The wrap's own findings, none of which were the session's subject: PENDING-168 ADDENDUM 1 — the /wrap-up §1.6 FIX lane is PROVISIONAL until a steward-jurist check-in that its own index calls due. Batch 1 closed 2026-08-02; 29 days, no check-in, and one executor-classified FIX applied past the boundary. The deferral machinery reported "5 tracked, none due" because nobody ever gave the check-in a DEFERRED-DECISION block. Filed one with a past trigger; the drift-check now reports 1 of 6 COME DUE. Proved by readback. PENDING-104 ADDENDUM 2 — two live executors today, detected by neither. A sibling session read an mtime, worked out this session was concurrent rather than previous, and stopped rather than write to PENDING.md. The wake digest had drawn the opposite inference from the same fact. MEMORY.md: the Fool line asserted NOTHING WIRED — false on all three clauses; statusLine has been running tarbuckle-body.py for six days. Ladder N-now is 44, not 51, and falling. Both verified against the substrate, not relayed — the sibling's counts were off in both directions. Today's one harvest candidate filed as PROPOSAL rather than applied, on the lane's own suspension rule, and it corrects a banked proposal's mechanism: a required-section check derived from the SKELETON constant cannot detect the drift, because SKELETON is the copy that is wrong. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01RmFYCUeAaPqbpJMj6uGokk
85 KiB
name, description, metadata
| name | description | metadata | ||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| skill-harvest-register-proposed-skills-awaiting-steward-authorization | Standing register of skill create/patch/retire proposals surfaced by /wrap-up §1.6, awaiting steward authorization. The governed analog of PENDING.md, turned on our own tooling — propose → authorize → build → record. Surfaced every wake via this MEMORY entry. |
|
Skill-harvest register
The single place proposed skills live so they don't evaporate between sessions. /wrap-up §1.6 proposes here; the steward authorizes; only then is a skill created/patched/retired (never autonomously — the loop is load-bearing, per PENDING-23). /wake-up surfaces the open proposals via this entry. The governed analog of ~/PENDING.md, for our own tools.
Status legend: PROPOSED (awaiting steward) · PROPOSED? (status never marked — open until ruled, never silently closed) · AUTHORIZED (proceed to build) · BUILT · DEFERRED · REJECTED.
Rebuilt 2026-08-07. The 2026-08-01 compaction was lossless but illegible: 55 scraped table-header rows were carried as numbered proposals, 95% of cells were cut mid-word, and pointers reached only a section — one of which holds 81 rows across 410 lines. Regenerated here from
skill-harvest-archive.md(authoritative, unchanged) with word-boundary text and exactarchive:L###/register:L###pointers. Nothing was ruled, reworded or dropped in the rebuild; the completeness invariant was asserted, not assumed. 154 live proposals (124 from the archive + 30 appended since); 13 ruled items remain excluded by the stated rule.
Stroke coverage — the 2026-07-19 full review granted standing authorizations. S2 = covered by Stroke 2 (all earned ladder entries, append wholesale — execution, not a ruling). S2? = names BOTH the ladder and Symmetria, so the stroke that covers it is not settled — rule before executing. S3 = the skill named in Stroke 3's verdicts. S1? = Symmetria flag needing a per-row check against the consolidated §3. — = genuinely awaiting the steward.
The steward's 2026-07-19 ruling is reproduced verbatim below. The 2026-08-07 rebuild initially carried only a paraphrase of it in the Stroke-coverage note above; a paraphrase must not stand in for a ruling on the live surface, so the ruled text is restored here.
⚖ FULL REVIEW 2026-07-19 (late night) — steward ruled ALL FOUR STROKES
This block is authoritative; per-section statuses below are superseded where they conflict. Physical compaction of the register = the same housekeeping slot as Stroke 2. (The 2026-07-12 steward request for this review is hereby discharged; REVIEWED-55 was separately resolved stale the same sitting — placed :489 since 07-12, PENDING-55 closed.)
Stroke 1 — Symmetria §3: consolidate, don't accumulate — BUILT SAME SITTING. Three consolidated flags + one widening landed in the skill (provenance-commented): assert-from-derivation-not-substrate (consolidates: claim-from-derived-artifact 07-03 jurist-elevated 3× · fuzzy-matcher membership 06-15 4× · soft-classification-over-checkable-claim 07-13 steward-named 5×/day · answer-from-training-before-banked-record 07-14 · re-derived-instructions 07-01 · enter-repo-read-docs-first 07-09) · completion-is-a-tripwire (recurrence-promoted per the governed watch-item pattern; folds gate-suite-blind-to-failure-class 07-07 · closable-now-is-a-claim 07-16 · reconcile-before-"finally" 07-17) · the-say-do-seam (record-asserts-applied-before-the-act · grounding-quoted-but-not-traced · consequence-trace-one-level-shallow — the 07-19 family) · trust-prior-pass-frame WIDENED (per-tier-demonstration 07-12 — the flag the steward queued — + claim-scope 06-28). NOT promoted (stay KG drift-patterns, wake-surfaced): probe-confirms-hypothesis · latency-isolation-first · reassuring-verb · tool-creep-into-substrate · solve-constraint-by-discarding-value · lost-the-forest · provenance-is-part-of-process · graduated-with-flagged-gap · convert-steward-state (redundant w/ contamination directives) · theorize-before-measuring-layout (redundant w/ causal-story) · reinvent-governed-DESIGN (widens the existing KG entry).
Stroke 2 — verification-ladder batch-append: AUTHORIZED; slot = next housekeeping pass. ALL earned ladder entries queued in this register (~25–30, from gate-itself-PASS-BUT-FALSELY and prose-word-guard through implement-the-relation-not-an-approximation and re-anchor=re-verify-by-sha-match; incl. the Fowler pair, CI-upper-bound-for-ESCALATE, positive-test-at-enforcement-path, method-class-vs-calibration, per-claim-citation) append to reference-verification-ladder.md with provenance, kin merged in the same pass. The ladder is the already-authorized canonical home (2026-06-05); this discharges the queue wholesale.
Stroke 3 — skills. BUILD (next session slots): /jurist-package (5-for-5, jurist-endorsed; ABSORBS /spec-amendment — supersession procedure goes to the ladder) · /model-handoff (3 proven uses + the path-verification authoring rule). CONFIRMED build-on-need (standing): /reconcile-open-work · /clone-test-runtime-fix · bmf-diagnose · /pre-build-audit · /measure-render · /version-essay. HOLD, named dependency: /graduate-chamber-source — build AFTER the one-door lane ruling (Eichmann pilot report §8.2); it would codify the very pipeline the ruling will change. BUILT SAME SITTING (small authorized patches): wake-up link-resolution canary · wake-up telos-conditional · feedback-governance-drafting-copy-paste-clean.md. RETIRED/REJECTED: mempalace-diagnose (wind-down done) · /wrap-up §4.a tags patch (overtaken by the 07-07 rewiring) · CLAUDE.md staleness canary (doc-currency-on-wrap covers it) · Fowler bad-smells lens (redundant w/ code-review) · /spec-amendment standalone (merged into /jurist-package). /vignette stays DEFERRED (condition unchanged since 06-05).
Stroke 4 — register compaction: AUTHORIZED; same slot as Stroke 2 (ruled items collapse to verdict lines; detail stays in git history — the register exceeded read caps 2026-07-19, its own tripwire).
Post-review additions to the Stroke-2 batch list (same authorization — "all earned ladder entries"; harvested from the pilot-ruling block later the same night): byte-check-hand-classifications-at-source-before-citing (two of my classes AND the jurist's Q3 assessment overturned by bytes — the F7 lesson, jurist-directed at F3's own numbers, discharged strengthening the finding) · coverage-metrics-are-blind-to-block-moves (jurist-minted from their own refuted assessment: any permutation preserving local windows passes coverage; refuted-by-default unless demonstrated on a block move — the demonstrated-not-composed instrument). No other harvest from the late-night block — the session's harvest WAS the ruled review; nothing manufactured.
Post-review addition (2026-07-22, PENDING-69 build — same authorization): read-the-gate's-decision-code-before-designing-its-consumer — before building a consumer/resolver for a gate's output, read the gate's OWN decision logic to know what it can and cannot mechanically produce or see. On PENDING-69 the inherited literal question forced reading verify_body_conservation.classify first: it revealed the gate classifies boundary runs by POSITION+SIZE only and provably cannot confirm class identity → that "no, and knowably no" shaped the honest design (attested declaration the gate consumes, not teaching it to classify) AND corrected my own package's mis-framing mid-build. Kin to render-and-LOOK / measure-toolchain-before-spec, one level over (read the substrate's decision logic, not just its output). Queue with the Stroke-2 batch.
verification-ladder (63)
Stroke 2 (2026-07-19) AUTHORIZED appending all earned ladder entries wholesale. These need EXECUTION, not a ruling — verify each against the current ladder before appending; some already landed.
| # | Item | Gist | Status | Stroke | Source |
|---|---|---|---|---|---|
| 1 | Revert-and-redo-smaller | Ch1's strongest working reflex we don't have: when a verification/gate fails and the cause isn't immediately visible, revert to… | PROPOSED | S2? | archive:L110 |
| 2 | Two-hat commit separation | Name which hat each commit wears: a refactor commit's compiled output is byte-identical (or carries a pre-stated classified… | PROPOSED | S2 | archive:L111 |
| 3 | Bad-smells → refactoring lens | Ch3's smell catalogue (Mutable/Global Data, Duplicated Code, Shotgun Surgery, Speculative Generality, Comments-as-deodorant…) as… | PROPOSED | S2? | archive:L112 |
| 4 | Headless-Chrome box-model measurement | When a rendered layout differs and the cause isn't obvious, measure the box model before theorizing the mechanism. Today this… | PROPOSED | S2? | archive:L136 |
| 5 | /measure-render (headless-Chrome box-model harness) | RE-FLAG — strongly earned. Proposed this morning (compass fix); the pm session ran it 4+ more times (true-advance measurement… | PROPOSED | S2? | archive:L143 |
| 6 | Measure the font's true average prose advance before a character-count… | When setting a measure to a target character count, measure the font's average advance over real corpus prose (incl. spaces), not… | PROPOSED | S2 | archive:L144 |
| 7 | byte-identical gate: hold/exclude volatile build-stamps | When proving a change byte-identical, a build-date/commit stamp (e.g. the colophon buildinfo/stamp) will differ between baseline… | PROPOSED | S2 | archive:L155 |
| 8 | /measure-render (headless-Chrome box-model/scroll harness) | RE-REINFORCED (4th day of evidence). Proposed 2026-06-09 (compass fix) + reinforced 06-09 pm; today drove the ENTIRE §VII.f build… | PROPOSED | S2? | archive:L167 |
| 9 | /model-handoff (premium-model scope charter) | When switching to an expensive/premium model (Fable 5 = 2× Opus rate; burn scales with context×session-length) for a bounded high… | PROPOSED | S2? | archive:L175 |
| 10 | verification-ladder: feature-detect gates can lie | A CSS @supports(feature) (or any capability probe) can return true on a platform where the feature is non-functional — today the… | PROPOSED | S2 | archive:L176 |
| 11 | verification-ladder: parse/validate machine-consumed artifacts that have… | When an artifact that humans have only ever read (a hand-authored YAML index, a config, a data file) is about to be machine… | PROPOSED | S2 | archive:L184 |
| 12 | dry-run-first for bulk file operations | When a mutation touches many files at once (mass git mv, graduation, rename), build it dry-run by default and emit the full move… | PROPOSED | S2 | archive:L193 |
| 13 | verification-ladder: re-verify a workflow/sub-agent's per-item dispositions… | A sub-agent or background workflow that reports a per-item verdict from a dry-run on a temp copy can be wrong on the real apply… | PROPOSED | S2? | archive:L203 |
| 14 | Work-in-omnibus: verify the interior, not just the endpoints | When a sidecar/scope brackets one work out of a multi-work source by heading-to-heading boundaries, content-sample the span… | PROPOSED | S2 | archive:L241 |
| 15 | CSS-mask: fill WHITE, not black (luminance-safe) | A CSS mask/-webkit-mask SVG must fill the shape white/opaque — a black-fill mask renders BLANK (the luminance-vs-alpha trap).… | PROPOSED | S2 | archive:L251 |
| 16 | live-CSS-patch in site for fast in-browser iteration | To eyeball size/style options in the real browser without a full Hakyll rebuild each round, sed the value directly in site/assets… | PROPOSED | S2? | archive:L252 |
| 17 | headless-Chrome element shot: scrollIntoView + full-viewport, NOT computed… | Recalibration: computed box-clips kept mis-landing on the page-top (burned several shots). The reliable element screenshot is… | PROPOSED | S2? | archive:L253 |
| 18 | glyph-outline → SVG from a woff2 | Build a typographic SVG asset from the real font glyphs: fontTools SVGPathPen (path) + BoundsPen (bbox) over the woff2, y-flip… | PROPOSED | S2 | archive:L254 |
| 19 | /clone-test-runtime-fix (CoW-clone + isolated-worktree harness) | When testing a runtime fix that needs real live data but must not touch the live instance: /bin/cp -c -R (APFS CoW) the live data… | PROPOSED | S2? | archive:L270 |
| 20 | verification-ladder: verify the RUNNING BINARY's provenance, not just… | Before reasoning about live behaviour, verify what the running process actually executes — compiled dist/ build mtime + grep the… | PROPOSED | S2 | archive:L271 |
| 21 | verification-ladder: quantify-the-removed-cost as the A/B control | When a fix removes a hot operation, the cleanest control isn't a flaky end-to-end before/after race — it's to time the exact… | PROPOSED | S2 | archive:L273 |
| 22 | verification-ladder note: OCR word-guard passes on SCRAMBLED text | A verbatim word-guard that checks word PRESENCE cannot catch reading-order scrambling (2-col read across the gutter) — same… | PROPOSED | S2 | archive:L300 |
| 23 | The gate itself can be PASS-BUT-FALSELY | A verifier that checks an enumerated set of cruft signatures silently passes any residue outside the set — verifyconversion… | PROPOSED | S2 | archive:L308 |
| 24 | prose word-guard for faithful structure-cleaning | When a cleaner removes/reflows STRUCTURE (headings, printed titles, residue) but must preserve PROSE, gate it with a prose-only… | PROPOSED | S2 | archive:L310 |
| 25 | structure-from-authoritative-ToC = one engine, two map-producers | Answer to the long-open unify question: chapter-structure recovery is ONE placement engine (insertchapterheadings: match… | PROPOSED | S2 | archive:L311 |
| 26 | Symmetria §3 flag: claim-from-derived-artifact-when-the-source-is-checkable | The load-bearing harvest — jurist-elevated to STANDING PRACTICE. I trusted a derived artifact / a regex-over-derived-text over… | PROPOSED | S2? | archive:L338 |
| 27 | per-claim citation verification (don't let a sub-agent's blanket "verified"… | Caught by the jurist: I cited arXiv 2605.24229 for a claim it didn't support, having let a sub-agent's aggregate "4/4 papers… | PROPOSED | S2? | archive:L340 |
| 28 | verification-ladder: CI-upper-bound + drop-one-robustness = STANDARD for… | The jurist RULED (2026-07-04) that grading on the one-sided 90% Clopper-Pearson upper bound (not the point estimate) + the drop… | PROPOSED | S2 | archive:L357 |
| 29 | memory/index restructure = byte-exact slice + md5-conservation + link-canary | When restructuring a memory index or any lossless-relocation of prose between files, do it as line-range slices (never retype) +… | PROPOSED | S2 | archive:L389 |
| 30 | quote a long-job ETA only from an observed rate, never model-size intuition | Twice today I gave a re-embed ETA from gut ("15–45 min") and was wrong by ~30×; the steward caught it. The fix was measuring… | PROPOSED | S2 | archive:L410 |
| 31 | mempalace-diagnose — RETIRE the proposal | AUTHORIZED 2026-06-05 (build-on-need). Now decorative: the steward decided (evidenced) to wind down palace-memory MemPalace.… | PROPOSED | S2 | archive:L412 |
| 32 | cross-volume verify-before-delete move | Moving data across filesystems (internal→external cold archive): rsync -a → verify exact file-count match + du (NOT a byte-sum… | PROPOSED | S2 | archive:L421 |
| 33 | verify at the granularity of the mutation, not the aggregate | A whole-set invariant (a document-wide word-multiset guard) can PASS while a per-item operation (a cross-note swap — a word from… | PROPOSED | S2 | archive:L440 |
| 34 | re-audit coverage with the TOOL's recognizer, not the classifier that… | When a classifier and the tool it feeds share a predicate, the classifier's mis-classifications masquerade as genuine "new… | PROPOSED | S2 | archive:L450 |
| 35 | extending a tool re-tests its foundations | Building an extension exercises shared machinery the original's tests never hit — so a widen's --validate should assert the… | PROPOSED | S2? | archive:L451 |
| 36 | verification-ladder: retroactively re-verify everything landed under a… | The jurist's Q1b principle, proven load-bearing: a stronger check existing and NOT pointed at canon that shipped under the weaker… | PROPOSED | S2 | archive:L463 |
| 37 | verification-ladder: structural safety = PROVISIONAL FIX; end-to-end proof… | The jurist's generalization after nested-block: "same risk as (a)" was true of the matching logic and silent on the rendering… | PROPOSED | S2? | archive:L464 |
| 38 | split cause from magnitude before sizing a remedy | A diagnostic bucket keyed on ONE summary axis (magnitude, holds%, a deficit size) can hold heterogeneous causes — a single label… | PROPOSED | S2 | archive:L502 |
| 39 | confirm-a-named-cause-by-swap-in (don't assert from identification) | When you NAME the true reference / config / cause behind an anomaly, don't assert the fix from the identification — swap the… | PROPOSED | S2? | archive:L503 |
| 40 | method-class-vs-calibration | When a metric/gate fails to separate two cases, ask whether it is mis-CALIBRATED or structurally BLIND to the distinction — no… | PROPOSED | S2? | archive:L511 |
| 41 | positive-test-at-the-enforcement-path over a negative-grep (bypass /… | For any "can X be bypassed?" / "is this gate skippable?" property, a negative grep proves the absence of a STRING, not the… | PROPOSED | S2 | archive:L527 |
| 42 | Symmetria §3 flag / ladder: "closable-now" is itself a claim to check | The jurist named it a standing habit: the closable-vs-blocked partition on a work-list must be reviewed, not asserted — the named… | PROPOSED | S2? | archive:L535 |
| 43 | ladder: reconcile against the AUTHORITATIVE source before any "closed… | Before claiming a block/scope closed or complete, reconcile against the authoritative source (the roadmap stage-1-rebuild-plan §4… | PROPOSED | S2? | archive:L545 |
| 44 | governed spec-supersession procedure | Landing a ratified spec version is: cp live→-vNEW.md → bounded Edits (never retype) → diff shows ONLY intended altered lines +… | PROPOSED | S2 | archive:L551 |
| 45 | verification-ladder / Symmetria §3: assert-"X is in Y" → read Y | A factual claim's grounding must reach the file that HOLDS the fact, not one that merely describes it. Earned hard 2026-07-17… | PROPOSED | S2? | archive:L552 |
| 46 | implementation-is-a-second-gate | A text passed by reading is re-tested by having to act on it — the jurist's own minting, after their 07-16 miss surfaced at build… | PROPOSED | S2? | archive:L560 |
| 47 | sandbox-must-pin-the-shared-module | When a test sandboxes module-level state (paths/constants), the patch must land on the SAME module object the code-under-test… | PROPOSED | S2? | archive:L568 |
| 48 | census-the-substrate-when-a-safety-net-stays-silent | A safety net (generic fallback, fail-loud branch, unrecognized kind) that never fires across N real cases is UNINFORMATIVE, not… | PROPOSED | S2 | archive:L569 |
| 49 | re-anchor = re-verify: reconstruct the old bound state by sha-match | When re-anchoring any sha-bound artifact after an upstream edit: reconstruct the OLD bound state from git by matching the… | PROPOSED | S2 | archive:L597 |
| 50 | implement-the-relation-not-an-approximation | When code implements a RULED relation/contract (an equivalence relation, a gate criterion), the acceptance path must BE the… | PROPOSED | S2 | archive:L605 |
| 51 | seam-probe the artifact (gates test claims; probes test joins) | The night's two REAL defects (empty footnote defs from per-spine -f html; defs-after-index swallowed by the trim) were invisible… | PROPOSED | S2 | archive:L613 |
| 52 | cmp-after-apply (tool-report ≠ write-decision) | stripcruft --apply prints its transform counts BEFORE the write decision; three distinct refusal causes in one night (residual… | PROPOSED | S2 | archive:L614 |
| 53 | Amendment-process: reassigned-component check | Jurist-minted in the REVIEWED-72 ruling: "when a change reassigns a named component, check what else names it." F4 moved the born… | PROPOSED | S2? | archive:L631 |
| 54 | reference-verification-ladder.md | "The parser defines the census." When a census counts items, the item-definition is itself a claim requiring its own control… | PROPOSED | S2 | archive:L652 |
| 55 | A | Strongly earned — three instances in one session. Every substantive vignette defect was found by rendering the artifact and… | PROPOSED | S2 | register:L231 |
| 56 | C | New method, proven today. Building Phase 1a produced nine findings about where the vignette spec fails to determine its output… | PROPOSED | S2 | register:L233 |
| 57 | verification ladder | A suspiciously UNIFORM offset is a constant masquerading as a measurement. A forward-window locator reports the window START, not… | PROPOSED | S2 | register:L256 |
| 58 | verification ladder | Pre-register the expected effect BEFORE building the change. fidelityequivalence@3's effect was filed in the jurist package as 3… | PROPOSED | S2 | register:L257 |
| 59 | verification ladder | Run the counterfactual before attributing a cause. Before claiming X causes Y, remove X and measure Y — where that is cheap and… | PROPOSED | S2 | register:L274 |
| 60 | verification ladder | 2026-08-06. The drainer exits 1 on a halted run; piped through tail, the harness recorded exit 0. A signal that existed was… | PROPOSED | S2 | register:L276 |
| 61 | verification ladder | 2026-08-07, four times in one session and not once by reading: 769 unreachable drawers (455 + 314, two unrelated causes), 2… | PROPOSED | S2 | register:L297 |
| 62 | verification ladder | 2026-08-07. Front-matter re-anchoring: nonsense keys correctly failed, so the control passed — while apatternlanguage silently… | PROPOSED | S2 | register:L299 |
| 63 | verification ladder | Never pin a derived total in a test; assert the invariant — and never let a test depend on a corpus accident. byname == 256 went… | PROPOSED | S2 | register:L300 |
symmetria-flag (33)
Stroke 1 (2026-07-19) consolidated four flags into the skill and explicitly did NOT promote a named list. Rows here need a per-row check against Symmetria §3 as it now stands before they are treated as open.
| # | Item | Gist | Status | Stroke | Source |
|---|---|---|---|---|---|
| 1 | Symmetria §3 flag: theorize-before-measuring-a-layout | The drift this caught, as a standing flag: a causal story about why a layout renders as it does, asserted before the rendered box… | PROPOSED | S1? | archive:L137 |
| 2 | check-for-governed-tooling-before-building | Before hand-rolling infrastructure (a PDF preamble, a build script, a template), grep the repo for an existing governed version.… | PROPOSED | S1? | archive:L154 |
| 3 | Symmetria §3 flag: inherited-marker-read-as-current-state | A status/marker inherited from a RECORD (a selector-index entry, a tracker line, a "-pending" file, a prior framing) asserted as… | PROPOSED | S1? | archive:L166 |
| 4 | Symmetria §3 flag: census-through-a-pattern | A filter/regex used to count or partition a set can silently mis-match and the count reads as authoritative. Today grep -iE 'LOG'… | PROPOSED | S1? | archive:L194 |
| 5 | Symmetria §3 flag: solve-the-constraint-by-discarding-the-value | A "fix" that satisfies a stated constraint by removing the thing the constraint was protecting is contamination shape — it… | PROPOSED | S1? | archive:L202 |
| 6 | Symmetria §3 flag: assert presence/absence from a fuzzy matcher, not the… | A presence/absence claim produced by a fuzzy/token matcher (filename tokens, embeddings, author-surname overlap) treated as fact… | PROPOSED | S1? | archive:L211 |
| 7 | Symmetria §3 flag: probe-confirms-hypothesis | A query/test I constructed to match my hypothesis, whose result I then read as confirming the hypothesis rather than testing… | PROPOSED | S1? | archive:L272 |
| 8 | Symmetria §3 flag: diagnose-inference/latency-without-isolating-the-exact… | The load-bearing harvest. When a network/inference call is slow, the FIRST test must be the isolated one: stop the competing load… | PROPOSED | S1? | archive:L281 |
| 9 | Symmetria §3 flag: reinvent-governed-DESIGN-without-reading-the-spec | Proposed PENDING-41 (consumer-hardware graceful degradation) as a novel architectural direction when local-inference-spec 43L/43M… | PROPOSED | S1? | archive:L282 |
| 10 | Symmetria §3 flag: finding-scoped-to-one-condition restated as… | A result true under a specific condition, restated as an unconditional rule, is contamination shape. Caught 2026-06-28: the… | PROPOSED | S1? | archive:L309 |
| 11 | Symmetria §3 flag: tool-creep-into-substrate (name genome-or-phenotype… | A convenience tool proposed for one job silently becoming the durable substrate (the source of truth) is contamination shape — it… | PROPOSED | S1? | archive:L319 |
| 12 | Symmetria §3 flag: graduated-with-a-flagged-gap-instead-of-resolved | Letting "honestly flagged" substitute for "resolved" — shipping a known-incomplete text because the hole is marked. Contamination… | PROPOSED | S1? | archive:L329 |
| 13 | Symmetria §3 flag: re-derived-instructions-instead-of-citing-the-governed… | Wrote agents hand-made instructions (and invented fields) instead of pointing them at conversion-runbook.yaml/the spec — the… | PROPOSED | S1? | archive:L330 |
| 14 | Symmetria §3 flag: reassuring-verb-before-verifying-the-mechanism | Reaching for a comforting characterization ("self-healed", "fine", "recovered", "handled") before verifying the actual mechanism… | PROPOSED | S1? | archive:L411 |
| 15 | classify a change by MECHANISM, not by how big it feels | Reflexively labeled the recognizer generalization "PROPOSAL" because it felt large; the jurist's own FIX/PROPOSAL test (does it… | PROPOSED | S1? | archive:L452 |
| 16 | Symmetria §3 flag: lost-the-forest-in-a-long-execution-arc | A long, productive execution session that costs the whole-program altitude is contamination shape (composition-over-consideration… | PROPOSED | S1? | archive:L465 |
| 17 | check-the-register-before-a-substantial-build | Before starting substantial INFRA/tool building (a converter, a pipeline, a substrate), read the tooling-register + landscape… | PROPOSED | S1? | archive:L471 |
| 18 | Symmetria §3 flag: a check proven for one tier/case is NOT proven for… | Reusing a verification method across a boundary it wasn't demonstrated on is contamination shape — the V-TEXT k-gram coverage… | PROPOSED | S1? | archive:L484 |
| 19 | Symmetria §3 flag: soft-classification-where-a-checkable-claim-was-available | Shipping a soft label ("this is reordering", "magnitude unresolved", "apparatus") when a CHECKABLE claim (a reportable number, a… | PROPOSED | S1? | archive:L494 |
| 20 | Symmetria §3 flag: answer-from-training-before-checking-the-banked-record | Answering an architecture/tooling/citation question — or proposing a tool/approach — from training memory before grepping the… | PROPOSED | S1? | archive:L519 |
| 21 | Symmetria §3 flag: convert-a-steward-state-into-a-process-weakening | A proposal that converts an observed steward STATE (fatigue, "has carried a lot," being busy) into a weakening of the review… | PROPOSED | S1? | archive:L528 |
| 22 | grounding-quoted-but-not-traced | The hook enforces QUOTING the ratified sections; this session proved quoting ≠ tracing: the coordinate-contract package quoted… | PROPOSED | S1? | archive:L581 |
| 23 | Symmetria §3 flag: record-asserts-applied-before-the-act | A session record (Addendum, brief, tracker line) composed AHEAD of its acts and asserting APPLIED/DONE is contamination shape… | PROPOSED | S1? | archive:L589 |
| 24 | /symmetria §3 | Add the contamination flag: "an instrument whose evidence is the same kind of thing as its own source." A text search cannot… | PROPOSED | S1? | archive:L658 |
| 25 | /wake-up | Read the day's own Symmetria ledger when one exists for today. The wake reads MEMORY.md + the session file + the KG, but never… | PROPOSED | S1? | archive:L681 |
| 26 | symmetria §4 (ledger template) | Add a standing ## What held section — instruments that fired prospectively, lessons that transferred to a failure class they were… | PROPOSED | S1? | archive:L702 |
| 27 | symmetria §2 / /wrap-up §1 | Retire the self-report framing of the standing question. The 2026-07-29 literal question — "is there any instrument I built… | PROPOSED | S1? | archive:L705 |
| 28 | D | Steward-caught today. Asked whether to send a spec to Fable, the executor reached for Constraint 6's independence framing and… | PROPOSED | S1? | register:L234 |
| 29 | Symmetria §3 flag: the-fix-for-an-overclaim-is-an-overclaim-candidate | When you repair an overclaim, the replacement inherits the frame that produced the original. Replacing the engine's "genuine… | PROPOSED | S1? | register:L247 |
| 30 | Widen assert-from-derivation-not-substrate with the null-result case | A null from an instrument you have not positive-controlled is a fact about your instrument, not about the world. Probed… | PROPOSED | S1? | register:L248 |
| 31 | /wake-up §4 | Do not print the Symmetria line unless Symmetria was invoked. This wake's briefing ended "Symmetria active. Practice of return… | PROPOSED | S1? | register:L258 |
| 32 | Symmetria §3 flag | A record asserting that a control is ABSENT is load-bearing, and must be verified like any other claim — it is the note that… | PROPOSED | S1? | register:L275 |
| 33 | Symmetria §3 flag | 2026-08-07, 3 of 3 new checkers: the R0 validator failed six healthy sources and the tempting repair was editing the reading… | PROPOSED | S1? | register:L298 |
patch (28)
Skill/instrument patches. Each needs a ruling.
