Place REVIEWED-136 and AMENDMENT 1 — the Tarbuckle gate, ruled

Steward act, 2026-09-09. Committed immediately after the deletion it authorizes,
because the asymmetry was the wrong way round: the corpus is gone and the entry
authorizing its removal existed only in a working tree.

REVIEWED-136 closes PENDING-162, replaces option 2 with the measure/verdict split,
and corrects three records. AMENDMENT 1 answers step 0 (the relay timestamp is
receipt, not authorship), records the read-before-placement deviation, withdraws
the jurist's inherited AMD-1 error, and adds conditions E, F and G.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TbXpZup4GGCbLBbRJ79KpM
This commit is contained in:
David F Glidden
2026-09-09 17:30:22 +02:00
co-authored by Claude Opus 5
parent 3d45e3abb2
commit 71226a42d4
+218
View File
@@ -2894,3 +2894,221 @@ instance.
amended. Then the standing-disclosure correction at point 7. Then the L934 near-instance filed amended. Then the standing-disclosure correction at point 7. Then the L934 near-instance filed
against PENDING-134 (b) as its sole datum. `ratio_A_to_B` returns for its own act under against PENDING-134 (b) as its sole datum. `ratio_A_to_B` returns for its own act under
condition 5. condition 5.
## REVIEWED-136 — PENDING-162 — The gate closes, the read is split rather than routed, and three records are corrected
**Date:** 2026-09-09
**Decision:** AUTHORIZED — PENDING-162 CLOSED. Option 1 confirmed and extended;
option 2 DECLINED as filed and replaced; option 3 remains severed to PENDING-168.
**Ruled by:** jurist (Claude.app), on substrate checks run by the executor and
reported with their controls.
**Authorized by:** steward, 2026-09-09. AMD 1 is not ratified retroactively; it is
superseded by this entry, which is the steward act the item never received.
**On AMENDMENT 1 — ADOPTED AND AMENDED.** Its substance is recorded here for the
first time: AMD 1 was placed in PENDING.md on 2026-08-27 and never entered
REVIEWED. That gap, not its content, is what this entry repairs.
⚠ **AMD 1's scope clause is superseded by events.** On 2026-09-01, in a
steward-prompted reconciliation, the executor aggregated `tarbuckle-rejects.jsonl`
and derived the population split, the 14-word rejection mode, the clustering, the
cap-of-11 counterfactual and the rate. Those figures were relayed to the steward
and the jurist; neither party raised condition 3.
**Not a breach of condition 3, and ESTABLISHED rather than assumed.** Verified
2026-09-09: every eligible rejected line matched against the session transcript in
raw and JSON-escaped form — 0 hits over a pool of 68, with a positive control
detecting exactly the two known 08-25 exposures and a negative control on a
same-day 1.6 MB transcript returning 0. The five commands run against the log were
aggregations. ⚠ Bound of the finding: both instruments read the same transcript,
which PENDING-169 §5a records as an incomplete census, and the probe's unit is the
exact string. **No verbatim line text was exposed in what the transcript persisted.**
**What was pre-empted is the INDEPENDENCE OF THE ARBITRATION, not the corpus** —
the figures were seen and reasoned about a week early by both AI parties.
⚠ **But the corpus is not clean either, and AMD 1 is wrong on a second clause.**
Two lines stand exposed, one per surface: the 11-word `wrap` line, and the 196-word
`invoked` line at 400 characters. AMD 1 held the invocation cap clean because
nobody had seen its evidence. Its most extreme single datum was displayed to the
steward on 2026-08-25.
**Disclosure therefore extends to all four findings, stated in that form:
pre-seen statistics; corpus exposed at two lines, one per surface.** No part of the
report may be presented as arbitrated from unseen evidence.
⚠ **The "seven hours" figure is FALSIFIED and REPLACED.** REVIEWED-128 records the
196-word rejection as known at the time of ruling; that entry is logged
`2026-08-25T17:06:12+0200`. The condition-3 relay is a single turn at
`2026-08-25T15:16:28Z` = 17:16:28 local, carrying the condition verbatim; the
breach is at `2026-08-25T19:49:52+0200`. **Interval: 2 h 33 min 24 s.** The clock
base is declared in the data, not inferred — the log's timestamps carry an explicit
`+0200`. The shorter reading is excluded: `3079c0d` is a batch session-wrap commit
over 7 files, so 19:45 does not date the placement. **PENDING-168's doctrine holds
at "hours, not weeks"; its stated number is corrected to 2 h 33 min.**
⚠ **Not claimed: that the condition went unrestated in the interval.** The probe
ran six needles, three of which occur in the relay itself — it is not blind to the
condition's own phrasing, and three turns matched in the window, none a
restatement. But all six derive from that single utterance, so a restatement in
other words would evade all of them. NOT ESTABLISHED at the level of paraphrase,
and not needed: the interval runs from placement, and a restatement would
strengthen the instance rather than shorten it.
**On option 2 — DECLINED as filed, and replaced.** Routing the whole read to a
non-executor buys nothing against disclosure contamination and costs the read's
cheapness. But the hazard option 2 reached for is real and is not the one AMD 1
answered: the executor is an interested party in three of the four findings.
PENDING-151 governs — no disclosure repairs that; only routing does. Therefore:
> The executor produces the measurements and does not deliver the verdicts. Rate,
> distribution and shape are reported as figures. "Scattered versus clustered",
> "is 6.7 s worth what wrap says", and any cap consequence are judgments reserved
> to the jurist and steward, in a later sitting.
**Condition A — the content-free statistics survive the deletion, with one
unconditional exception.** The log dies per REVIEWED-128 condition 2; the derived
counts do not — word-count distribution against cap, per-surface counts,
timestamps. Counting is not filing. ⚠ **But `why` is not content-free by
construction:** `echoes_soul()` returns `sorted(hit)[0]`, a literal n-gram from the
suppressed line — a 4-word run against the sample lines, a 6-word run against the
soul's prose. Every recital-class reason therefore embeds a verbatim fragment, at
both thresholds. **Reason strings are normalised to categories unconditionally for
that class, and the normalisation map is fixed and recorded BEFORE the read** —
after deletion the map is the only thing that makes the tallies auditable.
**Condition B — the disclosure is carried at the head of the report, not in a
footnote**, in the two-part form above. PENDING-167's independent provenance is
restated where any cap figure is reported, so no raise is later read as driven by
the pre-seen evidence.
**Condition C — the cap section reports `wrap` and `seam` separately.** Substrate,
2026-09-09: `tarbuckle-seam.py:124` and `tarbuckle-wrap.py:209` both call
`acceptable(line)` with no `max_words`, inheriting the mumble's 9. Rejections by
surface: `seam` n=1 at 10 words; `wrap` n=3, of which two at 11 words.
**PENDING-167 is aimed at the wrong file** — it changes `tarbuckle-seam.py` only
and would leave 9 where the ceiling pressure is. **PENDING-167 is HELD pending
re-scoping, not re-timing.** Its existing argument already reaches wrap without
amendment: a wrap is a threshold occasion on the same grounds a seam is.
⚠ `tarbuckle-wrap.py:236` holds a control asserting 12 words are rejected there; if
the cap moves, that control is **re-derived from what the surface is for, never
adjusted to pass.**
⚠ **And the file has no ruling history.** `tarbuckle-wrap.py`: 7 commits, all
2026-08-25, none since; **0 mentions in REVIEWED.md, 0 in PENDING-archive.md**, 2
in PENDING.md, neither about its cap. The surface carrying both ceiling rejections,
the 6.7 s blocking cost and the control coupling has never been named in a ruling.
That is why the misaiming survived two weeks: it was never in the register's
vocabulary.
**Condition D — the read is reported as a two-point series.** 69 entries carry
`t <= 2026-09-01`, which reconciles against the 59 reported in the 09-01 relay with
dates attached. The date partition must be built into the read: once the corpus is
deleted, 100 entries cannot be split by date again. This converts the early read
from a contamination into the better instrument — a growth rate, and a second
window against which the 08-28/30 clustering is tested rather than asserted.
**Holding PENDING-167 does not block deletion.** The re-scope needs `wrap n=3, two
at 11 words, one banned-token`, and the per-surface call-site facts. All of it
survives as normalised statistics under condition A. No part of it requires line
text. Recorded because the natural reading is the opposite, and retention by
omission is the failure this entry exists to prevent.
**Filed under PENDING-164's class — three ways the artifact differed from the
account the ruling was given.** REVIEWED-128 was told the log holds up to 200
characters of suppressed lines. It holds one entry at 400; it carries a per-recital
verbatim fragment in a field the description did not name. No breach of condition 1
— still rejections only — and the effect is nil. Recorded because the shape is the
one PENDING-164 reports.
**Filed as a datum for PENDING-89:** three parties, one shape, one sitting —
executor attending to the counter's unit and jurist to its populations on 09-01,
neither to the authorization; executor re-reading PENDING-178 on 09-09 without
recognising the 09-01 read; jurist accepting a single-source corroboration it had
itself labelled single-source, then over-generalising a probe defect from one
needle of six. **Each party stopped at the field it came for, and each error was
caught by a different party than the one that made it.**
**PENDING-169 §4 is RELEASED**, by this revisit occurring and not by a date. It
releases PENDING-166 and PENDING-167 from deferral only; it authorizes nothing else
in the running system. PENDING-166 executes; PENDING-167 is held per condition C.
**If AUTHORIZED:** Proceed to the read, once, under the split, with the
normalisation map recorded first. Bank the statistics, verify sufficiency, then
delete per REVIEWED-128 condition 2 and tag the commits REVIEWED-136. **The four
verdicts are reserved to a later sitting** and are not to be offered in the report.
If the sitting compresses, deletion is **deferred by recorded decision with a new
date**, never by omission.
## REVIEWED-136 — AMENDMENT 1 — Step 0's answer, a recorded deviation, AMD 1's third error, and two bounds on the deletion
**Date:** 2026-09-09
**Amends:** REVIEWED-136 (2026-09-09). Nothing above is rewritten; this is additive.
⚠ **Step 0, answered.** `2026-08-25T15:16:28.744Z` is a `type: user` / `role: user`
record in the Claude Code session transcript
`23b7a720-af1a-4479-a5ba-0c9b8fba5a7e.jsonl`, non-meta and non-sidechain — the
steward's message into the executor's session. **It is RECEIPT, not authorship.**
The clock starts when the bound party was told, which is what the doctrine requires,
and 2 h 33 min 24 s is a measured interval rather than an upper bound.
**Recorded deviation.** The read ran on 2026-09-09 before this entry was placed. The
split was honoured, no verdict was offered, and the substance is unaffected — but the
sequence is the shape this entry exists to correct: acting on a jurist view that has
not yet received the steward act. **This entry ratifies the read as conducted**,
explicitly rather than by silence.
⚠ **AMD 1 is wrong on a third clause, and this one has consequences.** It asserts the
seam cap was raised to twelve on 2026-08-27 and builds its provenance argument on that
act. The act did not occur: substrate 2026-09-09 shows `max_words` has never appeared
in `tarbuckle-seam.py` or `tarbuckle-wrap.py` in their entire git history, and no
commit has touched any surface file since 2026-08-26. Two register records disagreed —
AMD 1 in the past tense, PENDING-167 in the future — and the substrate settles it for
PENDING-167.
⚠ **The jurist's 2026-09-09 analysis inherited the error.** It reasoned that because
the raise had already happened on independent grounds, the seam datum was retrospective
and its contamination correspondingly reduced. **Both conclusions are withdrawn.** The
cap decision is live, undecided, and still exposed to the contaminated datum.
**Condition B — REPLACED.** The disclosure is carried at the head of the report in the
two-part form, and is **load-bearing rather than precautionary**: the cap decision it
protects has not been taken. It is restated wherever any cap figure appears. The
provenance sentence AMD 1 offered is struck; PENDING-167's reasoning stands as
reasoning for a proposal, which is what it is.
**Condition E — the corpus is non-stationary, and the record says so before it dies.**
Per-day 14-word rejections: 10, 11, 9, 10 across 08-28 → 09-01; 5 on 09-02; **none from
09-03 to 09-09.** Rejection rate 62.1% (W1) → 40.3% (W2). ⚠ Nothing in the net changed
— zero commits to any surface file since 2026-08-26. The 14-word pile-up that was the
entire evidence base for the cap question is absent from the second window. **No cap
judgment may be made from the pooled corpus.** Any cap reasoning names the window it
draws on. ⚠ For the verdicts sitting: an unchanged constraint with a changed output rate
invites "the generator improved", and the alternative — **the input distribution
changed** — is not excluded. Tarbuckle spawns in the cwd of whatever session it
decorates, across eight directories, at tick volumes ranging 99 to 370 in three days.
That confound lives in `tarbuckle-draws.jsonl` and `tarbuckle-invocations.jsonl`, which
are **not** under the deletion order.
**Condition F — the deletion is scoped in writing, and it is TWO files.**
`~/.claude/state/tarbuckle-rejects.jsonl` and
`claude/governance/tarbuckle-fortnight/rejects-snapshot-2026-09-09.jsonl`. The snapshot
is a verbatim copy of the corpus — leak-gated 2026-09-09 at 100 hits against 0 in every
other artifact — and committing it would defeat condition 2 permanently in git history.
**`tarbuckle-draws.jsonl` and `tarbuckle-invocations.jsonl` are NOT under the order**;
they carry no line text and hold the confound analysis. Byte-identity of live and
snapshot is re-verified immediately before removal; any tail logged in the interval is
re-normalised or discarded by recorded decision, never by silence.
⚠ **Condition G — the writer is stopped before the corpus is deleted.**
`log_rejection()` at `tarbuckle-mumble.py:123` opens the log in append mode, which
creates it if absent, so deleting the file retires this corpus and starts the next
one. **The writer is disabled in the same act as the deletion** — the write path is
made inert, not the file made absent. Deletion does not proceed on a live writer:
that would retire 101 entries into a successor accumulating under no condition,
which is condition 2's rationale defeated the moment it is honoured.
**What replaces it is NOT ruled here.** Whether rejection logging resumes, under
what bound, with what expiry and whose act — including whether counting can be made
structurally content-free at the point of write — is filed as open and is owed a
ruling before any write path is restored.