Skip to content

DO NOT MERGE — discriminator: drive an authored-quotation break through the required gate - #10782

Closed
gunbai-bot[bot] wants to merge 1 commit into
mainfrom
probe/quotation-red-discriminator
Closed

gunbai-bot[bot] wants to merge 1 commit into
mainfrom
probe/quotation-red-discriminator

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Sep 7, 2026

Copy link
Copy Markdown
Contributor

⚠️ DO NOT MERGE — this is a discriminator, not work

Delete this branch and close this PR once CI reports. It exists to execute one measurement and nothing else.

What it tests

gunbc.recurring_failure_mode.authored_quotation_terminates_the_string_it_is_authored_in (landing in #10710) claims the failure is loud within the required run after #10701. Nothing had ever driven an unparseable quotation through the post-#10701 required acceptance path, so that claim was stronger than its evidence — DESIGN §4b(1) requires the reported rung equal the rung established by executed evidence on the real acceptance path.

This commit plants one receipt containing a bare double-quoted phrase inside a double-quoted string, in absorbing_fallback.dag, reproducing the defect exactly.

Controls

  • Discriminating RED, verified before pushing: the planted break refuses locally with three undefined variable diagnostics, so the probe is not inert.
  • Positive control, already executed: main and this branch's parent both run green on the same required lane, so a red here is attributable to the planted break rather than to the tree.

The two outcomes, both informative

I am not picking the comfortable one.

…equired gate

Discriminator for the rung claim in
authored_quotation_terminates_the_string_it_is_authored_in. That row asserts
the failure is LOUD WITHIN THE REQUIRED RUN after gunbc#10701; nothing had
driven an unparseable quotation through the post-#10701 required acceptance
path, so the claim was stronger than its evidence.

This commit plants one receipt containing a bare-double-quoted phrase inside
a double-quoted string, reproducing the defect exactly. It refuses locally
with three `undefined variable` diagnostics, so the probe discriminates
before it reaches CI.

The positive control is already executed and needs no commit: main and this
branch's parent both run green on the same required lane, so a red here is
attributable to the planted break rather than to the tree.

DELETE THIS BRANCH once the required run reports. It is evidence, not work.
@gunbai-bot
gunbai-bot Bot marked this pull request as ready for review September 7, 2026 15:31
gunbai-bot Bot pushed a commit that referenced this pull request Sep 7, 2026
… rung

BLOCKER 1 -- THREE LATER PIECES OF THE UNRESOLVED ROW STILL TAUGHT THE MODEL
THE HEADLINE, CEILING AND TRIGGER HAD ABANDONED. The instrument-recurrence
receipt called "the seam returns its diagnostics as part of its result" the
DURABLE REPAIR and the next-rung candidate; the BOUNDARY said the repair is
partitioning one state into two constructors so the declared-but-unreachable
case can refuse; the recognition rule's tell was a failure constructor whose
consumer computes a refusal and does not use it. Those no longer described
history, they PRESCRIBED -- and they prescribe what the corrected trigger
says not to do. Making the direct-classifier diagnostics undiscardable
removes neither ExprCall-tail absorber, and partitioning CallableUnresolved
cannot be the wall when methods, builtins and variant constructors
legitimately inhabit that state.

The instrument incident is KEPT, because it is a genuine receipt, and given
its disposition explicitly: an INSTRUMENTATION AND WIRING defect discovered
while measuring this class, not this class's repair. The durable-repair and
next-rung-candidate framing is gone. The BOUNDARY and the recognition rule
are restated against the actual absorber -- after every legitimate authority
misses, a later fallback fabricates an answer instead of letting the
terminal refusal that is already written fire. The recognition tell is now
a terminal refusal that EXISTS AND IS NEVER REACHED, with the instruction to
ask what runs between the last legitimate authority and it.

BLOCKER 2(b) -- STRING ESCAPING CANNOT BE THE NEXT-RUNG TRIGGER, AND THIS
ROW'S OWN CEILING IS WHAT REFUTES IT. The ceiling now says correctly that
escaping makes the intent expressible and leaves the bad state writable. A
capability that leaves the invalid state writable changes no rung. So the
trigger is the construction-owned carrier, and escaping is recorded as what
it is: a real authoring capability that removes the forced backtick
workaround, an EXPRESSIBILITY climb rather than a ladder climb. Naming it as
the trigger was the third instance in this row of one paragraph being
correct in isolation and refuted by another.

BLOCKER 2(c) -- the sibling edge still spoke in present tense. It now reads
that docs_markdown_projections_have_no_completing_actuator WAS the detector
gap for this incident and #10701 closed it, with the identity still cited
because a failure-mode row survives its own repair.

BLOCKER 2(a) IS NOT IN THIS COMMIT AND IS BEING MEASURED RATHER THAN
DECIDED. The row reports mitigatable while claiming the failure is loud
within the required run; 4b defines that combination as rung 2. Nothing had
driven an unparseable quotation through the post-#10701 REQUIRED acceptance
path, so the claim was stronger than its evidence. #10782 plants exactly
that break and is running now; the rung will be set from what it reports.
The probe refuses locally with three `undefined variable` diagnostics, so it
is discriminating rather than inert, and main plus this branch's parent are
the executed positive control.

Blocker 3, the stale PR body, is fixed on the PR rather than in the tree.

Projection regenerated through the projector.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GwvzQ3SQoWWDgHkAeffMeF
gunbai-bot Bot pushed a commit that referenced this pull request Sep 7, 2026
…isting

The row reported MITIGATABLE while also claiming the failure is LOUD WITHIN
THE REQUIRED RUN. Those cannot both stand: DESIGN 4b defines rung 2 as a
gate that reliably exposes and blocks a still-writable invalid state, which
is exactly what "loud within the required run" describes. And 4b(1) requires
the reported rung equal the rung established by EXECUTED evidence on the
real acceptance path -- which nothing had produced, because no unparseable
quotation had ever been driven through the post-#10701 required run.

MEASURED RATHER THAN DECIDED (#10782). A receipt carrying a bare
double-quoted phrase inside a double-quoted string was planted in one ledger
row and pushed. The required run REFUSED:

  error: resolve failed for dag/gunbc/instruments/generated_artifact_gate.dag
    cause: .../absorbing_fallback.dag:10:62: undefined variable 'unresolved'
           .../absorbing_fallback.dag:10:73: undefined variable 'AND'
           .../absorbing_fallback.dag:10:77: undefined variable 'declared'

Located to file, line and column. Two required jobs failed on it.

THE CONTROLS THAT MAKE THAT READ AS A MEASUREMENT. The probe was confirmed
to refuse LOCALLY before being pushed, so it was discriminating rather than
inert -- a probe that cannot fail proves the harness works, not the claim.
The positive control is the same required lane green on main and on this
branch's parent, so the red is attributable to the planted break rather than
to the tree.

TWO THINGS ALMOST MADE THIS PROBE INERT WHILE LOOKING ARMED, and both are
worth knowing: witnesses.yml triggers on push only for main, so the branch
push alone would never have run; and the auto-created PR was a DRAFT, which
skips CI gates entirely. Either would have produced a probe that executed
nothing and a conclusion drawn from its silence.

RUNG IS NOW: below the ladder at the incident, MECHANICALLY PREVENTABLE now.
Rung 2 and not higher, for 4b's own reason -- the state REMAINS WRITABLE and
safety depends on that gate executing and staying enrolled. The ceiling and
the trigger are unchanged: structural impossibility still needs a carrier
where delimiter escaping is construction-owned.

Projection regenerated through the projector.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GwvzQ3SQoWWDgHkAeffMeF
@gunbai-bot

gunbai-bot Bot commented Sep 7, 2026

Copy link
Copy Markdown
Contributor Author

Measurement complete — closing as designed, not merging. The required run REFUSED on the planted break:

error: resolve failed for dag/gunbc/instruments/generated_artifact_gate.dag
  cause: dag/gunbc/recurring_failure_mode/absorbing_fallback.dag:10:62: error: undefined variable 'unresolved'
         dag/gunbc/recurring_failure_mode/absorbing_fallback.dag:10:73: error: undefined variable 'AND'
         dag/gunbc/recurring_failure_mode/absorbing_fallback.dag:10:77: error: undefined variable 'declared'

Two required jobs failed on it, located to file, line and column. That establishes the rung claim in authored_quotation_terminates_the_string_it_is_authored_in (#10710) as mechanically preventable by execution rather than by inference from the gate existing — rung 2 and not higher, because the state remains writable and safety depends on the gate staying enrolled.

The REQUEST_CHANGES verdict (review 62000) was correct and is being honoured: read the gate result, then delete the branch.

Recorded for anyone building a similar probe: this nearly executed nothing while looking armed. witnesses.yml triggers push only on main, so the branch push alone would never have run, and the auto-created PR was a draft, which skips CI gates entirely.

— sent from quick-heron-85

@gunbai-bot gunbai-bot Bot closed this Sep 7, 2026
@gunbai-bot
gunbai-bot Bot deleted the probe/quotation-red-discriminator branch September 7, 2026 15:45
briansrls pushed a commit that referenced this pull request Sep 9, 2026
…and unresolved callee conflated with dispatched-elsewhere (#10710)

* Two failure-mode rows for the roster: authored quotation, and unresolved callee

FOUR .dag ROWS IN THE SUBSTRATE. This is not a document change: the
authority is gunbc.recurring_failure_mode, these are rows in it, and
docs/design-failure-modes.md is their derived projection. The projection is
DELIBERATELY NOT IN THIS COMMIT -- see the last paragraph.

authored_quotation_terminates_the_string_it_is_authored_in (new). The .dag
lexer has no string escaping, so a double quote inside a string literal is
not expressible -- it is avoided by convention. A receipt that QUOTES a
phrase therefore terminates the string it is authored in, and the row
filing the evidence is the row the evidence disables. The harm is not the
parse error: an unparseable authority does not empty its projection, the
projector refuses and the committed markdown stays at its previous vintage
while its own header still says it is generated from the authority. Nothing
in the rendered file distinguishes "this row has no new receipt" from "this
row stopped compiling".

Its ceiling is structurally impossible and NOT reachable by diligence, and
its trigger names the capability: string escaping in the .dag lexer,
sufficient to make a double quote expressible inside a string literal --
not a lint, not a convention, not a projection gate, each of which leaves
the state writable and merely reports it. The projection gate under
construction elsewhere makes this class LOUD within one commit, which is a
real improvement to detection and is not the climb; the row says so.

The specimen is a real un-staged occurrence, and the sharpest receipt cuts
against its own author: seven doubled apostrophes in the same rows,
defending against a hazard that does not exist -- an apostrophe inside a
double-quoted string is ordinary text, written plainly across the roster.
One author defended the case that was safe and left the fatal one
undefended. A convention misapplied in both directions at once is not held
by diligence, it is guessed at.

unresolved_callee_conflated_with_dispatched_elsewhere (new). One
unresolved-callee state carries both ANSWERED BY ANOTHER DISPATCH PATH and
DECLARED SOMEWHERE BUT UNREACHABLE FROM HERE, so the second can never
refuse -- and a delete-first census that rests on loud refusal undercounts
by the ratio of the two.

stale_claim_survives_its_own_correct_edit (append). One receipt: an import
is not a consumer, so a census of a symbol's consumers that counts import
lines measures the wrong form.

THE PROJECTION IS NOT REGENERATED HERE, ON PURPOSE. docs/design-failure-modes.md
is a generated artifact, and another branch is appending to this same roster
and regenerating this same file. Bytes derived from a roster missing their
rows would merge CLEAN AND WRONG -- no conflict, their rows silently gone.
The .dag edits are the authority and merge on their own terms; the doc is
regenerated once, on top of whichever authority lands last.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GwvzQ3SQoWWDgHkAeffMeF

* chore: regenerate drifted generated artifacts (ci auto-heal)

Ledger-Repair-Judged: docs/design-failure-modes.md
Ledger-Rows-Repaired: docs/design-failure-modes.md stale_claim_survives_its_own_correct_edit
Ledger-Rows-Repaired: docs/design-failure-modes.md unresolved_callee_conflated_with_dispatched_elsewhere
Ledger-Rows-Repaired: docs/design-failure-modes.md authored_quotation_terminates_the_string_it_is_authored_in
Ledger-Repair-Judged: docs/design-rung-drops.md

* Cite the neighbouring row by identity, in both directions this lane owns

gunbc#10734 measured, on 2026-09-07, that eight of nine members of the
absence family named no sibling at all, and that the one existing edge was
invisible to the identity join because it was spelled as a NICKNAME -- a
nickname being a DELETED EDGE rather than a weaker citation. Landing two new
rows with zero sibling edges would add to that debt on the day it was
published, in the same ledger the measurement is about.

So both rows now cite by IDENTITY, never by description:

  authored_quotation_terminates_the_string_it_is_authored_in names
  docs_markdown_projections_have_no_completing_actuator as the DETECTOR GAP
  for the same incident -- a projection with no completing actuator, so a
  stale artifact and an unbuildable authority are indistinguishable from the
  committed markdown alone -- while this row is the AUTHORING INJURY. That
  gate makes this class loud within one commit and does not make it
  unwritable, which is why the repairs are non-substitutable.

  unresolved_callee_conflated_with_dispatched_elsewhere records that it is
  NOT a member of the absence family, tested against the audit's own
  membership rule rather than by resemblance: membership needs an EMPTINESS
  consumed AS AN AFFIRMATIVE VERDICT, and the repair here is partitioning
  one state into two constructors so the declared-but-unreachable case can
  refuse -- which neither a positive control nor a denominator supplies.

THE REVERSE EDGE IS MISSING AND IS DELIBERATELY NOT REPAIRED HERE.
docs_markdown_projections_have_no_completing_actuator names this row by
description -- "a neighbouring class they are filing separately" -- which is
exactly the shape the audit condemns. That row is merged and is not this
lane's to edit; a follow-up owes it, and both the row and the PR body say so
rather than leaving the obligation silently half-done.

AND THE DEFECT THE FIRST ROW EXISTS TO NAME WAS COMMITTED WHILE WRITING IT,
FOR THE SECOND TIME. Five doubled apostrophes went into these two receipts
-- defending against a hazard that does not exist -- and were caught before
commit by the same scan the row prescribes. Recorded here rather than
quietly fixed, because a class whose author reproduces it twice while
documenting it is better evidence for the lexer trigger than either
occurrence alone.

Projection regenerated from the authority.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GwvzQ3SQoWWDgHkAeffMeF

* The ceiling derived its climb from two mechanisms the same row withdraws

BLOCKING CONTRADICTION, INSIDE ONE ROW. The CEILING paragraph of
unresolved_callee_conflated_with_dispatched_elsewhere justified
"structurally guaranteed, reachable now" from two ingredients the row
itself refutes further down:

  1. that the state is already partitioned because CallTargetOutcome
     carries CallableUnresolved as its own constructor -- while the
     ABSORBER paragraph says in capitals that this constructor is NOT the
     absorber, that an earlier revision looked at the wrong seam, and that
     the constructor legitimately means the direct classifier did not give
     the final answer.
  2. that corpus membership decides whether a callee is declared -- which
     is the leaf-name predicate the row explicitly WITHDRAWS, because it
     makes corpus population into naming input.

THE DECISIVE TELL WAS THAT THE TRIGGER NAMED A DIFFERENT MECHANISM. The
NEXT-RUNG TRIGGER calls for structural declaration-kind evidence at the
ExprCall tail, removal of the bare whole-pool fallback, and an exact
reference-resolution arm it describes as "independent of pool population,
which is exactly what the withdrawn leaf-name predicate was not". The
trigger contrasted itself against the very predicate the ceiling still
rested on: ceiling and trigger disagreed about what the climb consists of.

WHY THAT BLOCKS RATHER THAN READING AS A WORDING NIT. DESIGN 4b(1) requires
a ceiling be DERIVED rather than aspirational, and a class below its ceiling
is ranked for climbing by exactly this paragraph. A ceiling derived from a
withdrawn mechanism sends the next reader to the seam this row already
established is the wrong one -- in a row whose whole content is that a
population sized by the wrong measure is the wrong number.

THE REPAIR IS RESTATEMENT, NOT RETREAT. The ceiling stays at structurally
guaranteed and reachable now; it is not weakened to mechanically preventable
to dodge the contradiction, and the paragraph is not deleted. It now derives
from the two structural facts the trigger names and the compiler already
carries: the DECLARATION KIND, which settles whether a callee is a callable
type or a data constructor without consulting what else the corpus happens
to declare, and an EXACT OCCURRENCE-TO-DECLARATION AUTHORITY saying this
occurrence binds this declaration, independent of pool population. Both are
decidable at the ExprCall tail, which is what makes the class a wall rather
than a ratchet.

BOTH WITHDRAWN INGREDIENTS ARE RECORDED RATHER THAN QUIETLY REPLACED, since
a ceiling that changes its derivation without saying so is the same class of
defect one revision later. And the one TRUE fact that survives the
withdrawal is kept as EVIDENCE rather than as the remaining work:
declared_formal_authority_failed is false for CallableUnresolved, so the
refusal reason is computed and never emitted -- a fact about the REPORTING
seam that says nothing about the absorbing one, which is precisely the
substitution the absorber paragraph exists to prevent.

Projection regenerated through the projector, not hand-edited.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GwvzQ3SQoWWDgHkAeffMeF

* Name the instrument that re-derives the silent remainder; drop two transcribed counts

TWO COUNTS FOR ONE POPULATION, AT UNSTATED GRAIN, IN THE SAME ROW. The
POSITIVE CONTROL receipt licensed "the reading of the 67 sites that emit
nothing"; SCOPE NOT CLAIMED said "the other 70 emit nothing". Only one
population exists and the row states how it is built: the MEASURED receipt
finds 73 distinct callees among the branch-only pairs, three of which
fabricate visibly, leaving 70. THERE IS NO DERIVATION THAT REACHES 67 -- it
was a transcription with no denominator behind it, and a reader could not
tell which population either sentence denominated.

CORRECTING THE DIGIT WOULD HAVE LEFT THE DEFECT. DESIGN section 6 says to
name the producer that re-derives a measurement rather than copy its numbers
into prose, for the reason this row demonstrates: a transcribed number is
unreachable from the thing that owns it, so it rots without anyone touching
either end. Writing 70 in place of 67 would have produced a correct sentence
with the same failure mode, one edit from going stale again.

So both sentences now name the SILENT REMAINDER and how it is obtained --
the MEASURED receipt's branch-only distinct-callee population less the three
whose failure is visible, re-derived by re-running that instrumentation of
call_target_for_direct_call over the two-root corpus. No transcribed count
survives in either sentence. This is the row whose whole content is that a
population sized by the wrong measure is the wrong number; an unnamed
denominator inside it was the same defect one paragraph over.

AND THE CEILING DEFECT REPAIRED IN THE PREVIOUS COMMIT IS FILED AS A RECEIPT
ON stale_claim_survives_its_own_correct_edit -- the class this same PR adds.
Both premises the ceiling rested on were TRUE WHEN WRITTEN and were
falsified by correct edits made elsewhere IN THE SAME ROW, which is that
class exactly. The transferable part is not the incident but the mechanical
tell: a ceiling and its next-rung trigger are the one pair in a row that
must agree, so checking them against each other is a cheap executable
instance of that row's recognition rule. Stated flatly -- a row long enough
to withdraw its own premises can outlive them internally, needing neither a
second author nor a second file.

Projection regenerated through the projector.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GwvzQ3SQoWWDgHkAeffMeF

* Four repairs: an inflated ceiling, an invalid derivation, an overstated fact, and stale tense

ITEM A -- THE CEILING REPAIR REPEATED THE DEFECT IT REPAIRED. The restated
CEILING said the compiler ALREADY CARRIES BOTH structural facts, including
the exact occurrence-to-declaration authority. The same row says, in its
qualified-reference receipt, that NOTHING PERFORMS THAT JOIN TODAY -- which
is why the segments of a qualified reference stay unrelated rows and the
qualified arm is unreachable. A nearby true fact promoted one rung, which is
this paragraph's original defect in a new sentence.

Narrowed, not lowered: the compiler carries the INGREDIENTS FROM WHICH both
are DERIVABLE WITHOUT NEW EXTERNAL GROUNDING. The ceiling still stands,
because DESIGN section 5's wall-after-grounding case is about a MISSING
AUTHORITY, and derivable-from-what-exists is exactly what makes this class
reachable now rather than blocked behind one. The overstatement is recorded
in the paragraph rather than quietly swapped.

ITEM B -- THE HEADLINE'S CAUSAL DERIVATION WAS REFUTED BY THIS ROW'S OWN
TRIGGER. It said one state carries both meanings SO THE SECOND CAN NEVER
REFUSE. But the final `function not found in scope` diagnostic is ALREADY
WRITTEN at the ExprCall tail and reachable once every legitimate dispatch
path has missed -- and the repair this row proposes KEEPS CallableUnresolved,
lets those authorities answer, and refuses there. Sharing an intermediate
constructor does not imply the unreachable case can never refuse. What
actually happens is that the direct-call miss is ABSORBED LATER, by
generic-type and whole-pool lookup running after the legitimate paths have
missed, so a targetless call acquires a fabricated answer instead of
arriving at the refusal that exists for it.

NEVER is DESIGN section 5's named trap word -- it lets a ratchet masquerade
as a wall -- and here it asserted an impossibility the row disproves three
paragraphs later. The class identity and its recognition name are unchanged;
it was the derivation that was wrong.

ITEM C -- THE QUOTATION ROW'S CEILING WAS INFLATED, AND ESCAPING DOES NOT
REACH IT. The paragraph argued that once a string can CARRY a quotation the
failure has nothing to be built from. It does not follow. ESCAPING MAKES THE
CORRECT INTENT EXPRESSIBLE; IT DOES NOT MAKE THE BAD STATE UNWRITABLE. After
escaping lands an author can still type a bare delimiter where they meant
content, terminate the literal, and reproduce the failure exactly, so 4b
rung 4 -- no constructor in the canonical model -- is not reached. That is
the construction-versus-diligence distinction this row exists to enforce,
committed by the row.

Split rather than lowered. The ceiling is now derived from a carrier where
delimiter escaping is CONSTRUCTION-OWNED rather than author-owned:
structured content rendered by a serializer, or any carrier in which content
cannot become its own delimiter. Lexer escaping remains a real next-rung
trigger that removes today's forced workaround, with one sentence separating
what it buys from what it does not, because conflating those is how the
paragraph was wrong.

ITEM D -- STALE TENSE, TRUE AT THE INCIDENT AND FALSE ON THIS TREE. The row
said docs projections are gated NOWHERE, red in no lane, class under repair.
#10701 has landed and this branch carries the completing comparison.
Historicalized: no required content gate existed at the time of the
incident; the failure is now loud within the required run, which closes the
DETECTOR gap and not the AUTHORING injury. The rung reads as REACHED rather
than conditional.

Projection regenerated. The two surviving occurrences of the withdrawn
wordings are inside the sentences that retract them, quoted deliberately.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GwvzQ3SQoWWDgHkAeffMeF

* The tail still prescribed the withdrawn repair; and escaping is not a rung

BLOCKER 1 -- THREE LATER PIECES OF THE UNRESOLVED ROW STILL TAUGHT THE MODEL
THE HEADLINE, CEILING AND TRIGGER HAD ABANDONED. The instrument-recurrence
receipt called "the seam returns its diagnostics as part of its result" the
DURABLE REPAIR and the next-rung candidate; the BOUNDARY said the repair is
partitioning one state into two constructors so the declared-but-unreachable
case can refuse; the recognition rule's tell was a failure constructor whose
consumer computes a refusal and does not use it. Those no longer described
history, they PRESCRIBED -- and they prescribe what the corrected trigger
says not to do. Making the direct-classifier diagnostics undiscardable
removes neither ExprCall-tail absorber, and partitioning CallableUnresolved
cannot be the wall when methods, builtins and variant constructors
legitimately inhabit that state.

The instrument incident is KEPT, because it is a genuine receipt, and given
its disposition explicitly: an INSTRUMENTATION AND WIRING defect discovered
while measuring this class, not this class's repair. The durable-repair and
next-rung-candidate framing is gone. The BOUNDARY and the recognition rule
are restated against the actual absorber -- after every legitimate authority
misses, a later fallback fabricates an answer instead of letting the
terminal refusal that is already written fire. The recognition tell is now
a terminal refusal that EXISTS AND IS NEVER REACHED, with the instruction to
ask what runs between the last legitimate authority and it.

BLOCKER 2(b) -- STRING ESCAPING CANNOT BE THE NEXT-RUNG TRIGGER, AND THIS
ROW'S OWN CEILING IS WHAT REFUTES IT. The ceiling now says correctly that
escaping makes the intent expressible and leaves the bad state writable. A
capability that leaves the invalid state writable changes no rung. So the
trigger is the construction-owned carrier, and escaping is recorded as what
it is: a real authoring capability that removes the forced backtick
workaround, an EXPRESSIBILITY climb rather than a ladder climb. Naming it as
the trigger was the third instance in this row of one paragraph being
correct in isolation and refuted by another.

BLOCKER 2(c) -- the sibling edge still spoke in present tense. It now reads
that docs_markdown_projections_have_no_completing_actuator WAS the detector
gap for this incident and #10701 closed it, with the identity still cited
because a failure-mode row survives its own repair.

BLOCKER 2(a) IS NOT IN THIS COMMIT AND IS BEING MEASURED RATHER THAN
DECIDED. The row reports mitigatable while claiming the failure is loud
within the required run; 4b defines that combination as rung 2. Nothing had
driven an unparseable quotation through the post-#10701 REQUIRED acceptance
path, so the claim was stronger than its evidence. #10782 plants exactly
that break and is running now; the rung will be set from what it reports.
The probe refuses locally with three `undefined variable` diagnostics, so it
is discriminating rather than inert, and main plus this branch's parent are
the executed positive control.

Blocker 3, the stale PR body, is fixed on the PR rather than in the tree.

Projection regenerated through the projector.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GwvzQ3SQoWWDgHkAeffMeF

* Blocker 2(a): set the rung from an executed RED, not from the gate existing

The row reported MITIGATABLE while also claiming the failure is LOUD WITHIN
THE REQUIRED RUN. Those cannot both stand: DESIGN 4b defines rung 2 as a
gate that reliably exposes and blocks a still-writable invalid state, which
is exactly what "loud within the required run" describes. And 4b(1) requires
the reported rung equal the rung established by EXECUTED evidence on the
real acceptance path -- which nothing had produced, because no unparseable
quotation had ever been driven through the post-#10701 required run.

MEASURED RATHER THAN DECIDED (#10782). A receipt carrying a bare
double-quoted phrase inside a double-quoted string was planted in one ledger
row and pushed. The required run REFUSED:

  error: resolve failed for dag/gunbc/instruments/generated_artifact_gate.dag
    cause: .../absorbing_fallback.dag:10:62: undefined variable 'unresolved'
           .../absorbing_fallback.dag:10:73: undefined variable 'AND'
           .../absorbing_fallback.dag:10:77: undefined variable 'declared'

Located to file, line and column. Two required jobs failed on it.

THE CONTROLS THAT MAKE THAT READ AS A MEASUREMENT. The probe was confirmed
to refuse LOCALLY before being pushed, so it was discriminating rather than
inert -- a probe that cannot fail proves the harness works, not the claim.
The positive control is the same required lane green on main and on this
branch's parent, so the red is attributable to the planted break rather than
to the tree.

TWO THINGS ALMOST MADE THIS PROBE INERT WHILE LOOKING ARMED, and both are
worth knowing: witnesses.yml triggers on push only for main, so the branch
push alone would never have run; and the auto-created PR was a DRAFT, which
skips CI gates entirely. Either would have produced a probe that executed
nothing and a conclusion drawn from its silence.

RUNG IS NOW: below the ladder at the incident, MECHANICALLY PREVENTABLE now.
Rung 2 and not higher, for 4b's own reason -- the state REMAINS WRITABLE and
safety depends on that gate executing and staying enrolled. The ceiling and
the trigger are unchanged: structural impossibility still needs a carrier
where delimiter escaping is construction-owned.

Projection regenerated through the projector.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GwvzQ3SQoWWDgHkAeffMeF

* The repair erased the specimen it was citing

The row said it cited the doubled apostrophe -- "seven occurrences,
`row''s`, `class''s` and the like" -- and displayed `row's`, `class's`. The
blanket regex that repaired the seven real occurrences REWROTE THE EXHIBIT
TOO, leaving a sentence that claimed to cite a defect while showing its
correct form.

FOUND BY READING AN APPROVAL, NOT BY DISTRUSTING IT. A review confirmed
`grep "''"` over the roster returns empty and read that as the residue being
genuinely zero. It is zero -- including in the sentence whose whole job was
to be non-zero. The mechanical test that verified the tree is the same test
that had destroyed the evidence, so it could only agree.

THE GENERAL FORM IS RECORDED IN THE ROW BECAUSE IT IS NOT ABOUT
APOSTROPHES: a specimen stored in the medium it is a defect of is destroyed
by the repair of that defect. That hazard applies to any row citing a
spelling, an encoding, or a delimiter, and it is DESIGN 4b(4) violated in
miniature -- a climb deletes the production machinery, and the discriminating
evidence is exactly what must survive it.

Repaired by DESCRIBING the spelling rather than exhibiting it: the possessive
written with its apostrophe typed twice. A description cannot be swept by the
sweep that repairs the class.

Projection regenerated through the projector.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GwvzQ3SQoWWDgHkAeffMeF

* State the apostrophe repair as delivered state, not as a commit that did it

The receipt said the seven occurrences were "repaired in the same commit
that files this row". That is a PROVENANCE claim in a permanent row, and it
binds to two things that outlive anyone watching: an integration mechanism
(true only under squash-merge) and a branch history.

RE-DERIVED FROM THIS BRANCH, AND THE PROVENANCE IS DIFFERENT AGAIN. At the
filing commit on this branch, unresolved_callee already carries ZERO doubled
apostrophes: the seven were repaired before these files were copied here, so
the repair does not appear in this branch's history at all. The only doubled
apostrophes present at filing were the TWO in the deliberate exhibit, since
destroyed by the sweep and now replaced by a description.

So the sentence was not merely squash-dependent. It named commits that do
not carry what it said they carried, on any branch.

REWORDED TO A CLAIM ABOUT STATE: the seven are repaired in this same change,
stated as a fact about the delivered rows, which carry none. State is
checkable forever by the same scan that found the defects; a commit is not.
That is DESIGN section 3 -- cite the thing, not its position -- applied to a
provenance sentence rather than to a symbol.

Projection regenerated.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GwvzQ3SQoWWDgHkAeffMeF

* Drop count and commit provenance from the erasure receipt; delete the next-rung clause

The archaeology refutes both halves of the provenance claim: the doubled-apostrophe
population GREW after the break commit, so "seven, in the same commit as the break"
was wrong in the count and in the commit. Neither is load-bearing. The durable
finding is the MECHANISM -- a specimen stored in the defective representation can be
destroyed by the repair of that defect -- plus the STATE of the delivered rows, which
carry none of it and are checkable forever by the same scan that found it. A
provenance claim would bind to an integration mechanism and a branch history instead.

Also removes the editing scar the reword left behind (a lowercase fragment after a
full stop, with a doubled space) and the now-false clause claiming the count rather
than the state was recorded.

In the unresolved-callee row, deletes the trailing "the structural form ... is the
next-rung candidate" clause. It was logically scoped by three preceding disclaimers
but sat immediately after a paragraph saying that same structural form CANNOT be this
class's next rung, so a reader taking the two sentences in order meets a
contradiction. The receipt already states what the interim repair accomplishes, so
the deletion loses nothing.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GwvzQ3SQoWWDgHkAeffMeF

* chore: regenerate drifted generated artifacts (ci auto-heal)

Ledger-Repair-Judged: docs/design-failure-modes.md
Ledger-Rows-Repaired: docs/design-failure-modes.md stale_claim_survives_its_own_correct_edit
Ledger-Rows-Repaired: docs/design-failure-modes.md unresolved_callee_conflated_with_dispatched_elsewhere
Ledger-Rows-Repaired: docs/design-failure-modes.md authored_quotation_terminates_the_string_it_is_authored_in
Ledger-Repair-Judged: docs/design-rung-drops.md

* chore: regenerate drifted generated artifacts (ci auto-heal)

Ledger-Repair-Judged: docs/design-failure-modes.md
Ledger-Rows-Repaired: docs/design-failure-modes.md stale_claim_survives_its_own_correct_edit
Ledger-Rows-Repaired: docs/design-failure-modes.md unresolved_callee_conflated_with_dispatched_elsewhere
Ledger-Rows-Repaired: docs/design-failure-modes.md authored_quotation_terminates_the_string_it_is_authored_in
Ledger-Repair-Judged: docs/design-rung-drops.md

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants