitted crate reports zero cargo error diagnostics, so the board attributes every phase a count of zero and furthest_phase_reached stands at Borrowck. The fifteen removals against receipt_2 need no disposition; nothing was added. The epoch does not change: the cargo half now pins the toolchain channel by copying the repo's rust-toolchain.toml into the scratch crate, and every recorded comparison field is identical to receipt_2 (whose census the fingerprint evidence shows the same 1.93.0 toolchain already compiled), so the same-epoch arm carries no reclassified predecessor. The frontier-state pin flips per DESIGN 4b(4): the_published_frontier_standing_does_not_claim_typeck_or_borrowck_passed becomes the_published_frontier_standing_claims_typeck_and_borrowck_passed, the permanent regression control over the green state. Validated: all 36 self_host_compile_phase_frontier_witness claims PASS, including current_persisted_compile_phase_frontier_holds. * chore: regenerate drifted generated artifacts (ci auto-heal) Ledger-Repair-Judged: docs/design-failure-modes.md Ledger-Repair-Judged: docs/design-rung-drops.md * Remove the stale PointwisePower inhabitant rows from the four language rosters First native-parity divergence class found by running the emitted closure on a discriminating fixture: the algebra inhabitant rosters still carried PointwisePower after its authority row was cut, so the emitted compiler panicked at 12 record-shaped carrier sites while the interpreted seed refused cleanly. The roster rows are removed in rust/python/go/typescript types.dag, the derived coercion assertions in compiler_tests.rs regenerate without them, and two witnesses pin the boundary: the record shape constructs its structural carrier, and FinitePowerSet still refuses while its row stands. Mirrors regenerated by a converged regen round (fixed point Reached, stage-1 PromoteGenerationInputs over the three language types mirrors). * Regen gen-2 gate: compare executable digests in one spelling The admitted side of run_built_seed_regen carries the executable-digest spelling (current_exe_digest, next_pass_executable_digest) while the observed side hashed the file through path_digest, which prepends the fnv1a64: tag. Same bytes, two spellings, so the gate could never pass -- unpassable since fa2d403dc8 (#9771). Factor current_exe_on_disk as the single path authority and read the observed digest through current_exe_digest so both sides spell the same bytes the same way. * Model ReleaseScopeEmpty for release-excluded mirrors, end to end A regen round whose only stage-2 drift was compiler_tests.rs (the PointwisePower roster removal rewrote its derived coercion assertions) refused the rebuild MirrorHasNoOwningPackage: the mirror is owned by no partition package, because every item it defines is #[cfg(test)] and no release unit elaborates it. The refusal conflated two different states -- unowned (a coverage hole) and excluded from the release build by construction (a precise empty scope). The model now names the class: rebuild_scope_release_excluded_mirrors rosters its members (compiler_tests.rs, cited to emit_compiler_tests_module), the decision answers ReleaseScopeEmpty when the whole change set is excluded, and the actuation shape is actuatable with an empty package closure and every partition package excluded -- the build still runs as verification, and a compiled partition package refuses the stage. The host admits the empty closure only when the new stage0_partition_rebuild_release_scope_empty_today query answers true; any other empty closure still refuses. A mixed change set scopes on its release-visible members alone. Verified by execution: the 2026-09-08 round converged (fixed point Reached) with stage-2 installing compiler_tests.rs alone; cargo recompiled the shell crate on its fingerprint (the outer mod line is ungated, so rustc reads the file) while the produced executable was byte-identical -- stage input seed digest == output seed digest. Four new witnesses pin the arm, its actuation shape, the mixed set, and the host-facing query's two arms; the boundary witness (unowned cli_run.rs still refuses) keeps the roster from decaying into the absorbing fallback. * Round-cost receipt: project installed mirrors to the model's vocabulary The receipt's partition-rebuild line is rendered by the model over receipt.installed_mirrors, which the host populated from the stages' projected_paths -- full paths -- while the partition rows and rosters key on basenames. Every drifted round's receipt therefore rendered a spurious RebuildScopeRefused MirrorHasNoOwningPackage line naming a full path, a false claim on the round's own receipt. Route the projection through emit_path_basename, the module's single path-to-basename bridge, so the field carries the mirror names the model's vocabulary means. * Hoist ReleaseScopeEmpty annotations to module-item grain The ReleaseScopeEmpty modeling commit placed three // blocks inside declaration bodies (stage0_partition_rebuild_is_actuatable, stage0_partition_rebuild_decision, stage0_partition_rebuild_excluded_today). The .dag realization admits annotations at module-item grain only, so the floor lane's parse phase refused the file with 12 located errors and the run ended floor refused. The prose is unchanged; each block now sits above the declaration it describes. * Spell the PointwisePower witness's finite-set exclusion as the applied realization The witness added with the fossil-row removal excluded the bare spelling "BTreeSet", but every emitted file's preamble imports OrdSet as BTreeSet, so the row could never green. The exclusion's subject is the finite-set REALIZATION the fossil row would have asserted; spell it applied (BTreeSet<i64), which the preamble's import line does not contain. * Emit fieldless-record data values as null for the unit-struct carrier The second native-parity divergence class, measured 2026-09-08 on the native run of the emitted 00_compile closure: emit_data_value_json spelled EVERY record literal as a JSON map, including the zero-field record, while emit_struct_from_children renders that same declaration as a Rust unit struct (pub struct BoolEncodingFact;). serde's derived unit-struct Deserialize reads null and rejects {}, so the emitted compiler panicked at first touch of v2.std.logic's bool_primitive_facts: "invalid type: map, expected unit struct BoolEncodingFact". The JSON spelling of a data value must deserialize into the Rust type the same declaration emitted; the record arm now spells the zero-field value null and keeps the map spelling for non-empty records. The mirror is taken from the required-regen candidate, not hand-edited. Two witnesses enroll: the discriminating red (zero-field record spells null, never {}) and the boundary control (a record with fields keeps the map spelling). * Bind the duplicate-definition filter ahead of its branch condition Main's FilterInBranchCondition wall (#10699) refuses to publish a module whose filter call sits in a branch condition, and the v2 00_compile closure emission names primitive_duplicate_semantic_definition_violation as such a site. The filter is pure and total; binding it with a let ahead of the branch is the authored remediation the wall exists to force, and the emitted closure is unchanged in behavior. * chore: regenerate drifted generated artifacts (ci auto-heal) Ledger-Repair-Judged: docs/design-rung-drops.md Ledger-Rows-Repaired: docs/design-rung-drops.md rust_unit_tests_off_the_merge_path Ledger-Rows-Repaired: docs/design-rung-drops.md determinism_transitive_reachability Ledger-Rows-Repaired: docs/design-rung-drops.md transitional_admission_exception * Emitter: three native-parity repairs for the post-merge 00_compile closure build Three divergence classes measured as the 21 rustc errors on the natively emitted 00_compile closure after the main merge, each repaired at the .dag source with a discriminating witness: - Locality wins over a foreign ambiguity (12 E0433 in v2_std_integer.rs): alias_rhs_base_module_filename asked the global leaf index, saw LeafAmbiguous for Compose, and emitted the poison marker even inside v2.std.integer itself, where source resolution binds the local declaration before any cross-module lookup. The local physical declaration now shadows foreign declarers; the poison marker still stands for a leaf two FOREIGN modules declare. - The qualifier is the disambiguator (8 E0425/E0433 in v2_lens_fact_density.rs): the qualified use-line route declined any globally-ambiguous leaf, but a qualified reference names its provider in its own spelling. The route now resolves by DeclaredCallableIdentity at the qualifier, keeping the type-declared and export-proof walls. The dotted spelling reaches the route through the value surface (a qualified value projection's borrowed type stamps the match patterns' parent_enum); the witness reproduces that chain exactly, and its exclude half pins the E0603 boundary (the dotted VARIANT head must still be declined). - Clone-bound forwarding is transitive (1 E0277 in std_realization_measurement.rs): the call-forwarding derivation re-derived only each callee's SELF-derived half, so a callee whose bound is itself forwarded re-derived to empty. The derivation now recurses over the call graph with the module's visited-set termination; the equality half stays one-hop as declared. Witnesses: 56/56 PASS on the rebuilt seed; regen fixed point holds. * Refuse variant record literals on the serde_json data path fail-closed A record literal with parent_enum present is a variant construction whose wire spelling is the parent coproduct's declared VariantEncoding policy -- a module-local fact of the parent's home module that emit_data_value_json does not carry. The zero-field arm's null and the map arm's untagged fields are both measured to fail serde deserialization under the internal-tag default, so the arm now refuses and the caller renders compile_error!, a build-time located refusal where a runtime panic on the data definition's expect was the latent alternative. The refusal names its trigger: a closure-wide wire-policy index beside EmitGraphInfo.type_decl_items. Witness: w_variant_record_lit_on_the_json_data_path_refuses_fail_closed forces the JSON path with a nested-record Holder and asserts the compile_error! spelling while excluding the former null mis-serialization. * Spell variant record literals on the serde_json data path from a closure-wide wire-policy index The fail-closed refusal landed in 73b582dea6 fired on 5 real corpus sites (SugarKey x2, CopiedPortCitationFrontierDisposition x3), proving variant record literals reach the JSON data path in the 00_compile closure. This change replaces the refusal with the correct spelling, driven by a new closure-wide index: - v1.compiler.infer_emit_info gains DataVariantWireSpelling, the language-general projection of a coproduct's Rust wire serde policy for one variant (InternalTagged { tag_field, tag } | BareString { tag } | Untagged | SpellingRefused { reason }), and EmitGraphInfo carries data_variant_wire_spellings: Map<String, DataVariantWireSpelling> keyed by coproduct.variant. - v1.compiler.emit_rust builds the index once per emission root via build_data_variant_wire_spellings, resolving each coproduct's policy through the new shared resolve_emission_coproduct_wire_policy (the same function the type-emission side now calls, so the two cannot drift), projecting each variant through data_path_wire_variant_tag (rename_all and StripAffix aware), and poisoning collisions as SpellingRefused so ambiguity stays fail-closed. - v1.compiler.emit's emit_data_value_json variant arm reads the index: internal-tagged spells {"_variant": tag, ...fields}, bare-string spells "tag" for nullary and refuses fielded, untagged spells the bare fields or null; unindexed keys and stored refusals remain compile-time errors. The service mock-property chain threads emit_info through so dry-run data spells identically. Witnesses: w_variant_record_lit_on_the_json_data_path_refuses_fail_closed is rewritten as ..._spells_the_internal_tag (asserts the internal-tag map, excludes the former null mis-serialization and the refusal), and w_fielded_variant_record_lit_on_the_json_data_path_spells_tag_and_fields pins the fielded case. 57/57 witnesses pass; regen fixed-point holds. * Promote field_access to SelfEmittedNative on the emit coverage frontier Fourth native-eval construct promotion, after classical_not, add, and complement. The native-only verdict arm pair lands in the already file-grain-enrolled long/ entry, so the backing citation is enrolled by construction: - emit_host_native_only_field_access_holds pins the family one-build cache run's stdout to octet 9 (the byte the family witness's warm leg pins on the same build), eval() never called. - emit_host_native_only_field_access_wrong_octet_mismatch_detected_holds breaks the expectation side with octet 1, the alt tree's byte. Both arms verified wet locally (real cargo build + native run, sharing the field_access family one-build cache key). The roster row flips to SelfEmittedNative; the two census guards update per 4b(4) — the split moves to 4 native / 11 retained and the identity-grain membership guard is renamed to name the four-member population. The family's equals_eval agreement pair stays enrolled as its program-side discrimination leg. * Drop the scratch parity probe from the tree The probe is a manual parity-loop instrument (the interpreted leg of the native-vs-interpreted comparison), not a corpus declaration with an executing consumer (DESIGN 6 experimental residue). It stays in use locally as an untracked file. * Promote match, loop, and fold_closure to SelfEmittedNative Fifth, sixth, and seventh native-eval construct promotions. The three match_loop_fold family rows flip together on one shared family-crate arm shape, per the witness_family_build_grain_ruling: each arm emits the three-member family crate once and runs its own member through the argv dispatcher against the family one-build cache key. - emit_host_native_only_{match,loop,fold_closure}_holds pin the warm legs' stdout to the family's declared octet lists (match/loop [0,1,0,0,0], fold [0,7,0,0,0]), eval() never called. - The wrong-octet controls break the expectation side with each member's own alt octets (match/loop [0,2,0,0,0], fold [0,255,255,255,255]). All six arms verified wet locally. The census guards update per 4b(4): 7 native / 8 retained, and the identity-grain membership guard is renamed to witness_native_rows_closed_membership_holds so the name stops encoding the volatile population. * Promote meet_join to SelfEmittedNative on the emit coverage frontier The meet_join family's native-only verdict arms land on the complement arm's helper, generalized to take the family member_id: meet and join run through the same argv-dispatched logic family crate (one-build cache key shared with complement, per the witness_family_build_grain_ruling), eval() never called, verdict decoded from stdout. Octets meet=1 join=1 are the bytes the family witness's warm legs pin on this same build; the wrong-octet control expects each member's alt byte (0), which the primary runs can never produce. Both arms verified wet: cold build then warm hits, PASS/PASS. The roster row flips InterpreterRetained -> SelfEmittedNative (eighth promotion); census guards move to 8 native / 7 retained with meet_join_eval_subject named in the closed membership. * Promote variant_construct to SelfEmittedNative on the emit coverage frontier The variant_construct family's native-only verdict arms follow the field_access arm shape exactly: the tree is the family's own equals_eval tree value (emit_variant_construct_eval_tree, no eval leg reachable), the run shares the family one-build cache key that emit_on_demand_variant_construct_native_one_build_holds colds, and the expected octet 9 is the byte the family witness's warm leg pins on this same build. The wrong-octet control expects the alt tree's byte (1), which the primary run can never produce; the wrong-value alt leg in the family witness keeps the program-side discrimination. Both arms verified wet: cold build then warm hit, PASS/PASS. The roster row flips InterpreterRetained -> SelfEmittedNative (ninth promotion); census guards move to 9 native / 6 retained with emit_variant_construct_eval_subgraph_node named in the closed membership. * Close the emit coverage frontier: final six rows to SelfEmittedNative The last six InterpreterRetained rows flip to SelfEmittedNative, taking the roster to 15 native / 0 retained: - filesystem_read and shell_exec_run (host-effect transport families, no translated arrow body): the arms reuse each family's own native leg with the expectation pinned as a literal grounded by the family's enrolled fixture pin (dag/extdeps/shell/exec.dag contains bash; its shell.Exec.Run argv materializes to exactly [bash, -s]), run through the families' fixed witness workspaces. - module and produced_module: the arms execute the exact sources the equals_eval pairs run (emit_module over the add fixture tree; produced_add_module_source's ingested two-fn module), octet 5 pinned against the add family's primitive-five/six oracle leg. - call and record_construct: the arms emit the families' own producer trees against their target models, octets 7 and 9 pinned against the primitive-seven/eight and wrong-field oracle legs. The four families without a one-build cache witness run under per-family fixed workspace roots; content-safety comes from the realization-digest nesting in run_host_process_admitted (changed source colds, never serves stale), the same mechanism the filesystem_read fixed workspace relies on. All twelve arms verified wet: PASS/PASS each, cold builds then warm hits. With zero retained rows the retained_via_eval_agreement constructor loses its last consumer and is deleted (DESIGN 3c); the InterpreterRetained variant stays as the disposition authority's other state. Census guards move to 15 native / 0 retained with all fifteen decl names in the closed membership. * Record the emit coverage frontier closure in the direct-path plan Axis C line: all fifteen roster rows are SelfEmittedNative as of 2026-09-08, interpreter_retained_rows() is empty, and the row constructor was deleted with the last flip. Notes explicitly that this closes axis (a) (witness-body-runs-native) only; axis (b) (the regen-grain production flip) remains operator-gated. * Restore structural text reads in 02_parse: the chars(String) <- Variant cluster Commit 285b02eed2 converted three structural-text reads in the parser to host-string builtins (chars(s:), string_length, char_at, code_point) while chasing emitted-closure compile errors. Lexeme is v2.std.text.String, which interprets as a Variant value, so every claim that parses tokens failed at runtime with 'chars expects a string argument, got Variant' — 10 claims in the required floor lane. parse_lexeme_digest folds the Lexeme list directly again, parse_char_is_arm_pattern_lead takes Char again, and parse_looks_like_match_arm_start matches string_head's CharFound/CharAbsent again. Verified locally: all 10 claims of the cluster pass. Co-authored-by: Brian Searls <briansrls@users.noreply.github.com> * Close the prepare_grammar shared-fill cost class: portable nullable carrier + preparation-time warming Two defects composed into the required floor's twelve FillBudgetExceeded refusals, both repaired at source: (1) GrammarFirstAnalysis.nullable_set was a PointwisePower<Symbol> characteristic function — a nested closure tower the cross-claim pure tier's publication walk refuses totally (ServeCacheValueNotPortable), so the one fill every parse of .dag source demands could never store and every demanding claim recomputed it. The carrier is now the enumeration it always was (List<Symbol>, the GrammarRoot.sync_tokens repair's own precedent): set_symbol_insert de-duplicates over symbol_list_contains (first_list_contains renamed, it was never first-specific), the fixpoint's convergence measure is the list's own length, and nullable_member_count dissolves into it. (2) The fill costs more than one claim's CPU budget on the lane's runner, so an in-fold first touch could never complete. The nullary v2.compiler.program_assembly.dag_prepared_grammar producer moves that first touch to strict preparation via floor_cross_claim_pure_producers_warm — outside every per-claim budget — and every claim then serves the landed fill. Co-authored-by: Brian Searls <briansrls@users.noreply.github.com> * Split the meet/join native-only arms: one member per claim under the 500ms line The two-member shape put two native-run verdicts inside one claim's 500ms CPU budget — emit of the family crate plus the cached-run receipt walk, twice over — and the required floor measured both meet_join arms over the line. The ceiling is the floor's own and does not move to admit a claim shape; the arm splits by member instead, the grain the family's equals_eval pair already claims at (emit_host_meet_equals_eval_holds / emit_host_join_equals_eval_holds). Each claim now pays one native run; the family crate build stays shared through the same one-build cache key. The coverage frontier's meet_join row re-cites emit_host_native_only_meet_holds; the join claim carries the family's other half. Co-authored-by: Brian Searls <briansrls@users.noreply.github.com> * Adjudicate the five structural-text/logic requalification deltas at their exact subjects The branch's required-witnesses lane reports five TargetChanged binding deltas, all one change class: three String sites (EmitSpellingEscape, apply_emit_spelling_escapes, integer_string_to_decimal_digits_step) requalified to v2.std.text and two Bool grounding sites (py_bool_grounding, ts_bool_grounding) requalified to v2.std.logic — the gunbc#9907 namespace-lane requalification reaching the sites the XL-N closure repair and the chars(String) <- Variant cluster repair touched. The spelling is identical on both sides in every row; only the declarer moved, from the ambient kernel type set to the named authority. Five exact-subject TransitionAdmission rows, enumerated never patterned, with the dissolution trigger on gunbc#10692's merge. Co-authored-by: Brian Searls <briansrls@users.noreply.github.com> * Share the ingested-fixture pipelines across claims: three warm producers for the five over-ceiling claims The prepare_grammar warm-store unmasked five changed witnesses over the 500ms per-claim ceiling: the classical_not family's three emit claims (marginal 474-501ms, each re-running the full tokenize->resolve pipeline on a module-constant source) and the produced_module pair (505-542ms, each re-assembling the same two-decl module). CI's runner is ~1.8x this lane's local host (median ratio over the 25 claims present in both ledgers), so these project to ~900ms there — structurally over, not variance. The repair is the roster's own named one — stop recomputing a pure function of program content — in its WARM arm, because a ~370-382ms claim-forced fill leaves under 130ms of headroom and would die mid-flight on the lane exactly as prepare_grammar's did: - produced_add_module_source (already nullary) is enrolled directly. - ingested_classical_not_arrow_with_body and its swapped sibling are new nullary producers in the ingested_fixture_arrows idiom; the three failing claims' tree helpers now take the arrow outcome, with the source-taking staging variant delegating so unselected claims keep their spans untouched. The arrow is the deepest pipeline stage whose value is closure-free and therefore portable; the InferredTree above it carries the facts PartialFunction and can never store. claim_batch: 14/14 classical_not claims pass with identical verdicts. Co-authored-by: Brian Searls <briansrls@users.noreply.github.com> * Share the door-specimen resolved tree across claims: one warm producer for the seven unmasked over-ceiling grounding claims Co-authored-by: Brian Searls <briansrls@users.noreply.github.com> * Stage0 emission boundary as a target profile: visibility and integer carrier selected, measured over the disk route The regen-grain flip's presumptive subject (std.integer) is not producible by the v2 generator, and neither is any other real corpus mirror. Measured, not assumed: of the 152 committed stage0 mirrors joined to their .dag sources, exactly one module carries a single declaration -- the shape the production composition admits -- and that module's body stops emission. So this change lands the two BOUNDARY selections the flip needs, and names the remainder. The two selections are not emitter generalization. Rust owns what Rust is; this adds what the stage0 SEED CRATE requires of a module emitted into it: visibility -- every committed mirror is `pub`, because the crate calls across module boundaries (gunbc_rust_decl_type_overlay's function is called from v1_compiler_emit_rust). The .dag source spells no visibility and Rust emission in general must not: a private item is correct at a boundary with no external consumer. The keyword is a Rust row; the SELECTION is the profile's. integer carrier -- the language's Int is unbounded and a Rust realization picks a primitive. The committed stage0 ABI is i64; the direct-door fixtures are organized around i32 and stay that way. rust_binding_spellings_for_int takes the carrier as a parameter rather than the base target being relabelled, which would have fused two boundaries into one row (DESIGN section 3). Evidence, all three PASS by execution (claim_batch, wet -- the specimen is read off disk, not carried inline): the profile emits `pub fn probe_add(x: i64, y: i64) -> i64 { x + y }` through source_ref_for_observed_storage_path -> ingest -> assemble -> infer -> the production single-declaration composition; and two controls, one per capability class, observe the base target emitting no `pub` and emitting i32 at the exact positions the crate fixes. Each fails for its own reason, so a regression in one cannot be masked by the other. No enrolled claim exercised the disk-backed production seam before this one -- the door's own specimen carries its module source inline. THE REMAINDER, measured per form over real files rather than predicted. The overlay module's body needs five further capabilities, and three of them are inference frontier, not emission: x > y EMIT refuses (transform shape invalid at the first operand) !a EMIT refuses (same site) x + 1 INFER refuses -- integer literals are Value-kind, no rule let z = ... INFER refuses -- Bind-kind, no rule Int? param EMIT refuses -- type ref renders only Atom shapes match v {...} ASSEMBLE refuses -- Present/Absent unbound with no import 04_infer's node_grounding_frontier_note already states this: v2 derives six of twelve node kinds, "Transform add-shape only". So the production-compatible corpus module is gated on that open frontier, not on a handful of spellings, and a > b working while a && b works is a resolution/layout question rather than a missing operator row (the canonicalization table already carries op_gt). Also noted, unfixed and deliberately so: an unspelled type binding prints its symbol lexeme (`bool_node_symbol`) instead of refusing, and the Rust bool spelling exists twice -- once as a TargetAtomRealization, once as a binding-spellings row. The repair is for produced-decl type refs to consult the atom realization catalog, which is the first missing join rather than a new row. One roadmap transition added between the direct door and the flip (v2-emitter-production-compatible-corpus-module), so the flip node keeps its own different fact: that production regeneration actually selected v2 and could not reach the old generator. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_011X5tyxfVrw3chDNbQ3sVD3 * Share the family-crate emitted pairs across claims: two warm producers for the twelve ceiling-band native-only verdict claims Co-authored-by: Brian Searls <briansrls@users.noreply.github.com> * Keep the base Rust spelling map byte-identical, and share the two stage0-boundary emissions The floor refused this branch's first head two ways, and both are cost, not content. Fixed at the cause rather than by raising a line. FIRST: twelve of #10692's native-only rows tipped 6-118ms over the 500ms per-claim ceiling. They sit deliberately just under it -- the parent's last two commits are about keeping them there -- and this branch had re-parameterized rust_binding_spellings, which every one of them evaluates. The profile now OVERLAYS the single key it changes (map_insert over the Rust map) instead, so the base map is byte-for-byte what it was and every claim already sharing one evaluation of it keeps sharing exactly that one. A profile's delta belongs to the profile; charging every other witness for it was the defect. SECOND: this branch's own three claims were INTERRUPTED BEFORE VERDICT at ~1200ms each -- a full ingest-assemble-infer-emit walk per claim. Split by an ingest-only/assemble-only probe pair, the disk read and its content-hash verification cost 0ms and assembly costs 878ms, so the recompute was assembly, three times, of a pure function of one file's content. Two repairs, both the roster's own named one: The emission claims now run over direct_rust_door_specimen_resolved, the already-warm-enrolled producer of a resolved add-shaped module. A second producer for a specimen of the same shape would have been the duplication that roster exists to end. The two emissions themselves (profile target, base target) are nullary producers enrolled warm, the same shape as produced_add_module_source. Each claim is then a string comparison, and infer+emit is evaluated once at preparation rather than three times inside three budgets. THE READ IS CLAIMED SEPARATELY, because it is a separate fact and it is free (0-5ms): the committed fixture reaches source_ref_for_observed_storage_path and source_root_ingest_from_source_refs, whose content-hash verification is the seam no enrolled claim covered -- the door's specimen carries its module source inline. The assertion is a containment, not a whole-text golden, so editing the fixture's prose is not a test failure (a change detector, not a check). claim_batch over the entry: 5/5 PASS. The emission claims read the door specimen, so the expected sources name its declaration (`add`) rather than the fixture's. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_011X5tyxfVrw3chDNbQ3sVD3 * The probe file states the seam it is actually the subject of Review 62939 is right, and the gap is exactly where it says: the fixture's own annotation still described the enrolled fact as disk -> ingest -> assemble -> infer -> emit. That was true when written and stopped being true one commit later, when the three emission claims moved onto the door's warm-shared resolved specimen to fit the floor's per-claim ceiling. An annotation describing a route no claim executes is DESIGN section 5's specification-without-execution, and it is worse than absent because it reads as coverage. The file now states what it is the subject of -- the storage-read seam, claimed by the two read claims over the bytes actually on disk -- and says outright that no claim ingests, assembles, infers or emits it, with the reason the split happened. The two facts stay separate on purpose: the READ is claimed over a real file, the two target-profile SELECTIONS over the shared specimen, and neither claim covers the other. No behavior changes; the claims are unchanged and still PASS. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_011X5tyxfVrw3chDNbQ3sVD3 * One measurement, one home: the claim file names the instrument and stops transcribing it Review 62942 caught the drift as it happened. The same measurement -- these three claims against the per-claim ceiling -- was transcribed twice in one diff, into the test file and into the enrolment row, and the two copies already disagreed (713-805 against 713-834). DESIGN section 6 forbids exactly this: name the producer that re-derives a measurement, never copy its numbers into prose, because a transcribed number is unreachable from the run that owns it and rots without either end being touched. The disagreement is that rot arriving on day zero. The figures now live once, at the enrolment row in v2.workflow.floor_pure_producer_share, which is where the ceiling arithmetic is argued and where every neighbouring row already argues its own. The test file names the instrument -- claim_batch's [witness] receipt over this entry, with the ingest-only / assemble-only probe pair that splits the pipeline -- and states the shape of the fact (unshared, each claim costs multiples of the ceiling; the read pair is the cheapest in the file) without restating a number beside it. Claims unchanged: 5/5 PASS. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_011X5tyxfVrw3chDNbQ3sVD3 * The…
… taxonomy, admission, enrolment gate (#10882) * Land the add-slice per-stage verdict instrument named as the floor_expected_red note's producer The add-slice roster note in v2.workflow.floor_expected_red carried a dated receipt (main 3a8344b5c: infer accepts dag_add_emitted_root; the infer-then-translate composition refuses headed by infer_grounding_not_derived) and named its own next-rung trigger: a .dag entry returning the per-stage verdicts for one root, so the paragraph can name a producer instead of a commit. v2.compiler.self_host.candidate_generation_stage_verdicts is that entry, parameterized over root and target: the receipt's verdict vocabulary (infer_accepted / infer_rejected; candidate_accepted or the rejection head reason) plus the carried-reasons lists -- the half the verdict symbols cannot say, namely that infer accepts while carrying the frontier diagnostic on its accepted path, so the enrolled witness's d == None conjunct fails even where the composition reaches acceptance. v2.test.execution.self_host_candidate_generation_stage_verdicts binds the instrument to the slice's own fixture, with add_slice_stage_verdicts_entry the runnable gunbc run --function form (ExitSuccess only when infer accepts clean and the composition accepts clean). Two witnesses: infer-accepts as a permanent positive control, and the frontier-state pin that is expected to red the day the add-slice stall's trigger lands, flipping to a permanent regression control in the same change that removes the roster row (DESIGN 4b(4)). Measured by execution on this branch: the entry exits 1 printing infer=infer_accepted, infer_carried=[infer_grounding_not_derived x10], composition=infer_grounding_not_derived, composition_carried=[x11] -- the receipt reproduced, with bind_outcome's pending-plus-gate chain counted. Both witnesses PASS; the enrolled semantic witness still fails as enrolled. Co-authored-by: Brian Searls <briansrls@users.noreply.github.com> * Derive grounding for dag declared inhabitants: the add slice greens end-to-end infer gains the declared-inhabitant membership derivation: a node declared in the dag language authority's declared-inhabitants roster derives its grounding by lookup, with the roster as evidence -- the namespacing answer to the atom authority question, at specimen scope. The add slice's ten type-spine nodes (Arrow, Conj, Atom) are all roster members, so: - candidate_generation_translate_self_emit_dag_add_slice_holds passes; its floor_expected_red roster row and per-row note delete per the roster's own stale-quarantine arm - the dag same-language ingest path compiles end-to-end: cross_language_compile accepts, byte-equal to the authority's own serialization, no carried diagnostics - the add-slice stall narrows to its four python/typescript round-trip members; the original trigger's causal clause was refuted by execution and is restated against the grammar parse-product population - the instrument's frontier guard flips to add_slice_composition_accepts_holds (DESIGN 4b(4): frontier guard to permanent regression control) - five manual witnesses flip with it: two root flips rewritten to assert the green state, three transitive conjunctions updated The kinds stay frontier: non-member Arrow/Conj/Atom specimens carry GroundingNotDerived exactly as before, and all fourteen enrolled refusal/acceptance controls pass unchanged. The door's production path still reds inside rust emission, untouched by this rule. Co-authored-by: Brian Searls <briansrls@users.noreply.github.com> * Derive grounding for canonical binding atoms: dag_binding_denotation joins binding to inhabitant once The resolver already binds the surface spelling Int to the canonical binding symbol dag_binding_type_int; what that binding DENOTES is the Int inhabitant declared at dag_declared_inhabitants_core. Every hand-rolled fixture facts lookup re-authored that join (dag_add_canonical_grounding_for, record_construct_canonical_grounding_for). The language authority now declares it once as dag_binding_denotation, and infer_node_facts consumes it: an Atom whose identity is a canonical dag binding with a declared denotation derives with that denotation as its grounding evidence. Direct-rust-door specimen census: 14 underived -> 10 underived (the four dag_binding_type_int atoms derive; grammar-production atoms, algebra atoms, bare operand atoms, and the arrow/conj spine stay on the frontier unchanged). Specimen-scope interim in the same frame as infer_node_declared_in_dag_inhabitants: both delete in favor of consuming resolution output when the resolver hands infer declaration-resolved identities directly (the namespace migration's completed state). Witness: v2.test.execution.dag_binding_denotation — all four Int binding atoms in the door specimen derive with dag_int_inhabitant_node() as structural evidence, and the two bare operand atoms stay GroundingNotDerived (boundary control). Refusal suite 14/14, ingest bridge 7/7, add-slice instruments 2/2 green; every remaining red in the at-risk population reproduces identically on the pre-change tree and is enrolled in floor_expected_red. Co-authored-by: Brian Searls <briansrls@users.noreply.github.com> * Add v2 self-host direct-path orientation: axes, sequence, autonomy contract A point-in-time orientation that defers to the existing authorities (DESIGN section 7, the four-wave self-host program, the roadmap node chain, the three frontier carriers, the guarantee-stall roster, XL-N) rather than restating them: state is re-derived by the named instruments, never transcribed here. Sequences the remaining work in roadmap order (door, parse-product grounding, first behavioral module, XL-N milestones, native bootstrap, fixed point, v1 deletion) and states which decisions stay operator-gated. Co-authored-by: Brian Searls <briansrls@users.noreply.github.com> * Derive grounding for fully-evidenced Conj and Arrow products The sixth and seventh kind rules: a non-roster Conj or Arrow whose every child carries DerivedGrounding derives, its evidence the same shape re-formed over the children's grounding evidence (a fresh OccurrenceSynthetic node, never the source — the self-evidence wall holds by construction). A product with any frontier or absent child stays on the frontier with its typed diagnostic; a childless product has no evidence to compose and stays frontier. Roster members keep their roster evidence. Measured on the direct-rust-door specimen (scratch probe, uncommitted): 10 underived of 15 -> 6. The parameter conj, the module-structure conjs, and the bodied add arrow derive; what remains is the algebra atoms from the + operation (AlgebraPrimitive, ring_field_add), the module atom (dag_surface_module), the parameter references (x, y), and the grammar-projection root conj that cascades once they land. Enrolled witnesses (src/v2/test/claim/execution/infer_product_introduction_test.dag): - product_introduction_derives_fully_evidenced_products_holds — census: 4 Conj (3 derived, 1 frontier-by-frontier-child) + 1 Arrow (derived). - product_introduction_composed_evidence_carries_child_groundings_holds — the params conj's evidence is a Conj whose x/y children target the dag authority's Int inhabitant. - product_introduction_leaves_childless_conj_on_the_frontier_holds — boundary control via direct infer over a hand-built childless Conj. Flip census (pre- and post-change, zero unexpected flips): translate_underived_refusal 14/14, infer_self_grounding_wall 12/12, branch_infer_if_then_else 2/2, compile_eval_thesis_proof 6/6, ingest_bridge 9/9, cross_language_add_python_to_typescript 4/4, inhabitant_neutralization 6/6 + e2e 6/6, emit_host_classical_not 14/14, dag_binding_denotation 2/2, stage-verdicts instrument 2/2, dag_add_emit_round_trip 4/6 (the 2 enrolled reds unchanged), door production group still enrolled-red (unchanged). Co-authored-by: Brian Searls <briansrls@users.noreply.github.com> * Ground canonical-operation and grammar-production atoms by authority roster membership Two more specimen-scope derivations in infer_node_facts, both lookups into declared authorities, never inventions: - Canonical-operations roster (target_model.dag): every CanonicalOperation the target-model authority declares, rendered by target_model_canonical_operation_wire_node and gathered under one Conj root. The resolver canonicalizes surface operators (e.g. +) to those declared operations, so the wire atoms -- the operation discriminant and its field references -- derive by membership with the roster root as evidence. General over all 14 declared operations, not add-narrow. - Grammar-productions roster (dag.dag): every production in dag_grammar_root() projected to its emitted surface atom under one Conj root keyed by production name. The bridge projects a production's parse into (identity atom, captured content) pairs, so the identity atom (dag_surface_module) derives by membership with the roster root as evidence. The roster derives from the grammar root, so a production added to the grammar joins by construction. Both roster roots are Conj nodes, never structurally equal to any member atom, so the self-evidence wall holds by construction (the first attempt at the operations rule used the wire node itself as evidence and was refused by grounding_evidence_is_source -- the wall doing its work). Measured on the direct-rust-door specimen (scratch probe, uncommitted): 6 underived of 15 -> 2 (only the operand atoms x and y remain; the grammar-projection root conj cascades once the module atom grounds). Enrolled witnesses (infer_atom_grounding_rules_test.dag): each roster rule pins derivation + evidence identity + census; a boundary control pins that a bare atom with no authority membership stays frontier; the closing control pins the 2-of-15 state. Flip census: the product-introduction census witness updates 3->4 derived conjs (the top conj now cascades) and gains a hand-built partially-evidenced boundary control to replace the in-specimen one the cascade consumed. Full battery otherwise unchanged: refusal suite 14/14, grounding wall 12/12, instrument 2/2, binding-denotation 2/2, round-trips, bridge, cross-language, neutralization, emit-host all green; enrolled reds unchanged. Co-authored-by: Brian Searls <briansrls@users.noreply.github.com> * Ground binding-reference atoms from the enclosing arrow's domain declaration The fifth specimen-scope derivation, closing the direct-rust-door specimen's inference frontier: an Atom whose binding an enclosing arrow's domain declares derives with the declared domain type as its evidence -- the declaration-site annotation, itself derived (x: Int grounds the x reference). This is the same lookup the branch-operand path already performs (infer_find_arrow_domain_type_in_tree), now written to the operand atom's own facts; it is scope-naive (whole-tree, first match), recorded in the frontier note, and deletes with the other specimen-scope rules when the resolver hands infer declaration-resolved identities. The tree is threaded through the fold's init chain to reach infer_node_facts; the helper had exactly one caller. Measured on the door specimen (scratch probe, uncommitted): 2 underived of 15 -> 0. The specimen's inference frontier is fully closed, and the production observation advances from InferenceRejected (infer_grounding_not_derived) to EmissionRejected (target_use_site_ownership_lookup_miss) -- a new, typed, located deficit in the emitter, the next gate on the path. Flip census (all three rewrites verified by execution): - dag_binding_denotation_leaves_unbound_operand_atoms_on_the_frontier_holds -> dag_binding_denotation_declares_no_denotation_for_operand_bindings_holds: the boundary moves to the authority itself (the denotation table returns Absent for x/y), true regardless of infer's other rules. - The three emit_host classical-not refusal guards (canonical, staging, staging-swapped) flip to acceptance witnesses pinning the emitted text's shape -- the real-infer tree now fully derives, and the emission is the same one the equals-eval witness proves behaviorally correct. The translate-refuses-underived behavior stays enrolled on hand-staged fixtures in translate_underived_refusal_test.dag (14/14 green). The renames are carried into the commit_workflow and witness_deferral_freeze rosters. - New witnesses: binding_reference_derives_parameter_atoms_holds (evidence is the domain's Int binding atom, census 2) and door_specimen_fully_derives_holds (0 frontier of 15). Full battery at this state: refusal suite 14/14, grounding wall 12/12, instrument 2/2, binding-denotation 2/2, product-introduction 4/4, atom-rules 5/5, emit_host 14/14, round-trips 4/6 (2 enrolled reds unchanged), bridge 9/9, cross-language 4/4, neutralization 6/6 + e2e 6/6, branch 2/2, eval-thesis 6/6; door production group still enrolled-red (unchanged). Co-authored-by: Brian Searls <briansrls@users.noreply.github.com> * Green the direct-rust-door: route emission through produced-decl composition and decode canonical operator wires The door specimen's inference frontier is fully closed, so its production observation now reaches the emission stage. Two defects surfaced there, both fixed here: Emission composition. generate_rust_emission_candidate served two lanes with one root shape: the door's production path (a dag module shell) and a fixture lane (a bare rust Arrow). The translate ownership gate queried the module atom's ownership at a struct-field use site and refused with target_use_site_ownership_lookup_miss, because the module's grammar-projection conj was misread as a type record. The door's real composition is the produced-decl path: collect declaration conjuncts from the inferred tree and emit via emit_produced_decl. A new generate_rust_module_emission_candidate does exactly that, enforcing an exactly-one-declaration admission policy (rust_module_emission_decl_absent / _ambiguous). The observation and production mint paths switch to it; the fixture-lane candidate is retained with a note that it is fixture-only. A pure collector, produced_decl_conjs_in_tree, finds nodes of produced-decl shape (a Conj whose first child is a Named edge to an Arrow). Its decl-head match routes through a declared FreeMonoid<Edge> parameter because the v1 seed stamps pattern variables from a declared parameter type, not from a field-access scrutinee. Operator decode. With composition fixed, source fidelity still refused: the door emitted fn add(x: i32, y: i32) -> i32 { AlgebraPrimitive(x, y) } instead of { x + y }. Resolution canonicalizes a surface operator atom into a canonical-operation wire node, so a production tree's transform operator position carries the wire, while fixture trees that bypass resolution still carry the surface token atom. translate_project_transform_in_arrow_scope only knew the surface-token table, so the wire missed and fell to callable apply, rendering the discriminant identity. The projection now tries the wire decode first (canonical_operation_from_wire_node) and only on a wire miss falls to the surface-token table, then to callable apply; the arms are disjoint, so the dispatch adds no fallback widening. target_transform_operator_child extracts the operator child safely. The door's closing expectation now greens by execution, so its known_red_probe row in explicit_witness_admission is deleted per its own dissolution condition, and the roadmap authority note, the door contract note, and the direct-path plan are updated to record the green state. realized_closure_for_v2_direct_ rust_door_emit_run's module list reflects the produced-decl route. Verified by execution: the door witness greens; the fixture, containment, algebra, produced-decl, add-slice, and classical-not witnesses stay green; claim_executor required-ci lanes build and witnesses both exit 0; cargo fmt and clippy --all-targets -D warnings are clean. One pre-existing red, witness_projection_is_active_only in the floor_cost_debt containment roster, reproduces on the base revision and is unrelated to this change. Co-authored-by: Brian Searls <briansrls@users.noreply.github.com> * Close the parse-product grounding frontier: widen declared-inhabitant membership to the closed ingest set The declared-inhabitant roster-membership derivation in 04_infer generalized from the dag roster to the closed ingest set (dag, python, typescript): infer_node_declared_in_language_inhabitants returns the declaring authority's roster root as evidence, with deep subtree membership so a declared inhabitant's leaf fact atoms derive exactly as the inhabitant node itself. Measured: the python fixture's 19-node frontier and the typescript fixture's 28-node frontier both close to zero; all four add-slice stall population round-trip witnesses green; the python->typescript cross-language compile accepts, byte-identical to ts_source_text. Section 4b(4) flips (expecting-red probes becoming permanent regression controls for the acceptances): - cross_language_compile_refuses_canonical_underived_holds -> cross_language_compile_python_to_typescript_round_trip_holds - inhabitant_neutralization_emit_after_neutralize / same_flavor_python / go_int64_to_ts refusal helpers -> round-trip controls - inhabitant_neutralization_python_to_ts_cross_language_compile (e2e) -> round-trip control; python->go members stay refusal guards (go is outside the closed ingest set) - cross_language_emit_inhabitant_neutralization_refuses_underived_holds -> round-trip control; the python->typescript emit-matrix row reads ChainProven The add-slice stall's next-rung trigger fired, so it retired per DESIGN 4b(4): removed from all_guarantee_stalls, row file deleted, witnesses stay enrolled. Co-authored-by: Brian Searls <briansrls@users.noreply.github.com> * Promote the add family to SelfEmittedNative: native-only verdict witness for the emitted add crate First InterpreterRetained -> SelfEmittedNative promotion after classical_not, executing the v2-emitter-first-behavioral-module first slice at the coverage-frontier grain: the add family (fewest dependencies — integer literals plus one canonical operation) now carries a native-only verdict witness, so its behavior is established by the emitted crate's own stdout with eval() unreachable from the verdict path. - emit_host_native_only_add_holds: real emit -> cargo build -> native run, stdout pinned to the family's expected octet, sharing the kernel family's one-build cache key exactly as the classical_not arm shares its family's key (no duplicated cold build). - emit_host_native_only_add_wrong_octet_mismatch_detected_holds: the broken control — a no-eval verdict has no oracle leg to break, so the expectation side breaks (an octet the run never produces must not match); program-side discrimination stays with the family's equals_eval primitive-five/six pair. - The add coverage row flips disposition with its backing citation enrolled by construction (the verdict entry is file-grain enrolled in falsifier_self_host_wet_template_entries). - Frontier census tests updated at identity grain: natives are exactly {classical_not, add}; split 2/13. Verified by execution: all six native-only verdict tests green locally (real wet legs — compile_skipped receipts show cold builds and native runs); all eight emit_coverage_frontier tests green, including the unbacked-claim RED control. Co-authored-by: Brian Searls <briansrls@users.noreply.github.com> * Record the add-slice defect's repair in the declined-live-tree classification The row classified candidate_generation_translate_self_emit_dag_add_slice_holds as RealDefect/CompilerBehaviourRefusal with measured evidence that translate refuses infer_grounding_not_derived. The owner lane (v2 self-host) repaired the subject: the declared-inhabitant roster-membership derivation grounds the slice's type spine by lookup, and the witness passes under claim_batch --hermetic on the merged tree. The dated classification is kept verbatim; the disposition flips RoutedToOwner -> RepairedInThisChange with the repair measurement appended to the evidence, so the routing carrier stops dispatching a fixed defect. Structural witnesses (count 13, no NotReproduced, exact partition) are untouched and pass. * Hoist two in-body annotation blocks to module-item grain Main's annotation-placement wall (source annotations admit only standalone leading blocks attached to module-scope declarations; in-body forms refuse) reached this branch through the merge and refused 8 blocking errors on the 00_compile closure: the add-family promotion note inside the emit_coverage_frontier_roster list and the python->typescript row note inside the cross_language_emit_matrix list. Both blocks move above their enclosing declarations, rephrased to name their subject row. Measured: gunbc compile of src/v2/compiler/00_compile.dag now emits 172 files with 0 blocking errors; both files' suites stay green (8/8 and 4/4). * Promote the complement family to SelfEmittedNative: native-only verdict witness for the emitted logic family crate The complement family's native execution runs family-grain per the witness_family_build_grain_ruling (one crate for meet + join + complement, argv-dispatched), so the native-only arm emits the logic family crate and runs the complement member through the family dispatcher, sharing the family witness's one-build cache key. The verdict is decided solely by the emitted native run's stdout (expected octet 0, complement(True) = False); the broken control flips the expectation side (octet 1 can never match), with the comparator pinned by the stdout mock pair. Program-side discrimination stays with the equals_eval agreement pair and the family witness's all-alt leg. The frontier row's backing citation lands in the already file-grain-enrolled native-only verdict entry, so it is enrolled by construction; the roster comment is rephrased to cover both 2026-09-07 promotions (add and complement). The frontier test's split and native membership assertions move to 3 native / 12 retained. Verified by execution: claim_batch --hermetic on emit_host_native_only_verdict_test.dag passes all 8 witnesses (the two new complement arms included), and emit_coverage_frontier_test.dag passes all 8. * Key the emitter's host-String arm on declaration provenance, not spelling is_host_text_carrier_type answered true for any type expression whose authored name reads "String", including references to the structural alias v2.std.text.String (type String = FreeMonoid<Char>) that the namespace lane (gunbc#9907) requalified the v2 corpus's text-carrier fields to. The emitter rendered every one of those references as the host String while value-position consumers rendered the structure -- the E0308 family dominating the self-host compile-phase frontier (41 of 64 in v2_compiler_tokenize.rs on the post-merge board). The String arm now consults the resolved declaration's provenance against v1.compiler.coercion structural_declaration_modules_for -- the same roster type_realization_decision reads -- so the legacy arm and the strict decision cannot diverge on one node (DESIGN section 3, and gunbc.recurring_failure_mode alias_resolution_collides_with_kernel_spelling). Kernel mints and unresolved references keep the host answer exactly as before. Regen: the only drifted stage0 mirror is v1_compiler_emit_rust.rs itself (no module in the stage0 closure references a structurally declared String -- verified by the whole-population candidate tree), installed from target/stage0-regen-candidate after the priced round's partitioned rebuild refused MirrorHasNoOwningPackage on the emitter (the emitter is monolith-shell, not partition-owned). Fixed point verified by execution: claim_executor --required-regen on the rebuilt seed reports first_generation_equal=true over 158 adjudicated mirrors. * Peel qualified String alias leaves in field position: XL-N closure 72 -> 28 errors A field authored v2.std.text.String reached the Rust emitter as an overlay-less resolved reference leaf and rendered the bare terminal name, which binds the prelude String cross-module (#9813: kernel names are never overridden by imports, so the use-line is dropped) while every value position renders the structural carrier Rc<Vec<i64>> -- the v2_compiler_tokenize.rs E0308 family, 41 of 72 errors on the XL-N phase board. The new rust_overlayless_alias_leaf_requires_peel arm in render_rust_type_without_applied_binding detects the population (overlay-less zero-parameter alias leaf, qualified spelling, String terminal segment, closed_alias_peel_verdict agrees) and renders the alias declaration's resolved right-hand side, projecting the same realization the fn-signature positions already produce. The qualified gate is load-bearing: inside the declaring module the bare name is the correct render (the emitted module carries the alias declaration), and the local binding's resolved_type drops the RHS type argument, so an ungated peel rendered Rc<FreeMonoid> there (E0107 x13, E0282 x2 on the probe). Bare String keeps denoting the kernel scalar through the host-carrier arm. Measured: probe specimen (qualified/bare/direct-FreeMonoid/container/variant/ local-alias positions) compiles clean; XL-N compiler closure cargo check 72 -> 28 errors with the residual census dominated by the declared text_boundary_identity_wall class (kernel String vs structural carrier at bare-authored boundaries, 17 of 20 E0308s); v1-corpus fixed point holds (first_generation_equal=true, 158/158 adjudicated). * Resolve the 12 non-hop XL-N closure errors at source: text-wall conversions + witness_violates helper Four clusters, all measured non-hop additions between receipt_1 (155) and the post-peel census (28); the live gate now measures 15 with zero unadmitted regressions: - integer.dag: integer_string_to_decimal_digits_step takes v2.std.text.String; the public boundary converts with chars() (text_boundary_identity_wall specimen discharged at this site). - 01_tokenize.dag: Token/UnboundSourceAnnotation lexemes convert structural -> host String with chars_to_string() at construction, mirroring the v1 tokenizer's host-lexeme carrier. - target_model.dag + bash.dag: EmitSpellingEscape.from/to and apply_emit_spelling_escapes go structural (v2.std.text.String); the EmitSpellingQuote arm converts host->structural->host at its boundary; bash's escape rows wrap their kernel String literals with chars(). - witness.dag + 3 call sites (collection list_nth, provenance span_index_resolve_textual_locus_from_ids, compile outcome_with_diagnostics): new witness_violates<C> helper puts Violates constructions in a Witness-headed position so the emitter resolves the carrier type argument; dissolves once inference records per-call substitutions. Verified: 48 targeted claim witnesses green (tokenize behavioral, shell conformance, string brace escape, string length, map-lookup violates, source text ingress, bash materialize x12, int literal smoke x6, provenance span index x2). * Record receipt_2 on the self-host compile-phase frontier: 15-error census at 66765317ec The census at the XL-N lane tip: 155 -> 15 net, credited to the qualified-alias peel (60cbd7b697, 72 -> 28) and the twelve-error source cluster (66765317ec, 28 -> 15). The epoch changes on the instrument's target pinning (found by review on gunbc#9857), admitted with receipt_1's board as the reclassified predecessor under the identity map. Nine added identities are hop relocations admitted by the hop index; four sit in python/typescript modules newly entered into the emitted closure, admitted as ExposedByNewEmittedModule. Validated: all 36 self_host_compile_phase_frontier_witness claims PASS, including current_persisted_compile_phase_frontier_holds. * Emitter: a substituted declaration node carries its own provenance Inference substitutes the resolved declaration into a data annotation's type-argument position, so BooleanAlgebra<v2.std.logic.Bool> reaches the emitter with the arg BEING the type Bool = True | False declaration itself (Disj connective, ident_span in src/v2/std/logic.dag, no Resolved wrapper). type_reference_provenance_in_env's bare-leaf arm re-resolved that leaf in the REFERENCING module's scope, where post-#9813 a kernel-shadowed spelling answers the kernel declaration -- so the structural enum rendered as host bool against a value of BooleanAlgebra<Bool> (the python.rs:328 / typescript.rs:177 E0308 pair on the XL-N compile-phase frontier). The connective is the discriminator: a reference node is a bare name (NoConnective); a node carrying Conj/Disj structure IS the declaration, and type_reference_provenance's own-span fallback already answers that shape correctly. The guard routes declaration-shaped nodes there directly, bypassing the scope lookup that #9813 makes answer the kernel. Mirror regenerated via the regen round; fixed-point verified (claim_executor --required-regen PASS). * Clear the remaining XL-N closure errors at source: carrier conversions at the boundaries The receipt_2 census's fifteen identities, resolved at their sources: - lexing.dag, dag.dag, python.dag, typescript.dag: LexPattern.text is the structural carrier (v2.std.text.String); the construction sites held host Strings. Convert at construction with chars() -- the #9907 ingress pattern. - python.dag / typescript.dag bool groundings: qualify the annotation as BooleanAlgebra<v2.std.logic.Bool>; with the emitter's substituted- declaration provenance guard the qualified arg now renders structural. - target_model.dag: target_lex_rule_literal_step returns the host carrier (chars_to_string over the structural pattern text); TargetText.source converts at the is_empty boundary; the unicode-scalar symbol intern converts its single-codepoint list to the host carrier. - qualified_name.dag: qualified_name_from_dotted_string uses the host-carrier emptiness check (string_length == 0) instead of routing through the structural string_is_empty. - 