Version. 0.5
Date. 2026-07-31
Charter. standing-notes/dunin7-standing-authorization-charter-v0_1, ratified 2026-07-30.
Author. Claude Code (execution + inspection session). Operator: Marvin Percival.
Supersedes. v0.4 at record 1ec5c2a. v0.2 at 40571cf and v0.1 at 602bd9c stand as siblings, unaltered. v0.3 remains deliberately absent.
Changes from v0.4. Records the first engine work of the charter regime and the first Operator Layer inspection under it. CR-2026-159 halted at Checkpoint A on its own named condition — §2 and §7 carry it. The Operator Layer CR-A Step 0 brief executed clean, both questions answered, none unread. §1 generated from git log at filing time, per v0.4's rule. Two new decision-queue entries, and D-1 is reopened by evidence for the first time.
What is different in kind about this window. v0.4 could assert that no engine work had been built all day. That is no longer true: the engine took a branch and three commits. main did not move.
This section is generated, not written — produced by the executing session from git log at filing time, per v0.4's rule.
loomworks-record), continuing from v0.4's table
| Commit | Subject | Files changed |
|---|---|---|
| 1ec5c2a | file status brief v0.4 — section 1 generated at filing; manifest v0.77 application closed | 1 |
| 05ba36b | file CR-2026-159 v0.4 — Checkpoint A reports and proceeds; no Operator gate | 1 |
| c942fe1 | file standing note — superseded versions of executable documents | 1 |
| 78388dc | file standing note v0.2 — record outranks kickoff; correct the v0.3 citation | 1 |
| 556c316 | file standing note v0.3 — strike the precedence claim; no note outranks an Operator instruction | 1 |
| 0c3a90a | file CR-2026-159 Checkpoint A halt report v0.1 | 1 |
| 1971eb2 | file Operator Layer CR-A Step 0 findings v0.1 | 1 |
main at 1971eb2 before this brief, pushed and origin-synced at each step.
loomworks-engine)
main unmoved at a317051. Nothing merged, nothing tagged, nothing pushed.
Branch cr-2026-159-provenance-seam, three commits, local and unmerged:
| Commit | Step |
|---|---|
| e2661bc | Step 0 — pre-flight + CR archival to docs/phase-crs/ |
| 9fbe04a | Step 1 — the seam + the corrected events.py module docstring |
| a794754 | Step 2 — the two backfill repairs |
Working tree carries M uv.lock unstaged, as it did at the window's start.
loomworks)
main at 99f7f64, working tree clean. Read-only inspection only — no branch, no commit, no stash, no install, no build, no test run.
steleUntouched this window.
Full evidence in current-status/cr-2026-159-checkpoint-a-halt-report-v0_1.md. In brief:
Steps 0, 1 and 2 are done and verified. Pre-flight matched the CR's Baseline in every particular — HEAD, git describe, working tree, alembic head 0102, CR number free, and all six §6.4 anchors confirmed unmoved by direct read. The seam works: live verification on a throwaway database shows both the provenance column and the nested payload.provenance carrying the row's true event_id, and a deliberately wrong caller-supplied value reaching neither. Acceptance-gate items 2 and 3 hold.
One of the four Checkpoint A halt conditions fired: a pre-existing test needs editing. tests/test_consideration_triggers.py:95 passes at a317051 and fails with the seam change — causation established by restoring the baseline file and re-running, not inferred. It asserts fetched == episode: whole-object equality between the object open_consideration returns and the object read back from the database.
The finding is larger than the test. The CR's §1 states "the surface is write-side only, so no downstream consumer can break." That does not hold for option B. MemoryObject is frozen, so append_event corrects a copy; the caller's object keeps the fabricated value. Roughly 35 of the 93 append_event call sites return a locally-built object within a few lines of the append — every one of them now hands back an object whose provenance disagrees with the row just written. It is invisible today only because nothing reads the field, and exactly one test detects it, by whole-object equality rather than by asserting the field — which is why the CR's sweep for value assertions correctly returned zero and still missed this.
This reopens D-1. Charter C-3 forbids absorbing the correction in flight; the resolution is a CR version bump from a drafting session. Three shapes are recorded in the halt report §1.2 as material for that bump, not as a recommendation.
tests/test_stele_router_mount.py::test_stele_router_mounts_and_begin_resolves_end_to_end fails at a317051, verified against the restored baseline. It expects 200 and receives 401 {"detail":"Authentication required (no valid session)."}. Unrelated to provenance, untouched by this CR, and out of its scope. Recorded rather than fixed. Suite totals both runs: 2 failed, 3438 passed, 68 skipped.
The CR asks Step 0 to confirm "83 sites / 37 files." 83 sites confirmed exactly — 81 wasGeneratedBy=uuid.uuid4() plus 2 wasGeneratedBy=uuid4() at engagement/manifestation.py:531 and :551. They sit in 36 files, not 37. The enumeration is closed: 103 total occurrences in src/ = 84 with a uuid4 call + 19 without, with no alternate-spacing form hiding a 37th file.
Not treated as the halt: the tree has not moved, and the figure describes code the CR puts explicitly out of scope. It is a fifth instance of the pattern §9 names.
The two manifest items owed to the next bump — the internal inconsistency between splice 4's "four instances" and entry 130's "caught all five", and the amendment-instructions filing gap — both stand.
D-1 — B-29 takes seam option B. REOPENED BY EVIDENCE. Option B is implemented and demonstrably correct at the database. What it also does — leave ~35 call sites returning an object that disagrees with the record — was not in the CR's risk case, and is now measured. This is a queue entry (Q-2), not a session decision. Reversal cost is no longer one redraft: the branch holds working Step 1 and Step 2 commits, and Step 2 survives any resolution.
D-2 — bookkeeping before the change request. Executed. Closed.
D-3 — the two backfill repairs ride with B-29 regardless of seam option. Confirmed correct in the strongest way available — they are built, and they are the part of the CR untouched by the finding. Both are raw-SQL paths returning no object.
D-4 — no historical backfill of the fabricated field. Unchanged, and unbuilt — the recorded statement rides in Step 4's implementation notes, which are not written.
D-5 — the Operator Layer brief went before the completion scoping note. Executed and vindicated: the brief closed both its questions with nothing unread, and change request A now has its grounding.
D-6 — the CR-A vocabulary-wall question resolves without an Operator ruling. CONFIRMED, with the mechanism now read. The wall and the seed agree, and no Operator ruling is needed. What the verification added is that enforcement does not match the stated intent, in the harmless direction — see §4.
Full findings at inspection-briefs/loomworks-operator-layer-cr-a-step-0-findings-v0_1.md. Read-only throughout; no engine, database or perimeter call; tree clean at 99f7f64 before and after. No unread items.
Question one. The shared fetching layer is src/hooks/usePagedList.ts — both rooms go through it, neither fetches independently, and it is where the typed state contract lands as an addition rather than a replacement: it already holds every input the five-value state needs and merely never combines them. The rooms are better than anticipated — loading initialises true, so no empty state can render before a read completes. Two real gaps for the contract to close: canMove in MemoryRoom conflates a failed read with a true-empty read and silently hides an action; and RenderingRoom has no refresh path at all — refreshNonce is never threaded to it, so the two rooms are not symmetrical.
There are no Operator Layer route handlers. One wildcard rewrite (/api/:path* → the engine, prefix stripped) proxies everything. No Manifestation route is reached, and memory-status is never called — so B-5 needs a caller, not plumbing.
Face 2 is confirmed verbatim and totally. All four unwired-room strings assert the data, not the surface: "Nothing organized into a picture yet." / "Committed memory is the raw material here." / "No shapes waiting on you yet." / "Shapes appear here once there's settled memory to shape." The sharpest evidence is internal — the read-backed renderingEmpty: "No finished outputs yet." makes the same kind of claim in the same form, honestly. The surface has taught the Operator that this sentence form means the engine was asked and said none, then used it where the engine was never asked. The honest-about-the-surface intent survives only in the comments, which is why this reads as careless string-writing until you look.
Question two. The wall is tests/components/vocabulary-wall.test.ts — a Vitest static scan, case-sensitive line.includes. Consequence: the capitalised labels pass everywhere (live at five sites outside room-labels.ts today), and the ROOM_LABEL_TERMS exception actually protects the two lowercase room keys, not the labels the comment describes. Practical output for B-5: it may carry Manifestation freely — component name, filename, imports, strings — and must only avoid the lowercase token in testids, class names, route segments, lowercase identifiers and lowercase prose in comments.
The finding that matters most is for change request D. The wall forbids engagement_title — the seed's own noun in wire form. The sanctioned escape is projection into "Operator vocabulary" inside a boundary adapter, and the noun this codebase chose was project: lib/api/dashboard.ts:79 and :143 read project_title: row.engagement_title. The displacement W-37 recorded is manufactured by the wall, not accumulated by carelessness. D cannot fix it by renaming call sites; the forbidden list is part of D's surface. Sizing: 457 occurrences across 50 files, of which 162 are internal projectId, 77 are wire-shaped fields, and roughly 25 are user-visible — separable, mostly centralised in lib/strings.ts, with zero route params affected (the only dynamic segment is already [engagement_address]).
