audit design-md-rolesplit (milestone close): DRIFT (one tidy iter) + bench causally-exonerated (baseline pristine)
Architect: relocation byte-faithful; one [medium] spirit-finding —
faithfully-migrated decision-record/history prose in
design/contracts/{typeclasses,str-abi,scope-boundaries}.md dodges the
6 literal clause-3 markers but is the relitigation content the
split's spirit sends to journals; [low] float-semantics.md
stale-direction 'see Str ABI below'. Both routed items: tidy not
ratify (the str-abi.md:23 advisory Sweep-1 exit-1 correctly
diagnoses real pre-existing history residue, byte-identical
DESIGN.md@deeffb1 — faithfully migrated, not split-introduced).
Bencher: causally-exonerated, DECISIVE on byte-evidence — emitted IR
AND final -O2 binaries byte-identical 176821c vs dd5b183 for all 6
check.py firings; all ~11 changed files audited
comment/docstring/diagnostic-string-only; tracked-P2 families;
compile_check/cross_lang pristine. NO-ratify, baseline pristine
(M2/M3/M5 disposition).
Resolution: one tidy iter (move history prose to the decision-record
journal; fix stale 'below'; re-scope architect_sweeps honesty sweeps
to design/contracts only — models/ is the narrative tier; widen
design_index_pin.rs clause-3 to subsume Sweep-1's history-anchor
regex over contracts/ so the hard gate enforces the spirit). No
fieldtest (zero authoring-surface change). Milestone closes after
the tidy lands Boss-verified.
This commit is contained in:
@@ -0,0 +1,122 @@
|
||||
# audit — milestone close: DESIGN.md → design/ role-split
|
||||
|
||||
**Date:** 2026-05-19
|
||||
**Scope:** `deeffb1..176821c` (spec a64b2cc/314e5e4, plan deeffb1, iter 176821c)
|
||||
**Status:** DRIFT (one tidy iteration) + bench causally-exonerated (baseline pristine)
|
||||
|
||||
## Architect (drift_found — one [medium] spirit-finding; relocation faithful)
|
||||
|
||||
**What holds:** relocation byte-faithful at `###` granularity (MIXED
|
||||
Decisions, dual-link frozen-value-layout, source-link-only
|
||||
mangling/env/qualified-xref, rewritten honesty-rule all match the
|
||||
spec Appendix vs `git show deeffb1:docs/DESIGN.md`); build-atomicity
|
||||
holds (`design_schema_drift.rs` `include_str!` retargeted, slicer
|
||||
removed exactly as spec'd; OQ7 cite deleted); `design_index_pin.rs`
|
||||
4/4 GREEN; tree-wide live-ref grep clean; `honesty-rule.md`
|
||||
present-tense, names `docs/journals/` as the rationale home, both
|
||||
`docs_honesty_pin.rs:70,72` phrases verbatim+contiguous; agent
|
||||
contracts coherent (no contract instructs reading a missing file).
|
||||
|
||||
**Drift:**
|
||||
- `[medium]` `design/contracts/typeclasses.md:182,199,280-317`,
|
||||
`str-abi.md:23,38-47`, `scope-boundaries.md:17,42` — faithfully
|
||||
migrated but contract-class-violating decision-record/history/
|
||||
cross-milestone-amendment prose ("An earlier draft committed
|
||||
to…", "Milestone 23/24 amends the above", "was retired at iter
|
||||
mq.3/ctt.3", iter/date provenance stamps, "deliberately deferred",
|
||||
"NOT in milestone 22", "new-baseline decision"). Dodges the 6
|
||||
*literal* clause-3 markers (case + wording variance: "An earlier
|
||||
draft" ≠ "an earlier draft"; "retired at iter" ≠ "retired in
|
||||
iter") yet is exactly the relitigation-guard content the split's
|
||||
*spirit* sends to journals.
|
||||
- `[low/known-debt]` `design/contracts/float-semantics.md`
|
||||
stale-direction `(see "Str ABI" below …)` — the prose moved to
|
||||
`str-abi.md`; pre-existing, faithfully migrated; wrong-direction
|
||||
anchor inside the ledger whose reason to exist is doc honesty.
|
||||
|
||||
**Routed-item adjudication (both):** strippable doc-archaeology to
|
||||
**tidy, NOT ratify**. The advisory `architect_sweeps.sh` Sweep-1
|
||||
exit-1 on `str-abi.md:23` is *correctly* diagnosing real
|
||||
history-anchor residue (Boss-confirmed byte-identical to
|
||||
DESIGN.md@deeffb1:2062-2065 — pre-existing, faithfully migrated, not
|
||||
split-introduced; the iter/date stamps are journal-class metadata,
|
||||
the present-tense contract is the signature itself).
