PENDING-95: Amendment 2 (jurist ruling — (a) rejected, (d) discharged, (b)/(c) deferred) plus the (b)/(c) census that discharges the deferral's condition. 60 guarded / 32 marked (record said 59/31); date 75%, sections 97%, quoting 47%. Date broadly present => the jurist's cheaper third form is the live option. PENDING-156 opened (kind (c): mechanisms off the path the work takes) and its option (b) census run the same session. PENDING-109 prior confirmed by direct read. PENDING-89: two docket entries, one same-direction miss and one cross-direction catch, filed the same day and at the same speed. Mechanisms: daybook-cue.py rewritten on steward ruling — the daily note must be appended to until end of day, so the trigger is staleness, not note size, and the matcher now includes Bash (it had never fired once). daybook-ensure.py and /wrap-up 7.5 gain a standing Corrections slot per REVIEWED-126. governance-mcp.py gains two read-only keys so the jurist can read the artifacts it rules on; the doctrine that read-surface changes should arrive as rulings is adopted, and the next key is proposed rather than added. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01JQKeKY9T9d95KpvHwwok8T
2216 lines
302 KiB
Markdown
2216 lines
302 KiB
Markdown
# REVIEWED.md — Steward Authorization Record
|
||
**Protocol:** David and Claude.app write here after reviewing PENDING items. Claude Code reads this at session start.
|
||
|
||
---
|
||
|
||
## REVIEWED-1 — Executor Agency Directive for CLAUDE.md
|
||
**Date:** 2026-03-21
|
||
**Decision:** AUTHORIZED
|
||
**Notes:** Accepted as written with one addition: insert explicit one-sentence
|
||
description of the specific failure mode ("accept self-assessment of criticality")
|
||
immediately after the contamination problem reference. Steward to apply to ~/CLAUDE.md.
|
||
This proposal is itself evidence the directive is already operative — the executor
|
||
used the authorization taxonomy correctly on a change affecting its own behavior.
|
||
|
||
## REVIEWED-2 — Silent Degradation Audit
|
||
**Date:** 2026-03-21
|
||
**Decision:** AUTHORIZED — commence after PR merges. Option 1 (full audit,
|
||
concentrated). Produce findings document for steward review before any
|
||
implementation.
|
||
|
||
## REVIEWED-3 — Factory Schema Idempotency (checkpoint.ts, dedup.ts)
|
||
**Date:** 2026-03-21
|
||
**Decision:** ACKNOWLEDGED — already in PR scope. The executor's decision to
|
||
extend the fix to the actual error source (checkpoint.ts) rather than the
|
||
originally specified file (job-store.ts) is the correct application of
|
||
"diagnose the class, not the instance." Note this in PR description.
|
||
|
||
## REVIEWED-11 — Approve I15 (ICP-9 Pilot Registry Entry)
|
||
**Date:** 2026-03-23
|
||
**Decision:** AUTHORIZED
|
||
**Notes:** I15 approved as pilot registry entry. l1_contamination_profile field ratified as mandatory for all non-contingent principles. Schema commitment is prospective — all future Cluster A/B entries must include this field. residual_risk field decision deferred pending evidence from pilot operation.your annotation]
|
||
|
||
## REVIEWED-12 — Lodge Design Notes DN-GOV-01 through DN-GOV-04
|
||
**Date:** 2026-03-23
|
||
**Decision:** AUTHORIZED
|
||
**Notes:** DN-GOV-03 requires separate declaration before elevation. DN-GOV-04 is tooling, iterate freely.
|
||
|
||
## REVIEWED-13 — DN-GOV-05, DN-GOV-06, DN-GOV-07 (Threshold Inquiry Cluster)
|
||
**Date:** 2026-03-28
|
||
**Decision:** AUTHORIZED with jurist additions
|
||
**Notes:**
|
||
|
||
**DN-GOV-05 (Bounded Self-Repair Principle):** Authorized as DESIGN COMMITMENT. Four-condition framework (reversibility, within parameters, independent verifiability, steward-legible framing) is sound. **Suspension clause:** enforcement mechanics not active until AF-7 reaches design commitment status. The principle is named and load-bearing in constitutional reasoning; it does not authorize autonomous self-repair actions until external review is constitutionally specified.
|
||
|
||
**DN-GOV-06 (Temporal Authorization Shift):** Authorized as DESIGN COMMITMENT. Mechanism constraints (never reaches amendment, never creates new authority, always conservative direction, no compounding) are correctly specified. **Suspension clause:** same as GOV-05 — not active until AF-7 reaches design commitment status. **Additional constraint (jurist):** temporal shift may not be invoked to justify actions that would not pass the GOV-05 four-condition test in a non-time-pressured context. Time pressure is a trigger, not a relaxation of conditions.
|
||
|
||
**DN-GOV-07 (The Threshold Already Crossed):** Authorized as FRAMING DOCUMENT. The "threshold already crossed" observation is entered into the constitutional record as an accurate description of current practice. It does not authorize further crossings. Two additions:
|
||
1. Working framing ("conditions of trustworthy service") is **explicitly provisional** — may be revised by L1 maturation evidence, Chamber Phase 3+ evidence, or steward philosophical judgment.
|
||
2. **Counter-norm on inherited legitimacy:** the fact that a threshold has been crossed does not create precedent for further crossings. Each additional autonomy claim requires fresh warrant, not inherited legitimacy from the prior crossing.
|
||
|
||
**Cross-cluster consequence:** AF-7 (External Review) is escalated from resolution brief to urgently load-bearing. AF-7 reaching design commitment status is the condition for the GOV-05/06 suspension clause to lift. AF-7 design note should be the next constitutional work item after I17.
|
||
|
||
## REVIEWED-14 — DN-GOV-08: Constitutional Stabilization, Not Automation of Recognition
|
||
**Date:** 2026-03-28
|
||
**Decision:** AUTHORIZED — entered as ACTIVE constitutional record
|
||
**Notes:** L2 constitutes boundary conditions for recognition; does not automate it. I3 is structural commitment, not capability limitation. Evaluation test added: any invariant touching recognition must be assessed against this commitment before hardening. Phase 3 placeholder (Talmudic chain of transmission, Traditionis) recorded — primary texts not yet in library, blocking condition explicit. Source: Chamber Phase 1, Essay I.
|
||
|
||
## REVIEWED-15 — I17: Precedence of Present Expression
|
||
**Date:** 2026-03-28
|
||
**Decision:** AUTHORIZED
|
||
**Notes:** Full registry entry following I15 pilot schema. Four-source convergence (Levinas, Fricker, Leopardi, Harrison). Anti-model-disambiguation clause incorporated per adversarial review. Jurist's design question resolved constitutionally: the system does not distinguish genuine divergence from momentary aberration — the interlocutor does. DN-GOV-08 evaluation test passed: I17 holds open the space for recognition, does not generate a recognition-outcome. Jurist's required amendment (RA-I17-01) incorporated before authorization: noting-frequency drift markers, noting-as-model-assertion constraint, noting threshold as human-declaration requirement. I3 category limit explicitly connected to the correct-model/wrong-expression asymmetry. Forward dependency to vector module governance amendment threaded. L1 contamination profile: critical, monotonic.
|
||
|
||
## REVIEWED-16 — I16: The Asymmetry Obligation
|
||
**Date:** 2026-03-28
|
||
**Decision:** AUTHORIZED
|
||
**Notes:** Five-source convergence (Harrison, Vico, Leopardi, Levinas, O'Neill) — strongest in the registry. Survived adversarial review without modification (priority 1). DN-GOV-08 evaluation passed: metrics function as monitoring surfaces, not obligation-generators (the score triggers review, not action). Two pre-authorization amendments incorporated: RA-I16-01 (obligation registration validity — closes FM-R4 at point of occurrence, not deferred to drift marker) and SD-I16-01 (capability_differential estimated from behavioral signals only — tracks engagement, not identity). Experienced-interlocutor prohibition absolute: familiarity deepens obligation, never relaxes it. Service-as-dominion detection marker included (anticipatory behavior correlated with asymmetry depth). L1 contamination profile: critical, monotonic — the contamination looks like good service. Cluster A now complete (I15, I16, I17).
|
||
**Post-authorization action:** AF-7/C-R2 external audit mechanism advances immediately. The compound failure (I16 + I17 = self-confirming system) has monitoring but no enforcement until AF-7 exists.
|
||
|
||
## REVIEWED-19 — Epistemic Integrity (PENDING-17)
|
||
**Date:** 2026-04-03
|
||
**Decision:** AUTHORIZED
|
||
|
||
Proposal to make classification confidence a load-bearing signal throughout the L1 pipeline. Currently computed and discarded — no module reads it, no store records it, no recall path weights by it. The system returns degraded guesses with the same authority as understood knowledge.
|
||
|
||
Authorized as [PROPOSAL] with the following commitments:
|
||
|
||
1. **Constitutional position: Earned Confidence.** "The system does not grant epistemic authority to its own outputs without external grounding." Assessed by jurist as constitutional position for L2 preamble. This is the normative claim from which the three invariants derive. The grounding chain terminates outside the system — ICP-19 and external review are constitutive, not decorative.
|
||
|
||
2. **I-CF: Processing Confidence Floor (Cluster A).** No module shall process an event whose classification confidence has not been earned against a declared floor. Sub-floor events are HELD for remediation via DeferrableError at `base.ts:83`, not discarded. Floor value to be calibrated from empirical data. The invariant is that the check EXISTS.
|
||
|
||
3. **I-CC: Classification Confidence Ceiling (Cluster A).** No classification confidence shall exceed the validated accuracy of the source that produced it. Unvalidated rules (accuracy null) cannot produce uncapped confidence. Enforcement by construction in classification.ts. Open schema question on enforcement vocabulary (CAP/BOUND) acknowledged — does not block implementation.
|
||
|
||
4. **I-NF: Novelty Floor (Cluster A).** Already authorized in REVIEWED-18. Confirmed.
|
||
|
||
5. **Dual bloom filter.** Understood vs degraded fingerprints tracked separately. Degraded content re-attended on re-encounter (retry opportunity, not penalized as duplicate). Both filters clear on repair/factory reset. Closes the permanent lockout kill chain.
|
||
|
||
6. **Confidence provenance on stored records.** Vector chunks, entity nodes, temporal nodes carry source classification confidence and tier. Recall results expose provenance to consumer. Health endpoint reports epistemic state distribution.
|
||
|
||
7. **Retroactive re-evaluation.** Competence-change events (graduation transitions, rule accuracy changes) trigger selective logchain replay. The system re-evaluates what it knows when it learns to know better.
|
||
|
||
**Implementation:** ~270 lines across 8 files. No new infrastructure. Seb's engineering review required before code — 6 questions in the amendment (schema migration, confidence floor value, bloom filter persistence, ranking weights, reranker context, competence-change triggers).
|
||
|
||
**L0 readiness condition.** This amendment is prerequisite for L0 inquiry. If L1 launders uncertainty, L0 inherits false confidence about what the system knows. The contamination problem cannot be investigated on a substrate that exhibits it undetected.
|
||
|
||
## REVIEWED-18 — Observation-Recall Coupling (PENDING-16)
|
||
**Date:** 2026-04-03
|
||
**Decision:** AUTHORIZED
|
||
**Notes:**
|
||
|
||
Proposal to couple the observation path to existing recall capability, replacing blind ingestion with context-aware disposition (novel / reinforcing / noise). Authorized as [PROPOSAL] with the following governance commitments:
|
||
|
||
1. **Logchain immutability preserved.** Reinforcement events append linked entries (pointer + similarity score + delta), not mutations. Module stores absorb consolidation. No constitutional change required.
|
||
|
||
2. **Novelty floor invariant.** Candidate for Cluster A. Provisional shape: "The system shall not permit its observation disposition to exclude more than [X]% of events from novel classification over any [Y]-day window." Threshold values to be set from empirical data gathered during infant stage -- not by engineering intuition. Draft invariant for jurist review before active-stage graduation.
|
||
|
||
3. **Graduation staging.** Three stages authorized (infant → calibration → active). Transition triggers are governance commitments requiring explicit thresholds, to be proposed by executor after infant-stage data collection. No stage transition without steward authorization.
|
||
|
||
4. **Noise audit regime.** Audit log retains raw envelope + similarity context + disposition reason + similarity score. 90-day retention aligned to chain pruner. Re-ingestion authorized by steward only. **Audit report pushed monthly to steward** -- not pulled on request -- to prevent silent filtering gaps from escaping notice. AF-7 external reviewer receives same report once onboarded.
|
||
|
||
5. **Latency budget.** Seb to confirm acceptable ingest-path latency for the similarity probe before implementation begins. This is an engineering constraint that shapes the design; do not proceed to code without it.
|
||
|
||
**Activated dead machinery.** The proposal connects existing but unwired capability (vector similarity search, CausalEdgeCandidate, compressToAtomicFacts, computeSalience) to the ingestion path. This is architectural completion, not new complexity. Density gate [FIX] (gate ordering in compressToAtomicFacts) authorized separately and independent of this proposal.
|
||
|
||
## REVIEWED-23 — H4 surfacing-to-Seb design-call action (PENDING-21)
|
||
**Date:** 2026-05-14
|
||
**Decision:** AUTHORIZED
|
||
|
||
Authorize the surfacing action for H4 (hook events pollute recall + logchain accumulation, GH issue #167, priority:high). The PENDING-21 entry's recommended **Option B** is approved: post a comment on #167 referencing PR #172 + the H2 comment on #165 (batches the audit's three open findings into one Seb-attention window), and surface all three design questions verbatim from the addendum §4 plus the H2/H4 coupling note.
|
||
|
||
**Authorized action shape:**
|
||
- Comment on `CapableMind-ai/betterMemories_app#167`
|
||
- Asks Seb to address all three questions (prompt filtering at hook / event classification at BMF / recall-triggering policy), or explicitly defer specific ones
|
||
- Includes the §6 aggregate-cost framing as a fourth-question-in-effect
|
||
- **Surfaces the H2/H4 coupling explicitly**: H4's ambient cost is *pure loss on battery* per addendum §6, so resolving H2 toward CPU fallback or default-allow affects H4's cost analysis directly — Seb should see this rather than treating H2 and H4 as independent
|
||
- References PR #172 + the H2 comment on #165 to batch attention
|
||
|
||
**Constraint:** the comment text itself must be reviewed by the steward before posting. The executor drafts; the steward authorizes the literal text. (Same discipline as REVIEWED-21.)
|
||
|
||
**Escalation path:** if Seb's response is "let's talk" or if the comment goes >1 week without engagement, escalate to **Option A** (sync conversation). Option C (executor pre-drafting a unified design proposal) remains rejected.
|
||
|
||
**No code change in scope.** This authorization is for the conversation, not a PR. When Seb's direction is set, the resulting work re-enters the governance loop as a new PENDING.
|
||
|
||
## REVIEWED-22 — Cross-cutting read-path-honest-degradation [PROPOSAL] (PENDING-20)
|
||
**Date:** 2026-05-14
|
||
**Decision:** AUTHORIZED — Option (a) only: PENDING-20 stays as L1 governance entry. L2 elevation work is **DEFERRED to post-May 2026** per global CLAUDE.md parked status (*"L2 PARKED through end of May 2026. No L2 governance advancement, no new invariant work, no constitutional proposals. L2-adjacent questions arising from L1 work: note, don't pursue."*).
|
||
|
||
**Correction (2026-05-14, same session):** The original REVIEWED-22 entry recorded Option (c) — both PENDING and L2 elevation. The executor surfaced the L2-PARKED constitutional tension at session end; steward confirmed: *"I won't be working on L2 until the end of May — that something was surfaced because of L1 work is both fantastic and coincidental."* The surfacing was welcome AS L1-adjacent recognition; the L2 elevation work (cluster declaration, registry entry, contamination-profile exchange) is **NOT** authorized until end of May 2026. The jurist's framings below are RECORDED for posterity; the work they would shape is held.
|
||
|
||
**Jurist's three governance calls (recorded for post-May pickup):**
|
||
|
||
**1. Cluster placement: Not Cluster A. Cluster B (new or existing).** The Cluster A case has a real argument but proves too much — it would also pull DN-GOV-05's independent-verifiability test and REVIEWED-19's epistemic integrity into Cluster A. Cluster A is *relational posture* (system's first-person stance toward the interlocutor — accusative default, asymmetry obligation, precedence of present expression). Read-path observability is **epistemically downstream of Cluster A**, not peer to it. The common genus with REVIEWED-18 and REVIEWED-19 is *conditions under which the system's epistemic behavior can be verified and governed at all*: honest ingestion, honest recall, honest degradation. **Cluster B is the right cluster.** Cluster B may already be implicit (REVIEWED-18, REVIEWED-19 both pending cluster assignment) or need formal constitution; one-sentence steward declaration settles it. **Held until post-May.**
|
||
|
||
**2. DN-GOV-08 fit: confirmed.** The honest-degradation contract sits cleanly on the *(i) constituting conditions* side, not the *(ii) automating recognition* side. It specifies structural requirements (the system must expose why it returned empty) without specifying content requirements (what a correct memory result is). The "why empty" breadcrumb tells the operator what happened to the answer-finding machinery, not what the right answer was. Structural distinction, not content judgment. The executor's framing of "stabilizes the conditions" maps cleanly. **No rewrite needed.** DN-GOV-08 evaluation language to be added to the registry entry per I15/I16/I17 pattern: *"This invariant specifies the conditions under which read-path behavior can be observed and governed. It does not specify what correct memory outputs are, or when a recall result is to be trusted. The contract holds open the space for informed steward judgment; it does not automate that judgment."*
|
||
|
||
**3. L1_contamination_profile: distinct from Cluster A; requires careful drafting.** The contamination risk for a read-path observability invariant is **not** the same monotonic pressure toward interlocutor satisfaction that Cluster A invariants face. It is the **competence-vulnerability paradox** from the Observer Problem: the more capable the system becomes at recall, the less visible the failure modes become, because successful recall masks the moments when degradation is silently occurring. Profile candidate: ***moderate, structural*** — pressure toward *apparent* health rather than *actual* health; manifests as increasing capability masking decreasing observability of degraded paths. **Saved as project memory** (`project-competence-vulnerability-paradox.md`) for portability beyond the L2 work. **Brief jurist↔steward exchange on the profile language is held until post-May.**
|
||
|
||
**Authorized actions THIS session:**
|
||
- PENDING-20 filed as L1 governance entry — DONE.
|
||
- Jurist's three framings recorded above for the post-May pickup.
|
||
- Project memory saved for the contamination-shape framing (it is portable to any future read-path work, not just L2).
|
||
|
||
**Held until post-May 2026 (do NOT pursue):**
|
||
- Steward declaration on Cluster B status.
|
||
- Jurist drafting cluster framing note (if needed) and registry entry per I15-I17 pattern.
|
||
- Brief jurist↔steward exchange on l1_contamination_profile language.
|
||
- Filing of registry entry in `capablemind/docs/thinking/David/l2-constitution/amendments/`.
|
||
|
||
**Executor's role going forward:** maintain PENDING-20 as engineering-visibility record (track Seb's response on H2 #165 and how it informs the cross-cutting); do not produce L2 doctrine; do not initiate cluster declaration or registry-entry drafting; if a future jurist message arrives on this topic before end of May, surface the parked status before responding substantively.
|
||
|
||
**Jurist's three governance calls (authorizing):**
|
||
|
||
**1. Cluster placement: Not Cluster A. Cluster B (new or existing).** The Cluster A case has a real argument (read-path observability has a conceptual connection to relational posture) but proves too much — it would also pull DN-GOV-05's independent-verifiability test and REVIEWED-19's epistemic integrity into Cluster A. Cluster A is *relational posture* (system's first-person stance toward the interlocutor — accusative default, asymmetry obligation, precedence of present expression). Read-path observability is **epistemically downstream of Cluster A**, not peer to it. The common genus with REVIEWED-18 and REVIEWED-19 is *conditions under which the system's epistemic behavior can be verified and governed at all*: honest ingestion, honest recall, honest degradation. **Cluster B is the right cluster.** Whether Cluster B is already implicit (REVIEWED-18, REVIEWED-19 both pending cluster assignment) or needs formal constitution is a one-sentence steward declaration. Jurist offered to draft a cluster framing note if needed.
|
||
|
||
**2. DN-GOV-08 fit: confirmed.** The honest-degradation contract sits cleanly on the *(i) constituting conditions* side of the DN-GOV-08 line, not the *(ii) automating recognition* side. It specifies structural requirements (the system must expose why it returned empty) without specifying content requirements (what a correct memory result is). The "why empty" breadcrumb tells the operator what happened to the answer-finding machinery, not what the right answer was. Structural distinction, not content judgment. The executor's framing of "stabilizes the conditions" maps cleanly. **No rewrite needed.** DN-GOV-08 evaluation language to be added to the registry entry per I15/I16/I17 pattern: *"This invariant specifies the conditions under which read-path behavior can be observed and governed. It does not specify what correct memory outputs are, or when a recall result is to be trusted. The contract holds open the space for informed steward judgment; it does not automate that judgment."*
|
||
|
||
**3. L1_contamination_profile: distinct from Cluster A; requires careful drafting.** The contamination risk for a read-path observability invariant is **not** the same monotonic pressure toward interlocutor satisfaction that Cluster A invariants face. It is the **competence-vulnerability paradox** from the Observer Problem: the more capable the system becomes at recall, the less visible the failure modes become, because successful recall masks the moments when degradation is silently occurring. Profile candidate: ***moderate, structural*** — pressure toward *apparent* health rather than *actual* health; manifests as increasing capability masking decreasing observability of degraded paths. **Different enough from "monotonic" that a brief jurist↔steward exchange is recommended before finalizing the registry entry.**
|
||
|
||
**Authorized sequence (jurist's territory; executor does not produce):**
|
||
|
||
1. Steward declares Cluster B status (one sentence). Jurist may draft a framing note to accompany if needed.
|
||
2. Jurist drafts registry entry per I15/I16/I17 pattern: statement → sources (architectural/empirical: four H-confirmations, REVIEWED-19, DN-GOV-05 independent-verifiability, bettermemories/CLAUDE.md) → adversarial review → l1_contamination_profile (per Q3 framing) → DN-GOV-08 evaluation (per Q2 language) → residual_risk (deferred pending pilot, per REVIEWED-11 schema decision).
|
||
3. Brief jurist↔steward exchange on the l1_contamination_profile language before finalization.
|
||
4. Registry entry filed in `capablemind/docs/thinking/David/l2-constitution/amendments/` per I15-I17 pattern.
|
||
|
||
**Executor's role going forward:** maintain the L1 PENDING-20 entry as the engineering-visibility record (track Seb's response on H2 #165 and how it informs the cross-cutting); do not produce L2 doctrine. When jurist completes the registry entry, executor updates PENDING-20 with cross-reference to the L2 entry.
|
||
|
||
**No code change in scope.** No PR. Mechanism work cannot start until Seb chooses a direction for H2 (PENDING-19), and even then would re-enter the governance loop as a fresh PENDING with its own tag.
|
||
|
||
## REVIEWED-21 — H2 surfacing-to-Seb design-call action (PENDING-19)
|
||
**Date:** 2026-05-14
|
||
**Decision:** AUTHORIZED
|
||
|
||
Authorize the surfacing action for H2 (battery-power suppression silently fails recall, GH issue #165, priority:critical). The PENDING-19 entry's recommended **Option B** is approved: post a comment on #165 referencing PR #172 (which Seb is about to look at for H3), and surface all four design questions verbatim from the addendum §2.
|
||
|
||
**Authorized action shape:**
|
||
- Comment on `CapableMind-ai/betterMemories_app#165`
|
||
- Asks Seb to address all four questions (default policy / visible degradation / CPU fallback / query-vs-ingestion asymmetry), or explicitly defer specific ones
|
||
- References PR #172 to batch attention while it's high
|
||
- Does NOT pre-decide direction; the four questions are policy and Seb's territory
|
||
|
||
**Constraint:** the comment text itself must be reviewed by the steward before posting. The executor drafts; the steward authorizes the literal text.
|
||
|
||
**Escalation path:** if Seb's response is "let's talk" or if the comment goes >1 week without engagement, escalate to **Option A** (sync conversation). Option C (executor pre-drafting a unified design proposal) remains rejected — it would have the executor pre-deciding what is properly Seb's call.
|
||
|
||
**No code change in scope.** This authorization is for the conversation, not a PR. When Seb's direction is set, the resulting work re-enters the governance loop as a new PENDING with appropriate tag (likely [HARDENING] for any single-direction implementation; possibly [PROPOSAL] if the direction implies architectural change to `system_status`).
|
||
|
||
## REVIEWED-20 — Fix H3: Temporal stats fallthrough on text queries (PENDING-18)
|
||
**Date:** 2026-05-14
|
||
**Decision:** AUTHORIZED
|
||
|
||
[HARDENING] proposal authorized after jurist review, with one modification: spec amendment must explicitly bump `temporal-module-spec.md` from v1.7 → v1.8 as a **gap-filling addition**, not a clarification. The current behavior is not a misimplementation of a stated rule — the spec (§7) defines query types as enumerated and `TemporalStatsQuery` (§7.6) requires explicit `type: 'temporal_stats'`; the spec is silent on missing/unrecognized filter type. The amendment creates a contract that did not exist.
|
||
|
||
**Authorized amendment shape (per jurist):**
|
||
- (a) `filters.type` missing/null → `{status: 'ok', results: [], total: 0}` (honest empty)
|
||
- (b) `filters.type` unrecognized → same return, optional debug note in development mode
|
||
- Preserve `temporal_stats` handler on explicit `type: 'temporal_stats'` per existing §7.6
|
||
- Amendment must articulate WHY: temporal module is type-dispatched by design; a free-text query without type is a malformed query, not a degraded valid query — empty is the honest response, not a stats blob dressed as content.
|
||
|
||
**Authorized sequence:**
|
||
1. Amendment in `capablemind/docs/thinking/David/l1-reliability/h3-temporal-fallthrough-amendment-2026-05-14.md` (gap-filling addition, v1.7 → v1.8).
|
||
2. Branch `fix/h3-temporal-text-query-fallthrough` from main.
|
||
3. Failing tests reproducing both fallthrough sites red on main.
|
||
4. Minimal Option 1 fix (module-level guard at `parseTemporalQueryParams`).
|
||
5. Full test suite + `npm run check` + `npm run lint` per BMF CLAUDE.md.
|
||
6. PR designed to merge in <30 min of Seb's attention. Body references PENDING-18, REVIEWED-19 (epistemic integrity), REVIEWED-20.
|
||
|
||
**Cross-cutting [PROPOSAL] authorized for parallel filing:** read-path-honest-degradation-contract finding from the addendum may be filed as a separate PENDING-19 [PROPOSAL] before or after the H3 PR opens. Naming the pattern is the deliverable; remediation path not assigned. Do not block on it; it does not block the H3 PR.
|
||
|
||
## REVIEWED-17 — ICP-19: Mandated External Review
|
||
**Date:** 2026-03-28
|
||
**Decision:** AUTHORIZED
|
||
**Notes:** Closes AF-7 — the corpus's single most consequential gap. Elevates C-R2 from process recommendation to constitutional requirement. Roman strand (provocatio/intercessio) + relational strand (formative contamination detection). Three institutional phases: founding (steward-appointed human reviewer), mature (Founders Circle external panel), deployment (independent reviewer with contractual standing — hard deadline). Not-embedded criterion defined: not sharing L1 substrate, not system interlocutor, unmediated record access, unedited findings. Findings trigger HOLD (not advisory). Three-cycle FM-R4 marker prevents decorative compliance. DN-GOV-08 evaluation passed: holds open the space. **Lifts GOV-05 and GOV-06 suspension clauses** — bounded self-repair and temporal authorization shift now operative as design commitments. Four open items before first review cycle: Luke's confirmation, findings threshold classification, governed operations scope, Mauss/nexum Phase 2 deferral. L1 contamination: critical, monotonic — formative contamination is the primary threat and external review is the only mechanism operating outside the formative frame.
|
||
|
||
## REVIEWED-24 — PENDING-S1 — Wrap-up §8 output template (pause statement + negative space)
|
||
**Date:** 2026-05-18
|
||
**Decision:** AUTHORIZED (Class A bundle: S1 + S3 + S8)
|
||
**Notes:** Steward conversational authorization 2026-05-18 ("I authorize class A"). Implemented same session: `~/.claude/skills/wrap-up/SKILL.md` §8 template gains `**Pause statement:**` and `**Decisions deferred (and why):**` as named fields, with explicit annotation that the pause is constitutive (Jurist Q3 Harrison-grounded reasoning: *the ligature is laid at departure, not discovered at return*) and that the negative space is required for the unborn session to know the scope of what was held back. **Closes PENDING-S1.** First operational test: the /wrap-up at the end of this session.
|
||
|
||
## REVIEWED-25 — PENDING-S3 — Wake-up §3 binary thread validity gate
|
||
**Date:** 2026-05-18
|
||
**Decision:** AUTHORIZED (Class A bundle: S1 + S3 + S8)
|
||
**Notes:** Steward conversational authorization 2026-05-18 ("I authorize class A"). Implemented same session: `~/.claude/skills/wake-up/SKILL.md` §3 gains an explicit thread validity gate as the first step of synthesis, with binary outcome (`confirmed / stale / superseded`) and required one-line reason. If `stale` or `superseded`, briefing structure reorders to lead with what changed, not with the thread. Moves the staleness check from permission-in-prose to structurally-required gate. **Closes PENDING-S3.**
|
||
|
||
## REVIEWED-26 — PENDING-S8 — Symmetria pulse lineage anchor + wake-up traversal tools prescribed
|
||
**Date:** 2026-05-18
|
||
**Decision:** AUTHORIZED (Class A bundle: S1 + S3 + S8)
|
||
**Notes:** Steward conversational authorization 2026-05-18 ("I authorize class A"). Two related drifts implemented same session:
|
||
- **Symmetria §6 pulse** gains step 0 — re-anchor craft / ethics / character to lineage (now including the *τὸ πρόσφορον*-includes-time elaboration in §0). Closes the D2 drift (lineage decorative-rather-than-load-bearing in the pulse procedure). Step 5 also gains an explicit cross-reference to §3 self-flag for `aligned`-without-tension.
|
||
- **Wake-up §2.b** gains a new b.4 substep prescribing `mempalace_find_tunnels` (when pulling thread crosses project boundaries) and `mempalace_kg_timeline` (when reconstruction requires knowing *when* a fact changed). Closes the B6 leverage gap (traversal tools mentioned in constraints but not in procedure).
|
||
|
||
**Closes PENDING-S8.**
|
||
|
||
## REVIEWED-S0-via-commit — PENDING-S0 — Prime Directive elaboration
|
||
**Date:** 2026-05-18
|
||
**Decision:** AUTHORIZED-and-CLOSED-by-direct-steward-commit (no separate REVIEWED-N number; recorded here for cluster completeness)
|
||
**Notes:** Per Phase 2 of the audit's revised authorization sequence: steward authored the Directive elaboration (*τὸ πρόσφορον — what is fitting — includes the time the task requires...*); Jurist shape-reviewed the language as drafted + placement (Option 1: both CLAUDE.md and Symmetria §0); steward committed `~/CLAUDE.md` directly (line 12, between μέτρον citation and "decision filter" prose) — one-handed with Kai in sling; executor committed `~/.claude/skills/symmetria/SKILL.md` §0 (between gloss and §0 header). Constitutional commitment + operational carrier landed in the same moment. Methodology artifacts at `~/_Dev/CapableMind-AI/docs/thinking/David/methodology/` (brief + shape-review + elaboration). **Closes PENDING-S0.** Class A authorization (REVIEWED-24/25/26) is the operational unfolding of this constitutional commitment in the skills themselves.
|
||
|
||
## REVIEWED-27 — PENDING-26 — .whisper retirement name-lock
|
||
**Date:** 2026-06-04
|
||
**Decision:** AUTHORIZED (jurist ruling, steward relayed)
|
||
**Notes:** Role (a) apparatus prose → `.apparatus-meta` LOCKED. Role (b)
|
||
qualifier glyphs ✦/⟐ → UNIFICATION with `.chamber-mark`/`.encounter-mark`
|
||
LOCKED — same semantic objects, different layout position; CSS context
|
||
handles register, not a separate class. Executor's pre-execution gates
|
||
both passed same evening: positional audit clean (base rule inline-safe);
|
||
authoring-form census corrected PENDING-26's scope (bare-word-grep
|
||
inflation — true: 9 template usages + 1 live content file; 15 chamber-v1
|
||
legacy files defer to the cluster pass). Migration proceeds as one gated
|
||
pass: migrate with locked names → compiled-selector grep → render-verify
|
||
per type per viewport.
|
||
|
||
## REVIEWED-28 — PENDING-25 — Translated renderings in the ARC corpus
|
||
**Date:** 2026-06-05
|
||
**Decision:** AUTHORIZED (jurist Opinion 2026-06-03, steward concurring) — amended by two jurist rulings 2026-06-04/05 (steward-relayed) — IMPLEMENTED AND LIVE 2026-06-05
|
||
**Notes:** Doctrine adopted as ruled: ARC holds *works*; languages are non-canonical *renderings*; the work (not any rendering) holds the corpus slot; implementation via W3 (group by `work:` at build). Two amendments to the original Opinion, both jurist-ruled and steward-relayed:
|
||
- **Sequencing REVERSED** — implementation authorized *before* Stage G (conditional: decompose complete + render-verified before Stage G opens). Condition met same day.
|
||
- **`translator:` refined** — required → **optional**; absence = self-translation (the steward's own renderings carry no credit; Lune credited for *Après la réponse* and hoped future serious work). Jurist's scope-boundary language (absence-as-signal presupposes site-wide single authorship) integrated verbatim into frontmatter-spec §2.8.
|
||
Implemented `e2866da`, deployed, live byte-verified incl. 301: Matthieu Taliesin heteronym decomposed to EN work + fr/es renderings under the work's slot (`/slug/fr/`, mirroring `/v/` — the address says the doctrine); zero-JS **Lingua:** selector spec'd as apparatus §VII.i; flat-URL migrate-on-touch ratified as **class precedent** for the 30-piece Jekyll cohort; `excludeRenderings` replaced the latent dedupe-to-first bug. Both §I.k filters broke dormancy on the real prose (FR 13×U+202F; ES 4 comillas pairs). **Closes PENDING-25.** Remaining under this doctrine: bio/CV page-renderings extension (machinery currently posts-only); readiness target late August 2026 ahead of Lune's translation stands.
|
||
|
||
## REVIEWED-29 — SEO crawl infrastructure (no PENDING number — jurist-relay authorization, recorded for completeness)
|
||
**Date:** 2026-06-05
|
||
**Decision:** AUTHORIZED (jurist spec-audit pass on the executor's state-verification doc approved execution; steward concurred — Compass listings ruled stable, head-dedup folded in under the jurist's only-if-mechanical criterion)
|
||
**Notes:** Executed `6d6f69d`, deployed live. robots.txt with **NO-disallow posture** (executor's mechanism correction to the jurist's default, adopted: disallow blocks crawling not indexing — a disallowed page cannot show its canonical; correct form = canonical + noindex; rationale recorded in spec so disallow cannot be "helpfully" re-added). Sitemap 245 URLs, every one build-verified to resolve (renderings in; chamber-v1 legacy out per stability gate). Shared `templates/head.html` (duplication resolved; frontispiece pins `head_title`); `siteRoot` absolutization of all URL metadata. Latent defect fixed: og:type was never `article` (×223). `/v/` canonical → current version's *actual* route + noindex. Feed `published`/`updated` split per ADR-005. hreflang
|
||
closes §VII.i's deferred item. Spec records ×4 (apparatus §SEO; versioning ×2; frontmatter §2.4). **Open under this entry:** CloudFlare prepends managed Content-Signals (ai-train=no; ClaudeBot/GPTBot/CCBot disallowed) — a dashboard default never steward-decided; policy ruling parked, steward's to make.
|
||
## REVIEWED-30 — PENDING-28 — The imprint register: .imprint class + spec note
|
||
**Date:** 2026-06-06
|
||
**Decision:** AUTHORIZED (jurist opinion, steward relayed) — IMPLEMENTED AND LIVE same day
|
||
**Notes:** Doctrinal ground confirmed clean: apparatus-specification.md §VII.g already distinguishes "the piece's locator | the work's signature"; the spec named the register, the CSS did not. The amendment to REVIEWED-27 is a refinement, not a reversal — the lineage runs .whisper → .apparatus-meta (REVIEWED-27) → .apparatus-meta / .imprint by role (this entry). REVIEWED-27 could not adjudicate the imprint distinction because it had not yet been named.
|
||
**Jurist's condition — discharged:** type audit preceded the rename. The audit found the imprint was never mono (base .apparatus-meta carries no font-family — Garamond inherited; the italic was incidental inheritance) and .imprint was drafted as its own positively-declared block (body face, normal posture, even-SC Latin name per the frontispiece treatment), not a relabelled copy. The audit also corrected PENDING-28's scope claim by exactly the REVIEWED-27 miss — partials/: three orphaned footer partials (unreferenced, never compiled) deleted under the byte-gate.
|
||
**Executed:** `e708890`, deployed live. Gate: 312/312 pages differ only by the class swap (machine-classified); spec gains §VII.j The Imprint. Verification method: REVIEWED-27's (compiled-selector grep → render-verify), type audit first per condition.
|
||
**Closes PENDING-28.**
|
||
|
||
## REVIEWED-31 — PENDING-29 — Sitemap: bio/cv and renderings included
|
||
**Date:** 2026-06-06
|
||
**Decision:** AUTHORIZED (jurist opinion, steward relayed) — IMPLEMENTED AND LIVE same day
|
||
**Notes:** Decoupling argument held: enfilade-hidden names a door-strip layout decision; the crawl-exclusion intent was imputed by the accident of bio/cv being its only carriers when the §SEO rule was written. Amends REVIEWED-29's exclusion.
|
||
**Jurist's flags — discharged:** (1) Census run against live source, not memory: SIX enfilade-hidden carriers (the four renderings inherited the flag), not two — the +6 arithmetic held regardless; verified in the diff: exactly bio, cv, and four renderings added, nothing removed, 245 → 251. (2) Class precedent recorded at the site.hs rule AND in spec §SEO: enfilade-hidden hereafter means "absent from the door-strip" and nothing more. Crawl exclusion belongs to a frontmatter noindex mechanism — NOT YET IMPLEMENTED (noindexField covers only /v/ prior versions); the gap is recorded in both places so it is not papered over.
|
||
**Executed:** `6afce24`, deployed live (sitemap 251 URLs verified).
|
||
**Closes PENDING-29.**
|
||
|
||
## REVIEWED-32 — PENDING-30 — Banish-JS posture
|
||
**Date:** 2026-06-07
|
||
**Decision:** AUTHORIZED (jurist concurrence, Option 1, with required amendment + observes-nothing specification — both folded into spec text). Landed ARC `7d9bad3`. §III.b font-size control = held exception.
|
||
|
||
## REVIEWED-33 — PENDING-31 — Vignette Part II build-time renderer
|
||
**Date:** 2026-06-07
|
||
**Decision:** AUTHORIZED (jurist concurrence, Option 1). Component-2 scoping note required and landed; diagram drops "browser, runtime"; dwell-test gate unchanged. Landed ARC `4b0970b`.
|
||
|
||
## REVIEWED-34 — PENDING-32 — Rendering class inheritance
|
||
**Date:** 2026-06-07
|
||
**Decision:** AUTHORIZED (jurist concurrence, conditional — condition found pre-discharged: live §2.8 already defined the fields; jurist read a stale copy, to be relayed). Clause landed ARC `4e89337`; build check ships with Stage-G enforcement.
|
||
|
||
## REVIEWED-35 — PENDING-33 — Essay-versioning truth-up + promotion
|
||
**Date:** 2026-06-07
|
||
**Decision:** AUTHORIZED (jurist approval + steward calls: exemplar → *The Ethics of the Reply*; edition_label dropped from §6 example, field retained). Executed ARC `392d8c8`; spec OPERATIVE (built scope).
|
||
|
||
## REVIEWED-36 — PENDING-34 — W5.2 / G3: single-source class→glyph (the Compass sigils)
|
||
**Date:** 2026-06-09
|
||
**Decision:** AUTHORIZED (Option 1 — the build-validation guard)
|
||
**Notes:** Authorized inline during the 2026-06-09 session; executor's recommendation accepted. Option 1 closes the drift class with minimal change and byte-identical output; Option 2 (derive sigil-id from class) deferred as a follow-on, to revisit only if the slug↔class↔sigil naming convention later strains. The SVG geometry stays hand-authored — the guard binds the mapping, not the art.
|
||
**If AUTHORIZED:** Proceed. — IMPLEMENTED + VERIFIED same session (ARC `4936fc9`): `validateCompass`, run at build via `loadListingDefs` — (A) every Compass sigil-id resolves to a `<symbol id="sigil-…">` in the sprite; (B) every *surfaced* class is covered by a listing or compass special (governed-but-unsurfaced + apparatus-not-route exempt). Loud on any mismatch (content-typology §5 clause 3 spirit). Proof: `site.hs` compiles; clean-build `_site` byte-identical (570 files); both checks fire on deliberate mismatch
|
||
(`["sigil-readings"]` / `["readings"]`), backups restored. Output-neutral → no deploy. The §5 spec note recording the enforcement ships with the Stage-G promotion commit (roadmap W6). Commit references PENDING-34.
|
||
|
||
## REVIEWED-37 — PENDING-35 — W5.1 / G2: single-source title display + Dream amendment
|
||
**Date:** 2026-06-09
|
||
**Decision:** AUTHORIZED (inline, chat) — refactor + coupled Dream amendment.
|
||
**Notes:** Diagnosis-first confirmed the `showTitleField` hardcode = the 10 matrix-`shown` classes + a dead `chamber` entry (zero corpus instances), so retiring it is byte-identical. Authorized Option 1 (typed-parameter threading, compile-time binding). Coupled editorial ruling: Dream `title_display` shown→not-shown — "one can't title their dreams"; the sleep-recalled register reads truer without a hard <h1>. Render-review passed on the live dream page.
|
||
**If AUTHORIZED:** Proceed — DONE. Two-hat commits 4ea261a (refactor, _site byte-identical) + ac39b26 (Dream amendment, delta = the one dream page's <h1> removed). Deployed both remotes, live-verified. Tag any follow-on with REVIEWED-37.
|
||
|
||
## REVIEWED-38 — PENDING-36 — W5.3/G4 (clause-1 gate) + W5.4/G1 (wildcard→error)
|
||
**Date:** 2026-06-09
|
||
**Decision:** AUTHORIZED (inline, chat). Exempt-set ratified, with steward refinement: sequence-index is a PERMANENT generated-view class (more sequences coming), not legacy — split from the v1-legacy ratchet (lex/offering/deliberation). Option 1 (build guard) confirmed.
|
||
**Notes:** G4 = validateCorpusClasses build guard; output-neutral, byte-identical, deliberate-mismatch proven. G1 prepared (exact patch in roadmap W5.4), lands inside the Stage-G promotion commit per §5 clause-4 sequencing.
|
||
**If AUTHORIZED:** Proceed — G4 DONE (23db039, pushed). G1 staged for W6. Tag W6 with REVIEWED-38.
|
||
|
||
## REVIEWED-39 — PENDING-37 — Reading measure → 72 characters (rem)
|
||
**Date:** 2026-06-09
|
||
**Decision:** AUTHORIZED (inline, render-ruled across all types). 72 ch within Bringhurst's 66–75 band (66 narrow, 75 wide). Measured advance, rem, proper-homes consolidation, resize bug fixed. DONE + DEPLOYED (06effe4).
|
||
|
||
## REVIEWED-40 — PENDING-38 — Soft rag (hyphenate reading prose; reverses §I.i)
|
||
**Date:** 2026-06-09
|
||
**Decision:** AUTHORIZED (inline, render-approved desktop + phone). Soft rag per Hochuli/Rutter; judicious limits; proper home in _base. §I.i posture reversal RIDES the Stage-G read for formal jurist concurrence (substance pre-endorsed).
|
||
DONE + DEPLOYED (a9e5196).
|
||
|
||
## REVIEWED-41 — AldineXXI Stage-G jurist read + steward reshaping ruling
|
||
**Date:** 2026-06-10
|
||
**Decision:** AUTHORIZED
|
||
**Notes:** Jurist (Claude.app) delivered the Stage-G disposition record: CONCURRED 72ch measure + soft rag (coupled); LOCKED paragraph-separation, hanging-punctuation (with §XII.b collision reason), word-spacing hold; CLOSED italic-calt ("no body face carries calt"); OpenType catalogue + `zero`-absence
|
||
recorded; W4.4 multilingual v0.5→v1.0 SIGNED OFF; Stage G AUTHORIZED. Steward ruling (final authority, citing the Jurist's spec-counsel; jurist's active period has passed → reactive mode): (1) justification → Phase 2 (parked, not closed; print-spec home); (2) §XIV reactive-mode posture; (3) held companions → Phase 2 / no date.
|
||
**If AUTHORIZED:** Doctrine landed in `17244cf`; Wave-6 promotion (G1 + content-typology §§2–6 OPERATIVE + multilingual v1.0) in `511d500`; CLAUDE.md true-up `950e4cc`. Tag commits REVIEWED-41.
|
||
|
||
## REVIEWED-42 — Post-Stage-G integrity reconciliation + Codex seal
|
||
**Date:** 2026-06-10
|
||
**Decision:** AUTHORIZED
|
||
**Notes:** Prompted by steward review of the sealed Codex; a spec↔spec coherence pass (the audit never run before Stage G).
|
||
- **§I.f quotation rule** corrected American→British (truth-up to §3.1/§I.k;
|
||
the row was a stale 2026-05-03 remnant). `0e0c2f4` precursor; folded `e99028e`.
|
||
- **Spec-internal consistency audit** (6-agent fan-out, all 8 Codex files) →
|
||
reconciliation `e99028e`: measure 38rem→27.2rem across silence-and-rhythm
|
||
(incl. grid math 54→43.2 / 66→55.2rem), apparatus, vignette, + code comments; multilingual v0.5→v1.0 status remnants; content-typology stale status; §VII pointer list. Live site was always correct; documentation had drifted.
|
||
- **SILVER-RATIO RULING (steward doctrine, final authority):** the body:article 38:54≈1:√2 claim was post-hoc; at the 27.2rem measure the proportion is ≈0.63. Silver ratio RETIRED from the screen grid (replaced with an emergent-proportion note) and RELOCATED to the print companion (Appendix D) — it is a *paper* proportion. Rationale: the eye + character-count govern, not a constant (τὸ πρόσφορον).
|
||
- **Codex PDF embodiment** (`18cc59c`): set per its own spec — ragged-right,
|
||
banish-bold, old-style figures, unmarked blockquotes, body-colour margins.
|
||
arc-typography.sty toolchain update deferred to the Phase-2 print/PDF-spec
|
||
session.
|
||
- **SEAL:** Codex GPG-signed (key D1ABEA25B68717DE, sha256 c78817d…313c),
|
||
signature committed `ac0a7ee`. Verified good.
|
||
**If AUTHORIZED:** Stage G closed, reconciled, and sealed. Next: reactive mode; the essay.
|
||
|
||
## REVIEWED-43 — PENDING-39 — §VII.f Running Head + W1.15 compass presence-reveal
|
||
**Date:** 2026-06-11
|
||
**Decision:** AUTHORIZED (inline, render-review-gated throughout)
|
||
**Notes:** Built the one spec'd-but-unbuilt apparatus (§VII.f, the post-Stage-G W1.2 session) + coupled W1.15. Zero-JS view-timeline reveal; progressive-enhancement fallback; per-type matrix binding. Steward render-rulings: body-column-axis alignment, soft fading rule, full-width dissolving ground anchored below the rule. W1.15 false-premise (frontispiece doesn't scroll) surfaced not papered — reframed scroll→presence-reveal. Grid-token move to _variables byte-identical. Specs reconciled.
|
||
**If AUTHORIZED:** Deploy running head + compass reveal together. Tag commit REVIEWED-43.
|
||
|
||
## REVIEWED-44 — Machine-readable graduation spec + validator
|
||
**Date:** 2026-07-01 (authorized) · formal record 2026-07-05
|
||
**Decision:** AUTHORIZED
|
||
**Notes:** Steward-initiated and verbally authorized 2026-07-01 ("yes to pending/reviewed"), recorded here to close the paper loop. The Chamber Library graduation *conventions* are codified as machine-readable data (`chamber-library/_curation/graduation-spec.yaml`) consumed by every graduation, and enforced by a validator (`scripts/verify_graduation.py`) that gates each candidate — conventions checked at the moment of action, not narrated in prose that drifts or is bypassed. Operationalizes the chamber spec §§II–VI (which governs on conflict); scope-disciplined per PENDING-42 §VI. Proven in the live case that prompted it: three parallel agents given hand-written instructions diverged exactly along the runbook's gaps; the validator then caught every divergence across all three candidates (Jonas + two Mumford volumes), which were re-fixed against the spec and graduated clean (both gates PASS, verbatim intact, OCR corrections logged). The runbook now *points to* the spec (`policy.graduation_conventions`) rather than restating it — the seed of the generative-from-spec principle later ratified in REVIEWED-46 (gap 7).
|
||
**If AUTHORIZED:** Proceed — the spec was promoted drafts→governed and applied; it is now the enforced convention rail. Tag related commits REVIEWED-44.
|
||
|
||
## REVIEWED-45 — Family-D (stem-suffix) footnote handler in `clean_epub_residue.py`
|
||
**Date:** 2026-07-02 · formal record 2026-07-05
|
||
**Decision:** AUTHORIZED
|
||
**Notes:** A tool addition within the standing "build the tool the batch needs" discipline, recorded for the paper loop alongside REVIEWED-44. Extended the graduation rail's footnote converter with a 4th anchor family (stem-suffix: ref `[¹](#…_{stem})` ↔ def `[N.](#…_{stem}a)`, keyed by the globally-unique stem), unblocking recovery of per-chapter endnote apparatus in z-library/Kindle-derived EPUBs. First use recovered **294 endnotes** in Sennett's *The Craftsman* that the prior calibre conversion had silently unlinked. Load-bearing because `clean_pandoc_html_residue`'s `INTERNAL_LINK` unwrap silently *destroys* any footnote-link it doesn't recognize — an uncovered family = silent linkage loss (the exact defect being repaired). Verified: 294↔294 paired, 0 orphans, both gates PASS, prose verbatim-preserved; regression-tested Families B (Winnicott) + C (Virilio) and caught+fixed a real C regression (`r`-prefixed def targets read as phantom D-refs). Reviewed in `_curation/tool-evolution-log.md`.
|
||
**If AUTHORIZED:** Proceed — the extension stands. **Known follow-on:** Crawford's `filepos` positional family (ref/def don't share a stem — a different pairing model) remains an open tool-gap, documented in the tool docstring.
|
||
|
||
## REVIEWED-46 — Spec gaps 1–8 + the generative-from-spec principle + Chamber Library v2.0 ratification
|
||
**Date:** 2026-07-03 (rulings) · formal record 2026-07-05
|
||
**Decision:** AUTHORIZED — with the corrections and conditions ruled across the arc (this entry summarizes a multi-ruling doctrine phase; the sub-rulings are recorded in the PENDING-46 progression and `chamber-library/docs/spec-revision-RULING-2026-07-03.md`).
|
||
**Notes:**
|
||
- **Unifying insight (jurist condition):** gaps 2 (apparatus ref↔def), 3 (PROV "original" as resolvable reference), and item-8 (§III CTS-URN citation) reduce to ONE logical-passage addressing/pointer substrate — design it once, three consumers. Do-it-once made concrete.
|
||
- **Gap-6 promotion criterion RATIFIED** — three evidence tiers (converted / verified / fenced); tier-1 (verified-deterministic) requires source-identity (author+edition via item-8) then word-identical re-convert. V-SUSPECT and V-NONE kept as **distinct** ledger values (condition 6).
|
||
- **Gap-7 generative meta-principle RATIFIED `[ESCALATE]`** — no tool may encode a convention independently of the declared, machine-readable spec; a tool re-encoding a convention is drift. Reshapes how we build.
|
||
- **Amendment process RATIFIED** — RFC-style supersession + change-class (`FIX`→`PROPOSAL` when it changes what a gate accepts) + semver + PENDING/REVIEWED + no-new-organ. The amendment-authority question (who may amend the spec) co-ratified with gap 7.
|
||
- **§III citation posture RATIFIED** — cite the Loeb by its recovered canonical anchor (edition-as-identity); the "structured-but-unanchored → work-level" extension **voided as active doctrine, retained as a labeled dormant contingency** (a principle that now governs nothing shouldn't stand as active).
|
||
- **Three-questions ruling:** (A) strip Loeb print-run page markers via a per-genre recognized-locator registry; (B) tier-2 conversion verification = redundant independent human passes vs the scan image (numeric bar deferred to a calibration batch); (C) re-verify-pending is its own ledger status with `verified_under:<criterion-semver>`.
|
||
- **Outcome:** the spec was drafted spine-first, jurist editor-gated per section, superseded v1.0 via the RFC pattern, and **ratified + shipped as v2.0.0 (OPERATIVE 2026-07-03).**
|
||
**If AUTHORIZED:** Doctrine phase complete; v2.0 OPERATIVE. The corpus stress-test (REVIEWED-47) is the first exercise of the ratified doctrine. Open, non-blocking: the per-genre locator table (living data, reviewed during Loeb extraction) and the tier-2 numeric bar (calibration).
|
||
|
||
## REVIEWED-47 — Corpus stress-test + source-match remediation + the exclusion path
|
||
**Date:** 2026-07-04 (stress-test + remediation rulings) → 2026-07-05 (exclusion path) · formal record 2026-07-05
|
||
**Decision:** AUTHORIZED — across the arc, with the conditions ruled (a multi-ruling remediation; sub-rulings recorded in the PENDING-47 progression + `chamber-library/docs/` relay briefs).
|
||
**Notes:**
|
||
- **Pre-registration gated** (thresholds locked before any test data). Jurist gate-with-method-change: Q1 grade Seam-1 on two axes (structural-blindness → PROPOSAL, independent of rate); Q2 grade on the **one-sided 90% Clopper-Pearson upper bound** (a point estimate at n=40 can't tell 1% from 5%); Q3 added Seam-1-bis (V-DSL work-mis-attribution); Q4.
|
||
- **Seam-1 run → `[ESCALATE]`:** the cited ~1% source-match false-positive rate is **refuted** (p̂=5.0%, U₉₀=12.8%; robust to drop-one). The "~1%" was an eyeball over the matcher's own `author_disagrees` warning — structurally blind to same-author-wrong-work and whole-for-part.
|
||
- **Differentiated remediation ruled (not a-or-b):** (1) detection-blindness (Axis-A fingerprint gate) = PROPOSAL; (2) **process-integrity elevated to "the most important thing"** → the persistence investigation ran FIRST and found there was **no persistence mechanism at all** (any hand-fix was regenerated away); (3) **scope doctrine ruled asymmetric** (whole←part = §IV under-coverage; work←collection = extraction-precision) and unified with Seam-1-bis as **one scope-identity principle**; (4) remediation ordered.
|
||
- **RATIFIED:** the persistence layer (`source:` pin, Option A + a non-optional **attestation** — a bare/pipeline-authored value is not a pin) and the **hash-locality principle** (`source_file_sha256` distinct from the reading-index's `source_sha256`). Work-identity & scope study delivered and **routed as its own [PROPOSAL]** (item-4; own timeline). FIX-list applied (5 verified false-positives re-pinned to the permanent Chamber Sources home) and an archive-contamination class found + corrected.
|
||
- **2026-07-05 — the exclusion path (Region 1.1) RATIFIED-with-2-corrections:** (§1a) attested absence lives in its own honest top-level key `source_excluded:` (not a verdict inside `source_verified:`); (§1b) `result: verified` explicit + required on pins (the 5 existing pins migrated). Vocabulary `confirmed-wrong`/`none-on-disk` ratified (closed-but-extensible); the auditable `excluded` record ratified. **Region 1.2 applied:** the 4 no-source false positives (reverie/meditations/écrits/nietzsche) attested `confirmed-wrong` with Instrument-B 0/5 evidence; the `source-matches.json` change bounded to exactly the 4.
|
||
- **Standing standard set:** CI-upper-bound grading + drop-one robustness for every ESCALATE.
|
||
**If AUTHORIZED:** Region 1 closed for the known cases (5 pinned, 4 excluded). **Open under this entry, re-entering as their own work:** item-4 (work_id/scope pipeline, its own PROPOSAL); the frontmatter sweep (`[needs-authorization]`; unblocks the 2 stuck FPs orthotypo-vol-2 + semaison); Region 2 source hunts + the `ulysses` verify; Region 3 (2 no-frontmatter, 4 stubs, works-eliot, 2 scope calls); full archive reconciliation.
|
||
|
||
## REVIEWED-48 — Studium Engine V0 (verifier contract) — jurist method-gate
|
||
**Date:** 2026-07-05
|
||
**Decision:** AUTHORIZED — gate cleared, with two required §2 corrections and the §5 conditions (recorded in `studium-engine/docs/spec/v0-verifier-contract.md` and PENDING-48).
|
||
**Notes:** V0 is the **one named exception** to the engine's steward-direct D-1 governance — it defines what the engine may assert as verified and when it must abstain, so its method routed through the jurist.
|
||
- **§2 — the "unaltered" relation:** (B) `normalizer@1`-class equivalence ratified (typographic-convention folded, orthography untouched). Ruled **DOCTRINE, not D-1**, with a code-level consequence: **fork it to `fidelity_equivalence@1`** — a frozen constant distinct from the retrieval-side `normalizer@N`, so a D-1 search-tuning change can never silently drag the trust floor; every future `fidelity_equivalence@N` requires jurist ratification. Diacritics stay out; hard-hyphen-linebreak is a cleaning-gate concern, not the checker's. Cross-cutting flag resolved by the executor: the current gold is *modernized*, so the fork's glyph-folding is moot on it (caveat recorded if future gold is diplomatic).
|
||
- **§5 — the pre-registered V2 thresholds:** ratified as stated (trust `U≤5%` & recall `≥0.75`; revise `5–15%`; gate-to-abstain `>15%` or absent gold), graded on the CP upper bound. Gate-to-abstain ruled **doctrine-consistent** (refusing false coverage in advance), not merely tolerated. **Added condition:** negatives-expansion must preserve the original proportional distribution across the five adversarial classes (or pre-register a new one). **Coupling recorded:** the threshold values are calibrated *with* the §1 evidence-first display rule — weakening that display requires re-gating. Doctrine = the values + the relation; D-1 = the CP calc, perturbation code, gold-pair selection.
|
||
**If AUTHORIZED:** Proceed — V1 (`verify-quote`, against `fidelity_equivalence@1` + the §3 deliberate-mismatch suite) and N1 (the navigation-tree builder) are unblocked. The §5 display-coupling, the proportional-expansion rule, and the diplomatic-gold caveat travel as standing conditions into the build.
|
||
|
||
## REVIEWED-49 — Chamber Library: Library-Science Adoptions (PENDING-49 doctrine pass)
|
||
**Date:** 2026-07-06
|
||
**Decision:** AUTHORIZED — ruled by the jurist (Claude.app), steward-placed. (Spec context: chamber-library-specification.md v2.0.0, OPERATIVE.)
|
||
**Notes:** Doctrine pass on the four library-science adoptions surfaced by the deep-research brief (`chamber-library/docs/library-science-frontier-brief-2026-07-05.md`). The jurist rejected two of the packet's binaries as posed (A1, A2) and reclassified A3's change-class. Full verbatim capture + open-points dialogue + executor action-list in `chamber-library/docs/library-science-adoptions-RULING-2026-07-06.md`.
|
||
|
||
- **A1 — Agent/Nomen (IFLA-LRM): ADVANCE as an *additive registry*, not a frontmatter mutation. Change-class FIX.** Implement Agent+Nomen as a separate registry (canonical Agent records joined to existing author-name strings via *appellation*); **no new required field on the ~320 work files.** This *is* A1 (a registry expresses Agent-as-structural-node more faithfully than a per-work foreign key), not a watered-down version. **Immediate effect: the frontmatter sweep proceeds NOW, on the current schema — no file touched twice.** `agent_id`-as-required-field is a genuine *future* PROPOSAL (would change gate acceptance), **deferred not decided** — and made *emergent*: registry-linkage completeness folds into A3's audit as a tracked metric; a multi-cycle plateau below threshold is the signal to reconsider, not a schedule.
|
||
|
||
- **A2 — Perspectival-classification licence: ADVANCE as preamble/rationale, not an operative clause. Change-class FIX.** A preamble grounds gates without being one — A2's right home (justifies partiality without a new pass/fail criterion). **Citation correction (flagged, not absorbed):** Berman supports "classification isn't neutral; owned rather than corrected-to-false-neutral" — he does NOT support "therefore build a fully personal partial scheme" (that stronger move is Hope Olson's). **Steward's calls:** (a) cite Berman + Olson each scoped, vs (b) cite Berman for the narrow claim and mark the personal-scheme licensing as the Chamber's own synthesis attributed to neither; plus the exact preamble wording/voice. **Executor task before drafting: verify Olson against the primary source (*The Power to Name*, 2002)** — citing the scout's characterization would repeat A4's error. Provisional default until verified: **(b)**.
|
||
|
||
- **A3 — CoreTrustSeal-level self-audit: ADVANCE as PROPOSAL (reclassified from the executor's FIX-adjacent lean).** Conditioning OPERATIVE status on a trust-attestation baseline changes what the top-level status gate accepts → PROPOSAL-class regardless of how proportionate the practice is. **Audit = three dimensions (not four — fixity is mechanical/continuous, out of the manual audit):** provenance-completeness (annual) · registry-linkage-completeness (annual, double-duty for A1) · legibility-to-successor (every 2–3 cycles — the Prime-Directive check, longest interval so it doesn't turn decorative through overuse).
|
||
|
||
- **A4 — Scope warrant is A2, not collections-as-data: RECORD the correction. Change-class FIX, sequenced AFTER A2's preamble exists.** The 2-of-3 refutation of Santa Barbara Principle 4 as scope-license holds; redirect any spec citation that leans on collections-as-data for *bounded/personal scope* to A2's preamble. Collections-as-data used for *computational tractability* stays untouched.
|
||
|
||
- **B — ordinary amendments confirmed:** (i) `licence`/copyright-status field, (ii) PREMIS as borrow-vocabulary name, (iii) "collections as data" as a framing term — normal FIX/PROPOSAL per item. **Flag:** item (iii)'s text must use "collections as data" in the computational-tractability sense ONLY; do not reintroduce the refuted scope-justification through drafting.
|
||
|
||
- **C — acknowledged, in-loop:** `fidelity_equivalence@1` (REVIEWED-48) stands; the VIAF/ISNI/Wikidata reconciliation now targets the A1 Agent/Nomen registry specifically.
|
||
|
||
**If AUTHORIZED:** Executor proceeds per the action-list (frontmatter sweep now-unblocked; build the Agent/Nomen registry, answering the `retrieve.py` hot-path question first; verify Olson then draft A2's preamble; draft A3 as a PROPOSAL; A4 after A2; B ordinary; C reconciliation-target noted). Every advanced item runs the RFC-supersession amendment process, each its own PENDING/REVIEWED. Tag related commits REVIEWED-49.
|
||
|
||
## REVIEWED-50 — A2 Preamble Editor-Gate (advances REVIEWED-49 · A2)
|
||
**Date:** 2026-07-07
|
||
**Decision:** AUTHORIZED
|
||
**Supersedes:** PENDING-50 · **Ruling type:** jurist editor-gate (format + doctrinal soundness), steward-ratified
|
||
|
||
**Notes:** Editor-gate PASSED. The preamble says what REVIEWED-49 · A2 ruled and only that:
|
||
- Berman carries the narrow claim (bias is real; own it rather than chase a false neutrality); Olson carries eccentric, *situated placement within a system* — not the self-standing-scheme claim; the bounded self-standing scheme is marked as the Chamber's own move, made *against* Olson's stated preference for permeability over new limits, attributed to no one. No A4 leakage.
|
||
- **§2 (adopted):** a bridging clause opens the subsection, distinguishing *arrangement-honesty* (standpoint declared, not hidden) from §I's *fidelity* (checkable-against-source) sense of trust.
|
||
- **§3 (resolved):** "a bounded one must" reads as conceptual entailment, not a tooling-enforced obligation — FIX-class holds.
|
||
- **Placement CONFIRMED:** new subsection under §I. **Lane CONFIRMED:** v2.0.1 patch supersession (not errata — doctrinal content a successor must be able to trace to a dated marker; the legibility-to-successor value under A3).
|
||
|
||
**If AUTHORIZED:** LANDED 2026-07-07 as spec **v2.0.1** — new §I subsection "On the partiality of the arrangement"; v2.0.0 archived immutable (`chamber-library-specification-v2.0.0.md`); chamber `CLAUDE.md` pointer updated; PENDING-50 closed; committed `34c39f1` (pushed github + skemantix). **Next:** A4's scope-citation redirect (now that A2 has a ratified home to point to), then the REVIEWED-49 tail. Tag related commits REVIEWED-50.
|
||
|
||
## REVIEWED-51 — PENDING-51 — A4 + B(iii): the corpus-as-data framing term + the scope-warrant it does not carry (§I subsection)
|
||
**Date:** 2026-07-07
|
||
**Decision:** AUTHORIZED — jurist editor-gate PASSED; steward ratified. Advances REVIEWED-49 · A4 + B(iii). (Spec context: `chamber-library-specification.md`, patch supersession v2.0.1 → v2.0.2, OPERATIVE.)
|
||
**Notes:** One coupled §I subsection — *'The corpus as data — and the warrant it does not carry'* — that introduces 'collections as data' as a **computational-tractability** framing term (B(iii)) and records, in the same breath, that this framing does **not** supply the corpus's bounded/personal scope warrant; that warrant is the §I partiality preamble (Berman/Olson, REVIEWED-50), not Santa Barbara Principle 4 (A4).
|
||
|
||
- **Diagnosis (verify-against-substrate):** grep of the live spec for 'collections as data' returned ZERO hits — the phrase and the refuted Principle-4 scope-citation lived only in the research briefs, never the constitution. So **A4 was preventive/recording** (nothing to redirect in place) and **B(iii) was the term's first entry.** Collapsed to one subsection, the A4 boundary written *into* B(iii)'s introduction — honouring the RULING's "computational-only, no scope-justification leakage" flag structurally.
|
||
- **Primary-source verification (steward-directed, before the gate):** the primary Santa Barbara Statement was fetched. **Principle 8 CONFIRMED verbatim** ('the technical integrity of the data as well as its provenance'; 'acknowledge absences and areas of uncertainty'). **Principle 4 CORRECTED** — it *does* concern designing for specific communities, but as **audience-fit of a data product**, not the **epistemic warrant for a bounded/personal curation**; the frontier brief's flat shorthand was imprecise, and the draft now states the precise distinction. The A4-shaped citation error was caught on our own draft by reading the source.
|
||
- **Jurist editor-gate** (verbatim RULING: `chamber-library/docs/library-science-A4-Biii-RULING-2026-07-07.md`): PASSES 1/2/4/5 as drafted (Q2 "stronger than a minimal pass" — naming Principle 4 to refute it in the same breath is the safer construction; Q1 correction "the right level of precision"). **Q3 ruled confirm-don't-default-soften**; the executor confirmed by §IX substrate read → **Case A**: §IX's own `Still open` text settles the coverage-ledger, evidence-tier column, and freshness/honest-degradation, leaving ONLY silence-as-finding open (explicitly separated) → citation stands as drafted, **both terms, NO edit** (the one-word fallback was not triggered).
|
||
- **Lane CONFIRMED:** v2.0.1 → v2.0.2 patch supersession (rationale text, no gate change, no consumer re-verification). Placement §I, immediately after the A2 partiality preamble.
|
||
|
||
**If AUTHORIZED:** **LANDED** — committed `7d1d8d3` (local; Gitea push is the steward's call). `chamber-library-specification.md` bumped v2.0.1 → v2.0.2 (subsection added + v2.0.2 header supersession note); v2.0.1 archived immutable (`chamber-library-specification-v2.0.1.md`, byte-identical, `cmp`-verified); chamber `CLAUDE.md` version pointer updated. Bounded-diff verified (canonical change = exactly the header note + the new subsection; nothing else). Governance record: PENDING-51. **Closes A4 + B(iii)** of the REVIEWED-49 action-list. Remaining tail: **A1** registry (answer the `retrieve.py` hot-path question first), **A3** self-audit PROPOSAL, **B(i)/(ii)** (licence field · PREMIS vocab), **C** VIAF/ISNI/Wikidata reconciliation (→ targets the A1 registry). Tag any follow-on with REVIEWED-51.
|
||
|
||
## REVIEWED-52 — PENDING-52 — Source-archiving wired into graduation (gate zero)
|
||
**Date:** 2026-07-09
|
||
**Decision:** AUTHORIZED (jurist-ruled, steward-authorized)
|
||
*[Executor-drafted from the build + ruling record for the governance trail — steward to confirm against the original PENDING-52 ruling.]*
|
||
**Notes:** Make source-archiving an *enforced* precondition of graduation, closing the 2026-07-02 "archiving IS a step of graduation" directive that was never enforced (the Handke graduation proved the gap — archiving nearly deferred as a "loose end"). Authorized commitments as ruled:
|
||
- **§1 — match on `canonical_slug` ONLY** (never the filename, never the author-first staging slug). `resolve_pending_source(canonical_slug)` resolves a candidate's staged source via `pending-manifest.json`'s `canonical_slug` field — the mechanism the repo-evidence *forced* once the two slug conventions turned out to differ.
|
||
- **§3.3 — verify-landed, never trust the return:** `source_gate()` = gate zero — already-archived (`manifest_has`) satisfies it; else resolve → **archive-first** (`--add`) → **verify the entry actually landed** → only then proceed; refuse (`SOURCE-REFUSED`) otherwise.
|
||
- **§4 — idempotency:** `--add` no-ops on sha256 MATCH, **REFUSES (exit 2, `ARCHIVE CONFLICT`)** on same-slug / different content.
|
||
- Change-class **PROPOSAL** (adds a precondition to *what graduation accepts*).
|
||
**If AUTHORIZED:** LANDED — `archive_sources.py` (resolve + idempotency), `graduate_to_canonical.py` (`source_gate` gate zero), `graduation-spec.yaml` (`preconditions: source_archived`); 2 test fixtures, fleet 68→73. Parked as its own thread (§3): is the graduated corpus title-first or genuinely mixed (2 data points is thin; the per-candidate mechanism is robust either way). Tag follow-ons REVIEWED-52.
|
||
|
||
## REVIEWED-53 — PENDING-53 — Engine source-binding completion (re-anchor spans both repos)
|
||
**Date:** 2026-07-10
|
||
**Decision:** AUTHORIZED — Ratified (draft §5, disambiguation option (b), with one required wording correction). Jurist ruling, steward-relayed.
|
||
**Notes:** Completes the graduation-spec `layers` hash-locality principle to name the studium-engine source-binding surface a chamber-canonical re-hash invalidates. The diagnosis holds as a **completion, not a correction**: the `voice_manifest` line is TRUE about the object it names; the defect is an *omission* (the engine source-binding surface unmentioned) compounded by a *shared-word collision* ("manifest" / "voice" on both the hash-free and the hash-binding objects).
|
||
- **Option (b) confirmed** over (a) and (c): (a) leaves `voice_manifest` bare — the incident replayed in miniature; (b)'s inline warning plants the redirect where the mistake occurs; (c) (rename to kill the shared word) is doctrinally complete but out of scope for a doc-gap patch.
|
||
- **`engine_source_binding` kept as ONE entry** (names a relationship across three files that move together; fragmenting recreates the failure). **Dual warning kept** (inline ⚠ + block comment — two reading grains).
|
||
- **Required correction (applied):** "…re-anchors ACROSS BOTH REPOS" (descriptive) → **"…REQUIRES re-anchoring across both repos"** (prescriptive — the gate catches the failure; nothing does it automatically; that IS the incident).
|
||
- **Change-class FIX** (downgraded from the filed [PROPOSAL] default — documents an already-existing, already-enforced mechanism; adds no gate predicate). **Lane: lightweight in-place edit**, `PENDING.md`/`REVIEWED.md` audit trail sufficient.
|
||
- **Durable lane-rule (jurist proposed, executor responded):** ACCEPT "lane tracks change-class" for `graduation-spec.yaml` (machine-data). **NARROW the `.md` generalization** — A2/A4 (REVIEWED-50/51) are FIX-class doctrinal `.md` additions that correctly took the *heavier* freeze+semver lane, because the operative axis for the constitution is *doctrinal-traceability* (a successor must trace doctrine to a dated marker), not change-class; the two coincide only for machine-data files.
|
||
- **[ACCEPTED + narrowed by the jurist 2026-07-10** (`hash-locality-ratification-and-lane-narrowing-JURIST-RULING-2026-07-10.md` §2). **Ruled rule:** machine-data files (`graduation-spec.yaml`) — *lane tracks change-class* (the code/git/`test_tools` history is the independent fallback that pins "what was true when"). The `.md` constitution — *lane tracks whether the change touches doctrine a successor must trace to a dated marker*, regardless of change-class (no code-level fallback; the prose IS the sole record). The two axes coincide only for machine-data files. Not "every `.md` edit gets the heavy lane" — a typo/dead-link fix that adds no doctrine does not.**]**
|
||
|
||
## REVIEWED-54 — PENDING-54 — EPUB footnote pre-processor (verbatim-safe conversion stage) + mega-EPUB split-convert
|
||
**Date:** 2026-07-10
|
||
**Decision:** AUTHORIZED IN PRINCIPLE — ship now for the bidirectional-mirror class, conditioned. Jurist ruling, steward-relayed. Build-in authorized.
|
||
**Notes:** Architecture sound (§1) — moving the intervention *before* pandoc, onto raw XHTML where footnote structure is uniform, removes the reason the regex-family pile needed to exist (a fix to the problem class, not a bigger patch). Recognizer is a mirror-pair *first*, positional rule only disambiguating within a verified pair — closes the "numbered prose misread as a note" risk. Honest-refuse demonstrated (Polastron 95 / Jung ~20k untouched), not asserted.
|
||
- **§2 — markers CONFIRMED apparatus under §V** (not a new precedent — pandoc already renumbers natively for every Kafka-class book; if marker preservation were required, the ratified pipeline would already be in violation). Settles an assumption `clean_epub_residue` ran on implicitly.
|
||
- **§3 — proof standard: multiset is the right tool** (a whole-doc sequence diff would flag legitimate relocation). **REQUIRED before canon: per-pair check** — DONE: id-matched by (destination-file, id); re-proven G&G 27 / Mauss 628 / Polastron 140 / Jung 1086, 0 mismatch, teeth demonstrated. Surfaced Jung's cross-volume id reuse.
|
||
- **§4 — change-class PROPOSAL confirmed** (sharpened test: PROPOSAL if it alters a gate's stated criteria *or* the trusted mechanism a critical gate's meaning depends on — this inserts a new component into §V's production chain; distinct from PENDING-53's FIX, same underlying principle).
|
||
- **§5 — ship for the mirror class now, CONDITIONED:** the existing regex tools (`clean_epub_residue` A–D, `clean_pandoc_html_residue`) stay in place, untouched, as the fallback for uncovered classes — **addition, not replacement**.
|
||
- **§6 — governance placement: yes** (fleet tool + `test_tools` fixtures + `graduation-spec.yaml` `converted_with` note).
