From 90dc0f7373da8e6e02b1ef70d130b27fcde8dffc Mon Sep 17 00:00:00 2001 From: David F Glidden Date: Sat, 8 Aug 2026 21:05:15 +0200 Subject: [PATCH] [HARDENING] Close PENDING-82 and -118; mark 119/120/123 BUILT MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit 82 is discharged by events. Its 2026-07-28 substrate check said there was no mcpServers key; today the config carries mcpServers: governance, and the jurist used the tools in three consecutive rulings — opening graduation-spec directly and refusing to rule from my summary, which is the capability the item existed to create. Two residuals carried, not buried: the read enum reaches neither the runbook nor the R0 contract, and the installed surface has 8 keys and a search tool the description does not name. 118 is built, and building it REFUTED the option I had recommended. I wrote that the checker already parses the archive format. It does not — the marker is an HTML comment and there are zero in either register file; their deferrals are prose, 53 and 26. Widening alone would have scanned two more files, found nothing and reported clean: a silent net built to close a blind spot, which is the failure the item was filed to describe. So the widening ships with its limit in its own output — prose deferrals counted and reported un-machine-readable, never as absent, with counting explicitly not classifying. The census stays owed. 119/120/123 marked BUILT with their commits so the built-vs-ruled checker sees them; all three were already ruled, so this closes a reporting gap, not an authorization one. Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_01A35wiD55yRHj5U1ECZAX4t --- PENDING.md | 45 +++++- REVIEWED.md | 260 +++++++++++++++++++++++++++++- scripts/governance-drift-check.py | 32 ++++ 3 files changed, 331 insertions(+), 6 deletions(-) diff --git a/PENDING.md b/PENDING.md index 406cd03..c0ebfb2 100644 --- a/PENDING.md +++ b/PENDING.md @@ -496,7 +496,19 @@ Merge that `mcpServers` key into `~/Library/Application Support/Claude/claude_de Delete the Cowork party entry and every reference to `COWORK.md`. Grounds, now two: a third executor costs a third doctrine copy of a document that is `CLAUDE.md` with the nouns changed; and Cowork could not have served as the jurist's filesystem eyes even in principle, since `coworkUserFilesPath` points at `~/Claude`, which does not exist, and remote Cowork — the incoming default — runs no local MCP at all. **Files affected:** new `~/dotfiles/scripts/governance-mcp.py`; `~/dotfiles/scripts/wake-digest.py` (`item_spans()` fence-awareness + 3 controls). Awaiting steward hand: `claude_desktop_config.json`, Claude.app §Your Role and §Standing Context. -**Awaiting:** Steward authorization to install the `mcpServers` key. The server itself is inert until then — nothing loads it. +**Awaiting:** ~~Steward authorization to install~~ → **INSTALLED AND IN USE. CLOSED 2026-08-08.** + +--- + +### AMENDMENT 1 — 2026-08-08, discharged by events; the item's substrate check is stale + +**§A — INSTALLED.** The item's 2026-07-28 substrate check recorded *"`claude_desktop_config.json` has **no `mcpServers` key**"*. Verified today: top-level keys are **`mcpServers`, `coworkUserFilesPath`, `preferences`**, and `mcpServers` contains **`governance`**. The gate this item waited on has been passed. + +**§B — And it is not merely installed, it is LOAD-BEARING.** Empirically, in a single day: the jurist used `governance_read`, `governance_item`, `governance_search` and `governance_state` across **three consecutive rulings**, opened `graduation-spec.yaml` L1–60 directly, and **refused to rule from the executor's summary** — *"ruling from the executor's summary of its own mandate is exactly the shape I should refuse."* That refusal is the capability this item existed to create, exercised. It also caught, from substrate the executor had quoted, an adverse ratified ruling the executor had missed (REVIEWED-53). + +**§C — ⚠ Two residuals, carried not buried.** (1) **The `governance_read` enum does not reach everything a ruling may rest on** — `conversion-runbook.yaml` and the R0 contract are reachable by **no key**, and one ruling had a leg in executor testimony until the steward relayed the files by hand. The remedy is its own extension mechanism: **the server takes keys from a list, so extending the list is the fix.** Recorded in this item's earlier amendment; it survives this closure as a **named follow-on**, not a reason to hold the item open. (2) The installed surface differs from the description above — **8 keys, not "six enumerated documents"**, and a `governance_search` tool the five-tool list does not name. The description is stale; the substrate is authoritative. + +**Closed:** the proposal was to build and install a read-only substrate interface for the jurist. It is built, installed, used, and has demonstrably changed rulings. What remains is a **bounded extension of an existing, working thing**, which is a different item. ### AMENDMENT — 2026-08-08, a concrete enum, from a ruling that hit the wall @@ -1683,7 +1695,30 @@ This is harmless today only because voice ⟺ source: measured, **max distinct v **Files affected:** `~/dotfiles/scripts/governance-drift-check.py`; a one-time census artifact (home to be decided with the ruling). -**Awaiting:** Steward authorization. +**Awaiting:** ~~Steward authorization.~~ → **BUILT 2026-08-08, `see dotfiles HEAD`. ⚠ AND THE ITEM'S OWN OPTION (1) IS REFUTED BY BUILDING IT.** + +--- + +### AMENDMENT 1 — 2026-08-08, built — and option (1) rested on a false premise about the format + +**§A — ⚠ MY OPTION (1) WAS WRONG, and building it is what showed that.** I wrote: *"Widen the scan to `~/PENDING-archive.md`. Smallest change; **the checker already parses that exact format.**"* **It does not.** The structured marker is an HTML comment — `` — and there are **ZERO** of those in `PENDING.md` **or** in `PENDING-archive.md`. Measured 2026-08-08. Their deferrals are **prose**: **53** occurrences of `defer*` in `PENDING.md`, **26** in the archive. + +**⇒ Widening alone would have scanned two more files, found nothing, and reported clean** — *a silent net, built to close a blind spot.* That is precisely the failure class this item was filed to describe, and I had specified it as the remedy. + +**§B — So the widening ships WITH its own limit stated in the output.** Structured blocks are now found anywhere in the register; prose deferrals are **counted and reported as un-machine-readable, never as absent**: + +``` +✓ deferred decisions: 2 tracked, none due (2 checkable, 0 manual-only) + ⚠ plus 79 PROSE deferral mention(s) in the register (PENDING.md 53, PENDING-archive.md 26) — these carry no + DEFERRED-DECISION block, so NO trigger is machine-checkable for any of them. + Counted, not classified. Whether any condition has fired is unestablished. +``` + +⚠ **Counting is not classifying.** 79 is an upper bound on candidates, not a count of deferrals — the regex matches any use of the word. **How many carry a condition, and how many of those have fired, is a READING task** and is reported as unestablished rather than skipped. That is the honest version of what option (2)'s census asked for, and the census itself remains **owed**. + +**§C — Three controls added**, per the script's standard: the prose counter fires on a known-present phrase, stays silent on unrelated text, and the register files are provably inside the widened scan. + +**§D — What this closes, and what it does not.** **Closes:** the checker no longer reads only `docs/**` — a structured deferral filed anywhere in the register is now seen, and the register's prose deferrals are **visible as a named unknown** instead of invisible. **Does not close:** the classification. The item's own ⚠ said *"size unmeasured, deliberately"*; it is now **bounded and still unclassified**, which is a better state and not the finished one. --- @@ -1730,7 +1765,7 @@ This is harmless today only because voice ⟺ source: measured, **max distinct v **§D — CONDITION ON (i): declare the cost threshold now, with its action.** `0.218 s over 14 sources` is honest about being burst-sized; (e) is unconditional and scales with sources × file size. **When it exceeds ~1 s, (e) re-scopes or hands off to (a)'s scheduled job.** Stated now because *a per-commit cost that grows unremarked converts a tripwire into a `--no-verify` habit* — this thread's own failure class arriving by the back door. -**Awaiting:** placement of the ruling. Build on placement: one line in `.precommit-triggers`, the §D threshold recorded beside it, tagged REVIEWED-N. +**Awaiting:** ~~placement of the ruling~~ → **BUILT 2026-08-08, `2534dfb`** under REVIEWED-102. One line in `.precommit-triggers` (`. | python3 engine/ingest_gate.py --check-only`), unconditional, with the §D cost threshold recorded beside it. Acceptance: both rules fire in declared order, cheapest first. --- @@ -1782,7 +1817,7 @@ So the pathspec was **not silence — it was a cost commitment inside the author **§D — Interaction with PENDING-119, if both land.** `.precommit-triggers` would carry two lines with overlapping paths; an engine commit pays ~2 s (fleet) + 0.218 s (binding). **Declare the order in the file** so a red is attributable to one check without reading both. -**Awaiting:** placement of the ruling. +**Awaiting:** ~~placement of the ruling~~ → **BUILT 2026-08-08, `2534dfb`** under REVIEWED-103. Pathspec widened to `corpus/ engine/ tests/ scripts/run-fleet.sh`. Acceptance decomposed per condition 2: `eecc8bb` replayed (both files match); red direction refuses — **fixture SYNTHETIC and labelled**, no real red `engine/` commit exists in 24 candidates; docs-only runs no suite. --- @@ -2043,7 +2078,7 @@ Three cases, all discriminated: a rule ran → existing output already says so, **§E — Related doctrine, filed as PENDING-124.** This item's *"needs a third state, not a pass or a fail"* and PENDING-122's `cannot-assess` are one finding reached twice in one day. -**Awaiting:** placement of the ruling. **Build order on placement: 123 → 119(i) → 120(a).** +**Awaiting:** ~~placement of the ruling~~ → **BUILT 2026-08-08, `448ce37`** under REVIEWED-105, first in the ruled order. (b)+(e): malformed declarations refuse with file/line/fault/`--no-verify`; a triggers file declaring nothing reports itself unguarded; the per-rule line prints in exactly the ambiguous case. Matched-rule output byte-identical. All seven table rows non-silent. --- diff --git a/REVIEWED.md b/REVIEWED.md index aebef04..b596f49 100644 --- a/REVIEWED.md +++ b/REVIEWED.md @@ -1293,4 +1293,262 @@ blocks without saying why is replaced by habit within a week. 4. SEQUENCING across the four open items: land 123 before 119(i) and 120(a). Both add lines to .precommit-triggers; a validator that catches a malformed line should exist before the file grows. In the other order, the first thing to test the new declarations is the declarations themselves. -**If AUTHORIZED:** Proceed with (b) + (e). Build order: REVIEWED-105 → REVIEWED-102 (i) → REVIEWED-103 (a). Tag commits with REVIEWED-105. \ No newline at end of file +**If AUTHORIZED:** Proceed with (b) + (e). Build order: REVIEWED-105 → REVIEWED-102 (i) → REVIEWED-103 (a). Tag commits with REVIEWED-105. + +## REVIEWED-106 — PENDING-124 — A check whose subject can be absent cannot be two-valued +**Date:** 2026-08-08 +**Decision:** DESIGN GATE PASSED WITH CONDITIONS. Q1 applied, not extended — no constitutional change, no [ESCALATE]. Landing: one ladder entry. +Five conditions, none changing the doctrine's substance; three changing what is recorded about its basis. +**Stores:** claude-md L251-257, REVIEWED-104, REVIEWED-105, PENDING-124 verbatim via the governance tools. R0 §3 verified directly against the +sha-matched contract (db39a503…, L180), so I.4 is substrate for this jurist, not testimony — the package's front-matter was true two turns ago and +is now false. + +1. Q1 APPLIED. Constraint 4 has two clauses. The contrary reading engages only the second; the first speaks of limits, not failures, and "I could +not look" is a limit. The executor overstated its own uncertainty here, and deserves to know the replacement is firm. + +2. CONDITION 1 — the quote-verification pass gains its own third state before it is relied on again. It reported verified on a normalized +reconstruction of REVIEWED-104, which had also dropped the sentence answering the package's own Q2. A two-valued verifier inside a package arguing +for three-valued verifiers. This is also a tenth instance, and the only one in the set independent of the advisory that proposed the doctrine — +produced by the gate, not the proposal. + +3. CONDITION 2 — the ladder entry names the attested-absence family and cites the 2026-07-05 ruling (REVIEWED-47), so it joins a lineage rather +than standing as an orphan under a constitutional clause. + +4. CONDITION 3 — the evidence statement is corrected before placement: two pre-existing instances of the shape, three of the adjacent principle, +one found at the gate. The uncorrected "five … same shape" would have been inherited as load-bearing. + +5. CONDITION 4 — III.1 carries the environment-vs-defect split in the normative statement, not only in the consequence-trace. CONDITION 5 — landing +as leaned: one named instrument on reference-verification-ladder.md, nothing in ~/CLAUDE.md. + +6. Q2 binds at reporting AND aggregation; the aggregation half is already ruled by REVIEWED-104 §1's closing sentence. Q3 names left free, with the +ratified test recorded: one name per referent, not one per concept. Q4 ratify not provisional, and not on the count — four of nine instances are +downstream of the advisory that proposed the doctrine; the chamber census is owed, not blocking. + +**If AUTHORIZED:** Conditions 1-5 are discharged as of 2026-08-08. Tag with REVIEWED-106. + +## REVIEWED-107 — PENDING-125 — A live false attestation in the governed record: Mauss's reading_index_status +**Date:** 2026-08-08 +**Decision:** AUTHORIZED — option (a). D-1 lane, authorized verbally; RECORDED RETROSPECTIVELY, after the build. +**Notes:** (a) and (b) are different acts and were