Skip to content

core: lower authored physical declarations into the canonical Program - #456

Closed
lemone112 wants to merge 1 commit into
agent/lcs-cam16-ucs-viewfrom
agent/canonical-program-lowerer
Closed

core: lower authored physical declarations into the canonical Program#456
lemone112 wants to merge 1 commit into
agent/lcs-cam16-ucs-viewfrom
agent/canonical-program-lowerer

Conversation

@lemone112

@lemone112 lemone112 commented Jul 23, 2026

Copy link
Copy Markdown
Collaborator

Summary

  • Add the sole concrete authored-package lowerer whose draft owns the actual CoreProgramV1 IR and compiles it atomically into the existing strong compiled owner. There is no transport DTO, duplicate declaration graph, or generic evaluator boundary.
  • Admit only typed physical declarations: encoded-sRGB8 Sources; fixed/finite Targets and explicit complete joint order; opacity inputs; Solid/Opacity Paints; Input/FromOccurrence Surfaces; encoded-sRGB8 SourceOver Occurrences with exact admitted appearance context; Exact/WCAG 2.2 hard/report constraints; and output slots.
  • Enforce a compile-time bijection between every declared SurfaceInputPort and exactly one input Surface. Undeclared, unused, duplicate, and dangling bindings fail closed.
  • Project Core compile failures through one authoritative owned typed enum. Duplicate participants, exact candidate stimulus, joint state/order detail, and full paint/render cycle membership are retained; cycle buffers move across the seam without a second allocation.
  • Use exact public physical names (OpacityInputId, SurfaceInputPortId, OutputSlot) with no compatibility aliases.
  • Preserve the existing weak generation-bound Session owner, canonical input/output order, borrowed state/certificate projection, and allocation-free replay after scratch growth.
  • Renew the canonical zero-headroom WASM ratchet to the two-build artifact measured by CI run 29971399220: raw/max 376830 B. Gzip 168035 B and artifact SHA-256 49842d628e4bdfb14afd00323b73960a0e88d4439dec9c15710e52c245e8516e remain diagnostic-only.

Scope

  • Exactly 10 files stacked on core: derive a typed CAM16-UCS occurrence view #455 (e45fcc2…), +2009/-63: 8 lowerer/proof files and 2 mechanically renewed WASM attestation files.
  • No PairFill, PairLabel, Glow, Material, Ladder, AlphaAnalog, recipe taxonomy, client vocabulary, string/serde declaration dialect, callbacks, evaluator registry, compatibility facade, arbitrary resource cap, WASM export, or controller change.
  • The package contract owns one unobservable canonical observation group; an empty authored port set is therefore reported as EmptySurfaceInputPortSet, without leaking the private generic group identity.
  • This slice makes no inverse-LCS, distance/UCS calibration, renderer, display, or universal-background claim. The packed streaming Core/WASM adapter is the next stack slice.

Verification

  • Rust 1.96 Core all-targets: 717 passed, 6 ignored
  • external authored-package RED contract: 13/13
  • property invariants: 7/7
  • solver characterization: 5/5
  • doctests: 4 + 28 compile-fail
  • clippy --all-targets -- -D warnings
  • rustfmt check
  • point-support independent verifier
  • proof claims/algebra semantic diff
  • focused canonical WASM budget contract
  • exact-head GitHub CI — run 29971850217
  • exact-head Native conformance — run 29971850206
  • CodeRabbit

Proof closure: 4310a239e732f0710fd6201c2517fd98ef4afd0e3cd8e27c248dee69d6c54cb3.
Proof payload: 2ab90713f2008fab2ba343d4525164ba9177d5bdda1a890bd3192a5ffd1891d8.
Verifier: 742503a19220d71dc5d4c4ff22c9e5e7cb407d2506e450312b87e7ba342761f0.
Canonical WASM budget SHA-256: 84a8d2e1f0517f871256fdc64bdf9323135c497e3a374b751d8c0bb710f60084.

This is a stacked draft. Review only against agent/lcs-cam16-ucs-view; do not merge independently.

@coderabbitai

coderabbitai Bot commented Jul 23, 2026

Copy link
Copy Markdown

Important

Review skipped

Draft detected.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: b0ee7761-26af-4202-96ac-9f7f8ae24a6c

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch agent/canonical-program-lowerer

Comment @coderabbitai help to get the list of available commands.

@lemone112
lemone112 force-pushed the agent/canonical-program-lowerer branch from 8326208 to 45f7de4 Compare July 23, 2026 01:27
lemone112 added a commit that referenced this pull request Jul 25, 2026
…fact

The exact-length gate still pinned 376830B from
`canonical-authored-program-lowerer` (#456, run 29971399220). This slice
grew the runtime artifact to 376985B and did not carry the re-pin that
every earlier stacked slice performed (#450, #452, #454, #456), so the
gate has rejected this head and every head above it.

The +155B is attributable to this slice alone: runs 30115821523 (#457),
30124467410 (#458), 30125634830 (#459), 30129537515 (#460) and
30136346868 (#461) all measure exactly 376985B, so #458-#461 contribute
zero bytes to the artifact and were failing only on the inherited pin.

The new measurement is the CI run for this exact head
(39ee0a7), not a local build: the
canonical platform is linux-x64 and a local arm64 build only produces a
DIAGNOSTIC result. The budget file's own SHA-256 is re-pinned in the
checker so the drift gate keeps rejecting unattributed edits.

Co-Authored-By: Claude <noreply@anthropic.com>
lemone112 added a commit that referenced this pull request Jul 26, 2026
* feat(core): compile generic point-render sessions

* fix(core): satisfy format and all-target lint gates

* perf(core): recycle point-render session buffers

* style(core): format reusable session buffers

* feat(lcs): execute sealed sRGB8 tristimulus derivation

* style(lcs): format sealed tristimulus slice

* feat(lcs): derive versioned appearance views

* style(lcs): canonicalize Oklab coefficient

* feat(core): expose typed terminal program path

* fix(core): satisfy terminal Program quality gates

* feat(lcs): bind private output projection registry

* style(core): canonicalize release module order

* fix(core): scope private registry lint firewall

* fix(core): harden terminal Program admission

* style(core): match pinned Rust formatter

* feat(core): bind F0 release descriptors

* perf(core): add linear canonical surface ingestion

* refactor(core): unify terminal physical identities

* perf(core): prebind terminal evaluation slots

* perf(core): make present ingestion lazy and borrowed

* refactor(core): remove per-port surface mutation

* feat(core): evaluate typed constraints and emit terminal paints

* feat(core): bind observation groups to runtime streams

* refactor(core): share one encoded point Paint value

* refactor(core): share revision-bound observation state

- admit correlated scenario sets once behind shared immutable backing
- make joint selection domain-safe, linear, and ownership-retryable
- refresh source-bound release proof gates

* fix(ci): bind V2a budget to measured artifact

- keep allocation tests ownership-preserving without a large Result closure
- pin the zero-headroom WASM ratchet to the reproducible V2a artifact

* refactor(core): remove superseded Program runtime

Keep only the private Program compiler/lowering payload for the direct sole-Session bridge.
Delete the duplicate owner, lifecycle, output materialization, and test evaluator scaffolding.
Pin the hard cut with a negative facade gate and refresh the exact point-support source receipt.

* feat(core): execute compiled plans through sole Session

Replace the point-support-specific lifecycle with one sealed monomorphized Session, attach reusable CompiledProgram epochs through strong ownership, and retain complete case-by-constraint reports. Bind every decision to the exact admitted observation before atomic commit and refresh release proof pins.

* feat(core): bind Program assessments to context-bound LCS

* Hard-delete Pair taxonomy from shipping surfaces

* Compile typed finite targets into Program sessions

* quarantine unsupported Display P3 promises

* core: make compiled programs the sole session-generation owner

* core: close the evaluator union and package session bridge

* core: derive a typed CAM16-UCS occurrence view

* core: lower authored physical declarations into the canonical Program

* core: bind Program content identity

* core: name versioned identity discriminants

* fix(ci): re-pin the runtime WASM budget to this slice's measured artifact

The exact-length gate still pinned 376830B from
`canonical-authored-program-lowerer` (#456, run 29971399220). This slice
grew the runtime artifact to 376985B and did not carry the re-pin that
every earlier stacked slice performed (#450, #452, #454, #456), so the
gate has rejected this head and every head above it.

The +155B is attributable to this slice alone: runs 30115821523 (#457),
30124467410 (#458), 30125634830 (#459), 30129537515 (#460) and
30136346868 (#461) all measure exactly 376985B, so #458-#461 contribute
zero bytes to the artifact and were failing only on the inherited pin.

The new measurement is the CI run for this exact head
(39ee0a7), not a local build: the
canonical platform is linux-x64 and a local arm64 build only produces a
DIAGNOSTIC result. The budget file's own SHA-256 is re-pinned in the
checker so the drift gate keeps rejecting unattributed edits.

Co-Authored-By: Claude <noreply@anthropic.com>

* fix(ci): re-bind the point-support source capsule to this slice's cone

This slice moves files inside the point-support semantic cone, so the capsule
digest and the committed surplus proof move with it. Both are now regenerated in
the same commit that causes the drift, matching the convention the rest of the
stack follows; previously the re-bind was batched at #460, which left #457-#459
fail-closed on their own heads and made the stack unmergeable in order.

Numerical review: every proof field is unchanged. Only the source-binding
identities move -- the file hashes of the cone files this slice edits, the
resulting closure digest, the verifier hash and the rolled-up payload hash.
The surplus mathematics is byte-identical.

Co-Authored-By: Claude <noreply@anthropic.com>

* core: project complete program certificate evidence

* fix(ci): re-bind the point-support source capsule to this slice's cone

This slice moves files inside the point-support semantic cone, so the capsule
digest and the committed surplus proof move with it. Both are now regenerated in
the same commit that causes the drift, matching the convention the rest of the
stack follows; previously the re-bind was batched at #460, which left #457-#459
fail-closed on their own heads and made the stack unmergeable in order.

Numerical review: every proof field is unchanged. Only the source-binding
identities move -- the file hashes of the cone files this slice edits, the
resulting closure digest, the verifier hash and the rolled-up payload hash.
The surplus mathematics is byte-identical.

Co-Authored-By: Claude <noreply@anthropic.com>

* core: bind Program operations to exact owner snapshots

* fix(ci): re-bind the point-support source capsule to this slice's cone

This slice moves files inside the point-support semantic cone, so the capsule
digest and the committed surplus proof move with it. Both are now regenerated in
the same commit that causes the drift, matching the convention the rest of the
stack follows; previously the re-bind was batched at #460, which left #457-#459
fail-closed on their own heads and made the stack unmergeable in order.

Numerical review: every proof field is unchanged. Only the source-binding
identities move -- the file hashes of the cone files this slice edits, the
resulting closure digest, the verifier hash and the rolled-up payload hash.
The surplus mathematics is byte-identical.

Co-Authored-By: Claude <noreply@anthropic.com>

* core: single-own compiled observation schemas

* chore(proof): document Python 3.9 zip invariant

* core: define the public Program API

* core: address Program API review

* fix(ci): re-bind public Program proof capsule

* test: close compile-fail sentinel escape

* core: make joint order non-empty by construction and bound evidence cells

`AdmittedFiniteJointOrderV1` stored one flat tuple slice, so an empty
admitted order was representable and the evaluation path carried a
runtime `state_count == 0 -> InternalInvariant` guard to reject it. The
guard proved nothing about the type; it only re-checked a property the
constructor already enforced.

Split the order into `first + rest`. Non-emptiness becomes structural,
`state_count()` is total, and the `InternalInvariant` branch in
`prepare_program_evaluation_buffers` is deleted rather than left dead.
The `joint_state_count: Option<usize>` parameter disappears with it:
cell counts are now derived from the epoch itself.

The same pass stops reserving an exhaustive-conflict buffer that no
constraint can ever fill. `can_conflict` is false when every compiled
constraint is report-only, so a report-only program no longer reserves
`cases x constraints x states` cells and no longer reports
`ResourceExhausted` for a conflict it cannot produce.

`OwnerV1::evidence_cell_bounds` exposes the same arithmetic as a pure
preflight, with `EvidenceBoundsErrorV1::CardinalityOverflow` as the only
closed failure. It creates no Session and mutates no state.

Verified locally on the CI-pinned toolchain: full workspace tests green,
`cargo fmt --all --check` and `cargo clippy --workspace --all-targets --
-D warnings` clean.

Co-Authored-By: Claude <noreply@anthropic.com>

* docs: explain packed proof invariants

* core: fail closed without current Program evidence

* core: revoke outputs on unknown session handoff

* core: keep incomplete Program crate-private

* perf: bind smaller private Program wasm

* core: make staged Program unexportable

* ci: explain rustdoc surface mismatch

---------

Co-authored-by: Claude <noreply@anthropic.com>
@lemone112

Copy link
Copy Markdown
Collaborator Author

Superseded by the reviewed cumulative squash merge #465 (24fd1f4). The lower stacked branch was intentionally not merged on its own because its intermediate head was not the safe terminal public boundary.

@lemone112 lemone112 closed this Jul 26, 2026
@lemone112
lemone112 deleted the agent/canonical-program-lowerer branch July 27, 2026 00:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant