session 2026-08-08 night: REVIEWED-99/100/101 placed; PENDING-117 amended + PENDING-118 filed; harvest #192 collision -> #194, #195 filed

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01A35wiD55yRHj5U1ECZAX4t
This commit is contained in:
David F Glidden
2026-08-08 15:11:29 +02:00
co-authored by Claude Opus 5
parent c86b82512b
commit ac4745b599
8 changed files with 444 additions and 16 deletions
+72 -1
View File
@@ -1097,4 +1097,75 @@ nested inside a genuine delimiter pair separates correctly
**Scope.** Disposes PENDING-114 only. REVIEWED-96, REVIEWED-97 and PENDING-115 are untouched; PENDING-115 remains a separate blocker on remediation step 3.
**Pacing.** Execution timing left to the executor as a proportionate-to-energy call, explicitly not decided by the substantive case above.
**Pacing.** Execution timing left to the executor as a proportionate-to-energy call, explicitly not decided by the substantive case above.
## REVIEWED-99 — PENDING-115 — Two mechanism defects blocking remediation step 3
**Date:** 2026-08-08
**Decision:** AUTHORIZED — (a1) and (b1), both before step 3.
**Notes:** Two of the cleaner items to come through today: each is a real, measured inconsistency between two internal registries that were supposed to agree and don't — ROLE_CLASS vs. SERVED_ROLES for (a), source-scoped vs. voice-scoped warrant query for (b) — not a design judgment call the way (vi) or PENDING-114 were.
(a1) over (a2): the chunker already treats quotation/translation as served in practice — that is not in dispute, it is measured. The fix makes the ledger's classification agree with what is already true, rather than inventing a fourth state. (a2)'s four-way vocabulary would be more faithful to something, but nothing here needs the extra category; D-4 prefers small closed vocabularies everywhere else this system touches, and that consistency is worth more than growing the vocabulary to solve a problem correct reclassification already solves.
(b1) over (b2): (b2) is not a live option — it is foreclosed by REVIEWED-97, which requires sub-source voices to exist at all. Named plainly: this defect is not a hypothetical edge case someone got cautious about, it is a defect (vi)'s own disposition directly creates. Good that it surfaced before step 3 rather than after.
No ordering dependency between (a1) and (b1) — different modules, different failure surfaces; both simply need to land before step 3 does.
The D-4-promise-not-implemented aside (citable:false really does mean unreachable, not just unindexed, contra the "config not migration" claim) is correctly left embedded rather than split out — it is explicitly non-actionable here, unlike Harrison/Mark, which was a live finding bearing on a different decision. A one-line tracking note is authorized so it does not quietly get treated as settled later; it does not need the full-entry treatment.
**If AUTHORIZED:** Proceed. Tag commits with REVIEWED-99. Each change carries the positive control named in the entry: for (a1), a quotation section in scope after the change and an apparatus section still out of it; for (b1), a two-voice source whose two voices return different scopes. Step 3 remains blocked until both have landed.
## REVIEWED-100 — PENDING-116 — Run the fleet on the change that breaks it
**Date:** 2026-08-08
**Decision:** AUTHORIZED — option (b), repo-declared trigger.
**Notes:** The cleanest justification of the three, because the cost of not having it already happened and was measured: a full day at 202/203 red, surviving two separate correction passes on the offending commit, caught by accident. That is not a risk being reasoned about in advance, it is a failure already logged.
(d) — rely on the discipline — is refuted by its own evidence, not merely argued against: the trap was named in CLAUDE.md and still did not fire, because naming a risk is not the same as mechanizing a check on it. That is the same lesson the harvest-routing thread landed on this morning for a completely different subsystem; two independent measurements of the same underlying fact in one day is worth noticing.
(b) is the right design among the three — (a) correctly rejected for coupling a shared global hook to one repo's layout, (c) correctly rejected for losing more than it gains. It reuses the declared-data-plus-thin-consumer pattern already established for graduation-spec.yaml rather than inventing a new mechanism, which is the right instinct architecturally.
The scope discipline is right and should not be pushed past: the cross-repo half (a chamber-library edit invalidating engine fixtures with no engine-side commit to hook into) is real and bigger, but needs a genuinely different mechanism — a scheduled source_sha256 check, not a commit hook — and trying to solve both here would likely land neither cleanly. It stays a named follow-on; its own PENDING number waits until the design is derived, which happens while building (b).
Sequencing note, not a condition: the Mauss re-tag (step 2 of the (vi) remediation) is itself a corpus edit in the same risk class 118f411 was. Landing 116 before or alongside that re-tag covers the very next edit this thread is about to make.
**If AUTHORIZED:** Proceed. Tag commits with REVIEWED-100. Both halves of the acceptance test are required — a triggering change refused, and a docs-only change that does not run the suites.
## REVIEWED-101 — PENDING-117 — The cross-repo half: a chamber edit invalidates engine bindings with no commit on either side
**Date:** 2026-08-08
**Decision:** AUTHORIZED WITH CONDITIONS — (e) + (a) + (c), sequenced (e) → (a) → (c); (b) REJECTED.
**Notes:** The scope as filed was incomplete and two stated reasons should not enter the record as they stood.
1. The recommendation collides with the principle it protects. graduation-spec.yaml carries
engine_source_binding as prose. A scheduled checker cannot consume it, so it either hardcodes
the surfaces — a second home for one enumeration, which the hash-locality principle four lines
below forbids — or the spec gains a structured surfaces: list. That is an amendment to a
ratified document, [PROPOSAL] work on the convention-data layer, and Files affected did not
name it. CONDITION: authorize (a) only together with that amendment, or the fix reproduces
the drift class one layer out.
2. The rejection of (b) is right; its stated reason is wrong. REVIEWED-100 rejected coupling a
globally shared hook to one repo's layout. (b) is a repo-local declaration — the authorized
mechanism — whose command reaches a sibling path. Different object, different failure mode.
The item's own parenthetical is the stronger objection and is the recorded reason: it fails
silently when the engine is not cloned beside the chamber, a detector that cannot see where
the quarry lives, which is this item's own subject class. A borrowed authority in a rejection
becomes precedent for the next rejection.
3. Resolved before ruling: chamber 177e2b3 touched the reading index only, not the engine
binding surface, so the item stands as filed and the "not a claim the trigger fired" framing
needs no correction. 56 days of undetected partial re-anchor is recorded as the detection-
latency datum the (a)-versus-(d) trade turns on. The executor's check then found that no hash
covers the reading index at all, so the three named surfaces would have read green throughout
those 56 days: the surface list is four, not three. That an enumeration was wrong when written
is itself the argument for condition 1.
4. (e), not on the item's list: check the binding shas unconditionally on every studium-engine
commit, in the hook REVIEWED-100 landed. Fires where a human is already in the invocation
path — the gap PENDING-98 names. It does not replace (a): if the chamber moves while the
engine is quiet, nothing fires. Measured cadence puts (e)'s latency in hours during active
work, against "whenever someone reads the log". (a) is demoted to backstop for the
engine-quiet case.
5. The second-order finding is split out as PENDING-118. It concerns an instrument and all
archived deferrals; filed inside a [PROPOSAL] it dies if the host is deferred or rejected.
It sits with PENDING-108 and PENDING-110 as one family — the register's own instruments not
reaching parts of the register.
6. Placement: ~/dotfiles/scripts/. A cross-repo invariant is owned by neither repo; putting it
in either makes that repo the authority over a relationship it is only one half of. Convention
data in the ratified spec, thin consumer in dotfiles — the pattern REVIEWED-100 authorized.
**If AUTHORIZED:** Proceed in sequence (e) → spec amendment (condition 1, jurist design-gate)
→ (a) → (c). Tag commits with REVIEWED-101. The spec amendment gates (a), not (e): (e) reads
the engine's own manifest and sidecars and needs no cross-repo enumeration. Each stage carries
a both-directions control — drift reported when a binding is stale, clean reported on a
genuinely clean corpus.