[HARDENING] Close PENDING-82 and -118; mark 119/120/123 BUILT

82 is discharged by events. Its 2026-07-28 substrate check said there was no
mcpServers key; today the config carries mcpServers: governance, and the jurist
used the tools in three consecutive rulings — opening graduation-spec directly
and refusing to rule from my summary, which is the capability the item existed
to create. Two residuals carried, not buried: the read enum reaches neither the
runbook nor the R0 contract, and the installed surface has 8 keys and a search
tool the description does not name.

118 is built, and building it REFUTED the option I had recommended. I wrote that
the checker already parses the archive format. It does not — the marker is an
HTML comment and there are zero in either register file; their deferrals are
prose, 53 and 26. Widening alone would have scanned two more files, found
nothing and reported clean: a silent net built to close a blind spot, which is
the failure the item was filed to describe.

So the widening ships with its limit in its own output — prose deferrals counted
and reported un-machine-readable, never as absent, with counting explicitly not
classifying. The census stays owed.

119/120/123 marked BUILT with their commits so the built-vs-ruled checker sees
them; all three were already ruled, so this closes a reporting gap, not an
authorization one.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01A35wiD55yRHj5U1ECZAX4t
This commit is contained in:
David F Glidden
2026-08-08 21:05:15 +02:00
co-authored by Claude Opus 5
parent d78c14dd0a
commit 90dc0f7373
3 changed files with 331 additions and 6 deletions
+40 -5
View File
@@ -496,7 +496,19 @@ Merge that `mcpServers` key into `~/Library/Application Support/Claude/claude_de
Delete the Cowork party entry and every reference to `COWORK.md`. Grounds, now two: a third executor costs a third doctrine copy of a document that is `CLAUDE.md` with the nouns changed; and Cowork could not have served as the jurist's filesystem eyes even in principle, since `coworkUserFilesPath` points at `~/Claude`, which does not exist, and remote Cowork — the incoming default — runs no local MCP at all.
**Files affected:** new `~/dotfiles/scripts/governance-mcp.py`; `~/dotfiles/scripts/wake-digest.py` (`item_spans()` fence-awareness + 3 controls). Awaiting steward hand: `claude_desktop_config.json`, Claude.app §Your Role and §Standing Context.
**Awaiting:** Steward authorization to install the `mcpServers` key. The server itself is inert until then — nothing loads it.
**Awaiting:** ~~Steward authorization to install~~ → **INSTALLED AND IN USE. CLOSED 2026-08-08.**
---
### AMENDMENT 1 — 2026-08-08, discharged by events; the item's substrate check is stale
**§A — INSTALLED.** The item's 2026-07-28 substrate check recorded *"`claude_desktop_config.json` has **no `mcpServers` key**"*. Verified today: top-level keys are **`mcpServers`, `coworkUserFilesPath`, `preferences`**, and `mcpServers` contains **`governance`**. The gate this item waited on has been passed.
**§B — And it is not merely installed, it is LOAD-BEARING.** Empirically, in a single day: the jurist used `governance_read`, `governance_item`, `governance_search` and `governance_state` across **three consecutive rulings**, opened `graduation-spec.yaml` L1–60 directly, and **refused to rule from the executor's summary** — *"ruling from the executor's summary of its own mandate is exactly the shape I should refuse."* That refusal is the capability this item existed to create, exercised. It also caught, from substrate the executor had quoted, an adverse ratified ruling the executor had missed (REVIEWED-53).
**§C — ⚠ Two residuals, carried not buried.** (1) **The `governance_read` enum does not reach everything a ruling may rest on** — `conversion-runbook.yaml` and the R0 contract are reachable by **no key**, and one ruling had a leg in executor testimony until the steward relayed the files by hand. The remedy is its own extension mechanism: **the server takes keys from a list, so extending the list is the fix.** Recorded in this item's earlier amendment; it survives this closure as a **named follow-on**, not a reason to hold the item open. (2) The installed surface differs from the description above — **8 keys, not "six enumerated documents"**, and a `governance_search` tool the five-tool list does not name. The description is stale; the substrate is authoritative.
**Closed:** the proposal was to build and install a read-only substrate interface for the jurist. It is built, installed, used, and has demonstrably changed rulings. What remains is a **bounded extension of an existing, working thing**, which is a different item.
### AMENDMENT — 2026-08-08, a concrete enum, from a ruling that hit the wall
@@ -1683,7 +1695,30 @@ This is harmless today only because voice ⟺ source: measured, **max distinct v
**Files affected:** `~/dotfiles/scripts/governance-drift-check.py`; a one-time census artifact (home to be decided with the ruling).
**Awaiting:** Steward authorization.
**Awaiting:** ~~Steward authorization.~~ → **BUILT 2026-08-08, `see dotfiles HEAD`. ⚠ AND THE ITEM'S OWN OPTION (1) IS REFUTED BY BUILDING IT.**
---
### AMENDMENT 1 — 2026-08-08, built — and option (1) rested on a false premise about the format
**§A — ⚠ MY OPTION (1) WAS WRONG, and building it is what showed that.** I wrote: *"Widen the scan to `~/PENDING-archive.md`. Smallest change; **the checker already parses that exact format.**"* **It does not.** The structured marker is an HTML comment — `<!-- DEFERRED-DECISION: slug … -->` — and there are **ZERO** of those in `PENDING.md` **or** in `PENDING-archive.md`. Measured 2026-08-08. Their deferrals are **prose**: **53** occurrences of `defer*` in `PENDING.md`, **26** in the archive.
**⇒ Widening alone would have scanned two more files, found nothing, and reported clean** — *a silent net, built to close a blind spot.* That is precisely the failure class this item was filed to describe, and I had specified it as the remedy.
**§B — So the widening ships WITH its own limit stated in the output.** Structured blocks are now found anywhere in the register; prose deferrals are **counted and reported as un-machine-readable, never as absent**:
```
✓ deferred decisions: 2 tracked, none due (2 checkable, 0 manual-only)
⚠ plus 79 PROSE deferral mention(s) in the register (PENDING.md 53, PENDING-archive.md 26) — these carry no
DEFERRED-DECISION block, so NO trigger is machine-checkable for any of them.
Counted, not classified. Whether any condition has fired is unestablished.
```
⚠ **Counting is not classifying.** 79 is an upper bound on candidates, not a count of deferrals — the regex matches any use of the word. **How many carry a condition, and how many of those have fired, is a READING task** and is reported as unestablished rather than skipped. That is the honest version of what option (2)'s census asked for, and the census itself remains **owed**.
**§C — Three controls added**, per the script's standard: the prose counter fires on a known-present phrase, stays silent on unrelated text, and the register files are provably inside the widened scan.
**§D — What this closes, and what it does not.** **Closes:** the checker no longer reads only `docs/**` — a structured deferral filed anywhere in the register is now seen, and the register's prose deferrals are **visible as a named unknown** instead of invisible. **Does not close:** the classification. The item's own ⚠ said *"size unmeasured, deliberately"*; it is now **bounded and still unclassified**, which is a better state and not the finished one.
---
@@ -1730,7 +1765,7 @@ This is harmless today only because voice ⟺ source: measured, **max distinct v
**§D — CONDITION ON (i): declare the cost threshold now, with its action.** `0.218 s over 14 sources` is honest about being burst-sized; (e) is unconditional and scales with sources × file size. **When it exceeds ~1 s, (e) re-scopes or hands off to (a)'s scheduled job.** Stated now because *a per-commit cost that grows unremarked converts a tripwire into a `--no-verify` habit* — this thread's own failure class arriving by the back door.
**Awaiting:** placement of the ruling. Build on placement: one line in `.precommit-triggers`, the §D threshold recorded beside it, tagged REVIEWED-N.
**Awaiting:** ~~placement of the ruling~~ → **BUILT 2026-08-08, `2534dfb`** under REVIEWED-102. One line in `.precommit-triggers` (`. | python3 engine/ingest_gate.py --check-only`), unconditional, with the §D cost threshold recorded beside it. Acceptance: both rules fire in declared order, cheapest first.
---
@@ -1782,7 +1817,7 @@ So the pathspec was **not silence — it was a cost commitment inside the author
**§D — Interaction with PENDING-119, if both land.** `.precommit-triggers` would carry two lines with overlapping paths; an engine commit pays ~2 s (fleet) + 0.218 s (binding). **Declare the order in the file** so a red is attributable to one check without reading both.
**Awaiting:** placement of the ruling.
**Awaiting:** ~~placement of the ruling~~ → **BUILT 2026-08-08, `2534dfb`** under REVIEWED-103. Pathspec widened to `corpus/ engine/ tests/ scripts/run-fleet.sh`. Acceptance decomposed per condition 2: `eecc8bb` replayed (both files match); red direction refuses — **fixture SYNTHETIC and labelled**, no real red `engine/` commit exists in 24 candidates; docs-only runs no suite.
---
@@ -2043,7 +2078,7 @@ Three cases, all discriminated: a rule ran → existing output already says so,
**§E — Related doctrine, filed as PENDING-124.** This item's *"needs a third state, not a pass or a fail"* and PENDING-122's `cannot-assess` are one finding reached twice in one day.
**Awaiting:** placement of the ruling. **Build order on placement: 123 → 119(i) → 120(a).**
**Awaiting:** ~~placement of the ruling~~ → **BUILT 2026-08-08, `448ce37`** under REVIEWED-105, first in the ruled order. (b)+(e): malformed declarations refuse with file/line/fault/`--no-verify`; a triggers file declaring nothing reports itself unguarded; the per-rule line prints in exactly the ambiguous case. Matched-rule output byte-identical. All seven table rows non-silent.
---
+259 -1
View File
@@ -1293,4 +1293,262 @@ blocks without saying why is replaced by habit within a week.
4. SEQUENCING across the four open items: land 123 before 119(i) and 120(a). Both add lines to .precommit-triggers; a validator that catches a
malformed line should exist before the file grows. In the other order, the first thing to test the new declarations is the declarations themselves.
**If AUTHORIZED:** Proceed with (b) + (e). Build order: REVIEWED-105 → REVIEWED-102 (i) → REVIEWED-103 (a). Tag commits with REVIEWED-105.
**If AUTHORIZED:** Proceed with (b) + (e). Build order: REVIEWED-105 → REVIEWED-102 (i) → REVIEWED-103 (a). Tag commits with REVIEWED-105.
## REVIEWED-106 — PENDING-124 — A check whose subject can be absent cannot be two-valued
**Date:** 2026-08-08
**Decision:** DESIGN GATE PASSED WITH CONDITIONS. Q1 applied, not extended — no constitutional change, no [ESCALATE]. Landing: one ladder entry.
Five conditions, none changing the doctrine's substance; three changing what is recorded about its basis.
**Stores:** claude-md L251-257, REVIEWED-104, REVIEWED-105, PENDING-124 verbatim via the governance tools. R0 §3 verified directly against the
sha-matched contract (db39a503…, L180), so I.4 is substrate for this jurist, not testimony — the package's front-matter was true two turns ago and
is now false.
1. Q1 APPLIED. Constraint 4 has two clauses. The contrary reading engages only the second; the first speaks of limits, not failures, and "I could
not look" is a limit. The executor overstated its own uncertainty here, and deserves to know the replacement is firm.
2. CONDITION 1 — the quote-verification pass gains its own third state before it is relied on again. It reported verified on a normalized
reconstruction of REVIEWED-104, which had also dropped the sentence answering the package's own Q2. A two-valued verifier inside a package arguing
for three-valued verifiers. This is also a tenth instance, and the only one in the set independent of the advisory that proposed the doctrine —
produced by the gate, not the proposal.
3. CONDITION 2 — the ladder entry names the attested-absence family and cites the 2026-07-05 ruling (REVIEWED-47), so it joins a lineage rather
than standing as an orphan under a constitutional clause.
4. CONDITION 3 — the evidence statement is corrected before placement: two pre-existing instances of the shape, three of the adjacent principle,
one found at the gate. The uncorrected "five … same shape" would have been inherited as load-bearing.
5. CONDITION 4 — III.1 carries the environment-vs-defect split in the normative statement, not only in the consequence-trace. CONDITION 5 — landing
as leaned: one named instrument on reference-verification-ladder.md, nothing in ~/CLAUDE.md.
6. Q2 binds at reporting AND aggregation; the aggregation half is already ruled by REVIEWED-104 §1's closing sentence. Q3 names left free, with the
ratified test recorded: one name per referent, not one per concept. Q4 ratify not provisional, and not on the count — four of nine instances are
downstream of the advisory that proposed the doctrine; the chamber census is owed, not blocking.
**If AUTHORIZED:** Conditions 1-5 are discharged as of 2026-08-08. Tag with REVIEWED-106.
## REVIEWED-107 — PENDING-125 — A live false attestation in the governed record: Mauss's reading_index_status
**Date:** 2026-08-08
**Decision:** AUTHORIZED — option (a). D-1 lane, authorized verbally; RECORDED RETROSPECTIVELY, after the build.
**Notes:** (a) and (b) are different acts and were correctly separated. Correcting the field stops the record asserting something false today and
needs no ruling; re-anchoring the index is curatorial work that must carry the ladder's re-anchor = re-verify discipline, since re-anchoring
without re-verifying is what produced this class. (b) remains open.
1. Built as 8231bce. reading_index_status VERIFIED-BOUND → SHA-STALE, bounded to one field, shas untouched, manifest re-parses at 14 sources.
2. The executor checked the sub-question it had flagged before choosing a value, and the answer changed the entry: the vocabulary is UNDEFINED.
Three tokens in use across the manifest, no definition anywhere in either repo, every external mention prose about this defect rather than a
specification. SHA-STALE is therefore a fourth undefined token, added because none of the three could state the truth, and recorded as a known cost
rather than minted quietly.
3. Noted: the commit was the trigger mechanism's first real corpus exercise — both declared rules fired, fleet green, not a probe.
**If AUTHORIZED:** Tag with REVIEWED-107. (b) stays open under PENDING-125.
## REVIEWED-108 — PENDING-126 — Two holes in the fleet, and the census that followed
**Date:** 2026-08-08
**Decision:** AUTHORIZED — options (a) then (c). D-1 lane, authorized verbally; RECORDED RETROSPECTIVELY, after the build.
**Notes:** Merged with PENDING-122 on the executor's argument that they are one subject with overlapping files, and that hole 2 was a prerequisite
for verifying 122 — while suites raise, cannot-assess cannot be told from red. The merge was right.
1. (a) built as 8ff5a9f. Hole 1: close_ranges' section_end bound guarded, both branches; discriminating negative run — bound removed → two named
failures citing 499 and 400, restored → 47/47. Hole 2 was THREE sites, not the one filed; fixed as a class. An induced citability break went from a
single StopIteration traceback to seven named failures.
2. (c) the census, done, and it renamed the class. Crash-rather-than-name: 3 of 7 suites under 3 triggers, origin suite-side direct access. The
unguarded-rule question is unanswerable by inspection — token-mention said 13 of 13 touched, which is worthless since hole 1 lived in a touched
clause. Mutation: 4 of 7 caught, and all 3 survivors verified EQUIVALENT on current data by sentinel and by positive control. So hole 1 was never
an unguarded rule; it was a guard the live corpus cannot exercise, and three more of that shape exist in R0 alone. Latent, not wrong.
3. The crash class then closed at the preflight rather than at six sites (d21a43b), on the ground that all six depend on one invariant. Closing the
six revealed two more under a fourth degraded state, in suites the census had cleared: 6 → 8. The eighth originates in ENGINE code (retrieve.py
_work_map) and was deliberately not fixed by a test-side patch; whether retrieve() should degrade rather than raise is filed as an engine question
rather than hidden.
4. Final census, five degraded states: zero crashes, against 3/3/0/3 before.
5. ⚠ Recorded as owed, not blocking: the census covered R0's clauses only. n0/n1/v0/v1/cluster-a are unmutated and their escape rate is unknown,
not zero.
**If AUTHORIZED:** Tag with REVIEWED-108.
## REVIEWED-109 — PENDING-127 — R0 §4 emits two states where §3 rules three
**Date:** 2026-08-08
**Decision:** AUTHORIZED — option (a). D-1 lane, authorized verbally; RECORDED RETROSPECTIVELY, after the build.
**Notes:** The item said §4 was binary against §3's three states. It was worse: the CODE was unary. emit promoted baseline_sha256 to content_sha256
on every region — 261 of 261 for Alexander, including regions no instrument had verified — under a hardcoded date. Three different answers lived
in one contract and one module.
1. Built as ccc4d6c. Contract v0.1 → v0.2, superseded sentence preserved in place. Suite 31 → 44. Fleet 7/7.
2. The fix goes further than (a) asked, on the item's own logic, and that is ratified: a content_sha256 attests the whole span while name-landing
is evidence about the anchor's first line, so recording the former because the latter held promotes a weaker claim into a stronger one — the
PENDING-47 shape. Emission now records NO new fingerprints; one enters only through an attested re-verification. This is what makes PENDING-121
condition 4 reachable rather than aspirational.
3. State determination is now one function called by validate and emit, which had silently disagreed — §3's own "one mechanism with two call sites"
applied to the module's interior.
4. ⚠ The acceptance fixture named in the item was STALE, and measuring corrected it. Alexander's five front_matter anchors were partitioned out on
2026-08-07; Alexander is 261/261 name-landing with zero unverified. The real unverified population is Mauss 23 and after-the-reply 33. The
discriminating pair is therefore Alexander against Mauss — two real artifacts, a better control than the one specified. stale is unreachable from
live data and its control is labelled synthetic.
5. One pre-existing check went red and was replaced rather than deleted: it asserted the promotion this item rules a defect. A test that pinned the
old contract is evidence of what the contract used to say.
**If AUTHORIZED:** Tag with REVIEWED-109.
## REVIEWED-110 — PENDING-121 — engine_source_binding: prose to declared surfaces, and the fingerprint specified but never recorded
**Date:** 2026-08-08 (design gate 2026-08-08; two follow-on passes same day) · placed retrospectively
**Decision:** DESIGN GATE PASSED WITH CONDITIONS (1-4), then HELD OPEN for a redraft of Part IV.2 after substrate
verification. The redraft is filed (item Amendment 3 §D) and is NOT gated by this entry. Placement gate outstanding,
jointly with PENDING-128.
**Stores:** REVIEWED-101, REVIEWED-53, REVIEWED-47, PENDING-121, PENDING-119, PENDING-120, PENDING-47 verbatim via the
governance tools; graduation-spec.yaml L1-60 via governance_read. conversion-runbook.yaml and the R0 contract were
unreachable at the time of ruling and were read only after the steward supplied them, sha-matched against the request's
table (fffeed86…, db39a503…). engine/reading_index.py was never read by the jurist: condition 4 was ruled
prophylactically and REVIEWED-109 later found the code unary, which is worse than the item claimed.
governance_state() timed out; no drift count or repo status informed this ruling.
1. AN ADVERSE RATIFIED RULING WAS MISSING FROM THE GROUNDING PASS. REVIEWED-53 kept engine_source_binding as ONE entry —
'names a relationship across three files that move together; fragmenting recreates the failure' — and the package
proposed five siblings. REVIEWED-101 condition 1 did not cite it either: two rulings from one lane pointing opposite
ways, neither aware of the other. Treated as a verification trigger, not a precedence call. Resolution: the entry stays
ONE, surfaces become addressable members, and the co-movement invariant becomes declared data rather than why: prose —
because prose is what this amendment establishes no consumer reads.
2. CONDITIONS IN FORCE. (1) co-movement declared, a consumer verifying a proper subset reports incomplete never clean —
and this collapses with IV.1 para 2 into one requirement, drafted once. (2) resolve scope, then DERIVE the enumeration
from the runbook's list plus the per-region surface, justifying every omission; never compose afresh. (3) no dated counts
in declared data — locators and semantics only, population computed at read time; unverified-by-construction survives
only as a rule, since a rule does not go stale and a count does. (4) the promotion rule is REVIEWED-47 applied, not new
normative text: reuse the ratified by/against/result attestation shape under the single shared guard, reducing the
constitutional change to one requirement.
3. Q1 — the zero-evidence surface is CARRIED, never omitted, and the stronger form is adopted. The marking is not what
prevents the Part V inversion; not computing a heterogeneous aggregate is. Report per surface; any derived aggregate
reports unverified when a member is unpopulated or unchecked. Two discriminations required: the drift signal must be
separable from the unverified signal, or the check becomes a constant nobody reads; and '271 verified' must never
surface unqualified, since R0 §3 holds name-landing insufficient.
4. Q2 — reading_index_status is NOT a binding surface and NOT evidence, and no consumer of this enumeration may read it
as such. Retention, demotion or retirement is the engine's lane, D-1, and a chamber spec ruling an engine field's fate
would exceed standing. STRENGTHENED after ruling by REVIEWED-107 §2: the vocabulary is undefined — three tokens in use,
no definition in either repo — which is a cleaner ground than the one given here. Recorded as owed and unowned: SHA-STALE
is now a fourth undefined token and no open item covers defining the vocabulary.
5. Q3 — REVISED against my own lean, and the revision is the more useful half. The enumeration is not incomplete but NOT
COMPLETABLE: the runbook's scope_note sets membership as any repo the engine manifest binds, and the runbook's own list
was found short by its own grep on 2026-07-19. So the spec is authoritative for SEMANTICS and the runbook's grep for
COMPLETENESS — two claims, two homes, not the fault condition 1 forbids. My original 'single enumerative authority' is
withdrawn: it would have demoted the only instrument that has ever caught a missing surface.
6. Q4 — refinement of the hash-locality principle's third instance, not a fourth. Same referent class, same home, finer
granularity, and REVIEWED-53's individuating reason (files that move together) covers it. The ratified sentence stands
untouched. TEST RECORDED, because the count is maintained by ruling and went 2 to 3 through REVIEWED-53: a future surface
introducing a NEW HOME amends it; one refining an existing home does not.
7. Q5 / Q6 — RENAME, not rescope in place. The voice_manifest incident that created this entry was a name inviting a
wrong generalization; rescoping with a scope: field would be the same remedy a second time in the same block for the same
failure mode. The ratified principle is NOT amended: L19 and L39-40 update as mechanical referring-name edits under
REVIEWED-53's own lane rule for machine-data, with both reading grains preserved at the new name. REVIEWED.md L471 is not
edited — a ruling records what it ruled. Name: canonical_binding, NOT canonical_binding_surface, which contains
binding_surface and would have made the runbook's own key un-greppable through the instrument built to prevent that.
Completion control required both directions: before, the search finds the known occurrences; after, zero hits on the old
name outside REVIEWED.md, excluded BY NAME in the command.
8. SUBSTRATE VERIFICATION. Both supplied files matched their declared shas and line counts, so the anchors held.
Condition 2 leg (a) verified without the runbook — a key named engine already housed chamber artifacts in the executor's
own draft. Leg (b) verified: catalogue.yaml at runbook L251. Two findings the package did not carry: the manifest binds
THREE repos, not two (five after-the-reply sources are ARC, hard-coded to chamber paths in the draft), and R0 §4 L223-225
is binary against §3 L180's collapse prohibition — split out as PENDING-127, since the chamber requirement was unmeetable
while it stood. Now closed as REVIEWED-109, which found the code unary and 261 of 261 regions promoted under a hardcoded
date.
9. TWO SURFACES ADDED AFTER VERIFICATION. chamber-catalogue, and engine-sidecar-region — R0 §3 rules the two per-region
gaps are one mechanism with two call sites, so enumerating only the reading index would have hard-coded that divergence
into declared data.
10. SPLITS AND COUPLING. PENDING-125 (Mauss, condition 5a) — a live false claim 53 days old must not die inside a
deferred PROPOSAL; now REVIEWED-107(a), with (b) open. PENDING-127 — now REVIEWED-109. PENDING-128 — REVIEWED-53's
deferred option (c), recorded as live again on the reasoning that carried Q6 and to be RULED jointly with this item. Its
landing was made conditional rather than fixed: PENDING-127 clearing selects a single commit for both, and REVIEWED-109
has cleared it, so the single commit obtains.
11. SUPERSEDED EXAMPLE, flagged so it is not inherited. The item's design question cites Alexander's five stale
front_matter anchors; REVIEWED-109 §4 records they were partitioned out on 2026-08-07 and that Alexander is 261/261 with
zero unverified. The hazard is confirmed and larger, not weakened. Cite the 261/261 unconditional promotion.
12. ON THE GROUNDING PASS. Five omissions across three passes, every substantive one understating the gap the executor
was arguing for — the executor's own reading, accepted: passages stating the problem were quoted, passages stating its
extent were skipped, and four of five were extent-passages. Not selective; systematic in kind.
13. THE VERBATIM FILED RULING IS SUPERSEDED IN FOUR PLACES AND CARRIES NO MARKER. engine-source-binding-surfaces-JURIST-RULING-2026-08-08.md is the first pass only: its Stores line says the three files were NOT read and Parts I.1-I.4 are testimony (they were later read and sha-matched); its Q3 under 2(i) asserts the 'single enumerative authority' holding this entry withdraws at point 5; its condition 2 leaves the branch open (the steward chose (i)); and its §4 cites Alexander's five front_matter anchors, partitioned out 2026-08-07 per REVIEWED-109 §4. It is also the only verbatim jurist text in chamber docs/, and it contains no Q5 or Q6 — the rename holding PENDING-128 stands on exists there not at all. CONDITION: a supersession header at its top pointing to this entry, and to the two later passes, before either is relied on again. The document
is not edited below the header — a filed ruling records what was ruled when.
**If AUTHORIZED:** Conditions 1-4 stand as discharged in the Amendment 3 §D redraft, which is filed and awaiting the
placement gate — that gate is NOT granted by this entry and requires the redrafted canonical_binding block itself, not
its description. Rule jointly with PENDING-128; land in one commit per point 10. Tag with REVIEWED-110.
## REVIEWED-111 — PENDING-128 — REVIEWED-53's deferred option (c): kill the manifest shared word
**Date:** 2026-08-08
**Decision:** DESIGN GATE PASSED on option (a); (c) rejected. Ruled jointly with PENDING-121 per §Coupling. The
same-commit requirement is NARROWED, not adopted as filed. Three conditions.
**Stores:** PENDING-128, PENDING-121 (incl. Amendments 1-3), REVIEWED-53, REVIEWED-107, REVIEWED-109 verbatim via the
governance tools; graduation-spec.yaml L1-60 via governance_read. The shared-name collision log is reachable by no key
and is executor testimony; it carries no weight here. Numbering assumes this follows REVIEWED-110 (PENDING-121).
1. 1. RULED TOGETHER: YES, and the ground is REVIEWED-53's own text, not an unplaced holding. REVIEWED-53 judged (c) doctrinally complete and deferred it on occasion — 'out of scope for a doc-gap patch' — and PENDING-121 is a PROPOSAL that opens the same block deliberately, so the occasion has arrived. The parallel rename ruling is REVIEWED-110 §7; cite that, not 'PENDING-121's
Q6', which appears in no placed or verbatim-filed record. Renaming one key because names must not mislead, while leaving its neighbour in the same block warned-around on the same ground, is incoherent. Neither is ruled without the other. ORDERING CONSEQUENCE: REVIEWED-110 must be placed before or with this entry, or point 1 cites forward into nothing.
2. SAME COMMIT: CONDITIONALLY, AND NARROWED. The conditional filed against PENDING-127 has resolved — REVIEWED-109
cleared it — so a single commit obtains. But PENDING-121 lands in TWO places: the mechanism in graduation-spec.yaml
declared data, and the requirement in the constitution, MINOR bump by supersession. PENDING-128 is pure machine-data.
Read as binding 128 to all of 121's landing, a machine-data rename would ride inside a constitutional supersession, and
reverting the requirement would revert the rename — the revertability cost the conditional existed to avoid, returning
through the door the blockage just left. RULED: the coupling binds PENDING-128 to PENDING-121's DECLARED-DATA landing —
the layers: block commit — and not to its constitutional landing. §Coupling's own reason (same block, L19 cross-references
L20 by name) supports exactly this scope and no more.
3. OPTION (a) PASSES. Rename kills the collision. The executor's ground for recommending (a) and not (c) is affirmed:
retiring a ratified safeguard should be its own decision with its own evidence, not a tidy-up riding on a rename.
4. OPTION (c) REJECTED, and REVIEWED-107 strengthens the rejection. Retiring the warning rests on 'the name is now
unambiguous', which is the assumption whose failure created this entry. REVIEWED-53 chose two reading grains
deliberately. Both stay. Retiring a reading grain in a corpus just shown to mint undefined tokens is the wrong direction.
5. CONDITION 1 — THE WARNING'S TEXT IS REWRITTEN, NOT MERELY KEPT. The item says keep the warning and does not notice
that the rename changes what the warning is about. L19 currently warns that the word manifest names two different engine
objects; after the rename the chamber side no longer carries that word, so the warning as written describes a collision
that no longer exists at the site where it is printed. A kept-verbatim warning would be a stale safeguard — the shape
this register keeps ruling against, arriving through a change made to improve clarity. Rewrite both grains to say what
they now need to say: that the engine's SOURCE manifest binds by hash and is a different object, and that a reader
arriving from an older citation of voice_manifest has reached the right entry. Preserving a safeguard means preserving
its function, not its bytes.
6. CONDITION 2 — THE NEW TERM IS DEFINED WHERE IT IS INTRODUCED, IN THE SAME ACT. REVIEWED-107 §2 found
reading_index_status's vocabulary undefined — three tokens in use, no definition in either repo — and a fourth minted to
state a truth none of the three could. That is a demonstrated corpus tendency to introduce terms without definitions and
notice later. voice_personification is drawn from the entry's own prose; if personification is undefined at its site, the
rename trades a documented collision for an undefined term, which is worse than the status quo, since the collision at
least carried a warning. The definition goes in the rewritten grains of condition 1 — one act, not two.
7. CONDITION 3 — THE COMPLETION CONTROL RUNS IN ONE INVOCATION, WITH A POSITIVE CONTROL. The item requires zero hits on
the old name outside REVIEWED.md, and separately that the L19-L20 cross-reference still resolves in both directions. Run
apart, the first is satisfiable by DELETING the cross-reference: the negative result passes precisely because the subject
was removed. RULED: both run together, with resolves-at-new-names serving as the positive control for the zero-hits
check. This hole opens only under a single commit, where the cross-reference becomes rewritable on both sides at once.
8. NAME. voice_personification passes the substring test against binding_surface-class hazards. Recorded as neutral, not
an improvement: graduation-spec.yaml carries voice as a frontmatter optional field in the same file, so a search for
voice cannot isolate the frontmatter field from the layer key, before or after. The item's claim to be 'the first
retired rather than warned around' should not be read as clearing the file of voice-family entanglement.
9. UNVERIFIED, and carrying no weight. The shared-name collision log, and therefore 'the ninth such case'. Reachable by
no governance_read key. The ground for (a) is REVIEWED-53's own text, which was read.
10. NOT RULED HERE. The census of the other eight collisions, which the item correctly declines to propose. Whether
REVIEWED.md L471 is touched — it is not; a ruling records what it ruled.
**If AUTHORIZED:** Land option (a) with conditions 1-3, in PENDING-121's declared-data commit per point 2, not in its
constitutional supersession. Tag with REVIEWED-111.
+32
View File
@@ -335,6 +335,21 @@ def trigger_fired(d: dict) -> bool | None:
_scan_targets = [(r, "*/docs/**/*.md") for r in SCAN_ROOTS] + EXTRA_SCAN_GLOBS
# PENDING-118, and the item's own option (1) is REFUTED by building it.
# The item said "widen the scan to ~/PENDING-archive.md — the checker already parses
# that exact format." It does not. The structured marker is an HTML comment
# <!-- DEFERRED-DECISION: slug ... -->, and there are ZERO of those in PENDING.md or in
# the archive. Their deferrals are PROSE — measured 2026-08-08: 53 and 26 occurrences of
# "defer*". Widening alone would scan two more files, find nothing, and report clean:
# a silent net built to close a blind spot, which is the failure this item describes.
#
# So the widening ships WITH its own honest limit. Structured blocks anywhere are now
# found; prose deferrals are COUNTED and reported as un-machine-readable, never as
# absent. Counting is not classifying — how many of those conditions have fired is a
# READING task, and it is reported as owed rather than silently skipped.
_scan_targets += [(HOME / "dotfiles", "PENDING.md"), (HOME / "dotfiles", "PENDING-archive.md")]
PROSE_DEFERRAL_RE = re.compile(r"defer(?:red|ral)", re.I)
_seen_files: set = set()
for root, pattern in _scan_targets:
if not root.is_dir():
@@ -381,6 +396,17 @@ control("trigger evaluator does NOT fire on an unmet condition "
_p_wait and trigger_fired(_p_wait[0]) is False)
control("deferred-decision scan surface is reachable",
any(r.is_dir() for r in SCAN_ROOTS))
# Prose-deferral census: counted, never classified, and never read as absence.
prose_counts = {}
for _f in (HOME / "dotfiles" / "PENDING.md", HOME / "dotfiles" / "PENDING-archive.md"):
if _f.exists():
prose_counts[_f.name] = len(PROSE_DEFERRAL_RE.findall(_f.read_text(errors="replace")))
control("prose-deferral counter finds a known-present phrase",
PROSE_DEFERRAL_RE.search("this was deferred pending recurrence") is not None)
control("prose-deferral counter does not fire on unrelated text",
PROSE_DEFERRAL_RE.search("the fleet is green") is None)
control("register files are inside the widened deferral scan",
any(str(t[1]).endswith("PENDING-archive.md") for t in _scan_targets))
# ------------------------------------------ 9. built without a ruling in the register
@@ -532,5 +558,11 @@ if deferrals:
waiting = len(deferrals) - len(manual)
print(f"✓ deferred decisions: {len(deferrals)} tracked, none due "
f"({waiting} checkable, {len(manual)} manual-only)")
if prose_counts:
_tot = sum(prose_counts.values())
print(f" ⚠ plus {_tot} PROSE deferral mention(s) in the register "
f"({', '.join(f'{k} {v}' for k, v in prose_counts.items())}) — these carry no")
print(" DEFERRED-DECISION block, so NO trigger is machine-checkable for any of them.")
print(" Counted, not classified. Whether any condition has fired is unestablished.")
sys.exit(0)