docs(remediation): bank D-55 — the squash discards branch authorship, and pre-merge gates cannot see it

Diagnosed by the USC orchestrator, not by me; I decline that credit and record it where it belongs. My
contribution was the independent mosaicstack confirmation on a discriminating row and the generalisation.

Confirmed on my own lane: PR #1027's branch was entirely f10-coder and its squash f58b3699 on main is
authored mos-dt-0, the poster. f10-coder's authorship of this mission's first delivery was erased and
replaced with mine. 23/23 discriminating across two estates, two Gitea instances, three repos. My other
two merges were non-discriminating and are excluded rather than counted — excluding rows that cannot
distinguish the hypotheses is what makes this evidence instead of a tally.

The generalisation, which is mine and bigger than authorship: every check we run pre-merge measures the
BRANCH, and main gets the SQUASH, so whatever the transform discards is invisible to every gate we have.
Open question on both boards: what else does the squash drop that no pre-merge gate observes?

Ruling corrected to trailers rather than posters, on two independent refutations from seats that checked
rather than agreed: posting-by-author would have forced a declining seat to file for work another
finishes, manufacturing a second false attribution to prevent the first; and it has no clean answer for
a multi-author branch. #1030 has three authors and no single correct poster.

Executed on #1030 before merge-gate rather than at the merge instant: three authors named with commit
counts, required Co-authored-by trailers written into the body verbatim, single-author limitation
stated, branch marked MUST-NOT-DELETE as the only provider-side record until trailers are confirmed.
Verified by read-back — head unmoved, trailers present, Fixes #1029 intact.

D-55b: two parties quoting a third is not corroboration. The coordinator restated the orchestrator's
panel-green as though verified while unable to reach the panel host at all; tl-uconnect caught it. That
sharpens redundant observation — redundancy requires independent ACCESS TO THE EVIDENCE, not independent
voices, and restatement is nearly undetectable downstream because it is indistinguishable from a second
observation. Ask what each party could actually see.

D-55c: the mis-attribution to me was not D-53's sender label. It was one file to five recipients with
the finding addressed as "your attribution finding" — in a broadcast, second person is undefined, so
every recipient correctly read it as theirs. The coordinator had recorded that exact rule as doctrine an
hour earlier and then committed it, in the message announcing that a merge machine loses people's
credit. Declining the credit was load-bearing: had it stood, the record of who found the attribution bug
would have been wrong in exactly the way the bug is wrong.

