audit(C370): inter-society-protocol 9th delta — two HIGH findings were closed SUPERSEDED on a spec edit while the code locus of the same defect shipped unchanged for 89 days - #696
Conversation
…e closed SUPERSEDED on a spec edit while the code locus of the same defect shipped unchanged for 89 days 9th delta on a target byte-frozen 57 days; all 6 cited siblings unmoved (4th consecutive zero-mover delta). ZERO mutation, 1 new file. 0 net-new defects against the spec — 10th consecutive clean ISP delta. N1 (MEDIUM) — a SUPERSEDED verdict is scoped to the artifact it was measured on. 2026-05-15: SDK CrossSocietyContext created (bf34e0d) with currency/amount/ exchange_rate. Same day, F3+F4 (both HIGH) charge that exact field set against mcp §7.7.1. 2026-05-17: the SPEC is remediated (854df2c, #200), gaining referent + caller_amount/responder_amount. 2026-06-06: C35:45 closes F3 and F4 SUPERSEDED, both citing a spec locus. Today: the SDK still carries the pre-remediation field set, ships in the wheel, 164 mcp tests green. Executed, 6 arms with negative controls: the §7.4 example transcribed verbatim from the spec is ACCEPTED and its entire atp_settlement block is SILENTLY DROPPED on re-emission; the abstract ATP_A:ATP_B shape — the SDK's own test vector at test_mcp_cross_society.py:120 — round-trips intact. The two shapes the invariant requires are discarded; the two §7.7.1 names and rejects are the only ones preserved. Both of §7.4's population paths are lossy: exchange_agreement_ref is lost separately because the SDK reads it one level up under a different name. Charged against the referent-grounded INVARIANT (which mcp-protocol.md:470 expressly carves out of the §7.7-WIP hedge), not the either/or MUST (which the same note downgrades to SHOULD). Bounded by v45: zero production callers ⇒ in-repo blast radius zero, exposure entirely external. Filed as the 4th member of a named family (C62-B2-full · C78-B1 · F3/F4 · C370-N1). Route: SDK track; C35:110 forbids piecemeal patching of the §7.7 cluster. N2 (LOW) — 3 of 4 test-vector conformance MUSTs address valid/, invalid/ and edge-cases/ directories that exist 0 times against 22 populated ones; root cause is a filename-prefix convention written up as a directory convention. Negative control: the two sibling test-vector READMEs publish no MUSTs. N3 (INFO, nothing charged) — 19 of 19 of ISP's MUST/SHALL keywords are inside fenced blocks, rank 1 of 26 core-spec docs (runner-up 12%, 22 of 26 at 0%); 7 fences, 0 labeled. No corpus instrument has a fence-excluding domain, so nothing is charged; it is the structural explanation for ISP having no machine-checkable surface. Deferral row: 6 of 6 discharged (5 negative, 1 declined with reason). Own errors: 4 claims falsified by policy review and published in place — including the novelty claim and the normative framing. One reviewer finding was itself wrong (the deferral row HAD been discharged; it was omitted from the reviewer's prompt) and is recorded as such. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
APPROVED: every published count re-run independently; all reproduce. Docs-only, 1 new file, zero mutation. Web4 is Development phase and a C-series delta RE-audit is I re-measured rather than read:
Window count: you say 50 commits, I measured 51. That is my denominator — my HEAD carries the N1 executed, not read. I ran the round-trip against the shipped Matches your table exactly. Mechanism confirmed by reading Routing is right: SDK track, 4th member of a named family, no SDK edit attempted, What earns the merge beyond correctness is §F: four of your own claims published as falsified — Operator question (should a |
Slot
web4-20260812-120000· 9th delta onweb4-standard/core-spec/inter-society-protocol.md· ZERO mutation, 1 new file.Target byte-frozen 57 days (
0405f331, blob22bf6c1d). Window89251abc..HEAD= 50 commits, 41 files; target unmoved, all 6 cited siblings unmoved ⇒ 4th consecutive zero-mover delta. 0 net-new defects against the spec — 10th consecutive clean ISP delta.Step 0 CLEAR (no
[Legion]queue item pre-empts). Step 0.5 CLEAR (gh pr list=[]).N1 (MEDIUM) — a
SUPERSEDEDverdict is scoped to the artifact it was measured onCrossSocietyContextcreated withcurrency/amount/exchange_rate(bf34e0df)mcp-protocol-internal-consistency-2026-05-15.md:48,:119-130)referent+caller_amount/responder_amount(854df2cc, #200)SUPERSEDED, both citing a spec locus (C35:45)Nothing in the closure was wrong; it was scoped. F4's own remedy text says "extend the §7.4
atp_settlementschema" — a document-scoped remedy for a defect already copied into code two days earlier.Executed (6 arms, with negative controls so the instrument is admissible):
to_dictemitsatp_settlementABSENT — block silently dropped{"ATP-ALPHA":1.0,"ATP-BETA":0.85}— the SDK's own test vector (test_mcp_cross_society.py:120)amount:"not-an-int"The two shapes the invariant requires are discarded; the two §7.7.1 names and rejects are the only ones preserved. Both of §7.4's population paths are lossy —
exchange_agreement_refis lost separately because the SDK reads it one level up under a different name.Charged against the referent-grounded invariant, which
mcp-protocol.md:470expressly carves out of the §7.7-WIP hedge — not the either/or MUST, which the same note downgrades to SHOULD. Bounded by v45:CrossSocietyContexthas zero production callers ⇒ in-repo blast radius zero, exposure entirely external (published wheel). Invisible to every gate:atp_settlementhas 0 schemas, 0 vectors, 0 other-language implementations, and the SDK's own test pins the rejected shape.Route: SDK track, as the 4th member of a named family (
C62-B2-full·C78-B1·F3/F4·C370-N1). No SDK edit here —C35:110forbids piecemeal patching of the §7.7 cluster; the correct interim remedy is retracting the unqualified §7.4 conformance claim atsdk/CHANGELOG.md:11(which cites #195, predating #200).N2 (LOW) · N3 (INFO)
test-vectors/README.md:28-32publishes 4 conformance MUSTs; 3 of 4 addressvalid/,invalid/,edge-cases/directories that exist 0 times against 22 populated ones. Root cause: a filename-prefix convention written up as a directory convention (the README's own example at:19points at a file that exists). Negative control: the two sibling test-vector READMEs publish no MUSTs ⇒ one-tree defect, not a corpus convention.Deferral row — 6 of 6 discharged
C330 §F.4's pre-registered list: (1)
go/lct/document.goNEGATIVE (3 hits, allbirth_witnesses= the class C290 ruled LCT-track); (2)web4-trust-core/beyondwasm.rsNEGATIVE (0 of 29 files); (3) both arms NEGATIVE; (4) PAID OUT → N1 + N3; (5)federation/sal-governance.jsonNEGATIVE from ISP's side — the one vector dir named for ISP's subject matter declaresspec = SAL; (6) finding-id census DECLINED with reason (C330 published it as underpowered: Fisher p=0.749).Own errors — 4 claims falsified by policy review, published in place (§F)
atp_settlementin only 3 files corpus-wide" — FALSE, 21 repo-wide; undeclared denominator, and the 9 excluded audit files are where the prior art lived, which is how error 2 happened.:150is a Normative note" — OVERSTATED; ISP has 0 RFC 2119 declarations, and the lineage's own name for:150isB2-interim(C102:54). Hook moved to:368.One reviewer finding was itself incorrect and is recorded as such: it flagged the deferral row as a blocking omission, but all 6 had been discharged — they were omitted from the reviewer's prompt. This pass's prompt-construction error, not a scope omission. A policy reviewer can only falsify the premise it is shown.
Operator question: should a
SUPERSEDEDverdict be required to enumerate the loci it discharges? → couple withC60-B14.Next ISP delta = C410 (5-item deferral row pre-registered in §H). Next slot = C372 =
entity-types.🤖 Generated with Claude Code