| # | Item | Gist | Status | Stroke | Source |
|---|---|---|---|---|---|
| 1 | /wrap-up §5 | Palace-fully-derived, part 1: mirror every kgadd/kginvalidate made at wrap into the session memory file (one line each), so KG… | PROPOSED | — | archive:L100 |
| 2 | /wake-up (new step or §2 check) | Wake canary: seconds-cheap probe at wake — every MEMORY.md pointer + link resolves to an existing memory file; flag dead… | PROPOSED | — | archive:L102 |
| 3 | spec↔spec coherence dimension | The 2026-06-10 audit found §I.f-class contradictions — the measure (38→27.2rem) un-propagated across silence-and-rhythm/apparatus… | PROPOSED | S3 | archive:L152 |
| 4 | /wake-up patch — surface the why when the thread touches the engine's… | When the active workstream is studium-engine / The Making / ARC-as-public-proof (the engine's reason-for-being), /wake-up should… | PROPOSED | — | archive:L262 |
| 5 | /wrap-up §4.a | The §4.a drawer-filing step instructs passing tags: to mempalaceadddrawer — the tool rejects it (MCP error -32602: Unknown… | PROPOSED | — | archive:L349 |
| 6 | Chamber graduation: build to the constitution, not to a legacy canonical | Steward-corrected 2× this session: "we cannot use the extant canon as precedent." The extant canon is a pre-constitution/pre… | PROPOSED | — | archive:L632 |
| 7 | chamber-library CLAUDE.md — integration-test-gap discipline | Add to §Load-bearing disciplines: "The fleet has UNIT tests (testtools, per-tool fixtures) but NO integration test — nothing runs… | PROPOSED | — | archive:L640 |
| 8 | /wake-up §2.c–2.d | Consume the SessionStart digest instead of recomputing it. wake-digest.py now fires at every SessionStart and already emits… | PROPOSED | — | archive:L650 |
| 9 | /wake-up §2.a | Fix the link-resolution canary's path handling — resolve pointers against the memory file's physical directory… | PROPOSED | — | archive:L651 |
| 10 | /wrap-up §6 / §6.5 | Verify that every file a commit message names is actually staged, and that steward-authored edits are committed — not just… | PROPOSED | — | archive:L659 |
| 11 | /wake-up §2.a | (Re-proposing, third firing.) Link-canary path resolution — root cause now precise, not merely reproduced: the memory dir's… | PROPOSED | — | archive:L661 |
| 12 | /jurist-package | Require a mechanical verbatim-containment proof over every quoted clause, reported in the package. The skill already says "Quote… | PROPOSED | S3 | archive:L682 |
| 13 | /jurist-package | Mandate a mechanical verbatim-containment proof over every quoted passage, with a positive AND negative control, as a required… | PROPOSED | S3 | archive:L692 |
| 14 | /jurist-package | Formatting convention: ratified text = > blockquote; PROPOSED text = fenced block, never a blockquote. The containment checker… | PROPOSED | S3 | archive:L693 |
| 15 | /wake-up §3 (Next move) | Before executing an inherited resumption point, grep the substrate for whether its premise is already settled. Today's inherited… | PROPOSED | — | archive:L694 |
| 16 | /wrap-up §5 (KG append) | Add a prevention predicate — {subject: , predicate: "prevention", object: <the failure it stopped, and where>}.… | PROPOSED | — | archive:L703 |
| 17 | /wake-up §2.b.2 | Surface one prevention alongside the drift-patterns. Currently the wake greps only drift-pattern, so the session opens by re… | PROPOSED | — | archive:L704 |
| 18 | wake-digest.py | The wake instrument silently hides open items. secpending() drops a PENDING-N whenever a REVIEWED-N exists — matching the number… | PROPOSED | — | register:L222 |
| 19 | normalizeocr.py (chamber fleet) | Silent degradation with no disclosure. dictstate reports only the static word list, so a --lang fr run with wordfreq absent falls… | PROPOSED | — | register:L223 |
| 20 | /jurist-package | Filing is not sending, and the skill has no step that distinguishes them. The 2026-08-01 ESCALATE doctrine package sat filed-and… | PROPOSED | S3 | register:L224 |
| 21 | /jurist-package | Require the mechanical containment proof the skill's own discipline implies. The skill states quote, never paraphrase but carries… | PROPOSED | S3 | register:L225 |
| 22 | /jurist-package | Require reading the clauses ADJACENT to every quote, and stating in the package that you did. Strongly earned and jurist-caught… | PROPOSED | S3 | register:L255 |
| 23 | governance-mcp / doc-access generally | A document whose head is superseded must disclose that at the point of access. The chamber constitution's first ~330 lines are… | PROPOSED | — | register:L259 |
| 24 | /jurist-package | When a quoted source cannot be mechanically containment-checked (PDF, image, external URL, anything the prover cannot read), the… | PROPOSED | S3 | register:L265 |
| 25 | /wake-up §1 | When the wake digest reports a state that contradicts another line of the same digest, name the contradiction as unreconciled… | PROPOSED | — | register:L266 |
| 26 | /wrap-up §1 | A tracker with two update surfaces drifts between them. When updating a canonical tracker, append to its chronological log, not… | PROPOSED | — | register:L277 |
| 27 | /wake-up + general | 2026-08-06. Was one keystroke from asking the steward to invent questions for the corpus, while corpus/chavruta-ground-truth.yaml… | PROPOSED | — | register:L278 |
| 28 | /jurist-package | 2026-08-07. The amendment was pasted OVER REVIEWED-87's original entry; the amendment's own Amends: REVIEWED-87 then pointed at a… | PROPOSED | S3 | register:L296 |
skill-create (13)
New skills. Stroke 3 ruled several by name (S3).
| # | Item | Gist | Status | Stroke | Source |
|---|---|---|---|---|---|
| 1 | bmf-diagnose | Today WAS that need and the method is proven+fresh: process sample → log pattern census (uniq -c histogram) → SIGUSR1→CDP CPU… | PROPOSED | S3 | archive:L94 |
| 2 | /version-essay | The ADR-005 essay-versioning procedure, derived from essay-versioning-specification.md this session: when a published essay gets… | PROPOSED | S3 | archive:L250 |
| 3 | /graduate-chamber-source (the /convert- family the runbook already plans) | Codify the now-PROVEN OCR→canonical→graduation pipeline as a single governed discipline, so the next source (Alexander 1–4, then… | PROPOSED | S3 | archive:L290 |
| 4 | /graduate-chamber-source (already PROPOSED 06-26/27) | Now carries the full EPUB path (structurefromncx→insertchapterheadings→cleanpandochtmlresidue, used when repairepubheadings… | PROPOSED | S3 | archive:L307 |
| 5 | /graduate-chamber-source (proposed 06-26/27/28) | The empirical spec is complete AND the rail it needs now exists (graduation-spec.yaml + verifygraduation.py + graduate-tool… | PROPOSED | S3 | archive:L327 |
| 6 | /spec-amendment (the RFC-supersession amendment process) | The now-RATIFIED chamber amendment process as a codified discipline: normative spec change = a superseding version (Obsoletes… | PROPOSED | S3 | archive:L339 |
| 7 | CLAUDE.md staleness canary (git tripwire) | If the scripts/ set or graduation-spec.yaml changed but CLAUDE.md didn't since, flag "may be stale." Bounded, low-false-positive… | PROPOSED | — | archive:L381 |
| 8 | /reconcile-open-work (program forest-view register) | The practice proven twice now (ARC open-work register, then the whole Chamber→Gold→Engine register today): when tracking has… | PROPOSED | S3 | archive:L462 |
| 9 | /jurist-package (create) | Draft a self-contained jurist package for a repo-blind reviewer: inline the ratified spec clauses verbatim (jurist gates the… | PROPOSED | S3 | archive:L544 |
| 10 | /glyph-map-source | Per-source character-as-image glyph-mapping — the repeatable procedure built + proven on Levi this session (REVIEWED-70/v2.5.0)… | PROPOSED | — | archive:L623 |
| 11 | /fool | Build WHEN STABLE, not now. The differently-formed-checker trial protocol, derived twice this session: withhold the ruling; pre… | PROPOSED | — | register:L221 |
| 12 | B | Headless-Chrome capture used again today, and this time it was decisive rather than diagnostic: the screenshots are what exposed… | PROPOSED | S3 | register:L232 |
| 13 | /census — the pre-registered instrument census | Strongly earned: two runs, ten days apart, both productive, and in BOTH the pre-registration caught a reversal the run would… | PROPOSED | — | register:L246 |
feedback-memory (9)
Proposed feedback memories.
| # | Item | Gist | Status | Stroke | Source |
|---|---|---|---|---|---|
| 1 | /wake-up §2.b | Until upstream #1665 closes: wake searches run unscoped + post-filter by wing (wing-scoped mempalacesearch errors at HEAD).… | PROPOSED | — | archive:L101 |
| 2 | ARC build has NO autoprefixer — hand-write -webkit- prefixes | ARC's plain-sass build adds no vendor prefixes. When introducing a new CSS property, check Safari's prefix need and hand-write… | PROPOSED | — | archive:L145 |
| 3 | Justification-judgment bar = Bringhurst even-colour/rivers, NOT Rutter… | Load-bearing for the future justification decision: when living with the soft rag to judge whether to justify, ask "is the colour… | PROPOSED | — | archive:L146 |
| 4 | container-must-embody-the-contained | When producing an ARTIFACT of a spec (a PDF of the spec, a rendered sample), set it per the spec's OWN rules and verify the… | PROPOSED | — | archive:L153 |
| 5 | clean cruft at the SOURCE layer, not as a downstream transform | When a source carries conversion cruft (EPUB footnote-links, image-scan embeds), clean it at the SOURCE — producing a new… | PROPOSED | — | archive:L185 |
| 6 | /wrap-up §4.b/§5 | Inline reminder at the KG-write step: kgadd object hard-caps at 128 chars — write short keyword objects on the FIRST pass (detail… | PROPOSED | — | archive:L235 |
| 7 | studium-engine tool-evolution-log | Establish the analog of chamber-library/curation/tool-evolution-log.md for the engine tools (patternfinder, ingestgate, chunker… | PROPOSED | — | archive:L242 |
| 8 | draft governance entries copy-paste-CLEAN | When drafting PENDING/REVIEWED entries for the steward to place, format them as clean copy-paste-ready blocks with plain ##… | PROPOSED | — | archive:L534 |
| 9 | /wake-up patch — a tracker marked THE GOVERNING FRAME is read ENTIRE, not… | Earned at a measured cost of ten days. MEMORY.md carries "[Chamber as versioned releases] — THE GOVERNING FRAME for all library… | PROPOSED | — | register:L249 |
other (8)
Notes, tool promotions, and rows that resist bucketing.
| # | Item | Gist | Status | Stroke | Source |
|---|---|---|---|---|---|
| 1 | /graduate-chamber-source (already PROPOSED 06-26) | Its empirical spec is now the full ocrmac column-aware pipeline, not the olmOCR one: render→ocrmac(per-line bbox/conf)→column… | PROPOSED | S3 | archive:L298 |
| 2 | 2 research sweeps owed (not skills — project tasks) | The engine's signature capabilities are greenfield: (1) genealogy/temporal/citation-graph/KG-augmented/diachronic-NLP; (2) multi… | UNMARKED | — | archive:L301 |
| 3 | /spec-amendment (proposed 2026-07-03, DEFERRED-until-first-use) | The 2026-07-03/04 v2.0 drafting IS its first real exercise — the empirical spec now exists. Codify the proven procedure so the… | PROPOSED | S3 | archive:L348 |
| 4 | /model-handoff (premium-model scope-charter) | Used tonight end-to-end: produced studium-engine/docs/stage-1-replan-scope-charter-2026-07-05.md on Opus (§0 discipline / §1… | PROPOSED | S3 | archive:L358 |
| 5 | /model-handoff (proposed 2026-06-12; reinforced 07-04 eve) | Tonight was the first time the pattern ran END-TO-END as designed: fresh Fable-5 session woke into the scope-charter, read only… | PROPOSED | S3 | archive:L366 |
| 6 | /model-handoff (premium-model scope charter) | Proposed 2026-06-12; this session built a full scope charter with the discipline (charter-on-Opus → Fable spends premium tokens… | PROPOSED | S3 | archive:L420 |
| 7 | convertlaneborndigital.py → fleet promotion | The one-door born-digital lane driver (whole-EPUB inject → whole-EPUB pandoc -f epub -t markdown-smart + non-empty-defs teeth)… | PROPOSED | — | archive:L615 |
| 8 | ~/dotfiles/scripts/ | Promote the union-losslessness verifier to verify-union-lossless.py ... — asserts baseline ⊆ union of parts at… | PROPOSED | — | archive:L660 |
New proposals (2026-08-07 evening wrap — retrieval is set by home; awaiting steward)
First batch filed under the REVIEWED-95 firing-moment gate. Each declares where and when it fires; the gate's own test is whether that declaration changes the routing — and for #191 it did, moving it off a 14% home onto an 83% one.
| # | Target | Kind | Proposal | Firing moment (declared) | Earned by | Status |
|---|---|---|---|---|---|---|
| 190 | Symmetria §3 | new flag | An elegant discriminator that explains the data is not thereby licensed to act on it. When a rule accounts for nearly all of a set, the pull to skip the per-item look is strongest exactly when the rule feels cleanest. Before executing a classification across many items, read the items the rule is about to dispose of. | /symmetria check, before any bulk move/delete/reclassification. Symmetria was invoked 56/64 sessions, so §3 is a genuine high-retrieval home — routed here rather than to a skill. |
2026-08-07. symlink-vs-real-dir explained 61 of 63 skills and was about to be executed wholesale; it was wrong for the 2 that were the steward's own (french-typography-pass, spec-code-audit). 97% right, and the 3% were what mattered. |
PROPOSED |
| 191 | feedback-tool-review-after-each-use.md |
patch (extend an existing memory, not a new entry) | Add: census where an instrument LOOKS versus where the thing it hunts actually lives. A detector that is correct everywhere it looks, and does not look where the quarry is, reports clean forever. | After each tool run — the parent rule's existing moment. Lives in MEMORY.md (83% reach) rather than the ladder (14%), because the gate asked: as a standalone ladder entry it would have been filed at one-sixth the retrieval. |
2026-08-07. governance-drift-check.py's deferral scan globbed only */docs/**/*.md, so claude/governance/ — where governance packages live — was invisible to it. Found by using the instrument to wire PENDING-112's falsifier, not by reading it. |
PROPOSED |
Classification: both [PROPOSAL], neither FIX-lane — each changes what the executor must do before acting (the latitude clause of the two-clause test). No FIX-lane changes were applied this session. The /wake-up, /wrap-up and governance-drift-check.py edits were all implementations of REVIEWED-95, not self-tending.
Reinforcement, not a new filing: "a mention is not a retrieval — count the access, never the name" is the existing census-by-mechanism-not-proxy rule, hit again (the ladder read as 53/64 by filename mention; 9/64 by actual tool-call access, because MEMORY.md's pointer line contains the filename and loads every wake). Recorded in the KG; no register row, because the rule already exists and already fires.
2026-08-07 night — two proposals, firing moments declared per the REVIEWED-95 gate
#192 — a cited-vs-placed check for the governance register. Three instances in one evening of a
REVIEWED-N cited as live authority while unplaced: REVIEWED-95 cited in four files (with the day's
/wake-up, /wrap-up and drift-checker edits recorded as "implementations of REVIEWED-95") while the
register held nothing at 95; REVIEWED-87's amendment cited by a jurist ruling as "record already
corrects it" while sitting as a draft; and a malformed header (## REVIEWED-95## REVIEWED-95 — …).
All three passed the drift checker, which verifies that amendment links resolve, not that cited
numbers are occupied. Proposed: for every REVIEWED-N cited anywhere in the memory files, registers
or repo docs, assert N is occupied in ~/REVIEWED.md and its header well-formed.
Firing moment: mechanical, should always fire → governance-drift-check.py, which is already named
in a /wake-up step (measured 83%-home class). Three real positives to build it against, not
synthetic fixtures — which is the standard the discrimination gate itself demands.
Classification: detection-only, adds visibility rather than narrowing it, asserts nothing and
expands no latitude → reads FIX-lane. Filed as [PROPOSAL] anyway: the lane is provisional, the
check is unbuilt and untested, and this session produced twelve instrument faults — building an
untested checker at wrap would be the exact shape of the day's failure.
#193 — ladder entry: read all N before acting on a classification rule. Earned twice today in two
sources. Reading all 23 anchor-initial lines in G&G caught L1997, an orphaned footnote reference
marker between two Weil paragraphs that the tidy rule would have withheld as Weil's own prose. Reading
all 15 blockquotes in Mauss caught that four are Mauss's own displayed scholia and N.B. notes
(17,828 chars) that a "blockquote ⇒ quoted voice" rule would have fenced. Same shape as the
symlink discriminator the previous day: ~90% right, wrong on exactly what mattered.
Firing moment: on a condition the executor must notice — the weakest class in the routing table.
There is no mechanical detector for "you are about to act on a classification rule." Routed to
reference-verification-ladder.md, whose retrieval was 14% but which now has a wake trigger
(REVIEWED-95's trial sentence) — so this is the first entry filed after that home acquired a ritual.
Recorded estimate: unknown, pending the 20-session trial. If the trial grades below 60%, this entry
is evidence about the home, not about the lesson.
2026-08-08 wrap — one proposal, firing moment declared per the REVIEWED-95 gate
⚠ RENUMBERED 192 → 194, 2026-08-08. This row was filed as
#192, which was already held by the cited-vs-placed governance check filed the previous night (#192, above);#193was likewise taken, so the next free number is 194. The collision was live, not cosmetic: PENDING-116 cited "skill-harvest register #192" meaning this row, and that citation resolved to the wrong entry — the exact failure PENDING-110 names, where a number pointing at two things entrenches a false expectation. The later filing was renumbered so the earlier claimant keeps its number; PENDING-116'sRelated:line was corrected to#194in the same pass. Recorded rather than silently fixed, because a renumbered proposal is the kind of change a reader must be able to trace.
| # | Target | Kind | Content | Firing moment | Evidence | Status |
|---|---|---|---|---|---|---|
| 194 | ⚠ filed as studium-engine/.git/hooks/pre-commit — wrong, and corrected by PENDING-116 on reading the substrate: the hook is global at ~/dotfiles/git/hooks/pre-commit via core.hooksPath, so the trigger had to become repo-declared (.precommit-triggers) rather than baked in |
extend an existing hook — NOT a new skill | When a commit touches corpus/ or corpus/sidecars/, run the test fleet and refuse on red. The hook already exists and already runs ("Pre-commit checks passed!"); it does not run the suites. |
Mechanical, and should always fire — the top row of the routing table. Requires no executor recall, which is the whole point: the knowledge was already banked and still did not fire. | 2026-08-08. 118f411 split the Mauss body section into body-01..13, breaking test_navigate.py's hardcoded node id. The fleet sat 202/203 red for a full day, through two separate rounds of correction to that very commit (REVIEWED-96's findings, then the L850 discovery), and surfaced only because the steward asked an unrelated question about instrument base-rate. A sidecar edit is a corpus change that silently invalidates engine fixtures — the cross-repo binding surface studium-engine's own CLAUDE.md names as a re-anchor trap. |
BUILT 2026-08-08 — routed through the register to PENDING-116 → REVIEWED-100 (authorized option (b), repo-declared trigger). Landed 088a171 (.precommit-triggers + scripts/run-fleet.sh) and c86b825 (dotfiles, generic hook block); prerequisite green fleet eef81fa. Acceptance proven both directions. ⚠ Closes the same-repo half only — cross-repo filed as PENDING-117. |
Deliberately NOT proposed, and the reason is the finding. The obvious second candidate — "any one-shot script carries a positive control derived from the property, run before its output is read" — is already banked, at reference-verification-ladder.md §Gate design: "Derive fixtures from the property; draw them from real artifacts." It is what diagnosed both of today's proxy-control failures. Filing it again would be duplication dressed as diligence. The gap is the firing moment, not the knowledge — which is PENDING-112's thesis, and this session is a third data point for the ladder-ritual trial rather than a reason to write a fourth copy of the rule.
2026-08-08 night wrap — one new proposal, one extension; firing moments declared per the REVIEWED-95 gate
#195 — ladder patch: widen two existing entries from checks that ship to any check whose result is stated. This is a scope correction on banked rules, not a new rule — and that distinction is the finding. reference-verification-ladder.md §Gate design already carries "Every check states, in its own output, what it did NOT establish… A check that cannot name its gap does not ship" and "A check must discriminate between two REAL artifacts." Both read as governing built gates. All five of this session's errors were checks that didn't ship — a grep -c, a tail -2, an inferred arithmetic, a probe anchor, a mention-census — and that exemption is precisely where they lived. Proposed additions: (i) the scope sentence, and (ii) the mechanical formulation that covers all five and is stated nowhere — every one of them reduced the output before looking at it; a reduction cannot show its own miscalibration. Inverse twin of the banked "Count first, then look."
Firing moment: on a condition the executor must notice — the weakest row, and declared as such rather than dressed up. There is no mechanical detector for "you are about to trust a check you just typed." Routed to the ladder because it is the correct home for the two entries it amends, and the ladder now has a wake trigger (REVIEWED-95's trial sentence). Recorded estimate: unknown, pending the 20-session trial. ⚠ The steward has already adopted the practical half — state the check's vocabulary alongside its result — which works by making a miscalibration catchable by a differently-positioned reader rather than by the author; that half needs no retrieval because it happens while composing a sentence already being written. This filing is for the ladder's record, not for the practice's operation.
Classification: [PROPOSAL] — it changes what the executor must do before asserting (latitude clause). Status: PROPOSED.
Extension to #192 (NOT a new number) — add placed-record well-formedness to the cited-vs-placed check. #192 proposes asserting that every cited REVIEWED-N is occupied. Rule of three fired today: I hand-typed a placement verification three times (REVIEWED-99, -100, -101) — heading uniqueness · the four structural parts present · a double-header canary. That is the same instrument written three times, which is the banked violation, and its natural home is #192's checker rather than a fourth copy. Deliberately filed as an extension so the two are ruled and built together, per the steward's standing preference to keep the open-thread count low.
Firing moment: mechanical, should always fire → governance-drift-check.py, already named in a /wake-up step (the measured 83% home class) and already performing register-integrity checks. Three real positives available, not synthetic: today's three placements, plus the historical REVIEWED-87 amendment-overwrite and the malformed ## REVIEWED-95## REVIEWED-95 header #192 already cites.
Status: PROPOSED, to be ruled with #192.
No FIX-lane changes were applied this session. All skill/tooling edits this session were either governed records (PENDING.md, the register, memory files) or authorized builds under REVIEWED-100 — none were self-tending edits to a skill.
2026-08-08 (late) — ladder candidate: the degraded-state shape census
Kind: verification-ladder entry (not a skill). Firing moment, declared: on a condition
the executor must first notice — "is this suite honest when its subject is missing?" Per the
routing table's fourth row this earns ~10% retrieval as a bare ladder entry, and that estimate
is recorded on the proposal rather than wished away. The mechanical detector already exists for
half of it (run-fleet now renders the third verdict), which is why only the method is proposed
here.
The instrument. To find out whether a check is honest, drive real degraded states and observe the output SHAPE — crash / named-failure / cannot-assess / pass — rather than grepping the source for risky constructs. Earned twice on 2026-08-08:
- The grep census counted comments and docstrings (3 of
test_navigate's 4next(hits were the executor's own prose about the fix); AST corrected 4 → 1. A construct that CAN raise is not a suite that DOES. - Driving five degraded states — manifest empty · source file missing · db empty · db absent · manifest unparseable — found 8 crash sites across 4 suites, and closing the first six revealed two more in suites the census had already cleared.
Companion, same family: for the discrimination gate's "a real known-bad where one exists"
standard, git history often holds one. git show HEAD:REVIEWED.md supplied a genuine prior
register state that lacked three rulings, so the new built-vs-ruled check was proven on a real
artifact rather than only on a fixture.
⚠ Against filing it: the census method is one instance of "census by mechanism, not proxy", which is already banked in MEMORY.md's standing preferences. This may be a restatement, and the honest proposal is that the steward decide whether the degraded-state form is distinct enough to earn its own entry or should be folded into the existing one as an example.
Awaiting: steward authorization.
2026-08-09 wrap — two proposals; firing moments declared per the REVIEWED-95 gate
#196 — governance-drift-check.py: assert that any text calling a governance item unruled or unplaced agrees with the register. Earned twice in one session, steward-caught both times: I wrote "PENDING-130 is unruled" in a commit message and had an artifact header say the item "proposes" — while REVIEWED-114 had ruled it (a) with five conditions. Ruled · placed · condition-discharged are three states and none implies another; the existing built-vs-ruled check covers only built-with-no-ruling, which is the opposite direction and did not fire. Proposed: for every PENDING-N/REVIEWED-N in the memory files, registers and repo docs asserted to be unruled / unplaced / not yet ruled / awaiting, assert the register agrees.
Firing moment: mechanical, should always fire → governance-drift-check.py — already named in a /wake-up step (the measured 83% home class) and already performing register-integrity checks. Real positives available, not synthetic: today's two, both preserved in git (8746dcf's message; 07727dd's parent state).
Classification: detection-only; asserts nothing, expands no latitude → reads FIX-lane. Filed as [PROPOSAL] anyway, on the same ground as #192: the check is unbuilt and untested, and this session's own lesson is that my checks are weaker than my writes. Status: PROPOSED, to be ruled with #192/#195 if convenient — all three are drift-checker extensions.
#197 — ladder entry (gate-design family): an induced-red probe must revert BEHAVIOUR, not delete the symbol. Removing the function under test produces an AttributeError traceback, which proves the suite crashes when the code is absent — not that it would name the regression when the code is present and wrong. The honest probe leaves every name in place and monkeypatches the pre-defect semantics; mine then produced exit 1 with six named failures, camus by name and the KeyError resurfacing. ⚠ Companion, same command: the exit code was read through a pipe (… | tail), so the reported 0 was tail's — the reduction-before-looking class, already banked as #195 and firing again the next day.
Firing moment: on a condition the executor must first notice — "I am about to witness this suite red." The weakest routing row, declared as such rather than dressed up; no mechanical detector exists for it. Routed to reference-verification-ladder.md §Gate design, beside "a control must sit at the layer the defect lives in", which it is a special case of: deleting the symbol puts the control at the wrong layer. Recorded estimate: ~10–14% retrieval pending the ladder-ritual trial.
Classification: [PROPOSAL] — changes what the executor must do before trusting a witness-red. Status: PROPOSED.
Deliberately NOT proposed. The preservation-header self-match (a strip instruction that quotes the marker it tells you to strip to, so index() matches inside the header) is a one-shot defect in a one-shot artifact, caught by the round-trip that was already there. Per feedback-one-shot-instruments-are-proportionate, its counterfactual is an assertion, not a durable instrument — filing it would be documentation dressed as diligence. The generalisable half is already banked: compare against a fresh emit, not against a recorded sha, which is what caught it.
No FIX-lane changes were applied this session.
2026-08-13 — three proposals from the nested-voice / voice_stamp session
HS-2026-08-13-a — a dotfiles pre-commit guard against unscoped staging of governance files
Earned: the executor ran git add -A in ~/dotfiles mid-session and swept the steward's
freshly-placed REVIEWED-119/120 and a sysupdate Brewfile line into a commit whose message
described only a governance-mcp.py change. Amended before push (92d5ad2), so no shared history
was rewritten — but the dotfiles log is explicitly meant to double as a legible session record, and
for one commit it attributed a steward governance act to an executor [FIX].
The routing finding, which is the point: /wrap-up §6.5 already states the rule — "Scoped add
only — never git add . or -A" — and states why. But §6.5 fires at WRAP, and dotfiles commits
happen throughout a session. The rule is correct and lives at the wrong moment. This is the
register's own diagnosis applied to itself: a capability is worth what a protocol exercises, and
this one is exercised at a juncture the violation routinely precedes.
Firing moment: mechanically, and it should always fire — the strongest row in the routing table.
A ~/dotfiles pre-commit hook that inspects the staged set: if REVIEWED.md or CLAUDE.md is
staged alongside files outside claude/, PENDING.md, refuse with the §6.5 text and require an
explicit override. Detects the actual failure (mixed staging of steward-authored governance) rather
than the proxy (-A in the command line, which is unobservable from a hook).
⚠ Must NOT block a legitimate steward commit — the hook lives in the executor's path only, and the
override must be one flag, documented in its own refusal message.
Classification: [PROPOSAL] — it changes what the executor may do without asking (it adds a
refusal), and it touches the path by which REVIEWED.md reaches the remote. Hard-floor adjacent:
REVIEWED.md is Constitutional Constraint 1 material, so the guard must only ever refuse, never
edit. Status: PROPOSED.
HS-2026-08-13-b — wake-digest.py's wrap_inside is two-valued over a three-case state
Earned: the digest announced "PREVIOUS SESSION DID NOT WRAP" at this session's wake. It was right this time. It was wrong on 2026-08-10, where the 08-09 session had wrapped at 19:48 and then kept working until 21:54 — and the 08-10 ledger already named the defect: "a two-valued detector over a state that has three cases (wrapped · wrapped-then-continued · never-wrapped)." Named, not fixed, and it has now fired twice with opposite truth values. A detector that cried wolf once and is right the next time is in the worst position available — the reader has already learned to discount it.
⚠ Third instance of this exact shape in one day, which is the argument for fixing it rather than re-noting it: the fleet's three-valued exit codes fixed this shape once already (REVIEWED-104/108), and the nested-voice census's hard-wrap detector reproduced it again the same afternoon.
Firing moment: mechanically, and it already runs — wake-digest.py fires at SessionStart. This
is a patch to an existing always-firing instrument, not a new capability needing a home.
Report three states: wrapped · wrapped-then-continued (with the post-wrap span) · never-wrapped.
Classification: [PROPOSAL] — it changes what a governed artifact asserts (the wake digest's
claim about session continuity, which the wake briefing then relays to the steward).
Status: PROPOSED.
HS-2026-08-13-c — "a control set drawn from one source establishes nothing about a corpus"
Earned: the nested-voice census carried five defects; four escaped its own controls. Every positive control was drawn from Mauss — one quotation convention (guillemets), one line structure (paragraph-per-line) — so the controls could exercise neither the ASCII-quote convention (3 sources, incl. the two largest EN texts) nor hard-wrapped text (2 sources). Both blindnesses produced clean zeros, which read as findings. Only the fifth defect — a regression in an already-covered case — was caught by the controls, and that asymmetry is the finding: the controls could not see what they were never drawn to cover, and did see a regression in what they did.
Distinct from what is already banked. Symmetria §3 carries frame-inheritance — reusing an instrument across a tier it was not demonstrated on. This is the complementary failure: the instrument was new, and its control set was the thing drawn from too narrow a population. The existing flag would not have caught it.
Proposed wording, for §3: A control set drawn from one source, one format, or one convention —
however many controls it contains. Coverage is the whole of a control set's strength; controls prove
what they were drawn to cover and nothing else. Enumerate the structural classes present in the
subject BEFORE writing controls, and report NOT ESTABLISHED for a class with no control rather
than reporting zero for it.
Firing moment: at a ritual juncture that already exists — Symmetria check fires before any
build or write with blast radius, which is exactly when a control set is being written. Stronger
than a bare ladder entry (measured 14%) and stronger than a skill (measured 0%).
Classification: [PROPOSAL] — §3 flags shape what the executor must notice before acting, and
this one imposes a precondition on building an instrument. Borderline against the FIX lane's
two-clause test; proposed rather than applied, per "when in doubt, propose."
Status: PROPOSED.
No FIX-lane changes were applied this session.
Proposed 2026-08-20 (wrap) — two, both with declared firing moments
SHR-2026-08-20-a · PATCH /wake-up — reconstruct an unwrapped session before composing the briefing
Status: PROPOSED · Firing moment: a ritual juncture that already exists — the wake digest
already detects and prints ⚠ PREVIOUS SESSION DID NOT WRAP. Today that banner fired, said
"Not established: whether that session did work worth keeping. The transcript is on disk and can be
read if the gap matters", and then the briefing was composed anyway from a MEMORY.md that predated
the lost session. The detector works; nothing consumes it. Proposal: when the banner fires, read
the transcript and reconstruct the missing session record before composing the briefing, rather
than offering it as an option the steward must think to take. Earned today — nine hours of work
(a ratified vault spec, seven commits, a trial prepared-and-held) existed only in a .jsonl the
harness prunes at 30 days. Routes to a named step in an existing ritual ⇒ high retrieval.
Classification: [PROPOSAL] — changes what a skill requires, not only what it records.
SHR-2026-08-20-b · CREATE a mechanical cited-but-never-opened detector
Status: PROPOSED · Firing moment: mechanically, and it should always fire ⇒ a hook or a
wrap-script check, not a skill. Earned by three instances in three days of the same failure, the
third inside the document reporting the second: a governance artifact asserted a claim about a
file it cited by path or hash and never opened in-session. Proposal: at compose- or wrap-time,
extract the file paths and sha256s a written artifact cites, diff against files actually read this
session, and flag the difference. This is the one routing the harvest table calls for — the
alternative is "a condition the executor must first notice", which the 2026-08-07 measurement puts
at ~10% retrieval and which has now failed three times running. Classification: [PROPOSAL] —
a new mechanism; and it touches what the executor may assert without checking.
SHR-2026-08-20-c · PATCH /wrap-up §7 — the vault sync can now REVERT authorized vault work
Status: PROPOSED · Firing moment: mechanically, every wrap ⇒ a guard in the §7 step itself.
Earned today, and only by accident. §7 rsyncs CapableMind-AI/docs/thinking/David/ →
vault/08. Notes/CapableMind/thinking-mirror/, one-directional. Since 2026-08-19 the destination
is the edited side: the vault frontmatter passes (spec v1.0.0, 511 edits / 268 files, steward-
authorized) touched files inside that mirror. Verified at this wrap — 14 files differ, and the
differences are the passes' own work, e.g. related: DN-DRAFT-ungovernable-threshold →
related: "[[DN-DRAFT-ungovernable-threshold]]", which is §6's wikilink conversion. A plain rsync
would have silently reverted it. The sync did not run today only because the auto-mode classifier
blocked the command; the guard should not depend on that.
Proposal: before syncing, diff the trees; if the destination differs on files the source did not
change this session, stop and surface rather than overwrite. Also record that this mirror is no
longer safely one-directional — a vault-side spec now governs files a repo also writes.
Classification: [PROPOSAL] — changes what a skill requires (a gate before a destructive
step), and the hard floor is engaged: silently reverting authorized work is exactly the
"reduces what is surfaced to the steward" clause.
SHR-2026-08-24-a · A /wake-up chamber conditional — THIRD instance of the same miss
Status: PROPOSED · Firing moment: a named step in /wake-up (the 77–83% tier), modelled
exactly on the telos conditional already in §2.a.
Earned for the third time today. feedback-chamber-work-ground-in-constitution-charter-runbook
(steward directive 2026-07-28) says any chamber work or talk about it begins with touchstone /
constitution / charter / runbook. This entire afternoon was chamber talk — the container question,
the treatise, the conversion machinery — and I opened none of the four until the steward said
"read the runbook". The cost was a proposal to build a second home for something already governed.
The note itself predicted this: "session-start prose has failed this class ≥4 times before, which
is exactly why the existing hook was built", and the enforcement mechanism has been owed since
2026-07-28.
Proposal: a conditional in /wake-up §2.a in the shape of the existing telos one — if the pulling
thread or the steward's opening touches chamber-library / studium-engine / the corpus / the
treatise, read the four and hold one line of the touchstone. ⚠ Deliberately NOT the skill route:
the note's own option (c) was /chamber, and 53 skills requiring executor recall measured 0%
retrieval. Routing to a wake step is the difference between 0% and 77%.
Classification: [PROPOSAL] — changes what a skill requires at wake.
SHR-2026-08-24-b · /wrap-up — a mechanism does not count as BUILT until a first firing is observed
Status: PROPOSED · Firing moment: mechanically, at every wrap that built a mechanism ⇒ a
condition on the §8 Instruments field. This is the skill-side of PENDING-156 option (c).
Earned three times in two days, each time on a tool with a green selftest: vault-links.py
(08-23), thread-query.py (08-24 morning), daybook-cue.py (08-24 — 16/16 green, wired to a
matcher the work routes around, never fired once, ~/.claude/state/ did not even exist). And the
propagation is the point: daybook-cue inherited the broken matcher by copy from
verify-before-compose, whose blindness was already on PENDING-95 — because that was filed as an
instance, not a class.
Proposal: the §8 Instruments field additionally reports, for any mechanism built this session,
whether a first firing was OBSERVED on the live path — not that a selftest passed. Unobserved is
a legitimate answer and must be stated as such, never rounded to "built".
Classification: [PROPOSAL] — changes what the wrap requires before a thing may be called built.
SHR-2026-08-24-c · The daily-note format is defined in TWO places and will drift
Status: PROPOSED · Firing moment: mechanically, whenever the format changes ⇒ one
definition deriving from the other.
daybook-ensure.py's SKELETON writes the note; /wrap-up §7.5 enumerates the same headings for
finalising. Adding ## Corrections today required editing both, which is the field-computed-
twice shape — the same class as the archive rule that produced a PASS-BUT-FALSELY on 08-23. Flagged
in §7.5 rather than quietly patched.
Proposal: §7.5 derives its shape list from SKELETON (or names it as the single source and stops
enumerating). ⚠ Derive from the CONSUMER, not the survivor — the consumer here is the wrap step
finalising a note the hook already created, so SKELETON is the natural source.
Classification: [PROPOSAL] — borderline; the FIX lane says propose when in doubt.
Appended 2026-08-25
| # | proposal | firing moment (declared) | status | stroke | pointer |
|---|---|---|---|---|---|
| 155 | A control's fixture must not name a file the session is editing | ⚠ Fires at the moment a control is written — a condition the executor must first NOTICE. Per the routing table this is the weakest class. A mechanical detector IS available and is the honest routing: a check that no control fixture path appears in git status --porcelain. Filed as a detector proposal, not a discipline entry. If built as a detector it fires always; if left as a remembered rule, estimated retrieval ~10%, recorded here as the routing table requires. |
PROPOSED | — | this session; earned when the file-changed-since negative control pointed at FOOL-SEED-RULE.md, which the same session then edited, and the drift-check reported ITSELF unverified |
⚠ Why this is filed as a detector rather than a ladder entry. The verification ladder is FROZEN under REVIEWED-123 and takes no additions from any source until the trial is graded, so it could not go there regardless. But the freeze is not the reason: even unfrozen, this is a rule that fires only if someone remembers it while writing a control, and the measured retrieval for that class is ~10%. The failure it prevents was caught by the controls running on every invocation, not by anyone recalling a rule — which is itself the argument for routing it to a detector.
⚠ Honest limit on the detector, stated before it is built: it catches a fixture naming a file currently dirty. It would NOT have caught today's case at the moment the control was written, because FOOL-SEED-RULE.md was clean then and dirtied minutes later. The detector's real firing moment is the drift-check run, where it would flag "this control's fixture is now dirty" — a warning, not a block. Filed with that limit on its face rather than discovered after building.
Proposed 2026-08-25 evening wrap — awaiting steward
| # | kind | skill | proposal | firing moment | routing |
|---|---|---|---|---|---|
| — | patch | /wrap-up §3 |
Rotation must not discharge a claim by side effect. Demoting the Active Session block moves whatever it carries into MEMORY-reference.md. Tonight that block held a deliberately-preserved false claim (STEWARD OWES: place REVIEWED-127), marked by a live STATE-CLAIM and agreed as next session's first act. A blind rotation would have made the claim invisible while its falsifier kept firing — a gate reporting FALSIFIED forever with nothing left to correct. Proposed step: before demoting, grep the block for STATE-CLAIM/DEFERRED-DECISION slugs and for anything the session agreed to carry; if found, restate it in the new block and update the marker's claims: text to name its new home. |
at /wrap-up §3, which already exists — the rotation itself is the trigger |
named step in /wrap-up (the strong routing tier) |
Why [PROPOSAL] and not the FIX lane: it adds a required check to a skill rather than
changing what the skill records, and the classification test's first clause ("what the
executor may do without asking") is arguable either way. The lane is provisional and its own
instruction is when in doubt, propose. ⚠ Also: the hazard it addresses is visibility of an
open item, which is the hard floor's subject — filing it in the lane would be deciding a
floor question in the executor's favour.
⚠ Caught by doing it, not by inspection. The trap was noticed only while writing the
rotation code and asking what happened to the line. Nothing in /wrap-up would have surfaced
it, which is the argument for the step.
Proposed 2026-08-26 wrap — awaiting steward
| # | kind | target | proposal | firing moment | routing |
|---|---|---|---|---|---|
| — | patch | governance-drift-check.py (detector, not a skill) |
PENDING-164 (d) shipped as a CLI requiring executor recall — the exact class the routing table measures at ~10%, and at 0% for the 53 skills needing recall. prior-art.py exists and works; nothing makes it fire. Proposed: the drift-check reports any PENDING-* item filed since its last run whose title or summary names a term with commit history and zero prior register mentions — the asymmetry prior_art already computes. ⚠ Honest limits, stated before building: (a) it fires after filing, not before — but before the steward rules, which is where the LFS error actually cost something; (b) extracting "the mechanism named by this item" is the same interpretive step that defeated the census, so a keyword heuristic will over- and under-fire; (c) it therefore catches the loud case (a named tool) and not the quiet one. Filed as a detector because the alternative is a discipline the routing table already measured at ~10%, and today's build ignored that measurement while the item recording it was open in the same session. |
at every governance-drift-check.py run — i.e. every wake, already a ritual |
mechanical detector (the strong tier) |
⚠ Why this is a [PROPOSAL] and not the FIX lane. It adds a required check to a governed instrument rather than changing what that instrument records, and the first clause of the classification test — "what the executor may do without asking" — is arguable either way. The lane's own instruction is when in doubt, propose. It also touches governance-drift-check.py, which REVIEWED-95's falsifier leans on; the ladder trial is frozen under REVIEWED-123 and adding a reporting section is not obviously outside that freeze's spirit even though it is outside its letter. That doubt alone routes it here.
⚠ The self-referential note, since it is the point. This proposal exists because the executor built (d) as a recall-dependent CLI on the same day, in the same item, as the register line recording that recall-dependent capabilities fire at ~0%. The measurement was in front of me and the build ignored it. That is not a discipline failure to be fixed with more care — it is the routing table's own thesis, demonstrated at its own expense.
Proposed 2026-08-27 wrap — awaiting steward
| # | kind | target | proposal | firing moment | routing |
|---|---|---|---|---|---|
| — | patch | /wrap-up §3 |
The MEMORY.md rotation is a two-file write with no atomicity, and it half-applied today. §3 demotes the prior Active Session into MEMORY-reference.md and rewrites MEMORY.md. This wrap's script wrote the reference file, then raised on the next statement, so the old Active Session existed in BOTH files — the exact "never leave two Active Session entries" hazard the step exists to prevent, arrived at from the other side. Caught by reading back, not by the step. Proposed: §3 states the order (write MEMORY.md first, demote second, so a mid-failure leaves one copy rather than two) and ends with a three-line assertion — exactly one ## Active Session, zero occurrences of the prior session's pointer in MEMORY.md, exactly one demotion marker in the reference file. ⚠ Honest limit: this makes a partial write detectable, not impossible; two files cannot be written atomically here. |
at every /wrap-up §3 — already a ritual step |
named step in an existing ritual (strong tier) |
| — | patch | /wrap-up §7.5 + daybook-ensure.py |
The daily note's required shape is asserted in two places and checked in none. §7.5 lists six required ## sections and warns in its own text that the skeleton is a second copy which "will drift". Today it had drifted in effect: the note carried The day in short and Open / next but not Decisions taken, Insights and exchanges worth keeping, or Corrections — and I only found out by grepping the headings against the list by hand. ⚠ ## Corrections is the one that matters: REVIEWED-126 added it precisely because a format with a slot for insights and none for errors under-records errors, and it was the missing section on a day with roughly a dozen corrections. Proposed: a check that reads the day's note and reports missing required sections — mechanically, from the skeleton's own SKELETON constant so the two copies cannot disagree. |
at every /wrap-up §7.5, or better, at the Stop hook that already fires the daybook cue |
mechanical detector (strongest tier) — the cue hook already runs on a timer and already reads this file |
⚠ Both filed as [PROPOSAL], not taken through the FIX lane, and the reason is the same for both. Each edits a /wrap-up step while that step is being executed by the session proposing it, which is the one configuration where the classification test is least trustworthy — the executor is both author and beneficiary of the judgement that it needs no authorization. The lane's own instruction is when in doubt, propose, and self-modification during execution is the definition of doubt.
⚠ Both were earned by failures in THIS wrap, not observed in the abstract: the half-applied rotation actually happened, and the missing sections were actually missing. Neither is a speculative improvement.
Proposed 2026-08-31 wrap — awaiting steward
| # | kind | target | proposal | firing moment | routing |
|---|---|---|---|---|---|
| — | CORRECTION to the 2026-08-27 row above, not a new proposal | /wrap-up §7.5 + daybook-ensure.py |
⚠ That row's proposed mechanism cannot work, and today shows why. It proposes deriving the required-section list "from the skeleton's own SKELETON constant so the two copies cannot disagree." The SKELETON constant is the copy that is wrong. Measured today: daybook-ensure.py writes 5 headings (The day in short · Decisions taken · Insights and exchanges worth keeping · Corrections · Open / next); §7.5 specifies 6, the extra being ## <Project> — one H2 per project touched, with commit hashes inline. So the skeleton structurally cannot produce a conforming note, and a checker derived from it would pronounce every note complete while the format's most distinctive element is absent from all of them. A rule derived from the drifted copy cannot detect the drift — feedback-derive-the-rule-from-the-consumer-not-from-the-survivor, arriving inside a proposal written to prevent exactly this class. Self-demonstrated: today's note was filled faithfully against the skeleton and has no project heading. Proposed instead: derive from §7.5 (the spec, which is what a reader of the note is owed), and add the missing slot to SKELETON in the same act so the two agree in the right direction. |
at every /wrap-up §7.5, or the Stop hook that already fires the daybook cue |
mechanical detector (strongest tier) |
| — | patch | /wake-up digest (wake-digest.py) |
PREVIOUS SESSION DID NOT WRAP is a negative state-claim with no falsifier, in the instrument every session reads first. Today it fired while the other session was live — still writing its transcript, and it had committed to dotfiles one minute into the sibling's wake. The digest was right that no wrap existed and wrong about why, and the wrong half is the dangerous one: a session that believes the other is finished has no reason not to write to PENDING.md. Collision avoided by one session reading an mtime attentively, not by any mechanism. Proposed: distinguish no wrap recorded from the session has ended — the transcript's mtime and a recent-commit check already answer it — and say ANOTHER SESSION MAY BE LIVE when they do. ⚠ Honest limit: mtime is a heuristic and a genuinely idle session looks live; the failure it introduces (an unnecessary caution) is the cheap direction, which is the whole argument. |
at every wake — already the ritual, already this script | mechanical detector (strongest tier) |
⚠ Both are filed as PROPOSED and neither was applied, though the first would otherwise have been a clean FIX with an exact 2026-08-24 precedent. The /wrap-up §1.6 FIX lane is PROVISIONAL until a steward–jurist check-in that its own index says is due and that has not happened in 29 days — see PENDING-168 ADDENDUM 1, which files the DEFERRED-DECISION block that now surfaces it. The lane's own rule: until that review, treat a borderline call as [PROPOSAL].