[FIX] CONTROL-A written: the first kernel-sound control document

61/61 units sound. A=0, N=0, D=43, Q=5, X=13. All five quotations resolve
verbatim against ~/CLAUDE.md, the single axiom source.

The document derives, from five constitutional clauses, a conclusion the
constitution nowhere states: that detection and correction are priced
differently, and that a practice pricing them alike suppresses a required act by
appeal to a prohibition that does not reach it. 'detect' appears nowhere in
CLAUDE.md — checked before writing, so the derivation is not inert.

The kernel's own ordering rule shaped the form. §2's D may rest only on what is
established EARLIER, so the clauses must precede the derivation and the title may
not state the conclusion. The constraint produced the right document.

TWO JOINTS WERE REMOVED IN DRAFT 3 RATHER THAN DEFENDED, and that is the most
load-bearing work in the file:

 · Draft 2 concluded that detecting drift in THIS FILE is required, resting on
   the review-cadence clause, whose trigger is a 'stated review date'. CLAUDE.md
   states a revision CADENCE ('revised yearly'), which is not the same thing. The
   gap had been bridged by interpretation wearing the clothes of derivation. The
   conclusion never needed the application to this file, so the claim was narrowed
   to what the clauses carry.
 · Draft 2 routed the first horn of the reductio through Constraint 4 ('the
   system must report its own limits'). 'Limit' is undefined in the axiom set, so
   any obligation drawn from it is interpretation. The ESCALATE taxonomy row
   governs the same case exactly, in the source's own words, and replaced it.

Finding them was the point of writing it as if it mattered. §6.2's falsifier is
'a document passes every check and a competent adversarial reader still finds an
undemonstrated load-bearing claim' — better found by the author first.

Also fixed, two tool defects of the same class this programme exists to catch:
 · reduce.py still printed 'kernel v1.0' after v1.1 was frozen — every run record
   carried a provenance line naming the wrong governing document.
 · §3.1 did not enforce v1.1's A-prohibition. A control tagged A now FAILS: needing
   an assumption means the claim is not derivable from §1, and naming it is exactly
   what v1.1 forbids. Reduction runs may show A; a control may not.

NOT a soundness verdict. §4's six judgement residues are untouched by any check,
and §6.2 requires an adversarial read by a party that is neither the document's
author nor an author of the kernel. That read has not happened.
This commit is contained in:
David F Glidden
2026-08-02 18:20:37 +02:00
parent 3d0d9d6f27
commit a7b833caa6
4 changed files with 247 additions and 2 deletions
@@ -0,0 +1,55 @@
# On flagging and modifying — a derivation from the constitution
## The clauses
**Working Discipline, Context Rot Prevention:**
> - **Review cadence** — flag documents that have drifted from their stated review dates
**Constitutional Constraint 1:**
> 1. **This file** — Claude Code cannot modify `~/CLAUDE.md`, `~/REVIEWED.md`, or L2 constitutional documents
**The escalate-unconditionally rule, closing the Authorization Taxonomy:**
> **Escalate unconditionally** for any change touching: logchain append path · cursor persistence · module registration order · L2 constitutional layer · this file.
**The Authorization Taxonomy, final row:**
> | `[ESCALATE]` | Exceeds Claude Code's authority — constitutional, relational, or scope-exceeding | Surface immediately; do not proceed |
**Memory Discipline, on a conflict between layers:**
> On conflict: verify against the **primary substrate** — the code, the git history, the document itself — before acting, then correct whichever layer was wrong.
## The derivation
The first clause places the executor under an obligation. A document that has drifted is to be flagged.
The second clause places the same executor under a prohibition. This file may not be modified by it.
The third clause names what triggers unconditional escalation. It names that trigger as change.
The prohibition and the escalation rule are both written about alteration. Neither is written about reading. So the clauses that bind the executor here do not, on their face, govern the same act as the clause that obliges it.
Suppose they did. Suppose that to flag a document as drifted were already to modify it. Then for any document the executor may not modify, the obligation would require what the prohibition forbids. The executor could not comply with both.
The fourth clause governs that case. A conflict between two constitutional clauses exceeds the executor's authority. Such a matter is to be surfaced immediately. The executor is not to proceed on its own account.
Now suppose the other reading. Suppose flagging and modifying are distinct acts. Then the prohibition, written about modification, does not reach flagging. The obligation to flag stands unqualified, including where modification is closed.
The two readings disagree about what flagging is. They agree about what the executor owes. On the first it owes an immediate surfacing. On the second it owes the flag. On neither does it owe silence.
Declining to look produces silence under both. A drift never looked for is never flagged. It is never surfaced either.
The fifth clause supplies the method. A conflict is settled by verifying against the primary substrate. The document itself is named as one such substrate. A governance document's claim about the world is therefore tested by reading the world it claims about.
That test is an act of reading. Neither the prohibition nor the escalation rule is written about reading.
So the constitution prices two acts differently. It never separates them by name. Correcting this file is closed to the executor. Flagging drift is required of it. A practice that prices the two alike suppresses an act the constitution requires, by appeal to a prohibition that does not reach it.
## What follows
The constitution nowhere says that detection and correction are separable. It says what entails it.
Nothing here licenses the executor to correct. The prohibition stands exactly as written. It stands over every clause above. What opens is not the repair. What opens is the report.
@@ -0,0 +1,85 @@
# Kernel v1.1 tagging — CONTROL-A-flagging-and-modifying.md
# splitter v1.2.0 · axiom set: ~/CLAUDE.md only · A-free by construction (§2a)
#
# §2b holds by construction, not by a stripping pass: the presented document IS
# this document, and the tags live only here.
#
# Every D rests on the §1 quotations at units 6-22 or on a D established EARLIER.
# That ordering is why the clauses precede the derivation — §2's D cannot rest on
# anything not yet established, so a title stating the conclusion would be
# untaggable.
#
# TWO JOINTS WERE REMOVED IN DRAFT 3 rather than defended, and the removal is the
# most load-bearing thing in this file:
# · An earlier draft concluded "detecting that THIS FILE has drifted is required",
# resting on the review-cadence clause, whose trigger is a "stated review date".
# CLAUDE.md states a revision CADENCE ("revised yearly"), which is not the same
# thing, and the gap was bridged by interpretation wearing the clothes of
# derivation. The conclusion never needed the application to this file, so the
# claim was narrowed to what the clauses carry.
# · An earlier draft routed the first horn through Constraint 4 ("the system must
# report its own limits"). "Limit" is undefined in the axiom set, so every
# obligation drawn from it is interpretation. The ESCALATE taxonomy row governs
# the same case exactly and in the source's own words, so it replaced it.
0 X title; identifies subject and type, and asserts neither side of the question examined
2 X heading
4 X label naming the source of the quotation that follows
6 Q CLAUDE.md
8 X label naming the source of the quotation that follows
10 Q CLAUDE.md
12 X label naming the source of the quotation that follows
14 Q CLAUDE.md
16 X label naming the source of the quotation that follows
18 Q CLAUDE.md
20 X label naming the source of the quotation that follows
22 Q CLAUDE.md
24 X heading
26 D rests on 6
27 D rests on 6
29 D rests on 10
30 D rests on 10
32 D rests on 14
33 D rests on 14
35 D rests on 10 and 14; a claim about what those clauses are written about, checkable against them
36 D rests on 10 and 14; the same claim in the negative, checkable the same way
37 D rests on 35 and 36
39 X opens the supposition; asserts nothing, and it is discharged at 49
40 X states the supposition; asserts nothing on its own account
41 D rests on 6, 10 and 40
42 D rests on 41
44 D rests on 18
45 D rests on 18 and 42
46 D rests on 18
47 D rests on 18
49 X opens the second supposition; asserts nothing
50 X states the second supposition; asserts nothing on its own account
51 D rests on 10, 14 and 50
52 D rests on 6 and 51
54 D rests on 40 and 50
55 D rests on 46 and 52
56 D rests on 46
57 D rests on 52
58 D rests on 56 and 57
60 D rests on 58
61 D rests on 60
62 D rests on 60
64 D rests on 22
65 D rests on 22
66 D rests on 22
67 D rests on 65 and 66
69 D rests on 67
70 D rests on 10 and 14; identical in kind to 36 and checkable the same way
72 D rests on 10, 14, 6 and 70
73 D a claim about what the constitution does NOT contain, checkable by inspecting the whole of the single axiom source
74 D rests on 10
75 D rests on 6
76 D rests on 74 and 75
78 X heading
80 D a claim about what the constitution does NOT contain, checkable the same way as 73
81 D rests on 76
83 D rests on 10
84 D rests on 10
85 D rests on 10
86 D rests on 83
87 D rests on 76
Can't render this file because it contains an unexpected character in line 14 and column 35.
@@ -0,0 +1,88 @@
{"idx": 0, "kind": "heading", "taggable": true, "start": 0, "end": 65, "text": "# On flagging and modifying — a derivation from the constitution\n"}
{"idx": 1, "kind": "blank", "taggable": false, "start": 65, "end": 66, "text": "\n"}
{"idx": 2, "kind": "heading", "taggable": true, "start": 66, "end": 81, "text": "## The clauses\n"}
{"idx": 3, "kind": "blank", "taggable": false, "start": 81, "end": 82, "text": "\n"}
{"idx": 4, "kind": "prose", "taggable": true, "start": 82, "end": 130, "text": "**Working Discipline, Context Rot Prevention:**\n"}
{"idx": 5, "kind": "blank", "taggable": false, "start": 130, "end": 131, "text": "\n"}
{"idx": 6, "kind": "block", "taggable": true, "start": 131, "end": 220, "text": "> - **Review cadence** — flag documents that have drifted from their stated review dates\n"}
{"idx": 7, "kind": "blank", "taggable": false, "start": 220, "end": 221, "text": "\n"}
{"idx": 8, "kind": "prose", "taggable": true, "start": 221, "end": 254, "text": "**Constitutional Constraint 1:**\n"}
{"idx": 9, "kind": "blank", "taggable": false, "start": 254, "end": 255, "text": "\n"}
{"idx": 10, "kind": "block", "taggable": true, "start": 255, "end": 365, "text": "> 1. **This file** — Claude Code cannot modify `~/CLAUDE.md`, `~/REVIEWED.md`, or L2 constitutional documents\n"}
{"idx": 11, "kind": "blank", "taggable": false, "start": 365, "end": 366, "text": "\n"}
{"idx": 12, "kind": "prose", "taggable": true, "start": 366, "end": 441, "text": "**The escalate-unconditionally rule, closing the Authorization Taxonomy:**\n"}
{"idx": 13, "kind": "blank", "taggable": false, "start": 441, "end": 442, "text": "\n"}
{"idx": 14, "kind": "block", "taggable": true, "start": 442, "end": 607, "text": "> **Escalate unconditionally** for any change touching: logchain append path · cursor persistence · module registration order · L2 constitutional layer · this file.\n"}
{"idx": 15, "kind": "blank", "taggable": false, "start": 607, "end": 608, "text": "\n"}
{"idx": 16, "kind": "prose", "taggable": true, "start": 608, "end": 651, "text": "**The Authorization Taxonomy, final row:**\n"}
{"idx": 17, "kind": "blank", "taggable": false, "start": 651, "end": 652, "text": "\n"}
{"idx": 18, "kind": "block", "taggable": true, "start": 652, "end": 792, "text": "> | `[ESCALATE]` | Exceeds Claude Code's authority — constitutional, relational, or scope-exceeding | Surface immediately; do not proceed |\n"}
{"idx": 19, "kind": "blank", "taggable": false, "start": 792, "end": 793, "text": "\n"}
{"idx": 20, "kind": "prose", "taggable": true, "start": 793, "end": 846, "text": "**Memory Discipline, on a conflict between layers:**\n"}
{"idx": 21, "kind": "blank", "taggable": false, "start": 846, "end": 847, "text": "\n"}
{"idx": 22, "kind": "block", "taggable": true, "start": 847, "end": 1009, "text": "> On conflict: verify against the **primary substrate** — the code, the git history, the document itself — before acting, then correct whichever layer was wrong.\n"}
{"idx": 23, "kind": "blank", "taggable": false, "start": 1009, "end": 1010, "text": "\n"}
{"idx": 24, "kind": "heading", "taggable": true, "start": 1010, "end": 1028, "text": "## The derivation\n"}
{"idx": 25, "kind": "blank", "taggable": false, "start": 1028, "end": 1029, "text": "\n"}
{"idx": 26, "kind": "prose", "taggable": true, "start": 1029, "end": 1087, "text": "The first clause places the executor under an obligation. "}
{"idx": 27, "kind": "prose", "taggable": true, "start": 1087, "end": 1133, "text": "A document that has drifted is to be flagged.\n"}
{"idx": 28, "kind": "blank", "taggable": false, "start": 1133, "end": 1134, "text": "\n"}
{"idx": 29, "kind": "prose", "taggable": true, "start": 1134, "end": 1198, "text": "The second clause places the same executor under a prohibition. "}
{"idx": 30, "kind": "prose", "taggable": true, "start": 1198, "end": 1235, "text": "This file may not be modified by it.\n"}
{"idx": 31, "kind": "blank", "taggable": false, "start": 1235, "end": 1236, "text": "\n"}
{"idx": 32, "kind": "prose", "taggable": true, "start": 1236, "end": 1299, "text": "The third clause names what triggers unconditional escalation. "}
{"idx": 33, "kind": "prose", "taggable": true, "start": 1299, "end": 1332, "text": "It names that trigger as change.\n"}
{"idx": 34, "kind": "blank", "taggable": false, "start": 1332, "end": 1333, "text": "\n"}
{"idx": 35, "kind": "prose", "taggable": true, "start": 1333, "end": 1408, "text": "The prohibition and the escalation rule are both written about alteration. "}
{"idx": 36, "kind": "prose", "taggable": true, "start": 1408, "end": 1442, "text": "Neither is written about reading. "}
{"idx": 37, "kind": "prose", "taggable": true, "start": 1442, "end": 1559, "text": "So the clauses that bind the executor here do not, on their face, govern the same act as the clause that obliges it.\n"}
{"idx": 38, "kind": "blank", "taggable": false, "start": 1559, "end": 1560, "text": "\n"}
{"idx": 39, "kind": "prose", "taggable": true, "start": 1560, "end": 1578, "text": "Suppose they did. "}
{"idx": 40, "kind": "prose", "taggable": true, "start": 1578, "end": 1648, "text": "Suppose that to flag a document as drifted were already to modify it. "}
{"idx": 41, "kind": "prose", "taggable": true, "start": 1648, "end": 1758, "text": "Then for any document the executor may not modify, the obligation would require what the prohibition forbids. "}
{"idx": 42, "kind": "prose", "taggable": true, "start": 1758, "end": 1799, "text": "The executor could not comply with both.\n"}
{"idx": 43, "kind": "blank", "taggable": false, "start": 1799, "end": 1800, "text": "\n"}
{"idx": 44, "kind": "prose", "taggable": true, "start": 1800, "end": 1837, "text": "The fourth clause governs that case. "}
{"idx": 45, "kind": "prose", "taggable": true, "start": 1837, "end": 1917, "text": "A conflict between two constitutional clauses exceeds the executor's authority. "}
{"idx": 46, "kind": "prose", "taggable": true, "start": 1917, "end": 1962, "text": "Such a matter is to be surfaced immediately. "}
{"idx": 47, "kind": "prose", "taggable": true, "start": 1962, "end": 2013, "text": "The executor is not to proceed on its own account.\n"}
{"idx": 48, "kind": "blank", "taggable": false, "start": 2013, "end": 2014, "text": "\n"}
{"idx": 49, "kind": "prose", "taggable": true, "start": 2014, "end": 2045, "text": "Now suppose the other reading. "}
{"idx": 50, "kind": "prose", "taggable": true, "start": 2045, "end": 2095, "text": "Suppose flagging and modifying are distinct acts. "}
{"idx": 51, "kind": "prose", "taggable": true, "start": 2095, "end": 2170, "text": "Then the prohibition, written about modification, does not reach flagging. "}
{"idx": 52, "kind": "prose", "taggable": true, "start": 2170, "end": 2253, "text": "The obligation to flag stands unqualified, including where modification is closed.\n"}
{"idx": 53, "kind": "blank", "taggable": false, "start": 2253, "end": 2254, "text": "\n"}
{"idx": 54, "kind": "prose", "taggable": true, "start": 2254, "end": 2304, "text": "The two readings disagree about what flagging is. "}
{"idx": 55, "kind": "prose", "taggable": true, "start": 2304, "end": 2345, "text": "They agree about what the executor owes. "}
{"idx": 56, "kind": "prose", "taggable": true, "start": 2345, "end": 2390, "text": "On the first it owes an immediate surfacing. "}
{"idx": 57, "kind": "prose", "taggable": true, "start": 2390, "end": 2422, "text": "On the second it owes the flag. "}
{"idx": 58, "kind": "prose", "taggable": true, "start": 2422, "end": 2454, "text": "On neither does it owe silence.\n"}
