plan(v0.62): scope the release — "Reach is part of correctness" (7 artifacts) - #1134
Merged
Merged
Conversation
…tifacts) v0.61 was 15 of 15 artifacts fixing CHECKERS. That was the right scope for one release and the wrong scope for two. CLAUDE.md's North Star extension says it directly — "A proof about input we refuse is worth nothing" — and the measured acceptance on 805 real modules is ARM 66 %, RV32 14 %, AArch64 1.6 %. So v0.62 turns outward. THE OPENER IS NOT A DEFECT WE FOUND. #1131: a real integrator is running a 5-stage `--relocatable` cascade on an emulated RT1176, the whole documented remedy chain lowers cleanly, and they stopped at the one part of the contract we never wrote down — R9 is specified, the linear-memory base is not. They asked rather than reverse-engineering it from disassembly. A user blocked on our docs outranks anything on this tracker that we found ourselves. MUST: RQ-62-EMBEDDER #1131 the --relocatable embedder layout contract, DERIVED from the emitter (a hand-written contract that drifts is the class #1080 cost 98 files) RQ-62-TABLEDANGLE #1102 the ONLY v0.61 residual that is a correctness hole: #1102's guard matches direct-call INDEX LABELS, so a declined function reachable solely through a funcref table keeps the pre-fix unlinkable behaviour RQ-62-REACH #242 VCR-REACH-002 scoped for the first time; increment 1 is RE-MEASUREMENT, not implementation — the census denominator moved under us when RQ-60-A64IMPORT landed, and picking work off a stale acceptance number is the error this release avoids SHOULD: RQ-62-MVLOWER #1093 param-block types decline everywhere but are still not LOWERED. Tractable now only because #1097's oracle exists as the ACCEPTANCE TEST — the guard may be relaxed only for a shape whose lowering makes the four silent-wrong vectors CORRECT RQ-62-CFOBLIG #1057 Block/End correspondence — where all 180 of gale's remaining instances live (End alone is 64) RQ-62-CLAIMCHECK #1062 the last required context with no system dependency still on the GitHub-hosted quota RQ-62-ROADMAPGATE #1133 NEW, found while consolidating this scope #1133 deserves naming: `status_evidence_check` globs `artifacts/release-v*` only, so the VCR roadmap's 39 artifacts are outside every status/evidence rule — and two of them (VCR-WCET-001, VCR-WCET-002) have NO STATUS KEY AT ALL. Same class as v0.61's entire scope, one directory over: the gate exists, is required, is green, and its SCOPE does not cover the file whose purpose is recording programme status. Every carried-forward item is a residual the v0.61 artifact NAMED, promoted from prose inside a closed artifact to a tracked requirement — because a residual recorded only in a closed artifact's `verified-by` is invisible to release planning. #1132 (org-wide feedback request) is deliberately NOT an artifact: it is addressed to the maintainer and answering it is the deliverable. ARTIFACT_FLOOR 509 -> 516, re-derived with `rivet list`, not computed. status_evidence 0 failures, claim_check 56/56. Refs #242, #1057, #1062, #1093, #1102, #1131, #1133 Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01YJK5LZZEkV5smCY1jKn18L
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
…val needs a DERIVABLE condition (7 -> 8) The maintainer granted STANDING approval to cut and tag every release, replacing per-release approval, with one condition: "yes it stands for all releases IF they run through the feature loop." THE CONDITION IS THE POINT AND IT IS CURRENTLY UNCHECKABLE. Today the only evidence a release ran the loop is that whoever cut it says so. A standing authorization gated on a self-assessment is exactly the shape this project has spent two releases removing — #1085 (evidence that could not fail), #1091 (a gate that printed instead of asserting), #1113 (a floor blind to half its oracle), #1119 (a rule blind to a delivery-commit shape), #1133 (a gate whose scope excluded the file recording programme status). Adding a sixth instance at the exact point where human approval was just removed would be the worst place in the repo to put one. Nothing new needs inventing: every loop step already leaves a machine-readable trace (rivet artifacts, oracle wiring, mcdc pins, the tag's Signing E2E conclusion, the pre-tag cold review, pin sweep + zero-diff + crate verification). The join is what is missing. STEPS 1-2 ARE THE HARD PART. spar/WIT have been recorded N/A every release and were NEVER FILED until #1136 — filed now, applying #912's own rule to itself. The precedent matters: witness MC/DC was N/A four releases running, was filed as #912, and #978 made it REAL, producing the gate that later found #1100. So the conformance check must treat an N/A as a FILED, REFERENCED decision, never as a blank. Red-first is cheap and is required: v0.61.0 conformed on steps 3-8 and is the GREEN corpus; v0.57 and earlier predate the witness gate entirely and are the RED corpus. A check that passes on every release ever cut is not checking anything. ARTIFACT_FLOOR 516 -> 517, re-derived with `rivet list`, not computed. Refs #1136, #912 Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01YJK5LZZEkV5smCY1jKn18L
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
v0.62 — "Reach is part of correctness"
v0.61 was 15 of 15 artifacts fixing checkers. That was the right scope for
one release and the wrong scope for two. CLAUDE.md's North Star extension says
it directly — "A proof about input we refuse is worth nothing" — and the
measured acceptance on 805 real modules is ARM 66%, RV32 14%, AArch64 1.6%.
So v0.62 turns outward.
The opener is not a defect we found
#1131. A real integrator is running a 5-stage
--relocatablecascade on anemulated RT1176. The whole documented remedy chain lowers cleanly, exit 0. They
stopped at the one part of the contract we never wrote down — R9 is specified,
the linear-memory base is not — and they asked rather than reverse-engineering
it from disassembly.
A user blocked on our docs outranks anything on this tracker that we found
ourselves.
Scope
RQ-62-EMBEDDER--relocatablelayout contract, derived from the emitter — a hand-written contract that drifts is the class #1080 cost 98 filesRQ-62-TABLEDANGLERQ-62-REACHRQ-62-MVLOWERRQ-62-CFOBLIGRQ-62-CLAIMCHECKRQ-62-ROADMAPGATETwo of these deserve calling out
RQ-62-TABLEDANGLEis a live correctness hole, not process debt. #1102'sguard matches direct-call index labels (
func_{idx}/synth_func_{idx}),which is complete for direct calls. A funcref table entry naming a declined
function has no direct call site, so no relocation carries its index label — the
driver-level gate sees nothing and the pre-fix unlinkable behaviour survives on
exactly that path. #1102's own history is that the same class was fixed on
aarch64 and left live on RV32 for a release because nobody checked the others.
#1133, found while writing this scope.
status_evidence_checkglobsartifacts/release-v*only, so the VCR roadmap's 39 artifacts are outsideevery status/evidence rule — and two (
VCR-WCET-001,VCR-WCET-002) have nostatuskey at all. Same class as v0.61's entire scope, one directory over:the gate exists, is required, is green, and its scope doesn't cover the file
whose purpose is recording programme status. Deliberately not a glob
widening — roadmap items carry
release: Noneby design, so the release-scopedruleset would produce false reds.
Residuals promoted, not left in prose
Every carried-forward item is a residual a v0.61 artifact named, moved from
prose inside a closed artifact to a tracked requirement. A residual recorded
only in a closed artifact's
verified-byis invisible to release planning.RQ-62-MVLOWERis tractable now only because #1097's oracle exists: it is theacceptance test, and the guard may be relaxed only for a shape whose lowering
makes the four silent-wrong vectors correct.
Not an artifact, on purpose
#1132 (org-wide feedback request) is addressed to the maintainer. Answering
it is the deliverable; a rivet artifact would be the wrong response.
Gates
ARTIFACT_FLOOR509 → 516, re-derived withrivet list, not computed.status_evidence0 failures ·claim_check56/56.Refs #242, #1057, #1062, #1093, #1102, #1131, #1133