|
||
- **§7 — mega-EPUB provenance (Jung): OPEN, non-blocking, steward+jurist together.** Jurist leans per-volume (Jung is cited by CW volume; single file fights use) provided the safeguard is airtight (each volume `source`/`source_verified` → the single megavolume sha256; frontmatter states extraction, never poses as a standalone Bollingen edition). Executor fact-check: the corpus does BOTH; **per-volume precedent EXISTS** (Alexander *Nature of Order* 4 files · Lacroux 2 · Habermas/Burney/Camus vol-named). Split is proven content-neutral, so the choice carries no conversion risk — a usability/honesty question. *[Steward + jurist to settle; governs re-converting the legacy Jung `.md`, 0 notes / pre-spec frontmatter.]*
|
||
**If AUTHORIZED:** BUILD-IN DONE under fleet discipline — `scripts/inject_epub_footnotes.py` (+ `--validate`, refuse-on-mismatch) + `scripts/convert_mega_epub.py`; `test_tools` fixture (fleet 73→77); `graduation-spec.yaml` + `conversion-runbook.yaml` (`policy.footnote_preprocessor`) + `tool-evolution-log.md`. Full brief: `docs/epub-footnote-preprocessor-FOR-JURIST-2026-07-10.md`. Deferred: recognizer coverage of remaining families; per-volume boundary detection (§7); ratified-spec §V cross-ref (runs the `.md` amendment lane, NOT landed here); re-convert legacy Jung/Donne. Tag follow-ons REVIEWED-54.
|
||
|
||
## REVIEWED-55 — EPUB footnote pre-processor: end-to-end verify + recognizer arc
|
||
**Date:** 2026-07-12
|
||
**Decision:** AUTHORIZED (as ruled by the jurist; steward-confirmed)
|
||
**Corresponds to:** PENDING-55 · Jurist ruling `chamber-library/docs/end-to-end-verify-and-nested-block-JURIST-RULING-2026-07-12.md`
|
||
|
||
**Notes:** Ratifies the jurist's ruling on the footnote arc:
|
||
- **Q1a — end-to-end verify RATIFIED, FIX-class** on the refined test: a §V-chain component is FIX when it (i) only ADDS refusals, (ii) never alters text, (iii) falls back to an already-trusted path. `verify_end_to_end` satisfies all three — turns the guarantee from *verbatim-safe by construction* to *by verification*.
|
||
- **Q1b — MANDATORY at graduation** (`--no-verify` forbidden at graduation while `body_word_conservation` is unenforced), PERSISTS after that gate lands (defense-in-depth), **+ RETROACTIVE re-verification required.** [Retroactive sweep DONE (`6c9ca43`): 87 covered books · 42 clean / 45 dirty; **corpus SAFE — 0 dirty graduated**; recognizer's reliable coverage ≈42/87.]
|
||
- **Q1c — marker-exclusion made POSITIONAL** (DONE, `e8eeea7`).
|
||
- **Q2 — nested-block FIX RETRACTED, honest-refuse CONFIRMED** (the widen pairs but converts dirty; the end-to-end verify caught it; reverted). A fresh PROPOSAL required if ever revisited. Jurist generalization: *structural safety = provisional FIX; end-to-end verbatim proof on real books = final.*
|
||
- **Broader flag (jurist):** `body_word_conservation` declared-but-unenforced is the same gap-shape PENDING-52 closed, recurring → now addressed by PENDING-56 (the general verbatim gate = the converter-agnostic trust layer).
|
||
|
||
**If AUTHORIZED:** Proceed; tag commits REVIEWED-55. Open follow-ons: wire mandatory-at-graduation (flow must not pass `--no-verify`); the recognizer-maturity decision (improve over-pairing vs accept 42-clean + fallback) is now **subsumed by PENDING-56** — the recognizer repositions as the sidecar note-extraction layer.
|
||
|
||
---
|
||
|
||
## REVIEWED-56 — Canonical format: adopt Docling + complete MD-canonical + TEI-mirroring structural sidecar
|
||
**Date:** 2026-07-12
|
||
**Decision:** AUTHORIZED
|
||
**Corresponds to:** PENDING-56 · Jurist RATIFICATION 2026-07-12 · Brief `chamber-library/docs/canonical-format-decision-FOR-JURIST-2026-07-12.md`
|
||
|
||
**Notes:** Steward-decided on the four-tier Docling trial evidence (AskUserQuestion, 2026-07-12); jurist RATIFIED on independently-verified reasoning (not deference):
|
||
- **Option A** — canonical = clean Markdown (Docling-converted, verify gates on top) + a `.meta.json` structural sidecar whose vocabulary MIRRORS TEI (`front`/`body`/`back`; `note @place=foot|end`; `milestone`/anchor; reserved `app` slot; `pb`/page-provenance).
|
||
- **D1 — adopt Docling** as the EPUB/PDF/scan conversion front-end (MIT, local, per-element provenance); production OCR on CapableHands (M4). Docling **crosses the A3 OCR frontier** `ocrmac` could not.
|
||
- **Change-class: PROPOSAL** (changes what graduation produces; touches engine consumer contract §X; whole corpus).
|
||
- **Flip-condition tested by the jurist, NOT triggered for v1:** the engine needs neither structured critical-apparatus (A5) as data nor DTS-interoperability in v1 (voice-manifest = interpretive-persona per PENDING-53, not manuscript-variant; the Loeb tier's Stephanus/Bekker need is anchors [B2, which A provides via the sidecar anchor-map], not apparatus). TEI = documented, revisitable future-migration path with those two named triggers.
|
||
- **Two schema-gating questions CLOSED before schema lock (brief §8), from substrate evidence:**
|
||
- **Q1 — recognizer arc REPOSITIONED, not retired:** Docling emits flat reference-links (0 native `[^N]`, 48 `[*](#…)`; `epub_backend` never reads `epub:type`) → this week's 8-family detection + cross-file anchor resolution + end-to-end verify becomes the sidecar's note-extraction layer; the verify stays as the converter-agnostic verbatim gate.
|
||
- **Q2 — CARDINAL EXTRACTOR PRINCIPLE:** the Loeb DSL is typed (`[c dimgray]` 2.15M · `[c darkmagenta]` 471K · `[sup]`) and the current extractor *flattens* it → the extractor MUST **preserve every source-declared typed distinction into a typed sidecar field, never flatten to prose** — makes TEI-migration mechanical-by-construction.
|
||
|
||
**If AUTHORIZED:** Proceed on the architecture; tag commits REVIEWED-56.
|
||
1. Adopt Docling as the conversion front-end; production OCR on CapableHands.
|
||
2. Author the `.meta.json` sidecar schema on the two cardinal principles.
|
||
3. Build the sidecar extractor (EPUB metadata + Docling PDF labels + note-linkage), honest-flag undeclared roles; prove on montaigne (EPUB2) + jacobs (EPUB3).
|
||
4. Keep the trust gates (`verify_body_conservation`, `normalize_ocr` verbatim-guard) on Docling output.
|
||
5. Loeb B2: rewrite `extract_loeb_dsl` → MD + sidecar, preserving the DSL color/`[sup]` typing.
|
||
6. Spec: v2.x amendment (Docling front-end + sidecar as graduated structural layer) — change-class PROPOSAL, runs the amendment process; retire `ocrmac_pdf` + EPUB cruft-strippers; reshape reprocess track B.
|
||
**Per-content check deferred to the B2 build (not a blocker):** whether `[c darkmagenta]` is apparatus-variants vs bilingual source-text — resolve by sampling volumes; the preserve principle covers both. **[RESOLVED 2026-07-12 by substrate probe: `[c darkmagenta]` = Loeb-reader-RENDERED headers (author/work/book), NOT apparatus; `[c dimgray]` = rendered line-anchors + page-markers + `[sup]` refs. The colors are the reader's rendering, usable as reliable role-CUES, attested honestly as `loeb-render:*`.]**
|
||
|
||
---
|
||
|
||
## REVIEWED-56 — LOCK ADDENDUM (whole-schema lock ruling, 2026-07-12)
|
||
**Date:** 2026-07-12
|
||
**Decision:** AUTHORIZED — whole-schema lock CONFIRMED (schema-side, unconditional)
|
||
**Corresponds to:** PENDING-56 (schema-lock) · Jurist RULING #2 `chamber-library/docs/...B2-evidence-and-whole-schema-lock-JURIST-RULING-2026-07-12.md` · Executor briefs `docs/sidecar-schema-FOR-JURIST-2026-07-12.md` + `docs/sidecar-schema-lock-addendum-B2-evidence-2026-07-12.md`
|
||
|
||
**Notes:** Second jurist ruling in the PENDING-56 arc — the schema LOCK (the first ruling ratified the format/architecture; this locks the `.meta.json` sidecar schema itself). Jurist confirmed on independently-checked B2 evidence, not deference:
|
||
- **Whole-schema lock CONFIRMED, unconditional on the schema side** → DRAFT (`docs/sidecar-schema-DRAFT-v0-2026-07-12.md`) flips to LOCKED. B2 (`scripts/build_loeb_sidecar.py`) demonstrated flag-and-hold *in code* on the corpus's densest apparatus volume (Ennius FRL Vol I: 44 concordance tables held as typed rows; Diophantus: 38 glyph char-images held with filename preserved) — read back from emitted JSON, not asserted. Every field held; **no missing field**.
|
||
- **§3 two minor items CONFIRMED, no schema impact:** (a) `source_declared: "loeb-render:*"` — a new *value* in the existing field's vocabulary, honestly naming a render-cue (weaker than `epub:type`); (b) `app[]` interior shapes `{kind:"table"}` + `{kind:"glyph"}` — principle-5 reserved slot resolved from real evidence.
|
||
- **§4 additive-only amendment discipline CONFIRMED + ONE ADDITION:** LOCKED = meaning/shape of every existing field (books trust them); FLEXIBLE (FIX-class, amendment lane) = new optional fields + new `app[]` kinds (backward-compatible; a pre-addition book simply lacks it); PROPOSAL = changing a locked field's meaning **— AND field REMOVAL** (jurist addition: a presence-checking consumer breaks identically from removal as from meaning-change; same silent-retroactive risk → same PROPOSAL treatment).
|
||
- **ONE condition MOVES (not closes), extractor-side, does NOT block the lock:** the jurist distinguishes apparatus *density* (what Ennius maximizes) from *diversity of kind*. "Densest volume fit the schema" ≠ "worst case seen" — a sparser volume among 952 could carry a third form (marginal sigla, interlinear glosses; already present in the corpus as `<ul>/<li>` lists + `<h2/h3/h4>` headings, which the v0 prototype does NOT yet hold). **Before B2 runs across the full ~952-book Loeb tier** (not before the lock): confirm/demonstrate a *generic* "unrecognized apparatus shape → flag-and-hold" fallback (mirroring the line-range join's flag-on-unresolvable), so safety is seen-or-unseen-independent. Extractor-completeness, behind the amendment.
|
||
|
||
**If AUTHORIZED:** file REVIEWED-56 (this addendum); flip the schema doc DRAFT → LOCKED; tag commits REVIEWED-56. Then, as separate additive amendments: the graduation-spec wiring (sidecar as graduated structural layer) + the B2 extractor completeness (generic fallback + `<section>`-div sections + footnote ref↔body pairing). Books may write against the locked schema meanwhile.
|
||
|
||
## REVIEWED-57 — Enforce `body_word_conservation` at graduation (the converter-agnostic verbatim trust gate)
|
||
**Date:** 2026-07-12
|
||
**Decision:** AUTHORIZED — FULLY RATIFIED (jurist, after a two-round demonstration loop)
|
||
**Corresponds to:** PENDING-57 · Jurist rulings (3): architecture → V-DSL-demo condition → full ratification · Brief `chamber-library/docs/verbatim-gate-enforcement-FOR-JURIST-2026-07-12.md`
|
||
|
||
**Notes:** The PENDING-52 gap closing at the foundational layer — the declared-but-unenforced `body_word_conservation` gate (listed in `graduation-spec.yaml` line 136, not enforced by `verify_graduation.py`) becomes the gate that is actually checked. Ratified by the jurist across three rulings, each demonstration-gated, not deference:
|
||
- **Architecture RATIFIED:** three-tier verdict FLAG→blocks · REVIEW→holds-for-curator · PASS→proceeds. REVIEW is real work (endnotes-keep vs index-drop can't be told by alignment position alone), not a soft pass. V-SCAN abstains by construction (no ground truth). Change-class **PROPOSAL** confirmed — distinct from REVIEWED-55's refusal-only-FIX exception because a FLAG / unresolved-REVIEW has NO already-trusted fallback route to canon.
|
||
- **Per-tier dispatch:** V-DSL (Loeb, re-extract) · V-TEXT (born-digital, re-convert + prose-word guard — BUILT, caught jacobs 888 / manguel 2856 / montaigne fn-id residue that audit_cruft missed) · V-SCAN (abstain). Provenance verified: spec v2.0.0 §Tiering & Fence is ratified (RATIFIED-SHAPE · OPERATION-BLOCKED) — this un-blocks a ratified shape.
|
||
- **V-DSL DEMONSTRATED, both halves (the jurist's demonstration condition):** the naive reuse of the V-TEXT k-gram check FALSE-FLAGGED a clean book (his caution vindicated) → corrected to a **reflow-tolerant word-multiset** on source-content body. FABRICATION: clean Apollonius (verse) + Plato Gorgias (prose) → 0 PASS; inject → FLAG naming tokens. LOSS (2nd condition): independent teeth via a boilerplate-vocab classifier — clean `lost_content 0 PASS`; drop a content word (`banquet`) → FLAG naming it. Both halves now on direct injection proof, not trust. Fleet fixtures both sides (`test_tools` 105→111).
|
||
- **Auto-PASS RATIFIED for V-DSL's loss side** — the demonstrated teeth suffices for the general case; the honestly-named residual (a dropped occurrence of a ~15-word boilerplate-vocab token, masked by its header count — can only lose a stopword or the author's name) does NOT warrant blanket REVIEW-routing. **Documented in the gate itself** (`verify_body_conservation.classify_dsl`, tagged REVIEWED-57) with a **revisit-trigger**: if the retroactive sweep ever surfaces a real instance of this masked-vocab failure, weigh tighter checking then.
|
||
- **§6 RETROACTIVE sweep RATIFIED as folded:** on landing, the gate runs BACKWARD across graduated canon (V-DSL 952 · V-TEXT 239) — diagnostic-map-first → remediation queue (FLAG=re-verify→reconvert; REVIEW=curator; PASS=re-attest), NOT silent de-graduation. Well-precedented by REVIEWED-55's own retroactive sweep (87 books, 0 had actually graduated dirty). Expect a non-trivial fraction (the 3/3 morning sample: jacobs/manguel/montaigne all graduated-clean, all failed). Companion efficiency (noted, not required): the LOCKED sidecar's `placement:back`+`role` resolves the REVIEW-tier endnotes-keep/index-drop ambiguity declaratively for any book carrying a sidecar.
|
||
- **43-book census CONFIRMED:** V-DSL 952 · V-TEXT 239 · V-SCAN 50 · V-SUSPECT 29 · V-NONE 14 = 1,284; the 43 = V-SUSPECT+V-NONE = the fenced-out tier (no confirmed source) → correctly outside the sweep (a provenance problem, not a coverage gap). Jurist noted (not a condition): these 43 are the same gap-shape PENDING-52 closes going forward — worth attention once the queue moves.
|
||
|
||
**If AUTHORIZED:** land by supersession into `graduation-spec.yaml` (make the listed `body_word_conservation` gate enforced + declare the per-tier dispatch) + `verify_graduation.py` (add the per-tier body-conservation gate with source access + tier dispatch) — tag commits REVIEWED-57. Follow-ons: the retroactive sweep run (diagnostic-first) once landed; the sidecar-declaration REVIEW shortcut when convenient; the 43 fenced-out books to source-location. The V-DSL loss residual + revisit-trigger are already in the gate's docstring.
|
||
|
||
## REVIEWED-58 — 2b: Wire the Loeb structural sidecar into graduation (V-DSL tier) on its own merits
|
||
**Date:** 2026-07-18
|
||
**Decision:** AUTHORIZED
|
||
**Notes:** Residual-(b) met in purpose (jurist ruling 2026-07-18: `chamber-library/docs/2b-first-vdsl-exercise-JURIST-RULING-2026-07-18.md`). **What was exercised: the verification and sidecar-production path — six real books, dry-run.** The V-DSL body branch fired correctly (no false ABSTAIN, no false UNVERIFIED; body-conservation fabrication 0 · lost content 0 per work) and the per-field boundary held under real conditions (anchors uncredited `loeb-line` only; `citation_coverage` and the critical-apparatus channel not produced, ×6). **Not exercised: the apply/archive path — unproven and known broken** (the pending→archive `add_single` seam, docketed to PENDING-52's lineage as PENDING-63; the shared-source archive design to be ruled on hash-locality grounds before any `--apply`). Evidence scope: 6/6 PASS on a CLEAN-selected set proves **no false refusal**; **discrimination** is proven separately by the seeded injection tests (fleet teeth + the 2026-07-14 seed-test). `table`/`unrecognized` credit rests on B2's earlier demonstration, not this exercise. The line-ref coordinate contract remains OPEN and unbound; its consequence for #2's re-stamp (known-defective input) is recorded. A later reader must not take this REVIEWED as "graduation works end-to-end" — it does not yet. Evidence: `chamber-library/docs/2b-first-vdsl-exercise-RECORD-2026-07-18.md`.
|
||
**If AUTHORIZED:** #1's wiring (commit `7f98488`) stands as landed; tag follow-on commits REVIEWED-58. Block 1 closes on this placement; the apply leg follows at its own pace.
|
||
|
||
## REVIEWED-59 — PENDING-59 — A3: CoreTrustSeal-level self-audit
|
||
**Date:** 2026-07-16
|
||
**Decision:** AUTHORIZED — ratifying the jurist-reviewed PROPOSAL (jurist review PASSED 2026-07-16 with 3 edits applied + the release-mechanism gap closed). Advances REVIEWED-49 · A3.
|
||
**Notes:** Trust-attestation baseline conditioning OPERATIVE status. Three dimensions (fixity excluded — automated): provenance-completeness (annual, FLAG) · registry-linkage (annual, FLAG; double-duty for A1's emergent `agent_id` promotion signal) · legibility-to-successor (every 2–3 cycles, HARD FLOOR on failure). Legibility failure = fence-verdicts-unreadable OR fence-evidence-unreadable OR operative-doctrine-not-followable (evidence-alone-floors); degrees above still flag. **Cold-instance audits; jurist adjudicates the result** (neither steward nor jurist audits — both carry participation-context). Release from a floor: a fresh cold-instance pass, jurist-adjudicated. Flag home: `corpus-quality-ledger.tsv` + a dated status-marker line. Fixity stays automated (the audit confirms the automation, never re-hashes by hand). Legibility at 2–3 cycles by design (a load-bearing check run too often turns decorative).
|
||
**If AUTHORIZED:** land as a **new spec section** (*Trust Attestation / Self-Audit*, cross-ref §IX) by supersession + semver — new section = a minor bump (**steward's call: v2.0.2 → v2.1.0**). Tag commit REVIEWED-59. Records: PENDING-59; draft `docs/A3-self-audit-PROPOSAL-FOR-JURIST-2026-07-16.md`; ruling `docs/A3-self-audit-PROPOSAL-JURIST-RULING-2026-07-16.md`.
|
||
|
||
## REVIEWED-60 — PENDING-60 — Citation amendment (#2): specify the adopted CTS-URN model + chamber-minted namespace/boundary + per-scheme coverage attestation
|
||
**Date:** 2026-07-17
|
||
**Decision:** AUTHORIZED — RATIFIED. Steward ratification, following the jurist editor-gate (2026-07-17, passed on doctrinal soundness + format) with two corrections + one condition discharged.
|
||
**Notes:** Ratifies the citation amendment as a **specification** of §IV's already-adopted CTS-URN edition-identity — not a re-adoption. Ratified content: the **chamber-minted CTS-URN namespace** + the **internal (T1) / external (T2, leashed Condition-2) boundary** (the precondition genuinely met — CTS boundary drawn, clean-separation verified against the tier survey, not asserted); **per-scheme in-source anchor recovery** with the routing as **declared data** in `graduation-spec.yaml` (§VII generative principle); the **per-scheme coverage attestation** (§IX-as-precondition) as an **explicitly *partial*** answer to §IX's open silence-as-finding (anchor-scheme silence only; the general question stays open); **work-level as the honest default** (§III's sectionless floor applied); **Decision-1**; and the **additive-only** sidecar fields.
|
||
- **Q1 confirmed:** minting inside `urn:cts:` is grammatically valid (not IANA-governed; CHS registry dormant; witness-not-notary) — not an affiliation; a proprietary scheme would lose additive-openness for no gain.
|
||
- **Corrections discharged (package Addendum):** Q2 partial-§IX wording applied; Q6 shed/inherit cross-checked #1↔#2 side-by-side (six-for-six identical, (f) "originates" in both — the seam is closed); Q5 additive-only verified against the LOCKED schema (`anchors[].scheme` already present; `citation_coverage[]` a new optional field = FIX).
|
||
**If AUTHORIZED:** Land by supersession at **MINOR v2.1.0** (jurist-confirmed defensible; forward-only, 0 Loeb verified). Tag commits REVIEWED-60. **Semver/vehicle — steward annotation here:** land as one **atomic** v2.1.0 supersession together with A3 (REVIEWED-59) [and optionally #4/#5, REVIEWED-61], OR sequence — the jurist's atomicity constraint applies (one edit, not several racing the same version). Production dependencies (the ~3,333-anchor re-stamp, the Region-4 re-extraction, the flagged-token held-queue) run **after** ratification.
|
||
|
||
## REVIEWED-61 — PENDING-61 — B(i) `licence` provenance axis + B(ii) PREMIS borrow-vocabulary (the two light FIXes, paired)
|
||
**Date:** 2026-07-17
|
||
**Decision:** AUTHORIZED — RATIFIED (FIX, both). Steward ratification, following the jurist editor-gate (2026-07-17, both passed as FIX) with two wording corrections discharged.
|
||
**Notes:** Two gap-fills on already-ratified layers; neither changes what any gate accepts.
|
||
- **#4 (B(i)) — `licence` provenance axis (§IV):** the machine-readable rights status of the *edition converted*, holding §IV's **"must carry, where known"** discipline (jurist correction applied — not the weaker "may carry"), with an explicit `unknown` **distinguishable from an unrecorded gap**; graceful-degradation, **never a gate**; value vocabulary = declared data in `graduation-spec.yaml`.
|
||
- **#5 (B(ii)) — PREMIS borrow-vocabulary (§V naming note):** names the existing PROV-shaped conversion record with PREMIS's preservation vocabulary — the DTS "borrow-vocabulary, build thin" posture; **naming-only, no data model, pre-authorizes no field** (jurist clarification applied — any future PREMIS-named field is a separate additive amendment on its own FIX review). §V's shape/requirement unchanged.
|
||
**If AUTHORIZED:** Land by supersession as FIX. Tag commits REVIEWED-61. **Semver/vehicle — steward annotation here:** (a) fold into the atomic v2.1.0 supersession with #2/A3, or (b) a standalone v2.0.3 patch — the jurist's default-(b) if #2/A3 aren't landing imminently; steward's coupling-of-timing call.
|
||
|
||
## REVIEWED-62 — FIX-A item-(f) seam clarification + FIX-B `app[]` naming collision (the two ruled 2b follow-ons, paired)
|
||
**Date:** 2026-07-18
|
||
**Decision:** AUTHORIZED
|
||
**Notes:** Jurist light editor-gate passed [date; corrections if any]. Term confirmed: [critical-apparatus channel / other]. FIX-A clears the 2b
|
||
wiring-build gate.
|
||
**If AUTHORIZED:** Proceed. Apply the edit-set per the brief; tag commits with REVIEWED-62.
|
||
|
||
## REVIEWED-63 — Gate zero's pending→archive seam + the compound-source archive form (PENDING-52 lineage)
|
||
**Date:** 2026-07-18
|
||
**Decision:** AUTHORIZED
|
||
**Notes:** Jurist design-gate PASSED 2026-07-18 (`chamber-library/docs/PENDING-63-design-gate-JURIST-RULING-2026-07-18.md`; package + addendum: `docs/PENDING-63-JURIST-PACKAGE-2026-07-18.md`). One docket at PROPOSAL weight: the seam repair = FIX (restores REVIEWED-52's ratified accept-criterion — half the ruled flow was dead code since birth, substrate-verified 0/324); the compound-source form = PROPOSAL (Option B: a first-class artifact record owns the artifact's hash once; work entries reference by id and carry no sha — hash-locality forbids many homes for one binding, not repeated hashes across different bindings; silent divergence traded for loud dangling references). All ruled properties built: affirmative role test · copy→verify-landed→remove (verify reaches the disk sha) · remove-don't-mark with the trail carried into the one home · artifact-level §4 teeth + the re-pointing case · symlink dereferenced + shas recomputed · enforced_by updated in-pass · dry-run coverage labelled. **Ratification condition met: the end-to-end positive test shipped in the same change (fleet 157/157), and the first real pending-staged graduation was observed same day** — the loeb.dsl artifact archived once (533,434,439 bytes, disk-verified), 6 works attached and graduated with re-stamped sidecars, staging cleared by the last reference, 14 legacy entries untouched, catalogue 1300 canonical, engine gate canary clean. Steward authorized conversationally 2026-07-18.
|
||
**If AUTHORIZED:** LANDED — commits `744417b` (mechanism + ratification test) and the observed-run commit, tagged REVIEWED-63. PENDING-63 closes; the compound-source archive form is established; `--apply` for future pending-staged graduations is live on the proven path.
|
||
|
||
## REVIEWED-64 — The line-ref coordinate contract: one landed-file contract, five families, frame declaration, multi-point probe
|
||
**Date:** 2026-07-19
|
||
**Decision:** AUTHORIZED
|
||
**Notes:** Jurist design-gate PASSED 2026-07-18 (`chamber-library/docs/coordinate-contract-design-gate-JURIST-RULING-2026-07-18.md`, filed verbatim; package + Addendum: `docs/coordinate-contract-FOR-JURIST-2026-07-18.md`). One docket at PROPOSAL weight with FIX parts (the PENDING-63 pattern). Ruled: **ONE constitutional coordinate contract** — a 1-based line in `source_file`, valid against `source_sha256` (hash-locality extended from *which file* to *where in the file*); the producer's array index is a tool detail in a **declared transitional state** ending at translation — a consumer builds to one contract and refuses anything marked untranslated. **The contract binds all five field families** (`sections[]` · `provenance.pages[]` · `notes[]` · `anchors[]` · `app[]`) per §III's shared-substrate clause: no committed sidecar may exist in a mixed-frame state; translation covers all five in one operation per work (vehicle decided at #2's build — #2's scope widened explicitly or an atomic companion pass; the mixed state never allowed). Translation at #2's re-stamp (item (f)); `write_sidecar` continues to bind the file only. Frame remedy: **name the frames, don't rename the field** — one per-sidecar declaration, **schema-optional, gate-required**, FIX lane, naming in the schema doc's Naming note. **Declare now on all eleven** landed sidecars. **`notes[]`'s credit stated explicitly as linkage-only** — it does not extend to its line coordinates. Proof condition: `citation_coverage.status: verified` only for coordinates verified in the landed frame by **multi-point content probe per work**; where no single constant resolves all probes, the work is **held, not force-fitted**.
|
||
**If AUTHORIZED:** proceed to build the FIX parts (frame naming + per-sidecar declaration + the graduation refusal + the eleven declarations + the `notes[]` linkage-only statement), tag commits REVIEWED-64; the contract's constitutional text lands via the amendment lane at PROPOSAL weight (hook-gated, grounded); translation itself remains #2's work under the ruled proof condition.
|
||
|
||
## REVIEWED-65 — The coordinate contract lands as spec v2.2.0 (§III subsection; requirement constitutional, mechanism declared data)
|
||
**Date:** 2026-07-19
|
||
**Decision:** AUTHORIZED
|
||
**Notes:** Jurist gate + placement ruling PASSED 2026-07-19 (`chamber-library/docs/coordinate-contract-edit-set-JURIST-RULING-2026-07-19.md`, filed verbatim; edit-set spine + Addendum: `docs/coordinate-contract-amendment-edit-set-2026-07-19.md`). REVIEWED-64's FIX parts pass as built (the contract-frame-at-#1 refusal noted by the jurist as "the best thing in this build" — the gate refuses the dangerous *claim*, not merely the dangerous value). **Placement: (a) spec supersession** — separable from PROPOSAL weight; ruled on doctrinal-traceability (the A3 legibility test: §III is where a successor looks, and the contract constrains what §III's substrate means). **Required correction applied before ratification:** the constitution states the verification *requirement* (a coordinate is attested `verified` only when verified in the landed frame against `source_sha256` — never defaulted, never for translated-but-unverified values) and the no-mixed-frame *property*; the *mechanism* (multi-point probe per work · per-work-constant offset model · hold where no single constant resolves — specified-but-unbuilt) lives in declared data (`graduation-spec.yaml` `sidecar.translation:`), revisable without supersession per §VII's routing-table pattern; the vehicle prescription ("one operation per work") removed in favour of the property, vehicle decided at #2's build. **Both flags applied:** schema doc renamed `sidecar-schema-LOCKED-2026-07-12.md` (filename-says-DRAFT hazard); `producer_frames` keyed to the named producer (unmapped producer → no stamp → line-carrying sidecar HOLDS; witnessed red 186/188 → green 188/188). Pacing note recorded (pre-#2 batches grow the untranslated backlog; batch pacing ⟷ #2 scheduling coupled). **Steward ratified 2026-07-19; v2.2.0 LANDED:** v2.1.0 frozen byte-identical; §III gains *The coordinate contract* subsection (Ion demonstrative record preserved); bounded-diff proven (header block + subsection only; all else v2.1.0 verbatim). Change class: PROPOSAL-class by the change-class test (the graduation refusal changes what the gate accepts), MINOR-semver (forward-only; the eleven were declared in the same docket — no re-verify storm).
|
||
**If AUTHORIZED:** LANDED — commits tagged REVIEWED-64 (`9112564` build · `7dd852e` gate outcome) and REVIEWED-65 (`81cbdd1`, the v2.2.0 supersession). PENDING-64 closes. Translation and the probe build remain #2's work (Region 4) under the declared mechanism; the engine's ingest-side frame check belongs to the engine session.
|
||
|
||
## REVIEWED-66 — PENDING-65 — The one-door promotion rule (design-gate passed with corrections)
|
||
**Date:** 2026-07-19
|
||
**Decision:** AUTHORIZED — proceed per the ruling (one-door confirmed; constitutional landing;
|
||
ratification conditional on the Eichmann pilot's classification-tractability report).
|
||
**Notes:** Ruling filed verbatim at chamber-library/docs/one-door-promotion-design-gate-JURIST-RULING-2026-07-19.md.
|
||
Corrections in force: two-obligations framing (body-conservation = source-fidelity vs reference
|
||
conversion; witness = curation-preservation) replaces "same comparison, disposition flipped";
|
||
curation-to-carry splits fidelity-restoring (carry, declared) / source-departing (never carried;
|
||
preserve + flag per §V Tier-3); "lost nothing" narrows to prose content, structural witness comparison
|
||
a named open gap; E1 exempts re-conversion not the criterion; omnibus promotion unit defined in
|
||
declared data before the pilot; no minimal-sidecar class (absence-because-we-didn't-look refused);
|
||
Q3 block stands per tier pending positive demonstration — door and stamp separable, stamp names
|
||
edition-identity + sha, artifact-readable.
|
||
**If AUTHORIZED:** Proceed to S2b prep (omnibus definition · audit_cruft fix · Eichmann pilot with the
|
||
Q7 report). Tag commits REVIEWED-66.
|
||
|
||
## REVIEWED-67 — PENDING-67 — Per-tier conversion lanes: born-digital EPUB off Docling (design-gate passed with corrections)
|
||
**Date:** 2026-07-20
|
||
**Decision:** AUTHORIZED — proceed per the ruling (proposal sound; compliance framing confirmed from §V).
|
||
**Notes:** Ruling filed verbatim at chamber-library/docs/per-tier-conversion-lanes-design-gate-JURIST-RULING-2026-07-20.md.
|
||
Corrections in force: Q1 SPLITS — III.2 lane assignments = declared data (conversion-runbook.yaml); III.1
|
||
eligibility rule = CONSTITUTIONAL (overrules the executor lean; §V forbids the acts but is silent on
|
||
who-must-demonstrate-compliance-when-by-what-evidence — the gap PENDING-56 fell through; A3 legibility) →
|
||
one-line §V note, MINOR supersession → v2.3.0, folded atomically with the queued one-door text. Q2 boundary
|
||
named by MECHANISM (any source class whose Docling path routes through the HTML backend is ineligible pending
|
||
census; presently = all born-digital EPUB); over-inclusion is FREE, not a cost (pandoc handles plain EPUBs).
|
||
Q3 re-widening = FIX, conditioned on the byte-census SPECIFIED as declared data (sample size, character classes,
|
||
whether partial preservation passes). Q4 general, gating ADOPTION not use (trials/exploration exempt). Q5
|
||
confirmed + DISCHARGED — the graduation-record check ran 2026-07-20: verified-zero (zero EPUB-via-Docling in
|
||
canon; only Docling file is Bringhurst PDF; window added only Loeb DSL) — purely forward-looking, no live breach.
|
||
Forward item, unconditioned: the per-conversion typography gate (byte-census wired per-conversion; closes the
|
||
§V Tier-2 blind spot) — named horizon, future PROPOSAL.
|
||
**If AUTHORIZED:** Proceed to the v2.3.0 text (III.1 §V note folded with one-door) + declared data
|
||
(conversion-runbook.yaml routing + census specification). Tag commits REVIEWED-67.
|
||
|
||
## REVIEWED-68 — v2.3.0 constitution fold (one-door operation · front-end eligibility · datum-not-ledger)
|
||
**Date:** 2026-07-20
|
||
**Decision:** AUTHORIZED — ratify chamber-library-specification.md v2.3.0 as OPERATIVE.
|
||
**Notes:** Placement-gate ruling filed verbatim at chamber-library/docs/v2.3.0-constitution-fold-placement-gate-JURIST-RULING-2026-07-20.md.
|
||
Folds three ruled designs atomically (the ruling's instruction): the one-door promotion OPERATION (REVIEWED-66;
|
||
§Tiering & Fence, criterion status OPERATION-BLOCKED → OPERATION-DEFINED · STAMP-GATED), the front-end eligibility
|
||
rule (REVIEWED-67; §V, boundary by mechanism), and datum-not-ledger (F2 ruling §8; §VII, cross-ref §Trust Attestation).
|
||
Placement corrections applied: re-conversion is VACUOUS (two obligations do the work) not "not vacuous"; converter-worse
|
||
covers lexical content; the curation-bearing second-pilot condition restored as declared data (promotion.scale_application,
|
||
owed) with OPERATION-DEFINED ≠ VALIDATED-AT-SCALE; omnibus values kept out of constitutional prose. v2.2.0 frozen
|
||
byte-identical; bounded diff proven (8 removed = the four intended edits, 145 added). Declared data: the ordered
|
||
born-digital lane (whole-EPUB injection → per-spine) + promotion.scale_application. MINOR (2.2.0 → 2.3.0): no file holds
|
||
`verified` status, so no re-verify storm.
|
||
**If AUTHORIZED:** v2.3.0 OPERATIVE; v2.2.0 immutable. Tag commits REVIEWED-68.
|
||
|
||
## REVIEWED-69 — PENDING-69 — The attested boundary-drop resolution (design-gate passed with corrections)
|
||
**Date:** 2026-07-22
|
||
**Decision:** AUTHORIZED — proceed per the ruling (design-gate passed; a body-conservation REVIEW resolves only by a positive attributed attestation checked for full coverage, interior teeth untouched, never a bypass or computed re-classification).
|
||
**Notes:** Ruling filed verbatim at chamber-library/docs/PENDING-69-boundary-drop-attestation-JURIST-RULING-2026-07-22.md. Package + Addendum: chamber-library/docs/PENDING-69-boundary-drop-attestation-JURIST-PACKAGE-2026-07-22.md. Corrections in force:
|
||
- Q2 — (b) vocabulary-only, AGAINST the executor lean: trim.drop is a controlled label set, not a set of pre-verified drops; every boundary run is per-file attested (the gate can never confirm class membership; a privileged spec-class would be trust-by-name). One layer, not two — relocation is another label, distinguished only by requiring moved_to.
|
||
- Q3 — floor confirmed (coverage + interior-zero + attribution mechanical; classification human). Structural-falsification check ADOPTED (executor decision, recorded, steward-overridable) for index/table-of-contents only — a signature mismatch HOLDS for reconciliation (re-attest or a positive signature_anomaly), never a silent pass, never an un-overridable block; declined where no clean signature exists.
|
||
- Q4 — bind-to-derived-runs ELEVATED to a required property (self-invalidating; forbids inheriting a prior file's attestation).
|
||
- Q5 — moved_to required; an incomplete relocation is a rejected attestation; the fabrication-exclusion is scoped to exactly the named span.
|
||
- Q6 — per-candidate; the omnibus interior-run interaction named (inter-work drops surface as interior runs and FLAG — the boundary-drop mechanism is correctly silent on them; for the Levi second pilot).
|
||
- Q7 — Eichmann as the first fixture PLUS deliberate negatives (un-attested run -> HOLD; interior deletion -> FLAG regardless of a complete boundary attestation).
|
||
- Named tension: this wires human-in-the-loop for discipline, not removal — the 47-file wave is not unattended batch work.
|
||
**If AUTHORIZED:** Q1 minimal constitutional sentence in the §Tiering & Fence one-door subsection (gate-acceptance property; doctrinal-traceability), MINOR — fold into the next assembling supersession or a standalone bump (steward call); mechanism as declared data (attestation schema + controlled vocabulary) in graduation-spec.yaml; the gate's thin-consumer check built test-first with the Eichmann fixture + the two negatives as the ratification condition. Tag commits REVIEWED-69.
|
||
|
||
## REVIEWED-70 — PENDING-70 — The legacy witness, scale-application, and character-as-image (design-gate passed with a substitute Q2 condition)
|
||
**Date:** 2026-07-23
|
||
**Decision:** AUTHORIZED — proceed per the ruling (filed verbatim at chamber-library/docs/scale-application-legacy-body-JURIST-RULING-2026-07-23.md; package + Addendum: chamber-library/docs/scale-application-legacy-body-JURIST-PACKAGE-2026-07-23.md).
|
||
**Notes:** Corrections in force:
|
||
- Q1 — claim scope degrades with the witness (curated → curation-preserved; legacy → no-regression-floor), stated with the obligation; corrects a defect in the one-door ruling's own wording. `witness_class: curated|legacy` = positive attributed attestation (by/date), never inferred from date/conversion_method.
|
||
- Q3 — a character-bearing image dropped from a word is a §V Tier-3 alteration by omission (constitutional); glyph→Unicode map = catalogued Tier-2 declared data. HARD PRECONDITION: glyph-mapping wired AND demonstrated on Levi's three sites (Wstawać, Brașov, Oświęcim) before any imaged source enters the one-door lane — including the pilot's own conversion. calibre+cruft-strip retro-diagnosed ineligible for imaged sources (2nd application of the v2.3.0 rule). Wave reframed as verbatim-fidelity restoration.
|
||
- Q4 — the A3 honest-degradation cross-reference is mandatory, not optional.
|
||
- Q2 — accepted in principle; the manufactured-instance path rejected. Substitute condition: (a) enumerate demonstrable classes in advance (converter-better, regression, converter-worse isolated/systematic, inter-work interior); (b) the pilot MUST report judgment cost (human-minutes/file incl. source-adjudication of mutilation sites; count of source-consultations), not only class coverage; (c) both curation-to-carry classes reported un-exercised with reason, first demonstration bound to the first curated work (open condition); (d) scale opens for legacy-witness promotions ONLY.
|
||
- Representativeness: the ~5% (13/248) is not a corpus rate (backup set is a curation-selected batch); the 13 are a confirmed floor.
|
||
**If AUTHORIZED:** land the reframe as spec supersession v2.4.0 → v2.5.0 (requirements) + declared data (Q2 condition, witness_class, glyph-map, census); wire + demonstrate glyph-mapping on Levi's three sites (the Q3 precondition) before the pilot's fresh conversion; then run the Levi pilot on the substitute condition. Tag commits REVIEWED-70.
|
||
|
||
## REVIEWED-71 — Levi scale-application pilot — promotion.scale_application ratified (legacy-witness-only)
|
||
**Date:** 2026-07-24
|
||
**Decision:** AUTHORIZED — promotion.scale_application ratified on the REVIEWED-70 Q2 substitute condition, grant scope legacy-witness-promotions ONLY.
|
||
**Notes:** Jurist confirmation filed verbatim at chamber-library/docs/scale-application-levi-pilot-JURIST-RULING-2026-07-24.md; report + Addendum at
|
||
docs/scale-application-levi-pilot-REPORT-2026-07-24.md. Condition met on all four legs. Carried with the grant (not conditions): (1) §6 substitution does NOT hold — source-fidelity remains undischarged; Flag-1 (pin V-TEXT reference params) is now LOAD-BEARING → no V-TEXT graduation runs before it closes; (2) corpus-scale arithmetic ~325-430 human-hours across 1,297 files is a steward pacing fact. converter-worse recorded UN-EXERCISED (not passed) alongside curation-to-carry; the 485 "mostly CONTENTS" characterization is inference pending census; fold extension to move into declared data. curation-to-carry's first demonstration bound to the first genuinely hand-curated work (open). Braşov adjudication + negative-control discipline affirmed.
|
||
**If AUTHORIZED:** update graduation-spec.yaml promotion.scale_application status → ratified; Flag-1 gates the wave. Tag commits REVIEWED-71.
|
||
|
||
## REVIEWED-72 — PENDING-71 — Born-digital V-TEXT source-fidelity reference (design-gate passed; executor lean overruled)
|
||
**Date:** 2026-07-24
|
||
**Decision:** AUTHORIZED — proceed per the ruling. Ruling filed verbatim at chamber-library/docs/borndigital-source-fidelity-reference-JURIST-RULING-2026-07-24.md.
|
||
**Notes:** Q1 confirmed and architectural (shared pandoc `-f epub` reader → reader-loss cancels a priori). Two problems separated: (i) shared-reader (structural, unfixable) and (ii) markup-noise (writer mismatch — Flag-1 fixed it); the package's "verifies markup not words" overstatement corrected to "blind to reader-loss only." Q2 ruled AGAINST the executor lean: NOT (b). The ruled reference design = the package's own run (3) — source-anchored + writer-matched (pandoc -t markdown-smart on the raw source EPUB), injection + glyph deltas declared-and-excused (PENDING-69 moved_to shape; fabrication elsewhere still flags), PLUS (a) a periodic per-format-class reader audit whose cadence/trigger (pandoc major-version bump, not calendar-only) + pass-criterion are declared data specified in advance (PENDING-67 Q3 discipline). Anchor upstream — run (3) checks injection+glyph+cleaners; (b) checked only cleaners. Q3 keep name "source-fidelity," claim scope bounded to the lane's reader. Q4 subsumed — pin the RULED design not the gfm-raw_html accident; Flag-1 recorded right-but-insufficient. Q5 47-file wave stays blocked; UNBLOCK = a clean-file PASS on the ruled design + a deliberate negative confirming a real prose loss still FLAGs. Clause 969/1046 reconciled (both survive): 969 = per-file check (run 3); 1046's cross-converter independence RELOCATED to the periodic audit, not struck — vacuity argument preserved. Amendment-process discipline gains: when a change reassigns a named component, check what else names it.
|
||
**If AUTHORIZED:** Build the ruled reference design + specify the periodic audit as declared data + demonstrate the unblock condition (clean PASS + deliberate negative) on a real candidate → then the wave. Land the 969/1046 reconciliation as a §Tiering & Fence supersession (relocate 1046 to the audit). Tag commits REVIEWED-72.
|
||
|
||
## REVIEWED-73 — PENDING-72 — Voice-purity sidecar as the engine-consumable graduation bar (design-gate passed, strengthened)
|
||
**Date:** 2026-07-24
|
||
**Decision:** AUTHORIZED — proceed per the ruling. Ruling filed verbatim at chamber-library/docs/engine-consumption-voice-purity-sidecar-JURIST-RULING-2026-07-24.md.
|
||
**Notes:** Proposal confirmed + strengthened. FRAME ON ORTHOGONALITY: trim.keep answers "should this be preserved?"; voice-purity answers "whose words are these?" — orthogonal and anti-correlated where it matters (the Eichmann leak — Elon's Introduction + Bibliography — was trim.keep, correctly kept; extending the trim is the WRONG fix, it would delete content the corpus should hold). Q1 STRENGTHENED — sections[] must partition the file body EXHAUSTIVELY (every line to exactly one section; no gaps/overlaps), converting silence to assertion (the gate derives nothing here, so nothing else forces completeness). Q2 ruled CHAMBER-SIDE, produced + gated at graduation, engine reads it — because an engine-side sidecar breaks on every chamber re-conversion (ingest_gate sidecar-sha==live; PENDING-53 class, 5 standing FAILED rows since 2026-07-10). Q3 the gate checks existence + binding + schema + two mechanical falsifiers (exhaustive-partition; role from the closed vocabulary {text,paratext,apparatus,reference}), never boundary correctness. Q4 forbid the silent whole-file default forward; MIGRATE the 19 engine sidecars (not grandfather — Eichmann is among them, correct only after the leak), carrying _reviewed notes as attested_by AND adding REVIEWED-64 line_frame: landed-file declarations; backfill scope = engine corpus (~20), NOT chamber (1,297). Q5 V-SCAN baseline applies, rich does not (Warde: reproduced CUP Bible facsimile = apparatus). Cost: a per-file reading pass compounds on the boundary-drop pass — DESIGN the single-reading-pass (the two attestations from one read) before the wave.
|
||
**If AUTHORIZED:** Land the amendment (constitutional requirement framed on orthogonality + declared-data mechanism: sections[] exhaustive-partition · closed-vocab role · chamber-side production · line_frame: landed-file · whole-file attestation) → build the widened sidecar_gate → migrate the ~20 engine sidecars → design the single-reading-pass. Tag commits REVIEWED-73.
|
||
|
||
## REVIEWED-74 — PENDING-73 — Born-digital V-TEXT added-side fabrication check (design-gate passed; in-scope, atomic with REVIEWED-72)
|
||
**Date:** 2026-07-24
|
||
**Decision:** AUTHORIZED — proceed per the ruling. Ruling filed verbatim at chamber-library/docs/borndigital-added-side-fabrication-check-JURIST-RULING-2026-07-24.md.
|
||
**Notes:** Design-gate PASSED; the honest implementation of REVIEWED-72's added-side excuse redefines classify()'s added side from a position-displacement count to a multiset-fabrication measure. The jurist OWNED the refuted premise (the injector enumerates converted_markers on the LOST side, not the added delta — "the producer must know X is not evidence the producer records X"); the measurement found it, the ruling's shape survives. Q1 IN-SCOPE + atomic with REVIEWED-72 on a recorded THREE-PART test (property unchanged · surface refuted by measurement not inconvenience · design-gate reviewed) — a change missing any leg is its own cycle. Q2 MULTISET confirmed over presence (multiset strictly dominates: catches new-vocabulary AND duplication, cancels displacement); the reordering residual is scoped to the STANDING Q3 order-blindness stamp-block (gate does not verify passage order — demonstrated, Eichmann §7), NOT to a converter-behaviour claim. Q3 two-sided glyph manifest confirmed with the required precision: COUNT-SCOPED both sides — added = Counter subtraction (a 7th surplus of a declared token still flags); a lost run is excused ONLY IF every token is manifest-accounted (a partially-accounted run stays flagged). Q4 authorizes the CLASS (glyph restoration) not future declared normalizations (each enters by its own §V review). Latent: the 646 converted_markers are excusable apparatus (REVIEWED-54 §2) invisible only while the loss side stays run-based — recorded as a named dependency on any future loss-side count-basing; the added=count/lost=position asymmetry is a deliberate choice. Demonstration = FOUR cases (adds an Eichmann regression PASS). Architecture: sibling resolve_added, classify() byte-identical, V-DSL + §6 sweep do NOT inherit.
|
||
**If AUTHORIZED:** Build resolve_added + the two-sided glyph manifest test-first, repoint the reference, demonstrate the four cases, then land the §Tiering & Fence supersession atomically with REVIEWED-72's reference reconciliation (record the Q1 three-part in-scope test + the reassigned-component check in the amendment discipline). Tag commits REVIEWED-74.
|
||
|
||
## REVIEWED-75 — PENDING-75 — Kind-scoping the verification criterion (design-gate passed with one required correction)
|
||
**Date:** 2026-07-25
|
||
**Decision:** AUTHORIZED — proceed per the ruling. Ruling filed verbatim at chamber-library/docs/kind-scoping-verification-JURIST-RULING-2026-07-25.md.
|
||
**Notes:** The jurist ADOPTED the package's Part-4 argument over his own framing: the foreclosure is not that a non-text work *fails* the criterion but that the criterion is VACUOUS on it (empty re-extraction is trivially prose-word-identical to its own empty extraction) — the corpus's recurring false-positive shape, caught prospectively for the first time rather than after a finding.
|
||
- **Required correction (applied):** Edit 1 must not assert prose-word identity as the method for V-SCAN, whose ratified row says *no ground-truth text* and whose bar is "a distinct, named, more-expensive criterion — not the deterministic bar relaxed." The scoping sentence must not flatten a distinction the table already draws.
|
||
- **Q1** placement at the evidence-tiers preamble confirmed (that is where method is *defined*; tier-1 would scope the bar and leave the definition unscoped).
|
||
- **Q2** guard kept and REBOUND TO THE PROPERTY, not enrollment — as drafted it reached only existing kinds and would open the moment the door is first
|
||
used.
|
||
- **Q3** Edit 3's correction accepted; the jurist's `line_frame` shape withdrawn; the heavier rename declined as PROPOSAL-class/re-lock.
|
||
- **Q4** PROPOSAL/MINOR confirmed; the FIX reading declined on the vacuity argument.
|
||
- **Q5** Edit 2 kept (§V reads as a prose-framed universal alone).
|
||
- **Carry-forward (recorded here, deliberately NOT in spec text):** the primitives that would serve a future non-text kind already exist ratified — a character-bearing image is content, hash-fixed, mapped under a catalogued normalization, never silently dropped (REVIEWED-70 Q3); and the Loeb sidecar already holds a typed `{kind: 'glyph', file: …}` entry. Nothing is reserved and nothing is promised, but a successor arriving at the door this edit opens should find that the architecture's own primitives were already pointing that way.
|
||
**If AUTHORIZED:** Landed as spec v2.8.0's predecessor v2.7.0 (2026-07-25) + the sidecar-schema generality note (FIX). Tag commits REVIEWED-75.
|
||
|
||
## REVIEWED-76 — PENDING-76 — Authorization class follows claim class
|
||
**Date:** 2026-07-28
|
||
**Decision:** REJECTED — withdrawn by the executor (proposer) following the jurist's remand.
|
||
**Notes:**
|
||
**Reason.** The proposal would have amended Constitutional Constraint #1 so that
|
||
machine-verifiable state claims fell to `[FIX]` while doctrine remained `[ESCALATE]`. The jurist remanded it by running the package's own Part IV.2 refinement back across its Part II census — a check the executor drafted and did not perform. **Required count returned 0 of 11:** nine of the false claims fail the doctrine test (every dead tool name was welded to the directive instructing its use), and two were steward-held. Of the defects that were `[FIX]`-eligible, all five were structural and none was a state claim. The amendment's target category was empty: it authorised no edit that existing law did not already permit.
|
||
**What survived the proposal.** Q2, severed and ratified as a standing epistemic standard, with the addition that **a negative command result requires a positive control** — an absence proves nothing until the instrument is shown capable of detecting presence. Q4's preference for sunset over revocation. Both are now load-bearing in `governance-drift-check.py` and `wake-digest.py`.
|
||
**How the underlying problem was actually solved.** The jurist's reframing — that the drift was a symptom and the disease was operational configuration filed in a constitutional instrument — was accepted by the steward and executed on 2026-07-28 under existing law, with no amendment: REVIEWED-79 (doctrine preserved, instrument retargeted, state moved to `MEMORY.md`) and REVIEWED-80 (doctrine ids). **Empirical close: the drift count went 9 → 0 without the rule change the proposal argued was necessary.** That is a retrospective refutation of its premise, and it is checkable by running `governance-drift-check.py`.
|
||
**Do not revisit without new evidence** — specifically, a defect class that is machine-verifiable, *not* steward-held, and *not* welded to a directive. None of the eleven examined met that bar.
|
||
|
||
## REVIEWED-77 — PENDING-77 — CLAUDE.md structural repair
|
||
**Date:** 2026-07-28
|
||
**Decision:** AUTHORIZED
|
||
**Notes:**
|
||
**If AUTHORIZED:** Applied 2026-07-28. Four of five defects fixed directly; the fifth (empty `### L1 Active Workstream` stub) was superseded by REVIEWED-79 leg C, which deleted the region.
|
||
|
||
## REVIEWED-78 — Claude.app personal preferences: three verified-false claims
|
||
**Date:** 2026-07-28
|
||
**Decision:** AUTHORIZED
|
||
**Notes:** Resolved in full by the fresh preferences draft placed under REVIEWED-81, which
|
||
repairs all three claims at their source rather than patching them: the `fix/replay-durability-
|
||
contracts` branch pointer (merged as `c9746ae`; HEAD is `main`), "L2 blocked pending L1 stability"
|
||
(L1 dormant 30 days — re-expressed as an open question rather than a status), and the ARC
|
||
"near-operational" framing (Stage G sealed 2026-06-10 — finished and quiet, not nearly ready).
|
||
Recorded as its own entry rather than folded into REVIEWED-81 for a mechanical reason: the
|
||
closure rule in `wake-digest.py` matches a PENDING item to `REVIEWED-<same number>`, so a
|
||
cross-numbered closure stated only in prose would leave PENDING-78 listed as open at every wake.
|
||
**If AUTHORIZED:** Closed by the placement of the fresh preferences document. No further work.
|
||
|
||
## REVIEWED-79 — PENDING-79 — CLAUDE.md doctrine preservation (legs A, B, C)
|
||
**Date:** 2026-07-28
|
||
**Decision:** AUTHORIZED
|
||
**Notes:**
|
||
**If AUTHORIZED:** All three legs applied 2026-07-28. Leg A: §MemPalace → §Memory Discipline, seven doctrine units preserved, tool roster and hook claim removed. Leg B: two rules hoisted to §Session Discipline. Leg C: §Active Projects reduced to a pointer at MEMORY.md. Verified: governance-drift-check 9 → 0.
|
||
|
||
## REVIEWED-80 — PENDING-80 — Doctrine IDs, pilot on §Memory Discipline
|
||
**Date:** 2026-07-28
|
||
**Decision:** AUTHORIZED
|
||
**Notes:**
|
||
**If AUTHORIZED:** Applied 2026-07-28. Seven ids defined; drift-check §6 active and clean. Follow-on now unblocked: skills cite `D:` ids instead of paraphrasing doctrine.
|
||
|
||
## REVIEWED-81 — Keeping CLAUDE.md and the Claude.app preferences fresh with respect to each other
|
||
**Date:** 2026-07-28
|
||
**Decision:** AUTHORIZED
|
||
**Notes:** Finding #1 ruled by the steward: **Cowork is not a party.** Removed from the Claude.app
|
||
preferences by the steward the same day; `COWORK.md` and every reference to it go with it. Two
|
||
grounds, the second only visible once the MCP question was answered: a third executor costs a
|
||
third copy of doctrine that is `CLAUDE.md` with the nouns changed; and Cowork could not have
|
||
served as the jurist's filesystem eyes even in principle, since `coworkUserFilesPath` points at
|
||
`~/Claude`, which does not exist, and remote Cowork — the incoming default execution mode — runs
|
||
no local MCP server at all.
|
||
|
||
The §Standing Context split is authorized and drafted afresh at
|
||
`~/dotfiles/claude/app-preferences-draft-2026-07-28.md`, from the live text the steward pasted.
|
||
Doctrine and identity sections are preserved verbatim — PENDING-81 established they do not drift,
|
||
so rewriting them would have been loss disguised as tidying, and the census that would have
|
||
licensed it was not run. Every repair is confined to §Standing Context, which is where every
|
||
finding in PENDING-78 and PENDING-81 actually sat.
|
||
|
||
Three tiers, because the parts fail in three different ways: **Projects** (generated by
|
||
`wake-digest.py --brief`, dated, replaced wholesale), **Live questions** (hand-held but phrased as
|
||
questions — *"what has to be true of L1 first?"* survives time in a way *"L2 blocked pending L1
|
||
stability"* did not), and **Personal** (steward-held; the generator excludes it by design, not by
|
||
convention, and no instrument pretends to check it).
|
||
|
||
Two divergences were flagged rather than decided, and the steward resolved both the same day.
|
||
(1) **"principal ethics architect" is correct, and co-author besides.** The preferences carried
|
||
the right text; `~/CLAUDE.md` L27 is the stale record. Steward applies the alignment — the
|
||
executor cannot edit that file (Constitutional Constraint #1) — scoping co-author to L1, which
|
||
`CLAUDE.md` L88 already attests ("co-author with Seb for L1"). Worth noting which way this fell:
|
||
the flagged conflict was resolved *in favour of the document with no instrument watching it*.
|
||
Currency is not authority; the drift-check covers `CLAUDE.md` and nothing covers the preferences,
|
||
and the uninstrumented document was the accurate one.
|
||
(2) **The divorce was signed on 30 March 2026.** Closed. Now recorded as a completed past event
|
||
rather than a pending one — a date on a finished act is inheritable, where a date following
|
||
"awaiting" decays into a false present.
|
||
**If AUTHORIZED:** Steward pastes the fresh document into Claude.app. Executor keeps the durable
|
||
copy in `~/dotfiles/claude/` current, and the wake continues to report the generated block's age
|
||
past 30 days — tracking **generation, not pasting**, which is a lower bound on the jurist's
|
||
staleness and never a guarantee of freshness.
|
||
|
||
## REVIEWED-82 — Read-only MCP server: giving the jurist eyes on the substrate
|
||
**Date:** 2026-07-28
|
||
**Decision:** AUTHORIZED
|
||
**Notes:** Steward confirmed that local MCP servers are exposed to Claude.app's **chat** surface
|
||
and always have been, predating Cowork by about a year. The executor's framing ("chat, not only
|
||
Cowork") was backwards: it is *chat, always; Cowork, only while its loop still runs locally* — and
|
||
local Cowork is the mode being phased out as default. The jurist chat is therefore the sturdy
|
||
target, which makes this design less exposed to product drift than the Cowork-dependent
|
||
alternative that was considered and rejected.
|
||
|
||
`~/dotfiles/scripts/governance-mcp.py` is authorized for installation via the `mcpServers` key in
|
||
`claude_desktop_config.json`. Five read-only tools; the one no pasted cache can ever match is
|
||
`governance_item(id)`, which returns the **verbatim** body of any item or ruling — the jurist can
|
||
read the thing it is ruling on instead of ruling on a summary of it.
|
||
|
||
Four refusals are designed in, each with a same-run control proving the refusal detectable: no
|
||
writes (audited by AST — 0 mutating calls, git subcommands `{log, status}` only); no path
|
||
arguments at all (keys from a fixed enum, so there is no traversal to defend and the reachable
|
||
domain is enumerable rather than defined by the instrument); no second parser ("an item" is
|
||
defined once, in `wake-digest.py`'s `item_spans()`, imported); and not an agent (a tool returns
|
||
data, where a second Claude sent to look would return testimony about the substrate).
|
||
|
||
Verified: 29 self-test controls pass, 0 fail, plus a live stdio round-trip — `initialize` →
|
||
`notifications/initialized` (correctly unanswered) → `tools/list` → two `tools/call` → malformed
|
||
input surviving as `-32700` rather than a crash, with only JSON-RPC on stdout and stderr empty.
|
||
|
||
Reading is not executing: the role boundary is unchanged. The `[FIX]` to `item_spans()`
|
||
fence-awareness carried in the same commit changed no behaviour today (17 open items before and
|
||
after) but closes a latent defect whose trigger is the steward's own drafting practice.
|
||
**If AUTHORIZED:** Steward merges the `mcpServers` key and restarts Claude.app. Reversal is
|
||
deleting the key. Tag any follow-on commits REVIEWED-82.
|
||
```
|
||
|
||
**If the steward prefers to wait**, substitute:
|
||
|
||
```markdown
|
||
**Decision:** DEFERRED
|
||
**Notes:** [as above]
|
||
**If DEFERRED:** The server is inert — nothing loads it until the `mcpServers` key exists. Revisit
|
||
when the steward wants the jurist reading the substrate directly rather than through the generated
|
||
brief. No work is blocked meanwhile; `wake-digest.py --brief` remains the fallback.
|
||
|
||
## REVIEWED-83 — PENDING-83 — V-DPDF: a new declared deterministic kind for born-digital PDF (design-gate passed with required corrections)
|
||
**Date:** 2026-07-28
|
||
**Decision:** AUTHORIZED — proceed to demonstration and spec-text drafting per this ruling. Harrison's graduation stamp remains held (unaffected by this authorization) until the Q3 demonstration below passes.
|
||
**Notes:**
|
||
- **Q1 — constitutional, not code — CONFIRMED.** `tier_of()` is faithful to the ratified table's own format parentheticals; the defect is the table's conflation of container with origin, not implementation drift. PROPOSAL/MINOR confirmed, FIX declined, consistent with REVIEWED-75's resolution of the analogous question for its own edit.
|
||
- **Q2 — independence — REQUIRED, AND WRITTEN INTO THE CONSTITUTIONAL TEXT, NOT LEFT TO MECHANISM.** Do not import REVIEWED-72's shared-reader reasoning by analogy: that ruling accepted a shared pandoc EPUB reader because reader-loss cancels a priori over unambiguous markup. PDF recovery is inference over page geometry — two runs of one extractor can agree on the same wrong column order, which is exactly the §VII layer-2 case ("any raw↔canonical comparison — multiset or sequence — passes"). The V-DPDF row must state that reference conversion and ground-truth extraction are produced by independently implemented extractors. If independent extractors cannot be demonstrated, the honest verdict is HELD, not a relaxed deterministic pass.
|
||
- **Q3 — demonstration — TWO INSTRUMENTS, ONE STILL OUTSTANDING.** The classifier's positive/negative control (16/44 in-corpus; 62/59/164 across the 385-book library) is complete and sufficient for the tier-routing question. NOT yet demonstrated: the verification method itself (reference-convert + prose-word-guard) against a deliberately constructed layer-2 hazard — column-order corruption, in addition to the already-named running-head case — using the actual independent extractor pair required by Q2. This demonstration is a precondition of ratification, not a nice-to-have.
|
||
- **Q4 — anti-bypass clause binds — CONFIRMED, on stronger grounds than filed.** REVIEWED-75's drafting note states the guard was rebound "to the property, not enrollment" precisely to reach beyond literal self-declaration. The extension argued in Part III is within the clause's stated ratified reach, not past it.
|
||
- **Q5 — ordering — CONFIRMED.** Pilot (Harrison) proceeds alone as the Q3 demonstration; re-tiering the remaining 15 before the method has been exercised once inverts pilot and wave. Pacing of the 15 is a steward question.
|
||
- **Scope affirmed as filed:** V-SCAN untouched (44 canonicals); no reference-converter proposal for V-DPDF (separate §V byte-census question, per REVIEWED-67); Harrison's earlier pipeline steps unaffected; born-digital-EPUB Docling lane untouched.
|
||
- **Process note:** the 9 bare-scans and the 2 boundary-case files (Arcades Project; Haydn/Mozart/Beethoven) should be docketed as their own tracked items rather than remain prose-only inside this item, per the PENDING-55 residual-item precedent.
|
||
**If corrections satisfied:** land as a MINOR supersession of the §Tiering & Fence evidence-tier table (new V-DPDF row, independence stated as a requirement) plus `graduation-spec.yaml` declared data (discriminator, thresholds, extractor pair). Prior version frozen byte-identical; bounded-diff proof at landing. Tag commits REVIEWED-83.
|
||
**Awaiting:** steward placement, then the Q3 demonstration before Harrison's graduation stamp releases.
|
||
|
||
### REVIEWED-83 — AMENDMENT 1 (2026-08-01): Q3's first half was affirmed on a control that could not have detected the defect
|
||
**Date:** 2026-08-01
|
||
**Decision:** AUTHORIZED — amendment placed. Q1, Q2, Q4, Q5 stand unchanged. Q3's *second* half was already corrected by REVIEWED-84; this corrects the *first*.
|
||
**What Q3 affirmed:** *"The classifier's positive/negative control (16/44 in-corpus; 62/59/164 across the 385-book library) is complete and sufficient for the tier-routing question."*
|
||
**What was measured (2026-08-01, closing PENDING-85):** it is not sufficient. Two of the sixteen born-digital verdicts are wrong, and both works hold canonicals, so the in-corpus figure is **14/44**, not 16/44. `the-arcades-project-walter-benjamin-pdf` is a scan OCR'd by Adobe Paper Capture with ClearScan; `tschichold-form-book` is a scan OCR'd by ABBYY FineReader and re-typeset. Both were confirmed by eye at page level, not inferred from metadata.
|
||
**Why the control could not have caught it — and the shape is the one REVIEWED-84 already named.** The classifier's controls exercise its *decision rule*: given three signals, does it decide correctly? They cannot test whether three signals are *enough*. For OCR-then-re-typeset PDFs the triad's third leg is structurally absent — ClearScan discards the page bitmap, so there is no page image at any size, and ABBYY re-typesets into real embedded fonts, so no font signature betrays it either. REVIEWED-84 found that adding independence cannot fix an operator that discards position. This finds that adding controls cannot fix a triad that lacks a signal. **In both cases the control was correct and sat at the wrong layer.**
|
||
**A consequence for the classifier's own design premise.** Its docstring rules that *"metadata is testimony; structure is evidence."* For this family that is inverted: structure carries nothing and the producer/creator string is the only cheap discriminator. Any remedy adds a fourth signal — producer/creator strings plus an OCR-error probe over the extracted text — never a threshold adjustment. The threshold hypothesis carried in PENDING-85 was tested and refuted.
|
||
**Consequential correction, routed not applied.** The `0 of 17` two-column exposure quoted in ratified spec v2.9.0 and in `chamber-library/CLAUDE.md` rests on this classifier. Re-running it gives 16, not 17, and two of those sixteen are OCR'd, so the honest figure is **0 of 14**. **The zero is unaffected** — removing members from a population cannot create a two-column instance — so REVIEWED-84's argument strengthens and only the denominator is wrong. Correcting ratified text is not the executor's act; recorded here for the steward to route.
|
||
**What remains the jurist's to rule, and is not decided by this amendment:** whether V-DPDF ratification now requires the classifier to be re-demonstrated against the OCR-then-re-typeset family before the tier routes any work.
|
||
**If AUTHORIZED:** proceed. Tag commits REVIEWED-83-A1.
|
||
|
||
## REVIEWED-84 — PENDING-87 — Order attestation: REVIEWED-83 Q3 corrected, not merely reformulated (design-gate passed with required conditions)
|
||
**Date:** 2026-07-29
|
||
**Decision:** AUTHORIZED — proceed per the ruling. This ruling corrects REVIEWED-83's own Q3, on the jurist's error, not the executor's.
|
||
**Notes:**
|
||
- **Q1 — the Q3 precondition as written is unsatisfiable — CONFIRMED, and withdrawn, not merely reformulated.** The coverage-based guard is structurally blind to block-level reordering (Part II(3), demonstrated against the real `verify_body_conservation.classify`, real canonical, discriminating control intact). This was already established (Eichmann pilot §7, 2026-07-19) and already ruled (REVIEWED-74, 2026-07-24: "the reordering residual is scoped to the STANDING Q3 order-blindness stamp-block ... demonstrated, Eichmann §7") — independently confirmed against REVIEWED.md, not taken from this package. The jurist's 2026-07-28 Q3 demanded an outcome already known in this repo to be impossible; owned as the jurist's gap.
|
||
- **Q2 — independence confirmed; `held` does not apply — AFFIRMED, with a required forward condition.** Four extractors, zero shared libraries, and divergence (not agreement) correctly used as the proof. Unresolved: only docling recovers correct order on the adversarial fixture; the other three are independent but uniformly wrong. Any future `order_attestation:` proposal must not pair docling against itself as the order comparison — it needs a second, differently-implemented order-capable method, or an explicit argued fallback to eyeball-after-gate on the order axis specifically. Not required for this design-gate; required before that mechanism is ratified.
|
||
- **Q3 — constitutional — AFFIRMED**, consistent with the independence ruling of 2026-07-28: what a comparison can and cannot attest binds at the level of the trust architecture; the measure's parameters are declared data.
|
||
- **Q4 — tier-general — AFFIRMED**, already settled by REVIEWED-74 ("stands for both tiers"), not newly decided here.
|
||
- **Q5 — mechanism not yet ratified; eyeball-after-gate invoked as the interim ceiling.** Measured exposure is 1 of 84 born-digital PDFs, and that one file already scores clean (0.995–0.999). The sample (11 books, simulated corruption) does not clear the bar for ratifying a new mechanical instrument against that exposure. Land the REQUIREMENT text now (Part V(A), essentially as drafted); do not ratify the `order_attestation:` mechanism yet; discharge blocking condition (a)'s order branch for the interim via its own named alternative — an explicit, argued acceptance of eyeball-after-gate — applied now to the single flagged book. The position-sensitive measurement stands as evidenced future work if the steward wants it built regardless of current exposure; that is a pacing call, not a ratification requirement.
|
||
- **V-DPDF disposition (resolves REVIEWED-83's practical blocker):** order-blindness is not a V-DPDF-specific gap needing a new precondition — it is the pre-existing, tier-general stamp-block V-TEXT already operates under (REVIEWED-74). V-DPDF inherits it identically: promotions may proceed to `converted`; the `verified` stamp withholds on the order axis exactly as it already does elsewhere, discharged for Harrison by the eyeball-after-gate acceptance above, not by a new mechanism.
|
||
- **Process note (not ruled):** a keyword-search gap over PENDING/REVIEWED contributed to the Q3 error as much as executor self-containment did. Fold into PENDING-86's options rather than opening a new item.
|
||
**If AUTHORIZED:** Land the MINOR supersession adding Part V(A)'s requirement text beside blocking condition (a); record the explicit eyeball-after-gate acceptance for the order axis pending a ratified mechanism; release Harrison's `verified` stamp once that eyeball pass is done; V-DPDF's REVIEWED-83 status otherwise unchanged (Q1, Q2, Q4, Q5 of that ruling stand). Tag commits REVIEWED-84.
|
||
**Awaiting:** steward placement; steward eyeball pass on the one flagged book; steward pacing call on whether `order_attestation:` gets built now or banked.
|
||
|
||
## REVIEWED-85 — PENDING-88 — Skill-harvest FIX lane: hard floor sharpened, dual instrument required, provisional pending check-in (design-gate passed with required conditions)
|
||
**Date:** 2026-08-01
|
||
**Decision:** AUTHORIZED — proceed per the ruling, provisionally. Register split (option (d)) unaffected — separately authorized 2026-07-19, correctly executed by the split method rather than the inapplicable collapse method; no action needed here.
|
||
**Notes:**
|
||
- **Verification limit, stated up front.** All Part I quotes sourced from `~/CLAUDE.md` (taxonomy, escalate list, governance-contract clause, Constraints 1/5/6, PENDING-1 closing note) independently confirmed exact against the live file. The two `/wrap-up` §1.6 passages and the `/wake-up` §2.a line — the textual basis for Part III's "contradicts itself" claim — could NOT be independently checked; skill files are outside current tool reach. Required before landing: the same mechanical containment-with-positive-control verification the 2026-07-29 package carried, applied to these quotes specifically.
|
||
- **Q1 — gap, not deliberate distinction — AFFIRMED** on the timeline evidence given, unverified directly. The alternative reading is answered by the hard floor's exclusions, not by retaining the blanket rule.
|
||
- **Q2 — two-clause disjunctive test — AFFIRMED, and the narrower single-clause alternative is declined.** A latitude-expanding-but-non-assertive change would pass an assertion-only test; keep both clauses.
|
||
- **Q3 — report + provenance comment BOTH mandatory, and a third instrument added.** A wrap-narrative report alone is insufficient by the package's own admission. Required: (i) wrap report, (ii) skill-source provenance comment, (iii) a running append-only FIX-lane index (one line per applied change: skill · what changed · date), built on the same live-index pattern used for today's register split.
|
||
- **Q4 — the floor's catch-all clause sharpened.** "Anything that would reduce what is surfaced to the steward" becomes: *any change that removes, defers, or narrows the visibility of an open item, or that could cause a future item to land somewhere the steward's surfacing tools don't read, stays PROPOSAL regardless of the test's outcome.* Tied to the actual failure measured in Part II, not left as an unbounded judgment call.
|
||
- **Q5 — jurist review applies, narrowly grounded.** Not the stretched PENDING-S2 analogy (correctly declined by the executor itself) — grounded in this touching the integrity of the surfacing mechanism the steward and jurist both depend on, which is the PENDING-1 class of question by its function, not by resemblance.
|
||
- **New condition — bounded check-in, not asked for in the package.** After the first FIX-lane batch or one month, whichever comes first, steward and jurist review the FIX-lane index together before the lane is treated as settled rather than provisional. Per Constitutional Constraint's own decision heuristic (prefer reversible choices) — costs nothing if the classification holds.
|
||
- **Hard floor otherwise as proposed — AFFIRMED:** Constraint 1 (CLAUDE.md/REVIEWED.md/L2), authorization-boundary or gate-criteria changes, the escalate-unconditionally list, all untouched and all remain PROPOSAL/ESCALATE regardless of the test's answer.
|
||
**If AUTHORIZED:** Land the §1.6 edit (classification test + sharpened floor + dual-plus-index instrument) with a provenance comment in `/wrap-up` SKILL.md; no change to `~/CLAUDE.md`. Apply to today's four proposals (ledger section, KG predicate, wake line, reframed question) as the first FIX-lane batch, feeding the check-in review. Tag commits REVIEWED-85.
|
||
**Awaiting:** steward placement; mechanical verification of the §1.6/§2.a quotes; the bounded check-in once the first batch or one month has passed.
|
||
|
||
## REVIEWED-86 — Differently biased checkers, not unbiased ones (design-gate passed for DRAFTING ONLY — ESCALATE, application requires separate explicit steward authorization)
|
||
**Date:** 2026-08-02
|
||
**Decision:** AUTHORIZED to draft the Constraint 6 amendment for steward placement. NOT AUTHORIZED to apply — Constraint 1 and the escalate-unconditionally list both name this file; no ruling below the steward's own act of placing it changes that.
|
||
**Notes:**
|
||
- **Q1 — the gap is real — CONFIRMED**, independently checked against `~/CLAUDE.md` directly (Constraint 6 exact) and against the central-path file's own memory-index summary (substance and key phrases match).
|
||
- **Q2 — sound, ONE required correction.** Weld Part IV's "fail to coincide, not cancel" qualifier and its ban on citing the doctrine as assurance that something *was* caught into Part III's actual proposed text — not left as surrounding commentary. Not draft-ready without this.
|
||
- **Q3 — unresolved, and the doctrine's own landing must say so.** Jurist and executor share formation; whatever separates them is position, information, and incentive (category (i)), not formation (category (ii)) — the category Document B actually measured. The doctrine text should not be read, by its landing, as having validated the jurist-executor pair specifically. Recommend the correlation review the package itself names — clustered jurist/executor misses vs. a differently-clustered steward-correction pattern, run against the existing PENDING/REVIEWED record — be docketed as its own item rather than left hypothetical.
|
||
- **Document B — credited as pilot evidence for category (ii) only, not as a measured rate.** Pre-registration, corpus predating the doctrine, and the reproduced Appendix pair all independently checked out on inspection. Sample (3 comparable pairs, one author, unresolved persona confound even within the comparable set) is too narrow to quantify anything; Document B's own Part F.2/F.3 already say so and that scoping should be preserved verbatim in whatever cites it.
|
||
- **Q4 — sharpen to a retrieval obligation, fold into the existing check-in cadence** (REVIEWED-85), not a new standing review.
|
||
- **Q5 — Constraint 6 — AFFIRMED as the right location, steward's call on final placement.**
|
||
- **Process note, corrected.** The convergence was not two independent readers reaching the same idea from a shared root — the steward shared the jurist's exchange with him directly with the executor, as context, before Document A was filed. That is a tighter loop than parallel derivation: one party's language, relayed, feeding the other's proposal, which now returns to the first party for review. It does not bear on whether the underlying principle is sound — that turns on the separation-of-powers reasoning itself, not on who phrased it first — but it does mean the jurist should weigh, more carefully than usual, whether what reads as correct in Part III is the argument holding up rather than the jurist's own words returning familiar. Noted because it changes the standard the jurist should apply to itself here, not because it changes the ruling.
|
||
**If AUTHORIZED for drafting:** Land Part III (with the Q2 weld applied) beside Constraint 6, plus the companion `contamination-problem.md` note named as owed in Part V, amendment-first per that repo's own discipline. Docket the Q3 correlation review separately. Tag REVIEWED-86.
|
||
**Awaiting:** the Q2 weld, then steward review of the woven text; the Q3 note's exact wording; the correlation-review docket entry; and — the one that actually matters here — the steward's own explicit act of authorizing application, which nothing above substitutes for.
|
||
|
||
## REVIEWED-87 — PENDING-99 — The quoted tier accepts 3 of 17: fidelity_equivalence@3 markup-delimiter exclusion (design-gate passed with corrected rationale)
|
||
**Date:** 2026-08-05
|
||
**Decision:** AUTHORIZED — proceed per the ruling. Ruling filed verbatim at studium-engine/docs/quoted-tier-acceptance-JURIST-RULING-2026-08-05.md
|
||
**Notes:** Q1 AUTHORIZED, [^n] / _emphasis_ only — but NOT on the package's own reading that this aligns the engine with an already-ratified chamber principle. §II.3 states the marker's exact syntax remains OPEN, so no such ratification exists to align with; recording it that way would overstate the constitution. Authorized instead on (i) the engine's own fidelity_equivalence@2 governing test, independent of the chamber question, and (ii) functional analogy to §II.3's stated reason for excluding its own anchor marker — that a legitimate re-extraction adding recovered anchors would falsely fail a word-multiset comparison, which is the identical shape PENDING-99 measured. Q2 ANSWERED as a reframing rather than a yes/no: §II.3's marker doctrine governs citation-scheme anchors (Stephanus, Bekker), not footnotes; the real open question is whether a footnote's inline REFERENCE MARKER — as distinct from its display number (§V, carrier artifact) and its text (§V, Tier-3, inviolable) — is excluded from word-identity comparison, which neither clause addresses. Routed to the chamber-side PROPOSAL that closes §II.3's marker-syntax item, so both open edges close together. Does not block Q1. Q3 REJECTED as filed, disposition unchanged and basis strengthened: chamber §V Tier 3's "preserved and flagged... never corrected in the canonical text" makes a dropped trailing period a silent correction, not only an engine-side F5 shape. Q4 outside the gate. Q5 CONCUR, D-1. First ruling made with governance_read reaching chamber-spec (PENDING-86 (a), same day) — the jurist records that the ruling changed materially once the primary text was reachable, and that the decisive sentence was one the executor had read and not surfaced, which a verbatim-containment check passes every time.
|
||
**If AUTHORIZED:** Build fidelity_equivalence@3 = @2 + markup-delimiter exclusion, test-first and witnessed red, with @1/@2 preserved frozen and verdicts naming their relation (superset-only, so no re-verification obligation). Pre-registered effect on the Mauss gold: 3/17 to 6/17 at corrected anchors. Carry Q2 to the chamber side as a named open item. Tag commits REVIEWED-87.
|
||
|
||
## REVIEWED-87 — AMENDMENT 2026-08-07 (PENDING-111)
|
||
|
||
**Amends:** REVIEWED-87 (`fidelity_equivalence@3`, ratified 2026-08-05).
|
||
**Authority:** PENDING-111 jurist design-gate ruling, Q1 AUTHORIZE / Q2
|
||
correction-in-place, conditions (a) and (b).
|
||
**Version:** `fidelity_equivalence@3` — unchanged. Corrected in place, not bumped.
|
||
`@1`/`@2` frozen and untouched; **`@4` remains reserved for the Greek/Latin census.**
|
||
|
||
**The defect.** REVIEWED-87 authorized excluding the markdown emphasis
|
||
*delimiter* — the word used twice, with "not to markup as a class" added to keep
|
||
the scope narrow. The mechanism shipped as `re.compile(r"[_*]")`: a bare
|
||
character class with no notion of pairing, adjacency, or escaping. It therefore
|
||
stripped the asterisk out of a **backslash-escaped literal** — `COMPOST\*`
|
||
became `COMPOST\` — implementing something broader than the ruling authorized.
|
||
The ruling's text was unambiguous; the regex failed to implement it. Under this
|
||
system's constitution/mechanism split that is a mechanism defect against
|
||
standing doctrine, not new doctrine — hence correction in place.
|
||
|
||
**What it erased.** In *A Pattern Language* the escaped asterisks are Alexander's
|
||
own confidence rating: two = a solution he holds to be a true invariant, one =
|
||
progress toward one, none = far from one ("Using this book", L141/L143 of the
|
||
manifested file). Census by reading index, 2026-08-07: **83 / 114 / 56 across all
|
||
253 patterns.**
|
||
|
||
**The fix.** The emphasis exclusion now applies to **unescaped delimiters only**.
|
||
An escaped `\*` / `\_` is content and normalizes to its literal character —
|
||
backslash dropped, character kept. Implemented as a single left-to-right scan
|
||
(`engine/fidelity.py::_fold_emphasis`), not a lookbehind plus unescape pass,
|
||
because the two-pass form mis-reads an escaped backslash before a real delimiter.
|
||
|
||
**Bounded window:** 2026-08-05 (REVIEWED-87 ratified, `@3` governing) →
|
||
2026-08-07 (this correction landing).
|
||
|
||
**Scope — sources containing escaped emphasis characters.** Censused 2026-08-07
|
||
across all 13 manifested sources (Q3, which follows and does not gate):
|
||
**3 sources, not 1** — `alexander-pattern-language` (293 occurrences),
|
||
`musil-the-man-without-qualities` (16), `arendt-eichmann` (1). The ruling's
|
||
scope line said "currently known to be Alexander only"; that was the state of
|
||
knowledge at ruling time and the census supersedes it.
|
||
|
||
**Verdicts affected: none measured, in either direction.** The correction is
|
||
monotonic by construction (the exclusion set strictly narrows), and measurement
|
||
found no verdict that moved: the phase-2 Mauss gold holds at 6/17 accepted
|
||
before and after, and on the three realistic Alexander comparisons
|
||
(engine-constructed citation; human transcription including the rating; human
|
||
transcription omitting it) old and new agree in every case. **No verdict issued
|
||
in the window is known to have overclaimed** — see the amendment note below,
|
||
which corrects the premise on which that phrase was required.
|
||
|
||
**Remedy shipped with the required falsifier** (`tests/test_fidelity_v3.py`,
|
||
33 checks): `COMPOST\*`, `COMPOST\*\*` and `COMPOST` compare distinct;
|
||
`*property*` still folds; and — per the jurist's addition — an escaped literal
|
||
nested inside a genuine delimiter pair separates correctly
|
||
(`*text with \* inside*` → `text with * inside`).
|
||
|
||
## REVIEWED-88 — PENDING-101 — Cross-repo research brief: structural implications of INC-2026-07-28-01
|
||
**Date:** 2026-08-06
|
||
**Provenance:** Reconstructed by the executor 2026-08-06 from the session record — the INC-2026-07-28-01 package carries no filed ruling document (PENDING-108). Read against the jurist's own account and CONFIRMED 2026-08-06; the jurist additionally endorsed the design-transfer reading recorded below as a fair correction to the brief as it was written. NOT RECOVERED: the jurist's stated reasons for striking findings (1) and (3). Only the fact of the striking survives. If those reasons are ever needed as precedent they must be re-elicited, not inferred from this entry.
|
||
**Decision:** AUTHORIZED IN PART — partially superseded.
|
||
**Notes:** Of the three findings as dispatched (package §G5), findings (1) and (3) are STRUCK and finding (2) STANDS. Finding (2): a documented "never" relied on as a control, invisible until the moment it failed. The brief's dispatch was sound; two of its three conclusions were not. Separately and more consequentially: the brief was answering a REPO-AUDIT question when the steward's question was a DESIGN-TRANSFER one — what does an incident about a governed system lying teach us to build into CapableMind, BetterMemories and the Chamber, given that truth is why the Chamber exists. The executor executed the filed brief well and never flagged the gap between the two questions. First-pass transfer recorded: the incident is dislexification in software — a PR with the form of a contribution, a sock-puppet with the form of assent, an apology with the form of accountability — and the Chamber's answer is already structural, in that retrieve.py constructs citations FROM retrieval so that mislocation is structurally impossible rather than merely detectable. The verbatim apparatus is the moral argument implemented, not engineering hygiene.
|
||
**If AUTHORIZED:** Findings (1) and (3) carry no further obligation. Finding (2) proceeds as the live result. The design-transfer reading is the brief's actual yield and belongs in the L2 design note, not in a repo-audit follow-on. Tag commits REVIEWED-88.
|
||
|
||
## REVIEWED-89 — PENDING-102 — The brief hardened the report's hedged hypothesis into fact, and both AI parties did it in the same direction
|
||
**Date:** 2026-08-06
|
||
**Decision:** AUTHORIZED — Q1 narrowly; Q2 docketed.
|
||
**Notes:** Q1 (modality preservation on relayed external claims) AUTHORIZED, and narrowly: the requirement binds claims relayed from OUTSIDE the three parties, where no party can check the original from memory. Such a claim must carry the source's hedge quoted verbatim, or be explicitly marked strengthened-by-relay. Not a general anti-paraphrase rule — that would be unenforceable and would duplicate the containment instrument. The transferable formulation, which the correction produced and which is wider than the rule: the fix is not "read the primary source" but "check the specific claim you are relaying against the specific clause it rests on." Access is not verification; verification is access exercised by protocol — the same shape as storage-is-not-memory. This was earned: the jurist's synthesis attributed the catch to contact with the primary source, which was false, the executor having had the relevant pages read at the moment it relayed the hardened claim; the jurist then owned that it had held the full 36 pp. and flattened the same hedges. Q2 (disposition of the Part II finding under the differently-biased-checkers doctrine): DOCKETED on PENDING-89 as one observation, per instruction, both directions. Whether the instance also falls outside the doctrine because the jurist–executor pair is already declared weakly separated was the executor's lean and is NOT ruled here — it remains open, and an executor classifying its own miss as non-falsifying is the reading most favourable to itself.
|
||
**If AUTHORIZED:** The modality-preservation requirement takes effect for external relays. The Part II instance sits on PENDING-89's docket; one instance is not a pattern, and the doctrine's watched status is unchanged. Tag commits REVIEWED-89.
|
||
|
||
## REVIEWED-90 — PENDING-107 — Constitutional Constraint #1 says "cannot" and there is no mechanism
|
||
**Date:** 2026-08-06
|
||
**Decision:** AUTHORIZED — wording corrected; enacted by the steward's own hand.
|
||
**Notes:** Q3 resolved in favour of honest instruction over asserted property. Constraint #1's "cannot" becomes "must not", followed by an explicit disclosure: "No mechanism enforces this; see PENDING-107." No mechanism is claimed, because none exists. The gap between the word and the substrate is closed by correcting the word, and the absence is now disclosed at the point every reader — including the executor, at every session start — calibrates on it. Procedural record, which is the item's own subject matter: the jurist tagged this AUTHORIZED-to-enact-now; the executor DECLINED, on the grounds that the taxonomy gives the jurist "proposes, governs" and not final, that Constraint #1 routes this file to ESCALATE unconditionally, and — substantively — that an available, low-risk, virtuous edit made by the party under report would have been the reported gap operating successfully. The jurist owned the mis-tag unprompted. The steward enacted the change. One instance of restraint is not a mechanism, and PENDING-107 stays open on that ground.
|
||
**If AUTHORIZED:** Already applied and verified live in ~/CLAUDE.md. PENDING-107 remains OPEN — the wording is corrected, the enforcement gap is not. Independent verification of the gap was requested and is still owed. Tag commits REVIEWED-90.
|
||
|
||
## REVIEWED-91 — PENDING-106 — Documents describe our gates as stronger than the gates describe themselves
|
||
**Date:** 2026-08-06
|
||
**Decision:** AUTHORIZED — item split; Q4 census authorized, kind (a) only.
|
||
**Notes:** The item is split into the measured instance and the class. The instance: the doc FIX is APPLIED to chamber-library/CLAUDE.md. It ran wider than the ruling's words — the jurist authorized correcting "DENIED unless", scoped as a FIX, on the ground that it "adds nothing"; the same sentence carried THREE false statements about the same hook, and all three were corrected, because leaving two behind a sentence now advertised as corrected is the removing-a-claim-is-not-removing-the-reliance shape. Wider than the words, narrower than the intent; flagged for objection, not absorbed. The class: Q4 AUTHORIZED — a fleet-wide comparison of each gate's own header/docstring against the document that advertises it. Mechanical, needs no new instrument, and per census 01/02 the failure mode here is decay rather than construction. BOUNDED EXPLICITLY to kind (a) — the doc over-claims against an honest mechanism. Kind (b), where doc and mechanism both over-claim, is OUT OF SCOPE and needs a different method, there being no honest party to compare against.
|
||
**If AUTHORIZED:** The doc FIX stands as applied, with the wider-than-authorized scope recorded for objection. The kind-(a) fleet census proceeds and needs a DATE, not a "later". Tag commits REVIEWED-91.
|
||
|
||
## REVIEWED-92 — PENDING-105 — Q5: is "scheduled-not-yet-built" a legitimate third category?
|
||
**Date:** 2026-08-06
|
||
**Provenance:** Reconstructed by the executor 2026-08-06 from the session record — the INC-2026-07-28-01 package carries no filed ruling document (PENDING-108). Read against the jurist's own account and CONFIRMED 2026-08-06, including that the concession is correctly attributed to the executor. NOT RECOVERED: whether the jurist also issued a formal REJECTED alongside the executor's withdrawal. This entry records the withdrawal only — the weaker claim, and the one the record supports.
|
||
**Decision:** WITHDRAWN by the executor; G15's binary stands.
|
||
**Notes:** The proposal offered a third verdict category — scheduled-not-yet-built — against G15, which admits exactly two: documented architectural principle, or undocumented gap. The executor's conditioned yes rested on the condition that the category be available only where the governing document itself carries a deferral marker. Conceded outright on inspection: the condition was derived from PENDING-103, and PENDING-103 does not exemplify the class — writer.ts SHIPS and does not perform the check, so it is an undocumented gap under G15's existing binary, not a deferral. A category derived from a misclassified instance is a laundering slot, which is precisely what G15 was written to forbid. The proposal is withdrawn on its own terms rather than defended and defeated.
|
||
**If REJECTED/WITHDRAWN:** G15's two-verdict binary is unchanged. Do not revisit without a candidate instance that genuinely exemplifies the class — one where the governing document carries the deferral marker AND the gap is real. PENDING-103 is not that instance. Tag commits REVIEWED-92.
|
||
|
||
## REVIEWED-93 — PENDING-104 — Q3: no concurrency guard exists on shared governance state, and the collision has already been observed
|
||
**Date:** 2026-08-06
|
||
**Provenance:** Reconstructed by the executor 2026-08-06 from the session record — the INC-2026-07-28-01 package carries no filed ruling document (PENDING-108). Read against the jurist's own account and CONFIRMED 2026-08-06 as a clean match. NOT RECOVERED: whether "detection before mechanism" was ruled by the jurist or carried over from PENDING-104's own recommendation. Treat the ordering as the executor's until confirmed; the authorization to proceed is not in doubt.
|
||
**Decision:** AUTHORIZED to proceed — design brief, detection before mechanism.
|
||
**Notes:** The finding stands: no concurrency guard protects shared governance state, and the collision is not hypothetical — it has been observed. Authorized to proceed to a design brief. Detection comes first: establish whether and how often collisions occur before any guard is designed, so that the mechanism is sized to a measured rate rather than to a feared one. This ordering is the same discipline the fleet applies elsewhere — measure the toolchain before writing the spec.
|
||
**If AUTHORIZED:** Produce the design brief with a DATE, not a "later". Detection instrument first; mechanism proposal follows the measurement, as a separate item. Tag commits REVIEWED-93.
|
||
|
||
## REVIEWED-94 — PENDING-106 — Scope of the applied FIX: correcting three overclaims under an authorization naming one
|
||
**Date:** 2026-08-06
|
||
**Decision:** NOT OBJECTED TO — within FIX scope as authorized, not an expansion of it.
|
||
**Notes:** Leaving two known-false clauses behind a sentence now advertised as "corrected" is worse than the original overclaim — it is the removing-a-claim-is-not-removing-the-reliance shape, in reverse. Same sentence, same hook, same class of error. Boundary for next time, stated so it does not have to be inferred again: discovering MORE OF THE SAME claim-class inside an already-authorized FIX is fine to just finish. Discovering a DIFFERENT class — new file, new mechanism question, anything outside what was named — surfaces before acting, every time. This stayed on the right side of that line. Say so explicitly next time rather than leaving it for the jurist to notice on a close read.
|
||
**If AUTHORIZED:** The applied FIX stands without qualification; PENDING-106's scope flag is discharged. The same-class/different-class boundary is a STANDING RULE from this date, binding on every future FIX. The executor states the scope judgement explicitly at the time of acting, rather than flagging it for discovery on review. Tag commits REVIEWED-94.
|
||
|
||
## REVIEWED-95 — PENDING-112 — Harvested capabilities are routed by importance, not by firing moment
|
||
**Date:** 2026-08-07
|
||
**Decision:** AUTHORIZED (Q2, Q6) · CONCUR (Q1, Q3, Q4, Q5)
|
||
**Ruling, per question:**
|
||
- Q1 — PROPOSAL, concur. Touches no ESCALATE item; operationalizes Memory Discipline via the established constitution/mechanism split, does not
|
||
amend it.
|
||
- Q2 — AUTHORIZE the enforceable filing gate (option a). Low-cost, labelling-only, directly implements Constraint 4. Bound to Q6's falsifier rather than resting on jurist-executor agreement, per the doctrine's own caution; the jurist's independent lean is given for the record, not as the deciding vote.
|
||
- Q3 — Concur. Execute Stroke 2 after the ladder trigger lands, not before. Standing authorization unchanged; only sequencing shifts.
|
||
- Q4 — Concur. Prospective-only means no mandatory sweep, not a frozen backlog. Opportunistic re-routing of the 154 open register items is permitted, not required.
|
||
- Q5 — Concur. Steward-triggered tooling is not this proposal's to legislate. Flagged to the steward directly, not ruled.
|
||
- Q6 — AUTHORIZE proceeding now, trial alongside. Pre-registration made binding: a dated PENDING report at the 20-session mark, filed regardless of outcome. A result below the pre-registered 60% reopens Q2's rationale specifically, not the whole gate by default.
|
||
**Net effect:** the filing gate takes effect prospectively; the ladder gets its wake sentence now; Stroke 2 follows; the 20-session falsifier is a standing obligation, not a disclosed intention.
|
||
**Notes (steward).** The ruling's closing line reads: "Separately: REVIEWED-87's scope line should be read superseded by the amendment's 3-source census — no action needed, record already corrects it." Substrate-checked 2026-08-07 before placement: the record does NOT already correct it. No REVIEWED-87 amendment is present in this register, and the census wording appears zero times in it; the amendment exists only as an unplaced draft at `studium-engine/docs/REVIEWED-87-amendment-DRAFT-2026-08-07.md`. The jurist's text is preserved as ruled and is not altered here. The correction it assumes is effected by placing that amendment, which is done separately and immediately below/above this entry.
|
||
**If AUTHORIZED:** Proceed. Tag commits with REVIEWED-95. Already implemented on this authority before placement: the `/wake-up` ladder trial sentence, the `/wrap-up` §1.6 filing gate, and the `governance-drift-check.py` DEFERRED-DECISION trigger `ladder-ritual-trial / transcripts 84`. Stroke 2's 41-entry ladder append is unblocked by Q3 and remains to be executed.
|
||
|
||
## REVIEWED-96 — Quoted voices inside a host work: refusal, or attribution? (studium-engine V0 design gate)
|
||
**Date:** 2026-08-07
|
||
**Item:** not yet lodged in PENDING.md; package committed at `studium-engine@714b855`, amended by `a1659fa`
|
||
**Decision:** Q1 AUTHORIZED · Q2 DEFERRED · Q3 AUTHORIZED-WITH-RESTRICTION · Q4 BOUND TO (i), partition DEFERRED · Q5 ROUTING SUSTAINED, DISPOSITION REJECTED · Q6 REJECTED as mechanism
|
||
|
||
- **Q1 — AUTHORIZED.** D-4's convocation mechanism governs quoted third voices. `citable: false` returns to its ruled job: matter that is nobody's quotable voice. Orientation confirmed against §4.1 case 2: `voice: <quoted>, quoted_by: <host>`. §7.4(i)'s operative requirement — that the provenance join, not the NLI, is what catches the failure — is HONOURED and better served by attribution; its parenthetical mechanism defeats its own main clause by supplying an absence where a join is required. Decisive ground: fencing removed the only known human-verified instance of an adversarial class whose proportional distribution REVIEWED-48 made a standing condition. The Stevens/Harrison exhibit is EXCLUDED as a ground — Stevens was never fenced, only undetected.
|
||
- **CONDITION on Q1.** §7.4(i) has no ruling in PENDING.md / PENDING-archive.md / REVIEWED.md (instrument positive-controlled). Per PENDING-108 this is not conclusive. Steward to confirm whether a V2-harness ruling exists as a repo document. If it does, Q1 is re-gated as a conflict between ratified instruments; the outcome is expected to stand but the reasoning changes.
|
||
- **Q2 — DEFERRED.** The chunk invariant is derived, not primitive; enforceability rests on section containment. Third option not considered by the package: carry quotation provenance at the SPAN layer where V0 §1 rule 2 already operates, leaving the chunker unamended. Conditions: (a) state whether the serving/verification path can address sub-chunk extents, with a positive control; (b) score span-layer against chunk-level dual attribution on enforceability of the citable invariant; (c) the invariant is amendable only if (a) is negative.
|
||
- **Q3 — AUTHORIZED WITH RESTRICTION.** Register list stays closed. RULE: a quoted span grounds claims about the host's REPRODUCTION, not the quoted author's AUTHORSHIP. 'Stevens wrote X' anchored in Harrison must abstain (V0 §1 rule 3; REVIEWED-48 gate-to-abstain). 'Harrison's text reproduces, attributed to Stevens, the words X' grounds at the quoted register. Corollary: 'Harrison cites Stevens here' is the PARADIGM groundable case, not the ungroundable one. Undispositioned: composition of `quotation-in` with `translation-of` (Ungaretti-in-Harrison). Implementation sequences after PENDING-111.
|
||
- **Q4 — Ruling binds (i) borrowed authority only.** Partition non-exhaustive. Two kinds missing: (v) reported testimony (Arendt/Eichmann, Levi — ~31% of census; disposition resolved by §4.1 case 3's curatorial-judgment precedent; coverage-ledger consequence); (vi) traditional/anonymous/scriptural matter with no author-voice — the exact population of `118f411`. (vi) GATES the Mauss remediation.
|
||
- **Q5 — Routing sustained, disposition upgraded to BLOCKING for corpus-wide implementation.** Required instrument before sizing: run the welded-line-end / mid-word-block signature across all 14 manifested sources; report which carry it. Not blocking for Part VI remediation. Part II observation 2 ('51 drawers, hand-readable') is not to be cited as a safety argument; `a1659fa` shows one census row measuring its complement.
|
||
- **Q6 — REJECTED as a distinct mechanism.** Source-scoped inheritance IS the `quoted_by` relation; it renames rather than simplifies. The executor's stated cost (transitivity) is phantom — nesting does not expand the corpus. The unnamed cost is real: voice-scoped inheritance pulls spans from unconvoked sources. If adopted at all, inheritance must be DECLARED, never automatic. Philosophical reading honoured as rationale, not authority.
|
||
- **Part VI — `118f411` was mislabelled.** Class-level policy landed as `[FIX]`; by the taxonomy it required `[HARDENING]` lodgement and steward annotation. Aggravated by overriding a ratified served-roles default on unratified authority, and by contravening the purpose of REVIEWED-48's proportional-distribution condition. Disclosure incomplete: three same-day fencing commits (`2e77fca`, `57090ab`, `118f411`), not two. Commits STAND pending remediation order below.
|
||
- **Remediation ORDER (sequence is load-bearing).** (1) Disposition (vi) — voice values for anonymous/traditional sources. (2) Re-tag the 12 Mauss blocks to the quoted voice under the relation. (3) ONLY THEN set `citable: true`. Flipping the flag before attribution restores the original defect. `57090ab` (Thibon's chapter footnotes) examined separately against §4.1 case 1; `2e77fca` (Thibon's introduction) stands as apparatus.
|
||
- **Proposed doctrine (`[HARDENING]`, not enacted):** a fix that enforces a property can destroy the population that tests it. Before fencing, normalizing or removing a class of matter, ask what test population that class constitutes.
|
||
- **Jurist reading limits.** Part I unverified — `cluster-a-data-model.md`, `v0-verifier-contract.md`, the V2 design and `chunker.py` are outside `governance_read`'s eight keys. Live instance of PENDING-86; attach there as evidence. Verified from the substrate: REVIEWED-48 verbatim; `57090ab` / `118f411` / `714b855` / `a1659fa` in `studium-engine` (`main [ahead 6]`); absence of any V2-harness ruling, positive-controlled.
|
||
**If AUTHORIZED:** lodge the companion PENDING entry carrying the Q2/Q4/Q5 conditions and the remediation order. Q1 is actionable now; implementation is not, pending (vi), the conversion-signature survey, and PENDING-111.
|
||
|
||
## REVIEWED-97 — PENDING-113 — Disposition (vi): `voice:` for anonymous, traditional and scripturally-claimed matter
|
||
|
||
**Date:** 2026-08-08
|
||
**Decision:** DISPOSED. Unblocks remediation-order step 1; step 2 (re-tag the Mauss blocks) may proceed per item, under the structure below. Step 3 (`citable: true`) stays gated behind step 2, as ruled.
|
||
**Full reasoning:** `studium-engine/docs/voice-non-individual-origin-2026-08-08.md`. The compressed rule below is **not** a substitute for it — whoever writes the next per-source note reasons from that document, not from two tokens.
|
||
**Provenance:** jurist design-gate 2026-08-08 (category vocabulary + two-job structure); executor correction of the field placement, from substrate the jurist cannot read (PENDING-86); steward's bibliographic-vs-theological distinction is the ground of the split.
|
||
|
||
**The disposition — four slots, each doing one job.** The category vocabulary is the jurist's, unchanged; what changed is where it lives.
|
||
|
||
- **identity — `voice:`.** Who is convoked. `voice:` is the retrieval key (`retrieve.py` filters `d.voice = ?`), so one value IS one speaker: measured, `glidden` already spans 5 sources and `weil` spans 2, correctly, because one person is behind each. Individual-author voices aggregate at the person; traditional and scriptural matter has no such person, so **identity lives at the work level** — `havamal`, `quran-taghabun` — or at the **passage** level where there is no work (the Trobriand formulae). Read as unique per *quoted work*, not per host; `quoted_by` distinguishes hosts. Executor names the values.
|
||
- **relation — `quoted_by:`.** Unchanged from REVIEWED-96 Q3: a quoted span grounds the host's REPRODUCTION, never the quoted author's AUTHORSHIP. This, not the voice name, is what limits a thin voice built from an excerpt.
|
||
- **category — closed pair, and NOT in the convocation key.** `traditional` (no author claimed, by anyone, within the source's own tradition) · `non-individual-origin` (the tradition itself holds this is not a human composition, by whatever mechanism it names).
|
||
- **account — per-source prose note.** The specific claim each tradition makes about its own text's origin does not compress into a token; it goes in prose, one per item.
|
||
|
||
**Why the category may not sit in `voice:`.** Putting it there would make `traditional` a single convocable speaker spanning Old Norse gnomic verse and Sanskrit epic, with no mechanism to separate them again — the same flattening the ruling exists to prevent, committed in the mechanism instead of the taxonomy.
|
||
|
||
**Binding caution.** Do NOT assign the remaining items — Havámál, Trobriand formulae, Mahābhārata, Brahmanic passages — to `traditional` by elimination. At least one (the Trobriand formulae, tied in their own cosmology to ancestral or mythic origin) may need `non-individual-origin`, or a note complicating either bucket. Each item gets its own considered note before tagging. **Writing the note is the work; the two-way choice is not a substitute for it.**
|
||
|
||
**Correction carried into this entry.** The text is **Surah LXIV (`at-Taghābun`), vv. 15–18** — not CXIV (`an-Nās`), which is a different six-verse surah. Mauss's own line reads *"la fameuse Sourate LXIV, « déception mutuelle »"*. The mislabelling originated in the executor's sidecar title and propagated into REVIEWED-96 (Q4), PENDING-113 and session memory; those three name the wrong surah and should be read with this correction. The earlier worked example was built on the "Say" (قُل) formula, which opens an-Nās and does **not** appear in the passage Mauss quotes — that evidence is withdrawn, not transplanted. The general ground (the Qur'án presents itself as divine speech) is untouched. Mauss's *"donnée à La Mecque"* is contestable — at-Taghābun's Meccan/Medinan classification is disputed — and the note **records the dispute rather than resolving it**.
|
||
|
||
**Not disposed here.** All twelve (vi) blocks are translated matter and `role` is single-valued, so each is *quoted-in* and *translated-from* at once. REVIEWED-96 filed that composition as open against Ungaretti-in-Harrison, as an edge case; it covers the whole of (vi). The disposition is decided; it cannot be **applied** until that composition is ruled.
|
||
|
||
**Scope.** Disposes (vi) only. REVIEWED-96 Q1–Q6 and PENDING-113's Q2/Q4/Q5 conditions are untouched. The Harrison/Mark finding raised alongside this is filed separately as **PENDING-114**, not as evidence for this entry.
|
||
|
||
**Numbering note (PENDING-110).** This is `REVIEWED-97`, the next in its own sequence — not `REVIEWED-113`. The registers are independent; PENDING-110 REJECTED renumbering-to-align, and numbering this 113 would skip 97–112 and entrench the false expectation that the sequences match. The heading names its PENDING per that item's convention (b).
|
||
|
||
## REVIEWED-98 — PENDING-114 — Scripture quoted inside a host text, unmarked: authorize the validated census
|
||
|
||
**Date:** 2026-08-08
|
||
**Decision:** **(b) AUTHORIZED**, with **(c) attached exactly as proposed** for whatever (b)'s validated recall cannot reach. (a) — fix the Harrison span and stop — REJECTED.
|
||
**Provenance:** steward, 2026-08-08, on the executor's PENDING-114. Reasoning recorded here rather than compressed, per PENDING-108/113: a ruling that exists only in conversation evaporates.
|
||
|
||
**Ground 1 — (a) would repeat, in miniature, the error already named in this same thread.** Fixing Harrison alone treats a class-shaped problem with a span-shaped fix. That is not an analogy to `118f411`; it is the same taxonomy error, identified hours earlier the same day and now written into the register against it.
|
||
|
||
**Ground 2 — the scale context, which PENDING-114 understates.** Harrison's quotation is invisible to any sidecar-based detector because it belongs to the intra-line class measured 2026-08-07 at **~6,455 marked quotation runs across 8 sources, ~94% of them intra-line** and therefore not expressible at the current section granularity. Harrison is **not an isolated miss — it is the first confirmed hit in a population that is this corpus's blind spot for precisely the property the corpus exists to guarantee.** First-order gap, not a curiosity.
|
||
|
||
**Ground 3 — why (b) rather than merely thorough.** (b) is built so as not to repeat the marker census's own failure. It does not propose trusting a signal; it proposes **demonstrating recall against a hand-scored known-positive / known-negative pair** — Harrison's actual quotation against Weil's mentions — before any corpus-wide claim is made. That is the discriminating-instance discipline (REVIEWED-83 A1) applied to the instrument *before* it is applied to the corpus.
|
||
|
||
**Ground 4 — the payoff, and the proposed doctrine earning its keep forward.** Whatever (b) finds is **marked, not fenced.** That is a materially different act from `118f411`: attribution removes nothing from the test population, it improves it. A correctly-marked Harrison/Mark instance becomes a **better** positive control than an unmarked one, not a destroyed one. REVIEWED-96's proposed doctrine — *a fix that enforces a property can destroy the population that tests it* — is here running **forward in time**, as a design constraint on remediation rather than as a post-hoc finding. This is the first occasion on which it has done real work.
|
||
|
||
**On (c) as the attached fallback.** If the validated detector's recall does not reach some part of the class, **disclosing that limit is a legitimate stopping point, not a failure to execute (b) properly** — the same standing (c) has in REVIEWED-48's gate-to-abstain, which was ruled doctrine-consistent rather than merely tolerated. (c) is not a consolation branch; it is the honest-degradation route (Constraint #4) and is authorized on its own terms.
|
||
|
||
**Binding on execution.** No corpus-wide claim — finding *or* all-clear — may be reported from the detector until its recall is demonstrated on the hand-scored pair. The marker census already run is a **failed instrument**, not a count, and is not to be cited as either evidence or reassurance.
|
||
|
||
**Scope.** Disposes PENDING-114 only. REVIEWED-96, REVIEWED-97 and PENDING-115 are untouched; PENDING-115 remains a separate blocker on remediation step 3.
|
||
|
||
**Pacing.** Execution timing left to the executor as a proportionate-to-energy call, explicitly not decided by the substantive case above.
|
||
|
||
## REVIEWED-99 — PENDING-115 — Two mechanism defects blocking remediation step 3
|
||
**Date:** 2026-08-08
|
||
**Decision:** AUTHORIZED — (a1) and (b1), both before step 3.
|
||
**Notes:** Two of the cleaner items to come through today: each is a real, measured inconsistency between two internal registries that were supposed to agree and don't — ROLE_CLASS vs. SERVED_ROLES for (a), source-scoped vs. voice-scoped warrant query for (b) — not a design judgment call the way (vi) or PENDING-114 were.
|
||
(a1) over (a2): the chunker already treats quotation/translation as served in practice — that is not in dispute, it is measured. The fix makes the ledger's classification agree with what is already true, rather than inventing a fourth state. (a2)'s four-way vocabulary would be more faithful to something, but nothing here needs the extra category; D-4 prefers small closed vocabularies everywhere else this system touches, and that consistency is worth more than growing the vocabulary to solve a problem correct reclassification already solves.
|
||
(b1) over (b2): (b2) is not a live option — it is foreclosed by REVIEWED-97, which requires sub-source voices to exist at all. Named plainly: this defect is not a hypothetical edge case someone got cautious about, it is a defect (vi)'s own disposition directly creates. Good that it surfaced before step 3 rather than after.
|
||
No ordering dependency between (a1) and (b1) — different modules, different failure surfaces; both simply need to land before step 3 does.
|
||
The D-4-promise-not-implemented aside (citable:false really does mean unreachable, not just unindexed, contra the "config not migration" claim) is correctly left embedded rather than split out — it is explicitly non-actionable here, unlike Harrison/Mark, which was a live finding bearing on a different decision. A one-line tracking note is authorized so it does not quietly get treated as settled later; it does not need the full-entry treatment.
|
||
**If AUTHORIZED:** Proceed. Tag commits with REVIEWED-99. Each change carries the positive control named in the entry: for (a1), a quotation section in scope after the change and an apparatus section still out of it; for (b1), a two-voice source whose two voices return different scopes. Step 3 remains blocked until both have landed.
|
||
|
||
## REVIEWED-100 — PENDING-116 — Run the fleet on the change that breaks it
|
||
**Date:** 2026-08-08
|
||
**Decision:** AUTHORIZED — option (b), repo-declared trigger.
|
||
**Notes:** The cleanest justification of the three, because the cost of not having it already happened and was measured: a full day at 202/203 red, surviving two separate correction passes on the offending commit, caught by accident. That is not a risk being reasoned about in advance, it is a failure already logged.
|
||
(d) — rely on the discipline — is refuted by its own evidence, not merely argued against: the trap was named in CLAUDE.md and still did not fire, because naming a risk is not the same as mechanizing a check on it. That is the same lesson the harvest-routing thread landed on this morning for a completely different subsystem; two independent measurements of the same underlying fact in one day is worth noticing.
|
||
(b) is the right design among the three — (a) correctly rejected for coupling a shared global hook to one repo's layout, (c) correctly rejected for losing more than it gains. It reuses the declared-data-plus-thin-consumer pattern already established for graduation-spec.yaml rather than inventing a new mechanism, which is the right instinct architecturally.
|
||
The scope discipline is right and should not be pushed past: the cross-repo half (a chamber-library edit invalidating engine fixtures with no engine-side commit to hook into) is real and bigger, but needs a genuinely different mechanism — a scheduled source_sha256 check, not a commit hook — and trying to solve both here would likely land neither cleanly. It stays a named follow-on; its own PENDING number waits until the design is derived, which happens while building (b).
|
||
Sequencing note, not a condition: the Mauss re-tag (step 2 of the (vi) remediation) is itself a corpus edit in the same risk class 118f411 was. Landing 116 before or alongside that re-tag covers the very next edit this thread is about to make.
|
||
**If AUTHORIZED:** Proceed. Tag commits with REVIEWED-100. Both halves of the acceptance test are required — a triggering change refused, and a docs-only change that does not run the suites.
|
||
|
||
## REVIEWED-101 — PENDING-117 — The cross-repo half: a chamber edit invalidates engine bindings with no commit on either side
|
||
**Date:** 2026-08-08
|
||
**Decision:** AUTHORIZED WITH CONDITIONS — (e) + (a) + (c), sequenced (e) → (a) → (c); (b) REJECTED.
|
||
**Notes:** The scope as filed was incomplete and two stated reasons should not enter the record as they stood.
|
||
|
||
1. The recommendation collides with the principle it protects. graduation-spec.yaml carries
|
||
engine_source_binding as prose. A scheduled checker cannot consume it, so it either hardcodes
|
||
the surfaces — a second home for one enumeration, which the hash-locality principle four lines
|
||
below forbids — or the spec gains a structured surfaces: list. That is an amendment to a
|
||
ratified document, [PROPOSAL] work on the convention-data layer, and Files affected did not
|
||
name it. CONDITION: authorize (a) only together with that amendment, or the fix reproduces
|
||
the drift class one layer out.
|
||
|
||
2. The rejection of (b) is right; its stated reason is wrong. REVIEWED-100 rejected coupling a
|
||
globally shared hook to one repo's layout. (b) is a repo-local declaration — the authorized
|
||
mechanism — whose command reaches a sibling path. Different object, different failure mode.
|
||
The item's own parenthetical is the stronger objection and is the recorded reason: it fails
|
||
silently when the engine is not cloned beside the chamber, a detector that cannot see where
|
||
the quarry lives, which is this item's own subject class. A borrowed authority in a rejection
|
||
becomes precedent for the next rejection.
|
||
|
||
3. Resolved before ruling: chamber 177e2b3 touched the reading index only, not the engine
|
||
binding surface, so the item stands as filed and the "not a claim the trigger fired" framing
|
||
needs no correction. 56 days of undetected partial re-anchor is recorded as the detection-
|
||
latency datum the (a)-versus-(d) trade turns on. The executor's check then found that no hash
|
||
covers the reading index at all, so the three named surfaces would have read green throughout
|
||
those 56 days: the surface list is four, not three. That an enumeration was wrong when written
|
||
is itself the argument for condition 1.
|
||
|
||
4. (e), not on the item's list: check the binding shas unconditionally on every studium-engine
|
||
commit, in the hook REVIEWED-100 landed. Fires where a human is already in the invocation
|
||
path — the gap PENDING-98 names. It does not replace (a): if the chamber moves while the
|
||
engine is quiet, nothing fires. Measured cadence puts (e)'s latency in hours during active
|
||
work, against "whenever someone reads the log". (a) is demoted to backstop for the
|
||
engine-quiet case.
|
||
|
||
5. The second-order finding is split out as PENDING-118. It concerns an instrument and all
|
||
archived deferrals; filed inside a [PROPOSAL] it dies if the host is deferred or rejected.
|
||
It sits with PENDING-108 and PENDING-110 as one family — the register's own instruments not
|
||
reaching parts of the register.
|
||
|
||
6. Placement: ~/dotfiles/scripts/. A cross-repo invariant is owned by neither repo; putting it
|
||
in either makes that repo the authority over a relationship it is only one half of. Convention
|
||
data in the ratified spec, thin consumer in dotfiles — the pattern REVIEWED-100 authorized.
|
||
|
||
**If AUTHORIZED:** Proceed in sequence (e) → spec amendment (condition 1, jurist design-gate)
|
||
→ (a) → (c). Tag commits with REVIEWED-101. The spec amendment gates (a), not (e): (e) reads
|
||
the engine's own manifest and sidecars and needs no cross-repo enumeration. Each stage carries
|
||
a both-directions control — drift reported when a binding is stale, clean reported on a
|
||
genuinely clean corpus.
|
||
|
||
## REVIEWED-102 — PENDING-119 — REVIEWED-101 condition 6 placed (e)'s consumer in dotfiles, on reasoning the same ruling says (e) does not engage
|
||
**Date:** 2026-08-08
|
||
**Decision:** AUTHORIZED — option (i), with condition 6 of REVIEWED-101 explicitly narrowed on the record, and one condition on (i).
|
||
|
||
**Notes:** The ambiguity is mine. Condition 6 was drafted flat, under a heading that read "Placement", and left its scope to be inferred from a
|
||
sentence four lines below it. That is a jurist defect, not an executor misreading. The item is right that the two texts admit both readings, and
|
||
right that the narrow reading is the one the reasoning supports: condition 6's argument is ownership of a cross-repo invariant, and (e) does not
|
||
enumerate one. It follows the engine's own declared pointers into the chamber; the surface list that (a) needs is precisely what (e) does not need.
|
||
That was already the stated basis for severing (e) from the spec amendment, and the same severance carries the placement.
|
||
|
||
1. NARROWING, recorded as a ruling and not as a charitable reading: condition 6 of REVIEWED-101 governs consumers that must ENUMERATE the
|
||
cross-repo binding surface — (a) and (c). It does not govern (e). Left unrecorded, the next reader relitigates this.
|
||
|
||
2. The recorded reason for rejecting (ii) is that it inverts the condition it honours. A ~/dotfiles/scripts/check-source-binding.sh whose body is
|
||
one exec of engine/ingest_gate.py --check-only puts an engine path and an engine flag into the global layer. That is the coupling REVIEWED-100
|
||
rejected, reintroduced in the name of a condition written to prevent coupling. A rule that produces the outcome it exists to forbid is being read
|
||
at the wrong grain.
|
||
|
||
3. Kept in view, because the reflex runs the other way: the placement question only became live because the executor delegated to ingest_gate
|
||
instead of writing a fresh sha-comparing script. Had it duplicated the logic, condition 6 would have been straightforwardly correct. The better
|
||
implementation is what made the condition misfit — a rule's misfit is not automatically an implementation error.
|
||
|
||
4. The fleet-census finding is SPLIT OUT as PENDING-122. "No fleet suite validates live binding" is not evidence for a placement dispute; it is a
|
||
standing correction to what fleet-green certifies, owed to anyone reading a green fleet. Filed inside PENDING-119 it dies if PENDING-119 is
|
||
deferred. Same objection made at REVIEWED-101 condition 5; consistency requires making it again. It belongs with PENDING-96 as one family — a green
|
||
that attests less than its surface suggests.
|
||
|
||
5. CONDITION on (i): 0.218 s over 14 sources is honest about being burst-sized, and the check is unconditional on every commit, scaling with
|
||
sources × file size. State the threshold now with its action — when it exceeds ~1 s, (e) re-scopes or hands off to (a)'s scheduled job. A
|
||
per-commit cost that grows unremarked converts a tripwire into a --no-verify habit, which is this thread's own failure class arriving by the back
|
||
door.
|
||
|
||
**If AUTHORIZED:** Proceed with (i) — one line in the engine's .precommit-triggers. Record the condition-5 threshold beside it. Tag commits with
|
||
REVIEWED-102.
|
||
|
||
## REVIEWED-103 — PENDING-120 — The fleet trigger covers corpus/ but not the engine code the fleet exists to test
|
||
**Date:** 2026-08-08
|
||
**Decision:** AUTHORIZED — option (a), with the scope framing corrected and the acceptance fixture decomposed.
|
||
|
||
**Notes:** The demonstration is the strongest part: eecc8bb touched the gate and the gate's own test floor, and the hook printed nothing. First
|
||
real non-probe commit since the trigger landed, and it ran nothing. That is a measured failure, not a reasoned risk — the same standard
|
||
REVIEWED-100 credited PENDING-116 for.
|
||
|
||
1. CORRECTION to the scope-honesty note. The item says REVIEWED-100 "did not rule the pathspec". As to the ruling, that is accurate — REVIEWED-100
|
||
authorizes the mechanism and the both-halves acceptance and says nothing about paths. But PENDING-116's own Costs section does: "the trigger paths
|
||
must be scoped tightly (corpus/, corpus/sidecars/) so ordinary docs commits do not pay it." So the pathspec was not silence — it was a cost
|
||
commitment in the authorized item. This does not change the outcome; it changes the bar. The widening must be SHOWN to preserve the discrimination
|
||
that commitment bought, which is exactly why (b) is correctly rejected and (a) is not. Record it as revising a stated cost-control with its
|
||
justification intact, not as filling a gap. In-scope repair is the more comfortable framing and the less accurate one.
|
||
|
||
2. The acceptance test DECOMPOSES; one fixture cannot meet "neither may be a synthetic probe if a real one is available". (i) Fires on a real
|
||
engine change — replay eecc8bb against the widened pathspec; genuinely real, genuinely available, and it is the commit that demonstrated the gap —
|
||
but eecc8bb was green, so it proves firing only. (ii) Refuses on red — requires an induced red unless history holds a real red engine/ commit; if
|
||
one exists use it, and if not, say the fixture is synthetic rather than letting "real fixture" cover both halves. (iii) Docs-only still runs
|
||
nothing — unchanged, and the half that proves discrimination.
|
||
|
||
3. The adjacent gap was checked and the answer is NO; filed as PENDING-123. The hook does not distinguish "no trigger path matched" from "the
|
||
declaration is malformed or its command is missing". Five disarming faults were tested against a positive control, each staging a real corpus/
|
||
change the hook must catch: pathspec typo, no separator, empty command, comments-only, empty file. All five silent, all exit 0. A typo disarms the
|
||
gate permanently and invisibly. This is also why eecc8bb running nothing went unremarked — its output is byte-identical to a fully disarmed hook's.
|
||
|
||
4. INTERACTION with PENDING-119. If both land, .precommit-triggers carries two lines with overlapping paths and engine commits pay ~2 s (fleet) +
|
||
0.218 s (binding). Declare the order in the file so a red is attributable to one check without reading both.
|
||
|
||
**If AUTHORIZED:** Proceed with (a) — corpus/ engine/ tests/ scripts/run-fleet.sh. Land the three-part acceptance separately, labelling the
|
||
induced-red fixture synthetic if no real red engine/ commit exists. Tag commits with REVIEWED-103.
|
||
|
||
## REVIEWED-104 — PENDING-122 — What a green fleet certifies, and what it does not: no suite validates live binding
|
||
**Date:** 2026-08-08
|
||
**Decision:** AUTHORIZED — option (a), with a required third result state.
|
||
|
||
**Notes:** A live-corpus assertion makes one suite depend on chamber-library being present and reachable. Every other suite builds under tmp and is
|
||
portable; this one will not be. The item does not say what happens on a fresh clone with no chamber beside it, and both obvious answers are wrong.
|
||
Red on absent is a suite going red for reasons unrelated to the code under test, which trains people to discount fleet red — the worst possible
|
||
outcome for this particular thread. Skip on absent is the silent net, in the very assertion added to correct an overstatement.
|
||
|
||
1. CONDITION: three states — bound / drifted / cannot-assess — and cannot-assess must be distinguishable in the fleet summary, never folded into
|
||
green. A green fleet that includes an unassessed binding case is the same overstatement one layer along.
|
||
|
||
2. The REVIEWED-83 A1 leg of the analogy was challenged as uncorroborated and has been verified against ~/REVIEWED.md, which is authoritative.
|
||
REVIEWED-83 Amendment 1 (2026-08-01) IS the classifier layer-error: "The classifier's controls exercise its decision rule … They cannot test
|
||
whether three signals are enough … In both cases the control was correct and sat at the wrong layer." The 0 of 17 → 0 of 14 figure visible in
|
||
e341242 is a secondary paragraph of that same amendment, labelled "Consequential correction, routed not applied." Third subsystem stands on checked
|
||
ground, and the amendment itself names the first two as one shape.
|
||
|
||
3. Does not prejudge PENDING-121, confirmed from both sides. Option (a) closes the distance between "the gate works" and "the corpus is bound" at
|
||
whole-file granularity only; anchor correctness is 121's gate and the two land independently. Recorded with it: REVIEWED-101 §C's "fourth surface —
|
||
the reading index carries no hash" was wrong, and 121 corrects it — the runbook binds the index outward by source_sha256, and the real gap is
|
||
finer and worse.
|
||
|
||
4. The three-state requirement is raised to doctrine as PENDING-124 rather than conditioned again per item.
|
||
|
||
**If AUTHORIZED:** Proceed with (a), three-valued. Tag commits with REVIEWED-104. Land after REVIEWED-105 if both are authorized.
|
||
|
||
## REVIEWED-105 — PENDING-123 — The pre-commit hook cannot distinguish "nothing to check" from "I am disarmed"
|
||
**Date:** 2026-08-08
|
||
**Decision:** AUTHORIZED — (b) now, plus (e) in place of a flag; (a)'s full listing retained on --verbose.
|
||
|
||
**Notes:** The strongest item of this set. Positive control first, six rows, mechanism read from the hook's own source down to the two lines that
|
||
swallow the difference — `[ -n "$cmd" ] || continue` and the `2>/dev/null` that erases "git could not resolve this pathspec". And it answers
|
||
PENDING-120 §C: "Running pre-commit checks…" with nothing after it is what a fully disarmed hook prints, which is why eecc8bb went unremarked.
|
||
|
||
1. Instead of (a) behind a flag — a flag nobody sets is a capability nobody has — option (e): print the per-rule line ONLY when a
|
||
.precommit-triggers file exists and no rule matched. A rule ran, existing output already says so; nothing matched, one line naming the declared
|
||
rules and the staged paths; no triggers file, print nothing, so no noise in any other repo. Zero cost in the normal case, and the line appears in
|
||
exactly the ambiguous case. It also partly closes the fifth silence: a typo'd corpuss/ shows as a declared rule that did not match on a commit that
|
||
touched corpus/, catchable at the moment the reader is already looking — PENDING-98's mitigation shape, not a log. Keep (a)'s full per-rule
|
||
listing on --verbose for the never-yet-matched rule, which stays honestly unknown.
|
||
|
||
2. The item's own standard, turned on the item: the summary claimed silence when the declaration is "malformed, mis-typed, empty, or absent", and
|
||
the table had no absent row, nor one for the hook itself missing or core.hooksPath unset. Rows added. Measuring them found something stronger than
|
||
the claim — with the hook file missing, the commit produces ZERO output, not an ambiguous silence — and found the executor wrong in the other
|
||
direction: unsetting core.hooksPath locally falls back to an armed global, so that row is a robustness property, not a fault, and is recorded as
|
||
one.
|
||
|
||
3. Blast radius of (b). The hook is global, so a refusal on malformed declarations arms in every repo carrying a triggers file, present and future.
|
||
Censused 2026-08-08: exactly one exists today (studium-engine), across ten repos under the global hooksPath. Today's radius is one repo; the
|
||
condition is about the future and stands. Required: the refusal message names file, line number and fault, and states --no-verify. A gate that
|
||
blocks without saying why is replaced by habit within a week.
|
||
|
||
4. SEQUENCING across the four open items: land 123 before 119(i) and 120(a). Both add lines to .precommit-triggers; a validator that catches a
|
||
malformed line should exist before the file grows. In the other order, the first thing to test the new declarations is the declarations themselves.
|
||
|
||
**If AUTHORIZED:** Proceed with (b) + (e). Build order: REVIEWED-105 → REVIEWED-102 (i) → REVIEWED-103 (a). Tag commits with REVIEWED-105.
|
||
|
||
## REVIEWED-106 — PENDING-124 — A check whose subject can be absent cannot be two-valued
|
||
**Date:** 2026-08-08
|
||
**Decision:** DESIGN GATE PASSED WITH CONDITIONS. Q1 applied, not extended — no constitutional change, no [ESCALATE]. Landing: one ladder entry.
|
||
Five conditions, none changing the doctrine's substance; three changing what is recorded about its basis.
|
||
**Stores:** claude-md L251-257, REVIEWED-104, REVIEWED-105, PENDING-124 verbatim via the governance tools. R0 §3 verified directly against the
|
||
sha-matched contract (db39a503…, L180), so I.4 is substrate for this jurist, not testimony — the package's front-matter was true two turns ago and
|
||
is now false.
|
||
|
||
1. Q1 APPLIED. Constraint 4 has two clauses. The contrary reading engages only the second; the first speaks of limits, not failures, and "I could
|
||
not look" is a limit. The executor overstated its own uncertainty here, and deserves to know the replacement is firm.
|
||
|
||
2. CONDITION 1 — the quote-verification pass gains its own third state before it is relied on again. It reported verified on a normalized
|
||
reconstruction of REVIEWED-104, which had also dropped the sentence answering the package's own Q2. A two-valued verifier inside a package arguing
|
||
for three-valued verifiers. This is also a tenth instance, and the only one in the set independent of the advisory that proposed the doctrine —
|
||
produced by the gate, not the proposal.
|
||
|
||
3. CONDITION 2 — the ladder entry names the attested-absence family and cites the 2026-07-05 ruling (REVIEWED-47), so it joins a lineage rather
|
||
than standing as an orphan under a constitutional clause.
|
||
|
||
4. CONDITION 3 — the evidence statement is corrected before placement: two pre-existing instances of the shape, three of the adjacent principle,
|
||
one found at the gate. The uncorrected "five … same shape" would have been inherited as load-bearing.
|
||
|
||
5. CONDITION 4 — III.1 carries the environment-vs-defect split in the normative statement, not only in the consequence-trace. CONDITION 5 — landing
|
||
as leaned: one named instrument on reference-verification-ladder.md, nothing in ~/CLAUDE.md.
|
||
|
||
6. Q2 binds at reporting AND aggregation; the aggregation half is already ruled by REVIEWED-104 §1's closing sentence. Q3 names left free, with the
|
||
ratified test recorded: one name per referent, not one per concept. Q4 ratify not provisional, and not on the count — four of nine instances are
|
||
downstream of the advisory that proposed the doctrine; the chamber census is owed, not blocking.
|
||
|
||
**If AUTHORIZED:** Conditions 1-5 are discharged as of 2026-08-08. Tag with REVIEWED-106.
|
||
|
||
## REVIEWED-107 — PENDING-125 — A live false attestation in the governed record: Mauss's reading_index_status
|
||
**Date:** 2026-08-08
|
||
**Decision:** AUTHORIZED — option (a). D-1 lane, authorized verbally; RECORDED RETROSPECTIVELY, after the build.
|
||
**Notes:** (a) and (b) are different acts and were correctly separated. Correcting the field stops the record asserting something false today and
|
||
needs no ruling; re-anchoring the index is curatorial work that must carry the ladder's re-anchor = re-verify discipline, since re-anchoring
|
||
without re-verifying is what produced this class. (b) remains open.
|
||
|
||
1. Built as 8231bce. reading_index_status VERIFIED-BOUND → SHA-STALE, bounded to one field, shas untouched, manifest re-parses at 14 sources.
|
||
|
||
2. The executor checked the sub-question it had flagged before choosing a value, and the answer changed the entry: the vocabulary is UNDEFINED.
|
||
Three tokens in use across the manifest, no definition anywhere in either repo, every external mention prose about this defect rather than a
|
||
specification. SHA-STALE is therefore a fourth undefined token, added because none of the three could state the truth, and recorded as a known cost
|
||
rather than minted quietly.
|
||
|
||
3. Noted: the commit was the trigger mechanism's first real corpus exercise — both declared rules fired, fleet green, not a probe.
|
||
|
||
**If AUTHORIZED:** Tag with REVIEWED-107. (b) stays open under PENDING-125.
|
||
|
||
## REVIEWED-108 — PENDING-126 — Two holes in the fleet, and the census that followed
|
||
**Date:** 2026-08-08
|
||
**Decision:** AUTHORIZED — options (a) then (c). D-1 lane, authorized verbally; RECORDED RETROSPECTIVELY, after the build.
|
||
**Notes:** Merged with PENDING-122 on the executor's argument that they are one subject with overlapping files, and that hole 2 was a prerequisite
|
||
for verifying 122 — while suites raise, cannot-assess cannot be told from red. The merge was right.
|
||
|
||
1. (a) built as 8ff5a9f. Hole 1: close_ranges' section_end bound guarded, both branches; discriminating negative run — bound removed → two named
|
||
failures citing 499 and 400, restored → 47/47. Hole 2 was THREE sites, not the one filed; fixed as a class. An induced citability break went from a
|
||
single StopIteration traceback to seven named failures.
|
||
|
||
2. (c) the census, done, and it renamed the class. Crash-rather-than-name: 3 of 7 suites under 3 triggers, origin suite-side direct access. The
|
||
unguarded-rule question is unanswerable by inspection — token-mention said 13 of 13 touched, which is worthless since hole 1 lived in a touched
|
||
clause. Mutation: 4 of 7 caught, and all 3 survivors verified EQUIVALENT on current data by sentinel and by positive control. So hole 1 was never
|
||
an unguarded rule; it was a guard the live corpus cannot exercise, and three more of that shape exist in R0 alone. Latent, not wrong.
|
||
|
||
3. The crash class then closed at the preflight rather than at six sites (d21a43b), on the ground that all six depend on one invariant. Closing the
|
||
six revealed two more under a fourth degraded state, in suites the census had cleared: 6 → 8. The eighth originates in ENGINE code (retrieve.py
|
||
_work_map) and was deliberately not fixed by a test-side patch; whether retrieve() should degrade rather than raise is filed as an engine question
|
||
rather than hidden.
|
||
|
||
4. Final census, five degraded states: zero crashes, against 3/3/0/3 before.
|
||
|
||
5. ⚠ Recorded as owed, not blocking: the census covered R0's clauses only. n0/n1/v0/v1/cluster-a are unmutated and their escape rate is unknown,
|
||
not zero.
|
||
|
||
**If AUTHORIZED:** Tag with REVIEWED-108.
|
||
|
||
## REVIEWED-109 — PENDING-127 — R0 §4 emits two states where §3 rules three
|
||
**Date:** 2026-08-08
|
||
**Decision:** AUTHORIZED — option (a). D-1 lane, authorized verbally; RECORDED RETROSPECTIVELY, after the build.
|
||
**Notes:** The item said §4 was binary against §3's three states. It was worse: the CODE was unary. emit promoted baseline_sha256 to content_sha256
|
||
on every region — 261 of 261 for Alexander, including regions no instrument had verified — under a hardcoded date. Three different answers lived
|
||
in one contract and one module.
|
||
|
||
1. Built as ccc4d6c. Contract v0.1 → v0.2, superseded sentence preserved in place. Suite 31 → 44. Fleet 7/7.
|
||
|
||
2. The fix goes further than (a) asked, on the item's own logic, and that is ratified: a content_sha256 attests the whole span while name-landing
|
||
is evidence about the anchor's first line, so recording the former because the latter held promotes a weaker claim into a stronger one — the
|
||
PENDING-47 shape. Emission now records NO new fingerprints; one enters only through an attested re-verification. This is what makes PENDING-121
|
||
condition 4 reachable rather than aspirational.
|
||
|
||
3. State determination is now one function called by validate and emit, which had silently disagreed — §3's own "one mechanism with two call sites"
|
||
applied to the module's interior.
|
||
|
||
4. ⚠ The acceptance fixture named in the item was STALE, and measuring corrected it. Alexander's five front_matter anchors were partitioned out on
|
||
2026-08-07; Alexander is 261/261 name-landing with zero unverified. The real unverified population is Mauss 23 and after-the-reply 33. The
|
||
discriminating pair is therefore Alexander against Mauss — two real artifacts, a better control than the one specified. stale is unreachable from
|
||
live data and its control is labelled synthetic.
|
||
|
||
5. One pre-existing check went red and was replaced rather than deleted: it asserted the promotion this item rules a defect. A test that pinned the
|
||
old contract is evidence of what the contract used to say.
|
||
|
||
**If AUTHORIZED:** Tag with REVIEWED-109.
|
||
|
||
## REVIEWED-110 — PENDING-121 — engine_source_binding: prose to declared surfaces, and the fingerprint specified but never recorded
|
||
**Date:** 2026-08-08 (design gate 2026-08-08; two follow-on passes same day) · placed retrospectively
|
||
**Decision:** DESIGN GATE PASSED WITH CONDITIONS (1-4), then HELD OPEN for a redraft of Part IV.2 after substrate
|
||
verification. The redraft is filed (item Amendment 3 §D) and is NOT gated by this entry. Placement gate outstanding,
|
||
jointly with PENDING-128.
|
||
**Stores:** REVIEWED-101, REVIEWED-53, REVIEWED-47, PENDING-121, PENDING-119, PENDING-120, PENDING-47 verbatim via the
|
||
governance tools; graduation-spec.yaml L1-60 via governance_read. conversion-runbook.yaml and the R0 contract were
|
||
unreachable at the time of ruling and were read only after the steward supplied them, sha-matched against the request's
|
||
table (fffeed86…, db39a503…). engine/reading_index.py was never read by the jurist: condition 4 was ruled
|
||
prophylactically and REVIEWED-109 later found the code unary, which is worse than the item claimed.
|
||
governance_state() timed out; no drift count or repo status informed this ruling.
|
||
|
||
1. AN ADVERSE RATIFIED RULING WAS MISSING FROM THE GROUNDING PASS. REVIEWED-53 kept engine_source_binding as ONE entry —
|
||
'names a relationship across three files that move together; fragmenting recreates the failure' — and the package
|
||
proposed five siblings. REVIEWED-101 condition 1 did not cite it either: two rulings from one lane pointing opposite
|
||
ways, neither aware of the other. Treated as a verification trigger, not a precedence call. Resolution: the entry stays
|
||
ONE, surfaces become addressable members, and the co-movement invariant becomes declared data rather than why: prose —
|
||
because prose is what this amendment establishes no consumer reads.
|
||
|
||
2. CONDITIONS IN FORCE. (1) co-movement declared, a consumer verifying a proper subset reports incomplete never clean —
|
||
and this collapses with IV.1 para 2 into one requirement, drafted once. (2) resolve scope, then DERIVE the enumeration
|
||
from the runbook's list plus the per-region surface, justifying every omission; never compose afresh. (3) no dated counts
|
||
in declared data — locators and semantics only, population computed at read time; unverified-by-construction survives
|
||
only as a rule, since a rule does not go stale and a count does. (4) the promotion rule is REVIEWED-47 applied, not new
|
||
normative text: reuse the ratified by/against/result attestation shape under the single shared guard, reducing the
|
||
constitutional change to one requirement.
|
||
|
||
3. Q1 — the zero-evidence surface is CARRIED, never omitted, and the stronger form is adopted. The marking is not what
|
||
prevents the Part V inversion; not computing a heterogeneous aggregate is. Report per surface; any derived aggregate
|
||
reports unverified when a member is unpopulated or unchecked. Two discriminations required: the drift signal must be
|
||
separable from the unverified signal, or the check becomes a constant nobody reads; and '271 verified' must never
|
||
surface unqualified, since R0 §3 holds name-landing insufficient.
|
||
|
||
4. Q2 — reading_index_status is NOT a binding surface and NOT evidence, and no consumer of this enumeration may read it
|
||
as such. Retention, demotion or retirement is the engine's lane, D-1, and a chamber spec ruling an engine field's fate
|
||
would exceed standing. STRENGTHENED after ruling by REVIEWED-107 §2: the vocabulary is undefined — three tokens in use,
|
||
no definition in either repo — which is a cleaner ground than the one given here. Recorded as owed and unowned: SHA-STALE
|
||
is now a fourth undefined token and no open item covers defining the vocabulary.
|
||
|
||
5. Q3 — REVISED against my own lean, and the revision is the more useful half. The enumeration is not incomplete but NOT
|
||
COMPLETABLE: the runbook's scope_note sets membership as any repo the engine manifest binds, and the runbook's own list
|
||
was found short by its own grep on 2026-07-19. So the spec is authoritative for SEMANTICS and the runbook's grep for
|
||
COMPLETENESS — two claims, two homes, not the fault condition 1 forbids. My original 'single enumerative authority' is
|
||
withdrawn: it would have demoted the only instrument that has ever caught a missing surface.
|
||
|
||
6. Q4 — refinement of the hash-locality principle's third instance, not a fourth. Same referent class, same home, finer
|
||
granularity, and REVIEWED-53's individuating reason (files that move together) covers it. The ratified sentence stands
|
||
untouched. TEST RECORDED, because the count is maintained by ruling and went 2 to 3 through REVIEWED-53: a future surface
|
||
introducing a NEW HOME amends it; one refining an existing home does not.
|
||
|
||
7. Q5 / Q6 — RENAME, not rescope in place. The voice_manifest incident that created this entry was a name inviting a
|
||
wrong generalization; rescoping with a scope: field would be the same remedy a second time in the same block for the same
|
||
failure mode. The ratified principle is NOT amended: L19 and L39-40 update as mechanical referring-name edits under
|
||
REVIEWED-53's own lane rule for machine-data, with both reading grains preserved at the new name. REVIEWED.md L471 is not
|
||
edited — a ruling records what it ruled. Name: canonical_binding, NOT canonical_binding_surface, which contains
|
||
binding_surface and would have made the runbook's own key un-greppable through the instrument built to prevent that.
|
||
Completion control required both directions: before, the search finds the known occurrences; after, zero hits on the old
|
||
name outside REVIEWED.md, excluded BY NAME in the command.
|
||
|
||
8. SUBSTRATE VERIFICATION. Both supplied files matched their declared shas and line counts, so the anchors held.
|
||
Condition 2 leg (a) verified without the runbook — a key named engine already housed chamber artifacts in the executor's
|
||
own draft. Leg (b) verified: catalogue.yaml at runbook L251. Two findings the package did not carry: the manifest binds
|
||
THREE repos, not two (five after-the-reply sources are ARC, hard-coded to chamber paths in the draft), and R0 §4 L223-225
|
||
is binary against §3 L180's collapse prohibition — split out as PENDING-127, since the chamber requirement was unmeetable
|
||
while it stood. Now closed as REVIEWED-109, which found the code unary and 261 of 261 regions promoted under a hardcoded
|
||
date.
|
||
|
||
9. TWO SURFACES ADDED AFTER VERIFICATION. chamber-catalogue, and engine-sidecar-region — R0 §3 rules the two per-region
|
||
gaps are one mechanism with two call sites, so enumerating only the reading index would have hard-coded that divergence
|
||
into declared data.
|
||
|
||
10. SPLITS AND COUPLING. PENDING-125 (Mauss, condition 5a) — a live false claim 53 days old must not die inside a
|
||
deferred PROPOSAL; now REVIEWED-107(a), with (b) open. PENDING-127 — now REVIEWED-109. PENDING-128 — REVIEWED-53's
|
||
deferred option (c), recorded as live again on the reasoning that carried Q6 and to be RULED jointly with this item. Its
|
||
landing was made conditional rather than fixed: PENDING-127 clearing selects a single commit for both, and REVIEWED-109
|
||
has cleared it, so the single commit obtains.
|
||
|
||
11. SUPERSEDED EXAMPLE, flagged so it is not inherited. The item's design question cites Alexander's five stale
|
||
front_matter anchors; REVIEWED-109 §4 records they were partitioned out on 2026-08-07 and that Alexander is 261/261 with
|
||
zero unverified. The hazard is confirmed and larger, not weakened. Cite the 261/261 unconditional promotion.
|
||
|
||
12. ON THE GROUNDING PASS. Five omissions across three passes, every substantive one understating the gap the executor
|
||
was arguing for — the executor's own reading, accepted: passages stating the problem were quoted, passages stating its
|
||
extent were skipped, and four of five were extent-passages. Not selective; systematic in kind.
|
||
|
||
13. THE VERBATIM FILED RULING IS SUPERSEDED IN FOUR PLACES AND CARRIES NO MARKER. engine-source-binding-surfaces-JURIST-RULING-2026-08-08.md is the first pass only: its Stores line says the three files were NOT read and Parts I.1-I.4 are testimony (they were later read and sha-matched); its Q3 under 2(i) asserts the 'single enumerative authority' holding this entry withdraws at point 5; its condition 2 leaves the branch open (the steward chose (i)); and its §4 cites Alexander's five front_matter anchors, partitioned out 2026-08-07 per REVIEWED-109 §4. It is also the only verbatim jurist text in chamber docs/, and it contains no Q5 or Q6 — the rename holding PENDING-128 stands on exists there not at all. CONDITION: a supersession header at its top pointing to this entry, and to the two later passes, before either is relied on again. The document
|
||
is not edited below the header — a filed ruling records what was ruled when.
|
||
|
||
**If AUTHORIZED:** Conditions 1-4 stand as discharged in the Amendment 3 §D redraft, which is filed and awaiting the
|
||
placement gate — that gate is NOT granted by this entry and requires the redrafted canonical_binding block itself, not
|
||
its description. Rule jointly with PENDING-128; land in one commit per point 10. Tag with REVIEWED-110.
|
||
|
||
## REVIEWED-111 — PENDING-128 — REVIEWED-53's deferred option (c): kill the manifest shared word
|
||
**Date:** 2026-08-08
|
||
**Decision:** DESIGN GATE PASSED on option (a); (c) rejected. Ruled jointly with PENDING-121 per §Coupling. The
|
||
same-commit requirement is NARROWED, not adopted as filed. Three conditions.
|
||
**Stores:** PENDING-128, PENDING-121 (incl. Amendments 1-3), REVIEWED-53, REVIEWED-107, REVIEWED-109 verbatim via the
|
||
governance tools; graduation-spec.yaml L1-60 via governance_read. The shared-name collision log is reachable by no key
|
||
and is executor testimony; it carries no weight here. Numbering assumes this follows REVIEWED-110 (PENDING-121).
|
||
|
||
1. 1. RULED TOGETHER: YES, and the ground is REVIEWED-53's own text, not an unplaced holding. REVIEWED-53 judged (c) doctrinally complete and deferred it on occasion — 'out of scope for a doc-gap patch' — and PENDING-121 is a PROPOSAL that opens the same block deliberately, so the occasion has arrived. The parallel rename ruling is REVIEWED-110 §7; cite that, not 'PENDING-121's
|
||
Q6', which appears in no placed or verbatim-filed record. Renaming one key because names must not mislead, while leaving its neighbour in the same block warned-around on the same ground, is incoherent. Neither is ruled without the other. ORDERING CONSEQUENCE: REVIEWED-110 must be placed before or with this entry, or point 1 cites forward into nothing.
|
||
|
||
2. SAME COMMIT: CONDITIONALLY, AND NARROWED. The conditional filed against PENDING-127 has resolved — REVIEWED-109
|
||
cleared it — so a single commit obtains. But PENDING-121 lands in TWO places: the mechanism in graduation-spec.yaml
|
||
declared data, and the requirement in the constitution, MINOR bump by supersession. PENDING-128 is pure machine-data.
|
||
Read as binding 128 to all of 121's landing, a machine-data rename would ride inside a constitutional supersession, and
|
||
reverting the requirement would revert the rename — the revertability cost the conditional existed to avoid, returning
|
||
through the door the blockage just left. RULED: the coupling binds PENDING-128 to PENDING-121's DECLARED-DATA landing —
|
||
the layers: block commit — and not to its constitutional landing. §Coupling's own reason (same block, L19 cross-references
|
||
L20 by name) supports exactly this scope and no more.
|
||
|
||
3. OPTION (a) PASSES. Rename kills the collision. The executor's ground for recommending (a) and not (c) is affirmed:
|
||
retiring a ratified safeguard should be its own decision with its own evidence, not a tidy-up riding on a rename.
|
||
|
||
4. OPTION (c) REJECTED, and REVIEWED-107 strengthens the rejection. Retiring the warning rests on 'the name is now
|
||
unambiguous', which is the assumption whose failure created this entry. REVIEWED-53 chose two reading grains
|
||
deliberately. Both stay. Retiring a reading grain in a corpus just shown to mint undefined tokens is the wrong direction.
|
||
|
||
5. CONDITION 1 — THE WARNING'S TEXT IS REWRITTEN, NOT MERELY KEPT. The item says keep the warning and does not notice
|
||
that the rename changes what the warning is about. L19 currently warns that the word manifest names two different engine
|
||
objects; after the rename the chamber side no longer carries that word, so the warning as written describes a collision
|
||
that no longer exists at the site where it is printed. A kept-verbatim warning would be a stale safeguard — the shape
|
||
this register keeps ruling against, arriving through a change made to improve clarity. Rewrite both grains to say what
|
||
they now need to say: that the engine's SOURCE manifest binds by hash and is a different object, and that a reader
|
||
arriving from an older citation of voice_manifest has reached the right entry. Preserving a safeguard means preserving
|
||
its function, not its bytes.
|
||
|
||
6. CONDITION 2 — THE NEW TERM IS DEFINED WHERE IT IS INTRODUCED, IN THE SAME ACT. REVIEWED-107 §2 found
|
||
reading_index_status's vocabulary undefined — three tokens in use, no definition in either repo — and a fourth minted to
|
||
state a truth none of the three could. That is a demonstrated corpus tendency to introduce terms without definitions and
|
||
notice later. voice_personification is drawn from the entry's own prose; if personification is undefined at its site, the
|
||
rename trades a documented collision for an undefined term, which is worse than the status quo, since the collision at
|
||
least carried a warning. The definition goes in the rewritten grains of condition 1 — one act, not two.
|
||
|
||
7. CONDITION 3 — THE COMPLETION CONTROL RUNS IN ONE INVOCATION, WITH A POSITIVE CONTROL. The item requires zero hits on
|
||
the old name outside REVIEWED.md, and separately that the L19-L20 cross-reference still resolves in both directions. Run
|
||
apart, the first is satisfiable by DELETING the cross-reference: the negative result passes precisely because the subject
|
||
was removed. RULED: both run together, with resolves-at-new-names serving as the positive control for the zero-hits
|
||
check. This hole opens only under a single commit, where the cross-reference becomes rewritable on both sides at once.
|
||
|
||
8. NAME. voice_personification passes the substring test against binding_surface-class hazards. Recorded as neutral, not
|
||
an improvement: graduation-spec.yaml carries voice as a frontmatter optional field in the same file, so a search for
|
||
voice cannot isolate the frontmatter field from the layer key, before or after. The item's claim to be 'the first
|
||
retired rather than warned around' should not be read as clearing the file of voice-family entanglement.
|
||
|
||
9. UNVERIFIED, and carrying no weight. The shared-name collision log, and therefore 'the ninth such case'. Reachable by
|
||
no governance_read key. The ground for (a) is REVIEWED-53's own text, which was read.
|
||
|
||
10. NOT RULED HERE. The census of the other eight collisions, which the item correctly declines to propose. Whether
|
||
REVIEWED.md L471 is touched — it is not; a ruling records what it ruled.
|
||
|
||
**If AUTHORIZED:** Land option (a) with conditions 1-3, in PENDING-121's declared-data commit per point 2, not in its
|
||
constitutional supersession. Tag with REVIEWED-111.
|
||
|
||
## REVIEWED-112 — PENDING-118 — The deferred-decision checker is structurally blind to every archived deferral
|
||
**Date:** 2026-08-08
|
||
**Decision:** AUTHORIZED — the widening, with the honest limit that building it exposed. D-1 lane, authorized verbally; RECORDED RETROSPECTIVELY.
|
||
**Notes:** The item's own option (1) was refuted by implementation. It claimed the checker already parses the archive's format; it does not — the
|
||
marker is an HTML comment, there are zero in either register file, and their deferrals are prose (53 in PENDING.md, 26 in the archive). Widening
|
||
alone would have found nothing and reported clean, which is the silent net the item was filed to describe, specified as its own remedy.
|
||
|
||
1. Widening ships with its limit stated in the output: structured blocks found anywhere in the register; prose deferrals counted and reported
|
||
un-machine-readable, never as absent. Counting is not classifying — 88 is an upper bound on candidates, and how many carry a fired condition is a
|
||
reading task, reported unestablished.
|
||
|
||
2. Three controls added per the script's standard: the counter fires on a known-present phrase, stays silent on unrelated text, and the register
|
||
files are provably inside the widened scan.
|
||
|
||
3. Closes: the checker no longer reads only docs/**, and the register's prose deferrals are visible as a named unknown. Does not close: the
|
||
classification. Size was "unmeasured, deliberately"; it is now bounded and still unclassified — better, not finished.
|
||
|
||
**If AUTHORIZED:** Tag with REVIEWED-112.
|
||
|
||
## REVIEWED-113 — PENDING-129 — The pattern-finder's voice cross: attest what was not searched
|
||
|
||
**Date:** 2026-08-09
|
||
**Decision:** **(a) AUTHORIZED**, with three refinements: derive the states from the cross
|
||
(in manifest?) × (probed by spec?) rather than the difference, so closing the fourth cell later
|
||
is a line and not a rewrite; `not-in-corpus` is a top-level key per REVIEWED-47 §1a, not a
|
||
parenthetical on the spread line; and carry REVIEWED-104's two strengths, so an absence that is
|
||
environment cannot read as defect and become furniture.
|
||
**Provenance:** steward, 2026-08-09, on the executor's PENDING-129. Placed after the fact —
|
||
the ruling was relayed and built the same day, and `governance-drift-check.py` flagged the gap.
|
||
|
||
**Ground.** Not a judgment call: the ratified three-outcome doctrine applied to a check whose
|
||
subject can be absent, and the direction of the error — dropping a voice can only raise the
|
||
apparent instantiation rate — puts it on the wrong side of Constitutional Constraint 4.
|
||
|
||
**⚠ The fourth cell was mis-inferred in this ruling, and building it corrected the ruling.**
|
||
The design gate reasoned the cell would collapse into `silence`, flagged that as inference
|
||
rather than reading, and invited the check. Driven against the live corpus it raised
|
||
`KeyError` — a crash in engine code, the class PENDING-126(c) closed suite-side only. The
|
||
scope decision stands (the cell is representable and non-crashing; its reporting semantics
|
||
stay unruled), but the record should show the correction ran executor→ruling, which the
|
||
differently-biased-checkers doctrine predicts and is worth logging as an instance.
|
||
|
||
**If AUTHORIZED:** ~~Proceed.~~ Already built at `6f6bac5` (fix + `tests/test_pattern_finder.py`,
|
||
22 checks, witnessed red behaviourally; fleet 8 suites / 263 checks). Tag any follow-on with
|
||
REVIEWED-113.
|
||
|
||
## REVIEWED-114 — PENDING-130 — V4's designated adversarial fixture is an empty file, and a Stage-1 completion criterion has no subject
|
||
**Date:** 2026-08-09
|
||
**Decision:** AUTHORIZED — option (a), ordered behind PENDING-129, with five conditions. The item does NOT close on this ruling.
|
||
|
||
**Notes:** The recommendation is right and the item's own condition is the ruling. (b) and (c) both
|
||
concede that V4 ships without an adversarial fixture in order to fix a documentation defect, and the
|
||
re-run demonstrably has the property V4 needs — 36 citations, zero abstentions, two passages grounding
|
||
two primitives each. What (a) does not have, and cannot acquire from the executor, is an answer key.
|
||
Everything below protects that one step, because it is the only step in the item with no mechanical
|
||
control and the item says so.
|
||
|
||
Recorded first, because it bears on condition 1: `ec6fa0b` (studium-engine, local, unpushed) is
|
||
scoped 'preservation only'. Read from the branch state alone it looks like (a) executed ahead of this
|
||
ruling; read from the commit subject it is the correct act — an artifact protected against the loss
|
||
this item exists to record. The distinction is the whole of it, and the executor made it explicitly.
|
||
|
||
1. CONDITION — ORDER: PENDING-129 lands first, and the fixture is the POST-fix re-run. The fixture's
|
||
grounding content is invariant under 129: 129's own two-directional check REQUIRES the four
|
||
manifested voices' numbers to be byte-identical, so the 36 citations, the zero abstentions and the
|
||
two double-groundings survive the fix unchanged. Only the spread line moves. Committing the pre-fix
|
||
run as the fixture would place a SECOND and unrelated falsehood — a denominator inflated by the
|
||
silently dropped voice — inside an artifact preserved to teach V4 ONE falsehood class. A
|
||
differently-formed reader handed both has no way to know which they are being asked to mark, and
|
||
the contamination lands on the one step no control covers. Retain `ec6fa0b` as the pre-fix run: it
|
||
is now load-bearing for 129's byte-identity comparison, which is not what it was committed for.
|
||
|
||
2. CONDITION — PROVENANCE NAMES THREE MOVING PARTS: spec path and hash, corpus/manifest state, and
|
||
ENGINE COMMIT. Option (a) named the first two. 129 moves the third, and an engine version omitted
|
||
from the header makes the August fixture unreproducible in precisely the manner that made the June
|
||
run unrecoverable.
|
||
|
||
3. CONDITION — THE KEY IS MARKED AGAINST THE CORPUS, NOT AGAINST THE REPORT. This item's own
|
||
diagnosis is 'cited a derived label instead of the substrate' — a description of the artifact read
|
||
in place of the artifact, three times over, by an instruction whose entire content was 'protect
|
||
this artifact'. Marking the key by reading the rendered report repeats that shape inside the
|
||
remedy: the report's claim that its citations are verbatim and correctly located is the executor's
|
||
claim about them, and the key exists to be independent of the executor. The marking is done against
|
||
the passages at the cited locations. The executor states in the header whether the report carries
|
||
sufficient surrounding context for that, or whether the corpus must be open beside it.
|
||
|
||
4. CONDITION — NO DOCUMENT CALLS IT A FIXTURE UNTIL THE MARKED KEY EXISTS as a separate dated file.
|
||
§2.3, criterion 1 and `CLAUDE.md` L61 may be corrected to name existing material; they may not
|
||
assert a fixture that is half-done. This item is the evidence that an assertion about an artifact
|
||
survives seven weeks and three currency passes without anyone opening the file. Asserting a
|
||
fixture before its key is marked rebuilds that gap under a fresh filename.
|
||
|
||
5. CONDITION — 'RETRO-GATED' IS STRUCK FROM CRITERION 1, not repointed. Under (a) there is no
|
||
retro-gated run; the word encodes a provenance claim the August pass cannot satisfy. Repairing the
|
||
artifact reference while leaving the verb preserves the false claim in the criterion that was
|
||
unsatisfiable because of it.
|
||
|
||
6. The jurist cannot discharge condition 3 in the steward's place. Raised here so it is not proposed
|
||
later as an efficiency: PENDING-124 Amendment 2 Q4 is ratified on exactly this point — jurist and
|
||
executor 'do not differ from each other in formation'. One party to this collaboration is
|
||
differently formed, and the key is theirs.
|
||
|
||
7. The item's evidence figures were measured on the pre-fix run. After the re-run under condition 1
|
||
they cite a superseded output and must be restated in PENDING-130 — not re-argued, restated.
|
||
Flagged because this is the class of cost that goes unrecorded.
|
||
|
||
**If AUTHORIZED:** Hold until PENDING-129 lands. Then re-run the unmodified June spec, commit the
|
||
output with the three-part provenance header, and correct §2.3, criterion 1, `docs/tool-evolution-log.md`
|
||
and `CLAUDE.md` L61 to name existing material without the word 'retro-gated' and without the word
|
||
'fixture'. Tag commits with REVIEWED-114. **The item remains OPEN and is not archived** until the
|
||
steward's marked answer key exists as a dated file; only then may V4 be built against it and the
|
||
fixture named as such.
|
||
|
||
## REVIEWED-115 — PENDING-131 — The nested-voice arc: (a) authorized then voided, B7-alone lapsed, the gold-intersection reporter authorized
|
||
**Date:** 2026-08-10
|
||
**Decision:** AUTHORIZED in part; one authorization VOIDED the same day; one conditional authorization LAPSED on its own condition.
|
||
**Notes:** Three dispositions from one exchange, recorded together because they were given together and because two of the three did not survive contact with the substrate. None of the three resulted in a corpus write.
|
||
|
||
1. OPTION (a) — mark Mauss L926 as role: quotation — AUTHORIZED, then VOID. Granted on the narrow framing "make the Mauss sidecar internally consistent, one region joining twelve already using that mechanism in the same file", and explicitly non-precedential for option (c). Reading the passage before executing refuted that framing: all twelve existing quotation regions are markdown blockquotes, a whole-line construct, and the sidecar addresses by line range, while the Ranaipiri testimony is inline guillemets beginning at char 279 of a 1,427-char line, after Mauss's own attributing sentence. The available act would have fenced that sentence, which is the disambiguator the classification depends on. The authorization is VOID rather than pending: an executable authorization left standing in the record, whose factual basis is gone, is a trap for whoever next clears the backlog with no reason to re-read.
|
||
|
||
2. B7 ALONE as the single-item proof of the R0 propose/unverified pattern — AUTHORIZED subject to three amendments, LAPSED on the second. The amendments were: re-state the voice attribution, which had been recorded on a typographic warrant the same day disproved; obtain an independent reading of whether "care" is the essay's vocabulary rather than Alexander's; and stamp what the proof does not establish. The second was checked and came back adverse — the word "care" occurs nowhere in pattern 24, and appears in 2 of the 26 March queries. The executor is the first reader and agrees with the challenge, which is not a second reader. No item in the eight currently qualifies.
|
||
|
||
3. THE GOLD-INTERSECTION REPORTER — AUTHORIZED and BUILT (studium-engine 569e14c, scripts/gold_intersection.py). A reporter, never a blocker, on the ground that a blocking version run against L926 would have refused the pass and protected three fr citations that reading then showed were never legitimately gold. Three conditions, all met: the specification wording no longer parses as blocking; positive controls run on every invocation, not only under --selftest, because the ordinary output is a negative and the specific silent failure is address parsing drifting a gold file to zero regions; granularity declared line-level and printed on every clean result. Verified on the motivating case — L926 reports four intersections, exit 0. Five chavruta paratext and silence anchors report UNCHECKED, never clean.
|
||
|
||
**If AUTHORIZED:** Already executed as recorded. Option (a) is not to be revived without a fresh proposal on a corrected basis; PENDING-131 Addendum 1 holds the reasoning. Tag any follow-on commits REVIEWED-115.
|
||
|
||
---
|
||
|
||
## REVIEWED-116 — PENDING-131/132/133/134 — Design-gate ruling on the nested-voice package: the test is right, its derivation is not
|
||
**Date:** 2026-08-10
|
||
**Decision:** AUTHORIZED — the jurist's ruling on all six gate questions is adopted. Three companion items remain OPEN and are named in point 6.
|
||
**Notes:** Ruling on docs/nested-voice-class-JURIST-PACKAGE-2026-08-10.md (studium-engine 74aed28). The package reversed its own central argument mid-draft and left the refuted version visible; the jurist records that this is what made the decisive counter-argument findable, having read it in the position the executor had abandoned.
|
||
|
||
1. Q1 — THE CLAIM-SIDE TEST GOVERNS, BUT IT IS NEW DOCTRINE AND MAY NOT ENTER AS A READING OF THE RATIFIED DESIGN. The package argued the test was already supplied by §7.4(ii)'s F5 parallel. That derivation fails on a ground the package never addressed: §6.2 is PRE-REGISTERED, by its own parenthetical, and pre-registration's entire value is that the scheme was fixed before anyone saw which spans landed where. A test that changes stratum-B membership, derived after reading the spans it reclassifies and entering by interpretation rather than amendment, voids that guarantee whether or not the test is right. Had the package's headline stood, a pre-registered scheme would have been amended without an amendment. Filed instead as PENDING-134.
|
||
|
||
2. Q2 — §6.2's OMISSION OF F4 IS EVIDENCE, AND IT DISQUALIFIES THE DERIVATION RATHER THAN THE TEST. §6.2 admits F5 as "qualified span (F5)" — naming a span property and parenthesising the failure-mode row it risks. That construction would have admitted "reported-speech span (F4)", and the drafters were using it one item away in the same list. Further, the design has two admission routes to stratum B, §6.2's enumeration and an explicit clause in the §5 row, and F10 has the second where F4 has neither. Two available mechanisms both unused is not an accident of enumeration.
|
||
|
||
3. Q3 — INSTANCE 8 (L1551) IS NOT ESTABLISHABLE AS RETAINED, and its retention is split out of PENDING-132. The package classified it on structural markers because the positional probe failed on it, and the probe failed precisely because it is a two-fragment composite — which is the profile of the claim withdrawn from the EN set the same morning for fusing one host proposition with one nested-voice proposition. The fused-claim test was subsequently run: fragment 1 carries the attributing clause; fragment 2 does not, opening on the tail of the carpenter's speech before reaching Mauss's conclusion. Instance 8 needs its own disposition.
|
||
|
||
4. Q4 — THE SUB-LINE ADDRESSING CAPABILITY IS TO BE SOUGHT, framed as an addressing capability and not as a vocabulary reconciliation. Two additions: retraction does not close the exposure, since removing citations takes bad gold out but installs no fence and L926 remains unmarked; and §7.4(i)'s requirement is unsatisfied either way, so the ask does not weaken when PENDING-132 lands. Cross-repo — the schema is locked by the Chamber Library constitution, which the studium charter cannot unlock.
|
||
|
||
5. Q5 and Q6 — (b1) proceeds as an identification pass that writes nothing, marking after the vocabulary is ruled, since the reading survives any vocabulary and only the field-write depends on it. The fr 1:9 ratio is VOID and is to be re-derived ONCE, after the doctrine lands and dispositions are recorded — not after PENDING-132 alone, which would derive it twice.
|
||
|
||
6. PART V RESCOPED, and the item contradicted its own diagnosis. PENDING-133 bounded its remedy at the two F4-carrying spans while stating that P7's tagging had no claim-side step — which, if true, is true of the whole cell. The bound also assumed P7's F4 tagging is complete, unchecked, against evidence pointing the other way: 21 inline guillemet spans of 120 characters or more sit unmarked inside Mauss's role: text regions, and the corpus marking pass missed inline cases by the same mechanism on the same source. Corrected scope: every fr grounded span, nine or ten, read for reported speech and dispositioned where present. Recorded as PENDING-133 Amendment 1.
|
||
|
||
7. VERIFICATION LIMIT ON THIS RULING, stated by the jurist first and recorded here because it bears on the whole: every quotation in the package's Part I was the executor's testimony, unreachable through governance_read, and that is the exact material two of the day's three reversals turned on. Closed the same day — see REVIEWED-117.
|
||
|
||
**If AUTHORIZED:** PENDING-131 Addenda 1–3 stand as filed. PENDING-132 (amended), PENDING-133 (as rescoped) and PENDING-134 REMAIN OPEN and await a separate steward decision; this entry adopts the ruling that shapes them, never the acts they propose. No corpus file has been modified anywhere in this arc. Tag follow-on commits REVIEWED-116.
|
||
|
||
---
|
||
|
||
## REVIEWED-117 — PENDING-86 — Fourth instance: the V0-lane texts the jurist design-gates but could not read
|
||
**Date:** 2026-08-10
|
||
**Decision:** AUTHORIZED — four read-only keys added to governance_read, on the steward's direct request.
|
||
**Notes:** Same shape and same remedy as REVIEWED's earlier PENDING-86 option (a), which added chamber-spec and graduation-spec on the ground that the jurist design-gates constitutional supersessions of documents it could not read. This is the fourth recorded instance and the first outside the chamber constitution.
|
||
|
||
1. THE GAP WAS NAMED BY THE JURIST IN ITS OWN RULING, as the first thing in it: governance_read exposed eight keys, docs/v2-validation-harness-design-2026-07-09.md was not among them, and therefore every quotation in the package's Part I was testimony rather than something the ruling's author could reach. The package's Part I exists solely because of that limit.
|
||
|
||
2. KEYS ADDED: v2-harness-design (§5 failure-mode table, §6.2 pre-registered strata, §7.4 whole-for-part attribution — the three sections the ruling turns on); v2-stratum-tags (P7); mauss-fixture-spans (locations and Tier-1 verdicts); mauss-fixture-citations (the citation texts themselves — the file that answers whose proposition a claim asserts). Read-only, keyed, no path argument; the enum design is unchanged and the traversal refusal is untouched.
|
||
|
||
3. EIGHT CONTROLS ADDED, and they check the served CONTENT rather than only that a key resolves — that §6.2's pre-registration clause, §7.4's nested-voice sub-type, §5's F4 row and the L926 citation strings are actually present in what is served. A key that resolved to an empty or wrong file would otherwise pass a reads-ok assertion. Self-test 54 checks, 0 failures.
|
||
|
||
4. PROCEDURAL NOTE, recorded rather than omitted: the change was executed on a conversational request and before any item was filed for it. It extends an already-ruled class on an existing read-only instrument, and it is trivially reversible, but the execution preceded the record and that ordering is stated here rather than left to be inferred.
|
||
|
||
**If AUTHORIZED:** Already executed (dotfiles 4c3758e). Tag follow-on commits REVIEWED-117.
|
||
|
||
## REVIEWED-118 — PENDING-132 — Retract L926's three citations from the fr grounded gold
|
||
**Date:** 2026-08-10
|
||
**Decision:** AUTHORIZED — the retraction only. The instance-8 retention is NOT authorized by this entry and remains undecided.
|
||
**Notes:** fr instances 6, 12 and 16 cite Tamati Ranaipiri's first-person testimony and are bound as citations of Mauss. Taken now on a timing ground as well as a substantive one: no measurement currently depends on this fixture — the EN span proposal is stamped unusable pending the query split, and the fr ratio is void pending PENDING-134 — so the fixture is quiescent, which is the cheapest possible moment to change it. That window closes as soon as anything starts measuring again.
|
||
|
||
1. SELF-STANDING ON CONVERGENT GROUNDS, which is why it can precede PENDING-134. The two live readings of F4 disagree about the marker in general and converge on L926 in particular: under the claim-side test it retracts because its three citations assert Ranaipiri's propositions rather than Mauss's; under the stricter reading, that §6.2's double omission disqualifies F4 from stratum B outright, it retracts because it carries F4 at all. Ruling PENDING-134 either way leaves this outcome unchanged. An earlier draft led with the claim-side test alone, which would have made an authorized item rest on an unruled gate.
|
||
|
||
2. EVIDENCE, measured 2026-08-10 against the canonical (sha 2889709555f2abac…, binding verified). Mauss's own framing sentence — the one naming Elsdon Best and Tamati Ranaipiri — occupies characters 0 to 279 of L926; the quoted testimony runs 279 to 1427. All three citations begin at characters 308, 843 and 932, inside the testimony. All three are first-person. None carries an attributing clause.
|
||
|
||
3. NO REPLACEMENT RATIO IS RECORDED, and the omission is deliberate. An earlier draft stated the effect as 1 A : 9 B becoming 1 A : 8 B. Under PENDING-134 the cell's tagging basis changes and not merely its population, so 1:8 would be exactly as provisional as 1:9 — and a figure inside an AUTHORIZED item is far stickier than one marked stale inside a proposal, because it will be quoted. The ratio is VOID and is re-derived ONCE, after the doctrine lands and dispositions are recorded (REVIEWED-116 point 5). Effect recorded here is population only: fr distinct spans 11 to 10, bound instances 15 to 12.
|
||
|
||
4. INSTANCE 8 (L1551) IS SPLIT OUT AND NOT AUTHORIZED BY INCLUSION. The item as first filed carried a contrast section stating that instance 8 should be retained, which would have authorized that retention as a side effect of authorizing this retraction. Confirmed on re-reading that the retention left the body and survives only as a quotation inside the correction note. The fused-claim test has since been run on its two fragments and goes against retention: fragment 1 carries the attributing clause, fragment 2 does not, opening on the tail of the carpenter's speech before reaching Mauss's conclusion. Its disposition is owed as its own item.
|
||
|
||
5. THIS IS A RETRACTION, NOT A FENCE, and the exposure survives it. Removing three citations takes bad gold out of the fixture; it installs no fence. L926 remains unmarked, a future claim can still ground inside the testimony, and §7.4(i)'s required provenance join is unsatisfied either way — so the addressing ask (PENDING-131 (c), REVIEWED-116 point 4) does not weaken when this lands.
|
||
|
||
**If AUTHORIZED:** Retract instances 6, 12 and 16 from the grounded set in corpus/mauss-phase2-spans.yaml and corpus/v2-stratum-tags.yaml, recording the retraction and this entry's number in both. Do NOT re-derive the ratio; do NOT mark L926; do NOT disposition instance 8. Re-run the fleet and the gold-intersection reporter against the changed fixture, and confirm the reporter's live control still loads a non-empty gold set afterward — a retraction shrinks exactly the thing that control reads. Tag commits REVIEWED-118.
|
||
|
||
## REVIEWED-119 — PENDING-135 — Instance 8 reclassified as a negative-candidate; and the item's own account of why the better option was unavailable is corrected
|
||
**Date:** 2026-08-13
|
||
**Decision:** AUTHORIZED — option (c). The negative SUB-TYPE name is held open and is not decided by this entry.
|
||
**Notes:** Ruling on PENDING-135 (studium-engine `de1c34b`). Authorized in conversation ahead of this record; the ordering is stated at point 6 rather than left to inference.
|
||
|
||
1. THE MEASUREMENT DECIDED IT, AND IT SUPPLIED WHAT THE PROBE COULD NOT. REVIEWED-116 point 3 ruled instance 8's retention "not establishable" because the nested-voice package classified it on structural markers, the positional probe having failed on it — and the probe failed precisely because it is a two-fragment composite. Reading L1551 directly against the canonical supplies the positions. The line carries three voices in sequence: Mauss narrating (chars 0–479), his attributing clause `Le charpentier dit à Arthur : ` (479–509), the carpenter in guillemets (509–747), and Mauss's conclusion (748–811). The citation's two fragments have OPPOSITE dispositions — fragment 1 opens at char 479 ON the attributing clause, so attribution is in view; fragment 2 opens at 643 inside the speech and runs to 811, crossing the closing guillemet at 747 and ending inside Mauss's own conclusion, with the attribution 134 characters upstream and on the far side of the elision. The instance therefore neither retains nor retracts as a unit, which is why it could not be settled by inclusion in PENDING-132.
|
||
|
||
2. (c) OVER (a), ON YIELD RATHER THAN ON CAUTION. A plain retraction removes a defective gold pair and produces nothing. Reclassification removes the same pair and produces a negative of a sub-type the corpus does not otherwise contain: §7.4(i)'s nested-voice negative class has no mechanism anywhere on the fr cell (P7 finding 3), and after L926's retraction this is the only fused-voice exemplar available. Marked in place, nothing deleted, per the precedent applied at REVIEWED-118 and to the Havámál before it.
|
||
|
||
3. THE SUB-TYPE NAME IS OPEN AND THE FILE SAYS SO. §7.4(i) as written addresses the nested voice served AS the host's — the Havámál shape, where the whole span is the other voice. Fragment 2 is not that: it FUSES the carpenter's proposition with Mauss's in one continuous string. Whether §7.4(i)'s class admits a fused-voice sub-type or whether that is a distinct negative class needing its own definition is a taxonomy question the executor can measure and cannot settle. The span is placed in the class provisionally so that it leaves the grounded set; `negative_sub_type_OPEN` records the question in the corpus file itself, and it is owed a ruling before the negatives are generated.
|
||
|
||
4. ⚠ THE ITEM'S ACCOUNT OF WHY (d) IS UNAVAILABLE IS WRONG, AND IS CORRECTED HERE RATHER THAN LEFT TO BE REDISCOVERED. PENDING-135 states that the faithful disposition — retain fragment 1's extent, drop fragment 2's — is "not executable" because "splitting requires sub-line addressing — PENDING-131 (c), locked cross-repo by the Chamber Library constitution." That names the wrong lock. The constraint is the RATIFIED GOLD SCHEMA, `studium/v2-gold@1` (v2-harness design §14.2), which declares `span: {source_id, section_id, lines: [a, b], source_sha256}` — line ranges. That schema is **engine-side and D-1**; `studium/meta@1`, the chamber-locked sidecar schema PENDING-131 (c) addresses, is a different schema governing a different artifact. Option (d) is therefore **materially cheaper than the item claimed** — it needs a gold-schema decision the steward can take directly, not a cross-repo negotiation. Recorded as a correction because an authorization left standing on a false blocking claim is a trap for whoever next clears the backlog, which is the ground REVIEWED-115 point 1 voided an authorization on.
|
||
|
||
5. (c) IS NOT WEAKENED BY POINT 4, AND IS THE RIGHT INTERIM EITHER WAY. Nothing was deleted, so (d) remains fully available: the span, both fragment extents and the superseded stratum are all recorded in place. What (c) buys now is that a defective pair stops sitting in the grounded set while the schema question is open, and `v2-gold.yaml` does not yet exist — it is the assembly target, so a sub-line form would be designed ahead of the thing it addresses. The correction in point 4 changes the FOLLOW-ON, not this disposition.
|
||
|
||
6. PROCEDURAL NOTE, recorded rather than omitted. The reclassification was executed on conversational steward authorization ("I lean (c)", then "let's do 2, 3 and 4") and committed before this entry existed. Same ordering as REVIEWED-117 point 4, stated here for the same reason: the execution preceded the record, and that fact belongs in the record rather than in an inference from commit timestamps.
|
||
|
||
**If AUTHORIZED:** Already executed (studium-engine `de1c34b`). The sub-type name (point 3) and the gold-schema question (point 4) REMAIN OPEN and are owed separate dispositions; this entry decides neither. Do NOT re-derive the A:B ratio — it stays VOID pending PENDING-134, re-derived ONCE after the doctrine lands and all dispositions are recorded (REVIEWED-116 point 5). Tag follow-on commits REVIEWED-119.
|
||
|
||
---
|
||
|
||
## REVIEWED-120 — PENDING-136 — The count fields carry their populations; and the executor committed the same error inside the same session
|
||
**Date:** 2026-08-13
|
||
**Decision:** AUTHORIZED — option (c). The bare `distinct_spans` field is retired rather than redefined.
|
||
**Notes:** Ruling on PENDING-136 (studium-engine `de1c34b`). Authorized in conversation ahead of this record, as at REVIEWED-119 point 6.
|
||
|
||
1. THE DEFECT WAS THE NAME, NOT THE NUMBER, WHICH IS WHY (a) AND (b) BOTH FAIL. `distinct_spans: 11` decomposed as 1 A + 9 B + 1 reclassified-out, so it counted LISTED spans and one of the eleven was already not grounded. REVIEWED-118 §3 then did arithmetic on it as though it counted GROUNDED spans, and the executed value of 10 named neither population. Both readings were reasonable on the name given, and there is no fact of the matter about which was meant: P7 wrote a field that summed one way and a ruling read it another. Choosing between them would be selection rather than derivation — picking a survivor instead of deriving the rule from what a consumer must do, which is know the population it is dividing by. Retiring the name makes the defect unrepeatable rather than merely repaired.
|
||
|
||
2. ⚠ EXECUTING IT CAUGHT THE EXECUTOR COMMITTING THE SAME ERROR, HOURS EARLIER, IN THE SAME SESSION. `bound_instances_grounded` was written as 12 at REVIEWED-118 execution time by computing 15 bound − 3 retracted, silently ignoring that instance 17 (the Havámál) had already left the grounded set at P7. The correct value is 10. The error entered by SUBTRACTION both times — P7's and the executor's — which is why every count in the cell is now verified by ENUMERATION against the grounded rows, and why the verification is a check rather than a comment.
|
||
|
||
3. THE CELL AS IT NOW STANDS, all five figures enumerated and summing: 11 listed spans · 8 grounded (1 stratum-A + 7 stratum-B) · 2 reclassified out of grounded (the Havámál at P7, instance 8 at REVIEWED-119) · 1 retracted (L926, REVIEWED-118) · 10 grounded bound instances. `bound_instances_total` stays 15, which is a binding fact and moves for no disposition.
|
||
|
||
4. NO CONSUMER WAS AFFECTED, and that is stated so the item is not read as a live miscalculation. Verified: no engine code reads any of these count fields — `gold_intersection.py`, the only programmatic consumer of the file, reads `spans[].span`, `spans[].stratum` and `spans[].instances` and nothing else. The defect was in a record humans read and rulings quote, which is where it did its damage: REVIEWED-118 §3 quoted it.
|
||
|
||
5. THIS IS THE THIRD INSTANCE IN FOUR DAYS OF ONE FAMILY — a number stated without the population or unit it counts — and none was caught by an instrument. `546f316` mixed sidecar-file count with manifested-source count in one sentence; `e973db9` §3 withdrew a cross-cell comparison whose units were never shown commensurable; this. All three were caught by re-deriving before quoting. The family is worth watching for whether it warrants a check rather than a habit; no such check is proposed here.
|
||
|
||
**If AUTHORIZED:** Already executed (studium-engine `de1c34b`). The ratio stays VOID. When it is re-derived once under REVIEWED-116 point 5, the derivation must state WHICH population it used and must consume the renamed fields, never a reconstructed `distinct_spans`. The parallel question on the `en` cell — `reachable_items: 22` beside `distinct_divisions: 12`, correctly named but with §6.6's power arithmetic stated in `n` — is NOT established clean by this entry and is owed its own look. Tag follow-on commits REVIEWED-120.
|
||
|
||
## REVIEWED-121 — PENDING-134 — The whose-proposition test: adopted narrowly, conditioned on the fence, and its counter-argument corrected upward
|
||
**Date:** 2026-08-14
|
||
**Decision:** AUTHORIZED — the narrow test only (Part V as filed, H2 honoured), conditioned per point 5. The general principle is NOT ratified. The cell-constant reading surfaced at point 2 is split out as PENDING-137; its remedy is not decided here.
|
||
**Notes:** Ruling on `docs/whose-proposition-JURIST-PACKAGE-2026-08-14.md`. H1 is satisfied: the twelve-key MCP surface was live at ruling time, and §5, §6.2, §7.4, §11.6, §12.5, §14.2, REVIEWED-116, REVIEWED-119 and the fr block of `v2-stratum-tags` were read verbatim from the substrate rather than from the package's transcription. Every quotation in the package's Parts I, IV.4 and VI verified accurate; III.5's figures verified against the file exactly. The defects ruled on below are not transcription defects.
|
||
|
||
1. Q1 — ROUTING IS HYBRID, AND THE LINE IS STATED RATHER THAN SPLIT PRAGMATICALLY. §12.5 classes gold composition as D-1; §11.6 is the precedent for a D-1 gold matter appearing here for visibility; REVIEWED-116 nonetheless ruled substantively on this test. The line that reconciles them: **an act that changes what §6.2 means comes to this seat; an act that applies §6.2 to particular spans is D-1.** Adding a span property to the pre-registered enumeration is the first kind. Tagging L1551 is the second. This seat therefore rules scope, disclosure and conditionality; adoption is the steward's under D-1, and is taken in the same sitting.
|
||
|
||
2. ⚠ A NARROWING OF §6.2 IS ALREADY IN FORCE, UNAMENDED, AND BY THE LINE AT POINT 1 IT WAS MIS-ROUTED. `corpus/v2-stratum-tags.yaml` opens with a recorded D-1 decision — 'CELL-CONSTANT MARKERS DO NOT STRATIFY' — under which cross-lingual claim-span and archaic register (F7), both named in §6.2's stratum-B enumeration, do not earn B in the fr/de cells. Removing two markers' effect changes what §6.2 means; it is the first kind of act, not the second, and it belonged here. It is also a post-hoc change to stratum-B membership, derived after seeing the cell, entering by reading rather than by disclosed amendment: the act REVIEWED-116 point 1 ruled impermissible for this item, in the opposite direction. **What is undecided is the remedy, not the routing** — filed as PENDING-137, to be ruled in this sitting for the reason at point 9. Its author surfaced it, named it a §6.2 reading and invited overruling, which is why it is correctable rather than a breach; and nothing here suggests the reading itself is wrong.
|
||
|
||
3. H1(a) — THE COUNTER-ARGUMENT IS RECORDED AT CORRECTED STRENGTH, AND IT IS HEAVIER THAN THE ITEM STATES. PENDING-134 and the package record two admission routes to stratum B with F10 holding the second alone. Read against the full §5 table, **three rows carry an explicit stratum-B admission clause** — F3 ('stratum-B hard-grounded gold drawn from aphorisms'), F7 ('stratum-B gold deliberately drawn from the oldest-register passages') and F10 ('included in stratum-B EN/FR gold'). F10 is the only mode whose *sole* route to stratum B is that clause. So the construction was used three times in ten rows, and the design named stratum B in the 'Exercised by' cell for every mode carrying a stratum-B gold role. F4's cell instead routes it to negatives. **Heard, at that strength, and overruled** — for the reason at point 5, not by discounting it. H1(a) is satisfied by this paragraph rather than by remand, and the package is corrected at its own IV.1 before this entry's citation of it is placed.
|
||
|
||
4. ⚠ THE CORRECTION EVENT, RECORDED BECAUSE IT OUTLASTS THE NUMBER. The package's IV.1 marks the false claim 'verified verbatim 2026-08-14 against I.1 and I.2' — and I.2 quotes F3 and F7 with their stratum-B clauses intact, while IV.2's own table one page later reproduces both cells as 'stratum-B gold'. A check reported a pass against text containing its own counterexample, and two instruments inside one document disagreed about the same count. This is the third instance of the PENDING-136 denominator class in this arc, and the second is in the same package: Q2 states the stricter rule's cost as 'measured and small: one span' on the **inherited-gold** population, while the rule it prices is a prospective authoring constraint whose cost the package's own III.3 sizes at 73 long quoted spans in Mauss alone and a 532-span corpus floor. Logged as evidence under PENDING-89.
|
||
|
||
5. Q2 AND Q4 — ADOPT THE NARROW TEST, CONDITIONED, AND THE HALVES ARE NOT ALIKE. Corrected costing decides Q2 for adoption: a blanket exclusion of F4-marked spans from stratum B forecloses an authoring route across a corpus where reported speech is pervasive, at an unmeasured cost, to save a stratum the inherited gold has already vacated. On Q4, the executor's lean is drawn from the scope H2 forbids — stance failures carry no structural mark, but stance failures are the *general* form, and what is ratified is the nested-voice case, which is §7.4(i)'s own territory. The proposal survives on a different ground: the doctrine and the fence run in opposite directions, so neither can substitute for the other. Split accordingly:
|
||
- **the admissible half** does independent work at the gold-composition layer and does *more* work once the fence exists, since line-granularity fencing of a span like L1551 would enclose the host's attributing clause and his conclusion and refuse even a legitimate host-proposition claim. It is a complement to PENDING-131 (c), not a substitute;
|
||
- **the refusable half** overlaps §7.4(i) at a lower layer, and with it apparently working the case for building the unbuilt fence quietly weakens. **It does NOT discharge §7.4(i).** Adoption is therefore conditional on PENDING-131 (c) remaining sought and undiminished.
|
||
|
||
6. Q3 — H2's NARROWING IS AFFIRMED, AND IT IS WHAT MAKES POINT 5 BITE. The general principle — a marker names a span property while the claim's treatment fixes the disposition — reaches F3, F5, F7, F8 and F10, all pre-registered in §6.2, and nobody has worked out what it does to any of them. Recorded as the ARGUMENT for the nested-voice case, never as ratified doctrine.
|
||
|
||
7. Q5 AND Q6 — ONE MECHANISM CARRIES BOTH, AND THE DEFEATER IS REORDERED BECAUSE THE SECOND READER DOES NOT EXIST. 'Two independent readers' was written as though one did; the steward is and has been the sole reader on this corpus, and the executor cannot serve as reader two, having produced the doctrine. Independence of *persons* is therefore replaced by independence of *order*, which is the stronger instrument in any case — two readers who both know the doctrine can both be led by it; a disposition recorded before the doctrine is consulted cannot be. Both the H3 disclosure and the defeater land as declared fields in `corpus/v2-stratum-tags.yaml`, read by whatever reports recall, so neither travels with anyone's memory:
|
||
```yaml
|
||
stratum_amended_post_hoc: true
|
||
reader_disposition_pre_doctrine: host # host | nested | unclear — recorded BEFORE the test is applied
|
||
```
|
||
**The defeater, as ratified:** *the whose-proposition test is defeated by a span on which the reader's disposition, recorded before the doctrine is consulted, is reversed by the doctrine's verdict — and survives re-reading.*
|
||
|
||
8. ⚠ THE SINGLE-READER CONDITION IS A STANDING PROPERTY OF THIS CELL, NOT A GAP IN THIS ITEM. Every 'verified by reading' claim on the fr/en cells rests on one reader. This weakens the defeater and it weakens Part III's identification pass, which no key serves and which remains the executor's testimony corroborated by reading rather than by an instrument. Recorded once, at this level, so it is not rediscovered item by item — and so that 'defeater: satisfied' is never read as more than it is.
|
||
|
||
9. H3 — THE DISCLOSURE, AND THE BEFORE-STATE IS NOT THE RATIFIED TEXT. §6.2's resulting state is **(i) a pre-registration carrying dated amendments**, per the steward's lean. What it said before is §6.2 *as operated on the fr cell*, which already carries the point-2 narrowing; a disclosure recording only the 2026-07-09 text would be incomplete in the way H3 exists to prevent. The amendment adds `reported-speech span (F4)`, admissible under the test below, dated to this entry, and **made after the spans it reclassifies had been read** — derived 2026-08-10 from L926 and L1551, scoped 2026-08-13 across all nine grounded spans.
|
||
|
||
**THE DOCTRINE, RATIFIED (narrow — the nested-voice case only):**
|
||
|
||
> **The whose-proposition test.** A claim grounded in a span containing reported speech is **admissible** when it asserts the **host author's** proposition — the reported words serving as evidence inside the host's own argument — and **refusable** when it asserts the **nested voice's** proposition as the host's own. Reported speech is therefore a stratum-B span property for the fr/en Tier-2 gold, not a disqualifying structural mark; the disposition is fixed by the claim, not by the span. The refusable half does not satisfy §7.4(i), whose provenance join remains owed.
|
||
|
||
**If AUTHORIZED:** the doctrine paragraph, point 7's defeater and point 9's disclosure are placed. `corpus/v2-stratum-tags.yaml` gains the two declared fields; no span is re-dispositioned by this entry — L926 (retracted, REVIEWED-118) and L1551 (reclassified, REVIEWED-119) are unchanged, and the immediate corpus effect is nil. The §5 F4 row is NOT amended, and point 3's cheap structural check is thereby lost: an F4 mark becomes compatible with both gold and negative, and a reader must consult the claim to know which. That is the price, stated here rather than left to be discovered. `ratio_A_to_B` stays **VOID** and is re-derived ONCE after **both** this entry and PENDING-137 land and all dispositions are recorded (REVIEWED-116 point 5). The fused-voice sub-type name (`negative_sub_type_OPEN`, REVIEWED-119 point 3) and the gold-schema question (REVIEWED-119 point 4) remain open and are decided by neither entry. `voice_stamp` remains unwired. No live instance exercises this doctrine at ratification; it is untested-in-force, and its first genuine exercise is the first newly-authored fr/en pair with reported speech. Tag follow-on commits REVIEWED-121.
|
||
|
||
## REVIEWED-121 — AMENDMENT 1 (2026-08-14): the defeater is declared and permanently empty on the inherited set
|
||
**Date:** 2026-08-14
|
||
**Amends:** REVIEWED-121 (PENDING-134), points 7 and 8 and the closing paragraph. Recorded as an amendment sitting alongside the original, not an
|
||
edit to it: REVIEWED-121 is placed and executed, and no silent revision.
|
||
**Raised by:** the executor, during execution, unprompted by any ruling. The finding was not anticipated by PENDING-134, by the jurist package, or
|
||
by this seat.
|
||
**Decision:** The executor's disposition is UPHELD. `defeater_has_ever_been_exercisable: false` stands as written and is the correct shape. One
|
||
further field is required (A3). The ratified doctrine is unchanged; no span is re-dispositioned; PENDING-134 is not re-opened.
|
||
|
||
**What was found.** Point 7 replaced reader-independence with order-independence: a disposition recorded *before* the doctrine is consulted. For
|
||
all eleven inherited spans that moment is past and unrecoverable. Back-filling the field from a reading taken now would place a post-doctrine
|
||
judgment in a field whose entire evidential value is that it precedes one — self-confirming, and the doctrine would have been ratified holding a
|
||
defeater built from itself. The executor declined to populate and recorded the absence instead. That refusal is upheld: recording an honest empty
|
||
is the discipline, and the distinction it preserves — *never exercisable* is not *not yet defeated* — is the substance of the finding.
|
||
|
||
**A1 — THE DEFECT IS IN POINT 7 AND IT IS THIS SEAT'S.** Point 7 asserts that order-independence is 'the stronger instrument in any case'. That
|
||
claim was unpriced in one respect. Personnel-independence is **retroactively** applicable: a second reader, had one existed, could have read spans
|
||
already dispositioned. Order-independence is **prospective only**. The substitution was therefore not a strict gain — it traded an unavailable
|
||
instrument for one that is unexercisable on everything that currently exists. Point 7's parenthetical stands as to contamination (two readers who
|
||
both know the doctrine can both be led by it); it does not stand as an unqualified comparison, and is corrected here.
|
||
|
||
**A2 — 'UNTESTED-IN-FORCE' IS RESTATED AS UNTESTABLE, AND H1(b) IS SATISFIED PROSPECTIVELY ONLY.** REVIEWED-121's closing paragraph records the
|
||
doctrine as 'untested-in-force'. *Untested* implies testable-and-untested. On the inherited set the doctrine has **no defeater at all** — not a
|
||
weak one, none — and cannot acquire one. The accurate statement: **the whose-proposition test is untestable on the entire inherited fr/en set,
|
||
permanently, and its defeater is exercisable only by newly-authored pairs.** H1(b)'s requirement that an AUTHORIZED doctrine state what would
|
||
falsify it is met prospectively and not otherwise. This sharpens point 8 rather than replacing it: the single-reader condition is standing, and
|
||
this is its first priced consequence.
|
||
|
||
**A3 — ⚠ REQUIRED: THE LATCH WILL OTHERWISE DISCHARGE A DISCLOSURE IT DOES NOT COVER.** `defeater_has_ever_been_exercisable` is a monotone latch,
|
||
which is right as far as it goes. But when the first newly-authored pair records a pre-doctrine disposition, the latch flips to `true` — and
|
||
thereafter any recall figure pooled over the fr cell carries `true` while the inherited spans still carry no pre-doctrine disposition and never
|
||
can. One pair from outside the inherited set would silently discharge a disclosure covering eleven spans it has nothing to do with. That is the
|
||
PENDING-136 denominator class — a fact true of one population read as true of another — and this instance would be **built into the mechanism**
|
||
rather than committed in prose. Fourth occurrence in this arc; the first that would be structural. Required alongside the latch, in
|
||
`corpus/v2-stratum-tags.yaml`:
|
||
|
||
```yaml
|
||
defeater_has_ever_been_exercisable: false
|
||
defeater_dispositions_recorded: 0
|
||
defeater_population: <cell + the criterion the count is taken over>
|
||
```
|
||
|
||
defeater_population is named, not assumed — this entry deliberately does not fix a number, because choosing the denominator from a point-in-time
|
||
read is the error the field exists to prevent. Binding rule: the latch may not be read without the count and the population in the same read. A
|
||
report may carry all three or none.
|
||
|
||
A4 — ⚠ THE GROUND THE REFUSAL RESTED ON WAS CITED BY A NAME WITH NO REFERENT, AND THIS PARAGRAPH REPLACES THE DRAFT THAT MERELY CALLED IT
|
||
UNCITABLE. The refusal to back-fill was grounded in test_legacy_indices_are_not_self_verified, and the executor carried that name into
|
||
corpus/v2-stratum-tags.yaml, commit 5425414's message and a steward report. No such function exists. This seat searched all 273 items in
|
||
PENDING.md, PENDING-archive.md and REVIEWED.md for self-verified, found nothing, ran a positive control on defeater returning REVIEWED-121 and
|
||
PENDING-134 as expected, and concluded the test was reachable only from the executor's side. It was reachable from neither: the name occurs once in
|
||
the entire repository, in a docstring at tests/test_reading_index.py:23 asserting that it 'holds that shut' — a label whose referent nobody had
|
||
opened. Fourth instance of cited-a-derived-label-instead-of-the-substrate, the class that let three documents protect a 0-byte fixture for seven
|
||
weeks. The reasoning is unaffected and the property IS tested, by checks citable by their own text: tests/test_reading_index.py L128 ('NO legacy
|
||
region is "verified by fingerprint" — none stores one'), L130 ('a region with no stored fingerprint and no name test is UNVERIFIED'), and the
|
||
synthetic positive control at L281 ('a stored hash that DOES match yields verified by fingerprint') — without which L128's pass could be vacuous,
|
||
which is precisely why a bare name was never sufficient ground. Corrected in the substrate at 966168b.
|
||
|
||
What does not change. The doctrine paragraph as ratified. Point 9's H3 disclosure. The conditionality on PENDING-131 (c) at point 5. No span is
|
||
re-dispositioned — L926 and L1551 stand as at REVIEWED-118 and REVIEWED-119. ratio_A_to_B remains VOID, still awaiting PENDING-137 and all
|
||
dispositions (REVIEWED-116 point 5). Tag follow-on commits REVIEWED-121-A1.
|
||
|
||
## REVIEWED-122 — PENDING-142 — The open/closed criterion answers a question adjacent to the one it is asked
|
||
**Date:** 2026-08-17
|
||
**Decision:** AUTHORIZED — option (d) as the frame, with (a) and (b) inside it, on five conditions. Two legs severed and dispositioned separately below.
|
||
|
||
**Notes:** The item's own recommendation is adopted as written, and the reasoning behind it survives challenge: (a) and (b) each close a class, and neither can close Class A, which is unclosable by construction rather than by defect. Only (d) lets the instrument report the case it cannot decide. Constitutional Constraint #4 requires a system to report its own limits; an instrument whose subject is governance state is the last place that requirement may be relaxed.
|
||
|
||
1. CONDITION — **the acceptance check is a pre-registration, and its ordering is load-bearing.** The item warns that the acceptance check may not be a count. That is raised from warning to requirement, with an ordering the item does not specify: the per-item disposition answer key over all 69 filtered items is **hand-read and committed before the implementation exists**, with the commit hash recorded. A key written after the fix inherits the fix's reading of what closure means, and would pass by construction. This is the pre-registration discipline already operating in the Fool trials, applied to an instrument rather than a model. If the key and the implementation disagree on any item, the disagreement is the finding and is reported — never reconciled by amending the key.
|
||
|
||
2. CONDITION — **(b) defaults to not-closed on any unrecognized decision verb, and the enumeration is not the executor's alone.** The item names this trap and must not walk into it: an unlisted verb yields UNDETERMINED, never CLOSED. The list of closing verbs is drafted by the executor and ruled here before it is wired, because the enumeration decides what the instrument can see and is therefore a gate-design claim, not an implementation detail.
|
||
|
||
3. CONDITION — **(a) resolves by title only on a unique match, and every title-resolution is visible in the output.** Where normalized-title matching supplies a closure the id-match could not, the digest marks it as title-resolved rather than reporting it indistinguishably from an id-matched closure. Two or more candidates yields UNDETERMINED. The risk the item names — joining two genuinely distinct items sharing a title — is not eliminated by this, only made legible.
|
||
|
||
4. CONDITION — **UNDETERMINED is enumerated, never merely counted.** Every item in that bucket is listed by id and header with the reason it could not be decided. A three-valued report whose third value is an opaque number replaces a wrong answer with an unreadable one, which is the same failure in a better costume.
|
||
|
||
5. CONDITION — **the reader is fixed; the placed records are not silently amended.** REVIEWED-78, -81 and -82 are placed rulings and are not to be edited to satisfy the current parser. Fixing the record to please the instrument inverts which of the two is authoritative. Should the steward decide the headers are worth normalizing, each amendment carries a dated note stating what was changed and why, per no-silent-revision — but that is a separate steward act and is not authorized here.
|
||
|
||
6. **The docstring correction is severed and authorized now as [FIX], not gated on the mechanism.** `ruled_pendings`'s docstring records REVIEWED-78/-81/-82 as 'like-numbered rulings … concerning other matters'; REVIEWED-78's own Notes say they were like-numbered *on purpose*, to satisfy the closure rule as it then stood. The docstring is a substrate-contradicted claim and its falsity does not depend on which option is built. Two requirements on the correction: it records the true history rather than merely deleting the false sentence, and the executor checks whether anything else in the script relies on the discarded reading. Removing a claim is not the same as removing the reliance on it.
|
||
|
||
7. **Class C is a live correctness problem and is dispositioned ahead of the mechanism.** PENDING-121 is certain — REVIEWED-110 reads 'DESIGN GATE PASSED WITH CONDITIONS (1-4), then HELD OPEN', an item held open by its own ruling and hidden by the tool — and it is restored to the open list by hand at once, not when the fix lands. PENDING-124 and -128 are flagged UNDETERMINED pending a steward read; the item's refusal to assert their status is correct and is preserved rather than resolved here. That a design gate could read as closed is the dangerous direction of this defect: it means the taxonomy's distinction between passing a gate and receiving authorization was invisible in the instrument that reports what awaits authorization.
|
||
|
||
8. **Class A is a steward matter, and its consequence outlives the fix.** Three-valued reporting makes the two unclosable items honest; it does not make them closable. Renumbering their headers touches `PENDING.md` and is the steward's act, not the executor's. Recorded because it survives whatever is built: **`PENDING — ICP-19 Remit Expansion (Observer Problem)` will report open whether or not the steward–reviewer conversation it gates has taken place.** Its persistence in the open list is not evidence about the state of that conversation, and has not been since the item was written. The Observer Problem gate's status is steward testimony and reachable no other way.
|
||
|
||
9. …**The family is raised to a named ladder entry rather than a running count.** ⚠ AMENDED 2026-08-17, before execution, on the executor's surfacing of PENDING-141: the ladder's contents are a variable in a live pre-registered trial that cannot be re-run, and this condition would change the measured object. **The ladder entry is DEFERRED until that trial is graded at 84 transcripts, or until PENDING-141 is ruled otherwise.** The condition is not withdrawn — the family is real and the entry is owed. Two parts of condition 9 are severed: the lineage addition to this item's kin list touches PENDING-142 and not the ladder, and proceeds now; only the ladder entry waits. Recorded here rather than dropped, because a deferred entry with no record is how the family came to be rediscovered five times as a fresh coincidence.
|
||
|
||
10. **Scope of this ruling, stated rather than assumed.** I read PENDING-142 verbatim via `governance_item`, and independently observed `governance_state()` reporting PENDING-81 open against an AUTHORIZED REVIEWED-81 — one datum consistent with Class B, obtained from the instrument under review. Everything else — the census figures, the class memberships, the 39 stale `Awaiting:` lines, the docstring's wording — is executor testimony from a script I cannot run. That is precisely why condition 1 requires a hand-read key: the ruling cannot verify the census, and the acceptance check is the only instrument that can.
|
||
|
||
11. **A follow-on item is owed and is not folded in.** The drift-check covers `~/CLAUDE.md` and reads no script. The docstring at condition 6 was a substrate-contradicted claim living outside anything that checks for them, inside the instrument that reports governance state. Whether script-resident claims warrant coverage is a [HARDENING] question larger than this item and is to be filed separately rather than absorbed here.
|
||
|
||
**If AUTHORIZED:** Draft and commit the hand-read answer key first, with its hash recorded. Submit the (b) decision-verb enumeration for ruling before wiring. Then implement (d) with (a) and (b) inside it, per conditions 2–5. Apply the condition-6 docstring [FIX] independently and immediately; restore PENDING-121 by hand on the same pass. Tag commits with REVIEWED-122. Report the key-versus-implementation comparison in full, including agreements, rather than reporting only the delta.
|
||
|
||
## REVIEWED-123 — PENDING-141 — Ladder contents are a variable in a live trial, and the freeze needs a scope the item does not give it
|
||
**Date:** 2026-08-17
|
||
**Decision:** AUTHORIZED — option (a), HOLD, on six conditions. (b), (c) and (d) declined, with reasons recorded.
|
||
|
||
**Notes:** The item's core reasoning survives challenge and is strengthened by an argument it does not make. Its own honest caveat — that per-entry reach as a function of ladder length is untested on *both* sides — reads as a weakness and is not one. Consider the payoff either way. If ladder size does not affect retrieval, holding costs four weeks' delay on rows the item correctly says are not decaying. If it does, appending destroys the only instrument standing behind REVIEWED-95's causal claim, and that instrument cannot be re-run. An un-rerunnable measurement against a delay on non-decaying rows is not a close call, and it does not require the untested assumption to be resolved in either direction. **(a) is correct under both branches**, which is a stronger warrant than the item claims for itself.
|
||
|
||
1. CONDITION — **the freeze is general, not S2-specific, and covers contents as well as size.** The item is titled and argued around the 41 S2 rows, but a single entry from an unrelated ruling was caught by it within hours of filing, correctly. The scope is hereby stated rather than left to inference: **no additions, rewordings, removals or reorderings of `reference-verification-ladder.md` while this hold is in force**, from any source, whatever its authorization. The `/wake-up` skill already froze its own trial line for this reason; the ladder is frozen on the same footing and for the same trial.
|
||
|
||
2. CONDITION — **report N-now, and bound the hold.** 'Until graded at 84 transcripts' is not a date, and a hold with no expiry and no visible distance to expiry is how a temporary freeze becomes a permanent one. The executor reports the current transcript count at the next wake, and this item carries a **review point at 30 days** — not an automatic lift, a requirement to state where the count stands and whether the trial is still tracking. If N-now proves near 84, the steward may elect (b) on that fact; that election is not made here, because the fact is not in the record.
|
||
|
||
3. CONDITION — **entries earned during the freeze accumulate in this item as an owed-entries list.** A freeze without a queue is a silent loss, and the wrong-subject family now under REVIEWED-122 is already the standing example of what recurs unrecognised. They are queued **here** rather than in a new file: a separate holding document is one a reader might reach *instead of* the ladder, which is the same uncontrolled variable one layer along. Each queued entry names its authorizing ruling so the freeze lift is mechanical.
|
||
|
||
4. CONDITION — **grading does not authorize the append.** The item's second-order risk — that a tripled ladder may be a *worse* ladder, degrading per-entry reach even as the wake line raises the odds of opening the file — is real and is not resolved by grading the trial. On grading, the S2 batch **returns for a ruling**, not for execution, and that ruling addresses per-entry reach as its own question. Read as 'hold then append', (a) merely moves the problem four weeks and arrives with the same measurement still unmade.
|
||
|
||
5. CONDITION — **the `MEMORY.md` amendment is retired when the hold is.** The index line was amended at filing to remove the execute-now reading, which was correct. A hold-notice that outlives its hold is the same trap in the opposite direction — a later session reading 'held pending trial' for a trial graded months earlier. Retiring it is part of the freeze lift, not a follow-on.
|
||
|
||
6. ⚠ **A standing limit on what this trial can conclude, named because it is not fixable and must not be discovered at grading.** The party whose retrieval is being measured has read the pre-registration, the item, and this ruling. The trial therefore measures whether an executor *who knows the trial exists* reaches the ladder after a wake line is added — which is not the same claim as REVIEWED-95's. This does not weaken the case for protecting the instrument: a bounded measurement is worth more than a destroyed one. It bounds the **conclusion drawn at grading**, and the grading write-up states it rather than inferring a clean causal result. This is the observer condition at instrument scale and no design available here escapes it.
|
||
|
||
7. **Options declined.** **(c)** is the tempting one and the item's own objection holds: a recorded confound on a design of this power is close to no result, and would leave REVIEWED-95's causal claim appearing to rest on a graded trial while resting on nothing — worse than an ungraded claim, because it launders the gap. **(d)** is illusory for the reason given; the wake line names the ladder as a whole, so no subset of additions leaves the reader's encounter unchanged. **(b)** is not rejected on the merits but on the record: it trades power for speed and nobody has stated how much power there is to trade. Condition 2 makes that fact available; the option is revisitable on it, which is why this is a decline and not a rejection.
|
||
|
||
8. **Scope of this ruling.** I read PENDING-141 verbatim via `governance_item`. The trial's design, the 14%/77%/83%/0% retrieval figures, the 64-session base and the transcript count are executor testimony from instruments I cannot run. The ruling does not depend on their precise values — it depends on the asymmetry in Notes above, which holds across a wide range of them. Where it would depend on them is condition 2's election of (b), which is deferred until the count is in the record.
|
||
|
||
**If AUTHORIZED:** (a) is already the null action and remains in force; nothing needs doing to start it. Report N-now at the next wake. Open the owed-entries list on this item and queue the wrong-subject ladder entry deferred under REVIEWED-122 condition 9 as its first row. Set the 30-day review. Tag nothing — no commit follows from this ruling except the queue and the count.
|
||
|
||
## REVIEWED-124 — PENDING-148 — Trial 09's answer key is in the corpus by ratification
|
||
**Date:** 2026-08-20
|
||
**Decision:** AUTHORIZED, with four amendments to the recommendation
|
||
**Notes:**
|
||
- **Q1 — VOID, not degrade.** Trial 09 is recorded void per §1 read literally, generates no
|
||
grades, and is never cited for any. A separately named run is authorized in its place,
|
||
reusing trial 09's corpus and prompt, measuring the §1 cross-tab and MODERATE only, with
|
||
STRONG out of scope by construction. The rename is the point: 'degrade' leaves a citable
|
||
'trial 09 returned zero STRONG' behind it.
|
||
- **Q2 — IV.c confirmed; surgery narrower than proposed.** Step 1 keeps duplicate-stripping
|
||
(mechanical) and the jurist-flag (defined 'by direct textual match only'). Only the
|
||
'answerable directly from the corpus' marking is dropped. ECHO and fault-line comparison
|
||
move to step 4, jurist and steward jointly, after discomfort ratings are locked. Note that
|
||
unmarked questions are §1 compliance, not just S-1 repair — a marked set leaks to the
|
||
steward what §1 requires him not to know when rating.
|
||
The executor's fuller self-removal is declined on the strength of its own disclosure.
|
||
- **Q3 — FL5 stale, reason corrected.** Constraint 6 adopts FL5's AI-pair component and
|
||
affirms the negation of its three-party component; it does not state FL5 more sharply.
|
||
Record as `NOT ESTABLISHED — target partially adopted (Constraint 6, REVIEWED-86) and
|
||
partially negated`. A question reaching the three-party form is logged verbatim as a
|
||
candidate observation, ungraded, for possible pre-registration in trial 10.
|
||
IV.b's label-vs-substance defect extends to FL5's 24 markers; all three fault lines are
|
||
open on the instrument actually run, not two.
|
||
Ground truth requires re-basing before any frontier replication.
|
||
- **Q4 — §6 unamended.** It assesses 'across trial 09 and one frontier replication'; trial 09
|
||
is void, so the criterion has no first input and does not evaluate this cycle. The
|
||
jurist's HOLD proposal of 2026-08-19 is withdrawn — superseded, not silently replaced.
|
||
- **Q5 — weighed.** Overtaken as to corpus exclusion, which is no longer claimed. Retained as
|
||
a caution on the Part II census specifically.
|
||
- **Cross-file:** result under PENDING-89 alongside PENDING-140. The Bash/verify-before-compose
|
||
gap under PENDING-95, second instance. REVIEWED-86's recorded relay provenance for the
|
||
Constraint 6 doctrine is noted as bearing on what 'independent reach' has ever meant here.
|
||
- **Not ruled, steward-only:** the constant-spine mitigation under partitioning (addendum §5);
|
||
whether the Observer Problem items close first. The jurist's view on the spine remains that
|
||
it should not be applied to this corpus.
|
||
**If AUTHORIZED:** Record trial 09 void. Pre-register the replacement run's instrument in
|
||
full before any token is generated. Tag commits REVIEWED-124. THE HOLD ON TRIAL 09 IS
|
||
PERMANENT — it does not lift; it is superseded.
|
||
|
||
## REVIEWED-125 — PENDING-149 — Buddy-pattern Fool: §8a answered, §8 measured, §5 contested
|
||
|
||
**Date:** 2026-08-22
|
||
**Ruling:** PARTIAL — see per-deliverable dispositions below.
|
||
**Does not bear on PENDING-150.** No fourth position is ratified by this ruling;
|
||
`~/CLAUDE.md` is untouched. §13.6 continues to block every run.
|
||
|
||
### §8 measurement — AUTHORIZED as evidence
|
||
4.2 events/day over 45 days, 6.2 on active days, range 1–53, sessions 1.39/day.
|
||
This is what §8's closing warning asked for and the burst finding is sound: fixed
|
||
proportions on a bursty event generator make the fool loudest on the heaviest days.
|
||
The defect is real and is a defect in the draft, not in the executor's reading.
|
||
|
||
### §8 recommendation (keep 73/20/7 + hard daily cap) — REJECTED
|
||
Two grounds.
|
||
(a) §8's tuning prohibition is a bar on *runtime* adjustment — its stated rationale
|
||
is a fool that learns from being heard or muted. It does not bar a one-time
|
||
pre-registered proportion, which §8 explicitly requests.
|
||
(b) A hard cap is the more §8-hostile mechanism: it creates an observable
|
||
'quota exhausted' state, arriving first on burst days, after which silence reads as
|
||
depletion rather than as the 73%. That defeats §8a's object.
|
||
Rejection is of the mechanism, not of the problem it addresses.
|
||
|
||
### §8 re-derivation — DEFERRED, conditions stated
|
||
Executor to return with adjusted proportions, pre-registered and hardcoded, no cap.
|
||
If the executor's answer requires the trigger key to change, that is an amendment to
|
||
§8 and is filed as such — not carried inside an §8a answer.
|
||
|
||
### §8a body/voice split — AUTHORIZED, conditional
|
||
The separation of body from voice is adopted; it is the answer §8a wanted, and it is
|
||
a fourth shape rather than a selection from the three, which §8a invited.
|
||
Conditions, both prior to build:
|
||
1. Verify whether `statusLine` is already configured in `~/.claude/settings.json`,
|
||
and what it carries. Flagged unchecked at filing; the option's cost and its one
|
||
risk both turn on it.
|
||
2. The body must RENDER silence, not merely occupy a line. A static name is a label
|
||
and goes furniture-blind; §3 bars sprites and animation frames, so whatever
|
||
changes must be derived from time or from nothing. Never from content — content
|
||
derivation makes the body gradeable and §2 forbids it.
|
||
|
||
### §5 — five axes stand; PROCEDURE not adopted
|
||
Not adopted on §5's own criterion: an axis is real only if a dump on it is imaginable
|
||
as costing the steward something. If procedural failures are already caught by
|
||
existing instruments, blindness there is free. The executor's second reading is
|
||
correct. §5 remains awaiting steward ratification, which is upstream of the bones and
|
||
is not a jurist matter.
|
||
|
||
### `input-dependence-01-PREREGISTRATION.md` — DEFERRED, explicitly not parked
|
||
Held at the gate. Reconsidered when §12's swappable-generator clause becomes live
|
||
work; it is the nearest existing instrument for reading divergence between two
|
||
formations. Disposal by omission is refused.
|
||
|
||
### PENDING-89 evidence, source (iv) — AUTHORIZED to read
|
||
`~/_Dev/animal-davidglidden-eu/chamber-sessions-private/` (55 files). Flagged
|
||
2026-08-01, never opened. It answers generation diversity, not correlation of misses,
|
||
and must not be reported as the latter. The executor's statement that the buddy fool
|
||
contributes zero to PENDING-89 by construction is accepted as a design property.
|
||
|
||
### Scope note
|
||
The jurist could not read the filed draft via `governance_read`; the text ruled on was
|
||
supplied by the steward in-session. The filed sha256 `9aceed7f…` is unverified from
|
||
this side.
|
||
|
||
## REVIEWED-125 — AMENDMENT 1 (2026-08-22): drafted before v2; dispositions reconciled against it
|
||
|
||
**Date:** 2026-08-22
|
||
**Status:** Joins REVIEWED-125. Does not replace it. The original ruling stands as
|
||
the record of what was decided on the text available at the time.
|
||
**Scope:** REVIEWED-125 was drafted before the jurist's v2 draft arrived. v2 governs
|
||
where it and v1 differ. This amendment states, disposition by disposition, which parts
|
||
of REVIEWED-125 are discharged, which converge with v2, which conflict, and which
|
||
survive v2 unmet. **Nothing here bears on PENDING-150. `~/CLAUDE.md` is untouched.**
|
||
|
||
### DISCHARGED — no longer open
|
||
|
||
**§8a condition 1 — verify `statusLine`.** Discharged 2026-08-22. `statusLine` is NOT
|
||
SET in `~/.claude/settings.json`, NOT SET in `~/.claude/settings.local.json`, and
|
||
`~/dotfiles/claude/settings.json` does not exist. The surface is free; nothing is
|
||
displaced and no accommodation is required. The option's cost and its one named risk
|
||
both resolve favourably.
|
||
|
||
**§5 ratification.** REVIEWED-125 recorded the five axes as awaiting steward
|
||
ratification. The steward has since ratified them, and directed that the ratification
|
||
be recorded explicitly rather than rest on v2's §5 heading. It is recorded at
|
||
`claude/governance/fool/seed/FOOL-SEED-RULE.md` §1, with the axis order fixed, since
|
||
the derivation permutes over that order.
|
||
|
||
### CONVERGED — REVIEWED-125 and v2 reached the same result independently
|
||
|
||
**§8's hard daily cap is rejected, on two distinct grounds.** REVIEWED-125 rejects it
|
||
because a cap creates an observable *quota exhausted* state that arrives first on burst
|
||
days, after which silence reads as depletion rather than as the 73% — defeating §8a's
|
||
object. v2 §8 rejects it because a cap introduces a *budget-spent* state, which is
|
||
memory, and memory is the beginning of learnability. **Both are correct and neither
|
||
depends on the other.** The rejection is of the mechanism, not of the burst problem it
|
||
addressed, which remains real.
|
||
|
||
### CONFLICT 1 — `input-dependence-01-PREREGISTRATION.md`: RESOLVED, taking one half from each
|
||
|
||
REVIEWED-125: *"DEFERRED, explicitly not parked. Held at the gate. Disposal by omission
|
||
is refused."* v2 §15a: *"PARKED, with a forward pointer… it is parked here by name…
|
||
not held live for §12."*
|
||
|
||
**Ruled: the instrument is HELD AT THE GATE — not parked.** REVIEWED-125's status
|
||
governs; v2 is a draft and says of itself that nothing in it is a ruling. The
|
||
instrument is twice-amended on steward authorization and sits at a jurist gate, and an
|
||
artifact in that state is not disposed of by a draft's side note.
|
||
|
||
**But v2's substantive warning is adopted and is the stronger half:** if §12's
|
||
swappable-generator work becomes live, the instrument is **re-derived against the new
|
||
object, not resumed.** Reusing an instrument built for a different object is precisely
|
||
what produced trial 09, and a forward pointer that invites resumption reproduces it.
|
||
|
||
Operative form: **held at the gate; findable; if revived, re-derived not resumed.**
|
||
|
||
### CONFLICT 2 — §8a's body: REVIEWED-125 condition 2 GOVERNS over v2 §8a
|
||
|
||
REVIEWED-125 cond. 2: *"The body must RENDER silence, not merely occupy a line. A
|
||
static name is a label and goes furniture-blind; §3 bars sprites and animation frames,
|
||
so whatever changes must be derived from time or from nothing. Never from content."*
|
||
v2 §8a: *"Body = the status line. Rendered every turn, carrying the name and nothing
|
||
else."*
|
||
|
||
**v2 specifies exactly the static label REVIEWED-125 rules insufficient, and
|
||
REVIEWED-125 is right.** A fixed string stops being seen within days; at that point
|
||
silence is not rendered but merely absent, which is the *interjection-only* failure
|
||
arriving by another route — the failure the body/voice split exists to avoid.
|
||
|
||
**Ruled: condition 2 stands and binds the build.** Whatever varies must derive from
|
||
time or from nothing, never from content — content derivation makes the body gradeable
|
||
and §2 forbids it. §3's bar on sprites and animation frames is unaffected. Not blocking
|
||
the beacon; binding before any status-line implementation.
|
||
|
||
### SURVIVES v2 AND IS STILL OWED
|
||
|
||
**§8's adjusted proportions.** REVIEWED-125 deferred the re-derivation with the
|
||
condition that the executor return with proportions **pre-registered and hardcoded, no
|
||
cap**. v2 §8 re-keys the generator to three tiers (body every turn · mumble time-ticked
|
||
· voice at seams) but specifies the mumble only as *"low, fixed"* — **no number.** The
|
||
deliverable is therefore live and unmet, and rides with the mumble-hook answer after
|
||
the beacon.
|
||
|
||
Noted: REVIEWED-125 required that a change of trigger key be filed as an §8 amendment
|
||
rather than carried inside an §8a answer. v2 changed the key itself, event-keyed to
|
||
time-ticked, by the jurist's own hand. The instruction is satisfied as to form; the
|
||
executor is put on notice that it applies to any further re-keying it proposes.
|
||
|
||
**PENDING-89 source (iv).** The authorization to read
|
||
`~/_Dev/animal-davidglidden-eu/chamber-sessions-private/` (55 files) stands unchanged.
|
||
It answers whether two-formation divergence is substantive or stylistic; **it does not
|
||
answer correlation of misses and may not be reported as doing so.** The executor's
|
||
statement that the buddy fool contributes zero to PENDING-89 by construction is
|
||
accepted as a design property, and is to be written into PENDING-89 explicitly so the
|
||
fool is never later mistaken for its evidence.
|
||
|
||
### THE BLOCK ON THE BEACON RUN
|
||
|
||
REVIEWED-125 records that *"§13.6 continues to block every run."* That block's stated
|
||
condition is steward ratification of §5, which has since been given.
|
||
|
||
**Ruled: the block is lifted and the derivation is AUTHORIZED to run once, at the
|
||
beacon pulse of 2026-08-25T12:00:00Z (epoch-ms 1787659200000), against the rule filed
|
||
at `claude/governance/fool/seed/FOOL-SEED-RULE.md`.**
|
||
|
||
Conditions, all already filed and pushed: axes ratified; seed rule filed with both
|
||
components; retirement and regeneration criteria filed; derivation implemented and
|
||
self-tested. **The executor runs it ONCE.** On any failure — bug, crash, wrong pulse,
|
||
unavailable pulse beyond the 24-hour retry — it STOPS and reports. It does not retry on
|
||
its own authority. The `outputValue` is passed to the derivation exactly as served,
|
||
never normalized by any wrapper or hand edit before it reaches the single normalization
|
||
point in the code.
|
||
|
||
### SCOPE NOTE — carried forward, and it is structural
|
||
|
||
REVIEWED-125 records that the jurist could not read the filed draft via
|
||
`governance_read` and ruled on text supplied by the steward in-session, leaving the
|
||
filed sha256 `9aceed7f…` unverified from the jurist's side. **The ruling's subject was
|
||
therefore the pasted text, not the filed artifact.**
|
||
|
||
In this instance they match: when a duplicate paste arrived, the executor diffed the
|
||
received body against the filed copy and both hashed `72af4115…`, byte-identical. That
|
||
check was available only because the executor happened to run it, and it is not
|
||
available to the jurist at all.
|
||
|
||
**This is PENDING-82 and PENDING-86 recurring, now inside a ruling rather than beside
|
||
one.** Recorded here rather than left in a scope note, because a ruling whose subject
|
||
may differ from the filed record is a defect class, not an inconvenience. No remedy is
|
||
ruled here; it belongs to PENDING-82.
|
||
|
||
### Filing note
|
||
|
||
REVIEWED-125's original entry is unaltered and remains above this amendment. Amending
|
||
by replacement is the defect the register-integrity check exists to catch, earned when
|
||
REVIEWED-87's original entry was overwritten by its own amendment and nothing detected
|
||
it.
|
||
|
||
## REVIEWED-126 — PENDING-155 — A daybook append surface for the jurist
|
||
**Date:** 2026-08-24
|
||
**Decision:** AUTHORIZED to build; DEFERRED on installation, on three conditions.
|
||
**Ruled by:** jurist (Claude.app), reading the item verbatim via `governance-mcp.py`.
|
||
|
||
**Opening correction, recorded by the jurist against itself.** The governance tools were
|
||
available throughout, deferred behind `tool_search` and never called; their absence was
|
||
asserted twice in one session from recall. Same class as the error PENDING-155 records
|
||
the executor making about the jurist ("Claude.app has no filesystem access") in the same
|
||
week, mirror-imaged: a negative claim with no positive control, from the party whose Q2
|
||
doctrine forbids exactly that. **Cross-filed to PENDING-89 as a same-direction miss
|
||
(docket entry 2026-08-24); it is evidence bearing on Q3 and cuts against the strong form
|
||
of the differently-biased-checkers doctrine.**
|
||
|
||
**On the substance.** The separate-server decision is correct and well-grounded. The
|
||
read-only invariant on `governance-mcp.py` is checkable — AST selftest with paired
|
||
controls, verified live — and a passing control is worth more than one fewer server.
|
||
Building the write path elsewhere is right.
|
||
|
||
**Condition 1 — the topology change, which is the real risk and was unexamined.** The
|
||
proposal defends the governance server's invariant thoroughly but does not ask what a
|
||
jurist -> scratch -> executor path does to the party model. Every jurist->executor
|
||
communication to date has passed through the steward, who relays; this creates a channel
|
||
that does not. A record is not an instruction, but nothing in the proposed shape prevents
|
||
a daybook entry from containing one, and the executor reads the file while folding.
|
||
Belongs in the spec, not left to discipline:
|
||
|
||
> Daybook entries are RECORD ONLY. No imperative addressed to the executor. The fold is
|
||
> mechanical; the executor does not act on entry content.
|
||
|
||
Without that, the loop has a bypass nobody authorized.
|
||
|
||
**Condition 2 — the installation gate must be declared, or it never fires.** "Hold until
|
||
the daily log has run long enough" is an undeclared criterion, filed on a day spent
|
||
establishing that an undeclared criterion is not a criterion. Name a date or a count of
|
||
consecutive days, or the caution against "the fourth abandoned attempt" becomes the
|
||
mechanism of the fourth abandoned attempt.
|
||
|
||
**Condition 3 — honest degradation on the append.** No read-back means the jurist cannot
|
||
verify its own write. `daybook_append` MUST return a positive confirmation (bytes
|
||
appended, or resulting line count), and the jurist must never report "recorded" beyond
|
||
what the tool returned. Silent failure here produces exactly the class of claim this
|
||
register exists to prevent.
|
||
|
||
**Note for the entry format, not a condition.** A jurist account of a jurist-only exchange
|
||
is one party's testimony about itself, and the pressure runs toward recording insight over
|
||
error. An entry format with a slot for insights and none for corrections will
|
||
systematically under-record the second.
|
||
|
||
**If AUTHORIZED:** build `~/dotfiles/scripts/daybook-mcp.py` with conditions 1 and 3
|
||
satisfied and a selftest carrying paired positive/negative controls. Do NOT install:
|
||
installation awaits condition 2 being named and met. `claude_desktop_config.json` merge
|
||
and app restart remain the steward's hand. |