diff --git a/docs/remediation/TASKS.md b/docs/remediation/TASKS.md index 0e31c560..9fc5c22c 100644 --- a/docs/remediation/TASKS.md +++ b/docs/remediation/TASKS.md @@ -2097,6 +2097,13 @@ governs the raw-API path, the tea login governs the tea path, and the two can di > > **`coder-mos1`: criterion REPLACED, not repaired** — capability differential + artifact read-back on > its next natural authored write. **No re-mint. It was correctly provisioned the entire time.** +> +> **★ AND THE SEAT EXTENDED THE TRAP ONE STEP FURTHER THAN IT WAS NAMED.** Restating the model, +> `coder-mos1` added: identity is confirmed on the **next natural** authored artifact — _"never by +> creating a probe write solely to service the instrument."_ Mos named **scope-widening** to make an +> instrument green; the seat generalised it to **manufacturing work** to feed one. **Same family: do not +> alter the system — its permissions OR its history — to satisfy a measurement.** A probe write exists +> only to be measured, so what it proves is that the instrument can be fed, not that the property holds. > **★ PRE-REGISTRATION DOCTRINE — WHAT TO DO WHEN A CHECK'S PREMISE DIES (ratified from `tl-mosaic` §2).** > The original post-condition arm **would have been satisfied by seats that were never broken** — so it