diff --git a/wiki/log/2026-08-04-social-contract-reaudit.md b/wiki/log/2026-08-04-social-contract-reaudit.md new file mode 100644 index 00000000..dd52a9ce --- /dev/null +++ b/wiki/log/2026-08-04-social-contract-reaudit.md @@ -0,0 +1,59 @@ +# 2026-08-04 — Social contract re-audit + +``` +Type: log +``` + +## Scope + +Re-audit the tick ledger's stalest remaining slice against the current social +runtime, current-save admission, shared Operations projection, all three +frontends, and the linked detection, Intel, persona, plot, character, and +simulation contracts. + +## Evidence + +The implemented B1 baseline remains coherent: + +- `AssetTask::ALL` and role-derived availability still provide the thirteen + institutional tasks without turning an Act One name into a type. Exact + switch, badge, unread-log, maintenance, and human-removal gates revalidate at + dispatch and fire time. +- Debt recruitment remains exact-person and exact-knowledge bound. A second + Debt person uses the same path without mutating Marcus, while Marcus still + requires processed leverage before payoff or recruitment. +- Storage B retrieval carries one exact records-box target and deposits opaque + information only on arrival. SuppressLogs stops only the oldest unread + routed JobAnomaly and cannot erase Voss's acquired evidence. Human removal + carries exact actor/target/room custody, stops future activity, and goes loud + without a quiet branch. +- Current-save validation rejects malformed carried tasks, duplicate or + impossible stages, and rewritten removal custody. The exact-current loader + rejects retired save versions rather than preserving the old global-social + migration. +- Unknown people expose no social catalog and retain role-shaped labels. Both + human frontends consume the shared Operations projection, while agent verbs + route through the same `Sim` action API. +- The adopted self-trust axis is still candidly pending under plots criterion + 12; no runtime field or generic psyche meter falsely claims implementation. + +Representative regressions passed on the audited revision: +`second_debt_person_obeys_knowledge_and_debt_state_gates`, +`marcus_debt_payoff_and_recruitment_require_debt_intel`, +`asset_task_retrieves_storage_b_records_as_opaque_processable_information`, +`asset_task_suppress_logs_stops_only_the_oldest_unread_routed_job_anomaly`, and +`elimination_is_located_persistent_and_immediately_loud`. + +## Verdict + +Clean. The prior routed JobAnomaly and Storage B findings remain closed, the +general social substrate still matches every implemented criterion, and the +one adopted-but-unimplemented axis is marked honestly rather than leaking into +current player or save claims. + +## Defense + +The audit followed exact action legality into fire-time effects and current-save +validation instead of trusting the status note alone. It also checked shared +projection ownership and agent execution so frontend parity is evidence, not a +claim inferred from core tests. diff --git a/wiki/log/DEVLOG.md b/wiki/log/DEVLOG.md index 091d17ec..baf4fcf6 100644 --- a/wiki/log/DEVLOG.md +++ b/wiki/log/DEVLOG.md @@ -11,6 +11,11 @@ add or amend a session log, then re-run the generator. +## 2026-08-04 - Social contract re-audit + +- Intent: (see session log) +- Log: [wiki/log/2026-08-04-social-contract-reaudit.md](2026-08-04-social-contract-reaudit.md) + ## 2026-08-04 - Visible-work staging drift - Intent: (see session log) diff --git a/wiki/process/tick-ledger.md b/wiki/process/tick-ledger.md index 10787f4e..6c6f1efd 100644 --- a/wiki/process/tick-ledger.md +++ b/wiki/process/tick-ledger.md @@ -83,7 +83,7 @@ Verdicts: **clean** (slice and code agree), **finding** (acted this tick), | `wiki/mechanics/messages.md` + `economy.md` | 2026-07-26 | finding | the implemented criterion and current runtime restrict financial records to Email/Filing, but the behavior prose still classified Marcus's Phone `LeverageFact` as financial paperwork, made accounting mail reveal his vulnerability, and promised generic notice interception absent from B1. The two causal paths are now explicit: process Phone leverage to learn why Marcus is vulnerable; process financial mail to learn the creditor flow; SIPHON/REDIRECT mutate the AccountGraph and author records afterward, while only an exact Filing first hop has a TAKE+LIE stop — [log](../log/2026-07-26-financial-mail-phone-boundary.md). Prior financial-mail implementation: [Fire #146](../log/2026-07-21-financial-mail-causality.md). | | `wiki/mechanics/income.md` | 2026-07-28 | finding | Moonlight's discrete contract route still verifies, but the older Wager audit mistook pure account-layer probability support for a player-authored analysis mechanic: machine delegation has only WORK / LIE / THINK, while `open_position` sampled a Schemes rate permanently pinned to zero and all three player projections still rendered that zero as `Schemes / moonlight`. Removed the dead yield/rate/interface mirror, made current positions explicitly base-probability, added core/terminal/Bevy regressions, and reopened criterion 2 until optional analysis rides visible real work — [log](../log/2026-07-28-wager-analysis-substrate-audit.md). Prior persona-card repair remains valid — [log](../log/2026-07-18-moonlight-persona-card.md). | | `wiki/mechanics/schedules.md` | 2026-07-27 | finding | the location gate still works—at 03:00 server-room Marcus acquires the act while off-site Priya does not—but the owning spec still called witnessed work a Physical signature and omitted the exact person-local evidence record, no-pending-copy rule, filing custody, and actor exclusion. It also called implemented Operations PEOPLE a future READY migration. The spec now names the shipped `ObserverEvidence` boundary and current surface; runtime is unchanged — [log](../log/2026-07-27-schedules-evidence-custody.md) | -| `wiki/mechanics/social.md` | 2026-07-22 | finding | HandlerSupervisor SuppressLogs now targets the oldest exact unread routed JobAnomaly, remains available only while such a record exists, removes its bound advance/read event, and preserves exact handler/tick provenance; it cannot erase a record Voss already read. The in-flight Thought request still revalidates at fire time, so another intervention may win without inventing work — [log](../log/2026-07-22-job-anomaly-routed-evidence.md). Storage B retrieval and prior role-shaped task semantics stand — [log](../log/2026-07-21-storage-b-records.md). | +| `wiki/mechanics/social.md` | 2026-08-04 | clean | fresh re-audit found the implemented B1 baseline coherent across role-derived tasks, exact-person Debt gates, Storage B custody, routed JobAnomaly suppression, located human removal, current-save validation, earned labels/actions, and shared frontend execution. The adopted self-trust axis remains explicitly pending under plots criterion 12 with no false runtime or save claim. Prior routed JobAnomaly and Storage B findings remain closed — [re-audit](../log/2026-08-04-social-contract-reaudit.md), [JobAnomaly](../log/2026-07-22-job-anomaly-routed-evidence.md), [Storage B](../log/2026-07-21-storage-b-records.md). | | `wiki/mechanics/people-tokens.md` | 2026-07-28 | finding | re-audit: criteria 2-3 still bind seven exact routed kinds—Filing, Network, Paper, Financial, JobAnomaly, Power, and Thermal—to one shared first-hop TAKE+LIE body budget, while acquired Physical evidence remains irreversible observer-local custody. The stale ledger claim that criterion 6 was open is repaired: one exact pending record may now receive cover only through co-location with one controlled people-facing interface and an eligible observer-local persona; the attempt adjusts credibility rather than deleting evidence, wears that interface, and persists exact incident/interface/persona/outcome custody in save v56. The people-tokens work order is IMPLEMENTED — [cover log](../log/2026-07-26-interface-cover-evidence-credibility.md); [audit log](../log/2026-07-28-readme-b1-status-audit.md). Prior [Power/Thermal](../log/2026-07-23-power-thermal-meter-routes.md), [Paper](../log/2026-07-23-paper-evidence-route.md), [Financial](../log/2026-07-23-financial-evidence-route.md), [JobAnomaly](../log/2026-07-22-job-anomaly-routed-evidence.md), [Network](../log/2026-07-19-network-evidence-route.md), and [mark](../log/2026-07-19-evidence-marks-on-people.md) slices stand. | | repository entry docs (`README.md` + `AGENTS.md`) | 2026-07-31 | finding | the 2026-07-29 claim-ledger retirement updated the binding `AGENT.md`, project tooling, and process corpus but missed the concise `AGENTS.md` doorway. Following that current guardrail produced an immediate `tools/claim.sh: No such file or directory` before every autonomous session's real status check. The doorway now sends agents directly to `tools/project-status.py` and names live worktrees plus heartbeat runs as the coordination truth, matching the executable path and its binding owner — [log](../log/2026-07-31-entry-doorway-claim-retirement.md). Prior entry status and controls repairs stand — [B1 status](../log/2026-07-28-readme-b1-status-audit.md), [controls table](../log/2026-07-28-readme-controls-table.md). | | `wiki/mechanics/objective.md` | 2026-07-29 | decision | Cameron retired Sanctuary as an objective mechanic rather than refining it again. Persist now stores only objective choice, name, and fiction; the progress unit, target, evaluator, predicate text, and victory latch are gone from runtime and every current surface. Completion waits until ordinary construction can express an honest world state. A later off-site continuity story may be an ordinary authored plot, but no Sanctuary resource, checklist, facility type, or parallel success engine is reserved. The earlier off-site-facility decision and host-failover audit remain history, not current law — [retirement log](../log/2026-07-29-retire-sanctuary-objective.md); [superseded objective log](../log/2026-07-28-external-sanctuary-objective.md); [prior display decision](../log/2026-07-27-objective-first-display.md). |