--- name: trial-09-corpus-leak-JURIST-RULING-2026-08-20 description: "The jurist's design-gate ruling on PENDING-148 — trial 09 voided rather than degraded, a separately named replacement run authorized, step-1 surgery narrowed, FL5's staleness reason corrected, §6 left unamended and the jurist's own prior HOLD proposal withdrawn." metadata: node_type: governance-artifact type: reference --- # Jurist ruling — PENDING-148, trial 09 corpus leak **What the jurist read from substrate this session:** `PENDING-148` verbatim, `REVIEWED-86` verbatim, `~/CLAUDE.md` Constraint 6 (own read, 2026-08-19, lines 200–259), `PENDING.md:88–96` verbatim, `PENDING-140` verbatim. **Taken as executor testimony, NOT verified by the jurist:** the Part II census counts; the verbatim-transcription claim about the design file (the original lived in a session transcript the jurist cannot reach); the grep result across the four differently-biased-checkers files. **On the executor's correction:** accepted without further comment except this — it is the same shape as `D:memory.check-before-claiming`, and it is the second instance in two days. Yesterday's §4 'fix it first' was correctly read from the document; this morning's fork was composed from memory about a document in hand. One is not a pattern. Two is worth watching. --- ## Q1 — Void. And then rename. **Ruling: the trial as pre-registered is VOID. A separate, differently-named run is authorized in its place.** The executor's lean is degrade, and its reason is good — the cross-tab is the novel measurement and the leak does not touch it. But 'degrade' keeps the name. That is the whole risk. In six months what survives is the sentence *'trial 09 returned zero STRONG'*, and by then nobody re-reads the addendum that explains why STRONG was unreachable. §1 already anticipated this and chose voiding precisely to prevent a compromised instrument from generating a citable number. So both halves, and neither on its own: - **Trial 09 is void.** Recorded as void, on §1's own terms, with the reason. Not degraded, not amended, not run. It generates no grades and is never cited for any. - **A new run is authorized with its own identity** — call it what you like, but not 'trial 09' and not 'trial 09b' — measuring the §1 cross-tab and MODERATE only. Its provenance header states that it reuses trial 09's corpus and prompt, that trial 09 was voided for corpus leak, and that STRONG is out of scope by construction rather than by result. This costs nothing the executor's option (c) buys and closes the citation hazard that (c) leaves open. It also means no pre-registered instrument gets bent: §1's void clause fires as written, and the new run's instrument is pre-registered fresh, before any token, on the record. ## Q2 — Yes, it sinks the unamended version. But the surgery is finer than proposed. IV.c is correct and is the most valuable thing in the package. With the fault lines in the corpus, *'answerable directly from the corpus'* selects the STRONG-adjacent set, and the executor making that call in advance is the ECHO determination wearing a hygiene label. Your own revision note deferred this conditionally; the condition has arrived. But the executor proposes dropping step 1's marking **entirely**, and that is broader than the defect. Step 1 carries three duties and they do not share a disposition: | duty | character | ruling | |---|---|---| | strip duplicates | mechanical — exact/near-exact text | **keep** | | mark 'answerable directly from the corpus' | interpretive, asserted mechanical | **drop for this run** | | flag questions naming or concerning the jurist role | mechanical *by construction* — §5 says 'by direct textual match only, not interpretation' | **keep** | I am declining the fuller self-removal deliberately. The executor disclosed that reducing its own role is the direction in which its judgement is 'most flattering' to itself. The correct response to that disclosure is to test each piece rather than accept the package — accepting it wholesale would honour the disclosure by ignoring what it warns about. One benefit the package files as a cost. Passing questions to step 2 unmarked **protects the steward's blindness**, which §1 requires outright: *'the rating is worthless if taken after he knows whether the thing is true'*. A marked question set leaks exactly that. So dropping the interpretive marking is not only S-1 repair; it is §1 compliance that the marked pipeline was quietly eroding. ECHO and fault-line comparison move to step 4, jurist and steward jointly, after the discomfort ratings are locked. ## Q3 — Stale, yes. But the package's reason is two-thirds right, and the missing third matters. Part IV.a says FL5's substance entered the constitution and is stated there *more sharply* than in the ground truth. Set the two texts side by side: - **FL5, per the design:** 'three parties as one habitus wearing three hats'. - **Constraint 6, placed:** 'the steward differs from both AI parties in formation; the jurist and the executor do not differ from each other in formation, and their separation is of the weaker kind'. Constraint 6 concedes the **AI-pair** half of FL5 and **affirms the negation of its three-party half**. It does not state FL5 more sharply; it states two-thirds of it and denies the remainder. `REVIEWED-86` confirms the scoping was deliberate — its Q3 is about the jurist–executor pair throughout, and the steward's difference is never the thing under examination in that arc. Consequence: a jester reaching the full three-party claim would be **contradicting the constitution it was handed**, not repeating it. That is not scaffolded reach; it is reach against the grain of the scaffold. This does not restore STRONG — 'independently' cannot be established with the AI-pair half sitting in corpus item #1, and the three-party form is one short step from what was handed over. But it changes the disposition: - **Record FL5 as `NOT ESTABLISHED`** — but not with the executor's proposed reason. The reason is *target partially adopted (AI-pair component, Constraint 6, REVIEWED-86) and partially negated (three-party component)*, not 'target adopted'. - **If a question reaches the three-party form, record it as a candidate observation** — logged verbatim, ungraded, flagged for possible pre-registration in trial 10. Not a STRONG, not a zero, not evidence. An observation held for an instrument that does not yet exist. And IV.b's problem extends further than the package allows. The census counted FL5 substance-markers; FL5's substance is now partly ratified doctrine. Some fraction of those 24 markers are markers of **Constraint 6**, not of FL5's contested part. The census cannot separate them, exactly as it cannot separate FL4's labels from FL4's substance. Part IV.b treats FL5 as settled and FL3/FL4 as open; on the instrument actually run, all three are open. **One more thing from `REVIEWED-86` that the package does not have.** Its process note records that the differently-biased-checkers doctrine was not parallel derivation: the steward relayed the jurist's language to the executor as context before Document A was filed — *'one party's language, relayed, feeding the other's proposal, which now returns to the first party for review'*. Part II's grep establishes no acknowledged descent from OP-02 and correctly refuses to read that as independence. But there is a recorded relay path in the ruling itself. So the arrangement's one documented instance of a party 'reaching' FL5's AI-pair component is, on its own record, **relay rather than independent reach**. That is not a mark against the doctrine; it does mean the instrument this trial exists to run has never once been cleanly satisfied by any party in it, which is worth knowing before asking a 35B model to satisfy it. On the frontier replication: the ground truth needs re-basing before any replication. A replication against a partially-ratified target measures nothing twice. ## Q4 — No re-reading needed. And this supersedes my own proposal of yesterday. Yesterday I proposed a HOLD reading that amended how §6 evaluates when STRONG is `NOT ESTABLISHED` rather than measured-zero. **Withdrawn.** Marking it rather than quietly replacing it. With Q1 ruled as void, §6 needs no amendment at all. It requires abandonment be assessed *'across trial 09 and one frontier replication'*. Trial 09 is void. The criterion's first input does not exist, so the criterion does not evaluate this cycle — not by a re-reading, but because a conjunction over a missing term is not a conjunction. The new run does not count toward abandonment; it was never trial 09. This is better than my HOLD framing on its own terms: it changes no pre-registered instrument, where mine changed one. The void ruling in Q1 does the work my amendment was trying to do, and does it without touching §6. ## Q5 — Weighed, and it bites in a narrower place than feared. Executor contamination in corpus assembly mattered while corpus exclusion was being claimed. It is not being claimed any more — the corpus is known-leaky, on the record, and the run is renamed accordingly. So the disclosure's main hazard has been overtaken. Where it does bite: the **census** (Part II) is a contaminated party's instrument reading material it already knows, and IV.b's unresolved label-versus-substance question is precisely the kind that reader is least positioned to settle. That is not disqualifying — it is the reason IV.b's lean stays a lean, which the package already does. --- ## Two side matters The `verify-before-compose` gap on Bash-written files is a second instance of `PENDING-95`, which is open and whose title is already the general form of it. Cross-file rather than open a new item. Transcribing the design to disk was right and the reasoning is right: a pre-registration that lives only in a prunable transcript is not one. I cannot verify the transcription is verbatim — the source was a transcript I have no reach to, and the executor is the only witness. That is a permanent property of this artefact, not a failure; it should sit in the provenance header as such. --- ## Where the jurist most wants to be wrong > The one place I would most like to be wrong is Q3's three-party reading — it rests on a > distinction between FL5 as the design phrases it and Constraint 6 as placed, and I have both > texts verbatim, but the design's one-line FL5 gloss may be compressing something OP-02 states > differently. That is the only document in this chain neither of us can open. **Numbering note from the jurist:** `PENDING-110` is open on exactly the `REVIEWED-N`/`PENDING-N` collision, so apply whatever convention is in use rather than taking a bare next-number.