Skip to content

Commit db7bdf1

Browse files
AdaWorldAPIclaude
andauthored
Consumer example: World/Trades — the zero-object fluent domain API (W5a) (#11)
* Core vertical slice: docs/abi.md contract, native/lgj-abi, Java facade Ships the fully verified core of the Panama x ndarray::simd x Valhalla vertical slice (Phases A-E of the mission plan): - docs/abi.md: the normative Rust<->Java ABI contract, written before either side was implemented so both could be checked against one frozen doc instead of each other. - Five new ndarray::simd primitives (eq_u32_to_mask, gt_i32_to_mask, mask_and/mask_or(_assign), masked_sum_i32), added under ndarray's own W1a consumer contract. - native/lgj-abi: the Rust ABI crate. Generation-checked handle registry, generic SoA fixture, bulk kernels routed exclusively through ndarray::simd, 14-symbol extern "C" surface. 72/72 tests green, clippy/fmt clean, and the registry's core safety check was disable-verified (short-circuited, confirmed exactly the two guarding tests go red, restored). - java/: the Panama membrane (internal/ffm, never exposed publicly) and the public semantic facade (NativePattern/View/Predicate/ Pattern/Mask). 132/132 checks green across 8 suites, including a reflection-enforced ApiSurfaceTest that mechanically proves zero FFM types ever reach a public signature, and a LazinessTest that empirically proves the thesis: building a chain costs zero crossings, evaluating it costs exactly one, independent of row count up to 1,000,000. - .claude/: a 6-agent ensemble, 6 knowledge docs, and a full board (LATEST_STATE/STATUS_BOARD/AGENT_LOG/EPIPHANIES/TECH_DEBT/ISSUES/ PR_ARC_INVENTORY/INTEGRATION_PLANS/CODEX_REVIEW_CHECKLIST), all scoped to this repo's actual seams. A mechanical audit (D-LGJ-AUDIT) found and fixed the one real rule violation before this commit: kernels.rs::simd_popcount was calling the internal ndarray::hpc::bitwise path instead of the sanctioned ndarray::simd re-export. Deliberately NOT included: the Valhalla lab (valhalla-lab/) and the Vector API benchmark harness (bench/) — still in flight, tracked as open STATUS_BOARD.md rows, to land in a follow-up PR once reviewed with the same rigor as this slice. Generated by [Claude Code](https://claude.ai/code) * Valhalla lab: three-truths method, causal isolation, 3 real reproducers Completes D-LGJ-F. One experiment source (src/shared/), compiled twice against real JDKs -- stable JDK 26 GA (record) and the official JEP 401 early-access binary (value record) -- via a self-verifying run.sh that mechanically diffs the two Vocab.java files modulo the 'value' keyword before trusting the A/B is honest. Experiments: IdentityExperiment (semantic truth -- is identity actually unobservable), FootprintExperiment (real per-object/array/field bytes via allocation-delta + JOL where available), FfmAddressingExperiment (is the wrapper free where it touches native memory), ThesisExperiment (the mandatory headline: 65,536 rows as one native lane vs hydrated Java objects, on both platforms). Causal isolation via three additional run.sh passes: escape analysis off, and UseArrayFlattening/UseFieldFlattening toggled independently -- isolates which flag actually drives the measured difference rather than inferring it. Three real Valhalla limitations reproduced and filed under reproducers/, none of which changed the production API: - R1: @NullRestricted field on an identity class is a VerifyError (javac's fault -- no source form expresses the required strict-field init order relative to super()) - R2: array flattening has a hard 8-byte payload cliff, confirmed via -XX:+PrintFlatArrayLayout. LaneId/Ordinal/MaskId (<=8B) flatten; RowRange/Row (16B) do not. This turns "Valhalla helps descriptors, not entities" from a hand-wave into a measured VM cutoff -- and RowRange landing on the wrong side is flagged as the one place the expectation was too optimistic. - R3: the densest null-restricted array form is jdk.internal-only and generics erase flattening entirely; Foo! null-restricted type syntax confirmed not to parse, matching the earlier archaeology finding. One real defect found and fixed before landing: IdentityExperiment and the stable Platform called Class::isValue() directly on four vocabulary types with a comment incorrectly claiming it was "final API on JDK 26" -- it does not exist there at all, confirmed by a real javac failure. Fixed by routing every query through Platform.isValueClass(Class<?>), answered honestly per platform. Generated by [Claude Code](https://claude.ai/code) * Vector API bench: real JMH, cross-checked; the crossing does not always win Completes D-LGJ-G, the mission's mandated "where does execution belong" comparison -- measured, not assumed to favor the Rust crossing. Real JMH 1.37 (fork+warmup+compiler-blackholes confirmed in the log, not a hand-rolled loop -- that lives in valhalla-lab and is labelled as such there). Four components, cost kept strictly separate per the mission brief: A_DowncallOverhead (bare crossing, no work), B_SegmentAccess (raw native-memory read throughput), C_ExecutionBoundary (native fused plan vs Java Vector API vs Java scalar, swept 64 to 4,194,304 rows), E_FusionAndPlanning (fused vs unfused vs the scalar reference kernel vs plan-construction-only, swept 1-8 predicates). 50/50 rows, 0 failures. Data.crossCheck() runs in @setup and throws if the three kernels disagree on count or sum, so a faster-but-wrong Vector kernel could not have won the comparison undetected. The headline complicates the thesis honestly: for a single predicate over one native lane, the Java Vector API -- reading the SAME native MemorySegment zero-copy via IntVector.fromMemorySegment, no byte[], no bounce buffer -- beats the native crossing at EVERY row count tested, 56.4x at small sizes down to 1.3-1.4x at 4M rows. A second crossover is also real: native beats a plain Java scalar loop only past roughly 4,096-16,384 rows. Component E shows why this doesn't overturn the project's premise: SIMD-vs-scalar is the largest lever measured anywhere in this suite (10.8x-31.1x, growing with predicate count), and fused/unfused land within this harness's own ~10% noise floor of each other at 65,536 rows -- the fused plan's real value is the structural one-crossing guarantee (already proven by LazinessTest), not a large measured time saving at this scale. Verdict: the crossing is worth paying for composed, multi-predicate work, not for reading one predicate off one lane, where Java on the same memory is simply faster. RESULTS.md was hand-written from the raw CSV, then independently cross-checked against summarise.sh -- a script the same PR ships that mechanically regenerates every table from results/jmh-results.csv, so a re-run's numbers can never silently drift from a hand-transcribed table. Both productions agreed to 3 decimal places on every cell checked. Generated by [Claude Code](https://claude.ai/code) * Phase I synthesis docs + fusion-sweep 256-row re-run + board hygiene Four synthesis docs close D-LGJ-I: architecture.md (the four layers and what each is provably responsible for), panama.md (manifest-over-header, belt-and-braces ownership, restricted-method discipline), valhalla-lab.md (three-truths synthesis, the 8-byte flattening cliff, zero API adoption), execution-boundary.md (the measured crossover picture + three structural hot-path facts, each checked rather than assumed). The fusion sweep was re-run with a 256-row arm after the first pass's 'fusion does nothing' finding proved true only at 65,536 rows: at 256 rows x 8 predicates unfused/fused reaches 2.99x. RESULTS.md is rewritten from jmh-results-merged.csv; TABLES.md is mechanically generated from the same file so the two cannot drift. MultiLaneColumn (ndarray::simd_soa) evaluated for the fixture kernels and declined on two concrete API mismatches (64-byte-multiple constraint, no u32 lane); earmarked for the future 512-byte row-store slice where it fits by construction. Operator layout reference recorded on the board. PR_ARC_INVENTORY backfilled for merged PRs 1-3; the lapse is owned in the file itself. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017Pud4qpxFHwqyqDjSabQbs * Board: PR #4 arc entry (post-merge) Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017Pud4qpxFHwqyqDjSabQbs * SoA row store: 512B rows, 32 facet lanes, ABI minor 2 (W1+W2) The lance-graph-shaped substrate, wired end to end. The flat three-lane fixture was always scaffolding (docs/abi.md 10, architecture.md said so from PR #1); this is the layout the stack actually converges on: 64K x 512-byte rows, 32 facet lanes of 16 bytes = 4-byte LE classid + 12-byte payload, the V3 content-blind facet. Rust (native/lgj-abi): - rowstore.rs: one Arc<[u8]>, two readings (row-major chunks and strided facet columns), zero copies, normative SplitMix64 generator. - LGJ_RESOURCE_ROWSTORE + lgj_rowstore_open; facet lanes described through the UNCHANGED LgjLaneDesc (stride_bytes carried this since minor 1); lgj_op_eq_classid produces ordinary masks that compose with the existing algebra; lgj_row_facet_match writes per-row 32-bit facet sets into a caller-owned buffer via MultiLaneColumn (Arc refcount bump, no copy). - byte_len tightened to the exact covered span (len-1)*stride + elem_bytes: a full-stride final window would let Java bound a segment past the allocation's end on a facet lane. - ABI minor 1 -> 2; docs/abi.md gains 11 and its symbol count is corrected (the 14 was drift; the list already enumerated 15, and the real number is now 18 per nm -D). Gates: cargo test 84/84, clippy -D warnings clean, fmt clean, release build exports 18/18 symbols. Both new kernels are parity-checked against independent scalar references over 10 row counts x 2 seeds x 4 facets x 4 needles, then cross-checked a third way against RowStore::classid_at; a two-sided falsifier proves payload bytes never satisfy a classid match and that a real match does fire. Docs: .claude/plans/lgj-soa-substrate-v1.md (W1-W5 waves) + one plan per consumer example (world-trades / bricks-analytics / graph-traversal), .claude/knowledge/soa-row-store-layout.md, and the board triple ledger. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017Pud4qpxFHwqyqDjSabQbs * Board: PR #5 arc entry (post-merge) Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017Pud4qpxFHwqyqDjSabQbs * Knowledge: assess the archived layout-bridge discussion; name W6 The operator's pre-build ChatGPT discussion is assessed once, in .claude/knowledge/prior-art-and-the-layout-bridge-claim.md, so it is never re-mined or cited naively. Verdict: it converged independently on the architecture this repo then built and measured. Kept: the callability-vs-shared-executable-layout positioning, the schema-key-as- join-point extractable (now the named W6 consideration: an explicit schema/classid field on the descriptors when ClassView lands), and the baseline-dependent claims discipline for W5 comparisons. Pinned: its page-descriptor sketch has no liveness story (the registry's whole job), its native-always-wins assumption is measured false (Component C), and its ndarray paragraph describes upstream crates.io ndarray, not the AdaWorldAPI fork whose ndarray::simd polyfill this stack mandates. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017Pud4qpxFHwqyqDjSabQbs * Plans: OGAR Machine (exploratory) + lance-graph-hydrate dependency note Captures the operator's second archived context as .claude/plans/ogar-machine-v1.md — a genuinely new workload for the shipped substrate, not convergent confirmation: one row = one machine STATE, control flow as population masks over 64K execution contexts, Ghidra P-code as the normalized guest ISA (repo attached and cloned), differential migration testing (legacy XOR replacement across 65,536 worlds) as the killer demo, Lance as the time machine. Strong claim vs weak claim separated per the discussion's own discipline; gated on W3 + one W5 example + Ghidra archaeology + a tiny falsifiable probe (P-M1). Also records lance-graph #957 (merged: lance-graph-hydrate, the generic SoA->S3->volume->Lance hydration crate minted for consumers to inherit) and #958 (its open hardening fast-follow) in the substrate plan: when this repo's persistence slice arrives, hydration is inherited from lance-graph-hydrate, never re-derived here. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017Pud4qpxFHwqyqDjSabQbs * Board: PR #6 arc entry (post-merge) Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017Pud4qpxFHwqyqDjSabQbs * Waves calcified: dispatch maps for every plan; Ghidra plan from real archaeology Operator ruling: calcify, don't execute. .claude/waves/ holds one dispatchable map per plan — README with the standing rules and the verbatim worker preamble, substrate W3+W4 (the only READY wave), three consumer waves stamped DO-NOT-DISPATCH, Ghidra G1+G2, and OGAR-Machine P-M1 (BLOCKED behind a 4-condition gate including an explicit operator go). Each map carries disjoint worker scopes, orchestrator-only steps, exact gate commands, disable-runs, and STOP triggers. ghidra-integration-v1.md is written from archaeology against the real clone, not the sketch: 74 P-code opcodes (CPUI_MAX=75), 12.2 DEV / Java 25+, analyzeHeadless entry, and Ghidra's own PcodeEmulator as the reference-implementation parity oracle (the tesseract-rs method). The ogar-machine plan is cross-updated to cite it. Mapping-time catches that would have burned a dispatch: the graph consumer needs a deliberate edge-bearing generator arm (today's payload is PRNG noise) - a substrate change, flagged in the wave; the hop has a real D1a/D1b design fork with ruling guidance recorded. Muscle memory pinned as E-LGJ-CALCIFY-THEN-DISPATCH-1: the eight earned-this-session rules and the plan->wave->shelf->dispatch rhythm. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017Pud4qpxFHwqyqDjSabQbs * Board: PR #7 arc entry (post-merge) Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017Pud4qpxFHwqyqDjSabQbs * Plan: lance-graph #958 merged (was open at last check) Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017Pud4qpxFHwqyqDjSabQbs * Java RowStore facade: W3 shipped (185/185, one bug found+fixed) First real dispatch of the calcified wave system (wave-substrate-w3-w4.md Dispatch 1) — 3 Sonnet workers on disjoint scopes, Opus orchestrator integration and central gating, per the standing rules in .claude/waves/README.md. New public surface: RowStore (open/rowCount/isOpen/maskOfFacetClass/ facetMatches/close), FacetMatchView (rowCount/matchesOf/cardinality), FacetId (0..31-checked record) -- zero java.lang.foreign types in any public signature, ApiSurfaceTest passed unmodified. Mask.source() retyped NativePattern -> NativeResource (new minimal interface) so a mask parents onto either a pattern or a row store with the existing algebra unchanged; verified zero call-site breakage before the retype. One real bug caught by the test suite itself: FacetMatchView.rowCount() was missing the closed-store guard its sibling accessors both had -- found by RowStoreLifetimeTest on the first real run, fixed, re-verified. Gate: javac -Xlint:all clean (7 pre-existing [restricted] warnings, 0 new); AllTests 132 -> 185 (+53 checks: 29 parity + 24 lifetime). Both mandated disable-runs ran red-then-green with the exact expected blast radius: (1) Abi.requireMinor inflated by 1 -> exactly the two RowStore suites failed, 8 others stayed green; (2) the generator's a/b draw order swapped -> exactly RowStoreParityTest broke (17/29), the generator-independent RowStoreLifetimeTest stayed green. Board: STATUS_BOARD D-LGJ-W3 DONE, LATEST_STATE, and E-LGJ-WAVE-DISPATCH-VALIDATED-1 -- the wave system's first real dispatch, including an orchestrator-side false alarm (wrong env var name guessed instead of read from source) recorded so it isn't repeated. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017Pud4qpxFHwqyqDjSabQbs * Board: PR #8 arc entry (post-merge) Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017Pud4qpxFHwqyqDjSabQbs * Plan: r2sleigh recorded as third lift path + decompiler candidate Operator-flagged: AdaWorldAPI/r2sleigh (read-only clone verified, HEAD 60942f6) is a Rust workspace lifting Ghidra .sla specs to P-code via libsla, with typed IR, SSA, Z3 symbolic execution, and a P-code-to-C decompiler. The honest FFI fact is pinned: libsla-sys means the SLEIGH runtime underneath is Ghidra's C++ via FFI, not pure Rust -- acceptable on the same lift-time-only footing as running Ghidra itself. G1 gains candidate C (r2sleigh-cli lift, no JVM in the loop, and a STRONGER falsifier: cross-implementation P-code agreement between two independent consumers of one .sla spec); r2dec is named as the engine candidate for the semantic-shim direction; r2sym joins SymbolicSummaryZ3 as branch-population prior art. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017Pud4qpxFHwqyqDjSabQbs * Bench Component F: the boundary re-asked on the real row-store layout (W4) One Sonnet worker per wave-substrate-w3-w4.md Dispatch 2, orchestrator- run JMH (9/9 combos), the cross-check discipline intact: both Java facet-match kernels verified row-by-row against the native FacetMatchView in @setup at every row count before anything was timed. The finding: Component C's direction survives, its margin collapses. The Vector API wins the per-row 32-facet strided scan at every row count measured, but by 2.51x / 1.92x / 1.14x (4K / 65K / 1M rows) against C's 56x -- and at 512 MiB traversed all three arms converge on memory bandwidth. More work per byte narrows the boundary exactly as execution-boundary.md predicted; it now records that as measurement. Disclosed, not hidden: the native arm allocates its output segment per call where the Java arms reuse a @setup buffer; facetMatchesInto is the named follow-up if the small-row gap ever matters. Java kernels mirror the Rust chunk algorithm line-for-line (VectorMask.toLong() & 0x1111, same four-term fold) so the comparison is between implementations of ONE algorithm, not two algorithms. Mechanics: summarise.sh gains the F table (and its old 'E/F' section title -- a genuine collision with the new component -- is corrected to 'E'); TABLES.md regenerated from the merged CSV; RESULTS.md gains provenance-table update + full F section; RowStore gains a package-private handle() mirroring NativePattern's for the bench's split-package NativeAccess bridge; main suite re-verified 185/185 against the fresh minor-2 .so in the bench's expected location. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017Pud4qpxFHwqyqDjSabQbs * Board: PR #9 arc entry (post-merge) Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017Pud4qpxFHwqyqDjSabQbs * Parity: the third independent read path (ROW_LAYOUT segment reads) Closes the gap the W3 dispatch honestly flagged: the wave file specified a raw-lane segment-read parity arm that my worker brief dropped. Section added to RowStoreParityTest: every classid of a 1000-row store read DIRECTLY from the raw lane-0 segment, addressed through Layouts.ROW_LAYOUT's own byteOffset arithmetic (sequenceElement + groupElement, not hand-multiplied constants) -- no native kernel, no mask, no FacetMatchView on the path. Three independent routes now reach the same numbers: the native kernels, the pure-Java generator transcription, and the structured-layout segment read. This is also ROW_LAYOUT's first real consumer; before this it was defined and size-checked but read by nothing. Plus the raw lane's own description pinned (byteLength == n*512, contiguous flag set). AllTests 185 -> 188. Also records the operator handoff boundary in the ghidra plan: r2sleigh/ruff/R2IL integration arrives from another session -- this session does not build toward it, and lift-candidate C is frozen until the handoff lands. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017Pud4qpxFHwqyqDjSabQbs * Board: PR #10 arc entry (post-merge) Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017Pud4qpxFHwqyqDjSabQbs * Consumer example: World/Trades — the zero-object fluent domain API (W5a) The One-Billion-Objects poster made runnable, on the shelf-calcified wave map (wave-consumer-trades.md): two Sonnet workers, disjoint scopes, orchestrator-gated. consumers/trades/ is its own compile unit consuming com.adaworldapi.lancegraph exactly as a third-party developer would -- zero new membrane surface, zero core-API changes. Trade is a schema, not an entity: static U32Field VENUE / I32Field PRICE over the existing lanes, venue constants, and a private unconditionally-throwing constructor -- the test forces it accessible via reflection and proves construction STILL fails, plus zero public ctors and zero instance fields by reflection walk. The measured thesis: TradesAllocationTest's steady-state floor is 240 bytes per count() query, IDENTICAL at 64,000 and 1,000,000 rows -- allocation does not scale with rows (the assertion), with a 64 KiB absolute backstop. Laziness holds through the domain vocabulary: 0 crossings composing a 4-predicate Trade chain, exactly 1 at count(). Parity: the fluent chain equals a pure-Java transcribed-generator recomputation at both sizes, anti-vacuity guarded. Disable-run (green-red-green): VENUE pointed at the wrong lane -- the membrane's own LANE_KIND_MISMATCH rejected the misbinding outright, proving the schema binding is checked by the ABI, not trusted. Restored, both suites re-verified (12/12 + 3/3). QUANTITY is honestly absent (the flat fixture has two data lanes); its arrival is the ClassView/W6 slice, stated in Trade's Javadoc rather than faked. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017Pud4qpxFHwqyqDjSabQbs --------- Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
1 parent 4114c4e commit db7bdf1

6 files changed

Lines changed: 650 additions & 1 deletion

File tree

.claude/board/PR_ARC_INVENTORY.md

Lines changed: 19 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -8,6 +8,25 @@
88
> anti-pattern the imported board rules name. Backfilled below in one
99
> pass rather than left stale; PR #4 onward gets its entry at merge time.
1010
11+
## PR #10 — third parity read path + R2IL handoff boundary (merged 2026-08-17, squash `4114c4e`)
12+
13+
- **Added:** `RowStoreParityTest` section reading all 32,000 classids of a
14+
1000-row store DIRECTLY from the raw lane-0 segment through
15+
`Layouts.ROW_LAYOUT.byteOffset(...)` — proving the LAYOUT's carving
16+
against the generator, and giving `ROW_LAYOUT` its first real consumer
17+
(it had been defined and size-checked but read by nothing). AllTests
18+
185 → 188.
19+
- **Locked:** three independent routes to the same numbers (native
20+
kernels / generator transcription / structured segment read); the raw
21+
lane's own description pinned (n*512 bytes, contiguous). The R2IL
22+
handoff boundary recorded in `ghidra-integration-v1.md`: r2sleigh/ruff
23+
integration arrives from ANOTHER session — lift-candidate C and the
24+
r2dec direction are FROZEN here until it lands.
25+
- **Deferred:** everything the handoff covers, deliberately.
26+
- **Docs:** the plan's handoff section IS the record.
27+
- **Confidence:** High — closes a gap the W3 worker itself flagged rather
28+
than one discovered by accident. Bot reviewers at usage limits.
29+
1130
## PR #9 — bench Component F: the boundary on the real layout (merged 2026-08-17, squash `b28bd34`)
1231

1332
- **Added:** `F_RowStoreFacetScan` + `RowStoreData` + two `Kernels`

.claude/board/STATUS_BOARD.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -40,4 +40,4 @@ layout wired end to end. Doctrine: `E-LGJ-THE-MIDDLE-TIER-IS-DELETED-NOT-WRAPPED
4040
| D-LGJ-W2 | lgj-abi row store: `rowstore.rs`, `LGJ_RESOURCE_ROWSTORE`, `lgj_rowstore_open`, strided facet lanes through the unchanged `LgjLaneDesc`, `lgj_op_eq_classid`, `lgj_row_facet_match`, ABI minor 1→2, `docs/abi.md` §11 | **DONE 2026-08-17**`cargo test` **84/84**, clippy/fmt clean, release build exports **18/18** symbols (`nm -D`). Parity: both kernels vs independent scalar references over 10 row counts × 2 seeds × 4 facets × 4 needles, cross-checked a THIRD way against `RowStore::classid_at`. Two-sided payload-vs-classid falsifier. End-to-end membrane test covers describe → predicate → mask algebra → count → facet-match → lifecycle |
4141
| D-LGJ-W3 | Java `RowStore` facade: structured `MemoryLayout`, minor-≥2 gate, `FacetMatchView`, parity test transcribing the generator | **DONE 2026-08-17** — dispatched per `.claude/waves/wave-substrate-w3-w4.md` (3 Sonnet workers, disjoint scopes: FFM membrane extension / public facade / tests), orchestrator-integrated. `javac -Xlint:all` clean (same 7 pre-existing `[restricted]` warnings, zero new). `AllTests` **185/185** (was 132; +53 new checks: 29 parity + 24 lifetime). **One real bug caught by the suite and fixed**: `FacetMatchView.rowCount()` was missing the closed-store guard `matchesOf`/`cardinality` both had — a stale row count was readable after the owning store closed. Fixed, re-verified. Both mandated disable-runs ran red-then-green: (1) `Abi.requireMinor` inflated by 1 → exactly `RowStoreParityTest`+`RowStoreLifetimeTest` failed, all 8 other suites stayed green; (2) the pure-Java generator's a/b draw order swapped in `RowStoreParityTest` → exactly that suite broke (17/29), `RowStoreLifetimeTest` (generator-independent) stayed green — confirming the parity test is a real falsifier, not decorative. `Mask.source()` retyped `NativePattern → NativeResource` (new interface) so a `Mask` can parent onto either a `NativePattern` or a `RowStore` — zero call-site breakage (verified: no existing caller bound the narrower type) |
4242
| D-LGJ-W4 | Bench Component F: Vector API facet scan vs the crossing, on the REAL layout | **DONE 2026-08-17** — 1 Sonnet worker (F_RowStoreFacetScan + RowStoreData + Kernels facet-match arms, cross-check-in-@Setup discipline), orchestrator-run JMH: 9/9 combos, cross-checks green at every row count. **Finding: Component C's direction survives, its margin collapses** — Vector API wins the 32-facet strided scan at every row count but by 2.51×/1.92×/1.14× (4K/65K/1M rows) vs C's 56×; at 512 MiB traversed all three arms converge on memory bandwidth. Native arm's per-call allocation asymmetry disclosed in §F with a named follow-up (`facetMatchesInto`), not hidden. summarise.sh extended with the F table (and the old 'E/F' section retitled 'E' — a real naming collision); tables regenerated from the merged CSV |
43-
| D-LGJ-W5 | Three consumer examples (trades / bricks / graph) — one plan file each | Planned, gated on W3 |
43+
| D-LGJ-W5 | Three consumer examples (trades / bricks / graph) — one plan file each | **trades DONE 2026-08-17**`consumers/trades/` (own compile unit, core consumed as a third-party would): `Trade` (schema-not-entity: zero public ctors, zero instance fields, reflection-forced construction still throws), `World.open` → the existing lazy `View` under domain names, zero new membrane surface. TradesParityTest 12/12 (chain vs transcribed-generator recomputation at 1K+64K rows; 0 crossings composing / 1 at terminal THROUGH the domain vocabulary; reflection guard). TradesAllocationTest 3/3 — **the poster's number, measured: 240 bytes/query, IDENTICAL at 64K and 1M rows** (row-count independence is the thesis assertion; 64 KiB absolute backstop). Disable-run: VENUE pointed at the wrong lane → the membrane's own LANE_KIND_MISMATCH rejected it (the binding is checked, not trusted); restored green. bricks + graph still shelved |
Lines changed: 114 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,114 @@
1+
package com.adaworldapi.trades;
2+
3+
import com.adaworldapi.lancegraph.Field;
4+
import com.adaworldapi.lancegraph.I32Field;
5+
import com.adaworldapi.lancegraph.LaneId;
6+
import com.adaworldapi.lancegraph.Ordinal;
7+
import com.adaworldapi.lancegraph.Pattern;
8+
import com.adaworldapi.lancegraph.U32Field;
9+
10+
import java.util.List;
11+
12+
/**
13+
* The domain schema for the "One Billion Objects. Zero Objects." poster.
14+
*
15+
* <h2>This is a schema, not an entity</h2>
16+
*
17+
* <p>There is no such thing as a {@code Trade} instance, on purpose, and the constructor enforces
18+
* that rather than merely discouraging it (see below). The thesis this consumer example exists to
19+
* demonstrate: <strong>a million logical trades are one native lane set, not a million Java
20+
* objects.</strong> {@code Trade} is the vocabulary a fluent query is written against —
21+
* {@code Trade.VENUE.eq(Trade.XETRA)} — never a bag of fields a row gets copied into.
22+
*
23+
* <p>This class is written the same generated shape as {@link Pattern}: constants only, no logic,
24+
* names taken from the schema, lane indices stated once. It is a domain-named sibling of
25+
* {@code Pattern}, not a replacement for it — see the field notes below for exactly how the two
26+
* relate.
27+
*
28+
* <pre>{@code
29+
* try (var world = World.open(1_000_000, World.DEFAULT_SEED).source()) {
30+
* long xetraCount = world.view()
31+
* .where(Trade.VENUE.eq(Trade.XETRA))
32+
* .where(Trade.PRICE.gt(100))
33+
* .count();
34+
* }
35+
* }</pre>
36+
*
37+
* <h2>Field mapping — honest about what the fixture actually offers</h2>
38+
*
39+
* <p>The generated fixture ({@link com.adaworldapi.lancegraph.NativePattern}) has exactly three
40+
* lanes: an id, an unsigned 32-bit class tag ({@code 0..15}), and a signed 32-bit value
41+
* ({@code -150..361}). This schema binds the domain names a trading example would actually use
42+
* onto those same two data lanes — {@link #VENUE} is the class lane, {@link #PRICE} is the value
43+
* lane — rather than inventing a fourth lane the substrate does not have.
44+
*
45+
* <ul>
46+
* <li>{@link #VENUE} — {@link Pattern#CLASS}'s lane ({@code lane 1}), read as a trading venue
47+
* identifier. The fixture generates 16 distinct values ({@code 0..15}); {@link #XETRA} and
48+
* {@link #NASDAQ} are two of them, chosen so a demo predicate selects a measured, known
49+
* fraction of the rows rather than an arbitrary one.
50+
* <li>{@link #PRICE} — {@link Pattern#VALUE}'s lane ({@code lane 2}), read as a price tick. The
51+
* fixture's signed range ({@code -150..361}) does not correspond to a real price in any
52+
* currency; the demo's fiction is that these are cents-scale ticks, deliberately unrealistic
53+
* (a real price is never negative) so that a signed-comparison bug shows up rather than
54+
* agreeing with an unsigned one by accident — see {@link I32Field#gt(int)}.
55+
* </ul>
56+
*
57+
* <h2>QUANTITY is deliberately absent</h2>
58+
*
59+
* <p>The poster's domain fiction has a third field, quantity. It is <strong>not fabricated
60+
* here</strong>: the current flat three-lane fixture has no third numeric lane to bind it to, and
61+
* inventing one would mean this schema quietly grows its own private data rather than projecting
62+
* the real substrate. A quantity field arrives with the multi-lane {@code ClassView} facet slice
63+
* (32 facets, {@code W6} in the substrate plan) — at that point {@code Trade} gains a
64+
* {@code QUANTITY} constant bound to a real lane, and this class's shape does not otherwise change.
65+
* Until then, honesty about what exists beats completeness of the poster.
66+
*
67+
* <h2>Binds onto the flat pattern, not the row store</h2>
68+
*
69+
* <p>{@link World#open} opens a {@link com.adaworldapi.lancegraph.NativePattern} and returns its
70+
* {@link com.adaworldapi.lancegraph.View} — the flat, three-lane substrate {@link Pattern} already
71+
* uses, not the 32-facet {@code RowStore} the substrate wave shipped alongside it. That is where
72+
* the {@code gt}/{@code eq} lazy {@code View} machinery lives today. A facet-row binding (one
73+
* {@code Trade} row addressed as a lane slice of a {@code RowStore} facet, via a future
74+
* {@code ClassView}) is future work, not a gap in this example — see the {@code QUANTITY} note
75+
* above for the same boundary from the data side.
76+
*/
77+
public final class Trade {
78+
79+
/**
80+
* Never constructed. A {@code Trade} instance would be exactly the per-entity object this
81+
* example exists to prove unnecessary — a million of them is the anti-thesis, not a
82+
* convenience. Thrown even through reflection with {@code setAccessible(true)}, so the
83+
* guarantee is "impossible," not merely "discouraged by visibility."
84+
*/
85+
private Trade() {
86+
throw new AssertionError(
87+
"a Trade is never materialized — 1,000,000 logical trades are one native lane set,"
88+
+ " not 1,000,000 objects. There is no Trade instance to construct.");
89+
}
90+
91+
/** Venue identifier — {@link Pattern#CLASS}'s lane, read under a domain name. */
92+
public static final U32Field VENUE =
93+
new U32Field("venue", LaneId.of(1), Ordinal.of(0));
94+
95+
/** Price tick — {@link Pattern#VALUE}'s lane, read under a domain name. See the class doc for
96+
* why this is a signed, fictional cents-scale tick rather than a real currency amount. */
97+
public static final I32Field PRICE =
98+
new I32Field("price", LaneId.of(2), Ordinal.of(1));
99+
100+
/**
101+
* A venue id used throughout this example's predicates. {@code 7} is the fixture class the
102+
* rest of this repo's test corpus already exercises, so {@code Trade.VENUE.eq(Trade.XETRA)}
103+
* selects the same, already-measured ~6% (1-in-16) fraction of rows as {@code
104+
* Pattern.CLASS.eq(7)} does elsewhere.
105+
*/
106+
public static final int XETRA = 7;
107+
108+
/** A second, distinct venue id, for predicates that need two venues to compare or exclude. */
109+
public static final int NASDAQ = 3;
110+
111+
/** Every field this schema defines, in schema order. See the class doc for why there is no
112+
* {@code QUANTITY} entry yet. */
113+
public static final List<Field> FIELDS = List.of(VENUE, PRICE);
114+
}
Lines changed: 84 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,84 @@
1+
package com.adaworldapi.trades;
2+
3+
import com.adaworldapi.lancegraph.NativePattern;
4+
import com.adaworldapi.lancegraph.View;
5+
6+
/**
7+
* The entry point for the "One Billion Objects. Zero Objects." poster example.
8+
*
9+
* <h2>The claim</h2>
10+
*
11+
* <p>A million (or a billion, given enough rows in the fixture) logical trades never become that
12+
* many Java objects. {@link #open} opens one native lane set and hands back one lazy {@link View}
13+
* — the same fluent {@code where}/{@code count}/{@code sumOf} machinery {@link
14+
* com.adaworldapi.lancegraph.NativePattern} already provides, addressed through domain names
15+
* ({@link Trade#VENUE}, {@link Trade#PRICE}) instead of schema-generic ones ({@code
16+
* Pattern.CLASS}, {@code Pattern.VALUE}).
17+
*
18+
* <pre>{@code
19+
* try (var pattern = NativePattern.open(1_000_000, World.DEFAULT_SEED)) {
20+
* long n = World.viewOf(pattern)
21+
* .where(Trade.VENUE.eq(Trade.XETRA))
22+
* .where(Trade.PRICE.gt(100))
23+
* .count();
24+
* }
25+
* }</pre>
26+
*
27+
* <h2>Zero membrane growth — the iron rule</h2>
28+
*
29+
* <p>This class adds no ABI symbol, no native call, no query engine. It consumes {@code
30+
* com.adaworldapi.lancegraph} exactly as a third-party developer would: {@link NativePattern#open}
31+
* to obtain rows, {@link NativePattern#view()} to obtain the lazy description, {@link View#where}
32+
* to narrow it. If a future domain example needs a capability the public API does not expose, the
33+
* fix is a change to the substrate plan, never a shortcut taken here.
34+
*
35+
* <h2>Lifetime, stated honestly</h2>
36+
*
37+
* <p>A {@link View} does not own the rows it describes — its parent {@link NativePattern} does,
38+
* and the parent must outlive every view (and every terminal operation) derived from it, exactly
39+
* as {@link NativePattern}'s own class documentation specifies. {@link View#source()} is how a
40+
* caller gets back to the resource that must eventually be closed.
41+
*
42+
* <p>{@link #open(long, long)} returns a {@code View} rather than the {@code NativePattern}
43+
* itself, matching the wave's domain-facade shape ("returns the existing lazy {@code View}
44+
* machinery under domain names") — but that means the resource is reachable only through {@link
45+
* View#source()}, which is why every example in this class's Javadoc closes via {@code
46+
* World.open(...).source().close()} (or, more idiomatically, by holding the pattern in the
47+
* try-with-resources and deriving the view from it, as shown above). A caller who wants the
48+
* cleaner try-with-resources shape should open the {@link NativePattern} directly and call {@link
49+
* NativePattern#view()} — {@link #open} exists for the one-line poster snippet, not to hide the
50+
* resource.
51+
*/
52+
public final class World {
53+
54+
private World() {}
55+
56+
/** The default seed, re-exported from {@link NativePattern#DEFAULT_SEED} so a caller need not
57+
* import the core package just to name it. */
58+
public static final long DEFAULT_SEED = NativePattern.DEFAULT_SEED;
59+
60+
/**
61+
* Open {@code nRows} trades generated deterministically from {@link #DEFAULT_SEED} and return
62+
* their lazy view.
63+
*
64+
* <p>See the class documentation for the lifetime note: the returned view's underlying
65+
* resource is reachable, and must eventually be closed, via {@link View#source()}.
66+
*/
67+
public static View open(long nRows) {
68+
return open(nRows, DEFAULT_SEED);
69+
}
70+
71+
/**
72+
* Open {@code nRows} trades generated deterministically from {@code seed} and return their
73+
* lazy view.
74+
*
75+
* <p>Building and narrowing the returned view crosses the native membrane zero times, exactly
76+
* as {@link View}'s own documentation specifies — only a terminal operation ({@code count()},
77+
* {@code sumOf(...)}, {@code select()}) executes.
78+
*
79+
* @throws IllegalArgumentException if {@code nRows} is negative
80+
*/
81+
public static View open(long nRows, long seed) {
82+
return NativePattern.open(nRows, seed).view();
83+
}
84+
}

0 commit comments

Comments
 (0)