ADR-036: Do not re-land the V3/V4 window guards — the refined terminal subsumes them

Status: Accepted Date: 2026-08-25 Task: — (F1 solver adversarial-review follow-up)

Context

  • A solver review cycle proposed “window guard” logic to stop the active-set walk’s terminal refine from under-shooting a sharp bounded piece corner, and part of that work was subsequently reverted. Whether the V3/V4 window guards should be re-landed was a pending review item. The prior implementation is NOT recoverable to verify against: it was dropped in the upstream tree rewrap (side-line, unpushed — a batch-all-objects content search returns 0 hits and no local/origin branch carries it). This ADR records the re-land decision without asserting what the lost code did; the decision stands on the current core refine path’s own corner safety, independent of the lost implementation.

  • Independently, the F1 adversarial review surfaced a real instance of that under-shoot: a single-piece CL path whose exact unclamped smooth argmax overshoots the piece’s chain-saturation corner, so the old anchor ± 2 probe + break landed in the negative post-cliff region and the path silently returned None — skipping a measured 9.56e9 wei of profit. That is exactly the sharp bounded corner the window guards were meant to defend.

Decision

Do not re-land the V3/V4 window guards. The corner safety they provided now lives in the core refine path, in both cases the guards covered:

  1. Single-piece paths — the F1 terminal refine (305141729, a89cc1587) probes the chain-saturation corner (and the wei below it) and refines the terminal window [0, max(corner, anchor)], so the sharp bounded corner is always bracketed by construction, not by an added guard layer.

  2. Multi-piece paths — walk_refine_window (with the coarsened 1e6-wei bracket, 56b3bdf21) resolves each piece with a ternary + smooth-anchor window to profit-ε. Bounded pieces pin hi to the bisected right edge (piece_window_right_edge); terminal pieces (right edge = None) refine [x_l, max(4·anchor, 2·x_l, x_l+1024)], an anchor-keyed window that the Q1 proof shows contains the discrete argmax. A bounded downstream kink is therefore bracketed and resolved to the coarsening ε, satisfying the same profit-ε contract the guards would have enforced.

Re-landing would re-introduce a superseded, parallel guard over a corner the core refine now guarantees, adding review surface and dead code with no new safety. (The “single-piece terminal now self-covers” framing is the reviewer’s own, agreed during the F1 exchange.)

If revisited

Were a future review to want the guards back, encode the Q1 anchor-bound proof as a regression: for any hop-j kink that is a true peak (right-marginal < 1 just past it, left-marginal ≥ 1 just before it), the unclamped smooth anchor is ≥ the kink input, so the refine window max(corner, anchor) contains it. single_piece_hop1_binding_kink_is_not_dropped already pins this empirically for the hop1 case; a hop0-corner sibling is single_piece_saturation_kink_is_not_missed.

Consequences

  • V3/V4 guard branches stay un-merged; no re-land.

  • Corner safety is enforced by the core refine and pinned by two regression tests (single-piece saturation corner + hop1-binding kink).

  • Recurrence of the original refine runaway (multi-million sims) is structurally capped: with the 1e6-wei bracket, worst-case refine sims per piece are ~2·log₃(width/1e6) + 33 + ~1025 (dense) ≈ 350 even for a 2²⁵⁶-wide window. The old runaway came from a 64-wei dense sweep over giant windows, which the bracket eliminated — that cap is the defense against recurrence, not the lost guards.