correctly separated. Correcting the field stops the record asserting something false today and +needs no ruling; re-anchoring the index is curatorial work that must carry the ladder's re-anchor = re-verify discipline, since re-anchoring +without re-verifying is what produced this class. (b) remains open. + +1. Built as 8231bce. reading_index_status VERIFIED-BOUND → SHA-STALE, bounded to one field, shas untouched, manifest re-parses at 14 sources. + +2. The executor checked the sub-question it had flagged before choosing a value, and the answer changed the entry: the vocabulary is UNDEFINED. +Three tokens in use across the manifest, no definition anywhere in either repo, every external mention prose about this defect rather than a +specification. SHA-STALE is therefore a fourth undefined token, added because none of the three could state the truth, and recorded as a known cost +rather than minted quietly. + +3. Noted: the commit was the trigger mechanism's first real corpus exercise — both declared rules fired, fleet green, not a probe. + +**If AUTHORIZED:** Tag with REVIEWED-107. (b) stays open under PENDING-125. + +## REVIEWED-108 — PENDING-126 — Two holes in the fleet, and the census that followed +**Date:** 2026-08-08 +**Decision:** AUTHORIZED — options (a) then (c). D-1 lane, authorized verbally; RECORDED RETROSPECTIVELY, after the build. +**Notes:** Merged with PENDING-122 on the executor's argument that they are one subject with overlapping files, and that hole 2 was a prerequisite +for verifying 122 — while suites raise, cannot-assess cannot be told from red. The merge was right. + +1. (a) built as 8ff5a9f. Hole 1: close_ranges' section_end bound guarded, both branches; discriminating negative run — bound removed → two named +failures citing 499 and 400, restored → 47/47. Hole 2 was THREE sites, not the one filed; fixed as a class. An induced citability break went from a +single StopIteration traceback to seven named failures. + +2. (c) the census, done, and it renamed the class. Crash-rather-than-name: 3 of 7 suites under 3 triggers, origin suite-side direct access. The +unguarded-rule question is unanswerable by inspection — token-mention said 13 of 13 touched, which is worthless since hole 1 lived in a touched +clause. Mutation: 4 of 7 caught, and all 3 survivors verified EQUIVALENT on current data by sentinel and by positive control. So hole 1 was never +an unguarded rule; it was a guard the live corpus cannot exercise, and three more of that shape exist in R0 alone. Latent, not wrong. + +3. The crash class then closed at the preflight rather than at six sites (d21a43b), on the ground that all six depend on one invariant. Closing the +six revealed two more under a fourth degraded state, in suites the census had cleared: 6 → 8. The eighth originates in ENGINE code (retrieve.py +_work_map) and was deliberately not fixed by a test-side patch; whether retrieve() should degrade rather than raise is filed as an engine question +rather than hidden. + +4. Final census, five degraded states: zero crashes, against 3/3/0/3 before. + +5. ⚠ Recorded as owed, not blocking: the census covered R0's clauses only. n0/n1/v0/v1/cluster-a are unmutated and their escape rate is unknown, +not zero. + +**If AUTHORIZED:** Tag with REVIEWED-108. + +## REVIEWED-109 — PENDING-127 — R0 §4 emits two states where §3 rules three +**Date:** 2026-08-08 +**Decision:** AUTHORIZED — option (a). D-1 lane, authorized verbally; RECORDED RETROSPECTIVELY, after the build. +**Notes:** The item said §4 was binary against §3's three states. It was worse: the CODE was unary. emit promoted baseline_sha256 to content_sha256 +on every region — 261 of 261 for Alexander, including regions no instrument had verified — under a hardcoded date. Three different answers lived +in one contract and one module. + +1. Built as ccc4d6c. Contract v0.1 → v0.2, superseded sentence preserved in place. Suite 31 → 44. Fleet 7/7. + +2. The fix goes further than (a) asked, on the item's own logic, and that is ratified: a content_sha256 attests the whole span while name-landing +is evidence about the anchor's first line, so recording the former because the latter held promotes a weaker claim into a stronger one — the +PENDING-47 shape. Emission now records NO new fingerprints; one enters only through an attested re-verification. This is what makes PENDING-121 +condition 4 reachable rather than aspirational. + +3. State determination is now one function called by validate and emit, which had silently disagreed — §3's own "one mechanism with two call sites" +applied to the module's interior. + +4. ⚠ The acceptance fixture named in the item was STALE, and measuring corrected it. Alexander's five front_matter anchors were partitioned out on +2026-08-07; Alexander is 261/261 name-landing with zero unverified. The real unverified population is Mauss 23 and after-the-reply 33. The +discriminating pair is therefore Alexander against Mauss — two real artifacts, a better control than the one specified. stale is unreachable from +live data and its control is labelled synthetic. + +5. One pre-existing check went red and was replaced rather than deleted: it asserted the promotion this item rules a defect. A test that pinned the +old contract is evidence of what the contract used to say. + +**If AUTHORIZED:** Tag with REVIEWED-109. + +## REVIEWED-110 — PENDING-121 — engine_source_binding: prose to declared surfaces, and the fingerprint specified but never recorded +**Date:** 2026-08-08 (design gate 2026-08-08; two follow-on passes same day) · placed retrospectively +**Decision:** DESIGN GATE PASSED WITH CONDITIONS (1-4), then HELD OPEN for a redraft of Part IV.2 after substrate +verification. The redraft is filed (item Amendment 3 §D) and is NOT gated by this entry. Placement gate outstanding, +jointly with PENDING-128. +**Stores:** REVIEWED-101, REVIEWED-53, REVIEWED-47, PENDING-121, PENDING-119, PENDING-120, PENDING-47 verbatim via the +governance tools; graduation-spec.yaml L1-60 via governance_read. conversion-runbook.yaml and the R0 contract were +unreachable at the time of ruling and were read only after the steward supplied them, sha-matched against the request's +table (fffeed86…, db39a503…). engine/reading_index.py was never read by the jurist: condition 4 was ruled +prophylactically and REVIEWED-109 later found the code unary, which is worse than the item claimed. +governance_state() timed out; no drift count or repo status informed this ruling. + +1. AN ADVERSE RATIFIED RULING WAS MISSING FROM THE GROUNDING PASS. REVIEWED-53 kept engine_source_binding as ONE entry — +'names a relationship across three files that move together; fragmenting recreates the failure' — and the package +proposed five siblings. REVIEWED-101 condition 1 did not cite it either: two rulings from one lane pointing opposite +ways, neither aware of the other. Treated as a verification trigger, not a precedence call. Resolution: the entry stays +ONE, surfaces become addressable members, and the co-movement invariant becomes declared data rather than why: prose — +because prose is what this amendment establishes no consumer reads. + +2. CONDITIONS IN FORCE. (1) co-movement declared, a consumer verifying a proper subset reports incomplete never clean — +and this collapses with IV.1 para 2 into one requirement, drafted once. (2) resolve scope, then DERIVE the enumeration +from the runbook's list plus the per-region surface, justifying every omission; never compose afresh. (3) no dated counts +in declared data — locators and semantics only, population computed at read time; unverified-by-construction survives +only as a rule, since a rule does not go stale and a count does. (4) the promotion rule is REVIEWED-47 applied, not new +normative text: reuse the ratified by/against/result attestation shape under the single shared guard, reducing the +constitutional change to one requirement. + +3. Q1 — the zero-evidence surface is CARRIED, never omitted, and the stronger form is adopted. The marking is not what +prevents the Part V inversion; not computing a heterogeneous aggregate is. Report per surface; any derived aggregate +reports unverified when a member is unpopulated or unchecked. Two discriminations required: the drift signal must be +separable from the unverified signal, or the check becomes a constant nobody reads; and '271 verified' must never +surface unqualified, since R0 §3 holds name-landing insufficient. + +4. Q2 — reading_index_status is NOT a binding surface and NOT evidence, and no consumer of this enumeration may read it +as such. Retention, demotion or retirement is the engine's lane, D-1, and a chamber spec ruling an engine field's fate +would exceed standing. STRENGTHENED after ruling by REVIEWED-107 §2: the vocabulary is undefined — three tokens in use, +no definition in either repo — which is a cleaner ground than the one given here. Recorded as owed and unowned: SHA-STALE +is now a fourth undefined token and no open item covers defining the vocabulary. + +5. Q3 — REVISED against my own lean, and the revision is the more useful half. The enumeration is not incomplete but NOT +COMPLETABLE: the runbook's scope_note sets membership as any repo the engine manifest binds, and the runbook's own list +was found short by its own grep on 2026-07-19. So the spec is authoritative for SEMANTICS and the runbook's grep for +COMPLETENESS — two claims, two homes, not the fault condition 1 forbids. My original 'single enumerative authority' is +withdrawn: it would have demoted the only instrument that has ever caught a missing surface. + +6. Q4 — refinement of the hash-locality principle's third instance, not a fourth. Same referent class, same home, finer +granularity, and REVIEWED-53's individuating reason (files that move together) covers it. The ratified sentence stands +untouched. TEST RECORDED, because the count is maintained by ruling and went 2 to 3 through REVIEWED-53: a future surface +introducing a NEW HOME amends it; one refining an existing home does not. + +7. Q5 / Q6 — RENAME, not rescope in place. The voice_manifest incident that created this entry was a name inviting a +wrong generalization; rescoping with a scope: field would be the same remedy a second time in the same block for the same +failure mode. The ratified principle is NOT amended: L19 and L39-40 update as mechanical referring-name edits under +REVIEWED-53's own lane rule for machine-data, with both reading grains preserved at the new name. REVIEWED.md L471 is not +edited — a ruling records what it ruled. Name: canonical_binding, NOT canonical_binding_surface, which contains +binding_surface and would have made the runbook's own key un-greppable through the instrument built to prevent that. +Completion control required both directions: before, the search finds the known occurrences; after, zero hits on the old +name outside REVIEWED.md, excluded BY NAME in the command. + +8. SUBSTRATE VERIFICATION. Both supplied files matched their declared shas and line counts, so the anchors held. +Condition 2 leg (a) verified without the runbook — a key named engine already housed chamber artifacts in the executor's +own draft. Leg (b) verified: catalogue.yaml at runbook L251. Two findings the package did not carry: the manifest binds +THREE repos, not two (five after-the-reply sources are ARC, hard-coded to chamber paths in the draft), and R0 §4 L223-225 +is binary against §3 L180's collapse prohibition — split out as PENDING-127, since the chamber requirement was unmeetable +while it stood. Now closed as REVIEWED-109, which found the code unary and 261 of 261 regions promoted under a hardcoded +date. + +9. TWO SURFACES ADDED AFTER VERIFICATION. chamber-catalogue, and engine-sidecar-region — R0 §3 rules the two per-region +gaps are one mechanism with two call sites, so enumerating only the reading index would have hard-coded that divergence +into declared data. + +10. SPLITS AND COUPLING. PENDING-125 (Mauss, condition 5a) — a live false claim 53 days old must not die inside a +deferred PROPOSAL; now REVIEWED-107(a), with (b) open. PENDING-127 — now REVIEWED-109. PENDING-128 — REVIEWED-53's +deferred option (c), recorded as live again on the reasoning that carried Q6 and to be RULED jointly with this item. Its +landing was made conditional rather than fixed: PENDING-127 clearing selects a single commit for both, and REVIEWED-109 +has cleared it, so the single commit obtains. + +11. SUPERSEDED EXAMPLE, flagged so it is not inherited. The item's design question cites Alexander's five stale +front_matter anchors; REVIEWED-109 §4 records they were partitioned out on 2026-08-07 and that Alexander is 261/261 with +zero unverified. The hazard is confirmed and larger, not weakened. Cite the 261/261 unconditional promotion. + +12. ON THE GROUNDING PASS. Five omissions across three passes, every substantive one understating the gap the executor +was arguing for — the executor's own reading, accepted: passages stating the problem were quoted, passages stating its +extent were skipped, and four of five were extent-passages. Not selective; systematic in kind. + +13. THE VERBATIM FILED RULING IS SUPERSEDED IN FOUR PLACES AND CARRIES NO MARKER. engine-source-binding-surfaces-JURIST-RULING-2026-08-08.md is the first pass only: its Stores line says the three files were NOT read and Parts I.1-I.4 are testimony (they were later read and sha-matched); its Q3 under 2(i) asserts the 'single enumerative authority' holding this entry withdraws at point 5; its condition 2 leaves the branch open (the steward chose (i)); and its §4 cites Alexander's five front_matter anchors, partitioned out 2026-08-07 per REVIEWED-109 §4. It is also the only verbatim jurist text in chamber docs/, and it contains no Q5 or Q6 — the rename holding PENDING-128 stands on exists there not at all. CONDITION: a supersession header at its top pointing to this entry, and to the two later passes, before either is relied on again. The document +is not edited below the header — a filed ruling records what was ruled when. + +**If AUTHORIZED:** Conditions 1-4 stand as discharged in the Amendment 3 §D redraft, which is filed and awaiting the +placement gate — that gate is NOT granted by this entry and requires the redrafted canonical_binding block itself, not +its description. Rule jointly with PENDING-128; land in one commit per point 10. Tag with REVIEWED-110. + +## REVIEWED-111 — PENDING-128 — REVIEWED-53's deferred option (c): kill the manifest shared word +**Date:** 2026-08-08 +**Decision:** DESIGN GATE PASSED on option (a); (c) rejected. Ruled jointly with PENDING-121 per §Coupling. The +same-commit requirement is NARROWED, not adopted as filed. Three conditions. +**Stores:** PENDING-128, PENDING-121 (incl. Amendments 1-3), REVIEWED-53, REVIEWED-107, REVIEWED-109 verbatim via the +governance tools; graduation-spec.yaml L1-60 via governance_read. The shared-name collision log is reachable by no key +and is executor testimony; it carries no weight here. Numbering assumes this follows REVIEWED-110 (PENDING-121). + +1. 1. RULED TOGETHER: YES, and the ground is REVIEWED-53's own text, not an unplaced holding. REVIEWED-53 judged (c) doctrinally complete and deferred it on occasion — 'out of scope for a doc-gap patch' — and PENDING-121 is a PROPOSAL that opens the same block deliberately, so the occasion has arrived. The parallel rename ruling is REVIEWED-110 §7; cite that, not 'PENDING-121's +Q6', which appears in no placed or verbatim-filed record. Renaming one key because names must not mislead, while leaving its neighbour in the same block warned-around on the same ground, is incoherent. Neither is ruled without the other. ORDERING CONSEQUENCE: REVIEWED-110 must be placed before or with this entry, or point 1 cites forward into nothing. + +2. SAME COMMIT: CONDITIONALLY, AND NARROWED. The conditional filed against PENDING-127 has resolved — REVIEWED-109 +cleared it — so a single commit obtains. But PENDING-121 lands in TWO places: the mechanism in graduation-spec.yaml +declared data, and the requirement in the constitution, MINOR bump by supersession. PENDING-128 is pure machine-data. +Read as binding 128 to all of 121's landing, a machine-data rename would ride inside a constitutional supersession, and +reverting the requirement would revert the rename — the revertability cost the conditional existed to avoid, returning +through the door the blockage just left. RULED: the coupling binds PENDING-128 to PENDING-121's DECLARED-DATA landing — +the layers: block commit — and not to its constitutional landing. §Coupling's own reason (same block, L19 cross-references +L20 by name) supports exactly this scope and no more. + +3. OPTION (a) PASSES. Rename kills the collision. The executor's ground for recommending (a) and not (c) is affirmed: +retiring a ratified safeguard should be its own decision with its own evidence, not a tidy-up riding on a rename. + +4. OPTION (c) REJECTED, and REVIEWED-107 strengthens the rejection. Retiring the warning rests on 'the name is now +unambiguous', which is the assumption whose failure created this entry. REVIEWED-53 chose two reading grains +deliberately. Both stay. Retiring a reading grain in a corpus just shown to mint undefined tokens is the wrong direction. + +5. CONDITION 1 — THE WARNING'S TEXT IS REWRITTEN, NOT MERELY KEPT. The item says keep the warning and does not notice +that the rename changes what the warning is about. L19 currently warns that the word manifest names two different engine +objects; after the rename the chamber side no longer carries that word, so the warning as written describes a collision +that no longer exists at the site where it is printed. A kept-verbatim warning would be a stale safeguard — the shape +this register keeps ruling against, arriving through a change made to improve clarity. Rewrite both grains to say what +they now need to say: that the engine's SOURCE manifest binds by hash and is a different object, and that a reader +arriving from an older citation of voice_manifest has reached the right entry. Preserving a safeguard means preserving +its function, not its bytes. + +6. CONDITION 2 — THE NEW TERM IS DEFINED WHERE IT IS INTRODUCED, IN THE SAME ACT. REVIEWED-107 §2 found +reading_index_status's vocabulary undefined — three tokens in use, no definition in either repo — and a fourth minted to +state a truth none of the three could. That is a demonstrated corpus tendency to introduce terms without definitions and +notice later. voice_personification is drawn from the entry's own prose; if personification is undefined at its site, the +rename trades a documented collision for an undefined term, which is worse than the status quo, since the collision at +least carried a warning. The definition goes in the rewritten grains of condition 1 — one act, not two. + +7. CONDITION 3 — THE COMPLETION CONTROL RUNS IN ONE INVOCATION, WITH A POSITIVE CONTROL. The item requires zero hits on +the old name outside REVIEWED.md, and separately that the L19-L20 cross-reference still resolves in both directions. Run +apart, the first is satisfiable by DELETING the cross-reference: the negative result passes precisely because the subject +was removed. RULED: both run together, with resolves-at-new-names serving as the positive control for the zero-hits +check. This hole opens only under a single commit, where the cross-reference becomes rewritable on both sides at once. + +8. NAME. voice_personification passes the substring test against binding_surface-class hazards. Recorded as neutral, not +an improvement: graduation-spec.yaml carries voice as a frontmatter optional field in the same file, so a search for +voice cannot isolate the frontmatter field from the layer key, before or after. The item's claim to be 'the first +retired rather than warned around' should not be read as clearing the file of voice-family entanglement. + +9. UNVERIFIED, and carrying no weight. The shared-name collision log, and therefore 'the ninth such case'. Reachable by +no governance_read key. The ground for (a) is REVIEWED-53's own text, which was read. + +10. NOT RULED HERE. The census of the other eight collisions, which the item correctly declines to propose. Whether +REVIEWED.md L471 is touched — it is not; a ruling records what it ruled. + +**If AUTHORIZED:** Land option (a) with conditions 1-3, in PENDING-121's declared-data commit per point 2, not in its +constitutional supersession. Tag with REVIEWED-111. \ No newline at end of file diff --git a/scripts/governance-drift-check.py b/scripts/governance-drift-check.py index b5e939b..15f0d4b 100755 --- a/scripts/governance-drift-check.py +++ b/scripts/governance-drift-check.py @@ -335,6 +335,21 @@ def trigger_fired(d: dict) -> bool | None: _scan_targets = [(r, "*/docs/**/*.md") for r in SCAN_ROOTS] + EXTRA_SCAN_GLOBS + +# PENDING-118, and the item's own option (1) is REFUTED by building it. +# The item said "widen the scan to ~/PENDING-archive.md — the checker already parses +# that exact format." It does not. The structured marker is an HTML comment +# , and there are ZERO of those in PENDING.md or in +# the archive. Their deferrals are PROSE — measured 2026-08-08: 53 and 26 occurrences of +# "defer*". Widening alone would scan two more files, find nothing, and report clean: +# a silent net built to close a blind spot, which is the failure this item describes. +# +# So the widening ships WITH its own honest limit. Structured blocks anywhere are now +# found; prose deferrals are COUNTED and reported as un-machine-readable, never as +# absent. Counting is not classifying — how many of those conditions have fired is a +# READING task, and it is reported as owed rather than silently skipped. +_scan_targets += [(HOME / "dotfiles", "PENDING.md"), (HOME / "dotfiles", "PENDING-archive.md")] +PROSE_DEFERRAL_RE = re.compile(r"defer(?:red|ral)", re.I) _seen_files: set = set() for root, pattern in _scan_targets: if not root.is_dir(): @@ -381,6 +396,17 @@ control("trigger evaluator does NOT fire on an unmet condition " _p_wait and trigger_fired(_p_wait[0]) is False) control("deferred-decision scan surface is reachable", any(r.is_dir() for r in SCAN_ROOTS)) +# Prose-deferral census: counted, never classified, and never read as absence. +prose_counts = {} +for _f in (HOME / "dotfiles" / "PENDING.md", HOME / "dotfiles" / "PENDING-archive.md"): + if _f.exists(): + prose_counts[_f.name] = len(PROSE_DEFERRAL_RE.findall(_f.read_text(errors="replace"))) +control("prose-deferral counter finds a known-present phrase", + PROSE_DEFERRAL_RE.search("this was deferred pending recurrence") is not None) +control("prose-deferral counter does not fire on unrelated text", + PROSE_DEFERRAL_RE.search("the fleet is green") is None) +control("register files are inside the widened deferral scan", + any(str(t[1]).endswith("PENDING-archive.md") for t in _scan_targets)) # ------------------------------------------ 9. built without a ruling in the register @@ -532,5 +558,11 @@ if deferrals: waiting = len(deferrals) - len(manual) print(f"✓ deferred decisions: {len(deferrals)} tracked, none due " f"({waiting} checkable, {len(manual)} manual-only)") + if prose_counts: + _tot = sum(prose_counts.values()) + print(f" ⚠ plus {_tot} PROSE deferral mention(s) in the register " + f"({', '.join(f'{k} {v}' for k, v in prose_counts.items())}) — these carry no") + print(" DEFERRED-DECISION block, so NO trigger is machine-checkable for any of them.") + print(" Counted, not classified. Whether any condition has fired is unestablished.") sys.exit(0)