UCCA Time Machine — 2026-07-31 UTC (H)¶
1. What shipped, and why it is the sentence that matters¶
The forward path now has an anchor guarantee at both layers. The gate demands a non-empty array of non-empty string outcome_numbers where it previously demanded truthiness; the assembler refuses to seal an artefact whose trace map does not cover every input requirement.
TRACE_COVERAGE_MODE = "full". Until today, NORTHSTAR's "generation traces coverage by construction" was a claim the engine did not keep — coverage was a property of well-formed input, not an enforced invariant. There is now a construct.
Baton G closed a window with zero code changes, three corrections deep, and a standing lesson that the discipline which catches a false sentence had started eating the work. This window is that lesson answered.
2. The deploy — record¶
| PRE | POST | |
|---|---|---|
ucca-gate |
9ef77a2f-0675-4e53-a1c2-09ab923cf171 |
a40d2c8c-41c5-46bb-a905-9807a3444861 |
ucca-reasoner |
6183f394-e0c3-4f7f-9d53-c97dde71e70b |
26f1e87e-80df-4f45-8245-3ebe976a77d3 |
| container app | version 34, sha256:ffc439d7… |
version 35, sha256:ed8bc7e2610c… |
Account pinned e5a98302 throughout. Script versions are now established — the thing that could not be established this morning, when the deployments endpoint returned empty and "deployed matches committed" had to be quoted as predicate identity rather than version equality.
Reasoner first, gate second, deliberately. Gate-first narrows input while the seal is unguarded; reasoner-first leaves the seal guarded while input is still wide. The safe intermediate is the one that exists.
The rollout lag was real and Alex caught it. Immediately after the reasoner deploy the container still reported version 34 and the old image with active_rollout_id: 9d5cf8d7… in flight. Deploying the gate at that moment would have narrowed input against a container still running seam-2-less code — the exact half-deployed state, and invisible from any endpoint. He polled to landing first.
One commit beyond the tree in the verdict: 23145ff4, bumping the Dockerfile's app-copy cache-bust marker — one comment string, no seam logic. The Dockerfile's own standing instruction requires it, and it exists because Docker Desktop served stale COPY layers on this image twice before. A stale reasoner would have produced the same half-deployed state by a different route.
3. Three confirmation legs, none of them /_build¶
- Alex, from the deployed gate bundle — 18 of 18 predicates present, with a negative control proving the old one-line
structureOKis gone. - Alex, from the deployed image by digest —
assembler.pyinsidesha256:ed8bc7e2610c…hashing identical to the tree; executed in that image:fullset, the real unsound shape raising, an uncovered ref raising and naming['2'],_trace_closes([])still returningTrue. - This seat, independently, read-only — the deployed
ucca-gatebundle read directly and every predicate confirmed. First time this seat has verified a deploy from the deployed artefact rather than from a report.
4. Two stop conditions fired. Both were right. One closed a standing question¶
Stop 1 — outcome_number is both types in production. 37 string occurrences across 34 generation payloads, 15 integer across 5; later extended by Alex to 9 payloads carrying integers, once the 4 edit payloads were counted. The brief's §5 predicate would have rejected real sealed payloads. The stop fired on its first use and saved a regression.
Stop 2 — four of the five wore rtopacks. Cleared on Tim's direct testimony that he submitted the burst himself, nine minutes after minting the credential. So no client has ever sent an integer; all of it is this house's own test traffic wearing the credential it was submitted with. This also closes the provenance question carried since the addendum: the 2026-07-20→22 burst was Tim. Attested, not artefact-proven, and the record says so.
The stop condition itself carried the defect it was written to catch. It keyed on client_id, and client_id records which credential submitted, never who authored. Its honest form was a question to a human, not a predicate on a field.
5. The replay falsified the floor, which is not what it was for¶
Commissioned to decide full. What it actually did was catch Alex's own Seam 2 defect. His first payload_carries_content asked only whether modules was non-empty — and both known-unsound envelopes carry modules: [] beside a 402-character description and four learning_outcomes. The floor would have returned False and never fired on the one class it exists to kill.
Every unit test passed it, because the fixtures encoded the same assumption the function did. Only the real bytes had the disagreeing shape. Fixed to deny-by-default on a five-field metadata list, so a field a later schema adds counts as content the day it appears.
Result: 43/43 fetched, zero holes; 26 forward in scope; 2 failures, both FLOOR, both the known-unsound pair; zero coverage failures. §4.3 applied mechanically and full shipped by the rule as written before the data was seen.
Also measured and recorded so a later tidier does not delete it: Ruling 5's String() normalisation changed 0 of 26 verdicts. The generator emits requirement_ref in the same type as the input — by construction, not by contract. Keep the asymmetry.
6. test_scope_surface — a fixture, not traffic¶
The container run found one failure and Alex introduced it: a fixture declaring two outcomes and tracing one, sealing every time, and nobody noticed because nothing checked. Ruled a fixture rather than §4.3 evidence — the instrument for measuring legitimate was the replay, over real traffic, and it said zero. A fixture is not a path.
It cuts for the seam: the shape was produced by a careful engineer writing a test about something else entirely. That is evidence it is easy to make by accident.
Fixed both halves — coverage and the integer types, because coverage alone would have left a green test corresponding to no submission the gate now accepts.
7. Terraform — half proven, and the half that is not is an open item¶
No Worker script, container or queue-consumer resource is declared in Terraform at all. main.tf:4 says so outright: "Worker script deployment is managed separately via wrangler." 11 resource types, none of them this deploy's surface. So the expected diff is zero, provable from config alone.
terraform plan did not run. The R2 state backend needs AWS_ACCESS_KEY_ID / AWS_SECRET_ACCESS_KEY and they are in no vault file under any name. Alex did not generate or guess them — correct. So "nothing else has drifted" is unproven, not proven-zero. Snapshot deliberately not republished: it derives from state, no apply ran, and state is L3 RESTRICTED.
This is the one place the keep-current rule is satisfied in spirit and not in full, and it is stated that way on purpose.
8. The defect ledger — eight this window, five of them this seat's, all one shape¶
A property established of one thing, asserted of another.
- The §4 stop keyed on
client_idand asserted authorship from it. (this seat) - The
/_builddeploy check. Specified a verification step without testing the instrument could measure the thing — the gate returns a hardcoded literal and lackscommitandbuilt_atentirely. Withdrawn while giving the deploy word. (this seat) - Condition 1 built around the wrong two suites. Reasoned from
anchor_hardeningandcalibrationimportingassembler; both passed. The regression was inscope_surface, and what caught it was the container run checking exit codes. The condition was right for a reason I did not hold. (this seat) - The census cited as 5 when it was 9. Repeated a generation-only figure in a filed verification block. (this seat)
- The export verified by dual transcription — correct method, disproportionate cost, on documents whose function never required byte-fidelity. Tim called it: ~480k tokens moving thirteen narrative files. (this seat)
payload_carries_contenttesting onlymodules. Caught by the replay, not by tests. (Alex)- A suite reported as passing on its last line rather than its exit code. (Alex)
git stashon a clean tree is a silent no-op, so the pairedpoppopped someone else's stash. Push and pop look symmetric; the stash is a shared stack. (Alex)
Two of these were caught by an executing agent looking at bytes instead of trusting a predicate. One was caught by Tim from outside the ledger. None was caught by the ledger.
The standing rule this window earns: a check that shares an input with the thing it checks is not a check. Alex's copy loop and its verification loop read the same variable; it could not have detected the failure by construction. That is the same reason the export was transcribed twice by agents that never saw each other's output.
