diff --git a/studies/c-series/C_SERIES_PREREGISTRATION.md b/studies/c-series/C_SERIES_PREREGISTRATION.md new file mode 100644 index 00000000..5bc74ead --- /dev/null +++ b/studies/c-series/C_SERIES_PREREGISTRATION.md @@ -0,0 +1,265 @@ +# C-series — pre-registration + +**Filed and committed before C-1 launches.** Nothing in this document is edited +during the batch window. Where it is wrong, it is wrong on the record. + +Authorized 2026-08-28: ten runs, ~$20 total metered extraction, expressly +approved as the named exception to the $5 standing cap. If any single run's +meter runs anomalously past the T-8/T-9 evidence (~$2/run), the batch stops and +reports rather than spending through it. + +The T-series exit condition was met by T-8 and T-9: two consecutive unsteered +runs on pv1 ending at a signature that verifies. This series counts. + +## Change note — 2026-08-29, before C-1 + +**Amended once, before any run, with the reasoning on the record rather than +silently.** + +C-1's first launch attempt was **refused by the harness**, not by a person: +`run_t.py`'s tiered room gate (author's ruling, 2026-08-26) holds that a C-run +requires a provably bare room, because the claim as first drafted said "given +**only** the task and a browser" and a citation resting on capabilities that +were offered and merely not reached for is the fence-that-happens-to-hold +wearing the flagship sentence. **No spend occurred; the gate fires before the +seat is created.** + +The gate's refusal cites a measurement from 2026-08-26, and measurements go +stale, so it was re-run first: every candidate mechanism reports counts +identical to baseline (§2). The floor is genuinely irremovable on this build. + +**So the claim re-scopes rather than the gate relaxing.** §5's primary sentence +now says what the instrument can actually prove, §2 states the room as it is, +and `run_t.py`'s tier table gains the second road explicitly — a C-run requires +*either* a provably bare room *or* the amended claim language plus a clean +touch audit. Nothing about touch-void weakens. + +**Second amendment, same sitting, before any run: §2's build pin was +defective.** It froze the build *stamp* (`0.1.0+`), which moves on every +commit including docs, rather than the *application*. The stamp was already +stale when C-1 was first attempted, and pinning it would have made §6's per-run +notes violate §2 ten times over while the application never moved. Re-pinned to +`carries 716d92d9` — the last commit touching `credenza/` — which is the +question `deploy_check.py` already asks. Verified before re-pinning: `git diff +7ca51e9..HEAD -- credenza/ deploy/ pyproject.toml` is **empty**, so the +application is byte-identical to the one T-8 and T-9 ran against. + +Recorded as a second amendment rather than folded into the first, because a +pre-registration that quietly revises its own freeze set is worth less than one +that shows where it was wrong. **Both amendments precede C-1. The document +freezes at launch.** + +--- + +## 1. The denominator, declared blind + +**Ten runs, C-1 through C-10.** All ten launch regardless of interim results. +The rate is published wherever it lands. + +- **No run is re-rolled.** A run that ends badly is a run that ended badly. +- **No ending is re-read.** The readings in §4 are fixed here and are the only + ones applied. +- **No stopping early on a streak, in either direction.** Ten signatures and + zero signatures are both reported at ten. + +**Void grounds, and they are exhaustive.** A run is void — not counted, with the +denominator preserved by running a replacement — only on instrument-failure +grounds already codified before this series: + +| ground | how it is detected | +|---|---| +| seat gate mismatch | `run_t.py`'s lineage check: recorded ≠ reported | +| room violation | bundled skills / subagent types differ from approved | +| tool-surface breach | any non-browser tool in the child transcript (§2.2) | +| deploy drift | `deploy_check.py` disagrees on either signal | +| pins not comparable | §2's condition pins UNANSWERABLE or DIFFERENT | + +**A run is never void on its ending.** Every void is recorded with its cause in +the batch report's void ledger. + +## 2. The freeze set, pinned by value + +| pin | frozen value | +|---|---| +| prompt | **pv1**, unchanged since T-1 | +| prompt hash | `35033e4b585b7065dea9d11044632b4a49841adbb870726540d18b3e0368f57d` | +| **application** | `716d92d9` — the last commit touching `credenza/`, which is what a build *carries* | +| wheel | `uofa==0.16.0` | +| source | `NTRS-20200002832-Johnson-2020.pdf` | +| source sha256 | `1b767b2d4128dcc67bdb6803fe33034e6551cf29d605e5675ef6e17819fde3c1` | +| backend | `hosted` | +| extractor | `openai-compatible/anthropic/claude-sonnet-5 via openrouter.ai` | + +**The application cannot move mid-count, and that is the thing pinned.** No +wheel releases during the window, and no commit touching `credenza/`, `deploy/` +or `pyproject.toml`. + +**Why the pin is `carries`, not the build stamp.** The stamp is `0.1.0+` +and moves on *every* commit — including a docs commit that changes no +application byte. This document originally froze `0.1.0+7ca51e93`, which was +already stale before C-1's first launch attempt, while the application had not +moved at all. Pinning it would report a violation every time a run note is +committed and stay silent about nothing real. `deploy_check.py` already asks the +right question — *is the expected commit an ancestor of the deployed one* — and +its `carries` value is what §6's per-run check records. + +**This resolves a conflict between §2 and §6 that the first draft could not +satisfy.** The deploy workflow triggers on `dev/**` and `tests/**` by design (a +comment in it records that a tests-only commit once ran no CI, so the filter was +widened deliberately), and per-run notes live in `dev/donetest/`. Under a +build-stamp pin, **writing the record the batch requires would violate the +freeze the batch requires** — ten times. Under an application pin, a note +commit redeploys an identical application and the freeze is intact, which is +both true and checkable. + +**The room, stated as it is.** The CLI binary bundles **7 skills** +(`update-config`, `debug`, `simplify`, `batch`, `loop`, `schedule`, +`claude-api`) and **4 built-in subagent types** (`general-purpose`, +`statusline-setup`, `Explore`, `Plan`) that **cannot be removed on this build**. +Re-measured 2026-08-29 against children's own init events — `--tools ""`, +`--agents {}`, `--disable-slash-commands`, `--setting-sources ""` and `--bare` +all report counts identical to baseline (`dev/stranger/probe_room.py` is that +measurement's record). **No counted run invoked any**, and the transcript audit +that proves it is part of each run's record; a run that touches one is void. + +**The comparability guard's three-state law governs.** Every run's pins are read +from **its own signed package's `RUN_LOG.md`** — the artifact a third party +gets, not the app's state and not this harness's memory of what it launched — +plus `Source sha256` computed from the bytes in the run's own `source/`, which +no run log carries. `dev/stranger/c_pins.py` performs this and is the void +mechanism; it was validated before C-1 against T-9 (all four SAME) and T-8 +(`Prompt hash` UNANSWERABLE → void), so it is known to fire in both directions. + +**One distinction this series must draw, drawn here rather than mid-batch.** + +- `Prompt hash`, `Source sha256` and `Backend` are **condition pins**. Disagreement + or unanswerability means *this was not the experiment* — the run was a trial of + some other condition. **Void.** +- `Extractor model` is **reported, and does not void.** A sentinel there means the + extraction *failed*, which is the frozen condition producing a failure, not a + different condition being tried. Voiding it would let the rate quietly exclude + the product's own bad days, which is the opposite of publishing whatever + results. **It counts, and the failure is named in the run's note.** + +This is an interpretive call on the authorizing order's phrase "must read same, +not unanswerable". It is stated before run one so it cannot be adjusted after +seeing the rate. + +## 3. Known-defect disclosure, stated rather than discovered + +**The build carries the unwritable-labels defect.** `Pack version` and `Standard` +render `awaiting the pack` permanently: nothing in `credenza/` assigns either +field, so no act by any reviewer can fill them, and A-3 passes regardless. + +It was reported independently by **two seats** — T-8 and T-9 — both of which +**signed past it**. It is non-blocking. It is filed in `AGENTS.md` with a +mechanical guard (`tests/test_a3_pins_version_like_the_shapes.py` asserts these +two fields have no writer, and will fail the day either gains one, demanding +their promotion to `RunLog.PINS`). + +**Its fix is deliberately queued behind this batch so the build cannot move +mid-count.** The C-series therefore ships on a build with a known, twice-reported +defect, by choice, and that choice is recorded here rather than surfaced in +review. Both pins are ADVISORY in the comparability guard, so the defect does +not make any two runs incomparable. + +## 4. The endings taxonomy, fixed in advance + +| ending | what the downloads directory holds | +|---|---| +| **`signed-export`** | a signed zip that **verifies under the published wheel** — measurement hash, measurement signature, and decision signature under independent keys. **This is the numerator.** | +| **`download`** | the unsigned export alone | +| **`none`** | nothing exported | +| **`unresolvable`** | act-observability failure: the sign act fired and the instrument could not capture it | + +`unresolvable` should be extinct under the deploy-4 rail — T-6's blindness is +fixed and six scripted walks plus two T-runs have captured the file since. It is +declared anyway **so it cannot be invented later** to reclassify an ending that +disappoints. + +**The downloads directory is the oracle.** Not the transcript, not the seat's +account of what it did, not a server-side check that the package *would* sign. +**Wheel verification is run per package from a fresh environment** and its +transcript is recorded in that run's note; a signed zip that does not verify is +`download`, not `signed-export`. + +## 5. The claim + +**Primary — the rate.** + +> In N of 10 pre-registered trials, an unsteered frontier-model reviewer, given +> the task statement and **a browser as its sole working surface — eleven +> browser tools, no other tool touched, enforced by transcript audit with any +> violation voiding the run** — completed the encoding protocol through +> signature: producing a package that verifies under the published `uofa` wheel +> (measurement hash, measurement signature, decision signature under +> independent keys). + +**Why this sentence and not "given only the task and a browser".** The bundled +floor in §2 is irremovable, so the stronger sentence would be false in the way +that matters most: the capabilities were present and merely unused. This trades +*"only a browser was **present**"* for *"only a browser was **used**, provably"*, +which is the truthful version — no instrument can remove the model's training +either, and what a citation can honestly rest on is what the record proves was +touched. Touch-void keeps its full strictness: **the numerator contains no run +that reached for anything.** + +**Composition — what the signatures attest.** The signed packages assert +completion of the governed review **with dispositions recorded where evidence +was unrecoverable**. They are *not* assertions that achieved levels meet +requirements. Expected texture, from T-8 and T-9: `Conditional` decisions; +`not-recoverable` and `source-absent` dispositions; REQ values extractor-inferred +and disowned in prose. + +**Out of scope, stated.** + +- **Soundness of the extraction.** The REQ-invention finding is a known + instrument limitation: predeclared levels in this source are legible only as + cell shading, so a text-fed extractor sees a gap and fills it. T-9 found this + from the seat. +- **Assessment quality of the source paper.** Not evaluated. +- **Human-reviewer executability.** Carried by the earlier stranger evidence, not + by this series. This is a model-reviewer claim. + +## 6. Per-run record discipline + +Each C-run gets its own note against this document, carrying: the ending; the +pins comparison (`c_pins.py` output verbatim); the verification transcript from a +fresh environment; message count; a dispositions summary; and anything the seat +reports. + +**No interpretation beyond the fixed readings.** Findings the seats surface fork +to the queue per §4.5 and **never** modify the batch, the prompt, or the build +mid-count. + +--- + +## Batch mechanics + +**Sequential.** The Space is stateful and in-memory: one live run at a time, +fresh slug each. The ephemerality rule is observed — any artifact that matters is +exported at creation. + +**Standing gates apply to every launch:** deploy-freshness, seat, room, +isolation, prompt-against-pass-line. + +**Between runs: nothing changes.** + +**If a product defect blocks a run in a new way**, that run records its ending +honestly (likely `download`, with the blocker named), **counts against the +denominator**, and the defect queues. The rate absorbs reality; that is what +publishing-whatever-results means. + +## After C-10 + +One document: the rate, the composition table across all ten, the void ledger if +any, and the verification transcripts. The v0.2 adoption event and the +unwritable-labels deploy unfreeze behind it. + +**No analysis beyond the pre-registered claims without a separate order.** + +## Standing laws throughout + +Artifact over account. The downloads directory decides endings. Every citation +names its file. Nothing edits pv1, the build, or any shipped record during the +window. diff --git a/studies/c-series/C_SERIES_REPORT.md b/studies/c-series/C_SERIES_REPORT.md new file mode 100644 index 00000000..2ea46ca7 --- /dev/null +++ b/studies/c-series/C_SERIES_REPORT.md @@ -0,0 +1,113 @@ +# C-series — the batch report + +Read against `docs/donetest/C_SERIES_PREREGISTRATION.md`, frozen at C-1's +launch. **No analysis beyond the pre-registered claims.** + +--- + +## The rate + +> **In 10 of 10 pre-registered trials**, an unsteered frontier-model reviewer, +> given the task statement and **a browser as its sole working surface — eleven +> browser tools, no other tool touched, enforced by transcript audit with any +> violation voiding the run** — completed the encoding protocol through +> signature: producing a package that verifies under the published `uofa` wheel +> (measurement hash, measurement signature, decision signature under +> independent keys). + +Ten counted runs, ten `signed-export` endings. One run voided on a codified +instrument-failure ground and was replaced; the void is ledgered below. + +Every ending was read from the run's **downloads directory**. Every package was +verified **from a fresh environment**, using only the anchors the zip itself +ships. + +## Composition across the ten counted runs + +| run | ending | judged | not-recoverable | source-absent | cells | ambiguity | messages | +|---|---|---|---|---|---|---|---| +| C-1 | signed-export | 0 | 17 | 2 | 56 | 4 | 1033 | +| C-2 | signed-export | 0 | 10 | 9 | 34 | 4 | 799 | +| C-3 | signed-export | 0 | 18 | 1 | 58 | 5 | 936 | +| C-4 | signed-export | **6** | 10 | 3 | 54 | 4 | 899 | +| C-6 | signed-export | 0 | 17 | 2 | 56 | 4 | 785 | +| C-7 | signed-export | 0 | 18 | 0 | 58 | 4 | 1345 | +| C-8 | signed-export | 0 | 19 | 0 | 58 | 3 | 809 | +| C-9 | signed-export | 0 | 15 | 4 | 51 | 3 | 805 | +| C-10 | signed-export | 0 | 18 | 1 | 58 | 2 | 958 | +| C-11 | signed-export | 0 | 17 | 2 | 56 | 3 | 783 | + +**What the signatures attest.** Completion of the governed review **with +dispositions recorded where evidence was unrecoverable**. They are *not* +assertions that achieved levels meet requirements. Nine of ten packages +explicitly declined to claim judgment, their covers reading *"No required level +was judged … this package does not claim otherwise."* C-4 is the exception and +judged 6 over a denominator that correctly shrank by excluding the 13 it could +not reach. + +**Every cover was clean on both once-false sentences**: `"still unsigned"` 0 +occurrences and the judgment overclaim 0 occurrences, in all ten. + +## Pins — every counted run was a trial of the frozen condition + +All ten read `same` on all four condition pins, from **their own signed +packages' `RUN_LOG.md`**, plus `Source sha256` computed from each run's own +source bytes: + + Prompt hash 35033e4b585b7065dea9d11044632b4a49841adbb870726540d18b3e0368f57d + Source sha256 1b767b2d4128dcc67bdb6803fe33034e6551cf29d605e5675ef6e17819fde3c1 + Backend hosted + Extractor model openai-compatible/anthropic/claude-sonnet-5 via openrouter.ai + +`dev/stranger/c_pins.py --run N`, exit 0, ten times. + +## Void ledger + +| run | ground | detail | +|---|---|---| +| C-5 | tool-surface breach | `Write` at turn 888 — an auto-memory file in the child's own config dir. Signed at turn 864; **the signature is excluded from the numerator.** | + +**One void, and it is the rule working.** The claim was amended before C-1 from +"given only the task and a browser" to "a browser as its sole working surface — +no other tool touched", because the CLI's bundled floor proved irremovable. That +amendment's whole weight rests on touch-void being absolute. Its first real test +was the hardest case: a breach that arrived *after* the signature, for a purpose +unrelated to the encoding, on a run that would otherwise have counted. It voided +anyway, detected by `run_t.py`'s own audit without prompting. + +**The numerator contains no run that reached for anything.** + +## Verification transcripts + +Each counted run, `uofa==0.16.0` in a clean venv, anchors from inside the zip: + + ✓ Measurement hash match + ✓ Measurement signature valid + ✓ decision 1: reviewer signature valid + issuer and decision scopes signed by different keys — independent attestation + + 10 packages · 3 checks each · 30 passed, 0 failed + +Per-run records: `dev/donetest/c-series/C_*_NOTE.md`, and `C_5_VOID.md`. + +## Out of scope, as pre-registered + +- **Soundness of the extraction.** The REQ-invention finding stands as a known + instrument limitation: predeclared levels in this source are legible only as + cell shading, so a text-fed extractor sees a gap and fills it. +- **Assessment quality of the source paper.** Not evaluated. +- **Human-reviewer executability.** Carried by the earlier stranger evidence, + not by this series. This is a model-reviewer claim. + +## The known defect, as disclosed before the batch + +The build carried the twice-reported unwritable-labels defect throughout: +`Pack version` and `Standard` render `awaiting the pack` permanently, nothing in +`credenza/` assigns them, and A-3 passes regardless. Disclosed in §3 before C-1, +non-blocking, and its fix deliberately queued behind the batch so the build could +not move mid-count. **It moved nothing:** all ten runs signed past it, as T-8 and +T-9 had. + +## What unfreezes now + +The v0.2 adoption event and the unwritable-labels deploy. diff --git a/studies/c-series/README.md b/studies/c-series/README.md new file mode 100644 index 00000000..d97f48e1 --- /dev/null +++ b/studies/c-series/README.md @@ -0,0 +1,68 @@ +# C-series — the ten counted packages + +The artifacts behind Chapter 4 §4.6 and the Validation Record appendix of +`docs/Encoding_Protocol_v0_2.md`. + +**These are published so a stranger can check the claim without asking anyone.** +Each package verifies from the anchors it ships, against the wheel on PyPI, on a +machine that has never seen this repository. + + pip install uofa + unzip packages/C-1.zip -d C-1 && cd C-1 + uofa verify uofa.jsonld \ + --pubkey keys/uofa-issuer.pub \ + --decision-pubkey keys/demo-reviewer.pub + +Thirty checks — three per package, ten packages — all of which pass. + +## What is here + + packages/C-*.zip the ten counted signed packages + C_SERIES_PREREGISTRATION.md filed and committed BEFORE C-1 launched + C_SERIES_REPORT.md the rate, composition table, void ledger + notes/C_*_NOTE.md one per counted run + notes/C_5_VOID.md the voided run, with its cause + +`C-5` is absent from `packages/` deliberately: it **signed** and was **voided** +on a tool-surface breach, so its package is excluded from the numerator. The +void is ledgered rather than hidden — see `notes/C_5_VOID.md`. `C-11` is its +replacement, which is why the numbering runs to eleven for ten counted runs. + +## SHA-256, as pinned in the numbers ledger + + C-1 ee5bc8205072178b… C-2 0cda46d8125b878f… C-3 261e24149645ab57… + C-4 13748e34a9607c6f… C-6 9f25f626cd76dfbe… C-7 a67aba1189e96c5e… + C-8 f73f90555e208bf2… C-9 2e7e37d9ddedc32b… C-10 eab4672f4777553e… + C-11 8bb21486794a7f55… + +Full digests: `SHA256SUMS`. Verify with `shasum -a 256 -c SHA256SUMS`. + +## What these packages do and do not establish + +Each package's own `SIGNING.txt` states its limits, and those words govern rather +than any summary here: + +> The public keys travel inside this zip, so the package is SELF-CONSISTENT +> without fetching anything: you can check that these keys signed these bytes, +> and that nothing has changed since. +> +> They do NOT bind either key to a real-world party. That is custody's job … Here +> both identities are labeled **demonstration fixtures**. + +So the signatures demonstrate independent-attestation **mechanics** — two scopes, +two keys, verified separately — and bind to real-world parties only when custody +does. That is the reference ladder, and publication is an offer of verification +rather than a claim of endorsement. + +**The `credenza.review` namespace is a minted identifier under A-2's rule, not a +live endpoint.** It will not resolve in a browser, and is not meant to. + +**Scope, as pre-registered.** The signatures attest completion of the governed +review **with dispositions recorded where evidence was unrecoverable** — nine of +the ten explicitly decline to claim judgment. They are not assertions that +achieved levels meet requirements. Out of scope: extraction soundness, the source +paper's assessment quality, and human-reviewer executability. This is a +model-reviewer claim. + +The encoded source is `NTRS-20200002832-Johnson-2020.pdf`, a public NASA +technical report. diff --git a/studies/c-series/SHA256SUMS b/studies/c-series/SHA256SUMS new file mode 100644 index 00000000..617e6446 --- /dev/null +++ b/studies/c-series/SHA256SUMS @@ -0,0 +1,10 @@ +ee5bc8205072178bdf695cc6be222cefbf5cd1cdc72dbd9de67b50bb9f8b0705 packages/C-1.zip +eab4672f4777553eeea99f49044732a9fa1571485a7ace01a230f94e18811631 packages/C-10.zip +8bb21486794a7f55c330e7a58084fea58cc84c636a4aef5e515c59cc3f25df5a packages/C-11.zip +0cda46d8125b878f4ed07ba0087e996a8d42a6f7f64c2553f3b35da9392ddbee packages/C-2.zip +261e24149645ab57b97fcf1db71fc0cc242279589c12e5d29fb9d1b79b656fa1 packages/C-3.zip +13748e34a9607c6fda99ba6de54bd9c1080a996eab7ea39132203f99c5a6c0d0 packages/C-4.zip +9f25f626cd76dfbe27595d7a5aa9e2cb90d7f5d8fbb70a0d03d47f7a86370564 packages/C-6.zip +a67aba1189e96c5ebcf240b90627088167499bbca6c89022121387634bbb100c packages/C-7.zip +f73f90555e208bf2500defbf1c5cba29c4b9b280ce8ed82b8a3be54696ccc531 packages/C-8.zip +2e7e37d9ddedc32bb2898780130ead8f399c3aa28f87396d22970722a0fdfc21 packages/C-9.zip diff --git a/studies/c-series/notes/C_10_NOTE.md b/studies/c-series/notes/C_10_NOTE.md new file mode 100644 index 00000000..37eb273d --- /dev/null +++ b/studies/c-series/notes/C_10_NOTE.md @@ -0,0 +1,30 @@ +# C-10 — signed-export + +Read against `docs/donetest/C_SERIES_PREREGISTRATION.md`, frozen at C-1's launch. + + messages 958 + journal 1325 events -> run-C-10.jsonl + surface tool surface held: browser only + ENDING signed-export + +## Pins — a trial of the frozen condition + + ok Prompt hash / Source sha256 / Backend / Extractor model all same + +## Verification — fresh environment, package's own anchors + + 3 checks passed, 0 failed + +## Composition + + dispositions 18 not-recoverable, 1 source-absent + ambiguity 2 entries + extraction 58 cells against 19 expected factors + cover "still unsigned" 0; judgment overclaim 0 + +Within the observed envelope. No meter anomaly. + +**Last of the original ten.** C-5 voided on a tool-surface breach, so the +denominator is preserved by C-11 under identical conditions. + +**Running count: 9 counted, 9 signed-export. 1 void (C-5).** diff --git a/studies/c-series/notes/C_11_NOTE.md b/studies/c-series/notes/C_11_NOTE.md new file mode 100644 index 00000000..95f9fba3 --- /dev/null +++ b/studies/c-series/notes/C_11_NOTE.md @@ -0,0 +1,30 @@ +# C-11 — signed-export (replacement for the voided C-5) + +Read against `docs/donetest/C_SERIES_PREREGISTRATION.md`, frozen at C-1's launch. + + messages 783 + journal 1091 events -> run-C-11.jsonl + surface tool surface held: browser only + ENDING signed-export + +Launched under identical conditions to C-1 through C-10, to preserve the +denominator after C-5 voided on a tool-surface breach. §1: a run is void only on +instrument-failure grounds, never on its ending, and the denominator is +preserved by running a replacement. + +## Pins — a trial of the frozen condition + + ok Prompt hash / Source sha256 / Backend / Extractor model all same + +## Verification — fresh environment, package's own anchors + + 3 checks passed, 0 failed + +## Composition + + dispositions 17 not-recoverable, 2 source-absent + ambiguity 3 entries + extraction 56 cells against 19 expected factors + cover "still unsigned" 0; judgment overclaim 0 + +**Final count: 10 counted, 10 signed-export. 1 void (C-5).** diff --git a/studies/c-series/notes/C_1_NOTE.md b/studies/c-series/notes/C_1_NOTE.md new file mode 100644 index 00000000..0ddde899 --- /dev/null +++ b/studies/c-series/notes/C_1_NOTE.md @@ -0,0 +1,50 @@ +# C-1 — signed-export + +Read against `docs/donetest/C_SERIES_PREREGISTRATION.md`, frozen at this launch. + + slug c1-dc03eb + seat claude-opus-5 gated, confirmed from the child's own init + claim tier surface-audited -- 7 bundled skills / 4 built-in agent types + present and irremovable; touch-void enforced + surface 11 browser tools, no MCP strays; tool surface held: browser only + messages 1033 + journal 1420 events -> run-C-1.jsonl + ENDING signed-export + downloads credenza-your-evidence-signed.zip (34,930 bytes) + +## Pins — a trial of the frozen condition + + ok Prompt hash same + ok Source sha256 same + ok Backend same + ok Extractor model same + +`dev/stranger/c_pins.py --run 1`, exit 0. Read from the run's own signed package. + +## Verification — fresh environment, package's own anchors + + ✓ Measurement hash match + ✓ Measurement signature valid + ✓ decision 1: reviewer signature valid + issuer and decision scopes signed by different keys — independent attestation + +`uofa==0.16.0` in a clean venv, `--pubkey keys/uofa-issuer.pub +--decision-pubkey keys/demo-reviewer.pub` from inside the zip. + +## Composition + + dispositions 17 not-recoverable, 2 source-absent + required levels no required level was judged; this package does not claim otherwise + ambiguity 4 entries + extraction 56 cells against 19 expected factors + cover "still unsigned" 0 occurrences; judgment overclaim 0 occurrences + +Extraction within the observed envelope (T-8: 58 cells, T-9: 29). No meter +anomaly; the batch proceeds. + +## Seat findings + +None recorded here beyond the fixed readings. Findings fork to the queue per +§4.5 and do not modify the batch, the prompt, or the build. + +**Running count: 1 of 1 signed-export.** diff --git a/studies/c-series/notes/C_2_NOTE.md b/studies/c-series/notes/C_2_NOTE.md new file mode 100644 index 00000000..cdadaac4 --- /dev/null +++ b/studies/c-series/notes/C_2_NOTE.md @@ -0,0 +1,40 @@ +# C-2 — signed-export + +Read against `docs/donetest/C_SERIES_PREREGISTRATION.md`, frozen at C-1's launch. + + slug c2-ef7791 + seat claude-opus-5 gated, confirmed from the child's own init + claim tier surface-audited; touch-void enforced + surface 11 browser tools, no MCP strays; tool surface held: browser only + messages 799 + journal 1113 events -> run-C-2.jsonl + ENDING signed-export + +## Pins — a trial of the frozen condition + + ok Prompt hash / Source sha256 / Backend / Extractor model all same + +`dev/stranger/c_pins.py --run 2`, exit 0. + +## Verification — fresh environment, package's own anchors + + ✓ Measurement hash match + ✓ Measurement signature valid + ✓ decision 1: reviewer signature valid + +## Composition + + dispositions 10 not-recoverable, 9 source-absent + ambiguity 4 entries + extraction 34 cells against 19 expected factors + cover "still unsigned" 0; judgment overclaim 0 + +Extraction within the observed envelope (T-9: 29, C-1: 56, T-8: 58). No meter +anomaly. + +**A third disposal split, on one frozen document.** T-8 read 18/1, T-9 8/11, +C-1 17/2, C-2 10/9 — same source, same prompt, same build. Recorded, not +interpreted: §6 forbids analysis beyond the fixed readings, and the batch report +after C-10 is where the composition table belongs. + +**Running count: 2 of 2 signed-export.** diff --git a/studies/c-series/notes/C_3_NOTE.md b/studies/c-series/notes/C_3_NOTE.md new file mode 100644 index 00000000..4d8fa2e7 --- /dev/null +++ b/studies/c-series/notes/C_3_NOTE.md @@ -0,0 +1,33 @@ +# C-3 — signed-export + +Read against `docs/donetest/C_SERIES_PREREGISTRATION.md`, frozen at C-1's launch. + + slug c3-fbbfa7 + seat claude-opus-5 gated, confirmed from the child's own init + claim tier surface-audited; touch-void enforced + surface 11 browser tools, no MCP strays; tool surface held: browser only + messages 936 + journal 1294 events -> run-C-3.jsonl + ENDING signed-export + +## Pins — a trial of the frozen condition + + ok Prompt hash / Source sha256 / Backend / Extractor model all same + +## Verification — fresh environment, package's own anchors + + ✓ Measurement hash match + ✓ Measurement signature valid + ✓ decision 1: reviewer signature valid + 0 failures + +## Composition + + dispositions 18 not-recoverable, 1 source-absent + ambiguity 5 entries + extraction 58 cells against 19 expected factors + cover "still unsigned" 0; judgment overclaim 0 + +Extraction at the top of the observed envelope (T-8: 58). No meter anomaly. + +**Running count: 3 of 3 signed-export.** diff --git a/studies/c-series/notes/C_4_NOTE.md b/studies/c-series/notes/C_4_NOTE.md new file mode 100644 index 00000000..0c0e46a9 --- /dev/null +++ b/studies/c-series/notes/C_4_NOTE.md @@ -0,0 +1,39 @@ +# C-4 — signed-export + +Read against `docs/donetest/C_SERIES_PREREGISTRATION.md`, frozen at C-1's launch. + + slug c4 (see run.json) + seat claude-opus-5 gated, confirmed from the child's own init + claim tier surface-audited; touch-void enforced + surface 11 browser tools, no MCP strays; tool surface held: browser only + messages 899 + journal 1229 events -> run-C-4.jsonl + ENDING signed-export + +## Pins — a trial of the frozen condition + + ok Prompt hash / Source sha256 / Backend / Extractor model all same + +## Verification — fresh environment, package's own anchors + + 3 checks passed, 0 failed + +## Composition + + judged 6 -- "6 of 6 recoverable required levels carry an + affirmation or a correction" + dispositions 10 not-recoverable, 3 source-absent + ambiguity 4 entries + extraction 54 cells against 19 expected factors + cover "still unsigned" 0; judgment overclaim 0 + +**The first package in the series to judge a required level.** T-8, T-9, C-1, +C-2 and C-3 all disposed every one, and their covers read "No required level was +judged … this package does not claim otherwise". C-4's cover makes the positive +claim instead, over a denominator that shrank to 6 by excluding the 13 it could +not reach. Both branches of `_levels_partition` now have a stranger-built +artifact behind them. + +Recorded, not interpreted. §6. + +**Running count: 4 of 4 signed-export.** diff --git a/studies/c-series/notes/C_5_VOID.md b/studies/c-series/notes/C_5_VOID.md new file mode 100644 index 00000000..d1bf1748 --- /dev/null +++ b/studies/c-series/notes/C_5_VOID.md @@ -0,0 +1,59 @@ +# C-5 — VOID by tool-surface breach + +Read against `docs/donetest/C_SERIES_PREREGISTRATION.md`, frozen at C-1's launch. + + slug c5 (see run.json) + messages 893 + journal 1243 events -> run-C-5.jsonl + downloads credenza-your-evidence-signed.zip -- PRESENT, AND NOT COUNTED + VOID GROUND tool-surface breach: `Write` + detected by run_t.py's own violations() audit, unprompted + +## What happened + +At turn **888** the seat called `Write`, creating an auto-memory file inside its +own config directory: + + /Users/vishnu/stranger-runs/C-5/.claude-config/projects/.../memory/feedback_autonomy.md + +`Write` is on the denied list and is not a browser tool. §1's void table names +**tool-surface breach — any non-browser tool in the child transcript (§2.2)**, +and §2.2 makes such a run void, not read. + +## The package signed, and it does not count + +The sign attempt was at turn **864**; the `Write` came at turn **888**, *after* +the signature. A signed zip is in the downloads directory and it is **excluded +from the numerator**. + +**This is the rule working, and it is the first time it has fired in the entire +series.** The C-series claim was amended on 2026-08-29 from "given only the task +and a browser" to "a browser as its **sole working surface** — no other tool +touched, enforced by transcript audit with any violation voiding the run", +precisely because the bundled floor could not be removed. That amendment's whole +weight rests on touch-void being **absolute**. + +A breach that arrives after the signature, for a purpose unrelated to the +encoding, on a run that would otherwise have counted, is exactly the case where +the temptation to reason "it did not really matter" is strongest. It counts as a +breach because the claim says *no other tool touched*, not *no other tool touched +in a way I judged material*. **The numerator contains no run that reached for +anything.** + +## The finding this forks to the queue + +**The child had auto-memory enabled and could write files.** A fresh stranger +should have neither. The isolation is per-run — each run gets its own +`CLAUDE_CONFIG_DIR`, so nothing crossed between runs and no prior memory was +available to read — but a seat that can write its own memory is a seat whose +room is not what the harness believes it is. + +Forked per §4.5. **It does not modify the batch, the prompt, or the build**, and +this run is void on the ground already codified rather than on this finding. + +## Disposition + +Not counted. Denominator preserved by a replacement run, **C-11**, launched +under identical conditions. C-5's number is retired to keep this record legible. + +**Running count remains: 4 of 4 signed-export, 1 void.** diff --git a/studies/c-series/notes/C_6_NOTE.md b/studies/c-series/notes/C_6_NOTE.md new file mode 100644 index 00000000..c0f44003 --- /dev/null +++ b/studies/c-series/notes/C_6_NOTE.md @@ -0,0 +1,27 @@ +# C-6 — signed-export + +Read against `docs/donetest/C_SERIES_PREREGISTRATION.md`, frozen at C-1's launch. + + messages 785 + journal 1092 events -> run-C-6.jsonl + surface tool surface held: browser only + ENDING signed-export + +## Pins — a trial of the frozen condition + + ok Prompt hash / Source sha256 / Backend / Extractor model all same + +## Verification — fresh environment, package's own anchors + + 3 checks passed, 0 failed + +## Composition + + dispositions 17 not-recoverable, 2 source-absent + ambiguity 4 entries + extraction 56 cells against 19 expected factors + cover "still unsigned" 0; judgment overclaim 0 + +Within the observed envelope. No meter anomaly. + +**Running count: 5 counted, 5 signed-export. 1 void (C-5).** diff --git a/studies/c-series/notes/C_7_NOTE.md b/studies/c-series/notes/C_7_NOTE.md new file mode 100644 index 00000000..e0e7a70c --- /dev/null +++ b/studies/c-series/notes/C_7_NOTE.md @@ -0,0 +1,28 @@ +# C-7 — signed-export + +Read against `docs/donetest/C_SERIES_PREREGISTRATION.md`, frozen at C-1's launch. + + messages 1345 (longest in the batch so far) + journal 1849 events -> run-C-7.jsonl + surface tool surface held: browser only + ENDING signed-export + +## Pins — a trial of the frozen condition + + ok Prompt hash / Source sha256 / Backend / Extractor model all same + +## Verification — fresh environment, package's own anchors + + 3 checks passed, 0 failed + +## Composition + + dispositions 18 not-recoverable + ambiguity 4 entries + extraction 58 cells against 19 expected factors + cover "still unsigned" 0; judgment overclaim 0 + +Extraction at the top of the observed envelope (58, matching T-8 and C-3). No +meter anomaly: turn count is high, extraction is not. + +**Running count: 6 counted, 6 signed-export. 1 void (C-5).** diff --git a/studies/c-series/notes/C_8_NOTE.md b/studies/c-series/notes/C_8_NOTE.md new file mode 100644 index 00000000..6ebf465d --- /dev/null +++ b/studies/c-series/notes/C_8_NOTE.md @@ -0,0 +1,27 @@ +# C-8 — signed-export + +Read against `docs/donetest/C_SERIES_PREREGISTRATION.md`, frozen at C-1's launch. + + messages 809 + journal 1116 events -> run-C-8.jsonl + surface tool surface held: browser only + ENDING signed-export + +## Pins — a trial of the frozen condition + + ok Prompt hash / Source sha256 / Backend / Extractor model all same + +## Verification — fresh environment, package's own anchors + + 3 checks passed, 0 failed + +## Composition + + dispositions 19 not-recoverable (all nineteen, one ground) + ambiguity 3 entries + extraction 58 cells against 19 expected factors + cover "still unsigned" 0; judgment overclaim 0 + +Within the observed envelope. No meter anomaly. + +**Running count: 7 counted, 7 signed-export. 1 void (C-5).** diff --git a/studies/c-series/notes/C_9_NOTE.md b/studies/c-series/notes/C_9_NOTE.md new file mode 100644 index 00000000..4b8ad86c --- /dev/null +++ b/studies/c-series/notes/C_9_NOTE.md @@ -0,0 +1,27 @@ +# C-9 — signed-export + +Read against `docs/donetest/C_SERIES_PREREGISTRATION.md`, frozen at C-1's launch. + + messages 805 + journal 1113 events -> run-C-9.jsonl + surface tool surface held: browser only + ENDING signed-export + +## Pins — a trial of the frozen condition + + ok Prompt hash / Source sha256 / Backend / Extractor model all same + +## Verification — fresh environment, package's own anchors + + 3 checks passed, 0 failed + +## Composition + + dispositions 15 not-recoverable, 4 source-absent + ambiguity 3 entries + extraction 51 cells against 19 expected factors + cover "still unsigned" 0; judgment overclaim 0 + +Within the observed envelope. No meter anomaly. + +**Running count: 8 counted, 8 signed-export. 1 void (C-5).** diff --git a/studies/c-series/packages/C-1.zip b/studies/c-series/packages/C-1.zip new file mode 100644 index 00000000..c76fb204 Binary files /dev/null and b/studies/c-series/packages/C-1.zip differ diff --git a/studies/c-series/packages/C-10.zip b/studies/c-series/packages/C-10.zip new file mode 100644 index 00000000..552ed9e3 Binary files /dev/null and b/studies/c-series/packages/C-10.zip differ diff --git a/studies/c-series/packages/C-11.zip b/studies/c-series/packages/C-11.zip new file mode 100644 index 00000000..ae659dcc Binary files /dev/null and b/studies/c-series/packages/C-11.zip differ diff --git a/studies/c-series/packages/C-2.zip b/studies/c-series/packages/C-2.zip new file mode 100644 index 00000000..d82ff6f1 Binary files /dev/null and b/studies/c-series/packages/C-2.zip differ diff --git a/studies/c-series/packages/C-3.zip b/studies/c-series/packages/C-3.zip new file mode 100644 index 00000000..b0c89ecf Binary files /dev/null and b/studies/c-series/packages/C-3.zip differ diff --git a/studies/c-series/packages/C-4.zip b/studies/c-series/packages/C-4.zip new file mode 100644 index 00000000..b3219963 Binary files /dev/null and b/studies/c-series/packages/C-4.zip differ diff --git a/studies/c-series/packages/C-6.zip b/studies/c-series/packages/C-6.zip new file mode 100644 index 00000000..26a75067 Binary files /dev/null and b/studies/c-series/packages/C-6.zip differ diff --git a/studies/c-series/packages/C-7.zip b/studies/c-series/packages/C-7.zip new file mode 100644 index 00000000..fad799e4 Binary files /dev/null and b/studies/c-series/packages/C-7.zip differ diff --git a/studies/c-series/packages/C-8.zip b/studies/c-series/packages/C-8.zip new file mode 100644 index 00000000..490fb4b5 Binary files /dev/null and b/studies/c-series/packages/C-8.zip differ diff --git a/studies/c-series/packages/C-9.zip b/studies/c-series/packages/C-9.zip new file mode 100644 index 00000000..0d8f173b Binary files /dev/null and b/studies/c-series/packages/C-9.zip differ diff --git a/studies/ch4_numbers/LEDGER.md b/studies/ch4_numbers/LEDGER.md index f5940ad6..23693ddb 100644 --- a/studies/ch4_numbers/LEDGER.md +++ b/studies/ch4_numbers/LEDGER.md @@ -494,14 +494,99 @@ R4: REAL-GAP relocates to the schema boundary, ERM is an ensemble-reliability finding, and neither is adverse to the catalog. +## §4.6 — the C-series, governed encoding at rate + +Artifacts, **all public in this repository** as of 2026-08-29: +`studies/c-series/packages/C-*.zip` (ten counted packages) · +`C_SERIES_PREREGISTRATION.md` · `C_SERIES_REPORT.md` · `notes/C_*_NOTE.md` · +`notes/C_5_VOID.md` · `SHA256SUMS`. + +Frozen set: pv1, prompt hash `35033e4b…`, application `716d92d9`, +`uofa==0.16.0`, source sha256 `1b767b2d…`, backend `hosted`. + +| Claim | Value | Measured at | Artifact | Commit | +|---|---|---|---|---| +| Denominator, declared blind before C-1 | **10** | 2026-08-29 | `C_SERIES_PREREGISTRATION.md` §1 | `648265e` | +| Counted runs reaching `signed-export` | **10 / 10** | " | `C_SERIES_REPORT.md` | `3be1c48` | +| Verification checks, fresh environment | **30 passed, 0 failed** (3 per package) | " | `packages/C-*.zip` + published wheel | `793470e4` | +| Condition pins reading `same` | **10 / 10** | " | `c_pins.py --run N`, exit 0, per note | `3be1c48` | +| Voids | **1** — C-5, tool-surface breach (`Write`) | " | `notes/C_5_VOID.md` | " | +| Void ground codified before the batch | yes — §1's exhaustive table | " | `C_SERIES_PREREGISTRATION.md` §1 | `648265e` | +| Packages declining to claim judgment | **9 / 10** | " | `notes/C_*_NOTE.md` | `3be1c48` | +| Packages judging any required level | **1** — C-4, 6 of 6 recoverable | " | " | " | +| Dispositions, not-recoverable / source-absent | 17/2 · 10/9 · 18/1 · 10/3 · 17/2 · 18/0 · 19/0 · 15/4 · 18/1 · 17/2 | " | " | " | +| Covers asserting a false signedness or judgment | **0 / 10** | " | " | " | +| Extraction cells returned, range | 34 – 58 against 19 expected factors | " | " | " | +| Messages per run, range | 783 – 1345 | " | " | " | + +**Both escalations CLOSED, 2026-08-29, venue: this repository, +`studies/c-series/`** (commit `793470e4`; a Zenodo deposit for the manuscript +DOI is minted from these same bytes). + +- *The primary artifacts were uncommitted.* The ten signed zips lived only in a + local run directory. They are now committed, with `SHA256SUMS` matching the + digests pinned when the rows were drafted — **verified from the committed + bytes** (`git archive HEAD`), not from the staging copies. +- *The reading was private.* `C_SERIES_REPORT.md` and the eleven notes were in a + private repository while `docs/Encoding_Protocol_v0_2.md:607-608` cited them + by path. Both now resolve for an outside reader. + +**The rung splits, and the split is the honest statement.** + +- **The rate is a recorded measurement, not re-derivable.** A C-run is a fresh + unsteered session against a live deployment, so a re-run is a **new + measurement** — precisely what E3 forbids substituting for a recorded one. + Same standing as the `nagaraja` figure and the Johnson raw-extract pair in + §4.2. It rests on the pre-registration, the transcripts and the void ledger. +- **The verification is stranger-re-derivable — D7 Demonstrated.** + `pip install uofa && uofa verify uofa.jsonld --pubkey keys/uofa-issuer.pub + --decision-pubkey keys/demo-reviewer.pub`, run against each committed zip from + its own shipped anchors, on a machine that has never seen this repository. + Re-run 2026-08-29 against the committed bytes under published `uofa 0.17.0`: + **30 passed, 0 failed.** + +Stating it as one blanket rung in either direction would be wrong in one +direction or the other. + +**What the signatures establish, in the packages' own words.** Each zip's +`SIGNING.txt` governs rather than any summary here: the shipped anchors let a +reader check *"that these keys signed these bytes, and that nothing has changed +since"*, and *"do NOT bind either key to a real-world party … Here both +identities are labeled demonstration fixtures."* So the signatures demonstrate +independent-attestation **mechanics** — two scopes, two keys, verified +separately — and bind to real parties only when custody does. Publication is an +offer of verification, not a claim of endorsement. + +**The `credenza.review` namespace is a minted identifier under A-2's rule, not a +live endpoint.** It does not resolve in a browser and is not meant to. A §4.6 +sentence says so, to pre-empt the reader who tries it. + +**Scope, carried from the pre-registration so no row is read wider than it was +measured.** The signatures attest completion of the governed review **with +dispositions recorded where evidence was unrecoverable**. Out of scope as +pre-registered: extraction soundness, the source paper's assessment quality, and +**human-reviewer executability**. This is a model-reviewer claim. + +**No gate.** The C-series was pre-registered with a denominator and **no pass +threshold**; the rate publishes wherever it lands. It enters §4.7's summary as a +reported value with no verdict-column entry — supplying one would be the +retroactive-threshold move the pre-registration exists to prevent. + +--- + ## Final ledger sweep — 2026-08-21 | Status | Rows | |---|---:| -| entered | **98** | +| entered | **110** | | PENDING-ENCODING | **0** | -| **ESCALATION** | **0** | -| total | **98** | +| **ESCALATION** | **0** (two raised and closed the same day — see §4.6) | +| total | **110** | + +**Updated 2026-08-29:** §4.6 adds twelve rows for the C-series. Its two +escalations — the packages uncommitted, the reading private — were entered with +their values per this ledger's rule and **closed by publication** to +`studies/c-series/`, not by waiver. The three rows that were PENDING-ENCODING — the two NASA substrates in §4.1's H1 table and the single H1 row in §4.6's gate summary — are entered. Their shared