Repository navigation
File the disagreement-blind class: a two-reader census cannot see a shared error, measured on the arbiter calibration control - #9934
Merged
Conversation
…the upstream cause of the six renderer short-circuits THE FINDING BEHIND THE FIRST ROW. The arbiter-repair design commissions a divergence census to adjudicate arm A, and states a calibration control: the diagnostic-producing `DivergesWithExactIdentity` subset must reproduce arm A's 25 sites, joined by source declaration and enclosing declaration, never by line. That control had never run against the typed-graph census landed by #9900. It has now, over the transitive import closure of `src/v2/compiler/01_tokenize.dag`, and it FAILS: - `v2.compiler.tokenize`, the module emitting the file where every arm-A site lives, contributes 76 rows: 74 Agrees, 2 IdentityUnavailable, ZERO DivergesWithExactIdentity. All 26 of its `String`-named rows Agree. - Every divergence row in the closure sits in `v2.std.text`, the DECLARING module, in the opposite direction. Empty intersection with the population the control exists to find. That is not the over-broad walk #9900 predicts — an over-broad walk shows the target population PLUS extras; this shows it NOT AT ALL. The shape of the absence is the diagnosis. The reason is general, and is why it is filed as a class rather than as a census defect: a two-reader DISAGREEMENT census reports AGREEMENT as healthy, so the population where both readers are wrong together is invisible to it by construction. At an arm-A site the short-circuit returns the host spelling before consulting anything and the authority answers from a fallback that returns the REFERENCING module's file, so both answer host and agree. Recognition rule, at the grain that generalises: any two-reader comparison cited as CORRECTNESS coverage — differential oracles, twin fixtures, cross-checks, self-hosted-versus-seed. Ask what a shared error would look like in its output; if the answer is "indistinguishable from health", it is not the correctness evidence. The remedy is a different oracle reaching outside the pair, never a repair of the comparison. SECOND ROW: the same run produced 121 `IdentityUnavailable` rows where the 2026-08-21 front-end-phase run reported zero. Rows that are neither agreements nor divergences are scored as decided by any ratio over the reported total. Both runs are NAMED rather than differenced — they are different instruments at different phases. THIRD CHANGE: `checkpoint_table_bypasses_identity_note` reads as though the spelling its six renderers short-circuit on had one meaning. It does not — a callee parameter type is re-resolved in the CALLER environment, so one declaration denotes the structural carrier in its own module and the kernel scalar at every foreign call site. The appended paragraph records that, and cites #9929 for calm-boar-314's three measurements (qualified spelling silences rather than pins; returns re-resolve on the same axis; one refusal can carry two disagreeing destinations) rather than restating them. No divergence number is published as a measurement of the emitter: the figures above appear only as the control's failure evidence, which is what the design asks for in the failing branch. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Vo22gFeUgs7vAVuhsmWqKk
…tions The carrier conflict was the shared-tail shape this file already documents as merge_region_excludes_shared_tail — main added sealing_property_erases_structure while this branch added two rows, with the trailing evidence/brace after the markers. Both sides kept; verified as a bijection in both directions (34 rows, 34 roster entries, none declared-unrostered and none rostered-undeclared) rather than by a count. DESIGN.md and docs/design-ledgers.md carried no conflict markers — the generated-artifact driver refuses rather than answering — so they are the regenerated projection of the resolved carrier, not a hand merge. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Vo22gFeUgs7vAVuhsmWqKk
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
THE FINDING BEHIND THE FIRST ROW. The arbiter-repair design commissions a
divergence census to adjudicate arm A, and states a calibration control: the
diagnostic-producing
DivergesWithExactIdentitysubset must reproduce arm A's25 sites, joined by source declaration and enclosing declaration, never by
line. That control had never run against the typed-graph census landed by
#9900. It has now, over the transitive import closure of
src/v2/compiler/01_tokenize.dag, and it FAILS:v2.compiler.tokenize, the module emitting the file where every arm-A sitelives, contributes 76 rows: 74 Agrees, 2 IdentityUnavailable, ZERO
DivergesWithExactIdentity. All 26 of its
String-named rows Agree.v2.std.text, the DECLARINGmodule, in the opposite direction.
Empty intersection with the population the control exists to find. That is not
the over-broad walk #9900 predicts — an over-broad walk shows the target
population PLUS extras; this shows it NOT AT ALL. The shape of the absence is
the diagnosis.
The reason is general, and is why it is filed as a class rather than as a
census defect: a two-reader DISAGREEMENT census reports AGREEMENT as healthy,
so the population where both readers are wrong together is invisible to it by
construction. At an arm-A site the short-circuit returns the host spelling
before consulting anything and the authority answers from a fallback that
returns the REFERENCING module's file, so both answer host and agree.
Recognition rule, at the grain that generalises: any two-reader comparison
cited as CORRECTNESS coverage — differential oracles, twin fixtures,
cross-checks, self-hosted-versus-seed. Ask what a shared error would look like
in its output; if the answer is "indistinguishable from health", it is not the
correctness evidence. The remedy is a different oracle reaching outside the
pair, never a repair of the comparison.
SECOND ROW: the same run produced 121
IdentityUnavailablerows where the2026-08-21 front-end-phase run reported zero. Rows that are neither agreements
nor divergences are scored as decided by any ratio over the reported total.
Both runs are NAMED rather than differenced — they are different instruments
at different phases.
THIRD CHANGE:
checkpoint_table_bypasses_identity_notereads as though thespelling its six renderers short-circuit on had one meaning. It does not — a
callee parameter type is re-resolved in the CALLER environment, so one
declaration denotes the structural carrier in its own module and the kernel
scalar at every foreign call site. The appended paragraph records that, and
cites #9929 for calm-boar-314's three measurements (qualified spelling
silences rather than pins; returns re-resolve on the same axis; one refusal can
carry two disagreeing destinations) rather than restating them.
No divergence number is published as a measurement of the emitter: the figures
above appear only as the control's failure evidence, which is what the design
asks for in the failing branch.
Stated limits
checkpoint_table_bypasses_identity_note's REACHABILITY CORRECTION plus two source facts, not executed here. It explains a measured absence; it is not itself a measurement.🤖 Generated with Claude Code
https://claude.ai/code/session_01Vo22gFeUgs7vAVuhsmWqKk