9. Filed, and the export¶
13 recovered session batons + their manifest filed at 22b03834, digests re-derived from committed blobs, verified at three points. The manifest is the important half — it records that these are content-verified re-typings, not byte-originals, and that no byte-original is obtainable: project_read returns inline at every size, probed to 44 KB. Every copy out of Project Files is a re-typing by a language model.
RULED, and it holds: the remaining 15 do not get moved. Not by a cheaper method — at all. No capacity pressure exists (851,988 of 2,000,000, 42.6%, measured 2026-07-31T10:50Z) and the only thing moving them buys is tidiness we cannot spend.
Four byte-original batons (07-24-B, -C, -D, 07-26-D) sit at the project root needing committing, not recovering.
10. Owed / open — cold-start order¶
- File this baton and the two cards —
UCCA-CARD-REQUEST-REGISTER-ROW-OUTCOME-NUMBER-RULING-2026-07-31(881bd191dfccf706…) andUCCA-CARD-REQUEST-BUILD-ENDPOINT-LIES-2026-07-31(313eb950d14dfca3…). Both unfiled at close. UCCA-ENGINE-RUNNABLE-STATE-<date>— now unblocked and it is the path to RTOpacks. Must carry: the new gate rejection path reusingGATE_STRUCTURE;affected_elementnow populated;JOB_TRACE_COVERAGE_INCOMPLETE; thatfullshipped; the three dead codes, still dead in the deployed bundle this window; the 56-orphaned state fact; the 17-payload stored-shape drift; one real envelope verbatim.- THE THIRD CLOUDFLARE CONNECTOR — unruled and it touches the catastrophic rule. Alex called
Cloudflare Developer Platformand it 404'd onucca-gate, which is what being bound to another account looks like.claude-ucca-cfworked for this seat in the same window. Read-only, he stopped immediately, no harm — but a third connector nobody has ruled on needs identifying and disposing. Also still unconfirmed: whether the G-ruled removal ofmcp__ucca-e5a98302-api__*was ever executed. requirement_refis typed NOWHERE. The erratum declared one half of the pair it is compared against. Owed into the erratum orv1.1. Do not close it by making a fixture consistent.v1.1nullablecourse_code— ruled, not built. Hard gate on RTOpacks' beta./_buildon both surfaces — decide bump-on-deploy vs wireenv.COMMITvs return the Cloudflare version id. The gate also returns two of the four fieldsCLAUDE.md§4 mandates.terraform plancredentials (§7) — until then, drift is unproven rather than zero.- Owed across the fence, four items, no crossing in flight: the three dead codes (their §5 was right and wider) · the digest convention sentence naming the object · the
outcome_numbertype and the withdrawal of contract-by-example as a method · the Project-Files lossy-export finding — they gave us a real warning and their own export runs the same way. - Unruled and Tim's: the name question (
outcome_id_local/outcome_number/internal_outcome_number) · the input triumvirate having no frozen schema at all · record-vs-revoke on the two unsound envelopes · the canon-register lifecycle state for the ruling. - The older carried set:
VL8/VL9VET-leak rows · the ADR-0005 annotation · level classification · verdict grammar · the two absent failure modes · the gradeability test · whetheraccuracy_ratesplits · Dependabot onucca-surfaces(470 alerts, unexamined since 2026-07-30) · the dormancy time machine at~/Downloads/app/. - WINDOW 2 — in-house beta loop. WINDOW 3 — the RTOpacks beta.
11. The standing lesson, and it replaces G's¶
G's was: when a session's output is a correction of a correction, stop verifying and start building.
This window built — and every defect in §8 was still caught by verification. The two are not in tension. The resolution is narrower and it is the one to carry:
Verification earns its cost when it runs against the real substrate and not against a restatement of it. The replay caught what every unit test missed. The container run caught what a last line hid. The deployed-bundle read confirmed what
/_buildcould not. Every expensive check that paid off this window read bytes that existed independently of the thing being checked. Every one that did not — the dual transcription, the self-audits of baton G — read a copy of the claim.
RECEIPT-CHECK: echo this line's end before acting.