The single-file ledger had grown to 2968 lines / ~42k tokens, mixing current design law with accreted history: 59 cycle-stamped realization blocks, 18 [HISTORY] passages, 22 supersession markers, and the C10 / C22 / C24 reframe sagas layered several supersessions deep. A code-grounding audit (31 agents, adversarially verified) confirmed 11 defects stated as current truth: stale crate homes from the C28 #288 roster split (cost nodes, PositionManagement, PositionEvent, Session), the renamed InputSpec->PortSpec, the pre-#241 project model in C16 and the open-threads section, a stale HarnessKind retirement deferral in C24, and three C28-internal inconsistencies. New shape, per the ailang precedent: - INDEX.md stays the sole addressable entry point: foundation, external components, a C-id-keyed contract map (one line per contract), and only the genuinely open architectural threads. - contracts/cNN-<slug>.md carries each contract's current truth only: Guarantee / Forbids / Why with ratified refinements integrated, plus a code-anchored Current state. All confirmed defects are fixed here; crate anchors were re-verified against the tree. - contracts/cNN-<slug>.history.md (18 sidecars) and INDEX.history.md preserve every superseded block verbatim, stamps and issue refs intact, under a frozen-record banner. Nothing was deleted: superseded design intent remains an addressable working-tree artifact, off the per-cycle audit walk. - Ledger discipline is now stated in INDEX.md: live files are edited in place at cycle close, superseded text moves verbatim to the sidecar, and a supersession marker in a live file is itself an audit finding. Every contract file was verified against its old text by an independent zero-loss pass (statement-by-statement) plus a code-accuracy spot check; C-ids and contract titles are unchanged, so existing C-id citations in code, tests, and issues resolve as before.
1.6 KiB
C1 — Determinism and disjoint parallelism: history
FROZEN HISTORICAL RECORD. Each block below was true as of its cycle/date stamp and may be superseded; this file is NOT current truth and NOT a grounding surface. Current contract: c01-determinism.md.
Realization note (2026-07-16, #277). Cross-sim parallelism now also spans
campaign cells: the executor flattens the cell matrix, groups it by instrument
ordinal, and walks sequential chunks of K instrument groups
(--parallel-instruments, default 4 — a structural bound on distinct resident
instruments, the RAM lever for the external data-server's per-reference file
retention); within a chunk, cells run concurrently on the process-global rayon
pool shared with the member/window fan-out. Results are collected into
document-order slots, so outputs stay byte-identical across worker counts and
bounds. Two deliberate scheduling-dependent carve-outs, both outside this
contract's per-run bit-identity (which governs successful runs): on the
run-fatal path (non-containable faults, e.g. a dead registry store) the
propagated fault is the lowest document-order fault among the cells that
completed before the abort flag latched, and the set of per-cell family lines
already written by then is scheduling-dependent — inert, because no
campaign-run record is written on that path and store reads are name-keyed,
never line-ordered. Duplicate campaign instruments are refused at both the
validate tier and the executor's preflight: the per-cell family name embeds
the raw instrument string, so uniqueness is what keeps concurrent appends from
racing one name's run-index assignment.