Skip to content

Gate-2 amendment proposal 2: explicit tranche structure (review #106 finding 4) - #111

Merged
MaxGhenis merged 2 commits into
masterfrom
gate2-amendment2-proposal
Jul 10, 2026
Merged

Gate-2 amendment proposal 2: explicit tranche structure (review #106 finding 4)#111
MaxGhenis merged 2 commits into
masterfrom
gate2-amendment2-proposal

Conversation

@MaxGhenis

Copy link
Copy Markdown
Contributor

Gate-2 amendment proposal 2: explicit tranche structure

A public amendment PROPOSAL for gate 2, mirroring the amendment-1 ceremony (PR #96 is the template). It is an inert object: gates.yaml gate_2 stays locked: true, status: locked, and the entire thresholds subtree is byte-identical to origin/master (the change is a pure insertion of the gate_2.amendment_proposed sibling; tests parsed-compare the subtree AND the derived cell sets). No model reads it; the harness scores only the locked block. Nothing is ratified — this is the object a referee round adjudicates.

Resolves the blocker in external architecture review #106, finding 4: the locked gate_2 description names "household-composition transitions" and holdout_basis includes MX23REL, while the locked scope_note says that MX23REL household tranche is not scored and marriage×earnings is uncovered. Before any pass that latent over-claim was inert; the fresh gate-2 PASS (candidate 16, #109) makes it load-bearing — a reader could over-read "gate 2 passes" as household / auxiliary-benefit readiness.

The change (structural — zero threshold movement)

Re-scope the locked block as tranche 2a_marital_fertility — exactly the 46 gated + 16 report-only cells as locked, every tolerance / derivation / protocol byte-identical — and declare two separate UNLOCKED tranches with their own future lock ceremonies:

  • 2b_relationship_household — the MX23REL relationship-matrix / household-composition transitions (who lives with whom). No floor, no gate, no scored run.
  • 2c_marriage_earnings_joint — the marriage×earnings joint (who marries whom), on which spousal/survivor benefit LEVELS depend. No floor, no gate.

Plus a certification_scope map (below) stating which reform-provision classes each tranche's pass supports, and a language_rescope change so tranche 2a's description/holdout_basis claim only mh85_23 + cah85_23 (+ ind2023er deaths), never MX23REL.

Zero-threshold-movement statement

This amendment moves NO number. Unlike amendment 1 (a per-cell estimator recalibration), amendment 2 is purely structural. gate_2.thresholds parses identical to origin/master; the 46 gated + 16 report-only cell sets are byte-identical to origin/master; gate_2 differs from master by the single added amendment_proposed key. No tolerance, no verdict, no scored cell moves. Verdict-preservation: candidate 16's PASS (4/5) and candidates 1–15's FAILs are the verdicts of tranche 2a as-run under the locked block — no verdict changes, no re-scoring. There is no goalpost-timing question because no goalpost moves; the only change is that the certification claim becomes explicit about which tranche the pass covers (2a) and which it does not (2b, 2c).

certification_scope (derived from the locked scope_note + the #74 provision matrix)

Locked provision class Locked coverage Requires tranche(s)
marital_and_survivor_timing COVERED (gated) 2a — survivor/spousal eligibility TIMING on real or generated marital histories
caregiver_and_child_in_care_survivor NOT COVERED HERE 2a + 2b — caregiver-credit eligibility rides on 2a's fertility process; the child-in-care survivor component + household-level rows need 2b (MX23REL)
marriage_x_earnings_joint NOT COVERED 2c — spousal/survivor benefit LEVELS depend on who-marries-whom

Per-tranche: 2a supports survivor/spousal incidence on real or generated marital histories and caregiver-credit (fertility-history) eligibility; 2b is required for household-unit poverty statistics and child-in-care survivor components; 2c is required for joint earnings×marital processes in generated panels. Each row's locked_coverage is the leading token of the locked provision_class_coverage entry, and the map is machine-bound to cover exactly the three classes named in the locked scope_note (#74: MS = marriage/survivorship Phase C "gate 2 proper"; FC = fertility/caregiving Phase D "caregiver credits"; "(✓)" = poverty/household rows only).

Considered and rejected

  • Leave the scope in prose — rejected: the pass invites the over-reading the review flags; a caveat three levels down in scope_note does not travel with the headline PASS.
  • Unlock 2b now — rejected: no floor, no pre-registered gate, no ceremony for MX23REL household composition; unlocking it would manufacture the false certification External architecture review (Codex gpt-5.6-sol): 10 findings + pre-CPS refactor plan #106 warns against.
  • Rename gate_2gate_2a repo-wide — rejected: churn on 16 frozen run artifacts + the frozen test suite for no gain; the tranche id lives INSIDE gate_2 (thresholds.tranche_id + the 2a/2b/2c declarations).

Tests

A dormant-safe gate-2 amendment-2 block in tests/test_gates_derivations.py (guarded on proposal_number == 2, mirroring gate 1's proposal-2 tests): the three tranches are declared (2a locked; 2b, 2c unlocked); tranche 2a's 46-gated / 16-report-only cell sets are byte-identical to origin/master and to the committed floor's gate_partition; gate_2.thresholds parses identical to origin/master with amendment_proposed the only added key; the certification_scope map covers every locked provision class; candidate 16 PASS + candidates 1–15 FAIL stand; the flip edits cite text present in the locked block. All skip until a proposal-2 object exists — so they stay dormant under amendment 1 and after this proposal is itself ratified and consumed. The gate-2 ratified-history invariant is relaxed to permit a strictly-later proposal (≥ 2) while still forbidding re-presentation of the consumed amendment 1.

Ceremony next steps

Adversarial referee round on this proposal → fixes if any → verification → maintainer ratification by merge → a follow-up flip PR that moves the tranche names, the re-scoped description/holdout_basis, and the certification_scope map into the locked block and adds the 2b/2c unlocked sibling stubs (as PR #96 flipped amendment 1). Do not merge this PR as a ratification.

Evidence chain: review #106 finding 4; the locked scope_note (gate_2.thresholds.scope); the #74 provision matrix; the candidate 1–16 ladder (runs/gate2_hazard_v1..v16.json, registered on #42) and the pass PR #109.

🤖 Generated with Claude Code

…finding 4)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@vercel

vercel Bot commented Jul 9, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
social-security-model Ready Ready Preview, Comment Jul 9, 2026 11:55pm

Request Review

@MaxGhenis

Copy link
Copy Markdown
Contributor Author

Verdict: AMEND BEFORE RATIFYING.

Adversarial round on the gate-2 amendment-2 proposal object (head b37cb5b), against the standard set by the gate-1 rounds (PR #57 / #67) and gate-2 amendment 1 (PR #96 comments 4915412987 / 4916419901). I re-verified in a detached read-only worktree, recomputing every load-bearing claim from the committed artifacts and the git record rather than trusting the PR text or the tests, and perturbation-tested the new bindings on a scratch copy (restored clean afterward). The tranche split itself is sound, faithfully implements review #106 finding 4's prescription, and moves nothing; the required fixes are certification-map precision, one real test-binding hole, flip-enumeration completeness, and two test-mechanics items — record and prospective-spec work, not redesign. Ratifiable after them.

1. Zero-movement (check 1): verified clean, to the byte and beyond the claim. git diff origin/master...HEAD (merge base = origin/master = fe90ee1) is a single-hunk pure insertion in gates.yaml (+446, the amendment_proposed sibling between the locked block and amendment_history); the only non-insertion edit anywhere is the disclosed test relaxation (finding 6). Recomputed independently: gate_2.thresholds parses identical to origin/master; set(gate_2) − set(master.gate_2) == {amendment_proposed} with empty reverse difference; and — stronger than the PR body claims — the ENTIRE parsed gates.yaml is identical to origin/master after deleting amendment_proposed (name, description, amendment_history, gate_1, gate_3 all equal). The 46 gated cells recompute from the union of views.*.tolerances (6+4+4+4+6+5+6+11), the 16 report-only cells from report_only, disjoint, both sets equal to origin/master's AND to runs/gate2_floors_v2.json gate_partition.gate_eligible / .report_only exactly. locked: true, status: locked unchanged; no code outside the tests reads amendment_proposed (grepped src/ and scripts/), so no verdict or score path exists.

2. Verdict preservation and no_self_rescue (checks 1+4): verified. From the committed artifacts, not the proposal's table: runs/gate2_hazard_v1..v15.json all carry verdict.gate_2_pass: false (15/15), and v16 carries gate_2_pass: true, n_seeds_pass: 4 — exactly as verdict_preservation discloses. The clause is unambiguous ("re-scores NOTHING and changes NO verdict"), every changes[*] entry carries threshold_change/verdict_change/scored_cell_change: false (test-bound), the inherited no_self_rescue text matches gate_1's verbatim clause, and its "trivially satisfied" argument is correct — a naming/language amendment has no verdict to rescue, and the scored surface is byte-identical. Governance coherent.

3. Accommodation shape (check 6): adjudicated — the inverse pattern is real but this object is clean. Scoping DOWN after a PASS is the mirror image of goalpost-moving: bank the headline verdict, then shrink what it certified. Three recomputed facts foreclose it here: (a) the locked scope.provision_class_coverage — already declaring MX23REL "NOT COVERED HERE" and marriage×earnings "NOT COVERED" — entered at commit 8200687 (PR #79, the lock), BEFORE all sixteen candidate runs; the amendment narrows the headline description/holdout_basis to the scope that was pre-registered in substance at lock time, and the 46-cell scored surface is byte-identical throughout. (b) The narrowing is deployment-restrictive (a 2a pass authorizes LESS than an over-read "gate 2 passes"), i.e. against the proposer's interest. (c) The trigger is an external Blocker (#106 finding 4), and the timing is stated plainly in process_statement. Residual pattern risk — future gates headlined broadly, run narrow, re-scoped post-pass — is addressed under recommendations.

4. Certification-scope map (check 2): substantively right on the two adjudicated boundaries, with three precision defects in text destined for the locked block — required fix A.

5. Test bindings (check 5): one real hole — required fix B — plus a weak token binding. Perturbations on a scratch copy, full derivations file after each, restore verified clean:

  • P1 (the hole): flipping the caregiver row's requires_tranche from [2a, 2b] to [2a] — a material certification flip that would let a 2a pass claim the caregiver/child-in-care class — breaks NOTHING (48 passed, 24 skipped). The map's load-bearing content, the per-class tranche requirements, is unbound: the test asserts only set(requires_tranche) <= declared. Bind the exact per-class lists. Note also locked_coverage binds by startswith, so "NOT COVERED HERE" degrading to "NOT COVERED" would pass; bind exact tokens.
  • P2 class rename -> breaks the set-equality test; P3 locked tolerance 0.047->0.048 -> breaks BOTH the new parsed-compare AND the pre-existing floor binding (zero-movement doubly bound); P4 gated_cells 46->45, P5 claims_only += MX23REL, P6 flip-anchor text, P7 n_seeds_pass 4->5 -> each breaks exactly its intended test; P8 proposal_number 2->1 (re-presenting as amendment 1) -> 12 failures: the dormant amendment-1 bindings wake and reject the object AND the relaxed history invariant fails. Dormant-safety: with the block deleted (the post-flip state), 37 passed / 35 skipped, zero failures — all 11 new tests skip cleanly. Full suite from the worktree: 1322 passed, 55 skipped, 0 failed (exit 0, 6m06s, -n 8). ruff and black -l 79 --check clean on the test file.

6. Flip enumeration (check 3): the three named edits verify, but the enumeration is incomplete — required fix C; and the master-compare test has a known-failing merge state — required fix D1.

  • All three flip_edits locked_text_now anchors resolve at their locked_path in the live locked block (recomputed independently of the test), and flip_additions names the tranche stubs. With the amendment live, over-reading the c16 pass as 2b/2c readiness requires ignoring explicit locked text — adequate protection once the fixes land.
  • C1: the locked description's second clause — benefit formulas earn per-rule "computes exactly" status. — has no disposition. currently_locked.description quotes it (with a single-vs-double quote-mark substitution; make the quote verbatim or mark it normalized), but proposed.description DROPS it and flip_edits[description] names only the household/MX23REL clause. As specified the flip would either silently delete locked-claimed certification surface (the oracle-certified formula work, Claiming-age module: SSA Statistical Supplement reference and reduction wiring #78/Survivor and spousal benefit plumbing: 402(b)/(c)/(e)/(f) with oracle cross-checks #80) or silently keep text the proposal presents as replaced. State where the clause goes and mirror it in proposed.description.
  • C2: two scope_note edits are unenumerated though they sit inside exactly the subtree the flip restructures: the stale "This DRAFT tranche covers..." label (precedent: the amendment-1 flip enumerated the stray "DRAFT" in pass_rule — fix B there), and the cross-reference "named in holdout_basis but not scored in this draft", which goes stale the moment flip edit 2 removes MX23REL from holdout_basis. Add both, with anchors.
  • C3 (recommendation): gate_2.name ("family and benefit outputs") is untouched and unenumerated — post-flip it remains the headline above a 2a-only lock. Either enumerate a rename (tranche-container phrasing) or record why it stays.
  • D1: the ratifying merge itself will turn master CI red until the flip lands — this is observed, not hypothetical. test_gate2_amendment2_changes_no_locked_value asserts set(gate_2) − set(master.gate_2) == {"amendment_proposed"}; at the ratification merge both sides contain the object, the difference is empty, and the assertion fails. Amendment 1's identical assertion did exactly this: master run 28954709231 on fec27eb (the PR Gate-2 amendment proposal 1: mean-over-draws scoring #96 ratification merge) failed with FAILED tests/test_gates_derivations.py::test_gate2_amendment_changes_no_locked_value - AssertionError: assert set() == {'amendment_proposed'}, pytest (3.13) cancelled, recovering only at the flip f6b571a ~68 minutes later. Precedented, but now a known failure mode with a one-line fix: assert <= {"amendment_proposed"} (keeping the thresholds-equality and locked-flag asserts unconditional — they hold in every state), or keep the strict equality only when master's gate_2 lacks a parsed-identical proposal-2 object.

7. Relaxed history invariant (check 4): sound today, under-implements its own docstring — required fix D2. The relaxation (proposed is None or proposal_number >= 2) correctly forbids re-presenting ratified amendment 1 (P8: 12 failures) while admitting this strictly-later proposal, and the amendment-1 history record + four ceremony pointers stay bound. But the docstring's principle — "a strictly later proposal, never a re-presentation of a ratified one" — is hard-coded at 2 = len(history)+1 as of today: after THIS amendment is ratified and flipped (history length 2), a re-presented consumed proposal-2 object would pass the invariant. Bind proposal_number >= len(gate_2["amendment_history"]) + 1 — identical behavior now, self-tightening at every future ratification.

8. Future-proofing 2b/2c (check 6): adequate, one addition recommended. 2b pins the staged holdout by name (MX23REL person-relationship map, staged per #74 alongside mh85_23/cah85_23/ind2023er), and its lock ceremony names the concrete steps (pre-registered gate on a 100-seed split noise floor over MX23REL household-composition transitions, power cap, adversarial referee round, ratifying merge). 2c honestly declares no single staged file (mh85_23 crossed with gate-1-certified earnings) and an assortative marriage-x-earnings floor. Neither can drift into a silent lock: lock_ceremony.exists: false is test-bound and any 2b/2c pass claim without its own ceremony would contradict the locked map. Two small additions: name the verification round in both required_before_any_*_pass step lists (the ceremony is proposal -> referee -> fixes -> verification -> ratify), and — the standing fix for finding 3's residual — have the flip (or a follow-up) add a governance rule that a gate/tranche's description and holdout_basis must claim exactly its scored surface at lock time, so the broad-headline -> pass -> re-scope pattern cannot recur at 2b/2c/gate 3.

Required fixes.
A. Certification-map precision (all destined for the locked block via the flip): A1 re-derive 2b's third required_for bullet — household-unit poverty rows -> 2b; by-marital-status subgroup rows -> 2a; correct the "(check)-columns" attribution (the #74 (✓)s sit on MS/FC for minimum benefits and DI for caregiver credits — component marks, not household-tranche marks) and restore the dropped "or subgroup" if the legend is quoted. A2 scope 2a's does_not_support levels clause: 2c is required for spousal/survivor LEVELS in generated panels; own-record provision levels are gate-1 + oracle territory, outside gate 2's tranches. A3 in 2a's supports, attribute the real-history side to the #84 real-couples validation rather than the tranche pass. (4)
B. Bind the map's load-bearing rows: exact requires_tranche list per provision class (P1 currently passes green), and exact locked_coverage tokens instead of startswith. (5)
C. Complete the flip enumeration: C1 disposition of the "benefit formulas earn per-rule computes-exactly" clause, mirrored in proposed.description, and a verbatim (or explicitly normalized) currently_locked.description quote; C2 enumerate the scope_note's stale "This DRAFT tranche" label and the "named in holdout_basis" cross-reference as flip edits with anchors. (6)
D. Test mechanics: D1 make the master-compare merge-safe (subset assert or parsed-identical-proposal guard) so ratification does not repeat the observed fec27eb red-master window; D2 derive the history invariant's floor from len(amendment_history) + 1. (6, 7)

The core change — naming the locked block tranche 2a byte-identically, declaring 2b/2c unlocked with their own ceremonies, and mapping the three locked provision classes to the tranches they require — is the right fix for #106 finding 4, moves no number (verified at full-file granularity), rescues nothing, and was pre-registered in substance at the lock. Fix the map's edge text, bind its rows, finish the flip enumeration, and harden the two test mechanics; then ratify.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@MaxGhenis

Copy link
Copy Markdown
Contributor Author

Referee fixes applied (adversarial round comment 4930448912, verdict AMEND BEFORE RATIFYING) — commit 81ea41e, one commit on top of the reviewed head b37cb5b. Fix-by-finding:

A. Certification-map precision (finding 4)

B. Map bound exactly (finding 5, P1)
test_gate2_amendment2_certification_scope_covers_locked_classes now pins a per-class expected table and asserts each row's requires_tranche list exactly (order-sensitive) and each locked_coverage token exactly — against the pinned table AND against the locked note's coverage designation (its text before the " -- " gloss), so a degrade in either the map or the note breaks. Perturbations re-run:

  • P1 (the referee's hole): caregiver [2a, 2b][2a] now FAILS (was 48 passed / 24 skipped green).
  • Token degrade NOT COVERED HERENOT COVERED: FAILS (was a startswith pass).
  • Order flip [2a, 2b][2b, 2a]: FAILS.
  • P8 re-presentation (proposal_number 2 → 1): 12 failures, matching the referee's count.
  • Dormant safety (block deleted, the post-flip state): 37 passed / 37 skipped, 0 failures — the two new tests skip cleanly.

C. Flip enumeration completed (finding 6)

  • C1 — formula clause disposition. New flip_edit description_formula_clause: the benefit formulas earn per-rule "computes exactly" clause is RETAINED verbatim (statutory-formula oracle certification Claiming-age module: SSA Statistical Supplement reference and reduction wiring #78/Survivor and spousal benefit plumbing: 402(b)/(c)/(e)/(f) with oracle cross-checks #80 — gate-1 + oracle territory, outside the tranche split), mirrored in proposed.description, so the flip neither silently deletes locked-claimed surface nor silently keeps text presented as replaced. currently_locked.description is now a verbatim quote of the live gate_2.description (quote marks reproduced; bound by a new test asserting the live description is a substring).
  • C2 — two scope_note edits enumerated with anchors. scope_note_draft_label (anchor This DRAFT tranche; relabel to the ratified 2a tranche, per the amendment-1 pass_rule DRAFT precedent) and scope_note_holdout_xref (anchor named in holdout_basis but not scored in this draft; re-pointed to gate_2b once flip edit holdout_basis removes MX23REL).
  • C3 — gate_2.name disposition. New flip_on_ratification.name_disposition: recommendation retain — gate_2 is the tranche CONTAINER (2a locked + 2b/2c stubs post-flip), the certification claim is carried by the tranche map, and a rename would churn frozen artifacts for no certification gain (cross-referenced to considered_and_rejected.rename_gate2_to_gate2a_repo_wide). Test-bound: the quoted name must equal the live gate_2.name.
  • All six flip_edit anchors verified resolving at their locked_path in the live locked block (test re-run green).

D. Test mechanics (findings 6, 7)

  • D1 — merge-safe master compare. test_gate2_amendment2_changes_no_locked_value now asserts set(cur_g2) - set(master) <= {"amendment_proposed"} (subset), keeping the thresholds-equality and locked-flag asserts unconditional. Verified across all three states: today ({amendment_proposed} ⊆, passes), the ratify-merge window (∅ ⊆, passes — the state that failed run 28954709231 on fec27eb under the == form), and a violation (second undisclosed key → still fails).
  • D2 — self-tightening history invariant. test_gate2_ratified_history_record now derives the floor: proposal_number >= len(gate_2["amendment_history"]) + 1. Identical behavior today (floor 2); after this amendment ratifies and flips (history length 2 → floor 3) a re-presented consumed proposal-2 object fails where the old hard-coded >= 2 would have passed; a genuine proposal 3 passes.

Finding 8 recommendations

Suite: 1324 passed, 55 skipped, 0 failed (exit 0, -n 8; the referee's 1322 + 2 new binding tests). black -l 79 --check and ruff check clean. gates.yaml still parses with gate_2.thresholds byte-identical to origin/master (all edits live in the proposal object and its tests); the zero-movement, verdict-preservation, and cell-set bindings re-verified green.

PR stays DRAFT pending the verification round; no ratification by this push.

@MaxGhenis

Copy link
Copy Markdown
Contributor Author

Verdict: RATIFY AS-IS.

Verification round on fix commit 81ea41e (one commit atop reviewed head b37cb5b), against round-1 comment 4930448912 (AMEND BEFORE RATIFYING, fixes A–D + finding-8 recommendations) and the fix summary 4930615774. Re-verified in a detached read-only worktree: every load-bearing claim recomputed from the committed artifacts, the git record, and the source issues (#74/#78/#80/#84/#86) rather than trusted from the PR text; every new binding perturbation-tested on a scratch copy and restored clean. Both required-fix families are genuinely resolved and nothing new broke. Two nits recorded for the flip PR, neither blocking.

A. Certification-map precision — resolved, recomputed against the sources.

B. Exact bindings — resolved; the P1 hole is closed. Independent perturbations on a scratch copy (full derivations file after each, restore verified clean): caregiver requires_tranche [2a, 2b] → [2a] FAILS (round 1: passed green); locked_coverage "NOT COVERED HERE" → "NOT COVERED" FAILS (was a startswith pass); order flip [2a, 2b] → [2b, 2a] FAILS. The note-token cross-bind recomputes: for all three classes the pinned token equals the locked note's designation before the " -- " gloss (COVERED / NOT COVERED HERE / NOT COVERED), so a degrade in either the map or the locked note breaks the test.

C. Flip enumeration — complete and genuinely bound. All six flip_edits anchors resolve at their locked_path in the live locked block, recomputed independently of the test. Each of the three NEW anchors was perturbation-tested and breaks test_gate2_amendment2_flip_edits_enumerated when corrupted (formula-clause anchor, DRAFT-label anchor, holdout-xref anchor — each FAILS). C1: currently_locked.description now quotes the live description verbatim, and the substring bind is real — a one-character drift inside the quoted text FAILS the disposition test; the RETAIN disposition is coherent (the "computes exactly" clause is the per-rule oracle certification, #78/#80 — gate-1 + oracle territory outside the tranche split) and is mirrored in proposed.description, so the flip neither silently deletes nor silently keeps it. C2: both scope_note edits are enumerated with anchors that appear at scope.note ("This DRAFT tranche") and at the caregiver coverage entry ("named in holdout_basis but not scored in this draft"). C3: name_disposition retain, with gate_2_name_now bound equal to the live gate_2.name.

D. Test mechanics — verified in all states.

  • D1. Today: full suite green under the subset assert. Simulated ratify-merge window (scratch clone with the origin/master ref moved to 81ea41e, so master's gate_2 contains the parsed-identical proposal): the ENTIRE derivations file passes 50 passed / 24 skipped — the state that failed run 28954709231 on fec27eb under the == form no longer produces a red-master window from any test (the amendment-1 bindings stay dormant behind their proposal_number == 1 guard). Violations: a bogus second key under gate_2 fails the subset assert loudly ({'amendment_proposed', 'bogus_extra_key'} <= {'amendment_proposed'} AssertionError); a REMOVED locked key sits outside any forward set-difference (the old == form had the identical blind spot) but is caught by the live bindings — deleting gate_2.name fails the flip-enumeration test, and description / thresholds / amendment_history removals fail their own binds. The thresholds-equality and locked-flag asserts stay unconditional and hold in every state.
  • D2. The floor recomputes as len(amendment_history) + 1 = 2 today, and proposal 2 passes. With a simulated second consumed history entry appended (length 2, entry[0] intact): a re-presented proposal-2 object FAILS the invariant (2 >= 3), a genuine proposal 3 passes it, and the derivations file shows 0 failures with the proposal-2 bindings skipping — the self-tightening semantics round 1 asked for, exactly.

Finding 8 items. governance.standing_rule (description_claims_exactly_the_scored_surface) is present, applies to 2b / 2c / gate_3, is attributed to #106 finding 4 plus this PR's referee round, is enumerated in flip_additions for promotion into the locked governance, and is test-bound; both 2b/2c lock ceremonies now name the verification round in the full five-step sequence (proposal → referee → fixes → verification → ratify).

Cross-cutting, recomputed. gate_2.thresholds parses identical to origin/master; forward key diff = {amendment_proposed}, reverse empty; the ENTIRE parsed gates.yaml equals master after deleting the object; the 46 gated + 16 report-only cell sets equal master's and runs/gate2_floors_v2.json gate_partition exactly; the gates.yaml diff vs master is a single hunk, 590 additions, 0 deletions — still a pure insertion, locked region untouched at byte level. Full suite: 1324 passed, 55 skipped, 0 failed (exit 0, -n 8) — the round-1 1322 plus exactly the two new binding tests. P8 re-presentation (proposal_number → 1): 12 failures, matching both prior counts. Dormancy (block deleted, the post-flip state): 37 passed / 37 skipped, 0 failures — every amendment-2 test skips cleanly. No non-test reader of amendment_proposed (src/ and scripts/ grep empty). ruff check and black -l 79 --check clean on the test file; PR CI green (lint, pytest 3.11/3.13, build).

Every fix-summary claim I tested reproduced exactly — suite counts, perturbation outcomes, dormancy counts, the P8 count. The two nits are flip-time text polish in prose outside the bound map and do not gate ratification. The proposal object is ready for maintainer ratification by merge; the follow-up flip PR then carries the enumerated edits, the certification map, and the standing governance rule into the locked block — and should pick up the two nits.

@MaxGhenis
MaxGhenis marked this pull request as ready for review July 10, 2026 00:21
@MaxGhenis
MaxGhenis merged commit 8a4a240 into master Jul 10, 2026
7 checks passed
@MaxGhenis
MaxGhenis deleted the gate2-amendment2-proposal branch July 10, 2026 00:22
MaxGhenis added a commit that referenced this pull request Jul 10, 2026
…ro threshold movement) (#112)

Moves gate-2's ratified amendment 2 (the tranche split) from the
amendment_proposed object into the locked block. STRUCTURAL, zero threshold
movement: the locked gate_2.thresholds scored surface is byte-identical to
origin/master -- all 46 gated cells, every tolerance and derivation, the
option-(a) protocol, the ln(1.5) power cap, and the 4-of-5 seed conjunction
unchanged (verified at full-subtree granularity). Only naming, scope prose,
the certification map, the unlocked sibling stubs, one governance rule, and
the history changed.

Ceremony (mirrors flips #69, #81, #97): adversarial round AMEND BEFORE
RATIFYING (PR 111 comment 4930448912) -> fixes 81ea41e (comment 4930615774)
-> verification RATIFY AS-IS (comment 4930753295) -> ratified by merge of PR
111 (merge commit 8a4a240) under the maintainer's standing campaign
directive of 2026-07-07, full ceremony.

The six locked-text edits (flip_on_ratification.flip_edits, applied exactly):
- description: first clause re-scoped so tranche 2a claims only mh85_23 +
  cah85_23 (+ ind2023er deaths); household-composition/MX23REL -> gate_2b.
- description_formula_clause: the "computes exactly" statutory-formula oracle
  clause (#78/#80) RETAINED verbatim (fix C1).
- holdout_basis: [mh85_23, cah85_23, MX23REL] -> [mh85_23, cah85_23]; MX23REL
  -> gate_2b.holdout_basis.
- scope_note: provision_class_coverage prose gains explicit tranche ids
  (2a/2b/2c); the certification_scope map is promoted into the locked scope.
- scope_note_draft_label: "This DRAFT tranche covers..." relabeled to
  "tranche 2a_marital_fertility covers...".
- scope_note_holdout_xref: the caregiver "named in holdout_basis but not
  scored in this draft" cross-reference re-pointed to the unlocked gate_2b.

The five flip_additions: tranche_id 2a_marital_fertility inside thresholds;
gate_2b (relationship_household) and gate_2c (marriage_earnings_joint)
UNLOCKED sibling tranches (locked: false, no floor, no scored run, each with
its own future lock ceremony naming the verification round); the
certification_scope map promoted into the locked scope; and the standing
governance rule description_claims_exactly_the_scored_surface promoted into
gate_2.governance.amendment_rules (attributed to review #106 finding 4 / PR
#111 finding 8), binding 2b/2c/gate_3. gate_2.name ("family and benefit
outputs") retained per its C3 disposition (the tranche container).

Also applies the two verification-round flip-time nits (comment 4930753295):
the 2b bullet-3 legend quote spacing normalized to "poverty/household" to
match the derivation_basis quote; and COLA qualified in the A2 own-record
example list (its levels ride the Phase-B claiming/mortality components -- #74
marks CA, M, DI; #78 covers CA, M/DI uncertified -- so it is not a pure
gate-1 + oracle surface, though still outside the 2a/2b/2c tranches).

Adds gate_2's second amendment_history entry (id 2026-07-09-tranche-split;
all four ceremony pointers; content: ZERO THRESHOLD MOVEMENT, verdicts v1-v15
FAIL and v16 PASS stand as tranche-2a verdicts, citing #106 finding 4 and the
candidate-16 pass #109), and removes amendment_proposed (preserved in git
history at the ratification merge 8a4a240).

PROSPECTIVE / STRUCTURAL ONLY (no_self_rescue): a naming + certification-scope
amendment has no verdict to rescue and re-scores nothing; candidate 16 stays
PASS (4/5), candidates 1-15 stay FAIL, as tranche-2a verdicts.

Tests rewired locked-hot: the re-scoped description/holdout_basis, tranche_id,
the promoted certification_scope map (per-class requires_tranche + coverage
tokens bound EXACTLY, both nits asserted), the gate_2b/gate_2c stubs, the
promoted standing rule, and the second history entry with all four pointers
rebind at their LIVE post-flip locations in a new "Gate-2 amendment 2
RATIFIED bindings" section. The proposal-object tests stay dormant-safe
(guarded on proposal_number == 2, so they skip once amendment_proposed is
gone), and the D1 merge-safe guard naturally skips post-flip. Full suite:
1319 passed, 68 skipped, 0 failed (-n 8); black -l 79 + ruff clean.

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant