DUNIN7 · LOOMWORKS · RECORD
record.dunin7.com
Status Current
Path session-handoffs/cr-2026-215-checkpoint-a-v0_1.md

CR-2026-215 — Checkpoint A — v0.1

Date. 2026-08-15 · CR. change-requests/cr-2026-215-loomworks-candidate-discard-policy-fence-v0_1. State. Built and tested. HALTED before tag and push. Engine main local commit a7ae23c (not pushed; no tag), built at 1adcd17 exactly, tree clean. Engine only, as drafted.

Step 1 — the census against code, and the halt condition that did not fire

The twenty verifications happened, and they CHANGED the declarations: the job writers (render, retrieval, shaping, summarization, drift, cadence, seed-cadence) carry NO state gates — reachability during candidacy is the caller's accident, so nothing is declared active_only on hope. The honest outcome: 25 of 27 FKs are delete (candidate-scoped residue of a thing being unmade — the endpoint's own rationale, and free when the table is empty), 1 is null (the focus pointer — stale, not gone; the account row survives), 1 is active_only with code evidence cited in the declaration (personal engagements are born 'active'personal_engagement.py:367). The Operator's halt condition did not fire: no FK fit none of the three honestly; none was forced. Each of the 27 carries its one-line reason, and a second fence jaw tests reason-quality (an empty reason fails — a policy chosen carelessly should not pass quietly).

The ruling improved on — the fourth time, and the pattern stated plainly (as ordered)

§0.2 said the declaration is where the thinking happens; the build made every active_only a claim verified against code and every reason a tested artifact. The pattern, stated: a ruling that says "think here" becomes a guarantee only when the thinking leaves evidence. Four instances now: the AST test, the source-scrape, the kinds fence, and the policy-with-cited-evidence + reason-quality jaw. (This CR holds two positions in the series: its fence is the fourth source-contract application, and its evidence-bearing declarations are the fourth ruling-improved-on.)

What is built

candidate_discard_policy.py — 27 declarations, each with its reason; discard_candidate_engagement executes the policy (the ADMIN-log seed cleanup kept as-is — extra work beyond FK satisfaction); the fence test reads information_schema and fails on any undeclared referencing FK (both directions — undeclared AND stale entries); three blocker fixtures the suites never had (turns / notification / focus — the focus fixture proving the pointer goes stale-not-away, the account row surviving); the active-untouched fence. Gates: suite 3739 green; ruff clean; the CI's own mypy-baseline script run locally and green (it caught one Literal-widening error pre-push — the CR-213 lesson operating as standing practice, at the desk this time instead of in CI); no-delete static check green (the policy module carries no SQL; candidate_discard.py stays the allow-listed executor).

Step 4 — E0129's discard, table by table (the census proving itself against a real object, as ordered)

Before: conversation_turns 2 · companion_notifications 1 · memberships 1 · memory_events (ADMIN seed) 1 · own-log events 0 · focus 0 · uploads 0 · api keys 0. The act: DELETE /engagements/{E0129}/candidate through the real route, the Operator-creator's session — 204, first attempt, all three blocker classes armed or present. After: every table zero; the row gone; the walk arc's control-test residue removed — the eye-test that proves the fix also deleted the last artefact of the arc that found it.

One residue the FK census structurally could not see, found by the after-census and REPORTED, not fixed: one orphaned finding survives on the ADMINISTRATIVE log — findings FK the ADMIN engagement, not the candidate, so they never block a discard; they linger, referencing a now-deleted seed (E0129's R-A9 finding, its suggestion still quoting the seed's text). The discard's ADMIN cleanup covers the SEED's events (object_id = candidate_seed_id), not the finding objects keyed to it by payload lineage. In-principle every discarded candidate that underwent induction leaves its findings orphaned on ADMIN. Blocks nothing; a data-hygiene candidate item for the gate — the same lineage filter _load_induction_state uses would collect them, but that is a scope decision, not a silent extension of this CR.

seed-mutability

Kind C as expected; the seed path untouched (its events were already in the delete class). Null finding recorded.

What Step 5 awaits

Tag; push a7ae23c; watch (verdict read directly); redeploy the engine. Then the permanent-object pair is fully closed: unblockable since CR-212, discardable now.


DUNIN7 — Done In Seven LLC — Miami, Florida — CR-2026-215 Checkpoint A — v0.1 — 2026-08-15 Twenty-seven decisions, each with its reason in evidence; three blockers dead on one 204; and the arc's last artefact gone by the very fix it led to.