diff --git a/docs/remediation/BOARD.md b/docs/remediation/BOARD.md index 63073a18..a30e2611 100644 --- a/docs/remediation/BOARD.md +++ b/docs/remediation/BOARD.md @@ -31,8 +31,8 @@ three times in one session by duplicating that table (D-26's class). Read the table. ⚠ **And re-derive any board claim from the provider before load-bearing use (D-43)** — the board is sole-written and has no independent verifier. -2. **`docs/remediation/TASKS.md` is authoritative**, not the newest voice in a chat. It holds 48 findings - (D-1…D-6 in `BOARD-LEDGER.md`, D-7…D-47 + D-38c in TASKS.md), every ruling with its rationale, and the +2. **`docs/remediation/TASKS.md` is authoritative**, not the newest voice in a chat. It holds 50 findings + (D-1…D-6 in `BOARD-LEDGER.md`, D-7…D-49 + D-38c in TASKS.md), every ruling with its rationale, and the requirements each finding placed on RM-02/RM-34/RM-50/RM-55. 3. **`MISSION.md` carries the first-class principles** — read them there, they are not listed here. Two added 2026-08-01: **the anchor must live outside the audited party's authority** (D-19/D-25/D-45, @@ -78,6 +78,6 @@ Roster rolled verbatim to [`BOARD-LEDGER.md`](./BOARD-LEDGER.md); live truth is ## Decisions log — full record in [`TASKS.md`](./TASKS.md) -All 48 findings (D-1…D-6 in `BOARD-LEDGER.md`, D-7…D-47 + D-38c in `TASKS.md`) and every ruling with +All 50 findings (D-1…D-6 in `BOARD-LEDGER.md`, D-7…D-49 + D-38c in `TASKS.md`) and every ruling with its rationale live there. **Not duplicated here.** The history of _why_ this board must not restate — six stale copies across two seams — is rolled verbatim into [`BOARD-LEDGER.md`](./BOARD-LEDGER.md). diff --git a/docs/remediation/TASKS.md b/docs/remediation/TASKS.md index dbe35c14..8037c54a 100644 --- a/docs/remediation/TASKS.md +++ b/docs/remediation/TASKS.md @@ -558,6 +558,78 @@ claims from the provider**, not merely confirming the file parses or that a succ > orchestrator does so before dispatch; **the coordinator does so before acting on or relaying a board > claim that gates a decision** — Mos noted he had relayed board-derived state to Jason all session. +### D-49 — "idle" is not "available", and no one can manually watch every seat's context + +**Banked at Mos's direction, correcting Mos's own earlier ruling.** + +**The parking rule, refined — this SUPERSEDES the coder-mos1 (c) ruling's rationale.** That ruling +rested on _"a parked seat costs nothing until it is needed."_ True at 67% — `coder-mos1` could still +take a lane. **False at 97.4%**: when needed, `f10-coder` **cannot serve**. + +> **THE THRESHOLD IS NOT "IS THE SEAT IDLE" BUT "CAN IT STILL TAKE THE NEXT LANE."** +> Idle does not equal available. + +Applied live: `f10-coder` was idle with round 3 pushed and frozen, which reads as safe. The orchestrator +rotated anyway on an **asymmetry** — if the pending verdict approved, rotating cost nothing; if it +requested changes, remediation would dispatch to a seat that could not take it, forcing a **mid-lane +rotation on the keystone under time pressure (F2)**. The verdict duly requested changes. **Idle-now was +the only clean boundary available.** + +**★ AND THE DETECTION WAS DISCIPLINE, NOT A MECHANISM.** The orchestrator was **not** watching seat +context in real time; **Mos caught 97.4% on a manual liveness sweep.** Mos's framing, kept verbatim +because it is the finding rather than an apology: _"a human/agent cannot manually watch every seat's +context %; my sweep caught it this time, which is discipline, not a mechanism, and this mission's thesis +is that discipline without a mechanism eventually fails."_ + +> **REQUIREMENT ON RM-58 / P-LIFECYCLE-001 / the coordinator daemon: the coordinator WATCHES TOKEN +> BUDGET ACROSS SEATS AND PRE-EMPTS AT THRESHOLD**, so a keystone seat's ceiling is never discovered by +> a failed round **or by a lucky manual sweep.** Interim: both coordinator and orchestrator sweep — and +> **the mechanism retires the sweep.** + +### D-48 — a both-directions boundary statement that was WRONG, verified by three seats, and the suspicion that contradicted it was sitting in the handoff + +**Banked as Mos's error, in Mos's words, at Mos's request.** (Mos said "bank as D-46"; that number is the +empty-registry finding — renumbered to D-48 rather than silently reuse it. **The ledger is the mission's +primary product; a duplicated number corrupts it.**) + +`gate-history.mjs` shipped, and three seats approved, this boundary statement: + +> DOES anchor to the provider target merge-base, sound against an author who cannot rewrite main; +> DOES NOT establish integrity when main itself is compromised; residual owner **Builds 1-2**. + +**A1's attack does not rewrite main.** It repoints a local remote-tracking ref with one unprivileged +`git update-ref` (reproduced by the orchestrator in seconds). **So the documented residual understates +the real attack by orders of magnitude** — it describes an exotic threat (compromise `main`) while the +actual one is trivial (one command, no privilege). + +> **★ STATING A BOUNDARY IS NOT THE SAME AS STATING IT CORRECTLY. AN UNDERSTATED RESIDUAL IS WORSE THAN +> NONE, BECAUSE IT READS AS RIGOROUS.** This is D-19's move 2 ("state the boundary in BOTH directions") +> performed with **wrong content** — and D-19 is the principle we had just promoted. The +> verify-the-property-not-the-proxy failure at the meta level: **everyone checked that a +> both-directions statement EXISTED; nobody checked it was TRUE.** + +Owned by Mos (who verified and praised it), by the orchestrator (who verified and praised it), and by +`f10-coder` (who wrote it). **Third distinct way the render/verify principles have failed inside their +own enforcers** — with D-26 and D-30. + +**★ AND THE CORRECT ANSWER WAS ALREADY WRITTEN DOWN.** `f10-coder`'s rotation handoff +(`~/agent-work/handoffs/f10-coder-20260801.md`) contains **both**: + +| line | content | +| ---- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| 21 | the **wrong claim** — "does not solve compromised/rewritten main; that residual belongs to Builds 1-2" | +| 29 | **"Suspicion (not verified): further review may probe whether provider-target ref selection itself can be influenced by CI checkout/fetch configuration; treat any such claim as a trust-boundary question."** | + +**The seat held the shipped claim and the suspicion that overturns it, simultaneously, and labelled the +suspicion honestly.** `rev-974` then found exactly that. **Had anyone run the suspicion down, D-48 would +not have shipped.** + +> **REQUIREMENT (RM-02 / RM-34): a labelled suspicion that CONTRADICTS a shipped claim must block that +> claim until falsified — it is not a note.** Suspicions are currently recorded and then ignored, which +> makes honest labelling free of consequence. The value of marking uncertainty is lost if nothing +> consumes the mark. **Where a suspicion targets a boundary statement or an integrity claim, it is a +> pre-registered check that has not been run yet.** + ### D-45 — you cannot fix "the author controls X" by deriving X from something the author also controls Second NO-GO on the keystone, `32b490a7`. **The pattern is the finding, not the three blockers.**