diff --git a/docs/remediation/BOARD.md b/docs/remediation/BOARD.md index 804be939..68582975 100644 --- a/docs/remediation/BOARD.md +++ b/docs/remediation/BOARD.md @@ -16,21 +16,22 @@ ## In-flight -| Task | Owner | State | -| ------------------- | ------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| RM-01 checkout | — | **MERGED** `f58b3699` (#1027) | -| RM-03 queue guard | **Jason** | **GO** @ `78ec47cd` (cmt 20392) — HELD FOR OWNER MERGE. Head unmoved; GO commit-bound, VOID if it moves — **do not push #1032** | -| RM-02 registry ★key | rev-974 | ★ **IN REVIEW @ `83d2ecb2`** — rebased onto `f4fd5967`; CI #2196 **10/10** incl `clone`; verifier exit 0 bound to head. ACs pre-registered @ `995f8b6a`. **Crux A4: is the activation seam vacuity-capable?** | -| RM-61 CI exemption | — | ✅ **MERGED** `f4fd5967` (#1033). #1034 closed; **#1000 stays OPEN** (retirement trigger). Exemption is on `main` | -| RM-59 / RM-60 | Jason (infra) | tracked deps; RM-60 option **B** | -| #1023 queue attempt | Jason | SUPERSEDED-PENDING-JASON — live REQUEST_CHANGES, do **not** merge | +| Task | Owner | State | +| ------------------- | ------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| RM-01 checkout | — | **MERGED** `f58b3699` (#1027) | +| RM-03 queue guard | **Jason** | **GO** @ `78ec47cd` (cmt 20392) — HELD FOR OWNER MERGE. Head unmoved; GO commit-bound, VOID if it moves — **do not push #1032** | +| RM-02 registry ★key | f10-coder | **NO-GO @ `83d2ecb2` — FOUR silent-defeat paths (D-44).** A4/A5/A6 confirmed. ALL FOUR in this PR, **no trim** (Mos): a registry with a known silent defeat IS the inert gate. Remediating, red-first | +| RM-61 CI exemption | — | ✅ **MERGED** `f4fd5967` (#1033). #1034 closed; **#1000 stays OPEN** (retirement trigger). Exemption is on `main` | +| RM-59 / RM-60 | Jason (infra) | tracked deps; RM-60 option **B** | +| #1023 queue attempt | Jason | SUPERSEDED-PENDING-JASON — live REQUEST_CHANGES, do **not** merge | ### For the incoming orchestrator — read this before acting -1. **RM-02 is the front**, in review at `83d2ecb2` (rebase + CI done). RM-03 waits on Jason; RM-61 - MERGED. ⚠ **Re-derive any board claim from the provider before load-bearing use (D-43).** -2. **`docs/remediation/TASKS.md` is authoritative**, not the newest voice in a chat. It holds 44 findings - (D-1…D-6 in `BOARD-LEDGER.md`, D-7…D-43 + D-38c in TASKS.md), every ruling with its rationale, and the +1. **RM-02 is the front** — NO-GO at `83d2ecb2`, remediating four silent-defeat paths (**D-44**). + RM-03 waits on Jason; RM-61 MERGED. ⚠ **Re-derive any board claim from the provider before + load-bearing use (D-43).** +2. **`docs/remediation/TASKS.md` is authoritative**, not the newest voice in a chat. It holds 45 findings + (D-1…D-6 in `BOARD-LEDGER.md`, D-7…D-44 + D-38c in TASKS.md), every ruling with its rationale, and the requirements each finding placed on RM-02/RM-34/RM-50/RM-55. 3. **`MISSION.md` carries five first-class principles**, all earned by live failures — observe the property not the proxy · pre-registration prevents retrofitting and nothing else · never ship an @@ -85,6 +86,6 @@ went missing from mission setup twice, once inside the correction for it (**D-26 ## Decisions log — full record in [`TASKS.md`](./TASKS.md) -All 44 findings (D-1…D-6 in `BOARD-LEDGER.md`, D-7…D-43 + D-38c in `TASKS.md`) and every ruling with +All 45 findings (D-1…D-6 in `BOARD-LEDGER.md`, D-7…D-44 + D-38c in `TASKS.md`) and every ruling with its rationale live there. **Not duplicated here.** The history of _why_ this board must not restate — six stale copies across two seams — is rolled verbatim into [`BOARD-LEDGER.md`](./BOARD-LEDGER.md). diff --git a/docs/remediation/TASKS.md b/docs/remediation/TASKS.md index 00f95874..658d7eec 100644 --- a/docs/remediation/TASKS.md +++ b/docs/remediation/TASKS.md @@ -558,6 +558,56 @@ claims from the provider**, not merely confirming the file parses or that a succ > orchestrator does so before dispatch; **the coordinator does so before acting on or relaying a board > claim that gates a decision** — Mos noted he had relayed board-derived state to Jason all session. +### D-44 — the anti-inert-gate registry was inert-able FOUR distinct ways, and every green missed all four + +`rev-974` @ `83d2ecb2`, **NO GO**. Each finding is a **silent-defeat path of the registry itself**: + +| # | defeat path | status | +| --- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------- | +| 1 | **The activation seam inerts the history audit.** `seam=HEAD` ⇒ 0 prospective commits, `failures: []`, verifier exit 0. **HEAD's parent** also exits 0 covering only HEAD; the **introduction commit** omits itself | A4/A5/A6 **CONFIRMED** | +| 2 | **D-38 and D-40 criteria absent** from the manifest ⇒ whole failure modes uncovered, no bound must-fail cases | ruled in-scope, missing | +| 3 | **The "closed schema" is not recursive.** `outputPattern` → `outputPatern` ⇒ structure check AND full verifier both exit 0, assertion silently reduced to exit-code-only | orchestrator confirmed by construction | +| 4 | **Provider evidence is not subject-bound.** Two records sharing pipeline number `7` certified **two different commits** — uniqueness is checked only AFTER filtering by commit | a **live instance of the missing D-38 clause** | + +**★ THE HEADLINE: every one of these passed CI, passed the canonical `pnpm gate:verify`, and passed +38/38 focused tests. Greens discharged NOTHING.** All four were found by mutating things nobody had +registered a check for — **two of them outside the orchestrator's registered set**, which is D-17 again +(a set is a floor, never a ceiling). The reviewer-beyond-the-set is the current backstop; the +registry's own coverage clause is what will eventually mechanise it. + +**The orchestrator's AC set was also incomplete:** A3 corrected the prospective range to **eight** +commits, not seven — `83d2ecb2` (the seam commit itself) was omitted. + +> **★ SCOPE RULED — ALL FOUR IN THIS PR, NO TRIM (Mos, 2026-08-01), and sizing does not help:** +> **a registry that ships with a known way to be silently defeated IS the inert gate it exists to +> detect.** There is no "core registry" that is integrity-complete without these — **they are not +> hardening on top of the deliverable, they ARE the deliverable.** This is the one place in the mission +> where _"it works except for these known holes"_ is **disqualifying by definition**, because detecting +> exactly those holes is the product. +> +> Theme: **"the registry's own checks must not be silently defeatable."** Each fix carries a RED-FIRST +> must-fail control proving the specific defeat is now **caught**. That control set **IS** the +> D-38/D-40/coverage clause work — **not additive to the ruled scope; it is that scope made real.** +> +> **Blocker 1's cheap fix is dead:** forbidding `seam == HEAD` does not close it, because HEAD's parent +> and the introduction commit also pass. The value must be **DERIVED from non-author-controlled +> history** (parent of the first first-parent commit introducing `gates/gates.manifest.json`) — +> computed, not asserted in an editable field. **Keep the value (A1 confirmed it right); fix the +> mechanism.** +> +> **If it balloons past reviewability, the ONLY acceptable split is by INTEGRITY-COMPLETE STAGE — never +> by deferring a blocker.** A stage that ships a known silent-defeat path is not a stage. + +**This NO-GO is the keystone being forged, not failing.** It lands hardened against its own failure +modes, which is the only thing that makes it a registry rather than a manifest. + +**Method note banked as a positive (Mos):** the orchestrator could **not** reproduce "full verifier exit +0", traced its first attempt to its **own instrumentation artifact** (`json.dump` reformatting the +manifest), and **stated the divergence rather than wielding non-reproduction as a refutation** — the +vacuity itself reproduced, and blocker 3 was confirmed by construction, which needs no environment. +**Non-reproduction is not refutation.** Open method thread, not a blocker: why the orchestrator's +`gate:verify` exits 1 on `checkout-preflight` with outcome 42 (bubblewrap class). + ### PRE-POSITIONED DISPOSITION — RM-02's activation-seam question (A4/A5/A6), ruled BEFORE the verdict > **Status: OPEN — the verdict belongs to `rev-974`'s independent A4/A5/A6, not to anyone's guess.**