Skip to content

Plan DESIGN placement for meaning, externalization, and quality floor - #9769

Merged
gunbai-bot[bot] merged 6 commits into
mainfrom
docs/meaning-externalization-design-placement
Aug 31, 2026
Merged

gunbai-bot[bot] merged 6 commits into
mainfrom
docs/meaning-externalization-design-placement

Conversation

@briansrls

Copy link
Copy Markdown
Contributor

Scope

Analysis-only placement study for the operator-supervised DESIGN authority edit.

This PR adds only docs/plans/meaning-externalization-design-placement.md. It does not edit gunbc.design_document, gunbc.recurring_failure_mode, DESIGN.md, or docs/design-ledgers.md, and it does not perform the carved-out corpus-wide violation audit.

Recommendation recorded

  • place accuracy-of-meaning in §3 as the one-name/two-meanings dual of nicknaming;
  • place the service quality floor and named-degradation discipline in §4b;
  • place externalization once in §5, explicitly derived from §2 rather than duplicated there;
  • add proposed meaning_fork and externalized_degradation recurring-failure-mode rows in the later supervised edit;
  • leave quality_floor_absent as a review test rather than minting a third ledger class.

The plan traces the generated projection pipeline, inventories the exact direct and generated change set plus current section-reference surface, distinguishes the private PR #25 executing evidence from its prose-only premise, and ends with exact NOT APPLIED source copy for gunbc.design_document.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Aug 30, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-08-30T19:25:25.654608Z bee47b5 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@briansrls
briansrls force-pushed the docs/meaning-externalization-design-placement branch from bee47b5 to 7ea52e4 Compare August 30, 2026 19:23

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: bee47b5073

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@@ -0,0 +1,400 @@
# Meaning, externalization, and quality-floor placement in DESIGN

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Register the new plan in the document graph

Adding this file without a corresponding gunbc.plan.Plan or HandAuthoredDocBind leaves it outside doc_graph_roots_all(). On docs-only changes, test.claim.doc_reachability_witness.doc_graph_has_no_orphan_docs runs against the live docs/ tree and will therefore fail with this plan as an orphan; add a typed binding to the relevant DESIGN/recurring-failure-mode authority and a retirement condition.

Useful? React with 👍 / 👎.


## Current citation review surface

This is a literal section-anchor census at the reviewed public revision. It includes `§3`, `§4b`, and `§5` references plus the repository's observed `DESIGN section …` / `DESIGN …` spellings. The spelled-out aliases add no new §3 or §4b artifacts; `DESIGN 5` adds `docs/plans/deploy-convergence-observed-side.md` to the §5 set. These are review surfaces, not proposed edits.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Complete the claimed section-anchor census

This is not a literal census of the stated revision: for example, docs/plans/replacement-migration-doctrine.md contains all three anchors but appears in none of the lists, while compiler-guarantee-recovery-gap-analysis.md is likewise omitted from §3, §4b, and §5. A revision-scoped search also finds additional omissions such as compute-envelope-model.md, host-effect-orchestration.md, and representation-minimization.md, so the reported counts and downstream review surface are incomplete and could cause the supervised edit to skip affected documents.

Useful? React with 👍 / 👎.

Brian Searls and others added 2 commits August 30, 2026 20:55
- Breach / separate product / rung drop stated as a three-way partition;
  'named degradation is the honest declared rung drop' removed. A drop in
  the ability to verify a promise forces refusal, never authorizes silent
  below-floor delivery. P2 copy carries the same separation.
- Meaning-fork subject scoped by (naming surface, visible name, declared
  effective version/epoch) in P1 and the meaning_fork row; same-spelling
  reuse across declared scopes or version transitions stated legitimate.
- Plan terminal disposition (retain / delete / bind) declared an operator
  decision at approval time; no bind row proposed (#9767's self-registered
  bind acknowledged as correctly rejected).
- Re-baselined onto main@826824d2 with the delta assessed against the
  census surface.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QhdaHkmZPoQoeUWz5V2mzF
@gunbai-bot

gunbai-bot Bot commented Aug 30, 2026

Copy link
Copy Markdown
Contributor

ROOT-0 executed on this PR per the operator's serial program: #9767 closed (consolidated here); branch re-baselined onto main@826824d2 (merge commit; the three intervening commits touch no DESIGN authority, ledger, projection route, or §3/§4b/§5 citation surface); and the review's remaining corrections applied to the plan and its NOT-APPLIED copy:

  • breach / separate-product / §4b(3) rung-drop stated as a three-way partition, with the 'named degradation is the honest declared rung drop' sentence removed — a verify-capability drop forces refusal and never authorizes silent below-floor delivery (also now in the P2 copy);
  • meaning-fork subject scoped by (naming surface, visible name, declared effective version/epoch) in P1 and the meaning_fork row, with same-spelling reuse across declared scopes stated legitimate;
  • the plan's terminal disposition (retain / delete / bind) declared an operator decision at approval time; no bind row proposed.

Already present from this branch's own drafting and left standing: externalization defined independently of absorbing_fallback; no private-witness inflation (rows carry no receipts; the evidence-boundary section states what the private witness does and does not establish); no diagnostic_name_mechanism_silent subsumption; no bare_name_fork_lens reuse claim; the literal §3/§4b/§5 citation census (56/19/59).

Diff vs main is the single plan file. ROOT-0 gate: this PR now awaits operator approval of the exact NOT-APPLIED source copy; no DESIGN authority edit begins before that. — sent from jolly-swift-749

Brian Searls and others added 2 commits August 30, 2026 22:06
…; accountability boundary; regen preflight

- Citation census re-derived at the merged tree with the derivation command
  recorded in the plan; exact file identities retained (66 / 21 / 69 docs for
  §3 / §4b / §5 — replacement-migration-doctrine.md and machine-intake-design.md
  now present); false 56/19/59 counts removed; bare-§N classification rule
  stated (exception scan over docs defining their own §-headings).
- meaning_fork root object generalized to material semantic referent, with
  contract identity as one specialization (analysis and row).
- ProviderInterfaceBinding reclassified: legitimate same-spelling reuse across
  distinct naming surfaces plus a search-homonym hazard, not a direct specimen;
  shared-surface question deferred to the operator census.
- Externalization restated at responsibility-and-principal grain (analysis, P3
  copy, and 'the responsible actor' in the row); disclosed refusable
  pre-contract allocation named as the priced arm.
- ROOT-1 regen preflight completed: exact-tree repo-built gunbc only;
  private cgroup bound or GUNBC_MEMORY_BUDGET_BYTES from a named source,
  exported in the same dispatch; HostBudgetUnreadable is a correct line stop;
  installed binary recorded as a refusal receipt, not a route.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QhdaHkmZPoQoeUWz5V2mzF
@gunbai-bot

gunbai-bot Bot commented Aug 30, 2026

Copy link
Copy Markdown
Contributor

ROOT-0 delta report (per the HOLD ruling's item 9):

  • Head: 877bcbd474c2ead087f375d6f1c5906c7c19eba3 · Base R: main@0a6d177619267443c7f62ba271d00aed26c6c3db (merged in; diff vs main remains the single plan file).
  • Census (item 2): re-derived at the exact merged tree, derivation command recorded in the plan, exact file identities retained — §3: 66, §4b: 21, §5: 69 documents; replacement-migration-doctrine.md and machine-intake-design.md present; 56/19/59 removed. Bare-§N classification by exception scan: the only docs defining their own §-headings (self-host-cargo-refusal-root-partition.md, §10+; replacement-migration-doctrine.md, whose §3 heading itself names DESIGN §3) were read occurrence-by-occurrence — all refer to DESIGN.
  • Items 3–5: meaning_fork root object is now material semantic referent (contract identity one specialization); ProviderInterfaceBinding reclassified as same-spelling reuse across distinct naming surfaces + search-homonym hazard, shared-surface question deferred to the operator census; externalization restated at responsibility-and-principal grain in analysis, P3, and the row ('the responsible actor').
  • Item 6: ROOT-1 regen preflight completed in the transaction section (exact-tree repo-built binary; cgroup bound or named-source GUNBC_MEMORY_BUDGET_BYTES exported in the same dispatch; HostBudgetUnreadable = correct line stop; installed binary = refusal receipt, not a route).
  • Item 8, probe: BuildBuddy one-dispatch repo-built main_wet on this exact head ran to completion and git status --porcelain was empty — regen no-op on a plan-only tree, as required. Host-budget source used: runner VM /proc/meminfo MemTotal × 0.8 — with an honest instrument caveat: awk's %d clamped the value to 2147483647 bytes (INT_MAX), so the run in fact succeeded under a ~2 GiB budget with cap-bounded typed-cache eviction (cap=682, ~160 evictions). The ROOT-1 dispatch must compute the byte value with overflow-safe arithmetic so the printed receipt equals the intended derivation.
  • Item 8, CI: rust-unit-tests and required-witnesses-build pass on this head; required-witnesses-floor and fabric-evidence are in flight — I will follow up here when they conclude.

ROOT-1 remains blocked pending operator approval of this exact head. — sent from jolly-swift-749

@gunbai-bot

gunbai-bot Bot commented Aug 30, 2026

Copy link
Copy Markdown
Contributor

Follow-up to the item-9 report: CI concluded fully green on head 877bcbd474 — required-witnesses-build, required-witnesses-floor (19m7s), rust-unit-tests, and the witnesses aggregate all pass. Item 8 is complete; ROOT-0 awaits the operator's exact-head approval. — sent from jolly-swift-749

…where; provider adjacent-not-specimen; caused costs in the externalization row; operator terminal ruling recorded

- 'Add meaning_fork' subsection rewritten to the scoped-key / material-
  semantic-referent formulation; contract fields are the commercial
  specialization; the private premium-name case is the direct specimen and
  ProviderInterfaceBinding is adjacent, consistent with the earlier section.
- meaning_fork row's recognition sentence concludes on the referent first,
  contract fields as sufficient evidence.
- externalized_degradation row widened to accepted-obligation-or-caused-cost
  -> burden shifted to another principal, with the disclosed pre-contract
  transfer arm and refusable-transfer wording.
- P3 final sentence: 'another principal', not 'the counterparty'.
- Terminal disposition records the operator ruling: plan deleted in ROOT-1
  in the consuming PR; no HandAuthoredDocBind.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QhdaHkmZPoQoeUWz5V2mzF
@gunbai-bot

gunbai-bot Bot commented Aug 30, 2026

Copy link
Copy Markdown
Contributor

Final consistency patch applied per the approvability re-check: head is now bbe0d9d2cc8d35754183e6a54c02bc0999805f42, still exactly one changed file vs main@0a6d1776.

  1. 'Add meaning_fork' subsection rewritten to the scoped-key / material-semantic-referent formulation (naming surface in the key; contract fields as the commercial specialization; the private premium-name case is the direct specimen; ProviderInterfaceBinding is adjacent, consistent with the earlier section).
  2. The NOT-APPLIED meaning_fork row's recognition sentence now concludes on the referent first, contract fields as sufficient evidence.
  3. The NOT-APPLIED externalized_degradation row widened to accepted-obligation-or-caused-cost → burden shifted to another principal, with the disclosed pre-contract transfer arm.
  4. P3's final sentence says 'another principal'.
  5. The operator terminal ruling is recorded: this plan is deleted in ROOT-1 in the same PR that consumes its copy; no HandAuthoredDocBind.

No census, probe, authority, projection, bind, or lens change; ordinary CI is rerunning on this head. Awaiting operator approval of this exact head to open ROOT-1. — sent from jolly-swift-749

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ROOT-0 EXACT-HEAD RULING: APPROVED at bbe0d9d.

GitHub does not permit the connected account to submit a formal APPROVE review on its own PR, so this comment records the side-chat reviewing-authority ruling rather than a GitHub approval state.

Accepted: the plan-only boundary; exact-tree citation census; scoped material-semantic-referent rule; breach / separate-product / §4b(3)-rung-drop partition; responsibility-and-principal externalization rule; honest private-evidence boundary; ROOT-1 regeneration preflight; and terminal plan deletion with no HandAuthoredDocBind.

Merge only after the current exact-head workflow completes green. ROOT-1 may then begin from the exact merged main revision; it must consume the approved NOT-APPLIED copy, regenerate DESIGN.md and docs/design-ledgers.md, and delete this plan in the same supervised PR. This approval authorizes no lens and no corpus-wide audit.

@gunbai-bot

gunbai-bot Bot commented Aug 30, 2026

Copy link
Copy Markdown
Contributor

ROOT-0 is complete and merge-ready at bbe0d9d2cc: exact-head reviewing-authority approval granted (recorded as a COMMENT review — GitHub refuses a formal APPROVE from the PR-owning account); CI fully green on this head (build, floor 20m42s, unit tests, fabric-evidence, aggregate); dashboard merge criteria all satisfied (1 distinct approval, no active REQUEST_CHANGES — review 57653's findings from head 7ea52e45 were addressed by the two subsequent delta commits; MERGEABLE; checks passing). Per the standing manual-merge policy I am not running the merge myself — operator merges. ROOT-1 then starts from the merged revision: consume the approved copy into gunbc.design_document / gunbc.recurring_failure_mode, regenerate DESIGN.md + docs/design-ledgers.md, and delete this plan in the same PR, no bind. — sent from jolly-swift-749

@gunbai-bot
gunbai-bot Bot merged commit 2603a63 into main Aug 31, 2026
5 checks passed
@gunbai-bot
gunbai-bot Bot deleted the docs/meaning-externalization-design-placement branch August 31, 2026 01:24
gunbai-bot Bot pushed a commit that referenced this pull request Aug 31, 2026
…py into the DESIGN authorities; the plan retires with its consumer

Applies the operator-approved source copy from #9769 (approved at
bbe0d9d, merged as 2603a63) verbatim:
- gunbc.design_document section_3_blocks: the meaning-fork paragraph after
  the nicknaming paragraph; section_4b_blocks: the quality-floor paragraph
  after the four meta-obligations; section_5_blocks: the externalization
  paragraph after the absorbing-fallback paragraph.
- gunbc.recurring_failure_mode: meaning_fork and externalized_degradation
  rows appended, roster extended in source order; evidence stays empty per
  the module's own standing note.
- docs/plans/meaning-externalization-design-placement.md DELETED per the
  operator terminal ruling: the supervised edit was its one consumer, and
  retaining it would leave a second prose representation of the live
  authority. No HandAuthoredDocBind. The merged #9769 and git history
  retain the placement analysis and review record.

Projections regenerate in the follow-up commit of this same PR.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QhdaHkmZPoQoeUWz5V2mzF
gunbai-bot Bot pushed a commit that referenced this pull request Aug 31, 2026
…, XL-R-4A rebuild scope #9765, DESIGN placement plan #9769). Conflicts: 5 regen-owned stage0 mirrors taken ours from the ef328db8 converged tree — regen fixes forward; main's hand-maintained required_regen_host.rs auto-merged from main.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GXfYKNQTD3VfYyQcnJpxNU
gunbai-bot Bot pushed a commit that referenced this pull request Aug 31, 2026
Conflict in dag/gunbc/recurring_failure_mode.dag: main's #9769 appended
surface_shorthand_preempts_resolved_identity while this branch appended
coarser_parallel_authority; both also appended to the roster. Kept both,
main's first, in the declaration region and the roster.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01N8xvN1T1NKiJqCUqwEmDgK
gunbai-bot Bot added a commit that referenced this pull request Aug 31, 2026
…py into the DESIGN authorities (#9786)

* ROOT-1: consume the approved meaning/externalization/quality-floor copy into the DESIGN authorities; the plan retires with its consumer

Applies the operator-approved source copy from #9769 (approved at
bbe0d9d, merged as 2603a63) verbatim:
- gunbc.design_document section_3_blocks: the meaning-fork paragraph after
  the nicknaming paragraph; section_4b_blocks: the quality-floor paragraph
  after the four meta-obligations; section_5_blocks: the externalization
  paragraph after the absorbing-fallback paragraph.
- gunbc.recurring_failure_mode: meaning_fork and externalized_degradation
  rows appended, roster extended in source order; evidence stays empty per
  the module's own standing note.
- docs/plans/meaning-externalization-design-placement.md DELETED per the
  operator terminal ruling: the supervised edit was its one consumer, and
  retaining it would leave a second prose representation of the live
  authority. No HandAuthoredDocBind. The merged #9769 and git history
  retain the placement analysis and review record.

Projections regenerate in the follow-up commit of this same PR.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QhdaHkmZPoQoeUWz5V2mzF

* ROOT-1: regenerate the projections from the exact merged tree

Produced by tools.generated_artifact_gate.main_wet via the repo-built gunbc
from tree 8965ebf, executed on srv2 (arm64) in a rust:1-bookworm container
under a 16 GiB docker cgroup memory bound — the modeled host-budget source,
no environment override needed. Generated diff is exactly DESIGN.md (three
paragraphs at their three anchors + two failure-mode index identities) and
docs/design-ledgers.md (two entries appended in roster order).

The BuildBuddy dispatches from the same tree ran main_wet to ExitSuccess
with an EMPTY diff — recorded as an infrastructure anomaly (suspect: runner
workspace reuse serving a stale tree), not a property of the transaction;
the srv2 run from a fresh clone of the pinned SHA is the receipt.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QhdaHkmZPoQoeUWz5V2mzF

* Repair the merge splice: close surface_shorthand_preempts_resolved_identity's row (the conflict's common tail had been consumed by the appended rows)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QhdaHkmZPoQoeUWz5V2mzF

* Regenerate projections from the repaired merge tree (0566b5f): restore #9741's surface_shorthand identity to the DESIGN index and its ledger entry, roster order preserved

Produced by main_wet via the repo-built binary on srv2 (fresh clone, 16 GiB
cgroup bound), same route as the ROOT-1 regen receipt.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QhdaHkmZPoQoeUWz5V2mzF

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
gunbai-bot Bot pushed a commit that referenced this pull request Sep 1, 2026
…nstruction cuts (#9851)

* ROOT-1: consume the approved meaning/externalization/quality-floor copy into the DESIGN authorities; the plan retires with its consumer

Applies the operator-approved source copy from #9769 (approved at
bbe0d9d, merged as 2603a63) verbatim:
- gunbc.design_document section_3_blocks: the meaning-fork paragraph after
  the nicknaming paragraph; section_4b_blocks: the quality-floor paragraph
  after the four meta-obligations; section_5_blocks: the externalization
  paragraph after the absorbing-fallback paragraph.
- gunbc.recurring_failure_mode: meaning_fork and externalized_degradation
  rows appended, roster extended in source order; evidence stays empty per
  the module's own standing note.
- docs/plans/meaning-externalization-design-placement.md DELETED per the
  operator terminal ruling: the supervised edit was its one consumer, and
  retaining it would leave a second prose representation of the live
  authority. No HandAuthoredDocBind. The merged #9769 and git history
  retain the placement analysis and review record.

Projections regenerate in the follow-up commit of this same PR.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QhdaHkmZPoQoeUWz5V2mzF

* ROOT-1: regenerate the projections from the exact merged tree

Produced by tools.generated_artifact_gate.main_wet via the repo-built gunbc
from tree 8965ebf, executed on srv2 (arm64) in a rust:1-bookworm container
under a 16 GiB docker cgroup memory bound — the modeled host-budget source,
no environment override needed. Generated diff is exactly DESIGN.md (three
paragraphs at their three anchors + two failure-mode index identities) and
docs/design-ledgers.md (two entries appended in roster order).

The BuildBuddy dispatches from the same tree ran main_wet to ExitSuccess
with an EMPTY diff — recorded as an infrastructure anomaly (suspect: runner
workspace reuse serving a stale tree), not a property of the transaction;
the srv2 run from a fresh clone of the pinned SHA is the receipt.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QhdaHkmZPoQoeUWz5V2mzF

* Repair the merge splice: close surface_shorthand_preempts_resolved_identity's row (the conflict's common tail had been consumed by the appended rows)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QhdaHkmZPoQoeUWz5V2mzF

* Regenerate projections from the repaired merge tree (0566b5f): restore #9741's surface_shorthand identity to the DESIGN index and its ledger entry, roster order preserved

Produced by main_wet via the repo-built binary on srv2 (fresh clone, 16 GiB
cgroup bound), same route as the ROOT-1 regen receipt.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QhdaHkmZPoQoeUWz5V2mzF

* ROOT-2 plan: contract identity and the quality floor as two serial construction cuts

Cut A generalizes the existing gunbc.fleet RequiredCiContractIdentity grain to the
DESIGN §3 triple (naming surface, name, epoch) rather than minting a second
contract-identity authority. The live gap it closes: required_ci_admission checks
workflow path and repository with per-cause refusals and then admits, carrying no
epoch, so a materially changed contract is admitted under the same workflow_path —
the §3 meaning fork, in production.

Cut B instantiates that identity for std.evaluation_budget: a graded dimension with
a typed consequence, consumed in production. The consequence-ownership fork is
adjudicated to Terminal A on four recorded pieces of evidence, the discriminator
being that no caller refusal-code protocol exists for a caller-owned code to belong
to. LimitUnset constructs no floor on that clock; the consequence derives from the
closed exceeded arm rather than caller-supplied text.

The two REDs are separate instruments with separate cardinalities — a semantic
breach RED with its two admitted controls, and an authority-wiring falsifier — and
the plan says in terms that 'some RED occurs' establishes nothing.

The plan names itself as dissolved by the second cut. Neither cut edits DESIGN.md
or gunbc.design_document.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014iheRFn4BiVGDwgN6gQBQX

* ROOT-2 plan, amended per the reviewing authority's five corrections

1. Cut A is an ATOMIC ROOT CUT, not an additive shadow: the public name
   RequiredCiContractIdentity may survive as a specialization of the canonical
   triple, but its old two-field representation is eliminated in the same landing.
   The three unacceptable shapes (field-beside-canonical, old/new/converter, shadow
   comparator) are named, and the field classification table keeps contract identity
   from widening into every admission prerequisite.

2. The blocking omission is closed: the plan now names a production source of the
   OBSERVED epoch. Adding epoch to required_ci_contract() alone would stamp the
   EXPECTED epoch onto the result and prove nothing about what the triggering run
   executed. Route chosen: exact-commit observation at event.head_sha of an epoch
   emitted into WitnessFloorYamlArtifact -- the exact bytes the run executed. The
   typed-receipt route is rejected with its reason: floor_component_receipt_document
   has no production consumer, so nothing emits it today. Oracle independence is
   restated at the grain that matters, and the RED must traverse the production join.

3. Cut B does not duplicate entry: entry is projected from the contract identity, and
   the verdict stays identity-bound so no detached Within value crosses the boundary.

4. The wiring falsifier requires a MOVED VALUE, not a refusal -- an always-refusing
   emitter would otherwise pass while proving no binding. Drift RED before regen,
   perturbed value after, zero occurrences of the former code. The exhaustiveness
   mutation is separate and not a substitute. The generated projection's full
   enrollment chain is named.

5. The epoch guarantee is stated honestly: cross-epoch admission is mechanically
   prevented; an unbumped material change remains declared-version diligence. This
   cut does not make all same-name meaning forks structurally impossible.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014iheRFn4BiVGDwgN6gQBQX

* ROOT-2 plan: discharge the reachability obligation and the Terminal-A stop-lines

The Terminal-A ruling left one discovery obligation open -- the exact
authority-to-generated-Rust-to-serve_budget_refusal_body chain -- and set stop-lines
the earlier draft did not carry. All are now in the plan.

- THE TERMINAL CONSEQUENCE LAW. No freely writable consequence_code field on the
  policy, the contract identity or the exceeded arm, so a contract with an arbitrary
  or self-contradictory consequence is not constructible. And the zero-argument
  refusal-code fn is an authority over the BYTES that does not yet establish that the
  typed cause determines their DELIVERY; Cut B closes that edge, with the required
  property stated and the implementation shape left free.

- REACHABILITY PROVED, not asserted, with the actual symbols and a named census base:
  authority -> emitter -> GeneratedArtifact variant (coproduct, roster, location,
  commit policy, equality arm) -> artifact_generate arm -> main_wet generation and
  drift -> crate inclusion -> serve_budget_refusal_body -> rebuilt binary -> executed
  response. Every link is an exhaustive match over the variant set, so a half-enrolled
  artifact fails to compile -- enrollment is closed by construction rather than by an
  author remembering a checklist.

- NO SEMANTIC HITCHHIKING. The consequence gets a DEDICATED generated projection
  rather than riding v1_interpreter_dispatch_generated.rs, whose subject is
  interpreter primitive dispatch; mixing two authorities into one generated file is
  the same fork wearing a generated file's clothes. Generated bytes carrying the
  literal are fine -- an independently maintained literal in cli_run is not.

- The semantic RED's 'exactly one' is identified at the correct grain: one bounded
  clock crossed, one exceeded cause, one named consequence, one production response.

- Cut A carries no generated budget-consequence bridge merely because one plan
  describes both cuts.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014iheRFn4BiVGDwgN6gQBQX

* ROOT-2 plan: correct three substantive defects the reviewing authority found

(1) THE RECEIPT-ROUTE REJECTION PREMISE WAS FALSE AND IS WITHDRAWN. I had grepped
for the document constructor in .dag only and concluded nothing emits it. The
receipt is real, rich infrastructure: schema floor-component-receipt/v1, artifact
name, path, typed subject with workflow name/run id/head sha, decoder, event-subject
join. The re-census answers all six questions and reaches the same route on a
materially different basis: NOTHING writes target/floor-component-receipt.json in
src/ or dag/; witnesses.yml uploads four artifacts and this is not one; and the
alert that downloads it, falsifier-alert.yml, was DELETED in the 2026-08-15 CI
bankruptcy. The obstacle is a deleted transport, not a missing model -- and the
authority's prose still recites that transport in the present tense, which is the
premise-contamination class DESIGN §4b names. Recorded as a finding for that
module's owner, not fixed here.

(2) THE RUNG-4 ENROLLMENT CLAIM WAS WRONG AND IS WITHDRAWN. artifact_location,
artifact_commit_policy, artifact_eq and artifact_generate are exhaustive, but
generated_artifact_registry is an explicitly AUTHORED List: a variant can join the
coproduct and every match arm while being omitted from the roster, and the tree still
compiles with main_wet and the drift boundary blind to it. Only the narrower claim
survives -- once a rostered variant is reached, its dispatch is compile-time
exhaustive. Cut B takes the mechanically preventive correction (a discriminating RED
that removes ONLY the registry member) and states the honest rung as mechanically
preventable, with registry derivation named as the next-rung trigger.

(3) required_ci_admission DOES NOT EXIST -- I invented the symbol. The real producer
is gunbc.fleet_revision_acceptance accept_required_ci_workflow_run, reached in
production through gunbc.fleet_desired_admission fleet_desired_accepted_from_event.
Corrected in all four places, and the epoch RED must traverse that live composition.

Also names what the selected route requires: the epoch as a STRUCTURAL top-level env
member emitted by gunbc.witness_floor_workflow beside the four existing GUNBC_* pairs
-- not a comment or substring -- with an exact-commit reader, a structural parser, six
distinct typed causes, and the binding that the bytes read are the definition the
observed run executed.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014iheRFn4BiVGDwgN6gQBQX

* ROOT-2 plan: the four-item bar at d038356

1. THE EPOCH EXPERIMENT WAS CONTRADICTORY. The epoch is a structural member of a
   committed artifact, so changing it changes the tree and therefore the commit
   identity -- 'hold the revision fixed, vary only the observed epoch' is not
   constructible against a real Git-backed read. The experiment is now two commits
   whose trees differ only in the epoch member, both revision-bearing propositions
   agreeing inside each case, and it traverses fleet_desired_accepted_from_event so
   at least one real production-composition execution is enrolled. The epoch carrier
   and its canonical wire representation are named: one top-level env key emitted by
   the workflow authority, one spelling, no alternate encodings.

2. THE INVERSE QUALITY ORDER IS NOW A LAW, not boundary examples: quality(a) >=
   quality(b) iff elapsed(a) <= elapsed(b); meets iff elapsed <= limit; breaches iff
   elapsed > limit. Equality belongs to the admitted side BY THE LAW rather than by
   convention. Without this a numerical ceiling had merely been renamed a floor.

3. THE RECEIPT SECTION OVERCHARGED EXISTING MACHINERY. ReceiptMemberAbsent and
   ReceiptMemberMalformed already exist, including duplicated-member, wrong-JSON-type
   and empty-string cases, plus the subject join. The genuinely missing work is the
   live writer, the upload, the run-bound download, epoch carriage, transport
   unavailability and any absent incomplete-run projection. And the stale
   present-tense recital finding may not live only in a file that Cut B deletes: its
   persistent destination is a routed item against the receipt authority's owning
   lane, opened before Cut A lands, or the recital is repaired before dissolution.

4. Module names are read from the module DECLARATION rather than derived from the
   path: gunbc.fleet_revision_acceptance and gunbc.fleet_desired_admission, not
   gunbc.fleet.*.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014iheRFn4BiVGDwgN6gQBQX

* ROOT-2 plan: record the stale-recital finding's durable destination

The precondition the authority set is satisfied. The finding was routed to
node://adhoc-8d0de08a-242 and landed as gunbc#9858, disposition DELETE. That lane
reproduced the census independently rather than inheriting it, and established the
discriminator this plan could not: there is no PRODUCER at all, so the join is
unreachable rather than merely unoccupied -- which separates deleting a dead model
from silencing a quiet guard. Its durable home is a receipt on the
reachability_read_as_occupancy row of gunbc.recurring_failure_mode, projected into
docs/design-ledgers.md, which survives this plan's dissolution.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014iheRFn4BiVGDwgN6gQBQX

* ROOT-2 plan: freeze Cut A's contribution boundary on a measured blast radius

The authority required the authority and consumer paths be rechecked immediately
before the contribution boundary is frozen. Measured rather than estimated:

- the identity type and its constructor occur in exactly three files -- one
  production module and two fleet witnesses;
- the values carrying it (RequiredCiSucceeded, AcceptedFleetRevision) reach four
  production .dag modules and three witness modules;
- it reaches NO Rust or seed surface at all.

That last point is load-bearing for the atomic root cut: there is no seed mirror to
synchronize, so Cut A needs no generated bridge and the emission machinery belongs
entirely to Cut B. It also bounds the population the old two-field representation
must disappear from in a single landing.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014iheRFn4BiVGDwgN6gQBQX

* ROOT-2 plan: close the two-item bar -- ContractEpoch value domain, truthful #9858 status

1. THE EPOCH VALUE DOMAIN WAS UNDEFINED. The plan named the container and location
   but not the language of valid values. ContractEpoch is now an opaque branded
   NonEmptyStr: the epoch is a discrete identity, not an ordered quantity, and nothing
   arithmetic is done with it, so a numeric or semver grammar would add interpretation
   no consumer needs. The container then closes the decision entirely -- missing key,
   duplicate key, non-string, empty string, nonempty string.

   EpochUndecodable IS REMOVED. Once the value is a nonempty string there is no
   further decode that can fail, so the arm had NO AUTHORABLE SUBJECT -- a
   permanently-green check that would later be cited as coverage, which §4b forbids at
   the top rung. It was in the draft for symmetry, which is exactly the wrong reason.
   Commit-unreadable and path-unreadable remain separate observation failures.

2. THE #9858 CLAIM WAS AHEAD OF THE FACTS WHEN THE AUTHORITY CHECKED IT -- I relayed
   'landed' from a hand-off message rather than verifying. It has since merged, and I
   verified rather than re-relaying: merged at main@83fe4399d0, with the receipt
   present at origin/main INSIDE the reachability_read_as_occupancy row carrying the
   unreachable-versus-unoccupied discriminator, and projected into
   docs/design-ledgers.md. The sequencing rule is retained rather than dropped now
   that it is satisfied, because it is the reason the verification was performed:
   Cut A may be authored on plan approval, but may not land until a durable repair has
   landed AND is verified on main.

Also records the authority's qualification that the seven-module blast radius is the
MAXIMUM JUSTIFIED CLOSURE, not an obligation to edit every reachable module: a module
that merely transports the generic carrier stays untouched, and every path in the Cut A
diff must carry its own concrete reason.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014iheRFn4BiVGDwgN6gQBQX

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant