docs(design): ratify the check→codegen boundary (mir.5, typed-MIR close)

mir.5 is the typed-MIR milestone's closing iteration. Its CODE half had
already converged before the iteration began, so mir.5 ships no code —
it ratifies into the design/ ledger the boundary the code already holds.

Verified at iteration entry (empirically, not from the spec sketch):
  - all four named re-derivers grep-clean in codegen: synth_with_extras,
    synth_arg_type, type_home_module, the second infer_module_with_cross;
  - lower_workspace takes &MirWorkspace (codegen consumes MIR);
  - MTerm::New is unreachable!() — raw-buf.4 desugars Term::New to
    (app T.new …) before codegen, so there is no element-type
    re-derivation left to relocate;
  - #51 / #53 (the element-type / new-T codegen crashes) are closed;
    their residue was fixed by ee4107c / 420f75f plus the New-desugar,
    not by a separate raw-buf patch track.

Ledger work (the mir.5 deliverable):
  - NEW design/contracts/0018-check-codegen-boundary.md: the invariant
    "codegen re-derives nothing; MIR is total over what check proved;
    a codegen arm that recomputes a fact instead of reading MIR is
    drift." Ratifier: lower_to_mir_ty.rs::callee_classification_builtin_and_static.
  - 0013-typeclasses invariant 2 retracted: codegen no longer re-resolves
    cross-module names via an import_map fallback; lower_to_mir::classify_callee
    resolves the reference once into Callee::Static and codegen consumes it.
  - 0003-pipeline.md: the "lower to MIR" line names the real stage
    (elaborate_workspace → MirWorkspace → lower_workspace) and a new
    paragraph states the boundary, cross-referencing 0018.
  - INDEX.md: boundary contract row added; qualified-xref re-pointed at
    lower_to_mir + 0018.
  - codegen_import_map_fallback_pin.rs doc-comment made honest — it pins
    the post-mono AST precondition classify_callee relies on, not a
    codegen-side resolution that no longer exists. Assertions unchanged;
    the test stays green.
  - spec 0060 gains a mir.5 refinement note recording the early code
    convergence.

Acceptance criteria 1-7 of docs/specs/0060-typed-mir.md are all met.
Full workspace suite green (exit 0, 0 failed, 2 ignored); 708 passed
carried from mir.4 (no test added or removed).

Not done here (deliberately): the milestone #7 (raw-buf) subsumption
note is an external Gitea tracker write; the /boss auto-mode classifier
declined it as an unauthorised external write and it is surfaced to the
user rather than worked around. The end-to-end milestone fieldtest
remains the deliberate manual close-gate before the tracker milestone
is marked done.

refs #51 #53
This commit is contained in:
2026-06-01 01:34:37 +02:00
parent c5fd16a4eb
commit a378dad0aa
7 changed files with 147 additions and 32 deletions
@@ -0,0 +1,13 @@
{
"iter_id": "mir.5",
"date": "2026-06-01",
"mode": "ledger-only",
"outcome": "DONE",
"tasks_total": 5,
"tasks_completed": 5,
"reloops_per_task": { "1": 0, "2": 0, "3": 0, "4": 0, "5": 0 },
"review_loops_spec": 0,
"review_loops_quality": 0,
"blocked_reason": null,
"notes": "mir.5 is the typed-MIR milestone's closing iteration. At iteration entry the orchestrator verified the CODE half was already complete: all four named re-derivers (synth_with_extras, synth_arg_type, type_home_module, codegen's infer_module_with_cross) are grep-clean; lower_workspace takes &MirWorkspace; MTerm::New is unreachable!() (raw-buf.4 desugars Term::New to (app T.new …) before codegen); #51/#53 are closed (element-type residue converged via the #51/#53 fixes ee4107c/420f75f + the raw-buf.4 New-desugar). So mir.5 shipped NO code — it is ledger-only ratification of the boundary the code already holds. Authored design/contracts/0018-check-codegen-boundary.md (invariant: codegen re-derives nothing; MIR is total over what check proved; ratifier crates/ailang-check/tests/lower_to_mir_ty.rs::callee_classification_builtin_and_static). Retracted 0013-typeclasses invariant 2 (codegen no longer re-resolves cross-module names; lower_to_mir::classify_callee resolves once into Callee::Static). Corrected design/models/0003-pipeline.md MIR line to name the real stage + a boundary paragraph. Updated design/INDEX.md: added the boundary row, re-pointed qualified-xref at lower_to_mir + 0018. Made the codegen_import_map_fallback_pin.rs doc-comment honest (it now pins the post-mono AST precondition classify_callee relies on, not a codegen-side resolution that no longer exists; assertions unchanged, stays green). Added a mir.5 refinement note to spec 0060 recording the early code convergence. Full workspace suite green (exit 0, 0 failed, 2 ignored); 708 passed carried from mir.4 (no test added/removed; the single .rs edit is a doc-comment). RESIDUAL (deferred to user): the milestone #7 (raw-buf) subsumption note is an external Gitea write the /boss auto-mode classifier correctly declined to make autonomously — surfaced to the user with the exact note text. #51/#53 already closed; #49 closes on push of c5fd16a. Acceptance criteria 1-7 of spec 0060 all met. Milestone code+ledger complete; the end-to-end milestone fieldtest is the remaining deliberate manual close-gate."
}