v3.1.7 — the Second Key
v3.1.7 — The Second Key
The LAW — the plan every slice is built against — was the last stage that sealed on a single
model family's word. It no longer does.
What changed
- Always-on cross-family ratification of the LAW. Before the LAW/architecture locks, an
opposite model family must ratify it — reusing the existing review loop and review schema, no new
schema family. Findings return to the producer for up to two repairs with same-reviewer recheck. - Honest HELD when the second key cannot be turned. If the reviewer bridge is unavailable, the
plan is blocked, or ratification will not converge, the run holds for the operator — the LAW never
locks single-family. - The kernel is the sole sealer. A new opaque
seal-lawverb computes and persists the LAW
digest after ratification; the LAW card no longer seals it. The displayed, ratified, and sealed
digests are provably the same sha256 of the same bytes.
Under the hood
- New
ratifyverb andratify-reviewerrole (gpt, opposite-family to the fable LAW producer),
boot-required and mirrored into the doctor preflight. - The kernel stays content-blind; the build path is byte-identical to v3.1.6.
Verification
- Harness floor green:
tests/v331/31, plugin suite 129/129. - Every slice cross-family reviewed (repair-to-approval); a whole-wave milestone QA passed.
- Live dogfood against real GPT: the ratify gate graded a candidate LAW, returned a schema-valid
verdict, and the sealed digest matched the ratified bytes exactly; a bridge-down run surfaced an
honest hold.
Wave 1 of the lifecycle realignment. Ships as a patch bump; the status light stays yellow.