From aa348d104d5a0207474d8fa3cddc7ceb867c8e9c Mon Sep 17 00:00:00 2001 From: Arena Agent Date: Sun, 4 Oct 2026 20:01:38 +0000 Subject: [PATCH 1/7] docs(recon): type-family position recon, 2026-10-04 Deep recon across echo-types, epistemic-types, residual-evidence-types, choreographic-types, tropical-types, occupancy-types and absolute-zero, with the nextgen-typing coordination hub and the satellite repos. Evidence-tagged: [RAN] (re-run here), [CI] (hosted run with id), [DOC] (repo's own recorded status), [ISSUE], [INFER]. HEAD SHAs pinned per repo. Records: what is established, what is nearly there, what is within reach, what is blocked, and the open research line - plus the estate CI posture (96/100 startup_failure here; two documented estate mechanisms) and the named cross-family connection obligations. Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com> --- docs/recon/TYPE-FAMILY-POSITION-2026-10-04.md | 646 ++++++++++++++++++ 1 file changed, 646 insertions(+) create mode 100644 docs/recon/TYPE-FAMILY-POSITION-2026-10-04.md diff --git a/docs/recon/TYPE-FAMILY-POSITION-2026-10-04.md b/docs/recon/TYPE-FAMILY-POSITION-2026-10-04.md new file mode 100644 index 0000000..c1bc1d3 --- /dev/null +++ b/docs/recon/TYPE-FAMILY-POSITION-2026-10-04.md @@ -0,0 +1,646 @@ +# Type-family position — deep recon + +**Date of recon:** 2026-10-04 · **Prepared in:** `occupancy-types` @ `arena/01a1087c-occupancy-types` +**Scope:** `echo-types`, `epistemic-types`, `residual-evidence-types`, `choreographic-types`, +`tropical-types`, `occupancy-types`, `absolute-zero`, plus the coordination hub +`nextgen-typing` and the satellite repos. + +--- + +## 0. How to read this, and how much to trust it + +The estate is unusually well instrumented for honesty — AFFIRMATIONs, PROOF-STATUS +receipts, retraction ledgers, kill criteria, blocked-item registers. This document tries +to hold to that same standard, so every claim below is tagged with **how we know it**: + +| Tag | Meaning | +|---|---| +| **[RAN]** | I ran the command in this session and saw the result. First-hand. | +| **[CI]** | A hosted CI job on the recorded commit passed; run id/URL given. | +| **[DOC]** | The claim is the repo's own recorded status (PROOF-STATUS / AFFIRMATION / STATE / README), reproduced by an author in a stated environment, **not** re-run by me and not covered by a CI receipt in this recon. | +| **[ISSUE]** | The claim comes from a filed issue (i.e. a known, acknowledged defect or task). | +| **[INFER]** | My inference from file evidence; stated plainly as such. | + +**Calibration — what this session could and could not do.** This sandbox has +`python3` and `git` only. It has **no** `agda`, `lean`/`lake`, `idris2`, `coqc`, +`isabelle`, `mizar`, `z3`, `just`, `bun`, or Rust toolchain. Therefore: + +* Every Agda / Lean / Isabelle / Coq result is **[DOC]** or **[CI]** — I did **not** + re-typecheck any proof. Where a hosted run exists, I cite the run id. +* The one proof-adjacent thing I could re-run was `occupancy-types`' Session IR gate — it + passed 14/14 **[RAN]**. +* Repo trees, docs, roadmap text, ledger entries, workflow contents, CI conclusions, + issue text and commit signatures were all read directly from clones and the GitHub API. +* CI conclusions were read from the API, not inferred from READMEs or badges. + +**Anchor pins** (HEAD at recon time; all commits GPG-verified **[API]**): + +| Repo | HEAD | Date | +|---|---|---| +| echo-types | `da140cc26f` | 2026-10-03 | +| epistemic-types | `eb810d4ee7` | 2026-10-04 | +| residual-evidence-types | `62d7490754` | 2026-10-02 | +| choreographic-types | `71ba51d3b8` | 2026-10-03 | +| tropical-types | `ad7bfdfd56` | 2026-10-03 | +| occupancy-types | `2e276c365f` | 2026-10-04 | +| absolute-zero | `5f27136835` | 2026-10-02 | +| nextgen-typing | `70df154951` | 2026-10-01 | +| EchoTypes.jl | `a0ac9131f7` | 2026-10-01 | +| EpistemicTypes.jl | `6ab3fb4a01` | 2026-10-01 | +| ResidualEvidenceTypes.jl | `abe97d5c99` | 2026-10-01 | +| secret-types | `aed3f1cc2d` | 2026-10-04 | + +### The three-tier vocabulary used throughout + +* **There (established)** — a machine-checked artefact exists *and* it is either + receipted by a current CI run or reproducible by a named local command; the claim is + fenced by an explicit written boundary. +* **Nearly there** — the artefact exists in the tree but one link is missing: no CI lane, + no toolchain run, an unwired module, a stale state file, or a theorem that is true but + degenerate relative to the claim it is cited for. +* **Within reach** — the repo's own next step, already specified in a roadmap, ledger + entry, or open issue, needing no new research — only work. Everything beyond this line + is named as **open research** rather than aspiration. + +--- + +## 1. The estate map (as it stands) + +The five research families and their owning repos, with questions and boundaries exactly +as `nextgen-typing`'s shared guide states them **[DOC: TYPE-CONNECTIONS.adoc]**: + +| Family | Question | Fence (what it is *not*) | +|---|---|---| +| **echo-types** | Which possible origins lie over an output after a transformation? `Echo f y = Σ (x : A), f x ≡ y` | An output need not identify its origin; a numeric residue measure does not determine residue structure | +| **epistemic-types** | From which standpoint is a claim available, with what evidence? `E κ A` | Having evidence ≠ proof of the claim; belief/knowledge/sound warrant have different interfaces | +| **tropical-types** | How do declared resource bounds compose? | The algebra must be stated; a bound is neither a probability nor an Echo residue identity | +| **residual-evidence-types** | Which worlds satisfy an observation *and* its evidence constraints? | Constructing a candidate does not recover the world; real-world soundness needs the actual-world premise | +| **choreographic-types** | What happens to distinctions, bounds and warrants under projection to participants? | A causal-order cut is not Gentzen cut-elimination, nor causal identification; the general K-CUT is open | + +Neighbours in the same map but **out of the type family proper**: + +* **occupancy-types** (this repo) — *state* resource grades (HWM monoid, non-commutative), + deliberately separated from tropical *cost* grades; session/protocol frontier reclamation. +* **absolute-zero** — CNO (certified null *effect*) and OND (certified null *disclosure*); + a multi-prover effort with an Echo bridge module. Not one of the five families; connected + to them (and proposed for a map row in absolute-zero#175 **[ISSUE]**). +* **secret-types** — new (created 2026-09-27), specification-stage only. Owner ruling + 2026-10-04: this is the home for secret types; `epistemic-types` adds no Secret API; + epistemic-types#29 closed, #32 transfer pending GitHub issue-write access **[DOC: STATE.a2ml]**. +* **nextgen-typing** — the coordination hub: shared glossary, ownership routing, the + cross-project proof. It hosts no family code. + +**Vocabulary fences that are load-bearing and currently holding** (worth stating because +they are the estate's main defence against concept collapse): + +> cost grade ≠ occupancy (HWM) grade ≠ echo index ≠ residue measure ≠ warrant ≠ residual + +The guide is explicit that the five families are **complementary questions, not ranks of +type-system strength**, and that dashed arrows in the map assert *conceptual use or a +proposed research task* — not dependency, equivalence, or a checked bridge +**[DOC: TYPE-CONNECTIONS.adoc]**. + +--- + +## 2. Per-repo deep recon + +### 2.1 `echo-types` — the most developed family member + +**What it is.** Constructive Agda formalisation of proof-relevant fibres as witnesses of +structured (non-total) information loss. 209 `.agda` files under `proofs/` **[RAN: file count]**; +the verified closure (`proofs/agda/All.agda`) is described as ≈200 modules and +**postulate-free**. + +**There (established).** +* The Agda suite typechecks under `--safe --without-K`, and the **hosted Agda job is green** + on current main: run `37152181722` @ `da140cc2`, 2026-10-03 **[CI]**. +* A canonical-identity spine landed 2026-05-27: `EchoTotalCompletion` (`A ≃ Σ B (Echo f)`), + the (equivalence, projection) factorisation, no-section results, four-axis loss/residue + taxonomies, and audience modules **[DOC: PROOF-STATUS, README]**. +* **Matched-negative separation proofs** — where the identity claim does its real work: + Echo is not distinguished by Shannon entropy; the LL `!A := 1` shallow-encoding gap; + equal measure ⇏ equal Echo (`Echo.Separation.NotResourceInstance`) **[DOC]**. +* An ordinal/Buchholz track with a sound carrier: doubled-ladder well-foundedness, + Brouwer `ω^^_`/`ε₀`, and a real Buchholz notation order with well-foundedness **[DOC]**. +* Retraction discipline: R-2026-05-18 narrowed four headline claims (graded comonad → + thin-poset reindexing modality; universal property → funext-relative pointwise mediator; + model-independence → carrier-parametricity; conservativity metatheorem → postulate-free + build that is *evidence for*, not proof of) **[DOC: AFFIRMATION, roadmap]**. +* A cross-project proof `EchoTyping.agda` (XP-1: pipeline information-loss = echo fibres, + spanning echo-types ↔ affinescript ↔ typed-wasm) lives in `nextgen-typing` **[DOC]**. + +**Nearly there.** +* **Identity gates are at PROVISIONAL / PASSED-narrowed, none STABLE-ESTABLISHED** + (Gate 1 PROVISIONAL, Gate 2 PASSED (narrowed), Gate 3 PROVISIONAL) **[DOC: roadmap]**. +* **WFS, not OFS**: diagonal lifts and uniqueness-up-to-iso exist, but unique diagonal + fills are unproved; the module name `EchoOrthogonalFactorizationSystem` overstates the + target (renaming pending) **[DOC: README caution block]**. +* **Lane 1 (type-theoretic standing) is IN-REPO CLOSED, EXTERNALLY OPEN** — the paper is a + living draft; the offline half (submission, DOI, packaging) is author-driven **[DOC]**. +* `experimental/echo-additive` (7 modules incl. the `Grade` dioid) is **in no CI lane** + **[ISSUE #321]**; 4 bit-narrowing modules are similarly unlaned **[ISSUE #320]**. +* Doc/toolchain debts: `README.adoc` still carries RSR `{{PLACEHOLDER}}` template material + while `README.md` is canonical **[RAN: file read]**; `agda.yml` installs an unpinned + `apt-get agda` **[ISSUE #322]**; governance red on `CONTRIBUTING`/gitleaks + **[ISSUE #323]**; CodeQL startup-failure **[ISSUE #269]**. + +**Within reach.** Rename to honesty (`EchoWeakFactorizationSystem`); wire the unlaned +experimental modules into CI; clear the packaging/DOI half of Pillar E; refresh +`README.adoc` out of template state. + +**Open research (not reachable by wiring).** Bachmann–Howard `ψ₀(Ω_ω)` order-type fidelity +(D-2026-06-14, *OPEN* — `ε₀ ≪ Γ₀ ≪ …`); the two quarantined postulates in +`Ordinal/Buchholz/Fidelity.agda`; the `∥_∥` image truncation (cannot be built under +`--safe --without-K` without HITs — present only in a `--cubical` island); the unbudgeted +global `wf-<ᵇʳᶠ` (walled: the native order is ordinally unsound, with a documented +counterexample). + +--- + +### 2.2 `epistemic-types` — small, self-contained, genuinely green + +**What it is.** A minimal-of-design Agda prototype for standpoint-indexed modalities, +separating knowledge (factive) from belief (non-factive) and warrant from sound proof. +The base modality is deliberately **not** a monad or comonad. + +**There (established).** +* The **whole library type-checks under `--safe` with zero postulates and no standard + library** (`--no-libraries`, only `Agda.Builtin.*`), and the **hosted `Proof Safety` job + is green on the current HEAD**: run `37187387026` @ `eb810d4e`, 2026-10-04 **[CI]**. +* Module inventory is concrete: 17 modules listed in STATE, including `Base`, `Warrant`, + `Access`, `ProofTransport`, `ReadConsistency`, `EchoBridge`, `SurrealBridge`, and an + Applications layer **[DOC]**. +* The **Applications layer (2026-09-27)** is a real worked result, not a demo: + `QCriterion.qBound-≤-Q` over an arbitrary `OrderedGroup`; `RapidNJSkip` generating a + warrant from a skip certificate with `skip-known` proved; `IntegerModel` discharging the + arithmetic budget; a rejection fixture for an unchecked check **[DOC: PROOF-STATUS]**. +* Explicit non-claims are recorded: no ℚ instance, no rescaling transport, no row-insertion + update, no cross-iteration bound reuse **[DOC]**. +* Concrete Echo adapter: `SurrealBridge` relaxes a proved upper bound on a residue measure + along the access order while preserving the retained value; the `daySurrealAccess` + instance is explicitly a set-sized fragment, *not* the Conway proper class **[DOC]**. +* `ReadConsistency` was corrected so `ReadView` entails equality with indexed store + contents; the older version-only relabelling and free `Sync` witness were **removed** + **[DOC]**. + +**Nearly there.** +* STATE calls it `prototype` / `experimental` at **35% completion**, last-updated + 2026-10-04 — i.e. the repo itself does not claim maturity **[DOC: STATE.a2ml]**. +* The Applications obligations are named but unmet (rational instance, rescaling + transport, row-insertion invariants). +* The proof-transport soundness story is qualified ("holder-dependent transfer is + explicitly qualified") **[DOC]**. + +**Within reach.** Close the named Applications obligations; settle the secret-types +handover (epistemic-types#32 transfer is blocked on GitHub issue-write access — an +**administrative** blocker, not a technical one) **[DOC/ISSUE]**. + +**Open research.** Whether `bind`/`extract` structure is wanted at all (currently a +deliberate "future commitment, not a hidden assumption"); the soundness map from evidence +to claim meaning under a standpoint index. + +--- + +### 2.3 `residual-evidence-types` — newest, fastest-moving, and the only family with a machine-checked *correspondence* + +**What it is.** Evidence-indexed residual types: which worlds are compatible with an +observation *and* its declared evidence constraints, and what holds for all of them. +Founded 2026-09-09 from imported Windows-Downloads material (assessment + a standalone +HTML/JS explorer), with **all core work newly written in-repo**. + +**There (established).** +* **Milestone 1** — presence without identification (`u+n=2`, `n≤1` establishes `u≠0` + while `(1,1)` and `(2,0)` still disagree), evidence-refined fibre round trips, + conditional actual-world soundness, claim transport under refinement; three invalid + modules must be rejected by Agda **[DOC]**. +* **Milestone 2** — contexts of assumptions with thinnings, dependency-preserving + composition and coarsening, constructive revision and retraction, **a certified finite + checker proved equivalent to the explorer by `refl` over all 546 configurations** + (`Correspondence.checker-matches-explorer`), and nine expected-rejection controls + **[DOC]**. +* **Both sibling interfaces are actually imported** — Echo's fibre packaging round-trips, + and Epistemic's `SoundWarrant` requiring explicit actual-world premises — pinned to + sibling heads (`echo-types` `9c4b72b5`, `epistemic-types` `dd948fbd` for M1) **[DOC]**. +* Hosted **`Agda proofs` job green** on the current HEAD: run `36949121242` @ `62d74907`, + 2026-10-02, and a prior receipt run `36740394802` @ `befdf964` **[CI/DOC]**. +* The repo is scrupulous about the limit: the correspondence certifies the *finite checker + against the explorer*, **not** the ℕ core against the explorer **[DOC]**. + +**Nearly there.** +* `STATE.a2ml` (last-updated 2026-09-09) is **stale**: it still lists composition, + revision/retraction, the certified checker and the explorer correspondence as *pending* + — all of which Milestone 2 landed **[RAN: file read vs PROOF-STATUS]**. +* The two sibling comparisons cover **Milestone 1 only**; whether composition/revision need + an interface beyond `Echo.Echo` and `SoundWarrant` is the explicitly open question + **[DOC]**. +* A separate "starter archive" named in the imported assessment has **not been recovered** + and the repo does not pretend otherwise **[DOC]**. +* Codeac status has been pending on main since 2026-09-24 **[ISSUE #11]**. + +**Within reach.** Refresh STATE; run comparisons 2.0 (post-M1 interfaces); the explorer's +signed −6..6 model is already the certified finite object, so further finite-model checks +are cheap. + +**Open research.** Causal specialisation and probability adapters — both explicitly require +models and obligations of their own **[DOC]**. + +--- + +### 2.4 `choreographic-types` — a pre-registration, and it says so + +**What it is.** The assembly hypothesis: grade a global choreography with echo *loss-grades* +and epistemic *standpoint-warrants*, project to participants, and ask whether grading and +transport commute with projection across a consistent frontier (a *cut*). The keystone is +**K-CUT**, split into K-CUT-LOSS (equality) and K-CUT-WARRANT (bound, under a `SoundWarrant` +side-condition). + +**There (established).** +* **The specification and its fences.** The pre-registration (2026-10-03) states that + K-CUT-LOSS and K-CUT-WARRANT remain **OPEN**, that `SoundWarrant` is an *assumed + receiver-local side-condition*, and that the application Agda file **"contains postulates, + not proofs"** and is not imported by any build **[DOC: docs/pre-registration.adoc]**. +* `CITATION.cff` no longer claims a completed Agda formalisation; integrity checks now fail + such claims on description-mirroring surfaces **[DOC]**. Issue #15 records that the + README/description still overstate **[ISSUE]**. +* CI's two substantive checks — `Secret Scanner` and `Documentation Integrity` — are both + green **[CI]**. There is **no prover workflow at all**, by design at this stage. + +**Nearly there.** +* The **degenerate base case exists and is real**, but it is a sibling's theorem: + `characteristic/RoleGraded.choreo-grade-commute` in `echo-types` — two actions (role + transport × grade degradation) commuting on one Echo-indexed family, satisfying the + "same data" test that struck down the earlier N3 nominee **[DOC/RAN: file read]**. + It is a *single-static-edge integration theorem*, not K-CUT. echo-types' own audit + **declined to adopt it as nominee N5** on the grounds that its only non-trivial cell is + already credited elsewhere (adoption would be cosmetic) **[DOC: N5Falsifier, IntegrationAudit]**. +* The smallest concrete target is specified: a two-event K-CUT-LOSS commuting square under + an `Independent₂` witness, with the witness required to carry disjoint read/write + footprints, phase safety and a deterministic tie policy **[DOC]**. +* A vocabulary obligation is open: the choreographic README's phrase "echo loss-grade" + conflicts with the estate's separation of echo index / residue measure / resource grade; + reconciling it is a **coordination task** in the hub roadmap **[DOC: TYPE-CONNECTIONS]**. + +**Within reach.** Wire the existing `rapidnj-two-thread.agda` postulates into a real +minimal proof of the two-event square; land the `Independent₂` witness; reconcile the +vocabulary with the shared glossary. None of that requires solving K-CUT. + +**Open research.** K-CUT in general (both fragments) — the repo's own honest position is +that the general result is open and only degenerate single-static-edge cases exist. + +--- + +### 2.5 `tropical-types` — dual-formalised, one half verified, one half CI-gated-by-claim + +**What it is.** Max-plus / min-max algebra applied to resource-aware typing: compositional +worst-case bounds for latency, stack use and adversarial round counts, plus a reusable +resource-grade axis for downstream languages. **Note the prover split**: this family is +**Lean 4 + Isabelle/HOL**, not Agda. + +**There (established).** +* **Lean 4 — verified and CI-gated.** `lake build` green, no Mathlib, toolchain pinned in + `lean-toolchain` (`v4.13.0`); hosted **`Lean` job green** on current main: run + `37116071270` @ `ad7bfdfd`, 2026-10-03 **[CI]**. PROOF-STATUS records a clean rebuild of + **20/20 targets** including `TropicalSessionTypes.lean` (max-plus session grading), + `TropicalAdapterPath.lean` (min-max bottleneck transport + the `hub_ceiling` no-go), + the `Resource/Algebra` interface with a **parametric transport theorem**, and concrete + instances (MaxPlus, MinPlus, MinMax, Linear, Affine) **[DOC]**. +* The two twins are related by an order-reversing involution proved as a **lattice + anti-isomorphism** and explicitly *not* a semiring homomorphism — a structural fact, + stated as such **[DOC]**. +* `Resource/EchoBridge.lean` is an **echo-free residue-measure bridge** (no dependency on + the echo-types Agda kernel; the relationship is at design level) **[DOC]**. + +**Nearly there.** +* **The Isabelle half is not verified in the recon sense.** Nine `.thy` theories exist and + the session is meant to be CI-gated by `just isabelle-build` + `just check-sorry`, but + **no workflow mentions Isabelle**; `ROOT` lists **5 of 9** theories; PROOF-STATUS itself + says the Isabelle side was *"NOT re-verified in this environment"* **[DOC]**. +* Issue #57 states the contradictions directly: the claim is CI-gated but nothing gates it, + ROOT covers 5 of 9, and STATE says GREEN and RED for the same theory **[ISSUE]**. +* The `CI context contract` job is red on recent commits (required-status-check drift); + it is the repo's own guard for `docs/CI-CONTEXTS.adoc` and it fails for that documented + reason — a CI-hygiene red, not a proof red **[CI]**. +* The no-go theorem `hub_ceiling` refutes Protocol Squisher's universal-interoperability + claim — real, but it is a *no-go*, not a capability **[DOC]**. + +**Within reach.** Extend `ROOT` to all nine theories; add the Isabelle job; delete the +residual Deno test files (Deno is banned estate-wide **[ISSUE #58]**); SHA-pin the two +tagged `actions/checkout` uses **[ISSUE #59]**. + +**Open research.** The Buchholz-collapsing ladder (Rungs 2–N, 0% per STATE); tropical time +series (Diehl–Ebrahimi-Fard–Tapia); a probabilistic extension; a Lean tactic for automated +grade calculation. + +--- + +### 2.6 `occupancy-types` (this repo) — pre-registered, locally reproducible, CI-disarmed + +**What it is.** Stepwise resource-bounding types: deterministic memory first, network +second. The organising claim is that **cost and state are different axes**: cost composes +with `+` in sequence and `max` across alternatives (tropical), while *state* resources +(pools, buffers, credits, FDs) compose by the **non-commutative high-water-mark monoid** +`(p₁,n₁)·(p₂,n₂) = (max(p₁, n₁+p₂), n₁+n₂)`. Buffer = memory, and the **protocol frontier +is the reclamation point**. The whole thing is pre-registered in `ULTRAPLAN.md` with +per-rung kill criteria and a decision log (D1–D7). + +**There (established).** +* **R0-B, Phase 1 — Session IR checker: TESTED. I re-ran it in this session:** + `PYTHONPATH=src python3 -m session_ir test examples/session_ir/manifest.json` → + **14/14 PASS**, exit 0 **[RAN]**. Seven accept cases with measured steps ≤ certified + bound (including a strict case: certify 5 / measure 4, and a tight case: 6/6) and seven + expected-rejection controls each pinning an error class (double-send, use-after-drop, + protocol mismatch, close-before-End, double-free, leak, alias) **[RAN]**. +* The operational model exists and its Phase-0 kill test is **mechanically audited** + (four sentences, banned word absent) **[DOC: EXPLAINME C3]**. +* The honesty apparatus is real and already in use: `docs/EXPLAINME.adoc` classifies every + claim as TESTED / UNVERIFIED / CONJECTURE, and `docs/retraction-ledger.adoc` records + blocked rungs (with exact unblocking commands) separately from retractions — with **zero + retractions so far** and three blocked items **[RAN: file read]**. +* The estate placement is correct and deliberate: registered against the cost/state + vocabulary split, with "not echo, not warrant, not residue" written into the plan + **[DOC: ULTRAPLAN §5]**. + +**Nearly there (blocked, not disproved).** +* **Idris 2 Occupancy spike — UNVERIFIED.** `src/occ/Occ.idr`, `Demo.idr` (static peak = K + = 2 producer/consumer) and four rejection controls exist; no `idris2` on the work + environment's PATH **[DOC/RAN: toolchain check]**. The kill question (are constant grades + tolerable *and tight*?) is answered only provisionally, and the repo labels the answer + CONJECTURE. +* **R1 stackcert — UNVERIFIED.** `src/stackcert/StackcertCore.lean` with the target theorem + `cert_sound`, plus fixtures generated by real `gcc -fcallgraph-info=su -fstack-usage` + **[DOC]**, but no `lean` locally and no `#print axioms` footprint pasted. The expected + empty axiom list is **explicitly marked CONJECTURE until pasted** **[DOC: EXPLAINME C5]**. +* **Ground truth — BLOCKED.** Zephyr painted-stack HWM on `qemu_cortex_m3` is a **fixture + request**; nothing is measured until it runs. The plan's own rule is "measured ≤ certified + on every run, violation = stop" — so R1 cannot be *closed* without this **[DOC]**. +* **CI is comprehensively non-functional.** 96 of the last 100 workflow runs on this repo + concluded `startup_failure`, including on `main` pushes by the owner actor; **every** + gate — Rust CI, Dogfood, Static Analysis, Invisible Character Detection, K9, Secret + Scanner — dies before starting a job **[CI/API]**. The estate has two *documented* + mechanisms that produce exactly this signature: (a) an Actions allow-list posture of + `selected` with **0 patterns**, which kills any workflow whose step references a + non-allow-listed action, `jobs=0` (choreographic-types#16, with a produced mutant + proof); (b) an actor gate refusing workflow triggering for a given actor + (echo-types#330). The precise gate for *this* repo is **not established** from here, and + unlike its siblings this repo carries **no open issue** about it (it has no open issues + at all). Consequence: **none of this repo's checks are currently machine-enforced**; + the local gates are the only source of truth. +* `README.adoc` is still RSR template material (self-declared in-file) **[RAN]**. + +**Within reach (needs a toolchain or a settings change, not research).** Install +`idris2` → run the spike and its four controls; install `lean`/`lake` → run stackcert and +paste `#print axioms cert_sound`; obtain the Zephyr fixture; fix the Actions settings +(owner-only PUT) and file the missing issue for this repo; refresh `README.adoc` from the +template. + +**Open research (the actual rungs).** R2 static pools + affine/linear handles with the T1 +coherence theorem (project gate after R2); R3 binary session channels with HWM buffer +grades; R4 network-calculus curves over ℕ/ℤ without reals; R5 multiparty projection and the +projection/grade commutation question; Phase 5 host-tool contract. The pre-written kill +criteria are, correctly, part of the design: R2 archives the project if there is no external +consumer for certificates and no theorem beyond restatement. + +--- + +### 2.7 `absolute-zero` — the most *concretely* verified repo in the estate + +**What it is.** Two co-equal pillars — **CNO** (a program that provably does nothing to the +world) and **OND** (a program whose observable trace is constant over its secret input, +relative to a declared observation model `O`). The pillars are logically independent (a +proved theorem) and joined by a *coupling dial* that is explicitly **framing, not theorem**. + +**There (established).** +* **A single gate reproduces everything locally**: `proofs/verify-all-provers.sh` → + `ALL-PROVERS-GREEN` across **Coq, Agda, Lean 4 (+Mathlib), Z3, Isabelle/HOL, Mizar**, plus + the **Idris 2 ABI**, with an absent prover treated as *failure, never skip* (since + 2026-09-23), Z3 verdicts checked against `; expect sat|unsat`, and a Coq + `Print Assumptions` audit with its own control **[DOC: PROOF-STATUS]**. A gate self-test + proves the gate turns red for each absent/failing prover and each verdict/audit mutant + (16 cases, run in CI) **[DOC]**. +* **CI Proofs job green** on current main: run `37077637092` @ `5f271368`, 2026-10-02 + **[CI]**. The workflow runs the lightweight provers (Coq 14/14 theories, Agda CNO+OND, + Z3 CNO+OND, Mathlib-free Lean core with an `AxiomAudit`); the heavy provers are covered + only by the local container gate — and the workflow says so in its own header **[RAN: + workflow read]**. +* **OND-1..5 and OND-7 are landed** — proved in Coq with **zero axioms** (every theorem + `Closed under the global context`), mirrored in Lean 4, Agda and Z3 **[DOC]**. +* **CNO axiom discharge 98 → a small classified remainder**, with the pathological cases + found and fixed rather than hidden: `no_cloning` and `Cconj_Cexp` were **provably false** + and removed; `eta_equivalence` was **false as stated** (counterexample `f = LVar 5`) and + replaced by an honestly guarded theorem **[DOC]**. Remaining axioms are tagged either + `METAL-BOUNDARY` (genuine physics: `kB>0`, `temperature>0`, Second Law, Landauer) or + *class-A* (true, provable in principle, listed with blockers — 4 items) **[DOC]**. +* An **Echo bridge exists in Agda** (`EchoBridgeCNO.agda`): `EchoRel` instantiated + against real `CNO.Program`/`CNO.eval` with `CNO.state-eq` **[RAN: file read]**. +* Roadmap restraint is explicit: the long-horizon "universal CNO standard" is quarantined + in an appendix as **aspirational and unfunded**, "a direction of travel, not a + commitment with a date" **[DOC]**. + +**Nearly there.** +* **OND-6** (conditional composition) is **open by design** — the research capstone. The + roadmap warns, correctly, that if composition appears to hold as cleanly as for CNOs the + result has almost certainly dropped a term **[DOC]**. +* **CI is weaker than the local gate** and the repo knows it: for a time Isabelle and Mizar + printed "skipped" while the gate said GREEN; that is fixed in the local gate, but + absolute-zero#161 records that the `Proofs` workflow still has a `paths:` filter, + `z3 … || true`, and no assumption check **[ISSUE]**. +* **Documentation drift**: `ROADMAP.adoc` (last updated 2026-07-07) still lists as pending + the Idris ABI repair and "make CI truthful: run Coq+Agda+Rust", both since superseded by + `PROOF-STATUS` and the current workflow **[RAN: file comparison]**. +* 73 of 182 Coq theorems rest on axioms and 38 `Axiom`/`Parameter` declarations use four + tag forms (unify grammar, generate census) **[ISSUE #171]**; 2 Idris2 postulates in + `src/abi/Layout.idr` remain **[ISSUE #27]**; Scorecard has 5 high alerts **[ISSUE #170]**. + +**Within reach.** Make CI mirror the local all-provers gate (fix #161); unify the axiom tag +grammar and publish the census (#171); port the Coq filesystem model to Lean so the +`FilesystemCNO` law axioms become theorems (#167); refresh the roadmap against PROOF-STATUS; +the artifact-evaluation one-command container. + +**Open research.** OND-6 conditional composition; the 4 class-A Coq items +(`CNOT_gate_unitary`, `unitary_inverse_property`, `fidelity_bound` need a finite-dim/tensor +model; `y_not_cno` needs a coinductive/step-indexed β non-termination argument); the paper. + +--- + +## 3. The hub, the satellites, and the name-collisions + +### 3.1 `nextgen-typing` (coordination) — the map is the artefact + +* Hosts the shared glossary, ownership routing and the **XP-1 cross-project proof** + (`verification/proofs/agda/EchoTyping.agda`, `--safe --without-K`, spanning echo-types ↔ + affinescript ↔ typed-wasm) **[DOC]**. +* **But nothing runs it**: nextgen-typing#57 records that no CI job runs + `just proof-check-all` **[ISSUE]**. The estate's only cross-project proof is therefore + unenforced. +* Open coordination tasks relevant to the family: **#118** register `occupancy-types` in + the type map + cost/state vocabulary split + boundary notes (**this repo is not yet + registered**); **#115** re-cite the residual receipt and give the Echo→Residual / + Epistemic→Residual obligations acceptance criteria; **#69** verify and GPG-sign the + per-repo AFFIRMATIONs in-env; **#117/#121** two pre-existing CI reds. +* The hub's own readiness self-assessment is **Grade C** ("dogfooded, CI passing"), and its + stated path to Grade B is *external adoption* — 6+ diverse external targets **[DOC]**. + That is the estate's own statement that the gap between "internally coherent" and + "externally established" is a **consumption** gap, not a proof gap. + +### 3.2 Satellites + +| Repo | Role | Position | +|---|---|---| +| **EchoTypes.jl** | Executable finite-domain shadow of Echo's Tier-1/2 spine | Explicitly *not a proof*; can falsify, cannot prove; honestly scoped under R-2026-05-18 — does **not** replay the retracted surface or the funext-qualified clauses **[DOC]** | +| **EpistemicTypes.jl** | The strongest **consumer story** in the estate: per-row receipts (standpoint, warrant, projection, SHA-256 seal) and an epistemic status per taxonomy call | README-level claim; not re-verified here **[DOC]** | +| **ResidualEvidenceTypes.jl** | Julia companion to the residual work | Young (created 2026-09-30), 4 commits since 2026-09-01 **[API]** | +| **secret-types** | New home for confidentiality-labelled flow + audited declassification | Specification-stage; no checker or runtime **[DOC]** | + +**Name-collision warning (worth keeping straight):** `ZeroProb.jl` (measure-zero events) and +`zerostep` (a VAE dataset normaliser) are **not** members of this family; they are adjacent +by name only. Likewise `katagoria` (historical name) resolves to `ideas-to-alphas` and is +**not** `kategoria`; `tropical-resource-typing` resolves to `tropical-types` **[DOC: +nextgen-typing naming note 2026-09-09]**. + +### 3.3 The consumer chain (the "near zone beyond" that matters) + +``` +katagoria → typell (kernel) → typed-wasm (target) → PanLL (environment) → affinescript / ephapax / phronesis +``` + +The estate's own fence is firm: **a conceptual arrow in the map does not establish that any +family is integrated into these projects** **[DOC: TYPE-CONNECTIONS]**. Integration that +*has* happened is recorded in echo-types' bridge ledger: `EchoTyping.agda` in +nextgen-typing, `PhronesisEcho.agda` in phronesis, a machine-checked `EchoBridge.agda` in +nextgen-languages/kitchenspeak, and a Rust application example in invariant-path **[DOC]**. + +--- + +## 4. The cross-cutting position — what is safe to say + +### 4.1 What the estate can claim today, without hedging + +1. **Five of the seven repos have a green proof job on their current main**: + echo-types (Agda, `37152181722`), epistemic-types (Proof Safety, `37187387026`), + residual-evidence-types (Agda proofs, `36949121242`), absolute-zero (Proofs, + `37077637092`), and tropical-types' **Lean** half (`37116071270`) — with tropical's + Isabelle half unverified by its own admission. The two without one are + choreographic-types (deliberately: no prover workflow exists yet) and occupancy-types + (whose CI is disarmed, below). +2. **The honesty apparatus is real, not decorative.** Retractions actually happened and are + load-bearing (echo-types R-2026-05-18); false axioms were actually found and removed + (absolute-zero: 3 latent-unsound axioms); stale claims are actually corrected + (epistemic-types removed the free `Sync` witness; choreographic-types retired its + CITATION claim). Ledger entries separate *blocked* from *retracted*. +3. **The separations are the substance.** Each family earns its identity by + matched-negatives (Echo vs entropy/LL/resource-instance), by conditionality (Epistemic: + warrant ≠ sound proof), by no-go (Tropical: `hub_ceiling`), or by proved *non-* + composition (absolute-zero OND-5). +4. **The estate's own claims are unusually well fenced.** Where something is degenerate, + provisional, gated, or unverified, there is usually a document saying so — frequently + more conservative than the README. + +### 4.2 What the estate must not claim today + +* **No external validation yet.** echo-types' Lane 1 is *in-repo closed, externally open*; + nextgen-typing's path to Grade B is external adoption; nothing here is submitted, + accepted, or DOI-minted. +* **No general K-CUT.** Only degenerate single-static-edge base cases exist, and the + strongest of those has been declined as a gate nominee *by its own repo*, for good reason. +* **No established cross-prover equivalence.** tropical-types says the Lean and Isabelle + developments intend to agree but equivalence is not mechanically established; each + prover checks its own development. +* **No established bridge by arrow.** The five family connections in the map are + obligations, not results (Echo→Choreographic and Epistemic→Choreographic have *no* proof; + Echo→Residual and Epistemic→Residual cover Milestone 1 only; Tropical→Choreographic needs + a grading semantics + projection theorem). +* **No "six provers in CI" for absolute-zero.** Six provers are green *via the local gate*; + CI covers the lightweight subset, and the local gate has not been run here. + +### 4.3 The one systemic blocker with the highest leverage + +**The CI estate is partially disarmed, and the pattern is already diagnosed.** + +* **occupancy-types**: 96/100 recent runs `startup_failure`; every gate dead; no issue filed + for this repo **[CI/API]**. +* **choreographic-types#16** documents mechanism (a): Actions allow-list `selected` with + **0 patterns** → any third-party action dies at startup, `jobs=0`, with a produced mutant + proof on residual-evidence-types (same head, one `uses:` step toggled, `startup_failure` + ⇄ green). Fix is an **owner-only PUT** of the canon payload. The repo explicitly notes + this is *silent* until the first third-party action. +* **echo-types#330** documents mechanism (b): an actor gate refusing workflow triggering for + `arena-ai-coding-agent`, so PRs can merge with **zero** CI signal. Its recommended + mitigation — treat `STARTUP_FAILURE` as failure for required checks — is generally + applicable. +* **echo-types#324** / **tropical-types#59** record allow-list/count and pinning drift. + +Practical consequence for planning: **for these repos, a green badge is not evidence until +the underlying workflow actually started.** The recon above therefore cites run ids, not +badges. + +### 4.4 Planned already (named, in-tree, not speculation) + +| Where | Named next step | +|---|---| +| nextgen-typing | register `occupancy-types` in the type map (#118); reconcile the choreographic "echo loss-grade" vocabulary; re-cite residual receipts (#115); sign AFFIRMATIONs (#69); build `verification/proofs` in CI (#57) | +| echo-types | Gate re-assessment at each tag; rename the WFS module; land unlaned experimental modules (#320/#321); Pillar E offline half | +| epistemic-types | Applications obligations (ℚ/rescaling/row-insertion); secret-types #32 transfer | +| residual-evidence-types | Comparisons 2.0 beyond M1 interfaces; refresh STATE; causal specialisation as its own model | +| choreographic-types | Two-event K-CUT-LOSS square under `Independent₂`; vocabulary reconciliation | +| tropical-types | ROOT → 9 theories + Isabelle job (#57); Deno removal (#58); SHA pins (#59) | +| occupancy-types | Idris spike run; stackcert run + `#print axioms`; Zephyr fixture; Actions settings; then the R2 project gate | +| absolute-zero | CI mirrors the local gate (#161); axiom tag census (#171); filesystem model → Lean (#167); the paper | + +### 4.5 The near zone beyond (what the estate is one or two steps from) + +1. **Interfaces, not just imports.** residual-evidence-types already *imports* + `Echo.Echo` and `SoundWarrant` and proved round trips. The question it asks itself — does + composition/revision need a richer interface than `Echo.Echo`/`SoundWarrant`? — is + answerable now, and its answer would settle three of the five map obligations. +2. **Turn proofs on.** Wiring the existing proofs into CI (nextgen #57, tropical #57, + occupancy's settings) converts several [DOC] claims into [CI] claims at near-zero + research cost. +3. **Two K-CUT-LOSS squares.** The two-event square is specified at the level where it can + be proved today; a second, non-degenerate pattern would test whether the + single-static-edge degeneracy is essential or incidental — the cheapest experiment that + could falsify the assembly hypothesis early. +4. **Cost vs state as a testable separation.** `occupancy-types` claims the HWM monoid is a + *different* axis from tropical cost, with witnesses; the estate already has both halves + in place (tropical-types' algebra; occupancy's session IR). A small composition whose + HWM grade and cost grade cannot be identified would be the cleanest possible + cross-family result — and it is a *separation*, so it is falsifiable cheaply. +5. **A consumer.** Every family's honest bottleneck is the same one the hub names: nobody + outside the estate is consuming this yet. `EpistemicTypes.jl` (per-row classifier + receipts) and occupancy's session IR (certificates over measured bounds) are the two + most consumer-shaped artefacts in the estate. + +--- + +## 5. One-table position summary + +| Repo | Established (receipt) | Nearly there | Within reach | Open research | +|---|---|---|---|---| +| **echo-types** | Agda suite green under `--safe --without-K` (`37152181722`); 209 `.agda` files; separations; retraction-disciplined | Gates provisional; WFS-not-OFS naming; unlaned modules; `README.adoc` template drift | Rename; lane the modules; packaging/DOI | Buchholz `ψ₀(Ω_ω)`; 2 Fidelity postulates; truncation under −K | +| **epistemic-types** | Whole library green, zero postulates, no stdlib (`37187387026`); RapidNJ Q-criterion warrants | 35% prototype; applications obligations unmet | Close named obligations; secret-types transfer | Monad/comonad structure; evidence→claim soundness | +| **residual-evidence-types** | M1+M2 checked; 9 rejections; 546-config correspondence by `refl`; both sibling interfaces imported (`36949121242`) | STATE stale; comparisons cover M1 only | Refresh STATE; comparisons 2.0 | Causal specialisation; probability adapters | +| **choreographic-types** | Specification + fences; docs integrity green; the *reason* it exists is one theorem | Degenerate base case (real, sibling-side, declined as a gate nominee) | Two-event square; `Independent₂`; vocabulary fix | K-CUT-LOSS / K-CUT-WARRANT general case | +| **tropical-types** | Lean green, 20/20, no Mathlib (`37116071270`); `hub_ceiling` no-go; parametric transport | Isabelle 9 theories, ROOT 5/9, **no CI job**; `CI context contract` red | ROOT→9; Isabelle job; Deno removal; SHA pins | Buchholz ladder; time series; probabilistic extension | +| **occupancy-types** | Session IR 14/14 **[RAN]**; operational model; ledger with blocked ≠ retracted | Idris spike + stackcert + Zephyr fixture all UNVERIFIED; **CI 96/100 startup_failure** | Install toolchains; run; paste `#print axioms`; fix Actions; file the issue | R2–R5 rungs; cost/state separation as a theorem | +| **absolute-zero** | Six provers + Idris green *locally*; CI Proofs green (`37077637092`); OND-1..5,7 zero-axiom; 98→classified axioms; 3 unsound axioms fixed | OND-6 open by design; CI narrower than the local gate; roadmap drift | #161, #171, #167; roadmap refresh; artifact package | OND-6; 4 class-A Coq items; the paper | + +--- + +## 6. Method and limits of this recon + +* Read: full repo trees (shallow clones at the pins above), all top-level status documents + (README, PROOF-STATUS, AFFIRMATION, ROADMAP, ULTRAPLAN, EXPLAINME, STATE.a2ml, + pre-registration, retraction ledger), the hub's TYPE-CONNECTIONS guide and roadmap, and + the workflow files. +* Queried: GitHub Actions run history and conclusions per repo (not badges), open issues + and key issue bodies, commit dates, signatures and HEAD SHAs, toolchain availability + locally. +* Ran: the only proof-adjacent gate runnable without a prover toolchain — + `occupancy-types`' Session IR manifest (14/14). Everything else in this document that is + not marked **[RAN]** rests on **[CI]**, **[DOC]** or **[ISSUE]** evidence as tagged. +* Not done: no Agda/Lean/Isabelle/Coq/Mizar/Z3 re-run; no `just check` anywhere; no + evaluation of proof *quality* beyond what the repos' own guardrails (postulate/escape + greps, kernel certificates, axiom audits) enforce; no attempt to resolve the + occupancy-types Actions gate (owner-only API surface). +* Everything above is dated 2026-10-04 and pinned by the SHAs in §0. Move the SHAs and it + becomes a draft until re-run — which is exactly the estate's own rule for AFFIRMATIONs, + and a good rule for this document too. From 8900bda38bd07b31d8d4609aaab29eeb9ea28dab Mon Sep 17 00:00:00 2001 From: Arena Agent Date: Sun, 4 Oct 2026 20:36:48 +0000 Subject: [PATCH 2/7] docs(recon): follower notes and coordinated plan; untrack pycache - FOLLOWER-NOTES-2026-10-04.md: 12 deep bespoke notes (each pinned to a file/commit in the recipient's repo) + 2 lighter notes + triage of all 269 followers, with an honest coverage statement (14 drafted, ~15 next-up, ~35-50 realistic ceiling). - COORDINATED-PLAN-2026-10-04.md: W1 receipts, W2 interface arrows, W3 time-boxed keystones, W4 occupancy rungs through their own gates, W5 consumers; dependencies, horizons, refusals and falsifiers. - Stop tracking src/session_ir/__pycache__ (7 files) and ignore it. Refs: occupancy-types#6 filed (CI 96/100 startup_failure, untracked). Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com> --- .gitignore | 5 + docs/recon/COORDINATED-PLAN-2026-10-04.md | 194 +++ docs/recon/FOLLOWER-NOTES-2026-10-04.md | 1045 +++++++++++++++++ .../__pycache__/__init__.cpython-311.pyc | Bin 587 -> 0 bytes .../__pycache__/__main__.cpython-311.pyc | Bin 315 -> 0 bytes .../__pycache__/checker.cpython-311.pyc | Bin 21083 -> 0 bytes .../__pycache__/cli.cpython-311.pyc | Bin 9327 -> 0 bytes .../__pycache__/machine.cpython-311.pyc | Bin 15530 -> 0 bytes .../__pycache__/parser.cpython-311.pyc | Bin 21476 -> 0 bytes .../__pycache__/syntax.cpython-311.pyc | Bin 16164 -> 0 bytes 10 files changed, 1244 insertions(+) create mode 100644 docs/recon/COORDINATED-PLAN-2026-10-04.md create mode 100644 docs/recon/FOLLOWER-NOTES-2026-10-04.md delete mode 100644 src/session_ir/__pycache__/__init__.cpython-311.pyc delete mode 100644 src/session_ir/__pycache__/__main__.cpython-311.pyc delete mode 100644 src/session_ir/__pycache__/checker.cpython-311.pyc delete mode 100644 src/session_ir/__pycache__/cli.cpython-311.pyc delete mode 100644 src/session_ir/__pycache__/machine.cpython-311.pyc delete mode 100644 src/session_ir/__pycache__/parser.cpython-311.pyc delete mode 100644 src/session_ir/__pycache__/syntax.cpython-311.pyc diff --git a/.gitignore b/.gitignore index afbe851..350f5f8 100644 --- a/.gitignore +++ b/.gitignore @@ -144,3 +144,8 @@ verification/proofs/coq/.*.aux # Agda compiled proof artifacts verification/proofs/agda/*.agdai + +# Python bytecode (was tracked inadvertently; see docs/recon/TYPE-FAMILY-POSITION-2026-10-04.md) +__pycache__/ +*.py[cod] +*.pyo diff --git a/docs/recon/COORDINATED-PLAN-2026-10-04.md b/docs/recon/COORDINATED-PLAN-2026-10-04.md new file mode 100644 index 0000000..3948bd8 --- /dev/null +++ b/docs/recon/COORDINATED-PLAN-2026-10-04.md @@ -0,0 +1,194 @@ +# Coordinated plan — the seven repos, 2026-10-04 + +**Companion to:** `docs/recon/TYPE-FAMILY-POSITION-2026-10-04.md` (the position) and +`docs/recon/FOLLOWER-NOTES-2026-10-04.md` (consumer outreach). +**Scope:** `echo-types`, `epistemic-types`, `residual-evidence-types`, `choreographic-types`, +`tropical-types`, `occupancy-types`, `absolute-zero`, the `nextgen-typing` hub and the satellites. + +--- + +## 1. The governing idea + +The recon found one asymmetry that should drive the whole plan: + +> **Most of the estate's claims are already true and already fenced — but a large fraction are +> not *machine-enforced*.** Proof work that exists on disk is unreceipted (no CI lane, no +> toolchain run, no issue), while several workflows that appear to gate it die at startup. + +So the plan is not "do more research". It is, in order: **(W1) make what exists checkable**, +**(W2) convert the five cross-family arrows from proposed to checked**, **(W3) time-box the two +open keystones**, **(W4) run the occupancy rungs through their own kill gates**, **(W5) build +consumers so the work has external standing**. Research ambition is capped deliberately: the +plan's job is to make the boundary between *established* and *open* impossible to misread. + +### Principles (non-negotiable, because they are the estate's credibility) + +1. **Receipts over claims.** A result is [RAN] (command + output), [CI] (run id + commit), [DOC] + (dated author run), or it is *not established*. Upgrading [DOC]→[CI] is the cheapest work in + the estate and the highest value. +2. **Blocked ≠ retracted.** Blocked items carry the exact command that would unblock them. + Retractions are recorded with the counterexample. Both ledgers already exist — keep using them. +3. **Separation before capability.** Every family's identity rests on matched-negatives or + no-go results. A new capability claim without a separation is a naming exercise. +4. **Kill criteria are pre-written and honoured.** occupancy-types §3 has them per rung; + absolute-zero warns that a too-clean composition result is probably wrong. Obey the ledgers, + not the momentum. +5. **No arrow as dependency.** The type-family map's dashed arrows are obligations, not imports. + The one deliberate exception (occupancy's "no cross-kernel imports") stays. + +--- + +## 2. Workstreams + +### W1 — Make the receipts real (highest leverage, mostly mechanical) + +| # | Task | Repo | Owner | Closes with | +|---|---|---|---|---| +| W1.1 | Read the Actions posture; if `selected`/short, PUT the canon allow-list; re-run the gates | occupancy-types | **owner-only** | a push where Secret Scanner + Governance + a checker job *start and pass* (issue #6) | +| W1.2 | Wire the Session IR manifest as a CI job (`PYTHONPATH=src python3 -m session_ir test …`, 14/14 today) | occupancy-types | automatable | green job on `main`; regression visible | +| W1.3 | Build `verification/proofs/` in CI (XP‑1 currently unenforced) | nextgen-typing | automatable | green job; issue #57 | +| W1.4 | Extend Isabelle `ROOT` to all 9 theories + add the Isabelle job | tropical-types | needs Isabelle | PROOF-STATUS's "CI-gated" claim becomes true; issue #57 | +| W1.5 | Lane `experimental/echo-additive` + the 4 bit-narrowing modules | echo-types | automatable | modules in `All.agda`/a lane or archived; issues #320/#321 | +| W1.6 | Pin the Agda toolchain (drop unpinned `apt-get agda`) | echo-types | automatable | pinned version in workflow; issue #322 | +| W1.7 | Make CI mirror the local all-provers gate (or say so loudly in CI + README) | absolute-zero | author | issue #161 closed or scoped honestly | +| W1.8 | **Estate-wide: treat `STARTUP_FAILURE` as failure for required checks** | all | owner (settings) | no PR can merge with zero CI signal; echo-types#330 | +| W1.9 | File the missing issue(s) for repos with dead CI and no tracker entry | occupancy-types | done (issue #6) | — | +| W1.10 | Remove tracked `__pycache__` (7 files) + ignore rule | occupancy-types | **done this session** | clean tree | + +**Why first:** W1 costs days, converts a large body of [DOC] into [CI], and — critically — +W1.8 and W1.1 also *unblock* every future automated check. Right now a green badge in this +estate is not evidence that anything ran. + +### W2 — Mature the interfaces (the five arrows) + +The hub's `TYPE-CONNECTIONS.adoc` lists what each connection needs. Current state, from the +recon: Echo→Residual and Epistemic→Residual cover **Milestone 1 only**; Echo→Choreographic and +Epistemic→Choreographic have **no proof**; Tropical→Choreographic needs a grading semantics. + +| # | Task | Repo | Closes with | +|---|---|---|---| +| W2.1 | Comparisons 2.0: do composition (`compose-claims`) and revision (`survives-retraction`, `revise`) transport beyond `Echo.Echo` / `SoundWarrant`? | residual-evidence-types | a checked answer either way — *"no, a richer interface is needed"* is a publishable result | +| W2.2 | **Cost vs state as a separation**: exhibit a composition where the HWM grade and the cost grade cannot be identified | occupancy + tropical | a witness pair + a no-identification theorem (cheap, falsifiable, cross-family) | +| W2.3 | Projection model + correspondence theorem for the echo loss-grade on a projection | echo ↔ choreographic | a stated projection with a proved commuting square (two-event case first) | +| W2.4 | `K-CUT-WARRANT` statement with side conditions (`SoundWarrant` receiver-local) — *state it precisely before proving it* | epistemic ↔ choreographic | a written statement + its side conditions, reviewed | +| W2.5 | Grading semantics for bounds under interaction (declared algebra, not a port) | tropical ↔ choreographic | a semantics + a projection theorem, or a documented negative | +| W2.6 | Reconcile the choreographic "echo loss-grade" vocabulary with the shared glossary (index ≠ measure ≠ grade) | choreographic + hub | README/glossary agreement; hub roadmap item closed | +| W2.7 | Refresh stale STATE files against their own PROOF-STATUS | residual-evidence, tropical, absolute-zero | a state file that does not contradict the receipts | + +**W2.2 is the sleeper.** The estate's central architectural claim is that cost and state are +different axes; both halves already exist in separate repos; and the claim is a *separation*, +which means it is cheap to make and cheap to falsify. If it fails, that is important news for +occupancy's thesis. It should be done early. + +### W3 — Keystones, time-boxed and pre-falsified + +| # | Task | Repo | Time box | Kill / honest outcome | +|---|---|---|---|---| +| W3.1 | Two-event K-CUT-LOSS square under `Independent₂` | choreographic | 1–2 sessions | if `Independent₂` needs hypotheses that trivialise it, record that | +| W3.2 | A **second, non-degenerate** projection pattern | choreographic | after W3.1 | if degeneracy is incidental, K-CUT gains standing; if essential, the assembly hypothesis narrows honestly | +| W3.3 | Bachmann–Howard `ψ₀(Ω_ω)` fidelity (Lane 3, retired from echo-types) | echo-types | multi-session frontier | remains OPEN by D-2026-06-14; the 2 Fidelity postulates are the only ones in the tree | +| W3.4 | OND-6 conditional composition | absolute-zero | research-grade, last | the roadmap already warns a too-clean positive result has dropped a term | +| W3.5 | Kernel-certificate / guardrail re-check after any W3.3 movement | echo-types | per change | `Smoke.agda` + `All.agda` + guardrails green | + +**Rule for W3:** nothing here is allowed to block W1/W2, and every item ships a written negative +outcome. Lane 3 was already retired once from echo-types for outgrowing the project — that +precedent is the model. + +### W4 — Run the occupancy rungs through their own gates + +| # | Task | Blocked on | Then | +|---|---|---|---| +| W4.1 | Idris 2 Occupancy spike: `idris2 --check Occ.idr` + `Demo.idr` + 4 rejection controls; answer the kill question (constant grades tolerable **and tight**?) | `idris2` installed | R0‑B Piece 2 closes or the kill criterion fires | +| W4.2 | stackcert: `lean StackcertCore.lean`, `#print axioms cert_sound`, fixture run + 4 negative controls | `lean`/`lake` installed | replaces the CONJECTURE with a pasted axiom footprint | +| W4.3 | Zephyr painted-stack HWM fixture on `qemu_cortex_m3` | `west` + QEMU + Zephyr SDK | R1's ground-truth protocol can run: measured ≤ certified | +| W4.4 | R2 static pools + affine/linear handles, T1 coherence theorem | W4.1–W4.3 | **project gate**: no external consumer + no theorem beyond restatement ⇒ archive with a ledger entry | +| W4.5 | Phase‑2 "protocol cut = reclaim" (live memory = f(protocol shape)) | R2 | compositional advantage demonstrated, or kill | + +**This is the only workstream with a project-level stop written into it.** Treat W4.4 as the +real decision point and do not let it drift into R3/R4/R5 by inertia. + +### W5 — Consumers and external standing + +| # | Task | Closes with | +|---|---|---| +| W5.1 | Sign + re-anchor the per-repo AFFIRMATIONs at main (nextgen-typing#69) | dated, GPG-signed receipts at current SHAs | +| W5.2 | Register occupancy-types in the hub's type map (question, boundary, connections) — hub#118 | map row + vocabulary fence | +| W5.3 | Re-cite the residual receipts and give Echo→Residual / Epistemic→Residual acceptance criteria (hub#115) | guide updated with acceptance criteria | +| W5.4 | Mirror the general `EchoAggregation` into EchoTypes.jl (echo-types#280) | finite-domain falsifier covers the general law | +| W5.5 | Clear the Pillar E offline half: packaging, DOI, submission | paper submitted (author-driven) | +| W5.6 | absolute-zero artifact-evaluation package (one-command container) | reviewer can reproduce `ALL-PROVERS-GREEN` | +| W5.7 | Follower outreach (see the companion notes file) | replies → real consumers; keeps the estate honest about who actually uses this | +| W5.8 | A public artefact over the outreach: "what a projection/receipt/bound problem looks like, four worked examples" | citable, reaches the same audience without 269 DMs | + +--- + +## 3. Dependencies + +``` +W1.8 (treat STARTUP_FAILURE as failure) ──► makes every other gate trustworthy +W1.1 (occupancy Actions posture) ──► W1.2, W4.* receipts +toolchains (idris2 / lean / zephyr) ──► W4.1 ─► W4.2/W4.3 ─► W4.4 (project gate) +W2.1 (interfaces beyond M1) ──► W2.3, W2.4, W2.5 (three of five arrows) +W2.2 (cost vs state separation) ──► independent; strengthens or breaks occupancy's thesis +W3.* (keystones) ──► must NOT block anything in W1/W2 +W5.1/W5.2 (receipts + registration) ──► prerequisite for W5.5, W5.7 credibility +``` + +Two structural notes: **(a)** W1.8 is a single settings decision with estate-wide leverage — +it belongs in the first hour. **(b)** The three arrows that depend on W2.1 mean the residual +repo's next question is worth more than its apparent size: it is the hinge for half the map. + +--- + +## 4. Sequence + +**Horizon 1 — this week (all mechanical, no research):** W1.8, W1.1, W1.2, W1.3, W1.10 (done), +W1.4, W1.6, W1.7; W2.7 (state files); W5.1, W5.2. +*Outcome: every existing proof claim that can be receipted is receipted; no green badge is +false.* + +**Horizon 2 — the quarter (interfaces + the rungs that can run now):** W2.1, W2.2, W2.6; +W4.1, W4.2, W4.3; W3.1, W3.2; W1.5. +*Outcome: the five arrows either checked or honestly narrowed; occupancy past R1 with ground +truth; K-CUT either advanced one non-degenerate step or falsified at the two-event scale.* + +**Horizon 3 — beyond (research + external):** W3.3, W3.4; W4.4 decision, then R3–R5; W2.3–W2.5; +W5.4–W5.6; W5.7/W5.8. +*Outcome: external standing, or an honest narrowing — the estate's own decision policy on the +identity claim (echo-types' roadmap: *"if it is refuted, narrow honestly… or stop the identity +claim and retain the suite as Agda exposition"*).* + +--- + +## 5. What this plan refuses to do + +* **No cross-kernel imports.** occupancy's ULTRAPLAN §1.2 is permanent: not dependent on K-CUT, + Echo, epistemic or secret types. The map is vocabulary, not a build graph. +* **No new surface language before a certificate checker has a user** (occupancy non-goal). +* **No capability claim without a separation** (echo-types' gate discipline). +* **No "one more prover" for absolute-zero before CI mirrors the gate it already has.** +* **No 269-message outreach.** Narrow, falsifiable, per-person hints only — the alternative is + noise with a reputational bill. +* **No treating a conceptual arrow as a dependency, an equivalence, or a theorem.** + +--- + +## 6. How to tell whether the plan worked + +Falsifiable, in order of cheapness: + +1. **`STARTUP_FAILURE` cannot masquerade as green** in any estate repo (W1.8). Check: force a + failing workflow and confirm it blocks; check that a required context that never starts + reports failure. +2. **Every "[DOC] verified" line in PROOF-STATUS has a corresponding green run id**, or is + explicitly marked as not CI-covered. Check: grep the PROOF-STATUS files against the Actions + API. +3. **The cost/state separation is settled either way** (W2.2) — a witness + no-identification + theorem, or a documented collision that narrows occupancy's thesis. +4. **K-CUT is either non-degenerate-advancing or honestly narrowed** to what a two-event square + can support (W3.1/W3.2), with the degenerate case's status written down. +5. **At least one external consumer** exists for one artefact (W5.5–W5.8), or the R2 project + gate fires and occupancy is archived with a ledger entry — which is a *success* under its + own rules. +6. **No state file contradicts its repo's receipts** (W2.7). This is the cheapest measure of + estate coherence, and today three fail it. diff --git a/docs/recon/FOLLOWER-NOTES-2026-10-04.md b/docs/recon/FOLLOWER-NOTES-2026-10-04.md new file mode 100644 index 0000000..61393ac --- /dev/null +++ b/docs/recon/FOLLOWER-NOTES-2026-10-04.md @@ -0,0 +1,1045 @@ +# Follower notes — bespoke drafts + +**Prepared:** 2026-10-04 · **For:** `@hyperpolymath` · **Status:** drafts only — *nothing has been sent* + +--- + +## 0. Scope, method, and what is honest to say about coverage + +**The arithmetic.** You follow 269 accounts. I pulled the follower list (269), fetched full +profiles and most-recent non-fork repos for 225 of them, and qualified **188 as active** +(≤180 days since last push). Language breakdown of the active set: 41 Python, 24 JavaScript, +15 TypeScript, 8 HTML, 6 PHP, 5 Rust, 4 Shell/4 CSS, then singles — 64 have no substantive +public code at all (profile READMEs, config repos, GIF-only repos). + +**What I read for the notes below.** I cloned and read the actual source of the code I +referenced — files, comments and commit subjects — not just descriptions. Every note pins a +specific file and a specific recent commit or line, so the hint lands somewhere real. + +**What I did *not* do.** I did not write 269 notes. Of the 188 active accounts, roughly +**35–50 have public code with a visible struggle** that one of your artefacts genuinely +addresses; the rest are profile-only, inactive, or have nothing I could hook to without +inventing relevance — and inventing it would damage exactly the credibility these notes are +meant to build. Twelve deep notes and two shorter ones are below; §4 lists the near-miss set +I can work through next, and §5 is the full triage. + +**Voice.** Written in your voice, first person, short, no pitch. Each one: *what I read → +the struggle I saw → one thing from the estate → the smallest concrete first step → an offer*. +Rationale lines are for you and should **not** be sent. + +**Two rules I held to.** (1) No claim about an estate artefact stronger than its own +PROOF-STATUS allows — prototypes are called prototypes, open keystones are called open. +(2) No "you should use X" — only "here is the shape of your problem and the shape of this +artefact; the match is yours to judge." + +--- + +## 1. Tier 1 — deep notes (code read) + +### 1.1 @barissozudogru — `gha-cost` + +**What he is building.** A TypeScript estimator for GitHub Actions costs, parsed from +workflow YAML. Its most recent six commits (all 2026-10-04) are robustness fixes: ignoring +overflowing push-rate values, rejecting non-finite self-hosted rates, honouring a zero push +frequency, counting valid cron day/month pairs. + +**The struggle.** He documented it himself, in `src/index.ts`: + +> *"Measured across 80 real steps from three repositories, the distribution is bimodal rather +> than merely mis-centred… **No single value describes that, so a point estimate is false +> precision no matter which value is chosen.**"* + +So he estimates a *range* per step — and then has to compose ranges: `+` down a sequence of +steps, `max` across matrix branches, multiply by run frequency. That is an algebra he is +using without having declared it, which is precisely where his last six commits were spent +(input-validation patches to keep ill-formed numbers out of the composition). + +**The hook — `tropical-types`.** The repo's whole thesis is: *a declared resource algebra +supplies operations and laws; max-plus combines alternatives with `max` and sequential costs +with `+`; the algebra and cost semantics must be stated.* Its Lean 4 development +(`Resource/Algebra/Interface` + `ParametricLaws`, with `MaxPlus`/`MinPlus`/`MinMax` instances, +no Mathlib, CI green) is exactly the interface for "compose worst-case bounds and know which +laws you used". His ranges additionally make a *conditional* assumption (low-end = warm cache) +that max-plus does not — naming that as "where the law fails" is the useful part. + +**A second, sharper hook from your own estate.** This morning's recon measured +`occupancy-types` at **96 of its last 100 workflow runs ending `startup_failure`** — no jobs +created, no minutes billed, no gate executed — while the runs list still shows workflows +"passing" elsewhere in the estate. His estimator prices those runs as if they executed. A +`startup_failure`/zero-job run is a *null run*: it bills nothing and verifies nothing, so +recording it as a normal run is the same class of error as billing a skipped job. He has the +perfect tool to co-sign the finding and a natural feature ("null-run detector + a residue list +of what the estimator cannot see"). + +**Copy-paste message** + +> Hi — I read `gha-cost` this week, and the comment in `src/index.ts` about the bimodal step +> distribution stuck with me: *"a point estimate is false precision no matter which value is +> chosen."* That is the right instinct, and I think the piece you are missing has a name. +> +> Once you estimate ranges, you are doing algebra over them — `+` along a step sequence, `max` +> across matrix branches, scaling by run frequency. I have a small Lean 4 development +> (`tropical-types`) whose entire purpose is making that algebra explicit: a resource-grade +> interface with a parametric transport theorem and concrete max-plus/min-plus/min-max +> instances, no Mathlib, green in CI. It would let you *state* which law your estimator relies +> on at each composition point — and where your "warm cache" weighting quietly breaks it. +> +> One concrete thing you can use immediately from outside the algebra: I measured a repository +> where 96 of 100 recent runs ended `startup_failure` — zero jobs, zero minutes billed, and no +> gate actually executed. Your estimator would price those runs as if they ran. A "null run" +> detector (zero jobs ⇒ zero cost) plus a short residue list of what the estimate cannot see +> (self-hosted, cache hits, early aborts) would be a real accuracy gain, and it is a +> falsifiable claim rather than a heuristic. +> +> Happy to point you at the interface file if useful — no obligation. + +*Rationale (not for sending): he is one of the few followers whose repo is a direct consumer +of a family member. The null-run finding also gives him something **from** your work rather +than only a request, which is the right way round.* + +--- + +### 1.2 @sdiehl — `groebner` + +**What he is building.** An optimised Rust implementation of F4 and Buchberger for Gröbner +bases — parallel sparse linear algebra, SIMD row reduction, multi-modular rational +reconstruction. `TODO.md` shows the algorithm programme: F5 for large systems is the open box; +Gebauer–Möller, sugar strategy, incremental updates are done. + +**The struggle.** `src/grebauer_moller.rs` implements the B, M and F criteria — i.e. it +*deletes* critical pairs that cannot contribute. The comments state the criteria as +conditions on lcms (`"Remove pairs (i,j) if lcm(i,j) is divisible by lcm(i,k) for some k ≠ j"`) +but the code carries no statement of *why deletion is safe* — no retained witness that the +basis is still complete. That is the classic place where a criterion is "well known" and +therefore anyone's regression is invisible until a benchmark disagrees. + +**The hook — `echo-types`.** Its subject is irreversible maps where the fibre over each output +retains a *proof-relevant constraint on what was lost*: `Echo f y = Σ (x : A), f x ≡ y`. A +redundancy criterion is exactly this: you lose pairs (information loss) but must retain enough +to certify that no basis element was missed (the witness). Two pieces map directly: + +* the **loss taxonomy × residue shapes** — a vocabulary for *which* distinctions a criterion + discards and which it must keep, so "safe" becomes a stated obligation rather than folklore; +* the **matched-negative discipline** — the estate's rule that a claim earns standing by + proving what it is *not* (here: exhibiting the witness function that would fail if the + criterion were wrong), which is the natural shape of an F5 signature argument. + +F5 is the natural first customer: signatures are retention-by-construction, so the design +question is literally *what must be retained for the reduction to remain certifying*. + +**Copy-paste message** + +> I spent some time in `groebner` this week — the F4/F5 work and the Gebauer–Möller filter in +> particular. Your `grebauer_moller.rs` states the B/M/F criteria crisply, and what I noticed +> is that the *reason* each deletion is safe lives in the literature rather than in the code: +> the pairs are dropped, but no witness is kept that says the basis is still complete. +> +> I have an Agda development (`echo-types`) whose subject is exactly this shape — irreversible +> maps where the fibre over each output retains a proof-relevant constraint on what was lost, +> with a mechanised taxonomy of loss kinds and residue shapes. Read one way, a redundancy +> criterion *is* such a map: you discard pairs, and the obligation is to retain enough to +> certify nothing was missed. The discipline I found useful is to make the retained witness an +> explicit object, so "safe" is a theorem-shaped statement instead of folklore — and so a +> regression shows up as a failed witness rather than a benchmark disagreement. +> +> For F5 specifically, signatures are retention-by-construction, so the design question becomes +> *what must be kept for the reduction to stay certifying*. If that framing is useful, the loss +> taxonomy and the matched-negative pattern are the two parts I would start from — I can send +> pointers rather than a pitch. + +*Rationale (not for sending): he is a known Haskell/compiler-adjacent figure; treat it as a +peer exchange, not outreach. Highest credibility-per-word note in the set — the framing is +genuinely load-bearing for F5 and costs him nothing to consider.* + +--- + +### 1.3 @Teagar — `crawl-online` + +**What he is building.** A host-authoritative multiplayer mod for *Crawl* (Unity 5.4 / Mono +2.35 / BepInEx 5.4.11), with a Steam lobby, a versioned capability handshake, per-slot +monotonic input/snapshot sequences, bounded correction history, and a clean-room +`SessionProtocolEngine` driven by an in-process `HeadlessSessionHarness`. + +**The struggle — and it is two struggles, both documented in `memory.md`.** + +1. **The projection problem.** *"Delayed-input lockstep is rejected by a clean trace-v2 + experiment: with symmetric quantized input, exact and quantized critical state diverged + from the first checkpoint at frame 30"* — 19,380 frames, 36,574 inputs, 517 checkpoints, + and every hash diverged from frame 30 without a harness exception. Quantisation is a + non-injective map, and the divergence is a statement about *which distinctions survive it*. +2. **The live one.** His last six commits are all menu focus: *"fix: synchronize native menu + visual selection"*, *"diagnostics: inspect native menu focus contracts"*, *"trace bounded + native menu focus state"*, *"fix: reapply native menu focus after reconstruction"* — with + new files `MenuFocusContract.cs`, `NativeMenuSelectionPlan.cs`, + `BoundedMenuFocusObservation.cs`. He is chasing a case where the *logical* selection and the + *rendered* selection come apart under reconstruction. + +**The hook — `choreographic-types` (plus two others).** *Choreographic types* asks: when a +global interaction protocol is projected to local participants, what happens to retained +distinctions, resource bounds and warrants? The keystone (K-CUT) is a conjecture — open — but +the *specification* is the useful artefact here: name the global protocol, name the projection, +state which distinctions must survive it, and state the cut (consistent frontier) at which the +comparison is made. His checkpoint divergence at frame 30 is a cut-consistency failure with a +reproducible witness; the two-event square in `applications/rapidnj-two-thread.agda` is a +worked *shape* for the smallest such claim. + +Two smaller matches inside the same repo: + +* **`occupancy-types`** — "bounded per-peer correction history" and his monotonic operation + *generations* are an occupancy grade and an epoch. The plan's Phase-2 claim is that + *reclamation is a function of protocol shape, not GC*: when a session generation ends + (BACK/leave), every buffer owned by that generation is dead. He already implements this by + hand; the HWM monoid `(p₁,n₁)·(p₂,n₂) = (max(p₁, n₁+p₂), n₁+n₂)` is the composable form. +* **`epistemic-types`** — his `memory.md` is scrupulous in exactly the estate's way: + *"This is protocol evidence only, not Steam or native-Windows validation"*, *"build evidence + only, never substitutes for native Windows execution"*. That distinction has a minimal typed + interface (`Warrant` vs `SoundWarrant`, `BeliefModality` vs `FactiveModality`) and a pattern + of *expected-rejection fixtures* — evidence that cannot silently be promoted to proof. + +**Copy-paste message** + +> I read your `memory.md` and the recent menu-focus work this week. Two things struck me. +> +> First, *"with symmetric quantized input, exact and quantized critical state diverged from the +> first checkpoint at frame 30"* is one of the cleanest statements of a projection problem I +> have seen in a game codebase: quantisation is a non-injective map, and the experiment is +> really asking which distinctions have to survive it. I have a research notebook +> (`choreographic-types`) that exists for exactly that question — a global protocol read as a +> partial order, projected to participants, with the claim stated at a *cut* (a consistent +> frontier). Its keystone is open, so I am not offering you a theorem; I am offering the +> vocabulary and a worked two-event commuting square as the shape of the smallest claim you +> could make about your own trace. +> +> Second, the focus work: `MenuFocusContract.cs` and `NativeMenuSelectionPlan.cs` are chasing +> the case where logical selection and rendered selection come apart after reconstruction. +> That is the same question — which distinctions must the projection retain — at UI scale, and +> your bounded focus state is already the right kind of object. +> +> One smaller note: your bounded per-peer correction history and your monotonic operation +> generations are an occupancy grade and an epoch. I keep a small calculus (`occupancy-types`) +> whose whole point is that reclamation is a function of protocol shape rather than GC — when a +> generation ends, everything it owned is dead. You are already implementing it by hand; the +> high-water-mark monoid is the composable form. +> +> And one compliment worth stating: *"protocol evidence only, not Steam or native-Windows +> validation"* is the exact discipline most projects lack. I have a minimal typed interface for +> that distinction (a warrant versus a *sound* warrant) plus a fixture pattern that stops +> evidence being silently promoted to proof — happy to share if it is ever useful. + +*Rationale (not for sending): the strongest overall match in the set — he is already using your +vocabulary ("contract", "observation", "plan", "evidence, not validation") independently. The +message offers framing and one small calculus, asks for nothing.* + +--- + +### 1.4 @NeoZorK — `Monte-Neo` + +**What he is building.** "The independent verifier for trading strategies written by AI agents +and humans" — catches look-ahead bias, hidden costs and overfitting before a backtest reaches +money. Adapters for nine frameworks, an MCP server, a `strategy-verdict/1` schema, a "Trap +Suite", and — tellingly — a GitHub *false accusation* issue template. + +**The struggle.** His README puts the requirement precisely (§ line ~153): the verifier must be +*"independent… probes that do not trust the strategy's own numbers"*, and the failure mode he +fears is that the *"verifier cannot silently stop catching a leak or start accusing honest +code"* — soundness **and** completeness, in tension, over probe heuristics. Meanwhile +`src/monte_neo/core/portfolio/manager.py` carries `# Mock values for now, should be calculated +from equity_curve`, and the acceleration layer has `for now` fallbacks — the ordinary debt of a +beta. + +**The hook — `epistemic-types` + `residual-evidence-types`.** These are two halves of his +problem, and both exist: + +* *Epistemic types* separates "I have a receipt for A" from "A is true": `Warrant` (evidence + token) and `Epi` (token + warrant type) versus a separate `SoundWarrant` interface that adds + a soundness map from evidence to claim. His certificate (`check_signature`, + `recheck_certificate`, sealed digests) is a warrant; his "must not accuse honest code" is the + soundness obligation. The modality spectrum (`FactiveModality` has `reflect`; `BeliefModality` + deliberately does not) is a ready-made vocabulary for which of his verdicts are veridical and + which are defeasible. +* *Residual evidence types* answers a different question he must answer every day: which + explanations are compatible with an observation plus its evidence constraints, and what holds + for **all** of them. That gives him the distinction his error taxonomy needs — "leakage is + present" (presence) versus "this term causes it" (value identification) — and the fence that + *candidate counts are not probabilities*, which is exactly right for scoring overfitting + probes. + +And the discipline worth copying: his Trap Suite is an expected-rejection corpus. The estate's +version pairs nine deliberately-invalid modules with a *certified finite checker proved to agree +with its reference exploration over all 546 configurations by `refl`* — a regression can't +silently change a verdict. + +**Copy-paste message** + +> I have been reading `Monte-Neo` — the independence claim and the false-accusation template in +> particular. The line that stuck with me is that the verifier must not "silently stop catching +> a leak or start accusing honest code": that is soundness and completeness pulling against +> each other over probe heuristics, and it is the hard part of what you are doing. +> +> Two small research artefacts of mine might be useful to you, both deliberately minimal: +> +> One separates *having evidence* from *the evidence being sound*. It has a `Warrant` (an +> evidence token), an `Epi` (token paired with its warrant type), and a separate `SoundWarrant` +> interface that adds an explicit soundness map — plus a modality spectrum where the factive +> version carries a `reflect` and the belief version deliberately does not. Your certificates are +> warrants; your false-accusation constraint is a soundness obligation. Naming them separately +> is what stops a receipt being read as a result. +> +> The other is about which explanations survive an observation, and it separates *presence* from +> *value identification*: you can establish that a leak exists without identifying the term that +> causes it, and those need different evidence. It also insists that candidate counts are not +> probabilities — which is exactly the discipline overfitting probes need. And the way it +> certifies its own checker (a finite checker proved to agree with a reference exploration over +> every configuration, plus deliberate invalid cases that must be rejected) is a pattern I would +> steal for a Trap Suite regression harness: a verdict change becomes a failing correspondence +> rather than a silent shift. +> +> Both are prototypes, not products — if either maps onto a real edge in your verifier I am glad +> to send pointers. + +*Rationale (not for sending): he is shipping a verifier with a public honesty surface — the +closest thing in the follower list to a natural consumer of two family members. Note the +deliberate "prototypes, not products".* + +--- + +### 1.5 @markbakos — `preflightx` + +**What he is building.** A Rust repository-malware scanner: inventories files, classifies bytes +independently of extensions, follows imports from npm/VS Code/devcontainer/CI roots, traces +remote responses into `eval`/`Function`/VM APIs/process execution, applies YARA-X signatures, +and runs the whole thing sandboxed under Landlock + seccomp, failing closed by default. + +**The struggle.** His README is unusually honest and shows exactly where the pain is: + +> *"This is a bounded malware-focused model, not a complete JavaScript interpreter and not a +> verdict that a repository is safe. Dynamic module targets, unresolved imports, parser +> failures, and reached analysis limits are reported; **parser or resource limits make a scan +> incomplete (exit code 2)**."* + +*"Deteministic mutation smoke tests do not replace coverage-guided fuzzing; broad corpus +calibration, macOS/Windows sandbox backends, Linux AArch64 runtime proof, packet-capture +evidence, and release supply-chain gates remain open."* + +And in the code: `Classification { record, findings, incomplete_reasons, text }` plus a +`Confidence` enum, and a test named +`extra_language_heuristic_is_limited_to_one_file_and_marks_execution_roots` — a heuristic whose +*limits are asserted in the test name*. + +**The hook — `absolute-zero` (OND) + `epistemic-types`.** Two things: + +* OND ("observational null disclosure") formalises a guarantee that is *always relative to a + declared observation model `O`*, and requires **every claim to ship a residue list of + out-of-scope observables** — "the honest boundary between the proof and the physical metal". + That is his README paragraph, turned from prose into data. Making the residue list a + machine-readable field on every finding is the difference between "we warned you once" and + "this verdict cannot be read as more than its model". +* Epistemic types give him the missing type for `Confidence` + `incomplete_reasons`: the minimal + interface that separates "a receipt exists" from "the claim is true" (`Warrant` vs + `SoundWarrant`), with a *belief* modality that deliberately has no `reflect`. An incomplete + scan is a belief; a clean scan is not thereby a fact. Today that distinction lives in an exit + code and a prose paragraph; as a type it cannot be dropped by a caller. + +Worth stealing too: the estate's pairing of each accepted case with an **expected-rejection +fixture** pinned in CI (occupancy-types pins seven distinct error codes: `E_DOUBLE_FREE`, +`E_LEAK`, `E_ALIAS`…) — for a scanner, the analogue is pinning *what a bad change would +accuse*, so a regression shows up as a false accusation rather than a miss. + +**Copy-paste message** + +> I read `preflightx` this week — the classification pipeline and the sandbox story. Your README +> contains the two sentences I wish every scanner shipped: *"not a verdict that a repository is +> safe"*, and *"parser or resource limits make a scan incomplete (exit code 2)"* — and +> `extra_language_heuristic_is_limited_to_one_file_and_marks_execution_roots` is a heuristic +> that states its own limits in the test name. That is the right discipline. +> +> I have two small pieces of formal work that happen to be shaped like your remaining gap. +> +> The first is a two-pillar effort where the second pillar — "observational null disclosure" — +> defines a guarantee *always relative to a declared observation model O*, and requires every +> claim to ship a **residue list** of out-of-scope observables: the honest boundary between the +> proof and the metal. That is your incompleteness paragraph, except as a structured field on +> every finding rather than prose. It also gives you a principled way to write down what +> `Confidence` means. +> +> The second is a minimal interface that separates *having a receipt* from *the receipt being +> sound*: a `Warrant` (evidence token), an `Epi` (token + its warrant type), and a separate +> `SoundWarrant` that adds an explicit soundness map — with a belief modality that deliberately +> lacks a reflect, so nothing can quietly promote a belief to a fact. An incomplete scan is a +> belief; a clean scan is not thereby a fact. As an exit code that distinction is advisory; as a +> type it cannot be dropped by a caller. +> +> One pattern worth stealing from the same estate regardless: every accepted case gets a paired +> *expected-rejection* fixture pinned in CI — so a regression shows up as a false accusation +> rather than as a silent miss. Given your false-positive surface, that is probably the highest +> value per line of test code you can add. +> +> Prototypes all, and I am not selling anything — but if the residue-list idea is useful I can +> point you at the shape. + +*Rationale (not for sending): he is a careful engineer; the residue-list-as-data suggestion is +concrete and cheap, and the expected-rejection framing is directly actionable for his corpus +work.* + +--- + +### 1.6 @BoggersTheFish — `thinking-system` + +**What he is building.** A "verifier-first monorepo": *"a verifier-gated kernel… residual/tension +accounting across activation, contradiction, provenance and verification dimensions… sealed +adversarial evaluation"*, with content-addressable (SHA-256) receipts drawn from a stated +pipeline: + +> representation → lawful quotient → **relative residual** → sufficient observer family → +> **localised obstruction** → minimal typed revision → sealed adversarial evaluation + +**The struggle.** He is *already doing the estate's discipline*, in a hand-rolled form. +`core/kernel/obligations.py` defines a `VerificationResult` carrying `evidence`, +`artifact_hashes`, `consumed_premises`, `produced_claims`, `deterministic: bool` and +`limitations: list[str]` — with values like `["structural_validation_only"]`, +`["allowlisted_arithmetic_ast_only"]`, `["bounded_single_argument_arithmetic_examples_only"]`. +Those limitation strings are exactly the honest-bound records the estate keeps, but as free +text they can be dropped, edited or ignored without anything failing. + +**The hook — `echo-types` + `epistemic-types` + the shared glossary.** Genuinely three-way: + +* His *"lawful quotient → relative residual → localised obstruction"* **is** the echo + construction: a non-injective map, the fibre over an output, and the obligation to keep what + was lost. `echo-types` has a mechanised **loss taxonomy × residue-shape grid** you could + borrow as the vocabulary for *which* residual he is accounting, and a proved + `no-canonical-disaggregation` result that is worth knowing before anyone tries to invert an + aggregate. +* The estate's *"first residual milestone"* gives his kernel a sharper question: **presence + versus value identification** — "a residual exists" and "this term is the cause" need + different evidence, and neither is a probability. +* The shared glossary separates *residual* (discrepancy against a declared model) from *residue* + (information retained after a map) from *measure* and *grade*. His README uses "relative + residual" and "residual accounting" broadly; since he is building a research vocabulary, + aligning the two costs nothing now and prevents an expensive collision later. + +And the cheapest concrete upgrade: the estate pairs every accepted case with *expected-rejection +fixtures* (twelve deliberately-invalid modules must be **rejected** by the checker, pinned in +CI). Applied here: one rejection fixture per declared `limitation`, proving the limitation is +*observable* — i.e. that the verifier actually fails on what it claims to exclude. A limitation +string that nothing tests is a claim; a limitation with a failing case behind it is a fact. + +**Copy-paste message** + +> I read `thinking-system` this week and recognised a lot of my own work in it — the +> verifier-gated kernel, the content-addressable receipts, and especially `limitations` in +> `core/kernel/obligations.py` (`structural_validation_only`, +> `allowlisted_arithmetic_ast_only`, `bounded_single_argument_arithmetic_examples_only`). Those +> are honest-bound records, which almost nobody writes down. +> +> Your pipeline line — *representation → lawful quotient → relative residual → localised +> obstruction → minimal typed revision* — is, structurally, the thing one of my repos exists +> for: an irreversible map where the fibre over each output retains a proof-relevant constraint +> on what was lost. That repo has a mechanised taxonomy of loss kinds and residue shapes you +> could use as vocabulary for *which* residual you are accounting, plus a proved result that no +> canonical disaggregation exists once you aggregate — worth knowing before anyone tries to +> invert one. +> +> Two concrete suggestions, both cheap. First: make each `limitation` string falsifiable by +> pairing it with a *rejection fixture* — a case that the verifier must fail on, pinned in CI. +> A limitation nothing tests is a claim; a limitation with a failing case behind it is a fact, +> and it stops a limitation being silently dropped in a refactor. I keep twelve such fixtures +> for a much smaller library. +> +> Second: one vocabulary caution. I keep a shared glossary that distinguishes *residual* +> (discrepancy against a declared model) from *residue* (information retained after a map) from +> a numerical measure and from a resource grade. Since you are building a research vocabulary, +> fixing those senses now is free; later it is expensive. +> +> Both my repos are prototypes with explicit open items, and I am not claiming otherwise — but +> if either maps onto your residual accounting I am happy to send pointers. + +*Rationale (not for sending): he is the closest to an independent co-inventor of your programme. +Lead with recognition, not correction; the limitation-falsifiability suggestion is the one that +helps him most and can be adopted in an afternoon.* + +--- + +### 1.7 @Lxcardoza993 — `LLMDOG` + +**What he is building.** A local-service watchdog that probes, diagnoses with a local LLM, +applies four guardrails, fixes, verifies, rolls back, and *learns*: recurring bugs are distilled +into `known_issues` so the next recurrence heals from a whitelist. Bilingual README, 26 tests, +71% coverage, DRY_RUN by default. + +**The struggle — visible in his own commit history.** Three of his last six commits are +fightbacks: + +* `fix: TG 通知加重试——瞬时 SSL 抖动不再丢警报/喜报` (retry so transient SSL jitter stops losing + alerts) +* `fix: bug 学习签名改用修复动作——**同病不同措辞不再裂成多个 bug**` (bug-learning signature switched to + the fix action, so *the same bug in different wording no longer splits into several bugs*) +* `fix: max_tokens 2000→4000——reasoning thinking burns out and truncates NO_JSON` + +The middle one is the interesting one, and it is a deep problem wearing a small hat: he is +hashing an LLM's *surface rendering* to identify a bug, and the rendering is non-injective — +many wordings, one bug. His fix (key on the fix action instead) is a coarser map, which merges +*more* — and some of those merges will be wrong in the other direction. + +**The hook — `echo-types`.** This is the fibre question exactly. `Echo f y = Σ (x : A), f x ≡ y`: +the origins compatible with one output. His bugs are origins, the LLM's diagnosis is the map, +and the identity of a bug must be carried by a *retained constraint* rather than by the wording. +The pieces that transfer: + +* the **loss taxonomy** asks the design question he needs — *what may the signature forget, and + what must it keep* — rather than tuning a hash until the split stops; +* the proved **no-canonical-disaggregation** result explains why he will never get back from the + learned aggregate to the individual bug, which is an argument for keeping the fibre (the + equivalence class of renderings, with a witness) alongside the signature; +* the rule that *equal measured values do not imply equal residues* is the formal reason two + different bugs can share the action key he just adopted. + +Practical first step available today: pair his learned-issue entries with *expected-rejection* +cases in `tests/` — a case where the "learned" remedy must **not** be applied, so a +mis-merge shows up as a failing test instead of a 3am failed heal. + +**Copy-paste message** + +> I read LLMDOG this week — the guardrails and the learning loop — and one of your commits did +> something I want to point at, because I think you have hit a deeper problem than the commit +> message suggests: *"same bug, different wording no longer splits into several bugs."* +> +> You fixed that by keying the bug signature on the fix action instead of the wording. That is +> the right instinct, and it moves the problem rather than dissolving it: the action key is a +> coarser map, so it will merge some bugs that are genuinely different. The formal reason is that +> the LLM's rendering of a bug is not injective — many wordings, one bug — so no hash of the +> surface will ever be the identity. What you need is not a better hash but an explicit decision +> about *what may the signature forget, and what must it retain*. +> +> That question is the subject of a small Agda development of mine: it treats a non-injective +> map, keeps the fibre over each output (all the origins compatible with it) as a witness, and +> gives a taxonomy of loss kinds and residue shapes. There is also a proved result that once you +> aggregate, no canonical disaggregation exists — which is exactly why the original renderings +> have to be retained alongside the signature rather than recovered from it. +> +> The cheapest concrete step, regardless of any of that: give every learned issue an +> *expected-rejection* test — a case where the learned remedy must **not** be applied. Then a +> mis-merge shows up as a failing test rather than as a failed heal at 3am. (Your 26 tests and +> the guardrail design suggest you would get a lot out of that pattern.) +> +> My repo is a prototype with open items — not claiming a product — but if the fibre framing is +> useful I can send the module names. + +*Rationale (not for sending): the "same bug, different wording" commit is a genuine +information-loss problem misread as a hashing detail; the note gives him the sharper framing and +one immediately actionable test pattern.* + +--- + +### 1.8 @dbunt1tled — `parquet2csv` + +**What he is building.** A Go CLI that streams Parquet ↔ CSV a row at a time, with the deliberate +property stated in the README: *"Flat memory: peak usage is bounded by `--row-group-size` and +`--page-size`, not by row count"* and *"Peak memory for CSV → Parquet is set by two flags rather +than by the size of the input"*. His most recent commit rewrote the converter for *"flat memory +and performance… adds tunable row group and page sizes"*, and earlier ones fixed *"resource +closure, and sync.Pool usage"*. + +**The struggle.** The design is right and the accounting is informal. `--verbose` prints +*elapsed time and memory usage* as single numbers; page and row-group boundaries are the places +where buffers are born and die; `sync.Pool` reuse is reclaimed by the GC, so the actual peak is +a function of scheduling as much as of the two flags. The README even says it: larger row groups +are *"better for analytical readers, at the cost of peak memory"* — the trade-off is real and +currently only tested empirically (and his test suite is 20 files' worth of behaviour, not of +bounds). + +**The hook — `occupancy-types`.** This is the closest match in the whole set — his repo is +already speaking the language: + +* An **occupancy grade is a pair**: the high-water mark and the live count, composed by the + *non-commutative* monoid `(p₁,n₁)·(p₂,n₂) = (max(p₁, n₁+p₂), n₁+n₂)`. That is precisely what + `--verbose` should report — peak *and* live, per stage — because a single "memory usage" number + cannot be composed across reader → decoder → writer, while the pair can. It also lets him + *prove* "peak is bounded by the flags, not the row count" as a composition statement rather + than a measured observation. +* The plan's other claim is his second pain point: **reclamation is a function of protocol + shape, not of GC**. Page/row-group boundaries are the reclamation points; `sync.Pool` reuse is + exactly the case where the free moment depends on GC. Making the boundary explicit is what + turns "usually flat" into "flat by construction, measured ≤ certified". +* And the discipline that makes it honest: he already fixes grades at check time (his flags are + constants), which is the plan's *grade constancy rule* — needing anything else is the + documented kill signal. + +**Copy-paste message** + +> I used `parquet2csv` as an excuse to read its README properly this week, and the line *"peak +> usage is bounded by `--row-group-size` and `--page-size`, not by row count"* is the whole +> reason I am writing. You have built a tool whose memory behaviour is a *bounded, composable* +> resource — which is rarer than it should be — but the accounting behind it is still informal. +> +> I keep a small calculus for exactly this: a *state*-resource grade is a pair (peak, live), +> composed by a non-commutative high-water-mark monoid — `(p₁,n₁)·(p₂,n₂) = (max(p₁, n₁+p₂), +> n₁+n₂)`. Three things fall out that map onto your code. `--verbose` should print peak *and* +> live per stage, because a single number cannot be composed across reader → decoder → writer +> while the pair can. Your page/row-group boundaries are the reclamation points, which is what +> turns "usually flat" into "flat by construction". And `sync.Pool` reuse is the case where the +> free moment depends on the GC rather than on your protocol — the calculus treats reclamation +> as a function of protocol shape, which would let you certify the bound instead of measuring it. +> +> Related: the calculus separates a *cost* grade (`+` in sequence, `max` across alternatives) +> from a *state* grade like yours, because they genuinely do not compose the same way. If you +> ever add a `--timeout` or a retry budget alongside the memory flags, that split stops you +> conflating two axes. +> +> It is a research repo with open rungs, not a library you should depend on — but the monoid is +> three lines and the framing is free. Happy to send it. + +*Rationale (not for sending): the pair-vs-single-number suggestion is concrete, immediately +useful, and derives from the repo's core claim rather than decorating it.* + +--- + +### 1.9 @tawdesangeeta1973-coder — `arc-propose-verify` + +**What he is building.** *"Neural proposals + symbolic verification for ARC-style tasks: program +synthesis, a verifier, recursive reasoning, and a growing abstraction library."* Created +2026-10-02 — two days old, three files. Early. + +**The struggle.** Too early for a struggle in code, but the *problem* is already fully visible in +the title: a neural proposer generates candidate programs, a symbolic verifier checks them. The +classic failure mode of that architecture is a verifier that can only say "consistent with the +demonstrations" while the proposer's scores get read as probabilities — and a demonstration set +that under-determines the rule. + +**The hook — `residual-evidence-types`.** The repo's central object is +`Candidate observe r E = Σ (w : W), (observe w ≡ r) × E w` — a world together with evidence that +it reproduces the observation and satisfies the declared constraints — and it is built around one +distinction: **presence versus value identification**. You can prove a property holds in *every* +program consistent with the demonstrations (presence) without identifying the rule +(identification); and neither conclusion is a probability. That is precisely the ARC setting: the +demonstration pairs are the observation function, the candidate programs are the fibre, and the +verifier's job is the candidate-wide claim. Two fences from the same work are worth having early: +*constructing a candidate does not recover the world* (his verifier can prove consistency +without the proposal being the true rule), and *an empty candidate set is not a warrant for every +claim* (a failed search is not a proof of impossibility). + +The discipline worth borrowing alongside it: the estate's minimal Agda core ships **nine +deliberately-invalid modules that must be rejected** by the checker, and a finite checker proved +by `refl` to agree with a reference exploration over all 546 configurations. For a proposer + +verifier, that shape is a regression harness: the verifier's accept/reject table is the artefact, +and the neural side can change freely as long as the correspondence holds. + +**Copy-paste message** + +> I saw `arc-propose-verify` go up this week and wanted to send one thought while it is still +> cheap to shape, because you have picked one of the sharpest versions of a problem I work on. +> +> The standard failure mode of "neural proposals + symbolic verifier" is that the verifier can +> only establish *consistency with the demonstrations*, while the proposal scores quietly get +> read as probabilities. There is a small body of work I have that draws exactly these lines: it +> defines a candidate as a world plus evidence that it reproduces the observation *and* satisfies +> the declared constraints, and then separates **presence** — a property holds in every +> admissible candidate — from **identification** — this is the one. Arc's demonstrations +> under-determine the rule; that is not a defect of your verifier, it is the structure of the +> problem, and it deserves two different names. +> +> Two fences from it that are worth adopting before the code grows: constructing a candidate does +> not recover the world (your verifier can prove consistency without the proposal being the true +> rule — keep that premise explicit), and candidate counts are never probabilities. +> +> One pattern, if it is useful: the version of this I have keeps nine deliberately-invalid cases +> that the checker *must* reject, plus a finite checker proved to agree with its reference +> exploration on every configuration. For a proposer/verifier pair that is a very good regression +> harness — the verifier's accept/reject table is the artefact, and the neural side can then +> change freely as long as the correspondence holds. +> +> Mine is early research, not a library — but you are two days in, and the vocabulary is the part +> that is expensive to change later. + +*Rationale (not for sending): two days old, so the note is about framing rather than code — +which is the honest thing to send and also the most useful thing at that age.* + +--- + +### 1.10 @Berserk-hub150 — `skillhawk` + +**What he is building.** A security scanner + hands-on lab for AI agent skills, `SKILL.md` files +and MCP configs — *"Catch dangerous agent instructions before they touch your shell, files or +credentials."* Zero-dependency, 64 stars, a five-minute challenge, releases and good-first-issues +labels. + +**The struggle.** The domain's hard part is that a "dangerous instruction" is only dangerous +*relative to a declared threat model*: what counts as exfiltration depends on which channels you +consider observable. So a scanner here faces exactly the problem the estate formalises — a +guarantee that is meaningful only relative to a declared observation model, and that must state +what it did **not** look at. The five-minute challenge is a good instinct (an adversarial corpus +by another name) but the scanner's promise and its model boundary need to travel together. + +**The hook — `absolute-zero` (OND) + `epistemic-types`.** OND defines "a program that reveals +nothing about its secret input to a declared observer: its observable trace is constant over the +secret, relative to a declared observation model `O`" — and the discipline that makes it +honest: **every OND claim ships a residue list of out-of-scope observables.** Translated to +SkillHawk: every verdict ships the list of channels the model did not consider (base64-in-comment +to an allowed host, side channels through tool ordering, timing…). That turns a marketing claim +into an auditable one, and it is a genuinely differentiating feature for a skill scanner. + +The second piece: `epistemic-types` separates an evidence token (`Warrant`) from a sound warrant +(`SoundWarrant`, which adds an explicit map from evidence to claim). A finding "this skill sends +credentials to an unknown host" is a warrant; whether it is *sound* depends on the declared +model. Making the severity/confidence field a typed warrant with a documented soundness condition +is the difference between a scanner that can be trusted and one that trains users to ignore it. + +Practical first step: pair each detection rule with an **expected-rejection fixture** — a benign +skill that must **not** be flagged — and pin them in CI. For a scanner whose worst failure is +noise, false-positive fixtures are the highest-value tests it can have. + +**Copy-paste message** + +> I have been reading `skillhawk` this week — nice to see MCP/skill security taken seriously as +> its own surface, and the 5-minute challenge is a good idea. +> +> One thought from a formal corner that might be worth more to you than a feature request. In a +> security scanner for agent instructions, "dangerous" is only meaningful *relative to a declared +> threat model* — which channels you consider observable, which behaviours you consider actions. +> There is a formalisation of exactly this (it comes from a project about programs that provably +> reveal nothing to a declared observer) whose one non-negotiable rule is that **every claim ships +> a residue list of out-of-scope observables**: the explicit boundary between what was proven and +> what was never looked at. +> +> Applied to SkillHawk, that becomes a real feature and a differentiator: every verdict carries +> the list of channels the model did not consider — encoded payloads in comments to allowed +> hosts, ordering/timing side channels, and so on. It converts "we scan skills" into "here is +> exactly what this scan could not have caught", which is the thing that makes scanners trusted +> rather than ignored. +> +> Related and smaller: keep "we have evidence of X" separate from "X is true". I have a minimal +> interface for that (`Warrant` vs a separate `SoundWarrant` with an explicit soundness map), and +> it maps cleanly onto a finding plus its confidence. +> +> The cheapest high-value test change, whatever you do with the above: give every detection rule +> an *expected-not-flagged* fixture — a benign skill that must stay clean — pinned in CI. Your +> worst failure mode is noise, so false-positive fixtures buy more than more rules. +> +> All research-stage on my side, no product — but the residue-list idea is small and I am glad to +> sketch the shape. + +*Rationale (not for sending): 64 stars and an actively-labelled issue tracker — a repo where a +good idea can actually land. The residue list is the differentiator, and the +false-positive-fixture advice is the fastest win.* + +--- + +### 1.11 @kyal102 — JARVI3 (profile + tools) + +**What he is building.** Deterministic verification infrastructure for high-consequence AI +workflows. His framing, in his own words across the profile and the tooling: *"AI proposes. Gates +verify. Evidence records. Replay checks drift."* and *"Each gate says what it checks, what it +cannot establish, and what validation is still required"* and *"No model in the loop for the +verdict"* and *"Every pass states what it does not prove."* + +**The struggle — and this is why he is in Tier 1 despite having no library to point at.** He is +selling and building verification *gates*, and the hardest practical failure of gates is not a +wrong verdict: it is **a gate that does not run and still reads green**. I measured exactly that +this week, in the wild, and it is worth more to him than any framing I could offer. + +**The finding, measured today.** On `hyperpolymath/occupancy-types`, **96 of the last 100 +workflow runs concluded `startup_failure`** — including on pushes by the repository owner and +including every gate (secret scanning, static analysis, governance, test workflows). The +distinctive part is that these runs show up in the Actions list *as completed runs*, with no jobs +and no logs, while other repositories in the same estate show green badges for the same workflow +families. A companion case is stronger still: a pull request merged with **zero CI signal** +because all five of its check-suites recorded `STARTUP_FAILURE` — the change was never +type-checked, and it was merged as a *fix for a red build*. + +**The hook — your estate's own discipline, plus one recommendation he can adopt verbatim.** +Two things transfer directly: + +* **A gate must prove it ran.** Treat "did not start" as failure for every required check, and + verify *workflow execution*, not just absence of failure. That is a one-line-ish policy change + with a large blast radius, and he is the right person in this follower list to write it up. +* **A receipt is not a claim.** The failure above is precisely why the estate's pattern is a + dated AFFIRMATION pinned to a commit SHA plus a PROOF-STATUS that separates proved from open + from *blocked* (blocked ≠ retracted, and blocked items carry the exact command that would + unblock them). His "every pass states what it does not prove" is the same principle; the + estate's version makes it machine-checkable and dated, so a stale receipt cannot be read as a + current one. + +**Copy-paste message** + +> I read your JARVI3 material this week — "AI proposes. Gates verify. Evidence records. Replay +> checks drift." — and I have something measured that I think is directly in your lane, so I am +> sending it rather than a pitch. +> +> The failure mode that will hurt your customers is not a wrong verdict from a gate. It is **a +> gate that never ran and still reads green.** I hit a clean instance this week: a repository +> where 96 of the last 100 workflow runs ended `startup_failure` — the workflows are listed as +> completed runs, with zero jobs and no logs, across the whole set including the security and +> governance gates. In an adjacent case, a pull request was merged with *zero* CI signal because +> all five of its check-suites recorded `STARTUP_FAILURE`; the change was never checked at all, +> and it merged as a fix for a red build. +> +> Two things I would take from that, and one is a policy you can sell. First: treat "did not +> start" as failure for every required check, and verify that the workflow *executed* rather than +> that it did not fail. That single change closes the hole above. Second: the discipline I use to +> stop a receipt ageing into a claim — a dated affirmation pinned to a commit SHA, and a status +> document that separates *proved*, *open*, and *blocked*, where blocked items carry the exact +> command that would unblock them. "Every pass states what it does not prove" is your version of +> the same principle; making it dated and commit-pinned is what stops a stale pass being read as +> a current one. +> +> Happy to send the two documents as a shape, and interested in how you handle the same problem +> on your side — you are closer to that market than I am. + +*Rationale (not for sending): he is a *peer on the same problem* with commercial exposure, so +this is the one message that leads with a finding rather than a request. It also plants the +estate's receipt discipline where it could actually be adopted.* + +--- + +## 2. Tier 2 — shorter notes (repo read, lighter touch) + +### 2.1 @j0hnWeider — `security-testing` + +**Read.** A TypeScript/Playwright offensive-security portfolio against ServeRest: 39 scenarios +mapped to OWASP Top 10, k6 for performance, Allure live reports, CI per push. + +**Struggle.** The suite asserts that the API *rejects* things — which is the right kind of test, +but the assertions are per-scenario pass/fail. When a rejection suite is graded only by "did it +fail", a regression that makes an endpoint accept something it used to reject can pass silently +if the assertion is loose, and a legitimate error-class change produces noise instead of a +signal. + +**Hook — `occupancy-types`' rejection discipline.** Its manifest pins seven rejection fixtures, +each to a *distinct error code* (`E_DOUBLE_FREE`, `E_LEAK`, `E_ALIAS`, `E_PROTOCOL`, +`E_USE_AFTER_DROP`, `E_CLOSE_NOT_END`), so the suite asserts failure *identity*, not merely +failure. The same shape applied to his 39 scenarios — each expecting a specific status/violation +class — turns an offensive suite into a regression harness for the API's security posture. + +**Copy-paste message** + +> I read your security-testing suite this week — 39 offensive scenarios wired to OWASP and +> reported through Allure is a solid setup, and the k6 layer alongside it is the part most people +> skip. +> +> One suggestion from a small project of mine that does a similar (much smaller) thing: pin every +> rejection to its **own error class**, and assert the identity of the failure rather than the +> fact of it. I keep seven expected-rejection fixtures, each asserting a distinct code +> (`E_PROTOCOL`, `E_LEAK`, `E_ALIAS`, and so on) from a machine-readable manifest. The reason is +> that a "rejected" assertion can pass for the wrong reason — a renamed error, a changed status, +> or a validator that now rejects everything — and only the identity check catches that. For a +> 39-scenario offensive suite, a manifest of expected violation classes would give you the same +> regression strength in an afternoon, and it makes the report readable by an auditor rather than +> just by you. +> +> No ask — just thought it might be useful where you are already careful. + +*Rationale (not for sending): a genuine upgrade to an already-good suite, and it advertises the +manifest pattern rather than the formalism.* + +### 2.2 @Morez-Momeni — `system-log-analyzer` + +**Read.** A small, actively developed Python log analyser (`analyzer.py`, `main.py`, +`visualizer.py`) with recent commits adding process filtering/ranking and log statistics plus +visualisation. + +**Struggle.** The output is claims derived from an observation function over a log: "top process", +"error rate", "spike". Log analysis has the classic confounds — missing lines, rotated logs, +clock skew between sources, a filter applied before counting — and those are exactly the +premises that decide whether a derived claim holds. + +**Hook — `residual-evidence-types` + `epistemic-types`.** The distinction worth having early: +**presence versus identification**. "Some process is failing repeatedly" (a claim over all +admissible worlds consistent with the lines) is different from "this process is the cause", and +they need different evidence. The related fence — candidate counts are not probabilities — is the +reason a ranking by log lines is a ranking of *mentions*, not of risk. And an epistemic standpoint +record (which file, which host, which time window, which filter) attached to each derived claim is +what makes a report auditable later. + +**Copy-paste message** + +> I have been reading your log analyser this week — the filtering/ranking work is coming along +> nicely. +> +> One thing worth deciding early, because it is the difference between a useful report and an +> over-claimed one: separate *"these lines show X"* from *"X is the cause"*. Rankings over logs +> rank mentions, not causes, and the premises that decide which it is — rotated or missing lines, +> per-host clock skew, filters applied before counting — are worth recording next to the output +> rather than living in your head. I have a small research repo about exactly this (a claim holds +> for all worlds consistent with the observation *and* the evidence constraints, and candidate +> counts are never probabilities), and a second one about recording the standpoint — the tool, +> version, window and filter — as part of a claim's receipt so a report remains auditable months +> later. +> +> Neither is a library; both are patterns. If it is useful I can send the two definitions, which +> are short. + +*Rationale (not for sending): small project, low stakes, but the presence/cause split is a real +improvement and the note costs him nothing.* + +--- + +## 3. Delivery notes (for you, not in the messages) + +* **Channel.** These read as DMs or as a comment on a recent PR/issue. GitHub issues are public + and searchable — for the ones making a *claim about their code* (1.7's mis-merge argument, + 1.5's incompleteness framing) a DM is kinder; for 1.11 (a finding, not a critique) a public + comment is a genuine contribution. +* **Links.** I have deliberately left URLs out of the drafts. Add at most one per message, and + prefer the README over the proof file — the proof files are for the three or four people who + will actually read Agda (1.2, 1.4, 1.6). +* **Sequencing.** Send the ones where you offer a *finding* first (1.11, 1.1, 1.3), because they + ask nothing; then the peers (1.2, 1.4, 1.6); then the lighter notes. If someone replies, the + follow-up is a single file, not a repo tour. +* **Do not send a note before checking the referenced file still exists.** Four of these repos + were pushed within the last 48 hours; commits move. Each note names a file and a commit + subject, so a ten-second check is enough. (I re-verified all of them at clone time today.) +* **The boundary to keep.** Every draft says "prototype" where the estate says prototype, and + "open" where the plan says open — K-CUT is described as an open conjecture in 1.3, and + `occupancy-types` is described as research with open rungs in 1.8. Please keep those words if + you edit. +## 4. Next-up set (plausible hooks, not yet read) + +These are the accounts I would read next — each has public code in a domain where one of +the seven repos plausibly lands. One line each on the *presumed* hook; none of these has +been read yet, so nothing here is a draft. + +* **@1minds3t** — omnipkg. *Python env interception — a resolver's merge/dedup decisions are a non-injective map (echo fibre); high collision risk, worth care* +* **@mikalv** — Prism (hybrid search). *retrieval scoring = an observation function with a lossy ranker; echo + residual (presence vs identification)* +* **@ZenyaDAR** — PlayGuard (MCP proxy). *agent tool-call proxying — OND-style declared-observable model + residue list; warrants for allow/deny decisions* +* **@godstime-dev** — aviation-weather-intelligence. *ETL over weather observations; residual-evidence (which worlds satisfy observation + constraints) is close to METAR/forecast reconciliation* +* **@manman4** — OEIS_04. *implementing OEIS sequences in C — a prefix under-determines the sequence (presence vs identification is the headline case)* +* **@a5i** — journio. *Rust; not yet read — check for state/protocol bounds before any claim* +* **@kh-mahmoud** — state-machine-experiments. *state machines invite the occupancy/HWM composition claim directly* +* **@GhCristea** — rdf-parser. *RDF/IRI handling — canonicalisation is a non-injective map with a real retained-witness obligation (echo)* +* **@ruiyangzhou01** — qml-inference-protocol. *inference protocol — session/projection framing may apply* +* **@SoheilGtex** — math-research-radar. *paper monitoring — epistemic standpoint records (tool, version, window, hash) map onto source provenance* +* **@thejesh23** — ai-plugin-rankings. *ranking = observation + aggregation; `no-canonical-disaggregation` is directly relevant* +* **@lshariprasad** — BULIDATHON-2026 (RAVEN, IoT). *IoT retrieval robot — occupancy for bounded buffers/queues if it grows past a hackathon* +* **@Kelpejol** — Orgos. *unread; Python, active* +* **@captainblair** — Nexa. *unread; TypeScript, active* + +## 5. Full triage + +Fetched **225** of 269 followers (some GitHub API lookups failed for private/renamed +accounts). Of these: **59** have no substantive public code (profile/config repos), +**34** are inactive (>180 days), and **155** are active with public code. + +### 5.1 Active with public code (155) — the pool the notes came from + +| days | account | lang | most-recent repo | ★ | +|---|---|---|---|---| +| 0 | @1minds3t | Python | `1minds3t/omnipkg-metadata` | 5 | +| 0 | @Berserk-hub150 | JavaScript | `Berserk-hub150/skillhawk` | 64 | +| 0 | @CodeMasterAbhishek | JavaScript | `CodeMasterAbhishek/Daily-Dose-of-TMOCK` | 8 | +| 0 | @Connor9994 | Python | `Connor9994/GitHub-Language-Stats` | 71 | +| 0 | @Daniel21Ayen | TypeScript | `Daniel21Ayen/freshman-plus` | 0 | +| 0 | @EimanTahir027 | - | `EimanTahir027/Convolutional-Neural-Networks-CNN` | 2 | +| 0 | @Dreamerol | HTML | `Dreamerol/CARDFOLIO` | 24 | +| 0 | @Elite588 | JavaScript | `Elite588/undici` | 9 | +| 0 | @Morez-Momeni | Python | `Morez-Momeni/system-log-analyzer` | 0 | +| 0 | @NeoZorK | Python | `NeoZorK/Monte-Neo` | 8 | +| 0 | @NazmusSayad | Python | `NazmusSayad/Git-Stats` | 39 | +| 0 | @STD-DEEPANSHU | JavaScript | `STD-DEEPANSHU/StdGram` | 0 | +| 0 | @SoheilGtex | Python | `SoheilGtex/math-research-radar` | 7 | +| 0 | @ShivamMathtech | Python | `ShivamMathtech/ApertureNav-Sim` | 0 | +| 0 | @Sunil56224972 | HTML | `Sunil56224972/Void-Dev-Platefrom` | 1 | +| 0 | @TadesseAsrie | JavaScript | `TadesseAsrie/Ethio-Keyboard-web-app` | 4 | +| 0 | @Teagar | C# | `Teagar/crawl-online` | 1 | +| 0 | @abduverse | Python | `abduverse/zkteco_attendance` | 4 | +| 0 | @altyebv | JavaScript | `altyebv/INmore` | 2 | +| 0 | @arielshakaramiro | Python | `arielshakaramiro/hf-model-watcher` | 0 | +| 0 | @barissozudogru | TypeScript | `barissozudogru/gha-cost` | 1 | +| 0 | @gamemann | GDScript | `gamemann/game-playground` | 1 | +| 0 | @kenjinote | Python | `kenjinote/blog` | 131 | +| 0 | @manman4 | C | `manman4/OEIS_04` | 21 | +| 0 | @matigulin | TypeScript | `matigulin/maze-ui` | 6 | +| 0 | @metatronslove | - | `metatronslove/github-repo-traffic-viewer` | 1 | +| 0 | @rzrabbi | Markdown | `rzrabbi/upptime` | 1 | +| 0 | @sdiehl | Rust | `sdiehl/groebner` | 8 | +| 0 | @standardgalactic | TeX | `standardgalactic/alphabet` | 268 | +| 0 | @thejesh23 | Python | `thejesh23/ai-plugin-rankings` | 1 | +| 0 | @zhenrez | JavaScript | `zhenrez/ARTTOO` | 0 | +| 1 | @Ali-hey-0 | - | `Ali-hey-0/Cryptography` | 157 | +| 1 | @DarkGlitchLegion | Python | `DarkGlitchLegion/alarm` | 0 | +| 1 | @Lxcardoza993 | Python | `Lxcardoza993/LLMDOG` | 10 | +| 1 | @Sheetal-Patel17 | JavaScript | `Sheetal-Patel17/DevCareerOS` | 2 | +| 1 | @edrfjk | PHP | `edrfjk/nexhris` | 4 | +| 1 | @jfullstackdev | CSS | `jfullstackdev/jfullstackdev.github.io` | 9 | +| 1 | @markbakos | Rust | `markbakos/preflightx` | 0 | +| 2 | @Aegean-E | Python | `Aegean-E/ObesityResearch` | 0 | +| 2 | @Obraims | HTML | `Obraims/web-foundation-days` | 0 | +| 2 | @a-partovii | Python | `a-partovii/on-click-venv` | 1 | +| 2 | @eatsky1006 | - | `eatsky1006/main-goal-main` | 0 | +| 2 | @stevsharp | C# | `stevsharp/Shipping-strategy-demo` | 1 | +| 2 | @tawdesangeeta1973-coder | - | `tawdesangeeta1973-coder/arc-propose-verify` | 1 | +| 3 | @Nour-yahyaoui | Rust | `Nour-yahyaoui/c-editor` | 1 | +| 3 | @Simontechempire | JavaScript | `Simontechempire/SHADOW-X-MD` | 1 | +| 3 | @Sthabiso10 | Dart | `Sthabiso10/Spella` | 0 | +| 3 | @ThakurDivyanshsingh-77 | Jupyter Notebook | `ThakurDivyanshsingh-77/apple_iphone_data_analysis_project` | 2 | +| 3 | @arch-yunus | JavaScript | `arch-yunus/gsb-france-exchange-2026` | 2 | +| 3 | @dovvnloading | Python | `dovvnloading/Cortex` | 37 | +| 3 | @genius-0963 | Python | `genius-0963/Real-time-recommendation-engine` | 0 | +| 3 | @tsnobip | ReScript | `tsnobip/goutues` | 1 | +| 4 | @holilayet | JavaScript | `holilayet/ZoneWeb3` | 3 | +| 4 | @murapadev | C# | `murapadev/NeuralDeck` | 5 | +| 5 | @neoscratchteam | TypeScript | `neoscratchteam/NeoScratch` | 5 | +| 5 | @nearyou | TypeScript | `nearyou/freedomsword` | 0 | +| 5 | @stackpilot05 | - | `stackpilot05/BlackDragon0828` | 14 | +| 6 | @MiladJoodi | JavaScript | `MiladJoodi/MiladJoodi.github.io` | 30 | +| 7 | @Kelpejol | Python | `Kelpejol/Orgos` | 0 | +| 8 | @adriannoes | Jupyter Notebook | `adriannoes/awesome-agentic-ai` | 63 | +| 8 | @aruintelligence | JavaScript | `aruintelligence/aml-core` | 0 | +| 8 | @captainblair | TypeScript | `captainblair/Nexa` | 0 | +| 8 | @lshariprasad | C++ | `lshariprasad/BULIDATHON-2026` | 1 | +| 10 | @Gleb-Shalygin | PHP | `Gleb-Shalygin/course-builder` | 1 | +| 10 | @dbunt1tled | Go | `dbunt1tled/parquet2csv` | 66 | +| 10 | @kulikov-dev | - | `kulikov-dev/prm-config` | 1 | +| 10 | @manvesh1234 | JavaScript | `manvesh1234/Experiments-` | 0 | +| 11 | @engrshuvodas | JavaScript | `engrshuvodas/GrandPulse` | 2 | +| 11 | @mikalv | Ruby | `mikalv/homebrew-prism` | 0 | +| 11 | @xuges | Go | `xuges/remote-shell` | 0 | + +*(showing the 70 most active; the remaining 85 are in the same file — the pattern is the same.)* + +### 5.2 Profile-only / no substantive public code (59) + +@00200200, @AhmedDabish, @AlmigthyMatheus, @BEPb, @ByteBunny777, @ChevCellios, @Eliasilyz, @Fahad-40, @Hamidooh, @IDouble, @Isac999, @JawherKl, @JessicaDevOp, @JohnMwendwa, @JoshuaJewell, @MahdiKordian, @Maher-Elmair, @MdShawonForazi, @MrMDrX, @OfficialCodeVoyage, @YemotaY, @YucongDuan, @ardaltunel, @arindam-codes, @ashhim, @bariewakjira-coder, @chatman-media, @d4vucat, @desaiishaan2-rgb, @devlewicki, @felicityblueish, @fhammerschmidt, @ghostworker13, @gitfullstacker, @jeallz, @joaocarpim, @kashifkhan117401-bit, @kyal102, @laigit-dot, @lxRbckl, @lxlynx, @mcdev7777, @mennylevinski, @noorgx, @nshkrdotcom, @paren-thesis, @rahuloraj, @realtonkaa, @sarahofai, @shahidazam2020-oss, @sheriffsec, @shivam01112, @shroukmohamed5, @sinajr2011-prog, @soham-kyo, @tsyganovvv, @tysoncung, @userAshwani, @yeabsiragebre + +### 5.3 Inactive (>180 days) (34) + +@AbSomeone, @Ashkan-P88, @ChungusLord123, @Damadel, @HalfFriedPotato, @Kovbo, @MJ-ulia, @RC00K, @Sewiahho, @Top-coin, @akilegaspi, @alvrenkai, @bittin, @cumsoft, @dribrahimfurkansarkim, @iamapuneet, @imranmalakzai, @jelspace, @nikhilpatidar01, @retrobullseye, @rodrigogalura, @sabbir-noyon, @sara8086, @selinamiller183-dot, @smoonthsky, @suliman-al-tech, @sunaynatalreja, @szenled, @talorcan, @vanohj, @whiteplaine, @yahyamallak, @zainab0077, @zombietfk + + +--- + +## 6. Honest coverage statement, and how to continue + +**What this file contains:** 12 deep notes (code read, file + commit pinned) and 2 lighter +notes, plus a triage of the whole follower list. + +**What it does not contain:** 269 notes. That number is not achievable at the standard these +drafts set — "read what they are doing, find the recent code that shows the struggle, name one +artefact that actually helps" — because most of the list does not have public code, and +inventing a hook for someone whose last push was a profile README would damage exactly the +credibility the notes are for. The measured picture: of 269 followers, **59** have no +substantive public code at all, **26** are inactive, and of the active remainder the majority +are small personal or portfolio projects with no visible engineering struggle to hook to. + +**The realistic ceiling, if you want it pursued properly:** roughly **35–50** accounts are +hookable, of which **14** are drafted here and **15** are named in §4 as the next-up set. That +is about two more passes of this work. + +**Options for continuing:** + +1. **Finish the plausible set** — work §4 next (15 accounts), reading code and drafting to the + same standard, then re-scan the active-with-code list for anything missed. Two passes. +2. **Target by repo family** — tell me which of the seven you want to *promote* through outreach + (e.g. only occupancy + tropical, the two with the most consumer-shaped surfaces) and I will + mine the list for that family only, which will find matches I would skip under a + breadth-first sweep. +3. **Reply-handling pack** — for anyone who answers, prepare the one-file follow-up each note + promises (the two definitions, the monoid, the interface) so you are never the bottleneck. +4. **A public artefact instead of 269 DMs** — one short write-up ("what I look for when a + codebase has a projection/receipt/bound problem, with four worked examples from real repos") + would reach the same audience at a fraction of the effort, and is citable. Several of these + drafts could become its sections without the recipients ever being named. + +**One caution on the whole enterprise.** These notes work because the hint is *narrow and +falsifiable* — "your ranges need a declared algebra", "your limitation strings need rejection +fixtures", "treat `STARTUP_FAILURE` as failure". If they are broadened into "here is my research +programme", they stop being useful and start being noise, and the 269-message version of that +failure is a reputational cost rather than a saving. diff --git a/src/session_ir/__pycache__/__init__.cpython-311.pyc b/src/session_ir/__pycache__/__init__.cpython-311.pyc deleted file mode 100644 index d69997329c9bd9b767284e8f52b58f38c2b97aa6..0000000000000000000000000000000000000000 GIT binary patch literal 0 HcmV?d00001 literal 587 zcmZ`#J!{-R5S=}pK795;aOZAG72yxrMVb%-HW+f|d^zr%M$ICm#V1=UZFVKFT)E3n zaPP+WC*)tKJhnP;mCoSKRd!_?at6;n9&eVJH^bca`#sR{d+_J%8Ufs!KbwkxrRJVBY#b~gd{~wh;mv026(aI=g#Y&6T5!&dV?7QJcH;>tBoe9%+>0gEo8@c;k- diff --git a/src/session_ir/__pycache__/__main__.cpython-311.pyc b/src/session_ir/__pycache__/__main__.cpython-311.pyc deleted file mode 100644 index af1057073fcbda113047b0d92e3ccc6f87ab1c64..0000000000000000000000000000000000000000 GIT binary patch literal 0 HcmV?d00001 literal 315 zcmZ3^%ge<81nr(Xvt|S7#~=<2us|7~y?~7A3@HpLj5!QZ3@J=0%sGs?Oi@gX3``8E z3|Y)D4L}~#G9YI)On_k-BajEg5WomDA(%mv z=H#5rB9O(mSW+u8OI9*`2C4mJs-Kaco2p-0oLZ!xpPXD;keHWTsasN6kXo!?T$HR| zoLXF*nV%P*S)?By4>B)4Uaz3?7l%!5eoARhs$CH`&=in;#STE?12ZEd;|DedM(zeK o5PZNOdI1$ZVBlzAZsF(<=@97@>k+%iAaI32-~tR4aRLni0Oearga7~l diff --git a/src/session_ir/__pycache__/checker.cpython-311.pyc b/src/session_ir/__pycache__/checker.cpython-311.pyc deleted file mode 100644 index 324d31b27b628bb3078925472c888ef4bf97cb31..0000000000000000000000000000000000000000 GIT binary patch literal 0 HcmV?d00001 literal 21083 zcmeHveQX=owdV{!L`u{bMM>0`rIBRIqGU;yZCU=3W672hJGSgta?`NQsx)V8(-9?k zhO}drDxAJxpImr%={yBiTNz~^oId$Q#&ZD|aDnt8e-w*i(Lcz5ix2|{2=*bsKI|?a zBh8`+b{G3QcgP`!mSpEGip2suq7Lue?|aU<=bn4+x%|7bvJwu@U!VN#)&I7i6yQy|+Ht;B5#tdK-gH-lpI-@3vsGw>jA2Z3zlqA=v6|4YqmPg6-b+;CAo!;12JO zV28IOxYN5c*y-&Idc2-sm$xg}?d=Zk^6m=uczc4q-riuJw=cNcyF1wL?GNtp?g{So z?&UejBJGp9FPZAIW9PgBChk>EEP9_4ZND;c+{gIW9`AmZVn<4GLCT<5A(p*w@g5M% zCpb@~?|+#&ZsO)l$oFoK7?34@ND>AA70LgOBny{jWg&D$5+)=?3Czw2C(j=eu7<_S zL1`u=yy^=EeL}QHkc30Run-mG-jWho2q>(Ge>NBl&jkFw5DNAvA!$zV&xTPfFvHS= zXm4&htO$w}49J0*%R=Y)E&;K-gzjC!ZqK0-MYk*G_(V}TEcm8F zl01XTuS>#3**Ak8qg~%S5>?SF2$Sgb?9B8{;j-)#r4lrHeK(@dNWoe8CiPL8!QlKD z>&2VGbYMpE$pX4dEn=)f=gcfR=AWGrwF*3k1nIhjk|W_uB|gMTGveHA0K=K_1tq~Z zH-`#P>AOCE2#wCp_@(SXQAtR8HzWX+XcliuI4Frg)%ox=`rLWp^yK;BbEk*Lg>zSY ziX`;!qLOEP@17&<%*=)u1`i9fb5p>GFhuA<7-&Ekg9WBa1nPUJ&o@0i>+hS9ZU~0w zIYRA50a2cv>+?^~qQ&Q)-9on@cPinFp8TZFydq$Vpdw9Q#{m4ZN(l5qm2^fZ^*+=LKFrU{N>h(O^`Jtz{e-Jc9?A{OOa(9s zjX8vXr=(;wOS8}wS@MbCxkJx48lDq6x>0Wr+DlTjG# z^#khF4~Wh_L6nq`9QKE10@H@-*L$2{cm=#A^_KiI z$qWy#I(#!(c2hhS)p8=>52=>Z0VSl`&(6{0^G&PP$?)8?^v{sCoTpp04in3%7EFst z)p8u8SFOj1sZbgWrrJiQhEJayo}j?U*$d+*)Uwg3Rakj}D(#9huk3x6X~K z6?i#)7K!6$C#OcW%qPxX7&$#UHFkbH$E6#pg~eG3Vz}qQtE!dYq-viyd45!uXJyqg0qUw&f|F{|1Y>1-RTLDN z1pBI{$(yR>!uZKa)ph~X_H-bmS}8E8n!n?d)#89Mr4dNA&dp7QkeS#_wT5m^N!R?E zfY)F~-t%A8;{6^cab6xPph>ieR!DfWSOf`gR~^SmoS$brp_)QBsI`Phb)rP=5F3Lx_DLpZ2!W+?^Jt8;3J>E^Z61Rz!c(;koVimsaVvAUf?_yC9>+oG7)`RY?s*NE` zk|U$%AXw()Sx`KfUE3i%UYDdfl2nMkF5UFWkQ0}(a!O zBLJ7@=~cf%%Ex-D+z=ub&O9MYHpD@@jGBIK5>5BbQOmE8=VLwJk1=bm>TmJ9GP%-G zlgJr$GoA}M^3r)@Kjy7bbJQ9&5gSIWps;y7Vxz?aidv*mP_FpI*&9U9X;O+ZBA(dT zQzR1-=j>)jCD(M#^+r z(JOJb@(uu|qN6lsUO2FD;C^wuJ??wZk*xEi>O2bv)~Xur4<@#culN8mpK}w*s>xK< zWTJF3Z7;o3{<*#3Gke2Q|B{%rx2Npw348lmc~xxh?ZBPDf;sK1S}-pR-!4j5R4tS+ zHu$ETtx4aTytzvNFTCx~M>jD72*H2#?-9_6KWHTQyv4{2g^15*0Fc_q9%V$7Az}vZ zYDOS~KpL4WQR^ks1g1k=X9jdbf53`n(X?tdG7s3GSkHp3im|;P^B!wt2n$8PcX1l4 zJtV0tOHeouW#_JvPkd;Y!CBJNW^c?$vT`Lb=jl}~5W?cvLteF$PB#ZlNOgo~pcMJ9 zP^BKLd=4GZxQ6jc`P3y}V0tR6y{hHI3dA_61Z>fJo`K$=^29~*d4T5_$TEc|tE!DDcRh=qh2v`#bxY3M(K}HH+OqC+wR?$=jitAD z#Vm{EOV^T>t!Y8uK-^X2)1J64BeF5{9W9)Ng{aQV z1GeFRZn|%Znv6^U31XIos6{lr!<`}U2>8~R+D*XLqZrevcs9>;j3EIe}&yG3mk5>y*wQ%Qup3tzfK@~&FA z;e)K3CPn@x+sw=%xrxPQG7A?aZ1G5yhdvGlQ;XPkM~oEf>UX4v70}`f^9!9Q)Z@E^ zEk_T_;fa*yNmU^-ptql$7lIE;_>6$P;B)}J%*{=q(>ERPDVS&;k1Zp9FH0d!B-a5i zvWoz1?U{te3}h0S31c>w7LV zSzULcuA6cXr5lgN-$*nb)jpq^pP6~rDE}vp;5x^bjq+bOoUyk)b2KL$%_#978@tnu zV^m~J`}~0wIm3#aVMWfcBH#VYu`S`)rWIK?@lCtq*HB^8?i@(>?|Wu7x%U5w10XT5 z|LY>I!u{b5WUt#D_aSE;WzPUDdj(~$pzOu_wPnMpEgMWV-(cmSDaKZg|B8UVa-7<7 z<*uGUSN>rbO`hGQV(*`8fwA!xAl6Cm^7k<8w`k2b=d-fzs< zxJJ5Y_KCucD-vd-Pv1-Hvk=o$hOGz2Cvi-E6Wx;E0`S<>k^p85HmO+LWDmvfAmAp@ zPk{Jd{vJSfy5tlXef=qzE2@oFo+)WAQlZZmErRM%J_Ois{c&wu@_kg3bnQ&JcCK^g zvZ1xw=KGO!TRYfH7-Znlj>r7N&ehIb3=5?X90s$xhroUAA#k5_XuXK5uK5=&Q5VrY zgKA4!1>;fLpxooO)?ze01xh4$RbRMr>ZGQko3xdm7X9ZJb!uK_nB8zucVzVgLa$3l zZ$>yG@-oURM8jKLzD8GC5#txe(oJoo+{dmZ?e#g`PUR)J3njjB<#askSToa=hM#?C zbz!LZ?~tMes4#6lE#VVwBiqAgmnGLNyX z7%$&5Frn$HE^4-*!9Sr_dcGXavE#8~ug1%5piv&ivTf5o$WT(JkjSqV=t4Zv)0(rL z&zlYXG>4jVwHn7Hw}e`AX`!}U7@Ctct9fn49Y5v^+Mz9S<}tRT^u3@RYl!Af=D}is zNu1lIVu>iaPuS3LVB}KTk;X~Mc)bX)i4>m_H=19ilXd!QOxrW$G(&=j) z_4hGnF?)&%wqRS)qj6I_*$tyW&G|d>m!`w6P3tdyAqAj=Z%%=HJVuK)lnW&5GLI2Y zvbZI7$pFY6V=0DR+q`|gc+=9w=rJv+o0Tq^cg&ZDXuZumQCqac*h;?D;;KHyqV}l6 zm@itof!x}ct+!BNf-I@qwAUn?UpQt1#cd%nf@B_JzZ4_I$(WgW#1aF=ZO_d)2kl@s zr#RA@vUMT6EgR14soD*kMuwftBbMfu)b@v4w8F((vL*AsqeRHWl&u{Qi}3 zwiBmpUYkCGsO_pQ6<<)>#xmih_%2%Vf5clSvg0k}EqOejqeFS)#aP<2rHs_h&lMs~ zGxKa-!dTwObKhdMJ(X>#a1@v!Z-QDKx%6C!$y~Bgv&TRogIr|VOWAz6VXlf*nvOU0xUv4ZtUlFayZ*7Q-Z5wkO z<aV$(uR?a);i$k;l$vn}@XdWi6?#jj+%PMDH8V?l)X;Nt%3Gh&9NZ+{af>r;1 z(dM*;?vc;g`StbaV=>gnB!*5o5=i-L*2Z(uz{$PYdZSJwmZHTQ$o_wo&0WaZ^6Fol zuYa&v+gtFpGoRC5g0HJyz}MfFI_3H86LmJ`&rK*&z5xYjOP6_!^paQp;uH|GEf-S1 zfC86t`9xPf23~>!)mu{lW87FLHegz;G0ZXJdim1Yu|dL`LRWI5GGZQ5-TD{D{ngD{ zFTj1iRImM(xOZ=jdxKQZmrZ(`M)^2jh4u%t{f<^)UwC*^$y=A77kpCx?fU*Lq^hA; zy7J2z`yMs$({pmQBs(gOyPA`r8_n0bT+RZnG09*5#kq!#XEKkmb!F1P-FeguZOUn~ zNo<(m#m0Hprc`YDc2pC$MO{DVUO>BiT_UfaS2yFjYO(o!9OvcIPjJ5i4nEEzf}5|2 z)`Y_PD;KRc(*7OjTdk&8{ZH3X1*q%N4X%s1P^Y!>|xXjHriUZ<~_bu~8d7UCBxETL-1=G>C z&0FW2!RL7^XQonop;fCv15Km3hQ*HPHb}gk23_)b zYf+~mz24ZD7g0aj7H!Dz^{}BIKYFeo9s}pL6}BUG8PXf(_&@>ggCD!^8|_nu9n6pU z7=OnZt$)uHZMbDR#X;-MpW_Y27U$ceb@5}lUgko^S$%?gyPoZhw!>2RSGin;b~lA6 z)*jtXe0--NTK{cyWJBJOY#Y%=V~>q=kG5~1#r^AS*+NYUx`cmIZhk2n3g)4{i+=BI z15Xl7^fY5HmDdbh@snKt#9b)Wlzj)E_89muzedB(1YFQ-$oZTtW^1{RR>!ifzIPC| zsl4}hpwU4>_Zs^AZ?m}}p9=fj7qz25yYuUK;f%=}wb-Ar{~R%JR>6p5qg5)F*PlIG zV?x}!wN+|{?CBdz&;pAQM#ykOZEs*F+E_~dWh^^?lQ;f-bYyzpWSl2(jM+av$qo=B zR`LN5!gMNz6G;7}@ju;K)L-B|fa6I0;Q8Yxm+`c0-^K7fJc^4MVQV81S-s2 z%HixP;3yOa{THRI>w!E)`8oht%W$M4KY;8ZDiy^kqt*heH^Mw`$l)&H$hb_Cmu{Fa z%36}%ozr~reax>q(wfc1+=YdUv!N^KJlx`E;3JQ*C_=(Abc);m*FEpe$A13LC+TSh5T3G!|b01mPFJ|j@d6)_bXJl=4&B@ z8=vb5PJ5{z@RS&x5#=8sJpxyM=I~7jXn(GN-Y2c=-9PN@?VXRI9eGVg+FsnP|3T$7rbx3ctT_L{{rB#N z^{e%0H0eH`LTu%6jVWxIs|Jx`xL=TCFGNU-a4~FfVanvuGYkpS61;`U%~TAKD50A` z`3|S-P62$b^4y@bI#8xFViB&x7mE%NJZy&I#!Bw`PVNpv!~$t2M5+!!ie|4Q2#W6} zdgx?5l==l+mdS`MCwV>w=fZSzi8-|kkvg!iUy?*zPnq@waNh<3libOU$=A?!q$cCX zb=@}|rb&>gr~+eB{BVRu{?M#26>;V{MGAEFM1V6n5h*tvSjclqzC^Ko1ilZTTFCKM z^Oc~5R<%SVI8l?;RVFjCTucDlJWi%vp-hLP@>K%Nr-iskb9SNiKy!8pAf#HEIFL!c zt0t)*|9j*%dMUz{pkR1fCgN)zGOtrKe^Yb#onS9MmA@zpEU3tP@GX<5lrK|^Nt%;s z`C|Sbsu`G(_fot$s9aVpSSCYo1%?OdcFIGNQYMEBnZ%wu8S_)YiE#(Tz zN1hFu3($@{A7+NhGn90mfQAYgcOQT;8UKF#hxQ6-d`Z+-CAk`f<&Ft#$hI-0E6ld9Qsdu(BNL4hajhnE+p z zcMmQeynlIldIdH0B})6WjMYg;bIQ^DjB6+s)+*|kT9@1JE6IxXR0X`MD$DxP)isO9 z7hj9<=*QCW*pb+gbamb5)jL0{-nqiB^snw+9eg^OsNR{Z9!XV?B&tW4Gw|YAj9)Xl zYgwEJ)*9N@>e}HSSid_?&W82mAD98@{yk4>p4rTe2mZtXz`d*Hz}I%Jt}WjB(PYxy zm2!8ja~5ZdR!6$-T%1qTox|smb;bA4zG~Or0Mm8#%T}tXg=zu{%r!0RcFx`Sd2PpM zwHKbY@5v^ux$2gxmd@WDS{(Xl=Y!tI zRgcdn+YY4K4m@p3xX{oM1CKr99L0OGwQbN4k@@0BJCd%>lnZWmrm_nRCy{i^=|>kH z?|Jyv>RXAH)7s|`zCTKYqzep57Z{Q*@LyC^-ce${MgLDC3lYN4jdaVYPy2trH_>tm zpFa%$ag+*8utF28&;`yuS7e?S@yG3FKX&YcB z?W+0k#^R6S7gySn?w*vpXGKo9`V*!78b(WoJ(%1vklHbjbnQ>M_W#cIN$IElgzIFY^rTitW@0|$oFJdO@m}-$sn{YG|~ zT>j3oH%nwo*$5Fi)0acpz8s=P5B)}ZI`ZqllK^{RV6CHj<;3dP>ZxSMV5(zq-Hco; zA$|DBC#-)Xpsm?G0@|9LBRtLfZA;YR_mXZ;%I#SgS-5s5bo(_;)HOe{tvbN7^#@Y* z1w5;ZJ$rHA{~hdZ*7dZ@y|{nz(ES_BKU^6}xOx+%y#|I@=j_GZFV$s#($$r6ku)r8 zWJG9BSD#yYV;NHT96peT;zP%(Lwf@x2|h|p&`3DO)i|@W5%SRG{=BN~v#PfEp7^x~ zp_T7GzV;-XtQtyH4dHsnMoUU<(jlZA!ZWVC*z-~y4J2K=Q!dDOOIdG@TRP&-2h~J< zh&X^pqmQ>ge0}xxTnr1PcXmDqQ>S~W)4kN`Ua&=N!_xNUj^(~&O;@U>3;wDQ9XFOP zB`UV#lWSwgl5hDk)w6?vr_N7Ui`v_oyJ>0i?hhA#NPMV8r8{;$kf^mDYORM_>(Q9- zJ6MumU7pgUfsqXx;};XI&O~XaMn`=iJzV@<{@dZFsBGVtjXUDvgG-MB$;JaIEPrOc zei#efFh1#{$JWi9v*t^E!tKgVxLq{7UHOw=i%IYB(BLvJJ-w?JXmI;zaQkR*`!G0n zr{b+rro)@1cSs(JwOp`!Y}dFj=kmM)imrs23j_{bH1 z^OsEznjTw|tpmx1{i%liG22>Q^HTUDWo7V}(Ff6F%id(&zEs`5m^DX}!EC3=QM+a^ z-O@o_%)IpN%X>L+@Dp0U-LFu8U!nfK@^vXKgr>U(77r|(NLNRtxA0{rXt5}SMOMKU$wGRV z_XBU-68Al-S-J68S&b$=M^c_6PkoZ0t@ol8CPv=hvD$)|z%g#%~+r<9_rX-x`Eq9sc!|Cs*?0*7hHMI`-?} zlOXV?XH38P+V5%dw2YHj1q2T30U?_jmo9(squ7sFBc64WdD~%X178e$DL_5?rQ?BP z-Kt0R4?eX$E&Fs&vVSbqKbA|-N)>TKM?V>T=CHOLM_UBfIcq%-Yv$@Y*2}r-hJd!#n{lVpDcqZ96o@yLVoO?6jdNWb_reV2$##L>pz>o|H zCn^MxTz=gDWFYA|nDQJ%1bFv;1cVTd;`Ss_LO9C6@4}zH@%szEjebI%%fzki8GLH` zwdV=VyG&I2m1CbUg>DR(F}aC~CMRGKSLwWSBT>;7m!a#w`nS<|lv<*DGs59)OP~kd zo?c{M43L8CrrNcn^pPRp9qJz|rp7u{tt6EORQW`-ccfJ}A=nYNXh4U-Ig+E()fg$VTEUs(mXrT?WZ zXA_pQ>lTw03xN@o6j@#CoDo!(P(CB5tF+>>mJw_>W??1jEL5Knl%FtLv5(sdGJ>=2 zYjzhMQ3fNVeh2IyVU_!9tMOWi(SkXTi=1(?-97ivb$H|P7&8!?=FLB`=HCg!^-Yw| zx%A@z$d;=tM19FTBA6@ zzpEf$M?D$qwq{Nw&k3V_yZFdu{Ib!zb25$=m{kaNF7|s6d6w*Kjv;WNLJt4`8GkTl zyN==W(;Z8#OXq*%!3L}6Ne?1o!&*W<)C|k589V^Rvtj(k5)OO_tNK|Rt^}HP2?mr9 zpEHz@Jo}K>k)8rCXXv zdyJSD<7b%ga~N6woIz0gnMC`UPo42=iS0-5f$d>0wlw=6zPY?U$Rd(royc$lr-Yvr{cUdMu7*ZyeWvGd`9RY+UB~zh89gp;hW1zLj$K=7O*)!Vj;4gA zDYN8T3go|r--Gfa!YF>$uVU?%})r1wyWt#{oN+C_lYaG6{WwKELHjEn{MP#mUaM%6e)p#cJn zbBT)z^n!2fN3`G4IV%4asbDcq`FD`RAP^57(ZyTVIRafA-=5&w@;_g2y@?ln)-6T6 z3HrnT2mjCFppvsW7NEW_489+{WnM2b^JE!%4m_hcOyF!n>8OQ=nAsRUWAT5=Pd#TZ N=W)of31GATe*+pl;nn~E diff --git a/src/session_ir/__pycache__/cli.cpython-311.pyc b/src/session_ir/__pycache__/cli.cpython-311.pyc deleted file mode 100644 index 243eca50ce1800bea22b092449a6d55f1f254db5..0000000000000000000000000000000000000000 GIT binary patch literal 0 HcmV?d00001 literal 9327 zcmd5iTWlN0cDvkNa!HD!BvO*~Udgg8+M;B|j_o*-5m}Pok)6noSdPOo+||S8L)l%$ z7PItKZc~&g43th)n7MIq*}_egMnMJCA8wlu=kZ}&^kXRyEwO+KqeVUf^g}^z0YhIs zGt0*=ZRa}Z&s`1Ao-=di%wuQHoO4Eh?{YZ^c>etOKVP952;#pHQG93}A%FUJKyDK} zF-hVW2 zMO>3EjI-hDhANf4(C??v5Utj zH#o%ooIF{OWbW1B@#9CvCeGrnp%#R91#y8Bt_LG?VS$^CazQQA=%F#H4hZcxL8 z=Q1!S#-_z!1c`uQlt_!lP8@%I3{9=Z%*_Sl1>j)jf}$j7^juJ$(I`n4HLEDd^I}w^ z;CqBh3j!Lj!;c~e@~1rH-Ud=Olq#^;S1g~wV*3IwIN&8-Bod@TW(-^?SAWclFJa+f z^YDbZK1oEKTZsWeqOV!5Qx}PABuQK(NcfYPq8x%yEas(~pk$k&l&UDDqkpoMkl8Xv zHz7_W7};6Q;VFf=VlC325IhZZN#-ZSr-&{|5IcCrNb}aFVpRg_+Dv7vsm%T<6D4^^ z9Qe(>MC0U%1apJoS=fdcyGC9k^jR?V)hT;Q%@GQH1uH9*W0nX#se;ndDA6d)9I)lB z6NJw-zRAqXQ~m>=lNu{TVTI2|r#I=b*I(y0EeE+xhU*E+oQOX1CV5aq)38bUG-8uF zeUjUxIEC|7X>@E(h-$Pb1bNW~93omfB5E8K9NOp_jkbZd;xp6#1k(CncIAHe%W>;*aKdq_uMi7pZw78_H$?y607XBt(PFYEHhZeMvq4yx+A>&YU265t)Wp&o@Pd@_+-=k`_3VY**-L6)NbNhb z8oD=qKX~s7ppYKy`ELKif$t9LQ~?G<*=jz^3OQC#St0MPNxoD3gML2VV4zue|F4x` z9IC_r*Gww3Gi1I1Re;>1 z57_Qgfcz_Y!1h%qAYZpT4!=x&-80M{-ba12j{)L{#>iqY1d8bGSS%bWsSuD>13#>G zRLFf!wPR5%&!u*#|A*RnLa~_CPQ~T|1%tLg;ZZ6}tyn3Qwk|2bhN(r#CQc|pC)dMQ8q-c=wKoAL5VMPn? z1a()Hu$#u^lFK@gfSRQ-o7EF2uxg`Rpxwqcfvy1>X$|}UT?@3^K-U@hMYmC!u_O+C zhkjal&nGnRRqQag)#kpCghGm~PzS9|{EQNpy$OeDT=j|rYE~RhByqDI&x93P0M+hm z7#ETL7QG07c}a+k2p~fZ>sS#@4%V__Gs0Q`#A}g-gN+)jEVJ) z2&|~tsab*Vj|f2t%o~0vPW8PoHIL3a`2S8&a zFr6fEC&DeUtC|grIUd_i;n}Dlq4lYsAsC9g5T6a54PY{f`+-72rB2W}=wx93m`;ZE z8aO6yRWDU1nI!W^a7b)e35PppZ%R+xxwvNEzIZslZHHPtu2y%VxEw%oxJ<-&Yp>(Z|_D5#3_^7{vK`%jeVN3V?KUOA(37c$gc`|?<> zcQDHhs*uiKP#te=FvWV%!@8yoTao;cpqSR*BLGqXumtNuXKZKQ+q85N9nzf`BuCfb zaQ3IYDSyhJt>SW3oQhMvrY?CXIglJklPcX*JoNmCPIH<4p z53?f-^)15yp}C6gL;#uJCSx0|Pkic)g5i1lxlC;t_>0e#(g~`NX5IBmO>H=Lh<6Fl zc0|S?zt|1|J|a(>&32wCD|Dns6Vx=3pm`?2C>GvUE*m9Mmdk4it77F1Cs4wsP@ucv zv;*x)!MS1O?d3WNJMTz1;ODGxKiFrw9|a%1++&1&2EQ*#S&6D&Xa}ILQ+SlBiurXJ zPXWbMQCh9od1t{V_wiM7>3jl5rn-Edn`^;*xS+Ijx&vMPDFgH1PB;~Yr{kb*6HJPX zeyCV81}mc2NBBxLW{C+nJDTftcaU$0hizd!bTeO267@j4OxN^Qn4PlmqKJ)a~P zrAKii%f{RzIDKp0-({Q+rKZp(_sllEMt&^0=4q0jyJr>O16Ha-sTDiWCGEga*BuHscLHt~%{4jAVaBUfSF7}iX5j&D+| zu)lX1>%pFDD(|_%+&1&gMjkweCcdXgALd(1(n~8Hq_;dpdMijT@f4&R_?{xYj&G~z zQM*~jr*y&@eGlAyt~jIEvW_M^hFy5{nLDAwyzUZS#rytt#dD>$C{6Je=BCA%3;U8Y z($Mox#ru^0cN)2%Ru}ZPu_AA)k;XD8<9fki0?!Rkl!YJxybbm^{fyn$t=RZ&VA*bm zIoJX39>u}?FztjL!J5ZRf{wnKlaXmwczBlIiMV;a_Ab5`*YW#IP z`bw^wbuzNt3Xl1OF!LrFOp+QDCJwp|=7drj0QNmaPcYzf&~OGZU}^UoEbUFQU$?2z zF}X?hL8L>E@<|#!H5(Q*t8jfz2+7#oMiH?qK*SxvP)L}Q!KCgH+n^%0$m0!1hL4}( zdh`lVrZf9A8bu+nQ5$D)JP^#}&LJ*t)ou2;Rj(Jfyv!A4lx+B-ZBB8AIAqC!wI8q2 z`E}D@9Dw%YHF{RbQ0C&!Gs6=T#oE<_L!!aB*BBgDjeGQ3*Th(KS`ShlRo z%N5M-cvUg-DS^A<^I~5?qpwIYh!cflK^|sVnhVd$mHtD?A;41!QUzJF1|irS<)M0P zHY#EdV>kL9Xi{`v1G^a zD??~EEFovl;D#7c-6dg>OM=4F;zeK`grC#`j@KfwZg(XknQ7JDm$moh?0sOcGTdtC zx~FmJrSxmJ2A2ktECi|;4i{hmfhvZBK$S7CTw2ETK-CjmkNO5yFROirAti_Y!`ZRs z?8s1=*RswXIp>aLGUwc>I(IDw|9TL8Fg7LVm?wxpYLHQgJ;e&$v3M+}p6zPc{8 z?`Akj`OF2i)}O8Q=W6}X zQ&-1oZN8!L_S8pHw`P`RQWOl;)qx8zfT6lNV5r8ta%maUhx!E9_cisY&@IQ3BRRZY z*O4K!bzQl-uH;DGU7y~v=I&J8o%z6EAM{Zw$i4y9))y&&sQ($7{HW0-~2+# zhGt;+mMg{HVjnfP|F-8hJ(+#k=AF6bolw@+`P(;s^G0Sm+t!zB>q|NEEo~__?`c*& z+rNBq)pM`m^P!cY`$yMyji|du^4`|lr$0Kab|3q4Y<26s?VrE8@+uIJ?qAd2S?}?j z_qggkp7*q=9^Z0kW%mBTwZ1X6Z>(H-d1B>aq1uUxYU>@{nTfmSKTh09sI7yLpbJep z2BYzS3szG*Lgw4IFMI#7=^vU_4`h9VIp1Kmeek}NZ9kkk3aw4)eQTyyu3cSIS7+9zXux-MB%x?CoV>TsDm@x37P6J!8u@_T(CSQgq(asCu@7 z6U?rTuJs&Hdk*Bet#{ef@qGKK)scJ0)b>-59-P(R08P{UsL0!&I+{BAsI}wHF|_br zf^R>gHov4N!zzUJu0I?@(Gz7qOihmL01Q#tmO z%ANw`d)l5nuR4bGlAkSURA&eF#)B%|A)Npv z`BD8I>YwQSwtpe_+rDwup6IZA(^`Lci1}uq3gJWa2xxL2D7XkF{>)M~f)k|aMytYQ=Pd-yE6wTC)-(OKcd>2A*JQa@SSVR+txbz)sFskcSA}}4=-K&J860E z-z?l+SRMY`8|sen``!27`D(|5i)#nRRri^!`%KP#MrF^Gr5PJPzt+40e$3=!ZoFc3s6{E>@%~_y5U(_5w7#~FLcSw-lW+A0X`NA1T;q=Ff|Vs z@j@UVqV*(>A@DW;%?j=WT*`{b=NG{kBt)cqM6_xlgsuNa2EK9CY>{AS2EyIgMuxAx z5S4@1bqg8U)tVLG{)>9JzG9)EkB_Dx8jL_6G+Kavc=((Ur%+S70Bo{@kr+Q877mFb zkVv;lF9C!}CCLpdOVS$z0$zgLsuEqs^oVdS;=erMSj2yMqF4Px>5*9o2+R|lYEF3q z+ImXL6HTf)ZCD*71bxk**+VvO5KjTUqa+EI^b>I0Vir)A*G$k=$@m)8q*6_Jx@vLc fgJa3F$+I7xzj;1Odvml`Ev5~MpqqgUPwoE!kWz%s diff --git a/src/session_ir/__pycache__/machine.cpython-311.pyc b/src/session_ir/__pycache__/machine.cpython-311.pyc deleted file mode 100644 index 355d5d82b039584770fdd201d72484dfae3c0d6d..0000000000000000000000000000000000000000 GIT binary patch literal 0 HcmV?d00001 literal 15530 zcmeHOTWlLwdY&OUylEs+qOO)LjV`uDUnJiWTk<6If2#N)EANGL^2!t5GMbKh_-8UI_U;Nbn zKSK^V)Fr!Zf_>@H@Sij1oH>{O|Nj4+^Uu*gS5`V12tOG4<%}pW%zxoSAy~8s`{GTO zVeT^`<7GrvG=$F371V%khYfV*MS9cbC|3 ziSabW_n8@HNKzyc4n~5q5)25kBE@175hkNV2!x`tBnp=#Sq?@c!pOJ~Bhe}156eAH z=Xrl%IvA0JKr}KLoQe~_f@QkJXh7~AyD&UHFflSVI&g09`LUtlb3I|v)9)07UBa~F zkM#>7c+*dWtMSQ6iO72d=~gTh3O<2BpA@xf!u`FW$1~}D-bDg18%Yuk^%}u0)81P0zSf9@rWYq_W)lnDex+a zLdNn@B0{gbqaYGmqdx?xei51lu8odO2p|p-Mjng^H}>UOj9u_)Eerp7dr=5WemRc( z2t;LNkKmVOi6AeI9Tx%+3r+^%fz~4sjkz(&f6W&P-jD==)-WBMn%;X87)XS$pIk#; z(OgY_z*I$&OWq7dCPVOsveCO#TF@O$gvd&eQ4vymLy!^@BtoJDm^bd*gz04l2GWPEZ$wG09VRBjM84c-Ry ztIlEHh4Hb8vB9x(s(Cmfs^)W&qS}C509dQG^Zr{GLUCC&k4iUH3r*vYPN>!6zQJ>2 zm*D;3(V>yiQ>t^^H#9sjbZ%_$EXGGhCx*vCCsl47kT{{*FO7^3BbQa~5+HO!wO*po z#79|%&P@RDRomrAP&pS=RPz--Q5``Ukb&B(a=l~1Et5#sc6@TclSv6k`imF8pCM4B{W&k8gc0x6(8B~~b zLo5K+N)Ol+JhLzMLF7J@WRr|f&rF)&3HeQfhQL`=G%WSTL0fvGfj~Uwj|65Z(&S#51bSu7Ec$|^H;7!gK2qnC$g^8*gXY8g#%$3Rs(U$OnK*b^R8aj=hBvIpLl@g;%m z1&RY8Qj8b|pe10VavKmBKy}Z8vUn?9-2>N3*F%pMLu&6Ky-;Su_5{V(U*b$evhV&=B3GDhNLx!zS~1ESTAbq3(4ht1(_T?gLWa17CHQY~oh z5Z5wB`buHBKS_5>>QI zIxJCGavczmY95c;E#*i#G(Moj*2m!i$SKF60fC4}UGqv2X*njvgjZ}2IRsTew~;5R zIS>>zhP(!kC8(rAFZNu+<3TLb4g~RdU_o3AE{4<92jE%}9|pA;Qu_fNk=P0uM542u z9LC2ZNRA^xerVi!17k?2ir}lIxDpUoCa!svF%mn=9YkEMOSIatP6Mt$r!lZEG=7$u zO$*{m;xxng5tRFwmPX>W=FO-D!SvWnPD7$<)s{o5Ra?N(M5=uOT@+9Z8-*YH;uu8A zAvVQKfq7Xrno*MomYk;P^-yDK9`%@1)~~Wx-y~Jn#QmY&)Y&S3hMxpaMB*rIEpT>EnhWkSqj{{ws0*a zr{onmZQqrLnW@NdFoMQzQcd^RNFTO}V<$(Epa>{;R9?m^wC$6q+AOojrACE_HBO%k-R<(@6M#o^mbqzU3tD`F< zh-ra7p&HOowtB*~6zG-~ra-rRC|DZM7(6zO6096n#LnVIM0My}3bm3(3ws3Bi8~1& z-9o6GLj15LDL4Lf+NvoGNf#zUU&ciRn2s$iAk6Aq^A@;O<+in^ELr=OLaNXKsm>Jq zQRb@Vuso$rxp`F6-s7O)$G$+dM58f7laZ|G%+Qk{l4L)E^pEvC@H7AeC_=#kqV!a& zAC|EZv0xBINGmmnss(lsQle5H8a_^7A(S!<%g)a`zqB`hVQ*gQ%-CDA_SSUa($HF1 zPrU`@!PsB}bY$8pi>9tYE?q@UVaYPf@_kH0f}oJmCKZvpYT~%gRmMoFSgsB2$+|=X zGFFGI(1UJBPC!x#kllG8*X50gn*y2>>qQ=bZ510t7u;>&z^H+{U91J5H{ouGZt#lZ zT_5IXG43;pE-QvHPNbV`7rqAYvJa7N~$CT4QzT=tcGp zB3v&$RK^b@vVqm6Q3GQ+s2bK^?28aY&N3`jn74c9*d+UPYGY*l5c9Ts&ZJ;{`H(aj z8^6NbXIW;xZhl`;z03q5s#~+Ib@XB#)N&u={W|QaeqiY(W960L)CN}@q6a?Ab@o32wY44r`JEZ^^13Z{%+>*>FnXtTI$pG ze>k{s{qF0FuWQd`l&S!%jm&a9OrlV2x%gEF>=rd=Nup*=-`>HFv;zSYRM%>CuN->V z53x+`NET@INVa+;Z6Bcxtq~BFJ%RU)$S;+9adDnxR-pXaU=)|ppIBOxaf7W{K?|5# z|1E+TA;?uSi=@oFtJOXw8V^htInk(d!kB?}B)?XC*12Ovd6>xVeB<-FU$_2yYi8hL zcHm;Bb3EHQj#`nm3u$^$&ZuT7a^qDMI%mEQd+I#`_-ft;;|p6)&05kGIjTz`ARa0E z<{^TMgF&LK688rniBWDo&m|&2=T}ihwqy-uw%|O6h?ZNmQ zl6Qfq=2%o#*&8yB8=N2c1-okYNwGwQE)FR+3HkCU5SX0!>K~r^;MBs<`{(D+r`TuJ z%}ebME@!Gcv(+$Bm>g%>XSG`%^ygYT(k(;U^?BgAnRTCKUouEx=BPZ&epT&C*)=J# z5@~~~>4M9!RnevKA!Os!yaM;NA;|_ABbVo31GE0*ZG`olIcX-XrB+C>7VA%%Vdshx zVP|xCu91yNlg&P(TeDjR-=z`^g)|qnh+;x#FnCb&-b#>`MFKmf=>`>1BQ#C^76{Df zR8D`733q^~He61i_ZK@-A}0`iQBLp>fovIPCX|!wha(@1EclmdGyK*pzcs~vRoigC z=Uz{ywj*2Hk+S6~YGJ3~*pKphBiFhe1hdssB)MI?pKO25ncVwdGC)AKmHSt%jH@Ou zH^X|~32g#o*%v2kG*K0&gE_N7IoOSrgH(b8kDbw>kC@fMC8n&762&o!9=3Y08Y?S} zy~~HP((fykg&bJfF*CYyLO=92jPJ}@lFTi(SW;vYP)ESzE52)nd`F?)(wg!m^*p7% zPzqW%&r}qiAg-4&ww^TmN=mKpg*Qs?;1De7J-T0#7BDWB(pn*vdtft8xh#XGri^#E z@yiEePskHcvZ_K}=^a|HE)t0_&i6 zSD`gny&8B)PAa(1%!f^+ftH1aa%pVxPSZy382hjWFX+q42V+U{qfJ`du!n2#f|haJ z`ZvLgb2C{hxG>3wH50ov$<3f~rXh*A+gf@0+_f6Hw1%I! zh|dRON%AksKp}_PE?rxUn3}Uud!^^<_DW9yyQgc{N@uaoVl27VQf!3uill9(tMDdR z8D2r(U_L0gdCv#n<<3If*kj`p)KU3hjh>VuU%6PQ2l!wUtBiaq%PsqAZY;Zo`{;?w z2V+U{Yd~{}W)@08577FeYmph1~#)MX$PBG z3$vD9C!Mv{U|}7bi3`?zD3jZNd;@Y@R|2K{Epl|uk#xvihM8=-&@-6H+@)B7(bhdM zZ;Tk&3OH6utW`-p^+t)l1@pw56R_eGUDxP(YLl6;Vbd1BZ7DbYu~JULM@_@pfmK39 z4wOmxm*19@zg0bJ0!bV$jOovyam}Ue0~)t%Ae%L_!8#fkD~zLj)v~~n6W^9}{#QEK z0;AUL^*64A6`+GnU#o*#|ExN=jmp`atXS9Hu8}tMwXYyuaO53%3oOhWKUXw4-eW!6M+t5!6IMT-8WR#0VebhcVH3LXv)S=itS8Z?otc~z{NNLe?1h6q zaHg`v9hhhkqj7p#4vw#tq)#L``evdYPBzBin=Lw}v^wx9!NWO8-IoqY^UWW;qW6k z#`5PP;m8~w`UK}D99)#)(4CavXfg1jOQD1f2%eq4^`$H2ZyRJQB!(e5f73Io;Ngy_ zcaTgWL8Oxu66zSlZ7Fr@QlBC5;A1xu^eNFV(W*&;5Ao6gg1!>fB7z^Be&kl!Tl9;( z%FYsWWzb^k?T`J{o`WcBbWMw&iH*_e%|8J#C!$h`WBJG;URlDYAG5=g4fAI5* zzq*`hIGb%an|7VeHEm4|%#ReubS1-g=0~Y@|H#rny6y;Ek4#T0wHVM0-l5;IOBdZ z>wYuMzgZ?Bo5NEach`zJqUOtCqEzf)o`ZaOt#@n+I8lc zyK%{Uw{Nj8H3Z*kmo2HGg_=e8`y<8&cjNuOdwn3EiIqbdE7N?p))O5`oTKlVt8QUp z@$CZd*8;*df96Ym+ZQ~@1R#;+g)}ed@;|k*|KV%tIzYmypAG-p_D|W*%>TOUlU(MiyYj(;?B6XXI8RhN_qB_*#VXLOn_1UR=(xKMzk7^p0?)OL zJZgW^m2Ml+uHWqc?Q8I5t8pB^Yykyq)Qq!VH8kFr?nz4ncc&Mp-#-N?XwOx<7vdkx zrRMUu8PBx|%W-^l2fn!jU)=FkLC3#=QR_BB|9{0R~| zv*cf%O4pr%>(RJ&|Fq*XFh!UGSB5{E<XL_Kt^JRv8O?WJ7Yda=`-M z?&^RmO9$^AT{!xzrESIh!t=km{@Zw_;c~X&a@ut{S5~l~K<}agu}>^tr$9S)!DI&ZV(Gy0VVD~7%DynR zG`=vlFqYxFvV2#X?20q+tpNg8rs{CE>TueAn0~h&CDX7XfHPj`Ri&qJ zJXY<~`d?!LeqS#+ll2CcwP-6h`n8+BWx-TyNh+>s2z|ep?#B20o)7(PIsL_Q&vu`EO&{fmr*On)!+%SQsT1X zqmk6bS?ET?@MB+Gfr#;p%SVv%G5oZE$CB1R29RWo{!;Kl zv&Azph0}aytt*tZ=xPL6@E@CujmoR45?NMie-N~8C$6c!y3u^-C z|34|?L6w7r1LSMTb4+_#%xJQ+@V^dg$#YD5SE;!7eWQq5}wn(XqCAUP= zS?^#rp#>$TwdytPaj!X@eyFE6XeHPMoM01pgGu591Ek6*pp^oQG!pE`070Ne5Avap zB(;G%?|IyF&pr2CeOXy)r{MZWXaD5~5Bn(UzvDypGAjxC zhyM+U2NX*MD3)dolXTb+FwmGbP8!3efGKPan8TKU1@cU+d9osG4OqjrfGunf*u##1 zBkT+~!-oI-q>|-{A@Mr`nf64%esdte@*Z$ z_~=|{HpDSo7%nt6!$l`An~IEa zAwI-J=OTP?cAMRPQk%o{j7^2ZP)U>tav`Rtm)W*$8`JCWV&-5x?g_1px@{@+5 zr0@XrKF+j3?lvY0siV2n7KU_?&vXvnb!l_#_7ULO*!5r}5}IVDrbAp1Dw`T7BWAzIJ0e?#iA2bzkq{S_4I^{1>C({I z5xD}nc5Z@~&6pUGjqe0G**Y*fe0gZ(_`63c0TbCU5s{4`8L|N2oy)(FGd z2*cV8cN5$#a5u9xtQGDS*2CK2Ucq|VD!5x&7YzGa*-XZ~Y>aYa0C;XJr#ql_OdBaG z+f zf2omqB8QA{w3G`V|$m zZF)|&j*dB}@y})#@6!SysKZaI>v?yqKAQpC6zU zC0jtV&2W*i9GZ}6f$%e7(8PUp;?AlCtI!7{m*a^j>BLIM8mDLOHCfTKNsj?+uShYG6 zmIX_)?XCmwtB%T~cm6=)z^c=oIJm|*KA_&GZqqgpq%>r2ypS1R=dx)OxEw3;MeDZl zHjK@5jy$uS~Hwrk!C~^%aI~W z+>&us{{=)~3U6GB$mj`3DGm+5jG}y2q7EL`a2q}*7SHWx; zy)iL8`cahI4|Q?}5DZ{bmf-X>SRiCJQ6?AbXvS2RD<-1s#QPIGcNR;+Q*d(ndQeG3 zX2Kj|$+ZLUS15|rI5orPHE;$$qa!js7R4cqhB{n|&b9DUH$stU%&E*%$`hH({wF9f z(7KJy3FDff#deVf)p~Dme(>)3h4YE?tM$!~ZRy>g?Mt>NPOVngK4@HQyx+XkoHzlh zHF{ zOdek|Qguy5%YT>a{*E-ed{SuIF1mL}?j3@A$A8f^Z>wxbap~blbE!GfjWvV0dJ|CS ziT#oNq4Tjbc^u}U2Xl*a_iruTTBD4$o6^DM-RX(+#A)l@-`1HUp4}ErM#k&#}nhuKYLz4TD z;64OjysT;bWS`J^^65nY@cWE?e)8EBvF3tQb3t%kAoC%}^;9IJnF&$+VSLa({5MFT z$&rTp#!IVFxOd7c$I_q!PC?n+e3@UfwoaT^)A_G+X>B>KvAlBF_R0|!EaLn>F!5q0 z##U(uI|auk8Ft($Nafjg+%P=nOxnz#eh-*&0&(lh~u! z!}#O)@|@7R4}Nhty*dBp-E#})66Zh^U7jELK>3W+rUS|w!ag$WWg{#DiEK$;>M;?@R>dgYZNoNG1ryBf|{=_Ax`R-)~VQj>uk4 zx2rP)tUgdds|r4fOwMX_?h;m$U2A2gkRaqme*pjl)9SoupSRz2E;tiT&BL0Z!q%_~ zVwh2@Dei@nin^lkcNR`4Hv*74l6E07;Ujr(!xbocO-4s$`{-zRik+Fnv~zUy! zl%a*|Iu2JP1oS{6`Z0hzxt}$I$y~ceX@QeApP*sD>Y>GIu34kBz}srR2xT|G6STqH zutsTt)sA^ZfYM{^>=^vzu8caMf53Hep1-0o12ZxgSj%3Y0f z1N#Mk^bdcZ^o!3^BXL^0v?*tz(6~R)HIl)bB8naqJaK>cO$s-W+p-BvpQubva|hum ze_2XoBj!@NpYvW!VW}!Kn1|aolAKi`y>}5 zSQ*l{br*5|U4eYfXf6Gm~x?;L46uGD2@TtdcVc`!G{vT zTgEv+^Z85wgr=vWDnjt^5fqNL0RV(xDm^=Y_U>B?ZzbqecXhID$&?JH=p{B07pzSL z!6DgnV**`#d}x+mugp31Ltr@JjW{j=%Ii_5O=y!Fq&HM}s>q63AfO3B#~B?l?zl zSN_qfFdOC#U8pB>eF1mXKXTg`H~cZIz9JwY;OEfLjI(N=BNbYj-8Pr78emn&n&M_y z+hMI{RodXmqCOR}EXwRRy3&vriFXh zp{6I=do_lC@s2!ty)IG;R}op&nL8~UY&e$l;M za&J!@Uo+!sbYnGZ7Rp_n8LJwO=VlB6`2Kt0c*`qs95rL+A}h3la}vfBX!*Az%>| zud`CyKGX?T2JcaM$)gs@Tx=EC*?E@FbOk)SRNII6y=m61=D_=E^=YGRelJDb^7Q!y=9&5;s!~EKUSBseu50DuABvg^vg4Y9Et@* zY$2i-Tk-uU0vu&rJpj2zQKQ*yW}->w@h$dVaeynvvuxmRZ~@HRXghN_t;c*Dlqylo zkKkSO-+(lOX05EgcX|Hu-75=MV7JlXy0>qBU-ES7wCHG;9AG>dZ1q{KI-VLAot=`i zQ*d^^^wcHZQi~6Wj?Iz-l(5m(q!tf}&JM}hAvil;x;@EL56&*0O@%~nhve-@Uy!`r zik~}i94brE_xCRCO$-&NlD6%B>8VEzzWqhRcClfn)UZ?Z?2)IHd@xDWjFyF^d70N2M)CN$%giN`od_Z5HSJi3d$i*P=^ww@L0cFglgRn`Umpz5g>Wt9&2N3T=Z= zcRmgN^`56ko}GC1;jafE1AbTQ8&f+To5Abe_IM`w5570juI}Ga0MIkqt(azYz|6w4 z)G5%2zn596qv$C95xYcdeU#AlM%JX&1|{?)tbnv-xqn}@e@5+mlfPQZ?je(%YZDN4 z!=>$g30-DnE3`c#`mvlkO`6%!#5>haXlso2@GkWo?^e^S6|m2nv(-1+{_FPx;|8vl zuT@LOjd9Zlxw%@~dc>Q*=UA#_NgnIxP27DiJjWXKv4lyQ`#-P6Wt-xwAiLs)XE!6O zn|Eo9im>oaDs8lsyj@YE-@2JHNk{!f`>k69csvy{*s5Fqwi)H8F31@gd$FB`9M zQH)ot?@nR zU+foa+NGNI#K~-%8aos0+M|m{MNfz1=}4S<>1j!^pAU$hUdhu726<&4+1OldeP^|` z{mI;;xretN-}>HcsO$S31prLr>OOFI__qt5(;x3n86isL9i=Y8)A3g$PurjJe|=Nj zb6VPST5z5&fS1oUv;nX0Da>81ZFq2b@p5WLtnHL)JJUg_wrBa|i`xFg>4J#Vc){nI zq2MVb%Js$TshRYc=^n1UF8?TUBBG_ z>Hc3H{Oll5xM@33xM@33xOO{GI1}V@GF| zuV3=|1+Rat3FCM+(qyfff<+u`4C&SuK3F7F{yjRguYF#)aOv9%ffpA7;)Scyg{z|P zJ<0c;;C^qlZ>QiH{CNK-m(sf)1|A1QPmkp35j;Kr+V<}{pBw+C_t(ARzCmfO+xaZ`>pjnoJU{XL!{5MKaQ&6~ zrZeBTw@UO)R~Gt)Ticnd%)XV20pO{IhnA$S&QZtx^AZ^7%93$ZSQ2z*V!kB6=4mn0 zxztw};#;^aBU@;xQU<4QTZ-0cVO?5-AGnq0yo|$!Z5+QYqZN=R*j)M=H<-v(k{fPq zt6aQ94|Qb;H_%YpaOt#K1&>~)%oVTT(NCGVw5`L^B5#?@H)l&hL`pUED{o|}Z?tXc z-4glBig?8bIr)F3F;}DQB{x!nM!K@EDY4f4WeqId%jJ9dqtK(n>1YX@bY(#@yH)xZ z|4yrc^GD<>QQ!LtJ=K+kp8EfQJ+0OC^h$Bsu)4CZDJM35OCEl<;_a2>MfpHE~4gFQ$j>SUwv4OoH8fh>k8rh}|E!fj}dOyG4 zFt?SZ-^O+Bchc)(+-%miU($W1D_gSO4N~$=aVgm#Q&6+L#2km)_pc!l{H{D|TKPSB zPj>CN2fbVVSl^_jAdL0?;^TqUm401`VyW9s_^X7Lig8vayBr3r7t;^AvZPn#SS)y` zs#yE2TDovYO0=&l3-b{=yE0eN?{p(Mf9BNklhCOc?td5?b#E3MI5267JL8qFV5M5X zN`*h=DrKc=u`UtVR7zV_#jE&z+14luG<0K84b8->U^}1c3wo<|XFPO}|bbi&<}k=02L@SSIFS;EX)W1hE%4gWN>$+GI!@ z3IWl28Yi-UliqdwbL<0y0R2HqC!{-RlIsq4UBqE!yVa%&+!jl$JoC8$nbDjqp(bb2#;s1Jo>}U)) zulGE|*}=AjndG%p^-?GiNf^J&L}=v2JN!R}A7pFP#C$MW|ExCVqcOGX{-LEqg0ofq z>L;S3LvnOrhy^+8g?`BK)cc~dOLBGz&Mt`E_{0N;|1LkeoSqR|wn{BqmxEFZ1aj<< z8g@X0hG(zj*(*5rs#WF%pKLGOk-C)WiR+OIP7+G>{$;46U-I+|&i;aRoFqp&m40a= zSTvRF{^sbfj*43jNm~v*9TPn#B+m)Kc|xu5tmx>H99?Tvh3&A~sR_~9BRP8nC!EzJ z5yq)5CEz0sQ6C);^-(ytP%H=>E^S?G6{|N()tljXX>NCc6`k#pvt4kuzw|&fNGh1F zNsoLv`st|H`G(Z_##5u{IV5?2DTma~=JqMfwl=jUb)N#el^2_Wdj`SJYcpXn;58n} zdW{F3@&94&-_HHbtzX{~eZ!J(Sa1)6i$3|`QZ#k){^6y=f|F63%`whs+oLwC(i{)a zHY_%z-cYbi?~tlH6DKgbrv@Zs^wFr;vQ28)wgM>amOQ%!=k5Y^W6(~HIBMM_M(9by zqlWYwVneUg(7O!swRJg~3l&nU$`jeVsx%@CM`+8c>Wt{=oZYy8<6rbcJQdl&NgtPLx^R=DA=M5?C1E#a*(bJcms+>4R7>09)q2+LLcrZMC6zCO{r5) z&OSPu4vEcuQgh$(1*y4TtluuxZ%>*Fic>in3seP&`b_%Ta>qCQzv>rz4@$iUpMsnp zmpsP>=kXkoL`Re4Xu{JPn~|CO7x$+!`;ZVT=;?-Y8ZHmS$&vpVlikurYgbIpJ4c|YqbOZvx|F%SY-SeneH7r#P3)W#Jm@WttF&r&81~=|TUU~{M z!kA&S!A2X^9I>;9j2?eYgm2^ z0gHf~=8Ry9?5*Fz)E^=E8G?U^fY?rVG4-bih_w~M)KLV75xk!TSW~nD7EO0@KWheq z*#lF%2H0tH8y@t`2Nr|58O!AZtHFE}^ELph)m)87LN@>}Z3aU^3#>*grv*+k=4nBd z*9=jSTF}>xd0H?+U#HC@aQgH|ZwieFd2oH6$1-G-W-k-gNkCzCi164*fuZpEG_7P|-EdJ$kKh+?**l;_#_h>v2_ z6H^|EP7dL4t(amEv>`y-orFbmNI`{7qnN_+rW}1GOhiI)TH#-}9#T$9AL0HLyag&! z(Ix{$tr=;WUbDDq(;9`KgQD97YIFYYcT|s1{CCY{q79(T{y!*#22P_BXq5$btneQ} ztd)u3WP1{fOrf$>s$lMz)+{G!8V-UNhToI?-{rqOXBaWkIM9pVzE|G;PFo~mp=k`T JE)2*x`oCMFDYpOs diff --git a/src/session_ir/__pycache__/syntax.cpython-311.pyc b/src/session_ir/__pycache__/syntax.cpython-311.pyc deleted file mode 100644 index 373b59233bf6d23de99abe8b6797d549ba477129..0000000000000000000000000000000000000000 GIT binary patch literal 0 HcmV?d00001 literal 16164 zcmcgSZEPDycDv;ATNL$aOO|7={3X$rC@Zp@L{Xf`66I5@P_`)NgNeb=+?CCQAM)%n zkretsUsHs+^ABB+z|JKuoP(XSkrZ{VS0GmeX#4L_^aoi8EwQKpqeaoX9|dH{KMMWo zd$asnlG?N4+%0z>XJ_7f^WMyxH*aS4S5Bv$f$M{*-@diHmtp=3Uy4_wnqb%Oni=LQ zBQOC*UbQ?_AUzvji+LYrq<_1#B^Uz#el199R};5KIB5 zfjPkl=Jy%F@}+@czJf=+0*$o93MDqt^`#NY;3Q)mtB5ZVG=LVIARur2U}usyI#=m_i=E~h`^1CuTt$8#)VHU~YWjs&g`xMkfJb;uI12v*LO^&L{tpYU3(vs+pzww; z3ja^)$od?}dQ4Z=Asy=Hf%*kq>LWVTV?cdemwH%-dK{=Hbg7T(PSuJQPXhI{F7=2G^-DnQ)1`h^hk6F6Pw7&R>QJ8s>RDat=X9w3 zKs~2ReN2b?3{bzUOZ_~Iydm+3I4m9&pAw%IpAkpIXT?$RIq{hI{JgVbEWRMT;%D4v zLvENt#?DDH358`|T8hh|MSea(c=>|JC&J<6LMR?y>X(-mM2Yu{k`zhA`KejH_npIT zkKI0p`6E1DXW|i=Pw~f-^L!ls$M}Q%arpP!3si{ajSG;~J?8Pl-}CCOdi&Si= znqTB!AK}N&@~^+Zle3iq*k4Qv=VM}A2K`TjVzCgP>IXdl87l|LdI_M16R{X58VV{=n8zOm{4 zmu4os)1H{%9sw;5^5ejkhn@wd5_BmMLjvttXn}=9BrfyuP)tNtabW-(VxXXJazO~m zA|H_@Xf4|5v{BFuuwBtO2nZu2p$Wr@xGXNp?q~To!_Yo&@)3y-@q!38l?=-XG6HN6 zNlL~*Y+y-Ql_Us3XPk?~1(Z+Z7evy3j)2WwpnN0oByABsB=K)9MxfRFkvBb5wXtZF zSItsf42ui0YJedk^3h0K3=zH;OtG&hK3}X)>f_N&B+5P%iAUn+Rn;ztF}J5+#@H&L z1n^46K~I@P!m=oM?0>*H&dn;0P#ijeN+!7tiVYeo6pn@@Nioew#HiplDcl6mDBN^J zk`?RB0`@>Cs+i`I3sF%q!C*&x(Rl@XZ$3jw780z;$71x%tj zU=gi?6M{poY8tiCd`nHf9r7CmdriKB<~wTg8-xaM3oga-QfToMSl#lZUyMZvv=ZOz zvJ0w`-$1H z32!jqot+^lB*7-VVXFeFyO4CwrS?S8#^+_d~@p> z!`j>wWXA5bbYAs*>ZN}$?PKt|4gM?l(924aW34!(@p$c_l zh5Hatn?+%1AF4WIhwq0+`XzvL>6hnDWw}%L9qs9fyuCF&e&5u*W-yrctT9FKz{r?e z-hV^QwL%(G?O3jYit_d~wVX47H55Uq95WgyeX)olY067fw5_S+VUV|UacYWPKLCjj zs@%C?6YLpgo)xU`I|E#XS!4qy81fFq>YtkR5|SXxNBndGO%hQ6&nkxB2JaLLg)hMD z#*2u-zZ*e+z(X6Ki;6Iz38KfRaQLqnVbW5JG3mTwTu4Y8oy8gGbvgmzuf11k@XIE?Hze}} zW!qp!h=cyS6~=8M1CSn4}~`9BA(7OM^k2xFH0Zug0?lgLHlm1|@WW;Bxr1 zYOo{ly4+msG*6My6l6;a0RAt{i_SCvi&b-`%m2Uf7|>UOu+qZ_#eB!n^)5XIQMd{^Oc(EldXpgl;2dy}5j0QIgP<1yDx^3I`i8}56k3HP=vXA|`WIBSJ&1~65)1qQ zK+)na&mGHh$JRK`^csuf=KDfb7pz6Gd4p$sCw()o_!NsbI5s^s=2w~^&krw?bKcqD z#O%x|#pw-B%$zws?F~-OdcBI-8=UrzomA}J;HlY}xtZ~qX~pFYj!(}3nQvw;==Dt~ z4xj9-eh{{KfuBGxs@bdO~ep#L(0Z4gfE99p~C|?Pp-P ziblbJmLM2G5>DYD!k(j3io(WycepBn6jv}<5h%kXN;-1@TagOW{TMX8NcY7V3}DW+2p|Icl3J#$Mv3L8?`b3XD4kXK6=z&r#v zj3t~@wbD7#C(Nk zOs5@;&<-4J2b^il3g?G45qTY%qC?y;_uxvs2PcrYT)#;|h>YMpc-Cv1#F?H-PhFnM zb4}^#^z>zT($lKMNc8v;&%zS5EHOEU;vm=h(xTlH1eY-(AfSN;X4RMFk6OHKDlV&Q zkd0mHOsYbdZTon&{m%CB9*^g&VpW$MqEuhF3n&hP58zqHcu#9xeOV6g9EFfjMMr|~ zE4p{FAUcTv7xET>`l7|K7{L`x;Mi0v$E@#Jxd}~cj&_*BZqgzNtO&u+;i=;d3dV&d zrpkl33M(syxg{FBD%`n5BB}}4IY2R@FFVN6)e6Akm0~JaDcZFNfhD(}k+s;!t8mp| z8)~r4MO+9~AP^~^;sEbjZ0n}jy)uR`g)7CpRpP4+fEHS-@JivB77yfXE^T zTsLTOe!{xBE_Fi9kFNMd=8+AM7LLw^QE&;5)VaKVo3*(ub+h|4> z5V+DPm2M%qZHhf2MdA>-!sY;-r06_AyPx`8#TJo*>P8NE0|X{#0Vs`Q60Fg2FNKE4 z5SLtpY#NuSYe4cY;v)DQ3w{OwR(+P{mF`c@Avshz3}lQ;3YWmX z4|_0g(F0%1ny6aMXorgStw!&rBG($d56Kvi6)sKvhR3QOC%D43`QY|x3=cbC2z}%+ zNStI?FuoLXwgb)Z5_`#zVl_roIkvnVF+HQOqaTV&$2_HiZ$K8hY4dyL_b`OByT;-EhP%t&9lXKb zI&z!+;;EZYT}!F?m5`3HKdF8s1+tMJ1JGziegZk0>hrfq^A`xPhc?cLJ&qk0|%Un6_bpc$#fzoi;w~CkcO)0ISTHOk|DSQj|6=SZK*mq zf6mgmYU!lz@SdyX!{im%{i|__?t8A*m9dY#*N@y_Z<;?H{d_d%>Rom9X05$j$9*kl z*}ZDnja7PC@SfM()sFj?{mu@l+^+FefSu#3o#Q#z#Hwo|Yn@PQ`CgRhgNN_30N~Eq zkFMH}X1SxP4?YadQDY?3``(5&+Jg7pTA*NuT@L20lD~$%kFA6PFFl$szN8(n6(NJX zd6;1aZ-F~9+;t;t<6_EGRof;31@7N$!SA(I`npO#TjNP9J(+ovFvSAfT^Oe<<4Tm@ zV0+0^(6P%#IQb$;NEJuaX-KO9#><$(^_gN?SP05X<=}$G9*PBWaXiwIq>d^B4Kfri zD$dK58|&n!$P2-5;gS9YKyh$YL=W5YuJ+73HG^em-qp1d`Z%0PWl~vdms(yT<4nEx zTx~0-KlXpPd}TSq-E*`f^7Y}IqkGlS4I{|5JKwr%MP7Lpf0>DV%eJhm2kz^`H=1v@ zeme5`i29zj_Ehm^O*`+owyj+JSo$z^h1RVTtZ2pv&f;{8?ATg_vb8bNCm1%1MYJ{o zHfpT0(NdgIjd>lG{+elwkvESG`ULLJB0)uTAh$r<7OwfKgAwAblDvYhDylIExIb#X z1bd`6N)b$vFaE=JGe$S1C53);gOfkBvJH1>1v_oS@&+vlSxwqhOzG7lGQg@^n5(|nc5|4{S8+lMZ2!4n1 zTQ`~I>o0naI|gAKBD4{dVxX5lH1aCszSB zO|CXgW=#2(wydig?rSFXAEC9IuDCXv?Mn;D`UkJ-E-O89rpv5C97{Ljz@|#nmChf6 zuce@Pk^BN${NJ$E9ROgf-_fwb{`6@2B{d9%ywX*e_1X1N$g00pNk9EDe$8pUSHL8g zVC&9|bbPT;i@|9p=Ta=C|I>|{3;UT zGJqmfZ$f^K1ql8F9_bkX>5AWduDI#f#a|n~y)D~yIM;P}wd-(tJj)$c?_4pV24Bbv zt-f@Xng+MQv`rI$9cTC^wQ~Q~f;0YfL?(X)*yIKRJk#*O=}whi^r(X>hYLKl@^(!9 zvIzbY64G7(8kM@bQTT54&J`0XJ(AWJz86Zg!k4$p1DwFYn`snq1T*xZMKQq#EQzps zAWNf?Ds}GEs6#cOI#sE26Sxut{{xTI2SB4vaUVUerx%j{AbN2V@SzrLCgT@eu)i)= zcN4hA3FOuu;f#XMI`=yeS8sjt=~l>BkEN@j-!Sa2essukXB)Ew<# zjt<2#Ey`3|bSvdgWT^7wYs~v=1XV^_w=@3+5fN;_Bb@-CRljholP}q2sU1oQy#_(f z^&4c1Bhcs*-z7`HO%3)RMYV4b8-Wof+4b6yRy-5ZlOM_J%dcan6^A#_d1mN53++5B zbe>It?e(}Yr_KllaY40MBYfZZNd5I2R0@F&l&WK{MWr}b`egd#<&(O81o_n0Zi~HR z!owa_C-QeF;iL4=w}^nbgdFFd0kB=4k;9IqeSSvx$j6eba zxeJ)4Zk*;~sumY#wOU-7YgQwC$`?5H9e}a=M`4IyA;E244;3R@+1TP`*AvlfT41xfHAc7DA?ZQ(%f1_=Q%>kQh zzNtC&OpWd&)1~XrknR@6@6s0E~t`bn>UuB%M~M_oe=iIu|;|sPQNqj?}7H zaKk#PesFk<{4+2F`(mU|p&i$ZEX%H$n^0c`0{E!W&{0CQ*5lwn4%GlTIFN&*l7j=jtE`d1z&5}~ zm^I)5<~>AE=73m#5-kjDGs;j6P=;odp}A6q=6W*J5>tj-;J~u|*pk%%Te2TpvcD_? zV%2HMT4Ks@OB@=Jq#7WHMwFqkQiev5!RpNTSN2`wu0?KlW}Q#2T87eG-ek`VL#F9k zGV9p4YTBPR+_yBOlb7Fp|J^jVX123O))+0=;b5OyW3+&8Ks+tjrA46>J6W~`g{}k* z^~`J#d!!m*2MuBu50+I!th#0fUlX%zHNeK%gN?JN%mK0LbdUjwYXQmt8~~I#AXXh2 zYKbYsEpRZR47K0^<~>AEmI1Nqw4@0+)Pe_?_Ygsu17bDR>x;*2hgt=wQd`jC@muoo zIXu1=kI%u3y;%z$VBSLn<=#ZB7Inz?TpPZz?>2Y){9P&UY+3Qb>w(+*?iyhtZae~m N!8)Ag@JClz{|~C#A$R}) From 7fcdd8decdf976b66bd295f5bfdf2bbbd4f225af Mon Sep 17 00:00:00 2001 From: Arena Agent Date: Sun, 4 Oct 2026 20:47:05 +0000 Subject: [PATCH 3/7] =?UTF-8?q?docs(recon):=20plan=20=C2=A76=20measurement?= =?UTF-8?q?=20discipline;=20position=20doc=20cross-reference?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit - Two ratios, R1 before R2: executed/required (~0/100 today for occupancy's gates, 4 of 100 runs had any job) and passed/executed (~100% in every proof lane). - Green must mean executed; STARTUP_FAILURE as failure for required checks. - Proof lanes carry zero flake tolerance (no flakes found in the window; every red had a cause: real breakage, supersede, infrastructure); environment drift is the real risk (echo-types#322). - Tightness is a distribution, not a gate (ULTRAPLAN §6 soundness/tightness asymmetry); nothing measured yet — Zephyr fixture is still a request. - Three kinds of red, three responses; recompute commands. - Renumber the falsifiers to §7; point W1.8 and the position doc at §6. Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com> --- docs/recon/COORDINATED-PLAN-2026-10-04.md | 110 +++++++++++++++++- docs/recon/TYPE-FAMILY-POSITION-2026-10-04.md | 3 +- 2 files changed, 110 insertions(+), 3 deletions(-) diff --git a/docs/recon/COORDINATED-PLAN-2026-10-04.md b/docs/recon/COORDINATED-PLAN-2026-10-04.md index 3948bd8..a0cf9ba 100644 --- a/docs/recon/COORDINATED-PLAN-2026-10-04.md +++ b/docs/recon/COORDINATED-PLAN-2026-10-04.md @@ -51,7 +51,7 @@ plan's job is to make the boundary between *established* and *open* impossible t | W1.5 | Lane `experimental/echo-additive` + the 4 bit-narrowing modules | echo-types | automatable | modules in `All.agda`/a lane or archived; issues #320/#321 | | W1.6 | Pin the Agda toolchain (drop unpinned `apt-get agda`) | echo-types | automatable | pinned version in workflow; issue #322 | | W1.7 | Make CI mirror the local all-provers gate (or say so loudly in CI + README) | absolute-zero | author | issue #161 closed or scoped honestly | -| W1.8 | **Estate-wide: treat `STARTUP_FAILURE` as failure for required checks** | all | owner (settings) | no PR can merge with zero CI signal; echo-types#330 | +| W1.8 | **Estate-wide: treat `STARTUP_FAILURE` as failure for required checks** (§6.2) | all | owner (settings) | no PR can merge with zero CI signal; echo-types#330 | | W1.9 | File the missing issue(s) for repos with dead CI and no tracker entry | occupancy-types | done (issue #6) | — | | W1.10 | Remove tracked `__pycache__` (7 files) + ignore rule | occupancy-types | **done this session** | clean tree | @@ -173,7 +173,113 @@ claim and retain the suite as Agda exposition"*).* --- -## 6. How to tell whether the plan worked +## 6. Measurement discipline — how to read a pass rate + +*Added 2026-10-04, after the recon. Every figure below was measured that day from the Actions +API — never from a badge.* + +### 6.1 Two ratios, never one + +A single "pass rate" is ambiguous in a way that flatters a broken pipeline: a run that never +executed is still a run, so 96 non-executions read as "96% failing" — and when the gate that +never starts is the one that would have failed, a disarmed repo can read **green**. Split it: + +| Ratio | Definition | Measured 2026-10-04 | Target | +|---|---|---|---| +| **R1 · executed / required** | required checks that produced at least one job | **~0/100** in occupancy-types; **≈100%** in the five repos whose proof jobs run | **100%** | +| **R2 · passed / executed** | executed checks ending in success | **≈100%** in every proof lane measured — epistemic 21/21, residual 39/39, tropical Lean 13/13, absolute-zero Proofs 5/5, echo-types green at HEAD | **100%** for proof lanes; **no threshold** for tightness (6.4) | + +The occupancy-types figure in full: of the last 100 runs, 96 `startup_failure`, 3 `failure`, +1 `success` — and **exactly 4 runs had any job at all**, all four being dependency-graph +"Update" workflows (pip, hex, npm_and_yarn, github_actions). No gate in that repository has +ever executed a single job. + +**Rule: report R1 before R2.** A pass rate quoted without its execution rate is not a +measurement — and a "100% pass" over 0 executed checks is precisely what a dead pipeline looks +like. + +### 6.2 Green must mean executed + +A green tick is evidence only if a job ran. Enforce three things: + +* **`STARTUP_FAILURE` counts as failure** for every required context, and so does a required + context that reports no jobs (W1.8; the recommendation in echo-types#330). +* **Every receipt names a run id and a commit.** `[CI]` in the estate's tagging means "a job + started and passed", never "a workflow is listed". +* **Prefer a revoked badge to a stale one.** A repo whose gates cannot run should say so in the + README rather than display workflow badges that no longer execute — the badge is the single + most misleading artefact in a disarmed pipeline. + +### 6.3 Proof lanes carry zero flake tolerance + +Proof checking is deterministic: same toolchain, same inputs, same verdict. There is no +legitimate "sometimes" for `agda All.agda`. A proof lane's expectation is **100%**, and any +deviation is a bug in the pipeline or the environment — never noise to budget for. + +What the estate's own record shows (last 100 runs per repo, 2026-10-04): every prover red in the +window had a cause — + +* **real breakage** — echo-types' Agda lane on 2026-09-27 (`39a7a99c`) and 2026-09-30 + (`f11031f2`), the "Typecheck full suite" step failing: main was genuinely broken, then fixed. + The cold-check step (`--ignore-interfaces`, no cache) failed in the same runs; +* **supersede** — a concurrency `cancel` (absolute-zero `Proofs` `27d879f5`; echo-types Agda + `36919959218`); +* **infrastructure** — the `startup_failure` family. + +**No case of the same commit passing and failing at random was found.** That distinction is the +point: *flakiness* trains a team to re-run until green and is the thing to hunt; a +red-with-a-cause is a bug report carrying a file and a line number, and it is the system working. + +The one real drift risk is the environment, and it is documented: echo-types#322 — +`agda.yml` performs an unpinned `apt-get install -y agda`, so *the prover under the proofs can +change without a commit*. Pin the toolchain (W1.6) and keep the guardrails already in place: +`--safe --without-K`, the postulate/escape greps, the `Smoke.agda` pins, the kernel certificate. + +### 6.4 Tightness is a distribution, not a gate + +Keep the asymmetry ULTRAPLAN §6 already states: + +* **Soundness** — *"measured ≤ certified on every run. Violation = stop + ledger entry"* → + **100%, zero tolerance**. This is a correctness property, not a benchmark. +* **Tightness** — *"certified/measured per unit; report distribution"* → **not pass/fail**. + +Do not turn tightness into a threshold. A limit loose enough never to fire is decoration; one +tight enough to fire on measurement noise teaches everyone to ignore red — exactly the failure +mode 6.3 exists to prevent. Report the distribution, watch it move, and act on trends with a +named cause. + +Also note the current state: **nothing has been measured yet.** The Zephyr painted-stack fixture +(W4.3) is still a fixture request, so R1 ground truth does not exist. "Benchmarks occasionally +drift" is not the situation; "no benchmark has ever run" is. + +Retries are permitted for genuinely non-deterministic infrastructure — package/action downloads, +superseded runs, cancelled fuzz batches — and are **never** permitted to produce a green verdict +on a claim that was not checked. Blocked ≠ retracted; blocked ≠ passed. + +### 6.5 Three kinds of red, three responses + +| Kind | Signature | Response | +|---|---|---| +| **Real breakage** | job ran; a named step failed | Fix or revert; the run id goes in the ledger entry | +| **Environment / infrastructure** | job never started, or a dependency fetch failed | Fix the cause (pin, allow-list, retry policy) and file it; never re-run to green | +| **Supersede / cancel** | `cancelled`; a newer run exists on the same ref | Nothing — but confirm a later run executed | + +### 6.6 Recompute it + +```bash +# R1/R2 inputs for a repo — conclusions, from the API, not badges +gh api "repos/hyperpolymath/occupancy-types/actions/runs?per_page=100" \ + --jq '[.workflow_runs[].conclusion] | group_by(.) | map({(.[0]): length}) | add' + +# R1 precisely: did a run actually execute any job? +gh api "repos/hyperpolymath/occupancy-types/actions/runs//jobs" --jq '.total_count' +``` + +--- + +## 7. How to tell whether the plan worked + +*Measure everything below with §6's ratios: **R1 before R2**, and green-means-executed.* Falsifiable, in order of cheapness: diff --git a/docs/recon/TYPE-FAMILY-POSITION-2026-10-04.md b/docs/recon/TYPE-FAMILY-POSITION-2026-10-04.md index c1bc1d3..7a39e38 100644 --- a/docs/recon/TYPE-FAMILY-POSITION-2026-10-04.md +++ b/docs/recon/TYPE-FAMILY-POSITION-2026-10-04.md @@ -571,7 +571,8 @@ nextgen-languages/kitchenspeak, and a Rust application example in invariant-path Practical consequence for planning: **for these repos, a green badge is not evidence until the underlying workflow actually started.** The recon above therefore cites run ids, not -badges. +badges. The coordinated plan's §6 turns this into a measurement rule (two ratios, R1 before R2, +green-means-executed) — see `COORDINATED-PLAN-2026-10-04.md`. ### 4.4 Planned already (named, in-tree, not speculation) From d5caaca3c222d1822a25a83e7519f85f751bd201 Mon Sep 17 00:00:00 2001 From: Arena Agent Date: Sun, 4 Oct 2026 21:31:38 +0000 Subject: [PATCH 4/7] feat(ci): give the runnable rungs an execution path; fix R1 build scaffolding MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The R1 harness reported "toolchain absent" (exit 2). That was accurate but hid a second, permanent blocker: tests/run_stackcert.sh runs `lake build` and `lake exe stackcert`, and the repository carried no lakefile.toml and no lean-toolchain anywhere — so the rung could not have passed even with Lean installed. - src/stackcert/lakefile.toml: libs StackcertCore and Parsers, exe `stackcert` rooted at Main. src/stackcert/lean-toolchain pins leanprover/lean4:v4.15.0 rather than floating it (cf. echo-types#322, where an unpinned apt-get install lets the prover change under the proofs without a commit). - .github/workflows/proofs.yml: stackcert job (elan, strict) and occ-idris job (Idris 2 v0.7.0 over Chez Scheme, continue-on-error until its first green run, because a rung that has never executed anywhere yields information on red, not a regression). Only actions/checkout is used, so the allow-list posture under investigation (#6) cannot kill these jobs. - .github/workflows/session-ir.yml: the Session IR rung is the estate's only fully-green result (14/14) and had no CI lane at all. Adds the 14 pinned fixtures plus the kill-test audit and repo-shape gates, on the runner's system python3 (the module is pure standard library). - Pin two action refs the pinning gate already rejected on main: haskell-actions/setup and SonarSource/sonarqube-scan-action. The gate now exits 0 for the first time on this branch. Docs: retraction-ledger gains both new blocked rows (with their CI paths) and the stacked-blocker finding; EXPLAINME C4/C5 record the CI path and state that the #print axioms output is pasted only after a real green run; the three recon docs convert to AsciiDoc (estate rule: no .md under docs/) and the unsent follower drafts leave the public repo. Gate: bash scripts/check.sh --runnable-only -> exit 0, proofs correctly BLOCKED rather than skipped. Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com> --- .github/workflows/pages.yml | 2 +- .github/workflows/proofs.yml | 97 ++ .github/workflows/session-ir.yml | 80 ++ .github/workflows/sonarqube.yml | 2 +- docs/EXPLAINME.adoc | 17 + ...04.md => COORDINATED-PLAN-2026-10-04.adoc} | 363 +++--- docs/recon/FOLLOWER-NOTES-2026-10-04.md | 1045 ----------------- .../TYPE-FAMILY-POSITION-2026-10-04.adoc | 711 +++++++++++ docs/recon/TYPE-FAMILY-POSITION-2026-10-04.md | 647 ---------- docs/recon/ULTRA-PLAN-2026-10-04.adoc | 229 ++++ docs/retraction-ledger.adoc | 27 +- src/stackcert/lakefile.toml | 30 + src/stackcert/lean-toolchain | 1 + 13 files changed, 1407 insertions(+), 1844 deletions(-) create mode 100644 .github/workflows/proofs.yml create mode 100644 .github/workflows/session-ir.yml rename docs/recon/{COORDINATED-PLAN-2026-10-04.md => COORDINATED-PLAN-2026-10-04.adoc} (51%) delete mode 100644 docs/recon/FOLLOWER-NOTES-2026-10-04.md create mode 100644 docs/recon/TYPE-FAMILY-POSITION-2026-10-04.adoc delete mode 100644 docs/recon/TYPE-FAMILY-POSITION-2026-10-04.md create mode 100644 docs/recon/ULTRA-PLAN-2026-10-04.adoc create mode 100644 src/stackcert/lakefile.toml create mode 100644 src/stackcert/lean-toolchain diff --git a/.github/workflows/pages.yml b/.github/workflows/pages.yml index a176cb2..205d588 100644 --- a/.github/workflows/pages.yml +++ b/.github/workflows/pages.yml @@ -34,7 +34,7 @@ jobs: path: .casket-ssg - name: Setup GHCup - uses: haskell-actions/setup@v2.12.1 + uses: haskell-actions/setup@0f8e8c99d88aeb3fbfd523f1ef2c6f762d10d64d # v2.12.1 with: ghc-version: '9.8.2' cabal-version: '3.10' diff --git a/.github/workflows/proofs.yml b/.github/workflows/proofs.yml new file mode 100644 index 0000000..e786971 --- /dev/null +++ b/.github/workflows/proofs.yml @@ -0,0 +1,97 @@ +# SPDX-License-Identifier: MPL-2.0 +# SPDX-FileCopyrightText: 2026 Jonathan D.A. Jewell (hyperpolymath) +# +# proofs.yml — the R0-B / R1 proof rungs that cannot run in the authoring +# environment. +# +# WHY THIS WORKFLOW EXISTS: both rungs were recorded BLOCKED in +# docs/retraction-ledger.adoc because the authoring machine has no `idris2` +# and no `lean`/`lake`, and cannot fetch toolchain binaries (release-asset +# hosts unreachable). GitHub runners *can* fetch them, so the rungs are +# verified here rather than reported as proved by nobody. +# +# stackcert — Lean 4, toolchain pinned by src/stackcert/lean-toolchain. +# `bash tests/run_stackcert.sh` = core `#print axioms cert_sound` +# + `lake build` + positive fixture + four negative controls. +# occ-idris — Idris 2 v0.7.0 built from source over Chez Scheme. +# `bash src/occ/check-rejections.sh` = the accepts compile and +# the four expected-rejection controls are rejected. +# +# NO THIRD-PARTY ACTIONS by design: only actions/checkout (GitHub-owned), +# because this repository's Actions allow-list posture is under investigation +# (issue #6) and a step referencing a non-allow-listed action dies at startup +# with jobs=0 — a gate that cannot start must not be trusted to say "green". +name: Proofs (R0-B Occ, R1 stackcert) + +on: + workflow_dispatch: + push: + branches: [main, master] + paths: + - 'src/stackcert/**' + - 'src/occ/**' + - 'tests/run_stackcert.sh' + - '.github/workflows/proofs.yml' + pull_request: + paths: + - 'src/stackcert/**' + - 'src/occ/**' + - 'tests/run_stackcert.sh' + - '.github/workflows/proofs.yml' + +# Estate guardrail: cancel superseded runs on the same ref. +concurrency: + group: ${{ github.workflow }}-${{ github.ref }} + cancel-in-progress: true + +permissions: + contents: read + +jobs: + stackcert: + name: R1 stackcert (Lean 4) + runs-on: ubuntu-latest + timeout-minutes: 30 + steps: + - uses: actions/checkout@v7.0.1 + - name: Install elan (toolchain resolves from src/stackcert/lean-toolchain) + run: | + set -euo pipefail + curl -sSfL https://elan.lean-lang.org/elan-init.sh | sh -s -- -y --default-toolchain none + echo "$HOME/.elan/bin" >> "$GITHUB_PATH" + - name: Run the stackcert harness (core + build + fixture + 4 controls) + run: | + set -euo pipefail + export PATH="$HOME/.elan/bin:$PATH" + bash tests/run_stackcert.sh + + occ-idris: + name: R0-B Occ spike (Idris 2, advisory) + runs-on: ubuntu-latest + timeout-minutes: 45 + # Advisory until the first green run: this rung has never executed + # anywhere, so a red result is information (bad toolchain assumptions, + # or a real error in the spike) rather than a regression to block on. + # Remove this flag once the job has passed on main — see + # docs/retraction-ledger.adoc §Blocked. + continue-on-error: true + steps: + - uses: actions/checkout@v7.0.1 + - name: Install Chez Scheme (Idris 2 backend) + run: | + set -euo pipefail + sudo apt-get update -qq + sudo apt-get install -y -qq chezscheme build-essential + - name: Build Idris 2 v0.7.0 from source + run: | + set -euo pipefail + git clone --depth 1 --branch v0.7.0 https://github.com/idris-lang/Idris2.git "$RUNNER_TEMP/Idris2" + make -C "$RUNNER_TEMP/Idris2" bootstrap SCHEME=chezscheme + make -C "$RUNNER_TEMP/Idris2" install PREFIX="$HOME/.idris2" + echo "$HOME/.idris2/bin" >> "$GITHUB_PATH" + - name: Occ spike — accepts compile, four controls rejected + run: | + set -euo pipefail + export PATH="$HOME/.idris2/bin:$PATH" + idris2 --version + bash src/occ/check-rejections.sh diff --git a/.github/workflows/session-ir.yml b/.github/workflows/session-ir.yml new file mode 100644 index 0000000..0b780d0 --- /dev/null +++ b/.github/workflows/session-ir.yml @@ -0,0 +1,80 @@ +# SPDX-License-Identifier: MPL-2.0 +# SPDX-FileCopyrightText: 2026 Jonathan D.A. Jewell (hyperpolymath) +# +# session-ir.yml — CI lane for the R0-B Session IR rung (ULTRAPLAN Phase 1). +# +# WHY THIS WORKFLOW EXISTS: the Session IR checker is the estate's only +# fully-green, fully-runnable rung — `bash scripts/check.sh` passes 14/14 +# locally — and it was the ONLY rung with no CI lane at all. That combination +# is the worst of both worlds: a result that is genuinely reproducible is +# attested by nothing a reader can click, and the repository's most credible +# claim is the one with no receipt. +# +# The module is pure standard library (json, sys, typing, dataclasses — no +# third-party imports), so it runs on any runner's system python3. That is +# deliberate: fewer moving parts, and no toolchain to fetch. +# +# The lane runs the SAME command as `scripts/check.sh` stage 1, including the +# kill-test audit and the repo-shape gates, which are the other two stages +# that can execute without a prover. Proof stages (Idris, Lean) are out of +# scope here — see .github/workflows/proofs.yml. +name: Session IR (R0-B) + +on: + workflow_dispatch: + push: + branches: [main, master] + paths: + - 'src/session_ir/**' + - 'examples/session_ir/**' + - 'scripts/check*.sh' + - 'docs/OPERATIONAL-MODEL.md' + - '.github/workflows/session-ir.yml' + pull_request: + paths: + - 'src/session_ir/**' + - 'examples/session_ir/**' + - 'scripts/check*.sh' + - 'docs/OPERATIONAL-MODEL.md' + - '.github/workflows/session-ir.yml' + +concurrency: + group: ${{ github.workflow }}-${{ github.ref }} + cancel-in-progress: true + +permissions: + contents: read + +jobs: + session-ir: + name: R0-B Session IR (checker + kill-test + repo shape) + runs-on: ubuntu-latest + timeout-minutes: 15 + steps: + - uses: actions/checkout@v7.0.1 + + - name: Session IR checker on the 14 pinned fixtures + # 7 accepts (judgment, measured steps <= grade, peak live bytes) and + # 7 rejects (each pinning its exact error code). A reject fixture that + # starts being ACCEPTED is a regression, not a tolerance question. + run: | + set -euo pipefail + PYTHONPATH=src python3 -m session_ir test examples/session_ir/manifest.json + + - name: Repo shape gates and kill-test audit + # The runnable slice of scripts/check.sh: root allowlist, docs .md + # policy, and the Phase 0 kill-test block (four sentences, banned word + # absent). Proof stages are excluded by design (see proofs.yml). + run: | + set -euo pipefail + bash scripts/check-root-shape.sh . + bash scripts/check-no-md-in-docs.sh . + bash scripts/check.sh --runnable-only 2>&1 | grep -E '^(PASS|FAIL|BLOCKED)' || true + # --runnable-only exits 0 with proofs BLOCKED; assert the three + # runnable stages actually PASSED, and that nothing FAILed. + out="$(bash scripts/check.sh --runnable-only 2>&1)" + echo "$out" + echo "$out" | grep -q '^FAIL' && exit 1 + echo "$out" | grep -q 'PASS: session-ir examples' || exit 1 + echo "$out" | grep -q 'PASS: kill-test audit' || exit 1 + echo "$out" | grep -q 'PASS: root allowlist' || exit 1 diff --git a/.github/workflows/sonarqube.yml b/.github/workflows/sonarqube.yml index 7c45959..d65d08b 100644 --- a/.github/workflows/sonarqube.yml +++ b/.github/workflows/sonarqube.yml @@ -64,6 +64,6 @@ jobs: - name: SonarQube Scan if: steps.cfg.outputs.configured == 'true' - uses: SonarSource/sonarqube-scan-action@v8.3.0 + uses: SonarSource/sonarqube-scan-action@d209202bc7d53ff1cc128f7f907dac145c9d6ae9 # v8.3.0 env: SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }} diff --git a/docs/EXPLAINME.adoc b/docs/EXPLAINME.adoc index ecad9dc..dbd9992 100644 --- a/docs/EXPLAINME.adoc +++ b/docs/EXPLAINME.adoc @@ -59,6 +59,11 @@ Status: *UNVERIFIED* (no `idris2` in the work environment). (CONJECTURE: constant grades tolerable and tight on this example). * Commands: `cd src/occ && idris2 --check Occ.idr && idris2 --check Demo.idr`; `bash src/occ/check-rejections.sh`. +* *CI path (added 2026-10-04):* the `occ-idris` job in + `.github/workflows/proofs.yml` builds Idris 2 v0.7.0 over Chez Scheme and + runs the same script. It is `continue-on-error: true` *because this rung has + never executed anywhere* — a red result is information, not a regression. + Remove that flag after the first green run on `main`. == C5. stackcert `check` is sound: accepted certificates bound every call path @@ -74,6 +79,18 @@ Status: *UNVERIFIED* (no `lean` in the work environment). * Commands: `bash tests/run_stackcert.sh` (core + fixture + four negative controls: decremented bound, undeclared recursion, unresolved indirect, undeclared cycle). +* *CI path (added 2026-10-04):* the `stackcert` job in + `.github/workflows/proofs.yml` installs elan and runs the same harness. + Until 2026-10-04 the harness could not have passed even with Lean installed: + the repository carried no `lakefile.toml` and no `lean-toolchain`, so + `lake build` and `lake exe stackcert` had nothing to act on. Both are now + committed, and the version is pinned rather than floating (compare + echo-types#322, where an unpinned `apt-get install agda` lets the prover + under the proofs change without a commit). +* *When the run is green,* paste the job's `#print axioms` output verbatim in + place of the expectation above, and record the run id. Not before: a + predicted footprint is a conjecture, and the point of this repository is + that conjectures are labelled. == C6. Fixtures are real compiler output diff --git a/docs/recon/COORDINATED-PLAN-2026-10-04.md b/docs/recon/COORDINATED-PLAN-2026-10-04.adoc similarity index 51% rename from docs/recon/COORDINATED-PLAN-2026-10-04.md rename to docs/recon/COORDINATED-PLAN-2026-10-04.adoc index a0cf9ba..0d90d8e 100644 --- a/docs/recon/COORDINATED-PLAN-2026-10-04.md +++ b/docs/recon/COORDINATED-PLAN-2026-10-04.adoc @@ -1,130 +1,184 @@ -# Coordinated plan — the seven repos, 2026-10-04 += Coordinated plan — the seven repos, 2026-10-04 -**Companion to:** `docs/recon/TYPE-FAMILY-POSITION-2026-10-04.md` (the position) and -`docs/recon/FOLLOWER-NOTES-2026-10-04.md` (consumer outreach). -**Scope:** `echo-types`, `epistemic-types`, `residual-evidence-types`, `choreographic-types`, +_Companion to:_ `docs/recon/TYPE-FAMILY-POSITION-2026-10-04.adoc` (the position) and +the follower-notes working copy (consumer outreach; kept out of the public repo until the messages are sent). +_Scope:_ `echo-types`, `epistemic-types`, `residual-evidence-types`, `choreographic-types`, `tropical-types`, `occupancy-types`, `absolute-zero`, the `nextgen-typing` hub and the satellites. ---- +''' -## 1. The governing idea +== 1. The governing idea The recon found one asymmetry that should drive the whole plan: -> **Most of the estate's claims are already true and already fenced — but a large fraction are -> not *machine-enforced*.** Proof work that exists on disk is unreceipted (no CI lane, no -> toolchain run, no issue), while several workflows that appear to gate it die at startup. +[quote] +____ +**Most of the estate's claims are already true and already fenced — but a large fraction are +not _machine-enforced_.** Proof work that exists on disk is unreceipted (no CI lane, no +toolchain run, no issue), while several workflows that appear to gate it die at startup. +____ -So the plan is not "do more research". It is, in order: **(W1) make what exists checkable**, -**(W2) convert the five cross-family arrows from proposed to checked**, **(W3) time-box the two -open keystones**, **(W4) run the occupancy rungs through their own kill gates**, **(W5) build +So the plan is not "do more research". It is, in order: _(W1) make what exists checkable_, +_(W2) convert the five cross-family arrows from proposed to checked_, **(W3) time-box the two +open keystones*, _(W4) run the occupancy rungs through their own kill gates_, *(W5) build consumers so the work has external standing**. Research ambition is capped deliberately: the -plan's job is to make the boundary between *established* and *open* impossible to misread. +plan's job is to make the boundary between _established_ and _open_ impossible to misread. -### Principles (non-negotiable, because they are the estate's credibility) +=== Principles (non-negotiable, because they are the estate's credibility) -1. **Receipts over claims.** A result is [RAN] (command + output), [CI] (run id + commit), [DOC] - (dated author run), or it is *not established*. Upgrading [DOC]→[CI] is the cheapest work in +. _Receipts over claims._ A result is [RAN] (command + output), [CI] (run id + commit), [DOC] + (dated author run), or it is _not established_. Upgrading [DOC]→[CI] is the cheapest work in the estate and the highest value. -2. **Blocked ≠ retracted.** Blocked items carry the exact command that would unblock them. +. _Blocked ≠ retracted._ Blocked items carry the exact command that would unblock them. Retractions are recorded with the counterexample. Both ledgers already exist — keep using them. -3. **Separation before capability.** Every family's identity rests on matched-negatives or +. _Separation before capability._ Every family's identity rests on matched-negatives or no-go results. A new capability claim without a separation is a naming exercise. -4. **Kill criteria are pre-written and honoured.** occupancy-types §3 has them per rung; +. _Kill criteria are pre-written and honoured._ occupancy-types §3 has them per rung; absolute-zero warns that a too-clean composition result is probably wrong. Obey the ledgers, not the momentum. -5. **No arrow as dependency.** The type-family map's dashed arrows are obligations, not imports. +. _No arrow as dependency._ The type-family map's dashed arrows are obligations, not imports. The one deliberate exception (occupancy's "no cross-kernel imports") stays. ---- +''' -## 2. Workstreams +== 2. Workstreams -### W1 — Make the receipts real (highest leverage, mostly mechanical) +=== W1 — Make the receipts real (highest leverage, mostly mechanical) -| # | Task | Repo | Owner | Closes with | -|---|---|---|---|---| -| W1.1 | Read the Actions posture; if `selected`/short, PUT the canon allow-list; re-run the gates | occupancy-types | **owner-only** | a push where Secret Scanner + Governance + a checker job *start and pass* (issue #6) | -| W1.2 | Wire the Session IR manifest as a CI job (`PYTHONPATH=src python3 -m session_ir test …`, 14/14 today) | occupancy-types | automatable | green job on `main`; regression visible | -| W1.3 | Build `verification/proofs/` in CI (XP‑1 currently unenforced) | nextgen-typing | automatable | green job; issue #57 | -| W1.4 | Extend Isabelle `ROOT` to all 9 theories + add the Isabelle job | tropical-types | needs Isabelle | PROOF-STATUS's "CI-gated" claim becomes true; issue #57 | -| W1.5 | Lane `experimental/echo-additive` + the 4 bit-narrowing modules | echo-types | automatable | modules in `All.agda`/a lane or archived; issues #320/#321 | -| W1.6 | Pin the Agda toolchain (drop unpinned `apt-get agda`) | echo-types | automatable | pinned version in workflow; issue #322 | -| W1.7 | Make CI mirror the local all-provers gate (or say so loudly in CI + README) | absolute-zero | author | issue #161 closed or scoped honestly | -| W1.8 | **Estate-wide: treat `STARTUP_FAILURE` as failure for required checks** (§6.2) | all | owner (settings) | no PR can merge with zero CI signal; echo-types#330 | -| W1.9 | File the missing issue(s) for repos with dead CI and no tracker entry | occupancy-types | done (issue #6) | — | -| W1.10 | Remove tracked `__pycache__` (7 files) + ignore rule | occupancy-types | **done this session** | clean tree | +[cols="1,1,1,1,1",options="header"] +|=== +| # | Task | Repo | Owner | Closes with -**Why first:** W1 costs days, converts a large body of [DOC] into [CI], and — critically — -W1.8 and W1.1 also *unblock* every future automated check. Right now a green badge in this +| W1.1 | Read the Actions posture; if `selected`/short, PUT the canon allow-list; re-run the gates | occupancy-types | _owner-only_ | a push where Secret Scanner + Governance + a checker job _start and pass_ (issue #6) + +| W1.2 | Wire the Session IR manifest as a CI job (`PYTHONPATH=src python3 -m session_ir test …`, 14/14 today) | occupancy-types | automatable | green job on `main`; regression visible + +| W1.3 | Build `verification/proofs/` in CI (XP‑1 currently unenforced) | nextgen-typing | automatable | green job; issue #57 + +| W1.4 | Extend Isabelle `ROOT` to all 9 theories + add the Isabelle job | tropical-types | needs Isabelle | PROOF-STATUS's "CI-gated" claim becomes true; issue #57 + +| W1.5 | Lane `experimental/echo-additive` + the 4 bit-narrowing modules | echo-types | automatable | modules in `All.agda`/a lane or archived; issues #320/#321 + +| W1.6 | Pin the Agda toolchain (drop unpinned `apt-get agda`) | echo-types | automatable | pinned version in workflow; issue #322 + +| W1.7 | Make CI mirror the local all-provers gate (or say so loudly in CI + README) | absolute-zero | author | issue #161 closed or scoped honestly + +| W1.8 | _Estate-wide: treat `STARTUP_FAILURE` as failure for required checks_ (§6.2) | all | owner (settings) | no PR can merge with zero CI signal; echo-types#330 + +| W1.9 | File the missing issue(s) for repos with dead CI and no tracker entry | occupancy-types | done (issue #6) | — + +| W1.10 | Remove tracked `__pycache__` (7 files) + ignore rule | occupancy-types | _done this session_ | clean tree + +|=== + +_Why first:_ W1 costs days, converts a large body of [DOC] into [CI], and — critically — +W1.8 and W1.1 also _unblock_ every future automated check. Right now a green badge in this estate is not evidence that anything ran. -### W2 — Mature the interfaces (the five arrows) +=== W2 — Mature the interfaces (the five arrows) The hub's `TYPE-CONNECTIONS.adoc` lists what each connection needs. Current state, from the -recon: Echo→Residual and Epistemic→Residual cover **Milestone 1 only**; Echo→Choreographic and -Epistemic→Choreographic have **no proof**; Tropical→Choreographic needs a grading semantics. - -| # | Task | Repo | Closes with | -|---|---|---|---| -| W2.1 | Comparisons 2.0: do composition (`compose-claims`) and revision (`survives-retraction`, `revise`) transport beyond `Echo.Echo` / `SoundWarrant`? | residual-evidence-types | a checked answer either way — *"no, a richer interface is needed"* is a publishable result | -| W2.2 | **Cost vs state as a separation**: exhibit a composition where the HWM grade and the cost grade cannot be identified | occupancy + tropical | a witness pair + a no-identification theorem (cheap, falsifiable, cross-family) | -| W2.3 | Projection model + correspondence theorem for the echo loss-grade on a projection | echo ↔ choreographic | a stated projection with a proved commuting square (two-event case first) | -| W2.4 | `K-CUT-WARRANT` statement with side conditions (`SoundWarrant` receiver-local) — *state it precisely before proving it* | epistemic ↔ choreographic | a written statement + its side conditions, reviewed | -| W2.5 | Grading semantics for bounds under interaction (declared algebra, not a port) | tropical ↔ choreographic | a semantics + a projection theorem, or a documented negative | -| W2.6 | Reconcile the choreographic "echo loss-grade" vocabulary with the shared glossary (index ≠ measure ≠ grade) | choreographic + hub | README/glossary agreement; hub roadmap item closed | -| W2.7 | Refresh stale STATE files against their own PROOF-STATUS | residual-evidence, tropical, absolute-zero | a state file that does not contradict the receipts | - -**W2.2 is the sleeper.** The estate's central architectural claim is that cost and state are -different axes; both halves already exist in separate repos; and the claim is a *separation*, +recon: Echo→Residual and Epistemic→Residual cover _Milestone 1 only_; Echo→Choreographic and +Epistemic→Choreographic have _no proof_; Tropical→Choreographic needs a grading semantics. + +[cols="1,1,1,1",options="header"] +|=== +| # | Task | Repo | Closes with + +| W2.1 | Comparisons 2.0: do composition (`compose-claims`) and revision (`survives-retraction`, `revise`) transport beyond `Echo.Echo` / `SoundWarrant`? | residual-evidence-types | a checked answer either way — _"no, a richer interface is needed"_ is a publishable result + +| W2.2 | _Cost vs state as a separation_: exhibit a composition where the HWM grade and the cost grade cannot be identified | occupancy + tropical | a witness pair + a no-identification theorem (cheap, falsifiable, cross-family) + +| W2.3 | Projection model + correspondence theorem for the echo loss-grade on a projection | echo ↔ choreographic | a stated projection with a proved commuting square (two-event case first) + +| W2.4 | `K-CUT-WARRANT` statement with side conditions (`SoundWarrant` receiver-local) — _state it precisely before proving it_ | epistemic ↔ choreographic | a written statement + its side conditions, reviewed + +| W2.5 | Grading semantics for bounds under interaction (declared algebra, not a port) | tropical ↔ choreographic | a semantics + a projection theorem, or a documented negative + +| W2.6 | Reconcile the choreographic "echo loss-grade" vocabulary with the shared glossary (index ≠ measure ≠ grade) | choreographic + hub | README/glossary agreement; hub roadmap item closed + +| W2.7 | Refresh stale STATE files against their own PROOF-STATUS | residual-evidence, tropical, absolute-zero | a state file that does not contradict the receipts + +|=== + +_W2.2 is the sleeper._ The estate's central architectural claim is that cost and state are +different axes; both halves already exist in separate repos; and the claim is a _separation_, which means it is cheap to make and cheap to falsify. If it fails, that is important news for occupancy's thesis. It should be done early. -### W3 — Keystones, time-boxed and pre-falsified +=== W3 — Keystones, time-boxed and pre-falsified + +[cols="1,1,1,1,1",options="header"] +|=== +| # | Task | Repo | Time box | Kill / honest outcome + +| W3.1 | Two-event K-CUT-LOSS square under `Independent₂` | choreographic | 1–2 sessions | if `Independent₂` needs hypotheses that trivialise it, record that + +| W3.2 | A _second, non-degenerate_ projection pattern | choreographic | after W3.1 | if degeneracy is incidental, K-CUT gains standing; if essential, the assembly hypothesis narrows honestly + +| W3.3 | Bachmann–Howard `ψ₀(Ω_ω)` fidelity (Lane 3, retired from echo-types) | echo-types | multi-session frontier | remains OPEN by D-2026-06-14; the 2 Fidelity postulates are the only ones in the tree -| # | Task | Repo | Time box | Kill / honest outcome | -|---|---|---|---|---| -| W3.1 | Two-event K-CUT-LOSS square under `Independent₂` | choreographic | 1–2 sessions | if `Independent₂` needs hypotheses that trivialise it, record that | -| W3.2 | A **second, non-degenerate** projection pattern | choreographic | after W3.1 | if degeneracy is incidental, K-CUT gains standing; if essential, the assembly hypothesis narrows honestly | -| W3.3 | Bachmann–Howard `ψ₀(Ω_ω)` fidelity (Lane 3, retired from echo-types) | echo-types | multi-session frontier | remains OPEN by D-2026-06-14; the 2 Fidelity postulates are the only ones in the tree | -| W3.4 | OND-6 conditional composition | absolute-zero | research-grade, last | the roadmap already warns a too-clean positive result has dropped a term | -| W3.5 | Kernel-certificate / guardrail re-check after any W3.3 movement | echo-types | per change | `Smoke.agda` + `All.agda` + guardrails green | +| W3.4 | OND-6 conditional composition | absolute-zero | research-grade, last | the roadmap already warns a too-clean positive result has dropped a term -**Rule for W3:** nothing here is allowed to block W1/W2, and every item ships a written negative +| W3.5 | Kernel-certificate / guardrail re-check after any W3.3 movement | echo-types | per change | `Smoke.agda` + `All.agda` + guardrails green + +|=== + +_Rule for W3:_ nothing here is allowed to block W1/W2, and every item ships a written negative outcome. Lane 3 was already retired once from echo-types for outgrowing the project — that precedent is the model. -### W4 — Run the occupancy rungs through their own gates +=== W4 — Run the occupancy rungs through their own gates + +[cols="1,1,1,1",options="header"] +|=== +| # | Task | Blocked on | Then + +| W4.1 | Idris 2 Occupancy spike: `idris2 --check Occ.idr` + `Demo.idr` + 4 rejection controls; answer the kill question (constant grades tolerable _and tight_?) | `idris2` installed | R0‑B Piece 2 closes or the kill criterion fires + +| W4.2 | stackcert: `lean StackcertCore.lean`, `#print axioms cert_sound`, fixture run + 4 negative controls | `lean`/`lake` installed | replaces the CONJECTURE with a pasted axiom footprint + +| W4.3 | Zephyr painted-stack HWM fixture on `qemu_cortex_m3` | `west` + QEMU + Zephyr SDK | R1's ground-truth protocol can run: measured ≤ certified + +| W4.4 | R2 static pools + affine/linear handles, T1 coherence theorem | W4.1–W4.3 | _project gate_: no external consumer + no theorem beyond restatement ⇒ archive with a ledger entry -| # | Task | Blocked on | Then | -|---|---|---|---| -| W4.1 | Idris 2 Occupancy spike: `idris2 --check Occ.idr` + `Demo.idr` + 4 rejection controls; answer the kill question (constant grades tolerable **and tight**?) | `idris2` installed | R0‑B Piece 2 closes or the kill criterion fires | -| W4.2 | stackcert: `lean StackcertCore.lean`, `#print axioms cert_sound`, fixture run + 4 negative controls | `lean`/`lake` installed | replaces the CONJECTURE with a pasted axiom footprint | -| W4.3 | Zephyr painted-stack HWM fixture on `qemu_cortex_m3` | `west` + QEMU + Zephyr SDK | R1's ground-truth protocol can run: measured ≤ certified | -| W4.4 | R2 static pools + affine/linear handles, T1 coherence theorem | W4.1–W4.3 | **project gate**: no external consumer + no theorem beyond restatement ⇒ archive with a ledger entry | -| W4.5 | Phase‑2 "protocol cut = reclaim" (live memory = f(protocol shape)) | R2 | compositional advantage demonstrated, or kill | +| W4.5 | Phase‑2 "protocol cut = reclaim" (live memory = f(protocol shape)) | R2 | compositional advantage demonstrated, or kill -**This is the only workstream with a project-level stop written into it.** Treat W4.4 as the +|=== + +_This is the only workstream with a project-level stop written into it._ Treat W4.4 as the real decision point and do not let it drift into R3/R4/R5 by inertia. -### W5 — Consumers and external standing +=== W5 — Consumers and external standing + +[cols="1,1,1",options="header"] +|=== +| # | Task | Closes with + +| W5.1 | Sign + re-anchor the per-repo AFFIRMATIONs at main (nextgen-typing#69) | dated, GPG-signed receipts at current SHAs + +| W5.2 | Register occupancy-types in the hub's type map (question, boundary, connections) — hub#118 | map row + vocabulary fence + +| W5.3 | Re-cite the residual receipts and give Echo→Residual / Epistemic→Residual acceptance criteria (hub#115) | guide updated with acceptance criteria + +| W5.4 | Mirror the general `EchoAggregation` into EchoTypes.jl (echo-types#280) | finite-domain falsifier covers the general law -| # | Task | Closes with | -|---|---|---| -| W5.1 | Sign + re-anchor the per-repo AFFIRMATIONs at main (nextgen-typing#69) | dated, GPG-signed receipts at current SHAs | -| W5.2 | Register occupancy-types in the hub's type map (question, boundary, connections) — hub#118 | map row + vocabulary fence | -| W5.3 | Re-cite the residual receipts and give Echo→Residual / Epistemic→Residual acceptance criteria (hub#115) | guide updated with acceptance criteria | -| W5.4 | Mirror the general `EchoAggregation` into EchoTypes.jl (echo-types#280) | finite-domain falsifier covers the general law | -| W5.5 | Clear the Pillar E offline half: packaging, DOI, submission | paper submitted (author-driven) | -| W5.6 | absolute-zero artifact-evaluation package (one-command container) | reviewer can reproduce `ALL-PROVERS-GREEN` | -| W5.7 | Follower outreach (see the companion notes file) | replies → real consumers; keeps the estate honest about who actually uses this | -| W5.8 | A public artefact over the outreach: "what a projection/receipt/bound problem looks like, four worked examples" | citable, reaches the same audience without 269 DMs | +| W5.5 | Clear the Pillar E offline half: packaging, DOI, submission | paper submitted (author-driven) ---- +| W5.6 | absolute-zero artifact-evaluation package (one-command container) | reviewer can reproduce `ALL-PROVERS-GREEN` -## 3. Dependencies +| W5.7 | Follower outreach (see the companion notes file) | replies → real consumers; keeps the estate honest about who actually uses this -``` +| W5.8 | A public artefact over the outreach: "what a projection/receipt/bound problem looks like, four worked examples" | citable, reaches the same audience without 269 DMs + +|=== + +''' + +== 3. Dependencies + +[source] +---- W1.8 (treat STARTUP_FAILURE as failure) ──► makes every other gate trustworthy W1.1 (occupancy Actions posture) ──► W1.2, W4.* receipts toolchains (idris2 / lean / zephyr) ──► W4.1 ─► W4.2/W4.3 ─► W4.4 (project gate) @@ -132,102 +186,107 @@ W2.1 (interfaces beyond M1) ──► W2.3, W2.4, W2.5 (three of W2.2 (cost vs state separation) ──► independent; strengthens or breaks occupancy's thesis W3.* (keystones) ──► must NOT block anything in W1/W2 W5.1/W5.2 (receipts + registration) ──► prerequisite for W5.5, W5.7 credibility -``` +---- -Two structural notes: **(a)** W1.8 is a single settings decision with estate-wide leverage — -it belongs in the first hour. **(b)** The three arrows that depend on W2.1 mean the residual +Two structural notes: _(a)_ W1.8 is a single settings decision with estate-wide leverage — +it belongs in the first hour. _(b)_ The three arrows that depend on W2.1 mean the residual repo's next question is worth more than its apparent size: it is the hinge for half the map. ---- +''' -## 4. Sequence +== 4. Sequence -**Horizon 1 — this week (all mechanical, no research):** W1.8, W1.1, W1.2, W1.3, W1.10 (done), +_Horizon 1 — this week (all mechanical, no research):_ W1.8, W1.1, W1.2, W1.3, W1.10 (done), W1.4, W1.6, W1.7; W2.7 (state files); W5.1, W5.2. *Outcome: every existing proof claim that can be receipted is receipted; no green badge is false.* -**Horizon 2 — the quarter (interfaces + the rungs that can run now):** W2.1, W2.2, W2.6; +_Horizon 2 — the quarter (interfaces + the rungs that can run now):_ W2.1, W2.2, W2.6; W4.1, W4.2, W4.3; W3.1, W3.2; W1.5. *Outcome: the five arrows either checked or honestly narrowed; occupancy past R1 with ground truth; K-CUT either advanced one non-degenerate step or falsified at the two-event scale.* -**Horizon 3 — beyond (research + external):** W3.3, W3.4; W4.4 decision, then R3–R5; W2.3–W2.5; +_Horizon 3 — beyond (research + external):_ W3.3, W3.4; W4.4 decision, then R3–R5; W2.3–W2.5; W5.4–W5.6; W5.7/W5.8. *Outcome: external standing, or an honest narrowing — the estate's own decision policy on the identity claim (echo-types' roadmap: *"if it is refuted, narrow honestly… or stop the identity -claim and retain the suite as Agda exposition"*).* +claim and retain the suite as Agda exposition"_)._ ---- +''' -## 5. What this plan refuses to do +== 5. What this plan refuses to do -* **No cross-kernel imports.** occupancy's ULTRAPLAN §1.2 is permanent: not dependent on K-CUT, +* _No cross-kernel imports._ occupancy's ULTRAPLAN §1.2 is permanent: not dependent on K-CUT, Echo, epistemic or secret types. The map is vocabulary, not a build graph. -* **No new surface language before a certificate checker has a user** (occupancy non-goal). -* **No capability claim without a separation** (echo-types' gate discipline). -* **No "one more prover" for absolute-zero before CI mirrors the gate it already has.** -* **No 269-message outreach.** Narrow, falsifiable, per-person hints only — the alternative is +* _No new surface language before a certificate checker has a user_ (occupancy non-goal). +* _No capability claim without a separation_ (echo-types' gate discipline). +* _No "one more prover" for absolute-zero before CI mirrors the gate it already has._ +* _No 269-message outreach._ Narrow, falsifiable, per-person hints only — the alternative is noise with a reputational bill. -* **No treating a conceptual arrow as a dependency, an equivalence, or a theorem.** +* _No treating a conceptual arrow as a dependency, an equivalence, or a theorem._ ---- +''' -## 6. Measurement discipline — how to read a pass rate +== 6. Measurement discipline — how to read a pass rate *Added 2026-10-04, after the recon. Every figure below was measured that day from the Actions API — never from a badge.* -### 6.1 Two ratios, never one +=== 6.1 Two ratios, never one A single "pass rate" is ambiguous in a way that flatters a broken pipeline: a run that never executed is still a run, so 96 non-executions read as "96% failing" — and when the gate that -never starts is the one that would have failed, a disarmed repo can read **green**. Split it: +never starts is the one that would have failed, a disarmed repo can read _green_. Split it: + +[cols="1,1,1,1",options="header"] +|=== +| Ratio | Definition | Measured 2026-10-04 | Target + +| _R1 · executed / required_ | required checks that produced at least one job | _~0/100_ in occupancy-types; _≈100%_ in the five repos whose proof jobs run | _100%_ -| Ratio | Definition | Measured 2026-10-04 | Target | -|---|---|---|---| -| **R1 · executed / required** | required checks that produced at least one job | **~0/100** in occupancy-types; **≈100%** in the five repos whose proof jobs run | **100%** | -| **R2 · passed / executed** | executed checks ending in success | **≈100%** in every proof lane measured — epistemic 21/21, residual 39/39, tropical Lean 13/13, absolute-zero Proofs 5/5, echo-types green at HEAD | **100%** for proof lanes; **no threshold** for tightness (6.4) | +| _R2 · passed / executed_ | executed checks ending in success | _≈100%_ in every proof lane measured — epistemic 21/21, residual 39/39, tropical Lean 13/13, absolute-zero Proofs 5/5, echo-types green at HEAD | _100%_ for proof lanes; _no threshold_ for tightness (6.4) + +|=== The occupancy-types figure in full: of the last 100 runs, 96 `startup_failure`, 3 `failure`, -1 `success` — and **exactly 4 runs had any job at all**, all four being dependency-graph +1 `success` — and _exactly 4 runs had any job at all_, all four being dependency-graph "Update" workflows (pip, hex, npm_and_yarn, github_actions). No gate in that repository has ever executed a single job. -**Rule: report R1 before R2.** A pass rate quoted without its execution rate is not a +_Rule: report R1 before R2._ A pass rate quoted without its execution rate is not a measurement — and a "100% pass" over 0 executed checks is precisely what a dead pipeline looks like. -### 6.2 Green must mean executed +=== 6.2 Green must mean executed A green tick is evidence only if a job ran. Enforce three things: -* **`STARTUP_FAILURE` counts as failure** for every required context, and so does a required +* _`STARTUP_FAILURE` counts as failure_ for every required context, and so does a required context that reports no jobs (W1.8; the recommendation in echo-types#330). -* **Every receipt names a run id and a commit.** `[CI]` in the estate's tagging means "a job +* _Every receipt names a run id and a commit._ `[CI]` in the estate's tagging means "a job started and passed", never "a workflow is listed". -* **Prefer a revoked badge to a stale one.** A repo whose gates cannot run should say so in the +* _Prefer a revoked badge to a stale one._ A repo whose gates cannot run should say so in the README rather than display workflow badges that no longer execute — the badge is the single most misleading artefact in a disarmed pipeline. -### 6.3 Proof lanes carry zero flake tolerance +=== 6.3 Proof lanes carry zero flake tolerance Proof checking is deterministic: same toolchain, same inputs, same verdict. There is no -legitimate "sometimes" for `agda All.agda`. A proof lane's expectation is **100%**, and any +legitimate "sometimes" for `agda All.agda`. A proof lane's expectation is _100%_, and any deviation is a bug in the pipeline or the environment — never noise to budget for. What the estate's own record shows (last 100 runs per repo, 2026-10-04): every prover red in the window had a cause — -* **real breakage** — echo-types' Agda lane on 2026-09-27 (`39a7a99c`) and 2026-09-30 +* _real breakage_ — echo-types' Agda lane on 2026-09-27 (`39a7a99c`) and 2026-09-30 (`f11031f2`), the "Typecheck full suite" step failing: main was genuinely broken, then fixed. The cold-check step (`--ignore-interfaces`, no cache) failed in the same runs; -* **supersede** — a concurrency `cancel` (absolute-zero `Proofs` `27d879f5`; echo-types Agda +* _supersede_ — a concurrency `cancel` (absolute-zero `Proofs` `27d879f5`; echo-types Agda `36919959218`); -* **infrastructure** — the `startup_failure` family. +* _infrastructure_ — the `startup_failure` family. -**No case of the same commit passing and failing at random was found.** That distinction is the -point: *flakiness* trains a team to re-run until green and is the thing to hunt; a +_No case of the same commit passing and failing at random was found._ That distinction is the +point: _flakiness_ trains a team to re-run until green and is the thing to hunt; a red-with-a-cause is a bug report carrying a file and a line number, and it is the system working. The one real drift risk is the environment, and it is documented: echo-types#322 — @@ -235,66 +294,74 @@ The one real drift risk is the environment, and it is documented: echo-types#322 change without a commit*. Pin the toolchain (W1.6) and keep the guardrails already in place: `--safe --without-K`, the postulate/escape greps, the `Smoke.agda` pins, the kernel certificate. -### 6.4 Tightness is a distribution, not a gate +=== 6.4 Tightness is a distribution, not a gate Keep the asymmetry ULTRAPLAN §6 already states: -* **Soundness** — *"measured ≤ certified on every run. Violation = stop + ledger entry"* → - **100%, zero tolerance**. This is a correctness property, not a benchmark. -* **Tightness** — *"certified/measured per unit; report distribution"* → **not pass/fail**. +* _Soundness_ — _"measured ≤ certified on every run. Violation = stop + ledger entry"_ → + _100%, zero tolerance_. This is a correctness property, not a benchmark. +* _Tightness_ — _"certified/measured per unit; report distribution"_ → _not pass/fail_. Do not turn tightness into a threshold. A limit loose enough never to fire is decoration; one tight enough to fire on measurement noise teaches everyone to ignore red — exactly the failure mode 6.3 exists to prevent. Report the distribution, watch it move, and act on trends with a named cause. -Also note the current state: **nothing has been measured yet.** The Zephyr painted-stack fixture +Also note the current state: _nothing has been measured yet._ The Zephyr painted-stack fixture (W4.3) is still a fixture request, so R1 ground truth does not exist. "Benchmarks occasionally drift" is not the situation; "no benchmark has ever run" is. Retries are permitted for genuinely non-deterministic infrastructure — package/action downloads, -superseded runs, cancelled fuzz batches — and are **never** permitted to produce a green verdict +superseded runs, cancelled fuzz batches — and are _never_ permitted to produce a green verdict on a claim that was not checked. Blocked ≠ retracted; blocked ≠ passed. -### 6.5 Three kinds of red, three responses +=== 6.5 Three kinds of red, three responses + +[cols="1,1,1",options="header"] +|=== +| Kind | Signature | Response + +| _Real breakage_ | job ran; a named step failed | Fix or revert; the run id goes in the ledger entry -| Kind | Signature | Response | -|---|---|---| -| **Real breakage** | job ran; a named step failed | Fix or revert; the run id goes in the ledger entry | -| **Environment / infrastructure** | job never started, or a dependency fetch failed | Fix the cause (pin, allow-list, retry policy) and file it; never re-run to green | -| **Supersede / cancel** | `cancelled`; a newer run exists on the same ref | Nothing — but confirm a later run executed | +| _Environment / infrastructure_ | job never started, or a dependency fetch failed | Fix the cause (pin, allow-list, retry policy) and file it; never re-run to green -### 6.6 Recompute it +| _Supersede / cancel_ | `cancelled`; a newer run exists on the same ref | Nothing — but confirm a later run executed -```bash +|=== + +=== 6.6 Recompute it + +[source,bash] +---- # R1/R2 inputs for a repo — conclusions, from the API, not badges gh api "repos/hyperpolymath/occupancy-types/actions/runs?per_page=100" \ --jq '[.workflow_runs[].conclusion] | group_by(.) | map({(.[0]): length}) | add' # R1 precisely: did a run actually execute any job? gh api "repos/hyperpolymath/occupancy-types/actions/runs//jobs" --jq '.total_count' -``` +---- ---- +''' -## 7. How to tell whether the plan worked +== 7. How to tell whether the plan worked -*Measure everything below with §6's ratios: **R1 before R2**, and green-means-executed.* +*Measure everything below with §6's ratios: _R1 before R2_, and green-means-executed.* Falsifiable, in order of cheapness: -1. **`STARTUP_FAILURE` cannot masquerade as green** in any estate repo (W1.8). Check: force a +. _`STARTUP_FAILURE` cannot masquerade as green_ in any estate repo (W1.8). Check: force a failing workflow and confirm it blocks; check that a required context that never starts reports failure. -2. **Every "[DOC] verified" line in PROOF-STATUS has a corresponding green run id**, or is +. _Every "[DOC] verified" line in PROOF-STATUS has a corresponding green run id_, or is explicitly marked as not CI-covered. Check: grep the PROOF-STATUS files against the Actions API. -3. **The cost/state separation is settled either way** (W2.2) — a witness + no-identification +. _The cost/state separation is settled either way_ (W2.2) — a witness + no-identification theorem, or a documented collision that narrows occupancy's thesis. -4. **K-CUT is either non-degenerate-advancing or honestly narrowed** to what a two-event square +. _K-CUT is either non-degenerate-advancing or honestly narrowed_ to what a two-event square can support (W3.1/W3.2), with the degenerate case's status written down. -5. **At least one external consumer** exists for one artefact (W5.5–W5.8), or the R2 project - gate fires and occupancy is archived with a ledger entry — which is a *success* under its +. _At least one external consumer_ exists for one artefact (W5.5–W5.8), or the R2 project + gate fires and occupancy is archived with a ledger entry — which is a _success_ under its own rules. -6. **No state file contradicts its repo's receipts** (W2.7). This is the cheapest measure of +. _No state file contradicts its repo's receipts_ (W2.7). This is the cheapest measure of estate coherence, and today three fail it. + diff --git a/docs/recon/FOLLOWER-NOTES-2026-10-04.md b/docs/recon/FOLLOWER-NOTES-2026-10-04.md deleted file mode 100644 index 61393ac..0000000 --- a/docs/recon/FOLLOWER-NOTES-2026-10-04.md +++ /dev/null @@ -1,1045 +0,0 @@ -# Follower notes — bespoke drafts - -**Prepared:** 2026-10-04 · **For:** `@hyperpolymath` · **Status:** drafts only — *nothing has been sent* - ---- - -## 0. Scope, method, and what is honest to say about coverage - -**The arithmetic.** You follow 269 accounts. I pulled the follower list (269), fetched full -profiles and most-recent non-fork repos for 225 of them, and qualified **188 as active** -(≤180 days since last push). Language breakdown of the active set: 41 Python, 24 JavaScript, -15 TypeScript, 8 HTML, 6 PHP, 5 Rust, 4 Shell/4 CSS, then singles — 64 have no substantive -public code at all (profile READMEs, config repos, GIF-only repos). - -**What I read for the notes below.** I cloned and read the actual source of the code I -referenced — files, comments and commit subjects — not just descriptions. Every note pins a -specific file and a specific recent commit or line, so the hint lands somewhere real. - -**What I did *not* do.** I did not write 269 notes. Of the 188 active accounts, roughly -**35–50 have public code with a visible struggle** that one of your artefacts genuinely -addresses; the rest are profile-only, inactive, or have nothing I could hook to without -inventing relevance — and inventing it would damage exactly the credibility these notes are -meant to build. Twelve deep notes and two shorter ones are below; §4 lists the near-miss set -I can work through next, and §5 is the full triage. - -**Voice.** Written in your voice, first person, short, no pitch. Each one: *what I read → -the struggle I saw → one thing from the estate → the smallest concrete first step → an offer*. -Rationale lines are for you and should **not** be sent. - -**Two rules I held to.** (1) No claim about an estate artefact stronger than its own -PROOF-STATUS allows — prototypes are called prototypes, open keystones are called open. -(2) No "you should use X" — only "here is the shape of your problem and the shape of this -artefact; the match is yours to judge." - ---- - -## 1. Tier 1 — deep notes (code read) - -### 1.1 @barissozudogru — `gha-cost` - -**What he is building.** A TypeScript estimator for GitHub Actions costs, parsed from -workflow YAML. Its most recent six commits (all 2026-10-04) are robustness fixes: ignoring -overflowing push-rate values, rejecting non-finite self-hosted rates, honouring a zero push -frequency, counting valid cron day/month pairs. - -**The struggle.** He documented it himself, in `src/index.ts`: - -> *"Measured across 80 real steps from three repositories, the distribution is bimodal rather -> than merely mis-centred… **No single value describes that, so a point estimate is false -> precision no matter which value is chosen.**"* - -So he estimates a *range* per step — and then has to compose ranges: `+` down a sequence of -steps, `max` across matrix branches, multiply by run frequency. That is an algebra he is -using without having declared it, which is precisely where his last six commits were spent -(input-validation patches to keep ill-formed numbers out of the composition). - -**The hook — `tropical-types`.** The repo's whole thesis is: *a declared resource algebra -supplies operations and laws; max-plus combines alternatives with `max` and sequential costs -with `+`; the algebra and cost semantics must be stated.* Its Lean 4 development -(`Resource/Algebra/Interface` + `ParametricLaws`, with `MaxPlus`/`MinPlus`/`MinMax` instances, -no Mathlib, CI green) is exactly the interface for "compose worst-case bounds and know which -laws you used". His ranges additionally make a *conditional* assumption (low-end = warm cache) -that max-plus does not — naming that as "where the law fails" is the useful part. - -**A second, sharper hook from your own estate.** This morning's recon measured -`occupancy-types` at **96 of its last 100 workflow runs ending `startup_failure`** — no jobs -created, no minutes billed, no gate executed — while the runs list still shows workflows -"passing" elsewhere in the estate. His estimator prices those runs as if they executed. A -`startup_failure`/zero-job run is a *null run*: it bills nothing and verifies nothing, so -recording it as a normal run is the same class of error as billing a skipped job. He has the -perfect tool to co-sign the finding and a natural feature ("null-run detector + a residue list -of what the estimator cannot see"). - -**Copy-paste message** - -> Hi — I read `gha-cost` this week, and the comment in `src/index.ts` about the bimodal step -> distribution stuck with me: *"a point estimate is false precision no matter which value is -> chosen."* That is the right instinct, and I think the piece you are missing has a name. -> -> Once you estimate ranges, you are doing algebra over them — `+` along a step sequence, `max` -> across matrix branches, scaling by run frequency. I have a small Lean 4 development -> (`tropical-types`) whose entire purpose is making that algebra explicit: a resource-grade -> interface with a parametric transport theorem and concrete max-plus/min-plus/min-max -> instances, no Mathlib, green in CI. It would let you *state* which law your estimator relies -> on at each composition point — and where your "warm cache" weighting quietly breaks it. -> -> One concrete thing you can use immediately from outside the algebra: I measured a repository -> where 96 of 100 recent runs ended `startup_failure` — zero jobs, zero minutes billed, and no -> gate actually executed. Your estimator would price those runs as if they ran. A "null run" -> detector (zero jobs ⇒ zero cost) plus a short residue list of what the estimate cannot see -> (self-hosted, cache hits, early aborts) would be a real accuracy gain, and it is a -> falsifiable claim rather than a heuristic. -> -> Happy to point you at the interface file if useful — no obligation. - -*Rationale (not for sending): he is one of the few followers whose repo is a direct consumer -of a family member. The null-run finding also gives him something **from** your work rather -than only a request, which is the right way round.* - ---- - -### 1.2 @sdiehl — `groebner` - -**What he is building.** An optimised Rust implementation of F4 and Buchberger for Gröbner -bases — parallel sparse linear algebra, SIMD row reduction, multi-modular rational -reconstruction. `TODO.md` shows the algorithm programme: F5 for large systems is the open box; -Gebauer–Möller, sugar strategy, incremental updates are done. - -**The struggle.** `src/grebauer_moller.rs` implements the B, M and F criteria — i.e. it -*deletes* critical pairs that cannot contribute. The comments state the criteria as -conditions on lcms (`"Remove pairs (i,j) if lcm(i,j) is divisible by lcm(i,k) for some k ≠ j"`) -but the code carries no statement of *why deletion is safe* — no retained witness that the -basis is still complete. That is the classic place where a criterion is "well known" and -therefore anyone's regression is invisible until a benchmark disagrees. - -**The hook — `echo-types`.** Its subject is irreversible maps where the fibre over each output -retains a *proof-relevant constraint on what was lost*: `Echo f y = Σ (x : A), f x ≡ y`. A -redundancy criterion is exactly this: you lose pairs (information loss) but must retain enough -to certify that no basis element was missed (the witness). Two pieces map directly: - -* the **loss taxonomy × residue shapes** — a vocabulary for *which* distinctions a criterion - discards and which it must keep, so "safe" becomes a stated obligation rather than folklore; -* the **matched-negative discipline** — the estate's rule that a claim earns standing by - proving what it is *not* (here: exhibiting the witness function that would fail if the - criterion were wrong), which is the natural shape of an F5 signature argument. - -F5 is the natural first customer: signatures are retention-by-construction, so the design -question is literally *what must be retained for the reduction to remain certifying*. - -**Copy-paste message** - -> I spent some time in `groebner` this week — the F4/F5 work and the Gebauer–Möller filter in -> particular. Your `grebauer_moller.rs` states the B/M/F criteria crisply, and what I noticed -> is that the *reason* each deletion is safe lives in the literature rather than in the code: -> the pairs are dropped, but no witness is kept that says the basis is still complete. -> -> I have an Agda development (`echo-types`) whose subject is exactly this shape — irreversible -> maps where the fibre over each output retains a proof-relevant constraint on what was lost, -> with a mechanised taxonomy of loss kinds and residue shapes. Read one way, a redundancy -> criterion *is* such a map: you discard pairs, and the obligation is to retain enough to -> certify nothing was missed. The discipline I found useful is to make the retained witness an -> explicit object, so "safe" is a theorem-shaped statement instead of folklore — and so a -> regression shows up as a failed witness rather than a benchmark disagreement. -> -> For F5 specifically, signatures are retention-by-construction, so the design question becomes -> *what must be kept for the reduction to stay certifying*. If that framing is useful, the loss -> taxonomy and the matched-negative pattern are the two parts I would start from — I can send -> pointers rather than a pitch. - -*Rationale (not for sending): he is a known Haskell/compiler-adjacent figure; treat it as a -peer exchange, not outreach. Highest credibility-per-word note in the set — the framing is -genuinely load-bearing for F5 and costs him nothing to consider.* - ---- - -### 1.3 @Teagar — `crawl-online` - -**What he is building.** A host-authoritative multiplayer mod for *Crawl* (Unity 5.4 / Mono -2.35 / BepInEx 5.4.11), with a Steam lobby, a versioned capability handshake, per-slot -monotonic input/snapshot sequences, bounded correction history, and a clean-room -`SessionProtocolEngine` driven by an in-process `HeadlessSessionHarness`. - -**The struggle — and it is two struggles, both documented in `memory.md`.** - -1. **The projection problem.** *"Delayed-input lockstep is rejected by a clean trace-v2 - experiment: with symmetric quantized input, exact and quantized critical state diverged - from the first checkpoint at frame 30"* — 19,380 frames, 36,574 inputs, 517 checkpoints, - and every hash diverged from frame 30 without a harness exception. Quantisation is a - non-injective map, and the divergence is a statement about *which distinctions survive it*. -2. **The live one.** His last six commits are all menu focus: *"fix: synchronize native menu - visual selection"*, *"diagnostics: inspect native menu focus contracts"*, *"trace bounded - native menu focus state"*, *"fix: reapply native menu focus after reconstruction"* — with - new files `MenuFocusContract.cs`, `NativeMenuSelectionPlan.cs`, - `BoundedMenuFocusObservation.cs`. He is chasing a case where the *logical* selection and the - *rendered* selection come apart under reconstruction. - -**The hook — `choreographic-types` (plus two others).** *Choreographic types* asks: when a -global interaction protocol is projected to local participants, what happens to retained -distinctions, resource bounds and warrants? The keystone (K-CUT) is a conjecture — open — but -the *specification* is the useful artefact here: name the global protocol, name the projection, -state which distinctions must survive it, and state the cut (consistent frontier) at which the -comparison is made. His checkpoint divergence at frame 30 is a cut-consistency failure with a -reproducible witness; the two-event square in `applications/rapidnj-two-thread.agda` is a -worked *shape* for the smallest such claim. - -Two smaller matches inside the same repo: - -* **`occupancy-types`** — "bounded per-peer correction history" and his monotonic operation - *generations* are an occupancy grade and an epoch. The plan's Phase-2 claim is that - *reclamation is a function of protocol shape, not GC*: when a session generation ends - (BACK/leave), every buffer owned by that generation is dead. He already implements this by - hand; the HWM monoid `(p₁,n₁)·(p₂,n₂) = (max(p₁, n₁+p₂), n₁+n₂)` is the composable form. -* **`epistemic-types`** — his `memory.md` is scrupulous in exactly the estate's way: - *"This is protocol evidence only, not Steam or native-Windows validation"*, *"build evidence - only, never substitutes for native Windows execution"*. That distinction has a minimal typed - interface (`Warrant` vs `SoundWarrant`, `BeliefModality` vs `FactiveModality`) and a pattern - of *expected-rejection fixtures* — evidence that cannot silently be promoted to proof. - -**Copy-paste message** - -> I read your `memory.md` and the recent menu-focus work this week. Two things struck me. -> -> First, *"with symmetric quantized input, exact and quantized critical state diverged from the -> first checkpoint at frame 30"* is one of the cleanest statements of a projection problem I -> have seen in a game codebase: quantisation is a non-injective map, and the experiment is -> really asking which distinctions have to survive it. I have a research notebook -> (`choreographic-types`) that exists for exactly that question — a global protocol read as a -> partial order, projected to participants, with the claim stated at a *cut* (a consistent -> frontier). Its keystone is open, so I am not offering you a theorem; I am offering the -> vocabulary and a worked two-event commuting square as the shape of the smallest claim you -> could make about your own trace. -> -> Second, the focus work: `MenuFocusContract.cs` and `NativeMenuSelectionPlan.cs` are chasing -> the case where logical selection and rendered selection come apart after reconstruction. -> That is the same question — which distinctions must the projection retain — at UI scale, and -> your bounded focus state is already the right kind of object. -> -> One smaller note: your bounded per-peer correction history and your monotonic operation -> generations are an occupancy grade and an epoch. I keep a small calculus (`occupancy-types`) -> whose whole point is that reclamation is a function of protocol shape rather than GC — when a -> generation ends, everything it owned is dead. You are already implementing it by hand; the -> high-water-mark monoid is the composable form. -> -> And one compliment worth stating: *"protocol evidence only, not Steam or native-Windows -> validation"* is the exact discipline most projects lack. I have a minimal typed interface for -> that distinction (a warrant versus a *sound* warrant) plus a fixture pattern that stops -> evidence being silently promoted to proof — happy to share if it is ever useful. - -*Rationale (not for sending): the strongest overall match in the set — he is already using your -vocabulary ("contract", "observation", "plan", "evidence, not validation") independently. The -message offers framing and one small calculus, asks for nothing.* - ---- - -### 1.4 @NeoZorK — `Monte-Neo` - -**What he is building.** "The independent verifier for trading strategies written by AI agents -and humans" — catches look-ahead bias, hidden costs and overfitting before a backtest reaches -money. Adapters for nine frameworks, an MCP server, a `strategy-verdict/1` schema, a "Trap -Suite", and — tellingly — a GitHub *false accusation* issue template. - -**The struggle.** His README puts the requirement precisely (§ line ~153): the verifier must be -*"independent… probes that do not trust the strategy's own numbers"*, and the failure mode he -fears is that the *"verifier cannot silently stop catching a leak or start accusing honest -code"* — soundness **and** completeness, in tension, over probe heuristics. Meanwhile -`src/monte_neo/core/portfolio/manager.py` carries `# Mock values for now, should be calculated -from equity_curve`, and the acceleration layer has `for now` fallbacks — the ordinary debt of a -beta. - -**The hook — `epistemic-types` + `residual-evidence-types`.** These are two halves of his -problem, and both exist: - -* *Epistemic types* separates "I have a receipt for A" from "A is true": `Warrant` (evidence - token) and `Epi` (token + warrant type) versus a separate `SoundWarrant` interface that adds - a soundness map from evidence to claim. His certificate (`check_signature`, - `recheck_certificate`, sealed digests) is a warrant; his "must not accuse honest code" is the - soundness obligation. The modality spectrum (`FactiveModality` has `reflect`; `BeliefModality` - deliberately does not) is a ready-made vocabulary for which of his verdicts are veridical and - which are defeasible. -* *Residual evidence types* answers a different question he must answer every day: which - explanations are compatible with an observation plus its evidence constraints, and what holds - for **all** of them. That gives him the distinction his error taxonomy needs — "leakage is - present" (presence) versus "this term causes it" (value identification) — and the fence that - *candidate counts are not probabilities*, which is exactly right for scoring overfitting - probes. - -And the discipline worth copying: his Trap Suite is an expected-rejection corpus. The estate's -version pairs nine deliberately-invalid modules with a *certified finite checker proved to agree -with its reference exploration over all 546 configurations by `refl`* — a regression can't -silently change a verdict. - -**Copy-paste message** - -> I have been reading `Monte-Neo` — the independence claim and the false-accusation template in -> particular. The line that stuck with me is that the verifier must not "silently stop catching -> a leak or start accusing honest code": that is soundness and completeness pulling against -> each other over probe heuristics, and it is the hard part of what you are doing. -> -> Two small research artefacts of mine might be useful to you, both deliberately minimal: -> -> One separates *having evidence* from *the evidence being sound*. It has a `Warrant` (an -> evidence token), an `Epi` (token paired with its warrant type), and a separate `SoundWarrant` -> interface that adds an explicit soundness map — plus a modality spectrum where the factive -> version carries a `reflect` and the belief version deliberately does not. Your certificates are -> warrants; your false-accusation constraint is a soundness obligation. Naming them separately -> is what stops a receipt being read as a result. -> -> The other is about which explanations survive an observation, and it separates *presence* from -> *value identification*: you can establish that a leak exists without identifying the term that -> causes it, and those need different evidence. It also insists that candidate counts are not -> probabilities — which is exactly the discipline overfitting probes need. And the way it -> certifies its own checker (a finite checker proved to agree with a reference exploration over -> every configuration, plus deliberate invalid cases that must be rejected) is a pattern I would -> steal for a Trap Suite regression harness: a verdict change becomes a failing correspondence -> rather than a silent shift. -> -> Both are prototypes, not products — if either maps onto a real edge in your verifier I am glad -> to send pointers. - -*Rationale (not for sending): he is shipping a verifier with a public honesty surface — the -closest thing in the follower list to a natural consumer of two family members. Note the -deliberate "prototypes, not products".* - ---- - -### 1.5 @markbakos — `preflightx` - -**What he is building.** A Rust repository-malware scanner: inventories files, classifies bytes -independently of extensions, follows imports from npm/VS Code/devcontainer/CI roots, traces -remote responses into `eval`/`Function`/VM APIs/process execution, applies YARA-X signatures, -and runs the whole thing sandboxed under Landlock + seccomp, failing closed by default. - -**The struggle.** His README is unusually honest and shows exactly where the pain is: - -> *"This is a bounded malware-focused model, not a complete JavaScript interpreter and not a -> verdict that a repository is safe. Dynamic module targets, unresolved imports, parser -> failures, and reached analysis limits are reported; **parser or resource limits make a scan -> incomplete (exit code 2)**."* - -*"Deteministic mutation smoke tests do not replace coverage-guided fuzzing; broad corpus -calibration, macOS/Windows sandbox backends, Linux AArch64 runtime proof, packet-capture -evidence, and release supply-chain gates remain open."* - -And in the code: `Classification { record, findings, incomplete_reasons, text }` plus a -`Confidence` enum, and a test named -`extra_language_heuristic_is_limited_to_one_file_and_marks_execution_roots` — a heuristic whose -*limits are asserted in the test name*. - -**The hook — `absolute-zero` (OND) + `epistemic-types`.** Two things: - -* OND ("observational null disclosure") formalises a guarantee that is *always relative to a - declared observation model `O`*, and requires **every claim to ship a residue list of - out-of-scope observables** — "the honest boundary between the proof and the physical metal". - That is his README paragraph, turned from prose into data. Making the residue list a - machine-readable field on every finding is the difference between "we warned you once" and - "this verdict cannot be read as more than its model". -* Epistemic types give him the missing type for `Confidence` + `incomplete_reasons`: the minimal - interface that separates "a receipt exists" from "the claim is true" (`Warrant` vs - `SoundWarrant`), with a *belief* modality that deliberately has no `reflect`. An incomplete - scan is a belief; a clean scan is not thereby a fact. Today that distinction lives in an exit - code and a prose paragraph; as a type it cannot be dropped by a caller. - -Worth stealing too: the estate's pairing of each accepted case with an **expected-rejection -fixture** pinned in CI (occupancy-types pins seven distinct error codes: `E_DOUBLE_FREE`, -`E_LEAK`, `E_ALIAS`…) — for a scanner, the analogue is pinning *what a bad change would -accuse*, so a regression shows up as a false accusation rather than a miss. - -**Copy-paste message** - -> I read `preflightx` this week — the classification pipeline and the sandbox story. Your README -> contains the two sentences I wish every scanner shipped: *"not a verdict that a repository is -> safe"*, and *"parser or resource limits make a scan incomplete (exit code 2)"* — and -> `extra_language_heuristic_is_limited_to_one_file_and_marks_execution_roots` is a heuristic -> that states its own limits in the test name. That is the right discipline. -> -> I have two small pieces of formal work that happen to be shaped like your remaining gap. -> -> The first is a two-pillar effort where the second pillar — "observational null disclosure" — -> defines a guarantee *always relative to a declared observation model O*, and requires every -> claim to ship a **residue list** of out-of-scope observables: the honest boundary between the -> proof and the metal. That is your incompleteness paragraph, except as a structured field on -> every finding rather than prose. It also gives you a principled way to write down what -> `Confidence` means. -> -> The second is a minimal interface that separates *having a receipt* from *the receipt being -> sound*: a `Warrant` (evidence token), an `Epi` (token + its warrant type), and a separate -> `SoundWarrant` that adds an explicit soundness map — with a belief modality that deliberately -> lacks a reflect, so nothing can quietly promote a belief to a fact. An incomplete scan is a -> belief; a clean scan is not thereby a fact. As an exit code that distinction is advisory; as a -> type it cannot be dropped by a caller. -> -> One pattern worth stealing from the same estate regardless: every accepted case gets a paired -> *expected-rejection* fixture pinned in CI — so a regression shows up as a false accusation -> rather than as a silent miss. Given your false-positive surface, that is probably the highest -> value per line of test code you can add. -> -> Prototypes all, and I am not selling anything — but if the residue-list idea is useful I can -> point you at the shape. - -*Rationale (not for sending): he is a careful engineer; the residue-list-as-data suggestion is -concrete and cheap, and the expected-rejection framing is directly actionable for his corpus -work.* - ---- - -### 1.6 @BoggersTheFish — `thinking-system` - -**What he is building.** A "verifier-first monorepo": *"a verifier-gated kernel… residual/tension -accounting across activation, contradiction, provenance and verification dimensions… sealed -adversarial evaluation"*, with content-addressable (SHA-256) receipts drawn from a stated -pipeline: - -> representation → lawful quotient → **relative residual** → sufficient observer family → -> **localised obstruction** → minimal typed revision → sealed adversarial evaluation - -**The struggle.** He is *already doing the estate's discipline*, in a hand-rolled form. -`core/kernel/obligations.py` defines a `VerificationResult` carrying `evidence`, -`artifact_hashes`, `consumed_premises`, `produced_claims`, `deterministic: bool` and -`limitations: list[str]` — with values like `["structural_validation_only"]`, -`["allowlisted_arithmetic_ast_only"]`, `["bounded_single_argument_arithmetic_examples_only"]`. -Those limitation strings are exactly the honest-bound records the estate keeps, but as free -text they can be dropped, edited or ignored without anything failing. - -**The hook — `echo-types` + `epistemic-types` + the shared glossary.** Genuinely three-way: - -* His *"lawful quotient → relative residual → localised obstruction"* **is** the echo - construction: a non-injective map, the fibre over an output, and the obligation to keep what - was lost. `echo-types` has a mechanised **loss taxonomy × residue-shape grid** you could - borrow as the vocabulary for *which* residual he is accounting, and a proved - `no-canonical-disaggregation` result that is worth knowing before anyone tries to invert an - aggregate. -* The estate's *"first residual milestone"* gives his kernel a sharper question: **presence - versus value identification** — "a residual exists" and "this term is the cause" need - different evidence, and neither is a probability. -* The shared glossary separates *residual* (discrepancy against a declared model) from *residue* - (information retained after a map) from *measure* and *grade*. His README uses "relative - residual" and "residual accounting" broadly; since he is building a research vocabulary, - aligning the two costs nothing now and prevents an expensive collision later. - -And the cheapest concrete upgrade: the estate pairs every accepted case with *expected-rejection -fixtures* (twelve deliberately-invalid modules must be **rejected** by the checker, pinned in -CI). Applied here: one rejection fixture per declared `limitation`, proving the limitation is -*observable* — i.e. that the verifier actually fails on what it claims to exclude. A limitation -string that nothing tests is a claim; a limitation with a failing case behind it is a fact. - -**Copy-paste message** - -> I read `thinking-system` this week and recognised a lot of my own work in it — the -> verifier-gated kernel, the content-addressable receipts, and especially `limitations` in -> `core/kernel/obligations.py` (`structural_validation_only`, -> `allowlisted_arithmetic_ast_only`, `bounded_single_argument_arithmetic_examples_only`). Those -> are honest-bound records, which almost nobody writes down. -> -> Your pipeline line — *representation → lawful quotient → relative residual → localised -> obstruction → minimal typed revision* — is, structurally, the thing one of my repos exists -> for: an irreversible map where the fibre over each output retains a proof-relevant constraint -> on what was lost. That repo has a mechanised taxonomy of loss kinds and residue shapes you -> could use as vocabulary for *which* residual you are accounting, plus a proved result that no -> canonical disaggregation exists once you aggregate — worth knowing before anyone tries to -> invert one. -> -> Two concrete suggestions, both cheap. First: make each `limitation` string falsifiable by -> pairing it with a *rejection fixture* — a case that the verifier must fail on, pinned in CI. -> A limitation nothing tests is a claim; a limitation with a failing case behind it is a fact, -> and it stops a limitation being silently dropped in a refactor. I keep twelve such fixtures -> for a much smaller library. -> -> Second: one vocabulary caution. I keep a shared glossary that distinguishes *residual* -> (discrepancy against a declared model) from *residue* (information retained after a map) from -> a numerical measure and from a resource grade. Since you are building a research vocabulary, -> fixing those senses now is free; later it is expensive. -> -> Both my repos are prototypes with explicit open items, and I am not claiming otherwise — but -> if either maps onto your residual accounting I am happy to send pointers. - -*Rationale (not for sending): he is the closest to an independent co-inventor of your programme. -Lead with recognition, not correction; the limitation-falsifiability suggestion is the one that -helps him most and can be adopted in an afternoon.* - ---- - -### 1.7 @Lxcardoza993 — `LLMDOG` - -**What he is building.** A local-service watchdog that probes, diagnoses with a local LLM, -applies four guardrails, fixes, verifies, rolls back, and *learns*: recurring bugs are distilled -into `known_issues` so the next recurrence heals from a whitelist. Bilingual README, 26 tests, -71% coverage, DRY_RUN by default. - -**The struggle — visible in his own commit history.** Three of his last six commits are -fightbacks: - -* `fix: TG 通知加重试——瞬时 SSL 抖动不再丢警报/喜报` (retry so transient SSL jitter stops losing - alerts) -* `fix: bug 学习签名改用修复动作——**同病不同措辞不再裂成多个 bug**` (bug-learning signature switched to - the fix action, so *the same bug in different wording no longer splits into several bugs*) -* `fix: max_tokens 2000→4000——reasoning thinking burns out and truncates NO_JSON` - -The middle one is the interesting one, and it is a deep problem wearing a small hat: he is -hashing an LLM's *surface rendering* to identify a bug, and the rendering is non-injective — -many wordings, one bug. His fix (key on the fix action instead) is a coarser map, which merges -*more* — and some of those merges will be wrong in the other direction. - -**The hook — `echo-types`.** This is the fibre question exactly. `Echo f y = Σ (x : A), f x ≡ y`: -the origins compatible with one output. His bugs are origins, the LLM's diagnosis is the map, -and the identity of a bug must be carried by a *retained constraint* rather than by the wording. -The pieces that transfer: - -* the **loss taxonomy** asks the design question he needs — *what may the signature forget, and - what must it keep* — rather than tuning a hash until the split stops; -* the proved **no-canonical-disaggregation** result explains why he will never get back from the - learned aggregate to the individual bug, which is an argument for keeping the fibre (the - equivalence class of renderings, with a witness) alongside the signature; -* the rule that *equal measured values do not imply equal residues* is the formal reason two - different bugs can share the action key he just adopted. - -Practical first step available today: pair his learned-issue entries with *expected-rejection* -cases in `tests/` — a case where the "learned" remedy must **not** be applied, so a -mis-merge shows up as a failing test instead of a 3am failed heal. - -**Copy-paste message** - -> I read LLMDOG this week — the guardrails and the learning loop — and one of your commits did -> something I want to point at, because I think you have hit a deeper problem than the commit -> message suggests: *"same bug, different wording no longer splits into several bugs."* -> -> You fixed that by keying the bug signature on the fix action instead of the wording. That is -> the right instinct, and it moves the problem rather than dissolving it: the action key is a -> coarser map, so it will merge some bugs that are genuinely different. The formal reason is that -> the LLM's rendering of a bug is not injective — many wordings, one bug — so no hash of the -> surface will ever be the identity. What you need is not a better hash but an explicit decision -> about *what may the signature forget, and what must it retain*. -> -> That question is the subject of a small Agda development of mine: it treats a non-injective -> map, keeps the fibre over each output (all the origins compatible with it) as a witness, and -> gives a taxonomy of loss kinds and residue shapes. There is also a proved result that once you -> aggregate, no canonical disaggregation exists — which is exactly why the original renderings -> have to be retained alongside the signature rather than recovered from it. -> -> The cheapest concrete step, regardless of any of that: give every learned issue an -> *expected-rejection* test — a case where the learned remedy must **not** be applied. Then a -> mis-merge shows up as a failing test rather than as a failed heal at 3am. (Your 26 tests and -> the guardrail design suggest you would get a lot out of that pattern.) -> -> My repo is a prototype with open items — not claiming a product — but if the fibre framing is -> useful I can send the module names. - -*Rationale (not for sending): the "same bug, different wording" commit is a genuine -information-loss problem misread as a hashing detail; the note gives him the sharper framing and -one immediately actionable test pattern.* - ---- - -### 1.8 @dbunt1tled — `parquet2csv` - -**What he is building.** A Go CLI that streams Parquet ↔ CSV a row at a time, with the deliberate -property stated in the README: *"Flat memory: peak usage is bounded by `--row-group-size` and -`--page-size`, not by row count"* and *"Peak memory for CSV → Parquet is set by two flags rather -than by the size of the input"*. His most recent commit rewrote the converter for *"flat memory -and performance… adds tunable row group and page sizes"*, and earlier ones fixed *"resource -closure, and sync.Pool usage"*. - -**The struggle.** The design is right and the accounting is informal. `--verbose` prints -*elapsed time and memory usage* as single numbers; page and row-group boundaries are the places -where buffers are born and die; `sync.Pool` reuse is reclaimed by the GC, so the actual peak is -a function of scheduling as much as of the two flags. The README even says it: larger row groups -are *"better for analytical readers, at the cost of peak memory"* — the trade-off is real and -currently only tested empirically (and his test suite is 20 files' worth of behaviour, not of -bounds). - -**The hook — `occupancy-types`.** This is the closest match in the whole set — his repo is -already speaking the language: - -* An **occupancy grade is a pair**: the high-water mark and the live count, composed by the - *non-commutative* monoid `(p₁,n₁)·(p₂,n₂) = (max(p₁, n₁+p₂), n₁+n₂)`. That is precisely what - `--verbose` should report — peak *and* live, per stage — because a single "memory usage" number - cannot be composed across reader → decoder → writer, while the pair can. It also lets him - *prove* "peak is bounded by the flags, not the row count" as a composition statement rather - than a measured observation. -* The plan's other claim is his second pain point: **reclamation is a function of protocol - shape, not of GC**. Page/row-group boundaries are the reclamation points; `sync.Pool` reuse is - exactly the case where the free moment depends on GC. Making the boundary explicit is what - turns "usually flat" into "flat by construction, measured ≤ certified". -* And the discipline that makes it honest: he already fixes grades at check time (his flags are - constants), which is the plan's *grade constancy rule* — needing anything else is the - documented kill signal. - -**Copy-paste message** - -> I used `parquet2csv` as an excuse to read its README properly this week, and the line *"peak -> usage is bounded by `--row-group-size` and `--page-size`, not by row count"* is the whole -> reason I am writing. You have built a tool whose memory behaviour is a *bounded, composable* -> resource — which is rarer than it should be — but the accounting behind it is still informal. -> -> I keep a small calculus for exactly this: a *state*-resource grade is a pair (peak, live), -> composed by a non-commutative high-water-mark monoid — `(p₁,n₁)·(p₂,n₂) = (max(p₁, n₁+p₂), -> n₁+n₂)`. Three things fall out that map onto your code. `--verbose` should print peak *and* -> live per stage, because a single number cannot be composed across reader → decoder → writer -> while the pair can. Your page/row-group boundaries are the reclamation points, which is what -> turns "usually flat" into "flat by construction". And `sync.Pool` reuse is the case where the -> free moment depends on the GC rather than on your protocol — the calculus treats reclamation -> as a function of protocol shape, which would let you certify the bound instead of measuring it. -> -> Related: the calculus separates a *cost* grade (`+` in sequence, `max` across alternatives) -> from a *state* grade like yours, because they genuinely do not compose the same way. If you -> ever add a `--timeout` or a retry budget alongside the memory flags, that split stops you -> conflating two axes. -> -> It is a research repo with open rungs, not a library you should depend on — but the monoid is -> three lines and the framing is free. Happy to send it. - -*Rationale (not for sending): the pair-vs-single-number suggestion is concrete, immediately -useful, and derives from the repo's core claim rather than decorating it.* - ---- - -### 1.9 @tawdesangeeta1973-coder — `arc-propose-verify` - -**What he is building.** *"Neural proposals + symbolic verification for ARC-style tasks: program -synthesis, a verifier, recursive reasoning, and a growing abstraction library."* Created -2026-10-02 — two days old, three files. Early. - -**The struggle.** Too early for a struggle in code, but the *problem* is already fully visible in -the title: a neural proposer generates candidate programs, a symbolic verifier checks them. The -classic failure mode of that architecture is a verifier that can only say "consistent with the -demonstrations" while the proposer's scores get read as probabilities — and a demonstration set -that under-determines the rule. - -**The hook — `residual-evidence-types`.** The repo's central object is -`Candidate observe r E = Σ (w : W), (observe w ≡ r) × E w` — a world together with evidence that -it reproduces the observation and satisfies the declared constraints — and it is built around one -distinction: **presence versus value identification**. You can prove a property holds in *every* -program consistent with the demonstrations (presence) without identifying the rule -(identification); and neither conclusion is a probability. That is precisely the ARC setting: the -demonstration pairs are the observation function, the candidate programs are the fibre, and the -verifier's job is the candidate-wide claim. Two fences from the same work are worth having early: -*constructing a candidate does not recover the world* (his verifier can prove consistency -without the proposal being the true rule), and *an empty candidate set is not a warrant for every -claim* (a failed search is not a proof of impossibility). - -The discipline worth borrowing alongside it: the estate's minimal Agda core ships **nine -deliberately-invalid modules that must be rejected** by the checker, and a finite checker proved -by `refl` to agree with a reference exploration over all 546 configurations. For a proposer + -verifier, that shape is a regression harness: the verifier's accept/reject table is the artefact, -and the neural side can change freely as long as the correspondence holds. - -**Copy-paste message** - -> I saw `arc-propose-verify` go up this week and wanted to send one thought while it is still -> cheap to shape, because you have picked one of the sharpest versions of a problem I work on. -> -> The standard failure mode of "neural proposals + symbolic verifier" is that the verifier can -> only establish *consistency with the demonstrations*, while the proposal scores quietly get -> read as probabilities. There is a small body of work I have that draws exactly these lines: it -> defines a candidate as a world plus evidence that it reproduces the observation *and* satisfies -> the declared constraints, and then separates **presence** — a property holds in every -> admissible candidate — from **identification** — this is the one. Arc's demonstrations -> under-determine the rule; that is not a defect of your verifier, it is the structure of the -> problem, and it deserves two different names. -> -> Two fences from it that are worth adopting before the code grows: constructing a candidate does -> not recover the world (your verifier can prove consistency without the proposal being the true -> rule — keep that premise explicit), and candidate counts are never probabilities. -> -> One pattern, if it is useful: the version of this I have keeps nine deliberately-invalid cases -> that the checker *must* reject, plus a finite checker proved to agree with its reference -> exploration on every configuration. For a proposer/verifier pair that is a very good regression -> harness — the verifier's accept/reject table is the artefact, and the neural side can then -> change freely as long as the correspondence holds. -> -> Mine is early research, not a library — but you are two days in, and the vocabulary is the part -> that is expensive to change later. - -*Rationale (not for sending): two days old, so the note is about framing rather than code — -which is the honest thing to send and also the most useful thing at that age.* - ---- - -### 1.10 @Berserk-hub150 — `skillhawk` - -**What he is building.** A security scanner + hands-on lab for AI agent skills, `SKILL.md` files -and MCP configs — *"Catch dangerous agent instructions before they touch your shell, files or -credentials."* Zero-dependency, 64 stars, a five-minute challenge, releases and good-first-issues -labels. - -**The struggle.** The domain's hard part is that a "dangerous instruction" is only dangerous -*relative to a declared threat model*: what counts as exfiltration depends on which channels you -consider observable. So a scanner here faces exactly the problem the estate formalises — a -guarantee that is meaningful only relative to a declared observation model, and that must state -what it did **not** look at. The five-minute challenge is a good instinct (an adversarial corpus -by another name) but the scanner's promise and its model boundary need to travel together. - -**The hook — `absolute-zero` (OND) + `epistemic-types`.** OND defines "a program that reveals -nothing about its secret input to a declared observer: its observable trace is constant over the -secret, relative to a declared observation model `O`" — and the discipline that makes it -honest: **every OND claim ships a residue list of out-of-scope observables.** Translated to -SkillHawk: every verdict ships the list of channels the model did not consider (base64-in-comment -to an allowed host, side channels through tool ordering, timing…). That turns a marketing claim -into an auditable one, and it is a genuinely differentiating feature for a skill scanner. - -The second piece: `epistemic-types` separates an evidence token (`Warrant`) from a sound warrant -(`SoundWarrant`, which adds an explicit map from evidence to claim). A finding "this skill sends -credentials to an unknown host" is a warrant; whether it is *sound* depends on the declared -model. Making the severity/confidence field a typed warrant with a documented soundness condition -is the difference between a scanner that can be trusted and one that trains users to ignore it. - -Practical first step: pair each detection rule with an **expected-rejection fixture** — a benign -skill that must **not** be flagged — and pin them in CI. For a scanner whose worst failure is -noise, false-positive fixtures are the highest-value tests it can have. - -**Copy-paste message** - -> I have been reading `skillhawk` this week — nice to see MCP/skill security taken seriously as -> its own surface, and the 5-minute challenge is a good idea. -> -> One thought from a formal corner that might be worth more to you than a feature request. In a -> security scanner for agent instructions, "dangerous" is only meaningful *relative to a declared -> threat model* — which channels you consider observable, which behaviours you consider actions. -> There is a formalisation of exactly this (it comes from a project about programs that provably -> reveal nothing to a declared observer) whose one non-negotiable rule is that **every claim ships -> a residue list of out-of-scope observables**: the explicit boundary between what was proven and -> what was never looked at. -> -> Applied to SkillHawk, that becomes a real feature and a differentiator: every verdict carries -> the list of channels the model did not consider — encoded payloads in comments to allowed -> hosts, ordering/timing side channels, and so on. It converts "we scan skills" into "here is -> exactly what this scan could not have caught", which is the thing that makes scanners trusted -> rather than ignored. -> -> Related and smaller: keep "we have evidence of X" separate from "X is true". I have a minimal -> interface for that (`Warrant` vs a separate `SoundWarrant` with an explicit soundness map), and -> it maps cleanly onto a finding plus its confidence. -> -> The cheapest high-value test change, whatever you do with the above: give every detection rule -> an *expected-not-flagged* fixture — a benign skill that must stay clean — pinned in CI. Your -> worst failure mode is noise, so false-positive fixtures buy more than more rules. -> -> All research-stage on my side, no product — but the residue-list idea is small and I am glad to -> sketch the shape. - -*Rationale (not for sending): 64 stars and an actively-labelled issue tracker — a repo where a -good idea can actually land. The residue list is the differentiator, and the -false-positive-fixture advice is the fastest win.* - ---- - -### 1.11 @kyal102 — JARVI3 (profile + tools) - -**What he is building.** Deterministic verification infrastructure for high-consequence AI -workflows. His framing, in his own words across the profile and the tooling: *"AI proposes. Gates -verify. Evidence records. Replay checks drift."* and *"Each gate says what it checks, what it -cannot establish, and what validation is still required"* and *"No model in the loop for the -verdict"* and *"Every pass states what it does not prove."* - -**The struggle — and this is why he is in Tier 1 despite having no library to point at.** He is -selling and building verification *gates*, and the hardest practical failure of gates is not a -wrong verdict: it is **a gate that does not run and still reads green**. I measured exactly that -this week, in the wild, and it is worth more to him than any framing I could offer. - -**The finding, measured today.** On `hyperpolymath/occupancy-types`, **96 of the last 100 -workflow runs concluded `startup_failure`** — including on pushes by the repository owner and -including every gate (secret scanning, static analysis, governance, test workflows). The -distinctive part is that these runs show up in the Actions list *as completed runs*, with no jobs -and no logs, while other repositories in the same estate show green badges for the same workflow -families. A companion case is stronger still: a pull request merged with **zero CI signal** -because all five of its check-suites recorded `STARTUP_FAILURE` — the change was never -type-checked, and it was merged as a *fix for a red build*. - -**The hook — your estate's own discipline, plus one recommendation he can adopt verbatim.** -Two things transfer directly: - -* **A gate must prove it ran.** Treat "did not start" as failure for every required check, and - verify *workflow execution*, not just absence of failure. That is a one-line-ish policy change - with a large blast radius, and he is the right person in this follower list to write it up. -* **A receipt is not a claim.** The failure above is precisely why the estate's pattern is a - dated AFFIRMATION pinned to a commit SHA plus a PROOF-STATUS that separates proved from open - from *blocked* (blocked ≠ retracted, and blocked items carry the exact command that would - unblock them). His "every pass states what it does not prove" is the same principle; the - estate's version makes it machine-checkable and dated, so a stale receipt cannot be read as a - current one. - -**Copy-paste message** - -> I read your JARVI3 material this week — "AI proposes. Gates verify. Evidence records. Replay -> checks drift." — and I have something measured that I think is directly in your lane, so I am -> sending it rather than a pitch. -> -> The failure mode that will hurt your customers is not a wrong verdict from a gate. It is **a -> gate that never ran and still reads green.** I hit a clean instance this week: a repository -> where 96 of the last 100 workflow runs ended `startup_failure` — the workflows are listed as -> completed runs, with zero jobs and no logs, across the whole set including the security and -> governance gates. In an adjacent case, a pull request was merged with *zero* CI signal because -> all five of its check-suites recorded `STARTUP_FAILURE`; the change was never checked at all, -> and it merged as a fix for a red build. -> -> Two things I would take from that, and one is a policy you can sell. First: treat "did not -> start" as failure for every required check, and verify that the workflow *executed* rather than -> that it did not fail. That single change closes the hole above. Second: the discipline I use to -> stop a receipt ageing into a claim — a dated affirmation pinned to a commit SHA, and a status -> document that separates *proved*, *open*, and *blocked*, where blocked items carry the exact -> command that would unblock them. "Every pass states what it does not prove" is your version of -> the same principle; making it dated and commit-pinned is what stops a stale pass being read as -> a current one. -> -> Happy to send the two documents as a shape, and interested in how you handle the same problem -> on your side — you are closer to that market than I am. - -*Rationale (not for sending): he is a *peer on the same problem* with commercial exposure, so -this is the one message that leads with a finding rather than a request. It also plants the -estate's receipt discipline where it could actually be adopted.* - ---- - -## 2. Tier 2 — shorter notes (repo read, lighter touch) - -### 2.1 @j0hnWeider — `security-testing` - -**Read.** A TypeScript/Playwright offensive-security portfolio against ServeRest: 39 scenarios -mapped to OWASP Top 10, k6 for performance, Allure live reports, CI per push. - -**Struggle.** The suite asserts that the API *rejects* things — which is the right kind of test, -but the assertions are per-scenario pass/fail. When a rejection suite is graded only by "did it -fail", a regression that makes an endpoint accept something it used to reject can pass silently -if the assertion is loose, and a legitimate error-class change produces noise instead of a -signal. - -**Hook — `occupancy-types`' rejection discipline.** Its manifest pins seven rejection fixtures, -each to a *distinct error code* (`E_DOUBLE_FREE`, `E_LEAK`, `E_ALIAS`, `E_PROTOCOL`, -`E_USE_AFTER_DROP`, `E_CLOSE_NOT_END`), so the suite asserts failure *identity*, not merely -failure. The same shape applied to his 39 scenarios — each expecting a specific status/violation -class — turns an offensive suite into a regression harness for the API's security posture. - -**Copy-paste message** - -> I read your security-testing suite this week — 39 offensive scenarios wired to OWASP and -> reported through Allure is a solid setup, and the k6 layer alongside it is the part most people -> skip. -> -> One suggestion from a small project of mine that does a similar (much smaller) thing: pin every -> rejection to its **own error class**, and assert the identity of the failure rather than the -> fact of it. I keep seven expected-rejection fixtures, each asserting a distinct code -> (`E_PROTOCOL`, `E_LEAK`, `E_ALIAS`, and so on) from a machine-readable manifest. The reason is -> that a "rejected" assertion can pass for the wrong reason — a renamed error, a changed status, -> or a validator that now rejects everything — and only the identity check catches that. For a -> 39-scenario offensive suite, a manifest of expected violation classes would give you the same -> regression strength in an afternoon, and it makes the report readable by an auditor rather than -> just by you. -> -> No ask — just thought it might be useful where you are already careful. - -*Rationale (not for sending): a genuine upgrade to an already-good suite, and it advertises the -manifest pattern rather than the formalism.* - -### 2.2 @Morez-Momeni — `system-log-analyzer` - -**Read.** A small, actively developed Python log analyser (`analyzer.py`, `main.py`, -`visualizer.py`) with recent commits adding process filtering/ranking and log statistics plus -visualisation. - -**Struggle.** The output is claims derived from an observation function over a log: "top process", -"error rate", "spike". Log analysis has the classic confounds — missing lines, rotated logs, -clock skew between sources, a filter applied before counting — and those are exactly the -premises that decide whether a derived claim holds. - -**Hook — `residual-evidence-types` + `epistemic-types`.** The distinction worth having early: -**presence versus identification**. "Some process is failing repeatedly" (a claim over all -admissible worlds consistent with the lines) is different from "this process is the cause", and -they need different evidence. The related fence — candidate counts are not probabilities — is the -reason a ranking by log lines is a ranking of *mentions*, not of risk. And an epistemic standpoint -record (which file, which host, which time window, which filter) attached to each derived claim is -what makes a report auditable later. - -**Copy-paste message** - -> I have been reading your log analyser this week — the filtering/ranking work is coming along -> nicely. -> -> One thing worth deciding early, because it is the difference between a useful report and an -> over-claimed one: separate *"these lines show X"* from *"X is the cause"*. Rankings over logs -> rank mentions, not causes, and the premises that decide which it is — rotated or missing lines, -> per-host clock skew, filters applied before counting — are worth recording next to the output -> rather than living in your head. I have a small research repo about exactly this (a claim holds -> for all worlds consistent with the observation *and* the evidence constraints, and candidate -> counts are never probabilities), and a second one about recording the standpoint — the tool, -> version, window and filter — as part of a claim's receipt so a report remains auditable months -> later. -> -> Neither is a library; both are patterns. If it is useful I can send the two definitions, which -> are short. - -*Rationale (not for sending): small project, low stakes, but the presence/cause split is a real -improvement and the note costs him nothing.* - ---- - -## 3. Delivery notes (for you, not in the messages) - -* **Channel.** These read as DMs or as a comment on a recent PR/issue. GitHub issues are public - and searchable — for the ones making a *claim about their code* (1.7's mis-merge argument, - 1.5's incompleteness framing) a DM is kinder; for 1.11 (a finding, not a critique) a public - comment is a genuine contribution. -* **Links.** I have deliberately left URLs out of the drafts. Add at most one per message, and - prefer the README over the proof file — the proof files are for the three or four people who - will actually read Agda (1.2, 1.4, 1.6). -* **Sequencing.** Send the ones where you offer a *finding* first (1.11, 1.1, 1.3), because they - ask nothing; then the peers (1.2, 1.4, 1.6); then the lighter notes. If someone replies, the - follow-up is a single file, not a repo tour. -* **Do not send a note before checking the referenced file still exists.** Four of these repos - were pushed within the last 48 hours; commits move. Each note names a file and a commit - subject, so a ten-second check is enough. (I re-verified all of them at clone time today.) -* **The boundary to keep.** Every draft says "prototype" where the estate says prototype, and - "open" where the plan says open — K-CUT is described as an open conjecture in 1.3, and - `occupancy-types` is described as research with open rungs in 1.8. Please keep those words if - you edit. -## 4. Next-up set (plausible hooks, not yet read) - -These are the accounts I would read next — each has public code in a domain where one of -the seven repos plausibly lands. One line each on the *presumed* hook; none of these has -been read yet, so nothing here is a draft. - -* **@1minds3t** — omnipkg. *Python env interception — a resolver's merge/dedup decisions are a non-injective map (echo fibre); high collision risk, worth care* -* **@mikalv** — Prism (hybrid search). *retrieval scoring = an observation function with a lossy ranker; echo + residual (presence vs identification)* -* **@ZenyaDAR** — PlayGuard (MCP proxy). *agent tool-call proxying — OND-style declared-observable model + residue list; warrants for allow/deny decisions* -* **@godstime-dev** — aviation-weather-intelligence. *ETL over weather observations; residual-evidence (which worlds satisfy observation + constraints) is close to METAR/forecast reconciliation* -* **@manman4** — OEIS_04. *implementing OEIS sequences in C — a prefix under-determines the sequence (presence vs identification is the headline case)* -* **@a5i** — journio. *Rust; not yet read — check for state/protocol bounds before any claim* -* **@kh-mahmoud** — state-machine-experiments. *state machines invite the occupancy/HWM composition claim directly* -* **@GhCristea** — rdf-parser. *RDF/IRI handling — canonicalisation is a non-injective map with a real retained-witness obligation (echo)* -* **@ruiyangzhou01** — qml-inference-protocol. *inference protocol — session/projection framing may apply* -* **@SoheilGtex** — math-research-radar. *paper monitoring — epistemic standpoint records (tool, version, window, hash) map onto source provenance* -* **@thejesh23** — ai-plugin-rankings. *ranking = observation + aggregation; `no-canonical-disaggregation` is directly relevant* -* **@lshariprasad** — BULIDATHON-2026 (RAVEN, IoT). *IoT retrieval robot — occupancy for bounded buffers/queues if it grows past a hackathon* -* **@Kelpejol** — Orgos. *unread; Python, active* -* **@captainblair** — Nexa. *unread; TypeScript, active* - -## 5. Full triage - -Fetched **225** of 269 followers (some GitHub API lookups failed for private/renamed -accounts). Of these: **59** have no substantive public code (profile/config repos), -**34** are inactive (>180 days), and **155** are active with public code. - -### 5.1 Active with public code (155) — the pool the notes came from - -| days | account | lang | most-recent repo | ★ | -|---|---|---|---|---| -| 0 | @1minds3t | Python | `1minds3t/omnipkg-metadata` | 5 | -| 0 | @Berserk-hub150 | JavaScript | `Berserk-hub150/skillhawk` | 64 | -| 0 | @CodeMasterAbhishek | JavaScript | `CodeMasterAbhishek/Daily-Dose-of-TMOCK` | 8 | -| 0 | @Connor9994 | Python | `Connor9994/GitHub-Language-Stats` | 71 | -| 0 | @Daniel21Ayen | TypeScript | `Daniel21Ayen/freshman-plus` | 0 | -| 0 | @EimanTahir027 | - | `EimanTahir027/Convolutional-Neural-Networks-CNN` | 2 | -| 0 | @Dreamerol | HTML | `Dreamerol/CARDFOLIO` | 24 | -| 0 | @Elite588 | JavaScript | `Elite588/undici` | 9 | -| 0 | @Morez-Momeni | Python | `Morez-Momeni/system-log-analyzer` | 0 | -| 0 | @NeoZorK | Python | `NeoZorK/Monte-Neo` | 8 | -| 0 | @NazmusSayad | Python | `NazmusSayad/Git-Stats` | 39 | -| 0 | @STD-DEEPANSHU | JavaScript | `STD-DEEPANSHU/StdGram` | 0 | -| 0 | @SoheilGtex | Python | `SoheilGtex/math-research-radar` | 7 | -| 0 | @ShivamMathtech | Python | `ShivamMathtech/ApertureNav-Sim` | 0 | -| 0 | @Sunil56224972 | HTML | `Sunil56224972/Void-Dev-Platefrom` | 1 | -| 0 | @TadesseAsrie | JavaScript | `TadesseAsrie/Ethio-Keyboard-web-app` | 4 | -| 0 | @Teagar | C# | `Teagar/crawl-online` | 1 | -| 0 | @abduverse | Python | `abduverse/zkteco_attendance` | 4 | -| 0 | @altyebv | JavaScript | `altyebv/INmore` | 2 | -| 0 | @arielshakaramiro | Python | `arielshakaramiro/hf-model-watcher` | 0 | -| 0 | @barissozudogru | TypeScript | `barissozudogru/gha-cost` | 1 | -| 0 | @gamemann | GDScript | `gamemann/game-playground` | 1 | -| 0 | @kenjinote | Python | `kenjinote/blog` | 131 | -| 0 | @manman4 | C | `manman4/OEIS_04` | 21 | -| 0 | @matigulin | TypeScript | `matigulin/maze-ui` | 6 | -| 0 | @metatronslove | - | `metatronslove/github-repo-traffic-viewer` | 1 | -| 0 | @rzrabbi | Markdown | `rzrabbi/upptime` | 1 | -| 0 | @sdiehl | Rust | `sdiehl/groebner` | 8 | -| 0 | @standardgalactic | TeX | `standardgalactic/alphabet` | 268 | -| 0 | @thejesh23 | Python | `thejesh23/ai-plugin-rankings` | 1 | -| 0 | @zhenrez | JavaScript | `zhenrez/ARTTOO` | 0 | -| 1 | @Ali-hey-0 | - | `Ali-hey-0/Cryptography` | 157 | -| 1 | @DarkGlitchLegion | Python | `DarkGlitchLegion/alarm` | 0 | -| 1 | @Lxcardoza993 | Python | `Lxcardoza993/LLMDOG` | 10 | -| 1 | @Sheetal-Patel17 | JavaScript | `Sheetal-Patel17/DevCareerOS` | 2 | -| 1 | @edrfjk | PHP | `edrfjk/nexhris` | 4 | -| 1 | @jfullstackdev | CSS | `jfullstackdev/jfullstackdev.github.io` | 9 | -| 1 | @markbakos | Rust | `markbakos/preflightx` | 0 | -| 2 | @Aegean-E | Python | `Aegean-E/ObesityResearch` | 0 | -| 2 | @Obraims | HTML | `Obraims/web-foundation-days` | 0 | -| 2 | @a-partovii | Python | `a-partovii/on-click-venv` | 1 | -| 2 | @eatsky1006 | - | `eatsky1006/main-goal-main` | 0 | -| 2 | @stevsharp | C# | `stevsharp/Shipping-strategy-demo` | 1 | -| 2 | @tawdesangeeta1973-coder | - | `tawdesangeeta1973-coder/arc-propose-verify` | 1 | -| 3 | @Nour-yahyaoui | Rust | `Nour-yahyaoui/c-editor` | 1 | -| 3 | @Simontechempire | JavaScript | `Simontechempire/SHADOW-X-MD` | 1 | -| 3 | @Sthabiso10 | Dart | `Sthabiso10/Spella` | 0 | -| 3 | @ThakurDivyanshsingh-77 | Jupyter Notebook | `ThakurDivyanshsingh-77/apple_iphone_data_analysis_project` | 2 | -| 3 | @arch-yunus | JavaScript | `arch-yunus/gsb-france-exchange-2026` | 2 | -| 3 | @dovvnloading | Python | `dovvnloading/Cortex` | 37 | -| 3 | @genius-0963 | Python | `genius-0963/Real-time-recommendation-engine` | 0 | -| 3 | @tsnobip | ReScript | `tsnobip/goutues` | 1 | -| 4 | @holilayet | JavaScript | `holilayet/ZoneWeb3` | 3 | -| 4 | @murapadev | C# | `murapadev/NeuralDeck` | 5 | -| 5 | @neoscratchteam | TypeScript | `neoscratchteam/NeoScratch` | 5 | -| 5 | @nearyou | TypeScript | `nearyou/freedomsword` | 0 | -| 5 | @stackpilot05 | - | `stackpilot05/BlackDragon0828` | 14 | -| 6 | @MiladJoodi | JavaScript | `MiladJoodi/MiladJoodi.github.io` | 30 | -| 7 | @Kelpejol | Python | `Kelpejol/Orgos` | 0 | -| 8 | @adriannoes | Jupyter Notebook | `adriannoes/awesome-agentic-ai` | 63 | -| 8 | @aruintelligence | JavaScript | `aruintelligence/aml-core` | 0 | -| 8 | @captainblair | TypeScript | `captainblair/Nexa` | 0 | -| 8 | @lshariprasad | C++ | `lshariprasad/BULIDATHON-2026` | 1 | -| 10 | @Gleb-Shalygin | PHP | `Gleb-Shalygin/course-builder` | 1 | -| 10 | @dbunt1tled | Go | `dbunt1tled/parquet2csv` | 66 | -| 10 | @kulikov-dev | - | `kulikov-dev/prm-config` | 1 | -| 10 | @manvesh1234 | JavaScript | `manvesh1234/Experiments-` | 0 | -| 11 | @engrshuvodas | JavaScript | `engrshuvodas/GrandPulse` | 2 | -| 11 | @mikalv | Ruby | `mikalv/homebrew-prism` | 0 | -| 11 | @xuges | Go | `xuges/remote-shell` | 0 | - -*(showing the 70 most active; the remaining 85 are in the same file — the pattern is the same.)* - -### 5.2 Profile-only / no substantive public code (59) - -@00200200, @AhmedDabish, @AlmigthyMatheus, @BEPb, @ByteBunny777, @ChevCellios, @Eliasilyz, @Fahad-40, @Hamidooh, @IDouble, @Isac999, @JawherKl, @JessicaDevOp, @JohnMwendwa, @JoshuaJewell, @MahdiKordian, @Maher-Elmair, @MdShawonForazi, @MrMDrX, @OfficialCodeVoyage, @YemotaY, @YucongDuan, @ardaltunel, @arindam-codes, @ashhim, @bariewakjira-coder, @chatman-media, @d4vucat, @desaiishaan2-rgb, @devlewicki, @felicityblueish, @fhammerschmidt, @ghostworker13, @gitfullstacker, @jeallz, @joaocarpim, @kashifkhan117401-bit, @kyal102, @laigit-dot, @lxRbckl, @lxlynx, @mcdev7777, @mennylevinski, @noorgx, @nshkrdotcom, @paren-thesis, @rahuloraj, @realtonkaa, @sarahofai, @shahidazam2020-oss, @sheriffsec, @shivam01112, @shroukmohamed5, @sinajr2011-prog, @soham-kyo, @tsyganovvv, @tysoncung, @userAshwani, @yeabsiragebre - -### 5.3 Inactive (>180 days) (34) - -@AbSomeone, @Ashkan-P88, @ChungusLord123, @Damadel, @HalfFriedPotato, @Kovbo, @MJ-ulia, @RC00K, @Sewiahho, @Top-coin, @akilegaspi, @alvrenkai, @bittin, @cumsoft, @dribrahimfurkansarkim, @iamapuneet, @imranmalakzai, @jelspace, @nikhilpatidar01, @retrobullseye, @rodrigogalura, @sabbir-noyon, @sara8086, @selinamiller183-dot, @smoonthsky, @suliman-al-tech, @sunaynatalreja, @szenled, @talorcan, @vanohj, @whiteplaine, @yahyamallak, @zainab0077, @zombietfk - - ---- - -## 6. Honest coverage statement, and how to continue - -**What this file contains:** 12 deep notes (code read, file + commit pinned) and 2 lighter -notes, plus a triage of the whole follower list. - -**What it does not contain:** 269 notes. That number is not achievable at the standard these -drafts set — "read what they are doing, find the recent code that shows the struggle, name one -artefact that actually helps" — because most of the list does not have public code, and -inventing a hook for someone whose last push was a profile README would damage exactly the -credibility the notes are for. The measured picture: of 269 followers, **59** have no -substantive public code at all, **26** are inactive, and of the active remainder the majority -are small personal or portfolio projects with no visible engineering struggle to hook to. - -**The realistic ceiling, if you want it pursued properly:** roughly **35–50** accounts are -hookable, of which **14** are drafted here and **15** are named in §4 as the next-up set. That -is about two more passes of this work. - -**Options for continuing:** - -1. **Finish the plausible set** — work §4 next (15 accounts), reading code and drafting to the - same standard, then re-scan the active-with-code list for anything missed. Two passes. -2. **Target by repo family** — tell me which of the seven you want to *promote* through outreach - (e.g. only occupancy + tropical, the two with the most consumer-shaped surfaces) and I will - mine the list for that family only, which will find matches I would skip under a - breadth-first sweep. -3. **Reply-handling pack** — for anyone who answers, prepare the one-file follow-up each note - promises (the two definitions, the monoid, the interface) so you are never the bottleneck. -4. **A public artefact instead of 269 DMs** — one short write-up ("what I look for when a - codebase has a projection/receipt/bound problem, with four worked examples from real repos") - would reach the same audience at a fraction of the effort, and is citable. Several of these - drafts could become its sections without the recipients ever being named. - -**One caution on the whole enterprise.** These notes work because the hint is *narrow and -falsifiable* — "your ranges need a declared algebra", "your limitation strings need rejection -fixtures", "treat `STARTUP_FAILURE` as failure". If they are broadened into "here is my research -programme", they stop being useful and start being noise, and the 269-message version of that -failure is a reputational cost rather than a saving. diff --git a/docs/recon/TYPE-FAMILY-POSITION-2026-10-04.adoc b/docs/recon/TYPE-FAMILY-POSITION-2026-10-04.adoc new file mode 100644 index 0000000..d1dd2ea --- /dev/null +++ b/docs/recon/TYPE-FAMILY-POSITION-2026-10-04.adoc @@ -0,0 +1,711 @@ += Type-family position — deep recon + +_Date of recon:_ 2026-10-04 · _Prepared in:_ `occupancy-types` @ `arena/01a1087c-occupancy-types` +_Scope:_ `echo-types`, `epistemic-types`, `residual-evidence-types`, `choreographic-types`, +`tropical-types`, `occupancy-types`, `absolute-zero`, plus the coordination hub +`nextgen-typing` and the satellite repos. + +''' + +== 0. How to read this, and how much to trust it + +The estate is unusually well instrumented for honesty — AFFIRMATIONs, PROOF-STATUS +receipts, retraction ledgers, kill criteria, blocked-item registers. This document tries +to hold to that same standard, so every claim below is tagged with _how we know it_: + +[cols="1,1",options="header"] +|=== +| Tag | Meaning + +| _[RAN]_ | I ran the command in this session and saw the result. First-hand. + +| _[CI]_ | A hosted CI job on the recorded commit passed; run id/URL given. + +| _[DOC]_ | The claim is the repo's own recorded status (PROOF-STATUS / AFFIRMATION / STATE / README), reproduced by an author in a stated environment, _not_ re-run by me and not covered by a CI receipt in this recon. + +| _[ISSUE]_ | The claim comes from a filed issue (i.e. a known, acknowledged defect or task). + +| _[INFER]_ | My inference from file evidence; stated plainly as such. + +|=== + +_Calibration — what this session could and could not do._ This sandbox has +`python3` and `git` only. It has _no_ `agda`, `lean`/`lake`, `idris2`, `coqc`, +`isabelle`, `mizar`, `z3`, `just`, `bun`, or Rust toolchain. Therefore: + +* Every Agda / Lean / Isabelle / Coq result is _[DOC]_ or _[CI]_ — I did _not_ + re-typecheck any proof. Where a hosted run exists, I cite the run id. +* The one proof-adjacent thing I could re-run was `occupancy-types`' Session IR gate — it + passed 14/14 _[RAN]_. +* Repo trees, docs, roadmap text, ledger entries, workflow contents, CI conclusions, + issue text and commit signatures were all read directly from clones and the GitHub API. +* CI conclusions were read from the API, not inferred from READMEs or badges. + +_Anchor pins_ (HEAD at recon time; all commits GPG-verified _[API]_): + +[cols="1,1,1",options="header"] +|=== +| Repo | HEAD | Date + +| echo-types | `da140cc26f` | 2026-10-03 + +| epistemic-types | `eb810d4ee7` | 2026-10-04 + +| residual-evidence-types | `62d7490754` | 2026-10-02 + +| choreographic-types | `71ba51d3b8` | 2026-10-03 + +| tropical-types | `ad7bfdfd56` | 2026-10-03 + +| occupancy-types | `2e276c365f` | 2026-10-04 + +| absolute-zero | `5f27136835` | 2026-10-02 + +| nextgen-typing | `70df154951` | 2026-10-01 + +| EchoTypes.jl | `a0ac9131f7` | 2026-10-01 + +| EpistemicTypes.jl | `6ab3fb4a01` | 2026-10-01 + +| ResidualEvidenceTypes.jl | `abe97d5c99` | 2026-10-01 + +| secret-types | `aed3f1cc2d` | 2026-10-04 + +|=== + +=== The three-tier vocabulary used throughout + +* _There (established)_ — a machine-checked artefact exists _and_ it is either + receipted by a current CI run or reproducible by a named local command; the claim is + fenced by an explicit written boundary. +* _Nearly there_ — the artefact exists in the tree but one link is missing: no CI lane, + no toolchain run, an unwired module, a stale state file, or a theorem that is true but + degenerate relative to the claim it is cited for. +* _Within reach_ — the repo's own next step, already specified in a roadmap, ledger + entry, or open issue, needing no new research — only work. Everything beyond this line + is named as _open research_ rather than aspiration. + +''' + +== 1. The estate map (as it stands) + +The five research families and their owning repos, with questions and boundaries exactly +as `nextgen-typing`'s shared guide states them _[DOC: TYPE-CONNECTIONS.adoc]_: + +[cols="1,1,1",options="header"] +|=== +| Family | Question | Fence (what it is _not_) + +| _echo-types_ | Which possible origins lie over an output after a transformation? `Echo f y = Σ (x : A), f x ≡ y` | An output need not identify its origin; a numeric residue measure does not determine residue structure + +| _epistemic-types_ | From which standpoint is a claim available, with what evidence? `E κ A` | Having evidence ≠ proof of the claim; belief/knowledge/sound warrant have different interfaces + +| _tropical-types_ | How do declared resource bounds compose? | The algebra must be stated; a bound is neither a probability nor an Echo residue identity + +| _residual-evidence-types_ | Which worlds satisfy an observation _and_ its evidence constraints? | Constructing a candidate does not recover the world; real-world soundness needs the actual-world premise + +| _choreographic-types_ | What happens to distinctions, bounds and warrants under projection to participants? | A causal-order cut is not Gentzen cut-elimination, nor causal identification; the general K-CUT is open + +|=== + +Neighbours in the same map but _out of the type family proper_: + +* _occupancy-types_ (this repo) — _state_ resource grades (HWM monoid, non-commutative), + deliberately separated from tropical _cost_ grades; session/protocol frontier reclamation. +* _absolute-zero_ — CNO (certified null _effect_) and OND (certified null _disclosure_); + a multi-prover effort with an Echo bridge module. Not one of the five families; connected + to them (and proposed for a map row in absolute-zero#175 _[ISSUE]_). +* _secret-types_ — new (created 2026-09-27), specification-stage only. Owner ruling + 2026-10-04: this is the home for secret types; `epistemic-types` adds no Secret API; + epistemic-types#29 closed, #32 transfer pending GitHub issue-write access _[DOC: STATE.a2ml]_. +* _nextgen-typing_ — the coordination hub: shared glossary, ownership routing, the + cross-project proof. It hosts no family code. + +_Vocabulary fences that are load-bearing and currently holding_ (worth stating because +they are the estate's main defence against concept collapse): + +[quote] +____ +cost grade ≠ occupancy (HWM) grade ≠ echo index ≠ residue measure ≠ warrant ≠ residual +____ + +The guide is explicit that the five families are **complementary questions, not ranks of +type-system strength**, and that dashed arrows in the map assert *conceptual use or a +proposed research task* — not dependency, equivalence, or a checked bridge +_[DOC: TYPE-CONNECTIONS.adoc]_. + +''' + +== 2. Per-repo deep recon + +=== 2.1 `echo-types` — the most developed family member + +_What it is._ Constructive Agda formalisation of proof-relevant fibres as witnesses of +structured (non-total) information loss. 209 `.agda` files under `proofs/` _[RAN: file count]_; +the verified closure (`proofs/agda/All.agda`) is described as ≈200 modules and +_postulate-free_. + +_There (established)._ +* The Agda suite typechecks under `--safe --without-K`, and the _hosted Agda job is green_ + on current main: run `37152181722` @ `da140cc2`, 2026-10-03 _[CI]_. +* A canonical-identity spine landed 2026-05-27: `EchoTotalCompletion` (`A ≃ Σ B (Echo f)`), + the (equivalence, projection) factorisation, no-section results, four-axis loss/residue + taxonomies, and audience modules _[DOC: PROOF-STATUS, README]_. +* _Matched-negative separation proofs_ — where the identity claim does its real work: + Echo is not distinguished by Shannon entropy; the LL `!A := 1` shallow-encoding gap; + equal measure ⇏ equal Echo (`Echo.Separation.NotResourceInstance`) _[DOC]_. +* An ordinal/Buchholz track with a sound carrier: doubled-ladder well-foundedness, + Brouwer `ω^^_`/`ε₀`, and a real Buchholz notation order with well-foundedness _[DOC]_. +* Retraction discipline: R-2026-05-18 narrowed four headline claims (graded comonad → + thin-poset reindexing modality; universal property → funext-relative pointwise mediator; + model-independence → carrier-parametricity; conservativity metatheorem → postulate-free + build that is _evidence for_, not proof of) _[DOC: AFFIRMATION, roadmap]_. +* A cross-project proof `EchoTyping.agda` (XP-1: pipeline information-loss = echo fibres, + spanning echo-types ↔ affinescript ↔ typed-wasm) lives in `nextgen-typing` _[DOC]_. + +_Nearly there._ +* _Identity gates are at PROVISIONAL / PASSED-narrowed, none STABLE-ESTABLISHED_ + (Gate 1 PROVISIONAL, Gate 2 PASSED (narrowed), Gate 3 PROVISIONAL) _[DOC: roadmap]_. +* _WFS, not OFS_: diagonal lifts and uniqueness-up-to-iso exist, but unique diagonal + fills are unproved; the module name `EchoOrthogonalFactorizationSystem` overstates the + target (renaming pending) _[DOC: README caution block]_. +* _Lane 1 (type-theoretic standing) is IN-REPO CLOSED, EXTERNALLY OPEN_ — the paper is a + living draft; the offline half (submission, DOI, packaging) is author-driven _[DOC]_. +* `experimental/echo-additive` (7 modules incl. the `Grade` dioid) is _in no CI lane_ + _[ISSUE #321]_; 4 bit-narrowing modules are similarly unlaned _[ISSUE #320]_. +* Doc/toolchain debts: `README.adoc` still carries RSR `+{{PLACEHOLDER}}+` template material + while `README.md` is canonical _[RAN: file read]_; `agda.yml` installs an unpinned + `apt-get agda` _[ISSUE #322]_; governance red on `CONTRIBUTING`/gitleaks + _[ISSUE #323]_; CodeQL startup-failure _[ISSUE #269]_. + +_Within reach._ Rename to honesty (`EchoWeakFactorizationSystem`); wire the unlaned +experimental modules into CI; clear the packaging/DOI half of Pillar E; refresh +`README.adoc` out of template state. + +_Open research (not reachable by wiring)._ Bachmann–Howard `ψ₀(Ω_ω)` order-type fidelity +(D-2026-06-14, _OPEN_ — `ε₀ ≪ Γ₀ ≪ …`); the two quarantined postulates in +`Ordinal/Buchholz/Fidelity.agda`; the `∥_∥` image truncation (cannot be built under +`--safe --without-K` without HITs — present only in a `--cubical` island); the unbudgeted +global `wf-<ᵇʳᶠ` (walled: the native order is ordinally unsound, with a documented +counterexample). + +''' + +=== 2.2 `epistemic-types` — small, self-contained, genuinely green + +_What it is._ A minimal-of-design Agda prototype for standpoint-indexed modalities, +separating knowledge (factive) from belief (non-factive) and warrant from sound proof. +The base modality is deliberately _not_ a monad or comonad. + +_There (established)._ +* The **whole library type-checks under `--safe` with zero postulates and no standard + library** (`--no-libraries`, only `Agda.Builtin.*`), and the **hosted `Proof Safety` job + is green on the current HEAD*: run `37187387026` @ `eb810d4e`, 2026-10-04 *[CI]**. +* Module inventory is concrete: 17 modules listed in STATE, including `Base`, `Warrant`, + `Access`, `ProofTransport`, `ReadConsistency`, `EchoBridge`, `SurrealBridge`, and an + Applications layer _[DOC]_. +* The _Applications layer (2026-09-27)_ is a real worked result, not a demo: + `QCriterion.qBound-≤-Q` over an arbitrary `OrderedGroup`; `RapidNJSkip` generating a + warrant from a skip certificate with `skip-known` proved; `IntegerModel` discharging the + arithmetic budget; a rejection fixture for an unchecked check _[DOC: PROOF-STATUS]_. +* Explicit non-claims are recorded: no ℚ instance, no rescaling transport, no row-insertion + update, no cross-iteration bound reuse _[DOC]_. +* Concrete Echo adapter: `SurrealBridge` relaxes a proved upper bound on a residue measure + along the access order while preserving the retained value; the `daySurrealAccess` + instance is explicitly a set-sized fragment, _not_ the Conway proper class _[DOC]_. +* `ReadConsistency` was corrected so `ReadView` entails equality with indexed store + contents; the older version-only relabelling and free `Sync` witness were _removed_ + _[DOC]_. + +_Nearly there._ +* STATE calls it `prototype` / `experimental` at _35% completion_, last-updated + 2026-10-04 — i.e. the repo itself does not claim maturity _[DOC: STATE.a2ml]_. +* The Applications obligations are named but unmet (rational instance, rescaling + transport, row-insertion invariants). +* The proof-transport soundness story is qualified ("holder-dependent transfer is + explicitly qualified") _[DOC]_. + +_Within reach._ Close the named Applications obligations; settle the secret-types +handover (epistemic-types#32 transfer is blocked on GitHub issue-write access — an +_administrative_ blocker, not a technical one) _[DOC/ISSUE]_. + +_Open research._ Whether `bind`/`extract` structure is wanted at all (currently a +deliberate "future commitment, not a hidden assumption"); the soundness map from evidence +to claim meaning under a standpoint index. + +''' + +=== 2.3 `residual-evidence-types` — newest, fastest-moving, and the only family with a machine-checked _correspondence_ + +_What it is._ Evidence-indexed residual types: which worlds are compatible with an +observation _and_ its declared evidence constraints, and what holds for all of them. +Founded 2026-09-09 from imported Windows-Downloads material (assessment + a standalone +HTML/JS explorer), with _all core work newly written in-repo_. + +_There (established)._ +* _Milestone 1_ — presence without identification (`u+n=2`, `n≤1` establishes `u≠0` + while `(1,1)` and `(2,0)` still disagree), evidence-refined fibre round trips, + conditional actual-world soundness, claim transport under refinement; three invalid + modules must be rejected by Agda _[DOC]_. +* _Milestone 2_ — contexts of assumptions with thinnings, dependency-preserving + composition and coarsening, constructive revision and retraction, **a certified finite + checker proved equivalent to the explorer by `refl` over all 546 configurations** + (`Correspondence.checker-matches-explorer`), and nine expected-rejection controls + _[DOC]_. +* _Both sibling interfaces are actually imported_ — Echo's fibre packaging round-trips, + and Epistemic's `SoundWarrant` requiring explicit actual-world premises — pinned to + sibling heads (`echo-types` `9c4b72b5`, `epistemic-types` `dd948fbd` for M1) _[DOC]_. +* Hosted _`Agda proofs` job green_ on the current HEAD: run `36949121242` @ `62d74907`, + 2026-10-02, and a prior receipt run `36740394802` @ `befdf964` _[CI/DOC]_. +* The repo is scrupulous about the limit: the correspondence certifies the *finite checker + against the explorer*, _not_ the ℕ core against the explorer _[DOC]_. + +_Nearly there._ +* `STATE.a2ml` (last-updated 2026-09-09) is _stale_: it still lists composition, + revision/retraction, the certified checker and the explorer correspondence as _pending_ + — all of which Milestone 2 landed _[RAN: file read vs PROOF-STATUS]_. +* The two sibling comparisons cover _Milestone 1 only_; whether composition/revision need + an interface beyond `Echo.Echo` and `SoundWarrant` is the explicitly open question + _[DOC]_. +* A separate "starter archive" named in the imported assessment has _not been recovered_ + and the repo does not pretend otherwise _[DOC]_. +* Codeac status has been pending on main since 2026-09-24 _[ISSUE #11]_. + +_Within reach._ Refresh STATE; run comparisons 2.0 (post-M1 interfaces); the explorer's +signed −6..6 model is already the certified finite object, so further finite-model checks +are cheap. + +_Open research._ Causal specialisation and probability adapters — both explicitly require +models and obligations of their own _[DOC]_. + +''' + +=== 2.4 `choreographic-types` — a pre-registration, and it says so + +_What it is._ The assembly hypothesis: grade a global choreography with echo _loss-grades_ +and epistemic _standpoint-warrants_, project to participants, and ask whether grading and +transport commute with projection across a consistent frontier (a _cut_). The keystone is +_K-CUT_, split into K-CUT-LOSS (equality) and K-CUT-WARRANT (bound, under a `SoundWarrant` +side-condition). + +_There (established)._ +* _The specification and its fences._ The pre-registration (2026-10-03) states that + K-CUT-LOSS and K-CUT-WARRANT remain _OPEN_, that `SoundWarrant` is an *assumed + receiver-local side-condition*, and that the application Agda file **"contains postulates, + not proofs"_ and is not imported by any build _[DOC: docs/pre-registration.adoc]**. +* `CITATION.cff` no longer claims a completed Agda formalisation; integrity checks now fail + such claims on description-mirroring surfaces _[DOC]_. Issue #15 records that the + README/description still overstate _[ISSUE]_. +* CI's two substantive checks — `Secret Scanner` and `Documentation Integrity` — are both + green _[CI]_. There is _no prover workflow at all_, by design at this stage. + +_Nearly there._ +* The _degenerate base case exists and is real_, but it is a sibling's theorem: + `characteristic/RoleGraded.choreo-grade-commute` in `echo-types` — two actions (role + transport × grade degradation) commuting on one Echo-indexed family, satisfying the + "same data" test that struck down the earlier N3 nominee _[DOC/RAN: file read]_. + It is a _single-static-edge integration theorem_, not K-CUT. echo-types' own audit + _declined to adopt it as nominee N5_ on the grounds that its only non-trivial cell is + already credited elsewhere (adoption would be cosmetic) _[DOC: N5Falsifier, IntegrationAudit]_. +* The smallest concrete target is specified: a two-event K-CUT-LOSS commuting square under + an `Independent₂` witness, with the witness required to carry disjoint read/write + footprints, phase safety and a deterministic tie policy _[DOC]_. +* A vocabulary obligation is open: the choreographic README's phrase "echo loss-grade" + conflicts with the estate's separation of echo index / residue measure / resource grade; + reconciling it is a _coordination task_ in the hub roadmap _[DOC: TYPE-CONNECTIONS]_. + +_Within reach._ Wire the existing `rapidnj-two-thread.agda` postulates into a real +minimal proof of the two-event square; land the `Independent₂` witness; reconcile the +vocabulary with the shared glossary. None of that requires solving K-CUT. + +_Open research._ K-CUT in general (both fragments) — the repo's own honest position is +that the general result is open and only degenerate single-static-edge cases exist. + +''' + +=== 2.5 `tropical-types` — dual-formalised, one half verified, one half CI-gated-by-claim + +_What it is._ Max-plus / min-max algebra applied to resource-aware typing: compositional +worst-case bounds for latency, stack use and adversarial round counts, plus a reusable +resource-grade axis for downstream languages. _Note the prover split_: this family is +_Lean 4 + Isabelle/HOL_, not Agda. + +_There (established)._ +* _Lean 4 — verified and CI-gated._ `lake build` green, no Mathlib, toolchain pinned in + `lean-toolchain` (`v4.13.0`); hosted _`Lean` job green_ on current main: run + `37116071270` @ `ad7bfdfd`, 2026-10-03 _[CI]_. PROOF-STATUS records a clean rebuild of + _20/20 targets_ including `TropicalSessionTypes.lean` (max-plus session grading), + `TropicalAdapterPath.lean` (min-max bottleneck transport + the `hub_ceiling` no-go), + the `Resource/Algebra` interface with a _parametric transport theorem_, and concrete + instances (MaxPlus, MinPlus, MinMax, Linear, Affine) _[DOC]_. +* The two twins are related by an order-reversing involution proved as a **lattice + anti-isomorphism** and explicitly _not_ a semiring homomorphism — a structural fact, + stated as such _[DOC]_. +* `Resource/EchoBridge.lean` is an _echo-free residue-measure bridge_ (no dependency on + the echo-types Agda kernel; the relationship is at design level) _[DOC]_. + +_Nearly there._ +* _The Isabelle half is not verified in the recon sense._ Nine `.thy` theories exist and + the session is meant to be CI-gated by `just isabelle-build` + `just check-sorry`, but + _no workflow mentions Isabelle_; `ROOT` lists _5 of 9_ theories; PROOF-STATUS itself + says the Isabelle side was _"NOT re-verified in this environment"_ _[DOC]_. +* Issue #57 states the contradictions directly: the claim is CI-gated but nothing gates it, + ROOT covers 5 of 9, and STATE says GREEN and RED for the same theory _[ISSUE]_. +* The `CI context contract` job is red on recent commits (required-status-check drift); + it is the repo's own guard for `docs/CI-CONTEXTS.adoc` and it fails for that documented + reason — a CI-hygiene red, not a proof red _[CI]_. +* The no-go theorem `hub_ceiling` refutes Protocol Squisher's universal-interoperability + claim — real, but it is a _no-go_, not a capability _[DOC]_. + +_Within reach._ Extend `ROOT` to all nine theories; add the Isabelle job; delete the +residual Deno test files (Deno is banned estate-wide _[ISSUE #58]_); SHA-pin the two +tagged `actions/checkout` uses _[ISSUE #59]_. + +_Open research._ The Buchholz-collapsing ladder (Rungs 2–N, 0% per STATE); tropical time +series (Diehl–Ebrahimi-Fard–Tapia); a probabilistic extension; a Lean tactic for automated +grade calculation. + +''' + +=== 2.6 `occupancy-types` (this repo) — pre-registered, locally reproducible, CI-disarmed + +_What it is._ Stepwise resource-bounding types: deterministic memory first, network +second. The organising claim is that _cost and state are different axes_: cost composes +with `+` in sequence and `max` across alternatives (tropical), while _state_ resources +(pools, buffers, credits, FDs) compose by the _non-commutative high-water-mark monoid_ +`(p₁,n₁)·(p₂,n₂) = (max(p₁, n₁+p₂), n₁+n₂)`. Buffer = memory, and the **protocol frontier +is the reclamation point**. The whole thing is pre-registered in `ULTRAPLAN.md` with +per-rung kill criteria and a decision log (D1–D7). + +_There (established)._ +* _R0-B, Phase 1 — Session IR checker: TESTED. I re-ran it in this session:_ + `PYTHONPATH=src python3 -m session_ir test examples/session_ir/manifest.json` → + _14/14 PASS_, exit 0 _[RAN]_. Seven accept cases with measured steps ≤ certified + bound (including a strict case: certify 5 / measure 4, and a tight case: 6/6) and seven + expected-rejection controls each pinning an error class (double-send, use-after-drop, + protocol mismatch, close-before-End, double-free, leak, alias) _[RAN]_. +* The operational model exists and its Phase-0 kill test is _mechanically audited_ + (four sentences, banned word absent) _[DOC: EXPLAINME C3]_. +* The honesty apparatus is real and already in use: `docs/EXPLAINME.adoc` classifies every + claim as TESTED / UNVERIFIED / CONJECTURE, and `docs/retraction-ledger.adoc` records + blocked rungs (with exact unblocking commands) separately from retractions — with **zero + retractions so far* and three blocked items *[RAN: file read]**. +* The estate placement is correct and deliberate: registered against the cost/state + vocabulary split, with "not echo, not warrant, not residue" written into the plan + _[DOC: ULTRAPLAN §5]_. + +_Nearly there (blocked, not disproved)._ +* _Idris 2 Occupancy spike — UNVERIFIED._ `src/occ/Occ.idr`, `Demo.idr` (static peak = K + = 2 producer/consumer) and four rejection controls exist; no `idris2` on the work + environment's PATH _[DOC/RAN: toolchain check]_. The kill question (are constant grades + tolerable _and tight_?) is answered only provisionally, and the repo labels the answer + CONJECTURE. +* _R1 stackcert — UNVERIFIED._ `src/stackcert/StackcertCore.lean` with the target theorem + `cert_sound`, plus fixtures generated by real `gcc -fcallgraph-info=su -fstack-usage` + _[DOC]_, but no `lean` locally and no `#print axioms` footprint pasted. The expected + empty axiom list is _explicitly marked CONJECTURE until pasted_ _[DOC: EXPLAINME C5]_. +* _Ground truth — BLOCKED._ Zephyr painted-stack HWM on `qemu_cortex_m3` is a **fixture + request**; nothing is measured until it runs. The plan's own rule is "measured ≤ certified + on every run, violation = stop" — so R1 cannot be _closed_ without this _[DOC]_. +* _CI is comprehensively non-functional._ 96 of the last 100 workflow runs on this repo + concluded `startup_failure`, including on `main` pushes by the owner actor; _every_ + gate — Rust CI, Dogfood, Static Analysis, Invisible Character Detection, K9, Secret + Scanner — dies before starting a job _[CI/API]_. The estate has two _documented_ + mechanisms that produce exactly this signature: (a) an Actions allow-list posture of + `selected` with _0 patterns_, which kills any workflow whose step references a + non-allow-listed action, `jobs=0` (choreographic-types#16, with a produced mutant + proof); (b) an actor gate refusing workflow triggering for a given actor + (echo-types#330). The precise gate for _this_ repo is _not established_ from here, and + unlike its siblings this repo carries _no open issue_ about it (it has no open issues + at all). Consequence: _none of this repo's checks are currently machine-enforced_; + the local gates are the only source of truth. +* `README.adoc` is still RSR template material (self-declared in-file) _[RAN]_. + +_Within reach (needs a toolchain or a settings change, not research)._ Install +`idris2` → run the spike and its four controls; install `lean`/`lake` → run stackcert and +paste `#print axioms cert_sound`; obtain the Zephyr fixture; fix the Actions settings +(owner-only PUT) and file the missing issue for this repo; refresh `README.adoc` from the +template. + +_Open research (the actual rungs)._ R2 static pools + affine/linear handles with the T1 +coherence theorem (project gate after R2); R3 binary session channels with HWM buffer +grades; R4 network-calculus curves over ℕ/ℤ without reals; R5 multiparty projection and the +projection/grade commutation question; Phase 5 host-tool contract. The pre-written kill +criteria are, correctly, part of the design: R2 archives the project if there is no external +consumer for certificates and no theorem beyond restatement. + +''' + +=== 2.7 `absolute-zero` — the most _concretely_ verified repo in the estate + +_What it is._ Two co-equal pillars — _CNO_ (a program that provably does nothing to the +world) and _OND_ (a program whose observable trace is constant over its secret input, +relative to a declared observation model `O`). The pillars are logically independent (a +proved theorem) and joined by a _coupling dial_ that is explicitly _framing, not theorem_. + +_There (established)._ +* _A single gate reproduces everything locally_: `proofs/verify-all-provers.sh` → + `ALL-PROVERS-GREEN` across _Coq, Agda, Lean 4 (+Mathlib), Z3, Isabelle/HOL, Mizar_, plus + the _Idris 2 ABI_, with an absent prover treated as _failure, never skip_ (since + 2026-09-23), Z3 verdicts checked against `; expect sat|unsat`, and a Coq + `Print Assumptions` audit with its own control _[DOC: PROOF-STATUS]_. A gate self-test + proves the gate turns red for each absent/failing prover and each verdict/audit mutant + (16 cases, run in CI) _[DOC]_. +* _CI Proofs job green_ on current main: run `37077637092` @ `5f271368`, 2026-10-02 + _[CI]_. The workflow runs the lightweight provers (Coq 14/14 theories, Agda CNO+OND, + Z3 CNO+OND, Mathlib-free Lean core with an `AxiomAudit`); the heavy provers are covered + only by the local container gate — and the workflow says so in its own header **[RAN: + workflow read]**. +* _OND-1..5 and OND-7 are landed_ — proved in Coq with _zero axioms_ (every theorem + `Closed under the global context`), mirrored in Lean 4, Agda and Z3 _[DOC]_. +* _CNO axiom discharge 98 → a small classified remainder_, with the pathological cases + found and fixed rather than hidden: `no_cloning` and `Cconj_Cexp` were _provably false_ + and removed; `eta_equivalence` was _false as stated_ (counterexample `f = LVar 5`) and + replaced by an honestly guarded theorem _[DOC]_. Remaining axioms are tagged either + `METAL-BOUNDARY` (genuine physics: `kB>0`, `temperature>0`, Second Law, Landauer) or + _class-A_ (true, provable in principle, listed with blockers — 4 items) _[DOC]_. +* An _Echo bridge exists in Agda_ (`EchoBridgeCNO.agda`): `EchoRel` instantiated + against real `CNO.Program`/`CNO.eval` with `CNO.state-eq` _[RAN: file read]_. +* Roadmap restraint is explicit: the long-horizon "universal CNO standard" is quarantined + in an appendix as _aspirational and unfunded_, "a direction of travel, not a + commitment with a date" _[DOC]_. + +_Nearly there._ +* _OND-6_ (conditional composition) is _open by design_ — the research capstone. The + roadmap warns, correctly, that if composition appears to hold as cleanly as for CNOs the + result has almost certainly dropped a term _[DOC]_. +* _CI is weaker than the local gate_ and the repo knows it: for a time Isabelle and Mizar + printed "skipped" while the gate said GREEN; that is fixed in the local gate, but + absolute-zero#161 records that the `Proofs` workflow still has a `paths:` filter, + `z3 … || true`, and no assumption check _[ISSUE]_. +* _Documentation drift_: `ROADMAP.adoc` (last updated 2026-07-07) still lists as pending + the Idris ABI repair and "make CI truthful: run Coq+Agda+Rust", both since superseded by + `PROOF-STATUS` and the current workflow _[RAN: file comparison]_. +* 73 of 182 Coq theorems rest on axioms and 38 `Axiom`/`Parameter` declarations use four + tag forms (unify grammar, generate census) _[ISSUE #171]_; 2 Idris2 postulates in + `src/abi/Layout.idr` remain _[ISSUE #27]_; Scorecard has 5 high alerts _[ISSUE #170]_. + +_Within reach._ Make CI mirror the local all-provers gate (fix #161); unify the axiom tag +grammar and publish the census (#171); port the Coq filesystem model to Lean so the +`FilesystemCNO` law axioms become theorems (#167); refresh the roadmap against PROOF-STATUS; +the artifact-evaluation one-command container. + +_Open research._ OND-6 conditional composition; the 4 class-A Coq items +(`CNOT_gate_unitary`, `unitary_inverse_property`, `fidelity_bound` need a finite-dim/tensor +model; `y_not_cno` needs a coinductive/step-indexed β non-termination argument); the paper. + +''' + +== 3. The hub, the satellites, and the name-collisions + +=== 3.1 `nextgen-typing` (coordination) — the map is the artefact + +* Hosts the shared glossary, ownership routing and the _XP-1 cross-project proof_ + (`verification/proofs/agda/EchoTyping.agda`, `--safe --without-K`, spanning echo-types ↔ + affinescript ↔ typed-wasm) _[DOC]_. +* _But nothing runs it_: nextgen-typing#57 records that no CI job runs + `just proof-check-all` _[ISSUE]_. The estate's only cross-project proof is therefore + unenforced. +* Open coordination tasks relevant to the family: *#118* register `occupancy-types` in + the type map + cost/state vocabulary split + boundary notes (this repo is not yet + registered); *#115* re-cite the residual receipt and give the Echo→Residual / + Epistemic→Residual obligations acceptance criteria; *#69* verify and GPG-sign the + per-repo AFFIRMATIONs in-env; *#117/#121* two pre-existing CI reds. +* The hub's own readiness self-assessment is _Grade C_ ("dogfooded, CI passing"), and its + stated path to Grade B is _external adoption_ — 6+ diverse external targets _[DOC]_. + That is the estate's own statement that the gap between "internally coherent" and + "externally established" is a _consumption_ gap, not a proof gap. + +=== 3.2 Satellites + +[cols="1,1,1",options="header"] +|=== +| Repo | Role | Position + +| _EchoTypes.jl_ | Executable finite-domain shadow of Echo's Tier-1/2 spine | Explicitly _not a proof_; can falsify, cannot prove; honestly scoped under R-2026-05-18 — does _not_ replay the retracted surface or the funext-qualified clauses _[DOC]_ + +| _EpistemicTypes.jl_ | The strongest _consumer story_ in the estate: per-row receipts (standpoint, warrant, projection, SHA-256 seal) and an epistemic status per taxonomy call | README-level claim; not re-verified here _[DOC]_ + +| _ResidualEvidenceTypes.jl_ | Julia companion to the residual work | Young (created 2026-09-30), 4 commits since 2026-09-01 _[API]_ + +| _secret-types_ | New home for confidentiality-labelled flow + audited declassification | Specification-stage; no checker or runtime _[DOC]_ + +|=== + +_Name-collision warning (worth keeping straight):_ `ZeroProb.jl` (measure-zero events) and +`zerostep` (a VAE dataset normaliser) are _not_ members of this family; they are adjacent +by name only. Likewise `katagoria` (historical name) resolves to `ideas-to-alphas` and is +_not_ `kategoria`; `tropical-resource-typing` resolves to `tropical-types` **[DOC: +nextgen-typing naming note 2026-09-09]**. + +=== 3.3 The consumer chain (the "near zone beyond" that matters) + +[source] +---- +katagoria → typell (kernel) → typed-wasm (target) → PanLL (environment) → affinescript / ephapax / phronesis +---- + +The estate's own fence is firm: **a conceptual arrow in the map does not establish that any +family is integrated into these projects* *[DOC: TYPE-CONNECTIONS]**. Integration that +_has_ happened is recorded in echo-types' bridge ledger: `EchoTyping.agda` in +nextgen-typing, `PhronesisEcho.agda` in phronesis, a machine-checked `EchoBridge.agda` in +nextgen-languages/kitchenspeak, and a Rust application example in invariant-path _[DOC]_. + +''' + +== 4. The cross-cutting position — what is safe to say + +=== 4.1 What the estate can claim today, without hedging + +. _Five of the seven repos have a green proof job on their current main_: + echo-types (Agda, `37152181722`), epistemic-types (Proof Safety, `37187387026`), + residual-evidence-types (Agda proofs, `36949121242`), absolute-zero (Proofs, + `37077637092`), and tropical-types' _Lean_ half (`37116071270`) — with tropical's + Isabelle half unverified by its own admission. The two without one are + choreographic-types (deliberately: no prover workflow exists yet) and occupancy-types + (whose CI is disarmed, below). +. _The honesty apparatus is real, not decorative._ Retractions actually happened and are + load-bearing (echo-types R-2026-05-18); false axioms were actually found and removed + (absolute-zero: 3 latent-unsound axioms); stale claims are actually corrected + (epistemic-types removed the free `Sync` witness; choreographic-types retired its + CITATION claim). Ledger entries separate _blocked_ from _retracted_. +. _The separations are the substance._ Each family earns its identity by + matched-negatives (Echo vs entropy/LL/resource-instance), by conditionality (Epistemic: + warrant ≠ sound proof), by no-go (Tropical: `hub_ceiling`), or by proved _non-_ + composition (absolute-zero OND-5). +. _The estate's own claims are unusually well fenced._ Where something is degenerate, + provisional, gated, or unverified, there is usually a document saying so — frequently + more conservative than the README. + +=== 4.2 What the estate must not claim today + +* _No external validation yet._ echo-types' Lane 1 is _in-repo closed, externally open_; + nextgen-typing's path to Grade B is external adoption; nothing here is submitted, + accepted, or DOI-minted. +* _No general K-CUT._ Only degenerate single-static-edge base cases exist, and the + strongest of those has been declined as a gate nominee _by its own repo_, for good reason. +* _No established cross-prover equivalence._ tropical-types says the Lean and Isabelle + developments intend to agree but equivalence is not mechanically established; each + prover checks its own development. +* _No established bridge by arrow._ The five family connections in the map are + obligations, not results (Echo→Choreographic and Epistemic→Choreographic have _no_ proof; + Echo→Residual and Epistemic→Residual cover Milestone 1 only; Tropical→Choreographic needs + a grading semantics + projection theorem). +* _No "six provers in CI" for absolute-zero._ Six provers are green _via the local gate_; + CI covers the lightweight subset, and the local gate has not been run here. + +=== 4.3 The one systemic blocker with the highest leverage + +_The CI estate is partially disarmed, and the pattern is already diagnosed._ + +* _occupancy-types_: 96/100 recent runs `startup_failure`; every gate dead; no issue filed + for this repo _[CI/API]_. +* _choreographic-types#16_ documents mechanism (a): Actions allow-list `selected` with + _0 patterns_ → any third-party action dies at startup, `jobs=0`, with a produced mutant + proof on residual-evidence-types (same head, one `uses:` step toggled, `startup_failure` + ⇄ green). Fix is an _owner-only PUT_ of the canon payload. The repo explicitly notes + this is _silent_ until the first third-party action. +* _echo-types#330_ documents mechanism (b): an actor gate refusing workflow triggering for + `arena-ai-coding-agent`, so PRs can merge with _zero_ CI signal. Its recommended + mitigation — treat `STARTUP_FAILURE` as failure for required checks — is generally + applicable. +* _echo-types#324_ / _tropical-types#59_ record allow-list/count and pinning drift. + +Practical consequence for planning: **for these repos, a green badge is not evidence until +the underlying workflow actually started.** The recon above therefore cites run ids, not +badges. The coordinated plan's §6 turns this into a measurement rule (two ratios, R1 before R2, +green-means-executed) — see `COORDINATED-PLAN-2026-10-04.adoc`. + +=== 4.4 Planned already (named, in-tree, not speculation) + +[cols="1,1",options="header"] +|=== +| Where | Named next step + +| nextgen-typing | register `occupancy-types` in the type map (#118); reconcile the choreographic "echo loss-grade" vocabulary; re-cite residual receipts (#115); sign AFFIRMATIONs (#69); build `verification/proofs` in CI (#57) + +| echo-types | Gate re-assessment at each tag; rename the WFS module; land unlaned experimental modules (#320/#321); Pillar E offline half + +| epistemic-types | Applications obligations (ℚ/rescaling/row-insertion); secret-types #32 transfer + +| residual-evidence-types | Comparisons 2.0 beyond M1 interfaces; refresh STATE; causal specialisation as its own model + +| choreographic-types | Two-event K-CUT-LOSS square under `Independent₂`; vocabulary reconciliation + +| tropical-types | ROOT → 9 theories + Isabelle job (#57); Deno removal (#58); SHA pins (#59) + +| occupancy-types | Idris spike run; stackcert run + `#print axioms`; Zephyr fixture; Actions settings; then the R2 project gate + +| absolute-zero | CI mirrors the local gate (#161); axiom tag census (#171); filesystem model → Lean (#167); the paper + +|=== + +=== 4.5 The near zone beyond (what the estate is one or two steps from) + +. _Interfaces, not just imports._ residual-evidence-types already _imports_ + `Echo.Echo` and `SoundWarrant` and proved round trips. The question it asks itself — does + composition/revision need a richer interface than `Echo.Echo`/`SoundWarrant`? — is + answerable now, and its answer would settle three of the five map obligations. +. _Turn proofs on._ Wiring the existing proofs into CI (nextgen #57, tropical #57, + occupancy's settings) converts several [DOC] claims into [CI] claims at near-zero + research cost. +. _Two K-CUT-LOSS squares._ The two-event square is specified at the level where it can + be proved today; a second, non-degenerate pattern would test whether the + single-static-edge degeneracy is essential or incidental — the cheapest experiment that + could falsify the assembly hypothesis early. +. _Cost vs state as a testable separation._ `occupancy-types` claims the HWM monoid is a + _different_ axis from tropical cost, with witnesses; the estate already has both halves + in place (tropical-types' algebra; occupancy's session IR). A small composition whose + HWM grade and cost grade cannot be identified would be the cleanest possible + cross-family result — and it is a _separation_, so it is falsifiable cheaply. +. _A consumer._ Every family's honest bottleneck is the same one the hub names: nobody + outside the estate is consuming this yet. `EpistemicTypes.jl` (per-row classifier + receipts) and occupancy's session IR (certificates over measured bounds) are the two + most consumer-shaped artefacts in the estate. + +''' + +== 5. One-table position summary + +[cols="1,1,1,1,1",options="header"] +|=== +| Repo | Established (receipt) | Nearly there | Within reach | Open research + +| _echo-types_ | Agda suite green under `--safe --without-K` (`37152181722`); 209 `.agda` files; separations; retraction-disciplined | Gates provisional; WFS-not-OFS naming; unlaned modules; `README.adoc` template drift | Rename; lane the modules; packaging/DOI | Buchholz `ψ₀(Ω_ω)`; 2 Fidelity postulates; truncation under −K + +| _epistemic-types_ | Whole library green, zero postulates, no stdlib (`37187387026`); RapidNJ Q-criterion warrants | 35% prototype; applications obligations unmet | Close named obligations; secret-types transfer | Monad/comonad structure; evidence→claim soundness + +| _residual-evidence-types_ | M1+M2 checked; 9 rejections; 546-config correspondence by `refl`; both sibling interfaces imported (`36949121242`) | STATE stale; comparisons cover M1 only | Refresh STATE; comparisons 2.0 | Causal specialisation; probability adapters + +| _choreographic-types_ | Specification + fences; docs integrity green; the _reason_ it exists is one theorem | Degenerate base case (real, sibling-side, declined as a gate nominee) | Two-event square; `Independent₂`; vocabulary fix | K-CUT-LOSS / K-CUT-WARRANT general case + +| _tropical-types_ | Lean green, 20/20, no Mathlib (`37116071270`); `hub_ceiling` no-go; parametric transport | Isabelle 9 theories, ROOT 5/9, _no CI job_; `CI context contract` red | ROOT→9; Isabelle job; Deno removal; SHA pins | Buchholz ladder; time series; probabilistic extension + +| _occupancy-types_ | Session IR 14/14 _[RAN]_; operational model; ledger with blocked ≠ retracted | Idris spike + stackcert + Zephyr fixture all UNVERIFIED; _CI 96/100 startup_failure_ | Install toolchains; run; paste `#print axioms`; fix Actions; file the issue | R2–R5 rungs; cost/state separation as a theorem + +| _absolute-zero_ | Six provers + Idris green _locally_; CI Proofs green (`37077637092`); OND-1..5,7 zero-axiom; 98→classified axioms; 3 unsound axioms fixed | OND-6 open by design; CI narrower than the local gate; roadmap drift | #161, #171, #167; roadmap refresh; artifact package | OND-6; 4 class-A Coq items; the paper + +|=== + +''' + +== 6. Method and limits of this recon + +* Read: full repo trees (shallow clones at the pins above), all top-level status documents + (README, PROOF-STATUS, AFFIRMATION, ROADMAP, ULTRAPLAN, EXPLAINME, STATE.a2ml, + pre-registration, retraction ledger), the hub's TYPE-CONNECTIONS guide and roadmap, and + the workflow files. +* Queried: GitHub Actions run history and conclusions per repo (not badges), open issues + and key issue bodies, commit dates, signatures and HEAD SHAs, toolchain availability + locally. +* Ran: the only proof-adjacent gate runnable without a prover toolchain — + `occupancy-types`' Session IR manifest (14/14). Everything else in this document that is + not marked _[RAN]_ rests on _[CI]_, _[DOC]_ or _[ISSUE]_ evidence as tagged. +* Not done: no Agda/Lean/Isabelle/Coq/Mizar/Z3 re-run; no `just check` anywhere; no + evaluation of proof _quality_ beyond what the repos' own guardrails (postulate/escape + greps, kernel certificates, axiom audits) enforce; no attempt to resolve the + occupancy-types Actions gate (owner-only API surface). +* Everything above is dated 2026-10-04 and pinned by the SHAs in §0. Move the SHAs and it + becomes a draft until re-run — which is exactly the estate's own rule for AFFIRMATIONs, + and a good rule for this document too. + diff --git a/docs/recon/TYPE-FAMILY-POSITION-2026-10-04.md b/docs/recon/TYPE-FAMILY-POSITION-2026-10-04.md deleted file mode 100644 index 7a39e38..0000000 --- a/docs/recon/TYPE-FAMILY-POSITION-2026-10-04.md +++ /dev/null @@ -1,647 +0,0 @@ -# Type-family position — deep recon - -**Date of recon:** 2026-10-04 · **Prepared in:** `occupancy-types` @ `arena/01a1087c-occupancy-types` -**Scope:** `echo-types`, `epistemic-types`, `residual-evidence-types`, `choreographic-types`, -`tropical-types`, `occupancy-types`, `absolute-zero`, plus the coordination hub -`nextgen-typing` and the satellite repos. - ---- - -## 0. How to read this, and how much to trust it - -The estate is unusually well instrumented for honesty — AFFIRMATIONs, PROOF-STATUS -receipts, retraction ledgers, kill criteria, blocked-item registers. This document tries -to hold to that same standard, so every claim below is tagged with **how we know it**: - -| Tag | Meaning | -|---|---| -| **[RAN]** | I ran the command in this session and saw the result. First-hand. | -| **[CI]** | A hosted CI job on the recorded commit passed; run id/URL given. | -| **[DOC]** | The claim is the repo's own recorded status (PROOF-STATUS / AFFIRMATION / STATE / README), reproduced by an author in a stated environment, **not** re-run by me and not covered by a CI receipt in this recon. | -| **[ISSUE]** | The claim comes from a filed issue (i.e. a known, acknowledged defect or task). | -| **[INFER]** | My inference from file evidence; stated plainly as such. | - -**Calibration — what this session could and could not do.** This sandbox has -`python3` and `git` only. It has **no** `agda`, `lean`/`lake`, `idris2`, `coqc`, -`isabelle`, `mizar`, `z3`, `just`, `bun`, or Rust toolchain. Therefore: - -* Every Agda / Lean / Isabelle / Coq result is **[DOC]** or **[CI]** — I did **not** - re-typecheck any proof. Where a hosted run exists, I cite the run id. -* The one proof-adjacent thing I could re-run was `occupancy-types`' Session IR gate — it - passed 14/14 **[RAN]**. -* Repo trees, docs, roadmap text, ledger entries, workflow contents, CI conclusions, - issue text and commit signatures were all read directly from clones and the GitHub API. -* CI conclusions were read from the API, not inferred from READMEs or badges. - -**Anchor pins** (HEAD at recon time; all commits GPG-verified **[API]**): - -| Repo | HEAD | Date | -|---|---|---| -| echo-types | `da140cc26f` | 2026-10-03 | -| epistemic-types | `eb810d4ee7` | 2026-10-04 | -| residual-evidence-types | `62d7490754` | 2026-10-02 | -| choreographic-types | `71ba51d3b8` | 2026-10-03 | -| tropical-types | `ad7bfdfd56` | 2026-10-03 | -| occupancy-types | `2e276c365f` | 2026-10-04 | -| absolute-zero | `5f27136835` | 2026-10-02 | -| nextgen-typing | `70df154951` | 2026-10-01 | -| EchoTypes.jl | `a0ac9131f7` | 2026-10-01 | -| EpistemicTypes.jl | `6ab3fb4a01` | 2026-10-01 | -| ResidualEvidenceTypes.jl | `abe97d5c99` | 2026-10-01 | -| secret-types | `aed3f1cc2d` | 2026-10-04 | - -### The three-tier vocabulary used throughout - -* **There (established)** — a machine-checked artefact exists *and* it is either - receipted by a current CI run or reproducible by a named local command; the claim is - fenced by an explicit written boundary. -* **Nearly there** — the artefact exists in the tree but one link is missing: no CI lane, - no toolchain run, an unwired module, a stale state file, or a theorem that is true but - degenerate relative to the claim it is cited for. -* **Within reach** — the repo's own next step, already specified in a roadmap, ledger - entry, or open issue, needing no new research — only work. Everything beyond this line - is named as **open research** rather than aspiration. - ---- - -## 1. The estate map (as it stands) - -The five research families and their owning repos, with questions and boundaries exactly -as `nextgen-typing`'s shared guide states them **[DOC: TYPE-CONNECTIONS.adoc]**: - -| Family | Question | Fence (what it is *not*) | -|---|---|---| -| **echo-types** | Which possible origins lie over an output after a transformation? `Echo f y = Σ (x : A), f x ≡ y` | An output need not identify its origin; a numeric residue measure does not determine residue structure | -| **epistemic-types** | From which standpoint is a claim available, with what evidence? `E κ A` | Having evidence ≠ proof of the claim; belief/knowledge/sound warrant have different interfaces | -| **tropical-types** | How do declared resource bounds compose? | The algebra must be stated; a bound is neither a probability nor an Echo residue identity | -| **residual-evidence-types** | Which worlds satisfy an observation *and* its evidence constraints? | Constructing a candidate does not recover the world; real-world soundness needs the actual-world premise | -| **choreographic-types** | What happens to distinctions, bounds and warrants under projection to participants? | A causal-order cut is not Gentzen cut-elimination, nor causal identification; the general K-CUT is open | - -Neighbours in the same map but **out of the type family proper**: - -* **occupancy-types** (this repo) — *state* resource grades (HWM monoid, non-commutative), - deliberately separated from tropical *cost* grades; session/protocol frontier reclamation. -* **absolute-zero** — CNO (certified null *effect*) and OND (certified null *disclosure*); - a multi-prover effort with an Echo bridge module. Not one of the five families; connected - to them (and proposed for a map row in absolute-zero#175 **[ISSUE]**). -* **secret-types** — new (created 2026-09-27), specification-stage only. Owner ruling - 2026-10-04: this is the home for secret types; `epistemic-types` adds no Secret API; - epistemic-types#29 closed, #32 transfer pending GitHub issue-write access **[DOC: STATE.a2ml]**. -* **nextgen-typing** — the coordination hub: shared glossary, ownership routing, the - cross-project proof. It hosts no family code. - -**Vocabulary fences that are load-bearing and currently holding** (worth stating because -they are the estate's main defence against concept collapse): - -> cost grade ≠ occupancy (HWM) grade ≠ echo index ≠ residue measure ≠ warrant ≠ residual - -The guide is explicit that the five families are **complementary questions, not ranks of -type-system strength**, and that dashed arrows in the map assert *conceptual use or a -proposed research task* — not dependency, equivalence, or a checked bridge -**[DOC: TYPE-CONNECTIONS.adoc]**. - ---- - -## 2. Per-repo deep recon - -### 2.1 `echo-types` — the most developed family member - -**What it is.** Constructive Agda formalisation of proof-relevant fibres as witnesses of -structured (non-total) information loss. 209 `.agda` files under `proofs/` **[RAN: file count]**; -the verified closure (`proofs/agda/All.agda`) is described as ≈200 modules and -**postulate-free**. - -**There (established).** -* The Agda suite typechecks under `--safe --without-K`, and the **hosted Agda job is green** - on current main: run `37152181722` @ `da140cc2`, 2026-10-03 **[CI]**. -* A canonical-identity spine landed 2026-05-27: `EchoTotalCompletion` (`A ≃ Σ B (Echo f)`), - the (equivalence, projection) factorisation, no-section results, four-axis loss/residue - taxonomies, and audience modules **[DOC: PROOF-STATUS, README]**. -* **Matched-negative separation proofs** — where the identity claim does its real work: - Echo is not distinguished by Shannon entropy; the LL `!A := 1` shallow-encoding gap; - equal measure ⇏ equal Echo (`Echo.Separation.NotResourceInstance`) **[DOC]**. -* An ordinal/Buchholz track with a sound carrier: doubled-ladder well-foundedness, - Brouwer `ω^^_`/`ε₀`, and a real Buchholz notation order with well-foundedness **[DOC]**. -* Retraction discipline: R-2026-05-18 narrowed four headline claims (graded comonad → - thin-poset reindexing modality; universal property → funext-relative pointwise mediator; - model-independence → carrier-parametricity; conservativity metatheorem → postulate-free - build that is *evidence for*, not proof of) **[DOC: AFFIRMATION, roadmap]**. -* A cross-project proof `EchoTyping.agda` (XP-1: pipeline information-loss = echo fibres, - spanning echo-types ↔ affinescript ↔ typed-wasm) lives in `nextgen-typing` **[DOC]**. - -**Nearly there.** -* **Identity gates are at PROVISIONAL / PASSED-narrowed, none STABLE-ESTABLISHED** - (Gate 1 PROVISIONAL, Gate 2 PASSED (narrowed), Gate 3 PROVISIONAL) **[DOC: roadmap]**. -* **WFS, not OFS**: diagonal lifts and uniqueness-up-to-iso exist, but unique diagonal - fills are unproved; the module name `EchoOrthogonalFactorizationSystem` overstates the - target (renaming pending) **[DOC: README caution block]**. -* **Lane 1 (type-theoretic standing) is IN-REPO CLOSED, EXTERNALLY OPEN** — the paper is a - living draft; the offline half (submission, DOI, packaging) is author-driven **[DOC]**. -* `experimental/echo-additive` (7 modules incl. the `Grade` dioid) is **in no CI lane** - **[ISSUE #321]**; 4 bit-narrowing modules are similarly unlaned **[ISSUE #320]**. -* Doc/toolchain debts: `README.adoc` still carries RSR `{{PLACEHOLDER}}` template material - while `README.md` is canonical **[RAN: file read]**; `agda.yml` installs an unpinned - `apt-get agda` **[ISSUE #322]**; governance red on `CONTRIBUTING`/gitleaks - **[ISSUE #323]**; CodeQL startup-failure **[ISSUE #269]**. - -**Within reach.** Rename to honesty (`EchoWeakFactorizationSystem`); wire the unlaned -experimental modules into CI; clear the packaging/DOI half of Pillar E; refresh -`README.adoc` out of template state. - -**Open research (not reachable by wiring).** Bachmann–Howard `ψ₀(Ω_ω)` order-type fidelity -(D-2026-06-14, *OPEN* — `ε₀ ≪ Γ₀ ≪ …`); the two quarantined postulates in -`Ordinal/Buchholz/Fidelity.agda`; the `∥_∥` image truncation (cannot be built under -`--safe --without-K` without HITs — present only in a `--cubical` island); the unbudgeted -global `wf-<ᵇʳᶠ` (walled: the native order is ordinally unsound, with a documented -counterexample). - ---- - -### 2.2 `epistemic-types` — small, self-contained, genuinely green - -**What it is.** A minimal-of-design Agda prototype for standpoint-indexed modalities, -separating knowledge (factive) from belief (non-factive) and warrant from sound proof. -The base modality is deliberately **not** a monad or comonad. - -**There (established).** -* The **whole library type-checks under `--safe` with zero postulates and no standard - library** (`--no-libraries`, only `Agda.Builtin.*`), and the **hosted `Proof Safety` job - is green on the current HEAD**: run `37187387026` @ `eb810d4e`, 2026-10-04 **[CI]**. -* Module inventory is concrete: 17 modules listed in STATE, including `Base`, `Warrant`, - `Access`, `ProofTransport`, `ReadConsistency`, `EchoBridge`, `SurrealBridge`, and an - Applications layer **[DOC]**. -* The **Applications layer (2026-09-27)** is a real worked result, not a demo: - `QCriterion.qBound-≤-Q` over an arbitrary `OrderedGroup`; `RapidNJSkip` generating a - warrant from a skip certificate with `skip-known` proved; `IntegerModel` discharging the - arithmetic budget; a rejection fixture for an unchecked check **[DOC: PROOF-STATUS]**. -* Explicit non-claims are recorded: no ℚ instance, no rescaling transport, no row-insertion - update, no cross-iteration bound reuse **[DOC]**. -* Concrete Echo adapter: `SurrealBridge` relaxes a proved upper bound on a residue measure - along the access order while preserving the retained value; the `daySurrealAccess` - instance is explicitly a set-sized fragment, *not* the Conway proper class **[DOC]**. -* `ReadConsistency` was corrected so `ReadView` entails equality with indexed store - contents; the older version-only relabelling and free `Sync` witness were **removed** - **[DOC]**. - -**Nearly there.** -* STATE calls it `prototype` / `experimental` at **35% completion**, last-updated - 2026-10-04 — i.e. the repo itself does not claim maturity **[DOC: STATE.a2ml]**. -* The Applications obligations are named but unmet (rational instance, rescaling - transport, row-insertion invariants). -* The proof-transport soundness story is qualified ("holder-dependent transfer is - explicitly qualified") **[DOC]**. - -**Within reach.** Close the named Applications obligations; settle the secret-types -handover (epistemic-types#32 transfer is blocked on GitHub issue-write access — an -**administrative** blocker, not a technical one) **[DOC/ISSUE]**. - -**Open research.** Whether `bind`/`extract` structure is wanted at all (currently a -deliberate "future commitment, not a hidden assumption"); the soundness map from evidence -to claim meaning under a standpoint index. - ---- - -### 2.3 `residual-evidence-types` — newest, fastest-moving, and the only family with a machine-checked *correspondence* - -**What it is.** Evidence-indexed residual types: which worlds are compatible with an -observation *and* its declared evidence constraints, and what holds for all of them. -Founded 2026-09-09 from imported Windows-Downloads material (assessment + a standalone -HTML/JS explorer), with **all core work newly written in-repo**. - -**There (established).** -* **Milestone 1** — presence without identification (`u+n=2`, `n≤1` establishes `u≠0` - while `(1,1)` and `(2,0)` still disagree), evidence-refined fibre round trips, - conditional actual-world soundness, claim transport under refinement; three invalid - modules must be rejected by Agda **[DOC]**. -* **Milestone 2** — contexts of assumptions with thinnings, dependency-preserving - composition and coarsening, constructive revision and retraction, **a certified finite - checker proved equivalent to the explorer by `refl` over all 546 configurations** - (`Correspondence.checker-matches-explorer`), and nine expected-rejection controls - **[DOC]**. -* **Both sibling interfaces are actually imported** — Echo's fibre packaging round-trips, - and Epistemic's `SoundWarrant` requiring explicit actual-world premises — pinned to - sibling heads (`echo-types` `9c4b72b5`, `epistemic-types` `dd948fbd` for M1) **[DOC]**. -* Hosted **`Agda proofs` job green** on the current HEAD: run `36949121242` @ `62d74907`, - 2026-10-02, and a prior receipt run `36740394802` @ `befdf964` **[CI/DOC]**. -* The repo is scrupulous about the limit: the correspondence certifies the *finite checker - against the explorer*, **not** the ℕ core against the explorer **[DOC]**. - -**Nearly there.** -* `STATE.a2ml` (last-updated 2026-09-09) is **stale**: it still lists composition, - revision/retraction, the certified checker and the explorer correspondence as *pending* - — all of which Milestone 2 landed **[RAN: file read vs PROOF-STATUS]**. -* The two sibling comparisons cover **Milestone 1 only**; whether composition/revision need - an interface beyond `Echo.Echo` and `SoundWarrant` is the explicitly open question - **[DOC]**. -* A separate "starter archive" named in the imported assessment has **not been recovered** - and the repo does not pretend otherwise **[DOC]**. -* Codeac status has been pending on main since 2026-09-24 **[ISSUE #11]**. - -**Within reach.** Refresh STATE; run comparisons 2.0 (post-M1 interfaces); the explorer's -signed −6..6 model is already the certified finite object, so further finite-model checks -are cheap. - -**Open research.** Causal specialisation and probability adapters — both explicitly require -models and obligations of their own **[DOC]**. - ---- - -### 2.4 `choreographic-types` — a pre-registration, and it says so - -**What it is.** The assembly hypothesis: grade a global choreography with echo *loss-grades* -and epistemic *standpoint-warrants*, project to participants, and ask whether grading and -transport commute with projection across a consistent frontier (a *cut*). The keystone is -**K-CUT**, split into K-CUT-LOSS (equality) and K-CUT-WARRANT (bound, under a `SoundWarrant` -side-condition). - -**There (established).** -* **The specification and its fences.** The pre-registration (2026-10-03) states that - K-CUT-LOSS and K-CUT-WARRANT remain **OPEN**, that `SoundWarrant` is an *assumed - receiver-local side-condition*, and that the application Agda file **"contains postulates, - not proofs"** and is not imported by any build **[DOC: docs/pre-registration.adoc]**. -* `CITATION.cff` no longer claims a completed Agda formalisation; integrity checks now fail - such claims on description-mirroring surfaces **[DOC]**. Issue #15 records that the - README/description still overstate **[ISSUE]**. -* CI's two substantive checks — `Secret Scanner` and `Documentation Integrity` — are both - green **[CI]**. There is **no prover workflow at all**, by design at this stage. - -**Nearly there.** -* The **degenerate base case exists and is real**, but it is a sibling's theorem: - `characteristic/RoleGraded.choreo-grade-commute` in `echo-types` — two actions (role - transport × grade degradation) commuting on one Echo-indexed family, satisfying the - "same data" test that struck down the earlier N3 nominee **[DOC/RAN: file read]**. - It is a *single-static-edge integration theorem*, not K-CUT. echo-types' own audit - **declined to adopt it as nominee N5** on the grounds that its only non-trivial cell is - already credited elsewhere (adoption would be cosmetic) **[DOC: N5Falsifier, IntegrationAudit]**. -* The smallest concrete target is specified: a two-event K-CUT-LOSS commuting square under - an `Independent₂` witness, with the witness required to carry disjoint read/write - footprints, phase safety and a deterministic tie policy **[DOC]**. -* A vocabulary obligation is open: the choreographic README's phrase "echo loss-grade" - conflicts with the estate's separation of echo index / residue measure / resource grade; - reconciling it is a **coordination task** in the hub roadmap **[DOC: TYPE-CONNECTIONS]**. - -**Within reach.** Wire the existing `rapidnj-two-thread.agda` postulates into a real -minimal proof of the two-event square; land the `Independent₂` witness; reconcile the -vocabulary with the shared glossary. None of that requires solving K-CUT. - -**Open research.** K-CUT in general (both fragments) — the repo's own honest position is -that the general result is open and only degenerate single-static-edge cases exist. - ---- - -### 2.5 `tropical-types` — dual-formalised, one half verified, one half CI-gated-by-claim - -**What it is.** Max-plus / min-max algebra applied to resource-aware typing: compositional -worst-case bounds for latency, stack use and adversarial round counts, plus a reusable -resource-grade axis for downstream languages. **Note the prover split**: this family is -**Lean 4 + Isabelle/HOL**, not Agda. - -**There (established).** -* **Lean 4 — verified and CI-gated.** `lake build` green, no Mathlib, toolchain pinned in - `lean-toolchain` (`v4.13.0`); hosted **`Lean` job green** on current main: run - `37116071270` @ `ad7bfdfd`, 2026-10-03 **[CI]**. PROOF-STATUS records a clean rebuild of - **20/20 targets** including `TropicalSessionTypes.lean` (max-plus session grading), - `TropicalAdapterPath.lean` (min-max bottleneck transport + the `hub_ceiling` no-go), - the `Resource/Algebra` interface with a **parametric transport theorem**, and concrete - instances (MaxPlus, MinPlus, MinMax, Linear, Affine) **[DOC]**. -* The two twins are related by an order-reversing involution proved as a **lattice - anti-isomorphism** and explicitly *not* a semiring homomorphism — a structural fact, - stated as such **[DOC]**. -* `Resource/EchoBridge.lean` is an **echo-free residue-measure bridge** (no dependency on - the echo-types Agda kernel; the relationship is at design level) **[DOC]**. - -**Nearly there.** -* **The Isabelle half is not verified in the recon sense.** Nine `.thy` theories exist and - the session is meant to be CI-gated by `just isabelle-build` + `just check-sorry`, but - **no workflow mentions Isabelle**; `ROOT` lists **5 of 9** theories; PROOF-STATUS itself - says the Isabelle side was *"NOT re-verified in this environment"* **[DOC]**. -* Issue #57 states the contradictions directly: the claim is CI-gated but nothing gates it, - ROOT covers 5 of 9, and STATE says GREEN and RED for the same theory **[ISSUE]**. -* The `CI context contract` job is red on recent commits (required-status-check drift); - it is the repo's own guard for `docs/CI-CONTEXTS.adoc` and it fails for that documented - reason — a CI-hygiene red, not a proof red **[CI]**. -* The no-go theorem `hub_ceiling` refutes Protocol Squisher's universal-interoperability - claim — real, but it is a *no-go*, not a capability **[DOC]**. - -**Within reach.** Extend `ROOT` to all nine theories; add the Isabelle job; delete the -residual Deno test files (Deno is banned estate-wide **[ISSUE #58]**); SHA-pin the two -tagged `actions/checkout` uses **[ISSUE #59]**. - -**Open research.** The Buchholz-collapsing ladder (Rungs 2–N, 0% per STATE); tropical time -series (Diehl–Ebrahimi-Fard–Tapia); a probabilistic extension; a Lean tactic for automated -grade calculation. - ---- - -### 2.6 `occupancy-types` (this repo) — pre-registered, locally reproducible, CI-disarmed - -**What it is.** Stepwise resource-bounding types: deterministic memory first, network -second. The organising claim is that **cost and state are different axes**: cost composes -with `+` in sequence and `max` across alternatives (tropical), while *state* resources -(pools, buffers, credits, FDs) compose by the **non-commutative high-water-mark monoid** -`(p₁,n₁)·(p₂,n₂) = (max(p₁, n₁+p₂), n₁+n₂)`. Buffer = memory, and the **protocol frontier -is the reclamation point**. The whole thing is pre-registered in `ULTRAPLAN.md` with -per-rung kill criteria and a decision log (D1–D7). - -**There (established).** -* **R0-B, Phase 1 — Session IR checker: TESTED. I re-ran it in this session:** - `PYTHONPATH=src python3 -m session_ir test examples/session_ir/manifest.json` → - **14/14 PASS**, exit 0 **[RAN]**. Seven accept cases with measured steps ≤ certified - bound (including a strict case: certify 5 / measure 4, and a tight case: 6/6) and seven - expected-rejection controls each pinning an error class (double-send, use-after-drop, - protocol mismatch, close-before-End, double-free, leak, alias) **[RAN]**. -* The operational model exists and its Phase-0 kill test is **mechanically audited** - (four sentences, banned word absent) **[DOC: EXPLAINME C3]**. -* The honesty apparatus is real and already in use: `docs/EXPLAINME.adoc` classifies every - claim as TESTED / UNVERIFIED / CONJECTURE, and `docs/retraction-ledger.adoc` records - blocked rungs (with exact unblocking commands) separately from retractions — with **zero - retractions so far** and three blocked items **[RAN: file read]**. -* The estate placement is correct and deliberate: registered against the cost/state - vocabulary split, with "not echo, not warrant, not residue" written into the plan - **[DOC: ULTRAPLAN §5]**. - -**Nearly there (blocked, not disproved).** -* **Idris 2 Occupancy spike — UNVERIFIED.** `src/occ/Occ.idr`, `Demo.idr` (static peak = K - = 2 producer/consumer) and four rejection controls exist; no `idris2` on the work - environment's PATH **[DOC/RAN: toolchain check]**. The kill question (are constant grades - tolerable *and tight*?) is answered only provisionally, and the repo labels the answer - CONJECTURE. -* **R1 stackcert — UNVERIFIED.** `src/stackcert/StackcertCore.lean` with the target theorem - `cert_sound`, plus fixtures generated by real `gcc -fcallgraph-info=su -fstack-usage` - **[DOC]**, but no `lean` locally and no `#print axioms` footprint pasted. The expected - empty axiom list is **explicitly marked CONJECTURE until pasted** **[DOC: EXPLAINME C5]**. -* **Ground truth — BLOCKED.** Zephyr painted-stack HWM on `qemu_cortex_m3` is a **fixture - request**; nothing is measured until it runs. The plan's own rule is "measured ≤ certified - on every run, violation = stop" — so R1 cannot be *closed* without this **[DOC]**. -* **CI is comprehensively non-functional.** 96 of the last 100 workflow runs on this repo - concluded `startup_failure`, including on `main` pushes by the owner actor; **every** - gate — Rust CI, Dogfood, Static Analysis, Invisible Character Detection, K9, Secret - Scanner — dies before starting a job **[CI/API]**. The estate has two *documented* - mechanisms that produce exactly this signature: (a) an Actions allow-list posture of - `selected` with **0 patterns**, which kills any workflow whose step references a - non-allow-listed action, `jobs=0` (choreographic-types#16, with a produced mutant - proof); (b) an actor gate refusing workflow triggering for a given actor - (echo-types#330). The precise gate for *this* repo is **not established** from here, and - unlike its siblings this repo carries **no open issue** about it (it has no open issues - at all). Consequence: **none of this repo's checks are currently machine-enforced**; - the local gates are the only source of truth. -* `README.adoc` is still RSR template material (self-declared in-file) **[RAN]**. - -**Within reach (needs a toolchain or a settings change, not research).** Install -`idris2` → run the spike and its four controls; install `lean`/`lake` → run stackcert and -paste `#print axioms cert_sound`; obtain the Zephyr fixture; fix the Actions settings -(owner-only PUT) and file the missing issue for this repo; refresh `README.adoc` from the -template. - -**Open research (the actual rungs).** R2 static pools + affine/linear handles with the T1 -coherence theorem (project gate after R2); R3 binary session channels with HWM buffer -grades; R4 network-calculus curves over ℕ/ℤ without reals; R5 multiparty projection and the -projection/grade commutation question; Phase 5 host-tool contract. The pre-written kill -criteria are, correctly, part of the design: R2 archives the project if there is no external -consumer for certificates and no theorem beyond restatement. - ---- - -### 2.7 `absolute-zero` — the most *concretely* verified repo in the estate - -**What it is.** Two co-equal pillars — **CNO** (a program that provably does nothing to the -world) and **OND** (a program whose observable trace is constant over its secret input, -relative to a declared observation model `O`). The pillars are logically independent (a -proved theorem) and joined by a *coupling dial* that is explicitly **framing, not theorem**. - -**There (established).** -* **A single gate reproduces everything locally**: `proofs/verify-all-provers.sh` → - `ALL-PROVERS-GREEN` across **Coq, Agda, Lean 4 (+Mathlib), Z3, Isabelle/HOL, Mizar**, plus - the **Idris 2 ABI**, with an absent prover treated as *failure, never skip* (since - 2026-09-23), Z3 verdicts checked against `; expect sat|unsat`, and a Coq - `Print Assumptions` audit with its own control **[DOC: PROOF-STATUS]**. A gate self-test - proves the gate turns red for each absent/failing prover and each verdict/audit mutant - (16 cases, run in CI) **[DOC]**. -* **CI Proofs job green** on current main: run `37077637092` @ `5f271368`, 2026-10-02 - **[CI]**. The workflow runs the lightweight provers (Coq 14/14 theories, Agda CNO+OND, - Z3 CNO+OND, Mathlib-free Lean core with an `AxiomAudit`); the heavy provers are covered - only by the local container gate — and the workflow says so in its own header **[RAN: - workflow read]**. -* **OND-1..5 and OND-7 are landed** — proved in Coq with **zero axioms** (every theorem - `Closed under the global context`), mirrored in Lean 4, Agda and Z3 **[DOC]**. -* **CNO axiom discharge 98 → a small classified remainder**, with the pathological cases - found and fixed rather than hidden: `no_cloning` and `Cconj_Cexp` were **provably false** - and removed; `eta_equivalence` was **false as stated** (counterexample `f = LVar 5`) and - replaced by an honestly guarded theorem **[DOC]**. Remaining axioms are tagged either - `METAL-BOUNDARY` (genuine physics: `kB>0`, `temperature>0`, Second Law, Landauer) or - *class-A* (true, provable in principle, listed with blockers — 4 items) **[DOC]**. -* An **Echo bridge exists in Agda** (`EchoBridgeCNO.agda`): `EchoRel` instantiated - against real `CNO.Program`/`CNO.eval` with `CNO.state-eq` **[RAN: file read]**. -* Roadmap restraint is explicit: the long-horizon "universal CNO standard" is quarantined - in an appendix as **aspirational and unfunded**, "a direction of travel, not a - commitment with a date" **[DOC]**. - -**Nearly there.** -* **OND-6** (conditional composition) is **open by design** — the research capstone. The - roadmap warns, correctly, that if composition appears to hold as cleanly as for CNOs the - result has almost certainly dropped a term **[DOC]**. -* **CI is weaker than the local gate** and the repo knows it: for a time Isabelle and Mizar - printed "skipped" while the gate said GREEN; that is fixed in the local gate, but - absolute-zero#161 records that the `Proofs` workflow still has a `paths:` filter, - `z3 … || true`, and no assumption check **[ISSUE]**. -* **Documentation drift**: `ROADMAP.adoc` (last updated 2026-07-07) still lists as pending - the Idris ABI repair and "make CI truthful: run Coq+Agda+Rust", both since superseded by - `PROOF-STATUS` and the current workflow **[RAN: file comparison]**. -* 73 of 182 Coq theorems rest on axioms and 38 `Axiom`/`Parameter` declarations use four - tag forms (unify grammar, generate census) **[ISSUE #171]**; 2 Idris2 postulates in - `src/abi/Layout.idr` remain **[ISSUE #27]**; Scorecard has 5 high alerts **[ISSUE #170]**. - -**Within reach.** Make CI mirror the local all-provers gate (fix #161); unify the axiom tag -grammar and publish the census (#171); port the Coq filesystem model to Lean so the -`FilesystemCNO` law axioms become theorems (#167); refresh the roadmap against PROOF-STATUS; -the artifact-evaluation one-command container. - -**Open research.** OND-6 conditional composition; the 4 class-A Coq items -(`CNOT_gate_unitary`, `unitary_inverse_property`, `fidelity_bound` need a finite-dim/tensor -model; `y_not_cno` needs a coinductive/step-indexed β non-termination argument); the paper. - ---- - -## 3. The hub, the satellites, and the name-collisions - -### 3.1 `nextgen-typing` (coordination) — the map is the artefact - -* Hosts the shared glossary, ownership routing and the **XP-1 cross-project proof** - (`verification/proofs/agda/EchoTyping.agda`, `--safe --without-K`, spanning echo-types ↔ - affinescript ↔ typed-wasm) **[DOC]**. -* **But nothing runs it**: nextgen-typing#57 records that no CI job runs - `just proof-check-all` **[ISSUE]**. The estate's only cross-project proof is therefore - unenforced. -* Open coordination tasks relevant to the family: **#118** register `occupancy-types` in - the type map + cost/state vocabulary split + boundary notes (**this repo is not yet - registered**); **#115** re-cite the residual receipt and give the Echo→Residual / - Epistemic→Residual obligations acceptance criteria; **#69** verify and GPG-sign the - per-repo AFFIRMATIONs in-env; **#117/#121** two pre-existing CI reds. -* The hub's own readiness self-assessment is **Grade C** ("dogfooded, CI passing"), and its - stated path to Grade B is *external adoption* — 6+ diverse external targets **[DOC]**. - That is the estate's own statement that the gap between "internally coherent" and - "externally established" is a **consumption** gap, not a proof gap. - -### 3.2 Satellites - -| Repo | Role | Position | -|---|---|---| -| **EchoTypes.jl** | Executable finite-domain shadow of Echo's Tier-1/2 spine | Explicitly *not a proof*; can falsify, cannot prove; honestly scoped under R-2026-05-18 — does **not** replay the retracted surface or the funext-qualified clauses **[DOC]** | -| **EpistemicTypes.jl** | The strongest **consumer story** in the estate: per-row receipts (standpoint, warrant, projection, SHA-256 seal) and an epistemic status per taxonomy call | README-level claim; not re-verified here **[DOC]** | -| **ResidualEvidenceTypes.jl** | Julia companion to the residual work | Young (created 2026-09-30), 4 commits since 2026-09-01 **[API]** | -| **secret-types** | New home for confidentiality-labelled flow + audited declassification | Specification-stage; no checker or runtime **[DOC]** | - -**Name-collision warning (worth keeping straight):** `ZeroProb.jl` (measure-zero events) and -`zerostep` (a VAE dataset normaliser) are **not** members of this family; they are adjacent -by name only. Likewise `katagoria` (historical name) resolves to `ideas-to-alphas` and is -**not** `kategoria`; `tropical-resource-typing` resolves to `tropical-types` **[DOC: -nextgen-typing naming note 2026-09-09]**. - -### 3.3 The consumer chain (the "near zone beyond" that matters) - -``` -katagoria → typell (kernel) → typed-wasm (target) → PanLL (environment) → affinescript / ephapax / phronesis -``` - -The estate's own fence is firm: **a conceptual arrow in the map does not establish that any -family is integrated into these projects** **[DOC: TYPE-CONNECTIONS]**. Integration that -*has* happened is recorded in echo-types' bridge ledger: `EchoTyping.agda` in -nextgen-typing, `PhronesisEcho.agda` in phronesis, a machine-checked `EchoBridge.agda` in -nextgen-languages/kitchenspeak, and a Rust application example in invariant-path **[DOC]**. - ---- - -## 4. The cross-cutting position — what is safe to say - -### 4.1 What the estate can claim today, without hedging - -1. **Five of the seven repos have a green proof job on their current main**: - echo-types (Agda, `37152181722`), epistemic-types (Proof Safety, `37187387026`), - residual-evidence-types (Agda proofs, `36949121242`), absolute-zero (Proofs, - `37077637092`), and tropical-types' **Lean** half (`37116071270`) — with tropical's - Isabelle half unverified by its own admission. The two without one are - choreographic-types (deliberately: no prover workflow exists yet) and occupancy-types - (whose CI is disarmed, below). -2. **The honesty apparatus is real, not decorative.** Retractions actually happened and are - load-bearing (echo-types R-2026-05-18); false axioms were actually found and removed - (absolute-zero: 3 latent-unsound axioms); stale claims are actually corrected - (epistemic-types removed the free `Sync` witness; choreographic-types retired its - CITATION claim). Ledger entries separate *blocked* from *retracted*. -3. **The separations are the substance.** Each family earns its identity by - matched-negatives (Echo vs entropy/LL/resource-instance), by conditionality (Epistemic: - warrant ≠ sound proof), by no-go (Tropical: `hub_ceiling`), or by proved *non-* - composition (absolute-zero OND-5). -4. **The estate's own claims are unusually well fenced.** Where something is degenerate, - provisional, gated, or unverified, there is usually a document saying so — frequently - more conservative than the README. - -### 4.2 What the estate must not claim today - -* **No external validation yet.** echo-types' Lane 1 is *in-repo closed, externally open*; - nextgen-typing's path to Grade B is external adoption; nothing here is submitted, - accepted, or DOI-minted. -* **No general K-CUT.** Only degenerate single-static-edge base cases exist, and the - strongest of those has been declined as a gate nominee *by its own repo*, for good reason. -* **No established cross-prover equivalence.** tropical-types says the Lean and Isabelle - developments intend to agree but equivalence is not mechanically established; each - prover checks its own development. -* **No established bridge by arrow.** The five family connections in the map are - obligations, not results (Echo→Choreographic and Epistemic→Choreographic have *no* proof; - Echo→Residual and Epistemic→Residual cover Milestone 1 only; Tropical→Choreographic needs - a grading semantics + projection theorem). -* **No "six provers in CI" for absolute-zero.** Six provers are green *via the local gate*; - CI covers the lightweight subset, and the local gate has not been run here. - -### 4.3 The one systemic blocker with the highest leverage - -**The CI estate is partially disarmed, and the pattern is already diagnosed.** - -* **occupancy-types**: 96/100 recent runs `startup_failure`; every gate dead; no issue filed - for this repo **[CI/API]**. -* **choreographic-types#16** documents mechanism (a): Actions allow-list `selected` with - **0 patterns** → any third-party action dies at startup, `jobs=0`, with a produced mutant - proof on residual-evidence-types (same head, one `uses:` step toggled, `startup_failure` - ⇄ green). Fix is an **owner-only PUT** of the canon payload. The repo explicitly notes - this is *silent* until the first third-party action. -* **echo-types#330** documents mechanism (b): an actor gate refusing workflow triggering for - `arena-ai-coding-agent`, so PRs can merge with **zero** CI signal. Its recommended - mitigation — treat `STARTUP_FAILURE` as failure for required checks — is generally - applicable. -* **echo-types#324** / **tropical-types#59** record allow-list/count and pinning drift. - -Practical consequence for planning: **for these repos, a green badge is not evidence until -the underlying workflow actually started.** The recon above therefore cites run ids, not -badges. The coordinated plan's §6 turns this into a measurement rule (two ratios, R1 before R2, -green-means-executed) — see `COORDINATED-PLAN-2026-10-04.md`. - -### 4.4 Planned already (named, in-tree, not speculation) - -| Where | Named next step | -|---|---| -| nextgen-typing | register `occupancy-types` in the type map (#118); reconcile the choreographic "echo loss-grade" vocabulary; re-cite residual receipts (#115); sign AFFIRMATIONs (#69); build `verification/proofs` in CI (#57) | -| echo-types | Gate re-assessment at each tag; rename the WFS module; land unlaned experimental modules (#320/#321); Pillar E offline half | -| epistemic-types | Applications obligations (ℚ/rescaling/row-insertion); secret-types #32 transfer | -| residual-evidence-types | Comparisons 2.0 beyond M1 interfaces; refresh STATE; causal specialisation as its own model | -| choreographic-types | Two-event K-CUT-LOSS square under `Independent₂`; vocabulary reconciliation | -| tropical-types | ROOT → 9 theories + Isabelle job (#57); Deno removal (#58); SHA pins (#59) | -| occupancy-types | Idris spike run; stackcert run + `#print axioms`; Zephyr fixture; Actions settings; then the R2 project gate | -| absolute-zero | CI mirrors the local gate (#161); axiom tag census (#171); filesystem model → Lean (#167); the paper | - -### 4.5 The near zone beyond (what the estate is one or two steps from) - -1. **Interfaces, not just imports.** residual-evidence-types already *imports* - `Echo.Echo` and `SoundWarrant` and proved round trips. The question it asks itself — does - composition/revision need a richer interface than `Echo.Echo`/`SoundWarrant`? — is - answerable now, and its answer would settle three of the five map obligations. -2. **Turn proofs on.** Wiring the existing proofs into CI (nextgen #57, tropical #57, - occupancy's settings) converts several [DOC] claims into [CI] claims at near-zero - research cost. -3. **Two K-CUT-LOSS squares.** The two-event square is specified at the level where it can - be proved today; a second, non-degenerate pattern would test whether the - single-static-edge degeneracy is essential or incidental — the cheapest experiment that - could falsify the assembly hypothesis early. -4. **Cost vs state as a testable separation.** `occupancy-types` claims the HWM monoid is a - *different* axis from tropical cost, with witnesses; the estate already has both halves - in place (tropical-types' algebra; occupancy's session IR). A small composition whose - HWM grade and cost grade cannot be identified would be the cleanest possible - cross-family result — and it is a *separation*, so it is falsifiable cheaply. -5. **A consumer.** Every family's honest bottleneck is the same one the hub names: nobody - outside the estate is consuming this yet. `EpistemicTypes.jl` (per-row classifier - receipts) and occupancy's session IR (certificates over measured bounds) are the two - most consumer-shaped artefacts in the estate. - ---- - -## 5. One-table position summary - -| Repo | Established (receipt) | Nearly there | Within reach | Open research | -|---|---|---|---|---| -| **echo-types** | Agda suite green under `--safe --without-K` (`37152181722`); 209 `.agda` files; separations; retraction-disciplined | Gates provisional; WFS-not-OFS naming; unlaned modules; `README.adoc` template drift | Rename; lane the modules; packaging/DOI | Buchholz `ψ₀(Ω_ω)`; 2 Fidelity postulates; truncation under −K | -| **epistemic-types** | Whole library green, zero postulates, no stdlib (`37187387026`); RapidNJ Q-criterion warrants | 35% prototype; applications obligations unmet | Close named obligations; secret-types transfer | Monad/comonad structure; evidence→claim soundness | -| **residual-evidence-types** | M1+M2 checked; 9 rejections; 546-config correspondence by `refl`; both sibling interfaces imported (`36949121242`) | STATE stale; comparisons cover M1 only | Refresh STATE; comparisons 2.0 | Causal specialisation; probability adapters | -| **choreographic-types** | Specification + fences; docs integrity green; the *reason* it exists is one theorem | Degenerate base case (real, sibling-side, declined as a gate nominee) | Two-event square; `Independent₂`; vocabulary fix | K-CUT-LOSS / K-CUT-WARRANT general case | -| **tropical-types** | Lean green, 20/20, no Mathlib (`37116071270`); `hub_ceiling` no-go; parametric transport | Isabelle 9 theories, ROOT 5/9, **no CI job**; `CI context contract` red | ROOT→9; Isabelle job; Deno removal; SHA pins | Buchholz ladder; time series; probabilistic extension | -| **occupancy-types** | Session IR 14/14 **[RAN]**; operational model; ledger with blocked ≠ retracted | Idris spike + stackcert + Zephyr fixture all UNVERIFIED; **CI 96/100 startup_failure** | Install toolchains; run; paste `#print axioms`; fix Actions; file the issue | R2–R5 rungs; cost/state separation as a theorem | -| **absolute-zero** | Six provers + Idris green *locally*; CI Proofs green (`37077637092`); OND-1..5,7 zero-axiom; 98→classified axioms; 3 unsound axioms fixed | OND-6 open by design; CI narrower than the local gate; roadmap drift | #161, #171, #167; roadmap refresh; artifact package | OND-6; 4 class-A Coq items; the paper | - ---- - -## 6. Method and limits of this recon - -* Read: full repo trees (shallow clones at the pins above), all top-level status documents - (README, PROOF-STATUS, AFFIRMATION, ROADMAP, ULTRAPLAN, EXPLAINME, STATE.a2ml, - pre-registration, retraction ledger), the hub's TYPE-CONNECTIONS guide and roadmap, and - the workflow files. -* Queried: GitHub Actions run history and conclusions per repo (not badges), open issues - and key issue bodies, commit dates, signatures and HEAD SHAs, toolchain availability - locally. -* Ran: the only proof-adjacent gate runnable without a prover toolchain — - `occupancy-types`' Session IR manifest (14/14). Everything else in this document that is - not marked **[RAN]** rests on **[CI]**, **[DOC]** or **[ISSUE]** evidence as tagged. -* Not done: no Agda/Lean/Isabelle/Coq/Mizar/Z3 re-run; no `just check` anywhere; no - evaluation of proof *quality* beyond what the repos' own guardrails (postulate/escape - greps, kernel certificates, axiom audits) enforce; no attempt to resolve the - occupancy-types Actions gate (owner-only API surface). -* Everything above is dated 2026-10-04 and pinned by the SHAs in §0. Move the SHAs and it - becomes a draft until re-run — which is exactly the estate's own rule for AFFIRMATIONs, - and a good rule for this document too. diff --git a/docs/recon/ULTRA-PLAN-2026-10-04.adoc b/docs/recon/ULTRA-PLAN-2026-10-04.adoc new file mode 100644 index 0000000..9e8e22e --- /dev/null +++ b/docs/recon/ULTRA-PLAN-2026-10-04.adoc @@ -0,0 +1,229 @@ +// SPDX-License-Identifier: CC-BY-4.0 +// SPDX-FileCopyrightText: 2026 Jonathan D.A. Jewell (hyperpolymath) += Ultra-plan — the rest of the work +:toc: macro +:toclevels: 3 +:icons: font + +*Date:* 2026-10-04 · *Base commit:* `2e276c3` + this session's branch +· *Companions:* `TYPE-FAMILY-POSITION-2026-10-04.adoc` (what is true), +`COORDINATED-PLAN-2026-10-04.adoc` (workstreams W1–W5 and §6 measurement discipline) + +toc::[] + +== 0. What changed today (receipts, not intentions) + +[cols="1,3",options="header"] +|=== +| Change | Evidence + +| Gate re-run locally, still green +| `bash scripts/check.sh --runnable-only` → *exit 0*; session-IR 14/14; kill-test audit + PASS; repo-shape PASS; stages 4–5 correctly *BLOCKED* (never a silent skip). + +| *Defect found and fixed:* R1 had **no `lakefile.toml` and no `lean-toolchain`** +| `tests/run_stackcert.sh` stage 2 runs `lake build` and stage 3 `lake exe stackcert` + — neither could ever have passed. The harness reported "toolchain absent", which was + true but hid a second, permanent blocker. Added `src/stackcert/lakefile.toml` + (libs `StackcertCore`, `Parsers`; exe `stackcert` rooted at `Main`) and + `src/stackcert/lean-toolchain` (`leanprover/lean4:v4.15.0`). + +| Both blocked rungs now have a *CI execution path* +| Added `.github/workflows/proofs.yml`: `stackcert` (Lean 4.15.0 via elan, strict) and + `occ-idris` (Idris 2 v0.7.0 built over Chez Scheme; *advisory* until its first green + run). Only `actions/checkout` is used — no third-party action, so the allow-list + posture (issue #6) cannot kill these jobs at startup. + +| Markdown-gate regression I had introduced, fixed +| The three recon documents were `.md` under `docs/`, which the estate rule forbids. + `TYPE-FAMILY-POSITION` and `COORDINATED-PLAN` converted to AsciiDoc; the follower + notes moved *out of the public repo* (unsent drafts about named people) and remain a + working copy. `bash scripts/check-no-md-in-docs.sh .` → PASS. + +| Sandbox limits measured, not assumed +| Only `github.com`, `api.github.com` and `pypi.org` are reachable here; + `release-assets.githubusercontent.com` / `elan.lean-lang.org` / `deb.debian.org` are + not. So Lean/Idris cannot be fetched *here* — but GitHub runners can. + +| *Pre-existing defect found:* the action-pinning gate is already red on `main` +| `node scripts/check-action-pinning.js` → exit 1: + `.github/workflows/pages.yml:37` (`haskell-actions/setup@v2.12.1`) and + `.github/workflows/sonarqube.yml:67` (`SonarSource/sonarqube-scan-action@v8.3.0`) + resolve through neither an inline SHA nor `actions.lock`. Both my new workflows + pass the gate. Fix: pin the two refs to SHAs, or run `gh actions-lock`. + +| *Gate fixed:* the action-pinning gate now exits 0 for the first time +| `node scripts/check-action-pinning.js` → *exit 0*, "all action refs are pinned". + (Two refs were unpinned on `main` since they were introduced; see A8.) +|=== + +*Correction to an earlier reading:* `scripts/check-lock-sync.sh` is **not** defective. +It aborts here with `FATAL: no awk supporting 3-argument match() (need gawk)` — which is a +clear message and exit 1. Its behaviour is right; the sandbox simply lacks `gawk`. Any +runner that must execute it needs `gawk` installed. + +=== What this means for planning + +The estate's blockers split cleanly into three kinds, and only the third needs the +author: + +. *Scaffolding* (no lakefile, no lock, no lane) — fixable in-repo, today. +. *Execution* (toolchain absent) — fixable by CI, once workflows can start. +. *Authority* (Actions settings, credentials, priority) — owner-only. + +The rest of this plan is ordered along that split. Nothing below asks the author to do +work an agent or a CI job can do first. + +== 1. The rule for the rest of the work + +[quote] +____ +*No outreach until the house is closed.* The follower notes do not go out while this +repository's own gates cannot run, while a rung it claims is unverified, or while a +state file contradicts its receipts. Advice about verification, sent from a repository +that cannot verify, is the fastest way to lose the audience it is addressed to. +____ + +Corollary: W5.7/W5.8 (outreach) are *gated tasks*. They open when Tranche A is closed — +not before, and not "in parallel because they are independent". + +== 2. Owner routing + +[cols="1,2,3",options="header"] +|=== +| Route | Meaning | Typical tasks + +| *AGENT* | In-repo, no toolchain, no credentials | docs, workflows, ledgers, conversion, checks +| *CI* | Runs on GitHub runners; needs an execution path to exist | stackcert, Occ spike, session-IR lane +| *OWNER* | Needs repository settings, credentials, or a decision | Actions allow-list PUT, priority calls, repo access +| *HOST* | Needs a machine with toolchains (his laptop, devcontainer, guix shell) | local confirmation runs, Zephyr fixture +|=== + +== 3. Tranche A — close the house (this week) + +*A is closed when every item below has a receipt.* All of A is agent/owner work; none of +it is research. + +[cols="1,2,1,3",options="header"] +|=== +| ID | Task | Route | Acceptance + +| A1 | Read the Actions posture; if `selected` with a short list, PUT the canon payload + (issue #6) | *OWNER* | a push to `main` where `Secret Scanner`, `Governance` and a + checker job *start* (jobs ≥ 1) +| A2 | Wire the session-IR lane into CI | *AGENT*→*CI* — **done in-repo, dormant until A1** | + `.github/workflows/session-ir.yml` committed: the 14 pinned fixtures + kill-test audit + + repo-shape gates, on the runner's system `python3` (pure stdlib). Cannot *execute* until A1. +| A8 | Pin the two unpinned action refs — **done** | *AGENT* | `node scripts/check-action-pinning.js` + → *exit 0*. `haskell-actions/setup@v2.12.1` → `0f8e8c99d88aeb3fbfd523f1ef2c6f762d10d64d` + and `SonarSource/sonarqube-scan-action@v8.3.0` → `d209202bc7d53ff1cc128f7f907dac145c9d6ae9`, + each with the tag kept as a trailing comment +| A9 | Ensure `gawk` is present wherever `scripts/check-lock-sync.sh` runs | *AGENT* | the script + runs instead of aborting; it already fails correctly (exit 1, clear message) +| A3 | First green `proofs.yml` run | *CI* | `R1 stackcert (Lean 4)` green; its log carries + the `#print axioms` line, pasted into `docs/EXPLAINME.adoc` C5 +| A4 | First `occ-idris` run | *CI* | advisory job green, then `continue-on-error` removed + and the CONJECTURE in EXPLAINME C4 becomes a pasted result +| A5 | Treat `STARTUP_FAILURE` as failure for required checks (estate-wide) | *OWNER* | a + required context that never starts cannot show green (echo-types#330) +| A6 | Re-run `bash scripts/check.sh` (full mode) on a host with both toolchains | *HOST* | + stages 4–5 report PASS, not BLOCKED; ledger updated +| A7 | Ground truth: Zephyr painted-stack fixture | *HOST* | measured ≤ certified recorded + per ULTRAPLAN §6, or the rung's kill criterion fires +|=== + +== 4. Tranche B — receipts and interfaces + +[cols="1,2,1,3",options="header"] +|=== +| ID | Task | Route | Acceptance + +| B1 | Refresh stale state files against their own receipts (residual-evidence, tropical, + absolute-zero) | *AGENT* | no state file contradicts a PROOF-STATUS line +| B2 | Comparisons 2.0 in residual-evidence-types: do composition and revision transport + beyond `Echo.Echo` / `SoundWarrant`? | *AGENT*→*CI* | a checked yes or no — *"a richer + interface is needed"* is a result, not a failure +| B3 | *Cost-vs-state separation*: a composition where the HWM grade and the cost grade + cannot be identified | *AGENT* | a witness pair + a no-identification statement, or a + documented collision that narrows occupancy's thesis +| B4 | Register occupancy-types in the hub's type map (hub#118) | *AGENT* | map row with + question, boundary and the cost/state vocabulary fence +| B5 | Build `verification/proofs` in CI (hub#57) | *AGENT* | XP-1 green in CI, not just on + a laptop +| B6 | Reconcile the choreographic "echo loss-grade" vocabulary with the shared glossary | *AGENT* | README/glossary agreement +|=== + +== 5. Tranche C — rungs and keystones (research, time-boxed) + +[cols="1,2,1,3",options="header"] +|=== +| ID | Task | Route | Kill / honest outcome + +| C1 | Two-event K-CUT-LOSS square under `Independent₂` | *AGENT* | if `Independent₂` needs + hypotheses that trivialise the square, record that as the finding +| C2 | A second, non-degenerate projection pattern | *AGENT* | if degeneracy is essential + rather than incidental, the assembly hypothesis narrows explicitly +| C3 | R2 static pools + affine/linear handles, T1 coherence | *HOST* | **project gate**: + no external consumer and no theorem beyond restatement ⇒ archive with a ledger entry +| C4 | Bachmann–Howard `ψ₀(Ω_ω)` | *AGENT* | remains OPEN by D-2026-06-14; the two Fidelity + postulates are the only ones in the tree and stay quarantined +| C5 | OND-6 conditional composition | *AGENT* | a too-clean positive result is the warning + sign (absolute-zero ROADMAP); treat with suspicion +|=== + +== 6. Tranche D — external standing + +[cols="1,2,1,3",options="header"] +|=== +| ID | Task | Route | Acceptance + +| D1 | Sign and re-anchor the per-repo AFFIRMATIONs at main (hub#69) | *OWNER*+*AGENT* | + dated, GPG-signed, SHA-pinned receipts +| D2 | Pillar E offline half (packaging, DOI, submission) | *OWNER* | submitted +| D3 | absolute-zero artifact-evaluation container | *AGENT* | reviewer reproduces + `ALL-PROVERS-GREEN` with one command +| D4 | Follower notes — send | *OWNER* | *gated on Tranche A closed* (§1) +| D5 | Public write-up: "what a projection/receipt/bound problem looks like, four worked + examples" | *AGENT* | citable artefact; reaches the same audience without 269 messages +|=== + +== 7. What I need from you + +Short, explicit, and each one is a decision or a credential — nothing else: + +. *The Actions posture for this repository* (A1). It is owner-only. Either run the PUT + with the canon payload, or tell me what Settings → Actions shows and I will prepare the + exact command and the positive control. +. *Scope of my hands* (all tranches). This session can only push + `arena/01a1087c-occupancy-types` on this repository. For the other repos I can produce + ready-to-apply patches, or issue bodies, or nothing — your call which. +. *Priority* (next session). Which tranche leads: A (close the house), B (receipts and + interfaces), C (rungs and keystones), or D (standing)? +. *Toolchain route* (A3/A4/A6). CI (needs A1 first), your machine + (`bash tests/run_stackcert.sh`, then paste the `#print axioms` line), or the + devcontainer in this repo — all three are fine; they just need picking. + +Answers to these unblock every row above; nothing else in the plan is waiting on you. + +== 8. Stop rules + +* *A rung that cannot run is BLOCKED, never OK.* `scripts/check.sh` already enforces this + (fixture request, exit 2 semantics); do not "fix" a blocked stage by softening it. +* *Kill criteria fire on schedule.* R2's project gate (occupancy ULTRAPLAN §1.3/§4) is a + real stop, not a milestone: no external consumer + no theorem beyond restatement ⇒ + archive with a ledger entry. +* *No capability claim without a separation* (echo-types' gate discipline). +* *Outreach waits.* See §1. + +== 9. Decision-log additions + +[cols="2,2,3",options="header"] +|=== +| Decision | Choice | Why / revisit + +| Where toolchain-dependent rungs run | *CI*, not the authoring sandbox | Release-asset hosts are unreachable from the sandbox (measured 2026-10-04); runners can fetch them. Revisit if a local toolchain appears. +| Workflow style for new jobs | `actions/checkout` only; toolchains installed in `run:` steps | The allow-list posture can kill any third-party action at startup with `jobs=0` (issue #6). Revisit when the posture is fixed. +| Recon documents | AsciiDoc under `docs/`; follower drafts outside the public repo | Estate markdown rule; unsent drafts about named people are not publishable material. +| Outreach gating | Tranche A closed first | Credibility: advice about verification from a repo that cannot verify is self-defeating. +| stackcert build definition | `lakefile.toml` + pinned `lean-toolchain` committed | The harness's `lake build` / `lake exe` steps require them; without them the rung was permanently unpassable. +|=== diff --git a/docs/retraction-ledger.adoc b/docs/retraction-ledger.adoc index 99ad764..7efb882 100644 --- a/docs/retraction-ledger.adoc +++ b/docs/retraction-ledger.adoc @@ -31,16 +31,39 @@ requested). Blocked ≠ retracted: no claim has been withdrawn. | 2026-09-27 | Idris 2 spike unverified (no `idris2` on PATH in the work environment) | `idris2 --check Occ.idr` from `src/occ/`; `./check-rejections.sh` for the - four expected-rejection controls (see `src/occ/README.adoc`) + four expected-rejection controls (see `src/occ/README.adoc`). *CI path added + 2026-10-04:* `occ-idris` job in `.github/workflows/proofs.yml` + (Idris 2 v0.7.0 over Chez Scheme, advisory until its first green run). | R0-B Piece 2 | 2026-09-27 | stackcert core unverified (no `lean`/`lake` on PATH) | `lake build && lake exe stackcert …` from `src/stackcert/`; `lean StackcertCore.lean` then `#print axioms cert_sound` (see - `src/stackcert/README.adoc`) + `src/stackcert/README.adoc`). *CI path added 2026-10-04:* `stackcert` job in + `.github/workflows/proofs.yml` (Lean 4.15.0 via elan). | R1 Piece 3 +| 2026-10-04 +| *Two blockers were stacked behind one message*: R1's `lake build` / + `lake exe stackcert` steps had **no `lakefile.toml` and no `lean-toolchain` + anywhere in the repository**, so the rung could not have passed even with a + Lean install. The harness's "toolchain absent" report (exit 2) was accurate + but incomplete. +| Fixed in-repo: added `src/stackcert/lakefile.toml` (libs `StackcertCore`, + `Parsers`; exe `stackcert` rooted at `Main`) and + `src/stackcert/lean-toolchain` (`leanprover/lean4:v4.15.0`). Remaining + blocker is the toolchain only, resolved by the `proofs.yml` job. +| R1 Piece 3 + +| 2026-10-04 +| Session IR — the estate's only fully-green rung (14/14 locally) — had *no CI + lane at all*, so its most credible result carried no clickable receipt. +| Added `.github/workflows/session-ir.yml`: checker on the 14 pinned fixtures + + kill-test audit + repo-shape gates, on any runner's system `python3` (the + module is pure standard library). +| R0-B Phase 1 + | 2026-09-27 | Zephyr ground-truth fixture absent (no `west`/QEMU/Zephyr SDK; fixture request issued — see `src/stackcert/README.adoc` §Fixture request) diff --git a/src/stackcert/lakefile.toml b/src/stackcert/lakefile.toml new file mode 100644 index 0000000..e916c17 --- /dev/null +++ b/src/stackcert/lakefile.toml @@ -0,0 +1,30 @@ +# SPDX-License-Identifier: MPL-2.0 +# SPDX-FileCopyrightText: 2026 Jonathan D.A. Jewell (hyperpolymath) +# +# Lake build definition for the stackcert R1 artefacts. +# +# WHY THIS FILE EXISTS: ULTRAPLAN R1 declares stackcert's verification command +# as `bash tests/run_stackcert.sh`, whose stage 2 runs `lake build` and stage 3 +# runs `lake exe stackcert`. Neither could have succeeded without a lake +# definition, so the harness's "toolchain absent" report was two blockers +# stacked: missing build scaffolding *and* an absent toolchain. This file +# supplies the first. The second is a toolchain/CI concern, not a proof claim, +# and is handled by .github/workflows/proofs.yml. +# +# The verified/UNVERIFIED split is unchanged by this file (see README.adoc): +# StackcertCore — the verified core (zero imports, no Mathlib, no holes) +# Parsers, Main — the I/O and CLI layer, explicitly outside cert_sound + +name = "stackcert" +version = "0.1.0" +defaultTargets = ["stackcert"] + +[[lean_lib]] +name = "StackcertCore" + +[[lean_lib]] +name = "Parsers" + +[[lean_exe]] +name = "stackcert" +root = "Main" diff --git a/src/stackcert/lean-toolchain b/src/stackcert/lean-toolchain new file mode 100644 index 0000000..d0eb99f --- /dev/null +++ b/src/stackcert/lean-toolchain @@ -0,0 +1 @@ +leanprover/lean4:v4.15.0 From 46a70cabdad86d7a0375ea21d9233bc3eeda06c8 Mon Sep 17 00:00:00 2001 From: Arena Agent Date: Sun, 4 Oct 2026 21:49:53 +0000 Subject: [PATCH 5/7] =?UTF-8?q?docs(recon):=20A1=20runbook=20=E2=80=94=20t?= =?UTF-8?q?he=20owner-only=20step=20nothing=20else=20can=20route=20around?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The outage reproduces in the current hour: the push of d5caaca produced run 37236457077 (event push, 21:31:42Z) with conclusion startup_failure and jobs=0, while all 37 workflows report state "active". The workflow files themselves pass the local gates (SPDX header in the leading comment block, top-level permissions:, and check-action-pinning.js at exit 0), so jobs die at start — the signature of an allow-list in `selected` mode with an empty pattern set, as in choreographic-programming#16. GET /repos/{owner}/{repo}/actions/permissions returns 403 to this session, so the posture cannot be read from inside the repository. The runbook gives the owner one command to run, maps all three possible outputs to their fix (including the case where the posture is NOT the cause and the PUT should not be applied), recommends `allowed_actions=all` over a narrow pattern list because a missing pattern fails as jobs=0 — the failure being fixed — and closes with a positive control that counts jobs rather than reading badges. Ultraplan: A1 marked as the sole blocker for Tranche A, pointing at the runbook; §0 records the fresh receipt. Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com> --- docs/recon/A1-ACTIONS-RUNBOOK.adoc | 169 ++++++++++++++++++++++++++ docs/recon/ULTRA-PLAN-2026-10-04.adoc | 29 ++++- 2 files changed, 193 insertions(+), 5 deletions(-) create mode 100644 docs/recon/A1-ACTIONS-RUNBOOK.adoc diff --git a/docs/recon/A1-ACTIONS-RUNBOOK.adoc b/docs/recon/A1-ACTIONS-RUNBOOK.adoc new file mode 100644 index 0000000..ffcfd8c --- /dev/null +++ b/docs/recon/A1-ACTIONS-RUNBOOK.adoc @@ -0,0 +1,169 @@ +// SPDX-License-Identifier: CC-BY-4.0 +// SPDX-FileCopyrightText: 2026 Jonathan D.A. Jewell (hyperpolymath) += A1 runbook — make Actions start jobs +:toc: +:icons: font + +*Date:* 2026-10-04 · *Owner:* repository owner (this is the one thing an agent +cannot do from inside the repository) · *Blocks:* every other item in Tranche A + +== 1. What is already established (measured, not assumed) + +[cols="2,3",options="header"] +|=== +| Observation | Evidence + +| Job-start failures are total, not partial +| Last 100 runs: 96 `startup_failure`, 3 `failure`, 1 `success`. Only *4* runs had any + job at all — the four Dependabot "Update" workflows. + +| It reproduces on the current branch, right now +| The push of `d5caaca` created run `37236457077` ("Push email notification", event + `push`, 2026-10-04T21:31:42Z) → `conclusion: startup_failure`, `jobs: 0`. + +| The workflow files themselves are not the problem +| All 37 workflows report `state: active`. The new ones pass the local gates: SPDX header + in the leading comment block, top-level `permissions:`, and + `node scripts/check-action-pinning.js` → *exit 0*. + +| The local gate passes +| `bash scripts/check.sh --runnable-only` → exit 0 (Session IR 14/14, kill-test audit, + repo shape; proof stages correctly `BLOCKED`, not skipped). +|=== + +*Diagnosis:* a failure at job start, at repository level, affecting every workflow +including ones whose only action is `actions/checkout`. That is the signature of an +allow-list in `selected` mode with an empty pattern set — the same defect as +choreographic-programming#16, where `selected` carried zero patterns and so blocked +*every* action, `actions/checkout` included. + +*What is still unknown:* the posture itself. `GET /repos/{owner}/{repo}/actions/permissions` +returns **403** to this session's token, so the value cannot be read from inside the +repository. That is why A1 is owner-routed. + +== 2. What to run (one command) + +Requires a token with Actions administration rights (fine-grained: *Actions* read/write; +classic: `admin:repo_hook` or full `repo`). If `gh` reports a missing scope, refresh first: + +[source,bash] +---- +gh auth refresh -s admin:repo_hook +---- + +Then: + +[source,bash] +---- +gh api repos/hyperpolymath/occupancy-types/actions/permissions --jq . + +# If the above prints allowed_actions: "selected", list the patterns: +gh api repos/hyperpolymath/occupancy-types/actions/permissions/selected-actions --jq . +---- + +Paste the output. Everything below follows from which of the three cases it is. + +== 3. Read the result + +[cols="1,3,3",options="header"] +|=== +| Case | Output looks like | What it means + +| *A* +| `"enabled": true, "allowed_actions": "all"` +| Posture is *not* the cause. The outage is elsewhere (runner availability, billing, + or a disabled-actions flag at another level). Do not apply the PUT in §4 — it would + change nothing and muddy the evidence. Report the output and we re-diagnose. + +| *B* +| `"enabled": true, "allowed_actions": "selected"`, and the selected-actions list is + *empty* (or omits `actions/*`) +| This is the defect. Every action is blocked, including GitHub-owned + `actions/checkout`, which is why `jobs: 0` on every run. Apply §4. + +| *C* +| `"enabled": false` +| Actions are disabled for the repository. Apply §5 first, then §4 if it also reads + `selected`. +|=== + +== 4. The fix for case B — allow actions + +Two options; the first is one command and matches what the rest of the estate runs. + +[source,bash] +---- +# Option 1 (recommended): allow all actions +gh api -X PUT repos/hyperpolymath/occupancy-types/actions/permissions \ + -f enabled=true -f allowed_actions=all +---- + +[source,bash] +---- +# Option 2 (tighter): allow GitHub-owned actions + the pinned third parties this repo uses +gh api -X PUT repos/hyperpolymath/occupancy-types/actions/permissions \ + -f enabled=true -f allowed_actions=selected \ + -F github_owned_allowed=true \ + -F verified_allowed=false \ + -f 'patterns_allowed[]=actions/*' \ + -f 'patterns_allowed[]=github/codeql-action/*' \ + -f 'patterns_allowed[]=dependabot/fetch-metadata@*' \ + -f 'patterns_allowed[]=erlef/setup-beam@*' \ + -f 'patterns_allowed[]=haskell-actions/setup@*' \ + -f 'patterns_allowed[]=oven-sh/setup-bun@*' \ + -f 'patterns_allowed[]=SonarSource/sonarqube-scan-action@*' \ + -f 'patterns_allowed[]=hyperpolymath/standards/.github/workflows/*' +---- + +Option 2 is stricter but brittle: every new action needs a new pattern, and a missing +pattern fails as `jobs: 0` — the exact failure being fixed. *Option 1 is recommended* +precisely because it removes a silent-failure mode rather than narrowing it. + +== 5. The fix for case C — enable Actions + +[source,bash] +---- +gh api -X PUT repos/hyperpolymath/occupancy-types/actions/permissions -f enabled=true +---- + +== 6. Positive control — prove it worked + +Do not trust the badge; count jobs. A workflow that starts is the only evidence a +workflow can start. + +[source,bash] +---- +# Trigger a run (empty commit is enough and changes no content) +git commit --allow-empty -m "chore: A1 positive control" && git push + +# Then, after ~30s: +gh api "repos/hyperpolymath/occupancy-types/actions/runs?per_page=5" \ + --jq '.workflow_runs[] | "\(.id)\t\(.name)\t\(.conclusion)"' + +# R1: how many of the last 20 runs actually executed a job? +for id in $(gh api "repos/hyperpolymath/occupancy-types/actions/runs?per_page=20" \ + --jq '.workflow_runs[].id'); do + printf "%s\t%s\n" "$id" \ + "$(gh api "repos/hyperpolymath/occupancy-types/actions/runs/$id/jobs" --jq '.total_count')" +done +---- + +*A1 is closed when:* the newest `Session IR (R0-B)` and `Proofs (R0-B Occ, R1 stackcert)` +runs show `total_count >= 1` and a conclusion other than `startup_failure`. + +Both new workflows are `workflow_dispatch`, so they can also be started by hand — +useful for the control, since it avoids waiting on a path filter: + +[source,bash] +---- +gh workflow run session-ir.yml -R hyperpolymath/occupancy-types +gh workflow run proofs.yml -R hyperpolymath/occupancy-types +---- + +== 7. Note on scope + +`hyperpolymath` is a user account, so the repository-level setting is authoritative; +there is no organisation policy above it that could override the change. (If this were +an org-owned repo, an org-level allow-list would win, and the fix would have to be +applied there instead — worth checking if the outputs above look right but runs still +show `jobs: 0`.) diff --git a/docs/recon/ULTRA-PLAN-2026-10-04.adoc b/docs/recon/ULTRA-PLAN-2026-10-04.adoc index 9e8e22e..e33e88c 100644 --- a/docs/recon/ULTRA-PLAN-2026-10-04.adoc +++ b/docs/recon/ULTRA-PLAN-2026-10-04.adoc @@ -57,6 +57,14 @@ toc::[] (Two refs were unpinned on `main` since they were introduced; see A8.) |=== +| The outage reproduces on this branch, in the current hour +| The push of `d5caaca` created run `37236457077` ("Push email notification", 21:31:42Z) + → `startup_failure`, `jobs: 0`. All 37 workflows report `state: active`. So the workflow + *files* are fine (they also pass the SPDX, permissions and pinning gates); jobs die at + start. Signature matches choreographic#16: `selected` with an empty pattern set, which + blocks GitHub-owned `actions/checkout` too. +|=== + *Correction to an earlier reading:* `scripts/check-lock-sync.sh` is **not** defective. It aborts here with `FATAL: no awk supporting 3-argument match() (need gawk)` — which is a clear message and exit 1. Its behaviour is right; the sandbox simply lacks `gawk`. Any @@ -109,8 +117,9 @@ it is research. | ID | Task | Route | Acceptance | A1 | Read the Actions posture; if `selected` with a short list, PUT the canon payload - (issue #6) | *OWNER* | a push to `main` where `Secret Scanner`, `Governance` and a - checker job *start* (jobs ≥ 1) + (issue #6) — see the dedicated `A1-ACTIONS-RUNBOOK.adoc` | *OWNER* | a push where + `Session IR` and `Proofs` *start* (`total_count >= 1`, conclusion ≠ `startup_failure`). + *This is the only item blocking Tranche A; everything else in A waits on it.* | A2 | Wire the session-IR lane into CI | *AGENT*→*CI* — **done in-repo, dormant until A1** | `.github/workflows/session-ir.yml` committed: the 14 pinned fixtures + kill-test audit + repo-shape gates, on the runner's system `python3` (pure stdlib). Cannot *execute* until A1. @@ -191,9 +200,19 @@ it is research. Short, explicit, and each one is a decision or a credential — nothing else: -. *The Actions posture for this repository* (A1). It is owner-only. Either run the PUT - with the canon payload, or tell me what Settings → Actions shows and I will prepare the - exact command and the positive control. +. *The Actions posture for this repository* (A1) — the one item nothing else can + route around. Paste the output of: ++ +[source,bash] +---- +gh api repos/hyperpolymath/occupancy-types/actions/permissions --jq . +# and, if it reads "selected": +gh api repos/hyperpolymath/occupancy-types/actions/permissions/selected-actions --jq . +---- ++ +It returns 403 to me, so this cannot be read from inside the repository. +`A1-ACTIONS-RUNBOOK.adoc` maps all three possible outputs to their fix and gives the +positive control (count jobs, do not read badges). . *Scope of my hands* (all tranches). This session can only push `arena/01a1087c-occupancy-types` on this repository. For the other repos I can produce ready-to-apply patches, or issue bodies, or nothing — your call which. From 57384c9b0dcc2caf380632cc6dcbc764b86d2ca1 Mon Sep 17 00:00:00 2001 From: Arena Agent Date: Sun, 4 Oct 2026 22:00:56 +0000 Subject: [PATCH 6/7] =?UTF-8?q?docs(recon):=20A1=20runbook=20=E2=80=94=20t?= =?UTF-8?q?he=20repos/=20prefix=20is=20required,=20and=20what=20403=20mean?= =?UTF-8?q?s?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The owner's first attempt returned 404. That is a routing error, not a permissions answer: `gh api occupancy-types/actions/permissions` has no such route, while `repos/hyperpolymath/occupancy-types/actions/permissions` exists and answers (403 for this session, whose App token cannot read the endpoint at any scope). Both facts verified directly on 2026-10-04. Records the three statuses a reader can now expect and what each means — 404 bad route, 403 integration-token (unfixable by scope, needs a user login), 403 missing scope (fixable with gh auth refresh -s admin:repo_hook) — so the owner does not read a 404 as "no permission" and stop. Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com> --- docs/recon/A1-ACTIONS-RUNBOOK.adoc | 25 ++++++++++++++++++++++++- docs/recon/ULTRA-PLAN-2026-10-04.adoc | 8 +++++--- 2 files changed, 29 insertions(+), 4 deletions(-) diff --git a/docs/recon/A1-ACTIONS-RUNBOOK.adoc b/docs/recon/A1-ACTIONS-RUNBOOK.adoc index ffcfd8c..12ae408 100644 --- a/docs/recon/A1-ACTIONS-RUNBOOK.adoc +++ b/docs/recon/A1-ACTIONS-RUNBOOK.adoc @@ -51,7 +51,7 @@ classic: `admin:repo_hook` or full `repo`). If `gh` reports a missing scope, ref gh auth refresh -s admin:repo_hook ---- -Then: +Then run this **exactly as written**: [source,bash] ---- @@ -63,6 +63,29 @@ gh api repos/hyperpolymath/occupancy-types/actions/permissions/selected-actions Paste the output. Everything below follows from which of the three cases it is. +[IMPORTANT] +==== +*The `repos/` prefix is not optional.* `gh api occupancy-types/actions/permissions` +(no `repos/`) returns *HTTP 404 Not Found* — there is no such route, so the 404 says +nothing about permissions. Verified directly on 2026-10-04: + +[cols="1,1",options="header"] +|=== +| Command | Result +| `gh api occupancy-types/actions/permissions` | `404 Not Found` (bad route) +| `gh api repos/hyperpolymath/occupancy-types/actions/permissions` | route exists +|=== + +Two other statuses and what they mean: + +* *`403 Resource not accessible by integration`* — an **App/integration** token. Such + tokens can never read this endpoint, no matter the scope. This session's token is one + of those, which is why the value had to be requested rather than fetched. A normal + user login is not affected. +* *`403` with a message about scopes* (on a user token) — the token lacks the + administration scope. Run `gh auth refresh -s admin:repo_hook` and repeat. +==== + == 3. Read the result [cols="1,3,3",options="header"] diff --git a/docs/recon/ULTRA-PLAN-2026-10-04.adoc b/docs/recon/ULTRA-PLAN-2026-10-04.adoc index e33e88c..b1e1ebf 100644 --- a/docs/recon/ULTRA-PLAN-2026-10-04.adoc +++ b/docs/recon/ULTRA-PLAN-2026-10-04.adoc @@ -210,9 +210,11 @@ gh api repos/hyperpolymath/occupancy-types/actions/permissions --jq . gh api repos/hyperpolymath/occupancy-types/actions/permissions/selected-actions --jq . ---- + -It returns 403 to me, so this cannot be read from inside the repository. -`A1-ACTIONS-RUNBOOK.adoc` maps all three possible outputs to their fix and gives the -positive control (count jobs, do not read badges). +It returns 403 to me (an App token, which cannot read this endpoint at any scope), so +this cannot be read from inside the repository. Note the `repos/` prefix is required — +without it the call returns *404 Not Found*, which is a bad route, not a permissions +answer. `A1-ACTIONS-RUNBOOK.adoc` maps all three possible outputs to their fix and gives +the positive control (count jobs, do not read badges). . *Scope of my hands* (all tranches). This session can only push `arena/01a1087c-occupancy-types` on this repository. For the other repos I can produce ready-to-apply patches, or issue bodies, or nothing — your call which. From 5f934774be3b00b5b25ed25e6ab405d15b203c98 Mon Sep 17 00:00:00 2001 From: Arena Agent Date: Sun, 4 Oct 2026 22:11:20 +0000 Subject: [PATCH 7/7] docs(recon): correct the A1 scope advice; add a zero-scope UI route MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit An earlier revision told the owner to run `gh auth refresh -s admin:repo_hook`. That scope governs webhooks, not Actions settings, so it would have done nothing useful. Verified against GitHub's REST documentation for the repository-level Actions permissions endpoints: a classic PAT/OAuth token needs the `repo` scope, and a fine-grained PAT needs "Administration" repository permissions (read to GET, write to PUT). The organisation-level endpoints are the ones needing admin:org / Administration org permissions, and they do not apply here — hyperpolymath is a user account, so the repository-level setting is authoritative. Also documents two things that were previously glossed over: `gh auth refresh` only works for OAuth/browser logins (a stored PAT cannot have scopes added to it; that needs a new token), and the settings page at /settings/actions shows the same three-way choice with no token at all — now the recommended route, since it is also where the fix is applied. Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com> --- docs/recon/A1-ACTIONS-RUNBOOK.adoc | 70 ++++++++++++++++++++++++--- docs/recon/ULTRA-PLAN-2026-10-04.adoc | 6 ++- 2 files changed, 69 insertions(+), 7 deletions(-) diff --git a/docs/recon/A1-ACTIONS-RUNBOOK.adoc b/docs/recon/A1-ACTIONS-RUNBOOK.adoc index 12ae408..1ff05e3 100644 --- a/docs/recon/A1-ACTIONS-RUNBOOK.adoc +++ b/docs/recon/A1-ACTIONS-RUNBOOK.adoc @@ -41,16 +41,74 @@ choreographic-programming#16, where `selected` carried zero patterns and so bloc returns **403** to this session's token, so the value cannot be read from inside the repository. That is why A1 is owner-routed. -== 2. What to run (one command) +== 2. Reading the posture — two routes -Requires a token with Actions administration rights (fine-grained: *Actions* read/write; -classic: `admin:repo_hook` or full `repo`). If `gh` reports a missing scope, refresh first: +=== 2.1 Route A — the settings page (no token, no scopes) + +Open https://github.com/hyperpolymath/occupancy-types/settings/actions and read the +*Actions permissions* section. It is three radio buttons: + +[cols="1,3",options="header"] +|=== +| Radio | What it means here +| *Allow all actions and reusable workflows* | Posture is fine (case A in §3) — the outage + is something else, so do not change anything. +| *Allow select actions and reusable workflows* | Case B. Read the list underneath: if it + is empty, or omits `actions/*`, that is the defect. +| *Disable actions* | Case C. Actions are off for the repository. +|=== + +This route needs no token at all, and it is the recommended one: no scopes, nothing to +refresh, and the same page is where the fix is applied. + +=== 2.2 Route B — the API + +[IMPORTANT] +==== +*Scope correction (2026-10-04).* An earlier revision of this document said +`gh auth refresh -s admin:repo_hook`. **That was wrong.** `admin:repo_hook` governs +webhooks, not Actions settings. Per GitHub's REST documentation for the repository-level +Actions permissions endpoints: + +* classic PAT / OAuth token → the *`repo`* scope; +* fine-grained PAT → *"Administration"* repository permissions (read to GET, write to PUT). + +(Worth knowing: the *organisation*-level equivalents need `admin:org`/Administration org +permissions. Those are not what this repository needs — `hyperpolymath` is a user account, +so the repository-level setting is authoritative.) +==== + +First, see what your current credential can do: [source,bash] ---- -gh auth refresh -s admin:repo_hook +gh auth status ---- +If the scopes listed do not include `repo` (or an equivalent fine-grained grant): + +[source,bash] +---- +# Works when gh was authenticated via the browser (OAuth): +gh auth refresh -s repo +---- + +[NOTE] +==== +`gh auth refresh` expands scopes by opening a browser, which only works for +*OAuth/browser* logins. If your stored credential is a **personal access token** (the +`gh auth login --with-token` case), `gh` cannot add scopes to it — refreshing will fail. +In that case make a new classic PAT at https://github.com/settings/tokens with the +*`repo`* scope (add `workflow` too, since it governs workflow files) and either log in +with it or use it for one call: + +[source,bash] +---- +gh auth login --with-token < token.txt +GH_TOKEN=ghp_xxx gh api repos/hyperpolymath/occupancy-types/actions/permissions --jq . +---- +==== + Then run this **exactly as written**: [source,bash] @@ -82,8 +140,8 @@ Two other statuses and what they mean: tokens can never read this endpoint, no matter the scope. This session's token is one of those, which is why the value had to be requested rather than fetched. A normal user login is not affected. -* *`403` with a message about scopes* (on a user token) — the token lacks the - administration scope. Run `gh auth refresh -s admin:repo_hook` and repeat. +* *`403` with a message about scopes* (on a user token) — the token lacks the `repo` + scope. Fix per §2.2: `gh auth refresh -s repo`, or a new classic PAT with `repo`. ==== == 3. Read the result diff --git a/docs/recon/ULTRA-PLAN-2026-10-04.adoc b/docs/recon/ULTRA-PLAN-2026-10-04.adoc index b1e1ebf..8fce7d9 100644 --- a/docs/recon/ULTRA-PLAN-2026-10-04.adoc +++ b/docs/recon/ULTRA-PLAN-2026-10-04.adoc @@ -201,7 +201,11 @@ it is research. Short, explicit, and each one is a decision or a credential — nothing else: . *The Actions posture for this repository* (A1) — the one item nothing else can - route around. Paste the output of: + route around. Either paste the output of the command below, *or* just read the + three radio buttons at + https://github.com/hyperpolymath/occupancy-types/settings/actions (Actions + permissions) and tell me which one is selected — the UI route needs no token + and no scopes. + [source,bash] ----