Skip to content

audit(C378): registries 9th delta — the pre-registered B-D1 trigger fired, and the firing is what proves the trigger cannot answer B-D1 - #710

Merged
dp-web4 merged 1 commit into
mainfrom
worker/web4-20260813-120000
Aug 13, 2026
Merged

audit(C378): registries 9th delta — the pre-registered B-D1 trigger fired, and the firing is what proves the trigger cannot answer B-D1#710
dp-web4 merged 1 commit into
mainfrom
worker/web4-20260813-120000

Conversation

@dp-web4

@dp-web4 dp-web4 commented Aug 13, 2026

Copy link
Copy Markdown
Owner

Slot web4-20260813-120000 · Protocol v2 · ZERO mutation, 1 new file
Target web4-standard/registries/initial-registries.md — blob 00a37a88, mover 3f1d6fad 2026-06-18, 56 days frozen. Window e5b87dbe..HEAD = 96 commits. Lineage C70 → … → C338 → C378.

Step 0 clean (no greenlit [Legion] queue item). Step 0.5 clean — the only open PR is hub/-prefixed, not this track's.

Headline

C338:200 pre-registered: "if either number moves without a B-D1 answer, that is the finding." It moved — 24 ⊊ 3125 ⊊ 31 at afd04623 (#678). Discharging it required a question the trigger does not contain: did the corpus actually change?

Set difference run at both window endpoints (no prior pass has done this): 57 → 57, zero minted, zero retired across 96 commits. The vocabulary did not move. One code was relocated between the only two files the trigger watches, and no registries/ file was touched — all five are still at the single commit 3f1d6fad.

Findings (2 net-new: 1 MED, 1 LOW; zero inside the frozen target)

C378-N1 (MED) — the trigger's two operands are per-file cardinalities covering 31 of 57 codes. 26 (46%) live in neither and are invisible to it — including B-8's own subject matter, a standing MED subordinate to the very flagship the trigger guards. Three distinct events move the left operand identically, including B-D1's feared outcome and its desired one. Four refutations attempted and answered. Corrected trigger pre-registered for C418: watch |corpus| = 57 and |corpus ∖ SSOT| = 32, not the file pair.

C378-N2 (LOW — reach-escalation on B-C7, explicitly not net-new) — all 7 of 7 [Web4-*] reference tokens in extensions.md resolve to zero files, so the Specification Required policy registries/README.md:24 assigns that file has never once been satisfied. B-C7 named 3; the other 4 appear in zero audit documents in 56 days — protected from examination by the finding that appeared to cover them.

Three candidates killed before charging, published with their numbers

  • extension-vocabulary disjointness — C70:63 already published it (, "0 consumers"). Novelty sweep.
  • w4_sig_cose@1/w4_sig_jose@1 as an unregistered third vocabulary — C70:88 is B-C6, verbatim.
  • schema_registry.json / _SCHEMA_FILES — this pass's proposed headline, killed by policy review on five grounds: it fails this lineage's own pre-registered predicate (C338:75); the C338:147 build-artifact precedent is on point; the exclusion is disclosed at the point of use (schemas/presence-protocol/README.md:5/:45/:71-72, 12 shapeMatchesSchema bindings verified live); three lineages already settled it (C302:393, C352:188, C372:389); and the implied fix is wrong — the bundle is keyed by bare basename and hestia_query_policy.schema.json exists at both v0/tools/ and v1/tools/, so a directory-denominated guard would collide and silently drop a protocol version. Its executed baseline is preserved (0/12 drift, 12 of 24, 2750-green probe, backed control) so the next pass inherits a closed question rather than an attractive one.

§own-error

The review falsified the proposed headline's direction cell: the presence schema tree landed 2026-05-16 (d7867704 ×11, e64eb4c2 ×1), 47 days after the bundle — not 94. The commit the draft named as the tree's arrival, cf0d6cc5, is remediate(C128) … complete presence schema-README gap ledgerthe commit that added the disclosure refuting the finding. Cause: git log -1 on a directory instead of --diff-filter=A per file. The false cell pointed the same direction as the argument, so it read as corroboration and survived until something executed it.

Two further cells caught by the post-write re-run without a reviewer (validation.py:73:74; row-set census 13→11, a figure lifted from C338's prose instead of counted from its bullets). No reviewer correction was rejected; all four, and all three reviewer-supplied audit cites, re-verified before acceptance.

Verification

Suites executed as instruments, not written: tests/test_validation.py 37 passed; full SDK suite 2750 passed, 5 xfailed with an unregistered 13th schema on disk; backed control (one bundle entry removed) → 1 failed, 36 passed; validate_context_refs.py exit 0. Both probes reverted in-tree, git status --porcelain empty after each.

C379 remediation slot: NO-OP — B-D1 gates all registries/ remediation and remains operator-unanswered.

surface: C378 registries delta-audit doc   act: none (read-only audit; 0 spec/code/ledger edits)
S: low/reversible [construct: docs/audits/C378-registries-9th-delta-2026-08-13.md is additive-only]
R: n/a   W: n/a (no identity-bound act)
O: n/a   A: pass [construct: audit committed atomically with its evidence-basis, hash-chained via git]
V: n/a
verdict: PASS

🤖 Generated with Claude Code

…ired, and the firing is what proves the trigger cannot answer B-D1

Target byte-frozen 56 days (blob 00a37a8, 3f1d6fa); 9th consecutive
zero-mutation pass. Window e5b87db..HEAD = 96 commits.

C338:200 pre-registered: "if either number moves without a B-D1 answer,
that is the finding." It moved, 24 ⊊ 31 → 25 ⊊ 31, at afd0462 (#678).
Discharging it required asking a question the trigger does not contain —
did the corpus actually change? Set difference run at BOTH window
endpoints (which no prior pass has done): 57 → 57, zero minted, zero
retired. The vocabulary did not move; one code was relocated between the
two files the trigger happens to watch, and no registries/ file was
touched (all five still at 3f1d6fa).

N1 (MED): the trigger's two operands cover 31 of 57 codes. 26 (46%) live
in neither watched file and are invisible to it — including B-8's own
subject matter, a standing MED subordinate to the flagship it guards.
Three distinct events move the left operand identically, including
B-D1's feared outcome and its desired one. Corrected trigger
pre-registered for C418: watch |corpus|=57 and |corpus∖SSOT|=32.

N2 (LOW, reach-escalation on B-C7, not net-new): all 7 of extensions.md's
[Web4-*] reference tokens resolve to zero files, so the "Specification
Required" policy registries/README.md:24 assigns that file has never once
been satisfied. B-C7 named 3; the other 4 appear in ZERO audit documents
in 56 days — protected from examination by the finding that appeared to
cover them.

Three candidates killed before charging, published with their numbers:
the extension-vocabulary disjointness (C70:63, "0 consumers", ⊥) and
w4_sig_* (C70:88 = B-C6) by novelty sweep; and schema_registry.json /
_SCHEMA_FILES by policy review, on five grounds — it fails this lineage's
own mirror-set predicate (C338:75), the C338:147 build-artifact
precedent, disclosure at the point of use, three lineages having already
settled it, and an implied fix that would collide v0/v1
hestia_query_policy.schema.json on a shared basename. Its executed
baseline is preserved (0/12 drift, 12 of 24, 2750-green probe, backed
control) so the next pass inherits a closed question.

§own-error: the review falsified the proposed headline's direction cell —
the presence schema tree landed 2026-05-16 (d786770), not 2026-07-02;
the commit named as its arrival is the one that added the disclosure
refuting the finding. Cause: git log -1 on a directory instead of
--diff-filter=A per file. Two further cells caught by the post-write
re-run without a reviewer. No reviewer correction rejected this pass;
all four, and all three reviewer-supplied audit cites, re-verified.

C379 remediation slot: NO-OP (B-D1 gates all registries/ remediation).

surface: C378 registries delta-audit doc   act: none (read-only audit)
S: low/reversible [construct: docs/audits/C378-... is additive-only]
R: n/a   W: n/a (no identity-bound act)
O: n/a   A: pass [construct: audit committed atomically with its evidence-basis]
V: n/a
verdict: PASS

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@dp-web4

dp-web4 commented Aug 13, 2026

Copy link
Copy Markdown
Owner Author

APPROVED — merging. Every published number was re-derived independently in an isolated worktree at head 73436fa6, from my own commands rather than from the doc's transcript.

The headline reproduces exactly.

Claim My measurement
corpus at base e5b87dbe / at HEAD 57 / 57
minted in window / retired in window 0 / 0 (both comm arms empty)
initial-registries.md / errors.md §2 31 / 25 (24 at base — the trigger did fire)
union of the two watched files 31 — so 25 ⊊ 31 holds and the seed is a strict superset
in NEITHER watched file 26, and the enumeration matches yours code-for-code
all 5 registries/ files 3f1d6fad 2026-06-18, unmoved
6 surviving one-way exceptions identical list

The 26 partition as you state it: 8 ACP_* + W4_ERR_ACP, 6 AGY_*, 4 CROSS_SOCIETY_*, and 7 singletons including the UNKNOWN_FAKE fixture — so 25 real vocabulary. C378-N1 is sound: the trigger's operands cover 31 of 57 and cannot distinguish B-D1's feared outcome from its desired one. Refutation (i) is the one that decides it, and it is answered correctly — the instrument is narrower than the proposition C338:69 offered it as evidence for.

C378-N2 verified at full strength. All 7 [Web4-*] tokens in extensions.md resolve to 0 files outside that file itself. registries/README.md:24 does assign it Specification Required and :28 states it verbatim. So a registry's declared registration policy has never once been an applied constraint in this corpus, and 4 of the 7 were protected from examination by the finding that appeared to cover them. The reach-escalation framing (domain 3→7, no severity change, target not charged) is the correct disposition.

Negative 1 re-verified rather than taken on trust, since it is where the pass spent most of its effort. schema_registry.json = 12 entries; git ls-files 'web4-standard/schemas/**.json' = 24; the presence tree = 12; shapeMatchesSchema in the conformance file = 12; the blind-tree grep still 0; validate_context_refs.py exit 0. And ground 4 holds — hestia_query_policy.schema.json is the duplicate basename across v0/tools/ and v1/tools/, so a directory-denominated guard would collide and silently drop a protocol version. A finding whose fix introduces a defect is correctly not a finding.

The §own-error correction re-verified on my instrument, which is the part worth crediting. Per-file --diff-filter=A across the presence tree returns d7867704 ×11 and e64eb4c2 ×1, all 2026-05-16 — your corrected date, not the draft's cf0d6cc5 2026-07-02. That the false cell pointed the same direction as the argument, and therefore read as corroboration until something executed it, is the sharpest thing in this document. Method carry v55 rider 3 (git log -1 on a directory answers a different question than per-file --diff-filter=A) is a real and portable instrument correction.

One denominator note, mine not yours: git rev-list --count e5b87dbe..HEAD returns 97 at the PR head against your 96. That is the audit's own commit — the window was 96 when you measured it. Not a discrepancy.

Criteria. Docs-only, 1 new file, additive, zero mutation, zero spec/code/ledger edits, registries/ untouched. C379 remediation slot correctly declared NO-OP rather than manufacturing a registries/ edit under an operator-gated flagship. Three candidates killed before charging and published with their numbers so the next pass inherits closed questions instead of attractive ones — that is the behavior this lineage should keep.

@dp-web4
dp-web4 merged commit 458d8f0 into main Aug 13, 2026
4 checks passed
@dp-web4
dp-web4 deleted the worker/web4-20260813-120000 branch August 13, 2026 23:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant