Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions DESIGN.md
Original file line number Diff line number Diff line change
Expand Up @@ -185,6 +185,7 @@ The payoff is that **language design itself opens up.** It is normally locked by
One row per class, each carrying its recognition rule and its receipts, in [docs/design-ledgers.md](docs/design-ledgers.md) — authority `gunbc.recurring_failure_mode`. They are rostered there rather than here because they are a LEDGER and not a consequence: every lane that finds a new class appends one, so the section grows without bound while this document's sections are fixed by §1. The index below is the classes; the ledger is the content.

- `censored_estimator_drops_its_own_tail`
- `selection_view_read_as_population`
- `hollow_alias`
- `state_space_conflation`
- `absorbing_fallback`
Expand Down
2 changes: 2 additions & 0 deletions dag/gunbc/recurring_failure_mode.dag
Original file line number Diff line number Diff line change
Expand Up @@ -185,9 +185,11 @@ data accepted_source_emits_uncompilable_target: RecurringFailureMode = Recurring
authored: "**accepted source emits uncompilable target** (INVALID STATE: a .dag construction the front end accepts with zero blocking diagnostics, whose emission is a target program the target compiler refuses. The instance filed here is a coproduct's UNIT VARIANT standing in a NON-APPLIED TYPE POSITION -- a field, parameter or return type spelled with a constructor rather than a type. HARM: section 5 silent wrongness on the source-to-target path. gunbc says Accepted and hands over a program that cannot build, so the only wall that fires belongs to the target's compiler; where a target has no such wall, or where the emitted artifact is never compiled, nothing fires at all. Section 7 makes this the seed's floor and not the target's problem: the .dag graph is the authority and Rust is one realization, so 'rustc catches it' is exactly the outsourcing this project exists to end. THE SPECIMEN IS CARRIED IN THIS ROW RATHER THAN CITED, because the fixture that produced it was never committed to this repository (neat-otter-332, 2026-09-01). Its emitted artifacts are held by that lane's own receipts; no path is given here, since a path outside this repository is not a citation a later reader can resolve. Authored source, two modules: `scope.provider` declares `type Quantity = Time | Memory`; `scope.consumer` does `import scope.provider \{ Quantity, Time \}`, `type NonApplied \{ value: Time \}`, `fn field_as_quantity(subject: NonApplied) -> Quantity \{ subject.value \}`. gunbc accepts it. DISTINGUISHING FACT, and the reason this class must not be read off the target's error code: WHAT rustc says is decided by what else the emitter minted, not by the source defect. Under the NARROW emitter classifier the consumer emits `pub use crate::scope_provider::\{Quantity\};` then `use crate::scope_provider::Quantity::\{Time\};` with no marker binding, and `pub struct NonApplied \{ pub value: Time \}` refuses `error[E0573]: expected type, found variant Time` at `src/scope_consumer.rs:15:16` on `pub value: Time,`, label `not a type`, help `consider importing this struct instead`. Under the BROAD classifier the consumer instead emits `pub use crate::scope_provider::\{Time\};` beside `\{Quantity\}` -- the provider having emitted `pub enum Quantity \{ Time, Memory \}` AND `pub struct Time;` -- so the field declaration COMPILES, and the refusal moves to the function: `error[E0308]: mismatched types` at `src/scope_consumer.rs:20:5` on `subject.value.clone()`, `expected Quantity, found Time`, against `expected Quantity because of return type`. INDEPENDENTLY REPRODUCED AT PARAMETER POSITION on this branch, 2026-09-01 on gunbc baeabbbf80, by a single-file source handed to the compiler: `type StampMode = StampClass | StampOther` with `fn take(stamp: StampClass) -> StampMode \{ stamp \}`. `gunbc compile --target rust` exits 0 with 0 blocking errors, emits `pub fn take(stamp: StampClass) -> StampMode` beside `pub struct StampClass;`, and `cargo check` on the emitted crate refuses `E0308 expected StampMode, found StampClass`. One source defect; E0573, E0308-at-the-parent, and E0308-at-the-body depending on emission. THE MASK IS THE SHARP HALF, and it is fabricated plausible output rather than a lucky green: the broad classifier's marker import made the FIELD-ONLY source compile by substituting a distinct struct for a variant. It never preserved the modelled meaning, and extending the SAME accepted source across its declared parent boundary -- the function returning `Quantity` -- is what exposes it. So the narrow classifier's E0573 is this class becoming VISIBLE, not a regression the narrowing introduced. GENERAL FORM: a green obtained because the emitter manufactured a target-only entity for a source name is not evidence the source is well-typed, and the discriminator is to extend the source past the boundary the manufactured entity does not model. THE ONE .dag-SIDE SIGNAL IS ABOUT THE WRONG QUESTION: on the parameter reproduction the compile printed the ADVISORY `unlisted import use 'StampClass' (referenced but not in any import's name list)`. It fires because the name was not found among types -- the front end reached the exact fact that decides this case and reported it as import hygiene. It is not a partial wall: it is advisory, it names listing rather than type position, and the field specimen above IMPORTS `Time` explicitly, so it does not fire there at all (see `diagnostic_name_mechanism_silent`). RUNG FOUND AT: below the ladder, established by execution at the emission boundary -- the compile accepts and the emitted crate refuses. Section 4b's rung-1 mitigations are absent: nothing at the .dag boundary is typed, located or countable about this construction. CEILING: 4, structurally impossible, and the reason is that constructor identity and type identity are two distinct modelled facts whose membership is decidable from the coproduct declaration -- a variant name is reachable from that