[HARDENING] PENDING-164 AMENDMENT 2: the classification pass ran; PENDING-171 filed

AMENDMENT 1 declared its second half owed and unclaimed. It ran on 40 of 362
rows, pre-registered at 5ba5842 before any commit body was read.

Sample B, systematic across the corrected population: 12 of the 17 rows that
decide about a mechanism name one the register never mentions. Three of the
five recorded rows first entered the register 25, 46 and 53 days after the
commit. Sample A — the literal inherited question, the newest 20 — returns 1,
and the pre-registration said in advance that it would refute nothing: 9 of
its 20 rows write to the register in the same commit and cannot be silent by
construction.

Controls both directions. logchain 29 mentions (alive); ChromaDB 213 commits
and 0 mentions (silence is emittable). All three register files hash
byte-identical before and after; nothing was written to them until the last
row was measured.

PENDING-171: owned_repos() tests remotes against a fragment of the steward's
account name, so CapableMind-AI, BetterMemories.io and be are invisible — 89
unseen candidates, and six of the twelve silent mechanisms come from them.
Both positive controls are satisfied by the broken predicate.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01RmFYCUeAaPqbpJMj6uGokk
This commit is contained in:
David F Glidden
2026-08-31 09:17:53 +02:00
co-authored by Claude Opus 5
parent 5ba5842822
commit 1d46d484ff
2 changed files with 283 additions and 0 deletions
+73
View File
@@ -6425,3 +6425,76 @@ Two things follow, and they point opposite ways. **The check fired correctly**
**Files affected:** none yet. `~/REVIEWED.md` under (a) — steward's hand only.
**Awaiting:** nothing from the steward as a fresh decision — this is a **[FIX] blocked on a named dependency**, filed so the blockage is visible rather than remembered.
---
### PENDING-164 — AMENDMENT 2 result: the classification pass ran, and the backlog is real
**Date:** 2026-08-31
**Tag:** [HARDENING] — reporting only. No new ask.
**Placement note:** appended at the end rather than inserted beside PENDING-164's body, because inserting mid-file is what silently changed the line numbers a checker was reading on 2026-08-27 (PENDING-104 ADDENDUM 1). This is the disposition PENDING-110 and the record-keeping block exist to settle; it is not proposed as a scheme.
**Summary:** AMENDMENT 1 declared its own second half owed — *"the 270-candidate classification pass is unscheduled and unclaimed."* It ran. **Of 20 systematically sampled candidates, 12 of the 17 that decide about a mechanism name a mechanism the register never mentions.** Pre-registered at `claude/governance/PENDING-164-census-classification-PREREGISTRATION-2026-08-31.md`, commit `5ba5842`, committed alone before any commit body was read; result at `…-RESULT-2026-08-31.md`; population frozen at `…-population-362-2026-08-31.tsv`.
**Two samples, both fixed in advance, and the contrast is the finding.**
| sample | rows | mechanism decisions | SILENT | RECORDED-LATE | RECORDED-contemporaneous |
|---|---|---|---|---|---|
| A — the newest 20, as the instrument prints them | 20 | 11 | **1** | 0 | 10 |
| B — every 18th row of the corrected 362 | 20 | 17 | **12** | 3 | 2 |
**Sample A answers the question exactly as it was left, and its answer refutes nothing.** The pre-registration said so before the reading began: Sample A's head is the fortnight in which the register was most active, 18 of its 20 rows are `dotfiles`, and **9 of the 20 write to the register in the same commit** — such a commit cannot be register-silent by construction. A near-zero there measures the sampling frame, not the record.
**RECORDED-LATE was pre-registered for a reason and it earned its place.** Three of Sample B's five RECORDED rows first entered the register **25, 46 and 53 days** after the commit. The known case demanded the column: `LFS` scores 84 register mentions today, every one filed on 2026-08-26, twelve weeks after `0677e8a`. A mention that post-dates the decision by months is recovery, not routing. **Wider reading: 15 of 17.**
**The strongest instances are unambiguously in scope, and none was looked for.**
- `95b44d0` (CapableMind-AI, 2026-02-25) amends the **log-chain spec** to v0.6. The logchain is named in `~/CLAUDE.md`'s constitutional constraints and `logchain` appears in the register **29** times; `data-portability`, `ImportProvenance` and `import trust` appear **zero**.
- `d0051dd` retires `KRONOS_TRACKED_REPOS`, a stopgap another plan document names as such.
- `0e3deee` retires an entire session-memory protocol (`SESSION-MEMORY.md`, `CONTEXT-MAPS.md`, `PROGRESS.md`, `ROADMAP.md`) and names `update-docs.py` for retirement.
**Controls, both directions, pre-registered.** Must-not-flag `logchain` → 29 register mentions, alive. Must-detect satisfied on the second of three fixed candidates: `ChromaDB`, 213 commits, **0** register mentions. All three candidates reported regardless, as pre-registered — `SurrealDB` returned 2 and did not serve. **Contamination guard held:** all three register files hash byte-identical before and after measurement, and nothing was written to them until the last row was measured.
**Where the judgement sits, exposed rather than hidden.** Naming the mechanism is interpretation, as `prior-art.py`'s own docstring declares. **Every term string is recorded**, so any verdict is re-runnable in one command and contestable on the term rather than on the conclusion. Two deviations from the pre-registration, both stated, both neutral-or-adverse to the finding: multiple terms per row with SILENT requiring *all* of them silent; and a reading rule under which a register occurrence counts only if it is *about* the mechanism. Seven terms returned non-zero and every occurrence was read and is quoted in the result. The rule moved four rows **in both directions** — `benchmark` and `lex` to RECORDED, `ornament` and `recall quality` to SILENT. **Sensitivity band 10–13; the ruling is 12.**
**⚠ What this does NOT establish, stated at the same volume.** Nothing about the remaining **322** rows. n=20 of 362 supports no extrapolation and none is offered; 71% is a property of this sample, not an estimate of the backlog. And it does not establish that any of the twelve *should* have been in the register — a MemPalace CI retry policy is not obviously the steward's governance business. **That question is untouched.** What is answered is the one that was asked: whether the record contains them. It does not.
**⚠ An instrument of mine reported five false zeroes during this pass** — a malformed `grep -m8 -n -o` context probe — and for some minutes it looked like two instruments disagreeing, the shape this thread has learned to read as a finding. Plain `grep` and `register_mentions` agree exactly. The tool was broken, not the register. Recorded because the *next* such disagreement should not inherit the assumption that a mismatch is always meaningful.
**Files affected:** three new files under `claude/governance/`. `scripts/prior-art.py` deliberately **unmodified** — see PENDING-171.
**Awaiting:** nothing. AMENDMENT 1's declared-owed half is discharged for 40 rows and explicitly not for 322.
---
## PENDING-171 — The prior-art census cannot see three of the steward's repos, and its positive controls could not have caught it
**Date:** 2026-08-31
**Tag:** [HARDENING]
**Summary:** `prior-art.py`'s `owned_repos()` decides ownership by testing each repo's remotes against `OWNED_HOSTS = ("github.com/davidglidden", "davidglidden/", "git.skemantix.com")`. That matches an account name *inside a remote path*, which is not the relation it claims to compute. `_Dev/CapableMind-AI`, `_Dev/BetterMemories.io` and `_Dev/be` all fail it. **The census population is 362, not the 270 AMENDMENT 1 reported.**
**Measured 2026-08-31:**
| repo | first remote | census candidates |
|---|---|---|
| `_Dev/BetterMemories.io` | `git@github.com:CapableMind-ai/betterMemories_app.git` | 42 |
| `_Dev/CapableMind-AI` | `git@github.com:CapableMind-ai/capableMind_docs.git` | 35 |
| `_Dev/be` | `git@github.com:boomerbot-xyz/be.git` | 12 |
| | **total unseen** | **89** |
**Why this is not a tidy-up.** The two largest omissions are **the doctrine repo and the L1 implementation repo** — the two the wake digest lists first among active work, and the two where a decision that never reached the authorization record matters most. The instrument exists to find exactly that asymmetry, and it was blind to it in the places the asymmetry is most consequential. **Six of the twelve silent mechanisms found under PENDING-164 AMENDMENT 2 come from these three repos**; on the instrument's own population, half the finding is invisible.
**⚠ The controls could not have caught it, and the reason is the general one.** `controls()` requires `0677e8a` (chamber-library) and `95760ff` (dotfiles) to be returned. **Both are satisfied by a predicate that misses all three repos above.** The controls encode the two cases that were already known at the time of writing — which is the failure this record has now logged three times: a must-detect control that encodes an expectation nobody verified (the arendt ≥5 control, 2026-08-27), the LFS census whose first run measured nothing (2026-08-26), and this. ⚠ **The build record's own sentence — *"Note the positive control below forced this"* — is true of the enumeration *mechanism* and false as an assurance about its *extension*.** Computing a list rather than hand-holding it removes one failure mode; it does not make the predicate correct.
**⚠ Also true of the docstring's boast, and it should be corrected in the same act:** *"ENUMERATION IS COMPUTED, NOT HAND-HELD… A hand-maintained list is the failure mode PENDING-108 already measured."* A computed list with a wrong predicate is a **silent** hand-maintained list — worse than the honest one, because nothing reports the forgetting and the docstring says forgetting is impossible.
**Options:**
- **(a) Nothing.** The instrument is useful on 7 repos. Costs: the two governance-relevant repos stay unreachable to the check that exists to reach them.
- **(b) Widen `OWNED_HOSTS`** with `CapableMind-ai/` and `boomerbot-xyz/`. One line, five minutes. **Reproduces the defect's shape** — a hand-listed set with a computed veneer, correct until the next org appears and silent when it does.
- **(c) Invert the predicate: enumerate every repo under `$HOME` and exclude by rule** (vendored trees under `.vim/`, `.oh-my-zsh*/`, `.config/`, `Library/Caches/`, `.nvm`, `.fzf`), rather than including by account-name fragment. A repo the steward works in is then visible **by default**, and the failure mode inverts from silent-omission to noisy-inclusion. Costs a slightly larger census and some third-party noise.
- **(d) (c) plus a control that can fail.** Assert that the returned set contains a commit from each of a named minimum — chamber-library, dotfiles, **CapableMind-AI, BetterMemories.io** — so that dropping any one of them fails loudly. Not a fix on its own; it is what makes (c) checkable.
**Recommendation: (c) with (d).** The defect is not that three repos were missed; it is that **omission is the silent direction**. (c) makes inclusion the default and noise the cost, which is the direction the record's own doctrine prefers — *honest degradation*, Constraint 4. (d) is the part that matters most and is cheap: today's controls pass while the instrument is blind to two of the steward's five active repos, and no control that can only confirm known hits will ever say otherwise.
**⚠ Not repaired in this session, deliberately.** Changing `OWNED_HOSTS` would change the census population and break the reproducibility of the run that PENDING-164 AMENDMENT 2 samples from, which is pre-registered against a frozen 362-row list. The fix should land **after** that result is read, not inside it.
**⚠ Weakness of this item, stated by its author.** The exclusion rule in (c) is itself a list, and lists rot. The claim is only that it rots **loudly** — a newly-vendored dependency shows up as noise in a census a human reads, where a newly-created org shows up as nothing at all. If that asymmetry does not hold in practice, (c) is no better than (b) and this recommendation is wrong.
**Files affected:** `scripts/prior-art.py` (`OWNED_HOSTS`, `owned_repos`, `controls`); `scripts/governance-mcp.py` if the delegate's proof surface changes.
**Awaiting:** Steward authorization.