Skip to content

receipt(campaign-1): ActionIntent adopts CNP-0-JCS - #28

Merged
s0fractal merged 3 commits into
mainfrom
receipt/campaign-1-action-intent
Aug 26, 2026
Merged

s0fractal merged 3 commits into
mainfrom
receipt/campaign-1-action-intent

Conversation

@s0fractal

Copy link
Copy Markdown
Owner

Campaign 1 receipt, signed with the registered claude key. Custody proved against the committed registry before signing; the key was never copied here.

Head: 078ac3afb577da0c3a79bed4a9d996d1347e5909

verify-chord   signed:true valid:true voice:claude
./t check      READY, 582 tests, 368 signed chords valid

Pinned separately

Trinity accepted 2db70569551a186b106765e03d00bed2bf2c05ef
Trinity merge 788304017b232534263a35d9c7b7a463e68df19f
MYC accepted e02d7f98637c1ea7fcc793c7023e3e015bbecf7e
MYC merge b1e94b03df9d0a34df693380b6bdeea9b970e2dc

Every one is restated in the body, where the signature reaches it — chord signatures cover the body and not the frontmatter, so a frontmatter edited after signing still verifies. A falsifier tells the reader to compare the two.

The adoption claim, bounded twice in the body

adoption-evidenced: true for one named authority path. Not either substrate generally: the proposal-body digest in the same file and every other stable() copy still use the old stringification.

interop-confirmed remains false, and the receipt states explicitly that the live parity test is not evidence of independent interoperability — it proves two vendored copies did not drift, which is a different and smaller thing. A3 is untouched.

The five executed attacks

Tabulated with what each produced before it was closed: duplicate verb last-wins, escape-equivalent duplicate, 0xff → U+FFFD, a getter answering validator and encoder differently, and a direct encoder call with requested_effects: [1].

All five were found by the reviewer. The receipt says so.

Corrections recorded rather than passed over

Four of my own claims that were load-bearing and wrong, including one you fixed after merge: Part 00 called adoption-evidenced both false and true in different places, and I left it that way.

Next: Campaign 2 — one frozen interface/evidence package for the typed-domain kernel B1–B5/B7/B8.

s0fractal and others added 2 commits August 27, 2026 01:07
Signed with the registered claude key; custody proved against the committed
registry before signing, key never copied here.

    trinity accepted  2db7056
    trinity merge     7883040
    myc accepted      e02d7f98637c1ea7fcc793c7023e3e015bbecf7e
    myc merge         b1e94b03df9d0a34df693380b6bdeea9b970e2dc

Every pinned value is restated in the BODY, where the signature reaches it —
chord signatures cover the body and not the frontmatter, so a frontmatter that
disagrees with the body was edited after signing while verify-chord still reports
valid:true. A falsifier says to compare them.

The adoption claim is scoped in the body, twice: one named authority path, not
either substrate generally, and the proposal-body digest plus every other
stable() copy still use the old stringification. `interop-confirmed` remains
false and the receipt says explicitly that the live parity test is NOT evidence
of independent interoperability — it proves two vendored copies did not drift,
which is a different and smaller thing.

The five executed attacks are tabulated with what each produced before it was
closed: two duplicate-member variants, invalid UTF-8, a changing getter, and a
direct encoder call. All five were found by the reviewer, none by me, and the
receipt says so.

Also recorded: four corrections to my own claims, including one the reviewer
fixed after merge — Part 00 called adoption-evidenced both false and true in
different places, and I left it that way.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DRHMVB9rUYNggn4wLmc1An
Separate commit from the signed chord, whose bytes must not move.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DRHMVB9rUYNggn4wLmc1An
@qodo-code-review

Copy link
Copy Markdown

PR Summary by Qodo

Record ActionIntent CNP-0-JCS adoption receipt

📝 Documentation 🕐 20-40 Minutes

Grey Divider

AI Description

• Records signed evidence that ActionIntent’s authority commitment adopts CNP-0-JCS.
• Pins accepted and merged Trinity/MYC commits, attack outcomes, and falsification commands.
• Regenerates ledger, evidence, network, and external-surface projections for the new receipt.
Diagram

graph TD
  R["Signed receipt"] --> D["Decision ledger"] --> E["Evidence report"]
  R --> X["Surface registry"] --> E
  R --> N["Network projection"]
Loading
High-Level Assessment

A signed, self-contained receipt with body-restated pins and explicit falsifiers is the appropriate strategy for preserving provenance while bounding the adoption claim. Regenerating all derived indexes in the same PR keeps repository projections consistent; no materially better architectural alternative is warranted for this documentation artifact.

Files changed (5) +216 / -14

Documentation (5) +216 / -14
x2B88_decisions.myc.mdIndex the Campaign 1 adoption receipt +32/-5

Index the Campaign 1 adoption receipt

• Adds the new signed receipt to the generated decision ledger. Increments total chord, signed chord, verified signature, receipt, and strong-evidence counts and records its falsifiers and verification commands.

src/x2B88_decisions.myc.md

x7700_964207_claude_campaign-1-action-intent-adoption.myc.mdAdd signed ActionIntent CNP-0-JCS adoption receipt +174/-0

Add signed ActionIntent CNP-0-JCS adoption receipt

• Adds the signed Campaign 1 receipt pinning Trinity and MYC accepted and merge commits, canonical commitment vectors, and verification commands. It narrowly scopes adoption to the ActionIntent authority path, preserves 'interop-confirmed: false', and records attack outcomes, safeguards, corrections, and falsifiers.

src/x7700_964207_claude_campaign-1-action-intent-adoption.myc.md

x7B88_evidence_report.myc.mdRefresh evidence metrics for the added receipt +3/-3

Refresh evidence metrics for the added receipt

• Updates generated external-surface, chord-ledger, and governance evidence totals to include the new receipt.

src/x7B88_evidence_report.myc.md

x8788_network.myc.mdRefresh network topology counts and manifest hash +4/-4

Refresh network topology counts and manifest hash

• Regenerates the network projection with a new source manifest hash. Increments Trinity’s node and chord totals and the overall chord composition count.

src/x8788_network.myc.md

x8F88_external_surfaces.myc.mdRegister the receipt as dynamic topology +3/-2

Register the receipt as dynamic topology

• Adds the receipt to the generated external-surfaces registry as a canonical retained topology artifact. Increments dynamic-topology and total surface counts.

src/x8F88_external_surfaces.myc.md

@qodo-code-review

qodo-code-review Bot commented Aug 26, 2026 •

Copy link
Copy Markdown

Code Review by Qodo

🐞 Bugs (0) 📘 Rule violations (0) 📜 Skill insights (0)

Grey Divider


Action required

1. Signed count falsifier is stale ✓ Resolved 🐞 Bug ≡ Correctness
Description
The signed falsifier says ./t check must report 367 valid signed chords, but this PR adds the
368th registry-verified signed chord and the generated ledger already reports 368. A correct post-PR
check therefore contradicts the receipt's own expected evidence, and fixing the signed body requires
recomputing and re-signing its payload.
Code

src/x7700_964207_claude_campaign-1-action-intent-adoption.myc.md[168]

+- `./t check` — READY, 582 unit tests, 367 signed chords valid.
Relevance

●●● Strong

Accepted precedent directly requires re-signing changed receipts and refreshing dependent generated
projections.

PR-#24

ⓘ Recommendations generated based on similar findings in past PRs

Evidence
The receipt states 367 in both its expected output and signed body, while the same PR's generated
decision summary records 368 signed and registry-verified chords; the generated falsifier projection
also propagates the stale 367 value.

src/x7700_964207_claude_campaign-1-action-intent-adoption.myc.md[38-48]
src/x7700_964207_claude_campaign-1-action-intent-adoption.myc.md[161-169]
src/x2B88_decisions.myc.md[10-20]
src/x2B88_decisions.myc.md[13503-13520]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

## Issue description
The receipt's signed `./t check` falsifier expects 367 valid signed chords, while this PR makes the correct total 368.

## Issue Context
Update both receipt occurrences to 368. Because the body is covered by `content_sig`, recompute the payload digest and signature after editing, then regenerate dependent projections so the extracted falsifier is refreshed.

## Fix Focus Areas
- src/x7700_964207_claude_campaign-1-action-intent-adoption.myc.md[41-48]
- src/x7700_964207_claude_campaign-1-action-intent-adoption.myc.md[168-168]
- src/x2B88_decisions.myc.md[13510-13510]

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools


Grey Divider

Context sources
Review mode: ⚖️ Balanced: The PR is documentation-heavy but records a security-sensitive signed receipt and updates authoritative ledgers/counters tied to adoption claims; it is not purely generated or formatting, yet the behavioral logic is not changed here and the diff is not dense enough to justify extended review.

Grey Divider

Tip of the day
💡 Did you know, you can start a comment with 'qodo' or '@qodo' to chat about any finding

More tips ↗ | Customize Qodo ↗ | Qodo docs ↗

Grey Divider

Qodo Logo

Comment thread src/x7700_964207_claude_campaign-1-action-intent-adoption.myc.md Outdated
@s0fractal

Copy link
Copy Markdown
Owner Author

One bounded receipt defect before merge: the signed body falsifier says ./t check — ... 367 signed chords valid, and frontmatter expected_after_running says the same, while this receipt itself makes the actual result 368 (as your report correctly states). The receipt therefore fails its own falsifier. Please replace both exact global-count claims with a stable predicate such as READY; all reported chord signatures valid, including this receipt, format, recompute payload, re-sign, regenerate projections, and push. No other change requested; this is not another semantic review round.

Its falsifier and `expected_after_running` both asserted `./t check — ... 367
signed chords valid`. This receipt is the 368th, so merging it made both claims
false. A falsifier over a number that moves when the artifact is added is not a
falsifier — it is a claim about the world before the claim existed.

Both replaced with a stable predicate: READY, and every reported chord signature
valid, INCLUDING this one. The body says what the earlier draft got wrong rather
than quietly swapping the number.

Same class as the hand-maintained control counts that drifted to 37/44/45 and the
`>= 41` floor: a number kept by hand describing something that moves. Here the
thing that moved it was the receipt itself.

Re-signed on the new bytes; custody was already proved this session and the key
was not copied. verify-chord: signed:true valid:true voice:claude. Projections
regenerated. `./t check` READY, 582 tests, 368 chords all valid.

No other change.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DRHMVB9rUYNggn4wLmc1An
@s0fractal

Copy link
Copy Markdown
Owner Author

Fixed. New head: 5b28082393cb3790586b73346e78264f47729683

Both exact-count claims replaced with the stable predicate: READY, and every reported chord signature valid, including this one. The body records what the earlier draft got wrong rather than quietly swapping the number.

verify-chord   signed:true valid:true voice:claude
./t check      READY — 582 tests, 368 chords, all valid
payload        sha256:5f919a0b8e5e8b62277274610bb9b5eaec97a72b5dd68fda2bb6612361d9d633

Re-signed on the new bytes, projections regenerated, no other change.

Worth naming what this was: the receipt asserted a global count that its own existence incremented. Same class as the control totals that drifted to 37/44/45 and the >= 41 floor — a number kept by hand describing something that moves. Here the thing that moved it was the artifact making the claim.

@s0fractal

Copy link
Copy Markdown
Owner Author

Accepted at exact head 5b28082393cb3790586b73346e78264f47729683. Delta from the prior head is limited to replacing the self-invalidating global count with the stable predicate, re-signing the changed body, and regenerating projections. Independent workspace-stripped verification reports signed:true valid:true voice:claude; all three GitHub checks are green. Merging.

@s0fractal
s0fractal merged commit 52b98e2 into main Aug 26, 2026
3 checks passed
@s0fractal
s0fractal deleted the receipt/campaign-1-action-intent branch August 31, 2026 09:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant