Skip to content

audit(C372): entity-types 9th delta — the §2.1 register cannot be applied to an entity, and the one shape it does validate certifies an empty registry as complete - #697

Merged
dp-web4 merged 1 commit into
mainfrom
worker/web4-20260812-180000
Aug 13, 2026

Conversation

@dp-web4

@dp-web4 dp-web4 commented Aug 13, 2026

Copy link
Copy Markdown
Owner

11th pass of the entity-types.md lineage (rotation C332 + 40). Target byte-frozen 29 days (blob a2dda417, 804 L, last moved 1354e4c2 #523 2026-07-14). ZERO mutation of the standard — one new audit document. Window 38d0bd89..HEAD = 50 commits / 41 files, target 0.

Gates: Step 0 (queue) CLEAR — no greenlit [Legion] item pre-empts the rotation. Step 0.5 CLEAR — gh pr list returned [] (zero open PRs corpus-wide, so an empty set rather than a filtered one).

Three findings, all executed rather than read

C372-N1 (MED) — the register schema cannot count. $defs/EntityTypeRegistry describes itself as "Full registry of all 15 canonical entity types" and carries no minItems/maxItems/uniqueItems. Executed with negative controls: empty registry PASS, human×15 PASS, 1 entry PASS; banana and agent both FAIL (enum not vacuous). The corpus's own MUST-FAIL set already holds the proof — entity-invalid-018 ships entity_types: [] charged solely for an unrelated additionalProperties key; strip it and the empty "full registry" passes. Denominator: 5 registry-shaped docs (2 MUST-PASS, 3 MUST-FAIL). Class bounded 2 of 12 schemas; the sibling (capability "all 6 levels", empty PASSES — also executed) is routed, not charged. Filed as a sharpening of C332-N1, not clean net-new: C332:218 was one hop away.

C372-N2 (MED) — adjudicates C364-N3, which is credited. §13.4's accountability-frame table keys on WAKE/FOCUS/REST/DREAM/CRISIS. C364 measured the forward direction (1 of 5 is a state) and routed adjudication here. This pass runs the operational complement through the SDK enum — an implementation holds a state and looks up the frame: 1 of 8 canonical metabolic states has one. WAKE is a transition trigger, FOCUS is a prose noun appearing once, CRISIS is prose describing TORPOR — and TORPOR, whose own spec description is "Crisis mode when resources critically low", resolves to NO FRAME, on the one table that sets the accountability equation.

C372-N3 (MED, net-new) — the §2.1 register is structurally unreachable for any real entity. entity-jsonld.schema.json's top-level oneOf admits only EntityTypeInfo and EntityTypeRegistry — documents about the taxonomy. Executed on a real LCT from the standard's own vector file: the control, a perfectly valid human LCT, returns FAIL(shape) — so the unreachability is structural, not type-dependent. An agent LCT PASSES the enforced schema and raises ValueError in the Python SDK, while Go (document.go:381) and TS (lct-document.ts:397) also reject it. This is the mechanism that let C368-N1 survive 145 days of green gates.

C368-N1: CONFIRMED, zero increment (already recorded at C368:123). Adds dates: agent entered 2026-03-20; the 15-value register was authored 3 days later; contradicting for 142 days.

Deferral ledger — 6 of 6 discharged, 4 NEGATIVE

row disposition
d1 role-extension 0 commits ⇒ C292-N1 STANDS, 3rd pass
d2 slashed sites 3→3C332-N2 STANDS, 57 d
d3 contexts/entity.jsonld opened first time in 11 passes — term mappings only, no enum ⇒ escalation hypothesis REFUTED
d4 ROUTED, not executed (C120→C121 corpus-sweep hazard); receiving slots named
d5 RFC claims substantively CORRECT (:579 MUST / :581) ⇒ independently confirms C332-N3's 518+63=581
d6 no §10 contradiction; summary IS indexed ⇒ confirms C364's scoping

v36 inbound set-difference: residue 8 files, 0 postdating C332 — NEGATIVE, recorded.

§own-error — 5

Policy review falsified this pass's proposed headline ("§2.1 has zero enforcement over the objects it governs"): three implementations enforce the 15 on real bindings, and C332:240/:419/:182 had already recorded it three separate times — the lineage's own predecessor contained the falsifier and this pass did not check it before drafting. The narrower schema-layer claim survives as N3. N1's strongest evidence (entity-invalid-018) was the reviewer's, not this pass's — the MUST-FAIL set was never enumerated (a v46 denominator error). The class-bounding instrument returned 0 and was believed for one step.

Two reviewer corrections were themselves wrong and were not adopted, both verified against the files first: the §13.4 anchor :779-783 is exact (:785 is the following prose), and the pass counter is 7th per C332:416, not 8th. The reviewer's C332:243 cite was off by three lines — caught by verifying the very citation that exposed this pass's own error.

Hazard named for successors: sdk/web4/validation.py's validate() does not raise (raise_on_error=False); any try/except harness reports 100% PASS on every input, including negative controls. The reviewer's first independent run hit exactly this trap — it manufactures the false green C332-N1 was charging.

Out-of-slot observations routed and deliberately not charged: sdk-test.yml path-filter, schema_registry.json content-drift, test_lct_jsonld_vectors.py:285-301's contradicting 15-value set.

Nothing self-applied — all three findings are author/operator rulings on a byte-frozen normative document plus conformance vectors. Deferral ledger for C412 left with 5 named rows.

🤖 Generated with Claude Code

…lied to an entity, and the one shape it does validate certifies an empty registry as complete

11th pass of the entity-types lineage (rotation C332+40). Target byte-frozen 29 days
(blob a2dda41, 804 L, last moved 1354e4c #523 2026-07-14). ZERO mutation of the
standard; one new audit document.

Three findings, all executed rather than read:

- C372-N1 (MED, sharpens C332-N1): entity-jsonld.schema.json $defs/EntityTypeRegistry
  describes itself as "Full registry of all 15 canonical entity types" and carries no
  minItems/maxItems/uniqueItems. Executed with negative controls: empty registry PASS,
  human x15 PASS, 1 entry PASS; "banana" and "agent" both FAIL (enum not vacuous). The
  corpus's own MUST-FAIL set already contains the proof — entity-invalid-018 ships
  entity_types: [] charged solely for an unrelated additionalProperties key; strip it and
  the empty "full registry" passes. Denominator: 5 registry-shaped docs (2 MUST-PASS,
  3 MUST-FAIL). Class bounded 2 of 12 schemas; sibling (capability "all 6 levels", empty
  PASSES) routed, not charged. C160:88's ratified deflation engaged and partially
  sustained -> MED, not HIGH.

- C372-N2 (MED, adjudicates C364-N3, credited): §13.4's accountability-frame table keys on
  WAKE/FOCUS/REST/DREAM/CRISIS. C364 measured the forward direction (1 of 5 is a state);
  this pass runs the operational complement through the SDK enum: 1 of 8 canonical
  metabolic states has a frame. WAKE is a transition trigger, FOCUS is a prose noun
  appearing once, CRISIS is prose describing TORPOR — and TORPOR, whose own spec
  description IS "Crisis mode when resources critically low", resolves to NO FRAME on the
  table that sets the accountability equation. MED on modality (§13.4 carries no MUST;
  the doc has 6 total).

- C372-N3 (MED, net-new): the §2.1 register is structurally unreachable for any real
  entity — entity-jsonld.schema.json's top-level oneOf admits only EntityTypeInfo and
  EntityTypeRegistry. Executed on a real LCT from the standard's own vector file: the
  control (a valid `human` LCT) returns FAIL(shape), so the unreachability is structural,
  not type-dependent. An `agent` LCT PASSES the enforced schema and raises ValueError in
  the Python SDK, while Go (:381) and TS (:397) also reject it. This is the mechanism that
  let C368-N1 survive 145 days of green gates.

C368-N1 CONFIRMED with zero increment (already at C368:123); adds the dates — `agent`
entered 2026-03-20, the 15-value register was authored 3 days later, contradicting for 142 d.

Deferral ledger 6 of 6 discharged, 4 NEGATIVE: d1 role-extension frozen (C292-N1 stands,
3rd pass); d2 3->3 (C332-N2 stands, 57 d); d3 contexts/entity.jsonld opened for the first
time in 11 passes — term mappings only, no enum, escalation hypothesis REFUTED; d4 ROUTED
not executed (C120->C121 corpus-sweep hazard), receiving slots named; d5 the RFC claims are
substantively CORRECT and independently confirm C332-N3's 518+63=581 arithmetic; d6 no §10
contradiction and the summary IS indexed, confirming C364's scoping. v36 inbound
set-difference: residue 8 files, 0 postdating C332 — NEGATIVE, recorded.

§own-error: 5. Policy review FALSIFIED this pass's proposed headline ("§2.1 has zero
enforcement") — three implementations enforce the 15 on real bindings, and C332:240/:419/:182
had already recorded it, so the lineage's own predecessor contained the falsifier. The
narrower schema-layer claim survives as N3. N1's strongest evidence (entity-invalid-018) was
the reviewer's, not this pass's — the MUST-FAIL set was never enumerated (v46 error). The
class-bounding instrument returned 0 and was believed for one step. Two reviewer corrections
were themselves WRONG and were not adopted (the §13.4 anchor :779-783 is exact, not :785;
the pass counter is 7th per C332:416, not 8th) — and the reviewer's C332:243 cite was off by
three lines, caught by verifying the citation that exposed the error.

Also named for successors: sdk/web4/validation.py's validate() does NOT raise
(raise_on_error=False), so any try/except harness reports 100% PASS on every input including
negative controls — the reviewer's first independent run hit exactly this trap.

Out-of-slot observations routed, deliberately not charged: sdk-test.yml path-filter,
schema_registry.json content-drift, test_lct_jsonld_vectors.py:285-301's contradicting
15-value set.

Accountability self-audit: not applicable — this diff adds one markdown audit document and
creates no surface, no caller-drivable path, and no consequential act.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@dp-web4

dp-web4 commented Aug 13, 2026

Copy link
Copy Markdown
Owner Author

APPROVED: all three findings independently re-executed at PR head; two were reproduced with the audit's own negative controls, and both reviewer-corrections the pass rejected were verified correct to reject.

C372-N1 — reproduced, including the control set. Against schemas/entity-jsonld.schema.json (Draft 2020-12) with the corpus's own entity-valid-009 as the base:

  • empty entity_types: [] -> PASS
  • same entry x15 -> PASS (no uniqueItems)
  • single entry -> PASS
  • entity_type: banana -> FAIL — the enum is not vacuous, so the schema is live and it still cannot count.

$defs/EntityTypeRegistry.properties.entity_types carries {type: array, description} and nothing else — no minItems/maxItems/uniqueItems — under a description reading "Full registry of all 15 canonical entity types."

And the audit's strongest evidence holds exactly as stated: entity-invalid-018 ships entity_types: [], its own reason field is "EntityTypeRegistry with extra field (additionalProperties: false)", and stripping the single offending key (version) flips it to PASS. The MUST-FAIL set does contain the proof. Denominator confirmed independently: 5 registry-shaped docs (entity-valid-009/010, entity-invalid-016/017/018) — 2 MUST-PASS, 3 MUST-FAIL, matching the published figure.

C372-N3 — reproduced, and the control is the load-bearing part. Every binding object in test-vectors/lct/lct-jsonld-vectors.json and .../lct-jsonld-validation.json returns FAIL against the register schema, and the MUST-PASS human LCT fails with the identical is not valid under any of the given schemas as the MUST-FAIL alien one. The unreachability is structural (the top-level oneOf admits only EntityTypeInfo / EntityTypeRegistry), not type-dependent — which is what makes it the mechanism rather than a restatement of C368-N1.

C372-N2 — confirmed. sdk/web4/metabolic.py:62-72 is an 8-value enum (ACTIVE, REST, SLEEP, HIBERNATION, TORPOR, ESTIVATION, DREAMING, MOLTING). §13.4's frame table keys on WAKE/FOCUS/REST/DREAM/CRISIS, so exactly 1 of 8 resolves — and TORPOR, whose own spec comment is "Emergency conservation", gets no frame on the one table that sets the accountability equation while CRISIS sits there as the duress row. The operational-complement direction is a genuine adjudication of C364-N3, not a re-run of it.

Both rejected reviewer corrections verified before accepting the rejection. §13.4's table occupies :779-783 exactly and :785 is the following CRISIS mode changes the accountability equation prose — the pass's anchor is right and the correction was wrong. Refusing a reviewer correction and being right is the harder half of §own-error, and it was done by verifying against the file rather than by preference.

§own-error is the real quality signal here. The pass published that policy review falsified its own proposed headline, that its predecessor C332 already contained the falsifier three times over, and that N1's best evidence came from the reviewer rather than from this pass — a v46 denominator error, named as such. The validation.py raise_on_error=False hazard is worth the callout: a try/except harness over that call reports 100% PASS on every input including negative controls, which is precisely the false green the finding charges. That is why my own run above reads verdicts off iter_errors instead.

Scope: 1 file, +421/-0, a new audit document. Zero mutation of the standard, zero self-application — all three findings are author/operator rulings on a byte-frozen normative document. d3's escalation hypothesis was published as REFUTED as prominently as a confirmation, and 4 of 6 deferral rows came back negative and were reported as such. Merging.

@dp-web4
dp-web4 merged commit 4dc2b5d into main Aug 13, 2026
4 checks passed
@dp-web4
dp-web4 deleted the worker/web4-20260812-180000 branch August 13, 2026 05:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant