Files
hq/02-DECISIONS/0022-the-constitution-absorbs-what-is-enforced.md
T
jschoubben b4607dfc03 Numbers are identity; the reading order is a generated, checked index
Decided after measuring what renumbering actually costs: 96 references in code
comments across two repositories, none of which would have failed to compile.
They would have pointed at the wrong reasoning, which is worse than a broken
link because nothing reports it.

So a number identifies a record and never changes. It cannot also be a
position -- a position moves when the set changes, and an identity that moves
is not one.

The reading order moves into an index generated from each record's `topic:`.
Six topics, in the order somebody learns the system.

The index is WRITTEN rather than only generated on demand, which reverses what
this repository previously said. The reason it said otherwise is that a
hand-written index drifts -- but a reader looking at the folder on a forge sees
the folder, not a command, and the drift objection is answered by checking
rather than by refusing to write one. That is §5's own rule: a rule states how
it is checked.

Two checks, both confirmed to bite. index.py fails when the written order no
longer matches the records. records.py fails when a record has no topic or one
nobody defined -- the quiet failure being a record that vanishes from the order
rather than appearing in the wrong place.
2026-08-28 23:39:18 +02:00

5.5 KiB

topic, status, date, deciders, reconstructed
topic status date deciders reconstructed
how we work accepted 2026-08-26 jochen false

22. The constitution absorbs what is already enforced

Context

ADR 0021 makes this repository the source and the knowledge base a derived copy, and playbook 05 publishes the copy whenever a rule changes.

Three rules were accepted on 2026-08-25 and the sync came due. Reading the target before overwriting it — as §2 requires — found the two documents had diverged in a way nobody had recorded, and that a literal republish would have deleted rules the mesh currently enforces.

source (how-we-build.md) enforced page
§4 naming and boundaries code quality — structure, layering, types, restraint
§5 four evidence rules one runtime-evidence rule
§6 review by a non-proposer a design meeting with two node operators

The enforced page was last written 2026-07-10, is agent-authored, and its code-quality section appears in no decision record anywhere. It has been checked against for six weeks regardless.

Two facts made this urgent rather than tidy:

Removal is not the safe option. The orchestrator reads "when absent, no constitution is injected (backward-compatible)" — so deleting the page would not fail, it would silently inject nothing, and every design meeting would run unchecked with no error anywhere. Three unenforced rules would become all of them.

The stricter review bar has never been met. The enforced page requires two node operators, neither the proposer. There is one operator. Every amendment ever made violated it.

Considered options

  1. Republish wholesale. What the playbook literally says. Rejected — it deletes the code-quality rules, which exist nowhere else.
  2. Merge surgically — update §2, §3, §5 in the copy and leave §4 alone. Nothing is lost and it is quick, but the source becomes authoritative for some sections and the copy for others, which is the drift being fixed.
  3. Absorb, then republish. Chosen.

Decision

What the mesh enforces and cannot cite is written down here first, then republished.

The code-quality rules become §8 rather than §4, because appending renumbers nothing and every existing citation stays valid.

They are recorded as inherited, and marked as such. Every other rule in the document states the incident or measurement that earned it. These state nothing, because nothing was ever written down. Importing them silently would have made the document claim a provenance it does not have, and this repository's whole argument is that the reasoning is the expensive half.

The review bar is resolved in favour of what is achievable. A rule requiring two operators where there is one is not a high standard, it is a rule everything silently violates — the same shape as a firewall key declared in five manifests and read by no code (04-ISSUES/003). Review means a person who is not the proposer, which is both achievable and what has been practised.

Consequences

  • The copy can now be a faithful projection, which is what makes "the source is the source" true rather than aspirational.
  • §8 has no reasoning behind it and says so. Anyone may propose replacing an inherited rule with an earned one; until then the marking is the honest state. It is also a standing invitation to delete any of them that turn out to serve nothing.
  • Six weeks of drift went unnoticed because nothing compares the two. The sync is manual and runs only when someone remembers a rule changed. Nothing detects divergence, and this record does not fix that — it is worth an issue.
  • The operator's instinct to remove the copy was right about the direction and wrong about the method. The end state where the mesh reads this repository directly — rendered and operable through the board — removes the second copy rather than blanking it. That is not designed and is not decided here.
  • Section numbering is now append-only in practice. §8 sits after the overrides section purely because renumbering would break citations, which is a cost of the copy existing at all.

Sync

Run 2026-08-26, and the read-back earned its place in the playbook.

The first publish reported success and changed nothing. It created a new revision and updated the title, and the body did not apply — a malformed argument was dropped silently. Had the sync been marked done on the strength of the tool saying "updated; new revision created", three accepted rules would have gone unenforced while every record said otherwise, and nothing would ever have contradicted it.

That is §5 demonstrating itself during its own publication: a green result proves transport, not effect. The republish was verified by reading the rule back out of the live page, not by trusting the second success message either.

References