From 9d40d5b1f69b48babef81b0eb83cf936db2d49a8 Mon Sep 17 00:00:00 2001 From: Claude Date: Mon, 7 Sep 2026 03:49:05 +0000 Subject: [PATCH 1/2] docs(board): record #1211 in the arc inventory and LATEST_STATE MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The merged-PR row of the board-hygiene rule was outstanding for #1211, which added the V2/V3 mint guard tests and an EPIPHANIES entry — substantive content, so the termination clause that discharged #1210 does not apply here. Records both the refutation (no mint path silently truncates; both asserts are live in release) and the coverage gap it surfaced, so the "body.rs truncates" claim is not re-derived from the same call site. Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_012wrzeZAdwGYTCKoxamwQht --- .claude/board/LATEST_STATE.md | 29 ++++++++++++++++++++++ .claude/board/PR_ARC_INVENTORY.md | 40 +++++++++++++++++++++++++++++++ 2 files changed, 69 insertions(+) diff --git a/.claude/board/LATEST_STATE.md b/.claude/board/LATEST_STATE.md index adbcdaac4..0a27a0382 100644 --- a/.claude/board/LATEST_STATE.md +++ b/.claude/board/LATEST_STATE.md @@ -1,3 +1,32 @@ +## 2026-09-07 — #1211 MERGED (c3bb095b): the V1 guard was tested, the V3 guard that replaced it was not + +| PR | merge | what landed | +|---|---|---| +| **#1211** | `c3bb095b` | Three tests on `NodeGuid::mint_for`'s V2/V3 width guards (`mint_for_v3_panics_on_identity_overflow`, `mint_for_v3_panics_on_family_overflow`, `mint_for_v3_admits_the_widest_legal_tail`) + the `EPIPHANIES` entry `E-THE-V1-GUARD-WAS-TESTED-THE-V3-GUARD-THAT-REPLACED-IT-WAS-NOT-1`. Test-only; no behaviour change. | + +**The claim that started it does not survive.** A q2-side FMA-bake audit asserted +that `osint-bake/src/bin/body.rs:129` silently truncates identity — a `u32` row +into a `u16` slot, "guarded by nothing". Both mint paths assert in release: +`NodeGuid::new` on `identity <= 0x00FF_FFFF` (`canonical_node.rs:209`), and +`mint_for`'s V2/V3 arm on `identity <= 0xFFFF`, whose message already says +*"no silent truncation"* (`:386-389`). An over-wide identity panics naming its +own width. **There is no silent wrap on any mint path** — treat the +"body.rs truncates" claim as refuted, not open. + +**What was genuinely missing, and is now closed.** The V1 guards have carried +`should_panic` cover since they landed (`:2152-2162`); the V2/V3 guards that +supersede them had **none** — one grep hit each, the definition site. The +assertion crossed the V1→V3 rung; the proof did not. That is this repo's +falsifiability rule pointed at a guard: *a watchdog that cannot bark is the +defect one level up.* The third test is the rule's can-it-STAY-SILENT twin, so +the guard is shown to discriminate rather than to fire on everything. + +**Load-bearing detail for anyone touching these tests:** the +`#[cfg(feature = "guid-v2-tail")]` gate is not decoration. Ungated, all three +compile against `mint_for`'s V1 fallback arm and assert the wrong panic message. +The `--no-default-features` count (1304, vs 1321 default) is the evidence the +gate excludes them exactly where the V2/V3 arm does not exist. + ## 2026-09-06 — #1209 MERGED (f1336b66): the temporal architecture was measured against the wrong store | PR | merge | what landed | diff --git a/.claude/board/PR_ARC_INVENTORY.md b/.claude/board/PR_ARC_INVENTORY.md index 0bb3a0a66..8fb64053a 100644 --- a/.claude/board/PR_ARC_INVENTORY.md +++ b/.claude/board/PR_ARC_INVENTORY.md @@ -1,3 +1,43 @@ +## 2026-09-07 — lance-graph PR #1211 (merged `c3bb095b`, branch `claude/ndarray-simd-tract-o3jfrn`) — the V1 guard was tested; the V3 guard that replaced it was not + +- **Added:** three tests in `crates/lance-graph-contract/src/canonical_node.rs` + (`mint_for_v3_panics_on_identity_overflow`, + `mint_for_v3_panics_on_family_overflow`, + `mint_for_v3_admits_the_widest_legal_tail`) + the `EPIPHANIES` entry + `E-THE-V1-GUARD-WAS-TESTED-THE-V3-GUARD-THAT-REPLACED-IT-WAS-NOT-1`. + Test-only; no behaviour change. +- **Refutes the claim it started from.** A q2-side audit of the FMA bake + asserted that `osint-bake/src/bin/body.rs:129` **silently truncates** identity + — a `u32` row into a slot the V3 tail stores as `u16`, "guarded by nothing". + Reading this crate settles it against the claim: `NodeGuid::new` asserts + `identity <= 0x00FF_FFFF` (`canonical_node.rs:209`) and `mint_for`'s V2/V3 arm + asserts `identity <= 0xFFFF` with the message *"no silent truncation"* + (`:386-389`). Both are plain `assert!`, live in release. There is no silent + wrap on any mint path. +- **The real defect it surfaced indirectly.** The **V1** guards have had + `should_panic` cover since they landed (`:2152-2162`). The **V2/V3** guards + that SUPERSEDE them had none — grepping their panic strings returned exactly + one hit each, the definition site. The assertion was inherited across the + V1→V3 rung; the proof was not. +- **This is the repo's own falsifiability rule turned on the guard itself** — + *"a guard/channel needs a can-it-fire test; a watchdog that cannot bark is the + defect one level up."* Hence the third test: the rule's twin + can-it-STAY-SILENT half, proving the guard **discriminates** (`0xFFFF`/`0xFFFF` + mints and reads back intact) rather than firing on everything. +- **Locked:** the `#[cfg(feature = "guid-v2-tail")]` gate is load-bearing, not + decoration — ungated, the three tests compile against `mint_for`'s V1 fallback + arm and assert the wrong panic message. The `--no-default-features` delta + (1304 vs 1321) is what proves the gate excludes them exactly where the V2/V3 + arm does not exist. +- **Docs:** `EPIPHANIES.md` prepended; `SUPERSESSION-INDEX.md` regenerated AFTER + that write per the ordering rule (output byte-identical — the entry cites no + D-ids, which is the one case where an early regeneration would have been + indistinguishable from a correct one). +- **Confidence:** HIGH on the refutation and the coverage gap (both read + directly off the source, and the tests fail without the guards). The + provenance note — that this began as a q2 bake audit — is recorded so a future + session does not re-derive the same wrong claim from the same call site. + ## 2026-09-06 — lance-graph PR #1209 (merged `f1336b66`, branch `claude/ndarray-simd-tract-o3jfrn`) — the temporal architecture, measured against the wrong store first - **Added:** `crates/lance-graph/tests/canonical_witness_identity_probe.rs` (3 From 82e9732725786542bcd8012655f997c1881c88f0 Mon Sep 17 00:00:00 2001 From: Claude Date: Mon, 7 Sep 2026 04:18:21 +0000 Subject: [PATCH 2/2] docs: correct the documented failure mode of the guid-v2-tail gate The entries claimed the three mint_for tests, ungated, "compile against the V1 fallback arm and assert the wrong panic message". Measured by stripping the gate and running --no-default-features, neither half holds: the V1 guard is 24-bit and accepts the 0x0001_0000 input, so the two should_panic tests fail with "test did not panic as expected"; the third fails at compile time (E0599) because family_v2/identity_v2 are behind the same feature. Also corrects the identical claim in the canonical_node.rs doc-comment, merged in #1211 and not flagged, so the board and the code do not disagree about why the gate exists. Comment-only: 1321 default and 1304 --no-default-features unchanged. Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_012wrzeZAdwGYTCKoxamwQht --- .claude/board/LATEST_STATE.md | 20 ++++++++++++++++--- .claude/board/PR_ARC_INVENTORY.md | 19 ++++++++++++++---- .../src/canonical_node.rs | 8 +++++--- 3 files changed, 37 insertions(+), 10 deletions(-) diff --git a/.claude/board/LATEST_STATE.md b/.claude/board/LATEST_STATE.md index 0a27a0382..8b3aecba2 100644 --- a/.claude/board/LATEST_STATE.md +++ b/.claude/board/LATEST_STATE.md @@ -22,10 +22,24 @@ defect one level up.* The third test is the rule's can-it-STAY-SILENT twin, so the guard is shown to discriminate rather than to fire on everything. **Load-bearing detail for anyone touching these tests:** the -`#[cfg(feature = "guid-v2-tail")]` gate is not decoration. Ungated, all three -compile against `mint_for`'s V1 fallback arm and assert the wrong panic message. +`#[cfg(feature = "guid-v2-tail")]` gate is not decoration, but the reason is not +the one first recorded here. An earlier draft of this entry said all three +"compile against `mint_for`'s V1 fallback arm and assert the wrong panic +message". Both halves are wrong, and the corrected failure modes were MEASURED by +stripping the gate and running `--no-default-features`: + +- The two `should_panic` tests DO reach the V1 arm, but its guard is 24-bit + (`identity <= 0x00FF_FFFF`) and the overflow input is only `0x0001_0000` + (65 536) — comfortably legal. Nothing panics, so they fail with + **"test did not panic as expected"**, not a message mismatch. +- `mint_for_v3_admits_the_widest_legal_tail` never gets that far: it fails to + **compile** (`E0599: no method named family_v2`), because `family_v2` and + `identity_v2` live in a `#[cfg(feature = "guid-v2-tail")] impl` block. + The `--no-default-features` count (1304, vs 1321 default) is the evidence the -gate excludes them exactly where the V2/V3 arm does not exist. +gate excludes them exactly where the V2/V3 arm does not exist. Found by the codex +P2 review on #1212 — an unverified claim about a failure mode, in an entry whose +own subject is a guard that was never proven able to fire. ## 2026-09-06 — #1209 MERGED (f1336b66): the temporal architecture was measured against the wrong store diff --git a/.claude/board/PR_ARC_INVENTORY.md b/.claude/board/PR_ARC_INVENTORY.md index 8fb64053a..0b1746468 100644 --- a/.claude/board/PR_ARC_INVENTORY.md +++ b/.claude/board/PR_ARC_INVENTORY.md @@ -25,10 +25,21 @@ can-it-STAY-SILENT half, proving the guard **discriminates** (`0xFFFF`/`0xFFFF` mints and reads back intact) rather than firing on everything. - **Locked:** the `#[cfg(feature = "guid-v2-tail")]` gate is load-bearing, not - decoration — ungated, the three tests compile against `mint_for`'s V1 fallback - arm and assert the wrong panic message. The `--no-default-features` delta - (1304 vs 1321) is what proves the gate excludes them exactly where the V2/V3 - arm does not exist. + decoration. The failure modes below were MEASURED (gate stripped, + `--no-default-features` run), correcting this entry's first draft, which + claimed all three "compile against the V1 fallback arm and assert the wrong + panic message" — wrong twice over: + - the two `should_panic` tests reach the V1 arm, whose guard is 24-bit and so + ACCEPTS the `0x0001_0000` input: they fail with **"test did not panic as + expected"**, not a message mismatch; + - the widest-legal-tail test fails to **compile** (`E0599`), since + `family_v2`/`identity_v2` are themselves behind the same feature. + + The `--no-default-features` delta (1304 vs 1321) still proves the gate excludes + them exactly where the V2/V3 arm does not exist. Raised as codex P2 on #1212; + the identical claim in the `canonical_node.rs` doc-comment (merged in #1211, + not flagged) is corrected in the same commit — the board and the code cannot + disagree about why a gate exists. - **Docs:** `EPIPHANIES.md` prepended; `SUPERSESSION-INDEX.md` regenerated AFTER that write per the ordering rule (output byte-identical — the entry cites no D-ids, which is the one case where an early regeneration would have been diff --git a/crates/lance-graph-contract/src/canonical_node.rs b/crates/lance-graph-contract/src/canonical_node.rs index 425e6136e..75a5e0cc7 100644 --- a/crates/lance-graph-contract/src/canonical_node.rs +++ b/crates/lance-graph-contract/src/canonical_node.rs @@ -2163,9 +2163,11 @@ mod tests { /// The V1 24-bit guards above have had `should_panic` cover since they /// landed; the V2/V3 16-bit guards in `mint_for` had none, so nothing - /// proved they could fire. Feature-gated because the V2/V3 arm only exists - /// under `guid-v2-tail` — without it `mint_for` falls back to the V1 arm and - /// panics with the 24-bit message instead. + /// proved they could fire. The gate is load-bearing: ungated, `mint_for` + /// falls back to the V1 arm, whose 24-bit guard ACCEPTS `0x0001_0000`, so + /// the two `should_panic` tests fail with "test did not panic as expected" + /// — measured, not assumed. The third fails earlier still, at compile time + /// (`E0599`), because `family_v2`/`identity_v2` are themselves gated. #[test] #[cfg(feature = "guid-v2-tail")] #[should_panic(expected = "v2/v3 identity must fit in 16 bits")]