diff --git a/PENDING.md b/PENDING.md index 9ba47f7..65808be 100644 --- a/PENDING.md +++ b/PENDING.md @@ -1540,7 +1540,7 @@ This is harmless today only because voice ⟺ source: measured, **max distinct v **Date:** 2026-08-08 **Tag:** [PROPOSAL] -**Related:** REVIEWED-97 · PENDING-115 · skill-harvest register #192. **PROPOSAL, not FIX** — it changes what a gate accepts (a hook that can refuse a commit), which the amendment discipline puts above the FIX lane regardless of how small the diff is. +**Related:** REVIEWED-97 · PENDING-115 · skill-harvest register **#194** (cited here as `#192` when filed; that number was already held by the cited-vs-placed check of 2026-08-07 night, and the later filing was renumbered 2026-08-08 — see the register's renumbering note). **PROPOSAL, not FIX** — it changes what a gate accepts (a hook that can refuse a commit), which the amendment discipline puts above the FIX lane regardless of how small the diff is. **Summary.** `118f411` split the Mauss sidecar's `body` section into `body-01…13`. That invalidated `test_navigate.py`'s hardcoded node id, and **the fleet sat 202/203 red for a full day** — through two separate rounds of correction to that very commit — surfacing only because the steward asked an unrelated question about instrument reliability. Nothing runs the suites on the change that breaks them. @@ -1568,3 +1568,97 @@ This is harmless today only because voice ⟺ source: measured, **max distinct v **Awaiting:** Steward authorization. --- + +## PENDING-117 — The cross-repo half: a chamber edit invalidates engine bindings with no commit on either side (resuming PENDING-53 Option 3) + +**Date:** 2026-08-08 +**Tag:** [PROPOSAL] +**Related:** PENDING-53 (archived, REVIEWED-53 2026-07-10) · PENDING-116 / REVIEWED-100 (built today) · chamber `_curation/graduation-spec.yaml` `engine_source_binding` · `_curation/conversion-runbook.yaml` `reanchor:` block. + +**Summary.** REVIEWED-100 landed a pre-commit trigger that runs the engine fleet when `corpus/` changes. It closes the **same-repo** half only. The canonical texts live in `chamber-library`, and a chamber-side re-anchor or re-clean invalidates the engine's `manifest.yaml` sha, the sidecars' `source_sha256` and the coverage ledger **with no engine-side commit at all** — so no hook fires on either side. This resumes PENDING-53's **Option 3**, which was deferred rather than rejected. + +**The deferral condition, stated precisely rather than favourably.** PENDING-53's recommendation reads: *"Option 3 as a follow-on if re-hash/re-anchor recurs across the ~30-source Making batch."* That condition is **NOT met** — the Making batch is sourced but not ingested. The "5 standing FAILED rows since 2026-07-10" cited at REVIEWED-73 are **repaired**: the ledger today reads `validated: 14, failed: 0, failures: []`. There is **one** documented cross-repo incident, the founding one (Weil P1, 2026-07-09, recorded in PENDING-53 as *"caught only by chance during P2 diagnosis"*). `118f411` is the **same-repo analog** and is evidence about the firing-moment diagnosis generalizing, not a second instance of this class. Filing this now is therefore **not** a claim that the trigger fired. + +**Rationale — why now, on different grounds.** Building half a gate raises confidence faster than it raises coverage. Before today, "does anything check the corpus↔engine binding?" answered *no*, uniformly. After REVIEWED-100 it answers *yes, visibly* — the hook prints `Staged change touches [corpus/] — running declared check` and refuses on red. A reader who has seen that fire has every reason to believe corpus changes are covered. They are covered **only when the edit originates engine-side.** The asymmetry is now invisible from the surface that demonstrates the protection, which is a worse epistemic state than the uniform *no*, and is Constraint #4 (honest degradation) applied to the gate's own advertised extent. The `.precommit-triggers` header and the engine `CLAUDE.md` both name the gap in prose — but PENDING-116's own argument is that a named risk is not a mechanized check. + +**A second-order finding, filed here rather than separately.** PENDING-53's deferral was invisible to every standing instrument. `governance-drift-check.py` reports *"deferred decisions: 2 tracked, none due"* — it does not read **archived** PENDING bodies, where this deferral lives. The gap surfaced only because a chamber YAML header cited "PENDING-53" and the citation did not resolve in the live register. Same shape as skill-harvest #191: a detector correct everywhere it looks, not looking where the quarry lives. + +**Options.** +- **(a) Scheduled binding check.** A periodic job recomputes each manifested source's live sha against `manifest.yaml`, the sidecar `source_sha256` and the coverage ledger, and reports drift. Catches the case with no commit on either side — the only option that does. Cost: a scheduler, and a report nobody is obliged to read. +- **(b) Chamber-side `.precommit-triggers`.** Declare in `chamber-library` that a change under `canonical_texts/` runs a checker which greps the engine repo for the affected sha. Fires at the moment of the edit and needs no scheduler. ⚠ Requires the chamber hook to reach into a sibling repo, which couples them at a path — and fails silently if the engine is not cloned beside it. +- **(c) The PENDING-53 Option 3 tool as written** — a `reanchor` helper that, given a canonical, greps both repos for the old sha, updates all bindings and runs both gates. Repairs rather than detects; still requires someone to invoke it. +- **(d) Do nothing; the prose warnings stand.** Refuted by PENDING-116's own reasoning, and now additionally by the confidence asymmetry above. + +**Recommendation: (a) + (c), in that order, and NOT (b).** (a) because it is the only option that fires when there is no commit to hang a hook on, which is the defining feature of this class. (c) second because detection without a repair path just relocates the manual work; PENDING-53 already specified it. (b) rejected: a hook in one repo reaching into another reintroduces exactly the coupling REVIEWED-100 rejected when it refused to bake studium-engine's paths into the global hook. + +**Check that it worked — both directions required.** Re-hash a chamber canonical without touching the engine: the check must report drift naming all three binding surfaces. Then re-hash and correctly re-anchor: it must report clean. A drift detector that has never reported clean on a genuinely-clean corpus has not been shown to discriminate. + +**⚠ What this does not establish.** Neither (a) nor (c) makes anyone *read* the report. A scheduled check that fires into an unwatched log is the disarmed-tripwire class this repo already names, one layer out. Whether the report needs an escalation path is a real open question and is deliberately not answered here. + +**Files affected:** a new scheduled checker (home undecided — engine `scripts/` vs `~/dotfiles/scripts/`, and that placement is itself part of what needs ruling); `corpus/manifest.yaml` + `corpus/sidecars/*.meta.json` + `corpus/coverage-ledger.json` as read-only inputs. No gate acceptance changes. + +**Awaiting:** Steward authorization. + +--- + +### AMENDMENT 1 — 2026-08-08, on the steward's conditional authorization + +*Appended, not substituted: the body above is what was ruled on and stays legible. Where a stated reason is withdrawn it is struck here and the replacement named, per the REVIEWED-87 lesson that an amendment joins its record rather than replacing it.* + +**§A — Condition 1 accepted. (a) is authorized only jointly with a spec amendment; the item's `Files affected` was incomplete.** `graduation-spec.yaml` carries `engine_source_binding` as a **prose string**. A scheduled checker cannot consume it, so it must either hardcode the surfaces — creating a second home for one enumeration, which the hash-locality principle four lines below it forbids — or the spec gains a structured `surfaces:` list. `Files affected` therefore gains **`_curation/graduation-spec.yaml`**. Change-class: ratified convention-data → **[PROPOSAL]**, jurist design-gate, per the lane rule discussed at REVIEWED-53 (lane tracks change-class for machine-convention-data files). **Without it the fix reproduces the drift class one layer out.** + +**§B — Condition 2 accepted. The stated reason for rejecting (b) is WITHDRAWN.** ~~"a hook in one repo reaching into another reintroduces exactly the coupling REVIEWED-100 rejected"~~ — that is **borrowed authority and factually wrong**: REVIEWED-100 rejected coupling a *globally shared* hook to one repo's layout; (b) is a *repo-local declaration*, the authorized mechanism, whose command reaches a sibling path. Different object, different failure mode. **Recorded reason, which was already the item's own parenthetical and is the stronger one: (b) fails silently when the engine is not cloned beside the chamber — a detector that cannot see where the quarry lives, which is this item's own subject class.** Noted for the future: a rejection resting on borrowed precedent becomes precedent; cheap to correct now, expensive later. + +**§C — Condition 3 RESOLVED. The framing stands; the MECHANISM does not.** Checked: `git show --name-only 177e2b3` returns **exactly one file**, `reading-indices/alexander-a-pattern-language.yaml`, and **zero** under `canonical_texts/`; `shasum -a 256` of the live canonical equals the engine-declared `accf235d…`. So it **did not touch the engine's three-sha binding surface**, the item does not understate its case, and *"not a claim the trigger fired"* stands **uncorrected**. + +**Detection latency, now recorded as this item's key empirical number: 56 days** (partial re-anchor 2026-06-12 → repair 2026-08-07). This is the quantity the (a)-versus-(d) trade turns on, and it is the only measured one we have. + +⚠ **But the datum breaks the proposal's scope, and that is the finding.** Nothing hashes the reading index. Measured: `content_sha256` occurs **0 times** in its 689 lines; `source_sha256` occurs 3 times and binds **outward** to the canonical text; the manifest declares `reading_index:` (a path) and `reading_index_status: RE-ANCHORED-BOUND` (a **prose status**, which `177e2b3`'s own message calls out as having read bound-throughout while the file was stale in one region). **The binding runs index→text; nothing binds to the index.** Therefore **all three surfaces named in (a) and (e) would have read GREEN for the entire 56 days** — the proposal as filed is silent on the best-documented incident in the record. + +**Consequence: the surface list is FOUR, not three** — the reading index needs a content hash of its own, or the checker inherits the exact blindness that let this drift live. And an enumeration that was wrong the moment it was written is itself the argument for §A: it must be **declared data with one home**, never hardcoded in a consumer. + +**Also noted:** PENDING-111 is open on Alexander (`fidelity_equivalence@3`, escaped emphasis, 293 instances). With this item and the R0 region-verification gap, **three open threads now converge on one canonical.** + +**§D — Condition 4 accepted; (e) added and sequenced FIRST.** +- **(e) Check the binding shas unconditionally on every studium-engine commit**, in the hook REVIEWED-100 already landed. Not path-triggered — unconditional, milliseconds. **Fires where a human is already in the invocation path**, which is the gap PENDING-98 names and the gap this item's own ⚠ concedes (a) leaves open. +- **Measured, rather than assumed:** engine cadence over the last 30 commits is **median gap 0.01 d, mean 0.09 d, max 0.8 d**, repo `ahead 11`. So (e)'s latency during active work is **hours, not days**. ⚠ That sample spans two days and is a burst, not lifetime cadence — which is exactly why (a) is retained. +- **Revised sequence: (e) → (a) → (c)**, with **(a) demoted to backstop for the engine-quiet case** (the chamber moves while the engine is silent — where (e) cannot fire by construction). **(b) rejected on §B's corrected reason.** + +**§E — Condition 6 accepted. Placement: `~/dotfiles/scripts/`.** Steward's reasoning recorded: a cross-repo invariant is owned by neither repo, and putting it in either makes that repo the authority over a relationship it is only one half of. Convention data in the ratified spec (§A), thin consumer in dotfiles — the pattern REVIEWED-100 authorized. + +**§F — Condition 5 accepted. The second-order finding is REMOVED from this item** and filed as **PENDING-118** (`governance-drift-check.py` does not read archived PENDING bodies, so *"deferred decisions: N tracked, none due"* is structurally blind to every archived deferral). It concerned an instrument and all archived deferrals, not this item; filed inside a [PROPOSAL] it would have died with a DEFERRAL or REJECTION of its host. + +**Awaiting:** placement of the ruling. Build sequence on placement: **(e) → spec amendment (§A, jurist-gated) → (a) → (c)**. + +--- + +## PENDING-118 — The deferred-decision checker is structurally blind to every archived deferral + +**Date:** 2026-08-08 +**Tag:** [HARDENING] +**Related:** PENDING-117 §F (split from it on steward's condition 5) · **PENDING-108** (a jurist ruling is filed as a document only when someone remembers) · **PENDING-110** (`REVIEWED-N`/`PENDING-N` are independent sequences) — the same family: **the register's own instruments not reaching parts of the register.** + +**Summary.** `governance-drift-check.py` runs at every wake and reports, today, *"deferred decisions: 2 tracked, none due (2 checkable, 0 manual-only)"*. It reads `~/PENDING.md`. It does **not** read `~/PENDING-archive.md`. Every deferral inside a **closed** item is therefore invisible to it — and a deferral inside a closed item is the normal case, because an item is typically closed *by* a ruling that defers part of what it proposed. + +**How it surfaced — not by looking for it.** Chamber `_curation/graduation-spec.yaml` cites "PENDING-53" for the cross-repo binding gap. The citation **did not resolve** in the live register (`grep -c "^## PENDING-53" ~/PENDING.md` → 0). It resolved in the archive, where PENDING-53's ruling had deferred its Option 3 against a named condition. The checker had reported "none due" at that same wake, correctly by its own lights and uninformatively about the question. + +**Rationale.** A deferral is the claim *not yet*, carrying a condition that makes it *now*. Archiving the item does not retire the condition — it removes the only place anything looks for it. The instrument's silence therefore certifies the wrong set, and its output sentence (*"N tracked"*) reads as a census of deferrals when it is a census of deferrals **in one file**. That is Constraint #4 applied to the instrument: it does not report its own extent. It is also skill-harvest **#191**'s shape exactly — *a detector correct everywhere it looks, and not looking where the quarry lives* — which is the second instance of that shape in eight days and argues the pattern is worth treating as a class rather than a coincidence. + +**⚠ Size unmeasured, deliberately.** How many archived deferrals exist, and how many have conditions that have since fired, is **not known** — establishing it is part of the work, not a premise of it. PENDING-53 is one confirmed instance (condition *not* met on strict reading; see PENDING-117 §C). One instance is not a rate, and this item does not claim one. + +**Options.** +- **(1) Widen the scan to `~/PENDING-archive.md`.** Smallest change; the checker already parses that exact format. ⚠ Every archived deferral becomes a standing report line, so the first run needs a triage pass or it reports a wall. +- **(2) Widen the scan, plus a one-time census** classifying each archived deferral as condition-met / not-met / unconditional, so the standing report starts from a known baseline rather than a backlog. +- **(3) Require deferrals to be re-filed as live items at close time** — a discipline, not a mechanism. Rejected on this register's own evidence: it depends on someone remembering at exactly the moment attention is leaving the item. + +**Recommendation: (2).** (1) alone converts an invisible backlog into an unread one, which is the same failure wearing a report. The census is the thing that makes the widened scan legible on its first run, and it is bounded — the archive is a finite file. + +**Check that it worked — both directions required.** A known archived deferral whose condition HAS fired must be reported; one whose condition has NOT must stay silent. **PENDING-53 is available as the negative** (strictly read, its Making-batch condition is unmet), and it is a *real* archived instance rather than a synthetic fixture — which is the standard the discrimination gate demands. A positive requires finding one, and if the census finds **none**, that is a reportable result, not a failed build. + +**⚠ What this does not establish.** Widening the scan makes archived deferrals *visible*; it does not make anyone act on them, and it says nothing about deferrals living in the third place they occur — inside `~/REVIEWED.md` ruling bodies, which neither file's scan covers. Named, not absorbed. + +**Files affected:** `~/dotfiles/scripts/governance-drift-check.py`; a one-time census artifact (home to be decided with the ruling). + +**Awaiting:** Steward authorization. + +--- diff --git a/REVIEWED.md b/REVIEWED.md index e5e2cab..9e71dfc 100644 --- a/REVIEWED.md +++ b/REVIEWED.md @@ -1097,4 +1097,75 @@ nested inside a genuine delimiter pair separates correctly **Scope.** Disposes PENDING-114 only. REVIEWED-96, REVIEWED-97 and PENDING-115 are untouched; PENDING-115 remains a separate blocker on remediation step 3. -**Pacing.** Execution timing left to the executor as a proportionate-to-energy call, explicitly not decided by the substantive case above. \ No newline at end of file +**Pacing.** Execution timing left to the executor as a proportionate-to-energy call, explicitly not decided by the substantive case above. + +## REVIEWED-99 — PENDING-115 — Two mechanism defects blocking remediation step 3 +**Date:** 2026-08-08 +**Decision:** AUTHORIZED — (a1) and (b1), both before step 3. +**Notes:** Two of the cleaner items to come through today: each is a real, measured inconsistency between two internal registries that were supposed to agree and don't — ROLE_CLASS vs. SERVED_ROLES for (a), source-scoped vs. voice-scoped warrant query for (b) — not a design judgment call the way (vi) or PENDING-114 were. +(a1) over (a2): the chunker already treats quotation/translation as served in practice — that is not in dispute, it is measured. The fix makes the ledger's classification agree with what is already true, rather than inventing a fourth state. (a2)'s four-way vocabulary would be more faithful to something, but nothing here needs the extra category; D-4 prefers small closed vocabularies everywhere else this system touches, and that consistency is worth more than growing the vocabulary to solve a problem correct reclassification already solves. +(b1) over (b2): (b2) is not a live option — it is foreclosed by REVIEWED-97, which requires sub-source voices to exist at all. Named plainly: this defect is not a hypothetical edge case someone got cautious about, it is a defect (vi)'s own disposition directly creates. Good that it surfaced before step 3 rather than after. +No ordering dependency between (a1) and (b1) — different modules, different failure surfaces; both simply need to land before step 3 does. +The D-4-promise-not-implemented aside (citable:false really does mean unreachable, not just unindexed, contra the "config not migration" claim) is correctly left embedded rather than split out — it is explicitly non-actionable here, unlike Harrison/Mark, which was a live finding bearing on a different decision. A one-line tracking note is authorized so it does not quietly get treated as settled later; it does not need the full-entry treatment. +**If AUTHORIZED:** Proceed. Tag commits with REVIEWED-99. Each change carries the positive control named in the entry: for (a1), a quotation section in scope after the change and an apparatus section still out of it; for (b1), a two-voice source whose two voices return different scopes. Step 3 remains blocked until both have landed. + +## REVIEWED-100 — PENDING-116 — Run the fleet on the change that breaks it +**Date:** 2026-08-08 +**Decision:** AUTHORIZED — option (b), repo-declared trigger. +**Notes:** The cleanest justification of the three, because the cost of not having it already happened and was measured: a full day at 202/203 red, surviving two separate correction passes on the offending commit, caught by accident. That is not a risk being reasoned about in advance, it is a failure already logged. +(d) — rely on the discipline — is refuted by its own evidence, not merely argued against: the trap was named in CLAUDE.md and still did not fire, because naming a risk is not the same as mechanizing a check on it. That is the same lesson the harvest-routing thread landed on this morning for a completely different subsystem; two independent measurements of the same underlying fact in one day is worth noticing. +(b) is the right design among the three — (a) correctly rejected for coupling a shared global hook to one repo's layout, (c) correctly rejected for losing more than it gains. It reuses the declared-data-plus-thin-consumer pattern already established for graduation-spec.yaml rather than inventing a new mechanism, which is the right instinct architecturally. +The scope discipline is right and should not be pushed past: the cross-repo half (a chamber-library edit invalidating engine fixtures with no engine-side commit to hook into) is real and bigger, but needs a genuinely different mechanism — a scheduled source_sha256 check, not a commit hook — and trying to solve both here would likely land neither cleanly. It stays a named follow-on; its own PENDING number waits until the design is derived, which happens while building (b). +Sequencing note, not a condition: the Mauss re-tag (step 2 of the (vi) remediation) is itself a corpus edit in the same risk class 118f411 was. Landing 116 before or alongside that re-tag covers the very next edit this thread is about to make. +**If AUTHORIZED:** Proceed. Tag commits with REVIEWED-100. Both halves of the acceptance test are required — a triggering change refused, and a docs-only change that does not run the suites. + +## REVIEWED-101 — PENDING-117 — The cross-repo half: a chamber edit invalidates engine bindings with no commit on either side +**Date:** 2026-08-08 +**Decision:** AUTHORIZED WITH CONDITIONS — (e) + (a) + (c), sequenced (e) → (a) → (c); (b) REJECTED. +**Notes:** The scope as filed was incomplete and two stated reasons should not enter the record as they stood. + +1. The recommendation collides with the principle it protects. graduation-spec.yaml carries +engine_source_binding as prose. A scheduled checker cannot consume it, so it either hardcodes +the surfaces — a second home for one enumeration, which the hash-locality principle four lines +below forbids — or the spec gains a structured surfaces: list. That is an amendment to a +ratified document, [PROPOSAL] work on the convention-data layer, and Files affected did not +name it. CONDITION: authorize (a) only together with that amendment, or the fix reproduces +the drift class one layer out. + +2. The rejection of (b) is right; its stated reason is wrong. REVIEWED-100 rejected coupling a +globally shared hook to one repo's layout. (b) is a repo-local declaration — the authorized +mechanism — whose command reaches a sibling path. Different object, different failure mode. +The item's own parenthetical is the stronger objection and is the recorded reason: it fails +silently when the engine is not cloned beside the chamber, a detector that cannot see where +the quarry lives, which is this item's own subject class. A borrowed authority in a rejection +becomes precedent for the next rejection. + +3. Resolved before ruling: chamber 177e2b3 touched the reading index only, not the engine +binding surface, so the item stands as filed and the "not a claim the trigger fired" framing +needs no correction. 56 days of undetected partial re-anchor is recorded as the detection- +latency datum the (a)-versus-(d) trade turns on. The executor's check then found that no hash +covers the reading index at all, so the three named surfaces would have read green throughout +those 56 days: the surface list is four, not three. That an enumeration was wrong when written +is itself the argument for condition 1. + +4. (e), not on the item's list: check the binding shas unconditionally on every studium-engine +commit, in the hook REVIEWED-100 landed. Fires where a human is already in the invocation +path — the gap PENDING-98 names. It does not replace (a): if the chamber moves while the +engine is quiet, nothing fires. Measured cadence puts (e)'s latency in hours during active +work, against "whenever someone reads the log". (a) is demoted to backstop for the +engine-quiet case. + +5. The second-order finding is split out as PENDING-118. It concerns an instrument and all +archived deferrals; filed inside a [PROPOSAL] it dies if the host is deferred or rejected. +It sits with PENDING-108 and PENDING-110 as one family — the register's own instruments not +reaching parts of the register. + +6. Placement: ~/dotfiles/scripts/. A cross-repo invariant is owned by neither repo; putting it +in either makes that repo the authority over a relationship it is only one half of. Convention +data in the ratified spec, thin consumer in dotfiles — the pattern REVIEWED-100 authorized. + +**If AUTHORIZED:** Proceed in sequence (e) → spec amendment (condition 1, jurist design-gate) +→ (a) → (c). Tag commits with REVIEWED-101. The spec amendment gates (a), not (e): (e) reads +the engine's own manifest and sidecars and needs no cross-repo enumeration. Each stage carries +a both-directions control — drift reported when a binding is stale, clean reported on a +genuinely clean corpus. \ No newline at end of file diff --git a/claude/memory/MEMORY-reference.md b/claude/memory/MEMORY-reference.md index bacbfe8..ab8120f 100644 --- a/claude/memory/MEMORY-reference.md +++ b/claude/memory/MEMORY-reference.md @@ -1,3 +1,4 @@ +- [Session 2026-08-08 — `voice:` is the convocation key](session-2026-08-08-voice-is-the-convocation-key.md) — **The disposition that landed is not the one any single party drafted.** Grounded first, then read the twelve blocks *from the source* rather than their sidecar titles — which produced nearly every finding: **Surah LXIV not CXIV** (already propagated into two governance records, and it voided the jurist's worked note, built on a formula absent from the passage); **`quotation-poet-jurist` reclassified** by one footnote; the naming evidence for six of nine blocks sits **inside the fenced apparatus**, engine-unreachable. Option C **refuted by measurement** (omission → host voice). The steward's correction on language sent me back to `[^101]` and thence to **L850 — Mauss's own prose fenced inside the Havámál block**, missed by a check using **length as a proxy for authorship**. Corrected the jurist upward: their category pair belonged **out** of the convocation key (`glidden` spans 5 sources, `weil` 2 — measured). Caught `REVIEWED-113` before it entered the register (PENDING-110 rules the sequences independent). **REVIEWED-97 placed + verified clean · PENDING-114 authorized (b)+(c) · PENDING-115 filed · `824139d`.** 🔑 **Corrections ran in all three directions in one day** — and the fleet was still red the whole time. *(Demoted on promote at the 2026-08-08 night wrap.)* - [Session 2026-08-07 evening — retrieval is set by home](session-2026-08-07-evening-retrieval-is-set-by-home.md) — **The skill-harvest bite taken whole, at the cost of V2.** Register censused before compacting: claimed 177, **real 154** (55 rows were scraped table-headers; 123 of 129 cut mid-word) — but **lossless**, 124 = 124, so my drafted "nine are invisible" and "59% misattributed" were both **refuted by the count**. Rebuilt from the archive with exact `archive:L###` pointers; restored the verbatim four-stroke ruling my own rebuild had replaced with a paraphrase. **Skills pruned 63 → 12** after measuring **53 never invoked in 5 months** (plus a dir named from a **404 error body** and ten with **newlines in their names**); 51 quarantined reversibly. The finding under both: **retrieval is set by home, 0%–83%**. **PENDING-112 → jurist ruling → steward concurrence → REVIEWED-95 drafted in one session**; filing gate + ladder trial sentence landed, **falsifier wired not intended** (`transcripts 84`) — which exposed two defects in the deferral checker itself, incl. that it **never looked at `claude/governance/`**. Package passed containment **20/20, 10/10 controls absent**, after the checker caught my own **elision-as-contiguous** and **fabricated join**. 🔑 **8 of 8 fresh instruments at fault; the elegant symlink discriminator was 97% right and would have destroyed the 2 that mattered.** *(Demoted on promote at the 2026-08-07 night wrap.)* - [Session 2026-08-07 — the count found what the read did not](session-2026-08-07-the-count-found-what-the-read-did-not.md) — **Twelve commits, three repos.** MEMORY.md trimmed 19.9→16.7 KB · **N1** (tree, 4 primitives) · **R0** (one reading-index loader — the adapters had already diverged on 3 of 253 patterns with *neither* right) · **N2** (`0/22` was the wrong search space: gold anchors are DIVISIONS → **top-1 15/22**, ⚠ **and 5/5 false positives**, untuned) · **@3 corrected in place** under the PENDING-111 ruling, with **three measured findings refuting the package's own premises** · **D-5** (TEI deferred, proxy trigger retired, discriminator pre-registered) · two governance checkers (register-integrity + deferred-decision triggers) · three corpus voice-defects fixed (Alexander re-anchor + "Using this book" partition; **Thibon's introduction had been served as citable Weil**) · **V2's German blocker dissolved — the source was graduated 2026-07-09 and nobody looked for a month.** 🔑 **Every defect was found by a COUNT, none by a read; 3 of 3 new checkers were themselves at fault.** *(Demoted on promote at the 2026-08-07 evening wrap.)* - [Session 2026-08-04 evening — the instruments that never fired](session-2026-08-04-evening-the-instruments-that-never-fired.md) — **Census 02 run entire on the seven instruments census 01 left uncensused. The firing record divides by whether a HUMAN is in the invocation path** — not by age, quality or importance. `audit_cruft`/`verify_conversion`/`apply_char_glyphs` exemplary (a curator invokes them); `resolve_archived_source` healthy 349/349 with **zero** log entries (nobody invokes it); `verify-before-compose` fired **exactly twice** (07-17, 07-18) recoverable only from harness transcripts; studium `verify-quote` + `fidelity_equivalence@2` have **no production caller at all**. **The hook cannot fire on the constitution it protects** — the existing file's own `GROUNDED-IN:` disarms it, 31 of 59 guarded files. **The engine was asked a question for the first time** and certified *"genuine silence, not a gap"* on `grey zone` over **ten `gray zone` matches in Levi** (corpus American-spelled, steward Canadian); mechanism is wider — bare FTS tokens are **conjunctive**, so recall dies as a question lengthens. Falsifier held (`the quality without a name` is *correctly* silent). **PENDING-95..98 filed together; 96 AUTHORIZED + LANDED on the jurist's sharper wording** (mine reproduced the overclaim one size down) and **stays OPEN** — `retrieve.py` has **no test at all**. Built: the **engine tool-evolution log**, seeded, **§0 declaring what it cannot see**. Two of my own findings died to their controls. **PULLING THREAD: name Chamber V1's purpose and settle the thirteen as its voice-set** — my "just go use it" was punctured by the steward's cycle (*engine missing x → source not golden → no bounded scope*); the break was already in his own tracker unread since 07-28 (*purpose choice and corpus scope are ONE decision*). Verified at wrap: **13/13 engine shas match disk** — the thirteen are NOT the 1,297, and the criterion is **stability, not quality**. One named defect inside them (Musil's stale voice-purity sidecar, off by 6). diff --git a/claude/memory/MEMORY.md b/claude/memory/MEMORY.md index 65623f4..c8d378e 100644 --- a/claude/memory/MEMORY.md +++ b/claude/memory/MEMORY.md @@ -66,13 +66,13 @@ permalink: claude-memory/memory - Chamber-typography — *tracker not yet established*; moves live in per-session memories (2026-05-11 →) + `project-chamber-cruft-restoration.md` + `project-chamber-typography-mining-plan-2026-05-15.md`. ## Active Session -> ⛔ **(vi) IS RULED — REVIEWED-97 (PENDING-113). It is DECIDED but INAPPLICABLE.** Four slots, each one job: **identity `voice:`** (the *convocation key* — `retrieve.py` filters `d.voice = ?`, so one value IS one speaker; identity lives at the **work**, never a category) · **relation `quoted_by:`** · **category** (`traditional` / `non-individual-origin`, held **OUT** of the key) · **per-source prose note**. ⚠ **Nothing can be applied** until the `quotation-in` × `translation-of` composition is ruled — all twelve blocks are translated matter and `role` is single-valued. -> 🔑 **The error to not repeat:** a field that is a KEY cannot also be a CATEGORY. `voice: traditional` would have made the Havámál and the Mahābhārata **one convocable speaker**. Invisible from the taxonomy side; obvious from `retrieve.py`. -> ⚠ **Surah LXIV (at-Taghābun), NOT CXIV.** The sidecar title was wrong and it reached **REVIEWED-96, PENDING-113 and memory**. The *"Say"* (قُل) formula opens an-Nās and is **absent** from the passage Mauss quotes — do not reuse the old worked note. -> 🔴 **`test_navigate.py` is RED and has been for a day** — `118f411` split Mauss `body` → `body-01..13`, so the hardcoded node id is stale (invariant itself verified intact). **Fourth defect in a commit already corrected twice.** Re-run the fleet after any sidecar/corpus change. -> ⏳ **Steward-authorized, queued:** PENDING-114 **(b)+(c)** — validation phase FIRST (hand-score Harrison/Mark vs Weil's *mentions*) before any corpus claim. **REVIEWED-98 PLACED** (2026-08-08, verified clean). Blockers on step 3: **PENDING-115**. Also open: **PENDING-116** (run the fleet on the change that breaks it — repo-declared trigger; ⚠ does NOT close the cross-repo half). +> ✅ **The fleet is GREEN (204/204, 7/7 exit 0) and now RUNS ON THE CHANGE THAT BREAKS IT** — `.precommit-triggers` (`corpus/ | scripts/run-fleet.sh`) + the repo-blind global hook, acceptance proven **both directions**. ⚠ `--no-verify` steps over it — **tripwire, not boundary** — and **its only firings so far are its own acceptance probes.** +> 🔑 **The binding-surface enumeration is WRONG — three named, FOUR actual.** Nothing hashes the reading index (`content_sha256` **0** in 689 lines; `source_sha256` binds *outward*; the manifest carries a **prose** `reading_index_status`). **All three surfaces in (a)/(e) would have read GREEN through the 56-day partial re-anchor.** Everything REVIEWED-101 authorized consumes this enumeration. +> ⚠ **All five of the day's errors were in CHECKS, none in writes** — grep vocabulary · `tail -2` · inferred arithmetic · a probe anchored below its own counters · a census counting *mentions*. **Every one reduced the output before looking at it.** Remedy **(a) ADOPTED**: state the check's vocabulary alongside its result. +> ⏳ **Authorized + sequenced (REVIEWED-101):** **(e)** unconditional sha check in the hook — **buildable now**, needs no cross-repo enumeration → **graduation-spec amendment** (condition 1, **jurist-gated**, `/jurist-package`) → **(a)** → **(c)**; placement `~/dotfiles/scripts/`. Also **PENDING-115 (a1)+(b1)** before remediation step 3. +> 📌 **The deeper thread is untouched and still unruled:** `quotation-in` × `translation-of` — (vi) remains **decided but inapplicable**. Today went underneath it on purpose. -- [Session 2026-08-08 — `voice:` is the convocation key](session-2026-08-08-voice-is-the-convocation-key.md) — **The disposition that landed is not the one any single party drafted.** Grounded first, then read the twelve blocks *from the source* rather than their sidecar titles — which produced nearly every finding: **Surah LXIV not CXIV** (already propagated into two governance records, and it voided the jurist's worked note, built on a formula absent from the passage); **`quotation-poet-jurist` reclassified** by one footnote; the naming evidence for six of nine blocks sits **inside the fenced apparatus**, engine-unreachable. Option C **refuted by measurement** (omission → host voice). The steward's correction on language sent me back to `[^101]` and thence to **L850 — Mauss's own prose fenced inside the Havámál block**, missed by a check using **length as a proxy for authorship**. Corrected the jurist upward: their category pair belonged **out** of the convocation key (`glidden` spans 5 sources, `weil` 2 — measured). Caught `REVIEWED-113` before it entered the register (PENDING-110 rules the sequences independent). **REVIEWED-97 placed + verified clean · PENDING-114 authorized (b)+(c) · PENDING-115 filed · `824139d`.** 🔑 **Corrections ran in all three directions in one day** — and the fleet was still red the whole time. +- [Session 2026-08-08 night — the checks were the weak link](session-2026-08-08-night-the-checks-were-the-weak-link.md) — **Went underneath the pulling thread to build the mechanism it needs.** Fleet green + trigger landed (`eef81fa` · `088a171` · `c86b825`); acceptance **both directions** (a real `body-04` rename refused the commit and tripped `test_every_drawer_is_reachable`, 63/5779; docs-only ran nothing). **PENDING-117 filed then amended on six steward conditions · PENDING-118 split out · #192 collision → #194** with PENDING-116's misdirected citation repaired. The steward's datum (`177e2b3`, partial Alexander re-anchor undetected **56 days**) resolved into a **third** answer — it did *not* touch the binding surface, so the framing stood, **but it broke my scope** and exposed the fourth, unhashed one. Struck my own rejection of (b) as **borrowed authority** (REVIEWED-100 rejected a *global* hook coupling, not a repo-local declaration). 🔑 **Every write landed sound first time; all five errors were in checks — on a day whose whole subject was checks.** ## Historical reference → MEMORY-reference.md Older archived-session pointers and the stable reference layer (steward profile · project-state detail · L1/L2/Chamber inventories · legacy pending-work · reference-file list) live in [MEMORY-reference.md](MEMORY-reference.md) — consult on demand; not loaded at wake. Recent cross-session trajectory comes from the Active Session entry above + the recent `session-*.md` files (wake §2.b.1). diff --git a/claude/memory/knowledge-graph.jsonl b/claude/memory/knowledge-graph.jsonl index 2eaa2fb..57bdb74 100644 --- a/claude/memory/knowledge-graph.jsonl +++ b/claude/memory/knowledge-graph.jsonl @@ -622,3 +622,8 @@ {"subject": "three-party correction", "predicate": "drift-pattern-good-direction", "object": "RAN IN ALL THREE DIRECTIONS IN ONE DAY, which the differently-biased-checkers doctrine predicts but had not been observed doing. Jurist corrected executor (flat value -> two-job split). Executor corrected jurist (category placed in the convocation key), on evidence only substrate access yields. Steward corrected executor on a careless framing about language, which is what led to the L850 discovery. None of the three could have produced the result alone. Recorded as a single instance, proving nothing general — but the doctrine says to record evidence when it appears.", "valid_from": "2026-08-08", "valid_to": null, "confidence": 0.9, "source_file": "session-2026-08-08-voice-is-the-convocation-key.md", "extracted_at": "2026-08-08"} {"subject": "claude-code", "predicate": "drift-pattern", "object": "NAMED-A-REMEDY-CLASS-AND-CALLED-IT-DEPLOYED. Asked whether we could act rather than wait on a degraded instrument base-rate, I wrote 'act, don't wait' and listed three remedies — a pre-commit hook (an unauthorized PROPOSAL), a prospective-control count (a one-shot literal question that rotates out at the next wrap), and the ladder-ritual trial (MEASUREMENT, not a remedy at all). None was deployed. The steward's one-word challenge ('How?') was what exposed it. Rhetorical closure reads as mechanism precisely because a class plus three examples has the SHAPE of a plan. Test: for each named remedy, can you point at the thing that makes it fire without anyone remembering?", "valid_from": "2026-08-08", "valid_to": null, "confidence": 1.0, "source_file": "session-2026-08-08-voice-is-the-convocation-key.md", "extracted_at": "2026-08-08"} {"subject": "a one-shot measurement", "predicate": "prevention", "object": "IS NOT A PRIME-DIRECTIVE VIOLATION, and treating it as one would have removed the thing that replaced guessing. Steward raised the worry 2026-08-08 after a bad week; the resolution is that the counterfactual for a one-shot script is an ASSERTION, not a durable instrument — so its visible fault rate is an improvement over an unfalsifiable hunch, not a decline. The real violation is re-writing what is already banked (a link-resolution canary typed inline the same day, though it lives in /wake-up AND on the ladder). Diagnosis: TOO FEW PROMOTED, not too many built — and only the first is actionable. Now measured as the K column of /wrap-up section 8's Instruments field.", "valid_from": "2026-08-08", "valid_to": null, "confidence": 0.9, "source_file": "feedback-one-shot-instruments-are-proportionate.md", "extracted_at": "2026-08-08"} +{"subject": "claude-code", "predicate": "drift-pattern", "object": "THE CHECKS ARE THE WEAK LINK, NOT THE WRITES — five instances in one session, every write sound on first attempt. `grep 'Instruments field'` against `**Instruments** field` · `tail -2` over a summary whose [FAIL] sat above the fold · inferring the tally's arithmetic instead of reading `total = len(_results)` · an induced-red probe anchored BELOW the counters it had to precede (3 false negatives) · a duplicate census counting MENTIONS including ones written seconds earlier. The unifying mechanism: EVERY ONE REDUCED THE OUTPUT BEFORE LOOKING AT IT (a count, a tail, an aggregate, an inference). A reduction cannot show its own miscalibration. Test before trusting any check: have I looked at this output unreduced, once?", "valid_from": "2026-08-08", "valid_to": null, "confidence": 1.0, "source_file": "session-2026-08-08-night-the-checks-were-the-weak-link.md", "extracted_at": "2026-08-08"} +{"subject": "the discrimination gate's BOTH-DIRECTIONS requirement", "predicate": "prevention", "object": "CAUGHT THE CONTROL'S OWN DEFECT, which a one-direction probe would have misread as a code defect in three suites. The induced-red probe injected its failing check below the tally lines, so suites capturing `total` into a variable exited 0 while still printing the failure — red_names_failure=False on navigate/retrieve/verify_quote. Requiring BOTH red-names-it AND restored-is-clean is what localised the fault to the probe rather than the code. Banked lesson (REVIEWED-83 A1 / ladder gate-design) stopping a DIFFERENT failure class: instrument self-fault, not the property under test.", "valid_from": "2026-08-08", "valid_to": null, "confidence": 1.0, "source_file": "session-2026-08-08-night-the-checks-were-the-weak-link.md", "extracted_at": "2026-08-08"} +{"subject": "the corpus-to-engine binding surface", "predicate": "has-enumeration-defect", "object": "FOUR SURFACES, NOT THREE. The governed record (graduation-spec.yaml engine_source_binding) names manifest.yaml sha256, sidecars source_sha256, coverage-ledger.json. The READING INDEX is a fourth consumed surface and NOTHING HASHES IT: measured 2026-08-08, content_sha256 occurs 0 times in the Alexander index's 689 lines, source_sha256 occurs 3 times and binds OUTWARD to the canonical text, and the manifest carries only a path plus a prose `reading_index_status`. Consequence: a three-sha checker would have read GREEN for all 56 days of the partial Alexander re-anchor (2026-06-12 to 2026-08-07, chamber 177e2b3). The binding runs index->text; nothing binds to the index.", "valid_from": "2026-08-08", "valid_to": null, "confidence": 1.0, "source_file": "session-2026-08-08-night-the-checks-were-the-weak-link.md", "extracted_at": "2026-08-08"} +{"subject": "a differently-positioned reader", "predicate": "drift-pattern-good-direction", "object": "BROKE THE EXECUTOR'S SCOPE WHERE THE EXECUTOR'S OWN CHECKS COULD NOT. The steward supplied one datum the item had not cited (chamber 177e2b3) and required it resolved before ruling. Resolving it produced a THIRD answer neither of the steward's two branches predicted: the commit did not touch the binding surface (so the framing stood) but revealed the enumeration the proposal rested on was incomplete. Second same-day instance of the doctrine's positive case; recorded as evidence, proving nothing general.", "valid_from": "2026-08-08", "valid_to": null, "confidence": 0.9, "source_file": "session-2026-08-08-night-the-checks-were-the-weak-link.md", "extracted_at": "2026-08-08"} +{"subject": "governance-drift-check.py", "predicate": "has-blind-spot", "object": "DOES NOT READ ~/PENDING-archive.md, so its wake line 'deferred decisions: N tracked, none due' is a census of deferrals IN ONE FILE while reading as a census of deferrals. Every deferral inside a CLOSED item is invisible — and that is the normal case, because an item is typically closed BY a ruling that defers part of what it proposed. Surfaced only because a chamber YAML cited PENDING-53 and the citation failed to resolve live. Filed as PENDING-118 [HARDENING]; family with PENDING-108 and PENDING-110 — the register's own instruments not reaching parts of the register. Size unmeasured by design.", "valid_from": "2026-08-08", "valid_to": null, "confidence": 1.0, "source_file": "session-2026-08-08-night-the-checks-were-the-weak-link.md", "extracted_at": "2026-08-08"} diff --git a/claude/memory/session-2026-08-08-night-the-checks-were-the-weak-link.md b/claude/memory/session-2026-08-08-night-the-checks-were-the-weak-link.md new file mode 100644 index 0000000..4d9d943 --- /dev/null +++ b/claude/memory/session-2026-08-08-night-the-checks-were-the-weak-link.md @@ -0,0 +1,152 @@ +--- +name: session-2026-08-08-night-the-checks-were-the-weak-link +description: "Went underneath the pulling thread to build the mechanism it needs: the fleet is green and now runs on the change that breaks it (REVIEWED-100). Every write landed sound on first attempt and ALL FIVE of the day's errors were in CHECKS — grep vocabulary, tail truncation, inferred arithmetic, a probe anchored below its own counters, a census counting mentions. PULLING THREAD: the corpus↔engine binding surface enumeration is WRONG — three surfaces named, four actual, and the fourth is unhashed — and every stage REVIEWED-101 authorized consumes that enumeration." +metadata: + node_type: memory + type: project + originSessionId: 932b538a-4624-4ce7-8826-ecbd6b8d079f + modified: 2026-08-08T13:08:23.437Z +--- + +# Session 2026-08-08 (night) — the checks were the weak link + +Second session of the day, straight after a wrap. The steward's rulings on +PENDING-115/116 came first and reshaped the session before it started: they +turned an idle thread-blocked evening into an executable mechanism bite. + +## PAST — what moved, and why + +**The shape changed because a finding changed it, not because the authorizations did.** +Asked how 115+116 reshaped the session, I ran the fleet to confirm the red test and +read `tail -2`: `33/34 checks passed`. Nearly reported the fleet green — overturning a +*correct* banked finding on a bad read. Caught only because REVIEWED-100's design forced +the question *what is red, mechanically*. Exit codes: `exit=1`. **The summary enumerated +skips and not failures**, so the natural place to look showed a pass-fraction and a skip +roll-call while the `[FAIL]` sat above, unrestated. That, not the node id, was the finding. + +**Step 1 — the fleet, `eef81fa`.** The Scolie is now reached **by title within the Mauss +work**, not by a hardcoded id: a curatorial re-split is legitimate and touches nothing the +containment check tests, and requiring exactly one such division keeps a vanished or +duplicated Scolie failing loudly. All seven suites now name failures in the summary; +exit-code logic untouched, so acceptance is bit-identical and only the report gained. +Proven by **induced-red discrimination on all seven**, both directions required. + +**Step 2 — the trigger, `088a171` + `c86b825` (dotfiles).** `.precommit-triggers` declares +`corpus/ | scripts/run-fleet.sh`; the global hook stays repo-blind and delegates path +matching to git's own pathspec engine. Deliberately **dependency-free rather than YAML** — +`yq` is absent, the consumer is bash, and a global convention needing a toolchain silently +fails to travel. `scripts/run-fleet.sh` is new because **the repo had no canonical fleet +runner at all**, which is part of why running the suites depended on memory. +**Acceptance both directions:** a real `body-04` rename refused the commit and tripped +`test_every_drawer_is_reachable` (63 unreachable of 5779); a docs-only commit ran nothing. + +**Three governance filings, two of them corrections of my own record.** +- **PENDING-117** (cross-repo) filed, then amended on the steward's conditions. +- **PENDING-118** split out per condition 5 — the drift checker is blind to archived + deferrals; it belongs with PENDING-108/110 as *the register's instruments not reaching + parts of the register*, and inside a [PROPOSAL] it would have died with its host. +- **#192 collision resolved** → **#194**, PENDING-116's citation repaired (it had been + resolving to the wrong entry), the row's target corrected, status set **BUILT**. + +## PRESENT — how it stood + +**All five of the day's errors were in checks; every write was sound first time.** +`grep 'Instruments field'` against `**Instruments** field` · `tail -2` over a summary whose +failure sat above the fold · inferring `total`'s arithmetic instead of reading +`total = len(_results)` · an induced-red probe anchored *below* the counters it needed to +precede (three false negatives) · a duplicate census counting **mentions**, including the +ones I had written thirty seconds earlier. Not carelessness in the work: **reaching for a +check whose vocabulary I had not verified against the thing it must match.** + +**Diagnosed sharply, and it is not a missing rule.** All five **reduced the output before +looking at it** — a count, a tail, an aggregate, an inference. A reduction cannot show its +own miscalibration. Two ladder entries already cover this (*state what you did NOT +establish*; *discriminate between two REAL artifacts*) and **both are scoped to checks that +ship**. Every failure was a check that didn't ship. **The exemption is the bug** — so the +remedy is a scope widening, and writing a third copy would be the actual violation. + +**Steward chose remedy (a): state the check's vocabulary alongside its result.** Adopted +immediately and visible from that point on. It works by making *my* miscalibration +catchable by a **differently-positioned reader** rather than by me — which the evidence +favours: of the five, three were caught only because the work continued and forced me to +touch the thing again, one by implausibility, and exactly **one by design** (the both- +directions probe). + +**The steward's ruling on 117 broke my scope, which was the useful outcome.** Their datum — +chamber `177e2b3`, a partial Alexander re-anchor undetected **56 days** — resolved into a +*third* answer, not the two they offered. It did **not** touch the engine binding surface +(one file changed, the reading index; zero under `canonical_texts/`; live canonical sha == +declared `accf235d…`), so the item's framing stood **uncorrected**. But: **nothing hashes +the reading index** (`content_sha256` 0 occurrences in 689 lines; `source_sha256` ×3 all +pointing *outward*; the manifest carries a path and a **prose** `reading_index_status`). +**All three surfaces in (a)/(e) would have read GREEN for the entire 56 days.** The +enumeration is **four, not three** — and being wrong the moment it was written is the +sharpest argument for the steward's own condition 1: declared data, one home, never +hardcoded in a consumer. + +**I also had a rejection resting on borrowed authority.** I rejected option (b) as *"exactly +the coupling REVIEWED-100 rejected"* — factually wrong (that was a *globally shared* hook vs +a repo-local declaration). Struck visibly in the amendment rather than swapped, because a +rejection's reasoning becomes precedent whether or not it was sound. + +## FUTURE — what pulls + +> **PULLING THREAD — the binding-surface enumeration is wrong, and everything +> REVIEWED-101 authorized consumes it.** Three surfaces are named in the governed record; +> four exist; the fourth (the reading index) has **no hash anywhere in either repo** — +> it binds outward to the text, and nothing binds to it. The spec amendment that makes the +> enumeration machine-readable is condition 1 of the ruling and gates (a) and (c). Until +> the enumeration is *true*, a checker built on it inherits the exact blindness that let a +> partial re-anchor live 56 days. + +**ACTIONABLE RESUMPTION POINT (as of wrap — re-judge against what changed):** +``` +0. Nothing half-finished. studium-engine main clean, PUSHED. Fleet 204/204, 7/7 exit 0. + REVIEWED-99/100/101 placed; PENDING-115/117/118 open. +1. START WITH (e) — it is buildable NOW and needs no cross-repo enumeration: + unconditional sha check on every studium-engine commit, in the hook already landed + (~/dotfiles/git/hooks/pre-commit). Three engine-side surfaces: manifest sha256, + sidecar source_sha256, coverage-ledger. Milliseconds. Placement per condition 6: + ~/dotfiles/scripts/. Both-directions control required. + ⚠ Re-verify the hook from the substrate — its only evidence is my own acceptance + test from THIS session; do not inherit that frame. +2. THEN the graduation-spec amendment (condition 1, JURIST-GATED → /jurist-package): + engine_source_binding prose -> structured `surfaces:` list, and it must carry FOUR, + including a content hash for the reading index that does not yet exist. +3. THEN (a) scheduled checker, THEN (c) the reanchor repair tool. +4. SEPARATELY: PENDING-115 (a1)+(b1) before remediation step 3. (b1)'s control needs a + two-voice fixture — the honest source is the REAL weil-gravity-and-grace sidecar + (17 `voice: thibon` sections, unchunked only because citable:false). +``` + +**Other open horizons, ranked:** +- **[load-bearing, authorized]** the (e)→spec→(a)→(c) sequence above. +- **[load-bearing, authorized]** PENDING-115 (a1)+(b1). ⚠ `translation` carries the + identical `ROLE_CLASS` gap, latent **by absence** (0 `role: translation` sections exist). +- **[the deeper thread, unruled]** the `quotation-in` × `translation-of` composition + package — (vi) is still **decided but inapplicable**. Today went *underneath* it + deliberately; it has not moved and still gates the Mauss remediation and V2's fr gold. +- **[open, unruled]** PENDING-118 (archived deferrals invisible to the checker). +- **[owed]** skill-harvest **#190–#193** + the ladder scope-widening (**#195**, filed + tonight) — the dedicated short session the steward named. +- **[converging]** three open threads now sit on the Alexander canonical: PENDING-111 + (`fidelity_equivalence@3`, 293 escaped-emphasis instances), the R0 region-verification + gap (0 verified by fingerprint), and this item. + +**PAUSE STATEMENT:** I am putting this down at a genuine close — the mechanism bite was +taken all the way, both halves proven, nothing mid-arc, everything pushed. I stopped +*before* (e) deliberately: (e) modifies the same global hook I changed ninety minutes +earlier, whose entire evidence base is my own acceptance test from this session, and +building onto it now would let the second test inherit the first's assumptions. A cold +session re-derives that from the substrate. What I want to find still pulling is the +**enumeration** — because a checker built on a false surface list is the failure this whole +item exists to prevent, committed one layer up. The unease I carry is not about the work +but about the ratio: five errors, all in checks, on a day whose entire subject was checks. + +**LITERAL QUESTION for next-Claude** *(checkable — the record answers it, not introspection)*: +**Did the `.precommit-triggers` fleet gate fire on a real, non-probe commit — and did it +catch anything?** Today it fired twice, both times on probes I staged myself. A gate whose +only firings are its own acceptance test has not been shown to work in the field; that is +precisely the *silent net is uninformative* class, turned on the net we just built. If the +answer is *it has never fired*, ask whether the trigger path (`corpus/`) actually matches +where corpus work lands, or whether `--no-verify` is being reached for routinely. diff --git a/claude/memory/session-ledger-2026-08-08.md b/claude/memory/session-ledger-2026-08-08.md index d3e804f..95c2a96 100644 --- a/claude/memory/session-ledger-2026-08-08.md +++ b/claude/memory/session-ledger-2026-08-08.md @@ -5,7 +5,7 @@ metadata: node_type: memory type: feedback originSessionId: 7d08dad4-626a-484c-870b-8f1a9674db7a - modified: 2026-08-08T10:50:42.266Z + modified: 2026-08-08T11:54:21.195Z --- # Session Ledger — 2026-08-08 @@ -42,6 +42,57 @@ metadata: `harrison-dominion.md`, which does not exist (manifest **id** ≠ filename). Caught by a link-resolution canary *after* filing. Corrected in place with the divergence named. +--- + +### ⎯ SESSION 2 (context cleared ~11:00; same day, same ledger) ⎯ + +- **T~11:0x — wake: two findings from reading the surfaces rather than trusting them.** + (1) **`skill-harvest-register.md` carries a numbering collision** — two distinct live + proposals are both **#192**: the cited-vs-placed governance check (08-07 night, prose + entry) and the pre-commit fleet hook (08-08 wrap, table row). #193 already exists, so + the 08-08 row should be #194. Same shape as yesterday's `REVIEWED-113` catch, found one + step *later* — after filing, not before. Not corrected here: the register is the + steward-facing surface and renumbering a filed proposal is a governance edit, not a typo. + Surfaced for the steward's call. + (2) **This ledger's `Authorization moves` section is empty** on a day that placed + **REVIEWED-97 and REVIEWED-98** and filed **PENDING-114, -115, -116**. The section exists + precisely to record those. A say–do seam at the ledger's own layer: the instrument was + open all day and the moves went unrecorded in it. Recorded retrospectively below, marked + as such. + +- **T~11:3x — read a printed summary instead of an exit code, while diagnosing that class.** + Ran the fleet with `tail -2`, saw `33/34 checks passed`, and nearly reported the fleet + green — overturning a *correct* banked finding on a bad read. Caught only because + REVIEWED-100's design forced the question *what is red, mechanically*. Then compounded + it: told the steward the tally "counts the skip as a pass". It does not — `total = + len(_results)`, skips are a separate list. **Inferred instead of reading the code, in the + middle of naming the read-the-substrate class.** Corrected to the steward unprompted. + The real defect was narrower and stands: the summary enumerated skips and not failures. + +- **T~11:5x — the discrimination control caught its own defect.** The induced-red probe + anchored injection on `failures = [`, which sits *below* the tally lines, so in the three + suites that capture `total` into a variable the counters were frozen before the induced + failure existed → three false negatives. **Requiring BOTH directions is what surfaced it** + (a one-direction probe would have read 4/7 as a code defect). Re-anchored above the tally: + 7/7 discriminate. Recorded because the control failing *as a control* is the outcome the + discrimination gate is for, not an embarrassment. + +- **T~12:0x — a repo doc's citation opened a closed item whose deferral had come due.** + chamber `graduation-spec.yaml` cites "PENDING-53" for the cross-repo binding gap. Not in + `~/PENDING.md` — it is **archived**, ruled REVIEWED-53 2026-07-10 with a *documentation* + remedy; its Option 3 (the actual mechanism) was deferred **pending recurrence**. The + archived body describes the July incident as *"caught only by chance"* — the same sentence + fits `118f411`. **Two instances, one month apart.** I had advised the steward to let this + wait; that advice was wrong on the facts and was corrected in the same turn. ⚠ Second-order: + the wake's deferred-decision checker does not read **archived** PENDING bodies — harvest + #191's shape (correct everywhere it looks, not looking where the quarry lives). + +- **Instruments counter (for /wrap-up §8), session 2:** **1 run** (`induced_red_control.py`) + · **1 with a control written before first execution** (the property — *a failing check is + named in the summary* — was stated before the probe ran, and both directions were required + from the start, which is what caught the probe's own anchor bug) · **0 duplicating + something already banked**. + ## What held - The inherited prospective-control question (1 of 12) is carried forward as a live counter, @@ -65,6 +116,39 @@ metadata: ## Authorization moves +*Recorded retrospectively at session-2 init from the session memory, **not logged live** — +the omission is itself the finding above.* + +- **REVIEWED-97 (PENDING-113)** — disposition (vi). Drafted by executor, corrected by jurist, + corrected upward by executor, **placed by steward**. Verified clean (single heading, seven + load-bearing parts). Filed at 97 not 113 per PENDING-110's independent-sequence rule. +- **REVIEWED-98 (PENDING-114)** — scripture quoted inside a host text. Steward **AUTHORIZED + (b)+(c)**; placed same day, verified clean (L1080, 8/8 parts). +- **PENDING-115** filed `[HARDENING]` — two mechanism defects blocking remediation step 3. +- **PENDING-116** filed `[PROPOSAL]` — run the fleet on the change that breaks it. +- **PENDING-117** filed `[PROPOSAL]` — the cross-repo half, resuming PENDING-53 Option 3. + Filed on **corrected** grounds: the literal deferral condition ("recurs across the ~30-source + Making batch") is **NOT** met, `118f411` is the same-repo analog rather than a second + cross-repo instance, and REVIEWED-73's "5 standing FAILED rows" are **repaired** + (`validated: 14, failures: []`). The real argument is the confidence asymmetry: building + half a gate raises confidence faster than coverage, and the surface that *demonstrates* + the protection is now the surface that hides its extent. +- **Numbering collision RESOLVED:** the 08-08 hook row renumbered **192 → 194** (the later + filing yields; #192 and #193 were both held from 08-07 night), PENDING-116's `Related:` + citation repaired, the row's *target* corrected (it named `.git/hooks/` — the hook is + global via `core.hooksPath`), and its status set **BUILT** with commits. Census by + mechanism: **#190–#194, one filing each.** +- **Awaiting, unauthorized:** skill-harvest **#190, #191, #192, #193** (#194 is BUILT). + +- **T~12:2x — the day's failures concentrate in CHECKS, not in writes.** Five instances now, + all verification-vocabulary: `grep 'Instruments field'` against `**Instruments** field` · + `tail -2` over a summary whose failure sat above the fold · inferring the tally's arithmetic + instead of reading `total = len(_results)` · the induced-red probe anchored below the + counters · and a duplicate-census counting *mentions* including the ones I had just written. + Every write this session was sound on first attempt. **The signal is not carelessness in the + work; it is that I reach for a check whose vocabulary I have not verified against the thing + it must match** — the substrate-vs-description class, pointed at my own instruments. + ## Sub-agent dialogues ## Bypasses diff --git a/claude/memory/skill-harvest-register.md b/claude/memory/skill-harvest-register.md index 697c167..ae51383 100644 --- a/claude/memory/skill-harvest-register.md +++ b/claude/memory/skill-harvest-register.md @@ -1,13 +1,12 @@ --- name: skill-harvest-register-proposed-skills-awaiting-steward-authorization -description: Standing register of skill create/patch/retire proposals surfaced by - /wrap-up §1.6, awaiting steward authorization. The governed analog of PENDING.md, - turned on our own tooling — propose → authorize → build → record. Surfaced every - wake via this MEMORY entry. -metadata: +description: "Standing register of skill create/patch/retire proposals surfaced by /wrap-up §1.6, awaiting steward authorization. The governed analog of PENDING.md, turned on our own tooling — propose → authorize → build → record. Surfaced every wake via this MEMORY entry." +metadata: node_type: memory + permalink: claude-memory/skill-harvest-register type: reference -permalink: claude-memory/skill-harvest-register + originSessionId: 932b538a-4624-4ce7-8826-ecbd6b8d079f + modified: 2026-08-08T11:53:32.970Z --- # Skill-harvest register @@ -290,8 +289,30 @@ is evidence about the home, not about the lesson. ### 2026-08-08 wrap — one proposal, firing moment declared per the REVIEWED-95 gate +> **⚠ RENUMBERED 192 → 194, 2026-08-08.** This row was filed as `#192`, which was already +> held by the cited-vs-placed governance check filed the previous night (`#192`, above); +> `#193` was likewise taken, so the next free number is **194**. The collision was live, not +> cosmetic: **PENDING-116 cited "skill-harvest register #192"** meaning *this* row, and that +> citation resolved to the wrong entry — the exact failure PENDING-110 names, where a number +> pointing at two things entrenches a false expectation. The **later** filing was renumbered +> so the earlier claimant keeps its number; PENDING-116's `Related:` line was corrected to +> `#194` in the same pass. Recorded rather than silently fixed, because a renumbered +> proposal is the kind of change a reader must be able to trace. + | # | Target | Kind | Content | Firing moment | Evidence | Status | |---|---|---|---|---|---|---| -| 192 | `studium-engine/.git/hooks/pre-commit` (+ chamber-library's) | **extend an existing hook** — NOT a new skill | When a commit touches `corpus/` or `corpus/sidecars/`, run the test fleet and refuse on red. The hook already exists and already runs ("Pre-commit checks passed!"); it does not run the suites. | **Mechanical, and should always fire** — the top row of the routing table. Requires no executor recall, which is the whole point: the knowledge was already banked and still did not fire. | 2026-08-08. `118f411` split the Mauss `body` section into `body-01..13`, breaking `test_navigate.py`'s hardcoded node id. The fleet sat **202/203 red for a full day**, through **two separate rounds of correction to that very commit** (REVIEWED-96's findings, then the L850 discovery), and surfaced only because the steward asked an unrelated question about instrument base-rate. A sidecar edit is a *corpus* change that silently invalidates *engine* fixtures — the cross-repo binding surface studium-engine's own CLAUDE.md names as a re-anchor trap. | PROPOSED | +| 194 | ⚠ *filed as* `studium-engine/.git/hooks/pre-commit` — **wrong, and corrected by PENDING-116 on reading the substrate:** the hook is global at `~/dotfiles/git/hooks/pre-commit` via `core.hooksPath`, so the trigger had to become **repo-declared** (`.precommit-triggers`) rather than baked in | **extend an existing hook** — NOT a new skill | When a commit touches `corpus/` or `corpus/sidecars/`, run the test fleet and refuse on red. The hook already exists and already runs ("Pre-commit checks passed!"); it does not run the suites. | **Mechanical, and should always fire** — the top row of the routing table. Requires no executor recall, which is the whole point: the knowledge was already banked and still did not fire. | 2026-08-08. `118f411` split the Mauss `body` section into `body-01..13`, breaking `test_navigate.py`'s hardcoded node id. The fleet sat **202/203 red for a full day**, through **two separate rounds of correction to that very commit** (REVIEWED-96's findings, then the L850 discovery), and surfaced only because the steward asked an unrelated question about instrument base-rate. A sidecar edit is a *corpus* change that silently invalidates *engine* fixtures — the cross-repo binding surface studium-engine's own CLAUDE.md names as a re-anchor trap. | **BUILT 2026-08-08** — routed through the register to `PENDING-116` → **REVIEWED-100** (authorized option (b), repo-declared trigger). Landed `088a171` (`.precommit-triggers` + `scripts/run-fleet.sh`) and `c86b825` (dotfiles, generic hook block); prerequisite green fleet `eef81fa`. Acceptance proven **both directions**. ⚠ Closes the **same-repo** half only — cross-repo filed as **PENDING-117**. | **Deliberately NOT proposed, and the reason is the finding.** The obvious second candidate — *"any one-shot script carries a positive control derived from the property, run before its output is read"* — **is already banked**, at `reference-verification-ladder.md` §Gate design: *"Derive fixtures from the property; draw them from real artifacts."* It is what diagnosed **both** of today's proxy-control failures. Filing it again would be duplication dressed as diligence. **The gap is the firing moment, not the knowledge** — which is PENDING-112's thesis, and this session is a third data point for the ladder-ritual trial rather than a reason to write a fourth copy of the rule. + +### 2026-08-08 night wrap — one new proposal, one extension; firing moments declared per the REVIEWED-95 gate + +**#195 — ladder patch: widen two existing entries from *checks that ship* to *any check whose result is stated*.** This is a **scope correction on banked rules, not a new rule** — and that distinction is the finding. `reference-verification-ladder.md` §Gate design already carries *"Every check states, in its own output, what it did NOT establish… A check that cannot name its gap **does not ship**"* and *"A check must discriminate between two REAL artifacts."* Both read as governing **built gates**. All five of this session's errors were checks that *didn't* ship — a `grep -c`, a `tail -2`, an inferred arithmetic, a probe anchor, a mention-census — and that exemption is precisely where they lived. Proposed additions: (i) the scope sentence, and (ii) the mechanical formulation that covers all five and is stated nowhere — ***every one of them reduced the output before looking at it; a reduction cannot show its own miscalibration.*** Inverse twin of the banked *"Count first, then look."* +**Firing moment: on a condition the executor must notice** — the weakest row, and **declared as such rather than dressed up**. There is no mechanical detector for *"you are about to trust a check you just typed."* Routed to the ladder because it is the correct home for the two entries it amends, and the ladder **now has a wake trigger** (REVIEWED-95's trial sentence). **Recorded estimate: unknown, pending the 20-session trial.** ⚠ The steward has already **adopted the practical half** — *state the check's vocabulary alongside its result* — which works by making a miscalibration catchable by a **differently-positioned reader** rather than by the author; that half needs no retrieval because it happens while composing a sentence already being written. This filing is for the ladder's record, not for the practice's operation. +**Classification: `[PROPOSAL]`** — it changes what the executor must do before asserting (latitude clause). **Status: PROPOSED.** + +**Extension to #192 (NOT a new number) — add placed-record *well-formedness* to the cited-vs-placed check.** #192 proposes asserting that every cited `REVIEWED-N` is **occupied**. Rule of three fired today: I hand-typed a placement verification **three times** (REVIEWED-99, -100, -101) — heading uniqueness · the four structural parts present · a double-header canary. That is the same instrument written three times, which is the banked violation, and its natural home is #192's checker rather than a fourth copy. **Deliberately filed as an extension so the two are ruled and built together**, per the steward's standing preference to keep the open-thread count low. +**Firing moment: mechanical, should always fire → `governance-drift-check.py`**, already named in a `/wake-up` step (the measured 83% home class) and already performing register-integrity checks. **Three real positives available**, not synthetic: today's three placements, plus the historical REVIEWED-87 amendment-overwrite and the malformed `## REVIEWED-95## REVIEWED-95` header #192 already cites. +**Status: PROPOSED**, to be ruled with #192. + +**No FIX-lane changes were applied this session.** All skill/tooling edits this session were either governed records (`PENDING.md`, the register, memory files) or authorized builds under REVIEWED-100 — none were self-tending edits to a skill.