docs(adr-0249): ADR-0249 (Proposed) + acceptance evidence — arc closure

ADR-0249 documents the reader→Hamiltonian compiler (P1-P5): thesis (composition
= certified turn sequences), the five components, anti-hollow discipline, the
Ring-2 non-mutating correction, three-tier reproducibility, Tier-1 scope +
recorded frontier, and the honest-measurement done-when. Status Proposed — no
self-Accept; §10 ruling record awaits Shay.

Acceptance evidence: phases + merge SHAs, the real GSM8K dev-holdout result
(26/50 Tier-1 ingestible, wrong=0, PARITY vs symbolic fold, 24 multi-entity
refused = recorded frontier), in-tree algebra + CNF-soundness verification, the
design corrections applied, and the honest open register.
This commit is contained in:
Shay 2026-07-18 13:10:01 -07:00
parent 324db57373
commit d65fb8cf36
2 changed files with 195 additions and 0 deletions

View file

@ -0,0 +1,126 @@
# ADR-0249: Reader→Hamiltonian Compiler — the Composition Frontier
**Status**: **Proposed**
**Date**: 2026-07-18
**Authors**: Joshua Shay + multi-model R&D (implemented Fable 5)
**Depends on**: ADR-0243 (cognitive lifecycle — `relax_to_ground`, `ProblemHamiltonian`), ADR-0244/0245 (content-addressing, f64 relaxation, `_cached_eigh`), ADR-0217 (R2 finite-integer constraint compiler — front-end precedent), ADR-0175/01910193 (calibrated-learning / composition-wall doctrine)
**Design record**: `docs/research/reader-hamiltonian-compiler-spike-2026-07-18.md`
**Acceptance evidence**: `docs/handoff/ADR-0249-Acceptance-Evidence.md`
---
## 1. What this ADR is — and the thesis
The generalized-lift instrument (ADR-0246 seam S4) recorded a single blocking
scope limitation: *no reader→Hamiltonian compiler existed beyond ≤5-atom
propositional problems and quadratic wells, so real problems (GSM8K arithmetic,
NL deduction) could not be ingested by the corridor at all.* This ADR builds
that compiler and nothing more — it does not touch serving, does not activate
any gate, and does not claim the corridor now beats symbolic solvers.
**Thesis — composition = certified turn sequences.** The corridor's native
space is 32-dimensional (the Cl(4,1) blade basis; `_MAX_ATOMS = 5` is exactly
2⁵ = 32, structural not incidental). A problem is therefore *not* compiled into
one large Hamiltonian. It is compiled into a **turn program** — an ordered
sequence of small relation-wells, each solved in one certified relaxation turn,
with the working state flowing turn-to-turn on the field. Composition depth
lives in the certified chain, not in matrix size. This is the "wall is
COMPOSITION" lesson (ADR-0193) finally getting its mechanism.
## 2. Components (five phases, each merged under its own PR)
| Phase | Module | What it does |
|---|---|---|
| P1 | `core/physics/quantity_kernel.py` | Quantities as null points on the Cl(4,1) conformal line; add/scale by constants as translator/dilator versor sandwiches; projective scale-invariant decode. |
| P2 | `core/physics/relation_compiler.py` | `output = scale·input + offset` → quadratic-well `ProblemHamiltonian` via versor transport (reuses `compile_quadratic_well`). |
| P3 | `evals/logic_cnf_compiler.py` | Structural formula→CNF (reuses `logic_canonical` parser; eliminate iff/implies → NNF → distribute) → `PropositionalProblem` + query `Clause`. |
| P4 | `evals/turn_program.py` | `MathProblemGraph` → ordered turn program; chained-relaxation executor; content-addressed tamper-evident turn ledger. |
| P5 | `evals/generalized_lift_instrument.py` | `arithmetic-chain` domain: corridor vs symbolic fold on the real GSM8K dev holdout; honest coverage recorded. |
## 3. Anti-hollow discipline (load-bearing)
The compiler must never *evaluate* the arithmetic or logic it encodes — else the
corridor confirms a precomputed answer rather than solving, and the instrument
is hollow. Enforcement:
- The relation/turn compilers apply the problem's **structure** as versor
operators (dilator for scale, translator for offset); the substrate's
geometric product performs the arithmetic. No Python `scale·input+offset`.
- Compiled wells are **bare projectors** — metadata `{curvature, target_digest}`
only; they carry no answer and no coefficients.
