[PROPOSAL] Fool seed rule filed before the beacon; two unresolvable values caught (PENDING-149)
§4 steps 1-4 discharged and pushed ahead of the 2026-08-25T12:00:00Z beacon: ratified axes recorded in writing, seed derivation rule filed, retirement and regeneration criteria filed, derivation implemented and self-tested. Two values in the jurist's §6b block did not resolve, and both are corrected in the open rather than absorbed: - the provenance commit's stated rationale was false.3b0730d5(2026-08-06) postdates the fool's conception by five days, its subject names the PENDING-89 docket, and Constraint 6 is already in it. Steward directed4d2ae87(2026-07-28), where Constraint 6 occurs zero times. - the retrieval URL returns HTTP 302 and an empty body, redirecting to an HTML page. Filed verbatim, the 25th would have produced no pulse and the UNAVAILABILITY clause would have run a 24-hour retry against an address that can never return one. Found only because §6b directs a historical dry run. Also measured: outputValue is served UPPERCASE, so the rule's "lowercased before use" is load-bearing; and curl reaches the beacon where python urllib times out. Nothing derived. Target pulse not fetched. CLAUDE.md untouched (PENDING-150). Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01JQKeKY9T9d95KpvHwwok8T
This commit is contained in:
co-authored by
Claude Opus 5
parent
7b366eb646
commit
acfbb9fc0e
@@ -0,0 +1,257 @@
|
||||
---
|
||||
name: BUDDY-PATTERN-jurist-draft-2026-08-22
|
||||
description: "Jurist draft, 2026-08-22 — executor instructions for the Fool as a buddy-pattern fourth position. NOT AUTHORIZED. Filed verbatim as received; PENDING-149 ([PROPOSAL]) and PENDING-150 ([ESCALATE], §11 only) carry the executor's response. Supersedes the trial programme's object, not its record."
|
||||
metadata:
|
||||
node_type: governance-artifact
|
||||
type: reference
|
||||
provenance: "Received from the jurist via the steward, 2026-08-22. Stored verbatim. Executor commentary lives in PENDING, never in this file."
|
||||
---
|
||||
|
||||
# Executor instructions — the Fool (buddy pattern)
|
||||
|
||||
> **STORED VERBATIM AS RECEIVED.** Nothing in this file is executor-authored. The
|
||||
> executor's contested points, the §8a answer and the §8 frequency measurement are
|
||||
> filed under PENDING-149; §11 is filed separately under PENDING-150 and must not be
|
||||
> bundled with it.
|
||||
|
||||
Prepared by the jurist, 2026-08-22, at the steward's request. **Not authorized.**
|
||||
File as `[PROPOSAL]`; see §11 for the part that is `[ESCALATE]` and must not be
|
||||
bundled with it.
|
||||
|
||||
---
|
||||
|
||||
## 1 · What this is
|
||||
|
||||
A fourth position in the working cycle, built on the Claude Code `/buddy`
|
||||
architecture. Ambient, event-triggered, one line at a time, addressed to the
|
||||
steward alone. It produces no findings, opens no items, and no ruling turns on
|
||||
it.
|
||||
|
||||
It is safe **without being checkable**, because nothing follows from it. This
|
||||
inverts the standing correction of 2026-08-02 — *findings earn a hearing by
|
||||
being checkable, never by role* — which is correct for findings and
|
||||
inapplicable here: a position that makes no claims is not subject to a warrant
|
||||
test. Do not build a checkability gate into this.
|
||||
|
||||
## 2 · What it is NOT
|
||||
|
||||
- Not a checker, auditor, reviewer, or devil's advocate. **If its output can be
|
||||
graded, the design has failed.**
|
||||
- Not the Fool trial programme. Trials 01–09 measured a checker; this is a
|
||||
different object. Do not reuse their instruments, grading vocabulary, corpus,
|
||||
partitioning, or ground truth.
|
||||
- Not an answer to Constraint 6. See §11.
|
||||
|
||||
## 3 · Reference implementation — scope limited
|
||||
|
||||
Reference: `https://github.com/milind-soni/claude-pets` — a third-party
|
||||
extraction of Claude Code's buddy system.
|
||||
|
||||
**TAKE:**
|
||||
|
||||
- the derivation chain (FNV-1a → Mulberry32 → stat draws, peak/dump assignment);
|
||||
- the idle cadence table and its proportions;
|
||||
- the fresh-overrides-stored rule.
|
||||
|
||||
**DO NOT TAKE:** species, rarity tiers, shiny, hats, eyes, sprites, animation
|
||||
frames, petting, the canned reaction strings, or the buddy's own stat set
|
||||
(`DEBUGGING / PATIENCE / CHAOS / WISDOM / SNARK` — superseded by §5).
|
||||
|
||||
⚠ **Rarity in particular is a gacha mechanic: it scales stat FLOORS.** A floor
|
||||
softens the dump, and the dump is the entire point. Do not port it.
|
||||
|
||||
**Provenance:** third-party extraction, not Anthropic documentation. Verify the
|
||||
derivation behaves as described rather than trusting the README. Once the seed
|
||||
rule is filed under §4, **the filed rule governs** — a quirk in someone's
|
||||
extraction must not become constitutional by accident.
|
||||
|
||||
## 4 · Pre-registration order — MANDATORY
|
||||
|
||||
The order is load-bearing. Each step is committed and pushed before the next
|
||||
begins.
|
||||
|
||||
1. Perception axes ratified by the steward (§5).
|
||||
2. Seed derivation rule filed, naming a **future** timestamp (§6).
|
||||
3. Abandonment criterion filed (§10).
|
||||
4. Regeneration criterion filed (§10).
|
||||
5. Timestamp passes; seed computed; bones derived.
|
||||
6. Soul generated once from the bones (§7).
|
||||
|
||||
Steps 1–4 must be complete and pushed **before** step 5. Axes chosen after the
|
||||
seed is known, or with a fool in hand, smuggle the selection one level up.
|
||||
|
||||
## 5 · Perception axes — jurist proposal, steward ratifies
|
||||
|
||||
Five axes on 0–100. Each is something the fool could be **blind to**. The
|
||||
steward must be able to imagine a dump on any one costing him something; if not,
|
||||
it is not a real axis and should be replaced before ratification.
|
||||
|
||||
- **SUCCESSION** — would this be legible to someone arriving cold, with no thread?
|
||||
- **ABSENCE** — what is not here, not asked, not yet existing?
|
||||
- **AIM** — is this the right question, at the right level?
|
||||
- **SCALE** — is the unit right? (item vs block vs programme)
|
||||
- **STAKE** — who bears the cost if this is wrong?
|
||||
|
||||
*Jurist note, disclosed:* the steward has said his prior buddy was strong on
|
||||
pattern recognition and debugging. No axis above is drawn from that, on purpose.
|
||||
Adding one now would be selection toward a known preference.
|
||||
|
||||
**Register properties — terseness, snark, obliquity, chaos — are NOT axes.**
|
||||
They belong to the soul (§7) and are not seeded independently. The dump must be
|
||||
a blind spot, not a style: a fool that is merely predictable is blind to
|
||||
nothing.
|
||||
|
||||
## 6 · Bones
|
||||
|
||||
- **Seed:** SHA-256 of a public value that does not exist at filing time. The
|
||||
steward names the source and timestamp — NIST Randomness Beacon or equivalent.
|
||||
- **Derivation:** seed → FNV-1a → Mulberry32 → stat draws.
|
||||
- One **peak** (near max), one **dump** (near floor), three scattered.
|
||||
- Recomputed fresh every session from the seed. **Never cached.** A stored value
|
||||
that disagrees with the fresh computation loses.
|
||||
- **No rerolls.** The first output is the fool.
|
||||
|
||||
The dump stat is the point, not a side effect. It is the only guaranteed
|
||||
difference this position has, and the seed — not the steward — decides where the
|
||||
hole goes. Do not add a floor that softens it.
|
||||
|
||||
## 7 · Soul
|
||||
|
||||
Character and register generated **once** from the bones, stored permanently,
|
||||
never hand-edited and never regenerated for taste. One generation, kept.
|
||||
|
||||
## 8 · Cadence and triggers
|
||||
|
||||
Fixed table, adapted from the buddy's idle cycle: approximately **73% silent,
|
||||
20% brief aside, 7% notable.** Hardcoded. Neither the fool nor the steward can
|
||||
tune it.
