Files
AILang/docs/journals/2026-05-19-audit-design-md-rolesplit.md
T
Brummel f2cdd67e69 plan+audit: design-md-rolesplit.tidy re-derived on planning-time evidence (mechanism + scope corrected)
The tidy's gate-first Task 1 RED-verification + Boss independent
verification surfaced two defects in the audit Resolution as first
written — caught exactly where the planner->Boss loop is designed to,
before any contract byte moved. Per the 'two+ defects in one
iteration => fix the upstream artifact, do not patch a third time'
discipline, the audit Resolution is corrected in lockstep with the
plan re-derivation:

- Mechanism (Resolution-4): the 'case-insensitive iter-code regex'
  clause-3 design is REJECTED as unworkable — a blanket
  iter/milestone detector conflates the memory-model rule-names
  'Iter A'/'Iter B' and ordinary words 'pre-existing'/'pre-set'/
  'pre-Boehm' with provenance, over-firing on legit present-tense
  contract prose (4 no-strip files). Replaced by a FAITHFUL Sweep-1
  superset: case-sensitive digit-anchored Sweep-1 line anchors
  (confirmed ZERO across all contracts) + Sweep-1's ^[^/]*
  path-excluded date (so docs/specs/2026-.. citations are not
  flagged — repairs the iso_date over-fire the implement
  orchestrator correctly BLOCKED on) + the audit-named
  decision-record phrases (case-insensitive). No regex dep. The
  load-bearing invariant (clause-3 GREEN => Sweep-1 clean) is
  preserved; it never required the blanket detector.
- Scope (Resolution-1): the architect's [medium] was a 3-file
  spot-check; the exhaustive scan found roundtrip-invariant.md:73
  ('at iter form-a.1') and data-model.md:149,161 ('loop-recur iter
  1:') also carry lowercase provenance. True strip set = 5 files;
  plan Task 5b adds the 2 (spirit-cleanup, not gate-blocking).

Plan self-review 8/8 re-run; clause-3 = hand-rolled faithful Sweep-1
superset, no regex dep, no blanket iter detector.
2026-05-19 13:36:14 +02:00

9.3 KiB

audit — milestone close: DESIGN.md → design/ role-split

Date: 2026-05-19 Scope: deeffb1..176821c (spec a64b2cc/314e5e4, plan deeffb1, iter 176821c) Status: DRIFT (one tidy iteration) + bench causally-exonerated (baseline pristine)

Architect (drift_found — one [medium] spirit-finding; relocation faithful)

What holds: relocation byte-faithful at ### granularity (MIXED Decisions, dual-link frozen-value-layout, source-link-only mangling/env/qualified-xref, rewritten honesty-rule all match the spec Appendix vs git show deeffb1:docs/DESIGN.md); build-atomicity holds (design_schema_drift.rs include_str! retargeted, slicer removed exactly as spec'd; OQ7 cite deleted); design_index_pin.rs 4/4 GREEN; tree-wide live-ref grep clean; honesty-rule.md present-tense, names docs/journals/ as the rationale home, both docs_honesty_pin.rs:70,72 phrases verbatim+contiguous; agent contracts coherent (no contract instructs reading a missing file).

Drift:

  • [medium] design/contracts/typeclasses.md:182,199,280-317, str-abi.md:23,38-47, scope-boundaries.md:17,42 — faithfully migrated but contract-class-violating decision-record/history/ cross-milestone-amendment prose ("An earlier draft committed to…", "Milestone 23/24 amends the above", "was retired at iter mq.3/ctt.3", iter/date provenance stamps, "deliberately deferred", "NOT in milestone 22", "new-baseline decision"). Dodges the 6 literal clause-3 markers (case + wording variance: "An earlier draft" ≠ "an earlier draft"; "retired at iter" ≠ "retired in iter") yet is exactly the relitigation-guard content the split's spirit sends to journals.
  • [low/known-debt] design/contracts/float-semantics.md stale-direction (see "Str ABI" below …) — the prose moved to str-abi.md; pre-existing, faithfully migrated; wrong-direction anchor inside the ledger whose reason to exist is doc honesty.

Routed-item adjudication (both): strippable doc-archaeology to tidy, NOT ratify. The advisory architect_sweeps.sh Sweep-1 exit-1 on str-abi.md:23 is correctly diagnosing real history-anchor residue (Boss-confirmed byte-identical to DESIGN.md@deeffb1:2062-2065 — pre-existing, faithfully migrated, not split-introduced; the iter/date stamps are journal-class metadata, the present-tense contract is the signature itself).

Bench (check.py exit 1; compile_check 24/24 exit 0; cross_lang 25/25 exit 0)

6 check.py firings: bench_list_sum.{gc_s,bump_s}, bench_hof_pipeline.gc_s, bench_list_sum_explicit.bump_s, latency.{explicit,implicit}_at_rc.max_us.

Bencher verdict — causally-exonerated, decisive on byte-evidence. H0 (no causal mechanism) supported: emitted IR and final -O2 native bench binaries byte-identical HEAD 176821c vs pre-milestone dd5b183 for every firing fixture (sha256 + cmp -s table in the bencher report). Bencher audited all ~11 changed code/runtime files (not just the 2 named) — every change is comment / rustdoc / diagnostic-string-literal (DESIGN.md §"…"design/contracts/….md), none on an IR-emitting path; checker diagnostic strings are type-check-time only, absent from the binary. The 6 firings are the recurring tracked-P2 families (*.bump_s environmental staleness; *_at_rc.max_us -n 5 single-sample tail jitter; *.gc_s Boehm-scan wall-time variance — NOT the M5-ratified gc_rss_kb trio). compile_check/cross_lang pristine corroborates (no codegen surface moved).

Disposition: NO-ratify / carry-on causally-exonerated — baseline stays pristine. Identical to the M2/M3/M5 closes; ratifying would bake measurement variance into the baseline. No --update-baseline, no paired ratify entry (none is warranted — nothing moved).

Bench-design limitations recorded (not milestone-close actions): *_at_rc.max_us is a bench/run.sh -n 5 artifact (max over 5 has no tail confidence); implicit_at_rc leaks by construction so its max_us is inherently unstable. Both pre-existing, tracked-P2, candidates for the standing latency-methodology rework — not this milestone.

Resolution (orchestrator)

  • Bench: carry-on, baseline pristine, no commit beyond this entry. Recorded causally-exonerated as M2/M3/M5.
  • Architect drift [medium]+[low]: fix path — one tidy iteration design-md-rolesplit.tidy. Orchestrator-decided scope (the architect named the gap; the clause-3-widening decision is mine):
    1. Move the decision-record/history prose out of the affected contract files into docs/journals/2026-05-19-design-decision-records.md (append — same milestone's relitigation archive). Each removed history sentence is replaced by its present-tense contract equivalent (the builtin signature is the contract; the (iter …) stamp is journal metadata). Scope corrected on planning-time evidence (see amendment below): the architect's [medium] was a 3-file spot-check (typeclasses/str-abi/scope-boundaries); the exhaustive plan-recon + Boss verification scan found two more contract files carrying lowercase iter <code> provenance the spot-check missed — roundtrip-invariant.md:73 ("at iter form-a.1") and data-model.md:149,161 ("loop-recur iter 1:"). The true strip set is 5 contract files.
    2. Fix float-semantics.md stale-direction cross-ref → (see design/contracts/str-abi.md).
    3. Re-scope the architect_sweeps.sh honesty sweeps from design/contracts design/models to design/contracts only. Substantive reason (not effort): post-split, design/models/ is the explicitly narrative tier — a whitepaper legitimately carries "as of milestone N" context; scanning it for history-anchors is a category error. The honesty surface is design/contracts/ (the hot, test-linked tier). Update ailang-architect.md + any sweep-scope doc in lockstep.
    4. Widen design_index_pin.rs clause-3 so, over the design/contracts/ scope, it subsumes architect_sweeps.sh Sweep-1's history-anchor regex. Invariant established: clause-3 GREEN ⟹ Sweep-1 finds nothing in contracts/ — the in-code hard gate enforces the spirit; the advisory then only legitimately fires on models/ (out of its scope after point 3). This permanently closes the spirit-vs-letter gap the literal 6-marker list left open. Mechanism corrected on planning-time evidence (see amendment below): the original "case-insensitive iter-code regex" sketch is unworkable and is rejected — a blanket case-insensitive iter/milestone detector conflates the memory-model rule-names "Iter A"/"Iter B" and the ordinary words "pre-existing"/"pre-set"/"pre-Boehm" with provenance, over-firing on legitimate present-tense contract prose. The workable design: clause-3 = a faithful reproduction of Sweep-1's actual alternatives (case-sensitive, digit-anchored — confirmed ZERO across all contracts) + Sweep-1's ^[^/]* path-excluded date (so docs/specs/2026-… citations are not flagged) + the audit-named decision-record phrases (case-insensitive — the deliberate widening that closes the capital-variance dodge). The lowercase (iter <code>) provenance is removed by the strip tasks (point 1), not by a fragile hard-gate regex; the invariant holds without the rejected detector.
    5. Exit state: architect_sweeps.sh exit 0; the widened (faithful-superset) design_index_pin.rs clause-3 GREEN; whole cargo test --workspace GREEN; the decision-record journal grows; no contract carries history residue.

Resolution amendment (2026-05-19, planning-time evidence)

The tidy plan's gate-first Task 1 (RED-verification) + Boss independent verification surfaced two defects in this Resolution as first written — caught exactly where the planner→Boss loop is designed to catch them, before any contract byte moved:

  • Mechanism (point 4): "case-insensitive iter-code regex" is unworkable (conflates rule-names + ordinary words with provenance). Replaced by the faithful-Sweep-1 + path-excluded-date
    • phrases design above. The load-bearing invariant (clause-3 ⟹ Sweep-1 clean) is preserved — it never required the blanket detector; faithful-Sweep-1 + phrases suffices and faithful-Sweep-1 is confirmed already ZERO across every contract.
  • Scope (point 1): the [medium] was a 3-file spot-check; the exhaustive scan found roundtrip-invariant.md + data-model.md also carry lowercase provenance. The strip set is 5 files (the plan's Task 5b covers the 2 additions; they are spirit-cleanup, not gate-blocking — neither Sweep-1 nor the corrected clause-3 trips on lowercase iter form-a.1, so the invariant/gate close regardless; stripping them is the audit's spirit fully honored).

This amendment is the upstream-artifact correction the discipline mandates over patching the plan a third time (the "two+ defects in one iteration ⇒ the upstream artifact is wrong" rule). The plan docs/plans/design-md-rolesplit.tidy.md is re-derived consistently with it.

Milestone closes after the tidy iteration lands Boss-verified. No fieldtest (zero authoring-surface change — the only author-facing delta is the 2 diagnostic pointers, a doc-pointer not a language change; recorded by reasoned exclusion, not omission).