[PROPOSAL] Fool seed rule filed before the beacon; two unresolvable values caught (PENDING-149)

§4 steps 1-4 discharged and pushed ahead of the 2026-08-25T12:00:00Z beacon:
ratified axes recorded in writing, seed derivation rule filed, retirement and
regeneration criteria filed, derivation implemented and self-tested.

Two values in the jurist's §6b block did not resolve, and both are corrected in
the open rather than absorbed:

  - the provenance commit's stated rationale was false. 3b0730d5 (2026-08-06)
    postdates the fool's conception by five days, its subject names the
    PENDING-89 docket, and Constraint 6 is already in it. Steward directed
    4d2ae87 (2026-07-28), where Constraint 6 occurs zero times.

  - the retrieval URL returns HTTP 302 and an empty body, redirecting to an
    HTML page. Filed verbatim, the 25th would have produced no pulse and the
    UNAVAILABILITY clause would have run a 24-hour retry against an address
    that can never return one. Found only because §6b directs a historical
    dry run.

Also measured: outputValue is served UPPERCASE, so the rule's "lowercased
before use" is load-bearing; and curl reaches the beacon where python urllib
times out.

Nothing derived. Target pulse not fetched. CLAUDE.md untouched (PENDING-150).

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JQKeKY9T9d95KpvHwwok8T
This commit is contained in:
David F Glidden
2026-08-22 20:52:12 +02:00
co-authored by Claude Opus 5
parent 7b366eb646
commit acfbb9fc0e
9 changed files with 1606 additions and 2 deletions
@@ -0,0 +1,452 @@
---
name: BUDDY-PATTERN-jurist-draft-v2-2026-08-22
description: "Jurist draft v2, 2026-08-22 — SUPERSEDES v1 of the same date. Stored verbatim. Where v1 and v2 differ, v2 governs; v1 is retained as the record of what was asked before the executor's measurements came back. NOT AUTHORIZED. Executor commentary lives in PENDING-149/150, never in this file."
metadata:
node_type: governance-artifact
type: reference
supersedes: BUDDY-PATTERN-jurist-draft-2026-08-22.md
provenance: "Received from the jurist via the steward, 2026-08-22. Stored verbatim, byte-checked on receipt."
---
> **STORED VERBATIM AS RECEIVED.** Nothing in this file is executor-authored.
> **This is v2 and it GOVERNS.** v1 (`9aceed7f…`) is retained unaltered as the record of
> what was asked before the executor's measurements came back — not deleted, not edited.
> Executor verification results, contested points and dispositions live in PENDING-149
> and PENDING-150.
# Executor instructions — the Fool (buddy pattern), **v2**
Prepared by the jurist, 2026-08-22. **Supersedes the v1 draft of the same date**
(stored verbatim at `9aceed7f…`). v1 is retained as the record of what was asked
before the executor's measurements came back; **where the two differ, v2
governs.**
Filed as `PENDING-149 [PROPOSAL]`; the constitutional part is `PENDING-150
[ESCALATE]` and stays unbundled. **Not authorized.**
## 0 · What changed from v1, and why
| § | change | cause |
|---|---|---|
| 3 | salt and stat-shift added to DO-NOT-TAKE | third source review |
| 5 | sixth axis (PROCEDURE) **declined**, with reason | executor's §5 observation |
| 8 | cadence re-keyed: **time-ticked, not event-ticked** | executor's burst measurement |
| 8a | **RESOLVED** — body/voice separation adopted | executor's answer |
| 15 | dispositions for `input-dependence-01` and PENDING-89 | executor's open question |
| 6, 6a, 6b | two-component seed specified; delegation protocol; filed rule with timestamp 2026-08-25T12:00:00Z | steward decision |
Two executor corrections are accepted and noted here so they are not lost: the
three-store negative that never reached disk, and the `find`-vs-`glob` error
that reported the transcript trend backwards (N = 46, not 54; corrected series
60 → 61 → 47 → 46). The second is the more instructive: **an obligation
discharged with the wrong instrument reported the trend inverted**, which is
worse than not discharging it. The glob rule now in `MEMORY.md` is the right fix.
---
## 1 · What this is
A fourth position in the working cycle, built on the Claude Code `/buddy`
architecture. Ambient, one line at a time, addressed to the steward alone. It
produces no findings, opens no items, and no ruling turns on it.
It is safe **without being checkable**, because nothing follows from it. This
inverts the standing correction of 2026-08-02 — *findings earn a hearing by
being checkable, never by role* — which is correct for findings and inapplicable
here: a position that makes no claims is not subject to a warrant test. Do not
build a checkability gate into this.
## 2 · What it is NOT
- Not a checker, auditor, reviewer, or devil's advocate. **If its output can be
graded, the design has failed.**
- Not the Fool trial programme. Trials 01–09 measured a checker; this is a
different object. Do not reuse their instruments, grading vocabulary, corpus,
partitioning, or ground truth.
- Not an answer to Constraint 6. See §11.
## 3 · Reference implementations — scope limited
Primary: `https://github.com/ramarivera/coding-buddy` — community MCP
recreation, and the most useful of the three. Secondary:
`https://github.com/milind-soni/claude-pets` — source extraction.
**TAKE:**
- the derivation chain (FNV-1a → Mulberry32 → stat draws, peak/dump assignment);
- the **body/voice integration pattern**: animated status line + hook-driven
reactions (see §8a);
- the fresh-overrides-stored rule.
**DO NOT TAKE:**
- species, rarity tiers, shiny, hats, eyes, sprites, animation frames, petting,
canned reaction strings, or the buddy's own stat set (superseded by §5);
- ⚠ **rarity** — it is a gacha mechanic that scales stat **floors**. A floor
softens the dump, and the dump is the entire point;
- ⚠ **the salt `friend-2026-401`.** Take the algorithm, not the salt. A fixed,
published salt with a single known user makes the fool computable in advance,
which defeats §6 entirely. The seed comes from §6's filed rule and nowhere
else;
- ⚠ **any mechanic by which stats shift during a session based on activity.**
A drifting dump is not a mandated blind spot. §6's fresh-recompute rule
governs; nothing modifies the bones after derivation.
**Provenance:** community reconstructions of a feature that shipped for eight
days and was withdrawn. The *code* is verifiable — FNV-1a and Mulberry32 are
standard, and the derivation can be tested directly. The surrounding
documentation is SEO-grade and should not be relied on. Once §6's rule is filed,
**the filed rule governs**, so no quirk of an extraction becomes constitutional
by accident.
⚠ Note also that **nobody has run this pattern for longer than eight days.**
There is no wear data. Expect to discover things.
## 4 · Pre-registration order — MANDATORY
Each step committed and pushed before the next begins.
1. Perception axes ratified by the steward (§5).
2. Seed derivation rule filed, naming a **future** timestamp (§6).
3. Abandonment criterion filed (§10).
4. Regeneration criterion filed (§10).
5. Timestamp passes; seed computed; bones derived.
6. Soul generated once from the bones (§7).
Steps 1–4 complete and pushed **before** step 5. Axes chosen after the seed is
known, or with a fool in hand, smuggle the selection one level up.
## 5 · Perception axes — five, ratified by the steward
Five axes, 0–100. Each is something the fool could be **blind to**. The steward
must be able to imagine a dump on any one costing him something.
- **SUCCESSION** — would this be legible to someone arriving cold, with no thread?
- **ABSENCE** — what is not here, not asked, not yet existing?
- **AIM** — is this the right question, at the right level?
- **SCALE** — is the unit right? (item vs block vs programme)
- **STAKE** — who bears the cost if this is wrong?
### 5a · The proposed sixth axis is DECLINED — and the observation is right
The executor observes that these five are all axes of *judgement*, while what
actually gets caught are failures of *procedure*: a claim made before the file
was opened, a hash recorded before the last edit, an instrument used past its
demonstrated tier. Three in a single day. The observation is correct and the
evidence is good.
**The axis is still declined, and the reason is structural: procedure failures
are checkable.** A claim made before a file was opened is verifiable from logs.
A hash predating an edit is verifiable from git. An instrument used past its
tier is verifiable against the instrument's own record. That is the one domain
this position must stay out of — §2 says gradeable means failed, and a
PROCEDURE-peaked fool would produce nothing but gradeable observations.
The observation should be honoured somewhere else. **If it can be scripted,
script it.** These three failure shapes are exactly what `governance-drift-check.py`
is for, and a procedure-check extension is a separate `[HARDENING]` item worth
opening on its own merits. Do not route it through the fool.
The executor's self-disclosure — that selection toward a known preference
applies to it harder than to the jurist — is accepted as correctly reasoned and
is part of why this is declined rather than adopted.
**Register properties — terseness, snark, obliquity, chaos — are NOT axes.**
They belong to the soul (§7). The dump must be a blind spot, not a style: a fool
that is merely predictable is blind to nothing.
## 6 · Bones
**Seed — two components, concatenated in this order:**
1. **Provenance component.** The SHA of `CLAUDE.md` at a **named past commit** in
the dotfiles repo, specified by full commit hash in the filed rule. Fixed
forever; the commit does not change.
2. **Entropy component.** The NIST Randomness Beacon output value for a pulse at
a **stated future timestamp**, hex-encoded, lowercase.
`seed_string = <claude-md-sha> || <beacon-value>`, then SHA-256 of that.
⚠ **What each component does, so neither is mistaken for the other.** The
provenance component contributes **no unpredictability** — its value is
computable today. It is there so the fool is seeded from the constitution it
will accompany, which is a meaningful property and not a protective one. **All
selection-resistance comes from the entropy component.** If the beacon component
were ever dropped, the construction would collapse into a value the steward can
compute and steer. It cannot be dropped.
The provenance commit must be **past and named by full hash** — never `HEAD`,
never 'the current version'. A live file makes the seed rerollable by ordinary
work: amending the constitution would redraw the fool, and §6's no-reroll rule
would be unenforceable precisely through the action most likely to be taken.
**Derivation:** seed → FNV-1a → Mulberry32 → stat draws.
- One **peak** (near max), one **dump** (near floor), three scattered.
- Recomputed fresh every session from the seed. **Never cached.** A stored value
disagreeing with the fresh computation loses.
- **No rerolls.** The first output is the fool.
The dump is the point, not a side effect. It is the only guaranteed difference
this position has, and the seed — not the steward — decides where the hole goes.
No floor softens it.
### 6a · Delegation protocol — the executor computes it
Delegation is correct here. The executor has no preference about the fool's
stats; the steward does. The risk is not steering but the ordinary failure
already seen twice this week — wrong instrument, or a good-faith regeneration
that quietly lands draw two.
**Before the timestamp**, the executor files and pushes: the beacon source, the
exact pulse timestamp, the provenance commit hash, and the derivation as
executable code.
**After the timestamp**, in a single commit: the raw beacon value, the seed
string, the SHA-256, the resulting stats, and the commit hash of the filed rule
it ran against.
**The steward does not see the beacon value before the derivation runs.**
⚠ **The executor does not run the derivation more than once.** If it fails —
bug, crash, wrong pulse — it **STOPS and reports.** It does not retry on its own
authority. A second run is a reroll regardless of intent.
The one distinction worth having in advance, because it will be met in good
faith: **a re-run against the same recorded pulse value is legitimate** — the
input did not change, only a broken implementation did. **A re-run against a
later pulse is a new draw** and is governed by §10's regeneration criterion.
Record the pulse value the moment it is fetched, before running anything, so
this distinction stays available.
⚠ **No dry runs against a live pulse.** The executor must not fetch the target
pulse, or any near-future pulse, to test the pipeline. A dry run against a live
value is how a test quietly becomes draw zero. **Test against a fixed historical
pulse** — any pulse from a past year — which exercises the identical code path
with no possibility of contaminating the real draw.
### 6b · The filed rule — commit this block verbatim
This is the artefact §4 step 2 requires. It is committed and pushed **before**
the timestamp below. Where this block and §6's prose differ, **this block
governs.**
```
FOOL SEED DERIVATION RULE
Filed: <DATE FILED> Governs: PENDING-149 §6
ENTROPY COMPONENT
Source: NIST Randomness Beacon v2.0, https://beacon.nist.gov/beacon/2.0/
Retrieval: GET /pulse?timeGE=2026-08-25T12:00:00Z
Field: pulse.outputValue, hex, lowercased before use
PROVENANCE COMPONENT
File: CLAUDE.md in ~/dotfiles, at commit
3b0730d59336113aa3a500a889a3e154be6a1de7
Value: SHA-256 of the file contents at that commit, hex, lowercase
Note: contributes provenance, NOT unpredictability. Past commit,
named by full hash. Verify with:
git -C ~/dotfiles cat-file -p 3b0730d5...:<path> | shasum -a 256
The path must be recorded alongside the hash — a repo may hold
more than one CLAUDE.md, and the rule must name exactly one file.
SEED
seed_string = <provenance-sha256> || <beacon-outputValue-lowercased>
seed = SHA-256(seed_string), hex, lowercase
DERIVATION
seed -> FNV-1a -> Mulberry32 -> stat draws over the five axes of §5.
One peak, one dump, three scattered. No salt from any reference
implementation.
EXECUTION
Run ONCE. The executor does not retry on its own authority.
A re-run against the SAME recorded outputValue is legitimate (broken
implementation). A re-run against a LATER pulse is a new draw, governed
by §10.
Record outputValue the moment it is fetched, before running anything.
UNAVAILABILITY
If no pulse is returned at or after the stated timestamp, retry the same
request for up to 24 hours. If still unavailable: STOP and report. Do not
substitute a different timestamp, beacon, or source.
TESTING
Dry runs use a fixed historical pulse only. Never the target pulse, never
a near-future pulse.
```
One value remains for the steward: `<DATE FILED>`. The provenance commit is
`3b0730d59336113aa3a500a889a3e154be6a1de7` — the last commit to the global
`CLAUDE.md` before this line of work began, chosen so the fool is seeded from
the constitution as it stood before the fool was conceived. The executor records
the file path alongside the hash and confirms the blob resolves before the
beacon timestamp; a rule that cannot be resolved on the day is not a rule.
## 7 · Soul
Character and register generated **once** from the bones, stored permanently,
never hand-edited, never regenerated for taste. One generation, kept.
## 8 · Cadence — RE-KEYED
⚠ **v1's §8 was wrong and the executor found why.** The buddy's 73/20/7
proportions are calibrated against a **time-uniform tick** — an idle animation
loop. v1 re-keyed them to *events*, and events burst by a factor of ~50: 4.2
governance events/day over 45 days, 6.2 on active days, range 1 to 53. Same
proportions, different generator, and the consequence is that **the fool is
loudest on the heaviest days** — fourteen utterances on 2026-08-08.
The executor proposed keeping the proportions, keying voice to seams, and adding
a hard daily cap. **Two of those three are adopted; the cap is not, and it is
redundant anyway** — if voice is seam-keyed, seams already fire two or three
times a day, so a daily cap gates nothing. It also introduces a *budget-spent*
state, which is memory, and memory is the beginning of learnability.
**The fix is to restore the original generator, not to patch the re-keyed one.**
Three tiers:
| tier | trigger | rate |
|---|---|---|
| **body** | every turn | always present, silent |
| **mumble** | **time-ticked**, not event-ticked | low, fixed |
| **voice** | seams (wake, wrap-up) | guaranteed, ~2–3/day |
The mumble ticks on a clock — per interval or per session — **never per
governance event.** Events supply *content*: what the fool remarks on is drawn
from what has happened since the last tick. Frequency and content are separated,
which is what v1 conflated.
This has no memory and no budget, so the cadence stays unlearnable. It also
preserves the *in the room, hears everything* property that a seam-only voice
would lose.
⚠ Report the observed mumble rate after two weeks. If it reads as noise, the
interval lengthens — **the proportions do not become adaptive.**
Triggers remain **EVENT-keyed for content, never content-keyed for judgement.**
The fool never assesses whether a thing is any good. **Do not implement quality
evaluation of any kind.**
### 8a · RESOLVED — body and voice are separable
The executor's answer is adopted, and it is better than any of v1's three
options, which each tried to solve presence and speech with one surface.
- **Body = the status line.** Rendered every turn, carrying the name and nothing
else. Silence becomes visible at near-zero cost. This is what makes the
three-tier cadence legible rather than merely intermittent.
- **Voice = the seams**, which already fire and are proven.
⚠ **One unverified assumption, flagged by the executor and to be closed before
implementation: whether a status line is already in use.** If it is, propose the
accommodation rather than displacing it.
`coding-buddy`'s Stop-hook fallback implies its primary trigger path is
unreliable. Plan for that rather than discovering it.
## 9 · Channel and register
- Output reaches **the steward**. Filed nowhere. No `PENDING` entry, no log, no
item.
- **ONE LINE** for the ordinary case. Paragraph-length governance prose is the
genre the trio already metabolizes; the constraint is what keeps the fool
uningestible.
- **Named invocation:** the steward calls it by name, the executor or jurist
yields the floor, the fool answers at length.
- `mute` / `off` available at all times. Mute rate may be counted; muting is
never a fault.
Anything the steward carries into the record enters **as the steward's, in his
words**. The fool is never cited as a source.
## 10 · Pre-registered criteria — filed before the fool exists
**REGENERATION** only on a demonstrable implementation error, verified against
the filed derivation rule. Not because the output is disliked.
**RETIREMENT** only on mechanical failure: does not fire; fires constantly; or
produces gradeable in-genre findings despite §9.
**NOT grounds for retirement:** being uncomfortable, being frequently wrong,
being annoying, being ignored. Those are the specification. Lear ignores his
Fool for four acts and the Fool is not thereby broken.
## 11 · `[ESCALATE]` — PENDING-150, unbundled
Whether a fourth position exists in the arrangement changes the tripartite model
and touches `~/CLAUDE.md`. Constitutional; separate item; separate steward
authorization. **Do not amend `CLAUDE.md` under PENDING-149.**
**Standing caveat, written into the fool's own doctrine at the outset:** if the
fool runs on Claude, three of four parties share formation, which makes
Constraint 6's concession worse rather than better. The dump mandates ONE
declared hole; the undeclared ones are shared and invisible — and if what the
jurist misses, the executor misses, and the fool also misses, that is
PENDING-89's falsifier firing quietly.
⚠ **THE FOOL MAY NEVER BE CITED AS SATISFYING CONSTRAINT 6 OR AS SUPPLYING
EPISTEMIC DIVERSITY.** It tests positional difference — PENDING-140's third axis
— not formation difference.
## 12 · Build order
**Claude-first.** Simpler, and the steward's own precedent ran on Claude.
The generator is a **swappable parameter**: running the same fool on a local
model and reading the divergence between the two is the v1 Chamber property at
negligible cost. Do not build for it now; do not preclude it.
## 13 · Deliverables
1. Spec document in the governance tree, provenance header naming this v2 draft
and what was changed.
2. Status-line availability confirmed (§8a) **before** §8 is implemented.
3. Filed axes, seed rule (both components, §6), abandonment and regeneration
criteria — committed and pushed **before** the beacon timestamp.
4. Derivation implementation: deterministic, fresh-overrides-stored, no reroll
path, **no salt from any reference implementation.**
5. Post-derivation record per §6a, in a single commit: raw beacon value, seed
string, SHA-256, resulting stats, and the commit hash of the filed rule.
6. Hook wiring: status line every turn; time-ticked mumble; seams guaranteed.
7. Nothing run until the steward ratifies §5.
## 14 · Contestable and not
**Contestable on evidence:** the five axes; the mumble interval; the status-line
approach if the surface is unavailable.
**Not contestable:** §6's no-reroll rule; §8's unlearnable cadence; §9's
no-filing rule; §11. These four are what make the position safe without a
warrant test. Weakening any one returns this to a fourth reviewer, which is what
nine trials already measured.
## 15 · Dispositions carried in from the executor's report
### 15a · `input-dependence-01` — PARKED, with a forward pointer
It measures a checker, so it serves the superseded object and is parked. The
executor was right not to park it by omission; it is parked here **by name**.
But it is **not held live for §12.** If the two-formation divergence work
begins, the instrument is **re-derived against the new object, not resumed** —
reusing an instrument built for a different object is precisely what produced
trial 09. The forward pointer is recorded so the work is findable, not so it can
be picked up unchanged.
### 15b · PENDING-89 — the buddy contributes zero, by construction
The executor is right: §9 files nothing, §2 makes gradeable output a failure,
§11 bars the citation. **Say so in PENDING-89 explicitly**, so the fool is never
later mistaken for its evidence.
The executor names the v1 Chamber archive — 55 files, two formations, same text,
outputs unmerged — as the largest untouched source, flagged on 2026-08-01 and
never opened. That is a separate `[PROPOSAL]`, not part of this one, and it is
the more valuable of the two threads: it is the only place where formation
difference has already been run and merely awaits reading.
---
*Jurist draft v2. The steward authorizes; the executor implements. Nothing in
this document is a ruling.*