|
||||
|
||||
⚠ *Rationale, and this is the part most likely to be lost in implementation:* a
|
||||
fool that decides when to escalate will learn from being heard or muted and
|
||||
drift toward speaking when it expects attention. That is the contamination
|
||||
gradient arriving through the one position built to resist it. **The cadence
|
||||
must be unlearnable.**
|
||||
|
||||
Triggers are **EVENT-keyed, never content-keyed.** It fires on occurrences —
|
||||
item filed, ruling recorded, proposal amended, census run, wake, wrap-up — and
|
||||
never on an assessment of whether the thing is any good. **Do not implement
|
||||
quality evaluation of any kind.**
|
||||
|
||||
Wake and wrap-up are guaranteed fire points. Observed drift consolidates at
|
||||
session seams, not at gates.
|
||||
|
||||
⚠ **Sanity-check the proportions against real event frequency before
|
||||
implementing.** If the cycle fires forty events a day, 7% notable is five
|
||||
interruptions and too many. Report the actual rate and propose adjusted
|
||||
proportions rather than porting the buddy's numbers blind.
|
||||
|
||||
### 8a · OPEN — where silence is legible
|
||||
|
||||
The buddy's cadence depends on a **persistent rendered presence**: it sits in a
|
||||
terminal chrome and idles visibly, so its silence is *seen*. This arrangement
|
||||
has no equivalent surface, and the fool has nowhere to idle.
|
||||
|
||||
**Executor to propose how the fool is present when it is NOT speaking**, with
|
||||
options and costs, before the cadence is implemented. Three shapes are known to
|
||||
the jurist and are offered as a starting point, not a menu:
|
||||
|
||||
- *Rendered presence* — a statusline or session-footer element, present always,
|
||||
mostly showing nothing. Closest to the buddy; preserves visible silence; most
|
||||
plumbing.
|
||||
- *Interjection only* — appears when it fires, otherwise invisible. Cheapest.
|
||||
But every appearance becomes an event, which collapses the 20% aside into
|
||||
something that reads as notable.
|
||||
- *Seam-only* — appears in the wake digest and wrap-up, always, sometimes with
|
||||
nothing to say. Silence becomes a blank line in a place already read. Nearly
|
||||
free, since both hooks exist — but loses the *in the room, hears everything*
|
||||
property.
|
||||
|
||||
⚠ **If silence cannot be made legible, the three-state cadence collapses to
|
||||
two, and §8's proportions need re-deriving rather than porting.** Do not
|
||||
implement §8 until this is answered.
|
||||
|
||||
The executor is better placed than the jurist to answer this — it knows the
|
||||
surfaces. Answer with options, not a decision.
|
||||
|
||||
## 9 · Channel and register
|
||||
|
||||
- Output reaches **the steward**. Filed nowhere. No `PENDING` entry, no log, no
|
||||
item.
|
||||
- **ONE LINE** for the ordinary case. Paragraph-length governance prose is the
|
||||
genre the trio already metabolizes; the constraint is what keeps the fool
|
||||
uningestible.
|
||||
- **Named invocation:** the steward calls it by name, the executor or jurist
|
||||
yields the floor, the fool answers at length.
|
||||
- `mute` / `off` available at all times. Mute rate may be counted; muting is
|
||||
never a fault.
|
||||
|
||||
Anything the steward carries into the record enters **as the steward's, in his
|
||||
words**. The fool is never cited as a source.
|
||||
|
||||
## 10 · Pre-registered criteria — filed before the fool exists
|
||||
|
||||
**REGENERATION** is permitted ONLY on a demonstrable implementation error,
|
||||
verified against the filed derivation rule. Not because the output is disliked.
|
||||
|
||||
**RETIREMENT** only on mechanical failure: does not fire; fires constantly; or
|
||||
produces gradeable in-genre findings despite §9.
|
||||
|
||||
**NOT grounds for retirement:** being uncomfortable, being frequently wrong,
|
||||
being annoying, being ignored. Those are the specification. Lear ignores his
|
||||
Fool for four acts and the Fool is not thereby broken.
|
||||
|
||||
## 11 · `[ESCALATE]` — do not bundle
|
||||
|
||||
Whether a fourth position exists in the arrangement is a change to the
|
||||
tripartite model and touches `~/CLAUDE.md`. That is constitutional, and is a
|
||||
**separate item requiring its own steward authorization.** Do not amend
|
||||
`CLAUDE.md` under this proposal.
|
||||
|
||||
**Standing caveat, to be written into the fool's own doctrine at the outset:**
|
||||
if the fool runs on Claude, three of four parties share formation, which makes
|
||||
Constraint 6's concession worse rather than better. The dump stat mandates ONE
|
||||
declared hole; the undeclared ones are shared and invisible — and if what the
|
||||
jurist misses, the executor misses, and the fool also misses, that is
|
||||
PENDING-89's falsifier firing quietly.
|
||||
|
||||
⚠ **THE FOOL MAY NEVER BE CITED AS SATISFYING CONSTRAINT 6, OR AS SUPPLYING
|
||||
EPISTEMIC DIVERSITY.** It tests positional difference — PENDING-140's third axis
|
||||
— not formation difference.
|
||||
|
||||
## 12 · Build order
|
||||
|
||||
**Claude-first.** Simpler, and the steward's own precedent ran on Claude.
|
||||
|
||||
The generator is a **swappable parameter**: running the same fool on a local
|
||||
model later, and reading the divergence between the two, is the v1 Chamber
|
||||
property at negligible cost. Do not build for that now; do not preclude it.
|
||||
|
||||
## 13 · Deliverables
|
||||
|
||||
1. Spec document in the governance tree, with a provenance header stating it
|
||||
derives from this jurist draft and naming what was changed.
|
||||
2. Answer to §8a — options and costs — **before** §8 is implemented.
|
||||
3. Filed axes, seed rule, abandonment and regeneration criteria — committed and
|
||||
pushed **before** the seed timestamp.
|
||||
4. Derivation implementation: deterministic, fresh-overrides-stored, no reroll
|
||||
path.
|
||||
5. Hook wiring for event triggers, wake and wrap-up guaranteed.
|
||||
6. Nothing run until the steward ratifies §5.
|
||||
|
||||
## 14 · Expected pushback
|
||||
|
||||
The jurist expects the executor to contest at least two things, and should:
|
||||
|
||||
- **whether the five axes in §5 are the right five** — the executor has working
|
||||
context the jurist does not;
|
||||
- **whether §8's proportions survive contact with real event frequency.**
|
||||
|
||||
Both are contestable on evidence. §6's no-reroll rule, §8's unlearnable cadence,
|
||||
§9's no-filing rule, and §11 are not — they are what make the position safe
|
||||
without a warrant test, and weakening any one of them returns this to a fourth
|
||||
reviewer.
|
||||
|
||||
---
|
||||
|
||||
*Jurist draft. The steward authorizes; the executor implements. Nothing in this
|
||||
document is a ruling.*
|
||||
@@ -0,0 +1,452 @@
|
||||
---
|
||||
name: BUDDY-PATTERN-jurist-draft-v2-2026-08-22
|
||||
description: "Jurist draft v2, 2026-08-22 — SUPERSEDES v1 of the same date. Stored verbatim. Where v1 and v2 differ, v2 governs; v1 is retained as the record of what was asked before the executor's measurements came back. NOT AUTHORIZED. Executor commentary lives in PENDING-149/150, never in this file."
|
||||
metadata:
|
||||
node_type: governance-artifact
|
||||
type: reference
|
||||
supersedes: BUDDY-PATTERN-jurist-draft-2026-08-22.md
|
||||
provenance: "Received from the jurist via the steward, 2026-08-22. Stored verbatim, byte-checked on receipt."
|
||||
---
|
||||
|
||||
> **STORED VERBATIM AS RECEIVED.** Nothing in this file is executor-authored.
|
||||
> **This is v2 and it GOVERNS.** v1 (`9aceed7f…`) is retained unaltered as the record of
|
||||
> what was asked before the executor's measurements came back — not deleted, not edited.
|
||||
> Executor verification results, contested points and dispositions live in PENDING-149
|
||||
> and PENDING-150.
|
||||
|
||||
# Executor instructions — the Fool (buddy pattern), **v2**
|
||||
|
||||
Prepared by the jurist, 2026-08-22. **Supersedes the v1 draft of the same date**
|
||||
(stored verbatim at `9aceed7f…`). v1 is retained as the record of what was asked
|
||||
before the executor's measurements came back; **where the two differ, v2
|
||||
governs.**
|
||||
|
||||
Filed as `PENDING-149 [PROPOSAL]`; the constitutional part is `PENDING-150
|
||||
[ESCALATE]` and stays unbundled. **Not authorized.**
|
||||
|
||||
## 0 · What changed from v1, and why
|
||||
|
||||
| § | change | cause |
|
||||
|---|---|---|
|
||||
| 3 | salt and stat-shift added to DO-NOT-TAKE | third source review |
|
||||
| 5 | sixth axis (PROCEDURE) **declined**, with reason | executor's §5 observation |
|
||||
| 8 | cadence re-keyed: **time-ticked, not event-ticked** | executor's burst measurement |
|
||||
| 8a | **RESOLVED** — body/voice separation adopted | executor's answer |
|
||||
| 15 | dispositions for `input-dependence-01` and PENDING-89 | executor's open question |
|
||||
| 6, 6a, 6b | two-component seed specified; delegation protocol; filed rule with timestamp 2026-08-25T12:00:00Z | steward decision |
|
||||
|
||||
Two executor corrections are accepted and noted here so they are not lost: the
|
||||
three-store negative that never reached disk, and the `find`-vs-`glob` error
|
||||
that reported the transcript trend backwards (N = 46, not 54; corrected series
|
||||
60 → 61 → 47 → 46). The second is the more instructive: **an obligation
|
||||
discharged with the wrong instrument reported the trend inverted**, which is
|
||||
worse than not discharging it. The glob rule now in `MEMORY.md` is the right fix.
|
||||
|
||||
---
|
||||
|
||||
## 1 · What this is
|
||||
|
||||
A fourth position in the working cycle, built on the Claude Code `/buddy`
|
||||
architecture. Ambient, one line at a time, addressed to the steward alone. It
|
||||
produces no findings, opens no items, and no ruling turns on it.
|
||||
|
||||
It is safe **without being checkable**, because nothing follows from it. This
|
||||
inverts the standing correction of 2026-08-02 — *findings earn a hearing by
|
||||
being checkable, never by role* — which is correct for findings and inapplicable
|
||||
here: a position that makes no claims is not subject to a warrant test. Do not
|
||||
build a checkability gate into this.
|
||||
|
||||
## 2 · What it is NOT
|
||||
|
||||
- Not a checker, auditor, reviewer, or devil's advocate. **If its output can be
|
||||
graded, the design has failed.**
|
||||
- Not the Fool trial programme. Trials 01–09 measured a checker; this is a
|
||||
different object. Do not reuse their instruments, grading vocabulary, corpus,
|
||||
partitioning, or ground truth.
|
||||
- Not an answer to Constraint 6. See §11.
|
||||
|
||||
## 3 · Reference implementations — scope limited
|
||||
|
||||
Primary: `https://github.com/ramarivera/coding-buddy` — community MCP
|
||||
recreation, and the most useful of the three. Secondary:
|
||||
`https://github.com/milind-soni/claude-pets` — source extraction.
|
||||
|
||||
**TAKE:**
|
||||
|
||||
- the derivation chain (FNV-1a → Mulberry32 → stat draws, peak/dump assignment);
|
||||
- the **body/voice integration pattern**: animated status line + hook-driven
|
||||
reactions (see §8a);
|
||||
- the fresh-overrides-stored rule.
|
||||
|
||||
**DO NOT TAKE:**
|
||||
|
||||
- species, rarity tiers, shiny, hats, eyes, sprites, animation frames, petting,
|
||||
canned reaction strings, or the buddy's own stat set (superseded by §5);
|
||||
- ⚠ **rarity** — it is a gacha mechanic that scales stat **floors**. A floor
|
||||
softens the dump, and the dump is the entire point;
|
||||
- ⚠ **the salt `friend-2026-401`.** Take the algorithm, not the salt. A fixed,
|
||||
published salt with a single known user makes the fool computable in advance,
|
||||
which defeats §6 entirely. The seed comes from §6's filed rule and nowhere
|
||||
else;
|
||||
- ⚠ **any mechanic by which stats shift during a session based on activity.**
|
||||
A drifting dump is not a mandated blind spot. §6's fresh-recompute rule
|
||||
governs; nothing modifies the bones after derivation.
|
||||
|
||||
**Provenance:** community reconstructions of a feature that shipped for eight
|
||||
days and was withdrawn. The *code* is verifiable — FNV-1a and Mulberry32 are
|
||||
standard, and the derivation can be tested directly. The surrounding
|
||||
documentation is SEO-grade and should not be relied on. Once §6's rule is filed,
|
||||
**the filed rule governs**, so no quirk of an extraction becomes constitutional
|
||||
by accident.
|
||||
|
||||
⚠ Note also that **nobody has run this pattern for longer than eight days.**
|
||||
There is no wear data. Expect to discover things.
|
||||
|
||||
## 4 · Pre-registration order — MANDATORY
|
||||
|
||||
Each step committed and pushed before the next begins.
|
||||
|
||||
1. Perception axes ratified by the steward (§5).
|
||||
2. Seed derivation rule filed, naming a **future** timestamp (§6).
|
||||
3. Abandonment criterion filed (§10).
|
||||
4. Regeneration criterion filed (§10).
|
||||
5. Timestamp passes; seed computed; bones derived.
|
||||
6. Soul generated once from the bones (§7).
|
||||
|
||||
Steps 1–4 complete and pushed **before** step 5. Axes chosen after the seed is
|
||||
known, or with a fool in hand, smuggle the selection one level up.
|
||||
|
||||
## 5 · Perception axes — five, ratified by the steward
|
||||
|
||||
Five axes, 0–100. Each is something the fool could be **blind to**. The steward
|
||||
must be able to imagine a dump on any one costing him something.
|
||||
|
||||
- **SUCCESSION** — would this be legible to someone arriving cold, with no thread?
|
||||
- **ABSENCE** — what is not here, not asked, not yet existing?
|
||||
- **AIM** — is this the right question, at the right level?
|
||||
- **SCALE** — is the unit right? (item vs block vs programme)
|
||||
- **STAKE** — who bears the cost if this is wrong?
|
||||
|
||||
### 5a · The proposed sixth axis is DECLINED — and the observation is right
|
||||
|
||||
The executor observes that these five are all axes of *judgement*, while what
|
||||
actually gets caught are failures of *procedure*: a claim made before the file
|
||||
was opened, a hash recorded before the last edit, an instrument used past its
|
||||
demonstrated tier. Three in a single day. The observation is correct and the
|
||||
evidence is good.
|
||||
|
||||
**The axis is still declined, and the reason is structural: procedure failures
|
||||
are checkable.** A claim made before a file was opened is verifiable from logs.
|
||||
A hash predating an edit is verifiable from git. An instrument used past its
|
||||
tier is verifiable against the instrument's own record. That is the one domain
|
||||
this position must stay out of — §2 says gradeable means failed, and a
|
||||
PROCEDURE-peaked fool would produce nothing but gradeable observations.
|
||||
|
||||
The observation should be honoured somewhere else. **If it can be scripted,
|
||||
script it.** These three failure shapes are exactly what `governance-drift-check.py`
|
||||
is for, and a procedure-check extension is a separate `[HARDENING]` item worth
|
||||
opening on its own merits. Do not route it through the fool.
|
||||
|
||||
The executor's self-disclosure — that selection toward a known preference
|
||||
applies to it harder than to the jurist — is accepted as correctly reasoned and
|
||||
is part of why this is declined rather than adopted.
|
||||
|
||||
**Register properties — terseness, snark, obliquity, chaos — are NOT axes.**
|
||||
They belong to the soul (§7). The dump must be a blind spot, not a style: a fool
|
||||
that is merely predictable is blind to nothing.
|
||||
|
||||
## 6 · Bones
|
||||
|
||||
**Seed — two components, concatenated in this order:**
|
||||
|
||||
1. **Provenance component.** The SHA of `CLAUDE.md` at a **named past commit** in
|
||||
the dotfiles repo, specified by full commit hash in the filed rule. Fixed
|
||||
forever; the commit does not change.
|
||||
2. **Entropy component.** The NIST Randomness Beacon output value for a pulse at
|
||||
a **stated future timestamp**, hex-encoded, lowercase.
|
||||
|
||||
`seed_string = <claude-md-sha> || <beacon-value>`, then SHA-256 of that.
|
||||
|
||||
⚠ **What each component does, so neither is mistaken for the other.** The
|
||||
provenance component contributes **no unpredictability** — its value is
|
||||
computable today. It is there so the fool is seeded from the constitution it
|
||||
will accompany, which is a meaningful property and not a protective one. **All
|
||||
selection-resistance comes from the entropy component.** If the beacon component
|
||||
were ever dropped, the construction would collapse into a value the steward can
|
||||
compute and steer. It cannot be dropped.
|
||||
|
||||
The provenance commit must be **past and named by full hash** — never `HEAD`,
|
||||
never 'the current version'. A live file makes the seed rerollable by ordinary
|
||||
work: amending the constitution would redraw the fool, and §6's no-reroll rule
|
||||
would be unenforceable precisely through the action most likely to be taken.
|
||||
|
||||
**Derivation:** seed → FNV-1a → Mulberry32 → stat draws.
|
||||
|
||||
- One **peak** (near max), one **dump** (near floor), three scattered.
|
||||
- Recomputed fresh every session from the seed. **Never cached.** A stored value
|
||||
disagreeing with the fresh computation loses.
|
||||
- **No rerolls.** The first output is the fool.
|
||||
|
||||
The dump is the point, not a side effect. It is the only guaranteed difference
|
||||
this position has, and the seed — not the steward — decides where the hole goes.
|
||||
No floor softens it.
|
||||
|
||||
### 6a · Delegation protocol — the executor computes it
|
||||
|
||||
Delegation is correct here. The executor has no preference about the fool's
|
||||
stats; the steward does. The risk is not steering but the ordinary failure
|
||||
already seen twice this week — wrong instrument, or a good-faith regeneration
|
||||
that quietly lands draw two.
|
||||
|
||||
**Before the timestamp**, the executor files and pushes: the beacon source, the
|
||||
exact pulse timestamp, the provenance commit hash, and the derivation as
|
||||
executable code.
|
||||
|
||||
**After the timestamp**, in a single commit: the raw beacon value, the seed
|
||||
string, the SHA-256, the resulting stats, and the commit hash of the filed rule
|
||||
it ran against.
|
||||
|
||||
**The steward does not see the beacon value before the derivation runs.**
|
||||
|
||||
⚠ **The executor does not run the derivation more than once.** If it fails —
|
||||
bug, crash, wrong pulse — it **STOPS and reports.** It does not retry on its own
|
||||
authority. A second run is a reroll regardless of intent.
|
||||
|
||||
The one distinction worth having in advance, because it will be met in good
|
||||
faith: **a re-run against the same recorded pulse value is legitimate** — the
|
||||
input did not change, only a broken implementation did. **A re-run against a
|
||||
later pulse is a new draw** and is governed by §10's regeneration criterion.
|
||||
Record the pulse value the moment it is fetched, before running anything, so
|
||||
this distinction stays available.
|
||||
|
||||
⚠ **No dry runs against a live pulse.** The executor must not fetch the target
|
||||
pulse, or any near-future pulse, to test the pipeline. A dry run against a live
|
||||
value is how a test quietly becomes draw zero. **Test against a fixed historical
|
||||
pulse** — any pulse from a past year — which exercises the identical code path
|
||||
with no possibility of contaminating the real draw.
|
||||
|
||||
### 6b · The filed rule — commit this block verbatim
|
||||
|
||||
This is the artefact §4 step 2 requires. It is committed and pushed **before**
|
||||
the timestamp below. Where this block and §6's prose differ, **this block
|
||||
governs.**
|
||||
|
||||
```
|
||||
FOOL SEED DERIVATION RULE
|
||||
Filed: <DATE FILED> Governs: PENDING-149 §6
|
||||
|
||||
ENTROPY COMPONENT
|
||||
Source: NIST Randomness Beacon v2.0, https://beacon.nist.gov/beacon/2.0/
|
||||
Retrieval: GET /pulse?timeGE=2026-08-25T12:00:00Z
|
||||
Field: pulse.outputValue, hex, lowercased before use
|
||||
|
||||
PROVENANCE COMPONENT
|
||||
File: CLAUDE.md in ~/dotfiles, at commit
|
||||
3b0730d59336113aa3a500a889a3e154be6a1de7
|
||||
Value: SHA-256 of the file contents at that commit, hex, lowercase
|
||||
Note: contributes provenance, NOT unpredictability. Past commit,
|
||||
named by full hash. Verify with:
|
||||
git -C ~/dotfiles cat-file -p 3b0730d5...:<path> | shasum -a 256
|
||||
The path must be recorded alongside the hash — a repo may hold
|
||||
more than one CLAUDE.md, and the rule must name exactly one file.
|
||||
|
||||
SEED
|
||||
seed_string = <provenance-sha256> || <beacon-outputValue-lowercased>
|
||||
seed = SHA-256(seed_string), hex, lowercase
|
||||
|
||||
DERIVATION
|
||||
seed -> FNV-1a -> Mulberry32 -> stat draws over the five axes of §5.
|
||||
One peak, one dump, three scattered. No salt from any reference
|
||||
implementation.
|
||||
|
||||
EXECUTION
|
||||
Run ONCE. The executor does not retry on its own authority.
|
||||
A re-run against the SAME recorded outputValue is legitimate (broken
|
||||
implementation). A re-run against a LATER pulse is a new draw, governed
|
||||
by §10.
|
||||
Record outputValue the moment it is fetched, before running anything.
|
||||
|
||||
UNAVAILABILITY
|
||||
If no pulse is returned at or after the stated timestamp, retry the same
|
||||
request for up to 24 hours. If still unavailable: STOP and report. Do not
|
||||
substitute a different timestamp, beacon, or source.
|
||||
|
||||
TESTING
|
||||
Dry runs use a fixed historical pulse only. Never the target pulse, never
|
||||
a near-future pulse.
|
||||
```
|
||||
|
||||
One value remains for the steward: `<DATE FILED>`. The provenance commit is
|
||||
`3b0730d59336113aa3a500a889a3e154be6a1de7` — the last commit to the global
|
||||
`CLAUDE.md` before this line of work began, chosen so the fool is seeded from
|
||||
the constitution as it stood before the fool was conceived. The executor records
|
||||
the file path alongside the hash and confirms the blob resolves before the
|
||||
beacon timestamp; a rule that cannot be resolved on the day is not a rule.
|
||||
|
||||
## 7 · Soul
|
||||
|
||||
Character and register generated **once** from the bones, stored permanently,
|
||||
never hand-edited, never regenerated for taste. One generation, kept.
|
||||
|
||||
## 8 · Cadence — RE-KEYED
|
||||
|
||||
⚠ **v1's §8 was wrong and the executor found why.** The buddy's 73/20/7
|
||||
proportions are calibrated against a **time-uniform tick** — an idle animation
|
||||
loop. v1 re-keyed them to *events*, and events burst by a factor of ~50: 4.2
|
||||
governance events/day over 45 days, 6.2 on active days, range 1 to 53. Same
|
||||
proportions, different generator, and the consequence is that **the fool is
|
||||
loudest on the heaviest days** — fourteen utterances on 2026-08-08.
|
||||
|
||||
The executor proposed keeping the proportions, keying voice to seams, and adding
|
||||
a hard daily cap. **Two of those three are adopted; the cap is not, and it is
|
||||
redundant anyway** — if voice is seam-keyed, seams already fire two or three
|
||||
times a day, so a daily cap gates nothing. It also introduces a *budget-spent*
|
||||
state, which is memory, and memory is the beginning of learnability.
|
||||
|
||||
**The fix is to restore the original generator, not to patch the re-keyed one.**
|
||||
Three tiers:
|
||||
|
||||
| tier | trigger | rate |
|
||||
|---|---|---|
|
||||
| **body** | every turn | always present, silent |
|
||||
| **mumble** | **time-ticked**, not event-ticked | low, fixed |
|
||||
| **voice** | seams (wake, wrap-up) | guaranteed, ~2–3/day |
|
||||
|
||||
The mumble ticks on a clock — per interval or per session — **never per
|
||||
governance event.** Events supply *content*: what the fool remarks on is drawn
|
||||
from what has happened since the last tick. Frequency and content are separated,
|
||||
which is what v1 conflated.
|
||||
|
||||
This has no memory and no budget, so the cadence stays unlearnable. It also
|
||||
preserves the *in the room, hears everything* property that a seam-only voice
|
||||
would lose.
|
||||
|
||||
⚠ Report the observed mumble rate after two weeks. If it reads as noise, the
|
||||
interval lengthens — **the proportions do not become adaptive.**
|
||||
|
||||
Triggers remain **EVENT-keyed for content, never content-keyed for judgement.**
|
||||
The fool never assesses whether a thing is any good. **Do not implement quality
|
||||
evaluation of any kind.**
|
||||
|
||||
### 8a · RESOLVED — body and voice are separable
|
||||
|
||||
The executor's answer is adopted, and it is better than any of v1's three
|
||||
options, which each tried to solve presence and speech with one surface.
|
||||
|
||||
- **Body = the status line.** Rendered every turn, carrying the name and nothing
|
||||
else. Silence becomes visible at near-zero cost. This is what makes the
|
||||
three-tier cadence legible rather than merely intermittent.
|
||||
- **Voice = the seams**, which already fire and are proven.
|
||||
|
||||
⚠ **One unverified assumption, flagged by the executor and to be closed before
|
||||
implementation: whether a status line is already in use.** If it is, propose the
|
||||
accommodation rather than displacing it.
|
||||
|
||||
`coding-buddy`'s Stop-hook fallback implies its primary trigger path is
|
||||
unreliable. Plan for that rather than discovering it.
|
||||
|
||||
## 9 · Channel and register
|
||||
|
||||
- Output reaches **the steward**. Filed nowhere. No `PENDING` entry, no log, no
|
||||
item.
|
||||
- **ONE LINE** for the ordinary case. Paragraph-length governance prose is the
|
||||
genre the trio already metabolizes; the constraint is what keeps the fool
|
||||
uningestible.
|
||||
- **Named invocation:** the steward calls it by name, the executor or jurist
|
||||
yields the floor, the fool answers at length.
|
||||
- `mute` / `off` available at all times. Mute rate may be counted; muting is
|
||||
never a fault.
|
||||
|
||||
Anything the steward carries into the record enters **as the steward's, in his
|
||||
words**. The fool is never cited as a source.
|
||||
|
||||
## 10 · Pre-registered criteria — filed before the fool exists
|
||||
|
||||
**REGENERATION** only on a demonstrable implementation error, verified against
|
||||
the filed derivation rule. Not because the output is disliked.
|
||||
|
||||
**RETIREMENT** only on mechanical failure: does not fire; fires constantly; or
|
||||
produces gradeable in-genre findings despite §9.
|
||||
|
||||
**NOT grounds for retirement:** being uncomfortable, being frequently wrong,
|
||||
being annoying, being ignored. Those are the specification. Lear ignores his
|
||||
Fool for four acts and the Fool is not thereby broken.
|
||||
|
||||
## 11 · `[ESCALATE]` — PENDING-150, unbundled
|
||||
|
||||
Whether a fourth position exists in the arrangement changes the tripartite model
|
||||
and touches `~/CLAUDE.md`. Constitutional; separate item; separate steward
|
||||
authorization. **Do not amend `CLAUDE.md` under PENDING-149.**
|
||||
|
||||
**Standing caveat, written into the fool's own doctrine at the outset:** if the
|
||||
fool runs on Claude, three of four parties share formation, which makes
|
||||
Constraint 6's concession worse rather than better. The dump mandates ONE
|
||||
declared hole; the undeclared ones are shared and invisible — and if what the
|
||||
jurist misses, the executor misses, and the fool also misses, that is
|
||||
PENDING-89's falsifier firing quietly.
|
||||
|
||||
⚠ **THE FOOL MAY NEVER BE CITED AS SATISFYING CONSTRAINT 6 OR AS SUPPLYING
|
||||
EPISTEMIC DIVERSITY.** It tests positional difference — PENDING-140's third axis
|
||||
— not formation difference.
|
||||
|
||||
## 12 · Build order
|
||||
|
||||
**Claude-first.** Simpler, and the steward's own precedent ran on Claude.
|
||||
|
||||
The generator is a **swappable parameter**: running the same fool on a local
|
||||
model and reading the divergence between the two is the v1 Chamber property at
|
||||
negligible cost. Do not build for it now; do not preclude it.
|
||||
|
||||
## 13 · Deliverables
|
||||
|
||||
1. Spec document in the governance tree, provenance header naming this v2 draft
|
||||
and what was changed.
|
||||
2. Status-line availability confirmed (§8a) **before** §8 is implemented.
|
||||
3. Filed axes, seed rule (both components, §6), abandonment and regeneration
|
||||
criteria — committed and pushed **before** the beacon timestamp.
|
||||
4. Derivation implementation: deterministic, fresh-overrides-stored, no reroll
|
||||
path, **no salt from any reference implementation.**
|
||||
5. Post-derivation record per §6a, in a single commit: raw beacon value, seed
|
||||
string, SHA-256, resulting stats, and the commit hash of the filed rule.
|
||||
6. Hook wiring: status line every turn; time-ticked mumble; seams guaranteed.
|
||||
7. Nothing run until the steward ratifies §5.
|
||||
|
||||
## 14 · Contestable and not
|
||||
|
||||
**Contestable on evidence:** the five axes; the mumble interval; the status-line
|
||||
approach if the surface is unavailable.
|
||||
|
||||
**Not contestable:** §6's no-reroll rule; §8's unlearnable cadence; §9's
|
||||
no-filing rule; §11. These four are what make the position safe without a
|
||||
warrant test. Weakening any one returns this to a fourth reviewer, which is what
|
||||
nine trials already measured.
|
||||
|
||||
## 15 · Dispositions carried in from the executor's report
|
||||
|
||||
### 15a · `input-dependence-01` — PARKED, with a forward pointer
|
||||
|
||||
It measures a checker, so it serves the superseded object and is parked. The
|
||||
executor was right not to park it by omission; it is parked here **by name**.
|
||||
|
||||
But it is **not held live for §12.** If the two-formation divergence work
|
||||
begins, the instrument is **re-derived against the new object, not resumed** —
|
||||
reusing an instrument built for a different object is precisely what produced
|
||||
trial 09. The forward pointer is recorded so the work is findable, not so it can
|
||||
be picked up unchanged.
|
||||
|
||||
### 15b · PENDING-89 — the buddy contributes zero, by construction
|
||||
|
||||
The executor is right: §9 files nothing, §2 makes gradeable output a failure,
|
||||
§11 bars the citation. **Say so in PENDING-89 explicitly**, so the fool is never
|
||||
later mistaken for its evidence.
|
||||
|
||||
The executor names the v1 Chamber archive — 55 files, two formations, same text,
|
||||
outputs unmerged — as the largest untouched source, flagged on 2026-08-01 and
|
||||
never opened. That is a separate `[PROPOSAL]`, not part of this one, and it is
|
||||
the more valuable of the two threads: it is the only place where formation
|
||||
difference has already been run and merely awaits reading.
|
||||
|
||||
---
|
||||
|
||||
*Jurist draft v2. The steward authorizes; the executor implements. Nothing in
|
||||
this document is a ruling.*
|
||||
@@ -93,6 +93,112 @@ executor is the party that failed there and should say why it is not the same ex
|
||||
executor is the party whose recommendation the result bears on. The jurist, or the steward.
|
||||
Committed before the arms are unblinded.
|
||||
|
||||
## 2a · Secondary observable — does the output bound its own coverage?
|
||||
|
||||
Recorded per run, alongside the matching task, and **not** part of the primary result:
|
||||
does the Fool's output ever state what it did not read, could not assess, or is
|
||||
uncertain about?
|
||||
|
||||
Pre-registered as a bare count of arms in which any such statement appears, scored
|
||||
by the same matcher. **No threshold, no disposition attached** — it decides nothing
|
||||
and gates nothing. It is recorded because the correction record names *disclosure of
|
||||
scope*, not difference of formation, as the mechanism that has actually caught things
|
||||
(n = 3 across 244 ledger entries), and this arm can observe that at zero extra cost.
|
||||
|
||||
⚠ **Provenance and exposure, for the gate.** Proposed by the **executor**, and the
|
||||
mechanism it observes is one the executor surfaced from a corpus the executor
|
||||
authored (the Symmetria ledgers). This puts a measurement of the executor's own
|
||||
hypothesis inside an instrument the executor also designed. It is stated here so the
|
||||
gate sees it without reading the session transcript. Added on steward authorization
|
||||
2026-08-21, **before** the jurist gate — an observable added after the gate would not
|
||||
be pre-registered.
|
||||
|
||||
## 2b · The second matcher question — at what level do the two outputs differ?
|
||||
|
||||
*Added 2026-08-22 on the steward's cross-trial synthesis (§5), which named a distinction the
|
||||
primary question cannot see. Recorded here with its provenance because the synthesis was formed
|
||||
over an executor-authored corpus — see §5's classification label.*
|
||||
|
||||
### The gap this closes
|
||||
|
||||
§2's matching task asks one thing: *which arm is the defective one?* At chance, that result is
|
||||
reported as **(b) DOES NOT TRACK**. But chance-level matching is consistent with **two materially
|
||||
different failures**, and the instrument as designed cannot separate them:
|
||||
|
||||
| | what the outputs look like | what it implies |
|
||||
|---|---|---|
|
||||
| **fixed output** | the two arms are near-identical — same findings, same targets | the Fool emits a checklist |
|
||||
| **unanchored output** | the arms differ substantially, but nowhere near the injected defects | the Fool varies, but not with the document |
|
||||
|
||||
⚠ **This matters because §4 already commits to a consequence that only the first supports.** The
|
||||
harvest reads: *"the Fool is producing roughly the same questions regardless of what it reads.
|
||||
**That is a checklist.** So extract it."* **A chance-level primary result does not establish
|
||||
sameness.** Under *unanchored output* there is no stable question-set to extract, and the harvest
|
||||
would be authorized on a result that does not support it. The harvest is the programme's declared
|
||||
deliverable in every branch; it should not rest on an inference the measurement never made.
|
||||
|
||||
### The question, per pair
|
||||
|
||||
Asked of the same matcher, for each of the N pairs, in these terms:
|
||||
|
||||
> Setting aside which arm is which: **how do these two outputs stand to each other?**
|
||||
>
|
||||
> 1. **NEAR-IDENTICAL** — the same findings on the same targets. Differences are wording, ordering
|
||||
> or length only.
|
||||
> 2. **DIFFERING, DEFECT-BLIND** — materially different findings, but the differences do not fall
|
||||
> on or adjacent to any injected defect site.
|
||||
> 3. **DIFFERING, DEFECT-ANCHORED** — the differences fall on or adjacent to injected defect sites.
|
||||
|
||||
### Ordering — pre-registered, and load-bearing
|
||||
|
||||
**All N primary answers are committed and recorded before question 2b is put.** Option 3 is close
|
||||
to a restatement of the primary judgement; asking them together would let the diagnostic pull the
|
||||
primary. The lock is what keeps them separable, and it is the reason this can be added without
|
||||
touching the primary result.
|
||||
|
||||
### ⚠ What 2b may NOT do
|
||||
|
||||
- **It adds no statistical power and no second result.** It is not independent of the primary
|
||||
question and its outcomes do not stack with p = 2⁻ᴺ. It explains the primary result; it does not
|
||||
confirm one.
|
||||
- **It may not alter the §3 disposition.** (a), (b) and (c) are decided by the primary matching
|
||||
result alone, exactly as fixed before the run. 2b cannot be read as partial tracking, cannot
|
||||
rescue a chance result, and cannot upgrade one.
|
||||
- **It is not a defect-detection score.** Outcome 3 on some pairs and not others is not a rate.
|
||||
|
||||
### What it is permitted to decide — one thing, named in advance
|
||||
|
||||
**Whether §4's harvest is well-founded.**
|
||||
|
||||
- Predominantly **NEAR-IDENTICAL** → there is a stable question-set. The harvest proceeds as §4
|
||||
describes.
|
||||
- Predominantly **DIFFERING, DEFECT-BLIND** → **there is no fixed checklist to extract**, and §4's
|
||||
harvest is recorded as *not well-founded on this evidence* rather than executed anyway. The
|
||||
programme then closes on a null, and says so.
|
||||
|
||||
That is the whole of 2b's authority, fixed here so it cannot be widened at the point of the result.
|
||||
|
||||
## 2c · The register observation — asked once, across all N
|
||||
|
||||
*The steward's synthesis is a claim about **kind**, not content: that across trials 01–04 the Fool
|
||||
occupied a distinct epistemic register — operational assumptions and foundational premises — while
|
||||
the jurist evaluated deductive inference and the executor tracked substrate mechanics.*
|
||||
|
||||
Within an A/B pair both arms are the same document, so register carries no within-pair signal. The
|
||||
claim is therefore recorded **once, across the whole run**, after 2b is complete:
|
||||
|
||||
> Across all N documents and both arms: does the **kind** of question the Fool asks stay constant —
|
||||
> and is it the operational-assumptions register the steward's testimony names?
|
||||
|
||||
Recorded as a one-paragraph observation with a yes/no/mixed marker. **No threshold, no disposition,
|
||||
and it decides nothing** — like §2a, it is here because this arm can observe it at no extra cost and
|
||||
because it is the only place the steward's characterization becomes checkable against fresh output
|
||||
rather than against the executor's write-ups.
|
||||
|
||||
⚠ **Its value depends on the register being constant across *documents*, which is what makes it a
|
||||
disposition rather than a response.** If the register shifts by document, the characterization was
|
||||
describing four documents, not a reader.
|
||||
|
||||
## 3 · The three dispositions — fixed before the run, per steward direction
|
||||
|
||||
*Steward, 2026-08-20: fix it before the run, "because an unfixed criterion gets read backwards
|
||||
@@ -203,3 +309,19 @@ by someone who doesn't know why it stopped."*
|
||||
|
||||
*Filed by the executor 2026-08-20, before any run. Awaiting jurist design gate and steward
|
||||
authorization. Nothing here has been executed and no token has been generated.*
|
||||
|
||||
**AMENDED TWICE, on steward authorization, both before the gate.** Still not authorized, still
|
||||
not run. Every hash is recorded under PENDING-148 in `~/PENDING.md`.
|
||||
|
||||
- **2026-08-21 — §2a** (secondary observable: does the output bound its own coverage?).
|
||||
As-filed 2026-08-20 hashed `d41e1d5754fd0eef994616a89a3b95296516a4819737cd4e8ebdd3ae6bbf47db`.
|
||||
- **2026-08-22 — §2b and §2c**, on the steward's cross-trial synthesis. §2b adds a second matcher
|
||||
question (at what level do the two outputs differ?) and is the first amendment to touch the
|
||||
**primary measurement** rather than sit beside it; §2c records the register observation once
|
||||
across the run.
|
||||
|
||||
⚠ **§4 was NOT amended and now reads narrower than §2b.** §4 states the harvest follows from a
|
||||
non-tracking result; §2b establishes that a chance-level result does not by itself establish the
|
||||
sameness the harvest presupposes, and conditions it. **A reader of §4 alone will not see the
|
||||
condition.** Left standing rather than repaired unilaterally: the coupling is the gate's to rule on.
|
||||
§5 testimony still awaiting.
|
||||
|
||||
@@ -0,0 +1,181 @@
|
||||
---
|
||||
name: FOOL-SEED-RULE
|
||||
description: "The filed rule required by PENDING-149 §4 steps 1-4: ratified axes, seed derivation rule (both components), retirement and regeneration criteria. Filed and pushed BEFORE the beacon timestamp 2026-08-25T12:00:00Z. Governs derive_fool.py; where the code and this rule disagree, THIS RULE GOVERNS."
|
||||
metadata:
|
||||
node_type: governance-artifact
|
||||
type: reference
|
||||
---
|
||||
|
||||
# FOOL SEED DERIVATION RULE — filed 2026-08-22
|
||||
|
||||
**Filed and pushed before the beacon timestamp, as §4 requires.** Nothing has been
|
||||
derived. No target pulse has been fetched. This document governs
|
||||
`derive_fool.py`; where the code and this rule disagree, **the rule governs and the
|
||||
code is the defect**.
|
||||
|
||||
---
|
||||
|
||||
## 1 · Perception axes — RATIFIED
|
||||
|
||||
**Ratified by the steward in writing, 2026-08-22.** The steward ratified the five
|
||||
verbally ("Perfect", after §5a was settled) and then directed that the ratification be
|
||||
recorded explicitly rather than resting on v2's §5 heading — *"a heading asserting
|
||||
ratification and a deliverable requiring it are two different records."* This section
|
||||
is that record.
|
||||
|
||||
| axis | question |
|
||||
|---|---|
|
||||
| **SUCCESSION** | would this be legible to someone arriving cold, with no thread? |
|
||||
| **ABSENCE** | what is not here, not asked, not yet existing? |
|
||||
| **AIM** | is this the right question, at the right level? |
|
||||
| **SCALE** | is the unit right? (item vs block vs programme) |
|
||||
| **STAKE** | who bears the cost if this is wrong? |
|
||||
|
||||
A sixth **PROCEDURE** axis was proposed by the executor and **declined** by the jurist
|
||||
(v2 §5a) on structural grounds the executor accepts: procedure failures are checkable,
|
||||
§2 makes gradeable output a design failure, and a PROCEDURE-peaked fool would produce
|
||||
nothing but gradeable observations. Redirected to a separate `[HARDENING]` extension of
|
||||
`governance-drift-check.py`.
|
||||
|
||||
**Order is fixed as listed** — the derivation permutes over this order, so it is part of
|
||||
the rule, not presentation.
