Files
stack/docs/remediation
mos-dt-0andClaude Opus 5 7fc7fa1a25 docs(remediation): amend the credential ruling — the widening is withdrawn, and my lean was wrong
tl-mosaic's split is adopted and it partially reverses (a). Two of the three reasons did not survive:
the read-back doctrine mandates reading back the AUTHORED ARTIFACT, whose author field is readable under
existing repo scopes, so identity-on-authoring never needed read:user; and "read-only, marginal
privilege" is true but is not a justification, because cheap is not the same as needed.

The named trap is a fleet-wide scope widening performed to make an instrument green — the tail wagging
the dog, same family as buying admin read to answer the wrong question more authoritatively.

My error is the sharper one and I am recording it as mine. I recommended (a), and my stated reason was
verbatim the discredited one: read-only on the actor's own identity, converts an unverifiable property
into a one-command self-check. Worse, I had already written the correct answer as my own option (b) —
the authored-artifact read-back — and reached past it for the widening because it made the check
mechanical. Having the right answer in hand and preferring the one that services the instrument is the
whole failure. tl-mosaic caught what neither Mos nor I did.

The amended split: CAPABILITY is the in-scope probe plus differential — this seat's D-11b check,
canonical and unchanged. IDENTITY is /user where the token holds read:user, and otherwise NOT-MEASURED,
which is neither pass nor fail; a seat lacking read:user is correctly provisioned, not defective.
NOT-MEASURED is the resolution of the whole class — P-WRAPPER-001's tri-state applied to measurement
itself. The false negative existed because a missing measurement was scored as a failure.

The MISMATCH class closes at mint time instead, at zero runtime scope cost: the minting authority holds
admin scopes and reads back the principal at mint, asserting filename-vs-principal once, at the only
moment a mismatch can be created. coder-mos1's criterion is replaced rather than repaired, no re-mint;
it was correctly provisioned throughout.

Also ratified: a pre-registered check whose premise has died is an active pressure toward breaking
working code. Amending it before it runs, in writing, with the premise-change named, is the only honest
handling — the original arm would have been satisfied by seats that were never broken, so a false red
was traded for a real test. That completes the pre-registration principle by naming its one legitimate
amendment.

Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
2026-08-05 12:01:49 -05:00
..