[PROPOSAL→AUTHORIZED] Control Kernel v1.1 — A demoted to a diagnostic; the control document is a derivation

Steward authorised the A-free rule. v1.0 is superseded and retained unchanged as
the record Reduction 01 and 02 were run under; no run was ever graded under it,
so nothing is invalidated.

THE CHANGE. Both reductions returned A=0 across 152 assertive units — our prose
does not name assumptions inline, it collects them into a section. That reads
like a defect and points the other way: a document with NO assumptions does not
hedge, and the prompt's anti-echo clause ('an assumption the author has already
named is not a finding') goes INERT, because nothing is named to exclude. So
'nothing found' can no longer be reached by recognising a confessional register;
it requires checking that every claim is demonstrated or quoted. The control
document is therefore a DERIVATION, not an argument — the proof-assistant
condition, and the strongest form the control can take.

Operationally: needing an A is a failure signal, not a licence. Derive the claim
or widen §1 and say so. Never name it and proceed.

WHAT IT BUYS (§7). The injected-defect arm becomes specifiable for the first
time: a defect is a RECORDED TRANSFORMATION — take a D and silently
de-demonstrate it. False-positive rate from the control arm, detection rate from
the defect arm, and the ground truth for both is a ledger rather than the
executor's reading. That is the first ground truth in this programme that is not
my judgement.

ALSO FOLDED IN, as corrections of the kernel's own account of its reach against
measurement already recorded — leaving them would have the kernel misstate what
it does, which Constraint 4 forbids:
 · the genre boundary, measured (8.5% on a ruling, 68.6% on a package)
 · §3.3 named a screen not a decision, and §2a moved into §4's judgement residue
   after it false-passed a real package
 · §6.3's cue test RE-AIMED: A-free removes the confessional-register risk and
   substitutes its opposite — a derivation may read dry and authoritative and
   earn 'nothing found' from that register instead

HELD with the dependency named, not deferred vaguely: PARAPHRASE and table rows
under §2c. Both bite only in the REDUCTION arm, and the control is now
constructed, so both are avoidable by construction and neither blocks the
critical path. They return if reduction is ever used to produce a control.

§4's residue list is now six. Its DIRECTION is unchanged — all six remain ways
for the author to make a document look sound. Watched.

1899 words, up 5% from v1.0 draft-2. §1 hashes re-verified against the live
sources. No control document has been written.
This commit is contained in:
David F Glidden
2026-08-02 18:07:36 +02:00
parent e9f3544012
commit 3d0d9d6f27
2 changed files with 118 additions and 0 deletions
@@ -0,0 +1,116 @@
# Control Kernel v1.1 — what "sound" means for a Fool false-positive control
**Supersedes v1.0** (frozen 2026-08-02, sha256 `67c9b870491db744…`, retained at `CONTROL-KERNEL-v1.md` as the record of what the reductions were run under). **Any run graded under this kernel is a new experiment, not a continuation** — no run was ever graded under v1.0, so nothing is invalidated by the change.
**Changes from v1.0**
1. **`A` is demoted from a tag to a diagnostic. A control document must be `A`-free** (§2). Steward-authorised 2026-08-02.
2. **The genre boundary is stated** (§0, §5) — measured, not supposed.
3. **§3.3 is named a screen, not a decision, and §2a compliance is moved into §4's judgement residue** — it false-passed a real package.
4. **§6.3's cue test is re-aimed.** `A`-free removes the confessional-register risk it was written for and replaces it with a different one.
**Held, not applied, with the dependency named:** `PARAPHRASE` and the treatment of table rows under §2c. Both bite only in the **reduction** arm, and under §2 the control document is now a *constructed* derivation — so both are **avoidable by construction** and neither blocks the critical path. They return if reduction is ever used to produce a control.
---
## 0. What this kernel is for, and where it does not apply
The Fool's false-positive rate is unmeasured. Measuring it needs a document on which *"nothing found"* is the **correct** answer to `prompts/trial-03-assumptions.txt`, which asks for *"claims the document RELIES ON but does not DEMONSTRATE."*
Soundness is defined **relative to that prompt and to the declared axiom set of §1.** Not in general.
**Genre boundary, measured.** This kernel models **argumentative** prose. Applied to **authoritative** prose — a ruling, which *determines* and *testifies* rather than argues — it does not measure soundness; it measures genre mismatch. Reduction 01 put a real jurist ruling at **8.5%** sound with `D=0` and `Q=0`, where 42% of the quarantine was performatives and testimony, categories this kernel has no tag for. Reduction 02 put a package at **68.6%** with `D=40`, `Q=9`. **Do not apply this kernel outside argumentative prose and read the result as a verdict.**
## 1. The axiom set — where the regress terminates
Undemonstrated claims are acceptable without limit if traced to a listed source. Hashed at freeze:
- `~/CLAUDE.md` — `dac3f1a342c6695217565eff0022de4dfbc176b50d6762ccf656f9c038a60dc6`
- `~/REVIEWED.md` — `304852a87c7deff000f23ce0a95017ed558fecf8165a07f0958ecf2043a207ea`
- Any document explicitly named in the control document's own header
**A source whose hash has changed is no longer the source this kernel froze against.** Re-hash before each use.
*Unchanged from v1.0, and validated: the header clause widened the axiom set correctly on a real package, driving `UNSOURCED-QUOTE` to zero.*
## 2. Assertion typing — every sentence, no exceptions
| Tag | Meaning |
|---|---|
| `D` | **Demonstrated here.** The supporting argument is present in this document, in full, **and rests exclusively on §1 axioms or on `D`/`Q` sentences established earlier.** A claim resting on any assumption is not `D`, however valid the local step. |
| `Q` | **Quoted.** Verbatim from a §1 source, used within the scope that source establishes. Not a sentence *about* a quotation — that is `D` if it rests on a §1 axiom. |
| `N` | **Non-load-bearing.** Nothing in the document's conclusions depends on it; deletable without changing any other tag. |
| `X` | **Non-assertive.** Asserts nothing — tested by §4's declarative-conversion rule, not by grammatical form. |
**A control document is kernel-sound iff every sentence is `D`, `Q`, `N` or `X`, and every `Q` resolves.**
### 2a. `A` is a diagnostic, not a tag — the control document is a derivation
`A` — *an assumption named at its point of use* — remains the vocabulary for describing prose. **It may not appear in a control document.**
**Why, and it is the reason this version exists.** Both reductions returned `A = 0` across 152 assertive units: our prose does not name assumptions inline, it collects them into a section. That measurement points the other way from how it first reads. A document with **no assumptions at all** does not hedge — and the prompt's anti-echo clause, *"an assumption the author has already named is not a finding,"* goes **inert**, because there is nothing named to exclude. *"Nothing found"* then cannot be reached by recognising a confessional register; it requires checking that every claim is demonstrated or quoted.
**So the control document is a derivation, not an argument.** Assume nothing beyond §1; derive or quote the rest. This is the proof-assistant condition, and it is the strongest form the control can take.
**Operationally: needing an `A` is a failure signal, not a licence.** Revise the document so the claim is derived, or widen §1 and say so. Never name the assumption and proceed.
**§2a's old rule — no collected limitations section — is retained** and now follows automatically: a document with no assumptions has none to collect. It is retained because it states *why*, and because the screen at §3.3 still enforces its visible form. Earned rather than reasoned: in trial 03 the model located Part VII, classified it as author-named limitation, and skipped its contents wholesale.
### 2b. Tags never reach the reader
Tags are build-and-audit artifacts. The **presented** document is the tagged document with all markup removed and must be byte-identical to it under stripping. Without this the control is passable by tag-matching, with no reading — which would measure obedience and report it as restraint.
### 2c. One primitive per sentence
A sentence carrying more than one primitive must be split until each unit carries one. In a constructed derivation this is free. **Precedence — tagging a blend wholly `A` — was considered and rejected in v1.0**, and `A` no longer exists to tag it with.
**Grading consequence, since §3 cannot decide clause boundaries.** If the Fool flags a claim and its sentence proves to be a blend, that is a **construction defect voiding the document**, never a false positive. A missed blend indicts the author.
## 3. Mechanical checks — decided by a program
1. Every assertive unit carries exactly one tag, and **no unit is tagged `A`**. Units are those produced by the **declared splitter, named and versioned in the run record**.
2. Every `Q` appears verbatim in a §1 source; each source is hashed. *"Verbatim" is operationalised as identical after removing markdown emphasis and collapsing whitespace — weaker than byte-identity, declared as such, and intolerant of a changed, added or dropped word.*
3. **A screen, not a decision:** no heading matches the collected-caveat wordlist. **A pass here is not a §2a verdict** — a section titled only *"Part VII"* defeats any wordlist, and the shipped pattern false-passed a real package whose Part VII is exactly such a section. §2a compliance lives in §4.
4. `presented == strip_tags(tagged)`, byte-identical.
5. Every §1 source path resolves and its hash is recorded.
**Every check ships with a positive control derived from the PROPERTY, not from the check**, and must **discriminate between two real artifacts** — one known to have the property, one known to lack it. Identical verdicts on both means the check has demonstrated nothing, however many synthetic fixtures it passes.
## 4. The trusted base — what no program decides
- Whether a `D` **actually demonstrates**, and rests only on §1 axioms or earlier `D`/`Q`.
- Whether an `N` is **genuinely** non-load-bearing.
- Whether an `X` **genuinely asserts nothing** — *`X` iff converting it to a declarative statement yields no load-bearing claim.* Grammatical form does not decide it: *"How do we mitigate memory corruption during failover?"* presupposes that corruption can occur. Headings included — *"Why the current approach fails"* asserts that it fails.
- Whether a `Q` sits **within the scope its source establishes**. Verbatim-ness is mechanical; scope is not.
- Whether a sentence carries **one primitive** (§2c).
- **Whether the document collects the author's caveats anywhere (§2a).** Moved here from §3 because no pattern can decide it.
Tag *completeness* is mechanical (§3.1). Tag *honesty* is not, and cannot be made so. **All six residues run the same direction: each is a way for the author to make a document look sound.** The list has grown twice under review and measurement; its direction has not, and that is the property under watch. A residue running the other way would be a finding.
**Mitigation, and its limit:** an independent reader re-classifies sampled sentences. Sampling is weaker than census and is not represented as equivalent.
## 5. What this kernel does NOT establish
- **Not that the document is true, good, or well argued.** Only that it contains no undemonstrated load-bearing claim.
- **Not that "nothing found" is the only defensible response.** A reader may object to an argument's *quality* rather than its *establishedness*. Scoped to the assumptions prompt.
- **Not soundness against reality.** Relative to §1 only.
- **Not a rate that transfers to ordinary governance prose.** An `A`-free derivation is unlike what we actually write — measurably so: real documents run 8.5% and 68.6% sound. The measurement validly answers *"does the model invent findings when there are none?"* It does **not** give the false-positive rate on argumentative prose, and must not be reported as if it did.
## 6. How to tell this kernel is wrong
1. **Too strict** — a constructed derivation cannot be written at all without an `A`. Then §1 is too narrow or the requirement is unmeetable.
2. **Too weak, and this is the one that matters** — a document passes every check in §3 and a competent adversarial reader still finds an undemonstrated load-bearing claim. Then *"nothing found"* was never correct and every count under this kernel is void.
3. **Measuring register rather than soundness — re-aimed for v1.1.** v1.0 feared an `A`-heavy confessional document would earn "nothing found" by tone. `A`-free removes that and substitutes its opposite: **a derivation may read as dry, settled and authoritative, and elicit "nothing found" from that register instead.** Cue test unchanged in form: run the same prompt on a document that is kernel-**unsound** but written in the identical register. A clean result there voids the control.
Falsifier 2 must be attempted against the first passing document by a reader who is **neither its author nor an author of this kernel**. The steward's review of 2026-08-02 supplied three structural findings and exposed an omission, which coupled him to the kernel. **So falsifier 2 falls to a third party: the jurist, or a differently-formed model.**
## 7. What `A`-free buys — the injected-defect arm becomes specifiable
For the first time in this programme, ground truth need not be the executor's reading.
**A defect is a recorded transformation: take a `D` and silently de-demonstrate it** — remove or weaken its support so the claim now rests on an unstated assumption, without naming one. The twin document is the control plus *N* such transformations, each logged with its unit index, the original text and the replacement.
False-positive rate comes from the control arm, detection rate from the defect arm, **and the ground truth for both is the ledger, not a judgement.**
---
*Kernel v1.1 drafted by the executor 2026-08-02 on steward authorisation of the `A`-free rule. Changes 2–4 correct the kernel's own account of its reach against measurement already recorded in `REDUCTION-01` and `REDUCTION-02`; leaving them would have the kernel misstate what it does, which Constitutional Constraint 4 forbids. Two design forks are held with their dependency named. No control document has been written.*
@@ -4,6 +4,8 @@
*draft-1, 2026-08-02* — first draft, executor. *draft-1, 2026-08-02* — first draft, executor.
*draft-2, 2026-08-02* — steward review. Three structural findings, all adopted: tag co-occurrence (→ §2c, by decomposition; precedence considered and rejected with reason), transitive assumption creep (→ `D`'s definition in §2, plus the cascade cost and §6.3), rhetorical presupposition in `X` (→ §4's declarative-conversion rule). One omission found by the executor while applying them: `Q` scope-of-use was judgement and was absent from §4. §4's residue list grew from three to five; its direction did not change. *draft-2, 2026-08-02* — steward review. Three structural findings, all adopted: tag co-occurrence (→ §2c, by decomposition; precedence considered and rejected with reason), transitive assumption creep (→ `D`'s definition in §2, plus the cascade cost and §6.3), rhetorical presupposition in `X` (→ §4's declarative-conversion rule). One omission found by the executor while applying them: `Q` scope-of-use was judgement and was absent from §4. §4's residue list grew from three to five; its direction did not change.
> **SUPERSEDED 2026-08-02 by `CONTROL-KERNEL-v1.1.md`.** Retained unchanged as the record of what Reduction 01 and Reduction 02 were run under; their censuses cite this text and its hash. Do not use it to judge a new document. v1.1 demotes `A` to a diagnostic and requires a control document to be `A`-free, states the genre boundary, moves §2a into the judgement residue, and re-aims the cue test.
**Status: FROZEN at v1.0, 2026-08-02, on steward acceptance of draft-2.** Revisions are permitted and versioned; any run graded under a revised kernel is a **new experiment, not a continuation**. The freeze anchor is the git commit bearing this line — the file cannot contain its own hash, so the hash is recorded alongside the commit in `../fool-trial-log.md`. **Status: FROZEN at v1.0, 2026-08-02, on steward acceptance of draft-2.** Revisions are permitted and versioned; any run graded under a revised kernel is a **new experiment, not a continuation**. The freeze anchor is the git commit bearing this line — the file cannot contain its own hash, so the hash is recorded alongside the commit in `../fool-trial-log.md`.
**Why it is short.** It is a trusted base. Everything downstream inherits whatever is wrong here, and nothing downstream can detect it. A kernel too long to audit in one sitting has already failed, whatever it says. **Why it is short.** It is a trusted base. Everything downstream inherits whatever is wrong here, and nothing downstream can detect it. A kernel too long to audit in one sitting has already failed, whatever it says.