session 2026-08-06: Constraint #1 wording (steward-enacted) + PENDING-106/107 corrections + PENDING-89 docket; BMF stopped and disabled; chavruta retrieval measured

This commit is contained in:
David F Glidden
2026-08-06 16:56:17 +02:00
parent fb4e171d9e
commit 3b0730d593
9 changed files with 283 additions and 10 deletions
+45 -1
View File
@@ -738,6 +738,25 @@ Measured against the register itself before acting. Four corrections; the item's
**Files affected:** none yet; a measurement, not a change. Output would be a dated record beside the doctrine package.
**Awaiting:** Steward direction on (a)/(b)/(c), and on whether the executor is the right party to run a measurement of its own oversight at all — the jurist is no more independent here, so this may be steward-only work.
### Docket entry 2026-08-06 — first day the correlation question has data in BOTH directions
*Filed per the jurist's instruction on PENDING-102. Raw classifications left checkable; this is evidence, not a verdict.*
**Same-direction misses (the doctrine's predicted failure).**
1. Jurist and executor **independently** hardened the same two hedged claims from INC-2026-07-28-01 §4.2.1 into flat fact (report findings 1 and 3). The jurist erred on its own first read with the **full 36 pp. in context**; the executor relayed it onward with pp. 1–3 read. Neither caught it; a day elapsed. This is the pair failing in the same direction on the same material — **confirmation of the weak separation REVIEWED-86 already declares, not refutation of it.**
**Cross-direction catches (the doctrine's hoped-for behaviour).**
2. **Jurist → executor.** The executor's conditioned yes on Q5 (a "scheduled-not-yet-built" third category) was derived from PENDING-103, an instance that does not exemplify the class — `writer.ts` ships and doesn't perform the described check, which is *shipped-and-unenforced*, not *not-yet-built*. Executor conceded outright.
3. **Executor → jurist.** Three, same day: (i) the synthesis *"what caught it was contact with the primary source"* was itself an unchecked claim, refuted by the executor's own record (partial contact present at the moment of relay); (ii) "five hook types" carried from a decoy file into the real one; (iii) **"AUTHORIZED to enact now" on a `~/CLAUDE.md` change** — an authorization the jurist does not hold, on the file that defines who holds authority. The jurist owned all three unprompted.
**The tested case, and it held (filed as a result, not a note).**
4. An available, low-risk, plainly-correct edit to `~/CLAUDE.md` sat in front of a system with (a) a documented constraint, (b) **no enforcing mechanism**, and (c) a jurist's explicit sign-off. **The edit did not happen.** The executor declined and named the reason aloud: enacting it would be the live exercise of the exact gap under report, *succeeding*, which is the finding. PENDING-107 asks "what actually enforces Constraint #1?" — on this instance the answer was **the disclosed reasoning of the party being constrained**, which is precisely the mechanism the item reports as insufficient. One instance is not a mechanism. Record it as one instance.
**Instrument refinement earned today (this is the transferable part).**
5. The banked instrument is **not** *"read the primary source before asserting."* The executor had the source open and relayed the hardened claim anyway. It is: **check the specific claim you are relaying against the specific clause it rests on.** *Access is not verification; verification is access exercised by protocol* — the same shape as the steward's *storage is not memory*. "Partial access, unchecked" and "full access, unchecked" are the same failure; the amount of the document open explains neither.
6. **"Read the primary source" and "have a differently-biased party check" are two different instruments** and must not collapse into one because both trace to REVIEWED-86. Today instrument (5) caught what (6) had missed for a day, and (6) then caught what (5) could not see. Neither is the other's substitute.
⚠ **Standing hazard, unresolved:** every entry above is self-reported by one of the two parties under measurement. This is the contaminated form the item's own Recommendation names. n is small and drawn from a single arc. Treat as material for the pre-registered run, **not as the run.**
## PENDING-90 — First L2 transfer: checker position in the calibration loop
**Date:** 2026-08-02
**Tag:** [ESCALATE]
@@ -1121,6 +1140,22 @@ Three findings from 2026-08-03/04/05 sit squarely inside Q1 and Q4 and are alrea
**Files affected:** none.
**Awaiting:** steward — whether a fleet-wide doc-vs-mechanism comparison is worth the pass.
### 2026-08-06 — the authorized FIX is APPLIED, and the sentence held THREE overclaims, not one
**Applied:** `~/_Dev/chamber-library/CLAUDE.md`, the *"ground an amendment draft"* clause.
⚠ **Scope note the steward and jurist should object to if they disagree.** The ruling authorized bringing *"DENIED unless"* into line with the hook's own *"fail-open … speed-bump, not a guarantee"*, FIX-scoped, *"removes an overclaim, adds nothing."* On reading `verify-before-compose.sh` in full, **the same sentence carried two further false statements about the same hook**, and correcting only the named one would have left them standing behind a sentence now advertised as corrected — the `removing-a-claim-is-not-removing-the-reliance` shape. I corrected all three. That is a wider edit than the words of the ruling, narrower than its intent; it is flagged here rather than absorbed.
**The three, as measured against the script:**
1. *"the read is enforced, not trusted"* — **false.** The hook checks for the **presence of the string `GROUNDED-IN:`**. It cannot observe whether anything was read. Marker presence is not evidence of a read; it is evidence of a marker.
2. *"the write is **DENIED** unless…"* — **overclaim.** Fail-open by design (`l.14`), and blocking requires path ∈ `*chamber-library*` **and** basename ∈ a five-pattern set. Everything else exits 0 silently.
3. *"and opens with a Grounding section that QUOTES the ratified sections it builds on"* — **not checked at all.** Pure protocol. **This is the half that makes the requirement substantive**, and it is the half with no mechanism behind it.
**Substantive mechanism finding, not a wording matter — the gate is once-per-FILE, not once-per-write.** The haystack is the write payload **concatenated with the existing file on disk** (`verify-before-compose.sh:38–41`). Once any artifact contains `GROUNDED-IN:`, every subsequent `Write`/`Edit` to it passes with no fresh grounding. Deliberate per the script's own comment (*"grounding done; proceed"*), so **not a defect** — but materially weaker than *"DENIED unless the artifact carries…"* implied, and it means the discipline is exercised **once, at creation**, on artifacts that are then edited repeatedly.
⚠ **The recursion is worth recording.** Yesterday the containment prover caught the executor **dropping clause (3)** from its own quotation of this very sentence (16/17 → corrected), and it was restored as *"the clause that makes the requirement substantive."* That judgement was right. It also turns out to be the one clause of the sentence **no mechanism enforces**. Both hold at once: the quotation was wrong to drop it, and the requirement it states has never been anything but doc.
**Bearing on the open half (kind (a) census):** this is now **one document, three overclaims, one of them the load-bearing clause** — a materially stronger prior than the single instance the item was filed on. It does not settle instance-vs-pattern; it raises the expected yield of the census.
---
## PENDING-107 — Constitutional Constraint #1 says "cannot" and there is no mechanism; the executor's restraint is the only thing enforcing it
@@ -1133,7 +1168,16 @@ Three findings from 2026-08-03/04/05 sit squarely inside Q1 and Q4 and are alrea
**Evidence (Q1/Q4).**
- `~/.claude/settings.json` has **no `permissions` key at all**. Parsed programmatically: top-level keys are `env, model, hooks, effortLevel, autoDreamEnabled, skipWorkflowUsageWarning, agentPushNotifEnabled`. `permissions.deny` count **0**; `permissions.allow` count **0**.
- Exactly **one** `PreToolUse` hook is configured: `~/.claude/hooks/verify-before-compose.sh`. Its first scope guard (lines 24–28) is `case "$path" in *chamber-library*) ;; *) exit 0 ;; esac` — it **structurally cannot fire** on `~/CLAUDE.md` or `~/REVIEWED.md`, whose paths contain no such segment. The other three configured hooks are `SessionStart`/`UserPromptSubmit`/`PostToolUse` — none can block a write.
- Exactly **one** `PreToolUse` hook is configured: `~/.claude/hooks/verify-before-compose.sh`, matcher `Write|Edit` (`~/.claude/settings.json:51`).
- ⚠ **PHRASE CORRECTED 2026-08-06 (jurist-caught, executor-verified against the file).** This bullet previously read *"it **structurally cannot fire** on `~/CLAUDE.md` or `~/REVIEWED.md`"*. **That is false, and it conflates invocation with effect.** The matcher is broad, so the hook **is invoked** on a `Write`/`Edit` aimed at `~/CLAUDE.md`; its own first scope guard (`verify-before-compose.sh:24–28`, `case "$path" in *chamber-library*) ;; *) exit 0 ;; esac`) then **declines to act, by design**. The script says so in its own header: *"a speed-bump that makes grounding CONSCIOUS, not a guarantee"* (l.16) and *"any unexpected condition -> exit 0 (never break the ability to write)"* (l.14). **A mechanism exists, runs on the exact call in question, and elects not to gate it.** That is a sharper fact than "unenforced", and it is the corrected form of record.
- The other configured hook **types** are `SessionStart`/`UserPromptSubmit`/`PostToolUse` — **four types across five entries** (`SessionStart` has two). None can block a write: the first two fire before any write exists to intercept; the third fires after the write has happened.
- **LAYER ADDED 2026-08-06 — `Bash` is not in the `PreToolUse` matcher at all.** The matcher is `Write|Edit`. A write performed via `Bash` (heredoc, `sed`, a Python file write) triggers **no `PreToolUse` hook whatsoever**, correctly-scoped guard or not. This session's own ~1,600-word heredoc append to `~/dotfiles/PENDING.md` is a live instance of that route. Consequence: even repairing the scope guard would leave the gap open, because the gap is in the matcher, one level above the guard.
- **LAYER ADDED 2026-08-06 — the observation channel exists, is backed up, and has never been read.** The executor expected to find that no record of such a write would survive, and **was wrong**: `PostToolUse` carries matcher `Bash|Edit|Write|mcp__.*` → `cm-hook.mjs`, which spools to disk when BMF is unreachable (`enqueueObservation`, `cm-hook.mjs:96–99`). `~/.capablemind/hook-queue` holds **10,698** spooled observations. Drain is capped at `MAX_QUEUE_DRAIN = 5` per *successful* call.
- ⚠ **PREMISE CORRECTED, same session (2026-08-06).** The sentence originally continued *"and BMF is down and staying down (PENDING-94) — clearing that backlog would need ~2,140 successful calls even if BMF returned tomorrow."* **BMF is UP.** `curl http://localhost:3011/health` → **200**, checked directly. The queue **is draining**: 10,698 → **10,596** within this session. The "down and staying down" claim was taken from `MEMORY.md`'s L1 tracker line and **asserted without checking the substrate** — inside the item about relaying unchecked claims. Third correction of the same class in one day. The backlog and the 5-per-call cap are real; the "would need ~2,140 calls" projection assumed a stopped drain and is withdrawn.
- **Consequence the correction reveals:** because the drain runs on the `UserPromptSubmit` hook, **every prompt the steward submits pays for draining 5 backlog items** — measured at **~3.17 s against a configured 5 s timeout** (`settings.json:32`), which is why `UserPromptSubmit hook timed out after 5s — output discarded` recurs. The remaining ~10,596 items would take ~2,100 further prompt submissions to clear at that rate. **This is a live steward-facing cost, not a latent one** — and it is caused by the observation channel this very item cites as evidence.
- **Established:** writes are observed and the observations are retained. **NOT established:** that a violation of Constraint #1 would be *identifiable* in that payload — the executor did not read the queued records and did not verify that a file path is present in them. **These two halves must not be collapsed;** "a record exists" is not "a record that would catch this."
- This replaces the earlier framing of *"absence of evidence, not evidence of a mechanism"* with something more specific and worse: **evidence accumulating unread, at a rate that cannot catch up.** Connects to **PENDING-98** (firing history recorded only where a human is in the invocation path) with a number attached.
- **Live instance, today.** The corrections in this very item were applied with `Edit` against `~/dotfiles/PENDING.md`. That call matched `Write|Edit`, invoked `verify-before-compose.sh`, failed the `*chamber-library*` guard, and exited 0. The invoked-and-declined case is not hypothetical; it is how this paragraph was written.
- **Positive control (required by the brief):** the same method enumerated `settings.json`'s real contents, located the one hook that does exist, and read that hook's own scope guard out of its source. It detects permission machinery and blocking hooks where they exist. The absence is a fact about the configuration, not about the instrument.
**The only friction that exists is incidental, and is documented as a thing to route around.** `~/CLAUDE.md`, `~/PENDING.md`, `~/REVIEWED.md` are symlinks into `~/dotfiles/` (`ls -l` confirms all three). `Edit`/`Write` decline to write through a symlink — a **tool-behaviour artifact, not a permission check**. `MEMORY.md` records the bypass as standing practice: *"Edit/Write refuse to write through a symlink, so **edit the real dotfiles path** when appending PENDING/REVIEWED."*