From a40fb9ba0bd398316d319e756f06fc78c86b0b4c Mon Sep 17 00:00:00 2001 From: Claude Date: Wed, 16 Sep 2026 13:13:55 +0000 Subject: [PATCH 1/8] docs(flaws): repoint the remaining F citations onto their minted FLAW-n addresses MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The superproject's flaw register minted registry-form addresses on 2026-09-16. That pass repointed the superproject doc tier and the DF/LF citations; its F half was scoped to the superproject and said so. This closes it here. Every site was read before it was rewritten. The MetaLog entries kept their numbers, so these are prefix changes that cannot mis-map. Deliberately untouched and distinguished by reading, not by pattern: the ML F1 score, float16 and hex literals, flake8 suppressions, and the MetaLog specification's own F2(b) clause — a public standard's numbering, in a different number space. Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_01DgF1dGH16hPwX7aaaKguWw --- core/CMakeLists.txt | 4 ++-- core/tests/mask/test_stateless_template.cpp | 2 +- core/tools/f13_cardinality_measure.cpp | 4 ++-- technical_docs/canonicalization_generations.md | 2 +- 4 files changed, 6 insertions(+), 6 deletions(-) diff --git a/core/CMakeLists.txt b/core/CMakeLists.txt index 71c680d..6693d86 100644 --- a/core/CMakeLists.txt +++ b/core/CMakeLists.txt @@ -296,7 +296,7 @@ install(FILES ${CMAKE_CURRENT_BINARY_DIR}/insight_canon-config.cmake ########################################################### # Measurement instruments (tools/) — built on the package's own compile surface ########################################################### -# The F13 masker-cardinality re-measure (ADR-8.D5): a CLI over the PUBLIC +# The FLAW-13 masker-cardinality re-measure (ADR-8.D5): a CLI over the PUBLIC # facade, deliberately NOT a test — its population is operator-mounted, so it reports and declares # rather than asserts. Built unconditionally so it can never rot unseen (the malf one-compile-surface # rule), linked exactly as an external consumer would link. @@ -306,7 +306,7 @@ target_compile_features(f13_cardinality_measure PRIVATE cxx_std_23) set_target_properties(f13_cardinality_measure PROPERTIES CXX_SCAN_FOR_MODULES ON CXX_MODULE_STD ON) # The G-L11 leading-level TOKEN-INDEX re-measure (ADR-16.D7, ROADMAP N98): the same shape as the -# F13 tool above — a CLI over the PUBLIC facade whose population is operator-mounted, so it declares +# FLAW-13 tool above — a CLI over the PUBLIC facade whose population is operator-mounted, so it declares # (files, lines, doors, the model's own control) and never asserts. It is what the token budget's # VALUE is taken from, and it re-runs on every corpus the budget is later re-derived against. add_executable(leading_level_token_index_measure tools/leading_level_token_index_measure.cpp) diff --git a/core/tests/mask/test_stateless_template.cpp b/core/tests/mask/test_stateless_template.cpp index 0aa6242..d574443 100644 --- a/core/tests/mask/test_stateless_template.cpp +++ b/core/tests/mask/test_stateless_template.cpp @@ -81,7 +81,7 @@ TEST(StatelessTemplate, KillsThePhantomPair) // invariant: the accepted tradeoff — the region word is KEPT literal rather than wildcarded. // refs: ADR-16.D5 EXPECT_NE(in_stream_a.find("eu-west"), std::string::npos) - << "a letter-leading word stays literal (F13 boundary): " << in_stream_a; + << "a letter-leading word stays literal (FLAW-13 boundary): " << in_stream_a; } TEST(StatelessTemplate, StatusValueKeptDistinct) diff --git a/core/tools/f13_cardinality_measure.cpp b/core/tools/f13_cardinality_measure.cpp index 61acdb4..dc9f524 100644 --- a/core/tools/f13_cardinality_measure.cpp +++ b/core/tools/f13_cardinality_measure.cpp @@ -121,7 +121,7 @@ try consumed.push_back(std::move(record)); } - std::println("=== Stateless template_id cardinality (F13 re-measure) ==="); + std::println("=== Stateless template_id cardinality (FLAW-13 re-measure) ==="); std::println("population : {} of {} *.log files under {} (recursive, sorted walk)", consumed.size(), files.size(), corpus_dir.string()); std::println("line budget : {}{}", max_lines, @@ -156,7 +156,7 @@ try for (std::size_t index{0}; index < std::min(kTopTemplatesShown, by_count.size()); ++index) std::println("{} {}", by_count[index].second, std::string_view{by_count[index].first}.substr(0, kTemplatePreviewChars)); - std::println("--- {} singleton samples (the F13 over-split tail) ---", kSingletonSamplesShown); + std::println("--- {} singleton samples (the FLAW-13 over-split tail) ---", kSingletonSamplesShown); std::size_t shown{0}; for (auto iter{by_count.rbegin()}; iter != by_count.rend() && shown < kSingletonSamplesShown; ++iter) diff --git a/technical_docs/canonicalization_generations.md b/technical_docs/canonicalization_generations.md index 12961be..95618a7 100644 --- a/technical_docs/canonicalization_generations.md +++ b/technical_docs/canonicalization_generations.md @@ -41,7 +41,7 @@ the §2.4 gate by construction. ## `-1` — the stateless masker -The stateless per-line masker plus the F13 class set. The first generation. +The stateless per-line masker plus the FLAW-13 class set. The first generation. ## `-2` — OTEL awareness From 12a524e3f86b35766477c906af8c87ba3c8d6427 Mon Sep 17 00:00:00 2001 From: Claude Date: Wed, 16 Sep 2026 21:34:00 +0000 Subject: [PATCH 2/8] ccc_migration: the deleted script `docs_lint.py` becomes the `docs` check module in three sentences MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The superproject deleted `scripts/docs_lint.py` on 2026-09-16 (DN-108.D2, plan row P1.2: every gate becomes a `pharos check` module). An audit of that migration swept every live surface for the old spelling and found this record naming it three times — one of them an OPERATOR INSTRUCTION under OPS-8 (`python3 scripts/docs_lint.py`), which the next operator would have typed and watched fail. The two prose mentions now name the module; the instruction is the one spelling, `./pharos check --module docs` from the superproject root, and says the script existed at the time of the run so the measurement it quotes stays attributable. Co-Authored-By: Claude Fable 5.1 Claude-Session: https://claude.ai/code/session_01DgF1dGH16hPwX7aaaKguWw --- technical_docs/operations/ccc_migration.md | 12 +++++++----- 1 file changed, 7 insertions(+), 5 deletions(-) diff --git a/technical_docs/operations/ccc_migration.md b/technical_docs/operations/ccc_migration.md index 8374ad4..df2c940 100644 --- a/technical_docs/operations/ccc_migration.md +++ b/technical_docs/operations/ccc_migration.md @@ -4289,15 +4289,17 @@ only units whose codes are citations. The step's three-part branch (create the directory, a roster README **and** a superproject `ShelfRuling` row) does **not** apply here, and that was checked rather than taken on the brief's -word. `scripts/docs_lint.py`'s `ShelfRuling("insight-canon", SHELF_TREE_PART, ROSTER, …)` covers the +word. The `docs` check module's `ShelfRuling("insight-canon", SHELF_TREE_PART, ROSTER, …)` covers the whole `technical_docs` tree recursively, so a new `operations/` subdirectory holding one file needs -no row — only a roster entry. Proven falsifiable: with the entry removed, `docs_lint` exits 1 and +no row — only a roster entry. Proven falsifiable: with the entry removed, the `docs` check exits 1 and names the file (*"does not link `operations/ccc_migration.md`, which is tracked under this shelf"*); with it, exit 0. Tracked-doc population 142 → 143. -**One trap worth adding to the step, met here:** these gates must be run from the workspace ROOT. -Run from inside the repo, `python3 scripts/docs_lint.py` exits 2 for a missing file, and an operator -reading only the exit code sees a red gate rather than a mistyped path. +**One trap worth adding to the step, met here:** these gates must be run from the superproject +ROOT, as `./pharos check --module docs`. Run from inside this repo, the same command has no `pharos` +to find and fails as a mistyped path, and an operator reading only the exit code sees a red gate +rather than a mistyped path. (At the time of this run the gate was the script `docs_lint.py`, since +deleted; the `docs` check module is its whole content.) ## 7. The census token is a DIRECTIVE, not the string `NOLINT` From 88803f5869bbfb5aa813abe464119d7d51b23d21 Mon Sep 17 00:00:00 2001 From: Claude Date: Thu, 17 Sep 2026 06:10:21 +0000 Subject: [PATCH 3/8] ccc_migration: five lines naming the deleted pin-coherence script name the `pin_coherence` check module `technical_docs/operations/ccc_migration.md` named `scripts/pin_coherence.py` as the reader of the `pin-coherence: mirrors` marker (lines 2298, 2575, 4655) and as the owner of the `INV-17-EXEMPT-OBJECT-STORE` token (lines 2830, 3017). On 2026-09-17 that script became the `pin_coherence` check module of the superproject's `pharos check` fleet (DN-108.D2, plan row P1.2) and was deleted; the five sentences state which instrument reads those declarations today, so they name the module. No measurement in the ledger moved. Co-Authored-By: Claude Fable 5.1 Claude-Session: https://claude.ai/code/session_01DgF1dGH16hPwX7aaaKguWw --- technical_docs/operations/ccc_migration.md | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/technical_docs/operations/ccc_migration.md b/technical_docs/operations/ccc_migration.md index df2c940..e7f4291 100644 --- a/technical_docs/operations/ccc_migration.md +++ b/technical_docs/operations/ccc_migration.md @@ -2295,7 +2295,7 @@ list, and the derivation found **three comment tokens read by live superproject `OPS-8.S4` does not enumerate**: `LOG-SEAT-ALLOW` (`scripts/log_seat_routing_lint.py`'s opt-out, whose scan globs cover `.cpp`/`.cppm` and exclude only tests, benchmarks and build trees — so `core/tools/` is inside its surface), a closure-model declaration marker read by -`scripts/closure_declaration_lint.py`, and a pin-mirror marker read by `scripts/pin_coherence.py`. +`scripts/closure_declaration_lint.py`, and a pin-mirror marker read by the `pin_coherence` check module. **All three have a population of ZERO in this repo's source**, checked before the strip; they are recorded because the population is a fact about today, not a property of the repo. @@ -2572,7 +2572,7 @@ and `/*name=*/`, `clang-format off/on`, `wall-clock:`, `DETERMINISM-ALLOW`, the `determinism-lint: allow()` spelling `coderoast-server` found, `SPDX-License-Identifier:`, `registry-lint: allow`, plus the three superproject markers `OPS-8.S4` does not list — the seat opt-out of `scripts/log_seat_routing_lint.py`, the closure-model marker of -`scripts/closure_declaration_lint.py` and the mirror marker of `scripts/pin_coherence.py`. +`scripts/closure_declaration_lint.py` and the mirror marker of the `pin_coherence` check module. **Every token has a population of ZERO in these three files except the namespace closer**, which reads 1 in `bench_tokenization.cpp` and 1 in `test_package.cpp` before and after. Zero differences, so zero census decisions. Two of the three files also sit outside `malf lint` by the standing law @@ -2827,7 +2827,7 @@ The census was derived from the gates rather than read off the step's list: ever in the superproject's `scripts/` that is read out of **comment text** — `DETERMINISM-ALLOW` (`random_determinism_lint.py`, `wallclock_lint.py`), `LOG-SEAT-ALLOW` (`log_seat_routing_lint.py`), `CLOSURE MODEL` (`closure_declaration_lint.py`), `pin-coherence: mirrors` and -`INV-17-EXEMPT-OBJECT-STORE` (`pin_coherence.py`) — plus `clang-format off`, `wall-clock:`, SPDX and +`INV-17-EXEMPT-OBJECT-STORE` (the `pin_coherence` check module) — plus `clang-format off`, `wall-clock:`, SPDX and the `/*name*/` forms. **Every one has a population of ZERO in these three files.** `NOLINT` before **2**, after **0**, and the decision is measured rather than argued. @@ -3014,7 +3014,7 @@ The census was derived from the gates rather than read off the step's list: ever in the superproject's `scripts/` that is read out of **comment text** — `DETERMINISM-ALLOW` (`random_determinism_lint.py`, `wallclock_lint.py`), `LOG-SEAT-ALLOW` (`log_seat_routing_lint.py`), `CLOSURE MODEL` (`closure_declaration_lint.py`), `pin-coherence: mirrors` and -`INV-17-EXEMPT-OBJECT-STORE` (`pin_coherence.py`), plus two this run added by enumerating the +`INV-17-EXEMPT-OBJECT-STORE` (the `pin_coherence` check module), plus two this run added by enumerating the same directory — `retired-structure-lint: allow` (`retired_structure_lint.py`) and `registry-lint: allow` (`registry_grammar_lint.py`) — and `clang-format off`, `wall-clock:`, SPDX and the `/*name*/` forms. This repo's own five gate scripts were read too @@ -4652,7 +4652,7 @@ fail once"* is what turned it up. Taken literally on `insight-canon` — enumerate `scripts/`, read each instrument's opt-out constant — it yields **three markers the list does not name**, all read from COMMENT TEXT by live superproject gates: `log_seat_routing_lint.py`'s seat opt-out, `closure_declaration_lint.py`'s closure-model -declaration, and `pin_coherence.py`'s mirror marker. The first is the sharpest of the three, because +declaration, and the `pin_coherence` check module's mirror marker. The first is the sharpest of the three, because its scan globs cover `.cpp`/`.cppm` and exclude only tests, benchmarks and build trees — a CCC unit under `src/`, `api/` or `tools/` sits squarely inside its surface, and the CCC grammar does not list its token, so a strip would delete it exactly as the determinism waiver was deleted. From bd141efe39e18844b1834b6fd0a9d55c13b4c7dc Mon Sep 17 00:00:00 2001 From: Claude Date: Thu, 17 Sep 2026 08:27:40 +0000 Subject: [PATCH 4/8] ccc_migration: five present-tense sentences naming the deleted closure_declaration_lint.py name the closure_declaration check module MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The superproject deleted `scripts/closure_declaration_lint.py` on 2026-09-17 (DN-108.D2, plan row P1.2: every gate becomes a `pharos check` module; the `source` family). A sweep of every live surface for the old spelling found five present-tense sentences in this ledger — the comment-token census lines that say which live superproject gate READS the `CLOSURE MODEL` marker. Each now names the `closure_declaration` check module (spelled `./pharos check --module closure_declaration` from the superproject root); the first keeps "(`scripts/ closure_declaration_lint.py` then)" so the dated measurement still reads. The sibling gate names on the same lines (`log_seat_routing_lint.py`, `wallclock_lint.py`, `random_determinism_lint.py`) are repointed when each of those gates migrates, in its own commit. Co-Authored-By: Claude Fable 5.1 Claude-Session: https://claude.ai/code/session_01DgF1dGH16hPwX7aaaKguWw --- technical_docs/operations/ccc_migration.md | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/technical_docs/operations/ccc_migration.md b/technical_docs/operations/ccc_migration.md index e7f4291..5b4a787 100644 --- a/technical_docs/operations/ccc_migration.md +++ b/technical_docs/operations/ccc_migration.md @@ -2295,7 +2295,7 @@ list, and the derivation found **three comment tokens read by live superproject `OPS-8.S4` does not enumerate**: `LOG-SEAT-ALLOW` (`scripts/log_seat_routing_lint.py`'s opt-out, whose scan globs cover `.cpp`/`.cppm` and exclude only tests, benchmarks and build trees — so `core/tools/` is inside its surface), a closure-model declaration marker read by -`scripts/closure_declaration_lint.py`, and a pin-mirror marker read by the `pin_coherence` check module. +the `closure_declaration` check module (`scripts/closure_declaration_lint.py` then), and a pin-mirror marker read by the `pin_coherence` check module. **All three have a population of ZERO in this repo's source**, checked before the strip; they are recorded because the population is a fact about today, not a property of the repo. @@ -2572,7 +2572,7 @@ and `/*name=*/`, `clang-format off/on`, `wall-clock:`, `DETERMINISM-ALLOW`, the `determinism-lint: allow()` spelling `coderoast-server` found, `SPDX-License-Identifier:`, `registry-lint: allow`, plus the three superproject markers `OPS-8.S4` does not list — the seat opt-out of `scripts/log_seat_routing_lint.py`, the closure-model marker of -`scripts/closure_declaration_lint.py` and the mirror marker of the `pin_coherence` check module. +the `closure_declaration` check module and the mirror marker of the `pin_coherence` check module. **Every token has a population of ZERO in these three files except the namespace closer**, which reads 1 in `bench_tokenization.cpp` and 1 in `test_package.cpp` before and after. Zero differences, so zero census decisions. Two of the three files also sit outside `malf lint` by the standing law @@ -2826,7 +2826,7 @@ count. The census was derived from the gates rather than read off the step's list: every marker constant in the superproject's `scripts/` that is read out of **comment text** — `DETERMINISM-ALLOW` (`random_determinism_lint.py`, `wallclock_lint.py`), `LOG-SEAT-ALLOW` (`log_seat_routing_lint.py`), -`CLOSURE MODEL` (`closure_declaration_lint.py`), `pin-coherence: mirrors` and +`CLOSURE MODEL` (the `closure_declaration` check module), `pin-coherence: mirrors` and `INV-17-EXEMPT-OBJECT-STORE` (the `pin_coherence` check module) — plus `clang-format off`, `wall-clock:`, SPDX and the `/*name*/` forms. **Every one has a population of ZERO in these three files.** @@ -3013,7 +3013,7 @@ After: **175 comment lines, 0 would-be violations** — `pre` 3 · `post` 4 · ` The census was derived from the gates rather than read off the step's list: every marker constant in the superproject's `scripts/` that is read out of **comment text** — `DETERMINISM-ALLOW` (`random_determinism_lint.py`, `wallclock_lint.py`), `LOG-SEAT-ALLOW` (`log_seat_routing_lint.py`), -`CLOSURE MODEL` (`closure_declaration_lint.py`), `pin-coherence: mirrors` and +`CLOSURE MODEL` (the `closure_declaration` check module), `pin-coherence: mirrors` and `INV-17-EXEMPT-OBJECT-STORE` (the `pin_coherence` check module), plus two this run added by enumerating the same directory — `retired-structure-lint: allow` (`retired_structure_lint.py`) and `registry-lint: allow` (`registry_grammar_lint.py`) — and `clang-format off`, `wall-clock:`, SPDX @@ -4651,7 +4651,7 @@ fail once"* is what turned it up. `OPS-8.S4` says to derive the census from the gates the repo runs and calls its own list a floor. Taken literally on `insight-canon` — enumerate `scripts/`, read each instrument's opt-out constant — it yields **three markers the list does not name**, all read from COMMENT TEXT by live superproject -gates: `log_seat_routing_lint.py`'s seat opt-out, `closure_declaration_lint.py`'s closure-model +gates: `log_seat_routing_lint.py`'s seat opt-out, the `closure_declaration` check module's closure-model declaration, and the `pin_coherence` check module's mirror marker. The first is the sharpest of the three, because its scan globs cover `.cpp`/`.cppm` and exclude only tests, benchmarks and build trees — a CCC unit under `src/`, `api/` or `tools/` sits squarely inside its surface, and the CCC grammar does not list From 857ab18d08b48654cca4812381fd7d75bd63961e Mon Sep 17 00:00:00 2001 From: Claude Date: Thu, 17 Sep 2026 08:36:45 +0000 Subject: [PATCH 5/8] ccc_migration: three present-tense sentences naming the deleted wallclock_lint.py name the wallclock check module MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The superproject deleted `scripts/wallclock_lint.py` on 2026-09-17 (DN-108.D2, plan row P1.2: every gate becomes a `pharos check` module; the `source` family). A sweep of every live surface for the old spelling found three present-tense sentences in this ledger — the two comment-token census lines and the determinism-waiver-token sentence, each saying which live superproject gate READS the `DETERMINISM-ALLOW` token. Each now names the `wallclock` check module (spelled `./pharos check --module wallclock` from the superproject root). `random_determinism_lint.py` and `log_seat_routing_lint.py` on the same lines are repointed when those gates migrate, each in its own commit. Co-Authored-By: Claude Fable 5.1 Claude-Session: https://claude.ai/code/session_01DgF1dGH16hPwX7aaaKguWw --- technical_docs/operations/ccc_migration.md | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/technical_docs/operations/ccc_migration.md b/technical_docs/operations/ccc_migration.md index 5b4a787..de971b5 100644 --- a/technical_docs/operations/ccc_migration.md +++ b/technical_docs/operations/ccc_migration.md @@ -2825,7 +2825,7 @@ count. The census was derived from the gates rather than read off the step's list: every marker constant in the superproject's `scripts/` that is read out of **comment text** — `DETERMINISM-ALLOW` -(`random_determinism_lint.py`, `wallclock_lint.py`), `LOG-SEAT-ALLOW` (`log_seat_routing_lint.py`), +(`random_determinism_lint.py`, the `wallclock` check module), `LOG-SEAT-ALLOW` (`log_seat_routing_lint.py`), `CLOSURE MODEL` (the `closure_declaration` check module), `pin-coherence: mirrors` and `INV-17-EXEMPT-OBJECT-STORE` (the `pin_coherence` check module) — plus `clang-format off`, `wall-clock:`, SPDX and the `/*name*/` forms. **Every one has a population of ZERO in these three files.** @@ -3012,7 +3012,7 @@ After: **175 comment lines, 0 would-be violations** — `pre` 3 · `post` 4 · ` The census was derived from the gates rather than read off the step's list: every marker constant in the superproject's `scripts/` that is read out of **comment text** — `DETERMINISM-ALLOW` -(`random_determinism_lint.py`, `wallclock_lint.py`), `LOG-SEAT-ALLOW` (`log_seat_routing_lint.py`), +(`random_determinism_lint.py`, the `wallclock` check module), `LOG-SEAT-ALLOW` (`log_seat_routing_lint.py`), `CLOSURE MODEL` (the `closure_declaration` check module), `pin-coherence: mirrors` and `INV-17-EXEMPT-OBJECT-STORE` (the `pin_coherence` check module), plus two this run added by enumerating the same directory — `retired-structure-lint: allow` (`retired_structure_lint.py`) and @@ -5063,7 +5063,7 @@ easy to break while trying to be polite about a contended resource. ## Two census tokens checked in this repo on a sibling lane's measurement, both with a population of ZERO -* **The determinism waiver token** that `wallclock_lint.py` and `random_determinism_lint.py` read — +* **The determinism waiver token** that the `wallclock` check module and `random_determinism_lint.py` read — which the CCC grammar does not list, so the stripper deletes it silently, and a sibling lane measured a gate going from PASS to FAIL after one was stripped. **Swept over `insight-canon`'s whole source tree: zero occurrences**, so neither unit of this run could have deleted one. Census From 2158ecdd520e9ca21fff67515af84ae3c69454c7 Mon Sep 17 00:00:00 2001 From: Claude Date: Thu, 17 Sep 2026 08:55:56 +0000 Subject: [PATCH 6/8] ccc_migration: three present-tense sentences naming the deleted random_determinism_lint.py name the random_determinism check module MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The superproject deleted `scripts/random_determinism_lint.py` on 2026-09-17 (DN-108.D2, plan row P1.2: every gate becomes a `pharos check` module; the `source` family). The three present-tense sentences in this ledger naming it — the two comment-token census lines and the determinism-waiver-token sentence, each saying which live superproject gates READ the `DETERMINISM-ALLOW` token — now name the `random_determinism` and `wallclock` check modules (spelled `./pharos check --module random_determinism` from the superproject root). `log_seat_routing_lint.py` on the same lines is repointed when that gate migrates. Co-Authored-By: Claude Fable 5.1 Claude-Session: https://claude.ai/code/session_01DgF1dGH16hPwX7aaaKguWw --- technical_docs/operations/ccc_migration.md | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/technical_docs/operations/ccc_migration.md b/technical_docs/operations/ccc_migration.md index de971b5..8687c64 100644 --- a/technical_docs/operations/ccc_migration.md +++ b/technical_docs/operations/ccc_migration.md @@ -2825,7 +2825,7 @@ count. The census was derived from the gates rather than read off the step's list: every marker constant in the superproject's `scripts/` that is read out of **comment text** — `DETERMINISM-ALLOW` -(`random_determinism_lint.py`, the `wallclock` check module), `LOG-SEAT-ALLOW` (`log_seat_routing_lint.py`), +(the `random_determinism` and `wallclock` check modules), `LOG-SEAT-ALLOW` (`log_seat_routing_lint.py`), `CLOSURE MODEL` (the `closure_declaration` check module), `pin-coherence: mirrors` and `INV-17-EXEMPT-OBJECT-STORE` (the `pin_coherence` check module) — plus `clang-format off`, `wall-clock:`, SPDX and the `/*name*/` forms. **Every one has a population of ZERO in these three files.