Skip to content

plan(v0.62): scope the release — "Reach is part of correctness" (7 artifacts) - #1134

Merged
avrabe merged 2 commits into
mainfrom
plan/v062-scope
Sep 3, 2026
Merged

avrabe merged 2 commits into
mainfrom
plan/v062-scope

Conversation

@avrabe

@avrabe avrabe commented Sep 2, 2026

Copy link
Copy Markdown
Contributor

v0.62 — "Reach is part of correctness"

v0.61 was 15 of 15 artifacts fixing checkers. That was the right scope for
one release and the wrong scope for two. CLAUDE.md's North Star extension says
it directly — "A proof about input we refuse is worth nothing" — and the
measured acceptance on 805 real modules is ARM 66%, RV32 14%, AArch64 1.6%.
So v0.62 turns outward.

The opener is not a defect we found

#1131. A real integrator is running a 5-stage --relocatable cascade on an
emulated RT1176. The whole documented remedy chain lowers cleanly, exit 0. They
stopped at the one part of the contract we never wrote down — R9 is specified,
the linear-memory base is not — and they asked rather than reverse-engineering
it from disassembly.

A user blocked on our docs outranks anything on this tracker that we found
ourselves.

Scope

priority artifact issue
must RQ-62-EMBEDDER #1131 the --relocatable layout contract, derived from the emitter — a hand-written contract that drifts is the class #1080 cost 98 files
must RQ-62-TABLEDANGLE #1102 the only v0.61 residual that is a correctness hole
must RQ-62-REACH #242 VCR-REACH-002, scoped for the first time; increment 1 is re-measurement, not implementation
should RQ-62-MVLOWER #1093 param-block types decline everywhere but are still not lowered
should RQ-62-CFOBLIG #1057 Block/End correspondence — where all 180 of gale's remaining instances live
should RQ-62-CLAIMCHECK #1062 last required context with no system dependency still on the hosted quota
should RQ-62-ROADMAPGATE #1133 new, found while consolidating this scope

Two of these deserve calling out

RQ-62-TABLEDANGLE is a live correctness hole, not process debt. #1102's
guard matches direct-call index labels (func_{idx}/synth_func_{idx}),
which is complete for direct calls. A funcref table entry naming a declined
function has no direct call site, so no relocation carries its index label — the
driver-level gate sees nothing and the pre-fix unlinkable behaviour survives on
exactly that path. #1102's own history is that the same class was fixed on
aarch64 and left live on RV32 for a release because nobody checked the others.

#1133, found while writing this scope. status_evidence_check globs
artifacts/release-v* only, so the VCR roadmap's 39 artifacts are outside
every status/evidence rule — and two (VCR-WCET-001, VCR-WCET-002) have no
status key at all
. Same class as v0.61's entire scope, one directory over:
the gate exists, is required, is green, and its scope doesn't cover the file
whose purpose is recording programme status. Deliberately not a glob
widening — roadmap items carry release: None by design, so the release-scoped
ruleset would produce false reds.

Residuals promoted, not left in prose

Every carried-forward item is a residual a v0.61 artifact named, moved from
prose inside a closed artifact to a tracked requirement. A residual recorded
only in a closed artifact's verified-by is invisible to release planning.

RQ-62-MVLOWER is tractable now only because #1097's oracle exists: it is the
acceptance test, and the guard may be relaxed only for a shape whose lowering
makes the four silent-wrong vectors correct.

Not an artifact, on purpose

#1132 (org-wide feedback request) is addressed to the maintainer. Answering
it is the deliverable; a rivet artifact would be the wrong response.

Gates

ARTIFACT_FLOOR 509 → 516, re-derived with rivet list, not computed.
status_evidence 0 failures · claim_check 56/56.

Refs #242, #1057, #1062, #1093, #1102, #1131, #1133

…tifacts)

v0.61 was 15 of 15 artifacts fixing CHECKERS. That was the right scope for one
release and the wrong scope for two. CLAUDE.md's North Star extension says it
directly — "A proof about input we refuse is worth nothing" — and the measured
acceptance on 805 real modules is ARM 66 %, RV32 14 %, AArch64 1.6 %. So v0.62
turns outward.

THE OPENER IS NOT A DEFECT WE FOUND. #1131: a real integrator is running a
5-stage `--relocatable` cascade on an emulated RT1176, the whole documented
remedy chain lowers cleanly, and they stopped at the one part of the contract we
never wrote down — R9 is specified, the linear-memory base is not. They asked
rather than reverse-engineering it from disassembly. A user blocked on our docs
outranks anything on this tracker that we found ourselves.

MUST:
  RQ-62-EMBEDDER     #1131  the --relocatable embedder layout contract, DERIVED
                            from the emitter (a hand-written contract that
                            drifts is the class #1080 cost 98 files)
  RQ-62-TABLEDANGLE  #1102  the ONLY v0.61 residual that is a correctness hole:
                            #1102's guard matches direct-call INDEX LABELS, so a
                            declined function reachable solely through a funcref
                            table keeps the pre-fix unlinkable behaviour
  RQ-62-REACH         #242  VCR-REACH-002 scoped for the first time; increment 1
                            is RE-MEASUREMENT, not implementation — the census
                            denominator moved under us when RQ-60-A64IMPORT
                            landed, and picking work off a stale acceptance
                            number is the error this release avoids

SHOULD:
  RQ-62-MVLOWER      #1093  param-block types decline everywhere but are still
                            not LOWERED. Tractable now only because #1097's
                            oracle exists as the ACCEPTANCE TEST — the guard may
                            be relaxed only for a shape whose lowering makes the
                            four silent-wrong vectors CORRECT
  RQ-62-CFOBLIG      #1057  Block/End correspondence — where all 180 of gale's
                            remaining instances live (End alone is 64)
  RQ-62-CLAIMCHECK   #1062  the last required context with no system dependency
                            still on the GitHub-hosted quota
  RQ-62-ROADMAPGATE  #1133  NEW, found while consolidating this scope

#1133 deserves naming: `status_evidence_check` globs `artifacts/release-v*`
only, so the VCR roadmap's 39 artifacts are outside every status/evidence rule —
and two of them (VCR-WCET-001, VCR-WCET-002) have NO STATUS KEY AT ALL. Same
class as v0.61's entire scope, one directory over: the gate exists, is required,
is green, and its SCOPE does not cover the file whose purpose is recording
programme status.

Every carried-forward item is a residual the v0.61 artifact NAMED, promoted from
prose inside a closed artifact to a tracked requirement — because a residual
recorded only in a closed artifact's `verified-by` is invisible to release
planning.

#1132 (org-wide feedback request) is deliberately NOT an artifact: it is
addressed to the maintainer and answering it is the deliverable.

ARTIFACT_FLOOR 509 -> 516, re-derived with `rivet list`, not computed.
status_evidence 0 failures, claim_check 56/56.

Refs #242, #1057, #1062, #1093, #1102, #1131, #1133

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01YJK5LZZEkV5smCY1jKn18L
@codecov

codecov Bot commented Sep 2, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

…val needs a DERIVABLE condition (7 -> 8)

The maintainer granted STANDING approval to cut and tag every release, replacing
per-release approval, with one condition: "yes it stands for all releases IF
they run through the feature loop."

THE CONDITION IS THE POINT AND IT IS CURRENTLY UNCHECKABLE. Today the only
evidence a release ran the loop is that whoever cut it says so. A standing
authorization gated on a self-assessment is exactly the shape this project has
spent two releases removing — #1085 (evidence that could not fail), #1091 (a
gate that printed instead of asserting), #1113 (a floor blind to half its
oracle), #1119 (a rule blind to a delivery-commit shape), #1133 (a gate whose
scope excluded the file recording programme status). Adding a sixth instance at
the exact point where human approval was just removed would be the worst place
in the repo to put one.

Nothing new needs inventing: every loop step already leaves a machine-readable
trace (rivet artifacts, oracle wiring, mcdc pins, the tag's Signing E2E
conclusion, the pre-tag cold review, pin sweep + zero-diff + crate
verification). The join is what is missing.

STEPS 1-2 ARE THE HARD PART. spar/WIT have been recorded N/A every release and
were NEVER FILED until #1136 — filed now, applying #912's own rule to itself.
The precedent matters: witness MC/DC was N/A four releases running, was filed as
#912, and #978 made it REAL, producing the gate that later found #1100. So the
conformance check must treat an N/A as a FILED, REFERENCED decision, never as a
blank.

Red-first is cheap and is required: v0.61.0 conformed on steps 3-8 and is the
GREEN corpus; v0.57 and earlier predate the witness gate entirely and are the
RED corpus. A check that passes on every release ever cut is not checking
anything.

ARTIFACT_FLOOR 516 -> 517, re-derived with `rivet list`, not computed.

Refs #1136, #912

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01YJK5LZZEkV5smCY1jKn18L
@avrabe
avrabe merged commit 5088918 into main Sep 3, 2026
59 of 60 checks passed
@avrabe
avrabe deleted the plan/v062-scope branch September 3, 2026 04:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant