Skip to content

delegation-and-review: coverage before clearance — an all-clear binds only what the review actually covered - #223

Merged
F-e-u-e-r merged 1 commit into
mainfrom
c13-coverage-before-clearance
Aug 28, 2026
Merged

delegation-and-review: coverage before clearance — an all-clear binds only what the review actually covered#223
F-e-u-e-r merged 1 commit into
mainfrom
c13-coverage-before-clearance

Conversation

@F-e-u-e-r

Copy link
Copy Markdown
Owner

Summary

One new delegation-and-review §3 rule — coverage before clearance — placed immediately after the packet-errors rule as its declared pair (claims before findings; coverage before clearances), plus its evidence package. One canonical file (+58, pure additions); 6 evidence files. Commit 81945a8 on main-tip 0e92d4a.

Spine: a clean verdict is never evidence about material the reviewer did not receive or otherwise verify.

Why (adjudicated PARTIAL-GAP)

A falsification-first orientation showed every existing rule passes this counterexample: an honest reviewer PROCEEDs over a silently-truncated packet (a pagination cap dropped one requested file's diff) and the orchestrator reads the verdict as full-requested-scope clean — a false clearance with zero rule violations. The dispatch-side scope declaration only declares; the completion-claim audit is dishonesty-bound, execution-deliverable-bound, and claim-side; the packet-errors rule fires only when crediting a finding; the settled-tree protocol guards motion, not assembly gaps.

The rule (owner-locked semantics)

  • Invariant: credited clearance scope ⊆ actually covered scope, reconciled over three distinct concepts — REQUIRED scope / AVAILABLE material / COVERED scope. No strict path-set equality; no machine-readable manifest; granularity follows the dispatch's own declaration.
  • Missing required material → UNREVIEWED, never clean; the reviewer's silence cannot clear it; sole carve-out = the orchestrator's own independent verified-unchanged ground truth.
  • Extra paths → authorized producer output, or a discovered dependency to escalate/re-scope, or outside the clearance — never auto-fraud, never silently absorbed.
  • A subset reviewer's PROCEED never inflates beyond its subset.
  • Direct-access carve-out: trusted frozen-tree/repo access satisfies availability — availability is not prompt-embedding (this keeps the rule from degrading into attachment-equality).
  • Truncation/pagination is a dispatch coverage defect, never reviewer fault.

Review

Design gate, dual-blind, mutually blind, isolated dirs, identity from tool banners: r1 = gpt-5.6-luna (max) PROCEED + gpt-5.6-sol (max) PROCEED — 2/2, zero findings, all ten mandatory axes answered line-anchored by both, and both explicitly confirmed correctness requires no new runtime path-set tooling.

Landing fidelity

The reviewed rule and Provenance blocks landed byte-verbatim (machine-proven: each block exactly once, full diff's line-multiset == exactly the two reviewed blocks, zero deletions). DECLARED-LANDING-ADAPTATIONS: NONE. Neighboring doctrine byte-unchanged (packet-errors, completion-claim audit, settled-tree protocol blob-identical, both recently-landed §3/§4 units untouched). Static controls 7/7 (EXTRA · MISSING-CLAIM · UNCHANGED · AUTHORIZED-DERIVED · DISCOVERED-DEPENDENCY · SUBSET · DIRECT-ACCESS). checks.py green (invisible-Unicode sweep included).

Probe debt

Behavioral transmission/effectiveness remains unprobed. The rule carries exactly one new unprobed marker; provenance class = counterexample-derived / design-reviewed; the future behavioral probe routes to the standing #115 queue.

The sibling queued candidate (evidence re-read-not-regenerate) remains LOCKED — zero of its content here.

🤖 Generated with Claude Code

https://claude.ai/code/session_0132RthrKSsMkywcEwtkXhkx

… a clearance

New delegation-and-review section-3 rule, placed immediately after the
packet-errors rule as its declared pair: claims before findings,
coverage before clearances. Spine: a clean verdict is never evidence
about material the reviewer did not receive or otherwise verify. Locked
invariant: credited clearance scope is a subset of actually covered
scope, reconciled over REQUIRED scope / AVAILABLE material / COVERED
scope — explanation-based, never path-set equality. Missing required
material stays UNREVIEWED (sole carve-out: independent
verified-unchanged ground truth); extras are authorized output,
escalated dependencies, or outside the clearance — never auto-fraud;
subset PROCEED never inflates; trusted frozen-tree access satisfies
availability; truncation is a dispatch coverage defect, not reviewer
fault; no machine-readable manifest. Adjudicated PARTIAL-GAP from a
false-clearance counterexample that passes every existing rule; design
review r1 dual-blind luna-max + sol-max = 2/2 PROCEED, zero findings;
landed byte-verbatim from the reviewed blocks (adaptations NONE); one
new unprobed marker, behavioral probe joins the #115 queue. Evidence:
reviews/2026-08-29-coverage-before-clearance/.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0132RthrKSsMkywcEwtkXhkx
@F-e-u-e-r
F-e-u-e-r merged commit d32420d into main Aug 28, 2026
3 checks passed
@F-e-u-e-r
F-e-u-e-r deleted the c13-coverage-before-clearance branch August 28, 2026 19:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant