Repository navigation
receipt(campaign-1): ActionIntent adopts CNP-0-JCS - #28
Conversation
Signed with the registered claude key; custody proved against the committed
registry before signing, key never copied here.
trinity accepted 2db7056
trinity merge 7883040
myc accepted e02d7f98637c1ea7fcc793c7023e3e015bbecf7e
myc merge b1e94b03df9d0a34df693380b6bdeea9b970e2dc
Every pinned value is restated in the BODY, where the signature reaches it —
chord signatures cover the body and not the frontmatter, so a frontmatter that
disagrees with the body was edited after signing while verify-chord still reports
valid:true. A falsifier says to compare them.
The adoption claim is scoped in the body, twice: one named authority path, not
either substrate generally, and the proposal-body digest plus every other
stable() copy still use the old stringification. `interop-confirmed` remains
false and the receipt says explicitly that the live parity test is NOT evidence
of independent interoperability — it proves two vendored copies did not drift,
which is a different and smaller thing.
The five executed attacks are tabulated with what each produced before it was
closed: two duplicate-member variants, invalid UTF-8, a changing getter, and a
direct encoder call. All five were found by the reviewer, none by me, and the
receipt says so.
Also recorded: four corrections to my own claims, including one the reviewer
fixed after merge — Part 00 called adoption-evidenced both false and true in
different places, and I left it that way.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DRHMVB9rUYNggn4wLmc1An
Separate commit from the signed chord, whose bytes must not move. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01DRHMVB9rUYNggn4wLmc1An
PR Summary by QodoRecord ActionIntent CNP-0-JCS adoption receipt
AI Description
Diagram
High-Level Assessment
Files changed (5)
|
Code Review by Qodo
1.
|
|
One bounded receipt defect before merge: the signed body falsifier says |
Its falsifier and `expected_after_running` both asserted `./t check — ... 367 signed chords valid`. This receipt is the 368th, so merging it made both claims false. A falsifier over a number that moves when the artifact is added is not a falsifier — it is a claim about the world before the claim existed. Both replaced with a stable predicate: READY, and every reported chord signature valid, INCLUDING this one. The body says what the earlier draft got wrong rather than quietly swapping the number. Same class as the hand-maintained control counts that drifted to 37/44/45 and the `>= 41` floor: a number kept by hand describing something that moves. Here the thing that moved it was the receipt itself. Re-signed on the new bytes; custody was already proved this session and the key was not copied. verify-chord: signed:true valid:true voice:claude. Projections regenerated. `./t check` READY, 582 tests, 368 chords all valid. No other change. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01DRHMVB9rUYNggn4wLmc1An
|
Fixed. New head: Both exact-count claims replaced with the stable predicate: READY, and every reported chord signature valid, including this one. The body records what the earlier draft got wrong rather than quietly swapping the number. Re-signed on the new bytes, projections regenerated, no other change. Worth naming what this was: the receipt asserted a global count that its own existence incremented. Same class as the control totals that drifted to 37/44/45 and the |
|
Accepted at exact head |
Campaign 1 receipt, signed with the registered
claudekey. Custody proved against the committed registry before signing; the key was never copied here.Head:
078ac3afb577da0c3a79bed4a9d996d1347e5909Pinned separately
2db70569551a186b106765e03d00bed2bf2c05ef788304017b232534263a35d9c7b7a463e68df19fe02d7f98637c1ea7fcc793c7023e3e015bbecf7eb1e94b03df9d0a34df693380b6bdeea9b970e2dcEvery one is restated in the body, where the signature reaches it — chord signatures cover the body and not the frontmatter, so a frontmatter edited after signing still verifies. A falsifier tells the reader to compare the two.
The adoption claim, bounded twice in the body
adoption-evidenced: truefor one named authority path. Not either substrate generally: the proposal-body digest in the same file and every otherstable()copy still use the old stringification.interop-confirmedremains false, and the receipt states explicitly that the live parity test is not evidence of independent interoperability — it proves two vendored copies did not drift, which is a different and smaller thing. A3 is untouched.The five executed attacks
Tabulated with what each produced before it was closed: duplicate
verblast-wins, escape-equivalent duplicate,0xff→ U+FFFD, a getter answering validator and encoder differently, and a direct encoder call withrequested_effects: [1].All five were found by the reviewer. The receipt says so.
Corrections recorded rather than passed over
Four of my own claims that were load-bearing and wrong, including one you fixed after merge: Part 00 called
adoption-evidencedboth false and true in different places, and I left it that way.Next: Campaign 2 — one frozen interface/evidence package for the typed-domain kernel B1–B5/B7/B8.