governance: record the kernel freeze in the Fool trial log
Hash, freeze commit, and axiom-source hashes recorded alongside the commit, since the file cannot contain its own hash. Also corrects the log's standing claim that soundness cannot be known by construction — unconditioned soundness cannot; operational soundness relative to a declared kernel can, which is what proof assistants have always done. Next arm named and not begun: reduction before generation, because reduction is the only arm that can falsify the kernel.
This commit is contained in:
@@ -57,7 +57,19 @@ The v1 Chamber (June–July 2025) ran written work past **two frontier models of
|
|||||||
|
|
||||||
*Still true after trial 03 — and more sharply than "unrun" conveys. **The false-positive control has never been designed, let alone run.** Trial 03 was carried in memory and in the session wrap as "the Fool's false-positive control", but its own pre-registration says it asks whether the checker shares the archive's self-exemption disposition, and its grading section states plainly that "the false-positive rate is still unmeasured". A false-positive control needs a **sound** document so that "nothing found" is the correct answer; trial 03's input was chosen with **five** pre-registered weaknesses precisely so that competence could be verified. The two are different experiments and were conflated in the record.*
|
*Still true after trial 03 — and more sharply than "unrun" conveys. **The false-positive control has never been designed, let alone run.** Trial 03 was carried in memory and in the session wrap as "the Fool's false-positive control", but its own pre-registration says it asks whether the checker shares the archive's self-exemption disposition, and its grading section states plainly that "the false-positive rate is still unmeasured". A false-positive control needs a **sound** document so that "nothing found" is the correct answer; trial 03's input was chosen with **five** pre-registered weaknesses precisely so that competence could be verified. The two are different experiments and were conflated in the record.*
|
||||||
|
|
||||||
*Designing it requires a decision not yet taken: what stands in for a sound document, given that soundness cannot be known? The candidates are a document that has already survived jurist review and steward placement, or a constructed one whose weaknesses are known to be absent. Until that is settled, no trial run can close this item.*
|
*Designing it required a decision, and it was taken on 2026-08-02 — on a corrected premise. I had written that soundness cannot be known by construction. The steward corrected it: **unconditioned** soundness cannot, but **operational** soundness relative to a declared axiomatic kernel is the standard move behind proof assistants and compiler semantics, and it is the same regress the central path already terminates by binding claims instead of certifying parties.*
|
||||||
|
|
||||||
|
### Control Kernel v1.0 — FROZEN 2026-08-02
|
||||||
|
|
||||||
|
**File:** `fool/CONTROL-KERNEL-v1.md` · **sha256** `67c9b870491db7444e98b680c7c80dcd99de376dda09b3e1758b27b1229ab045` · **freeze commit** `2e83b2c` · **axiom sources at freeze:** `~/CLAUDE.md` `dac3f1a3…`, `~/REVIEWED.md` `304852a8…`
|
||||||
|
|
||||||
|
Defines soundness **relative to the assumptions prompt and a declared axiom set** — not in general. Every sentence typed `D`/`Q`/`A`/`N`/`X`; sound iff every sentence is tagged and every `Q` resolves verbatim; tags stripped before the model sees anything, byte-verified, so the control cannot be passed by tag-matching without reading. Two rules were paid for in evidence: **no limitations section** (trial 03 — Qwen found Part VII, called it author-named limitation, and skipped it wholesale), and **one primitive per sentence**, where a blend the model catches **voids the document** rather than counting as a false positive.
|
||||||
|
|
||||||
|
**Trusted base, stated rather than buried (§4):** five judgement residues — whether a `D` demonstrates and rests only on axioms or earlier `D`/`Q`; whether an `N` is truly non-load-bearing; whether an `X` truly asserts nothing; whether a `Q` is used within its source's scope; whether a sentence carries one primitive. **All five run the same direction — each is a way for the author to make a document look sound.** That one-directionality is the property under watch; a residue running the other way would be a finding.
|
||||||
|
|
||||||
|
**Provenance of the review, and its cost.** Steward review supplied three structural findings — tag co-occurrence, transitive assumption creep, rhetorical presupposition in `X` — all adopted; applying them surfaced a fourth the executor had missed (`Q` scope-of-use, the defect the jurist caught on 2026-07-19). The review materially improved the kernel and thereby **coupled the steward to it**, a cost priced in advance when the ordering was agreed. **§6.2's adversarial falsifier therefore falls to a third party — the jurist or a differently-formed model — not to the steward.**
|
||||||
|
|
||||||
|
**Next, and not yet begun:** the reduction arm. Reduce one real governance package to kernel form under non-destructive quarantine, gated by byte-identical reconstruction. It runs before the synthetic arm because it is the only arm that can **falsify** the kernel; a generated corpus can only ratify it. No model run until it passes.
|
||||||
|
|
||||||
## Grading caveat, standing
|
## Grading caveat, standing
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user