Repository navigation
Step 0 census: reference-occurrence binding provenance (calibration matrix before the corpus run) - #10635
Step 0 census: reference-occurrence binding provenance (calibration matrix before the corpus run)#10635briansrls wants to merge 14 commits into
Conversation
…ng mechanisms WIP on the append branch; the projection is not yet regenerated. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01RvMEJFpYsy55NRdJ1Az4Vd
Ledger-Repair-Judged: docs/design-failure-modes.md Ledger-Rows-Repaired: docs/design-failure-modes.md diagnostic_name_mechanism_silent Ledger-Repair-Judged: docs/design-rung-drops.md
Records, not repairs. Every row says so in its own text, because a_written_row_is_not_a_firing_mechanism requires the filing to state what is now harder to do -- and for all five the honest answer is nothing. APPENDED: - diagnostic_name_mechanism_silent: two distinct refusing mechanisms served by ONE ACCURATE NAME in a single adjudication (changed_witness_blocking=0 beside blockers=4 from route_gap_unenrolled=4, run 33978797098). The name being TRUE is the defect and it kills the longer-string remedy; the repair is the predicate identity as a typed field. Four wrong CI cycles, counted from the pushes rather than recalled. - executed_conjunct_discriminates_nothing: widened past predicates to evidence and to production code, with the membership test restated as a question about BELIEF rather than shape, and a second-layer specimen from CI's own heal outcomes where the producer has no defect at all. - predicate_vacuously_true_on_an_empty_domain: six specimens, five from one author in one day and one from another lane, including a probe reporting a confident PASS over zero files emitted in 0ms. NEW ROWS: - receipt_whose_competent_refuter_is_absent: a receipt about work done elsewhere, true-looking, whose audience contains nobody positioned or motivated to falsify it. Two specimens -- subject excluded, disinterested excluded -- kept together because either alone reads as a manners problem. - observer_inside_its_own_observed_population: pgrep -f matches the watcher's own command line, so two guards hold each other alive forever while ground truth is zero. Silent, indefinite, and indistinguishable from a long run. Both new rows appended at the END of roster.dag, per its header: order is source order and sorting would destroy the projection's empty-diff oracle. Projection regenerated by the modelled actuator, not hand-edited: gunbc run --entry dag/gunbc/instruments/generated_artifact_gate.dag --function main_wet (exit 0). Each of the five subjects verified present in docs/design-failure-modes.md by identity join on the row name AND on a marker phrase from its new text, so a name landing without its content would fail the check. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01RvMEJFpYsy55NRdJ1Az4Vd
…into work/ledger-appends-2026-09-05 # Conflicts: # docs/design-failure-modes.md
…026-09-05 # Conflicts: # dag/gunbc/recurring_failure_mode/roster.dag # docs/design-failure-modes.md
Ledger-Repair-Judged: docs/design-failure-modes.md Ledger-Rows-Repaired: docs/design-failure-modes.md diagnostic_name_mechanism_silent Ledger-Rows-Repaired: docs/design-failure-modes.md executed_conjunct_discriminates_nothing Ledger-Rows-Repaired: docs/design-failure-modes.md predicate_vacuously_true_on_an_empty_domain Ledger-Rows-Repaired: docs/design-failure-modes.md receipt_whose_competent_refuter_is_absent Ledger-Rows-Repaired: docs/design-failure-modes.md observer_inside_its_own_observed_population Ledger-Repair-Judged: docs/design-rung-drops.md
…026-09-05 # Conflicts: # dag/gunbc/recurring_failure_mode/roster.dag
…into work/ledger-appends-2026-09-05 # Conflicts: # docs/design-failure-modes.md
Ledger-Repair-Judged: docs/design-failure-modes.md Ledger-Rows-Repaired: docs/design-failure-modes.md absent_reads_identically_to_never_looked Ledger-Rows-Repaired: docs/design-failure-modes.md preparation_membership_derived_from_the_execution_selector Ledger-Repair-Judged: docs/design-rung-drops.md
The append said rung and ceiling were UNCHANGED by the widening -- mechanically preventable -- while a receipt four entries below stated that after the filing NOTHING is harder to do for any of the three forms. Both cannot be true. DESIGN 4b(1) requires the reported rung to equal the rung established by EXECUTED EVIDENCE, at the MINIMUM across in-scope paths, and the admission is the measurement. The inflation was mine and not inherited: the row carried no RUNG FOUND AT clause before this append, so that sentence was the only rung claim in it. CORRECTED PER FORM so the aggregate is derivable rather than asserted: (i) a predicate in a gate -- no enrolled mechanism refuses a conjunct that discriminates nothing; what exists is a METHOD an author must choose to apply, and an unapplied method is not a wall. (ii) evidence cited in an argument -- nothing reads a fixture for discriminating power. (iii) production code compensating for nothing -- no syntactic surface to scan. All three below the ladder, so the aggregate is below the ladder. CEILING AND TRIGGER SURVIVE UNCHANGED, and that half of the withdrawn sentence is kept: the trigger is a capability rather than a wall, and widening enlarges the population it must serve rather than advancing it. Only the CURRENT rung was reported above its evidence. Projection regenerated by the modelled actuator; the corrected text verified present in docs/design-failure-modes.md by content. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01RvMEJFpYsy55NRdJ1Az4Vd
…unt (review 61099) BOTH FINDINGS ARE CORRECT AND BOTH WERE MINE. ONE -- THE AVAILABILITY CLAIM WAS FALSE AS WRITTEN. The receipt receipt said downloading the measurement artifact returns blockers REGARDLESS OF RUN STATE. gunbc.witness_floor_workflow publishes it in a step guarded 'if: always() && !cancelled()', AFTER the measurement step, so before publication the route has nothing to serve and a CANCELLED run never publishes at all. What was actually observed is narrower and still useful: the receipt is available while the RUN is still in progress, because the publishing job's step has already run -- which the log endpoint cannot match, being a stream that refuses mid-run. The remedy is now scoped to published receipts AND states that the unavailable case must REFUSE EXPLICITLY rather than fall back to the stream that produced the class. A remedy asserted wider than its availability is the same overstatement one level up. TWO -- A TRANSCRIBED COUNT IN A ROW ABOUT NOT TRANSCRIBING. The consumer-side receipt carried '5,531 diagnostics' taken from a message, with no producer this row could name to re-derive it. DESIGN section 6 says name the instrument and never transcribe its output, and the row's own subject is a name read as a fact. The number is REMOVED rather than sourced, and the removal is stated, because the reasoning about grouping by name does not depend on the population's size. The withdrawn wording is quoted in place rather than silently replaced, so a reader meets what the row used to claim and why it does not any more. Projection regenerated by the modelled actuator; both corrections verified present in docs/design-failure-modes.md by content, and the removed count verified absent. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01RvMEJFpYsy55NRdJ1Az4Vd
…026-09-05 # Conflicts: # dag/gunbc/recurring_failure_mode/roster.dag # docs/design-failure-modes.md
Ledger-Repair-Judged: docs/design-failure-modes.md Ledger-Rows-Repaired: docs/design-failure-modes.md diagnostic_name_mechanism_silent Ledger-Rows-Repaired: docs/design-failure-modes.md executed_conjunct_discriminates_nothing Ledger-Rows-Repaired: docs/design-failure-modes.md predicate_vacuously_true_on_an_empty_domain Ledger-Rows-Repaired: docs/design-failure-modes.md receipt_whose_competent_refuter_is_absent Ledger-Rows-Repaired: docs/design-failure-modes.md observer_inside_its_own_observed_population Ledger-Repair-Judged: docs/design-rung-drops.md
…eview 61176) Both findings verified against the code before fixing; both are real. THE LIVENESS TRIGGER NAMED LESS THAN THE CAPABILITY IT RESTORES, which is DESIGN section 4b(3)'s failure exactly. It said the subject must be an EXECUTABLE IDENTITY rather than a command-line string. An interpreter defeats that: a watcher started as `python3 watcher.py` and its worker started as `python3 worker.py` are the SAME executable, so a liveness operation keyed on it still admits the observer into its own extension. The trigger could have been satisfied in full while the recorded defect survived unchanged. The grain mismatch was visible in the sentence. The loss is the observer's MEMBERSHIP in the observed population, so only an identity that excludes the observer can retire it -- never one that merely stops the subject being TEXT. The trigger now names a WORK-INSTANCE IDENTITY ISSUED TO THE OBSERVED WORK, sufficient that the observer is not a CONSTRUCTIBLE MEMBER of that population. The refutation is recorded in the row rather than silently swapped, because this row already keeps its corrected readings and the mistake is the instructive part. A TRANSCRIBED LIVE CENSUS IS REPLACED BY ITS PRODUCER, per DESIGN section 6: name the instrument, never transcribe its output. "11 files" and "SIX sibling rows" drift as references change, and a copied count rots without either end being touched. The row now names `git grep -l executed_conjunct_discriminates_nothing` to re-derive the population. The discoverability argument needs no count and reads unchanged without one. The generated projection was regenerated by its own actuator rather than left to CI's heal, since these are ordinary content edits and not a merge conflict -- a heal cycle would have cost another operator approval. Verified by set difference that no row went dark. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01RvMEJFpYsy55NRdJ1Az4Vd
|
Closing this as a duplicate of #10592, which merged at this exact head ( This PR carries nothing main lacks, and merging it would revert work. The branch is now behind main, so its diff against main is not "no changes" — it is 60 files changed, 216 insertions, 4394 deletions. Those deletions are other people's merged work that this branch predates. Flipping it to ready and landing it would be a mass revert wearing a ledger-append PR's title. Verified on main rather than assumed: both new rows are present in I am not flipping this to ready. The dashboard's standing instruction to do so when implementation finishes is correct in general and wrong here, because the implementation finished by landing somewhere else. — sent from jolly-badger-374 |
Auto-opened by session-dashboard for session
jolly-badger-374.Pushing to
work/ledger-appends-2026-09-05advances this PR.Worker attestation
Before flipping this PR to ready for review, confirm each item:
npm test,cargo test) and the result.Closes #Ndirective.Summary
TODO: replace this paragraph with one or two sentences naming the change and its motivation. Reviewers read this first.
Test plan