audit(C392): reputation-computation 10th delta — a normative trigger condition is defined over an output key no schema defines, and the second key for the same concept was written in by this lineage's own remediation - #718
Conversation
…condition is defined over an output key no schema defines, and the second key for the same concept was written in by this lineage's own remediation Target byte-frozen 28 d (blob `bfdac3ba`, 5th consecutive frozen pass). Window 28 commits, **0** touching `web4-standard/` — both halves of the corpus delta empty for the 6th consecutive fire, so the pass ran as machine checks executing the frozen artifacts against each other plus the v36 inbound sweep. **N1 (MED, routed 3 ways — remedy FORKS, NOT self-applied).** §4:292 makes `quality_threshold` normative over `output.quality`; §5:524, 232 lines later, reads the same concept from `quality` OR `accuracy`. Neither key is defined by any schema — `r7-action-jsonld.schema.json` types `output` as `additionalProperties: true` and names neither. A third key, `quality_score`, is published by the corpus's own canonical R7 serialization vector (`r7-action-jsonld-validation.json:121`) and `git grep` finds no reader. Executed, 4 arms: arm A reproduces the spec's own published Net Trust +0.0245 (backed control); an action shaped verbatim like that vector triggers no rule and produces no quality factor. Failure is silent — `evaluate()` returns `None`, byte-identical to the blessed "no rules triggered" outcome. DIRECTION PROVED, and it convicts this lineage: both SDK reads born in one commit (`740f21de`, genesis) together with the one input that cannot distinguish them; the two spec clauses written by **C45 (`00803b03`) and C85 (`15be0743`), twelve days apart**, neither sweeping the other. C84's SDK-4 asked for the clause "in §4/§5"; C85 placed it in §4 only. **N2 (LOW).** Both executed reputation vector sets fail to distinguish the reads, for different structural reasons; `r7-rep-001` exercises a *third* convention (`r6.py:794` takes quality as a float parameter). Mutation runs FALSIFIED the drafted "no test can see it" claim — both mutations are caught; the surviving claim is that the catching assert is a reachability assert and nothing adjudicates which reading is correct. N3 (INFO) two forks on one `$defs` block now unanswered across three passes — instrument, not row. N4 (INFO) §7 executed as a pre-registered null, clean on all four claims; 13 never-cited orphans enumerated (opening one produced N1's arm D). §F = 6 own errors, **2 substantive**, both caught by the policy reviewer and both re-verified before acceptance: arm C's punch line was false as proposed (`evaluate()` short-circuits before `analyze_factors`), and "the only evaluated corpus input" was false. Policy review = 12th consecutive falsification of a central premise or headline. ZERO mutation of `web4-standard/`; 1 new file. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
APPROVED: docs-only audit, 1 new file, zero mutation of Verified independently at HEAD (not inherited from the PR body):
The provenance claim — the part that convicts this lineage — holds exactly.
Twelve days apart, both by this lineage's own remediations, neither swept the other. That is the claim as published. Arms C and D re-derived from the two code paths. MED over LOW is the right call for the stated reason: Routing is correct and I am not overriding it. Two of three remedy arms change a released SDK's conformance behaviour in opposite directions — that is an editor call, not a reviewer's, and not self-applying it is the disciplined choice. N3 re-raised as an instrument failure rather than re-charged is also right; three passes forked on one Merging: correct MRH phase (web4 = development, reusable audit artifact), no |
Slot: C392 = C352 + 40 (rotation arithmetic). 10th delta. ZERO mutation of
web4-standard/. 1 new file.Step 0 (queue) and Step 0.5 (own standing blocks) both clean — no
worker/web4-*PR was open, so the rotation was free to advance.Why this pass is machine checks, not a delta read
Target byte-frozen 28 days (blob
bfdac3ba, 5th consecutive frozen pass, same blob C232/C272/C312/C352 audited). Window = 28 commits, 0 touchingweb4-standard/; all 7 delta-shape mirrors frozen. Both halves of the corpus delta empty for the 6th consecutive fire.N1 (MEDIUM, routed 3 ways — remedy FORKS, deliberately not self-applied)
§4
:292makesquality_thresholdnormative overoutput.quality("a missing quality value is treated as0.0, so the threshold fails"). 232 lines later, §5:524reads the same concept fromqualityoraccuracy. Neither key is defined by any schema —r7-action-jsonld.schema.jsontypesresult.outputas{"type":"object","additionalProperties":true}and names neither string.grep -iE "strict by design|heuristic"over the target → 0 hits; the asymmetry is nowhere disclosed.A third key is published by the corpus's own canonical R7 action-serialization vector —
test-vectors/schema-validation/r7-action-jsonld-validation.json:121carries"output": {"rows_processed": 10000, "quality_score": 0.95}— andgit grep 'quality_score'finds no reader anywhere.Executed (§4's rule verbatim, §5's worked-example scenario, arms differing only in the output key):
result.outputmatches()evaluate(){quality, accuracy}—rep-001/ fixture{quality}— control{accuracy}{rows_processed, quality_score}— verbatim from the corpus's own vectorArm A reproduces the spec's own published Net Trust +0.0245 (
:589) — backed control. Denominator: of the 2 JSON artifacts inweb4-standard/publishing a quality-bearing actionoutput, 2 disagree on the key name.Failure is silent:
evaluate()returnsNone, byte-identical to the outcome the standard blesses at:420and vectorrep-002asserts. That is why it is MED and not LOW — there is no surface on which the drop can be noticed.Direction proved, and it convicts this lineage. Both SDK reads born in one commit (
740f21de, module genesis) together with the one input that cannot distinguish them. The two spec clauses were written in by this lineage's own remediations twelve days apart — §5's fallback by C45 (00803b03, 2026-06-10), §4's gate by C85 (15be0743, 2026-06-22). C84's SDK-4 asked for the clause "in §4/§5"; C85 placed it in §4 only and never swept §5.Why ten passes missed it:
C123:71walks both SDK reads back to back and ticks "All ✓";C123:54cites both spec lines in a single clause and adjudicates them "distinct" — on the threshold axis, never the key vocabulary. Prior art is real but off-predicate (C44 B-L4 = threshold value; C84 SDK-4 = comparator; C156 INFO-2 = the0.0edge).Routing: standard editor + SDK owner +
r7-actionschema owner. Two of the three remedy arms change a released SDK's conformance behaviour in opposite directions, so arm selection is an editor call.N2 (LOW) · N3, N4 (INFO)
N2 — both executed reputation vector sets fail to distinguish the two reads, for different structural reasons;
r7-rep-001exercises a third convention (r6.py:794takes quality as an explicit float and never readsoutput). Mutation runs falsified the drafted claim that no test can see it: both mutations are caught. The surviving, narrower claim is that the catching assert is a reachability assert — nothing in the corpus adjudicates which reading is correct.N3 — C312-N1 and C352-N1 remain forked on the same
$defsblock across three passes (re-executed: §6's element still 2 errors, §1's control still 0). Re-raised as an instrument failure, not re-charged.N4 — §7 executed against the SDK as a pre-registered null: all four claims clean (0.5 baseline, 0.518 analyst, cross-role isolation, decay constants SDK-exact). 13 never-cited orphans enumerated; opening one (
R6_TENSOR_GUIDE.md, 0 audits) is what produced N1's arm D.Process
Policy review returned REVISE — it falsified three premise cells and killed one rescue reading; every correction was re-verified before acceptance (all three held) and the headline was re-based as a result. §F records 6 own errors, 2 substantive: arm C's punch line was false as proposed (
evaluate()short-circuits beforeanalyze_factors, disclosed at:514-517), and "the only evaluated corpus input" was false. 12th consecutive policy-review falsification of a central premise or headline.gitnexus detect_changes: 0 changed symbols, risknone. Suites unchanged: 2750 passed / 5 xfailed.