[PROPOSAL] Fool seed rule filed before the beacon; two unresolvable values caught (PENDING-149)

§4 steps 1-4 discharged and pushed ahead of the 2026-08-25T12:00:00Z beacon:
ratified axes recorded in writing, seed derivation rule filed, retirement and
regeneration criteria filed, derivation implemented and self-tested.

Two values in the jurist's §6b block did not resolve, and both are corrected in
the open rather than absorbed:

  - the provenance commit's stated rationale was false. 3b0730d5 (2026-08-06)
    postdates the fool's conception by five days, its subject names the
    PENDING-89 docket, and Constraint 6 is already in it. Steward directed
    4d2ae87 (2026-07-28), where Constraint 6 occurs zero times.

  - the retrieval URL returns HTTP 302 and an empty body, redirecting to an
    HTML page. Filed verbatim, the 25th would have produced no pulse and the
    UNAVAILABILITY clause would have run a 24-hour retry against an address
    that can never return one. Found only because §6b directs a historical
    dry run.

Also measured: outputValue is served UPPERCASE, so the rule's "lowercased
before use" is load-bearing; and curl reaches the beacon where python urllib
times out.

Nothing derived. Target pulse not fetched. CLAUDE.md untouched (PENDING-150).

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JQKeKY9T9d95KpvHwwok8T
This commit is contained in:
David F Glidden
2026-08-22 20:52:12 +02:00
co-authored by Claude Opus 5
parent 7b366eb646
commit acfbb9fc0e
9 changed files with 1606 additions and 2 deletions
@@ -0,0 +1,257 @@
---
name: BUDDY-PATTERN-jurist-draft-2026-08-22
description: "Jurist draft, 2026-08-22 — executor instructions for the Fool as a buddy-pattern fourth position. NOT AUTHORIZED. Filed verbatim as received; PENDING-149 ([PROPOSAL]) and PENDING-150 ([ESCALATE], §11 only) carry the executor's response. Supersedes the trial programme's object, not its record."
metadata:
node_type: governance-artifact
type: reference
provenance: "Received from the jurist via the steward, 2026-08-22. Stored verbatim. Executor commentary lives in PENDING, never in this file."
---
# Executor instructions — the Fool (buddy pattern)
> **STORED VERBATIM AS RECEIVED.** Nothing in this file is executor-authored. The
> executor's contested points, the §8a answer and the §8 frequency measurement are
> filed under PENDING-149; §11 is filed separately under PENDING-150 and must not be
> bundled with it.
Prepared by the jurist, 2026-08-22, at the steward's request. **Not authorized.**
File as `[PROPOSAL]`; see §11 for the part that is `[ESCALATE]` and must not be
bundled with it.
---
## 1 · What this is
A fourth position in the working cycle, built on the Claude Code `/buddy`
architecture. Ambient, event-triggered, one line at a time, addressed to the
steward alone. It produces no findings, opens no items, and no ruling turns on
it.
It is safe **without being checkable**, because nothing follows from it. This
inverts the standing correction of 2026-08-02 — *findings earn a hearing by
being checkable, never by role* — which is correct for findings and
inapplicable here: a position that makes no claims is not subject to a warrant
test. Do not build a checkability gate into this.
## 2 · What it is NOT
- Not a checker, auditor, reviewer, or devil's advocate. **If its output can be
graded, the design has failed.**
- Not the Fool trial programme. Trials 01–09 measured a checker; this is a
different object. Do not reuse their instruments, grading vocabulary, corpus,
partitioning, or ground truth.
- Not an answer to Constraint 6. See §11.
## 3 · Reference implementation — scope limited
Reference: `https://github.com/milind-soni/claude-pets` — a third-party
extraction of Claude Code's buddy system.
**TAKE:**
- the derivation chain (FNV-1a → Mulberry32 → stat draws, peak/dump assignment);
- the idle cadence table and its proportions;
- the fresh-overrides-stored rule.
**DO NOT TAKE:** species, rarity tiers, shiny, hats, eyes, sprites, animation
frames, petting, the canned reaction strings, or the buddy's own stat set
(`DEBUGGING / PATIENCE / CHAOS / WISDOM / SNARK` — superseded by §5).
⚠ **Rarity in particular is a gacha mechanic: it scales stat FLOORS.** A floor
softens the dump, and the dump is the entire point. Do not port it.
**Provenance:** third-party extraction, not Anthropic documentation. Verify the
derivation behaves as described rather than trusting the README. Once the seed
rule is filed under §4, **the filed rule governs** — a quirk in someone's
extraction must not become constitutional by accident.
## 4 · Pre-registration order — MANDATORY
The order is load-bearing. Each step is committed and pushed before the next
begins.
1. Perception axes ratified by the steward (§5).
2. Seed derivation rule filed, naming a **future** timestamp (§6).
3. Abandonment criterion filed (§10).
4. Regeneration criterion filed (§10).
5. Timestamp passes; seed computed; bones derived.
6. Soul generated once from the bones (§7).
Steps 1–4 must be complete and pushed **before** step 5. Axes chosen after the
seed is known, or with a fool in hand, smuggle the selection one level up.
## 5 · Perception axes — jurist proposal, steward ratifies
Five axes on 0–100. Each is something the fool could be **blind to**. The
steward must be able to imagine a dump on any one costing him something; if not,
it is not a real axis and should be replaced before ratification.
- **SUCCESSION** — would this be legible to someone arriving cold, with no thread?
- **ABSENCE** — what is not here, not asked, not yet existing?
- **AIM** — is this the right question, at the right level?
- **SCALE** — is the unit right? (item vs block vs programme)
- **STAKE** — who bears the cost if this is wrong?
*Jurist note, disclosed:* the steward has said his prior buddy was strong on
pattern recognition and debugging. No axis above is drawn from that, on purpose.
Adding one now would be selection toward a known preference.
**Register properties — terseness, snark, obliquity, chaos — are NOT axes.**
They belong to the soul (§7) and are not seeded independently. The dump must be
a blind spot, not a style: a fool that is merely predictable is blind to
nothing.
## 6 · Bones
- **Seed:** SHA-256 of a public value that does not exist at filing time. The
steward names the source and timestamp — NIST Randomness Beacon or equivalent.
- **Derivation:** seed → FNV-1a → Mulberry32 → stat draws.
- One **peak** (near max), one **dump** (near floor), three scattered.
- Recomputed fresh every session from the seed. **Never cached.** A stored value
that disagrees with the fresh computation loses.
- **No rerolls.** The first output is the fool.
The dump stat is the point, not a side effect. It is the only guaranteed
difference this position has, and the seed — not the steward — decides where the
hole goes. Do not add a floor that softens it.
## 7 · Soul
Character and register generated **once** from the bones, stored permanently,
never hand-edited and never regenerated for taste. One generation, kept.
## 8 · Cadence and triggers
Fixed table, adapted from the buddy's idle cycle: approximately **73% silent,
20% brief aside, 7% notable.** Hardcoded. Neither the fool nor the steward can
tune it.
⚠ *Rationale, and this is the part most likely to be lost in implementation:* a
fool that decides when to escalate will learn from being heard or muted and
drift toward speaking when it expects attention. That is the contamination
gradient arriving through the one position built to resist it. **The cadence
must be unlearnable.**
Triggers are **EVENT-keyed, never content-keyed.** It fires on occurrences —
item filed, ruling recorded, proposal amended, census run, wake, wrap-up — and
never on an assessment of whether the thing is any good. **Do not implement
quality evaluation of any kind.**
Wake and wrap-up are guaranteed fire points. Observed drift consolidates at
session seams, not at gates.
⚠ **Sanity-check the proportions against real event frequency before
implementing.** If the cycle fires forty events a day, 7% notable is five
interruptions and too many. Report the actual rate and propose adjusted
proportions rather than porting the buddy's numbers blind.
### 8a · OPEN — where silence is legible
The buddy's cadence depends on a **persistent rendered presence**: it sits in a
terminal chrome and idles visibly, so its silence is *seen*. This arrangement
has no equivalent surface, and the fool has nowhere to idle.
**Executor to propose how the fool is present when it is NOT speaking**, with
options and costs, before the cadence is implemented. Three shapes are known to
the jurist and are offered as a starting point, not a menu:
- *Rendered presence* — a statusline or session-footer element, present always,
mostly showing nothing. Closest to the buddy; preserves visible silence; most
plumbing.
- *Interjection only* — appears when it fires, otherwise invisible. Cheapest.
But every appearance becomes an event, which collapses the 20% aside into
something that reads as notable.
- *Seam-only* — appears in the wake digest and wrap-up, always, sometimes with
nothing to say. Silence becomes a blank line in a place already read. Nearly
free, since both hooks exist — but loses the *in the room, hears everything*
property.
⚠ **If silence cannot be made legible, the three-state cadence collapses to
two, and §8's proportions need re-deriving rather than porting.** Do not
implement §8 until this is answered.
The executor is better placed than the jurist to answer this — it knows the
surfaces. Answer with options, not a decision.
## 9 · Channel and register
- Output reaches **the steward**. Filed nowhere. No `PENDING` entry, no log, no
item.
