From 1c0959e826784cf240d9e8ca8ed9218fa27983c2 Mon Sep 17 00:00:00 2001 From: Claude Date: Sat, 1 Aug 2026 15:15:36 +0000 Subject: [PATCH 1/3] board: correct stale batch-writer claim in write-on-behalf.md MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The "Interim reality" section said the batch writer does not exist (INTEGRATION-PLAN W1, audited 2026-07-02). It shipped since — lance-graph-planner/src/batch_writer.rs (BatchWriter::cast, ahead-firing, no confirmation state) — and the stale claim was caught being relayed as current state in this session's #876 exec-run arc. Append-only correction per governance; the bake-pipeline paragraph is untouched. --- .claude/v3/knowledge/write-on-behalf.md | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/.claude/v3/knowledge/write-on-behalf.md b/.claude/v3/knowledge/write-on-behalf.md index 58d306ff..839ab7ed 100644 --- a/.claude/v3/knowledge/write-on-behalf.md +++ b/.claude/v3/knowledge/write-on-behalf.md @@ -61,6 +61,13 @@ Before authoring any consumer write path: ## Interim reality (audited 2026-07-02; CORRECTED same day by the consumer audit) +> **⊘ SUPERSEDED 2026-08-01 (D-MBX-A6-P3c).** The batch writer + a real +> write-on-behalf consumer shipped: `owner_adapter::emit_bootstrap_intent` +> casts `on_behalf` of the live owner. `emit_bootstrap_intent` itself has no +> production caller yet. This entry replaces an earlier, narrower correction +> (2026-07-31, PR #876 exec-run arc) that only retired the "batch writer does +> not exist" claim without yet having a real consumer to point at. + The batch writer now exists (`lance_graph_planner::batch_writer::BatchWriter`) and `owner_adapter::emit_bootstrap_intent` is its write-on-behalf consumer — it casts `on_behalf` of the live owner (D-MBX-A6-P3c, 2026-08-01). `emit_bootstrap_intent` From ee8a22c22205f599c20990a70c458c7ad4166028 Mon Sep 17 00:00:00 2001 From: Claude Date: Mon, 3 Aug 2026 21:50:14 +0000 Subject: [PATCH 2/3] =?UTF-8?q?plan/board:=20kanban-64k-inverted-awareness?= =?UTF-8?q?=20v1=20=E2=80=94=20parallel-thinking=20+=20witness=20integrati?= =?UTF-8?q?on=20plan?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Adds the W0-W6 integration plan for the two-anchor arc: (a) measured parallel thinking over the 64k kanban fleet (Arm A designs the actor-fleet driver seam after the MailboxFleet-over-registry approach was withdrawn as structurally impossible per external review; pre-registered numeric can-fire/stay-silent parallelism falsifier), and (b) the inverted-awareness witness surface (catalog binary-range criterion contract type, dichotomous statistics honesty: phi/KR-20/kappa-family, Jirak noise floors, ICC only on the non-binary jc escalation, Horizontverschmelzung falsifier via kappa agreement middle band). Board hygiene in the same commit per the mandatory rule: INTEGRATION_PLANS prepend, STATUS_BOARD D-KIA rows, write-on-behalf.md caller-status supersession note (cycle_driver.rs cognitive_pass is the existing HashMap-fleet-driven production caller; first actor-owned caller is W1). Incorporates three external review rounds (consistency fixes, the missed W1 gate row, the design-gate rewording, the pre-registered thresholds). Co-Authored-By: Claude Fable 5 Claude-Session: https://claude.ai/code/session_01K3RyLEbuNSHxxB3NTTrGki --- .claude/board/INTEGRATION_PLANS.md | 40 +++ .claude/board/STATUS_BOARD.md | 14 + .../plans/kanban-64k-inverted-awareness-v1.md | 250 ++++++++++++++++++ .claude/v3/knowledge/write-on-behalf.md | 13 +- 4 files changed, 312 insertions(+), 5 deletions(-) create mode 100644 .claude/plans/kanban-64k-inverted-awareness-v1.md diff --git a/.claude/board/INTEGRATION_PLANS.md b/.claude/board/INTEGRATION_PLANS.md index 60cafbab..8f8d52ab 100644 --- a/.claude/board/INTEGRATION_PLANS.md +++ b/.claude/board/INTEGRATION_PLANS.md @@ -1,3 +1,43 @@ +## 2026-08-02 — kanban-64k-inverted-awareness v1 — PLANNED / CONJECTURE (parallel thinking + the inverted-awareness witness) — main thread + +**Plan:** `.claude/plans/kanban-64k-inverted-awareness-v1.md` +Two operator anchors: (a) real thinking at 64k via kanban orchestration **in +parallel** — everything shipped by `cycle-loop-closure-driver-v1`/PR #879 +except the word "parallel" (driver loop is synchronous, fleet is a HashMap, +`KanbanActor` unwired = the named incomplete refactor); Arm A designs the +actor-fleet driver seam (`MailboxFleet`-over-registry withdrawn per codex P1 — +the trait's sync `owner()`/`owner_mut()` borrows cannot reach actor-private +state behind `where_is`; W1 chooses guarantee-dummy single owner vs per-mailbox +`KanbanMsg::Advance` apply) and lands the first ACTOR-OWNED caller of +`owner_adapter::emit_bootstrap_intent` (the existing `cognitive_pass` caller is +HashMap-fleet-driven — the deliberate order-free keyed store, ordering +recovered by `temporal.rs` at read), +then MEASURES parallelism with a pre-registered can-fire/stay-silent falsifier, with the +pre-registered kill condition that failure regrades the claim to "64k-scale +sequential sparse cycles". (b) inverted awareness for the private consumer arc: +ontology = frozen-cathedral LTM, subject STM observations reflected via +rails-shaped READ-ONLY wiring (no `&mut` path to the cathedral, checked +structurally), catalog criteria as binary ranges (contract type + the +catalog-mirror drift guard generalized); view-2 cohort statistics as the WITNESS — +stored under the zero-copy law's ELEVATED carve-out, with the dichotomous +forms named honestly (φ not "Pearson", KR-20 not "α", κ-family not "ICC", +Spearman dropped at view 2), Jirak 2016 noise floors per I-NOISE-FLOOR-JIRAK, +a hard reliability≠validity gate (validity unclaimed until an external +criterion exists), and an anti-circularity rule (witness gates only via +held-out slices — the task-#65 M-GATE lesson promoted to a rule). Arm D: +observer/observed as two Locus categories over ONE arena (cheapest-first via +`standing_wave_grounded_lens`), reflexivity stays escalate +(PROBE-REFLEXIVE-POLICY untouched), and measurable Horizontverschmelzung as a +falsifier with the middle band PRE-REGISTERED before any run (κ≈1 = +redundancy, κ≈0 = no shared horizon, fusion lives between — κ-family per the +plan's own dichotomous rule; ICC only on the jc non-binary escalation) — whose machinery +is also the corpus-side Synthesis producer that un-blocks session task #65's gate 1 +without the query-string category error. Waves W0–W6 (D-KIA-0/A1/A2/B1/C5/D1/D3), +each probe-first with both falsifier halves. Blocked-on external: the consumer +physical bake (private repo), validity criterion, `LanceShardSink`. Built on the R1–R15 +review list (session 2026-08-02); §0 ground state carries receipts so nothing +is re-derived. + ## 2026-08-02 — cycle-loop-closure-driver v1 — PLANNED / CONJECTURE (the seam that makes persist_sink load-bearing at 64k) — main thread **Plan:** `.claude/plans/cycle-loop-closure-driver-v1.md` diff --git a/.claude/board/STATUS_BOARD.md b/.claude/board/STATUS_BOARD.md index 0eed045e..d8a3d693 100644 --- a/.claude/board/STATUS_BOARD.md +++ b/.claude/board/STATUS_BOARD.md @@ -1,3 +1,17 @@ +## kanban-64k-inverted-awareness v1 — parallel thinking + inverted-awareness witness (PLANNED 2026-08-02) + +Plan: `.claude/plans/kanban-64k-inverted-awareness-v1.md` (operator anchors a/b; R1-R15 review basis). + +| D-id | Deliverable | Repo | Status | Evidence | +|---|---|---|---|---| +| D-KIA-0 | jc capability map + dichotomous-statistics decision note (phi/KR-20/kappa naming; Spearman dropped at view 2) | lance-graph | Queued | plan W0 | +| D-KIA-A1 | actor-fleet driver seam — design gate (guarantee-dummy single owner vs per-mailbox KanbanMsg apply; MailboxFleet-over-registry withdrawn per codex P1); first ACTOR-OWNED caller of owner_adapter::emit_bootstrap_intent; #879 caveat fixes (retry footgun guard, held_owners strand falsifier, missing-owner counter) | lance-graph | Queued | plan W1 | +| D-KIA-A2 | parallelism falsifier (protocol pre-registered: median-of-5, >=2x at >=4k owners, +/-10% stay-silent; kill = regrade claim (a)) | lance-graph | Queued | plan W2 | +| D-KIA-B1 | catalog binary-range criterion contract type + generalized catalog-mirror drift guard | lance-graph | Queued | plan W3 | +| D-KIA-C5 | cohort-statistic witness type under the ELEVATED carve-out + held-out anti-circularity gate | lance-graph | Queued | plan W4 | +| D-KIA-D1 | observer/observed as two Locus categories over one arena (cheapest-first) | lance-graph | Queued | plan W5 | +| D-KIA-D3 | Horizontverschmelzung fusion falsifier, middle band pre-registered; corpus-side Synthesis producer (un-blocks session task #65 gate 1 — session-local task list, not a GitHub number) | lance-graph | Queued | plan W6 | + ## PROBE-BABEL-STANCES — two Rosetta stones + four-channel phase split (IN PR — slice 2, 2026-07-28) | D-id | Deliverable | Repo | Status | Evidence | diff --git a/.claude/plans/kanban-64k-inverted-awareness-v1.md b/.claude/plans/kanban-64k-inverted-awareness-v1.md new file mode 100644 index 00000000..285b85fa --- /dev/null +++ b/.claude/plans/kanban-64k-inverted-awareness-v1.md @@ -0,0 +1,250 @@ +# kanban-64k-inverted-awareness v1 — parallel thinking + the inverted-awareness witness + +> **Status:** PLANNED / CONJECTURE-graded per section (2026-08-02, main thread) +> **Operator anchors (verbatim):** (a) *"real thinking 64k via kanban as +> orchestration is possible in parallel"*; (b) *"for the private consumer arc we inverted +> awareness — the ontologies are the frozen cathedral the LTM mind is looking +> into, and the subject's STM gets the reflection of the volatile observations +> as a domain subset via rails-shaped RO wiring into ontologies, using all +> catalog criteria as binary ranges … *(anchor paraphrased: private-consumer +> names elided — public-repo separation of concerns)* … the statistics +> correlation is then a witness … the standing wave can sit in observer and +> observed in 2 categories — that allows for measurable Horizontverschmelzung +> of ontologies (Gadamer)."* +> **Companion plans:** `cycle-loop-closure-driver-v1.md` (P4a–P4f SHIPPED, +> PR #879), `epistemic-quadrant-materialization-v1.md` §4c (cross-term rule + +> PROBE-REFLEXIVE-POLICY), `persistence-cycle-wal-bootstrap-v1.md` (§2 sparse +> ruling; LanceShardSink DEFERRED). +> **Review basis:** the R1–R15 review list (this session, 2026-08-02) — each +> wave below names which R-items it settles. + +--- + +## 0. Ground state (verified, with receipts — do not re-derive) + +| Fact | Receipt | +|---|---| +| Cycle driver seal/apply shipped; 64k/17 sparse falsifier green incl. anti-vacuity untouched-count, 1 WAL write, 0 dataset reads | PR #879, `lance-graph-supervisor/src/cycle_driver.rs`; second-opinion review confirmed all 8 self-audited findings | +| Execution is a **synchronous loop**; "wait-free" scoped to the cast/cycle boundary only; `MailboxFleet` = blanket impl over `HashMap` | #879 module doc (its own honesty ledger); review §D | +| `KanbanActor` (real ractor, serialized single-writer, S2 MUL gate + S3 version tick + S4 registry delivery) exists and is **not** among `BatchWriter::cast`'s callers | `lance-graph-supervisor/src/kanban_actor.rs`; grep receipt 2026-07-31 | +| `owner_adapter::emit_bootstrap_intent` = the write-on-behalf cast consumer; its one caller (`cycle_driver.rs:516`, `cognitive_pass`) is driven by the **HashMap probe fleet**, not by actors — no ACTOR-OWNED caller exists (#879's own honesty-ledger scope) | `cycle_driver.rs:516`; `write-on-behalf.md` §Interim reality (D-MBX-A6-P3c) | +| Cross-mailbox ordering = `temporal.rs` HLC deinterlace, recovered at READ time — this is *why* ahead-firing needs no ack | operator ruling, `lance-graph-planner/src/temporal.rs` module doc | +| `LanceShardSink` does not exist; durability leg is a test-only in-RAM `FakeWalSink` | #879 review §D; `persistence-cycle-wal-bootstrap-v1.md` status table | +| Rung-3 recipe substrate: 34 NARS recipes catalogued, 29/34 primitive modules shipped; **O1 gap: no rung dispatches to recipes/verbs/StyleFamily yet** | `.claude/v3/knowledge/persona-vs-rung-ladder.md` | +| Consumer-side physical bake does not exist yet (in-RAM buffering sinks only; writer not built); a criteria-catalog/migration drift was found by the private consumer repo's own audit | private consumer board (details stay there) | +| `InferenceType::Synthesis` has **no producer over derived corpus beliefs** — only over Cypher query strings + the cache layer | session task #65 gate-1 correction (SESSION-LOCAL task list, not a GitHub number; category error, self-caught, recorded in the task's metadata) | +| Statistic-as-witness = the zero-copy law's ELEVATED carve-out (cross-input computation of a different KIND), same precedent as `Locus::Quorum` | zero-copy-warden verdict vocabulary; `zero-copy-lens-law.md` | + +--- + +## 1. The two claims, with their unproven words named + +**Claim (a)** — *64k parallel thinking via kanban.* Everything is shipped +except the word **"parallel"**: the driver loop is synchronous, the fleet is a +HashMap, and the real actors are unwired. This is the operator-named +"KanbanStep was rewired and the refactor not completed" gap. Arm A closes it. + +**Claim (b)** — *inverted awareness.