Skip to content
Closed

XL-0 #9950

Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 2 additions & 0 deletions DESIGN.md
Original file line number Diff line number Diff line change
Expand Up @@ -216,6 +216,8 @@ One row per class, each carrying its recognition rule and its receipts, in [docs
- `mitigation_injected_where_judgment_declined`
- `merge_region_excludes_shared_tail`
- `sealing_property_erases_structure`
- `disagreement_census_blind_to_agreed_wrong`
- `undecided_fraction_read_as_denominator`
- `restoration_promise_names_a_route_that_does_not_exist`

## Building & checks
Expand Down
14 changes: 14 additions & 0 deletions dag/gunbc/recurring_failure_mode.dag
Original file line number Diff line number Diff line change
Expand Up @@ -149,6 +149,18 @@ data unbacked_execution_claim: RecurringFailureMode = RecurringFailureMode { ide

data merge_region_excludes_shared_tail: RecurringFailureMode = RecurringFailureMode { identity: "merge_region_excludes_shared_tail" as NonEmptyStr, authored: "**merge region excludes the shared tail** (a roster carrier whose rows are multi-line blocks ending in an identical suffix makes every two-lane append resolve WRONG BY DEFAULT. The three-way merge factors the shared suffix out of the conflict region, so the region holds two half-blocks above the markers and one tail below them, and the purely additive resolution -- delete the markers, keep both sides, which is the CORRECT resolution when the two appended rows are independent -- leaves the first row's closing lines belonging to the second. Specimen: this carrier, which conflicted on every integration of main across four merge bases in one session (2026-09-01) with a shared tail of `evidence: [],` and `}`; `gunbc.rung_drop` had the same shape with `}` alone. **THE CLASS IS LOUD, AND THAT IS THE HALF A REPORT OF IT WILL GET WRONG.** The first reading was that the severed row survives as a structurally broken declaration under which the natural check -- declared names against rostered names -- still passes, because both lists stay complete. Measured against a gunbc built at d0009ca531 on the resolved shape: it is a PARSE REFUSAL at the module index, `expected expression, found Eq`, because a `data` keyword cannot stand in record-field position. Nothing reaches the checks that reading worried about, so the cost is toil and not silent wrongness -- a load-bearing authority whose every integration lands a conflict whose natural resolution does not compile, hand-repaired each time. **RECOGNITION RULE: for a carrier two lanes append to, ask what suffix the appended units SHARE, because a conflict region never contains it -- whatever semantics live in that suffix are exactly what a resolution can drop.** THE REPAIR IS THE UNIT AND NOT A CHECK: make the appended unit one line, and the shared suffix is a blank separator carrying nothing. A brace-balance or name-join check written here would be the DESIGN section 4b decoration -- permanently green, because the compiler already refuses the only corpus it could fire on.)", evidence: [] }

data disagreement_census_blind_to_agreed_wrong: RecurringFailureMode = RecurringFailureMode {
identity: "disagreement_census_blind_to_agreed_wrong" as NonEmptyStr,
authored: "**a two-reader disagreement census is blind to the case where BOTH readers are wrong together** (an instrument whose subject is DISAGREEMENT between two producers of one answer reports AGREEMENT as healthy, so the population where both answer the same WRONG thing is scored green and is invisible to it by construction. The trap is that such an instrument is commissioned precisely to adjudicate a known-defective population, and it can be structurally incapable of seeing that population while looking perfectly well-formed and producing rows. **SPECIMEN, measured 2026-09-01.** `v1.tests.claim.carrier_realization_census` records, per type-reference occurrence, the legacy short-circuit key and the strict authority answer, and reports where they diverge. Its calibration control -- stated in docs/plans/carrier-realization-arbiter-repair-design.md -- requires the diagnostic-producing `DivergesWithExactIdentity` subset to reproduce arm A 25 sites, joined by source declaration and enclosing declaration, never by line. Run over the transitive import closure of `src/v2/compiler/01_tokenize.dag`, the module that emits the file where every arm-A site lives contributed 76 rows: 74 Agrees, 2 IdentityUnavailable, ZERO divergences, and all 26 of its `String`-named rows Agree. Every divergence row in the closure sat in `v2.std.text`, the DECLARING module, in the opposite direction. Empty intersection with the population the control exists to find. **THE SHAPE OF THE ABSENCE IS THE DIAGNOSIS, and it is what distinguishes this class from an over-broad walk.** `gunbc#9900` predicted the walk might visit occurrences the emitter never renders; that defect shows the target population PLUS extras. This showed the target population NOT AT ALL. Same instrument, same rows, opposite conclusions -- and only the shape separates them. **WHY BOTH READERS AGREE THERE**, read off `v1.compiler.emit_rust` `checkpoint_table_bypasses_identity_note` REACHABILITY CORRECTION rather than executed here: the short-circuit returns the host spelling before consulting any authority, and the authority answers from `type_reference_decl_file`, whose fallback returns the file containing the REFERENCE. Two readers, one wrong answer, perfect agreement. **RECOGNITION RULE: any two-reader comparison cited as CORRECTNESS coverage.** A differential oracle, a twin fixture, a cross-check, a self-hosted-versus-seed comparison, an A/B over two emitters -- each answers `do these two concur`, and none answers `is the answer right`. Ask what a SHARED error would look like in its output; if the answer is `indistinguishable from health`, the instrument cannot be the correctness evidence, whatever else it is good for. **THE REMEDY IS A DIFFERENT ORACLE, NOT A REPAIR OF THIS ONE.** The adjudicating instrument has to reach OUTSIDE the pair of readers for its ground truth -- for this specimen, a census of agreement-at-a-wrong-answer joined against emitted-crate diagnostics. Widening the occurrence set, fixing the walk, or adding a third reader that shares the same defective input do not help, and the first two are what a reader who diagnosed this as an over-broad walk would have spent. **Bounded against `executed_conjunct_discriminates_nothing`**: there a live gated conjunct never meets a population that would falsify it, and one authored fixture retires it; here the instrument meets its population on every run and reports it as healthy, so no fixture over this instrument can retire it. **Bounded against `instrument_output_read_as_subject_content`**: there the instrument answers its own question faithfully and a consumer substitutes the subject; here the instrument answers ITS OWN question faithfully too, and the defect is that its question -- do the readers concur -- was never the question that was asked.)",
evidence: [],
}

data undecided_fraction_read_as_denominator: RecurringFailureMode = RecurringFailureMode {
identity: "undecided_fraction_read_as_denominator" as NonEmptyStr,
authored: "**a census with an unresolvable fraction of its population reports a denominator it does not have** (an occurrence census that emits a third disposition for `could not determine` is honest at the row grain and misleading at the total grain: rows scored `identity unavailable` are neither agreements nor divergences, so any ratio taken over the reported total silently treats them as decided. **SPECIMEN, unowned and unexplained at filing (2026-09-01).** The `v1.tests.claim.carrier_realization_census` run over the `src/v2/compiler/01_tokenize.dag` closure produced 121 `IdentityUnavailable` rows -- roughly a tenth of its population. The earlier run recorded in docs/plans/carrier-realization-arbiter-repair-design.md, over the same subject module at the FRONT-END phase on 2026-08-21, reported `1142 rows: 1134 Agrees, 8 DivergesWithExactIdentity, 0 IdentityUnavailable`. Zero to a tenth, across a phase change nobody predicted it for. **BOTH RUNS ARE NAMED RATHER THAN THEIR NUMBERS INHERITED**: the earlier is the front-end-phase run the design itself later withdraws as measuring the wrong phase, and the later is the typed-graph census landed by `gunbc#9900`. They are not the same instrument and the pair is recorded to locate the question, not to compute a delta from. **RECOGNITION RULE: an instrument with a `cannot answer` disposition, whose consumers aggregate over the reported total.** Ask what fraction is undecided before reading any ratio, and treat the undecided fraction as a separate finding rather than as noise. **WHY IT IS FILED WITHOUT INVESTIGATION**: identity being unavailable is a different defect from the readers disagreeing, it has no owner, and it was found while running a control for an unrelated question. A row that records it with both runs named is what stops the next reader taking the census denominator at face value.)",
evidence: [],
}

data sealing_property_erases_structure: RecurringFailureMode = RecurringFailureMode {
identity: "sealing_property_erases_structure" as NonEmptyStr,
authored: "**a construction-restricting property read as a structure-erasing one** (a declaration is annotated to RESTRICT how its inhabitants may be built, and a consumer that asks about the declaration's SHAPE treats the annotation as a reason to stop looking -- so the deliberate climb on the construction axis silently drops a rung on every axis decided by shape, with no declaration, because the two axes are read by different consumers. **THE INVERSION IS THE CLASS**: the annotation exists to make the carrier MORE distinct from its payload, and the consumer's response is to make it INDISTINGUISHABLE from everything. Recognition rule, keyed on the SHAPE and not on any one keyword: whenever a declaration-level marker is stored in a general side-channel -- a properties list, an attribute bag, a modifier set -- find every consumer that BRANCHES ON THAT CHANNEL BEING NON-EMPTY rather than on the specific marker, and ask what each of them would have answered had the marker been absent; a consumer that answers 'opaque', 'unknown', or 'skip' for the whole channel has conflated 'this declaration carries a marker I do not model' with 'this declaration has no structure', and every future marker inherits the same silence on arrival. **SPECIMEN, with the discriminating pair** (gunbc XL-0-FLOOR, 2026-09-01): `v2.compiler.normalized_tree` `NormalizedTree` was sealed by BL-1 from an alias for `Node` into a `sole_constructor` record so that a wrapper-retention drop would be unwritable. `sole_constructor` is carried as a PROPERTY on the declaration node (`v1.compiler.parse` `parsed_sole_constructor_properties`), and `v1.compiler.infer` `exposure_view_for_node` answered `OpaqueTypeHead` for any node whose properties list was non-empty -- so `nominal_product_head_name` answered the empty string for every sealed carrier, `nominal_product_inhabitance_refusal` short-circuited on the empty head, and `declared_type_inhabitance` fell through to `Inhabits`. `v2.compiler.source_authority` `normalized_source_ast_equal_witness` then bound a `NormalizedTree` at a formal declared `Node` and the compiler ACCEPTED it: the ordinary-floor violation DESIGN section 4b names as exact application bijection, below baseline. The discriminating pair is two record declarations identical to the token except for the word `sole_constructor` -- the sealed one compiled with zero diagnostics where the plain one refused. **WHY A CENSUS MISSED IT, which is the part that generalizes**: gunbc#8886 measured 285 sites behind the `v2.*` direct-call argument-type exemption, of which 148 were `Node` against `ResolvedTree`/`ParseTree` and siblings -- every one a transparent-ALIAS false positive. This shape never appears in that roster and could not have, because it is a TRUE positive the comparison relation cannot reach: the census enumerates what the relation REFUSES, so a defect the relation is blind to is invisible to the census by construction, and a large census reads as thorough coverage of exactly the region it cannot see. **THE MISDIAGNOSIS THIS CLASS INVITES, recorded because this lane was dispatched with it**: the silence sat inside a module the exemption covers, so the exemption was the obvious cause; refuting it took running the identical program in an ordinary module and on a tree with the exemption deleted, both of which stayed silent, while the same run showed the exemption's effect on a kernel red so the arms were provably live. A plausible nearby mechanism that is genuinely broken is the most expensive wrong answer available, because repairing it changes nothing and the repair reads as coverage. **Rung: mechanically preventable, and the ceiling for this class as a class is the same rung.** The repair makes one marker structure-preserving by positive establishment -- the parser builds the identical declaration node and only the properties list differs -- and every OTHER marker in that channel stays opaque and unmeasured, which is a named residue rather than a covered class. The next-rung trigger is a CAPABILITY: markers carried in the declaration's own type rather than in an untyped side-channel, so that a consumer branching on the channel cannot compile.)",
Expand Down Expand Up @@ -190,5 +202,7 @@ data recurring_failure_mode_roster: List<RecurringFailureMode> = [
mitigation_injected_where_judgment_declined,
merge_region_excludes_shared_tail,
sealing_property_erases_structure,
disagreement_census_blind_to_agreed_wrong,
undecided_fraction_read_as_denominator,
restoration_promise_names_a_route_that_does_not_exist,
]
Loading
Loading