melinoe 0.10.0

Zero-sized, branded, multi-token phantom capabilities for compile-time data-access and thread-synchronization proofs (a generalized evolution of GhostCell) for the Mnemosyne memory ecosystem.
Documentation
# Backlog — melinoe

## ATLAS-MELINOE-PARTITION-PANIC-ORACLE-2026-08-20 — Assert recovered panic values [patch, complete]

**Finding:** the panic-recovery regression used `is_err()` for both panic
closures and `is_none()` for the recovered payload mutex. Those checks did not
prove the captured panic values or the empty post-recovery state.

**Outcome:** both `catch_unwind` results now match `Err` and assert their
exact static-string payloads. The recovered empty mutex state is compared as
`Option<()> == None`, preserving the empty-value contract without an
existence-only assertion.

**Evidence (2026-08-20):** clean lane branch
`fix/melinoe-panic-oracle` is based on fetched `origin/main` `689f562`.
All-feature locked all-target check and warning-denied Clippy pass; no-default
locked all-target check and Clippy pass. All-feature Nextest passes `127/127`,
no-default Nextest `52/52`; all-feature doctests pass `31/31`, no-default
doctests `20/20`; Rustdoc is warning-free. The conformance scan reports
`existence_only_assertions: 0` versus `2` on the fetched default, with every
other class unchanged. A temporary `take_panic_payload` mutation to `None`
fails the focused recovery test; the implementation was restored and the
focused test passes.

**Delivery:** commit `67e177d` is published on
`fix/melinoe-panic-oracle`. GitHub compare confirms exact base `689f562` →
head `67e177d` is one commit ahead with four intended files. Draft PR creation
was rejected by the GitHub connector with HTTP 403 `Resource not accessible by
integration`; no hosted gate or merge is claimed. Re-open publication when
repository write authorization is available. The dirty detached primary
checkout remains untouched.

## Atlas in-house replacement roadmap — melinoe slice [minor]

melinoe is the capability/ownership-proof foundation. The Atlas GPU program
(the `hephaestus` device substrate — atlas ADR 0001 — used by coeus/apollo on wgpu +
CUDA, with mnemosyne device pools) wants compile-time proofs for device-buffer ownership:
- [x] [minor] Stage D1 support: a documented device-buffer ownership-transfer pattern —
  moving a `SyncRegionToken` transfers write capability across host/device/stream; a
  `SharedReadToken` fans out concurrent device reads; `BrandedAtomic` covers fence/
  counter values touched on both sides. Add a real contract test over the lowest
  available device/stream abstraction; do not substitute a mock buffer.

## Active

- [x] [patch] Verify the declared Rust 1.65 MSRV with a standalone locked
  `cargo check --all-targets --all-features` workflow. The current Atlas
  overlay is not a valid floor oracle because peer provider manifests can
  require newer Cargo. Hosted run `31785253730` passed at PR #16 head
  `6e6a181`; the merged default is `6cad6e7`.

- [x] [minor] Add generic branded-vector generation through
  `BrandedVec::from_fn` and `collections::with_generated`. The fresh
  higher-ranked brand remains inside the callback while its result escapes;
  generated cells compose with the existing partition driver, and
  `into_boxed_cells` supports Themis's branded placement container. Keep
  topology providers above Melinoe: Themis-derived worker counts enter through
  `PartitionPlan::parts`, not a reverse dependency. Evidence: all-feature
  Nextest 125/125, alloc-only Nextest 79/79, strict Clippy for both feature
  surfaces, offline check, documentation and semver gates, Themis branded
  placement compile, and CFDrs `cfd-core` Nextest 269/269 through the Atlas
  overlay.

- [x] [patch] Consolidate conditional-atomic ordering resolution behind one
  generic `OrderingSource` strategy. Runtime `Ordering` and sealed ZST
  `AtomicOrder` policies now share the same operation bodies; static policy
  monomorphizations retain their associated ordering constants without a
  runtime policy branch. No public API or consumer migration is required.
  Evidence: ordering-role unit coverage, all-feature Nextest 126/126, strict
  Clippy, and offline check.

- [x] [patch] Consolidate fresh higher-ranked brand minting behind the private
  GAT-based `TokenFamily` factory. Exclusive, cross-thread region, thread-local,
  scoped-worker, and reentrant entry points now share one brand proof boundary
  while retaining their distinct token auto-trait postures. Public signatures
  and consumer behavior remain unchanged. Evidence: all-feature Nextest
  126/126, alloc-only Nextest 80/80, strict Clippy for both feature surfaces,
  offline check, 31 doctests, rustdoc, and diff checks.

- [x] [patch] Repair the conditional-atomic README link after the atomic
  module hierarchy split; the documented `BrandedAtomic` source now resolves to
  `src/atomic/branded.rs`.

- [x] [patch] Split the 513-line `BrandedVec` implementation into named
  generation, operation, view, partition, iterator, and manifest modules.
  Public exports and signatures remain unchanged; the largest resulting leaf
  is 157 lines. Evidence: all-feature Nextest 126/126, alloc-only Nextest
  80/80, strict Clippy for both feature surfaces, 31 doctests, rustdoc,
  rustfmt, offline check, and diff checks.

- [x] [minor] Move `CellCowExt`'s `Clone` requirement from the public trait
  boundary to the four methods that construct `Cow` values. Non-`Clone`
  branded cells can now satisfy the capability boundary while clone-dependent
  operations retain explicit method bounds. Evidence: all-feature Nextest
  127/127, alloc-only Nextest 81/81, strict Clippy for both feature surfaces,
  31 doctests, rustdoc, offline check, rustfmt, and diff checks.

- [x] [patch] Consolidate wrapped
  `BrandedVecDeque` `Cow` construction through one generic segment helper and
  document the transparent-storage safety contracts for deque conversions.
  Preserve the existing borrow/retain policy semantics and public methods;
  prove contiguous and wrapped value behavior through the existing deque Cow
  suite plus focused feature gates. Evidence: focused deque Nextest 22/22,
  all-feature Nextest 127/127, alloc-only Nextest 81/81, strict Clippy on both
  feature surfaces, 31 doctests, rustdoc, rustfmt, and diff checks.

- [x] [patch] Harden registered partition panic recovery against mutex poisoning.
  `sync::scoped::partition::driver_core` now recovers the first captured panic
  payload with `PoisonError::into_inner` both when task wrappers report a panic
  and when the executor tears down the manually managed result buffer. This
  prevents a poisoned payload mutex from masking the original panic; the
  existing panic-safety drop-count tests continue to cover initialized-result
  cleanup. A focused regression poisons the payload mutex, reports a second
  panic, and verifies the first payload remains recoverable. Evidence
  (2026-08-06): `cargo check --all-features`, strict
  `cargo clippy --all-targets --all-features -- -D warnings`, Nextest **122/122**,
  doctests **29/29**, `cargo check --no-default-features`, rustfmt, and diff
  checks all pass. Implementation scope is one provider-local source file;
  no consumer or peer-owned files changed.

- [x] [patch] Move segmented `Cow` assembly into the existing `cell::cow`
  policy owner. `BrandedVecDeque` remains a consumer of the sealed `CowPolicy`
  seam; contiguous zero-copy and wrapped owned behavior remain unchanged, with
  no public API or peer-owned file changes. Evidence: focused branded-deque
  Nextest 22/22, all-feature and alloc-only Nextest, strict Clippy on both
  feature surfaces, 31 doctests, rustdoc, rustfmt, and diff checks.

- [x] [patch] Publish future releases through a pinned GitHub Actions workflow
  using crates.io OIDC Trusted Publishing and no stored registry credential.

- [x] [patch] Fix executor-state test interference in `tests/partition.rs`.
  The executor registry is process-global, so `register_parallel_executor`/
  `clear` windows leaked into concurrently running unsynchronized tests: a
  non-guard test could observe a registered deterministic executor mid-flight,
  overwrite the shared `EXECUTED_TASKS` side-channel, break a guard test's
  driver assertions, and the failed guard's unwind then poisoned
  `EXECUTOR_TEST_LOCK` and cascaded into the next guard test. Fix: every test
  that touches the driver — all partition read/write tests in the module plus
  the proptests, not just the registration tests — acquires `ExecutorTestGuard`
  (moved to file scope so the proptests can see it), which both serializes
  registration windows and guarantees a clean registry baseline; the guard
  additionally recovers a poisoned lock (`PoisonError::into_inner`) so one
  genuine failure never cascades. Tests still exercise real concurrency inside
  their own partition calls. Evidence (2026-08-11): all-feature Nextest
  127/127, no-default-features Nextest 52/52, doctests 31/31, strict Clippy on
  both feature surfaces, rustfmt, and 8/8 repeated parallel partition-suite
  runs. Pre-existing on `origin/main`; unrelated to the book/`mdbook-test`
  change.

- No Melinoe-local item remains in progress; the 0.10.0 executor capability is
  ready for upstream publication and downstream Moirai lock refresh.

## Next

- <a id="partition-spawn-crossover"></a>[minor] Guard the scoped-thread
  partition fallback against shard counts whose work cannot pay for a thread
  spawn, **and prefer the pool-backed path**. Measured 2026-09-11 on a 24-core
  x86_64 host: the fallback's cost is linear in shard count at **~30 µs/shard**
  and essentially independent of work — `cells=8` and `cells=65536` both cost
  ~250 µs at 8 shards, despite 8192× more elements. `parts=1` costs 40 ns,
  `parts=2` costs 93 µs (a 2300× cliff from one spawn). Break-even is **~130 µs
  of total work** (≈ `cells × cost ≳ 50,000` element-ops at 4 threads); below
  that the parallel path is *slower* than running inline.
  `driver_core::drive` spawns `min(parts, n) − 1` OS threads unconditionally, so
  every small-region call is pure loss.

  Note this is the **fallback**, not the production path: moirai's
  `moirai-parallel::melinoe_ext::{par_partition_for_each, par_partition_map}`
  already routes partitioning onto the shared work-stealing pool and bypasses
  OS-thread spawning entirely, and `CFDrs` uses it
  (`crates/cfd-core/src/physics/fluid_dynamics/operations.rs:47`). So the
  priority is not to tune the spawn path but to (a) route through the pool, and
  (b) document that consumers doing fine-grained work must register an executor.
  Any added floor should reuse moirai's own compile-time `ExecutionPolicy`
  (`moirai-parallel/src/policy.rs`) rather than introduce a second threshold
  concept in melinoe. Blocked on a public-behaviour decision, because
  `partition_map`'s `parts` is documented as an exact shard count and a guard
  that silently runs inline changes that contract. Evidence:
  `benches/access.rs::bench_partition_driver` plus the scaling probe recorded in
  the 2026-09-11 workspace log.

- <a id="moirai-melinoe-ext-execution-policy"></a>[minor] cross-repo, moirai
  `moirai-parallel::melinoe_ext::{par_partition_for_each, par_partition_map}`
  dispatch to `global().for_each_indexed(...)` **unconditionally** — no
  `ExecutionPolicy` parameter and no size check — so a 4-cell region is
  parallelized as eagerly as a million-cell one. This is precisely the failure
  mode `Adaptive` exists to prevent, and the policy machinery is already in the
  same crate (`moirai-parallel/src/policy.rs`, with the crossover already
  tabulated in `ADAPTIVE_PARALLEL_THRESHOLD`'s docs). The module's own tests
  call it with 16 and 10 elements. Fix must not break the live `CFDrs` consumer
  (`crates/cfd-core/src/physics/fluid_dynamics/operations.rs:47`): either add
  `P: ExecutionPolicy` as a type parameter with a `Parallel` default, or add
  parallel `*_with_policy` functions and leave the existing signatures as
  `Parallel`.

- <a id="moirai-executor-registration-order"></a>[minor] cross-repo, moirai
  `global_arc()` calls `melinoe::register_parallel_executor` **inside** its
  `OnceLock` initializer (`moirai-executor/src/lib.rs:141-154`), so melinoe's
  driver routes through the moirai pool only after something has first touched
  moirai's `global()`. A consumer calling `melinoe::sync::partition_map` earlier
  silently gets the ~54 µs-per-thread spawn fallback. The passing test
  `placement.rs:162 test_melinoe_partition_routing` opens with
  `let _exec = crate::global();` — that line is load-bearing and the ordering
  hazard is undocumented. Either register eagerly from a constructor/`ctor`
  path, or document the required ordering at the melinoe registration API.

- <a id="semver-registry"></a>[patch] After registry publication, switch
  `cargo-semver-checks` from the `--baseline-rev` git workflow (now established)
  to the default crates.io baseline, and re-run once semver-checks supports the
  newer rustdoc-JSON format so its lints execute rather than skip.

## Closed

- <a id="parallel-executor-capability"></a>[major] Replaced the
  `ParallelExecutorFn` domain alias with an unsafe `ParallelExecutor` trait and
  a transparent function-pointer capability. The associated `run_indexed`
  entry point stores no fabricated receiver; a non-zero-sized implementation is
  covered at the registration boundary. Evidence: compile-time layout assertion,
  partition and panic tests, doctests, Clippy/rustdoc, focused Miri executor-path
  tests, and major-change semver classification. Decision: ADR 0001.

- <a id="atlas-device-contract"></a>[minor] Added the Atlas device-buffer
  ownership-transfer contract crate in commit `375108b`; the workspace now
  carries the real Hephaestus-backed contract instead of an uncommitted plan.

- <a id="halo-workspace-crate"></a>[minor] Added `crates/halo` as the
  Melinoe-backed protective collection crate. The first migrated vertical slice
  is `halo::BrandedVec<'brand, T>`, backed directly by
  `Vec<MelinoeCell<'brand, T>>` and Melinoe's permit, zero-copy slice, and
  conditional `Cow` traits. Evidence: `cargo check -p halo` plus targeted tests,
  docs, and benchmark harness verification in the delivering change.
- <a id="halo-branded-vec-ops"></a>[minor] Extended `halo::BrandedVec` with
  owned vector structural operations and `std`-gated partitioned mutation/map
  adapters over Melinoe `PartitionPlan` shards. Evidence: default and
  `--no-default-features` Halo builds, value-semantic structural/concurrent
  tests, workspace nextest/clippy/doc gates, and benchmark harness compilation.
- <a id="halo-read-partitions"></a>[minor] Exposed
  `PartitionPlan::chunk_len_for` for downstream chunk planning and added
  `halo::BrandedVec` read-side partition map/for-each adapters over
  permit-gated shared slices. Evidence: Melinoe plan-resolution tests, Halo
  shared-shard tests, workspace gates, and benchmark harness compilation.
- <a id="halo-branded-vecdeque"></a>[minor] Migrated the next lowest-risk
  upstream Halo collection as `halo::BrandedVecDeque<'brand, T>`:
  `std::collections::VecDeque` maps directly to one owned standard container,
  unlike the remaining hash/tree/graph collections with broader invariants.
  Storage is `VecDeque<MelinoeCell<'brand, T>>`; element, split-slice, `Cow`,
  clone, read-partition, and write-partition access are gated through Melinoe
  permits/cells instead of a Halo-local `GhostToken` / `GhostCell` layer.
  Evidence: value-semantic deque tests and the `branded_deque` Criterion
  harness.
- <a id="halo-branded-deque-ops"></a>[minor] Extended `halo::BrandedVecDeque`
  with the same `std`-gated partitioned mutation/map adapters as `BrandedVec`
  (`partition_map_with`/`partition_for_each_with` for shared reads,
  `partition_for_each_mut_with`/`partition_map_mut_with` for exclusive
  mutation), via a `DequeShardPlan` that maps the flat logical index range
  onto the deque's front/back ring segments — a shard crossing the wrap
  boundary is split into two physical subshards sharing one logical offset.
  Evidence: contiguous and wrapped-deque correctness tests, a same-logical-
  plan consistency check across both mutation and read paths, workspace
  nextest/clippy/fmt gates.
- <a id="halo-upstream-migration"></a>[major] Consolidated `crates/halo` into
  the root `melinoe` crate (`2e9bf87`). `halo` workspace member removed;
  `BrandedVec`, `BrandedVecDeque`, `BrandedDrain`, `BrandedVecDequeDrain` live
  in `melinoe::collections` (re-exported at crate root under `alloc` gate).
  Single-crate workspace. 121/121 nextest, clippy/rustdoc clean.
- <a id="region-module-hierarchy"></a>[patch] Region module hierarchy split
  delivered in 0.6.0. `src/region/mod.rs` is now the documentation/re-export
  root, `src/region/shard.rs` owns `WriterShard`, and
  `src/region/chunks.rs` owns `ShardChunks` exact-size iteration. Public exports
  are unchanged; evidence: partition integration suite and stable gates.
- <a id="default-provider-feature-policy"></a>[patch] Default `parallel` and
  `mnemosyne-memory` feature markers delivered. `mnemosyne-memory` forwards to
  `alloc`; no dependency cycle to Mnemosyne is introduced. Evidence: Atlas
  feature-policy metadata audit, fmt, and diff checks.
- <a id="apollo-boundary-contract"></a>[patch] Apollo-facing zero-copy scratch
  boundary contract tests delivered. `Borrowed` ZST policy returns a
  pointer-identical `Cow::Borrowed` with zero element clones; `Retained` ZST
  policy returns independent owned storage with exactly one clone per element.
  Evidence: value-semantic integration tests in `tests/apollo_boundary.rs`.
- <a id="residuals-0-6-0"></a>[patch] 0.6.0 verification residuals resolved:
  (1) `cargo-semver-checks` baseline via `--baseline-rev HEAD` — v0.5.0→v0.6.0
  reports no semver update required; (2) Miri clean across all nine test suites
  (no UB / no data races), covering the previously-pending partition and
  projection paths; (3) nightly `cargo clippy --all-targets --all-features -- -D
  warnings` clean (the MSYS2 nightly needs `RUSTC_BOOTSTRAP=1` for the
  `doc_cfg` feature gate). Feature matrix verified: default, `alloc`,
  `--no-default-features`, and nightly `--all-features` build.
- <a id="shard-chunks-exact-size"></a>[minor] `ShardChunks: ExactSizeIterator`
  with exact `size_hint`, delivered in 0.6.0. The partition driver reserves
  worker capacity from the iterator's exact size, making it the single source of
  truth for the shard count; the duplicated `shard_count` helper and
  `ResolvedPartitionPlan` struct are removed. Evidence: exact-size and
  empty-region value-semantic tests; `partition_driver/empty_region` benchmark
  pins the no-spawn / zero-capacity contract.
- <a id="codegen-example-alloc-gate"></a>[patch] `examples/codegen.rs` gated on
  `required-features = ["alloc"]` in 0.6.0; restores a clean
  `cargo test --no-default-features` build (the example uses alloc-gated
  `borrow_cow`).
- <a id="cell-cow-direct"></a>[minor] Direct conditional-Cow boundary methods
  (`borrow_cow` / `retain_cow`) delivered in 0.5.0, covering common static
  borrow/retain cases without a generic policy parameter.
- <a id="zst-boundary-policies"></a>[minor] ZST boundary and synchronization
  policies delivered in 0.4.0. `CellCowExt` covers conditional borrow-or-retain
  at the ownership boundary; `AtomicOrder` covers monomorphized atomic
  orderings.
- <a id="partition-plan"></a>[minor] Typed multithreading plan surface delivered
  in 0.3.0. `PartitionPlan` supports fixed parts, reported hardware
  parallelism, and fixed chunk sizes.
- <a id="partition-driver-memory"></a>[patch] Partition driver memory discipline
  delivered in 0.2.1. `partition_map` uses overflow-safe ceiling division and
  reserves worker handles to the actual non-empty shard count.
- <a id="guard-projection"></a>[minor] Zero-copy guard projection delivered in
  0.2.0 with `MelinoeRef`/`MelinoeMut` `map` and `map_split`.

## Cross-repo filing (2026-06-12 stack audit)

- [x] [minor] (0.7.0) Shared thread-local value-cache utility delivered as
  `thread_cached!` (macro: TLS statics are declaration-site constructs no
  generic type can capture; same sanctioned route as moirai's
  `thread_local_static!`). themis `CACHED_NODE` and mnemosyne `CACHED_CPU_ID`
  adopt it in the same coordinated change. moirai's `thread_local_static!`
  remains separate by design: it serves no_std targets with a different
  fallback shape (evaluated 2026-06-12).