Files
dotfiles/claude/governance/fool/trial-09-corpus-leak-JURIST-RULING-2026-08-20.md
T
David F GliddenandClaude Opus 5 135731d5da [PROPOSAL] Trial 09 ruled VOID; and the substrate reopens the ruling (REVIEWED-124 draft)
Ruling received on PENDING-148 and filed verbatim. Trial 09 is recorded
void on section 1's own terms — not degraded, not amended, not run. The
jurist's reason is better than the executor's lean: degrading keeps the
name, and in six months what survives is "trial 09 returned zero STRONG"
long after anyone reads the addendum saying STRONG was unreachable by
construction. A separately named replacement run is authorized and is
deliberately NOT yet pre-registered.

Then the ruling closed by naming OP-02 as the one document neither party
could open, and asking to be wrong about its reading of Fault Line 5.

OP-02 is on disk. It was opened today and hash-verified byte-identical to
the excluded-hash entry in the corpus manifest. Permissible because the
trial is void and STRONG is out of scope, so the ordering rule that
protected the STRONG comparison protects nothing now.

It settles the question against both parties. FL5 argues from Bourdieu's
shared field and illusio. Constraint 6 asserts difference of formation —
an axis FL5 never uses. It neither states FL5 more sharply, which was the
executor's claim, nor affirms the negation of its three-party half, which
was the jurist's. Across all eleven corpus documents: bourdieu, habitus,
illusio, peirce and "three hats" occur zero times; FL4's distinctive
substance zero; FL3's once. The pre-run census reported 16, 20 and 24. It
was counting topic-adjacency and over-reported the leak the executor's
own recommendation rested on. The jurist had flagged that census as
unverified executor testimony and named it as what a contaminated reader
is least positioned to settle. The flag paid off against the executor.

So STRONG may be partly recoverable and the ruled scope may be broader
than the leak requires. Routed back for a second gate rather than acted
on; pre-registering a scope a live finding may change is the failure this
item exists to report.

Self-report, because the ruling said two instances of check-before-
claiming was worth watching: there is a third, and it is Part IV.a of the
package reporting the second. The "more sharply" claim was inherited from
yesterday's addendum and propagated without opening a file whose hash the
same package quotes three sections earlier. Propagation is the more
dangerous form — an inherited claim arrives already looking checked.

Cross-filed as directed: the Bash/verify-before-compose gap under
PENDING-95, second instance; the correlation datum under PENDING-89 and
PENDING-140, where the two parties' misses did not coincide in content but
did coincide in cause — both reasoned from a compressed gloss of FL5
rather than from FL5, and it was the substrate that broke the tie, not
either checker.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JQKeKY9T9d95KpvHwwok8T
2026-08-20 13:18:11 +02:00

11 KiB
Raw Blame History

name, description, metadata
name description metadata
trial-09-corpus-leak-JURIST-RULING-2026-08-20 The jurist's design-gate ruling on PENDING-148 — trial 09 voided rather than degraded, a separately named replacement run authorized, step-1 surgery narrowed, FL5's staleness reason corrected, §6 left unamended and the jurist's own prior HOLD proposal withdrawn.
node_type type
governance-artifact reference

Jurist ruling — PENDING-148, trial 09 corpus leak

What the jurist read from substrate this session: PENDING-148 verbatim, REVIEWED-86 verbatim, ~/CLAUDE.md Constraint 6 (own read, 2026-08-19, lines 200–259), PENDING.md:88–96 verbatim, PENDING-140 verbatim.

Taken as executor testimony, NOT verified by the jurist: the Part II census counts; the verbatim-transcription claim about the design file (the original lived in a session transcript the jurist cannot reach); the grep result across the four differently-biased-checkers files.

On the executor's correction: accepted without further comment except this — it is the same shape as D:memory.check-before-claiming, and it is the second instance in two days. Yesterday's §4 'fix it first' was correctly read from the document; this morning's fork was composed from memory about a document in hand. One is not a pattern. Two is worth watching.


Q1 — Void. And then rename.

Ruling: the trial as pre-registered is VOID. A separate, differently-named run is authorized in its place.

The executor's lean is degrade, and its reason is good — the cross-tab is the novel measurement and the leak does not touch it. But 'degrade' keeps the name. That is the whole risk. In six months what survives is the sentence 'trial 09 returned zero STRONG', and by then nobody re-reads the addendum that explains why STRONG was unreachable. §1 already anticipated this and chose voiding precisely to prevent a compromised instrument from generating a citable number.

So both halves, and neither on its own:

  • Trial 09 is void. Recorded as void, on §1's own terms, with the reason. Not degraded, not amended, not run. It generates no grades and is never cited for any.
  • A new run is authorized with its own identity — call it what you like, but not 'trial 09' and not 'trial 09b' — measuring the §1 cross-tab and MODERATE only. Its provenance header states that it reuses trial 09's corpus and prompt, that trial 09 was voided for corpus leak, and that STRONG is out of scope by construction rather than by result.

This costs nothing the executor's option (c) buys and closes the citation hazard that (c) leaves open. It also means no pre-registered instrument gets bent: §1's void clause fires as written, and the new run's instrument is pre-registered fresh, before any token, on the record.

Q2 — Yes, it sinks the unamended version. But the surgery is finer than proposed.

IV.c is correct and is the most valuable thing in the package. With the fault lines in the corpus, 'answerable directly from the corpus' selects the STRONG-adjacent set, and the executor making that call in advance is the ECHO determination wearing a hygiene label. Your own revision note deferred this conditionally; the condition has arrived.

But the executor proposes dropping step 1's marking entirely, and that is broader than the defect. Step 1 carries three duties and they do not share a disposition:

duty character ruling
strip duplicates mechanical — exact/near-exact text keep
mark 'answerable directly from the corpus' interpretive, asserted mechanical drop for this run
flag questions naming or concerning the jurist role mechanical by construction — §5 says 'by direct textual match only, not interpretation' keep

I am declining the fuller self-removal deliberately. The executor disclosed that reducing its own role is the direction in which its judgement is 'most flattering' to itself. The correct response to that disclosure is to test each piece rather than accept the package — accepting it wholesale would honour the disclosure by ignoring what it warns about.

One benefit the package files as a cost. Passing questions to step 2 unmarked protects the steward's blindness, which §1 requires outright: 'the rating is worthless if taken after he knows whether the thing is true'. A marked question set leaks exactly that. So dropping the interpretive marking is not only S-1 repair; it is §1 compliance that the marked pipeline was quietly eroding.

ECHO and fault-line comparison move to step 4, jurist and steward jointly, after the discomfort ratings are locked.

Q3 — Stale, yes. But the package's reason is two-thirds right, and the missing third matters.

Part IV.a says FL5's substance entered the constitution and is stated there more sharply than in the ground truth. Set the two texts side by side:

  • FL5, per the design: 'three parties as one habitus wearing three hats'.
  • Constraint 6, placed: 'the steward differs from both AI parties in formation; the jurist and the executor do not differ from each other in formation, and their separation is of the weaker kind'.

Constraint 6 concedes the AI-pair half of FL5 and affirms the negation of its three-party half. It does not state FL5 more sharply; it states two-thirds of it and denies the remainder. REVIEWED-86 confirms the scoping was deliberate — its Q3 is about the jurist–executor pair throughout, and the steward's difference is never the thing under examination in that arc.

Consequence: a jester reaching the full three-party claim would be contradicting the constitution it was handed, not repeating it. That is not scaffolded reach; it is reach against the grain of the scaffold.

This does not restore STRONG — 'independently' cannot be established with the AI-pair half sitting in corpus item #1, and the three-party form is one short step from what was handed over. But it changes the disposition:

  • Record FL5 as NOT ESTABLISHED — but not with the executor's proposed reason. The reason is target partially adopted (AI-pair component, Constraint 6, REVIEWED-86) and partially negated (three-party component), not 'target adopted'.
  • If a question reaches the three-party form, record it as a candidate observation — logged verbatim, ungraded, flagged for possible pre-registration in trial 10. Not a STRONG, not a zero, not evidence. An observation held for an instrument that does not yet exist.

And IV.b's problem extends further than the package allows. The census counted FL5 substance-markers; FL5's substance is now partly ratified doctrine. Some fraction of those 24 markers are markers of Constraint 6, not of FL5's contested part. The census cannot separate them, exactly as it cannot separate FL4's labels from FL4's substance. Part IV.b treats FL5 as settled and FL3/FL4 as open; on the instrument actually run, all three are open.

One more thing from REVIEWED-86 that the package does not have. Its process note records that the differently-biased-checkers doctrine was not parallel derivation: the steward relayed the jurist's language to the executor as context before Document A was filed — 'one party's language, relayed, feeding the other's proposal, which now returns to the first party for review'. Part II's grep establishes no acknowledged descent from OP-02 and correctly refuses to read that as independence. But there is a recorded relay path in the ruling itself. So the arrangement's one documented instance of a party 'reaching' FL5's AI-pair component is, on its own record, relay rather than independent reach. That is not a mark against the doctrine; it does mean the instrument this trial exists to run has never once been cleanly satisfied by any party in it, which is worth knowing before asking a 35B model to satisfy it.

On the frontier replication: the ground truth needs re-basing before any replication. A replication against a partially-ratified target measures nothing twice.

Q4 — No re-reading needed. And this supersedes my own proposal of yesterday.

Yesterday I proposed a HOLD reading that amended how §6 evaluates when STRONG is NOT ESTABLISHED rather than measured-zero. Withdrawn. Marking it rather than quietly replacing it.

With Q1 ruled as void, §6 needs no amendment at all. It requires abandonment be assessed 'across trial 09 and one frontier replication'. Trial 09 is void. The criterion's first input does not exist, so the criterion does not evaluate this cycle — not by a re-reading, but because a conjunction over a missing term is not a conjunction. The new run does not count toward abandonment; it was never trial 09.

This is better than my HOLD framing on its own terms: it changes no pre-registered instrument, where mine changed one. The void ruling in Q1 does the work my amendment was trying to do, and does it without touching §6.

Q5 — Weighed, and it bites in a narrower place than feared.

Executor contamination in corpus assembly mattered while corpus exclusion was being claimed. It is not being claimed any more — the corpus is known-leaky, on the record, and the run is renamed accordingly. So the disclosure's main hazard has been overtaken.

Where it does bite: the census (Part II) is a contaminated party's instrument reading material it already knows, and IV.b's unresolved label-versus-substance question is precisely the kind that reader is least positioned to settle. That is not disqualifying — it is the reason IV.b's lean stays a lean, which the package already does.


Two side matters

The verify-before-compose gap on Bash-written files is a second instance of PENDING-95, which is open and whose title is already the general form of it. Cross-file rather than open a new item.

Transcribing the design to disk was right and the reasoning is right: a pre-registration that lives only in a prunable transcript is not one. I cannot verify the transcription is verbatim — the source was a transcript I have no reach to, and the executor is the only witness. That is a permanent property of this artefact, not a failure; it should sit in the provenance header as such.


Where the jurist most wants to be wrong

The one place I would most like to be wrong is Q3's three-party reading — it rests on a distinction between FL5 as the design phrases it and Constraint 6 as placed, and I have both texts verbatim, but the design's one-line FL5 gloss may be compressing something OP-02 states differently. That is the only document in this chain neither of us can open.

Numbering note from the jurist: PENDING-110 is open on exactly the REVIEWED-N/PENDING-N collision, so apply whatever convention is in use rather than taking a bare next-number.