diff --git a/wiki/interface/presence.md b/wiki/interface/presence.md index ef264df4..565fc115 100644 --- a/wiki/interface/presence.md +++ b/wiki/interface/presence.md @@ -104,10 +104,15 @@ Both former extensions — **remembered** and **telemetry** — were affirmed 2026-07-07 and are folded into the lists above (wiki/mechanics/cursor.md criteria 9-10). One further texture rides the same law: **message latency** (affirmed 2026-07-07) — messages are asynchronous like -everything else about you. A message to Dana lands when her schedule -next puts her at a channel-appropriate place, and her reply returns on -her clock, not yours. You are a process; the humans are not. (Spec: -wiki/mechanics/intel.md.) +everything else about you. A message can be delivered and remain unread; +its effects land only when that channel's read condition is met. Email and +tickets wait for a recipient's desk block, Phone reads anywhere including +off-site in the current B1 model, In-person requires co-location, and Filing +waits for the receiving role's sampling cadence. Replies return on each +person's response distribution, on their clock rather than yours. You are a +process; the humans are not. [messages.md](../mechanics/messages.md) owns the +exact channel and timing contract; [intel.md](../mechanics/intel.md) owns what +intercepted traffic becomes after capture. ## No disembodied hands diff --git a/wiki/log/2026-07-18-presence-message-latency.md b/wiki/log/2026-07-18-presence-message-latency.md new file mode 100644 index 00000000..29215d8e --- /dev/null +++ b/wiki/log/2026-07-18-presence-message-latency.md @@ -0,0 +1,34 @@ +# Presence delegates message timing to the channel + +``` +Type: log +``` + +The findings queue carried one remaining contradiction from the presence-law +audit. `wiki/interface/presence.md` said a message to Dana lands when her +schedule next puts her at a channel-appropriate place and named `intel.md` as +the owning spec. That compressed delivery, read, and effect into one +schedule-shaped event, even though `messages.md` owns four distinct read +conditions and `intel.md` already delegates latency back to it. + +Current runtime made the stale wording observable. `Sim::read_condition_at` +keeps delivery separate from read: Email waits for a scheduled work block, +Phone reads for an existing recipient anywhere (including off-site in B1), +In-person requires co-location, and Filing to an observer waits for that +observer's sampling cadence. The +`phone_reads_off_site_while_email_waits_for_a_work_block` regression sends +both channels to off-site Dana at 02:00 and pins those different outcomes. + +The law now states the shared invariant without stealing the detailed +contract. A delivered message may remain unread; its effects land only when +its channel-specific read condition is met, and replies follow the person's +response distribution on their clock. `messages.md` owns those channel and +timing rules. `intel.md` owns the separate consequence of capturing that +traffic and processing it into information. No runtime behavior, tuning, or +message state changed. + +Defense: `wiki/mechanics/messages.md` is the binding message-graph owner and +already distinguishes all four delivered channels, while +`wiki/mechanics/intel.md` explicitly delegates latency back to it. Presence +should state the cross-system invariant and point to those owners, not replace +their channel table with an Email-shaped summary. diff --git a/wiki/log/DEVLOG.md b/wiki/log/DEVLOG.md index bdebb17c..e7387ef9 100644 --- a/wiki/log/DEVLOG.md +++ b/wiki/log/DEVLOG.md @@ -46,6 +46,11 @@ add or amend a session log, then re-run the generator. - Intent: (see session log) - Log: [wiki/log/2026-07-18-priya-implemented.md](2026-07-18-priya-implemented.md) +## 2026-07-18 - Presence delegates message timing to the channel + +- Intent: (see session log) +- Log: [wiki/log/2026-07-18-presence-message-latency.md](2026-07-18-presence-message-latency.md) + ## 2026-07-18 - Presence states which side of the sensor attack exists - Intent: (see session log) diff --git a/wiki/process/tick-ledger.md b/wiki/process/tick-ledger.md index 6acb7200..ad7c37c1 100644 --- a/wiki/process/tick-ledger.md +++ b/wiki/process/tick-ledger.md @@ -31,7 +31,7 @@ Verdicts: **clean** (slice and code agree), **finding** (acted this tick), | `wiki/mechanics/aggregate-observer.md` | 2026-07-18 | clean | re-audit hours after the earned-topology landing: the page absorbed it coherently — the institutional card, `@assurance` addressing, and band are hidden until a captured filing is processed, the two-stage discovery is pinned by `captured_then_processed_filing_earns_the_assurance_office_in_two_stages`, and `WatchedInput::Filings(ids)` still matches the code; prior audits stand — [2026-07-14 log](../log/2026-07-14-aggregate-observer-audit.md) | | `wiki/gameplay/act-one.md` | 2026-07-15 | clean | law verified against the tree: hall census (prefab.rs 51 live/5 dead/3 empty allocations, `HALL_ROWS` six controlled row segments with named specialists), pre-opened EARS reservoir -> dormant-camera Eyes sink (`sinks.rs`), off-map Voss-desktop demand origin (`sim/work.rs`), QUIET EXIT READY / act_one_complete latch strings (`sim/mod.rs`), two-segment VLAN naming; the opening prelude and loud exit are owned by their dispatched specs (opening.md DRAFT, overt-phase.md READY), cast/schedules pinned by earlier rows | | `wiki/gameplay/run-shape.md` | 2026-07-15 | finding | law verified (Persist default + evaluator, fingerprints gate nothing, split is serde-compat, backup decisions dispatched to rollback/hardware-capabilities); resolved the stale staging [OPEN] to the ROADMAP board and repaired the dangling "Roadmap (v2)" pointer, renaming the section anchor corpus-wide — [log](../log/2026-07-15-run-shape-staging-resolved.md) | -| `wiki/interface/presence.md` | 2026-07-18 | finding | the cursor, fog, provenance, subscription, no-disembodied-hands, and shared-view contracts verify; the drift was the attack-surface clause presenting breaker-gated senses and hostile camera cuts as if current while devices have no powered/available state and breaker panels are inert tiles. The law now states the B1 boundary and the existing overt-phase work order owns explicit circuits, reversible power/device cuts, sense recomputation, and observed acceptance proof — [log](../log/2026-07-18-presence-attack-surface-honesty.md) | +| `wiki/interface/presence.md` | 2026-07-18 | finding | re-audit: the cursor, fog, provenance, subscription, no-disembodied-hands, and shared-view contracts verify. The attack-surface clause now separates B1 feed theft from overt-phase hostile cuts ([prior log](../log/2026-07-18-presence-attack-surface-honesty.md)). The queued follow-up repaired the latency boundary: delivery and read are distinct, read conditions are channel-specific, `messages.md` owns the exact table, and `intel.md` owns only the captured-traffic consequence — [log](../log/2026-07-18-presence-message-latency.md) | | `wiki/interface/narration.md` | 2026-07-18 | finding | Beacon #1: Concerned Assurance felt terminal because decay was invisible; added shared `Nudge::SuspicionCooling` (LIE response) when Office suspicion is Concerned+ and still above its floor, with terminal/Bevy/agent wording and pins — [log](../log/2026-07-18-suspicion-cooling-nudge.md) | | `wiki/engineering/crate-workspace.md` | 2026-07-15 | finding | package shape, contracts, binaries (incl. auto-discovered misaligned-effects), and gate tiers verify; the binding core dependency edge was stale — toml (plots catalog) and blake3 (save fingerprint) landed with Defenses but never amended the edge list; page updated with both and their rationale — [log](../log/2026-07-15-workspace-dep-edges.md) | | `wiki/engineering/sim-decomposition.md` | 2026-07-18 | finding | re-audit: one aggregate, explicit `advance` order, behavior-owned test files, private module seams, canonical fingerprint, public facade, and the under-2,500-line module bound still verify; current persistence wording still claimed additive migrations remained live in `save.rs` after the pre-release ladder was retired, so the standing spec and architecture mirror now assign the exact-current-version gate to `save.rs` while preserving dated v26 extraction history; the queued `carrier.rs` / `read.rs` classification was taken the same day: both post-extraction projections now have rows in the standing topology table and the architecture mirror | @@ -83,5 +83,3 @@ Format: `- YYYY-MM-DD · type · slice · one-line statement of the finding`. Types are the five from [tick.md](tick.md): violation, contradiction, question, bug, insecurity — plus `gate` for a checker owed to the recurrence-promotes-to-the-gate rule. - -- 2026-07-18 · contradiction · `wiki/interface/presence.md` · The message-latency paragraph delegates channel/read timing to `intel.md` and speaks as if every message waits on a person's schedule; `messages.md` owns the four channel conditions, including Phone reading anywhere.