forked from mosaicstack/stack
Mos ruled both open questions and promoted the pattern to the charter. PRINCIPLE 1 — the anchor must live outside the audited party's authority. You cannot fix "the author controls X" by deriving X from something the author also controls; deriving only MOVES the control point. Third independent arrival of one conclusion, each reached while shipping something else and each from a different direction: the manifest certifying its own tree (D-19), the sandbox evaluating code that enters before the boundary exists (D-25), and now the registry seam derived from a path the author also places (D-45). Three impossibility-derivations of the same conclusion is the strongest architectural evidence this mission has produced, and it is what forces Builds 1-2 rather than making them a preference. PRINCIPLE 2 — no universally-quantified check may pass over an empty set. "All registered cases ran" is vacuously true when there are none. Non-emptiness and anchoring are preconditions asserted before the quantified check runs, not properties hoped for after. The identical vacuity appeared twice at two levels — seam=HEAD emptied the commit range, an emptied manifest emptied the registry population — and the first was fixed as an instance, so it returned one level up. Corollary, same disease: a clause written for the instance that produced it is not a clause. Q1 ruled: the merge-base anchor IS in scope for f10-coder in this PR. It is git-computable against main, which the author does not control, so reordering or splitting within the branch cannot move it — an existing non-author-controlled reference, no new infrastructure. RM-60's execution boundary is a sibling under the same principle but a different mechanism (where gate-verify runs, not what the anchor is) and stays with Mos and Jason. Honesty required in both directions: the merge-base anchors to main, whose integrity rests on the merge discipline this registry enforces — a bootstrap, sound against an author who cannot rewrite main and NOT sound against an attacker who can, with that residual bound to the Builds 1-2 dependency rather than implied. Q2 ruled: state the empty-set principle as a general clause now, and generalize the D-38/D-40 criteria the same way — quantify over the population instead of relabeling the originating instances. Round 3 dispatched to f10-coder: merge-base anchor plus delayed-introduction must-fail; empty-set precondition as a general clause with an emptied-registry must-fail; generalized clauses bound across the gate inventory; each red-first. Number.isInteger accepting zero/negative/unsafe pipeline numbers banked as a non-blocking follow-up. Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>