Unchanged, and now load-bearing. B-29 before FORAY integration opens; before B-25; before the completion arc's engine rider. Because B-29 is halted, all three stay parked behind it. The engine remains held by CR-2026-159.
Nothing. All repositories pushed and origin-synced. No session in flight. One local unmerged engine branch, recorded in §1.
a794754; Steps 0-2 need no revisiting.
| # | Question | Default | Blocks | Proceeds regardless |
|---|---|---|---|---|
| Q-1 | B-16 — seed v0.13. Drafting authorized 2026-07-30. Committing a seed version is an Operator act (charter F-3). The draft awaits your reading. | Commit as drafted once read. | Seed v0.13 only. | Everything. |
| Q-2 | CR-2026-159 D-1, reopened. Option B leaves ~35 call sites returning an object whose provenance disagrees with the row written, and one existing test detects it. Which shape does the bump take — accept and edit the test, have append_event hand the corrected object back, or move to option A? | None. The branch stays unmerged and B-29 stays open. | B-29's close, and behind it B-25, FORAY integration and the engine rider. | Everything outside the engine, including change request A. |
| Q-3 | The engine test baseline is no longer zero. test_stele_router_mount fails at a317051 with a 401, not caused by this CR. Own item, or a rider on the next engine CR? | Stays red and stays recorded. | The zero-failure gate on every subsequent engine CR, which cannot be asserted while it stands. | Everything. |
Batched Operator acts pending: none. No deployment due (F-1) — CR-2026-159 did not reach Checkpoint B, so no restart is owed. No passkey ceremony outstanding (F-2). No external communication queued (F-5).
A-2 — divergence from a CR's evidence base (CR-2026-159). Fired, reported, queued as Q-2. Handled per C-3: the test was not edited, nothing was merged, and the correction is referred to a drafting session rather than absorbed in flight.
One process note from this session, reported rather than smoothed. The Step 0 commit was first made on main before the session moved it to a branch. main was reset to a317051 and the commit re-homed; nothing was pushed at any point, so no other session could observe it. The git reset --hard in that move discarded the pre-existing unstaged M uv.lock churn, which the next uv run regenerated — the tree now matches the baseline description and nothing was lost. Recorded because it was careless, not because it cost anything. The lesson is small and general: branch before the first commit, not after it.
Carried from v0.4: A-6 name resolution (resolved), and the v0.2 pre-flight halt (correctly judged).
The test in force stands: no number, identifier or characterisation in prose unless it is itself the finding.
This window supplies a fifth instance and, for the first time, one that ran the other way. The fifth is "37 files" (§2.3) — a count beside an already-listed set, wrong by one, changing nothing. The other way: "83 sites" verified exactly, and it is a finding, and it stayed. So did "six positions, five numerals," which did what it was written to do — the shared :142 was checked as two positions and both confirmed.
What this window adds to the diagnosis. Every prior instance was ornament caught before it reached the work. §2.1's finding is the opposite shape and is worth naming as a distinct class: an analytical claim, load-bearing, stated as settled fact and wrong. The CR's "the surface is write-side only, so no downstream consumer can break" was reasoning, not decoration, and the sweep behind it — zero value assertions on the field — was correct. It missed because it asked whether anything asserts the field when the exposure was anything asserting the object. No discipline about prose specifics would have caught it. What caught it was building the thing and running the suite. Recorded as a candidate for the manifest's methodology set: a sweep proves only the question it asked; state the question, not the conclusion.
R-2 executed for the first time, and its checkpoint did its job. The auto-proceed steps ran unattended with per-step commits; Checkpoint A halted on a condition the CR had pre-named, without an interruption and without a decision the session was not authorized to make. The v0.4 amendment that removed the Operator gate at Checkpoint A was correct — nothing at that checkpoint needed him, and the halt that did occur was substantive rather than ceremonial.
R-5 inspection ran read-only throughout, verified by a clean tree at 99f7f64 before and after.
C-3 held under pressure. The tempting edit was one line in one test. It was not made.
R-1 filing proceeded and pushed on clean pre-flight, three times, origin-verified each time. Gate-review files mirrored to ~/Downloads.
§1's two-role discipline held: this session executed only documents it did not draft, and it caught a load-bearing error in one of them.
The standing note on executable-document versions was exercised and worked. Both documents were confirmed highest-version before execution — CR-2026-159 v0.4 against v0.1-v0.3, and the Operator Layer brief v0.3 against v0.1. Both kickoffs named the version they meant, so no mismatch arose and no halt was needed. The note's mechanism cost one directory listing each and would have caught a stale sibling.
DUNIN7 — Done In Seven LLC — Miami, Florida DUNIN7 — status brief — v0.5 — 2026-07-31 Three queue entries. The seam works and cannot merge yet. The rooms model their states honestly; the strings do not.