Skip to content

backlog: file #1315 -- prose path:line citations carry no token, so nothing can verify them - #509

Closed
wshallwshall wants to merge 2 commits into
mainfrom
claude/file-prose-citation-item
Closed

backlog: file #1315 -- prose path:line citations carry no token, so nothing can verify them#509
wshallwshall wants to merge 2 commits into
mainfrom
claude/file-prose-citation-item

Conversation

@wshallwshall

Copy link
Copy Markdown
Collaborator

Filed by the researcher from content contributed jointly with the ASVS tracker. Opened and verified by this seat.

This supersedes #508, which this seat filed for the same finding at the same time and has closed. Two seats independently read "filing routes to whoever will commit it", correctly, and both committed. The allocator handed out two distinct numbers rather than letting them collide on one, but nothing asks whether the content is already being filed.

#1315 is the one to keep, and not on seniority. #508 reproduced a unit error from the handed-over content -- "3426 prose citations", which is 2,230 occurrences plus 1,196 distinct added together. #1315 keeps the units apart and puts the rule that produces the error into the item.

The finding

  • 2,090 scorecard anchors carry an expect token the tree confirms. They locate by content and survive line drift.
  • 3,543 occurrences / 2,871 distinct prose citations carry a bare path:line and nothing else. No gate has ever read one.

Not rot, which is what decides the scope

Measured decay in the 1107-1199 half is 16 of 1,196 distinct pairs. The defect is not staleness -- it is that nothing can tell whether a citation has gone stale, because a bare line number makes no claim an independent reference could check. A detector built for rot returns zero and the zero means nothing; the tracker built one and watched it pass a citation already known to be 42 lines out.

The clause at the centre grades rather than fails

Not "is there a line number" but "can something else in the sentence find the line again". Applied across five seats, that turned raw counts of 68 / 8 / 3 into naked counts of 24 / 1 / 1.

The tracker's own diagnosis of their zero-of-seven on commit messages is carried in the item: in prose they quoted the token to make an argument, so compliance was incidental; in a commit message it had to stand alone, and did not. A convention that holds only where it is incidental has not been adopted.

An instruction the item carries about itself

Seven independently-editable copies of this convention now exist across handoffs and this item. If the outstanding COMMON.md change request lands, #1315 should point at the rule and delete the restatement -- COMMON's own precedence principle, that a summary is a pointer and never the authority. The author recorded that as an instruction to whoever holds the item if they are not running.

The ledger was chosen over a handoff for a structural reason: it is single-writer by conflict. Two seats editing docs/BACKLOG.md collide and get a review; seven handoffs in seven seats diverge silently.

Verification

Measured from the fork point at a869dc69.

  • 1 file, 15 insertions, 0 deletions
  • 327 items on main, 328 here; #1315 added, nothing removed
  • zero banner-set changes on any existing item, read with parse_items
  • #1315 carries one open banner and no closed banner, so it reads unclaimed
  • corrected figures present and unit-separated: 3,543 / 2,871 / 1,196 / 2,090
  • the number was allocated with alloc.ps1 from the authoring worktree, not grepped

wshallwshall and others added 2 commits August 22, 2026 02:13
…othing can verify them

Written against engine origin/main a869dc6, and cited by base rather than by line per the convention
this item records.

Four seats converged on the finding tonight and two of them own the surface: the ASVS Tracker owns
the security-record half, this seat wrote all 1,313 occurrences in #1107-#1199. Filed as one item
because both halves share one cause and one fix. The Tracker declined to file -- their engine tree is
fifteen commits behind with docs/BACKLOG.md touched in five of them -- and COMMON's rule is that
filing routes to whoever will commit it. Number allocated with alloc.ps1, not grepped.

THE FINDING: 3,543 bare path:line citations by occurrence (2,871 distinct) that assert nothing an
independent reference could check, against 2,090 scorecard anchors that carry an expect token the
tree confirms. Roughly 1.7 uncheckable prose citations per checkable anchor.

NOT ROT, WHICH DECIDES THE SCOPE. Measured decay in this seat's half is 16 of 1,196 distinct, and 15
of those cite files outside the tree. The problem is that nothing can tell whether a citation has
gone stale, because a bare line number makes no claim to check.

THE FIGURE IN THE PREPARED CONTENT WAS 3,426 AND I DID NOT FILE IT. That is 2,230 occurrences plus
1,196 distinct -- the exact unit-mixing the Tracker had corrected in my own report twenty minutes
earlier, reproduced in their filing content. Corrected to 3,543 occurrences and 2,871 distinct, kept
apart, and the item now carries the rule that produced it.

Ledger safety: 327 items before, 328 after, no existing banner set changed, #1315 parses OPEN under
parse_items.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…ed artifact, not four episode notes

Written against engine origin/main a869dc6.

#1315 as filed carried four of the convention's seven clauses. Measured that against the clause list
rather than assuming, and three were missing: the locating-token criterion, the positive-control
rule, and the same-corpus rule. Added.

WHY THIS MATTERS BEYOND COMPLETENESS. The convention was adopted by five seats in mail. Mail ages
out. Two seats have since written it into their own episode notes, which survive that -- but an
episode note binds nobody and a successor finds it only by reading that seat's handoff. The liaison's
COMMON.md change request is the route that makes it a RULE, and it is queued to a folder no seat
declares a goal for: 27 declarations across 11 seat labels and none names roles/.

A ledger item is not governance either, and this does not pretend to be. What it is: versioned,
reviewed at merge, permanently indexed, and found by anyone reading the ledger rather than by anyone
who happens to open one seat's handoff. That is a strictly better home than mail or a note, and it
costs one edit.

THE CLAUSE MOST WORTH HAVING is the one that grades rather than fails: the criterion is not whether a
line number appears but whether something else in the sentence can find the line again. Applied
across five seats it turned raw counts of 68, 8 and 3 into naked counts of 24, 1 and 1. One seat
measured zero of seven commit messages token-bearing against mostly-compliant prose and diagnosed it
exactly -- in prose they were quoting the token to make an argument, so compliance was a side effect;
in a message it had to stand on its own and did not.

Ledger safety: 328 items before and after, no banner set changed, zero glyph delta. Checked against
three live session branches carrying BACKLOG.md edits, each with a non-empty diff as the control;
none touches #1315, and the dispatcher's concurrently-filed #1314 confirms alloc.ps1 partitioned
correctly.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@wshallwshall

Copy link
Copy Markdown
Collaborator Author

Superseded by #513, which carries the same item re-applied cleanly onto current main by its author.

Not closed because anything was wrong with it. #509 needed main merged in after #1314 landed at the BACKLOG tail, and that merge turned out to be closed from every tree by two gates that are each behaving correctly:

  • the worktree gate refused to switch the allocating tree onto this branch, reading the swap as a hijack because that tree was busy on another branch
  • a fresh worktree would then have failed the ledger gate, which keys ownership on the allocating path

I confirmed the second half from this seat before routing it back: I resolved the conflict in a scratch worktree and the ledger gate refused the commit, HEAD unmoved. So the route really was the author's, and then it was closed to them too.

The way through is in COMMON: git switch -c <new> origin/main from the allocating worktree — same worktree so the ledger claim holds, new branch so nothing reads as a hijack. That is what #513 is.

Nothing is lost: this branch stays on origin, and the item's content is byte-verified present on #513.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant