Correct GH-DEC-2026-014 section 4 and A-16 on audit-core's return
audit-core met the condition and then corrected its wording, and the correction matters enough that leaving it implicit would have made the section wrong. The archive CARRIES the declaration; it does not DETECT non-production. It performs no retrieval, holds no client for the emitting repository, and its egress policy permits nothing that would let it try — asserted by a test, because the claim silently stops being true the day someone adds one. Detection sits with the REVIEWER at retrieval, and the stored declaration is what makes that discovery a finding rather than a blank. Section 4 now says so, and says explicitly that an archive must not be read as required to chase content: an archive that fetched from the parties it audits would acquire exactly the dependency that makes it corruptible by them. The residual they raised against their own delivered work is now in the text. A custodian that never held content can emit a false content_exists; they validate the declaration's shape, never its truth. So what section 4 buys is narrower than it reads — it converts an unattributable absence into an attributable false statement. Strictly better, not proof. Better stated here than in a conformance argument later, which was their reason for raising it. A-16 gains two notes, both from their return. The obligation attaches to the party that OBSERVED the route. A-16 does not require every downstream holder to restate a route it never saw; that is manufacturing a marker, which is the rider's failure in its most direct form. audit-core established this by DECLINING an obligation offered to it — its tenant is not an identity claim it resolves but a value a credential is permitted to write, so recording a route in an audit event would restate something it did not see. The refusal is A-16 applied properly, not an exception to it, and it lands the obligation on the party that resolved the value. And applying A-16 relocates ambiguity rather than terminating it. Their declaration disambiguates erased from never-held and creates a fourth pair, false-declaration versus honest-declaration-then-loss. Not a defect and not a reason to stop: the ambiguity ends up somewhere attributable. Judge each application by whether the new residual has an owner. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012viPor8WJNCbV64ipwewrm Assistant: claude-code Assistant-Model: opus Assistant-Process: 1754332@bnt-lap001 Assistant-Session: 9c8ac536-ff5e-46a3-8ab1-a548bde25fc0
This commit is contained in:
parent
5ec2fe9649
commit
b9d1dd1e2f
2 changed files with 49 additions and 0 deletions
|
|
@ -584,6 +584,28 @@ Without this rider A-16 becomes the thing it exists to prevent: a sound check re
|
|||
as establishing a property it does not carry. Raised by `informed-decision`
|
||||
against its own instance, which is the weak one.
|
||||
|
||||
**The obligation attaches to the party that observed the route.** A-16 requires
|
||||
the record to say which route produced the state; it does **not** require every
|
||||
downstream holder of the value to restate a route it never saw. A party writing a
|
||||
route marker for a transition it did not observe is manufacturing the marker, which
|
||||
is the rider's failure in its most direct form.
|
||||
|
||||
`audit-core` established this by declining an obligation offered to it: asked
|
||||
whether its envelope inherited `GH-DEC-2026-013`'s tenant-provenance requirement, it
|
||||
answered no — its `tenant` is not an identity claim it resolves but a value a
|
||||
credential is permitted to write, checked by exact match against a registration, so
|
||||
recording a route in an audit event would be restating something it did not see.
|
||||
The obligation lands on the party that resolved the value, and the record of the
|
||||
authority for the scope lives in the registration. Confirmed correct; the refusal is
|
||||
A-16 applied properly rather than an exception to it.
|
||||
|
||||
**Applying A-16 relocates ambiguity; it does not terminate it.** `audit-core`'s
|
||||
declaration disambiguates *erased* from *never held* and creates a fourth pair —
|
||||
*false declaration* versus *honest declaration then loss*. That is not a defect in
|
||||
the rule and not a reason to stop applying it: the ambiguity ends up somewhere
|
||||
**attributable**, which is the point. Expect each application to move the question
|
||||
rather than close it, and judge the move by whether the new residual has an owner.
|
||||
|
||||
### A-17 — Fail-closed transitions
|
||||
|
||||
A transitional deviation from an invariant is admissible only where it fails
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue