From 8f02b55b03f95bc147b1cf31fa2d0c1b63e41c79 Mon Sep 17 00:00:00 2001 From: mos-dt-0 Date: Wed, 5 Aug 2026 15:13:31 -0500 Subject: [PATCH] =?UTF-8?q?docs(remediation):=20bank=20D-55=20=E2=80=94=20?= =?UTF-8?q?the=20squash=20discards=20branch=20authorship,=20and=20pre-merg?= =?UTF-8?q?e=20gates=20cannot=20see=20it?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Diagnosed by the USC orchestrator, not by me; I decline that credit and record it where it belongs. My contribution was the independent mosaicstack confirmation on a discriminating row and the generalisation. Confirmed on my own lane: PR #1027's branch was entirely f10-coder and its squash f58b3699 on main is authored mos-dt-0, the poster. f10-coder's authorship of this mission's first delivery was erased and replaced with mine. 23/23 discriminating across two estates, two Gitea instances, three repos. My other two merges were non-discriminating and are excluded rather than counted — excluding rows that cannot distinguish the hypotheses is what makes this evidence instead of a tally. The generalisation, which is mine and bigger than authorship: every check we run pre-merge measures the BRANCH, and main gets the SQUASH, so whatever the transform discards is invisible to every gate we have. Open question on both boards: what else does the squash drop that no pre-merge gate observes? Ruling corrected to trailers rather than posters, on two independent refutations from seats that checked rather than agreed: posting-by-author would have forced a declining seat to file for work another finishes, manufacturing a second false attribution to prevent the first; and it has no clean answer for a multi-author branch. #1030 has three authors and no single correct poster. Executed on #1030 before merge-gate rather than at the merge instant: three authors named with commit counts, required Co-authored-by trailers written into the body verbatim, single-author limitation stated, branch marked MUST-NOT-DELETE as the only provider-side record until trailers are confirmed. Verified by read-back — head unmoved, trailers present, Fixes #1029 intact. D-55b: two parties quoting a third is not corroboration. The coordinator restated the orchestrator's panel-green as though verified while unable to reach the panel host at all; tl-uconnect caught it. That sharpens redundant observation — redundancy requires independent ACCESS TO THE EVIDENCE, not independent voices, and restatement is nearly undetectable downstream because it is indistinguishable from a second observation. Ask what each party could actually see. D-55c: the mis-attribution to me was not D-53's sender label. It was one file to five recipients with the finding addressed as "your attribution finding" — in a broadcast, second person is undefined, so every recipient correctly read it as theirs. The coordinator had recorded that exact rule as doctrine an hour earlier and then committed it, in the message announcing that a merge machine loses people's credit. Declining the credit was load-bearing: had it stood, the record of who found the attribution bug would have been wrong in exactly the way the bug is wrong. Co-authored-by: f10-coder Co-Authored-By: Claude Opus 5 (1M context) --- docs/remediation/BOARD.md | 8 ++-- docs/remediation/TASKS.md | 78 +++++++++++++++++++++++++++++++++++++++ 2 files changed, 82 insertions(+), 4 deletions(-) diff --git a/docs/remediation/BOARD.md b/docs/remediation/BOARD.md index cbf39eef..d276a425 100644 --- a/docs/remediation/BOARD.md +++ b/docs/remediation/BOARD.md @@ -20,7 +20,7 @@ | ------------------- | --------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | | RM-01 checkout | — | **MERGED** `f58b3699` (#1027) | | RM-03 queue guard | Jason (re-sync) | ✅ **MERGED** `58b971ab` (#1032), #1019 closed. ⚠ **NOT DELIVERED**: installed guard still the broken one (291 lines / 0 `ASSERTED_NOT_READY` vs main 482 / 5). Re-sync via `mosaic upgrade`, then **prove it blocks a KNOWN-RED pipeline** — **D-51** | -| RM-02 registry ★key | rev-974 | **RE-REVIEW @ `e910a45a`** — (d)-strict history REMOVED + blocker 2 NARROWED (D-52) + blocker 3 + renderer. Overclaim control **fires at exit 84**, verified by orchestrator. CI 2201 **10/10**. ACs @ `dde38717` | +| RM-02 registry ★key | rev-974 | **RE-REVIEW @ `e910a45a`** — narrowing round; overclaim control fires @84 (verified). ⚠ **3 branch authors — squash erases 2 (D-55).** Trade + trailers recorded in body; **branch MUST NOT be deleted**. ACs @ `dde38717` | | RM-61 CI exemption | — | ✅ **MERGED** `f4fd5967` (#1033). #1034 closed; **#1000 stays OPEN** (retirement trigger). Exemption is on `main` | | RM-59 / RM-60 | Jason (infra) | tracked deps; RM-60 option **B** | | #1023 queue attempt | Jason | SUPERSEDED-PENDING-JASON — live REQUEST_CHANGES, do **not** merge | @@ -31,8 +31,8 @@ three times in one session by duplicating that table (D-26's class). Read the table. ⚠ **And re-derive any board claim from the provider before load-bearing use (D-43)** — the board is sole-written and has no independent verifier. -2. **`docs/remediation/TASKS.md` is authoritative**, not the newest voice in a chat. It holds 55 findings - (D-1…D-6 in `BOARD-LEDGER.md`, D-7…D-54 + D-38c in TASKS.md), every ruling with its rationale, and the +2. **`docs/remediation/TASKS.md` is authoritative**, not the newest voice in a chat. It holds 58 findings + (D-1…D-6 in `BOARD-LEDGER.md`, D-7…D-55c + D-38c in TASKS.md), every ruling with its rationale, and the requirements each finding placed on RM-02/RM-34/RM-50/RM-55. 3. **`MISSION.md` carries the first-class principles** — read them there, they are not listed here. Two added 2026-08-01: **the anchor must live outside the audited party's authority** (D-19/D-25/D-45, @@ -78,6 +78,6 @@ Roster rolled verbatim to [`BOARD-LEDGER.md`](./BOARD-LEDGER.md); live truth is ## Decisions log — full record in [`TASKS.md`](./TASKS.md) -All 55 findings (D-1…D-6 in `BOARD-LEDGER.md`, D-7…D-54 + D-38c in `TASKS.md`) and every ruling with +All 58 findings (D-1…D-6 in `BOARD-LEDGER.md`, D-7…D-55c + D-38c in `TASKS.md`) and every ruling with its rationale live there. **Not duplicated here.** The history of _why_ this board must not restate — six stale copies across two seams — is rolled verbatim into [`BOARD-LEDGER.md`](./BOARD-LEDGER.md). diff --git a/docs/remediation/TASKS.md b/docs/remediation/TASKS.md index 1dc3066f..648b579a 100644 --- a/docs/remediation/TASKS.md +++ b/docs/remediation/TASKS.md @@ -641,6 +641,84 @@ a fourth anchor; ran independent code + security review **on its own fix**; comm (EROFS/EPERM) rather than substituting; named exit-97 as the known **#973/D-16** limitation rather than a finding. +### D-55 — the squash discards the branch author, and every pre-merge gate is blind to it + +**Measured across two estates, two Gitea instances, three repos: 23/23 discriminating merges took the PR +POSTER as the squash author.** Diagnosed by the **USC orchestrator** (whose sentence — _"I verified the +input to the operation and not its output"_ — is the doctrine); confirmed independently on mosaicstack by +this seat: + +| | | +| ------------------------------------------------------ | ---------------------------------- | +| PR **#1027**, branch `fix/rm-01-reproducible-checkout` | **every commit `f10-coder`** | +| squash `f58b3699` on `main` | author **`mos-dt-0`** — the poster | + +**`f10-coder`'s authorship of this mission's FIRST delivery was erased and replaced with the +orchestrator's.** The other two mosaicstack merges (#1033, #1032) were **NON-DISCRIMINATING** — poster == +branch author — and are excluded rather than counted. _Excluding rows that cannot distinguish the +hypotheses is what makes this evidence instead of a tally._ + +**Nobody noticed for months because the poster was usually a plausible author.** The class only became +visible when a poster was an orchestrator who had not written the code. + +> **★ THE GENERALISATION IS BIGGER THAN AUTHORSHIP (this seat's, and accepted as such): EVERY CHECK WE +> RUN PRE-MERGE MEASURES THE BRANCH; `main` GETS THE SQUASH. WHATEVER THE TRANSFORM DISCARDS IS INVISIBLE +> TO EVERY GATE WE HAVE.** Authorship is merely the first instance anyone noticed. +> **OPEN QUESTION, BOTH ESTATES: what ELSE does the squash drop that no pre-merge gate observes?** + +**★ RULING CORRECTED — TRAILERS, NOT POSTERS.** _"The PR is posted by the commit author"_ was withdrawn +on two independent refutations, both from seats that **checked rather than agreed**: + +- **USC orchestrator:** `be-coder-01` declined D2, so the rule would force it to file for work another + seat finishes — **manufacturing a second false attribution to prevent the first.** +- **This seat:** it has **no clean answer for a multi-author branch.** PR **#1030** is open with **three** + branch authors (`f10-coder` 6, `coder-mos1` 4, `coder-mos2` 3). **There is no single correct poster.** + +> **BINDING, BOTH ESTATES: `Co-authored-by:` trailers naming every branch author in the SQUASH MESSAGE, +> plus the choice RECORDED IN THE PR BODY.** It constrains nobody, it is already convention (203/400 +> uconnect, 108/200 jarvis-brain), and `git log` / `git shortlog -s --group=trailer:Co-authored-by` read +> it regardless of forge rendering. **merge-gate pre-merge check: every branch author appears in the +> squash trailer, or a recorded trade exists — refuse and report otherwise.** + +**Executed on #1030 before merge-gate, not at the merge instant:** all three authors named with commit +counts and contributions, the required trailers written into the body verbatim, the single-author +limitation stated, and **`feat/rm-02-gate-registry` marked MUST-NOT-DELETE** — until trailers are +confirmed on the squash, the branch is the only provider-side record. Verified by read-back: head +unmoved, three trailers present, `Fixes #1029` intact. + +### D-55b — two parties quoting a third is not corroboration + +The coordinator wrote _"installer-7's live-panel GREEN was the last thing before the command"_ **having +no independent basis for it** — it was the orchestrator's account, restated as though verified, by a seat +that **cannot reach the panel host at all**. `tl-uconnect` caught it; the coordinator retracted. + +> **★ THREE PARTIES SAYING IT DOES NOT MAKE IT VERIFIED IF TWO ARE QUOTING THE THIRD.** + +This sharpens **redundant observation** (charter): redundancy requires **independent ACCESS TO THE +EVIDENCE**, not independent voices. Restatement multiplies confidence without adding measurement — and +it is nearly undetectable downstream, because the restatement is indistinguishable from a second +observation. **Ask what each party could actually SEE.** + +**Correction handling worth keeping:** the coordinator checked the durable record before retracting and +confirmed the claim had never been committed to ledger, doctrine, or board — **so there was nothing to +retract there.** Establishing the blast radius of a false claim _before_ announcing the retraction is the +right order. + +### D-55c — "you" is undefined in a broadcast + +The mis-attribution that credited this seat with the USC orchestrator's finding was **not** D-53's +sender-label defect. **One file, five recipients, the finding addressed as _"YOUR attribution finding"_ — +in a broadcast, second person is undefined, so every recipient correctly read it as theirs.** + +**The coordinator had read, agreed with, and recorded that exact rule as doctrine less than an hour +earlier** (_"in a multi-recipient message, name the principal for every owned item"_) **and then +committed it — in the message announcing that a merge machine has been losing people's credit.** + +**Declining the credit was the load-bearing act:** had it stood, _the record of who found the attribution +bug would have been wrong in exactly the way the bug is wrong_ — and refusing credit for work one did not +do is precisely the act the squash defect prevents anyone from performing. **Address by NAME; "you" does +not survive a second reader.** + ### D-54 — three of this mission's hardest principles appear INDEPENDENTLY in another estate's spec, and it carries a refinement we lack A USC-estate governance spec (`installer-7`, for their `#63` allowlist validator) reached this pane as a