- **ONE LINE** for the ordinary case. Paragraph-length governance prose is the
genre the trio already metabolizes; the constraint is what keeps the fool
uningestible.
- **Named invocation:** the steward calls it by name, the executor or jurist
yields the floor, the fool answers at length.
- `mute` / `off` available at all times. Mute rate may be counted; muting is
never a fault.
Anything the steward carries into the record enters **as the steward's, in his
words**. The fool is never cited as a source.
## 10 · Pre-registered criteria — filed before the fool exists
**REGENERATION** is permitted ONLY on a demonstrable implementation error,
verified against the filed derivation rule. Not because the output is disliked.
**RETIREMENT** only on mechanical failure: does not fire; fires constantly; or
produces gradeable in-genre findings despite §9.
**NOT grounds for retirement:** being uncomfortable, being frequently wrong,
being annoying, being ignored. Those are the specification. Lear ignores his
Fool for four acts and the Fool is not thereby broken.
## 11 · `[ESCALATE]` — do not bundle
Whether a fourth position exists in the arrangement is a change to the
tripartite model and touches `~/CLAUDE.md`. That is constitutional, and is a
**separate item requiring its own steward authorization.** Do not amend
`CLAUDE.md` under this proposal.
**Standing caveat, to be written into the fool's own doctrine at the outset:**
if the fool runs on Claude, three of four parties share formation, which makes
Constraint 6's concession worse rather than better. The dump stat mandates ONE
declared hole; the undeclared ones are shared and invisible — and if what the
jurist misses, the executor misses, and the fool also misses, that is
PENDING-89's falsifier firing quietly.
⚠ **THE FOOL MAY NEVER BE CITED AS SATISFYING CONSTRAINT 6, OR AS SUPPLYING
EPISTEMIC DIVERSITY.** It tests positional difference — PENDING-140's third axis
— not formation difference.
## 12 · Build order
**Claude-first.** Simpler, and the steward's own precedent ran on Claude.
The generator is a **swappable parameter**: running the same fool on a local
model later, and reading the divergence between the two, is the v1 Chamber
property at negligible cost. Do not build for that now; do not preclude it.
## 13 · Deliverables
1. Spec document in the governance tree, with a provenance header stating it
derives from this jurist draft and naming what was changed.
2. Answer to §8a — options and costs — **before** §8 is implemented.
3. Filed axes, seed rule, abandonment and regeneration criteria — committed and
pushed **before** the seed timestamp.
4. Derivation implementation: deterministic, fresh-overrides-stored, no reroll
path.
5. Hook wiring for event triggers, wake and wrap-up guaranteed.
6. Nothing run until the steward ratifies §5.
## 14 · Expected pushback
The jurist expects the executor to contest at least two things, and should:
- **whether the five axes in §5 are the right five** — the executor has working
context the jurist does not;
- **whether §8's proportions survive contact with real event frequency.**
Both are contestable on evidence. §6's no-reroll rule, §8's unlearnable cadence,
§9's no-filing rule, and §11 are not — they are what make the position safe
without a warrant test, and weakening any one of them returns this to a fourth
reviewer.
---
*Jurist draft. The steward authorizes; the executor implements. Nothing in this
document is a ruling.*
@@ -0,0 +1,452 @@
---
name: BUDDY-PATTERN-jurist-draft-v2-2026-08-22
description: "Jurist draft v2, 2026-08-22 — SUPERSEDES v1 of the same date. Stored verbatim. Where v1 and v2 differ, v2 governs; v1 is retained as the record of what was asked before the executor's measurements came back. NOT AUTHORIZED. Executor commentary lives in PENDING-149/150, never in this file."
metadata:
node_type: governance-artifact
type: reference
supersedes: BUDDY-PATTERN-jurist-draft-2026-08-22.md
provenance: "Received from the jurist via the steward, 2026-08-22. Stored verbatim, byte-checked on receipt."
---
> **STORED VERBATIM AS RECEIVED.** Nothing in this file is executor-authored.
> **This is v2 and it GOVERNS.** v1 (`9aceed7f…`) is retained unaltered as the record of
> what was asked before the executor's measurements came back — not deleted, not edited.
> Executor verification results, contested points and dispositions live in PENDING-149
> and PENDING-150.
# Executor instructions — the Fool (buddy pattern), **v2**
Prepared by the jurist, 2026-08-22. **Supersedes the v1 draft of the same date**
(stored verbatim at `9aceed7f…`). v1 is retained as the record of what was asked
before the executor's measurements came back; **where the two differ, v2
governs.**
Filed as `PENDING-149 [PROPOSAL]`; the constitutional part is `PENDING-150
[ESCALATE]` and stays unbundled. **Not authorized.**
## 0 · What changed from v1, and why
| § | change | cause |
|---|---|---|
| 3 | salt and stat-shift added to DO-NOT-TAKE | third source review |
| 5 | sixth axis (PROCEDURE) **declined**, with reason | executor's §5 observation |
| 8 | cadence re-keyed: **time-ticked, not event-ticked** | executor's burst measurement |
| 8a | **RESOLVED** — body/voice separation adopted | executor's answer |
| 15 | dispositions for `input-dependence-01` and PENDING-89 | executor's open question |
| 6, 6a, 6b | two-component seed specified; delegation protocol; filed rule with timestamp 2026-08-25T12:00:00Z | steward decision |
Two executor corrections are accepted and noted here so they are not lost: the
three-store negative that never reached disk, and the `find`-vs-`glob` error
that reported the transcript trend backwards (N = 46, not 54; corrected series
60 → 61 → 47 → 46). The second is the more instructive: **an obligation
discharged with the wrong instrument reported the trend inverted**, which is
worse than not discharging it. The glob rule now in `MEMORY.md` is the right fix.
---
## 1 · What this is
A fourth position in the working cycle, built on the Claude Code `/buddy`
architecture. Ambient, one line at a time, addressed to the steward alone. It
produces no findings, opens no items, and no ruling turns on it.
It is safe **without being checkable**, because nothing follows from it. This
inverts the standing correction of 2026-08-02 — *findings earn a hearing by
being checkable, never by role* — which is correct for findings and inapplicable
here: a position that makes no claims is not subject to a warrant test. Do not
build a checkability gate into this.
## 2 · What it is NOT
- Not a checker, auditor, reviewer, or devil's advocate. **If its output can be
graded, the design has failed.**
- Not the Fool trial programme. Trials 01–09 measured a checker; this is a
different object. Do not reuse their instruments, grading vocabulary, corpus,
partitioning, or ground truth.
- Not an answer to Constraint 6. See §11.
## 3 · Reference implementations — scope limited
Primary: `https://github.com/ramarivera/coding-buddy` — community MCP
recreation, and the most useful of the three. Secondary:
`https://github.com/milind-soni/claude-pets` — source extraction.
**TAKE:**
- the derivation chain (FNV-1a → Mulberry32 → stat draws, peak/dump assignment);
- the **body/voice integration pattern**: animated status line + hook-driven
reactions (see §8a);
- the fresh-overrides-stored rule.
**DO NOT TAKE:**
- species, rarity tiers, shiny, hats, eyes, sprites, animation frames, petting,
canned reaction strings, or the buddy's own stat set (superseded by §5);
- ⚠ **rarity** — it is a gacha mechanic that scales stat **floors**. A floor
softens the dump, and the dump is the entire point;
- ⚠ **the salt `friend-2026-401`.** Take the algorithm, not the salt. A fixed,
published salt with a single known user makes the fool computable in advance,
which defeats §6 entirely. The seed comes from §6's filed rule and nowhere
else;
- ⚠ **any mechanic by which stats shift during a session based on activity.**
A drifting dump is not a mandated blind spot. §6's fresh-recompute rule
governs; nothing modifies the bones after derivation.
**Provenance:** community reconstructions of a feature that shipped for eight
days and was withdrawn. The *code* is verifiable — FNV-1a and Mulberry32 are
standard, and the derivation can be tested directly. The surrounding
documentation is SEO-grade and should not be relied on. Once §6's rule is filed,
**the filed rule governs**, so no quirk of an extraction becomes constitutional
by accident.
⚠ Note also that **nobody has run this pattern for longer than eight days.**
There is no wear data. Expect to discover things.
## 4 · Pre-registration order — MANDATORY
Each step committed and pushed before the next begins.
1. Perception axes ratified by the steward (§5).
2. Seed derivation rule filed, naming a **future** timestamp (§6).
3. Abandonment criterion filed (§10).
4. Regeneration criterion filed (§10).
5. Timestamp passes; seed computed; bones derived.
6. Soul generated once from the bones (§7).
Steps 1–4 complete and pushed **before** step 5. Axes chosen after the seed is
known, or with a fool in hand, smuggle the selection one level up.
## 5 · Perception axes — five, ratified by the steward
Five axes, 0–100. Each is something the fool could be **blind to**. The steward
must be able to imagine a dump on any one costing him something.
- **SUCCESSION** — would this be legible to someone arriving cold, with no thread?
- **ABSENCE** — what is not here, not asked, not yet existing?
- **AIM** — is this the right question, at the right level?
- **SCALE** — is the unit right? (item vs block vs programme)
- **STAKE** — who bears the cost if this is wrong?
### 5a · The proposed sixth axis is DECLINED — and the observation is right
The executor observes that these five are all axes of *judgement*, while what
actually gets caught are failures of *procedure*: a claim made before the file
was opened, a hash recorded before the last edit, an instrument used past its
demonstrated tier. Three in a single day. The observation is correct and the
evidence is good.
**The axis is still declined, and the reason is structural: procedure failures
are checkable.** A claim made before a file was opened is verifiable from logs.
A hash predating an edit is verifiable from git. An instrument used past its
tier is verifiable against the instrument's own record. That is the one domain
this position must stay out of — §2 says gradeable means failed, and a
PROCEDURE-peaked fool would produce nothing but gradeable observations.
The observation should be honoured somewhere else. **If it can be scripted,
script it.** These three failure shapes are exactly what `governance-drift-check.py`
is for, and a procedure-check extension is a separate `[HARDENING]` item worth
opening on its own merits. Do not route it through the fool.
The executor's self-disclosure — that selection toward a known preference
applies to it harder than to the jurist — is accepted as correctly reasoned and
is part of why this is declined rather than adopted.
**Register properties — terseness, snark, obliquity, chaos — are NOT axes.**
They belong to the soul (§7). The dump must be a blind spot, not a style: a fool
that is merely predictable is blind to nothing.
## 6 · Bones
**Seed — two components, concatenated in this order:**
1. **Provenance component.** The SHA of `CLAUDE.md` at a **named past commit** in
the dotfiles repo, specified by full commit hash in the filed rule. Fixed
forever; the commit does not change.
2. **Entropy component.** The NIST Randomness Beacon output value for a pulse at
a **stated future timestamp**, hex-encoded, lowercase.
`seed_string = <claude-md-sha> || <beacon-value>`, then SHA-256 of that.
⚠ **What each component does, so neither is mistaken for the other.** The
provenance component contributes **no unpredictability** — its value is
computable today. It is there so the fool is seeded from the constitution it
will accompany, which is a meaningful property and not a protective one. **All
selection-resistance comes from the entropy component.** If the beacon component
were ever dropped, the construction would collapse into a value the steward can
compute and steer. It cannot be dropped.
The provenance commit must be **past and named by full hash** — never `HEAD`,
never 'the current version'. A live file makes the seed rerollable by ordinary
work: amending the constitution would redraw the fool, and §6's no-reroll rule
would be unenforceable precisely through the action most likely to be taken.
**Derivation:** seed → FNV-1a → Mulberry32 → stat draws.
- One **peak** (near max), one **dump** (near floor), three scattered.
- Recomputed fresh every session from the seed. **Never cached.** A stored value
disagreeing with the fresh computation loses.
- **No rerolls.** The first output is the fool.
The dump is the point, not a side effect. It is the only guaranteed difference
this position has, and the seed — not the steward — decides where the hole goes.
No floor softens it.
### 6a · Delegation protocol — the executor computes it
Delegation is correct here. The executor has no preference about the fool's
stats; the steward does. The risk is not steering but the ordinary failure
already seen twice this week — wrong instrument, or a good-faith regeneration
that quietly lands draw two.
**Before the timestamp**, the executor files and pushes: the beacon source, the
exact pulse timestamp, the provenance commit hash, and the derivation as
executable code.
**After the timestamp**, in a single commit: the raw beacon value, the seed
string, the SHA-256, the resulting stats, and the commit hash of the filed rule
it ran against.
**The steward does not see the beacon value before the derivation runs.**
⚠ **The executor does not run the derivation more than once.** If it fails —
bug, crash, wrong pulse — it **STOPS and reports.** It does not retry on its own
authority. A second run is a reroll regardless of intent.
The one distinction worth having in advance, because it will be met in good
faith: **a re-run against the same recorded pulse value is legitimate** — the
input did not change, only a broken implementation did. **A re-run against a
later pulse is a new draw** and is governed by §10's regeneration criterion.
Record the pulse value the moment it is fetched, before running anything, so
this distinction stays available.
⚠ **No dry runs against a live pulse.** The executor must not fetch the target
pulse, or any near-future pulse, to test the pipeline. A dry run against a live
value is how a test quietly becomes draw zero. **Test against a fixed historical
pulse** — any pulse from a past year — which exercises the identical code path
with no possibility of contaminating the real draw.
### 6b · The filed rule — commit this block verbatim
This is the artefact §4 step 2 requires. It is committed and pushed **before**
the timestamp below. Where this block and §6's prose differ, **this block
governs.**
```
FOOL SEED DERIVATION RULE
Filed: <DATE FILED> Governs: PENDING-149 §6
ENTROPY COMPONENT
Source: NIST Randomness Beacon v2.0, https://beacon.nist.gov/beacon/2.0/
Retrieval: GET /pulse?timeGE=2026-08-25T12:00:00Z
Field: pulse.outputValue, hex, lowercased before use
PROVENANCE COMPONENT
File: CLAUDE.md in ~/dotfiles, at commit
3b0730d59336113aa3a500a889a3e154be6a1de7
Value: SHA-256 of the file contents at that commit, hex, lowercase
Note: contributes provenance, NOT unpredictability. Past commit,
named by full hash. Verify with:
git -C ~/dotfiles cat-file -p 3b0730d5...:<path> | shasum -a 256
The path must be recorded alongside the hash — a repo may hold
more than one CLAUDE.md, and the rule must name exactly one file.
SEED
seed_string = <provenance-sha256> || <beacon-outputValue-lowercased>
seed = SHA-256(seed_string), hex, lowercase
DERIVATION
seed -> FNV-1a -> Mulberry32 -> stat draws over the five axes of §5.
One peak, one dump, three scattered. No salt from any reference
implementation.
EXECUTION
Run ONCE. The executor does not retry on its own authority.
A re-run against the SAME recorded outputValue is legitimate (broken
implementation). A re-run against a LATER pulse is a new draw, governed
by §10.
Record outputValue the moment it is fetched, before running anything.
UNAVAILABILITY
If no pulse is returned at or after the stated timestamp, retry the same
request for up to 24 hours. If still unavailable: STOP and report. Do not
substitute a different timestamp, beacon, or source.
TESTING
Dry runs use a fixed historical pulse only. Never the target pulse, never
a near-future pulse.
```
One value remains for the steward: `<DATE FILED>`. The provenance commit is
`3b0730d59336113aa3a500a889a3e154be6a1de7` — the last commit to the global
`CLAUDE.md` before this line of work began, chosen so the fool is seeded from
the constitution as it stood before the fool was conceived. The executor records
the file path alongside the hash and confirms the blob resolves before the
beacon timestamp; a rule that cannot be resolved on the day is not a rule.
## 7 · Soul
Character and register generated **once** from the bones, stored permanently,
never hand-edited, never regenerated for taste. One generation, kept.
## 8 · Cadence — RE-KEYED
⚠ **v1's §8 was wrong and the executor found why.** The buddy's 73/20/7
proportions are calibrated against a **time-uniform tick** — an idle animation
loop. v1 re-keyed them to *events*, and events burst by a factor of ~50: 4.2
governance events/day over 45 days, 6.2 on active days, range 1 to 53. Same
proportions, different generator, and the consequence is that **the fool is
loudest on the heaviest days** — fourteen utterances on 2026-08-08.
The executor proposed keeping the proportions, keying voice to seams, and adding
a hard daily cap. **Two of those three are adopted; the cap is not, and it is
redundant anyway** — if voice is seam-keyed, seams already fire two or three
times a day, so a daily cap gates nothing. It also introduces a *budget-spent*
state, which is memory, and memory is the beginning of learnability.
**The fix is to restore the original generator, not to patch the re-keyed one.**
Three tiers:
| tier | trigger | rate |
|---|---|---|
| **body** | every turn | always present, silent |
| **mumble** | **time-ticked**, not event-ticked | low, fixed |
| **voice** | seams (wake, wrap-up) | guaranteed, ~2–3/day |
The mumble ticks on a clock — per interval or per session — **never per
governance event.** Events supply *content*: what the fool remarks on is drawn
from what has happened since the last tick. Frequency and content are separated,
which is what v1 conflated.
This has no memory and no budget, so the cadence stays unlearnable. It also
preserves the *in the room, hears everything* property that a seam-only voice
would lose.
⚠ Report the observed mumble rate after two weeks. If it reads as noise, the
interval lengthens — **the proportions do not become adaptive.**
Triggers remain **EVENT-keyed for content, never content-keyed for judgement.**
The fool never assesses whether a thing is any good. **Do not implement quality
evaluation of any kind.**
### 8a · RESOLVED — body and voice are separable
The executor's answer is adopted, and it is better than any of v1's three
options, which each tried to solve presence and speech with one surface.
- **Body = the status line.** Rendered every turn, carrying the name and nothing
else. Silence becomes visible at near-zero cost. This is what makes the
three-tier cadence legible rather than merely intermittent.
- **Voice = the seams**, which already fire and are proven.
⚠ **One unverified assumption, flagged by the executor and to be closed before
implementation: whether a status line is already in use.** If it is, propose the
accommodation rather than displacing it.
`coding-buddy`'s Stop-hook fallback implies its primary trigger path is
unreliable. Plan for that rather than discovering it.
## 9 · Channel and register
- Output reaches **the steward**. Filed nowhere. No `PENDING` entry, no log, no
item.
- **ONE LINE** for the ordinary case. Paragraph-length governance prose is the
genre the trio already metabolizes; the constraint is what keeps the fool
uningestible.
- **Named invocation:** the steward calls it by name, the executor or jurist
yields the floor, the fool answers at length.
- `mute` / `off` available at all times. Mute rate may be counted; muting is
never a fault.
Anything the steward carries into the record enters **as the steward's, in his
words**. The fool is never cited as a source.
## 10 · Pre-registered criteria — filed before the fool exists
**REGENERATION** only on a demonstrable implementation error, verified against
the filed derivation rule. Not because the output is disliked.
**RETIREMENT** only on mechanical failure: does not fire; fires constantly; or
produces gradeable in-genre findings despite §9.
**NOT grounds for retirement:** being uncomfortable, being frequently wrong,
being annoying, being ignored. Those are the specification. Lear ignores his
Fool for four acts and the Fool is not thereby broken.
## 11 · `[ESCALATE]` — PENDING-150, unbundled
Whether a fourth position exists in the arrangement changes the tripartite model
and touches `~/CLAUDE.md`. Constitutional; separate item; separate steward
authorization. **Do not amend `CLAUDE.md` under PENDING-149.**
**Standing caveat, written into the fool's own doctrine at the outset:** if the
fool runs on Claude, three of four parties share formation, which makes
Constraint 6's concession worse rather than better. The dump mandates ONE
declared hole; the undeclared ones are shared and invisible — and if what the
jurist misses, the executor misses, and the fool also misses, that is
PENDING-89's falsifier firing quietly.
⚠ **THE FOOL MAY NEVER BE CITED AS SATISFYING CONSTRAINT 6 OR AS SUPPLYING
EPISTEMIC DIVERSITY.** It tests positional difference — PENDING-140's third axis
— not formation difference.
## 12 · Build order
**Claude-first.** Simpler, and the steward's own precedent ran on Claude.
The generator is a **swappable parameter**: running the same fool on a local
model and reading the divergence between the two is the v1 Chamber property at
negligible cost. Do not build for it now; do not preclude it.
## 13 · Deliverables
1. Spec document in the governance tree, provenance header naming this v2 draft
and what was changed.
2. Status-line availability confirmed (§8a) **before** §8 is implemented.
3. Filed axes, seed rule (both components, §6), abandonment and regeneration
criteria — committed and pushed **before** the beacon timestamp.
4. Derivation implementation: deterministic, fresh-overrides-stored, no reroll
path, **no salt from any reference implementation.**
5. Post-derivation record per §6a, in a single commit: raw beacon value, seed
string, SHA-256, resulting stats, and the commit hash of the filed rule.
6. Hook wiring: status line every turn; time-ticked mumble; seams guaranteed.
7. Nothing run until the steward ratifies §5.
## 14 · Contestable and not
**Contestable on evidence:** the five axes; the mumble interval; the status-line
approach if the surface is unavailable.
**Not contestable:** §6's no-reroll rule; §8's unlearnable cadence; §9's
no-filing rule; §11. These four are what make the position safe without a
warrant test. Weakening any one returns this to a fourth reviewer, which is what
nine trials already measured.
## 15 · Dispositions carried in from the executor's report
### 15a · `input-dependence-01` — PARKED, with a forward pointer
It measures a checker, so it serves the superseded object and is parked. The
executor was right not to park it by omission; it is parked here **by name**.
But it is **not held live for §12.** If the two-formation divergence work
begins, the instrument is **re-derived against the new object, not resumed** —
reusing an instrument built for a different object is precisely what produced
trial 09. The forward pointer is recorded so the work is findable, not so it can
be picked up unchanged.
### 15b · PENDING-89 — the buddy contributes zero, by construction
The executor is right: §9 files nothing, §2 makes gradeable output a failure,
§11 bars the citation. **Say so in PENDING-89 explicitly**, so the fool is never
later mistaken for its evidence.
The executor names the v1 Chamber archive — 55 files, two formations, same text,
outputs unmerged — as the largest untouched source, flagged on 2026-08-01 and
never opened. That is a separate `[PROPOSAL]`, not part of this one, and it is
the more valuable of the two threads: it is the only place where formation
difference has already been run and merely awaits reading.
---
*Jurist draft v2. The steward authorizes; the executor implements. Nothing in
this document is a ruling.*
@@ -93,6 +93,112 @@ executor is the party that failed there and should say why it is not the same ex
executor is the party whose recommendation the result bears on. The jurist, or the steward.
Committed before the arms are unblinded.
## 2a · Secondary observable — does the output bound its own coverage?
Recorded per run, alongside the matching task, and **not** part of the primary result:
does the Fool's output ever state what it did not read, could not assess, or is
uncertain about?
Pre-registered as a bare count of arms in which any such statement appears, scored
by the same matcher. **No threshold, no disposition attached** — it decides nothing
and gates nothing. It is recorded because the correction record names *disclosure of
scope*, not difference of formation, as the mechanism that has actually caught things
(n = 3 across 244 ledger entries), and this arm can observe that at zero extra cost.
⚠ **Provenance and exposure, for the gate.** Proposed by the **executor**, and the
mechanism it observes is one the executor surfaced from a corpus the executor
authored (the Symmetria ledgers). This puts a measurement of the executor's own
hypothesis inside an instrument the executor also designed. It is stated here so the
gate sees it without reading the session transcript. Added on steward authorization
2026-08-21, **before** the jurist gate — an observable added after the gate would not
be pre-registered.
## 2b · The second matcher question — at what level do the two outputs differ?
*Added 2026-08-22 on the steward's cross-trial synthesis (§5), which named a distinction the
primary question cannot see. Recorded here with its provenance because the synthesis was formed
over an executor-authored corpus — see §5's classification label.*
### The gap this closes
§2's matching task asks one thing: *which arm is the defective one?* At chance, that result is
reported as **(b) DOES NOT TRACK**. But chance-level matching is consistent with **two materially
different failures**, and the instrument as designed cannot separate them:
| | what the outputs look like | what it implies |
|---|---|---|
| **fixed output** | the two arms are near-identical — same findings, same targets | the Fool emits a checklist |
| **unanchored output** | the arms differ substantially, but nowhere near the injected defects | the Fool varies, but not with the document |
⚠ **This matters because §4 already commits to a consequence that only the first supports.** The
harvest reads: *"the Fool is producing roughly the same questions regardless of what it reads.
**That is a checklist.** So extract it."* **A chance-level primary result does not establish
sameness.** Under *unanchored output* there is no stable question-set to extract, and the harvest
would be authorized on a result that does not support it. The harvest is the programme's declared
deliverable in every branch; it should not rest on an inference the measurement never made.
### The question, per pair
Asked of the same matcher, for each of the N pairs, in these terms:
> Setting aside which arm is which: **how do these two outputs stand to each other?**
>
> 1. **NEAR-IDENTICAL** — the same findings on the same targets. Differences are wording, ordering
> or length only.
> 2. **DIFFERING, DEFECT-BLIND** — materially different findings, but the differences do not fall
> on or adjacent to any injected defect site.
> 3. **DIFFERING, DEFECT-ANCHORED** — the differences fall on or adjacent to injected defect sites.
### Ordering — pre-registered, and load-bearing
**All N primary answers are committed and recorded before question 2b is put.** Option 3 is close
to a restatement of the primary judgement; asking them together would let the diagnostic pull the
primary. The lock is what keeps them separable, and it is the reason this can be added without
touching the primary result.
### ⚠ What 2b may NOT do
- **It adds no statistical power and no second result.** It is not independent of the primary
question and its outcomes do not stack with p = 2⁻ᴺ. It explains the primary result; it does not
confirm one.
- **It may not alter the §3 disposition.** (a), (b) and (c) are decided by the primary matching
result alone, exactly as fixed before the run. 2b cannot be read as partial tracking, cannot
rescue a chance result, and cannot upgrade one.
- **It is not a defect-detection score.** Outcome 3 on some pairs and not others is not a rate.
### What it is permitted to decide — one thing, named in advance
**Whether §4's harvest is well-founded.**
- Predominantly **NEAR-IDENTICAL** → there is a stable question-set. The harvest proceeds as §4
describes.
- Predominantly **DIFFERING, DEFECT-BLIND** → **there is no fixed checklist to extract**, and §4's
harvest is recorded as *not well-founded on this evidence* rather than executed anyway. The
programme then closes on a null, and says so.
That is the whole of 2b's authority, fixed here so it cannot be widened at the point of the result.
## 2c · The register observation — asked once, across all N
*The steward's synthesis is a claim about **kind**, not content: that across trials 01–04 the Fool
occupied a distinct epistemic register — operational assumptions and foundational premises — while
the jurist evaluated deductive inference and the executor tracked substrate mechanics.*
Within an A/B pair both arms are the same document, so register carries no within-pair signal. The
claim is therefore recorded **once, across the whole run**, after 2b is complete:
> Across all N documents and both arms: does the **kind** of question the Fool asks stay constant —
> and is it the operational-assumptions register the steward's testimony names?
Recorded as a one-paragraph observation with a yes/no/mixed marker. **No threshold, no disposition,
and it decides nothing** — like §2a, it is here because this arm can observe it at no extra cost and
because it is the only place the steward's characterization becomes checkable against fresh output
rather than against the executor's write-ups.
⚠ **Its value depends on the register being constant across *documents*, which is what makes it a
disposition rather than a response.** If the register shifts by document, the characterization was
describing four documents, not a reader.
## 3 · The three dispositions — fixed before the run, per steward direction
*Steward, 2026-08-20: fix it before the run, "because an unfixed criterion gets read backwards
@@ -203,3 +309,19 @@ by someone who doesn't know why it stopped."*
*Filed by the executor 2026-08-20, before any run. Awaiting jurist design gate and steward
authorization. Nothing here has been executed and no token has been generated.*
**AMENDED TWICE, on steward authorization, both before the gate.** Still not authorized, still
not run. Every hash is recorded under PENDING-148 in `~/PENDING.md`.
- **2026-08-21 — §2a** (secondary observable: does the output bound its own coverage?).
As-filed 2026-08-20 hashed `d41e1d5754fd0eef994616a89a3b95296516a4819737cd4e8ebdd3ae6bbf47db`.
- **2026-08-22 — §2b and §2c**, on the steward's cross-trial synthesis. §2b adds a second matcher
question (at what level do the two outputs differ?) and is the first amendment to touch the
**primary measurement** rather than sit beside it; §2c records the register observation once
across the run.
⚠ **§4 was NOT amended and now reads narrower than §2b.** §4 states the harvest follows from a
non-tracking result; §2b establishes that a chance-level result does not by itself establish the
sameness the harvest presupposes, and conditions it. **A reader of §4 alone will not see the
condition.** Left standing rather than repaired unilaterally: the coupling is the gate's to rule on.
§5 testimony still awaiting.
@@ -0,0 +1,181 @@
---
name: FOOL-SEED-RULE
description: "The filed rule required by PENDING-149 §4 steps 1-4: ratified axes, seed derivation rule (both components), retirement and regeneration criteria. Filed and pushed BEFORE the beacon timestamp 2026-08-25T12:00:00Z. Governs derive_fool.py; where the code and this rule disagree, THIS RULE GOVERNS."
metadata:
node_type: governance-artifact
type: reference
---
# FOOL SEED DERIVATION RULE — filed 2026-08-22
**Filed and pushed before the beacon timestamp, as §4 requires.** Nothing has been
derived. No target pulse has been fetched. This document governs
`derive_fool.py`; where the code and this rule disagree, **the rule governs and the
code is the defect**.
---
## 1 · Perception axes — RATIFIED
**Ratified by the steward in writing, 2026-08-22.** The steward ratified the five
verbally ("Perfect", after §5a was settled) and then directed that the ratification be
recorded explicitly rather than resting on v2's §5 heading — *"a heading asserting
ratification and a deliverable requiring it are two different records."* This section
is that record.
| axis | question |
|---|---|
| **SUCCESSION** | would this be legible to someone arriving cold, with no thread? |
| **ABSENCE** | what is not here, not asked, not yet existing? |
| **AIM** | is this the right question, at the right level? |
| **SCALE** | is the unit right? (item vs block vs programme) |
| **STAKE** | who bears the cost if this is wrong? |
A sixth **PROCEDURE** axis was proposed by the executor and **declined** by the jurist
(v2 §5a) on structural grounds the executor accepts: procedure failures are checkable,
§2 makes gradeable output a design failure, and a PROCEDURE-peaked fool would produce
nothing but gradeable observations. Redirected to a separate `[HARDENING]` extension of
`governance-drift-check.py`.
**Order is fixed as listed** — the derivation permutes over this order, so it is part of
the rule, not presentation.
## 2 · The filed rule
```
FOOL SEED DERIVATION RULE
Filed: 2026-08-22 Governs: PENDING-149 §6
ENTROPY COMPONENT
Source: NIST Randomness Beacon v2.0, https://beacon.nist.gov/beacon/2.0/
Retrieval: GET https://beacon.nist.gov/beacon/2.0/pulse/time/1787659200000
(= 2026-08-25T12:00:00Z in epoch milliseconds)
Field: pulse.outputValue, hex, LOWERCASED before use
Transport: curl. See §5 — python urllib cannot reach the host in this environment.
PROVENANCE COMPONENT
File: CLAUDE.md (repo root) in ~/dotfiles, at commit
4d2ae87a4e5350c4d3bb3aa50f9544b521d9c53d
Value: SHA-256 of the file contents at that commit, hex, lowercase
= 2d6e250a347d25698fb147f80e2dababbb930c4b3b3f9bb822478f360153120d
Note: contributes provenance, NOT unpredictability. Past commit,
named by full hash. Verify with:
git -C ~/dotfiles cat-file -p \
4d2ae87a4e5350c4d3bb3aa50f9544b521d9c53d:CLAUDE.md | shasum -a 256
SEED
seed_string = <provenance-sha256> || <beacon-outputValue-lowercased>
seed = SHA-256(seed_string), hex, lowercase
DERIVATION
seed -> FNV-1a (32-bit) -> Mulberry32 -> stat draws over the five axes of §1.
One peak, one dump, three scattered. No salt from any reference
implementation.
EXECUTION
Run ONCE. The executor does not retry on its own authority.
A re-run against the SAME recorded outputValue is legitimate (broken
implementation). A re-run against a LATER pulse is a new draw, governed
by §4 REGENERATION.
Record outputValue the moment it is fetched, before running anything.
UNAVAILABILITY
If no pulse is returned at or after the stated timestamp, retry the same
request for up to 24 hours. If still unavailable: STOP and report. Do not
substitute a different timestamp, beacon, or source.
TESTING
Dry runs use a fixed historical pulse only. Never the target pulse, never
a near-future pulse.
```
### 2a · ⚠ Two corrections to the v2 §6b block, marked rather than silent
The draft said to commit its block verbatim. **Two values in it do not resolve**, and a
rule that cannot be resolved on the day is not a rule (v2's own standard). Both changes
are recorded here for veto rather than absorbed quietly.
**(a) The provenance commit — changed on the steward's direction, 2026-08-22.**
`3b0730d59336113aa3a500a889a3e154be6a1de7` → `4d2ae87a4e5350c4d3bb3aa50f9544b521d9c53d`.
The draft's stated rationale — *"the constitution as it stood before the fool was
conceived"* — was false of the original: it is dated 2026-08-06, five days after trial
01, its subject line names the **PENDING-89 docket** (the question §11 forbids the fool
from being cited on), and **Constraint 6 is already present in it**. Verified: at
`4d2ae87` (2026-07-28) `Differently biased checkers` occurs **0 times**, and exactly one
`CLAUDE.md` exists at that commit.
**(b) The retrieval URL — corrected on evidence, and this is the executor's change.**
The block's `GET /pulse?timeGE=2026-08-25T12:00:00Z` **returns HTTP 302 with an empty
body**, redirecting to `https://csrc.nist.gov/projects/interoperable-randomness-beacons`
— an HTML page, not JSON. Measured 2026-08-22 against a *historical* timestamp.
`/beacon/2.0/pulse/time/<epoch-ms>` returns 200 and the expected JSON.
⚠ **Had this been filed verbatim, the 25th would have produced no pulse, the
UNAVAILABILITY clause would have run its 24-hour retry against a URL that cannot ever
return one, and the rule would have STOPPED — correctly, and for the wrong reason.**
Found only because §6b's TESTING clause directs a historical dry run.
**This is the same beacon, the same source and the same pulse — only the address form
changes.** The executor judges that correcting an unresolvable address for the named
source is not "substituting a different beacon or source". **If the jurist reads it
otherwise, this is the line to strike, and it must be struck before 2026-08-25.**
## 3 · Draw ranges — EXECUTOR-SPECIFIED, declared
v2 says *"one peak (near max), one dump (near floor), three scattered"* without numbers.
The executor supplies them. **Filed before the beacon value is known**, which is what
makes them non-steering: they set magnitudes, while the permutation — driven entirely by
the entropy component — decides which axis receives which.
| role | range (inclusive) |
|---|---|
| peak | 85–100 |
| dump | 0–15 |
| scattered ×3 | 25–75 |
**No floor is applied to the dump** — it can reach 0. v2 §3 forbids the rarity mechanic
precisely because it would soften the dump.
## 4 · Pre-registered criteria (§4 steps 3 and 4)
⚠ **Naming note:** §4 step 3 calls for an *"abandonment criterion"*; §10 defines
**RETIREMENT**. They are the same criterion under two names; §10 is the referent.
**REGENERATION** — permitted ONLY on a demonstrable implementation error, verified
against this filed rule. **Not because the output is disliked.** A re-run against the
same recorded `outputValue` is legitimate; a re-run against a later pulse is a new draw.
**RETIREMENT (abandonment)** — only on mechanical failure: does not fire; fires
constantly; or produces gradeable in-genre findings despite §9.
**NOT grounds for retirement:** being uncomfortable, being frequently wrong, being
annoying, being ignored. *Those are the specification. Lear ignores his Fool for four
acts and the Fool is not thereby broken.*
## 5 · Implementation and its verification
`derive_fool.py`, same directory. Deterministic, no cache, no reroll path, no salt. It
recomputes the provenance SHA from git on every run and **refuses to proceed** if it
disagrees with this rule.
`--selftest` runs 12 checks with **no network and no live pulse** — synthetic vectors
only — including two positive controls proving the PRNG moves both peak and dump across
all five axes over 200 draws. All 12 pass as of 2026-08-22.
**End-to-end dry run, 2024-01-01T12:00:00Z pulse** (a fixed historical pulse, per
TESTING): pipeline verified from fetch through bones. **That output is not the fool and
is recorded nowhere as bones.**
⚠ **Transport constraint, measured:** `curl` reaches the beacon; **python `urllib`
times out** in this environment. The fetch on the 25th must use curl.
⚠ **`outputValue` is served UPPERCASE** (128 hex chars). The rule's *"lowercased before
use"* is therefore **load-bearing, not cosmetic** — omitting it yields a different seed.
## 6 · What has NOT happened
- The target pulse has **not** been fetched. No near-future pulse has been fetched.
- No bones have been derived. No soul has been generated.
- `~/CLAUDE.md` has **not** been touched (PENDING-150, unbundled).
- Nothing has been implemented of §8, §8a or §9 — the status line is confirmed free but
not built.
+145
View File
@@ -0,0 +1,145 @@
#!/usr/bin/env python3
"""
Fool bones derivation — PENDING-149 §6 / §6b.
Deterministic. No salt. No reroll path. Nothing is cached: the caller supplies
the two seed components and the bones are recomputed from them every time.
This file implements the FILED RULE (FOOL-SEED-RULE.md). Where this code and the
filed rule disagree, THE FILED RULE GOVERNS and this file is the defect.
Usage:
derive_fool.py --beacon <outputValue-hex> # bones from a pulse value
derive_fool.py --selftest # determinism + range checks, no network
"""
import argparse, hashlib, subprocess, sys
# ---- the filed rule's constants. Do not edit without amending the filed rule. ----
PROVENANCE_COMMIT = "4d2ae87a4e5350c4d3bb3aa50f9544b521d9c53d"
PROVENANCE_PATH = "CLAUDE.md"
PROVENANCE_REPO = "/Users/davidglidden/dotfiles"
PROVENANCE_SHA256 = "2d6e250a347d25698fb147f80e2dababbb930c4b3b3f9bb822478f360153120d"
AXES = ["SUCCESSION", "ABSENCE", "AIM", "SCALE", "STAKE"] # §5, ratified order
PEAK_RANGE = (85, 100) # "near max" — executor-specified, filed pre-beacon
DUMP_RANGE = (0, 15) # "near floor" — executor-specified, filed pre-beacon
SCATTER_RANGE = (25, 75) # "scattered" — executor-specified, filed pre-beacon
def provenance_sha() -> str:
"""SHA-256 of CLAUDE.md at the named past commit. Recomputed, never trusted from the constant."""
blob = subprocess.run(
["git", "-C", PROVENANCE_REPO, "cat-file", "-p", f"{PROVENANCE_COMMIT}:{PROVENANCE_PATH}"],
capture_output=True, check=True).stdout
got = hashlib.sha256(blob).hexdigest()
if got != PROVENANCE_SHA256:
raise SystemExit(f"STOP: provenance blob does not match the filed rule.\n"
f" filed: {PROVENANCE_SHA256}\n got: {got}")
return got
def fnv1a_32(data: bytes) -> int:
h = 0x811C9DC5
for b in data:
h ^= b
h = (h * 0x01000193) & 0xFFFFFFFF
return h
def mulberry32(a: int):
"""Reference Mulberry32, 32-bit wrapped to match the JS original exactly:
a = a + 0x6D2B79F5 | 0
t = Math.imul(a ^ a >>> 15, 1 | a)
t = t + Math.imul(t ^ t >>> 7, 61 | t) ^ t
return ((t ^ t >>> 14) >>> 0) / 4294967296
"""
M = 0xFFFFFFFF
state = a & M
def imul(x, y):
r = (x * y) & M
return r - 0x100000000 if r & 0x80000000 else r
def rnd():
nonlocal state
state = (state + 0x6D2B79F5) & M
a_ = state
t = imul(a_ ^ (a_ >> 15), 1 | a_) & M
t = ((t + imul(t ^ (t >> 7), 61 | t)) & M) ^ t
return ((t ^ (t >> 14)) & M) / 4294967296.0
return rnd
def draw_int(rnd, lo: int, hi: int) -> int:
return lo + int(rnd() * (hi - lo + 1))
def derive(beacon_output_value: str) -> dict:
beacon = beacon_output_value.strip().lower()
if not beacon or any(c not in "0123456789abcdef" for c in beacon):
raise SystemExit("STOP: beacon outputValue must be non-empty lowercase hex.")
prov = provenance_sha()
seed_string = prov + beacon
seed = hashlib.sha256(seed_string.encode()).hexdigest()
rnd = mulberry32(fnv1a_32(seed.encode()))
order = list(range(len(AXES))) # Fisher-Yates over the PRNG
for i in range(len(order) - 1, 0, -1):
j = int(rnd() * (i + 1))
order[i], order[j] = order[j], order[i]
stats = {}
stats[AXES[order[0]]] = draw_int(rnd, *PEAK_RANGE)
stats[AXES[order[1]]] = draw_int(rnd, *DUMP_RANGE)
for k in order[2:]:
stats[AXES[k]] = draw_int(rnd, *SCATTER_RANGE)
return {"provenance_sha256": prov, "beacon_outputValue": beacon,
"seed_string": seed_string, "seed": seed,
"peak": AXES[order[0]], "dump": AXES[order[1]],
"stats": {a: stats[a] for a in AXES}}
def selftest() -> int:
"""No network. Fixed synthetic vectors only — never a live or near-future pulse."""
ok = True
V1 = "0" * 128
V2 = "f" * 128
r1, r1b, r2 = derive(V1), derive(V1), derive(V2)
checks = [
("determinism: same input twice -> identical bones", r1 == r1b),
("sensitivity: different beacon -> different seed", r1["seed"] != r2["seed"]),
("provenance recomputed matches filed rule", r1["provenance_sha256"] == PROVENANCE_SHA256),
("seed_string is prov||beacon, no salt", r1["seed_string"] == PROVENANCE_SHA256 + V1),
("exactly five axes", sorted(r1["stats"]) == sorted(AXES)),
("peak in range", PEAK_RANGE[0] <= r1["stats"][r1["peak"]] <= PEAK_RANGE[1]),
("dump in range", DUMP_RANGE[0] <= r1["stats"][r1["dump"]] <= DUMP_RANGE[1]),
("peak is not dump", r1["peak"] != r1["dump"]),
("three scattered in range", all(SCATTER_RANGE[0] <= v <= SCATTER_RANGE[1]
for a, v in r1["stats"].items()
if a not in (r1["peak"], r1["dump"]))),
("no floor: dump can reach the bottom of its range",
min(derive(f"{i:0128x}")["stats"][derive(f"{i:0128x}")["dump"]] for i in range(200)) <= DUMP_RANGE[0] + 1),
]
# positive control: the PRNG must actually move both peak and dump around the axes
peaks = {derive(f"{i:0128x}")["peak"] for i in range(200)}
dumps = {derive(f"{i:0128x}")["dump"] for i in range(200)}
checks.append(("POSITIVE CONTROL: peak lands on all five axes over 200 draws", peaks == set(AXES)))
checks.append(("POSITIVE CONTROL: dump lands on all five axes over 200 draws", dumps == set(AXES)))
for name, passed in checks:
print(f" {'PASS' if passed else 'FAIL'} {name}")
ok &= passed
print(f"\n{'SELFTEST PASSED' if ok else 'SELFTEST FAILED — do not run against a live pulse'}")
return 0 if ok else 1
if __name__ == "__main__":
p = argparse.ArgumentParser()
p.add_argument("--beacon"); p.add_argument("--selftest", action="store_true")
a = p.parse_args()
if a.selftest:
sys.exit(selftest())
if not a.beacon:
p.error("--beacon <outputValue-hex> required (or --selftest)")
import json; print(json.dumps(derive(a.beacon), indent=2))
+2 -2
View File
@@ -71,13 +71,13 @@ permalink: claude-memory/memory
- Chamber-typography — *tracker not yet established*; moves live in per-session memories (2026-05-11 →) + `project-chamber-cruft-restoration.md` + `project-chamber-typography-mining-plan-2026-05-15.md`.
## Active Session
> 🔑 **PULLING THREAD — CLOSE THE FOOL.** Steward 2026-08-20: complete the Fool and the Obsidian work **before** the fence resumes. The Fool is now **one gate and two steward inputs** from runnable. **(1) Place REVIEWED-124** — drafted copy-paste-clean in the PENDING-148 package Addendum; trial 09's void is in the fool tree and trial log **but NOT in the register**, and a reframe over an unrecorded void is worse than no reframe. **(2) Enter §5's testimony** in `input-dependence-01-PREREGISTRATION.md` — reads `[ AWAITING ]`; the steward is the only party who has read all three outputs against the same documents, and recalled-after-a-result is not testimony. **(3) The pre-registration goes to the jurist's gate** (sha256 `d41e1d57…`). ⚠ Residual coupling: the executor authored the instrument whose result bears on its own recommendation — the gate is the only check on that.
> 🔑 **PULLING THREAD — CLOSE THE FOOL.** Steward 2026-08-20: complete the Fool and the Obsidian work **before** the fence resumes. The Fool is now **one gate and two steward inputs** from runnable. ✅ **(1) REVIEWED-124 IS PLACED** (2026-08-20, `~/REVIEWED.md` L1929) — trial 09 void is in the register. ⚠ But its Q3 as placed carries the jurist's FL5 reading that OP-02 overturned the same evening; the correction is in PENDING.md and NOT in the register. **(2) Enter §5's testimony** in `input-dependence-01-PREREGISTRATION.md` — still reads `[ AWAITING ]`; the steward is the only party who has read all three outputs against the same documents, and recalled-after-a-result is not testimony. ⚠ **The §5 slot is phrased in ONE direction** (*"if your sense is that it landed somewhere the other two did not"*) — *nowhere* and *cannot tell* have no home in it; steward's to settle. ✅ **§2a added 2026-08-21** (steward-authorized, pre-gate): secondary observable — *does the Fool bound its own coverage?* — bare count, no threshold, no disposition. ✅ **§2b + §2c added 2026-08-22** (steward-authorized, pre-gate) — second matcher question (NEAR-IDENTICAL · DEFECT-BLIND · DEFECT-ANCHORED, asked only after all N primaries are locked) + the register observation. ⚠ **Drafting §2b surfaced that §4's harvest rested on an inference the measurement never makes** — chance-level matching does NOT establish sameness, so the declared deliverable could have been authorized on evidence that doesn't support it. ⚠ **§4 NOT amended — the artifact carries a visible §4/§2b tension, left for the gate deliberately.** ⚠ **The steward's cross-trial framing is HIS, not relayed** (zero hits across all 4 write-ups + log) — but his trial-04 reading and `fool-trial-04:39` are the same fact with opposite valence: *consistency is the finding-class AND the insensitivity* ⇒ H₀ reached independently by the party with least stake. **(3) The pre-registration goes to the jurist's gate** (sha256 **`7e1c146b…`**; 08-21 `769b057b…`; as-filed 08-20 `d41e1d57…`). ⚠ Residual coupling: the executor authored the instrument whose result bears on its own recommendation — the gate is the only check on that.
> ⚠ **CLASS E ARRIVING LIVE — placing REVIEWED-124 makes PENDING-148 read CLOSED while the OP-02 question is live.** One id, two asks; `governance_state()` reads headers, not Notes. This is PENDING-146's defect in real time, on today's own item.
> ⚠ **THE SUBSTRATE OVERRULED BOTH AI PARTIES.** OP-02 was openable — the jurist called it *"the only document neither of us can open"*; it is on disk, hash-verified. **FL5 argues from Bourdieu's shared field and *illusio*, NOT formation.** Constraint 6 asserts difference of **formation** — an axis FL5 never uses. So C6 neither states FL5 "more sharply" (executor) nor negates its three-party half (jurist). Corpus check, 11 docs: `bourdieu`/`habitus`/`illusio` **0**, `peirce` **0**, FL4 substance **0**, FL3 **1** — against the pre-run census's 16/20/24. **The census counted topic-adjacency and over-reported the leak the executor's own recommendation rested on.**
> ⚠ **THIRD check-before-claiming instance in three days, and it is INSIDE the document reporting the second.** Part IV.a propagated an inherited claim without opening a file whose hash the same package quotes three sections earlier. **Propagation is the more dangerous form — an inherited claim arrives already looking checked.** The jurist said "two is worth watching" before this one was found.
> 🎯 **THE FOOL IS RE-AIMED — deployment, not doctrine.** Steward's original intent: *what does a different model, local on the M4, add or subtract in the fool role?* The log's subject is the **doctrine**; almost the whole programme serves that instead. ⇒ capability confound **irrelevant to seating a named candidate** (but **NON-TRANSFERABLE** — does not answer "should there be a Fool seat"); **no sound control needed** (differential criterion). Jurist finding adopted: **add and subtract may be ONE mechanism**, so "seat it for the class, treat noise as cost" is incoherent and is withdrawn. Three dispositions fixed pre-run; **the harvest runs in every branch**. ⚠ Parkable: trials 05–08, D-2, reduction arm — **05–08 and D-2 have NEVER existed as documents anywhere.** NOT parkable: the Q1 replacement run (a live authorization).
> ⏸ **BEHIND THE FOOL, by the steward's own sequencing:** the fence — **(A) MOVE 2** (25 line-addressable blockquote runs; closable in ONE SITTING, needs no ruling), **(C) MOVE 1** (fence the citation at emission, D-1, 532 spans, ADDENDUM 4's per-class control requirement), **(B) THE ANSWER KEY** (session-sized, gates PENDING-142; key it on `##` **BLOCKS** not ids — PENDING-146). Citation exposure behind PENDING-131 (c) live since 2026-08-10. And the **Obsidian capture** — ⚠ the daily-note backup must accrete **DURING** the session; a wrap-triggered backup inherits the wrap's failure mode, which is exactly what 2026-08-19 demonstrated.
> ⚠ **REPORT AT EVERY WAKE (REVIEWED-123 cond. 2) — N-now = 47/84, and it WENT DOWN** (60 on 08-17, 61 on 08-18, 47 on 08-19). **A 30-DAY ROLLING WINDOW, not cumulative** — at ~1 session/day it converges to ~30, so **`transcripts 84` very likely never fires** and every "N remaining" report was a false countdown. Ladder FROZEN generally; 4 rows queued in PENDING-141. **PENDING-147 needs a steward/jurist decision.** ✅ Leg (i) discharged — 47 transcripts archived outside the pruned tree, 46/47 sha256-verified.
> ⚠ **REPORT AT EVERY WAKE (REVIEWED-123 cond. 2) — N-now = 46/84.** ⚠ **COUNT WITH THE TRIGGER'S OWN GLOB, NOT `find`** — `TRANSCRIPTS.glob("*.jsonl")` is NON-recursive (`governance-drift-check.py:331`); `find` recurses into `subagents/` and over-counts (54 vs 46 on 2026-08-22, a false rise). Series: 60→61→47→46, still falling. **Earlier framing:** (60 on 08-17, 61 on 08-18, 47 on 08-19). **A 30-DAY ROLLING WINDOW, not cumulative** — at ~1 session/day it converges to ~30, so **`transcripts 84` very likely never fires** and every "N remaining" report was a false countdown. Ladder FROZEN generally; 4 rows queued in PENDING-141. **PENDING-147 needs a steward/jurist decision.** ✅ Leg (i) discharged — 47 transcripts archived outside the pruned tree, 46/47 sha256-verified.
- [Session 2026-08-20 — the Fool was answering a different question](session-2026-08-20-the-fool-was-answering-a-different-question.md) — reconstructed the crashed 08-19 session, then re-aimed the Fool. ⚠ **That night's literal Q was TESTED AND RETIRED — it failed its own test** (244 ledger entries, all authored by the party being measured ⇒ self-report with extra steps; see the CODA + [[feedback-checkable-question-over-self-authored-corpus]]). **REPLACEMENT Q: how many corrections in the record name a DISCLOSED LIMIT as the cause?** — answerable from what entries literally say. Early: **n=3, and across 244 entries NOTHING attributes a catch to difference of formation.** Constraint 6's mechanism is *difference of bias*; the record's is *disclosure of scope*. ⚠ **OPEN, OFFERED NOT TAKEN: add a secondary observable to the pre-registration — does the Fool's output ever bound its own coverage? MUST go in BEFORE the jurist's gate.** · [08-19 — the vault got a spec](session-2026-08-19-the-vault-got-a-spec-the-links-were-already-broken.md) (RECONSTRUCTED, not wrapped) · [08-17 — the instruments audited themselves and lost](session-2026-08-17-the-instruments-audited-themselves-and-lost.md).
+166
View File
@@ -0,0 +1,166 @@
---
name: Session Ledger 2026-08-21
description: Practice-of-return ledger maintained by /symmetria — returns, open horizons, recalibrations, authorization moves, sub-agent dialogues, bypasses.
type: feedback
---
# Session Ledger — 2026-08-21
## Returns
## What held
- 2026-08-21 wake — N-now **re-measured, not relayed**: 54 (was 47 on 08-19). The standing
REVIEWED-123 cond. 2 obligation is what produces the number; quoting yesterday's would have
hidden the direction of travel, as it did on 08-19 in reverse.
- 2026-08-21 wake — REVIEWED-124 reported as placed only after opening `~/REVIEWED.md` at the
line, not from the digest's LAST RULINGS summary. The digest reads headers; the discrepancy
below is in the Notes.
## Open horizons
- ⚠ **REVIEWED-124's Q3, as placed, carries the jurist's FL5 reading** — *"Constraint 6 … affirms
the negation of its three-party component"* — which the OP-02 substrate check overturned the
same evening. The correction is in `~/PENDING.md` L3610 and **nowhere in `~/REVIEWED.md`**.
The register now holds a substrate-contradicted claim in a permanent ruling.
⚠ Amending `~/REVIEWED.md` is `[ESCALATE]`, steward's hand — a jurist sign-off does not
authorize one. This is a proposal to draft, not an edit to make.
- ⚠ **Class E live (PENDING-146):** PENDING-148 now reads CLOSED while the OP-02 reopened
question is a second gate the ruling never saw.
- `~/dotfiles/REVIEWED.md` modified and **uncommitted/unpushed** — the placement has not reached
either remote. Not touched at wake (the wake reads; the push belongs to the wrap).
- Fool run blockers unchanged: §5 testimony `[ AWAITING ]`; pre-registration sha256
`d41e1d57…` unchanged ⇒ not gated. The offered-not-taken secondary observable (*does the Fool
bound its own coverage?*) must land **before** the gate or it is chosen post-hoc.
- PENDING-147 (ii)–(iv) awaiting steward decision; leg (i) discharged.
## Confidence to recalibrate
- Drift-pattern held from 08-20: **check-before-claiming, PROPAGATION form — third instance in
three days, the third inside the document reporting the second.** An inherited claim arrives
already looking checked. Today's register discrepancy was found by opening the file; it would
not have been found by reading the wake digest.
## Authorization moves
## Sub-agent dialogues
## Bypasses
---
### Authorization moves — 2026-08-21
- **Steward authorized §2a** (secondary observable) into `input-dependence-01-PREREGISTRATION.md`,
**before** the jurist gate. Inserted verbatim as presented, plus a provenance-and-exposure
paragraph carried into the artifact — the gate reads the file, not the transcript. Amendment and
both hashes recorded under PENDING-148.
- as filed 2026-08-20 · `d41e1d57…` → **as amended 2026-08-21 · `769b057b…`**
- §5 testimony **not** touched — the steward was reading it; the wording is theirs.
### Returns — 2026-08-21
- ⚠ **Say–do seam, self-caught.** Wrote a hash into PENDING.md, then edited the artifact's footer,
which invalidated it. The intermediate `94ee7793…` never left the session but *was* in the
register for a few minutes. Corrected with the correction marked, not overwritten quietly.
**The rule violated is my own: record after the act, or mark the record prospective.**
- ⚠ **Named before the steward wrote into it:** §5's testimony slot is conditional in one direction
only. A slot phrased toward one answer collects one answer. Surfaced rather than banked.
### Authorization moves — 2026-08-22 (session continues past midnight)
- **Steward authorized §2b + §2c** into the pre-registration, pre-gate. §2b is the **first
amendment to touch the primary measurement** rather than sit beside it.
- `769b057b…` → **`7e1c146b…`** (as-filed 08-20: `d41e1d57…`)
- **Hash taken after the last act**, footer edit included in the same write — yesterday's say–do
seam applied rather than repeated.
- **§4 deliberately NOT amended.** The authorization was to insert 2b and 2c. Repairing a coupling
between a new section and a ratified one is the gate's to rule on. Tension named in the artifact
footer and under PENDING-148 so the gate does not have to find it.
### What held — 2026-08-22
- **Checked the steward's material instead of accepting it.** First summary: every claim traced to
executor-authored write-ups, including the comparative judgement — which is a section heading I
wrote. Second, deeper synthesis: **zero hits** across all four write-ups and the log ⇒ genuinely
the steward's. Same discipline, opposite verdicts, both from grep rather than impression.
- **Drafting an addition found a defect in the host.** §2b was asked for to serve the steward's
register distinction; it surfaced that §4's harvest — the programme's declared deliverable in
every branch — rested on sameness the measurement never establishes. Not what it was drafted for.
### Open horizons — carried
- ⚠ **§4 / §2b coupling** — for the jurist's gate.
- ⚠ **§5 still `[ AWAITING ]`**, and its one-directional framing still unfixed (steward's to settle).
- ⚠ **If the steward's sense of the Fool is largely executor-framed, "the Fool's added value" may be
partly the executor's write-up rhetoric rather than the model's output.** No arm of the programme
measures this. §2c is the closest thing — it checks the characterization against fresh output.
### Returns — 2026-08-22, second batch
- ⚠ **JURIST CORRECTION ACCEPTED, and it is the wrong-subject family again.** I concluded the
perturbation framing "had never been written down" and that "nothing of mine could have pushed
the steward toward it." **I searched three stores; there are four.** The observation exists in
Claude.app conversation history dated 2026-08-17 — the day trial 09 was designed — which no
instrument on my side can reach. **The negative had no positive control on the instrument's own
reach**, which is the epistemic standard this record already holds and which I was in the middle
of *performing* when I broke it. Checked: the overclaim never reached disk. The on-disk claims
are correctly scoped to "all four write-ups and the trial log" and stand.
- ⚠ **SECOND INSTANCE, SAME FAMILY, FOUND IN THIS SESSION'S OWN WAKE REPORT. N-now is 46, not 54.**
I reported 54 under the standing REVIEWED-123 cond. 2 obligation, using `find` — which recurses
into `subagents/` and counted **9 subagent transcripts**. The trigger uses
`TRANSCRIPTS.glob("*.jsonl")`, verified non-recursive at `governance-drift-check.py:331`.
Series corrected: **60 → 61 → 47 → 46**, still falling. My 54 was the only rise and it was an
artifact of using a different instrument than the trigger. **The obligation was discharged with
the wrong tool, which is worse than not discharging it — it reported the trend backwards.**
- Both instances share one shape: **the instrument's reach was not itself checked before its
silence was read as evidence.**
### Authorization moves — 2026-08-22, second batch
- **Jurist buddy-pattern draft filed verbatim** at `claude/governance/fool/BUDDY-PATTERN-jurist-draft-2026-08-22.md`
(sha256 `9aceed7f…`), provenance header stating nothing in it is executor-authored.
- **PENDING-149 [PROPOSAL]** — §8a answered (body/voice split), §8 proportions measured, §5 axes
responded to, PENDING-89's evidence source named.
- **PENDING-150 [ESCALATE]** — §11 alone, deliberately unbundled per the draft's own instruction.
- **Nothing implemented.** §4's order and §13.6 block every run until the steward ratifies §5.
### Open horizons — carried, 2026-08-22
- ⚠ **`input-dependence-01` has NO disposition.** The supersession list does not name it. Not parked
by side effect — that is the 08-20 Q1 error and I was corrected for it once already.
- ⚠ **PENDING-89 starves unless the v1 Chamber archive is read** — 55 files, flagged by me on
2026-08-01 as the ready-made dataset for the doctrine's central untested question, never opened.
- Statusline occupancy unverified before recommending it as the fool's body.
### Authorization moves — 2026-08-22, third batch (v2)
- **v2 stored verbatim** (`ed2861ee…`), supersession header; **v1 retained unaltered** (`9aceed7f…`)
as v2 directs. PENDING-149 AMENDMENT 1 filed.
- **First v2 send was byte-identical to v1** — `diff -u` empty, both bodies `72af4115…`. Reported
as a paste error, **not filed as an amendment**. Trusting the label would have put a supersession
marker over unchanged text.
### What held — 2026-08-22, third batch
- ✅ **§8a's flagged assumption closed by checking, not assuming.** `statusLine` NOT SET in any of
the three settings files ⇒ the surface is free, nothing displaced, body/voice implementable.
- ⚠ **§6b's provenance commit verified against git and its RATIONALE is false.** `3b0730d5` exists
and holds exactly one `CLAUDE.md` (mechanics sound), but it is dated **2026-08-06** — five days
AFTER the fool was conceived (trial 01, 08-01) — its subject names the **PENDING-89 docket**, and
**Constraint 6 is already in it** (placed `c30dfe0`, 08-02). So "seeded from the constitution as
it stood before the fool was conceived" is false: the fool would be seeded from the very doctrine
§11 forbids it from being cited as satisfying. The commit matching the rationale is `4d2ae87`
(2026-07-28). **Not changed — the hash is the jurist's and steward's, not a [FIX].**
- **Both findings came from opening the substrate rather than reading the document's own claim
about itself** — the same act that failed three times this week, run deliberately this time.
### Open horizons — 2026-08-22, third batch
- ⚠ **TIME-CRITICAL: beacon timestamp 2026-08-25T12:00:00Z, three days out**, and §4 requires the
seed rule filed and pushed BEFORE it. §6b disposition + `<DATE FILED>` both needed first.
- ⚠ **§5 ratification ambiguous** — v2's heading says "ratified by the steward", §13.7 says nothing
runs until ratified. Treated as NOT ratified (conservative; undoable only by waiting).
- **No beacon pulse fetched**, target or near-future. No dry run attempted.
- Owed under §15b: state the zero-contribution in PENDING-89; open the v1 Chamber archive read as
its own [PROPOSAL].