Skip to content

policy: record the pre-rule foreign files modified by label-gated #6826/#6847 (Closes #6936) - #6937

Merged
gHashTag merged 3 commits into
masterfrom
sieve/exceptions-6936
Oct 6, 2026
Merged

gHashTag merged 3 commits into
masterfrom
sieve/exceptions-6936

Conversation

@gHashTag

@gHashTag gHashTag commented Oct 6, 2026

Copy link
Copy Markdown
Owner

Closes #6936
Refs #6657, #6826, #6847, #6695

What

Four entries in tools/policy/foreign-exceptions.txt for pre-rule files whose label-gated modifications landed on master without a recording:

The approval these entries record is the owner-approved-foreign label those PRs already carried plus the standing 2026-10-06 authorization ("add the label yourself and do the foreign part", translated). No new foreign code is authorized.

Why

Lefthook own-language checks a local merge-commit against its first parent, so merging master into any branch trips on these files even when the branch adds no foreign code -- the #5921 trap, now triggered by master-side content; it blocked the conflicts-rebase route for #6695. CI is unaffected (it reads the BASE copy of this file).

🤖 Generated with Claude Code

#6847 (Closes #6936, Refs #6657)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@gHashTag gHashTag added the owner-approved-foreign Owner-approved exception to the only-t27 rule: hand-written foreign code allowed in this PR label Oct 6, 2026
gHashTag added a commit that referenced this pull request Oct 6, 2026
Seal conflicts resolved to the side whose spec_hash equals the merged spec
text (verified: sha256 of specs/isa/t27a.t27 and specs/isa/ternary_encoding.t27
in the merged tree match master's 4c2caab4... and 563b6ca6... exactly).
One-time foreign-exceptions entries for the master-side #6826/#6847 mods,
per the file's own mechanism; dedup with #6937.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
gHashTag added a commit that referenced this pull request Oct 6, 2026
foreign-exceptions conflict resolved keeping both blocks (this branch's
main.rs entry and master's t27b_reduce.py entry); one-time entries for the
master-side #6826/#6847 mods, per the file's own mechanism; dedup with #6937.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

PR Dashboard

Generated at: 2026-10-06 16:14:14 UTC

Summary

Status Count
Total Open PRs 50
PRs with Failing Checks 36
PRs with All Checks Green 14
READY 0
FAILING 36
PENDING 0
NO CHECKS YET 0

These columns do not partition: 0 + 36 + 0 + 0 = 36, and there are 50 open PRs. A PR is being counted twice or not at all.

Seal Status

  • ⚠️ STALE -- sha256(compiler.rs)=0ec05a8c1a46 != manifest seal=87e5cbd3ad94.
    The committed NMSE numbers were certified against an older compiler.rs.
    Run scripts/reseal-check.sh locally for the two-step reseal command (advisory; not a merge gate).

foreign-exceptions conflict resolved keeping both blocks (this PR's
permanent #6826/#6847 entries and master's #6046-52 selfhost fixtures).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

PR Dashboard

Generated at: 2026-10-06 16:58:44 UTC

Summary

Status Count
Total Open PRs 50
PRs with Failing Checks 46
PRs with All Checks Green 4
READY 0
FAILING 46
PENDING 0
NO CHECKS YET 0

These columns do not partition: 0 + 46 + 0 + 0 = 46, and there are 50 open PRs. A PR is being counted twice or not at all.

Seal Status

  • ⚠️ STALE -- sha256(compiler.rs)=0ec05a8c1a46 != manifest seal=87e5cbd3ad94.
    The committed NMSE numbers were certified against an older compiler.rs.
    Run scripts/reseal-check.sh locally for the two-step reseal command (advisory; not a merge gate).

@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

PR Dashboard

Generated at: 2026-10-06 17:30:22 UTC

Summary

Status Count
Total Open PRs 50
PRs with Failing Checks 48
PRs with All Checks Green 2
READY 0
FAILING 48
PENDING 0
NO CHECKS YET 0

These columns do not partition: 0 + 48 + 0 + 0 = 48, and there are 50 open PRs. A PR is being counted twice or not at all.

Seal Status

  • ⚠️ STALE -- sha256(compiler.rs)=b23641f01baa != manifest seal=87e5cbd3ad94.
    The committed NMSE numbers were certified against an older compiler.rs.
    Run scripts/reseal-check.sh locally for the two-step reseal command (advisory; not a merge gate).

@gHashTag
gHashTag merged commit 33e61b3 into master Oct 6, 2026
25 checks passed
gHashTag added a commit that referenced this pull request Oct 6, 2026
foreign-exceptions conflict resolved to master's permanent #6937 entries;
this branch's one-time merge-route block dropped (superseded on master).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@gHashTag gHashTag removed the owner-approved-foreign Owner-approved exception to the only-t27 rule: hand-written foreign code allowed in this PR label Oct 6, 2026
gHashTag added a commit that referenced this pull request Oct 6, 2026
Closes #6961) (#6970)

* Implement merger gate specification with discounted check rules

- Add red_check_passes function: true only when not required, concluded and discounted
- Add required_check_passes function: true when posted and green
- Add gate_open function: false when ruleset unreadable (fails closed)
- Include 13 tests covering all negative controls and positive cases
- Meets all acceptance criteria for functions, tests, and test results

Closes #5776

* Fix competitive claims in BITNET_STACK.md to be properly supported by evidence

Narrow 'no competitor has' and 'unique position' claims to reference the four projects surveyed here, removing absolute claims that aren't supported by systematic survey evidence as required by POSITIONING_CONFORMANCE_LAYER.md.

