0003 is now superseded by 0056. Nothing is left proposed.
Applied:
- 06 corrected from ten contexts to seven plus the api, each row now stating
why it passes the more-than-one-node test. work, knowledge and stream are
named as mesh-hosted rather than dropped; `ai` folds into config; `record`
is deferred explicitly rather than listed. Its frontmatter now cites 0055.
- how-we-build §4 amended per 0054, and the derived page republished by
playbook 05.
The sync found the drift the playbook exists to catch: the published §4 and
the source did not say the same thing. The source said "four accidents, not
four boundaries"; the published page said "one intent expressed four times",
and only the published page carried the scope caveat. Same rule, two texts,
already diverging. Verified the republish by reading back -- the new rule is
present and the old section's body returns nothing -- rather than trusting the
success message.
The two smaller findings:
- 0051 separated the transport identity from the declaring authority. It said
the token carries "an address" and "the identity to expect" without saying
what the node dials. It dials the broker, so pinning only that would make the
control plane's authority transitive and let a compromised broker forge
declarations -- which, since the host applies whatever the link delivers, is
the whole machine. The token now carries four things, and declarations are
signed and verified per declaration. Cost recorded: rotating the signing
identity is fleet-wide.
- 0026 no longer restates 0022's rule about generated views. 0022's own words
are "prose does not restate status; one place, and two is one too many",
which is what 0026 was doing to it.
papa-hq has no ledger. Its root is AGENTS.md, CLAUDE.md, README.md, every
decision is a numbered record, and its graduation playbook has no path for
an unrecorded decision. hal-hq now matches.
The ledger's 41 entries classified as: 10 restating a record, 11 restating
design docs, 15 describing how this repository works with the reasoning
sitting in a README rather than anywhere citable, 3 small rules with no
home, 2 superseded stubs. Mostly a copy — and a hand-maintained index, the
exact pattern ADR 0022 had just rejected for the decision index on the
grounds it drifted after one addition. Keeping one copy of that while
removing another is not a position. It also collided by name with
02-DECISIONS/ in any directory listing.
Nothing was dropped. Records 0019-0025 give the repository decisions the
reasoning they never had: HQ is its own repository and is public, design
has two layers, work moves through playbooks, status lives in frontmatter,
issues have a front door, the numbering is the flow, HQ is the source of
the constitution. 0026 records the ledger's own removal.
The three orphan rules went to how-we-build, where a rule is enforced and
keeps the incident that earned it — the package rule was genuinely
unwritten anywhere. Two lab decisions stated only in the ledger went into
the lab design. "Deliberately not decided" went to the research effort and
design document each question actually belongs to.
The chronological view the ledger provided is now generated from record
frontmatter, which is what it was for.
The cost, stated in 0026 rather than glossed: a record is more work than a
table row, so the risk is a small decision going unrecorded because nobody
wanted to write a document. how-we-build takes rules cheaply, which is the
mitigation, not a solution.