diff --git a/ArchitectureBlueprint.md b/ArchitectureBlueprint.md index 438ba6c..498621e 100644 --- a/ArchitectureBlueprint.md +++ b/ArchitectureBlueprint.md @@ -584,6 +584,28 @@ Without this rider A-16 becomes the thing it exists to prevent: a sound check re as establishing a property it does not carry. Raised by `informed-decision` against its own instance, which is the weak one. +**The obligation attaches to the party that observed the route.** A-16 requires +the record to say which route produced the state; it does **not** require every +downstream holder of the value to restate a route it never saw. A party writing a +route marker for a transition it did not observe is manufacturing the marker, which +is the rider's failure in its most direct form. + +`audit-core` established this by declining an obligation offered to it: asked +whether its envelope inherited `GH-DEC-2026-013`'s tenant-provenance requirement, it +answered no — its `tenant` is not an identity claim it resolves but a value a +credential is permitted to write, checked by exact match against a registration, so +recording a route in an audit event would be restating something it did not see. +The obligation lands on the party that resolved the value, and the record of the +authority for the scope lives in the registration. Confirmed correct; the refusal is +A-16 applied properly rather than an exception to it. + +**Applying A-16 relocates ambiguity; it does not terminate it.** `audit-core`'s +declaration disambiguates *erased* from *never held* and creates a fourth pair — +*false declaration* versus *honest declaration then loss*. That is not a defect in +the rule and not a reason to stop applying it: the ambiguity ends up somewhere +**attributable**, which is the point. Expect each application to move the question +rather than close it, and judge the move by whether the new residual has an owner. + ### A-17 — Fail-closed transitions A transitional deviation from an invariant is admissible only where it fails diff --git a/decisions/decisions.md b/decisions/decisions.md index da4a844..746eaf5 100644 --- a/decisions/decisions.md +++ b/decisions/decisions.md @@ -2259,6 +2259,33 @@ retrieval is a **conformance failure** attributable to the custodian rather than gap in the record. A commitment with no accompanying assertion that something is being committed to is indistinguishable from a commitment to nothing. +**Amended 2026-09-10 — detection sits with the reviewer, not with the archive.** +`audit-core` accepted this condition and corrected its wording, and the correction is +load-bearing enough that leaving it as an assumption would have made this section wrong. +The archive **carries** the declaration; it does not **detect** non-production. It +performs no retrieval, holds no client for the emitting repository, and its egress policy +permits nothing that would let it try — asserted by a test, because the claim silently +stops being true the day someone adds one. + +So the mechanism is: the **reviewer** discovers non-production at retrieval, and the +stored declaration is what makes that discovery a **finding** rather than a blank — +because the reviewer holds a chained, timestamped statement that content existed and where +custody sat. Nothing in this section requires an archive to chase content, and it MUST NOT +be read as requiring it. An archive that fetched from the parties it audits would be +acquiring exactly the dependency that makes it corruptible by them. + +**And the residual this creates, stated rather than left to be found.** A custodian that +never held the content can emit a false `content_exists`; the archive validates the +declaration's **shape**, never its **truth**. That is the same class as omission at source +— an archive cannot retrofit a property the boundary did not have — and it is closed by +neither the hash chain, nor attestation, nor `T-04`/`T-06`. + +What §4 actually buys is narrower than it first reads, and this is the honest statement of +it: **the declaration converts an unattributable absence into an attributable false +statement.** Strictly better, and not the same as proof. Raised by `audit-core` against +its own delivered work, with the observation that the distinction is better in this text +now than in a conformance argument later. + This is `GH-DEC-2026-011` §3's rule in its third setting: two states, one observable appearance, and the record must distinguish them. There it was `unknown` versus `absent` in a stance map; in `GH-DEC-2026-013` §5 it was directory-asserted versus