docs(c-series): publish the ten counted packages, and close §4.6's escalations - #121
Merged
Conversation
…notes The artifacts behind Chapter 4 §4.6 and v0.2's Validation Record appendix, published so a stranger can check the claim without asking anyone. **Two escalations in the numbers ledger close on this commit.** The ten signed zips were in no repository, and the report and notes were in a private one while `Encoding_Protocol_v0_2.md:607-608` cited them by path — so the rate was Asserted to any outside reader regardless of what the packages would show. Both now resolve publicly. What this changes about the rung, stated precisely rather than upgraded by fiat: the **rate stays a recorded measurement**. A C-run is a fresh unsteered session against a live deployment, so re-running is a NEW measurement, which is what E3 forbids substituting for a recorded one — the same standing the ledger already gives the nagaraja figure and the Johnson raw-extract pair. What becomes stranger-re-derivable is the **verification**: `pip install uofa && uofa verify` against each committed zip, from its own shipped anchors, is a re-runnable command in the fullest sense, and thirty checks anyone can re-run reaches D7's Demonstrated for the packages themselves. C-5 is absent from packages/ deliberately: it signed and was voided on a tool-surface breach, excluded from the numerator, and its cause is ledgered in notes/C_5_VOID.md rather than hidden. C-11 is its replacement. The README cites each package's own SIGNING.txt rather than paraphrasing it: the zips already state that the shipped anchors prove these keys signed these bytes and do NOT bind either key to a real-world party, both identities being labeled demonstration fixtures. That is what makes publication an offer of verification rather than a claim of endorsement. The credenza.review namespace is recorded as a minted identifier under A-2's rule, not a live endpoint. Content-reviewed before publication: no private key material, no credentials, no local paths or usernames, xlsx metadata carries only openpyxl and timestamps, and every URL resolves to credenza.review (synthetic), uofa.net, or this repo's own published JSON-LD context.
…blication Twelve rows for the C-series, entered under this ledger's own rule: a figure whose artifact is not committed is entered as ESCALATION with what was searched, not omitted and not presented as checkable. Two were raised — the ten packages uncommitted, the report and notes private — and both are CLOSED by publishing to studies/c-series/ (793470e), not by waiver. **The rung splits, and the split is the honest statement.** The RATE stays a recorded measurement: a C-run is a fresh unsteered session against a live deployment, so a re-run is a NEW measurement, which is what E3 forbids substituting for a recorded one — the same standing the ledger already gives the nagaraja figure and the Johnson raw-extract pair. The VERIFICATION becomes stranger-re-derivable at D7's Demonstrated: `pip install uofa && uofa verify` against each committed zip from its own shipped anchors, re-run against the committed bytes under published 0.17.0 — 30 passed, 0 failed. Stating one blanket rung in either direction would be wrong in one direction or the other. SIGNING.txt is quoted rather than paraphrased. The packages already state that the shipped anchors prove these keys signed these bytes and do NOT bind either key to a real-world party, both identities being labeled demonstration fixtures — so the signatures demonstrate independent-attestation MECHANICS and bind to real parties only when custody does. The credenza.review namespace is recorded as a minted identifier under A-2's rule, not a live endpoint. No gate row: the series was pre-registered with a denominator and no pass threshold, so it enters §4.7's summary as a reported value with no verdict-column entry. Supplying one would be the retroactive-threshold move the pre-registration exists to prevent. Sweep: 98 -> 110 rows entered, 0 PENDING, 0 ESCALATION.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Publishes the artifacts behind Chapter 4 §4.6 and v0.2's Validation Record, and adds the ledger section that cites them.
What lands
440K total.
Why publish
Two escalations stood in
studies/ch4_numbers/LEDGER.md§4.6: the ten signed zips were in no repository, and the report and notes were in a private one whiledocs/Encoding_Protocol_v0_2.md:607-608cited them by path. The rate was Asserted to any outside reader regardless of what the packages would show. Both now resolve.These are the one artifact class in the program designed to be handed to strangers — self-verifying by construction — so leaving them uncommitted would have been the thesis declining its own claim at the last step.
The rung splits
nagarajafigure and the Johnson raw-extract pair.Re-run against the committed bytes under published
uofa 0.17.0: 30 passed, 0 failed.Verified after the bytes landed
shasum -a 256 -c SHA256SUMSviagit archive HEAD— 10/10 OK, matching the digests pinned when the rows were drafted, checked from committed bytes rather than staging copies3421 passed, 14 skippedContent review before publication
No private key material (
keys/holds twoBEGIN PUBLIC KEYblocks). No credentials — every secret-pattern hit was the extractor string…via openrouter.ai, which A-3 requires be recorded. No local paths or usernames.workbook.xlsxmetadata carries onlyopenpyxland timestamps. Every URL resolves tocredenza.review(synthetic namespace),uofa.net, or this repo's own published JSON-LD context.What these do and do not establish
Each zip's
SIGNING.txtgoverns, and is quoted rather than paraphrased: the anchors prove "these keys signed these bytes, and that nothing has changed since" and "do NOT bind either key to a real-world party … both identities are labeled demonstration fixtures."So the signatures demonstrate independent-attestation mechanics, and bind to real parties only when custody does. Publication is an offer of verification, not a claim of endorsement.
C-5is absent frompackages/deliberately — it signed and was voided on a tool-surface breach, excluded from the numerator, cause ledgered innotes/C_5_VOID.md.C-11is its replacement.