diff --git a/.claude/board/INTEGRATION_PLANS.md b/.claude/board/INTEGRATION_PLANS.md index 60cafbabf..8f8d52ab6 100644 --- a/.claude/board/INTEGRATION_PLANS.md +++ b/.claude/board/INTEGRATION_PLANS.md @@ -1,3 +1,43 @@ +## 2026-08-02 — kanban-64k-inverted-awareness v1 — PLANNED / CONJECTURE (parallel thinking + the inverted-awareness witness) — main thread + +**Plan:** `.claude/plans/kanban-64k-inverted-awareness-v1.md` +Two operator anchors: (a) real thinking at 64k via kanban orchestration **in +parallel** — everything shipped by `cycle-loop-closure-driver-v1`/PR #879 +except the word "parallel" (driver loop is synchronous, fleet is a HashMap, +`KanbanActor` unwired = the named incomplete refactor); Arm A designs the +actor-fleet driver seam (`MailboxFleet`-over-registry withdrawn per codex P1 — +the trait's sync `owner()`/`owner_mut()` borrows cannot reach actor-private +state behind `where_is`; W1 chooses guarantee-dummy single owner vs per-mailbox +`KanbanMsg::Advance` apply) and lands the first ACTOR-OWNED caller of +`owner_adapter::emit_bootstrap_intent` (the existing `cognitive_pass` caller is +HashMap-fleet-driven — the deliberate order-free keyed store, ordering +recovered by `temporal.rs` at read), +then MEASURES parallelism with a pre-registered can-fire/stay-silent falsifier, with the +pre-registered kill condition that failure regrades the claim to "64k-scale +sequential sparse cycles". (b) inverted awareness for the private consumer arc: +ontology = frozen-cathedral LTM, subject STM observations reflected via +rails-shaped READ-ONLY wiring (no `&mut` path to the cathedral, checked +structurally), catalog criteria as binary ranges (contract type + the +catalog-mirror drift guard generalized); view-2 cohort statistics as the WITNESS — +stored under the zero-copy law's ELEVATED carve-out, with the dichotomous +forms named honestly (φ not "Pearson", KR-20 not "α", κ-family not "ICC", +Spearman dropped at view 2), Jirak 2016 noise floors per I-NOISE-FLOOR-JIRAK, +a hard reliability≠validity gate (validity unclaimed until an external +criterion exists), and an anti-circularity rule (witness gates only via +held-out slices — the task-#65 M-GATE lesson promoted to a rule). Arm D: +observer/observed as two Locus categories over ONE arena (cheapest-first via +`standing_wave_grounded_lens`), reflexivity stays escalate +(PROBE-REFLEXIVE-POLICY untouched), and measurable Horizontverschmelzung as a +falsifier with the middle band PRE-REGISTERED before any run (κ≈1 = +redundancy, κ≈0 = no shared horizon, fusion lives between — κ-family per the +plan's own dichotomous rule; ICC only on the jc non-binary escalation) — whose machinery +is also the corpus-side Synthesis producer that un-blocks session task #65's gate 1 +without the query-string category error. Waves W0–W6 (D-KIA-0/A1/A2/B1/C5/D1/D3), +each probe-first with both falsifier halves. Blocked-on external: the consumer +physical bake (private repo), validity criterion, `LanceShardSink`. Built on the R1–R15 +review list (session 2026-08-02); §0 ground state carries receipts so nothing +is re-derived. + ## 2026-08-02 — cycle-loop-closure-driver v1 — PLANNED / CONJECTURE (the seam that makes persist_sink load-bearing at 64k) — main thread **Plan:** `.claude/plans/cycle-loop-closure-driver-v1.md` diff --git a/.claude/board/STATUS_BOARD.md b/.claude/board/STATUS_BOARD.md index 0eed045e6..d8a3d693c 100644 --- a/.claude/board/STATUS_BOARD.md +++ b/.claude/board/STATUS_BOARD.md @@ -1,3 +1,17 @@ +## kanban-64k-inverted-awareness v1 — parallel thinking + inverted-awareness witness (PLANNED 2026-08-02) + +Plan: `.claude/plans/kanban-64k-inverted-awareness-v1.md` (operator anchors a/b; R1-R15 review basis). + +| D-id | Deliverable | Repo | Status | Evidence | +|---|---|---|---|---| +| D-KIA-0 | jc capability map + dichotomous-statistics decision note (phi/KR-20/kappa naming; Spearman dropped at view 2) | lance-graph | Queued | plan W0 | +| D-KIA-A1 | actor-fleet driver seam — design gate (guarantee-dummy single owner vs per-mailbox KanbanMsg apply; MailboxFleet-over-registry withdrawn per codex P1); first ACTOR-OWNED caller of owner_adapter::emit_bootstrap_intent; #879 caveat fixes (retry footgun guard, held_owners strand falsifier, missing-owner counter) | lance-graph | Queued | plan W1 | +| D-KIA-A2 | parallelism falsifier (protocol pre-registered: median-of-5, >=2x at >=4k owners, +/-10% stay-silent; kill = regrade claim (a)) | lance-graph | Queued | plan W2 | +| D-KIA-B1 | catalog binary-range criterion contract type + generalized catalog-mirror drift guard | lance-graph | Queued | plan W3 | +| D-KIA-C5 | cohort-statistic witness type under the ELEVATED carve-out + held-out anti-circularity gate | lance-graph | Queued | plan W4 | +| D-KIA-D1 | observer/observed as two Locus categories over one arena (cheapest-first) | lance-graph | Queued | plan W5 | +| D-KIA-D3 | Horizontverschmelzung fusion falsifier, middle band pre-registered; corpus-side Synthesis producer (un-blocks session task #65 gate 1 — session-local task list, not a GitHub number) | lance-graph | Queued | plan W6 | + ## PROBE-BABEL-STANCES — two Rosetta stones + four-channel phase split (IN PR — slice 2, 2026-07-28) | D-id | Deliverable | Repo | Status | Evidence | diff --git a/.claude/plans/kanban-64k-inverted-awareness-v1.md b/.claude/plans/kanban-64k-inverted-awareness-v1.md new file mode 100644 index 000000000..285b85fa3 --- /dev/null +++ b/.claude/plans/kanban-64k-inverted-awareness-v1.md @@ -0,0 +1,250 @@ +# kanban-64k-inverted-awareness v1 — parallel thinking + the inverted-awareness witness + +> **Status:** PLANNED / CONJECTURE-graded per section (2026-08-02, main thread) +> **Operator anchors (verbatim):** (a) *"real thinking 64k via kanban as +> orchestration is possible in parallel"*; (b) *"for the private consumer arc we inverted +> awareness — the ontologies are the frozen cathedral the LTM mind is looking +> into, and the subject's STM gets the reflection of the volatile observations +> as a domain subset via rails-shaped RO wiring into ontologies, using all +> catalog criteria as binary ranges … *(anchor paraphrased: private-consumer +> names elided — public-repo separation of concerns)* … the statistics +> correlation is then a witness … the standing wave can sit in observer and +> observed in 2 categories — that allows for measurable Horizontverschmelzung +> of ontologies (Gadamer)."* +> **Companion plans:** `cycle-loop-closure-driver-v1.md` (P4a–P4f SHIPPED, +> PR #879), `epistemic-quadrant-materialization-v1.md` §4c (cross-term rule + +> PROBE-REFLEXIVE-POLICY), `persistence-cycle-wal-bootstrap-v1.md` (§2 sparse +> ruling; LanceShardSink DEFERRED). +> **Review basis:** the R1–R15 review list (this session, 2026-08-02) — each +> wave below names which R-items it settles. + +--- + +## 0. Ground state (verified, with receipts — do not re-derive) + +| Fact | Receipt | +|---|---| +| Cycle driver seal/apply shipped; 64k/17 sparse falsifier green incl. anti-vacuity untouched-count, 1 WAL write, 0 dataset reads | PR #879, `lance-graph-supervisor/src/cycle_driver.rs`; second-opinion review confirmed all 8 self-audited findings | +| Execution is a **synchronous loop**; "wait-free" scoped to the cast/cycle boundary only; `MailboxFleet` = blanket impl over `HashMap` | #879 module doc (its own honesty ledger); review §D | +| `KanbanActor` (real ractor, serialized single-writer, S2 MUL gate + S3 version tick + S4 registry delivery) exists and is **not** among `BatchWriter::cast`'s callers | `lance-graph-supervisor/src/kanban_actor.rs`; grep receipt 2026-07-31 | +| `owner_adapter::emit_bootstrap_intent` = the write-on-behalf cast consumer; its one caller (`cycle_driver.rs:516`, `cognitive_pass`) is driven by the **HashMap probe fleet**, not by actors — no ACTOR-OWNED caller exists (#879's own honesty-ledger scope) | `cycle_driver.rs:516`; `write-on-behalf.md` §Interim reality (D-MBX-A6-P3c) | +| Cross-mailbox ordering = `temporal.rs` HLC deinterlace, recovered at READ time — this is *why* ahead-firing needs no ack | operator ruling, `lance-graph-planner/src/temporal.rs` module doc | +| `LanceShardSink` does not exist; durability leg is a test-only in-RAM `FakeWalSink` | #879 review §D; `persistence-cycle-wal-bootstrap-v1.md` status table | +| Rung-3 recipe substrate: 34 NARS recipes catalogued, 29/34 primitive modules shipped; **O1 gap: no rung dispatches to recipes/verbs/StyleFamily yet** | `.claude/v3/knowledge/persona-vs-rung-ladder.md` | +| Consumer-side physical bake does not exist yet (in-RAM buffering sinks only; writer not built); a criteria-catalog/migration drift was found by the private consumer repo's own audit | private consumer board (details stay there) | +| `InferenceType::Synthesis` has **no producer over derived corpus beliefs** — only over Cypher query strings + the cache layer | session task #65 gate-1 correction (SESSION-LOCAL task list, not a GitHub number; category error, self-caught, recorded in the task's metadata) | +| Statistic-as-witness = the zero-copy law's ELEVATED carve-out (cross-input computation of a different KIND), same precedent as `Locus::Quorum` | zero-copy-warden verdict vocabulary; `zero-copy-lens-law.md` | + +--- + +## 1. The two claims, with their unproven words named + +**Claim (a)** — *64k parallel thinking via kanban.* Everything is shipped +except the word **"parallel"**: the driver loop is synchronous, the fleet is a +HashMap, and the real actors are unwired. This is the operator-named +"KanbanStep was rewired and the refactor not completed" gap. Arm A closes it. + +**Claim (b)** — *inverted awareness.* The inversion: ontology = immutable LTM +(the cathedral the mind looks INTO — read-only, cacheable, public); subject +STM = volatile observations REFLECTED onto the cathedral via rails-shaped +read-only wiring; awareness becomes **measurable** when a view-2 observer +computes cohort statistics over the reflection and those statistics act as a +**witness** (higher-rung derivation, legitimately stored). Fusion of two +ontology horizons (Gadamer) becomes a *measured* quantity. Arms B–D build the +lance-graph side; the private consumer repo consumes (separation of concerns +— its bake, its migrations, its sensitive-data handling stay in its own repo +and PRs, and are never named here). + +--- + +## 2. Arm A — make "parallel" true (settles R1) + +**A1 — the actor-fleet driver seam (the incomplete refactor).** Two +structural facts bound this wave (codex P1 on this plan + operator +clarification, 2026-08-03): +(i) `MailboxFleet`'s synchronous `owner()`/`owner_mut()` borrows +(`cycle_driver.rs:183-190`) CANNOT be implemented over the ractor registry — +`where_is` returns an `ActorRef`, and `KanbanActor` deliberately keeps its +owner private behind async messages; holding a second owner to satisfy the +trait would break single-writer. The earlier "implement `MailboxFleet` over +the registry, wiring-only" spec is **withdrawn as structurally impossible**. +(ii) The `HashMap` fleet is NOT a placeholder awaiting actor replacement — +it is the deliberate cheap keyed store whose job is ORDER-FREE access: +cross-mailbox ordering is `temporal.rs`' read-time job (HLC deinterlace, +operator ruling), so the apply side never needs sorted or synchronized +writes. W1 is therefore an Opus DESIGN gate first, choosing between two +seams that both preserve the pre-registered invariant — *one writer per +mailbox-phase state, no second owner, no ack*: + - **Guarantee-dummy owner** (operator model): ONE supervisor actor owns + the keyed fleet store — its serialized message loop is the sole + mutator; the thought phase fans out over read-only owner views, casts + ahead-fire into the single `BatchWriter`, seal/apply stay + single-writer inside the owning actor. + - **Per-mailbox actors** (codex variant): the sealed sparse set is + applied by delivering each owner's transition through its own mailbox + (`KanbanMsg::Advance`, the shipped S4 edge). +Either seam lands the first **actor-owned** `emit_bootstrap_intent` caller +(the existing `cognitive_pass` caller is HashMap-fleet-driven). +- Design constraint: the seal/collect side stays single-writer (one + `BatchWriter`); parallelism lives in the **thought phase** (owners think + concurrently, cast ahead-fire), never in the seal. Ordering is already the + read side's job (HLC deinterlace), so no ack machinery may appear — a + confirmation ledger anywhere in this arm is an automatic reject + (`E-KANBANSTEP-IS-THE-TRIGGER-1`). +- Carries #879 review caveats as requirements, not notes: the `run_cycle` + retry footgun gets a doc-comment + a `debug_assert`-style guard or typestate + (drained writer must not silently "succeed" a retried cycle); `held_owners` + accumulation becomes the driver's job with a strand falsifier; + `cognitive_pass`'s silently-dropped missing owner gets a `missing` counter + (symmetry with `apply_sealed_transitions`). + +**A2 — the parallelism falsifier.** The claim is only honest if measured: +N actors thinking concurrently (tokio joinset over `MulAdvance`-gated work) +vs. the same N sequentially, same corpus, same seals. +- **Can-fire:** concurrent wall-clock materially below sequential at 4k+ + owners with non-trivial per-thought work. +- **Stay-silent:** with trivial thought bodies the two must converge (else the + harness measures its own overhead). +- **Pre-registered measurement protocol** (hand-set a priori per the + threshold-honesty rule; codex P2 on this plan; NOT adjustable after the + measured run — a miss is a miss): statistic = median wall-clock over ≥5 + measured runs after 1 discarded warm-up, identical corpus and seals. + Can-fire = at ≥4,096 owners with per-thought busy-work ≥100 µs, concurrent + median ≤ ½ × sequential median (≥2× speedup). Stay-silent = with trivial + thought bodies (<1 µs), medians within ±10 %. +- **Kill condition:** if seal-side contention serializes end-to-end throughput + regardless of fleet size, claim (a) is regraded to "64k-scale sequential + sparse cycles" — still true, different claim, board-recorded as such. + +**A3 — `LanceShardSink` (real durability).** Stays DEFERRED behind its own +crash falsifiers per the persistence plan. Arm A does not pretend it exists; +A1/A2 run on the WAL contract only. (R6's consumer bake has the same shape on +the private-consumer side.) + +## 3. Arm B — the cathedral/reflection contract surface (settles R5, R8; lance-graph side only) + +**B1 — catalog binary-range criteria as an L-plane reading.** The rails already +exist (`le-contract.md` L1–L3, `part_of:is_a`); what's missing is the +*criterion* reading: per-criterion `(range, in/out)` as bit-positions over a +facet — content-blind bytes the ClassView projects, per V3 doctrine. No new +key layout, no new tenant until `v3-envelope-auditor` gates it. Deliverable is +the contract type + field-isolation tests, NOT any consumer's data. +- Includes the **catalog-mirror guard** shape (generic: contract criteria set + ↔ consumer migration must not drift — the drift-audit lesson as a reusable check, so + the missing-catalog-entries class of bug dies once). + +**B2 — RO-wiring direction proof.** The inversion's invariant: observation → +ontology binding is **read-only into the cathedral** — a subject row *points +at* ontology addresses (classid via `HealthcarePort::class_id`, never a local +codebook copy per `ogar-consumer-preflight.md`); nothing ever writes the +ontology. Falsifier: the contract surface offers no `&mut` path from an +observation to an ontology row — checked structurally (API audit), not by +convention. + +## 4. Arm C — the statistics witness (settles R2, R3, R4, R7, R9, R13) + +**C1 — jc crate audit first** (R7 — one read, no build): what does `jc` +actually provide toward ICC/α/ρ with variance components? Output: a one-page +capability map. Everything below adjusts to what's found. + +**C2 — name the dichotomous statistics correctly.** Over binary catalog +criteria: Pearson→**φ** (report the marginal-capped ceiling), Cronbach's +α→**KR-20**, ICC→**κ-family agreement**, Spearman **degenerates and is +dropped** at view 2 (it returns only in jc's non-binary escalation). The +implementation and every doc name the dichotomous forms; reporting "Pearson" +while computing φ is the defect class this arm exists to prevent. + +**C3 — reliability vs validity split (hard gate).** α/KR-20/ICC/κ = +**reliability**, claimable from the cohort alone. **Validity requires an +external criterion** (an external gold-standard criterion, defined on the private consumer board) and +is NOT claimed until one is wired. The plan's public claim ceiling until then: +*"measurable reliability as a first step toward measurable awareness."* + +**C4 — Jirak noise floors.** Binary criteria within one catalog panel are +domain-correlated — weak dependence *by construction*, so every +significance statement cites Jirak 2016 rates per `I-NOISE-FLOOR-JIRAK`; +classical IID Berry-Esseen is forbidden here exactly as for fingerprints. + +**C5 — witness storage under the ELEVATED carve-out.** The cohort statistic +is a cross-input derivation of a different KIND than any observation → it may +be stored; the ruling names the rung explicitly in the type's doc. i4 +quantization (~0.13 resolution over [−1,1]) is sufficient for a *witness* +(tap/signal); the full-precision value lives in jc's output, not the lane. + +**C6 — anti-circularity gate.** The witness may gate admission ONLY when +computed on a prior/held-out cohort slice — never the slice it gates (the +M-GATE self-proving-loop lesson from session task #65 — session-local task +list, not a GitHub number — promoted to a rule here). +Falsifier: same cohort, gate on/off, admitted-set must differ only via the +held-out statistic. + +## 5. Arm D — measurable Horizontverschmelzung (settles R10, R11, R14; feeds #65) + +**D1 — observer/observed as two Locus categories, cheapest formulation +first.** Try expressing view-1 (patient-in-cathedral) and view-2 +(cohort-observer) as two `Locus` values over ONE arena, resolved by the +shipped `standing_wave_grounded_lens` — no new machinery. Only if the +bipartite read genuinely cannot be expressed does a structural change get +designed (and then as a ClassView election, not a new layer). + +**D2 — reflexivity stays escalate.** Observer-observing-itself is +unrepresentable as routing (offset 0 = unbound) and the shipped policy +escalates. Arm D changes nothing here; any minting proposal routes through +`PROBE-REFLEXIVE-POLICY` first (plan §4c), full stop. + +**D3 — the fusion falsifier, middle band pre-registered NOW.** Two ontology +projections of one cohort (e.g. two catalog-derived criteria +views); fusion measured as their **κ-family agreement** (the projections are +binary criteria views, so C2's dichotomous rule applies here too; ICC returns +only if the comparison runs on jc's non-binary escalation): +- **κ ≈ 1.0 ⇒ redundancy** — two names for one horizon, no fusion. +- **κ ≈ 0 ⇒ no shared horizon** — nothing to fuse. +- **Fusion lives in the pre-registered middle band** (band fixed from C1's + capability map + a pilot slice *before* the measured run; recorded on the + board before results exist). +- Connection to session task #65 (PROBE-FREE-ENERGY-DESCENT, session-local + task list — not a GitHub number): a genuine fusion event is Synthesis-*shaped* + (cross-domain closure). D3's machinery is the corpus-side Synthesis + producer the M-GATE was missing — landing it un-blocks that task's gate 1 + without the query-string classifier category error. + +## 6. Wave order, D-ids, gates + +| Wave | D-id | Deliverable | Gate to pass | Model | +|---|---|---|---|---| +| W0 | D-KIA-0 | jc capability map (C1) + dichotomous-statistics decision note (C2 naming) | read-only; note on board | main thread | +| W1 | D-KIA-A1 | actor-fleet driver seam — design gate: guarantee-dummy single owner vs per-mailbox `KanbanMsg` apply (`MailboxFleet`-over-registry withdrawn, codex P1) + first ACTOR-OWNED `emit_bootstrap_intent` caller + #879 caveat fixes | existing 19 falsifiers stay green over the actor fleet; strand falsifier; no-ack audit clean | Opus design → Sonnet impl | +| W2 | D-KIA-A2 | parallelism falsifier (protocol pre-registered in §2 A2: median-of-5, ≥2× at ≥4k owners, ±10 % stay-silent) | can-fire + stay-silent both green, else regrade claim (a) | Opus | +| W3 | D-KIA-B1 | catalog criterion contract type + catalog-mirror drift guard | field-isolation matrix; `v3-envelope-auditor` verdict LAYOUT-CLEAN/GATED | Sonnet impl, Opus gate | +| W4 | D-KIA-C5 | witness type under ELEVATED ruling + C6 held-out gate | zero-copy verdict ELEVATED recorded; anti-circularity falsifier | Opus | +| W5 | D-KIA-D1 | observer/observed two-Locus read | expressible-with-shipped-machinery answer (either way, recorded) | Opus | +| W6 | D-KIA-D3 | fusion falsifier over two projections | middle band pre-registered BEFORE run; result vs band | Opus | + +Blocked-on external (not this repo's waves): the consumer physical bake +(private repo, R6), validity criterion selection (C3), `LanceShardSink` (A3). + +## 7. Kill conditions (pre-registered) + +1. A2 fails both directions → claim (a) regraded, not massaged. +2. jc lacks variance-component machinery (C1) → witness ships as κ/KR-20 only; + ICC deferred, stated plainly. +3. D3 lands outside the pre-registered band → "no measured fusion at this + granularity" is the recorded result; the band is not moved post hoc. +4. D1 needs new machinery → it stops and reports; no new layer without the + ClassView-election route. + +## 8. Discipline carried from this session + +- Falsifiability rule in full: every gate has a can-fire AND a stay-silent + half on non-trivial input; thresholds get inertness tests; no doc claim + without an exercising test or a *claimed, unverified* label. +- Statistics honesty: reliability ≠ validity; dichotomous forms named as + such; Jirak everywhere significance is claimed. +- No confirmation/ack state anywhere in Arm A (the transition is the event). +- helix API untouched (standing ruling). No model identifier in artifacts. +- Board hygiene in the same commit as any wave landing. + +**Honesty ledger:** nothing in this plan is measured yet except the §0 ground +state. Claim (a) is CONJECTURE until W2; claim (b)'s "measurable awareness" is +capped at *reliability* until a validity criterion exists; Horizontverschmelzung +is a designed falsifier, not a finding. diff --git a/.claude/v3/knowledge/write-on-behalf.md b/.claude/v3/knowledge/write-on-behalf.md index 58d306ff4..939d0231f 100644 --- a/.claude/v3/knowledge/write-on-behalf.md +++ b/.claude/v3/knowledge/write-on-behalf.md @@ -5,7 +5,7 @@ > ladybug-rs), and any session adding a write path to SoA rows / Lance > datasets / tenant lanes. -## Status: FINDING (operator-ruled 2026-07-02; batch writer + `owner_adapter` write-on-behalf cast SHIPPED 2026-08-01 — no production caller of `emit_bootstrap_intent` yet) +## Status: FINDING (operator-ruled 2026-07-02; batch writer + `owner_adapter` write-on-behalf cast SHIPPED 2026-08-01; `cycle_driver.rs` `cognitive_pass` is the existing production caller of `emit_bootstrap_intent` — HashMap-probe-fleet-driven; the first ACTOR-OWNED `KanbanActor` caller is the open W1 work, plan `kanban-64k-inverted-awareness-v1` D-KIA-A1) --- @@ -61,10 +61,20 @@ Before authoring any consumer write path: ## Interim reality (audited 2026-07-02; CORRECTED same day by the consumer audit) +> **⊘ SUPERSEDED 2026-08-01 (D-MBX-A6-P3c).** The batch writer + a real +> write-on-behalf consumer shipped: `owner_adapter::emit_bootstrap_intent` +> casts `on_behalf` of the live owner. Its existing caller is +> `cycle_driver.rs:516` (`cognitive_pass`) — production lib code, but driven by +> the HashMap probe fleet, not by actors; the first ACTOR-OWNED `KanbanActor` +> caller is open (D-KIA-A1). This entry replaces an earlier, narrower correction +> (2026-07-31, PR #876 exec-run arc) that only retired the "batch writer does +> not exist" claim without yet having a real consumer to point at. + The batch writer now exists (`lance_graph_planner::batch_writer::BatchWriter`) and `owner_adapter::emit_bootstrap_intent` is its write-on-behalf consumer — it -casts `on_behalf` of the live owner (D-MBX-A6-P3c, 2026-08-01). `emit_bootstrap_intent` -itself has no production caller yet (INTEGRATION-PLAN W1). Almost all consumer writes are **bake pipelines** +casts `on_behalf` of the live owner (D-MBX-A6-P3c, 2026-08-01); `cycle_driver.rs`'s +`cognitive_pass` calls it (HashMap-fleet-driven) — the first ACTOR-OWNED caller +remains open (D-KIA-A1). Almost all consumer writes are **bake pipelines** (q2 `osint_scene.soa` / `fma.soa` / `body.soa`): offline, single-writer, owner-less by construction — grandfathered as bootstrap-owner writes, migrating in W5. diff --git a/crates/lance-graph-ogar/src/bridges/medcare_bridge.rs b/crates/lance-graph-ogar/src/bridges/medcare_bridge.rs index 9ff1b6894..64a71f113 100644 --- a/crates/lance-graph-ogar/src/bridges/medcare_bridge.rs +++ b/crates/lance-graph-ogar/src/bridges/medcare_bridge.rs @@ -1,4 +1,7 @@ -//! MedCare (healthcare) tenant bridge — now a thin type alias over +//! ⚠ STATUS: DEPRECATED alias — do not construct. Pull the classid via +//! `ogar_vocab::ports::HealthcarePort::class_id(name)` (OGAR#95, +//! `docs/CONSUMER-BRIDGE-DEPRECATION.md`). What remains is one line: the +//! healthcare tenant bridge as a thin type alias over //! [`crate::bridges::unified::UnifiedBridge`] parameterised by //! [`ogar_vocab::ports::HealthcarePort`]. //! diff --git a/crates/lance-graph-ontology/src/soa_bake/mod.rs b/crates/lance-graph-ontology/src/soa_bake/mod.rs index 702b645a2..df004d2bf 100644 --- a/crates/lance-graph-ontology/src/soa_bake/mod.rs +++ b/crates/lance-graph-ontology/src/soa_bake/mod.rs @@ -1,3 +1,9 @@ +//! ⚠ STATUS: PARTIAL — only the label-codebook half is implemented +//! ([`LabelColumn`]). The address column, edge pairs, `ClassView` inheritance +//! and the bake driver are TYPE SCAFFOLDING, not a working bake. OGAR's +//! `ogar-obo` / `ogar-fma` now ship complete bakes emitting `NodeRow` bytes, +//! so whether this half stays a bake or becomes a loader is an OPEN question. +//! //! **SoA bake** — the codec-native ontology cache (issue #845). //! //! An RDF/OWL/OBO source file is *address-verbatim* — every triple respells diff --git a/crates/lance-graph-supervisor/src/actors/medcare_actor.rs b/crates/lance-graph-supervisor/src/actors/medcare_actor.rs index 540e15114..14053a93a 100644 --- a/crates/lance-graph-supervisor/src/actors/medcare_actor.rs +++ b/crates/lance-graph-supervisor/src/actors/medcare_actor.rs @@ -1,19 +1,28 @@ -//! `MedcareConsumerActor` — G=2, HEALTHCARE_V1 consumer actor (proof-of-concept). +//! ⚠ STATUS: UNWIRED STUB — never spawned, owns no bridge, emits no audit. +//! Every `handle` arm is a `tracing::debug!` plus a `// TODO`; the supervisor +//! tree spawns `supervisor::StubConsumerActor` instead (supervisor.rs:368). +//! Retained as the worked SHAPE for a generic `ConsumerActor`; it +//! is public API (re-exported from `lib.rs`), so removal is a breaking change. //! -//! This is the first concrete `Actor` impl for the `CallcenterSupervisor` tree. -//! It owns a `UnifiedBridge` (to be wired in the full impl) and -//! responds to `ConsumerEnvelope` messages, emitting `UnifiedAuditEvent` records -//! via the bridge's `AuditChain` on each authorization decision. +//! Healthcare-specific surface is two constants (`MEDCARE_G`, +//! `MEDCARE_VERSION`), one env-var name (`MEDCARE_AUDIT_SALT`) and the type +//! names — the message handling itself is generic `ConsumerEnvelope` logging. //! -//! For v1 (sprint-7), this is a **skeleton**: -//! - `UnifiedBridge` wiring is a `// TODO` (HSM salt wiring is sprint-8). -//! - `ConsumerEnvelope::Health` is fully handled. -//! - All other arms return a diagnostic response. +//! What it would become: the actor half of the collapse the bridge already +//! made (`MedcareBridge` → `UnifiedBridge`, lance-graph#570). +//! `MEDCARE_G` / `MEDCARE_VERSION` / the actor name / the audit-salt env var +//! are spawn parameters a `PortSpec` already carries (`P::NAMESPACE`, +//! `P::BRIDGE_ID`, `P::class_id`), so the generic form re-derives this file as +//! a one-line type alias. The healthcare VOCABULARY is owned upstream and is +//! not duplicated here: capability + classid table in `ogar_vocab` +//! (`healthcare_actions`, `ports::HealthcarePort`), public ontology reference +//! in OGAR `ogar-obo` (MONDO/HPO/Uberon/PATO/RO + the agnostic xref crosswalk). //! -//! Audit chain initialization: accepts env var `MEDCARE_AUDIT_SALT` (hex u64). -//! Sprint-8 hardening PR wires HSM instead. -//! -//! Spec: pr-g2-ractor-supervisor.md §8 (medcare_actor.rs, ~130 LOC). +//! Original v1 intent (sprint-7 spec `pr-g2-ractor-supervisor.md` §8), none of +//! it built: own a `UnifiedBridge`, answer `ConsumerEnvelope`, emit +//! `UnifiedAuditEvent` per authorization decision, seed the `AuditChain` from +//! `MEDCARE_AUDIT_SALT` (hex u64) and later from HSM. The env var is read in +//! `pre_start` and logged; it is wired to nothing else. use ractor::{Actor, ActorProcessingErr, ActorRef}; use tracing; diff --git a/crates/lance-graph-supervisor/src/actors/mod.rs b/crates/lance-graph-supervisor/src/actors/mod.rs index a7c53d04e..e7ed63a73 100644 --- a/crates/lance-graph-supervisor/src/actors/mod.rs +++ b/crates/lance-graph-supervisor/src/actors/mod.rs @@ -1,9 +1,12 @@ -//! Per-consumer actor implementations. +//! ⚠ STATUS: NO CONCRETE ACTOR SHIPS HERE YET — the one module below is an +//! unwired stub. Every G slot the supervisor actually spawns gets +//! `supervisor::StubConsumerActor`; nothing in this directory is reachable at +//! runtime. Treat the contents as shape/reference, not as consumer wiring. //! -//! Each active G slot has one actor. The `StubConsumerActor` (in `supervisor.rs`) -//! serves as the skeleton. Concrete implementations live here: +//! Per-consumer actor implementations. Each active G slot has one actor. //! -//! - `medcare_actor.rs` — `MedcareConsumerActor` (G=2, HEALTHCARE_V1, proof-of-concept) +//! - `medcare_actor.rs` — `MedcareConsumerActor` (G=2, HEALTHCARE_V1) — +//! UNWIRED stub; the generalization candidate for `ConsumerActor` //! //! Future: //! - `ogit_actor.rs` — OgitBridge actor (G=4, SMB_V1)