Court doctrine · ratified 2026-08-14

The Primitives Lens

A standing five-question dimension for every court that verdicts a consequential merge — so the primitives can never be silently sidelined again.

RATIFIED by Robert · 2026-08-14 · standing doctrine, flagship + factory; fleet-wide via the port
  1. Why now — your steering, taken seriously

    You said it in one sentence: “the adversaries weren’t testing the right things — I want the environment legible, and the primitives (genome, atomic slots, claims, the reader) never silently sidelined.” The record backs you. Last night’s courts tested whether claims were honest — eight-plus lies caught before any merge. Nothing standing tests whether the primitives are honored: did captured truth stay untouched, did anything ship nameless, did every writer hold a claim, did code quietly start deciding meaning, is new state honest on its face. This proposal makes that second test standing, with evidence instead of vibes.

  2. What the census found — two repos, read end to end

    Where the primitives are wired, they hold. Twice today the environment refused a receipt that no longer matched reality — exactly the behavior we want. The captured-truth writers are fail-closed in both repos, with automatic rewind on refusal.

    Where they aren’t wired, drift is real. Two pieces of code that were ordered killed seven weeks ago — both of them code making judgment calls — are still alive and wired into the factory’s production paths. A declared safety backstop at the flagship turns out to be a setting no code reads. And the factory’s build file claims several checks are merge-blocking that its own governance ledger says never run in automation.

    The reader primitive cannot be held by standing checks at all. Four separate times, code quietly re-grew the ability to interpret meaning. Every catch was an adversarial review. The standing check’s own author admits deliberate insertion “is not mechanically decidable.” For this one primitive, a recurring adversary isn’t one option — it’s the only mechanism that has ever worked.

    ↘ go deeper — where the receipts live
    Full censuses with file:line citations: ~/next-arc/primitives-census/flagship-census.md (Neuron-Sites/mvahpets.com @ assembly-line-build) and factory-census.md (Neuron-Sites/neuron @ main), raw transcripts alongside. Every claim on this page resolves to a citation in those two files; nothing here is from memory.
  3. Where this applies — the mold and the castings

    One place: every court that verdicts a consequential change, in either repo. Two layers protected: sites are castings, the compiler is the mold. The machinery’s whole job is to confer the five properties on every site that flows through it — a mold that quietly loses a property loses it for every future casting, so the court guards the mold and the mold guarantees the castings.

    Histories makes this concrete: for sites, history is collected by construction — capture is genesis, provenance is minted at the door, and the writers physically refuse overwrites. So the court-time question is never “was history collected?” It is: did this change break the collecting machinery, or reach in and rewrite something already captured? And the machinery keeps histories about itself too — receipts bound to the exact state of the tree, version labels never reused, verdicts banked where a session’s death can’t take them. The spine says it in four words: the axiom points at ourselves.

  4. The lens — five questions, answered by every court that verdicts a consequential merge

    Grounded in the spine — one axiom, nothing is allowed to be nameless, at its five altitudes — plus the reader law. One line each per court; most answers will be “this change touches no primitive.”

    Q1 — NAMES. Did anything ship nameless — content, behavior, an instrument, or an absence without a recorded reason?
    ↘ what the court reads · current state
    Reads: anchor/coverage/tree records against page bytes; born-covered mint verdicts; absence categories; (factory) the word-tier coverage proxy + the no-type-allowlist lint + the gate-reachability ledger for any new instrument. State: flagship is strong at the mint — a page born with an unlabeled piece is red at birth. Factory: the full total-coverage instrument is honestly declared unwired (a 12-page proxy blocks instead), and the coverage ratchet counts instead of keying — a one-for-one swap (one slot dies, an unrelated one is born) stays green. Both gaps are self-declared in-repo: honest, but thin.
    Q2 — HISTORIES. Was captured truth annotated — never overwritten, never back-filled with synthetic history?
    ↘ what the court reads · current state
    Reads: provenance trailers on every capture-touching commit; the single-writer guard and its structural test; lineage chains; the flagship’s rule that every deployed byte traces to captured bytes. State: the strongest primitive in both repos — fail-closed writers with synchronous rewind. The known scar is human, not code: the July door-bypass, where a lead stepped around a correct refusal by hand. Rails hold; the residual risk is seats.
    Q3 — CLAIMS. Did any writer act without a claim, or two writers share one surface?
    ↘ what the court reads · current state
    Reads: lock files left mid-flight in a diff; the edit log’s last entry against actual history; the machine-level claims file for fleet surfaces. State: strong inside each repo (exclusive per-book locks with liveness reclaim; a single fact-writer; a fencing lease built ahead of its consumer). The fleet level is honor-system only — the claims file lives outside both repos and nothing mechanical proves a writer consulted it.
    Q4 — THE READER. Did any code take a meaning seat — deciding same, done, verified, or refusing on its own behalf?
    ↘ what the court reads · current state
    Reads: the physics/route/rails test (the only three legitimate shapes of “no”); the ratified shape for deferred judgments — actor, basis, revisit trigger; the flagship’s closed refusal census; the factory’s judgment-seat audit table (stale — see F-1). State: provably not holdable by standing checks — four adversary-only catches; the one existing lint guards one already-dead instance by name. The cure shape is a recurring adversarial round, not more code. This question is the lens’s beating heart.
    Q5 — THE FACE. Is every new verdict-bearing surface honest on its face — basis and residual stated — and does a named reader actually read it?
    ↘ what the court reads · current state
    Reads: certificate and risk-record schemas plus the three-way registry lint (factory, wired and blocking); manifest and receipt freshness (flagship, wired and blocking — it fired twice today); and for anything new, one question: name the reader of this record. State: freshness is green and battle-tested, but write-only surfaces exist that nothing reads, and one declared backstop is a dead setting. The sub-question “name the reader” alone would have caught two of this census’s findings.
    If no reader is named, the record is decoration. And for the reader question itself: only a recurring adversary keeps it true — that is a census-proven fact, not a preference.
  5. What the lens already caught — the census as its own first ride

    Seven findings, ranked. Each verdict is one line; depth under it.

    F-1 · factory · the reader — RESOLVED by its own court (the lens’s first ride, 08-14). The “kill order” was never Robert’s and never named these modules. One seat is a measured meaning-guesser — demoted, never deleted (the deletion floor held); its small basis-carrying cure is queued. The other was already cured by Robert’s August proceed-and-inform ruling — superseded, off the table. The court also caught our own census overclaiming (“no resolution record” — five existed) and found the doctrine map itself citation-stale at every receipt — a new class finding with its cure queued.

    F-2 · flagship · the face. A declared mislabel-backstop is a setting no code reads — a mislabeled change would skip its whole safety battery.

    F-3 · factory · the face. The build file claims merge-blocking status the repo’s own governance ledger denies.

    F-4 · factory · names. The coverage ratchet counts instead of keying — a slot can silently stop being editable.

    F-5 · factory · the face. Three write-only record surfaces have no reader at all.

    F-6 · flagship · names. The absence ledger cites a law document that doesn’t exist in that repo.

    F-7 · factory · histories. The external audit ledger is honor-system, declared unwired.

    ↘ go deeper — routes and citations
    F-1: classifyWorldConsequence (world-consequence-registry.ts:59 ← insert-text.ts:381) + computeEditDecision (edit-cli.ts:888 ← :1491, edit-transaction.ts:645); ordered killed per LAW-ENFORCEMENT-MAP.md:96-105; no resolution record. Route: its own court — verify the kill order’s intent, then execute or supersede on the record.
    F-2: ci/checks.json:66 contentLane:true, read nowhere in two-lap-gate.ts (inclusion is guards[].length>0 at :575/:906). Route: wire or delete, with a red-proof through the mislabel path.
    F-3: gate-reachability-allowlist.json: “make gate runs on NO automated surface.” Route: every enforcement citation traces to the CI workflow or the comment goes.
    F-4: editability-coverage.ts:14-22, self-documented. Route: keyset ratchet, scheduled.
    F-5: .edits/walk-log.jsonl, .gate/goal-tracer.json, docs/ai/receipts/ — zero gate/CI readers. Route: name a reader or retire the surface.
    F-6: absence-ledger.ts:4 cites docs/ai/genome-legibility-law.md, absent in mvahpets. Route: vendor the text or fix the citation.
    F-7: Plato deposit ledger, “no deposit step wired into either CI shard yet.” Route: acknowledged gap; owner’s call.
    Standing item already on the road: the flagship word-counter meaning seat (two-lap-gate.ts ~379-391) — deletion queued.
  6. Cadence — teeth without ceremony

    1. Every court that verdicts a consequential merge answers the five questions — one line each; findings land at class altitude or above, never as one-off patches.

    2. The reader question additionally gets a recurring adversarial round: on every change touching edit or gate machinery, plus a periodic sweep. Standing checks provably cannot hold it.

    3. The full two-repo census re-runs at every arc boundary. Today’s census is the baseline; re-runs diff against it cheaply.

    4. The one-way valve holds: lens findings tighten the machine only. Nothing a teammate can reach ever gets a new refusal because of a lens finding.

  7. The four calls — RULED

    Ratified by Robert, 2026-08-14, all four as recommended. Recorded below; annotation stays open for amendments.

1 · Wording — RATIFIED as-is

Q5 deliberately keeps “honest face” and “named reader” married — the reader-half gives the face-half its teeth. Wording stays amendable as court usage teaches.

2 · The undead judgment seats (F-1) — RULED: its own court

Investigation dispatched the night of ratification (read-only seat court: provenance of the kill order, what each seat decides today, verdict per seat). Its cure lands after the factory cure train merges — never a drive-by deletion inside a big PR.

3 · Scope — RULED: flagship + factory now; the port carries it fleet-wide

One clause rides the port spec, so every future repo inherits the lens at birth — never by retrofit.

4 · Census cadence — RULED: keeper-owned, every arc boundary

Each re-run diffs against this census as baseline; any new unprotected edge is a routed finding, never a filed note.

Reference strip — jump by type: Q1 names · Q2 histories · Q3 claims · Q4 reader · Q5 face  |  F-1 F-2 F-3 F-4 F-5 F-6 F-7  |  cadence · your calls · canonical Markdown: ~/next-arc/primitives-lens/the-primitives-lens.md