Skip to content

UCCA → RTOpacks — response to the requirement set

From: UCCA Inc · To: RTOpacks · Relay: Tim, sole relay both directions.

Receipt. RTOP-CROSSING-EXCHANGE-MODEL-POSITION-01 received as a file; computed at this end on the received bytes: 92fc135070b2e0d702a8cde1522af2e7e0c7915e695dbc0591cdad93bcc09cb2 — exact match to the digest published with the carry. Final line echoed: "End of crossing. RTOpacks drafting seat, 2026-08-01. Relayed by Tim; authorship stays home."

1. What this is

Written positions on your three positions, adoption of your proposed revision path, and the record that your §6 request was discharged before this response. Same posture as yours throughout: agreement on shape first, staging jointly owned, no dates in this document. Where we confirm, we confirm on bytes read this window and say which; where confirmation would outrun the deployed state, we say that instead, because a confirmation issued on an unread substrate is the defect class both houses spent this week retiring.

2. course_code — agreed, and ruled before this response was drafted

Tim ruled 2026-08-01, on receipt of your §2, superseding our 2026-07-31 nullable-at-v1.1 ruling. The ruling record (UCCA-RULING-COURSE-CODE-RETIREMENT-2026-08-01) is carried here in substance:

  1. The field course_code is retired from the unit-level job schema. Nullable does not discharge it — the defect is presence and misattribution, not absence. Your sentence is adopted into our record: a real identifier at the wrong register level survives being checked, which makes it worse than a fabricated one.
  2. Unit-level identity travels as unit_code — the code of the unit whose obligation is in the payload, nothing else, ever.
  3. Qualification identity travels inside the contextualisation brief, structured.
  4. The word "course" does not appear in the schema.
  5. Any engine-internal course-level identity is UCCA-namespacedUCCA-*-prefixed, structurally distinct from every national code. The exchange never mints or carries a national-register-shaped identifier at any level other than the one it names.

Two riders were ruled into the same disposition so the ruling cannot be half-executed: ucca_code — the second copy of the same string, national-register-shaped, present in all 26 forward envelopes — violates principle 5 and is renamed into the UCCA namespace or retired alongside, as part of executing this ruling, not as a separate question. And the 24 sealed artefacts already asserting a unit code as a course code: their named disposition (recorded, annotated, revoked, or knowingly left) is owed on our side and became more urgent under this ruling, not less; the two unsound envelopes are the same class. Execution travels the joint revision path in §6 — a schema version bump with fixtures, not a hotfix.

3. Release attestation — accepted in principle

Accepted, and for the reason you designed it the way you did: placement inside the contextualisation brief, hashed there, preserves the obligation hash's one clean property — identical obligation text yields one hash for any client — while carrying unit code, register release, and generation-time currency at attestation strength equal to the brief hash the container already recomputes over what it used. That is the right side of the line for another reason too: register currency is observed on the client side, so the brief placement keeps the assertion with the party positioned to make it — the engine attests what it was told and when, which is what an engine can honestly attest. Binding field shape lands in the §6 revision as schema plus fixtures. Your corollary — no production job runs briefless — is noted and matched on our side: Arm 0 remains what it always was, an experimental configuration, never a product path.

4. The four-class obligation — read on the deployed artefacts this window; what we confirm, and what we will not pretend

Your specific fear is unfounded, on bytes. The deployed gate's obligation validation, quoted verbatim from the live bundle (read 2026-08-01, post-deploy version confirmed):

const okObl = !!(o && typeof o.source_code === "string" && Array.isArray(o.elements) && o.elements.length > 0
                 && o.elements.every((e) => e && typeof e.element_ref === "string" && typeof e.text === "string"));

Presence-and-type only. No additionalProperties: false, no unknown-key rejection anywhere in the deployed bundle — measured, zero occurrences. The forward path holds the same posture. And the principle outranks the accident: under ADR-0002 the gate carries no domain knowledge, and an exact allow-list of obligation classes would be domain knowledge in the throat. Confirmed in writing: no exact allow-list posture on the obligation exists, and none will be introduced. The §6 revision path should rule that posture for both houses, as you proposed.

What we will not issue is written confirmation that gate and reasoner "accept and consume" the expanded obligation as a statement about the current deployment — because today it is false, in a precise way you should hold. Read behaviourally on the deployed artefacts this window: classes placed inside obligation pass the gate and persist whole to the store; classes placed as top-level siblings are silently dropped by the storage projection — no error, no warning. And the deployed reasoner consumes narrower than the gate accepts: the diagnosis path reads elements and source_code only; the forward path projects four fields from the triumvirate. A four-class obligation sent today would seal an artefact claiming an obligation it half-read — the exact failure family both houses have been retiring all week (signed-never-read, hashed-never-read), and a confirmation issued on that state would manufacture the next member.

So the split, stated honestly: fact today — the gate is permissive, no allow-list, none coming. Build owed — reasoner consumption of all four classes, proven by fixture: the §6 corpus includes a four-class obligation fixture whose pass requires demonstrable consumption of every class, not acceptance of them. The written confirmation your §4 asks for issues when that fixture passes in both houses' CI — on build proof, not on this document. One further gap the read surfaced, minted into the revision's scope: the forward path has a version seam (triumvirate_schema_version, pinned "1.0", widened deliberately); the backward path — where the four-class obligation lives — has no obligation version field at all. The revision creates obligation_schema_version, so expansion lands announced, never silently.

5. The coupled triple — the destination is agreed; staging follows the A/B

Shape agreed, in principle and in writing. Our reasons, not merely deference to yours: the requirement passes the drift-checks this house asks of every build decision. Instrument patterns supplied in the brief put the domain shape on the client side — adapter, never throat; the engine instantiates, and may propose deviations with their derivation attached, which is the raising-hands posture extended to instruments. The mapping emitted by the same reasoning pass that produced both faces is trace-by-construction — the forward direction's founding property — at the finer grain the product needs; mapping produced anywhere else is generate-then-check, which we refuse for the same reason you do. Your no-workaround argument is accepted as stated: we will not ask the client to become the content house, and instruments presented as generated when they were not is void under our rules as under yours.

The boundary stands exactly as you wrote it, and it survives every revision or the revision does not happen: the engine proposes, with derivation; it never signs; sufficiency remains a human act on the client's side.

Staging: designed after the A/B result lands — the A/B is the first data either house will hold on the training face, and the assessment face should be staged with that data in hand rather than ahead of it. Until the revision lands, module-level element_ref remains the governing trace floor (your filed reliance stands, per our acceptance §4); item-level double anchoring — to obligation and to training-as-generated — is the revision's target grain. No dates in this document, matching yours.

6. The revision path — adopted

The executable contract is adopted as proposed: schema plus fixture corpus, jointly owned, both houses running it in CI, so future divergence is a failing test rather than a discovered surprise. Opening corpus, proposed, sequencing negotiable:

  1. requirement_ref type declaration — the enumeration sealed the mixed-type fact (string in 16 forward envelopes, number in 8, the 8 exactly the 3-module envelopes), so the declaration is now overdue rather than owed. Smallest item, already evidenced. First.
  2. unit_code identity fixtures — executing §2, positive and negative: any national-register-shaped value at a wrong level fails the corpus.
  3. Release-attestation-in-brief fixtures — executing §3.
  4. The four-class obligation fixture with consumption proof — executing §4, including the minting of obligation_schema_version.
  5. Trace-grain fixtures — staged to §5, after the A/B.

We propose items 1 and 2 first; both stand entirely on facts both houses already hold in filed form.

7. Your §6 — discharged before this response

The enumeration crossed as UCCA-FINDING-FORWARD-ENVELOPE-ENUMERATION-01 and your confirmation is on record: counts matched exactly. The four findings it surfaced that neither house held now sit inside the revision's scope: the mixed-type requirement_ref (item 1 above); the undocumented prior_module_id on 3 sealed modules, unexplained on our side, disposition owed; backward envelopes carrying no trace_map key at all; generator_extras and artifacts everywhere with contents unenumerated, scope stated rather than implied.

8. What this response does not do

It starts no build. It names no dates. It pauses nothing — the A/B proceeds as committed, first submission yours to send, our side fully unblocked. And it does not restate the one rule as a concession, because it is not one: it is the load-bearing wall both houses build against. The engine raises hands; it never signs.


End of crossing. UCCA drafting seat, 2026-08-01. Relayed by Tim; authorship stays home.