02_parse.dag: parse_looks_like_match_arm_start rewritten on host-carrier operations (string_length, char_at, code_point) rather than converting to the structural carrier for a two-character lookahead; parse_char_is_arm_pattern_lead takes the codepoint Int directly. - v1_interpreter_primitive_surface.dag row_key: the concat pipeline lowered to a .concat() method call on std::string::String (E0599); rewritten as nested concat calls. Measured: the 00_compile closure emits 172 files and cargo check reports cargo_clean=true, cargo_error_population=0 under the pinned 1.93.0 toolchain. * Pin the cargo half's toolchain channel by construction The cargo half runs with cwd = a fresh mktemp directory; with no rust-toolchain.toml there, rustup resolves the host's DEFAULT toolchain, so a census under cargo 1.83 and one under cargo 1.93 would compare as equal epochs while different compilers did the measuring -- the fabricated comparability the target pin (gunbc#9857) excludes, one level up. Measured 2026-09-07: a host default of 1.83.0 met a crates.io index whose freshly published dependency manifests require edition2024, resolution failed before any diagnostic existed, and the zero-diagnostic refusal fired on an unmeasured tree. The pin is propagated by copying the repo's rust-toolchain.toml into out_dir: the file remains the sole in-repo channel authority (its header forbids a second pinned literal), and the copy makes the measured channel true by construction on any host. The gate's read_live_toolchain observes the same channel because every documented actuator invokes from the repository root, which the same file governs. * Record receipt_3 on the self-host compile-phase frontier: the emitted closure's cargo census is empty Measured at 5ee4892b70 by the one-entry instrument: the 172-file emitted crate reports zero cargo error diagnostics, so the board attributes every phase a count of zero and furthest_phase_reached stands at Borrowck. The fifteen removals against receipt_2 need no disposition; nothing was added. The epoch does not change: the cargo half now pins the toolchain channel by copying the repo's rust-toolchain.toml into the scratch crate, and every recorded comparison field is identical to receipt_2 (whose census the fingerprint evidence shows the same 1.93.0 toolchain already compiled), so the same-epoch arm carries no reclassified predecessor. The frontier-state pin flips per DESIGN 4b(4): the_published_frontier_standing_does_not_claim_typeck_or_borrowck_passed becomes the_published_frontier_standing_claims_typeck_and_borrowck_passed, the permanent regression control over the green state. Validated: all 36 self_host_compile_phase_frontier_witness claims PASS, including current_persisted_compile_phase_frontier_holds. * chore: regenerate drifted generated artifacts (ci auto-heal) Ledger-Repair-Judged: docs/design-failure-modes.md Ledger-Repair-Judged: docs/design-rung-drops.md * Remove the stale PointwisePower inhabitant rows from the four language rosters First native-parity divergence class found by running the emitted closure on a discriminating fixture: the algebra inhabitant rosters still carried PointwisePower after its authority row was cut, so the emitted compiler panicked at 12 record-shaped carrier sites while the interpreted seed refused cleanly. The roster rows are removed in rust/python/go/typescript types.dag, the derived coercion assertions in compiler_tests.rs regenerate without them, and two witnesses pin the boundary: the record shape constructs its structural carrier, and FinitePowerSet still refuses while its row stands. Mirrors regenerated by a converged regen round (fixed point Reached, stage-1 PromoteGenerationInputs over the three language types mirrors). * Regen gen-2 gate: compare executable digests in one spelling The admitted side of run_built_seed_regen carries the executable-digest spelling (current_exe_digest, next_pass_executable_digest) while the observed side hashed the file through path_digest, which prepends the fnv1a64: tag. Same bytes, two spellings, so the gate could never pass -- unpassable since fa2d403dc8 (#9771). Factor current_exe_on_disk as the single path authority and read the observed digest through current_exe_digest so both sides spell the same bytes the same way. * Model ReleaseScopeEmpty for release-excluded mirrors, end to end A regen round whose only stage-2 drift was compiler_tests.rs (the PointwisePower roster removal rewrote its derived coercion assertions) refused the rebuild MirrorHasNoOwningPackage: the mirror is owned by no partition package, because every item it defines is #[cfg(test)] and no release unit elaborates it. The refusal conflated two different states -- unowned (a coverage hole) and excluded from the release build by construction (a precise empty scope). The model now names the class: rebuild_scope_release_excluded_mirrors rosters its members (compiler_tests.rs, cited to emit_compiler_tests_module), the decision answers ReleaseScopeEmpty when the whole change set is excluded, and the actuation shape is actuatable with an empty package closure and every partition package excluded -- the build still runs as verification, and a compiled partition package refuses the stage. The host admits the empty closure only when the new stage0_partition_rebuild_release_scope_empty_today query answers true; any other empty closure still refuses. A mixed change set scopes on its release-visible members alone. Verified by execution: the 2026-09-08 round converged (fixed point Reached) with stage-2 installing compiler_tests.rs alone; cargo recompiled the shell crate on its fingerprint (the outer mod line is ungated, so rustc reads the file) while the produced executable was byte-identical -- stage input seed digest == output seed digest. Four new witnesses pin the arm, its actuation shape, the mixed set, and the host-facing query's two arms; the boundary witness (unowned cli_run.rs still refuses) keeps the roster from decaying into the absorbing fallback. * Round-cost receipt: project installed mirrors to the model's vocabulary The receipt's partition-rebuild line is rendered by the model over receipt.installed_mirrors, which the host populated from the stages' projected_paths -- full paths -- while the partition rows and rosters key on basenames. Every drifted round's receipt therefore rendered a spurious RebuildScopeRefused MirrorHasNoOwningPackage line naming a full path, a false claim on the round's own receipt. Route the projection through emit_path_basename, the module's single path-to-basename bridge, so the field carries the mirror names the model's vocabulary means. * Hoist ReleaseScopeEmpty annotations to module-item grain The ReleaseScopeEmpty modeling commit placed three // blocks inside declaration bodies (stage0_partition_rebuild_is_actuatable, stage0_partition_rebuild_decision, stage0_partition_rebuild_excluded_today). The .dag realization admits annotations at module-item grain only, so the floor lane's parse phase refused the file with 12 located errors and the run ended floor refused. The prose is unchanged; each block now sits above the declaration it describes. * Spell the PointwisePower witness's finite-set exclusion as the applied realization The witness added with the fossil-row removal excluded the bare spelling "BTreeSet", but every emitted file's preamble imports OrdSet as BTreeSet, so the row could never green. The exclusion's subject is the finite-set REALIZATION the fossil row would have asserted; spell it applied (BTreeSet<i64), which the preamble's import line does not contain. * Emit fieldless-record data values as null for the unit-struct carrier The second native-parity divergence class, measured 2026-09-08 on the native run of the emitted 00_compile closure: emit_data_value_json spelled EVERY record literal as a JSON map, including the zero-field record, while emit_struct_from_children renders that same declaration as a Rust unit struct (pub struct BoolEncodingFact;). serde's derived unit-struct Deserialize reads null and rejects {}, so the emitted compiler panicked at first touch of v2.std.logic's bool_primitive_facts: "invalid type: map, expected unit struct BoolEncodingFact". The JSON spelling of a data value must deserialize into the Rust type the same declaration emitted; the record arm now spells the zero-field value null and keeps the map spelling for non-empty records. The mirror is taken from the required-regen candidate, not hand-edited. Two witnesses enroll: the discriminating red (zero-field record spells null, never {}) and the boundary control (a record with fields keeps the map spelling). * Bind the duplicate-definition filter ahead of its branch condition Main's FilterInBranchCondition wall (#10699) refuses to publish a module whose filter call sits in a branch condition, and the v2 00_compile closure emission names primitive_duplicate_semantic_definition_violation as such a site. The filter is pure and total; binding it with a let ahead of the branch is the authored remediation the wall exists to force, and the emitted closure is unchanged in behavior. * chore: regenerate drifted generated artifacts (ci auto-heal) Ledger-Repair-Judged: docs/design-rung-drops.md Ledger-Rows-Repaired: docs/design-rung-drops.md rust_unit_tests_off_the_merge_path Ledger-Rows-Repaired: docs/design-rung-drops.md determinism_transitive_reachability Ledger-Rows-Repaired: docs/design-rung-drops.md transitional_admission_exception * Emitter: three native-parity repairs for the post-merge 00_compile closure build Three divergence classes measured as the 21 rustc errors on the natively emitted 00_compile closure after the main merge, each repaired at the .dag source with a discriminating witness: - Locality wins over a foreign ambiguity (12 E0433 in v2_std_integer.rs): alias_rhs_base_module_filename asked the global leaf index, saw LeafAmbiguous for Compose, and emitted the poison marker even inside v2.std.integer itself, where source resolution binds the local declaration before any cross-module lookup. The local physical declaration now shadows foreign declarers; the poison marker still stands for a leaf two FOREIGN modules declare. - The qualifier is the disambiguator (8 E0425/E0433 in v2_lens_fact_density.rs): the qualified use-line route declined any globally-ambiguous leaf, but a qualified reference names its provider in its own spelling. The route now resolves by DeclaredCallableIdentity at the qualifier, keeping the type-declared and export-proof walls. The dotted spelling reaches the route through the value surface (a qualified value projection's borrowed type stamps the match patterns' parent_enum); the witness reproduces that chain exactly, and its exclude half pins the E0603 boundary (the dotted VARIANT head must still be declined). - Clone-bound forwarding is transitive (1 E0277 in std_realization_measurement.rs): the call-forwarding derivation re-derived only each callee's SELF-derived half, so a callee whose bound is itself forwarded re-derived to empty. The derivation now recurses over the call graph with the module's visited-set termination; the equality half stays one-hop as declared. Witnesses: 56/56 PASS on the rebuilt seed; regen fixed point holds. * Refuse variant record literals on the serde_json data path fail-closed A record literal with parent_enum present is a variant construction whose wire spelling is the parent coproduct's declared VariantEncoding policy -- a module-local fact of the parent's home module that emit_data_value_json does not carry. The zero-field arm's null and the map arm's untagged fields are both measured to fail serde deserialization under the internal-tag default, so the arm now refuses and the caller renders compile_error!, a build-time located refusal where a runtime panic on the data definition's expect was the latent alternative. The refusal names its trigger: a closure-wide wire-policy index beside EmitGraphInfo.type_decl_items. Witness: w_variant_record_lit_on_the_json_data_path_refuses_fail_closed forces the JSON path with a nested-record Holder and asserts the compile_error! spelling while excluding the former null mis-serialization. * Spell variant record literals on the serde_json data path from a closure-wide wire-policy index The fail-closed refusal landed in 73b582dea6 fired on 5 real corpus sites (SugarKey x2, CopiedPortCitationFrontierDisposition x3), proving variant record literals reach the JSON data path in the 00_compile closure. This change replaces the refusal with the correct spelling, driven by a new closure-wide index: - v1.compiler.infer_emit_info gains DataVariantWireSpelling, the language-general projection of a coproduct's Rust wire serde policy for one variant (InternalTagged { tag_field, tag } | BareString { tag } | Untagged | SpellingRefused { reason }), and EmitGraphInfo carries data_variant_wire_spellings: Map<String, DataVariantWireSpelling> keyed by coproduct.variant. - v1.compiler.emit_rust builds the index once per emission root via build_data_variant_wire_spellings, resolving each coproduct's policy through the new shared resolve_emission_coproduct_wire_policy (the same function the type-emission side now calls, so the two cannot drift), projecting each variant through data_path_wire_variant_tag (rename_all and StripAffix aware), and poisoning collisions as SpellingRefused so ambiguity stays fail-closed. - v1.compiler.emit's emit_data_value_json variant arm reads the index: internal-tagged spells {"_variant": tag, ...fields}, bare-string spells "tag" for nullary and refuses fielded, untagged spells the bare fields or null; unindexed keys and stored refusals remain compile-time errors. The service mock-property chain threads emit_info through so dry-run data spells identically. Witnesses: w_variant_record_lit_on_the_json_data_path_refuses_fail_closed is rewritten as ..._spells_the_internal_tag (asserts the internal-tag map, excludes the former null mis-serialization and the refusal), and w_fielded_variant_record_lit_on_the_json_data_path_spells_tag_and_fields pins the fielded case. 57/57 witnesses pass; regen fixed-point holds. * Promote field_access to SelfEmittedNative on the emit coverage frontier Fourth native-eval construct promotion, after classical_not, add, and complement. The native-only verdict arm pair lands in the already file-grain-enrolled long/ entry, so the backing citation is enrolled by construction: - emit_host_native_only_field_access_holds pins the family one-build cache run's stdout to octet 9 (the byte the family witness's warm leg pins on the same build), eval() never called. - emit_host_native_only_field_access_wrong_octet_mismatch_detected_holds breaks the expectation side with octet 1, the alt tree's byte. Both arms verified wet locally (real cargo build + native run, sharing the field_access family one-build cache key). The roster row flips to SelfEmittedNative; the two census guards update per 4b(4) — the split moves to 4 native / 11 retained and the identity-grain membership guard is renamed to name the four-member population. The family's equals_eval agreement pair stays enrolled as its program-side discrimination leg. * Drop the scratch parity probe from the tree The probe is a manual parity-loop instrument (the interpreted leg of the native-vs-interpreted comparison), not a corpus declaration with an executing consumer (DESIGN 6 experimental residue). It stays in use locally as an untracked file. * Promote match, loop, and fold_closure to SelfEmittedNative Fifth, sixth, and seventh native-eval construct promotions. The three match_loop_fold family rows flip together on one shared family-crate arm shape, per the witness_family_build_grain_ruling: each arm emits the three-member family crate once and runs its own member through the argv dispatcher against the family one-build cache key. - emit_host_native_only_{match,loop,fold_closure}_holds pin the warm legs' stdout to the family's declared octet lists (match/loop [0,1,0,0,0], fold [0,7,0,0,0]), eval() never called. - The wrong-octet controls break the expectation side with each member's own alt octets (match/loop [0,2,0,0,0], fold [0,255,255,255,255]). All six arms verified wet locally. The census guards update per 4b(4): 7 native / 8 retained, and the identity-grain membership guard is renamed to witness_native_rows_closed_membership_holds so the name stops encoding the volatile population. * Promote meet_join to SelfEmittedNative on the emit coverage frontier The meet_join family's native-only verdict arms land on the complement arm's helper, generalized to take the family member_id: meet and join run through the same argv-dispatched logic family crate (one-build cache key shared with complement, per the witness_family_build_grain_ruling), eval() never called, verdict decoded from stdout. Octets meet=1 join=1 are the bytes the family witness's warm legs pin on this same build; the wrong-octet control expects each member's alt byte (0), which the primary runs can never produce. Both arms verified wet: cold build then warm hits, PASS/PASS. The roster row flips InterpreterRetained -> SelfEmittedNative (eighth promotion); census guards move to 8 native / 7 retained with meet_join_eval_subject named in the closed membership. * Promote variant_construct to SelfEmittedNative on the emit coverage frontier The variant_construct family's native-only verdict arms follow the field_access arm shape exactly: the tree is the family's own equals_eval tree value (emit_variant_construct_eval_tree, no eval leg reachable), the run shares the family one-build cache key that emit_on_demand_variant_construct_native_one_build_holds colds, and the expected octet 9 is the byte the family witness's warm leg pins on this same build. The wrong-octet control expects the alt tree's byte (1), which the primary run can never produce; the wrong-value alt leg in the family witness keeps the program-side discrimination. Both arms verified wet: cold build then warm hit, PASS/PASS. The roster row flips InterpreterRetained -> SelfEmittedNative (ninth promotion); census guards move to 9 native / 6 retained with emit_variant_construct_eval_subgraph_node named in the closed membership. * Close the emit coverage frontier: final six rows to SelfEmittedNative The last six InterpreterRetained rows flip to SelfEmittedNative, taking the roster to 15 native / 0 retained: - filesystem_read and shell_exec_run (host-effect transport families, no translated arrow body): the arms reuse each family's own native leg with the expectation pinned as a literal grounded by the family's enrolled fixture pin (dag/extdeps/shell/exec.dag contains bash; its shell.Exec.Run argv materializes to exactly [bash, -s]), run through the families' fixed witness workspaces. - module and produced_module: the arms execute the exact sources the equals_eval pairs run (emit_module over the add fixture tree; produced_add_module_source's ingested two-fn module), octet 5 pinned against the add family's primitive-five/six oracle leg. - call and record_construct: the arms emit the families' own producer trees against their target models, octets 7 and 9 pinned against the primitive-seven/eight and wrong-field oracle legs. The four families without a one-build cache witness run under per-family fixed workspace roots; content-safety comes from the realization-digest nesting in run_host_process_admitted (changed source colds, never serves stale), the same mechanism the filesystem_read fixed workspace relies on. All twelve arms verified wet: PASS/PASS each, cold builds then warm hits. With zero retained rows the retained_via_eval_agreement constructor loses its last consumer and is deleted (DESIGN 3c); the InterpreterRetained variant stays as the disposition authority's other state. Census guards move to 15 native / 0 retained with all fifteen decl names in the closed membership. * Record the emit coverage frontier closure in the direct-path plan Axis C line: all fifteen roster rows are SelfEmittedNative as of 2026-09-08, interpreter_retained_rows() is empty, and the row constructor was deleted with the last flip. Notes explicitly that this closes axis (a) (witness-body-runs-native) only; axis (b) (the regen-grain production flip) remains operator-gated. * Model the required-v2-native lane authority: route receipt, exclusion taxonomy, admission, enrolment gate Parallel track B (operator authorization 2026-09-09): one additional required CI job whose subject is the compiler/test execution route itself — the emitted-native compiler binary invoked by explicit path over a derived v2.test.