Skip to content

Epic 17 + Epic 18 charters, the stage-mismatch measurement, and the audit that corrected itself - #5

Merged
Inan15 merged 37 commits into
masterfrom
epic-16/discharge-df-15-2-d
Aug 24, 2026
Merged

Epic 17 + Epic 18 charters, the stage-mismatch measurement, and the audit that corrected itself#5
Inan15 merged 37 commits into
masterfrom
epic-16/discharge-df-15-2-d

Conversation

@varinderpratap

Copy link
Copy Markdown
Collaborator

35 commits from 2026-08-24. Every one is documentation, planning or research —
argus/** is byte-unchanged and no shipped behaviour moves.

What this delivers

Two operator decisions that were overdue. DF-13-5-A's re-review trigger fired when 16.6 and
16.7 reached done; it is DECLINED a second time, with its calendar-shaped trigger replaced by
a substantive one. The entry stays OPEN and UNSPENTmembers_ratified NONE, protocol_edit
NONE. Approving this PR is not approval to spend that round.

A measurement that answered the Epic 17 charter question. vacuous_test flags on assertion
density (1,025 of 1,032 — 100%) and corroborates on mock provenance (0 of 1,032). Two stages
graded on different definitions of vacuity, disjoint on the ratified corpus. The detector's
verdict-eligible output is zero, and the widely-quoted "corroborable ceiling of six" is W1
fact (b) with its mock clause deleted. Reproducible: five harnesses under research/.

Epic 17 (assertion-strength grading, 5 stories) and Epic 18 (detector-audit discharge, 4
stories), both APPROVED, both at backlog. Epic 18 is sequenced firstDF-AUD-DETECT-A is a
live secret-detection false negative, re-verified here by execution.

What it does not do

The ≥80% precision gate is unchanged and still NOT CLEARED. No FR is amended, no member
ratified, no third-party source fetched, no protocol re-versioned. Epics 1–16 are not reopened and
Story 6.2's closed record is not edited.

Two entries that correct this session's own work

DF-INV-WHEEL-A asserted a cause it had not isolated — withdrawn after all five harnesses were run
individually and none reproduced the write. DF-INV-DELIVERY-A had three claims withdrawn after
git patch-id refuted its most serious one. Both errors ran toward a more severe finding than the
evidence carried, and the withdrawals are in the record as prominently as the claims.

Why CI matters here

These commits have never executed on Linuxaudit-ci.yml runs only on push to master/main or
a PR targeting them, so a feature-branch push triggers nothing. The local suite is Windows-only,
1,716 passed at every commit
. This PR is the first POSIX exercise of the work.

Merge

origin/master is merged in as ancestry only: git diff HEAD after resolution was empty.
Both conflicts were resolved by taking ours, after verifying containment in both directions —
zero master lines of deferred-work.md and zero master comment fragments in sprint-status.yaml
are absent from this branch.

🤖 Generated with Claude Code

XAgentsLabs007 and others added 30 commits August 22, 2026 22:53
DF-15-2-D demanded that the next change of any size to
argus/detectors/vacuous_test.py perform the cohesion split FIRST. Commit
4123931 did exactly that, alone and before any behaviour change. Nothing
recorded it. An entry that reads OPEN while its condition is gone is the
same failure the entry itself was filed for: a disposition in prose and
not in the ledger is not a disposition (AI-E12-3 / AI-E12-6).

DF-15-2-D CLOSED by append-only dated note; the entry above is not
rewritten (section 3.4). Verified by execution rather than by report, on
the DF-8-2-A standard:

  vacuous_test.py        1,196 -> 796  (headroom 4 -> 404)
  vacuous_vocabulary.py    new -> 455  (headroom 745)

  ast span comparison across 4123931^: 31 top-level nodes = 25 stayed +
  6 moved; all six byte-identical by sha256; zero vanished, zero new,
  zero changed-in-place. Re-export checked by is-identity, not equality:
  all six resolve to the SAME OBJECT through either module, so no call
  site moved. __all__ unchanged at 9. DN-14-2-1 intact at 23 names. No
  _EXEMPT_BY_DESIGN entry added (MAINT-001-04). 4123931 touched only the
  two production modules - no guard, no registry, no test.

WHAT THIS CLOSURE DOES NOT DO, stated so it is not over-read. 16-6 STAYS
backlog: the split was a precondition on whoever opened the module next,
not the story's behaviour change, which is unstarted. DF-15-2-E STAYS
OPEN and its trigger has NOT fired - tests/test_vacuous_density.py
re-measures 1,159/1,200, 41 headroom, unmoved by this split, against a
trigger at 1,180. Nothing ratified, promoted, or moved.

sprint-status.yaml records the discharge under 16-6 so story creation
cannot re-plan work already on master, and names the consequence that
matters: THE TARGET FILE HAS MOVED. The vocabulary now lives in
argus/detectors/vacuous_vocabulary.py, and a story contexted against
vacuous_test.py would write ACs naming a file that no longer holds the
code.

Also deletes the spent DRAFT-decline-record-2026-08-22.md - untracked,
so it appears in no diff. All four of its edits were confirmed live
first (deferred-work DF-13-5-A append, the recommended no-protocol-edit,
story 16-4's four edits, the sprint-status entry); its own checklist
required deletion once applied.

Docs only. argus/ and tests/ byte-unchanged, so no currency guard
re-arms. 180 guards that read the ledger: all green.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Story 16.5 ready-for-dev -> in-progress, and the two governance-record
defects Task 0 found by execution, repaired first so the arc starts clean.

SS0 re-derived EXACT, nothing amended: 31 live rows, 26 FP / 5 BORDERLINE /
0 TP / 0 UNADJUDICATED, exactly ONE distinct adjudicator, protocol V1.3 with
expert_hours null, BLOCKED, breadth/seal/yield false/false/true, zero
`adjudicators` assertions anywhere in tests/ or scripts/, both builders
--check exit 0, and all 21 SS0.5 line counts exact against the ceiling
guard's own _physical_line_count.

SS0's next false premise, found on the first command: the baseline suite was
RED. TC-ArgusAgent-DOCS-001-78 reported five unbacked ledger-closure claims
across the story file and its round-1 validation report. Both are record
defects and neither is a reason to touch the guard.

1. DF-15-2-D really was CLOSED on 2026-08-22, with its date and its evidence
   — but the disposition was written as a `- **CLOSED ...**` bullet carrying
   no id, which `ledger_closed_ids` cannot see: it recognises the id ON the
   closure line, or a trailing `- status:` field. The closure was real and
   machine-INVISIBLE, so a TRUE story claim read as unbacked. Repaired by the
   remedy the guard's own message prescribes — a PURE APPEND of the
   machine-readable field. Not one byte of the entry above it is edited and
   NOTHING NEW is disposed of: DF-15-2-E, DF-16-1-A, DF-16-3-A and DF-13-5-A
   are all still OPEN, and DF-13-5-A's one round is still UNSPENT.

2. The round-1 validation report listed four OPEN ids and one CLOSED id on
   one physical line, and `story_closure_claims` is line-scoped BY DESIGN —
   its docstring says widening the window "swept unrelated ids into the
   claim". The row is split in two; every word, cite and verdict is preserved
   verbatim and no finding changes.

No `argus/`, `tests/` or `scripts/` file is touched by this commit.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…dent

`GateDecision.adjudicators` has been published since 13.3 and guarded by
NOTHING: zero assertions anywhere in tests/ or scripts/ closed over it, and
no surface rendered it beside the precision figure. A reader who wanted to
know whether the precision figure was judged by the people who wrote the tool
had to open a JSON artifact and reconstruct it from protocol SS2. This makes
the answer DERIVED, PUBLISHED and GUARDED, and puts it on the same sentence as
the figure so the two cannot be quoted apart.

Derived answer over the live committed record: NOT_INDEPENDENT - 31 of 31
live human judgements authored by XAgent007 (Engineering Lead). That is the
correct output, not a failure.

NEW argus/precision/gate_independence.py (328 lines): the closed four-member
vocabulary with its raising lookup (DF-10-4-E), the frozen assessment with
to_payload(), the pure derivation, and every sentence this story publishes.
PURE (AR8) - no I/O, no clock, no module-level path. The three role names are
DESTRUCTURED out of PROTOCOL_ADJUDICATOR_ROLES, so a fourth role fails at
import rather than drifting; ids are parsed by the EXISTING adjudicator_role.
NOT_ESTABLISHED and NOT_INDEPENDENT do not collapse: *nothing was judged* and
*the author judged everything* are different findings.

One optional keyword on precision_gate_status_for, rendered in ALL THREE
branches - a note wired into the unevaluable branch alone would be correct
today and silently wrong on the day the gate clears.

The four SS2.3 forwarders (adjudication, gate_breadth, gate_seal, gate_yield)
each change by EXACTLY the AC7.1a budget and nothing else: one optional
keyword, one forward to the one existing precision_gate_status_for call, one
docstring line. Zero deletions, no second parameter, no new import edge, and
none of them imports gate_independence - they forward an opaque string.
NFR-P1 PROVEN BY RENDERING, not by reading the diff: 26 surfaces rendered
against the pre-story tree at 52143eb and against this one with the keyword
omitted, sha256 27dde086258766f5 both times, BYTE-IDENTICAL.

gate_decision.py: one field defaulted last, one payload key, the note threaded
through all four renderer branches, and the live/adjudicators derivation
RE-ORDERED above the fold call at :811 so the note can be passed into it.
Nothing is recounted - assess_independence READS the tuple decide_gate
already computes.

THIS GATES NOTHING. SECTION_5_CONDITIONS stays at SEVEN, byte-unchanged;
precision_evaluable keeps exactly FOUR conjuncts; _precision_condition gains
no branch; no role is filled, no disposition written, no member ratified, no
detector run; adjudication-record.json is byte-unchanged; DF-13-5-A stays
OPEN and UNSPENT.

DN-16-1-1's HOLDING stands and gate_breadth.py's shipped docstring is left
byte-as-shipped (sha256 20d3b1f18a74c555 before and after) - correcting it was
considered and DECLINED; DN-16-5-7 records the correction in the story only.

NEW tests/test_gate_independence.py, TC-ArgusAgent-PRECISION-001-105..-112,
plus -113 in test_gate_decision_artifact.py. Populations are GENERATED with
the member spread, size, locators and dispositions PINNED so the adjudicator
field is the only term that can move - asserted mechanically row by row
(SS2.8's lockstep trap, which caught 16.1, 16.2 and 16.3 in turn). TEN
mutations executed at the REAL seam under PYTHONDONTWRITEBYTECODE=1 with a
cleared __pycache__, ALL TEN RED, tree restored byte-exact after each:
the empty-arm collapse, the silent-default lookup, the cleared branch dropping
the note, the unevaluable branch withholding the figure, a SECOND function
emitting the precision= surface, a dropped seal forward (RED on -108 and on
nothing else), a FIFTH precision_evaluable conjunct, an EIGHTH SS5 condition,
a dropped payload key, a DN-16-5-6-violating dogfood note, and a hand-edited
artifact status.

test_release_preflight.py's test-tree-reach registry gains the new module -
DELIBERATE, which is what that registry exists to force someone to say. It
joins TRANSITIVELY by its single import of adjudication and resolves no path
at module level.

NFR-M1: gate_decision.py 1084 -> 1132, inside the 1100-1150 band, so a ledger
entry is owed and NOT a split; the four forwarders land at 977 / 780 / 563 /
439 against the 1200 ceiling, exactly as SS0.5 projected. No _EXEMPT_BY_DESIGN
entry added.

Evidence-partition: none

No corpus evidence of any kind informed this change, from either partition.
This story runs NO detector, reads NO finding and adjudicates NOTHING; it
touches a declared detector-tuning path (argus/precision/replay_harness.py)
only to add one optional rendering keyword whose default is proven
byte-identical, and it changes no detector, no threshold, no scorer and no
predicate. The trailer is written because the rule says write it - the
comparison across partitions is only possible if every change says which side
it learned from, and "nothing" is an answer that has to be stated too.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
SS2.5's order, unchanged from the one 16.2 and 16.3 both used: argus/ committed
first, regenerate, artifacts committed separately. The generator refuses on a
dirty argus/ tree by design, which is what makes the order enforceable rather
than remembered.

Every delta is the new module being counted, and nothing else: 93 -> 94 source
files, 32140 -> 32555 LOC, 73/93 -> 74/94 deep coverage, 162 -> 164 findings,
465 -> 470 credits, critical set 66 -> 67. Regenerating executes NO detector
over a bench member.

DN-16-5-6 holds, and it is checked rather than asserted: the string
"adjudication independence" appears ZERO times in the regenerated diff. The
dogfood generator passes precision=None and reads no adjudication record at
all, so a sentence about independence there would describe a judgement that
never happened. derive_gate_status's rendered output is byte-identical.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
`--check` went exit 1 (STALE) the moment the payload grew a key, exactly as
SS2.5 says it would, so the artifact is REGENERATED by its builder and
committed separately from the argus/ change. `--check` is exit 0 afterwards,
and `build_adjudication_record.py --check` is exit 0 and untouched - this
story writes no disposition and regenerates no adjudication record.

What the artifact now says, derived and not typed:

  independence.status            NOT_INDEPENDENT
  independence.adjudicators      ["XAgent007 (Engineering Lead)"]
  independence.roles_present     ["Engineering Lead"]
  independence.roles_absent      ["QA Lead", "External adjudicator"]
  independence.gates_anything    false

and the clause now travels ON the gate_status sentence itself, after the
precision figure, so the two cannot be separated by copy-and-paste. That was
the whole point.

Unmoved, and checked: outcome still BLOCKED, precision.evaluable still false,
seven SS5 conditions, adjudication-record.json byte-unchanged.
TC-ArgusAgent-PRECISION-001-61 (NFR-S1) re-run GREEN against the regenerated
artifact - no backslash, no host path, no source byte, even though the
sentence now names a human.