- In a turn chain the accumulator flows as a **field state and is decoded exactly
once, at the end**; intermediate values are never decoded to drive the next
turn.
- Ablation pins confirm the answer is produced by relaxation (the start state
decodes to the input, only the relaxed state to the answer, with byte-identical
Hamiltonians).
## 4. The Ring-2 correction (verified in-tree)
The design spike proposed "chain turns through the Ring-2 residual protocol."
Grounding against the code corrected this: `run_residual_protocol`
(`core/ports/residual_protocol.py:222`) is **zero-bound / non-mutating** — its
stage-5 recertification re-witnesses the subject and raises
`recertification_witness_changed` if it moved. Arithmetic turns *mutate*. The
protocol therefore certifies a *fixed* state's admissibility, not a state
*transition*, and cannot be the vehicle for the mutating turn.
Resolution (no hollow integration): the per-turn certificate is the relaxation's
own `RelaxationCertificate`; the tamper-evident *sequence* is recorded with the
Ring-2 chain-integrity **pattern** — a content-addressed `TurnRecord`,
`GENESIS_DIGEST`-linked, with `verify_turn_chain` mirroring `verify_replay_chain`.
## 5. Reproducibility — three tiers, honestly bounded (spike §4.6)
- **Tier 1 (content address): solved.** SHA-256 over explicit `<f8` LE bytes.
- **Tier 2 (matrix construction): enforced.** `geometric_product` is a
fixed-order scatter-add (no BLAS/reduction) ⇒ IEEE-754 hardware-deterministic;
it silently truncates to f32 unless handed f64, so every construction is
explicit f64 and pinned with golden-bytes canaries.
- **Tier 3 (eigensolve): bounded, not overclaimed.** The affine well
`H = c(Id ψψᵀ)` has a 31-fold-degenerate excited eigenspace whose LAPACK
basis is build-dependent; propagator bytes are not cross-hardware identical.
Mitigation: the ground state is analytic (the target is constructed), so the
basis-invariant `phase_correlation/2` agreement is pinned, never the bytes.
## 6. Tier-1 scope + recorded frontier
Tier-1 is the **affine single-accumulator** envelope: add / subtract / multiply /
divide with constant `Quantity` operands and positive scale; propositional
deduction over ≤5 atoms. Everything else — multi-entity, transfer, rate,
comparison, fraction, partition, non-positive scale, >5-atom deduction, unknown×
unknown — is **refused with a typed error and recorded**, never silently dropped
(no-silent-caps). >5-atom deduction via ROBDD-partitioned turn programs is the
next arc, not this one (a sequencing choice, not an impossibility).
## 7. Honest measurement (the done-when)
On the sealed real GSM8K dev holdout (50 cases): **26 are Tier-1 ingestible and
solved wrong=0**; the corridor matches the symbolic fold on every one (PARITY,
delta = 0 — the field matches arithmetic, it does not beat it); the 24 refused
are all multi-entity, the recorded Tier-2 frontier. This is the honest-NULL
protocol working as designed: the deliverable is a *decidable measurement* and
*recorded real-data coverage*, not an inflated lift claim. The recognition
domain's genuine +9 lift stands separately; arithmetic is honestly PARITY.
## 8. Governance
Off-serving (A-04): every module lives in `core/physics/` or `evals/` and is
never imported by `chat/runtime.py`. No gate is activated; no manifold is
mutated (I-03). Reuses ratified contracts (`compile_quadratic_well`,
`HamiltonianCompileError`, `logic_canonical`, the Ring-2 chain pattern) rather
than forking them. Local-first CI: smoke green in-worktree at every phase.
## 9. What this ADR does NOT claim (honest register)
- Not a serving change; the symbolic `generate/` path remains the serve path.
- Not a lift over symbolic solvers on arithmetic (PARITY is the honest result).
- Not full GSM8K coverage — 52% of the dev holdout is Tier-1; the rest is the
recorded frontier.
- Not an activation of any admission gate (ADR-0246 §3.7 stays uncalibrated).
## 10. Ruling record (§8 — Shay)
_Awaiting ratification._ The four design rulings (affine-only Tier-1; >5-atom
deduction deferred; single ADR; field wedge independent) are recorded RESOLVED
in the spike; acceptance of this ADR is Shay's alone (no self-Accept).

View file

@ -0,0 +1,69 @@
# ADR-0249 — Acceptance Evidence
**Status**: Evidence pack for Shay's ruling (no self-Accept)
**Date**: 2026-07-18
**ADR**: `docs/adr/ADR-0249-reader-hamiltonian-compiler-composition-frontier.md`
**Design record**: `docs/research/reader-hamiltonian-compiler-spike-2026-07-18.md`
The reader→Hamiltonian compiler closes the composition frontier the
generalized-lift instrument (ADR-0246 S4) was waiting to measure. Built in five
smoke-gated phases, each merged under its own PR off `forgejo/main`.
## Phases merged
| Phase | PR | Merge commit | Module | Pins |
|---|---|---|---|---|
| P1 quantity kernel | #66 | `aca98d85` | `core/physics/quantity_kernel.py` | 35/35 |
| P2 relation compiler | #67 | `2575d0d9` | `core/physics/relation_compiler.py` | 21/21 |
| P3 CNF converter | #68 | `309e0ef6` | `evals/logic_cnf_compiler.py` | 32/32 |
| P4 turn-program executor | #69 | `805752db` | `evals/turn_program.py` | 15/15 |
| P5 instrument integration | this PR | — | `evals/generalized_lift_instrument.py` | 10/10 |
Smoke (`uv run core test --suite smoke -q`) green at every phase boundary (176 passed).
## Load-bearing results
**Multi-step arithmetic by chained certified relaxation** (P4):
`((5+3)*2)-4 = 12`, `(10/2+7)*3 = 36`, `(100-40)/4 = 15` — every turn
`ground_state_certified`; accumulator flows as a field state, decoded once.
**Real GSM8K dev holdout** (P5, sealed 50 cases, `evals/gsm8k_math/dev`):
| Metric | Value |
|---|---|
| Tier-1 affine ingestible | 26 / 50 (52%) |
| Corridor correct on ingested | 26 / 26 — **wrong = 0** |
| Corridor vs symbolic fold | PARITY (delta = 0) |
| Refused (multi-entity) | 24 / 50 — recorded Tier-2 frontier |
The corridor solves real GSM8K problems it can ingest with zero wrong answers,
and honestly refuses the rest. It does not beat arithmetic at arithmetic
(PARITY is honest); the deliverable is real-data coverage + a decidable
measurement, per the honest-NULL protocol.
**Algebra verified in-tree** (P1): conformal line embedding + translator/dilator
exactness checked against `algebra/cl41.py`'s own multiplication table (nullity
< 3e-10; translator exact to f64 rounding; dilator sign convention pinned).
**CNF soundness proved** (P3): for a 14-formula panel, the compiled CNF has the
same ROBDD identity as the source (`canonicalize` oracle); end-to-end entailment
agrees with `evaluate_entailment` gold, wrong = 0 on consistent premises.
## Design corrections applied (honest register)
- **Ring-2 is non-mutating.** `run_residual_protocol` is zero-bound (stage-5
recertification refuses a moved witness), so it certifies fixed-state
admissibility, not transitions. The turn ledger reuses the chain-integrity
*pattern* (`TurnRecord` / `verify_turn_chain`), not the admission protocol.
- **`cga_inner` is the wrong metric for versor states** — readback and quantity
decode use `phase_correlation/2`, pinned in the P1 module.
- **Scope note corrected** — the instrument's stale "no compiler exists" line is
replaced with measured Tier-1 coverage + the multi-entity frontier.
## What remains open (not claimed here)
- Multi-entity / non-affine GSM8K (transfer, rate, comparison, fraction) —
Tier-2, refused and recorded.
- >5-atom deduction via ROBDD-partitioned turn programs — next arc.
- ADR-0246 §3.7 admission-policy calibration — unchanged; no gate activated.
- `generate/` ("core_logos") serve-path articulation upgrade — still deferred.