|
||||
|
||||
## Bench (check.py exit 1; compile_check 24/24 exit 0; cross_lang 25/25 exit 0)
|
||||
|
||||
6 `check.py` firings: `bench_list_sum.{gc_s,bump_s}`,
|
||||
`bench_hof_pipeline.gc_s`, `bench_list_sum_explicit.bump_s`,
|
||||
`latency.{explicit,implicit}_at_rc.max_us`.
|
||||
|
||||
**Bencher verdict — causally-exonerated, decisive on byte-evidence.**
|
||||
H0 (no causal mechanism) supported: emitted IR **and** final `-O2`
|
||||
native bench binaries **byte-identical** HEAD `176821c` vs
|
||||
pre-milestone `dd5b183` for every firing fixture (sha256 + `cmp -s`
|
||||
table in the bencher report). Bencher audited *all ~11* changed
|
||||
code/runtime files (not just the 2 named) — every change is
|
||||
comment / rustdoc / diagnostic-string-literal (`DESIGN.md §"…"` →
|
||||
`design/contracts/….md`), none on an IR-emitting path; checker
|
||||
diagnostic strings are type-check-time only, absent from the
|
||||
binary. The 6 firings are the recurring tracked-P2 families
|
||||
(`*.bump_s` environmental staleness; `*_at_rc.max_us` `-n 5`
|
||||
single-sample tail jitter; `*.gc_s` Boehm-scan wall-time variance —
|
||||
NOT the M5-ratified `gc_rss_kb` trio). `compile_check`/`cross_lang`
|
||||
pristine corroborates (no codegen surface moved).
|
||||
|
||||
**Disposition: NO-ratify / carry-on causally-exonerated — baseline
|
||||
stays pristine.** Identical to the M2/M3/M5 closes; ratifying would
|
||||
bake measurement variance into the baseline. No `--update-baseline`,
|
||||
no paired ratify entry (none is warranted — nothing moved).
|
||||
|
||||
Bench-design limitations recorded (not milestone-close actions):
|
||||
`*_at_rc.max_us` is a `bench/run.sh` `-n 5` artifact (max over 5
|
||||
has no tail confidence); `implicit_at_rc` leaks by construction so
|
||||
its `max_us` is inherently unstable. Both pre-existing, tracked-P2,
|
||||
candidates for the standing latency-methodology rework — not this
|
||||
milestone.
|
||||
|
||||
## Resolution (orchestrator)
|
||||
|
||||
- **Bench:** carry-on, baseline pristine, no commit beyond this
|
||||
entry. Recorded causally-exonerated as M2/M3/M5.
|
||||
- **Architect drift [medium]+[low]:** **fix path — one tidy
|
||||
iteration** `design-md-rolesplit.tidy`. Orchestrator-decided
|
||||
scope (the architect named the gap; the clause-3-widening
|
||||
decision is mine):
|
||||
1. Move the decision-record/history prose out of
|
||||
`design/contracts/{typeclasses,str-abi,scope-boundaries}.md`
|
||||
into `docs/journals/2026-05-19-design-decision-records.md`
|
||||
(append — same milestone's relitigation archive). Each removed
|
||||
history sentence is replaced by its present-tense contract
|
||||
equivalent (e.g. the builtin *signature* is the contract; the
|
||||
`(iter …)` stamp is journal metadata).
|
||||
2. Fix `float-semantics.md` stale-direction cross-ref →
|
||||
`(see design/contracts/str-abi.md)`.
|
||||
3. **Re-scope the `architect_sweeps.sh` honesty sweeps from
|
||||
`design/contracts design/models` to `design/contracts` only.**
|
||||
Substantive reason (not effort): post-split, `design/models/`
|
||||
is the *explicitly narrative* tier — a whitepaper legitimately
|
||||
carries "as of milestone N" context; scanning it for
|
||||
history-anchors is a category error. The honesty surface is
|
||||
`design/contracts/` (the hot, test-linked tier). Update
|
||||
`ailang-architect.md` + any sweep-scope doc in lockstep.
|
||||
4. **Widen `design_index_pin.rs` clause-3** so, over the
|
||||
`design/contracts/` scope, it *subsumes* `architect_sweeps.sh`
|
||||
Sweep-1's history-anchor regex (case-insensitive; iter-code
|
||||
and ISO-date regexes; "earlier draft", "amends the above",
|
||||
"was retired", "deliberately deferred", "new-baseline
|
||||
decision", "milestone NN"). Invariant established:
|
||||
**clause-3 GREEN ⟹ Sweep-1 finds nothing in `contracts/`** —
|
||||
the in-code hard gate enforces the spirit; the advisory can
|
||||
then only legitimately fire on `models/` (now out of its
|
||||
scope). This permanently closes the spirit-vs-letter gap the
|
||||
literal 6-marker list left open.
|
||||
5. Exit state: `architect_sweeps.sh` exit 0; widened
|
||||
`design_index_pin.rs` clause-3 GREEN; whole `cargo test
|
||||
--workspace` GREEN; the decision-record journal grows; no new
|
||||
contract carries history residue.
|
||||
|
||||
Milestone closes after the tidy iteration lands Boss-verified.
|
||||
No fieldtest (zero authoring-surface change — the only author-facing
|
||||
delta is the 2 diagnostic pointers, a doc-pointer not a language
|
||||
change; recorded by reasoned exclusion, not omission).
|
||||
@@ -116,3 +116,4 @@
|
||||
- 2026-05-19 — iter embedding-abi-m5.tidy (DONE 3/3): resolves the M5 milestone-close audit DRIFT (28ab56a). DOC/COMMENT-ONLY, recon-pin-verified, single cohesive commit (M2.tidy a80d495 / M3.tidy 63d7d60 precedent — pins are the coverage, no RED, no audit/fieldtest gate). `docs/DESIGN.md` edit-1 §"Free (host side)": dropped the retired-M4 forward-reference ("an additive M4 concern, not a contradiction of this freeze" — M4 retired 2026-05-18) → present-tense current fact (a boxed-field record is **not** an M3 embedding type, export-gate-rejected; the freeze covers exactly the all-scalar single-ctor record). edit-2 §"Embedding ABI": reconciled the now-inaccurate "(no shared mutable runtime state — … data-race-free, sanitiser-verified)" blanket with the real post-7bfa11e state — the per-allocation hot path (per-ctx counters + per-object refcount header) is non-atomic by design and never shared (`Ctx: !Send`, single-thread-per-ctx); the one datum a multi-threaded host shares is the global RC-stats fallback counter, atomic-relaxed so the swarm's leak accounting is exact; "data-race-free, sanitiser-verified" retained (still true). `runtime/rc.c:88` 18g.0-block comment-only: stale "two unconditional `++` operations" → accurate "one counter bump per alloc/free … relaxed atomic add on the global null-ctx fallback, a plain `++` on the per-ctx path" (consistent with the adjacent already-correct :93-106 atomic block + :45-55 Threading header). Boss-verified independently: all pins green (design_schema_drift 8/0, docs_honesty_pin 5/0, effect_doc_honesty_pin 4/0, embed_record_layout_pin 1/0) — the mechanical proof the edits moved no pinned/hashed byte; the adjacent separately-pinned bare-scalar sentence is byte-identical (shifted 2299→2305 by net-added lines; `docs_honesty_pin.rs:135` is a substring pin, passes); rc.c diff strictly comment-only (filter empty); `cargo build --workspace` Finished; git scope = only docs/DESIGN.md + runtime/rc.c + journal/stats. Clears the M5-audit doc-honesty debt; no new debt. This is the FINAL M5 iteration — M5 (the M1–M5 Embedding ABI arc) is now functionally complete, audited, ratified, and doc-honest. → 2026-05-19-iter-embedding-abi-m5.tidy.md
|
||||
- 2026-05-19 — iter design-md-rolesplit.1 (DONE 9/9, whole milestone): the 3020-line `docs/DESIGN.md` replaced by the `design/` ledger — `design/INDEX.md` (sole addressable spine, typed Contracts+Models tables, polymorphic links: prose file OR authoritative source `//!`), 14 `design/contracts/*.md` test-linked invariants + 3 source-link-only contracts (mangling/env-construction/qualified-xref, no prose file — code is SoT), 5 `design/models/*.md` onboarding whitepapers, and `docs/journals/2026-05-19-design-decision-records.md` (the relitigation-guard archive: every why/rejected/does-not-do/rollback/empirical `###` moved out at `###` granularity). Clean cut (`git rm docs/DESIGN.md`, no stub). RED-first `crates/ailang-core/tests/design_index_pin.rs` 4-clause anti-regrowth spine (DESIGN.md-gone / every-INDEX-link-resolves / every-contract-names-a-resolvable-ratifier / contracts-carry-no-decision-record-prose) demonstrably RED→GREEN. Build-atomic by task ordering (the only compile-time consumer, `design_schema_drift.rs` `include_str!`, retargeted to `design/contracts/data-model.md` BEFORE the deletion; the `## Data model`/`## Pipeline` slicer dropped — a simplification the split enables). 2 NoInstance diagnostics + their 2 lockstep E2Es retargeted to `design/contracts/{float-semantics,typeclasses}.md` (the contiguity-across-`\`-continuation hazard scrubbed). ~12 agent reading lists + 5 SKILL bodies + CLAUDE.md + skills/README.md + ~25 code/C/.ail/spec comment xrefs retargeted to the Appendix destinations; OQ7 dangling "Iter 13b" cite deleted (no forward target — a pointer would be fiction). honesty-rule.md rewritten so the rule names the new home (rationale→journals), resolving the recon-found internal contradiction; the two `docs_honesty_pin.rs:70,72` pinned phrases preserved verbatim+contiguous. Boss-verified independently: whole `cargo test --workspace` **646 passed / 0 failed**, `design_index_pin` 4/4, acceptance grep **CLEAN of live DESIGN.md refs** (residuals = only the spec-mandated clause-4 deletion-enforcer), honesty-rule repair carries no clause-3 marker. Spec grounding-check PASS ×2 (one re-dispatch after a corrected commitment-4 pin-status claim; one after the Boss-adjudicated relocation-appendix amendment resolving plan-recon's 7 open questions — ledger completed to 17 contract rows incl. the qualified-xref/str-abi/scope-boundaries additions the 12-list under-counted). 2 DONE_WITH_CONCERNS routed to the mandatory milestone-close `audit`: (a) `design/contracts/str-abi.md:23` `(iter str-concat, 2026-05-13)` API-provenance stamp trips advisory `architect_sweeps.sh` Sweep-1 — Boss-confirmed **byte-identical to DESIGN.md@deeffb1:2062-2065**, a faithfully-migrated PRE-EXISTING anchor (sweep regexes verbatim, only the path retargeted), NOT a split-introduced regression — RATIFY-or-tidy at audit; (b) the now stale-direction `(see "Str ABI" below)` intra-prose cross-ref in `float-semantics.md` (the Appendix is heading-level; no task prescribes intra-prose cross-ref rewrite) — audit-adjudication candidate. One plan defect recorded (Task 9 Step 4's verbatim acceptance grep used a `^\./` anchor not matching the system's `grep -rIn` output; substance independently re-verified CLEAN). → 2026-05-19-iter-design-md-rolesplit.1.md
|
||||
- 2026-05-19 — design-decision-records (migration): relitigation-guard archive — every why/rejected/does-not-do/rollback/empirical ### moved out of the former docs/DESIGN.md by the design-md-rolesplit milestone. Companion to spec 2026-05-19-design-md-rolesplit. → 2026-05-19-design-decision-records.md
|
||||
- 2026-05-19 — audit design-md-rolesplit (milestone close): DRIFT (one tidy iteration) + bench causally-exonerated (baseline pristine). Architect drift_found, relocation byte-faithful (MIXED Decisions / dual-link / source-link / rewritten honesty-rule all match the spec Appendix vs deeffb1; build-atomicity holds; design_index_pin 4/4; honesty-rule.md correct + pins retargeted; agent contracts coherent) — one [medium] spirit-finding: faithfully-migrated decision-record/history prose in design/contracts/{typeclasses,str-abi,scope-boundaries}.md DODGES the 6 literal clause-3 markers (case+wording variance) but IS the relitigation content the split's spirit sends to journals; plus [low] float-semantics.md stale-direction "see Str ABI below". Both routed items adjudicated strippable-doc-archaeology-to-TIDY-not-ratify (the str-abi.md:23 advisory Sweep-1 exit-1 correctly diagnoses real pre-existing history residue, byte-identical DESIGN.md@deeffb1:2062-2065, faithfully migrated — not split-introduced). Bencher: NO-ratify, causally-exonerated DECISIVE on byte-evidence — emitted IR AND final -O2 binaries byte-identical 176821c vs pre-milestone dd5b183 for all 6 check.py firings (sha256+cmp), all ~11 changed code/runtime files audited comment/docstring/diagnostic-string-only, zero IR-path change; the firings are tracked-P2 (*.bump_s staleness, *_at_rc.max_us -n5 tail jitter, *.gc_s Boehm-scan variance — NOT the M5 gc_rss trio); compile_check 24/24 + cross_lang 25/25 pristine corroborate; baseline untouched (identical to M2/M3/M5). Resolution: one tidy iter design-md-rolesplit.tidy — (1) move the history prose to the decision-record journal, (2) fix the stale "below", (3) re-scope architect_sweeps honesty sweeps to design/contracts only (models/ is the explicitly-narrative tier — scanning it for history-anchors is a post-split category error), (4) widen design_index_pin.rs clause-3 to SUBSUME Sweep-1's history-anchor regex over contracts/ (invariant: clause-3 GREEN ⟹ Sweep-1 clean in contracts/ — the hard gate enforces the spirit, closing the literal-marker dodge permanently). No fieldtest (zero authoring-surface change). Milestone closes after the tidy lands Boss-verified. → 2026-05-19-audit-design-md-rolesplit.md
|
||||
|
||||
Reference in New Issue
Block a user