CB-WP-0004 T04: fact registry and make facts-check — DFD gets a gate

Duplicated-fact drift is the fourth error class and the only one with no
executable rule. No positive control catches it (both copies are
internally consistent) and re-derivation does not either (the copy
reproduces whatever it was copied from). It is caught only by reading a
copy against its source, which nothing in the loop required.

facts.toml holds 15 facts and is GENERATED by `make facts-gen` from
cb-cost, dep-weight and rule-coverage. The trap this task named — a
hand-maintained registry that becomes another drifting copy — is closed
by facts-check re-running the instruments and failing when the committed
registry disagrees with them. A stale registry cannot certify stale
artifacts.

An artifact quoting a fact tags it: **$93.15** <!-- fact --> with the key.
17 occurrences across 5 artifacts are now checked.

Falsified before being believed: changing CostAccounting.md line 158 from
$93.15 to $92.87 — the exact historical drift — produced exit 1 naming
the file, the line and the expected value. Tested against the class it
exists to catch, on a real artifact, not only in its self-test.

It then caught a live tag inside its own documentation example in
InnerLoop.md within the hour. Third time a gate has failed on its own
pass's work.

What it does not close is stated rather than implied: 22 untagged literal
copies remain and are reported, not failed. Tagging is opt-in, a number
can legitimately recur, and a gate that fires on coincidence gets routed
around. Naming the uncovered surface beats claiming the class is closed.

InnerLoop single-source-of-fact moves from prose to executable — v1.3.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
tegwick 2026-07-31 10:24:39 +02:00
parent 6281cd546e
commit 53c460c992
12 changed files with 536 additions and 16 deletions

View file

@ -136,7 +136,7 @@ believed because it was produced by a program rather than by hand.
```task
id: CB-WP-0004-T03
status: todo
status: done
priority: medium
state_hub_task_id: "5466a510-37a5-4491-b93e-509cd400cc23"
```
@ -207,6 +207,34 @@ and say so — a gate with no generator still closes the class.
**Predicted:** **$69** recovered, plus DFD's first executable gate.
Confidence medium; this is the hardest task here and the most valuable.
**Delivered — both halves, not just the check.** `facts.toml` holds 15
facts and is **generated** by `make facts-gen` from cb-cost, dep-weight
and rule-coverage; the file opens with `# GENERATED — do not edit` and
the self-test asserts that line is still there. The trap named in this
task — a hand-maintained registry that becomes another drifting copy —
is closed by `facts-check` re-running the instruments and failing if the
committed registry disagrees with them. A stale registry cannot certify
stale artifacts.
An artifact quoting a fact tags it: `**$93.15** <!-- fact:pinned_total -->`.
17 occurrences across 5 artifacts are now under the gate.
**Falsified before being believed.** Changing `specs/CostAccounting.md`
line 158 from $93.15 to $92.87 — the exact historical drift — produced
exit 1 and `specs/CostAccounting.md:158 claims fact:pinned_total but does
not state $93.15`. The gate was tested against the class it exists to
catch, on a real artifact, not only in its self-test.
**What it does not close, stated rather than implied.** 22 untagged
literal copies remain, across `specs/InnerLoop.md`, `specs/GameKernel.md`,
`research/CB-RES-0002` and the older workplans. They are **reported, not
failed**: tagging is opt-in, a number can legitimately recur, and a gate
that fires on coincidence gets routed around. Naming the uncovered
surface is more useful than claiming the class is closed.
InnerLoop's single-source-of-fact rule moves from prose to executable —
**v1.3**.
## Phase C — Prove it, or withdraw the claim
## Task: Control loop — measure recovery and test for relocation