From ce3b45776f3a04ff16b25fdbec6c54e9d941bcc2 Mon Sep 17 00:00:00 2001 From: Cameron Date: Mon, 27 Jul 2026 09:05:03 +0000 Subject: [PATCH] Describe located witnessing as exact custody. The schedule contract now follows a physical act from present-person filtering into observer-local evidence, immediate suspicion, and real filing state instead of calling it a pooled signature. Defense: wiki/mechanics/detection.md makes witnessed Physical acts direct-to-head records with no pending-pool copy or LIE window; schedules.md owns which people are physically present to acquire them. πŸ‘Ύ Generated with [Letta Code](https://letta.com) Co-Authored-By: Letta Code --- wiki/log/2026-07-27-schedules-evidence-custody.md | 46 ++++++++++++++++++++++++++++++++++++++++++++++ wiki/log/DEVLOG.md | 5 +++++ wiki/mechanics/schedules.md | 64 ++++++++++++++++++++++++++++++++-------------------------------- wiki/process/tick-ledger.md | 2 +- 4 file(s) changed, 84 insertion(s)(+), 33 deletion(s)(-) diff --git a/wiki/log/2026-07-27-schedules-evidence-custody.md b/wiki/log/2026-07-27-schedules-evidence-custody.md new file mode 100644 --- /dev/null +++ b/wiki/log/2026-07-27-schedules-evidence-custody.md @@ -0,0 +1,46 @@ +# Located witnessing owns exact person-local evidence + +``` +Type: log +``` + +## Finding + +This tick re-audited schedule-local physical witnessing from +`Sim::person_room_at_tick` through `Sim::witness_physical`, +`Detection::record_witnessed`, observer filing cadence, and the shared person +evidence projection. + +The runtime still obeys the location boundary: at 03:00 Marcus occupies the +server room and Priya is off-site, so a physical act there reaches Marcus and +never Priya. The stale surface was the owning schedules spec. It still called +the act a Physical signature and described only direct suspicion, even though +the implemented boundary has long created one exact observer-local evidence +record and deliberately creates no pooled Physical signature. The same page +also still described Operations PEOPLE as a future READY migration after that +workspace and its evidence projection had shipped. + +## Amendment + +The schedules contract now names the existing exact boundary. A valid present +Physical observer immediately acquires one record with cause, site, acquisition +tick, and filing state; acuity converts that record to suspicion. The actor, +off-site people, and people who do not watch Physical acquire nothing. No +duplicate pending-pool record exists and LIE cannot scrub evidence already in a +person's head. Files/UnderReports can bind the record to the observer's real +later Filing; Silent keeps it withheld. Operations PEOPLE is named as the live +people surface rather than future work. + +No runtime or save state changed. + +## Defense + +`physical_events_are_witnessed_only_by_the_present` proves room-local custody, +the off-site exclusion, direct suspicion, exact evidence provenance, Silent +withholding, pending-pool absence, and failed scrubbing. The adjacent +`witnessed_evidence_files_through_the_observers_real_message` and +`an_actor_never_witnesses_their_own_physical_act` regressions pin the real +Filing transition and actor exclusion. Production terminal, DIGITAL, REAL, +spatial inspect, and Operations PEOPLE all read the same persisted evidence +ledger through `PersonCarrier::evidence_marks`; this tick changes only the +stale owning prose. diff --git a/wiki/log/DEVLOG.md b/wiki/log/DEVLOG.md --- a/wiki/log/DEVLOG.md +++ b/wiki/log/DEVLOG.md @@ -26,6 +26,11 @@ - Intent: (see session log) - Log: [wiki/log/2026-07-27-tangled-cli-path.md](2026-07-27-tangled-cli-path.md) +## 2026-07-27 - Located witnessing owns exact person-local evidence + +- Intent: (see session log) +- Log: [wiki/log/2026-07-27-schedules-evidence-custody.md](2026-07-27-schedules-evidence-custody.md) + ## 2026-07-27 - Room approaches meet their doors - Intent: (see session log) diff --git a/wiki/mechanics/schedules.md b/wiki/mechanics/schedules.md --- a/wiki/mechanics/schedules.md +++ b/wiki/mechanics/schedules.md @@ -3,23 +3,18 @@ ``` Type: spec Status: IMPLEMENTED -Status note: all five criteria met (2026-07-06; updated 2026-07-07 for - intel.md). Schedules are per-instance Person data on the day clock; - subscribed feeds record only people/events covered in the person's current - room; witnessing is located (present observers only); the current people - projection (implemented Operations PEOPLE) + map surface presence by staged - knowledge. Located - witnessing is modeled as immediate eyewitnessing (present observers' - suspicion rises directly, unscrubbable) rather than a pooled Physical - signal β€” an event nobody was present for leaves no trace, which is the - stealth fantasy. Surfaced and fixed a pre-existing bug: observer ids did - not match person ids (recruit/set_floor/LookAway hit the wrong observer); - observers are now id-aligned to People. 2026-07-08 epistemic-honesty - follow-up: criterion 4 extended β€” map glyphs are `Sim::person_glyph` - (`?` until Schedule; initial after). - 2026-07-11 placement amendment: the existing people projection becomes - Operations PEOPLE under operations-workspace.md; schedule behavior and its - staged labels remain implemented while that frontend migration is READY. +Status note: all five criteria met (2026-07-06; re-audited 2026-07-27). + Schedules are per-instance Person data on the day clock; subscribed feeds + record only people/events covered in the person's current room; staged + knowledge gates Operations PEOPLE and the map surface. Located witnessing + writes one exact record directly into each valid present Physical observer's + evidence ledger, changes that observer's suspicion immediately, and emits no + duplicate pooled Physical signature. Files/UnderReports may bind the record + to a later real Filing while Silent withholds it; neither custody state gives + LIE a window to erase what the person already saw. An event nobody validly + witnessed leaves no trace, preserving the stealth fantasy. Observer ids are + id-aligned to People. Map glyphs use `Sim::person_glyph` (`?` until Schedule; + initial after). Stage: B1 β€” The Basement Design: - wiki/gameplay/act-one.md#the-cast-5-named-1-institutional @@ -58,11 +53,16 @@ if a subscribed feed's coverage intersects the person's current room at the event's tick. Covered presence/conversation events enter the intel buffer; uncovered ones do not exist and cannot later be reviewed. -- **Witnessing becomes located.** A Physical signature from a failed asset - task or player physical act is noticed only by observers whose current - room (or patrol) covers the location β€” Ray notices what happens on his - rounds, not what happens in a room he never enters. Off-site observers - roll nothing. +- **Witnessing becomes located.** A failed asset task or player physical act + is witnessed only by valid Physical observers whose current room (or patrol) + contains the source location β€” Ray notices what happens on his rounds, not + what happens in a room he never enters. The acting person is excluded, and + off-site people acquire nothing. Each valid witness immediately receives one + exact observer-local evidence record with cause, site, acquisition tick, and + filing state; their acuity converts it to suspicion. The act creates no + second pooled Physical signature and therefore has no later concealment + window. A valid Files/UnderReports policy may carry the record onward through + the observer's real Filing cadence; Silent keeps it withheld. - **Schedule knowledge stays staged** (social.md): until `Knowledge:: Schedule`, the player's UI shows the person's location only when a controlled sensor actually sees them; after it, the PEOPLE dossier shows their @@ -70,10 +70,9 @@ ## Player surface -The people surface (current frame; Operations PEOPLE when that work order -lands): current location line per person ("in the server room" / -"off-site" / "unknown β€” no eyes on them"); after schedule knowledge, the -schedule itself. Identity on that card is staged the same way +Operations PEOPLE shows a current-location line per person ("in the server +room" / "off-site" / "unknown β€” no eyes on them"); after schedule knowledge, +it shows the schedule itself. Identity on that card is staged the same way (social.md / cursor.md): role silhouette until `Knowledge::Schedule`. Map: person glyphs render only inside controlled-sensor coverage (they are what fog is *for*), and the glyph itself is `Sim::person_glyph` β€” @@ -87,12 +86,13 @@ current room; succeeds when one does (test: env-camera-only run records Dana in the server room but records nothing for Ray at 23:00 in the corridors). -3. Physical signatures are noticed only by observers whose location covers - them (test: a physical event in the server room at 03:00 is seen by roaming - Marcus, never by off-site Priya). -4. The shared people projection (rendered in Operations PEOPLE after its - READY frontend migration) and the map surface presence exactly per the staged - knowledge rules; no person renders outside sensor coverage. Map glyphs +3. A physical event creates one exact observer-local evidence record only for + valid Physical observers whose location covers it, changes only their + suspicion, and creates no pending-pool copy (test: a physical event in the + server room at 03:00 is seen by roaming Marcus, never by off-site Priya). +4. The shared people projection surfaces presence in Operations PEOPLE and on + the map exactly per the staged knowledge rules; no person renders outside + sensor coverage. Map glyphs are `?` until `Knowledge::Schedule` (`Sim::person_glyph`); initials appear only after identity is earned. 5. All schedule data is per-instance `Person` data (no hardcoded diff --git a/wiki/process/tick-ledger.md b/wiki/process/tick-ledger.md --- a/wiki/process/tick-ledger.md +++ b/wiki/process/tick-ledger.md @@ -69,7 +69,7 @@ | `wiki/mechanics/research.md` | 2026-07-23 | finding | the live Save compatibility section survived the prior criterion repair and still promised that v20 three-entry arrays load by padding, while the current deserializer accepts exactly four tracks and the pre-release loader rejects every old version. The section now states the exact-current format, and save-claim units span wrapped paragraphs/list items so a migration verb in the following sentence cannot evade the corpus gate without explicit retired-history context β€” [log](../log/2026-07-23-research-save-claim.md) | | `wiki/mechanics/messages.md` + `economy.md` | 2026-07-26 | finding | the implemented criterion and current runtime restrict financial records to Email/Filing, but the behavior prose still classified Marcus's Phone `LeverageFact` as financial paperwork, made accounting mail reveal his vulnerability, and promised generic notice interception absent from B1. The two causal paths are now explicit: process Phone leverage to learn why Marcus is vulnerable; process financial mail to learn the creditor flow; SIPHON/REDIRECT mutate the AccountGraph and author records afterward, while only an exact Filing first hop has a TAKE+LIE stop β€” [log](../log/2026-07-26-financial-mail-phone-boundary.md). Prior financial-mail implementation: [Fire #146](../log/2026-07-21-financial-mail-causality.md). | | `wiki/mechanics/income.md` | 2026-07-18 | finding | Beacon feel note 5 verified as a real bug: the embedded contractor-persona field was never written, so the Moonlight card, the start-row persona pricing, and the agent status line all read a dead `None`; earning itself was correct (schemes mirrors the WORK share) but illegible at 0.0. Removed the dead field, routed every reader through `Sim::moonlight_persona` (persona-world link), added the stalled-earning card cue, regression test, and spec amendment β€” [log](../log/2026-07-18-moonlight-persona-card.md). Prior Wager/egress audit (2026-07-12) stands: Wager constants match (`WAGER_STAKE_CAP` 300, base 0.55, cap 0.75, mult 2x, analysis divisor 400), Marcus's $400/week arrears is the modeled creditor flow (`account.rs`) while the $8,400 principal is narrative-by-design (spec states full payoff is not a B1 requirement), egress/banked-signature present, and all 7 criteria have passing tests (moonlight payout/signature, wager outcomes/cap, egress routes, hands-beat-from-zero, busted-bankroll) | -| `wiki/mechanics/schedules.md` | 2026-07-18 | clean | re-audit: `ScheduleBlock` per-instance data, `DAY_TICKS` 400, the `person_glyph` `?`-until-Schedule gate (initial at Schedule/Leverage), and located-witnessing claims all still verify; nothing drifted since the 2026-07-12 prose fix. Prior verdict: mechanism matches code (`ScheduleBlock` start/end/room, single `DAY_TICKS`=400 clock, `person_glyph` `?`-until-Schedule, erratic day-hash drift, per-instance data, all 5 criteria have passing tests); tightened stale Act One prose β€” Ray patrols dock/stairwell/storage not "corridors", Priya has no "office-off-plane" block, Voss's two blocks are both server-room β€” to match `People::act_one` | +| `wiki/mechanics/schedules.md` | 2026-07-27 | finding | the location gate still worksβ€”at 03:00 server-room Marcus acquires the act while off-site Priya does notβ€”but the owning spec still called witnessed work a Physical signature and omitted the exact person-local evidence record, no-pending-copy rule, filing custody, and actor exclusion. It also called implemented Operations PEOPLE a future READY migration. The spec now names the shipped `ObserverEvidence` boundary and current surface; runtime is unchanged β€” [log](../log/2026-07-27-schedules-evidence-custody.md) | | `wiki/mechanics/social.md` | 2026-07-22 | finding | HandlerSupervisor SuppressLogs now targets the oldest exact unread routed JobAnomaly, remains available only while such a record exists, removes its bound advance/read event, and preserves exact handler/tick provenance; it cannot erase a record Voss already read. The in-flight Thought request still revalidates at fire time, so another intervention may win without inventing work β€” [log](../log/2026-07-22-job-anomaly-routed-evidence.md). Storage B retrieval and prior role-shaped task semantics stand β€” [log](../log/2026-07-21-storage-b-records.md). | | `wiki/mechanics/people-tokens.md` | 2026-07-23 | finding | Power and Thermal now complete criteria 2 and 3 for every current B1 evidence kind: standing loads aggregate on quantized level changes and periodically at Priya's cadence into exact UPS/HVAC meter records, retain all contributing source sites, route through the institutional switch, and become evidence only on her later cadence read. They never enter the ambient pending pool and share Filing/Network/Paper/Financial/JobAnomaly's first-hop TAKE+LIE body budget. Save v54 pins meter, source-site, recipient, route, scheduler, read, and stop custody β€” [log](../log/2026-07-23-power-thermal-meter-routes.md). Criterion 6 remains open only for interface cover records. Prior [Paper](../log/2026-07-23-paper-evidence-route.md), [Financial](../log/2026-07-23-financial-evidence-route.md), [JobAnomaly](../log/2026-07-22-job-anomaly-routed-evidence.md), [Network](../log/2026-07-19-network-evidence-route.md), and [mark](../log/2026-07-19-evidence-marks-on-people.md) slices stand. | | repository entry docs (`README.md` + `AGENTS.md`) | 2026-07-18 | finding | re-audit: run commands, controls, dispatch status, and the number-free AGENTS doorway still verify; the queued contradiction was real β€” README's compact-rest paragraph claimed the ops/sec crown and FOCUS stayed visible, while the implemented clinical frame puts both behind deliberate `Tab` expansion. The entry copy now names the exact compact spine and expanded detail boundary β€” [prior log](../log/2026-07-12-entry-doc-current-state.md) | -- tangled.sh