[FIX] The deferral checker silently skipped the governance register (REVIEWED-123)
Executing REVIEWED-123 conditions 2 and 3 surfaced a defect in the instrument that was supposed to carry them. PENDING.md had grown to 546,944 bytes, past the scanner's 400 KB guard, so EVERY structured DEFERRED-DECISION block in the governance register was skipped — silently — by the checker built to stop deferred conditions from being silently missed. The 30-day review point placed under condition 2 was inert on arrival. Worse than silent. The prose-deferral loop has no size guard, so PENDING.md's prose count (70) still appeared in the report, making the file look examined while its structured blocks were never read. Found only by placing a block and noticing the tracked count did not move. Both halves fixed: - The two named governance files are exempt from the guard. The guard exists to bound the unbounded **/*.md globs; it was never meant for the files the scan reaches outside docs/ specifically to include. - A size-skip is now REPORTED, not swallowed: "NOT SCANNED for structured blocks", named, with byte counts, and stated as "could not assess" rather than "nothing there" — REVIEWED-104's third outcome, applied to the instrument whose entire subject is conditions nobody is watching. Two legitimate skips now visible (Carruthers 1.6 MB, Yates 1.0 MB — scholarly texts, correctly out of scope). Three controls added, derived from the PROPERTY rather than the guard's own vocabulary: is the register actually scanned; is a real block in it parsed (the live instance, not a fixture); and does the guard still apply to non-governance files, so the exemption cannot quietly become "scan everything". A control asking "does the guard work" would have passed throughout. Result: 32/32 controls (was 29/29); deferred decisions 3 tracked (was 2), all checkable. The ladder-freeze-30day-review trigger is live at date 2026-09-16. Also under REVIEWED-123: N-now recorded (60 transcripts of 84, 24 remaining); freeze scope stated as GENERAL per condition 1 and ladder file verified untouched; owed-entries list ratified with each row naming its authorizing ruling per condition 3 — OWED-1 under REVIEWED-122 cond. 9, OWED-2 explicitly NONE, queued but not authorized and needing its own ruling before it joins the ladder. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013Y6t6qx7cpaCu5xGdD36u4
This commit is contained in:
co-authored by
Claude Opus 5
parent
d7d543cc77
commit
d04c875054
+31
-5
@@ -3169,14 +3169,40 @@ So **PENDING-138 and this entry are worded to avoid the bare uppercase token**,
|
||||
|
||||
---
|
||||
|
||||
### OWED LADDER ENTRIES — accumulated during the freeze
|
||||
*Added 2026-08-17, jurist-proposed, **mechanism itself awaiting steward ratification**. Reason for living here rather than in a file of its own: a separate register is something a reader might reach **instead of** the ladder, which is a second uncontrolled variable in the same trial — the trap one layer along. This list is inert; it changes nothing a reader retrieves. **Without it the freeze silently becomes a loss**, which is how the wrong-subject family came to be rediscovered five times as a fresh coincidence.*
|
||||
*Discharge condition: when PENDING-141 is ruled or the trial is graded at 84 transcripts, append these to `reference-verification-ladder.md` and strike this section.*
|
||||
### ⚖ RULED — REVIEWED-123 (2026-08-17): AUTHORIZED (a) HOLD, on six conditions
|
||||
|
||||
**OWED-1 — the wrong-subject family.** *Earned across five instances in a fortnight; ordered by REVIEWED-122 cond. 9, deferred by the amendment to that condition the same day.*
|
||||
**The freeze is GENERAL, not S2-specific** (cond. 1): no additions, rewordings, removals or reorderings of `reference-verification-ladder.md` while the hold is in force, **from any source, whatever its authorization**. Verified at ruling: the ladder file is untouched in the working tree.
|
||||
|
||||
**N-now, per condition 2 — reported here and at each wake until lifted:**
|
||||
|
||||
| | |
|
||||
|---|---|
|
||||
| transcripts at 2026-08-17 | **60** |
|
||||
| trigger | 84 |
|
||||
| remaining | **24** |
|
||||
|
||||
**30-day review point** (cond. 2) — *not* an automatic lift; a requirement to state where the count stands and whether the trial is still tracking. Made machine-checkable rather than left as prose, since 92 prose deferrals in this register carry no checkable trigger and their firing is unestablished:
|
||||
|
||||
<!-- DEFERRED-DECISION: ladder-freeze-30day-review
|
||||
since: 2026-08-17
|
||||
trigger: date 2026-09-16
|
||||
owner: steward
|
||||
-->
|
||||
|
||||
⚠ **Grading does not authorize the append** (cond. 4). On grading, the S2 batch **returns for a ruling, not for execution**, and that ruling must address the second-order risk on its own terms: a tripled ladder may be a *worse* ladder, degrading per-entry reach even as the wake line raises the odds of the file being opened. Read as "hold then append", this ruling would merely move the problem four weeks and arrive with the same measurement unmade.
|
||||
|
||||
⚠ **Standing limit on what the trial can conclude** (cond. 6, recorded because it is unfixable and must not be discovered at grading): the party whose retrieval is measured has read the pre-registration, this item and the ruling. The trial therefore measures whether an executor **who knows the trial exists** reaches the ladder after the wake line was added — which is not REVIEWED-95's claim. It bounds the conclusion, not the value of protecting the instrument; the grading write-up must state it rather than infer a clean causal result.
|
||||
|
||||
**On the freeze lift** (cond. 5): retire `MEMORY.md`'s hold-notice in the same act. A hold-notice outliving its hold is the same trap inverted — a later session reading "held pending trial" for a trial graded months earlier.
|
||||
|
||||
### OWED LADDER ENTRIES — accumulated during the freeze
|
||||
*Mechanism **ratified by REVIEWED-123 condition 3**, which requires each queued entry to name its authorizing ruling so the freeze lift is mechanical. Reason for living here rather than in a file of its own: a separate register is something a reader might reach **instead of** the ladder, which is a second uncontrolled variable in the same trial — the trap one layer along. This list is inert; it changes nothing a reader retrieves. **Without it the freeze silently becomes a loss**, which is how the wrong-subject family came to be rediscovered five times as a fresh coincidence.*
|
||||
*Discharge: on freeze lift, append each row below to `reference-verification-ladder.md` under the claim-class named, then strike this section and the hold-notice in `MEMORY.md`.*
|
||||
|
||||
**OWED-1 — the wrong-subject family.** · **Authorizing ruling: REVIEWED-122 condition 9**, as amended 2026-08-17. · **Ladder claim-class: gate-design claims.** *Earned across five instances in a fortnight; ordered by that condition, deferred by the amendment to it the same day.*
|
||||
> **A control whose SUBJECT is not the claim's subject is not a weak check — it is not a check.** Ask what proposition the control actually tests before reading its pass as verification. Recurring disguises: a control over *transcription* cited for an *inference over what was transcribed* (2026-08-14); a control at the layer of the decision **rule** cited for the sufficiency of the **signal set** (REVIEWED-83 A1); a **count** cited for a per-item **classification** — which cannot see an error running equally in both directions (PENDING-142; removing 3 false-opens and restoring 3 false-closeds both leave 29); a field true **of the string** cited as true **of the result** (Fool trial 03); a guard conflating *opens as deliberation* with *produced no answer* (Fool trial 04).
|
||||
|
||||
**OWED-2 — a discriminator for real vs manufactured authorization boundaries.** *Jurist-offered 2026-08-17, answering the literal question logged unanswered on 2026-08-01 — what distinguishes a real boundary from a manufactured one **at the moment of deciding**, when both present as caution and every available test runs afterwards.*
|
||||
**OWED-2 — a discriminator for real vs manufactured authorization boundaries.** · **Authorizing ruling: NONE — this row is queued, not authorized.** It is jurist-*offered*, explicitly not promoted, and on freeze lift it needs a ruling of its own before it joins the ladder; it is recorded here only so the freeze does not lose it. · **Candidate claim-class: governed-document changes / authorization conduct — unsettled.** *Offered 2026-08-17, answering the literal question logged unanswered on 2026-08-01 — what distinguishes a real boundary from a manufactured one **at the moment of deciding**, when both present as caution and every available test runs afterwards.*
|
||||
> **Can you name the instrument that would be damaged, and does the caution come with an offer to proceed?** A manufactured boundary tends to cite a **rule** rather than an instrument, and to terminate in **inaction** rather than in a question — because its function is to avoid the act, not to protect anything.
|
||||
>
|
||||
> Evidence, n=2, one of each sign and both from the executor's own conduct: **negative, 2026-08-01** — declined the register split by invoking PENDING-88's *unratified* change-class test, a rule that did not exist, and produced no question. **Positive, 2026-08-17** — declined the ladder entry by naming a specific open item, stating the substantive conflict (ladder size as an uncontrolled variable in a trial that cannot be re-run), taking the null action that item already puts in force, and offering to proceed if overruled.
|
||||
|
||||
@@ -350,7 +350,24 @@ _scan_targets = [(r, "*/docs/**/*.md") for r in SCAN_ROOTS] + EXTRA_SCAN_GLOBS
|
||||
# READING task, and it is reported as owed rather than silently skipped.
|
||||
_scan_targets += [(HOME / "dotfiles", "PENDING.md"), (HOME / "dotfiles", "PENDING-archive.md")]
|
||||
PROSE_DEFERRAL_RE = re.compile(r"defer(?:red|ral)", re.I)
|
||||
# The size guard bounds the unbounded `**/*.md` globs. It must NOT apply to the two
|
||||
# governance files, which were added to the scan on purpose and are the whole reason
|
||||
# the scan reaches outside docs/ at all.
|
||||
#
|
||||
# 2026-08-17 [FIX]: it did apply, and PENDING.md had grown to 546,944 bytes — so every
|
||||
# structured DEFERRED-DECISION block in the governance register was skipped, silently,
|
||||
# by the checker built to stop deferrals from being silently missed. Worse than silent:
|
||||
# the prose-deferral loop below has no size guard, so PENDING.md's prose count appeared
|
||||
# in the report and made the file look examined. Found by placing a block under
|
||||
# REVIEWED-123 cond. 2 and noticing the tracked count did not move.
|
||||
#
|
||||
# Both halves are fixed here: the named governance files are never size-skipped, and a
|
||||
# skip is now REPORTED rather than swallowed — the third outcome of REVIEWED-104's
|
||||
# doctrine, on the instrument whose whole subject is conditions nobody is watching.
|
||||
GOVERNANCE_FILES = {HOME / "dotfiles" / "PENDING.md",
|
||||
HOME / "dotfiles" / "PENDING-archive.md"}
|
||||
_seen_files: set = set()
|
||||
skipped_too_large: list = []
|
||||
for root, pattern in _scan_targets:
|
||||
if not root.is_dir():
|
||||
continue
|
||||
@@ -359,7 +376,8 @@ for root, pattern in _scan_targets:
|
||||
continue
|
||||
_seen_files.add(f)
|
||||
try:
|
||||
if f.stat().st_size > 400_000:
|
||||
if f.stat().st_size > 400_000 and f not in GOVERNANCE_FILES:
|
||||
skipped_too_large.append(f)
|
||||
continue
|
||||
body = f.read_text(errors="replace")
|
||||
except OSError:
|
||||
@@ -389,6 +407,20 @@ control("transcripts trigger silent on an unreached threshold",
|
||||
control("governance dir is inside the deferral scan",
|
||||
any("claude/governance" in str(p) for p in _seen_files)
|
||||
or not (HOME / "dotfiles/claude/governance").is_dir())
|
||||
# 2026-08-17: PENDING.md passed 400 KB and every structured block in it went unscanned,
|
||||
# silently, while its prose count still appeared in the report. These controls are derived
|
||||
# from the PROPERTY (is the register's block actually parsed?), not from the guard's own
|
||||
# vocabulary — a control asking "does the guard work" would have passed throughout.
|
||||
control("the governance register is actually scanned for blocks, whatever its size",
|
||||
(HOME / "dotfiles/PENDING.md") in _seen_files
|
||||
and (HOME / "dotfiles/PENDING.md") not in skipped_too_large)
|
||||
control("a real block IN the register is parsed [the live instance, not a fixture]",
|
||||
any(d["file"].name == "PENDING.md" for d in deferrals)
|
||||
or "DEFERRED-DECISION:" not in (HOME / "dotfiles/PENDING.md").read_text(errors="replace"))
|
||||
control("the size guard still applies to non-governance files [negative control — "
|
||||
"the exemption must not become 'scan everything']",
|
||||
(HOME / "dotfiles/PENDING.md") in GOVERNANCE_FILES
|
||||
and (HOME / "dotfiles/CLAUDE.md") not in GOVERNANCE_FILES)
|
||||
control("trigger evaluator FIRES on a met condition",
|
||||
_p_ok and trigger_fired(_p_ok[0]) is True)
|
||||
control("trigger evaluator does NOT fire on an unmet condition "
|
||||
@@ -564,5 +596,13 @@ if deferrals:
|
||||
f"({', '.join(f'{k} {v}' for k, v in prose_counts.items())}) — these carry no")
|
||||
print(" DEFERRED-DECISION block, so NO trigger is machine-checkable for any of them.")
|
||||
print(" Counted, not classified. Whether any condition has fired is unestablished.")
|
||||
if skipped_too_large:
|
||||
print(f" ⚠ and {len(skipped_too_large)} file(s) were NOT SCANNED for structured blocks "
|
||||
f"(over the 400 KB guard):")
|
||||
for _s in skipped_too_large:
|
||||
print(f" {_s.relative_to(HOME) if HOME in _s.parents else _s} "
|
||||
f"({_s.stat().st_size:,} bytes)")
|
||||
print(" Any DEFERRED-DECISION block in these is INERT. This is 'could not assess',")
|
||||
print(" not 'nothing there' — the distinction REVIEWED-104 rules may not be collapsed.")
|
||||
|
||||
sys.exit(0)
|
||||
|
||||
Reference in New Issue
Block a user