session 2026-08-09: PENDING-129/130 filed → REVIEWED-113/114 placed; the V4 fixture was a 0-byte file

This commit is contained in:
David F Glidden
2026-08-09 21:27:53 +02:00
parent f530df6cde
commit 009359f64e
8 changed files with 571 additions and 7 deletions
+14
View File
@@ -348,3 +348,17 @@ honest proposal is that the steward decide whether the degraded-state form is di
earn its own entry or should be folded into the existing one as an example.
**Awaiting:** steward authorization.
### 2026-08-09 wrap — two proposals; firing moments declared per the REVIEWED-95 gate
**#196 — `governance-drift-check.py`: assert that any text calling a governance item *unruled* or *unplaced* agrees with the register.** Earned twice in one session, steward-caught both times: I wrote *"PENDING-130 is unruled"* in a commit message and had an artifact header say the item *"proposes"* — while REVIEWED-114 had ruled it (a) with five conditions. **Ruled · placed · condition-discharged are three states and none implies another**; the existing built-vs-ruled check covers only *built-with-no-ruling*, which is the opposite direction and did not fire. Proposed: for every `PENDING-N`/`REVIEWED-N` in the memory files, registers and repo docs asserted to be *unruled / unplaced / not yet ruled / awaiting*, assert the register agrees.
**Firing moment: mechanical, should always fire → `governance-drift-check.py`** — already named in a `/wake-up` step (the measured 83% home class) and already performing register-integrity checks. **Real positives available, not synthetic:** today's two, both preserved in git (`8746dcf`'s message; `07727dd`'s parent state).
**Classification:** detection-only; asserts nothing, expands no latitude → reads FIX-lane. **Filed as `[PROPOSAL]` anyway**, on the same ground as #192: the check is unbuilt and untested, and this session's own lesson is that my checks are weaker than my writes. **Status: PROPOSED**, to be ruled with #192/#195 if convenient — all three are drift-checker extensions.
**#197 — ladder entry (gate-design family): an induced-red probe must revert BEHAVIOUR, not delete the symbol.** Removing the function under test produces an **`AttributeError` traceback**, which proves the suite *crashes* when the code is absent — not that it would **name** the regression when the code is present and wrong. The honest probe leaves every name in place and monkeypatches the pre-defect semantics; mine then produced exit **1 with six named failures**, camus by name and the `KeyError` resurfacing. ⚠ **Companion, same command:** the exit code was read **through a pipe** (`… | tail`), so the reported `0` was `tail`'s — the *reduction-before-looking* class, already banked as #195 and firing again the next day.
**Firing moment: on a condition the executor must first notice** — *"I am about to witness this suite red."* The weakest routing row, **declared as such rather than dressed up**; no mechanical detector exists for it. Routed to `reference-verification-ladder.md` §Gate design, beside *"a control must sit at the layer the defect lives in"*, which it is a special case of: deleting the symbol puts the control at the wrong layer. **Recorded estimate: ~10–14% retrieval pending the ladder-ritual trial.**
**Classification: `[PROPOSAL]`** — changes what the executor must do before trusting a witness-red. **Status: PROPOSED.**
**Deliberately NOT proposed.** The preservation-header self-match (a strip instruction that quotes the marker it tells you to strip to, so `index()` matches inside the header) is a **one-shot** defect in a one-shot artifact, caught by the round-trip that was already there. Per `feedback-one-shot-instruments-are-proportionate`, its counterfactual is an assertion, not a durable instrument — filing it would be documentation dressed as diligence. The generalisable half is already banked: **compare against a fresh emit, not against a recorded sha**, which is what caught it.
**No FIX-lane changes were applied this session.**