From 90bd2fefe98190a4963333108c6e2a961c3af3ed Mon Sep 17 00:00:00 2001 From: gunbc-ci-auto-heal Date: Tue, 1 Sep 2026 02:03:19 +0000 Subject: [PATCH 1/2] XL-0-SERVICE (PARKED): pin the shell service-emission fabrication with a three-output known-hole probe MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The shell service-emission path in 05_emit_rust binds `stdout` to EVERY declared output field, whatever source the declaration named, and returns a bare String from the error arm against a declared Box. Both emit Rust that does not compile, with zero diagnostics. This commit lands the reproduction only -- the lane was parked by the operator before the repair (it does not reduce the typeck count). The probe is a §4b(4) known-hole probe: green today asserting the WRONG behavior, and it must flip to the refusal assertion when the wall lands. The three-output fixture is the load-bearing part. Two fields cannot distinguish "wrong tuple index" from "the declared source never arrived"; three can, and the ABSENCE of the emitted `let stderr = ...` prelude is the positive evidence that the `from "stderr"` field was invisible rather than mis-ordered. Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_01SKidppJZFSPywEdbVGJ1Ex --- src/v1/stage0/src/compiler_tests.rs | 83 +++++++++++++++++++++++++++++ 1 file changed, 83 insertions(+) diff --git a/src/v1/stage0/src/compiler_tests.rs b/src/v1/stage0/src/compiler_tests.rs index 9e4f5de6bf1..6b7577b198f 100644 --- a/src/v1/stage0/src/compiler_tests.rs +++ b/src/v1/stage0/src/compiler_tests.rs @@ -3125,4 +3125,87 @@ mod compiler_tests { .join(); result.expect("profile_reconcile_per_module panicked"); } + + // KNOWN-HOLE PROBE (not a desired-behavior control), DESIGN section 4b(4). + // + // The shell service-emission path FABRICATES rather than refuses: every declared + // output field is bound to `stdout`, whatever source the declaration named, and the + // error arm returns a bare String against a declared Box. + // Both produce Rust that does not compile, with ZERO diagnostics -- section 5's + // fabricated-plausible-output arm, in the emitter. + // + // The three-output fixture is load-bearing. The two-field case this was first seen + // on (an operation declaring `success: Bool from "exit_success"` beside + // `stdout: String from "stdout"`) cannot distinguish "wrong tuple index" from "the + // declared source never arrived": with two fields, "always the first output" and + // "always stdout" produce the same bytes. Three fields separate them, and the + // ABSENCE of the `let stderr = ...` prelude line is the positive evidence -- that + // line is emitted only when some field claims the stderr channel, so its absence + // proves the `from "stderr"` field was invisible to the renderer rather than + // mis-ordered. child_from_key returns Absent for all three. + // + // WHEN THE WALL LANDS THIS PROBE MUST FLIP and become a permanent regression + // control: the emitted body must bind each field to its named source, box the error + // arm, and REFUSE -- typed and located, naming the field and the unresolvable + // source -- for any source it cannot realize. + #[test] + fn shell_service_output_projection_fabricates_stdout_known_hole_probe() { + let result = std::thread::Builder::new() + .stack_size(32 * 1024 * 1024) + .spawn(|| { + let source = std::rc::Rc::new(crate::v1_compiler_compile::SourceFile { + path: "probe.dag".to_string(), + content: "module probe\nservice Probe {\n operation Version {\n input {}\n output {\n success: Bool from \"exit_success\"\n out: String from \"stdout\"\n err: String from \"stderr\"\n }\n transport shell { argv: [\"git\", \"--version\"] }\n }\n}\n".to_string(), + }); + let r = crate::v1_compiler_compile::compile_sources( + std::rc::Rc::new(im::vector![source]), + crate::v1_compiler_artifact::RenderTarget::Rust, + ); + let errors: Vec<_> = r + .diagnostics + .iter() + .filter(|d| crate::v1_std_core::is_error_diagnostic(d.diagnostic.clone())) + .collect(); + assert!( + errors.is_empty(), + "KNOWN HOLE today: the emitter does not refuse; it fabricates silently. \ + When the wall lands this becomes the refusal assertion. Got: {:?}", + errors + ); + let emitted = r + .files + .iter() + .find(|f| f.path == "src/probe.rs") + .map(|f| f.content.clone()) + .expect("service module must emit src/probe.rs"); + + // The signature reads the declaration correctly... + assert!( + emitted.contains( + "-> Result<(bool, String, String), Box>" + ), + "signature must project the three declared output types, got:\n{}", + emitted + ); + // ...and the body then ignores every declared source. + assert!( + emitted.contains("Ok((stdout.clone(), stdout.clone(), stdout.clone()))"), + "KNOWN HOLE: every output field is bound to stdout regardless of its \ + declared source. If this assertion fails the wall may have landed -- \ + flip this probe to assert the correct per-channel binding. Got:\n{}", + emitted + ); + // The stderr prelude is the absence that proves the source was never read. + assert!( + !emitted.contains("String::from_utf8_lossy(&output.stderr)"), + "KNOWN HOLE: the `from \"stderr\"` field is invisible to the renderer, \ + so no stderr prelude line is emitted. Got:\n{}", + emitted + ); + }) + .expect("failed to spawn thread") + .join(); + result + .expect("shell_service_output_projection_fabricates_stdout_known_hole_probe panicked"); + } } From 0a383a93eeb81ce67347a175cdcfd3b35cb4d4c6 Mon Sep 17 00:00:00 2001 From: gunbc-ci-auto-heal Date: Tue, 1 Sep 2026 03:41:51 +0000 Subject: [PATCH 2/2] XL-0-SERVICE: move the known-hole probe into the .dag authority and regenerate the stage0 mirror The parked commit hand-wrote the probe into src/v1/stage0/src/compiler_tests.rs, which is a GENERATED file -- the emitted-population manifest names it, so the next regeneration would have silently deleted it. The authority for that surface is src/v1/compiler_tests_rust.dag. This commit authors ct_shell_service_output_projection_known_hole_probe_test() there, enrolls it in compiler_tests_source(), and carries both generated projections that follow from it: - src/v1/stage0/src/v1_compiler_compiler_tests_rust.rs (the mirror of the generator module itself), and - src/v1/stage0/src/compiler_tests.rs (the generator's own output), where the probe now sits at the position compiler_tests_source() places it rather than at end-of-file. Both were taken from --required-regen candidate bytes, not hand-edited: round one reported exactly one generated-surface drift (v1_compiler_compiler_tests_rust.rs), and round two -- with the seed rebuilt from that mirror -- reported exactly one more (compiler_tests.rs). The probe's own bytes are unchanged; it still asserts today's WRONG behavior and must flip when the wall lands. --- src/v1/compiler_tests_rust.dag | 88 ++++++++++ src/v1/stage0/src/compiler_tests.rs | 166 +++++++++--------- .../src/v1_compiler_compiler_tests_rust.rs | 6 +- 3 files changed, 176 insertions(+), 84 deletions(-) diff --git a/src/v1/compiler_tests_rust.dag b/src/v1/compiler_tests_rust.dag index 30ee22789df..93d14d20f25 100644 --- a/src/v1/compiler_tests_rust.dag +++ b/src/v1/compiler_tests_rust.dag @@ -2785,6 +2785,93 @@ fn ct_declared_type_conformance_witness_test() -> String { " }\n\n") } +fn ct_shell_service_output_projection_known_hole_probe_test() -> String { + concat( + " // KNOWN-HOLE PROBE (not a desired-behavior control), DESIGN section 4b(4).\n", + " //\n", + " // The shell service-emission path FABRICATES rather than refuses: every declared\n", + " // output field is bound to `stdout`, whatever source the declaration named, and the\n", + " // error arm returns a bare String against a declared Box.\n", + " // Both produce Rust that does not compile, with ZERO diagnostics -- section 5's\n", + " // fabricated-plausible-output arm, in the emitter.\n", + " //\n", + " // The three-output fixture is load-bearing. The two-field case this was first seen\n", + " // on (an operation declaring `success: Bool from \"exit_success\"` beside\n", + " // `stdout: String from \"stdout\"`) cannot distinguish \"wrong tuple index\" from \"the\n", + " // declared source never arrived\": with two fields, \"always the first output\" and\n", + " // \"always stdout\" produce the same bytes. Three fields separate them, and the\n", + " // ABSENCE of the `let stderr = ...` prelude line is the positive evidence -- that\n", + " // line is emitted only when some field claims the stderr channel, so its absence\n", + " // proves the `from \"stderr\"` field was invisible to the renderer rather than\n", + " // mis-ordered. child_from_key returns Absent for all three.\n", + " //\n", + " // WHEN THE WALL LANDS THIS PROBE MUST FLIP and become a permanent regression\n", + " // control: the emitted body must bind each field to its named source, box the error\n", + " // arm, and REFUSE -- typed and located, naming the field and the unresolvable\n", + " // source -- for any source it cannot realize.\n", + " #[test]\n", + " fn shell_service_output_projection_fabricates_stdout_known_hole_probe() {\n", + " let result = std::thread::Builder::new()\n", + " .stack_size(32 * 1024 * 1024)\n", + " .spawn(|| {\n", + " let source = std::rc::Rc::new(crate::v1_compiler_compile::SourceFile {\n", + " path: \"probe.dag\".to_string(),\n", + " content: \"module probe\\nservice Probe {\\n operation Version {\\n input {}\\n output {\\n success: Bool from \\\"exit_success\\\"\\n out: String from \\\"stdout\\\"\\n err: String from \\\"stderr\\\"\\n }\\n transport shell { argv: [\\\"git\\\", \\\"--version\\\"] }\\n }\\n}\\n\".to_string(),\n", + " });\n", + " let r = crate::v1_compiler_compile::compile_sources(\n", + " std::rc::Rc::new(im::vector![source]),\n", + " crate::v1_compiler_artifact::RenderTarget::Rust,\n", + " );\n", + " let errors: Vec<_> = r\n", + " .diagnostics\n", + " .iter()\n", + " .filter(|d| crate::v1_std_core::is_error_diagnostic(d.diagnostic.clone()))\n", + " .collect();\n", + " assert!(\n", + " errors.is_empty(),\n", + " \"KNOWN HOLE today: the emitter does not refuse; it fabricates silently. \\\n", + " When the wall lands this becomes the refusal assertion. Got: {:?}\",\n", + " errors\n", + " );\n", + " let emitted = r\n", + " .files\n", + " .iter()\n", + " .find(|f| f.path == \"src/probe.rs\")\n", + " .map(|f| f.content.clone())\n", + " .expect(\"service module must emit src/probe.rs\");\n", + "\n", + " // The signature reads the declaration correctly...\n", + " assert!(\n", + " emitted.contains(\n", + " \"-> Result<(bool, String, String), Box>\"\n", + " ),\n", + " \"signature must project the three declared output types, got:\\n{}\",\n", + " emitted\n", + " );\n", + " // ...and the body then ignores every declared source.\n", + " assert!(\n", + " emitted.contains(\"Ok((stdout.clone(), stdout.clone(), stdout.clone()))\"),\n", + " \"KNOWN HOLE: every output field is bound to stdout regardless of its \\\n", + " declared source. If this assertion fails the wall may have landed -- \\\n", + " flip this probe to assert the correct per-channel binding. Got:\\n{}\",\n", + " emitted\n", + " );\n", + " // The stderr prelude is the absence that proves the source was never read.\n", + " assert!(\n", + " !emitted.contains(\"String::from_utf8_lossy(&output.stderr)\"),\n", + " \"KNOWN HOLE: the `from \\\"stderr\\\"` field is invisible to the renderer, \\\n", + " so no stderr prelude line is emitted. Got:\\n{}\",\n", + " emitted\n", + " );\n", + " })\n", + " .expect(\"failed to spawn thread\")\n", + " .join();\n", + " result\n", + " .expect(\"shell_service_output_projection_fabricates_stdout_known_hole_probe panicked\");\n", + " }\n", + "\n") +} + fn compiler_tests_source() -> String { concat( ct_module_header(), @@ -2800,6 +2887,7 @@ fn compiler_tests_source() -> String { ct_call_shape_duplicate_wall_witness_test(), ct_function_value_named_application_controls_witness_test(), ct_function_value_field_method_known_hole_probe_test(), + ct_shell_service_output_projection_known_hole_probe_test(), ct_method_existence_wall_witness_test(), ct_declared_type_conformance_witness_test(), ct_sole_constructor_test(), diff --git a/src/v1/stage0/src/compiler_tests.rs b/src/v1/stage0/src/compiler_tests.rs index 6b7577b198f..18b60ae33c1 100644 --- a/src/v1/stage0/src/compiler_tests.rs +++ b/src/v1/stage0/src/compiler_tests.rs @@ -856,6 +856,89 @@ mod compiler_tests { ); } + // KNOWN-HOLE PROBE (not a desired-behavior control), DESIGN section 4b(4). + // + // The shell service-emission path FABRICATES rather than refuses: every declared + // output field is bound to `stdout`, whatever source the declaration named, and the + // error arm returns a bare String against a declared Box. + // Both produce Rust that does not compile, with ZERO diagnostics -- section 5's + // fabricated-plausible-output arm, in the emitter. + // + // The three-output fixture is load-bearing. The two-field case this was first seen + // on (an operation declaring `success: Bool from "exit_success"` beside + // `stdout: String from "stdout"`) cannot distinguish "wrong tuple index" from "the + // declared source never arrived": with two fields, "always the first output" and + // "always stdout" produce the same bytes. Three fields separate them, and the + // ABSENCE of the `let stderr = ...