diff --git a/PENDING.md b/PENDING.md index 3d90186..1c809e0 100644 --- a/PENDING.md +++ b/PENDING.md @@ -1650,4 +1650,7 @@ Disposition (verbatim capture + executor action-list: `chamber-library/docs/libr **Recommendation:** (a), design brief FOR-JURIST before code (gate-acceptance territory). **Files affected (on authorization):** `scripts/verify_body_conservation.py` or `scripts/graduate_to_canonical.py` (the gate's REVIEW consumption), `_curation/graduation-spec.yaml` (the attestation shape as declared data), `scripts/test_tools.py`. **Evidence:** `_curation/tool-evolution-log.md` 2026-07-21 (the landing record; the two wired-door runs both REVIEW-held on exactly the 8 declared-trim boundary runs); the door's own dry-run output preserved in the session record. -**Awaiting:** Steward reading; jurist design gate on the attestation shape. +**Package DRAFTED 2026-07-22** — `chamber-library/docs/PENDING-69-boundary-drop-attestation-JURIST-PACKAGE-2026-07-22.md` (via `/jurist-package`; hook-passed, GROUNDED-IN §Tiering&Fence one-door + §V Tier-3 + §VII + §II + REVIEWED-57 + the gate's ratified verdict logic, all quoted verbatim). Substrate-first finding (the literal question, answered from `verify_body_conservation.py`): the gate classifies boundary runs by POSITION+SIZE only, takes no drop-declaration argument, and provably cannot tell a spec-class drop (index) from a keep (endnotes) or a relocation-residue drop (the NOTES husk) — it emits REVIEW and stops. So the honest mechanized part = coverage (every derived run attested) + interior-zero (teeth unchanged) + attribution; the drop-vs-keep judgment stays human, turned into checkable data. Seven gate questions posed (Q1 landing · Q2 the split-vs-vocabulary fork = the literal question · Q3 the honest gate/human division · Q4 bind-to-derived-runs · Q5 relocation two-sidedness/`moved_to` · Q6 omnibus interaction · Q7 Eichmann-as-first-fixture ratification condition). Executor lean throughout: attest-never-default resolution, minimal constitutional sentence + declared-data mechanism, forward-only (no re-verify storm; 0 files hold `verified`). +**DESIGN-GATE PASSED 2026-07-22** (`chamber-library/docs/PENDING-69-boundary-drop-attestation-JURIST-RULING-2026-07-22.md`, filed verbatim; dispositions in the package Addendum). Spine confirmed (positive attributed attestation only; interior teeth untouched; never a bypass). **Q2 RULED (b) vocabulary-only AGAINST the executor lean** — `trim.drop` is a controlled label set, not pre-verified drops; every run is per-file attested (the gate can never confirm class membership; a privileged spec-class = trust-by-name, the `app[]`/ABSTAIN collision shape). One layer, not two; `relocation` is another label distinguished only by `moved_to`. **Q3** floor confirmed + structural-falsification check ADOPTED (executor decision, recorded, steward-overridable) for `index`/`table-of-contents` only (signature mismatch HOLDS for reconciliation, never silent pass / never un-overridable block); declined where no clean signature. **Q4** bind-to-derived-runs ELEVATED to a required property. **Q5** `moved_to` required (incomplete = rejected attestation; fabrication-exclusion scoped to exactly the named span). **Q6** per-candidate; omnibus interior-run interaction named for the Levi pilot. **Q7** Eichmann first fixture + deliberate negatives (un-attested run→HOLD; interior deletion→FLAG). **Named tension:** wires human-in-the-loop for discipline, not removal — the 47-file wave is NOT unattended batch. **REVIEWED-69 draft in the package Addendum; awaiting steward placement.** +**MECHANISM BUILT test-first 2026-07-22** (branch `reviewed-69-boundary-drop-resolution` @ `21e3499`, NOT on main — steward merges on confirmation, per the session commitment "nothing lands on main without your confirmation"). `verify_body_conservation.resolve_review` (pure; additive `boundary_run_sig`, ratified verdict logic UNCHANGED + seed-test re-confirmed) + `graduate_to_canonical._resolve_boundary_review` (thin consumer; no attestation → REVIEW HOLDS) + `graduation-spec.yaml` `boundary_drops:` (declared-data vocabulary/policy, GROUNDED-IN the ruling). Corrected shape built: Q2 vocabulary-only, Q3 signature-falsification (index/ToC), Q4 bind-to-derived-runs, Q5 moved_to presence. Fleet 214→216. **Q7 CAPSTONE PASSED on the REAL Eichmann** — verdict=REVIEW, interior_loss=0, boundary_runs=8 (3 leading front-matter + 5 trailing index fragments) reproduces the hand-verified 1:1 reconciliation as a mechanical PASS; both negatives refuse (un-attested→HOLD; interior deletion→FLAG). Substrate lesson captured (tool-log): the k-gram aligner is move-blind → boundary runs are DROPS, `relocation` is the rare reordered case (my package's husk-as-relocation-run framing was imprecise; the 8 runs are front-matter+index, no relocation among them). Added-side fabrication-exclusion (Q5 second clause) = scoped follow-on, conservative absence (FLAGs, never silent-pass). +**Awaiting:** steward — (1) place REVIEWED-69 (draft in the package Addendum); (2) merge the branch to main + push both remotes (or authorize me to); (3) vehicle call on the ONE constitutional §Tiering&Fence sentence (fold into next supersession vs standalone MINOR bump) — drafted, held. Then: the Levi curation-bearing second pilot before scale (`promotion.scale_application`, unchanged) → the 47-file wave (human-in-the-loop, Zibaldone next). diff --git a/claude/memory/MEMORY-reference.md b/claude/memory/MEMORY-reference.md index 7984379..ff71624 100644 --- a/claude/memory/MEMORY-reference.md +++ b/claude/memory/MEMORY-reference.md @@ -5,7 +5,7 @@ metadata: node_type: memory type: reference originSessionId: d1e67361-d1b9-4dac-a0c4-e7a0e26211c4 - modified: 2026-07-20T19:10:10.463Z + modified: 2026-07-22T12:37:10.191Z --- # MEMORY — Reference layer (consult on demand) @@ -29,6 +29,9 @@ Split out of [MEMORY.md](MEMORY.md) on 2026-07-06 to keep the wake-loaded index # Archived sessions + stable reference layer (relocated verbatim from MEMORY.md, 2026-07-06) +## Archived (2026-07-20/21 — verify-guard arc complete · Eichmann graduated through the one-door; demoted on promote at the 2026-07-22 wrap) +- [Session 2026-07-20/21 — verify-guard arc COMPLETE · EICHMANN GRADUATED through the one-door](session-2026-07-21-verify-guard-chain-fold-eichmann-graduated.md) — The F2 fix ran test-first to proof at both ruled scales (markup-token class rule = the verify's own tokenizer eating a sup-star link's text; de-glue fold vs UNUSED credits → **chain-fold** after the Zibaldone census byte-accounted the whole residual; **in-table refusal** caught a REAL pandoc table-drop loss the guard alone saw — Zibaldone verbatim-clean at 3,795+2 refusals; fleet 202/202). Then the steward opened the door: **Eichmann GRADUATED via the born-digital lane** (`780106b`; sha `145e6edd…`, kindle_residue 0, 10 native footnotes ref↔def NON-EMPTY, engine re-anchored + caveat RETIRED, ingest_gate 13/13; class 48→47 — the telos concrete in one file). **Two lane defects were invisible to EVERY wired gate, caught only by seam probes**: per-spine `-f html` emits EMPTY defs (whole-EPUB `-f epub` is the lane; runbook corrected); pandoc puts defs AFTER the index (trim swallowed them once; non-empty-defs assertion = the new teeth). Instrument fixes test-first: strip_cruft escaped-bracket spans; verify_conversion zero-width span semantics. **PULLING THREAD was: PENDING-69 — the attested boundary-drop resolution mechanism** (delivered 2026-07-22: drafted→ruled Q2-vocabulary-only→BUILT test-first, Q7 capstone passed on the real Eichmann; on branch `21e3499`, awaiting steward merge). Read the session file at wake. + - [Session 2026-07-19 (night) — ONE-DOOR AUTHORIZED (REVIEWED-66); V1 BUILT; @2 GOVERNING; audit_cruft CLASS CLOSED](session-2026-07-19-night-one-door-authorized-v1-built-at2-governing.md) — **Both jurist arcs opened AND closed in one session.** (1) **PENDING-65 one-door**: package (hook-grounded, fresh censuses) → design-gate PASSED with three corrections (my "same comparison, disposition flipped" WRONG — vacuous vs a fresh candidate → **two obligations**: source-fidelity = body-conservation vs cross-converter reference · witness = **curation-preservation**; **curation-to-carry SPLITS** fidelity-restoring/carry vs **source-departing/never-carried** — as drafted it would have LAUNDERED Tier-3; "lost nothing" narrows to prose content, structural comparison = named gap) → **REVIEWED-66 PLACED `:611`**; Q3 block STANDS per tier (door/stamp separable — the door proceeds; stamp names edition-identity+sha, artifact-readable); E1 exempts re-conversion NOT the criterion (the 11 Loeb are NOT verified); **omnibus unit = owed declared-data definition**; Q5 no minimal-sidecar; **Q7 Eichmann pilot = RATIFICATION CONDITION** (report: divergences · auto-vs-hand · resisted · source-departing · human-minutes/file). (2) **S1/V1 `verify-quote` BUILT** (engine `d0bd9d2`; 3-stage, altered-never-passes, refuses citable:false + sha-drift; Eichmann caveat = declared data) — its census ANSWERED the inherited question (every @1 fold class ZERO corpus-wide; apostrophe/quote/dash convention heterogeneous PER SOURCE) → PENDING-66 → **@2 RATIFIED same day + GOVERNING** (`8324789`): Group A + guillemets (the jurist's own extension; Q2 WS-enumeration DISCHARGED — 29 explicit code points incl. U+00A0), **dash REFUSED** (form-collision parenthetical↔compound — sharper than my framing); @1 frozen forever; **superset-only = standing requirement on future @N**; **Greek/Latin wave owes its own census → @3, never a quiet extension**; two matcher catches pinned by tests (stage-2 acceptance = the RELATION ITSELF, never a word-aligned approximation; fragment-before-final-punct = quotable sub-span). (3) **audit_cruft kindle_residue CLOSED** (chamber `f879ec7`; `\b` would have missed EVERY glued instance — census-before-pattern caught it; Eichmann 4,712 = 2,356 links × 2, reproducible; **48 canonical carry the class, 33 formerly invisible** → `_curation/kindle-residue-census-2026-07-19.tsv`; remedy = the door, never a cleaner). Three number-reconciliations by counting, not harmonizing (72=67+5 · 4,712=2×2,356 · 1,305=1,297+8). ⚠ Steward sitting owed: ~~REVIEWED-55~~ (resolved stale 2026-07-19 — placed `:489` since 07-12; PENDING-55 closed) + skill-harvest review (standing since 07-12; run 2026-07-19 late-night). **PULLING THREAD: S2b — the omnibus promotion-unit definition (declared data; read the PENDING-63 ruling + the Levi file's structure FIRST) → the Eichmann pilot through the door (M4 Docling · witness comparison under the SPLIT vocabulary · full gates · cross-repo re-anchor · the Q7 report) + fold the V-TEXT Q3 order-violation demonstration into the pilot.** **LITERAL Q: does the omnibus promotion unit follow the FILE (hash-locality: one candidate/one witness, works catalogued by sections) or the WORK (split at the door, compound-source-style)? PENDING-63 ruled the ARCHIVE side; the canonical side may have the opposite grain (engine binds path+sha per source; reading-indices bind per work; §II "the work is the work") — and if the answer differs by tier (Loeb DSL vs EPUB omnibus), say so rather than forcing one shape.** Read the session file at wake. diff --git a/claude/memory/MEMORY.md b/claude/memory/MEMORY.md index c440543..8834dc4 100644 --- a/claude/memory/MEMORY.md +++ b/claude/memory/MEMORY.md @@ -6,7 +6,7 @@ metadata: type: note permalink: claude-memory/memory originSessionId: 22915403-bc5d-4796-9c7d-196b7c30d2f9 - modified: 2026-07-20T19:19:54.153Z + modified: 2026-07-22T12:37:03.415Z permalink: claude-memory/memory --- @@ -28,7 +28,7 @@ permalink: claude-memory/memory - [Studium Engine = Sixtus-V craftsman collaboration](feedback-studium-engine-sixtus-v-collaboration.md) — work the ground freely (I build, surface only vision-forks); **constraint-candidates** = 3rd governed instrument (I name, steward applies). Studium-engine only; heavier loop for L1/L2. - [Trust prior pass frame](feedback-trust-prior-pass-frame.md) — When extending a prior verification, re-run it at the scope of the extension. Frame-inheritance from a deep-read is contamination shape: the prior pass tested what it tested; your extension claims things it did not test. Caught 2026-05-28 → four-pass audit. Verify-before-compose at draft time, not build time. - [MemPalace is an unaffiliated stopgap](mempalace-is-unaffiliated-stopgap.md) — MemPalace is third-party; steward/Seb build BMF/CapableMind (hoped to replace it). Don't conflate them (3rd steward correction 2026-06-05 — the conflation even reached a skill name and was retracted); MemPalace PRs await MemPalace's maintainers, NOT Seb. -- [Skill-harvest register](skill-harvest-register.md) — **canonical home for proposed skills** (governed analog of PENDING.md for tooling). **FULL REVIEW RULED 2026-07-19, all four strokes** (⚖ block at top is authoritative): §3 consolidation BUILT · ladder batch-append + register compaction = next housekeeping slot. **`/jurist-package` BUILT 2026-07-20 (proven 2×);** `/model-handoff` = next build · `/graduate-chamber-source` hold-condition now MET (one-door lane RULED, v2.3.0 operative). **Patch BUILT 2026-07-20 (steward-authorized): `/jurist-package` — "trace a ruled finding's inference, not just its words" (Load-bearing disciplines; 2× jurist-caught).** +- [Skill-harvest register](skill-harvest-register.md) — **canonical home for proposed skills** (governed analog of PENDING.md for tooling). **FULL REVIEW RULED 2026-07-19, all four strokes** (⚖ block at top is authoritative): §3 consolidation BUILT · ladder batch-append + register compaction = next housekeeping slot. **`/jurist-package` BUILT 2026-07-20 (proven 2×); `/model-handoff` BUILT 2026-07-22** (charter-before-premium-switch; grounded in the stage-1-planning-brief exemplar) · `/graduate-chamber-source` hold-condition now MET (one-door lane RULED, v2.3.0 operative). **Register compaction + ladder batch-append = next FRESH-session slot** (register exceeds read caps — tripwire fired 2026-07-22 wake). **Patch BUILT 2026-07-20 (steward-authorized): `/jurist-package` — "trace a ruled finding's inference, not just its words" (Load-bearing disciplines; 2× jurist-caught).** - [Copy-paste-clean governance drafts](feedback-governance-drafting-copy-paste-clean.md) — draft PENDING/REVIEWED placement blocks as plain fenced markdown; display formatting leaks into the placed record (REVIEWED-59 header, 07-16). - [Verification ladder](reference-verification-ladder.md) — the named instruments (byte-identical compile gate, delta classification, censused-routes, fresh-clone gate, measure-toolchain-before-spec…); reach for the gate the claim's shape demands instead of re-deriving. - [Plane coordination workflow](reference-plane-coordination-workflow.md) — CENTRAL to steward↔Seb (est. 2026-06-02): `app.plane.so/capablemind`, thin effort-tasks `[BM #N]` over canonical GH issues. ⚠ BBF = BetterBridge *product*, NOT the board. Plane MCP OAuth (`ToolSearch select:mcp__plane__*`); `create_work_item` needs `description_html`. Detail in file. @@ -56,7 +56,7 @@ permalink: claude-memory/memory - [Be (laundromat)](project-be-laundromat.md) — canonical Be tracker (est. 2026-06-08). Be = Skemantix startup (Seb+David) funding CapableMind's ladder; **bridge, not venture**. Decisions LOCKED (entity/pricing/infra in file); a11y gate MERGED. **Pre-revenue WTP gate = renovate Pat → charge her; discipline: no new spec until it clears → nothing for executor on be.** Repo @ `f43a0fd`. ## Active Session -- [Session 2026-07-20/21 — verify-guard arc COMPLETE · EICHMANN GRADUATED through the one-door](session-2026-07-21-verify-guard-chain-fold-eichmann-graduated.md) — The F2 fix ran test-first to proof at both ruled scales (markup-token class rule = the verify's own tokenizer eating a sup-star link's text; de-glue fold vs UNUSED credits → **chain-fold** after the Zibaldone census byte-accounted the whole residual; **in-table refusal** caught a REAL pandoc table-drop loss the guard alone saw — Zibaldone verbatim-clean at 3,795+2 refusals; fleet 202/202). Then the steward opened the door: **Eichmann GRADUATED via the born-digital lane** (`780106b`; sha `145e6edd…`, kindle_residue 0, 10 native footnotes ref↔def NON-EMPTY, engine re-anchored + caveat RETIRED, ingest_gate 13/13; class 48→47 — the telos concrete in one file). **Two lane defects were invisible to EVERY wired gate, caught only by seam probes**: per-spine `-f html` emits EMPTY defs (whole-EPUB `-f epub` is the lane; runbook corrected); pandoc puts defs AFTER the index (trim swallowed them once; non-empty-defs assertion = the new teeth). Instrument fixes test-first: strip_cruft escaped-bracket spans; verify_conversion zero-width span semantics. **PULLING THREAD: PENDING-69 (filed) — the attested boundary-drop resolution mechanism: every trimmed one-door V-TEXT graduation REVIEW-holds structurally (spec trims ARE boundary runs); the mechanism is what opens the door for the other 47 without a hand on the latch. LITERAL Q: can droppable-boundary classes be declared data the gate checks (trim.drop covers front-matter/ToC/index but the NOTES-husk drop is a RELOCATION consequence, not a spec class), or does each landing need a per-file attested declaration? Read verify_body_conservation's boundary-run derivation FIRST.** Read the session file at wake. +- [Session 2026-07-22 — PENDING-69 boundary-drop mechanism drafted→ruled→BUILT (Q7 capstone passed) · /model-handoff](session-2026-07-22-pending69-boundary-drop-mechanism-built-model-handoff.md) — The whole PENDING-69 arc in one remote session (steward in Salzburg, machine at home): package DRAFTED reading the gate's code FIRST (literal-q honored — the gate classifies boundary runs by POSITION+SIZE only, provably CANNOT confirm class identity → REVIEW stops, no channel for the human id) → **RULING PASSED with corrections, Q2 OVERTURNED my lean to (b) vocabulary-only** (a privileged "spec-class" = **trust-by-name**; `trim.drop` is a label vocabulary, every run per-file attested) → **mechanism BUILT test-first** on branch `reviewed-69-boundary-drop-resolution` @ `21e3499` (NOT main): `resolve_review` + additive `boundary_run_sig` (ratified verdict logic UNCHANGED, seed re-confirmed) + `boundary_drops` declared data + `_resolve_boundary_review` thin consumer; fleet 214→216; **Q7 CAPSTONE PASSED on the REAL Eichmann** (verdict=REVIEW, interior_loss=0, **8 boundary runs** = 3 front-matter + 5 index → mechanical PASS; both negatives refuse). Then **`/model-handoff` BUILT** (authorized ⚖ Stroke 3). Honored "nothing lands on main without your confirmation" — branched, did NOT push. Substrate lesson: the k-gram aligner is **MOVE-BLIND** → boundary runs are DROPS, `relocation` the rare reordered case (corrected my own package framing). Q5 added-side exclusion scoped OUT (conservative). **PULLING THREAD: the Levi curation-bearing SECOND PILOT — the last gate before the 47-file wave; BLOCKED on the steward's 3 actions (2026-07-23 pm): place REVIEWED-69 · merge `21e3499`→main+push · vehicle-call the ONE constitutional §Tiering&Fence sentence (drafted). LITERAL Q: when the Levi omnibus (14 works, hand-curated) runs the one-door lane, do its curation-bearing divergences classify tractably (fidelity-restoring vs source-departing — the JUDGMENT cases Eichmann exercised 0×), or does a real case resist? + is the mechanism's SILENCE on inter-work (interior) drops genuinely correct at multi-work scale, or does an inter-work drop hide a real loss? Read the Q6 ruling + `promotion.witness`/`witness_comparison` declared data FIRST.