feat(quality): add anti-inert gate registry

This commit is contained in:
2026-08-01 09:58:46 -05:00
parent f4fd5967fc
commit 0b4aa4751a
18 changed files with 3247 additions and 3 deletions
+8
View File
@@ -12,6 +12,8 @@ gate/program; the LLM handles only genuine judgment.
### First-class principle — observe the property, not the exit code
<!-- GATE-CLAIM:OBSERVE-PROPERTY -->
> **No write is done until the requested PROPERTY is observed. A success exit code is not evidence.**
>
> **Success output is designed to be believed.** That is the whole reason the inert-gate class exists
@@ -30,6 +32,8 @@ gate/program; the LLM handles only genuine judgment.
### First-class principle — pre-registration prevents retrofitting, and nothing else
<!-- GATE-CLAIM:PREREGISTRATION-BOUNDARY -->
> **A pre-registered check set can fail in three distinct ways:**
>
> | mode | the set is… | found as |
@@ -56,6 +60,8 @@ gate/program; the LLM handles only genuine judgment.
### Corollary — never ship an integrity claim dressed as a property
<!-- GATE-CLAIM:ARTIFACT-INTEGRITY-BOUNDARY -->
> A verification artifact that can be forged by whoever it is meant to catch verifies nothing. If a
> manifest, marker, ledger, or receipt is writable by the same actor whose behaviour it certifies, it
> **certifies the attack.** Such an artifact must sit inside the integrity envelope it belongs to,
@@ -68,6 +74,8 @@ gate/program; the LLM handles only genuine judgment.
### First-class principle — when a property cannot exist at the layer it was specified
<!-- GATE-CLAIM:IMPOSSIBLE-LAYER-BOUNDARY -->
> Some required properties are **impossible at the layer that asked for them** — not hard, impossible.
> A local check cannot defend against an actor who can rewrite the check itself. When that happens,
> there are exactly three honest moves, and all three are mandatory: