R-404 CLOSED with the ruling; R-417 CLOSED by cause removal; R-418/419/420 filed
gates / gates (push) Successful in 17s

THE RULING WAS NEITHER OPTION AS FRAMED. Both offered answers - narrow the gate, or leave it and
write waivers - argued about the gate, and the gate was never the problem.

DIAGNOSIS, from live source: golden_currency_gate.py never looks at the push. It compares the
controller's newest CHANGELOG heading against this repo's bake evidence and returns the same
verdict whatever you are pushing - correct for a standing invariant, wrong as a push gate. And
controller_gates.py had NO golden-currency entry at all. So the repo where a release happens never
checked, and the repo that cannot create the debt was refused on every push. 18 of the last 24
pushes here touched no code - measured, and the new classifier agrees EXACTLY - most of them by
construction, because the controller's code is in one repo and its register lives in this one. SIX
of those 18 were bake records, so the push that PAYS the debt is itself documents-only: the gate
was blocking its own cure.

Not the waiver its docstring prescribes: that clause was written for a release nobody wants a
golden for. R-417 was a release we DID want a golden for, on a night the runbook forbade baking. A
waiver would have recorded a lie.

RULING: block the push that can create the debt, notify the push that cannot.

The gate's logic, exit codes and wording are BYTE-IDENTICAL. Only the consequence changed, for one
gate, on one kind of push, with a loud ADVISORY block so nothing goes quiet.

R-242's vouch half is amended in place to say it is UNTOUCHED and still open - a baked-but-unvouched
golden still passes both the gate and the new notice. Do not read R-404's closure as closing it.

FILED: R-418 - this runner's docstring listed ELEVEN gates while THIRTEEN were registered;
one-register and closed-register ran undocumented since 2026-08-24. Enumeration fixed here, the
correspondence is still unenforced. R-419 - observations_gate.py accepts an item whose body merely
CONTAINS "NOT-A-FINDING", even in prose disclaiming it; found by accident when a planted test
observation passed and my live validation proved nothing. R-420 - controller_gates.py could not
express a non-blocking gate at all before today.

Register: OPEN 171 -> 172, CLOSED 158 -> 160.
This commit is contained in:
2026-09-01 12:01:10 +02:00
parent 1f74427fd2
commit 1e6c387a0b
6 changed files with 116 additions and 18 deletions
+32
View File
@@ -14,6 +14,38 @@
> language, one screen, no identifiers in the prose. Same subjects, different readers; merging them
> would make one of the two audiences stop reading. `STATUS.md` is also a **view of `OPEN-ITEMS.md`**
> and holds nothing of its own; this file does hold its own content, namely the standing rulings below.
## A guard aimed at the wrong repository trains everyone to bypass it (2026-09-01, R-404 / R-417)
**The ruling was neither option as framed.** The question on the table was whether a documents-only
push should be subject to the golden-currency gate, and both answers offered — *narrow the gate*, or
*leave it and write waivers* — argued about the gate. **The gate was never the problem.**
The diagnosis, measured from live source rather than reasoned: `golden_currency_gate.py` **never
looks at the push**. It compares the controller's newest CHANGELOG heading against this repo's bake
evidence and returns the same verdict whatever you are pushing — correct for a standing invariant,
wrong as a push gate. And `controller_gates.py` had **no golden-currency entry at all**. So the
repository where a release actually happens never checked, while the repository that cannot create
the debt enforced it on every push. **18 of the last 24 pushes here touched no code** — measured, and
the classifier built for this agrees exactly — most of them by construction, because the controller's
code lives in one repo and its register, architecture and status live in this one. Worse: **six of
those eighteen were bake records**, so the push that pays the debt is itself documents-only and the
gate was blocking its own cure. `--no-verify` had been reached for thirteen times, each with a
recorded reason, which is what a correctly-bypassed guard produces.
**The ruling: block the push that can create the debt, notify the push that cannot.** The gate's
logic, exit codes and wording are byte-identical; only the consequence changed, for one gate, on one
kind of push, with a loud ADVISORY block so nothing goes quiet. A notice now fires in the controller
repo at the moment a release is committed — advisory in every case, because at that moment the golden
legitimately cannot exist yet.
**Why not the waiver the gate's own docstring prescribes.** That clause was written for *a release
nobody wants a golden for*. The case that actually occurred was *a release we did want a golden for,
on a night the drill runbook forbade baking*. A waiver would have recorded a lie.
**What did NOT change, and must not be presumed:** nothing gates the **vouch**. A baked-but-unvouched
golden still passes both the gate and the new notice — R-242's remaining half, still open, for the
unchanged and forced reason that the vouched version exists only in the hub's database.
## Skills cover the PROCESS domain too, from named MIT sources with named exclusions (2026-08-25)
**[RULING] `felhom.eu/skills/` now holds two kinds of skill and the distinction is deliberate.** The