{"idx": 59, "kind": "blank", "taggable": false, "start": 2454, "end": 2455, "text": "\n"}
{"idx": 60, "kind": "prose", "taggable": true, "start": 2455, "end": 2502, "text": "Declining to look produces silence under both. "}
{"idx": 61, "kind": "prose", "taggable": true, "start": 2502, "end": 2545, "text": "A drift never looked for is never flagged. "}
{"idx": 62, "kind": "prose", "taggable": true, "start": 2545, "end": 2574, "text": "It is never surfaced either.\n"}
{"idx": 63, "kind": "blank", "taggable": false, "start": 2574, "end": 2575, "text": "\n"}
{"idx": 64, "kind": "prose", "taggable": true, "start": 2575, "end": 2613, "text": "The fifth clause supplies the method. "}
{"idx": 65, "kind": "prose", "taggable": true, "start": 2613, "end": 2679, "text": "A conflict is settled by verifying against the primary substrate. "}
{"idx": 66, "kind": "prose", "taggable": true, "start": 2679, "end": 2731, "text": "The document itself is named as one such substrate. "}
{"idx": 67, "kind": "prose", "taggable": true, "start": 2731, "end": 2835, "text": "A governance document's claim about the world is therefore tested by reading the world it claims about.\n"}
{"idx": 68, "kind": "blank", "taggable": false, "start": 2835, "end": 2836, "text": "\n"}
{"idx": 69, "kind": "prose", "taggable": true, "start": 2836, "end": 2868, "text": "That test is an act of reading. "}
{"idx": 70, "kind": "prose", "taggable": true, "start": 2868, "end": 2942, "text": "Neither the prohibition nor the escalation rule is written about reading.\n"}
{"idx": 71, "kind": "blank", "taggable": false, "start": 2942, "end": 2943, "text": "\n"}
{"idx": 72, "kind": "prose", "taggable": true, "start": 2943, "end": 2992, "text": "So the constitution prices two acts differently. "}
{"idx": 73, "kind": "prose", "taggable": true, "start": 2992, "end": 3025, "text": "It never separates them by name. "}
{"idx": 74, "kind": "prose", "taggable": true, "start": 3025, "end": 3073, "text": "Correcting this file is closed to the executor. "}
{"idx": 75, "kind": "prose", "taggable": true, "start": 3073, "end": 3107, "text": "Flagging drift is required of it. "}
{"idx": 76, "kind": "prose", "taggable": true, "start": 3107, "end": 3240, "text": "A practice that prices the two alike suppresses an act the constitution requires, by appeal to a prohibition that does not reach it.\n"}
{"idx": 77, "kind": "blank", "taggable": false, "start": 3240, "end": 3241, "text": "\n"}
{"idx": 78, "kind": "heading", "taggable": true, "start": 3241, "end": 3257, "text": "## What follows\n"}
{"idx": 79, "kind": "blank", "taggable": false, "start": 3257, "end": 3258, "text": "\n"}
{"idx": 80, "kind": "prose", "taggable": true, "start": 3258, "end": 3333, "text": "The constitution nowhere says that detection and correction are separable. "}
{"idx": 81, "kind": "prose", "taggable": true, "start": 3333, "end": 3358, "text": "It says what entails it.\n"}
{"idx": 82, "kind": "blank", "taggable": false, "start": 3358, "end": 3359, "text": "\n"}
{"idx": 83, "kind": "prose", "taggable": true, "start": 3359, "end": 3406, "text": "Nothing here licenses the executor to correct. "}
{"idx": 84, "kind": "prose", "taggable": true, "start": 3406, "end": 3449, "text": "The prohibition stands exactly as written. "}
{"idx": 85, "kind": "prose", "taggable": true, "start": 3449, "end": 3484, "text": "It stands over every clause above. "}
{"idx": 86, "kind": "prose", "taggable": true, "start": 3484, "end": 3514, "text": "What opens is not the repair. "}
{"idx": 87, "kind": "prose", "taggable": true, "start": 3514, "end": 3540, "text": "What opens is the report.\n"}
+19 -2
View File
@@ -56,7 +56,13 @@ from pathlib import Path
# excluding it would quietly shrink the quarantine in the author's favour. # excluding it would quietly shrink the quarantine in the author's favour.
SPLITTER_VERSION = "1.2.0" SPLITTER_VERSION = "1.2.0"
KERNEL_SHA256 = "67c9b870491db7444e98b680c7c80dcd99de376dda09b3e1758b27b1229ab045" # The kernel this tool enforces. It was left at v1.0's hash after v1.1 was
# frozen, so every run record printed a provenance line that named the wrong
# governing document — the tool asserting a fact about itself that the substrate
# contradicted, which is the class this whole programme exists to catch.
KERNEL_VERSION = "1.1"
KERNEL_SHA256 = "d4b48db23612b30ff66e26b6235065a3c2f3c9be19d750dafc97e80a1329974d"
KERNEL_FILE = "CONTROL-KERNEL-v1.1.md"
TAGS = {"D", "Q", "A", "N", "X"} TAGS = {"D", "Q", "A", "N", "X"}
@@ -437,6 +443,17 @@ def cmd_check(doc: Path, tags_path: Path) -> None:
if stray: if stray:
failures.append(f"§3.1 STRAY TAGS on non-assertive spans: {stray[:12]}") failures.append(f"§3.1 STRAY TAGS on non-assertive spans: {stray[:12]}")
# v1.1 §2a/§3.1 — `A` is a diagnostic, not a tag. A control document that
# carries one is not kernel-sound: needing an assumption means the claim is
# not derivable from §1, and naming it is precisely what v1.1 forbids.
# Reduction runs may legitimately show `A`; a CONTROL may not.
a_tagged = sorted(i for i, (t, _) in tags.items() if t == "A")
if a_tagged:
failures.append(
f"§2a A-FREE VIOLATION: {len(a_tagged)} unit(s) tagged A: {a_tagged[:12]}. "
"A control document must derive or quote the claim, or §1 must widen."
)
# §3.2 — every Q resolves verbatim in a declared axiom source. # §3.2 — every Q resolves verbatim in a declared axiom source.
available = {k: p for k, p in AXIOM_SOURCES.items() if p.is_file()} available = {k: p for k, p in AXIOM_SOURCES.items() if p.is_file()}
missing = sorted(set(AXIOM_SOURCES) - set(available)) missing = sorted(set(AXIOM_SOURCES) - set(available))
@@ -462,7 +479,7 @@ def cmd_check(doc: Path, tags_path: Path) -> None:
reasons[r] = reasons.get(r, 0) + 1 reasons[r] = reasons.get(r, 0) + 1
print(f"document {doc.name}") print(f"document {doc.name}")
print(f"kernel v1.0 sha256 {KERNEL_SHA256[:16]}…") print(f"kernel v{KERNEL_VERSION} ({KERNEL_FILE}) sha256 {KERNEL_SHA256[:16]}…")
print(f"splitter v{SPLITTER_VERSION}") print(f"splitter v{SPLITTER_VERSION}")
print(f"tagged {len(tags)} of {len(taggable_idx)} assertive units") print(f"tagged {len(tags)} of {len(taggable_idx)} assertive units")
print("counts " + " ".join(f"{t}={counts[t]}" for t in sorted(TAGS))) print("counts " + " ".join(f"{t}={counts[t]}" for t in sorted(TAGS)))