The tidy's gate-first Task 1 RED-verification + Boss independent
verification surfaced two defects in the audit Resolution as first
written — caught exactly where the planner->Boss loop is designed to,
before any contract byte moved. Per the 'two+ defects in one
iteration => fix the upstream artifact, do not patch a third time'
discipline, the audit Resolution is corrected in lockstep with the
plan re-derivation:
- Mechanism (Resolution-4): the 'case-insensitive iter-code regex'
clause-3 design is REJECTED as unworkable — a blanket
iter/milestone detector conflates the memory-model rule-names
'Iter A'/'Iter B' and ordinary words 'pre-existing'/'pre-set'/
'pre-Boehm' with provenance, over-firing on legit present-tense
contract prose (4 no-strip files). Replaced by a FAITHFUL Sweep-1
superset: case-sensitive digit-anchored Sweep-1 line anchors
(confirmed ZERO across all contracts) + Sweep-1's ^[^/]*
path-excluded date (so docs/specs/2026-.. citations are not
flagged — repairs the iso_date over-fire the implement
orchestrator correctly BLOCKED on) + the audit-named
decision-record phrases (case-insensitive). No regex dep. The
load-bearing invariant (clause-3 GREEN => Sweep-1 clean) is
preserved; it never required the blanket detector.
- Scope (Resolution-1): the architect's [medium] was a 3-file
spot-check; the exhaustive scan found roundtrip-invariant.md:73
('at iter form-a.1') and data-model.md:149,161 ('loop-recur iter
1:') also carry lowercase provenance. True strip set = 5 files;
plan Task 5b adds the 2 (spirit-cleanup, not gate-blocking).
Plan self-review 8/8 re-run; clause-3 = hand-rolled faithful Sweep-1
superset, no regex dep, no blanket iter detector.
9.3 KiB
audit — milestone close: DESIGN.md → design/ role-split
Date: 2026-05-19
Scope: deeffb1..176821c (spec a64b2cc/314e5e4, plan deeffb1, iter 176821c)
Status: DRIFT (one tidy iteration) + bench causally-exonerated (baseline pristine)
Architect (drift_found — one [medium] spirit-finding; relocation faithful)
What holds: relocation byte-faithful at ### granularity (MIXED
Decisions, dual-link frozen-value-layout, source-link-only
mangling/env/qualified-xref, rewritten honesty-rule all match the
spec Appendix vs git show deeffb1:docs/DESIGN.md); build-atomicity
holds (design_schema_drift.rs include_str! retargeted, slicer
removed exactly as spec'd; OQ7 cite deleted); design_index_pin.rs
4/4 GREEN; tree-wide live-ref grep clean; honesty-rule.md
present-tense, names docs/journals/ as the rationale home, both
docs_honesty_pin.rs:70,72 phrases verbatim+contiguous; agent
contracts coherent (no contract instructs reading a missing file).
Drift:
[medium]design/contracts/typeclasses.md:182,199,280-317,str-abi.md:23,38-47,scope-boundaries.md:17,42— faithfully migrated but contract-class-violating decision-record/history/ cross-milestone-amendment prose ("An earlier draft committed to…", "Milestone 23/24 amends the above", "was retired at iter mq.3/ctt.3", iter/date provenance stamps, "deliberately deferred", "NOT in milestone 22", "new-baseline decision"). Dodges the 6 literal clause-3 markers (case + wording variance: "An earlier draft" ≠ "an earlier draft"; "retired at iter" ≠ "retired in iter") yet is exactly the relitigation-guard content the split's spirit sends to journals.[low/known-debt]design/contracts/float-semantics.mdstale-direction(see "Str ABI" below …)— the prose moved tostr-abi.md; pre-existing, faithfully migrated; wrong-direction anchor inside the ledger whose reason to exist is doc honesty.
Routed-item adjudication (both): strippable doc-archaeology to
tidy, NOT ratify. The advisory architect_sweeps.sh Sweep-1
exit-1 on str-abi.md:23 is correctly diagnosing real
history-anchor residue (Boss-confirmed byte-identical to
DESIGN.md@deeffb1:2062-2065 — pre-existing, faithfully migrated, not
split-introduced; the iter/date stamps are journal-class metadata,
the present-tense contract is the signature itself).
Bench (check.py exit 1; compile_check 24/24 exit 0; cross_lang 25/25 exit 0)
6 check.py firings: bench_list_sum.{gc_s,bump_s},
bench_hof_pipeline.gc_s, bench_list_sum_explicit.bump_s,
latency.{explicit,implicit}_at_rc.max_us.
Bencher verdict — causally-exonerated, decisive on byte-evidence.
H0 (no causal mechanism) supported: emitted IR and final -O2
native bench binaries byte-identical HEAD 176821c vs
pre-milestone dd5b183 for every firing fixture (sha256 + cmp -s
table in the bencher report). Bencher audited all ~11 changed
code/runtime files (not just the 2 named) — every change is
comment / rustdoc / diagnostic-string-literal (DESIGN.md §"…" →
design/contracts/….md), none on an IR-emitting path; checker
diagnostic strings are type-check-time only, absent from the
binary. The 6 firings are the recurring tracked-P2 families
(*.bump_s environmental staleness; *_at_rc.max_us -n 5
single-sample tail jitter; *.gc_s Boehm-scan wall-time variance —
NOT the M5-ratified gc_rss_kb trio). compile_check/cross_lang
pristine corroborates (no codegen surface moved).
Disposition: NO-ratify / carry-on causally-exonerated — baseline
stays pristine. Identical to the M2/M3/M5 closes; ratifying would
bake measurement variance into the baseline. No --update-baseline,
no paired ratify entry (none is warranted — nothing moved).
Bench-design limitations recorded (not milestone-close actions):
*_at_rc.max_us is a bench/run.sh -n 5 artifact (max over 5
has no tail confidence); implicit_at_rc leaks by construction so
its max_us is inherently unstable. Both pre-existing, tracked-P2,
candidates for the standing latency-methodology rework — not this
milestone.
Resolution (orchestrator)
- Bench: carry-on, baseline pristine, no commit beyond this entry. Recorded causally-exonerated as M2/M3/M5.
- Architect drift [medium]+[low]: fix path — one tidy
iteration
design-md-rolesplit.tidy. Orchestrator-decided scope (the architect named the gap; the clause-3-widening decision is mine):- Move the decision-record/history prose out of the affected
contract files into
docs/journals/2026-05-19-design-decision-records.md(append — same milestone's relitigation archive). Each removed history sentence is replaced by its present-tense contract equivalent (the builtin signature is the contract; the(iter …)stamp is journal metadata). Scope corrected on planning-time evidence (see amendment below): the architect's[medium]was a 3-file spot-check (typeclasses/str-abi/scope-boundaries); the exhaustive plan-recon + Boss verification scan found two more contract files carrying lowercaseiter <code>provenance the spot-check missed —roundtrip-invariant.md:73("at iter form-a.1") anddata-model.md:149,161("loop-recur iter 1:"). The true strip set is 5 contract files. - Fix
float-semantics.mdstale-direction cross-ref →(see design/contracts/str-abi.md). - Re-scope the
architect_sweeps.shhonesty sweeps fromdesign/contracts design/modelstodesign/contractsonly. Substantive reason (not effort): post-split,design/models/is the explicitly narrative tier — a whitepaper legitimately carries "as of milestone N" context; scanning it for history-anchors is a category error. The honesty surface isdesign/contracts/(the hot, test-linked tier). Updateailang-architect.md+ any sweep-scope doc in lockstep. - Widen
design_index_pin.rsclause-3 so, over thedesign/contracts/scope, it subsumesarchitect_sweeps.shSweep-1's history-anchor regex. Invariant established: clause-3 GREEN ⟹ Sweep-1 finds nothing incontracts/— the in-code hard gate enforces the spirit; the advisory then only legitimately fires onmodels/(out of its scope after point 3). This permanently closes the spirit-vs-letter gap the literal 6-marker list left open. Mechanism corrected on planning-time evidence (see amendment below): the original "case-insensitive iter-code regex" sketch is unworkable and is rejected — a blanket case-insensitiveiter/milestonedetector conflates the memory-model rule-names "Iter A"/"Iter B" and the ordinary words "pre-existing"/"pre-set"/"pre-Boehm" with provenance, over-firing on legitimate present-tense contract prose. The workable design: clause-3 = a faithful reproduction of Sweep-1's actual alternatives (case-sensitive, digit-anchored — confirmed ZERO across all contracts) + Sweep-1's^[^/]*path-excluded date (sodocs/specs/2026-…citations are not flagged) + the audit-named decision-record phrases (case-insensitive — the deliberate widening that closes the capital-variance dodge). The lowercase(iter <code>)provenance is removed by the strip tasks (point 1), not by a fragile hard-gate regex; the invariant holds without the rejected detector. - Exit state:
architect_sweeps.shexit 0; the widened (faithful-superset)design_index_pin.rsclause-3 GREEN; wholecargo test --workspaceGREEN; the decision-record journal grows; no contract carries history residue.
- Move the decision-record/history prose out of the affected
contract files into
Resolution amendment (2026-05-19, planning-time evidence)
The tidy plan's gate-first Task 1 (RED-verification) + Boss independent verification surfaced two defects in this Resolution as first written — caught exactly where the planner→Boss loop is designed to catch them, before any contract byte moved:
- Mechanism (point 4): "case-insensitive iter-code regex" is
unworkable (conflates rule-names + ordinary words with
provenance). Replaced by the faithful-Sweep-1 + path-excluded-date
- phrases design above. The load-bearing invariant (clause-3 ⟹ Sweep-1 clean) is preserved — it never required the blanket detector; faithful-Sweep-1 + phrases suffices and faithful-Sweep-1 is confirmed already ZERO across every contract.
- Scope (point 1): the
[medium]was a 3-file spot-check; the exhaustive scan foundroundtrip-invariant.md+data-model.mdalso carry lowercase provenance. The strip set is 5 files (the plan's Task 5b covers the 2 additions; they are spirit-cleanup, not gate-blocking — neither Sweep-1 nor the corrected clause-3 trips on lowercaseiter form-a.1, so the invariant/gate close regardless; stripping them is the audit's spirit fully honored).
This amendment is the upstream-artifact correction the discipline
mandates over patching the plan a third time (the "two+ defects in
one iteration ⇒ the upstream artifact is wrong" rule). The plan
docs/plans/design-md-rolesplit.tidy.md is re-derived consistently
with it.
Milestone closes after the tidy iteration lands Boss-verified. No fieldtest (zero authoring-surface change — the only author-facing delta is the 2 diagnostic pointers, a doc-pointer not a language change; recorded by reasoned exclusion, not omission).