Correct GH-DEC-2026-014 section 4 and A-16 on audit-core's return

audit-core met the condition and then corrected its wording, and the
correction matters enough that leaving it implicit would have made the
section wrong.

The archive CARRIES the declaration; it does not DETECT non-production.
It performs no retrieval, holds no client for the emitting repository,
and its egress policy permits nothing that would let it try — asserted
by a test, because the claim silently stops being true the day someone
adds one. Detection sits with the REVIEWER at retrieval, and the stored
declaration is what makes that discovery a finding rather than a blank.
Section 4 now says so, and says explicitly that an archive must not be
read as required to chase content: an archive that fetched from the
parties it audits would acquire exactly the dependency that makes it
corruptible by them.

The residual they raised against their own delivered work is now in the
text. A custodian that never held content can emit a false
content_exists; they validate the declaration's shape, never its truth.
So what section 4 buys is narrower than it reads — it converts an
unattributable absence into an attributable false statement. Strictly
better, not proof. Better stated here than in a conformance argument
later, which was their reason for raising it.

A-16 gains two notes, both from their return.

The obligation attaches to the party that OBSERVED the route. A-16 does
not require every downstream holder to restate a route it never saw;
that is manufacturing a marker, which is the rider's failure in its
most direct form. audit-core established this by DECLINING an
obligation offered to it — its tenant is not an identity claim it
resolves but a value a credential is permitted to write, so recording a
route in an audit event would restate something it did not see. The
refusal is A-16 applied properly, not an exception to it, and it lands
the obligation on the party that resolved the value.

And applying A-16 relocates ambiguity rather than terminating it. Their
declaration disambiguates erased from never-held and creates a fourth
pair, false-declaration versus honest-declaration-then-loss. Not a
defect and not a reason to stop: the ambiguity ends up somewhere
attributable. Judge each application by whether the new residual has an
owner.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012viPor8WJNCbV64ipwewrm

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 1754332@bnt-lap001
Assistant-Session: 9c8ac536-ff5e-46a3-8ab1-a548bde25fc0
This commit is contained in:
tegwick 2026-09-10 15:23:57 +02:00
parent 5ec2fe9649
commit b9d1dd1e2f
2 changed files with 49 additions and 0 deletions

View file

@ -584,6 +584,28 @@ Without this rider A-16 becomes the thing it exists to prevent: a sound check re
as establishing a property it does not carry. Raised by `informed-decision`
against its own instance, which is the weak one.
**The obligation attaches to the party that observed the route.** A-16 requires
the record to say which route produced the state; it does **not** require every
downstream holder of the value to restate a route it never saw. A party writing a
route marker for a transition it did not observe is manufacturing the marker, which
is the rider's failure in its most direct form.
`audit-core` established this by declining an obligation offered to it: asked
whether its envelope inherited `GH-DEC-2026-013`'s tenant-provenance requirement, it
answered no — its `tenant` is not an identity claim it resolves but a value a
credential is permitted to write, checked by exact match against a registration, so
recording a route in an audit event would be restating something it did not see.
The obligation lands on the party that resolved the value, and the record of the
authority for the scope lives in the registration. Confirmed correct; the refusal is
A-16 applied properly rather than an exception to it.
**Applying A-16 relocates ambiguity; it does not terminate it.** `audit-core`'s
declaration disambiguates *erased* from *never held* and creates a fourth pair —
*false declaration* versus *honest declaration then loss*. That is not a defect in
the rule and not a reason to stop applying it: the ambiguity ends up somewhere
**attributable**, which is the point. Expect each application to move the question
rather than close it, and judge the move by whether the new residual has an owner.
### A-17 — Fail-closed transitions
A transitional deviation from an invariant is admissible only where it fails

View file

@ -2259,6 +2259,33 @@ retrieval is a **conformance failure** attributable to the custodian rather than
gap in the record. A commitment with no accompanying assertion that something is being
committed to is indistinguishable from a commitment to nothing.
**Amended 2026-09-10 — detection sits with the reviewer, not with the archive.**
`audit-core` accepted this condition and corrected its wording, and the correction is
load-bearing enough that leaving it as an assumption would have made this section wrong.
The archive **carries** the declaration; it does not **detect** non-production. It
performs no retrieval, holds no client for the emitting repository, and its egress policy
permits nothing that would let it try — asserted by a test, because the claim silently
stops being true the day someone adds one.
So the mechanism is: the **reviewer** discovers non-production at retrieval, and the
stored declaration is what makes that discovery a **finding** rather than a blank —
because the reviewer holds a chained, timestamped statement that content existed and where
custody sat. Nothing in this section requires an archive to chase content, and it MUST NOT
be read as requiring it. An archive that fetched from the parties it audits would be
acquiring exactly the dependency that makes it corruptible by them.
**And the residual this creates, stated rather than left to be found.** A custodian that
never held the content can emit a false `content_exists`; the archive validates the
declaration's **shape**, never its **truth**. That is the same class as omission at source
— an archive cannot retrofit a property the boundary did not have — and it is closed by
neither the hash chain, nor attestation, nor `T-04`/`T-06`.
What §4 actually buys is narrower than it first reads, and this is the honest statement of
it: **the declaration converts an unattributable absence into an attributable false
statement.** Strictly better, and not the same as proof. Raised by `audit-core` against
its own delivered work, with the observation that the distinction is better in this text
now than in a conformance argument later.
This is `GH-DEC-2026-011` §3's rule in its third setting: two states, one observable
appearance, and the record must distinguish them. There it was `unknown` versus `absent`
in a stance map; in `GH-DEC-2026-013` §5 it was directory-asserted versus