Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
57 changes: 57 additions & 0 deletions docs/changelog.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,63 @@

A rolling log of what just landed and what's actively underway in the compiler. For the full spec and pipeline docs see `compiler/SPEC.md` and `compiler/PIPELINE.md`.

## S393 — 2026-09-01 (bryan · ASUS-Vivobook) — the session where verification kept changing the answer

**Seven PRs merged** (#805 #807 #808 #809 #810 #811, +#806 pre-boot). Boot 32.3%.

**The result that matters is not a landing.** Nine adversarial reviews and two fix rounds ran; what
they produced was **four premises dying on contact with execution, two of them mine**, and three of
my own instruments returning confident wrong answers.

### Landings
- **#807** — review floor drained **9 OWED → 0**, verified by re-running the probe. Six carve-out,
three finding; code-bearing carve-out rate **0/3**.
- **#808** — ten verified gap entries + **three corrections to existing entries**, each striking a
statement that read as accurate and was not.
- **#805** — peter's two `<each>`-interp codegen drops, landed only after an S239 pass found a
**silent-data-loss regression** (a value-form `if` in a `<textarea>` gained an injected element
child; RCDATA + element child reads `value === ""`), a fix round, and a re-review against the new
SHA. Landed with ONE known narrow regression (`<title>`), stated in the commit and filed.
- **#809** — peter's routes answered by execution; return leg written, committed AND pushed.
- **#810** — the two adopter `Direction:` issues banked as `dpa-038` / `dpa-039`, 21 and 24 days after
first being named.
- **#811** — the **if-chain descent class** closed across ten walks on `ast-if-chain.js`.

### The if-chain class
`collapseIfChains` rewrites a chain into `{kind:"if-chain", branches:[{condition,element}],
elseBranch}` — keys no hand-rolled walk recursed into, and `branches` holds RECORDS with no `.kind`.
#805 fixed six walks; #811 closed ten more. **The dispatch brief's traced root was wrong**: the real
hole was `type-system.ts`, whose `visitNode` had no case, so the entire chain subtree was unvisited.
A second brief premise was wrong in the dangerous direction — a comment above a deliberately-TOTAL
walk that routing would have NARROWED.

**Both halves landed together by design.** Removing the false `E-STATE-UNDECLARED` was correct and
could not ship alone — it was the last diagnostic in front of the uninitialised-cell hole, so alone it
converted a loud failure into a silent blank render. `reactive-deps.ts` (13 collectors) + `collect.ts`
joined the arc; `reactive-deps.ts` alone did NOT clear the bar, producing subscribed reads of a cell
that is never created.

⚑ **An agent walked into a server leak and backed out.** Closing `collect.ts`'s `collectFunctions`
emitted a `server fn` BODY into `client.js` with no `server.js`. It ran a control confirming it had
introduced the leak, reverted, filed HIGH, and shipped a LEAK GUARD proven to red on exactly that
mistake. Trading a loud `ReferenceError` for a silent server-code-in-client leak is strictly worse.

Evidence: double-emission probed over 2,198 files (40 descents, **0 duplicates**, positive control 16);
oracle parity on 7 shapes; security scanned **absolute not differential** (2,269 bundles per tip, same
56 files, byte-identical marker sets); conformance 889/889.

### Owed to bryan
⚑⚑ **A ratified limb of the S371 value-form ruling was INVERTED** — *"else required on every path"*
became `SHALL NOT require a trailing else`, on a dispatch brief's authority. Surfaced, not adjudicated.
Plus `g-if-chain-all-arms-run-at-module-init` (landed knowingly — the property never held; a lone `if=`
with a FALSE condition fires its body on untouched main) and the bound-sugar HIGH.

### Misses
A gate poll reported `GATE PASS` off the **previous SHA's** run — merging on it would have claimed a
green gate that never ran. My first channel-mount reproducer was wrong (a pure-channel file needs
`export <channel …>`). I nearly reported a cross-repo delivery failure that does not exist (checked:
9 of 9 delivered). **Three instruments, three wrong answers, none caught by remembering.**

## S392 — 2026-08-31 (peter · P-Tech1 Windows) — two `<each>`-interp codegen fixes, and a ledger that was inflated with already-closed gaps

Two silent-wrong `<each>`-interp bugs fixed (PR #805, gate-green), plus the recurring lesson that
Expand Down
3 changes: 3 additions & 0 deletions docs/pr-reviews.md
Original file line number Diff line number Diff line change
Expand Up @@ -1037,3 +1037,6 @@ surface, safe to take only because he is not live** ([[review-floor-is-shared-su
<!-- @review pr=805 verdict=finding by=S393-bryan date=2026-09-01 probe=CODE-BEARING — TWO full S239 passes plus a fix round between them, and the PA re-executed every load-bearing claim rather than relaying it. PASS 1 (on 3e8a7a4a) returned 2 MED: (a) a value-form `if` in a <textarea> inside an <each> body gained an injected <span data-scrml-mv> ELEMENT CHILD where main emitted a text assignment — an RCDATA element with an element child reads value === "", total loss of the adopter's string at exit 0; (b) the if-chain descent went into six walks but not lint-w-each-key.js, so an <each> under if=/else lost W-EACH-KEY-001 while now genuinely rendering with index-identity reconcile. PA REPRODUCED (a) two-sided on a detached worktree before dispatching the fix round. PASS 2 bound to the NEW SHA 06014c93 (a fix round invalidates the review that produced it) and returned findings-non-blocking: the six-site refactor into ast-if-chain.js is set-equivalent (the reviewer tried to construct a distinguishing input and could not — collapseIfChains only builds branches from truthy markup nodes and every walk guards its entry), and emit-inertness was independently re-measured at 0 emit / 0 diagnostic / 0 crash deltas over 1,912 files, POSITIVE-CONTROLLED. All four mutations bite in both directions; the PR's own pin still reds 3/6 if its descent is removed. PA ran its own R26 empirical check: the reproducer's post-fix emit is BYTE-IDENTICAL to main. ⚑ LANDED WITH ONE KNOWN REGRESSION, STATED IN THE COMMIT BODY AND FILED, NOT HIDDEN: <title> in an <each> per-item body still takes the element-child path, because isRcdataElement is registry-driven and <title> has NO registry row (html-elements.js:279 says so and calls the row "a cheap follow-up"). Holding a HIGH fix — zero renderers plus two FALSE E-DG-002 telling the adopter to delete cells in use — for one <title> per list item was judged the wrong trade. note=two-S239-passes-one-fix-round-and-a-knowingly-landed-narrow-regression -->
<!-- @review pr=807 verdict=carve-out by=S393-bryan date=2026-09-01 probe=docs-only, MEASURED not assumed: `gh pr diff 807 --name-only` returns exactly TWO files — docs/pr-reviews.md and docs/changes/s393-pr805-fix-round/BRIEF.md — and ZERO matching ^(compiler/|stdlib/|conformance/cases/|scripts/); direction=inert. Content: the nine-marker floor drain (9 OWED -> 0, verified by re-running the probe) plus the verbatim S136 archival of the #805 fix-round dispatch prompt. Same structural recursion #541 recorded — a floor binding MERGED PRs can never read zero at the moment a floor-recording PR merges, so this row was always going to be owed to the next batch. note=docs-only-floor-drain-plus-brief-archival -->
<!-- @review pr=808 verdict=carve-out by=S393-bryan date=2026-09-01 probe=docs-only, MEASURED: docs/known-gaps.md + handOffs/delta-log.md; ZERO code-bearing. Content: ten verified gap entries (4 HIGH / 4 MED / 2 LOW) and three corrections to existing entries. ⚑ This is the PR where the carve-out label is most misleading and the note matters: no code changed, but the CONTENT is verification work — every entry is labelled either PA-reproduced-by-execution or RELAYED-UNVERIFIED / INSPECTION-ONLY, precisely so a reviewer's claim never reads as PA-confirmed downstream. The three corrections each struck a statement that read as accurate and was not: a repair recorded as "explicitly NOT fixed here" that #800 had fixed (its locus named a test case that no longer exists anywhere in compiler/); a root-cause narrative asserting dev has no "/" fold when dev.js:1027 does the same fold INTO the gated loop; and a cost prediction that limb (a) "will turn some of the 18 RED" when running the real harness turns ZERO red. gap-counts moved HIGH 72->76, MED 194->198, LOW 84->86 — exactly the ten new entries, which is the proof they are machine-visible rather than prose-only. note=verification-content-in-a-docs-only-diff-plus-three-stale-claims-struck -->
<!-- @review pr=809 verdict=carve-out by=S393-bryan date=2026-09-01 probe=docs-only, MEASURED: 4 files — the return leg to peter, docs/pr-reviews.md, docs/changes/s393-if-chain-class/BRIEF.md, handOffs/delta-log.md; ZERO matching ^(compiler/|stdlib/|conformance/cases/|scripts/); direction=inert. ⚑ The CONTENT is PA execution, not correspondence: peter's channel-mount matrix was re-run independently (his correction CONFIRMED, plus a FOURTH cell he did not have — one <each> in the arm deletes E-CHANNEL-MOUNT-IN-CONDITIONAL, which is what shows his limb (b) IS arc (b), already ratified+promoted at S385, so no ruling is owed) and his colorless-async matrix reproduced four-cell. Delivery verified against origin/main, not against a status: field the author wrote — the S385 last-hop failure. note=return-leg-delivered-and-verified-on-origin-main -->
<!-- @review pr=810 verdict=carve-out by=S393-bryan date=2026-09-01 probe=docs-only, MEASURED: handOffs/dpa-queue.md + handOffs/delta-log.md; ZERO code-bearing. Content: the two adopter Direction issues banked as dpa-038/dpa-039 in the ONLY file the dPA drains (S319 — banked elsewhere is never banked). dpa-038 carries a PA-verified fact that removes a third of its question: 6nz has ZERO service-worker files, ZERO manifest, ZERO serviceWorker references, so the "offline-first PWA" the adopter was told to copy is a README design-GOAL line, not a shipped pattern. dpa-039 carries the opposite warning: its five premises are adopter-surveyed and phase 1 of that DD must verify them BY EXECUTION. note=banking-with-one-fact-established-and-one-explicitly-unverified -->
<!-- @review pr=811 verdict=finding by=S393-bryan date=2026-09-01 probe=CODE-BEARING, emit-changing — TWO adversarial passes with a fix round between them, plus PA reproduction of every load-bearing claim. Closes the if-chain descent class across TEN walks on ast-if-chain.js. ⚑ The dispatch brief's traced root was WRONG (type-system.ts visitNode had no case, so the ENTIRE chain subtree was unvisited; symbol-table.ts was blind but secondary) and a second brief premise was wrong in the DANGEROUS direction (a comment above a deliberately-TOTAL walk, which routing would have NARROWED) — both caught by the brief's own verify-instruction. Governing-sentence gate discharged BEFORE dispatch: SPEC.md:2071 §6.1.1 makes the branch-declared cell's read legal, so the accepting half is base §8 toward-the-contract restoration, not a widening. BOTH HALVES LANDED TOGETHER because removing the false error alone converts a loud failure into a silent blank render (PA-reproduced two-sided); reactive-deps.ts alone did NOT clear the bar, producing subscribed reads of a cell never created. Acceptance = exact lone-if oracle parity 1/1/4/3, PA-verified and re-verified on merged main. ⚑ AN AGENT WALKED INTO A SERVER LEAK AND BACKED OUT: closing collectFunctions puts a server fn BODY in client.js with no server.js; reverted, filed HIGH, LEAK GUARD proven to red on exactly that mistake. Evidence: double-emission probed over 2,198 files (40 descents, 0 duplicates, positive control 16); oracle parity on 7 shapes incl. elseBranch/nested/inside-each/inside-component; migration round 1 = 6 files +8 E-SCOPE-001 and nothing else, round 2 = 1 emit change on a REJECTING compile; security ABSOLUTE not differential (2,269 bundles per tip, same 56 files, byte-identical marker sets); conformance 889/889. LANDED WITH ONE KNOWN SPEC DIVERGENCE, filed: g-if-chain-all-arms-run-at-module-init — every arm's ${} body runs at module init, last writer wins, against §17.1.1. Landed because the property NEVER held (PA-verified: a LONE if= with a FALSE condition still fires its body on untouched main), so this is parity with existing non-conformance, no currently-correct program regresses, corpus impact measured zero. Closing it is a RULING about markup-${}-body scoping and changes lone if= too. note=class-closed-server-leak-backed-out-one-known-spec-divergence-landed-and-filed -->
Loading
Loading