` prelude line is the positive evidence -- that + // line is emitted only when some field claims the stderr channel, so its absence + // proves the `from "stderr"` field was invisible to the renderer rather than + // mis-ordered. child_from_key returns Absent for all three. + // + // WHEN THE WALL LANDS THIS PROBE MUST FLIP and become a permanent regression + // control: the emitted body must bind each field to its named source, box the error + // arm, and REFUSE -- typed and located, naming the field and the unresolvable + // source -- for any source it cannot realize. + #[test] + fn shell_service_output_projection_fabricates_stdout_known_hole_probe() { + let result = std::thread::Builder::new() + .stack_size(32 * 1024 * 1024) + .spawn(|| { + let source = std::rc::Rc::new(crate::v1_compiler_compile::SourceFile { + path: "probe.dag".to_string(), + content: "module probe\nservice Probe {\n operation Version {\n input {}\n output {\n success: Bool from \"exit_success\"\n out: String from \"stdout\"\n err: String from \"stderr\"\n }\n transport shell { argv: [\"git\", \"--version\"] }\n }\n}\n".to_string(), + }); + let r = crate::v1_compiler_compile::compile_sources( + std::rc::Rc::new(im::vector![source]), + crate::v1_compiler_artifact::RenderTarget::Rust, + ); + let errors: Vec<_> = r + .diagnostics + .iter() + .filter(|d| crate::v1_std_core::is_error_diagnostic(d.diagnostic.clone())) + .collect(); + assert!( + errors.is_empty(), + "KNOWN HOLE today: the emitter does not refuse; it fabricates silently. \ + When the wall lands this becomes the refusal assertion. Got: {:?}", + errors + ); + let emitted = r + .files + .iter() + .find(|f| f.path == "src/probe.rs") + .map(|f| f.content.clone()) + .expect("service module must emit src/probe.rs"); + + // The signature reads the declaration correctly... + assert!( + emitted.contains( + "-> Result<(bool, String, String), Box>" + ), + "signature must project the three declared output types, got:\n{}", + emitted + ); + // ...and the body then ignores every declared source. + assert!( + emitted.contains("Ok((stdout.clone(), stdout.clone(), stdout.clone()))"), + "KNOWN HOLE: every output field is bound to stdout regardless of its \ + declared source. If this assertion fails the wall may have landed -- \ + flip this probe to assert the correct per-channel binding. Got:\n{}", + emitted + ); + // The stderr prelude is the absence that proves the source was never read. + assert!( + !emitted.contains("String::from_utf8_lossy(&output.stderr)"), + "KNOWN HOLE: the `from \"stderr\"` field is invisible to the renderer, \ + so no stderr prelude line is emitted. Got:\n{}", + emitted + ); + }) + .expect("failed to spawn thread") + .join(); + result + .expect("shell_service_output_projection_fabricates_stdout_known_hole_probe panicked"); + } + #[test] fn method_existence_wall_witness() { // DISCRIMINATING RED for method_existence_wall_note. Before the wall an @@ -3125,87 +3208,4 @@ mod compiler_tests { .join(); result.expect("profile_reconcile_per_module panicked"); } - - // KNOWN-HOLE PROBE (not a desired-behavior control), DESIGN section 4b(4). - // - // The shell service-emission path FABRICATES rather than refuses: every declared - // output field is bound to `stdout`, whatever source the declaration named, and the - // error arm returns a bare String against a declared Box. - // Both produce Rust that does not compile, with ZERO diagnostics -- section 5's - // fabricated-plausible-output arm, in the emitter. - // - // The three-output fixture is load-bearing. The two-field case this was first seen - // on (an operation declaring `success: Bool from "exit_success"` beside - // `stdout: String from "stdout"`) cannot distinguish "wrong tuple index" from "the - // declared source never arrived": with two fields, "always the first output" and - // "always stdout" produce the same bytes. Three fields separate them, and the - // ABSENCE of the `let stderr = ...` prelude line is the positive evidence -- that - // line is emitted only when some field claims the stderr channel, so its absence - // proves the `from "stderr"` field was invisible to the renderer rather than - // mis-ordered. child_from_key returns Absent for all three. - // - // WHEN THE WALL LANDS THIS PROBE MUST FLIP and become a permanent regression - // control: the emitted body must bind each field to its named source, box the error - // arm, and REFUSE -- typed and located, naming the field and the unresolvable - // source -- for any source it cannot realize. - #[test] - fn shell_service_output_projection_fabricates_stdout_known_hole_probe() { - let result = std::thread::Builder::new() - .stack_size(32 * 1024 * 1024) - .spawn(|| { - let source = std::rc::Rc::new(crate::v1_compiler_compile::SourceFile { - path: "probe.dag".to_string(), - content: "module probe\nservice Probe {\n operation Version {\n input {}\n output {\n success: Bool from \"exit_success\"\n out: String from \"stdout\"\n err: String from \"stderr\"\n }\n transport shell { argv: [\"git\", \"--version\"] }\n }\n}\n".to_string(), - }); - let r = crate::v1_compiler_compile::compile_sources( - std::rc::Rc::new(im::vector![source]), - crate::v1_compiler_artifact::RenderTarget::Rust, - ); - let errors: Vec<_> = r - .diagnostics - .iter() - .filter(|d| crate::v1_std_core::is_error_diagnostic(d.diagnostic.clone())) - .collect(); - assert!( - errors.is_empty(), - "KNOWN HOLE today: the emitter does not refuse; it fabricates silently. \ - When the wall lands this becomes the refusal assertion. Got: {:?}", - errors - ); - let emitted = r - .files - .iter() - .find(|f| f.path == "src/probe.rs") - .map(|f| f.content.clone()) - .expect("service module must emit src/probe.rs"); - - // The signature reads the declaration correctly... - assert!( - emitted.contains( - "-> Result<(bool, String, String), Box>" - ), - "signature must project the three declared output types, got:\n{}", - emitted - ); - // ...and the body then ignores every declared source. - assert!( - emitted.contains("Ok((stdout.clone(), stdout.clone(), stdout.clone()))"), - "KNOWN HOLE: every output field is bound to stdout regardless of its \ - declared source. If this assertion fails the wall may have landed -- \ - flip this probe to assert the correct per-channel binding. Got:\n{}", - emitted - ); - // The stderr prelude is the absence that proves the source was never read. - assert!( - !emitted.contains("String::from_utf8_lossy(&output.stderr)"), - "KNOWN HOLE: the `from \"stderr\"` field is invisible to the renderer, \ - so no stderr prelude line is emitted. Got:\n{}", - emitted - ); - }) - .expect("failed to spawn thread") - .join(); - result - .expect("shell_service_output_projection_fabricates_stdout_known_hole_probe panicked"); - } } diff --git a/src/v1/stage0/src/v1_compiler_compiler_tests_rust.rs b/src/v1/stage0/src/v1_compiler_compiler_tests_rust.rs index ed55e34a04a..03024183f5d 100644 --- a/src/v1/stage0/src/v1_compiler_compiler_tests_rust.rs +++ b/src/v1/stage0/src/v1_compiler_compiler_tests_rust.rs @@ -364,6 +364,10 @@ pub fn ct_declared_type_conformance_witness_test() -> String { v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(" #[test]\n".to_string(), " fn declared_type_conformance_witness() {\n".to_string()), " // DISCRIMINATING RED for declared_type_conformance_note. infer_item kept the\n".to_string()), " // declaration's inferred return regardless of what the body produced, so\n".to_string()), " // `fn f() -> Int { \\\"wrong\\\" }` typechecked with ZERO diagnostics.\n".to_string()), " let result = std::thread::Builder::new()\n".to_string()), " .stack_size(8 * 1024 * 1024)\n".to_string()), " .spawn(|| {\n".to_string()), " let red = std::rc::Rc::new(crate::v1_compiler_compile::SourceFile {\n".to_string()), " path: \"red.dag\".to_string(),\n".to_string()), " content: \"module red\\nfn f() -> Int { \\\"a string\\\" }\\ndata d: Int = \\\"a string\\\"\\n\".to_string(),\n".to_string()), " });\n".to_string()), " let red_result = crate::v1_compiler_compile::compile_sources(\n".to_string()), " std::rc::Rc::new(im::vector![red]),\n".to_string()), " crate::v1_compiler_artifact::RenderTarget::Rust,\n".to_string()), " );\n".to_string()), " let mismatches: Vec<_> = red_result.diagnostics.iter()\n".to_string()), " .filter(|d| matches!(*d.diagnostic, crate::v1_std_core::CompilerDiagnostic::TypeMismatch { .. }))\n".to_string()), " .collect();\n".to_string()), " assert!(\n".to_string()), " mismatches.len() >= 2,\n".to_string()), " \"expected a TypeMismatch for BOTH the fn return and the data annotation, got: {:?}\",\n".to_string()), " red_result.diagnostics\n".to_string()), " );\n".to_string()), " // POSITIVE CONTROLS: conforming declarations, and the optional-cardinality\n".to_string()), " // case (`first` yields Int? for a declared Int?) which must not red.\n".to_string()), " let green = std::rc::Rc::new(crate::v1_compiler_compile::SourceFile {\n".to_string()), " path: \"green.dag\".to_string(),\n".to_string()), " content: \"module green\\nfn a() -> Int { 42 }\\nfn b() -> String { \\\"fine\\\" }\\ndata c: Int = 7\\nfn e(xs: List) -> Int? { xs |> first }\\n\".to_string(),\n".to_string()), " });\n".to_string()), " let green_result = crate::v1_compiler_compile::compile_sources(\n".to_string()), " std::rc::Rc::new(im::vector![green]),\n".to_string()), " crate::v1_compiler_artifact::RenderTarget::Rust,\n".to_string()), " );\n".to_string()), " assert!(\n".to_string()), " green_result.diagnostics.is_empty(),\n".to_string()), " \"conforming declarations must produce NO diagnostic of any severity — filtering to the blocking variant would let an advisory pass unnoticed (codex review 45357), got: {:?}\",\n".to_string()), " green_result.diagnostics\n".to_string()), " );\n".to_string()), " // DISCRIMINATING RED for the container widening (codex review 45398:\n".to_string()), " // a provable mismatch in container ELEMENT types was indistinguishable\n".to_string()), " // from a valid declaration, because the ground-scalar gate required a\n".to_string()), " // plain shape and a List is not one). A List of a ground kernel scalar\n".to_string()), " // carries no alias, brand, coproduct or cardinality representation\n".to_string()), " // between the two sides either, so the same positive-establishment\n".to_string()), " // argument that admits Int-vs-String admits List-vs-List.\n".to_string()), " let container_red = std::rc::Rc::new(crate::v1_compiler_compile::SourceFile {\n".to_string()), " path: \"container_red.dag\".to_string(),\n".to_string()), " content: \"module container_red\\nfn f() -> List { [\\\"a\\\", \\\"b\\\"] }\\ndata d: List = [1, 2]\\n\".to_string(),\n".to_string()), " });\n".to_string()), " let container_result = crate::v1_compiler_compile::compile_sources(\n".to_string()), " std::rc::Rc::new(im::vector![container_red]),\n".to_string()), " crate::v1_compiler_artifact::RenderTarget::Rust,\n".to_string()), " );\n".to_string()), " let container_mismatches: Vec<_> = container_result.diagnostics.iter()\n".to_string()), " .filter(|d| matches!(*d.diagnostic, crate::v1_std_core::CompilerDiagnostic::TypeMismatch { .. }))\n".to_string()), " .collect();\n".to_string()), " assert!(\n".to_string()), " container_mismatches.len() >= 2,\n".to_string()), " \"a declared container whose ELEMENT type the body contradicts must refuse, for BOTH the fn return and the data annotation, got: {:?}\",\n".to_string()), " container_result.diagnostics\n".to_string()), " );\n".to_string()), " // POSITIVE CONTROL for the same widening: matching element types, and a\n".to_string()), " // container of a NON-ground element, which stays unjudged rather than\n".to_string()), " // guessed at.\n".to_string()), " let container_green = std::rc::Rc::new(crate::v1_compiler_compile::SourceFile {\n".to_string()), " path: \"container_green.dag\".to_string(),\n".to_string()), " content: \"module container_green\\nfn g() -> List { [1, 2] }\\ndata h: List = [\\\"x\\\"]\\n\".to_string(),\n".to_string()), " });\n".to_string()), " let container_green_result = crate::v1_compiler_compile::compile_sources(\n".to_string()), " std::rc::Rc::new(im::vector![container_green]),\n".to_string()), " crate::v1_compiler_artifact::RenderTarget::Rust,\n".to_string()), " );\n".to_string()), " assert!