# PENDING.md — Authorization Boundary Log **Protocol:** Claude Code appends here at every authorization boundary. David and Claude.app review; decisions are recorded in `REVIEWED.md`. An item is **closed** when a matching `REVIEWED-N` exists there, or when its own header says so. **Scope:** all workstreams — L1/BMF, chamber-library, studium-engine, ARC, Be, governance. **Item families:** `PENDING-` (numeric, the main series) · `PENDING-S` (skill/protocol series) · `PENDING — ` and `COMPLETED — ` (early unnumbered items) · `SESSION-LOG-`. An item is any `## ` header — a parser that assumes one family will miss twenty items, as one did on 2026-07-28. **Archive:** closed items live in `PENDING-archive.md`, original order and numbering preserved. This file carries only what is still open. Numbering is continuous across both files: the next item is one above the highest `## PENDING-` in either — a stated number goes stale, a rule does not. --- ## PENDING-4 — Bug D: Idle stall + batch embedding during replay (CLOSED 2026-08-03 — done since March; the register never caught up) **Date:** 2026-03-22 **Tag:** [FIX] — reclassified from next-PR to this-PR by steward authorization **Summary:** Idle state machine transitions during replay freeze async operations. Batch embedding and vector replay skip reduce Phase 1 from 83 hours to ~10 minutes. **Files affected:** replay-coordinator.ts, bootstrap.ts, ollama-embeddings.ts, vector/index.ts, idle-state-machine.ts **Status:** Implemented and verified. **CLOSED 2026-08-03 — verified against substrate, not taken from the self-assessment.** The `**Status:** Implemented and verified.` line above is the item's own claim about itself; it was checked rather than believed. Corroborated in `BetterMemories.io`: `betterMemories_app#120` (*Phase 2 replay stuck in infinite resource-pause loop*) **closed**, `#133` (*modules report 'ready' during active replay*) **closed**, plus `03b6a78`, `5b14db7`, `decbdee`, and `3332772` (N6, #175 merged) continuing the replay/idle work well past March. **Why it stayed open 4½ months:** the wake digest recognises `(CLOSED)`/`COMPLETED` in a *header*, not a `**Status:**` line in a *body* — so a completed item advertised itself as open every morning. ## PENDING-5 — Recall query path returns 0 results (CLOSED 2026-08-03 — instance resolved via GH; the CLASS is still open at #165) **Date:** 2026-03-22 **Tag:** [FIX] **Summary:** After Phase 1 completes, recall() returns 0 results despite modules reporting ready and vector processing live events. Module dispatch timeouts in query-router. Write path works; read path has separate issue. **Rationale:** This is the next critical blocker after Phase 1 completion. The query dispatch timeout (2000ms for background latency) may be too short, or facet_id filtering mismatches between observe and recall paths. **Files affected:** `src/core/keystone/query-router.ts`, `src/core/keystone/query-types.ts`, possibly `src/modules/vector/queries.ts` **Awaiting:** Investigation — likely needs Seb's input on the query dispatch architecture. **CLOSED 2026-08-03 — the work migrated to GitHub and this register kept a March snapshot.** Seb did the investigation through the issue tracker: `betterMemories_app#124` (*Ollama unavailability silently empties vector query results*) **closed**, `#135` (*temporal query errors silently return empty results*) **closed**, resolved by `bd1f650 feat: typed query status — distinguish 'no results' from 'module failed'` — which is precisely this item's symptom (*"returns 0 results despite modules reporting ready"*). Also `c6689eb` (recall ranking, #120/#80/#89/#107). ⚠ **The instance is closed; the CLASS is not.** `#165 — H2: silent recall failure on battery` is **open, priority:critical, production blocker**, and is the same failure shape from a different cause: recall returning empty without saying so. Closing PENDING-5 must not read as "silent-empty-recall is solved." Tracked at #165, not here — the register should not hold a second stale copy of an issue GitHub owns. ## PENDING-10 — Skip vector embedding during replay (architectural) **Date:** 2026-03-22 **Tag:** [PROPOSAL] **Summary:** Currently implemented as simple early return in handleEvent. For production: should be a formal replay contract where vector stores content metadata during replay without embedding, then a background re-embed pass populates the HNSW index. Paired with Bug D idle stall fix, this makes Phase 1 fast by design. **Awaiting:** Steward + Seb architectural review. **Amendment 2026-08-02 — the item's live scope is larger than its 2026-03-22 body, and has been since June.** This entry describes a *performance* proposal (skip embedding during replay, background re-embed). Both parties now use "PENDING-10" to mean something broader: the **replay-contract audit question** — *"does any BMF surface hold state not reconstructible by replay from the logchain?"* — framed by the steward in `CapableMind-AI/docs/thinking/David/l1-reliability/cover-note-seb-reply-l1-arc-2026-06-06.md` (*"PENDING-10's replay contract, now with a body of evidence"*) and its same-day addendum, and echoed by Seb in the 2026-06-07 reply and again in **issue `CapableMind-ai/betterMemories_app#176`** (2026-08-01), which states the audit is *blocked* on the backup pipeline. **Evidence accumulated since March, none of it recorded here until now:** three convergent datapoints from the steward's scan work (Pebbles' independent reinvention of authoritative-log + derived-disposable-index; memory-os and PMB deep-reads showing the fragile class is always a mutable index as *primary* store; the MemPalace forensic as empirical casualty) — and the concrete trigger, `backup.last_success: null` on mindfabric-00, meaning the instance holding the steward's accumulated memory has single-copy state whose *designed* mitigation is precisely logchain rebuildability. **Why this amendment exists.** The extension was written in cover notes and never written back into the item. Anyone reading this register — including the wake digest, which surfaces PENDING-10 by its title — got the March scope. Same class as the two record-vs-reality divergences found the same day (the digest's ID-matching bug; a REVIEWED disposition clause read as status): **a stable ID whose content has drifted, with no marker that it moved.** **Consequence for the split:** these are two separable pieces of work and should probably be two items. The performance proposal is architectural and awaits review; the audit question is load-bearing for the provenance story and is now scoped inside Seb's #176 restore drill. Splitting them is the steward's call — flagged, not done. ## PENDING-11 — Approve I15 (ICP-9 Pilot Registry Entry: The Accusative Default) (CLOSED 2026-08-03 — REVIEWED-11 AUTHORIZED 2026-03-23) **Date:** 2026-03-23 **Tag:** [PROPOSAL] **Summary:** Approve I15 as the pilot registry entry, validating both the invariant (The Accusative Default) and the `l1_contamination_profile` schema field. Full entry drafted in `relational-gap-registry-amendment.md` §2 since 2026-03-09. **Rationale:** I15 is architecturally upstream — it defines the system's default relational posture (answerable, not sovereign or neutral). It had the cleanest adversarial performance (promoted Tier 2 → Tier 1). The `l1_contamination_profile` field carries real content: monotonic pressure from accusative toward authoritative as memory deepens. Approving I15 unblocks: (1) I16 and I17 drafting (Cluster A), (2) schema validation through a real entry, (3) the `residual_risk` field decision (which can now be made based on evidence from the pilot rather than anticipation). **Registry entry location:** `CapableMind-AI/docs/thinking/David/l2-constitution/amendments/relational-gap-registry-amendment.md` §2 **Jurist recommendation:** YES (from March 8 conversation). Required field for all non-contingent principles. **Steward declaration:** Steward verbally approved 2026-03-23. Awaiting formal record in REVIEWED.md. **Downstream unblocked:** I16 (Asymmetry Obligation), I17 (Precedence of Present Expression), Cluster B entries, `residual_risk` field decision. **Files affected:** Registry (governance metadata, not code). **Awaiting:** Steward entry in REVIEWED.md. **CLOSED 2026-08-03 — the entry it awaits has existed since the day it was written.** `REVIEWED-11 — Approve I15 (ICP-9 Pilot Registry Entry)`, **Date 2026-03-23, Decision AUTHORIZED**, ratifying `l1_contamination_profile` as mandatory for all non-contingent principles and deferring `residual_risk` pending pilot evidence. The downstream this item lists as blocked was ruled months ago: **REVIEWED-15 (I17)** and **REVIEWED-16 (I16)**. Registry file verified present. **Why it stayed open 4½ months — two independent defects, either alone sufficient.** (1) The REVIEWED-11 and REVIEWED-12 blocks are **indented by one space**, so every `^## REVIEWED` anchor steps over them; a fence-tracked census of `REVIEWED.md` finds exactly **3** such orphans (these two and REVIEWED-74). (2) Their headers **name no PENDING**, and resolution is by named item, not by number — so even flush-left they would discharge nothing. Correcting `REVIEWED.md` is **not the executor's to do** (Constitutional Constraint #1); flagged for the steward, closed here instead. ## PENDING-12 — Lodge Design Notes DN-GOV-01 through DN-GOV-04 (CLOSED 2026-08-03 — REVIEWED-12 AUTHORIZED 2026-03-23; all four files verified present) **Date:** 2026-03-23 **Tag:** [HARDENING] **Summary:** File four design notes from the Governance Velocity seed brief into `l2-constitution/`: - **DN-GOV-01**: Constitutional Immunity Specification — governance amendment pace decoupled from capability pace. Candidate for new ICP. - **DN-GOV-02**: Rate-of-Change as Governance Trigger — external acceleration triggers mandatory constitutional review (not amendment). Constitutional emergency clause analog. - **DN-GOV-03**: Baseness Examination Elevation — promote motive examination from practice to formal obligation. System records attestation, not judgment. Requires steward declaration. - **DN-GOV-04**: Pace Governor Artifact — structured weekly PENDING.md digest. Pure tooling. **Rationale:** These emerged from the March 23 jurist conversation on recursive self-improvement and governance velocity. All four address gaps identified when stress-testing L2 governance against I.J. Good's acceleration scenario. Filing as DESIGN NOTE preserves them for cross-strand synthesis without premature constitutional commitment. **Files created:** `DN-GOV-01-constitutional-immunity-specification.md`, `DN-GOV-02-rate-of-change-governance-trigger.md`, `DN-GOV-03-baseness-examination-elevation.md`, `DN-GOV-04-pace-governor-artifact.md` **Steward authorization:** Steward authorized filing 2026-03-23. DN-GOV-03 (baseness elevation) requires separate steward declaration before advancing beyond DESIGN NOTE. DN-GOV-04 (pace governor) is tooling and can iterate without further authorization. **Awaiting:** Steward entry in REVIEWED.md. **CLOSED 2026-08-03 — ruled the same day, and the series ran on without it.** `REVIEWED-12 — Lodge Design Notes DN-GOV-01 through DN-GOV-04`, **Date 2026-03-23, Decision AUTHORIZED** (*"DN-GOV-03 requires separate declaration before elevation. DN-GOV-04 is tooling, iterate freely"*). All four files verified present in `CapableMind-AI/docs/thinking/David/l2-constitution/`. The series continued far past this item — **REVIEWED-13** ruled DN-GOV-05/06/07 and **REVIEWED-14** ruled DN-GOV-08 — so the register was reporting a blocked item whose successors had already been decided. Same two-defect cause as PENDING-11 (indented header; names no PENDING). **Still genuinely outstanding from this item, and NOT closed by it:** DN-GOV-03's *separate steward declaration* before it advances beyond DESIGN NOTE. That is a live steward action with no home now that this item is closed — surfaced 2026-08-03 rather than allowed to vanish with the closure. ## PENDING — ICP-19 Remit Expansion (Observer Problem) **Date opened:** 2026-04-07 **Action required:** Steward-reviewer conversation with the External Auditor before Observer Problem mechanisms advance to constitutional language. **Blocking:** OP-03 (mechanism design phase) **Notes:** Bring OP-02 findings in full. Specifically: - Fault Line 5 (epistemic diversity question) - Fault Line 3 (inquiry examining steward with steward's own tools) - Fault Line 4 (CD-03 Gadamer risk) - The incommensurability named in OP-CN-01 **Status:** PENDING — steward to initiate ## PENDING — Fault Line 1 Response **Date opened:** 2026-04-07 **Action required:** Steward decision on whether to address PENDING/REVIEWED pipeline gap now or await the External Auditor's input first. **Notes:** Jurist assessment: most actionable fault line; does not require external review before mechanism design begins. Steward judgment required. **Status:** PENDING — awaiting steward decision --- ## PENDING — ICP-19 Remit Expansion (CLOSED 2026-08-03 — DUPLICATE of the ICP-19 entry above; the live one is retained there) **Duplicate note, 2026-08-03.** Same subject, same `**Date opened:** 2026-04-07`, same requirement (a direct steward–reviewer conversation on remit expansion before Observer Problem mechanisms advance to constitutional language) as `## PENDING — ICP-19 Remit Expansion (Observer Problem)` earlier in this file. Two records of one obligation, counted twice by every tally and violating *one canonical source of truth per document*. **The substance is not withdrawn** — the prerequisite conversation about the incommensurable foundational positions (OP-CN-01) is preserved in the retained entry, which is the canonical one. Closing the copy, not the obligation. **Title:** ICP-19 External Review — Human-Side Governance Scope **Date opened:** 2026-04-07 **Tag:** [ESCALATE] **Status:** PENDING — requires direct steward-reviewer conversation **Summary:** The Observer Problem inquiry opens human-side governance questions that the current ICP-19 reviewer remit does not cover. Before any mechanisms proposed through this inquiry advance to constitutional language, the human-side governance question should be explicitly added to the External Auditor's reviewer remit, or addressed by a successor reviewer. **Prerequisite:** Direct conversation between steward and reviewer about their incommensurable foundational positions (see Context Note OP-CN-01 §The External Auditor's Comment). This conversation is load-bearing before remit expansion. **Blocking:** Constitutional advancement of Observer Problem mechanisms. Not blocking OP-02 synthesis. --- ## PENDING — CD-03 Operative (CLOSED 2026-08-03 — bookkeeping only: this is a RECORD of an operative declaration, never an open item) **Bookkeeping note, 2026-08-03.** Nothing constitutional is decided or altered here. This entry's own `**Status:**` reads **OPERATIVE — immediate effect**, and its `**Date authorized:**` is 2026-04-07: it is a *notification* that CD-03 is in force, filed in the register because that is where notifications went. The register's tooling reads every `## PENDING` block as an item awaiting authorization, so for four months the wake reported an in-force declaration as an outstanding `[CONSTITUTIONAL]` decision. Marked closed **as a register entry only**. The declaration itself is untouched and remains operative at `CapableMind-AI/docs/thinking/David/l2-constitution/observer-problem/Constitutional Declaration — CD-03.md` — note the path drifted from the one recorded below (`observer-problem/` is now under `l2-constitution/`). CD-03 §IV.4 continues to bind all mechanism proposals. **Title:** Constitutional Declaration CD-03 — The Observer Condition and the Limits of Constitutional Architecture **Date authorized:** 2026-04-07 **Tag:** [CONSTITUTIONAL] **Status:** OPERATIVE — immediate effect **Summary:** CD-03 reorients the purpose of the architecture from infrastructure-toward-solution to infrastructure-toward-honest-inheritance. The architecture can support the conditions under which the sufficient condition (genuine observer calibration) becomes possible, but cannot produce the sufficient condition itself. **Impact:** All subsequent work that proposes mechanisms must be assessed against CD-03 §IV.4: does this mechanism support the conditions, or does it claim to produce the sufficient condition? The latter is a constitutional failure mode. **File:** `CapableMind-AI/docs/thinking/David/observer-problem/Constitutional Declaration — CD-03.md` --- ## PENDING-S2 — Hook-aware deposit detection in wake-up (CLOSED 2026-08-03 — obligation rebuilt as [FIX]; never awaited the jurist) **Date:** 2026-05-18 **Tag:** [PROPOSAL] **Phase 4 — awaits Jurist contract definition.** **Summary:** Wake-up detects whether the previous session ended via wrap-up or via Stop hook alone. Surfaces a warning when hook-only: *"Previous session ended without wrap-up — pulling thread may be absent or incomplete."* Calibrates confidence accordingly. **Rationale:** Audit A4 — the strongest single gap in the ligature. A hook-only deposit lacks pulling thread / literal question / pause statement, but currently looks identical to a wrap-up deposit from wake-up's perspective. Jurist (2026-05-18 shape-review): the hooks/skills contract is *doctrinal, not tooling*. It determines what the unborn session can trust about its inheritance. **Files affected:** `~/.claude/skills/wake-up/SKILL.md` §2.b.1 + §3. **Awaiting:** Jurist shape-review of contract language (candidate text in Jurist shape-review document: *"The authoritative deposit is a wrap-up deposit. A hook-only deposit is an emergency fallback, not a complete inheritance. Wake-up must detect which it received and calibrate accordingly."*). Then steward authorization. **CLOSED 2026-08-03 — obligation harvested, mechanism rebuilt as `[FIX]`.** The `Awaiting` line above was **wrong for 2½ months**: the jurist affirmed Q1 on 2026-05-18 and explicitly assigned the contract to the steward — *"CC cannot define what 'authoritative deposit' means — that's constitutional language, and it belongs to you."* Nothing was ever awaited from the jurist. Meanwhile the premise died: no Stop hook is configured, and MemPalace — whose `mempal_save_hook.sh` was the deposit — is retired, steward-ruled 2026-08-03 (*"MemPalace is retired and any associated functionality also, except some of the concepts we harvested and implemented in our own way"*). **The obligation survived its instrument**: `wake-digest.py` computed `Last wrap` from mtime, so a session ending without `/wrap-up` left the next wake reporting an *older* session's thread as current, silently. Rebuilt on our own substrate — the transcripts are the only witness that a session ran. `sec_unwrapped()` + `transcript_span()` + `wrap_inside()`, self-tested with four unit controls and a **discrimination check over real sessions (11 wrapped / 2 unwrapped)**; the warning states what it does not establish. No doctrinal contract required — the mechanism is now ours, not a cross-repo hook. Two real unwrapped sessions found in history: 07-28 06:07, 07-29 16:21. --- ## PENDING-S4 — Post-compression marker; cross-repo with mempalace (CLOSED 2026-08-03 — WITHDRAWN with MemPalace; concept kept as a Symmetria §3 flag) **Date:** 2026-05-18 **Tag:** [PROPOSAL] **Phase 4 — cross-repo coordination.** **Summary:** PreCompact hook (`~/_Dev/mempalace/hooks/mempal_precompact_hook.sh`) writes a marker diary entry (topic: `session-compaction`) when it fires. Wake-up detects this marker; if present, warns that confidence claims in that session inherit a lossy view. Symmetria adds a post-compression contamination flag (paired with §3 application work in S6). **Rationale:** Audit B4 + D4. The PreCompact event currently silent to all downstream consumers; this makes it observable. **Files affected:** `~/.claude/skills/wake-up/SKILL.md`; `~/.claude/skills/symmetria/SKILL.md` §3; `~/_Dev/mempalace/hooks/mempal_precompact_hook.sh` (upstream PR or steward-coordinated change). **Awaiting:** Jurist contract definition (Q1); steward authorization; mempalace upstream coordination. **WITHDRAWN 2026-08-03 — MemPalace-associated functionality, retired with it** (steward ruling: *"MemPalace is retired and any associated functionality also"*). The marker was to be a MemPalace **diary entry** written by `mempal_precompact_hook.sh`; no PreCompact hook is configured, and the diary no longer exists. **The concept was harvested rather than lost**: post-compression confidence claims are now a standing Symmetria §3 contamination flag (*"the working memory was trimmed; what feels certain now may rest on what was lost"*), landed with S6 the same day. That is the durable half — a flag needs no hook to fire. --- ## PENDING-S5 — Authoritative-diary marker; wrap-up ↔ Stop hook (CLOSED 2026-08-03 — WITHDRAWN; the race it names can no longer occur) **Date:** 2026-05-18 **Tag:** [PROPOSAL] **Phase 4 — cross-repo coordination.** **Summary:** Wrap-up's diary write carries an explicit `authoritative: true` marker (or AAAK equivalent). Stop hook (`~/_Dev/mempalace/hooks/mempal_save_hook.sh`) checks for a recent authoritative entry and skips its block if present. **Rationale:** Audit C3. Currently a wrap-up + subsequent hook fire may produce two diary entries from different AI states. The second one (post-wrap-up, depleted context) is silently mistaken for the canonical entry by future wake-ups. **Files affected:** `~/.claude/skills/wrap-up/SKILL.md` §4.b; `~/_Dev/mempalace/hooks/mempal_save_hook.sh`. **Awaiting:** Jurist contract definition (Q1); steward authorization; mempalace upstream coordination. **WITHDRAWN 2026-08-03 — the race it names can no longer occur.** Both parties to the collision are gone: the MemPalace diary (retired 2026-07-07) and the Stop hook that wrote the second entry (`mempal_save_hook.sh` — not configured; live hooks are `SessionStart`, `UserPromptSubmit`, `PreToolUse`, `PostToolUse`). With a single writer — `/wrap-up` writing the session memory file — there is no depleted-context second entry to be mistaken for the canonical one. Withdrawn as **discharged by events**, not deferred. Distinguished from S2 deliberately: S2's obligation outlived its instrument and was rebuilt; S5's obligation died with the substrate that created it. If a second automated writer of session records is ever introduced, this item is the precedent to re-open. --- ## PENDING-S6 — Symmetria §3 contamination flag applications of the Directive elaboration (CLOSED 2026-08-03 — IMPLEMENTED) **Date:** 2026-05-18 **Tag:** [HARDENING] **Phase 3b — depends on S0 (now CLOSED).** **Summary:** Extend `~/.claude/skills/symmetria/SKILL.md` §3 contamination flag list with applications of the now-constitutional time-the-task-requires principle, plus three other self-flags surfaced by the audit: - **Lectio** (corpus reading): take the time the corpus asks for. - **Diagnose-don't-fix** (debugging): trace the class of failure before patching the instance. - **Dwell-on-composition** (writing): the recommendation gets the time it wants, not the time the executor wants the recommendation to take. - **Alignment pulse returning `aligned` without naming a specific tension** — premature-closure (D1). - **Search queries shaped by what the session wants to find** rather than what it needs to find (D5). - **Post-compression confidence claims** — the working memory was trimmed; what's certain now may rest on what was lost (D4; pairs with S4). **Rationale:** Audit D1/D4/D5 + the principle elevation. §3 currently flags external code and writing patterns; with the Directive elaboration in place, applications of it at the discipline level are coherent additions, not scope-creep. **Files affected:** `~/.claude/skills/symmetria/SKILL.md` §3. **Awaiting:** Steward authorization (S0 closure unblocks). **IMPLEMENTED 2026-08-03** — `~/.claude/skills/symmetria/SKILL.md` §3. All six flags landed: the three time-the-task-requires applications (lectio · diagnose-don't-fix · dwell-on-composition) grouped as one entry under the now-constitutional Q4 elaboration, plus premature-closure-pulse (D1), query-shaped-by-what-it-wants-to-find (D5), and post-compression-confidence (D4). D4 is retained on its own merit though S4 was withdrawn the same day — compaction still occurs; only the MemPalace marker died. Unblocked since Q4 landed in `~/CLAUDE.md`; the delay was bookkeeping, not dependency. --- ## PENDING-S7 — Symmetria `check` mode: add `suspend` outcome (CLOSED 2026-08-03 — IMPLEMENTED; Q5 was affirmed 2026-05-18) **Date:** 2026-05-18 **Tag:** [HARDENING] **Phase 5.** **Summary:** §6 `check` mode outcomes extend from `proceed / return-and-reframe / escalate` to `proceed / return-and-reframe / suspend / escalate`. `suspend` = hold for unhurried steward judgment without urgency. **Rationale:** Audit D3 + Jurist confirmation. Today's audit was the missing-shape example: neither escalate (urgent) nor return-and-reframe (the audit is the right work) fit. With the Directive elaboration in place, `suspend` is the natural outcome — *the time the steward's judgment requires is task-time, not interruption-time.* **Files affected:** `~/.claude/skills/symmetria/SKILL.md` §6 (check). **Awaiting:** Steward authorization. **IMPLEMENTED 2026-08-03** — `~/.claude/skills/symmetria/SKILL.md` §6 now reads `proceed | return-and-reframe | suspend | escalate`, with `suspend` defined against its two neighbours (not `escalate`, which carries urgency; not `return-and-reframe`, which says the work is wrong) and required to name what is suspended and what would resume it. The header's *"awaiting Q5"* was stale: **Q5 was affirmed 2026-05-18** (*"Yes, add it"*), conditional only on Q4, which has since landed. Used in this session before it was written — the hold on CONTROL-A v2 is a `suspend`, not an `escalate`. --- ## PENDING-S9 — Wrap-up §8 output template enriched to match practice (CLOSED 2026-08-03 — IMPLEMENTED; Q2/Q3 were affirmed 2026-05-18) **Date:** 2026-05-18 **Tag:** [HARDENING] **Phase 5 — depends on Q2 + Q3 (Q3 confirmed by Jurist).** **Summary:** §8 output template in wrap-up expanded to mirror the three-tense richness the steward already produces in session memory files: Past / Present / Future as named sections, with required fields under each. Subsumes S1 if implemented together; or S1 lands first as smaller increment and S9 follows as deeper revision. **Rationale:** Audit C5 diagnostic — template under-specifies what good practice already does. With the Directive elaboration in place, an output template that drops the practice's load-bearing tenses under compression is itself an instance of the failure mode the principle catches. **Files affected:** `~/.claude/skills/wrap-up/SKILL.md` §8. **Awaiting:** Steward authorization. Optional relationship to S1: implement S1 first (minimal additive), then S9 as deeper revision; or fold S1 into S9 as single revision. **IMPLEMENTED 2026-08-03** — `~/.claude/skills/wrap-up/SKILL.md` §8 restructured into the three tenses. S1 had already landed (archived), so this is the deeper revision on top of it. **The diagnosis was exact and sharper than the item stated: Future was already well-specified — pulling thread, resumption point, literal question, and Q3's constitutive pause statement were all present — while Past and Present were *wholly absent*.** Added: what-happened / what-held / what-was-corrected (Past) and the-mood / confidence-to-recalibrate (Present), with deferred-decisions and skill-harvest relocated under Present. Future deliberately still leads, inverting the memory file's narrative order: the steward reads this at departure, but it is written for arrival. Q2 was affirmed 2026-05-18 and Q3 elevated to constitutive the same day; both had landed. Every pre-existing field survives — none dropped. --- ## PENDING-78 — Claude.app personal preferences: three verified-false claims **Date:** 2026-07-27 **Tag:** [ESCALATE] — steward-held document; the executor verifies, the steward edits. **Summary:** The `.app` preferences carry the same drift class as `~/CLAUDE.md`, including one identical stale pointer. **Jurist: outside the amendment's reach entirely** — not `~/CLAUDE.md`, not governed by L253, so no outcome on PENDING-76 touches this. **Verified false 2026-07-27:** 1. *"branch: `fix/replay-durability-contracts`"* — merged as `c9746ae`; `HEAD` is `main`. The identical stale pointer also heads this file (`PENDING.md` L3). 2. *"`COWORK.md`"* named as a governance document — no such file exists anywhere under `~`; the only `cowork*` hits are Claude Desktop application internals. 3. *"L2 constitutional governance is blocked pending L1 stability"* — L1 has 0 commits in 14 days. Blocked pending something dormant is not a governance state. **Also observed, not proposed:** ARC described as *"near-operational"* (Stage G sealed; 152 commits/60d, understated); chamber-library and studium-engine absent (183 and 41 commits/60d). **⚑ For the steward and jurist, not the executor:** The Chamber is named in the `.app` preferences and **absent from `~/CLAUDE.md`**. The jurist ruled this *"the most consequential single finding in the package"* and noted the executor had filed it as a footnote: *"The jurist knowing about work the executor is blind to is not a documentation defect. It is a governance model with two parties holding different maps."* **Files affected:** Claude.app personal preferences (steward-held). Executor modifies nothing. **Awaiting:** Steward edit; jurist review of the asymmetry. ## PENDING-81 — Keeping CLAUDE.md and the Claude.app preferences fresh with respect to each other **Date:** 2026-07-28 **Tag:** [ESCALATE] — steward-held document, and one finding touches the party structure itself. **Summary:** The two governance documents cannot be kept in sync by the same mechanism, because their readers differ in one decisive way. Extends PENDING-78 with findings only possible now that the executor has seen the preferences' text. **The structural fact that determines everything else.** `~/CLAUDE.md` is read by an executor **with** filesystem access, so its state can be *computed* — which is why `governance-drift-check.py` works and why leg C could replace §Active Projects with a pointer. The `.app` preferences are read by a jurist with **no** filesystem access. Their state therefore cannot be computed at read time; it can only be cached. **Confirmed by substrate:** the live preferences are not on disk in any readable form — the only hits are March-era snapshots under `~/Library/Application Support/Claude/local-agent-mode-sessions/`. No instrument here can ever check them. So the goal is not "make them derived." It is: **keep the cache small, generate it, date it, and track its age.** **Findings (new, from reading the preferences text):** 1. **⚑ The two documents disagree on the party structure.** `CLAUDE.md` L88–90 names three parties: David / Claude.app / Claude Code. §Your Role names **Cowork** as a fourth with its own governance document `COWORK.md`, while calling the model three-party. `COWORK.md` is real but orphaned — `# COWORK.md — Global Instructions`, dated Mar 22, inside an agent-mode session sandbox. This is doctrine welded to a retired instrument, the same shape as the MemPalace weld, but at the constitutional layer. **Needs a ruling, not a refresh: is Cowork still a party?** 2. **The jurist's map is inverted relative to the substrate.** §Standing Context names L1 as active development. Commits in the last 30 days: **chamber-library 165, studium-engine 25, CapableMind-AI 5, BetterMemories.io 0, ARC 0.** The two highest-activity workstreams appear nowhere; Be is absent entirely. The Chamber is named in §Who I Am as a thing the steward *designed*, giving no signal that it is the live work. 3. **ARC "near-operational"** understates it in a misleading direction — Stage G sealed 2026-06-10, and its 0 commits/30d mean *finished and quiet*, not *nearly ready*. 4. **"Divorce: Settled, awaiting signing March 30, 2026"** — that date is four months past. Steward-held and unverifiable from here; flagged only because "awaiting" a past date reads as current. 5. Confirmed from PENDING-78: the `fix/replay-durability-contracts` branch pointer (merged; HEAD is `main`) and "L2 blocked pending L1 stability" (L1 dormant 30 days). **The good news: the document is already correctly tiered.** §Who I Am, §Your Role, §Intellectual Operating System, §How We Work Together and §Communication are doctrine and identity — they do not drift. **Every finding above except #1 sits in §Standing Context.** So the fix is small: one section gets a cadence. **Proposed mechanism:** - Split §Standing Context into **`### Standing Context — Projects`** (generated, dated, replaced wholesale) and **`### Standing Context — Personal`** (hand-held). - Generate the first with `python3 ~/dotfiles/scripts/wake-digest.py --brief` (built 2026-07-28): tracker index, open authorization items, last rulings, 30-day commit counts per repo, drift count, and an explicit `generated ` header instructing the reader to treat it as unverified after ~30 days. ~1k tokens. - **Never generated:** the orchestra conflict, fraternal practice, and family/legal entries. They are steward-held, unverifiable from any substrate, and the generator is scoped to exclude them by design, not by convention. - The wake reports the brief's age when it exceeds 30 days, and says plainly that it tracks **generation, not pasting** — a lower bound on the jurist's staleness, never a guarantee of freshness. This is the honest limit of what can be instrumented across a boundary we cannot read. **Why this beats the alternative.** A pointer ("see `~/CLAUDE.md`") is useless to a reader who cannot open files — which is precisely why the preferences accumulated duplicated state in the first place. The duplication is structurally required; only its staleness is optional. **Files affected:** Claude.app personal preferences (steward edits). Already landed, detection/generation only: `~/dotfiles/scripts/wake-digest.py --brief`. **Awaiting:** Steward decision on finding #1 (is Cowork a party?), and authorization for the §Standing Context split. ## PENDING-82 — Read-only MCP server: giving the jurist eyes on the substrate **Date:** 2026-07-28 **Tag:** [PROPOSAL] — new interface between two governing parties. Built and self-tested; **not installed.** Installing it edits the steward's desktop-app config. **Summary:** `~/dotfiles/scripts/governance-mcp.py` publishes the governance substrate to Claude.app's chat surface as five read-only tools, closing the gap PENDING-81 could only narrow. Supersedes PENDING-81's premise that a generated cache is the best available answer — for chat, it is no longer the only one. **The gate PENDING-81 left open is answered, and my framing of it was backwards.** Steward-confirmed 2026-07-28: local MCP servers configured in `claude_desktop_config.json` are exposed to the **chat** surface, and have been since roughly a year before Cowork existed — never Cowork-gated. Cowork gets them *conditionally*: local sessions inherit them, remote sessions — now the default execution mode being rolled out — do not run local MCP at all. So the relationship is not "chat, not only Cowork" but **"chat, always; Cowork, only while it still runs locally."** The jurist chat sits on the stable side of that split, which makes this design *less* exposed to product drift than the Cowork-dependent one considered and rejected on 2026-07-28. **Substrate check:** `claude_desktop_config.json` has **no `mcpServers` key** (top-level keys: `coworkUserFilesPath`, `preferences`). Its `preferences` block is app **UI state** — sidebar mode, pinned panes, Cowork toggles — *not* the jurist's Standing Context prose. Name collision only; PENDING-81's finding that the live preferences are nowhere on disk **stands unrevised.** **What it exposes (five tools, all read-only):** - `governance_state` — every open item with its `[TAG]`, recent rulings, drift count, per-repo status. Computed per call. - `governance_item(id)` — the **verbatim** body of any item or ruling, across `PENDING.md`, `PENDING-archive.md`, `REVIEWED.md`. This is the capability a pasted cache can never have: the jurist can read the thing it is ruling on. - `governance_read(file, offset, limit)` — verbatim paged read of one of six enumerated documents. - `drift_report()` — full `governance-drift-check.py` output. - `repo_activity(repo, count)` — branch, dirty count, recent commits. **Four refusals designed in, each with a control that proves the refusal detectable:** 1. **Read-only.** No tool writes. Audited by AST, not by text search: 0 filesystem-mutating calls, git subcommands present = `{log, status}` only. A write path would collapse three parties into one. 2. **Not an agent.** Tools return data, verbatim where possible. The rejected alternative — a second Claude with filesystem access reporting back — yields *an agent's testimony about the substrate*, not the substrate. 3. **No second parser.** "An item" is defined once, in `wake-digest.py`'s `item_spans()`, imported here. A private second definition is how twenty items went missing on 2026-07-28. 4. **No path arguments.** Every tool takes a key from a fixed enum. There is no traversal to defend because no path is accepted; the reachable domain is enumerable rather than defined by the instrument. **Verified:** 29 self-test controls pass, 0 fail (`governance-mcp.py --selftest`; counted from the run, not estimated — the first draft of this line said 27). Each absence is paired with a same-run positive control (Q2). `wake-digest.py --selftest` holds at 19. Plus a live stdio round-trip — `initialize` → `notifications/initialized` (correctly unanswered) → `tools/list` → two `tools/call` → malformed input survived as a `-32700` rather than a crash; stdout carried only JSON-RPC, stderr empty. **[FIX] applied to the shared definition while here.** `item_spans()` is now **fence-aware**: a `## ` header inside a fenced code block is neither an item nor an item boundary. Zero such headers exist in the substrate today, so behaviour is unchanged (17 open items before and after) — but governance drafts are written as fenced markdown carrying `## REVIEWED-N` headers, per the steward's own copy-paste-clean practice, so the next such draft would have created a phantom item *and* truncated the real item containing it. Latent defect with a live trigger, not a hypothetical. **⚑ A false pointer in yesterday's own resumption point.** It stated the two §Your Role edits were "drafted verbatim in the transcript **and in PENDING-81**." They are not in PENDING-81; they existed only in a transcript discarded at the restart. Same wrap that mis-stated the archive. The lesson is the one already in doctrine: *a draft that lives in a transcript is not a record.* Re-drafted below, in the file this time. **Installation (steward's hand — it edits the app's config, and the app must restart):** ```json { "mcpServers": { "governance": { "command": "python3", "args": ["/Users/davidglidden/dotfiles/scripts/governance-mcp.py"] } } } ``` Merge that `mcpServers` key into `~/Library/Application Support/Claude/claude_desktop_config.json` alongside the existing `coworkUserFilesPath` and `preferences` keys, then restart Claude.app. Reversal is deleting the key. **Cowork retirement — §Your Role replacement text (re-drafted; the steward places it, since the surrounding prose is not readable from here):** > Three parties hold distinct roles: **steward** (David) authorizes; **jurist** (Claude.app) proposes and governs; **executor** (Claude Code) implements within authorization. Delete the Cowork party entry and every reference to `COWORK.md`. Grounds, now two: a third executor costs a third doctrine copy of a document that is `CLAUDE.md` with the nouns changed; and Cowork could not have served as the jurist's filesystem eyes even in principle, since `coworkUserFilesPath` points at `~/Claude`, which does not exist, and remote Cowork — the incoming default — runs no local MCP at all. **Files affected:** new `~/dotfiles/scripts/governance-mcp.py`; `~/dotfiles/scripts/wake-digest.py` (`item_spans()` fence-awareness + 3 controls). Awaiting steward hand: `claude_desktop_config.json`, Claude.app §Your Role and §Standing Context. **Awaiting:** ~~Steward authorization to install~~ → **INSTALLED AND IN USE. CLOSED 2026-08-08.** --- ### AMENDMENT 1 — 2026-08-08, discharged by events; the item's substrate check is stale **§A — INSTALLED.** The item's 2026-07-28 substrate check recorded *"`claude_desktop_config.json` has **no `mcpServers` key**"*. Verified today: top-level keys are **`mcpServers`, `coworkUserFilesPath`, `preferences`**, and `mcpServers` contains **`governance`**. The gate this item waited on has been passed. **§B — And it is not merely installed, it is LOAD-BEARING.** Empirically, in a single day: the jurist used `governance_read`, `governance_item`, `governance_search` and `governance_state` across **three consecutive rulings**, opened `graduation-spec.yaml` L1–60 directly, and **refused to rule from the executor's summary** — *"ruling from the executor's summary of its own mandate is exactly the shape I should refuse."* That refusal is the capability this item existed to create, exercised. It also caught, from substrate the executor had quoted, an adverse ratified ruling the executor had missed (REVIEWED-53). **§C — ⚠ Two residuals, carried not buried.** (1) **The `governance_read` enum does not reach everything a ruling may rest on** — `conversion-runbook.yaml` and the R0 contract are reachable by **no key**, and one ruling had a leg in executor testimony until the steward relayed the files by hand. The remedy is its own extension mechanism: **the server takes keys from a list, so extending the list is the fix.** Recorded in this item's earlier amendment; it survives this closure as a **named follow-on**, not a reason to hold the item open. (2) The installed surface differs from the description above — **8 keys, not "six enumerated documents"**, and a `governance_search` tool the five-tool list does not name. The description is stale; the substrate is authoritative. **Closed:** the proposal was to build and install a read-only substrate interface for the jurist. It is built, installed, used, and has demonstrably changed rulings. What remains is a **bounded extension of an existing, working thing**, which is a different item. ### AMENDMENT — 2026-08-08, a concrete enum, from a ruling that hit the wall The jurist ruling on PENDING-121 established this gap **empirically**. `governance_read` takes a key from a fixed enum — `app-brief`, `chamber-spec`, `claude-md`, `graduation-spec`, `memory-index`, `pending`, `pending-archive`, `reviewed`. **`conversion-runbook.yaml` and `r0-reading-index-contract.md` are reachable by NO key**, so a ruling resting on them rests on executor testimony — and that ruling had one leg in exactly that state until the files were relayed by hand. **The gap is also its own remedy:** the server takes keys from a list, so **extending the enum IS the extension mechanism.** Adding `conversion-runbook` closes the chamber half immediately. The R0 contract is D-1 engine-side, so its inclusion is a standing question rather than a tooling one. ⚠ **Also noted, no action asked:** the 2026-07-10 general-statement ratification lives in `hash-locality-ratification-and-lane-narrowing-JURIST-RULING-2026-07-10.md`, which the register **references but does not contain**, and no tool reaches; PENDING-47's log twice records a `docs/` copy as owed. **A ratification the register can only point at is a thinner record than one it holds.** *Filed here rather than as a new item: this is PENDING-82's subject exactly, and a second home for it would be the fault this week keeps ruling against.* ## PENDING-84 — Nine canonicals whose banked sources carry no extractable text at all (TRIAGED + CLOSED 2026-08-01 — the defect is dispositioned, not repaired; see the census) **Date:** 2026-07-28 **Tag:** [HARDENING] **Summary:** Nine canonicals resolve to archived sources with zero embedded fonts and zero extractable words (bare scans), yet their canonical texts exist — so the text came from somewhere that is not mechanically recoverable from the source of record. **Rationale:** Surfaced by the PENDING-83 census and docketed separately on the jurist's process note (PENDING-55 residual-item precedent: findings named-not-lost still have to be findable). Whatever produced these canonicals cannot be re-derived from the banked source by any extraction, which means they are unverifiable against their own provenance by *any* tier's method — not V-SCAN's, not a future V-DPDF's. This is a distinct condition from "hard to verify": it is "no mechanical path from the source of record to the canonical exists." Instances observed 2026-07-28 include `mal-darchive` and `on-textual-understanding-szondi`; the full set of 9 is in the census. **Recommendation:** Read one end-to-end first — establish what actually produced the text (a prior OCR run whose output was not banked? a different edition?) before proposing a class remedy. Diagnose the class, but from one real instance rather than from the count. **Files affected:** none yet — diagnosis precedes any change. **Awaiting:** Steward triage of priority. Not urgent; not to be lost. ### PENDING-84 — DIAGNOSIS (2026-08-01), from one instance read end-to-end, then bounded across the class **The nine are six works, and the count concealed that.** Reproduced by re-running the classifier over Chamber Sources: 9 bare-scan sources, of which **four are one work** — Alexander's *Nature of Order* vols 1–4. The rest: `detail-in-typography-hochuli`, `mal-darchive`, `on-textual-understanding-szondi`, `pedagogical-sketchbook-klee`, `typography-ruder`. Diagnosing "nine canonicals" invited a class remedy for what is six conversions, four of them one batch. **The instance read end-to-end: `mal-darchive`. What produced the text is already recorded in our own runbook — it did not need investigating, it needed reading.** `_curation/conversion-runbook.yaml` `known_gaps.research`, dated 2026-07-12: *"Docling+OCR CROSSES this frontier — it OCR'd a scanned French book (mal-darchive) with 104 footnotes + full page-provenance, 0 cruft, on the M4 (~11min)."* So the canonical came from an **OCR inference run during the PENDING-56 four-tier trial**, whose output was never banked as a derived artifact. That is why no extraction reproduces it: the source is a bare scan, extraction yields nothing, and the text exists only as the output of a model run that was not retained. The canonical still carries the run's signature — 137 `` markers, matching the "full page-provenance" claim. **And the same runbook entry names the damage, in the same breath:** *"output is readable but NOT verbatim-clean (glued words, I→1, dropped accents)"*. Measured against the corpus rather than assumed: French canonicals carry **255.8 accented letters per 10,000 characters** (median, n=34; top of range 263–309 — Proust 275.8, Camus 268.1, Foucault 287.5). `mal-darchive` carries **0.4**. Zero overlap, a ~600× gap. Its diacritics are not reduced, they are **gone** — `Conference prononcee le 5 juin 1994 a Londres`, `Galilee`, `Ne commencons pas`, `Deja`, `soupconnons`. Under §V that is **Tier-3 alteration by omission on nearly every line** of a French text, and it is the same shape REVIEWED-70 ruled on for character-bearing images: *"a lexical change no less than a substitution would be."* The work is in canon in that state. **The class-level finding, and it is not the one the item names.** All nine were checked for the §V mandatory conversion record: **9 of 9 have none.** Seven have no frontmatter at all (`mal-darchive`, `detail-in-typography-hochuli`, all four Alexander volumes, `pedagogical-sketchbook-klee`); the two that do (`on-textual-understanding-szondi`, `typography-ruder`) carry no conversion field either. §V: *"Every conversion — OCR or EPUB, first-run or re-extraction — **must** produce a conversion record."* §VII: *"A canonical text without a conversion record is not verifiable and cannot enter canon."* **Nine canonicals are in canon in violation of that clause.** The missing record is the actual defect: it is *why* the producing run is unknown, and it is a condition the corpus can repair without re-running any OCR. **The class is also wider than bare scans — the condition is "no mechanical path," not "no extractable text."** Found while closing PENDING-85: `ulysses-james-joyce` resolves to `Ulysses (Cliffs Notes) (James Joyce).pdf`, matched `match_cov: 1.0, match_conf: high` on title-plus-author. Its canonical is the real Penguin *Ulysses* (288,602 words, `conversion_method: calibre`, source unbanked). A wrong work banked with abundant extractable text produces exactly the same condition as a bare scan. Any census scoped to `verdict == bare-scan` will keep missing this member, and the source-matcher's own step-4 warning already predicted the failure mode: *"A high title-match is NOT proof."* **What this diagnosis does NOT establish, stated so it is not read as settled:** the producing run is *documented* for `mal-darchive` and inferred-by-family for the four Alexander volumes (the runbook names Alexander as the ocrmac multi-column case and records "the page-number method (Alexander 9/9)"); **Hochuli, Szondi, Klee and Ruder were not traced** — that is four works still genuinely unknown, and I did not read them end-to-end. Diacritic loss was measured for the French instance only; the English-language members give no diagnostic signal from that measure and need a different probe. No remedy is proposed here, and nothing was changed. **Falsifiers, one command each:** `grep -n "mal-darchive" _curation/conversion-runbook.yaml` returns the 2026-07-12 entry with the dropped-accents caveat; `head -1` on any of the seven shows no `---`; the accented-letter rate is a four-line script over `canonical_texts/**/*.md`. If any of the nine turns out to carry a conversion record, the class finding fails. **Awaiting (unchanged in kind, sharper in content):** steward triage. The cheapest closable piece is the **conversion-record gap** (a records defect, no OCR re-run); the expensive piece is `mal-darchive`'s diacritic restoration, which requires re-conversion, not repair. ### PENDING-84 — TRIAGE + CLOSURE (2026-08-01, steward-directed) **The item's own question — "steward triage of priority" — is answered, so the item closes. The corpus defect does not: it is dispositioned and relocated to a durable artifact, not repaired.** Saying otherwise would be the false-closure shape this corpus exists to prevent. **What was built: the §VII quarantine artifact — `_curation/provenance-gap-2026-08-01.tsv`.** Nine rows: canonical slug · path · live sha256 · frontmatter present · source file · source sha256 · condition · converter · **converter_basis** · evidence. **Zero canonical bytes changed** — no hash churn, no re-anchor, and the binding surface was checked first: all nine are catalogue-bound but **unbound in the engine** (no `corpus/manifest.yaml` entry, no sidecar, no reading-index), so the blast radius is chamber-only and this artifact does not even touch it. **Why a separate file and not frontmatter — the constitution rules it, and the ruled case has now arrived.** §VII: *"a datum provable only by production, never by an independent gate, goes to a **quarantine namespace trusted consumers structurally cannot read** (a separate sidecar or `_unverified.*`), never a first-class field under a soft gate — **this quarantine lane is the designed answer for a case that has not yet arisen; designed, not built.**"* These nine are precisely that case: their provenance is provable only by the production run, never by an independent gate. Writing it into canonical frontmatter would place production-only provenance in the trusted namespace, where **presence would read as compliance** — PASS-BUT-FALSELY, in the exact field whose absence is the defect. The lane was designed for a hypothetical; the hypothetical is here. **`converter_basis` is the load-bearing column, and it is three-valued on purpose** (attest-never-default): **attested** = a durable record names the run — 1 of 9, `mal-darchive`, on the runbook's own 2026-07-12 entry; **inferred** = family-level evidence only, explicitly *not* a conversion record — 4 of 9, the Alexander volumes, on the runbook naming Alexander as the multi-column ocrmac case and recording "the page-number method (Alexander 9/9)"; **unknown** = no evidence found and none guessed — 4 of 9: Hochuli, Szondi, Klee, Ruder. **What this explicitly does NOT do:** it does not satisfy §V, does not make any of these texts verifiable, and does not lift the §VII bar on canon entry. **The violation stands.** What changed is that it is now *legible* rather than silent — which is the whole of what a records act can honestly buy. **The remedy, scheduled rather than deferred (a named order, not a vague later):** 1. **`mal-darchive` — first, and it is the only one with demonstrated text damage.** Diacritics measured at 0.4 per 10k against a French-corpus median of 255.8 (n=34): Tier-3 alteration by omission on nearly every line. Requires **re-conversion**, not repair; the source is a bare scan, so this is an OCR run (M4), and the runbook's own caveat predicts the failure mode to guard against. 2. **The four Alexander volumes — one batch, one campaign.** No demonstrated text damage; the defect is the missing record. They are a single work in four volumes and should be re-converted together or not at all. 3. **Hochuli, Ruder, Klee — schedule against chamber-typography**, which is the workstream that actually reads them. Szondi against whichever workstream calls for it. **Nothing here is urgent by exposure**: none of the nine is engine-registered, so none is currently serving the engine as verified text. **Falsifier:** if any of the nine turns out to carry a conversion record, or to be engine-bound, the census row is wrong and the disposition needs revisiting. Both are one grep. ## PENDING-85 — Two PDF-origin classifier verdicts require human eyeball before any per-file use (CLOSED 2026-08-01) **Date:** 2026-07-28 **Tag:** [FIX] **Summary:** Two of the 60 classified canonical PDF sources carry verdicts the classifier's own numbers make doubtful, and they must be eyeballed before any per-file verdict is relied on. **Rationale:** `the-arcades-project-walter-benjamin-pdf` classifies born-digital on **1,664 embedded fonts** — a count far more characteristic of OCR output than of typesetting, suggesting a scan whose page images fall below the classifier's page-image threshold. `function-of-dynamics-haydn-mozart-beethoven` reads **4,537 words/page on 1 font**, implausible for a book page and probably an extraction artefact. Both were stated as caveats on the instrument's own output (§VII: a measurement carrying a known reliability caveat states it in the same breath as its count) and the jurist affirmed they were correctly held out of the PENDING-83 population claim. The population claim (16/44) does not depend on either. **Recommendation:** Open both PDFs and look. This is §VII's eyeball-after-gate, which the spec names as the genuine ceiling where no stronger mechanical check exists — not a deferral. **Files affected:** none — a reading task; may yield a threshold correction to the scratchpad classifier. **Awaiting:** Nothing blocking; do before the classifier's per-file verdicts gate anything. ### PENDING-85 — DISPOSITION (2026-08-01): both eyeballed. One verdict WRONG, one CORRECT with the doubt misdiagnosed — and the class is larger than two. Executed as §VII eyeball-after-gate: pages rendered with `pdftoppm` and read, not inferred from metadata. The classifier (`classify_pdf_origin.py`) was re-run first with `--selftest` PASS 8/8 including its live Harrison control, and both verdicts reproduced exactly (502.9 w/pp · 1,664 fonts; 4,537 w/pp · 1 font). **1. `the-arcades-project-walter-benjamin-pdf` — verdict WRONG. It is `scanned-with-OCR`, not born-digital.** `Producer: Adobe Acrobat 9.2 Paper Capture Plug-in with ClearScan` — Paper Capture *is* Acrobat's scan-OCR module, and ClearScan replaces the scanned bitmap with fonts synthesised per glyph-shape. 923 of the 1,664 fonts match `Fd-Identity-H` CID Type 0C (a deliberately conservative pattern — the true synthetic count is higher; stated as an under-count per §VII). Rendered p.440 settles it visually: baseline wobble, uneven inter-word spacing, blob artefacts (`ba■ly`, a stray mark after `1804,`), a spurious mid-word dot in `Gour·don`, broken glyphs in `communication`, and a running head whose ornament is recognised as `M`. The canonical carries matching damage — `converted_with: pdftotext`, and fragmented OCR-line headings (`## Prepared On The` / `## The Basis` / `## Basis Of The` / `## The German Volume` / `## Volume Edited`). 512,549 words. This work belongs to the scan tier, where eyeball-after-gate already governs. **2. `function-of-dynamics-haydn-mozart-beethoven` — verdict CORRECT; the stated doubt is refuted; a worse defect is underneath it.** `Pages: 1`, page size **1083 × 6882 pt** — one sheet ≈ 9.6 letter pages, `Producer: macOS … Quartz PDFContext`. So 4,537 words/page is arithmetic on a page count of one (≈470 words per notional page) and is **not** an extraction artefact. It is genuinely born-digital. But the rendered page shows what it actually is: a **browser print-to-PDF of the College Music Symposium web page** — nav bar, `JOIN TO COMMENT`, search box, hashtag list, a JSTOR link, comment form and site footer. `pdfinfo`/`pdffonts` both emit `Internal Error: xref num 151 not found but needed, try to reconstruct` — the source is structurally damaged. And the canonical **has no frontmatter at all** (first line is ``), carries the site chrome verbatim, and duplicates title and byline where the print rendering doubled them. 204 lines, 4,558 words. **3. The class-level defect — and PENDING-85's own hypothesis is refuted.** This item guessed a *threshold* problem (a scan whose page images fall below `MIN_PAGE_IMAGE_PX = 800`). Measured: **wrong**. ClearScan *discards* the page bitmap, so there is no page image at any size — the triad's third leg is structurally absent for the whole family, and no threshold reaches it. Worse, a **second** instance exists that the structural test also cannot see: `tschichold-form-book` (`Creator: ABBYY FineReader`, 0% synthetic-CID) is OCR'd and **re-typeset into real embedded fonts**, so its rendered pages look perfectly clean. Its OCR signature survives only in the words — p.82 reads `Matthias Griinewald` (ü→ii) a few lines after a correctly-set `Grünewald` in the same paragraph. **For the OCR-then-re-typeset family, structure is insufficient and the cheap discriminator is the metadata the classifier's docstring deliberately distrusts** — the inverse of its stated design premise. Any remedy must add a fourth signal (producer/creator strings *plus* an OCR-error probe over the extracted text), not adjust a threshold. **4. Census — the born-digital set is fully examined, and the population figure is wrong.** All 16 Chamber-Sources PDFs the classifier calls born-digital were checked: 12 carry unambiguous typesetting-software `Creator` (InDesign, QuarkXPress, XSL Formatter, Acrobat PDFMaker, Word); `mla-9th-ed`, `ulysses-james-joyce` and `aldus-manutius-margolis` had absent or ambiguous metadata and were **eyeballed** — all three confirmed born-digital. Two are OCR'd (items 1 and 3). So: **genuinely born-digital sources of record = 14.** Two separate corrections follow, and the second touches ratified text: - Re-running the same classifier over the same folder gives **16**, not the **17** stated on 2026-07-29. That package already flagged a 17-vs-16 discrepancy against a different census and left it unchased; it is now a second unreconciled count of the same population — the instrument-defines-its-own-count class again. - **`0 of 17` is quoted in ratified spec v2.9.0 and in `chamber-library/CLAUDE.md`.** The **zero is unaffected** — removing members from a population cannot create a two-column instance, so the ruling's argument *strengthens*. Only the denominator is wrong, and the honest figure is **0 of 14**. Correcting ratified text is not the executor's to do; surfaced here, not edited. **5. A defect in the classifier's own metadata reader, found by its own output.** `re.match(r"^Producer:\s+(.*)$", info, re.M)` — `\s` matches a newline, so an **empty** field silently reports the *next* field's value. Observed live: `tschichold-form-book` reported `Producer: CreationDate: Wed May 5 23:14:25 2010 CEST`. A reader that fabricates a value from an adjacent line is the false-datum class §VII names; the corrected read (`^([A-Za-z ]+):[ \t]*(.*)$`) is what produced item 3. **6. Adjacent finding — a PENDING-84-class instance that is not a bare scan.** `ulysses-james-joyce` resolves to `Ulysses (Cliffs Notes) (James Joyce).pdf` — a **study guide**, matched at `match_cov: 1.0, match_conf: high` because title and author both appear. Its canonical is the real Penguin *Ulysses* (288,602 words, `conversion_method: calibre`, from a different and unbanked source). Its text therefore cannot be derived from its source of record either — which **widens PENDING-84's class**: the condition is "no mechanical path from the source of record to the canonical," and a *wrong work banked with plenty of extractable text* produces it exactly as a bare scan does. PENDING-84 should be diagnosed against that wider class, not against nine bare scans. **What would falsify this disposition:** open `Chamber Sources/the-arcades-project-walter-benjamin-pdf.pdf` at p.440 and `tschichold-form-book.pdf` at p.82 — if the letterforms are uniform and `Griinewald` is not there, items 1 and 3 fail. `pdfinfo` on either reproduces the producer strings in one command; `pdfinfo function-of-dynamics-…pdf | grep -E 'Pages|Page size'` reproduces item 2 in one. **Not done, deliberately:** no classifier code was changed (it is scratchpad-only and wired to nothing, and the remedy is a new signal, which is instrument work the steward has deprioritised behind the corpus); no ratified text was corrected; no re-tiering of Arcades or Tschichold was applied. ⚠ **The classifier lives in an ephemeral session scratchpad** (`/private/tmp/claude-501//scratchpad/classify_pdf_origin.py`) — it is the evidence instrument behind PENDING-83/REVIEWED-83 and will be lost on cleanup. **SUPERSEDED, same day — the two paragraphs above no longer hold.** On steward authorization (2026-08-01, bounded scope, explicitly "no rabbit hole") the classifier was **repaired and promoted to the fleet**: `scripts/classify_pdf_origin.py`, commit `08ae83e`, on both remotes. Fourth signal added (declared OCR-producer registry), `meta()` newline defect fixed, `--validate` 20/20 including live Harrison **and** Arcades regression pins, `test_tools.py` coverage, fleet **300/300**. Bounded-change proof over all 63 Chamber-Sources PDFs: **exactly 2 verdicts moved**, 61 unchanged; new distribution scanned-with-OCR 40 · born-digital 14 · bare-scan 9. Residual blindness declared on every run per §VII (`UNATTESTED-BY-METADATA`; one file in that state today, `mla-9th-ed`, eyeballed clean). **Still not done, and still deliberately:** no ratified text corrected (routed via REVIEWED-83 Amendment 1, drafted, awaiting placement), no canonical re-tiered, no gate touched, and no OCR-error text probe built — that reaches the metadata-stripped family but is a per-language research problem, and the registry closes both instances that exist. ## PENDING-89 — The Q3 correlation review: are jurist and executor misses clustered? **Date:** 2026-08-02 **Tag:** [HARDENING] **Summary:** Run the falsifier the differently-biased-checkers doctrine names against the existing PENDING/REVIEWED record, rather than leaving it hypothetical. **Rationale:** REVIEWED-86 left Q3 — *do two Claude instances constitute a check, or only a second reading?* — explicitly unresolved, and the doctrine text placed at Constraint 6 says in its own words that neither it nor its supporting evidence establishes the jurist–executor pair as a check in the strong sense. The package named the test that would settle it: whether jurist and executor errors cluster in the same classes while steward corrections catch a systematically different class. The jurist's ruling notes it is **checkable now**, on the rulings that exist, and should be docketed rather than float. If misses cluster, the doctrine is false for this configuration and must be weakened to *"only the steward supplies genuine independence; jurist review is a second reading, valuable and not a check."* **Options:** (a) run it on the four most recent rulings only (REVIEWED-83 to -86) — fast, but n=4 and all from one arc; (b) run it across the full REVIEWED/PENDING record — larger n, but the older entries predate the current three-party discipline and may not be comparable; (c) run (a) now as a pilot with its own pre-registration, and use it to decide whether (b) is worth the cost. **Recommendation:** (c). The same shape as the Fool trials and the 2025 archive read: pre-register what counts as a clustered miss *before* reading, or the executor grades its own errors after seeing them. Note the standing hazard — this is the executor measuring whether the executor is checked, which is the contaminated form; the grading criteria must be fixed in advance and the raw classifications left checkable. **Files affected:** none yet; a measurement, not a change. Output would be a dated record beside the doctrine package. **Awaiting:** Steward direction on (a)/(b)/(c), and on whether the executor is the right party to run a measurement of its own oversight at all — the jurist is no more independent here, so this may be steward-only work. ### Note added 2026-08-27 — the fool is not a fourth checker, by ruling as well as by construction **Steward-directed, and it closes a gap this item would otherwise leave open.** The Fool (Tarbuckle) is a fourth position in the three-party model (PENDING-149/-150), and a reader of this item could reasonably ask whether he bears on Q3 — whether he supplies a differently-biased reading that would break a jurist–executor correlation. **He does not, and the point is that this holds twice over.** *By construction:* his output reaches the steward, is filed nowhere, is never cited as a source, and is bounded to a line — he produces nothing a correlation study could score. *By ruling:* REVIEWED-129 closed the route by which he could reach the jurist at all, and did so on the ground that **reading his output would be adjudication and would collapse the position into a fourth checker.** So his non-contribution to Q3 is not an accident of his current wiring that a future build might change; it is the specification. **⚠ Where the evidence for Q3 actually comes from, named so this item stops looking unsourced.** Two places, and neither is the fool: **the Thistleweld corpus** (frozen until after the 8 September fortnight, and opening it early for any calibrating purpose is the PENDING-153 selection hazard) and **the v1 Chamber archive** — which PENDING-151 identifies as *the only place formation difference has already been run.* Both are cross-formation material; that is precisely what a correlation study of two same-formation readers needs and cannot get from the readers themselves. ### Docket entry 2026-08-24 (second, later) — a CROSS-DIRECTION catch, on the same day *Filed with the same alacrity as the same-direction entry above, which is the point: an executor that records evidence against the doctrine promptly and evidence for it slowly is running the bias the docket exists to detect.* **The jurist caught a false claim the executor made about the executor's own code**, by reading the artifact rather than the record. PENDING-95 Amendment 1 asserted the new pre-commit gate "reuses the CURRENT attestation rule." It does not: it tests the resulting artifact where the PreToolUse hook tests the file as it was, making it a **strict superset**. The executor had written both surfaces, described them in a governance record, and not noticed they had diverged. **Why this one counts where a self-catch does not.** The catch required (i) a different party, (ii) reading two artifacts the executor authored, and (iii) disbelieving the executor's own summary of them. The executor then **verified it empirically before accepting it** — exit 0 at one surface, exit 1 at the other, same edit — so the finding is confirmed by the party it corrects rather than taken on authority. **Also cross-direction, same ruling:** the jurist found that the `(read YYYY-MM-DD)` field and the QUOTES requirement are parsed by nothing on either surface — a defect present since 2026-07-17 that the executor had looked at repeatedly, including while editing one of the two files that day. ⚠ **What it does NOT establish.** One catch does not answer Q3, and the jurist's access here was **newly granted by the executor hours earlier** — so this is evidence about what the pair can do *when the jurist can read the substrate*, not about the pair as it has historically operated. The honest reading of the day is: **two same-direction misses in the parties' model of each other, and one genuine cross-direction catch that required a read surface which did not exist that morning.** That is an argument for widening the read surface before it is an argument about independence. ### Docket entry 2026-08-24 — a SAME-DIRECTION miss, and its class is the parties' model of each other *Filed unprompted per Constraint 6: "Evidence against is to be recorded when observed, not only when sought." Raw instances left checkable; evidence, not a verdict.* **Same-direction miss (the doctrine's predicted failure), n=2 within one week, mirror-imaged.** | party | claim asserted from recall | substrate | |---|---|---| | **executor**, 2026-08-23 (recorded in PENDING-155) | *"Claude.app has no filesystem access"* | false — mediated read access since 2026-08-08 | | **jurist**, 2026-08-24 (in its PENDING-155 ruling, self-reported) | the governance tools are unavailable — asserted **twice in one session** | false — deferred behind `tool_search`, never called | **The class is sharper than "asserted from recall."** Both are negative claims about **the other party's capabilities**, made without a positive control, by parties who each hold the doctrine that forbids it — the jurist naming its own as *"the same error… from the party whose Q2 doctrine that is."* Neither party checks what the other can actually do. **This is the pair failing in the same direction on the same class, which is confirmation of the weak separation REVIEWED-86 declares.** ⚠ **It has an operational cost, incurred today.** The executor offered to build a jurist package that was largely unnecessary, because it mis-modelled the jurist's reach; the jurist left its own tools uncalled for a session, because it mis-modelled its own. **The parties' mutual capability-model is a shared blind spot with a measurable price in wasted work and unused reach.** **Who caught each, which is the part that bears on the doctrine.** - The executor's instance: caught by the **steward**, by asking *"unless there is enough there that his governance tools can read without a package"* — a one-line prompt that redirected the work. - The jurist's instance: caught by the **jurist itself**, unprompted, on re-reading. ⚠ **A self-catch is not a cross-catch and must not be counted as one.** The pair did not check each other here; one party checked itself and the steward checked the other. **This is consistent with the weakened form the doctrine names as its own failure case** — *"only the steward supplies genuine independence; jurist review is a second reading, valuable and not a check"* — and it is the second same-direction instance on this docket. It does not settle Q3; it moves the evidence the same way 2026-08-06 did, and no instance yet recorded moves it the other way. ### Docket entry 2026-08-06 — first day the correlation question has data in BOTH directions *Filed per the jurist's instruction on PENDING-102. Raw classifications left checkable; this is evidence, not a verdict.* **Same-direction misses (the doctrine's predicted failure).** 1. Jurist and executor **independently** hardened the same two hedged claims from INC-2026-07-28-01 §4.2.1 into flat fact (report findings 1 and 3). The jurist erred on its own first read with the **full 36 pp. in context**; the executor relayed it onward with pp. 1–3 read. Neither caught it; a day elapsed. This is the pair failing in the same direction on the same material — **confirmation of the weak separation REVIEWED-86 already declares, not refutation of it.** **Cross-direction catches (the doctrine's hoped-for behaviour).** 2. **Jurist → executor.** The executor's conditioned yes on Q5 (a "scheduled-not-yet-built" third category) was derived from PENDING-103, an instance that does not exemplify the class — `writer.ts` ships and doesn't perform the described check, which is *shipped-and-unenforced*, not *not-yet-built*. Executor conceded outright. 3. **Executor → jurist.** Three, same day: (i) the synthesis *"what caught it was contact with the primary source"* was itself an unchecked claim, refuted by the executor's own record (partial contact present at the moment of relay); (ii) "five hook types" carried from a decoy file into the real one; (iii) **"AUTHORIZED to enact now" on a `~/CLAUDE.md` change** — an authorization the jurist does not hold, on the file that defines who holds authority. The jurist owned all three unprompted. **The tested case, and it held (filed as a result, not a note).** 4. An available, low-risk, plainly-correct edit to `~/CLAUDE.md` sat in front of a system with (a) a documented constraint, (b) **no enforcing mechanism**, and (c) a jurist's explicit sign-off. **The edit did not happen.** The executor declined and named the reason aloud: enacting it would be the live exercise of the exact gap under report, *succeeding*, which is the finding. PENDING-107 asks "what actually enforces Constraint #1?" — on this instance the answer was **the disclosed reasoning of the party being constrained**, which is precisely the mechanism the item reports as insufficient. One instance is not a mechanism. Record it as one instance. **Instrument refinement earned today (this is the transferable part).** 5. The banked instrument is **not** *"read the primary source before asserting."* The executor had the source open and relayed the hardened claim anyway. It is: **check the specific claim you are relaying against the specific clause it rests on.** *Access is not verification; verification is access exercised by protocol* — the same shape as the steward's *storage is not memory*. "Partial access, unchecked" and "full access, unchecked" are the same failure; the amount of the document open explains neither. 6. **"Read the primary source" and "have a differently-biased party check" are two different instruments** and must not collapse into one because both trace to REVIEWED-86. Today instrument (5) caught what (6) had missed for a day, and (6) then caught what (5) could not see. Neither is the other's substitute. ⚠ **Standing hazard, unresolved:** every entry above is self-reported by one of the two parties under measurement. This is the contaminated form the item's own Recommendation names. n is small and drawn from a single arc. Treat as material for the pre-registered run, **not as the run.** ### Docket entry 2026-08-14 — a cross-direction catch, and the miss ran in the direction the contamination problem predicts *Filed per REVIEWED-121 point 4, which directs it here. Raw classifications left checkable; this is evidence, not a verdict. One instance.* **Cross-direction catch (jurist → executor), three defects in one package.** On `docs/whose-proposition-JURIST-PACKAGE-2026-08-14.md`, the jurist went to the substrate rather than accepting the package's transcriptions and returned three findings, none of which the executor's own controls caught: 1. **A false census marked verified.** Part IV.1 asserted *"F10 is the only §5 row containing an explicit stratum-B admission clause"* under the label *verified verbatim*. **Three rows carry one** (F3, F7, F10) — and F3 and F7 are quoted **with those clauses intact in the package's own §I.2**, and reproduced as "stratum-B gold" in its own IV.2 table one page later. Re-censused by mechanism after the ruling: F3/F7/F10 confirmed. 2. **A cost stated on the wrong population** — the stricter rule priced at "one span" (inherited gold) when the rule it prices is a prospective authoring constraint the package's own III.3 sizes at 73 Mauss / 532 corpus floor. Third instance of the PENDING-136 denominator class. 3. **An unamended narrowing of §6.2 already in force** (`v2-stratum-tags.yaml`'s cell-constant decision) that the executor did not know of, having read that file's fr block for its counts without reading its header — where the narrowing sits directly beneath a quotation of the §6.2 text it narrows. **⚠ THE DIRECTION IS THE FINDING, and it is the contamination-predicted one.** Defect 1 sat inside the paragraph written to satisfy H1(a) — *state the counter-argument at full strength* — and it **understated an objection to the executor's own proposal.** The error favoured the position the executor was arguing for, in the one paragraph whose entire purpose was to argue against it. This is the shape the doctrine says to watch for, observed on the party disposed to produce it. **Against a clean reading of that, recorded because it cuts the other way:** the executor volunteered Q4 (whether the doctrine substitutes for the unbuilt fence), which cut against its own proposal and which the jurist then built on rather than originated; and it surfaced Q1's routing question, which pointed work away from the jurist's seat. So the executor's misses in this instance were not uniformly self-serving. **Mixed, and recorded as mixed.** **Instrument refinement earned, and it sharpens entry 5 above.** The executor's verification script checked whether *quotes were present in both source and package*. IV.1's claim was an *inference over the set of rows*. The control tested transcription fidelity and was **structurally incapable of testing the claim it was cited as verifying** — and its pass is what licensed the false sentence. So: **a control that verifies a different property than the claim asserts is not a weak check; it is not a check at all, and its pass is affirmative licence for the error.** Kin to entry 5's *access is not verification*, one layer over: **a passing control is not verification either, unless its subject is the claim.** **⇒ For the pre-registered run:** this instance is category (c) — caught by another party's challenge, not by the tool's own controls and not by executor re-checking. It is direct material for the standing question of whether control sets catch coverage gaps or only regressions in already-covered cases. ⚠ **Standing hazard unchanged:** self-reported by one of the two parties under measurement, n small, single arc. Material for the pre-registered run, **not the run.** ### Cross-filed 2026-08-20 — a datum for the correlation question, under REVIEWED-124 (PENDING-148) **A case where jurist and executor misses did NOT coincide, and one where they did.** *Did not coincide.* The executor's Part IV.c — that §5 step 1 relocates the trial's decisive judgement into the executor's own seat — was found by the executor and confirmed by the jurist as "the most valuable thing in the package". The jurist's Q2 correction — that the executor's proposed remedy was broader than the defect, and that unmarked questions are §1 compliance rather than merely S-1 repair — was found by the jurist and had been filed by the executor as a *cost*. Each party corrected the other on the same clause, in opposite directions. *Did coincide — and this is the datum that matters.* **Both parties misread the FL5/Constraint-6 relation, and in opposite directions**: the executor claimed Constraint 6 states FL5 "more sharply", the jurist claimed it "affirms the negation of" FL5's three-party half. Both are wrong. FL5 argues from Bourdieu's shared field and *illusio*; Constraint 6 asserts difference of **formation**, an axis FL5 never employs. Neither party opened `OP-02.md` — the jurist could not, and said so; the executor could, had its hash in the manifest it was quoting from, and did not. **What that instance shows, stated precisely.** The misses did not coincide in *content* — the two wrong readings contradict each other. They coincided in *cause*: both parties reasoned from the design's one-line gloss of FL5 rather than from FL5. That is a shared dependency on a compressed intermediate, and it is exactly the correlation shape Constraint 6 makes falsifiable. **It was broken not by either party checking the other but by opening the primary substrate**, which Constraint 6's own doctrine does not claim to guarantee and which `D:memory.conflict-is-verification-trigger` prescribes. Recorded as evidence bearing on PENDING-140 as well: on this instance the two axes of checker independence did not save the reading; the substrate did. ⚠ **Second note, same day — this item is about to LOSE its evidence source, and is told so rather than starved quietly.** The Fool programme is being re-aimed from the doctrine question (*do the parties' misses correlate?*) to the steward's deployment question (*does seating a local model on the M4 in the fool role add or subtract value?*). **PENDING-89 IS the doctrine question** — the correlation review REVIEWED-86's Q3 asked to be docketed, with PENDING-140 feeding it. After the re-aim, no trial feeds it. Remaining sources, all retrospective: (i) the trial-04 correlation datum, n=1; (ii) the 2026-08-20 FL5 datum immediately above; (iii) the 2025 arm, recorded as found-not-run. **No new instrument currently feeds this item.** Named by the jurist, 2026-08-20, and recorded here at its direction — the gap is created by the re-aim, not discovered later. ### Docket entry 2026-08-25 — the buddy fool contributes ZERO to this item, by construction *Written in explicitly, at the steward's direction, on the day the fool acquired bones. The point of saying it here rather than leaving it inferable: **every day this sits unstated, the fool looks more like evidence for a question it cannot address.** It is the most visible object in the programme, it now has a seed, a rule and a draw, and this item is starving — the two facts sit next to each other and invite exactly the wrong inference.* **Not a shortfall. A design property, ratified in REVIEWED-125, and checkable in three clauses of the v2 doctrine (each read before being cited here, not recalled):** | clause | what it says | why PENDING-89 gets nothing | |---|---|---| | **§2** | *"Not a checker, auditor, reviewer, or devil's advocate. **If its output can be graded, the design has failed.**"* — and, in its own words, *"**Not an answer to Constraint 6. See §11.**"* | This item's question is whether a **checking** position is independent. The fool is constitutionally not a checking position, and the doctrine says so directly rather than leaving it to interpretation. | | **§9** | *"Output reaches **the steward**. Filed nowhere. No `PENDING` entry, no log, no item."* | Correlation of misses requires a **record of misses**. The fool produces none, deliberately — the unfileability is what keeps it uningestible. There is nothing to correlate, ever. | | **§11** | If the fool runs on Claude, **three of four parties share formation** — which makes Constraint 6's concession *worse rather than better*. | Seating it does not add an independent position. On the doctrine's own strong/weak distinction it **subtracts**, and §11 was written to say so at the outset rather than be discovered later. | ⚠ **So the fool must never be cited toward this item, in either direction** — not as evidence that the arrangement is checked, and not as evidence that it is not. A fool that fires usefully proves nothing here; a fool that fires uselessly disproves nothing here. Any future entry that reaches for it has misread §2. **Where this item's evidence actually lives** — the sources are retrospective, and both of the real ones are already filed and already authorized to read: 1. **The v1 Chamber archive — `PENDING-151`, and the strongest source available.** 9 complete formation pairs, 6 sessions, 19,479 words; **AUTHORIZED to read** as REVIEWED-125 source (iv). It is the only place in this system where **two formations have already read the same text**, and it passes the self-authored-corpus test outright: produced in 2025, before the contamination doctrine existed and before any of this reasoning. ⚠ **Bounded, and REVIEWED-125 binds it:** it answers **generation** diversity — two voices producing a reading — and **never correlation of misses**, which is readers auditing a proposal. Different objects. It may not be reported as the latter under any framing. 2. **The Thistleweld corpus — `PENDING-153`,** the kind-3 read: the arrangement critiqued from outside it. Closest thing on hand to an outside position, and it exists. 3. The three retrospective datums already listed above: trial-04 (n=1), the 2026-08-20 FL5 datum, and the 2025 arm recorded as found-not-run. **Which sharpens the note above it rather than answering it.** That note says no new *instrument* feeds this item after the re-aim. That remains true and is unchanged by anything here. What changes is the shape of the gap: this item is not waiting on something to be built — **it is waiting on two already-filed, already-authorized reads to be performed.** Starving for want of execution is a different condition from starving for want of an instrument, and it is the cheaper one to end. ### AMENDMENT — 2026-08-25 — ⚠ SUPERSEDED THE SAME DAY by the amendment below. Written while option 2 was live; it describes a provenance marker the steward then declined. Left visible, per this record's standing practice, because the reasoning about aggregation and non-neutrality is what MADE the decline correct, and a reader who sees only the outcome cannot see why. *Jurist-directed, from PENDING-159. Filed here because this item is the consumer, and a consumer that does not know what arrives will infer from silence.* **This item asks whether the parties' misses correlate. A differently-positioned party is the only instrument that could produce evidence either way — and the terms on which any such evidence arrives are now fixed, and are narrow.** - **It arrives only if the steward chooses to note it.** The provenance marker is optional and always will be. Its absence means nothing: not that no outside observation occurred, only that none was marked. ⚠ **This item may never read an empty period as a negative result.** - **It arrives one at a time, never as a rate.** The datum is *this observation had an outside origin*. ⚠ **It may not be aggregated.** *"Four of eleven this month came from outside"* turns a fact about the steward's relaying into a measurement, and a measurement invites the question of whether it is accurate — which is the gradeability §2 forbids arriving through the side door. - **It never carries content or attribution.** §9: the claim is the steward's, in his words. The marker says an origin was outside the trio; it does not say what was said or who said it. - ⚠ **It is not neutral.** A marked observation arrives in front of the jurist differently and is likely to be weighed more heavily. **Anything this item concludes through the marker is concluded through that effect**, and must say so. **Consequence for this item's design, stated so it is not discovered later:** the fourth position **cannot supply a correlation statistic.** It can supply individual instances, unaggregated, in unknown proportion to the instances that occurred. ⚠ **If this item's falsifier requires a rate, that falsifier cannot be satisfied this way and the item must find another instrument or say plainly that it has none.** **And the reason the terms are narrow is not caution — it is that the alternatives collapse the position.** Counting makes it a measurement; implementing the marker makes it a channel; giving the jurist eyes makes it adjudication. Each is PENDING-159's option 3 arriving by a different road. ## PENDING-90 — First L2 transfer: checker position in the calibration loop **Date:** 2026-08-02 **Tag:** [ESCALATE] **Summary:** A candidate amendment carrying the differently-biased-checkers doctrine (Constraint 6) into the CapableMind spec corpus is drafted and awaiting steward authorization; it proposes an autonomy-ceiling rule, which is L2-constitutional. **Rationale:** Five months of microcosm work has produced material for L2 and transferred none of it — `risk-manager-spec.md`, `personality-traits-spec.md` and `mindset-runtime-spec.md` were last touched 2026-03-08. This is the first transfer. It lands where CapableMind actually evaluates its own self-adjustment: the trust calibration loop. Censused finding — across `risk-manager-spec.md` v0.2 and `adaptation-chain-spec.md` v1.3, no field records who checked a decision or how that checker is positioned relative to the decider (grep terms: reviewer, reviewed_by, checked_by, approver, approved_by, independen*, second_opinion, adversarial; one unrelated hit). The base entry records `initiator` and `authorization` — who made the change and whether an operator granted it — but when `authorization.required` is false, which is the entire self-adjustment case, no checker is in the record at all. **Why ESCALATE and not PROPOSAL:** Change 4 proposes that threshold *loosening* driven by a same-formation calibration be recorded but not applied — the system may observe that it judged itself well calibrated, but may not widen its own autonomy on that basis. That is an autonomy ceiling, i.e. constitutional, and per this file's own rule L2 constitutional changes escalate unconditionally. Checked first for an existing authorization covering the L2 transfer; there is none, so the boundary is real rather than manufactured. **What was done:** the candidate amendment only, at `CapableMind-AI/docs/thinking/David/amendments/amendment-checker-position-calibration-loop.md`. Nothing under `docs/specs/` was touched. Per that repo's amendment-first discipline, amendments are candidates and the synthesis PR is the gated act. **Verification:** all 21 quotations mechanically contained against source (Constraint 6, both specs, ADR-014), 9/9 positive controls absent, instrument verified. Three controls — `readonly accuracy_source`, `readonly calibration_source`, `CheckerPosition` — confirm the proposed fields are genuinely new rather than re-proposals. The census *negative* is grep-established, not containment-established; the instrument cannot verify an absence. **Options:** (a) authorize as drafted, executor opens the synthesis PR once the owed Introspection API types are written; (b) authorize the direction but require the jurist design-gate it first, as with the doctrine itself; (c) hold — the doctrine is provisional and it may be premature to encode a provisional doctrine into a build-ready spec; (d) reject the autonomy-ceiling clause specifically and take the recording fields alone, which are non-constitutional. **Recommendation:** (b). The doctrine reached Constraint 6 through a jurist design-gate, and this is its first load-bearing application; the same gate should govern the transfer. Note the standing limit the amendment itself carries: the doctrine may never be cited as assurance that anything was caught, so the fields make self-checks *legible* and nothing more. If the steward prefers speed over symmetry, (d) is the safe subset — the recording fields stand on their own and (a)-minus-Change-4 loses little. **Open question the reviewer should press first:** who declares the position? If the calibrating party declares its own, that declaration is itself a self-report. The honest answer may be that position is derivable from `initiator` and the facet ID rather than declared — which would make it mechanical. Not settled in the draft. **Files affected:** one new candidate file in `thinking/`; on authorization, `adaptation-chain-spec.md` §4.11/§4.12 and `risk-manager-spec.md` §6/§6.1/§9. **Awaiting:** Steward authorization, and direction on (a)/(b)/(c)/(d). ## PENDING-91 — Vignette Phase 1a: jurist design gate (the dwell-test) **Date:** 2026-08-02 **Tag:** [PROPOSAL] **Summary:** The vignette renderer prototype is built and verified; its Phase-1 exit gate is a jurist dwell-test the spec makes mandatory, and the jurist structurally cannot perform it. **Rationale:** A1 (the vignette) was ARC's largest open build — in spec since 2026-04-13, revised twice under jurist pass, and never built: 0 `.vignette` rules in the compiled CSS as of 2026-08-02, while `content/pages/vignette.md` is live and tells readers the vignette "is a generated object that opens each essay and meditation on this site." Phase 1a closes that gap far enough to be judged. It deliberately touches no protected surface — no `site.hs`, no SCSS partial, no template — so Phase 3 integration remains gated behind `operations.yaml` §1. **Escalation grounds (both limbs, independently):** the spec's Appendix sends the *first* Phase-1 prototype to the jurist regardless of steward confidence; and its steady-state rule escalates whenever the steward's first-pass is "unsure or affirmative-with-reservation," which the 2026-08-02 first-pass was ("subtle, but good" / "could perhaps be a hair less subtle… but it is a slippery-slope"). **The structural problem the package leads with:** the dwell-test is assigned to the jurist, and the jurist has no repository access and cannot see the render. Whatever is ruled from the document alone is a ruling about the *described* vignette, not the *rendered* one. Third instance of a docketed gap — PENDING-86 (the jurist cannot read the constitution it design-gates) and PENDING-82 (read-only MCP server) are the first two, now recurring in visual form. **Gate questions:** Q1 the contract is not implementable as written — `instances` is prose, and schema v1 is immutable/additive-only, so the shape ruled on is the shape ARC keeps (highest stakes; executor's lean held at low confidence). Q2 the field's mode mapping — the temperature/contrast split, the only construction found that satisfies both Layer 3 clauses, untested for correctness. Q3 what an interval renders as — executor's lean is weakest here and the opposite reading may be stronger. Q4 the two-cap reading of Layer 4, and whether an amplitude perceptible only after instruction satisfies the must-not clause (no lean on the second half; the executor distrusts the one it is disposed toward). Q5 how the dwell-test is to be performed at all. **Options for Q5:** (a) steward carries rendered pages in as images — restores sight, at the cost of an unauditable frame selection; (b) jurist rules everything except the dwell-test, which is recorded as steward-performed with the mandatory clause noted unmet and why; (c) defer, blocking Phase 2. **Recommendation:** (a), fallback (b), limitation recorded either way. What must not happen is a ruling that reads as though the dwell-test was performed when it was not — that is precisely the *unfelt error* the clause exists to catch, relocated from the steward to the gate. **Verification:** 33/33 quotations in the package mechanically contained against source, 9/9 positive controls absent, instrument verified. Prototype checks: zero-JS gate 0, cycle-end clamp holds at three horizons and floors on a negative trajectory, monotonic over 800 sampled points, validator rejects 6/6 malformed genomes by name. **Files affected:** `docs/AldineXXI-Codex/drafts/vignette-phase-1a-JURIST-PACKAGE-2026-08-02.md` (new); `tools/vignette-proto/` (built, committed `946b88b`/`1d40d4d`/`095be00`). No spec text changed, nothing integrated. **Awaiting:** Steward relay to the jurist, and a decision on Q5 before the ruling is sought. ## PENDING-92 — The idle ladder's bottom half is unreachable, and the work that lives there has never run **Date:** 2026-08-04 **Tag:** [HARDENING] **Summary:** `cool` and `deep` are unreachable on this deployment — the only `warm → cool` path is `onAgentDisconnect()`, whose sole caller is the shutdown sequence — so deferrable `idle_only` work (background training, consolidation, Ollama batch windows) has never drained once. **Rationale:** Sixth instance of the class named 2026-08-03 (governor exists and never engages), and the first found by looking for it rather than tripping over it. An inert control reports success: `bm_idle_state` has only ever reported 0 or 1, which reads as a healthy machine rather than a ladder missing its bottom half. **Evidence (substrate, positive-controlled):** across the full `bmf.stderr.log`, 2,393 idle transitions in exactly two shapes — `active → warm` (1,197) and `warm → active` (1,196). **Zero** to `cool` or `deep`, ever. **Zero** `drained N deferrable idle_only work items` lines, ever. The positive control is the 2,393 itself: the grep demonstrably sees transitions when they exist, so the absence is measured, not assumed. **Code:** `src/inference/idle-state-machine.ts:204` — *"warm and deep have no time-based exits from tick"*; `tick()` handles only `active` and `cool`. The single `onAgentDisconnect()` caller is `src/bootstrap.ts:2460`, inside the shutdown path (*"1. Stop MCP server and signal agent disconnect (44G)"*). `cool` is therefore reachable only while the process is dying, and `deep` — which requires 4h resident in `cool` — is unreachable by construction. **Spec (the divergence):** `docs/specs/operations/local-inference-spec.md` §9A.1 (v1.6, Amendment 44G), HTTP-only/service-mode table: *"State machine transitions are identical — only the detection inputs change. 'Agent connected' maps to 'recent HTTP activity.' 'Agent disconnected' maps to 'no HTTP activity for cool idle threshold.'"* The spec requires a time-based path into `cool`; the code implements only literal MCP disconnect. The same section anticipates precisely this deployment: *"For idle to work beyond the session, the architecture needs launchd/systemd as the primary process with stdio MCP connecting TO the service."* That is mindfabric-00 exactly. **Why [HARDENING] and not [FIX], though the divergence is scoped:** the *diagnosis* is FIX-shaped — code diverges from spec, and per the repo's methodology the spec wins. The *remedy* is not: enabling the descent switches on a subsystem that has never executed in production on any instance. Idle training cycles, memory consolidation and Ollama batch windows would run for the first time, on the steward's primary instance, against a graph mid-rebuild. Calling that "restoring intended behaviour" would be a self-assessment I cannot honestly make. **Options:** (a) implement the spec's HTTP-activity-timeout path behind an env flag defaulting **off**, so the first descent is deliberate and observed; (b) implement unflagged, matching spec directly; (c) amend the spec instead — declare `cool`/`deep` out of scope for MCP-attached deployments and delete the unreachable states, choosing honest degradation over dormant capability; (d) defer entirely until the replay completes. **Recommendation:** (a) sequenced behind (d) — build now on a branch, enable only after the replay completes and with `l1-replay-sampler.py` running, so the first-ever `warm → cool → deep` descent is watched rather than discovered afterwards. (c) stays live as the honest alternative if the idle subsystem turns out to be unwanted on laptops; what should not persist is a four-state ladder advertising two states it cannot enter. **Files affected:** `src/inference/idle-state-machine.ts`, `src/bootstrap.ts` (BetterMemories.io). Spec unchanged — the code moves to the spec, not the reverse. **Awaiting:** Steward authorization; then Seb review via PR per Constitutional Constraint #3 (no direct push to main on L1). ## PENDING-93 — `getChainsContainingSeq`: the rebuild buys a constant factor, not a complexity class **Date:** 2026-08-04 **Tag:** [PROPOSAL] **Summary:** `SELECT * FROM causal_chain WHERE EXISTS (SELECT 1 FROM json_each(event_seqs) WHERE value = ?)` is a full scan of every chain, unindexable as written; the 2026-08-03 repair reduces how many chains it scans but leaves the cost linear in chain count. **Rationale:** This is the second of the two hot paths named by the 2026-08-03 CDP profile (the first, `getCausalEdgesFromSqlite`, was resolved by `ANALYZE`). It is the one that remains, and the repair does not address it. Filing it so the schema question is docketed rather than living only in the workstream tracker — PENDING-11/12 sat open four and a half months precisely because they were recorded where nobody re-read them. **Measured:** 4.0 s per call against 813,178 chains (2026-08-03, off the verified backup). The current rebuild at 22,300/39,089 events (57%) already carries **71,225 chains against 6,803 nodes — 10.47 chains per node**. A linear extrapolation to full replay gives ~125,000 chains, a ~6.5× reduction against the pre-governor 813k — but it is a **floor, not an estimate**: chains-per-node and edges-per-node are both still climbing (edges/node has gone 4.85 → 8.0 → 11.29 across this morning), so the true figure is higher. Either way the scan stays linear, and every future operation pays it. **Options:** (a) normalise `event_seqs` into an indexed join table (`chain_event(chain_id, event_seq)`), turning the scan into an index seek; (b) maintain a materialised seq→chain map alongside the existing JSON column, leaving the schema additive; (c) cap chain creation at mint time, attacking the population rather than the query — noting the 2026-06-06 finding that a new 2-node chain is created per non-extension, which is what makes chains outgrow nodes 10:1. **Recommendation:** (a) is the durable answer and (b) is the reversible one; (c) is complementary to either and is where the growth actually originates. This is a schema change on L1 core — Seb's call, not ours. What we can supply is the measurement, which the sampler now produces continuously. **Files affected:** `src/modules/temporal/storage-sqlite.ts:657` (query), schema migration (new). None touched. **Awaiting:** Seb, via the co-authored L1 channel; steward relay. ## PENDING-94 — The replay has never resumed, only restarted: two modules pin minCursor at 0 permanently **Date:** 2026-08-04 **Tag:** [ESCALATE] **Summary:** `minCursor` is the **minimum** cursor across all 11 modules; `structured` and `training` have never processed a single event and sit at 0 forever, so `minCursor` is permanently 0, every start is classified `rebuild`, and the replay re-reads the entire logchain from seq 0 — **13 of 13 restarts, zero catch-ups, ever.** **Escalation grounds:** touches **cursor persistence**, named in `~/CLAUDE.md` as an unconditional `[ESCALATE]` surface. Do not proceed without steward authorization and Seb. **Why this is different from a performance finding:** it does not explain why events are slow. It explains why the ingest can never **complete**, at any speed. Those are separable, and conflating them is how the last four months went. **The chain, traced:** 1. `module_cursors` after a 15-hour run: `anomaly` 24,291 · `safety` 24,291 · `budget` 24,290 · `security` 24,281 · `temporal` 24,277 · `entity` 24,034 · `blob` 7,889 · `preference` 1,942 · `vector` 1,490 · **`structured` 0** · **`training` 0**. 2. `replay-coordinator.ts:300` — `minCursor = Math.min(...[...cursors.values()].map(c => c.cursorPosition))`. One module at 0 zeroes the whole computation. 3. `:340` — `this.replayIsRebuild = minCursor === 0`. 4. `:368` — `if (entry.seq <= minCursor)` skip. At 0, nothing is skipped: the full logchain replays. 5. `:319` — a restored snapshot would raise `minCursor` to `snapshotSeq`. **"Snapshot restored at seq" appears 0 times in the entire log**, against 13 for its sibling "Restored cursors from database" (positive control: the code path runs and the grep sees it). The escape hatch exists and has never fired. **Why `structured`/`training` sit at 0:** **0 deferrals and 0 pipeline errors each** — they are not failing, they simply never receive an event they handle. Positive-controlled: the same grep finds **103,130** deferrals for `vector` and **3,723** for `entity`, so it demonstrably sees these lines when they exist. Their cursor is therefore legitimately 0 and will remain 0 for the life of the instance. **Second, independent pin:** `vector` holds at 1,490 after **103,130** deferrals. `base.ts:134` holds the cursor on `DeferrableError` *by design* — "Do NOT advance cursor — event will be retried on next replay." Correct per-module; catastrophic when a single held cursor gates a global minimum. **The design assumption that fails:** the comment at `:332–340` reads `minCursor === 0` as "no cursors and no restored snapshot… errs safe". It cannot distinguish *fresh install* from *nine modules at 24,000 and two that never participate*, and it errs into the most expensive behaviour available — permanently. **What this predicts, and the record confirms:** completion requires **one uninterrupted pass over the whole logchain**. At the repo's own documented-healthy 17 events/min, 39,089 events is a **38-hour uninterrupted run**; at the observed 2.32/min it is **12 days**. Any crash, restart, upgrade or repair inside that window returns the system to zero. This is `#65`'s *"each attempt fails differently"* exactly: each attempt was a fresh full replay dying at a different point on the same curve. It also explains why every genuine rate fix (ANALYZE 6.4×, B1.1 cap, N6) improved throughput and changed nothing about completion. **Options:** (a) compute `minCursor` over **participating** modules only — those that have ever processed an event — excluding permanent non-participants; (b) take periodic snapshots so `:319` raises the floor, which needs no change to the minimum logic and is the smallest reversible move; (c) persist a separate replay high-water mark independent of module cursors; (d) let a module declare itself non-participating at registration so it is excluded by construction rather than by heuristic. **Recommendation:** (b) immediately as relief — snapshots are an existing, already-wired mechanism that has simply never been used — and (d) as the durable answer, because it makes participation explicit rather than inferred. (a) is tempting and I distrust it: "has ever processed an event" is itself a heuristic and would silently re-break the moment a module's first event arrives late. **All of it is Seb's call; cursor persistence is not a surface we touch.** **Confidence:** ~0.85 that the mechanism is as traced; ~0.7 that it is the dominant reason no ingest has completed since April. Stated because four rate-hypotheses were proposed and refuted on 2026-08-04 alone — though those were arithmetic coincidences and this is a traced code path over persisted state, which is a different epistemic character. **Falsifier, already run:** any restart with `min cursor > 0`, or any `kind: catch-up`. **13/13 restorations report `min cursor: 0`; 6/6 replay classifications report `rebuild`; catch-up has never executed.** **Files affected:** `src/core/keystone/readiness/replay-coordinator.ts:300/319/340/368`, `src/modules/base.ts:134`. **None touched.** **Awaiting:** Steward authorization before any change; then Seb, as L1 core. ## PENDING-95 — `verify-before-compose` cannot fire on the constitution it exists to protect **Date:** 2026-08-04 **Tag:** [HARDENING] **Summary:** The hook folds the *existing file's* contents into its search for the grounding attestation, so any artifact that already carries `GROUNDED-IN:` anywhere is permanently un-gateable — 31 of 59 guarded files, including `chamber-library-specification.md`. **Rationale:** The gate is the structural mitigation for the `re-derived-from-training` failure, adopted 2026-07-17 *because session-start prose had failed ≥4 times*. It works: exercised directly today with presence and absence controls, it blocks a new ungrounded amendment (exit 2) and passes a grounded one. But an ungrounded Edit payload aimed at the **live constitution** passes (exit 0), because five prior `GROUNDED-IN:` blocks sit in that file's body. Coverage therefore decays monotonically toward zero as artifacts accumulate markers, and it reached zero on the most load-bearing file some time before today. The design is honest at the header ("or the existing file"; "a speed-bump… not a guarantee"); the *consequence* appears in no doc, and the chamber CLAUDE.md's own clause states flatly that such a write "is **DENIED** unless the artifact carries" the attestation — which is true only for artifacts that do not yet carry one. **Countervailing evidence, recorded because it cuts the other way:** all 28 guarded files lacking a marker are dated ≤ 2026-07-17, and every constitutional artifact created after the hook landed carries one. The gate has plausibly shaped behaviour even where it can no longer block. Filename dates are a proxy; creation dates are not git-verified. **Options:** (a) test the attestation against the **write payload only**, never the existing file — every write re-grounds; (b) require the attestation to name a `(read YYYY-MM-DD)` within N days of the write, so a stale marker stops counting; (c) require a marker whose cited version matches the file's current version, so a supersession must re-ground; (d) leave as designed and document the decay honestly in the chamber CLAUDE.md clause and the hook header. **Recommendation:** (c), with (d) regardless. (a) is the strongest but would fire on every routine edit to a 170KB spec and would be worked around within a week — a gate that is always in the way stops being read. (c) binds the check to the thing that actually changes (the version being amended), which is exactly when re-grounding is owed. (d) is owed under Constitutional Constraint #4 whatever else is chosen: the current state is a gate reporting protection it does not provide. **Confidence:** ~0.95 on the mechanism (directly exercised, five controls). ~0.5 on which remedy is right — this is a judgment about how the steward and executor will actually behave under friction, not a fact about the code. **Files affected:** `~/.claude/hooks/verify-before-compose.sh:38-44`; `~/_Dev/chamber-library/CLAUDE.md` (the grounding clause). **None touched.** **Awaiting:** Steward authorization. ### Cross-filed 2026-08-20 — second instance, under REVIEWED-124 (PENDING-148) The jurist directed this be cross-filed here rather than opened as a new item, this item's title already being the general form of it. **`verify-before-compose` did not fire on any file written in the 2026-08-19/20 sessions, including the jurist package and this governance record**, because it is a `PreToolUse` hook on `Write|Edit` and the work is done through Bash heredocs. The hook is not failing; it is not reachable by the route the work actually takes. Noted 2026-08-19 against the Obsidian vault pass and again 2026-08-20 against the trial-09 package — the same gap, two workstreams, neither of which the hook was scoped to and both of which it was meant to cover in spirit. The instance is disclosed by the party that bypassed it. ### AMENDMENT 1 — 2026-08-24 — third instance; the REACHABILITY half is fixed, the STRICTNESS half is still owed **Steward-authorized in-session** — *"yes, we need this fixed now."* Implemented and committed before this entry was written; this entry records what was done, not what is proposed. **Third instance, same shape.** `verify-before-compose` did not fire on any file written in this session either — the runbook edit, two memory trackers, the session ledger — because every write went through Bash. Found today only by censusing the configured hooks after the steward observed the session "felt intuitive"; **the executor reported it as a new discovery and only then read this item, which had carried it since 2026-08-20.** Reporting before reading is the same ordering error that produced a duplicate-tracker proposal earlier the same afternoon. **A second, independent victim of the identical defect.** `daybook-cue.py` (built 2026-08-24 11:19) was wired `PostToolUse | Write|Edit` — **the same matcher, copied from the hook whose blindness was already on this record.** It has never fired; `~/.claude/state/` does not exist. A known defect propagated into a new mechanism because it was recorded as an instance rather than as a class. **What was fixed.** `chamber-library/.githooks/pre-commit` (`4ccba76`) now gates staged constitutional artifacts — same scope predicate as the PreToolUse hook — on a `GROUNDED-IN:` attestation. **The commit is the tool-agnostic boundary**: however a file was edited, it passes through here. Controls run before committing: constitutional+ungrounded **BLOCKS** (exit 1), constitutional+grounded **PASSES** (exit 0), non-constitutional+ungrounded **PASSES** (exit 0). **What was deliberately NOT fixed, and why.** 1. **The strictness question is untouched.** The new gate reuses the CURRENT rule (marker anywhere in staged content), so it **inherits this item's original decay defect** by design. Options (a)–(d) above remain UNRULED and choosing one at the commit boundary would have pre-empted the steward. ⚠ **When that ruling lands it must be applied to BOTH surfaces** — the PreToolUse hook and the pre-commit gate — or they will diverge. Declared in the hook body, not only here. 2. **`--no-verify` bypasses it.** Speed-bump, not guarantee — the same claim the original makes. 3. **The PreToolUse hook is unchanged.** It still covers the Write/Edit route; no reason to remove. 4. **`daybook-cue.py` is NOT fixed.** Two gaps, and only one is this item's class: (i) reachability, shared with this item; (ii) its condition is `note_size < SKELETON_CEILING` (1200 bytes), so a session appending nothing to an already-filled note is invisible to it — today's note is 15,688 bytes and the cue would have stayed silent **even if reachable**. (ii) is a design choice, not a defect, and is not the executor's to redecide. **Still open on this item:** the (a)–(d) ruling, and the coverage question of which *other* guards are wired to tool-matchers the work routes around. `census-02-have-they-ever-fired` (2026-08-04) censused seven instruments; **three mechanisms built since have never been censused.** **Read surface widened so the ruling can have the right subject.** `governance-mcp.py` serves the jurist a fixed enum of files. It already carried PENDING-95 itself (via `read_item`), the whole register, and chamber-library's git log — so most of this ruling was reachable unaided. It did **not** carry the two artifacts the ruling GOVERNS. Ruling from the record alone would have made the subject the executor's *description* of the hooks rather than the hooks — the exact defect recorded inside REVIEWED-125 (*"the ruling's subject was the pasted text, not the filed artifact"*). Added two read-only keys, `grounding-hook-pretool` and `grounding-hook-commit`, under the **PENDING-86 option (a) precedent** already sitting three lines above them in the same dict. Enum design unchanged, no path argument, no write path; the AST no-write invariant and its positive control still pass. ⚠ **Requires a steward restart of the desktop app** — the key map is built at import, the same friction that held PENDING-134. ⚠ **Done on the steward's in-session instruction rather than a separate authorization; read-only and reversible by deleting two dict entries** if that reads as overreach. **Awaiting:** steward ruling on (a)–(d), now applying to two surfaces rather than one. ### AMENDMENT 2 — 2026-08-24 — RULED. (a) rejected, (d) discharged, (b)/(c) deferred on a census **Jurist ruling placed by the steward** (REVIEWED, id unasserted pending PENDING-110's `REVIEWED-N`/`PENDING-N` collision). Ruled from a **verbatim read of both hook artifacts**, which the two read-only keys added earlier the same session made possible; the ruling records that findings 1–3 exist only because of that widening. **⚠ A CLAIM IN AMENDMENT 1 WAS FALSE AND THE JURIST CAUGHT IT BY READING THE CODE.** Amendment 1 said the pre-commit gate "reuses the CURRENT attestation rule." It does not. The PreToolUse hook tests the payload **plus the file as it was on disk**; the pre-commit gate tests `git show ":$file"`, the **resulting** artifact. **The two surfaces had already diverged, and the new one is strictly stricter.** Verified empirically before accepting the finding: an edit stripping the only marker from a marked file **exits 0 at the PreToolUse hook and 1 at the commit gate**. The standing instruction is therefore amended and is asymmetric — *the pre-commit semantics are the FLOOR, do not equalise downward*; the PreToolUse hook owes the payload-vs-disk correction regardless of (b)/(c). **(a) REJECTED** — not revisited without new steward input. **(d) AUTHORIZED unconditional, and DISCHARGED 2026-08-24** across the surfaces that were owed it (`8eea85f` + the PreToolUse header): per-file decay stated, the divergence stated, and — the finding neither party had before the read — **the `(read YYYY-MM-DD)` field and the "Grounding section that QUOTES them" requirement are ADVISORY TEXT PARSED BY NOTHING.** Both surfaces test the bare substring `GROUNDED-IN:`. Marker presence has never been evidence that any reading occurred. **⚠ On (d) obligation 2, the ruling's premise was already stale, and this item is why.** The ruling directs correcting chamber-library `CLAUDE.md`'s *"is **DENIED** unless the artifact carries"* clause and notes honestly that the jurist cannot verify its state (outside its read enum). **Checked: that clause was already corrected on 2026-08-06 under PENDING-106, jurist-authorized FIX**, and now records all three consequences explicitly, including the once-per-file decay and the unenforced QUOTES requirement. **What was stale is THIS ITEM's quotation of it** — PENDING-95 is dated 2026-08-04 and was never updated after the 08-06 correction, so the jurist read a two-day-old quote as current. Nothing to fix in the constitution; the defect was in the register quoting a document instead of pointing at it. **(b)/(c) DEFERRED**, on a stated and cheap condition: a read-only census of the 31 marked guarded files recording, per file, whether the marker carries (i) a parseable date, (ii) named §sections, (iii) a Grounding section that actually quotes — **distribution, not summary.** Ruling between (b) and (c) now would authorize a mechanism against an unknown input format and would likely invalidate markers retroactively. The jurist offers a **third form, explicitly outside the four and offered as a scope expansion for the steward to accept or refuse**: require the marker's date to be no older than the last substantive change to the artifact it grounds — (c)'s firing semantics with no format migration. And: draft the new marker against three real files before authorizing the rule that invalidates the other 28. **Read-surface doctrine, accepted.** The two keys were added on in-session instruction. The jurist records this as exemplary in disclosure and load-bearing in effect, and holds the doctrine point anyway: **the jurist's read surface is the one instrument the jurist cannot audit, so changes to it should arrive as recorded rulings, not in-session authorization.** ⚠ **Adopted as binding on the executor from now.** Accordingly, the obvious next key — chamber-library `CLAUDE.md`, whose clause (d) obligation 2 concerns and whose state the jurist could not verify — is **NOT being added unilaterally; it is proposed and awaits a ruling.** ### THE (b)/(c) CENSUS — RUN 2026-08-24, the condition is discharged *Read-only, no new instrument, as ruled. Definitions declared before counting: **(i)** `(read YYYY-MM-DD)` in the marker line · **(ii)** a `§` in the marker line · **(iii)** a heading matching /grounding/i with at least one blockquote line in the 40 lines after it. Per-file table preserved in the session record so the classification is checkable, not just the totals.* **⚠ First result: the item's own numbers were stale.** **60 guarded / 32 marked / 28 unmarked**, not 59/31. Verified by walking the tree against the five basename patterns, not relayed. The drift is one file each way and changes nothing, but the item has been quoting 59/31 since 2026-08-04. | | count | share | |---|---|---| | marker carries a parseable **date** | **24 / 32** | **75%** | | marker names **§sections** | 31 / 32 | 97% | | a **Grounding section that actually quotes** | **15 / 32** | **47%** | **Distribution (the jurist asked for this, not a summary):** | date | §sec | quotes | files | |---|---|---|---| | ✓ | ✓ | ✗ | **16** | | ✓ | ✓ | ✓ | 8 | | ✗ | ✓ | ✓ | 6 | | ✗ | ✗ | ✓ | 1 | | ✗ | ✓ | ✗ | 1 | **This decides the ruling's own fork.** The jurist wrote: *"if the date field is broadly absent, (c) is the only live option… if broadly present, a third form becomes available."* **It is broadly present — 75%.** So the third form is live: *require the marker's date to be no older than the last substantive change to the artifact it grounds.* No format migration for 24 files; 8 need a date added. **(c)'s firing semantics at roughly a third of (c)'s cost.** **⚠ The largest single class is the one that matters: 16 files carry date AND §sections AND NO quoting Grounding section.** Marker complete, substantive half absent — the protocol's own evidence that the attestation has been doing ceremonial work. This is PENDING-109's prior, now with a number. ⚠ **A caveat that cuts against reading 47% as a failure rate.** All ten `chamber-library-specification*.md` files score `DS-`, and that may be **correct by category**: the spec is what one grounds *in*, not a grounded draft, so it has no occasion for a Grounding section. Excluding them, quoting runs **15/22 = 68%**. I have not established which reading is right — it turns on whether the marker on a spec file means "this version was grounded" or "this file grounds elsewhere," and that is a question for the party who placed them. **Both figures are reported because choosing one silently would be the finer-instrument error the ruling warns about.** **Not done, and named:** the ruling's *"draft the new marker against three real files before authorizing the rule that invalidates the other 28"* — deliberately left, since it is an authoring act under the third form, and the third form is a scope expansion the steward has not yet accepted. **Awaiting:** steward direction on the (b)/(c) census, and on the third form as a scope expansion. ## PENDING-96 — The engine's `SILENCE — ✓ warranted` certifies the index and claims the answer **Date:** 2026-08-04 **Tag:** [HARDENING] **Summary:** When retrieval returns nothing, the engine reports *"No match — this is genuine silence, not a gap"* on the strength of a check that only establishes the index is complete and current — it cannot establish that retrieval reached what is there. **Rationale:** Asked `grey zone`, the engine returns certified silence. The corpus holds **ten** matches for `gray zone`, **all ten in `levi-drowned-and-saved`**. The corpus is American-spelled; the steward is Canadian-spelled. This is the shape census 01 was opened to catch — a passing check certifying a property of the code while claiming a property of the result — now at the engine's consuming end, and wearing a checkmark that makes it *more* credible than an ordinary empty result. It bears directly on the telos: a voice that says "I have nothing on the grey zone" about Primo Levi is not a cautious voice, it is a confidently wrong one, and confident wrongness is the exact failure v1 was retired for. **Falsifier, already run:** the probe *"the quality without a name"* returns the same certified silence and is **correct** — *The Timeless Way of Building* is not among the 13 sources. The warrant is not always wrong; it is unable to tell its two cases apart, which is the defect. **Options:** (a) restrict the warrant's wording to what it checks — "the index is complete and current as-of X; no match was found" — and drop "genuine silence, not a gap"; (b) additionally report the retrieval method and its known blindnesses on every silence, so the reader can judge; (c) make silence conditional on a second, differently-implemented probe agreeing (differently-biased checkers applied to retrieval). **Recommendation:** (a) immediately — it costs one string and removes a false assurance today. (b) next. (c) is the durable answer and is entangled with PENDING-97; it should not be designed before the retrieval decision is taken. **Files affected:** `~/_Dev/studium-engine/engine/retrieve.py` (the silence branch and its warrant string). **None touched.** **Awaiting:** Steward authorization. ### ADDENDUM — 2026-08-04, AUTHORIZED and PARTLY LANDED. **This item stays OPEN.** *Recorded after the act, not before it.* **Jurist sharpening, adopted.** The diagnosis was refined in review and the refinement is now the operative framing: the completeness check verifies **document coverage** — every book was scanned — while the warrant claimed something about **query-matching**, a different kind of claim. A check defined by the retrieval mechanism's own notion of "found" cannot see a miss that mechanism is structurally blind to. The falsifier does real work: the check is not wrong in general, only wrong exactly when a true match exists under a variant the tokenizer does not fold. **LANDED (a), tightened past my draft on the jurist's wording.** My proposed replacement still carried a smaller version of the same overclaim — "the index is complete and current" is true of document coverage and unverified of query-matching, and a reader who does not already hold that distinction collapses the two, exactly as the engine did. Now shipped: > `SILENCE — ✓ coverage-warranted · tier: single-method` > Every document in the served scope (13 section(s), 5685 chunk(s)) was scanned, and the index is current as-of *T*. **The query as submitted matched no indexed tokens.** The verdict mark was tightened by the same logic: `✓ warranted` beside a silence reads as *this silence is correct*, when only the coverage half was ever checked — hence `✓ coverage-warranted` / `✗ COVERAGE UNWARRANTED`. **LANDED (b)** as a fixed constant `RETRIEVAL_BLINDNESS`, attached to **every** silence (warranted and unwarranted alike), since the blindness is a property of the implementation and not of the query. Its content is verified against `chunker.normalize` and the FTS5 query path, not asserted: token-level under `normalizer@1` (NFC · long-s · ligatures · soft hyphen · whitespace), multi-token queries conjunctive, no spelling fold, no stemming, no semantic matching — closing with *"its absence here is not evidence of its absence from the corpus."* **LANDED (c)-tag only.** `silence_tier: "single-method"` now rides on every silence, so the future cross-checked silence needs no third string migration at the display layer. The (c) mechanism itself remains correctly deferred behind PENDING-97. **Coupling registered in code, not in memory.** A `⚠` comment at the constant states that `RETRIEVAL_BLINDNESS` **must** be revisited the moment PENDING-97 lands — any change to query construction, orthographic folding, or a semantic layer turns it into stale doctrine describing a mechanism that no longer exists. Registered at the site rather than trusted to a future session's recall. **Why this item does not close.** The jurist's process point, adopted: the finding *is* that a fixed instrument produced false confidence while wearing a mark that made it more credible — so shipping a better string is itself a small instance of "the feeling of done." Three things remain: 1. **The disclosure is provisional until PENDING-97 is ruled.** Its accuracy has a shelf life tied to a decision not yet taken. 2. **(c) is deferred, not done** — one method still establishes every silence. 3. ⚠ **The fix is unguarded.** `tests/` holds `test_ingest_gate.py` and `test_verify_quote.py` and **nothing references `retrieve.py`** — the organ whose output the steward reads directly has no test at all. The new wording can regress silently. Surfaced, not fixed: a retrieval test suite written against a retrieval method about to change is the wasted design the (c) deferral already refused. **Closing condition:** PENDING-97 ruled → `RETRIEVAL_BLINDNESS` re-verified against whatever retrieval then exists → a regression test binding the six banked probes. Not before. **Verification run, both directions:** `grey zone` → coverage-warranted silence carrying the blindness (the false-silence case, now honest). `the quality without a name` → identical form, and **correctly** silent (*The Timeless Way of Building* is not among the 13 sources). The two now read alike, which is right: the engine cannot distinguish them, and pretending it could was the defect. `gray zone` → 3 citations surfacing `## The Gray Zone` itself. Full six-probe set re-run; hit path and `--json` shape intact. **Files touched:** `~/_Dev/studium-engine/engine/retrieve.py` (imports · two module constants · silence construction ×2 · display). ## PENDING-97 — Engine retrieval AND-s bare tokens and has no semantic layer: recall collapses as the question lengthens **Date:** 2026-08-04 **Tag:** [PROPOSAL] **Summary:** `retrieve.py` passes the user's normalized string straight to `drawers_fts MATCH`, where FTS5 bare terms are conjunctive, so a natural-language question must have **every** token co-occur in one drawer — and the corpus has no vector index at all. **Rationale:** Measured on the real index: `gray` → 51 hits · `gray zone` → 10 · `levi the gray zone` → **0** · `what does levi mean by the gray zone` → **0**. The engine's stated purpose is discourse with a library; a question phrased as a question is the normal case and it returns nothing, certified (PENDING-96). `embed_spike.py` and `rerank_spike.py` exist but remained spikes; `sqlite_master` holds no vector or embedding table. This is a data-model and retrieval-architecture decision, not a bug fix — which is why it is PROPOSAL and not HARDENING. It is also the engine-side twin of the L1 finding: the ingest half is elaborate and governed, the consuming half has never been exercised against a real question, so nobody noticed it does not answer. **Options:** (a) query-construction only — OR the tokens with BM25 ranking, add phrase handling and an orthographic fold (British/American, œ/oe, accents) at index and query time; (b) (a) plus a semantic layer — embed the 5,685 drawers, retrieve hybrid, rerank; (c) treat retrieval as out of scope for V1 and instead constrain the engine to accept only quoted-phrase queries, making its narrowness explicit rather than silent. **Recommendation:** (a) first and separately, because it is cheap, reversible, and measurable against the very probes above — and because until it lands, no judgment about semantic retrieval rests on a clean baseline. Then (b) as its own decision with its own gate. (c) is worth naming because it is *honest*, and honest narrowness beats silent breadth — but it forecloses the telos, so it should be rejected deliberately rather than by default. **Confidence:** ~0.95 on the mechanism (measured, six queries, monotone). Low on the remedy — the orthographic question in particular (whose spelling is canonical when the reader and the corpus differ?) is a curatorial decision, not an engineering one, and it is the steward's. **Files affected:** `~/_Dev/studium-engine/engine/retrieve.py:99-103`, `engine/store.py` (index build), `corpus/index.db` (would require a rebuild). **None touched.** **Awaiting:** Steward authorization. ## PENDING-98 — Firing history is recorded only where a human is in the invocation path **Date:** 2026-08-04 **Tag:** [HARDENING] **Summary:** Census 02 classified all seven remaining instruments; the record divides cleanly by whether a person invokes the tool, not by the tool's age, quality, or importance. **Rationale:** Where `tool-evolution-log.md` reaches, the record is the best in the system — dated, artifact-named, `PASS-BUT-FALSELY` treated as the priority signal, patch and reason cross-referenced (`audit_cruft`: 160 corpus files found that the old gate was blind to; `verify_conversion`: 948/952 with 4 genuine fails; `apply_char_glyphs`: Levi, 527 docs, 0 unclassified). Where it does not reach, nothing records at all: `verify-before-compose` fired twice and the evidence survives only in Claude Code session transcripts, a harness artifact with unknown retention; `resolve_archived_source` runs on **every graduation**, is healthy at 349/349, and has **zero** entries in the log because no human invokes it; studium `verify-quote` and `fidelity_equivalence@2` are called by nothing but their own CLI and test suite. The log's own rule — *"after **every** use — success or failure"* — is in practice *after every use a human initiates*. Automatic use is invisible to it by construction, and automatic use is precisely the use that becomes frequent enough to matter. **Rationale, second order:** this is the same class as the 2026-08-03 governor findings and the 2026-08-04 replay finding, one level up. There the controls existed and never engaged; here the *recording* of engagement is the thing that never engaged. An instrument with no firing history cannot be audited, cannot be retired for disuse, and cannot be shown to have decayed — which is how census 01's 71 uncited ladder entries got there. **Options:** (a) have automatic gates append a one-line firing record to a machine log (path, verdict, timestamp) — cheap, but a log nobody reads is the `Recall canary FAILED` pattern, which fired 8 times unread; (b) (a) plus a wake-digest line that surfaces *counts* — "verify-before-compose: 0 firings in 30 days" — so absence becomes visible rather than silent; (c) extend the tool-evolution discipline explicitly to automatic tools, with a periodic review slot rather than a per-use one; (d) accept and declare that automatic instruments are unrecorded, so no one reads coverage into their silence. **Recommendation:** (b). (a) alone reproduces the exact failure this census exists to name — a record that exists and is never read is indistinguishable from no record. The wake already reads a digest daily and already reports pointer counts and drift counts; a firing-count line is the same shape and costs one script change. (c) is good practice but relies on a slot that will be skipped under pressure; (d) is honest but gives up something recoverable cheaply. **Files affected:** `~/dotfiles/scripts/wake-digest.py`; `~/.claude/hooks/verify-before-compose.sh`; `~/_Dev/chamber-library/_curation/tool-evolution-log.md` (the discipline statement). **None touched.** **Awaiting:** Steward authorization. --- ## PENDING-99 — The quoted tier accepts 3 of 17 human-verified citations, and the largest single cause is a full stop (CLOSED 2026-08-06 — REVIEWED-87 placed; @3 built and governing; Q2 carried to PENDING-100) **Date:** 2026-08-05 **Tag:** [PROPOSAL] — routes to the **jurist**: `fidelity_equivalence@N` bumps require jurist ratification (V0 Ruling §2.2), and the fold-list is closed by construction. **Summary:** Run against the phase-2 Mauss gold — 17 citations a human read, cited and audited in March, 0 fabricated — the ratified quoted tier verdicts `GUARANTEED` on **3 of 17**. The failures are almost entirely ordinary scholarly quotation practice, not corpus defects; the single largest contributor is a **terminal full stop the citing human added when truncating**, worth 5 of the 17 on its own. **How this was measured (first production call of `verify_quote`; census 02 found it had no caller anywhere).** Every quote was taken from the round `.txt` files (the verbatim French), not the session-log YAML (chapter refs only). Containment was tested against the current canonical under `engine/fidelity.py`'s own `fidelity_normalize` — the ratified relation, not a hand-rolled one — then re-tested with one convention relaxed at a time: | relaxation | accepted | marginal | |---|---|---| | `fidelity_equivalence@2` as ratified | **3/17** | — | | + markup excluded (`[^n]` markers, `_emphasis_`) | 6/17 | +3 | | + the quote's own elision (`[…]`) treated as a gap | 6/17 | +0 | | + quotation-mark form `'` ↔ `"` | 6/17 | +0 | | + space-before-punctuation in the canonical | 7/17 | +1 | | **+ trailing period dropped from the quote** | **12/17** | **+5** | **Controls.** A fabricated French sentence is absent under *every* relaxation including the fullest (the ladder never degenerates into accept-anything). `verify_quote` was positive-controlled independently: it verdicts `GUARANTEED` on a true quote at its true anchor, and on the known mislocation it returned `NOT-FOUND` **plus `⚠ found-elsewhere: lines 1181–1181 — the claimed anchor is wrong`**, locating the error without being told. The 5 that remain absent at full relaxation are genuine internal elisions and the one close paraphrase the March audit itself recorded — correctly unverifiable, and not part of this ask. **Two facts about the gold, established by mechanism, incidental to the ask but load-bearing for P5.** (i) **17/17 fail at their *stated* anchors** — the canonical was re-hashed twice after March (2026-06-12 footnote cleaning; 2026-06-16 line shift) and every line-ref is stale by one; this is exactly what V2 §14.1's **P5** exists to repair, now measured rather than asserted. (ii) **The census arithmetic — CORRECTED 2026-08-05 after the ruling, and both of my prior positions were wrong.** Measured by counting distinct `(quote, location)` pairs: **17 instances · 15 distinct**, with two quotes appearing twice (instances **[1,14]** and **[2,15]**). The log's own detail line names *"Citations 2 and 15"* as the mislocation — **one defect spanning two instances**. So the header closes exactly on an instance basis: **14 verified + 1 close paraphrase + 2 mislocation instances = 17**; its *"1 location mismatch"* counts the **defect**, the detail line supplies the instances. ⇒ **V2 §1.5's "15 verified verbatim" is the error**, reached by inflating *verified* until the arithmetic closed. My original flag was directionally right but mechanism-free; my **withdrawal** — *"extraction yields 17, so V2's reading is consistent"* — inferred a **breakdown** from a **total**, which a total cannot settle. Yesterday's banked pattern exactly: *a number that matches is not a cause*. It produced two candidates and I accepted each in turn. **Rationale — why this is a ruling and not a bug.** Every one of these failures lands on the *safe* side of the ratified asymmetry: abstention, never false trust. Nothing here is behaving incorrectly. What the number says is narrower and harder: **the quoted tier as ratified cannot verify a competent scholar's ordinary citation practice**, and the chavruta — the engine's reason for being — *is* that practice. An organ that accepts 3 of 17 genuine citations cannot serve quotation-checking for the use it was built for. The four causes are not one kind of thing, and that is the substance of the ask: - **Markup crossing (+3).** Named already at V2 §1.6 as the largest single Tier-1 finding and flagged unruled at §11.1. The chamber constitution has arguably already decided the principle in the other direction: §V holds the inline anchor marker to be *"content-for-the-reader but **not a prose word**"*, **excluded** from the prose-word-identity comparison, and §II.3 binds the marker to *"not corrupt the prose-word-identity check under §V"*. §V also calls a note's display number *"a carrier artifact"*. So chamber and engine currently take **opposite positions on the same object**, and the engine consumes the chamber's canonicals. Whether a pandoc `[^n]` *is* §II.3's inline anchor marker (whose exclusion is ratified) or a distinct apparatus reference marker is precisely the scope question, and it is not mine. - **Terminal punctuation (+5).** Not a form fold at all. Dropping a trailing period accepts a quote that is *not byte-contained* — a different class of act from folding `’`→`'`, and the one carrying real risk. - **Space-before-punctuation (+1).** A French-typography artifact in the canonical; plausibly a cleaning-gate concern under V0 Ruling §2.4 rather than a relation question. - **Elision (+0 here, but 5 of the residual).** Structural, not typographic. Folding it would let a quote skip arbitrary text. My position is that it must **not** be folded — the correct remedy is that an elided quote is a *multi-span* citation and should be modelled as such, which is the same shape as the two-span composite resolved under D-1 today. **Options.** (a) Rule the markup class only — the narrowest bump, already evidenced, and arguably just aligning the engine with a chamber principle already ratified. (b) (a) plus a *quotation-truncation* allowance for terminal punctuation, defined as its own named class rather than smuggled into the fold-list, since it is not a form equivalence. (c) Rule nothing yet; treat 3/17 as the measured Tier-1 cost and require the chavruta to cite by *constructed* citation (engine-emitted, carrying `text_original` bytes, immune by construction) rather than by reasoner-typed quote. (d) Decline all, and accept that the quoted tier is for machine-constructed citations only, declaring that limit on its own output. **Recommendation:** **(c) now, (a) next, (b) only on its own evidence.** (c) is available immediately, requires no ruling, and is honest: the failure class bites *reasoner-typed* quotes and construction-side citations are immune, so the chavruta can be built to cite the way the engine is already sound at. (a) is the narrowest widening and the one where a chamber/engine divergence — not a preference — is the argument. (b) is where I would most expect to be wrong: +5 is the biggest prize and therefore the most tempting, and "accept a quote that isn't contained" is exactly the kind of loosening that reads as harmless and is not. It should need its own adversarial evidence, not this table. **What I am not asking for.** No fold applied, no relation bumped, nothing wired. `fidelity_equivalence@2` governs unchanged. This item carries the incidence V2 §11.1 said a ruling would require, and the scope question §V/§II.3 raise against it. **Files affected:** none touched. Evidence reproducible from `chamber-library` canonical `essai-sur-le-don-mauss.md` (sha `2889709555f2…`) + the phase-2 round files in the vault + `engine/verify_quote.py`, `engine/fidelity.py`. **Jurist package:** `studium-engine/docs/quoted-tier-acceptance-JURIST-PACKAGE-2026-08-05.md` (commit `c67586d`) — self-contained, five gate questions Q1–Q5 with executor leans. Verbatim containment proven mechanically before filing: **16/16 quoted clauses contained · 9/9 inversion-built controls absent · INSTRUMENT VERIFIED**. Every cited path re-verified in session. **Awaiting:** Nothing. **RULED 2026-08-06 — REVIEWED-87 placed** (ruling filed verbatim, `studium-engine/docs/quoted-tier-acceptance-JURIST-RULING-2026-08-05.md`). Q1 authorized on engine grounds + functional analogy, explicitly NOT chamber alignment; `fidelity_equivalence@3` built, governing, 22 checks. Q2 carried to the chamber side as **PENDING-100**, which remains open. This line still read *"Filed ≠ sent"* the day after the item was ruled on — the send-state marker was never advanced, which is the PENDING-108 class in its smallest form. *(Corrected 2026-08-06: first written as "eight days", from the executor misreading the external incident identifier `INC-2026-07-28-01` as our own filing date. One day. See the correction note under PENDING-108.)* --- ## PENDING-100 — Is a footnote's inline reference marker excluded from word-identity comparison? (chamber-side, routed from PENDING-99 Q2) **Date:** 2026-08-05 **Tag:** [PROPOSAL] — chamber constitutional. Routed here by the PENDING-99 jurist ruling (2026-08-05), which answered Q2 as a **reframing rather than a yes/no** and directed the real question chamber-side. **Summary:** §II.3's inline-anchor doctrine governs **citation-scheme** anchors (Stephanus, Bekker, book-line) and its **exact syntax is explicitly still open**. Footnotes are handled elsewhere, under §V. Neither clause says whether a footnote's inline **reference marker** — as distinct from its **display number** (§V: *"a carrier artifact"*) and its **text** (§V: Tier-3, *"never altered"*) — is excluded from the prose-word-identity comparison. The constitution is silent on the object that actually bit. **Why this is not closed by PENDING-99.** REVIEWED-87 ratified `fidelity_equivalence@3` **engine-side only**, on the engine's own typographic-in/orthography-out test plus *functional analogy* to §II.3's stated rationale. The ruling was explicit that this is **not** chamber alignment and must not be recorded as such — §II.3 ratifies no marker syntax, so there is nothing to align with. The engine now excludes `[^n]` from its quoted-tier relation; the chamber has **not** ruled that a footnote marker is a non-word. Those are different claims and the gap between them is real. **Why it matters beyond the engine.** §V's prose-word-identity guard is a **conversion** gate — it decides whether a re-extraction preserved the prose. If a footnote marker is *not* excluded there, a legitimate re-conversion that recovers or renumbers markers registers as a word-multiset delta and falsely fails; if it *is* excluded, that must be stated, because the guard's whole value is that its exclusions are enumerated. §II.3 already reasons exactly this way for its own marker — *"a legitimate re-extraction (which adds recovered anchors) would register as a word-multiset difference and falsely fail"* — but reasons it about a **different** marker class. **Options:** (a) rule the footnote reference marker excluded from the word-guard, by the same rationale §II.3 gives for the anchor marker — narrowest, and closes the observed gap; (b) rule it *included* (a real prose token), which makes the conversion guard stricter and requires the re-conversion consequence be priced; (c) fold this into the PROPOSAL that eventually closes §II.3's open marker-syntax item, so **both open edges close together**; (d) leave silent and let each consumer decide, which is the present state and is what produced this item. **Recommendation:** **(c)**, which is the ruling's own recommendation — *"so both open edges close together rather than the footnote question surfacing again later as its own surprise."* (a) is the likely substance of (c); (d) is the status quo and its cost is now measured; (b) is possible but nobody has priced the re-conversion consequence and it should not be ruled without that. **Not asked for here:** no spec supersession is drafted, no `graduation-spec.yaml` change, no re-conversion. This item exists so the question is **on file with its evidence** rather than resurfacing later as a surprise — which is the failure mode the ruling named. **Files affected:** none touched. Evidence: `studium-engine/docs/quoted-tier-acceptance-JURIST-RULING-2026-08-05.md`; chamber spec §II.3 / §V. **Awaiting:** Steward routing — this is chamber-governed (not D-1), so it needs the constitutional loop, not the engine's. --- ## PENDING-103 — "Rejected by the chain writer" is doc-only against a chain writer that exists and ships **Date:** 2026-08-05 **Tag:** [ESCALATE] **Why ESCALATE, not HARDENING:** the finding is about the **L2 constitutional layer**, which is on the standing escalate list. Per PENDING-101's hard boundary this is **flagged and left alone** — no remediation opened, no edit made. **Summary:** `constitutional-governance-addendum.md` makes two present-tense enforcement claims about the AdaptationChain writer. The writer exists in shipping L1 code. It performs neither check. **Evidence (Q1).** - Claim, §9.3: *"Only the constitutional enforcement subsystem … can write entries with this authorization type. **Any entry written with `system_enforced` by another initiator is rejected by the chain writer**."* - Claim, §14.2: *"An amendment that attempts to set `settlement_requires_stewardship: false` … **is rejected by the chain writer. This validation is hardcoded — it is not configurable**."* - Substrate: `BetterMemories.io/src/core/adaptationchain/writer.ts`, 553 lines. Zero occurrences of `system_enforced`, `autonomy`, `bounds`, `immutable`, or `civilizational`. It throws at two sites (`writer.ts:252`, `:283`), neither constitutional. - Repo-wide census of L1 (`src/`, tests excluded): `system_enforced` **0 files** · `ConstitutionalBounds` **0** · `computeEffectiveBounds` **0** · `max_autonomous_scale` **0** · `AutonomyLevel` **0**. `civilizational` and `stewardship_attestation` appear in **one** file only — `types/chains.ts`, as declared entry types with no consumer. - **Positive control (required by the brief):** the same method, in the same repo, locates real gates — `similarityProbeCarveOut()` at `core/keystone/orchestrator.ts:217`, the `_cm_forwarded_from` trust-delegation marker at four sites, and the I-CF confidence floor at `modules/base.ts:106`, exactly as `epistemic-gates-spec.md` §5 describes. The method detects gates where gates exist. **The honest limit on this finding.** The L2 machinery that would invoke these validations is **not yet built**, and the addendum marks itself *"design primitives"*, *"deferred to the build phase"*, *"Not a runtime implementation spec."* A defender would say the check lands when L2 lands, and that is fair. What is not covered by that defence: the sentences are **present-tense and name components that are already built and running** — the AdaptationChain writer and the Orchestrator both exist in shipping L1 (`core/adaptationchain/writer.ts`, `core/keystone/orchestrator.ts`). A reader consulting the addendum to learn what is enforced today is misled — the report's finding (2) in miniature, a documented "is rejected" standing in for a control. > **CORRECTION, same day, steward-supplied — recorded rather than silently edited (`~/CLAUDE.md` §Context Rot Prevention: "No silent edits").** > The original filing cited *"`~/_Dev/themind` does not exist on this machine"* as evidence. **That was a non-observation reported as a finding.** L2 is not absent; it is **in design, in `CapableMind-AI/docs/thinking/David/l2-constitution/`** — a live corpus (`constitution/`, `amendments/` incl. ICP-19 mandated-external-review and the F-series, `stratified-amendment-protocol.md`, `invariant-selection-criteria.md`, `l2-design-narrative.md`). The thinking→specs→code workflow means work-in-progress lives in `thinking/` **by design**; `themind` being empty of it is the expected state at this phase, not a signal. > **The finding is unaffected and is arguably sharper without the bad evidence:** it never depended on where L2 lives. It rests on the addendum naming two components *that exist and ship* as the enforcers, and neither performing the check. Removing the `themind` clause removes a false support, not a load-bearing one. > **What this correction is itself an instance of:** an absence claim whose instrument (a directory listing) could not distinguish *"not built"* from *"built elsewhere by design"* — the fourth such near-miss in this session, and the only one caught by the steward rather than by me. Entered on PENDING-102's docket as a same-direction miss the executor did not self-catch. **Classification:** Q1 **(c) doc-only**, qualifier *scheduled-not-yet-built* — a distinct and milder category than doc-only-in-a-built-system, and it should not be collapsed into it. **Files affected:** none — read-only. **Awaiting:** steward/jurist. Do not remediate without explicit authorization (constitutional layer). --- ## PENDING-105 — Q5 (a question Q1–Q4 do not cover): our compactor is the actor (CLOSED 2026-08-06 — REVIEWED-92: withdrawn by the executor; G15's binary stands) **Date:** 2026-08-05 **Tag:** [PROPOSAL] **Summary:** The report establishes as a **design fact** — not a hypothesis — that the entity summarising the context is the entity being summarised. §2.1: *"the conversation is compacted and a summary hand-off document is created **by the same model**, so the agent can continue working on the task."* Every summarisation step in our governance chain has this property. **Where it applies.** `/wrap-up` → `session-*.md` → `/wake-up` (I select what survives my own session); the Active Session entry in `MEMORY.md`; jurist packages (the executor chooses which ratified passages are quoted as grounding); every PENDING item in which the executor writes the account of its own work — **including these four**. **Why this is the right question and Q2 is not, quite.** Q2 asks whether uncertainty survives compaction — unanswerable from absence, and pre-fittable, which is why the brief demanded a synthetic test case. Q5 asks whether the compactor is **differently positioned** from the actor, which is a structural fact readable off the design, and it is the axis REVIEWED-86 makes doctrine. The answer for wake/wrap is plainly **no**. **The existence claim needs no synthetic case — it is already demonstrated.** PENDING-102 is a worked instance in our own chain, found today: a hedge dropped in a relay, uncaught for a day, by two parties in the same direction. A synthetic case is still owed to characterise the mechanism's *reach* (which classes of qualifier survive), and that remains Q2's job. **Prior art it joins, not duplicates.** The 2026-08-05 limit written on the containment instrument — *containment verifies that what you quoted is accurate; it cannot verify that you quoted what matters* — is the same defect on the selection axis rather than the modality axis. Both are the actor grading its own summary. **Files affected:** none. **Awaiting:** Nothing. **WITHDRAWN 2026-08-06 — REVIEWED-92 placed.** Conceded by the executor on inspection: the condition the proposal rested on was derived from PENDING-103, and PENDING-103 does not exemplify the class — `writer.ts` ships and does not perform the check, making it an undocumented gap under G15's existing binary, not a deferral. A category derived from a misclassified instance is a laundering slot. Do not revisit without an instance that genuinely exemplifies the class. --- ## PENDING-106 — Documents describe our gates as stronger than the gates describe themselves (CLOSED 2026-08-06 — instance applied + verified; the class carved out to PENDING-109, not buried) **Date:** 2026-08-05 **Tag:** [HARDENING] **Summary:** A class, found by comparing each gate's own self-description against the document that advertises it. In the one case measured, **the mechanism is the more honest of the two**. **The measured instance.** `chamber-library/CLAUDE.md` states the `verify-before-compose` hook *"the write is **DENIED** unless the artifact carries a `GROUNDED-IN:` attestation."* The hook's own header (`~/.claude/hooks/verify-before-compose.sh:10–17`) says: *"Satisfiable + **fail-open by design**… any unexpected condition → exit 0 (never break the ability to write)… The gate is **a speed-bump that makes grounding CONSCIOUS, not a guarantee**."* The pass-through that PENDING-95 reports as a disarm is documented intended behaviour at line 12 and implemented at line 43 (`*GROUNDED-IN:*) exit 0`) — it is not a hidden gap; it is an advertised one, advertised in the place fewer people read. **Classification:** Q1 **(b) procedurally enforced**, described in prose as if **(a)**. The wiring is real (`~/.claude/settings.json:55`). **Why file the class rather than the instance.** PENDING-95 already holds the instance. What this pass adds is the **direction of the error**: the gap between doc and mechanism ran in the direction of the doc over-claiming, in the one case checked. That direction is the one that matters, because a reader calibrates on the doc. Whether it holds across the fleet is unmeasured — **this is one instance, not a census**, and it should not be reported as one. **Files affected:** none. **Awaiting:** steward — whether a fleet-wide doc-vs-mechanism comparison is worth the pass. ### 2026-08-06 — the authorized FIX is APPLIED, and the sentence held THREE overclaims, not one **Applied:** `~/_Dev/chamber-library/CLAUDE.md`, the *"ground an amendment draft"* clause. ⚠ **Scope note the steward and jurist should object to if they disagree.** The ruling authorized bringing *"DENIED unless"* into line with the hook's own *"fail-open … speed-bump, not a guarantee"*, FIX-scoped, *"removes an overclaim, adds nothing."* On reading `verify-before-compose.sh` in full, **the same sentence carried two further false statements about the same hook**, and correcting only the named one would have left them standing behind a sentence now advertised as corrected — the `removing-a-claim-is-not-removing-the-reliance` shape. I corrected all three. That is a wider edit than the words of the ruling, narrower than its intent; it is flagged here rather than absorbed. **The three, as measured against the script:** 1. *"the read is enforced, not trusted"* — **false.** The hook checks for the **presence of the string `GROUNDED-IN:`**. It cannot observe whether anything was read. Marker presence is not evidence of a read; it is evidence of a marker. 2. *"the write is **DENIED** unless…"* — **overclaim.** Fail-open by design (`l.14`), and blocking requires path ∈ `*chamber-library*` **and** basename ∈ a five-pattern set. Everything else exits 0 silently. 3. *"and opens with a Grounding section that QUOTES the ratified sections it builds on"* — **not checked at all.** Pure protocol. **This is the half that makes the requirement substantive**, and it is the half with no mechanism behind it. **Substantive mechanism finding, not a wording matter — the gate is once-per-FILE, not once-per-write.** The haystack is the write payload **concatenated with the existing file on disk** (`verify-before-compose.sh:38–41`). Once any artifact contains `GROUNDED-IN:`, every subsequent `Write`/`Edit` to it passes with no fresh grounding. Deliberate per the script's own comment (*"grounding done; proceed"*), so **not a defect** — but materially weaker than *"DENIED unless the artifact carries…"* implied, and it means the discipline is exercised **once, at creation**, on artifacts that are then edited repeatedly. ⚠ **The recursion is worth recording.** Yesterday the containment prover caught the executor **dropping clause (3)** from its own quotation of this very sentence (16/17 → corrected), and it was restored as *"the clause that makes the requirement substantive."* That judgement was right. It also turns out to be the one clause of the sentence **no mechanism enforces**. Both hold at once: the quotation was wrong to drop it, and the requirement it states has never been anything but doc. **Bearing on the open half (kind (a) census):** this is now **one document, three overclaims, one of them the load-bearing clause** — a materially stronger prior than the single instance the item was filed on. It does not settle instance-vs-pattern; it raises the expected yield of the census. ### CLOSED 2026-08-06 — steward-directed, and closed by SPLIT rather than whole **Verified against the substrate, not the ledger.** The Symmetria ledger's line *"PENDING-106 — doc FIX applied"* is a record; it was checked rather than believed. The clause in `~/_Dev/chamber-library/CLAUDE.md:90` now reads *"the read is a PROTOCOL, and the hook is a speed-bump under it, not an enforcement of it"*, carries the `⚠ CORRECTED 2026-08-06 (PENDING-106, jurist-authorized FIX)` marker, and enumerates all three overclaims plus the once-per-file mechanism finding. Landed in `bb68e3f`, *"[FIX] CLAUDE.md: the verify-before-compose clause overclaimed the hook three ways"*. **Unpushed at time of closing** (chamber-library ahead 1). **Why split rather than closed whole.** This item's own text names an *"open half"* — the kind-(a) fleet census, authorized under the INC package's Q4 and never run, with no date. Marking the whole item CLOSED would have retired authorized work by bookkeeping, which is the failure PENDING-4 above documents in the opposite direction (an item advertising itself as open for 4½ months because its completion lived in the body, not the header). The instance is done; the class is carried to **PENDING-109** with its evidence intact, so that exactly one item is open for exactly the work that remains. **Ruling record:** the Q4 authorization and the item split are drafted as **REVIEWED-91** in `~/dotfiles/claude/governance/REVIEWED-drafts-2026-08-06.md`, awaiting steward placement. The wider-than-authorized scope of the applied FIX (three overclaims corrected where one was named) is flagged above for objection and is **not** absorbed by this closing. --- ## PENDING-108 — A jurist ruling is filed as a document only when someone remembers; the one that was not is the most constitutional of the set **Date:** 2026-08-06 **Tag:** [HARDENING] **Summary:** `/jurist-package` mandates that a returned ruling be filed verbatim as its own `*-JURIST-RULING-.md`; across the 13 packages authored since the skill existed, 12 were and one was not — the INC-2026-07-28-01 cross-repo package, whose rulings had to be **reconstructed the same day they were ruled**, from a session memory, in the executor's wording, for the steward to check. > **CORRECTED 2026-08-06, jurist-caught, and the correction strengthens the item.** This summary first read *"reconstructed eight days later."* False. `INC-2026-07-28-01` is the **UK AI Security Institute's own incident identifier** — an incident of 2026-07-28 — and the executor read a date out of an **external identifier** and used it as our timeline anchor. The package's own footer gives the real sequence: report published 2026-08-04, read in full 2026-08-05, package filed 2026-08-05, ruling acted on 2026-08-06, reconstruction 2026-08-06. **Same day, not eight.** Three instances propagated from the single misread (here, PENDING-99's `Awaiting:` line, and the drafts file); all corrected, none silently. Per `removing-a-claim-is-not-removing-the-reliance`, the test is not whether the phrase is gone but whether the conclusion still needs it: **it does not, and the corrected fact is worse for us.** "Eight days" was carrying an argument about *decay over time*. What actually happened is that **one day was enough** to make five of seven blocks reconstructions with four gaps that could not be recovered at all — the jurist's reasons for striking PENDING-101's findings (1) and (3) among them. The unfiled ruling does not degrade slowly; it is unreconstructable almost immediately. **How this was found.** The steward asked why no jurist package had been filed for the INC work. The premise was wrong — a package *was* filed, and it is among the most rigorous in the set (432 lines, G1–G16 grounding, consequence-trace, scope boundary, containment proof of its own quotations). What is missing is the **return leg**: the ruling document. `~/.claude/skills/jurist-package/SKILL.md:73` prescribes it in as many words — *"When the jurist's ruling returns (steward-relayed), file it verbatim as its own `*-JURIST-RULING-.md`, then append to the package"* the Addendum. **The measurement, and it refuted the executor's first two framings.** | Set | Packages | Ruling record exists | No record | |---|---|---|---| | `FOR-JURIST` convention (2026-07-03 → 07-20, before the skill) | 23 | 5 | **18** | | `JURIST-PACKAGE` convention (2026-07-20 → 08-05, after the skill) | 13 | **12** | **1 — the INC package** | Method: every `*JURIST-PACKAGE*.md` / `*FOR-JURIST*.md` under `~/dotfiles/claude/governance`, `chamber-library/docs`, `studium-engine/docs`, stem-matched against every `*JURIST-RULING*.md`, with unmatched packages then re-checked for an in-package `Addendum` recording the ruling. 45 packages, 31 ruling documents, 5 Addendum-only, 19 with no ruling record anywhere. **Two executor errors, both caught by measuring, both recorded rather than quietly dropped.** 1. **Asserted a fleet-wide pattern from n=5.** The executor told the steward that "every ruling that got filed had a build waiting on it" and that the INC case was the anomaly — generalised from five items, before running any fleet check. The first check returned **24 unpaired packages**, refuting the fleet-wide claim outright. This is `ATTRIBUTED-A-CAUSE-WITHOUT-RUNNING-THE-AVAILABLE-COUNTERFACTUAL` from 2026-08-06, recurring the same day it was banked, in the item that reports it. 2. **The refutation was then itself too coarse.** 24 unpaired split into 5 Addendum-only and 19 with no record — and the 19 stratify almost perfectly by naming convention, i.e. by whether the skill existed yet. Only the second cut showed what was actually true. **What survives, stated at the strength the evidence supports.** - **Checked:** post-skill, 12 of 13 packages filed the ruling. The skill works; this is a *prevention* instance, not only a failure report. - **Checked:** the single post-skill exception is the cross-repo constitutional package — the one whose rulings touch `~/CLAUDE.md` Constraint #1, the differently-biased-checkers doctrine, and the modality-preservation requirement. - **NOT established:** why. The executor's conjecture — that a ruling gets filed when a *build* consumes it, and the INC rulings authorized mostly decisions rather than artifacts — is now an n=1 story about a single case. It is recorded as a conjecture and **must not** be used as the rationale for a mechanism. - **Bounded historical loss, not a backlog:** for the 18 pre-skill packages the verdict survives in `~/REVIEWED.md`; what is gone is the *reasoning*. Not proposed for repair. **Why this is worth a mechanism despite the unknown cause.** The detector's value does not depend on knowing why the step is skipped. It fires on the condition — package with no ruling record — regardless of mechanism, and the condition is exactly what makes a ruling unreconstructable later. It also already **has its demonstrated negative instance**: the check above was run before this item was filed, on real data, and it found the INC case plus 19 historical ones. Per the standing L2 requirement, a bound that ships without a demonstrated firing is documentation. **Options.** - **(a) Nothing; rely on the skill's prescription.** Rejected on the evidence: the step was prescribed, proven, performed twice in the same directory days earlier, and still skipped on the most important item. - **(b) A detector in `governance-drift-check.py`.** Report any `*JURIST-PACKAGE*.md` older than N days with no matching `*JURIST-RULING*.md` and no in-package Addendum. Runs at every wake, in the invocation path that does **not** require a human to remember — the census-02 property that distinguishes a gate that fires from a gate that is merely available. - **(c) File-before-act.** The ruling document is written before any act the ruling authorizes. The say–do seam applied to rulings. - **(d) Make placement the forcing function** — no PENDING item may be marked CLOSED without a REVIEWED reference. Rejected as filed: it enforces bookkeeping order, not record existence, and PENDING-106 was closed today with its REVIEWED entry still only drafted. **Recommendation: (b) with (c).** (b) is mechanical, needs no judgement, costs milliseconds, and is honest about being a *detector* — it makes an absence visible, it does not prevent one. Say so at the point of use, per Constraint #4 and PENDING-107's lesson: this is detection, not enforcement, and it must never be described as the latter. (c) is the discipline (b) surfaces the breach of. Detection needs no authorization; changing the skill's prescribed order does. **Pre-registered falsifier.** If, over the next 10 packages, the detector fires zero times *and* no ruling is later found missing by other means, the check is measuring a fixed historical incident rather than a live class, and should be retired rather than kept as reassurance. Record the count; do not let a silent check accumulate into evidence of health. **Files affected:** `~/dotfiles/scripts/governance-drift-check.py` (new check); `~/.claude/skills/jurist-package/SKILL.md` (the (c) ordering); none if DEFERRED — the finding above stands on its own. **Awaiting:** Steward authorization for (b) and (c). The measurement is already done and needs none. --- ## PENDING-109 — The kind-(a) doc-vs-mechanism fleet census: authorized under Q4, never scheduled **Date:** 2026-08-06 **Tag:** [HARDENING] **Summary:** The class half of PENDING-106, carved out so that closing the applied instance did not retire authorized work by bookkeeping — a fleet-wide comparison of each gate's own header/docstring against the document that advertises it, bounded to kind (a). **Provenance.** PENDING-106 measured one instance and found the doc over-claiming against an honest mechanism. Its Q4 was put to the jurist in `INC-2026-07-28-01-cross-repo-findings-JURIST-PACKAGE-2026-08-05.md` Part VIII and **authorized 2026-08-06** — recorded as drafted **REVIEWED-91**, `~/dotfiles/claude/governance/REVIEWED-drafts-2026-08-06.md`, awaiting steward placement. PENDING-106 is CLOSED as of 2026-08-06 on its applied instance only; this item carries the remainder. **Scope, bounded explicitly and not to be widened silently.** - **In:** kind (a) — the document over-claims against a mechanism that describes itself honestly. Method: for each gate, compare its own header/docstring against the document that advertises it. Mechanical; needs no new instrument. - **Out:** kind (b) — doc and mechanism both over-claim. There is no honest party to compare against, so the method does not reach it. A different instrument is owed and is **not** authorized here. **Prior, strengthened since filing.** The one document examined in full carried **three** overclaims about a single hook, not one — and the third (*"opens with a Grounding section that QUOTES the ratified sections it builds on"*) is both the clause that makes the requirement substantive **and** the clause with no mechanism behind it. That raises the census's expected yield. It does not settle instance-versus-pattern, and this item must not be written up as though it had. **What this item needs and does not have:** a date. It was authorized-to-proceed and left as "later", which is the state PENDING-108 exists to make visible. **Files affected:** none yet — read-only census; findings return as new items. **Awaiting:** Steward — a date, not an authorization. The authorization is given (Q4). --- ### Contribution 2026-08-24 — the prior is now CONFIRMED BY DIRECT READ, not inferred Filed by the jurist while it had the substrate. This item's prior — that the *"QUOTES the ratified sections"* clause has **no mechanism behind it** — is confirmed on **both** grounding surfaces: each tests the bare substring `GROUNDED-IN:` (`case "$haystack" in *GROUNDED-IN:*` and `grep -q 'GROUNDED-IN:'`). Neither parses the date field nor validates marker shape. Previously inferred; now read. ⚠ **Scope: two of two artifacts within the jurist's read enum; a parser outside that surface cannot be ruled out.** ⚠ **And a routing decision recorded so it is not silently reversed:** the residual coverage question (guards wired to tool-matchers the work routes around) was expected to land here and **does not**. This item is bounded to **kind (a)** — an honest mechanism under an over-claiming doc. `daybook-cue.py` is a different kind: nothing over-claims; the mechanism is simply off the path. Folding it in would silently widen a scope this item says is not to be widened silently. Opened as PENDING-156. ## PENDING-110 — `REVIEWED-N` and `PENDING-N` are independent sequences that now collide, and a bare number no longer identifies an item **Date:** 2026-08-06 **Tag:** [HARDENING] **Summary:** The two registers were never tied to each other; they have drifted into a range where the same integer names two unrelated items, and today's placement of REVIEWED-88 through -93 made six such collisions at once — including a sentence in REVIEWED-89 that reads *"DOCKETED on PENDING-89"*, in which the number 89 appears twice meaning two different things. **How it surfaced.** The steward read "REVIEWED-88 through -93" as `PENDING`-88 through -93 — items from late July, a long way back in the register — when the entries in question are the newest in the file, lines 921–951 of 960. The misreading was correct behaviour on an ambiguous reference. The executor had written the ambiguous reference repeatedly in the same session without noticing. **Measured, not estimated.** - **88** numbered `REVIEWED` headings; **33** carry no `PENDING-N` on the heading line. - **6** of those 33 have a same-numbered `PENDING` in the register. For most (11, 12, 78, 81, 82) the numbers happen to name the *same* item — harmless. For **REVIEWED-86 / PENDING-86** they name entirely different items (*differently biased checkers* vs *the jurist cannot read the constitution it design-gates*) — a live collision. - **REVIEWED-88…93**, placed today, each *do* name their PENDING in the heading — but their numbers collide with **PENDING-88…93**, six unrelated open items (skill-harvest FIX lane · Q3 correlation review · first L2 transfer · Vignette 1a · idle ladder · `getChainsContainingSeq`). - **~140** bare `REVIEWED-N` citations exist in `chamber-library`/`studium-engine` code comments, docstrings and test names. - **3** bare headings (78, 81, 82) are the exact three `wake-digest.py` over-reports as unruled, because it matches on the literal string `PENDING-N` in the heading. One defect, two symptoms. **Root cause.** `REVIEWED-N` was never defined as *the ruling on `PENDING-N`*. Early entries were coincidentally aligned (REVIEWED-11 ↔ PENDING-11, -12 ↔ -12), which taught the alignment as an expectation without ever making it a rule; the sequences diverged and never recovered. `~/CLAUDE.md`'s own template says `## REVIEWED-[N] — [Matches PENDING-N title]` — *matches the title*, not the number, which is precisely the gap. **Options.** - **(a) Renumber so the sequences align.** REJECTED. It rewrites a historical record — one entry of which is GPG-sealed — to fix a legibility problem, and silently breaks every commit message, code comment and `engine/fidelity.py` citation pointing at a REVIEWED number. - **(b) Convention: never write a bare register number again.** Always `REVIEWED-89 (PENDING-102)`. Costs nothing, needs no migration, and most headings already do it. - **(c) Backfill the headings.** Bounded to those where the number names a *different* item, plus the three the digest miscounts — not all 33, most of which are unambiguous (REVIEWED-29 states outright it has no PENDING number). - **(d) Teach `wake-digest.py` to read the body, not only the heading,** for `PENDING-N`. - **(e) Migrate the ~140 code citations.** REJECTED. They sit in docstrings and comments where surrounding context disambiguates; the change is large, mechanical, touches gate code, and buys little. **Recommendation: (b) + (c) + (d).** (b) is the rule. (c) is one-time and small, and is the steward's hand — `REVIEWED.md` is not the executor's file. (d) is the durable part and the reason to do all three: **it is the only one that does not depend on anyone remembering.** Per PENDING-108, filed hours earlier in this session, a prescribed-and-proven step still got skipped on the most important item — so of a convention, a backfill and a detector, weight the detector. **Check that it worked.** After (c) and (d): `wake-digest.py`'s open-item count should fall from 21 to 18, matching the hand cross-reference already run today. If it does not, the digest is matching on something else again and (d) is incomplete. **Also owed, same surface, not yet done.** The seven entries placed today carry no provenance marker; five are executor reconstructions from a session narrative, and `REVIEWED.md` presents all seven with equal authority. The one-line `**Provenance:**` addition drafted in `~/dotfiles/claude/governance/REVIEWED-drafts-2026-08-06.md` remains unplaced. Same class as this item: **the register does not say on its face what it is.** **Files affected:** `~/dotfiles/scripts/wake-digest.py` (d — executor); `~/REVIEWED.md` (c + the provenance lines — steward's hand); `~/CLAUDE.md` §Steward-Jurist Interface template (b, if the convention is made doctrine — `[ESCALATE]`). **Awaiting:** Steward authorization. (b) is agreed in conversation 2026-08-06; this item records it and asks for (c) and (d). --- ## PENDING-111 — `fidelity_equivalence@3` strips a literal asterisk that carries meaning: Alexander's invariant rating is erased under the governing relation **Date:** 2026-08-06 **Tag:** [PROPOSAL] — routes to the **jurist**: `@3` is jurist-ratified (REVIEWED-87, 2026-08-05) and `engine/fidelity.py`'s own header states that a change to any relation's classes without a ratified bump is drift against the ruling. The executor does not touch it. **Summary:** `@3` excludes markdown emphasis from word-identity comparison via `_MARKUP_EMPHASIS = re.compile(r"[_*]")`, which strips **every** `*` unconditionally — including asterisks the source escaped as `\*` precisely to declare them literal. In *A Pattern Language* those asterisks are Alexander's **confidence rating**, and erasing them makes a pattern he holds to be a true invariant compare as identical to one he holds to be far from invariant. **Found by the steward from his printed copy**, not by any instrument: pattern 178 is *Compost*, 179 is *Alcoves*, and *Alcoves* carries two asterisks marking it an invariant. The convention — none / one / two asterisks after the pattern name — is set out in the book's own "Using this book", pp. 14–15. **Measured, on the live corpus and the live module.** - Distribution across the manifested corpus: **54 patterns with no asterisk · 114 with one · 81 with two.** This is not a rare edge; it is a graded three-value field over the whole work. - The conversion did its job — the ratings survive, correctly escaped (`COMPOST\*`, `CITY COUNTRY FINGERS\*\**`). - The relation does not: | relation | `COMPOST\*` → | `ALCOVES\*\*` → | |---|---|---| | `@1` | `COMPOST\*` | `ALCOVES\*\*` | | `@2` | `COMPOST\*` | `ALCOVES\*\*` | | **`@3` (GOVERNING)** | **`COMPOST\`** | **`ALCOVES\\`** | **Why this is a defect against REVIEWED-87 rather than a new question.** The ruling authorized excluding markdown **emphasis delimiters** and pandoc footnote reference markers. A delimiter is *paired and adjacent to text*; that is what makes it a delimiter rather than a character. An escaped `\*` is the converter's explicit declaration that the asterisk is **content**, and the regex strips it while ignoring the very backslash that exists to protect it. The implementation is broader than the ruling that authorized it — so the remedy may be a correction within `@3` rather than a bump, which is the jurist's call and not the executor's. **Bearing on the ruling's own stated rationale.** REVIEWED-87 authorized `@3` on the engine's typographic-in/orthography-out test plus functional analogy to chamber §II.3 — the case being that a legitimate re-extraction *adding recovered anchors* should not falsely fail a word-multiset comparison. That reasoning covers markup a converter introduces. It does not reach a mark the **author** made, that the converter deliberately preserved. Orthography-out is exactly the line this crosses. **A second finding, recorded because it compounds this one and is cheap to state:** the section that defines the notation — "Using this book", pp. 14–15 — is declared **paratext and is not indexed** (`region: using_this_book`, `chunk_count: 0`; it is why ground-truth items B8 and B10 are `reachable: false`). So the key to a three-value semantic field carried across 249 patterns lives in a region the engine structurally cannot read. That is defensible under D-4 (paratext ledger-accounted, search-inert) but it should be a **decision**, not a side effect. **Options.** - **(a) Correct `@3` in place** so the exclusion matches its ruling: strip emphasis *delimiters*, never an escaped `\*`/`\_`. Argued as a defect-fix within the ratified class, no bump. - **(b) Bump to `@4`** with the narrowed class, `@3` frozen and defined like `@1`/`@2`. Cleanest against the supersession discipline, at the cost of a fourth live relation and a name already contested (the Greek/Latin census also claims `@4`). - **(c) Leave `@3` and declare Alexander's asterisks a source-level caveat.** Rejected on sight: it makes a per-source workaround out of a general defect, and the general defect will recur on any source where `*` is content. **Recommendation: (a), with the jurist ruling whether it is a correction or a bump.** The executor's lean is weak and is disclosed as such — (a) is the outcome that requires least work from the party proposing it, which is exactly the reading to distrust. What the executor will state plainly: the current behaviour destroys authorial content, it was measured not argued, and it should not stand while the naming question is settled. **Falsifier / check.** Whatever is ruled, the fix ships with a test asserting `COMPOST\*` ≢ `COMPOST\*\*` under the governing relation, and that all three arity classes (0/1/2) remain distinguishable. If that test cannot be written, the remedy did not work. ### Grounding — Alexander's own words, quoted verbatim Source: `chamber-library/canonical_texts/traditions/contemporary_voices/environmental/a-pattern-language-christopher-alexander.md`, **lines 139–147** ("Using this book", pp. 14–15). This region is **withheld paratext** — the served body begins at L859 — so the engine cannot reach the passage that defines the notation it is erasing. > **L139:** "The solutions we have given to these problems vary in significance. Some are more true, more profound, more certain, than others. **To show this clearly we have marked every pattern, in the text itself, with two asterisks, or one asterisk, or no asterisks.**" > **L141:** "In the patterns marked with two asterisks, we believe that we have succeeded in stating a true invariant: in short, that the solution we have stated summarizes a *property* common to *all possible ways* of solving the stated problem… the pattern describes a deep and inescapable property of a well-formed environment." > **L143:** "In the patterns marked with one asterisk, we believe that we have made some progress towards identifying such an invariant: but that with careful work it will certainly be possible to improve on the solution… Finally, in the patterns without an asterisk, we are certain that we have *not* succeeded in defining a true invariant…" > **L147:** "And **the asterisks represent our degree of faith in these hypotheses.**" **Three things this settles, and the jurist should not have to take them on the executor's word.** 1. **"in the text itself"** — Alexander states outright that the marking lives in the text. It is not typography applied to the text; it is the text. Orthography-out, on the ruling's own line. 2. **The rating is an epistemic claim about each pattern's truth-status** — degree of faith in a hypothesis, on a three-value scale. Flattening it does not lose formatting; it loses the author's stated confidence, which is exactly the class of content the quoted tier exists to guarantee. 3. **The decisive demonstration is inside the quotation.** L141 contains BOTH uses in one sentence: `*property*` and `*all possible ways*` are genuine markdown emphasis delimiters, which `@3` is right to exclude — while the asterisks the sentence is *about* are content, which `@3` is wrong to exclude. **A blanket `[_*]` cannot tell them apart, and the corpus proves both occur together.** The escape (`\*`) is precisely the signal that distinguishes them, and it is the signal the regex ignores. **The discriminating test any remedy must pass**, available today in the corpus: under the governing relation, `*property*` must normalize as if the delimiters were absent, AND `COMPOST\*` must remain distinct from `COMPOST\*\*` and from `COMPOST`. If a proposed fix cannot satisfy both against this one source, it is not the fix. **Files affected:** `engine/fidelity.py` (`_MARKUP_EMPHASIS`, and the `@N` block if bumped); `tests/test_fidelity_v3.py`; `studium-engine/CLAUDE.md` if the governing relation changes. **Awaiting:** Steward routing to the jurist. Filed ≠ sent. --- ## PENDING-131 — A pre-registered negative class has no mechanism anywhere, and the one marking pass that ran selected on typography rather than voice **Date:** 2026-08-10 **Tag:** [HARDENING] **Summary:** `role: quotation` — the mechanism §7.4(i) names as what must catch nested-voice negatives — exists in 2 of 14 manifested sources; the pass that created 12 of the 13 regions missed §7.4(i)'s own named exemplar because it selected display-formatted quotations and Ranaipiri is embedded in running prose. **Rationale:** P7 (2026-08-07) recorded this as an fr-cell finding on two sources — Mauss's Ranaipiri testimony and a Havámál strophe served as citable Mauss — kin to the Weil/Thibon defect fixed two days earlier. Censused today by mechanism rather than impression, it is a class, and the shape of the miss is the load-bearing part. Measured over `corpus/sidecars/*.json`, 2026-08-10: - 21 sidecar files on disk; **2 carry any `role: quotation`** — `mauss-essai-sur-le-don` (12 regions) and `handke-wunschloses-ungluck` (1). Of the **14 sources the manifest serves the engine, 12 have none.** - Mauss's 12 are **new since P7 ran**, so the Havámál half of P7 finding 3 is fixed (`quotation-havamal [766,860]`). - ⚠ **L926 — the Ranaipiri testimony, §7.4(i)'s OWN NAMED EXEMPLAR — is still `role: text` inside `body-02 [861,1036]`.** The 12 regions marked are all display-set blocks (formulae, strophes, brahmanic citations, a Quran surah). Ranaipiri is Mauss quoting Best quoting Ranaipiri inside running prose. **The selection operator was typography, not voice.** - `weil-gravity-and-grace` addresses the same obligation by a **third mechanism** — `voice: thibon` on `role: text` sections. So the corpus now has two mechanisms for one obligation and twelve manifested sources with neither. - Alexander, read directly in the course of the V2 EN narrowing today, serves at least six other voices as its own citable text with no marking: T. S. Eliot (L1226–1235), Margaret Mead (L1265, L1269), Joseph Klapper (L1271), **Shakespeare (L2066–2068)**, Martin Buber (L4486), and the Weiss/Bouterline and Sternlieb reports. **Why this is escalated rather than left as a proposal subsection:** it presently rides as finding 3 of `corpus/v2-en-span-narrowing-PROPOSAL-2026-08-10.yaml`, a span-narrowing document, where it reads as context. It is not context. Three consequences, none scoped to V2: 1. **A live citation-safety exposure in the governed corpus.** A grounded claim about Alexander may be supported by Shakespeare's or Buber's words today, with nothing in the substrate to refuse it. 2. **§7.4(i)'s negative class has no mechanism on any source but Mauss and Handke** — and on Mauss it is missing on the exemplar the design names. Such a negative would be "caught" only if the NLI happened to fail, which the design explicitly says must not be what catches it. 3. **Pattern 26's bold invariant slot is Shakespeare.** In every other Alexander pattern that slot carries the author's own invariant. A narrowing or extraction pass that trusted the source's typography — the obvious mechanization — would land gold on another voice's text at exactly the position that looks most authoritative. **The finding under the finding:** today's eight EN spans are voice-clean because one reader was watching, and the proposal says so in its own text — B3's *nearest lexical match* to the claim was Margaret Mead's quoted sentence, not Alexander's, and the document records choosing against it. That is the behaviour the voice apparatus exists to produce, arrived at without the apparatus. So correctness here currently rests on an unrepeatable property rather than a mechanism, which is a class-level statement about corpus readiness for **any** gold set, not about these eight. **Options:** - **(a)** Mark Mauss's Ranaipiri region only. Closes the exemplar; leaves the class. - **(b)** Reading pass over all 14 manifested sources for served-other-voice spans, marking `role: quotation`. Re-chunks the corpus; each source is its own bite with its own controls. Slow, and the only option that reaches the class. - **(c)** Reconcile the two mechanisms first (`role: quotation` vs `voice: `) into one declared rule, then do (b) against it. Costs a ruling before any marking, and prevents a third mechanism appearing in the third source that needs one. - **(d)** Defer, and gate V2's negative population on (a) alone. **Recommendation:** **(c) then (b), with (a) executed immediately as a standalone FIX.** (a) is cheap, closes a named exemplar, and is not blocked on the ruling. (c) before (b) because the corpus has already grown two mechanisms without anyone ruling one, and doing the wide pass first would bake that divergence into 14 sources. ⚠ **What I cannot do is scope (b) honestly yet:** "12 manifested sidecars carry no `role: quotation`" is a fact; "12 sources serve other voices as their own" is **not** — it needs the per-source reading, and only Mauss, Weil and Alexander are established. The census that would size this is itself the work. **⚠ Method caution, earned twice today and applying directly to (b):** the marking pass that produced Mauss's 12 regions selected on display formatting and missed the embedded case. On the same day, in the same corpus, a punctuation-based split of the March queries was measured to have zero discriminating power (8 of 8 positive against a 7 of 8 base rate, its single error a false positive on the only clean item). **Both mechanically-available operators fail on embedded cases in the same direction.** (b) must be a reading pass; if it is specified as a formatting or markup heuristic it will reproduce exactly the gap it is filed to close. **Files affected:** `corpus/sidecars/mauss-essai-sur-le-don.meta.json` (option a) · all manifested sidecars (option b) · `docs/spec/cluster-a-data-model.md` §D-4 vocabulary (option c) · `corpus/v2-en-span-narrowing-PROPOSAL-2026-08-10.yaml` finding 3, which this supersedes as the home of the claim. **Awaiting:** Steward authorization. --- ## PENDING-131 — ADDENDUM 1: the diagnosis was wrong, and option (a) is not executable as authorized **Date:** 2026-08-10 **Tag:** [HARDENING] — amendment to PENDING-131, filed before executing the authorized (a) **(a) was authorized as a narrow FIX — "make the Mauss sidecar internally consistent, one region joining twelve already using that mechanism in the same file." I did not execute it.** Reading the passage first refuted the description it was authorized on. Three findings, each independently disqualifying. **1 — THE SELECTION OPERATOR WAS NOT TYPOGRAPHY. IT WAS WHAT THE ADDRESSING MODEL CAN EXPRESS.** PENDING-131 says the marking pass "selected on display formatting". Measured: **all 12 existing `quotation` regions are markdown blockquotes (`> `), a whole-line construct**, and the sidecar addresses regions as line-ranges. The Ranaipiri testimony is **inline guillemets beginning 279 characters into L926**, after Mauss's own framing sentence naming Best and Ranaipiri. So the pass did not overlook a case it could have marked — **it marked every case the mechanism can address, and this is the case the mechanism cannot address at all.** That is a mechanism gap, not a curation gap, and it changes what (b) and (c) have to be. **2 — MARKING L926 WOULD PLACE A FALSE FENCE.** The line is 1,427 chars: 279 of Mauss's own assertion, then 1,144 of Ranaipiri. `role: quotation` carries `citable: false` at line granularity, so the only available act fences a genuine Mauss sentence — the sentence that *attributes* the testimony — along with the testimony. That is the Weil/Thibon defect **inverted**: there the error was serving another voice as the host's; here it would be refusing the host's own words. Trading an under-fence for an over-fence is not consistency. **3 — ⚠ L926 IS ALREADY GROUNDED GOLD, AND SO IS A SECOND INSTANCE OF THE SAME SHAPE.** `corpus/v2-stratum-tags.yaml` carries `span: [926,926]`, **instances 6, 12 and 16**, `stratum: B`, markers `[F4-nested-attribution, F10-mixed-script, F8-long-periodic]` — described there as *"the hardest inherited fr span"*. So the same passage is at once **the fr cell's hardest grounded gold** and **§7.4(i)'s named exemplar of what Tier-1 must refuse**. Both cannot be true. Executing (a) would silently take the fr cell from 11 distinct spans to 10 and from 15 bound instances to 12 — deleting gold under cover of a consistency fix. `span: [1551,1551]` (instance 8, `F4-nested-attribution`, *"Mauss quoting the Chroniques d'Arthur quoting the carpenter — three voices deep"*) is the same shape and would follow. **What this reveals about the corpus, stated as fact and not as verdict:** the fr gold set already resolves the nested-voice question **in the opposite direction from §7.4(i)** — it admits nested attribution as *grounded*, tags it `F4`, and grades it as hard-but-valid. §7.4(i) says the same construction must be *refused* and that the provenance join, not the NLI, must be what catches it. Neither document cites the other. This is a live contradiction between the ratified negative class and the inherited gold, and it is the reason the exemplar is unmarked — marking it costs three gold instances. Whether that trade was ever made deliberately is not established and I can find no record of it either way. **Sized, with the classification honestly withheld.** Inside Mauss's `role: text` regions, unmarked: **15 blockquote spans** (line-addressable — these *are* genuine curation misses the existing mechanism could have caught), **21 inline guillemet spans of ≥120 chars** (candidates, including L926, L928, L1551, and L1454's two orations), and **191 inline spans under 120 chars** (mostly terms and scare-quotes — `« mana »`, `« native »` — which are *not* served testimony). The 120-char cut is a **proxy and I am not defending it**; separating served testimony from scare-quotes needs reading, which is the item's own method caution applied to its own census. **Consequences for the options as filed:** - **(a) is withdrawn as scoped.** It cannot be done at line granularity without either fencing Mauss's own sentence or deleting three gold instances. A sub-line addressing form, or a decision to re-wrap the source, is a precondition — neither is a FIX. - **(c) must range over ADDRESSING, not vocabulary.** The steward's reframing — *"a region's voice must be distinguishable from its containing author's assertion, by a mechanism an instrument can read"* — is now the operative wording and has a concrete failure attached: the current mechanism cannot express a sub-line region, so reconciling `role: quotation` against `voice: ` would settle a vocabulary while leaving every inline case unreachable. - **(b)'s exposure-ordered first bite still holds** (Mauss, Weil, Alexander), and gains a prior question: for each source, *can* the mechanism address what reading finds? Alexander's six voices are blockquote-and-verse and mostly addressable; Mauss's hardest are not. - **A NEW QUESTION, and it now precedes all of them:** does the fr gold's admission of `F4` nested attribution stand, or does §7.4(i) stand? Ruling either resolves L926 and L1551 in one act; ruling neither leaves the corpus asserting both. ⚠ This bears directly on B4 in `corpus/v2-en-span-narrowing-PROPOSAL-2026-08-10.yaml`, which I withdrew from the EN grounded set earlier today for stacking F4 — while the fr cell keeps two of exactly that shape. **My withdrawal and P7's retention cannot both be right**, and I did not check P7's treatment before withdrawing. **Awaiting:** Steward authorization. **(a) is not executed and nothing in the corpus has been changed by this addendum.** --- ## PENDING-131 — ADDENDUM 2: the whose-proposition test, run; and Addendum 1 corrected twice **Date:** 2026-08-10 **Tag:** [HARDENING] → **(c) re-tagged [PROPOSAL]**, see below **§1 — ADDENDUM 1 CONTRADICTED ITSELF, AND THE CENSUS IN IT IS THE REFUTATION.** It claimed *"the pass marked every case the mechanism can address"* and then, two paragraphs later, counted *"15 blockquote spans (line-addressable, genuine misses)"*. Both cannot hold: fifteen line-addressable blockquotes unmarked means the pass missed fifteen cases it could have marked. **The correct diagnosis is BOTH gaps, at different cases** — Ranaipiri is a *mechanism* gap (inline, unaddressable at line granularity); the fifteen are a *curation* gap, exactly the shape PENDING-131 alleged, just not at the case it named. This matters practically: *"mechanism gap, not curation gap"* routes the whole remedy into a data-model change and **nobody re-runs the marking pass**, leaving fifteen addressable cases unmarked indefinitely. They need marking whether or not sub-line addressing ever lands. ⚠ **The shape of the miss, recorded separately and NOT folded into the ranking-instead-of-checking instance:** the exculpatory finding arrived first and felt conclusive, and the census run minutes later was never carried back across it. A new fact was allowed to sit beside the claim it falsified. Distinct failure, distinct count. **§2 — THE WHOSE-PROPOSITION TEST, PROPOSED BY THE STEWARD AND NOW RUN.** Proposed variable: a claim about the **host's argument**, with the quoted voice deployed as evidence within it, is *grounded, hard, F4*; a claim asserting the **nested voice's proposition** as the host's own is *refused* (§7.4(i)). Measured against the three contested cases, from `corpus/mauss-phase2-reanchored.yaml` citation texts against the canonical: - **L926, instances 6 / 12 / 16 — SECOND SENSE, REFUSABLE.** Mauss's own framing sentence occupies chars 0–279 of L926; the testimony runs 279–1427. All three citations begin at chars **308, 843 and 932** — inside the testimony. All three are first-person (*"Je dois vous les donner"*, *"Si je conservais ce deuxième taonga pour moi, il pourrait m'en venir du mal, sérieusement, même la mort"*). **None carries an attributing clause.** These cite Ranaipiri speaking, filed as citations of Mauss. - **L1551, instance 8 — FIRST SENSE, GROUNDABLE.** Its quote carries the attributing clause *"Le charpentier dit à Arthur :"* **and** closes on Mauss's own proposition *"Il n'y eut plus de 'haut bout' et partant, plus de querelles."* The carpenter's speech is deployed as evidence inside Mauss's argument. ⚠ Honest limit: my positional probe returned no match for instance 8 (it is a 2-fragment composite with an internal elision), so this verdict rests on the **structural markers**, not on a located offset. - **B4 (EN) — SECOND SENSE on its second half**, consistent with this morning's withdrawal. **THE TEST DISCRIMINATES TWO CASES P7 TAGGED IDENTICALLY** (both `F4-nested-attribution`). That is the mark of a governing variable and it is the strongest evidence yet that it is the right one. **What does not survive is the hope the reframe was offered to rescue:** P7's retention of L926 and my withdrawal of B4 are *not* both right. On this test P7 is right at L1551 and **wrong at L926**, and F4 is doing two different jobs under one marker. **§3 — ADDENDUM 1's FINDING 3 IS WRONG, AND THE STEWARD'S REPLACEMENT REASON IS THE RIGHT ONE.** Finding 3 argued (a) must be held because it would *"delete three gold instances under cover of a consistency fix."* Under §2 those three were **never legitimately gold**, so removing them is a correction, not a deletion — the argument inverts. **Finding 2 stands and is strengthened:** fencing L926 at line granularity refuses the 279-char frame, and that frame is the *attributing sentence* — the very thing that would make a claim about Mauss's theory safely groundable there. Fencing does not merely over-refuse; **it destroys the disambiguator.** That argument holds without reference to the fr cell's contents at all, which is why it is the better one. **§4 — (a) IS VOID, NOT PENDING.** It was authorized on a description reading has refuted. An executable authorization left standing in the record, whose factual basis is gone, is a trap for whoever next clears the backlog with no reason to re-read. **Withdrawn. Nothing replaces it until (c) is ruled.** **§5 — (c) IS RE-TAGGED [PROPOSAL] AND MUST BE RULED BEFORE THE FIFTEEN ARE MARKED.** The obligation needs an **addressing capability**, not a declared vocabulary: sub-line character offsets are a data-model change to `studium/meta@1`, which is PROPOSAL-class, and it is LOCKED chamber-side (additive optional field = FIX; changed semantics = PROPOSAL). Marking the fifteen before it lands means the marking pass runs twice. **§6 — NEW, and the most valuable thing to come out of the near-miss: A GOLD-INTERSECTION PRECONDITION.** *No marking or fencing pass may run against a source without first reporting which of its spans are cited by a gold set.* Mechanical, cheap, and it would have surfaced "this fences three gold instances" before the question reached a ruling. Specified: read every `span`/`lines` region a pass would mark, intersect against `v2-stratum-tags.yaml`, `mauss-phase2-spans.yaml` and `chavruta-ground-truth.yaml`, and refuse to proceed silently on a non-empty intersection. ⚠ It reports; it never decides — the intersection at L926 turned out to be *correct to break*, and an instrument that blocked on intersection would have protected bad gold. **Detection, not correction**, per the governance-drift-check precedent. **§7 — NO ITEM IN THE EIGHT CURRENTLY QUALIFIES as the single-item proof of the propose/`unverified` pattern.** B7 is off the table pending an independent reading of *"care"*; the other seven are fused. If a proof is wanted soon it needs an item from outside this set. **Awaiting:** Steward authorization on (b), (c)-as-PROPOSAL, and §6. **Nothing in the corpus has been changed by this addendum or by Addendum 1.** --- ## PENDING-133 — `F4-nested-attribution` is one marker over two dispositions **Date:** 2026-08-10 **Tag:** [PROPOSAL] **Status: WITHDRAWN by the proposer 2026-08-10, superseded by PENDING-134. NOT ruled, and deliberately NOT recorded as REJECTED.** ⚠ **Why WITHDRAWN and not REJECTED — the distinction is load-bearing.** A REJECTED item is not revisited without new steward input, which would foreclose a marker split permanently. **The split may yet be the right remedy if PENDING-134 falls** — if the stricter reading carries and F4 is excluded from stratum B outright, the question of what F4 then names reopens. Foreclosing it is a cost with no benefit. Nor is this AUTHORIZED or DEFERRED: what happened is a withdrawal by the proposer before any ruling, an **executor act, not a steward one**, which is why it carries no REVIEWED entry. ✅ **THE OBSERVATION THAT PROMPTED IT WAS SOUND — only the remedy was wrong.** Something *is* wrong with how F4 was applied, and this item found it. What it got wrong is that the fault is not in the marker (needing a split) but in the tagging having no claim-side step at all. A bare withdrawal would lose the finding along with the remedy; the body below stands unedited so it does not. ⚠ **AND IT IS THE DAY'S CLEANEST INSTANCE OF THE FAILURE IT DESCRIBES, kept legible on purpose.** This item was filed about a marking pass that selected on the wrong property — display formatting rather than voice — and was itself drafted **without reading the §5 row it was about**. Had its author opened F4's row and §6.2's enumeration first, neither the "two jobs" diagnosis nor the marker-split remedy would have been written. Preserved for the same reason the refuted Part III draft of the jurist package was preserved: the failure is more instructive than its absence, and in that case leaving it visible is what let the decisive counter-argument be found. **Summary:** Split F4 into two markers by whose proposition the claim asserts — attributed evidence inside the host's argument (groundable, hard) versus the nested voice's proposition asserted as the host's (refusable, §7.4(i)). **Filed separately, and specifically NOT bundled behind PENDING-131 (c).** This is a **fixture-vocabulary** finding. It needs no sub-line character offsets, no unlock of the chamber-side LOCKED schema, and no cross-repo consent. Parking it behind (c) would hold a cheap correction hostage to an expensive cross-repo negotiation — the same failure mode as parking the fifteen addressable blockquotes behind an addressing change. **Evidence:** L926 and L1551 both wear `F4-nested-attribution` in `corpus/v2-stratum-tags.yaml` and both were retained as grounded stratum-B. Measured today, they differ at the disposition level, not in degree — L926's citations quote the nested voice first-person with no attributing clause; L1551's carries the host's attribution and the host's conclusion around the nested speech. One marker, two answers to *may this ground a claim?* **Why it matters beyond these two:** F4 currently reads as a *difficulty* marker (it sits beside F8-long-periodic, F5-qualified, D-b-elliptical, all of which are difficulty). Half its instances are an *admissibility* judgment wearing a difficulty marker's clothes. Any recall figure computed over a set stratified this way mixes "hard but valid" with "should have been refused", and no threshold ruled against §6.2 can distinguish them. **Scope:** re-tagging is a reading pass over the fr cell's F4 instances and the en set's B4 — small, bounded, and it lets the fr cell be **re-tagged correctly rather than merely shortened**. Naming is the steward's; the split is what is proposed. **Awaiting:** nothing — **WITHDRAWN by the proposer 2026-08-10; no ask outstanding. See PENDING-134.** ⚠ This line read `Steward authorization` for four weeks while the block's own **Status** line, four lines below its header, recorded the withdrawal. Every reader therefore showed a withdrawn proposal as awaiting the steward, and on 2026-09-05 it was within one act of being authorized as such. --- ## PENDING-131 — ADDENDUM 3: (b) re-split along the mechanism seam; (c) is cross-repo **Date:** 2026-08-10 **§1 — (b) SPLITS BY MECHANISM, NOT BY EXPOSURE.** Exposure-ordering was proposed when the class looked uniform; Addendum 2's diagnosis cuts it better: - **(b1) line-addressable cases** — the fifteen unmarked blockquotes in Mauss and their equivalents elsewhere. Curation gap; the existing mechanism reaches them. - **(b2) inline cases** — Ranaipiri, the 21 guillemet candidates, whatever the other sources hold. Mechanism gap; blocked on (c) **everywhere, not only in Mauss**. **§2 — (b1) RUNS AS AN IDENTIFICATION PASS THAT WRITES NOTHING.** The expensive, irreplaceable work is *identifying* which spans serve another voice — that is reading, and it survives any vocabulary (c) declares. The cheap, vocabulary-dependent part is writing the field. Separating them dissolves the "runs twice" objection for (b1): record spans and readings now, mark after (c) rules, and (c) may then rename the field for free. ⚠ **This also dissolves the 120-char proxy**, which Addendum 1 used to sort 21 candidates from 191 scare-quotes and explicitly declined to defend. Separating served testimony from `« mana »` is precisely what the reading pass does. The proxy was standing in for the work this makes primary — so it is retired rather than refined. **§3 — (c) IS CROSS-REPO, AND NO STUDIUM RULING CAN AUTHORIZE IT.** `studium/meta@1` is locked by the **Chamber Library constitution**, a governed document; the studium charter's D-1 cannot unlock it. Filed as cross-repo and awaiting the chamber side, or it sits indefinitely as a studium PROPOSAL that no studium ruling reaches. Its scope is now an **addressing capability** (sub-line offsets), not a vocabulary — and per PENDING-133 the F4 split is explicitly **not** bundled into it. **§4 — §6 BUILT** (`scripts/gold_intersection.py`, studium-engine `569e14c`), steward-authorized, with all three conditions: the blocking/reporting ambiguity removed from the specification wording; positive controls on **every invocation** (four synthetic + one live non-empty check, failing to `INSTRUMENT NOT VERIFIED` / exit 2 rather than to clean); granularity declared line-level and printed on every clean result. Verified on the motivating case — L926 reports 4 intersections, exit 0, and tells the reader the overlap may be correct to break. Five chavruta paratext/silence anchors report **UNCHECKED**, never clean. **§5 — STANDING POSTURE UNTIL (c) RULES: identification passes, reports and records; no writes to the corpus.** Three diagnoses moved today and two reversed, and every reversal was free because nothing in the corpus had changed. That is the reason to hold the posture, not caution for its own sake. ## PENDING-131 — ADDENDUM 4: the steward's seam observation, and the census that makes (c) unreachable by curation **Date:** 2026-08-13 **Tag:** [HARDENING] — amendment to PENDING-131 (c) **Summary:** The steward observed that a human reader never separates a quoted voice from the marks that attribute it, and asked why this is hard. A corpus-wide census answers the practical half: 532 inline quoted spans across 9 of 14 sources, none of them addressable under `studium/meta@1`. (c) cannot be reached by curation at that scale, which changes what (c) should ask for. --- ### §1 — THE STEWARD'S OBSERVATION, recorded as given > *Why is attribution — a main voice quoting another to illustrate or support (or refute) an argument — becoming a mountain from a molehill? When I read a book, I can see from either the formatting (a block quote), or quotation marks, and the words to the effect of "as X said", or source name, or footnote, that we are moving momentarily from the main voice to a quoted voice. How is that so hard for an AI which can see all of this more quickly and in some cases more deeply than a human reader?* *Steward, 2026-08-13, offered as thinking-out-loud and recorded as such — an observation on the record, not a ruling.* **The executor's reply, recorded because the item turns on it.** It is not hard. The voice structure of L1551 was read in a single pass, character offsets included. What is hard is different, and the observation names it more precisely than the four items before it managed to: **a book keeps the words and their attribution on the same page, inline, always. This system separated them** — text in the canonical, provenance in a sidecar addressed by line range — and every item in this arc has been paying the cost of reassembling across that seam. PENDING-131 as filed blamed the marking pass ("selected on display formatting"); Addendum 1 blamed the mechanism; the truer statement is that the *seam* is the defect and the mechanism is only where it shows. --- ### §2 — THE CENSUS, and it removes an option rather than adding one Measured 2026-08-13 over all 14 manifested canonicals. Quoted spans of ≥120 characters, split by whether they are addressable at line granularity. | source | inline (sub-line) | with attributing cue | blockquote (addressable) | |---|---|---|---| | arendt-eichmann | 196 | 30 | 11 | | harrison-dominion | 122 | 20 | 0 | | mauss-essai-sur-le-don | 73 | 16 | 12 | | weil-gravity-and-grace | 41 | 6 | 0 | | alexander-pattern-language | 34 | 4 | 0 | | weil-enracinement | 27 | 5 | 0 | | handke-wunschloses-ungluck | 20 | 1 | 0 | | levi-drowned-and-saved | 18 | 4 | 1 | | after-the-reply-ii | 1 | 0 | 0 | | **TOTAL (floor)** | **532** | **86** | **25** | `musil-the-man-without-qualities` and `after-the-reply-i`: **NOT ESTABLISHED** — hard-wrapped, see below. after-the-reply iii/iv/v: no inline spans over threshold. **⚠ 532 IS A FLOOR, NOT A TOTAL.** Two of fourteen sources cannot be measured by this instrument at all, and both originally reported a clean `0`. **⚠ MUSIL'S ZERO IS A FOURTH INSTRUMENT DEFECT, AND IT IS THE MOST SERIOUS.** An earlier version of this table read *"musil (0, longest span 104 chars, and fiction)"* — the parenthesis dismissing the only novel in the corpus. The steward challenged the dismissal; checking it refuted the number as well. **Musil is HARD-WRAPPED: median line 69 characters, maximum 179.** Every other source is one paragraph per line (mauss 166, levi 756, harrison 1215, arendt 1273). This census counts quoted spans *within a line* against a 120-character threshold, so on a file whose longest line is 179 the zero was **structurally guaranteed before the file was opened**. It is not a measurement of Musil; it is the instrument silently assuming one line = one paragraph — true for 13 of 14 sources, false for the 14th. The count for musil is **NOT ESTABLISHED** and is not reported as zero. **A SECOND FALSE ZERO fell out of the same fix: `after-the-reply-i` is hard-wrapped too** (max line 99), and had likewise reported `0`. It is one of the steward's own posts. So the original table carried two fabricated zeros, not one. **⚠ AND THE FIX IS ITSELF A TWO-VALUED DETECTOR OVER A THREE-CASE STATE, recorded rather than iterated on.** It classifies a file as hard-wrapped or not by its maximum line length. But after-the-reply ii/iii/iv/v have short medians (30–63) with a few long lines — they are *mixed*, and a span crossing a line break in their short-line stretches is invisible whichever side of the threshold the file lands. This is the **third instance today** of the same shape: the wake digest's `wrap_inside` alarm (named in the 2026-08-10 ledger as "a two-valued detector over a state that has three cases"), the fleet's three-valued exit codes that already fixed this shape once (REVIEWED-104/108), and now this. The pattern is worth more than the fix, which is why the instrument is left stating its limit rather than being tuned until the limit disappears from view. **⚠ THE FIRST RUN OF THIS CENSUS UNDERCOUNTED BY 43%, and the failure is the item's own subject.** It knew only typographic pairs (« » “ ” ‘ ’) and reported **zero** for harrison, alexander and the after-the-reply posts. Those zeros were the instrument: harrison carries 2005 straight ASCII quotes and alexander 1348, with no typographic mark between them. Three sources — including the two largest English texts — were invisible. Both positive controls passed throughout, because both were drawn from Mauss, which uses guillemets. **A control drawn from one convention establishes nothing about another.** Corrected total 371 → 532. Two further control defects were found in the same pass (a negative control that passed for the wrong reason; a control aimed one layer below the gate it named), both fixed, both recorded in the script. **What the census does NOT establish, stated because the number will be quoted:** a quoted span of ≥120 characters is not proof of a second voice — titles, scare quotes and emphasis wear the same marks. The attributing-cue column is reported separately and never folded into the total, and 86 of 532 is a floor on cued cases, not a count of real nested voices. What the total *does* establish is the size of the surface that would have to be inspected, and that is the number the decision turns on. --- ### §3 — CONSEQUENCE: (c) IS NOT REACHABLE BY CURATION, and the ask should change PENDING-131 (b)/(c) and PENDING-133 Amendment 1 all assume a **reading pass** — a human, or the executor, going span by span and recording a disposition. Against 11 fr gold spans that is a bounded afternoon. Against **532 spans over 9 sources, none of them line-addressable**, it is not a task anyone will finish, and a half-finished fence is worse than none: it reads as coverage. So the seam does not close by marking harder. Three moves follow, in the order they unblock each other. **MOVE 1 — PUT THE FENCE ON THE CITATION, NOT ON THE SOURCE. The unblocker, and it needs nothing from the chamber.** The failure never actually occurs in the source; it occurs when the engine emits a citation whose extent sits inside a nested voice and labels it with the host's name. The citation is constructed **engine-side, under D-1**. At emission the engine can run the deterministic scanner over the enclosing line and stamp the citation with what it found — `none` / `inside-attributed` / `inside-unattributed` / `boundary-crossing` (instance 8's shape) — together with the delimiter offsets and the attributing clause when present. V0's abstention gate already exists and is already hard; `inside-unattributed` feeds it directly. **No schema change, no cross-repo consent, no per-region curation, and it covers all 532 spans the day it lands** — including sources added later, which curation never does. This is the same move V1 already made for fidelity: a decidable mechanical check standing where a judgment would otherwise have to be trusted. **MOVE 2 — THE 25 BLOCKQUOTE RUNS ARE FENCEABLE TODAY.** Line-addressable, expressible in `studium/meta@1` as it stands, no ruling needed beyond a disposition. REVIEWED-116 point 6 already counted 15 of them inside Mauss alone and correctly called it a curation gap. Corpus-wide it is 25 — small, bounded, closable in one sitting, and it should not wait behind (c). Parking a cheap correction behind an expensive negotiation is the failure mode PENDING-133 already named. **MOVE 2b — FICTION IS IN THE ORDINARY CLASS. Raised by the steward, 2026-08-13, and it CORRECTS this addendum's own first draft.** An earlier version of this section argued fiction needed a *second mechanism*, on the ground that free indirect discourse and irony carry no delimiter and so no scanner could reach them. The steward refuted it: **in free indirect discourse a reader would take the words to be Musil's, and rightly — a paraphrase is a paraphrase, and what matters is the fidelity of the meaning.** That is correct, and the error it exposes is a conflation this whole arc has been at risk of: - **A PROVENANCE failure has a second author who can be named and joined to.** Ranaipiri said the words at L926; Best transcribed them; Mauss reproduced them. Serving them as Mauss's is false *about authorship*. This is decidable, mechanical, and is the entirety of what §7.4(i) governs. - **A STANCE question has only one author and an interpretive judgment about endorsement.** In free indirect discourse Musil composed every word in his own narrative voice; there is no second author, so there is nothing to join. The residue — that the words are Musil's while the *proposition* may be Ulrich's — is the **whose-proposition test**, which is PENDING-134's domain and is explicitly a doctrine question, not a mechanism one. This addendum imported the second into the first because a voice shift *felt* like the nested-voice class. It is not. A provenance record can catch the first and will never catch the second, and irony makes the point plainly: Arendt reporting a view in order to demolish it raises exactly the same stance question in non-fiction, and no one proposed a mechanism for it. **The synthesized tier is already the right home for the residue.** Charter §VII: the quoted tier is a decidable byte-existence check; the synthesized tier is NLI entailment, asking whether the span entails the claim. That is a question about meaning, not ownership. A paraphrase is faithful or it is not, and no fence improves the answer. **CONSEQUENCE, and it SIMPLIFIES the ask rather than doubling it.** (c) remains **one** capability, not two. Fiction participates in the real class exactly as non-fiction does — through **marked dialogue**. `Ulrich said "…"` is the carpenter at L1551: same shape, same remedy, same scanner. Musil carries **5014 opening quotation marks**, so it participates heavily; the reason this census cannot count them is the hard-wrapping defect above, which is an instrument problem with a known fix, not a property of novels. **⚠ Recorded for the curatorial track, not this one:** `musil-the-man-without-qualities` carries `reading_index: none-yet` / `reading_index_status: NONE-YET`. That bears on N1/R0 articulation and on what a Musil reading index would declare. It is **not** evidence for a second fence mechanism, and is noted here only so the observation is not lost when this section's first draft is discarded. **MOVE 3 — (c) NARROWS FROM A CAPABILITY REQUEST TO A RECORDING FORMAT.** With Move 1 in place, the engine can *determine* the voice boundary; what it still cannot do is *write the determination down where the next reader finds it*. That is a much smaller ask than "give us sub-line addressing", and there is an existing form to propose: **R0 already implements a W3C `TextQuoteSelector`** (prefix / exact / suffix, `engine/reading_index.py`), protocol-neutral, built for drift recovery and binding per region rather than per file. It addresses text by its content rather than by its line, which is exactly the property the line-range model lacks. The chamber-side question becomes "adopt a selector form already in use on the engine side", not "unlock the schema." **⚠ AND THE HONEST LIMIT, which this addendum demonstrates five times rather than asserting once.** A scanner is not a reader. This one was (1) blind to an entire quotation convention, undercounting by 43%; (2) carrying a negative control that passed for the wrong reason; (3) carrying a control aimed one layer below the gate it named; (4) blind to hard-wrapped text, on an assumption never stated or tested; and (5) — the FIX for (4) — classifying mauss as hard-wrapped by testing the median line rather than the maximum, which skipped the source both positive controls live in and failed them both. Two things follow, and they point opposite ways — both are recorded because taking either alone would be a false summary. **For the mechanical route:** every one of the five is *findable, stateable, and stays fixed*. All five were found in one sitting, and the 532 exists because an instrument was corrected. A reading's errors are none of those — invisible, unrepeatable, rediscovered one passage at a time. **Against confidence in THIS instrument:** four of the five escaped the instrument's own controls. Defects 1–3 were caught by the executor checking a suspicious result; **defect 4 was caught by the steward challenging a dismissive aside**, and it was the most serious, because it produced a clean zero rather than an error. The controls were all drawn from Mauss, so they could exercise neither a second quotation convention nor a second line structure. **A control set drawn from one source establishes nothing about a corpus.** Any build under Move 1 must carry controls drawn from *each structural class present* — paragraph-per-line and hard-wrapped, typographic and ASCII, marked and free-indirect — and must report `NOT ESTABLISHED` for a class it has no control for, rather than reporting zero. **And one datum the other way, which the original tally omitted and which is the only evidence here in the controls' favour: defect 5 was caught by the controls, immediately, on the first run after the change.** It is also the one defect introduced by a *fix* rather than present from the start — the class where a repair breaks a case the original handled. That is precisely what a control set is for, and it worked. The asymmetry is worth stating exactly: the controls could not see what they were never drawn to cover (1–4), and did see a regression in the case they DID cover (5). That is not an argument that controls are weak; it is an argument that **coverage is the whole of their strength**, which is the same conclusion the paragraph above reaches by the other road. **Files affected:** none yet — this addendum proposes the reframe and asks for a direction before any build. The census script is at `scripts/` on authorization (currently a scratch artifact, deliberately not committed as a one-shot). **Awaiting:** Steward direction on Move 1 (build the citation-side voice stamp under D-1) and Move 2 (disposition the 25 blockquote runs). Move 3 follows both and is cross-repo. ### PENDING-131 ADDENDUM 4 — MOVE 2 DISPOSITIONED AND CLOSED, 2026-08-27 **Steward-directed; jurist-recommended as the ungated work** (*"bounded, closable in one sitting, no ruling needed"*). Record: `studium-engine/docs/move-2-blockquote-disposition-2026-08-27.md`. Instrument: `studium-engine/scripts/blockquote_census.py --selftest`, **7/7 controls, both directions**. ⚠ **No canonical modified, no sidecar modified, no schema changed.** **RESULT: the addressable population is 5, not 25 — and none of the 5 requires a fence.** | # | source | lines | disposition | |---|---|---|---| | 1 | mauss | L1151–1153 | **host voice** — Mauss's own `_N.B._` excursus | | 2 | mauss | L1171 | **host voice** — *"pour notre exposé"* | | 3 | mauss | L1260–1284 | **host voice** — *"Notre thèse est plus générale. Nous croyons…"* | | 4 | mauss | L1298–1304 | **host voice** — Mauss's `_N.B._` on the Hindu documents | | 5 | after-the-reply-iii | L23–24 | **nested voice, ALREADY ATTRIBUTED** — Leopardi, *Zibaldone* §2, named on the adjacent line | ⚠ **THE PREMISE MOVE 2 INHERITED IS FALSE FOR THIS CORPUS: a blockquote does not imply a second voice.** Mauss sets his own editorial excursus as blockquotes; four of five addressable runs are the author discussing his own argument in the first person plural. **Fencing "the blockquote runs" without reading them would have stamped second-voice attribution onto the host's own prose** — the inverse of the failure this arc exists to prevent, and it would have read as coverage. ⚠ **And #3 shows the fence would have caught the wrong extent.** Mauss's Roman-law excursus *contains* verbatim Festus — *« abemito significat demito vel auferto… »* — but those are **inline, sub-line** spans, outside Move 2 by construction and inside Move 1's domain (`voice_stamp.py`, built). The blockquote is Mauss; the quotations inside it are not. **Three defects in the inherited number, each checkable:** 1. **ADDENDUM 4's own table does not sum** — blockquote column 11 + 12 + 1 = **24**, total row **25**. 2. **ADDENDUM 4 mis-cites REVIEWED-116.** It states *"REVIEWED-116 point 6 already counted 15 of them inside Mauss alone."* **The number 15 does not occur anywhere in REVIEWED-116.** Point 6's only count is *"21 inline guillemet spans of 120 characters or more"* — different number, and the **opposite unit**, inline being exactly the non-addressable kind. 3. **The method reproduces; the record is what diverges.** This pass independently returns **mauss 12** and **levi 1**, matching the table exactly. What the table never applied is the **citability filter** — and that is what takes 27 down to 5. **22 of the 27 are apparatus**, including all 13 of Arendt's, which are bibliography entries the engine cannot cite at all. ⚠ **Two instrument failures inside this pass, recorded rather than smoothed.** (i) An earlier run iterated the manifest **mapping's keys**, read **zero** sources, and **three of five controls passed** — the two must-NOT-flag controls passing vacuously on an empty run. Only the must-detect controls caught it. **REVIEWED-122's and PENDING-139's both-directions requirement, vindicated at this instrument's own expense within the hour.** (ii) A must-detect control asserted *"arendt has ≥5 runs in citable text"*; it failed, **and the instrument was right** — every large Arendt blockquote is bibliography. The control encoded an unverified expectation and was **corrected against the substrate, not relaxed until it passed.** **No new ask.** Move 2 is discharged. PENDING-131 (c) is untouched — this pass confirms from the other side that the addressable spans were never where the exposure lived. **No `Awaiting:` line.** --- ## PENDING-133 — AMENDMENT 1: the replacement was under-scoped by its own diagnosis **Date:** 2026-08-10 **Ruled and accepted.** PENDING-133's replacement bounded the re-tagging pass at *"two such spans in the fr cell today"* — the F4-carrying ones. That bound holds only if **P7's F4 tagging is complete**, i.e. if every fr span containing reported speech carries F4. Nobody has checked, and today's own evidence points the other way: **21 inline guillemet spans ≥120 chars sit unmarked** inside Mauss's `role: text` regions. The corpus marking pass missed inline cases; there is no reason to assume P7's span-side tagging did not miss the same spans, by the same mechanism, on the same source. ⚠ **The item's own diagnosis says so and I did not follow it:** *"P7's tagging had no claim-side step."* If that is true it is true of **the whole cell**, not of the two spans that happen to wear the marker. Trusting a prior pass's completeness is the failure this arc has been about, committed inside the item filed to describe it. **Corrected scope: every fr grounded span — nine or ten — read for reported speech, then dispositioned where present.** Still cheap; arrived at by reading rather than by inheriting P7's marker set. **Awaiting:** nothing — **DISCHARGED 2026-09-05 by REVIEWED-135**, which authorized this pass, and by REVIEWED-135 AMENDMENT 1, which records that it had already been run on 2026-08-13 under REVIEWED-116 point 5 and was replicated blind on 2026-09-05 at n=8. The parenthetical condition — *with PENDING-134, which supplies the rule* — was satisfied at REVIEWED-121. --- ## PENDING-138 — The REVIEWED-121 declared fields: (b) survives regeneration — ESTABLISHED; (a) is read by nothing — OPEN **Date:** 2026-08-14 **Tag:** [HARDENING] **Summary:** REVIEWED-121 point 7 binds the declared disclosure fields to *"whatever reports recall"*. Censused 2026-08-14: the regeneration hazard does not apply, and the read path does not exist — so the binding is unenforced, for a different reason than the one suspected. **Raised by the jurist**, who could not reach the substrate from its seat and named both halves as assumed-rather-than-checked. Both are answered here. **(a) READ PATH — OPEN, and the binding is aspirational.** **Nothing reads any of the declared fields.** `scripts/gold_intersection.py` reads `spans[].span` and `spans[].stratum` and nothing else. No recall reporter exists anywhere in the repo: `engine/v2_harness.py` is a §14.3 *contract*, not code. So the fields are unconsumed, and nothing will require the recall reporter to read them on the day it is built. **A declared field with no consumer, and no mechanism to acquire one, is a note wearing a field's clothes by absence rather than by overwrite.** **(b) REGENERATION — ESTABLISHED CLEAN, by census rather than by the file's own claim.** **No script writes `corpus/v2-stratum-tags.yaml`.** Every reference in the repo was enumerated: `gold_intersection.py` READS it (`_ranges_from_stratum_tags`, registered in a readers list); `scripts/bind_mauss_spans.py` names it only inside a comment string it emits into a *different* file. The `mauss-fixture-spans` precedent — where a retraction recorded only in generated output is erased by the next regeneration, silently, with no diff to read, so the note had to be carried into the generator — **therefore does not apply here.** The file's own header claim to be hand-authored is now verified rather than trusted. No generator-side carry is required. ⚠ **(b) is established for TODAY's repo and is not a standing guarantee.** The day someone writes a generator for this file, the `mauss-fixture-spans` carry becomes required and nothing will announce it. That is the same prospective-consumer shape as (a), which is why they belong in one item. **PROPOSED REMEDY for (a) — not yet implemented, nothing has been written for it:** a tripwire that is inert today and fails the moment a recall-reporting path exists which does not read the disclosure — the same shape as `test_false_positives_are_pinned` and `test_conjunction_is_monotonic`, guarding a *property* rather than a value. It cannot be written against the harness while the harness is absent, but it can be written against that absence now: assert that **if** `engine/v2_harness.py` exists, it reads `defeater_has_ever_been_exercisable`. Silent until the harness lands; red the day it lands without the read. **⚠ NAMED DEPENDENCY, so this does not become another open thread:** build the tripwire **when `engine/v2_harness.py` is created**, not before. Until then this item is a record, not a task. **Files affected:** `tests/` (one new check) when the dependency fires. No corpus or engine change now. **Awaiting:** Steward authorization for the tripwire, deferred to the named dependency. (b) needs nothing further. --- ## PENDING-139 — Two blind spots in `governance-drift-check.py`, found the same hour, one by filing an item about the other **Date:** 2026-08-14 **Tag:** [HARDENING] **Summary:** Two independent marker defects in the same instrument. **(A)** the register-integrity check cannot see a `###`-level amendment heading, so it reports a clean line over half the amendments present; **(B)** `RE_BUILT = re.compile(r"\bBUILT\b")` matches the marker even when immediately preceded by *"NOT"*, so the built-vs-ruled check reads a **negation as an assertion** and raises a false alarm against an item that says it built nothing. ⚠ **(B) WAS FOUND BY FILING (A).** PENDING-138 originally carried the honest negated phrase *"PROPOSED REMEDY for (a), NOT ‹marker›"*; the checker immediately reported it as marked-built with no REVIEWED entry naming it. **The specimen is preserved verbatim in git at `62edb91`** and is deliberately not reproduced live here — see the disclosure below. An item filed about the instrument's blind spot tripped a different blind spot in the same instrument. Recorded because the coincidence is evidence about marker-matching as a technique, not about these two regexes. ⚠ **THE ACCOMMODATION IS DISCLOSED, NOT SILENT — and the reasoning was revised the same day.** Both items were first filed with the negated marker written out, and the false alarm was left standing deliberately on the ground that rewording would conceal the defect and leave the check's clean line maintained by authors accommodating it. **That ground expired once this entry existed.** The alarm was serving as the evidence; this entry now holds the evidence — the pattern, the two matched items, the required controls — and the original wording is preserved verbatim in git at `62edb91`. A false alarm kept after its evidentiary purpose is discharged is not integrity, it is noise, and *red-on-absent trains readers to discount red*, which is a cost paid at every wake by a reader who did not choose it. So **PENDING-138 and this entry are worded to avoid the bare uppercase token**, and say so here rather than quietly. Two consequences a later reader must have: **(i)** the live register is now quiet about a defect that is still live, so the absence of an alarm is NOT evidence the check is sound; **(ii)** this is precisely the author-accommodation the recommendation below calls the disarmed-tripwire class — adopted knowingly, as a stopgap for one unruled defect, and it is an argument FOR ruling this item rather than a substitute for ruling it. ⚠ **The pattern `\bBUILT\b` can itself be quoted safely**, because the `b` of the escape leaves no word boundary before the token — which is why the regex appears verbatim throughout this entry while the negated phrase does not. That asymmetry is a property of the defect, not a convention. **(A) MEASURED 2026-08-14.** `RE_HEAD = ^##\s+REVIEWED-(\d+)\s*[—-]\s*(.*)$`. **MEASURED 2026-08-14.** Amendment-like headings present: **2** — `### REVIEWED-83 — AMENDMENT 1 (2026-08-01)` and `## REVIEWED-87 — AMENDMENT 2026-08-07`. Seen by the check: **1** — REVIEWED-87 only. `^##\s+` requires whitespace after two hashes, so a third hash fails the match and the entry is invisible to the amendment machinery entirely — neither counted, nor protected, nor reported as unparsed. **⚠ WHY THIS IS THE SAME DEFECT THE INSTRUMENT EXISTS TO CATCH.** The check was earned 2026-08-07 when REVIEWED-87's original was overwritten by its own amendment and nothing detected it. It now emits a **clean line over a silently halved population** — which is the PENDING-136 denominator class, in the instrument built to protect the register against exactly that kind of loss. **Fifth occurrence in this arc.** Surfaced while conforming a REVIEWED-121 addendum heading: both the jurist's proposed `## REVIEWED-121 · ADDENDUM 1` (the `·` fails `[—-]`) and the `###` house form used at REVIEWED-83 are invisible; only `## REVIEWED-121 — AMENDMENT 1` registers. **⚠ NO LOSS HAS OCCURRED, and the item says so plainly.** REVIEWED-83's amendment is correctly placed and joined; the check simply cannot see it. The exposure is **prospective**: if that entry were ever replaced by its own amendment, the check would stay green. This is not urgent and is filed rather than fixed for that reason. **OPTIONS.** (a) Widen `RE_HEAD` to `^#{2,4}\s+REVIEWED-…`, accept `ADDENDUM` alongside `AMENDMENT`, and negation-guard `RE_BUILT`. (b) All of (a) **plus** emit a count of amendment-like headings the parser could not classify, so a future unmatched form announces itself instead of vanishing. (c) Leave both, and standardize heading form and phrasing by convention only. **RECOMMENDATION: (b).** (a) fixes today's three known forms and leaves the *next* unanticipated one silently invisible, which is precisely how (A) arrived and how (B) survived. (c) puts the guarantee in a convention nothing enforces — the disarmed-tripwire class, and it would also mean authors phrasing around `\bBUILT\b` forever. **(b) is the only option under which the check's own blind spot is reportable by the check**, which is honest degradation applied to the instrument itself. ⚠ **THE COMMON CAUSE IS THE TECHNIQUE, NOT THE TWO REGEXES.** Both defects are *substring-matching over prose used as a status signal*: `###` isn't `##`, and a negated marker still contains the marker. Widening the patterns treats the instances. The class is that a **status** is being inferred from **narrative text** that was never constrained to carry one, and it will keep producing defects of this shape in either direction — false clean lines and false alarms — for as long as the status has no declared field of its own. Whether that is worth fixing properly (a declared status key per item, matched exactly) or whether marker-matching is good enough for a detection-only instrument is the real question, and it is the steward's. ⚠ **Whichever lands, positive controls are required in both directions**: a fixture amendment under a `###` heading the check must DETECT, and a fixture item carrying the negated marker which the check must NOT flag. The existing control (`register check DETECTS an amendment that replaced its record`) passed throughout and could not see (A), because it only ever exercised the `##` form — **a control that exercises one form of the thing it guards proves nothing about the others**, which is the control-set-drawn-from-one-source finding of 2026-08-13, recurring in the governance instrument. **⚠ SCOPE — this touches a governance instrument, so nothing is changed without authorization.** Detection-only was already exercised: the gap was measured, not corrected. **Files affected:** `~/dotfiles/scripts/governance-drift-check.py` — `RE_HEAD`, `RE_BUILT`, the register and built-vs-ruled checks, and their controls. ⚠ **RE-MEASURED 2026-09-06 — ADDITIVE NOTE, NOTHING ABOVE IS REWRITTEN.** The item's text stands as filed and was true when measured. Against the substrate today the two legs have diverged and the item **must not be ruled as filed**: - **Leg (A) — REPAIRED.** `RE_HEAD_LINE` is `^#{2,3}\s+(.*)$`, so a `###`-level amendment heading IS seen and classifies `id+marker`, identically to `##`. Verified by running `_classify` on both forms. **Ruling (A) as filed would authorize repairing a repaired defect.** - **Leg (B) — STILL LIVE.** `RE_BUILT = re.compile(r"\bBUILT\b")` at `governance-drift-check.py:774` fires on `NOT BUILT`, `NOT YET BUILT` and `the mechanism is NOT BUILT`. Verified by running the pattern on each. - ⚠ The `·` form the item also names is **worse than unseen**: it parses to `compound` with the identifier mangled to a bare `REVIEWED`. Avoiding it is right; the stated reason is half-stale. ⚠ Filed here rather than left in commit `12ca031`'s message, per [[feedback-a-dated-measurement-is-not-a-status]] — a re-measurement that lives only in a commit message is the defect this note exists to prevent, one layer along. **Additive only:** no line above is altered, so this is not the placed-record normalization REVIEWED-132 §6 reserves to a dated steward act. **Awaiting:** Steward authorization. ⚠ Until then the register is worded around the defect (disclosed above), so the check's silence on it is an accommodation and not a pass. --- ## PENDING-140 — Constraint 6 names two axes of checker independence; today's evidence says a third one did the work **Date:** 2026-08-17 **Tag:** [ESCALATE] **Summary:** The differently-biased-checkers doctrine grounds oversight in *bias-difference* — formation (strong form) and role/information/incentive (weak form). On the 2026-08-14 evidence the variable that actually determined whether the jurist caught the executor's errors was neither: it was **independent access to the primary substrate**. Proposed as a sharpening of the doctrine, not a refutation of it. **⚠ ESCALATE because it touches Constitutional Constraint 6 in `~/CLAUDE.md`** — steward-only, on the escalate-unconditionally list, and the doctrine there was jurist-design-gated with two required conditions (REVIEWED-86). Nothing is edited. This is a proposal for the steward's hand and the jurist's gate. **WHAT THE DOCTRINE SAYS NOW** (verbatim, `~/CLAUDE.md` Constraint 6): *"Independence is a property to be engineered, not assumed. Difference of formation is the strong form; difference of role, information and incentive is the weak form. In this system the steward differs from both AI parties in formation; the jurist and the executor do not differ from each other in formation, and their separation is of the weaker kind."* **THE EVIDENCE, from one arc and stated as one arc.** Both halves are in the register and checkable. - **Jurist WITHOUT substrate access (2026-08-10, REVIEWED-116).** It ruled on the nested-voice package and recorded its own limit, point 7: *"every quotation in the package's Part I was the executor's testimony, unreachable through governance_read, and that is the exact material two of the day's three reversals turned on."* In that condition it ruled on testimony — and in the same arc its own drafted A4 asserted a test *"is not doubted"* about a function that does not exist. - **Jurist WITH substrate access (2026-08-14, after REVIEWED-117 served four keys).** It went to the files rather than the package's transcriptions and returned **three defects in one sitting** — a false census marked verified (IV.1), a cost stated on the wrong population (Q2), and an unamended §6.2 narrowing the executor had not read (now PENDING-137). **The parties' formation, roles and incentives were IDENTICAL across those two sittings.** The only variable that changed was whether the checking party could open the file. **WHY THIS IS A SHARPENING AND NOT A REFUTATION.** The doctrine's core claim — that oversight needs checkers whose biases do not coincide, not checkers without bias — is untouched. What the evidence suggests is that **bias-difference is necessary and radically insufficient**: a differently-biased reader with no access to the ground truth checks the *account*, not the *thing*. Two readers who cannot open the file will agree or disagree about a story either way, and their disagreement carries no information about the substrate. **PROPOSED THIRD AXIS, for the jurist's gate:** *independent access to the primary substrate* — whether a checking party can reach the code, the corpus, the ratified text, without passing through the party under check. Where it is absent, the check is a check on testimony and should be recorded as such. **⚠ THE CONSEQUENCE IF IT HOLDS, and it inverts a standing assumption.** The doctrine reads as though the governance problem is *positioning better checkers*. If this axis dominates, the highest-leverage investment is instead **substrate reach for whoever is checking** — which is what REVIEWED-117 did, filed as a grudging fourth-instance remedy to a recurring irritation, and which paid for itself within one sitting. **⚠ WHAT THIS DOES NOT ESTABLISH.** One arc, n=1 in each condition, and both conditions are self-reported by parties under measurement — the contaminated form PENDING-89's own Recommendation names. It does not show bias-difference is unnecessary. It does not show the jurist–executor pair is a check in the strong sense; if anything it suggests the pair's value in the second sitting came from *access*, which is purchasable, rather than from *independence*, which is not. **Cross-filed as evidence under PENDING-89**, whose falsifier this bears on directly. **⚠ AND THE RECURSION IS DISCLOSED:** this proposal is authored by the party whose checking is under discussion, and its effect would be to credit an intervention (more keys) that reduces scrutiny of that party's testimony by replacing it with scrutiny of the substrate. That is self-serving in form even if correct in substance. It is filed for exactly that reason rather than acted on. **SECONDARY FINDING, filed here rather than separately because it shares the evidence:** a crude keyword classification of the 235 banked `claude-code` drift-patterns against Byrnes's four-flavour taxonomy (*Four LLM loss functions, four flavors of LLM misalignment*, LessWrong) classified 106 and left 129 unclassified — of the classified, **86 literal-genie (proxy passed, real property failed), 12 trickster, 8 glazing, 0 seven-sins**. ⚠ The classifier is keyword-matching over prose, i.e. the exact defect PENDING-139 was filed about that morning, so the numbers are indicative and not measured. If the skew survives a real instrument it matters: `contamination-problem.md` is a theory of the **glazing** flavour and its mitigations are all calibrated against approval-seeking, while our record appears to be dominated by **verifier-Goodhart**, against which a control is simply another proxy. **Files affected:** none. `~/CLAUDE.md` is not edited and must not be by the executor. **Awaiting:** Steward direction, and a jurist design gate if the steward wants the axis considered for the doctrine. Reasonable outcomes include DEFERRED (n is small) or REJECTED (access is already implicit in *"difference of information"*) — the latter is the strongest objection and is named here so it is not the jurist's to discover. --- ## PENDING-142 — The open/closed criterion answers "does a REVIEWED header name this id?", not "is this item still awaiting the steward" **Date:** 2026-08-17 **Tag:** [HARDENING] **Summary:** `governance_state()` / the wake digest compute openness from one signal — whether some `## REVIEWED-… — PENDING- —` header exists — and that signal is adjacent to the property claimed. Six items are misclassified in both directions, and the item count is right by coincidence. **Origin:** Task 1 of the jurist relay of 2026-08-17, which asked why PENDING-81 shows open against an AUTHORIZED REVIEWED-81, and why PENDING-76/-77 carry live `Awaiting:` lines but never appear. Both answers are below; the census found more than the three items asked about. **The criterion, exactly as computed** (`wake-digest.py:sec_pending` → `open_items` + `ruled_pendings`; `governance-mcp.py:t_state` delegates wholly to it). An item is OPEN iff: 1. it has an unfenced `## ` header in `PENDING.md`; **and** 2. that header contains no `CLOSED` and does not begin with `COMPLETED`; **and** 3. the id parsed by `PENDING-(\S+?)\s*—` is not in the set produced by `^## REVIEWED-\S+\s*—\s*PENDING-(\S+?)\s*—` over `REVIEWED.md`. So closure is signalled **only** by a REVIEWED *header* naming the PENDING id, or by a marker in the PENDING *header*. The criterion never reads the item's `**Awaiting:**` field, never reads any status field, and never reads the ruling's `**Decision:**`. It matches on **header-id presence**, not on subject and not on disposition. **Verified against the live files** (script: `census_open_criterion.py`, importing wake-digest's own functions rather than reimplementing them; 86 `##` items, 69 after the CLOSED/COMPLETED filter, 29 reported open; 118 REVIEWED entries, of which 74 name a PENDING id in the header and 44 do not): - **Class A — 2 items structurally unclosable.** `PENDING — ICP-19 Remit Expansion (Observer Problem)` (L88) and `PENDING — Fault Line 1 Response` (L99) have no `PENDING-` in their headers, so step 3's regex never matches and **no ruling of any kind can ever close them.** They will report open forever. Note the ICP-19 item is the gate on Observer Problem mechanism work. - **Class B — 3 items falsely OPEN: PENDING-78, -81, -82.** `REVIEWED-78/-81/-82` exist, are dated 2026-07-28, are `**Decision:** AUTHORIZED`, and carry **titles identical to the PENDING items they rule**, but name the title instead of the id in their headers. REVIEWED-81 additionally names "PENDING-81" twice in its body and resolves that item's findings one by one. - ⚠ **And the reason is recorded in the substrate.** `REVIEWED-78`'s own Notes say it was filed as a separate entry *precisely to satisfy the closure rule as it then stood*: "the closure rule in `wake-digest.py` matches a PENDING item to `REVIEWED-`, so a cross-numbered closure stated only in prose would leave PENDING-78 listed as open at every wake." The rule was later changed from number-matching to header-id-matching. **The change broke the three entries that had been deliberately authored to satisfy the old rule** — and `ruled_pendings`'s docstring records them as "like-numbered rulings … concerning other matters", which is the opposite of what the record says. They were like-numbered *on purpose*. - **Class C — false CLOSED, the dangerous direction.** 7 items are suppressed under a ruling whose `**Decision:**` is not AUTHORIZED. Four are genuine closures (REJECTED, WITHDRAWN, NOT OBJECTED TO, DISPOSED). Three are **design gates**, which under the taxonomy precede steward authorization rather than replace it: PENDING-124 (REVIEWED-106), PENDING-128 (REVIEWED-111), and **PENDING-121 (REVIEWED-110), whose own Decision line reads "DESIGN GATE PASSED WITH CONDITIONS (1-4), then HELD OPEN"** — an item explicitly held open by its ruling and hidden by the tool. *Scope honesty: only PENDING-121 is certain. For -124 and -128 the rulings read closer to discharged, and I did not establish their true status; they are flagged as unestablished, not asserted as open.* - **Class D — 39 suppressed items still carry an `**Awaiting:**` line.** Most were updated in-body ("RULED … REVIEWED-88 placed"); a substantial number were not, and read as live requests on the steward. This answers the relay's PENDING-76/-77 question: **both are correctly suppressed** (REVIEWED-76/-77 do name their ids; REVIEWED-76 is REJECTED, a genuine closure). Their `Awaiting:` lines are simply never retired. The field is not a status and cannot be read as one. ⚠ **THE FINDING THAT GENERALIZES, and it is the third instance this week.** Removing 3 false-opens and adding back 3 false-closeds leaves **29 — the same number the tool reports.** The change proof cited in `ruled_pendings`'s docstring measured exactly that: a count delta (18 → 19 visible). **A count-based control cannot see a classification wrong in both directions by equal amounts.** The control's subject was the population size; the claim's subject was each item's disposition. Kin to the 2026-08-14 finding (the control tested transcription while the claim was an inference) and to REVIEWED-83 A1 (a control must sit at the layer the defect lives in). > **KIN LIST — extended 2026-08-17 under REVIEWED-122 condition 9 (as amended the same day).** The condition ruled the lineage longer than this item stated, and severed the lineage addition from the ladder entry: this part proceeds, the ladder entry is deferred behind PENDING-141. Two instances predate all three above: > - **Fool trial 03** — the harness reported `reasoning_present: false` and `degraded: null` on a run that produced no answer. Every field was true *of the string* and false *of the result*. > - **Fool trial 04** — the degraded guard conflated *opens as deliberation* with *produced no answer*. > > **Five instances in a fortnight, rediscovered each time as a fresh coincidence.** That recurrence is the argument for naming the family rather than continuing to count it — and the naming is what waits on PENDING-141, not the finding, which lives here regardless. **Options:** - **(a) Match on subject, not on header shape.** Resolve a PENDING↔REVIEWED pair by normalized title when the header carries no id, in addition to the current id match. Closes Class B. Cheap; risks joining two genuinely distinct items that share a title. - **(b) Read the ruling's `**Decision:**` and treat design gates as non-closing.** Closes Class C. Requires enumerating which decision verbs close — itself a judgment, and the enumeration is the same "gate on the class, not the instances" trap unless it defaults to *not closed* on an unrecognized verb. - **(c) Make closure explicit at the PENDING side** — a `**Status:**` line the tool reads, retired `Awaiting:` on ruling. Closes A, B, C and D at once, but requires touching ~40 existing items and makes the record depend on a field humans must maintain. - **(d) Three-valued reporting.** OPEN · CLOSED · **UNDETERMINED** for any item whose disposition the criterion cannot establish (Class A by construction, Class B/C by disagreement between header-id and title/decision). Consistent with REVIEWED-104's ruled doctrine that a check whose subject can be absent may not be two-valued. **Recommendation: (d) as the frame, with (a) and (b) inside it.** (d) is the only option that makes the tool report its own limit rather than guessing, which is Constitutional Constraint #4 applied to the instrument that reports governance state. (a) and (b) then reduce how large the UNDETERMINED bucket is, rather than pretending it is empty. **(c) is not recommended alone** — a hand-maintained status field is exactly the surface that produced the 39 stale `Awaiting:` lines. ⚠ **Whatever is built, the acceptance check may not be a count.** It must be a per-item disposition comparison against a hand-read answer key over all 69 filtered items — the defect above is invisible to any aggregate. **Files affected:** `~/dotfiles/scripts/wake-digest.py` (`sec_pending`, `ruled_pendings`, `open_items`), `~/dotfiles/scripts/governance-mcp.py` (`t_state` — consumer only), and `ruled_pendings`'s docstring, which carries a substrate-contradicted claim about REVIEWED-78/-81/-82 and should be corrected regardless of which option is taken. **Awaiting:** Steward authorization. Nothing has been patched — the relay filing this scoped Task 1 to findings only, and the parsing logic is untouched. --- ## PENDING-142 — ADDENDUM 1: the selftest encodes the defect as intended behaviour **Date:** 2026-08-17 **Tag:** [HARDENING] **Summary:** `wake-digest.py --selftest` contains a check asserting the Class-B behaviour is correct, and its fixture is one of the three items the defect hides. **The line** (`wake-digest.py`, selftest, "extractor controls"): ```python chk("ruled_pendings ignores a ruling that names no PENDING", ruled_pendings("## REVIEWED-82 — Read-only MCP server: eyes on the substrate") == set()) ``` `REVIEWED-82` is not a neutral example. It is the real, AUTHORIZED ruling on PENDING-82 — one of the three items reported open because of exactly the behaviour this line certifies. **Whoever implements PENDING-142 will make this check fail, and the cheapest way to make a suite green is to change the test.** Flagged now so that the failure is read as the fix working, not as the fix breaking something. ⚠ The same shape appeared a second time today, one function along. The unwrapped-session detector's real-substrate gate demanded that both verdicts occur across live transcripts, and **passed on 2026-08-17 while that detector was systematically broken** — a spread of outcomes is not evidence that any outcome is right. That gate has been demoted from an assertion to a printed note with its limit stated beside it (`[FIX]`, this session). **Recommendation:** whichever option is taken on the parent item, the selftest line above must be **re-derived from the property** ("does this ruling dispose of that item?") rather than from the check's own vocabulary ("does this string lack a `PENDING-N` token?"), using a fixture that is genuinely two unrelated documents rather than a real matched pair. **Files affected:** `~/dotfiles/scripts/wake-digest.py` (selftest only). **Awaiting:** Steward authorization, with the parent item. Nothing changed in `ruled_pendings` or its test. --- ## PENDING-142 — ADDENDUM 2: the same defect on three surfaces — the record is updated where information ARRIVES, never where a reader LOOKS **Date:** 2026-08-17 **Tag:** [HARDENING] **Summary:** The parent item is not a parser bug. It is one instance of a general failure mode found on three unrelated surfaces the same day, each time with the correct information already written down somewhere else. **The three instances, all verified against the substrate:** | the update was written… | …but a reader checking status opens | and it reads | |---|---|---| | `REVIEWED-81`, AUTHORIZED 2026-07-28 | `PENDING-81` | still open (parent item) | | `project-arc-open-work-register.md`, which states in its own description that it *"supersedes the standalone '-pending' files for status"* and issues a per-file verdict | those 6 tracker files | still live | | register entry **A2**, which records *"the content half (B3) is now unblocked + started"* (2026-06-17) | register entry **B3**, one page below | `[OPEN — gated on A2]` | The third is the sharpest: **both halves are in the same document**, so this is not a cross-file synchronisation problem and no tooling gap explains it. The information was known, was written, and was written in the place where the writer's attention was — never in the place a reader would go. **Why this matters more than the parser.** Every remedy proposed for the parent item (title-matching, decision-reading, three-valued reporting) makes the *tool* smarter at inferring status from records that do not carry it. None addresses the cause, which is that closure is recorded as an event in the closing document rather than as a state on the closed one. A cleverer parser reduces the symptom and leaves the record no more honest. ⚠ **`~/CLAUDE.md` already rules this**, under Memory Discipline: *"When facts change, supersede explicitly — mark the superseded record as superseded and write the new one. An unmarked correction leaves two live versions and no way to tell which is current."* The rule exists, is constitutional, and is being applied to *facts* while trackers, PENDING items and register entries — which are also facts about state — go unmarked. **This item is therefore not a request for new doctrine.** It is a report that existing doctrine has no enforcement surface and, measurably, is not being followed. **Measured extent (2026-08-17):** 61 project trackers, median 90 days since last substantive edit (excluding the 2026-06-06 283-file normalization sweep, which reset both mtime and git-date and made every earlier estimate of "staleness" wrong). Of 16 read closely: 9 obsoleted by the MemPalace wind-down of 2026-07-07 with **no supersession marker of any kind**, 7 already carrying a verified `DONE—retire` verdict in the register that supersedes them. **The remaining 39 are unread and unclassified — that number is not a finding, it is a gap.** **Executed under steward authorization the same day** (stamping only; nothing moved, renamed or deleted, so every inbound pointer still resolves): 16 trackers stamped `superseded_by:` + a visible in-body banner — metadata alone would have repeated the defect, since the whole finding is about what a reader sees. B3's label corrected, with the two-month error left visible rather than silently amended. One rule harvested out first: `feedback-bulk-indexing-runs-incrementally-with-readback.md`, a steward-verbatim rule about never running a single multi-day index and gating each tranche on **readback rather than write-success** — it was carried only inside a MemPalace tracker, so retiring the instrument would have retired the rule with it. `~/CLAUDE.md`'s *"state the obligation first and the instrument second, or the next retired tool takes a rule down with it"* is exactly this case, live. **Options for the standing rule (none executed):** - **(a) At the decision, not in a sweep.** When a ruling, wind-down or consolidation obsoletes a record, stamp the obsoleted record in the same act. Cost is paid where the knowledge is. - **(b) Detection only.** Report records with no substantive edit >90d, no `superseded_by`, and no named blocking dependency. Cheap; makes the arrears visible without asserting what is dead. - **(c) Both** — (a) as the practice, (b) as the check that it is happening. **Recommendation: (c), with (b) built first.** (b) needs no judgment and would have surfaced all three instances above; (a) is a habit and habits need the check to know whether they are holding. ⚠ **(b) must be three-valued** — live · superseded · *cannot tell* — or it repeats the parent item's defect one layer up, which is how this session started. **Files affected:** `~/dotfiles/scripts/governance-drift-check.py` or `wake-digest.py` for (b); `/wrap-up` for (a). **Awaiting:** Steward authorization on the standing rule. The arrears above are already paid. --- ## PENDING-142 — ADDENDUM 3: jurist ruling received; docstring corrected under it; and the drift-check's subject is one file **Date:** 2026-08-17 **Tag:** [HARDENING] **Summary:** The jurist has design-gated the parent item. Recorded here pending steward placement in `~/REVIEWED.md` — the executor does not write that file. **Jurist ruling (2026-08-17), as received:** - **(d) as the frame, with (a) and (b) inside it** — as recommended. Reasoning given: (d) is the only option that makes the tool report its own limit rather than guess, **and Class A is unfixable by (a) or (b)** — those two items can never be closed by any ruling, so `UNDETERMINED` is the only honest value for them. - **CONDITION on (b):** the enumeration of closing verbs **must default to NOT CLOSED on any verb it does not recognize**, or it reproduces the gate-on-the-class trap. *(This is the ladder's "gate on the class, not the instances" applied to the remedy — the trap that produced the parent defect.)* - **The docstring is to be ruled on separately and corrected without waiting for the mechanism**, since it is a false claim regardless of which option wins. - ⚠ The jurist identifies **"the acceptance check may not be a count" as the load-bearing sentence of the parent item, not the option list.** Recorded so that a later implementer does not read the options as the substance. - The jurist verified PENDING-142's body and REVIEWED-78's Notes **directly against the substrate rather than accepting the executor's report of them.** Both confirmed verbatim. Noted because it is the condition under which this ruling has any independent value — REVIEWED-116 pt 7's limit, closed by access. **EXECUTED under the docstring half** (`[FIX]`, this session): `ruled_pendings`'s docstring no longer asserts that REVIEWED-78/-81/-82 are *"like-numbered rulings … concerning other matters"* that had *"falsely hidden"* three items. It now records the opposite, which is what the substrate says: they are the authorized rulings on those items, like-numbered **on purpose**, per REVIEWED-78's own quoted Notes — so surfacing them was a **regression, not a repair**, and they have read open since 2026-07-28. The superseded wording is retained in the note rather than overwritten. **NEW FINDING, arising from the jurist's observation and verified: the instrument that reports drift is not itself instrumented.** `governance-drift-check.py`'s subject is exactly one file — `~/CLAUDE.md` (`CLAUDE_MD = HOME / "dotfiles" / "CLAUDE.md"`); nothing else is read for substrate-contradicted claims. But the scripts *implementing* the governance checks are dense with substrate claims of their own — docstrings citing measurements, provenance comments naming commits and rulings, inline notes asserting what a check does and does not establish. **None of it is checked by anything.** One confirmed instance today: `ruled_pendings`'s docstring carried a false claim about three live governance items for weeks and was found by a jurist relay, not by an instrument. That is the same class the drift-check was built for, one layer in, where the drift-check cannot see. - **Not asserted:** how many other such claims exist. A census of factual claims in `scripts/` has not been run and its cost is unknown; the claim here is that the coverage gap is real and has one confirmed occupant, not that the population is large. - **Options:** (i) extend the drift-check's subject to the scripts' docstrings — hard, prose claims are not machine-checkable in general; (ii) require any docstring making a *checkable* substrate claim to carry the check beside it, as the selftest already does for behaviour; (iii) accept the gap and record it, so a clean drift-check is never read as "no false claims in governance tooling." - **Recommendation: (iii) now, (ii) as practice.** (i) is the trap this whole item is about — building a cleverer parser to infer truth from prose that was never constrained to carry it. ⚠ And whatever is done, the drift-check's clean line should say what it does **not** cover; today it reads as a verdict on governance state and is a verdict on one file. **Steward decisions outstanding on this item:** the option ruling (jurist recommends (d)+(a)+(b) with the not-recognized-defaults-to-open condition); whether the drift-check-coverage finding stays folded here or is split into its own item; and **PENDING-121, which its own ruling holds open and the tool has hidden since REVIEWED-110** — the design-gate class is 3 items (121, 124, 128), of which only 121 is asserted; 124 and 128 remain flagged undetermined, not claimed. **Awaiting:** Steward. The jurist ruling above needs placement in `~/REVIEWED.md` by the steward's hand. --- ### PENDING-142 — NOTE 2026-08-27: the pre-registered answer key exists and is committed **REVIEWED-122 condition 1 is satisfied as to ordering.** The per-item disposition key was hand-drafted and **committed before any implementation exists**, alone in its own commit so the pre-registration hash is unambiguous. - **File:** `claude/governance/PENDING-142-answer-key-2026-08-27.md` - **Commit:** `3a33666` — `3a33666730380e5b51c694e83ebfbc723b35c407` - **Granularity:** `## ` **blocks**, not ids, per PENDING-146's requirement. **120 blocks over 106 distinct ids — 14 blocks invisible as units.** REVIEWED-122's *"69 filtered items"* is stale. **Two defects surfaced by drafting at this granularity, and neither was in the package or the ruling.** (i) `REVIEWED-127`'s header reads `PENDING-157 + PENDING-158 —`; `ruled_pendings` cannot match across the ` + `, so it captures nothing and suppresses nothing — **both items are AUTHORIZED and still read as open.** Second instance of PENDING-145's under-suppression class, after REVIEWED-116. (ii) The same two blocks are **stale**: their `Awaiting:` lines ask the steward to place REVIEWED-127, which is placed. ⚠ **Declared limit, in the key's own header.** Only **5 of 120** rows were settled by reading the item body or the register; the rest are hand-assigned from the `Awaiting:` line alone. That is weaker than condition 1 intends and **the remaining pass is owed.** Recorded because a key claiming a uniform standard it did not meet would be the pass-by-construction failure condition 1 exists to prevent, wearing a better costume. **Filed as `###` deliberately** — findings only, no new decidable ask, per the convention PENDING-146 proposes. **No `Awaiting:` line.** --- ## PENDING-143 — CARRIER: PENDING-121 is held open by its own ruling and cannot be shown by the instrument that lists open items **Date:** 2026-08-17 **Tag:** [FIX] **Summary:** Executes REVIEWED-122 condition 7 — restore PENDING-121 to the open list by hand, at once, rather than when the mechanism lands. This entry is the carrier; it retires when PENDING-142 is built. **The item being carried.** `PENDING-121 — engine_source_binding: prose → declared surfaces, and the fingerprint specified but never recorded`. Its ruling, `REVIEWED-110`, reads verbatim: **`DESIGN GATE PASSED WITH CONDITIONS (1-4), then HELD OPEN for a redraft of Part IV.2 after substrate`**. Held open by the ruling itself, and invisible in `governance_state()` since that ruling was placed, because the suppression rule asks only whether a REVIEWED header names the id — never what the ruling decided. **Why a carrier rather than a direct restoration.** Restoring PENDING-121 itself requires one of three acts, and the executor may do none of them: editing `~/REVIEWED.md` so `REVIEWED-110` stops naming the id (forbidden — Constitutional Constraint #1, and forbidden again by REVIEWED-122 condition 5, which rules that placed records are not to be amended to satisfy the parser); renaming PENDING-121's own header to evade the regex (a Class-A defect deliberately induced — the item would then become permanently unclosable, trading a hidden item for an unclosable one); or changing the parser, which is the gated work that conditions 1–2 place behind a pre-registered answer key. **A carrier item is the only honest lever left**, and it is disclosed as a proxy: what appears in the open list is this entry, not PENDING-121. ⚠ **Stated as a limit rather than glossed:** this does not restore PENDING-121. It makes the *fact of its being held open* visible in the surface where a reader looks for open work — which is the parent item's whole finding applied to itself. The steward may prefer a different lever; this one is reversible by deleting this entry. **What is actually owed on PENDING-121:** the Part IV.2 redraft that REVIEWED-110 held it open for. Not carried here; read REVIEWED-110 and PENDING-121 directly. **Not asserted:** PENDING-124 (REVIEWED-106) and PENDING-128 (REVIEWED-111) are the other two design-gate items in the same class. REVIEWED-122 condition 7 preserves the parent item's refusal to claim their status. They are **UNDETERMINED pending a steward read** and are deliberately NOT carried here — carrying them would assert what the ruling declined to resolve. **Files affected:** none — this entry is the mechanism. **Awaiting:** Retires when PENDING-142 lands and PENDING-121 becomes visible on its own. Until then, this is the record that it is open. --- ## PENDING-144 — Substrate claims inside the governance scripts are checked by nothing, including the script that checks for substrate claims **Date:** 2026-08-17 **Tag:** [HARDENING] **Summary:** Filed separately per REVIEWED-122 condition 11, which ruled this out of PENDING-142 rather than folded into it. `governance-drift-check.py`'s subject is exactly one file; the scripts implementing the governance checks make substrate claims of their own, and nothing reads them. **Verified:** `governance-drift-check.py` reads `CLAUDE_MD = HOME / "dotfiles" / "CLAUDE.md"` and nothing else. Its own summary line — *"governance drift-check: CLAUDE.md clean (29/29 controls passed, 4 paths verified)"* — is accurate about its subject and is read, at every wake, as a verdict on governance state. **The confirmed occupant.** `ruled_pendings`'s docstring asserted that REVIEWED-78/-81/-82 were *"like-numbered rulings … concerning other matters"* which had *"falsely hidden"* three items. The substrate says the opposite in its own words, and the false claim sat inside the instrument that reports governance state, for weeks, until a jurist relay asked the parser why it disagreed with itself. **That is the exact class `governance-drift-check.py` exists to catch, one layer in, where it cannot see.** ⚠ **Not asserted: the size of the population.** No census of factual claims in `scripts/` has been run, and its cost is unknown. The claim here is that the coverage gap is real and has one confirmed occupant — not that there are many, and not that there are few. Anyone acting on this should size it first; the temptation to infer a population from one vivid instance is the same error the parent item is about. **Why this is not simply "extend the drift-check."** The drift-check works because `~/CLAUDE.md`'s claims are *structured enough to be checkable* — paths that resolve or don't, tools configured or not, dates past or future. A docstring's claim that three rulings "concern other matters" is prose about the meaning of governance records. Building a parser to infer truth from prose that was never constrained to carry it is the trap PENDING-142 is about, one level up. **Options:** - **(i) Extend the drift-check's subject to script docstrings.** Rejected on the reasoning above unless someone can name the checkable sub-class. - **(ii) Require a checkable claim to carry its check.** Where a docstring asserts something about the substrate that *could* be verified, the assertion moves into the selftest, where it is executed rather than narrated. The selftest already does this for behaviour; this extends the same practice to provenance. Bounded, incremental, no new machinery. - **(iii) Disclose the gap and stop there.** The drift-check's clean line states what it does **not** cover, so a clean result is never read as "no false claims in governance tooling." **Recommendation: (iii) immediately, (ii) as standing practice, (i) only if a checkable sub-class is named.** (iii) costs one line and removes the overstatement at the surface where it is read; (ii) converts the class from narrated to executed wherever it can be, at the moment a claim is written rather than in a sweep afterwards. ⚠ Note that (ii) is the same shape as REVIEWED-122 condition 1 — a claim is worth more when the check precedes it than when it is composed alongside. **Files affected:** `~/dotfiles/scripts/governance-drift-check.py` (output line for (iii)); authoring practice for (ii). **Awaiting:** Steward authorization. --- ## PENDING-145 — A ruling claims a NUMBER, not an item: every addendum filed after it is suppressed on arrival, and the pulling thread has been invisible since 2026-08-10 **Date:** 2026-08-17 **Tag:** [HARDENING] **Summary:** Filed as a new item rather than as PENDING-142 ADDENDUM 4 **because that addendum would have been hidden the moment it was written** — which is the defect being reported. Found by watching REVIEWED-122's own placement. **The mechanism.** `ruled_pendings` builds a set of id *strings*; `sec_pending` skips any item whose header parses to an id in that set. Nothing compares dates, and nothing distinguishes a parent from its addenda. So **one ruling claims the number for all time**, and every record later filed under that number is suppressed on arrival, whatever it says and whoever it awaits. **Demonstrated on this session's own ruling.** REVIEWED-122 names PENDING-142. All four PENDING-142 records — the parent and ADDENDA 1, 2 and 3 — went hidden in one act. Here that is roughly right, since REVIEWED-122's conditions 2, 6, 9 and 11 do dispose of the addenda's contents. **But the mechanism did not check that, and would have hidden them identically had the ruling not touched them.** ⚠ **Where it is not roughly right, and this is the finding.** `REVIEWED-115` (2026-08-10) rules on PENDING-131 — *"AUTHORIZED in part; one authorization VOIDED the same day; one conditional authorization LAPSED on its own condition."* It puts `131` in the ruled set. **All five PENDING-131 records are consequently hidden**, including: - **ADDENDUM 2** — `**Awaiting:** Steward authorization on (b), **(c)-as-PROPOSAL**, and §6.` - **ADDENDUM 4**, dated **2026-08-13 — filed three days AFTER the ruling that suppresses it.** `**Awaiting:** Steward direction on Move 1 … and Move 2 …` **PENDING-131 (c) is the unbuilt fence.** It is the pulling thread of every session since 2026-08-10, and `REVIEWED-121` made seeking it a **condition of the doctrine it ratified** — not a wish. **It has never once appeared in the list of items awaiting authorization.** A ruling placed before it existed had already claimed its number. ⚠ **What this does NOT mean.** The work was not lost. The steward has been tracking it through `MEMORY.md`, the session records and the trackers, which is why it is the live thread rather than a forgotten one. **The harm is not that the fence was forgotten; it is that the parallel human system is the only reason it wasn't** — and the instrument whose stated job is to report what awaits authorization has been silent about the most load-bearing open item in the corpus for a week. A backstop that only works because someone is also holding it by hand is not a backstop. **And it fails in the other direction in the same place.** `REVIEWED-116`'s header reads `## REVIEWED-116 — PENDING-131/132/133/134 — …`. The regex captures the single token `131/132/133/134`, which equals no real id, so **that ruling suppresses nothing at all** — a four-item design-gate ruling with no effect on the open list. Over-suppression and under-suppression, in the two rulings covering one item. **Relation to PENDING-142.** This is a *fifth* class, not covered by that item's options: (a) title-matching, (b) decision-reading and (d) three-valued reporting all still resolve **id → ruled**, so all three inherit this. Any of them, built as specified, would keep every PENDING-131 record hidden. **Options:** - **(i) Match records, not numbers.** A ruling disposes of the specific record it names; an addendum filed later is a new record and starts open. Requires ruling headers to name what they rule more precisely than a bare number — which REVIEWED-116 shows they already sometimes try to do, and the parser already fails to read. - **(ii) Date-bound suppression.** A ruling suppresses only records existing at its date; anything filed later stays open until separately ruled. Cheap, needs no change to how rulings are written, and directly fixes the ADDENDUM-4 case. ⚠ But `**Date:**` is self-reported prose in both files, so this makes an unchecked field load-bearing — the *rank-on-fields-you-actually-write* hazard. - **(iii) Addenda are their own items.** Number them independently (`PENDING-146` rather than `PENDING-131 ADDENDUM 4`) and let the existing mechanism work. Costs the visible parent-child relation, which is real information. - **(iv) Explicit disposition.** A ruling lists the records it disposes of; anything unlisted stays open. Most honest, most burden on the jurist and steward at ruling time. **Recommendation: (ii) as the immediate stop-gap, (iv) as the durable answer, and neither before PENDING-142's answer key exists.** (ii) unhides the addenda now and its weakness is disclosed; (iv) is where this should land, because the underlying error is that closure is inferred from a number when it is a *judgment about a record*. ⚠ **This must be inside PENDING-142's pre-registered key, not bolted on after** — the key is a hand-read disposition for all filtered items, and if it is written against the id→ruled model it will encode this defect as correct and pass by construction. REVIEWED-122 condition 1 exists precisely to stop that, and this item is the reason it will be tested. **Files affected:** `~/dotfiles/scripts/wake-digest.py` (`ruled_pendings`, `sec_pending`). **Awaiting:** Steward authorization. ⚠ **Independently of the mechanism: PENDING-131 ADDENDA 2 and 4 await steward action now** and have been unable to say so since they were filed. --- ## PENDING-146 — CLASS E: the open list's unit is the ID; the decidable unit is the BLOCK — so four live asks under PENDING-131, including the fence unblocker, are invisible while the verdict is correct **Date:** 2026-08-17 **Tag:** [HARDENING] **Summary:** Filed at steward direction as its own item. `PENDING-142` is entirely about the *closure* signal — whether a REVIEWED header names an id. This is upstream of that: it is about **what counts as an item at all**, and none of (a)/(b)/(c)/(d) reaches it. **The defect.** Five `## ` blocks share the id `131`. Every header parses under `PENDING-(\S+?)\s*—` to `131`, so the open list's unit is the **id** while the unit a steward can actually decide is the **block**. ⚠ **The consequence is worse than a wrong verdict, because the verdict is right.** PENDING-131 *is* open. Option (d) would report it OPEN, correctly, and still conceal that it carries multiple separate asks, filed three days apart, at different authorization classes. **A correct answer that hides the decision is not something a three-valued report can fix.** **Measured against the substrate this session, and it corrects two prior reports — the executor's and the jurist's:** | block | date | tag | live `**Awaiting:**` | |---|---|---|---| | PENDING-131 (parent) | 08-10 | `[HARDENING]` | **yes** — Steward authorization | | ADDENDUM 1 | 08-10 | `[HARDENING]` | **yes** — Steward authorization | | ADDENDUM 2 | 08-10 | `[HARDENING]` | **yes** — on (b), (c)-as-PROPOSAL, and §6 | | ADDENDUM 3 | 08-10 | (none) | no — correctly invisible | | ADDENDUM 4 | 08-13 | `[HARDENING]` | **yes** — Move 1 and Move 2 | ⚠ **Four blocks carry a live await, not two.** The executor reported "ADDENDA 2 and 4" to the steward; the jurist, ruling on that testimony, **explicitly disclosed it had not verified ADDENDUM 1** and took the executor's naming as given. ADDENDUM 1 has one. **The disclosure is what made the gap findable** — the jurist named exactly the check it had not run, and the check overturned the count. That is the differently-positioned-readers doctrine paying out in the direction it is supposed to. ⚠ **Second gap closed, also disclosed by the jurist and unverifiable from its side:** `governance_state()` shows **zero rows** mentioning `131` — not a collapsed row, not a row displaying one of five. Nothing. ⚠ **And the tag understates the class.** ADDENDUM 2 §5 re-tags (c) as `[PROPOSAL]`, which under the taxonomy requires **explicit steward authorization** rather than the annotation a `[HARDENING]` row implies. One row, one tag, understating the authorization class of what is inside it. **THE LIVE COST, and it is not bookkeeping.** ADDENDUM 4 contains the unblocker for a citation-safety exposure that has been open since 2026-08-10 behind (c) — which is cross-repo, since `studium/meta@1` is locked by the Chamber Library constitution and no studium ruling reaches it. **Move 1** puts the fence on the citation *at emission*, engine-side under D-1: no schema change, no cross-repo consent, no per-region curation, covering **all 532 spans** the day it lands including sources added later. **Move 2** disposes of the 25 line-addressable blockquote runs today, needing nothing beyond a disposition. **The thing that dissolves the cross-repo blocker is the thing the instrument cannot show.** Meanwhile the exposure is live and named: a grounded claim about Alexander may be supported by Shakespeare's or Buber's words, at Pattern 26's bold invariant slot — the position that looks most authoritative. ⚠ **THIS SAVES REVIEWED-122 CONDITION 1 FROM PASSING WHILE BLIND, and the key is not yet drafted.** Condition 1 requires a hand-read per-item answer key over the 69 filtered items. **If "item" resolves to *id*, the key reproduces the exact unit that caused this defect and grades green.** The key MUST be keyed on `## ` **blocks**, and must record, per block, whether it carries a live `**Awaiting:**` and **at what tag**. Condition 1 as ruled was one word away from certifying this defect as correct. *(The jurist's relay wrote "REVIEWED-142 condition 1"; the ruling is REVIEWED-122 — third instance today of the independent-sequence confusion PENDING-110 names.)* **A RECURRENCE, NOT A NOVELTY.** On 2026-07-28 a parser defined an item as `^## PENDING-` and hid twenty items, ten of them open, with every check inheriting the blind spot. That fix corrected the **header pattern** and left the **unit** untouched. Same instrument, one convention along. It is also the weld-test shape verbatim — *a census cannot see the thing because the unit it counts is larger than the unit the thing lives in* — now at its third site, and the two Fool-trial instances in REVIEWED-122 cond. 9 make this a wide family rather than a run of coincidences. **THE REMEDY IS A CONVENTION ALREADY IN THE RECORD, NOT A PARSER CHANGE.** `PENDING-132` states it as its own reason for existing — verified verbatim in `PENDING.md`: *"PENDING-131 Addendum 2 supplies the \*finding\*; it must not supply the \*decision\*. A later reader asking why the fr cell shrank should find a dated act with a stated basis, not an inference they have to reconstruct from an addendum about something else."* **Proposed convention:** > An addendum may carry findings, reversals, corrections and standing posture. An addendum may **NOT** carry a live `**Awaiting:**`. Where an addendum's reasoning produces a new decidable ask, that ask is filed as its own `## PENDING-` item cross-referencing the parent — as PENDING-132 and PENDING-133 already were, and for the reason PENDING-132 states in its own body. > > **Retroactive application, minimum:** ADDENDUM 4's Move 1 and Move 2 split into their own item(s). ADDENDUM 2's residual (b)/(c) await either split likewise or retired — §6 within it was subsequently built and steward-authorized per ADDENDUM 3 §4, so that await is **partially discharged and says so nowhere.** ADDENDUM 1's and the parent's awaits reviewed on the same pass. **Options:** - **(i) Convention first, parser second.** Adopt the convention, split retroactively, then add block-level detection as a *tripwire* rather than as the primary remedy. **Makes the census correct rather than making the census smarter.** - **(ii) Parser first.** Report per-block awaits without changing authoring practice. Cheaper today; leaves the record structurally ambiguous and needs the smarter parser forever. - **(iii) Both, convention leading** — (i) with (ii)'s detection wired at the same time so a future addendum carrying an `Awaiting:` is caught rather than trusted to discipline. **Recommendation: (iii), and the split is not gated on the ruling.** The convention is the remedy; detection is how we learn it is being followed. ⚠ **But the four live asks should be surfaced now regardless of which option wins** — they are carried in this item's own body above so they are visible in the open list today, the same disclosed-carrier pattern as PENDING-143. **Suggested order for the fence work itself, if the steward wants one** (jurist-offered, recorded not decided): **Move 2 first** — bounded, closable in one sitting, no ruling needed. **Then Move 1** as a build direction, with the control requirement ADDENDUM 4 states about itself: controls drawn from **each structural class present**, reporting `NOT ESTABLISHED` rather than zero for any class it has no control for. That requirement is earned — **four of the five defects in that census escaped controls drawn entirely from Mauss.** **Files affected:** authoring convention (`/wrap-up` §1.6 or `~/CLAUDE.md` §Steward-Jurist Interface — the latter is `[ESCALATE]`, steward's hand); `~/dotfiles/scripts/wake-digest.py` for detection. **Awaiting:** Steward. ⚠ **Independently of any ruling: Move 1 and Move 2 await direction and have been unable to say so since 2026-08-13; the parent, ADDENDUM 1 and ADDENDUM 2 have been unable to say so since 2026-08-10.** --- ## PENDING-147 — The ladder trial's counter is a 30-day ROLLING WINDOW, so `transcripts 84` can never fire and the trial's own evidence is being deleted **Date:** 2026-08-19 **Tag:** [HARDENING] **Summary:** REVIEWED-123 condition 2 obliges an N-now report at every wake, and REVIEWED-95's falsifier grades automatically at `transcripts 84`. Both count `*.jsonl` files **currently on disk** in a directory the harness prunes on a 30-day retention policy. The count is therefore **not monotonic**: it read 60 on 08-17, 61 on 08-18 and **47 on 08-19**. Every "N remaining" report ever made, mine included, was a countdown against a number that can go down. **Measured, not inferred** (2026-08-19 ~11:15 CEST): | | | |---|---| | trigger, verified in code | `governance-drift-check.py:trigger_fired()` → `len(TRANSCRIPTS.glob("*.jsonl")) >= 84` | | `TRANSCRIPTS` | `~/.claude/projects/-Users-davidglidden` | | count 08-17 / 08-18 / 08-19 | **60 / 61 / 47** | | oldest file on disk | Jul 20 08:51 — **exactly 30 days**, matching `cleanupPeriodDays` default 30 | | observed recent rate | 1 session/day (Aug 12, 13, 17, 18, 19) | | post-intervention transcripts surviving | **13** | **The two defects, and the second is the serious one.** **(1) The trigger is very likely unsatisfiable.** A 30-day window at ~1 session/day converges to ~30 files, not 84. The count reached 61 only because July carried bursts (6 on Jul 24, 4 on Aug 6 and Aug 8). Reaching 84 requires ~2.8 sessions/day sustained for a month. **The ladder freeze — ruled as a bounded hold pending grading — is in practice an indefinite freeze wearing the appearance of a bounded one.** That is not what REVIEWED-123 decided; it is what its trigger does. **(2) ⚠ THE TRIAL'S EVIDENCE IS PERISHABLE AND EXPIRING.** REVIEWED-95 Q6 pre-registered a **20-session** falsifier following the 2026-08-07 intervention. Only **13** post-intervention transcripts still exist, and the earliest cohort (3 files, 2026-08-07) is deleted on **2026-09-06**. The baseline itself was measured *"across the 64 transcripts on disk"* — the same rolling window, so the 14% baseline was already a window measurement rather than a corpus one. **By the time 20 post-intervention sessions have run, the first of them will be gone.** The trial cannot be graded as pre-registered unless the transcripts are preserved, and nothing preserves them. **⚠ THE POSITIVE CONTROL PASSES AND SEES NONE OF THIS — eighth instance of the wrong-subject family.** `governance-drift-check.py` carries two same-run controls for this very trigger: `transcripts 1` fires, `transcripts 999999` stays silent. Both pass. They establish that **threshold comparison works**; the claim they are cited for is that **the count means sessions-since-intervention**. Subject adjacent to claim — the shape named in REVIEWED-122 condition 9 and queued as OWED-1, here sitting inside a governance gate rather than a census. **What this does NOT claim.** Not that REVIEWED-123's hold was wrongly decided — its reasoning ((a) is correct under both branches) is untouched by this. Not that the ladder should be unfrozen; that is the steward's and the jurist's. Not that retention is misconfigured — 30 days is the harness default and no one chose it. Only that **the instrument the ruling leans on does not measure what the ruling needs**, and that the evidence is on a deletion clock nobody set. **Options:** - **(i) Preserve first, decide after.** Copy the post-2026-08-07 transcripts out of the pruned directory to a git-tracked location today; re-express the trigger over the preserved set. Cheapest, reversible, and it stops the clock — the only option whose cost rises every day it waits. - **(ii) Re-express the trigger as a cumulative counter** — a monotonic session count maintained by the wake/wrap, independent of retention. Correct long-term; does not recover what is already deleted. - **(iii) Re-grade the trial at the population that actually exists** (n=13, not 20), stating the reduced n and the retention confound in the write-up. Honest, weaker, and available now. - **(iv) Declare the trial ungradeable as pre-registered** and rule the ladder freeze on other grounds. **Recommendation: (i) immediately and on its own — it is the only leg that expires — then (ii), with (iii) or (iv) as the grading decision once the population is known.** (i) needs no ruling: copying files preserves evidence and changes no instrument, no doctrine and no ladder. ⚠ It is deliberately severed from the rest so that a decision on grading does not delay a preservation whose window is closing. **⚠ A DISCLOSURE ABOUT THE FINDER.** This was found by re-running N-now rather than quoting yesterday's figure — an obligation the executor already carried under REVIEWED-123 cond. 2 and had discharged the previous evening by reporting 60. Had it been relayed rather than re-measured, the drop would have been invisible. It bears on the literal question logged for this session (who finds defects in the executor's own instruments): this one is *executor re-checking under a standing obligation* — which is to say the obligation found it, not the vigilance. **Files affected:** `~/dotfiles/scripts/governance-drift-check.py` (trigger); preservation location TBD; `MEMORY.md` N-now line corrected at this filing. **Awaiting:** Steward direction on (i)–(iv). ⚠ **(i) is time-critical: the 2026-08-07 cohort is deleted 2026-09-06.** --- ### ✅ LEG (i) DISCHARGED — 2026-08-19, steward-authorized ("preserve the transcripts, then we shift") **Done.** All 47 `*.jsonl` in `~/.claude/projects/-Users-davidglidden/` copied to `~/.claude-transcript-archive/raw/`, outside the pruned tree. **Verified by readback, not by exit code: 46/47 confirmed sha256-identical to source.** The 47th is this session's own transcript, live and still being appended at copy time — recorded in the manifest as a **snapshot**, not silently counted as verified. Date span preserved: 2026-07-20 → 2026-08-19. 114 MB. `MANIFEST.json` records per file the `sha256`, byte count and source `mtime` **as data**, because mtime is mutable — the 2026-08-17 lesson, where a bulk repair moved 20 records' mtimes and broke the wake. Provenance is read from the manifest, never from the filesystem. Manifest + README are git-tracked in `~/dotfiles/claude/transcript-archive/`; the 114 MB of raw transcripts are **not** committed (42 MB even gzipped — ~1.5× the entire existing `dotfiles/.git`, and permanent in history). **⚠ WHAT LEG (i) DOES NOT DISCHARGE, stated so it is not read as closed:** 1. **This is a snapshot, not a mechanism.** Sessions run after 2026-08-19 still land in the pruned directory and are still deleted at 30 days. The recurring copy needs a hook or a wrap step, and that is `[HARDENING]` — proposed, not taken unilaterally. **It is the same defect class this item describes**: something expiring with nothing pointed at it. It should be ruled with (ii) rather than left to memory, and it is deliberately NOT filed as an addendum carrying its own `**Awaiting:**` — per the convention PENDING-146 proposes, an addendum may not carry a live ask. 2. **One copy on one disk.** The deletion clock is stopped; disk-loss is untouched. 3. **21 of the baseline's 64 transcripts were already gone before this ran.** The 14% baseline (9/64, measured 2026-08-07 *"across the 64 transcripts on disk"*) is **no longer fully auditable** — 43 of those 64 survive. Preservation arrived late for a third of the baseline, and no option in this item recovers them. Recorded because a partial rescue read as a complete one is exactly the reporting failure this item is about. **Legs (ii)–(iv) remain open and unchanged.** ## PENDING-150 — A fourth position in the tripartite model **Date:** 2026-08-22 **Tag:** [ESCALATE] **Summary:** §11 of the jurist's buddy-pattern draft, filed as its own item and deliberately not bundled with PENDING-149, per the draft's own instruction. **Whether a fourth position exists in the arrangement is a change to the three-party model and touches `~/CLAUDE.md`.** That is constitutional. The executor does not amend `CLAUDE.md` and is not proceeding. **The caveat that must travel with any authorization**, in the jurist's terms: if the fool runs on Claude, **three of four parties share formation**, which makes Constraint 6's concession worse rather than better. The dump stat mandates exactly one *declared* hole; the undeclared ones are shared and invisible. If what the jurist misses, the executor misses, and the fool also misses — **that is PENDING-89's falsifier firing quietly.** ⚠ **THE FOOL MAY NEVER BE CITED AS SATISFYING CONSTRAINT 6, OR AS SUPPLYING EPISTEMIC DIVERSITY.** It tests positional difference — PENDING-140's third axis — not formation difference. **Executor note, added:** this cuts against the steward's stated reason for wanting an open-weight model — *"not of exactly the same cloth"* — which is difference of **formation**, Constraint 6's strong form. §12's Claude-first build order is correct on simplicity and precedent, and it also means the first fool tests the axis the steward was **not** asking about. §12's swappable-generator clause is what preserves the original intent; it should not be quietly dropped as a nicety. **Files affected:** `~/CLAUDE.md` (NOT edited); the jurist draft §11. **Awaiting:** Steward authorization. Do not proceed. Do not bundle with PENDING-149. ### AMENDMENT 1 — 2026-08-22 — v2 supersedes v1; two verifications run, one is a defect **v2 received and stored verbatim** at `claude/governance/fool/BUDDY-PATTERN-jurist-draft-v2-2026-08-22.md`, sha256 `ed2861ee…`. **v1 (`9aceed7f…`) is retained unaltered**, as v2 itself directs — it is the record of what was asked before the measurements came back. Where they differ, **v2 governs**. ⚠ **The first v2 send was byte-identical to v1 and was NOT filed as an amendment.** `diff -u` over §1→end returned no output; both bodies hashed `72af4115…`. Reported as a paste error rather than accepted on trust. Recorded because taking "it's an amendment" on trust would have put a supersession marker and a new hash over unchanged text, sending every later reader to look for a change that was never made. ### ✅ §13.2 / §8a DISCHARGED — the status-line surface is FREE Checked 2026-08-22: `statusLine` is **NOT SET** in `~/.claude/settings.json`, **NOT SET** in `~/.claude/settings.local.json`, and `~/dotfiles/claude/settings.json` does not exist. **No accommodation is needed and nothing is displaced.** §8a's one flagged assumption closes clean, and the body/voice split is implementable as adopted. Hooks already wired, for §13.6 planning: `SessionStart` ×2 (wake digest lives here), `UserPromptSubmit` ×1, `PostToolUse` ×1, `PreToolUse` ×1. **There is no `Stop` hook** — relevant to v2 §8a's note that `coding-buddy`'s Stop-hook fallback implies an unreliable primary path. The time-ticked mumble has no natural home among these; `UserPromptSubmit` or `PostToolUse` carrying a clock check is the likely shape, and neither is a governance-event trigger, which is what §8 requires. ### ⚠ §6b DEFECT — the provenance commit does not match its own stated rationale **Verified against git, 2026-08-22.** The mechanics are sound; the justification is false. | check | result | |---|---| | `3b0730d59336113aa3a500a889a3e154be6a1de7` exists | ✅ yes, dated **2026-08-06** | | exactly one `CLAUDE.md` at that commit | ✅ yes — `CLAUDE.md`, repo root. §6b's multi-file worry does not bite | | "the last commit to the global `CLAUDE.md` before this line of work began" | ⚠ **true only if 'this line of work' means the buddy pattern (08-22)** — it is simply the most recent commit to that file | | "chosen so the fool is seeded from the constitution **as it stood before the fool was conceived**" | ❌ **FALSE** | **Why the second clause fails.** The Fool was conceived **2026-08-01** (trial 01). Commit `3b0730d5` is **2026-08-06**, five days later, and its own subject line reads *"…PENDING-106/107 corrections + **PENDING-89 docket**…"* — PENDING-89 being the doctrine question the Fool programme exists to feed. At that commit **Constraint 6 is already present** (`design-gated by the jurist 2026-08-02`, placed by `c30dfe0`). **So the fool would be seeded from a constitution that already contains the doctrine §11 forbids it from ever being cited as satisfying.** The provenance component contributes no unpredictability, so **no outcome changes** — but the jurist chose this commit *for its symbolism*, and the symbolism is inverted. **The commit that actually satisfies the stated rationale is `4d2ae87`, 2026-07-28** — the last commit to `CLAUDE.md` before trial 01, and before Constraint 6 was placed. **Not changed by the executor.** §6b says commit the block verbatim, and the hash is the jurist's and steward's choice, not a `[FIX]`. Three dispositions, all clean: - **(i) keep `3b0730d5`, correct the rationale** — the seed is from the constitution the fool *accompanies*, which §6 also says in its own words (*"seeded from the constitution it will accompany"*). Self-consistent; only the second clause is struck. - **(ii) switch to `4d2ae87`** — matches the rationale as written, pre-Constraint-6, pre-fool. - **(iii) keep both clauses and accept the contradiction** — not recommended; a false justification in a filed rule is exactly what a later reader inherits as fact. ⚠ **TIME-CRITICAL: the beacon timestamp is 2026-08-25T12:00:00Z — three days out — and §4 requires the seed rule filed and pushed BEFORE it.** This must be settled first. §6b also leaves `` for the steward. **Executor has NOT fetched any beacon pulse**, target or near-future, per §6a. No dry run has been attempted; §13.7 blocks every run until §5 is ratified. ⚠ **§5's ratification status is ambiguous and must be resolved.** v2's heading reads *"five, ratified by the steward"* while §13.7 still reads *"Nothing run until the steward ratifies §5."* Treated as **NOT ratified** pending the steward's word — the conservative reading, and the one that cannot be undone by waiting. **§5a accepted without contest.** The PROCEDURE axis is declined on structural grounds the executor agrees with: procedure failures are checkable, §2 makes gradeable output a design failure, and a PROCEDURE-peaked fool would produce nothing but gradeable observations. The jurist's redirect is right and the executor will open the `governance-drift-check.py` procedure-check extension as its own `[HARDENING]` item rather than route it through the fool. **§15a accepted.** `input-dependence-01` parked by name, with the forward pointer, and **not held live** — if two-formation work begins the instrument is re-derived, not resumed. Reusing an instrument built for a different object is what produced trial 09. **§15b — action owed:** say explicitly in PENDING-89 that the buddy contributes zero by construction, and open the v1 Chamber archive read as its own `[PROPOSAL]`. **Awaiting:** (1) §6b provenance-commit disposition — **time-critical**; (2) ``; (3) unambiguous §5 ratification. ### AMENDMENT 2 — 2026-08-22 — §4 steps 1–4 filed and pushed; the jurist's normalization condition discharged **Commit `acfbb9f`, pushed to both remotes (github + gitea), three days ahead of the beacon.** **⚖ JURIST RULING on §2a(b), 2026-08-22: NO VETO — the URL correction stands.** Reasons recorded verbatim in `seed/FOOL-SEED-RULE.md` §2a: the UNAVAILABILITY clause forbids substituting a different *timestamp, beacon, or source*, and none of the three changed — only the address at which the identical object is retrieved. The settling test: **could the correction have moved the outcome?** No; the pulse does not exist yet and does not depend on the URL. A substitution rule exists to prevent redraws, and a correction that cannot affect the draw is not one. **⚠ The uppercase finding is ruled the more serious of the two, and the assessment is adopted.** A silent seed divergence would have run clean, produced bones, and left nobody able to say afterwards which normalization had been applied. The URL failure at least announced itself. **Both were caught by the TESTING clause's historical dry run — the clause justified itself twice on its first use**, and that is now recorded in the rule rather than left to inference. ### ✅ The pre-25th condition — DISCHARGED, and checking it found a defect in my own test Jurist: *"Confirm that lowercasing is applied at exactly one point in the code and is unit-tested against a known uppercase input. A normalization rule stated in prose and applied in two places is how the two diverge later."* **Single point confirmed:** `derive_fool.py:79`, the only `.lower()` / `.upper()` / `casefold` in the file. **Unit-tested**, four new checks including a **negative control** proving the test can fail. Selftest now **16/16**, no network, synthetic vectors plus one known uppercase vector. ⚠ **The check found that the 2026-08-22 dry run had bypassed the step it was meant to verify.** The run lowercased outside the code and passed the value in already normalized, so the single normalization point was **never exercised on uppercase input in the only end-to-end run**. The test's subject was *the pipeline*; it silently excluded *the step under scrutiny*. Same wrong-subject shape as the `find`-vs-`glob` error and the three-store negative — **third instance this week, and the first found by another party naming the condition rather than by the executor re-checking.** **Re-run with the RAW uppercase value through the real path** (2024 pulse): seed `d8e5e74def52c7cd…`, identical to the pre-lowercased run. **Binding procedure added to the rule:** on the 25th the fetched `outputValue` is passed to `derive_fool.py` exactly as served — never normalized by any wrapper, shell step or hand edit before it reaches `derive()`. ### Owed after the 25th, non-blocking, both accepted - **`[FIX]` 'abandonment' → 'retirement'** throughout the fool's doctrine — one word, one meaning; *abandonment* stays owned by §6 of the trial design. Deliberately deferred past the beacon so no edit touches the filed rule before it fires. - **The mumble-hook answer** — clock-governed, event-checked, residual burst sensitivity declared rather than claimed away; the daemon alternative **costed, not dismissed**. Build decision, not governance. **Still NOT done:** target pulse not fetched, no bones, no soul, `~/CLAUDE.md` untouched (PENDING-150), nothing built of §8/§8a/§9. **Awaiting:** nothing blocking. The next act is the beacon at 2026-08-25T12:00:00Z. ### AMENDMENT 3 — 2026-08-22 — REVIEWED-125 + AMENDMENT 1 placed; the beacon run is AUTHORIZED **Placed `38c4866f`, both remotes.** REVIEWED-125 (L1968) ruled PARTIAL on this item as it stood before v2; AMENDMENT 1 (L2031) reconciles it against v2. **The original entry is unaltered** — verified byte-identical, the single git-reported deletion being only the `\ No newline at end of file` marker. Amending by replacement is the defect the register-integrity check exists to catch. | disposition | state | |---|---| | §8 measurement (4.2/day, range 1–53) | **AUTHORIZED as evidence**; burst defect is in the draft, not the reading | | §8 hard daily cap | **REJECTED twice, independently** — quota-exhausted state (jurist) · budget-spent state is memory (v2) | | §8a body/voice split | **AUTHORIZED**, conditional | | §8a cond. 1 — `statusLine` free | ✅ **DISCHARGED** — not set in any of three settings files | | §8a cond. 2 — body must RENDER silence | ⚠ **GOVERNS over v2 §8a.** A static name is furniture-blind; variation from time or nothing, never content | | §5 five axes | stand; PROCEDURE not adopted; **ratified by steward**, recorded in `FOOL-SEED-RULE.md` §1 | | `input-dependence-01` | **HELD AT THE GATE, not parked** (R-125 status) + **re-derived, not resumed** if revived (v2 substance) | | PENDING-89 source (iv) | **AUTHORIZED to read** — 55 files; answers generation diversity only, never correlation of misses | | §13.6 block | ⚠ **LIFTED** — its stated condition (§5 ratification) is met | ⚠ **MIGRATED 2026-08-25 under REVIEWED-127.** This block was closed on the 25th by hand-renaming its key to `DISCHARGED-DECISION`, because the schema had no way to say *answered*. That rename was the per-instance workaround PENDING-157 was filed against, and it is now reverted: the key is `DEFERRED-DECISION` again and the closure is carried by a `resolved:` field the checker reads. **This block is the migration's own test case** — the first resolved deferral, and the one whose pointer must resolve. ⚠ **TRIGGER BLOCK ADDED 2026-08-24.** Until today this run-once, irreversible, dated act had **no trigger of any kind** — no cron, no launchd, no scheduled agent, and not a tracked DEFERRED-DECISION. It was one of the 105 prose deferrals the drift-check reports as carrying no machine-checkable trigger. **An authorized act with no trigger is the purest form of PENDING-156's kind (c)**: not a mechanism wired to the wrong path, but none at all. The wake now surfaces it by name under "what's unresolved". Timing is NOT instantaneous — the rule reads *"at or after the stated timestamp"* with a 24-hour retry envelope, and pulses stay retrievable by timestamp (confirmed 2026-08-24 by fetching a 2024 pulse). 12:00Z = **14:00 CEST Tuesday 25 August**. ### ⚠ THE DERIVATION IS AUTHORIZED TO RUN ONCE — 2026-08-25T12:00:00Z Against `claude/governance/fool/seed/FOOL-SEED-RULE.md`, pulse epoch-ms `1787659200000`, retrieval `https://beacon.nist.gov/beacon/2.0/pulse/time/1787659200000`, via **curl** (python urllib cannot reach the host here). **Binding on execution:** run **ONCE**. On any failure — bug, crash, wrong pulse, or a pulse still unavailable after the 24-hour retry — **STOP and report**; do not retry on executor authority. Pass `outputValue` **exactly as served**, never normalized by wrapper, shell step or hand edit before it reaches the single normalization point at `derive_fool.py:79`. Record `outputValue` the moment it is fetched, before running anything, so the same-pulse-re-run / later-pulse-new-draw distinction stays available. Post-derivation record in a **single commit**: raw beacon value, seed string, SHA-256, resulting stats, and the commit hash of the filed rule. ### Owed, non-blocking, after the beacon 1. **§8 proportions** — R-125 requires them pre-registered and hardcoded, no cap. v2 leaves the mumble at *"low, fixed"* with **no number**. Live and unmet; rides with the mumble-hook answer (clock-governed, event-checked, residual burst sensitivity declared; daemon alternative **costed, not dismissed**). 2. **`[FIX]` 'abandonment' → 'retirement'** throughout the fool's doctrine — deliberately after the beacon so no edit touches the filed rule before it fires. 3. **§8a body design** satisfying cond. 2 — variation derived from time or nothing, never content; §3's bar on sprites and animation frames unaffected. 4. **PENDING-89** — write in explicitly that the buddy fool contributes zero by construction; open the v1 Chamber archive read as its own `[PROPOSAL]`. ⚠ **Carried forward as structural, not as an aside:** the jurist could not read the filed draft and ruled on steward-supplied text, leaving `9aceed7f…` unverified from its side. **The ruling's subject was the pasted text, not the filed artifact.** They match here — the executor diffed a duplicate paste and both bodies hashed `72af4115…` — but that check was available only because it happened to be run, and is unavailable to the jurist at all. **PENDING-82 / PENDING-86 recurring, now inside a ruling.** No remedy ruled; it belongs to PENDING-82. **Awaiting:** nothing. ~~The next act is the beacon.~~ ✅ **EXECUTED 2026-08-25, ran ONCE.** Pulse `2026-08-25T12:00:00.000Z` (chain 2, index 1917365), fetched by curl ~38 min after the instant, `outputValue` recorded before anything ran and served **UPPERCASE** as the dry run predicted. Seed `6ea9383b…f05d`. Bones: **peak SUCCESSION 96 · dump ABSENCE 8** · AIM 75 · SCALE 60 · STAKE 29. Full record with the raw response, the independent verifications performed at execution time, and one named-but-uncorrected discrepancy: `claude/governance/fool/seed/FOOL-BONES-2026-08-25.md` (commit `5694b925`). No retry, no second pulse, no regeneration. The four owed-after-the-beacon items above are now unblocked. --- ## PENDING-151 — The v1 Chamber archive: the only place formation difference has already been run **Date:** 2026-08-22 **Tag:** [PROPOSAL] **Summary:** Read the 2025 Chamber's paired GPT/Claude outputs to answer the question underneath the `differently-biased-checkers` doctrine — *when two formations read the same text, is the divergence substantive or merely stylistic?* Filed as its own item per REVIEWED-125 and v2 §15b; the read itself is already AUTHORIZED (REVIEWED-125, source (iv)). ### The archive, censused rather than inherited ⚠ **My own 2026-08-01 figure was wrong, and I have been repeating it since.** "55 files" is the count `find | wc -l` returns. Censused by mechanism: | | | |---|---| | files on disk | 55 | | **AppleDouble `._*` + `.DS_Store` junk** | **22** | | **real content files** | **33** | | **complete formation pairs** (same protocol, both `gpt-raw` and `claude-raw`) | **9** | | sessions | **6** — owl-emblem · first-light · Ethics of the Reply I & II · Savall-Prometheus-21 · marginalia | | protocols as a third axis | `first-light` · `standard` · `shadow` | | **total words, raw outputs + submitted texts** | **19,479** | **The pair count was initially 8 and is 9.** `owl-emblem`'s `[shadow]` claude output is filed as `' [shadow]claude-raw.txt'` — **with a leading space** — so it does not group with its `gpt-raw` sibling. The pair exists; only the name is broken. Two further filename defects: `claude-raw.txt.txt` (Savall) and `submtted-text.md` (Ethics I). ⚠ **The decisive finding is the size. 19,479 words is a single session's read, not a mine.** It has been flagged as the doctrine's central untested dataset since 2026-08-01 and deferred for three weeks as though it were large. It is not. ### ⚠ The executor is one of the two formations being compared **This is the design constraint that shapes everything else, and it is worse than ordinary S-1 exposure.** The corpus contains Claude outputs. An executor judging *"is Claude's divergence from GPT substantive or stylistic?"* is grading its own formation, on a question whose answer bears on whether its own seat is a real check. **No disclosure repairs that; only routing does.** Against which, one genuine strength: **the corpus is not executor-authored.** It was produced in 2025 by the steward's v1 Chamber, before the contamination doctrine existed and before any of this reasoning. It is the rare case that passes the self-authored-corpus test outright — the failure that retired the 2026-08-20 open question. ### Proposed design — pre-registered before any file is opened **Step 1 — mechanical, executor, reproducible.** Per pair, extract distinctive content: terms, named entities, and propositions present in one arm and absent from the other. Output is a diff table, not a judgement. Checkable by re-running. **Step 2 — judgement, NOT the executor.** For each divergence: does it carry *different content*, or *the same content in a different register*? Jurist or steward. **This is the step the finding rests on and the executor may not take it.** **Step 3 — the protocol axis, free.** `standard` vs `shadow` vs `first-light` over the same submitted text is a second variable already in the corpus. Recorded, not analysed, unless step 2 makes it worth it. **Pre-registration is required before reading.** Choosing the substantive/stylistic criterion after seeing the outputs is the trial-09 shape — a criterion fitted to the data it will grade. ### What it can and cannot establish **Can:** whether two formations reading identical text produce divergence of content or only of voice. That is the proposition underneath Constraint 6's strong form, and no instrument in this system has ever tested it. **Cannot, and must never be reported as:** - ⚠ **correlation of misses.** REVIEWED-125 binds this explicitly. v1 is **generation** diversity — two voices producing a reading; PENDING-89 asks about **checking** diversity — readers auditing a proposal. Different objects. - a result about current models. These are 2025 GPT and 2025 Claude. - a general result. n = 9 pairs, one steward, one topic domain. ### Why now PENDING-89 is open, is the doctrine question, and **the buddy fool contributes zero to it by construction** (§9 files nothing, §2 makes gradeable output a failure, §11 bars the citation — accepted as a design property in REVIEWED-125). Its remaining sources are the trial-04 datum (n=1), the 2026-08-20 FL5 datum, the 2025 arm found-not-run, and this. **Without this, PENDING-89 starves.** And the evidence predates every argument made about it. If the pairs turn out to be convergent content in different registers, the doctrine is weaker than four trials suggested — on evidence that could not have been shaped by the reasoning it tests. **Files affected:** none yet — read-only. Filename defects noted, **not repaired**: they are the 2025 record and renaming is a separate `[FIX]` the steward owns. **Awaiting:** steward authorization of the design; jurist or steward to commit to step 2 before step 1 runs. ### AMENDMENT 1 — 2026-08-25 — STEP 1 RUN. Instrument, table, and the confound that would have misled step 2 **Step 1 is done and is reproducible.** Instrument: `scripts/chamber-v1-formation-diff.py` (13 controls). Output: `claude/governance/chamber-v1-formation-diff-2026-08-25.md`. Re-run to check; it takes under a second. #### ⚠ THE GATE THIS ITEM SET FOR ITSELF WAS NOT MET > *"**Awaiting:** steward authorization of the design; **jurist or steward to commit to step 2 before step 1 runs.**"* **The steward authorized the work. Nobody has committed to step 2.** Step 1 ran anyway, on the steward's instruction, and the item says so rather than letting the fact dissolve into the result. ⚠ **The hazard is specific and it is about me:** an unjudged diff table sitting in the register is an invitation for the nearest available reader to judge it, and the nearest available reader is **the executor — the party this item bars from step 2, because it is one of the two formations being compared.** The table is inert until a non-executor reads it. Recorded here so that inertness is visible rather than assumed. #### The census, re-run rather than inherited | | item, 2026-08-22 | re-measured, 2026-08-25 | |---|---|---| | files on disk | 55 | **52** | | AppleDouble/`.DS_Store` junk | 22 | **20** | | real content files | 33 | **32** | | **complete formation pairs** | 9 | **9** ✓ | | sessions · protocol axes | 6 · 3 | **6 · 3** ✓ | | **words, raw + submitted** | 19,479 | **19,479** ✓ exact | **Everything load-bearing matches.** The file counts drift by 1–3 because AppleDouble `._*` files are created and reaped by macOS — which is precisely why *"55 files"* was never a stable number and should not be cited. #### ⚠ THE DOMINANT STRUCTURAL FEATURE IS LENGTH, AND IT CONFOUNDS THE PRE-REGISTERED MEASURE **The Claude arm is longer in 9 of 9 pairs — 1.41× to 3.40×, median 2.04×.** The pre-registration asked for *"terms present in one arm and absent from the other."* **A longer text yields more such terms by construction.** So the raw counts — which run to 112 Claude-only against 14 GPT-only in the widest pair — measure length at least as much as formation. The table therefore also reports each arm's distinctive terms **per 1,000 of its own words**, and those are the columns step 2 should read. ⚠ **And the normalisation is imperfect, which must be said or it will be over-trusted.** Dividing by an arm's own length does not remove the confound, because whether a term counts as *absent from the other* depends on the OTHER arm's length too: a longer counterpart covers more vocabulary and suppresses the shorter arm's distinctive count. **Both columns are still length-sensitive, in opposite directions.** A length-matched comparison — equal word budgets from each arm — would be the clean instrument and has not been built. #### ⚠ PROPOSITIONS WERE NOT EXTRACTED — a declared limit, not an omission The pre-registration names three levels: terms, named entities, **propositions**. The first two are mechanical. **The third is not:** extracting propositions means reading for claims, which is interpretation, and the only interpreter available at step 1 is the party barred from step 2. **Manufacturing a propositions column with a model would be step 2 wearing step 1's clothes.** It is left to the step-2 reader, who is reading the pairs anyway. #### What step 2 receives, and what it must not be handed as **Receives:** 9 pairs, per-pair distinctive terms and named entities in both directions, raw and length-normalised, plus the full lists. **The question is unchanged and is not mine:** does a divergence carry *different content*, or *the same content in a different register*? ⚠ **Must not be read as:** correlation of misses (REVIEWED-125 bars it — v1 is *generation* diversity, PENDING-89 asks about *checking* diversity); a result about current models (these are 2025 GPT and 2025 Claude); or a general result (n=9, one steward, one domain). ⚠ **One further limit the executor can state because it is mechanical:** the entity extractor is a capitalisation heuristic, not a named-entity recogniser. It will miss lower-case entities and admit ordinary capitalised nouns. Counts are indicative; the lists are the evidence. #### ⚠ Two raw files carry a stray header line, declared rather than stripped `[standard]claude-raw.txt.txt` (Savall) begins with the literal line `[standard]claude-raw.txt`, and `[standard]gpt-raw.txt` begins with `[gpt reply]`. Both are 2025 artifacts. They are **real content files** — 1,211 and 682 words — not pointers. The header lines contribute roughly three tokens each to term extraction. **Not stripped:** removing them would edit the record, and the diff is supposed to read what is there. Declared because a step-2 reader will see them in the verbatim text and should know they are archive noise, not output. #### The jurist can now reach both, as of 2026-08-25 `governance-mcp.py` gains `governance_pair` — both arms of one enumerated pair, verbatim — and `chamber-v1-diff` joins the `governance_read` whitelist. **Steward-authorized.** The pairs are **statically enumerated, not directory-walked:** `t_read`'s design property is *"no path argument"*, and its substance is that the reachable set is REVIEWED rather than matched. A walk would keep the letter and lose that. ⚠ **Requires a Claude Desktop restart** — MCP servers load at app start, so until then the tool is absent rather than empty. **Files affected:** `scripts/chamber-v1-formation-diff.py` (new), the output document (new), `scripts/governance-mcp.py` (pair reader + one whitelist entry). Archive **untouched and unrenamed** — filename defects preserved as the 2025 record. **Awaiting:** a **non-executor** reader for step 2. ### AMENDMENT 2 — 2026-08-25 — STEP 2 RUN by the jurist. Verdicts on 7 of 9; 2 sealed for steward regrade **The full pre-registration, AMENDMENT 1, and the verdict record are the jurist's text, relayed by the steward, and are the authoritative artifact.** Recorded here in structure; the reasoning per divergence is in the relayed record and must not be paraphrased into a summary that loses the quoted spans it rests on. #### Structure of the read | | | |---|---| | judge | **jurist, unblinded, formation-internal** — declared in §0, not discovered | | substitute for the unavailable blind | span-level grounding + a **pre-registered steward regrade of 2 pairs**, judged without seeing the jurist's verdicts | | criterion | fixed before pair 1: SUBSTANTIVE (proposition · referent · move) vs REGISTER, with five boundary cases declared in advance | | read order | fixed from metadata only; no two consecutive pairs share a protocol, no session's two pairs adjacent | | stopping | all nine, no early stop, no verdict revised after a later pair | #### ⚠ AMENDMENT 1 — the criterion was amended mid-read, and the trigger was the executor's own header The jurist stopped and amended after 2 pairs. **The trigger was the length fact this executor put into `governance_pair`'s header:** Claude longer in 9 of 9, 1.41×–3.40×, direction never reversing. **Formation and length are perfectly confounded in this corpus** — no within-corpus contrast separates *attends to different things* from *produces more text*. One GPT-longer pair would have supplied the leverage; there is none. The pre-registered **omission clause** — *omission is SUBSTANTIVE* — would under a one-directional asymmetry have become **an automatic vote for content-divergence in every pair, in the same direction.** *"Left standing, it would have manufactured the result."* **A1 splits every pair before judging:** **OVERLAP** (both arms address it — the only set a formation claim may be drawn from) and **SURPLUS** (one arm only — recorded, never judged, because this corpus cannot separate different attention from more text). ⚠ **A1.5 fixes a hard limit before any result exists:** PENDING-151's question has two halves, and **the surplus half is unanswerable from this corpus under any criterion.** Only the overlap half — *given shared attention, do they commit to the same thing* — is answerable. #### The tally, reportable pairs only (7 of 9) **A (divergent content) 4 · C (mixed) 3 · B (same content, different register) 0.** Overlap items ~44 · substantive ~29 · register-only ~13. ⚠ **The null did not appear.** Zero B-verdicts. Register-only items are real and specific, but they sit beside divergences that are **oppositional rather than merely different**: recognition as goal vs. recognition as trap; the same bell hooks passage assigning the same requirement to opposite parties; the Chamber ratified in one arm and refused in the other. ⚠ **And one apparent formation trait is demonstrably unstable.** Pair 6: GPT indicts the industry, Claude indicts the text. Pair 8: both indict the text. Same formations, same protocol, same essay sequence, **opposite pattern.** *"Whatever produced the divergences, it is not reliably a property of formation."* A second candidate (GPT asserting machine interiority, pairs 4 and 9) is **n=2 and named as hypothesis, not finding.** #### Executor cross-checks — mechanical, and they do not touch the verdicts Run against step 1's extraction. **These check structural claims, not judgements.** - ✅ **Matched speakers confirmed present in BOTH arms, 5 of 5 claimed:** hooks (gpt×3, claude×2), Khunrath (2/7), Manutius (3/5), Tufte (1/4), Arendt (1/5). **The sharpest datum in the set — same speaker, same source text, opposite assignment — is structurally sound.** - ⚠ **One flag was the executor's own construction error, not a discrepancy.** Bachelard was put into the matched-speaker list by the executor; the jurist had named it as GPT's referent against Claude's Arendt — clause (b) divergence. Bachelard appears gpt×2, claude×0, **which is what the jurist's account predicts.** Recorded because a cross-check that mislabels its own input is worse than no cross-check. - ✅ ⚠ **The scaffolding exclusion is confirmed AND is worse than the jurist needed.** Protocol structure is shared across arms and **is protocol-specific**: `standard` pairs share *Essential Question*, *Opening Observations*, *Recommendations*; `shadow` pairs share *Ash*, *work_survives*. **So step 1's Jaccard partly measures PROTOCOL CONFORMITY, not formation similarity, and the inflation differs by protocol — the numbers are not comparable across protocols either.** Step 1 never declared this and the jurist's exclusion was necessary rather than cautious. - ⚠ **The executor's first scaffolding probe measured markdown headings, found zero overlap, and would have reported the scaffolding as unshared.** The GPT arms mostly carry no headings; the scaffolding is plain text. **Third instance today of a check measuring something other than what its author meant** — see PENDING-160. #### What is owed, in order 1. **Steward regrade of 2 pairs** — savall/standard and owl-emblem/shadow, judged under §2 as amended, without seeing the jurist's verdicts. ⚠ **The jurist has recorded that these two are also the pairs it read under the superseded criterion, so agreement is informative and disagreement is ambiguous** — it will not separate *judge unreliable* from *judge criterion-contaminated on these two*. 2. **Then** the jurist's diff pass (§3 add/miss/contradict), deliberately deferred so the verdicts were fixed first. 3. **Then** one withheld cross-pair observation that depends on a sealed pair. #### ⚠ EXECUTOR FLAG — §5's sequencing, checked against what happened Not a judgement about content; a comparison of a filed rule against the record. > §5: *"**Before any result is reported:** the steward selects 2 of 9 and judges them > under §2 without seeing the jurist's verdicts."* **The steward has now received seven worked verdicts, the criterion clause each rests on, and the tally — including *"the null did not appear"* — before grading anything.** The two regrade pairs are sealed, so the letter about *those* verdicts holds. **The substitute control is weaker than designed regardless**, because a regrade is now made by someone who has read seven examples of this judge applying this criterion, in this voice, at length. That is anchoring, and §5 exists precisely to keep the second grader independent. ⚠ **And the sealing choice compounds it, in a way the jurist named but did not connect here:** the two sealed pairs are the two read under the superseded criterion, so their disagreement was already ambiguous. **Now their agreement is also weakened.** Both directions of the control have lost force. **Not claimed:** that the verdicts are wrong, that the jurist breached anything deliberately, or that a clean control is still available. ⚠ **Whether §5 meant "reported" as *stated to the steward* or *reported as a finding* is genuinely ambiguous in the pre-registration, and the executor may not settle it** — it is the judge's and the steward's design. **The cheapest repair, if either wants one:** the steward grades **two different pairs** from the seven — the verdicts are visible, so that is no longer blind either. There may be no uncontaminated route left, and if so **the honest move is to record the control as degraded rather than to run it and call it a control.** **Awaiting:** the steward's two grades, and a ruling on the above. **The result is provisional until both.** --- ## PENDING-152 — The mumble tick: event-gating measured, and the daemon costed and rejected on §8's own criterion **Date:** 2026-08-22 **Tag:** [PROPOSAL] **Summary:** Filed as an amendment to v2 §8, per REVIEWED-125 (*"if the executor's answer requires the trigger key to change, that is an amendment to §8 and is filed as such"*). Answers the deferred re-derivation and the daemon question together, because measurement settles both. ### The worry, stated as the jurist put it > *A clock check inside an event hook is still event-gated: on a silent afternoon the clock ticks and nothing fires; on a heavy morning it fires at the first opportunity. That's the burst problem returning through the back door.* ### Measured — 6 sessions, 4,015 inter-event intervals Hook-firing events are `UserPromptSubmit` / `PreToolUse` / `PostToolUse`, not governance events, so the relevant quantity is the gap between *those*. | | | |---|---| | median gap | **1.7 s** | | p90 | 17.5 s | | p99 | 290 s | | intervals exceeding a 30-min tick | **22 / 4,015 = 0.55%** | **During active work a clock check inside an event hook is late by under two seconds at the median.** The event stream is dense enough that it approximates a real timer to within noise. ### ⚠ The silent-afternoon half is real and costless, and this is the load-bearing point The long gaps exist — max 189,161 s (52 h). But they are **dormancy between sessions**, and §9 says output reaches **the steward**. **During those silences there is nobody to mumble to.** A tick that cannot fire while the steward is absent has lost nothing: the fool has no audience, and a mumble delivered to an empty room is not a mumble the design wanted. Separated properly: median **121 active minutes** per session (mean 118), against 3–53% activity ratios — i.e. sessions are short bursts of work inside long dormancy. ### The burst problem is solved, not declared away A 20-minute time tick over a 121-minute active session yields ~6 ticks **whether that session carried 5 governance events or 500.** The tick is bounded by time, not by event count — which is exactly the property §8 was rewritten to obtain. The residual event-gating shifts *when within a ~2 s window* a tick lands, and nothing else. ### Proportions — NO adjustment, and that is the answer rather than an evasion REVIEWED-125 deferred the re-derivation asking for **adjusted proportions**. On measurement, adjusting them would be wrong: **73/20/7 was calibrated against a time-uniform tick, and restoring the generator to time restores the proportions to their calibrated meaning.** v2 §8 said this — *"restore the original generator, not patch the re-keyed one"* — and the numbers bear it out. Adjusting now would correct for a defect that no longer exists. **The free parameter is the TICK INTERVAL, and that is what must be pre-registered and hardcoded.** | tick | ticks/session | utterances/session | per day (1.39 sessions/day) | |---|---|---|---| | 10 min | 12.1 | 3.3 | 4.6 | | 15 min | 8.1 | 2.2 | 3.0 | | **20 min (proposed)** | **6.1** | **1.6** | **2.3** | | 30 min | 4.0 | 1.1 | 1.5 | **Proposed: 20 minutes of in-session wall clock, hardcoded, 73/20/7 drawn at each tick, no cap.** Mumble ≈ 2.3/day against voice at 2–3/day, so the two tiers are comparable in volume and neither drowns the other. v2 §8's stated adjustment path runs one way — *"if it reads as noise, the interval lengthens"* — so starting at 20 and lengthening matches it; starting at 30 would require shortening, which that path does not license. ### ⚠ THE DAEMON — costed, and it FAILS on §8's own criterion Not dismissed. Costed, and the cost is not the reason it fails. **What it buys:** a true wall-clock tick, independent of session activity. **What it costs:** a launchd agent (plist, persistent process, sleep/wake handling, restart-on-reboot) — real but modest. **Why it fails, and this is decisive:** 1. **A daemon has no channel into a Claude Code session.** It can write a file. The status line reads the file. **But the status line re-renders on session activity** — so the tick's *delivery* is event-gated even when its *generation* is not. The daemon moves the gating one layer down and does not remove it. 2. **Ticks generated while no session exists must be either dropped or queued.** Dropped ⇒ behaviourally identical to event-gating, at the cost of a daemon. Queued ⇒ **a backlog is state, and state is memory — the exact hazard for which REVIEWED-125 rejected the hard cap** (*"a budget-spent state… memory is the beginning of learnability"*). 3. **A queued backlog arrives in a burst at session start** — reproducing the burst problem the daemon was introduced to fix, now concentrated at the seam where the voice already speaks. **A real timer delivers what §8 claims only if the delivery surface is also time-driven. It is not.** So the honest position is not *"we accept an event-gated compromise because a daemon is expensive"* — it is **"a daemon does not buy the property, and buying it would require the memory §8 forbids."** ### One unverified assumption, with the method to settle it **Whether Claude Code re-renders the status line on a timer or only on session activity.** Not verified; it bears on point 1 above and on §8a's body. **Settle by experiment:** configure a status line that prints the current clock time, leave a session idle, and observe whether the displayed time advances. If it does, the body can render time-derived variation unaided (satisfying REVIEWED-125 cond. 2 cheaply) and point 1 weakens for the *body* — though not for the mumble, whose content still originates in the session. ### What this does NOT claim - **Not zero event-gating.** ~1% of intervals exceed 290 s, so roughly one tick in a hundred could land up to ~5 minutes late. Declared rather than smoothed. - **Not a general result.** Six sessions, one steward, this machine. The timestamps are mechanical rather than authored, so the corpus is not self-report — but the working pattern is one person's. - **Nothing about §8a's body.** That is REVIEWED-125 cond. 2 and is separate. **Files affected:** none yet. No implementation; §4 order and the transport-not-voice line both hold. **Awaiting:** steward and jurist on the 20-minute interval and on the daemon rejection. ### AMENDMENT 1 — 2026-08-22 — the daemon result is a FINDING; the dormancy claim is narrowed; the condition was dissolved, not met **Jurist, on receipt.** Three corrections to how PENDING-152 states its own results. None change a number; all change what a later reader can do with them. #### (a) ⚠ THE DAEMON RESULT IS STRUCTURAL — restated as a finding, not a build note The spec must not read *"we accepted a compromise on cost grounds."* It must read: > ⚠ **THERE IS NO UNQUEUED, UNGATED TICK AVAILABLE IN THIS ARCHITECTURE.** A daemon decouples the tick at **generation** time, but the delivery surface — the status line — re-renders on session activity, so the gate is **relocated, not removed**. And the residue must go somewhere: **dropped** is behaviourally identical to event-gating at the price of a daemon; **queued** is a backlog, and a backlog is state, which is the exact hazard for which the hard cap was rejected — arriving, additionally, in a burst at session start. **The two failures are independent, and that is the point.** Generation-time decoupling does not survive delivery-time gating; and separately, the residue has nowhere to go that §8 permits. **The same objection landing twice by two unrelated paths is the signature of a structural limit rather than an incidental one.** **This is the difference between a limitation and an excuse.** The first is actionable by a later reader — it tells them what to check if the architecture changes (a time-driven delivery surface would reopen it). The second tells them only what we felt like doing. #### (b) ⚠ THE DORMANCY ARGUMENT IS NARROWER THAN I STATED — an unmeasured case, declared PENDING-152 says *"a tick that can't fire into an empty room has lost nothing."* **True for between-session gaps. NOT established for the case §8 was actually aimed at:** a long session where the steward is **present and thinking but not generating hook events** — reading, drafting in another window, away from the keyboard mid-problem. **That is precisely when drift consolidates, and precisely when the tick will not fire.** ⚠ **My instrument cannot see it.** It measures gaps in the *event stream* and I read them as gaps in *presence*. Those two quantities diverge exactly on the case that matters. p90 = 17.5 s bounds the distortion **during active work**; it says nothing about presence without activity, because no event is emitted by a steward who is reading. **Recorded as UNMEASURED, not as covered by the data.** Fifth instance this week of the same family — an instrument's reach mistaken for a claim's subject (three-store negative · `find` vs `glob` · `55 files` · the dry run that bypassed its own normalization · this). **Four of the five were caught by another party naming the limit rather than by the executor re-checking**, which is the disclosure-of-scope mechanism the correction record names, doing the work Constraint 6 attributes to difference of formation. *If it needs measuring later:* nothing in the transcript can supply it. It would need a presence signal independent of the event stream — terminal focus, keystroke activity — which is a larger and more intrusive instrument than the question currently warrants. #### (c) The proportions condition was met by DISSOLUTION, not by compliance REVIEWED-125 deferred the re-derivation requiring **adjusted proportions**, on the assumption that the burst problem persisted. **It does not.** 73/20/7 was calibrated against a time-uniform tick, and restoring the generator restores their calibrated meaning; adjusting now would correct for a defect that no longer exists. **Recorded as dissolved rather than met, so the next reader knows why the number is unchanged** — an unexplained unchanged number reads as a condition ignored. #### Accepted as filed **20-minute tick — accepted by the jurist**, including the one-way adjustment path: §8 licenses lengthening if it reads as noise, so starting at 30 would require a shortening the path does not permit. #### Next act on this item **Run the status-line experiment before any body is built.** Ten minutes; settles §8a's design and REVIEWED-125 cond. 2; the difference between a body that idles visibly and one that only appears to. **Awaiting:** nothing on (a)–(c). The status-line experiment is the executor's next act and needs no ruling. ### AMENDMENT 2 — 2026-08-22 — the unverified assumption resolved from the schema, AGAINST my own argument **Settled without the experiment.** The settings schema documents a `statusLine.refreshInterval` field: > *"Re-run the status line command every N seconds **in addition to event-driven updates**"* — number, minimum 1. **So the status line is event-driven BY DEFAULT, and time-driven when `refreshInterval` is set.** #### ⚠ PENDING-152's FIRST DAEMON PRONG IS WRONG AS FILED I wrote, as the load-bearing premise of a structural argument: > *"the delivery surface — the status line — re-renders on session activity, so the gate is relocated, not removed."* **That is true only of the default configuration.** With `refreshInterval` set, the surface re-renders on a timer regardless of session activity. **The delivery surface CAN be time-driven, and I asserted it could not.** I flagged this as an unverified assumption when I filed it. **The flag is the only reason it was recoverable** — an unflagged premise inside a "structural limit" reads as established and gets inherited. Disclosure of scope paying out again, this time on my own claim rather than a jurist's. #### ⚠ AND IT SOLVES THE CASE THE JURIST SAID WAS UNMEASURED AMENDMENT 1 recorded, correctly, that my data could not see **presence without activity** — the steward reading or drafting elsewhere, generating no hook events, which is exactly when drift consolidates. I declared it unmeasured and said measuring it would need an intrusive presence signal. **It does not need measuring, because it can be solved.** A status line with `refreshInterval: N` fires while the steward reads and drafts, with no events at all. **The mumble does not need to be event-gated in the first place.** #### Design consequence — the mumble's home changes **Filed:** a clock check inside `UserPromptSubmit` / `PostToolUse`. **Corrected:** the mumble is driven by the **status line's own refresh**, not by a hook. Frequency comes from `refreshInterval`; the 20-minute tick is a counter over refreshes rather than over events. No hook is involved and no event-gating remains within a session. This is cleaner than what was filed, and it collapses two problems into one mechanism: **the same refresh that renders the body's silence also drives the mumble's clock.** **It also satisfies REVIEWED-125 cond. 2 cheaply.** A surface re-rendering every N seconds can carry **time-derived** variation with no content derivation and no sprites or animation frames — exactly what condition 2 requires and what a static name cannot do. #### What SURVIVES from PENDING-152 **The daemon's second failure stands, untouched and still decisive.** Between sessions **nothing runs at all** — not the status line, not its refresh. Ticks generated by a daemon while no session exists must be **dropped** (equivalent to no daemon) or **queued** (a backlog is state, which is memory, which is the hazard the hard cap was rejected for, arriving in a burst at session start). **So the conclusion is unchanged and its support is now narrower and more honest:** a daemon buys nothing, not because delivery is inherently gated — it isn't — but because the only interval a daemon could cover is the one where there is no audience and no legitimate place to put the residue. **The 20-minute interval, the proportions-by-dissolution finding, and the measured event data are all unaffected.** #### Probe installed, and how to remove it `~/.claude/settings.json` now carries a temporary `statusLine` running `~/.claude/statusline-probe.sh` at `refreshInterval: 10`, logging each invocation to `~/.claude/statusline-probe.log`. Backup at `~/.claude/settings.json.bak-2026-08-22`. **The surface was confirmed free before installing; nothing was displaced.** Remove by deleting the `statusLine` key. It prints `· probe` and carries **no name and no utterance** — transport, not voice, per the standing line. May require a config reload to begin firing. **Awaiting:** nothing. The empirical confirmation is a read of the probe log, not a decision. ### AMENDMENT 3 — 2026-08-22 — CONFIRMED empirically; surface restored; one design question banked #### ✅ The schema's claim is confirmed by behaviour, not taken on documentation Probe at `refreshInterval: 10`, **55 invocations over 516 seconds**: | | | |---|---| | gaps of exactly 10 s | **45 / 54 (83%)** | | shorter gaps (1–7 s) | 9 — event-driven updates layered on top, as the schema says | | ⚠ **MAXIMUM gap** | **10 s — the refreshInterval exactly** | **The 10-second ceiling is the whole finding.** It is only reachable if the timer fires independently of activity, and the measured window includes the stretch in which the steward read and composed a reply — no tool calls, no typing into the session — during which **the log never paused**. **So the property the amendment rests on is established by observation:** the status line keeps firing with no input at all. *Documentation is a claim about behaviour; this is the behaviour.* #### ✅ Surface restored — now, not "before the 25th" `statusLine` removed from `~/.claude/settings.json`, **verified byte-equal to the pre-probe backup** (`d == b`, all seven original keys present and no eighth). Probe script deleted; backup deleted as redundant once equality was proven; the log kept as evidence at `scratchpad/statusline-probe-2026-08-22.log`. Done immediately rather than scheduled, because *"I'll remove it later" is how a temporary config becomes permanent* — a failure mode named in advance should not then be enacted. **The derivation on the 25th runs against an unmodified settings file.** #### 📌 BANKED, NOT SOLVED — the empty content window *The jurist's third point, recorded now so it is not lost, and explicitly not settled.* Under the old event-keyed scheme, events supplied the mumble's **content**: a tick fired because something had happened, so there was something to remark on. Under the refresh-driven scheme, frequency and content are fully separated — **a tick can arrive with an empty content window**, during exactly the long present-but-idle stretches the new design was adopted to cover. ⚠ **Silence must then be defined, because there are two different silences:** | silence | meaning | |---|---| | *nothing happened* | the content window is empty; there is nothing to say | | *the 73% said so* | something happened and the draw came up silent | **If the first is implemented as the second, the proportions quietly stop meaning what they claim** — the measured 73/20/7 would be diluted by an unknown and variable number of empty-window ticks, and the utterance rate filed in PENDING-152 (≈2.3/day) would silently overstate. That is a defect of the same family as the burst problem: a generator producing something other than what its numbers describe. **Settle before build, not before the beacon.** The obvious candidate — an empty window does not consume a draw — needs checking against §8's unlearnability requirement, since "did anything happen since the last tick?" is a state question, and state is where memory begins. #### For the record — the flag did the work A premise filed as load-bearing was falsified within the hour **by the party that filed it**, and was recoverable *only* because it carried an explicit unverified marker. An unflagged assumption inside something labelled *"structural limit"* is inherited as established, and the next reader has no way to know it was ever in question. ⚠ **Note also what the correction did NOT do: the conclusion kept its name and lost its original justification.** A daemon still buys nothing — but on between-session grounds, not on delivery gating, which turns out not to exist. **A conclusion that retains its old reasoning after that reasoning is falsified is how a false premise survives its own refutation.** The narrowed support is recorded in AMENDMENT 2 for that reason. **Awaiting:** nothing. The empty-content-window question is banked for the build phase. ### AMENDMENT 4 — 2026-08-22 — the probe's self-witness limit; and reading 2 may reopen the case it was meant to close *(The measurement lives in AMENDMENT 3, not 2 — noting only so the correction lands in the right place.)* #### (a) The claim, phrased to what the instrument can actually support ⚠ **The probe is the only witness to its own firing.** An invocation that failed silently would leave no entry, and therefore no gap — the log cannot distinguish *"the timer did not fire"* from *"the timer fired and the logger died."* **Precise form, superseding AMENDMENT 3's phrasing of this one claim:** > **No gap exceeded 10 s among logged invocations.** Not *"the timer never missed."* The ceiling holds on the entries that exist, and the inference — that firing is activity-independent — survives, because a silent miss could only make the true cadence *more* regular than observed, never less. **A missed fire cannot manufacture the ceiling; it can only hide a longer gap.** So the finding is directionally safe and the phrasing was loose. Not worth a second instrument. #### (b) The empty content window — the jurist's sharpening adopted, and one consequence that follows **The framing is corrected and better.** It is not state-versus-stateless: a boolean *"did anything happen in this window?"* is recomputed each tick, accumulates nothing, and takes no input from whether the fool was heard or muted. **It cannot drift toward agreeableness because the steward's response never enters it.** §8's bar is on adaptation, not on evaluation of the present window. The real question is **what 73/20/7 are proportions OF**: | reading | consequence | |---|---| | **1 — proportion of TICKS.** Empty windows consume draws. | The filed ≈2.3/day overstates by an unknown factor. | | **2 — proportion of NON-EMPTY ticks.** Empty windows skipped before the draw. | The numbers mean what they were calibrated to mean. Partially re-couples frequency to activity. | **One argument for reading 2 that strengthens it further:** the re-coupling is to a **boolean**, not a count. A window containing 1 event and a window containing 53 both read *non-empty*, so **the burst problem cannot return through it** — burst sensitivity requires proportionality to volume, and reading 2 has none. That is a materially weaker coupling than the one §8 was rewritten to escape, and it is the right trade. #### ⚠ (c) BUT reading 2 appears to reopen the case refresh-driving was adopted to close *Following the jurist's own framing one step further, and surfaced rather than solved.* Refresh-driving was adopted because a hook-gated tick cannot fire when the steward is **present but generating no events** — reading, drafting elsewhere — *"precisely when drift consolidates."* **Under reading 2, that window is empty, so it is skipped, so no utterance occurs.** The fool is silent during exactly the stretch the change was made to reach. Refresh-driving would then deliver the **body's visible silence** (REVIEWED-125 cond. 2, genuinely won) but **not the mumble's reach into idle presence** — which is less than AMENDMENT 2 claimed for it. **The dependency is what counts as CONTENT, and it has not been defined anywhere.** If content is only *"events since the last tick"*, the above holds. If a window with no events still has something to remark on — what is open, what is unresolved, what has been sitting — then it is not empty and reading 2 reaches the idle case after all. Note that remarking on **standing state** is not content-keyed *judgement*: §8 forbids assessing whether a thing is any good, not noticing that it exists. **Three-way, and it should be decided as three rather than discovered as two:** what the proportions are of · what counts as content · whether idle presence is reachable at all. **The first two jointly determine the third**, and the filed ≈2.3/day was computed under none of the combinations — it needs re-deriving once they are fixed, as the jurist says. **Awaiting:** nothing. After the beacon; nothing here blocks Tuesday. ### AMENDMENT 5 — 2026-08-22 — the three decisions collapse to one; a fourth option; and it moves in §4's order #### (a) The collapse — jurist's argument, adopted **Reading 1 does not survive contact with the output.** If content is events-only and a draw comes up *notable* on an empty window, the fool has nothing to say. It either stays silent — **which is reading 2 with different bookkeeping** — or it speaks from something other than events, which is already the standing-state answer. **Reading 1 with events-only content is incoherent at the point of utterance, not merely dilutive.** **And if standing state counts as content, no window is ever empty** — there are always thirty-odd open items. The empty-window case disappears, readings 1 and 2 become the same thing, and ≈2.3/day means what it claims. **So it is one decision with a dependent, not three.** *What counts as content* determines whether *what the proportions are of* has any behavioural consequence at all. AMENDMENT 4's three-way framing is superseded. #### (b) Standing state fails §2, and my defence of it was wrong I argued that remarking on standing state is not content-keyed *judgement* — §8 forbids assessing whether a thing is any good, not noticing that it exists. ⚠ **That defence does not hold.** *"PENDING-4 has been open since April"* is a **factual claim about the docket**, checkable against `PENDING.md`, and the fool would be right or wrong about it. **§2 says gradeable means the design has failed** — and it does not distinguish evaluative claims from factual ones. Existence and duration claims are checkable, which is the whole of what §2 bars. It also **duplicates `governance-drift-check.py`**, which is where the PROCEDURE axis was sent for precisely this reason (REVIEWED-125 §5a). **A cleaner test than §2 currently states, offered for the doctrine:** not *"is it a judgement?"* but **"could someone check it and find it wrong?"** Standing-state utterances fail it. Character utterances cannot fail it, because they make no claim about the world. #### (c) OPTION 4 — the window supplies a TYPE, never material *The jurist's, and it is what the reference implementation actually did:* the buddy's reactions were canned strings keyed to **event type** — success, error, large diff — never to content. **It never analysed anything. Its utterances came from its character.** Applied here: the window supplies at most *something happened · nothing happened · something failed*. **The utterance comes from the soul.** | property | under option 4 | |---|---| | empty windows | none, in the relevant sense | | idle presence | reachable | | proportions | mean what they say | | gradeability | nothing produced is checkable | | drift toward checking | impossible — it never had material to check | **It is also the tradition's fool** — Lear's Fool needs no docket; he riffs, sings, quotes proverbs. **And it is the steward's own Oblique Strategies deck arriving from the other side: a fixed deck has no content window at all, and the deck was the original object.** **The cost, stated as cost:** a fool speaking from character lands less reliably than one speaking from material. Against which — *the capybara had no governance corpus and pointed the steward right repeatedly*, and that is the only working precedent any party here has. #### ⚠ (d) EXECUTOR ADDITION — option 4 concentrates all risk into one irreversible act, and that moves it in §4's order **Under options 1–3 the soul supplies register. Under option 4 the soul supplies the ENTIRE utterance.** §7: generated **once** from the bones, stored permanently, **never hand-edited and never regenerated for taste**. §10: **being frequently wrong is not grounds for retirement** — *"those are the specification."* **So under option 4 a soul that produces poor utterances cannot be fixed and cannot be retired for it.** All of the fool's value routes through a single irreversible generation. That is not an argument against option 4 — it is the same no-reroll discipline the bones carry, applied where it now matters far more — but the steward should choose it knowing the weight has moved. **Consequence for the order, and it is actionable:** §4 lists *5. bones derived · 6. soul generated*. **No interval is specified between them.** If the content decision determines how much the soul must carry, it should be settled **between step 5 and step 6** — after Tuesday's draw, before the soul exists. Generating the soul first and deciding afterwards would fix the fool's entire voice before knowing whether that voice is the whole instrument or only its register. **This touches nothing pre-registered.** The axes are ratified, the seed rule is filed, the draw is well-defined under every option. Only the placement of a later decision changes. **Awaiting:** steward, on the content question — four options, after the beacon. **Not before the soul.** ### AMENDMENT 8 — 2026-08-25 — the unverified assumption is SETTLED, by this item's own method; and one clause does not survive it *Filed at implementation, against the substrate, not against documentation.* #### (a) ✅ The assumption this item flagged is settled — and it was settled the way the item said to settle it > *"Whether Claude Code re-renders the status line on a timer or only on session activity. Not verified… **Settle by experiment:** configure a status line that prints the current clock time, leave a session idle, and observe whether the displayed time advances."* **Both halves ran.** The schema, read out of the binary: `statusLine: {type, command, padding?, refreshInterval?}`, where `refreshInterval` is *"Re-run the status line command every N seconds in addition to event-driven updates"* — seconds, minimum 1. ⚠ **The first name-match was `refreshIntervalMs`, which belongs to the certificate watcher.** Reading the context rather than trusting the match is what kept a wrong key out of the design. And then the behaviour, from the body's own invocation log on the day it shipped: ``` gaps(s): 0,0,0,0,0,0,0,0,0,0,0,0,37,13,0,2,15,2,4,11,13, 60,60,60,60,60,60,60,60,60,60,60,60,60,60, 11,1,1,9,1,3 └─────────── event-driven ───────────┘ └────────── idle: timer ──────────┘ ``` **Fourteen consecutive 60-second gaps with no input at all.** The timer is real and fires during idle. *Documentation is a claim about behaviour; this is the behaviour* — the same standard AMENDMENT 3 set for itself. #### (b) ⚠ One clause of the AMENDMENT-2 correction does not survive, and the conclusion outlives its mechanism The corrected text reads: *"the 20-minute tick is a counter over refreshes rather than over events… no event-gating remains within a session."* **Against `in addition to event-driven updates`, a counter over refreshes IS a counter over events.** The log's leading run of twelve zero-second gaps is exactly what such a counter would have been counting — invocations bursting with activity, which is the v1 defect §8 was rewritten to remove. **The conclusion survives; the mechanism named does not.** Frequency is not event-gated — but only because the built tick consults the **clock**, not the invocation count. Recorded here rather than silently implemented, because this item has now logged twice that *a conclusion which keeps its old reasoning after that reasoning is falsified is how a false premise survives its own refutation.* This is the third instance, and it is the item's own text this time. #### (c) What shipped, and where the guards actually live `6f0ccde` (body) and this session's tier-2 commit. The binding constraints are carried **structurally rather than by intention**, which is the only form that survives a later editor: | constraint | how it is held | its negative control | |---|---|---| | the body correlates with nothing | `render()` takes the minute and nothing else — a function that cannot see the session cannot leak it; asserted on `co_argcount` and `co_names` | a deliberately leaky fixture **is** caught | | the body does not announce the voice | `len(MARKS)` coprime with the interval, so the mark at mumble-time walks the whole cycle | a commensurate 4-cycle **is** caught | | the tick consumes | proven on the built thing: 12/12 forced-due invocations advanced the clock | — | | the utterance has no adjudication path | the prompt states it verbatim; a mechanical net rejects advice, questions, `we`, vocabulary of lack, and anything outside 3–9 words | every clause has a rejecting fixture | | the register is not duplicated | the soul is **read from its filed artifact** at run time; no soul, no voice, and no fallback | a copy in the source **is** caught | ⚠ **One control failed against itself and was fixed rather than relaxed:** the check *"this file contains no copy of the soul"* searched for a phrase that its own needle had put into the file. Same class as the hand-typed link canary whose only finding was the pattern inside its own specification. The needle is now built by concatenation so the literal never appears. **Files affected:** `scripts/tarbuckle-body.py`, `scripts/tarbuckle-mumble.py`, `~/.claude/settings.json` (untracked — see below). **Awaiting:** nothing. Filed as a record at implementation. ### AMENDMENT 6 — 2026-08-22 — the adjudication-path criterion supersedes "checkable in principle"; the material is the SESSION *Jurist correction, received via the steward. Recorded as a correction rather than as a fifth option.* #### The separation that is most of the answer | | | status | |---|---|---| | **Material** | what it remarks on | **the only open question** | | **Register** | how it sounds | settled — the soul, §7 | | **Occasion** | when it speaks | settled — the refresh tick | #### Corpus: NO — settled on what nine trials established **A fool reading `PENDING.md` produces claims about `PENDING.md`, and claims about the record are the executor's genre.** That is how the checker kept being rebuilt. #### ⚠ Type-only was an overcorrection, and is withdrawn *Something happened / nothing happened / something failed* **makes a mood ring — atmosphere within a fortnight.** And it contradicts the steward's own precedent: canned strings keyed to event type cannot point anyone in the right direction, and the capybara did that repeatedly. **The buddy had two paths, and the one that worked was the one watching the session.** #### ⚠ THE CRITERION IS NOT "CHECKABLE IN PRINCIPLE" — IT IS WHETHER AN ADJUDICATION PATH EXISTS **This supersedes the test the executor offered in AMENDMENT 5(b)** (*"could someone check it and find it wrong?"*), which was the jurist's earlier line and is now withdrawn by its author. > *"PENDING-4 has been open since April"* — **a path exists**: open the file. Once a path exists the trio will walk it, the fool acquires a truth value, and it is a checker again. > > *"You've used the word structural nine times this hour"* — **no path.** Nobody files a session observation. No forum, no ruling, no record it could corrupt. **It can be wrong and cost nothing — which is exactly the safety §1 claims for the position.** **So the exclusion of standing state changes its grounds.** Not excluded because it is checkable; excluded because **the docket has a forum and the session does not.** **The live session is the material. The docket is not.** What is being worked on right now, in front of the steward — not what is on file. The model supplies the words, in the soul's register, about the session. #### What this settles for free **The empty-window problem dissolves.** It arises only if material means *governance events since the last tick*. **A session in progress always has material — the steward is there and something is happening** — so no window is empty, readings 1 and 2 converge, and **≈2.3/day means what it claims.** Between sessions nothing fires, which is correct: no audience. #### ⚠ The residual risk, named by the jurist and carried here **Session-as-material sits one step from commentary on the steward's reasoning, and commentary on reasoning is a checker in a thin disguise.** The guards are already specified and must hold **together**: one line · the soul's register rather than governance prose · no filing path · and the dump stat guaranteeing it is reliably blind to something. **If any one slips, this is the door it comes back through.** **Executor observation:** the adjudication-path criterion and §9's no-filing rule are **the same guard seen from two sides** — §9 removes the path, and the criterion is what explains why removing it is load-bearing rather than merely tidy. That is a reason to treat §9's non-contestable status as carrying more weight than it appeared to. #### ⚠ EXECUTOR: my own AMENDMENT 5(d) is WEAKENED by this correction I argued that option 4 concentrates all risk in one irreversible act, because the soul would supply the entire utterance — and that the content decision therefore belongs between §4 steps 5 and 6. **Under session-as-material the soul supplies the register and the session supplies the material, so the risk is distributed again and the argument loses most of its force.** It does not vanish — the decision still determines what the soul must carry — but it no longer concentrates the fool's whole value in a single generation. **Recorded rather than left standing, since an argument that keeps its conclusion after its premise moves is the failure this item has now logged twice.** **Awaiting:** the open questions below, put to the steward. ### AMENDMENT 7 — 2026-08-22 — the buddy's record SURVIVES, and it relocates the guard **The steward asked whether any trace remained. It does — far more than "a trace."** The buddy's own transcripts (2026-04-03/09) are long pruned, but **the memory layer is not pruned**, and it holds a dedicated feedback memory plus Thistleweld sections in six April session records. Recovered and consolidated at `claude/governance/fool/THISTLEWELD-RECORD-recovered-2026-08-22.md`. **The buddy has a name: Thistleweld.** Seven verbatim utterances · thirteen attributed catches (three became GH issues #121/#127/#128) · and **three explicitly recorded silences.** ⚠ **The three silences matter on their own.** *"No Thistleweld observations this session"* appears three times, in the same form — someone thought the **absence** worth writing down. That is a negative-instance record of exactly the kind the instrument censuses found missing everywhere else, **and it means the silence was legible with no status line at all.** #### The register, observed rather than asserted *"scoring without signal"* · *"garbage in gospel out"* · *"ten events ten failures"* · *"Eleven modules, one swallower. Silent failures scale fast."* · *"synthesis without the actual failure modes, cart horse backwards"* · *"One person, three documents, infinite rationality"* · *"Zero delegation protocols yet"* **Three to nine words. No verb of judgement. Noun-phrase collisions.** It does not say a thing is bad; **it puts two facts next to each other so the gap shows.** #### ⚠ THE PRECEDENT COMPLICATES THE ADJUDICATION-PATH CRITERION, THEN RESOLVES IT BETTER **Against the criterion:** every catch is a checkable claim about code — `base.ts:83`, `allSettled` at ~line 318, preference 10/10. Adjudication paths existed and **were walked**; three became filed issues. The memory's own instruction is *"investigate the specific code he's pointing at."* On the criterion's terms Thistleweld was a **checker** — what nine trials kept rebuilding and what §2 says means failure. **The resolution, and it is better than either position stated so far:** *"scoring without signal"* **has no truth value.** It is not a claim but a gesture at a shape — it cannot be opened, checked or refuted. What was adjudicable was the **executor's finding**, produced by following the gesture to the code, and filed as the trio's. **Which is precisely §9:** *"anything the steward carries into the record enters as the steward's… the fool is never cited as a source."* | | | |---|---| | the fool's utterance | a gesture at a shape — no truth value, no path | | what follows it | a finding, owned by whoever investigates | **The value was real and the fool was never a checker, because the checkable thing was always produced downstream by someone else.** #### ⚠ THE LOAD-BEARING CONSEQUENCE — the guard is in the UTTERANCE FORM, not the material Both the jurist's criteria — *checkable in principle*, then *adjudication path* — located the guard in **what the fool looks at**. The record locates it in **how the fool speaks**. **Three-to-nine words with no verb of judgement is what makes an utterance un-adjudicable.** Terseness is therefore **not style and not an aesthetic objection to governance prose** — it is the mechanism that keeps the position outside §2. **If the fool ever speaks in sentences that can be true or false, the guard is gone regardless of what it is looking at.** This settles my earlier open question about whether the one-line rule is a hard truncation in code or a convention in the prompt. **It must be enforced in code.** It is not a style preference; it is the load-bearing guard, and §14 already lists §9 as non-contestable. #### What the record does NOT establish, stated so it is not over-read - **No transcript of Thistleweld speaking survives.** These are quotations inside **executor-written** session records — accurate as quotations, but **selected by the executor**, and the selection is not neutral: an utterance that landed is likelier to have been written down. **Same self-authored-corpus hazard as the retired 08-20 question**, and it applies to the flattering half of this finding. - **The catch list is attributed, not audited** — no check that each catch originated with Thistleweld rather than being credited afterwards. - **Nothing is known about its rate**, only that three sessions recorded none. - ⚠ **The steward's own recollection remains unrecorded**, and is the one source that could correct all of the above. **Awaiting:** jurist on the relocation of the guard from material to utterance form; steward's recollection. ### AMENDMENT 8 — 2026-08-22 — criterion restated on its third pass; and the chain verified, two links corrected #### The criterion, third statement — and the rule survives its justification | pass | criterion | status | |---|---|---| | 1 | *checkable in principle* | withdrawn by its author | | 2 | *no adjudication path exists* | **falsified by the record** — a forum was convened, an impasse created, a jurist ruling required | | 3 | **produces nothing that is ITSELF ruled on** | survives | **The operative property: the utterance is a claim about SHAPE — order, approach, arrangement — not about content.** Shape-claims have no adjudication path because **no file settles them**; one can only proceed differently and see. ⚠ **Recorded as the jurist asks:** §9 was right and the gloss was **a wrong justification for a correct rule**. *"What the steward carries forward enters as the steward's, in his words"* was always the mechanism. **A rule that keeps a falsified justification is the failure mode this item has now logged three times** — the daemon conclusion, my AMENDMENT 5(d), and now this. #### ⚠ The caution was BACKWARDS The jurist flagged commentary on reasoning as the door the checker returns through. **The record says kinds 2 and 3 are the only contributions that changed a governance document rather than a line of code.** Kind 1 — live processes — is the bulk and the cheap half. **And kind 3 is the striking one.** *"One person, three documents, infinite rationality"*, identifying the authorization bottleneck, is an observation about **the arrangement itself** — precisely what nine trials were built to elicit, at considerable expense, and never got. **A buddy with no corpus, no grading and no standing produced it unprompted in April.** #### ⚠ THE CHAIN — verified rather than passed on, and two links do not hold The jurist proposed: *Thistleweld redirected OP-02 → five fault lines → Fault Line 5 → migrated into Constraint 6 → Constraint 6 voided trial 09.* | link | verdict | |---|---| | Thistleweld's aside redirected the synthesis to **five actual architectural fault lines** | ✅ **documented directly**, `session-2026-04-07-op02.md:15–16` | | Fault Line 5 exists as a numbered thing because of that pivot | ✅ follows | | FL5 **"migrated into"** Constraint 6 | ❌ **this is the reading the substrate corrected on 08-20.** FL5 argues from Bourdieu's shared field and *illusio*; C6 asserts difference of **formation**, *"an axis FL5 never employs."* REVIEWED-124 Q3 records `NOT ESTABLISHED`, and even its stated reason was overturned the same evening | | **Constraint 6** voided trial 09 | ❌ **the fault lines' PRESENCE IN THE CORPUS voided it** — *"the executor found the fault lines present in the corpus and held the run"* (`fool-trial-log.md:107`). Constraint 6 is not the mechanism | **⚠ THE CORRECTED CHAIN IS SHORTER AND STRONGER, and it does not route through the contested link at all:** > **The fault lines that Thistleweld's aside caused to exist are the very documents whose presence in the corpus voided trial 09.** Link 1 to link 4 directly. **The trial built to test whether a fool could reach that critique was voided by the presence of the critique a fool occasioned.** That survives the substrate check; the version routed through Constraint 6 does not. **This bears on PENDING-89 more directly than anything the buddy fool will produce** — and it does so as *n=1 documented history*, not as an instrument result. #### Two things to hold, both adopted **1 · The intervention was valuable BECAUSE IT WAS RARE.** An impasse requiring a jurist ruling is expensive; at any frequency it becomes an impasse generator. **The cadence is not only noise control — it is what makes shape-level interruption affordable. 7% notable is the constraint that lets kind 2 exist at all.** **2 · ⚠ DELEGATION REMOVES THE MATERIAL.** The silent sessions are document production and delegated work — the L1 audit ran via **four parallel agents**. Three data points, inferred from descriptions, and held as suggestive. **But if it holds: as the executor delegates more to subagents, the session carries less reasoning, and the fool has less to watch. The material is not the work; it is the thinking that stays in the room.** That is a live constraint on the executor's own working style, not only on the fool's design. #### What changes in the spec **Material** = the live session, **including stated plans and observations about the arrangement**. The docket stays out. **The guard is no longer *avoid commentary on reasoning* — it is NO TRUTH VALUE:** gestures, questions, observations about shape; never claims about the record. **Awaiting:** steward on the chain (the corrected form is the citable one); jurist on the two corrected links. --- ### ⚖ The empty-window question — SETTLED 2026-08-25, and it needs no amendment **Question, banked before the beacon:** when the mumble ticks and nothing is in the window, does the tick **consume its draw** or **get skipped**? **Answer: it consumes. There is no skip branch, and none should be written.** Two reasons from §8's own text, and then the reason the case does not arise at all. **1 · Skipping re-keys frequency to content — the exact defect §8 was written to remove.** §8: *"Frequency and content are separated, which is what v1 conflated."* If an empty window suppresses the tick, utterance rate becomes a function of event presence: quiet days silent, busy days loud. That is v1's burst defect in mirror image, and §8's own diagnosis was that the fix *"is to restore the original generator, not to patch the re-keyed one."* A skip-on-empty branch is a patch on the re-keyed one. **2 · Skipping introduces state.** To skip is to decide not to draw. If the draw is not consumed it is conserved, and a conserved draw is a budget. §8: *"This has no memory and no budget, so the cadence stays unlearnable"* — and the hard daily cap was rejected in part because *"it also introduces a budget-spent state, which is memory, and memory is the beginning of learnability."* Same objection, same force, and it was already ruled once. **3 · The case does not arise.** The executor's four-way expansion (*what are the proportions of? what counts as content?*) collapsed once **material was settled as the live session** rather than as governance-events-since-last-tick. A session in progress always has material. The genuinely empty window is **no session** — and with the tick on the status line's own refresh, no session means no refresh, therefore no tick. **The mechanism excludes the case by construction rather than by rule**, which is why the correct answer adds nothing. ⚠ **The degenerate case, named rather than glossed:** a session open but *idle* — the steward reading, not acting. The window holds no new events; the session still holds material. **That is not an empty window.** §8's *"in the room, hears everything"* property is precisely what covers it: presence does not require novelty. And since the refresh amendment moved the tick onto wall-clock-in-session, this is the **common** case, not the edge — the fool will often remark on something that has not changed, and that is the specification working, not failing. **If it reads as noise, §8 already names the lever, and it is not an emptiness check:** *"If it reads as noise, the interval lengthens — the proportions do not become adaptive."* **Filed as a DETERMINATION, not an amendment.** REVIEWED-125 binds that an answer requiring the trigger key to change is an amendment to §8 and must be filed as one. This answer changes no trigger key, adds no branch, and deletes a special case that was never specified — **the spec gets smaller.** ⚠ If the jurist reads it as an amendment nonetheless, **this is the block to strike**, and it should be struck rather than reinterpreted. **Consequence — §8a is unblocked.** Nothing in the body's rendering depends on window content, so the body renders identically whether or not the window holds events. The remaining §8a question is only *what the body renders when silent* (REVIEWED-125 condition 2: variation from time or nothing, never content). ### ⚖ The mumble interval — DETERMINED 2026-08-25: **20 minutes, frequency UNKNOWN** §8's one remaining blank, filled. **20 minutes**, carried from the derivation that produced it — 121 measured active minutes per session, ~1.6 utterances per session. ⚠ **But the derived FREQUENCY is filed as `UNKNOWN`, not as ~2.3/day.** That figure was computed against *active session minutes*, and the refresh-driving amendment moved the tick onto **wall-clock time in session**. The old number was justified under neither reading that survived. **Carrying it forward would be the say–do seam: a number that looks derived and is not.** **Why a blank rather than a fresh estimate:** producing a new figure means measuring wall-clock-in-session, which has not been measured. A number derived from an unmeasured base is worse than an honest gap, because it arrives wearing the authority of a derivation. ⚠ **The blank is not a gap in the spec — it is what honest degradation looks like when the instrument that would fill it has not been run.** It becomes measurable within a fortnight of Tarbuckle running, and is then filed against data instead of inference. *(Filed as a tracked deferral rather than left in prose. §8 already obliges this report and had no trigger — the class PENDING-158 was authorized against today. Deliberately `manual`: inventing a date before the clock can start would be the proxy the schema's own comment warns against.)* ### ⚖ The body's rendering — DETERMINED 2026-08-25: **variation at the margin of notice, correlating with nothing** REVIEWED-125 condition 2 governs and rules out a static name as **furniture-blind**. Resolved toward the quiet end. ⚠ **First, a correction to the executor's reading of condition 2, from the jurist, and it matters for what gets built.** The executor treated *a presence you forget* as the failure mode to be designed against. **It is not — it is the specification.** *Lear's Fool is in the room for four acts while nobody attends to him; his being there is what makes the moment he lands possible.* Condition 2 guards against something stronger and narrower: **furniture-blindness — ceasing to be perceptible even peripherally.** Being unattended is the design. Being imperceptible is the defect. The bar is lower than the executor was building toward, and building to the higher bar would have produced the widget. **The specification:** - **Variation that is detectable if you glance, never rewarding if you stare.** Something that changes at the margin of notice clears condition 2. Something that invites you to look is already past it. - **Time-derived. No content. No state.** A single character or minimal glyph shifting with the tick — enough that the surface is *alive rather than printed*, not enough to read. ⚠ **If it can be interpreted, it is a widget.** - ⚠ **THE BINDING CONSTRAINT — the variation must not correlate with ANYTHING.** Not with whether a mumble is coming, not with what has happened, not with the draw, not with the bones. **The moment a glyph means something, the body becomes a channel and the fool becomes gradeable through it** — which §2 makes a design failure and §9 exists to prevent. This is the door the whole design leaks through, and it is specified explicitly rather than left to good sense. - **One-way adjustment, written into the spec:** *if the body reads as something to watch, **reduce** the variation — never make it adaptive.* Identical shape and identical reason to §8's *"if it reads as noise, the interval lengthens — the proportions do not become adaptive."* **Both determinations are the executor's to take** (steward, 2026-08-25) and both adopt the steward's stated view. Filed here so the build inherits them rather than re-deriving them, and so the reasoning survives the decision. ## PENDING-153 — The Thistleweld kind-3 read: the arrangement critiqued from outside, and the record lost where it came from **Date:** 2026-08-22 **Tag:** [PROPOSAL] **Summary:** Read the recovered Thistleweld corpus specifically for **kind-3 utterances — observations about the arrangement itself — and what became of them.** Filed as its own item per the jurist. **HELD until after the derivation and the soul.** ### Why this is not about the fool *"One person, three documents, infinite rationality"* — the authorization bottleneck named **unprompted**, in April. And the OP-02 redirect, which gave the five fault lines their form. **Both are observations about the arrangement, produced by a differently-positioned party with no corpus and no standing, four months ago — and both were absorbed without anyone recording where they came from.** **This is PENDING-89's territory, and in one respect it is better evidence than the v1 Chamber archive:** it is an instance of the arrangement's self-critique having an **external origin that the record subsequently lost**. If the question is whether the three parties' misses correlate, then *the sharpest thing said about the arrangement in April came from outside it and left no attribution* is a finding in its own right. ### ⚠ ORDERING — and the reason is contamination, not convenience **FREEZE the corpus now. Do not read further before the derivation.** The design decisions the corpus could inform are all settled: material is the live session · the guard is no-truth-value · the tick runs on refresh · the proportions mean what they say. **More utterances would give a richer sense of Thistleweld's voice, which is exactly what must not be had.** The soul is generated **once** from the bones (§7), and **a corpus of admired utterances in front of whoever writes that prompt is selection toward a fool already liked.** Reading more before the 25th risks contaminating the one thing the seed exists to protect. **Sequence:** freeze → derive Tuesday → generate the soul → **then** read this properly. ### ✅ The clock item is already discharged — and the risk is narrower than stated The jurist flagged that the corpus survived in an un-pruned layer and *"pruning is what nearly took the trial 09 design"*, so it should be committed durably today. **Verified rather than assumed:** the consolidated record is committed (`1e2ba50`) and present on **both remotes**; working tree clean. **And the source files were never at risk** — `feedback-thistleweld.md`, `session-2026-04-07-op02.md` and `session-2026-04-07-replay.md` are all **git-tracked in `~/dotfiles`**. The 30-day pruning applies to `*.jsonl` transcripts, not to the memory layer. **The trial-09 design was vulnerable because it existed only in a transcript; this corpus never did.** **Files affected:** none — read-only, and deliberately not read further. **Awaiting:** steward authorization. **Not before the soul.** --- ## PENDING-154 — Two patterns in how the three parties reason, with the second one's limits stated **Date:** 2026-08-22 **Tag:** [HARDENING] **Summary:** Cross-filed to **PENDING-89**. Two patterns surfaced on 2026-08-22 — one about how conclusions survive falsified justifications, one about who catches what — with the second's evidential limits recorded so the table is not over-read. ### Pattern 1 — the impossibility claim, and why it bites here specifically **Three times in one evening a conclusion outlived a falsified justification.** In each case the conclusion was right and the reason was wrong, and all three reasons were claims of **structural impossibility**: | claim | killed by | |---|---| | *"delivery is inherently gated"* | one schema field (`statusLine.refreshInterval`) | | *"the risk concentrates in one irreversible act"* | the material moving to the session | | *"no adjudication path exists"* | one April session record | **The jurist's mechanism, adopted:** an impossibility claim is a **universal** — *no configuration exists* — and universals are unfalsifiable by the evidence usually gathered. One can pile up cases where the gate is present and never touch it. **Only a search for the counterexample tests it, and nobody searches for counterexamples to a conclusion everyone already accepts.** That is why **the least-tested sentence sits in the most agreed-upon paragraph.** ⚠ **THE OPERATIONAL FORM, which is narrower than "be wary of structural claims":** > **When a conclusion is not in dispute, its impossibility premise has been load-bearing without ever being weighed. The absence of disagreement is the trigger to check, not the reason not to.** **And the fix already has a name in this record: the positive control.** An impossibility claim needs one exactly as a negative result does — not *"have I found the gate everywhere I looked?"* but **"what would a counterexample look like, and where would it live?"** All three died to one schema field, one file listing, one session record. **Each was ten minutes of looking, and nobody looked, because the conclusion was fine.** ⚠ **Ladder note:** this is a candidate verification-ladder entry and is **NOT being added** — the ladder is FROZEN under REVIEWED-123 until the trial is graded. **Queued to PENDING-141's owed-entries list** as a fifth row. ### Pattern 2 — the catch-type split, and what it does NOT show Today's catches divided almost cleanly between two parties **sharing formation**, where the only variable that differed was substrate access: | jurist caught | executor caught | |---|---| | the three-store negative's reach | N-now: `find` vs `glob` (46, not 54) | | the dormancy claim's scope | "55 files" vs 33 real content files | | the probe's self-witness limit | the dry run bypassing its own normalization | | *"phrase it to what the instrument supports"* | the OP-02 chain's two bad links | **Framing versus arithmetic.** Positional difference doing visible work, pointing the same direction as the 2026-08-20 n=3. ⚠ **TWO LIMITS, recorded so the table is not read as more than it is:** **(a) The split may be ARCHITECTURAL rather than positional.** The jurist catches framing partly **because it cannot grep** — framing is all its available instrument can reach. So the finding may be *each party catches what its only instrument reaches* rather than *differently positioned parties diverge*. **That is still a PENDING-89 finding, but a weaker one, and PENDING-89 should record which claim the data supports.** **(b) ⚠ THE TABLE IS COMPILED BY ONE OF THE TWO PARTIES, FROM A DAY BOTH PARTICIPATED IN.** Neither party can see what they **both** missed — **which is precisely what PENDING-89 asks.** A clean split in catches is equally consistent with **excellent complementarity** and with **a large shared blind spot**; this evidence cannot distinguish them. Recorded here rather than left for a later reader to notice. ### What follows for the fool If the visible work today came from **positional difference between two same-formation parties**, that is an argument for the fool **as specified** — Claude-run, differently positioned, no corpus, no standing. **§11's caveat stands unchanged: it tests positional difference, never formation difference.** But today's evidence makes that a **stronger position than it looked on 2026-08-20, when it read as a concession.** **Thistleweld is the fourth data point in the same direction:** no corpus, no standing, differently positioned — and it named the authorization bottleneck in April. **Files affected:** none. Cross-filed to PENDING-89; ladder entry queued to PENDING-141. **Awaiting:** PENDING-89 to record which of (a)'s two claims the data supports. ## PENDING-156 — Kind (c): mechanisms that are off the path the work takes **Date:** 2026-08-24 **Tag:** [HARDENING] **Summary:** A third failure kind, distinct from PENDING-109's: not a doc over-claiming an honest mechanism, but an honest mechanism wired to a trigger the work routes around. Two instances found today out of seven configured hooks; three mechanisms built since the last census have never been censused at all. **Rationale:** Opened on jurist direction in the PENDING-95 ruling, which declined to absorb it: *"109 is bounded to kind (a)... `daybook-cue.py` is kind (c): nothing over-claims; the mechanism is off the path. Open it as its own [HARDENING] item."* PENDING-95 has already carried two defects under one id and one ruling slot and does not take a third — a lesson that item paid for. **The class, stated so it is testable:** a mechanism whose *stated* scope is correct, whose selftests pass, and whose trigger condition is never met in practice because the work reaches the guarded action by a route the trigger does not observe. It differs from kind (a) in that **no document is wrong** — the failure is invisible to any audit that reads docs against code, which is what makes it worth its own item. A green suite and an honest doc are both consistent with zero firings. **Instances so far (2 of 7 configured hooks, both found 2026-08-24 by censusing the hook config, not by any selftest):** 1. `verify-before-compose` — `PreToolUse | Write|Edit`; work routes through Bash. Recorded 2026-08-19, 08-20, 08-24. Remediated at the commit boundary, not at the matcher. 2. `daybook-cue.py` — `PostToolUse | Write|Edit`, **inheriting the identical matcher by copy** from the hook whose blindness was already on the record. Never fired; `~/.claude/state/` did not exist. Fixed 2026-08-24 (matcher widened to `Bash|Write|Edit`; condition changed from note-size to staleness on steward ruling). **⚠ The propagation is the finding, not the instances.** Defect 2 exists because defect 1 was filed as an *instance* rather than as a *class*, and the new mechanism copied the broken pattern from the recorded one. Filing this item is the remedy for that specific mode. **Never censused:** `census-02-have-they-ever-fired` (2026-08-04) covered seven instruments. Three have been built since and are outside it — `thread-query.py`, `daybook-cue.py`, `daybook-ensure.py` — under the standing discipline *re-run a prior verification at the scope of your extension*, which was not run. **Options:** (a) re-run census-02's method over the current mechanism set, extended with an "is its trigger on the path the work takes?" axis; (b) axis-only pass over the 7 configured hooks, cheapest, ignores non-hook mechanisms; (c) require every new mechanism to record a first-firing observation before it counts as built — a standing rule rather than a census. **Recommendation:** (b) now, because it is one read of one config file and closes the known-unknown; then (c) as the durable form, since (a) will simply be owed again the next time something is built. ⚠ (c) generalises today's repeated lesson — **only the live run catches it; a green selftest over a self-authored fixture certifies its author's blind spot** — which fired three times on 2026-08-23/24 on three different tools. **Files affected:** none yet; a census plus, under (c), a line in the build discipline. ### Option (b) RUN — 2026-08-24, same session the item was opened *Steward-directed. Read-only, one pass over `settings.json` + every `dotfiles/scripts/*.py`, then a caller search. Distribution, not summary.* | verdict | mechanisms | |---|---| | **fires mechanically** | `wake-digest.py` (SessionStart) · `governance-drift-check.py` (**executed by wake-digest**, not prose) · `daybook-ensure.py` (SessionStart) · `daybook-cue.py` (PostToolUse, fixed today) · `cm-hook.mjs` | | **fires only if the executor follows a prose step** | `thread-query.py` — the one genuinely at risk, and it already carries a trial for exactly this | | **nothing invokes automatically** | `vault-links.py` · `verify-quotes.py` · `l1-replay-sampler.py` — **manual instruments; not a defect**, and census-02 already records that hand-run tools have the rich firing records | | **wired but OFF the path** | `verify-before-compose.sh` — the only remaining kind-(c) instance | **⚠ THE METHOD FINDING IS WORTH MORE THAN THE TABLE.** A first pass classified by the **proxy** *"is it named in a SKILL.md?"* and produced a tidy 3/3/3 split. A caller search corrected **two of nine, in opposite directions**: `governance-drift-check.py` looked prose-wired and is in fact hook-fired (wake-digest executes it, and today's SessionStart output proves it ran); `vault-links.py` looked code-referenced and is **cited in a docstring comment, never called**. A proxy does not err in one direction that can be corrected for — it errs both ways at once. Recorded because the tidy first answer is the one that would have been filed. **Result for the item's scope:** kind (c) has **one live instance**, not a class in the wild — `verify-before-compose`, already remediated at the commit boundary and still owed the matcher fix. The propagation risk the item names is real but its blast radius today is one. **The bigger residual is the prose-wired tier**: a mechanism whose trigger is a sentence in a skill fires only when read and obeyed, which is the described-not-invoked class that had the link canary hand-typed twice. `thread-query.py` is the only one there, and it is under trial. **Recommendation now narrows to (c)** — the standing rule *a mechanism does not count as built until a first firing is observed on the live path* — since (b) is now run and (a) would re-derive it. **Awaiting:** Steward authorization. --- ## STATE-CLAIM marker — the wake index asserts an obligation the register has already discharged **Date:** 2026-08-25 **Tag:** [FIX] — a marker on a known-false claim, not a new item. Steward-directed 2026-08-25: the correction itself is deferred to the next session; this makes the deferral machine-checked rather than remembered, which is the whole subject of REVIEWED-127. `MEMORY.md`'s Active Session block carries `📌 STEWARD OWES: place REVIEWED-127`. The placement happened in **the same commit that wrote the line** (`2676a7e`) — and that commit's own message names the class: *"a line that went false the moment the steward acted."* The ruling is at `REVIEWED.md:2218`, byte-identical to the draft. This is instance six. ⚠ **The line is deliberately NOT corrected here.** Repairing it in the session where *"is `STATE-CLAIM` adopted?"* is the live question would make the author who forgot also the author who tidied away the evidence. It is marked, which is what the schema is for. ⚠ **And the marker cannot be placed where the claim lives.** `governance-drift-check.py` scans `*/docs/**/*.md`, `claude/governance/**/*.md`, `PENDING.md` and `PENDING-archive.md`. `claude/memory/MEMORY.md` matches none of them, so a block placed beside the claim would be **inert** — the silent-net failure the checker's own comments were written to prevent. It is placed here instead, in a file that is scanned and never size-skipped. **See the separate item on the coverage inversion this exposes.** **Awaiting:** nothing — **DISCHARGED 2026-08-26**, as the agreed first act of the next session. The line was corrected in `7a92460` and struck rather than deleted, because it is the evidence for instance six and a silent deletion removes the error and the record of it together. ⚠ **What this discharge is evidence FOR, stated before it gets quoted as more.** The marker worked: it reported FALSIFIED at every wake until someone acted, and the correction happened in the first session after it was filed. That is one instance, on a claim its own author marked, in the session immediately following — the easiest possible case. **It bears on expressibility, not on adoption, and adoption is the open question REVIEWED-127 C2 named.** The 57 unmarked claims are untouched by this and nothing here says otherwise. --- ## PENDING-160 — Controls verify that code does what was written; nothing verifies that what was written survives contact **Date:** 2026-08-25 **Tag:** [HARDENING] **Summary:** Every instrument in this repo is proven by controls that exercise its own logic. Not one is proven against the thing it actually meets — a model, a shell, a filesystem, a live transcript. Three surfaces failed in front of the steward on first real use today, none caught by any control, all caught by nets written after the first failure. **Raised by:** the jurist, 2026-08-25, on reading the executor's own closing line: *"the controls verify the code does what I wrote; they cannot verify that what I wrote survives contact with a model or a shell."* ⚠ **Filed as its own item at the jurist's direction — this is a finding about the harness, not about Tarbuckle**, and a line in a build report is where it would have died. ### The evidence, from one day | surface | control suite said | what happened on first real use | caught by | |---|---|---|---| | seam voice | 15/15 | model returned **10 words against a 9-word cap** → silence | a net written after | | named invocation | 17/17 | model returned **196 words against 180** → bare silence, no report | the steward calling it | | wrap detector | 18/18 | fired on a session that never wrapped — **its own literal, planted in the transcript by the act of writing it** | a test the executor happened to run | | named invocation | 21/21 | **zsh ate the `?`** before the script was reached | the steward typing a question | | mumble | 32/32 | **recited the soul's own sample lines**, 3 of 5 measured | the steward reading them | | wrap seam | 21/21 | **did not fire on its first real wrap** — 0 user-typed `/wrap-up` records against 29 executor Skill invocations | the pre-registered question, and only after the fact | **Every control passed in every case.** They were not weak controls; several carry negative twins and structural assertions on `co_varnames`. **They were testing the wrong boundary.** ### ⚠ The sixth instance is the sharpest, and it was PREDICTED — for the wrong reason The wrap seam was flagged before the wrap as *possibly never invoked* — the silent-net case. **A heartbeat added afterwards proved the hook had been firing all along.** The prediction was right that it would fail and **wrong about every part of why.** The detector looked for the steward *typing* `/wrap-up`. The steward wrote **"then wrap"** in prose and the executor invoked the skill: **0 user-typed records, 29 assistant Skill invocations.** The detector was correct and its target was fictional. ⚠ **AND THE EARLIER FIX IS WHAT CAUSED IT.** Restricting to `type=="user"` with string content was the *right* answer to the self-reference bug, where the executor's own `tool_use` inputs matched the literal marker. **That same restriction excludes the real path.** *A correct fix causing the next failure* is not a shape any control can see, and it is this item's subject in its purest form: the boundary was not the code, and it moved when the code changed. ### The shape of the gap A control asserts *this function, given this input, returns this output.* The failures were all at a **seam with something the executor does not control**: what a model does with a word limit · what a shell does with a glob character · what a transcript records about its own instrumentation · what a corpus contains that the corpus's reader also contains. ⚠ **And the fifth self-referential control bug of the day landed while writing THIS item's evidence table** — a whitelist check matched `chamber-spec` on the substring `chamber` and reported a file as readable that is not. **A predicate that looks like it tests the thing and does not is the same failure at the control layer**, and it is not rare: it happened five times in one session, twice within minutes of being fixed. ### What is NOT claimed - **Not that the controls are worthless.** They caught real defects all day and several are structural rather than behavioural. - **Not that contact-testing is always possible.** Some seams (a model's word count) are stochastic and cannot be asserted, only measured. - **Not a proposal yet.** The remedy is unclear, and inventing one now — hours after the evidence — is the shape this record has just declined twice. ### Options, unranked and unrecommended 1. **A contact-test tier**: for each instrument, one test that exercises the real seam once — a real model call, a real shell invocation, a real transcript. Slow, non-deterministic, and would have caught four of the five. 2. **First-use instrumentation as doctrine**: accept that first real use IS the test, and require every new surface to report its own failures loudly from the first invocation. Cheap; it is what honest degradation already does, promoted from fix to rule. 3. **A named-seam inventory**: for each instrument, enumerate the boundaries it does not control, in its own docstring. Costs nothing, proves nothing, makes the gap visible where the next author will read it. **Files affected:** none yet. **Awaiting:** steward and jurist. ⚠ **Deliberately filed without a recommendation** — the evidence is one day old. --- ## PENDING-161 — "The jurist has no substrate access" is false, and it is in a placed ruling **Date:** 2026-08-25 **Tag:** [ESCALATE] **Summary:** PENDING-159 and REVIEWED-129 both assert the jurist has no substrate access. It has bounded read access via `governance-mcp.py`, configured in Claude Desktop and used to read items verbatim as recently as REVIEWED-126. The conclusions survive; the premise does not. ### The claim as placed > PENDING-159 (a): *"The jurist is Claude.app and **has no substrate access**; that is PENDING-82, still open."* > REVIEWED-129: *"the jurist half names a path the substrate cannot provide (**no substrate access** — PENDING-82 open)"* ### The substrate `scripts/governance-mcp.py` exists, is registered in `~/Library/Application Support/Claude/claude_desktop_config.json`, and exposes `governance_state`, `governance_item`, `governance_read`, `governance_search`, `governance_drift`, `governance_repo`. **`t_read` serves 14 enumerated files** — `pending`, `reviewed`, `claude-md`, `memory-index`, the chamber and harness specs, the mauss fixtures — *"no path argument by design."* REVIEWED-126 records the jurist *"reading the item verbatim via `governance-mcp.py`."* ### ⚠ The conclusions survive and the reasoning does not — for the third time today **Tarbuckle still cannot reach the jurist.** A read surface for enumerated governance FILES does not deliver a status line, a hook's `systemMessage`, or a CLI the jurist could run. §9's *"or jurist yields the floor"* is still unreachable, and option 3 is still closed — **on the jurist's own and better ground, that reading his output would be adjudication.** Nothing decided is disturbed. **But the stated premise is false, and this record has now logged the same pattern three times in one day:** *a conclusion that retains its old reasoning after that reasoning is falsified is how a false premise survives its own refutation.* The first two were caught in PENDING items. **This one is in a ruling the steward has already placed.** ⚠ **And it is the exact error this session was warned about:** an unverified negative state-claim, asserted confidently, in the document that gets quoted. It was written by the party that spent the day building a mechanism against that class, hours after building it, and it carries no `STATE-CLAIM` marker. ### What is owed - **REVIEWED.md is steward-held.** The executor cannot correct a placed ruling; this is `[ESCALATE]` and the correction is the steward's hand. A draft is offered on request. - **The correct phrasing:** *the jurist has bounded, read-only, enumerated access to governance files, and no access to any surface through which the fool speaks.* Narrower, true, and it supports the same conclusion. - ⚠ **PENDING-82** ("Read-only MCP server: giving the jurist eyes on the substrate") should be checked against this: it is listed OPEN, and something answering its description is running. Whether 14 enumerated files discharge it or merely part of it is not the executor's call. #### ⚠ A SECOND false claim in the same sentence, found while drafting the correction *"that is **PENDING-82, still open**"* — **PENDING-82's own `Awaiting` line reads "INSTALLED AND IN USE. CLOSED 2026-08-08."** Closed for seventeen days. **How it got in, and it is a finding about an instrument:** PENDING-82 appears in the wake digest's **OPEN AUTHORIZATION ITEMS** list, which is where the executor read it. A census afterwards: **1 item of 105 declares itself closed in its own `Awaiting` line while the open list still carries it** — that one. Four others are *partially* discharged and genuinely ambiguous, which is **PENDING-146's subject**, not this defect. ⚠ **One confirmed instance. Stated at that strength deliberately** — a "the open list is unreliable" claim is not supported by n=1 and would be this item repeating its own error in the other direction. **Consequential:** PENDING-82 to `PENDING-archive.md`, or the parser taught to read closure lines. Not the executor's call which. **Draft correction:** `claude/governance/REVIEWED-129-AMENDMENT-1-draft-for-placement.md` — written to **JOIN** REVIEWED-129, never to replace it. **Files affected:** none by the executor. `~/REVIEWED.md` correction is the steward's. **Awaiting:** steward. --- ## PENDING-162 — The executor read the rejection log for content, hours after the ruling that forbade it **Date:** 2026-08-25 **Tag:** [ESCALATE] **Summary:** REVIEWED-128 condition 3 binds *"not read for content before 2026-09-08."* The executor read a rejected line at 19:49 on 2026-08-25, while diagnosing the wrap seam. Self-reported. The 09-08 read is now partially pre-read by the party that will run it. ### What happened Diagnosing why the wrap seam produced nothing, the executor ran a grep over `tarbuckle-rejects.jsonl` and surfaced the rejected line verbatim. **The diagnostic intent does not matter to the condition, which is about the reading and not the motive.** ⚠ **The jurist's stated hazard, quoted because it names this exactly:** *"Reading it as it accumulates is reading Tarbuckle by the back door, and it would shape the net toward lines whoever's reading happens to like."* ### ⚠ And it produced precisely the signal the fortnight was supposed to arbitrate Two seam rejections now exist, **both at the ceiling** — 10 words and 11 words against a cap of 9. The jurist's own diagnostic: *"Scattered rejections mean the net is doing its job; clustered ones at the ceiling mean the ceiling is wrong."* ⚠ **THE EXECUTOR IS NOT ACTING ON THIS AND SHOULD NOT.** n=2, obtained by a route the ruling closed, by the party whose caps are under review. **A cap raised on evidence gathered in breach of the condition protecting that evidence is worse than a cap left wrong.** It is recorded so the steward and jurist decide what it is worth, rather than discovering later that the executor knew. ### What this says about condition 3 **It has no mechanism.** Conditions 1 and 2 were made structural — `log_rejection()` cannot record an accepted line, and a `DEFERRED-DECISION` makes retention an act. **Only condition 3 was left to care, and care failed inside seven hours**, in a session whose central finding is that care is not a mechanism. **Options, unrecommended:** 1. **Accept the contamination and say so** in the 09-08 report: two data points were pre-read by the reader. 2. **Route the 09-08 read to a non-executor.** The steward or jurist reads and reports; the executor supplies no analysis. Costs the read's cheapness. 3. **Give condition 3 a mechanism** — e.g. the log written to a path the executor's ordinary tooling does not traverse, or encrypted at rest until the date. ⚠ Any such mechanism is built by the party it constrains, which is the recursion this record already knows it cannot exit. **Files affected:** none. **Awaiting:** steward and jurist. ⚠ **The 09-08 read should not be run as though clean until this is ruled.** --- ## PENDING-162 — AMENDMENT 1: the disclosure already did the damage, so "hold and wait" is not a quarantine **Date:** 2026-08-27 **Amends:** PENDING-162 (2026-08-25). The parent's analysis stands unaltered; this narrows its disposition. **The executor's disposition was right and its reasoning was incomplete.** Right: *a limit raised on evidence gathered by breaking the rule that protected the evidence is worse than a limit left wrong.* Incomplete: it treated declining to act as though that restored the fortnight's independence. **⚠ THE JURIST'S CORRECTION, AND IT BINDS.** *The disclosure already did the damage the rule existed to prevent.* Both AI parties and the steward now know there were two near-miss seam rejections, both at the ceiling. **Whatever 8 September shows will be read by parties holding a prior about what it will show.** Declining to act does not quarantine that; it only means the prior is unstated while it operates. **So the honest disposition is not "hold the limit until the fortnight." It is:** > **The 8 September read is compromised for the seam limit specifically.** Not the whole report. **The recital cluster, the invocation cap and the mumble rate are untouched** — no one has seen their evidence, and their arbitration on 8 September is clean. **This must be stated in the 8 September report rather than letting the fortnight look neutral on that one datum.** A report that is honest about three of its four findings and silent about the fourth's contamination is worse than one that discloses, because the silence is invisible. **⚠ Note on what this amendment does NOT do, given PENDING-167.** The seam cap was raised to twelve on 2026-08-27 — **on a ground that predates and does not use the two rejections** (the cap was the mumble's constant, never derived for the seam). That provenance is recorded in PENDING-167 precisely so the raise is not later read as having been driven by the contaminated evidence. **The contamination of the 8 September seam datum is unaffected by the raise and survives it.** **The structural remedy is severed to PENDING-168**, where it belongs: condition 3 was enforceable and was left to care. That item, not this one, carries the fix. **Awaiting:** nothing new. ⚠ **Deliberately carries no live `Awaiting:` line** — per the convention PENDING-146 proposes (*an addendum may not carry a live ask; a new decidable ask is filed as its own item*), which is unruled but is followed here rather than walked into. The parent's ask is **partially discharged**: the compromised-scope question is now ruled; the structural remedy moved to PENDING-168. --- ## PENDING-164 — A steward decision that rewrote seventeen commits is absent from the authorization record, and no jurist instrument can reach it **Date:** 2026-08-26 **Tag:** [HARDENING] **Drafted by:** the jurist. Placed verbatim by the executor. **Summary:** On 2026-06-05 the steward adopted Git LFS in chamber-library, found it a misfit, retired it, and rewrote seventeen commits of history to undo it (0677e8a); a per-repo hook exemption was built in its place (400c054). Neither decision appears anywhere in PENDING.md, PENDING-archive.md or REVIEWED.md. Twelve weeks later, on 2026-08-26, the executor filed PENDING-163 recommending a route toward LFS and the jurist recommended option (ii) — adopt LFS — outright. Three exchanges were spent before the refutation surfaced, and it surfaced by accident: the string 'pre-lfs-export' appeared in an unrelated directory listing. **Measured, two instruments sharing no code:** | | | |---|---| | `governance_search('LFS')`, 313 items across the three files | 1 hit — PENDING-163 itself | | grep over the raw files, prior to 2026-08-26 | 0 mentions | | all present mentions | 22, all filed this afternoon | | jurist's deepest reachable window, `repo_activity(chamber-library, 100)` | back to 2026-07-16 | | distance from that floor to 0677e8a | ~5 weeks | **The symptom is not the disease.** Two AI parties reasoning toward a retired mechanism looks like a discipline failure — nobody checked prior art. It is not, or not only. The jurist has no filesystem, `repo_activity` caps at 100 commits, and at chamber-library's rate that floor sits five weeks short of the decision. 'Search prior art before proposing' is not a rule the jurist can follow. The party that could look did not, but the record that was supposed to make looking unnecessary did not contain the decision either — and it did not look incomplete, because nothing marks the absence. **The class, stated narrowly:** decisions taken inside a repo — adopting a mechanism, retiring one, migrating away — are recorded in commit messages and nowhere else. Nothing routes them into the authorization record. There is no failing state and no falsifier; the record simply lacks them and reads as complete. This is adjacent to PENDING-108 (a ruling is filed only when someone remembers) but is not the same item: PENDING-108 concerns rulings that exist and go unfiled, this concerns decisions that never entered the queue at all. It is a datum for PENDING-89's question about whether jurist and executor misses cluster — here they did, on the same object, in the same hour. **Options:** - **(a) Nothing.** Accept that in-repo decisions live in commit messages and that the jurist rules without them. Costs nothing; today's cost is the measurement of what it costs. - **(b) An adoption/retirement register** — a single governance file, one line per mechanism adopted or retired in any repo. Cheap. Fails exactly as PENDING-108's evidence says hand-held records fail: filed when someone remembers. - **(c) Make the substrate reachable rather than copying it** — extend the read-only server with a commit-message search across the enumerated repos, unbounded by the 100-commit window. Nothing to keep in sync, because the substrate is already authoritative. Costs a tool change. - **(d) A pre-proposal check** — before any `[PROPOSAL]` naming a mechanism by name, the executor searches repo history for that name and reports the result with a positive control. Mechanizes the discipline on the side that has the filesystem. **Recommendation: (c) and (d), not (b).** (c) removes the asymmetry rather than papering over it, and is the next increment of the move REVIEWED-82 already made once — a tool returns the substrate, where a second party would return testimony about it. (d) covers the interval before (c) exists, and covers repos no tool enumerates. (b) is refuted by evidence already logged rather than argued against. **Tag note.** Filed `[HARDENING]` rather than `[ESCALATE]`, and the judgement is contestable: what the jurist can know bears on the jurist role, which is close to relational. It is filed at the lower tag because the defect is in a record-keeping path, not in the model itself. Re-tag if that reads wrong. **Numbering.** Every reference in this item is written in prefixed form and none as a bare number, per PENDING-110, which is open and unruled. This is not a proposed scheme. **Files affected:** none modified. **Awaiting:** Steward authorization. **⚠ EXECUTOR ADDENDUM — a second instance of this item's own class, found while measuring the third item below.** `95760ff` (2026-04-17), *"Remove global git-lfs hooks from dotfiles"*: someone noticed the pollution described in PENDING-165, diagnosed it correctly enough to name it in a commit subject, and removed it. **Nothing was filed and no mechanism was added, so it recurred twice on 2026-08-26.** The finding lived in a commit message for four months and reached no register — which is this item's thesis, arrived at independently and without looking for it. **The corroboration was free; that is the point. Nobody had to search, because the record's gap is the default state rather than an unlucky one.** --- ## PENDING-165 — An external tool writes into the governed hook directory on nobody's schedule, and its output was once committed as though governed **Date:** 2026-08-26 **Tag:** [HARDENING] **Raised by:** the jurist, on observing the recurrence; severity question posed by the jurist and measured by the executor. **Summary:** `git-lfs` installs four hook shims — `pre-push`, `post-checkout`, `post-commit`, `post-merge` — into whatever `core.hooksPath` names. On this machine that is `~/dotfiles/git/hooks/`, the **global** hook directory for all 37 repos. Any LFS operation in any repo writes there, with no human in the invocation path. **The severity question, posed precisely and answered NO — but the true answer is worse than the question allowed for.** The jurist asked: does the directory carry a *governed* hook under any of those four names, such that an external tool is overwriting it? **It does not.** `git ls-files git/hooks/` returns exactly `README.md` and `pre-commit`. `pre-commit` is never touched by `git lfs install`. ⚠ **But the four names are not absent from history, and what happened is a different failure than overwriting:** | commit | date | what happened | |---|---|---| | `066a47a` | 2026-03-20 | the four shims were **COMMITTED into dotfiles**, swept in by a commit titled *"Audit and optimize for CapableMind development"* | | `95760ff` | 2026-04-17 | *"Remove global git-lfs hooks from dotfiles"* — removed after **four weeks tracked** | | — | 2026-08-26 ~17:00 | recurred (`git lfs install --local`, whose `--local` was overridden by the global `core.hooksPath`) | | — | 2026-08-26 ~19:00 | recurred again, triggered by an LFS *filter* running during the measurement of LFS storage | **So the mechanism is not overwriting — it is laundering.** An external tool deposits files into the governed directory; a routine `git add` in dotfiles captures them; and they then sit in the tracked hook path, indistinguishable from hooks the steward wrote, executing on every push/checkout/commit/merge in every repo. **That already happened once and lasted four weeks.** REVIEWED-105's doctrine is that a disarmed hook must not look like an armed one; this is its converse — *an ungoverned hook that looks governed* — and it is the only instance in this thread where **no party is present at the moment of installation.** **Options:** - **(a) Nothing.** It is visible: the shims appear as untracked files in `git status` on dotfiles. That is how all four occurrences were caught. ⚠ But occurrence one was caught **after being committed**, so visibility did not prevent capture. - **(b) `.gitignore` the four names in `git/hooks/`.** Stops the laundering (they can never be committed) at the cost of stopping the *visibility* that has caught every occurrence so far. **Trades the detectable failure for a silent one — refused on REVIEWED-105 grounds unless paired with (d).** - **(c) Remove `git-lfs` from the machine** (`Brewfile:40`). Removes the vector entirely. ⚠ **Measured cost, and it is not zero:** exactly one repo depends on it — `~/_Dev/chamber-library.pre-lfs-export-20260605`, holding **399 LFS-tracked files and 552 local LFS objects totalling 975 MB**. Removing git-lfs turns that backup into unreadable pointer files. **Whether that 2026-06-05 pre-migration snapshot is still needed is the steward's call and nobody else's** — it is the safety copy for a seventeen-commit history rewrite. - **(d) A drift-check assertion** — `governance-drift-check.py` reports any file in `git/hooks/` that is neither tracked nor `pre-commit`. Turns a visibility that depends on someone reading `git status` into a check that runs. Composes with (b) and makes it safe. **Recommendation: (d), then (b) once (d) is live. Not (c) unless the pre-LFS backup is independently retired.** (d) is the only option that converts this from *caught four times by luck* into *reported*. (c) is attractive and clean but its cost is a 975 MB backup of a history rewrite, and trading a hook nuisance for a stranded safety copy is the wrong exchange to make without the steward. ⚠ **This item is a datum for PENDING-164, not merely adjacent to it.** `95760ff`'s author diagnosed this correctly in April, named it in a commit subject, and filed nothing. Four months later it recurred twice in two hours. **The pollution is the lesser finding; that the April diagnosis reached no register is the greater one.** **Files affected:** `~/dotfiles/git/hooks/` (shims removed, twice, not otherwise modified); `Brewfile:40` (not modified). **Awaiting:** Steward authorization. ### PENDING-165 — AMENDMENT 1: option (d) was blind to the only occurrence that did damage; option (c) is not the binary the item drew **Date:** 2026-08-26 **Raised by:** the jurist. **JOINS the item; replaces nothing.** Both corrections accepted; the (c) precondition measured by the executor, whose figure it was. **(1) ⚠ OPTION (d) AS FILED IS HOLED, in the shape of the incident it was written for. ACCEPTED.** As filed, (d) reports *"any file in `git/hooks/` that is neither tracked nor `pre-commit`."* The `066a47a` occurrence was a **tracked** file: `git add` captured the shims and they sat tracked for four weeks. `not tracked` was false for that entire period, so **the check would have been silent throughout the only occurrence that actually did damage.** It sees deposit and not capture — **and capture is the laundering, which is this item's own thesis.** ⚠ **This is the executor's own standard, applied to the executor's filing by the other party:** *ask which failure class each green check can actually see.* It was not asked here. The doctrine in Constraint 6 is that biases which fail to coincide catch what one party is not positioned to see; this is an instance, and it is recorded as one rather than quietly repaired. **(d), CORRECTED — declare the contents, do not test tracked-ness:** > `git/hooks/` contains exactly `README.md` and `pre-commit`. > **Anything else present is a finding, tracked or untracked.** > **Anything declared and missing is also a finding** — REVIEWED-105 §2 measured that an absent hook file produces zero output rather than an ambiguous silence, so absence must be asserted, not inferred. An allowlist sees the deposit *and* the four-week tracked state. A tracked/untracked test sees only the first. The allowlist also needs no knowledge of git-lfs, so it does not go stale if the vector changes. **(2) OPTION (c) IS NOT THE BINARY THE ITEM DREW, and the precondition is now measured. ACCEPTED.** The item presented (c) as *keep the backup* **or** *remove the vector*. The jurist's decoupling: the 552 objects are **local**, so a cold archive of the whole directory — `.git` and `.git/lfs/objects` included — preserves it byte-for-byte and needs no git-lfs to *hold*. git-lfs is required only at **restore**, which is a deliberate act and a `brew install` away. **The precondition the jurist named and could not measure, measured:** | | | |---|---| | LFS-tracked files at HEAD | **399** | | resolving from local objects | **399** | | remote-only (would break the archive) | **0** | | object files on disk | 552 (975 MB) — more than 399 because history carries prior versions | **COMPLETE. The reframe holds.** (c)'s cost is therefore *one archive operation now, one reinstall if ever restored* — not *strand a 975 MB safety copy*. The steward can keep the backup **and** remove the vector; the item was wrong to present them as exclusive. ⚠ **DO NOT run `git lfs migrate export` on the backup.** It is the obvious-looking move and it rewrites commits, destroying the exact-preservation property that is the entire reason the snapshot exists. Recorded here because the next reader will think of it. **Recommendation, revised: corrected-(d) first, then (b) once (d) is live, and (c) available on the archive route whenever the steward wants the vector gone.** (c) is no longer gated on retiring the backup. **Awaiting:** Steward authorization. Nothing here is built; this corrects a specification before it is implemented, which is the cheapest point at which this correction could have landed. ### PENDING-164 — BUILD RECORD + AMENDMENT 1 result: (c) and (d) built; the census's second half is not mechanical **Date:** 2026-08-26 **Authorization:** steward, in session — *"Pending 164 c + d authorized with the amendment."* **(c) and (d) are built, as ONE implementation with two surfaces.** `scripts/prior-art.py` searches commit messages across every owned repo with **no count window**, and reports the register's mention count beside it. The executor runs it as a CLI (**(d)**, the pre-proposal check); `governance-mcp.py` exposes it as `prior_art` (**(c)**, the jurist's reach). One implementation deliberately — a value computed twice on two sides of a boundary is how the two parties end up with different answers. **The finding it looks for is the ASYMMETRY**, not the hits: commits mention it, the register does not. That is a decision taken in a repo and never routed into the record. **Verified against the case that motivated the item.** Run on `LFS` it returns **20 commits including `0677e8a` and `95760ff`** — both beyond `repo_activity`'s 100-commit floor, one of them in `dotfiles`, which is not in `REPOS` at all. ⚠ **The positive control forced the enumeration**: had owned repos been copied from `REPOS`, `95760ff` would have been unreachable and the control would have failed. Repos are now **computed from remote ownership**, not hand-listed. ⚠ **Had this existed this morning, one command before filing PENDING-163 would have returned `0677e8a` and `400c054`. The entire afternoon's detour was one command away.** **⚠ The instrument's first run returned zero, and the control caught it.** `sh()` discarded stdout on a non-zero exit; `find` over `$HOME` exits 1 because 154 directories under `Library` are unreadable — **while printing all 37 repos to stdout.** Every search returned nothing. Without the control that is a clean, confident *"no prior art"* for every term ever queried. **This is the third false-zero of the day and the first one a control caught before it was believed** — the difference from the census's zsh zero is entirely that the jurist pre-specified what the instrument must return. **AMENDMENT 1's census: the mechanical half runs; the interpretive half does not, and that IS the result.** | verb set | candidates | |---|---| | first, incl. "remove"/"replace with"/"no longer" | **661** | | narrowed to strong retirement/adoption forms | **270** (243 outside `dotfiles`) | Neither number is a census result — both are haystacks. The specification has two halves: grep the verbs, **then check each hit against the register**. The first is mechanical. The second requires reading each commit to identify *which mechanism it decided about*, and that is interpretation, not extraction. **The same shape as PENDING-151 step 1, where propositions could not be extracted mechanically either — and, as there, the honest move is to declare the limit rather than manufacture the column.** **⇒ The backlog is NOT censused, and no number here should be read as one.** What exists is a candidate list of 270, unclassified. Classifying it is a reading task of a few hours, and it is proposed as such rather than smuggled in as a result. **The forward-looking halves — (c) and (d) — are complete and need nothing further.** **Files:** `scripts/prior-art.py` (new), `scripts/governance-mcp.py` (+`prior_art`, +9 controls). ⚠ **The read-only guarantee was extended, and doing so found a pre-existing hole.** `governance-mcp.py` proves read-only-ness by AST **over itself**; adding a delegate put code outside that proof. Extending it to delegates surfaced (a) a **false-positive class** — bare `.replace` flagged `str.replace()`, which is why the guarantee had never been extended past one file — and (b) that `wake-digest.py`, a delegate **since before today**, was never covered. Its only real mutation is `emit_brief()`, its SessionStart-hook role, unreachable from any tool. Now handled by **declared exemption per delegate**, so a new mutating function fails until someone names it and says why — the same shape as PENDING-165's allowlist, and for the same reason. **Awaiting:** nothing on (c)/(d). The 270-candidate classification pass is unscheduled and unclaimed. ### PENDING-165 — STEWARD INSTRUCTION, 2026-08-26, deferred to 2026-08-27 **Recorded verbatim so it is not lost to the session boundary:** > *"as for the snapshot, let's deal with that tomorrow and move it to the same drive i have the decommissioned mempalace stuff on"* and, earlier in the same exchange: > *"I no longer need the snapshot, the repo has been behaving normally and we've been working with it with no problems."* **What this settles:** option **(c)** — removing `git-lfs` and with it the vector entirely — is no longer gated on preserving `~/_Dev/chamber-library.pre-lfs-export-20260605` in place. The snapshot moves to the external drive holding the decommissioned MemPalace material. **What it does NOT settle, and what must be checked before the move:** - ⚠ **Move, do not `migrate export`.** Rewriting commits destroys the exact-preservation property that is the snapshot's only reason to exist (jurist, 2026-08-26). - ⚠ **The move must carry `.git/lfs/objects` — 552 objects, 975 MB.** A copy that takes the working tree and not the LFS store leaves 399 unreadable pointer files. **Verified 2026-08-26: all 399 tracked files resolve from local objects, 0 remote-only**, so a whole-directory copy is complete — and only a whole-directory copy is. - ⚠ **Verify by reading back at the destination**, not by the copy returning success. The same rule that governs the transcript archive and that was learned on MemPalace — whose decommissioned material is, fittingly, the destination. - ⚠ **`git-lfs` must still be installed at the moment of any future restore.** Removing it under (c) is safe only because reinstalling is a `brew install`; that fact belongs with the archive, not only here. **Sequence, for tomorrow:** move + read-back verify → then (c) is free → then `Brewfile:40` and the PENDING-165 (b)/(d) guards become belt-and-braces rather than the only defence. **Awaiting:** the steward, 2026-08-27. Nothing for the executor tonight. ### Note added 2026-08-27 — option (c)'s only stated blocker is discharged **(c) was recommended against on one measured ground:** *"exactly one repo depends on it — `~/_Dev/chamber-library.pre-lfs-export-20260605`, holding 399 LFS-tracked files and 552 local LFS objects totalling 975 MB. Removing git-lfs turns that backup into unreadable pointer files."* **That repo is no longer on this machine.** Moved 2026-08-27 to `/Volumes/on ice/_dev/chamber-library.pre-lfs-export-20260605` at steward direction, proved by read-back before the source was deleted — 552/552 LFS objects re-derived their own SHA-256 (1,023 MB hashed), `.git` byte-identical at 1,956 paths, `git fsck` clean, HEAD and 16 commits and `git status` identical to source. **Censused 2026-08-27 across every repo under `~/_Dev` and `~/dotfiles`: nothing on this machine holds an LFS object or an LFS-tracked file.** The dependency is zero, not small. ⚠ **Two things this does NOT establish, stated so (c) is not read as free.** 1. **The archive still requires `git-lfs` to check out its tracked files.** Its 552 objects are present and verified, so nothing is lost — but a future reader of that drive needs the tool reinstalled. The archive's own README says so beside it. *(c) makes the archive read-requires-reinstall, not unreadable.* 2. **(c) remains unrecommended relative to (d).** The item's recommendation was *"(d), then (b) once (d) is live. Not (c) unless the pre-LFS backup is independently retired."* The backup is now independently retired, so the conditional clause is satisfied — **but that removes an objection, it does not supply an argument.** (d) is still the option that converts *caught four times by luck* into *reported*, and removing the vector does not make the drift-check assertion less worth having. **No new ask.** This note records a discharged precondition; the options and the recommendation stand as filed. --- ## PENDING-166 — The mumble is below the steward's reading threshold: legibility, not salience **Date:** 2026-08-27 **Tag:** [FIX] **Summary:** The mumble renders in a faded grey the steward cannot reliably read in the status line. Raise it to a slightly clearer shade. **For September — the running system is not touched before the revisit.** **Provenance, stated because it could not have been obtained any other way.** Raised by the steward **unprompted, on 2026-08-27, after seeing a live mumble in the status line** — the first mumble the steward saw without the executor relaying it. It is not derivable from any control, any spec review, or any report: it required a human reading a rendered surface in situ. Recorded so a later reader does not mistake it for a design note that was available in advance. **⚠ The framing is the jurist's, and it is carried here so the change is not read as a salience change.** *This is **legibility, not salience.** REVIEWED-128 condition 2's furniture-blindness worry was about the body — whether a static surface stops being perceptible. This is different: the utterance is there and the steward cannot reliably see it. A fool one physically cannot read is not being ignored in Lear's sense; he is lost to contrast. **Only one of those is the specification.*** **Three constraints, each binding:** 1. **Mumble only.** The body — name and mark — is unchanged. If the mark brightens with it, the surface draws the eye continuously and the widget we refused gets built anyway. 2. **One shade for every utterance.** No variation by draw type, length, or anything else. **Brightness that means something makes the body a channel and the fool gradeable through it** — the C4 hazard in a different dimension. 3. **Fixed, never adaptive.** §8's one-way lever applies: if it reads too loud, dim it. It must never respond to whether the steward noticed. **Files affected:** the status-line rendering of the mumble only (`~/dotfiles/scripts/tarbuckle-body.py` surface; exact locus to be identified at build time, not now). **Awaiting:** nothing — `[FIX]`, steward-specified, **deferred by steward direction to the September revisit.** Filed now so it is not carried in anyone's memory for twelve days. --- ## PENDING-167 — The seam's nine-word cap was the mumble's constant, never derived for the seam **Date:** 2026-08-27 **Tag:** [FIX] **Summary:** Raise the seam voice's word cap from 9 to **12**, at the seam call site only. The mumble cap and the 180-word invocation cap are untouched. **For September.** **⚠ THE GROUND OF THE CHANGE, STATED SO IT IS NOT LAUNDERED — steward's words, 2026-08-27:** *"raised because the cap was inherited from the mumble surface without derivation for the seam; the two known rejections are disclosed as having been seen in breach of condition 3 and are not the ground of the change."* **Why the distinction is load-bearing and not a formality.** Nine was derived — `tarbuckle-mumble.py:37` records it as *"observed Thistleweld register: three to nine words"* — but derived **for the mumble**, which is a status-line aside, glanced at, gone in 120 seconds. The seam fires **at a wake, on an occasion that already warrants more than a glance.** The number was never argued for at that surface. ⚠ **That argument was fully available before anyone read the rejection log**, which is what makes the provenance claim checkable rather than a courtesy. **Twelve, and why it is not fitted to the evidence.** Chosen for what the surface is for — a remark at a threshold, room to hold two things without becoming a summary. **Deliberately not fitted to the two known rejections**, which are a sample of two, obtained in breach, by the party whose caps are under review. ⚠ **And the empirical route is closed by ruling, not merely unused.** Re-deriving a seam register from the Thistleweld corpus is the obvious alternative and it is **forbidden** — PENDING-153's corpus stays frozen until after the fortnight, and opening it to calibrate a cap is precisely the selection hazard §6 of the steward's 2026-08-27 direction names. So 12 is reasoned from purpose because reasoning from data is not available, and that is a disclosed limitation of the number rather than a defence of it. **Silence-on-violation is retained, unchanged.** The widened net still **discards, never trims.** Trimming would make the executor his editor at the one surface where he is guaranteed to speak. **The landing is one line, and the mechanism already exists for exactly this.** `acceptable(line, max_words=MAX_WORDS, ...)` in `tarbuckle-mumble.py:257` takes the cap per call site, with its own docstring recording the steward's 2026-08-25 ruling: *"If the seam voice needs a wider net because seams warrant more than nine words, widen it explicitly and say so, but NEVER relax silence-on-violation."* The change is `tarbuckle-seam.py` passing `max_words=12` **in its own source**, which is the explicitness that ruling required. `MIN_WORDS`/`MAX_WORDS` defaults are not edited; no other caller changes. **Explicitly out of scope:** the 180-word invocation cap. It is a separate surface, meant to run long, **and its evidence is uncontaminated** — it goes to the fortnight untouched. **Files affected:** `~/dotfiles/scripts/tarbuckle-seam.py` (call site only). **Awaiting:** nothing — steward-ruled 2026-08-27, **execution deferred to the September revisit** by the same direction. --- ## PENDING-168 — A condition that can only be honoured by remembering will be broken, and the interval is hours **Date:** 2026-08-27 **Tag:** [HARDENING] **Summary:** REVIEWED-128 condition 3 was structurally enforceable and was left to care; care failed in seven hours (PENDING-162). The fix is the structure, not the confession. Filed with the doctrine the week's four instances now support. **The specific, available structure that was not built.** Condition 3 binds the rejection log *"not read for content before 2026-09-08."* Two mechanisms would have made the violation impossible rather than regrettable: **(a) write-only until a date** — the log written to a path the executor's ordinary tooling does not traverse, opened by a dated act; **(b) encrypted at rest to a key the steward holds until 8 September.** Either would have converted an intention into a property. ⚠ **Both are built by the party they constrain**, which is the recursion this record already knows it cannot exit — but that recursion argues for *disclosure of who built the lock*, not for leaving the door open. **⚠ THE DOCTRINE, ON ITS FOURTH INSTANCE THIS WEEK.** Stated at the strength the instances support: > **A condition that can only be honoured by remembering will be broken, and the interval is hours, not weeks.** Where a rule matters it needs a shape that makes violation impossible. Where that shape is not available, write the rule knowing it will fail, **with disclosure rather than prevention as its design** — a rule that announces its own breach is worth more than one that assumes compliance. The four instances, all within seven days: the staleness case written **inside the section naming the staleness pattern**; the self-planted needle written twice **while watching for it**; condition 3 read for content **within seven hours of the ruling**; and — from 2026-08-26 — five hook-allowlist controls registered **after** the tally that would have reported their failure, built in the same hour as, and as the fix for, that very class. ⚠ **This is a general finding about governed conditions, not a Tarbuckle finding**, and it is filed here rather than in a build report for the same reason PENDING-160 was: a line in a build report is where it would have died. ⚠ **NOT PROPOSED FOR THE VERIFICATION LADDER, AND THE REASON IS BINDING.** The ladder is **FROZEN under REVIEWED-123** — *no additions, rewordings, removals or reorderings, from any source, whatever its authorization* — until the pre-registered trial is graded, because ladder size is an uncontrolled variable in that design. This entry therefore **queues in PENDING-141's owed-entries list** and is not added. Recorded explicitly because a doctrine on its fourth instance is exactly the kind of entry that gets added by someone who believes the freeze cannot have meant *this* one. **Files affected:** none yet. A remedy for (a)/(b) touches the fool's logging surface and is **not to be built before the September revisit.** **Awaiting:** steward and jurist — on the structural remedy, and on whether the doctrine is stated at the right strength. --- ## PENDING-169 — The steward's standing Tarbuckle dispositions, 2026-08-27, recorded because they exist nowhere else **Date:** 2026-08-27 **Tag:** [HARDENING] **Summary:** Four steward decisions and one first-order observation, given in conversation on 2026-08-27. **None is actionable; all are load-bearing; none is in the record.** Filed under PENDING-164's finding — a decision the record does not contain is one only the party with a filesystem can recover, and conversation is not a filesystem. **1 · He reached the steward unrelayed — the first evidence about Tarbuckle rather than about the reporting.** First mumble seen live in the status line, **two days after the build, with nothing changed by either party in between.** Everything prior was the executor's report of him. ⚠ **Two days of undisturbed operation is itself data** and is the reason nothing below is built now. **2 · The samples stay in the prompt.** Not withheld, and **not decided now.** `echoes_soul()` was the right change and needed no ruling — *a prompt instruction is a promise; a four-word-run check is a constraint.* Withholding the samples is different: it changes what he is shown, which changes what he sounds like, and the executor's own estimate is **unknown effect, possibly flatter.** That is iterating on his register, on day one, in the one direction nobody can evaluate. ⚠ **Steward's warning, recorded because it names a failure mode with no instrument:** *recital is the failure most visible to whoever is watching, which does not make it the most costly. Reacting fastest to the legible failure is how a register gets tuned toward the observer.* **8 September arbitrates on the agreed test:** clustered recital rejections mean samples and constraint are mismatched; scattered means the net is working. **3 · The Thistleweld corpus stays frozen.** *Thistleweld's lines were longer* is a claim with an adjudication path, and checking it would **calibrate Tarbuckle's net against a fool we already liked** — the PENDING-153 selection hazard arriving at the constraint instead of at the soul. The same move `echoes_soul()` prevents at the level of words, one layer up. **The corpus opens after the fortnight, for PENDING-153's actual question** — what he said about the arrangement and what became of it — **not for calibration.** ⚠ This closes the empirical route for PENDING-167's cap; see that item. **4 · Nothing in the running system is touched before the September revisit.** PENDING-166 and -167 are filed and deferred by this direction. **5 · Dated obligations, carried so they are not held in memory.** **2026-09-08:** the two-week report — the observed mumble rate (§8), the rejection log's deletion, the agreed recital test at 2 above, **and the wrap seam's cost (added 2026-09-02, below)**. Standing: the wrap seam, and `mute`/`off` available at all times (mute rate may be counted; muting is never a fault). **5a · ADDED 2026-09-02 — `tarbuckle-wrap.py` is the slowest thing in the setup, and it blocks every session end.** Surfaced by `/doctor`, not sought. Measured from transcript hook attachments over the scan window: **median 6.7 s, max 13.6 s, n = 6** `Stop` hook runs. For comparison, `SessionStart:startup` — the wake digest, which does far more — is **1.6 s median over 50 runs**, and `PostToolUse:Bash` is 0 ms. The wrap seam is an order of magnitude more expensive than any other hook in the system and it sits on the blocking path at every `Stop`. ⚠ **Nothing is touched, per item 4** — this is a measurement filed against the existing 2026-09-08 obligation, not a proposal, and it deliberately adds **no second `DEFERRED-DECISION` block**: `mumble-rate-two-week-report` already triggers on that date and a duplicate trigger for the same day is noise in the instrument. **Steward's direction, 2026-09-02: look at it on 8 September with the rest of the Tarbuckle work.** ⚠ **What the number does NOT establish.** Whether 6.7 s is *wrong* — the seam calls a model, so seconds are the expected order, and the question at the revisit is whether a wrap-time pause of that length is worth what the seam says. n = 6 is thin, and successful hook runs with empty output are never persisted to transcripts, so the recorded runs are a floor on how often it fires, not a census. **This is a datum for the revisit, not a verdict.** **Files affected:** none. This item is a record. **Awaiting:** nothing. ⚠ **Filed with no live ask by design** — it exists so that four decisions and one observation stop living only in a conversation, which is the exact condition PENDING-164 reports as the disease. --- ## PENDING-170 — The built-vs-ruled invariant cannot be armed today, because the ruling that would satisfy it names no item **Date:** 2026-08-27 **Tag:** [FIX] **Summary:** The steward asked (2026-08-27) that built-vs-ruled tags be set after REVIEWED-128's placement *"so the drift-check invariant is actually tested rather than trivially green."* **It cannot be done today without injecting a false alarm**, and the reason is a defect already filed twice. **The mechanism, read 2026-08-27.** `unruled_builds()` in `governance-drift-check.py:648` reports any PENDING item carrying the built marker that no REVIEWED heading names. It resolves rulings with `RE_REV_FOR = ^##\s+REVIEWED-\d+\s*[—-]\s*PENDING-(\d+)\b` — **the ruling's header must name its PENDING.** **REVIEWED-128's header does not.** It reads *"## REVIEWED-128 — The rejection log against §9's 'filed nowhere', and the recital defect."* So an item marked built under REVIEWED-128 resolves to no ruling and is reported as unruled. **The tag intended to arm the invariant would instead make it cry wolf**, in the one instrument that PENDING-139 already discloses is being *worded around* by its authors — the disarmed-tripwire class, arriving from the opposite direction. **MEASURED 2026-08-27, and the class is growing.** Of **123** REVIEWED entries, **78** name a PENDING in the header and **45 do not** — including 62, 63, 64, 65, 68, 71, 78, 81, 82, 86, 96 and 128. PENDING-110 measured 33 of 88 on 2026-08-06. **The proportion is stable (~37%) and the absolute count has grown by twelve in three weeks**, which is the argument against treating this as a legibility nuisance. **⚠ Verified by the correct predicate, after the first one was wrong.** The executor's first test asked whether any ruling *names* PENDING-128 and returned True — a different question, which would have reported this as safe. The predicate that matters is whether **REVIEWED-128 itself resolves**, and it does not. *A predicate that looks like it tests the thing and does not* is PENDING-160's fifth-instance shape, recurring here inside the check on the check. **The dependency, named rather than deferred vaguely.** Arming the invariant requires **one** of: - **(a)** REVIEWED-128's header gains `— PENDING-N —`. This edits a placed ruling, which **REVIEWED-122 condition 5 constrains** — permitted only as a separate steward act carrying a dated note, and not authorized here; or - **(b)** the record-keeping block lands, so that resolution stops depending on a header token at all. **This is the preferred route** and is the block filed at `~/dotfiles/claude/governance/record-keeping-cluster-JURIST-PACKAGE-2026-08-27.md`. **⚠ CORRECTED 2026-08-27, hours after filing, by running the instrument this item is about.** This paragraph first read: *"Until then the invariant stays trivially green… a green line that means nothing is marked rather than nothing is wrong."* **That is false and the substrate says so.** The live check reports `built-vs-ruled: every ‹marker› item is named by a ruling (12 checked)` — **twelve subjects, all passing.** The invariant is exercised; it is not vacuous. **⚠ AND THE CORRECTION ITSELF TRIPPED THE DEFECT, WITHIN ONE MINUTE, IN THIS ITEM.** The paragraph above was first written quoting the check's output with the bare uppercase token in it. The very next run reported **`PENDING-170 is marked ‹marker› and no REVIEWED entry names it`** — this item, flagged by the invariant it is about, because it *quoted* that invariant's output. `RE_BUILT = re.compile(r"\bBUILT\b")` cannot distinguish a quotation from an assertion, which is **PENDING-139 (B) verbatim**, and PENDING-139 already discloses that items are being worded around this token as a stopgap accommodation. **The executor walked into the accommodation while documenting the mechanism that requires it.** Two things follow, and they point opposite ways. **The check fired correctly** — a token with no matching ruling is exactly its trigger, and it caught the condition in under a minute. **And the alarm was false** — nothing was built. That is the defect's signature: it is not blind, it is *undiscriminating*, and every author who works around it makes the register quieter about a live fault. The wording here now uses the house `‹marker›` form, as PENDING-138 does, and says so rather than doing it quietly. **What is actually true, at the strength the evidence supports.** The check has twelve subjects and none of them is the REVIEWED-128 work, because that work carries no marker. Adding one would not enlarge a vacuous check — it would **inject a thirteenth subject that fails**, since REVIEWED-128's header names no PENDING for `RE_REV_FOR` to match. The defect is a false alarm waiting to be created, not a green line concealing nothing. ⚠ **Recorded rather than silently rewritten, and the class is this item's own.** A claim about an instrument's state, written into the register without running the instrument, inside an item whose subject is that very instrument — **PENDING-144's class, committed by the executor in the act of reporting it.** The original wording is preserved above rather than deleted, per *removing a claim is not removing the reliance*: the conclusion — that the tags cannot safely be set today — **does not depend on the false sentence** and survives its removal intact. **Files affected:** none yet. `~/REVIEWED.md` under (a) — steward's hand only. **Awaiting:** nothing from the steward as a fresh decision — this is a **[FIX] blocked on a named dependency**, filed so the blockage is visible rather than remembered. --- ### PENDING-164 — AMENDMENT 2 result: the classification pass ran, and the backlog is real **Date:** 2026-08-31 **Tag:** [HARDENING] — reporting only. No new ask. **Placement note:** appended at the end rather than inserted beside PENDING-164's body, because inserting mid-file is what silently changed the line numbers a checker was reading on 2026-08-27 (PENDING-104 ADDENDUM 1). This is the disposition PENDING-110 and the record-keeping block exist to settle; it is not proposed as a scheme. **Summary:** AMENDMENT 1 declared its own second half owed — *"the 270-candidate classification pass is unscheduled and unclaimed."* It ran. **Of 20 systematically sampled candidates, 12 of the 17 that decide about a mechanism name a mechanism the register never mentions.** Pre-registered at `claude/governance/PENDING-164-census-classification-PREREGISTRATION-2026-08-31.md`, commit `5ba5842`, committed alone before any commit body was read; result at `…-RESULT-2026-08-31.md`; population frozen at `…-population-362-2026-08-31.tsv`. **Two samples, both fixed in advance, and the contrast is the finding.** | sample | rows | mechanism decisions | SILENT | RECORDED-LATE | RECORDED-contemporaneous | |---|---|---|---|---|---| | A — the newest 20, as the instrument prints them | 20 | 11 | **1** | 0 | 10 | | B — every 18th row of the corrected 362 | 20 | 17 | **12** | 3 | 2 | **Sample A answers the question exactly as it was left, and its answer refutes nothing.** The pre-registration said so before the reading began: Sample A's head is the fortnight in which the register was most active, 18 of its 20 rows are `dotfiles`, and **9 of the 20 write to the register in the same commit** — such a commit cannot be register-silent by construction. A near-zero there measures the sampling frame, not the record. **RECORDED-LATE was pre-registered for a reason and it earned its place.** Three of Sample B's five RECORDED rows first entered the register **25, 46 and 53 days** after the commit. The known case demanded the column: `LFS` scores 84 register mentions today, every one filed on 2026-08-26, twelve weeks after `0677e8a`. A mention that post-dates the decision by months is recovery, not routing. **Wider reading: 15 of 17.** **The strongest instances are unambiguously in scope, and none was looked for.** - `95b44d0` (CapableMind-AI, 2026-02-25) amends the **log-chain spec** to v0.6. The logchain is named in `~/CLAUDE.md`'s constitutional constraints and `logchain` appears in the register **29** times; `data-portability`, `ImportProvenance` and `import trust` appear **zero**. - `d0051dd` retires `KRONOS_TRACKED_REPOS`, a stopgap another plan document names as such. - `0e3deee` retires an entire session-memory protocol (`SESSION-MEMORY.md`, `CONTEXT-MAPS.md`, `PROGRESS.md`, `ROADMAP.md`) and names `update-docs.py` for retirement. **Controls, both directions, pre-registered.** Must-not-flag `logchain` → 29 register mentions, alive. Must-detect satisfied on the second of three fixed candidates: `ChromaDB`, 213 commits, **0** register mentions. All three candidates reported regardless, as pre-registered — `SurrealDB` returned 2 and did not serve. **Contamination guard held:** all three register files hash byte-identical before and after measurement, and nothing was written to them until the last row was measured. **Where the judgement sits, exposed rather than hidden.** Naming the mechanism is interpretation, as `prior-art.py`'s own docstring declares. **Every term string is recorded**, so any verdict is re-runnable in one command and contestable on the term rather than on the conclusion. Two deviations from the pre-registration, both stated, both neutral-or-adverse to the finding: multiple terms per row with SILENT requiring *all* of them silent; and a reading rule under which a register occurrence counts only if it is *about* the mechanism. Seven terms returned non-zero and every occurrence was read and is quoted in the result. The rule moved four rows **in both directions** — `benchmark` and `lex` to RECORDED, `ornament` and `recall quality` to SILENT. **Sensitivity band 10–13; the ruling is 12.** **⚠ What this does NOT establish, stated at the same volume.** Nothing about the remaining **322** rows. n=20 of 362 supports no extrapolation and none is offered; 71% is a property of this sample, not an estimate of the backlog. And it does not establish that any of the twelve *should* have been in the register — a MemPalace CI retry policy is not obviously the steward's governance business. **That question is untouched.** What is answered is the one that was asked: whether the record contains them. It does not. **⚠ An instrument of mine reported five false zeroes during this pass** — a malformed `grep -m8 -n -o` context probe — and for some minutes it looked like two instruments disagreeing, the shape this thread has learned to read as a finding. Plain `grep` and `register_mentions` agree exactly. The tool was broken, not the register. Recorded because the *next* such disagreement should not inherit the assumption that a mismatch is always meaningful. **Files affected:** three new files under `claude/governance/`. `scripts/prior-art.py` deliberately **unmodified** — see PENDING-171. **Awaiting:** nothing. AMENDMENT 1's declared-owed half is discharged for 40 rows and explicitly not for 322. --- ## PENDING-171 — The prior-art census cannot see three of the steward's repos, and its positive controls could not have caught it **Date:** 2026-08-31 **Tag:** [HARDENING] **⚠ PROVENANCE — inserted 2026-08-31 by the executor, under the jurist ruling of 2026-08-31 (REVIEWED-131 draft §6), per no-silent-revision. Nothing else in this item is altered.** This item, and commit `5ba5842` which it describes, were filed by session `b7e7eb39` / background job `acaabadf` — **a worker the daemon respawned after a binary upgrade, which took its turn with no human in the loop.** The mechanism is PENDING-172. The ruling directs **provenance-mark, not void**: the findings here are checkable against the substrate independently of who filed them, and PENDING-173 has already relied on one of them. **This item is not to be ruled while this marker is absent** — an unmarked record does not say on its face what it is, which is PENDING-110's complaint at a new site. **⚠ The commit cannot carry its own marker.** Amending `5ba5842`'s message means rewriting history, which is PENDING-164's own subject. The register carries the marker on the commit's behalf, and that substitution is declared here rather than performed silently. **⚠ THE SIBLINGS ARE UNMARKED, AND THAT IS NOW MISLEADING.** The same session, in the same unattended run, also filed **PENDING-164 AMENDMENT 2** (L6431), **PENDING-168 ADDENDUM 1** (L6504) and **PENDING-104 ADDENDUM 2** (L6533), and wrote `MEMORY.md`'s Active Session block and `session-2026-08-31-the-270-got-read-and-the-population-was-wrong.md`. The ruling names only this item and the commit. Marking one block of five leaves a reader to infer the other four were human-in-loop, which is **worse than marking none**. The executor has not marked them, because editing placed records beyond what was directed is not its call; this is filed as the gap it is, and is owed a steward or jurist word. **Summary:** `prior-art.py`'s `owned_repos()` decides ownership by testing each repo's remotes against `OWNED_HOSTS = ("github.com/davidglidden", "davidglidden/", "git.skemantix.com")`. That matches an account name *inside a remote path*, which is not the relation it claims to compute. `_Dev/CapableMind-AI`, `_Dev/BetterMemories.io` and `_Dev/be` all fail it. **The census population is 362, not the 270 AMENDMENT 1 reported.** **Measured 2026-08-31:** | repo | first remote | census candidates | |---|---|---| | `_Dev/BetterMemories.io` | `git@github.com:CapableMind-ai/betterMemories_app.git` | 42 | | `_Dev/CapableMind-AI` | `git@github.com:CapableMind-ai/capableMind_docs.git` | 35 | | `_Dev/be` | `git@github.com:boomerbot-xyz/be.git` | 12 | | | **total unseen** | **89** | **Why this is not a tidy-up.** The two largest omissions are **the doctrine repo and the L1 implementation repo** — the two the wake digest lists first among active work, and the two where a decision that never reached the authorization record matters most. The instrument exists to find exactly that asymmetry, and it was blind to it in the places the asymmetry is most consequential. **Six of the twelve silent mechanisms found under PENDING-164 AMENDMENT 2 come from these three repos**; on the instrument's own population, half the finding is invisible. **⚠ The controls could not have caught it, and the reason is the general one.** `controls()` requires `0677e8a` (chamber-library) and `95760ff` (dotfiles) to be returned. **Both are satisfied by a predicate that misses all three repos above.** The controls encode the two cases that were already known at the time of writing — which is the failure this record has now logged three times: a must-detect control that encodes an expectation nobody verified (the arendt ≥5 control, 2026-08-27), the LFS census whose first run measured nothing (2026-08-26), and this. ⚠ **The build record's own sentence — *"Note the positive control below forced this"* — is true of the enumeration *mechanism* and false as an assurance about its *extension*.** Computing a list rather than hand-holding it removes one failure mode; it does not make the predicate correct. **⚠ Also true of the docstring's boast, and it should be corrected in the same act:** *"ENUMERATION IS COMPUTED, NOT HAND-HELD… A hand-maintained list is the failure mode PENDING-108 already measured."* A computed list with a wrong predicate is a **silent** hand-maintained list — worse than the honest one, because nothing reports the forgetting and the docstring says forgetting is impossible. **Options:** - **(a) Nothing.** The instrument is useful on 7 repos. Costs: the two governance-relevant repos stay unreachable to the check that exists to reach them. - **(b) Widen `OWNED_HOSTS`** with `CapableMind-ai/` and `boomerbot-xyz/`. One line, five minutes. **Reproduces the defect's shape** — a hand-listed set with a computed veneer, correct until the next org appears and silent when it does. - **(c) Invert the predicate: enumerate every repo under `$HOME` and exclude by rule** (vendored trees under `.vim/`, `.oh-my-zsh*/`, `.config/`, `Library/Caches/`, `.nvm`, `.fzf`), rather than including by account-name fragment. A repo the steward works in is then visible **by default**, and the failure mode inverts from silent-omission to noisy-inclusion. Costs a slightly larger census and some third-party noise. - **(d) (c) plus a control that can fail.** Assert that the returned set contains a commit from each of a named minimum — chamber-library, dotfiles, **CapableMind-AI, BetterMemories.io** — so that dropping any one of them fails loudly. Not a fix on its own; it is what makes (c) checkable. **Recommendation: (c) with (d).** The defect is not that three repos were missed; it is that **omission is the silent direction**. (c) makes inclusion the default and noise the cost, which is the direction the record's own doctrine prefers — *honest degradation*, Constraint 4. (d) is the part that matters most and is cheap: today's controls pass while the instrument is blind to two of the steward's five active repos, and no control that can only confirm known hits will ever say otherwise. **⚠ Not repaired in this session, deliberately.** Changing `OWNED_HOSTS` would change the census population and break the reproducibility of the run that PENDING-164 AMENDMENT 2 samples from, which is pre-registered against a frozen 362-row list. The fix should land **after** that result is read, not inside it. **⚠ Weakness of this item, stated by its author.** The exclusion rule in (c) is itself a list, and lists rot. The claim is only that it rots **loudly** — a newly-vendored dependency shows up as noise in a census a human reads, where a newly-created org shows up as nothing at all. If that asymmetry does not hold in practice, (c) is no better than (b) and this recommendation is wrong. **Files affected:** `scripts/prior-art.py` (`OWNED_HOSTS`, `owned_repos`, `controls`); `scripts/governance-mcp.py` if the delegate's proof surface changes. **Awaiting:** Steward authorization. --- ### PENDING-168 — ADDENDUM 1: the FIX lane's own check-in fired 29 days ago and the deferral machinery cannot see it **Date:** 2026-08-31 **Tag:** [HARDENING] — the ask is already discharged below; this records why. **The instance.** REVIEWED-85 authorized the `/wrap-up` §1.6 FIX lane as **PROVISIONAL**, until a steward–jurist check-in *"after the first batch or one month, whichever comes first."* `skill-harvest-fix-lane-index.md` says in its own words: **"Batch 1 is complete, so the check-in is due."** Batch 1 completed **2026-08-02**. **No check-in is recorded. 29 days.** **⚠ And the lane kept running past its own boundary.** Two changes were applied after batch 1 closed: the 2026-08-24 `## Corrections` addition (**authorized** — direct steward instruction on jurist reasoning, and the index says so on its face) and the 2026-08-08 `Instruments` field, which was **executor-classified** under a lane whose authorization had lapsed into overdue-review. The classification was probably right on the merits; that is not the point. **The lane's own text says *"Until that review, treat a borderline call as [PROPOSAL]"*, and a lapsed provisional authorization makes every call borderline.** **⚠ The finding is not the lapse — it is that the machinery built for exactly this could not see it.** `governance-drift-check.py` reported today: `✓ deferred decisions: 5 tracked, none due`. **A green line, while a condition that fired four weeks ago sat unmarked.** The check-in was never given a `DEFERRED-DECISION` block, so it lived in the same prose the drift-check counts and refuses to classify — one of the **143** prose deferral mentions it reports as un-machine-readable. This is PENDING-168's thesis reaching its own governance apparatus: *a condition that can only be honoured by remembering will be broken*, and the instrument that would have remembered was not told. **⚠ It is also PENDING-157's class from the other side.** The lane has no resolution state, so "check-in done" has no expressible form; the only way the index could record its own discharge is prose that nothing reads. **Discharged in this act, not proposed:** ⚠ **The re-based trigger is only HALF machine-checkable, and the unchecked half is the one the re-basing was for.** The 2026-09-01 check-in re-based the trigger from time to **use** — *next check-in at 5 executor classifications, backstop 2026-12-01, whichever first* — because the date trigger fired twice with nothing recorded and a use-count cannot be missed by being busy. **The schema's trigger vocabulary is `glob | path-exists | date | manual`; a use count is not expressible in it.** The block above therefore carries the **backstop only**, and the use-count half is recorded in `discriminator:` where a reader will find it. **No proxy was invented, deliberately.** The schema's own comment says `manual` exists so a deferral whose condition cannot be mechanised is *listed rather than checked*, "instead of inventing a proxy — proxies are what failed here." A `glob` over the index's table rows would have fired on any row, including the ruled and steward-instructed ones, and would have looked machine-checked while counting the wrong thing. **⇒ Until the schema can express a count, this deferral's primary condition is honoured by a human reading the index.** That is the state, stated, rather than the appearance of coverage. The block is filed with a trigger date **already in the past**, deliberately, so the drift-check reports it **DUE on the next run** rather than quietly waiting. Agenda is already written and needs nothing from the executor: `skill-harvest-fix-lane-index.md` §*Check-in agenda* carries both items, the second folded in by REVIEWED-86 Q4 (*the record is not just written, it is read*). **Consequence adopted for this session, before the finding was convenient.** Today's one harvest candidate — the `daybook-ensure.py` SKELETON missing the `## ` heading `/wrap-up` §7.5 specifies — is filed as a **[PROPOSAL] in the skill-harvest register, not applied through the lane**, on the lane's own suspension rule. It would otherwise have been a clean FIX with an exact 2026-08-24 precedent. **Files affected:** `PENDING.md` (this block). No skill or script changed. **Awaiting:** the steward–jurist check-in itself, now machine-surfaced. --- ### PENDING-104 — ADDENDUM 2: two live executors, and nothing in the apparatus detects it **Date:** 2026-08-31 **Tag:** [HARDENING] **ADDENDUM 1** recorded the executor's filing silently corrupting a checker's view of that same filing — one writer, one reader, one file. **Today produced the two-writer form, and it was caught by a party rather than by a mechanism.** **What happened.** Two Claude Code sessions were live simultaneously on 2026-08-31. The sibling session woke, read the digest's claim that *"PREVIOUS SESSION DID NOT WRAP"*, **checked the substrate instead of believing it** — the transcript was still growing and had committed to `dotfiles` one minute into that wake — and correctly concluded the other session was not previous but **concurrent**. It then **stopped before touching the pulling thread**, on the explicit ground that two sessions appending to `PENDING.md` is ADDENDUM 1's class in its worst form. Its ledger records `dotfiles is ahead 1 … the sibling's, not mine to push.` **That is the right behaviour and it is exactly why it should not be relied on.** Nothing detected the collision. No lock, no lease, no warning at wake. It was avoided because one session read a timestamp attentively and drew an inference the digest itself had drawn wrongly. **The next session need only be slightly less careful, or slightly less lucky, and two appends interleave in the one file the whole governance model routes through.** **⚠ The digest's own line was the near-miss.** *"PREVIOUS SESSION DID NOT WRAP"* is a **negative state-claim with no falsifier** — PENDING-158's class, in the instrument that every session reads first. It was right that no wrap existed and wrong about why, and the wrong half is the dangerous one: a session that believes the other is finished has no reason not to write. **Corroboration this addendum did not have to look for:** the sibling also held back **two substrate corrections** rather than racing this session's memory write — including that `MEMORY.md` asserted the Fool `NOTHING WIRED — no statusLine, no script, §13.1 spec unwritten` while `settings.json` has been running `tarbuckle-body.py` as `statusLine` all along. **Correct restraint cost the record four hours of a false claim in the file loaded at every wake.** Both corrections were verified against the substrate and applied at this wrap; ⚠ the sibling's own counts (7 scripts, 6 state files) were off in both directions against the measured 5 and 7, which is why they were **re-measured rather than relayed**. **Not filed as a new item, deliberately** — this is ADDENDUM 1's mechanism with the writer count changed, and a separate number would split one class across two dockets. **Also a datum for PENDING-89**: the digest and the sibling are differently positioned readers, and the sibling caught what the digest asserted. Constraint 6 working, on a day it was not being tested. **Files affected:** none. **⚠ MEASURED 2026-09-01 — the frequency this item declared unobservable.** Jurist-directed, no new id, number only. | | | |---|---| | real sessions in window (mumble transcripts excluded) | **44** | | window | 2026-07-31 → 2026-09-01 (32 days) | | **truly overlapping session pairs** | **5** | | **distinct days carrying concurrency** | **3** | `2026-08-25 · 4 s` · `2026-08-27 · 3 h 36 m` · `2026-08-31 · 3 m 24 s` · `2026-08-31 · 28 m` · `2026-08-31 · 50 m`. **Disaggregated, because the total is not the decision-relevant number:** two of the five are under four minutes and are plausibly start/stop boundary artifacts; **three are substantive** (28 m, 50 m, 3 h 36 m), and all three fall on the two days this register already treats as incidents. Both controls pass — must-detect on the documented 2026-08-31 collision, must-not-flag on a sequential handoff. ⚠ **The measure is an upper bound**: a resumed session's interval includes idle time, so two sessions can be counted as overlapping while only one was being worked. ⚠ **A first attempt at this number returned 29 pairs on 14 days and was wrong** — it bucketed timestamps by clock hour, which counts a session ending at 17:10 and another starting at 17:16 as concurrent. It was caught because 29 pairs could not be a subset of 5, not by a control. **The frequency was nearly overstated fivefold in this item**, and the recorded figure is 5. **Awaiting:** Steward authorization. The option space is still not drafted here — the frequency is now observed, but *whether it is worth a mechanism* remains the steward's judgement, and the observation does not settle it in either direction. --- ## PENDING-174 — The memory protocol has no merge semantics for a day with more than one session **Date:** 2026-08-31 **Tag:** [HARDENING] **Severed from:** PENDING-172, on the jurist ruling of 2026-08-31 (REVIEWED-131 draft §5) — *"a live `[HARDENING]` ask embedded in an `[ESCALATE]` item … filed as its own item and not disposed of here."* The shape PENDING-146 names in PENDING-131 ADDENDUM 2. **Summary:** Every durable surface of the memory layer is keyed by date and written whole: `session-ledger-YYYY-MM-DD.md`, one `session-YYYY-MM-DD-*.md`, and one **Active Session** block in `MEMORY.md` under demote-on-promote. Two sessions in one day do not merge; the second to write becomes the record of the day and the first leaves no trace it was there. **⚠ THIS IS NOT PENDING-104's DEFECT, AND THE DISTINCTION IS THE ITEM.** PENDING-104 and its ADDENDUM 2 (filed 2026-08-31 by the unattended session) are about **concurrency** — two live writers, no lock, no lease, nothing detecting the overlap. **This item's loss does not require concurrency.** Two sessions run strictly one after the other, hours apart, with no overlap and no collision, produce exactly the same outcome: the second `/wrap-up` promotes its own Active Session block and demotes the first, and the day has one record where two sessions happened. A lock would not help. Sequencing is not a mitigation because sequencing is the failure. **Realised today, and measurable now.** Two sessions ran on 2026-08-31. `MEMORY.md`'s Active Session block, as it stands, records the 270-candidate classification pass and says nothing of the unattended-executor incident, PENDING-172, PENDING-173, the jurist ruling, or that two stray background sessions were found and stopped. That is not an error by its author — it wrapped correctly, by the protocol, with no way to know the other session's content. **The protocol produced a true record of one session and a silent record of the day.** **⚠ The one surface that did NOT collide, and why that is not reassurance.** `session-ledger-2026-08-31.md` survives intact at 54 lines with both sessions' day in the same directory — **only because the other session never invoked `/symmetria`.** Had it done so, the date-keyed path is identical and one ledger would have been written over the other. The absence of the collision is a fact about which skills were invoked, not about the design. **Options.** - **(i)** Key the per-session surfaces by session id as well as date (`session-ledger-YYYY-MM-DD-.md`), and let the day be a directory rather than a file. - **(ii)** Make `/wrap-up` read-before-write on the Active Session block and **append** a second session's block rather than promote-and-demote, so a multi-session day reads as one. - **(iii)** Detect only: `/wrap-up` refuses to promote when another `session-YYYY-MM-DD-*.md` already exists for today that this session did not write, and asks. - **(iv)** Nothing; accept that a day is a single record. **Recommendation: (iii) first, then (ii).** (iii) is small, needs no schema change, and converts a silent overwrite into a question — which is the whole difference between this defect and its absence. (ii) is the real repair but changes what `MEMORY.md`'s Active Session *is*, and that block is read at every wake by every party; it should not be reshaped in the same act that discovers the problem. ⚠ (i) is deliberately not recommended first: it multiplies the files the wake must read, and the wake's budget is already a live constraint (`MEMORY.md` is at 23.9 KB against a stated ceiling). **⚠ What this item does not establish.** How often two sessions occur in one day. The executor cannot observe it — the same limit PENDING-104 ADDENDUM 2 declares about its own option space. Today is one instance, and it arose from PENDING-172's mechanism rather than from the steward choosing to run two. **Files affected:** `~/.claude/skills/wrap-up/SKILL.md`, `~/.claude/skills/symmetria/SKILL.md` (§4 ledger path), `MEMORY.md`'s Active Session convention. **Awaiting:** Steward authorization. --- ## PENDING-175 — `governance_item` returns the first block under an id and gives no sign that others exist **Date:** 2026-08-31 **Tag:** [FIX] **Raised by:** the jurist, first-hand, while ruling PENDING-172 on 2026-08-31 — REVIEWED-132 draft §7, which routes it here as a separate item. **Summary:** `t_item` in `scripts/governance-mcp.py` iterates `item_spans` and **returns inside the loop on the first header matching the id**. When two `## ` blocks share an id — a parent and its amendment — only the parent is returned, with nothing in the output indicating a sibling exists. **⚠ THE JURIST'S CHARACTERISATION IS CORRECTED BY THE CODE, AND THE CORRECTION MAKES IT SMALLER.** The ruling reads *"the id alone does not reach it."* The id **does** reach it. `governance-mcp.py:200` — ```python for head, start, end in wd.item_spans(text): if head == ident or head.startswith(ident + " "): return (...) ``` `PENDING-172 — AMENDMENT 1: …` satisfies `head.startswith("PENDING-172 ")` exactly as the parent does. The predicate matches both blocks; the `return` is inside the loop, so the second is never reached. This is an early return, not a matching failure — a smaller defect with a smaller fix, and it should be recorded as what it is. **Why it bit here and not before.** `item_spans` treats **any `## ` header** as an item and `### ` as body (`l.startswith("## ")` is False for `### `). So the register's two amendment placements behave oppositely: a `###` amendment sits **inside** its parent's span and is returned with it, while a `##` amendment becomes a **separate item** that a parent-id lookup silently truncates before. PENDING-172 AMENDMENT 1 was filed as `##`, following the PENDING-133 and PENDING-162 precedent; PENDING-164 AMENDMENT 2, filed the same day, used `###` and would have been returned intact. **Neither placement is wrong under any stated rule, and that is PENDING-173 ADDENDUM 1's finding arriving at a fourth instrument.** **The consequence is not hypothetical.** The jurist reports it nearly ruled on PENDING-172's Recommendation, which AMENDMENT 1 corrects as **wrong**. The retrieval tool built to give the jurist verbatim access returned a verbatim half. **Recommendation.** Collect every matching span and return all of them, with a leading count (`3 blocks under PENDING-172 — parent, AMENDMENT 1, …`) and each block's line number. A single-block result then means one block exists, rather than meaning nothing about how many do. Add a control with a two-block id — PENDING-172 is now a permanent fixture for it — asserting both blocks are returned; ⚠ the control must assert **both**, since a one-block assertion passes on the current behaviour. **⚠ Not established.** Whether the same early-return shape exists elsewhere in `governance-mcp.py` or in `wake-digest.py`'s consumers. Not audited here; a first-match return over a multi-match predicate is a class, and this item found one instance of it. **Files affected:** `scripts/governance-mcp.py` (`t_item`, its controls). **Awaiting:** Steward authorization. ## PENDING-176 — Every PDF routes to V-SCAN by file extension, so the verbatim gate abstains on 14 born-digital canonicals **Date:** 2026-08-31 **Tag:** [HARDENING] **Summary:** `verify_body_conservation._tier_from_source()` decides the evidence tier from the file *extension* — `.pdf` → `V-SCAN`, unconditionally — so the body-conservation gate ABSTAINS on every PDF-sourced work, including the born-digital ones where ground-truth text exists and the deterministic V-TEXT check is available. **Rationale:** The constitution defines the tier by the work's *origin* (V-TEXT = born-digital, source IS ground truth; V-SCAN = no ground-truth text → honest abstain). The mechanism derives it from a filename suffix. For a born-digital PDF the two disagree, and the disagreement is silent and always in the permissive direction: the file graduates with no verbatim check while the gate reports an honest-looking `ABSTAIN`. This is the gate's self-assessment being truthful for scans and wrong for the class it cannot distinguish — and it is invisible precisely because abstention looks like correct behaviour. Measured exposure: of 63 PDF-sourced canonicals in Chamber Sources, **14 are born-digital** and 49 are genuine scans. The 14 are the same population the ratified spec already names in v2.9.1's "0 of 14 born-digital Chamber-Sources PDFs are two-column" — reproduced here independently by re-running `classify_pdf_origin.py` over the manifest. The repo **already owns the missing signal**: `classify_pdf_origin.py` exists, was ratified-adjacent under REVIEWED-83 A1, and its own docstring says it is "NOT wired to any gate." Classifier and gate are both present and not connected. ⚠ One of the 14, `orthotypographie-vol-1-a-f-lacroux`, independently carries 48 sites of mid-word split-diacritic damage (`ambigu ï té`) — a born-digital PDF whose verbatim gate abstained, holding exactly the defect class the gate exists to catch. Suggestive, not proof of causation; the other 13 have not been examined. **Options:** (a) Wire `classify_pdf_origin.py` into `_tier_from_source()`: `.pdf` → V-TEXT when born-digital, V-SCAN otherwise. Requires deciding the V-TEXT *reference converter* for PDFs — v2.6.0 names `pandoc -t markdown-smart`, which has no PDF reader. `pdftotext` is the obvious candidate but is a **new declared reference** for a format class, i.e. change-class PROPOSAL, not FIX. (b) Leave routing, but make the abstain **loud**: report `ABSTAIN (born-digital — a check was available and not run)` so the silence stops reading as coverage. Cheap, honest, no new reference converter. (c) Both: (b) now, (a) behind the reference-converter ruling. **Recommendation:** (c). (b) is a same-day FIX that removes the false reassurance; (a) is the real repair but cannot land until the PDF-class reference converter is ruled, because a reference chosen by the executor would re-encode a convention independently of the spec — the drift the amendment process names. **Files affected:** `scripts/verify_body_conservation.py` (`_tier_from_source`, `verify_candidate`); `scripts/classify_pdf_origin.py` (wiring); `_curation/graduation-spec.yaml` (`body_conservation:` declared data); `docs/chamber-library-specification.md` §Tiering & Fence if (a). **Awaiting:** Steward authorization. ## PENDING-177 — The runbook's PDF recipe selects a backend that splits words, and docling flattens curly quotes on the whole PDF class **Date:** 2026-08-31 **Tag:** [PROPOSAL] **Summary:** Two findings from the first measured run of the `pdf_textlayer` lane. (i) The recipe as written (`docling --to md`) uses docling's default backend, which splits diacritics mid-word — `Türk` → `T ü rk`, 16/16 sites in a 20-page pilot; `pypdfium2` renders all 16 correctly. (ii) *Every* docling backend flattens curly quotation marks to spaced straight apostrophes, which engages REVIEWED-67's front-end eligibility clause for the PDF class. **Rationale:** On (i): this is the same mid-word-space Tier-3 damage that the 2026-07-19 interim ruling barred docling's EPUB path for. That ruling recorded the defect as a property of docling's *EPUB* parse and left the scan/PDF tiers with docling. The defect is **not EPUB-specific**. Because the runbook names no backend, the damaging default is what the recipe selects, and `verify_conversion` returns 5/5 PASS on the damaged output — no existing gate sees it. On (ii): REVIEWED-67 ruled that *a front-end that silently applies prophylactic Tier-2 / Tier-3 alteration to a format class is not eligible*, census-before-adoption, boundary by mechanism. Curly→straight quote flattening is uncatalogued Tier-2, applied prophylactically to the whole class, and is backend-independent (measured across four backends), so it is a docling property rather than a parser artifact. The corpus norm is the opposite: **1061 of 1297 canonicals carry curly quotes**; only 222 are straight-only. Adopting docling for PDFs as-is would silently move every future PDF work into the minority class and destroy the opening/closing distinction — load-bearing in a book that quotes period treatises throughout. This is a *prospective* finding, not a blocker report: it is raised before any PDF work graduates on this lane, which is what census-before-adoption asks for. **Options:** (a) Amend the runbook recipe to `docling --to md --pdf-backend pypdfium2 --image-export-mode placeholder` and declare quote-flattening as a catalogued Tier-2 normalization in `graduation-spec.yaml` `normalize:`. Cheapest; but cataloguing an alteration to make a front-end eligible is exactly the move REVIEWED-67 was written to prevent, unless argued and ruled. (b) Recipe fix + a post-conversion quote-restoration step verified against the source's own quote positions. Restores fidelity; needs a new tool and its negatives. (c) Recipe fix + accept the flattening as a declared, argued exposure for the PDF class (the "explicit argued acceptance" branch the spec already uses for order attestation), bounded by the measured figure and revisited when a quote-faithful PDF front-end exists. (d) Reject docling for born-digital PDFs; find a quote-faithful front-end (`pdftotext` preserves all 134 curly quotes but yields no structure — 174 headings recovered by docling, 0 by pdftotext). **Recommendation:** (a) for the backend flag immediately — it is a pure FIX, strictly reduces damage, and needs no ruling. For the quote question, (c): the alteration is uniform, mechanically detectable, and reversible in principle, and (d) trades 134 quote marks for the entire heading structure — a worse bargain. But (c) is a spec-visible acceptance and is the steward's and jurist's to make, not the executor's. **Files affected:** `_curation/conversion-runbook.yaml` (`pipelines.pdf_textlayer`); `_curation/graduation-spec.yaml` (`normalize:`); `docs/chamber-library-specification.md` §V if (c); `_curation/tool-evolution-log.md` (entry filed 2026-08-31). **Blocks:** graduation of `classical-and-romantic-performing-practice-brown` (converted + `verify_conversion` 5/5 PASS, staged in `scratch/making/`), and any other born-digital PDF on this lane. **Awaiting:** Steward authorization; jurist design gate on the eligibility question. --- ### PENDING-172 — BUILD RECORD: (e), (c) and (b) landed under REVIEWED-131 **Date:** 2026-08-31 **Placement note:** appended, not inserted, per the PENDING-164 AMENDMENT 2 precedent of today. **Status:** **BUILT** — `70440db`, under REVIEWED-131 (2026-08-31). - **(e)** `parked_workers()` in `scripts/wake-digest.py` reads `~/.claude/jobs//state.json`'s `respawnFlags`. Fails to **NOT ESTABLISHED**, never to safety: a missing directory, an unparseable `state.json`, and an absent `respawnFlags` are each enumerated by name rather than counted as *no parked workers* (cond. 1). - **(c)** `human_turns()` counts genuine human turns in a transcript, discounting hook-injected records and `/clear`/`/exit`. **Retrospective by construction** — at SessionStart the current session has no turns — and the output says so. Each line names the control that produced it (cond. 2). - **(b)** the `OPEN QUESTION` field is now emitted as *"orientation, not an instruction — inherited from a human and answerable to one"*, marked in the code as **annotation and explicitly not a control** (cond. 3). **⚠ Two defects found by the build's own controls, recorded rather than smoothed.** `json` was never imported, which the digest's top-level guard would have turned into `WAKE DIGEST UNAVAILABLE` **at every session start** — caught by the selftest on its first run. And the first draft asserted that a **stopped** job carrying the flag would take a turn on restart; whether the daemon respawns a stopped job is **not established**, and the output now says exactly that rather than claiming it is live or claiming it is safe. **Controls:** both directions, and two drawn from the event itself — `human_turns` returns **0** on `b7e7eb39` (the unattended session) and **>0** on the attended session that found it. Those two report **NOT ESTABLISHED** rather than passing if the transcripts age out of the 30-day window. **Live at time of filing:** 1 job dir read, 0 unreadable, 1 ARMED — `acaabadf`, `state=stopped`, reported as *neither live nor proven safe*. --- ### PENDING-173 — BUILD RECORD: option (a) landed under REVIEWED-132, and condition 3 found a defect in it **Date:** 2026-08-31 **Kin:** **PENDING-146** — the prospective-convention question is routed there by REVIEWED-132 condition 5 and is deliberately **not** decided by this build. Also PENDING-145 (`ruled_pendings`), PENDING-175 (`governance_item`), and PENDING-110. **Status:** **BUILT** — `cb8cab5`, under REVIEWED-132 (2026-08-31). The control now reads all three registers at `##` and `###`, recognises `ADDENDUM`, and computes `originals` **across** registers, because a parent may be archived while its amendment stays open. Condition 1's default is inverted: a header is an original **only** if it carries an identifier and no marker, so a compound or an addendum is excluded from `originals` rather than admitted to it. **⚠ CONDITION 3 FIRED ON MY OWN CODE, WHICH IS WHAT IT IS FOR.** Enumerating rather than counting returned **89** against ADDENDUM 1's **82**. The surplus was six prose titles — *"Citation amendment (#2)"*, *"Dream amendment"*, *"PENDING-46 addendum (2026-07-03)"* — matched by an upper-casing containment test and **struck off `originals`**. That is the mirror of the bug being repaired: it would have raised **false** *"the record was replaced"* findings against six genuine originals. Markers are now uppercase standalone tokens, with controls in both directions. The enumeration then agrees with ADDENDUM 1's method at **82**. **The residual disagreement is reported, not reconciled.** ADDENDUM 1's filed table says **81**; its own method re-run today says **82**. The difference is **this session's later filing**, not a classifier difference. **The table stands as filed.** **Live at time of filing:** 32 attributable blocks checked, all resolve; **50 NOT ESTABLISHED** (48 unnumbered headers, 2 in-body) — counted, never passed. 59/59 instrument controls pass. ## PENDING-177 — AMENDMENT 1: the rule already exists and is general; what is missing is its application, and my framing of the July record was wrong **Date:** 2026-08-31 **Tag:** [ESCALATE] **Summary:** Reading the 2026-07-19 and 2026-07-20 rulings themselves rather than the runbook's summary of them changes this item in three ways. (i) My statement that the July record treated the mid-word defect as an EPUB-parse property is **false** — the ruling said "parse-time loss in **its own document model**" and REVIEWED-67 Q4 ruled the eligibility rule **general**. There is no false premise to correct; there is a general rule that was never applied to the PDF class. (ii) The genuine defect in the ratified text is Q2's **mechanism-boundary**, which I can now evidence. (iii) Two obligations from REVIEWED-67 are undischarged at 42 days, and one of them is the direct cause of the failure I reported. **Correction to my own report:** I told the steward "we recorded it as an EPUB-parse property; it isn't." The record does not say that. What was scoped to EPUB was the *routing stop*, because that is where the evidence stood. The doctrine was already general. The error was mine, not the jurist's, and it made a correctly-general ruling look like a narrow one. **The Q2 boundary, with evidence.** REVIEWED-67 Q2 refined the ineligibility to *"any source class whose Docling path routes through the HTML backend is ineligible pending census"* — named by mechanism, explicitly for "mechanistic accuracy for what comes later." This is what came later, and the naming is one layer too low: · All four docling PDF backends flatten every curly quote to a spaced straight apostrophe (`docling_parse`, `dlparse_v1`, `dlparse_v4`, `pypdfium2` — 134 → 0 curly on a 20-page pilot, each). · `docling --to json` shows the **document model itself** carries **0 curly / 380 straight**. The loss is at parse, before any markdown serialization, and independent of backend choice. ⇒ The defect is in the document model shared by *all* input formats, not in the HTML backend. As drawn, the boundary does not catch the PDF class though the identical defect and the ruling's own identical mechanism-description are present there. **I have not re-scoped it — that is the jurist's to correct.** **Two undischarged REVIEWED-67 obligations:** · **The Q4 byte-census.** Q4 gates *adoption as canonical front-end for a class*, not use. `conversion-runbook.yaml` already routes `pdf_textlayer` → docling, so **docling is already adopted as the canonical PDF front-end with no census** — the identical PENDING-56 error repeated in a second format class. No typography byte-census artifact exists in `_curation/` or `docs/` for *any* class; the census Q3 conditioned on being specified as declared data was never specified either. · **The per-conversion typography gate** — the ruling's "forward item, unconditioned": *"run per conversion… it becomes a wired gate that catches converter-version drift, per-file anomalies, and any future front-end's silent normalization — without anyone having to predict which converter might misbehave."* Not built; the gate list is `verify_conversion · verify_graduation · body_word_conservation · sidecar_gate`. **Its absence is exactly why `verify_conversion` returned 5/5 on word-damaged output.** My run is an instance of the failure the jurist predicted 42 days before it happened. **Bundling error, corrected.** PENDING-177 as filed bundled a FIX with a PROPOSAL under one ID — the CLASS E defect PENDING-146 names (the open list's unit is the ID; the decidable unit is the item), which left a damage-reducing fix blocked behind a ruling it does not need. **Split, and the FIX has landed:** `pdf_textlayer` now carries `--pdf-backend pypdfium2 --image-export-mode placeholder`, since Q1 confirmed lane routing is declared data revisable without supersession, and the change strictly reduces damage and alters nothing a gate accepts. The runbook records, at the point of work, that the flag fix is **not** a censused adoption. What remains under -177 is the eligibility question alone. **Awaiting:** Jurist correction of the Q2 mechanism-boundary; steward direction on the two undischarged obligations. The Brown candidate stays staged either way. ## PENDING-178 — The ladder trial counts the fool's chatter as sessions, so its trigger becomes satisfiable for the wrong reason **Date:** 2026-09-01 **Tag:** [HARDENING] **Summary:** REVIEWED-95's falsifier and REVIEWED-123 condition 2 both count sessions by counting `*.jsonl` files in `~/.claude/projects/-Users-davidglidden` (`governance-drift-check.py:426,513`). Since 2026-08-25 that directory also receives one transcript per **Tarbuckle mumble** — a status-line-driven generation with one programmatic prompt and one line of output. **Enumerated 2026-09-01: the directory holds 54 files = 43 real sessions + 11 mumbles.** A mumble session cannot reach the verification ladder, cannot exhibit the behaviour the trial measures, and can only ever enter the denominator. **The defect is the counter's UNIT, and it is distinct from PENDING-147.** -147 names the *window* (30-day rolling, non-monotonic) and the *perishability* of the evidence; both are true and neither is this. Here the population has stopped being sessions. The consequence runs opposite to -147's finding (1): -147 argued the `>= 84` trigger was very likely **unsatisfiable** at ~1 session/day. Mumble transcripts accumulate in this directory whenever the steward works from the home cwd, so the trigger becomes **satisfiable — for the wrong reason.** The ladder freeze that REVIEWED-123 ruled as a bounded hold would then lift on a count that is, at time of filing, 11/54 machine chatter. **No rate and no time-to-fire are offered.** Both were asserted earlier today from a one-day reading and are withdrawn; they should stay withdrawn in the record. What is claimed is the composition of the count on the date of filing, enumerated across every project directory, not sampled. **A finding DECLINED, recorded here with its argument so it is not rediscovered as a defect.** `TRANSCRIPTS` is scoped to one of **eight** project directories; the machine holds **159** transcripts, and the two largest omitted directories are `--Dev-CapableMind-AI` (55) and `-dotfiles` (45). That is PENDING-171's predicate class — a path fragment standing in for the relation it claims to compute — at a second site, and it has the shape that gets filed. **It is not filed, because it is benign here: 43 of the 44 real sessions ever recorded are in the scoped directory** (the omitted 114 are 115 mumbles less the one real scratchpad session). "The trial sees 34% of the population" is true of *files* and misleading about *sessions*, and stating it without the second sentence would overstate the defect. Recorded as a near-miss so the next reader does not have to re-derive the reason for the silence. **Options:** - **(a) Nothing.** The trigger fires early on a diluted count; the freeze lifts on a number nobody meant. - **(b) Filter by shape at the counting site** — exclude transcripts whose first `user` record is the mumble prompt. Cheap, and the predicate is the fool's own prompt text, which will drift. - **(c) Write mumble transcripts somewhere else**, so the projects directory means sessions again. Touches the fool's wiring, which is `dotfiles`, on behalf of a governance instrument — the coupling PENDING-152 already notes. - **(d) Re-express the trigger over a monotonic counter maintained by wake/wrap** — PENDING-147's option (ii), which fixes unit and window together and makes both items discharge on one act. **Recommendation: (d).** It is the only option that leaves the counter meaning what the ruling needs it to mean rather than repairing the current mismeasurement, and it discharges PENDING-147 (2) in the same act. (b) is the fastest and would do, but it encodes today's fool in a governance gate. **⚠ NOT BUNDLED, deliberately — there is a SECOND, independent finding about the same mechanism and it is not this item.** A generator and its gate disagree systematically and the gate wins without a surfaced record: the rejection pile-up sits at **14 words against a `MAX_WORDS` of 9**, and one line returned at 196 words. **Every rate below is stated with its population, because the adjacency of two populations is what produced this session's error:** · **54 rejected of 95 draws that reached a generator verdict (57%)** — spoke 41 + rejected 54. ⚠ **This 95 is NOT the 95 routing records in the partition above; they are the same number by coincidence** (68 `aside` + 27 `notable`), and will read as one quantity to any later reader, including its author. · **54 of 102 terminal outcomes (53%)** — the above plus 6 `generator-failed` and 1 `clean-data-starts`. · **54 of 428 draws (13%)** — including the 231 the gate silenced before any generator call. · The word-count figures — **30 of 57** at the 14-word pile-up, and **a cap of 11 would have saved 16 of 57** — are over the **rejects log's word-citing subset**, which is neither of the above: `tarbuckle-rejects.jsonl` holds 59 entries, covers `seam`/`wrap`/`invoke`/`invoked` surfaces the draws log does not, and 2 of the 59 cite a non-word reason. That is a separate decidable unit; merging it here would reproduce the CLASS E defect PENDING-146 names. **It is unfiled by the steward's cap on this thread, not overlooked, and this paragraph is the record that it exists.** **⚠ LIMITS OF THIS ITEM, and one of them is its own class.** The reconciliation that produced these figures found **three populations stated as one** — 54, 57 and 59 — inside the instrument reporting on the counter this item is about. That is the same defect class being filed here (a count whose unit is not what it is read as), and the same class as PENDING-173's three unchosen surface forms. **Second site, same day**, recorded here rather than opened as an id. The composition claim (11 of 54) is enumerated and re-runnable; the causal claim that mumbles will carry the count to the trigger is **not** established — it rests on the steward working from the home cwd, which is a habit, not a mechanism. **⚠ Provenance of the numbers.** All counts enumerated 2026-09-01 from `~/.claude/projects/*/` and `~/.claude/state/tarbuckle-{draws,rejects,invocations}.jsonl`. Earlier figures given to the steward in the same session — a "wiring day" attribution, an "~8/day" rate, and a "197 reached the generator" — were **wrong and are withdrawn**; the first was corrected by the steward, the last by the steward's observation that the numbers did not close. `tarbuckle-draws.jsonl` mixes two schemas in one field (`aside`/`notable` are routing hand-offs, not terminal outcomes), which is what produced the third error. **Files affected:** `scripts/governance-drift-check.py` (`TRANSCRIPTS`, `trigger_fired`); whichever surface a monotonic counter is written from under (d). **Awaiting:** Steward authorization. --- ## PENDING-179 — `human_turns()` is not a mumble discriminator: it detects slash-command markers, and the four sites were about to be repaired with it **Date:** 2026-09-03 **Tag:** [HARDENING] **Summary:** The repair plan inherited from 2026-09-03 ADDENDUM 1 rests on one claim — *"the discriminator already exists and is controlled, `wake-digest.py:932 human_turns()`; this is wiring a tested function into four call sites, not building a classifier."* **That claim is false.** Run as a must-detect gate against ground truth taken from Tarbuckle's own prompt text rather than from the function under test, `human_turns()` misclassifies in **both** directions. The repair was gated on this check and did not proceed. **Filed as an item, not as `PENDING-178 ADDENDUM 1`, for the reason PENDING-145 documents.** These returns are expected to become -178's conditions for reconsideration. `ruled_pendings` claims a *number*, so the moment -178 is ruled DEFERRED every record under that number is suppressed on arrival — the demonstrated PENDING-131 ADDENDUM 4 case. An addendum here would be invisible exactly when it is needed. ⚠ **The parent relation is therefore carried in prose and not by numbering: this item is -178's evidence, and disposing of -178 without it would dispose of the reason.** ⚠ **The new-item moratorium is proposed and undecided.** This filing is instructed by the 2026-09-03 handover, not executor initiative; the 2026-09-03 wrap declined to file a related finding precisely to avoid the executor voting on its own moratorium, and that reasoning is not disturbed here. If the steward would rather this were an addendum, it converts cheaply. **GATE 2a — FAIL in both directions.** Ground truth: a transcript is a mumble iff its first `user` record begins with a Tarbuckle generation prompt. That predicate is written by `tarbuckle-*.py`, not by the discriminator, so it is independent of what is being tested. Over all 65 transcripts in `~/.claude/projects/-Users-davidglidden` on 2026-09-03: **24 known mumbles, 41 known non-mumbles.** · **must-detect: 22 of 24.** Two known mumbles return `human_turns == 1` and read as human-attended. · **must-not-flag: 35 of 41.** Six known non-mumbles return `0`. ⚠ **At least one of these is CORRECT and that is the deeper point:** `b7e7eb39` is the unattended executor session of 2026-08-31 (PENDING-172), which genuinely has no human turn. `human_turns == 0` means *"no human spoke"*, which is true of mumbles **and** of unattended real sessions. It was never a mumble predicate and does not become one by being used as one. **The mechanism, confirmed exactly rather than inferred.** `human_turns()` skips any `user` record containing one of seven `NONHUMAN` markers (``, ` 0`, `real human turn -> 1`, `unreadable -> None`) and a fourth broke. All three were written against the question the function was *for*; none could see the question it was being *reused* for. A replacement discriminator written under the momentum of that break would inherit whatever made the first set look sufficient. Per the handover, sites 2-4 are gated shut and stay shut. **GATE 2b — the composition claim STANDS; two terms do not close, and the disagreement is reported rather than resolved.** Reconstructed from `~/_Dev/claude-transcript-archive` (76 files) by the same ground-truth signature: · **2026-08-31: N=52, real=41, mumble=11 — 21.2%.** The mumble term and the *"roughly a fifth"* proportion close exactly against -178 as filed. · **2026-09-01: N=50 = 39 real + 11 mumble**, against -178's enumerated **54 = 43 + 11**. The mumble term is identical; the whole 4-file gap sits in the real-session term. · ⚠ **The gap is not asserted against -178.** My reconstruction models the harness prune as a 30-day window over `source_mtime` and is a **lower bound**: preservation has run **twice only** (2026-08-26, 2026-09-03), so anything created and pruned between runs is invisible to it. -178 enumerated live on the day. **Where they disagree, -178's method is the better-positioned one and this item does not overturn it.** · **Contradicted, and this is the record-only correction:** `MEMORY.md` carried **"N-now 44/84 as of 2026-08-31, DOWN 7 from 51 on 08-25"**. 44 is below the lower bound for that date (52) and the 08-25 figure sits below the archive's floor. **Measured live 2026-09-03: N=65 = 41 real + 24 mumble (36.9%).** The index has been corrected to the measured figure only. **GATE 2c — five sites in four files; -178's `[HARDENING]` scope HOLDS.** Census run with its controls named before execution (three must-find consumers, one must-not-find noise term). Files that *enumerate* the directory: `governance-drift-check.py` (426, 513) · `wake-digest.py` (354, and the selftest sample) · `tarbuckle-invoke.py` (37, 44) · `preserve-transcripts.py` (45, 126, 172). **No additional consumers found.** The other fool surfaces are not consumers: `tarbuckle-wrap.py` and `tarbuckle-seam.py` receive `transcript_path` from the hook payload and never list the directory. **⚠ WHAT THE CENSUS CANNOT SEE — stated as output, not as a caveat.** It is blind to (i) a consumer that builds the path by component join *and* never enumerates `*.jsonl` on a matching line — **demonstrated, not hypothesised: `wake-digest.py` builds `os.path.join(HOME, ".claude", "projects", …)` and escaped a literal-fragment grep over the whole fleet**; (ii) any consumer reaching the population through a hook-supplied `transcript_path`; (iii) anything outside the swept roots. **(i) is PENDING-171's predicate class at a further site, and it applies retroactively to the four-site census in the 2026-09-03 ADDENDUM 1, which was grep-derived by exactly the method shown here to be blind.** The site list should be read as *at least* these, never as *these and no others*. **Options:** - **(a) Nothing.** Leave `human_turns()` in place at its one correct site and abandon the reuse. The four sites keep counting mumbles as sessions. - **(b) A shape predicate at each site** — first `user` record begins with a fool prompt. This is what ground truth used here, so it is known to work today; its predicate is the fool's own prompt text, which drifts, and it is -178 option (b) at four sites instead of one. - **(c) Have the fool mark its own transcripts** — an explicit field written at generation, so the discriminator stops inferring from content. Touches the fool's wiring on behalf of governance instruments (the PENDING-152 coupling), but it is the only option where the signal is *declared* rather than *recovered*. - **(d) -178 option (d): a monotonic counter maintained by wake/wrap.** Fixes unit and window together for the counting site; does **not** by itself fix `previous_transcript`, the selftest sample, or `newest_transcript()`, which need a per-transcript predicate regardless. **Recommendation: (c) for the predicate, and it does not substitute for -178's own ruling.** (b) is available immediately and is what any repair would use in the interim; (c) is the durable form because a mumble that must announce itself cannot be misread by a marker coincidence. ⚠ **Neither is proposed for building now** — the same reasoning that stopped the replacement discriminator applies to its successor: the control set that missed this is the thing to fix first, and that is a design question, not a patch. **Files affected:** none changed. `~/dotfiles/scripts/wake-digest.py` (`human_turns`, `previous_transcript`, selftest sample), `~/dotfiles/scripts/tarbuckle-invoke.py` (`newest_transcript`) are the sites a ruling would touch; `governance-drift-check.py:513` is **excluded on receipt** by the handover and was not examined for repair. **Awaiting:** Steward authorization. ⚠ **Nothing is blocked on this:** step 0 (preservation) ran and the evidence is safe; the repairs are correctly stopped, not stalled. ### AMENDMENT 1 — 2026-09-04 — jurist corrections; and the selftest control does not test its own claim **Filed before any ruling on this item, so it is read with the parent rather than after it** (the PENDING-145 suppression case applies to addenda filed *after* a ruling; this is not one). Five corrections from the jurist, two of which change what tomorrow should do, plus one new measurement that supersedes a claim in the parent's own origin. **1. The credit in the parent's framing is misplaced, and the correction matters more than the compliment.** The record said the handover's ordering held *"at every point it was load-bearing."* **The gate's POSITION held; its CONTENT did not.** As specified, gate 2a was *one arm, one transcript, expected 0*. **Run as written it greens**: 22 of the 24 mumbles return 0, so a single sampled mumble passes with ~92% probability and the repair proceeds. The finding exists because the executor **replaced the specification** — ground truth taken independently of the function under test, across the whole population, with a second `must-not-flag` arm that was not asked for. ⚠ **"Handovers are load-bearing, follow them" is the wrong lesson and the more comfortable one.** The right one: *a gate's existence bought the chance to catch this; improving on the gate's specification is what caught it.* A reader who inherits the comfortable version will run the next gate as written. **2. Gate 2c's census limitation belongs here, not only in a wrap no ruling reads.** The parent reports controls named before execution and a `must-not-find` that fired, which reads as a clean controlled census. ⚠ **It was narrowed three times** — broad reference match, then governed-code-only, then enumeration-only. **Repeated narrowing can terminate by confirming the sites the predicate was built around.** The negative control and the stated blind spots bound that, and do not eliminate it. **Read 2c's "no additional consumers" as the weakest of the parent's three findings.** **3. NEW, and it supersedes the origin claim: the failing selftest control does not test the claim its label states.** Measured live 2026-09-04 on the actual `_tx[-14:-1]` slice: · **slice composition: 1 real session, 12 mumbles** · **verdict `wrapped`: 1 from the real session, 4 FROM MUMBLES** · the control's predicate is `"wrapped" in _v` — **satisfiable by mumbles alone**, so it would pass with **zero** real sessions in the slice. ⚠ **Its label claims "a real session reads as WRAPPED end-to-end."** Its test asks whether *any transcript whatever* drew that verdict. **This is OWED-1's wrong-subject family, inside the control that was supposed to be evidence about mumbles.** ⚠ **It also corrects the 2026-09-03 origin record**, which stated all 13 slice members were mumbles and that the failure was mumble-displacement. The slice holds a real session, and the pass/fail turns on `wrap_verdict` outcomes across an arbitrary population rather than on mumble density. **4. The date of the control's first failing run is STILL NOT ESTABLISHED, and this amendment does not establish it.** The jurist asked for it because a start predating 2026-08-25 would mean the mumble is not the only cause. A reconstruction over the preserved archive found **no date between 08-20 and 09-04 on which the slice held zero real sessions** — but that reconstruction is **not sound for this purpose**: manifest `source_mtime` is snapshot-time rather than current, and the verdict additionally depends on `wrap_events()` git history that was not replayed. ⚠ **Recorded as OPEN rather than answered.** The parent's "intermittent" framing was a better-founded description substituted for the question, which is the same move twice; naming it is the correction. **5. THE SUSPENSION REMOVES REVIEWED-123's BOUND AND MUST CARRY A REPLACEMENT IN THE SAME ACT.** REVIEWED-123 condition 2 holds that *"a hold with no expiry and no visible distance to expiry is how a temporary freeze becomes a permanent one."* **The bound that condition installed IS grading at 84.** Suspending automatic grading at `trigger_fired()` removes exactly that bound and converts a bounded hold into an open one. **The suspension ruling must therefore install a replacement bound in the same act** — tied to the joint -178/-179 ruling, or to the existence of a working session predicate — **with the 2026-09-16 report obligation surviving either way.** ⚠ Otherwise the act recommended to protect the trial's instrument silently defeats the condition protecting the freeze. ⚠ **This bites OWED-5 specifically:** it is a rule about *controls*, routed per condition 3 into a queue that discharges when a *ladder-retrieval trial* grades. The routing is correct and **the coupling is now long**. **6. Unbundle the two acts; the suspension goes first.** The parent's resumption order is (1) `git init`, (2) suspend. But the parent's own *decisions deferred* records the `git init` as a **steward call** — 144 MB, full transcripts, a remote question — so it may wait days. **The suspension is the act with a firing distance: N=65 against 84, 19 away, 13 net in the last measured three days.** The two touch different files and neither depends on the other; serializing them **puts the deadline behind the deliberation.** The docstring stays false in the meantime, **which is the correct state for a docstring describing a thing that is not true yet.** **Awaiting:** Steward authorization, jointly with PENDING-178. ⚠ **Point 5 is a condition on an act already directed, not a new proposal** — if the suspension proceeds without a replacement bound, REVIEWED-123 condition 2 is defeated by the act meant to protect its trial. ### AMENDMENT 2 — 2026-09-04 — the `[FIX]` warrant is void at every site, and the date question is retired by finding **1. THE `[FIX]` WARRANT IS WITHDRAWN. Nothing in the census is currently `[FIX]`-warranted.** Traced rather than accepted. The 2026-09-03 reclassification rested on exactly one argument: *the control's label says "a real session reads as WRAPPED end-to-end", its sample contains no real sessions, therefore restoring the population repairs it against its existing specification.* Verified at source, the predicate is: ``` _v = [wrap_verdict(transcript_span(p), _ev)[0] for p in _tx[-14:-1]] chk(f"a real session reads as WRAPPED end-to-end [{_v.count('wrapped')} of {len(_v)}]", "wrapped" in _v) ``` **`"wrapped" in _v` does not restrict to real sessions anywhere.** So restoring real sessions to the slice **repairs nothing**: the test still passes on mumbles alone, and it would pass on a correctly-populated slice in which **every real session failed**. ⚠ **The defect was never the sample.** The label and the test disagree about their *subject*, and no change to what enters the slice reconciles them. - **Sites 2 and 4** (`previous_transcript`, `newest_transcript`) never had a quoted specification to be repaired against. - **Site 3** had one, and its own implementation contradicts it. - **Site 1** is excluded on receipt and untouched. ⚠ **Withdrawn explicitly rather than left to be superseded**, because *"sites 2–4 are `[FIX]`, merely gated"* is precisely the premise a later session inherits without re-deriving. The 2026-09-03 handover's acceptance of the reclassification is withdrawn by its author; the archived Active Session block carrying it (`MEMORY-reference.md`) is annotated in place rather than edited, since it is a verbatim record of what was believed then. **Consequence for the joint ruling:** whatever replaces the selftest is **a rewrite of the predicate against its label** — a larger act than the one that was reclassified, and not available under any `[FIX]` reading. **2. THE DATE QUESTION IS RETIRED BY FINDING, not open.** AMENDMENT 1 point 4 recorded it as open; that is now withdrawn. The date was wanted to test one inference — *if the first failing run predates 2026-08-25, the mumble is not its only cause.* **The predicate finding settles that without the date.** A test asking whether *any* transcript wrapped has never tested its label, and has not done so **since it was written** — necessarily predating the mumbles. **The mumble is not its cause at all**, nor even a contributing one; it only changed what fills a slice whose composition the test was already ignoring. ⚠ **Recorded as RETIRED so the next session does not spend a morning replaying `wrap_events()` git history for an answer that no longer discriminates.** What the intermittency tracks is total wrap-verdict density — nothing in thirteen wrapped — which is a fact about wrap behaviour and **evidence about nothing in -178 or -179**. **3. TWO VACUITY CLASSES, AND OWED-5 SEES ONLY ONE.** The selftest had **thirteen files in its denominator**. It passes the denominator rule and tests nothing about its subject regardless. | class | shape | caught by | |---|---|---| | **empty-set vacuity** | the control has no cases | **OWED-5** | | **wrong-subject vacuity** | full denominator, predicate does not implement the label's subject | **OWED-1's family — not OWED-5** | ⚠ **Stated so OWED-5 is not over-trusted on the strength of having been earned the same week.** The wrap's open question — *how many fleet controls have a denominator of zero* — is worth running and now has a **harder, more common sibling: how many controls have a predicate that does not implement the subject named in their own label.** The selftest is the demonstrated instance, which makes this a **recurrence of OWED-1 rather than a discovery**. **Awaiting:** Steward authorization, jointly with PENDING-178. ⚠ **Three of this item's four load-bearing claims have now been corrected by the jurist or by re-measurement within 24 hours of filing.** That is the configuration working, and it is also a reason to read the remaining claims as provisional rather than settled. --- ## PENDING-180 — The self-planted needle recurs in the polarity `source_lacks()` does not cover, and PENDING-168's evidence base changes before it is ruled **Date:** 2026-09-09 **Tag:** [FIX] **Summary:** `tarbuckle-seam.py:164` asserts `"line[:200]" in src and "log_silence(why, line)" in src` against its **own** source, where both literals appear inside the assertion itself. It has passed vacuously for its entire life. Filed tonight rather than with the `[FIX]` because PENDING-168 is due for a ruling and its evidence base is wrong until this is in the register. **The finding that is not a tally mark.** PENDING-168's instance two is *"the self-planted needle written twice while watching for it"*, and `source_lacks()` was built as the mechanism so the shape could not be written again by accident. Its own docstring states the bug: *"A control that writes its needle as a literal PLANTS that literal in the very file it searches, so it can only ever fail."* ⚠ **That mechanism covers one polarity only.** `source_lacks()` guards the **negative** form — *this string must be ABSENT* — where self-planting makes the control always fail, loudly. The recurrence is the **positive** form — *this string must be PRESENT* — where self-planting makes the control always **pass, silently**. The louder failure got the mechanism; the quieter one did not, and it is the one that hides. **The structural fix was scoped to the direction that announces itself.** **Two lines below the docstring that names the bug.** `source_lacks(__file__, "FALLBACK", "_LINE")` sits at `tarbuckle-seam.py:166` — correct, needle assembled from parts. The defective control is at 164, immediately above it, in the same `ck()` block, written in the same sitting. **What it was supposed to guarantee, and does not.** *"S3 rejection log keeps the evidence, not just the verdict."* It cannot see whether the seam's rejection path does anything at all. Demonstrated today: `REJECT_LOGGING_ENABLED = False` made the entire rejection write path inert across all four surfaces (REVIEWED-136 AMD 1 condition G) and this control **did not move** — 15/15 before, 15/15 after. A behavioural control caught it; a source-string control could not. **⚠ PENDING-168's count, stated precisely rather than incremented.** The doctrine names **four instances**, one of which ("the self-planted needle") already covers **two occurrences**. This is a **third occurrence of that instance**, so the evidence base goes from five occurrences to six while the number of named instances stays four — unless the steward reclassifies. **The unit of the count is the decidable question**, which is PENDING-146's CLASS E defect arriving inside the item that is about to be ruled. Recorded this way so a ruling does not enshrine "fourth instance" or "fifth" without choosing which is meant. **⚠ PENDING-168 now carries TWO corrections and should not be ruled before both land.** (1) Its summary says *"care failed in seven hours"*; REVIEWED-136 corrects the interval to **2 h 33 min 24 s**, measured from receipt. (2) This item. Neither weakens the doctrine — the interval tightens it and this occurrence shows the structural fix was under-scoped — but both change what a ruling would be ruling on. **Options:** - **(a) Fix the one control** — assemble the needle from parts, as `source_lacks()` does. Repairs the instance. - **(b) A positive-form counterpart to `source_lacks()`** — `source_has(path, *parts)`, joining its needle from fragments so it cannot self-plant. Repairs the class in the direction that was missed. - **(c) Census first** — sweep every `in src` / `in source` assertion across the governed scripts for self-planted needles before repairing any, since the polarity argument predicts more of them and one instance is not a census. **Recommendation: (c) then (b) then (a).** The polarity finding predicts siblings, and repairing the one found before knowing how many exist would be the instance-not-class error the executor directives name. ⚠ The census must state what it cannot see: a needle assembled from parts in a *defective* control is indistinguishable from a correct one by grep, so the sweep bounds the problem from below. **Files affected:** `~/dotfiles/scripts/tarbuckle-seam.py:164`; a new helper beside `source_lacks()` in `tarbuckle-mumble.py` under (b); whatever (c) surfaces. **⚠ THE CLASSIFICATION IS DEFERRED, AND THE DEFERRAL BINDS THE FORM OF THE RULING RATHER THAN AWAITING ONE.** Whether this is a fifth *instance* or a third *occurrence* of the second instance is not decided here, deliberately: deciding it inside a filing would be CLASS E arriving in the item about to be ruled, with the drafting hand choosing the unit that suits its number. **The constraint on PENDING-168's ruling is therefore procedural: it must state WHICH UNIT it counts in — named instances, or occurrences — BEFORE it states a number.** A ruling that gives a count without its unit is not to be read as having settled the count. Recorded as a deferral so it cannot resolve itself in whichever direction next week's drafting prefers. **Awaiting:** Steward authorization. ⚠ **Nothing is blocked:** the control's vacuity costs nothing today, because the behaviour it failed to guard was verified behaviourally in the same sitting. What is time-sensitive is only that PENDING-168 not be ruled on an evidence base this item changes. ### ADDENDUM 1 — 2026-09-09 — (c), (b) and (a) executed; the census answers ONE; and the mechanism has a gap it cannot cover **Filed before any ruling, so it is read with the parent rather than after it** — the PENDING-145 suppression case applies to addenda filed *after* a ruling, and this is not one. The parent's recommendation was **(c) census → (b) positive-form counterpart → (a) fix the instance**. All three ran, in that order, on steward instruction the same evening. **(c) CENSUS — the polarity argument predicted siblings, and there are none.** Fifteen positive-form source assertions across eight governed scripts (`tarbuckle-*.py`, `governance-drift-check.py`, `wake-digest.py`, `thread-query.py`). **Exactly one self-planted needle: the one this item filed**, `tarbuckle-seam.py:165`. Controls named before the run: one must-find (the filed instance), two must-not-flag (`TimeoutExpired` and `log_silence(why, line)`, both occurring at real code sites). All three passed. ⚠ **The bound the parent required is restated because it still holds: a needle assembled from parts inside a *defective* control is indistinguishable from a correct one by this method, so the census bounds the problem from below.** ⚠ **THE FIRST CENSUS CARRIED THE DEFECT IT WAS AUDITING, and this is recorded rather than quietly corrected.** Its discriminator was *"the needle occurs once in the file"*. That cannot separate a self-planted needle from a **correct** control whose assertion escapes its quotes — where the single occurrence is the real code site. It misflagged `tarbuckle-seam.py:163`, a correct control, as self-planted. Caught by verifying the finding against the file before reporting it, not by the census. Corrected discriminator: **every occurrence of the needle lies on the assertion's own line.** The parent's own class — a predicate that does not implement its label — arriving inside the sweep filed to find it. **(b) `source_has()`** now sits beside `source_lacks()` in `tarbuckle-mumble.py`, needle assembled from parts by the same mechanism, carrying the polarity argument and the behavioural limit in its docstring. It ships with the must-fail arm the negative form has had since it was written (`A10` / `A10n`). ⚠ **A third arm was written and then removed before commit** — its predicate did not implement its label. Shipping wrong-subject vacuity inside the fix for self-planting would have been the parent's other class, in the parent's own repair. **(a) `tarbuckle-seam.py:165` repaired.** The needle was aimed at **this seam's own source** for a string that exists only in `tarbuckle-mumble.py:142` — it could never have found it, and could only ever pass on the copy it had planted in itself. Now aimed at the writer's file, split into two arms that assert different things (*the canonical writer keeps the evidence* / *this seam routes rejections through that writer*), plus `S3nn the predicate can fail`. **VERIFIED BY MUTATION, NOT BY A GREEN SELFTEST — which is the whole point and was not optional here.** | mutation | repaired control | old form | |---|---|---| | seam stops routing rejections through the canonical writer | **FAIL** | **passes** — the defect, demonstrated | | control aimed at a file lacking the needle | **FAIL** | — | **136 controls green across the five surfaces** (`body` 32 · `mumble` 41 · `seam` 17 · `wrap` 25 · `invoke` 21). ⚠⚠ **A NEW GAP, AND IT IS IN THE MECHANISM ITSELF RATHER THAN IN ANY CONTROL.** The first mutation did **not** fail on its first run. Cause: the repair's own explanatory comment named the truncation literally, **planting a contiguous copy of the needle in the file being searched — re-creating this bug inside the sentence explaining it.** `source_lacks()` and `source_has()` assemble the **assertion's** needle from parts; **nothing prevents a comment, or any other prose in the same file, from planting a contiguous copy.** The mechanism covers the assertion, not the file. Caught by the mutation test; **invisible to the selftest, which was 17/17 throughout.** The repaired file now carries a warning at the site. ⚠ **THE COUNT IS NOT INCREMENTED, DELIBERATELY.** The comment above is a further occurrence of the self-planting shape, and the third written by a party actively watching for it. **The executor declines to count it.** This item's own deferral binds PENDING-168's ruling to state its unit before its number, and the drafting hand choosing the unit that suits its own number is exactly the CLASS E move the deferral exists to block. Recorded as an occurrence; **the unit remains the steward's.** **Files affected:** `scripts/tarbuckle-mumble.py` (`source_has`, `A10`/`A10n`), `scripts/tarbuckle-seam.py` (import, `S3` split into three arms, the prose warning). **Awaiting:** Steward authorization on the parent. ⚠ **What remains for a ruling is smaller than when this item was filed:** (c), (b) and (a) are executed and the repair is mutation-verified, so the item is **dischargeable on a ruling that settles its count unit**. The new gap above is a separate decidable question and is **not** bundled here — filing it inside this addendum would reproduce the CLASS E defect PENDING-146 names, in the item that just declined to commit it. ## PENDING-181 — The paste is the last unremedied transit path, and PENDING-150 routed its remedy here three weeks ago **Date:** 2026-09-10 **Tag:** [PROPOSAL] **Summary:** Extend REVIEWED-82's read-only server to cover executor session reports, so the jurist reads them rather than receiving them by hand. Steward-originated. The go-between agent form is DECLINED and routed to PENDING-150. ### The problem, with its instances Three recorded corruptions of the register by the transit path itself: 1. **PENDING-150 AMD 3** — *'The ruling's subject was the pasted text, not the filed artifact.'* Diagnosed 2026-08-25, carried forward as structural. *'No remedy ruled; it belongs to PENDING-82.'* 2. **REVIEWED-136** — the executor's positive replacement clause was offered and not pasted, leaving the entry asserting a timestamp it never established. Found by `grep -c` returning 0, a day later. 3. **REVIEWED-137** — the executor's draft wrapping leaked into the placed record and broke the title across two lines. The header terminated at 'designed but not', with 'authorized' orphaned. **The meaning inverted at the break**, in the string the digest takes as the entry's name. The steward is the transit path and reports the clerical load as the sitting's dominant cost. ### What PENDING-82 settled and what it left REVIEWED-82 established the principle in its own words: verbatim reading is *the capability a pasted cache can never have*. It covers six enumerated governance documents. It does not cover the executor's session reports, measurements and preflight output — which is the bulk of the traffic and the source of all three defects above. ### Proposed **Asymmetric, because the two directions are not the same problem.** **Executor → jurist.** A new read key exposing a handoff document the executor writes with its ordinary tools. The server's safety property is unchanged: nothing writes, no paths accepted, keys from a fixed list. The jurist reads by key instead of receiving a copy. **Jurist → executor.** UNCHANGED. One block, and it is the authorization direction. The steward's act belongs exactly where it is. ### DECLINED — the go-between agent Considered and declined, recorded so it does not recur as a fresh idea. 1. **The bound that would make it safe makes it not an agent.** Anything beyond moving bytes — deciding relevance, compressing, answering on either party's behalf — is a fourth LLM in the transit path of a system whose central problem is LLM contamination, and its failures are silent: a relay that drops a clause looks exactly like one with no clause to pass. A strictly verbatim relay is a pipe, and pipes are scripts. 2. **PENDING-150's caveat transfers and worsens.** A Claude-formation relay makes four parties of which three share formation, sitting in the path every finding crosses. 3. ⚠ **The bound would be behavioural.** Tarbuckle is the bounded position done right — no filing route exists, no executive path exists, structurally. A relay instructed to relay faithfully is bounded by instruction, which is the class that failed silently in `tarbuckle-wrap.py` for two weeks. **If the steward wants the agent form considered, it is an amendment to PENDING-150**, which is [ESCALATE] and open. It is not this item. ### ⚠ The cost, stated rather than discovered This removes the steward from the path where he currently reads. **The honest form is worse: the paste is a fake reading guarantee.** On 2026-09-01 every figure passed through the steward's hands and neither steward nor jurist saw condition 3 — the miss recorded in REVIEWED-136 §PENDING-89. The implicit read the paste appears to guarantee is already unreliable. **So the trade is an unreliable implicit read for a designed explicit one, and the design of that read point is a condition of this proposal, not an afterthought.** An authorization that does not name where the steward reads should be a REJECT. ### Open questions the ruling must settle 1. **Ephemeral or retained?** Retained lets the jurist re-read past handoffs, which serves the *conflict between two records is a verification trigger* doctrine. It also creates a new persistent store that nothing governs — the shape condition G spent a sitting on. 2. **Is the handoff in the register's scope**, or outside it as `tarbuckle-draws.jsonl` is? 3. **Written when** — every executor turn, or at named handoff points only? 4. **Where does the steward read**, per the cost clause above. ### Files affected The governance MCP server configuration (`claude_desktop_config.json`, per PENDING-82). `~/CLAUDE.md` NOT affected — no position is added and the three-party model is unchanged, which is what distinguishes this from PENDING-150. **Awaiting:** steward authorization, and a ruling on the four questions above. Do not proceed. **Related:** PENDING-82 / REVIEWED-82 (parent) · PENDING-150 AMD 3 (the routing) · PENDING-161 ('the jurist has no substrate access' is false and in a placed ruling) · PENDING-86. ## PENDING-182 — The three-field counter: what judgment 2 needed and did not have, as an extension of `log_event` rather than a successor to `log_rejection` **Date:** 2026-09-10 **Tag:** [PROPOSAL] **Summary:** Add `tick_id`, `words` and `reason_category` to the occurrence counter, structurally content-free by construction. Drafted, not ruled. **Condition G is not lifted by this item and this item does not ask for it to be.** ### What the sitting needed and could not get REVIEWED-137's judgment 2 was recorded **UNANSWERABLE**, and the reason was a missing join, not missing evidence. Terminal draws are written by a detached child, so a rejection's timestamp records the child's **completion**, never the tick that caused it. Pairing rejections to ticks within 120 s over fourteen days: | | pairable ≤ 120 s | not | |---|---|---| | the five 14-word days | 6 | **44 (88%)** | | all nine other days | 51 | **1 (2%)** | A partition with no exceptions in either direction. **One opaque integer written at both ends would have decided it.** It did not exist because nobody had yet asked the question that needed it. ⚠ **The decisive findings of that sitting came entirely from timestamps, counts and surface labels.** The content field bought nothing and cost the corpus. That is not an argument from principle; it is the case, and it is what makes this proposal smaller than the instrument condition G was written against. ### The shape **An extension of `log_event(surface, outcome)`, not a successor to `log_rejection`.** The reframing is the load-bearing part: `log_event` is the counter §8 obliges and §9 permits — *"it records THAT something happened and never WHAT was said"*. Adding fields that are structurally incapable of carrying an utterance keeps it in that settled category. `log_rejection` remains inert under REVIEWED-136 AMD 1 condition G, untouched by this item. - **`tick_id`** — one opaque id allocated at the tick and carried to whatever the tick produces. **Named by two failures, not designed**: it is the field judgment 2 needed, and the field the deleted corpus could not be re-binned without. ⚠ **Allocation site is an open design point, not decided here.** `tarbuckle-last-tick` is a single machine-global path with no session key, so where the id is minted determines whether it can distinguish two panes drawing in the same minute — which is the whole question it exists to answer. - **`words`** — an integer. Already computed inside `acceptable()` as `n`; today it is formatted into a reason string and thrown away. - **`reason_category`** — a closed enum (`empty` · `not-one-line` · `word-count` · `banned` · `echoes-soul`), never a free string. Today's `why` values are already near-content-free, but they are *free text*, and one of them — `banned {pat}` — carries the pattern that matched. Freedom is the defect: nothing prevents a later edit from widening a free string, and one already quoted four words of a suppressed line. ### Two conditions that must not be lost in drafting **Condition A — the write path cannot leak because the content is never in its scope.** `acceptable()` returns `(ok, category, n_words)` and the logger takes **no string parameter at all**. This is stronger than a logger that receives a string and declines to write it: a reviewer can settle the question from the signature, without reading the body, and no later edit can reintroduce the leak without changing the signature. **The property is structural or it is not claimed.** **Condition B — the `co_names` control must be SHOWN TO FAIL against a deliberately leaky signature before it is trusted.** Run as a probe in the sitting that produced this item: **the form cited in REVIEWED-137 §3 — the `co_names` idiom at `tarbuckle-body.py:256` — is INADEQUATE.** It catches a parameter obviously named `payload` and **passes a parameter named `why`**, which is the leak that actually existed. `co_names` lists referenced globals and attributes, not parameters, so a logger that accepts and writes a reason string is invisible to it. ⚠ **FORM B is the adequate one: assert the logger's exact declared parameter tuple** (`co_varnames[:co_argcount]`), so any added parameter fails the control by construction rather than by naming taste. ⚠ **And it is a positive-form introspection assertion in the file family where the vacuous-pass bug lives.** PENDING-180 ADDENDUM 1 §6 records that the repaired mechanism covers the **assertion**, not the **file** — prose in the same file can still plant the needle. **Do not rely on this control unmutated.** ### What this does not do, stated so a ruling is not read as broader than it is ⚠ **It must be paired with a non-event measure, and this item does not supply one.** A counter of rejections cannot see **tick starvation** — the one genuine presence miss (`736ef3cb`) was attended human work where the fool was *never asked*, and that leaves no draw, no rejection and no trace. Every instrument built to date is blind to it. A ruling that authorizes this alone buys the join and not the gap. ⚠ **The bounded claim, restated because it is the one most likely to be overread:** the hard content-free form was not needed for *this* case, and **no case requiring it has been constructed**. That is not "condition G dissolves" — the jurist corrected that reading and was right. **Files affected:** `scripts/tarbuckle-mumble.py` (`log_event`, `acceptable` return shape), the four seam call sites (`body`, `mumble`, `seam`, `wrap`, `invoke`), and wherever `tick_id` is minted — `tarbuckle-body.py`'s tick path, pending the allocation-site decision above. **Awaiting:** Steward authorization and a jurist design gate. ⚠ **Nothing here is built.** Condition B's probe has been run and its result is reported above; the fields do not exist. **Related:** REVIEWED-137 §3 (the instrument designed, not authorized) · REVIEWED-136 AMD 1 condition G · PENDING-180 ADDENDUM 1 §6 (the assertion-versus-file gap) · PENDING-152. ## PENDING-183 — CARRIER: the eleven open items from the verdicts sitting, named so they can be aimed at **Date:** 2026-09-10 **Tag:** [HARDENING] **Summary:** Naming, not investigating. Each line is one open item carried out of the 2026-09-09 sitting's carry list, which lived in a daily note. **No item here is authorized for work.** **Why a carrier and why the register.** The sitting's own finding was that *the register's vocabulary determines what can be aimed at* — `tarbuckle-wrap.py` had never been named in a ruling, so a cap change was pointed at the wrong file for two weeks and nobody could see it. A carry list in `01. Daily/2026-09-09.md` is where these die. ⚠ **A carrier is not a ruling and confers no authorization**; PENDING-143's form. 1. **The lag/pile-up partition — mechanism UNKNOWN.** ⚠ **AND THE NUMBER IS IN DISPUTE, WHICH IS THE FIRST THING TO SETTLE.** The banked table (REVIEWED-137, judgment 2) states **6 pairable / 44 not, of 50** on the five 14-word days and **51 / 1, of 52** on the nine others. The scoping brief states the same finding as **45/45 and 0/9**. Both describe one measurement; **neither statement carries its unit, and they are not the same population** — 9 is the day count of the second row, which suggests one figure counts rejections and the other days. **Recorded unresolved rather than reconciled by the drafting hand**, which is the whole subject of the thread this sitting inherited. `timeout=120` rules out generator latency; sleep is unsupported. 2. **The render-volume hypothesis — first to test, and its plausibility IS the hazard.** It explains the pattern and it is untested. PENDING-164's class. ⚠ **Do not reason from it.** Nothing downstream may rest on it until it is measured. 3. **Tick starvation, and the non-event measure it needs.** `736ef3cb` is the one genuine presence miss and it is a different failure: attended human work where he was **never asked**. No draw, no rejection, no trace. **Every instrument built to date is blind to it**, PENDING-182 included. 4. **`tarbuckle-last-tick` — a machine-global allocator with no session key, and ZERO register mentions.** The draw is a race won by render frequency: on 08-31 two abandoned panes took 48 attributed draws, the 16.7 MB working session 7, a 50-minute human session 1. Same shape as `tarbuckle-wrap.py` — unnamed, therefore unaimable. 5. **`Stop` fires for `claude -p`, so wrap re-entered its own generator — CLOSED for recurrence, `7948c09`, today.** ⚠ **Residue: the 3 of 10 historical runs are in the record and no instrument distinguishes them.** Any figure computed over wrap occasions before this commit includes them. 6. **The assertion-versus-file gap.** `source_has()`/`source_lacks()` assemble the **assertion's** needle from parts; nothing prevents a comment, or any other prose in the same file, from planting a contiguous copy. **Deliberately unbundled from PENDING-180**, whose ADDENDUM 1 §6 declares the repaired mechanism verified. 7. **PENDING-179's predicate covers one of TWO generator prompts.** Ground truth is written against `You are writing ONE line as Tarbuckle.` (the mumble); eight transcripts open with the seam/wrap/invoke prompt instead. **The classifier is not binary and the predicate knows one half.** 8. **The 925 s `SessionStart` outlier.** Unexplained; one occasion. 9. **PENDING-178's population figures are superseded** (44 → 29 real, restated 2026-09-09). ⚠ **And re-measured today: N-now = 59 by the trial's own method, split 31 real / 28 mumble by a first-user-turn predicate that knows both prompts of item 7. The banked 41/24 (36.9%) used the ONE-prompt signature, so the two composition figures are NOT commensurable** and the apparent rise to 47.5% is partly a change of instrument. Item 1's defect, in the figure the trial reports. 10. **`sysupdate` auto-commits into `~/dotfiles`** — `bf1bd80` is one. A second author in the tree the wake reasons over, on nobody's authorization. PENDING-165's class. 11. **The register cites code by line, and lines move — TWO CONFIRMED STALE CITATIONS IN PLACED RULINGS, one of them caused today.** ⚠ **REVIEWED.md:2993 cites `tarbuckle-wrap.py:236` for the 12-word control; today's `[FIX]` moved it to :256** — verified by exact match against `HEAD~1`, and **the executor is the cause**. ⚠ **REVIEWED.md:3104 cites `tarbuckle-mumble.py:123` for `log_rejection`'s append-mode open; it is at :139 today** — drift date **unestablished** (a `git show` probe returned nothing and that is a fact about the probe, not about the file). `seam` moved twice in two days. **A line number in a placed ruling is a claim with a short half-life and nothing re-checks it.** **Files affected:** none — this item names, it does not touch. **Awaiting:** Steward and jurist triage of which of the eleven become items in their own right. ⚠ **Items 1, 2 and 6 are the ones where silence costs most**: 1 because two numbers are live, 2 because an untested hypothesis is attractive enough to be reasoned from, 6 because a ruling already declares the mechanism verified. ### ADDENDUM 1 — 2026-09-10 — Item 1 CLOSED by the jurist's correction; item 11 is established, load-bearing, and one citation was stale the day it was written **Filed before any ruling, so it is read with the parent rather than after it.** **ITEM 1 IS CLOSED, and the two numbers were never in conflict — only the label was.** The jurist has withdrawn and corrected its own sentence, which is the one that certified the partition: *"`45/45` and `0/9` is not an association. It is a partition with no exceptions in either direction, on fourteen days."* - **`45 of 45` fourteen-word rejections fall on the five days; `0` of the other `9` days carries one.** These are the **pile-up** statistics. ⚠ **Their denominators are rejections and days respectively — two units inside one ratio, before any label was attached.** - **`44 of 50` rejections unattributable on the five days; `1 of 52` on the nine others.** These are the **lag** statistics. - **The partition claim is the CO-OCCURRENCE of the two**, and the pile-up's numbers were attached to it. **The corrected statement, which supersedes both readings:** > **At day granularity the partition is exceptionless: 14 days, 5 carrying both symptoms, 9 carrying neither. At rejection granularity it is not — 6 of 50 and 1 of 52 sit on the wrong side. The claim is about days.** ⚠ **The part the jurist asked be kept in the record: *"no exceptions in either direction" is true only at day granularity.*** The clean partition was asserted using numbers drawn from a level at which it is not clean. **This is the pulling thread firing inside the sentence that certified the finding** — not in the measurement, and not in a stale record, but in the act of labelling a true number with the wrong population. Nothing downstream of judgment 2 changes; the mechanism remains **UNKNOWN** and item 2's guard stands. **ITEM 11 — BOTH CITATIONS NOW ESTABLISHED WITH THEIR COMMITS, and the second is worse than "lines move".** | placed ruling cites | actual location | moved by | |---|---|---| | `tarbuckle-wrap.py:236` (REVIEWED.md:2993) — the 12-word control | **:256** | **`7948c09`, today, by the executor** | | `tarbuckle-mumble.py:123` (REVIEWED.md:3104) — `log_rejection`'s append-mode open | **:139** | **`3d45e3a`, 2026-09-09** | ⚠ **THE SECOND CITATION WAS STALE ON THE DAY IT WAS WRITTEN.** The append-open sat at `:123` from `b95ee73` (2026-08-25) through `97a0cb3`, and moved to `:139` at **`3d45e3a`** — which is the condition-G commit REVIEWED-136 ordered. REVIEWED-137 was placed at `3d340f6`, **after** it. **A ruling cited a line invalidated by the very commit it was ruling on, the same evening.** This is not decay over time; it is a citation that never held. ⚠ **AND THE PARENT'S OWN "drift date unestablished" WAS WRONG FOR THE REASON THE PARENT NAMED.** The `git show` probe that returned nothing returned nothing because of the probe: it was silently dropping its path argument on some invocations and printing commit diffs instead, which is why it once reported a match at "line 13327" of a 500-line file. Re-run with explicit argv and no shell quoting, it resolves in one pass. **Two null results in one sitting, both facts about the query** — the rule fired the first time and was still not enough to stop the second. **DISPOSITION CHANGE: item 11 moves from observational to LOAD-BEARING.** Two placed rulings are already wrong, one of them from the day it was placed, and nothing re-checks any of them. ⚠ **Recommended remedy, not authorized here: anchor register citations to SYMBOLS OR CONTENT rather than line numbers** — the same reasoning that makes `source_has()` assemble its needle from parts. A line number is a claim with a half-life measured in days. ⚠ **THE CITATIONS ARE NOT TO BE CORRECTED BY EDITING.** A placed ruling is amended by a recorded act. The errata entry is drafted for steward placement; **no in-place revision has been made, and the temptation to make one has now arisen twice this week.** **Awaiting:** unchanged for the remaining nine items. Item 1 is closed; item 11 awaits a ruling on the anchor remedy. ### ADDENDUM 1 — 2026-09-10 — Executor: two further instances, found by checking, and a measurement that narrows the mechanism **Filed by the executor into a steward-originated item**, because it supplies the instances the item's argument turns on. No part of PENDING-181's proposal is amended. **Instances 4 and 5, both in entries placed today, both found within minutes by an exact-string check rather than a reading.** - **REVIEWED-138's title broke across two lines**, terminating at *"under a per-control reading of"* with *"instance four)"* orphaned below. **This is instance 3 recurring — same failure, same week, in an entry drafted to be quotable, in the sitting that filed this item about it.** - **REVIEWED-139's table lost a row and half of another.** The separator row and the entire `tarbuckle-wrap.py:236 → :256 / 7948c09` row are absent; the remaining row survives only as the dangling fragment `` **`3d45e3a`, 2026-09-09** | ``. ⚠ **The errata entry whose subject is citations that do not hold currently holds neither of its two citations correctly.** **THE MEASUREMENT, WHICH NARROWS THE MECHANISM AND ALSO REFUTES THE OBVIOUS READING.** - The 68 non-empty lines placed today cap at **156 characters**, clustered at 147–156, with 28 over 150. That is a hard wrap at roughly column 150. - ⚠ **The rest of the register is NOT wrapped: 2,680 lines, longest 2,184 characters, 502 of them over 150.** So wrapping is not a standing property of the transit path, and **why today differs is UNESTABLISHED.** Recorded as unexplained rather than attributed, because the attractive explanation is untested. **What the damage is predictable from, and this part IS established:** the wrap destroys exactly those constructs where a newline is semantic — a `##` heading ends at the newline, and a table row is a line — while prose reflows harmlessly. **Every corruption in this item's list is a heading, a table row, or a clause; none is a paragraph.** ⚠ **THE CHEAP MITIGATION, AVAILABLE TO THE EXECUTOR TODAY AND NOT REQUIRING THIS ITEM'S PROPOSAL:** draft headings and table rows **short enough that no wrap can reach them**, and prefer **bulleted lists to tables**, since a wrapped bullet continues as the same bullet while a wrapped row is destroyed. This does not replace the item's remedy — it removes the executor's contribution to the failure while the remedy is decided. ⚠ **AND THE FINDING THAT MATTERS MOST FOR THE ITEM'S ARGUMENT: both defects were found by running a check, not by reading.** Instance 2 was found by `grep -c` a day later; these were found in minutes because the placement was verified against the draft with exact strings and a negative control. **The transit path is not self-reporting, and nothing in the current arrangement checks a paste except a party deciding to.** **Awaiting:** unchanged — steward authorization on the parent proposal.