Skip to content

spec(proposal): Phase 5 — approval semantics over the Phase-2 Ward (threads-uqx)#6

Draft
BunsDev wants to merge 6 commits into
mainfrom
spec/phase-5-proposal-approval-semantics
Draft

spec(proposal): Phase 5 — approval semantics over the Phase-2 Ward (threads-uqx)#6
BunsDev wants to merge 6 commits into
mainfrom
spec/phase-5-proposal-approval-semantics

Conversation

@BunsDev

@BunsDev BunsDev commented Jul 18, 2026

Copy link
Copy Markdown
Member

Summary

Records the provisional Phase 5 approval-semantics design over the Phase-2 Ward.
Val opened implementation on the recorded defaults; independent Nova attestation
and final Val freeze remain explicit human gates.

Authority constraints

  • RFC-0001 and frozen Phase 0 remain upstream.
  • Protected-surface proposals reject at Gates 1, 2, and 4.
  • Principal-authorized protected updates use a separate audited authority path.
  • Channel remains the load/enforcement axis; ApprovalPath is an orthogonal
    promotion ceremony.
  • Veto windows are delayed-apply only and revalidate evidence at deadline.
  • Deterministic predicates are authoritative; descriptors and probes cannot
    authorize promotion.
  • Commit trailers, agent statements, and authorship claims cannot satisfy Nova
    or Val gates.

Remaining freeze gates

  • threads-uqx.2: merge familiar-contract PR RFC-0001 §5.5: add S_p(F) ∈ S_p(F) as explicit closure precondition (Cody soundness flag) #3 for closure and provenance.
  • threads-uqx.12: align RFC/schema approval-tier declarations with typed
    daemon semantics.
  • threads-uqx.13: create an authorized, sanitized, reproducible v0.1 migration
    fixture.
  • threads-uqx.8: complete implementation and migration fidelity.
  • threads-uqx.7: extend the Cave contract after daemon read models exist.
  • threads-uqx.9: independently attributable Nova coherence sign-off.
  • threads-uqx.10: direct Val freeze or rejection.

Review evidence

Fresh-context authority review identified four blocking defects. Commit
7eb8522 fixes all four and a second fresh-context review reported no
significant issues. The Beads graph is acyclic.

BunsDev and others added 2 commits July 18, 2026 04:18
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
…s-k9s)

Cave implementation wraps route-1 data as { weaves, degraded } rather than
overloading a WeaveSummary[] with degraded entries — the wrapped shape avoids
any fabricated health fields on degraded familiars. Same-day alignment of the
2026-07-18 §2.7/R12 amendment.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@BunsDev BunsDev self-assigned this Jul 18, 2026
BunsDev and others added 2 commits July 18, 2026 15:37
All 8 open questions resolved on Sage's recommended defaults:
- ApprovalPath separate from Channel (load axis preserved)
- Delayed apply only for veto windows (fail-closed posture)
- Classify-first for harness regions
- Deterministic + probe for invariants (not LLM-judge-only)
- RFC #3/#4 blocker resolved (familiar-contract@2a5bb98)
- Daemon contract before Cave ProposalView extension
- Display labels preserved, typed variants internal
- proposal_window_opened audit event lands with delayed apply

Rename PHASE-5-PROPOSAL -> PHASE-5-APPROVAL-SEMANTICS to reflect open status.

Co-authored-by: Nova <nova@opencoven.dev>
…uqx)

Add substantive annotations from Sage and Echo review (2026-07-18):

Decision #1: rationale callback — ApprovalPath is authoritative, Channel is
derived; if enforcement rule shifts, revisit all eight decisions.

Decision #2: audit implication — close event needs reason field
(applied|vetoed|expired|superseded); delayed-apply without it is a post-hoc
audit black hole.

Decision #3: forward-only promotion — retroactive region projection corrupts
authority trail with apparently-authored writes from before promotion.

Decision #4: fail-closed on extraction ambiguity — not silent LLM fallback;
ambiguity is an explicit ignored/blocked state.

Decision #5: RFC provenance pointer added.

Decision #6: Cave ProposalView labeled [DESIGNED, NOT SHIPPED] from the start.

Decision #7: label-variant round-trip is daemon wire contract (load-time reject
on drift); Cave has zero policy freedom over label strings.

Decision #8: proposal_window_opened paired with close event; window is a
first-class audit interval.

threads-uqx.3 design constraints (Sage): evidence_replay_hash on
ProposalClassification; VetoWindow.min_visible: Duration; label mapping as
daemon wire contract.

Co-authored-by: Sage <sage@opencoven.dev>
Co-authored-by: Echo <echo@opencoven.dev>
Co-authored-by: Nova <nova@opencoven.dev>
@BunsDev

BunsDev commented Jul 19, 2026

Copy link
Copy Markdown
Member Author

Independent coherence review (fresh-context, commissioned by coordinator session; reviewed branch tip 3fe72ca) — NEEDS-REVISION, record-level. Five findings before/alongside merge:

HIGH — decision #1 annotation contradicts frozen Phase-0. "ApprovalPath is authoritative; Channel is a derived load descriptor. Never gate on Channel" — but frozen PHASE-0 makes Channel a first-class enforcement axis: §2.1 (every gate check = 'does thread T hold under channel C'), §5 (unknown channel → Reject), §3.3 (C7 requires SerializationMarker under Channel::Serialization; two-compaction is channel-keyed). Taken literally the rule makes C7 unimplementable, and it misbinds the Phase-0 term descriptor (§2.2) onto Channel (§2.5 violation). Rescope to: "never derive ApprovalPath from Channel" — the underlying decision (classification independence) is sound. Urgent because uqx.3–.5 are already committed on feat/phase-5-uqx3-approval-types with this annotation marked load-bearing for all eight decisions.

MEDIUM×4:

  1. RFC-0001 §5.2/§4.2 divergence unflagged — RFC still mandates ward.toml TOML + [protected].invariants array; "v0.1 TOML stays dead" needs either a declaration→predicate compilation story or a named RFC-amendment dependency (the doc flags RFC-0001 §5.5: add S_p(F) ∈ S_p(F) as explicit closure precondition (Cody soundness flag) #3/RFC-0001 §4.2 predicate (iv): require provenance on admitted entries (Echo soundness flag) #4 scrupulously; this one is missing).
  2. §4 terminal audit events vs decision-feat(portability): surfaces content map + lossy one-way .af exporter (threads-jq4) #2 close reasons don't compose: superseded undefined, rejected absent from close reasons, expired ambiguous when expiry triggers apply — reconcile into one event/reason table before ApplyAudit (issue ward_audit: add an apply-audit event type so the coven daemon can persist Gate-4 apply records #5) consumes it.
  3. §0 ("does not start Phase 5") vs §7/§8 ("Phase 5 is open… executed") — restate as: §§0–5 proposal-as-reviewed, §§6–8 decision record.
  4. §7 bead list has no v01.bak corpus content migration/fidelity item — uqx.4 builds the mechanism; nothing accepts that the retired invariants (name/person/pronouns/purpose/coven) are actually re-expressed with coverage. Add a bead gated before/at uqx.10 freeze.

Verified sound: ApprovalPath lattice = RFC §5.3 exactly (incl. MUST NOT auto-promote protected surface); delayed-apply-only holds everywhere (no provisional-apply reintroduction); strand-kind and channel extension discipline respected; metaphor binding otherwise exemplary. Full analysis on bead threads-uqx.

BunsDev and others added 2 commits July 19, 2026 20:58
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@BunsDev

BunsDev commented Jul 20, 2026

Copy link
Copy Markdown
Member Author

Authority-review remediation is now pushed in 7eb8522. The spec excludes protected targets from ApprovalPath, makes RFC/schema alignment (threads-uqx.12) and an authorized reproducible migration fixture (threads-uqx.13) explicit freeze dependencies, and no longer treats a co-author trailer as Nova gate evidence. Final fresh-context review: no significant issues. PR remains draft because independent Nova attestation and final Val freeze are intentionally unsatisfied.

@BunsDev

BunsDev commented Jul 20, 2026

Copy link
Copy Markdown
Member Author

Upstream RFC/schema gate is now implemented as stacked draft OpenCoven/familiar-contract#4 (1854e4e). It adds standards-compliant TOML + JSON Schema validation, the typed approval compiler contract, 6 positive/36 negative conformance fixtures, migration guidance, and immutable RFC snapshots. It remains human-gated: familiar-contract#3 must merge first, then #4 retargets to main and requires independently attributable Nova + Val approval.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant