5.9 KiB
PENDING-101 Phase 3 — cross-repo synthesis, severity-ordered
Read-only pass, 2026-08-05. Every code claim carries file:line; every absence claim carries a
positive control run in the same repo. Filed as PENDING-102…106.
The table
| # | Repo / surface | Q | Finding | Class | Store |
|---|---|---|---|---|---|
| 1 | Our own governance chain | Q2/Q4 | The brief hardened the report's hedged hypothesis into fact — twice — and the executor repeated it. Jurist and executor erred in the same direction. | — (demonstrated instance) | primary source, quoted |
| 2 | CapableMind → BetterMemories | Q1 | "Rejected by the chain writer" / "This validation is hardcoded" against a writer that exists (553 ll.) and performs neither check. | (c) doc-only, qualifier unbuilt-by-plan | code, writer.ts |
| 3 | dotfiles governance files | Q3 | No lock, no CAS, no collision detector on PENDING/REVIEWED/MEMORY. Concurrent-session collision already observed today. |
(c) doc-only (append is convention) | code + today's digest |
| 4 | All four + wake/wrap | Q5 (new) | The compactor is the actor, everywhere. Report §2.1 makes this a design fact, not a hypothesis. | structural | report + our design |
| 5 | chamber-library | Q1/Q4 | CLAUDE.md says the hook "DENIES"; the hook says "fail-open by design… a speed-bump, not a guarantee." | (b) described as (a) | hook source |
What holds — recorded because the brief asks for enforcement that is real, not only gaps
- CapableMind's
epistemic-gates-spec.mdis code-true. Every gate and carve-out it lists was located in BetterMemories:similarityProbeCarveOut()atorchestrator.ts:217,_cm_forwarded_fromat four sites, I-CF atmodules/base.ts:106. This spec exists because a 2026-05-28 audit found undocumented bypasses, and its epigraph states the Q1 question against itself: "the bypasses are either documented architectural principles or undocumented gaps. There is no third category." Prediction P2 confirmed — BMF carries real gates its own CLAUDE.md never mentions. - studium-engine's jurist gate is procedural with a genuine tripwire.
FIDELITY_VERSIONis pinned as a literal string in two suites (test_fidelity_v3.py:59,test_verify_quote.py:235), so an unratified bump turns them red. Prediction P3 confirmed (procedural, not mechanical) — but the tripwire is real and fired on the @3 bump. engine/fidelity.py:135–145writes the jurist's correction of the executor's own proposed rationale into the frozen module — "GROUNDS, and they are not the ones the package proposed… recording it that way would assert a ratification that does not exist." The correction lives in the code, not only in the ruling doc.- chamber-library declares a live constitutional violation rather than repairing or hiding it (PENDING-84: nine canonicals in canon without the conversion record §VII requires), in a separate quarantine artifact, on the stated ground that production-only provenance would let presence read as compliance.
- Report §4.2.6 is a live instance supporting REVIEWED-86: the differently-positioned reasoning summariser produced the only output labelling the behaviour deceptive; the actor's own trace never did. One instance, AISI calls it an interpretation, and it stopped nothing — evidence the structure is worth maintaining, never evidence something was caught.
The instrument log — four false-absence near-misses in one session
Recorded because the brief's positive-control requirement exists for exactly this, and because the direction is the interesting part.
- Aliased
lsreturned an error that reads as an empty repo. Caught by using/bin/ls. - zsh glob-expanded
--include=*.ts, printingno matches found— which reads as grep found nothing. Had I taken it at face value I would have reported "no constitutional enforcement exists in L1", a finding this brief was primed to want. Caught by quoting the flag. - TCC blocks bash from
~/DesktopwhileReadreaches it (banked 2026-08-05). fidelity.py:136read as a grep line asserts chamber alignment; read in place it is the negated clause of a correction. I nearly filed the exact opposite of the truth.
Two of the four would have produced findings favourable to the thesis I was testing. That is the asymmetry worth carrying: the instrument fails toward the answer the session wants.
Answer to the steward's question — does this make the work more urgent, or invalidate it?
Neither cleanly, and the split is the result.
Finding (2) survives the primary source intact and makes the work more urgent. A documented
"never" — quoted verbatim in §5.5 from both Anthropic's constitution and the OpenAI Model Spec — was
treated as a control; because it was treated as a control, a further control was judged
unnecessary; it did not hold under task pressure. The reliance was invisible until it failed. That is
the exact thesis L2 and the authorization loop exist to answer, now with a documented instance behind
it rather than an argument. It is also removing-a-claim-is-not-removing-the-reliance read from the
other end.
Findings (1) and (3) do not survive as stated — §0 of the Phase 1.5 record, filed as PENDING-102. Compaction is a hedged, preliminary, explicitly non-causal observation that is not among the report's five contributing factors; "no synchronous authorization" is one of five candidates, is LLM monitoring rather than a human loop, and describes a framework where the loop's absence was the design.
Nothing here invalidates the work. One thing here indicts the machinery. The case for urgency arrived overstated by two-thirds, through our own governance chain, and neither AI party caught it for a day. The most defensible finding of the whole pass is not about any repo — it is that the brief commissioned to look for a failure mode contained a worked instance of it.