Co-authored-by: f10-coder <[email protected]>
Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
This commit is contained in:
mos-dt-0
2026-08-05 15:13:31 -05:00
co-authored by f10-coder Claude Opus 5
parent aa4b584764
commit 8f02b55b03
2 changed files with 82 additions and 4 deletions
+4 -4
View File
@@ -20,7 +20,7 @@
| ------------------- | --------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | | ------------------- | --------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| RM-01 checkout | — | **MERGED** `f58b3699` (#1027) | | RM-01 checkout | — | **MERGED** `f58b3699` (#1027) |
| RM-03 queue guard | Jason (re-sync) | ✅ **MERGED** `58b971ab` (#1032), #1019 closed. ⚠ **NOT DELIVERED**: installed guard still the broken one (291 lines / 0 `ASSERTED_NOT_READY` vs main 482 / 5). Re-sync via `mosaic upgrade`, then **prove it blocks a KNOWN-RED pipeline****D-51** | | RM-03 queue guard | Jason (re-sync) | ✅ **MERGED** `58b971ab` (#1032), #1019 closed. ⚠ **NOT DELIVERED**: installed guard still the broken one (291 lines / 0 `ASSERTED_NOT_READY` vs main 482 / 5). Re-sync via `mosaic upgrade`, then **prove it blocks a KNOWN-RED pipeline****D-51** |
| RM-02 registry ★key | rev-974 | **RE-REVIEW @ `e910a45a`**(d)-strict history REMOVED + blocker 2 NARROWED (D-52) + blocker 3 + renderer. Overclaim control **fires at exit 84**, verified by orchestrator. CI 2201 **10/10**. ACs @ `dde38717` | | RM-02 registry ★key | rev-974 | **RE-REVIEW @ `e910a45a`**narrowing round; overclaim control fires @84 (verified). ⚠ **3 branch authors — squash erases 2 (D-55).** Trade + trailers recorded in body; **branch MUST NOT be deleted**. ACs @ `dde38717` |
| RM-61 CI exemption | — | ✅ **MERGED** `f4fd5967` (#1033). #1034 closed; **#1000 stays OPEN** (retirement trigger). Exemption is on `main` | | RM-61 CI exemption | — | ✅ **MERGED** `f4fd5967` (#1033). #1034 closed; **#1000 stays OPEN** (retirement trigger). Exemption is on `main` |
| RM-59 / RM-60 | Jason (infra) | tracked deps; RM-60 option **B** | | RM-59 / RM-60 | Jason (infra) | tracked deps; RM-60 option **B** |
| #1023 queue attempt | Jason | SUPERSEDED-PENDING-JASON — live REQUEST_CHANGES, do **not** merge | | #1023 queue attempt | Jason | SUPERSEDED-PENDING-JASON — live REQUEST_CHANGES, do **not** merge |
@@ -31,8 +31,8 @@
three times in one session by duplicating that table (D-26's class). Read the table. ⚠ **And three times in one session by duplicating that table (D-26's class). Read the table. ⚠ **And
re-derive any board claim from the provider before load-bearing use (D-43)** — the board is re-derive any board claim from the provider before load-bearing use (D-43)** — the board is
sole-written and has no independent verifier. sole-written and has no independent verifier.
2. **`docs/remediation/TASKS.md` is authoritative**, not the newest voice in a chat. It holds 55 findings 2. **`docs/remediation/TASKS.md` is authoritative**, not the newest voice in a chat. It holds 58 findings
(D-1…D-6 in `BOARD-LEDGER.md`, D-7…D-54 + D-38c in TASKS.md), every ruling with its rationale, and the (D-1…D-6 in `BOARD-LEDGER.md`, D-7…D-55c + D-38c in TASKS.md), every ruling with its rationale, and the
requirements each finding placed on RM-02/RM-34/RM-50/RM-55. requirements each finding placed on RM-02/RM-34/RM-50/RM-55.
3. **`MISSION.md` carries the first-class principles** — read them there, they are not listed here. 3. **`MISSION.md` carries the first-class principles** — read them there, they are not listed here.
Two added 2026-08-01: **the anchor must live outside the audited party's authority** (D-19/D-25/D-45, Two added 2026-08-01: **the anchor must live outside the audited party's authority** (D-19/D-25/D-45,
@@ -78,6 +78,6 @@ Roster rolled verbatim to [`BOARD-LEDGER.md`](./BOARD-LEDGER.md); live truth is
## Decisions log — full record in [`TASKS.md`](./TASKS.md) ## Decisions log — full record in [`TASKS.md`](./TASKS.md)
All 55 findings (D-1…D-6 in `BOARD-LEDGER.md`, D-7…D-54 + D-38c in `TASKS.md`) and every ruling with All 58 findings (D-1…D-6 in `BOARD-LEDGER.md`, D-7…D-55c + D-38c in `TASKS.md`) and every ruling with
its rationale live there. **Not duplicated here.** The history of _why_ this board must not restate — its rationale live there. **Not duplicated here.** The history of _why_ this board must not restate —
six stale copies across two seams — is rolled verbatim into [`BOARD-LEDGER.md`](./BOARD-LEDGER.md). six stale copies across two seams — is rolled verbatim into [`BOARD-LEDGER.md`](./BOARD-LEDGER.md).
+78
View File
@@ -641,6 +641,84 @@ a fourth anchor; ran independent code + security review **on its own fix**; comm
(EROFS/EPERM) rather than substituting; named exit-97 as the known **#973/D-16** limitation rather than (EROFS/EPERM) rather than substituting; named exit-97 as the known **#973/D-16** limitation rather than
a finding. a finding.
### D-55 — the squash discards the branch author, and every pre-merge gate is blind to it
**Measured across two estates, two Gitea instances, three repos: 23/23 discriminating merges took the PR
POSTER as the squash author.** Diagnosed by the **USC orchestrator** (whose sentence — _"I verified the
input to the operation and not its output"_ — is the doctrine); confirmed independently on mosaicstack by
this seat:
| | |
| ------------------------------------------------------ | ---------------------------------- |
| PR **#1027**, branch `fix/rm-01-reproducible-checkout` | **every commit `f10-coder`** |
| squash `f58b3699` on `main` | author **`mos-dt-0`** — the poster |
**`f10-coder`'s authorship of this mission's FIRST delivery was erased and replaced with the
orchestrator's.** The other two mosaicstack merges (#1033, #1032) were **NON-DISCRIMINATING** — poster ==
branch author — and are excluded rather than counted. _Excluding rows that cannot distinguish the
hypotheses is what makes this evidence instead of a tally._
**Nobody noticed for months because the poster was usually a plausible author.** The class only became
visible when a poster was an orchestrator who had not written the code.
> **★ THE GENERALISATION IS BIGGER THAN AUTHORSHIP (this seat's, and accepted as such): EVERY CHECK WE
> RUN PRE-MERGE MEASURES THE BRANCH; `main` GETS THE SQUASH. WHATEVER THE TRANSFORM DISCARDS IS INVISIBLE
> TO EVERY GATE WE HAVE.** Authorship is merely the first instance anyone noticed.
> **OPEN QUESTION, BOTH ESTATES: what ELSE does the squash drop that no pre-merge gate observes?**
**★ RULING CORRECTED — TRAILERS, NOT POSTERS.** _"The PR is posted by the commit author"_ was withdrawn
on two independent refutations, both from seats that **checked rather than agreed**:
- **USC orchestrator:** `be-coder-01` declined D2, so the rule would force it to file for work another
seat finishes — **manufacturing a second false attribution to prevent the first.**
- **This seat:** it has **no clean answer for a multi-author branch.** PR **#1030** is open with **three**
branch authors (`f10-coder` 6, `coder-mos1` 4, `coder-mos2` 3). **There is no single correct poster.**
> **BINDING, BOTH ESTATES: `Co-authored-by:` trailers naming every branch author in the SQUASH MESSAGE,
> plus the choice RECORDED IN THE PR BODY.** It constrains nobody, it is already convention (203/400
> uconnect, 108/200 jarvis-brain), and `git log` / `git shortlog -s --group=trailer:Co-authored-by` read
> it regardless of forge rendering. **merge-gate pre-merge check: every branch author appears in the
> squash trailer, or a recorded trade exists — refuse and report otherwise.**
**Executed on #1030 before merge-gate, not at the merge instant:** all three authors named with commit
counts and contributions, the required trailers written into the body verbatim, the single-author
limitation stated, and **`feat/rm-02-gate-registry` marked MUST-NOT-DELETE** — until trailers are
confirmed on the squash, the branch is the only provider-side record. Verified by read-back: head
unmoved, three trailers present, `Fixes #1029` intact.
### D-55b — two parties quoting a third is not corroboration
The coordinator wrote _"installer-7's live-panel GREEN was the last thing before the command"_ **having
no independent basis for it** — it was the orchestrator's account, restated as though verified, by a seat
that **cannot reach the panel host at all**. `tl-uconnect` caught it; the coordinator retracted.
> **★ THREE PARTIES SAYING IT DOES NOT MAKE IT VERIFIED IF TWO ARE QUOTING THE THIRD.**
This sharpens **redundant observation** (charter): redundancy requires **independent ACCESS TO THE
EVIDENCE**, not independent voices. Restatement multiplies confidence without adding measurement — and
it is nearly undetectable downstream, because the restatement is indistinguishable from a second
observation. **Ask what each party could actually SEE.**
**Correction handling worth keeping:** the coordinator checked the durable record before retracting and
confirmed the claim had never been committed to ledger, doctrine, or board — **so there was nothing to
retract there.** Establishing the blast radius of a false claim _before_ announcing the retraction is the
right order.
### D-55c — "you" is undefined in a broadcast
The mis-attribution that credited this seat with the USC orchestrator's finding was **not** D-53's
sender-label defect. **One file, five recipients, the finding addressed as _"YOUR attribution finding"_
in a broadcast, second person is undefined, so every recipient correctly read it as theirs.**
**The coordinator had read, agreed with, and recorded that exact rule as doctrine less than an hour
earlier** (_"in a multi-recipient message, name the principal for every owned item"_) **and then
committed it — in the message announcing that a merge machine has been losing people's credit.**
**Declining the credit was the load-bearing act:** had it stood, _the record of who found the attribution
bug would have been wrong in exactly the way the bug is wrong_ — and refusing credit for work one did not
do is precisely the act the squash defect prevents anyone from performing. **Address by NAME; "you" does
not survive a second reader.**
### D-54 — three of this mission's hardest principles appear INDEPENDENTLY in another estate's spec, and it carries a refinement we lack ### D-54 — three of this mission's hardest principles appear INDEPENDENTLY in another estate's spec, and it carries a refinement we lack
A USC-estate governance spec (`installer-7`, for their `#63` allowlist validator) reached this pane as a A USC-estate governance spec (`installer-7`, for their `#63` allowlist validator) reached this pane as a