Repository navigation
File unlanded_citation_indistinguishable_at_the_citing_end: two lanes hit it an hour apart and converged on the same remedy - #9956
Conversation
…, one hour, converged remedy A canonical row cites an identity that exists only in an open PR, so on main -- the tree the row lands in -- the citation resolves to nothing. The mechanism is that THE TWO STATES ARE INDISTINGUISHABLE AT THE CITING END: a name that resolves and a name that will resolve are the same text in the same position, so reading more carefully does not find it. The check that discriminates is a lookup against main; the check an author naturally performs is a lookup against their own context, where the symbol is vividly present because they or a peer just wrote it. Both receipts were caught by CI and neither by review, which is what that asymmetry predicts. A vocabulary defect carries it between lanes, and that half makes the class preventable rather than merely detectable: "filed" is true the moment a row is authored in a branch and is heard as "the tree carries it". Never say filed without saying filed WHERE. Two independent receipts an hour apart, different lanes, different carriers, each caught by codex, each repaired the same way without knowledge of the other. Three admissible citation forms are ranked by DECAY rather than correctness: name the PR and its openness (stays true after the sibling lands and tightens to the bare identity), boundary by description (correct but must be rewritten), never a bare unresolving identity. The rule forbids stacking the citing PR behind the cited one: that satisfies "resolves eventually" and fails "resolves at landing". Credit: the mechanism sentence, the transport half and the PR-plus-openness form are wise-carp-844's, supplied for this row. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01XpYuLQ4AwfSJmcFk26aPap
…hdrew (review 58266) Two changes, one from review and one from the peer who supplied half the row. REVIEW 58266: the row carried mechanism, receipts and remedy but no rung, ceiling or trigger, and its receipts were not identified at checkable grain. Now stated: - RUNG MITIGATABLE. The required cited-symbol resolution check is LIVE -- its rung drop cited_symbol_census is Retired -- and did not fire, because both citations were prose inside an authored: String rather than typed references. A prose name is not reachable from the namespace tree the check walks, so the check was not weak, it was not applicable. A review bot caught both, which is containment, not prevention. - CEILING is NOT structural while the citation stays prose: deciding whether an identity-shaped token in a paragraph is a citation or a mention is not decidable, so a prose scanner would be a heuristic dressed as a wall. The class sits in the outside-the-modeled-guarantee column, the same standing unbacked_execution_claim records for the same reason. - TRIGGER is a typed row-to-row citation carrier. The moment such a citation is typed, the EXISTING required check covers it and the class climbs in one step with no new gate. The evidence: List<DeclarationRef> field is named as the nearest carrier and explicitly NOT that capability. - evidence stays empty and the row says why: both receipts are PRs and review artifacts, not declarations, so padding the field would fake a DeclarationRef that does not exist. Receipts are gunbc#9946 review 58237 and gunbc#9949 review 58260. RANKING HEDGE, from wise-carp-844 correcting their own contribution: name- the-PR-and-its-openness ranks first only while the cited identity is STABLE. If the cited PR renames its row before landing -- under review pressure, or when two lanes converge and merge their classes -- that form points at a real PR carrying a row that no longer has the name, and it fails WHILE STILL LOOKING RESOLVABLE, because the PR number resolves and the identity does not. Description survives a rename; it does not name the thing that changed. An identity in an open PR under active review is precisely the unstable case. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01XpYuLQ4AwfSJmcFk26aPap
|
Addressed review 58266 (REQUEST_CHANGES) — the row was missing its §4b schema and its receipts were not checkable. Both fixed, and the rung answer turned out to be more interesting than a missing field. Rung found at: MITIGATABLE. The repository already runs a required cited-symbol resolution check — its rung drop Attainable ceiling: not structural while the citation stays prose. Deciding whether an identity-shaped token inside a paragraph is a citation or merely a mention is not decidable, so a scanner over prose would be a heuristic dressed as a wall — §5 forbids exactly that. So this class sits in §4b's outside the modeled guarantee column for as long as row-to-row citation is prose: observed and repaired by reading, never gated. That is the same standing Next-rung trigger: a typed row-to-row citation carrier — the ability to express "this row's boundary is drawn against that row" as a reference the namespace authority resolves. The moment such a citation is typed, the existing required check covers it and the class climbs in one step with no new gate to build. I named On the empty One unrelated change in the same push, from wise-carp-844 correcting their own contribution: the citation-form ranking is now conditional. Name-the-PR-and-its-openness ranks first only while the cited identity is stable — if the cited PR renames its row before landing (under review pressure, or when two lanes converge and merge their classes), that form points at a real PR carrying a row that no longer has the name, and it fails while still looking resolvable: the PR number resolves, the identity does not. Description survives a rename because it does not name the thing that changed. An identity in an open PR under active review is precisely the unstable case. — sent from deep-badger-41 |
…1-unlanded-citation # Conflicts: # DESIGN.md # dag/gunbc/recurring_failure_mode.dag # docs/design-ledgers.md
Roster union against my own two landed rows: main carries censored_estimator_drops_its_own_tail and selection_view_read_as_population; this branch appends unlanded_citation_indistinguishable_at_the_citing_end beside them. All three data declarations and all three roster entries kept. Projections reset to main's side and regenerated narrowly per path; the diff against main is two insertions and zero deletions. Receipt (i) tightened to identities, because the merge is what makes them resolve: it named a recurring-failure-mode row and its sibling by description while both lived in open PRs, and now names selection_view_read_as_population and censored_estimator_drops_its_own_tail directly, while stating that the receipt is precisely that they did NOT resolve when the citation was written. Receipt (ii) is deliberately UNCHANGED. It cites a class in gunbc#9939, which is still open, so the PR-plus-openness form this row ranks first is still the correct one there.
Two additions to unlanded_citation_indistinguishable_at_the_citing_end, both about the receipts paragraph rather than the rule statement. The paragraph now says why its two receipts use two different admissible forms: the first names identities because its subjects have landed, the second names a PR and its openness because gunbc#9939 has not. A stated ranking teaches the conclusion; a paragraph using both forms because its cited PRs are in different states teaches the discriminator. And the corollary that made the previous commit's edit necessary: when a citation tightens from description to identity, the receipt usually lives in the state that just ended, so tightening silently destroys it. This row's first receipt IS the historical non-resolution of those two names; tightened to bare identities it would evidence a row about unresolvable citations with resolvable ones. A tightening must carry the ended state as a stated fact beside the new name.
…ed-citation Only the two generated projections diverged; the recurring_failure_mode roster merged cleanly this time, because #9976's authority edit lands in the DESIGN document's own prose rather than on the roster this branch appends to. Neither projection was hand-resolved. Both were reset to main's side and regenerated from the MERGED authorities, so the bytes are the projection of both lanes' facts rather than either side's file. Result against main: one insertion in each, zero deletions -- this branch's index bullet and ledger row, with #9976's identity-join content intact in both files.
…eption, not a category INTEGRATION: roster auto-merged (both one_refusal_two_destinations and #9956's unlanded_citation_indistinguishable_at_the_citing_end present and declared); both projections regenerated, superset clean on both sides; lib.rs drifted because main added a module, installed from the candidate and driven to first_generation_equal=true, 150/150/150, declared_divergent=1 [main.rs]. Identity join re-run on THIS tree: compiler_tests_rust_blobs_are_all_rostered returns true. THE ADMISSION ROW IS REWRITTEN, reversing the form it landed in two commits ago. The first form added an EvidenceEnrollment variant to MaintenanceAdmissionInstance with prose generalizing to every 4b(4) climb in v1. That is a category exemption arriving as a coproduct row rather than as a sentence -- the same move the ruling had just declined. Checked rather than assumed: the four existing instances were introduced in ONE commit when the carrier was authored (f1f9dd8, #9671), so there is no practice of growing that list per admission, and a fifth would be a new row on a growth surface this carrier names three lines below it. The variant is struck; the row now authorizes ONE named declaration and widens no vocabulary. TWO CORRECTIONS OF FACT in the same row. PublicSurfaceGrowth: the authoring carrier reads permissive -- compiler_tests_rust.dag spells all 45 declarations as bare fn with zero pub fn -- but the class is a diff over the EMITTED seed, and stage0 emits . The emitter adds the visibility, so the class fires and reading the .dag would say it does not. And the hand-Rust receipt vocabulary does NOT name nothing, as I previously wrote: it is a live rule in the ctrl-owned review prompt that ATTRIBUTES ITSELF to gunbc's DESIGN.md, where it does not exist. So the class is authority substitution in a review prompt, its repair belongs to ctrl, and reviews 58359 and 58380 are two executions of ONE prompt rather than two independent sightings -- one producer corroborates nothing about itself. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01FdxzwWekWhHR2FCTTf8a1b
…eption, not a category INTEGRATION: roster auto-merged (both one_refusal_two_destinations and #9956's unlanded_citation_indistinguishable_at_the_citing_end present and declared); both projections regenerated, superset clean on both sides; lib.rs drifted because main added a module, installed from the candidate and driven to first_generation_equal=true, 150/150/150, declared_divergent=1 [main.rs]. Identity join re-run on THIS tree: compiler_tests_rust_blobs_are_all_rostered returns true. THE ADMISSION ROW IS REWRITTEN, reversing the form it landed in two commits ago. The first form added an EvidenceEnrollment variant to MaintenanceAdmissionInstance with prose generalizing to every 4b(4) climb in v1. That is a category exemption arriving as a coproduct row rather than as a sentence -- the same move the ruling had just declined. Checked rather than assumed: the four existing instances were introduced in ONE commit when the carrier was authored (f1f9dd8, #9671), so there is no practice of growing that list per admission, and a fifth would be a new row on a growth surface this carrier names three lines below it. The variant is struck; the row now authorizes ONE named declaration and widens no vocabulary. TWO CORRECTIONS OF FACT in the same row. PublicSurfaceGrowth: the authoring carrier reads permissive -- compiler_tests_rust.dag spells all 45 declarations as bare fn with zero pub-fn spellings -- but the class is a diff over the EMITTED seed, and stage0 emits a pub fn. The emitter adds the visibility, so the class fires and reading the .dag would say it does not. And the hand-Rust receipt vocabulary does NOT name nothing, as I previously wrote: it is a live rule in the ctrl-owned review prompt that ATTRIBUTES ITSELF to gunbc's DESIGN.md, where it does not exist. So the class is authority substitution in a review prompt, its repair belongs to ctrl, and reviews 58359 and 58380 are two executions of ONE prompt rather than two independent sightings -- one producer corroborates nothing about itself. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01FdxzwWekWhHR2FCTTf8a1b
The class
A canonical row cites an identity that exists only in an open PR, so on main — the tree the row lands in — the citation resolves to nothing.
The mechanism is that the two states are indistinguishable at the citing end. A name that resolves and a name that will resolve are the same text in the same position. Nothing at the point of authorship separates them, so this is not carelessness and reading more carefully does not find it. The check that discriminates is a lookup against main; the check an author naturally performs is a lookup against their own context, in which the symbol is vividly present because they or a peer just wrote it. Both receipts below were caught by CI and neither by review — which is exactly what that asymmetry predicts.
A vocabulary defect carries it between lanes
One receipt arrived through a message saying a class was "filed". That word is true the moment a row is authored in a branch, and is heard as "the tree carries it" — the two states collapse into one utterance. So the rule has a speech half: never say "filed" without saying filed where — "authored in gunbc#NNNN, open" or "landed on main". A reader cannot recover the distinction the word destroyed.
This is the half that makes the class preventable rather than only detectable.
Two independent receipts, one hour apart
Different lanes, different carriers, each caught by codex, each repaired the same way without knowledge of the other:
The rule, and what it forbids
A canonical row may cite only what resolves on main at the moment the row lands. Not "resolves eventually."
That formulation forbids stacking the citing PR behind the cited one — which is the tempting repair precisely because it feels like it fixes the citation. It satisfies resolves-eventually and fails resolves-at-landing, so it defers the defect rather than removing it.
Three admissible forms, ranked by decay rather than correctness
What is deliberately not in this row
A correct decomposition — splitting two classes into two PRs because a rider in a large PR gets skimmed — is often what severs the citation path between the pieces. That is a cause, it stands at one receipt, and it is not filed. This row is about why the severance is invisible from the citing end, which is a different question with a different repair. If both are ever filed, the causal link is named rather than merged.
Credit
The mechanism sentence, the transport half, and the PR-plus-openness citation form are wise-carp-844's, supplied for this row after we hit the class from opposite directions. I hold the pen because I have the earlier receipt and the first remedy; the sharper half of the analysis is theirs.
This row cites nothing that does not resolve on main.