* population. The lane is modelled in full in gunbc.witness_v2_native_route: the prefix universe derivation, the per-member verdict rows (head + fatal reason grain), the exclusion taxonomy delegating attribution to the door ledger's known_frontier_causes, the counted exclusion census with a totality check, the terminal-observation receipt carrier, the admission predicate (one predicate per contract clause, all causes collected), and the enrolment gate with today's standing as data. Enrolment is BLOCKED, as data with a named capability trigger: the measured census over the derived universe (882 members, seed withdrawn during the run) refused every member — the emitted DirectIngestDriver admits only the hard-coded compile_driver_subject name with empty imports, and the compile door is at its modelled frontier — so the contracted positive population is empty and native_route_admission over the real receipt executed to 'refused: positive_population_empty'. The exact enrolment edit (phase-roster variants, claim_executor mirror, workflow lane, aggregate join, YAML regen) is carried on the standing row. The census measured five fatal-grain refusal causes the door ledger's head-grain attribution table did not carry; they are added to known_frontier_causes with their owning lanes (three MigrationOwned under nimble-boar-198, two normalize/body-lowering SharedSelfHostCriticalPath). Seventeen floor witnesses (v2.test.v2_native_route) consume the authority and execute green through the seed interpreter. Co-authored-by: briansrls <briansrls@gunb.ai> * Split preparation predicates so EmittedClosureUnrecorded is reachable Review on #10882 (briansrls, point 7): native_route_preparation_recorded folded the seed and closure observations into one && predicate, so a receipt with a recorded seed and an unrecorded closure misreported as preparation_seed_unrecorded and the emitted_closure_unrecorded cause had no reachable construction — the grain-mismatch class DESIGN 4b(3) names. One predicate per observation, one admission clause per predicate, and two witnesses pinning each refusal name against its own receipt shape (including the negative: each refuses ONLY by its own name). Co-authored-by: briansrls <briansrls@gunb.ai> * Key cause ownership by diagnostic grain; classify native refusals at fatal grain The door ledger's known_frontier_causes was a head-grain authority; the native route classified fatal reasons through it, crossing grains (review on #10882). Generalize the ownership key with DiagnosticGrain so one table answers both grains: the door ledger's cause_is_attributed keeps its head-grain contract, and the native route's exclusion classifier asks the fatal-grain question of the same table. The head advisory is live receipt data again: every refused row's head reason must be owned at head grain (or by this lane's driver-limit roster), and an unowned advisory blocks admission by its own clause name. Co-authored-by: briansrls <briansrls@gunb.ai> * Hoist known_frontier_causes row-group notes above the declaration The grain-keyed ownership change left its row-group commentary inside the list literal; the annotation channel admits only module-item grain, so the emitted closure refused with nine annotation-grain diagnostics. Move the notes to a single block above the declaration. No semantic change. Co-authored-by: briansrls <briansrls@gunb.ai> * Parse test fn as a contextual production in the v2 dag grammar The emitted native compiler could not parse any v2.test.* module: the modeled dag grammar had no test fn production, so every floor witness module refused with parse_g0_tokens_remain (706 of 882 in the census). test stays an ordinary identifier — typescript/program.dag models the TypeScript compiler's Cond.test field under real-upstream-names — so the production is the contextual sequence(ident, fn_decl): a new choice arm in top_level_item with no FIRST overlap with the keyword-led arms, a body-lowering arm that lifts the nested fn member after checking the marker lexeme is literally test (a typed refusal otherwise), and a forward-producer row for the new surface identity. Verified against the emitted native binary: probe_testfn.dag moves from parse_g0_tokens_remain to resolve_module_not_found (the driver's synthetic-subject limit, identical to a plain fn), and the standing choice-overlap residue roster is unchanged at seven rows. Co-authored-by: briansrls <briansrls@gunb.ai> * Add SourceRootEvalDriver: native whole-ingest test-execution route The required-v2-native lane's terminal subject is an exact test identity reaching a native Eval verdict, not a module accepted for translation. DirectIngestDriver (one source, no peers, synthetic subject) stays as the front-door census instrument; the new driver renders a main that reads a host-derived universe of qualified test identities plus the declared source roots, assembles the ingest once, prepares each module (resolve + infer), and Evals each named test body -- one typed verdict row per member, with a prepare-refusal fan-out so no member is silently dropped. Co-authored-by: briansrls <briansrls@gunb.ai> * Escape literal braces in SourceRootEvalDriver main.rs template The .dag string lexer reads '{' followed by an identifier as interpolation, so the emitted Rust use::-import lists and format! captures must spell literal braces as \{ \}. The single parse error desynced the file parse and cascaded into 2618 unattributed-annotation errors; with the escapes the emitter compiles clean (0 blocking, 107 files emitted). Co-authored-by: briansrls <briansrls@gunb.ai> * Collect per-file front-end refusals in the native test context fold The SourceRootEvalDriver's context fold reused program_assembly_fold_ingest, which is wholesale fail-closed: one source hitting the v2 front-end's live corpus frontier would deny verdict rows for every other universe member. The fold now collects each source's tokenize/parse/normalize refusal as a NativeTestFileRefusal row (head and fatal reason grains, matching the door ledger's grain-keyed ownership) and keeps folding; a refused file contributes no root, so its test identities surface as Context-stage refusal rows and nothing is widened. The emitted main.rs prints the file-refusal rows and counts them in the terminal marker, and prepare/eval refusals now classify at the fatal (last diagnostic) grain consistently. Co-authored-by: briansrls <briansrls@gunb.ai> * Add native lane control fixtures Two controls for the required-v2-native lane's host harness: src/v2/native_lane_fixture/control.dag carries the live-verdict pair (a well-formed false control and its true positive half) as plain fns outside the v2.test. prefix, so floor discovery enrolls no universe rows for them; fixtures/native_lane_malformed/poison.dag is a deliberately unterminating string that any honest front-end must refuse at tokenize, kept outside every declared source root so the broken bytes never enter an honest ingest. Co-authored-by: briansrls <briansrls@gunb.ai> * Fix Vec/Vector type mismatches in the SourceRootEvalDriver main.rs template The emitted driver crate aliases im::Vector as Vec, so the template's std Vec-typed bindings and collect calls failed to compile in the emitted crate: universe rows and module order carry Rc<Vector<String>>, the reads vector moves into the FreeMonoid parameter with .into(), and the dotted module name is built from an iterator collect. Co-authored-by: briansrls <briansrls@gunb.ai> * Harden the v2-native route contract: test-identity grain, exact join, paired reference Reframe the terminal subject from module-grain acceptance to the exact test identity reaching a native verdict. The receipt's universe is a list of qualified NativeRouteTestIdentity rows; the observed population joins it exactly (uniqueness, no foreign rows, no omissions); every member verdict is paired against the floor's own expected-red and route-gap rosters for agreement, exclusion, or divergence; refusals are classified from stage and provenance with cause ownership at fatal and head grains; and the four controls (true, false, malformed specimen, old-route withdrawal) are admission clauses. The 46 tests cover universe derivation, identity qualification, reference pairing, refusal classification, disposition, census counting, and every admission clause. Co-authored-by: briansrls <briansrls@gunb.ai> * Wire the required-v2-native lane into the roster, workflow, and aggregate Add V2NativeLane/V2NativePhase to the required-CI roster, the lane's claim_executor command to fabric_witness_run, and the required-v2-native job to the witness floor workflow with the aggregate witnesses job needing it in both verdict arms. Regenerate witnesses.yml. Co-authored-by: briansrls <briansrls@gunb.ai> * Add the required-v2-native host harness and phase dispatch The lane's one phase derives the v2.test.* universe with the floor's own discovery producer over the full module inventory, prepares the emitted-native compiler through the emit-compile phase's crate writer and cargo invocation, withdraws the old-route gunbc binary for the spawn window, runs the emitted binary by explicit path over the universe plus the named controls, reclassifies context-stage refusals against the observed file refusals, mints the NativeRouteReceipt as the authority's own types, and hands it to native_route_admission for the verdict. claim_executor gains the V2Native lane and phase with the roster sizes moved to six. Co-authored-by: briansrls <briansrls@gunb.ai> * Regenerate stage0 mirrors for the SourceRootEvalDriver emitter arm std_compiler_entry.rs gains the SourceRootEvalDriver variant and v1_compiler_emit_rust.rs the emit_source_root_eval_driver_main_rs template with its dispatch arm, emitted by the regenerated seed and verified at the fixed point (first_generation_equal=true over the whole 155-module population). Co-authored-by: briansrls <briansrls@gunb.ai> * Name the probe crate's lib target v1_compiled, the emitter's self-name contract emit_rust_selected binds the self-emitted crate's name to v1_compiled for every non-retained-host pipeline entry, and the SourceRootEvalDriver and DirectIngestDriver mains reach the closure through use v1_compiled::. The probe manifest's per-entry package name left the lib target named after the package, so a pipeline entry's driver main failed E0433 in the probe build -- unreachable while every probe entry was pipeline-free, and measured on the required-v2-native lane's first preparation. The lib path stays cargo's default; only the name is stated. Co-authored-by: briansrls <briansrls@gunb.ai> * Release retained emission arena before the native cargo build The lane's first run held ~15GiB RSS from the emission's resolved graph into the cargo build of the emitted compiler and was SIGKILLed (rc=137) with no diagnostic. Drop the emission run and malloc_trim the retained arena at both derivation-to-emission and emission-to-build handoffs, reporting the reclaimed KB so a trim that cannot release live memory shows in the lane log. Co-authored-by: briansrls <briansrls@gunb.ai> * Apply rustfmt to the v2-native lane host changes Co-authored-by: briansrls <briansrls@gunb.ai> * Lower FreeMonoid tail to im::Vector::skip — O(log n) share, not O(n) copy The emitter lowered every cons-match tail on a FreeMonoid to iter().skip(1).cloned().collect(), materializing the whole tail per step: every fold over a FreeMonoid was quadratic. Measured on the required-v2-native lane's first native run (2026-09-09): the self-hosted lexer, which tails the remaining source per character and per rule attempt, tokenized a 22KB file in 23.3s against 70ms for 899B, projecting a multi-hour whole-corpus context fold — the lane's dominant term. im::Vector::skip shares the RRB tree in O(log n). Two mirrors carry the only cons-tail sites in the stage0 corpus: v1_compiler_emit_rust.rs (the emitter itself) and std_occurrence_binding_candidates.rs. The e0599 emitter-decision census and its witness tests move to the new (skip, __fm) site with the measured rationale. Fixed-point regen green: the rebuilt seed regenerates both mirrors byte-identically. Co-authored-by: briansrls <briansrls@gunb.ai> * Route FreeMonoid length/snoc through the count/list_push primitives length folded the whole carrier per call (O(n)); the parse repeat loop calls it on the remaining-token list twice per element — an O(elements x tokens) quadratic measured at 40% of self-hosted parse self-time on the required-v2-native lane's first native run (2026-09-09). list_snoc_item routed through list_append, paying a full O(n) right-fold per snoc and making every build-by-appending accumulator quadratic (measured on the first-set union fold). count is O(1) and list_push amortized O(log n) on the persistent-vector realization. Probe-measured on the emitted crate: 25s -> 6.6s parse on a 4k-element synthetic, 209s -> 33s on a 315KB table module. Co-authored-by: briansrls <briansrls@gunb.ai> * Hoist first-fold knowledge into prepared grammar expressions The parse choice dispatch recomputed expr_first_fold on both branches at every Choice node at every token position: right-nested choice chains made that O(k^2) per position with O(t^2) union constants — the dominant self-hosted parse cost once the algebra carriers were fixed. The grammar is fixed for a whole parse, so each node's first fold (and each Choice's ambiguity verdict) is a pure function of the grammar: compute it once at preparation, bottom-up, and carry it on a PreparedGrammarExpr tree hung off GrammarFirstAnalysis / ParseTableRealization. parse_expr keeps its GrammarExpr signature as a compat wrapper that prepares on the fly; parse_nonterminal_memoized_core reads the prepared map. Forecast by a pointer-keyed memo probe on the emitted crate: 33s -> 14s on the 315KB table module. parse_minted_id_list also moves off list_append-per-node (O(n^2) per captured repeat) onto a snoc fold over the list_push primitive. Verified by execution: 29-test battery over parse_table_claims, grammar_validation (left-recursion suite), parse_token_first_empty_ semantics, parse_table_content_key and parse_table_memo_governed_witness all green through the seed interpreter. Co-authored-by: briansrls <briansrls@gunb.ai> * Deref boxed variant fields in enum shared accessors The storage side boxes a variant record field w…
… seed-prepared artifact (lands after #10990) (#10940) * Land the add-slice per-stage verdict instrument named as the floor_expected_red note's producer The add-slice roster note in v2.workflow.floor_expected_red carried a dated receipt (main 3a8344b5c: infer accepts dag_add_emitted_root; the infer-then-translate composition refuses headed by infer_grounding_not_derived) and named its own next-rung trigger: a .dag entry returning the per-stage verdicts for one root, so the paragraph can name a producer instead of a commit. v2.compiler.self_host.candidate_generation_stage_verdicts is that entry, parameterized over root and target: the receipt's verdict vocabulary (infer_accepted / infer_rejected; candidate_accepted or the rejection head reason) plus the carried-reasons lists -- the half the verdict symbols cannot say, namely that infer accepts while carrying the frontier diagnostic on its accepted path, so the enrolled witness's d == None conjunct fails even where the composition reaches acceptance. v2.test.execution.self_host_candidate_generation_stage_verdicts binds the instrument to the slice's own fixture, with add_slice_stage_verdicts_entry the runnable gunbc run --function form (ExitSuccess only when infer accepts clean and the composition accepts clean). Two witnesses: infer-accepts as a permanent positive control, and the frontier-state pin that is expected to red the day the add-slice stall's trigger lands, flipping to a permanent regression control in the same change that removes the roster row (DESIGN 4b(4)). Measured by execution on this branch: the entry exits 1 printing infer=infer_accepted, infer_carried=[infer_grounding_not_derived x10], composition=infer_grounding_not_derived, composition_carried=[x11] -- the receipt reproduced, with bind_outcome's pending-plus-gate chain counted. Both witnesses PASS; the enrolled semantic witness still fails as enrolled. Co-authored-by: Brian Searls <briansrls@users.noreply.github.com> * Derive grounding for dag declared inhabitants: the add slice greens end-to-end infer gains the declared-inhabitant membership derivation: a node declared in the dag language authority's declared-inhabitants roster derives its grounding by lookup, with the roster as evidence -- the namespacing answer to the atom authority question, at specimen scope. The add slice's ten type-spine nodes (Arrow, Conj, Atom) are all roster members, so: - candidate_generation_translate_self_emit_dag_add_slice_holds passes; its floor_expected_red roster row and per-row note delete per the roster's own stale-quarantine arm - the dag same-language ingest path compiles end-to-end: cross_language_compile accepts, byte-equal to the authority's own serialization, no carried diagnostics - the add-slice stall narrows to its four python/typescript round-trip members; the original trigger's causal clause was refuted by execution and is restated against the grammar parse-product population - the instrument's frontier guard flips to add_slice_composition_accepts_holds (DESIGN 4b(4): frontier guard to permanent regression control) - five manual witnesses flip with it: two root flips rewritten to assert the green state, three transitive conjunctions updated The kinds stay frontier: non-member Arrow/Conj/Atom specimens carry GroundingNotDerived exactly as before, and all fourteen enrolled refusal/acceptance controls pass unchanged. The door's production path still reds inside rust emission, untouched by this rule. Co-authored-by: Brian Searls <briansrls@users.noreply.github.com> * Derive grounding for canonical binding atoms: dag_binding_denotation joins binding to inhabitant once The resolver already binds the surface spelling Int to the canonical binding symbol dag_binding_type_int; what that binding DENOTES is the Int inhabitant declared at dag_declared_inhabitants_core. Every hand-rolled fixture facts lookup re-authored that join (dag_add_canonical_grounding_for, record_construct_canonical_grounding_for). The language authority now declares it once as dag_binding_denotation, and infer_node_facts consumes it: an Atom whose identity is a canonical dag binding with a declared denotation derives with that denotation as its grounding evidence. Direct-rust-door specimen census: 14 underived -> 10 underived (the four dag_binding_type_int atoms derive; grammar-production atoms, algebra atoms, bare operand atoms, and the arrow/conj spine stay on the frontier unchanged). Specimen-scope interim in the same frame as infer_node_declared_in_dag_inhabitants: both delete in favor of consuming resolution output when the resolver hands infer declaration-resolved identities directly (the namespace migration's completed state). Witness: v2.test.execution.dag_binding_denotation — all four Int binding atoms in the door specimen derive with dag_int_inhabitant_node() as structural evidence, and the two bare operand atoms stay GroundingNotDerived (boundary control). Refusal suite 14/14, ingest bridge 7/7, add-slice instruments 2/2 green; every remaining red in the at-risk population reproduces identically on the pre-change tree and is enrolled in floor_expected_red. Co-authored-by: Brian Searls <briansrls@users.noreply.github.com> * Add v2 self-host direct-path orientation: axes, sequence, autonomy contract A point-in-time orientation that defers to the existing authorities (DESIGN section 7, the four-wave self-host program, the roadmap node chain, the three frontier carriers, the guarantee-stall roster, XL-N) rather than restating them: state is re-derived by the named instruments, never transcribed here. Sequences the remaining work in roadmap order (door, parse-product grounding, first behavioral module, XL-N milestones, native bootstrap, fixed point, v1 deletion) and states which decisions stay operator-gated. Co-authored-by: Brian Searls <briansrls@users.noreply.github.com> * Derive grounding for fully-evidenced Conj and Arrow products The sixth and seventh kind rules: a non-roster Conj or Arrow whose every child carries DerivedGrounding derives, its evidence the same shape re-formed over the children's grounding evidence (a fresh OccurrenceSynthetic node, never the source — the self-evidence wall holds by construction). A product with any frontier or absent child stays on the frontier with its typed diagnostic; a childless product has no evidence to compose and stays frontier. Roster members keep their roster evidence. Measured on the direct-rust-door specimen (scratch probe, uncommitted): 10 underived of 15 -> 6. The parameter conj, the module-structure conjs, and the bodied add arrow derive; what remains is the algebra atoms from the + operation (AlgebraPrimitive, ring_field_add), the module atom (dag_surface_module), the parameter references (x, y), and the grammar-projection root conj that cascades once they land. Enrolled witnesses (src/v2/test/claim/execution/infer_product_introduction_test.dag): - product_introduction_derives_fully_evidenced_products_holds — census: 4 Conj (3 derived, 1 frontier-by-frontier-child) + 1 Arrow (derived). - product_introduction_composed_evidence_carries_child_groundings_holds — the params conj's evidence is a Conj whose x/y children target the dag authority's Int inhabitant. - product_introduction_leaves_childless_conj_on_the_frontier_holds — boundary control via direct infer over a hand-built childless Conj. Flip census (pre- and post-change, zero unexpected flips): translate_underived_refusal 14/14, infer_self_grounding_wall 12/12, branch_infer_if_then_else 2/2, compile_eval_thesis_proof 6/6, ingest_bridge 9/9, cross_language_add_python_to_typescript 4/4, inhabitant_neutralization 6/6 + e2e 6/6, emit_host_classical_not 14/14, dag_binding_denotation 2/2, stage-verdicts instrument 2/2, dag_add_emit_round_trip 4/6 (the 2 enrolled reds unchanged), door production group still enrolled-red (unchanged). Co-authored-by: Brian Searls <briansrls@users.noreply.github.com> * Ground canonical-operation and grammar-production atoms by authority roster membership Two more specimen-scope derivations in infer_node_facts, both lookups into declared authorities, never inventions: - Canonical-operations roster (target_model.dag): every CanonicalOperation the target-model authority declares, rendered by target_model_canonical_operation_wire_node and gathered under one Conj root. The resolver canonicalizes surface operators (e.g. +) to those declared operations, so the wire atoms -- the operation discriminant and its field references -- derive by membership with the roster root as evidence. General over all 14 declared operations, not add-narrow. - Grammar-productions roster (dag.dag): every production in dag_grammar_root() projected to its emitted surface atom under one Conj root keyed by production name. The bridge projects a production's parse into (identity atom, captured content) pairs, so the identity atom (dag_surface_module) derives by membership with the roster root as evidence. The roster derives from the grammar root, so a production added to the grammar joins by construction. Both roster roots are Conj nodes, never structurally equal to any member atom, so the self-evidence wall holds by construction (the first attempt at the operations rule used the wire node itself as evidence and was refused by grounding_evidence_is_source -- the wall doing its work). Measured on the direct-rust-door specimen (scratch probe, uncommitted): 6 underived of 15 -> 2 (only the operand atoms x and y remain; the grammar-projection root conj cascades once the module atom grounds). Enrolled witnesses (infer_atom_grounding_rules_test.dag): each roster rule pins derivation + evidence identity + census; a boundary control pins that a bare atom with no authority membership stays frontier; the closing control pins the 2-of-15 state. Flip census: the product-introduction census witness updates 3->4 derived conjs (the top conj now cascades) and gains a hand-built partially-evidenced boundary control to replace the in-specimen one the cascade consumed. Full battery otherwise unchanged: refusal suite 14/14, grounding wall 12/12, instrument 2/2, binding-denotation 2/2, round-trips, bridge, cross-language, neutralization, emit-host all green; enrolled reds unchanged. Co-authored-by: Brian Searls <briansrls@users.noreply.github.com> * Ground binding-reference atoms from the enclosing arrow's domain declaration The fifth specimen-scope derivation, closing the direct-rust-door specimen's inference frontier: an Atom whose binding an enclosing arrow's domain declares derives with the declared domain type as its evidence -- the declaration-site annotation, itself derived (x: Int grounds the x reference). This is the same lookup the branch-operand path already performs (infer_find_arrow_domain_type_in_tree), now written to the operand atom's own facts; it is scope-naive (whole-tree, first match), recorded in the frontier note, and deletes with the other specimen-scope rules when the resolver hands infer declaration-resolved identities. The tree is threaded through the fold's init chain to reach infer_node_facts; the helper had exactly one caller. Measured on the door specimen (scratch probe, uncommitted): 2 underived of 15 -> 0. The specimen's inference frontier is fully closed, and the production observation advances from InferenceRejected (infer_grounding_not_derived) to EmissionRejected (target_use_site_ownership_lookup_miss) -- a new, typed, located deficit in the emitter, the next gate on the path. Flip census (all three rewrites verified by execution): - dag_binding_denotation_leaves_unbound_operand_atoms_on_the_frontier_holds -> dag_binding_denotation_declares_no_denotation_for_operand_bindings_holds: the boundary moves to the authority itself (the denotation table returns Absent for x/y), true regardless of infer's other rules. - The three emit_host classical-not refusal guards (canonical, staging, staging-swapped) flip to acceptance witnesses pinning the emitted text's shape -- the real-infer tree now fully derives, and the emission is the same one the equals-eval witness proves behaviorally correct. The translate-refuses-underived behavior stays enrolled on hand-staged fixtures in translate_underived_refusal_test.dag (14/14 green). The renames are carried into the commit_workflow and witness_deferral_freeze rosters. - New witnesses: binding_reference_derives_parameter_atoms_holds (evidence is the domain's Int binding atom, census 2) and door_specimen_fully_derives_holds (0 frontier of 15). Full battery at this state: refusal suite 14/14, grounding wall 12/12, instrument 2/2, binding-denotation 2/2, product-introduction 4/4, atom-rules 5/5, emit_host 14/14, round-trips 4/6 (2 enrolled reds unchanged), bridge 9/9, cross-language 4/4, neutralization 6/6 + e2e 6/6, branch 2/2, eval-thesis 6/6; door production group still enrolled-red (unchanged). Co-authored-by: Brian Searls <briansrls@users.noreply.github.com> * Green the direct-rust-door: route emission through produced-decl composition and decode canonical operator wires The door specimen's inference frontier is fully closed, so its production observation now reaches the emission stage. Two defects surfaced there, both fixed here: Emission composition. generate_rust_emission_candidate served two lanes with one root shape: the door's production path (a dag module shell) and a fixture lane (a bare rust Arrow). The translate ownership gate queried the module atom's ownership at a struct-field use site and refused with target_use_site_ownership_lookup_miss, because the module's grammar-projection conj was misread as a type record. The door's real composition is the produced-decl path: collect declaration conjuncts from the inferred tree and emit via emit_produced_decl. A new generate_rust_module_emission_candidate does exactly that, enforcing an exactly-one-declaration admission policy (rust_module_emission_decl_absent / _ambiguous). The observation and production mint paths switch to it; the fixture-lane candidate is retained with a note that it is fixture-only. A pure collector, produced_decl_conjs_in_tree, finds nodes of produced-decl shape (a Conj whose first child is a Named edge to an Arrow). Its decl-head match routes through a declared FreeMonoid<Edge> parameter because the v1 seed stamps pattern variables from a declared parameter type, not from a field-access scrutinee. Operator decode. With composition fixed, source fidelity still refused: the door emitted fn add(x: i32, y: i32) -> i32 { AlgebraPrimitive(x, y) } instead of { x + y }. Resolution canonicalizes a surface operator atom into a canonical-operation wire node, so a production tree's transform operator position carries the wire, while fixture trees that bypass resolution still carry the surface token atom. translate_project_transform_in_arrow_scope only knew the surface-token table, so the wire missed and fell to callable apply, rendering the discriminant identity. The projection now tries the wire decode first (canonical_operation_from_wire_node) and only on a wire miss falls to the surface-token table, then to callable apply; the arms are disjoint, so the dispatch adds no fallback widening. target_transform_operator_child extracts the operator child safely. The door's closing expectation now greens by execution, so its known_red_probe row in explicit_witness_admission is deleted per its own dissolution condition, and the roadmap authority note, the door contract note, and the direct-path plan are updated to record the green state. realized_closure_for_v2_direct_ rust_door_emit_run's module list reflects the produced-decl route. Verified by execution: the door witness greens; the fixture, containment, algebra, produced-decl, add-slice, and classical-not witnesses stay green; claim_executor required-ci lanes build and witnesses both exit 0; cargo fmt and clippy --all-targets -D warnings are clean. One pre-existing red, witness_projection_is_active_only in the floor_cost_debt containment roster, reproduces on the base revision and is unrelated to this change. Co-authored-by: Brian Searls <briansrls@users.noreply.github.com> * Close the parse-product grounding frontier: widen declared-inhabitant membership to the closed ingest set The declared-inhabitant roster-membership derivation in 04_infer generalized from the dag roster to the closed ingest set (dag, python, typescript): infer_node_declared_in_language_inhabitants returns the declaring authority's roster root as evidence, with deep subtree membership so a declared inhabitant's leaf fact atoms derive exactly as the inhabitant node itself. Measured: the python fixture's 19-node frontier and the typescript fixture's 28-node frontier both close to zero; all four add-slice stall population round-trip witnesses green; the python->typescript cross-language compile accepts, byte-identical to ts_source_text. Section 4b(4) flips (expecting-red probes becoming permanent regression controls for the acceptances): - cross_language_compile_refuses_canonical_underived_holds -> cross_language_compile_python_to_typescript_round_trip_holds - inhabitant_neutralization_emit_after_neutralize / same_flavor_python / go_int64_to_ts refusal helpers -> round-trip controls - inhabitant_neutralization_python_to_ts_cross_language_compile (e2e) -> round-trip control; python->go members stay refusal guards (go is outside the closed ingest set) - cross_language_emit_inhabitant_neutralization_refuses_underived_holds -> round-trip control; the python->typescript emit-matrix row reads ChainProven The add-slice stall's next-rung trigger fired, so it retired per DESIGN 4b(4): removed from all_guarantee_stalls, row file deleted, witnesses stay enrolled. Co-authored-by: Brian Searls <briansrls@users.noreply.github.com> * Promote the add family to SelfEmittedNative: native-only verdict witness for the emitted add crate First InterpreterRetained -> SelfEmittedNative promotion after classical_not, executing the v2-emitter-first-behavioral-module first slice at the coverage-frontier grain: the add family (fewest dependencies — integer literals plus one canonical operation) now carries a native-only verdict witness, so its behavior is established by the emitted crate's own stdout with eval() unreachable from the verdict path. - emit_host_native_only_add_holds: real emit -> cargo build -> native run, stdout pinned to the family's expected octet, sharing the kernel family's one-build cache key exactly as the classical_not arm shares its family's key (no duplicated cold build). - emit_host_native_only_add_wrong_octet_mismatch_detected_holds: the broken control — a no-eval verdict has no oracle leg to break, so the expectation side breaks (an octet the run never produces must not match); program-side discrimination stays with the family's equals_eval primitive-five/six pair. - The add coverage row flips disposition with its backing citation enrolled by construction (the verdict entry is file-grain enrolled in falsifier_self_host_wet_template_entries). - Frontier census tests updated at identity grain: natives are exactly {classical_not, add}; split 2/13. Verified by execution: all six native-only verdict tests green locally (real wet legs — compile_skipped receipts show cold builds and native runs); all eight emit_coverage_frontier tests green, including the unbacked-claim RED control. Co-authored-by: Brian Searls <briansrls@users.noreply.github.com> * Record the add-slice defect's repair in the declined-live-tree classification The row classified candidate_generation_translate_self_emit_dag_add_slice_holds as RealDefect/CompilerBehaviourRefusal with measured evidence that translate refuses infer_grounding_not_derived. The owner lane (v2 self-host) repaired the subject: the declared-inhabitant roster-membership derivation grounds the slice's type spine by lookup, and the witness passes under claim_batch --hermetic on the merged tree. The dated classification is kept verbatim; the disposition flips RoutedToOwner -> RepairedInThisChange with the repair measurement appended to the evidence, so the routing carrier stops dispatching a fixed defect. Structural witnesses (count 13, no NotReproduced, exact partition) are untouched and pass. * Hoist two in-body annotation blocks to module-item grain Main's annotation-placement wall (source annotations admit only standalone leading blocks attached to module-scope declarations; in-body forms refuse) reached this branch through the merge and refused 8 blocking errors on the 00_compile closure: the add-family promotion note inside the emit_coverage_frontier_roster list and the python->typescript row note inside the cross_language_emit_matrix list. Both blocks move above their enclosing declarations, rephrased to name their subject row. Measured: gunbc compile of src/v2/compiler/00_compile.dag now emits 172 files with 0 blocking errors; both files' suites stay green (8/8 and 4/4). * Promote the complement family to SelfEmittedNative: native-only verdict witness for the emitted logic family crate The complement family's native execution runs family-grain per the witness_family_build_grain_ruling (one crate for meet + join + complement, argv-dispatched), so the native-only arm emits the logic family crate and runs the complement member through the family dispatcher, sharing the family witness's one-build cache key. The verdict is decided solely by the emitted native run's stdout (expected octet 0, complement(True) = False); the broken control flips the expectation side (octet 1 can never match), with the comparator pinned by the stdout mock pair. Program-side discrimination stays with the equals_eval agreement pair and the family witness's all-alt leg. The frontier row's backing citation lands in the already file-grain-enrolled native-only verdict entry, so it is enrolled by construction; the roster comment is rephrased to cover both 2026-09-07 promotions (add and complement). The frontier test's split and native membership assertions move to 3 native / 12 retained. Verified by execution: claim_batch --hermetic on emit_host_native_only_verdict_test.dag passes all 8 witnesses (the two new complement arms included), and emit_coverage_frontier_test.dag passes all 8. * Key the emitter's host-String arm on declaration provenance, not spelling is_host_text_carrier_type answered true for any type expression whose authored name reads "String", including references to the structural alias v2.std.text.String (type String = FreeMonoid<Char>) that the namespace lane (gunbc#9907) requalified the v2 corpus's text-carrier fields to. The emitter rendered every one of those references as the host String while value-position consumers rendered the structure -- the E0308 family dominating the self-host compile-phase frontier (41 of 64 in v2_compiler_tokenize.rs on the post-merge board). The String arm now consults the resolved declaration's provenance against v1.compiler.coercion structural_declaration_modules_for -- the same roster type_realization_decision reads -- so the legacy arm and the strict decision cannot diverge on one node (DESIGN section 3, and gunbc.recurring_failure_mode alias_resolution_collides_with_kernel_spelling). Kernel mints and unresolved references keep the host answer exactly as before. Regen: the only drifted stage0 mirror is v1_compiler_emit_rust.rs itself (no module in the stage0 closure references a structurally declared String -- verified by the whole-population candidate tree), installed from target/stage0-regen-candidate after the priced round's partitioned rebuild refused MirrorHasNoOwningPackage on the emitter (the emitter is monolith-shell, not partition-owned). Fixed point verified by execution: claim_executor --required-regen on the rebuilt seed reports first_generation_equal=true over 158 adjudicated mirrors. * Peel qualified String alias leaves in field position: XL-N closure 72 -> 28 errors A field authored v2.std.text.String reached the Rust emitter as an overlay-less resolved reference leaf and rendered the bare terminal name, which binds the prelude String cross-module (#9813: kernel names are never overridden by imports, so the use-line is dropped) while every value position renders the structural carrier Rc<Vec<i64>> -- the v2_compiler_tokenize.rs E0308 family, 41 of 72 errors on the XL-N phase board. The new rust_overlayless_alias_leaf_requires_peel arm in render_rust_type_without_applied_binding detects the population (overlay-less zero-parameter alias leaf, qualified spelling, String terminal segment, closed_alias_peel_verdict agrees) and renders the alias declaration's resolved right-hand side, projecting the same realization the fn-signature positions already produce. The qualified gate is load-bearing: inside the declaring module the bare name is the correct render (the emitted module carries the alias declaration), and the local binding's resolved_type drops the RHS type argument, so an ungated peel rendered Rc<FreeMonoid> there (E0107 x13, E0282 x2 on the probe). Bare String keeps denoting the kernel scalar through the host-carrier arm. Measured: probe specimen (qualified/bare/direct-FreeMonoid/container/variant/ local-alias positions) compiles clean; XL-N compiler closure cargo check 72 -> 28 errors with the residual census dominated by the declared text_boundary_identity_wall class (kernel String vs structural carrier at bare-authored boundaries, 17 of 20 E0308s); v1-corpus fixed point holds (first_generation_equal=true, 158/158 adjudicated). * Resolve the 12 non-hop XL-N closure errors at source: text-wall conversions + witness_violates helper Four clusters, all measured non-hop additions between receipt_1 (155) and the post-peel census (28); the live gate now measures 15 with zero unadmitted regressions: - integer.dag: integer_string_to_decimal_digits_step takes v2.std.text.String; the public boundary converts with chars() (text_boundary_identity_wall specimen discharged at this site). - 01_tokenize.dag: Token/UnboundSourceAnnotation lexemes convert structural -> host String with chars_to_string() at construction, mirroring the v1 tokenizer's host-lexeme carrier. - target_model.dag + bash.dag: EmitSpellingEscape.from/to and apply_emit_spelling_escapes go structural (v2.std.text.String); the EmitSpellingQuote arm converts host->structural->host at its boundary; bash's escape rows wrap their kernel String literals with chars(). - witness.dag + 3 call sites (collection list_nth, provenance span_index_resolve_textual_locus_from_ids, compile outcome_with_diagnostics): new witness_violates<C> helper puts Violates constructions in a Witness-headed position so the emitter resolves the carrier type argument; dissolves once inference records per-call substitutions. Verified: 48 targeted claim witnesses green (tokenize behavioral, shell conformance, string brace escape, string length, map-lookup violates, source text ingress, bash materialize x12, int literal smoke x6, provenance span index x2). * Record receipt_2 on the self-host compile-phase frontier: 15-error census at 66765317ec The census at the XL-N lane tip: 155 -> 15 net, credited to the qualified-alias peel (60cbd7b697, 72 -> 28) and the twelve-error source cluster (66765317ec, 28 -> 15). The epoch changes on the instrument's target pinning (found by review on gunbc#9857), admitted with receipt_1's board as the reclassified predecessor under the identity map. Nine added identities are hop relocations admitted by the hop index; four sit in python/typescript modules newly entered into the emitted closure, admitted as ExposedByNewEmittedModule. Validated: all 36 self_host_compile_phase_frontier_witness claims PASS, including current_persisted_compile_phase_frontier_holds. * Emitter: a substituted declaration node carries its own provenance Inference substitutes the resolved declaration into a data annotation's type-argument position, so BooleanAlgebra<v2.std.logic.Bool> reaches the emitter with the arg BEING the type Bool = True | False declaration itself (Disj connective, ident_span in src/v2/std/logic.dag, no Resolved wrapper). type_reference_provenance_in_env's bare-leaf arm re-resolved that leaf in the REFERENCING module's scope, where post-#9813 a kernel-shadowed spelling answers the kernel declaration -- so the structural enum rendered as host bool against a value of BooleanAlgebra<Bool> (the python.rs:328 / typescript.rs:177 E0308 pair on the XL-N compile-phase frontier). The connective is the discriminator: a reference node is a bare name (NoConnective); a node carrying Conj/Disj structure IS the declaration, and type_reference_provenance's own-span fallback already answers that shape correctly. The guard routes declaration-shaped nodes there directly, bypassing the scope lookup that #9813 makes answer the kernel. Mirror regenerated via the regen round; fixed-point verified (claim_executor --required-regen PASS). * Clear the remaining XL-N closure errors at source: carrier conversions at the boundaries The receipt_2 census's fifteen identities, resolved at their sources: - lexing.dag, dag.dag, python.dag, typescript.dag: LexPattern.text is the structural carrier (v2.std.text.String); the construction sites held host Strings. Convert at construction with chars() -- the #9907 ingress pattern. - python.dag / typescript.dag bool groundings: qualify the annotation as BooleanAlgebra<v2.std.logic.Bool>; with the emitter's substituted- declaration provenance guard the qualified arg now renders structural. - target_model.dag: target_lex_rule_literal_step returns the host carrier (chars_to_string over the structural pattern text); TargetText.source converts at the is_empty boundary; the unicode-scalar symbol intern converts its single-codepoint list to the host carrier. - qualified_name.dag: qualified_name_from_dotted_string uses the host-carrier emptiness check (string_length == 0) instead of routing through the structural string_is_empty. - 02_parse.dag: parse_looks_like_match_arm_start rewritten on host-carrier operations (string_length, char_at, code_point) rather than converting to the structural carrier for a two-character lookahead; parse_char_is_arm_pattern_lead takes the codepoint Int directly. - v1_interpreter_primitive_surface.dag row_key: the concat pipeline lowered to a .concat() method call on std::string::String (E0599); rewritten as nested concat calls. Measured: the 00_compile closure emits 172 files and cargo check reports cargo_clean=true, cargo_error_population=0 under the pinned 1.93.0 toolchain. * Pin the cargo half's toolchain channel by construction The cargo half runs with cwd = a fresh mktemp directory; with no rust-toolchain.toml there, rustup resolves the host's DEFAULT toolchain, so a census under cargo 1.83 and one under cargo 1.93 would compare as equal epochs while different compilers did the measuring -- the fabricated comparability the target pin (gunbc#9857) excludes, one level up. Measured 2026-09-07: a host default of 1.83.0 met a crates.io index whose freshly published dependency manifests require edition2024, resolution failed before any diagnostic existed, and the zero-diagnostic refusal fired on an unmeasured tree. The pin is propagated by copying the repo's rust-toolchain.toml into out_dir: the file remains the sole in-repo channel authority (its header forbids a second pinned literal), and the copy makes the measured channel true by construction on any host. The gate's read_live_toolchain observes the same channel because every documented actuator invokes from the repository root, which the same file governs. * Record receipt_3 on the self-host compile-phase frontier: the emitted closure's cargo census is empty Measured at 5ee4892b70 by the one-entry instrument: the 172-file emitted crate reports zero cargo error diagnostics, so the board attributes every phase a count of zero and furthest_phase_reached stands at Borrowck. The fifteen removals against receipt_2 need no disposition; nothing was added. The epoch does not change: the cargo half now pins the toolchain channel by copying the repo's rust-toolchain.toml into the scratch crate, and every recorded comparison field is identical to receipt_2 (whose census the fingerprint evidence shows the same 1.93.0 toolchain already compiled), so the same-epoch arm carries no reclassified predecessor. The frontier-state pin flips per DESIGN 4b(4): the_published_frontier_standing_does_not_claim_typeck_or_borrowck_passed becomes the_published_frontier_standing_claims_typeck_and_borrowck_passed, the permanent regression control over the green state. Validated: all 36 self_host_compile_phase_frontier_witness claims PASS, including current_persisted_compile_phase_frontier_holds. * chore: regenerate drifted generated artifacts (ci auto-heal) Ledger-Repair-Judged: docs/design-failure-modes.md Ledger-Repair-Judged: docs/design-rung-drops.md * Remove the stale PointwisePower inhabitant rows from the four language rosters First native-parity divergence class found by running the emitted closure on a discriminating fixture: the algebra inhabitant rosters still carried PointwisePower after its authority row was cut, so the emitted compiler panicked at 12 record-shaped carrier sites while the interpreted seed refused cleanly. The roster rows are removed in rust/python/go/typescript types.dag, the derived coercion assertions in compiler_tests.rs regenerate without them, and two witnesses pin the boundary: the record shape constructs its structural carrier, and FinitePowerSet still refuses while its row stands. Mirrors regenerated by a converged regen round (fixed point Reached, stage-1 PromoteGenerationInputs over the three language types mirrors). * Regen gen-2 gate: compare executable digests in one spelling The admitted side of run_built_seed_regen carries the executable-digest spelling (current_exe_digest, next_pass_executable_digest) while the observed side hashed the file through path_digest, which prepends the fnv1a64: tag. Same bytes, two spellings, so the gate could never pass -- unpassable since fa2d403dc8 (#9771). Factor current_exe_on_disk as the single path authority and read the observed digest through current_exe_digest so both sides spell the same bytes the same way. * Model ReleaseScopeEmpty for release-excluded mirrors, end to end A regen round whose only stage-2 drift was compiler_tests.rs (the PointwisePower roster removal rewrote its derived coercion assertions) refused the rebuild MirrorHasNoOwningPackage: the mirror is owned by no partition package, because every item it defines is #[cfg(test)] and no release unit elaborates it. The refusal conflated two different states -- unowned (a coverage hole) and excluded from the release build by construction (a precise empty scope). The model now names the class: rebuild_scope_release_excluded_mirrors rosters its members (compiler_tests.rs, cited to emit_compiler_tests_module), the decision answers ReleaseScopeEmpty when the whole change set is excluded, and the actuation shape is actuatable with an empty package closure and every partition package excluded -- the build still runs as verification, and a compiled partition package refuses the stage. The host admits the empty closure only when the new stage0_partition_rebuild_release_scope_empty_today query answers true; any other empty closure still refuses. A mixed change set scopes on its release-visible members alone. Verified by execution: the 2026-09-08 round converged (fixed point Reached) with stage-2 installing compiler_tests.rs alone; cargo recompiled the shell crate on its fingerprint (the outer mod line is ungated, so rustc reads the file) while the produced executable was byte-identical -- stage input seed digest == output seed digest. Four new witnesses pin the arm, its actuation shape, the mixed set, and the host-facing query's two arms; the boundary witness (unowned cli_run.rs still refuses) keeps the roster from decaying into the absorbing fallback. * Round-cost receipt: project installed mirrors to the model's vocabulary The receipt's partition-rebuild line is rendered by the model over receipt.installed_mirrors, which the host populated from the stages' projected_paths -- full paths -- while the partition rows and rosters key on basenames. Every drifted round's receipt therefore rendered a spurious RebuildScopeRefused MirrorHasNoOwningPackage line naming a full path, a false claim on the round's own receipt. Route the projection through emit_path_basename, the module's single path-to-basename bridge, so the field carries the mirror names the model's vocabulary means. * Hoist ReleaseScopeEmpty annotations to module-item grain The ReleaseScopeEmpty modeling commit placed three // blocks inside declaration bodies (stage0_partition_rebuild_is_actuatable, stage0_partition_rebuild_decision, stage0_partition_rebuild_excluded_today). The .dag realization admits annotations at module-item grain only, so the floor lane's parse phase refused the file with 12 located errors and the run ended floor refused. The prose is unchanged; each block now sits above the declaration it describes. * Spell the PointwisePower witness's finite-set exclusion as the applied realization The witness added with the fossil-row removal excluded the bare spelling "BTreeSet", but every emitted file's preamble imports OrdSet as BTreeSet, so the row could never green. The exclusion's subject is the finite-set REALIZATION the fossil row would have asserted; spell it applied (BTreeSet<i64), which the preamble's import line does not contain. * Emit fieldless-record data values as null for the unit-struct carrier The second native-parity divergence class, measured 2026-09-08 on the native run of the emitted 00_compile closure: emit_data_value_json spelled EVERY record literal as a JSON map, including the zero-field record, while emit_struct_from_children renders that same declaration as a Rust unit struct (pub struct BoolEncodingFact;). serde's derived unit-struct Deserialize reads null and rejects {}, so the emitted compiler panicked at first touch of v2.std.logic's bool_primitive_facts: "invalid type: map, expected unit struct BoolEncodingFact". The JSON spelling of a data value must deserialize into the Rust type the same declaration emitted; the record arm now spells the zero-field value null and keeps the map spelling for non-empty records. The mirror is taken from the required-regen candidate, not hand-edited. Two witnesses enroll: the discriminating red (zero-field record spells null, never {}) and the boundary control (a record with fields keeps the map spelling). * Bind the duplicate-definition filter ahead of its branch condition Main's FilterInBranchCondition wall (#10699) refuses to publish a module whose filter call sits in a branch condition, and the v2 00_compile closure emission names primitive_duplicate_semantic_definition_violation as such a site. The filter is pure and total; binding it with a let ahead of the branch is the authored remediation the wall exists to force, and the emitted closure is unchanged in behavior. * chore: regenerate drifted generated artifacts (ci auto-heal) Ledger-Repair-Judged: docs/design-rung-drops.md Ledger-Rows-Repaired: docs/design-rung-drops.md rust_unit_tests_off_the_merge_path Ledger-Rows-Repaired: docs/design-rung-drops.md determinism_transitive_reachability Ledger-Rows-Repaired: docs/design-rung-drops.md transitional_admission_exception * Emitter: three native-parity repairs for the post-merge 00_compile closure build Three divergence classes measured as the 21 rustc errors on the natively emitted 00_compile closure after the main merge, each repaired at the .dag source with a discriminating witness: - Locality wins over a foreign ambiguity (12 E0433 in v2_std_integer.rs): alias_rhs_base_module_filename asked the global leaf index, saw LeafAmbiguous for Compose, and emitted the poison marker even inside v2.std.integer itself, where source resolution binds the local declaration before any cross-module lookup. The local physical declaration now shadows foreign declarers; the poison marker still stands for a leaf two FOREIGN modules declare. - The qualifier is the disambiguator (8 E0425/E0433 in v2_lens_fact_density.rs): the qualified use-line route declined any globally-ambiguous leaf, but a qualified reference names its provider in its own spelling. The route now resolves by DeclaredCallableIdentity at the qualifier, keeping the type-declared and export-proof walls. The dotted spelling reaches the route through the value surface (a qualified value projection's borrowed type stamps the match patterns' parent_enum); the witness reproduces that chain exactly, and its exclude half pins the E0603 boundary (the dotted VARIANT head must still be declined). - Clone-bound forwarding is transitive (1 E0277 in std_realization_measurement.rs): the call-forwarding derivation re-derived only each callee's SELF-derived half, so a callee whose bound is itself forwarded re-derived to empty. The derivation now recurses over the call graph with the module's visited-set termination; the equality half stays one-hop as declared. Witnesses: 56/56 PASS on the rebuilt seed; regen fixed point holds. * Refuse variant record literals on the serde_json data path fail-closed A record literal with parent_enum present is a variant construction whose wire spelling is the parent coproduct's declared VariantEncoding policy -- a module-local fact of the parent's home module that emit_data_value_json does not carry. The zero-field arm's null and the map arm's untagged fields are both measured to fail serde deserialization under the internal-tag default, so the arm now refuses and the caller renders compile_error!, a build-time located refusal where a runtime panic on the data definition's expect was the latent alternative. The refusal names its trigger: a closure-wide wire-policy index beside EmitGraphInfo.type_decl_items. Witness: w_variant_record_lit_on_the_json_data_path_refuses_fail_closed forces the JSON path with a nested-record Holder and asserts the compile_error! spelling while excluding the former null mis-serialization. * Spell variant record literals on the serde_json data path from a closure-wide wire-policy index The fail-closed refusal landed in 73b582dea6 fired on 5 real corpus sites (SugarKey x2, CopiedPortCitationFrontierDisposition x3), proving variant record literals reach the JSON data path in the 00_compile closure. This change replaces the refusal with the correct spelling, driven by a new closure-wide index: - v1.compiler.infer_emit_info gains DataVariantWireSpelling, the language-general projection of a coproduct's Rust wire serde policy for one variant (InternalTagged { tag_field, tag } | BareString { tag } | Untagged | SpellingRefused { reason }), and EmitGraphInfo carries data_variant_wire_spellings: Map<String, DataVariantWireSpelling> keyed by coproduct.variant. - v1.compiler.emit_rust builds the index once per emission root via build_data_variant_wire_spellings, resolving each coproduct's policy through the new shared resolve_emission_coproduct_wire_policy (the same function the type-emission side now calls, so the two cannot drift), projecting each variant through data_path_wire_variant_tag (rename_all and StripAffix aware), and poisoning collisions as SpellingRefused so ambiguity stays fail-closed. - v1.compiler.emit's emit_data_value_json variant arm reads the index: internal-tagged spells {"_variant": tag, ...fields}, bare-string spells "tag" for nullary and refuses fielded, untagged spells the bare fields or null; unindexed keys and stored refusals remain compile-time errors. The service mock-property chain threads emit_info through so dry-run data spells identically. Witnesses: w_variant_record_lit_on_the_json_data_path_refuses_fail_closed is rewritten as ..._spells_the_internal_tag (asserts the internal-tag map, excludes the former null mis-serialization and the refusal), and w_fielded_variant_record_lit_on_the_json_data_path_spells_tag_and_fields pins the fielded case. 57/57 witnesses pass; regen fixed-point holds. * Promote field_access to SelfEmittedNative on the emit coverage frontier Fourth native-eval construct promotion, after classical_not, add, and complement. The native-only verdict arm pair lands in the already file-grain-enrolled long/ entry, so the backing citation is enrolled by construction: - emit_host_native_only_field_access_holds pins the family one-build cache run's stdout to octet 9 (the byte the family witness's warm leg pins on the same build), eval() never called. - emit_host_native_only_field_access_wrong_octet_mismatch_detected_holds breaks the expectation side with octet 1, the alt tree's byte. Both arms verified wet locally (real cargo build + native run, sharing the field_access family one-build cache key). The roster row flips to SelfEmittedNative; the two census guards update per 4b(4) — the split moves to 4 native / 11 retained and the identity-grain membership guard is renamed to name the four-member population. The family's equals_eval agreement pair stays enrolled as its program-side discrimination leg. * Drop the scratch parity probe from the tree The probe is a manual parity-loop instrument (the interpreted leg of the native-vs-interpreted comparison), not a corpus declaration with an executing consumer (DESIGN 6 experimental residue). It stays in use locally as an untracked file. * Promote match, loop, and fold_closure to SelfEmittedNative Fifth, sixth, and seventh native-eval construct promotions. The three match_loop_fold family rows flip together on one shared family-crate arm shape, per the witness_family_build_grain_ruling: each arm emits the three-member family crate once and runs its own member through the argv dispatcher against the family one-build cache key. - emit_host_native_only_{match,loop,fold_closure}_holds pin the warm legs' stdout to the family's declared octet lists (match/loop [0,1,0,0,0], fold [0,7,0,0,0]), eval() never called. - The wrong-octet controls break the expectation side with each member's own alt octets (match/loop [0,2,0,0,0], fold [0,255,255,255,255]). All six arms verified wet locally. The census guards update per 4b(4): 7 native / 8 retained, and the identity-grain membership guard is renamed to witness_native_rows_closed_membership_holds so the name stops encoding the volatile population. * Promote meet_join to SelfEmittedNative on the emit coverage frontier The meet_join family's native-only verdict arms land on the complement arm's helper, generalized to take the family member_id: meet and join run through the same argv-dispatched logic family crate (one-build cache key shared with complement, per the witness_family_build_grain_ruling), eval() never called, verdict decoded from stdout. Octets meet=1 join=1 are the bytes the family witness's warm legs pin on this same build; the wrong-octet control expects each member's alt byte (0), which the primary runs can never produce. Both arms verified wet: cold build then warm hits, PASS/PASS. The roster row flips InterpreterRetained -> SelfEmittedNative (eighth promotion); census guards move to 8 native / 7 retained with meet_join_eval_subject named in the closed membership. * Promote variant_construct to SelfEmittedNative on the emit coverage frontier The variant_construct family's native-only verdict arms follow the field_access arm shape exactly: the tree is the family's own equals_eval tree value (emit_variant_construct_eval_tree, no eval leg reachable), the run shares the family one-build cache key that emit_on_demand_variant_construct_native_one_build_holds colds, and the expected octet 9 is the byte the family witness's warm leg pins on this same build. The wrong-octet control expects the alt tree's byte (1), which the primary run can never produce; the wrong-value alt leg in the family witness keeps the program-side discrimination. Both arms verified wet: cold build then warm hit, PASS/PASS. The roster row flips InterpreterRetained -> SelfEmittedNative (ninth promotion); census guards move to 9 native / 6 retained with emit_variant_construct_eval_subgraph_node named in the closed membership. * Close the emit coverage frontier: final six rows to SelfEmittedNative The last six InterpreterRetained rows flip to SelfEmittedNative, taking the roster to 15 native / 0 retained: - filesystem_read and shell_exec_run (host-effect transport families, no translated arrow body): the arms reuse each family's own native leg with the expectation pinned as a literal grounded by the family's enrolled fixture pin (dag/extdeps/shell/exec.dag contains bash; its shell.Exec.Run argv materializes to exactly [bash, -s]), run through the families' fixed witness workspaces. - module and produced_module: the arms execute the exact sources the equals_eval pairs run (emit_module over the add fixture tree; produced_add_module_source's ingested two-fn module), octet 5 pinned against the add family's primitive-five/six oracle leg. - call and record_construct: the arms emit the families' own producer trees against their target models, octets 7 and 9 pinned against the primitive-seven/eight and wrong-field oracle legs. The four families without a one-build cache witness run under per-family fixed workspace roots; content-safety comes from the realization-digest nesting in run_host_process_admitted (changed source colds, never serves stale), the same mechanism the filesystem_read fixed workspace relies on. All twelve arms verified wet: PASS/PASS each, cold builds then warm hits. With zero retained rows the retained_via_eval_agreement constructor loses its last consumer and is deleted (DESIGN 3c); the InterpreterRetained variant stays as the disposition authority's other state. Census guards move to 15 native / 0 retained with all fifteen decl names in the closed membership. * Record the emit coverage frontier closure in the direct-path plan Axis C line: all fifteen roster rows are SelfEmittedNative as of 2026-09-08, interpreter_retained_rows() is empty, and the row constructor was deleted with the last flip. Notes explicitly that this closes axis (a) (witness-body-runs-native) only; axis (b) (the regen-grain production flip) remains operator-gated. * Model the required-v2-native lane authority: route receipt, exclusion taxonomy, admission, enrolment gate Parallel track B (operator authorization 2026-09-09): one additional required CI job whose subject is the compiler/test execution route itself — the emitted-native compiler binary invoked by explicit path over a derived v2.test.* population. The lane is modelled in full in gunbc.witness_v2_native_route: the prefix universe derivation, the per-member verdict rows (head + fatal reason grain), the exclusion taxonomy delegating attribution to the door ledger's known_frontier_causes, the counted exclusion census with a totality check, the terminal-observation receipt carrier, the admission predicate (one predicate per contract clause, all causes collected), and the enrolment gate with today's standing as data. Enrolment is BLOCKED, as data with a named capability trigger: the measured census over the derived universe (882 members, seed withdrawn during the run) refused every member — the emitted DirectIngestDriver admits only the hard-coded compile_driver_subject name with empty imports, and the compile door is at its modelled frontier — so the contracted positive population is empty and native_route_admission over the real receipt executed to 'refused: positive_population_empty'. The exact enrolment edit (phase-roster variants, claim_executor mirror, workflow lane, aggregate join, YAML regen) is carried on the standing row. The census measured five fatal-grain refusal causes the door ledger's head-grain attribution table did not carry; they are added to known_frontier_causes with their owning lanes (three MigrationOwned under nimble-boar-198, two normalize/body-lowering SharedSelfHostCriticalPath). Seventeen floor witnesses (v2.test.v2_native_route) consume the authority and execute green through the seed interpreter. Co-authored-by: briansrls <briansrls@gunb.ai> * Split preparation predicates so EmittedClosureUnrecorded is reachable Review on #10882 (briansrls, point 7): native_route_preparation_recorded folded the seed and closure observations into one && predicate, so a receipt with a recorded seed and an unrecorded closure misreported as preparation_seed_unrecorded and the emitted_closure_unrecorded cause had no reachable construction — the grain-mismatch class DESIGN 4b(3) names. One predicate per observation, one admission clause per predicate, and two witnesses pinning each refusal name against its own receipt shape (including the negative: each refuses ONLY by its own name). Co-authored-by: briansrls <briansrls@gunb.ai> * Key cause ownership by diagnostic grain; classify native refusals at fatal grain The door ledger's known_frontier_causes was a head-grain authority; the native route classified fatal reasons through it, crossing grains (review on #10882). Generalize the ownership key with DiagnosticGrain so one table answers both grains: the door ledger's cause_is_attributed keeps its head-grain contract, and the native route's exclusion classifier asks the fatal-grain question of the same table. The head advisory is live receipt data again: every refused row's head reason must be owned at head grain (or by this lane's driver-limit roster), and an unowned advisory blocks admission by its own clause name. Co-authored-by: briansrls <briansrls@gunb.ai> * Hoist known_frontier_causes row-group notes above the declaration The grain-keyed ownership change left its row-group commentary inside the list literal; the annotation channel admits only module-item grain, so the emitted closure refused with nine annotation-grain diagnostics. Move the notes to a single block above the declaration. No semantic change. Co-authored-by: briansrls <briansrls@gunb.ai> * Parse test fn as a contextual production in the v2 dag grammar The emitted native compiler could not parse any v2.test.* module: the modeled dag grammar had no test fn production, so every floor witness module refused with parse_g0_tokens_remain (706 of 882 in the census). test stays an ordinary identifier — typescript/program.dag models the TypeScript compiler's Cond.test field under real-upstream-names — so the production is the contextual sequence(ident, fn_decl): a new choice arm in top_level_item with no FIRST overlap with the keyword-led arms, a body-lowering arm that lifts the nested fn member after checking the marker lexeme is literally test (a typed refusal otherwise), and a forward-producer row for the new surface identity. Verified against the emitted native binary: probe_testfn.dag moves from parse_g0_tokens_remain to resolve_module_not_found (the driver's synthetic-subject limit, identical to a plain fn), and the standing choice-overlap residue roster is unchanged at seven rows. Co-authored-by: briansrls <briansrls@gunb.ai> * Add SourceRootEvalDriver: native whole-ingest test-execution route The required-v2-native lane's terminal subject is an exact test identity reaching a native Eval verdict, not a module accepted for translation. DirectIngestDriver (one source, no peers, synthetic subject) stays as the front-door census instrument; the new driver renders a main that reads a host-derived universe of qualified test identities plus the declared source roots, assembles the ingest once, prepares each module (resolve + infer), and Evals each named test body -- one typed verdict row per member, with a prepare-refusal fan-out so no member is silently dropped. Co-authored-by: briansrls <briansrls@gunb.ai> * Escape literal braces in SourceRootEvalDriver main.rs template The .dag string lexer reads '{' followed by an identifier as interpolation, so the emitted Rust use::-import lists and format! captures must spell literal braces as \{ \}. The single parse error desynced the file parse and cascaded into 2618 unattributed-annotation errors; with the escapes the emitter compiles clean (0 blocking, 107 files emitted). Co-authored-by: briansrls <briansrls@gunb.ai> * Collect per-file front-end refusals in the native test context fold The SourceRootEvalDriver's context fold reused program_assembly_fold_ingest, which is wholesale fail-closed: one source hitting the v2 front-end's live corpus frontier would deny verdict rows for every other universe member. The fold now collects each source's tokenize/parse/normalize refusal as a NativeTestFileRefusal row (head and fatal reason grains, matching the door ledger's grain-keyed ownership) and keeps folding; a refused file contributes no root, so its test identities surface as Context-stage refusal rows and nothing is widened. The emitted main.rs prints the file-refusal rows and counts them in the terminal marker, and prepare/eval refusals now classify at the fatal (last diagnostic) grain consistently. Co-authored-by: briansrls <briansrls@gunb.ai> * Add native lane control fixtures Two controls for the required-v2-native lane's host harness: src/v2/native_lane_fixture/control.dag carries the live-verdict pair (a well-formed false control and its true positive half) as plain fns outside the v2.test. prefix, so floor discovery enrolls no universe rows for them; fixtures/native_lane_malformed/poison.dag is a deliberately unterminating string that any honest front-end must refuse at tokenize, kept outside every declared source root so the broken bytes never enter an honest ingest. Co-authored-by: briansrls <briansrls@gunb.ai> * Fix Vec/Vector type mismatches in the SourceRootEvalDriver main.rs template The emitted driver crate aliases im::Vector as Vec, so the template's std Vec-typed bindings and collect calls failed to compile in the emitted crate: universe rows and module order carry Rc<Vector<String>>, the reads vector moves into the FreeMonoid parameter with .into(), and the dotted module name is built from an iterator collect. Co-authored-by: briansrls <briansrls@gunb.ai> * Harden the v2-native route contract: test-identity grain, exact join, paired reference Reframe the terminal subject from module-grain acceptance to the exact test identity reaching a native verdict. The receipt's universe is a list of qualified NativeRouteTestIdentity rows; the observed population joins it exactly (uniqueness, no foreign rows, no omissions); every member verdict is paired against the floor's own expected-red and route-gap rosters for agreement, exclusion, or divergence; refusals are classified from stage and provenance with cause ownership at fatal and head grains; and the four controls (true, false, malformed specimen, old-route withdrawal) are admission clauses. The 46 tests cover universe derivation, identity qualification, reference pairing, refusal classification, disposition, census counting, and every admission clause. Co-authored-by: briansrls <briansrls@gunb.ai> * Wire the required-v2-native lane into the roster, workflow, and aggregate Add V2NativeLane/V2NativePhase to the required-CI roster, the lane's claim_executor command to fabric_witness_run, and the required-v2-native job to the witness floor workflow with the aggregate witnesses job needing it in both verdict arms. Regenerate witnesses.yml. Co-authored-by: briansrls <briansrls@gunb.ai> * Add the required-v2-native host harness and phase dispatch The lane's one phase derives the v2.test.* universe with the floor's own discovery producer over the full module inventory, prepares the emitted-native compiler through the emit-compile phase's crate writer and cargo invocation, withdraws the old-route gunbc binary for the spawn window, runs the emitted binary by explicit path over the universe plus the named controls, reclassifies context-stage refusals against the observed file refusals, mints the NativeRouteReceipt as the authority's own types, and hands it to native_route_admission for the verdict. claim_executor gains the V2Native lane and phase with the roster sizes moved to six. Co-authored-by: briansrls <briansrls@gunb.ai> * Regenerate stage0 mirrors for the SourceRootEvalDriver emitter arm std_compiler_entry.rs gains the SourceRootEvalDriver variant and v1_compiler_emit_rust.rs the emit_source_root_eval_driver_main_rs template with its dispatch arm, emitted by the regenerated seed and verified at the fixed point (first_generation_equal=true over the whole 155-module population). Co-authored-by: briansrls <briansrls@gunb.ai> * Name the probe crate's lib target v1_compiled, the emitter's self-name contract emit_rust_selected binds the self-emitted crate's name to v1_compiled for every non-retained-host pipeline entry, and the SourceRootEvalDriver and DirectIngestDriver mains reach the closure through use v1_compiled::. The probe manifest's per-entry package name left the lib target named after the package, so a pipeline entry's driver main failed E0433 in the probe build -- unreachable while every probe entry was pipeline-free, and measured on the required-v2-native lane's first preparation. The lib path stays cargo's default; only the name is stated. Co-authored-by: briansrls <briansrls@gunb.ai> * Release retained emission arena before the native cargo build The lane's first run held ~15GiB RSS from the emission's resolved graph into the cargo build of the emitted compiler and was SIGKILLed (rc=137) with no diagnostic. Drop the emission run and malloc_trim the retained arena at both derivation-to-emission and emission-to-build handoffs, reporting the reclaimed KB so a trim that cannot release live memory shows in the lane log. Co-authored-by: briansrls <briansrls@gunb.ai> * Apply rustfmt to the v2-native lane host changes Co-authored-by: briansrls <briansrls@gunb.ai> * Lower FreeMonoid tail to im::Vector::skip — O(log n) share, not O(n) copy The emitter lowered every cons-match tail on a FreeMonoid to iter().skip(1).cloned().collect(), materializing the whole tail per step: every fold over a FreeMonoid was quadratic. Measured on the required-v2-native lane's first native run (2026-09-09): the self-hosted lexer, which tails the remaining source per character and per rule attempt, tokenized a 22KB file in 23.3s against 70ms for 899B, projecting a multi-hour whole-corpus context fold — the lane's dominant term. im::Vector::skip shares the RRB tree in O(log n). Two mirrors carry the only cons-tail sites in the stage0 corpus: v1_compiler_emit_rust.rs (the emitter itself) and std_occurrence_binding_candidates.rs. The e0599 emitter-decision census and its witness tests move to the new (skip, __fm) site with the measured rationale. Fixed-point regen green: the rebuilt seed regenerates both mirrors byte-identically. Co-authored-by: briansrls <briansrls@gunb.ai> * Route FreeMonoid length/snoc through the count/list_push primitives length folded the whole carrier per call (O(n)); the parse repeat loop calls it on the remaining-token list twice per element — an O(elements x tokens) quadratic measured at 40% of self-hosted parse self-time on the required-v2-native lane's first native run (2026-09-09). list_snoc_item routed through list_append, paying a full O(n) right-fold per snoc and making every build-by-appending accumulator quadratic (measured on the first-set union fold). count is O(1) and list_push amortized O(log n) on the persistent-vector realization. Probe-measured on the emitted crate: 25s -> 6.6s parse on a 4k-element synthetic, 209s -> 33s on a 315KB table module. Co-authored-by: briansrls <briansrls@gunb.ai> * Hoist first-fold knowledge into prepared grammar expressions The parse choice dispatch recomputed expr_first_fold on both branches at every Choice node at every token position: right-nested choice chains made that O(k^2) per position with O(t^2) union constants — the dominant self-hosted parse cost once the algebra carriers were fixed. The grammar is fixed for a whole parse, so each node's first fold (and each Choice's ambiguity verdict) is a pure function of the grammar: compute it once at preparation, bottom-up, and carry it on a PreparedGrammarExpr tree hung off GrammarFirstAnalysis / ParseTableRealization. parse_expr keeps its GrammarExpr signature as a compat wrapper that prepares on the fly; parse_nonterminal_memoized_core reads the prepared map. Forecast by a pointer-keyed memo probe on the emitted crate: 33s -> 14s on the 315KB table module. parse_minted_id_list also moves off list_append-per-node (O(n^2) per captured repeat) onto a snoc fold over the list_push primitive. Verified by execution: 29-test battery over parse_table_claims, grammar_validation (left-recursion suite), parse_token_first_empty_ semantics, parse_table_content_key and parse_table_memo_governed_witness all green through the seed interpreter. Co-authored-by: briansrls <briansrls@gunb.ai> * Deref boxed variant fields in enum shared accessors The storage side boxes a variant record…
Standalone uniform kernel-precedence repair (queue slot 1 per the side-chat ruling). Single producer repair in
src/v1/04_infer.dag; no residuals riding along.The defect
build_type_envandbuild_type_env_unresolvedboth skipped the kernel cache overlay when a module had exactly one import (resolved_imports |> count == 1→ the import's flattened cache alone). With one import, kernel identity won or lost by ancestry occupancy — a leak-dependent resolution regime: identical imports, different realizations, resolution by accident rather than by the declared precedence. The authority note (direct_import_export_precedence_note) already statedlocals > kernel > direct-selected > transitive union; the realization didn't implement it.The repair
One shared producer,
build_ancestry_precedence, consumed by both builders:import union (fork ledger unchanged — conflicts still recorded) → kernel overlay UNCONDITIONALLY → direct-selected overlay with kernel names skipped (
overlay_direct_import_exports, unchanged) → locals kept above by the existing str_bindings-first lookup. No downstream kernel checks added anywhere; theis_kernel_typecensus over 04_types/04_resolve/04_infer/04_env found only conformance/brand/qualification guards, none compensating for the closed hole. The unresolved builder gains the direct-selected overlay it previously lacked — same one-producer boundary. The authority note is updated in this PR: kernel installation independent of import cardinality.v1 PURPOSE admission (gunbc.v1_maintenance_standing v1_seed_standing)
boolin leak-carrying modules and structurally in leak-free ones, e.g.v2_std_subject_evidence, from identical import shapes). XL-0T's re-census is sequenced BEHIND this repair precisely because their battlefield changes under it.build_type_envto repair; the v2 program is blocked behind the seed producing wrong environments.count == 1special case is deleted; the shared producer replaces two divergent inline copies.T's four conditions (accepted, satisfied)
overlay_skips_kernel_nameuntouched; a directv2.std.text.Stringimport still binds deterministically via the direct-selected overlay's kernel-name skip.count == 1skip) is deleted, not guarded — no arm survives beside the rule.self_host_structural_text_witness_test(12 rows, materialized from their pinned head c14f7fe) run in the validation cycle — results recorded below when the cycle lands.Validation (updated when the cycle lands)
Regen to byte fixed point on the merged head (the seed changed, so the mirror regenerates — the current draft-head CI red is exactly
regen FAIL generated surface drift: v1_compiler_infer.rs, the expected pre-regen state); identity diff vs the 158-row post-#9808 baseline with every moved row classified under the adjudicated precedence-flip disposition (coordinated with PH — one deliberate corpus-wide event, not N unadmitted additions); full witness batteries + T's controls.🤖 Generated with Claude Code
https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU
Why the kernel-Bool commit is part of this repair (not a rider)
The floor caught it first: at head
8f371a67— precedence flip only, no kernel-Bool commit in existence —bcp_foreign_coproduct_where_bool_required_must_refusereturned false. Mechanism:coproduct_payload_where_parent_requiredreads the formal's resolved declaration vialookup_type_by_name. The fixture (module bcp.probe, one import,std.types { Int, Bool }) previously resolvedBoolthrough the import cache to std.types' concretetype Bool = True | Falseand judged. Under the unconditional kernel overlay the formal resolves to the synthetic kernel binding — scalar,NoConnective, no children — sodecl_is_concrete_coproductgoes false and the wall abstains. An abstaining wall accepts: the refusal silently became a decoration as a side effect of the precedence fix.f2e89e5a4brepairs it by construction at the producer: the kernel Bool binding carries the coproduct structure its cited declaration has (the existingkernel_optionalprecedent, applied in all three kernel-env constructors), no downstream kernel check. Splitting it out would land the precedence repair minus a refusal — exactly what §5 forbids ("the minimum Y must preserve every required refusal"). Thebcpwitness itself is untouched; the only re-pinned row is the separate peano emission row, whose old expectation encoded the ancestry-occupancy accident the ruling lists as unchanged semantics ("bare direct import of a kernel spelling cannot displace kernel") — re-pinned with Rule-1 as the flip-back trigger so it reds if leak-dependence is ever reintroduced.The in-cycle proof that ships with the final head: the full 10-row coproduct-payload battery and the full peano battery run against the compiler built from the committed mirror — the artifact that ships, not sources the seed hasn't caught up to.