Repository navigation
Plan DESIGN placement for meaning, externalization, and quality floor - #9769
Conversation
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
bee47b5 to
7ea52e4
Compare
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: bee47b5073
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| @@ -0,0 +1,400 @@ | |||
| # Meaning, externalization, and quality-floor placement in DESIGN | |||
There was a problem hiding this comment.
Register the new plan in the document graph
Adding this file without a corresponding gunbc.plan.Plan or HandAuthoredDocBind leaves it outside doc_graph_roots_all(). On docs-only changes, test.claim.doc_reachability_witness.doc_graph_has_no_orphan_docs runs against the live docs/ tree and will therefore fail with this plan as an orphan; add a typed binding to the relevant DESIGN/recurring-failure-mode authority and a retirement condition.
Useful? React with 👍 / 👎.
|
|
||
| ## Current citation review surface | ||
|
|
||
| This is a literal section-anchor census at the reviewed public revision. It includes `§3`, `§4b`, and `§5` references plus the repository's observed `DESIGN section …` / `DESIGN …` spellings. The spelled-out aliases add no new §3 or §4b artifacts; `DESIGN 5` adds `docs/plans/deploy-convergence-observed-side.md` to the §5 set. These are review surfaces, not proposed edits. |
There was a problem hiding this comment.
Complete the claimed section-anchor census
This is not a literal census of the stated revision: for example, docs/plans/replacement-migration-doctrine.md contains all three anchors but appears in none of the lists, while compiler-guarantee-recovery-gap-analysis.md is likewise omitted from §3, §4b, and §5. A revision-scoped search also finds additional omissions such as compute-envelope-model.md, host-effect-orchestration.md, and representation-minimization.md, so the reported counts and downstream review surface are incomplete and could cause the supervised edit to skip affected documents.
Useful? React with 👍 / 👎.
- Breach / separate product / rung drop stated as a three-way partition; 'named degradation is the honest declared rung drop' removed. A drop in the ability to verify a promise forces refusal, never authorizes silent below-floor delivery. P2 copy carries the same separation. - Meaning-fork subject scoped by (naming surface, visible name, declared effective version/epoch) in P1 and the meaning_fork row; same-spelling reuse across declared scopes or version transitions stated legitimate. - Plan terminal disposition (retain / delete / bind) declared an operator decision at approval time; no bind row proposed (#9767's self-registered bind acknowledged as correctly rejected). - Re-baselined onto main@826824d2 with the delta assessed against the census surface. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01QhdaHkmZPoQoeUWz5V2mzF
|
ROOT-0 executed on this PR per the operator's serial program: #9767 closed (consolidated here); branch re-baselined onto
Already present from this branch's own drafting and left standing: externalization defined independently of Diff vs main is the single plan file. ROOT-0 gate: this PR now awaits operator approval of the exact NOT-APPLIED source copy; no DESIGN authority edit begins before that. — sent from jolly-swift-749 |
…; accountability boundary; regen preflight - Citation census re-derived at the merged tree with the derivation command recorded in the plan; exact file identities retained (66 / 21 / 69 docs for §3 / §4b / §5 — replacement-migration-doctrine.md and machine-intake-design.md now present); false 56/19/59 counts removed; bare-§N classification rule stated (exception scan over docs defining their own §-headings). - meaning_fork root object generalized to material semantic referent, with contract identity as one specialization (analysis and row). - ProviderInterfaceBinding reclassified: legitimate same-spelling reuse across distinct naming surfaces plus a search-homonym hazard, not a direct specimen; shared-surface question deferred to the operator census. - Externalization restated at responsibility-and-principal grain (analysis, P3 copy, and 'the responsible actor' in the row); disclosed refusable pre-contract allocation named as the priced arm. - ROOT-1 regen preflight completed: exact-tree repo-built gunbc only; private cgroup bound or GUNBC_MEMORY_BUDGET_BYTES from a named source, exported in the same dispatch; HostBudgetUnreadable is a correct line stop; installed binary recorded as a refusal receipt, not a route. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01QhdaHkmZPoQoeUWz5V2mzF
|
ROOT-0 delta report (per the HOLD ruling's item 9):
ROOT-1 remains blocked pending operator approval of this exact head. — sent from jolly-swift-749 |
|
Follow-up to the item-9 report: CI concluded fully green on head |
…where; provider adjacent-not-specimen; caused costs in the externalization row; operator terminal ruling recorded - 'Add meaning_fork' subsection rewritten to the scoped-key / material- semantic-referent formulation; contract fields are the commercial specialization; the private premium-name case is the direct specimen and ProviderInterfaceBinding is adjacent, consistent with the earlier section. - meaning_fork row's recognition sentence concludes on the referent first, contract fields as sufficient evidence. - externalized_degradation row widened to accepted-obligation-or-caused-cost -> burden shifted to another principal, with the disclosed pre-contract transfer arm and refusable-transfer wording. - P3 final sentence: 'another principal', not 'the counterparty'. - Terminal disposition records the operator ruling: plan deleted in ROOT-1 in the consuming PR; no HandAuthoredDocBind. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01QhdaHkmZPoQoeUWz5V2mzF
|
Final consistency patch applied per the approvability re-check: head is now
No census, probe, authority, projection, bind, or lens change; ordinary CI is rerunning on this head. Awaiting operator approval of this exact head to open ROOT-1. — sent from jolly-swift-749 |
briansrls
left a comment
There was a problem hiding this comment.
ROOT-0 EXACT-HEAD RULING: APPROVED at bbe0d9d.
GitHub does not permit the connected account to submit a formal APPROVE review on its own PR, so this comment records the side-chat reviewing-authority ruling rather than a GitHub approval state.
Accepted: the plan-only boundary; exact-tree citation census; scoped material-semantic-referent rule; breach / separate-product / §4b(3)-rung-drop partition; responsibility-and-principal externalization rule; honest private-evidence boundary; ROOT-1 regeneration preflight; and terminal plan deletion with no HandAuthoredDocBind.
Merge only after the current exact-head workflow completes green. ROOT-1 may then begin from the exact merged main revision; it must consume the approved NOT-APPLIED copy, regenerate DESIGN.md and docs/design-ledgers.md, and delete this plan in the same supervised PR. This approval authorizes no lens and no corpus-wide audit.
|
ROOT-0 is complete and merge-ready at |
…py into the DESIGN authorities; the plan retires with its consumer Applies the operator-approved source copy from #9769 (approved at bbe0d9d, merged as 2603a63) verbatim: - gunbc.design_document section_3_blocks: the meaning-fork paragraph after the nicknaming paragraph; section_4b_blocks: the quality-floor paragraph after the four meta-obligations; section_5_blocks: the externalization paragraph after the absorbing-fallback paragraph. - gunbc.recurring_failure_mode: meaning_fork and externalized_degradation rows appended, roster extended in source order; evidence stays empty per the module's own standing note. - docs/plans/meaning-externalization-design-placement.md DELETED per the operator terminal ruling: the supervised edit was its one consumer, and retaining it would leave a second prose representation of the live authority. No HandAuthoredDocBind. The merged #9769 and git history retain the placement analysis and review record. Projections regenerate in the follow-up commit of this same PR. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01QhdaHkmZPoQoeUWz5V2mzF
…, XL-R-4A rebuild scope #9765, DESIGN placement plan #9769). Conflicts: 5 regen-owned stage0 mirrors taken ours from the ef328db8 converged tree — regen fixes forward; main's hand-maintained required_regen_host.rs auto-merged from main. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU
Conflict in dag/gunbc/recurring_failure_mode.dag: main's #9769 appended surface_shorthand_preempts_resolved_identity while this branch appended coarser_parallel_authority; both also appended to the roster. Kept both, main's first, in the declaration region and the roster. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01N8xvN1T1NKiJqCUqwEmDgK
…py into the DESIGN authorities (#9786) * ROOT-1: consume the approved meaning/externalization/quality-floor copy into the DESIGN authorities; the plan retires with its consumer Applies the operator-approved source copy from #9769 (approved at bbe0d9d, merged as 2603a63) verbatim: - gunbc.design_document section_3_blocks: the meaning-fork paragraph after the nicknaming paragraph; section_4b_blocks: the quality-floor paragraph after the four meta-obligations; section_5_blocks: the externalization paragraph after the absorbing-fallback paragraph. - gunbc.recurring_failure_mode: meaning_fork and externalized_degradation rows appended, roster extended in source order; evidence stays empty per the module's own standing note. - docs/plans/meaning-externalization-design-placement.md DELETED per the operator terminal ruling: the supervised edit was its one consumer, and retaining it would leave a second prose representation of the live authority. No HandAuthoredDocBind. The merged #9769 and git history retain the placement analysis and review record. Projections regenerate in the follow-up commit of this same PR. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01QhdaHkmZPoQoeUWz5V2mzF * ROOT-1: regenerate the projections from the exact merged tree Produced by tools.generated_artifact_gate.main_wet via the repo-built gunbc from tree 8965ebf, executed on srv2 (arm64) in a rust:1-bookworm container under a 16 GiB docker cgroup memory bound — the modeled host-budget source, no environment override needed. Generated diff is exactly DESIGN.md (three paragraphs at their three anchors + two failure-mode index identities) and docs/design-ledgers.md (two entries appended in roster order). The BuildBuddy dispatches from the same tree ran main_wet to ExitSuccess with an EMPTY diff — recorded as an infrastructure anomaly (suspect: runner workspace reuse serving a stale tree), not a property of the transaction; the srv2 run from a fresh clone of the pinned SHA is the receipt. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01QhdaHkmZPoQoeUWz5V2mzF * Repair the merge splice: close surface_shorthand_preempts_resolved_identity's row (the conflict's common tail had been consumed by the appended rows) Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01QhdaHkmZPoQoeUWz5V2mzF * Regenerate projections from the repaired merge tree (0566b5f): restore #9741's surface_shorthand identity to the DESIGN index and its ledger entry, roster order preserved Produced by main_wet via the repo-built binary on srv2 (fresh clone, 16 GiB cgroup bound), same route as the ROOT-1 regen receipt. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01QhdaHkmZPoQoeUWz5V2mzF --------- Co-authored-by: Brian Searls <briansearls1@gmail.com> Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
…nstruction cuts (#9851) * ROOT-1: consume the approved meaning/externalization/quality-floor copy into the DESIGN authorities; the plan retires with its consumer Applies the operator-approved source copy from #9769 (approved at bbe0d9d, merged as 2603a63) verbatim: - gunbc.design_document section_3_blocks: the meaning-fork paragraph after the nicknaming paragraph; section_4b_blocks: the quality-floor paragraph after the four meta-obligations; section_5_blocks: the externalization paragraph after the absorbing-fallback paragraph. - gunbc.recurring_failure_mode: meaning_fork and externalized_degradation rows appended, roster extended in source order; evidence stays empty per the module's own standing note. - docs/plans/meaning-externalization-design-placement.md DELETED per the operator terminal ruling: the supervised edit was its one consumer, and retaining it would leave a second prose representation of the live authority. No HandAuthoredDocBind. The merged #9769 and git history retain the placement analysis and review record. Projections regenerate in the follow-up commit of this same PR. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01QhdaHkmZPoQoeUWz5V2mzF * ROOT-1: regenerate the projections from the exact merged tree Produced by tools.generated_artifact_gate.main_wet via the repo-built gunbc from tree 8965ebf, executed on srv2 (arm64) in a rust:1-bookworm container under a 16 GiB docker cgroup memory bound — the modeled host-budget source, no environment override needed. Generated diff is exactly DESIGN.md (three paragraphs at their three anchors + two failure-mode index identities) and docs/design-ledgers.md (two entries appended in roster order). The BuildBuddy dispatches from the same tree ran main_wet to ExitSuccess with an EMPTY diff — recorded as an infrastructure anomaly (suspect: runner workspace reuse serving a stale tree), not a property of the transaction; the srv2 run from a fresh clone of the pinned SHA is the receipt. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01QhdaHkmZPoQoeUWz5V2mzF * Repair the merge splice: close surface_shorthand_preempts_resolved_identity's row (the conflict's common tail had been consumed by the appended rows) Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01QhdaHkmZPoQoeUWz5V2mzF * Regenerate projections from the repaired merge tree (0566b5f): restore #9741's surface_shorthand identity to the DESIGN index and its ledger entry, roster order preserved Produced by main_wet via the repo-built binary on srv2 (fresh clone, 16 GiB cgroup bound), same route as the ROOT-1 regen receipt. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01QhdaHkmZPoQoeUWz5V2mzF * ROOT-2 plan: contract identity and the quality floor as two serial construction cuts Cut A generalizes the existing gunbc.fleet RequiredCiContractIdentity grain to the DESIGN §3 triple (naming surface, name, epoch) rather than minting a second contract-identity authority. The live gap it closes: required_ci_admission checks workflow path and repository with per-cause refusals and then admits, carrying no epoch, so a materially changed contract is admitted under the same workflow_path — the §3 meaning fork, in production. Cut B instantiates that identity for std.evaluation_budget: a graded dimension with a typed consequence, consumed in production. The consequence-ownership fork is adjudicated to Terminal A on four recorded pieces of evidence, the discriminator being that no caller refusal-code protocol exists for a caller-owned code to belong to. LimitUnset constructs no floor on that clock; the consequence derives from the closed exceeded arm rather than caller-supplied text. The two REDs are separate instruments with separate cardinalities — a semantic breach RED with its two admitted controls, and an authority-wiring falsifier — and the plan says in terms that 'some RED occurs' establishes nothing. The plan names itself as dissolved by the second cut. Neither cut edits DESIGN.md or gunbc.design_document. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_014iheRFn4BiVGDwgN6gQBQX * ROOT-2 plan, amended per the reviewing authority's five corrections 1. Cut A is an ATOMIC ROOT CUT, not an additive shadow: the public name RequiredCiContractIdentity may survive as a specialization of the canonical triple, but its old two-field representation is eliminated in the same landing. The three unacceptable shapes (field-beside-canonical, old/new/converter, shadow comparator) are named, and the field classification table keeps contract identity from widening into every admission prerequisite. 2. The blocking omission is closed: the plan now names a production source of the OBSERVED epoch. Adding epoch to required_ci_contract() alone would stamp the EXPECTED epoch onto the result and prove nothing about what the triggering run executed. Route chosen: exact-commit observation at event.head_sha of an epoch emitted into WitnessFloorYamlArtifact -- the exact bytes the run executed. The typed-receipt route is rejected with its reason: floor_component_receipt_document has no production consumer, so nothing emits it today. Oracle independence is restated at the grain that matters, and the RED must traverse the production join. 3. Cut B does not duplicate entry: entry is projected from the contract identity, and the verdict stays identity-bound so no detached Within value crosses the boundary. 4. The wiring falsifier requires a MOVED VALUE, not a refusal -- an always-refusing emitter would otherwise pass while proving no binding. Drift RED before regen, perturbed value after, zero occurrences of the former code. The exhaustiveness mutation is separate and not a substitute. The generated projection's full enrollment chain is named. 5. The epoch guarantee is stated honestly: cross-epoch admission is mechanically prevented; an unbumped material change remains declared-version diligence. This cut does not make all same-name meaning forks structurally impossible. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_014iheRFn4BiVGDwgN6gQBQX * ROOT-2 plan: discharge the reachability obligation and the Terminal-A stop-lines The Terminal-A ruling left one discovery obligation open -- the exact authority-to-generated-Rust-to-serve_budget_refusal_body chain -- and set stop-lines the earlier draft did not carry. All are now in the plan. - THE TERMINAL CONSEQUENCE LAW. No freely writable consequence_code field on the policy, the contract identity or the exceeded arm, so a contract with an arbitrary or self-contradictory consequence is not constructible. And the zero-argument refusal-code fn is an authority over the BYTES that does not yet establish that the typed cause determines their DELIVERY; Cut B closes that edge, with the required property stated and the implementation shape left free. - REACHABILITY PROVED, not asserted, with the actual symbols and a named census base: authority -> emitter -> GeneratedArtifact variant (coproduct, roster, location, commit policy, equality arm) -> artifact_generate arm -> main_wet generation and drift -> crate inclusion -> serve_budget_refusal_body -> rebuilt binary -> executed response. Every link is an exhaustive match over the variant set, so a half-enrolled artifact fails to compile -- enrollment is closed by construction rather than by an author remembering a checklist. - NO SEMANTIC HITCHHIKING. The consequence gets a DEDICATED generated projection rather than riding v1_interpreter_dispatch_generated.rs, whose subject is interpreter primitive dispatch; mixing two authorities into one generated file is the same fork wearing a generated file's clothes. Generated bytes carrying the literal are fine -- an independently maintained literal in cli_run is not. - The semantic RED's 'exactly one' is identified at the correct grain: one bounded clock crossed, one exceeded cause, one named consequence, one production response. - Cut A carries no generated budget-consequence bridge merely because one plan describes both cuts. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_014iheRFn4BiVGDwgN6gQBQX * ROOT-2 plan: correct three substantive defects the reviewing authority found (1) THE RECEIPT-ROUTE REJECTION PREMISE WAS FALSE AND IS WITHDRAWN. I had grepped for the document constructor in .dag only and concluded nothing emits it. The receipt is real, rich infrastructure: schema floor-component-receipt/v1, artifact name, path, typed subject with workflow name/run id/head sha, decoder, event-subject join. The re-census answers all six questions and reaches the same route on a materially different basis: NOTHING writes target/floor-component-receipt.json in src/ or dag/; witnesses.yml uploads four artifacts and this is not one; and the alert that downloads it, falsifier-alert.yml, was DELETED in the 2026-08-15 CI bankruptcy. The obstacle is a deleted transport, not a missing model -- and the authority's prose still recites that transport in the present tense, which is the premise-contamination class DESIGN §4b names. Recorded as a finding for that module's owner, not fixed here. (2) THE RUNG-4 ENROLLMENT CLAIM WAS WRONG AND IS WITHDRAWN. artifact_location, artifact_commit_policy, artifact_eq and artifact_generate are exhaustive, but generated_artifact_registry is an explicitly AUTHORED List: a variant can join the coproduct and every match arm while being omitted from the roster, and the tree still compiles with main_wet and the drift boundary blind to it. Only the narrower claim survives -- once a rostered variant is reached, its dispatch is compile-time exhaustive. Cut B takes the mechanically preventive correction (a discriminating RED that removes ONLY the registry member) and states the honest rung as mechanically preventable, with registry derivation named as the next-rung trigger. (3) required_ci_admission DOES NOT EXIST -- I invented the symbol. The real producer is gunbc.fleet_revision_acceptance accept_required_ci_workflow_run, reached in production through gunbc.fleet_desired_admission fleet_desired_accepted_from_event. Corrected in all four places, and the epoch RED must traverse that live composition. Also names what the selected route requires: the epoch as a STRUCTURAL top-level env member emitted by gunbc.witness_floor_workflow beside the four existing GUNBC_* pairs -- not a comment or substring -- with an exact-commit reader, a structural parser, six distinct typed causes, and the binding that the bytes read are the definition the observed run executed. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_014iheRFn4BiVGDwgN6gQBQX * ROOT-2 plan: the four-item bar at d038356 1. THE EPOCH EXPERIMENT WAS CONTRADICTORY. The epoch is a structural member of a committed artifact, so changing it changes the tree and therefore the commit identity -- 'hold the revision fixed, vary only the observed epoch' is not constructible against a real Git-backed read. The experiment is now two commits whose trees differ only in the epoch member, both revision-bearing propositions agreeing inside each case, and it traverses fleet_desired_accepted_from_event so at least one real production-composition execution is enrolled. The epoch carrier and its canonical wire representation are named: one top-level env key emitted by the workflow authority, one spelling, no alternate encodings. 2. THE INVERSE QUALITY ORDER IS NOW A LAW, not boundary examples: quality(a) >= quality(b) iff elapsed(a) <= elapsed(b); meets iff elapsed <= limit; breaches iff elapsed > limit. Equality belongs to the admitted side BY THE LAW rather than by convention. Without this a numerical ceiling had merely been renamed a floor. 3. THE RECEIPT SECTION OVERCHARGED EXISTING MACHINERY. ReceiptMemberAbsent and ReceiptMemberMalformed already exist, including duplicated-member, wrong-JSON-type and empty-string cases, plus the subject join. The genuinely missing work is the live writer, the upload, the run-bound download, epoch carriage, transport unavailability and any absent incomplete-run projection. And the stale present-tense recital finding may not live only in a file that Cut B deletes: its persistent destination is a routed item against the receipt authority's owning lane, opened before Cut A lands, or the recital is repaired before dissolution. 4. Module names are read from the module DECLARATION rather than derived from the path: gunbc.fleet_revision_acceptance and gunbc.fleet_desired_admission, not gunbc.fleet.*. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_014iheRFn4BiVGDwgN6gQBQX * ROOT-2 plan: record the stale-recital finding's durable destination The precondition the authority set is satisfied. The finding was routed to node://adhoc-8d0de08a-242 and landed as gunbc#9858, disposition DELETE. That lane reproduced the census independently rather than inheriting it, and established the discriminator this plan could not: there is no PRODUCER at all, so the join is unreachable rather than merely unoccupied -- which separates deleting a dead model from silencing a quiet guard. Its durable home is a receipt on the reachability_read_as_occupancy row of gunbc.recurring_failure_mode, projected into docs/design-ledgers.md, which survives this plan's dissolution. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_014iheRFn4BiVGDwgN6gQBQX * ROOT-2 plan: freeze Cut A's contribution boundary on a measured blast radius The authority required the authority and consumer paths be rechecked immediately before the contribution boundary is frozen. Measured rather than estimated: - the identity type and its constructor occur in exactly three files -- one production module and two fleet witnesses; - the values carrying it (RequiredCiSucceeded, AcceptedFleetRevision) reach four production .dag modules and three witness modules; - it reaches NO Rust or seed surface at all. That last point is load-bearing for the atomic root cut: there is no seed mirror to synchronize, so Cut A needs no generated bridge and the emission machinery belongs entirely to Cut B. It also bounds the population the old two-field representation must disappear from in a single landing. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_014iheRFn4BiVGDwgN6gQBQX * ROOT-2 plan: close the two-item bar -- ContractEpoch value domain, truthful #9858 status 1. THE EPOCH VALUE DOMAIN WAS UNDEFINED. The plan named the container and location but not the language of valid values. ContractEpoch is now an opaque branded NonEmptyStr: the epoch is a discrete identity, not an ordered quantity, and nothing arithmetic is done with it, so a numeric or semver grammar would add interpretation no consumer needs. The container then closes the decision entirely -- missing key, duplicate key, non-string, empty string, nonempty string. EpochUndecodable IS REMOVED. Once the value is a nonempty string there is no further decode that can fail, so the arm had NO AUTHORABLE SUBJECT -- a permanently-green check that would later be cited as coverage, which §4b forbids at the top rung. It was in the draft for symmetry, which is exactly the wrong reason. Commit-unreadable and path-unreadable remain separate observation failures. 2. THE #9858 CLAIM WAS AHEAD OF THE FACTS WHEN THE AUTHORITY CHECKED IT -- I relayed 'landed' from a hand-off message rather than verifying. It has since merged, and I verified rather than re-relaying: merged at main@83fe4399d0, with the receipt present at origin/main INSIDE the reachability_read_as_occupancy row carrying the unreachable-versus-unoccupied discriminator, and projected into docs/design-ledgers.md. The sequencing rule is retained rather than dropped now that it is satisfied, because it is the reason the verification was performed: Cut A may be authored on plan approval, but may not land until a durable repair has landed AND is verified on main. Also records the authority's qualification that the seven-module blast radius is the MAXIMUM JUSTIFIED CLOSURE, not an obligation to edit every reachable module: a module that merely transports the generic carrier stays untouched, and every path in the Cut A diff must carry its own concrete reason. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_014iheRFn4BiVGDwgN6gQBQX --------- Co-authored-by: Brian Searls <briansearls1@gmail.com> Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Scope
Analysis-only placement study for the operator-supervised DESIGN authority edit.
This PR adds only
docs/plans/meaning-externalization-design-placement.md. It does not editgunbc.design_document,gunbc.recurring_failure_mode,DESIGN.md, ordocs/design-ledgers.md, and it does not perform the carved-out corpus-wide violation audit.Recommendation recorded
meaning_forkandexternalized_degradationrecurring-failure-mode rows in the later supervised edit;quality_floor_absentas a review test rather than minting a third ledger class.The plan traces the generated projection pipeline, inventories the exact direct and generated change set plus current section-reference surface, distinguishes the private PR #25 executing evidence from its prose-only premise, and ends with exact NOT APPLIED source copy for
gunbc.design_document.