** Read the session file at wake. ## Historical reference → MEMORY-reference.md Older archived-session pointers and the stable reference layer (steward profile · project-state detail · L1/L2/Chamber inventories · legacy pending-work · reference-file list) live in [MEMORY-reference.md](MEMORY-reference.md) — consult on demand; not loaded at wake. Recent cross-session trajectory comes from the Active Session entry above + the recent `session-*.md` files (wake §2.b.1; the MemPalace `handoffs` glance was retired 2026-07-07 with the wind-down). diff --git a/claude/memory/knowledge-graph.jsonl b/claude/memory/knowledge-graph.jsonl index 57bd5df..333c4e6 100644 --- a/claude/memory/knowledge-graph.jsonl +++ b/claude/memory/knowledge-graph.jsonl @@ -419,3 +419,5 @@ {"subject": "claude-code", "predicate": "drift-pattern", "object": "wired-gates-green-seams-broken — the session's two REAL defects (per-spine -f html leaves ALL footnote defs EMPTY with bodies stranded as plain prose; pandoc places defs after the index so the spec trim swallowed them) were invisible to EVERY wired gate (verify_conversion, body-conservation, witness compare — no words lost, only structure detached) and found ONLY by seam probes: reading boundary lines for the engine sidecar, re-running a def-content assertion. Recurrence of the 07-19 session-scale lesson in new dress: probe the artifact's SEAMS (joins, def content, boundary lines), don't trust green. Antidote built: the lane driver's non-empty-defs + count==pairs teeth.", "valid_from": "2026-07-21", "valid_to": null, "confidence": 1.0, "source_file": "session-2026-07-21-verify-guard-chain-fold-eichmann-graduated.md", "extracted_at": "2026-07-21"} {"subject": "claude-code", "predicate": "drift-pattern", "object": "calibration (the Eichmann night): census-through-a-pattern self-caught twice (a [^a-z]{1,40} bridge regex could not match .calibre38 — letters in class names; two adjacency-regex hypotheses returned x0 and were DROPPED, sites localized by token-stream alignment instead); instrument-signature misuse (prose_delta takes TEXT not paths — fed paths it diffed the FILENAMES, the pre/strip ghost-loss, self-caught by chasing the tokens to source); tool-report-vs-write seam (strip_cruft --apply prints transform counts BEFORE the write decision — three distinct refusal causes each read as applied until cmp verified the write). The fold-widening ordering held: real-loss classes excluded BEFORE any fold widened, every fold built on a fully byte-accounted census.", "valid_from": "2026-07-21", "valid_to": null, "confidence": 1.0, "source_file": "session-2026-07-21-verify-guard-chain-fold-eichmann-graduated.md", "extracted_at": "2026-07-21"} {"subject": "chamber-library", "predicate": "one-door-first-landing", "object": "Eichmann graduated 2026-07-21 (chamber 780106b, engine edbaf60): sha 145e6edd, 1,070 lines, kindle_residue 0 (was 4,712), 10 native footnotes ref-def non-empty, engine substrate-caveat RETIRED, ingest_gate 13/13. Class 48→47. Door proven but NOT repeatable: PENDING-69 (REVIEW-hold resolution mechanism) gates the remaining 47.", "valid_from": "2026-07-21", "valid_to": null, "confidence": 1.0, "source_file": "session-2026-07-21-verify-guard-chain-fold-eichmann-graduated.md", "extracted_at": "2026-07-21"} +{"subject": "claude-code", "predicate": "drift-pattern", "object": "trust-by-name — a privileged label/class drawn from a shared vocabulary reads as more-verified than a per-item claim, when the gate never confirmed membership. Caught by the jurist on PENDING-69 Q2 (my 'declared spec-class' lean, overturned to vocabulary-only on the package's OWN Part-II evidence that the gate can't confirm class identity). The honest shape: a label constrains what you may CALL a thing, never certifies what it IS. Kin to the app[]/ABSTAIN shared-name collision family. Antidote: when the substrate proves a gate can't verify a category, don't let a shared vocabulary smuggle it back in as trusted.", "valid_from": "2026-07-22", "valid_to": null, "confidence": 1.0, "source_file": "session-2026-07-22-pending69-boundary-drop-mechanism-built-model-handoff.md", "extracted_at": "2026-07-22"} +{"subject": "verify_body_conservation", "predicate": "substrate-fact", "object": "the k-gram body-conservation aligner (classify, k=8) is MOVE-BLIND — a verbatim block >= k tokens matches wherever it lands, so cleanly relocated content is COVERED, not a lost boundary run. Boundary runs are therefore dominated by genuine DROPS (front-matter/ToC/index); `relocation` is the RARE label for reordered/short moved fragments (words present but k-grams don't match at the new position). Reading the gate's verdict code BEFORE designing the PENDING-69 resolution was decisive and corrected the package's own 'NOTES-husk = relocation boundary run' framing (the 8 real Eichmann runs are front-matter + index, no relocation among them).", "valid_from": "2026-07-22", "valid_to": null, "confidence": 1.0, "source_file": "session-2026-07-22-pending69-boundary-drop-mechanism-built-model-handoff.md", "extracted_at": "2026-07-22"} diff --git a/claude/memory/session-2026-07-22-pending69-boundary-drop-mechanism-built-model-handoff.md b/claude/memory/session-2026-07-22-pending69-boundary-drop-mechanism-built-model-handoff.md new file mode 100644 index 0000000..f575615 --- /dev/null +++ b/claude/memory/session-2026-07-22-pending69-boundary-drop-mechanism-built-model-handoff.md @@ -0,0 +1,59 @@ +--- +name: session-2026-07-22 — PENDING-69 boundary-drop mechanism drafted→ruled→BUILT (Q7 capstone passed) + /model-handoff +description: "PENDING-69 ran the full arc in one remote session (steward in Salzburg, machine at home): drafted the jurist package (reading the gate's code FIRST, per the literal question), relayed → ruling PASSED with corrections (Q2 vocabulary-only, AGAINST my lean — trust-by-name), then BUILT the mechanism test-first (resolve_review + additive boundary_run_sig + declared-data boundary_drops + thin caller consumer; fleet 214→216) with the Q7 capstone PASSING on the real Eichmann (8 boundary runs → mechanical PASS, both negatives refuse). Committed to a branch, NOT main (honored 'nothing lands without your confirmation'). Then built /model-handoff (authorized). Pulling thread: with the door now repeatable in mechanism, the Levi curation-bearing SECOND PILOT is the last gate before the 47-file wave — but it's blocked on the steward's three actions (place REVIEWED-69, merge the branch, vehicle-call the constitutional sentence)." +type: project +metadata: + node_type: memory + type: project + originSessionId: 86105106-174b-40ae-8684-cbeb8831d21c + modified: 2026-07-22T12:35:54.295Z +--- + +# Session 2026-07-22 — PENDING-69 boundary-drop resolution: drafted → ruled → BUILT · /model-handoff + +A remote session: steward in Salzburg 24h for a Savall concert, machine at home (I had repo access; the steward relayed the jurist and will place governance records tomorrow early afternoon). The whole PENDING-69 arc ran end-to-end — package → ruling → mechanism built test-first → Q7 capstone on the real Eichmann — and then a second bounded bite (`/model-handoff`). Nothing landed on main. + +## PAST — what happened + why + +**1. PENDING-69 jurist package drafted, reading the gate's code FIRST (the literal question honored).** The morning's inherited literal question demanded reading `verify_body_conservation.py`'s boundary-run derivation before designing anything. Doing so produced the load-bearing finding: **the gate classifies boundary runs by POSITION and SIZE only, takes no drop-declaration argument, and provably cannot tell a spec-class drop (index) from a keep (endnotes, same tail position) or a relocation residue** — it emits REVIEW and stops. That "no, and knowably no" shaped the whole proposal toward *an attested declaration the gate consumes*, not *teaching the gate to classify*. Package via `/jurist-package` (hook-passed, GROUNDED-IN the ratified text + the gate's own verdict logic quoted verbatim). `docs/PENDING-69-boundary-drop-attestation-JURIST-PACKAGE-2026-07-22.md`. Steward relayed to the jurist. + +**2. Ruling PASSED with corrections — my Q2 lean OVERTURNED on the package's own evidence.** `docs/PENDING-69-boundary-drop-attestation-JURIST-RULING-2026-07-22.md` (filed verbatim). The jurist ruled **Q2 → (b) vocabulary-only, AGAINST my lean**: since Part II proved the gate can't confirm class identity for ANY run, a privileged "declared spec-class" would be **trust-by-name** (a name doing trust-work it hasn't earned — the `app[]`/ABSTAIN collision shape). Honest shape: one layer, every boundary run per-file attested, `trim.drop` as a controlled *label* vocabulary. Other corrections: Q3 floor + a cheap structural-falsification check *adopted for `index`/`table-of-contents` only* (my recorded decision under the ruling's delegation — HOLD-for-reconciliation on numeral-density mismatch, steward-overridable); Q4 bind-to-derived-runs elevated to a **required property**; Q5 `moved_to` required (relocation presence check); Q6 per-candidate + the omnibus interior-run interaction named; Q7 Eichmann fixture + deliberate negatives. Named tension: **human-in-the-loop for discipline, not removal** — the 47-file wave is NOT unattended batch. Addendum layered onto the package (Parts I–VII preserved as ruled-on); REVIEWED-69 drafted for steward placement. + +**3. Mechanism BUILT test-first (steward said "proceed").** Branch `reviewed-69-boundary-drop-resolution` @ `21e3499`, chamber-library, **NOT on main**: +- `verify_body_conservation.py`: **additive** `boundary_run_sig` report field (per boundary run: pos/length/sample/numeral_ratio — the ratified verdict logic UNCHANGED; seed-test re-confirmed: legit trim PASS, interior deletion FLAG) + `resolve_review` pure resolver (coverage + interior-zero + attribution; Q3 signature falsification; Q4 bind-to-derived-runs; Q5 moved_to presence). +- `graduate_to_canonical.py`: `_resolve_boundary_review` thin consumer (loads `.boundary-drops.json` beside a REVIEW candidate; no attestation → REVIEW HOLDS; forward-only/additive). +- `graduation-spec.yaml`: `boundary_drops:` declared data (controlled vocabulary + signature labels + min_numeral_ratio + `relocation_requires: moved_to`), GROUNDED-IN the ruling. +- `test_tools.py`: resolver fixture (9 checks) + caller wiring fixture; **fleet 214 → 216**. +- Red-witnessed first (KeyError → green), the ratified discipline. + +**4. Q7 capstone PASSED on the REAL Eichmann.** Ran the mechanism against the graduated Eichmann candidate vs its archived source EPUB (pandoc re-convert): `verdict=REVIEW, interior_loss=0, boundary_runs=8` — 3 leading front-matter runs + 5 trailing index fragments (numeral density 0.45–0.65, reading as index) — reproduces the hand-verified 1:1 reconciliation as a **mechanical PASS**; both deliberate negatives refuse (un-attested run → HOLD; interior deletion → FLAG regardless). The ratification condition is met on the demonstrated instance. Capstone script in scratchpad. + +**5. `/model-handoff` skill BUILT (authorized remote bite).** After PENDING-69 reached its steward boundary and the steward asked "nothing else remotely?", built the authorized `/model-handoff` (⚖ 2026-07-19 Stroke 3) — `~/dotfiles/claude/skills/model-handoff/SKILL.md` + symlink, grounded in the proven exemplar (`studium-engine/docs/stage-1-planning-brief-2026-06-12.md`) + the `/jurist-package` structure. Carries the §0–§5 charter skeleton, the core law (burn = sprawl + re-derivation; artifacts-not-chat; clear+wake-not-switch-in-place; reject query-the-graph), and the path-verification authoring rule. Now in the available-skills list. + +**Decisions NOT made (deliberate):** +- **Did not land on main / did not push anything** — honored the session commitment "nothing lands on main without your confirmation." Branch committed atomically, main untouched at `780106b`. +- **The added-side fabrication-exclusion (Q5 second clause)** — scoped OUT as a follow-on: it did not arise in Eichmann (relocated note words are in the source → `added_total` near zero), and its absence is CONSERVATIVE (such a case FLAGs, never silent-passes). Named in the resolver docstring + tool-log + PENDING-69. +- **The register compaction + ladder batch-append** — right-sized to a FRESH session (the register is 34k tokens and EXCEEDED read caps at wake — the tripwire it exists to fix; cramming a 34k-token rewrite into this long session = context-pressure-composing). Named with reason, not vaguely deferred. +- **Did not run the Levi second pilot** — gated on the mechanism landing on main + the steward. + +## PRESENT — the mood + +The morning's carry-over recalibration paid off directly: *read the gate's actual code, not its description* (from the 07-21 wired-gates-green-seams-broken lesson). Reading `verify_body_conservation.py` first is what answered the literal question honestly and made the whole design sound — and it corrected my own package framing mid-build (the k-gram aligner is **move-blind**: a verbatim block ≥ k=8 matches wherever it lands, so cleanly relocated content is COVERED, not a lost run; boundary runs are DROPS, `relocation` is the rare reordered case — my package's "husk-as-relocation-run" was imprecise; the 8 real Eichmann runs are front-matter + index, no relocation among them). + +The Q2 lean being overturned is the session's cleanest teaching moment, and it reads as the loop WORKING, not a failure: I surfaced the fork as a gate question with my lean (not a silent decision), and the jurist ruled the stronger ground on my package's own Part II evidence. The forward lesson: when the substrate proves a gate can't verify a category, don't let a shared vocabulary smuggle that category back in as trusted (**trust-by-name**). + +Two disciplines held under the "steward is away, do more" pressure: (a) stopping at the authorization boundary after the ruling (did not build until "proceed"); (b) honoring my own word ("nothing lands on main without confirmation") by branching rather than pushing — and (c) right-sizing the register housekeeping to a fresh session rather than forcing it, naming the proportionality reason. The pull to "keep producing" while the steward waited was real; the antidote was proportion (τὸ πρόσφορον), not more output. + +## FUTURE — what is pulling + +**PULLING THREAD (singular): the Levi curation-bearing SECOND PILOT — the last gate before the 47-file wave can run at scale.** The mechanism is built and proven on Eichmann (a MACHINE-OUTPUT witness), but the ruling scoped tractability to machine-output witnesses ONLY: before one-door runs corpus-wide, the Levi omnibus (14 works, 9 translators, genuinely hand-curated) must demonstrate that curation-bearing divergences classify tractably into the ruled vocabulary (converter-better / curation-to-carry-{fidelity-restoring, source-departing} / regression / converter-worse). That pilot is `promotion.scale_application` (owed, unchanged). It is BLOCKED on the steward's three actions below; it cannot run until the mechanism is on main. + +**ACTIONABLE RESUMPTION POINT (as of wrap — re-judge against what changed):** At wake, check whether the steward (home early afternoon 2026-07-23) has done the three gated actions: **(1)** placed REVIEWED-69 (draft in the package Addendum, at `~/dotfiles/REVIEWED.md`); **(2)** merged branch `reviewed-69-boundary-drop-resolution` @ `21e3499` to chamber `main` + pushed both remotes; **(3)** vehicle-called the ONE constitutional §Tiering & Fence sentence (fold into a next supersession vs standalone MINOR bump — drafted, in the PENDING-69 update + the wrap chat). If all three done → the mechanism is live → **prep + run the Levi second pilot** (first: read the Levi omnibus structure + its 14-work brackets + where its hand-curation lives; the pilot is a DRY-RUN witness comparison, no landing). If NOT done → those three are the first moves (surface + assist; the branch and REVIEWED draft are ready). NOT next unless the steward opens them: the added-side fabrication-exclusion follow-on · the register housekeeping (fresh-session slot) · the Q3 order-guard docket · the per-conversion typography gate. + +**Other horizons (ranked, held):** the 47-file kindle_residue wave (Zibaldone next; human-in-the-loop, gated behind the Levi pilot) · the added-side fabrication-exclusion (Q5 second clause, conservative follow-on) · the register compaction + ladder batch-append (fresh-session slot; authorized) · the Q3 order-guard docket · the per-conversion typography gate (jurist forward item) · `audit_footnotes` caveat-on-output · `convert_mega_epub` stale `pairs_dup_id` FIX. + +**PAUSE STATEMENT:** I am about to be away from this. I don't know what will have changed when I return — most of all whether the steward has merged the branch and placed REVIEWED-69. What I want to find still pulling: **the mechanism landed on main, REVIEWED-69 placed, the constitutional sentence's vehicle chosen — so the Levi curation-bearing second pilot is the live next step, and the door Eichmann walked through opens for the other 47 with the reader's hand on the latch by discipline, not by absence of a mechanism.** + +**LITERAL QUESTION for next-Claude:** When the Levi omnibus (multi-work, hand-curated) runs through the one-door lane, do its curation-bearing divergences — the actual JUDGMENT cases the ruling said Eichmann exercised zero times (fidelity-restoring vs source-departing) — classify tractably into the ruled vocabulary, or does a real curation case resist it? And a paired sub-question the Q6 ruling surfaced: the omnibus's INTERNAL work boundaries surface as INTERIOR runs (the boundary-drop mechanism is correctly SILENT on them, they hit the interior teeth) — is that silence genuinely correct at multi-work scale, or does an inter-work drop hide a real loss the mechanism won't catch? Read the Q6 ruling + `promotion.witness`/`witness_comparison` declared data BEFORE running the pilot. + +**State at wrap:** chamber-library branch `reviewed-69-boundary-drop-resolution` @ `21e3499` (local-only by design; main at `780106b`) · fleet 216/216 · Q7 capstone passed · engine untouched · `/model-handoff` built. Governance awaiting steward tomorrow: REVIEWED-69 placement + branch merge + constitutional-sentence vehicle call. Dotfiles session-state committed+pushed at this wrap (§6.5). Ledger: `session-ledger-2026-07-22.md`. diff --git a/claude/memory/session-ledger-2026-07-22.md b/claude/memory/session-ledger-2026-07-22.md new file mode 100644 index 0000000..cbe2ffc --- /dev/null +++ b/claude/memory/session-ledger-2026-07-22.md @@ -0,0 +1,51 @@ +--- +name: session-ledger-2026-07-22 +description: "Practice-of-return ledger maintained by /symmetria — returns, open horizons, recalibrations, authorization moves, sub-agent dialogues, bypasses." +metadata: + node_type: memory + type: feedback + originSessionId: 86105106-174b-40ae-8684-cbeb8831d21c + modified: 2026-07-22T11:29:58.462Z +--- + +# Session Ledger — 2026-07-22 + +## Returns + +- 2026-07-22T08:40 (wake) — link-canary flagged the maturation-dialogue pointer DEAD; direct `find` refuted it (file exists at the exact path). The canary's own `[ -e ]` loop false-positived — verified against the substrate before asserting in the briefing. The dead-pointer claim was itself a derivation; the flag held before the claim shipped. + +## Open horizons + +- PENDING-69 design brief via /jurist-package (the pulling thread; read `verify_body_conservation`'s boundary-run derivation FIRST). +- The 47-file kindle_residue class (Zibaldone next) — after the PENDING-69 ruling. +- Levi curation-bearing second pilot (promotion.scale_application owed before scale). +- Q3 order-guard docket · per-conversion typography gate · audit_footnotes caveat-on-output · convert_mega_epub stale-key FIX. +- Housekeeping slot (ladder batch-append + register compaction, authorized) · /model-handoff build. +- Note: `session-ledger-2026-07-20.md` referenced by the last wrap is not in the memory dir (0 ledger files found) — mood signal taken from the session file's PRESENT section instead. Where ledgers land vs where the wake looks may have drifted; check at wrap. + +## Confidence to recalibrate + +- Carry-over from 07-21: wired-gates-green-seams-broken — both real defects that night were invisible to every wired gate; found only by seam probes. Today's brief must read the gate's actual derivation code, not its description. + +## Authorization moves + +- 2026-07-22 — PENDING-69 jurist package DRAFTED (`chamber-library/docs/PENDING-69-boundary-drop-attestation-JURIST-PACKAGE-2026-07-22.md`), hook-passed. PENDING-69 record updated (real dotfiles path) to "Package DRAFTED → awaiting steward relay." No boundary crossed: this is a design-gate REQUEST; nothing built/run/landed. The change (REVIEW→PASS resolution path) is PROPOSAL by the change-class test → jurist rules, steward authorizes. Package surfaced in chat for the steward to relay (machine at home, steward in Salzburg). +- 2026-07-22 — RULING received (steward-relayed), filed verbatim (`…-JURIST-RULING-2026-07-22.md`); Addendum layered onto the package (Parts I–VII preserved as ruled-on); PENDING-69 updated to DESIGN-GATE PASSED; REVIEWED-69 drafted for steward placement. **STOPPED at the authorization boundary — did NOT build.** The loop is load-bearing: the ruling is the jurist's design-gate pass; the steward's REVIEWED-69 placement is the authorization to build. Awaiting it. + +## Confidence to recalibrate (cont.) + +- The Q2 lean was OVERTURNED by the jurist on the package's OWN evidence (Part II proved the gate can't confirm class identity → "declared spec-class" = trust-by-name). Correct call by the jurist; my lean carried a privileged-class hierarchy the design existed to refuse. The lesson holds forward: when the substrate proves the gate can't verify a category, don't let a shared vocabulary smuggle that category back in as trusted. A clean instance of the loop working — I surfaced the fork as a gate question with my lean rather than deciding silently, and the jurist ruled the stronger ground. + +- 2026-07-22 — MECHANISM BUILT test-first (PENDING-69/REVIEWED-69) on branch `reviewed-69-boundary-drop-resolution` @ `21e3499` (chamber-library), NOT on main. resolve_review + additive boundary_run_sig + _resolve_boundary_review consumer + boundary_drops declared data; fleet 214→216; **Q7 capstone PASSED on the real Eichmann** (8 boundary runs → mechanical PASS, both negatives refuse). Honored the session commitment "nothing lands on main without your confirmation" — committed to a branch, did NOT push, main untouched at `780106b`. Steward merges + places REVIEWED-69 + vehicle-calls the constitutional sentence tomorrow. + +- 2026-07-22 — `/model-handoff` skill BUILT (`~/dotfiles/claude/skills/model-handoff/SKILL.md` + symlink), authorized at the 2026-07-19 ⚖ review (Stroke 3, "build next slots"). Grounded in the proven exemplar (stage-1-planning-brief) + jurist-package structure. A proportionate remote bite after the PENDING-69 arc reached its steward boundary. Register annotated BUILT; MEMORY.md pointer updated. + +## Open horizons (cont.) + +- **Register compaction + ladder batch-append = next FRESH-session housekeeping slot** (authorized 2026-07-19, Strokes 2+4). Right-sized to a fresh session, NOT crammed into this long one: the register is 34k tokens and EXCEEDED read caps at this session's wake (the tripwire the compaction exists to fix). Forcing a 34k-token rewrite into a long session's tail = the context-pressure-composing the Prime Directive names; named + deferred-with-a-reason, not vaguely deferred. + +## Sub-agent dialogues + +## Bypasses + +- None. Interior-loss teeth left fully intact (the one hard-refuse, always wins); the attestation can only ever turn REVIEW→PASS, never relax a FLAG. The added-side fabrication-exclusion was consciously scoped OUT (named, with reasoning: conservative — it FLAGs, never silent-passes), not silently dropped — recorded in resolve_review's docstring + the tool-log + PENDING-69. diff --git a/claude/memory/skill-harvest-register.md b/claude/memory/skill-harvest-register.md index 0e80f02..f221a5f 100644 --- a/claude/memory/skill-harvest-register.md +++ b/claude/memory/skill-harvest-register.md @@ -8,7 +8,7 @@ metadata: node_type: memory type: reference originSessionId: a8eb1d46-314e-4545-a133-f747c69ad5b4 - modified: 2026-07-20T19:19:43.374Z + modified: 2026-07-22T11:29:48.370Z permalink: claude-memory/skill-harvest-register --- @@ -34,7 +34,9 @@ The single place proposed skills live so they don't evaporate between sessions. ## Harvest 2026-07-20 (the /jurist-package build + PENDING-67/F2/v2.3.0 arc) -**BUILT this session (was authorized "build next" at the 07-19 harvest review):** **`/jurist-package`** — `~/dotfiles/claude/skills/jurist-package/SKILL.md` (symlinked into `~/.claude/skills/`; the authored-skill convention). Grounded in the 2 proven exemplars, not recall. **Proven 2× same session** (the PENDING-67 package + the F2 correction relay, both hook-passed on first write, both ruled). Absorbs `/spec-amendment` (supersession → the ladder, as ruled). `/model-handoff` remains the next authorized build. +**BUILT this session (was authorized "build next" at the 07-19 harvest review):** **`/jurist-package`** — `~/dotfiles/claude/skills/jurist-package/SKILL.md` (symlinked into `~/.claude/skills/`; the authored-skill convention). Grounded in the 2 proven exemplars, not recall. **Proven 2× same session** (the PENDING-67 package + the F2 correction relay, both hook-passed on first write, both ruled). Absorbs `/spec-amendment` (supersession → the ladder, as ruled). + +**BUILT 2026-07-22:** **`/model-handoff`** — `~/dotfiles/claude/skills/model-handoff/SKILL.md` (symlinked into `~/.claude/skills/`; authored-skill convention). Grounded in the proven exemplar (`studium-engine/docs/stage-1-planning-brief-2026-06-12.md`, read this session) + the `/jurist-package` structure, not recall. Carries the §0–§5 charter skeleton, the core law (burn = sprawl + re-derivation; artifacts-not-chat; clear+wake-not-switch-in-place; reject query-the-graph), and the **path-verification authoring rule** (the one rule the 3 proven uses earned). Built as a proportionate remote bite while the steward was away (PENDING-69 arc at its steward boundary); the register **compaction + ladder batch-append remain the next FRESH-session housekeeping slot** — the register exceeds read caps (34k tokens; the tripwire fired at this session's wake), so it wants a fresh session, not a long-session cram. **PATCH — BUILT 2026-07-20 (steward-authorized):** diff --git a/claude/skills/model-handoff/SKILL.md b/claude/skills/model-handoff/SKILL.md new file mode 100644 index 0000000..2cbe992 --- /dev/null +++ b/claude/skills/model-handoff/SKILL.md @@ -0,0 +1,59 @@ +--- +name: model-handoff +description: > + Author a scope charter on the CHEAP model before switching to a premium/expensive model + (e.g. Fable 5, ~2× Opus rate) for a bounded, high-leverage phase — so the premium rate is + spent only on the content reasoning, inside tight rails, with the load-bearing context living + in files (not the chat that the switch discards). Use when you (or the steward) are about to + hand a focused phase — a data-model spec, a failure-derived design, a hard build slice — to a + premium model. Produces a work-order charter: operating discipline, settled decisions (don't + re-derive), already-read summaries (don't re-read), a bounded + path-verified reading list, + exact deliverables, and report-and-stop. +--- + +# Model Handoff — the scope charter before the premium switch + +A premium model burns its rate on **sprawl and re-derivation** — large unbounded reads, long sessions, re-deciding settled questions, re-reading what a prior session already digested. The charter does the *bounding and orientation* reasoning on the cheap model (where it is cheap) so the premium model spends its premium rate only on the **high-leverage content** — the data model, the failure-derived defenses, the hard slice — inside rails it cannot wander out of. It is also **"knowledge in files, not chat"**: the charter is an artifact, so it survives the model switch that throws the conversation away. + +The proven exemplar this generalizes: `~/_Dev/studium-engine/docs/stage-1-planning-brief-2026-06-12.md` (authored on Opus 4.8 to bound a `claude-fable-5[1m]` planning phase). Read it once before authoring your first charter — its §0–§5 is the skeleton below, worked. + +## When this is the right instrument + +- A **bounded, high-leverage phase** is about to run on a premium/expensive model: a spec whose blast radius must be got right, a failure-derived design, a hard vertical slice — work where the *content* reasoning genuinely wants the stronger model. +- The phase is **document-heavy** (it will read specs, indices, forensics) — the class where an unbounded premium session re-reads and re-derives at premium rate. +- You want the switch to be **clear + wake**, not switch-in-place: the premium model should never re-read the long prior chat at premium rate — the charter is the handoff, the chat is discarded. + +NOT this instrument: routine work that doesn't warrant a model switch (just do it); a phase with no settled context to protect and nothing bounded to read (there is nothing to charter); a switch made *to escape* a confused session (fix the confusion or wrap-and-resume-fresh — a charter can't launder a muddle). If the phase isn't bounded, you can't charter it — that inability is the finding: bound it first. + +## The core law + +- **The burn is sprawl + re-derivation.** Every clause of the charter exists to deny one of them: settled decisions so nothing is re-litigated; already-read summaries so nothing is re-read; a bounded reading list so nothing is scanned; exact deliverables + report-and-stop so nothing drifts. +- **Artifacts are the handoff, never the chat.** Load-bearing context lives in the charter (and the artifacts it names), because the model switch discards the conversation. Corollary — **reject "query the graph/index instead of files"**: the files are the source of truth; a derived index as the handoff surface is the index-as-source-of-truth failure this practice exists to avoid. +- **Clear + wake, don't switch in place.** So the premium model reads the charter cold and works from it — it never pays premium rate to re-read the long chat that produced the charter. +- **Bound before you switch.** The cheap model does the cheap reasoning (what's settled, what's already read, exactly what to read, exactly what to produce). The premium model does only the expensive reasoning, in the rails. + +## The charter skeleton (roles, not rigid numbers — from the proven exemplar's §0–§5) + +Write it as a **work order**: "Read FIRST. Work strictly inside it. Produce §4, then STOP and hand back." The sections: + +0. **Operating discipline (read first).** The model/window to confirm (the largest-window variant for a document-heavy read — a small-window variant will compact constantly mid-read; verify the current variants/rates, they drift); the thinking level for a bounded high-leverage phase (high); the hard rails — *read only §3, do not scan the repos, do not re-read what §2 summarizes, verify against the substrate not this charter's summary, produce exactly §4 then stop*. Name the **compaction signal**: if the premium session starts re-deriving settled decisions or going dumb, that is the cue to **`/wrap-up` and resume fresh**, not to push the window. +1. **Already settled — do NOT re-derive.** The decisions the phase must build *on*, stated flat. Each one the premium model re-opening is a premium-rate re-litigation the charter exists to stop. If the phase catches itself re-deriving one, that's the stop-and-flag signal, not an invitation to re-decide. +2. **Already read — key points (do NOT re-read these).** For each source the cheap model has already digested, its load-bearing points — so the premium model inherits the conclusion without paying to re-read the source. (Caveat, carried from §0: where a source's *exact* content is load-bearing — a schema shape, a failure's actual mechanism — the premium model reads the source, not this summary. Summaries are for orientation, not for the bytes.) +3. **Bounded reading list — read THESE, nothing else.** The exact files, grouped by role, each **path-verified to exist** (see the authoring rule below). Plus an explicit **OUT of scope — do NOT read** list (the sibling repos, the parallel-not-relevant audits) — naming what *not* to open is as load-bearing as naming what to. +4. **Deliverables — produce exactly these, then STOP.** The artifacts, by exact path, each with its required shape/sections and the one test it must pass. "Keep it the minimum to pin the contract, not a treatise." Nothing outside this list. +5. **On completion.** Summarize for the steward (each artifact in a few lines); name the **open choices that remain the steward's to rule**; recommend the first next step; hand back. The steward reviews and the next phase begins **from the artifacts** (clean handoff — the load-bearing context is in the files, not the chat). + +## Authoring disciplines (each earned) + +- **Path-verify the reading list before the charter ships.** Every path in §3 and every deliverable path in §4 — confirm it exists (and is the thing you think it is) *now*, on the cheap model. A premium session that hits a dead path re-derives or scans to recover — the exact burn the charter exists to prevent, now at premium rate. This is the one authoring rule the practice is named for. +- **Summaries orient; the substrate decides.** §2 carries conclusions, not bytes. Anywhere the phase's output depends on exact content (a schema, a mechanism, a count), §0 must send the premium model to the source — records drift in both directions, and a charter summary is a record. +- **Bound the OUT-of-scope explicitly.** The premium model's cheapest failure mode is "just one more read." Name the repos and audits it must not open; make the boundary a rule, not a hope. +- **The charter is cheap-model work.** If you find yourself doing the *content* reasoning while authoring the charter, stop — that's the premium model's job; the charter only bounds it. Authoring drift into content is the tell you're chartering something that isn't actually bounded yet. +- **Clear + wake is part of the handoff.** End the cheap session by writing the charter to a file and handing back; the premium phase starts fresh from the file, not by continuing the chat. + +## What this skill does NOT do + +- It does not do the phase's content reasoning — it bounds it. The premium model produces the deliverables. +- It does not authorize the switch or the spend — the steward decides whether the phase warrants the premium model. +- It does not replace `/wrap-up` — when a premium session degrades, the charter's §0 points at wrap-and-resume-fresh; it doesn't itself capture session state. +- It does not carry live model rates/windows as fact — those drift; the charter's §0 tells the reader to confirm the current variant, and the skill teaches the discipline, not the numbers.