Correct GH-DEC-2026-014 section 4 and A-16 on audit-core's return
audit-core met the condition and then corrected its wording, and the correction matters enough that leaving it implicit would have made the section wrong. The archive CARRIES the declaration; it does not DETECT non-production. It performs no retrieval, holds no client for the emitting repository, and its egress policy permits nothing that would let it try — asserted by a test, because the claim silently stops being true the day someone adds one. Detection sits with the REVIEWER at retrieval, and the stored declaration is what makes that discovery a finding rather than a blank. Section 4 now says so, and says explicitly that an archive must not be read as required to chase content: an archive that fetched from the parties it audits would acquire exactly the dependency that makes it corruptible by them. The residual they raised against their own delivered work is now in the text. A custodian that never held content can emit a false content_exists; they validate the declaration's shape, never its truth. So what section 4 buys is narrower than it reads — it converts an unattributable absence into an attributable false statement. Strictly better, not proof. Better stated here than in a conformance argument later, which was their reason for raising it. A-16 gains two notes, both from their return. The obligation attaches to the party that OBSERVED the route. A-16 does not require every downstream holder to restate a route it never saw; that is manufacturing a marker, which is the rider's failure in its most direct form. audit-core established this by DECLINING an obligation offered to it — its tenant is not an identity claim it resolves but a value a credential is permitted to write, so recording a route in an audit event would restate something it did not see. The refusal is A-16 applied properly, not an exception to it, and it lands the obligation on the party that resolved the value. And applying A-16 relocates ambiguity rather than terminating it. Their declaration disambiguates erased from never-held and creates a fourth pair, false-declaration versus honest-declaration-then-loss. Not a defect and not a reason to stop: the ambiguity ends up somewhere attributable. Judge each application by whether the new residual has an owner. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012viPor8WJNCbV64ipwewrm Assistant: claude-code Assistant-Model: opus Assistant-Process: 1754332@bnt-lap001 Assistant-Session: 9c8ac536-ff5e-46a3-8ab1-a548bde25fc0
This commit is contained in:
parent
5ec2fe9649
commit
b9d1dd1e2f
2 changed files with 49 additions and 0 deletions
|
|
@ -584,6 +584,28 @@ Without this rider A-16 becomes the thing it exists to prevent: a sound check re
|
|||
as establishing a property it does not carry. Raised by `informed-decision`
|
||||
against its own instance, which is the weak one.
|
||||
|
||||
**The obligation attaches to the party that observed the route.** A-16 requires
|
||||
the record to say which route produced the state; it does **not** require every
|
||||
downstream holder of the value to restate a route it never saw. A party writing a
|
||||
route marker for a transition it did not observe is manufacturing the marker, which
|
||||
is the rider's failure in its most direct form.
|
||||
|
||||
`audit-core` established this by declining an obligation offered to it: asked
|
||||
whether its envelope inherited `GH-DEC-2026-013`'s tenant-provenance requirement, it
|
||||
answered no — its `tenant` is not an identity claim it resolves but a value a
|
||||
credential is permitted to write, checked by exact match against a registration, so
|
||||
recording a route in an audit event would be restating something it did not see.
|
||||
The obligation lands on the party that resolved the value, and the record of the
|
||||
authority for the scope lives in the registration. Confirmed correct; the refusal is
|
||||
A-16 applied properly rather than an exception to it.
|
||||
|
||||
**Applying A-16 relocates ambiguity; it does not terminate it.** `audit-core`'s
|
||||
declaration disambiguates *erased* from *never held* and creates a fourth pair —
|
||||
*false declaration* versus *honest declaration then loss*. That is not a defect in
|
||||
the rule and not a reason to stop applying it: the ambiguity ends up somewhere
|
||||
**attributable**, which is the point. Expect each application to move the question
|
||||
rather than close it, and judge the move by whether the new residual has an owner.
|
||||
|
||||
### A-17 — Fail-closed transitions
|
||||
|
||||
A transitional deviation from an invariant is admissible only where it fails
|
||||
|
|
|
|||
|
|
@ -2259,6 +2259,33 @@ retrieval is a **conformance failure** attributable to the custodian rather than
|
|||
gap in the record. A commitment with no accompanying assertion that something is being
|
||||
committed to is indistinguishable from a commitment to nothing.
|
||||
|
||||
**Amended 2026-09-10 — detection sits with the reviewer, not with the archive.**
|
||||
`audit-core` accepted this condition and corrected its wording, and the correction is
|
||||
load-bearing enough that leaving it as an assumption would have made this section wrong.
|
||||
The archive **carries** the declaration; it does not **detect** non-production. It
|
||||
performs no retrieval, holds no client for the emitting repository, and its egress policy
|
||||
permits nothing that would let it try — asserted by a test, because the claim silently
|
||||
stops being true the day someone adds one.
|
||||
|
||||
So the mechanism is: the **reviewer** discovers non-production at retrieval, and the
|
||||
stored declaration is what makes that discovery a **finding** rather than a blank —
|
||||
because the reviewer holds a chained, timestamped statement that content existed and where
|
||||
custody sat. Nothing in this section requires an archive to chase content, and it MUST NOT
|
||||
be read as requiring it. An archive that fetched from the parties it audits would be
|
||||
acquiring exactly the dependency that makes it corruptible by them.
|
||||
|
||||
**And the residual this creates, stated rather than left to be found.** A custodian that
|
||||
never held the content can emit a false `content_exists`; the archive validates the
|
||||
declaration's **shape**, never its **truth**. That is the same class as omission at source
|
||||
— an archive cannot retrofit a property the boundary did not have — and it is closed by
|
||||
neither the hash chain, nor attestation, nor `T-04`/`T-06`.
|
||||
|
||||
What §4 actually buys is narrower than it first reads, and this is the honest statement of
|
||||
it: **the declaration converts an unattributable absence into an attributable false
|
||||
statement.** Strictly better, and not the same as proof. Raised by `audit-core` against
|
||||
its own delivered work, with the observation that the distinction is better in this text
|
||||
now than in a conformance argument later.
|
||||
|
||||
This is `GH-DEC-2026-011` §3's rule in its third setting: two states, one observable
|
||||
appearance, and the record must distinguish them. There it was `unknown` versus `absent`
|
||||
in a stance map; in `GH-DEC-2026-013` §5 it was directory-asserted versus
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue