🔧 Auto-commit from sysupdate on 2026-05-19 21:49

This commit is contained in:
David F Glidden
2026-05-19 21:49:14 +02:00
parent e9e772d69c
commit f83aae27c5
132 changed files with 14728 additions and 38 deletions
+130 -1
View File
@@ -111,7 +111,136 @@ Proposal to couple the observation path to existing recall capability, replacing
**Activated dead machinery.** The proposal connects existing but unwired capability (vector similarity search, CausalEdgeCandidate, compressToAtomicFacts, computeSalience) to the ingestion path. This is architectural completion, not new complexity. Density gate [FIX] (gate ordering in compressToAtomicFacts) authorized separately and independent of this proposal.
## REVIEWED-23 — H4 surfacing-to-Seb design-call action (PENDING-21)
**Date:** 2026-05-14
**Decision:** AUTHORIZED
Authorize the surfacing action for H4 (hook events pollute recall + logchain accumulation, GH issue #167, priority:high). The PENDING-21 entry's recommended **Option B** is approved: post a comment on #167 referencing PR #172 + the H2 comment on #165 (batches the audit's three open findings into one Seb-attention window), and surface all three design questions verbatim from the addendum §4 plus the H2/H4 coupling note.
**Authorized action shape:**
- Comment on `CapableMind-ai/betterMemories_app#167`
- Asks Seb to address all three questions (prompt filtering at hook / event classification at BMF / recall-triggering policy), or explicitly defer specific ones
- Includes the §6 aggregate-cost framing as a fourth-question-in-effect
- **Surfaces the H2/H4 coupling explicitly**: H4's ambient cost is *pure loss on battery* per addendum §6, so resolving H2 toward CPU fallback or default-allow affects H4's cost analysis directly — Seb should see this rather than treating H2 and H4 as independent
- References PR #172 + the H2 comment on #165 to batch attention
**Constraint:** the comment text itself must be reviewed by the steward before posting. The executor drafts; the steward authorizes the literal text. (Same discipline as REVIEWED-21.)
**Escalation path:** if Seb's response is "let's talk" or if the comment goes >1 week without engagement, escalate to **Option A** (sync conversation). Option C (executor pre-drafting a unified design proposal) remains rejected.
**No code change in scope.** This authorization is for the conversation, not a PR. When Seb's direction is set, the resulting work re-enters the governance loop as a new PENDING.
## REVIEWED-22 — Cross-cutting read-path-honest-degradation [PROPOSAL] (PENDING-20)
**Date:** 2026-05-14
**Decision:** AUTHORIZED — Option (a) only: PENDING-20 stays as L1 governance entry. L2 elevation work is **DEFERRED to post-May 2026** per global CLAUDE.md parked status (*"L2 PARKED through end of May 2026. No L2 governance advancement, no new invariant work, no constitutional proposals. L2-adjacent questions arising from L1 work: note, don't pursue."*).
**Correction (2026-05-14, same session):** The original REVIEWED-22 entry recorded Option (c) — both PENDING and L2 elevation. The executor surfaced the L2-PARKED constitutional tension at session end; steward confirmed: *"I won't be working on L2 until the end of May — that something was surfaced because of L1 work is both fantastic and coincidental."* The surfacing was welcome AS L1-adjacent recognition; the L2 elevation work (cluster declaration, registry entry, contamination-profile exchange) is **NOT** authorized until end of May 2026. The jurist's framings below are RECORDED for posterity; the work they would shape is held.
**Jurist's three governance calls (recorded for post-May pickup):**
**1. Cluster placement: Not Cluster A. Cluster B (new or existing).** The Cluster A case has a real argument but proves too much — it would also pull DN-GOV-05's independent-verifiability test and REVIEWED-19's epistemic integrity into Cluster A. Cluster A is *relational posture* (system's first-person stance toward the interlocutor — accusative default, asymmetry obligation, precedence of present expression). Read-path observability is **epistemically downstream of Cluster A**, not peer to it. The common genus with REVIEWED-18 and REVIEWED-19 is *conditions under which the system's epistemic behavior can be verified and governed at all*: honest ingestion, honest recall, honest degradation. **Cluster B is the right cluster.** Cluster B may already be implicit (REVIEWED-18, REVIEWED-19 both pending cluster assignment) or need formal constitution; one-sentence steward declaration settles it. **Held until post-May.**
**2. DN-GOV-08 fit: confirmed.** The honest-degradation contract sits cleanly on the *(i) constituting conditions* side, not the *(ii) automating recognition* side. It specifies structural requirements (the system must expose why it returned empty) without specifying content requirements (what a correct memory result is). The "why empty" breadcrumb tells the operator what happened to the answer-finding machinery, not what the right answer was. Structural distinction, not content judgment. The executor's framing of "stabilizes the conditions" maps cleanly. **No rewrite needed.** DN-GOV-08 evaluation language to be added to the registry entry per I15/I16/I17 pattern: *"This invariant specifies the conditions under which read-path behavior can be observed and governed. It does not specify what correct memory outputs are, or when a recall result is to be trusted. The contract holds open the space for informed steward judgment; it does not automate that judgment."*
**3. L1_contamination_profile: distinct from Cluster A; requires careful drafting.** The contamination risk for a read-path observability invariant is **not** the same monotonic pressure toward interlocutor satisfaction that Cluster A invariants face. It is the **competence-vulnerability paradox** from the Observer Problem: the more capable the system becomes at recall, the less visible the failure modes become, because successful recall masks the moments when degradation is silently occurring. Profile candidate: ***moderate, structural*** — pressure toward *apparent* health rather than *actual* health; manifests as increasing capability masking decreasing observability of degraded paths. **Saved as project memory** (`project-competence-vulnerability-paradox.md`) for portability beyond the L2 work. **Brief jurist↔steward exchange on the profile language is held until post-May.**
**Authorized actions THIS session:**
- PENDING-20 filed as L1 governance entry — DONE.
- Jurist's three framings recorded above for the post-May pickup.
- Project memory saved for the contamination-shape framing (it is portable to any future read-path work, not just L2).
**Held until post-May 2026 (do NOT pursue):**
- Steward declaration on Cluster B status.
- Jurist drafting cluster framing note (if needed) and registry entry per I15-I17 pattern.
- Brief jurist↔steward exchange on l1_contamination_profile language.
- Filing of registry entry in `capablemind/docs/thinking/David/l2-constitution/amendments/`.
**Executor's role going forward:** maintain PENDING-20 as engineering-visibility record (track Seb's response on H2 #165 and how it informs the cross-cutting); do not produce L2 doctrine; do not initiate cluster declaration or registry-entry drafting; if a future jurist message arrives on this topic before end of May, surface the parked status before responding substantively.
**Jurist's three governance calls (authorizing):**
**1. Cluster placement: Not Cluster A. Cluster B (new or existing).** The Cluster A case has a real argument (read-path observability has a conceptual connection to relational posture) but proves too much — it would also pull DN-GOV-05's independent-verifiability test and REVIEWED-19's epistemic integrity into Cluster A. Cluster A is *relational posture* (system's first-person stance toward the interlocutor — accusative default, asymmetry obligation, precedence of present expression). Read-path observability is **epistemically downstream of Cluster A**, not peer to it. The common genus with REVIEWED-18 and REVIEWED-19 is *conditions under which the system's epistemic behavior can be verified and governed at all*: honest ingestion, honest recall, honest degradation. **Cluster B is the right cluster.** Whether Cluster B is already implicit (REVIEWED-18, REVIEWED-19 both pending cluster assignment) or needs formal constitution is a one-sentence steward declaration. Jurist offered to draft a cluster framing note if needed.
**2. DN-GOV-08 fit: confirmed.** The honest-degradation contract sits cleanly on the *(i) constituting conditions* side of the DN-GOV-08 line, not the *(ii) automating recognition* side. It specifies structural requirements (the system must expose why it returned empty) without specifying content requirements (what a correct memory result is). The "why empty" breadcrumb tells the operator what happened to the answer-finding machinery, not what the right answer was. Structural distinction, not content judgment. The executor's framing of "stabilizes the conditions" maps cleanly. **No rewrite needed.** DN-GOV-08 evaluation language to be added to the registry entry per I15/I16/I17 pattern: *"This invariant specifies the conditions under which read-path behavior can be observed and governed. It does not specify what correct memory outputs are, or when a recall result is to be trusted. The contract holds open the space for informed steward judgment; it does not automate that judgment."*
**3. L1_contamination_profile: distinct from Cluster A; requires careful drafting.** The contamination risk for a read-path observability invariant is **not** the same monotonic pressure toward interlocutor satisfaction that Cluster A invariants face. It is the **competence-vulnerability paradox** from the Observer Problem: the more capable the system becomes at recall, the less visible the failure modes become, because successful recall masks the moments when degradation is silently occurring. Profile candidate: ***moderate, structural*** — pressure toward *apparent* health rather than *actual* health; manifests as increasing capability masking decreasing observability of degraded paths. **Different enough from "monotonic" that a brief jurist↔steward exchange is recommended before finalizing the registry entry.**
**Authorized sequence (jurist's territory; executor does not produce):**
1. Steward declares Cluster B status (one sentence). Jurist may draft a framing note to accompany if needed.
2. Jurist drafts registry entry per I15/I16/I17 pattern: statement → sources (architectural/empirical: four H-confirmations, REVIEWED-19, DN-GOV-05 independent-verifiability, bettermemories/CLAUDE.md) → adversarial review → l1_contamination_profile (per Q3 framing) → DN-GOV-08 evaluation (per Q2 language) → residual_risk (deferred pending pilot, per REVIEWED-11 schema decision).
3. Brief jurist↔steward exchange on the l1_contamination_profile language before finalization.
4. Registry entry filed in `capablemind/docs/thinking/David/l2-constitution/amendments/` per I15-I17 pattern.
**Executor's role going forward:** maintain the L1 PENDING-20 entry as the engineering-visibility record (track Seb's response on H2 #165 and how it informs the cross-cutting); do not produce L2 doctrine. When jurist completes the registry entry, executor updates PENDING-20 with cross-reference to the L2 entry.
**No code change in scope.** No PR. Mechanism work cannot start until Seb chooses a direction for H2 (PENDING-19), and even then would re-enter the governance loop as a fresh PENDING with its own tag.
## REVIEWED-21 — H2 surfacing-to-Seb design-call action (PENDING-19)
**Date:** 2026-05-14
**Decision:** AUTHORIZED
Authorize the surfacing action for H2 (battery-power suppression silently fails recall, GH issue #165, priority:critical). The PENDING-19 entry's recommended **Option B** is approved: post a comment on #165 referencing PR #172 (which Seb is about to look at for H3), and surface all four design questions verbatim from the addendum §2.
**Authorized action shape:**
- Comment on `CapableMind-ai/betterMemories_app#165`
- Asks Seb to address all four questions (default policy / visible degradation / CPU fallback / query-vs-ingestion asymmetry), or explicitly defer specific ones
- References PR #172 to batch attention while it's high
- Does NOT pre-decide direction; the four questions are policy and Seb's territory
**Constraint:** the comment text itself must be reviewed by the steward before posting. The executor drafts; the steward authorizes the literal text.
**Escalation path:** if Seb's response is "let's talk" or if the comment goes >1 week without engagement, escalate to **Option A** (sync conversation). Option C (executor pre-drafting a unified design proposal) remains rejected — it would have the executor pre-deciding what is properly Seb's call.
**No code change in scope.** This authorization is for the conversation, not a PR. When Seb's direction is set, the resulting work re-enters the governance loop as a new PENDING with appropriate tag (likely [HARDENING] for any single-direction implementation; possibly [PROPOSAL] if the direction implies architectural change to `system_status`).
## REVIEWED-20 — Fix H3: Temporal stats fallthrough on text queries (PENDING-18)
**Date:** 2026-05-14
**Decision:** AUTHORIZED
[HARDENING] proposal authorized after jurist review, with one modification: spec amendment must explicitly bump `temporal-module-spec.md` from v1.7 → v1.8 as a **gap-filling addition**, not a clarification. The current behavior is not a misimplementation of a stated rule — the spec (§7) defines query types as enumerated and `TemporalStatsQuery` (§7.6) requires explicit `type: 'temporal_stats'`; the spec is silent on missing/unrecognized filter type. The amendment creates a contract that did not exist.
**Authorized amendment shape (per jurist):**
- (a) `filters.type` missing/null → `{status: 'ok', results: [], total: 0}` (honest empty)
- (b) `filters.type` unrecognized → same return, optional debug note in development mode
- Preserve `temporal_stats` handler on explicit `type: 'temporal_stats'` per existing §7.6
- Amendment must articulate WHY: temporal module is type-dispatched by design; a free-text query without type is a malformed query, not a degraded valid query — empty is the honest response, not a stats blob dressed as content.
**Authorized sequence:**
1. Amendment in `capablemind/docs/thinking/David/l1-reliability/h3-temporal-fallthrough-amendment-2026-05-14.md` (gap-filling addition, v1.7 → v1.8).
2. Branch `fix/h3-temporal-text-query-fallthrough` from main.
3. Failing tests reproducing both fallthrough sites red on main.
4. Minimal Option 1 fix (module-level guard at `parseTemporalQueryParams`).
5. Full test suite + `npm run check` + `npm run lint` per BMF CLAUDE.md.
6. PR designed to merge in <30 min of Seb's attention. Body references PENDING-18, REVIEWED-19 (epistemic integrity), REVIEWED-20.
**Cross-cutting [PROPOSAL] authorized for parallel filing:** read-path-honest-degradation-contract finding from the addendum may be filed as a separate PENDING-19 [PROPOSAL] before or after the H3 PR opens. Naming the pattern is the deliverable; remediation path not assigned. Do not block on it; it does not block the H3 PR.
## REVIEWED-17 — ICP-19: Mandated External Review
**Date:** 2026-03-28
**Decision:** AUTHORIZED
**Notes:** Closes AF-7 — the corpus's single most consequential gap. Elevates C-R2 from process recommendation to constitutional requirement. Roman strand (provocatio/intercessio) + relational strand (formative contamination detection). Three institutional phases: founding (steward-appointed human reviewer), mature (Founders Circle external panel), deployment (independent reviewer with contractual standing — hard deadline). Not-embedded criterion defined: not sharing L1 substrate, not system interlocutor, unmediated record access, unedited findings. Findings trigger HOLD (not advisory). Three-cycle FM-R4 marker prevents decorative compliance. DN-GOV-08 evaluation passed: holds open the space. **Lifts GOV-05 and GOV-06 suspension clauses** — bounded self-repair and temporal authorization shift now operative as design commitments. Four open items before first review cycle: Luke's confirmation, findings threshold classification, governed operations scope, Mauss/nexum Phase 2 deferral. L1 contamination: critical, monotonic — formative contamination is the primary threat and external review is the only mechanism operating outside the formative frame.
**Notes:** Closes AF-7 — the corpus's single most consequential gap. Elevates C-R2 from process recommendation to constitutional requirement. Roman strand (provocatio/intercessio) + relational strand (formative contamination detection). Three institutional phases: founding (steward-appointed human reviewer), mature (Founders Circle external panel), deployment (independent reviewer with contractual standing — hard deadline). Not-embedded criterion defined: not sharing L1 substrate, not system interlocutor, unmediated record access, unedited findings. Findings trigger HOLD (not advisory). Three-cycle FM-R4 marker prevents decorative compliance. DN-GOV-08 evaluation passed: holds open the space. **Lifts GOV-05 and GOV-06 suspension clauses** — bounded self-repair and temporal authorization shift now operative as design commitments. Four open items before first review cycle: Luke's confirmation, findings threshold classification, governed operations scope, Mauss/nexum Phase 2 deferral. L1 contamination: critical, monotonic — formative contamination is the primary threat and external review is the only mechanism operating outside the formative frame.
## REVIEWED-24 — PENDING-S1 — Wrap-up §8 output template (pause statement + negative space)
**Date:** 2026-05-18
**Decision:** AUTHORIZED (Class A bundle: S1 + S3 + S8)
**Notes:** Steward conversational authorization 2026-05-18 ("I authorize class A"). Implemented same session: `~/.claude/skills/wrap-up/SKILL.md` §8 template gains `**Pause statement:**` and `**Decisions deferred (and why):**` as named fields, with explicit annotation that the pause is constitutive (Jurist Q3 Harrison-grounded reasoning: *the ligature is laid at departure, not discovered at return*) and that the negative space is required for the unborn session to know the scope of what was held back. **Closes PENDING-S1.** First operational test: the /wrap-up at the end of this session.
## REVIEWED-25 — PENDING-S3 — Wake-up §3 binary thread validity gate
**Date:** 2026-05-18
**Decision:** AUTHORIZED (Class A bundle: S1 + S3 + S8)
**Notes:** Steward conversational authorization 2026-05-18 ("I authorize class A"). Implemented same session: `~/.claude/skills/wake-up/SKILL.md` §3 gains an explicit thread validity gate as the first step of synthesis, with binary outcome (`confirmed / stale / superseded`) and required one-line reason. If `stale` or `superseded`, briefing structure reorders to lead with what changed, not with the thread. Moves the staleness check from permission-in-prose to structurally-required gate. **Closes PENDING-S3.**
## REVIEWED-26 — PENDING-S8 — Symmetria pulse lineage anchor + wake-up traversal tools prescribed
**Date:** 2026-05-18
**Decision:** AUTHORIZED (Class A bundle: S1 + S3 + S8)
**Notes:** Steward conversational authorization 2026-05-18 ("I authorize class A"). Two related drifts implemented same session:
- **Symmetria §6 pulse** gains step 0 — re-anchor craft / ethics / character to lineage (now including the *τὸ πρόσφορον*-includes-time elaboration in §0). Closes the D2 drift (lineage decorative-rather-than-load-bearing in the pulse procedure). Step 5 also gains an explicit cross-reference to §3 self-flag for `aligned`-without-tension.
- **Wake-up §2.b** gains a new b.4 substep prescribing `mempalace_find_tunnels` (when pulling thread crosses project boundaries) and `mempalace_kg_timeline` (when reconstruction requires knowing *when* a fact changed). Closes the B6 leverage gap (traversal tools mentioned in constraints but not in procedure).
**Closes PENDING-S8.**
## REVIEWED-S0-via-commit — PENDING-S0 — Prime Directive elaboration
**Date:** 2026-05-18
**Decision:** AUTHORIZED-and-CLOSED-by-direct-steward-commit (no separate REVIEWED-N number; recorded here for cluster completeness)
**Notes:** Per Phase 2 of the audit's revised authorization sequence: steward authored the Directive elaboration (*τὸ πρόσφορον — what is fitting — includes the time the task requires...*); Jurist shape-reviewed the language as drafted + placement (Option 1: both CLAUDE.md and Symmetria §0); steward committed `~/CLAUDE.md` directly (line 12, between μέτρον citation and "decision filter" prose) — one-handed with Kai in sling; executor committed `~/.claude/skills/symmetria/SKILL.md` §0 (between gloss and §0 header). Constitutional commitment + operational carrier landed in the same moment. Methodology artifacts at `~/_Dev/CapableMind-AI/docs/thinking/David/methodology/` (brief + shape-review + elaboration). **Closes PENDING-S0.** Class A authorization (REVIEWED-24/25/26) is the operational unfolding of this constitutional commitment in the skills themselves.