Skip to content

File the disagreement-blind class: a two-reader census cannot see a shared error, measured on the arbiter calibration control - #9934

Merged
gunbai-bot[bot] merged 4 commits into
mainfrom
session/bold-carp-449-divergence-blind
Sep 1, 2026
Merged

gunbai-bot[bot] merged 4 commits into
mainfrom
session/bold-carp-449-divergence-blind

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Sep 1, 2026

Copy link
Copy Markdown
Contributor

THE FINDING BEHIND THE FIRST ROW. The arbiter-repair design commissions a
divergence census to adjudicate arm A, and states a calibration control: the
diagnostic-producing DivergesWithExactIdentity subset must reproduce arm A's
25 sites, joined by source declaration and enclosing declaration, never by
line. That control had never run against the typed-graph census landed by
#9900. It has now, over the transitive import closure of
src/v2/compiler/01_tokenize.dag, and it FAILS:

  • v2.compiler.tokenize, the module emitting the file where every arm-A site
    lives, contributes 76 rows: 74 Agrees, 2 IdentityUnavailable, ZERO
    DivergesWithExactIdentity. All 26 of its String-named rows Agree.
  • Every divergence row in the closure sits in v2.std.text, the DECLARING
    module, in the opposite direction.

Empty intersection with the population the control exists to find. That is not
the over-broad walk #9900 predicts — an over-broad walk shows the target
population PLUS extras; this shows it NOT AT ALL. The shape of the absence is
the diagnosis.

The reason is general, and is why it is filed as a class rather than as a
census defect: a two-reader DISAGREEMENT census reports AGREEMENT as healthy,
so the population where both readers are wrong together is invisible to it by
construction. At an arm-A site the short-circuit returns the host spelling
before consulting anything and the authority answers from a fallback that
returns the REFERENCING module's file, so both answer host and agree.

Recognition rule, at the grain that generalises: any two-reader comparison
cited as CORRECTNESS coverage — differential oracles, twin fixtures,
cross-checks, self-hosted-versus-seed. Ask what a shared error would look like
in its output; if the answer is "indistinguishable from health", it is not the
correctness evidence. The remedy is a different oracle reaching outside the
pair, never a repair of the comparison.

SECOND ROW: the same run produced 121 IdentityUnavailable rows where the
2026-08-21 front-end-phase run reported zero. Rows that are neither agreements
nor divergences are scored as decided by any ratio over the reported total.
Both runs are NAMED rather than differenced — they are different instruments
at different phases.

THIRD CHANGE: checkpoint_table_bypasses_identity_note reads as though the
spelling its six renderers short-circuit on had one meaning. It does not — a
callee parameter type is re-resolved in the CALLER environment, so one
declaration denotes the structural carrier in its own module and the kernel
scalar at every foreign call site. The appended paragraph records that, and
cites #9929 for calm-boar-314's three measurements (qualified spelling
silences rather than pins; returns re-resolve on the same axis; one refusal can
carry two disagreeing destinations) rather than restating them.

No divergence number is published as a measurement of the emitter: the figures
above appear only as the control's failure evidence, which is what the design
asks for in the failing branch.

Stated limits

  • The diagnostic-producing filter the control specifies was NOT computed. It only shrinks a subset already empty in the relevant module, so the verdict cannot turn on it — that is why the failure is reportable without it.
  • The agreement mechanism is read off checkpoint_table_bypasses_identity_note's REACHABILITY CORRECTION plus two source facts, not executed here. It explains a measured absence; it is not itself a measurement.
  • My transitive closure came to 21 modules where the design says 22, every import resolving, discrepancy UNRESOLVED. It cannot explain a zero inside a module present with 76 rows, but it is against a design document and anyone reporting a population should resolve it first.

