governance: REVIEWED-75 placed; PENDING-72/75 built-and-landed; session ledger
REVIEWED-75 (kind-scoping the verification criterion) placed by the steward. PENDING-75 -> spec v2.7.0 landed with both required corrections (V-SCAN's distinct criterion preserved; the anti-bypass guard rebound to the property). PENDING-72 -> spec v2.8.0 landed (voice-purity as the engine-consumable bar), mechanism built test-first, backfill executed 18/1, gate wired, single-reading- pass designed. Plus the source_lines FIX: producer + 11 consumers in one change-set, then corrected again when the base-rate sweep found splitlines() also wrong (308 lines' disagreement on one canonical). Ledger records the session's sharpest return: the sweep caught a fix one commit old, because ratifying a convention by comparing two implementations is SELECTION, not derivation — I verified the two disagreed, never that either was right. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Xefg5EXwcpd9RMAr63dWrD
This commit is contained in:
co-authored by
Claude Opus 4.8
parent
d77c86e7a5
commit
0a7feef12c
+11
-2
@@ -1690,7 +1690,14 @@ Disposition (verbatim capture + executor action-list: `chamber-library/docs/libr
|
||||
**Package (self-contained, jurist-ready):** `chamber-library/docs/engine-consumption-voice-purity-sidecar-JURIST-PACKAGE-2026-07-24.md` (GROUNDED-IN graduation-spec `sidecar_gate` + 2b Loeb-first ruling + sidecar-schema-LOCKED §1/§2 + engine `ingest_gate` contract + spec §Tiering&Fence, all quoted verbatim; the Eichmann leak inlined as the realized-failure evidence).
|
||||
**Files affected (on ratification):** spec supersession (the voice-boundary-attestation requirement; MINOR) + `graduation-spec.yaml` (`sidecar_gate` scope widened to baseline existence/binding/schema across tiers; whole-file attestation vocabulary) + `scripts/graduate_to_canonical.py` (the check) + possibly a chamber↔engine locus decision (Q2). No re-verify storm (0 hold engine-verified through this gate; forward-only).
|
||||
**RULED 2026-07-24 — design-gate PASSED, strengthened** (`docs/engine-consumption-voice-purity-sidecar-JURIST-RULING-2026-07-24.md`, filed verbatim; Addendum + REVIEWED-73 draft appended to the package). All 5 Qs resolve toward the proposal. **Sharper diagnosis (frame on this): ORTHOGONALITY** — `trim.keep` answers "should this be preserved?"; voice-purity answers "whose words?" — orthogonal + ANTI-correlated where it matters (the Eichmann leak = Elon intro + Bibliography = `trim.keep`, correctly kept; **extending the trim is the WRONG fix**). **Q1 STRENGTHENED: sections[] must partition the file body EXHAUSTIVELY** (no gaps/overlaps) — converts silence→assertion (the gate derives nothing, so nothing else forces completeness; the teeth my package lacked). **Q2 ruled CHAMBER-SIDE** on the concrete arg (my architectural lean was right-but-weak): engine-side sidecar breaks on every re-conversion (`ingest_gate` sidecar-sha==live; PENDING-53 class, **5 standing FAILED rows since 2026-07-10**) → produce+gate at graduation, engine reads. **Q3** falsifiers = existence + binding + schema + exhaustive-partition + closed-vocab `role {text,paratext,apparatus,reference}`. **Q4 MIGRATE the 19** (not grandfather — Eichmann is among them, correct only post-leak); carry `_reviewed`→`attested_by` + add **REVIEWED-64 `line_frame: landed-file`** (the package MISSED this — sections[] is a coordinate-contract family); backfill scope = engine corpus (~20), NOT chamber (1,297). **Q5** V-SCAN baseline yes / rich no. **Cost:** per-file reading pass compounds → design the SINGLE-reading-pass (boundary-drop ⊂ voice-purity, one read) before the wave.
|
||||
**Awaiting:** steward placement of REVIEWED-73 (draft in the package Addendum) → land the amendment (constitutional requirement framed on orthogonality + declared-data mechanism: exhaustive-partition · closed-vocab role · chamber-side production · line_frame · whole-file attestation) → build the widened `sidecar_gate` → migrate the ~20 → design the single-reading-pass. Related: PENDING-71. **Does NOT block Warde's chamber graduation; DEFINES what Warde needs to become an engine voice** (exhaustive sections[] over the canonical: essays=`text`, CUP Bible facsimile=`apparatus`, front/back=apparatus; line_frame landed-file).
|
||||
**BUILT + LANDED 2026-07-27 (REVIEWED-73 placed 2026-07-24):** spec **v2.8.0** (v2.7.0 frozen; bounded-diff proven — 1 deletion + hunks confined to header stack and the new obligation), the obligation stated beside the one-door two and **framed on the orthogonality** (so a future reader reaching for the trim to close a voice leak stops at the right place). Mechanism: `scripts/verify_voice_purity.py` (16 self-test invariants; **the negatives are the point** — each is a failure class the leak or the ruling named) + `graduation-spec.yaml` `voice_purity:` (closed roles · frame contract · backfill scope · **named open seams**) + `scripts/migrate_voice_purity_sidecars.py`; fleet **266/266** (was 248). **Backfill EXECUTED: 18 migrated · 1 HELD**, verified at the REAL enforcement path (18 PASS / 1 REFUSE); census `_curation/voice-purity-backfill-2026-07-27.tsv`. ⚑ **The rule validated itself on first contact** — applied to the existing engine corpus it surfaced **3 files with unassigned trailing lines** (ARC ornament tails; assigned + flagged `_migration_assigned` for curator confirmation, since the ROLE is a judgment neither gate nor script can make) **and 1 drifted binding**: `musil-mwq-tome-1` (canonical 5032→5038 lines) — **the engine has been serving Musil with boundaries shifted by 6**, body truncated early and 6 lines unassigned at the tail. HELD for re-derivation by a reading pass, not migrated. ⚑ **Correction to the ruling's premise (measured, not inferred):** the ruling cites the *5 standing FAILED ARC rows* as the live instance of the cross-repo drift class — **all five ARC sidecar bindings verify clean**; the one genuinely broken binding is Musil, a chamber canonical. The argument for chamber-side is unaffected (it is architectural), but the cited instance was wrong and the real one was unknown.
|
||||
**Single-reading-pass: DESIGNED, not built** (`docs/single-reading-pass-DESIGN-2026-07-27.md`) — the two reads are *nested* (the derived boundary runs fall inside sections the curator assigns anyway), so **one read can emit both records**; the saving is the traversal, NOT the judgment count. States the collapse it must avoid: **boundary-drop labels must NEVER be derived from voice-purity roles** (`role: apparatus` + `trim.drop: keep` is the common correct case — an author's own endnotes); a derived attestation is the silent default wearing a second name. Named dependency for building it: no boundary-drop capture surface exists either, so this would be the lane's FIRST curator-facing tool, not an optimization of one.
|
||||
**GATE WIRED 2026-07-27 — the chain is CLOSED:** land the amendment ✓ → migrate the ~20 ✓ → design the single-reading-pass ✓ → **wire the gate ✓**. `voice_purity_gate()` + `write_voice_purity()` in `graduate_to_canonical` (after `sidecar_gate`); fleet **278/278**; real dry-run **INERT** (no candidate currently reaches it — all 8 gate earlier on health/conventions). **Scope resolved without straining either leg of the ruling:** engine-registered candidates only — Q2 gates *at graduation*, Q4 bounds the obligation to the *engine corpus*; both hold at once, and this is what stops the bar silently blocking the un-registered Loeb wave (non-registered = NOT-APPLICABLE, proceeds). **The authoring/stamping seam resolved by READING the apply leg, not assuming it:** graduation is a **pure move** (`git mv`/rename, no content transformation), so the candidate's bytes ARE the landed bytes — the curator attests against the candidate and the coordinates are already landed-frame. `write_voice_purity` re-stamps **only** `source_file`/`source_path` and deliberately does **NOT** recompute sha/lines: recomputing would let a silent content change re-bind quietly, which is the drift the binding exists to catch.
|
||||
**⚑ NEW FINDING (6th shared-name/two-senses instance — after manifest · ABSTAIN · app[] · line · frame): `source_lines` is computed two ways in-repo and they disagree by ONE.** Engine-side `len(splitlines())`; chamber-side `write_sidecar` `text.count("\n") + 1`. **Measured on all 11 landed Loeb sidecars: every one is count+1** — one MORE line than the file has, a *phantom line past the final newline*. Harmless while `source_lines` is only a binding head field; **LOAD-BEARING under exhaustive partition**, which would demand a curator assign a line that does not exist. **Declared, not silently fixed:** `voice_purity.line_count: splitlines` states the correct convention *for this gate* (REVIEWED-64: a 1-based line in `source_file` — N newline-terminated lines is N lines). **Reconciling `write_sidecar` is a PRODUCER change with 11 landed consumers → its own FIX/PROPOSAL cycle**, not a tool edit made in passing (the change-impact clause: a producer change must enumerate its consumers). Named in `voice_purity.open.line_count_divergence`. **Recommendation:** FIX-class (the count is wrong against the ratified frame definition, not a design choice), landing with a bounded re-stamp of the 11 + a byte-diff proof that nothing but `source_lines` moves.
|
||||
**RULED + BUILT 2026-07-27 (steward: FIX, re-stamp now, producer-then-consumers in one change-set).** Grounds accepted as stated: REVIEWED-64 ratified "a 1-based line in `source_file`", and a file of N lines has no line N+1 — `count+1` did not name a second defensible convention, it named a coordinate the ratified frame says **cannot exist** (the de-glued-marker shape: restoring ratified intent against an implementation that never matched it). ⚑ **The steward's "confirm the rule, not the sample" caught a live corruption risk:** the formulas agree iff the file does NOT end in a newline — **36 of 1,297 canonicals** — so a blanket `-= 1` migration would have corrupted exactly those 36; the 11-file sample (one producer, all newline-terminated) could not have revealed it. Migration **recomputes per file**. Landed `4a1a731`: producer fixed + all 11 re-stamped in one change-set, **byte-diff = 11 files / 11 insertions / 11 deletions, every changed line a `source_lines` field**.
|
||||
**⚑⚑ THE SWEEP'S FIRST YIELD LANDED ON THAT VERY FIX (`b82fc48`) — reported as a correction, not a refinement.** I had ratified `len(splitlines())` on the strength of the engine-side convention **without checking what `splitlines()` splits on**: it also breaks on `\v \f \x1c \x1d \x1e \x85 U+2028 U+2029`, which **no** consumer of a line coordinate treats as a break (editor · `wc -l` · `sed -n 'Np'` · the engine chunker). Censused: **4 canonicals carry them** — `lintott` **308 lines' disagreement**, `auerbach` 52, `rutter` 2, `solnit` 2 (U+2028); `wc -l` confirms newline-based. **So BOTH prior formulas were wrong, on COMPLEMENTARY subsets** (`count+1` on the 1,261 newline-terminated; `splitlines` on the 4 exotic-bearing) — *no single sample distinguishes all three*, which is the generalized form of the steward's own point. Correct rule: `count("\n") + (0 if trailing newline else 1)`, empty = 0. **ROOT CAUSE fixed, not just the value: ONE implementation** (`verify_voice_purity.count_lines`; `write_sidecar` + the migration script now IMPORT it) — two formulas for one field is how this arose and a third would have arrived the same way. `measure()` also now REFUSES an unknown declared convention (no silent fallback) and hashes **raw bytes** not `read_text().encode()` (universal-newline translation diverges on CRLF; 0/1,297 CRLF today — door closed before use). **INERT on landed artifacts** (0/11 carry exotic chars → the `4a1a731` values stand, no canonical moved); the correction is to the stated convention + implementation, which would have bitten the moment Lintott/Auerbach/Solnit/Rutter acquired a sidecar. Pinned on all three shapes + the one-definition invariant; the suite caught the stale assertion from the prior commit on first run. Fleet **288/288**.
|
||||
**Base-rate sweep (steward-directed, "an hour"; the yield was not zero) — remaining sites CHECKED:** `sha256` — one live basis divergence class (`read_text().encode()` vs `read_bytes()`, CRLF-only); **0/1,297 CRLF**, my tools now on bytes; `write_sidecar` still text-based → *named, not silently changed* (same producer-with-consumers shape). **Tokenizers AGREE**: `\w+` + `.lower()` identical across `verify_body_conservation._tokens`, `inject_epub_footnotes` (×3), `build_sidecar` (×2) — the missing `re.UNICODE` on `build_sidecar:198` is a **no-op** (default for str patterns in py3), and `inject:358` is pre-lowered on the prior line. Empirical cross-check on Eichmann: gate 122,715 vs raw 122,735 tokens, **identical 9,620 types**; the 20-token delta is exactly the footnote-marker digits `_tokens` strips by design and the injector accounts for separately via `converted_markers`. **Consistent-by-design, difference fully accounted.**
|
||||
**Awaiting:** the 3 `_migration_assigned` ARC tails want curator confirmation of the ROLE; `musil-mwq-tome-1` wants a reading pass to re-derive its boundaries; `write_sidecar`'s text-vs-bytes sha basis wants its own small FIX cycle (latent, 0 live instances). Related: PENDING-71. **Does NOT block Warde's chamber graduation; DEFINES what Warde needs to become an engine voice** (exhaustive sections[] over the canonical: essays=`text`, CUP Bible facsimile=`apparatus`, front/back=apparatus; line_frame landed-file).
|
||||
|
||||
## PENDING-73 — Born-digital V-TEXT added-side check: the fabrication measure REVIEWED-72 activated (change-class confirmation)
|
||||
**Date:** 2026-07-24
|
||||
@@ -1716,4 +1723,6 @@ Disposition (verbatim capture + executor action-list: `chamber-library/docs/libr
|
||||
**Gate questions (with leans):** Q1 placement (lean: evidence-tiers preamble, tightest adjacency) · Q2 anti-bypass clause verbatim (lean: keep, it is the separator) · Q3 Edit-3's true subject (⚑ flagged: principle not field) · Q4 change-class (lean PROPOSAL/MINOR/additive-in-effect) · Q5 is Edit 2 needed or subsumed by Edit 1 (lean: keep).
|
||||
**Landing:** standalone MINOR supersession (v2.7.0 or steward's version call) — NO in-flight supersession assembling (v2.2.0→v2.6.0 all landed); additive-in-effect (no current canonical changes tier/method → no re-verify storm). Requirement = constitution; which-kinds-exist + their methods = declared data.
|
||||
**Files affected (on ratification only, drafted to the Addendum's corrected design):** `docs/chamber-library-specification.md` (§Tiering & Fence + §V), `docs/sidecar-schema-LOCKED-2026-07-12.md` (naming note). Nothing built/run/landed now.
|
||||
**Awaiting:** steward relay → jurist design-gate.
|
||||
**RULED 2026-07-25 — design-gate PASSED, with one REQUIRED correction** (`docs/kind-scoping-verification-JURIST-RULING-2026-07-25.md`). The jurist **adopted the package's Part-4 argument over his own framing**: the foreclosure is not that a non-text work *fails* the criterion but that the criterion is **VACUOUS** on it (empty re-extraction is trivially prose-word-identical to itself) — the false-positive shape, caught prospectively for the first time rather than after a finding. **Required correction:** Edit 1's *"that method is prose-word identity … (V-DSL · V-TEXT · V-SCAN)"* **overstates against V-SCAN**, whose ratified row says *no ground-truth text* and whose bar is *"a distinct, named, more-expensive criterion — not the deterministic bar relaxed"* — the scoping sentence must not flatten a distinction the table already draws. **Q1** placement at the evidence-tiers preamble CONFIRMED (that is where method is *defined*; tier-1 would scope the bar and leave the definition unscoped). **Q2** guard kept and **rebound to the property, not enrollment** (*"a text-bearing work … no work may weaken its applicable method"*) — as drafted it reached only existing kinds and would open the moment the door is first used. **Q3** Edit 3's correction ACCEPTED, the jurist's `line_frame` shape WITHDRAWN (3rd substrate-refutes-composed-shape this session); the heavier rename correctly declined. **Q4** PROPOSAL/MINOR confirmed, the FIX reading **declined on the vacuity argument**. **Q5** Edit 2 kept (§V reads as a prose-framed universal alone; cross-section inference is what a successor cannot be assumed to perform). **Carry-forward for the REVIEWED entry, NOT spec text:** the primitives that would serve a future non-text kind already exist ratified (character-bearing image = content, hash-fixed, catalogued normalization, never silently dropped — REVIEWED-70 Q3; the Loeb sidecar's typed `{kind:'glyph', file:…}`) — nothing reserved, nothing promised, but a successor should find in the record that the architecture already pointed that way.
|
||||
**BUILT + LANDED 2026-07-25 (steward-authorized verbally; REVIEWED-75 placement 2026-07-27):** spec **v2.7.0** (v2.6.0 frozen `-v2.6.0.md`; **bounded-diff proven** — 1 deletion [the title line, reappearing as `(obsoleted)`] + 3 hunks [header stack · §V +6 · evidence-tiers +16], every other line v2.6.0 byte-preserved), both corrections applied verbatim to the ruling, + the sidecar-schema **generality note** (FIX) with its amendment-log row. Fleet 248/248 (doc-only change, baseline unmoved). CLAUDE.md brought current.
|
||||
**Awaiting:** steward placement of REVIEWED-75 (draft ready, 2026-07-27). Related: REVIEWED-64 (`line_frame`/the declaration principle), REVIEWED-70 (§V character-as-image), REVIEWED-56 (sidecar additive-only lock discipline).
|
||||
|
||||
Reference in New Issue
Block a user