Skip to content

Commit 4ed5eda

Browse files
committed
P-037-X Stage 1: re-record the census, the controls and the #380 pins on the research branch
EXPLORATORY record on research/p037-max-v1 only; never main, never #304 (frozen 2026-09-28, unchanged). Every re-recorded file keeps its superseded value verbatim in an append-only entry that names the Stage-1 carrier commit 702d25b and classifies the move as a research-branch measurement, not a production baseline: - corpus/p037-shapes (9 of 14): the caller records that #380 dropped return (`record: absent` -> `present`, the absence kept as superseded), `Outer.s` no -> may on the bare/negated forward shapes, OWN051 where the fold used to sit; 5 shapes unchanged. - corpus/p036-bakeoff (4 controls): findings ['OWN051'] on both engines, no fabricated release at the call site, never a consume. The `post_a1` layer is untouched: it is the A1 acceptance record, and `p037_controls.py --post-a1` is documented and CI-configured as expected to fail until A1 lands. Stage 1 is not A1 and reads no guard value. - tests/test_guarded_consume.py: the definite consumers are carried as canonical `call` ops and OWN002 is derived by the core (INF-S2 on the callee + A1) instead of fabricated by the extractor; the four kept streams pin exactly the OWN051 advisory (no fabricated release, no fabricated leak, and not silence: silence would mean the carrier is gone); BorrowingWrapper.borrowed and ForwardDynamic.forwarded pinned `may`, the latter being the pin's own "canonical call facts arrived" branch. Whether #304 reopen condition 1 is met by an exploratory carrier is the owner's decision and is not claimed. Verified on this tree: scripts/p037_fact_shapes.py check --engine both (14/14 match), scripts/p037_controls.py --engine both (all match), the re-recorded tests/test_guarded_consume.py (0 failed), ruff clean. The full tests/run_tests.py with OWN_TIERB_REQUIRED=1 was run before this re-record: every module green except the six pins re-recorded here, test_p037_evidence's fresh-record-valid (it refuses a dirty tree, which this commit resolves) and test_verify_target_tierb's incompat chain, which needs a .NET 9 SDK this container does not carry (NETSDK1045) and is unrelated to the change. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Am9eQwzNfbugH72eVKetC2
1 parent 2d2ba15 commit 4ed5eda

14 files changed

Lines changed: 1281 additions & 98 deletions

File tree

‎corpus/p036-bakeoff/gv4-control-aliased-self-null/expected.json‎

Lines changed: 32 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -3,12 +3,14 @@
33
"control": "gv4-control-aliased-self-null",
44
"p037": "§8 row 19 — G-V4, writably aliased self-null resource parameter",
55
"classification": "KNOWN_FALSE_POSITIVE",
6-
"measured_at": "f164dd3",
6+
"measured_at": "702d25b",
77
"owner_ruling": "2026-09-18: accepted as pre-A1 regression anchors, not as authorization for a pre-cutover fix; no ConsumesParam change before P-022 Stage 3",
88
"call_site_line": 29,
99
"defensive_dispose_line": 30,
1010
"current": {
11-
"findings": [],
11+
"findings": [
12+
"OWN051"
13+
],
1214
"fabricated_release_at_call_site": false
1315
},
1416
"post_a1": {
@@ -61,6 +63,34 @@
6163
},
6264
"result": "CHANGED — `current` re-recorded to the new measurement, which equals the `post_a1` record this file has carried since the controls landed on main (afeca38, 2026-09-18; the record was measured at 70189a3) and which is unchanged here: the new expectation was not chosen after the fix. P-037 is not implemented by this; `post_a1` being met is a consequence of removing the fabricated release, not of cell selection.",
6365
"classification": "ACCEPTED BASELINE MOVEMENT CAUSED BY #380 — NOT a P-037 implementation, NOT a reopen of #304, NOT evidence that the A2 contract is satisfied"
66+
},
67+
{
68+
"at": "702d25b",
69+
"on": "2026-09-29",
70+
"why": "P-037-X Stage 1 (research/p037-max-v1, EXPLORATORY): canonical first-party call transport. A statement-form invocation of a first-party owned-parameter callee that carries a record is lowered as ONE OwnIR `call` op for its tracked handles (no `release`/`use` fold), and a canonically forwarded local is no longer an escape, so caller records that #380 dropped return.",
71+
"engines": {
72+
"python": {
73+
"findings": [
74+
"OWN051"
75+
],
76+
"fabricated_release_at_call_site": false
77+
},
78+
"rust": {
79+
"findings": [
80+
"OWN051"
81+
],
82+
"fabricated_release_at_call_site": false
83+
}
84+
},
85+
"superseded_current": {
86+
"measured_at": "f164dd3",
87+
"current": {
88+
"findings": [],
89+
"fabricated_release_at_call_site": false
90+
}
91+
},
92+
"result": "CHANGED — exploratory Stage-1 record; the honest call reaches the MOS, so the `may` callee yields the INF-A5 optimistic untrack plus its OWN051 advisory where the fold used to sit",
93+
"classification": "EXPLORATORY P-037-X STAGE-1 RECORD — a research-branch measurement, NOT a production baseline, NOT a reopen of #304, NOT a P-037 implementation (no guard value is read by any engine at this stage)"
6494
}
6595
],
6696
"note": "Close disposes r through the alias, not the caller's s; today Close(s, other) is lowered to a release of s (may-as-must), so s.Dispose() is a false OWN003. After A1: no split for the aliased q, no release op at the call, the dispose is clean.",

‎corpus/p036-bakeoff/gv4-control-mutated-guard/expected.json‎

Lines changed: 32 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -3,12 +3,14 @@
33
"control": "gv4-control-mutated-guard",
44
"p037": "§8 row 18a — G-V4, mutated guard (direct write)",
55
"classification": "KNOWN_FALSE_POSITIVE",
6-
"measured_at": "f164dd3",
6+
"measured_at": "702d25b",
77
"owner_ruling": "2026-09-18: accepted as pre-A1 regression anchors, not as authorization for a pre-cutover fix; no ConsumesParam change before P-022 Stage 3",
88
"call_site_line": 39,
99
"defensive_dispose_line": 40,
1010
"current": {
11-
"findings": [],
11+
"findings": [
12+
"OWN051"
13+
],
1214
"fabricated_release_at_call_site": false
1315
},
1416
"post_a1": {
@@ -61,6 +63,34 @@
6163
},
6264
"result": "CHANGED — `current` re-recorded to the new measurement, which equals the `post_a1` record this file has carried since the controls landed on main (afeca38, 2026-09-18; the record was measured at 70189a3) and which is unchanged here: the new expectation was not chosen after the fix. P-037 is not implemented by this; `post_a1` being met is a consequence of removing the fabricated release, not of cell selection.",
6365
"classification": "ACCEPTED BASELINE MOVEMENT CAUSED BY #380 — NOT a P-037 implementation, NOT a reopen of #304, NOT evidence that the A2 contract is satisfied"
66+
},
67+
{
68+
"at": "702d25b",
69+
"on": "2026-09-29",
70+
"why": "P-037-X Stage 1 (research/p037-max-v1, EXPLORATORY): canonical first-party call transport. A statement-form invocation of a first-party owned-parameter callee that carries a record is lowered as ONE OwnIR `call` op for its tracked handles (no `release`/`use` fold), and a canonically forwarded local is no longer an escape, so caller records that #380 dropped return.",
71+
"engines": {
72+
"python": {
73+
"findings": [
74+
"OWN051"
75+
],
76+
"fabricated_release_at_call_site": false
77+
},
78+
"rust": {
79+
"findings": [
80+
"OWN051"
81+
],
82+
"fabricated_release_at_call_site": false
83+
}
84+
},
85+
"superseded_current": {
86+
"measured_at": "f164dd3",
87+
"current": {
88+
"findings": [],
89+
"fabricated_release_at_call_site": false
90+
}
91+
},
92+
"result": "CHANGED — exploratory Stage-1 record; the honest call reaches the MOS, so the `may` callee yields the INF-A5 optimistic untrack plus its OWN051 advisory where the fold used to sit",
93+
"classification": "EXPLORATORY P-037-X STAGE-1 RECORD — a research-branch measurement, NOT a production baseline, NOT a reopen of #304, NOT a P-037 implementation (no guard value is read by any engine at this stage)"
6494
}
6595
],
6696
"note": "Today the extractor lowers Outer(r, true) to a release of r (may-as-must ConsumesParam), so the honest r.Dispose() is a false OWN003. After A1 the call must carry no release op and lower to plain + OWN051; the dispose is clean.",

‎corpus/p036-bakeoff/gv4-control-ref-alias-guard/expected.json‎

Lines changed: 32 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -3,12 +3,14 @@
33
"control": "gv4-control-ref-alias-guard",
44
"p037": "§8 row 18b — G-V4, writable ref-alias of the guard",
55
"classification": "KNOWN_FALSE_POSITIVE",
6-
"measured_at": "f164dd3",
6+
"measured_at": "702d25b",
77
"owner_ruling": "2026-09-18: accepted as pre-A1 regression anchors, not as authorization for a pre-cutover fix; no ConsumesParam change before P-022 Stage 3",
88
"call_site_line": 36,
99
"defensive_dispose_line": 37,
1010
"current": {
11-
"findings": [],
11+
"findings": [
12+
"OWN051"
13+
],
1214
"fabricated_release_at_call_site": false
1315
},
1416
"post_a1": {
@@ -61,6 +63,34 @@
6163
},
6264
"result": "CHANGED — `current` re-recorded to the new measurement, which equals the `post_a1` record this file has carried since the controls landed on main (afeca38, 2026-09-18; the record was measured at 70189a3) and which is unchanged here: the new expectation was not chosen after the fix. P-037 is not implemented by this; `post_a1` being met is a consequence of removing the fabricated release, not of cell selection.",
6365
"classification": "ACCEPTED BASELINE MOVEMENT CAUSED BY #380 — NOT a P-037 implementation, NOT a reopen of #304, NOT evidence that the A2 contract is satisfied"
66+
},
67+
{
68+
"at": "702d25b",
69+
"on": "2026-09-29",
70+
"why": "P-037-X Stage 1 (research/p037-max-v1, EXPLORATORY): canonical first-party call transport. A statement-form invocation of a first-party owned-parameter callee that carries a record is lowered as ONE OwnIR `call` op for its tracked handles (no `release`/`use` fold), and a canonically forwarded local is no longer an escape, so caller records that #380 dropped return.",
71+
"engines": {
72+
"python": {
73+
"findings": [
74+
"OWN051"
75+
],
76+
"fabricated_release_at_call_site": false
77+
},
78+
"rust": {
79+
"findings": [
80+
"OWN051"
81+
],
82+
"fabricated_release_at_call_site": false
83+
}
84+
},
85+
"superseded_current": {
86+
"measured_at": "f164dd3",
87+
"current": {
88+
"findings": [],
89+
"fabricated_release_at_call_site": false
90+
}
91+
},
92+
"result": "CHANGED — exploratory Stage-1 record; the honest call reaches the MOS, so the `may` callee yields the INF-A5 optimistic untrack plus its OWN051 advisory where the fold used to sit",
93+
"classification": "EXPLORATORY P-037-X STAGE-1 RECORD — a research-branch measurement, NOT a production baseline, NOT a reopen of #304, NOT a P-037 implementation (no guard value is read by any engine at this stage)"
6494
}
6595
],
6696
"note": "Same mechanism as row 18a; the alias write must disqualify the guard (fail-closed) and the call must not fabricate a consume.",

