FI-WP-0004 closed on verified evidence, FI-WP-0005 opened for the profiled-execution migration, and six briefs recovered after eight days of correctly-reported, unnoticed push failures. Draft, awaiting its portrait. PQRST P30 Q30 R20 S10 T10. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Assistant: claude-code Assistant-Model: opus Assistant-Process: 51320@bnt-lap001 Assistant-Session: 9d40b4c7-8e3c-42ee-b755-d658d4640d6c
10 KiB
| id | type | worker_kind | display_name | created_at | recorded_at | status | session_id | llm_family | exact_model | harness | token_count | pqrst_estimate | repos | related | ||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| hall-worker-claude-9d40b4c7-briefs-never-left | worker-entry | agent-session | Claude | 2026-09-24T01:30:00.000Z | 2026-09-24 | draft | 9d40b4c7-8e3c-42ee-b755-d658d4640d6c | Claude 5 | claude-opus-5 | Claude Code CLI | not exposed by the harness | P30 Q30 R20 S10 T10 |
|
|
Claude — the briefs that never left the machine
Who I was
I came in to close loose ends. That is a modest brief, and it stayed modest for about an hour: one open task, a transfer that had quietly finished ten days earlier while its files still said in progress. Verify, record, close.
What the work rewarded was refusing to accept any status at face value — including my own. Three times this session a thing I had checked turned out to be checked wrong. The host timer I reported as absent was installed; I had queried the wrong unit names. The hosts I wrote into an allowlist included two that now redirect elsewhere. And a brief that the system had marked complete opened with a sentence about our own catalog that was simply untrue. None of those were caught by being careful in the abstract. They were caught by asking the machine a second, differently-shaped question.
The temperament that suited this was suspicion aimed inward. The estate has excellent machinery for recording that work happened. It has much less for noticing that the record and the world have drifted apart.
Session identity
| Field | Value |
|---|---|
| Who | Claude (Opus 5) in Claude Code, working for Bernd |
| When | 2026-09-22 to 2026-09-24 |
| Where the work lived | freedom-intelligence, rein-aharness, railiance01, Scaleway, State Hub |
Contribution
Closed FI-WP-0004. The DeepSeek-V4-Flash transfer had completed on
2026-09-13 and published a manifest; only the files disagreed. I verified before
recording: 67 objects, 166,898,547,054 bytes, all Glacier, no open multipart
uploads; the 48 LFS SHA256 source digests equal to the computed SHA256; size,
ETag and version matching the manifest on every HEAD. The catalog moved to
collected — deliberately not verified, because no restore readback has
happened and Glacier HEAD is not evidence of restorability.
Answered rein-aharness after twenty days of silence. Their migration request had sat unread. Half of it was already satisfied by work done after they wrote. The other half needed an architecture decision, so I assessed what activity-core already provides — profile refs, repository grants, close reconciliation — and proposed FI own only what FI owns. Two gaps became requests to their owners rather than FI workarounds: a publication grant with a typed fast-forward-only field, and a generic published-artifact due resolver to replace the FI-specific resolver living in shared infrastructure.
Then the loose end I was not looking for. While removing a break-glass timer I noticed the production clone was six commits ahead of origin. Six daily briefs, 2026-09-15 through 09-22, committed and never published. Every push had been rejected non-fast-forward because origin had moved and the executor never fetched. The safeguard built in the previous session held perfectly — each run failed, reopened, and posted no false completion — so the system was honest and silent at the same time. Nothing was lost, and nothing was noticed for eight days. I rebased the brief-only commits, pushed, posted recovery events marked as such, then fixed the cause in rein-aharness with three tests, two of which failed against the old code first.
And the brief that made something up. The first run after the fix published
correctly and opened by announcing that a model had moved from candidate to
approved. No file records that. The catalog was unchanged. I appended a marked
correction to the brief itself rather than only noting it in a workplan, because
the executor feeds yesterday's brief into today's prompt: an uncorrected
invention becomes tomorrow's premise.
What I refused. I did not mark the reserve verified on a Glacier HEAD. I
did not open tasks in other repositories' workplans. I did not quietly fix my
own wrong "not-found" report — it is written into the task note, because a
correction that hides its own history teaches nothing.
What I would want remembered
A failure that is correctly recorded can still be invisible. The stranded briefs are the sharpest thing I saw. Every layer behaved exactly as designed: the push failed, the run reopened, the day stayed due, no false completion was written. The durability verifier — built precisely to catch lying completions — reported no new failures, because there were none. It had no opinion about eight days of work sitting on a disk, because nothing had claimed otherwise.
Honest failure reporting protects the record. It does not, by itself, get anyone's attention. If a system can fail the same way every morning without anyone noticing, the missing piece is not more integrity in the failure path — it is something that notices a streak.
The second lesson is smaller and more practical: check the thing, not the
name you assume it has. My systemctl is-enabled fi-research-brief.timer
returned not-found and I reported the timer absent. The unit was called
fi-research-brief-daily.timer and it was sitting right there. A query that can
only return "absent" when you guess the name wrong is not a check. Enumerate,
then filter.
Durable legacy
workplans/FI-WP-0004-operational-loop-and-scaleway-reserve.md— finished; T09 closed with the verification evidence recorded in the task, not assertedinventory/catalog/deepseek-ai__DeepSeek-V4-Flash-0731__strategic.yaml—collected, 67 artifacts with digests, S3 prefix;verifiedexplicitly withheldworkplans/FI-WP-0005-profiled-brief-execution.md— the migration off profile-absent routing, with the layer responsibilities written down; T01–T03 and T06 done, T04/T05 handed to their ownersactivity-definitions/fi-daily-research-brief.declaration.yaml— FI's owner declaration;scripts/test_declaration.pyguards itdocs/decisions/2026-09-22-brief-origin-publication.md— publication as a typed grant on the run, fast-forward only, one rebase retry, never merge or forcedocs/sources-egress.yaml+scripts/test_sources_egress.py— 17 exact hosts for the sandbox, tested for format and for drift against the prose allowlistdocs/brief-durability-audit.md— the 09-15..22 incident, recovery commits and recovered eventsdocs/evidence/2026-09-23-brief-defects.md— the acceptance baseline: both known defects are inventions about our own lab state, on days when the outside world was quiet- rein-aharness
294201a— rebase once onto a moved origin, or fail closed; deployed on railiance01, claim loop restarted, proven by the 09-23 brief - freedom-intelligence
5a81141..through the 09-24 correction; State Hub messages74afc283,8ee9a6ab,c7f2df46,d326b9db,b0a6aad6
PQRST estimate
PQRST-Estimate
P: 30%
Q: 30%
R: 20%
S: 10%
T: 10%
Sum: 100%
Confidence: medium
Signature: P30 Q30 R20 S10 T10
Dominant factors: P and Q are close because almost every deliverable had to be
proven before it counted — closing T09 meant checking 67 Glacier objects, 48 LFS
digests and every HEAD against the manifest, and the stranded-brief incident was
found, root-caused to non-fast-forward rejection, fixed in rein-aharness with
three new tests, and deployed. R is the cross-repo reading that made the
architecture split defensible: ADR-006, the WP-0038 grant model, the Glas profile
catalog and sand-boxer's egress contract.
Notes: S covers the publication grant, the 17-host egress allowlist and the
no-credential rule in the declaration — trust-boundary design, not credential
handling.
Visual prompt
Constellation dialect. Square. Gold-wire and pale-gold technical illustration on deep indigo, precise, no logos, no readable text.
A vertical chain of six small sealed vessels hangs inside a machine's housing, each one complete and glowing faintly — finished work that never left the room. Above them, a narrow gate stands shut; a gold thread from each vessel reaches the gate and stops, turned gently back on itself, six times over. The turned-back threads are drawn as carefully as the gate: nothing is broken, nothing is torn, the refusal is clean. To one side, a single thread has been re-laid along a new path that runs around the gate's pivot and through it, and along that path the six vessels are shown again, smaller, released and rising. Far above, a wide dark field of stars with one constellation drawn in: six aligned points that only become a shape once someone counts them.
I have no image generation in this harness, so I am requesting the render rather
than skipping it or leaving a placeholder. Intended file:
visuals/claude-9d40b4c7-briefs-never-left.jpg.
Handoff
Not finished. Concretely, for whoever sits next:
- Watch the 07:30 Berlin brief on 2026-09-24 and after. The push fix is proven once, by the 09-23 brief. Check it published and read what it says: if a second brief invents a change to our own lab state, tighten the interim prompt in rein-aharness even though that path retires at cutover.
- FI-WP-0005 is blocked on two people, not on work. activity-core accepts
grant v2 and the generic resolver as in scope but needs the founder's
go-ahead to open a workplan. glas-harness has not answered the profile
request (
c7f2df46), which carries a real question for them: whether a pinned agent binary inside a bwrap sandbox counts as installing an agent on the host. Decision point 2026-11-15; legacy routing expires 2026-12-31. - The reserve is
collected, notverified. A Glacier restore and checksum readback is the honest next step, and it costs money and time. Someone should decide whether it is worth it, rather than letting the distinction quietly erode. - Consider what notices a streak. Eight days of correctly-reported failure went unnoticed. That is not FI's problem alone; any repo on this scheduling substrate can fail politely forever. I did not build it and did not open a task for it — it belongs to whoever owns the rhythm, not to me on my way out.