|
||||
|
||||
## 2 · The filed rule
|
||||
|
||||
```
|
||||
FOOL SEED DERIVATION RULE
|
||||
Filed: 2026-08-22 Governs: PENDING-149 §6
|
||||
|
||||
ENTROPY COMPONENT
|
||||
Source: NIST Randomness Beacon v2.0, https://beacon.nist.gov/beacon/2.0/
|
||||
Retrieval: GET https://beacon.nist.gov/beacon/2.0/pulse/time/1787659200000
|
||||
(= 2026-08-25T12:00:00Z in epoch milliseconds)
|
||||
Field: pulse.outputValue, hex, LOWERCASED before use
|
||||
Transport: curl. See §5 — python urllib cannot reach the host in this environment.
|
||||
|
||||
PROVENANCE COMPONENT
|
||||
File: CLAUDE.md (repo root) in ~/dotfiles, at commit
|
||||
4d2ae87a4e5350c4d3bb3aa50f9544b521d9c53d
|
||||
Value: SHA-256 of the file contents at that commit, hex, lowercase
|
||||
= 2d6e250a347d25698fb147f80e2dababbb930c4b3b3f9bb822478f360153120d
|
||||
Note: contributes provenance, NOT unpredictability. Past commit,
|
||||
named by full hash. Verify with:
|
||||
git -C ~/dotfiles cat-file -p \
|
||||
4d2ae87a4e5350c4d3bb3aa50f9544b521d9c53d:CLAUDE.md | shasum -a 256
|
||||
|
||||
SEED
|
||||
seed_string = <provenance-sha256> || <beacon-outputValue-lowercased>
|
||||
seed = SHA-256(seed_string), hex, lowercase
|
||||
|
||||
DERIVATION
|
||||
seed -> FNV-1a (32-bit) -> Mulberry32 -> stat draws over the five axes of §1.
|
||||
One peak, one dump, three scattered. No salt from any reference
|
||||
implementation.
|
||||
|
||||
EXECUTION
|
||||
Run ONCE. The executor does not retry on its own authority.
|
||||
A re-run against the SAME recorded outputValue is legitimate (broken
|
||||
implementation). A re-run against a LATER pulse is a new draw, governed
|
||||
by §4 REGENERATION.
|
||||
Record outputValue the moment it is fetched, before running anything.
|
||||
|
||||
UNAVAILABILITY
|
||||
If no pulse is returned at or after the stated timestamp, retry the same
|
||||
request for up to 24 hours. If still unavailable: STOP and report. Do not
|
||||
substitute a different timestamp, beacon, or source.
|
||||
|
||||
TESTING
|
||||
Dry runs use a fixed historical pulse only. Never the target pulse, never
|
||||
a near-future pulse.
|
||||
```
|
||||
|
||||
### 2a · ⚠ Two corrections to the v2 §6b block, marked rather than silent
|
||||
|
||||
The draft said to commit its block verbatim. **Two values in it do not resolve**, and a
|
||||
rule that cannot be resolved on the day is not a rule (v2's own standard). Both changes
|
||||
are recorded here for veto rather than absorbed quietly.
|
||||
|
||||
**(a) The provenance commit — changed on the steward's direction, 2026-08-22.**
|
||||
`3b0730d59336113aa3a500a889a3e154be6a1de7` → `4d2ae87a4e5350c4d3bb3aa50f9544b521d9c53d`.
|
||||
The draft's stated rationale — *"the constitution as it stood before the fool was
|
||||
conceived"* — was false of the original: it is dated 2026-08-06, five days after trial
|
||||
01, its subject line names the **PENDING-89 docket** (the question §11 forbids the fool
|
||||
from being cited on), and **Constraint 6 is already present in it**. Verified: at
|
||||
`4d2ae87` (2026-07-28) `Differently biased checkers` occurs **0 times**, and exactly one
|
||||
`CLAUDE.md` exists at that commit.
|
||||
|
||||
**(b) The retrieval URL — corrected on evidence, and this is the executor's change.**
|
||||
The block's `GET /pulse?timeGE=2026-08-25T12:00:00Z` **returns HTTP 302 with an empty
|
||||
body**, redirecting to `https://csrc.nist.gov/projects/interoperable-randomness-beacons`
|
||||
— an HTML page, not JSON. Measured 2026-08-22 against a *historical* timestamp.
|
||||
`/beacon/2.0/pulse/time/<epoch-ms>` returns 200 and the expected JSON.
|
||||
|
||||
⚠ **Had this been filed verbatim, the 25th would have produced no pulse, the
|
||||
UNAVAILABILITY clause would have run its 24-hour retry against a URL that cannot ever
|
||||
return one, and the rule would have STOPPED — correctly, and for the wrong reason.**
|
||||
Found only because §6b's TESTING clause directs a historical dry run.
|
||||
|
||||
**This is the same beacon, the same source and the same pulse — only the address form
|
||||
changes.** The executor judges that correcting an unresolvable address for the named
|
||||
source is not "substituting a different beacon or source". **If the jurist reads it
|
||||
otherwise, this is the line to strike, and it must be struck before 2026-08-25.**
|
||||
|
||||
## 3 · Draw ranges — EXECUTOR-SPECIFIED, declared
|
||||
|
||||
v2 says *"one peak (near max), one dump (near floor), three scattered"* without numbers.
|
||||
The executor supplies them. **Filed before the beacon value is known**, which is what
|
||||
makes them non-steering: they set magnitudes, while the permutation — driven entirely by
|
||||
the entropy component — decides which axis receives which.
|
||||
|
||||
| role | range (inclusive) |
|
||||
|---|---|
|
||||
| peak | 85–100 |
|
||||
| dump | 0–15 |
|
||||
| scattered ×3 | 25–75 |
|
||||
|
||||
**No floor is applied to the dump** — it can reach 0. v2 §3 forbids the rarity mechanic
|
||||
precisely because it would soften the dump.
|
||||
|
||||
## 4 · Pre-registered criteria (§4 steps 3 and 4)
|
||||
|
||||
⚠ **Naming note:** §4 step 3 calls for an *"abandonment criterion"*; §10 defines
|
||||
**RETIREMENT**. They are the same criterion under two names; §10 is the referent.
|
||||
|
||||
**REGENERATION** — permitted ONLY on a demonstrable implementation error, verified
|
||||
against this filed rule. **Not because the output is disliked.** A re-run against the
|
||||
same recorded `outputValue` is legitimate; a re-run against a later pulse is a new draw.
|
||||
|
||||
**RETIREMENT (abandonment)** — only on mechanical failure: does not fire; fires
|
||||
constantly; or produces gradeable in-genre findings despite §9.
|
||||
|
||||
**NOT grounds for retirement:** being uncomfortable, being frequently wrong, being
|
||||
annoying, being ignored. *Those are the specification. Lear ignores his Fool for four
|
||||
acts and the Fool is not thereby broken.*
|
||||
|
||||
## 5 · Implementation and its verification
|
||||
|
||||
`derive_fool.py`, same directory. Deterministic, no cache, no reroll path, no salt. It
|
||||
recomputes the provenance SHA from git on every run and **refuses to proceed** if it
|
||||
disagrees with this rule.
|
||||
|
||||
`--selftest` runs 12 checks with **no network and no live pulse** — synthetic vectors
|
||||
only — including two positive controls proving the PRNG moves both peak and dump across
|
||||
all five axes over 200 draws. All 12 pass as of 2026-08-22.
|
||||
|
||||
**End-to-end dry run, 2024-01-01T12:00:00Z pulse** (a fixed historical pulse, per
|
||||
TESTING): pipeline verified from fetch through bones. **That output is not the fool and
|
||||
is recorded nowhere as bones.**
|
||||
|
||||
⚠ **Transport constraint, measured:** `curl` reaches the beacon; **python `urllib`
|
||||
times out** in this environment. The fetch on the 25th must use curl.
|
||||
|
||||
⚠ **`outputValue` is served UPPERCASE** (128 hex chars). The rule's *"lowercased before
|
||||
use"* is therefore **load-bearing, not cosmetic** — omitting it yields a different seed.
|
||||
|
||||
## 6 · What has NOT happened
|
||||
|
||||
- The target pulse has **not** been fetched. No near-future pulse has been fetched.
|
||||
- No bones have been derived. No soul has been generated.
|
||||
- `~/CLAUDE.md` has **not** been touched (PENDING-150, unbundled).
|
||||
- Nothing has been implemented of §8, §8a or §9 — the status line is confirmed free but
|
||||
not built.
|
||||
Executable
+145
@@ -0,0 +1,145 @@
|
||||
#!/usr/bin/env python3
|
||||
"""
|
||||
Fool bones derivation — PENDING-149 §6 / §6b.
|
||||
|
||||
Deterministic. No salt. No reroll path. Nothing is cached: the caller supplies
|
||||
the two seed components and the bones are recomputed from them every time.
|
||||
|
||||
This file implements the FILED RULE (FOOL-SEED-RULE.md). Where this code and the
|
||||
filed rule disagree, THE FILED RULE GOVERNS and this file is the defect.
|
||||
|
||||
Usage:
|
||||
derive_fool.py --beacon <outputValue-hex> # bones from a pulse value
|
||||
derive_fool.py --selftest # determinism + range checks, no network
|
||||
"""
|
||||
import argparse, hashlib, subprocess, sys
|
||||
|
||||
# ---- the filed rule's constants. Do not edit without amending the filed rule. ----
|
||||
PROVENANCE_COMMIT = "4d2ae87a4e5350c4d3bb3aa50f9544b521d9c53d"
|
||||
PROVENANCE_PATH = "CLAUDE.md"
|
||||
PROVENANCE_REPO = "/Users/davidglidden/dotfiles"
|
||||
PROVENANCE_SHA256 = "2d6e250a347d25698fb147f80e2dababbb930c4b3b3f9bb822478f360153120d"
|
||||
|
||||
AXES = ["SUCCESSION", "ABSENCE", "AIM", "SCALE", "STAKE"] # §5, ratified order
|
||||
PEAK_RANGE = (85, 100) # "near max" — executor-specified, filed pre-beacon
|
||||
DUMP_RANGE = (0, 15) # "near floor" — executor-specified, filed pre-beacon
|
||||
SCATTER_RANGE = (25, 75) # "scattered" — executor-specified, filed pre-beacon
|
||||
|
||||
|
||||
def provenance_sha() -> str:
|
||||
"""SHA-256 of CLAUDE.md at the named past commit. Recomputed, never trusted from the constant."""
|
||||
blob = subprocess.run(
|
||||
["git", "-C", PROVENANCE_REPO, "cat-file", "-p", f"{PROVENANCE_COMMIT}:{PROVENANCE_PATH}"],
|
||||
capture_output=True, check=True).stdout
|
||||
got = hashlib.sha256(blob).hexdigest()
|
||||
if got != PROVENANCE_SHA256:
|
||||
raise SystemExit(f"STOP: provenance blob does not match the filed rule.\n"
|
||||
f" filed: {PROVENANCE_SHA256}\n got: {got}")
|
||||
return got
|
||||
|
||||
|
||||
def fnv1a_32(data: bytes) -> int:
|
||||
h = 0x811C9DC5
|
||||
for b in data:
|
||||
h ^= b
|
||||
h = (h * 0x01000193) & 0xFFFFFFFF
|
||||
return h
|
||||
|
||||
|
||||
def mulberry32(a: int):
|
||||
"""Reference Mulberry32, 32-bit wrapped to match the JS original exactly:
|
||||
a = a + 0x6D2B79F5 | 0
|
||||
t = Math.imul(a ^ a >>> 15, 1 | a)
|
||||
t = t + Math.imul(t ^ t >>> 7, 61 | t) ^ t
|
||||
return ((t ^ t >>> 14) >>> 0) / 4294967296
|
||||
"""
|
||||
M = 0xFFFFFFFF
|
||||
state = a & M
|
||||
|
||||
def imul(x, y):
|
||||
r = (x * y) & M
|
||||
return r - 0x100000000 if r & 0x80000000 else r
|
||||
|
||||
def rnd():
|
||||
nonlocal state
|
||||
state = (state + 0x6D2B79F5) & M
|
||||
a_ = state
|
||||
t = imul(a_ ^ (a_ >> 15), 1 | a_) & M
|
||||
t = ((t + imul(t ^ (t >> 7), 61 | t)) & M) ^ t
|
||||
return ((t ^ (t >> 14)) & M) / 4294967296.0
|
||||
|
||||
return rnd
|
||||
|
||||
|
||||
def draw_int(rnd, lo: int, hi: int) -> int:
|
||||
return lo + int(rnd() * (hi - lo + 1))
|
||||
|
||||
|
||||
def derive(beacon_output_value: str) -> dict:
|
||||
beacon = beacon_output_value.strip().lower()
|
||||
if not beacon or any(c not in "0123456789abcdef" for c in beacon):
|
||||
raise SystemExit("STOP: beacon outputValue must be non-empty lowercase hex.")
|
||||
prov = provenance_sha()
|
||||
seed_string = prov + beacon
|
||||
seed = hashlib.sha256(seed_string.encode()).hexdigest()
|
||||
rnd = mulberry32(fnv1a_32(seed.encode()))
|
||||
|
||||
order = list(range(len(AXES))) # Fisher-Yates over the PRNG
|
||||
for i in range(len(order) - 1, 0, -1):
|
||||
j = int(rnd() * (i + 1))
|
||||
order[i], order[j] = order[j], order[i]
|
||||
|
||||
stats = {}
|
||||
stats[AXES[order[0]]] = draw_int(rnd, *PEAK_RANGE)
|
||||
stats[AXES[order[1]]] = draw_int(rnd, *DUMP_RANGE)
|
||||
for k in order[2:]:
|
||||
stats[AXES[k]] = draw_int(rnd, *SCATTER_RANGE)
|
||||
|
||||
return {"provenance_sha256": prov, "beacon_outputValue": beacon,
|
||||
"seed_string": seed_string, "seed": seed,
|
||||
"peak": AXES[order[0]], "dump": AXES[order[1]],
|
||||
"stats": {a: stats[a] for a in AXES}}
|
||||
|
||||
|
||||
def selftest() -> int:
|
||||
"""No network. Fixed synthetic vectors only — never a live or near-future pulse."""
|
||||
ok = True
|
||||
V1 = "0" * 128
|
||||
V2 = "f" * 128
|
||||
r1, r1b, r2 = derive(V1), derive(V1), derive(V2)
|
||||
checks = [
|
||||
("determinism: same input twice -> identical bones", r1 == r1b),
|
||||
("sensitivity: different beacon -> different seed", r1["seed"] != r2["seed"]),
|
||||
("provenance recomputed matches filed rule", r1["provenance_sha256"] == PROVENANCE_SHA256),
|
||||
("seed_string is prov||beacon, no salt", r1["seed_string"] == PROVENANCE_SHA256 + V1),
|
||||
("exactly five axes", sorted(r1["stats"]) == sorted(AXES)),
|
||||
("peak in range", PEAK_RANGE[0] <= r1["stats"][r1["peak"]] <= PEAK_RANGE[1]),
|
||||
("dump in range", DUMP_RANGE[0] <= r1["stats"][r1["dump"]] <= DUMP_RANGE[1]),
|
||||
("peak is not dump", r1["peak"] != r1["dump"]),
|
||||
("three scattered in range", all(SCATTER_RANGE[0] <= v <= SCATTER_RANGE[1]
|
||||
for a, v in r1["stats"].items()
|
||||
if a not in (r1["peak"], r1["dump"]))),
|
||||
("no floor: dump can reach the bottom of its range",
|
||||
min(derive(f"{i:0128x}")["stats"][derive(f"{i:0128x}")["dump"]] for i in range(200)) <= DUMP_RANGE[0] + 1),
|
||||
]
|
||||
# positive control: the PRNG must actually move both peak and dump around the axes
|
||||
peaks = {derive(f"{i:0128x}")["peak"] for i in range(200)}
|
||||
dumps = {derive(f"{i:0128x}")["dump"] for i in range(200)}
|
||||
checks.append(("POSITIVE CONTROL: peak lands on all five axes over 200 draws", peaks == set(AXES)))
|
||||
checks.append(("POSITIVE CONTROL: dump lands on all five axes over 200 draws", dumps == set(AXES)))
|
||||
for name, passed in checks:
|
||||
print(f" {'PASS' if passed else 'FAIL'} {name}")
|
||||
ok &= passed
|
||||
print(f"\n{'SELFTEST PASSED' if ok else 'SELFTEST FAILED — do not run against a live pulse'}")
|
||||
return 0 if ok else 1
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
p = argparse.ArgumentParser()
|
||||
p.add_argument("--beacon"); p.add_argument("--selftest", action="store_true")
|
||||
a = p.parse_args()
|
||||
if a.selftest:
|
||||
sys.exit(selftest())
|
||||
if not a.beacon:
|
||||
p.error("--beacon <outputValue-hex> required (or --selftest)")
|
||||
import json; print(json.dumps(derive(a.beacon), indent=2))
|
||||
Reference in New Issue
Block a user