From 4983c502ab74a2b342b8b6b779e272d48affa210 Mon Sep 17 00:00:00 2001 From: Claude Date: Wed, 16 Sep 2026 13:13:55 +0000 Subject: [PATCH 1/7] docs(flaws): repoint the remaining F citations onto their minted FLAW-n addresses MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The superproject's flaw register minted registry-form addresses on 2026-09-16. That pass repointed the superproject doc tier and the DF/LF citations; its F half was scoped to the superproject and said so. This closes it here. Every site was read before it was rewritten. The MetaLog entries kept their numbers, so these are prefix changes that cannot mis-map. Deliberately untouched and distinguished by reading, not by pattern: the ML F1 score, float16 and hex literals, flake8 suppressions, and the MetaLog specification's own F2(b) clause — a public standard's numbering, in a different number space. Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_01DgF1dGH16hPwX7aaaKguWw --- tests/reservoir/test_reservoir.cpp | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/tests/reservoir/test_reservoir.cpp b/tests/reservoir/test_reservoir.cpp index 4dac828..ccd1599 100644 --- a/tests/reservoir/test_reservoir.cpp +++ b/tests/reservoir/test_reservoir.cpp @@ -89,7 +89,7 @@ TEST(ReservoirTest, RareErrorNotRetainedWithoutReservoir) EXPECT_FALSE(top_k_has(doc, "connection refused to db")) << "the rare error is below top_k by frequency (one occurrence vs the steady benign 100s)"; EXPECT_FALSE(reservoir_has(doc, "connection refused to db")) - << "with the reservoir off the rare severe event is tail dust — retained nowhere (the F1 " + << "with the reservoir off the rare severe event is tail dust — retained nowhere (the FLAW-1 " "recall=0 baseline the salience reservoir flips to 1)"; } From bb347ca3066c6c067e02fe1d7159c0c120a81c5c Mon Sep 17 00:00:00 2001 From: Claude Date: Thu, 17 Sep 2026 07:31:43 +0000 Subject: [PATCH 2/7] ci: lint.yml's sibling-closure comment names the pin_coherence check module, not the deleted script .github/workflows/lint.yml line 16 said the lint-siblings roster is held to packages.yml by the superproject's "pin_coherence.py INV-13"; it now names the pin_coherence check module's INV-13, re-wrapped to two lines. The superproject's scripts/pin_coherence.py was deleted on 2026-09-17 (coderoast commit b60d217c) when its check became the pin_coherence check module (scripts/pharos/checks/pin_coherence.py, run as `./pharos check --module pin_coherence`) and its producer verbs became scripts/version_line.py. Comment only: no step, input, ref or shell line changes, and every workflow in this repository still loads as YAML (checked with PyYAML). The same repoint lands in the superproject's compatibility_matrix.md (coderoast commit b2e7602f) and in the four other sibling repositories whose workflow comments named the script. Co-Authored-By: Claude Fable 5.1 Claude-Session: https://claude.ai/code/session_01DgF1dGH16hPwX7aaaKguWw --- .github/workflows/lint.yml | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/.github/workflows/lint.yml b/.github/workflows/lint.yml index 2d43d6d..ef99e6a 100644 --- a/.github/workflows/lint.yml +++ b/.github/workflows/lint.yml @@ -13,5 +13,6 @@ jobs: with: # clang-tidy runs (the default), over a clang-21 source build of this repo's whole first-party # closure. These are the repos that closure reaches, held to packages.yml by the superproject's - # pin_coherence.py INV-13. A private one would fail its clone loudly, never be skipped. + # pin_coherence check module's INV-13. A private one would fail its clone loudly, never be + # skipped. lint-siblings: insight-canon From e0a0be692cc3a8f6f0a29507183b3d9f63f0273a Mon Sep 17 00:00:00 2001 From: Claude Date: Thu, 17 Sep 2026 08:36:56 +0000 Subject: [PATCH 3/7] ccc_migration: the comment-token census line naming the deleted wallclock_lint.py names the wallclock check module MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The superproject deleted `scripts/wallclock_lint.py` on 2026-09-17 (DN-108.D2, plan row P1.2: every gate becomes a `pharos check` module; the `source` family). A sweep of every live surface for the old spelling found one present-tense sentence in this ledger — the comment-token census line saying which live superproject gates READ the `DETERMINISM-ALLOW` token. It now names the `wallclock` check module (spelled `./pharos check --module wallclock` from the superproject root). The recorded scope fact five lines down ("`wallclock_lint.py`'s SCOPE covers insight-canon and insight-eidos only") is a dated measurement and keeps its wording; insight-metalog joined that scope on 2026-09-09, and the module walks 17 of its units today. `scripts/random_determinism_lint.py` on the same line is repointed when that gate migrates. Co-Authored-By: Claude Fable 5.1 Claude-Session: https://claude.ai/code/session_01DgF1dGH16hPwX7aaaKguWw --- technical_docs/operations/ccc_migration.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/technical_docs/operations/ccc_migration.md b/technical_docs/operations/ccc_migration.md index c3d151a..048b0c7 100644 --- a/technical_docs/operations/ccc_migration.md +++ b/technical_docs/operations/ccc_migration.md @@ -1244,7 +1244,7 @@ one questionnaire over 200 blocks is two interrogations pretending to be one. **Census (`OPS-8.S4`), derived rather than taken from the written list.** The gates that read a comment token in this repo were enumerated first: `malf/comment_contract_lint.py` (the CCC tool forms), clang-tidy (`NOLINT` in all spellings, `/*name*/`, `/*name=*/`), clang-format -(`clang-format off`/`on`, the namespace closer), `scripts/wallclock_lint.py` and +(`clang-format off`/`on`, the namespace closer), the `wallclock` check module and `scripts/random_determinism_lint.py` (`DETERMINISM-ALLOW`), `scripts/log_seat_routing_lint.py` (`LOG-SEAT-ALLOW`), `scripts/retired_structure_lint.py` (its `allow` marker, whose regex does not require an HTML comment and can therefore sit in C++), plus `wall-clock:` and From b17c6ce28b0fd65b7a24e9e1b93ea17442c56eca Mon Sep 17 00:00:00 2001 From: Claude Date: Thu, 17 Sep 2026 08:51:44 +0000 Subject: [PATCH 4/7] ccc_migration: the Q1 row naming the deleted json_write_closure_lint.py names the json_write_closure check module MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The superproject deleted `scripts/json_write_closure_lint.py` on 2026-09-17 (DN-108.D2, plan row P1.2: every gate becomes a `pharos check` module; the `source` family). A sweep of every live surface for the old spelling found one present-tense sentence in this ledger — the Q1 row saying the JSON write-closure rule "is mechanically gated by" the script, run in lint.yml's pin-coherence job. It now names the `json_write_closure` check module (spelled `./pharos check --module json_write_closure` from the superproject root) and keeps "(`scripts/ json_write_closure_lint.py` then)" so the dated finding still reads; the job, the derived-list claim and the exit-2-on-empty-derivation claim are unchanged and still true of the module. Co-Authored-By: Claude Fable 5.1 Claude-Session: https://claude.ai/code/session_01DgF1dGH16hPwX7aaaKguWw --- technical_docs/operations/ccc_migration.