Closes the CDC gap found in the FIFO bug-rejection corpus by
implementing Phase 1's committed scope from 02-type-system-core.md §5
("nominal clock/reset domains"), not Phase 2's full typed-CDC-bridge
contract system.
strata-hir already elaborated ClockDomain items and attached domain
labels to types via TypeKind::Label, but nothing consulted them and
item-level unsafe(name) qualifiers (already parseable) were dropped
during lowering. This wires both up:
- HIR now records ItemHeader.unsafe_qual, so unsafe(clock_crossing)
survives lowering.
- strata-check's package_type_equal now strips Stamped domain wrappers
before structural comparison (previously any domain-labeled type
broke equality outright).
- A new structural check (cdc_unbridged_domain_crossing) rejects a
body's return/tail, let initializer, register reset, or register
update whenever both sides carry explicit, differing domain labels,
unless the component is marked unsafe(clock_crossing).
Deliberately does not touch domain inference/propagation, generic
domain params, mem/array storage, evidence tiers, or contract/epoch
machinery — those remain real Phase 2/4 gaps, not silently closed
here. cdc_bridge.strata (the full Phase 2/4 fixture) is unaffected:
its crossings live entirely inside still-deferred domain{}/mem/sync_ff
constructs.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
4ffcb40a54versecafe committed on 8/20/2026, 12:10:18 AMparent767e623