-113's guard-adequacy (ii) discharged against this artifact: hand-editing
independence.status to EXTERNAL_ADJUDICATOR_PARTICIPATED - the flattering
drift the guard exists to catch - turns it RED. Artifact restored byte-exact
and --check re-confirmed exit 0.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…disclosure

Four records, each amended by the rule that governs it and none by rewriting.

precision-validation-protocol.md SS2 - a FIFTH dated block under the existing
V1.3, and NO V1.4 row. 57 insertions, ZERO deletions: not one existing byte of
SS2, SS3, SS4 or SS5 is edited (SS3.4, strike-never-erase). A V1.4 row would
re-stamp protocol_version across the 31 human judgements of 2026-08-17 and
re-interpret judgements nobody re-made; the change-log head is unmoved and
TC-ArgusAgent-PRECISION-001-45 / -63 stay green. The block answers, in terms,
the question the FOURTH dated block handed on when it filled the QA Lead
role: *"whether any given adjudication was independent is Story 16.5's
question to record, not this block's to assert."*

architecture.md SS Enforcement - a dated addition under *Gate-decision
enforcement*, appended to that registration with 6,053 bytes added and ZERO
removed; the original text is a verbatim prefix of the new. It records the
module, the closed vocabulary, the derivation source, and - stated first
because three amendments in a row did the opposite - that this one appends NO
SS5 condition. TC-ArgusAgent-DOCS-001-77 green.

deferred-work.md - a PURE APPEND, 46 insertions and ZERO deletions
(TC-ArgusAgent-DOCS-001-78). NEW DF-16-5-A: argus/precision/gate_decision.py
ends this story at 1,132 of 1,200, inside the 1,100-1,150 band the story's own
SS0.5 said must be FILED rather than discovered. The projection was taken at
Task 1 BEFORE any code was written, against a threshold set before that, so
this entry is a rule firing as designed rather than a surprise found
afterwards - which is exactly what the four unfiled triggers handed to the
four stories before this one were not. Remedy is a cohesion split, never a
shave and never an exemption; MAINT-001-04 binds and no _EXEMPT_BY_DESIGN
entry was added. The boundary is deliberately NOT proposed here.

README.md / CHANGELOG.md - updated because a rendered surface ACTUALLY moved,
and said either way rather than left implicit. TC-ArgusAgent-DOCS-001-54
measures the published module figures against a freshly built wheel, and the
new module moved four of them: importable and shipped modules 93 -> 94, wheel
entries 101 -> 102, sdist members 100 -> 101. Every figure is DERIVED from the
artifact by that guard - *the artifact is the fact* - and both documents keep
their full amendment history rather than being overwritten. No FR34 surface
moved: negative_assurance.py is byte-unchanged, InstrumentStatus is still a
closed two-member vocabulary, and both disclosure texts and short forms are
untouched.

Nothing here ratifies, adjudicates, fills a role or moves a threshold.
DF-13-5-A stays OPEN and UNSPENT; DF-15-2-E, DF-16-1-A and DF-16-3-A stay
OPEN; no historical entry on any ledger is edited.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Story 16.5 in-progress -> review; sprint-status likewise, with the STATUS
DEFINITIONS block and every existing comment preserved and the YAML re-parsed
to prove it. All 43 task checkboxes ticked, none of them optimistically: every
one is backed by something executed and recorded below it.

The Dev Agent Record carries the numbers rather than the adjectives - the ten
mutations and which guard each turned red, the 26-surface byte-identity sha,
the AC7.1a per-module diff counts, the 1,084 -> 1,132 projection and why it
was a FILING and not a split, and the five SS0 rows re-derived exact against
the one that was false.

⛔ The two judgement calls are flagged IN the record for the reviewer to
attack first, rather than buried: the two governance-record repairs in
`9aea1be`, which AC7.2 did not anticipate and which a RED baseline forced;
and the `Evidence-partition: none` trailer, which is a claim about the change
that only a reader of the diff can falsify.

Gates at hand-off, each run and each number recorded:
  full suite (ARGUS_REQUIRE_LANGUAGE_GRAMMARS=1)   1686 passed, exit 0
  mypy argus                                       94 files, no issues
  bandit -r argus --severity-level medium          0 medium, 0 high
  scripts/build_gate_decision.py --check           exit 0
  scripts/build_adjudication_record.py --check     exit 0
  tests/test_module_size_ceiling.py                green, _EXEMPT_BY_DESIGN
                                                   still 3 - none added

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Review finding 1 (Patch, High), AC6.4. Commit `9aea1be` repaired DF-15-2-D's
machine-invisible closure and stated, in terms, that "not one byte of the entry
above it is edited". Its diffstat was 24 insertions(+), 1 deletion(-), and the
deletion falsifies the claim: a literal CR byte was dropped from a pre-existing,
pre-16.5 entry at deferred-work.md:5257.

The byte is not incidental. The entry discusses line endings, and the prose reads
"the reason `<CR>` / `<LF>` are not part of the problem" - two inline code spans
whose CONTENT is the two bytes being contrasted. Dropping the CR split one line
into two and made the sentence contrast a newline with itself, destroying the
distinction the entry exists to draw. 16.1's review caught this same class and the
remedy there was restoration; it is restoration here.

ROOT CAUSE, recorded because it is a trap and not a slip. core.autocrlf=true with
no .gitattributes, and a LONE CR makes git classify a file as binary
(convert_is_binary returns 1 on lonecr), which silently switches CRLF
normalisation OFF. So the blob carried LF terminators plus one lone CR and the
worktree copy was byte-identical; an editor then rewrote the file as CRLF, which
both normalised every terminator and consumed the lone CR; on commit git saw no
lone CR, decided the file was text after all, normalised CRLF->LF, and booked
exactly one net deletion. The first attempt at this fix hit the same trap in
reverse - restoring the CR into a CRLF worktree flipped git back to binary mode
and would have staged 5,643 CRLF terminators into the blob - so the file is
rebuilt FROM THE BLOB, with LF terminators plus the single lone CR, and
`worktree bytes == staged blob bytes` is asserted.

Also restores the trailing newline dropped by `927548d`. That is not a
historical-byte edit (the prior content remained a strict prefix) but it is a
POSIX text-file violation on a repo whose CI runs an ubuntu matrix, and it is
recorded here rather than absorbed silently.

THE AUDIT WENT PAST THE ONE BYTE THE REVIEW FOUND. A byte-level difflib
alignment of every blob in the arc - 52143eb -> 9aea1be -> c5ca6a7 -> cd4cbe4 ->
ca0dee2 -> 927548d -> 028c3c8 - plus a whole-file comparison against the
pre-story baseline. Result: EXACTLY ONE change in the entire arc modified a
pre-existing line, and it is this CR. Every other change is a pure line INSERT
(22 lines, the DF-15-2-D status: field; 45 lines, DF-16-5-A), and four of the six
commits did not touch the file at all. Proven two ways: the alignment reports
HISTORICAL LINES DELETED OR REPLACED: 0, and the 424,300-byte baseline
reconstructs byte-exactly from the unchanged lines. CR count is back to 1.

TC-ArgusAgent-DOCS-001-78 and ledger_closed_ids are UNAMENDED and UNWEAKENED.
The guard was correct; the record was wrong.

Evidence-partition: none. No argus/ or scripts/ delta, nothing ratified, no
detector run, no disposition written, no role filled, no V1.4 row,
adjudication-record.json byte-unchanged, DF-13-5-A OPEN and UNSPENT.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Review finding 2 (Patch, Medium), AC1.3 / AC5.4. AC1.3 claims the independence
status is derived from the LIVE rows of the committed record. The review
mutation-tested that claim and found it unguarded: replacing
`live = record.live_rows()` with `live = record.rows` in decide_gate produced
ZERO failures across test_gate_independence.py, test_gate_decision.py,
test_adjudication_record.py and test_gate_decision_artifact.py, because no
generated population anywhere carried a superseded row.

Nothing is mis-derived today - the committed record carries 0 superseded rows -
so this is a regression path rather than a live defect. But a disclosure a reader
is asked to trust, whose central claim no guard closes over, is exactly the
AI-E11-1 shape this module was written to stop, and exactly what AC5.4 means by
"an adversarial variant GENERATED from the record the guard closes over".

NEW TC-ArgusAgent-PRECISION-001-114, with a _superseded_population builder that
extends _population rather than forking it, so every pinned term - member spread,
size, locators, rule ids, dispositions - is inherited and §2.8's lockstep
discipline still holds. It strikes one row through a real `supersedes`
correction: the struck row and its replacement share a finding_id by
construction, so only row_id, adjudicator, reason and supersedes move.

GENERATED adversarial variants: 2 - one per registered role that is not the
Engineering Lead, each forging a DIFFERENT status (SECOND_REVIEWER_INTERNAL,
EXTERNAL_ADJUDICATOR_PARTICIPATED). That is precisely the "quietly upgrading a
NOT_INDEPENDENT record because a struck row happened to be authored by a
different role" leak the review named.

PROVEN NON-VACUOUS BY THE REVIEW'S OWN MUTATION, at the real seam:
gate_decision.py:856 live_rows() -> rows drives BOTH -114 cases RED on the leaked
adjudicator set, while every other guard in the four targeted files stays GREEN -
so the guard is aimed at exactly the defect that previously escaped and nothing
else moved to mask it. Run with PYTHONDONTWRITEBYTECODE=1 and a cleared
__pycache__, restored IN THE SAME COMMAND so the tree could not be left holding a
mutation, git status --porcelain confirmed empty afterwards. Non-vacuity is
asserted first and structurally: the two views of the SAME record are asserted to
derive DIFFERENT statuses before any claim about the derivation is made.

_decide gains one defaulted keyword (per_finding=False). A correction shares a
finding_id with the row it strikes, and a real emitted finding population is per
FINDING, never per row; every pre-existing caller passes byte-identical
arguments and no existing guard's behaviour moves.

DF-16-5-B FILED as a pure append: tests/test_gate_independence.py 962 -> 1,127,
crossing §0.5's "file an entry between 1,100 and 1,150" band - the same
pre-registered rule that produced DF-16-5-A, firing as designed rather than being
discovered later. NOT split (1,127 < 1,150) and NOT shaved: the -114 docstring
carries the GUARD-ADEQUACY content the clause mandates, and the entry names that
as the thing not to reclaim. DF-16-5-A is neither closed nor amended, and its
line recording 962 is left as shipped - this ledger is append-only.

argus/ and scripts/ are byte-unchanged by this commit, so §2.5's
artifact-currency order is not re-armed and gate_decision.py stays at 1,132.

Evidence-partition: none. Nothing ratified, no detector run, no disposition
written, no role filled, no V1.4 row, adjudication-record.json byte-unchanged,
SECTION_5_CONDITIONS still 7, precision_evaluable still 4 conjuncts,
no _EXEMPT_BY_DESIGN entry added, DF-13-5-A OPEN and UNSPENT.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Review fix round 1. Both findings resolved, 2 of 2; none rebutted, none
deferred, no guard weakened. Story in-progress -> review; sprint-status updated
to match, preserving every comment and the STATUS DEFINITIONS block.

Finding 1 (Patch, High, AC6.4) - the CR byte 9aea1be dropped from
deferred-work.md:5257 is restored (a4de7e7), together with the EOF newline
927548d dropped. The audit covered every blob in the arc by byte-level alignment
and found exactly ONE change that modified a pre-existing line - that CR - with
every other change a pure insert; the pre-story baseline reconstructs
byte-exactly. TC-ArgusAgent-DOCS-001-78 and ledger_closed_ids left unamended.

Finding 2 (Patch, Medium, AC1.3/AC5.4) - TC-ArgusAgent-PRECISION-001-114 guards
the live-rows derivation and is proven non-vacuous by the review's own mutation
(ca3853e). DF-16-5-B filed for the 962 -> 1,127 band crossing.

Both Review Findings checkboxes are ticked, a Review Fix Round 1 section records
each finding by name with what was measured, and the File List and Change Log
carry the deltas.

GATES, all re-run after the fix: full suite with
ARGUS_REQUIRE_LANGUAGE_GRAMMARS=1 - 1,688 passed, exit 0 (1,686 at review plus
the 2 new -114 cases); mypy argus - 94 source files, no issues; bandit -r argus
--severity-level medium - 0 medium / 0 high; tests/test_module_size_ceiling.py -
6 passed with no _EXEMPT_BY_DESIGN entry added; scripts/build_gate_decision.py
--check exit 0; scripts/build_adjudication_record.py --check exit 0.

Evidence-partition: none. argus/ and scripts/ byte-unchanged across the whole fix
round. Nothing ratified, no detector run, no disposition written, no role filled,
no V1.4 row, adjudication-record.json byte-unchanged, SECTION_5_CONDITIONS still
7, precision_evaluable still 4 conjuncts, gate_breadth.py:366-368 byte-as-shipped,
DF-13-5-A OPEN and UNSPENT.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Commit the code-review writes the review worker left in the tree: the
16.5 story file's iteration-2 review record and the sprint-status
transition to done. Review workers write but do not commit; this closes
the 16.5 arc on its own commit so the next story's diff stays legible.

No code, test or script file is touched.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
… a raise

`raise AssertionError("msg")` is one of the most rigorous assertions a Python
test can make, and the density numerator scored it as zero: a `raise` is not an
assertion callee, and `\A_?assert\w*\Z` is case-sensitive, so the capitalised
builtin matched neither limb of `is_assertion_callee`.

ONE NAME. `"AssertionError"` joins `_ASSERTION_CALLEES` (88 -> 89), +79/-0, a
pure insertion - which is what proves `_CORROBORATION_ASSERTION_CALLEES`, the
convention regex, `_MOCK_CALLEES` and both thresholds untouched rather than
merely asserting it. `DN-14-2-1` holds; the frozen table stays at 23 names and
nothing is promoted. Advisory tier only; the gate outcome does not move.

NOT A SECOND SCANNER. The call form ALREADY emits an `AssertionError` edge, so
the whole measured population is reachable from the table entry; a `raise`-
matching line scanner would count all 22 corpus spans twice, because
`assertion_sites` sums two independent counters over the same span. The bare
`raise AssertionError` stays invisible by measured decision - 0 of 1,032.

MEASURED over the 1,032 recorded `vacuous_test_heuristic` findings, read from
their pinned git objects: 22 carry the idiom (minions 12 + agent-smith 10),
flagged 1,032 -> 1,025, delta -7, newly flagged 0. Not -22: the other 15 gain
assertion sites but stay under the 1/4 floor or are flagged on the mock_ratio
limb this table cannot reach. `DN-14-3-5` re-derived with stdlib ast under
stated inclusion rules: 182 in-`raise` sites : 2 non-`raise`, 91x, over 5,086
files, with both collision sites named.

Seven guards in a NEW tests/test_vacuous_vocabulary.py (-138..-144), per
`DN-16-6-3`: tests/test_vacuous_density.py stays byte-unchanged at 1,159, so
`DF-15-2-E`'s 1,180 trigger does not fire and no split is dragged into a
behaviour-change story. Six of the seven go RED when the name is removed, while
the entire pre-existing vacuous suite stays green under the same mutation -
which is the point: no existing guard can see this fix.

tests/test_vacuous_cross_language.py takes two comment lines only, so `-133`
does not silently become a five-of-six register of accepted collision costs.

ON THE TRAILER BELOW, WHICH IS A JUDGEMENT AND IS DISCLOSED AS ONE. This is the
first post-seal commit to touch a declared detector-tuning path, so nothing
precedes it. Corpus findings DID inform this change - they sized the -7, and the
spelling census is what decided the fix shape - so `none` would be false. But
all five ratified members carry `partition: pre-seal`, and the sealed and open
partitions are BOTH EMPTY (0 sealed / 0 open / 5 pre-seal). `pre-seal` is not in
SEAL_CITATION_VALUES, whose only members are sealed|open|none. `sealed` would
falsely disclose that a holdout was peeked at, and there is no holdout: pre-seal
means Argus output over the member already existed when the seal was taken, so
the bisection was never applied and the member is EXCLUDED from being a holdout.
That leaves `open` as the nearest true value - the non-holdout side, "the
partition tuning happens against". It is cited in that sense ONLY and NOT as an
assignment: DN-16-2-4 keeps pre-seal a distinct partition precisely so an
exclusion is never read as one. The rule was NOT amended and no guard was
touched; the gap between the partition registry and the trailer vocabulary is
recorded in the story's Completion Notes for whoever owns the protocol.

NOTE ON THIS MESSAGE BEING PLAIN ASCII, because it is a measured constraint and
not a style choice. tests/test_gate_seal.py::_git shells out with `text=True`
and no `encoding=`, so it decodes git output with the LOCALE codec - cp1252 on
this Windows box. A commit message carrying a character outside cp1252 makes the
reader thread raise, `stdout` comes back None, and the seal guard dies with a
TypeError instead of reading the trailer. It would pass on the ubuntu CI leg,
where the locale is UTF-8, so the failure is Windows-only and invisible to CI.
The guard was NOT amended; the message was kept in ASCII, which is what every
commit in this history already does.

Evidence-partition: open

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
The one-name change added 79 physical lines to `argus/`, and the three committed
dogfood artifacts cite the tree's total physical LOC as the build-cost proxy
every budget figure folds from. 32555 -> 32634 turned
`test_committed_partition_plan_artifact_exists_and_matches_live_derivation` and
`test_committed_proof_artifact_exists_and_matches_live_run` red.

THE STORY DID NOT FORESEE THIS, AND IT IS RECORDED RATHER THAN SMOOTHED. AC6.1
fences the write set and declares everything outside it byte-unchanged, but ANY
line added to `argus/` moves this number, and the story's only possible
deliverable is a line added to `argus/`. So AC6.1's fence is unsatisfiable
alongside AC7.1's green suite as both are written, and the tree wins (AC4.4).
Section 2.3 and the Git-intelligence note say "no artifact is regenerated" about
the CORPUS artifacts - adjudication-record.json, adjudication-set-13-5.json and
gate-decision-record.json, which are byte-unchanged and stay that way. These are
the DOGFOOD artifacts, a different set the story never considered. Section 0.2
already records that `4123931` re-armed four currency guards and `ba5e8df` had
to repair them in a separate commit; this is that same discipline, on the same
epic, for the same reason.

Produced by `scripts/regenerate_dogfood_artifacts.py` - the named entry point
every one of those guards prints in its own failure message - which renders each
artifact through its OWN renderer and re-reads it to assert byte-equality. No
`.md` was hand-edited and no assertion was loosened (`DF-8-5-B`). It refuses to
run on a dirty `argus/` tree, so the behaviour change landed alone and first and
the artifacts follow separately, exactly as the bootstrap requires.

Diff is 3 lines per artifact: the LOC figure and the provenance sha. No corpus
artifact moves, nothing is ratified, no detector runs over a bench member, and
`DF-13-5-A` stays OPEN and UNSPENT.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…umber

`DF-16-6-B` is filed for the bare `raise AssertionError` spelling - the one the
table entry cannot reach, because a bare `Name` is not a call node and emits no
edge. It is a DECISION and not a gap: the spelling census over all 1,032
recorded findings measures 22 call-form against 0 bare, so a source-line scanner
buys exactly nothing on the measured population and would count all 22 call-form
spans twice. `TC-ArgusAgent-DETECT-001-141` holds it by execution, so nobody
completes it into that double count and nobody rediscovers it as news.

Appended in BINARY with the byte checks `DF-16-6-C` asks for: lone-CR count
1 -> 1, trailing newline intact, the HEAD blob still a strict prefix of the file
with the preceding bytes verbatim, `git ls-files --eol` still `i/-text w/-text`,
`git diff --numstat` +207/-0. No historical entry edited, no `.gitattributes`
added, and no `DF-*` other than `-B` created or disposed of.

The story record carries the re-derived figures, the mutation evidence and every
gate exit code. Three items the story did not foresee are written up in its
section 7b rather than smoothed:

  (i)   AC6.1's write-set fence cannot hold alongside AC7.1's green suite for
        ANY change to `argus/`, because the three DOGFOOD artifacts cite the
        tree's total physical LOC. Regenerated through their own renderers in
        their own commit. The CORPUS artifacts are byte-unchanged.
  (ii)  The first-ever post-seal detector commit needs an `Evidence-partition:`
        trailer, and the corpus has no matching value: 0 sealed / 0 open / 5
        pre-seal. Cited `open` in the sense of "not the sealed holdout", with
        the judgement disclosed in that commit's own body.
  (iii) `tests/test_gate_seal.py::_git` decodes git output with the locale
        codec, so a non-ASCII commit message makes the seal guard die on
        Windows and pass on the ubuntu leg. The message was kept ASCII.

NO guard was amended, weakened or exempted - not `ledger_closed_ids`, not
`story_closure_claims`, not the seal rule, not a dogfood assertion. No `DN-*`
reopened. `story_closure_claims` extracts zero new claims from anything this
story wrote.

Gates at the end: suite 1,695 passed / exit 0 (baseline 1,688 + 7), coverage
95.55%, `mypy argus` clean over 94 files, bandit Medium 0 / High 0, ceiling 6
passed with no `_EXEMPT_BY_DESIGN` entry added, `tests/test_gate_*.py` 36
passed, both builders `--check` exit 0.

`N` stays 5. Nothing ratified, no detector run over a bench member, no
third-party fetch, no disposition written, no role filled, no `V1.4` row,
`protocol_cleared` still False, the seal still closed, and `DF-13-5-A` stays
OPEN and UNSPENT. No threshold moved and nothing was promoted.

Story 16.6 moves to `review`.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Fix round 1 against the 2026-08-23 code review, which returned CONCERNS with
one [Review][Patch] and two [Review][Defer]. One of one actionable findings is
resolved. NO EXECUTABLE LINE CHANGED: the write set of this round is the story
record and `sprint-status.yaml`, and nothing under `argus/`, `tests/`,
`scripts/` or `.../validation-corpus/`.

THE DEFECT WAS A WRONG NUMBER IN THE STORY'S OWN RECORD. Completion Notes
section 7's gate table and the Change Log both reported
`pytest tests/test_gate_*.py` as "36 passed". The real figure is 58. The
reviewer got 58, the orchestrator got 58, and this round re-ran it a third time
and got 58 - `58 passed in 3.24s`, exit 0 - with the per-file collection
counted separately so the total is checkable rather than asserted:

  breadth 5 + condition_lookup 2 + decision 8 + decision_artifact 7 +
  flip_path 7 + independence 10 + ordering 4 + seal 9 + yield 6 = 58

No subset of the nine files sums to 36, so the "36" was a transcription error
and not a narrower selection somebody forgot to name. It is corrected in both
places, and the selection is now spelled out in the table cell so the number
and its scope cannot drift apart again.

AC3.3's discharge is UNAFFECTED. The selection is green at either figure, none
of the nine files was touched by this story, and all nine predate its baseline
commit `6d48c15`. `SECTION_5_CONDITIONS` stays SEVEN and `precision_evaluable`
keeps exactly FOUR conjuncts, discharged by those pre-existing guards and by
nothing this story wrote. This was a record-accuracy defect, not a functional
one - the same shape as the known "182 vs 109 keys" sprint-status miscount, and
the shape this epic keeps getting bitten by. That is why it was worth a round.

THE TWO [Review][Defer] FINDINGS WERE DELIBERATELY LEFT ALONE. Neither was
fixed and neither was filed to the ledger by this round; both are being filed
separately, outside this story's write-set fence, and `deferred-work.md` is
BYTE-UNTOUCHED here.

  (i)  `SEAL_CITATION_VALUES` in `argus/precision/gate_seal.py` carries no
       `pre-seal` member, so the `Evidence-partition: open` trailer on a
       100%-pre-seal corpus is a disclosed protocol gap. It corrupts no
       computed state: `cites_partition` matches only the three literal
       strings and `corpus_partition_counts` is computed independently of any
       trailer. Widening that enum is the seal-protocol owner's call.
  (ii) `tests/test_gate_seal.py::_git` runs `subprocess.run(text=True)` with no
       `encoding=`, so a non-cp1252 commit message yields `stdout` None and
       `cites_partition(None)` raises TypeError. Windows-only, invisible to
       the ubuntu leg. THIS MESSAGE WAS KEPT PURE ASCII for that reason.

Gates re-run in full with the edited record on disk, every number measured
this round rather than copied: suite 1,695 passed / exit 0 (identical to the
implementation round, as it must be), `mypy argus` clean over 94 source files,
bandit Medium 0 / High 0, ceiling 6 passed with the guard file byte-unchanged
and no `_EXEMPT_BY_DESIGN` entry added, `tests/test_gate_*.py` 58 passed,
governance-record integrity 3 passed, both builders `--check` exit 0.
`_ASSERTION_CALLEES` re-asserted at 89 and `_CORROBORATION_ASSERTION_CALLEES`
at 23 by execution.

NO guard was amended, weakened or exempted. No `DN-*` reopened. No eighth
section 5 condition. `story_closure_claims` extracts exactly one claim from
this story file, the pre-existing `DF-15-2-D` one the ledger backs, and zero
new ones from anything this round wrote. `sprint-status.yaml` keeps all 109
`development_status` keys, every comment and the STATUS DEFINITIONS block; one
line changed.

`N` stays 5. Nothing ratified, no detector run over a bench member, no
third-party fetch, no disposition written, no role filled, no `V1.4` row,
`adjudication-record.json` byte-unchanged, `protocol_cleared` still False, the
seal still closed. `DF-13-5-A` stays OPEN and UNSPENT.

Story 16.6 returns to `review`.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…t will not buy you

`--deep-audit` was documented as a flag with no page telling a reader how to point it at a
provider. The three environment variables that decide it were discoverable only by reading
`open_llm_adapter.py`, and two of their sharp edges only by reading it carefully:

* the ENDPOINT variable is the switch, not the key. `OPENAI_API_KEY` alone leaves every
  endpoint variable unset, so `resolve_provider_endpoint()` returns `None`, no adapter is
  constructed, and the pass degrades `provider_unconfigured` -- correct behaviour that reads
  as silence.
* the adapter appends `/v1/chat/completions`, so a base URL ending in `/v1` -- the near
  universal habit -- doubles the path and returns 404 as a `dispatch-failed` degradation
  rather than as a configuration error.

The page leads with `DF-12-2-D` rather than burying it: neither `_dispatch_litellm` nor
`_dispatch_httpx` populates `structured_output`, so `_dispatch_one` returns `empty-response`
before grounding is consulted and `delivered_count` is always 0 through the shipped adapter.
A successful dispatch to a healthy provider still degrades, and a paid provider still bills.
A setup guide written over that would be the over-claim this page's own preamble rule
forbids, so it is stated where the reader meets the command.

TC-ArgusAgent-DOCS-001-63 widened, because it was matching the wrong observable. It scans
the page for SCREAMING_SNAKE_CASE and calls what it finds a verdict token; an environment
variable name is that shape too, so all six tripped a guard about verdicts -- the same class
as the README false positive its own comment already records. The exemption is DERIVED by
`ast` from the adapter's own `os.getenv` calls, reusing `adapter_environment_variables()`
(Story 12.2 / AC2.3) rather than forking a second list, so a variable is admitted only while
the adapter genuinely reads it and a seventh is covered the day it lands. Stripping code
spans was the tempting fix and was declined: the verdict table is backticked too, so it
would have gutted the guard it was meant to preserve.

Suite: -62 and -63 green, `test_invocation_contract` green. Full suite carries 26 failures,
MEASURED IDENTICAL with these two files stashed -- pre-existing tree-sitter grammar failures
on this host, untouched by this change and not introduced by it.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…easured

Story 16.7 ready-for-dev -> in-progress. Task 0 reproduced every section 0
premise by execution at HEAD b3b761f rather than trusting the story text.

Reproduced exactly: the variant lattice V0 0 / V1 6 / V2 36 / V3 6 / V4 676 /
V5 125 and 45 spans asserting nothing at any disc; the class at 36, agent-smith
22 + minions 14 across 19 files, 18 carrying a comment somewhere in the span;
1032 vacuous_test_heuristic findings walked, 0 skipped, 0 unresolvable; 39
pre-16.6 with the three findings 16.6 removed named identically to the story's
own table; the blast radius of a wrong write, total_tp 0->36,
adjudicated_population 31->67, distinct_rule_class_count 1->2 and
independence.status NOT_INDEPENDENT -> SECOND_REVIEWER_INTERNAL, with
adjudication-record.json proved byte-identical before and after the simulation;
both closed-schema traps, a widened ROW_FIELDS making load_record RAISE and
rec.to_bytes() equal to the committed bytes; the import-reach registry at 14;
the ledger at 457560 bytes with exactly one lone CR and zero CRLF pairs; the
protocol change-log head at V1.3; the next free ids 115 and DF-16-7-B.

Two section 0 items did NOT hold and the tree wins:

1. HEAD is b3b761f, one commit past the story's d6625b5. That commit is the
   real fix for docs/first-run.md's verdict-vocabulary case - the same case
   section 0.0 diagnosed as a false RED from stale bytecode. The stale-cache
   effect was real, but the case was also genuinely under-specified, so the
   diagnosis was half right. Task 0.1 allows "at or after d6625b5".

2. Another party held this working tree between 18:53 and 18:57 local, moving
   it to dev and master, rebasing, and stashing the 16.6 in-flight artifacts
   before restoring all of it. One baseline suite run was poisoned by it and
   was re-run clean. Section 0.7 says a corpus member is a live shared tree;
   this repository is one too.

Also recorded: minions' porcelain now reads 0 entries, a third same-day value
after section 0.7's 7 and 1. That confirms DN-16-7-4 rather than denying it -
neither emptiness nor invariance is assertable there.

Nothing is adjudicated by this commit and nothing is promoted.

Evidence-partition: pre-seal
The shipped fact-(b) predicate reaches ZERO of the 1032 vacuous_test_heuristic
findings the ratified corpus recorded, so the externalization gate is BLOCKED on
an empty denominator rather than on a shortfall. This adds the instrument that
measures the one cheaply-reachable alternative, and it deliberately stops short
of using it.

  argus/precision/silent_class.py       the predicate and the record (pure, AR8)
  scripts/build_silent_class_record.py  the derivation and the two artifacts
  tests/test_silent_class.py            the PREDICATE:  -115..-118, -126..-128
  tests/test_silent_class_record.py     the RECORD:     -119..-125, -129..-133
  tests/test_release_preflight.py       ONE registry entry and its comment

A THIRD SECTION-0 PREMISE FELL, and it is worth naming because the guard that
caught it is index-scoped and therefore can only catch it LATE. The story's
section 0.8 records tests/test_silent_class.py as a new file with 1200 lines of
headroom. Written whole it came to 1241 - a real NFR-M1 breach - and
tests/test_module_size_ceiling.py stayed GREEN through every local run, because
its population is `git ls-files` and the file was still UNTRACKED. It went red
only on `git add`. So the guards are split along AR8's own seam, which is the
remedy NFR-M1 prescribes: the PREDICATE and its containment in one file, the
RECORD and its vocabularies in the other, with the fixture plumbing IMPORTED
from the first rather than copied. No line was shaved and no _EXEMPT_BY_DESIGN
entry was added - MAINT-001-04 lets that registry shrink only. 699 and 772
lines.

THE PREDICATE IS COMPOSED, NEVER RE-IMPLEMENTED. V2 SILENT is "the span reaches
the SUT, discards a result, and asserts NOTHING AT ALL". It is built by CALLING
provenance_evidence (frozen table - fact (b) own arithmetic), is_assertion_callee
(the WIDE table - DN-14-2-1), opens_bare_assert, body_statement_count and
index_aligned_lines over a real build_ast_index. There is no second AST walk and
no second assertion-name regex, and -126 asserts that by walking the module own
source: it imports neither ast nor re, and the ONE function that answers the
silence question is asserted not to reach the frozen table while the ONE function
that computes fact (b) arithmetic is asserted to keep using it.

Why the wide table for silence, when the detector must use the frozen one for
corroboration: the direction of harm reverses. Inside the detector, widening the
table moves a test TOWARDS an accusation. Here, a test asserting through a name
the frozen table has never heard of would be scored assertion-free and published
to a human as SILENT when it is nothing of the kind. Measured this round: routing
the silence question through the frozen table takes the class 36 -> 84. Those 48
extra spans all assert. That is what the DN-14-2-1 moat is worth, quantified.

THE EDGE RUNS ONE WAY, and -127 walks the whole argus import graph to say so:
nothing under argus/detectors and no argus/precision/gate_*.py reaches this
module, directly or transitively. A predicate that scores test functions sitting
on the detector path is a shipped promotion waiting for someone to wire it up.
The walk asserts it parsed 60+ modules and resolved this module own known
outbound edge BEFORE asserting what it did not find; a walk that silently parsed
zero files passes a "nothing imports it" guard forever.

THE DISPOSITIONS DO NOT GO ON THE GATE RECORD, and that is the load-bearing
scoping decision. Simulated in memory: appending 36 advisory TP rows to
adjudication-record.json takes total_tp 0 -> 36, adjudicated_population 31 -> 67,
distinct_rule_class_count 1 -> 2 and independence.status NOT_INDEPENDENT ->
SECOND_REVIEWER_INTERNAL. Two of those the epic forbids outright, and the move is
wrong on the protocol own terms besides: all 1032 findings are advisory, and
protocol section 4, build_adjudication_record.py and blocking-worklist-13-5.md
each say independently that an advisory finding is not a false ACCUSATION and is
not in the denominator. So this record lives at its own address (DN-16-7-1), and
the four committed corpus JSONs are byte-unchanged.

THE VOCABULARY IS BORROWED, NEVER FORKED. DISPOSITIONS, HUMAN_DISPOSITIONS,
PROTOCOL_ADJUDICATOR_ROLES, LOCATOR_RE, adjudicator_role, disposition_meaning and
finding_row_id are the SAME OBJECTS as adjudication.py - asserted with "is" and
not "==", because an "==" comparison passes over a re-declared copy and every
other guard would stay green while the two records drifted. The counting, the
live-row rule and the exhaustiveness rule are DELEGATED to AdjudicationRecord
rather than restated. The ONE thing added is idiom, on a NEW row type: a row may
be FP AND DELIBERATE_SMOKE_TEST at once and that combination IS the measurement,
so it is an orthogonal axis and emphatically not a fifth disposition (DN-16-7-2).
ROW_FIELDS stays at eleven, DISPOSITIONS at four - measured: adding a twelfth
field makes load_record() on the committed record RAISE outright.

NOTHING IS PROMOTED AND NOTHING IS ADJUDICATED. seed_row is the only row factory
the builder can reach and it has no parameter for a disposition, an adjudicator
or a date, so "the producer started filling in the human judgements" is not a
failure mode a reviewer has to watch for - it is unreachable, and -125 asserts it
from the signature. verdict_eligible stays False on every row.

CONTAINMENT IS PROVED, NOT PROMISED. Every byte read from a corpus member comes
out of the git object database at the pin, through the shipped content-addressed
pinned_tree / materialize_pinned_bytes / verify_pinned_bytes, with every
materialized file re-hashed against the id ls-tree reported. Every git call goes
through a named READ-ONLY verb allow-list from which checkout, stash, clean,
reset, worktree, add, commit, fetch and pull are absent - and -130 proves the
refusal by DRIVING it for all twelve mutating verbs rather than by reading the
constant. Deliberately NOT asserted: that a member tree is clean, or invariant
across the run. minions returned 13, 14, 0, 7, 1, 0 and 2 dirty entries across
seven same-day readings by three different sessions, because it is a live tree
other people are editing. A check nobody can satisfy is the Story 16.5 defect
class; the porcelains are captured and reported (DN-16-7-4).

GUARD ADEQUACY, discharged rather than promised. Three mutations were executed
against the real tree, each observed RED at the real seam, each restored with
git status --porcelain proved byte-identical to the pre-mutation capture:

  (i)   remove "AssertionError" from the WIDE table -> class 36 -> 39, and the
        three admitted are EXACTLY the three Story 16.6 removed. RED: -117, -128.
  (ii)  route silence through _CORROBORATION_ASSERTION_CALLEES -> class 36 -> 84.
        RED: -116, -117, -126, -128 and the fixture-honesty preamble.
  (iii) drop the disc >= 1 conjunct -> class 36 -> 45, all 9 admitted at disc 0.
        RED: -118, -125.

The lockstep trap is answered by construction: the predicate cases score the SAME
fixture text under two vocabularies and assert statement_count and
discarded_sut_calls came out EQUAL across the pair, so a membership difference
cannot be explained by the fixture having grown. -128 GENERATES its adversarial
variants from _ASSERTION_CALLEES minus the frozen table minus the names the
naming convention already catches, with the count asserted, so a name entering or
leaving the table re-runs the adversary automatically.

EVERY REFUSAL THIS RECORD CAN MAKE IS REACHABLE, and -133 drives each one with a
single input that differs from a known-valid row in exactly one field, so a
failure names the field rather than the fixture. A raise nobody can trigger
protects nothing, and construction-time validation is this record's entire
enforcement mechanism - it is why "the producer started writing judgements" and
"a promotion was smuggled in through a row" are construction errors rather than
things a reviewer must notice. Nine row refusals, four record refusals, two
impossible-tally refusals, three human-judgement refusals, and the EXHAUSTIVE arm
that a seeded record can never reach. argus/precision/silent_class.py measures
100% statement coverage as a result, and the suite total moved 95.55 -> 95.68.

PORTABILITY IS A CRITERION, NOT A HOPE (AI-E13-1, DF-16-6-F). -129 asserts, by
AST scan of both new modules: no platform separator constant, no path-join
helper, no backslash inside ANY string constant, every read_text/write_text/open
names its encoding, every write_text names its newline, and no subprocess call
passes text=. All 36 locators are checked against LOCATOR_RE. The builder adds no
sixth _git and reuses the shipped one, which captures bytes and decodes them
explicitly - the exact bug DF-16-6-F is open for in a sibling guard.

tests/test_release_preflight.py gains ONE registry entry and its prose comment.
The import-reach set moves 14 -> 15, measured, and the addition is DELIBERATE,
which is what that registry exists to force someone to say. No assertion, no
other registry and no import in that file changed.

Nothing here asserts anything about argus/precision/gate_*.py and nothing here
imports gate_decision. That the gate did not move is discharged by the nine
existing tests/test_gate_*.py staying green and by both existing builders exiting
0 under --check. Forking a guard that already exists is the AR7 defect, and AR7
is what this whole story is about.

Evidence-partition: pre-seal
TC-ArgusAgent-DOGFOOD-001-50 went RED the moment the previous commit landed, and
it was right to. The three committed dogfood artifacts cited dd1e03a and argus/
had moved since - one file, 944 insertions, argus/precision/silent_class.py.
The guard's property is exactly that: an artifact is current iff the sha it cites
is an ancestor of HEAD and `git diff <cited-sha> HEAD -- argus/` is empty.

Regenerated through the artifacts' own renderer by
scripts/regenerate_dogfood_artifacts.py, which refuses a dirty argus/ tree
outright (exit 2) because a rendered artifact cites `git rev-parse HEAD` as its
provenance and a commit cannot cite itself. That refusal is what forces this
story's commit arc to be four commits rather than three - the feat had to land
first so the regeneration had a truthful sha to cite. It is the same shape Story
16.6 paid for unplanned in 6304552; here it was planned for.

  provenance sha now cited by all three: 7fec3cd
  tracked source files enumerated: 95   total LOC: 33578
  REWRITTEN  minions-dogfood-partition-plan.md
  REWRITTEN  minions-dogfood-budget-plan.md
  REWRITTEN  minions-dogfood-proof.md

No .md was edited by hand. No assertion was loosened or deleted - DF-8-5-B's own
instruction is "do not close it by loosening an assertion", and the operator
ruling of 2026-08-12 is that a regeneration is legitimate only through the
artifact's own renderer at a truthful sha.

Nothing about the silent class, the adjudication record or the gate is touched
by this commit. It is provenance bookkeeping the previous commit made necessary.

Evidence-partition: pre-seal
36 rows now await a named human, and that is the story succeeding.

  validation-corpus/silent-class-record.json    36 seeded UNADJUDICATED rows
  validation-corpus/silent-class-worklist.md    the human worklist, DERIVED
  deferred-work.md                              DF-16-7-B appended
  README.md / CHANGELOG.md                      four DERIVED figures, 94 -> 95
  the story record, sprint-status               in-progress -> review

THE HALT IS DESIGNED, AND REACHING IT IS THE STORY SUCCEEDING. DN-16-7-3 and
AC4.5 fixed this terminal state before a line was written. Protocol section 2
registers UNADJUDICATED as "the ONLY member an automated producer may write" and
records that "an autonomous story that tags its own findings TP has measured
nothing and has produced the exact artifact Epic 13 exists to make impossible."
So the instrument is built, the class is derived, one UNADJUDICATED row per
member is seeded, the worklist is published, and this stops. Story 13.2 (AC7)
and Story 16.4 (AC1.4) are the precedent, and 13.2's own review ruled that such
a halt is a legitimate designed terminal state rather than an unmet AC.

WHAT THE NAMED HUMAN MUST NOW DO, and exactly where. The worklist is
_bmad-output/design-artifacts/ArgusAgent/validation-corpus/silent-class-worklist.md.
It carries all 36 rows with the member, the repo-relative POSIX locator, the test
name, the pinned sha, the measured disc/cons, and the test's full source span
rendered from the PINNED BLOB, so the judgement can be made without cloning five
repositories. Each row needs four things and the row constructor refuses anything
less: a disposition (TP / FP / BORDERLINE); an idiom (DELIBERATE_SMOKE_TEST /
NOT_A_SMOKE_TEST / NOT_ASSESSED) which is a SEPARATE AXIS, so a row may be FP AND
a deliberate smoke test at once and that combination IS the measurement; an
adjudicator id of the exact form "<who> (<role>)" - the two registered holders
are XAgent007 (Engineering Lead) and Veer Pratap Singh (QA Lead), role filled
2026-08-22 by operator act; and a date plus a REASON, because a judgement with no
reason cannot be re-examined and section 4's ladder IS a re-examination
procedure. Then re-run scripts/build_silent_class_record.py --checkout-root
<ROOT>: it is append-only over human judgements, so every judged row is carried
through byte-identically.

THE EXTERNAL ADJUDICATOR TIE-BREAK IS STILL UNFILLED, deliberately. Section 4's
ladder is three steps and only PERSISTENT DISAGREEMENT between the two filled
roles reaches step 3; a run that reaches it must STOP and report which rows and
why. A BORDERLINE on its own is NOT step 3 - it is a first-class recorded outcome
meaning "looked at, could not decide", it makes the run non-exhaustive, and it
enters neither side of any ratio. Nothing in this story reached step 3, because
nothing was judged at all. AC4.4 is discharged vacuously, and it is recorded as
vacuous rather than claimed as a pass.

THE SEEDED STATE, which is the honest one: TP 0, FP 0, BORDERLINE 0,
UNADJUDICATED 36. Exhaustiveness UNEVALUABLE with 36 residuals. Independence
NOT_ESTABLISHED - nobody judged it, which is a different finding from "the author
judged all of it". The smoke-test proportion is NOT MEASURED and REFUSES to
report 0/36, because a proportion over rows nobody read is not a measurement and
producing one is the exact artifact this story exists to avoid.

DF-16-7-B, appended in binary and verified byte by byte. It records (a) that
DF-16-7-A's V5 figure re-measured 122 -> 125, the delta being exactly Story
16.6's three, which stopped being silent and became asserts-but-not-about-the-SUT
once raise AssertionError became recognised - DF-16-7-A is NOT edited, because
section 3.4 is strike-never-erase and the ledger is append-only; (b) that the
class's true-positive proportion is NOT YET MEASURED pending the human act; and
two measurements nobody had written down - that V1 is a strict SUBSET of V2 with
30 of the 36 outside it, so promoting V2 later would be a genuinely DIFFERENT
predicate rather than a loosening of fact (b), and that routing the silence
question through the frozen table takes the class 36 -> 84, which is 48 false
accusations and is what DN-14-2-1's two-table split is worth over this corpus.

  ledger 457560 -> 462339 bytes; lone CR still exactly 1; CRLF pairs still 0;
  still ends with a newline; the pre-append bytes are a strict PREFIX of the
  result; git diff --numstat reports +139 / -0. No .gitattributes was added.

Note that deferred-work.md in this commit also carries the DF-16-6-E and
DF-16-6-F appends that Story 16.6's iteration-2 review left uncommitted in the
working tree. They were present before this story opened - the story's own
section 0.0 records them as such - and they are carried through here untouched
rather than stranded. Nothing on this ledger is edited and nothing is disposed
of; DF-13-5-A stays OPEN and UNSPENT.

ONE DEVIATION FROM AC8.1's WRITE SET, recorded rather than smoothed. README.md
and CHANGELOG.md are not in it, and this commit writes to both. A FOURTH registry
that section 0.6 does not name - TC-ArgusAgent-DOCS-001-54 - builds a real wheel
and sdist and asserts in BOTH directions that every count published in those two
documents equals the freshly built artifact's, while also asserting the sentence
still EXISTS so that "the way to make this test pass can never be to delete the
sentence". Adding one shipped module moved four derived figures: 94 -> 95
modules, 102 -> 103 wheel entries, 101 -> 102 sdist members. The only
alternatives were a red suite or a weakened guard, and the guard's own failure
message is the instruction - the artifact is the fact, fix the document. Story
16.5 made the identical 93 -> 94 edit when it added gate_independence.py and that
shape is followed verbatim. Four numbers and two dated parentheticals changed; no
assertion anywhere was touched. Completion Note 4b carries the full rationale.

NOTHING IS PROMOTED AND NOTHING ON THE GATE'S DECISION PATH MOVED.
verdict_eligible is False on all 36. argus/detectors is byte-unchanged, and so
are adjudication-record.json, adjudication-set.json, adjudication-set-13-5.json
and gate-decision-record.json - re-asserted by PRECISION-001-131 around a live
--check run rather than by inspection. SECTION_5_CONDITIONS stays at seven,
precision_evaluable keeps four conjuncts, VALIDATION_SET_FLOOR_N stays 5,
PRECISION_GATE_THRESHOLD stays Fraction(4, 5), N stays 5, protocol_cleared stays
False, the seal stays closed, the gate stays BLOCKED, the protocol change-log
head stays V1.3 with no V1.4 row, no role was filled, no vocabulary was widened,
no DN-* was reopened and no AC9.4 escalation was reached.

Final gates: 1715 passed / 0 failed / exit 0 - exactly +20, this story's own
case count, so the pre-story baseline derives to 1695 and agrees with the story's
section 0.0 measurement to the case; coverage 95.68 percent (baseline 95.55, so this
story raised it) with the new module at 100; mypy argus 95 files clean; bandit no issues over 26581 LOC; all
nine tests/test_gate_*.py green at 58 passed, which is AC8.2's whole discharge;
ceiling 6; ordering 4; preflight 21; dogfood currency 4; governance 3; this
story's own 20; all three builders --check exit 0.

Evidence-partition: pre-seal
… gets

Four rules registered in architecture.md section Enforcement, each with its
measured trigger, its mechanism, and what it explicitly does NOT do. All
additive: no byte deleted, no existing gate weakened, no blocking gate added.

WHAT WAS MEASURED, 2026-08-23. Governance prose is 108,190 lines against
33,578 of product source. The process-derived share of an epic's stories ran
11% (Epic 12) -> 25% (13) -> 33% (14) -> 86% (Epic 16), and from Epic 13
onward no epic seed's **Covers:** line names a single FR/NFR driver. Over the
128 commits since 40cdb3c, argus/ changed by 8,486 lines of which 6,483 (76%)
are argus/precision/ -- this project's own gate machinery, unreachable from
argus.cli -- while argus/cli.py and argus/commands/ changed by zero. The last
user-reachable feature shipped 2026-08-15 (Story 12.8).

scripts/check_meta_drift.py reports the budget and the capability field.
ADVISORY, always exits 0 on a clean parse: its predicates read prose, and a
blocking prose-parser produces false failures that abort legitimate work --
TC-ArgusAgent-DOCS-001-78 went RED three times from prose in one day. Forward-
only at CUTOFF_EPIC 17; Epics 1-16 are never classified, because an item's age
is evidence, not debt (3.4).

tests/conftest.py records every guard observed RED, AUTOMATICALLY. 967 of
1,251 guard ids are named nowhere outside their own test file and zero tests
have ever been deleted in 189 commits, so "never caught anything" is currently
indistinguishable from "nobody wrote it down" -- and RETIREMENT IS THEREFORE
WITHHELD for two full epics. The mechanism is automatic because the manual
alternative is the one AI-E14-1..-9 recorded as not-addressed across six
consecutive retrospectives. It writes to a gitignored path, since a hook that
dirtied the tree would break release_preflight's E1 refusal, and it is
exception-wrapped throughout: telemetry is never allowed to be load-bearing.
Verified by executed probe -- a synthetic TC-named failure recorded with id,
nodeid and sha; an ordinary failure in the same run correctly not recorded.

scripts/acceptance_scenarios.py answers the question the gates do not. The
committed final-verdict.md reads RELEASE_READY with 0 blocking findings while
protocol section 5 reads BLOCKED: both true, neither a release decision. Six
hermetic scenarios build their fixtures from bytes in the script -- nothing
fetched, no corpus member read -- and cross-check three independently produced
surfaces: the exit code the OS saw, the stdout summary a script parses, and
the final-verdict.md a human reads. NO EXPECTED VERDICT IS HARDCODED, because
a sheet of pinned verdicts rots into a change detector that re-asserts
whatever the tool already does. A surface that cannot be observed is
UNEVALUABLE, never a silent pass. Driven to BOTH outcomes by executed mutation
per AI-E14-1: 6 of 6 agree at HEAD, and flipping the observed exit code away
from the report's stated one turns them RED with the failing check named.
Existing gates are DEMOTED, not deleted -- every one keeps its blocking power.

The ruling index is additive only. DN-3 is restated in 48 documents and
"3.4 evidence immutability" -- cited 144 times -- has no defining section in
any indexed governance document. Reconciling the existing copies is DECLINED,
not deferred: filing it would create the unbounded process backlog this rule
exists to bound.

meta-drift-baseline.md freezes the pre-rule state and carries the warning that
a row may never be added to silence a new finding.

Suite: 1716 passed.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Fix round 1 of story 16.7's code review, committed a round late: the round
itself was killed by a session limit before it could commit, and its work
survived uncommitted in the working tree. Both iteration-1 findings were [Low]
and [Patch]; 2 of 2 resolved, 0 refused, 0 deferred, 0 filed to the ledger.

FINDING 1, the only executable change. --map MEMBER_ID=RELATIVE_PATH refused an
escaping override with Path(relative).is_absolute(), and its message promised to
stop "pathlib discards the left operand when the right one is absolute - which
silently escapes the root entirely". On this repository's local platform it did
not stop it: on Windows Path("/etc/passwd").is_absolute() is False - there is no
drive - so root / "/etc/passwd" resolved to <root drive>:\etc\passwd, outside
--checkout-root, which is the precise escape the message named. A
backslash-anchored path and drive-relative "C:etc" walked through the same way:
three of the five anchored forms pathlib honours were accepted by a check whose
whole purpose was to reject them. Nothing in the suite referenced --map or
is_absolute at all, so the gap was invisible to it. Windows-only local gates, an
ubuntu matrix CI leg, and a portability check nobody drives is AI-E13-1, found
here inside AC8.4's own scope.

_discards_the_root asks the question that actually decides the join - is the
operand ANCHORED? - of BOTH flavours, refusing if either PurePosixPath or
PureWindowsPath reports a root or a drive. It catches all five anchored forms,
needs no backslash literal (-129 forbids one in this module), and answers
IDENTICALLY on the local Windows leg and on the ubuntu CI leg, which is the
whole defect. Traversal via ".." is left permitted and named out of scope in the
docstring: that escape is visible, this one was silent.

TC-ArgusAgent-PRECISION-001-134 drives it at the real CLI seam and was RED
first. The exit code alone would have been a vacuous assertion - the unfixed
guard also exits 2, one step later, refusing a missing checkout it reached
without ever detecting the escape - so the assertion is on the message. The case
proves the escape is real on this platform before asserting anything about it,
drives the predicate two-sided over five anchored forms and over every
DEFAULT_CHECKOUT_MAP value the tool ships, and drives the two sibling --map
refusals, equally undriven until now.

FINDING 2 was text only: Change Log row 2's cohesion split 699 + 641 corrected
to 699 + 772, plus a second occurrence of the same stale figure in Completion
Note 2 that the review did not catch.

RE-VERIFIED AT A MOVED BASELINE. An unrelated concurrent session committed
c7912a1 onto this branch after fix round 1 took its measurements, adding a
repo-wide tests/conftest.py of guard-fire telemetry that hooks every test. Every
figure was therefore re-measured at the new HEAD with __pycache__ cleared, and
no gate figure moved: suite 1716 tests / 0 failures / 0 errors / 0 skipped /
exit 0; coverage 95.68 percent (7313 stmts, 316 missed) with silent_class.py at
100; mypy argus 95 files clean; bandit Medium 0 / High 0 over 26581 LOC; all
nine tests/test_gate_*.py green at 58, which is AC8.2's whole discharge; ceiling
6; ordering 4; preflight 21; dogfood currency 4; governance 3; this story's own
21; all three builders --check exit 0. c7912a1 adds no test file and touches
nothing under argus/, which is why every denominator is undisturbed.

The conftest OBSERVES this story's guards and cannot perturb them, checked both
ways rather than argued. Its regex resolves 20 of this story's 21 cases to ids
-115..-134, and -134 is the worked example in its own docstring, having sat
uncommitted in the tree while c7912a1 was written. But it fires only on a RED
call phase, so the green run wrote no ledger at all, and a synthetic RED report
wrote its row while git status --porcelain stayed byte-identical, since .argus/
is gitignored. AC7.2's before/after porcelain invariance therefore still holds
and the three AC7.1 mutations are neither invalidated nor observed differently.

Two non-gate figures in the record were wrong and are corrected by dated
supersession rather than overwrite: this commit's own write-set line counts are
+35/-5 and +94/-1, not the +30/-5 and +93 fix round 1 recorded.

Nothing else was reopened: 36 rows still UNADJUDICATED, gate still BLOCKED, the
operator handoff still UN-TAKEN, argus/** and all six corpus artifacts
byte-unchanged, deferred-work.md untouched, no guard weakened or exempted, no
_EXEMPT_BY_DESIGN entry added, no ceiling constant moved, no DN-* reopened,
DF-13-5-A OPEN and UNSPENT. Story 16.7 stays in review.

Evidence-partition: pre-seal

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Story 16.6's iteration-2 code review, written back to its story file. Committed
separately from story 16.7's fix round because it is a separate concern: 16.6 is
already done, and this is its record catching up. Its sprint-status key was
already committed as done; the story file's own Status line catches up here.

The iteration-1 [Patch] finding is confirmed fixed by independent execution: all
nine tests/test_gate_*.py re-run at 58 passed, matching the corrected figure,
and fix round 1's diff confirmed to touch only the story record and
sprint-status.yaml. Both iteration-1 [Defer] findings were re-confirmed real by
reading the shipped code rather than re-trusting the write-up, and both remain
correctly outside 16.6's fence under AC7.4.

The round also closed a process gap it found in itself. Both [Defer] findings
had been correctly triaged by iteration 1 and then never filed to the ledger -
fix round 1's own commit message disclosed the intent to file them separately
and no filing commit followed. Filing a defer finding is this review workflow's
step, not the dev's, so iteration 2 filed DF-16-6-E (SEAL_CITATION_VALUES has no
pre-seal member, so an Evidence-partition: open citation is the closest
available and not the true one) and DF-16-6-F (tests/test_gate_seal.py::_git
decodes git output with the locale codec, so a non-ASCII commit message kills
the seal guard on the Windows leg and passes on the ubuntu one). Both are
already in deferred-work.md, committed in 76ee9fa, which swept the ledger file
up with DF-16-7-B - verified against HEAD before writing this, so nothing is
appended to the ledger here and this commit carries the story record only.

A reconciliation note is added ABOVE iteration 1's findings rather than editing
them. Iteration 1's text reads "Verdict: pass" while the verdict it actually
enacted was CONCERNS - sprint-status.yaml records review -> in-progress, and an
unresolved [Review][Patch] finding blocks pass by definition. The slip is left
exactly as written and the inconsistency is named next to it, per the
preserve-history convention rather than a silent overwrite.

Iteration-2 verdict: PASS. Every AC independently verified met by fresh
execution, no unresolved decision-needed, patch, High or Medium finding remains.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Judged fix round 1 (commit 7219223), scoped exactly as instructed: judge the
fix, not relitigate the story. The Task 7 HALT ruling from iteration 1
(DN-16-7-3 / AC4.5's designed terminal state) stands and is not reopened; the
36 UNADJUDICATED rows remain correctly outside AC scope.

Finding 1 verified by execution, not by reading the record. In-memory
monkeypatched build_silent_class_record._discards_the_root back to the
iteration-1-reported Path(relative).is_absolute() behaviour (the repository
file itself was never edited) and drove main(["--map",
"minions=/etc/passwd", ...]) against it: the escape was silently accepted
and the run failed two members later on an unrelated missing checkout, exit
2, with no refusal text at all in stderr -- independently reproducing the
exact vacuity risk TC-ArgusAgent-PRECISION-001-134's message-content
assertion exists to close. Re-ran the shipped _discards_the_root directly
over all five anchored forms (all True) and over "..", every
DEFAULT_CHECKOUT_MAP value and two legitimate paths (all False): two-sided,
and ".." confirmed a documented, deliberate scope exclusion rather than a
hole. -134 and -129 both pass in isolation.

Finding 2 verified clean: every remaining "641" in the story file is inside
finding or narrative text, none a live asserted figure; Change Log row 2
reads 699 + 772; wc -l on all four new files matches the claimed physical
line counts exactly.

The concurrent-baseline-move audit (c7912a1) was independently re-executed
rather than trusted. Full suite via junit: 1,716 tests / 0 failures / 0
errors / 0 skipped, exit 0 (241.7s); coverage 95.68% (7,313 stmts, 316
missed), exit 0; mypy argus 95 files clean; bandit 0 medium / 0 high over
26,581 LOC; tests/test_gate_*.py 58; ceiling 6; ordering 4; preflight 21;
dogfood currency 4; governance 3; this story's own 21; all three builders
--check exit 0 -- every figure matches Completion Note 10 exactly. git diff
7219223 --numstat confirms +35/-5 and +94/-1 exactly.

The conftest-interaction claim was re-verified by execution rather than
re-read. Read tests/conftest.py in full: it records only on
when=="call" and failed, writes to the gitignored .argus/guard-fires.jsonl
(confirmed at .gitignore:19), and is exception-wrapped throughout. Ran this
story's 21 green cases -- .argus/ was not created at all. Added and ran a
scratch always-failing test (never committed, deleted immediately after) --
.argus/guard-fires.jsonl was written, and git status --porcelain showed only
the untracked scratch file itself, no .argus/ entry before or after. This
directly confirms AC7.2's porcelain-invariance contract cannot be perturbed
by the conftest hook.

git show --stat 7219223 confirms exactly the four claimed write-set paths.
deferred-work.md confirmed to carry DF-16-7-B, DF-16-6-E and DF-16-6-F on
disk. HEAD confirmed at 95d41f6 with c7912a1 and 7219223 both ancestors;
git status --porcelain clean before and after this review's own execution.
The baseline-move disclosure in Completion Note 10 and 7219223's own commit
message is honest and specific, not smoothed.

No new finding. No decision-needed, no patch, no Medium/High, no unmet AC,
no failing gate.

Iteration-2 verdict: PASS. Story 16.7 review -> done. Epic 16 -- the last
epic in the plan -- has no story left in review.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…it legal

The Epic 16 retrospective document, committed together with the one line in
`tests/test_status_document_registry.py::_STATUS_DOCUMENTS` that registers it.
The two belong in one commit because `TC-ArgusAgent-DOCS-001-22` closes in BOTH
directions: the document without the entry and the entry without the document
red `master` equally.

The retrospective worker could not add that line itself. It was chartered
READ-ONLY over `tests/` on a working tree shared with another active session,
so it filed the omission against itself as `AI-E16-15` -- item 0 of its own
critical path -- and stated that the tree was RED from the moment the file was
written. This commit is that action item discharged, and nothing else: the
document's content and its action items are untouched, and no
`development_status` value was changed here.

RED then GREEN, observed on the live tree, not assumed. All `__pycache__` and
`.pytest_cache` cleared first, because this repository has produced a false RED
from a stale cache. Before the entry, `-22` failed with exactly the message it
exists to produce: `AssertionError: status-asserting document(s) exist but are
not registered: ['epic-16-retro-2026-08-23.md']`, at
tests/test_status_document_registry.py:383. After the entry, `-22` passes. The
guard's own docstring documents this protocol and an unobserved transition would
be a vacuous claim.

Registered, not exempted. No `_EXCLUDED_BY_DESIGN` entry was added and not one
assertion in `-22` was weakened, reworded or exempted -- `AI-E16-15` names that
as the escape route to refuse, and `-22`'s written-reason rule exists precisely
to close it. `git diff --numstat` on the test module is +35/-0: purely additive.

The prose comment carries what the four previous retrospective registrations
carried, verified by execution rather than by assertion:
`_split_sentences()` returns 498 sentences, so `-21` is genuinely reading the
document rather than passing over an unparseable one; `_status_assertions()`
returns 0 -- no phrase in `_STATUS_CLAIMS` occurs in it at all, denied or
otherwise -- so `-21`'s per-document loop short-circuits and this registration
is inert rather than load-bearing; and `_executed_gate_citations()` returns 0,
so it mints an excuse for nothing. This is `AI-E12-1`'s second half on its FIFTH
consecutive retrospective, and the FIRST time the registration was not written
by the session that wrote the document; the comment records that break rather
than smoothing it over.

Wider gates re-run after the edit, on Windows, all green: full suite
`ARGUS_REQUIRE_LANGUAGE_GRAMMARS=1 pytest` 1,716 passed / exit 0 (240.9s) --
unchanged from the pre-existing baseline, with zero delta because `-21` and
`-22` are not parametrized, so a registry entry adds a document to an existing
test rather than a test node; `tests/test_status_document_registry.py` in full,
all nine `tests/test_gate_*.py` and `tests/test_module_size_ceiling.py` together
66 passed / exit 0; and `build_gate_decision.py`,
`build_adjudication_record.py`, `build_silent_class_record.py` each `--check`
exit 0. Local gates are Windows-only here; the ubuntu leg is not evidence this
commit can produce.

Staged by explicit path on a shared working tree. `git status --porcelain` was
checked before staging and showed only the three expected paths;
`sprint-status.yaml` is deliberately left for the next commit.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…ion items

The `bmad-retrospective` worker's own sprint-status write, committed separately
from the document because it is a separate concern: the previous commit lands
the record and the registry line that makes it legal, and this one is the
tracker catching up.

`epic-16-retrospective` moves `backlog -> done` and `last_updated` gains the
retrospective's entry. `epic-16` itself stays `in-progress` -- the epic roll-up
is the orchestrator's to make, not this session's, and it is deliberately not
made here. No other `development_status` value was touched.

The fifteen `AI-E16-*` action items are added to the action-item block exactly
as the retrospective wrote them, and three carried Epic-15 items move
`open -> in-progress` with the retrospective's own follow-through verdicts.
`AI-E16-15` -- the registration item this pair of commits discharges -- is left
`open` as the retrospective filed it; dispositioning it is an adjudication, and
this session was chartered to register the document, not to rule on its
contents.

Staged by explicit path on a shared working tree: `sprint-status.yaml` alone.
`git status --porcelain` was checked before staging and showed no other dirty
path, and `git log -1` was re-checked immediately before and after each of the
two commits -- HEAD was `23dcb7f` at the start and moved only by these two.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
`epic-16: in-progress -> done`. This is the orchestrator's roll-up, the one
write the `bmad-dev-loop` reserves to itself, and it is made only now that all
seven stories are `done` and `epic-16-retrospective` is `done` with its document
registered and `TC-ArgusAgent-DOCS-001-22` observed RED-then-GREEN (`f5cefbd`,
`1ba6c90`).

The value flips and one comment line is added above the key. Nothing else in
`development_status` moves: 109 keys before and after, none added or removed,
`yaml.safe_load` green, 0 CRLF, 0 lone CR, and all nine STATUS DEFINITIONS
occurrences intact.

The added note exists because a bare `done` would overstate the result. The
roll-up asserts that the STORIES are delivered and nothing more. Epic 16 did not
spend the round: 36 rows remain `UNADJUDICATED` at
`validation-corpus/silent-class-worklist.md`, the precision gate is still
`BLOCKED`, the External adjudicator tie-break is still UNFILLED, and
`DF-13-5-A`'s re-review trigger FIRED on 2026-08-23 against its own condition
-- 16.6 and 16.7 both `done`. An operator SPEND-OR-DECLINE decision is DUE and
is not closed by this commit.

Epic 16 is the last epic in `epics.md`. The retrospective recommends three
candidate charters for an Epic 17 and deliberately chooses none.

Staged by explicit path on a shared working tree: `sprint-status.yaml` alone.
`git status --porcelain` showed no other dirty path before staging.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…ing a date

`AI-E16-6: open -> done`. The re-review trigger fired on 2026-08-23 when 16.6
and 16.7 both reached `done`, and the epic-16 retrospective observed it without
taking a branch -- correctly, since it is an automated producer and this is an
operator act. This commit is that act.

BRANCH TAKEN: NEITHER. The round stays UNSPENT and the pre-registered rule of
2026-08-17 stands verbatim. `round_state`, `members_ratified` and
`protocol_edit` were re-read on disk and all three are unchanged. The ledger
entry STAYS OPEN; the action item closes because its own DoD asked for a dated
ruling plus a new bounded trigger, not for the round.

Two grounds, the second of which was not available in August. First, the
2026-08-22 reasoning was re-checked against Epic 16's result and still holds:
Epic 16 did not widen the aperture the deferral was about --
`eligible_member_count()` is still 5, the corroborable ceiling is still six,
fact (b)'s mock-bound-name clause still fires 0 times in 1,032, and the binding
`consumed == 0` whole-function scope is untouched at 676 vs 14. Story 16.6's
`raise AssertionError` fix is real, but it corrected 22 findings in the
OVER-flagging direction, which is precision, not aperture.

Second, branch (a) is not executable as written today. 16.2 measured sealed
intersect ratified as EMPTY, so R2 must ratify >=3 of the six sealed candidates
for `CLEARED` to be reachable; 16.4 measured that ratifying three drops the
candidate population 14 -> 11, beneath this entry's OWN 12-20 band. Executing
(a) would amend the pre-registered rule in the act of executing it, and the
entry closes by EXECUTION of that rule, never by re-opening it.

Branch (b) is NOT taken and NOT ruled out: its conditions are zero blocking
findings or precision below 80%, and neither has been observed because the
round has never run.

The replacement trigger is the change. It fires on the earlier of a merged
predicate change that raises the corroborable ceiling above six over the five
already-ratified members -- measured with the harnesses already under
`research/`, no member ratified, no round spent -- or 2026-11-22, the ORIGINAL
backstop carried unchanged and deliberately NOT re-dated. Re-dating it would
turn a bounded deferral into a rolling one. The bar in the first condition is
deliberately low because the trigger returns the entry to the operator to LOOK,
not to spend; this ruling sets no threshold for spending and schedules no work.

`deferred-work.md` +74/-0 as an append-only note under the entry, nothing above
it rewritten (section 3.4): 0 CRLF, lone CR 1 -> 1, trailing newline intact.
`sprint-status.yaml` changed two lines and added none: 1,152 LF before and
after, 109 `development_status` keys, 88 `action_items`, `yaml.safe_load` green,
the status-definitions legend byte-identical. Suite 1,716 passed / exit 0.

Still open and untouched by this: AI-E16-7's External adjudicator tie-break,
`DOCS-001-75` / `prd.md`, and the 36 UNADJUDICATED worklist rows. Nothing
published changes -- FR34's disclosure stands and the attested tier stays
blocked.

Staged by explicit path on a shared working tree; `git status --porcelain`
showed no other dirty path before staging.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…s proves it

An operator asked whether the zero yield is a badly-built detector or a defect
class that is simply rare. Measured: neither. `vacuous_test` flags on assertion
DENSITY and corroborates on mock PROVENANCE, and on the ratified corpus those
two populations are disjoint.

Over all 1,032 `vacuous_test_heuristic` findings at the five pinned shas: stage
1 selects density_only 1,025 (100%), mock_only 0, both 0 -- the mock arm has
never fired. Stage 2 promotes 0. `mock_referencing_assertions >= 1` holds in 0
of 1,032. 917 of 1,032 carry three or more CONSUMED SUT calls against a
whole-function `consumed == 0`.

"The corroborable ceiling is six" is a misreading and this commit stops it. Six
is W1 -- fact (b) with its mock clause deleted. The shipped predicate's output
is ZERO and always has been.

The obvious repair was measured and rejected. `_mock_bound_names` genuinely
cannot see @patch injection, fixture injection, or setUp's `self.attr` -- only
the bare local `fake = Mock()`, which is the shape of the project's own
corroborated fixture. An extended resolver covering all four idioms was run
over the same population with an INDEPENDENT instrument (CPython ast, not the
tree-sitter index): 1,025 of 1,032 flagged tests bind no mock at all, and the
count moves 0 -> 1. Filed as DF-INV-VACUOUS-B specifically so it is not
rediscovered later and mistaken for the remedy. Control: the corpus does mock
(23.2% / 22.9% / 11.5% of test files in three members) -- the FLAGGED population
does not.

The reading error underneath both DF-13-5-A branches is named: "0 blocking
findings" has been read as a fact about the world when it is a fact about the
instrument. No conclusion about the real-world base rate is available from this
evidence.

This is NOT the first document to reach the blindness finding. The 2026-08-21
detector-categories research got there three days earlier and is credited as the
primary source. This corrects one half of its §6 table -- the row it marks
verdict-eligible is also empty, 0 of 1,032 -- which re-weights its own
recommendation: of Story 6.2's two halves the provenance half is worth
approximately nothing here and the assertion-strength half is worth everything.

DF-13-5-A carries a same-day append-only note sharpening condition 1 of the
trigger written earlier today. The metric was W1-shaped ("ceiling above six"),
defined in terms of the very predicate the trigger waits for the replacement of;
it now reads "shipped promotions above zero", predicate-agnostic. Condition 2
(2026-11-22) is untouched and still not re-dated, the 2026-08-17 rule stands
verbatim, and the entry STAYS OPEN and UNSPENT. The substance is unchanged and
better supported: a larger bench samples more repositories through an aperture
that is structurally shut.

Nothing is loosened, promoted, ratified or spent. `consumed == 0` stays as it
is -- it is what keeps the moat closed. Neither V2 (36) nor V5 (125) is proposed
for promotion; DF-16-7-B's rule that a different predicate must be argued as one
applies to both.

Filed: DF-INV-VACUOUS-A, DF-INV-VACUOUS-B under a new `DF-INV-*` origin kind,
following the DF-AUD-APAA-* precedent for a finding no story produced, with the
reason for the new prefix written into the section heading.

deferred-work.md +135/-0, pure append plus one append-only note under an
existing entry, nothing above either rewritten (section 3.4): 0 CRLF, lone CR
1 -> 1, trailing newline intact. Research doc and its three harnesses are new
files; the harnesses use dash names so pytest cannot collect them (verified: "no
tests collected"). Doc registry unaffected -- `-22`'s globs are
`sprint-change-proposal-*.md` and `epic-*-retro-*.md` at the artifact root, and
research/ matches neither. Suite 1,716 passed / exit 0.

Staged by explicit path on a shared working tree; `git status --porcelain`
showed no other dirty path before staging.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…d 6.2 stops being a container

`bmad-correct-course`, operator-directed, no story. The epic-16 roll-up closed
`epics.md` at Epic 16 with no Epic 17; both outstanding operator obligations are
now taken, so the plan gets its next container.

EPIC 17 -- Say What The Assertion Constrains. CAPABILITY: the vacuous-test
detector grades what a test's assertions actually constrain about the value the
code under test returned, replacing a mock-provenance signal that cannot fire.
Five stories, ordered so that 17.1 pre-registers the precision criterion BEFORE
any successor predicate exists -- yield and precision move in opposite
directions, and a criterion written once a number is in view is not a criterion.
A git-ancestry guard in 17.4 enforces it. `consumed == 0` is NOT loosened; the
epic REPLACES the signal rather than widening fact (b) by clause removal, and
17.2 is the argument `DF-16-7-B` requires.

EPIC 18 -- The Secret Detector Reports What It Finds. Four stories discharging
the 2026-08-24 detector audit. SEQUENCED BEFORE EPIC 17 despite the higher
number: epic numbers are creation order here and execution order is stated.
`DF-AUD-DETECT-A` is a live security false negative -- through the shipped
`SecretScanDetector.run()`, `postgres://admin:Tr0ub4dor3@localhost:5432/prod`
returns 0 findings while the same value with the sentinel substring removed
returns 1. Nothing in Epic 17 depends on Epic 18; the ordering is urgency, not
coupling.

A SECOND ISSUE FOUND WHILE ASSESSING IMPACT, and it changes what the project
believed was scheduled. `Story 6.2` is `done`, and it never contained the work
four shipped modules and six open ledger entries say it owns -- its story file
carves out dataflow explicitly and it was scoped to claim-grounding for non-test
Python files. So the 2026-08-21 research's recommendation to "complete Story 6.2
... already scheduled" rests on a stale forward reference: the assertion-strength
work has no container at all. Story 17.5 re-homes those references forward and
adds a guard asserting no ledger entry's `target_story` names a story whose
sprint-status key is `done`. `DF-1-7-B` is untouched -- it is CLOSED and
correctly names 6.2 as its closer. Epics 1-16 are NOT reopened.

`DF-AUD-DETECT-D` rides on 17.3 -- its own entry asked to, saying it rides with
whatever story next reworks `provenance_scan` -- and collapsing the duplicate
statement-boundary derivation BEFORE layering assertion-grading on it is cheaper
than after. `-C` is named as context, not a story, and stays OPEN.

Registered as the last four proposals were: `-22` observed RED against this
document (`unregistered: ['sprint-change-proposal-2026-08-24.md']`) and GREEN
after, on the live tree, in the same commit as the document. Verified before
registering: `_split_sentences()` 133, `_status_assertions()` 0,
`_executed_gate_citations()` 0, so the registration is inert. No
`_EXCLUDED_BY_DESIGN` entry added and no assertion weakened.

NOTHING IS SPENT. `DF-13-5-A` stays OPEN and UNSPENT, no member ratified, no
third-party source fetched, no protocol re-version, no FR amended, the >=80%
gate unchanged and still NOT CLEARED, FR34's disclosed tier unchanged.

`epics.md` +309 lines, every line still CRLF, 0 lone CR. It adds NO FR Coverage
Map row and says why: the map answers which epic DELIVERS an FR, and these two
REPAIR delivered ones. Recorded there as an observation: the map, the
Requirements Inventory and the Final Validation Summary all stop at Epic 13 --
Epics 14-16 never updated them -- and that drift is NOT fixed here because it
predates this proposal.

`sprint-status.yaml` 109 -> 122 keys, thirteen at `backlog`, no existing value
changed and none removed; `yaml.safe_load` green, 0 CRLF, 0 lone CR, the
status-definitions legend byte-identical, 88 action_items unchanged. Both
`epic-*-retrospective` keys created in the same act (`AI-E15-9`, second
application, still no guard) -- `epic-18-retrospective` was missed on the first
write and caught by a count assertion, which is the omission that action item
exists to prevent.

Suite 1,716 passed / exit 0. One unrelated red was diagnosed and cleared first:
`TC-ArgusAgent-DOCS-001-54` measured a 127-entry wheel against README's 103,
the difference being 24 untracked, gitignored files under `argus/verdict/.argus/`
-- the tool's own runtime output, written into the source tree by running the
research harnesses and then PACKAGED BY THE WHEEL BUILD. Removed, suite green.
The underlying defect is real and unfiled: the wheel includes gitignored paths,
so running Argus inside its own repo reddens that guard, and CI never sees it
because a fresh checkout has no `.argus/` directory.

DEFERRED WITH A NAMED OWNER, not a silence: the `deferred-work.md` re-homing of
the six entries pointing at the done Story 6.2, plus scheduling notes for
`DF-AUD-DETECT-A..F`, is owed by Story 17.5. That file currently holds a
concurrent session's UNCOMMITTED audit entries, and staging it by path would
have swept their unfinished work into this commit.

Staged by explicit path on a shared working tree; `deferred-work.md` deliberately
left out and unstaged.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
XAgentsLabs007 and others added 5 commits August 24, 2026 08:41
… that prose could flip

APPROVED 2026-08-24 by XAgent007. Both epic sections keep their "awaiting
approval" paragraphs exactly as written, with append-only approval notes beneath
them (section 3.4, Epic 16 precedent). Approval unblocks story creation and
nothing else: the epics stay `backlog`, DF-13-5-A stays OPEN and UNSPENT, and
17.1's binding ordering constraint is not relaxed.

This also carries the 235 lines of detector-suite audit that were sitting
uncommitted in the working tree, written by an earlier session. Reviewed before
committing rather than passed through: the section is purely additive, files six
entries, and declines to file three more with written reasons (already owned /
subsumed / REFUTED), which is the discipline this ledger is supposed to have.

DF-AUD-DETECT-A was re-verified BY EXECUTION before being scheduled, because a
security claim that decides an epic ordering should not be taken on trust.
Through the shipped `SecretScanDetector.run()`: the localhost line returns 0
findings, the example.com line 0, and the control -- same value, sentinel
substring removed -- returns 1. All three match the entry. Against the source,
`is_public_sentinel` (:116) tests `sentinel in snippet_clean`, it is consulted at
step 2 above the Live-Key Safeguard at step 3, and `is_live_production_key`
(:125) carries the same short-circuit so the safeguard disables itself on the
same string. The entry is sound and its citations resolve.

THE DEFERRAL FROM b85e597 IS DISCHARGED. Six entries that pointed at Story 6.2 --
`done`, retrospective signed, and never holding that scope -- are re-homed to
Epic 17. DF-AUD-DETECT-A/B/E/F are scheduled to Epic 18, -D to Story 17.3 because
its own entry asked to ride with whatever story next reworks `provenance_scan`,
and -C is named as context only and stays OPEN. DF-1-7-B is untouched: it is the
one reference to 6.2 in this ledger that is true.

TWO NEW ENTRIES, both found by this session rather than looked for.

DF-INV-WHEEL-A: the wheel packages gitignored runtime output. A freshly built
wheel measured 127 entries against README's 103, the difference being 24
untracked `argus/verdict/.argus/` files, so running Argus inside its own repo
reddens TC-ArgusAgent-DOCS-001-54. A plain pytest run does NOT reproduce it --
verified after clearing -- so the polluter is running the tool. CI cannot see it
because a fresh checkout has no `.argus/`, which means the green CI record is
evidence CI never runs the tool in its own tree, not evidence the packaging is
clean. It is the mirror of AI-E16-5: that guard under-reaches the filesystem
because its population is `git ls-files`; this build over-reaches it.

DF-INV-LEDGER-A: `ledger_closed_ids` recognises two closure forms and this ledger
writes three. The `- **CLOSED ... by story ...**` form carries the verb but no id
on the line and is not `- status:`-shaped, so 7 real dispositions are invisible --
DF-1-3-A, DF-2-3-B, DF-1-7-B, DF-8-1-A, DF-AUD-APAA-C, DF-AUD-APAA-D, DF-14-3-H.
Five of them sit in `_UNBACKED_AT_LANDING`, accounting for 9 of its 17 rows: the
guard's headline governance backlog is 53% extraction artifact.

HOW THAT WAS FOUND IS THE FINDING. A prose sentence here originally read
"..., closing `DF-1-7-B`" -- verb and id on one line -- and DOCS-001-78's shrink
assertion went RED demanding three registry rows be deleted. The sentence was
REWORDED and NOT ONE ROW WAS REMOVED: making a guard green by editing prose is
AI-E12-3's defect committed inside the guard written to stop it, and the comment
above the registry names that move as considered and rejected. The blind spot
was then tripped twice more in the same sitting -- by the paragraph describing it
(35 -> 39) and by the title of the entry filing it (36) -- which is why the fix
belongs in the extractor and the registry must only shrink afterwards. Verified
before committing: `ledger_closed_ids` over the working copy returns exactly the
committed set, 35 ids, added none and removed none. This commit's documentation
moves no guard's verdict.

epics.md +21/-0, every line still CRLF, 0 lone CR. deferred-work.md +413/-0, a
pure append plus three reworded lines of my own text, nothing above rewritten:
0 CRLF, lone CR 1 -> 1, trailing newline intact. One process note worth keeping:
an early edit of that file used text mode, whose universal-newline translation
silently converted the lone CR to LF; it was detected by the invariant check and
restored in binary. That file must be edited in binary mode.
sprint-status.yaml one line changed, none added: 122 keys, 109 done, 13 backlog,
88 action_items, yaml.safe_load green, legend byte-identical.

Suite 1,716 passed / exit 0.

Staged by explicit path.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
An audit of this session's own four commits found a causal claim asserted
without isolation. DF-INV-WHEEL-A stated "the polluter is running Argus itself
(or a research harness that calls it), which is what that session did five
times." That was an inference written as a finding.

FALSIFIED by execution. All five harnesses under research/ were run
individually against a clean tree with argus/verdict/.argus/ checked after each
-- revalidate-fact-b-widening, measure-flag-rate-inversion,
investigate-per-call-scoping, measure-heuristic-arms, measure-mock-binding-idioms
-- and none reproduce the write. Neither does a full pytest run. The candidate
set the entry named is eliminated and no replacement has been demonstrated.

The DEFECT is untouched and still reproducible: with the directory present a
freshly built wheel measures 127 entries against README's 103, and removing it
returns 103. The build packages untracked, gitignored paths. What is not
established is which process writes them.

Recorded as an append-only correction, the entry above it not rewritten
(section 3.4), because the entry was wrong in a way that would have sent the
fixing story after the wrong thing. The packaging fix does not depend on knowing
the trigger and should not wait for it.

Verified the correction moves no guard: ledger_closed_ids over the working copy
returns exactly the committed set, 35 ids, none added and none removed --
the check DF-INV-LEDGER-A exists to make routine. Suite 1,716 passed / exit 0.
deferred-work.md pure append, 0 CRLF, lone CR 1 -> 1, trailing newline intact.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
An operator-directed audit of the 2026-08-24 commits asked whether they are
consistent and complete against the project objective and production readiness.
Method was resolution and execution, not reading: every id, FR and path in the
new documents resolved against the artifact that owns it (0 unresolved), every
headline figure was re-derived by re-running the harnesses, and every guard
verdict was diffed against the committed baseline.

The prose held. Two entries record what sat outside it.

DF-INV-REFS-A: 124 declared entries against 143 distinct ids referenced, and six
do not resolve -- after excluding three correct by construction and one the
record already declares. DF-8-4-D is cited in 17 files including
architecture.md; DF-8-4-C in 11. DF-1-7-A, DF-2-3-A and DF-3-1-A all first
appear at 084c6a7, the separation seed commit -- Epic 10's subject class, found
again by a different instrument, and recorded rather than re-opening a signed
epic. DF-22-15-A is not an Argus id at all: it names "story 22-15", this plan
ends at Epic 18, and it is quoted from shipped argus/audit/deep_audit.py, so a
reader of that module cannot reach the record justifying its EXPERIMENTAL mark.

DF-INV-DELIVERY-A, and it is the most severe thing the audit found. 31 commits
ahead of origin/master, 2 behind, and `git branch -r --contains HEAD` is empty:
this branch has never been pushed. audit-ci.yml runs ubuntu-latest and its
matrix varies Python versions, not the OS, so every gate this project owns is
green on a Windows working copy no other machine has seen. AI-E16-3 already asks
for a second OS leg or a dated decision saying why not; that item is now
load-bearing rather than tidy.

Four files are touched on both sides -- deferred-work.md, sprint-status.yaml,
docs/first-run.md, tests/test_release_surface_honesty.py -- and git merge-tree
reports conflicts. Every commit today appended to deferred-work.md, so the
conflict grows with each further session on this branch.

DF-15-2-D now carries two independent dispositions written by sessions that
could not see each other: this branch cites 4123931 + ba5e8df, origin/master's
797bba8 cites 4123931. Both append-only, both dated, both honest, and
duplicates. That is the AI-E12-6 class arriving by a route no guard here
watches -- not a disposition in prose instead of the ledger, but the same one in
the ledger twice, on two branches. Reconciling it is a judgement and must not be
automated: taking one side of a conflict hunk destroys evidence, which is the
one thing this ledger forbids everywhere else.

Wording constraint observed deliberately throughout: no line carries a closure
verb beside a DF id, because that is the DF-INV-LEDGER-A defect and it tripped
three times while that entry was being written. Verified: ledger_closed_ids over
the working copy returns exactly the committed set, 35 ids, none added or
removed.

deferred-work.md +100/-0, pure append, 0 CRLF, lone CR 1 -> 1, trailing newline
intact. Suite 1,716 passed / exit 0.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…NV-DELIVERY-A

Trying to act on a finding is the cheapest way to test it. The push this entry
asked for produced the evidence the audit should have gathered before writing
it, and three of its claims do not survive.

WITHDRAWN (1) "this branch has never been pushed." The push reported
52143eb..937addc -- the remote branch already existed, at 52143eb, since
2026-08-22, via PR #4, which is MERGED. `git branch -r --contains HEAD` returns
empty whenever the remote branch is merely BEHIND local; the audit read absence
of containment as absence of a branch. The true figure was 32 unpushed commits.

WITHDRAWN (2), and this is the one that mattered. The entry claimed DF-15-2-D
carries two independent dispositions written by sessions that could not see each
other, and filed it as the AI-E12-6 class. It is one disposition, authored once.
`git patch-id --stable` returns 01d436875d6fc9635774211142d8060d990895fa for
BOTH 52143eb and 797bba8 -- the identical patch under two shas, because PR #4
was merged with a sha-rewriting strategy. `git cherry origin/master HEAD` shows
2 equivalent-upstream, 31 new. There is no governance defect here and there
never was. The forecast conflict is a textual duplicate of one record,
resolvable by keeping a single copy, not the evidence-destroying judgement the
entry warned about.

WITHDRAWN IN PART (3) "CI cannot have seen any of it." CI did run green on
52143eb, both workflows, 2026-08-22. But the corrected version is worse:
audit-ci.yml triggers on push to master/main and pull_request TARGETING
master/main, so a push to a feature branch triggers nothing -- verified, the
2026-08-24 push produced no new run.

WHAT SURVIVES. 31 commits are not on master and have never executed on POSIX.
Pushing them did not change that and cannot: the only route to CI is an open
pull request against master. The local suite stays Windows-only and AI-E16-3 is
still load-bearing. Severity stays at that ground alone.

THE METHOD FAILURE IS THE LESSON, and it is the second this session.
DF-INV-WHEEL-A asserted a cause without isolating it; this entry read one
ambiguous git command as dispositive and reached for AI-E12-6 when `git
patch-id` would have refuted it in seconds. Both errors ran the same direction,
toward a more serious finding than the evidence carried. An audit that only
revises upward in severity is not measuring.

Append-only, nothing above rewritten (3.4). +44/-0, 0 CRLF, lone CR 1 -> 1,
trailing newline intact. ledger_closed_ids unchanged at 35, none added or
removed. Suite 1,716 passed / exit 0.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…ours

Brings master's two commits into this branch so a PR against master is
mergeable and CI can run. `git diff HEAD` after resolution is EMPTY: the merged
tree is byte-identical to this branch's, because master has nothing we lack.
797bba8 is the patch-equivalent of our 52143eb (same patch-id,
01d436875d6fc9635774211142d8060d990895fa, PR #4 merged with sha rewriting), and
ad3d35e's content is already present here.

Two conflicts, both resolved by taking ours, and both verified rather than
assumed before doing so. deferred-work.md: our side carries Story 16.5's
machine-readable status field for DF-15-2-D, master's side of the hunk is empty.
sprint-status.yaml: master had 16-5/16-6/16-7 and epic-16-retrospective at
`backlog` from 2026-08-22; this branch has them done plus the thirteen Epic
17/18 keys.

Evidence containment was checked in both directions before resolving, because
taking a side of a conflict hunk is how a ledger silently loses a record:
zero master lines of deferred-work.md are absent from ours (master 5,576 lines,
ours 6,819), and zero master comment fragments in sprint-status.yaml are absent
from ours. Our branch is a strict superset of master for both files, so nothing
is dropped by the resolution.

Post-merge invariants: deferred-work.md LF 6,818, 0 CRLF, lone CR 1, trailing
newline intact. sprint-status.yaml parses, 122 development_status keys, 109
done, 13 backlog, 88 action_items.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@github-actions

github-actions Bot commented Aug 24, 2026

Copy link
Copy Markdown

🛡️ ArgusAgent Code Quality & Assurance Report

Hello! ArgusAgent has audited your commit (0df37f9).

ArgusAgent coverage ledger (schema 1)

file_path depth claim_present recording_ids
_bmad-output/design-artifacts/ArgusAgent/research/investigate-per-call-scoping.py audited_deep true []
_bmad-output/design-artifacts/ArgusAgent/research/measure-flag-rate-inversion.py audited_deep true []
_bmad-output/design-artifacts/ArgusAgent/research/measure-heuristic-arms.py audited_deep true []
_bmad-output/design-artifacts/ArgusAgent/research/measure-mock-binding-idioms.py audited_deep true []
_bmad-output/design-artifacts/ArgusAgent/research/measure-vacuous-population-split.py audited_deep true []
_bmad-output/design-artifacts/ArgusAgent/research/revalidate-fact-b-widening.py audited_deep true []
_bmad/scripts/memlog.py audited_deep true []
_bmad/scripts/resolve_config.py audited_deep true []
_bmad/scripts/resolve_customization.py audited_deep true []
_bmad/scripts/sync_skills.py audited_deep true []
argus/init.py audited_shallow false []
argus/assets/init.py audited_shallow false []
argus/assets/commands/init.py audited_shallow false []
argus/audit/init.py audited_shallow false []
argus/audit/deep_audit.py audited_deep true []
argus/audit/deep_pass.py audited_deep true []
argus/audit/grounding.py audited_deep true []
argus/audit/minions_llm_adapter.py audited_deep true []
argus/audit/open_llm_adapter.py audited_deep true []
argus/audit/ports.py audited_deep true []
argus/cache/init.py audited_shallow false []
argus/cache/invalidation.py audited_deep true []
argus/cache/key.py audited_deep true []
argus/cache/memo_store.py audited_deep true []
argus/cache/stage_memo.py audited_deep true []
argus/cli.py audited_deep true []
argus/commands/init.py audited_shallow false []
argus/commands/hosts.py audited_deep true []
argus/commands/installer.py audited_deep true []
argus/cost/init.py audited_shallow false []
argus/cost/budget_governor.py audited_deep true []
argus/cost/exhaustion.py audited_deep true []
argus/cost/resume.py audited_deep true []
argus/detectors/init.py audited_shallow false []
argus/detectors/base.py audited_deep true []
argus/detectors/orphan_code.py audited_deep true []
argus/detectors/provenance_scan.py audited_deep true []
argus/detectors/secret_scan.py audited_deep true []
argus/detectors/secret_suppression.py audited_deep true []
argus/detectors/tool_runner.py audited_deep true []
argus/detectors/vacuous_test.py audited_deep true []
argus/detectors/vacuous_vocabulary.py audited_deep true []
argus/dogfood/init.py audited_shallow false []
argus

💡 Student Tip: Make sure you have no bare tests or committed API keys in your repository before submitting!

XAgentsLabs007 and others added 2 commits August 24, 2026 13:07
… Linux

The actionable half is discharged. PR #5 against master is the only trigger
audit-ci.yml offers, and the 35 commits executed on Linux for the first time:
Quality Gates pass on Python 3.10, 3.11 and 3.12, plus the security audit.
origin/master merged in as ancestry only, branch 0 behind / 35 ahead, MERGEABLE.

No POSIX defect surfaced, reported rather than quietly enjoyed. That does not
retire AI-E16-3: the risk it names is finding a divergence after a long run of
unexercised commits instead of at the one that caused it, and 35 commits went
unexercised. The exposure was real; it just did not cash in.

Still open: the work is not on master — PR #5 is open, not merged, and merging
is an operator act. DF-INV-REFS-A is untouched.

Append-only, +14/-0, 0 CRLF, lone CR 1 -> 1. ledger_closed_ids unchanged at 35.
Suite 1,716 passed / exit 0.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
… day before

Found while resolving the merge conflict, which is the only reason it surfaced:
the prior record sits in a region of deferred-work.md the audit never read.

PRIOR ART. DF-16-6-D, filed 2026-08-23 -- "authors keep putting a disposition
verb and an OPEN ledger id on the SAME PHYSICAL line" -- already carries the
authoring defect, the ledger_closed_ids false positive from historical prose,
and the verification method by HEAD-blob-versus-working-tree symmetric
difference that DF-INV-LEDGER-A reported as its own. It also already carries the
observation that the last four instances were written by authors who knew the
guard existed and had read its docstring: knowing about it does not prevent it.

And it had already counted them. DF-16-6-D records eight -- four by Stories 12.4
and 12.5, four more inside Epic 16 alone on 2026-08-23. So this entry's "three
independent accidents in one sitting" are instances nine, ten and eleven of a
counted series, not a new phenomenon. Story 16.5 is the other prior record, at
ledger lines 5437-5458.

THE PRESCRIPTION IS CONTESTED AND THE PRIOR POSITION WINS ON PROCEDURE.
DF-INV-LEDGER-A says the fix is the extractor. DF-16-6-D says the extractor is
correct and essentially unimprovable and the record is what is wrong every
single time; Story 16.5 says never a widened analyzer. A later entry does not
overturn an earlier one by not having read it, so the reconciliation is
deliberate work and DF-16-6-D is the senior record.

DF-16-6-D also carries an ordering hazard this entry did not know about:
repairing the analyzer unmasks a surviving instance and turns the full suite RED,
so the record must be wrapped first and the analyzer repaired only after.
Anyone acting on DF-INV-LEDGER-A alone would have hit that ambush.

WHAT SURVIVES AS NEW, narrowly. The prior records describe the false-positive
direction. This entry measured the opposite one -- a real bullet disposition the
analyzer cannot see because its line carries no id -- and quantified the blast
radius: seven such records invisible against thirty-five visible, and nine of
_UNBACKED_AT_LANDING's seventeen rows false positives in consequence. The
diagnosis is not new; the measurement is.

THE PROCESS LESSON, third of this session. The audit searched the code for the
defect and never searched the ledger for prior art on it, in a repository whose
ledger is the primary record and which had filed the class the previous day. Two
of this session's three self-corrections would have been prevented by one grep
of this file before filing.

Checked that this note is not instance twelve: ledger_closed_ids over the
working copy returns exactly the committed set, 35 ids, none added or removed.
Append-only, +52/-0, 0 CRLF, lone CR 1 -> 1. Suite 1,716 passed / exit 0.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@Inan15
Inan15 merged commit 932cec9 into master Aug 24, 2026
4 checks passed
Inan15 pushed a commit that referenced this pull request Aug 24, 2026
… Linux

The actionable half is discharged. PR #5 against master is the only trigger
audit-ci.yml offers, and the 35 commits executed on Linux for the first time:
Quality Gates pass on Python 3.10, 3.11 and 3.12, plus the security audit.
origin/master merged in as ancestry only, branch 0 behind / 35 ahead, MERGEABLE.

No POSIX defect surfaced, reported rather than quietly enjoyed. That does not
retire AI-E16-3: the risk it names is finding a divergence after a long run of
unexercised commits instead of at the one that caused it, and 35 commits went
unexercised. The exposure was real; it just did not cash in.

Still open: the work is not on master — PR #5 is open, not merged, and merging
is an operator act. DF-INV-REFS-A is untouched.

Append-only, +14/-0, 0 CRLF, lone CR 1 -> 1. ledger_closed_ids unchanged at 35.
Suite 1,716 passed / exit 0.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@Inan15
Inan15 deleted the epic-16/discharge-df-15-2-d branch August 24, 2026 12:29
Inan15 pushed a commit that referenced this pull request Aug 24, 2026
…old sha

master went RED on TC-ArgusAgent-DOGFOOD-001-49 immediately after PR #5 merged.
The three dogfood artifacts cited 7fec3cd --
a real commit, and an ancestor of the feature branch, but NOT of master. PR #5
was merged with a sha-rewriting strategy, so the tree those artifacts describe
is no longer on this line of development. That is precisely what the guard says
it exists to catch: "it is on an abandoned or rebased history."

Remedied exactly as the failure message prescribes, and by no other means:
`python scripts/regenerate_dogfood_artifacts.py`, which re-renders each artifact
through its OWN renderer -- render_partition_plan_markdown,
render_budget_plan_markdown, render_proof_markdown -- and writes the returned
string verbatim, then re-reads and asserts equality. No artifact was hand-edited
(operator ruling 2026-08-12) and no assertion was loosened or deleted
(DF-8-5-B: "do not close it by loosening an assertion").

The delta is one line per artifact and nothing else: the commit descriptor moves
7fec3cd -> 932cec9, the current master HEAD. Enumeration is unchanged at 95
tracked source files and 33,578 LOC, so the tree being described did not move --
only the name it is cited under. argus/ was clean, which is the precondition the
script refuses to run without.

Note for whoever picks the merge strategy next time: this failure is a
CONSEQUENCE of squash/rebase merging, not of the work in PR #5. The same tree
passed all four checks on the PR, because there 7fec3cd was still an ancestor.
Any future PR carrying regenerated dogfood artifacts will red master the same
way unless it is merged with a strategy that preserves shas, or is followed by
this regeneration.

Suite 1,716 passed / exit 0.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Inan15 pushed a commit that referenced this pull request Aug 24, 2026
…FOOD-001-49

master went RED the moment PR #5 landed, and PR #6 repaired it the same day.
This entry records why, and the decision taken.

THE MECHANISM. TC-ArgusAgent-DOGFOOD-001-49 requires each dogfood artifact to
cite a provenance sha that is an ancestor of HEAD. A merge commit keeps the
branch's commits as ancestors; squash and rebase rewrite them, orphaning the
citation the instant it lands.

IT IS INVISIBLE UNTIL TOO LATE, which is why the remedy is a setting and not a
habit. The identical tree passed all four checks on PR #5, and passes locally,
because there the sha is still an ancestor. Only the push to master can observe
it.

The history shows when practice changed and it was not announced: PRs #2 and #3
landed as merge commits with master green; #4, #5 and #6 landed sha-rewritten.
PR #4 is also why a 2026-08-24 audit finding had to be withdrawn -- its rewrite
made 52143eb and 797bba8, one patch under two shas, look like two independent
dispositions. The same change cost a false finding and a red master in two days.

THE EXCEPTION THAT MAKES THE RULE PRECISE. PR #6 was also sha-rewritten and did
NOT red master, because its regeneration cited 932cec9 -- master's own HEAD --
which survives any rewrite of the branch. So the hazard is narrower than
"sha-rewriting is unsafe": it is an artifact regenerated on a branch citing a
branch sha. That is also the normal case, because regeneration happens where the
work happens.

DECISION by XAgent007: restrict the repository to merge commits, disable squash
and rebase, enable head-branch deletion. Linear history is lost and that cost is
stated rather than hidden; it is accepted because this repository's guards rest
on sha ancestry of artifact provenance, and of the two, provenance carries the
assurance argument. It restores the practice of #2 and #3 rather than inventing
one.

STATUS: DECIDED, NOT YET APPLIED, and the entry stays OPEN until it is. The API
call returned 404, which GitHub returns for a settings update when the caller
lacks admin; push, PR and merge all work, so it is an admin-scope gap. The
manual remedy is recorded in the entry.

The rejected alternative is recorded so it is not re-proposed as new: a master
CI job that regenerates and fails on a dirty tree converts a preventable class
into a detected-after-the-fact one, and master still reds first. Loosening -49 is
not available at all (DF-8-5-B).

Append-only, +61/-0, 0 CRLF, lone CR 1 -> 1. ledger_closed_ids unchanged at 35.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants