governance: steward places the §4 revision note and REVIEWED-131 AMENDMENT 1

Two steward placements in one commit, per the jurist's ordering so a
single commit carries the whole state of the file:

- The §4 revision note. §4 was rewritten in place on 2026-09-01 inside a
  ruling placed 2026-08-31, and nothing in the record said so. The note
  records what the original said, why it changed, and that PENDING-173's
  integrity control cannot see the change because its unit is the block
  header while what changed is a section inside a block.

- REVIEWED-131 AMENDMENT 1, joined at ### depth beneath its parent:
  control (c)'s premise is false, and a by-design unattended agent has
  been in production since 2026-08-25.

Committed by the executor at the steward's explicit direction. The
content is entirely the steward's and the jurist's; committing records
it rather than modifies it, and REVIEWED.md was otherwise untouched
across this session.

⚠ THE DRIFT-CHECK REPORTS TWO BROKEN AMENDMENT LINKS AGAINST THIS FILE,
AND THE FINDING IS FALSE. REVIEWED-131 is present and was not replaced.
RE_ID requires a dash immediately after the identifier; the house form
`## REVIEWED-N (PENDING-M) — title` defeats it, and the regex backtracks
to capture the bare token `REVIEWED`, so REVIEWED-131 never enters
`originals` and its amendment looks orphaned.

Scope measured, not assumed: 3 of 132 REVIEWED headers — 130, 131, 132,
all placed within the last week. It fired now because ours is the first
amendment against a parenthetical parent.

Not repaired here. Whether the control should parse the newer header
form, or the newer form is an undeclared convention change, is the
question PENDING-146 and PENDING-110 already hold, and this is the
control REVIEWED-132 widened this morning.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017vKkg2EJF1rGwdFdBogwqx
This commit is contained in:
David F Glidden
2026-09-01 10:14:49 +02:00
co-authored by Claude Opus 5
parent 6eff2056f9
commit 6a93505c7f
+59 -1
View File
@@ -2444,7 +2444,29 @@ PENDING-163. Close PENDING-163. Tag nothing new with REVIEWED-130.
3. CONDITION — **(b) is authorized as annotation and is explicitly not a control.** Marking the digest as orientation, and `OPEN QUESTION` as inherited-from-a-human and answerable to a human, is cheap and honest. It cannot enforce and must not appear in any report as a mitigation. The item's own warning on this point is adopted verbatim.
4. **(d) is the steward's standing decision and is not ruled.** Recorded because it survives whatever is built: both binaries contain the mechanism, `cause=upgrade` supplied the restart and not the capability, and the sole precondition is a parked idle worker. The burden has moved — keeping background sessions is now the choice requiring justification. (e) is the tripwire that reports whether the policy is holding; it is not a substitute for the policy.
4. **(d) is the steward's standing decision and is not ruled.** Recorded because it
survives whatever is built: `cause=upgrade` supplied the restart and not the
capability — identical `reply-on-resume` and `post-takeover prewarm` counts in
2.1.248 and 2.1.251 show the flag exists in both, though not that the respawn
policy is byte-identical — and the sole precondition is a parked idle worker.
The burden has moved: keeping background sessions is now the choice requiring
justification.
**PENDING-172 AMENDMENT 1's (e) is not subordinate to (d), and this ruling does
not make it so.** The parent's claim that only (d) is enforceable without
depending on the party checked was withdrawn the same day: `respawnFlags` in
`~/.claude/jobs/<id>/state.json` is readable without asking the session
anything. The amendment weighs (e) against (d), not beneath it — and (d)'s own
precondition is unobservable at the surfaces the steward uses, so on this record
(e) is what makes (d) falsifiable rather than a monitor of whether it holds.
⚠ (e)'s declared weakness travels with it wherever it is stated: a missing job
dir reads as absence, not as safety.
**§4 REVISED 2026-09-01 (jurist-drafted, steward-placed; executor-verified against the file).** The original §4 read *"(e) is the tripwire that reports
whether the policy is holding; it is not a substitute for the policy"* — subordinating (e) to (d). PENDING-172 AMENDMENT 1 had already withdrawn the parent
claim that grounded it: `respawnFlags` is readable without asking the session anything. Sixteen lines of a ruling placed 2026-08-31 were rewritten in place;
**PENDING-173's integrity control cannot see this, because its unit is the block header and what changed is a section inside a block.** Recorded per §6's
own no-silent-revision.
5. **SEVERED — the memory protocol assumes one executor per day.** Date-keyed `session-ledger-YYYY-MM-DD.md`, one session file, one Active Session block with demote-on-promote: two concurrent sessions do not merge and the second silently becomes the record of the day. This is a live `[HARDENING]` ask embedded in an `[ESCALATE]` item — the shape PENDING-146 names in PENDING-131 ADDENDUM 2. It is filed as its own item and is not disposed of here. Its cost was incurred today, not hypothetically.
@@ -2456,6 +2478,42 @@ PENDING-163. Close PENDING-163. Tag nothing new with REVIEWED-130.
**If AUTHORIZED:** Build (e) first, with its NOT ESTABLISHED path and enumeration. Then (c). Apply (b) on the same pass, marked as annotation in the code and in the output. File the severed item at §5 before wrapping. Place the provenance markers at §6 before PENDING-171 is brought forward.
### REVIEWED-131 — AMENDMENT 1: control (c)'s premise is false, and a by-design unattended agent has been in production since 2026-08-25
**Date:** 2026-09-01
**Amends:** REVIEWED-131 §2, which authorized (c). Joined to the original, which stands as placed.
**Status:** Steward-directed 2026-09-01; drafted by the executor on the substrate question left open. Not a ruling.
**The finding.** Control (c) fired on session `435f1368` (00:56, 2026-09-01), reporting `NO HUMAN TURN … That session ran unattended. PENDING-172.` The session had no human turn and was a **Tarbuckle mumble** — statusline-driven, one programmatic prompt, one line of output. The predicate was true and the inference was wrong.
**The correction, at the level it belongs.** §2 authorized (c) on the premise that a session with no preceding human record is anomalous. **That premise is false.** Some sessions are unattended because they are meant to be. The governing property is **whether the unattendedness was authorized**, not whether a human was present; the two coincide only for session kinds nobody has declared.
**What is not wanted.**
- **No exclusion list.** A name in a list is honoured by whoever remembers it — PENDING-168's class.
- **No self-declaration.** A field the session writes is the control reading the party it checks — PENDING-107's finding. It must be set where the session is spawned and read where the session cannot reach.
- **No widening of (c)** into a general "is this session legitimate" check. It reads one thing.
**What is wanted — three outcomes, never two.**
- human turns present → **attended**
- none, and the kind is declared unattended → **BY DESIGN**, named
- none, and no declaration → **the PENDING-172 condition**
⚠ A session whose kind **cannot be read** reports **NOT ESTABLISHED**, never "by design" — REVIEWED-131 condition 1's rule for (e), applied to (c) for the same reason. A two-state control must guess on what it cannot classify, and it will guess toward silence; that is how today's false positive becomes tomorrow's suppressed true one.
**The location, established from substrate 2026-09-01 (the question §2 left open).** Two sites, one existing and one absent.
- **(i) Daemon-spawned sessions — exists and suffices.** `~/.claude/jobs/<job>/state.json` carries `respawnFlags` **and `resumeSessionId`**, which is the job→session index (c) needs. Verified: `acaabadf` names `resumeSessionId = b7e7eb39…`, the unattended executor of 2026-08-31. **A job-dir-keyed control preserves the motivating true positive.**
- **(ii) `claude -p` spawns — the entire mumble class — nothing exists.** `~/.claude/jobs/` holds exactly one entry, ever; the mumble is `subprocess.run(["claude", "-p", …])` from the status line, not a daemon job, so there is no state file, no `respawnFlags`, no job dir. The spawner **already sets `TARBUCKLE_CHILD="1"` in the child environment** — the right intent at the wrong durability, since env is persisted nowhere a later reader can reach. Making it durable requires the spawner to learn the child's session id (`--output-format json` returns `session_id`) and write it to a registry the **spawner** owns.
**Interim behaviour, buildable without touching the fool.** Until (ii) exists, (c) reports **NOT ESTABLISHED** for a no-human-turn session with no job dir. That is today's 115 mumble transcripts, and it removes the false positive **without** removing the true positive, which is reachable through (i). ⚠ It is a narrowing, not a fix: a genuine unattended `-p` session would also report NOT ESTABLISHED, and the report must say so on its face.
**Two things recorded here, because they are the wider finding.**
1. **Tarbuckle has been running as a by-design unattended agent since 2026-08-25** — across eight project directories, **115 of 159 transcripts**. A bounded unattended loop is already in production and **was never governed as one**. It reached the register as a denominator defect (PENDING-178) and as a false positive, never as a session kind.
2. **Whether such loops can be compliant with this system is therefore not a future question.** It is being answered by what this amendment builds.
**Not asked for, and deliberately absent:** no audit of Tarbuckle's conduct, no measurement of its output, no second instrument. The suppression finding and the counter's unit defect are separately held and stay separate — bundling them here is PENDING-146's CLASS E.
**Executor's declared limit.** (ii) is a mechanism in `dotfiles`, proposed on behalf of a governance instrument — the coupling PENDING-152 notes. Nothing is built under this draft; the interim narrowing in (i) is the only part reachable without a ruling.
## REVIEWED-132 (PENDING-173) — The register-integrity control covers one word of a two-word convention, in one of two registers
**Date:** 2026-08-31
**Decision:** AUTHORIZED — option (a), on five conditions. The proposed maxim is WITHHELD; the convention question is routed to PENDING-146 and not decided here.