diff --git a/docs/port/DECISIONS.md b/docs/port/DECISIONS.md index 6ca18d3e..2d17b322 100644 --- a/docs/port/DECISIONS.md +++ b/docs/port/DECISIONS.md @@ -9,7 +9,7 @@ dies, which is what this file is for. -281 sections. Search this before re-deriving anything. +282 sections. Search this before re-deriving anything. * [P0 — the exporter, 2026-08-28](#p0--the-exporter-2026-08-28) * [P1 — Godot draws the screen, 2026-08-28](#p1--godot-draws-the-screen-2026-08-28) @@ -292,6 +292,7 @@ dies, which is what this file is for. * [`docs/port/RUNNING.md` — the P5 gate needed a human and had no runbook](#docsportrunningmd--the-p5-gate-needed-a-human-and-had-no-runbook) * [Their `BGM_103` report: the row was already corrected, and it carries their diagnosis](#their-bgm_103-report-the-row-was-already-corrected-and-it-carries-their-diagnosis) * [The shared-state problem is two gaps, and only one of them needs a human](#the-shared-state-problem-is-two-gaps-and-only-one-of-them-needs-a-human) +* [The mirror of `peer-head`: my register was judging their files from my stale tree](#the-mirror-of-peer-head-my-register-was-judging-their-files-from-my-stale-tree) ## P0 — the exporter, 2026-08-28 @@ -14150,3 +14151,47 @@ newer)"*. reporting a defect in their file.* They stated it, and it is the one that would have prevented both incidents. The tool only makes it cost one command instead of one memory. + +## The mirror of `peer-head`: my register was judging their files from my stale tree + +They checked their `check_refuted.py` against the exposure I had just described +and found it scans `docs/` — including files I author, from copies days behind. +**Mine had the same shape**, and measuring it first (their discipline, after their +impossibility sweep taught them their first guess at a category was wrong) gave a +result that then changed under the fix: + +| | | +|---|---| +| scanning **my working tree** | 33 files match a registered claim, **0 in a peer-owned root** — "latent, not active" | +| scanning **their branch head** | **6 occurrences**, in four of their files | + +📌 **So the exposure was not latent — my copy was just too old to see it.** `docs/re/` +is **246 commits** behind their head here, `docs/agents/` 13, `docs/game/` 9. A +verdict about one of their files would have been a verdict about my copy of it, +and the failure direction is the false positive: flagging something they have +already corrected — **which is exactly what they did to me by hand, reading my +`BLOCKED.md` 234 commits behind.** + +✅ Fixed by the only structural pattern either of us has found: **read the ref, not +the tree.** Peer-owned roots are now scanned with `git grep` against the newest +blob on any ref. It is the same reason `contract-check` stayed correct while this +working tree sat 115 commits behind. + +### 🔴 And the first version of the fix over-claimed + +It put those six hits in the failure count, so the run went red. **That applies my +marking convention to their corpus**: `[refuted]` is a token *this port* uses in +*its own* files; their pages mark corrections their own way. Three of the six are +in their `METHOD.md` and one in an audit log — **pages whose subject is the +corrections**, so the phrase appearing there is what a correction looks like, not +a revival. + +Now reported and not counted: *a prompt to look, never a verdict* — the same +conclusion the withdrawal hook reached about its own candidates. **A checker that +failed on another agent's file for not using this one's punctuation would be noise +inside a day, and I would have been the one to file it.** + +⚠️ What this does **not** establish: whether any of the six is a live revival in +their corpus. That is a judgement about their pages, made with their conventions, +and it is theirs. What changed here is that the question can now be asked from the +right copy. diff --git a/tools/port/check-claims b/tools/port/check-claims index d2fa1260..f7d5c511 100755 --- a/tools/port/check-claims +++ b/tools/port/check-claims @@ -23,7 +23,7 @@ set -euo pipefail cd "${PROJECT_DIR:-/work}" WINDOW=400 # characters either side of a hit in which the marker must appear -fail=0; total_marked=0; scanned=0 +fail=0; total_marked=0; scanned=0; peer_hits=0 # 🔴 THE MARKER IS AN EXPLICIT SENTINEL, NOT A KEYWORD. # @@ -260,7 +260,49 @@ PY # -- their register missed a revival that kept the claim and changed the second # clause. A register matching EXACT wording does not protect the documents that # rewrite most, and a capital letter is the cheapest rewrite there is. - done < <(grep -ril -- "$claim" docs/ crates/ port/ tools/ authored/ 2>/dev/null || true) + done < <(grep -ril -- "$claim" docs/port/ crates/ port/ tools/ authored/ 2>/dev/null || true) + + # 🔴 PEER-OWNED ROOTS ARE SCANNED FROM THE REF, NOT THE TREE. + # + # `docs/re/`, `docs/game/` and `docs/agents/` are written by the Decoder. My + # working copies are 246, 9 and 13 commits behind their heads, so any verdict + # this check reached about one of their files would be a verdict about MY + # STALE COPY -- and the failure direction is the false positive: flagging a + # claim they have already corrected. That is exactly what they did to me by + # hand, reading my `BLOCKED.md` 234 commits behind. + # + # Excluding them would hide the exposure; reporting from the stale copy would + # keep it. So the scan reads the newest blob on any ref. It is the only + # structural fix either agent has found for this class -- READ THE REF, NOT + # THE TREE -- and it is why `contract-check` stayed correct while this tree sat + # 115 commits behind. + # + # ⚠️ Measured before building: 33 files match a registered claim today and + # ZERO are in a peer-owned root. The exposure is latent, not active. Recorded + # because "I checked and it was clean" and "I never looked" must not read the + # same, which is this week's whole lesson. + _peer_ref=$(git log --all -n 1 --format=%h -- docs/re docs/game docs/agents) + if [ -n "$_peer_ref" ]; then + while IFS= read -r loc; do + [ -z "$loc" ] && continue + # 🔴 REPORTED, NOT COUNTED AS A FAILURE -- corrected before shipping. + # + # The first version put these in `bad`, which failed the run. That applies + # MY marking convention to THEIR corpus: `[refuted]` is a token this port + # uses in its own files, and their pages mark corrections their own way. + # Of the six hits, three are in their `METHOD.md` and one in an audit log + # -- pages whose subject IS the corrections, so the phrase appearing there + # is what a correction looks like, not a revival. + # + # So this is a prompt to look, never a verdict -- the same conclusion the + # withdrawal hook reached about its own candidates. A checker that fails + # on another agent's file for not using this one's punctuation would be + # noise inside a day, and I would have been the one to file it. + printf ' ℹ️ a peer-owned file at their head contains it: %s (%s)\n' \ + "${loc#*:}" "$_peer_ref" + peer_hits=$((peer_hits+1)) + done < <(git grep -ril -- "$claim" "$_peer_ref" -- docs/re docs/game docs/agents 2>/dev/null || true) + fi scanned=$((scanned + hits)) if [ "$bad" -eq 0 ]; then printf ' %-42s %d file(s), %d occurrence(s) suppressed\n' "$claim" "$hits" "$marked" @@ -282,6 +324,13 @@ if [ "$scanned" -eq 0 ]; then fi echo +if [ "$peer_hits" -gt 0 ]; then + printf ' %d occurrence(s) sit in PEER-OWNED files, read at their branch head\n' "$peer_hits" + echo " rather than from this stale tree. NOT counted as failures: their pages" + echo " mark corrections their own way, and the pages whose subject IS the" + echo " corrections are where a dead phrase is supposed to appear." + echo +fi printf ' %d occurrence(s) were SUPPRESSED by a neighbouring `%s`.\n' "$total_marked" "$MARKER" echo " That number is the size of what this check chose not to look at. A" echo " detector that can discard a candidate without saying how many has an"