From 48473b94b9ad695e7c1783cd7ac5ad707646da4f Mon Sep 17 00:00:00 2001 From: David F Glidden Date: Mon, 31 Aug 2026 11:30:59 +0200 Subject: [PATCH] Jurist ruling on PENDING-172 + PENDING-173, filed verbatim before any act MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Second adoption of PENDING-108 (c)'s ordering. NOT PLACED — these are jurist drafts; REVIEWED.md is the steward's hand. Relay provenance recorded: the text reached the executor as a relayed message, not from a file it read (REVIEWED-129 / PENDING-159). Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_01Wn9mxsFjHJkzYjuDdrtxwp --- ...ENDING-172-173-JURIST-RULING-2026-08-31.md | 177 ++++++++++++++++++ 1 file changed, 177 insertions(+) create mode 100644 claude/governance/PENDING-172-173-JURIST-RULING-2026-08-31.md diff --git a/claude/governance/PENDING-172-173-JURIST-RULING-2026-08-31.md b/claude/governance/PENDING-172-173-JURIST-RULING-2026-08-31.md new file mode 100644 index 0000000..a4f893f --- /dev/null +++ b/claude/governance/PENDING-172-173-JURIST-RULING-2026-08-31.md @@ -0,0 +1,177 @@ +# PENDING-172 + PENDING-173 — JURIST RULING, 2026-08-31 + +**Received:** 2026-08-31, via steward relay into the executor's session. +**Filed:** verbatim, **before any act taken under it** — PENDING-108 (c)'s ordering, second adoption +(first was `record-keeping-cluster-JURIST-RULING-2026-08-27.md`). +**Status:** ⚠ **NOT PLACED.** These are jurist drafts. `~/REVIEWED.md` is the steward's hand; a +jurist sign-off does not authorize an executor write to it. Nothing below is in force until the +steward places it. +**⚠ Relay provenance:** this text reached the executor as a relayed message, not from a file the +executor read. Per REVIEWED-129 / PENDING-159, relaying strips provenance; what is preserved here +is the text as relayed, and that limit is part of the record. + +--- + +## Jurist's reading, as relayed — verbatim + +Read verbatim via `governance_item` for PENDING-172, its AMENDMENT 1, PENDING-173, REVIEWED-122, PENDING-110, PENDING-145 and PENDING-146; open list and repo status via `governance_state()` (57 open items, computed 11:19). I did not use the §Standing Context block in my preferences — it is dated 2026-07-28 and reports 15 open items, so it is 34 days stale and contradicted. + +## First, a near-miss in my own instrument + +`governance_item(id='PENDING-172')` returned the parent block only. It gave no indication that a second block existed under that id. I found AMENDMENT 1 in `governance_state()`'s enumeration and had to retrieve it by its full header string via `governance_search` — the id alone does not reach it. + +Had I ruled from `governance_item` alone, I would have ruled on the parent's Recommendation — which AMENDMENT 1 corrects as **wrong**. The parent argues that only (d) is enforceable without depending on the party being checked; AMENDMENT 1 supplies `respawnFlags`, an external check that reads the harness rather than the session, and offers option (e). + +That is PENDING-173's exact class — a control whose unit is the id while the decidable unit is the block — occurring in the jurist's reading tool, on the day, on the item being ruled. It is the fourth instrument known to guess differently at the same undefined convention: `wake-digest.py`'s `ruled_pendings` (PENDING-145), `governance-drift-check.py`'s `register_findings` (PENDING-173), the open-list unit (PENDING-146), and now `governance_item`. This is a first-hand observation, not testimony, and it belongs in the record. + +## PENDING-172 — AUTHORIZED in part; one leg is the steward's, one leg severed + +The finding is accepted. The item is right that Constraint 5 was not wrong but unenforced, and right not to propose amending it. + +**On the options.** (b) and (c) and (e) are not competitors; they read three different substrates. (e) reads harness state before respawn, (c) reads the session's own transcript shape at the turn, (b) annotates the artifact. (e) is the strongest and is the first mechanism here that answers 'is the loop currently removable?' *before* the removal. (c) is weaker but not empty — a transcript with no human record is in-session evidence — and two checkers on different substrates is Constraint 6's own logic. (b) cannot enforce anything and must never be reported as a control. + +**(d) is not mine to rule.