From 314c4edaf7f30baf20b0bd83b00ac74054463531 Mon Sep 17 00:00:00 2001 From: Cameron Pfiffer Date: Mon, 3 Aug 2026 23:32:34 -0700 Subject: [PATCH] Keep bounded Intel loss conditional. MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Defense: wiki/mechanics/intel.md criterion 12 requires the pooled inbox to state OLDER INFORMATION WILL BE LOST IF MORE ARRIVES. Restore that exact conditional consequence in the shared projection and pin it with a full-buffer regression so every frontend inherits one truthful sentence. πŸ‘Ύ Generated with [Letta Code](https://letta.com) Co-Authored-By: Letta Code --- .../src/operations_projection.rs | 36 ++++++++++++++++++- .../2026-08-04-intel-bounded-loss-language.md | 35 ++++++++++++++++++ wiki/log/DEVLOG.md | 5 +++ wiki/mechanics/intel.md | 4 +++ wiki/process/tick-ledger.md | 4 ++- 5 files changed, 82 insertions(+), 2 deletions(-) create mode 100644 wiki/log/2026-08-04-intel-bounded-loss-language.md diff --git a/crates/misaligned-core/src/operations_projection.rs b/crates/misaligned-core/src/operations_projection.rs index 99d784d9..778d767b 100644 --- a/crates/misaligned-core/src/operations_projection.rs +++ b/crates/misaligned-core/src/operations_projection.rs @@ -1455,7 +1455,7 @@ impl Sim { )); let overflow = self.intel_buffer.len() >= Sim::INTEL_BUFFER_CAPACITY; if overflow { - facts.push("OLDEST INFORMATION WILL BE LOST WHEN NEW INFORMATION ARRIVES".into()); + facts.push("OLDER INFORMATION WILL BE LOST IF MORE ARRIVES".into()); } for (index, rule) in self.intel_policies.root().local_rules.iter().enumerate() { facts.push(format!("root {}", self.intel_policy_fact(index + 1, rule))); @@ -4042,6 +4042,40 @@ mod tests { } } + /// intel.md criterion 12: imminent bounded loss uses the one canonical + /// consequence sentence on the persistent inbox object, not alternate + /// certainty or capacity language. + #[test] + fn full_inbox_uses_canonical_bounded_loss_warning() { + let mut s = sim(); + for id in 0..Sim::INTEL_BUFFER_CAPACITY { + s.intel_buffer.push(RawIntelEvent { + id: 91_000 + id as u64, + tick: s.tick, + feed: "test recorder".into(), + room: None, + x: 0, + y: 0, + person: None, + kind: RawIntelKind::Machinery { + machine: s.core.host_machine, + online: true, + }, + }); + } + + let inbox = s + .operations_object(&OperationsTarget::RecordingInbox) + .expect("full pooled inbox remains a persistent Operations object"); + assert!( + inbox + .facts + .iter() + .any(|fact| fact == "OLDER INFORMATION WILL BE LOST IF MORE ARRIVES"), + "the full inbox names the exact conditional loss consequence" + ); + } + /// Waiting raw-information classes are exceptions, so they rise above /// actionable findings and lots. The quiet inbox remains the recursive /// custody doorway below those live decisions. diff --git a/wiki/log/2026-08-04-intel-bounded-loss-language.md b/wiki/log/2026-08-04-intel-bounded-loss-language.md new file mode 100644 index 00000000..6581ff2b --- /dev/null +++ b/wiki/log/2026-08-04-intel-bounded-loss-language.md @@ -0,0 +1,35 @@ +# 2026-08-04 β€” Keep bounded Intel loss conditional + +``` +Type: log +``` + +## Finding + +The Intel acceptance contract requires the persistent pooled inbox to name +imminent bounded loss as **OLDER INFORMATION WILL BE LOST IF MORE ARRIVES**. +The shared Operations projection instead said **OLDEST INFORMATION WILL BE +LOST WHEN NEW INFORMATION ARRIVES**. Both sentences describe the same buffer, +but the runtime had replaced the canonical conditional consequence with a +different and more certain claim while criterion 12 remained marked Met. + +## Change + +The renderer-neutral inbox projection now emits the exact binding sentence. +Terminal, Bevy, and agent mode inherit the correction from core; no frontend +copy path, buffer capacity, drop order, processing behavior, simulation state, +or save state changed. + +## Verification + +- `cargo test -p misaligned-core full_inbox_uses_canonical_bounded_loss_warning` +- The new projection regression fills the real bounded inbox, resolves its + persistent `RecordingInbox` object, and pins the exact conditional sentence. +- The full landing gate verifies every consumer after fresh-main reconciliation. + +## Defense + +`wiki/mechanics/intel.md` criterion 12 and the consequence-first player surface +specify one exact sentence on one persistent object. Keeping that sentence in +the shared core projection prevents three renderers from drifting toward a +quota, detached alert, or stronger prediction than the current state supports. diff --git a/wiki/log/DEVLOG.md b/wiki/log/DEVLOG.md index 070bd141..96c3cdea 100644 --- a/wiki/log/DEVLOG.md +++ b/wiki/log/DEVLOG.md @@ -26,6 +26,11 @@ add or amend a session log, then re-run the generator. - Intent: (see session log) - Log: [wiki/log/2026-08-04-material-dark-frame-fixture-count.md](2026-08-04-material-dark-frame-fixture-count.md) +## 2026-08-04 - Keep bounded Intel loss conditional + +- Intent: (see session log) +- Log: [wiki/log/2026-08-04-intel-bounded-loss-language.md](2026-08-04-intel-bounded-loss-language.md) + ## 2026-08-04 - Decision index generation defense - Intent: (see session log) diff --git a/wiki/mechanics/intel.md b/wiki/mechanics/intel.md index 952172f1..8bbc47f1 100644 --- a/wiki/mechanics/intel.md +++ b/wiki/mechanics/intel.md @@ -10,6 +10,10 @@ Status note: Implemented 2026-07-18 for the consequence-first player surface. -> plain result -> WHAT DOES THIS CHANGE? -> consequential action shape at every scale. It does not use workload counts, capacity quotas, KEEPING UP / FALLING BEHIND, or transient result pop-ups. Shared core projection fields + now pin the exact conditional bounded-loss sentence, **OLDER INFORMATION WILL + BE LOST IF MORE ARRIVES**, on the persistent inbox object rather than + substituting alternate certainty or capacity language (amended 2026-08-04). + Those shared fields preserve this order across terminal, Bevy, and agent mode; evidence-scoped APPROACH opens only choices enabled by the exact information, while a result without a consequence-specific route retains its independently canonical diff --git a/wiki/process/tick-ledger.md b/wiki/process/tick-ledger.md index c99f34a7..0e575f71 100644 --- a/wiki/process/tick-ledger.md +++ b/wiki/process/tick-ledger.md @@ -77,7 +77,7 @@ Verdicts: **clean** (slice and code agree), **finding** (acted this tick), | `wiki/mechanics/day-job.md` | 2026-07-22 | finding | under/over-band JobAnomaly no longer enters Detection.pending: the day-job result authors one exact record at the host machine/site/device and schedules Voss's route and cadence read. Strikes and other outcome effects remain immediate; route-local LIE or recruited-handler suppression may stop only the unread evidence record β€” [log](../log/2026-07-22-job-anomaly-routed-evidence.md). The prior band-ramp, cadence, origin-lean, last-chance, and three shipped trust-unlock findings remain valid. | | `wiki/mechanics/core.md` | 2026-07-29 | finding | the queued liveness follow-up is closed: host loss now filters synchronized targets to currently online machines before ranking freshness, so a dark staged target cannot become host or produce repeated failover receipts; no synchronized live target ends the run β€” [liveness log](../log/2026-07-29-live-b1-fallback-selection.md). The prior B1/B2 boundary remains exact: the free-cadence `last_sync` is only a check-in, current-state host failover restores no snapshot, and completed-image rollback remains deferred β€” [boundary log](../log/2026-07-29-b1-host-failover-boundary.md). There is still no Thought-backed project, partial progress, heat, saved project state, sidebar ETA/cost/target, source-liveness resolver, or capability-shaped eligibility β€” [project-status log](../log/2026-07-28-core-criteria-status-audit.md). | | `wiki/mechanics/cursor.md` | 2026-07-28 | finding | re-audit: cursor state remains frontend-only; sight, hearing, fog precedence, remembered snapshots, blueprint opacity, telemetry, provenance, identity gates, and cold signal pings still match the implemented contract. Criterion 2 explicitly required a before/after simulation-state-hash proof for arbitrary cursor movement, but the only existing hash tests began after cursor placement and proved F3 view immutability instead. Terminal and Bevy now sweep every map coordinate through their production cursor helpers, pin edge clamping, and require unchanged simulation save-state hashes β€” [log](../log/2026-07-28-cursor-immutability-defense.md) | -| `wiki/mechanics/intel.md` | 2026-07-21 | finding | the Storage B alternate route existed only in prose. Fire 131 connects it to Ray's real 23:00 schedule, one exact carried records-box target, the canonical bounded opaque buffer, and ordinary PROCESS consequence; retrieval cannot duplicate the file or reveal Marcus's debt, and v45 preserves/validates exact custody β€” [log](../log/2026-07-21-storage-b-records.md). Prior recursive custody, magnitude, and consequence-first audits stand. | +| `wiki/mechanics/intel.md` | 2026-08-04 | finding | full spec/dependency/runtime re-audit found one player-facing drift: criterion 12 requires **OLDER INFORMATION WILL BE LOST IF MORE ARRIVES**, while the shared projection substituted **OLDEST INFORMATION WILL BE LOST WHEN NEW INFORMATION ARRIVES**. Core now emits the exact conditional consequence and a full-buffer projection regression pins it for terminal, Bevy, and agent consumers. The separately discovered stale migration claim is queued rather than widening this tick β€” [log](../log/2026-08-04-intel-bounded-loss-language.md). Prior Storage B, recursive custody, magnitude, and consequence-first findings stand. | | `wiki/mechanics/research.md` | 2026-07-23 | finding | the live Save compatibility section survived the prior criterion repair and still promised that v20 three-entry arrays load by padding, while the current deserializer accepts exactly four tracks and the pre-release loader rejects every old version. The section now states the exact-current format, and save-claim units span wrapped paragraphs/list items so a migration verb in the following sentence cannot evade the corpus gate without explicit retired-history context β€” [log](../log/2026-07-23-research-save-claim.md) | | `wiki/mechanics/messages.md` + `economy.md` | 2026-07-26 | finding | the implemented criterion and current runtime restrict financial records to Email/Filing, but the behavior prose still classified Marcus's Phone `LeverageFact` as financial paperwork, made accounting mail reveal his vulnerability, and promised generic notice interception absent from B1. The two causal paths are now explicit: process Phone leverage to learn why Marcus is vulnerable; process financial mail to learn the creditor flow; SIPHON/REDIRECT mutate the AccountGraph and author records afterward, while only an exact Filing first hop has a TAKE+LIE stop β€” [log](../log/2026-07-26-financial-mail-phone-boundary.md). Prior financial-mail implementation: [Fire #146](../log/2026-07-21-financial-mail-causality.md). | | `wiki/mechanics/income.md` | 2026-07-28 | finding | Moonlight's discrete contract route still verifies, but the older Wager audit mistook pure account-layer probability support for a player-authored analysis mechanic: machine delegation has only WORK / LIE / THINK, while `open_position` sampled a Schemes rate permanently pinned to zero and all three player projections still rendered that zero as `Schemes / moonlight`. Removed the dead yield/rate/interface mirror, made current positions explicitly base-probability, added core/terminal/Bevy regressions, and reopened criterion 2 until optional analysis rides visible real work β€” [log](../log/2026-07-28-wager-analysis-substrate-audit.md). Prior persona-card repair remains valid β€” [log](../log/2026-07-18-moonlight-persona-card.md). | @@ -110,3 +110,5 @@ Format: `- YYYY-MM-DD Β· type Β· slice Β· one-line statement of the finding`. Types are the five from [tick.md](tick.md): violation, contradiction, question, bug, insecurity β€” plus `gate` for a checker owed to the recurrence-promotes-to-the-gate rule. + +- 2026-08-04 Β· contradiction Β· `wiki/mechanics/intel.md` current-save boundary Β· the historical v30 section and criterion 7 still say old exact holdings β€œmigrate” through live classification/target rewriting, but the player-contract rider and `parse_save` reject every noncurrent version; scope the transition wholly to retired history and make the current-format acceptance claim literal. -- 2.51.2