** @@ -3012,7 +3012,7 @@ After: **175 comment lines, 0 would-be violations** — `pre` 3 · `post` 4 · ` The census was derived from the gates rather than read off the step's list: every marker constant in the superproject's `scripts/` that is read out of **comment text** — `DETERMINISM-ALLOW` -(`random_determinism_lint.py`, the `wallclock` check module), `LOG-SEAT-ALLOW` (`log_seat_routing_lint.py`), +(the `random_determinism` and `wallclock` check modules), `LOG-SEAT-ALLOW` (`log_seat_routing_lint.py`), `CLOSURE MODEL` (the `closure_declaration` check module), `pin-coherence: mirrors` and `INV-17-EXEMPT-OBJECT-STORE` (the `pin_coherence` check module), plus two this run added by enumerating the same directory — `retired-structure-lint: allow` (`retired_structure_lint.py`) and @@ -5063,7 +5063,7 @@ easy to break while trying to be polite about a contended resource. ## Two census tokens checked in this repo on a sibling lane's measurement, both with a population of ZERO -* **The determinism waiver token** that the `wallclock` check module and `random_determinism_lint.py` read — +* **The determinism waiver token** that the `wallclock` and `random_determinism` check modules read — which the CCC grammar does not list, so the stripper deletes it silently, and a sibling lane measured a gate going from PASS to FAIL after one was stripped. **Swept over `insight-canon`'s whole source tree: zero occurrences**, so neither unit of this run could have deleted one. Census From a982846670d9e3fde6fc93e52db19d89f6c0934b Mon Sep 17 00:00:00 2001 From: Claude Date: Thu, 17 Sep 2026 09:07:08 +0000 Subject: [PATCH 7/8] ccc_migration: five sentences naming the deleted log_seat_routing_lint.py name the log_seat_routing check module MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The superproject deleted `scripts/log_seat_routing_lint.py` on 2026-09-17 (DN-108.D2, plan row P1.2: every gate becomes a `pharos check` module; the `source` family). The five present-tense sentences in this ledger naming it — the comment-token census lines and the marker-derivation sentences saying which live superproject gate reads `LOG-SEAT-ALLOW` — now name the `log_seat_routing` check module (spelled `./pharos check --module log_seat_routing` from the superproject root). With this, every gate of the `source` family's first half that these lines name is spelled as its module. Co-Authored-By: Claude Fable 5.1 Claude-Session: https://claude.ai/code/session_01DgF1dGH16hPwX7aaaKguWw --- technical_docs/operations/ccc_migration.md | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/technical_docs/operations/ccc_migration.md b/technical_docs/operations/ccc_migration.md index 8687c64..9625960 100644 --- a/technical_docs/operations/ccc_migration.md +++ b/technical_docs/operations/ccc_migration.md @@ -2292,7 +2292,7 @@ this run was **not consumed**, and the next free integer is unchanged. The census was derived from the gates this repo actually runs rather than taken from the written list, and the derivation found **three comment tokens read by live superproject gates that -`OPS-8.S4` does not enumerate**: `LOG-SEAT-ALLOW` (`scripts/log_seat_routing_lint.py`'s opt-out, +`OPS-8.S4` does not enumerate**: `LOG-SEAT-ALLOW` (the `log_seat_routing` check module's opt-out, whose scan globs cover `.cpp`/`.cppm` and exclude only tests, benchmarks and build trees — so `core/tools/` is inside its surface), a closure-model declaration marker read by the `closure_declaration` check module (`scripts/closure_declaration_lint.py` then), and a pin-mirror marker read by the `pin_coherence` check module. @@ -2571,7 +2571,7 @@ The derivation of unit 14 was re-used and re-run per file: `NOLINT` in every spe and `/*name=*/`, `clang-format off/on`, `wall-clock:`, `DETERMINISM-ALLOW`, the `determinism-lint: allow()` spelling `coderoast-server` found, `SPDX-License-Identifier:`, `registry-lint: allow`, plus the three superproject markers `OPS-8.S4` does not list — the seat -opt-out of `scripts/log_seat_routing_lint.py`, the closure-model marker of +opt-out of the `log_seat_routing` check module, the closure-model marker of the `closure_declaration` check module and the mirror marker of the `pin_coherence` check module. **Every token has a population of ZERO in these three files except the namespace closer**, which reads 1 in `bench_tokenization.cpp` and 1 in `test_package.cpp` before and after. Zero differences, @@ -2825,7 +2825,7 @@ count. The census was derived from the gates rather than read off the step's list: every marker constant in the superproject's `scripts/` that is read out of **comment text** — `DETERMINISM-ALLOW` -(the `random_determinism` and `wallclock` check modules), `LOG-SEAT-ALLOW` (`log_seat_routing_lint.py`), +(the `random_determinism` and `wallclock` check modules), `LOG-SEAT-ALLOW` (the `log_seat_routing` check module), `CLOSURE MODEL` (the `closure_declaration` check module), `pin-coherence: mirrors` and `INV-17-EXEMPT-OBJECT-STORE` (the `pin_coherence` check module) — plus `clang-format off`, `wall-clock:`, SPDX and the `/*name*/` forms. **Every one has a population of ZERO in these three files.** @@ -3012,7 +3012,7 @@ After: **175 comment lines, 0 would-be violations** — `pre` 3 · `post` 4 · ` The census was derived from the gates rather than read off the step's list: every marker constant in the superproject's `scripts/` that is read out of **comment text** — `DETERMINISM-ALLOW` -(the `random_determinism` and `wallclock` check modules), `LOG-SEAT-ALLOW` (`log_seat_routing_lint.py`), +(the `random_determinism` and `wallclock` check modules), `LOG-SEAT-ALLOW` (the `log_seat_routing` check module), `CLOSURE MODEL` (the `closure_declaration` check module), `pin-coherence: mirrors` and `INV-17-EXEMPT-OBJECT-STORE` (the `pin_coherence` check module), plus two this run added by enumerating the same directory — `retired-structure-lint: allow` (`retired_structure_lint.py`) and @@ -4651,7 +4651,7 @@ fail once"* is what turned it up. `OPS-8.S4` says to derive the census from the gates the repo runs and calls its own list a floor. Taken literally on `insight-canon` — enumerate `scripts/`, read each instrument's opt-out constant — it yields **three markers the list does not name**, all read from COMMENT TEXT by live superproject -gates: `log_seat_routing_lint.py`'s seat opt-out, the `closure_declaration` check module's closure-model +gates: the `log_seat_routing` check module's seat opt-out, the `closure_declaration` check module's closure-model declaration, and the `pin_coherence` check module's mirror marker. The first is the sharpest of the three, because its scan globs cover `.cpp`/`.cppm` and exclude only tests, benchmarks and build trees — a CCC unit under `src/`, `api/` or `tools/` sits squarely inside its surface, and the CCC grammar does not list From 38632d19d60592dfa68706b8b5031694b24fdb26 Mon Sep 17 00:00:00 2001 From: Claude Date: Thu, 17 Sep 2026 15:10:58 +0000 Subject: [PATCH 8/8] re-pin layer 3 of 3: this repository's 10 malf-toolchain references move onto da2abf63 Layer 3 (the last) of the malf-toolchain re-pin that unblocks the next CodeRoast release tag. THE DEFECT. The workspace pinned malf-toolchain at b5e15eee5e2cc9a2709309850f845b28ba8d9e58. The `malf` driver at that revision does `local pin="$MALF_WORKSPACE_ROOT/scripts/pin_coherence.py"` followed by `[[ -f "$pin" ]] || return 1`, in both `cut-verify` and `bump`. That superproject script no longer exists: the check became the Pharos check module `scripts/pharos/checks/pin_coherence.py` and its two producer verbs (`released` and `bump X.Y.Z`) moved to `scripts/version_line.py`. So the next `v*` tag would run `.github/workflows/cut-verify.yml`, which checks malf-toolchain out at the pinned revision and runs that checkout's `malf cut-verify`, which exits 1 on the missing file -- and every release job declaring `needs: [cut-verify, ...]` would be skipped. Measured: `git show b5e15eee:malf | grep -c pin_coherence` returns 6; `git show da2abf63:malf | grep -c pin_coherence` returns 2, and both survivors are correct (one comment and one `python3 "$pharos" check --module pin_coherence` invocation). THE TARGET IS NOT THE TOOLCHAIN'S main. `origin/main` is b62485cde9e1d5438b2c4ebabe86189a0ea7f028 and its count is also 6 -- main does not carry the fix. The target is da2abf639f64e1c1bca382aa7a973e9cc2f00412, the head of malf-toolchain's `claude/coderoast-claude-md-malf-p80u1w` branch, which is a strict fast-forward of main (7 commits ahead, 0 behind). That branch must be merged, not squashed, or every reference below would name a commit that no longer exists. WHY da2abf63 IS A LEGAL TARGET FOR EXTERNAL REFERENCES. The re-pin is layered because a commit may only pin edges whose TARGET it does not touch. Layer 1 (390108f5) moved malf-toolchain's 9 action->action refs onto the content head 5081176 and touched only 6 files under `.github/actions/`, none of them a target of those refs. Layer 2 (da2abf63) moved the 10 workflow->action refs onto layer 1 and touched only `.github/workflows/`, so all 10 target actions have identical bytes at layer 1 and at da2abf63. This layer touches no malf-toolchain file at all, so every workflow and every action a consumer executes has, at da2abf63, exactly the bytes it has at the revision this workspace pins. INV-17 (d) verifies that chain independently: each pinned SHA must be an ancestor of its successor differing by nothing but `uses:` lines. IN THIS REPOSITORY. 10 references move from b5e15eee to da2abf63: 8 `uses:` step(s) and 2 `actions/checkout` refs. Verified: every changed line is either a `uses: CodeRoasted/malf-toolchain/...@<40-hex>` step or the `ref:` of an `actions/checkout` whose `repository:` is `CodeRoasted/malf-toolchain`; every changed file parses under `python3 -c "import yaml; yaml.safe_load(open(f))"`. Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_01DgF1dGH16hPwX7aaaKguWw --- .github/workflows/ci.yml | 4 ++-- .github/workflows/golden.yaml | 12 ++++++------ .github/workflows/lint.yml | 2 +- .github/workflows/release.yaml | 2 +- 4 files changed, 10 insertions(+), 10 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 66dfcd7..ef14f9f 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -11,7 +11,7 @@ jobs: permissions: contents: read actions: read - uses: CodeRoasted/malf-toolchain/.github/workflows/coderoast-ci.yml@b5e15eee5e2cc9a2709309850f845b28ba8d9e58 + uses: CodeRoasted/malf-toolchain/.github/workflows/coderoast-ci.yml@da2abf639f64e1c1bca382aa7a973e9cc2f00412 with: # canon is a tower root (no first-party deps to vendor). Post-ADR-17 it is a MULTI-package # repo: the core under core/ (the logcraft/server layout — the repo root is the shelf), the three @@ -45,7 +45,7 @@ jobs: permissions: pull-requests: write actions: read - uses: CodeRoasted/malf-toolchain/.github/workflows/coderoast-sift-post.yml@b5e15eee5e2cc9a2709309850f845b28ba8d9e58 + uses: CodeRoasted/malf-toolchain/.github/workflows/coderoast-sift-post.yml@da2abf639f64e1c1bca382aa7a973e9cc2f00412 with: run-id: ${{ github.run_id }} secrets: inherit diff --git a/.github/workflows/golden.yaml b/.github/workflows/golden.yaml index 67b2223..764e921 100644 --- a/.github/workflows/golden.yaml +++ b/.github/workflows/golden.yaml @@ -88,18 +88,18 @@ jobs: uses: actions/checkout@v5 with: repository: CodeRoasted/malf-toolchain - ref: b5e15eee5e2cc9a2709309850f845b28ba8d9e58 + ref: da2abf639f64e1c1bca382aa7a973e9cc2f00412 path: malf fetch-depth: 1 persist-credentials: false - name: Provision gcc-16.2 toolchain (OUR OWN published asset; arm64 auto-picked by uname -m) if: matrix.leg == 'gcc' - uses: CodeRoasted/malf-toolchain/.github/actions/setup-gcc@b5e15eee5e2cc9a2709309850f845b28ba8d9e58 + uses: CodeRoasted/malf-toolchain/.github/actions/setup-gcc@da2abf639f64e1c1bca382aa7a973e9cc2f00412 - name: Provision clang-21 + libc++-21 if: matrix.leg == 'clang' - uses: CodeRoasted/malf-toolchain/.github/actions/setup-clang21-libcxx@b5e15eee5e2cc9a2709309850f845b28ba8d9e58 + uses: CodeRoasted/malf-toolchain/.github/actions/setup-clang21-libcxx@da2abf639f64e1c1bca382aa7a973e9cc2f00412 - name: Base — ninja + CMake 4.3.x (+ gcc-16.2 /opt wiring on the gcc leg) run: | @@ -198,13 +198,13 @@ jobs: uses: actions/checkout@v5 with: repository: CodeRoasted/malf-toolchain - ref: b5e15eee5e2cc9a2709309850f845b28ba8d9e58 + ref: da2abf639f64e1c1bca382aa7a973e9cc2f00412 path: malf fetch-depth: 1 persist-credentials: false - name: Install + activate MSVC 14.52 (the C++23-modules fix floor; not pre-installed) - uses: CodeRoasted/malf-toolchain/.github/actions/setup-msvc1452@b5e15eee5e2cc9a2709309850f845b28ba8d9e58 + uses: CodeRoasted/malf-toolchain/.github/actions/setup-msvc1452@da2abf639f64e1c1bca382aa7a973e9cc2f00412 - name: Verify the active toolset is MSVC 14.52, not a fallback shell: pwsh @@ -314,7 +314,7 @@ jobs: pattern: golden-digest-* - name: Compare + validate the golden (all 5 legs must be byte-identical) - uses: CodeRoasted/malf-toolchain/.github/actions/coderoast-golden-compare@b5e15eee5e2cc9a2709309850f845b28ba8d9e58 + uses: CodeRoasted/malf-toolchain/.github/actions/coderoast-golden-compare@da2abf639f64e1c1bca382aa7a973e9cc2f00412 with: digests-dir: digests min-legs: '5' diff --git a/.github/workflows/lint.yml b/.github/workflows/lint.yml index f7473b3..11d6285 100644 --- a/.github/workflows/lint.yml +++ b/.github/workflows/lint.yml @@ -8,7 +8,7 @@ on: jobs: lint: - uses: CodeRoasted/malf-toolchain/.github/workflows/coderoast-lint.yml@b5e15eee5e2cc9a2709309850f845b28ba8d9e58 + uses: CodeRoasted/malf-toolchain/.github/workflows/coderoast-lint.yml@da2abf639f64e1c1bca382aa7a973e9cc2f00412 # PUBLIC repo: no runs-on passthrough — a self-hosted runner reachable from a fork PR is an RCE. # No `with:` at all: every gate in the reusable workflow defaults TRUE, so a caller that says # nothing is fully gated, and a hole would have to be a written line here. diff --git a/.github/workflows/release.yaml b/.github/workflows/release.yaml index d2bbe43..4a2d797 100644 --- a/.github/workflows/release.yaml +++ b/.github/workflows/release.yaml @@ -37,7 +37,7 @@ jobs: release: needs: golden - uses: CodeRoasted/malf-toolchain/.github/workflows/coderoast-release.yml@b5e15eee5e2cc9a2709309850f845b28ba8d9e58 + uses: CodeRoasted/malf-toolchain/.github/workflows/coderoast-release.yml@da2abf639f64e1c1bca382aa7a973e9cc2f00412 with: tag: ${{ github.event.inputs.tag || github.ref_name }} # ADR-17.D8: the four semantic vocabulary packages ride the train on the SAME footing as canon