Ruling brief — five standing rules¶
Engine-side. Home. No fence crossing. Nothing built, run, deployed, written or deleted.
1. Fence state is QUOTED, never composed — offered for ratification¶
Any document asserting fence state quotes canon/sent/index.md's dated register line verbatim, rather
than composing its own sentence from what the author believes the state to be.
This is already practice and it is already load-bearing. It exists because the alternative failed twice inside one document line: rev 1 of the runnable-state document told RTOpacks that an artefact was filed-and-uncarried when the register recorded it Carried; rev 2 replaced that with a count of one when the register — committed in the same commit — said two. Both were composed sentences. Neither would have survived a quote.
Ratifying, not deciding. The rule is being followed. What is missing is a filed statement of it, so the next seat inherits it as law rather than as a habit it might not notice.
2. Replace-in-place — THIS ONE NEEDS TIM¶
Replace-in-place has now run SIX times — UCCA-CROSSING-TIER1-QUESTIONS-ANSWER-01 rev 1, and the
runnable-state document's revs 1 through 5 — and has never been ruled. Every application justified
itself by citing the previous one. That is precedent, not law, and the safety of the whole convention
rests on a single predicate: the document never crossed.
The exposure, stated plainly. If replace-in-place is ever applied to a document that did cross, two
houses hold different bytes under one doc_id and the digest-identity rule is broken silently — because
the failure produces no error, only a disagreement discovered later, if ever.
What is proposed, for Tim to accept, amend or reject:
Replace-in-place is permitted only when never crossed is verified from
canon/sent/index.mdat the moment of the replacement — not assumed, not remembered, and not inherited from the previous application. The verification is recorded in the replacing revision's ownstatus:field. A document that has crossed is superseded by a newdoc_id, never replaced.
Not ruled here. It has fence consequence and it is Tim's.
3. Flag loudly, or not at all — offered for ratification¶
UCCA Alex's rule, and it is the missing half of "flag, don't fix". In his words: a quietly-noted imprecision in a report you are already skimming is not materially different from a silent fix.
The operational form: a flag goes somewhere it cannot be skimmed past — the register row, the commit message, or a filed document — and not only into the body of a report. The rev 5 miscount survived to be corrected because it went into the register row as well as the report. Both R2 traps spent a full pass living only in prose and were recorded in no document; they are in the README now only because they were caught a second time. A flag that lives only in a message dies with the message.
4. Multi-edit cards state their ORDER, or prove their edits disjoint — NEW, from this seat's defect¶
UCCA-CARD-KEY-FIX-AND-FINDING-FILE-2026-08-01 carried three edits and specified no application order.
Edit A's replacement text introduces the phrase Edit C anchors on. UCCA Alex applied C first,
deliberately, and said why: applying A first risked re-pointing C at text A had just introduced.
Stated at its true size, because overclaiming it would be the same defect again. The exact OLD
strings would probably not have collided — A's insertion wraps the phrase across a newline and C's
anchor is a single line with a trailing period — and Alex asserted all three counts before any edit,
which is what the card told him to do. The failure was not certain. It was left to the executing seat to
notice, and it should never have been.
Proposed:
A card carrying more than one anchored edit to the same file either states the application order explicitly and says why, or asserts that no edit's replacement text contains any other edit's anchor. One of those two sentences is mandatory. Where order matters, apply later-in-file edits first, so that no insertion can shift or duplicate an anchor not yet applied.
5. Instructions to FILE carry an idempotency clause — NEW, from this seat's defect¶
The same card's §3 instructed a filing that was already complete. Both instruments were handed over together; Tim relayed the finding first; Alex filed it; the card then arrived asking for it again. Alex detected it, verified the existing object hashed to the expected digest, and did not double-file. The card gave him nothing to work with — it simply assumed a world in which the filing had not happened.
Nothing was drafted falsely. The card was accurate when written and stale by the time it executed, because relay order is Tim's and the drafting seat does not know it in advance.
Proposed:
Any instruction to file an artefact states: "If this is already present at the expected digest, verify and skip; report which branch you took." A filing instruction that assumes it is the first one is a filing instruction that will eventually double-file or trip a collision check.
6. Why 4 and 5 are the SAME defect this house has been logging all week — on a new axis¶
The previous baton logged ten instances of one shape: a property true of one instance, one file, one docstring — asserted of the set. Its counter-discipline: name what the evidence covers at the moment of asserting it.
Rules 4 and 5 are that defect rotated ninety degrees. Nothing here was true of a part and claimed of a whole. Both were true at DRAFT time and asserted of EXECUTION time — the anchor was unique when I read it, and I asserted uniqueness of an editing process; the filing was outstanding when I wrote it, and I asserted outstandingness of a moment I did not control.
The counter-discipline widens accordingly, and this is the sentence worth carrying forward:
Name what the evidence covers — in extent AND in time. A card is read at a moment the drafting seat does not choose. Anything it asserts about the world must either be re-checkable by the executing seat at execution time, or be stated as a condition rather than a fact.
And the observation this seat owes, again. Both defects were caught by UCCA Alex, neither by me, and that is now consistent across two windows. A house whose drafting layer is less precise than its executing layer should not treat verification as a courtesy the executing layer performs. It is the reason the drafting layer's output is trustworthy at all — and the drafting layer's job is to stop manufacturing work for it.
7. Delivery slip¶
| Who it goes to | Tim. Then UCCA Alex on Tim's relay, only if Tim rules. |
| What Tim does | Ratifies rules 1 and 3 (already practice), rules on rule 2 (the one that is genuinely open), and accepts, amends or rejects rules 4 and 5. |
| What Alex does | Nothing until Tim rules. On ratification: files this verbatim to ground/ and mints one canon-register row in the ruling class only for rule 2, which is the only rule here that decides rather than records. |
| What nobody does | Treats any rule here as in force before Tim rules. Applies rule 2's proposed text to a document retroactively — the six prior applications stand as made and are not reopened. Delays either carry. |
| Blocking? | No. Nothing blocks either carry; the register still records two artefacts filed and awaiting carry. |
RECEIPT-CHECK: echo this line's end before acting.