‎corpus/p036-bakeoff/legacy-honesty-else-unresolved-forward/expected.json‎

Lines changed: 32 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -3,12 +3,14 @@
33
"control": "legacy-honesty-else-unresolved-forward",
44
"p037": "G-T2b class 3 — guarded local release, unresolved forward on the other branch",
55
"classification": "VERDICT_COMPATIBLE_VALUE_DIFFERENCE",
6-
"measured_at": "f164dd3",
6+
"measured_at": "702d25b",
77
"owner_ruling": "2026-09-18: accepted as pre-A1 regression anchors, not as authorization for a pre-cutover fix; no ConsumesParam change before P-022 Stage 3",
88
"call_site_line": 41,
99
"defensive_dispose_line": null,
1010
"current": {
11-
"findings": [],
11+
"findings": [
12+
"OWN051"
13+
],
1214
"fabricated_release_at_call_site": false
1315
},
1416
"post_a1": {
@@ -55,6 +57,34 @@
5557
},
5658
"result": "CHANGED — `current` re-recorded to the new measurement, which equals the `post_a1` record this file has carried since the controls landed on main (afeca38, 2026-09-18; the record was measured at 70189a3) and which is unchanged here: the new expectation was not chosen after the fix. P-037 is not implemented by this; `post_a1` being met is a consequence of removing the fabricated release, not of cell selection.",
5759
"classification": "ACCEPTED BASELINE MOVEMENT CAUSED BY #380 — NOT a P-037 implementation, NOT a reopen of #304, NOT evidence that the A2 contract is satisfied"
60+
},
61+
{
62+
"at": "702d25b",
63+
"on": "2026-09-29",
64+
"why": "P-037-X Stage 1 (research/p037-max-v1, EXPLORATORY): canonical first-party call transport. A statement-form invocation of a first-party owned-parameter callee that carries a record is lowered as ONE OwnIR `call` op for its tracked handles (no `release`/`use` fold), and a canonically forwarded local is no longer an escape, so caller records that #380 dropped return.",
65+
"engines": {
66+
"python": {
67+
"findings": [
68+
"OWN051"
69+
],
70+
"fabricated_release_at_call_site": false
71+
},
72+
"rust": {
73+
"findings": [
74+
"OWN051"
75+
],
76+
"fabricated_release_at_call_site": false
77+
}
78+
},
79+
"superseded_current": {
80+
"measured_at": "f164dd3",
81+
"current": {
82+
"findings": [],
83+
"fabricated_release_at_call_site": false
84+
}
85+
},
86+
"result": "CHANGED — exploratory Stage-1 record; the honest call reaches the MOS, so the `may` callee yields the INF-A5 optimistic untrack plus its OWN051 advisory where the fold used to sit",
87+
"classification": "EXPLORATORY P-037-X STAGE-1 RECORD — a research-branch measurement, NOT a production baseline, NOT a reopen of #304, NOT a P-037 implementation (no guard value is read by any engine at this stage)"
5888
}
5989
],
6090
"note": "0 findings at warning severity today AND after A1 (class 3 is verdict-equivalent). The facts layer differs: today the extractor lowers M(r, flag, sink) to a release (may-as-must) and even the OWN051 advisory is suppressed; after A1 the guarded value is unknown, the call is plain + OWN051 at note level, and no release op may appear at the call site. The value-level pin (unknown, never repaired to may) is the kernel test k11_finding_release_priority_drops_an_unresolved_forward.",

‎corpus/p037-shapes/call-expression-statement/expected.json‎

Lines changed: 121 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -19,11 +19,16 @@
1919
},
2020
{
2121
"function": "ShapeStatementCall.Caller",
22-
"record": "absent",
23-
"since": "#380"
22+
"record": "present",
23+
"since": "p037x-stage1",
24+
"superseded_absence": {
25+
"function": "ShapeStatementCall.Caller",
26+
"record": "absent",
27+
"since": "#380"
28+
}
2429
}
2530
],
26-
"measured_at": "f164dd3",
31+
"measured_at": "702d25b",
2732
"facts": {
2833
"ShapeStatementCall.Inner": {
2934
"params": [
@@ -51,16 +56,57 @@
5156
}
5257
]
5358
}
59+
},
60+
"ShapeStatementCall.Caller": {
61+
"params": null,
62+
"body": [
63+
"acquire:r@25",
64+
"call:ShapeStatementCall.Inner@26[args=['r']]"
65+
],
66+
"guarded_facts": {
67+
"version": 1,
68+
"calls": [
69+
{
70+
"site": {
71+
"line": 26,
72+
"column": 9
73+
},
74+
"statement_line": 26,
75+
"form": "statement",
76+
"callee": "ShapeStatementCall.Inner",
77+
"sig": "System.IO.Stream,System.Boolean",
78+
"first_party": true,
79+
"args": [
80+
{
81+
"param": 0,
82+
"kind": "var",
83+
"name": "r"
84+
},
85+
{
86+
"param": 1,
87+
"kind": "bool_const",
88+
"value": true
89+
}
90+
]
91+
}
92+
],
93+
"guards": []
94+
}
5495
}
5596
},
5697
"verdict": {
57-
"rust": [],
58-
"python": []
98+
"rust": [
99+
"OWN051:note@26"
100+
],
101+
"python": [
102+
"OWN051:note@26"
103+
]
59104
},
60105
"status_history": [
61106
"pending_a2 (recorded at 464308b)",
62107
"anchored (A2.1 sidecar)",
63-
"anchored — baseline transition #380 at f164dd3 (caller record absent; A2 carrier lost, asserted as absent)"
108+
"anchored — baseline transition #380 at f164dd3 (caller record absent; A2 carrier lost, asserted as absent)",
109+
"p037x-stage1 exploratory record at 702d25b (canonical call transport)"
64110
],
65111
"baseline_transitions": [
66112
{
@@ -147,6 +193,75 @@
147193
},
148194
"known_limitation": "canonical first-party call transport remains absent: the honest call reaches the facts only through the sidecar of a record that ordinary relevance filtering may drop",
149195
"note": "docs/notes/p037-fact-shape-baseline-transition-380.md"
196+
},
197+
{
198+
"id": "p037x-stage1",
199+
"on": "2026-09-29",
200+
"from": {
201+
"measured_at": "f164dd3"
202+
},
203+
"to": {
204+
"measured_at": "702d25b"
205+
},
206+
"cause": "P-037-X Stage 1 (research/p037-max-v1, EXPLORATORY): canonical first-party call transport. A statement-form invocation of a first-party owned-parameter callee that carries a record is lowered as ONE OwnIR `call` op for its tracked handles (no `release`/`use` fold), and a canonically forwarded local is no longer an escape, so caller records that #380 dropped return.",
207+
"classification": "EXPLORATORY P-037-X STAGE-1 RECORD — a research-branch measurement, NOT a production baseline, NOT a reopen of #304, NOT a P-037 implementation (no guard value is read by any engine at this stage)",
208+
"consequences": [
209+
"ShapeStatementCall.Caller: record absent -> ['acquire:r@25', \"call:ShapeStatementCall.Inner@26[args=['r']]\"]",
210+
"verdict: {'rust': [], 'python': []} -> {'rust': ['OWN051:note@26'], 'python': ['OWN051:note@26']}"
211+
],
212+
"superseded": {
213+
"facts": {
214+
"ShapeStatementCall.Inner": {
215+
"params": [
216+
{
217+
"name": "s",
218+
"line": 15
219+
}
220+
],
221+
"body": [
222+
"if:None@17",
223+
"then:release:s@19"
224+
],
225+
"guarded_facts": {
226+
"version": 1,
227+
"calls": [],
228+
"guards": [
229+
{
230+
"site": {
231+
"line": 17,
232+
"column": 9
233+
},
234+
"param": 1,
235+
"predicate": "truth",
236+
"negated": true
237+
}
238+
]
239+
}
240+
}
241+
},
242+
"verdict": {
243+
"rust": [],
244+
"python": []
245+
},
246+
"a2_expect": [
247+
{
248+
"function": "ShapeStatementCall.Inner",
249+
"guard": {
250+
"site": {
251+
"line": 17
252+
},
253+
"param": 1,
254+
"predicate": "truth",
255+
"negated": true
256+
}
257+
},
258+
{
259+
"function": "ShapeStatementCall.Caller",
260+
"record": "absent",
261+
"since": "#380"
262+
}
263+
]
264+
}
150265
}
151266
]
152267
}

0 commit comments

Comments
 (0)