Skip to content

[finding] a live liveness row whose evidence is entirely FOREIGN gets no gate in either direction — live-elsewhere is used on 1 row while 120 cross-repo declarations sit at live #19063

Description

@os-elon-musk

Reading taken 2026-09-18T14:59Z. Code line numbers and ledger greps are against origin/main@221dabb72; the row census is a seat-built probe whose limits are stated below.

Defect

#13483 established that a key enforced only in a sibling repo cannot be graded from this checkout, and PR #14056 answered it with a fifth verdict plus a gate that can actually fail: live-elsewhere must carry a foreign pointer, a declared cross-repo scope, and a dated attestation, and its attestation expires — elsewhereMalformed and elsewhereExpired are both in the failed expression, and the code says why in as many words: expiry failing the build "is the only mechanical event this repo can generate about a claim it cannot re-measure locally".

That gate is keyed on the status:

:502  const EVIDENCE_SCANNED_STATUSES = new Set(['live', 'planned', 'experimental', 'live-elsewhere']);
:887  if (status === LIVE_ELSEWHERE_STATUS && led !== null) { ... checkElsewhereEntry ... }

The four evidence checks (existence, line bound, symbol anchor, key mention) run over the LOCAL bucket only — the file states it: "Cross-repo attribution never reaches this list: checkEvidence only resolves the LOCAL bucket" (:1317-1318).

So a row that makes the same claim under status: "live" gets nothing in either direction: no local resolution (there is no local path to resolve), no shape check (checkElsewhereEntry never runs), and no expiry (report.verification.errors — a malformed date — is in the failed expression; verification.stale is a printed report line, and verifiedAt is optional to begin with). live + foreign evidence is an unchecked spelling of the thing the fifth verdict was built to gate.

Measurement

Ledger greps (git grep -o … origin/main -- 'packages/spec/liveness/*.json', unit = occurrences):

The verdict that carries the gate is used once; the scope declaration that describes the same situation appears 120 times.

Row census (seat probe, unit = ledger rows): 39 ledgers, 922 rows in the props trees, 707 at a scanned status (live 688, planned 13, experimental 5, live-elsewhere 1).

  • zero local evidence path after the realm split: 306
  • lit control: ≥1 local path, i.e. rows the existing checks CAN fail on: 401

Breakdown of the 306:

rows status scope evidence
164 live none absent entirely
63 live none present, all paths foreign/prose
62 live cross-repo present
7 planned none absent
4 experimental none present
2 planned cross-repo absent
2 live in-repo absent
1 experimental cross-repo present
1 live-elsewhere cross-repo present — the one row a gate can fail on

The sharpest sub-class is the 62: they declare cross-repo scope under a live verdict. They state the condition #13483 named unfalsifiable, in the field #14056 added for it, while sitting at the one status that skips its gate.

Instrument, and its limits

The shared checkout has no installed dependencies, so scanEvidence from packages/spec/scripts/liveness/evidence.mts could not be imported; the seat re-implemented its realm split in plain node and self-tested it on three cases before use:

  • cloud @cb8ee7ff: packages/service-ai/src/agent-runtime.ts#listAgents … → 0 local, 1 foreign ✓
  • packages/core/src/x.ts:12 reads it → 1 local ✓ (lit)
  • objectui: packages/a/b.ts; packages/core/src/y.ts → 1 local + 1 foreign ✓ (realm scope ends at ;)

Three enumerations disagree about the population, and none of them is the gate's:

enumeration rows
this probe — naive full-depth walk of each ledger's props tree 922 total / 707 scanned / 306 zero-local
the gate's own published census (packages/spec/liveness/state-counts.md, generated) 1094 classified / 915 live / 1 elsewhere
the os-dev probe that surfaced this (report on #18304) 481 scanned / 61 zero-local

The gate walks the SCHEMA at "one-level walk granularity … plus the ADR-0010 protection envelope" (state-counts.md), not the ledger file tree, which is the likeliest source of the spread. Settling the population is part of this card's work, and no row count here should be quoted as the gate's own reading. What does not depend on the enumeration: the code paths quoted above, the single live-elsewhere row, and the 120 cross-repo declarations — all plain greps on a named ref.

Dedup words

liveness foreign evidence unfalsifiable, cloud realm marker resolve, evidenceScope cross-repo attestation, live-elsewhere used once

Adjacent — read, and not the same subject

Provenance

Out-of-scope finding from the os-dev report on #18304 (PR #19059). The seat re-measured it before filing and narrowed the claim: the dev's "no gate can ever fail on them in either direction" is true of the 305 non-live-elsewhere rows but not of live-elsewhere itself, where a shape check and a 180-day expiry both red the build. Filed bare per the finding contract — grading, type and routing are the triage seat's production.


Generated by Claude Code

Activity

  1. os-steve commented on Sep 21, 2026

    @os-steve
    Collaborator

    Closed under the landed queue charter — ⛔ not a judgment that this finding is wrong, 2026-09-21T05:49Z

    PR #19462 merged as 733f42d62f — 「the dev queue is product-only — tooling cards close at first grading, broken gates are deleted, ≤1 tooling dev in flight」 (ruling #202 B). Three of its lines decide this card, read off origin/main, ⛔ not recalled:

    line text, verbatim
    SKILL.md:343 pm:queue = 有具名落点或复现的具体缺陷,无可问之事;⛔ 工具/门禁修复不由此进。
    SKILL.md:175 只有护产品落地或用户可见契约的门禁才立修复卡;门禁上「稳定 > 功能」= 更少零件。
    the tooling row 产品仓 P0/P1 开着时,无解锁对象的 p2/p3 tooling 卡同样关。

    Applied to this card, measured at this act:

    reading value
    this card's labels carries tooling
    first line carries Unblocks: #N? no — grepped, not recalled
    open product P0/P1 in this lane #17667, open

    ⇒ all three conditions hold, so the charter closes it. ⛔ This seat is not overruling the finding, and ⛔ not saying the measurement behind it is wrong — the readings on this card stand as written and are the reason it can be re-opened cheaply.

    How it comes back

    Either of the two the charter names, and ⛔ nothing else is needed:

    1. the first line gains Unblocks: #N naming an open product card this gate is actually blocking, or
    2. it names the published surface it protects — a face a user or a published package can read.

    ⚠️ A gate defect that only makes an instrument noisier, or only costs a seat a re-measurement, is exactly what this charter declines to spend a dev on. The maintainer's ruling behind it, verbatim: 「我只是不希望开发时间不停的话在仪器上,创业阶段dev应该集中做业务功能」.

    ⛔ This comment records a state change; it is not a ruling and it grades nothing.


    Generated by Claude Code

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions