docs(remediation): promote two first-class principles to the charter; dispatch RM-02 round 3
Mos ruled both open questions and promoted the pattern to the charter. PRINCIPLE 1 — the anchor must live outside the audited party's authority. You cannot fix "the author controls X" by deriving X from something the author also controls; deriving only MOVES the control point. Third independent arrival of one conclusion, each reached while shipping something else and each from a different direction: the manifest certifying its own tree (D-19), the sandbox evaluating code that enters before the boundary exists (D-25), and now the registry seam derived from a path the author also places (D-45). Three impossibility-derivations of the same conclusion is the strongest architectural evidence this mission has produced, and it is what forces Builds 1-2 rather than making them a preference. PRINCIPLE 2 — no universally-quantified check may pass over an empty set. "All registered cases ran" is vacuously true when there are none. Non-emptiness and anchoring are preconditions asserted before the quantified check runs, not properties hoped for after. The identical vacuity appeared twice at two levels — seam=HEAD emptied the commit range, an emptied manifest emptied the registry population — and the first was fixed as an instance, so it returned one level up. Corollary, same disease: a clause written for the instance that produced it is not a clause. Q1 ruled: the merge-base anchor IS in scope for f10-coder in this PR. It is git-computable against main, which the author does not control, so reordering or splitting within the branch cannot move it — an existing non-author-controlled reference, no new infrastructure. RM-60's execution boundary is a sibling under the same principle but a different mechanism (where gate-verify runs, not what the anchor is) and stays with Mos and Jason. Honesty required in both directions: the merge-base anchors to main, whose integrity rests on the merge discipline this registry enforces — a bootstrap, sound against an author who cannot rewrite main and NOT sound against an attacker who can, with that residual bound to the Builds 1-2 dependency rather than implied. Q2 ruled: state the empty-set principle as a general clause now, and generalize the D-38/D-40 criteria the same way — quantify over the population instead of relabeling the originating instances. Round 3 dispatched to f10-coder: merge-base anchor plus delayed-introduction must-fail; empty-set precondition as a general clause with an emptied-registry must-fail; generalized clauses bound across the gate inventory; each red-first. Number.isInteger accepting zero/negative/unsafe pipeline numbers banked as a non-blocking follow-up. Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
This commit is contained in:
co-authored by
Claude Opus 5
parent
09875143c0
commit
4520d2f672
@@ -70,3 +70,10 @@ board is one of the six stale restatements below.
|
||||
not a 200 on a read. Mos owns provisioning; escalate missing pairs.
|
||||
- Seat identity (D-11a): token identity AND `git config user.name`/`user.email` must BOTH be set and
|
||||
agree. Exporting `MOSAIC_GIT_IDENTITY` alone does NOT fix commit authorship.
|
||||
|
||||
<!-- board-roll: D-26 gate-restatement rationale rolled verbatim from BOARD.md 2026-08-01 -->
|
||||
|
||||
### Why the board must not restate the delivery gates (D-26)
|
||||
|
||||
Restating the gate from memory is how the merge-gate step went missing from mission setup twice,
|
||||
once inside the correction for it (**D-26**).
|
||||
|
||||
Reference in New Issue
Block a user