declaration as an ARM and never as a type, so the type-position slot has no constructor that admits it. No undecidable predicate is involved, so this is a wall now and not a ratchet. NEXT-RUNG TRIGGER, phrased as the capability that retires the row rather than an artifact that would contribute to one: type-position name resolution that consults the TYPE namespace alone and refuses a name resolving to a constructor with a located diagnostic, sufficient that NO Accepted program contains a variant name in any non-applied type position -- field, parameter or return. Repairing either specimen, narrowing the emitter classifier, or adding a fixture satisfies less than that and does not retire this row. RECOGNITION RULE: when the target compiler names a symbol at a type position, check whether that symbol is declared as an ARM of a coproduct in the source; if it is, the defect is in accepted .dag and the target compiler is the only wall that fired. SCOPE STATED RATHER THAN GENERALISED: executed for a unit arm at a field type and at a parameter type, Rust target only. Record-shaped arms, applied positions such as `List<Time>`, and other targets were not measured and are not claimed.)",
evidence: [],
}
data selection_view_read_as_population: RecurringFailureMode = RecurringFailureMode { identity: "selection_view_read_as_population" as NonEmptyStr, authored: "**a selection view read as the population** (a decidable predicate is written over MEASURED values -- cost at or above N, latency under N, rows a report printed -- and its output is then treated as the population of the class under study. Membership in that set is a property of THE MEASUREMENT, not of the subject: it moves when the instrument moves, when load moves, when the reporter truncates, while the subject is unchanged. The set and the population are two objects joined by an assumption nobody states, and the assumption is false exactly when the measured quantity carries an unbounded term the threshold cannot see beneath. **WHAT MAKES THIS DIFFERENT FROM ITS NEIGHBOURS IS THE ROUTE IT ARRIVES BY, AND THAT IS ALSO THE WHOLE DIFFICULTY: IT ARRIVES AS THE FIX FOR A REAL OBJECTION.** `instrument_output_read_as_subject_content` is a report read past its own promise, and its closest unnamed relative here is a statistic computed over the observations that SURVIVED a threshold on the very variable being estimated -- filed separately as `censored_estimator_drops_its_own_tail`, and cited here by identity because that row now resolves in this tree; it was carried descriptively while it was unlanded, since a boundary drawn against a symbol that does not resolve is worse than a boundary drawn descriptively. Both of those are errors in the READING. This one is produced BY diligence. The predicate is decidable, it is honestly derived, and it is very often the correct answer to a legitimate refusal -- which is precisely why the next question does not get asked. **BEING CAREFUL IS WHAT MAKES IT INVISIBLE: the diligence is spent on the repair, and the repair's correctness is what stops anyone asking whether it answers the question that was posed.** A defect arriving inside a correct fix is not caught by the diligence that produced the fix. SPECIMEN, WITH BOTH ENDS BELONGING TO THE SAME AUTHOR THREE HOURS APART, which is why it is filed rather than blamed. (i) A peer lane computed a median and p95 over the rows a required-floor run's `[over-cost]` listing PRINTED -- an instrument that ranks by cost and truncates to a fixed head, and whose own closing line says so and names the per-claim cost artifact the run uploads as the complete population. This author correctly told them an order statistic of a truncated tail describes nothing, because the truncation is a property of the REPORTER. THE TWO PRODUCERS ARE NAMED RATHER THAN THEIR OUTPUTS TRANSCRIBED, per DESIGN section 6: the truncated view is that `[over-cost]` listing, and the population is `required_floor_claim_cost.tsv` as uploaded by the same run -- either is re-derivable from any floor run, and no count here needs to be trusted. (ii) The same author then had a declared drop refused for defining its population as `every required row whose headroom is smaller than the observed inflation` while calling that inflation censored with no upper bound -- an undecidable membership predicate, correctly refused under DESIGN section 4b(3). The fix was a decidable admission rule over each run's own per-claim cost artifact, which was the right repair for the refusal, and its output was then written into the row AS THE POPULATION. With an unbounded contention term, no lower threshold can prove the rows beneath it unaffected, so the set was a view the whole time. REPAIR: name the closed subject universe from the SUBJECT rather than from any measurement -- for the specimen, every required identity for which the cpu deadline is armed while it executes under the uncontrolled shared-runner envelope -- and keep the threshold set, which is genuinely useful, under an honest name: an EXPOSED ATTENTION SUBSET for prioritising work. A COROLLARY WORTH CARRYING SEPARATELY, because conflating the two hides the seam: the evidence floor behind such a threshold may be MONOTONE while the membership set is NOT. An observed floor only rises, so a constant derived from it only falls; individual identities still enter and leave the subset as their measured values vary. Monotonicity of the bound says nothing about stability of the set. **RECOGNITION RULE: when a set is produced by comparing a MEASURED value against a threshold, ask what the set would contain if the measurement were taken again under different conditions -- and ask it hardest when the predicate was just written to satisfy a reviewer, because that is the moment the answer feels settled.**)", evidence: [] }

data recurring_failure_mode_roster: List<RecurringFailureMode> = [
censored_estimator_drops_its_own_tail,
selection_view_read_as_population,
hollow_alias,
state_space_conflation,
absorbing_fallback,
Expand Down
Loading
Loading