Correct GH-DEC-2026-014 section 4 and A-16 on audit-core's return

audit-core met the condition and then corrected its wording, and the
correction matters enough that leaving it implicit would have made the
section wrong.

The archive CARRIES the declaration; it does not DETECT non-production.
It performs no retrieval, holds no client for the emitting repository,
and its egress policy permits nothing that would let it try — asserted
by a test, because the claim silently stops being true the day someone
adds one. Detection sits with the REVIEWER at retrieval, and the stored
declaration is what makes that discovery a finding rather than a blank.
Section 4 now says so, and says explicitly that an archive must not be
read as required to chase content: an archive that fetched from the
parties it audits would acquire exactly the dependency that makes it
corruptible by them.

The residual they raised against their own delivered work is now in the
text. A custodian that never held content can emit a false
content_exists; they validate the declaration's shape, never its truth.
So what section 4 buys is narrower than it reads — it converts an
unattributable absence into an attributable false statement. Strictly
better, not proof. Better stated here than in a conformance argument
later, which was their reason for raising it.

A-16 gains two notes, both from their return.

The obligation attaches to the party that OBSERVED the route. A-16 does
not require every downstream holder to restate a route it never saw;
that is manufacturing a marker, which is the rider's failure in its
most direct form. audit-core established this by DECLINING an
obligation offered to it — its tenant is not an identity claim it
resolves but a value a credential is permitted to write, so recording a
route in an audit event would restate something it did not see. The
refusal is A-16 applied properly, not an exception to it, and it lands
the obligation on the party that resolved the value.

And applying A-16 relocates ambiguity rather than terminating it. Their
declaration disambiguates erased from never-held and creates a fourth
pair, false-declaration versus honest-declaration-then-loss. Not a
defect and not a reason to stop: the ambiguity ends up somewhere
attributable. Judge each application by whether the new residual has an
owner.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012viPor8WJNCbV64ipwewrm

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 1754332@bnt-lap001
Assistant-Session: 9c8ac536-ff5e-46a3-8ab1-a548bde25fc0
This commit is contained in:
tegwick 2026-09-10 15:23:57 +02:00
parent 5ec2fe9649
commit b9d1dd1e2f
2 changed files with 49 additions and 0 deletions

View file

@ -2259,6 +2259,33 @@ retrieval is a **conformance failure** attributable to the custodian rather than
gap in the record. A commitment with no accompanying assertion that something is being
committed to is indistinguishable from a commitment to nothing.
**Amended 2026-09-10 — detection sits with the reviewer, not with the archive.**
`audit-core` accepted this condition and corrected its wording, and the correction is
load-bearing enough that leaving it as an assumption would have made this section wrong.
The archive **carries** the declaration; it does not **detect** non-production. It
performs no retrieval, holds no client for the emitting repository, and its egress policy
permits nothing that would let it try — asserted by a test, because the claim silently
stops being true the day someone adds one.
So the mechanism is: the **reviewer** discovers non-production at retrieval, and the
stored declaration is what makes that discovery a **finding** rather than a blank —
because the reviewer holds a chained, timestamped statement that content existed and where
custody sat. Nothing in this section requires an archive to chase content, and it MUST NOT
be read as requiring it. An archive that fetched from the parties it audits would be
acquiring exactly the dependency that makes it corruptible by them.
**And the residual this creates, stated rather than left to be found.** A custodian that
never held the content can emit a false `content_exists`; the archive validates the
declaration's **shape**, never its **truth**. That is the same class as omission at source
— an archive cannot retrofit a property the boundary did not have — and it is closed by
neither the hash chain, nor attestation, nor `T-04`/`T-06`.
What §4 actually buys is narrower than it first reads, and this is the honest statement of
it: **the declaration converts an unattributable absence into an attributable false
statement.** Strictly better, and not the same as proof. Raised by `audit-core` against
its own delivered work, with the observation that the distinction is better in this text
now than in a conformance argument later.
This is `GH-DEC-2026-011` §3's rule in its third setting: two states, one observable
appearance, and the record must distinguish them. There it was `unknown` versus `absent`
in a stance map; in `GH-DEC-2026-013` §5 it was directory-asserted versus