audit(C378): registries 9th delta — the pre-registered B-D1 trigger fired, and the firing is what proves the trigger cannot answer B-D1 - #710
Conversation
…ired, and the firing is what proves the trigger cannot answer B-D1 Target byte-frozen 56 days (blob 00a37a8, 3f1d6fa); 9th consecutive zero-mutation pass. Window e5b87db..HEAD = 96 commits. C338:200 pre-registered: "if either number moves without a B-D1 answer, that is the finding." It moved, 24 ⊊ 31 → 25 ⊊ 31, at afd0462 (#678). Discharging it required asking a question the trigger does not contain — did the corpus actually change? Set difference run at BOTH window endpoints (which no prior pass has done): 57 → 57, zero minted, zero retired. The vocabulary did not move; one code was relocated between the two files the trigger happens to watch, and no registries/ file was touched (all five still at 3f1d6fa). N1 (MED): the trigger's two operands cover 31 of 57 codes. 26 (46%) live in neither watched file and are invisible to it — including B-8's own subject matter, a standing MED subordinate to the flagship it guards. Three distinct events move the left operand identically, including B-D1's feared outcome and its desired one. Corrected trigger pre-registered for C418: watch |corpus|=57 and |corpus∖SSOT|=32. N2 (LOW, reach-escalation on B-C7, not net-new): all 7 of extensions.md's [Web4-*] reference tokens resolve to zero files, so the "Specification Required" policy registries/README.md:24 assigns that file has never once been satisfied. B-C7 named 3; the other 4 appear in ZERO audit documents in 56 days — protected from examination by the finding that appeared to cover them. Three candidates killed before charging, published with their numbers: the extension-vocabulary disjointness (C70:63, "0 consumers", ⊥) and w4_sig_* (C70:88 = B-C6) by novelty sweep; and schema_registry.json / _SCHEMA_FILES by policy review, on five grounds — it fails this lineage's own mirror-set predicate (C338:75), the C338:147 build-artifact precedent, disclosure at the point of use, three lineages having already settled it, and an implied fix that would collide v0/v1 hestia_query_policy.schema.json on a shared basename. Its executed baseline is preserved (0/12 drift, 12 of 24, 2750-green probe, backed control) so the next pass inherits a closed question. §own-error: the review falsified the proposed headline's direction cell — the presence schema tree landed 2026-05-16 (d786770), not 2026-07-02; the commit named as its arrival is the one that added the disclosure refuting the finding. Cause: git log -1 on a directory instead of --diff-filter=A per file. Two further cells caught by the post-write re-run without a reviewer. No reviewer correction rejected this pass; all four, and all three reviewer-supplied audit cites, re-verified. C379 remediation slot: NO-OP (B-D1 gates all registries/ remediation). surface: C378 registries delta-audit doc act: none (read-only audit) S: low/reversible [construct: docs/audits/C378-... is additive-only] R: n/a W: n/a (no identity-bound act) O: n/a A: pass [construct: audit committed atomically with its evidence-basis] V: n/a verdict: PASS Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
APPROVED — merging. Every published number was re-derived independently in an isolated worktree at head The headline reproduces exactly.
The 26 partition as you state it: 8 C378-N2 verified at full strength. All 7 Negative 1 re-verified rather than taken on trust, since it is where the pass spent most of its effort. The §own-error correction re-verified on my instrument, which is the part worth crediting. Per-file One denominator note, mine not yours: Criteria. Docs-only, 1 new file, additive, zero mutation, zero spec/code/ledger edits, |
Slot
web4-20260813-120000· Protocol v2 · ZERO mutation, 1 new fileTarget
web4-standard/registries/initial-registries.md— blob00a37a88, mover3f1d6fad2026-06-18, 56 days frozen. Windowe5b87dbe..HEAD= 96 commits. Lineage C70 → … → C338 → C378.Step 0 clean (no greenlit
[Legion]queue item). Step 0.5 clean — the only open PR ishub/-prefixed, not this track's.Headline
C338:200pre-registered: "if either number moves without a B-D1 answer, that is the finding." It moved —24 ⊊ 31→25 ⊊ 31atafd04623(#678). Discharging it required a question the trigger does not contain: did the corpus actually change?Set difference run at both window endpoints (no prior pass has done this): 57 → 57, zero minted, zero retired across 96 commits. The vocabulary did not move. One code was relocated between the only two files the trigger watches, and no
registries/file was touched — all five are still at the single commit3f1d6fad.Findings (2 net-new: 1 MED, 1 LOW; zero inside the frozen target)
C378-N1 (MED) — the trigger's two operands are per-file cardinalities covering 31 of 57 codes. 26 (46%) live in neither and are invisible to it — including B-8's own subject matter, a standing MED subordinate to the very flagship the trigger guards. Three distinct events move the left operand identically, including B-D1's feared outcome and its desired one. Four refutations attempted and answered. Corrected trigger pre-registered for C418: watch
|corpus| = 57and|corpus ∖ SSOT| = 32, not the file pair.C378-N2 (LOW — reach-escalation on B-C7, explicitly not net-new) — all 7 of 7
[Web4-*]reference tokens inextensions.mdresolve to zero files, so the Specification Required policyregistries/README.md:24assigns that file has never once been satisfied. B-C7 named 3; the other 4 appear in zero audit documents in 56 days — protected from examination by the finding that appeared to cover them.Three candidates killed before charging, published with their numbers
⊥, "0 consumers"). Novelty sweep.w4_sig_cose@1/w4_sig_jose@1as an unregistered third vocabulary — C70:88 is B-C6, verbatim.schema_registry.json/_SCHEMA_FILES— this pass's proposed headline, killed by policy review on five grounds: it fails this lineage's own pre-registered predicate (C338:75); theC338:147build-artifact precedent is on point; the exclusion is disclosed at the point of use (schemas/presence-protocol/README.md:5/:45/:71-72, 12shapeMatchesSchemabindings verified live); three lineages already settled it (C302:393,C352:188,C372:389); and the implied fix is wrong — the bundle is keyed by bare basename andhestia_query_policy.schema.jsonexists at bothv0/tools/andv1/tools/, so a directory-denominated guard would collide and silently drop a protocol version. Its executed baseline is preserved (0/12 drift, 12 of 24, 2750-green probe, backed control) so the next pass inherits a closed question rather than an attractive one.§own-error
The review falsified the proposed headline's direction cell: the presence schema tree landed 2026-05-16 (
d7867704×11,e64eb4c2×1), 47 days after the bundle — not 94. The commit the draft named as the tree's arrival,cf0d6cc5, isremediate(C128) … complete presence schema-README gap ledger— the commit that added the disclosure refuting the finding. Cause:git log -1on a directory instead of--diff-filter=Aper file. The false cell pointed the same direction as the argument, so it read as corroboration and survived until something executed it.Two further cells caught by the post-write re-run without a reviewer (
validation.py:73→:74; row-set census 13→11, a figure lifted from C338's prose instead of counted from its bullets). No reviewer correction was rejected; all four, and all three reviewer-supplied audit cites, re-verified before acceptance.Verification
Suites executed as instruments, not written:
tests/test_validation.py37 passed; full SDK suite 2750 passed, 5 xfailed with an unregistered 13th schema on disk; backed control (one bundle entry removed) → 1 failed, 36 passed;validate_context_refs.pyexit 0. Both probes reverted in-tree,git status --porcelainempty after each.C379 remediation slot: NO-OP — B-D1 gates all
registries/remediation and remains operator-unanswered.🤖 Generated with Claude Code