governance: file the PENDING-88 ruling verbatim + Addendum discharging the verification

Design gate PASSED with conditions. Q1/Q2/Q4/Q5 affirmed; Q2's narrower alternative that I
myself offered was declined as less safe — a latitude-expanding but non-assertive change
would pass an assertion-only test. Q3 went against my fallback framing: report and
provenance comment are both mandatory, not one held in reserve. Two things added that I did
not propose: an append-only FIX-lane index, and a bounded check-in making the lane
provisional rather than settled.

The ruling required the containment verification the 2026-07-29 package carried. Correction
recorded rather than quietly repaired: that check WAS run before filing, 15/15 with
controls, and the package did not report it. For a reader with no repository access, a check
performed but not disclosed is indistinguishable from one not performed. The failure was in
the record, not the method.

Supplied per-quote with source-file shas so it is repeatable: all four §1.6/§2.a passages
byte-contained at named lines, with positive, negative, and cross-file-negative controls
passing.

Q1's timeline, which the jurist affirmed as unverified, is now verified from git rather than
from a provenance comment: the blanket prohibition entered 2026-05-29 (fffcf17), the
change-class clause 2026-07-05 (9ca673f) — 37 days later, not carried back. That makes the
factual premise checkable; it does not rescue the lean from being the interested party's
reading, and the jurist's alternative stands on its own.

Parts I-IX preserved unrewritten as the text ruled on. Nothing landed: the §1.6 edit awaits
steward placement of REVIEWED-85. The accompanying steward-jurist exchange is read as
background and deliberately not filed — per the jurist's own direction that making it
doctrine would be its own item, ruled on rather than absorbed by inclusion.

Refs PENDING-88, REVIEWED-85 (drafted, awaiting placement).

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WuMjg3ipEVa3n8CoSzoyvc
This commit is contained in:
David F Glidden
2026-08-01 19:54:21 +02:00
co-authored by Claude Opus 5
parent 8303b48796
commit bec7996673
2 changed files with 108 additions and 0 deletions
@@ -194,3 +194,61 @@ If any of those falsifiers lands, **option (a) — status quo — is the correct
--- ---
*Filed by the executor 2026-08-01. Companion entry: `~/PENDING.md` PENDING-88 (with its 2026-08-01 amendment, which corrects the item's counts and records that option (d) was already authorized and is now executed). No code was run, no skill was changed, and no governed artifact was edited in the authoring of this package.* *Filed by the executor 2026-08-01. Companion entry: `~/PENDING.md` PENDING-88 (with its 2026-08-01 amendment, which corrects the item's counts and records that option (d) was already authorized and is now executed). No code was run, no skill was changed, and no governed artifact was edited in the authoring of this package.*
---
# Addendum — design-gate ruling received, and the required verification supplied (2026-08-01)
**Parts I–IX above are preserved unrewritten as the text the jurist ruled on.** This Addendum layers disposition; it does not revise history. Ruling filed verbatim at `skill-harvest-fix-lane-JURIST-RULING-2026-08-01.md`.
## The ruling in force
Design gate **PASSED, conditioned**. Q1, Q2, Q4, Q5 affirmed — Q2 with the executor's own narrower alternative **declined** as *less* safe (a latitude-expanding but non-assertive change would pass an assertion-only test). Q3 answered against the executor's fallback framing: report and provenance comment are **both mandatory**, not one with the other in reserve. Register split (option (d)) untouched — separately authorized 2026-07-19 and correctly executed by the split method.
## Corrections that supersede the drafted design
1. **A third instrument, not proposed:** a running **append-only FIX-lane index**, one line per applied change (skill · what changed · date), separate from wrap narratives — on the same live-index pattern as today's register split, and for the same reason: to stop this proposal's own failure mode recurring one level up, on the *changes* instead of the *proposals*.
2. **The floor's catch-all gets an operational form.** *"Anything that would reduce what is surfaced to the steward"* becomes: **any change that removes, defers, or narrows the visibility of an open item, or that could cause a future item to land somewhere the steward's surfacing tools don't read, stays PROPOSAL regardless of the test's outcome.** Checkable against the failure Part II measured, rather than a standing judgment call.
3. **The lane is provisional, not settled.** After the first FIX-lane batch or one month, whichever comes first, steward and jurist review the index together before the lane is treated as settled.
## The required verification — supplied
The ruling: *"Required before landing: the same mechanical containment-with-positive-control verification the 2026-07-29 package carried, applied to these quotes specifically."*
**Executor's correction first, because it bears on how this should be read.** The check *was* run before filing — 15/15 quotes contained, positive and negative controls passing — and the package **did not report it**. The jurist noticed its absence. For a reader with no repository access, a check performed but not disclosed is indistinguishable from one not performed; the failure is in the record, not the method, and it is the say–do seam running in the less familiar direction. Supplied now per-quote, with the file identity pinned so the check is repeatable:
| Source file | sha256 (first 32) | bytes | lines |
|---|---|---|---|
| `~/.claude/skills/wrap-up/SKILL.md` | `37a31595298b13645e7389197a76ceab` | 19,696 | 215 |
| `~/.claude/skills/wake-up/SKILL.md` | `2341552bd137fa329bbc5ade2908a53f` | 18,487 | 161 |
**Per-quote containment — exact byte substring, no normalisation, no fuzzy matching:**
| Quoted passage | File | Line | Result |
|---|---|---|---|
| §1.6 change-class clause (*"Mechanical updates … the same FIX-vs-PROPOSAL split, one level up"*) | wrap-up | 75 | **contained** |
| §1.6 blanket prohibition (*"never create, patch, or retire a skill autonomously at wrap"*) | wrap-up | 80 | **contained** |
| §1.6 event-based sentence (*"This is event-based, not change-count …"*) | wrap-up | 75 | **contained** |
| §2.a register read (*"Read `skill-harvest-register.md` directly …"*) | wake-up | 63 | **contained** |
**Controls:** positive (a known-present clause is found) **pass**; negative (an invented clause, *"the executor may patch any skill without reporting it"*, is absent) **pass**; cross-file negative (the §2.a text does **not** appear in the wrap-up file, confirming the two sources are distinct and not one file matched twice) **pass**.
**Q1's timeline, affirmed by the jurist as "unverified directly" — now verified directly, from git rather than from a provenance comment:**
- The **blanket prohibition** entered `wrap-up/SKILL.md` on **2026-05-29** (`fffcf17`).
- The **change-class clause** entered on **2026-07-05** (`9ca673f`) — **37 days later**, carrying its own `<!-- 2026-07-05: CLAUDE.md-freshness check, steward-authorized -->` provenance comment at line 75.
So *"the distinction was drawn later and simply not carried back"* is a **git-verified fact**, not a timeline inference. It does not rescue the lean from being the interested party's reading — the jurist's coherent alternative stands or falls on its own — but the factual premise it rested on is now checkable by anyone with the repository.
## What proceeds now
1. **Steward places REVIEWED-85.** Not yet placed; the block is in the ruling file, plain-fenced and paste-ready.
2. **Then** land the §1.6 edit: two-clause disjunctive test · sharpened floor per correction 2 · all three instruments per correction 1 · provenance comment in `/wrap-up` SKILL.md · **no change to `~/CLAUDE.md`**. Tag commits **REVIEWED-85**.
3. **Then** apply today's four proposals (ledger `## What held` section, `prevention` KG predicate, the wake line, the reframed standing question) as the **first FIX-lane batch**, each recorded in the new index — the material for the check-in.
4. **Then** the bounded check-in, at the first batch or one month, whichever comes first.
**Nothing at steps 2–4 is done.** The landing awaits placement; this Addendum discharges only the verification condition.
## A note the executor is deliberately not folding in
A steward–jurist exchange accompanied the ruling (contamination, Anthropic's published position on recursive self-improvement, and *"differently biased checkers rather than unbiased ones"*). It has been read as background. Per the jurist's own direction it carries **no governed weight** and is not filed with the ruling: making any of it doctrine would be *"its own item: what exactly gets added, where it lives, and why now, ruled on rather than absorbed by inclusion."* Recording that here so its absence is a decision rather than an oversight.
@@ -0,0 +1,50 @@
# Jurist ruling — PENDING-88, the skill-harvest FIX lane and its hard floor
*Filed verbatim by the executor, 2026-08-01, steward-relayed. Design gate PASSED with required conditions. This file is the record of what was ruled; it is not edited or summarised. The executor's response and the verification the ruling requires are in the package Addendum, not here.*
---
Before the substance: this is a different category of request from the last two, and I'm treating it that way. The first two were about how a text corpus gets verified. This one is about how much an executor may change, unsupervised, in the files that govern its own future sessions. Same taxonomy, higher bar — the kind of proposal PENDING-1 itself required dual review for, not because the mechanism is exotic, but because of what it's about.
**Verification, and where it stops.** I read `~/CLAUDE.md` in full, directly — not corroborated, read. Every Part I quote sourced from it is exact, byte for byte: the four-tier taxonomy, the escalate-unconditionally list, the full governance-contract clause, Constraints 1/5/6, and the PENDING-1 closing note. Confirmed independently: skills are not named anywhere in this file — not on the escalate list, not in the constraints, not anywhere in its 250 lines. That part of Part III's argument is solid. What I could **not** check is the part the whole diagnosis actually turns on: the two `/wrap-up` §1.6 passages and the `/wake-up` §2.a line. Skill files aren't in my reach — `governance_read` covers claude-md, pending, pending-archive, reviewed, app-brief, memory-index, and no more, which is exactly PENDING-86's still-open complaint, now shown to bite a second class of document beyond the chamber constitution. I'll say plainly: I'm ruling on the *inference from* those quotes, not on the quotes themselves. I also notice this package doesn't carry the "mechanically verified by containment, positive control" line the order-attestation package used one day earlier for the same job. Given I can't check it myself, I want it back.
**Is the diagnosis real, independent of that gap?** Yes. PENDING-88's own amendment already caught and corrected its first draft's arithmetic (151→123, 26→8) against a stated counting rule, and reported that the falsifier it named for itself — small or recent backlog — did not fire. 177 open items, oldest 2026-05-24, a file at 166,589 bytes against a read cap that `/wake-up`'s own surfacing step needs to clear. That's a dated, checkable, self-corrected measurement, not an assertion.
**The question underneath Q1–Q5: does a blanket pre-authorization gate that has stopped being readable still honour "the loop is load-bearing," or has form quietly replaced function?** I think the honest answer is that a gate nobody can see through isn't preserving the loop — it's preserving the appearance of one while the steward's actual awareness has already been lost, silently, for weeks. That cuts toward reform being the more faithful reading of Constraint 5, not a relaxation of it. But it cuts toward a *narrow* reform, and I want more than what's on the table before I'd call this settled.
**Q1 — gap, not deliberate.** Agreed, on the timeline evidence given (repo-CLAUDE.md clause added later, not carried back), with the caveat that I can't confirm the dates myself. The alternative reading (skills govern what sessions *do*, not just what they *read*) is coherent enough that it shouldn't be dismissed — but it's already answered by the hard floor's own exclusions, not by keeping the blanket rule.
**Q2 — keep the two-clause test, and I'd resist the narrower form even as an option.** The executor's own suggested alternative — collapse to "does it change what the system asserts to be true?" alone — is *less* safe, not more elegant: a change could expand executor latitude without asserting anything new, and a single-clause assertion-only test would wave it through. Keep both clauses, disjunctive, exactly as drafted.
**Q3 — the report is not enough alone, and the package already knows this.** Its own words: the failure it must catch is one the executor would be the last to notice. Given that, both halves of the mechanism — wrap report *and* skill-source provenance comment — are mandatory, not a report with a mechanical fallback held in reserve. I'm also adding a third: a running, append-only FIX-lane index, one line per applied change, separate from individual wrap narratives. The register-split executed today is the working model for exactly this — cheap, and it directly guards against the one failure mode this whole proposal exists to fix happening again, one level up, to the changes instead of the proposals.
**Q4 — sharpen the floor's catch-all, and tie it to the mechanism that actually broke.** "Anything that would reduce what is surfaced to the steward" is doing real work and is also, as flagged, the clause a self-interested party has the most room to read favourably. Give it an operational form: *any change that removes, defers, or narrows the visibility of an open item, or that could cause a future item to be filed somewhere the steward's surfacing tools don't read, stays PROPOSAL regardless of the test's answer.* That's checkable against the same failure this package measured, rather than a standing judgment call.
**Q5 — yes, and for a reason narrower than the PENDING-S2 stretch the package itself declined to lean on.** Not because this is a self-authorization-posture change in general — because it's a change to the integrity of the *surfacing mechanism itself*, the instrument the steward and I both depend on to know what's happening. Defects there get dual review on the same logic PENDING-1 set, not because of the analogy to a doctrinal ruling about deposits.
One more condition, not asked for but warranted by what's actually being granted: a bounded check-in. After the first month or the first batch of FIX-lane applications, whichever comes first, steward and jurist review the actual FIX-lane log together — not to re-litigate the principle, but to confirm the self-classification held up in practice before treating the lane as settled rather than provisional. This is what "prefer reversible choices" (your own Decision Heuristics, §4) asks for on a genuinely novel grant, and it costs nothing if the classification turns out to be as clean as today's four examples suggest.
Design-gate passed, conditioned on the above. Ready to paste:
```
## REVIEWED-85 — PENDING-88 — Skill-harvest FIX lane: hard floor sharpened, dual instrument required, provisional pending check-in (design-gate passed with required conditions)
**Date:** 2026-08-01
**Decision:** AUTHORIZED — proceed per the ruling, provisionally. Register split (option (d)) unaffected — separately authorized 2026-07-19, correctly executed by the split method rather than the inapplicable collapse method; no action needed here.
**Notes:**
- **Verification limit, stated up front.** All Part I quotes sourced from `~/CLAUDE.md` (taxonomy, escalate list, governance-contract clause, Constraints 1/5/6, PENDING-1 closing note) independently confirmed exact against the live file. The two `/wrap-up` §1.6 passages and the `/wake-up` §2.a line — the textual basis for Part III's "contradicts itself" claim — could NOT be independently checked; skill files are outside current tool reach. Required before landing: the same mechanical containment-with-positive-control verification the 2026-07-29 package carried, applied to these quotes specifically.
- **Q1 — gap, not deliberate distinction — AFFIRMED** on the timeline evidence given, unverified directly. The alternative reading is answered by the hard floor's exclusions, not by retaining the blanket rule.
- **Q2 — two-clause disjunctive test — AFFIRMED, and the narrower single-clause alternative is declined.** A latitude-expanding-but-non-assertive change would pass an assertion-only test; keep both clauses.
- **Q3 — report + provenance comment BOTH mandatory, and a third instrument added.** A wrap-narrative report alone is insufficient by the package's own admission. Required: (i) wrap report, (ii) skill-source provenance comment, (iii) a running append-only FIX-lane index (one line per applied change: skill · what changed · date), built on the same live-index pattern used for today's register split.
- **Q4 — the floor's catch-all clause sharpened.** "Anything that would reduce what is surfaced to the steward" becomes: *any change that removes, defers, or narrows the visibility of an open item, or that could cause a future item to land somewhere the steward's surfacing tools don't read, stays PROPOSAL regardless of the test's outcome.* Tied to the actual failure measured in Part II, not left as an unbounded judgment call.
- **Q5 — jurist review applies, narrowly grounded.** Not the stretched PENDING-S2 analogy (correctly declined by the executor itself) — grounded in this touching the integrity of the surfacing mechanism the steward and jurist both depend on, which is the PENDING-1 class of question by its function, not by resemblance.
- **New condition — bounded check-in, not asked for in the package.** After the first FIX-lane batch or one month, whichever comes first, steward and jurist review the FIX-lane index together before the lane is treated as settled rather than provisional. Per Constitutional Constraint's own decision heuristic (prefer reversible choices) — costs nothing if the classification holds.
- **Hard floor otherwise as proposed — AFFIRMED:** Constraint 1 (CLAUDE.md/REVIEWED.md/L2), authorization-boundary or gate-criteria changes, the escalate-unconditionally list, all untouched and all remain PROPOSAL/ESCALATE regardless of the test's answer.
**If AUTHORIZED:** Land the §1.6 edit (classification test + sharpened floor + dual-plus-index instrument) with a provenance comment in `/wrap-up` SKILL.md; no change to `~/CLAUDE.md`. Apply to today's four proposals (ledger section, KG predicate, wake line, reframed question) as the first FIX-lane batch, feeding the check-in review. Tag commits REVIEWED-85.
**Awaiting:** steward placement; mechanical verification of the §1.6/§2.a quotes; the bounded check-in once the first batch or one month has passed.
```
---
## Note on scope of this file
A follow-on exchange between steward and jurist accompanied this ruling, covering the contamination problem, Anthropic's published position on recursive self-improvement, and the "differently biased checkers rather than unbiased ones" framing. The jurist's own direction on it: *"relay REVIEWED-85 unchanged. Share the exchange if you want to, but as background the executor reads, not as text that carries any new obligation on its own."* It is therefore **deliberately not filed here** and carries no governed weight. Should any of it become doctrine, that is *"its own item: what exactly gets added, where it lives, and why now, ruled on rather than absorbed by inclusion."*