diff --git a/PENDING.md b/PENDING.md index 768e623..8e62712 100644 --- a/PENDING.md +++ b/PENDING.md @@ -498,6 +498,16 @@ Delete the Cowork party entry and every reference to `COWORK.md`. Grounds, now t **Files affected:** new `~/dotfiles/scripts/governance-mcp.py`; `~/dotfiles/scripts/wake-digest.py` (`item_spans()` fence-awareness + 3 controls). Awaiting steward hand: `claude_desktop_config.json`, Claude.app §Your Role and §Standing Context. **Awaiting:** Steward authorization to install the `mcpServers` key. The server itself is inert until then — nothing loads it. +### AMENDMENT — 2026-08-08, a concrete enum, from a ruling that hit the wall + +The jurist ruling on PENDING-121 established this gap **empirically**. `governance_read` takes a key from a fixed enum — `app-brief`, `chamber-spec`, `claude-md`, `graduation-spec`, `memory-index`, `pending`, `pending-archive`, `reviewed`. **`conversion-runbook.yaml` and `r0-reading-index-contract.md` are reachable by NO key**, so a ruling resting on them rests on executor testimony — and that ruling had one leg in exactly that state until the files were relayed by hand. + +**The gap is also its own remedy:** the server takes keys from a list, so **extending the enum IS the extension mechanism.** Adding `conversion-runbook` closes the chamber half immediately. The R0 contract is D-1 engine-side, so its inclusion is a standing question rather than a tooling one. + +⚠ **Also noted, no action asked:** the 2026-07-10 general-statement ratification lives in `hash-locality-ratification-and-lane-narrowing-JURIST-RULING-2026-07-10.md`, which the register **references but does not contain**, and no tool reaches; PENDING-47's log twice records a `docs/` copy as owed. **A ratification the register can only point at is a thinner record than one it holds.** + +*Filed here rather than as a new item: this is PENDING-82's subject exactly, and a second home for it would be the fault this week keeps ruling against.* + ## PENDING-83 — The evidence tier is decided by file extension, so a born-digital PDF gets a false ABSTAIN **Date:** 2026-07-28 **Tag:** [PROPOSAL] @@ -1850,6 +1860,26 @@ The package proposed **five sibling entries.** REVIEWED-53 appears in no Part, i **§E — Nothing of the mechanism is drafted.** The ruling's *"then, and only then"* is respected: a refuted quotation should cost a paragraph, not a design. +--- + +### AMENDMENT 3 — 2026-08-08, verification returned; GATE HELD OPEN for a redraft of IV.2 + +**§A — All three files ultimately read.** Parts I.1–I.2 **confirmed exact**; Files 2 and 3 confirmed by recomputed sha against the request's table. **Condition 2 leg (a) verified** — and it never needed the runbook: a key named `engine` already housed chamber artifacts in my own draft. **Leg (b) verified**: `catalogue.yaml` is at runbook **L251**. + +**§B — Verified against MY substrate, because they were claims about it.** ⚠ **The manifest binds THREE repos, not two** — chamber-library 9, **`animal-davidglidden-eu` 5** (`after-the-reply-i…v`). Part II censused all eight reading-index sources in one table without marking five as **ARC**, and IV.2 hard-coded `chamber-library` paths for them: **wrong for five of eight.** ⚠ **`canonical_binding_surface` CONTAINS `binding_surface`** — my availability census used substring matching, which is exactly how `source_binding` scored six. The name I recommended would have made the runbook's own key un-greppable **through the instrument built to prevent that**. → **`canonical_binding`**. ⚠ **R0 §4 L223–225 is binary** (*"emitted marked `stale`, never silently corrected"*) against §3 L180's *"must not be collapsed into either neighbour"* — confirmed; and its mitigation is real (emission is steward-reviewed and does not write into the chamber unasked). + +**§C — Q3 REVISED, and my lean was wrong in a way worth keeping.** The enumeration is **not incomplete — it is NOT COMPLETABLE**: the runbook's `scope_note` sets membership as *any repo the engine manifest binds*, and the runbook's own list was found short **by its own grep** in 2026-07-19. So the spec is authoritative for **semantics**, the runbook's grep for **completeness** — two claims, two homes, **not** the fault condition 1 forbids. My *"single enumerative authority"* would have demoted the only instrument that has ever caught a missing surface. + +**§D — IV.2 REDRAFTED** (package Addendum 2): renamed `canonical_binding`; one entry, addressable members; co-movement as a declared `invariant:` with `partial_coverage_verdict: incomplete`, drafted **once** with IV.1 ¶2; `exhaustive: false` + `completeness_authority:`; `membership_rule:` open over repos with a `` placeholder; **`chamber-catalogue` added** (V8); **`engine-sidecar-region` added** (V10 — R0 §3 rules the two per-region gaps are *one mechanism with two call sites*, so enumerating only one would hard-code the divergence into declared data); dated counts replaced by `may_contribute_to_green` / `unpopulated_is`; `promotion.states` with `collapsing_unverified: forbidden`; `staleness_model: exact-signature-entries` per the `known-failures.json` precedent (V12). + +**§E — Q5 and Q6 as ruled.** No amendment to the ratified principle; L19 and L39–L40 update as **mechanical referring-name edits**, REVIEWED-53's two reading grains preserved at the new name; `~/REVIEWED.md` L471 **not** edited. ⚠ **Completion control required, both directions** — before: the search finds the known occurrences; after: **zero hits on the old name outside `REVIEWED.md`, excluded BY NAME in the command**, not by the search happening to miss it. + +**§F — Recorded, not taken up:** REVIEWED-53's deferred option (c) — renaming to kill the *"manifest"* shared word — is **live again** by the same reasoning that carried Q6, its deferral having rested on occasion rather than merit. A separate object with its own scope. + +**§G — On my own calibration.** Five omissions are now known, and the jurist's reading is that every substantive one **understates** the gap I was arguing for. Accepted. The pattern I would add: they were not selective, but they were **systematic in kind** — I quoted the passages stating the *problem* and skipped the passages stating its *extent*. Four of the five are extent-passages. + +**Awaiting:** redraft reviewed at the placement gate. ⚠ **Blocked on a D-1 defect** — the R0 §4 L224 binary, filed as **PENDING-127**; the chamber requirement is unmeetable while it stands. + --- ## PENDING-122 — What a green fleet certifies, and what it does not: no suite validates live binding @@ -2114,3 +2144,33 @@ Three cases, all discriminated: a rule ran → existing output already says so, **Awaiting:** Steward authorization (D-1 lane). --- + +## PENDING-127 — R0 §4 emits two states where §3 rules three, and it loses `unverified` exactly when the claim becomes durable + +**Date:** 2026-08-08 +**Tag:** [HARDENING] — engine-side, D-1 +**Related:** R0 contract §3 L180 / §4 L223–225 · PENDING-121 condition 4 (**unmeetable while this stands**) · PENDING-124 (the three-valued doctrine) · PENDING-122 Amendment 2 (the same collapse, in the fleet). +**Found by:** the jurist, reading R0 §4 — a section the package quoted *around* and never quoted. + +**Summary.** R0 §3 rules three states and forbids collapsing one: *"`unverified` is not a failure state and must not be collapsed into either neighbour."* R0 §4 L223–225, which governs **emission**, is **binary**: *"A region whose anchors do not verify is emitted marked `stale`, never silently corrected."* Verify, or `stale`. There is no third branch. + +**Why it bites exactly where it matters.** Alexander's five `front_matter` anchors are **unverifiable** by the only instrument available at emission — name-landing, which §3 says reaches `verbatim` titles only. Under L224 they either become **`stale`** (collapsing `unverified` into a neighbour, which §3 forbids) or fall through the binary and get **fingerprinted**. **Either way one of the three states is lost at the exact moment the claim becomes durable and dated.** + +**And the mitigation depends on the defect.** §4 L223 is real and PENDING-121's III.4 missed it: *"Migration emits R0 files for steward review; it does not write into `chamber-library` unasked."* But **a steward reviewing 327 regions cannot re-verify them by hand** — that review is meaningful only if the emitted artifact distinguishes the three states, which it currently cannot. The safeguard is load-bearing and presently hollow. + +**Options.** +- **(a) Make §4 three-valued**, matching §3: a region no available instrument reaches is emitted `unverified` **and carries no fingerprint**. Supersession of the contract's §4 (engine spec-note, D-1). +- **(b) Fix `emit` only**, leaving §4's prose binary. ⚠ Code and contract then disagree — the drift this repo names as its own failure mode. +- **(c) Defer until migration is run.** ⚠ It is reachable only *at* emission, so deferring means discovering it by having already ratified a wrong fingerprint. + +**Recommendation: (a).** §3 is the ruled clause; §4 should implement it, not narrow it. Cheap **now** — **zero regions carry a fingerprint**, so nothing is retroactively wrong and the entire exposure is prospective. + +**Check that it worked — both directions.** Emit against Alexander: the five `front_matter` regions must come out **`unverified` with no `content_sha256`**, and the 253 name-landed patterns must come out distinguishably; neither may read as the other. ⚠ A control that only exhibits `stale` and `verified` **cannot detect this defect** and is the wrong instrument. + +**⚠ What this does not establish.** Three-valued emission does not make anyone act on `unverified`, and verifies no anchor. It preserves a distinction; the re-verification pass is separate work. + +**Files affected:** `~/_Dev/studium-engine/docs/spec/r0-reading-index-contract.md` §4; `~/_Dev/studium-engine/engine/reading_index.py` (`emit`). + +**Awaiting:** Steward authorization (D-1 lane). + +---