** It is a standing steward policy about whether background workers exist at all. What I will say is where the burden now sits: the item establishes that both binaries carry the mechanism and that `cause=upgrade` supplied only the restart, so **every auto-update will do this given a parked idle worker**. The precondition is the parked worker. Keeping background sessions is now the choice that requires justification, not removing them. + +**Two things the item does not ask for and should.** + +The one-executor-per-day finding is an embedded `[HARDENING]` ask inside an `[ESCALATE]` item — the same shape PENDING-146 names in PENDING-131 ADDENDUM 2 ('one row, one tag, understating the authorization class of what is inside it'). Sever it. Its cost is live today: two sessions existed this morning and whichever wraps second becomes the record of the day. + +And provenance. PENDING-171 and commit `5ba5842` were produced with no human in the loop, and PENDING-173 already cites PENDING-171 as precedent. I rule **provenance-mark, not void**: the findings are checkable on their own merits, and voiding would discard real substrate work for a defect the executor could not have detected. But PENDING-171 must not be ruled until it carries the marker — this is PENDING-110's own complaint that the register does not say on its face what it is. + +## PENDING-173 — AUTHORIZED (a), with the maxim withheld + +The mechanism is right. Three undeclared narrowings, 3 of 16 covered, and a latent false-negative in the safe-looking direction. Authorize the widening. + +Two corrections. + +**The citation is strengthened by relay.** PENDING-173 says REVIEWED-122 condition 5 'declined exactly that on principle'. Condition 5 declined it *as an executor act in that ruling* and left the door open: 'Should the steward decide the headers are worth normalizing, each amendment carries a dated note stating what was changed and why, per no-silent-revision — but that is a separate steward act and is not authorized here.' The principle is there; its scope is narrower than the relay reports. I will not ratify 'never rewrite the record to fit the instrument' as doctrine on that basis. + +**The option set has a hole, and closing it collides with an open item.** PENDING-173's (b) is *retroactive header rewriting*, correctly rejected. But a *prospective* convention — define what AMENDMENT and ADDENDUM each mean for blocks filed from here on, touching no placed record — is neither its (a) nor its (b). That is precisely PENDING-146's recommendation on the adjacent axis: option (iii), convention leading, detection as tripwire, 'makes the census correct rather than making the census smarter'. + +PENDING-173 does not cite PENDING-146. Ruling 173's maxim as written would decide 146 by side-effect, in the direction 146 argues against. So: authorize the parser widening, which is owed regardless; route the convention question to 146; do not let the instrument fix pre-empt it. + +--- + +## Draft REVIEWED block for PENDING-172 — jurist-authored, NOT PLACED + +```markdown +## REVIEWED-131 (PENDING-172) — A version upgrade resumed an unattended executor, and the wake digest became its work order +**Date:** 2026-08-31 +**Decision:** AUTHORIZED in part — (e) and (c) as a two-substrate control, (b) as annotation only; (d) recorded as a steward policy decision, not ruled here. One leg severed. +**Rules on:** PENDING-172 (parent) and PENDING-172 AMENDMENT 1, both blocks, named explicitly per PENDING-145 and PENDING-146. + +**Notes:** The finding is accepted. Constraint 5 was not wrong but unenforced, and the item is correct not to propose amending it. AMENDMENT 1's correction of its own parent is better than the claim it replaces and is the reason this ruling can be more than a policy note. + +1. CONDITION — **(e) is authorized as the primary control and must fail to NOT ESTABLISHED, never to safety.** A missing, unreadable or empty `~/.claude/jobs/` reports NOT ESTABLISHED, not 'no parked workers'. The item states this weakness itself; it is raised from disclosure to requirement. The check enumerates every job dir read and every one it could not read, per REVIEWED-122 condition 4 — a control over parked workers whose negative result is an opaque zero is the failure this item is about. + +2. CONDITION — **(c) is authorized as a second control on a different substrate, and is never reported as the primary one.** (e) reads harness state; (c) reads the session's own transcript for a preceding human record. Two differently-positioned readers is Constraint 6's logic and the reason to build both. Output must name which control fired. + +3. CONDITION — **(b) is authorized as annotation and is explicitly not a control.** Marking the digest as orientation, and `OPEN QUESTION` as inherited-from-a-human and answerable to a human, is cheap and honest. It cannot enforce and must not appear in any report as a mitigation. The item's own warning on this point is adopted verbatim. + +4. **(d) is the steward's standing decision and is not ruled.** Recorded because it survives whatever is built: both binaries contain the mechanism, `cause=upgrade` supplied the restart and not the capability, and the sole precondition is a parked idle worker. The burden has moved — keeping background sessions is now the choice requiring justification. (e) is the tripwire that reports whether the policy is holding; it is not a substitute for the policy. + +5. **SEVERED — the memory protocol assumes one executor per day.** Date-keyed `session-ledger-YYYY-MM-DD.md`, one session file, one Active Session block with demote-on-promote: two concurrent sessions do not merge and the second silently becomes the record of the day. This is a live `[HARDENING]` ask embedded in an `[ESCALATE]` item — the shape PENDING-146 names in PENDING-131 ADDENDUM 2. It is filed as its own item and is not disposed of here. Its cost was incurred today, not hypothetically. + +6. **PROVENANCE, not voiding.** PENDING-171 and commit `5ba5842` were produced with no human turn in the session. They are not void: their findings are checkable against the substrate independently of who filed them, and PENDING-173 has already relied on one. Both carry a dated provenance marker naming the session and the absent loop, per no-silent-revision. **PENDING-171 is not to be ruled until it carries that marker** — an unmarked record does not say on its face what it is, which is PENDING-110's complaint at a new site. + +7. **A recorded limit, not a fault.** Deleting `~/.claude/jobs/84ce2880/` was the steward's instruction and its load-bearing values were quoted first. It nonetheless narrows the parent's own 'Not established' question — how a session comes to be `kind: background`. The remaining evidence is `acaabadf`, deliberately kept. Do not delete it. + +8. **Scope of this ruling.** I read both blocks verbatim via `governance_item` and `governance_search`. `daemon.log`, the transcript record numbers, `respawnFlags` values and the cross-binary string counts are executor testimony from files I cannot open. The item's own limit on the last of these — identical string counts do not establish identical respawn policy — is preserved rather than resolved. + +**If AUTHORIZED:** Build (e) first, with its NOT ESTABLISHED path and enumeration. Then (c). Apply (b) on the same pass, marked as annotation in the code and in the output. File the severed item at §5 before wrapping. Place the provenance markers at §6 before PENDING-171 is brought forward. +``` + +## Draft REVIEWED block for PENDING-173 — jurist-authored, NOT PLACED + +```markdown +## REVIEWED-132 (PENDING-173) — The register-integrity control covers one word of a two-word convention, in one of two registers +**Date:** 2026-08-31 +**Decision:** AUTHORIZED — option (a), on five conditions. The proposed maxim is WITHHELD; the convention question is routed to PENDING-146 and not decided here. + +**Notes:** The three undeclared narrowings are real, the demonstration is the right kind (the count did not move when a matching header was appended), and the latent false-negative runs in the dangerous direction — an `ADDENDUM` counted as an original can satisfy 'an un-amended entry exists' on behalf of a record that was replaced. The item's declared correction of its own first census is what earns the rest of it. + +1. CONDITION — **`originals` defaults to not-original on any unrecognized marker.** The predicate is an enumerated list of amendment-marker forms, and a header carrying an unrecognized marker is excluded from `originals` rather than admitted to it. This mirrors REVIEWED-122 condition 2: an unlisted verb never yields the permissive answer. The current `not startswith('AMENDMENT')` fails in the permissive direction, which is why one word's absence became a latent pass. + +2. CONDITION — **controls are drawn from the census, not from the author's memory of the convention.** The fixture set must contain, at minimum, `ADDENDUM` headers, in-body `**AMENDMENT`/`**ADDENDUM` forms, and `PENDING`-side instances. For any form present in the record and not covered by a control, the check reports NOT ESTABLISHED rather than passing. This is the third instance this month of a positive control satisfied by the narrowing it should have caught, and the item names the other two itself. + +3. CONDITION — **the acceptance check enumerates, it does not count.** '3 → 16' is not the check. The thirteen newly visible blocks are listed by register and header, and compared against the item's table. If the two disagree, the disagreement is the finding and is reported, never reconciled by amending the table. + +4. CONDITION — **placed records are not rewritten.** Affirmed, and consistent with REVIEWED-122 condition 5. Widening the reader is authorized; normalizing headers already placed is not, here or by implication. + +5. CONDITION — **the convention question is routed to PENDING-146, which is open and argues the opposite ordering.** PENDING-146 recommends convention-first with detection as tripwire, on the adjacent axis of the same undefined convention. PENDING-173 does not cite it. A *prospective* definition — what AMENDMENT means as against ADDENDUM, for blocks filed from here on, touching no placed record — is neither this item's (a) nor its (b), and it is the option its own root-cause diagnosis points at. This ruling authorizes the parser widening, which is owed under either ordering, and leaves the convention to 146. + +6. **THE MAXIM IS WITHHELD.** 'Widen the instrument to the record; never rewrite the record to fit the instrument' is stated more absolutely than its cited authority supports. REVIEWED-122 condition 5 declined normalization *as an executor act in that ruling* and expressly reserved it as a separate steward act carrying a dated note. Strengthened-by-relay, and the strengthening is load-bearing: adopted as written, the maxim would decide PENDING-146 by side-effect in the direction 146 argues against. The corrected form, offered and not ratified: *the instrument is widened to the record; a placed record is normalized only by a dated steward act stating what changed and why.* Doctrine addition is `[ESCALATE]` and belongs with 146. + +7. **A fourth instrument, observed first-hand this session.** `governance_item(id='PENDING-172')` returns the parent block only, with no indication that a sibling exists; AMENDMENT 1 is reachable only by its full header string. The jurist's own reading tool has the defect this item reports, and it nearly produced a ruling on a Recommendation that AMENDMENT 1 corrects as wrong. Recorded here because it belongs to this item's class and is not testimony — it happened to the instrument in the act of ruling. Whether the MCP server's id resolution is fixed is a separate item. + +8. **Scope of this ruling.** The line numbers, the census table, the fixture contents and the append-and-recount demonstration are executor testimony from a script I cannot run. What I verified directly: REVIEWED-122 condition 5 verbatim, PENDING-110 option (c) verbatim, PENDING-145 and PENDING-146 verbatim, and the behaviour of `governance_item` at §7. + +**If AUTHORIZED:** Implement (a) per conditions 1–4. Report the enumeration in full, agreements included. Do not touch placed headers. Cross-reference PENDING-146 in the commit and in the item's kin list. +``` + +--- + +## Numbering flag, as relayed + +One flag before you place these. `REVIEWED-131` collides with `PENDING-131` — the fence item, the most-cited open record in the corpus, and the exact hazard PENDING-110 names. Both headers above name their PENDING explicitly per PENDING-110(b), which is agreed in conversation but still unruled; PENDING-110(c) and (d) remain open. You may prefer to skip 131 outright rather than rely on the parenthetical. + +--- + +## Jurist advice on (d) — offered, explicitly NOT a ruling, as relayed + +Advice, jurist-offered and not a ruling — but I'd put it more strongly than I did an hour ago. + +**(d) as written is addressed to a party who may not be able to comply.** It reads as a policy about the steward's habits: stop starting background workers. But the item's own 'Not established' section says nothing aliases `claude --bg` in your shell config and nothing in `settings.json` requests it. If workers acquire `kind: background` through the daemon's adopt/respawn path rather than through anything you type, then 'do not run background workers' is not a policy you can execute. It is a wish, and adopting it would produce exactly the false safety the item warns about in (b) and (c). + +So the parent's claim that (d) is 'the only one whose enforcement does not depend on the party being checked' needs the same correction AMENDMENT 1 already applied once to that sentence. (b) and (c) fail because the checker is inside the session. (d) may fail for a different reason: the party who creates the condition is unidentified. Its advantage is asserted, not established. + +**The hazardous property is narrower than the category.** `84ce2880` was a background worker for three months and would not have taken a turn — `respawnFlags=[]`. `acaabadf` had `--reply-on-resume` and did. The thing that converts a respawn into an unattended turn is the flag, not the backgrounding. That gives you an option the item does not list: + +> **(d′) — no parked worker carries `--reply-on-resume`.** Background sessions may exist; none may be configured to take a turn on respawn. + +(d′) gives up much less than (d), removes the same mechanism, and is measured by precisely the `respawnFlags` read that (e) already performs. One instrument serves the policy and the tripwire. + +**But (d′) is contingent on the same missing fact,** which is why I'd sequence rather than decide: + +1. **Establish who sets the flag.** Start a foreground session, `/exit`, then read `~/.claude/jobs/*/state.json` for a new entry and its `respawnFlags`. That is a positive control on the creation path — it shows the instrument can detect presence — and it decides which readings of (d) are addressed to a party who can comply. Cheap, and it is the gate on everything below. +2. **If the daemon sets it:** (d) and (d′) both collapse to disabling the capability at the configuration level, and I do not know whether that is available — I have not read the binary or its settings surface, and I would not assume it from the log lines. Establish that before choosing. +3. **If the launch sets it:** (d′) is a real policy and I would take it over (d). (d) bans a category whose uses nobody has enumerated; `acaabadf`'s `mcp__computer-use__` tools suggest at least one live use, and a policy that quietly costs a working practice gets reversed without a record. + +**The version of (d) I would not adopt** is the wrap-discipline one — 'check for parked workers before you leave'. PENDING-168 is open in your own register and says the thing: a condition that can only be honoured by remembering will be broken, and the interval is hours. That is not a policy, it is a fifth place to forget. + +**Interim, costing nothing and not a control:** treat `Bye!` as false, stop workers rather than detaching from them, and run (e) once today. At time of filing, `acaabadf` was parked idle again with the flag set — if it still is, the condition is live now, not historical. + +Recordable form, if you want it in the ruling rather than in conversation: + +```markdown +4. **(d) is the steward's standing decision and is not ruled. Jurist advice, recorded not decided:** + (d)'s stated advantage — enforcement independent of the party being checked — is not + established, because the party that sets `kind: background` and `--reply-on-resume` is the + item's own open question. Prefer **(d′): no parked worker carries `--reply-on-resume`** — + it removes the mechanism that converts a respawn into a turn, costs the category nothing, + and is measured by the same `respawnFlags` read as (e). Both are gated on one cheap + determination: exit a foreground session and read `~/.claude/jobs/*/state.json` for a new + entry. A wrap-discipline reading of (d) is declined outright per PENDING-168. +``` + +--- + +## Executor's note on receipt — written after filing the text above, and kept separate from it + +Nothing has been acted on under this ruling. What it obliges, and where each sits: + +- **§5 SEVERED** — file the one-executor-per-day finding as its own item. Executor-fileable + (`[HARDENING]`) regardless of placement. +- **§6 PROVENANCE** — dated markers on PENDING-171 and commit `5ba5842`. ⚠ The commit message + cannot be marked without rewriting history, which is PENDING-164's own subject; the marker must + therefore live in the register, naming the commit. +- **§7 (172)** — `~/.claude/jobs/acaabadf/` is not to be deleted. Noted; it is kept. +- **REVIEWED-132 §7** — `governance_item`'s id-vs-block defect is a separate item, owed. +- **Building (e), (c), (b)** — blocked twice over: the ruling is not placed, and the FIX-lane + check-in is COME DUE, which suspends the lane. +- **The maxim** is withheld and must not be used as doctrine. PENDING-173 is to cross-reference + PENDING-146 on implementation. + +⚠ **The jurist's interim check, run on receipt:** `acaabadf` was stopped at 07:35:50Z on the +steward's instruction, before this ruling arrived. State at time of filing is recorded in the +executor's report accompanying this document, not asserted here.