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/technical_docs/operations/ccc_migration.md b/technical_docs/operations/ccc_migration.md index 048b0c7..411b893 100644 --- a/technical_docs/operations/ccc_migration.md +++ b/technical_docs/operations/ccc_migration.md @@ -505,7 +505,7 @@ wrote was found INCOMPLETE and repaired before the commit.** | Q | unit | verdict | what the agent found | |---|---|---|---| -| Q1 | 5 | recovered, high — **and it found an enforcement this lane had not** | the rule is mechanically gated by `scripts/json_write_closure_lint.py`, run in `lint.yml`'s `pin-coherence` job, with every list derived rather than hand-kept and an exit 2 on an empty derivation. Two limits it read off the tree: the gate proves LOCATION only, and `lint.yml` has no `push:` trigger, so it fires on pull request, dispatch and the release tag, never on a main push | +| Q1 | 5 | recovered, high — **and it found an enforcement this lane had not** | the rule is mechanically gated by the `json_write_closure` check module (`scripts/json_write_closure_lint.py` then), run in `lint.yml`'s `pin-coherence` job, with every list derived rather than hand-kept and an exit 2 on an empty derivation. Two limits it read off the tree: the gate proves LOCATION only, and `lint.yml` has no `push:` trigger, so it fires on pull request, dispatch and the release tag, never on a main push | | Q2 | 5 | recovered, high | `DN-65.O4` in full: the opts-spelling rule was written first and falsified the same day — 5 true positives, 9 false positives, 2 false negatives as a grep, and it missed the live defect | | Q3 | 5 | recovered, high | `opt_true` assigns the member when the caller's type carries it and derives a new type when it does not, so `prettify`/`skip_null_members` survive and no caller can spell the escape false. It added a "cannot" specific to this file: metalog's wrapper exposes only `to_string`, with no `write(value, buffer)` overload, so a metalog caller cannot recover Glaze's error context — sift's twin offers both | | Q4 | 5 | recovered, high | the 5/27 split with a third, independent source this lane had not used: a measurement recorded in the release history that reverted this very wrapper to a raw `glz::write`, rebuilt, and redded on 27 of 32 C0 bytes with the survivors *"exactly `0x08 0x09 0x0a 0x0c 0x0d`"*. It also bounded the claim: nothing in the tree covers bytes at or above 0x20 | From 87931be2f97ffdc6450b571af0b47c4618587d04 Mon Sep 17 00:00:00 2001 From: Claude Date: Thu, 17 Sep 2026 08:56:18 +0000 Subject: [PATCH 5/7] ccc_migration: the comment-token census line naming the deleted random_determinism_lint.py names the random_determinism check module The superproject deleted `scripts/random_determinism_lint.py` on 2026-09-17 (DN-108.D2, plan row P1.2: every gate becomes a `pharos check` module; the `source` family). The comment-token census line in this ledger saying which live superproject gates READ the `DETERMINISM-ALLOW` token now names the `wallclock` and `random_determinism` check modules (spelled `./pharos check --module random_determinism` from the superproject root). The recorded scope fact a few lines down ("`random_determinism_lint.py`'s SCOPE does name insight-metalog (6 module interface units)") is a dated measurement and keeps its wording. `scripts/log_seat_routing_lint.py` on the same line is repointed when that gate migrates. Co-Authored-By: Claude Fable 5.1 Claude-Session: https://claude.ai/code/session_01DgF1dGH16hPwX7aaaKguWw --- technical_docs/operations/ccc_migration.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/technical_docs/operations/ccc_migration.md b/technical_docs/operations/ccc_migration.md index 411b893..de8949c 100644 --- a/technical_docs/operations/ccc_migration.md +++ b/technical_docs/operations/ccc_migration.md @@ -1244,8 +1244,8 @@ one questionnaire over 200 blocks is two interrogations pretending to be one. **Census (`OPS-8.S4`), derived rather than taken from the written list.** The gates that read a comment token in this repo were enumerated first: `malf/comment_contract_lint.py` (the CCC tool forms), clang-tidy (`NOLINT` in all spellings, `/*name*/`, `/*name=*/`), clang-format -(`clang-format off`/`on`, the namespace closer), the `wallclock` check module and -`scripts/random_determinism_lint.py` (`DETERMINISM-ALLOW`), `scripts/log_seat_routing_lint.py` +(`clang-format off`/`on`, the namespace closer), the `wallclock` and +`random_determinism` check modules (`DETERMINISM-ALLOW`), `scripts/log_seat_routing_lint.py` (`LOG-SEAT-ALLOW`), `scripts/retired_structure_lint.py` (its `allow` marker, whose regex does not require an HTML comment and can therefore sit in C++), plus `wall-clock:` and `SPDX-License-Identifier:`. Two scope facts fell out of that walk and are recorded because they From d2d724f70871e878540d4053b864ecd2ad5aec4c Mon Sep 17 00:00:00 2001 From: Claude Date: Thu, 17 Sep 2026 09:07:30 +0000 Subject: [PATCH 6/7] ccc_migration: the comment-token census line naming the deleted log_seat_routing_lint.py names the log_seat_routing check module The superproject deleted `scripts/log_seat_routing_lint.py` on 2026-09-17 (DN-108.D2, plan row P1.2: every gate becomes a `pharos check` module; the `source` family). The comment-token census line in this ledger saying which live superproject gates read their markers now names the `log_seat_routing` check module (spelled `./pharos check --module log_seat_routing` from the superproject root) beside the `wallclock` and `random_determinism` modules already named there. Co-Authored-By: Claude Fable 5.1 Claude-Session: https://claude.ai/code/session_01DgF1dGH16hPwX7aaaKguWw --- technical_docs/operations/ccc_migration.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/technical_docs/operations/ccc_migration.md b/technical_docs/operations/ccc_migration.md index de8949c..aa71f78 100644 --- a/technical_docs/operations/ccc_migration.md +++ b/technical_docs/operations/ccc_migration.md @@ -1245,7 +1245,7 @@ one questionnaire over 200 blocks is two interrogations pretending to be one. comment token in this repo were enumerated first: `malf/comment_contract_lint.py` (the CCC tool forms), clang-tidy (`NOLINT` in all spellings, `/*name*/`, `/*name=*/`), clang-format (`clang-format off`/`on`, the namespace closer), the `wallclock` and -`random_determinism` check modules (`DETERMINISM-ALLOW`), `scripts/log_seat_routing_lint.py` +`random_determinism` check modules (`DETERMINISM-ALLOW`), the `log_seat_routing` check module (`LOG-SEAT-ALLOW`), `scripts/retired_structure_lint.py` (its `allow` marker, whose regex does not require an HTML comment and can therefore sit in C++), plus `wall-clock:` and `SPDX-License-Identifier:`. Two scope facts fell out of that walk and are recorded because they From 22ccbd37da216bee2f8cea461cab52b544a90f36 Mon Sep 17 00:00:00 2001 From: Claude Date: Thu, 17 Sep 2026 15:10:59 +0000 Subject: [PATCH 7/7] re-pin layer 3 of 3: this repository's 10 malf-toolchain references move onto da2abf63 Layer 3 (the last) of the malf-toolchain re-pin that unblocks the next CodeRoast release tag. THE DEFECT. The workspace pinned malf-toolchain at b5e15eee5e2cc9a2709309850f845b28ba8d9e58. The `malf` driver at that revision does `local pin="$MALF_WORKSPACE_ROOT/scripts/pin_coherence.py"` followed by `[[ -f "$pin" ]] || return 1`, in both `cut-verify` and `bump`. That superproject script no longer exists: the check became the Pharos check module `scripts/pharos/checks/pin_coherence.py` and its two producer verbs (`released` and `bump X.Y.Z`) moved to `scripts/version_line.py`. So the next `v*` tag would run `.github/workflows/cut-verify.yml`, which checks malf-toolchain out at the pinned revision and runs that checkout's `malf cut-verify`, which exits 1 on the missing file -- and every release job declaring `needs: [cut-verify, ...]` would be skipped. Measured: `git show b5e15eee:malf | grep -c pin_coherence` returns 6; `git show da2abf63:malf | grep -c pin_coherence` returns 2, and both survivors are correct (one comment and one `python3 "$pharos" check --module pin_coherence` invocation). THE TARGET IS NOT THE TOOLCHAIN'S main. `origin/main` is b62485cde9e1d5438b2c4ebabe86189a0ea7f028 and its count is also 6 -- main does not carry the fix. The target is da2abf639f64e1c1bca382aa7a973e9cc2f00412, the head of malf-toolchain's `claude/coderoast-claude-md-malf-p80u1w` branch, which is a strict fast-forward of main (7 commits ahead, 0 behind). That branch must be merged, not squashed, or every reference below would name a commit that no longer exists. WHY da2abf63 IS A LEGAL TARGET FOR EXTERNAL REFERENCES. The re-pin is layered because a commit may only pin edges whose TARGET it does not touch. Layer 1 (390108f5) moved malf-toolchain's 9 action->action refs onto the content head 5081176 and touched only 6 files under `.github/actions/`, none of them a target of those refs. Layer 2 (da2abf63) moved the 10 workflow->action refs onto layer 1 and touched only `.github/workflows/`, so all 10 target actions have identical bytes at layer 1 and at da2abf63. This layer touches no malf-toolchain file at all, so every workflow and every action a consumer executes has, at da2abf63, exactly the bytes it has at the revision this workspace pins. INV-17 (d) verifies that chain independently: each pinned SHA must be an ancestor of its successor differing by nothing but `uses:` lines. IN THIS REPOSITORY. 10 references move from b5e15eee to da2abf63: 8 `uses:` step(s) and 2 `actions/checkout` refs. Verified: every changed line is either a `uses: CodeRoasted/malf-toolchain/...@<40-hex>` step or the `ref:` of an `actions/checkout` whose `repository:` is `CodeRoasted/malf-toolchain`; every changed file parses under `python3 -c "import yaml; yaml.safe_load(open(f))"`. Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_01DgF1dGH16hPwX7aaaKguWw --- .github/workflows/ci.yml | 4 ++-- .github/workflows/golden.yaml | 12 ++++++------ .github/workflows/lint.yml | 2 +- .github/workflows/release.yaml | 2 +- 4 files changed, 10 insertions(+), 10 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index d9e2318..7e0eb16 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -11,7 +11,7 @@ jobs: permissions: contents: read actions: read - uses: CodeRoasted/malf-toolchain/.github/workflows/coderoast-ci.yml@b5e15eee5e2cc9a2709309850f845b28ba8d9e58 + uses: CodeRoasted/malf-toolchain/.github/workflows/coderoast-ci.yml@da2abf639f64e1c1bca382aa7a973e9cc2f00412 with: # metalog vendors insight_canon from its PUBLIC release, then builds the single root package # (test=true runs the full gtest suite; create=true verifies packaging + test_package). @@ -38,7 +38,7 @@ jobs: permissions: pull-requests: write actions: read - uses: CodeRoasted/malf-toolchain/.github/workflows/coderoast-sift-post.yml@b5e15eee5e2cc9a2709309850f845b28ba8d9e58 + uses: CodeRoasted/malf-toolchain/.github/workflows/coderoast-sift-post.yml@da2abf639f64e1c1bca382aa7a973e9cc2f00412 with: run-id: ${{ github.run_id }} secrets: inherit diff --git a/.github/workflows/golden.yaml b/.github/workflows/golden.yaml index 4d669b0..390699c 100644 --- a/.github/workflows/golden.yaml +++ b/.github/workflows/golden.yaml @@ -135,7 +135,7 @@ jobs: uses: actions/checkout@v5 with: repository: CodeRoasted/malf-toolchain - ref: b5e15eee5e2cc9a2709309850f845b28ba8d9e58 + ref: da2abf639f64e1c1bca382aa7a973e9cc2f00412 path: malf fetch-depth: 1 persist-credentials: false @@ -151,11 +151,11 @@ jobs: - name: Provision gcc-16.2 toolchain (OUR OWN published asset; arm64 auto-picked by uname -m) if: matrix.leg == 'gcc' - uses: CodeRoasted/malf-toolchain/.github/actions/setup-gcc@b5e15eee5e2cc9a2709309850f845b28ba8d9e58 + uses: CodeRoasted/malf-toolchain/.github/actions/setup-gcc@da2abf639f64e1c1bca382aa7a973e9cc2f00412 - name: Provision clang-21 + libc++-21 if: matrix.leg == 'clang' - uses: CodeRoasted/malf-toolchain/.github/actions/setup-clang21-libcxx@b5e15eee5e2cc9a2709309850f845b28ba8d9e58 + uses: CodeRoasted/malf-toolchain/.github/actions/setup-clang21-libcxx@da2abf639f64e1c1bca382aa7a973e9cc2f00412 - name: Base — ninja + CMake 4.3.x (+ gcc-16.2 /opt wiring on the gcc leg) run: | @@ -264,7 +264,7 @@ jobs: uses: actions/checkout@v5 with: repository: CodeRoasted/malf-toolchain - ref: b5e15eee5e2cc9a2709309850f845b28ba8d9e58 + ref: da2abf639f64e1c1bca382aa7a973e9cc2f00412 path: malf fetch-depth: 1 persist-credentials: false @@ -278,7 +278,7 @@ jobs: persist-credentials: false - name: Install + activate MSVC 14.52 (the C++23-modules fix floor; not pre-installed) - uses: CodeRoasted/malf-toolchain/.github/actions/setup-msvc1452@b5e15eee5e2cc9a2709309850f845b28ba8d9e58 + uses: CodeRoasted/malf-toolchain/.github/actions/setup-msvc1452@da2abf639f64e1c1bca382aa7a973e9cc2f00412 - name: Verify the active toolset is MSVC 14.52, not a fallback shell: pwsh @@ -475,7 +475,7 @@ jobs: pattern: golden-digest-* - name: Compare + validate the golden (all 5 legs must be byte-identical) - uses: CodeRoasted/malf-toolchain/.github/actions/coderoast-golden-compare@b5e15eee5e2cc9a2709309850f845b28ba8d9e58 + uses: CodeRoasted/malf-toolchain/.github/actions/coderoast-golden-compare@da2abf639f64e1c1bca382aa7a973e9cc2f00412 with: digests-dir: digests min-legs: '5' diff --git a/.github/workflows/lint.yml b/.github/workflows/lint.yml index ef99e6a..cd6c45b 100644 --- a/.github/workflows/lint.yml +++ b/.github/workflows/lint.yml @@ -8,7 +8,7 @@ on: jobs: lint: - uses: CodeRoasted/malf-toolchain/.github/workflows/coderoast-lint.yml@b5e15eee5e2cc9a2709309850f845b28ba8d9e58 + uses: CodeRoasted/malf-toolchain/.github/workflows/coderoast-lint.yml@da2abf639f64e1c1bca382aa7a973e9cc2f00412 # PUBLIC repo: no runs-on passthrough and no checkout token — a fork PR runs this job. with: # clang-tidy runs (the default), over a clang-21 source build of this repo's whole first-party diff --git a/.github/workflows/release.yaml b/.github/workflows/release.yaml index 580854f..9e98bdd 100644 --- a/.github/workflows/release.yaml +++ b/.github/workflows/release.yaml @@ -38,7 +38,7 @@ jobs: release: needs: golden - uses: CodeRoasted/malf-toolchain/.github/workflows/coderoast-release.yml@b5e15eee5e2cc9a2709309850f845b28ba8d9e58 + uses: CodeRoasted/malf-toolchain/.github/workflows/coderoast-release.yml@da2abf639f64e1c1bca382aa7a973e9cc2f00412 with: tag: ${{ github.event.inputs.tag || github.ref_name }} packages: 'insight_metalog:.'