Files
AILang/docs/journals/2026-05-19-audit-design-md-rolesplit.md
T
Brummel 2ba5e16806 audit design-md-rolesplit (milestone close): DRIFT (one tidy iter) + bench causally-exonerated (baseline pristine)
Architect: relocation byte-faithful; one [medium] spirit-finding —
faithfully-migrated decision-record/history prose in
design/contracts/{typeclasses,str-abi,scope-boundaries}.md dodges the
6 literal clause-3 markers but is the relitigation content the
split's spirit sends to journals; [low] float-semantics.md
stale-direction 'see Str ABI below'. Both routed items: tidy not
ratify (the str-abi.md:23 advisory Sweep-1 exit-1 correctly
diagnoses real pre-existing history residue, byte-identical
DESIGN.md@deeffb1 — faithfully migrated, not split-introduced).

Bencher: causally-exonerated, DECISIVE on byte-evidence — emitted IR
AND final -O2 binaries byte-identical 176821c vs dd5b183 for all 6
check.py firings; all ~11 changed files audited
comment/docstring/diagnostic-string-only; tracked-P2 families;
compile_check/cross_lang pristine. NO-ratify, baseline pristine
(M2/M3/M5 disposition).

Resolution: one tidy iter (move history prose to the decision-record
journal; fix stale 'below'; re-scope architect_sweeps honesty sweeps
to design/contracts only — models/ is the narrative tier; widen
design_index_pin.rs clause-3 to subsume Sweep-1's history-anchor
regex over contracts/ so the hard gate enforces the spirit). No
fieldtest (zero authoring-surface change). Milestone closes after
the tidy lands Boss-verified.
2026-05-19 13:14:15 +02:00

6.5 KiB

audit — milestone close: DESIGN.md → design/ role-split

Date: 2026-05-19 Scope: deeffb1..176821c (spec a64b2cc/314e5e4, plan deeffb1, iter 176821c) Status: DRIFT (one tidy iteration) + bench causally-exonerated (baseline pristine)

Architect (drift_found — one [medium] spirit-finding; relocation faithful)

What holds: relocation byte-faithful at ### granularity (MIXED Decisions, dual-link frozen-value-layout, source-link-only mangling/env/qualified-xref, rewritten honesty-rule all match the spec Appendix vs git show deeffb1:docs/DESIGN.md); build-atomicity holds (design_schema_drift.rs include_str! retargeted, slicer removed exactly as spec'd; OQ7 cite deleted); design_index_pin.rs 4/4 GREEN; tree-wide live-ref grep clean; honesty-rule.md present-tense, names docs/journals/ as the rationale home, both docs_honesty_pin.rs:70,72 phrases verbatim+contiguous; agent contracts coherent (no contract instructs reading a missing file).

Drift:

  • [medium] design/contracts/typeclasses.md:182,199,280-317, str-abi.md:23,38-47, scope-boundaries.md:17,42 — faithfully migrated but contract-class-violating decision-record/history/ cross-milestone-amendment prose ("An earlier draft committed to…", "Milestone 23/24 amends the above", "was retired at iter mq.3/ctt.3", iter/date provenance stamps, "deliberately deferred", "NOT in milestone 22", "new-baseline decision"). Dodges the 6 literal clause-3 markers (case + wording variance: "An earlier draft" ≠ "an earlier draft"; "retired at iter" ≠ "retired in iter") yet is exactly the relitigation-guard content the split's spirit sends to journals.
  • [low/known-debt] design/contracts/float-semantics.md stale-direction (see "Str ABI" below …) — the prose moved to str-abi.md; pre-existing, faithfully migrated; wrong-direction anchor inside the ledger whose reason to exist is doc honesty.

Routed-item adjudication (both): strippable doc-archaeology to tidy, NOT ratify. The advisory architect_sweeps.sh Sweep-1 exit-1 on str-abi.md:23 is correctly diagnosing real history-anchor residue (Boss-confirmed byte-identical to DESIGN.md@deeffb1:2062-2065 — pre-existing, faithfully migrated, not split-introduced; the iter/date stamps are journal-class metadata, the present-tense contract is the signature itself).

Bench (check.py exit 1; compile_check 24/24 exit 0; cross_lang 25/25 exit 0)

6 check.py firings: bench_list_sum.{gc_s,bump_s}, bench_hof_pipeline.gc_s, bench_list_sum_explicit.bump_s, latency.{explicit,implicit}_at_rc.max_us.

Bencher verdict — causally-exonerated, decisive on byte-evidence. H0 (no causal mechanism) supported: emitted IR and final -O2 native bench binaries byte-identical HEAD 176821c vs pre-milestone dd5b183 for every firing fixture (sha256 + cmp -s table in the bencher report). Bencher audited all ~11 changed code/runtime files (not just the 2 named) — every change is comment / rustdoc / diagnostic-string-literal (DESIGN.md §"…"design/contracts/….md), none on an IR-emitting path; checker diagnostic strings are type-check-time only, absent from the binary. The 6 firings are the recurring tracked-P2 families (*.bump_s environmental staleness; *_at_rc.max_us -n 5 single-sample tail jitter; *.gc_s Boehm-scan wall-time variance — NOT the M5-ratified gc_rss_kb trio). compile_check/cross_lang pristine corroborates (no codegen surface moved).

Disposition: NO-ratify / carry-on causally-exonerated — baseline stays pristine. Identical to the M2/M3/M5 closes; ratifying would bake measurement variance into the baseline. No --update-baseline, no paired ratify entry (none is warranted — nothing moved).

Bench-design limitations recorded (not milestone-close actions): *_at_rc.max_us is a bench/run.sh -n 5 artifact (max over 5 has no tail confidence); implicit_at_rc leaks by construction so its max_us is inherently unstable. Both pre-existing, tracked-P2, candidates for the standing latency-methodology rework — not this milestone.

Resolution (orchestrator)

  • Bench: carry-on, baseline pristine, no commit beyond this entry. Recorded causally-exonerated as M2/M3/M5.
  • Architect drift [medium]+[low]: fix path — one tidy iteration design-md-rolesplit.tidy. Orchestrator-decided scope (the architect named the gap; the clause-3-widening decision is mine):
    1. Move the decision-record/history prose out of design/contracts/{typeclasses,str-abi,scope-boundaries}.md into docs/journals/2026-05-19-design-decision-records.md (append — same milestone's relitigation archive). Each removed history sentence is replaced by its present-tense contract equivalent (e.g. the builtin signature is the contract; the (iter …) stamp is journal metadata).
    2. Fix float-semantics.md stale-direction cross-ref → (see design/contracts/str-abi.md).
    3. Re-scope the architect_sweeps.sh honesty sweeps from design/contracts design/models to design/contracts only. Substantive reason (not effort): post-split, design/models/ is the explicitly narrative tier — a whitepaper legitimately carries "as of milestone N" context; scanning it for history-anchors is a category error. The honesty surface is design/contracts/ (the hot, test-linked tier). Update ailang-architect.md + any sweep-scope doc in lockstep.
    4. Widen design_index_pin.rs clause-3 so, over the design/contracts/ scope, it subsumes architect_sweeps.sh Sweep-1's history-anchor regex (case-insensitive; iter-code and ISO-date regexes; "earlier draft", "amends the above", "was retired", "deliberately deferred", "new-baseline decision", "milestone NN"). Invariant established: clause-3 GREEN ⟹ Sweep-1 finds nothing in contracts/ — the in-code hard gate enforces the spirit; the advisory can then only legitimately fire on models/ (now out of its scope). This permanently closes the spirit-vs-letter gap the literal 6-marker list left open.
    5. Exit state: architect_sweeps.sh exit 0; widened design_index_pin.rs clause-3 GREEN; whole cargo test --workspace GREEN; the decision-record journal grows; no new contract carries history residue.

Milestone closes after the tidy iteration lands Boss-verified. No fieldtest (zero authoring-surface change — the only author-facing delta is the 2 diagnostic pointers, a doc-pointer not a language change; recorded by reasoned exclusion, not omission).