DUNIN7 · LOOMWORKS · RECORD
record.dunin7.com
Status Current
Path change-requests/cr-2026-191-loomworks-b70-log-reconstruction-v0_2.md

DUNIN7-M4 — INFRASTRUCTURE CHANGE REQUEST

CR-2026-191 — B-70: the ratification comes before the remedy (v0.2)

Version. 0.2 · Date. 2026-08-08 · Author. Claude.ai (v0.1) / Claude Code (v0.2 amendment) / Marvin Percival (deciding). Supersedes. v0.1 at record f337279, which stands as a sibling. Target. /Users/dunin7/loomworks-engine. Blocked — nothing is built until §2 is decided. Companion to. inspection-briefs/loomworks-b70-log-reconstruction-findings-v0_1.

What changed from v0.1. v0.1 named a remedy as settled. Step 1 found that the remedy has no precedent and that a different one has three. This version does not pick between them. It puts the question underneath both to the Operator, because neither remedy can be chosen without it.


1. Correction to §1: "settled already, and not reopened here"

v0.1 said: "Settled already, and not reopened here. The remedy is compensating events carrying the numbers 0054 computed."

That was asserted, not read. Step 1 found four migrations that backfilled an operational identifier into existing objects. Three wrote the event log. 0054 alone did not. The compensating-event remedy has no precedent in this system; the in-place backfill has three, and 0041 — the same identifier, on assertions, thirteen migrations earlier — states its reasoning in the docstring.

Fourth instance this run of a premise asserted from a plausible model rather than read, after the credentials list, the Shape response, and CR-2026-189's consent fields.

> Operator, 2026-08-08, on the tell: "The pattern shows up when a document says a thing is settled and names no source. §1 of this CR did exactly that."

Worth having as a check rather than a lesson. Settled is a claim about the past, so it can always be sourced — a decision, a ruling, a prior document. A settledness claim with no citation is the tell, and it is cheap to notice: the sentence itself is the evidence, before any code is read.

2. The ratification, framed narrowly enough to decide

"Is in-place mutation of the event log acceptable" is too broad a question to answer. Asked that way the answer is obviously no, and three migrations become violations by a definition nobody applied when they were written.

The real question is narrower:

> ### Is an operational identifier that did not exist when the object was created an audit-trail fact at all?

0041 claims it is not, and says why:

> "R-A28's non-erasure discipline governs ongoing operation — the assertion's content / state / commit facts are never mutated. display_number is an operational identifier that didn't exist before this migration; surfacing it after the fact is a one-time data evolution, not an audit-trail rewrite."

The claim has a shape worth naming: **it distinguishes what the record is about from what the record is addressed by.** Content, state, and commit facts are what happened. A display number is a handle the system later grew for pointing at what happened. On 0041's reading, adding a handle is not editing the account.

The two outcomes are not symmetric:

Either way the question is prior to the remedy, which is why v0.2 stops here rather than proposing one.

3. The compensating-event path, costed

v0.1 preferred this path on philosophical grounds, and those grounds are real: it writes only new facts and edits nothing. Its structural cost was not stated, and it is substantial.

memory_events carries UNIQUE (object_id, object_version), and append_event builds the payload from a complete MemoryObject. A compensating event cannot attach a fact to an existing version; it must mint a new one.

> That is noise written into the record in the append-only discipline's name. A person reading that engagement afterwards sees 52 revisions that never happened. The discipline exists so the record tells the truth about what occurred; a remedy that honours its letter by fabricating history is not plainly serving it.

And there is no honest author. ActorKind is contributor | agent | person | companion, and all four are in live use — 599 / 299 / 187 / 77 events respectively. None is the system. Writing a compensating event means either attributing a repair to a party who did not perform it, or inventing a fifth actor kind — a substrate decision, not a change-request decision.

Dating, for completeness: timestamp is caller-supplied, so backdating is mechanically available. It should not be used, and the safeguard is convention rather than schema.

4. What Step 1 established as fact

5. Seed-mutability impact — Kind C, checked, no contact

All 64 shape events carry seed_version_at_production; no render event does; no seed_ref in either. Numbering never reads it, and neither remedy would introduce a seed dependency. Seed-adjacent, not seed-dependent — B-69's worked example holding on the first entry recorded after it was adopted.

6. Revised build steps

| Step | What | Mode | |---|---|---| | 0 | Pre-flight. | done | | 1 | Read per v0.1 §2. File findings. Halt. | done — findings filed | | R | Operator ratifies or rejects §2's claim. | Blocked on the Operator | | 2+ | Scoped in v0.3, and the shape depends entirely on R. | Blocked |

No remedy is proposed here on purpose. Proposing one would smuggle an answer to §2 into a document meant to ask it.

7. Out of scope, unchanged


DUNIN7 — Done In Seven LLC — Miami, Florida CR-2026-191 — B-70 the ratification comes before the remedy — v0.2 — 2026-08-08