* The inversion: ontology = immutable LTM +(the cathedral the mind looks INTO — read-only, cacheable, public); subject +STM = volatile observations REFLECTED onto the cathedral via rails-shaped +read-only wiring; awareness becomes **measurable** when a view-2 observer +computes cohort statistics over the reflection and those statistics act as a +**witness** (higher-rung derivation, legitimately stored). Fusion of two +ontology horizons (Gadamer) becomes a *measured* quantity. Arms B–D build the +lance-graph side; the private consumer repo consumes (separation of concerns +— its bake, its migrations, its sensitive-data handling stay in its own repo +and PRs, and are never named here). + +--- + +## 2. Arm A — make "parallel" true (settles R1) + +**A1 — the actor-fleet driver seam (the incomplete refactor).** Two +structural facts bound this wave (codex P1 on this plan + operator +clarification, 2026-08-03): +(i) `MailboxFleet`'s synchronous `owner()`/`owner_mut()` borrows +(`cycle_driver.rs:183-190`) CANNOT be implemented over the ractor registry — +`where_is` returns an `ActorRef`, and `KanbanActor` deliberately keeps its +owner private behind async messages; holding a second owner to satisfy the +trait would break single-writer. The earlier "implement `MailboxFleet` over +the registry, wiring-only" spec is **withdrawn as structurally impossible**. +(ii) The `HashMap` fleet is NOT a placeholder awaiting actor replacement — +it is the deliberate cheap keyed store whose job is ORDER-FREE access: +cross-mailbox ordering is `temporal.rs`' read-time job (HLC deinterlace, +operator ruling), so the apply side never needs sorted or synchronized +writes. W1 is therefore an Opus DESIGN gate first, choosing between two +seams that both preserve the pre-registered invariant — *one writer per +mailbox-phase state, no second owner, no ack*: + - **Guarantee-dummy owner** (operator model): ONE supervisor actor owns + the keyed fleet store — its serialized message loop is the sole + mutator; the thought phase fans out over read-only owner views, casts + ahead-fire into the single `BatchWriter`, seal/apply stay + single-writer inside the owning actor. + - **Per-mailbox actors** (codex variant): the sealed sparse set is + applied by delivering each owner's transition through its own mailbox + (`KanbanMsg::Advance`, the shipped S4 edge). +Either seam lands the first **actor-owned** `emit_bootstrap_intent` caller +(the existing `cognitive_pass` caller is HashMap-fleet-driven). +- Design constraint: the seal/collect side stays single-writer (one + `BatchWriter`); parallelism lives in the **thought phase** (owners think + concurrently, cast ahead-fire), never in the seal. Ordering is already the + read side's job (HLC deinterlace), so no ack machinery may appear — a + confirmation ledger anywhere in this arm is an automatic reject + (`E-KANBANSTEP-IS-THE-TRIGGER-1`). +- Carries #879 review caveats as requirements, not notes: the `run_cycle` + retry footgun gets a doc-comment + a `debug_assert`-style guard or typestate + (drained writer must not silently "succeed" a retried cycle); `held_owners` + accumulation becomes the driver's job with a strand falsifier; + `cognitive_pass`'s silently-dropped missing owner gets a `missing` counter + (symmetry with `apply_sealed_transitions`). + +**A2 — the parallelism falsifier.** The claim is only honest if measured: +N actors thinking concurrently (tokio joinset over `MulAdvance`-gated work) +vs. the same N sequentially, same corpus, same seals. +- **Can-fire:** concurrent wall-clock materially below sequential at 4k+ + owners with non-trivial per-thought work. +- **Stay-silent:** with trivial thought bodies the two must converge (else the + harness measures its own overhead). +- **Pre-registered measurement protocol** (hand-set a priori per the + threshold-honesty rule; codex P2 on this plan; NOT adjustable after the + measured run — a miss is a miss): statistic = median wall-clock over ≥5 + measured runs after 1 discarded warm-up, identical corpus and seals. + Can-fire = at ≥4,096 owners with per-thought busy-work ≥100 µs, concurrent + median ≤ ½ × sequential median (≥2× speedup). Stay-silent = with trivial + thought bodies (<1 µs), medians within ±10 %. +- **Kill condition:** if seal-side contention serializes end-to-end throughput + regardless of fleet size, claim (a) is regraded to "64k-scale sequential + sparse cycles" — still true, different claim, board-recorded as such. + +**A3 — `LanceShardSink` (real durability).** Stays DEFERRED behind its own +crash falsifiers per the persistence plan. Arm A does not pretend it exists; +A1/A2 run on the WAL contract only. (R6's consumer bake has the same shape on +the private-consumer side.) + +## 3. Arm B — the cathedral/reflection contract surface (settles R5, R8; lance-graph side only) + +**B1 — catalog binary-range criteria as an L-plane reading.** The rails already +exist (`le-contract.md` L1–L3, `part_of:is_a`); what's missing is the +*criterion* reading: per-criterion `(range, in/out)` as bit-positions over a +facet — content-blind bytes the ClassView projects, per V3 doctrine. No new +key layout, no new tenant until `v3-envelope-auditor` gates it. Deliverable is +the contract type + field-isolation tests, NOT any consumer's data. +- Includes the **catalog-mirror guard** shape (generic: contract criteria set + ↔ consumer migration must not drift — the drift-audit lesson as a reusable check, so + the missing-catalog-entries class of bug dies once). + +**B2 — RO-wiring direction proof.** The inversion's invariant: observation → +ontology binding is **read-only into the cathedral** — a subject row *points +at* ontology addresses (classid via `HealthcarePort::class_id`, never a local +codebook copy per `ogar-consumer-preflight.md`); nothing ever writes the +ontology. Falsifier: the contract surface offers no `&mut` path from an +observation to an ontology row — checked structurally (API audit), not by +convention. + +## 4. Arm C — the statistics witness (settles R2, R3, R4, R7, R9, R13) + +**C1 — jc crate audit first** (R7 — one read, no build): what does `jc` +actually provide toward ICC/α/ρ with variance components? Output: a one-page +capability map. Everything below adjusts to what's found. + +**C2 — name the dichotomous statistics correctly.** Over binary catalog +criteria: Pearson→**φ** (report the marginal-capped ceiling), Cronbach's +α→**KR-20**, ICC→**κ-family agreement**, Spearman **degenerates and is +dropped** at view 2 (it returns only in jc's non-binary escalation). The +implementation and every doc name the dichotomous forms; reporting "Pearson" +while computing φ is the defect class this arm exists to prevent. + +**C3 — reliability vs validity split (hard gate).** α/KR-20/ICC/κ = +**reliability**, claimable from the cohort alone. **Validity requires an +external criterion** (an external gold-standard criterion, defined on the private consumer board) and +is NOT claimed until one is wired. The plan's public claim ceiling until then: +*"measurable reliability as a first step toward measurable awareness."* + +**C4 — Jirak noise floors.** Binary criteria within one catalog panel are +domain-correlated — weak dependence *by construction*, so every +significance statement cites Jirak 2016 rates per `I-NOISE-FLOOR-JIRAK`; +classical IID Berry-Esseen is forbidden here exactly as for fingerprints. + +**C5 — witness storage under the ELEVATED carve-out.** The cohort statistic +is a cross-input derivation of a different KIND than any observation → it may +be stored; the ruling names the rung explicitly in the type's doc. i4 +quantization (~0.13 resolution over [−1,1]) is sufficient for a *witness* +(tap/signal); the full-precision value lives in jc's output, not the lane. + +**C6 — anti-circularity gate.** The witness may gate admission ONLY when +computed on a prior/held-out cohort slice — never the slice it gates (the +M-GATE self-proving-loop lesson from session task #65 — session-local task +list, not a GitHub number — promoted to a rule here). +Falsifier: same cohort, gate on/off, admitted-set must differ only via the +held-out statistic. + +## 5. Arm D — measurable Horizontverschmelzung (settles R10, R11, R14; feeds #65) + +**D1 — observer/observed as two Locus categories, cheapest formulation +first.** Try expressing view-1 (patient-in-cathedral) and view-2 +(cohort-observer) as two `Locus` values over ONE arena, resolved by the +shipped `standing_wave_grounded_lens` — no new machinery. Only if the +bipartite read genuinely cannot be expressed does a structural change get +designed (and then as a ClassView election, not a new layer). + +**D2 — reflexivity stays escalate.** Observer-observing-itself is +unrepresentable as routing (offset 0 = unbound) and the shipped policy +escalates. Arm D changes nothing here; any minting proposal routes through +`PROBE-REFLEXIVE-POLICY` first (plan §4c), full stop. + +**D3 — the fusion falsifier, middle band pre-registered NOW.** Two ontology +projections of one cohort (e.g. two catalog-derived criteria +views); fusion measured as their **κ-family agreement** (the projections are +binary criteria views, so C2's dichotomous rule applies here too; ICC returns +only if the comparison runs on jc's non-binary escalation): +- **κ ≈ 1.0 ⇒ redundancy** — two names for one horizon, no fusion. +- **κ ≈ 0 ⇒ no shared horizon** — nothing to fuse. +- **Fusion lives in the pre-registered middle band** (band fixed from C1's + capability map + a pilot slice *before* the measured run; recorded on the + board before results exist). +- Connection to session task #65 (PROBE-FREE-ENERGY-DESCENT, session-local + task list — not a GitHub number): a genuine fusion event is Synthesis-*shaped* + (cross-domain closure). D3's machinery is the corpus-side Synthesis + producer the M-GATE was missing — landing it un-blocks that task's gate 1 + without the query-string classifier category error. + +## 6. Wave order, D-ids, gates + +| Wave | D-id | Deliverable | Gate to pass | Model | +|---|---|---|---|---| +| W0 | D-KIA-0 | jc capability map (C1) + dichotomous-statistics decision note (C2 naming) | read-only; note on board | main thread | +| W1 | D-KIA-A1 | actor-fleet driver seam — design gate: guarantee-dummy single owner vs per-mailbox `KanbanMsg` apply (`MailboxFleet`-over-registry withdrawn, codex P1) + first ACTOR-OWNED `emit_bootstrap_intent` caller + #879 caveat fixes | existing 19 falsifiers stay green over the actor fleet; strand falsifier; no-ack audit clean | Opus design → Sonnet impl | +| W2 | D-KIA-A2 | parallelism falsifier (protocol pre-registered in §2 A2: median-of-5, ≥2× at ≥4k owners, ±10 % stay-silent) | can-fire + stay-silent both green, else regrade claim (a) | Opus | +| W3 | D-KIA-B1 | catalog criterion contract type + catalog-mirror drift guard | field-isolation matrix; `v3-envelope-auditor` verdict LAYOUT-CLEAN/GATED | Sonnet impl, Opus gate | +| W4 | D-KIA-C5 | witness type under ELEVATED ruling + C6 held-out gate | zero-copy verdict ELEVATED recorded; anti-circularity falsifier | Opus | +| W5 | D-KIA-D1 | observer/observed two-Locus read | expressible-with-shipped-machinery answer (either way, recorded) | Opus | +| W6 | D-KIA-D3 | fusion falsifier over two projections | middle band pre-registered BEFORE run; result vs band | Opus | + +Blocked-on external (not this repo's waves): the consumer physical bake +(private repo, R6), validity criterion selection (C3), `LanceShardSink` (A3). + +## 7. Kill conditions (pre-registered) + +1. A2 fails both directions → claim (a) regraded, not massaged. +2. jc lacks variance-component machinery (C1) → witness ships as κ/KR-20 only; + ICC deferred, stated plainly. +3. D3 lands outside the pre-registered band → "no measured fusion at this + granularity" is the recorded result; the band is not moved post hoc. +4. D1 needs new machinery → it stops and reports; no new layer without the + ClassView-election route. + +## 8. Discipline carried from this session + +- Falsifiability rule in full: every gate has a can-fire AND a stay-silent + half on non-trivial input; thresholds get inertness tests; no doc claim + without an exercising test or a *claimed, unverified* label. +- Statistics honesty: reliability ≠ validity; dichotomous forms named as + such; Jirak everywhere significance is claimed. +- No confirmation/ack state anywhere in Arm A (the transition is the event). +- helix API untouched (standing ruling). No model identifier in artifacts. +- Board hygiene in the same commit as any wave landing. + +**Honesty ledger:** nothing in this plan is measured yet except the §0 ground +state. Claim (a) is CONJECTURE until W2; claim (b)'s "measurable awareness" is +capped at *reliability* until a validity criterion exists; Horizontverschmelzung +is a designed falsifier, not a finding. diff --git a/.claude/v3/knowledge/write-on-behalf.md b/.claude/v3/knowledge/write-on-behalf.md index 839ab7ed..939d0231 100644 --- a/.claude/v3/knowledge/write-on-behalf.md +++ b/.claude/v3/knowledge/write-on-behalf.md @@ -5,7 +5,7 @@ > ladybug-rs), and any session adding a write path to SoA rows / Lance > datasets / tenant lanes. -## Status: FINDING (operator-ruled 2026-07-02; batch writer + `owner_adapter` write-on-behalf cast SHIPPED 2026-08-01 — no production caller of `emit_bootstrap_intent` yet) +## Status: FINDING (operator-ruled 2026-07-02; batch writer + `owner_adapter` write-on-behalf cast SHIPPED 2026-08-01; `cycle_driver.rs` `cognitive_pass` is the existing production caller of `emit_bootstrap_intent` — HashMap-probe-fleet-driven; the first ACTOR-OWNED `KanbanActor` caller is the open W1 work, plan `kanban-64k-inverted-awareness-v1` D-KIA-A1) --- @@ -63,15 +63,18 @@ Before authoring any consumer write path: > **⊘ SUPERSEDED 2026-08-01 (D-MBX-A6-P3c).** The batch writer + a real > write-on-behalf consumer shipped: `owner_adapter::emit_bootstrap_intent` -> casts `on_behalf` of the live owner. `emit_bootstrap_intent` itself has no -> production caller yet. This entry replaces an earlier, narrower correction +> casts `on_behalf` of the live owner. Its existing caller is +> `cycle_driver.rs:516` (`cognitive_pass`) — production lib code, but driven by +> the HashMap probe fleet, not by actors; the first ACTOR-OWNED `KanbanActor` +> caller is open (D-KIA-A1). This entry replaces an earlier, narrower correction > (2026-07-31, PR #876 exec-run arc) that only retired the "batch writer does > not exist" claim without yet having a real consumer to point at. The batch writer now exists (`lance_graph_planner::batch_writer::BatchWriter`) and `owner_adapter::emit_bootstrap_intent` is its write-on-behalf consumer — it -casts `on_behalf` of the live owner (D-MBX-A6-P3c, 2026-08-01). `emit_bootstrap_intent` -itself has no production caller yet (INTEGRATION-PLAN W1). Almost all consumer writes are **bake pipelines** +casts `on_behalf` of the live owner (D-MBX-A6-P3c, 2026-08-01); `cycle_driver.rs`'s +`cognitive_pass` calls it (HashMap-fleet-driven) — the first ACTOR-OWNED caller +remains open (D-KIA-A1). Almost all consumer writes are **bake pipelines** (q2 `osint_scene.soa` / `fma.soa` / `body.soa`): offline, single-writer, owner-less by construction — grandfathered as bootstrap-owner writes, migrating in W5. From 02413efdcfb053dd4d3f23be018ac6dde447f744 Mon Sep 17 00:00:00 2001 From: Claude Date: Mon, 3 Aug 2026 22:13:05 +0000 Subject: [PATCH 3/3] docs: make the first five header lines honest on four unwired/partial modules MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit A `head -5` / grep on these files previously described intent, not state. Doc-comment-only change; no code paths touched. - actors/medcare_actor.rs: header claimed it owns a UnifiedBridge and emits UnifiedAuditEvent per authorization decision. It does neither — every handler is a tracing::debug! plus a TODO, and the supervisor tree spawns StubConsumerActor (supervisor.rs:368) instead. Header now leads with UNWIRED STUB, notes it is public API (re-exported from lib.rs, so removal is breaking), names the two constants + one env-var that are the only domain-specific surface, and points at the generic ConsumerActor it is retained as the worked shape for. Original intent kept below, marked as unbuilt. - actors/mod.rs: said concrete implementations live here; none ship. - soa_bake/mod.rs: only the label-codebook half is implemented; the address column, edge pairs, ClassView inheritance and bake driver are type scaffolding. Also records that OGAR now ships complete bakes emitting NodeRow bytes, so the ownership of this half is an open question. - bridges/medcare_bridge.rs: the type carries #[deprecated] but a head-5 did not show it; the migration pointer is now the first line. Co-Authored-By: Claude Fable 5 Claude-Session: https://claude.ai/code/session_01K3RyLEbuNSHxxB3NTTrGki --- .../src/bridges/medcare_bridge.rs | 5 ++- .../lance-graph-ontology/src/soa_bake/mod.rs | 6 ++++ .../src/actors/medcare_actor.rs | 35 ++++++++++++------- .../lance-graph-supervisor/src/actors/mod.rs | 11 +++--- 4 files changed, 39 insertions(+), 18 deletions(-) diff --git a/crates/lance-graph-ogar/src/bridges/medcare_bridge.rs b/crates/lance-graph-ogar/src/bridges/medcare_bridge.rs index 9ff1b689..64a71f11 100644 --- a/crates/lance-graph-ogar/src/bridges/medcare_bridge.rs +++ b/crates/lance-graph-ogar/src/bridges/medcare_bridge.rs @@ -1,4 +1,7 @@ -//! MedCare (healthcare) tenant bridge — now a thin type alias over +//! ⚠ STATUS: DEPRECATED alias — do not construct. Pull the classid via +//! `ogar_vocab::ports::HealthcarePort::class_id(name)` (OGAR#95, +//! `docs/CONSUMER-BRIDGE-DEPRECATION.md`). What remains is one line: the +//! healthcare tenant bridge as a thin type alias over //! [`crate::bridges::unified::UnifiedBridge`] parameterised by //! [`ogar_vocab::ports::HealthcarePort`]. //! diff --git a/crates/lance-graph-ontology/src/soa_bake/mod.rs b/crates/lance-graph-ontology/src/soa_bake/mod.rs index 702b645a..df004d2b 100644 --- a/crates/lance-graph-ontology/src/soa_bake/mod.rs +++ b/crates/lance-graph-ontology/src/soa_bake/mod.rs @@ -1,3 +1,9 @@ +//! ⚠ STATUS: PARTIAL — only the label-codebook half is implemented +//! ([`LabelColumn`]). The address column, edge pairs, `ClassView` inheritance +//! and the bake driver are TYPE SCAFFOLDING, not a working bake. OGAR's +//! `ogar-obo` / `ogar-fma` now ship complete bakes emitting `NodeRow` bytes, +//! so whether this half stays a bake or becomes a loader is an OPEN question. +//! //! **SoA bake** — the codec-native ontology cache (issue #845). //! //! An RDF/OWL/OBO source file is *address-verbatim* — every triple respells diff --git a/crates/lance-graph-supervisor/src/actors/medcare_actor.rs b/crates/lance-graph-supervisor/src/actors/medcare_actor.rs index 540e1511..14053a93 100644 --- a/crates/lance-graph-supervisor/src/actors/medcare_actor.rs +++ b/crates/lance-graph-supervisor/src/actors/medcare_actor.rs @@ -1,19 +1,28 @@ -//! `MedcareConsumerActor` — G=2, HEALTHCARE_V1 consumer actor (proof-of-concept). +//! ⚠ STATUS: UNWIRED STUB — never spawned, owns no bridge, emits no audit. +//! Every `handle` arm is a `tracing::debug!` plus a `// TODO`; the supervisor +//! tree spawns `supervisor::StubConsumerActor` instead (supervisor.rs:368). +//! Retained as the worked SHAPE for a generic `ConsumerActor`; it +//! is public API (re-exported from `lib.rs`), so removal is a breaking change. //! -//! This is the first concrete `Actor` impl for the `CallcenterSupervisor` tree. -//! It owns a `UnifiedBridge` (to be wired in the full impl) and -//! responds to `ConsumerEnvelope` messages, emitting `UnifiedAuditEvent` records -//! via the bridge's `AuditChain` on each authorization decision. +//! Healthcare-specific surface is two constants (`MEDCARE_G`, +//! `MEDCARE_VERSION`), one env-var name (`MEDCARE_AUDIT_SALT`) and the type +//! names — the message handling itself is generic `ConsumerEnvelope` logging. //! -//! For v1 (sprint-7), this is a **skeleton**: -//! - `UnifiedBridge` wiring is a `// TODO` (HSM salt wiring is sprint-8). -//! - `ConsumerEnvelope::Health` is fully handled. -//! - All other arms return a diagnostic response. +//! What it would become: the actor half of the collapse the bridge already +//! made (`MedcareBridge` → `UnifiedBridge`, lance-graph#570). +//! `MEDCARE_G` / `MEDCARE_VERSION` / the actor name / the audit-salt env var +//! are spawn parameters a `PortSpec` already carries (`P::NAMESPACE`, +//! `P::BRIDGE_ID`, `P::class_id`), so the generic form re-derives this file as +//! a one-line type alias. The healthcare VOCABULARY is owned upstream and is +//! not duplicated here: capability + classid table in `ogar_vocab` +//! (`healthcare_actions`, `ports::HealthcarePort`), public ontology reference +//! in OGAR `ogar-obo` (MONDO/HPO/Uberon/PATO/RO + the agnostic xref crosswalk). //! -//! Audit chain initialization: accepts env var `MEDCARE_AUDIT_SALT` (hex u64). -//! Sprint-8 hardening PR wires HSM instead. -//! -//! Spec: pr-g2-ractor-supervisor.md §8 (medcare_actor.rs, ~130 LOC). +//! Original v1 intent (sprint-7 spec `pr-g2-ractor-supervisor.md` §8), none of +//! it built: own a `UnifiedBridge`, answer `ConsumerEnvelope`, emit +//! `UnifiedAuditEvent` per authorization decision, seed the `AuditChain` from +//! `MEDCARE_AUDIT_SALT` (hex u64) and later from HSM. The env var is read in +//! `pre_start` and logged; it is wired to nothing else. use ractor::{Actor, ActorProcessingErr, ActorRef}; use tracing; diff --git a/crates/lance-graph-supervisor/src/actors/mod.rs b/crates/lance-graph-supervisor/src/actors/mod.rs index a7c53d04..e7ed63a7 100644 --- a/crates/lance-graph-supervisor/src/actors/mod.rs +++ b/crates/lance-graph-supervisor/src/actors/mod.rs @@ -1,9 +1,12 @@ -//! Per-consumer actor implementations. +//! ⚠ STATUS: NO CONCRETE ACTOR SHIPS HERE YET — the one module below is an +//! unwired stub. Every G slot the supervisor actually spawns gets +//! `supervisor::StubConsumerActor`; nothing in this directory is reachable at +//! runtime. Treat the contents as shape/reference, not as consumer wiring. //! -//! Each active G slot has one actor. The `StubConsumerActor` (in `supervisor.rs`) -//! serves as the skeleton. Concrete implementations live here: +//! Per-consumer actor implementations. Each active G slot has one actor. //! -//! - `medcare_actor.rs` — `MedcareConsumerActor` (G=2, HEALTHCARE_V1, proof-of-concept) +//! - `medcare_actor.rs` — `MedcareConsumerActor` (G=2, HEALTHCARE_V1) — +//! UNWIRED stub; the generalization candidate for `ConsumerActor` //! //! Future: //! - `ogit_actor.rs` — OgitBridge actor (G=4, SMB_V1)