🤖 Generated with Claude Code

https://claude.ai/code/session_01Vo22gFeUgs7vAVuhsmWqKk

gunbc-ci-auto-heal and others added 4 commits September 1, 2026 12:47
…the upstream cause of the six renderer short-circuits

THE FINDING BEHIND THE FIRST ROW. The arbiter-repair design commissions a
divergence census to adjudicate arm A, and states a calibration control: the
diagnostic-producing `DivergesWithExactIdentity` subset must reproduce arm A's
25 sites, joined by source declaration and enclosing declaration, never by
line. That control had never run against the typed-graph census landed by
#9900. It has now, over the transitive import closure of
`src/v2/compiler/01_tokenize.dag`, and it FAILS:

  - `v2.compiler.tokenize`, the module emitting the file where every arm-A site
    lives, contributes 76 rows: 74 Agrees, 2 IdentityUnavailable, ZERO
    DivergesWithExactIdentity. All 26 of its `String`-named rows Agree.
  - Every divergence row in the closure sits in `v2.std.text`, the DECLARING
    module, in the opposite direction.

Empty intersection with the population the control exists to find. That is not
the over-broad walk #9900 predicts — an over-broad walk shows the target
population PLUS extras; this shows it NOT AT ALL. The shape of the absence is
the diagnosis.

The reason is general, and is why it is filed as a class rather than as a
census defect: a two-reader DISAGREEMENT census reports AGREEMENT as healthy,
so the population where both readers are wrong together is invisible to it by
construction. At an arm-A site the short-circuit returns the host spelling
before consulting anything and the authority answers from a fallback that
returns the REFERENCING module's file, so both answer host and agree.

Recognition rule, at the grain that generalises: any two-reader comparison
cited as CORRECTNESS coverage — differential oracles, twin fixtures,
cross-checks, self-hosted-versus-seed. Ask what a shared error would look like
in its output; if the answer is "indistinguishable from health", it is not the
correctness evidence. The remedy is a different oracle reaching outside the
pair, never a repair of the comparison.

SECOND ROW: the same run produced 121 `IdentityUnavailable` rows where the
2026-08-21 front-end-phase run reported zero. Rows that are neither agreements
nor divergences are scored as decided by any ratio over the reported total.
Both runs are NAMED rather than differenced — they are different instruments
at different phases.

THIRD CHANGE: `checkpoint_table_bypasses_identity_note` reads as though the
spelling its six renderers short-circuit on had one meaning. It does not — a
callee parameter type is re-resolved in the CALLER environment, so one
declaration denotes the structural carrier in its own module and the kernel
scalar at every foreign call site. The appended paragraph records that, and
cites #9929 for calm-boar-314's three measurements (qualified spelling
silences rather than pins; returns re-resolve on the same axis; one refusal can
carry two disagreeing destinations) rather than restating them.

No divergence number is published as a measurement of the emitter: the figures
above appear only as the control's failure evidence, which is what the design
asks for in the failing branch.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Vo22gFeUgs7vAVuhsmWqKk
…tions

The carrier conflict was the shared-tail shape this file already documents as
merge_region_excludes_shared_tail — main added sealing_property_erases_structure
while this branch added two rows, with the trailing evidence/brace after the
markers. Both sides kept; verified as a bijection in both directions (34 rows,
34 roster entries, none declared-unrostered and none rostered-undeclared) rather
than by a count.

DESIGN.md and docs/design-ledgers.md carried no conflict markers — the
generated-artifact driver refuses rather than answering — so they are the
regenerated projection of the resolved carrier, not a hand merge.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Vo22gFeUgs7vAVuhsmWqKk
@gunbai-bot
gunbai-bot Bot merged commit 792d6e3 into main Sep 1, 2026
6 checks passed
@gunbai-bot
gunbai-bot Bot deleted the session/bold-carp-449-divergence-blind branch September 1, 2026 15:41
@gunbai-bot gunbai-bot Bot mentioned this pull request Sep 1, 2026
6 tasks
@briansrls
briansrls restored the session/bold-carp-449-divergence-blind branch September 1, 2026 15:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants