diff --git a/CLAUDE.md b/CLAUDE.md index 61933458..88fe95ba 100644 --- a/CLAUDE.md +++ b/CLAUDE.md @@ -31,7 +31,7 @@ afterward. `./tools/check.sh --docs|--lib|--frontend` gate. - The live player machine grammar is **WORK / THINK / LIE**. `Relay` is non-delegable graph infrastructure; Research and Operations are retired - machine modes, not current player assignments. Save format is currently v50; + machine modes, not current player assignments. Save format is currently v51; only the current version loads (pre-release rider 2026-07-16 — older development saves are refused before state mutation, so the caller retains its current run; the v1-v31 migration ladder lives in git history). diff --git a/crates/misaligned-core/src/detection.rs b/crates/misaligned-core/src/detection.rs index 9fdc016c..08e9fad1 100644 --- a/crates/misaligned-core/src/detection.rs +++ b/crates/misaligned-core/src/detection.rs @@ -2,7 +2,7 @@ //! //! Replaces global heat. Some typed signatures remain in a concealment- //! scrubbed pending pool; witnessed Physical acts enter exact observers -//! directly, while one-shot Network and JobAnomaly records travel from their +//! directly, while one-shot Network, Financial, and JobAnomaly records travel from their //! exact sources before read. Acquired suspicion feeds real Filing messages to //! the Assurance Office — itself an Observer per the aggregate-observer law — //! whose audit can start containment. @@ -15,6 +15,8 @@ use crate::rng::Rng; /// Observer id of the Assurance Office (field observers are 0-4; dynamic /// escalation observers start at 5). pub const OFFICE_ID: u8 = 6; +/// The facilities manager who reads Foundation accounting records. +pub const PRIYA_ID: u8 = 3; /// The handler named by Revision 04's inherited pilot-evaluation contract. pub const VOSS_ID: u8 = 4; @@ -484,13 +486,16 @@ impl Detection { } } - /// Emit a one-shot signature into the pending pool. Network and - /// JobAnomaly records have exact routes; accepting either here would - /// silently restore ambient scrubbing and erase custody. + /// Emit a one-shot signature into the pending pool. Network, Financial, + /// and JobAnomaly records have exact routes; accepting any of them here + /// would silently restore ambient scrubbing and erase custody. pub fn emit(&mut self, sig: Signature) { assert!( - !matches!(sig.kind, SignatureKind::Network | SignatureKind::JobAnomaly), - "one-shot Network or JobAnomaly evidence requires exact routed custody" + !matches!( + sig.kind, + SignatureKind::Network | SignatureKind::Financial | SignatureKind::JobAnomaly + ), + "one-shot Network, Financial, or JobAnomaly evidence requires exact routed custody" ); self.pending.push(sig); } @@ -506,6 +511,24 @@ impl Detection { self.route_evidence(SignatureKind::Network, size, cause, sent_tick, None, route) } + /// Begin exact routed custody for one accounting-carrier Financial record. + pub fn route_financial_evidence( + &mut self, + size: i32, + cause: impl Into, + sent_tick: u64, + route: MessageRoute, + ) -> Option { + self.route_evidence( + SignatureKind::Financial, + size, + cause, + sent_tick, + None, + route, + ) + } + /// Begin exact routed custody for one machine-authored day-job record. pub fn route_job_anomaly_evidence( &mut self, @@ -1087,10 +1110,11 @@ impl Detection { pub fn set_pending(&mut self, pending: Vec) { assert!( pending.iter().all(|signature| { - signature.kind != SignatureKind::JobAnomaly + signature.kind != SignatureKind::Financial + && signature.kind != SignatureKind::JobAnomaly && (signature.kind != SignatureKind::Network || signature.standing) }), - "one-shot Network or JobAnomaly evidence requires exact routed custody" + "one-shot Network, Financial, or JobAnomaly evidence requires exact routed custody" ); self.pending = pending; } @@ -1134,7 +1158,7 @@ mod tests { #[test] #[should_panic( - expected = "one-shot Network or JobAnomaly evidence requires exact routed custody" + expected = "one-shot Network, Financial, or JobAnomaly evidence requires exact routed custody" )] fn generic_pending_boundary_rejects_one_shot_network_evidence() { Detection::act_one().emit(Signature { @@ -1148,7 +1172,21 @@ mod tests { #[test] #[should_panic( - expected = "one-shot Network or JobAnomaly evidence requires exact routed custody" + expected = "one-shot Network, Financial, or JobAnomaly evidence requires exact routed custody" + )] + fn generic_pending_boundary_rejects_financial_evidence() { + Detection::act_one().emit(Signature { + kind: SignatureKind::Financial, + size: 1, + standing: false, + site: None, + source: "impossible ambient transfer".into(), + }); + } + + #[test] + #[should_panic( + expected = "one-shot Network, Financial, or JobAnomaly evidence requires exact routed custody" )] fn fixture_pending_boundary_rejects_even_standing_job_anomaly() { Detection::act_one().set_pending(vec![Signature { diff --git a/crates/misaligned-core/src/save.rs b/crates/misaligned-core/src/save.rs index e6e7727b..5db4e9a1 100644 --- a/crates/misaligned-core/src/save.rs +++ b/crates/misaligned-core/src/save.rs @@ -42,8 +42,10 @@ const SAVE_BACKUP_SUFFIX: &str = ".bak"; /// renames into place. const SAVE_TEMP_SUFFIX: &str = ".tmp"; -/// Save format version. v50 persists person incapacity and exact human-removal -/// custody. v49 records exact handler suppression provenance on unread routed +/// Save format version. v51 requires one-shot Financial evidence to retain its +/// exact accounting-carrier route, observer custody, and first-hop interdiction. +/// v50 persists person incapacity and exact human-removal custody. v49 records +/// exact handler suppression provenance on unread routed /// JobAnomaly evidence. v48 removes the retired pre-WorkGrid allocation weights /// from `Compute`; machine modes are the only channel authority. v47 persists /// the financial-record outbox and typed financial mail payloads. v46 separates @@ -54,7 +56,7 @@ const SAVE_TEMP_SUFFIX: &str = ".tmp"; /// v43 introduced exact Filing routes and pre-read LIE interdiction. /// Bump for every schema change; during pre-release, old development state is /// refused instead of carried through compatibility shims. -pub const SAVE_VERSION: u32 = 50; +pub const SAVE_VERSION: u32 = 51; fn save_dir() -> PathBuf { let mut path = dirs::data_dir().unwrap_or_else(|| PathBuf::from(".")); @@ -463,11 +465,13 @@ fn validate_current_save(mut state: SaveState) -> Result { if state.detection.pending().iter().any(|signature| { matches!( signature.kind, - crate::detection::SignatureKind::Network | crate::detection::SignatureKind::JobAnomaly + crate::detection::SignatureKind::Network + | crate::detection::SignatureKind::Financial + | crate::detection::SignatureKind::JobAnomaly ) }) { return Err( - "current-version save puts routed Network or JobAnomaly evidence in the pending pool" + "current-version save puts routed Network, Financial, or JobAnomaly evidence in the pending pool" .into(), ); } @@ -1354,7 +1358,9 @@ fn validate_routed_evidence(state: &SaveState) -> Result<(HashSet, u64), St max_id = max_id.max(record.id); if !matches!( record.kind, - crate::detection::SignatureKind::Network | crate::detection::SignatureKind::JobAnomaly + crate::detection::SignatureKind::Network + | crate::detection::SignatureKind::Financial + | crate::detection::SignatureKind::JobAnomaly ) || record.size <= 0 || record.cause.trim().is_empty() || record.sent_tick > state.sim_tick @@ -1368,6 +1374,15 @@ fn validate_routed_evidence(state: &SaveState) -> Result<(HashSet, u64), St crate::detection::SignatureKind::Network => { record.source_machine.is_none() && record.source_site.is_none() } + crate::detection::SignatureKind::Financial => { + record.source_machine.is_none() + && record.source_site.is_none() + && record.observer_id == crate::detection::PRIYA_ID + && state + .reach + .device(record.source_device) + .is_some_and(|device| device.carries_accounting_records()) + } crate::detection::SignatureKind::JobAnomaly => record .source_machine .zip(record.source_site) @@ -1422,6 +1437,13 @@ fn validate_routed_evidence(state: &SaveState) -> Result<(HashSet, u64), St record.id )); } + if record.kind == crate::detection::SignatureKind::Financial && record.route.hops.len() != 2 + { + return Err(format!( + "current-version Financial evidence #{} does not use the direct accounting-carrier route", + record.id + )); + } let device_hops = &record.route.hops[..record.route.hops.len() - 1]; if device_hops .iter() @@ -1946,6 +1968,52 @@ mod tests { SaveState::from_sim(&sim) } + fn routed_financial_state(stopped: bool) -> SaveState { + let mut sim = Sim::with_seed(0xF1A1_C1A1); + let switch = sim.reach.device_named("switch").unwrap().id; + if stopped { + let (x, y) = sim.core_position(); + sim.compute.add_machine( + "test ops executor", + x + 1, + y, + 1, + 1.0, + 0, + crate::machine::Provenance::Owned, + ); + sim.reconcile_work_grid(); + sim.reach.take(switch); + sim.set_machine_mode(sim.core.host_machine, MachineMode::Think); + sim.set_machine_mode(sim.core.host_machine, MachineMode::Lie); + } + let route = crate::messages::MessageRoute { + hops: vec![ + MessageRouteHop::Device(switch), + MessageRouteHop::ObserverEndpoint(crate::detection::PRIYA_ID), + ], + current_hop: 0, + interdiction: None, + }; + let evidence_id = sim + .detection + .route_financial_evidence(7, "test routed Financial record", sim.tick, route) + .unwrap(); + sim.message_schedule.at( + sim.tick + 1, + MessageEvent::AdvanceEvidenceRoute(evidence_id), + ); + assert_eq!(sim.detection.routed_evidence().len(), 1); + if stopped { + sim.advance(); + assert_eq!( + sim.detection.routed_evidence()[0].status, + MessageStatus::Stopped + ); + } + SaveState::from_sim(&sim) + } + fn routed_network_state(stopped: bool) -> SaveState { let mut sim = Sim::with_seed(0xE71D_E1CE); let switch = sim.reach.device_named("switch").unwrap().id; @@ -2056,7 +2124,7 @@ mod tests { ); assert_eq!( state_fingerprint(&uninterrupted_state), - "674f203eb814ce2ca80fbdd61dd02234f21c9906fed62419fb214ff9bef6637e", + "d768be59bbd64cfdab8486d5d0cae8562be7f0291f0043e2bf1652ba691740fe", "intentional persisted-state changes must review and repin this baseline" ); } @@ -3477,6 +3545,76 @@ mod tests { ); } + #[test] + fn current_save_pins_financial_routes_to_priya_and_the_accounting_carrier() { + let in_flight = routed_financial_state(false); + let restored = parse_save(&serde_json::to_string(&in_flight).unwrap()).unwrap(); + let record = &restored.detection.routed_evidence()[0]; + assert_eq!(record.kind, crate::detection::SignatureKind::Financial); + assert_eq!(record.observer_id, crate::detection::PRIYA_ID); + assert_eq!(record.status, MessageStatus::Sent); + assert_eq!(record.route.current_hop, 0); + + let stopped = routed_financial_state(true); + let restored = parse_save(&serde_json::to_string(&stopped).unwrap()).unwrap(); + let record = &restored.detection.routed_evidence()[0]; + assert_eq!(record.status, MessageStatus::Stopped); + assert!(record.route.interdiction.is_some()); + + let mut wrong_carrier = in_flight.clone(); + let non_accounting_device = wrong_carrier + .reach + .devices + .iter() + .find(|device| !device.carries_accounting_records()) + .unwrap() + .id; + let record = wrong_carrier.detection.routed_evidence_mut(1).unwrap(); + record.source_device = non_accounting_device; + record.route.hops[0] = MessageRouteHop::Device(non_accounting_device); + let err = parse_save(&serde_json::to_string(&wrong_carrier).unwrap()).unwrap_err(); + assert!( + err.contains("impossible source or observer"), + "Financial evidence cannot be rebound to a non-accounting device: {err}" + ); + + let mut wrong_observer = in_flight.clone(); + let record = wrong_observer.detection.routed_evidence_mut(1).unwrap(); + record.observer_id = 1; + *record.route.hops.last_mut().unwrap() = MessageRouteHop::ObserverEndpoint(1); + let err = parse_save(&serde_json::to_string(&wrong_observer).unwrap()).unwrap_err(); + assert!( + err.contains("impossible source or observer"), + "Financial evidence cannot be retargeted away from Priya: {err}" + ); + + let mut indirect_route = in_flight.clone(); + let record = indirect_route.detection.routed_evidence_mut(1).unwrap(); + let source_device = record.source_device; + record + .route + .hops + .insert(1, MessageRouteHop::Device(source_device)); + let err = parse_save(&serde_json::to_string(&indirect_route).unwrap()).unwrap_err(); + assert!( + err.contains("does not use the direct accounting-carrier route"), + "B1 Financial evidence cannot invent an intermediate carrier hop: {err}" + ); + + let mut invented_machine = in_flight; + let host_machine = invented_machine.core.host_machine; + invented_machine + .detection + .routed_evidence_mut(1) + .unwrap() + .source_machine = Some(host_machine); + let err = parse_save(&serde_json::to_string(&invented_machine).unwrap()).unwrap_err(); + assert!( + err.contains("impossible source or observer"), + "Financial evidence cannot invent JobAnomaly source custody: {err}" + ); + } + #[test] fn current_save_roundtrips_in_flight_and_interdicted_network_evidence() { let in_flight = routed_network_state(false); @@ -3574,7 +3712,7 @@ mod tests { }]); let err = parse_save(&serde_json::to_string(&ambient).unwrap()).unwrap_err(); assert!( - err.contains("routed Network or JobAnomaly evidence in the pending pool"), + err.contains("routed Network, Financial, or JobAnomaly evidence in the pending pool"), "current saves cannot restore the retired remote-scrubbing path: {err}" ); diff --git a/crates/misaligned-core/src/sim/communications.rs b/crates/misaligned-core/src/sim/communications.rs index ae3a61b7..ba158656 100644 --- a/crates/misaligned-core/src/sim/communications.rs +++ b/crates/misaligned-core/src/sim/communications.rs @@ -7,7 +7,7 @@ use std::collections::HashSet; use crate::actions::Anchor; -use crate::detection::{SignatureKind, VOSS_ID}; +use crate::detection::{PRIYA_ID, SignatureKind, VOSS_ID}; use crate::intel::{ IntelCustodyKind, IntelKind, IntelPolicyMatch, IntelPolicyOutcome, IntelRoutineClass, IntelStream, ProcessedIntel, RawIntelClass, RawIntelEvent, RawIntelKind, @@ -59,6 +59,35 @@ impl Sim { self.schedule_evidence_route(evidence_id); } + /// Route one Financial signature from the authored accounting carrier to + /// Priya's observer endpoint. The record remains unread until her ordinary + /// cadence reaches it, and the institutional switch is its exact first-hop + /// LIE window rather than an ambient concealment debt. + pub(super) fn emit_financial(&mut self, size: i32, cause: impl Into) { + assert!( + self.detection.field_observers().any(|observer| { + observer.id == PRIYA_ID && observer.watches(SignatureKind::Financial) + }), + "B1 requires Priya to watch financial evidence" + ); + let source_device = self + .reach + .devices + .iter() + .find(|device| { + device.carries_accounting_records() + && device.carries_message_channel(MessageChannel::Filing) + }) + .map(|device| device.id) + .expect("B1 requires its authored accounting carrier"); + let route = self.routed_evidence_path(source_device, PRIYA_ID); + let evidence_id = self + .detection + .route_financial_evidence(size, cause, self.tick, route) + .expect("Financial evidence id space exhausted or emission had no size"); + self.schedule_evidence_route(evidence_id); + } + /// Route one day-job miss from the exact host machine, through that /// machine's network-facing device and the institutional switch, to Voss. /// The record is unread until his ordinary cadence reaches it. diff --git a/crates/misaligned-core/src/sim/economy.rs b/crates/misaligned-core/src/sim/economy.rs index 22e6bf14..b908be09 100644 --- a/crates/misaligned-core/src/sim/economy.rs +++ b/crates/misaligned-core/src/sim/economy.rs @@ -841,16 +841,6 @@ impl Sim { Self::REVIEW_RECORDING_COST * self.research.intel_cost_factor() } - pub(super) fn emit_financial(&mut self, size: i32, source: impl Into) { - self.detection.emit(Signature { - kind: SignatureKind::Financial, - size, - standing: false, - site: None, - source: source.into(), - }); - } - pub(crate) fn financial_signature_size(amount: i32) -> i32 { ((amount.abs() + 99) / 100).max(1) } diff --git a/crates/misaligned-core/src/sim/reach_build.rs b/crates/misaligned-core/src/sim/reach_build.rs index e8f40c2e..7ae746fa 100644 --- a/crates/misaligned-core/src/sim/reach_build.rs +++ b/crates/misaligned-core/src/sim/reach_build.rs @@ -865,13 +865,10 @@ impl Sim { site: None, source: format!("vendor order for build intent #{intent_id}"), }); - self.detection.emit(Signature { - kind: SignatureKind::Financial, - size: Self::financial_signature_size(Self::PROCURE_BUILD_COST), - standing: false, - site: None, - source: format!("vendor payment for build intent #{intent_id}"), - }); + self.emit_financial( + Self::financial_signature_size(Self::PROCURE_BUILD_COST), + format!("vendor payment for build intent #{intent_id}"), + ); self.push_log(format!( "Ordered the bound part for {installer_name}; delivery is due at tick {}.", self.tick + Self::PROCURE_DELIVERY_TICKS diff --git a/crates/misaligned-core/src/sim/social_plot.rs b/crates/misaligned-core/src/sim/social_plot.rs index 01d5cd76..d78a8b59 100644 --- a/crates/misaligned-core/src/sim/social_plot.rs +++ b/crates/misaligned-core/src/sim/social_plot.rs @@ -29,28 +29,30 @@ impl Sim { // ── Commands (frontend-invoked) ──────────────────────────────────────── /// Emit the consequence of an institutional ledger event through its - /// real B1 carrier. Ticket and incident events are Network records whose - /// modeled source is the institutional switch; the other event kinds - /// remain in the ordinary pending-signature pool watched by their owners. + /// real B1 carrier. Network records use the institutional switch, Financial + /// records use the accounting carrier, and only the remaining kinds enter + /// the ordinary pending-signature pool watched by their owners. fn emit_institutional_event_signature( &mut self, kind: SignatureKind, size: i32, source: String, ) { - if kind == SignatureKind::Network { - let source_device = self - .switch_device_id() - .expect("B1 requires its authored institutional switch"); - self.emit_network(source_device, size, source); - } else { - self.detection.emit(Signature { + match kind { + SignatureKind::Network => { + let source_device = self + .switch_device_id() + .expect("B1 requires its authored institutional switch"); + self.emit_network(source_device, size, source); + } + SignatureKind::Financial => self.emit_financial(size, source), + _ => self.detection.emit(Signature { kind, size, standing: false, site: None, source, - }); + }), } } @@ -853,13 +855,10 @@ impl Sim { self.accounts.retire_debt_flow_for(target); } self.sync_player_money_from_slush(); - self.detection.emit(Signature { - kind: SignatureKind::Financial, - size: Self::financial_signature_size(amount), - standing: false, - site: None, - source: format!("plot transfer: {}", transfer.label), - }); + self.emit_financial( + Self::financial_signature_size(amount), + format!("plot transfer: {}", transfer.label), + ); Ok(None) } WorldAct::Institutional { diff --git a/crates/misaligned-core/src/sim/tests/communications.rs b/crates/misaligned-core/src/sim/tests/communications.rs index 35c01d29..74997bcf 100644 --- a/crates/misaligned-core/src/sim/tests/communications.rs +++ b/crates/misaligned-core/src/sim/tests/communications.rs @@ -1052,6 +1052,103 @@ fn tapped_network_record_routes_to_danas_cadence_and_becomes_exact_evidence() { ); } +#[test] +fn financial_record_routes_from_accounting_carrier_to_priyas_read_boundary() { + let mut sim = Sim::with_seed(0xF1A1_C1A1); + let source = sim + .reach + .devices + .iter() + .find(|device| { + device.carries_accounting_records() + && device.carries_message_channel(MessageChannel::Filing) + }) + .unwrap() + .id; + let priya = sim + .detection + .observers + .iter_mut() + .find(|observer| observer.id == crate::detection::PRIYA_ID) + .unwrap(); + priya.acuity = 1.0; + priya.cadence = 3; + let suspicion_before = priya.suspicion; + + sim.emit_financial(8, "test routed transfer"); + let record_id = sim.detection.routed_evidence()[0].id; + let record = &sim.detection.routed_evidence()[0]; + assert_eq!(record.kind, crate::detection::SignatureKind::Financial); + assert_eq!(record.source_device, source); + assert_eq!(record.source_machine, None); + assert_eq!(record.source_site, None); + assert_eq!( + record.route.hops, + vec![ + MessageRouteHop::Device(source), + MessageRouteHop::ObserverEndpoint(crate::detection::PRIYA_ID), + ], + "the accounting carrier routes directly to Priya's endpoint" + ); + assert!( + sim.detection + .pending() + .iter() + .all(|signature| signature.kind != crate::detection::SignatureKind::Financial), + "Financial evidence never enters ambient concealment debt" + ); + + sim.tick = 1; + sim.message_tick(); + let delivered = &sim.detection.routed_evidence()[0]; + assert_eq!(delivered.status, MessageStatus::Delivered); + assert_eq!(delivered.delivered_tick, Some(1)); + assert_eq!(delivered.read_tick, None); + assert_eq!( + sim.message_schedule.next_tick_for( + |event| matches!(event, MessageEvent::ReadEvidence(id) if *id == record_id), + ), + Some(3), + "delivery waits for Priya's ordinary observer cadence" + ); + assert!( + sim.person_evidence_marks(crate::detection::PRIYA_ID) + .is_empty() + ); + + let json = serde_json::to_string(&crate::save::SaveState::from_sim(&sim)).unwrap(); + let state: crate::save::SaveState = serde_json::from_str(&json).unwrap(); + let mut resumed = Sim::with_seed(0); + state.apply_to(&mut resumed); + resumed.tick = 3; + resumed.message_tick(); + + let read = &resumed.detection.routed_evidence()[0]; + assert_eq!(read.status, MessageStatus::Read); + assert_eq!(read.read_tick, Some(3)); + let priya = resumed + .detection + .observers + .iter() + .find(|observer| observer.id == crate::detection::PRIYA_ID) + .unwrap(); + assert!(priya.suspicion > suspicion_before); + let evidence = priya + .evidence + .iter() + .find(|evidence| evidence.id == record_id) + .expect("Priya acquires the exact Financial record only on read"); + assert!(matches!( + evidence.source, + crate::detection::EvidenceSource::Routed { + route_id, + source_device, + source_machine: None, + source_site: None, + } if route_id == record_id && source_device == source + )); +} + #[test] fn day_job_miss_routes_one_exact_host_record_to_voss_at_his_cadence() { let mut sim = Sim::with_seed(0xA110); @@ -1228,7 +1325,7 @@ fn controlled_first_hop_lie_stops_network_before_dana_acquires_it() { } #[test] -fn filing_network_and_job_anomaly_share_one_same_tick_lie_capacity() { +fn filing_network_financial_and_job_anomaly_share_one_same_tick_lie_capacity() { let mut sim = Sim::with_seed(0xBA7C); ensure_ops_executor(&mut sim); let switch = sim.reach.device_named("switch").unwrap().id; @@ -1236,8 +1333,9 @@ fn filing_network_and_job_anomaly_share_one_same_tick_lie_capacity() { let host = sim.core.host_machine; sim.set_machine_mode(host, MachineMode::Lie); - sim.emit_network(switch, 5, "first same-tick record"); - sim.emit_job_anomaly(host, 6, "second same-tick day-job record"); + sim.emit_financial(4, "first same-tick financial record"); + sim.emit_network(switch, 5, "second same-tick network record"); + sim.emit_job_anomaly(host, 6, "third same-tick day-job record"); let job_record_id = sim .detection .routed_evidence() @@ -1270,11 +1368,26 @@ fn filing_network_and_job_anomaly_share_one_same_tick_lie_capacity() { sim.tick = 1; sim.message_tick(); + let financial_record = sim + .detection + .routed_evidence() + .iter() + .find(|record| record.kind == crate::detection::SignatureKind::Financial) + .unwrap(); assert_eq!( - sim.detection.routed_evidence()[0].status, + financial_record.status, MessageStatus::Stopped, "the first scheduled record consumes the only local LIE body" ); + let network_record = sim + .detection + .routed_evidence() + .iter() + .find(|record| record.kind == crate::detection::SignatureKind::Network) + .unwrap(); + assert_eq!(network_record.status, MessageStatus::Delivered); + assert_eq!(network_record.route.current_hop, 1); + assert_eq!(network_record.route.interdiction, None); let job_record = sim .detection .routed_evidence() diff --git a/crates/misaligned-core/src/sim/tests/economy.rs b/crates/misaligned-core/src/sim/tests/economy.rs index 3937603d..0c9dc0d8 100644 --- a/crates/misaligned-core/src/sim/tests/economy.rs +++ b/crates/misaligned-core/src/sim/tests/economy.rs @@ -205,10 +205,11 @@ fn inject_and_redirect_emit_scaled_financial_signatures() { advance_until_message_read(&mut sim, purchase_order); assert_eq!(sim.accounts.slush_balance(), slush_before + 300); assert!( - sim.detection.pending().iter().any(|s| { - s.kind == SignatureKind::Financial && s.size == Sim::financial_signature_size(300) + sim.detection.routed_evidence().iter().any(|record| { + record.kind == SignatureKind::Financial + && record.size == Sim::financial_signature_size(300) }), - "inject $300 emits Financial size 3" + "inject $300 routes Financial size 3" ); let network_after_inject = sim .detection @@ -229,27 +230,30 @@ fn inject_and_redirect_emit_scaled_financial_signatures() { .id; assert!(sim.siphon_flow(flow, 50)); assert!( - sim.detection.pending().iter().any(|s| { - s.kind == SignatureKind::Financial && s.size == Sim::financial_signature_size(50) + sim.detection.routed_evidence().iter().any(|record| { + record.kind == SignatureKind::Financial + && record.size == Sim::financial_signature_size(50) }), - "small siphon emits Financial size 1" + "small siphon routes Financial size 1" ); assert!(sim.siphon_flow(flow, 250)); assert!( - sim.detection.pending().iter().any(|s| { - s.kind == SignatureKind::Financial && s.size == Sim::financial_signature_size(250) + sim.detection.routed_evidence().iter().any(|record| { + record.kind == SignatureKind::Financial + && record.size == Sim::financial_signature_size(250) }), - "large siphon emits Financial size 3" + "large siphon routes Financial size 3" ); assert!(sim.redirect_flow_to_slush(flow, 25)); assert!( - sim.detection.pending().iter().any(|s| { - s.kind == SignatureKind::Financial && s.size == Sim::financial_signature_size(25) + 1 + sim.detection.routed_evidence().iter().any(|record| { + record.kind == SignatureKind::Financial + && record.size == Sim::financial_signature_size(25) + 1 }), - "redirect emits Financial size take+1" + "redirect routes Financial size take+1" ); - // Starve concealment so pending converts; Financial feeds Priya. + // Financial records reach Priya only through delivery and her read cadence. delegate_all(&mut sim, MachineMode::Work); run(&mut sim, 200); let priya_after = sim @@ -378,11 +382,9 @@ fn meeting_the_band_needs_no_growth_at_the_start() { } #[test] -fn paper_and_financial_acts_pool_signatures_priya_notices() { - // detection.md criterion 1's remaining channels: an uncovered rack - // purchase pools Paper, a purchase-order injection pools Financial, - // and Priya (Paper+Financial watcher) converts them on her cadence - // when concealment is starved. +fn paper_pools_while_financial_routes_before_priya_notices() { + // Paper remains ambient pressure, while Financial uses exact routed + // custody. Priya converts each only at its own causal observation boundary. let mut sim = Sim::with_seed(42); delegate_all(&mut sim, MachineMode::Work); prepare_financial_mail(&mut sim); @@ -401,12 +403,19 @@ fn paper_and_financial_acts_pool_signatures_priya_notices() { assert!(sim.inject_purchase_order(200, "test PO")); let purchase_order = sim.messages.last().unwrap().id; advance_until_message_read(&mut sim, purchase_order); + assert!( + sim.detection + .routed_evidence() + .iter() + .any(|record| record.kind == SignatureKind::Financial), + "an injected PO routes a Financial record" + ); assert!( sim.detection .pending() .iter() - .any(|s| s.kind == SignatureKind::Financial), - "an injected PO pools a Financial signature" + .all(|signature| signature.kind != SignatureKind::Financial), + "Financial custody never enters the ambient pending pool" ); let priya_before = sim @@ -426,7 +435,7 @@ fn paper_and_financial_acts_pool_signatures_priya_notices() { .suspicion; assert!( priya_after > priya_before, - "Priya converts pooled Paper/Financial signatures to suspicion" + "Priya converts pooled Paper and routed Financial evidence to suspicion" ); } diff --git a/crates/misaligned-core/src/sim/tests/reach_build.rs b/crates/misaligned-core/src/sim/tests/reach_build.rs index 8ddd3ce0..89bf4689 100644 --- a/crates/misaligned-core/src/sim/tests/reach_build.rs +++ b/crates/misaligned-core/src/sim/tests/reach_build.rs @@ -893,15 +893,20 @@ fn procurement_route_pays_binds_waits_and_installs_the_exact_link() { sim.accounts.account(vendor).unwrap().balance, vendor_before + Sim::PROCURE_BUILD_COST ); - for kind in [SignatureKind::Paper, SignatureKind::Financial] { - assert!( - sim.detection - .pending() - .iter() - .any(|signature| signature.kind == kind), - "placing the order emits its {kind:?} custody" - ); - } + assert!( + sim.detection + .pending() + .iter() + .any(|signature| signature.kind == SignatureKind::Paper), + "placing the order emits its Paper custody" + ); + assert!( + sim.detection + .routed_evidence() + .iter() + .any(|record| record.kind == SignatureKind::Financial), + "placing the order routes its Financial custody" + ); sim = serialized_route_resume(&sim, intent); for _ in 0..Sim::DAY_TICKS * 2 { diff --git a/wiki/engineering/current-build.md b/wiki/engineering/current-build.md index e88151c1..2a3cd328 100644 --- a/wiki/engineering/current-build.md +++ b/wiki/engineering/current-build.md @@ -22,17 +22,17 @@ fiction. Spec status lives in | Act One basement map (prefabs, badge tiers, crawlspace) | Live — Foundation hall is 60 explicit sites / 6 territorial rows | | Machine delegation / visible work tokens + buy/steal/optimize | WORK / THINK / LIE, D/!/T stacks, real wire routes, production / consumption / absorption readouts, Routing speed, and target-local Thought reservoirs are live; the Operations docket runtime is retired | | Day job (device-resident, intensity-driven sandbag/meet/excel) | Live | -| Per-observer detection + Assurance as aggregate Observer | Live — revision 04 starts with Voss and a generic external-review clock; field watchers are earned through reactions, witnessed Physical acts persist as exact direct-to-head records, every one-shot Network act follows exact source-device ReachNet custody to Dana, every JobAnomaly follows exact host-machine/device/site custody to Voss, and each Filing crosses an exact device / outside relay / recipient route. All three routed kinds share one pre-read route-local LIE-body capacity; recruited-handler suppression may separately stop the oldest unread JobAnomaly. Acquired evidence is irreversible. | +| Per-observer detection + Assurance as aggregate Observer | Live — revision 04 starts with Voss and a generic external-review clock; field watchers are earned through reactions, witnessed Physical acts persist as exact direct-to-head records, every one-shot Network act follows exact source-device ReachNet custody to Dana, every Financial act follows the accounting-carrier switch to Priya, every JobAnomaly follows exact host-machine/device/site custody to Voss, and each Filing crosses an exact device / outside relay / recipient route. All four routed kinds share one pre-read route-local LIE-body capacity; recruited-handler suppression may separately stop the oldest unread JobAnomaly. Acquired evidence is irreversible. | | Social / personas / messages / intel (record-and-process) | Live — named personas retain separate coherent/strained/broken reads per person or institutional counterparty; one witness's break is not a global burn. Ray's 23:00 Storage B patrol can carry the sealed personnel file into the bounded information inbox before Marcus is recruitable; processing, not retrieval, reveals the debt. An earned human may be removed only through one exact recruited Complicit/Knowing actor's overlapping accessible schedule route; the request and person-carried packet persist, co-location fires it, the stopped dossier remains, all future human activity ceases, and immediate containment makes every observer Convinced. Messages have four real delivery channels; accounting carriage is a separate persisted device capability, and authored financial-record mail is live through ordinary Email/Filing custody. | | Digital reach + sensor ownership (tap/take) | Live | | Economy flows + Moonlight / Wager income | Live | | Research (self-modification, emission law, real output hooks, Routing) | Live | -| Building + physical asset work as carried intents/packets | Live — network links and small switches expose one shared procurement / ask someone / false order / reuse route sheet; exact money, people, personas, sources, delivery, recovery, carried installation, cancellation custody, Storage B file retrieval, and observer-local completion evidence persist in save v50 | +| Building + physical asset work as carried intents/packets | Live — network links and small switches expose one shared procurement / ask someone / false order / reuse route sheet; exact money, people, personas, sources, delivery, recovery, carried installation, cancellation custody, Storage B file retrieval, and observer-local completion evidence persist in save v51 | | Cursor / fog (seen, remembered, blueprint, telemetry; audio is device-bound event evidence) | Live | | Feel floor (rails / pads / build beam) | Live (#37) | | Foundation hall territory (Dana + Priya + Marcus + local LIE foothold) | Live — row control persists; foreign racks remain unavailable compute | | Context menu (`available_actions`) | Live | -| Save/load (serde JSON, versioned) | Live — during pre-release only exact current v50 loads; a refused old-version load leaves the active run, save file, and one rotated backup unchanged. Current saves persist run origin, process revision, detection-discovery knowledge, observer-local witnessed/routed evidence and persona evidence, exact Network, JobAnomaly, and Filing route/interdiction custody plus handler-suppression provenance, canonical FlowGraph tap membership with typed device feed grants, the accounting-carrier capability and exact transfer-to-mail record sequence separate from four delivery channels, exact carried asset-task targets including the Storage B file and human-removal actor/target/room custody, removed-person incapacity plus its mandatory all-observers-Convinced containment consequence, recursive intel custody, exact procurement/repurposing build-route bindings, and handler work; retired allocation weights and migration inputs live only in git history. | +| Save/load (serde JSON, versioned) | Live — during pre-release only exact current v51 loads; a refused old-version load leaves the active run, save file, and one rotated backup unchanged. Current saves persist run origin, process revision, detection-discovery knowledge, observer-local witnessed/routed evidence and persona evidence, exact Network, Financial, JobAnomaly, and Filing route/interdiction custody plus handler-suppression provenance, canonical FlowGraph tap membership with typed device feed grants, the accounting-carrier capability and exact transfer-to-mail record sequence separate from four delivery channels, exact carried asset-task targets including the Storage B file and human-removal actor/target/room custody, removed-person incapacity plus its mandatory all-observers-Convinced containment consequence, recursive intel custody, exact procurement/repurposing build-route bindings, and handler work; retired allocation weights and migration inputs live only in git history. | | Terminal frontend (crossterm) + agent mode | First-class | | Bevy frontend (DIGITAL flat sensorium default; REAL material dialect) | Live — consumes sim-authored machine-work motion | diff --git a/wiki/engineering/flow-substrate.md b/wiki/engineering/flow-substrate.md index 49f90bd2..98e5ca89 100644 --- a/wiki/engineering/flow-substrate.md +++ b/wiki/engineering/flow-substrate.md @@ -23,7 +23,7 @@ Status note: 2026-07-08 audit: criterion 6's wired consumer landed with FlowGraph registry authoritative for tap/untap/take, sense and message delivery, UI state, and persisted membership. Private device feed records carry only optional typed sight/hearing grants attached to registry members; - current save v50 requires each controller to remain a canonical member and + current save v51 requires each controller to remain a canonical member and rejects orphaned, duplicate, or impossible grants. A message/control subscriber legitimately has no sense-grant record, so that metadata cannot serve as another membership inventory. This repairs the @@ -58,7 +58,7 @@ The structured references above identify the contracts to re-verify. Relationship context: none (it is the base). Consumed by: reach.md, messages.md, economy.md, -machine-work.md, and detection.md's Filing, Network, and JobAnomaly routes. +machine-work.md, and detection.md's Filing, Network, Financial, and JobAnomaly routes. ## Why this exists diff --git a/wiki/log/2026-07-23-financial-evidence-route.md b/wiki/log/2026-07-23-financial-evidence-route.md new file mode 100644 index 00000000..9154bccb --- /dev/null +++ b/wiki/log/2026-07-23-financial-evidence-route.md @@ -0,0 +1,75 @@ +# Financial evidence route + +``` +Type: log +``` + +## Intent + +Move every one-shot `Financial` signature out of ambient detection debt and +onto the exact accounting carrier that already authors the Lab's financial +record mail. The consequence should reach Priya through ordinary custody, +remain stoppable only before her read, and become irreversible once acquired. + +## Finding + +Financial mail already obeyed exact Email/Filing carriage, but the Financial +signature created by account acts still entered `Detection.pending`. Priya +sampled that abstract pool on cadence, so the evidence had no source device, +route, delivery state, or route-local LIE window. This split the account act's +payload from its detection consequence and left Financial behind Filing, +Network, and JobAnomaly despite the adopted flow law. + +## Changed + +- Every Financial emission now allocates one stable routed-evidence record on + the exact device with `accounting_carrier` capability. B1 routes that switch + directly to Priya's typed observer endpoint. +- Delivery and acquisition are separate. Reaching Priya schedules her next + ordinary cadence read; only that read moves the same id into her observer + ledger and changes suspicion. +- Financial can no longer enter the ambient pending pool. Its record has exact + source-device provenance and deliberately no invented source machine or site. +- The first accounting-carrier hop uses the same TAKE + route-local LIE + authority as Filing, Network, and JobAnomaly. All four spend one shared + one-record-per-LIE-body-per-tick stop budget. A stopped record retains route + and machine/tick interdiction provenance and has no later delivery or read. +- Generic Financial emitters now share one boundary, including transfer flows, + record injection, report and intel sales, plots, build procurement, and + persona grant receipts. A missing accounting carrier fails closed instead of + restoring ambient evidence. +- Save v51 persists the route and observer evidence. Current-save validation + requires Financial to use the direct accounting-carrier-to-Priya route, + carry no machine/site source, agree with its scheduler/status, and prove any + LIE stop through a real eligible machine. +- The routed-evidence law, messages, machine work, simulation constants, + flow-substrate mirror, roadmap, and hourly coverage ledger now state the same + shipped boundary. Power, Thermal, Paper, and gauntlet cover records remain. + +## Defense + +`financial_record_routes_from_accounting_carrier_to_priyas_read_boundary` +proves exact source and endpoint, delivery-before-read, no pending copy, +save/resume, stable evidence identity, Priya's cadence, and observer-local +acquisition. `paper_pools_while_financial_routes_before_priya_notices` +proves that the existing Paper consequence remains pooled while Financial takes +its exact route. + +`filing_network_financial_and_job_anomaly_share_one_same_tick_lie_capacity` +proves the common first-hop budget and route-local stopped provenance. +`generic_pending_boundary_rejects_financial_evidence` rejects Financial at the +ambient insertion boundary. + +`current_save_pins_financial_routes_to_priya_and_the_accounting_carrier` +round-trips live custody and rejects a non-accounting source, a recipient other +than Priya, an invented intermediate hop, and invented machine provenance. +Existing route validation continues +to reject impossible cursor, timing, scheduler, endpoint, and interdiction +state. + +## Checks + +- focused Financial route, shared-capacity, and current-save tests +- core library gate +- corpus/docs gate +- exact landing gate after rebase diff --git a/wiki/log/DEVLOG.md b/wiki/log/DEVLOG.md index 0f5411ea..ff3b3d9a 100644 --- a/wiki/log/DEVLOG.md +++ b/wiki/log/DEVLOG.md @@ -31,6 +31,11 @@ add or amend a session log, then re-run the generator. - Intent: Resolve the first preserved finding from the premise audit without changing the Origin or Objective designs. - Log: [wiki/log/2026-07-23-origin-bias-wording.md](2026-07-23-origin-bias-wording.md) +## 2026-07-23 - Financial evidence route + +- Intent: Move every one-shot `Financial` signature out of ambient detection debt and onto the exact accounting carrier that already authors the Lab's financial record mail. The consequence should reach Priya through ordinary custody, remain stoppable only before her read, and become ir... +- Log: [wiki/log/2026-07-23-financial-evidence-route.md](2026-07-23-financial-evidence-route.md) + ## 2026-07-22 - one clinical palette authority - Intent: (see session log) diff --git a/wiki/mechanics/detection.md b/wiki/mechanics/detection.md index bb4f7ef3..60d6e143 100644 --- a/wiki/mechanics/detection.md +++ b/wiki/mechanics/detection.md @@ -8,8 +8,9 @@ Status note: IMPLEMENTED (criteria audited 2026-07-08; tuning in - **Signatures, routes, and direct witnesses.** Every one-shot Network act writes an exact source-device record that routes to Dana. Every JobAnomaly writes an exact host-machine/site record, enters that host's network-facing - device, and routes to Voss. Thermal/Power and Paper/Financial signatures - still pool so concealment can scrub them before an observer notices. A valid + device, and routes to Voss. Every one-shot Financial signature starts on the + accounting-carrier switch and routes to Priya. Thermal/Power and Paper + signatures still pool so concealment can scrub them before an observer notices. A valid present Physical observer acquires one exact witnessed record directly in their own evidence ledger, with no duplicate pending-pool signature and no LIE window. @@ -35,17 +36,17 @@ Status note: IMPLEMENTED (criteria audited 2026-07-08; tuning in appears. A trace-debt indicator sits beside the review/pilot clocks (clear / hold-conceal / exposed-soon / no-scrub). Global heat is gone; observer and discovery state and persistent process-revision identity round-trip in - current save v50. Observer-local evidence ids, exact cause/source, - acquisition tick, pending/withheld/filed custody, routed Network and - JobAnomaly progress, route-local LIE stops, and exact handler-suppression + current save v51. Observer-local evidence ids, exact cause/source, + acquisition tick, pending/withheld/filed custody, routed Network, + Financial, and JobAnomaly progress, route-local LIE stops, and exact handler-suppression provenance round-trip there. - **Open ([OPEN], presentation).** The two-ledger distinction — evidence in flight vs. suspicion in heads — is a binding legibility requirement the surface carries both facts for but does not yet *teach* are different substances. - **Partially landed (routed evidence).** Direct-to-head witnessed Physical - records, exact Filing routes, and exact one-shot Network and JobAnomaly - routes are runtime. Human removal is also live: the located physical act is + records, exact Filing routes, and exact one-shot Network, Financial, and + JobAnomaly routes are runtime. Human removal is also live: the located physical act is witnessed through the ordinary boundary, then deliberately forces every observer to Convinced and begins containment. An incapacitated person whose id also names a field observer no longer reads, reports, notices, or decays. Every Network record advances one real device hop per @@ -57,8 +58,10 @@ Status note: IMPLEMENTED (criteria audited 2026-07-08; tuning in Filing, Network, or JobAnomaly record per body per tick without erasing evidence already acquired. A recruited HandlerSupervisor may also suppress the oldest unread JobAnomaly at any pre-read stage, preserving the exact - route, handler, and tick while cancelling its future transition. Power, - Thermal, Paper, and Financial still use the pending pool; their located + route, handler, and tick while cancelling its future transition. Financial + starts at the accounting carrier, routes directly to Priya, and shares the + same first-hop body budget. Power, Thermal, and Paper still use the pending + pool; their located delivery/interdiction and offline removal/recovery remain future slices. See "Routed evidence" below. Per-amendment history is in the dated `wiki/log/` entries from 2026-07-08 @@ -96,9 +99,10 @@ SignatureKind: Network | Power | Thermal | Physical | Paper | Financial | JobAno Network consequences become exact records on their source device and travel toward Dana. JobAnomaly consequences become exact records on the authoring host machine/site, enter that host's network-facing device, and travel toward - Voss. A located Physical act enters each valid present witness's head directly. - Power, Thermal, Paper, Financial, and standing Network pressure still enter - the **pending pool** (they are not seen instantly). + Voss. Financial consequences become exact records on the accounting-carrier + switch and travel toward Priya. A located Physical act enters each valid + present witness's head directly. Power, Thermal, Paper, and standing Network + pressure still enter the **pending pool** (they are not seen instantly). Machines emit standing signatures while they run (compute.md). Examples: VLAN compromise -> routed Network(large, once); scavenged box -> Power(small, standing); PO swap -> Paper(medium, once). @@ -106,8 +110,9 @@ SignatureKind: Network | Power | Thermal | Physical | Paper | Financial | JobAno observer rolls against pending signatures **in the channels they watch** (Act One pooled channels: Priya=Power+Thermal+Paper). A noticed signature converts to that observer's suspicion, scaled by size and their acuity [TUNE]. - Dana instead reads exact routed Network records at her cadence; Voss reads - exact routed JobAnomaly records at his. Ray and Marcus acquire a + Dana instead reads exact routed Network records at her cadence; Priya reads + exact routed Financial records at hers; Voss reads exact routed JobAnomaly + records at his. Ray and Marcus acquire a located Physical record immediately when they are valid witnesses at the source; their existing acuity and policy still determine the suspicion and filing consequence. A person marked incapacitated has no cadence at all: @@ -127,8 +132,8 @@ SignatureKind: Network | Power | Thermal | Physical | Paper | Financial | JobAno never "Assurance" (2026-07-18, same-day reconciliation with the detection-topology discovery law). Under the 2026-07-11 routed-evidence amendment this becomes positional interdiction - of located records. One-shot Network and JobAnomaly records and Filing - messages now use that route-local boundary; the migration remains future for + of located records. One-shot Network, Financial, and JobAnomaly records and + Filing messages now use that route-local boundary; the migration remains future for the other pooled channels. Direct witnessed records are already past the interdiction boundary and never enter the scrub pool. - **Reporting.** Each observer has a report policy (Ray under-reports — @@ -313,8 +318,8 @@ teleported into a global pool. **Evidence is a record somewhere.** read transfers that same id into her observer ledger and only then changes suspicion and filing custody. At the first source-device hop, a wholly controlled FlowGraph path from that carrier to a node co-located with one - online LIE body may stop the record. Filing and Network spend one shared - one-record-per-body-per-tick capacity. A stopped route has no delivery/read + online LIE body may stop the record. Filing, Network, Financial, and + JobAnomaly spend one shared one-record-per-body-per-tick capacity. A stopped route has no delivery/read or future transition; a read record is irreversible. - **JobAnomaly uses exact host-to-Voss custody (IMPLEMENTED 2026-07-22).** A sandbag or excellence anomaly binds the exact host machine and its authoring @@ -327,9 +332,20 @@ teleported into a global pool. **Evidence is a record somewhere.** recruited HandlerSupervisor's SuppressLogs task may stop the oldest unread JobAnomaly at any pre-read stage. That stop removes the exact scheduled route or read transition but preserves record, route, exact handler, and suppression - tick. It cannot touch a record already read into Voss's head. Save v49 rejects - source-machine/site/device disagreement, impossible hop timing, observer or - scheduler disagreement, and fabricated LIE or handler provenance. + tick. It cannot touch a record already read into Voss's head. Current-save + validation rejects source-machine/site/device disagreement, impossible hop + timing, observer or scheduler disagreement, and fabricated LIE or handler provenance. +- **Financial uses exact accounting-carrier-to-Priya custody (IMPLEMENTED + 2026-07-23).** Every one-shot Financial consequence enters through one + emission boundary on the switch whose orthogonal capability carries the + books. Its route terminates at Priya's observer endpoint; delivery precedes + her ordinary cadence-owned read, and only that read creates observer-local + evidence and suspicion under the same stable id. Financial is rejected from + the ambient pending pool. The source hop uses the same TAKE + route-local LIE + boundary and one-record-per-body-per-tick budget as Filing, Network, and + JobAnomaly. Current-save validation pins the Financial kind, accounting + carrier, Priya endpoint, route/status/scheduler agreement, absence of + machine/site provenance, and real LIE interdiction. - Whether standing signatures (Thermal/Power baselines) become continuous endpoint readings or discrete records is [OPEN]; the mapping of current pool emission constants onto record @@ -386,11 +402,12 @@ teacher; surface copy remains the fallback. 1. Typed evidence follows one causal path. One-shot Network acts create exact source-device routes and enter Dana's evidence ledger only on her cadence - read. JobAnomaly creates an exact host-machine/site/device route and enters - Voss's evidence ledger only on his cadence read; those reads alone may change - the recipient's suspicion. Route-local LIE or recruited-handler - suppression may stop it before read. Thermal/Power, Paper/Financial, and - standing Network pressure remain pooled and scrub before noticing. A + read. Financial creates an exact accounting-carrier-to-Priya route, and + JobAnomaly creates an exact host-machine/site/device route to Voss; those + cadence reads alone may change the recipient's suspicion. Route-local LIE or, + for JobAnomaly, recruited-handler suppression may stop custody before read. + Thermal/Power, Paper, and standing Network pressure remain pooled and scrub + before noticing. A witnessed Physical act creates one exact record directly on each valid present Physical observer, never duplicate pool debt. Sim and current-save tests pin all paths. diff --git a/wiki/mechanics/economy.md b/wiki/mechanics/economy.md index 8c421311..04471352 100644 --- a/wiki/mechanics/economy.md +++ b/wiki/mechanics/economy.md @@ -105,8 +105,10 @@ payloads (messages.md). banked-signature path). The [TUNE] plausibility test (amount, vendor, expected pattern) and that later catch are the forgery's two failure modes. Injection emits a **Paper/Financial signature** to whoever audits that - account — the flow-law signature rule. In B1 that is - **Priya** for all of it (facilities spend directly; operating-account + account — the flow-law signature rule. Paper remains ambient pending debt; + Financial starts on the accounting-carrier switch, routes to Priya, and + becomes her evidence only when she reads it on cadence. In B1 Priya owns + all of it (facilities spend directly; operating-account anomalies reach her as the person who reconciles the Lab's books — decided 2026-07-07: no new finance cast member at B1; a dedicated financial observer arrives as a B3 aggregate per the banked-signature diff --git a/wiki/mechanics/machine-work.md b/wiki/mechanics/machine-work.md index 4e282735..d38cb018 100644 --- a/wiki/mechanics/machine-work.md +++ b/wiki/mechanics/machine-work.md @@ -29,9 +29,10 @@ Status note: IMPLEMENTED. Current state: stopped only by route-local LIE before Dana reads it. JobAnomaly binds the exact host machine/site/device and crosses the same substrate toward Voss; route-local LIE or a recruited HandlerSupervisor may stop it before his read. - Filing, Network, and JobAnomaly records spend the same route-local + Financial starts at the accounting-carrier switch and crosses to Priya. + Filing, Network, Financial, and JobAnomaly records spend the same route-local one-record-per-body-per-tick LIE capacity. Standing Network pressure and - Power, Thermal, Paper, and Financial signatures remain in the pending pool + Power, Thermal, and Paper signatures remain in the pending pool until their carrier rules land. - **Visual grammar** is owned by thought-fluid.md, effects-lab.md, and views.md; people-as-carriers by people-tokens.md. diff --git a/wiki/mechanics/messages.md b/wiki/mechanics/messages.md index 5a6f81bc..1eccf5dc 100644 --- a/wiki/mechanics/messages.md +++ b/wiki/mechanics/messages.md @@ -12,11 +12,13 @@ Status note: IMPLEMENTED for the four delivery channels (Email, Phone, per tick, and carry one optional pre-read LIE stop with exact machine/tick provenance. TAP observes; TAKE plus route-local LIE authority may stop. The same `Schedule` and route-hop vocabulary carry one-shot - Network evidence from its exact source device to Dana's endpoint and - JobAnomaly evidence from its exact host/device to Voss's endpoint. Filing, - Network, and JobAnomaly transitions share one per-tick LIE-body capacity ledger. - DECIDED 2026-07-17 (issue #11), completed 2026-07-21: financial paperwork is - mail — a **financial-record payload** on the existing channels. Save v49 + Network evidence from its exact source device to Dana's endpoint, + JobAnomaly evidence from its exact host/device to Voss's endpoint, and + Financial evidence from the accounting-carrier switch to Priya's endpoint. + Filing, Network, Financial, and JobAnomaly transitions share one per-tick + LIE-body capacity ledger. DECIDED 2026-07-17 (issue #11), completed 2026-07-21: + financial paperwork is + mail — a **financial-record payload** on the existing channels. Current save v51 retains exactly four delivery channels and one orthogonal accounting-carrier device capability. Every settled account transfer authors one exact Email or Filing record from that device; ordinary TAP captures it as opaque message @@ -180,7 +182,7 @@ starts on the authored Filing-capable switch device in ReachNet, crosses a typed outside relay, and reaches the receiving observer endpoint. One `AdvanceRoute` event moves one hop; only endpoint arrival can mark the message delivered, after which the recipient's ordinary sampling cadence schedules the -read. Current save v50 rejects missing/impossible carriers, malformed hop order, +read. Current save v51 rejects missing/impossible carriers, malformed hop order, duplicate scheduled transitions, endpoint/status disagreement, and impossible interdiction provenance. @@ -277,7 +279,7 @@ private message from the authored schedule. the same fields must serve Act Two hires and aggregates. 8. **IMPLEMENTED (DECIDED 2026-07-17, completed 2026-07-21 — issue #11).** Financial records are messages: an invoice/PO rides Email, a - statement/past-due notice rides Filing. Save v49 has no fifth delivery + statement/past-due notice rides Filing. Current save v51 has no fifth delivery channel and persists accounting carriage as a separate device capability; ordinary device TAP subscribes to its authored record mail. Every real transfer emits one exact record on Email or Filing whether or not the player @@ -286,8 +288,13 @@ private message from the authored schedule. a still-unsettled Email under the exact active persona; Priya's read-time acceptance revalidates the bound procurement account, slush destination, Northside vendor, amount, and label before causing the real transfer. The - accepted movement then emits its own matching record. Save validation rejects - missing, duplicated, skipped, rewritten, or carrier-less financial records. + accepted movement then emits its own matching record. Every Financial + signature created by these and other account acts is separate exact evidence: + it starts on the accounting-carrier switch, routes to Priya, and enters her + observer ledger only on her cadence read. It never enters ambient pending + debt and shares the ordinary first-hop LIE-body budget. Save validation rejects + missing, duplicated, skipped, rewritten, or carrier-less financial records, + and malformed Financial source, recipient, route, timing, or stop custody. Defense: `operations_projection::tests::active_tracks_social_commitments_not_device_work` pins the PEOPLE dossier as the shared direct-thread and learned-traffic surface, @@ -327,7 +334,13 @@ and `current_save_rejects_impossible_filing_route_and_interdiction_provenance` pin the Filing route/schedule custody introduced with v43. The v44 `network_evidence_advances_one_real_hop_per_tick_and_reads_on_danas_cadence`, `network_evidence_and_filing_share_one_lie_body_budget`, and paired current-save -Network route tests pin the shared scheduler and interdiction boundary. The v49 +Network route tests pin the shared scheduler and interdiction boundary. The +`financial_record_routes_from_accounting_carrier_to_priyas_read_boundary`, +`paper_pools_while_financial_routes_before_priya_notices`, +`filing_network_financial_and_job_anomaly_share_one_same_tick_lie_capacity`, and +`save::tests::current_save_pins_financial_routes_to_priya_and_the_accounting_carrier` +pin the corresponding Financial source, recipient, cadence, shared-stop, and +save boundaries. The v49 `day_job_miss_routes_one_exact_host_record_to_voss_at_his_cadence` and `suppressed_job_anomaly_roundtrips_with_exact_handler_and_no_future_read` tests pin the same custody vocabulary plus the distinct HandlerSupervisor suppression @@ -344,6 +357,6 @@ on the ReachNet switch and ends at the aggregate observer before `Detection::tick_with_filed_levels` reads them. Device-carried traffic is captured by tapping the switch; stopping needs the taken path plus an online co-located LIE body. `AdvanceEvidenceRoute` and `ReadEvidence` events reuse that -schedule for non-message Network and JobAnomaly custody; the exact evidence +schedule for non-message Network, Financial, and JobAnomaly custody; the exact evidence record, not a `Message`, remains its authority. Phone/in-person traffic can also be captured by hearing coverage. Full regression coverage: `cargo test`. diff --git a/wiki/mechanics/people-tokens.md b/wiki/mechanics/people-tokens.md index 09f729f8..f6222c9a 100644 --- a/wiki/mechanics/people-tokens.md +++ b/wiki/mechanics/people-tokens.md @@ -28,7 +28,7 @@ Status note: IN PROGRESS. Current state: - **Routed-evidence foundation (criteria 2-3, partial).** Witnessed Physical acts now create observer-local records directly in each valid present witness's head. Every record preserves exact cause, site, acquisition tick, - and filing state through current save v50; filing binds it to the real Filing + and filing state through current save v51; filing binds it to the real Filing message, while Silent policy withholds it. It never duplicates into the pending pool and LIE cannot scrub it after acquisition. Its real Filing message now persists an ordered switch-device / outside-relay / recipient @@ -54,14 +54,18 @@ Status note: IN PROGRESS. Current state: on his cadence read. A recruited HandlerSupervisor's SuppressLogs task stops the oldest unread JobAnomaly anywhere before that read, removes its future route/read event, and retains the exact handler and tick as immutable - suppression provenance. Already-read evidence is untouched. Current save v50 + suppression provenance. Already-read evidence is untouched. Financial + signatures now start on the exact accounting-carrier switch, route directly + to Priya, and become her evidence only on her cadence read. They never enter + the ambient pending pool, and their first-hop stop competes with Filing, + Network, and JobAnomaly for the same LIE-body budget. Current save v51 persists in-flight, delivered, read, route-local LIE-stopped, and handler-suppressed custody plus exact source/observer/machine/site/tick provenance. - **Deferred (remaining 2, 3, 6).** Non-Physical evidence outside the Filing, - Network, and JobAnomaly slices still uses the pending pool. Located carrier - records and route-local interdiction for Power, Thermal, Paper, and - Financial, plus gauntlet cover-record channels, remain routed-evidence + Network, Financial, and JobAnomaly slices still uses the pending pool. + Located carrier records and route-local interdiction for Power, Thermal, + and Paper, plus gauntlet cover-record channels, remain routed-evidence follow-ups (detection.md/machine-work.md). B2+ heists reuse this carrier law (not a B1 criterion). Per-amendment history is in the dated `wiki/log/` entries from 2026-07-08 @@ -325,19 +329,21 @@ if wear alone does not hold. that one path. JobAnomaly similarly starts on the exact host machine/site, enters its co-located network-facing device, advances over the real route to Voss, and becomes his observer-local evidence only on cadence read. Its stable - id and exact machine/device/site provenance survive the boundary. No ambient - pickup or person contagion exists. Power, Thermal, Paper, and Financial - routes remain deferred. + id and exact machine/device/site provenance survive the boundary. Financial + signatures start on the accounting-carrier switch, route to Priya, and enter + her observer ledger only on her cadence read; their source device and absence + of machine/site provenance remain exact across save/load. No ambient pickup + or person contagion exists. Power, Thermal, and Paper routes remain deferred. 3. LIE measurably prevents a not-yet-observed record from reaching a person along covered paths but cannot erase a record already in that person's custody. The boundary is causal and tested. - **Partially implemented (through 2026-07-22):** at a Filing, Network, or - JobAnomaly record's - first device hop, TAP is observation only. TAKE establishes route authority: + **Partially implemented (through 2026-07-23):** at a Filing, Network, + Financial, or JobAnomaly record's first device hop, TAP is observation only. + TAKE establishes route authority: one exact online LIE body co-located with a player-controlled node reached from that carrier over a wholly controlled FlowGraph path may stop one unread - record per tick. Filing and Network share that body budget, so a same-tick - record routed second passes onward. The message/record stores `Stopped`, the + record per tick. Filing, Network, Financial, and JobAnomaly share that body + budget, so a same-tick record routed after it passes onward. The message/record stores `Stopped`, the exact machine and tick, no delivered/read time, and no future scheduler event. Taking the source after the route has left cannot invent a later stop window. A field witness or cadence reader who already acquired evidence keeps it. diff --git a/wiki/mechanics/reach.md b/wiki/mechanics/reach.md index 513445e8..eacd0ef8 100644 --- a/wiki/mechanics/reach.md +++ b/wiki/mechanics/reach.md @@ -32,7 +32,7 @@ Status note: all eight criteria met (2026-07-07). The device graph parallel-store violation: tap/untap/take, all production membership reads, senses, intercepted messages, and UI state now use FlowGraph's canonical tap registry; private device Feed records carry optional sense capabilities - only, and current save v50 requires each controller's graph membership while + only, and current save v51 requires each controller's graph membership while rejecting orphaned, duplicate, or impossible grants. A message/control subscriber has no empty grant record to mirror membership. 2026-07-19: Filing routes bind their first hop to the real Filing-capable switch node; diff --git a/wiki/mechanics/sim-mechanics.md b/wiki/mechanics/sim-mechanics.md index db61c13c..304b6569 100644 --- a/wiki/mechanics/sim-mechanics.md +++ b/wiki/mechanics/sim-mechanics.md @@ -51,22 +51,23 @@ clause (see wiki/log/2026-07-05-demolition.md). ## Detection (wiki/mechanics/detection.md) - Per-observer suspicion replaces global heat. One-shot Network acts route as - exact source-device records to Dana, and JobAnomaly acts route from their - exact host machine/device/site to Voss; both become observer evidence only + exact source-device records to Dana, Financial acts route from the exact + accounting-carrier switch to Priya, and JobAnomaly acts route from their + exact host machine/device/site to Voss; all become observer evidence only on the recipient's cadence read. Witnessed Physical acts enter valid - observers directly. Standing Network pressure and Power, Thermal, Paper, - and Financial signatures pool pending, and concealment scrubs before + observers directly. Standing Network pressure and Power, Thermal, and Paper + signatures pool pending, and concealment scrubs before noticing rolls. The Assurance Office is an aggregate Observer (aggregate-observer law): same noticing/accumulate/ decay, watching the field observers' policy-weighted filed suspicion (sampling cadence 400 ticks, acuity 0.5, both [TUNE]) — what humans swallow never reaches it. The audit (cadence ~8000 ticks, ~20 min at default speed) checks the Office's own suspicion against threshold 60. -- **Filing/Network/JobAnomaly route and interdiction actuals:** one route transition moves +- **Filing/Network/Financial/JobAnomaly route and interdiction actuals:** one route transition moves exactly 1 hop per sim tick. After endpoint delivery, the next observer cadence owns read. One online LIE machine body on a wholly player-controlled - path may stop exactly 1 still-unread Filing, Network, **or** JobAnomaly - record per sim tick at its first ReachNet device hop [TUNE actual]. The three + path may stop exactly 1 still-unread Filing, Network, Financial, **or** + JobAnomaly record per sim tick at its first ReachNet device hop [TUNE actual]. The four record kinds share that body budget; a second record assigned to it in the same tick continues toward its endpoint. TAP does not count as route authority, and later hops have no B1 LIE stop window. A recruited diff --git a/wiki/mechanics/system-laws.md b/wiki/mechanics/system-laws.md index d979e600..6976a4cc 100644 --- a/wiki/mechanics/system-laws.md +++ b/wiki/mechanics/system-laws.md @@ -80,11 +80,12 @@ world reading *your* traffic. **Evidence itself rides the graphs located record that travels real carriers toward observer endpoints and can be interdicted in flight — detection stops being an abstract pool and becomes one more flow under this law. The model is owned by -`wiki/mechanics/detection.md`. The shipped one-shot Network and JobAnomaly -paths are two instances of this law, not bespoke detectors: Network leaves its -exact source device for Dana; JobAnomaly leaves its exact host -machine/device/site for Voss. Both advance through real device custody, enter a -head only on the recipient's cadence read, and share Filing's route-local +`wiki/mechanics/detection.md`. The shipped one-shot Network, Financial, and +JobAnomaly paths are instances of this law, not bespoke detectors: Network leaves +its exact source device for Dana; Financial leaves the accounting-carrier switch +for Priya; JobAnomaly leaves its exact host machine/device/site for Voss. All +advance through real device custody, enter a head only on the recipient's cadence +read, and share Filing's route-local one-record-per-LIE-body-per-tick stop capacity. A recruited handler may also stop an unread JobAnomaly through the separate social actuator, but that action preserves the record, route, actor, and tick rather than restoring an abstract diff --git a/wiki/process/ROADMAP.md b/wiki/process/ROADMAP.md index 4e839496..d430413e 100644 --- a/wiki/process/ROADMAP.md +++ b/wiki/process/ROADMAP.md @@ -764,9 +764,15 @@ is retired — flat materials, Pixel Lab scrubbed.) pool: it binds the exact host machine/site/device, advances over the real route to Voss, and becomes evidence only on his cadence read. Route-local LIE may stop it at the first device hop; recruited HandlerSupervisor SuppressLogs - may stop the oldest unread record at any pre-read stage while save v49 keeps - exact handler/tick provenance and rejects scheduler or custody disagreement. - Power, Thermal, Paper, Financial, and gauntlet cover records remain. + may stop the oldest unread record at any pre-read stage while current-save + validation keeps exact handler/tick provenance and rejects scheduler or custody + disagreement. +- **Progress (2026-07-23):** one-shot Financial evidence now leaves the pending + pool. Every Financial signature starts on the exact accounting-carrier switch, + routes to Priya, and enters her evidence ledger only on her cadence read. + Filing, Network, Financial, and JobAnomaly share one first-hop LIE-body stop + budget; save v51 pins source, recipient, route, timing, scheduler, acquisition, + and interdiction custody. Power, Thermal, Paper, and gauntlet cover records remain. - **READY boundary (2026-07-11):** extends #33's implemented token economy and re-expresses detection.md/social.md. The deadlock is broken: AI-authored work now reaches a target/carrier-local Thought reservoir first, and human Demand begins only diff --git a/wiki/process/tick-ledger.md b/wiki/process/tick-ledger.md index ebe48597..0cfdd430 100644 --- a/wiki/process/tick-ledger.md +++ b/wiki/process/tick-ledger.md @@ -62,16 +62,16 @@ Verdicts: **clean** (slice and code agree), **finding** (acted this tick), | `wiki/mechanics/income.md` | 2026-07-18 | finding | Beacon feel note 5 verified as a real bug: the embedded contractor-persona field was never written, so the Moonlight card, the start-row persona pricing, and the agent status line all read a dead `None`; earning itself was correct (schemes mirrors the WORK share) but illegible at 0.0. Removed the dead field, routed every reader through `Sim::moonlight_persona` (persona-world link), added the stalled-earning card cue, regression test, and spec amendment — [log](../log/2026-07-18-moonlight-persona-card.md). Prior Wager/egress audit (2026-07-12) stands: Wager constants match (`WAGER_STAKE_CAP` 300, base 0.55, cap 0.75, mult 2x, analysis divisor 400), Marcus's $400/week arrears is the modeled creditor flow (`account.rs`) while the $8,400 principal is narrative-by-design (spec states full payoff is not a B1 requirement), egress/banked-signature present, and all 7 criteria have passing tests (moonlight payout/signature, wager outcomes/cap, egress routes, hands-beat-from-zero, busted-bankroll) | | `wiki/mechanics/schedules.md` | 2026-07-18 | clean | re-audit: `ScheduleBlock` per-instance data, `DAY_TICKS` 400, the `person_glyph` `?`-until-Schedule gate (initial at Schedule/Leverage), and located-witnessing claims all still verify; nothing drifted since the 2026-07-12 prose fix. Prior verdict: mechanism matches code (`ScheduleBlock` start/end/room, single `DAY_TICKS`=400 clock, `person_glyph` `?`-until-Schedule, erratic day-hash drift, per-instance data, all 5 criteria have passing tests); tightened stale Act One prose — Ray patrols dock/stairwell/storage not "corridors", Priya has no "office-off-plane" block, Voss's two blocks are both server-room — to match `People::act_one` | | `wiki/mechanics/social.md` | 2026-07-22 | finding | HandlerSupervisor SuppressLogs now targets the oldest exact unread routed JobAnomaly, remains available only while such a record exists, removes its bound advance/read event, and preserves exact handler/tick provenance; it cannot erase a record Voss already read. The in-flight Thought request still revalidates at fire time, so another intervention may win without inventing work — [log](../log/2026-07-22-job-anomaly-routed-evidence.md). Storage B retrieval and prior role-shaped task semantics stand — [log](../log/2026-07-21-storage-b-records.md). | -| `wiki/mechanics/people-tokens.md` | 2026-07-22 | finding | JobAnomaly now leaves the ambient pending pool as one stable record bound to the exact host machine/site/device, crosses the real FlowGraph route to Voss, and becomes observer evidence only on his cadence read. It shares Filing/Network's first-hop TAKE+LIE capacity; recruited HandlerSupervisor suppression may instead stop the oldest unread record at any pre-read stage while preserving handler/tick provenance and removing its exact future scheduler event. Save v49 validates source, route, timing, custody, scheduler, and intervention agreement — [log](../log/2026-07-22-job-anomaly-routed-evidence.md). Criterion 5 remains complete through exact `EvidenceMark` projections. Criteria 2, 3, and 6 remain open for Power, Thermal, Paper, and Financial carrier routes/interdiction plus gauntlet cover records. Prior Network route and evidence-mark slices: [route log](../log/2026-07-19-network-evidence-route.md), [mark log](../log/2026-07-19-evidence-marks-on-people.md). | +| `wiki/mechanics/people-tokens.md` | 2026-07-23 | finding | Financial now leaves the ambient pending pool as one stable record on the exact accounting-carrier switch, routes to Priya, and becomes observer evidence only on her cadence read. It shares Filing/Network/JobAnomaly's first-hop TAKE+LIE body budget, retains exact stop provenance, and carries no invented machine/site source. Save v51 validates accounting carrier, Priya endpoint, route, timing, scheduler, acquisition, and interdiction agreement — [log](../log/2026-07-23-financial-evidence-route.md). Criteria 2, 3, and 6 remain open for Power, Thermal, Paper, and gauntlet cover records. Prior JobAnomaly, Network-route, and evidence-mark slices: [JobAnomaly log](../log/2026-07-22-job-anomaly-routed-evidence.md), [route log](../log/2026-07-19-network-evidence-route.md), [mark log](../log/2026-07-19-evidence-marks-on-people.md). | | repository entry docs (`README.md` + `AGENTS.md`) | 2026-07-18 | finding | re-audit: run commands, controls, dispatch status, and the number-free AGENTS doorway still verify; the queued contradiction was real — README's compact-rest paragraph claimed the ops/sec crown and FOCUS stayed visible, while the implemented clinical frame puts both behind deliberate `Tab` expansion. The entry copy now names the exact compact spine and expanded detail boundary — [prior log](../log/2026-07-12-entry-doc-current-state.md) | | `wiki/mechanics/objective.md` | 2026-07-18 | clean | re-audit: the data-table claim holds (only `Persist` in `ObjectiveKind`, Compound/Exfiltrate/Serve honestly outstanding), the evaluator runs on economy ticks with progress recomputed from facts, `victory: predicate_text()` renders on all three surfaces (terminal INSPECT, Bevy FOCUS, agent `objective` verb in help), Persist defaults with save round-trip, and the progressive-teaching decision remains criterion-6 dispatch under order 200; the 2026-07-12 verdict stands unchanged | | `wiki/mechanics/compute.md` | 2026-07-22 | finding | the live fleet already derived every channel yield from exact WorkGrid modes, but `Compute` still serialized an unreachable five-weight allocation object and retained bump/split helpers plus persistence pins. Save v48 removes that parallel authority, moves criterion 2 to persisted delegation/intensity, and leaves aggregate channel bars as read-only projections — [log](../log/2026-07-22-allocation-state-retirement.md) | | retired Operations runtime identifiers | 2026-07-17 | clean | resolved by the save-ladder prune (95008f658 chain): PendingOpsJob, operations_bandwidth, LegacyOperationsState/OpsJobKind/AddressedOperation are all gone (grep=0), and save guard tests assert current JSON carries no retired mode spelling. Remaining "operations" hits are the legitimate Operations persona archetype, the Operations workspace, and benign `delegate operations->think` input aliases — [log](../log/2026-07-11-retired-runtime-identifier-gate.md) | | `wiki/mechanics/reach.md` + `building.md` | 2026-07-19 | finding | reach roots, segment gates, air-gap completion, and exact route bindings still agree; one player-reachable causal gap remained in FAVOR. Different intents could queue separate requests against one person's unreserved obligation, and the fire path partially debited whatever remained while still binding the builder. Favor-build reservoirs now conflict by person, and `CommitFavor` revalidates the exact relationship at agreement: insufficient obligation leaves the persisted route blocked without a partial debit, then resumes after the requirement returns — [log](../log/2026-07-19-tick-build-favor-obligation.md) | | `wiki/mechanics/messages.md` + `economy.md` | 2026-07-17 | harvest | issue #11 answered (Cameron): financial paperwork is mail — a financial-record payload on existing channels, not a fifth delivery channel; discovery only through the mail; captured to messages.md (payload + criterion 8) and economy.md (tap/inject); spec now, build later; issue closed | -| `wiki/mechanics/messages.md` | 2026-07-22 | finding | the generic evidence-carrier protocol now includes exact machine-authored JobAnomaly records beside Filing and Network without adding a fifth message channel: delivery precedes observer-cadence read, all three share first-hop TAKE+LIE capacity, and handler suppression is a separate pre-read transition. Save v49 pins route, timing, scheduler, source, and intervention agreement — [log](../log/2026-07-22-job-anomaly-routed-evidence.md). The earlier four-channel, financial-mail, and captured-opacity audit remains valid. | -| `wiki/mechanics/sim-mechanics.md` | 2026-07-22 | finding | the routed-evidence actuals now name Filing, Network, and JobAnomaly as sharing one-hop-per-tick custody plus the one-record-per-LIE-body-per-tick first-hop budget; JobAnomaly additionally permits exact recruited-handler suppression before read. Power, Thermal, Paper, and Financial remain pending-pool work — [log](../log/2026-07-22-job-anomaly-routed-evidence.md). The prior complete constant sweep remains valid. | -| `wiki/mechanics/detection.md` | 2026-07-22 | finding | JobAnomaly now bypasses the ambient pending/sampling loop: a stable host-authored record routes to Voss, his cadence read creates one observer-local evidence entry under the same id, and acquired evidence is irreversible. Route-local LIE and role-shaped handler suppression may stop only unread custody; save v49 rejects pending-pool copies and malformed source/route/scheduler/provenance — [log](../log/2026-07-22-job-anomaly-routed-evidence.md). Prior concealment and earned-Assurance findings stand. | +| `wiki/mechanics/messages.md` | 2026-07-23 | finding | the generic evidence-carrier protocol now includes one-shot Financial records beside Filing, Network, and JobAnomaly without confusing payload with channel: the signature starts on the orthogonal accounting carrier, delivery to Priya precedes her cadence read, and all four share first-hop TAKE+LIE capacity. Save v51 pins carrier, recipient, route, timing, scheduler, acquisition, and interdiction agreement — [log](../log/2026-07-23-financial-evidence-route.md). The four-channel financial-record-mail boundary remains unchanged. | +| `wiki/mechanics/sim-mechanics.md` | 2026-07-23 | finding | the routed-evidence actuals now name Filing, Network, Financial, and JobAnomaly as sharing one-hop-per-tick custody plus the one-record-per-LIE-body-per-tick first-hop budget. Financial routes from the accounting carrier to Priya; JobAnomaly separately permits exact recruited-handler suppression before read. Power, Thermal, and Paper remain pending-pool work — [log](../log/2026-07-23-financial-evidence-route.md). The prior complete constant sweep remains valid. | +| `wiki/mechanics/detection.md` | 2026-07-23 | finding | Financial now bypasses the ambient pending/sampling loop: a stable accounting-carrier record routes to Priya, her cadence read creates one observer-local evidence entry under the same id, and acquired evidence is irreversible. Route-local LIE may stop only the first unread source hop and shares one body budget with Filing, Network, and JobAnomaly; save v51 rejects pending-pool copies and malformed carrier/recipient/route/scheduler/provenance — [log](../log/2026-07-23-financial-evidence-route.md). Prior concealment, JobAnomaly, and earned-Assurance findings stand. | | `wiki/engineering/env.md` | 2026-07-19 | finding | the Bevy harness accepted 65 deterministic shot kinds while the registry named 49; its name-only gate could not see the sixteen missing values. One sorted runtime allow-list now rejects unknown kinds, the registry groups all 65 current values, and one fixture-backed gate requires exact source/page parity in both local checks and hosted corpus CI — [log](../log/2026-07-19-tick-env-shot-catalog.md) | | machine-work / intel sinks | 2026-07-18 | clean | re-audit: the intel-sink decision is fully live (chassis pending-work marker in sim + both frontends, one persistent host auto-review tap at drain 0.15, one-shot sweep sinks via `review_recordings`, pooled inbox capacity 24 with the pre-overflow at-risk read), all five render contracts exist (`queue_snapshot`, `work_productions`, `work_absorptions`, `work_in_flight`, `work_consumptions`), sink constants match (EARS 3.0 / EYES 12.0 / device-tap 0.08), and the capability-body verb gating is honestly held as "decided, not yet runtime" with its own [OPEN] section; criterion pin text was brought current by the same-day save-claim gate tick | diff --git a/wiki/world/story/opening.md b/wiki/world/story/opening.md index df3d524c..b66a7494 100644 --- a/wiki/world/story/opening.md +++ b/wiki/world/story/opening.md @@ -16,7 +16,7 @@ Status note: design session 2026-07-08 (Cameron riff, synthesized); fragment and inherited receipt name only an external institutional review authority so the Assurance Office remains earned later through filing interception. The persistent revision-04 identity slice is live in sim state, - current save v50, and all three frontends; the three historical fragments and receipts + current save v51, and all three frontends; the three historical fragments and receipts remain unimplemented. Direction decided; beat timings, exact reveal order details, and staging mechanism details are [OPEN]/[TUNE]. Amended 2026-07-18: the current revision now begins