Closes #5399

* Port 8 functions from tools/check_vector_data.py to specs/port/tools/check_vector_data.t27

- Port counts(), census(), baseline(), _write_vectors(), _run_gate(), _control_case(), _baselined_empty_file_case(), _record_refusal_case()
- Add 8 test blocks for each function
- All acceptance criteria met:
  1. File exists and is present
  2. All 8 functions are present with correct names
  3. Generated code has 0 'not yet implemented' and >24 lines
  4. File parses successfully (status: IMPLEMENTED)
  5. File has 8 test blocks

Closes #6405

* Add erratum lines to wave reports documenting unimplemented deliverables

Erratum (#5406): Add erratum lines to both WAVE_LOOP_51_REPORT.md and WAVE_LOOP_45_REPORT.md documenting deliverables that were claimed as complete but never implemented in source code.

- W51: ExprAddressOf and t27c lint --ascii identifiers absent from source
- W45: has_cycle_dfs identifier absent from source

Closes #5406

* docs: the coordination entry this branch needs to land

A pull request must add exactly one docs/now entry and a bee has no way
to know that: its brief names a boundary file and acceptance criteria,
and docs/now/ is neither. The publisher adds it rather than failing the
gate.

Closes #5406

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* docs: the coordination entry this branch needs to land

A pull request must add exactly one docs/now entry and a bee has no way
to know that: its brief names a boundary file and acceptance criteria,
and docs/now/ is neither. The publisher adds it rather than failing the
gate.

Closes #6405

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* docs: the coordination entry this branch needs to land

A pull request must add exactly one docs/now entry and a bee has no way
to know that: its brief names a boundary file and acceptance criteria,
and docs/now/ is neither. The publisher adds it rather than failing the
gate.

Closes #5399

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* docs: the coordination entry this branch needs to land

A pull request must add exactly one docs/now entry and a bee has no way
to know that: its brief names a boundary file and acceptance criteria,
and docs/now/ is neither. The publisher adds it rather than failing the
gate.

Closes #5776

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* feat(t27b): std.mem.eql/indexOf on byte slices and byte-array pointers (Closes #6961)

In the reference, buf[a:b] of a [N]u8 is a []u8 and &buf is a *[N]u8;
Zig coerces both to []const u8 for std.mem.eql/indexOf, so they compare
by content. t27b refused them as ExprCall(std.*) "not a string"; it now
coerces exactly these two shapes. Other element types stay refused.

Conformance spec first: specs/tri/t27b/conformance/std_mem_byte_slice.t27
(6 pass under t27c test-report, 0 vacuous). Rust edited under the owner's
owner-approved-foreign approval on #6063.

Refs #6063

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* t27b ledger: ls.t27 and std_mem_byte_slice.t27 pass, gen_w384_lean.t27 to codegen (#6961)

Master's ledger plus this PR's own three moves, measured on the t27b lab
with the same tree and reference before and after. Cap 55 -> 54.

Refs #6063

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* ci(t27b): native arm64 t27b tests and corpus ratchet per PR; tri t27b ready reads them (#6444) (#6846)

* ci(t27b): native arm64 t27b tests and corpus ratchet per PR; ready reads them (#6444)

New workflow .github/workflows/t27b-native.yml with three checks:

- t27b-native-linux (ubuntu-24.04-arm) and t27b-native-macos (macos-14):
  cargo test --release -p t27b with T27B_DIFF_SEED = the run number, so
  each run draws new differential programs; failing seeds go to the summary.
- t27b-native-ratchet (ubuntu-24.04-arm): t27b corpus specs --json natively
  with the reference path (t27c release + zig 0.16.0 built in CI), then
  tri t27b ratchet against docs/reports/t27b_expectations.json. The lab's
  /refcache.json is lab.py's format keyed by the x86 t27c's sha256, which
  t27b's --reference-cache cannot read, so the reference cache is t27b's own
  TSV carried in actions/cache, seeded by master runs.

tri t27b ready: t27b-native-linux and t27b-native-macos join
REQUIRED_WHEN_PRESENT; the ratchet check stays non-required (Q16). Three
planted PRs in the ready test cover it. gate-topology classification entry
and foreign-exceptions entries per the owner's owner-approved-foreign
label on #6444.

Refs #6444 #6488 #6063

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* ci(t27b-native): pass the run's commit and ref through env, not shell interpolation (#6444)

The untrusted-input gate flagged github.head_ref interpolated into run:.

Refs #6444

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* ci(t27b-native): no quiet shapes in the report steps (#6444)

The quiet census counted four report steps of this workflow (an existence
gate, two '|| echo'/'|| true' arms). The summaries now read the log and name
it, the ratchet verdict comes from its exit code, and the cache trim moved
into the corpus step, where the file always exists.

Refs #6444

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* chore(census): re-bless shell + quiet for t27b-native.yml (#6444)

What moved and why:
- workflow files read 64 -> 65 (both): the new t27b-native.yml.
- jobs 83 -> 85, run: steps 291 -> 300, the runner does 270 -> 279 (shell):
  its 2 jobs and 8 run: steps, plus 1 run: step that master's #6848 (tri
  t27b fuzz) added without a bless, which made master's cli-tri red.
- named a path but not quiet 154 -> 161 (quiet): 7 of its steps name a path.
  Steps in a quiet shape stay at 30.

Written from the output of tri gates quiet / tri gates shell (the same text
tri census pin --bless writes).

Refs #6444

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* ci(t27b-native): reference timeout 120 s; timeouts are never cached (#6444)

Four specs/fpga/testbench references never finish. A timeout is never cached,
so at t27b's default 300 s every run, warm or cold, stalled all four workers
for five minutes (run 37475897137: files 250-275 took 325 s).

Refs #6444

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* feat(verified): the receipt record contract -- six fields, producer named (Closes #6942) (#6943)

The contract half of epic #6655 Round 2: the shape of the receipt
artifact t27c silicon must persist (R2-1) and the toolchain identity
it must carry (R2-2). Six fields judged in fixed order with a
first-missing code; verdict word must be one verdict.t27 defines;
producer compared verbatim against the seal's producer. 6 zig tests,
8/8 mutants killed, sealed and verified.

Epic #6655.

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* spec(queen): BEAM-style actors under the Queen's agents (Closes #6963) (#6966)

specs/queen/actors.t27 (module QueenActors) is the layer below
control.t27: pids as slot + generation, a mailbox where send never
blocks and receive is selective, exit signals and links (trap, normal,
untrappable kill -> killed, noproc), one-way monitors with flush, and
OTP supervisors (permanent/transient/temporary, one_for_one/one_for_all/
rest_for_one, reverse stop order, shutdown-then-kill, restart intensity
escalating to the parent). Section 6 places the Queen's tree on it;
section 7 names what is deliberately not the BEAM.

16 tests and 6 invariants pass via t27c gen + zig test; all six t27c
backends exit 0 and are deterministic; 62 of 62 mutants killed.
dupe_scan finds nothing written elsewhere. Slice of #6657.

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* feat(tri): tri night -- the whole overnight operation in one command (#6804)

* feat(tri): tri night -- the whole overnight operation in one command (Closes #6803)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* census: bless the fetch ledger for the night module (Refs #6803)

cli/tri/src/night.rs adds one source file to the read set and two
bounded gh fetch sites that print what they got (pr_line's pr view,
the verdict loop's mergeStateStatus). Numbers moved: files read
47->48, lines naming a spelling 74->76, FETCH SITES 33->35,
prints-what-it-got 3->5. All four moves are the same single cause.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* policy: record the pre-rule foreign files modified by label-gated #6826/#6847 (Closes #6936, Refs #6657) (#6937)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* t27b: a module var written at the top of a test is a write to module state (Closes #6911) (#6965)

* t27b: a module var written at the top of a test is a write to module state

Since #6295 the reference (block_fresh_binding in bootstrap/src/compiler.rs)
no longer binds a top-level write to a module `var` in a test as a fresh
`const`; gen-zig prints the plain write, and t27c test-report passes it.
t27b still refused it as StmtAssign(module var in test). The refusal is
removed; the write takes the module-var store path a fn body already uses.

Dogfood spec first: specs/tri/t27b/conformance/module_var_in_test.t27
(reference: 6 pass, 0 vacuous). A test-local `var` that shadows a module
var and a write inside an invariant stay refused.

Rust edit under the owner's approval on epic #6063 (label
owner-approved-foreign); files listed in tools/policy/foreign-exceptions.txt.

Closes #6911
Refs #6063

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* t27b conformance: keep module_var_in_test to one family

The test that wrote a test-local var twice also hit StmtAssign(reference
redeclares), a separate family; it now writes only module state. On the
lab: reference 6 pass, 13 runtime asserts, 0 vacuous; t27b 6 pass, 13
runtime asserts; three mutants (wrong value, leaked state, sign) fail.

Refs #6911

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* t27b ledger + NOW entry: formal_tb and vcd_trace_tb pass (#6911)

Lab run on 8aa626c (mismatch 0, reference_disagree 0): formal_tb and
vcd_trace_tb move from blocked to pass, and module_var_in_test passes
with 13 runtime asserts. Scoped hand edit of the ledger; cap 57 -> 55.
The #6911 approval note joins the existing #6864 block in
foreign-exceptions.txt instead of repeating the paths.

Refs #6911

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* t27b ledger: recount after merging #6938 (477/262/53, cap 55 -> 53) (#6911)

Lane 2's #6938 and this branch both moved the counts to 474/262/55,
so the merge took the line unchanged; the entries now give 477 pass,
262 pass_vacuous and 53 not_pass.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* feat(fpga): PoC slots a/b on silicon -- one JTAG boundary, two implementations (Closes #6829, epic #6655) (#6832)

Two wrappers identical except the EXPECTED expression (x vs x^255) and the
design id (19/20): the slot boundary of specs/verified/poc is one boundary.
Bench evidence: both slots verdict AGREED ACROSS 3 PLACEMENTS (seeds 1,7,42),
clauses=1111 ok=1, wrong-part control Done 0->1; seals of static_counter and
both slots verified MATCH. Hand-written Verilog as owner-approved-foreign per
chat 2026-10-06, exceptions entry added in this branch.

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* spec(queen): actors control lane, call, backoff, hung turn, dead letters (Closes #6972 #6974 #6975 #6976 #6990 #6991 #6992) (#7001)

* spec(queen): actors control lane, call, backoff, hung turn, dead letters (Refs #6971)

A self-review of specs/queen/actors.t27 against Erlang/OTP, Akka,
Temporal, Orleans and Dapr found five places weaker than the systems it
borrows from. This closes them in the spec:

- #6972 control lane: cancel and heartbeat survive a full mailbox,
  coalesce per kind, and are taken before data;
- #6974 call: reply, DOWN or timeout; a reply wins over a DOWN; the alias
  dies with the call, so a late reply reaches nobody;
- #6975 backoff: a slow crash loop extends an unstable streak, waits
  10 s doubling to 300 s, and gives up to the parent past 6;
- #6990 hung turn: past TURN_MAX_SECONDS the supervisor kills the turn
  and the DOWN reclaims its task at once;
- #6991 dead letters: every lost message is counted, a coalesced one is not;
- #6992 two Erlang corners stated (no trappable kill on a link; no
  exit(self, normal) quirk);
- #6976 coverage: all 49 pub functions called by a test, section 7 pinned
  by an invariant with a negative control.

22 tests and 9 invariants pass, 0 vacuous; gen-rust, gen-c, gen-verilog
exit 0; 40 of 41 new-line mutants killed, the survivor is equivalent.

Closes #6972, Closes #6974, Closes #6975, Closes #6976, Closes #6990,
Closes #6991, Closes #6992

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* test(queen): actors boundary asserts from the first tri mutate spec run (Refs #6976, #6993)

`tri mutate spec` (#6993) ran the whole file on the lab: 149 of 157
mutants killed, 8 survivors. Two were test gaps and are closed here:

- pid_of: `slot > GEN_MASK` -> `>=` survived; slot GEN_MASK is a real
  slot, now asserted.
- mbox_push: `tag > TAG_MASK` -> `>=` survived; tag 255 is a message,
  now asserted.

Both mutants were applied by hand and now fail `zig test`.

Six are equivalent and stay:
- mbox_len and mbox_find loop bounds `< MBOX_SLOTS` -> `<=`: mbox_tag
  returns 0 past the last slot, so both loops end the same way.
- ctl_next `t < CTL_TAGS` -> `<=`: ctl_pending is false for tag 64.
- backoff_seconds `wait >= CAP` -> `>`: 10 * 2^k never equals 300.
- backoff_seconds `wait > CAP` -> `>=`: at equality both return CAP.
- the reclaim wait at `since_renewal == ttl`: every branch returns 0.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* docs(now): actors lanes -- the whole-file tri mutate spec count beside the hand list (Refs #6976)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* Port scripts/gen_w633.py (Python, 3 functions) to specs/port/scripts/gen_w633.t27 (Closes #6711) (#6997)

* feat(port): scripts/gen_w633.py to specs/port/scripts/gen_w633.t27 (Closes #6711)

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* chore(dupes): record build_tree shared by the gen_w631 and gen_w633 ports

scripts/gen_w633.py is a copy of scripts/gen_w631.py with a different grid
size, so the two ports carry the same subtree walk. Reusing gen_w631's
function is not possible today: a use of another port module does not
compile under t27c test-report (undeclared identifier), which issue #6711
requires to pass. The copy is deliberate, so it is recorded in the ledger
(tools/dupe_scan.py --bless; one line, no other group moved).

Refs #6711

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>

* fix(numeric): settle gf16.t27 against FORMAT-SPEC-001 -- no subnormals, ties toward zero, NaN 0xFE01, exponent mask (#6940) (#6969)

* fix(spec-guards): ring-096 and specs/numeric/formats.t27 agree on f32, as the gf16 SSOT says (Closes #6887)

check_ring_spec_drift.py reported the pair DRIFTED (5 of 6 shared
signatures differ) and failed spec-guards on master and every PR.

Both sides disagreed with specs/numeric/gf16.t27 (L6):
- spec: gf16_to_f32, ternary_to_f32 and quantize_value returned gf16
  (lowered to u16); the SSOT decoder gf16_decode_to_f32 returns f32.
  Now f32; tests/invariants compare the f32 directly. Two false test
  claims fixed: 1.0 is 0x3E00 under bias 31 (not 0x3C00), and -0.5/0.5
  are not fixed points of ternary quantize/dequantize.
- ring: the public API used f64 where spec and SSOT say f32. Now f32;
  the f64 arithmetic stays private (narrowing is exact for GF16 values).
  42/42 crate tests pass (rustc 1.99, t27c Railway lab).

The Rust edit is an owner-approved-foreign exception scoped to #6887.

Refs #6488

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* seal(numeric/formats): reseal after the f32 return types (Refs #6887)

Resealed on the t27c Railway lab with master 75cf4e5 t27c
(t27c seal specs/numeric/formats.t27 --save; tri seals sync-twins).
spec_hash matches the local spec (sha256 b5fed047...b088).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(numeric/formats): shift constants are u8, as in the gf16 SSOT (Refs #6887)

ExpShift and SignShift read u5 and u4; specs/numeric/gf16.t27 declares
EXP_SHIFT and SIGN_SHIFT as u8. gen-rust passed u5/u4 through verbatim, so
the generated Rust did not compile and the spec-guards differential step
could not even build its harness for ring-096.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* seal(numeric/formats): reseal after the u8 shift constants (Refs #6887)

Resealed on the t27c Railway lab with master 75cf4e5 t27c.
spec_hash matches the local spec (sha256 51e4a456...a417a831).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* numeric/formats: implement the codec bodies; ring-096 encodes denormals

The six functions in specs/numeric/formats.t27 had empty bodies, so the
generated Rust could not run and ring-096 had nothing to be compared with.
They now have bodies built from the numeric SSOT (GF16 [S|E6|M9], bias 31,
specs/numeric/gf16.t27 and FORMAT-SPEC-001.json):

- gf16_to_f32 decodes zero, denormals, normals, +/-Inf and NaN exactly.
- f32_to_gf16 rounds to nearest with ties away from zero, as
  gf16_encode_f32 does; overflow goes to +/-Inf, NaN to 0x7F01.
- f32_to_ternary / ternary_to_f32 / format_bytes / quantize_value.

Eight new tests, including an exhaustive decode-then-encode round trip over
all 65536 codes. Trit members are spelled Trit::pos because gen-rust only
learns an enum's name when it emits the enum, and a `use`-imported enum is
emitted after the functions.

ring-096 encoded every denormal at twice its value and 2^-31 as +0: its
scale-down loop ran to e = 0 instead of stopping at e = 1. Fixed, with the
same exhaustive round-trip test on the ring side (#6887 foreign exception).

Refs #6893 #6488

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* spec-guards: published figures follow the corpus; harness learns enums and floats

published_figures.py: the pins had not moved since 5b2f8e4 (#5613), where
every figure still equals its pin. Eight drifted as merges landed. Each new
pin names the merges that moved it, counted per merge with the file's own
regexes; no matcher, exit code or self-check changed (#6899).

ring_spec_differential.py (#6893):
- enum parameters and returns, with variants paired by name across case;
  an enum that does not pair one to one is refused;
- an f32/f64 input grid (both zeros, ties, denormals, the GF16 overflow
  edge, +/-Inf, NaN), with floats compared by {:?};
- a producer that panics on one side only is counted as a disagreement
  instead of killing the harness.
Three new negative controls in --self-check.

Both Python files are listed in tools/policy/foreign-exceptions.txt under
owner-approved-foreign issues #6893 and #6899.

Refs #6893 #6899 #6488

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* numeric/formats: build the decoded NaN through a typed local

gen-zig typed `(pos_inf() - pos_inf()) as f32` as an integer-to-float cast
(@floatFromInt of an f64), so the seal reported the Zig tests as blocked.
With a typed f64 local all 34 tests and the comptime invariants compile and
pass under zig 0.16.0 on the lab.

Refs #6893

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* reseal formats.t27 after NaN typed-local fix (lab, 34/34)

Refs #6893

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* published figures: test blocks 15611 -> 15614 after master merged #6892 and #6880

#6892 added one test block and #6880 added two; counted per merge with the
checker's own regex. No matcher changed.

Refs #6899

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(numeric): settle the four gf16.t27 self-contradictions against FORMAT-SPEC-001 (#6940)

D1 no subnormals: FORMAT-SPEC-001 value_formula has no subnormal clause, so
E=0, M!=0 is normal and |x| < 2^-31 flushes to signed zero (as gf16_v2_mul.v
flushes underflow).
D2 round to nearest, ties toward zero: frozen_silicon_anchor.rounding_mode is
"ties-to-zero (frozen)".
D3 canonical NaN 0xFE01 (gf16_v2_mul.v emits 16'hFE01); every E=63, M!=0
code is NaN.
D4 extract_exponent is (x & EXP_MASK) >> EXP_SHIFT.

gf16.t27 now compiles and its 201 tests run; compiling exposed three wrong
bodies (fmod sign, exp overflow, negate of zero) that are fixed with it.
formats.t27 and ring-096 follow the same decisions; ties, overflow tie,
no-subnormal and NaN cases are pinned with concrete bit patterns.

Closes #6940
Refs #6488

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* seal: reseal gf16 and Formats on the t27c lab after #6940

gf16.t27 now compiles: its seal records tests 201/201 instead of
"blocked: does not compile". Formats 34/34. check_seal_currency on the lab:
STALE generated-code hash 0, ring/spec drift CONVERGED 3, differential
ring-096 vs formats.t27 138/138 agree.

Refs #6940

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* published figures: re-pin after master moved to 33e61b3 (Refs #6899)

spec-guards was red on the PR head because master merged under it.
Counted per merge with the file's own regexes, 2838800..33e61b3:

- test blocks 15614 -> 15714: #6966 +16, #6943 +6, #6938 +6, #6828 +38,
  #6749 +6, #6900 +1, #6747 +27 (= +100). This PR's own +8 in
  specs/numeric/formats.t27 is unchanged; master alone measures 15706.
- x.len field reads 2147 -> 2149: #6938 +2. This PR adds none.

No matcher changed. The census gate passes on the merge: the quiet census
move (159 -> 160) that failed cli-tri was re-blessed on master by #6924,
so nothing is re-blessed here.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* published figures: test blocks 15714 -> 15720 after master merged #6965 (Refs #6899)

#6965 added specs/tri/t27b/conformance/module_var_in_test.t27 (+6 test
blocks). Master alone measures 15712 at 38a6e30; + 8 from this PR =
15720. x.len field reads unchanged at 2149. Census gate passes.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* t27b: an untyped var takes the reference's u32/u64 width; an untyped undefined const is accepted (Closes #6967) (#6998)

* t27b: untyped var set to an integer literal takes the reference's width; untyped undefined const accepted

An untyped `var` whose initializer is a bare integer literal takes the
width t27c's Zig backend pins on it (`zig_int_literal_default_type`):
the literal's suffix, else u32, or u64 past u32::MAX. An untyped
`const x = undefined;` binds nothing, as the reference prints it and
Zig accepts it; a read of it stays refused. Dogfood spec
specs/tri/t27b/conformance/untyped_local.t27 passes the reference
6/6 with 13 runtime asserts.

Owner approval (translated): label owner-approved-foreign on epic
#6063, "add the label yourself and do the work".

Closes #6967
Refs #6063

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* t27b untyped_local: a typed module const is not an untyped-literal case (#6967)

The lab showed `var x = N` with `const N: u32` already passes on both
sides, so the unit test no longer expects it refused, and the spec
header says so.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* t27b: ledger and NOW entry for the untyped local (Closes #6967)

Lab corpus run on 1e6e128 vs master 6540a67: 523/831 -> 526/832
specs the reference passes, mismatch 0, reference_disagree 0.
submit.t27 moves blocked -> pass; orbitofrontal_value.t27 and the new
conformance spec untyped_local.t27 enter the ledger as pass. Cap 55 -> 54.

Refs #6063

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* feat(tri): tri mutate spec -- guard, operator and arithmetic mutants of a .t27 spec (Closes #6993 #7022) (#7043)

* feat(tri): tri mutate spec -- guard and operator mutants of a .t27 spec (Closes #6993)

`tri mutate spec --file F [--fn NAME] [--jobs N] [--timeout S]` drops
guards, flips comparisons, swaps and/or and drops `+ 1` / `- 1` inside
the functions of a spec (test and invariant blocks untouched). Each
mutant goes through `t27c gen` + `zig test` in its own temp dir; the
unmutated spec must pass first. Survivors are printed with line, kind
and text; the exit is 0 with survivors (a question, not a verdict) and
1 when a mutant could not be run, listed as NOT RUN with its cause.

