Version. 0.16
Date. 2026-08-03
Charter. standing-notes/dunin7-standing-authorization-charter-v0_1.
Author. Claude Code (inspection session). Operator: Marvin Percival.
Supersedes. v0.15 at record c891e03. All earlier versions stand as siblings; v0.3 remains deliberately absent.
Changes from v0.15. B-9 Step 0 is done, and it did not go the way the promise reads. The walk between records is buildable today over routes that all exist. The walk into a document is not, and cannot be derived — which makes B-9's size an Operator decision rather than a build.
Nothing in code. R-5 inspection run, read-only in both repositories. Engine ffc29af and Operator Layer f477c87, both untouched — no branch, no commit, no npm install, no dev server, no build, no test run, no database, no perimeter call. playground_dev was never connected to.
One document filed: inspection-briefs/loomworks-b9-step-0-findings-v0_1.md, mirrored to ~/Downloads per the standing gate-review rule.
Per-statement linkage does not exist and is not derivable. Four reads settle it:
{"text": <model output>} under content_kind="inline_dict".RenderEvent has no field for one.selected_memory_refs, version-pinned — but the render's only tie to the Shape is one whole-Shape reference. There is no per-fragment structure on either side for a link to attach to.So B-9 as promised is a production-pipeline change and a substrate change, not a walk. That is the fork at Q-15. This session did not design across it.
The render-level walk is buildable now. Five hops, five routes, all five version-pinnable, zero database reads. Plus two forward routes that already exist — ?confirmed_shape_event_id= on renders, and CR-2026-155's /assertions/{id}/dependents. B-9 can walk both directions with what is in the tree.
Its cost is on the surface, not the engine. Three of the five hops are already served over the wire and discarded at the adapter boundary: renders.ts omits confirmed_shape_event_ref, shape.ts omits the Manifestation reference and selected_memory_refs, and compose.ts reads the version-pinned assertion refs and collapses each group to a count.
W-16 is struck, independently. Version-pinned Manifestation retrieval has existed since 5af3195 (2026-04-23) — it predates the walk audit. The mechanism of the miss is worth keeping: the audit enumerated paths, and Manifestation pinning is a query parameter on an existing path, not a path of its own. It encoded the assertion route's shape as the expected shape of the answer.
W-6 is not closed by B-25. B-25 corrected which kind is written; a Companion-path contribution still terminates in the Companion's name. What B-25 makes usable is that kind="companion" carries the person's own id — so a walk need never dead-end there, and the correction belongs at render time.
There is a fifth terminus and it is a sentinel. LEGACY_UNRESOLVED_ACTOR_ID is written with kind="contributor" where the identity is genuinely absent. It reads as an ordinary contributor and must be special-cased by id, or a walk will name a person where the engine deliberately recorded an unknown.
The walk's terminus is the committer, not the contributor. commit_assertion re-attributes on the new version, so contributed_by on a committed assertion names who approved it. B-9's promise asks for who said it — v1, over the existing /history route. Hop 5 is two reads, and they are two different sentences.
wasGeneratedBy opens a real hop and nothing reads it, on either side. B-29 is verified at the code: append_event takes the caller's minted event_id and writes it as the row's primary key. So the field is a primary-key lookup reaching what no reference hop touches — the event kind, the engagement-version, the actor's instruction version, and the WebAuthn presence proof. But zero response schemas expose it and zero routes accept an event id. Exposing it is new work twice over. Q-16.
Hop 3 has a gap the walk survives. organized_groups is null for pre-Phase-19 Manifestations and the response carries no assertion list otherwise — so hop 3 can legitimately return counts and nothing enumerable. Hop 2 already delivers the same set from the Shape, so hop 3 is confirmatory, not load-bearing.
The vocabulary wall: this is CR-2026-163's case, but the cheapest build needs no new exemption. A dedicated walk adapter cannot avoid the walled tokens — one of its route paths is a walled word. But every wire read the walk needs can land in an adapter that is already exempt, as a version-pinned sibling of a read that file already performs. One new adapter needs one entry; four extensions need none.
ReadState needs nothing added. Each hop carries its own, exactly as the Manifestation room already drives one by hand for a single-value read. The distinction a walk needs most — a hop that returned nothing versus a hop that could not be read — is the distinction the contract was built to make. Composition across N hops is the item's business. This is B-6's answer a second time: the question was answered by the item, not by the contract.
Two counts were not taken, and are named as unread. How many live Manifestations carry a null organization, and how many live assertions carry the sentinel. Both are counts, the discipline forbids reading a figure in place of counting one, and neither is countable without the database this session may not touch.
DiscoveryToSeedNotConfiguredError returns 500 where its siblings return 503.RenderingRoom onto ReadState — the last room deriving its own ladder.Q-1, Q-3, Q-10, Q-13 carry forward unchanged. Two new entries, both from this inspection.
| # | Question | Default | Blocks | Proceeds regardless |
|---|---|---|---|---|
| Q-15 | B-9 promises a walk the substrate cannot make. Per-statement linkage does not exist and is not derivable. Three ways forward: build the render-level walk (buildable today, five hops, all routes exist); change the production pipeline so renders carry per-statement provenance (specialist output contract, storage shape, validator — a substrate change); or split B-9 and do both in order. | None taken. Charter F-7 — a pipeline change is an architecture-level fork, and the brief reserves this to the Operator explicitly. | B-9's change request only. | Everything else on the queue. |
| Q-16 | Should the walk use wasGeneratedBy? It opens a hop the reference-walk cannot make — which event produced this version, by which actor, with what presence proof — and nothing reads it today on either side. Exposing it is a response-schema field and a route that resolves an event id. | None taken. The brief directed this session to report what it makes possible and not to recommend; deciding by default is not permitted (F-8). | Only whether B-9 includes the hop. | All of B-9's other scoping. |
F-1: six merges still await one restart — CR-2026-159, -160, -161, both halves of -162, and -163. Unchanged from v0.15; this session merged nothing.
R-5 throughout. Read-only in both repositories, evidence-cited, every claim anchored to a file and line. No fix, no branch, no commit to either code repository, no change request, no design.
No dev stack was raised at all — so R-4's conditions did not arise. No server, no build, no test run, no database, no perimeter call. playground_dev was never connected to (A-7 respected).
Discipline clause held. Three carried claims corrected rather than inherited (W-16, W-6, the walk audit's hop-5 generalization); the grounding documents' remaining claims re-verified against the current tree rather than repeated. Five items reported unread rather than closed with a plausible reading. Where a count was the finding it was counted, not read off a prior document.
Two forks filed rather than decided — Q-15 and Q-16, per §5. Neither was decided by default.
No anomaly. Both trees clean, both SHAs matched the brief's header exactly, no concurrent-session evidence.
DUNIN7 — Done In Seven LLC — Miami, Florida DUNIN7 — status brief — v0.16 — 2026-08-03 The walk between records is proven and buildable. The walk into a document is not, because nothing inside a document points anywhere.