Skip to content

backlog: rule G26 sittings 1 and 2 (33 rows), file #1211 - #312

Merged
wshallwshall merged 1 commit into
mainfrom
w3-ledger-g26
Aug 10, 2026
Merged

backlog: rule G26 sittings 1 and 2 (33 rows), file #1211#312
wshallwshall merged 1 commit into
mainfrom
w3-ledger-g26

Conversation

@wshallwshall

Copy link
Copy Markdown
Collaborator

Rules G26 sittings 1 and 2 over the DEMAND-GATE surface. Ledger only -- no engine, IDE or webconsole
code is touched.

BACKLOG #1211

What it does

33 rows resolved: 18 dropped, 12 deferrals confirmed with a dated review, 3 promoted out of
demand-gate. Roughly two thirds of the demand-gate surface, with no engineering.

BACKLOG #1211 is filed by this commit: empty_claims_monotonic excursions exceed the band its ratio
form claims to be immune to. Its scope says to establish the true variance from several samples at one
N, then either widen the band to the measured distribution -- recording the pool and date as data -- or
replace the monotonicity expectation with one the metric can support. Explicitly not a flaky marker,
which would re-hide the class. It also records what the excursion is NOT, preserving the
fd_count_monotonic discriminator so the next reader does not re-derive a causal story that was
already refuted.

Verification

  • Ledger re-derived with parse_items from this branch rather than carried forward: live 242, open
    192, closed-in-live 50, archive 236 -- namespace 478 conserved. No duplicate numbers, and no item
    declaring more than one status.
  • Merges cleanly onto main; the instrument was checked first -- merge-tree --write-tree against a
    known-conflicting branch returns exit 1, so exit 0 here means clean rather than blind.
  • #1040, #1210 and #64 confirmed still open; none was tidied.
  • Leak scan run with the detector set loaded and confirmed non-empty, so the pass is evidence rather
    than a vacuous green on an empty ruleset.

Note

Four rows are routed to the owner for a ruling rather than decided here -- two policy questions about
the cipher-floor posture, one promotion argued on path-traversal grounds rather than demand, and one
whose stated gate is an internal item number that does not exist in the public namespace.

Sittings 1 and 2 of the standing demand-gate triage, ruled under the owner's
delegation. 33 rows resolved: 18 DROP, 12 deferral confirmed with a dated review,
3 promoted out of demand-gate. Open items 209 -> 191, then 192 with #1211 filed.

WHY DROPPING IS THE HONEST OUTCOME, not neglect. Every drop was verified to have a
working alternative in shipped code, or a trigger that cannot arise as the engine
is built. Re-filing a dropped row costs one item; carrying it costs a re-read and
a re-price at every planning pass. Recording a row as "not yet triggered" year
after year, with no evidence the question was ever re-asked, IS the failure mode.

The line applied, so it can be re-applied to the remaining sittings: KEEP the rows
whose trigger, if it fires, BLOCKS a feed; DROP the rows whose trigger merely
INCONVENIENCES, because a shipped mechanism, a configuration change or the network
layer already answers it.

THREE DROPS ARE STALE RATHER THAN PENDING, and they are the ones worth noticing --
in a status scan a demand-gate row whose trigger has ALREADY BEEN SERVED looks
identical to one still waiting:
  #127 proxy auth    -- fired and answered; #112/#128 shipped under ADR 0126 and
                        the NTLM residual is refused at construction with the
                        cntlm workaround named. Duplicates an ADR decision.
  #125 uploaded logs -- fired and served across five API routes and seven /ui
                        routes, none of which ingests into the live store.
  #130 shared queues -- cannot fire: it describes a competitor's internal queue
                        model, not a capability a feed here lacks.

PROMOTED, each because its API half already ships and only the console half is
absent: #177 (no PHI), #132 (trigger fired against this repo's own sample), and
#124 -- a PHI EGRESS PATH, which must ship behind the same step-up and scope
controls as its API half or it is a downgrade.

FOUR ROWS ROUTED TO THE OWNER rather than ruled: #141 and #178 are policy
questions about the cipher floor and out-of-engine relays; #158 is a promotion
argued on security-sequencing rather than demand; #105 is gated on #313, which
does not exist in the public namespace and is resolvable only internally.

ALSO FILES #1211, allocated with scripts/coord/alloc.ps1 -- empty_claims_per_msg's
contention-immunity claim measured false on a hosted runner. The confirming re-run
was predicted BEFORE it ran, so its green is a result and not a rationalisation.
Its mechanism section records what the excursion is NOT, because the near miss was
recalibrating an SLO on a causal story the same test run already refuted.

THE LEAK GATE BLOCKED THE FIRST ATTEMPT AT THIS COMMIT AND IT WAS RIGHT. #169's
rationale named the vendor adjacent to the estate: the vendor name alone is
ordinary competitor prose and appears throughout this file, but paired with the
estate word it implies a specific customer's installation. Isolated by probing the
scanner phrase by phrase rather than by reading the token out of a log, and fixed
by removing the adjacency -- not by an allowlist entry, which the gate's own
remediation text explicitly refuses for a real token.

Ledger, re-derived with parse_items: live 242, open 192, closed-in-live 50,
archive 236, namespace 478 conserved. All three ledger gates pass.
@wshallwshall
wshallwshall merged commit 751ca08 into main Aug 10, 2026
34 checks passed
@wshallwshall
wshallwshall deleted the w3-ledger-g26 branch August 10, 2026 23:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant