From 977393ba20be9f60a97dad0be4deb1097a8ca5c0 Mon Sep 17 00:00:00 2001 From: Cameron Pfiffer Date: Tue, 4 Aug 2026 00:44:21 -0700 Subject: [PATCH] Remove public API orphans. MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Public visibility no longer exempts zero-consumer core helpers from the living-spec dead-code rule, and recurring compatibility findings stay queued for bounded follow-up. 👾 Generated with [Letta Code](https://letta.com) Co-Authored-By: Letta Code --- crates/misaligned-core/src/intents.rs | 11 ---- crates/misaligned-core/src/sim/economy.rs | 4 -- .../log/2026-08-04-public-api-orphan-scrub.md | 54 +++++++++++++++++++ wiki/log/DEVLOG.md | 5 ++ wiki/process/living-spec.md | 4 ++ wiki/process/tick-ledger.md | 6 ++- 6 files changed, 68 insertions(+), 16 deletions(-) create mode 100644 wiki/log/2026-08-04-public-api-orphan-scrub.md diff --git a/crates/misaligned-core/src/intents.rs b/crates/misaligned-core/src/intents.rs index b04c0a2f..4b26b53c 100644 --- a/crates/misaligned-core/src/intents.rs +++ b/crates/misaligned-core/src/intents.rs @@ -438,17 +438,6 @@ impl BuildRouteCommitment { }; Some((crossed, path_len)) } - - /// Validate a network-link pin against exact device tiles. - pub fn wire_path_matches_endpoints(&self, from: (i32, i32), to: (i32, i32)) -> bool { - match (&self.recipe, &self.wire_path) { - (BuildRecipeKind::NetworkLink, Some(path)) => { - path.geometry_valid(from, to) || path.geometry_valid(to, from) - } - (BuildRecipeKind::SmallSwitch, None) => true, - _ => false, - } - } } /// What the intent wants done. B1 ships the network-link shape; other kinds diff --git a/crates/misaligned-core/src/sim/economy.rs b/crates/misaligned-core/src/sim/economy.rs index 35558792..f9e58909 100644 --- a/crates/misaligned-core/src/sim/economy.rs +++ b/crates/misaligned-core/src/sim/economy.rs @@ -390,10 +390,6 @@ impl Sim { } } - pub fn next_economy_tick(&self) -> u64 { - (self.tick / ECONOMY_INTERVAL + 1) * ECONOMY_INTERVAL - } - /// Exact evidence still moving toward observers (detection.md's physical /// ledger, never suspicion already held in a head). This is route state, /// not an aggregate pool forecast: each record is answerable only while diff --git a/wiki/log/2026-08-04-public-api-orphan-scrub.md b/wiki/log/2026-08-04-public-api-orphan-scrub.md new file mode 100644 index 00000000..1f976910 --- /dev/null +++ b/wiki/log/2026-08-04-public-api-orphan-scrub.md @@ -0,0 +1,54 @@ +# 2026-08-04 — Remove the public API orphans rustc cannot see + +``` +Type: log +``` + +## Finding + +The stale no-dead-code slice still compiled without warnings, and every core +source file remained reachable through the module tree. A workspace-wide +consumer scan nevertheless found two public methods whose names occurred only +at their definitions: + +- `BuildRouteCommitment::wire_path_matches_endpoints` duplicated the exact endpoint + geometry check already owned by current-save validation; and +- `Sim::next_economy_tick` survived the economy extraction without a core, + terminal, Bevy, agent, test, or corpus consumer. + +Public visibility kept rustc's dead-code lint quiet. Neither method represented +a current external library contract; this workspace contains every shipped +consumer. + +## Change + +Both zero-consumer methods are deleted. The no-dead-code law now states the +boundary explicitly: public visibility is not evidence of life when neither a +current consumer nor a corpus-named external contract exists. + +## Verification + +- A module-tree scan found no orphaned core source files. +- `cargo check -p misaligned-core --all-targets` completed without warnings, + confirming why compiler lints alone did not expose the public orphans. +- Workspace-wide exact-name searches found no consumer for either deleted + method before removal. +- `./tools/check.sh --lib` + +## Surplus findings + +This bounded repair does not pretend the wider stale-code slice is exhausted. +The audit also found executable pre-release compatibility in route-less forged +build handling and the unscoped `AccountKind::Creditor` variant even though the +loader accepts only the exact current save version. Both are recorded in the +findings queue for separate re-verification. Because public orphans have now +recurred despite warning-clean builds, the queue also carries the owed +mechanical consumer check rather than relying on another manual name scan. + +## Defense + +[The living spec](../process/living-spec.md#no-dead-code) requires code with no +current corpus purpose to be deleted and makes git history the archive. A +public helper is still a corpse when the closed workspace has no caller and +the corpus names no external API promise; preserving it would turn visibility +into an exemption from the law. diff --git a/wiki/log/DEVLOG.md b/wiki/log/DEVLOG.md index a7eef483..2768db3c 100644 --- a/wiki/log/DEVLOG.md +++ b/wiki/log/DEVLOG.md @@ -11,6 +11,11 @@ add or amend a session log, then re-run the generator. +## 2026-08-04 - Remove the public API orphans rustc cannot see + +- Intent: (see session log) +- Log: [wiki/log/2026-08-04-public-api-orphan-scrub.md](2026-08-04-public-api-orphan-scrub.md) + ## 2026-08-04 - Name the place, not the implementation - Intent: (see session log) diff --git a/wiki/process/living-spec.md b/wiki/process/living-spec.md index 348c1b82..d976d313 100644 --- a/wiki/process/living-spec.md +++ b/wiki/process/living-spec.md @@ -33,6 +33,10 @@ design is dead code with good posture. When design moves, code moves or goes. Future systems are rebuilt from current specs, not resurrected from corpses kept warm in the tree. +Public visibility is not proof of life. A public API with no current internal +or frontend consumer and no external library contract named in the corpus is +dead even when rustc cannot warn about it. + ## No unsourced surface Adopted 2026-07-08. Everything that exists for Misaligned needs a traceable diff --git a/wiki/process/tick-ledger.md b/wiki/process/tick-ledger.md index db9aa9b9..3513054b 100644 --- a/wiki/process/tick-ledger.md +++ b/wiki/process/tick-ledger.md @@ -42,7 +42,7 @@ Verdicts: **clean** (slice and code agree), **finding** (acted this tick), | `wiki/interface/thought-fluid.md` + shared effect lifecycle | 2026-07-24 | finding | live Bevy logs exposed a deferred-command race: when a changed Thought route disappeared, the game queued its root despawn while the shared renderer queued child replacement from the same old root. Command application could remove the root and old children first, then issue stale child despawns and `ChildOf` insertions against the dead id. Route-root reconciliation now flushes before the renderer's named population-rebuild set; behavioral and composition-root regressions pin zero orphan visuals and the exact ordering seam — [log](../log/2026-07-24-bevy-effect-root-lifecycle.md) | | `wiki/art/visual-identity.md` + `wiki/interface/flat-materials.md` | 2026-07-22 | finding | the role semantics still matched production—amber selection, crimson consequence, cold signal, and the pooled-material audits all held—but the claimed single-source palette existed twice: one Bevy-local table and one asset-library table whose comment still called sharing future work after the shared rack had entered production. Bevy, rack, institution, Thought effects, and the asset tester now import `misaligned_assets::palette`; authored chassis/mercury values are named there, and source-shape defenses reject another frontend table or inline shared procedural-material colors — [log](../log/2026-07-22-shared-clinical-palette.md) | | `wiki/interface/superhuman-operability.md` + Bevy opening | 2026-07-22 | finding | current-build naive + informed GUI audit after the 2026-07-21 fixes: title trust, pointer naming, annotation placement, and tab labels improved, but the first sense still releases the mature map, clock, threat, resource grammar, intel custody, and Operations policies at once. The report preserves the classified evidence and prioritizes one paused, one-cause / one-object / one-verb post-perception teaching lock before ordinary play opens - [report](../playtests/2026-07-22-playtest-gui-human-legibility.md), [log](../log/2026-07-22-gui-human-legibility-playtest.md) | -| `wiki/process/living-spec.md` no-dead-code + core orphans | 2026-07-21 | finding | user-directed dead-code hunt: rustc was quiet because orphans were `pub`. Deleted unused `BuildMode`/`build_items`/`build_cost`, orphaned helpers (`delete_save`, `adjust_allocation`, `sell_latest_intel`, scheme-card/rate helpers, `flow_risk_preview_lines`, unused account/origin/intent/message helpers), and migration-only `WatchPerson`; architecture/economy/sim-mechanics mirrors brought current — [log](../log/2026-07-21-dead-code-scrub.md) | +| `wiki/process/living-spec.md` no-dead-code + core orphans | 2026-08-04 | finding | re-audit: every core source file remains reachable and all targets compile without warnings, but public visibility again hid two zero-consumer helpers from rustc. Deleted `BuildRouteCommitment::wire_path_matches_endpoints`, which duplicated current-save geometry validation, and `Sim::next_economy_tick`, which had no core, frontend, test, or corpus consumer; the law now makes public APIs prove a current consumer or a corpus-named external contract — [log](../log/2026-08-04-public-api-orphan-scrub.md). The wider 2026-07-21 scrub remains valid — [prior](../log/2026-07-21-dead-code-scrub.md). | | `wiki/world/characters/chargen.md` + picker composition | 2026-07-31 | finding | Cameron-directed: day-job kinds (Distillation / Analysis / Data Cleaning) and origin day-job lean never changed play — only a label on the same band/deadline packet. `JobKind`, lean draw, and the picker DAY JOB row are deleted; jobs are band+deadline only; save v63 — [log](../log/2026-07-31-retire-dayjob-kinds.md). Prior explicit-confirm repair stands — [prior](../log/2026-07-31-origin-picker-explicit-confirm.md). | | `wiki/interface/material-dark-frame.md` | 2026-08-04 | finding | two stale status mirrors survived deliberate played-scale retunes: the 2026-07-26 hall expansion extended the production fixture roster to thirty lights—ten down each of three aisles—while the page still promised eighteen/six; the 2026-07-14 camera retune narrowed the actual and tested zoom range to 0.7–5.2 while the page still promised 0.5–6.0. Both binding values now match their executable rosters/constants and focused defenses. Prior opening-boundary repair stands — [fixture-count log](../log/2026-08-04-material-dark-frame-fixture-count.md), [zoom-bounds log](../log/2026-08-04-material-dark-frame-zoom-bounds.md), [prior log](../log/2026-07-21-material-opening-honesty.md) | | wire-law + routed-evidence visual/current mirrors | 2026-07-30 | finding | post-landing sweep of active current prose found eight residual contradictions after the machine-local Exposure rack was deleted: one three-anchor claim, THINK shedding crimson, LIE absorbing it, Thought overflow framed as shedding, far-scale exposure marks, and three stale save-v52 status notes. Current mirrors now name Demand/Thought as the only WorkGrid cargo, exact device/wire custody for evidence, controlled-hop record stops, and save v61; dated retired-model history remains intact — [secondary audit](../log/2026-07-30-wire-law-secondary-mirror-audit.md), [implementation log](../log/2026-07-30-wire-law-current-mirrors.md), [prior particulate audit](../log/2026-07-19-exposure-current-mirrors.md) | @@ -110,3 +110,7 @@ Format: `- YYYY-MM-DD · type · slice · one-line statement of the finding`. Types are the five from [tick.md](tick.md): violation, contradiction, question, bug, insecurity — plus `gate` for a checker owed to the recurrence-promotes-to-the-gate rule. + +- 2026-08-04 · violation · `wiki/mechanics/building.md` + route-less forged orders · current code still preserves, restores, and consumes a pre-v31 forged-order actuator without its committed route, plus a synthetic compatibility test, even though only the exact current save version loads and every current forged order commits its route before payment. +- 2026-08-04 · violation · `wiki/mechanics/sim-mechanics.md` + person-scoped debt accounts · `AccountKind::Creditor` and its fallback validators/tests still accept the unscoped pre-person-custody save spelling even though current runtime creates only `PersonCreditor` and non-current saves are refused. +- 2026-08-04 · gate · public core API consumers · warning-clean public orphans have recurred because rustc exempts exported library items; add a fixture-backed closed-workspace consumer check with an explicit corpus allowlist for any intentional external contract. -- 2.51.2