Measured on the Railway lab:
- unit tests: 22 passed, 0 failed (`cargo test -p tri --release mutate`);
  one starts a `sleep` grandchild and fails if it outlives the timeout.
- controls: an unreached guard -> drop-guard survivor on its line; an
  unreached boundary -> flip-cmp survivor on its line.
- specs/queen/actors.t27 as on #6966: 105 of 110 killed; the #6971
  follow-up: 149 of 157 killed, 2 gaps closed there, 6 equivalent.
- 0 orphaned test binaries after runs with hangs (the first version
  left them spinning at 100% CPU); a failed spawn retries on EAGAIN.

cli/tri/src/mutate.rs is foreign Rust: listed in
tools/policy/foreign-exceptions.txt, label owner-approved-foreign on

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* feat(tri): tri mutate spec -- swap-arith, ret-default and one-line function sites (Refs #7022)

The first version had no arithmetic mutants: `--fn seed_hash` on the actor
spec printed "No guard or operator sites" while a wrong hash constant in it
survived the tests until a hand mutant found it.

- swap-arith: `*`<->`/`, `%`->`/`, `+`<->`-`, `&`<->`|`, `^`->`|`,
  `>>`<->`<<`, only with a space on both sides (never `->`, unary minus,
  `&&`, `*T`, `+=`).
- ret-default: a whole body becomes its type's default return (`return 0;`,
  `return 0.0;`, `return false;`, empty for void); a body that already is
  the default is skipped, a struct or array return gets none; the spanned
  lines are emptied so report line numbers stay true.
- One-line functions are sites (header masked): grep counts 326 in 72 specs,
  none of which had a site before.
- `--max` defaults to 1000: the walk is in file order, and actors.t27 alone
  has 261 mutants, so 200 left the end of the file unmutated.
- Numeric constants stay with `tri mutate run` and the hand list: a +1 on a
  hash constant whose low bits `>> 16` drops is often equivalent.

Lab (Railway): `cargo test -p tri mutate` 25 passed; release build 0.
Planted control (test pins guard and zero only): `a * 2` -> `a / 2`
reported as a swap-arith survivor on its line (applied by hand first:
`zig test` passed). `--fn seed_hash` 5 of 5 killed, `--fn jittered_seconds`
7 of 7. Whole actors.t27 (#7002 follow-up): 261 mutants, 255 killed (252 by
zig test, 3 by a hang), 73 s at --jobs 8, 0 orphans. The 6 survivors are
the known equivalents:
- 114, 131 mbox loop `<` -> `<=`: mbox_tag guards the extra index
- 224 ctl_next loop `<` -> `<=`: ctl_pending guards the extra tag
- 423 backoff `wait >= CAP` -> `>`: 10 * 2^k never equals CAP
- 427 `wait > CAP` -> `>=`: returns CAP either way at equality
- 563 reclaim `since >= ttl` -> `>`: 0 on every branch at equality
None of the 103 new mutants survived.

The full `cargo test -p tri` on the lab's sparse worktree fails 11 tests that
read files outside its cone (docs/now, ledgers, ceilings, a toolchain pin);
none is in mutate.rs. CI runs the full tree.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* feat(t27b): --check interpreter fuel per file, policy in check_budget.t27 (Closes #6664) (#6695)

t27b test --check gave the reference interpreter 50e6 steps per test; under
qemu one fuel-bound test costs ~31 s, so kernel_fib, kernel_matmul,
kernel_ternary and d_g22_test exceed the 60 s corpus timeout while proving
nothing (Stop::Fuel counts as agreement).

The policy is specs/tri/t27b/check_budget.t27: one budget of 20e6 steps per
file (about 12.3 s under qemu), deterministic rather than wall-clock, with the
four measured cases of #6664 as test vectors and invariants. cli/t27b loads
its t27c gen-rust output gen/rust/tri/t27b/check_budget.rs; the hand-written
Rust is the call-site glue in cmd_test (6 lines), owner-approved 2026-10-06.

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* verified: run_record -- when a set of receipts is one verified run (R2-4 spec half) (#7061)

* verified: run_record -- when a set of receipts is one verified run, and when it may be a verdict's run reference (Closes #7058, Refs #6655)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* verified: seal VerifiedRunRecord -- 10/10 zig, 7/7 mutants, sealed with master's t27c on the lab (Refs #7058)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* t27b: a comptime_float is a binary128 value, folded like Zig (Closes #7007) (#7045)

* spec(t27b): comptime_float conformance spec, folded vs run-time pairs (Closes #7007)

Refs #6063. Six tests, each pairing a compile-time float fold with the
same arithmetic at run time, so a fold done in f64 gets at least one
assert wrong. Reference (t27c gen + zig test): 6 pass, 13 runtime
asserts, 0 vacuous.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* t27b: a comptime_float is a binary128 value, folded like Zig (Closes #7007)

Refs #6063. Zig parses an untyped float literal to the nearest binary128,
rounds each compile-time + - * / to binary128, compares binary128 values
and rounds once to f64 or f32 where a typed float is needed. t27b held
the nearest f64 plus an exact flag and refused every inexact fold.

Val::Cf now holds float::Q, computed exactly with integers and rounded to
nearest even: literals, the four operations, comparison, one rounding to
f64 (refused past its range) and to f32 (infinity past its range, as
before), and @intFromFloat of a value that is exactly an f64.

Rust edit approved by the owner (label owner-approved-foreign on #6063).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* t27b: binary128 Q checked against the hardware f64 and exact decimals (Closes #7007)

Refs #6063. 113 >= 2 * 53 + 2, so a binary128 rounding followed by an
f64 rounding of + - * / is the f64 rounding: random f64 pairs (a fifth
subnormal or tiny) must give the hardware result bit for bit, and the
exact decimal expansion of an f64 must parse back to it.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* t27b: ledger and NOW entry for comptime_float folding (Closes #7007)

Refs #6063. comptime_float.t27, pysr_trinity_blind_test_v2.t27 and
verify_smoking_guns.t27 become pass; pass 477 -> 480, cap 53 -> 52.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* spec(queen): actors jitter, significant children, call cycle, max children; control.t27 effects journal (Closes #7002 #7003 #7004 #7005 #7006) (#7060)

* spec(queen): actors restart jitter -- pulled down, phi-hashed, pinned (Refs #7002)

backoff_seconds gives every agent of a domain the same wait, so agents that
crashed on one provider outage restart in the same second. jittered_seconds
pulls the wait down by up to JITTER_PERCENT (20) from a seed the host supplies
(the pid's slot): never above the wait, so never above the cap, and still
spread at the cap, where a long outage leaves everyone. #7002 asked for
"never below wait, never above the cap" -- together those leave zero spread at
the cap, so the bound is turned around. Akka's randomFactor and gRPC's +-20%
cross their maximum; AWS's equal jitter pulls down by half.

The seed goes through Knuth's multiplicative hash with floor(2^32 / phi) =
2654435769 first: a plain `seed % range` puts slots at a stride equal to the
range in one second.

Test jitter_spreads_one_domain_and_never_crosses_the_cap: bounds for streaks
0..8 x slots 0..63, growth below the cap, 9 distinct seconds for 10 slots at
the cap, all 3 seconds for 10 slots at stride 3 at the base wait, two pinned
draws (slot 1 = 240, slot 61 = 292).

Mutation:
- tri mutate spec (lab build of #6993): seed_hash has no guard or operator
  site; jittered_seconds 1 of 1 killed. The tool does not mutate arithmetic,
  so that count says little here.
- by hand, 12 arithmetic mutants, 12 killed: >> 15, >> 17, no shift, no
  mod 2^32, * -> + on the multiplier, * -> / on the percent, / 100 -> / 10,
  % -> / on the draw, percent 25 and 15, multiplier 2654435761 (Knuth's
  prime: killed only after the slot-61 pin), return wait.
- negative controls by hand: plain `seed % (spread + 1)` fails at
  `seconds == 3`; `wait +` instead of `wait -` fails the bound.

51 pub fns, 23 tests, 0 vacuous; parse, typecheck, gen-rust, gen-verilog,
gen-c exit 0; zig test 23/23.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* spec(queen): significant children and auto_shutdown, as OTP 24 (Refs #7003)

A supervisor may end itself when its significant children are done:
AUTO_ANY_SIGNIFICANT on any one, AUTO_ALL_SIGNIFICANT on the last active
one, AUTO_NEVER (0, the default) on none. OTP's restriction is kept:
child_spec_valid refuses a significant permanent child and any significant
child under AUTO_NEVER. auto_shutdown_after_exit counts only a child that
is not restarted (should_restart) and that ended on its own: a child its
supervisor stopped never ends the supervisor. The supervisor exits with
X_SHUTDOWN (AUTO_SHUTDOWN_REASON).

One rule beyond the issue, from OTP's own warning: auto_shutdown_sticks
says a supervisor with auto_shutdown must not be a permanent child of its
parent, or the shutdown is undone at once. That is the second reason
QUEEN_AUTO_SHUTDOWN is AUTO_NEVER: the domain supervisors are permanent
children of the root, and a test asserts it.

Counts, printed by commands: 54 pub functions (51 before), 11 invariants
(9), 24 tests (23); all 24 pass, vacuous passes 0 of 24; parse,
typecheck, gen-rust, gen-verilog, gen-c exit 0.

tri mutate spec --fn (lab build of #6993 + #7022, --jobs 8):
child_spec_valid 8 of 8 killed, auto_shutdown_after_exit 10 of 10,
auto_shutdown_sticks 2 of 2. Constants by hand (the tool does not nudge
them): 9 mutants, 1 survivor -- AUTO_ALL_SIGNIFICANT 2 -> 3 -- a real
gap: the range guard `auto_mode > AUTO_ALL_SIGNIFICANT` then admits the
non-mode 2. Killed by the new invariant the_auto_shutdown_modes_are_contiguous
(re-run: killed). The new invariant's negative control (AUTO_NEVER == 1)
fails zig at comptime.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* spec(queen): a call into its own chain is refused at once, and the chain is bounded (Refs #7004)

A runtime runs one turn at a time and a caller blocks, so a call cycle
(A calls B, B calls A) left both sides waiting out their timeouts and
looking like two hung turns (#6990). Every call now carries its chain:
one bit per slot of the callers blocked on it (this caller included) and
their count. call_admit refuses a callee already on the chain with
CALL_CYCLE before any send, alias or monitor, and a depth past
CALL_MAX_DEPTH (8) with CALL_TOO_DEEP. A cycle is named before the depth.

Prior art, read for this commit: Erlang's gen_server:call refuses only a
call to self (calling_self) and leaves longer cycles to the 5000 ms
timeout; Orleans deadlocks a non-reentrant cycle until the call times
out; Dapr refuses a call back into the chain unless reentrancy is on and
bounds a reentrant chain at maxStackDepth 32.

Choices beyond the issue, stated in the spec:
- The slot, not the pid, is on the chain: a runtime blocked on a chain is
  alive, so its slot is not reused while the chain lasts. A caller that
  dies and whose slot is reused makes a call to the new owner read as a
  cycle; that chain's reply goes to a dead alias, so nothing is lost.
- The model tracks slots 0..63 (CHAIN_SLOTS, one u64). A slot past it is
  never on the chain: a call to it is admitted unchecked, and a cycle
  through it waits out the timeout, as in Erlang. An invariant checks the
  Queen's 23 processes (control.t27's 4 domains of 4 agents, as literals
  per the owner rule) fit, given a runtime that hands out the lowest free
  slot.
- CALL_MAX_DEPTH 8 is chosen, not measured; Dapr's 32 is for a reentrant
  chain.
- A send carries no chain: it waits for nothing, so it closes no cycle.

Counts, printed by commands: 57 pub functions (54 before), 13 invariants
(11), 25 tests (24); all 25 pass, vacuous passes 0 of 25; parse,
typecheck, gen-rust, gen-verilog, gen-c exit 0.

tri mutate spec --fn (lab build of #6993 + #7022, --jobs 8): chain_has
6 of 6 killed, chain_add 5 of 5, call_admit 4 of 4. By hand: 13 mutants
(the 4 new constants up and down, << to >>, | to ^ and &, > to >=, the
two guards swapped), 13 killed. The two new invariants' negative controls
(CALL_TOO_DEEP == 6; a depth bound past the model; a population of 4 x 16
agents) each fail zig at comptime.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* docs(now): actors jitter, significant children, call cycle -- whole-file mutation count (Refs #6971)

The three follow-ups (#7002, #7003, #7004) in one NOW entry, with the
whole-file tri mutate spec run on this branch: 296 mutants, 290 killed,
the 6 known equivalents survive, 0 of the 35 new.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* spec(queen): a full domain refuses a new start and still restarts its own (Refs #7005)

start_answer(live, stopping, max_children) refuses a start past the bound
with START_MAX_CHILDREN, inside the supervisor's own turn, so two starts
decided on one stale count (control.t27 placement) cannot both pass.
A child being stopped counts until its EXIT. children_after_exit keeps a
restarted child's place, so a restart never asks the bound.

The issue asked for a per-domain MAX_CHILDREN constant. It is not added:
control.t27 already owns DOMAIN_CAP and placement's P_WAIT, so a second
constant would be a second home for one number. The bound is a parameter
the Queen fills from DOMAIN_CAP; a refused start leaves control.t27's
P_WAIT (the task stays unleased), never a drop.

Prior art: Elixir DynamicSupervisor checks max_children in handle_call,
does not check it on restart, and deletes a terminated child only after
its exit; a Temporal worker with no free slot stops polling.

Mutants: tool 8 of 8 killed (start_answer 4, children_after_exit 4);
hand 8 of 8 killed. Without the new invariant, START_OK 0 -> 1 and
START_MAX_CHILDREN 1 -> 0 both survive, so the invariant is what pins
them. 59 pub fn, 14 invariants, 26 tests, 26 passed, 0 vacuous.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* docs(now): actors max children -- counts and whole-file run after #7005 (Refs #7005)

59 pub fn, 14 invariants, 26 tests; whole file 304 mutants, 298 killed,
the same 6 equivalents. The "35 mutants added since" line is replaced by
a claim the survivor lines check: none sits on a line #7002-#7005 added.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* spec(queen): an effects journal so a new lease holder does not repeat what the old one did (Refs #7006)

A fence stops the old holder's writes, not what it already did outside:
a crash after a push but before the next journal write left the new
holder to push again, open a second pull request or post a second
comment. control.t27 section 7 adds the journal's contract:

- an entry per effect, intent written before it and done after it, at
  the holder's fence; the key is (task, kind, target), not the position
  (a model turn is not deterministic, so Temporal/Restate's replay by
  position does not apply) and not the fence (every retry must see the
  same key, as Temporal's run id + activity id leaves the attempt out);
- effect_action: a stale fence does nothing; no entry runs; done skips;
  an open intent looks the effect up at GitHub where it can
  (push, pull request, comment) and runs again where it cannot (a model
  call repeats once per crash that leaves its intent open);
- look_wait_seconds: after a DOWN, a look waits out GitHub's 10 s
  request limit, so a request the old holder sent cannot land after the
  look; an invariant keeps that wait under the first heartbeat;
- effect_may_repeat: a push (leased) and a pull request (one per head,
  422) are refused by the receiver; a comment can still repeat behind a
  partition, and the journal's marker only makes the copy detectable.

actors.t27 reclaim_wait_seconds points at the journal (doc only; the
spec does not import control.t27, T7).

Counts printed by commands: control.t27 42 pub fn, 8 invariants,
15 tests, 15/15 zig, 0 vacuous; actors.t27 59/14/26 unchanged, 26/26.
tri mutate spec --fn on the 7 new functions (lab, #7043 build): 36 of
36 killed after one gap: dropping `seconds_since_down > LIMIT` survived
(at 11 s both paths return 0); asserts at 12 s and 3600 s now kill it
(the u32 subtraction underflows). Hand constant mutants 16/16 killed;
without the_effect_codes_are_distinct the four DO_* mutants survive,
so that invariant is what pins the action codes.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* docs(now): control.t27 effects journal -- design, counts and mutation run (Refs #7006)

The entry now closes #7006 too: the journal key, effect_action,
look_wait_seconds and effect_may_repeat, the answer to the issue's
Restate question, and the counts and mutation results printed by
commands in the same tick (control.t27 42/8/15, 36 of 36 tool mutants
after one gap, 16 hand constant mutants).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* spec(queen): name the assumption under the journal's look wait (Refs #7006)

GitHub documents that it terminates a request after 10 s; it does not
document that a write it terminated is never applied later. The look
wait rests on that assumption, so the doc now says so, and says what
fails if it is wrong: a comment can repeat even after a DOWN, and its
marker shows the copy. Doc only; 15/15 tests unchanged.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* spec(t27b): std_mem_byte_slice put returns pos + i, not a third copy of an existing body

duplicate-bodies flagged put() as byte-identical to gen_w384_lean.t27 and ls.t27. The return now uses the loop counter (equal to s.len after the loop). Lab: t27c test-report 6 pass, 0 vacuous; t27b pass, mismatch 0.

Refs #6063

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

---------

Co-authored-by: Trinity Bee <bee@trinity.local>
Co-authored-by: queen-publisher[bot] <noreply@anthropic.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Dmitrii Fedorov <dmitrii.f@t27.ai>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

policy: foreign-exceptions.txt is missing the pre-rule files modified by label-gated PRs #6826/#6847

1 participant