(\n".to_string()), " container_green_result.diagnostics.is_empty(),\n".to_string()), " \"a conforming container declaration must produce NO diagnostic, got: {:?}\",\n".to_string()), " container_green_result.diagnostics\n".to_string()), " );\n".to_string()), " })\n".to_string()), " .expect(\"failed to spawn thread\")\n".to_string()), " .join();\n".to_string()), " result.expect(\"declared_type_conformance_witness panicked\");\n".to_string()), " }\n\n".to_string()) } +pub fn ct_shell_service_output_projection_known_hole_probe_test() -> String { + v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(" // KNOWN-HOLE PROBE (not a desired-behavior control), DESIGN section 4b(4).\n".to_string(), " //\n".to_string()), " // The shell service-emission path FABRICATES rather than refuses: every declared\n".to_string()), " // output field is bound to `stdout`, whatever source the declaration named, and the\n".to_string()), " // error arm returns a bare String against a declared Box.\n".to_string()), " // Both produce Rust that does not compile, with ZERO diagnostics -- section 5's\n".to_string()), " // fabricated-plausible-output arm, in the emitter.\n".to_string()), " //\n".to_string()), " // The three-output fixture is load-bearing. The two-field case this was first seen\n".to_string()), " // on (an operation declaring `success: Bool from \"exit_success\"` beside\n".to_string()), " // `stdout: String from \"stdout\"`) cannot distinguish \"wrong tuple index\" from \"the\n".to_string()), " // declared source never arrived\": with two fields, \"always the first output\" and\n".to_string()), " // \"always stdout\" produce the same bytes. Three fields separate them, and the\n".to_string()), " // ABSENCE of the `let stderr = ...` prelude line is the positive evidence -- that\n".to_string()), " // line is emitted only when some field claims the stderr channel, so its absence\n".to_string()), " // proves the `from \"stderr\"` field was invisible to the renderer rather than\n".to_string()), " // mis-ordered. child_from_key returns Absent for all three.\n".to_string()), " //\n".to_string()), " // WHEN THE WALL LANDS THIS PROBE MUST FLIP and become a permanent regression\n".to_string()), " // control: the emitted body must bind each field to its named source, box the error\n".to_string()), " // arm, and REFUSE -- typed and located, naming the field and the unresolvable\n".to_string()), " // source -- for any source it cannot realize.\n".to_string()), " #[test]\n".to_string()), " fn shell_service_output_projection_fabricates_stdout_known_hole_probe() {\n".to_string()), " let result = std::thread::Builder::new()\n".to_string()), " .stack_size(32 * 1024 * 1024)\n".to_string()), " .spawn(|| {\n".to_string()), " let source = std::rc::Rc::new(crate::v1_compiler_compile::SourceFile {\n".to_string()), " path: \"probe.dag\".to_string(),\n".to_string()), " content: \"module probe\\nservice Probe {\\n operation Version {\\n input {}\\n output {\\n success: Bool from \\\"exit_success\\\"\\n out: String from \\\"stdout\\\"\\n err: String from \\\"stderr\\\"\\n }\\n transport shell { argv: [\\\"git\\\", \\\"--version\\\"] }\\n }\\n}\\n\".to_string(),\n".to_string()), " });\n".to_string()), " let r = crate::v1_compiler_compile::compile_sources(\n".to_string()), " std::rc::Rc::new(im::vector![source]),\n".to_string()), " crate::v1_compiler_artifact::RenderTarget::Rust,\n".to_string()), " );\n".to_string()), " let errors: Vec<_> = r\n".to_string()), " .diagnostics\n".to_string()), " .iter()\n".to_string()), " .filter(|d| crate::v1_std_core::is_error_diagnostic(d.diagnostic.clone()))\n".to_string()), " .collect();\n".to_string()), " assert!(\n".to_string()), " errors.is_empty(),\n".to_string()), " \"KNOWN HOLE today: the emitter does not refuse; it fabricates silently. \\\n".to_string()), " When the wall lands this becomes the refusal assertion. Got: {:?}\",\n".to_string()), " errors\n".to_string()), " );\n".to_string()), " let emitted = r\n".to_string()), " .files\n".to_string()), " .iter()\n".to_string()), " .find(|f| f.path == \"src/probe.rs\")\n".to_string()), " .map(|f| f.content.clone())\n".to_string()), " .expect(\"service module must emit src/probe.rs\");\n".to_string()), "\n".to_string()), " // The signature reads the declaration correctly...\n".to_string()), " assert!(\n".to_string()), " emitted.contains(\n".to_string()), " \"-> Result<(bool, String, String), Box>\"\n".to_string()), " ),\n".to_string()), " \"signature must project the three declared output types, got:\\n{}\",\n".to_string()), " emitted\n".to_string()), " );\n".to_string()), " // ...and the body then ignores every declared source.\n".to_string()), " assert!(\n".to_string()), " emitted.contains(\"Ok((stdout.clone(), stdout.clone(), stdout.clone()))\"),\n".to_string()), " \"KNOWN HOLE: every output field is bound to stdout regardless of its \\\n".to_string()), " declared source. If this assertion fails the wall may have landed -- \\\n".to_string()), " flip this probe to assert the correct per-channel binding. Got:\\n{}\",\n".to_string()), " emitted\n".to_string()), " );\n".to_string()), " // The stderr prelude is the absence that proves the source was never read.\n".to_string()), " assert!(\n".to_string()), " !emitted.contains(\"String::from_utf8_lossy(&output.stderr)\"),\n".to_string()), " \"KNOWN HOLE: the `from \\\"stderr\\\"` field is invisible to the renderer, \\\n".to_string()), " so no stderr prelude line is emitted. Got:\\n{}\",\n".to_string()), " emitted\n".to_string()), " );\n".to_string()), " })\n".to_string()), " .expect(\"failed to spawn thread\")\n".to_string()), " .join();\n".to_string()), " result\n".to_string()), " .expect(\"shell_service_output_projection_fabricates_stdout_known_hole_probe panicked\");\n".to_string()), " }\n".to_string()), "\n".to_string()) +} + pub fn compiler_tests_source() -> String { - v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(ct_module_header(), ct_workspace_helpers()), ct_file_discovery_helpers()), ct_source_builders()), ct_tokenizer_tests()), ct_parse_tests()), ct_pipeline_test()), ct_unlisted_import_use_witness_test()), ct_call_shape_wall_witness_test()), ct_call_deficit_red_witness_test()), ct_call_shape_duplicate_wall_witness_test()), ct_function_value_named_application_controls_witness_test()), ct_function_value_field_method_known_hole_probe_test()), ct_method_existence_wall_witness_test()), ct_declared_type_conformance_witness_test()), ct_sole_constructor_test()), ct_constructor_call_admission_test()), ct_constructor_call_admission_same_module_sibling_test()), ct_constructor_call_admission_function_value_test()), ct_constructor_call_admission_zero_arity_test()), ct_constructor_call_admission_shadowing_test()), ct_constructor_call_admission_qualified_caller_test()), ct_sole_constructor_fieldless_witness_test()), ct_contracts_sidecar_witness_test()), ct_self_parse_all_test()), ct_self_resolve_test()), ct_self_compile_test()), ct_self_compile_cargo_check_test()), ct_type_size_test()), ct_coercion_tests()), ct_profile_helpers()), ct_profile_self_compile_test()), ct_profile_full_pipeline_test()), ct_profile_reconcile_test()), ct_module_footer()) + v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(v1_rt::concat(ct_module_header(), ct_workspace_helpers()), ct_file_discovery_helpers()), ct_source_builders()), ct_tokenizer_tests()), ct_parse_tests()), ct_pipeline_test()), ct_unlisted_import_use_witness_test()), ct_call_shape_wall_witness_test()), ct_call_deficit_red_witness_test()), ct_call_shape_duplicate_wall_witness_test()), ct_function_value_named_application_controls_witness_test()), ct_function_value_field_method_known_hole_probe_test()), ct_shell_service_output_projection_known_hole_probe_test()), ct_method_existence_wall_witness_test()), ct_declared_type_conformance_witness_test()), ct_sole_constructor_test()), ct_constructor_call_admission_test()), ct_constructor_call_admission_same_module_sibling_test()), ct_constructor_call_admission_function_value_test()), ct_constructor_call_admission_zero_arity_test()), ct_constructor_call_admission_shadowing_test()), ct_constructor_call_admission_qualified_caller_test()), ct_sole_constructor_fieldless_witness_test()), ct_contracts_sidecar_witness_test()), ct_self_parse_all_test()), ct_self_resolve_test()), ct_self_compile_test()), ct_self_compile_cargo_check_test()), ct_type_size_test()), ct_coercion_tests()), ct_profile_helpers()), ct_profile_self_compile_test()), ct_profile_full_pipeline_test()), ct_profile_reconcile_test()), ct_module_footer()) }