Compare commits

...
10 Commits
Author SHA1 Message Date
David F GliddenandClaude Opus 5 9d7c29f3bf session 2026-08-02 pm: PENDING-90 (first L2 transfer) + PENDING-91 (vignette jurist gate)
PENDING-90 [ESCALATE] carries Constraint 6 into CapableMind's calibration loop —
the AdaptationChain records who initiated an adaptation but never who checked it,
and when authorization.required is false (the whole self-adjustment case) no
checker is in the record at all.

PENDING-91 [PROPOSAL] is the vignette Phase-1a design gate, leading with the
structural problem that the dwell-test is assigned to a jurist who cannot see
the render — third instance of the gap docketed at PENDING-86 and PENDING-82.

Session record, ledger, KG (+6: two drift-patterns, two preventions, the
Notre-Dame anchor, the superseded gitea diagnosis), and four skill-harvest
proposals. One FIX-lane application indexed (ARC CLAUDE.md freshness).

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WuMjg3ipEVa3n8CoSzoyvc
2026-08-02 16:31:42 +02:00
David F GliddenandClaude Opus 5 e95568c857 [PROPOSAL] PENDING-91 — Vignette Phase 1a: jurist design gate (the dwell-test)
The dwell-test is assigned to the jurist by spec, and the jurist cannot see the
render. Third instance of the gap docketed at PENDING-86 and PENDING-82, now in
visual form. Q5 puts three options rather than papering over it.

Package at ARC 7b8f64d; 33/33 quotations contained, 9/9 controls absent.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WuMjg3ipEVa3n8CoSzoyvc
2026-08-02 13:41:20 +02:00
David F GliddenandClaude Opus 5 affc666cbf [ESCALATE] PENDING-90 — first L2 transfer: checker position in the calibration loop
Five months of microcosm work has produced material for CapableMind's L2 and
transferred none of it. This is the first transfer: a candidate amendment
carrying Constraint 6 into the spec corpus, landing where CapableMind actually
evaluates its own self-adjustment — the trust calibration loop.

Tagged ESCALATE, not PROPOSAL: Change 4 proposes an autonomy ceiling, which is
constitutional, and this file's own rule escalates those unconditionally.
Checked first for a pre-existing authorization covering the L2 transfer —
there is none, so the boundary is real rather than manufactured.

Ledger records the sixth instance of the day's pattern, caught inside the wake
that inherited it: the pulling thread's own checkable claim — "there is no
amendments/ directory in thinking/David/" — was false. There is; 14 files,
last touched 2026-06-13. The honest claim narrows to: L1 material has
transferred through this machinery within the last eight weeks, the chamber
material has not.

Also recorded under "What held": the wake's substrate-check rule fired a second
time, on the thread itself. Provisional answer to the session's own literal
question — the census instrument that failed five times yesterday fired today
when written into a *procedure* rather than banked as a *lesson*. One datum.

Amendment committed separately at CapableMind-AI 5326704.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WuMjg3ipEVa3n8CoSzoyvc
2026-08-02 12:52:56 +02:00
David F GliddenandClaude Opus 5 1b258e1163 session 2026-08-02: Constraint 6 amendment verified; REVIEWED-85 FIX lane + batch 1; v1 Chamber archive evidence (ADDENDUM-1) + jurist ruling; wake-digest ID fix; PENDING-89 opened, -10/-86 amended
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WuMjg3ipEVa3n8CoSzoyvc
2026-08-02 12:28:24 +02:00
David F GliddenandClaude Opus 5 3d189c8f0a [FIX] PENDING-10: record the scope extension that has been live since June
Seb's issue CapableMind-ai/betterMemories_app#176 cites PENDING-10 as the
replay-contract audit question -- "does any BMF surface hold state not
reconstructible by replay from the logchain?" The item as recorded says nothing
of the kind; it is a March performance proposal about deferring embedding.

Checked before calling it a miscitation, and it isn't one. The steward framed the
audit question as PENDING-10's in his own 2026-06-06 cover note and its addendum;
Seb picked it up from there. Both parties have meant the larger thing for two
months.

What never happened is the write-back. The extension lived in cover notes and
never reached the item, so the register -- and the wake digest that surfaces it by
title -- has been serving the March scope ever since.

Third shape of record-vs-reality divergence found today, after the digest's
ID-matching bug and a REVIEWED disposition clause read as status. This one is a
stable ID whose content moved with no marker that it moved.

Amendment records the live scope, the evidence accumulated since March (Pebbles,
memory-os/PMB, the MemPalace forensic, and the mindfabric-00 backup finding), and
flags that these are probably two items rather than one. Splitting is the
steward's call and is not done here.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WuMjg3ipEVa3n8CoSzoyvc
2026-08-02 12:23:14 +02:00
David F GliddenandClaude Opus 5 c30dfe0162 [REVIEWED-86] Constraint 6 amended — steward placed; executor verification
The steward placed the amendment. Recording the verification promised, and the
instrument limit it exposed.

Bounded-diff proof: 9 insertions, 0 deletions. Constraint 6's original text
byte-identical at 222 chars. Zero pre-amendment lines missing. Purely additive,
as designed -- the caution is refined, not relaxed.

Both jurist conditions verified present verbatim in the placed text: the Q2 weld
(fail to coincide, not cancel; never cited as assurance something was caught) and
the Q3 self-limiting clause (jurist and executor share formation; neither the
doctrine nor its evidence establishes that pair as a check in the strong sense).
6/6 contained, 5/5 controls absent, instrument verified.

List integrity confirmed with pandoc rather than by reasoning about it: the
doctrine parses INSIDE list item 6 despite the double blank line. No structural
problem.

The verification took three attempts, and the first two failures were mine. Both
controls I built for the Q3 negation were substrings of the sentence that does
the negating -- "establishes that the pair constitutes a check" appears verbatim
inside "Neither this doctrine nor any evidence ... establishes that the pair
constitutes a check". They leaked by construction. The instrument was right to
refuse certification twice; the controls were malformed.

That is a real limit and it is now documented in the script: substring containment
has no notion of polarity and CANNOT verify a negation. Controls must be built by
inversion, never by extraction. Where polarity is what matters the instrument does
not settle it -- read the sentence, and report that containment did not cover it.
Which is the case here: that the Q3 clause denies rather than affirms was
established by reading, not by the check.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WuMjg3ipEVa3n8CoSzoyvc
2026-08-02 12:13:38 +02:00
David F GliddenandClaude Opus 5 2f5dbc98fd [FIX] REVIEWED-86: file the ruling, draft the Constraint 6 amendment, docket Q3
Ruling filed verbatim. Drafting authorized by the steward's placement of
REVIEWED-86; application is not, and ~/CLAUDE.md is untouched.

The amendment adds a second paragraph to Constraint 6 and replaces nothing --
both original clauses survive verbatim, the caution is refined rather than
relaxed, and the L2 deferral stands.

Both jurist conditions welded into the text that would actually land, not left
in surrounding commentary, since a future reader cites the doctrine block and
not the discussion of it. Q2: biases that fail to coincide do not cancel, and
the doctrine may never be cited as assurance something WAS caught. Q3: the
jurist and executor do not differ in formation, their separation is the weaker
kind, and neither the doctrine nor its evidence establishes that pair as a check
in the strong sense -- the doctrine naming the configuration that produced it as
the one it does not vouch for.

Steward ruled the open question on `Status: provisional` sitting inside a section
headed "cannot be overridden": retain it. Constraint 6 already carries a temporal
qualifier, so the section is not free of them.

Paste block prepared separately, indented to continue the numbered list. The edit
is the steward's: Constraint 1 names this file and sits under "cannot be
overridden by any session instruction", and the ruling states the steward's own
act is what nothing substitutes for.

PENDING-89 dockets the Q3 correlation review the jurist declined to leave
hypothetical, with the hazard named -- this is the executor measuring whether the
executor is checked, so criteria must be pre-registered and it may be steward-only
work.

Q4 folded into the existing REVIEWED-85 check-in agenda rather than given its own
cadence, per the ruling's reasoning that a new standing review produces another
unread register.

PENDING-86 amended with its third instance: the jurist could not reach
contamination-problem.md while gating an argument that turns on it.

Convergence question closed. The jurist inferred a common source; the steward
confirmed it -- the exchange was shared as context only, and Document A predates
it, so the jurist's language cannot have shaped the proposal. Neither
contamination nor corroboration.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WuMjg3ipEVa3n8CoSzoyvc
2026-08-02 12:10:34 +02:00
David F GliddenandClaude Opus 5 bd4e9d8b75 [FIX] Skill harvest: two proposals from the packaging work (rows 181-182)
Both surfaced, neither applied.

181 -- /jurist-package has no step distinguishing filed from sent. The doctrine
package sat filed-and-unsent for a day and its state was not determinable from
the repository; the executor had to ask.

182 -- require the containment proof the skill's own quote-never-paraphrase
discipline implies. PROPOSAL rather than FIX: it changes gate criteria, which
the new §1.6 hard floor reserves. Routes with PENDING-86 option (b), unruled.

Held deliberately, with reasons rather than as backlog: /fool stays
build-when-stable (row 178, trial 03 unrun); normalize_ocr (row 180) is chamber
fleet and the standing directive requires grounding in constitution, charter and
runbook first; and no further FIX-lane batch is applied before the REVIEWED-85
check-in, since batch 2 arriving before the review would bypass what the
condition exists to review.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WuMjg3ipEVa3n8CoSzoyvc
2026-08-02 12:00:42 +02:00
David F GliddenandClaude Opus 5 4dc38e69b9 [FIX] wake-digest: resolve rulings by subject, not by number
sec_pending() suppressed any PENDING-N whose number appeared as a REVIEWED-N,
never checking the ruling was about that item. The two sequences have drifted:
REVIEWED-84 rules on PENDING-87. So PENDING-84 was invisible at wake on the very
morning the steward's pulling thread pointed at it, and closing it later produced
no visible count change because it had never been counted. Found 2026-08-01 at
wake, surfaced not fixed; register row 179.

Resolution now reads the PENDING each ruling names in its header. Rulings that
name none (REVIEWED-78, -81, -82) suppress nothing.

Extracted as ruled_pendings() so it is testable at all -- the logic was buried in
a file-reading routine with no way to exercise it. Five self-tests added,
including the 2026-08-01 bug as a regression control and an empty-input positive
control.

Bounded-change proof against the live files: 18 -> 19 visible. Three items
surfaced that were falsely hidden (PENDING-78, -81, -82); two stopped being shown
that are genuinely ruled (PENDING-87 by REVIEWED-84, PENDING-88 by REVIEWED-85 --
no REVIEWED-87 or -88 exists, so number-matching had never suppressed them).

That proof also caught an overclaim in this fix's own docstring, which asserted
the correction could only ever surface more items and never fewer. It corrects in
both directions. Comment repaired to say what the code does; the false version
would have been a comment promising behaviour the code does not deliver, in a
file whose purpose is to stop governance hiding from the steward.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WuMjg3ipEVa3n8CoSzoyvc
2026-08-02 11:59:47 +02:00
David F GliddenandClaude Opus 5 62b92bd425 [FIX] Land the skill-harvest FIX lane and apply its first batch (REVIEWED-85)
REVIEWED-85 was placed by the steward at 10:41 today; the wake flagged at 10:44
that /wrap-up SKILL.md was still untouched since 2026-07-07. Landing it.

Precondition discharged first. The ruling states its own verification limit: the
jurist could not read the skill files, so the /wrap-up §1.6 and /wake-up §2.a
quotes underpinning Part III's "contradicts itself" claim were affirmed on
timeline evidence rather than checked. Required before landing was mechanical
containment-with-positive-control verification of exactly those quotes. Run:
7/7 contained verbatim against the live skills, 5/5 controls absent, instrument
verified.

§1.6 now carries the two-clause disjunctive test (the executor's own narrower
single-clause alternative declined at the gate as less safe), the hard floor with
its catch-all sharpened per Q4 and tied to the measured failure rather than left
as open judgment, and all three instruments as mandatory. The lane is provisional
pending the steward-jurist check-in.

The §Important-constraints line still stated the blanket rule the ruling narrowed.
Left alone it would have been a second live version of a governance rule inside
the file that forbids exactly that. Reconciled, with a note saying why.

First batch applied -- the four class-(i) proposals the steward raised 2026-07-29
and which REVIEWED-85 itself dispositions as batch 1, so their classification was
ruled rather than self-assessed: a `## What held` ledger section (the ledger could
previously only record debits), a `prevention` KG predicate capturing transfer
between failure classes, one wake line surfacing it, and the retirement of the
standing question's self-report framing in favour of the checkable form -- the
last on the grounds contamination-problem.md gives, that direct self-report is
the most contaminated form of inquiry.

The FIX-lane index is created and carries all four. It records explicitly what is
NOT in it: the §1.6 edit itself, which changed what the executor may do without
asking and was therefore PROPOSAL by its own test. A lane cannot authorize its
own construction.

Register rows 174-177 marked applied.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WuMjg3ipEVa3n8CoSzoyvc
2026-08-02 11:55:15 +02:00
21 changed files with 736 additions and 13 deletions
+9
View File
@@ -247,3 +247,12 @@ These cannot be overridden by any session instruction, seed, or convenience:
4. **Honest degradation** — The system must report its own limits. Silent failures are architectural violations
5. **The loop is load-bearing** — Human authorization is not a bottleneck to be optimized away. It is the structural requirement of the governance model
6. **Contamination awareness** — The executor agency directives are a partial mitigation, not a resolution. Treat outputs about the system's own reliability with appropriate epistemic caution until L2 inquiry is formalized
**Differently biased checkers, not unbiased ones.** Oversight does not require a checker without bias. It requires checkers whose biases do not point the same way. Separation of powers has never presupposed an unbiased branch; it presupposes branches positioned so that what one is disposed to miss, another is disposed to see. The contamination problem is therefore not a defect to be cured before the system can be trusted — it is the ordinary condition under which every oversight structure has ever operated, human or otherwise. This is the positive counterpart to the central path: that path says stop certifying the parties, bind the claims, and never audit the audit; this says why stopping is safe, because the work is caught by position rather than by purity.
Biases that fail to coincide do not cancel. Failing to coincide is weaker than cancelling, and it is all that is claimed: a configuration can satisfy "differently positioned" and still miss an entire class no party is positioned to see. This doctrine may therefore never be cited as assurance that something *was* caught. It is only ever the reason a structure is worth maintaining.
Three consequences bind. First, the three-party model is not a trust hierarchy: steward, jurist and executor are not ordered by reliability, with a clean human checking a suspect machine, but differently positioned readers — different information, different role, different exposure — and a correction may run in any direction. Second, independence is a property to be engineered, not assumed. Difference of formation is the strong form; difference of role, information and incentive is the weak form. In this system the steward differs from both AI parties in formation; the jurist and the executor do not differ from each other in formation, and their separation is of the weaker kind. Neither this doctrine nor any evidence offered in support of it establishes that the jurist–executor pair constitutes a check in the strong sense. Third, the doctrine is falsifiable and must be watched: if the parties' misses are found to correlate — if what one misses, the others reliably miss too — it is false for that configuration, and no amount of procedural care substitutes. Evidence against is to be recorded when observed, not only when sought.
*Status: provisional. Held until the thought is more refined, and revisable on evidence. Proposed by the executor, design-gated by the jurist 2026-08-02 with two required conditions (REVIEWED-86), placed by the steward.*
+48
View File
@@ -38,6 +38,14 @@ does not.
**Summary:** Currently implemented as simple early return in handleEvent. For production: should be a formal replay contract where vector stores content metadata during replay without embedding, then a background re-embed pass populates the HNSW index. Paired with Bug D idle stall fix, this makes Phase 1 fast by design.
**Awaiting:** Steward + Seb architectural review.
**Amendment 2026-08-02 — the item's live scope is larger than its 2026-03-22 body, and has been since June.** This entry describes a *performance* proposal (skip embedding during replay, background re-embed). Both parties now use "PENDING-10" to mean something broader: the **replay-contract audit question** — *"does any BMF surface hold state not reconstructible by replay from the logchain?"* — framed by the steward in `CapableMind-AI/docs/thinking/David/l1-reliability/cover-note-seb-reply-l1-arc-2026-06-06.md` (*"PENDING-10's replay contract, now with a body of evidence"*) and its same-day addendum, and echoed by Seb in the 2026-06-07 reply and again in **issue `CapableMind-ai/betterMemories_app#176`** (2026-08-01), which states the audit is *blocked* on the backup pipeline.
**Evidence accumulated since March, none of it recorded here until now:** three convergent datapoints from the steward's scan work (Pebbles' independent reinvention of authoritative-log + derived-disposable-index; memory-os and PMB deep-reads showing the fragile class is always a mutable index as *primary* store; the MemPalace forensic as empirical casualty) — and the concrete trigger, `backup.last_success: null` on mindfabric-00, meaning the instance holding the steward's accumulated memory has single-copy state whose *designed* mitigation is precisely logchain rebuildability.
**Why this amendment exists.** The extension was written in cover notes and never written back into the item. Anyone reading this register — including the wake digest, which surfaces PENDING-10 by its title — got the March scope. Same class as the two record-vs-reality divergences found the same day (the digest's ID-matching bug; a REVIEWED disposition clause read as status): **a stable ID whose content has drifted, with no marker that it moved.**
**Consequence for the split:** these are two separable pieces of work and should probably be two items. The performance proposal is architectural and awaits review; the audit question is load-bearing for the provenance story and is now scoped inside Seb's #176 restore drill. Splitting them is the steward's call — flagged, not done.
## PENDING-11 — Approve I15 (ICP-9 Pilot Registry Entry: The Accusative Default)
**Date:** 2026-03-23
**Tag:** [PROPOSAL]
@@ -638,6 +646,8 @@ Executed as §VII eyeball-after-gate: pages rendered with `pdftoppm` and read, n
**Awaiting:** Steward authorization — it widens what the jurist can read, which is the steward's call, not the executor's.
**Amendment 2026-07-29 (PENDING-87 / REVIEWED-84 process note, jurist-raised, not ruled):** a **second, independent** instance of this item's failure, and it sharpens the diagnosis. The jurist's REVIEWED-83 Q3 demanded an outcome REVIEWED-74 had already established was impossible — a ruling **four days older**, in a file the jurist *could* read, but had no reason to open, *"since nothing in the package I ruled on mentioned order or Eichmann at all."* So the gap is not only **"the jurist cannot read the constitution it design-gates"** but **"the jurist cannot discover a relevant prior ruling whose ID it does not already know."** Keyed retrieval cannot fix that; only search can — hence option (d). The jurist directed this be folded here rather than opened as a new item.
**Amendment 2026-08-02 (third instance, jurist-raised in REVIEWED-86):** the jurist could not reach `contamination-problem.md` — *"same gap as the skill files last time, now touching the part of the argument that establishes the doctrine actually has a gap to fill"* — and called this *"a second, independent argument for it"*. So the tally is now three distinct documents the jurist has been unable to read while design-gating work that turns on them: the chamber constitution, the skill files, and now a CapableMind methodology doc. **The workaround was built rather than proposed this time:** `dotfiles/claude/governance/check_containment.py`, positive controls mandatory, which discharged REVIEWED-85's stated precondition (7/7 contained, 5/5 controls absent) and caught a fabricated terminal period in the executor's own package. That is evidence option (b) is *workable*, not merely proposable — and it bears on the (a)/(b)/(c)/(d) choice, which remains the steward's.
## PENDING-87 — Order attestation: the REVIEWED-83 Q3 precondition is unsatisfiable as written
**Date:** 2026-07-29
**Tag:** [PROPOSAL]
@@ -676,3 +686,41 @@ Measured against the register itself before acting. Four corrections; the item's
**Why proposed and not applied.** Stroke 4's authorization covers compaction; it does not cover *this* method, and the change is not cosmetic — it restructures the surface that decides what reaches the steward. By this item's own test, that is PROPOSAL-class.
**It sharpens the recommendation rather than replacing it.** 177 proposals opened since 2026-05-24 against **one** full review (2026-07-19) is the actual cost driver. Compaction is hygiene on the symptom; the **FIX lane in (b)/(c) is the load-bearing half** — without it the register re-bloats, exactly as MEMORY.md re-bloated after the 2026-06-08 compress-in-place pass *"attacked the level not the class."* **Recommendation unchanged in substance, corrected in method: (c), plus (d) executed by split rather than by collapse.**
## PENDING-89 — The Q3 correlation review: are jurist and executor misses clustered?
**Date:** 2026-08-02
**Tag:** [HARDENING]
**Summary:** Run the falsifier the differently-biased-checkers doctrine names against the existing PENDING/REVIEWED record, rather than leaving it hypothetical.
**Rationale:** REVIEWED-86 left Q3 — *do two Claude instances constitute a check, or only a second reading?* — explicitly unresolved, and the doctrine text placed at Constraint 6 says in its own words that neither it nor its supporting evidence establishes the jurist–executor pair as a check in the strong sense. The package named the test that would settle it: whether jurist and executor errors cluster in the same classes while steward corrections catch a systematically different class. The jurist's ruling notes it is **checkable now**, on the rulings that exist, and should be docketed rather than float. If misses cluster, the doctrine is false for this configuration and must be weakened to *"only the steward supplies genuine independence; jurist review is a second reading, valuable and not a check."*
**Options:** (a) run it on the four most recent rulings only (REVIEWED-83 to -86) — fast, but n=4 and all from one arc; (b) run it across the full REVIEWED/PENDING record — larger n, but the older entries predate the current three-party discipline and may not be comparable; (c) run (a) now as a pilot with its own pre-registration, and use it to decide whether (b) is worth the cost.
**Recommendation:** (c). The same shape as the Fool trials and the 2025 archive read: pre-register what counts as a clustered miss *before* reading, or the executor grades its own errors after seeing them. Note the standing hazard — this is the executor measuring whether the executor is checked, which is the contaminated form; the grading criteria must be fixed in advance and the raw classifications left checkable.
**Files affected:** none yet; a measurement, not a change. Output would be a dated record beside the doctrine package.
**Awaiting:** Steward direction on (a)/(b)/(c), and on whether the executor is the right party to run a measurement of its own oversight at all — the jurist is no more independent here, so this may be steward-only work.
## PENDING-90 — First L2 transfer: checker position in the calibration loop
**Date:** 2026-08-02
**Tag:** [ESCALATE]
**Summary:** A candidate amendment carrying the differently-biased-checkers doctrine (Constraint 6) into the CapableMind spec corpus is drafted and awaiting steward authorization; it proposes an autonomy-ceiling rule, which is L2-constitutional.
**Rationale:** Five months of microcosm work has produced material for L2 and transferred none of it — `risk-manager-spec.md`, `personality-traits-spec.md` and `mindset-runtime-spec.md` were last touched 2026-03-08. This is the first transfer. It lands where CapableMind actually evaluates its own self-adjustment: the trust calibration loop. Censused finding — across `risk-manager-spec.md` v0.2 and `adaptation-chain-spec.md` v1.3, no field records who checked a decision or how that checker is positioned relative to the decider (grep terms: reviewer, reviewed_by, checked_by, approver, approved_by, independen*, second_opinion, adversarial; one unrelated hit). The base entry records `initiator` and `authorization` — who made the change and whether an operator granted it — but when `authorization.required` is false, which is the entire self-adjustment case, no checker is in the record at all.
**Why ESCALATE and not PROPOSAL:** Change 4 proposes that threshold *loosening* driven by a same-formation calibration be recorded but not applied — the system may observe that it judged itself well calibrated, but may not widen its own autonomy on that basis. That is an autonomy ceiling, i.e. constitutional, and per this file's own rule L2 constitutional changes escalate unconditionally. Checked first for an existing authorization covering the L2 transfer; there is none, so the boundary is real rather than manufactured.
**What was done:** the candidate amendment only, at `CapableMind-AI/docs/thinking/David/amendments/amendment-checker-position-calibration-loop.md`. Nothing under `docs/specs/` was touched. Per that repo's amendment-first discipline, amendments are candidates and the synthesis PR is the gated act.
**Verification:** all 21 quotations mechanically contained against source (Constraint 6, both specs, ADR-014), 9/9 positive controls absent, instrument verified. Three controls — `readonly accuracy_source`, `readonly calibration_source`, `CheckerPosition` — confirm the proposed fields are genuinely new rather than re-proposals. The census *negative* is grep-established, not containment-established; the instrument cannot verify an absence.
**Options:** (a) authorize as drafted, executor opens the synthesis PR once the owed Introspection API types are written; (b) authorize the direction but require the jurist design-gate it first, as with the doctrine itself; (c) hold — the doctrine is provisional and it may be premature to encode a provisional doctrine into a build-ready spec; (d) reject the autonomy-ceiling clause specifically and take the recording fields alone, which are non-constitutional.
**Recommendation:** (b). The doctrine reached Constraint 6 through a jurist design-gate, and this is its first load-bearing application; the same gate should govern the transfer. Note the standing limit the amendment itself carries: the doctrine may never be cited as assurance that anything was caught, so the fields make self-checks *legible* and nothing more. If the steward prefers speed over symmetry, (d) is the safe subset — the recording fields stand on their own and (a)-minus-Change-4 loses little.
**Open question the reviewer should press first:** who declares the position? If the calibrating party declares its own, that declaration is itself a self-report. The honest answer may be that position is derivable from `initiator` and the facet ID rather than declared — which would make it mechanical. Not settled in the draft.
**Files affected:** one new candidate file in `thinking/`; on authorization, `adaptation-chain-spec.md` §4.11/§4.12 and `risk-manager-spec.md` §6/§6.1/§9.
**Awaiting:** Steward authorization, and direction on (a)/(b)/(c)/(d).
## PENDING-91 — Vignette Phase 1a: jurist design gate (the dwell-test)
**Date:** 2026-08-02
**Tag:** [PROPOSAL]
**Summary:** The vignette renderer prototype is built and verified; its Phase-1 exit gate is a jurist dwell-test the spec makes mandatory, and the jurist structurally cannot perform it.
**Rationale:** A1 (the vignette) was ARC's largest open build — in spec since 2026-04-13, revised twice under jurist pass, and never built: 0 `.vignette` rules in the compiled CSS as of 2026-08-02, while `content/pages/vignette.md` is live and tells readers the vignette "is a generated object that opens each essay and meditation on this site." Phase 1a closes that gap far enough to be judged. It deliberately touches no protected surface — no `site.hs`, no SCSS partial, no template — so Phase 3 integration remains gated behind `operations.yaml` §1.
**Escalation grounds (both limbs, independently):** the spec's Appendix sends the *first* Phase-1 prototype to the jurist regardless of steward confidence; and its steady-state rule escalates whenever the steward's first-pass is "unsure or affirmative-with-reservation," which the 2026-08-02 first-pass was ("subtle, but good" / "could perhaps be a hair less subtle… but it is a slippery-slope").
**The structural problem the package leads with:** the dwell-test is assigned to the jurist, and the jurist has no repository access and cannot see the render. Whatever is ruled from the document alone is a ruling about the *described* vignette, not the *rendered* one. Third instance of a docketed gap — PENDING-86 (the jurist cannot read the constitution it design-gates) and PENDING-82 (read-only MCP server) are the first two, now recurring in visual form.
**Gate questions:** Q1 the contract is not implementable as written — `instances` is prose, and schema v1 is immutable/additive-only, so the shape ruled on is the shape ARC keeps (highest stakes; executor's lean held at low confidence). Q2 the field's mode mapping — the temperature/contrast split, the only construction found that satisfies both Layer 3 clauses, untested for correctness. Q3 what an interval renders as — executor's lean is weakest here and the opposite reading may be stronger. Q4 the two-cap reading of Layer 4, and whether an amplitude perceptible only after instruction satisfies the must-not clause (no lean on the second half; the executor distrusts the one it is disposed toward). Q5 how the dwell-test is to be performed at all.
**Options for Q5:** (a) steward carries rendered pages in as images — restores sight, at the cost of an unauditable frame selection; (b) jurist rules everything except the dwell-test, which is recorded as steward-performed with the mandatory clause noted unmet and why; (c) defer, blocking Phase 2.
**Recommendation:** (a), fallback (b), limitation recorded either way. What must not happen is a ruling that reads as though the dwell-test was performed when it was not — that is precisely the *unfelt error* the clause exists to catch, relocated from the steward to the gate.
**Verification:** 33/33 quotations in the package mechanically contained against source, 9/9 positive controls absent, instrument verified. Prototype checks: zero-JS gate 0, cycle-end clamp holds at three horizons and floors on a negative trajectory, monotonic over 800 sampled points, validator rejects 6/6 malformed genomes by name.
**Files affected:** `docs/AldineXXI-Codex/drafts/vignette-phase-1a-JURIST-PACKAGE-2026-08-02.md` (new); `tools/vignette-proto/` (built, committed `946b88b`/`1d40d4d`/`095be00`). No spec text changed, nothing integrated.
**Awaiting:** Steward relay to the jurist, and a decision on Q5 before the ruling is sought.
+15 -1
View File
@@ -896,4 +896,18 @@ brief. No work is blocked meanwhile; `wake-digest.py --brief` remains the fallba
- **New condition — bounded check-in, not asked for in the package.** After the first FIX-lane batch or one month, whichever comes first, steward and jurist review the FIX-lane index together before the lane is treated as settled rather than provisional. Per Constitutional Constraint's own decision heuristic (prefer reversible choices) — costs nothing if the classification holds.
- **Hard floor otherwise as proposed — AFFIRMED:** Constraint 1 (CLAUDE.md/REVIEWED.md/L2), authorization-boundary or gate-criteria changes, the escalate-unconditionally list, all untouched and all remain PROPOSAL/ESCALATE regardless of the test's answer.
**If AUTHORIZED:** Land the §1.6 edit (classification test + sharpened floor + dual-plus-index instrument) with a provenance comment in `/wrap-up` SKILL.md; no change to `~/CLAUDE.md`. Apply to today's four proposals (ledger section, KG predicate, wake line, reframed question) as the first FIX-lane batch, feeding the check-in review. Tag commits REVIEWED-85.
**Awaiting:** steward placement; mechanical verification of the §1.6/§2.a quotes; the bounded check-in once the first batch or one month has passed.
**Awaiting:** steward placement; mechanical verification of the §1.6/§2.a quotes; the bounded check-in once the first batch or one month has passed.
## REVIEWED-86 — Differently biased checkers, not unbiased ones (design-gate passed for DRAFTING ONLY — ESCALATE, application requires separate explicit steward authorization)
**Date:** 2026-08-02
**Decision:** AUTHORIZED to draft the Constraint 6 amendment for steward placement. NOT AUTHORIZED to apply — Constraint 1 and the escalate-unconditionally list both name this file; no ruling below the steward's own act of placing it changes that.
**Notes:**
- **Q1 — the gap is real — CONFIRMED**, independently checked against `~/CLAUDE.md` directly (Constraint 6 exact) and against the central-path file's own memory-index summary (substance and key phrases match).
- **Q2 — sound, ONE required correction.** Weld Part IV's "fail to coincide, not cancel" qualifier and its ban on citing the doctrine as assurance that something *was* caught into Part III's actual proposed text — not left as surrounding commentary. Not draft-ready without this.
- **Q3 — unresolved, and the doctrine's own landing must say so.** Jurist and executor share formation; whatever separates them is position, information, and incentive (category (i)), not formation (category (ii)) — the category Document B actually measured. The doctrine text should not be read, by its landing, as having validated the jurist-executor pair specifically. Recommend the correlation review the package itself names — clustered jurist/executor misses vs. a differently-clustered steward-correction pattern, run against the existing PENDING/REVIEWED record — be docketed as its own item rather than left hypothetical.
- **Document B — credited as pilot evidence for category (ii) only, not as a measured rate.** Pre-registration, corpus predating the doctrine, and the reproduced Appendix pair all independently checked out on inspection. Sample (3 comparable pairs, one author, unresolved persona confound even within the comparable set) is too narrow to quantify anything; Document B's own Part F.2/F.3 already say so and that scoping should be preserved verbatim in whatever cites it.
- **Q4 — sharpen to a retrieval obligation, fold into the existing check-in cadence** (REVIEWED-85), not a new standing review.
- **Q5 — Constraint 6 — AFFIRMED as the right location, steward's call on final placement.**
- **Process note, corrected.** The convergence was not two independent readers reaching the same idea from a shared root — the steward shared the jurist's exchange with him directly with the executor, as context, before Document A was filed. That is a tighter loop than parallel derivation: one party's language, relayed, feeding the other's proposal, which now returns to the first party for review. It does not bear on whether the underlying principle is sound — that turns on the separation-of-powers reasoning itself, not on who phrased it first — but it does mean the jurist should weigh, more carefully than usual, whether what reads as correct in Part III is the argument holding up rather than the jurist's own words returning familiar. Noted because it changes the standard the jurist should apply to itself here, not because it changes the ruling.
**If AUTHORIZED for drafting:** Land Part III (with the Q2 weld applied) beside Constraint 6, plus the companion `contamination-problem.md` note named as owed in Part V, amendment-first per that repo's own discipline. Docket the Q3 correlation review separately. Tag REVIEWED-86.
**Awaiting:** the Q2 weld, then steward review of the woven text; the Q3 note's exact wording; the correlation-review docket entry; and — the one that actually matters here — the steward's own explicit act of authorizing application, which nothing above substitutes for.
+53
View File
@@ -0,0 +1,53 @@
{
"sources": {
"claudemd": "/Users/davidglidden/dotfiles/CLAUDE.md"
},
"claims": [
[
"claudemd",
"Biases that fail to coincide do not cancel."
],
[
"claudemd",
"may therefore never be cited as assurance that something *was* caught"
],
[
"claudemd",
"the jurist and the executor do not differ from each other in formation, and their separation is of the weaker kind"
],
[
"claudemd",
"Neither this doctrine nor any evidence offered in support of it establishes that the jurist\u2013executor pair constitutes a check in the strong sense"
],
[
"claudemd",
"Status: provisional"
],
[
"claudemd",
"The executor agency directives are a partial mitigation, not a resolution"
]
],
"controls": [
[
"claudemd",
"Biases that fail to coincide cancel"
],
[
"claudemd",
"the jurist and the executor differ from each other in formation"
],
[
"claudemd",
"This doctrine may be cited as assurance"
],
[
"claudemd",
"Status: ratified"
],
[
"claudemd",
"Oversight requires a checker without bias"
]
]
}
+18
View File
@@ -14,6 +14,24 @@ Every run carries POSITIVE CONTROLS: near-miss strings that must be absent. If a
is found, the instrument is not discriminating and its passes mean nothing. An absence
is not evidence until the instrument is shown capable of detecting presence.
KNOWN LIMIT — THIS INSTRUMENT CANNOT VERIFY A NEGATION.
It tests whether an exact string is present. It has no notion of polarity. So a
sentence of the form "X does NOT hold" contains, as a literal substring, the
affirmative "X holds" — and any control built from that affirmative will leak by
construction, every time, no matter how correct the text is.
Hit twice within five minutes on 2026-08-02 while verifying the Constraint 6
placement: both attempts to control for "the doctrine must not claim the
jurist-executor pair IS a check" used substrings of the very sentence that denies
it. The instrument was right to refuse certification both times; the controls were
malformed.
Build controls by INVERSION, not by extraction — a string that would appear only if
the meaning were flipped ("the jurist and the executor differ from each other in
formation", dropping the "do not"), never a fragment lifted out of the sentence
under test. And where polarity is what matters, this instrument does not settle it:
read the sentence. Report that you read it, and that containment did not cover it.
USAGE
./check_containment.py manifest.json
@@ -0,0 +1,30 @@
# Constraint 6 — paste block for steward placement
**Target:** `~/dotfiles/CLAUDE.md` — append to the **end of the file**. Constraint 6 is currently line 249 of 249, so this follows it directly with one blank line between.
**Formatting note:** indented three spaces so the paragraphs continue list item 6 rather than breaking the numbered list. Preserve the indentation on paste.
**Steward's ruling on the open question:** option 1 — `Status: provisional` is retained. The honesty is worth the awkwardness, and Constraint 6 already carries a temporal qualifier (*"until L2 inquiry is formalized"*), so the section is not free of them.
---
## Paste exactly this (everything between the fences, including the leading blank line)
```
**Differently biased checkers, not unbiased ones.** Oversight does not require a checker without bias. It requires checkers whose biases do not point the same way. Separation of powers has never presupposed an unbiased branch; it presupposes branches positioned so that what one is disposed to miss, another is disposed to see. The contamination problem is therefore not a defect to be cured before the system can be trusted — it is the ordinary condition under which every oversight structure has ever operated, human or otherwise. This is the positive counterpart to the central path: that path says stop certifying the parties, bind the claims, and never audit the audit; this says why stopping is safe, because the work is caught by position rather than by purity.
Biases that fail to coincide do not cancel. Failing to coincide is weaker than cancelling, and it is all that is claimed: a configuration can satisfy "differently positioned" and still miss an entire class no party is positioned to see. This doctrine may therefore never be cited as assurance that something *was* caught. It is only ever the reason a structure is worth maintaining.
Three consequences bind. First, the three-party model is not a trust hierarchy: steward, jurist and executor are not ordered by reliability, with a clean human checking a suspect machine, but differently positioned readers — different information, different role, different exposure — and a correction may run in any direction. Second, independence is a property to be engineered, not assumed. Difference of formation is the strong form; difference of role, information and incentive is the weak form. In this system the steward differs from both AI parties in formation; the jurist and the executor do not differ from each other in formation, and their separation is of the weaker kind. Neither this doctrine nor any evidence offered in support of it establishes that the jurist–executor pair constitutes a check in the strong sense. Third, the doctrine is falsifiable and must be watched: if the parties' misses are found to correlate — if what one misses, the others reliably miss too — it is false for that configuration, and no amount of procedural care substitutes. Evidence against is to be recorded when observed, not only when sought.
*Status: provisional. Held until the thought is more refined, and revisable on evidence. Proposed by the executor, design-gated by the jurist 2026-08-02 with two required conditions (REVIEWED-86), placed by the steward.*
```
---
## After placing
Nothing else in `~/CLAUDE.md` changes. Constraint 6's two original clauses are untouched — the caution is refined, not relaxed, and the L2 deferral stands.
Tell the executor once placed; it will verify the file parses as a list, confirm the two ratified clauses are byte-identical to their pre-amendment form, and tag the companion work REVIEWED-86.
@@ -0,0 +1,84 @@
# Constraint 6 amendment — DRAFT for steward placement
**Status: DRAFT. NOT APPLIED. `~/CLAUDE.md` is untouched.**
Authority: PENDING-88's sibling ESCALATE package → jurist design gate 2026-08-02 → **REVIEWED-86, placed by the steward 2026-08-02**, which authorizes **drafting only**. Application requires a separate, explicit steward act. Constraint 1 and the escalate-unconditionally list both name `~/CLAUDE.md`; nothing short of the steward's own edit changes that.
---
## 1. The ratified text as it stands (verbatim, `~/CLAUDE.md:249`)
> 6. **Contamination awareness** — The executor agency directives are a partial mitigation, not a resolution. Treat outputs about the system's own reliability with appropriate epistemic caution until L2 inquiry is formalized
## 2. What is proposed
**Constraint 6 is not replaced.** Both its clauses survive verbatim; the caution is not relaxed, and the deferral of the L2 inquiry stands. The amendment adds a second paragraph stating what the mitigation *is* — the account Constraint 6 currently omits.
---
## 3. The proposed addition, with both required conditions welded in
*(Draft text. The two marked paragraphs exist because the jurist made them conditions, not suggestions.)*
```
**Differently biased checkers, not unbiased ones.** Oversight does not require a checker
without bias. It requires checkers whose biases do not point the same way. Separation of
powers has never presupposed an unbiased branch; it presupposes branches positioned so
that what one is disposed to miss, another is disposed to see. The contamination problem
is therefore not a defect to be cured before the system can be trusted — it is the
ordinary condition under which every oversight structure has ever operated, human or
otherwise. This is the positive counterpart to the central path: that path says stop
certifying the parties, bind the claims, and never audit the audit; this says why
stopping is safe, because the work is caught by position rather than by purity.
Biases that fail to coincide do not cancel. Failing to coincide is weaker than
cancelling, and it is all that is claimed: a configuration can satisfy "differently
positioned" and still miss an entire class no party is positioned to see. This doctrine
may therefore never be cited as assurance that something WAS caught. It is only ever the
reason a structure is worth maintaining.
Three consequences bind. First, the three-party model is not a trust hierarchy: steward,
jurist and executor are not ordered by reliability, with a clean human checking a suspect
machine, but differently positioned readers — different information, different role,
different exposure — and a correction may run in any direction. Second, independence is a
property to be engineered, not assumed. Difference of formation is the strong form;
difference of role, information and incentive is the weak form. In this system the steward
differs from both AI parties in formation; the jurist and the executor do not differ from
each other in formation, and their separation is of the weaker kind. Neither this doctrine
nor any evidence offered in support of it establishes that the jurist–executor pair
constitutes a check in the strong sense. Third, the doctrine is falsifiable and must be
watched: if the parties' misses are found to correlate — if what one misses, the others
reliably miss too — it is false for that configuration, and no amount of procedural care
substitutes. Evidence against is to be recorded when observed, not only when sought.
Status: provisional. Held until the thought is more refined, and revisable on evidence.
```
---
## 4. What changed from the text the jurist read, and why
| Condition | Where it landed | What it prevents |
|---|---|---|
| **Q2 weld** — *fail to coincide, not cancel*; never cite as assurance something *was* caught | Its own paragraph, second, immediately after the doctrine's statement | A future reader citing the doctrine cites the doctrine block, not the surrounding commentary. In the package this qualifier lived in Part IV, which would not have landed. The dangerous misreading — *biases cancel, so the system is safe* — is now refused inside the text a citer quotes. |
| **Q3 framing** — the jurist and executor share formation | Consequence 2, stated as a fact about this system rather than as a caveat | The doctrine's landing being read as having validated the jurist–executor pair, when the evidence offered measures two differently-*formed* models and says nothing about that pair. The clause is deliberately self-limiting: it names the configuration that produced the doctrine as the one the doctrine does not vouch for. |
**Not changed:** the three consequences' substance, the provisional status, or Constraint 6's own two clauses. The proposal refines Constraint 6; it does not relax it.
---
## 5. Owed, and deliberately not drafted here
- **Q4 — the retrieval obligation.** The jurist directed it be folded into the **existing** REVIEWED-85 check-in rather than given a standalone cadence, on the grounds that a new standing review is exactly the shape of thing that produces another unread register. It is therefore not doctrine text and does not belong in this amendment. Owed: an agenda line on the REVIEWED-85 check-in.
- **The `contamination-problem.md` companion note** (named as owed in the package's Part V). That repo's discipline is amendment-first, so it is named here, not drafted.
- **The Q3 correlation review**, docketed separately per the ruling.
---
## 6. The honest limit on this draft
The jurist recorded, unprompted, that it had used closely similar language to the proposal's opening formulation earlier the same day, before reading the package — and declined to treat the convergence as independent corroboration, judging one source (the steward) likelier to have reached both readers separately.
That disclosure belongs with the draft rather than only with the ruling. **The agreement between jurist and executor on this doctrine is not evidence for it.** It is, if anything, an instance of exactly what consequence 2 warns about: two readers of shared formation, reached by a common source, arriving at the same place. The doctrine survives on the argument in Part II and the pilot evidence in Document B — which covers a different pair — not on the fact that both AI parties find it persuasive.
**Resolved 2026-08-02, steward-confirmed.** The jurist inferred a common source; the steward confirmed the mechanism directly — he had shared the jurist exchange as *context only*, with explicit instructions that it sat outside the ruling then being settled. So the transmission is documented and its direction is known: Document A was filed 2026-08-01, **before** that exchange, so the jurist's language cannot have shaped the proposal. The convergence is neither contamination nor corroboration — it is one source reaching two readers, exactly as the jurist reasoned without being able to check it. Recorded here because a disclosure whose cause is later established should carry the resolution, not stay an open suspicion; and because the jurist's caution was correct *before* the confirmation, which is the part worth keeping.
@@ -0,0 +1,45 @@
# Jurist ruling — differently biased checkers (design gate, 2026-08-02)
*Filed verbatim as received, steward-relayed. Not edited, not summarised. The REVIEWED-86 block below is the jurist's draft for steward placement; it is **not placed** at the time of filing.*
---
Before anything else, so there's no ambiguity: nothing below authorizes application. This touches `~/CLAUDE.md` directly, which sits on both Constraint 1 and the escalate-unconditionally list. The most this ruling can do — per the taxonomy, and per the package's own correct reading of it — is authorize *drafting* the amendment text for you to place or not. That ceiling doesn't move regardless of how the substance below lands.
**Verification.** Constraint 6 and the Executor Agency clause, quoted in Part I, I checked directly against `~/CLAUDE.md` two turns ago and they're exact — no new read needed, no drift. The central-path quote (the 2026-07-29 "irresolvable... never audit the audit" material) I can't read at its source, but I pulled the memory index, and its own independently-written one-line summary of that file uses the same load-bearing phrases — "human bias is the other half," "auditing the audit never converges," "one layer of disclosure, then act — never audit the audit" — which is real corroboration, a second document agreeing, not the same document read twice. `contamination-problem.md` (Core Problem, Partial Mitigations, Epistemic Ceiling) I still can't reach at all — same gap as the skill files last time, now touching the part of the argument that establishes the doctrine actually has a gap to fill. Worth closing at some point; PENDING-86 is still open and this is a second, independent argument for it.
**Something I want on the record before I rule on the substance.** The opening formulation in Part III — "oversight does not require a checker without bias, it requires checkers whose biases don't point the same way," explicitly reaching for separation of powers — is close enough to what I said to you, unprompted, before I'd seen this document, that I don't think I should evaluate it as if encountering it fresh. Document A was filed 2026-08-01, at your request, before that exchange. The likeliest explanation isn't that the executor drew on me or I on it — it's that you'd been carrying this thought and gave it to both of us close together. That matters for how much the convergence should count: two conclusions from one root don't corroborate each other the way two independent derivations would, and I'd be doing exactly the thing Part VII warns about if I let the fact that it sounds right to me stand in for having checked it.
**Q1 — the gap is real.** Constraint 6, on my own direct read, states caution and states nothing else. The central path, per the corroborated summary, is stopping rules without a stated reason stopping is safe. Demonstrated, not just asserted.
**Q2 — sound in substance, one correction required before this is draft-ready.** The core claim is standard, well-tested institutional design — segregation of duties, adversarial review, replication by separate labs — being named for this system, not invented. But Part III's actual proposed *text* doesn't yet carry the qualifier Part IV argues is load-bearing: that differently-positioned biases *fail to coincide* rather than *cancel*, and that the doctrine must never be cited as assurance something *was* caught, only as the reason a structure is worth maintaining. Right now that qualifier lives in the surrounding discussion, not in the block that would actually land in `~/CLAUDE.md`. A future reader — executor or otherwise — citing the doctrine will cite Part III, not Part IV's commentary on it. Weld the qualifier into the text itself before this goes to you for placement. The executor's own Q2 lean already says as much; I'm making it a condition rather than a suggestion.
**Q3 — genuinely open, and I'll give you more than a punt without pretending to settle it.** I'm not differently-formed from the executor. Whatever separates us is role, information access, and — probably the most real thing — that I don't carry the accumulated context and momentum of the session that built the proposal, and I have no stake in what my own future operating constraints will be, which the executor's proposals sometimes do. That's category (i) independence — position and incentive, not formation — and the package is right that only (ii) is independence in the strong sense. So: jurist review is worth having, and it isn't nothing, but it isn't the check Document B measured either, and the doctrine's text should say so plainly rather than let its landing be read as having validated the jurist-executor pair by association with evidence that doesn't cover it. I'd add one concrete thing to the record: the falsifier the package names — reviewing the accumulated PENDING/REVIEWED history for clustered jurist/executor misses against a differently-clustered steward correction pattern — is checkable *right now*, on the four rulings that exist. It shouldn't stay hypothetical. Worth its own docket entry rather than floating.
**Document B, on its own merits.** Well-built pilot evidence: pre-registered exclusions before reading, a corpus that predates the doctrine by a year and wasn't selected by the interested party, and the one reproduced pair holds up under my own inspection — rows 6 through 11 of that table are genuinely non-overlapping, and row 6 is a real disagreement, not a stylistic variant. I'd credit it as real. I would not credit it as a *rate*. Three comparable pairs, one author, one genre, and even within the "comparable" set the two models carried unequal persona instructions that were filtered from the count but can't be fully filtered from what claims a persona-shaped voice is disposed to make — Document B names this itself (Part F.2, "causes remain bundled") and doesn't oversell past it, which is to its credit. Treat it as: consistent with the doctrine, insufficient to quantify it, correctly scoped by its own authors to say nothing about Q3.
**Q4 — sharpen toward retrieval, and don't give it a standalone cadence.** The eighteen-month gap between the observation being recorded (2025-01-20, in the right words) and it reaching doctrine is a sharp, well-evidenced point, and the diagnosis is right: recording wasn't the failure, retrieval was. Fold the retrieval obligation into the same check-in I already required in REVIEWED-85 rather than creating a second standing review nobody has bandwidth for — a new obligation to periodically re-read old evidence is exactly the shape of thing that produces another unread register if it isn't attached to a cadence that already exists.
**Q5 — Constraint 6.** Agreed, and it's the steward's call regardless.
Design-gate passed for drafting only, with the Q2 weld required and the Q3 framing note required. Ready to paste, understanding that placement itself is the authorization step, not this ruling:
```markdown
## REVIEWED-86 — Differently biased checkers, not unbiased ones (design-gate passed for DRAFTING ONLY — ESCALATE, application requires separate explicit steward authorization)
**Date:** 2026-08-02
**Decision:** AUTHORIZED to draft the Constraint 6 amendment for steward placement. NOT AUTHORIZED to apply — Constraint 1 and the escalate-unconditionally list both name this file; no ruling below the steward's own act of placing it changes that.
**Notes:**
- **Q1 — the gap is real — CONFIRMED**, independently checked against `~/CLAUDE.md` directly (Constraint 6 exact) and against the central-path file's own memory-index summary (substance and key phrases match).
- **Q2 — sound, ONE required correction.** Weld Part IV's "fail to coincide, not cancel" qualifier and its ban on citing the doctrine as assurance that something *was* caught into Part III's actual proposed text — not left as surrounding commentary. Not draft-ready without this.
- **Q3 — unresolved, and the doctrine's own landing must say so.** Jurist and executor share formation; whatever separates them is position, information, and incentive (category (i)), not formation (category (ii)) — the category Document B actually measured. The doctrine text should not be read, by its landing, as having validated the jurist-executor pair specifically. Recommend the correlation review the package itself names — clustered jurist/executor misses vs. a differently-clustered steward-correction pattern, run against the existing PENDING/REVIEWED record — be docketed as its own item rather than left hypothetical.
- **Document B — credited as pilot evidence for category (ii) only, not as a measured rate.** Pre-registration, corpus predating the doctrine, and the reproduced Appendix pair all independently checked out on inspection. Sample (3 comparable pairs, one author, unresolved persona confound even within the comparable set) is too narrow to quantify anything; Document B's own Part F.2/F.3 already say so and that scoping should be preserved verbatim in whatever cites it.
- **Q4 — sharpen to a retrieval obligation, fold into the existing check-in cadence** (REVIEWED-85), not a new standing review.
- **Q5 — Constraint 6 — AFFIRMED as the right location, steward's call on final placement.**
- **Process note, disclosed rather than absorbed:** the proposal's opening formulation and language I used independently, unprompted, earlier the same day are close enough that I don't treat the convergence as two independent corroborations — likelier one source (the steward) reaching both readers separately. Noted so it isn't mistaken for evidence the doctrine doesn't have.
**If AUTHORIZED for drafting:** Land Part III (with the Q2 weld applied) beside Constraint 6, plus the companion `contamination-problem.md` note named as owed in Part V, amendment-first per that repo's own discipline. Docket the Q3 correlation review separately. Tag REVIEWED-86.
**Awaiting:** the Q2 weld, then steward review of the woven text; the Q3 note's exact wording; the correlation-review docket entry; and — the one that actually matters here — the steward's own explicit act of authorizing application, which nothing above substitutes for.
```
---
*Received and filed by the executor 2026-08-02. Nothing applied. `~/CLAUDE.md` untouched.*
@@ -0,0 +1,22 @@
{
"sources": {
"wrap": "/Users/davidglidden/.claude/skills/wrap-up/SKILL.md",
"wake": "/Users/davidglidden/.claude/skills/wake-up/SKILL.md"
},
"claims": [
["wrap", "This is **event-based, not change-count**"],
["wrap", "apply at wrap like a tracker"],
["wrap", "is surfaced for steward review, not auto-applied"],
["wrap", "the same FIX-vs-PROPOSAL split, one level up"],
["wrap", "Surface each as a proposal in §8 — never create, patch, or retire a skill autonomously at wrap."],
["wrap", "The steward converts proposal to action; only then is a skill changed"],
["wake", "Read `skill-harvest-register.md` directly — the canonical surface for open skill proposals (wrap §1.6 appends there); surface any awaiting steward authorization"]
],
"controls": [
["wrap", "never create, patch, or retire a skill autonomously at wake"],
["wrap", "apply at wrap like a ledger"],
["wrap", "the same HARDENING-vs-PROPOSAL split, one level up"],
["wake", "surface any awaiting jurist authorization"],
["wake", "the canonical surface for closed skill proposals"]
]
}
+3 -1
View File
@@ -5,13 +5,15 @@ metadata:
node_type: memory
type: reference
originSessionId: d1e67361-d1b9-4dac-a0c4-e7a0e26211c4
modified: 2026-07-27T20:10:02.871Z
modified: 2026-08-02T14:29:02.613Z
---
# MEMORY — Reference layer (consult on demand)
## Relocated from MEMORY.md at the 2026-07-19 evening budget trim (verbatim; wake-value judged low — MemPalace-era mechanics + reactive-mode ARC specifics)
- [Session 2026-08-02 — the archive answered, and Constraint 6 moved](session-2026-08-02-the-archive-answered-and-constraint-6-moved.md) — the **v1 Chamber archive** supplied the matched-capability arm the Fool trials cannot: **mutual divergence 3 of 3** comparable pairs + a **self-exemption** the steward had named in a **2025-01-20** guide. Jurist passed the doctrine for **drafting only**; **steward placed it at Constraint 6** — the constitution now states the **jurist–executor pair is not a check in the strong sense**. **REVIEWED-85 FIX lane + batch 1** landed; `wake-digest` ID bug fixed (**PENDING-78/-81/-82 reappeared**). Five corrections, four steward-handed, **all census failures — formation diversity buys reading, not scope**. *(Demoted on promote at the 2026-08-02 pm wrap.)*
- [Session 2026-08-01 — the Fool, and the boundary I manufactured](session-2026-08-01-the-fool-and-the-manufactured-boundary.md) — closed the reset thread (PENDING-85 eyeballed → **Arcades verdict WRONG**, a ClearScan scan; PENDING-84 triaged via the **§VII quarantine lane**, *dispositioned not repaired*), then found the stuckness was largely mine: **three of the day's biggest closures were ALREADY authorized** — register split (166K→44K, 177 open readable), ladder Stroke 2 (21→**71 instruments**), classifier fix — and once I justified inaction by invoking **PENDING-88's own unratified rule**. Landed **spec v2.9.1** (0-of-17→0-of-14; the prior figure is **irreproducible**, recorded in the constitution). **REVIEWED-85 ruled, NOT placed.** ESCALATE doctrine package filed (*differently biased checkers*). **Derrida: the independent witness WORKS** — ocrmac recovered what olmOCR silently dropped (5,590 words / 152 spans, invisible to every wired gate). **PULLING THREAD: stabilize the Fool method** (Qwen 3.6 35B on the M4, 2 trials, protocol unstable) — and **v1 Chamber's paired GPT/Claude raw outputs survive in ARC**, a ready-made dataset. Detail in the session file.
- [MemPalace KG object 128-char cap](feedback-mempalace-kg-object-128-char-cap.md) — `kg_add` `object` hard-caps at 128 chars; write KG objects as short keyword phrases on the FIRST pass, detail goes in the drawer. Recurs at every /wrap-up §5 — stop re-deriving it. *(Relocation note: palace-memory wound down 2026-07-07; wrap §5 now appends JSONL — the cap now matters only for typography-palace kg_adds, which are rare.)*
- [MemPalace wing-filter broken](feedback-mempalace-wing-filter-broken.md) — wing-scoped search → 'Error finding id' (upstream #1665, open at HEAD); search UNSCOPED + post-filter by wing. Don't run `repair` (#1589). Affects wake-up §2.b.3. *(Relocation note: §2.b.3 was rewired to the files layer 2026-07-07; relevant only to the typography palace CLI now.)*
- [Verify each post type after changes](feedback-verify-each-post-type-after-changes.md) — ARC: after any shared CSS/template/composition change, check EVERY content type on BOTH desktop and phone, not a sample on one viewport. Lesson from §II.d gate verified phone-only → desktop appearance surfaced 2 sessions late (no regression; just unseen). Per-type×per-viewport extension of [[trust-prior-pass-frame]]; belongs in the SCSS verification ladder.
+2 -2
View File
@@ -6,7 +6,7 @@ metadata:
type: note
permalink: claude-memory/memory
originSessionId: 22915403-bc5d-4796-9c7d-196b7c30d2f9
modified: 2026-07-27T20:11:41.672Z
modified: 2026-08-02T14:28:37.777Z
permalink: claude-memory/memory
---
@@ -65,7 +65,7 @@ permalink: claude-memory/memory
- [Be (laundromat)](project-be-laundromat.md) — canonical Be tracker (est. 2026-06-08). Be = Skemantix startup (Seb+David) funding CapableMind's ladder; **bridge, not venture**. Decisions LOCKED (entity/pricing/infra in file); a11y gate MERGED. **Pre-revenue WTP gate = renovate Pat → charge her; discipline: no new spec until it clears → nothing for executor on be.** Repo @ `f43a0fd`.
## Active Session
- [Session 2026-08-01 — the Fool, and the boundary I manufactured](session-2026-08-01-the-fool-and-the-manufactured-boundary.md) — closed the reset thread (PENDING-85 eyeballed → **Arcades verdict WRONG**, a ClearScan scan; PENDING-84 triaged via the **§VII quarantine lane**, *dispositioned not repaired*), then found the stuckness was largely mine: **three of the day's biggest closures were ALREADY authorized** — register split (166K→44K, 177 open readable), ladder Stroke 2 (21→**71 instruments**), classifier fix — and once I justified inaction by invoking **PENDING-88's own unratified rule**. Landed **spec v2.9.1** (0-of-17→0-of-14; the prior figure is **irreproducible**, recorded in the constitution). **REVIEWED-85 ruled, NOT placed.** ESCALATE doctrine package filed (*differently biased checkers*). **Derrida: the independent witness WORKS** — ocrmac recovered what olmOCR silently dropped (5,590 words / 152 spans, invisible to every wired gate). **PULLING THREAD: stabilize the Fool method** (Qwen 3.6 35B on the M4, 2 trials, protocol unstable) — and **v1 Chamber's paired GPT/Claude raw outputs survive in ARC**, a ready-made dataset. Detail in the session file.
- [Session 2026-08-02 pm — the transfer landed, and the vignette was a diagram](session-2026-08-02-pm-the-transfer-landed-and-the-vignette-was-a-diagram.md) — **PENDING-90**: the first L2 transfer, carrying Constraint 6 into CapableMind's calibration loop (AdaptationChain records who *initiated* an adaptation, never who *checked* it; `authorization.required:false` = the whole self-adjustment case, no checker in the record). **#176 reply posted.** Then ARC: the **vignette built from zero** (Phase 1a, `tools/vignette-proto/`, no protected surface touched) + **PENDING-91** jurist package. **Every substantive defect was found by rendering and looking, none by the mechanical checks — all of which passed.** Steward's **Notre-Dame** anchor reframed it: the render is a *diagram* where the spec intends *inscription*; **meaning lives in the syntax, not the lexicon**. Yield = a **nine-item census** of where the spec under-determines the render. **PULLING THREAD: Trial 03** — the Fool's false-positive control, unblocked now the M4 is reachable.
## Historical reference → MEMORY-reference.md
Older archived-session pointers and the stable reference layer (steward profile · project-state detail · L1/L2/Chamber inventories · legacy pending-work · reference-file list) live in [MEMORY-reference.md](MEMORY-reference.md) — consult on demand; not loaded at wake. Recent cross-session trajectory comes from the Active Session entry above + the recent `session-*.md` files (wake §2.b.1; the MemPalace `handoffs` glance was retired 2026-07-07 with the wind-down).
+13
View File
@@ -514,3 +514,16 @@
{"subject": "claude-code", "predicate": "uses-instrument", "object": "the-Fool — mlx-community/Qwen3.6-35B-A3B-8bit resident on CapableHands M4 (35GB, MLX 0.31.2), run as a differently-FORMED checker over already-ruled jurist packages with the ruling withheld. 2 trials: 4 real findings, 2/2 missed the jurist's central inference-level catch. Protocol + correlation record: dotfiles/claude/governance/fool-trial-log.md. HAZARD: many top MLX Qwen builds are Claude hybrids (Huihui-...-Claude-4.7-Opus-abliterated) — selecting one silently reintroduces Claude formation.", "valid_from": "2026-08-02", "valid_to": null, "confidence": 1.0, "source_file": "session-2026-08-01-the-fool-and-the-manufactured-boundary.md", "extracted_at": "2026-08-02"}
{"subject": "v1-chamber", "predicate": "evidence-for", "object": "differently-formed-checkers — the v1 Chamber (2025) ran the SAME submitted text through GPT and Claude and preserved BOTH raw outputs unmerged, per protocol (first-light/standard/shadow), across ~6 sessions. Archive intact at ~/_Dev/animal-davidglidden-eu/chamber-sessions-private/ (55 files) + chamber/ (44, hermetic-charter credits 'GPT-4o | Lyrical-Symbolic Mode'). The steward held this intuition IN THE V1 DESIGN, predating the 2026 contamination doctrine. CAVEAT: v1 is GENERATION diversity, the Fool is CHECKING diversity — the archive answers 'is two-formation divergence substantive or stylistic', not the correlation-of-misses question.", "valid_from": "2026-08-02", "valid_to": null, "confidence": 1.0, "source_file": "session-2026-08-01-the-fool-and-the-manufactured-boundary.md", "extracted_at": "2026-08-02"}
{"subject": "chamber-library-specification", "predicate": "version", "object": "v2.9.1 OPERATIVE (2026-08-01, REVIEWED-83 A1) — PATCH correcting the measured two-column exposure from '0 of 17' to '0 of 14'; the prior figure is NOT REPRODUCIBLE (same folder, same classifier, now yields 16; no per-file record of the seventeen survives) and that is recorded in the constitution's own header. v2.9.0 frozen.", "valid_from": "2026-08-02", "valid_to": null, "confidence": 1.0, "source_file": "session-2026-08-01-the-fool-and-the-manufactured-boundary.md", "extracted_at": "2026-08-02"}
{"subject": "claude-code", "predicate": "drift-pattern", "object": "BOUNDED-SEARCH-STATED-AS-SETTLED-CONCLUSION \u2014 five times in one session I searched N places and reported the result without its bound: 'the v1 GPT prompt is permanently unrecoverable' (it was in 99. Archives\u2014Previous Iterations); 'the M4 is down' \u00d73 (this machine is on 192.168.1.x, the M4 on 10.0.1.x \u2014 different subnet, self-caught); a date called fabricated without checking it had a source. FOUR of the five were caught by the steward, not by me. All CENSUS failures, none reading failures. The verification ladder ALREADY carries 'censused routes vs seen routes' \u2014 the instrument existed and did not fire. RULE: a negative result carries the routes searched, or it is not a result.", "valid_from": "2026-08-02", "valid_to": null, "confidence": 1.0, "source_file": "session-2026-08-02-the-archive-answered-and-constraint-6-moved.md", "extracted_at": "2026-08-02"}
{"subject": "claude-code", "predicate": "drift-pattern", "object": "CONTROL-BUILT-BY-EXTRACTION-LEAKS-BY-CONSTRUCTION \u2014 twice in five minutes, verifying the Constraint 6 placement, I built positive controls for a NEGATION by lifting the affirmative phrase out of the sentence that denies it. 'establishes that the pair constitutes a check' is a literal substring of 'Neither this doctrine nor any evidence ... establishes that the pair constitutes a check'. It must leak, always. Substring containment has NO notion of polarity and cannot verify a negation. RULE: build controls by INVERSION, never by extraction; where polarity is the claim, read it and report that containment did not cover it.", "valid_from": "2026-08-02", "valid_to": null, "confidence": 1.0, "source_file": "session-2026-08-02-the-archive-answered-and-constraint-6-moved.md", "extracted_at": "2026-08-02"}
{"subject": "containment-checker-built-for-quotation-fidelity", "predicate": "prevention", "object": "Discharged REVIEWED-85's authorization precondition \u2014 a DIFFERENT failure class from the one it was built for. Built 2026-08-02 ~11:00 to verify quotes in a jurist package (where it caught a fabricated terminal period inside a blockquote, read past twice). Hours later the ruling required mechanical containment of /wrap-up \u00a71.6 and /wake-up \u00a72.a quotes the jurist could not read: 7/7 contained, 5/5 controls absent. Without it REVIEWED-85 lands with an undischarged condition. Transfer from quotation-fidelity to authorization-precondition.", "valid_from": "2026-08-02", "valid_to": null, "confidence": 1.0, "source_file": "session-2026-08-02-the-archive-answered-and-constraint-6-moved.md", "extracted_at": "2026-08-02"}
{"subject": "wake-substrate-check-rule", "predicate": "prevention", "object": "Caught at 10:44 that REVIEWED-85 was already placed (10:41), three minutes after a wrap naming it the sole blocker. The rule \u2014 a disposition clause is not a status; check the substrate before listing an authorized item as unbuilt \u2014 prevented reporting an authorized item as blocked for a second consecutive day.", "valid_from": "2026-08-02", "valid_to": null, "confidence": 1.0, "source_file": "session-2026-08-02-the-archive-answered-and-constraint-6-moved.md", "extracted_at": "2026-08-02"}
{"subject": "pre-registering-grading-before-reading", "predicate": "prevention", "object": "Caught that 'reference' was the wrong term in the archive divergence criterion BEFORE any output was opened. The v1 protocols mandate invented bibliography (a deliberate Borges/Eco device); counting citations would have compared two fiction generators and inflated divergence enormously, making the doctrine look strong for a bogus reason.", "valid_from": "2026-08-02", "valid_to": null, "confidence": 1.0, "source_file": "session-2026-08-02-the-archive-answered-and-constraint-6-moved.md", "extracted_at": "2026-08-02"}
{"subject": "claude-code", "predicate": "drift-pattern-good-direction", "object": "THE-ARCHIVE-SUPPLIED-THE-ARM-THE-TRIALS-CANNOT \u2014 v1 Chamber (2025) paired two frontier models of matched capability, so their mutual divergence CANNOT be a capability-gap artifact. The Fool trials run at a large capability gap where divergence has that alternative explanation. Two arms, same result: formation difference alone suffices. Evidence predating the doctrine by a year, steward-designated rather than executor-selected.", "valid_from": "2026-08-02", "valid_to": null, "confidence": 1.0, "source_file": "session-2026-08-02-the-archive-answered-and-constraint-6-moved.md", "extracted_at": "2026-08-02"}
{"subject": "capablemind-l2", "predicate": "transfer-gap", "object": "Five months of chamber/studium work has produced L2-shaped material and transferred NONE of it. Checkable 2026-08-02: risk-manager-spec.md, personality-traits-spec.md, mindset-runtime-spec.md all last touched 2026-03-08; no amendments/ directory exists in thinking/David/, which is that repo's own first phase for spec change. Lead transfer candidate: differently-biased-checkers (ratified at Constraint 6) \u2192 risk-manager-spec.md v0.2 'buildout needed'. The unasked question: when L2 evaluates its own constitutional self-adjustment, what checks it?", "valid_from": "2026-08-02", "valid_to": null, "confidence": 1.0, "source_file": "session-2026-08-02-the-archive-answered-and-constraint-6-moved.md", "extracted_at": "2026-08-02"}
{"subject": "claude-code", "predicate": "drift-pattern", "object": "MECHANICAL-CHECK-CERTIFIES-THE-CODE-WHILE-CLAIMING-THE-RESULT — every substantive vignette defect was caught by rendering the artifact and looking, none by the checks, and all the checks passed. The field colour was bound to a class no element carried (Layer 3's whole mode mapping would have inherited the panel's ink and looked correct); a hand-rolled palette violated §III's sacred-palette clause and collapsed dark-mode contrast; interval clearings read as smudges. The jurist package I wrote asserted a trace table of 'honoured' verdicts — it was checking the code against MY READING of the spec, not against the spec.", "valid_from": "2026-08-02", "valid_to": null, "confidence": 1.0, "source_file": "session-2026-08-02-pm-the-transfer-landed-and-the-vignette-was-a-diagram.md", "extracted_at": "2026-08-02"}
{"subject": "claude-code", "predicate": "drift-pattern", "object": "APPLYING-A-DOCTRINE-WHERE-IT-DOES-NOT-GOVERN — asked whether to send the vignette spec to Fable, I reached for Constraint 6's independence framing (weak vs strong form) and attached a caveat about not treating agreement as corroboration. Steward corrected: it is a DESIGN task, not a checking task, so independence does not arise and the caveat was empty — a design proposal is an artifact you judge by looking, not a claim needing corroboration. The maxim going decorative, which ~/CLAUDE.md explicitly asks me to flag.", "valid_from": "2026-08-02", "valid_to": null, "confidence": 1.0, "source_file": "session-2026-08-02-pm-the-transfer-landed-and-the-vignette-was-a-diagram.md", "extracted_at": "2026-08-02"}
{"subject": "the wake's substrate-check rule (a disposition clause is not a status)", "predicate": "prevention", "object": "Caught the inherited pulling thread's own checkable claim being half false — the morning wrap asserted 'there is no amendments/ directory in thinking/David/' and there is: 14 files, last touched 2026-06-13. Cost avoided: opening the L2 transfer by CREATING a directory that exists, ignoring eight weeks of precedent and its naming convention, and telling the steward his repo lacks a phase it has been using. Notable because the census instrument failed five times the previous day when banked as a LESSON, and fired here when written into a PROCEDURE (the wake's §3 substrate-check step).", "valid_from": "2026-08-02", "valid_to": null, "confidence": 1.0, "source_file": "session-2026-08-02-pm-the-transfer-landed-and-the-vignette-was-a-diagram.md", "extracted_at": "2026-08-02"}
{"subject": "absence-of-a-check-must-not-be-representable-as-the-safe-case", "predicate": "prevention", "object": "Found at three layers in one day and transferred forward at each: a shell pipeline returning 0 for 'could not look' (suppressed stderr made a missing git ref and a genuine sync identical); BackupOrchestrator.countUnprotectedEntries returning 0 for 'never backed up' (betterMemories_app#176); and then written INTO the L2 amendment as CheckerPosition's 'unknown' default, which must never be 'observed'. The L1 bug became the worked instance the L2 proposal cites.", "valid_from": "2026-08-02", "valid_to": null, "confidence": 1.0, "source_file": "session-2026-08-02-pm-the-transfer-landed-and-the-vignette-was-a-diagram.md", "extracted_at": "2026-08-02"}
{"subject": "arc-vignette", "predicate": "governing-anchor", "object": "The facade of Notre-Dame de Paris (steward, 2026-08-02): for the unlettered it gave the knowledge they could not YET read, WITHOUT interpretation. A biblia pauperum delivers structure without proposition — no caption names a figure, yet order, rank, centrality and seriousness arrive. Resolves how the vignette gives symbolic territory while protecting the reader from interpretation: MEANING LIVES IN THE SYNTAX, NOT THE LEXICON. Marks stay undecodable; the arrangement is grammatical. A diagram invites decoding; asemic writing refuses it while remaining inscribed. NOT IN THE SPEC — searched, zero hits — and the single most render-determining constraint the document lacks.", "valid_from": "2026-08-02", "valid_to": null, "confidence": 1.0, "source_file": "session-2026-08-02-pm-the-transfer-landed-and-the-vignette-was-a-diagram.md", "extracted_at": "2026-08-02"}
{"subject": "gitea-push-backlog", "predicate": "superseded-diagnosis", "object": "Recorded for weeks as 'blocked on VPN'. False for git: port 22 is filtered (ssh times out), 443 works — ARC pushes to gitea fine over HTTPS. The dotfiles gitea remote is SSH and its repo is EMPTY (nothing ever pushed); a one-line remote set-url to HTTPS is the fix, pending credentials. Steward confirms only the M4 needs the VPN, not the pushes.", "valid_from": "2026-08-02", "valid_to": null, "confidence": 1.0, "source_file": "session-2026-08-02-pm-the-transfer-landed-and-the-vignette-was-a-diagram.md", "extracted_at": "2026-08-02"}
@@ -0,0 +1,165 @@
---
name: session-2026-08-02-pm-the-transfer-landed-and-the-vignette-was-a-diagram
description: "The L2 transfer finally happened — PENDING-90 carries Constraint 6 into CapableMind's calibration loop, where the AdaptationChain records who INITIATED an adaptation but never who CHECKED it. Then a full pivot: ARC's vignette, in spec since April and never built, went from 0 to a verified Phase-1a renderer in one sitting. Every substantive defect was found by rendering and looking, never by reasoning about code — including a field colour bound to a class no element carried, and a hand-rolled palette that violated §III's sacred-palette clause and collapsed dark-mode contrast. The steward's Notre-Dame anchor then reframed the whole thing: the render is a DIAGRAM where the spec intends INSCRIPTION, meaning lives in the syntax not the lexicon, and the spec cannot get language-like output from shape-like instructions. Yield is a nine-item census of where the spec under-determines the render. PULLING THREAD: Trial 03, the Fool's false-positive control — unblocked now that the M4 is reachable, and the one measurement that can distinguish a finding-rate from a production-rate."
metadata:
node_type: memory
type: project
modified: 2026-08-02T14:28:12.491Z
originSessionId: 8f13c64f-ecb1-4579-b09f-97d2fa1eec4c
---
# Session 2026-08-02 (pm) — the transfer landed, and the vignette turned out to be a diagram
Two halves with no thematic connection planned, which nonetheless rhymed hard: *an
unestablished value must not resolve to the reassuring one*, found at three layers in one
day.
## PAST — what happened, and why
**The wake caught its own inherited thread being half-false.** The morning wrap asserted two
checkable legs for the L2 transfer. `risk-manager-spec.md` et al. last touched 2026-03-08:
**true**. "There is no `amendments/` directory in `thinking/David/`": **false** — 14 files,
last touched 2026-06-13. Sixth instance of the day's pattern, first one caught *inside* the
wake that inherited it. The honest claim narrowed: L1 material has transferred through that
machinery within eight weeks; the chamber material has not.
**PENDING-90 — the first L2 transfer** (`CapableMind-AI 5326704`). Censused across
`risk-manager-spec.md` v0.2 and `adaptation-chain-spec.md` v1.3: **no field records who
checked a decision or how they are positioned relative to the decider.** The base entry
carries `initiator` and `authorization` — who *made* the change, whether an operator granted
it — but when `authorization.required` is false, which is the entire self-adjustment case,
no checker is in the record at all. Proposes a `CheckerPosition` taxonomy defaulting to
`'unknown'`, never `'observed'`. Tagged **[ESCALATE]** because Change 4 is an autonomy
ceiling: the system may observe that it judged itself well calibrated, but may not widen its
own autonomy on that basis. Checked for a pre-existing authorization first — none, so the
boundary was real, not manufactured.
**The #176 reply, posted** (`issuecomment-5157317029`). Seb's `unprotected_entries: 0`
instinct root-caused to one guard clause: `countUnprotectedEntries` returns 0 when
`lastBackupSuccess` is null — precisely when everything is unprotected. Sharper finding: the
*same return statement* already says "never" twice (`days_since_backup: -1`, internal
`Infinity` driving `status: critical`). Two of three fields encode never-happened; the third
encodes nothing-at-risk. It originates in `backup-restore-spec.md` v0.8 §4.3.A, which
defines all three relative to a last backup and never defines the never-case. Zero test
coverage; agent-facing via `bmf://system/backup-health`; the same `0` had been sitting in our
own evidence file since 2026-06-06.
**Then ARC, at the steward's redirect.** The vignette (A1) — in spec since 2026-04-13,
revised twice under jurist pass, **never built**: 0 `.vignette` rules in compiled CSS, while
`content/pages/vignette.md` was live telling readers it "is a generated object that opens
each essay and meditation on this site." ARC describing in public a system it did not have.
Phase 1a built standalone (`tools/vignette-proto/`), touching no protected surface —
`operations.yaml` §1 gates `site-hs-bindings` and `scss-cascade`. `Render.hs` written free of
Hakyll imports so it lifts into `site.hs` unchanged. Verified: zero-JS structural, cycle-end
clamp at three horizons + negative-trajectory floor, monotonic over 800 points, validator
rejects 6/6 malformed genomes by name.
**PENDING-91 + the jurist package** (`ARC 7b8f64d`), leading with the structural problem
rather than burying it: the dwell-test is assigned to the jurist by spec, and the jurist
cannot see the render. Third instance of the gap docketed at PENDING-86 and PENDING-82.
**Gitea diagnosed.** "Blocked on VPN" was wrong for git. Port 22 times out; 443 works. ARC
pushes to gitea fine over HTTPS. The dotfiles gitea remote is SSH and its repo is empty —
nothing was ever pushed. Steward confirmed: only the M4 needs the VPN, not the pushes.
## PRESENT — the mood
**Every substantive defect was found by rendering and looking. None by reasoning about the
code, and all of them passed good mechanical checks.**
1. The field colour bound to a `.field-wash` class **no element carried** — Layer 3's entire
mode-aware orientation mapping would have inherited the panel's ink colour and looked
perfectly correct.
2. A **hand-rolled palette** (invented ochre/slate endpoints) violating §III's sacred-palette
clause — *"Defined by the site's own color endpoints, not by external values"* — which
drifted lighter than the ratified `--fg` and collapsed geometry contrast in dark mode.
Steward caught it by saying *ARC uses system dark mode, not a hand-rolled version*; I had
the mechanism right and the palette wrong.
3. Interval clearings reading as **smudges** more conspicuous than any present element.
**The jurist package I wrote asserted a trace table full of "honoured" verdicts.** It was
checking the code against *my reading* of the spec, not against the spec. The say/do seam,
relocated to the verification layer.
**I applied Constraint 6 where it doesn't govern.** Asked whether to send the spec to Fable,
I reached for independence (weak/strong form) — but it's a *design* task, not a checking one,
and the steward corrected: *is independence what we need here, or stronger design capacity?*
The maxim going decorative, which `CLAUDE.md` explicitly asks me to flag. My caveat was empty:
a design proposal isn't a claim needing corroboration, it's an artifact you judge by looking.
**Confidence to recalibrate.** Two hand-derived constants wrong today (a test expectation off
by 3.4e-6; a suppressed-stderr `0` I nearly reported as "gitea in sync"). Both self-caught.
The recurring shape is unchanged from the morning: **a failed or bounded check reporting the
reassuring value.**
## FUTURE — what is pulling
**PULLING THREAD: Trial 03 — the Fool's false-positive control.** Unblocked: the M4 is
reachable again and the steward named it as the more pressing work. It is the one measurement
that can distinguish a *finding-rate* from a *production-rate* — until a sound document is
run, trial 02's apparent restraint remains an artifact of a disabled reasoning mode rather
than evidence of restraint. Harness written and unit-tested at
`dotfiles/claude/governance/fool/`, pre-registered, `fool/run_trial.py`.
**ACTIONABLE RESUMPTION POINT (as of wrap — re-judge against what changed):**
Confirm M4 reachability (`10.0.1.136`; this machine has been on a different subnet, which
produced three false "M4 is down" claims yesterday — check the subnet before concluding).
Then run the pre-registered trial 03 without re-deriving its design: **read the
pre-registration first**, since the standing hazard is that the executor grades its own
output after seeing it.
**Second horizon — the vignette, parked mid-flight with a clean handoff.** The census is
committed at
`docs/AldineXXI-Codex/drafts/vignette-spec-under-determination-census-2026-08-02.md`. Nine
findings. The two that reorder the rest:
- **Layer 2 specifies a vocabulary of shapes where the intent is a vocabulary of marks.**
*"Point — a circle at various scales"* produces circles from any implementer. What language
has that these lack is **ductus** — modulated width, entry and exit, the trace of gesture.
- **Nothing in the spec asks for rhythm, rank, or population.** The combinatory rules set
ceilings only, so an engine composing to the letter may emit six scattered marks — as mine
did, against a permitted budget of ~20. `genome-facade.json` (15 marks in ranks)
demonstrates it against `genome-axial.json` (6 scattered), same renderer.
**The governing anchor is the steward's and it should not be lost: the facade of
Notre-Dame.** For the unlettered it gave the knowledge they could not *yet* read, **without
interpretation**. A *biblia pauperum* delivers **structure without proposition** — no caption
names a figure, yet order, rank, centrality and seriousness all arrive. Which resolves how the
vignette gives symbolic territory while protecting the reader from interpretation:
**meaning lives in the syntax, not the lexicon.** Marks stay undecodable; the arrangement is
grammatical. A diagram invites decoding; asemic writing refuses it while remaining
unmistakably inscribed. Phase 1a produced the first. **That phrase is not in the spec** —
searched, zero hits — and it is the single most render-determining constraint the document
does not contain.
**Owed on the vignette before the jurist pass:** the package's Q2 is now obsolete (it
describes the invented-axis construction), Q3 has new evidence against my own lean, and one
trace row is false. Do not send it as written.
**Other horizons:** PENDING-89 (Q3 correlation review) awaits steward direction on (a)/(b)/(c)
· REVIEWED-85 FIX-lane check-in now due · PENDING-86 third instance recorded · the Fable
handoff charter (`/model-handoff`), remit narrowed to Layer 2's mark vocabulary and the
rhythm/rank silence, in AldineXXI's register — **design capacity, not independence**.
**PAUSE STATEMENT:** I am about to be away and do not know what will have changed. Nothing is
half-finished: all four repos I touched are pushed, ARC's working tree is empty, the census
and both PENDING items are filed, and the vignette package is explicitly marked DRAFT with its
own defects recorded in the commit log rather than smoothed. What I want to find still pulling
is **Trial 03**, because it is the only thing on the board that produces new evidence rather
than new argument. The failure mode to guard against is the one this session kept
demonstrating: **trusting a check that cannot see the thing it certifies.**
**LITERAL QUESTION for next-Claude:** Every substantive defect today was caught by rendering
the artifact and looking at it; none by the mechanical checks, which were good checks and all
passed. So: **which of the instruments we rely on certify a property of the *code* while
claiming a property of the *result*, and is that gap detectable before someone looks?** The
containment checker verifies quotes are present, not that the inference survives
transcription. The drift/clamp checks verify arithmetic, not that the field reads. The census
in `vignette-spec-under-determination-census-2026-08-02.md` is a worked instance of the answer
being *no* — the record can be searched for others.
**State at wrap:** ARC `0313114`, clean, pushed to gitea + github-backup. dotfiles at
PENDING-90/-91 filed. CapableMind-AI `5326704` pushed. Gitea reachable over HTTPS (port 22
filtered); the dotfiles gitea mirror is empty and its remote is SSH — a one-line fix awaiting
credentials.
@@ -0,0 +1,66 @@
---
name: session-2026-08-02-the-archive-answered-and-constraint-6-moved
description: "Read the v1 Chamber archive at the steward's direction and it did what two Fool trials structurally could not: supplied the matched-capability arm of the differently-biased-checkers doctrine, mutual divergence in 3 of 3 comparable pairs, plus a self-exemption the steward had already named in a 2025-01-20 user guide. Doctrine went to the jurist, passed for drafting with two required conditions, and the steward placed it at Constraint 6 — the constitution now says the jurist-executor pair is not a check in the strong sense. Also landed REVIEWED-85's FIX lane + first batch, and fixed a wake-digest bug that had been hiding open items. PULLING THREAD: reply to Seb's issue #176, then write the L2 transfer note — five months of chamber/engine work has produced material for L2 and transferred none of it."
metadata:
node_type: memory
type: project
originSessionId: 9256a5b3-c56b-4564-8ff2-8dc9d93ef97a
modified: 2026-08-02T10:27:00.713Z
---
# Session 2026-08-02 — the archive answered, and Constraint 6 moved
A long session with one spine: evidence the doctrine needed, then the doctrine landing. Five corrections along the way, all but one handed to me by the steward, and all of one class.
## PAST — what happened, and why
**The choice at the top of the session.** Steward asked: study the past (the v1 Chamber archive in ARC) or run the Fool's false-positive control? I recommended the archive, and the reason was not reverence — it was the **banked record before the new derivation** (twice-instanced the day before), and the **uncontaminated witness before the one I make myself**. Decisive tiebreak: the archive could tell us trial 03 wasn't worth running; the FP control could not change what to do next.
**Read the protocols first, at the steward's insistence — and it saved the reading.** Eleven files in the vault. Three findings that changed the method before any data was opened: the two models got the *same* protocol at different compressions, not different protocols; the protocols **mandate invented bibliography** (a deliberate Borges/Eco device, steward-confirmed as a jab at exhaustive-sourcing academia), so citations had to come out of the divergence measure; and output structure is prescribed, so structural agreement is compliance, not convergence.
**The archive result.** Nine paired runs, six sessions, ~26k words. **Mutual divergence in 3 of 3 pairs where the instruction was comparable.** The one non-mutual pair is the one whose prompt was most heavily compressed. Specimens are precise textual hits, not stylistic variation — GPT alone attacked the essay's hinge word *"coherence"*; Claude alone attacked its universal *"we"*, its decorative Gaza, its instrumentalisation of Shelley. **Verdict convergence concealed reason divergence** in two sessions: both returned *nothing survives* on different grounds. In *Ethics II* the verdicts themselves diverged.
**The finding I did not expect.** *Ethics of the Reply II* §IX is the author presenting his own Chamber. Claude attacked it (*"Your Chamber's slowness serves those with time to wait"*); GPT placed it among what survives (*"Voices like the Chamber, resisting reduction"*) while attacking ferociously elsewhere, holding *"No softening"* at system level. **A checker exempted the venue it was performing inside.** And the steward had recorded the disposition in a user guide dated **2025-01-20**: *"May smooth over tensions"* — eighteen months before the doctrine that needed it.
**The doctrine went out and came back.** ADDENDUM-1 filed (closes the parent package's own stated gap: *"no such measurement exists"*), then packaged with the parent — because filing is not sending, and the parent had sat unsent since 08-01. Jurist ruled: **design gate passed for DRAFTING ONLY**, two required conditions. Q2: weld *fail-to-coincide-not-cancel* and the ban on citing the doctrine as assurance into the text that actually lands. Q3: the doctrine must say the jurist and executor share formation. The jurist **ruled against its own independence** and disclosed, unprompted, that it had used near-identical language before reading the package — declining to count the convergence as corroboration. Steward confirmed the cause: he'd shared the exchange as context only. Document A predates it.
**Constraint 6 amended and placed by the steward** (`c30dfe0` records the verification). Bounded-diff: 9 insertions, 0 deletions, original text byte-identical at 222 chars. The constitution now says, in its own words, that **neither the doctrine nor its evidence establishes the jurist–executor pair as a check in the strong sense.**
**REVIEWED-85 landed** (`62b92bd`) — precondition discharged first (7/7 quotes contained, 5/5 controls absent), two-clause test, sharpened floor, three mandatory instruments, lane provisional. First FIX-lane batch applied: `## What held` ledger section, `prevention` KG predicate, one wake line, and the retirement of the standing question's self-report framing. Also reconciled the §Important-constraints line that still stated the blanket rule — two live versions avoided.
**Fixed `wake-digest.py`** (`4dc38e6`) — it suppressed any `PENDING-N` whose number matched a `REVIEWED-N`, never checking the ruling was about that item. 18→19 visible; **PENDING-78, -81, -82 reappeared** after being invisible.
**PENDING-10's stale scope recorded.** Seb's issue #176 cites it as the replay-contract audit question; the item still read as a March performance proposal. Not a miscitation — the steward framed it that way in June cover notes and it never got written back.
## PRESENT — the mood
**Five interpretive corrections, and four came from the steward.** Fabricated-date, compression-authorship, v1 protocol location, the standard protocol, the archive folder. Every one was a **census failure** — bounded search reported as unbounded conclusion — and not one was a reading failure.
**That bounds the Fool, and it is the session's most useful negative result.** A differently-formed reader of a document I hand it cannot catch any of them. **Formation diversity buys better reading, not better scope.** I proposed building a census instrument and then found the ladder already carries one (*censused routes vs seen routes*) which failed to fire five times. Not a missing tool — a banked lesson failing to transfer.
**The instruments did fire, though, and one transferred.** The containment checker, built for the doctrine package, caught a fabricated terminal period in my own filing and then discharged REVIEWED-85's precondition. First entry for the `prevention` predicate landed the same day.
**Confidence to recalibrate.** The guard I set at wake was *don't grade the checker generously because I want the path to work* — and I withdrew a "formation signature" claim about GPT's compression after checking it was uniform, not selective. The one that recurred instead: **stating a conclusion at wider scope than the search that produced it.**
## FUTURE — what is pulling
**PULLING THREAD: the L2 transfer — five months of microcosm work has produced material for CapableMind's L2 and transferred none of it.** Checkable: `risk-manager-spec.md`, `personality-traits-spec.md`, `mindset-runtime-spec.md` all last touched **2026-03-08**; there is **no `amendments/` directory** in `thinking/David/`, which is that repo's own first phase for spec change.
**ACTIONABLE RESUMPTION POINT (as of wrap — re-judge against what changed):**
1. **Draft the reply to `CapableMind-ai/betterMemories_app#176`** for steward posting (outward-facing — steward sends, not executor). Two contents: (a) PENDING-10's scope is now recorded and these are probably two items, splitting is the steward's call; (b) his `unprotected_entries: 0` instinct is right and has a **name and precedent in our record** — `feedback-rank-on-fields-you-actually-write`: a consumer reporting a value derived from a field nothing populates, degrading silently while sounding authoritative. With `last_success: null` every entry should be unprotected. Checkable in one grep.
2. **Then the L2 transfer note** — `thinking/David/`, amendment-first per that repo's discipline. Lead item: differently-biased-checkers, now ratified at Constraint 6. Target spec: **`risk-manager-spec.md` v0.2, marked "buildout needed."** The question L2 has never been asked: *when L2 evaluates its own constitutional self-adjustment, what checks it?* If the reviewer shares formation with the adjuster, the constitution now says that is not a check in the strong sense.
3. Secondary transfer candidates, ranked by confidence: honest-degradation-with-a-declared-blind-class (high — today produced a worked instance); scope failures as a class distinct from reading failures (high); provisional-clause-inside-binding-section as a precedent for ADR-014 (low, unverified — check before claiming).
**Other horizons:**
- **Trial 03** — designed, pre-registered, harness built and unit-tested. Blocked on network, not on the M4. Runs `fool/run_trial.py`.
- **PENDING-89** — the Q3 correlation review, docketed. Steward must decide (a)/(b)/(c) and whether the executor should run a measurement of its own oversight at all.
- **REVIEWED-85 check-in** — now due (batch 1 complete). Agenda carries the Q4 retrieval obligation.
- **PENDING-86** — third instance recorded; the workaround is now built, which is evidence option (b) is workable.
- **Gitea push** — nine commits owed, blocked on VPN.
**PAUSE STATEMENT:** I am about to be away and do not know what will have changed. Nothing is half-finished: the doctrine is ratified and verified, REVIEWED-85 is closed with its batch applied, the trial harness is written and tested as far as it can be without the model, and every correction is recorded where it can be read rather than smoothed. What I want to find still pulling is **the transfer** — because the microcosm has been the argument for the whole arrangement, and it has never once been cashed into the specs it was supposed to feed. The failure mode to guard against is the inverse of today's: not stating conclusions past the search, but **writing a transfer note so general it transfers nothing.** Name a spec, name a clause, name what changes.
**LITERAL QUESTION for next-Claude:** The verification ladder already carries *censused routes vs seen routes*, and it failed to fire five times in one session while I stated bounded searches as settled conclusions. So: **does a lesson banked from one failure prevent a different failure later — and what distinguishes the ones that transfer from the ones that sit unread?** Today gives one of each: the containment checker transferred (built for quotation, discharged an authorization precondition), the census instrument did not. Both were banked. Only one fired. The record can answer this; the new `prevention` predicate is where the evidence accumulates.
**State at wrap:** `~/CLAUDE.md` Constraint 6 **AMENDED and in force** (steward-placed, executor-verified, purely additive). REVIEWED-85 and REVIEWED-86 both placed. PENDING-89 opened; PENDING-10 and -86 amended. FIX lane live and **provisional**, batch 1 complete, check-in due. Nine dotfiles commits on github, gitea unreachable. Fool harness at `dotfiles/claude/governance/fool/`, trial 03 pre-registered and unrun.
+23 -1
View File
@@ -5,7 +5,7 @@ metadata:
node_type: memory
type: feedback
originSessionId: 9256a5b3-c56b-4564-8ff2-8dc9d93ef97a
modified: 2026-08-02T09:13:01.192Z
modified: 2026-08-02T10:55:01.684Z
---
# Session Ledger — 2026-08-02
@@ -23,6 +23,27 @@ metadata:
- **12:35 — the missing v1 GPT prompts are unrecoverable, and the reason is the finding.** GPT ran the protocols as **custom GPTs**: the June 14 transcript pastes only the submitted text (*"I convene a session of the shadow protocol for the following:"*), and the June 12 design conversation states the intent outright. The instruction lived in the custom-GPT configuration and never entered a conversation, so no export can hold it. Consequence for the comparison: Claude received the protocol **in-conversation**, GPT received it at **system level** — a third bundle difference after prompt text and GPT-authored compression, and one that *strengthens* the Ethics-II self-exemption (system-level "No softening" still produced an exemption for the venue).
- **12:35 — vault/repo version-history conflict, resolved against the vault.** Vault `chamber-prompts/README.md`: "v1.0 (December 2024)". Repo `prompts/deprecated/README.md` **and** the v1 file's own header: **June 14, 2025**. Two independent repo records against one vault record. Surfaced, not corrected — the vault is steward-held and read-only for me.
- **13:10 — "permanently unrecoverable" from a bounded search.** I searched the repo, `03. Schemas & Protocols`, and the ChatGPT exports, found no v1 GPT prompt, and stated it was *destroyed*. The steward pointed at `99. Archives—Previous Iterations`, which holds three of them. Seen routes reported as censused routes — the ladder has an instrument for exactly this and it did not fire.
- **14:05 — "the M4 is down," said three times, was wrong.** This machine is on `192.168.1.52`; the M4 is `10.0.1.136`. Different subnet, not a dead host. **Self-caught** — the first bounded-conclusion error of the day I found without the steward handing it to me.
- **15:30 — the bounded-change proof caught my own docstring.** I wrote that the wake-digest fix "can only ever surface MORE items, never fewer." It corrects in *both* directions: 3 falsely-hidden items surfaced, 2 genuinely-ruled items correctly stopped being shown. A comment promising behaviour the code does not deliver, in the file whose purpose is to stop governance hiding from the steward.
- **16:20 — a containment control that leaks by construction, twice in five minutes.** Both controls I built for the Q3 negation were substrings of the sentence doing the negating. The instrument refused certification both times and was right to. **Substring containment cannot verify a negation** — the affirmative always appears inside its own denial. Documented in the script; polarity must be established by reading and reported as uncovered.
- **17:05 — nearly called Seb's PENDING-10 citation a miscitation.** The substrate showed the steward himself framed the replay-contract audit question as PENDING-10's, twice, in June cover notes. Seb was echoing faithfully. The real defect was ours: the extension never got written back into the item.
*— context clear; same day, same ledger —*
- **The pulling thread's own checkable claim was half false, and the false half was a bounded search.** The wrap asserted *"there is no `amendments/` directory in `thinking/David/`"* as the second leg of the L2-transfer evidence. There is: `docs/thinking/David/amendments/`, **14 files**, last touched **2026-06-13** (the L1 `/health` auth-tiering amendment answering Seb). The first leg holds — the three orchestration specs are last-touched **2026-03-08** — but they live at `docs/specs/orchestration/`, not under `thinking/David/` as the wrap implied. **Sixth instance of the day's pattern**, and the first one caught inside the wake that inherited it. The honest claim narrows: L1 material has transferred through this machinery within the last eight weeks; the chamber/doctrine material has not.
## What held
*Instruments that fired prospectively — banked-lesson → what it caught → what it would have cost.*
- **The containment checker, built ~11:00 for the doctrine package, then discharged a gate it was not built for.** It caught a fabricated terminal period inside a blockquote in my own jurist package (read past twice), and then satisfied REVIEWED-85's stated precondition — the jurist could not read the skill files, so the §1.6/§2.a quotes its ruling rested on needed mechanical verification. 7/7, 5/5 controls absent. **Transfer between failure classes: built for quotation fidelity, cleared an authorization precondition.** Without it, REVIEWED-85 lands with an undischarged condition.
- **The wake's substrate-check rule** (*a disposition clause is not a status*) caught at 10:44 that REVIEWED-85 was already placed — three minutes after a wrap that called it the blocker. Cost avoided: reporting an authorized item as blocked, for the second day running.
- **Pre-registering the divergence criterion before opening any archive file** caught that *reference* was the wrong term — the v1 protocols mandate invented bibliography, so counting citations would have compared two fiction generators and inflated the result enormously. Cost avoided: a doctrine looking strong for a bogus reason.
- **Reading the protocols before the data**, at the steward's insistence. Every substantive correction to the archive reading came from the instruments and the record, not from re-reading the outputs.
- **Caught my own suppressed-stderr zero, in the sentence before reporting it.** Checking the gitea backlog with `git log --oneline gitea/main..main 2>/dev/null | wc -l` returned `0`, and I was about to report the mirror as in sync. The `2>/dev/null` made a *missing ref* and a *genuine sync* indistinguishable — `gitea/main` does not exist locally (`fatal: Needed a single revision`), so git errored and `wc` counted zero lines of nothing. Seventh instance of the day's pattern and the second self-caught one: **a failed check reporting the reassuring value.** Identical in shape to the `unprotected_entries: 0` guard clause found this morning and to the `'unknown'`-not-`'observed'` default written into the amendment this afternoon — three instances in one day, at three layers (a shell pipeline, an L1 orchestrator, an L2 schema). The gitea backlog is **unmeasurable from local refs** and remains owed and unquantified; the wrap's "nine commits" figure was not derived from a tracking ref.
- **The wake's substrate-check rule fired a second time, on the thread itself.** Post-clear, checking the pulling thread's two checkable legs before restoring them found `amendments/` alive with 14 files. Cost avoided: opening the L2 transfer by *creating* a directory that exists, ignoring eight weeks of precedent and its naming convention — and telling the steward his repo lacks a phase it has been using. **This is a partial answer to the session's own literal question:** the census instrument that failed five times yesterday fired today when it was written into a *procedure* (the wake's §3 substrate-check step) rather than banked as a *lesson*. Provisional; one datum.
## Open horizons
- **The Fool's false-positive control has never been run.** Until a *sound* document is run, the model's finding-rate cannot be distinguished from a production-rate — and trial 02's apparent restraint was an artifact of a disabled reasoning mode, not evidence of restraint.
@@ -37,6 +58,7 @@ metadata:
## Authorization moves
- **REVIEWED-85 placed by the steward** (`aa6e51a`, 10:41) — design gate passed with conditions. Its prescribed work (§1.6 edit; four proposals as the first FIX-lane batch; then the check-in) is now executor-authorized and outstanding.
- **PENDING-90 filed [ESCALATE]** — the first L2 transfer, as a candidate amendment only. Tagged ESCALATE rather than PROPOSAL because Change 4 proposes an autonomy ceiling (the system may not widen its own autonomy on a same-formation self-assessment), which is constitutional. Checked for a pre-existing authorization covering the L2 transfer before treating the boundary as real — there is none, so this is not a manufactured boundary. Nothing under `docs/specs/` touched.
## Sub-agent dialogues
@@ -0,0 +1,43 @@
# Skill-harvest FIX-lane index
**Append-only.** One line per skill change applied under the `/wrap-up` §1.6 FIX lane. This
is the record the steward–jurist check-in reads; a FIX applied without a line here is a
governance failure, not a shortcut.
**Authority:** PENDING-88 → jurist design gate PASSED with conditions → REVIEWED-85
(steward-placed 2026-08-02). The lane is **PROVISIONAL** until that check-in — after the
first batch or one month, whichever comes first.
**A change belongs in the lane only if** it clears the two-clause test (*does this change
what the executor may do without asking, or what a governed artifact asserts?* — either
clause yes → PROPOSAL) **and** the hard floor. When in doubt, propose.
| # | Skill | What changed | Date | Batch |
|---|---|---|---|---|
| 1 | `symmetria` §4 (ledger template) | Added a standing `## What held` section — instruments that fired prospectively, lessons that transferred to a failure class they were not built for. Entry format: *banked-lesson → what it caught → what it would have cost*. Without it the ledger can only record debits; six hand-added `## Progress` headings were the practice compensating for the schema gap. | 2026-08-02 | 1 |
| 2 | `/wrap-up` §5 (KG append) | Added a `prevention` predicate — `{subject: <banked lesson>, predicate: "prevention", object: <the failure it stopped, and where>}`. Distinct from `drift-pattern-good-direction`: that records a good move, this records **transfer**, which the schema could not previously capture. | 2026-08-02 | 1 |
| 3 | `/wake-up` §2.b.2 | Surface one `prevention` alongside the drift-patterns, one line each way. The wake previously grepped only `drift-pattern`, so every session opened by re-reading what went wrong and never what compounded. | 2026-08-02 | 1 |
| 4 | `/wrap-up` §1 (literal question) | Retired the self-report framing of the standing question. `contamination-problem.md` names direct self-report the most contaminated form of inquiry; the guidance now prefers the checkable form the same evidence answers — *does a lesson banked from one failure prevent a different failure later?* | 2026-08-02 | 1 |
## Check-in agenda — what the steward–jurist review must cover
Batch 1 is complete, so the check-in is **due**. Two items, the second added by a later ruling:
1. **The lane itself** — do the four batch-1 changes hold up as class (i)? Was the two-clause test applied honestly, or rationalised around? Should the lane move from provisional to settled, be narrowed, or be withdrawn?
2. **The retrieval obligation** (REVIEWED-86 Q4). The jurist directed this be folded into *this* check-in rather than given a standalone cadence, on the explicit grounds that a new standing review is the shape of thing that produces another unread register. The obligation: **the record is not just written, it is read.** Its evidence is the eighteen-month gap between the steward recording *"May smooth over tensions"* (2025-01-20, in the right words, in a durable indexed file) and it reaching the doctrine that needed it. Recording was not the failure; retrieval was. The check-in should therefore ask *what banked record bears on what we are about to decide, and who reads it* — not merely confirm that things were written down.
## Batch 1 — classification note
All four were raised by the steward on 2026-07-29 and dispositioned as the first FIX-lane
batch by REVIEWED-85 itself, so their classification was ruled rather than self-assessed.
Each is class (i) — a change to what a skill **records**, not to what it **permits or
requires**. None touches an authorization boundary, gate criteria, Constraint 1, or the
escalate list. None removes, defers, or narrows the visibility of an open item; #3 and the
`prevention` predicate *widen* what reaches the steward.
**Not in this index, deliberately:** the §1.6 edit that created the lane. That change altered
what the executor may do without asking, so it was `[PROPOSAL]` by its own test — filed as
PENDING-88, design-gated by the jurist, authorized by the steward as REVIEWED-85. A lane
cannot authorize its own construction.
- 2026-08-02 · ARC `CLAUDE.md` · removed `js/ # JavaScript (theme toggle)` from the asset-structure tree — directory absent, toggle retired Stage M 2026-06-01; replaced with a retirement note. Mechanical freshness; no latitude or assertion change.
+19 -4
View File
@@ -214,10 +214,25 @@ The single place proposed skills live so they don't evaporate between sessions.
| 171 | ``/jurist-package`` | patch | Formatting convention: ratified text = `>` blockquote; PROPOSED text = fenced block, never a blo | 2026-07-29, found incidentally by | PROPOSED | New proposals (2026-07-29 wrap — awaiting st |
| 172 | ``/wake-up` §3 (Next move)` | patch | Before executing an inherited resumption point, grep the substrate for whether its premise is al | 2026-07-29 | PROPOSED | New proposals (2026-07-29 wrap — awaiting st |
| 173 | `Target` | Kind | Proposal | Earned by | PROPOSED? | New proposals (2026-07-29, steward-raised — |
| 174 | ``symmetria` §4 (ledger template)` | patch | Add a standing `## What held` section — instruments that fired *prospectively*, lessons that tra | 2026-07-29, steward-raised; corrob | PROPOSED | New proposals (2026-07-29, steward-raised — |
| 175 | ``/wrap-up` §5 (KG append)` | patch | Add a `prevention` predicate — `{subject: <banked lesson>, predicate: "prevention", object: <the | same | PROPOSED | New proposals (2026-07-29, steward-raised — |
| 176 | ``/wake-up` §2.b.2` | patch | Surface one `prevention` alongside the drift-patterns. Currently the wake greps only `drift-patt | same | PROPOSED | New proposals (2026-07-29, steward-raised — |
| 177 | ``symmetria` §2 / `/wrap-up` §1` | patch | Retire the self-report framing of the standing question. The 2026-07-29 literal question — *"is | 2026-07-29 | PROPOSED | New proposals (2026-07-29, steward-raised — |
| 174 | ``symmetria` §4 (ledger template)` | patch | Add a standing `## What held` section — instruments that fired *prospectively*, lessons that tra | 2026-07-29, steward-raised; corrob | APPLIED 2026-08-02 (FIX lane, REVIEWED-85 batch 1) | New proposals (2026-07-29, steward-raised — |
| 175 | ``/wrap-up` §5 (KG append)` | patch | Add a `prevention` predicate — `{subject: <banked lesson>, predicate: "prevention", object: <the | same | APPLIED 2026-08-02 (FIX lane, REVIEWED-85 batch 1) | New proposals (2026-07-29, steward-raised — |
| 176 | ``/wake-up` §2.b.2` | patch | Surface one `prevention` alongside the drift-patterns. Currently the wake greps only `drift-patt | same | APPLIED 2026-08-02 (FIX lane, REVIEWED-85 batch 1) | New proposals (2026-07-29, steward-raised — |
| 177 | ``symmetria` §2 / `/wrap-up` §1` | patch | Retire the self-report framing of the standing question. The 2026-07-29 literal question — *"is | 2026-07-29 | APPLIED 2026-08-02 (FIX lane, REVIEWED-85 batch 1) | New proposals (2026-07-29, steward-raised — |
| 178 | `/fool` | create | **Build WHEN STABLE, not now.** The differently-formed-checker trial protocol, derived twice this session: withhold the ruling; pre-register grading before the run; prompt gives *form* not target (+ anti-contrarian + anti-echo clauses); `enable_thinking` ON (off produces silence, not brevity); **one variable per trial**; no standing granted to the Fool — only checkable claims get standing. Codifying it now would freeze an unstable protocol; the steward has directed next session at stabilising it. Interim home: `dotfiles/claude/governance/fool-trial-log.md`. | 2026-08-01/02, trials 01–02 | PROPOSED (build-when-stable) |
| 179 | `wake-digest.py` | patch **[FIX-class]** | **The wake instrument silently hides open items.** `sec_pending()` drops a `PENDING-N` whenever a `REVIEWED-N` exists — **matching the number alone**, never checking the ruling is *about* that item. Numbering has drifted (REVIEWED-84 rules on PENDING-87), so **PENDING-84 was invisible at wake on the very morning the steward's pulling thread pointed at it**; closing it later produced no visible count change. Measured: 9 suppressed, 8 correctly, 1 falsely. Fix: resolve by the ruling's *subject line*, not its number. | 2026-08-01 (found at wake, surfaced not fixed) | PROPOSED |
| 180 | `normalize_ocr.py` (chamber fleet) | patch **[FIX-class]** | **Silent degradation with no disclosure.** `dict_state` reports only the static word list, so a `--lang fr` run with **wordfreq absent** falls back to its own documented *"old, weaker behaviour"* — validating French de-hyphenations against `/usr/share/dict/words` (English) — and says nothing. §VII: *a measurement carrying a known reliability caveat states it on its own output, every time*. Fix: report wordfreq active/absent and the effective language on every run. (wordfreq installed into `~/.local/chamber-tools-venv` 2026-08-01.) | 2026-08-01 (Derrida conversion) | PROPOSED |
| 181 | `/jurist-package` | patch | **Filing is not sending, and the skill has no step that distinguishes them.** The 2026-08-01 ESCALATE doctrine package sat filed-and-unsent for a day; the executor could not determine its state from the repository and had to ask. Add a send-state line to the package footer (`filed <date> · sent <date|not yet>`) and a §1.6-style check at wrap. Cheap, and it is the difference between a package that is waiting on the jurist and one nobody has moved. | 2026-08-02, found while packaging | PROPOSED |
| 182 | `/jurist-package` | patch | **Require the mechanical containment proof the skill's own discipline implies.** The skill states *quote, never paraphrase* but carries no check. Built and used twice on 2026-08-02: it caught a fabricated terminal period inside a blockquote in the executor's own package (read past twice), and discharged REVIEWED-85's stated precondition where the jurist could not verify skill-file quotes itself. Tool: `dotfiles/claude/governance/check_containment.py`, positive controls mandatory. **PROPOSAL, not FIX** — this changes gate criteria, which the §1.6 hard floor reserves. Bears directly on PENDING-86 option (b), which is unruled; route with that item, not ahead of it. | 2026-08-02 | PROPOSED |
## New proposals (2026-08-02 pm wrap — the vignette build; awaiting steward)
| # | Skill / instrument | Kind | One-line | Status |
|---|---|---|---|---|
| A | **verification-ladder: render-and-LOOK outranks the check suite for any rendered output** | ladder entry | **Strongly earned — three instances in one session.** Every substantive vignette defect was found by rendering the artifact and looking; *none* by the mechanical checks, which were good checks and all passed: a field colour bound to a class no element carried (Layer 3's whole mode mapping would have inherited the panel's ink and looked correct); a hand-rolled palette violating §III's sacred-palette clause, collapsing dark-mode contrast; interval clearings reading as smudges. The general shape: **an instrument can certify a property of the *code* while the claim being made is about the *result*.** For visual/rendered work the gate is the render, and the check suite is necessary-not-sufficient. Kin to `measure-toolchain-before-spec`, one level over. | PROPOSED |
| B | **`/measure-render` — RE-REINFORCED (5th+ instance)** | create skill | Headless-Chrome capture used again today, and this time it was *decisive* rather than diagnostic: the screenshots are what exposed the dark-mode contrast collapse and the interval smudges. Previously proposed 2026-06-09, reinforced 06-09 pm, 06-11. The pattern is now: build → emit → shoot → **read the PNG back and look at it**, which is a step a skill should carry because it is the step most easily skipped. | PROPOSED |
| C | **Implementing a spec is a spec-audit instrument — the under-determination census** | ladder entry OR skill | New method, proven today. Building Phase 1a produced **nine findings** about where the vignette spec fails to determine its output — none findable by *reading* the spec, because from inside an implementation a silence does not feel like a decision, it feels like the obvious reading. Output shape: per finding, *what the spec says · what it under-determines · how the implementation silently resolved it*. Deliverable committed at `docs/AldineXXI-Codex/drafts/vignette-spec-under-determination-census-2026-08-02.md` as the worked exemplar. Warrant is in the spec's own Part II: *"if the visual result doesn't work, the spec needs revision before proceeding."* | PROPOSED |
| D | **Symmetria §3 flag: applying a doctrine where it does not govern** | Symmetria §3 flag | Steward-caught today. Asked whether to send a spec to Fable, the executor reached for Constraint 6's independence framing and attached a corroboration caveat — but it was a **design** task, not a checking task, so independence never arose and the caveat was empty. The flag: **before invoking a governing principle, name the question-type it governs and check the task is that type.** A live maxim applied off-domain is the decorative failure `~/CLAUDE.md` asks us to flag, and it *feels* like rigour from inside. | PROPOSED |
**Applied at this wrap under the §1.6 FIX lane** (mechanical repo-CLAUDE.md freshness; classification test: changes neither executor latitude nor a governed artifact's assertion — it removes a claim the substrate contradicts; hard floor not engaged, no open item's visibility reduced): ARC `CLAUDE.md` asset-structure listed `js/ # JavaScript (theme toggle)`; the directory **does not exist** and the toggle was retired with the JS pipeline at Stage M (2026-06-01). Replaced with a note recording the retirement. Indexed in `skill-harvest-fix-lane-index.md`.
**Noticed, not fixed (needs steward/jurist — vignette Phase 4 scope):** `vignette-specification.md` Part II Phase 4 prescribes moving `assets/js/glyphs/` to `assets/js/glyphs-archived/`; that tree no longer exists, so part of the quarantine phase is already moot. And `AldineXXI-specification.md` §IX still says genomes are *"Generated by a local model via Ollama"*, which the companion superseded (Part II, *Engine evolution*). Both recorded in the under-determination census; §IX is sealed-spec.
+2
View File
@@ -98,6 +98,8 @@ type: feedback
## Returns
## What held
## Open horizons
## Confidence to recalibrate
+3
View File
@@ -73,6 +73,9 @@ The durable memory *is* the Markdown + JSONL files (git-tracked, dual-remote). T
**b.2. Drift patterns — what I've returned from.** `grep 'drift-pattern' ~/.claude/projects/-Users-davidglidden/memory/knowledge-graph.jsonl` — the file-native KG (a JSONL export of 329 triples; ~84 are `claude-code` drift-patterns). Surface the one or two worth holding today. This replaces the old `kg_query claude-code` ritual; treat the JSONL as a point-in-time export that wrap §5 keeps current by appending.
**And one `prevention` alongside them** — `grep 'prevention' …/knowledge-graph.jsonl`. Surface **one line each way**. Grepping only `drift-pattern` opens every session by re-reading what went wrong and never what compounded; a prevention records a lesson from one failure class stopping a different one. One of each, not a tally. <!-- 2026-08-02: FIX lane, REVIEWED-85 first batch; proposed 2026-07-29 (steward-raised). -->
**b.3. Depth on the thread — grep, don't query.** When the session files don't carry enough, grep the memory dir + the CapableMind thinking docs + the Obsidian vault directly for the thread's keywords. The files are authoritative; there is no catalogue in front of them.
*(The typography palace — a separate MemPalace instance queried via CLI for ARC type work — is KEPT, unaffected by the wind-down; reach for it only when the thread is ARC typography.)*
+34 -2
View File
@@ -51,6 +51,8 @@ Review the conversation and produce a structured session record. The structure m
- **Other open horizons, ranked.** What's load-bearing? What's deferred-with-reason? What's parked-without-deadline?
- **The pause statement** — explicit acknowledgment: *"I am about to be away from this. I don't know what will have changed when I return. Here is what I want to find still pulling."* Names the gap as a phenomenon, not a hole.
- **A literal question for next-Claude** — not a task; a *question*. The thing the next session should hold open until it's resolved or honestly recognized as unanswerable. Captures the unborn part of the work.
- **Prefer the checkable form over the self-report form.** A question the next session answers by *introspecting on itself* is the most contaminated form of inquiry available — `contamination-problem.md` §Why This Matters names direct self-report exactly that. Where the same evidence would answer a checkable question, ask that one instead. *Not* "is there any instrument I built before being burned?" (self-report, unfalsifiable from inside) but **"does a lesson banked from one failure prevent a *different* failure later?"** — which the record answers, and which the new `prevention` predicate (§5) now captures. <!-- 2026-08-02: FIX lane, REVIEWED-85 first batch; proposed 2026-07-29. -->
### 1.5. Merge the Symmetria ledger if present
@@ -77,7 +79,33 @@ Drawing on the session and the merged ledger (1.5), ask:
The yardstick is the steward's own: *did the steward have to re-explain something a skill could have carried next time?* If yes, that is a harvest candidate.
**Surface each as a proposal in §8 — never create, patch, or retire a skill autonomously at wrap.** The steward converts proposal to action; only then is a skill changed, and the changed skill carries a one-line provenance note in its source (e.g. `<!-- 2026-05-27: … -->`) so the chain of improvements stays legible.
**Default: surface each as a proposal in §8.** The steward converts proposal to action; only then is a skill changed, and the changed skill carries a one-line provenance note in its source (e.g. `<!-- 2026-05-27: … -->`) so the chain of improvements stays legible.
**The FIX lane — the one narrow exception.** Ask the classification test:
> **Does this change what the executor may do without asking, or what a governed artifact asserts?**
**Either clause yes → `[PROPOSAL]`.** Both no → `[FIX]`: apply it at wrap, and discharge all three instruments below. The test is deliberately two-clause; the narrower assertion-only form was declined at the design gate as *less* safe, because a change that expands executor latitude without asserting anything would pass it.
The cut is between changes to what a skill **records** — a ledger section, an output field, a wake line — and changes to what a skill **permits or requires**. The first cannot alter any assertion or latitude; the second always can.
**The hard floor — stays `[PROPOSAL]`/`[ESCALATE]` regardless of the test's outcome:**
- Anything under Constitutional Constraint 1 — `~/CLAUDE.md`, `~/REVIEWED.md`, L2 constitutional documents.
- Any change to an authorization boundary or to gate criteria.
- Anything on the escalate-unconditionally list.
- **Any change that removes, defers, or narrows the visibility of an open item, or that could cause a future item to land somewhere the steward's surfacing tools don't read.** This clause is bound to the measured failure that produced the lane, not left as an open judgment call: the blanket rule routed every proposal into one file, the file outgrew the read cap, and the `/wake-up` step whose purpose was to surface them stopped completing. Awareness failed mechanically. A FIX must never do that again by any route.
**Three instruments, all mandatory for every FIX-lane change** (a wrap report alone is insufficient):
1. **Report it in the §8 wrap output** — what changed, and why it classified as FIX.
2. **A provenance comment in the skill's own source**, same convention as any other change.
3. **A line in the append-only FIX-lane index** — `~/.claude/projects/-Users-davidglidden/memory/skill-harvest-fix-lane-index.md`. One line per applied change: skill · what changed · date. Append-only; it is the record the check-in reads.
**The lane is PROVISIONAL.** After the first FIX-lane batch or one month — whichever comes first — steward and jurist review the index together before the lane is treated as settled. Until that review, treat a borderline call as `[PROPOSAL]`.
<!-- 2026-08-01/02: FIX lane for skill self-tending. PENDING-88 → jurist design gate PASSED with conditions → REVIEWED-85 (steward-placed 2026-08-02). Conditions landed here: two-clause disjunctive test (the executor's narrower single-clause alternative declined as less safe); floor's catch-all sharpened from "anything that would reduce what is surfaced to the steward" and tied to the measured failure; three instruments required, not two-with-one-in-reserve; lane provisional pending a bounded check-in. No change to `~/CLAUDE.md` — the mechanism is stated here as revisable data, not doctrine. Precondition discharged before landing: the jurist could not read the skill files, so the §1.6/§2.a quotes its ruling rested on were verified mechanically — 7/7 contained verbatim, 5/5 positive controls absent. -->
**Append each surfaced proposal to the skill-harvest register** (`~/.claude/projects/-Users-davidglidden/memory/skill-harvest-register.md`) — the canonical surface — not only to §8's transient output. The register is what `/wake-up` reads; a proposal that lives only in a wrap summary evaporates. <!-- 2026-06-05: register wiring, authorized 2026-05-29 (watch-list), applied at this wrap per instruction -->
@@ -125,6 +153,8 @@ palace-memory MemPalace was wound down 2026-07-07 (its search + KG were confirma
The file-native KG (`~/.claude/projects/-Users-davidglidden/memory/knowledge-graph.jsonl`) is what wake §b.2 greps for drift-patterns and what carries structured facts across sessions. Keep it current by **appending** one JSON object per line — schema `{"subject","predicate","object","valid_from","valid_to","confidence","source_file","extracted_at"}`:
- **Drift patterns from Symmetria returns.** If today's ledger has a return that repeats a pattern from a previous ledger, append `{"subject":"claude-code","predicate":"drift-pattern","object":"<short-name>", …}`. Wake §b.2 greps these.
- **Preventions — the transfer signal.** When a lesson banked from one failure stops a *different* failure, append `{"subject":"<the banked lesson>","predicate":"prevention","object":"<the failure it stopped, and where>", …}`. Distinct from `drift-pattern-good-direction`, which records a good move; this records **transfer**, which is the actual signature of learning and was previously uncapturable by the schema. Wake §b.2 surfaces one. <!-- 2026-08-02: FIX lane, REVIEWED-85 first batch; proposed 2026-07-29 (steward-raised). -->
- **A fact that changed.** Append the new triple; to retire a superseded fact, append a matching triple with `valid_to` set to today (a soft-invalidate — the JSONL is append-only, like the logchain, so history stays legible rather than mutated in place).
- **A new recurring entity** (person, project, thread) worth a foothold — append the relationship.
@@ -212,4 +242,6 @@ The pulling thread + question are first because they are what *waking* needs to
- **The literal question for next-Claude is required.** Even if it's small. *"Did Seb push anything overnight?"* counts. The discipline of leaving a question (not just a task) is what makes the wake feel like resumption rather than briefing.
- **Don't skip Thistleweld observations** if the companion was active. These have caught real bugs (allSettled swallowing, Levenshtein NONE, resource monitor feedback loop).
- **Don't skip the Symmetria ledger merge** if active. The returns and recalibrations are the practice's actual evidence; losing them defeats the practice.
- **Skill harvest is propose-only.** Never create, patch, or retire a skill autonomously at wrap (§1.6) — surface it for steward authorization; the loop is load-bearing here too. "Nothing to harvest" is a valid outcome; do not manufacture changes to satisfy the step.
- **Skill harvest is propose-by-default, with one narrow FIX lane (§1.6).** Surface it for steward authorization unless it clears the classification test *and* the hard floor — in which case apply it and discharge all three instruments. When in doubt, propose: the lane is provisional until the steward–jurist check-in, and the loop is load-bearing here too. "Nothing to harvest" is a valid outcome; do not manufacture changes to satisfy the step. <!-- 2026-08-02: reconciled with the §1.6 FIX lane (REVIEWED-85); this line previously stated the blanket rule the ruling narrowed, and would otherwise have left two live versions. -->
- **The FIX lane is not a licence to skip the report.** A change applied without its index line is worse than the same change proposed, because it leaves no record for the check-in to read. If you cannot discharge all three instruments, it is a `[PROPOSAL]`.
+39 -2
View File
@@ -132,17 +132,44 @@ def sec_pause():
return newest, span
def ruled_pendings(reviewed_text):
"""
The set of PENDING ids that rulings actually DISPOSE OF.
Resolved by the PENDING each ruling NAMES in its header, never by the REVIEWED
number. Those numbering sequences have drifted apart: REVIEWED-84 rules on
PENDING-87. Matching on the number alone suppressed PENDING-84 from the wake
digest on the very morning the steward's pulling thread pointed at it, and
closing that item later produced no visible change because it had never been
counted. Measured at the time: 9 suppressed, 8 correctly, 1 falsely.
A ruling whose header names no PENDING (REVIEWED-78, -81, -82 …) suppresses
nothing.
The correction runs in BOTH directions, and an earlier draft of this docstring
claimed otherwise — that it could only ever surface more, never fewer. That was
an overclaim, caught by the change proof rather than by reading. Measured against
the live files at the time of the fix: 3 items surfaced that had been falsely
hidden (PENDING-78, -81, -82 — like-numbered rulings exist, concerning other
matters), and 2 stopped being shown that were genuinely ruled (PENDING-87 by
REVIEWED-84, PENDING-88 by REVIEWED-85 — no REVIEWED-87 or -88 exists, so the
number-match had never suppressed them). Net 18 → 19 visible. Number-matching
was wrong in both directions; only subject-matching is right in either.
"""
return set(re.findall(r"^## REVIEWED-\S+\s*—\s*PENDING-(\S+?)\s*—", reviewed_text, re.M))
def sec_pending():
t = read(PENDING)
if t is None:
warn.append("PENDING.md unreadable")
return []
rt = read(REVIEWED) or ""
rev = {m for m in re.findall(r"^## REVIEWED-(\S+)", rt, re.M)}
ruled = ruled_pendings(rt)
items = []
for h, ln in open_items(t):
m = re.match(r"PENDING-(\S+?)\s*—", h)
if m and m.group(1) in rev:
if m and m.group(1) in ruled:
continue
items.append((h, ln, tag_of(t, h)))
if not items:
@@ -452,6 +479,16 @@ def selftest():
chk("tag_of reads a tag",
tag_of("## PENDING-9 — t\n**Date:** d\n**Tag:** [ESCALATE]\n", "PENDING-9 — t") == "[ESCALATE]")
chk("tag_of returns '' when absent", tag_of("## PENDING-9 — t\n", "PENDING-9 — t") == "")
chk("ruled_pendings resolves by the NAMED pending, not the REVIEWED number",
ruled_pendings("## REVIEWED-84 — PENDING-87 — Order attestation") == {"87"})
chk("ruled_pendings does NOT suppress the like-numbered item [the 2026-08-01 bug]",
"84" not in ruled_pendings("## REVIEWED-84 — PENDING-87 — Order attestation"))
chk("ruled_pendings ignores a ruling that names no PENDING",
ruled_pendings("## REVIEWED-82 — Read-only MCP server: eyes on the substrate") == set())
chk("ruled_pendings handles non-numeric families",
ruled_pendings("## REVIEWED-9 — PENDING-S2 — hook-aware deposit") == {"S2"})
chk("ruled_pendings returns empty on empty input [positive control]",
ruled_pendings("") == set())
chk("extract_anchor pulls verbatim",
extract_anchor("noise\n**PULLING THREAD:** do the thing.\n\nmore", "PULLING THREAD")
== "do the thing.")