Section 3 said main was at ee3fedf with 547 passing. Section 12 transcribed a commit log ending at a8081e1, ten commits behind. Neither is corrected; both are removed. git rev-parse, git describe and git log report them, and the header already explained why the hash line could never be right - it is not known until the commit is made, so the value was always the previous commit. The same reasoning applies to the rest and nobody had applied it.
Section 4 item 2 listed STL export as forthcoming work. It landed at 0545b79 and the bounded route at cdde394. The length_view gap that would have made every export a silent 100 mm preview was fixed before the route shipped. The roadmap entry still said the composer does not export anything.
Section 3 module table was missing stl.py entirely. The baseline run is now dated 2026-08-18 and marked overdue against DIV-006, since it predates both the DNAT rule and the placeholder service replacement, which PROCESS section 9a names as requiring a run.
Section 7 recorded the F-034 per-profile breakdown as Three-Fin 9, Y 7, A Frame 5, Rectangle 5, T 1, Four-Fin 1 - which sums to 28 against its own stated total of 30. The measured distribution had been recorded correctly in ACCEPTANCE section 7 and in F-034 resolution for three weeks, while the wrong numbers stayed in the document a successor reads first.
Section 0 reading order gains DIVERGENCES.md and ENVIRONMENT.md. ENVIRONMENT.md was missing from it for three weeks while PROCESS section 8 carried ENVIRONMENT and omitted HANDOFF instead. Two lists, neither complete, each looking authoritative. Both now carry both.
PROCESS correction: the amendment rule added at 15e90fd claimed a document replaced rather than amended loses content, citing HANDOFF.md. Checked today against both archived handoffs - it had lost nothing. The dihedral gap, the three artifact classes, the cross-project mail question and the toolchain probe recipe are all still present. The hazard is structural, a rewrite has no diff, but the loss I asserted did not happen. Corrected rather than left standing.
Applied by anchored patcher, all-or-nothing across both files. Suite 643 passed, oracle intact. Documentation only.
Known cosmetic defect: the baseline paragraph in section 3 now has two adjacent bold spans and a line over 80 columns, because the anchor stopped mid-paragraph. Renders correctly. To be rewrapped with the next patch that touches the file.
New section 3a records the whole path from an assistant producing something to it existing in Gitea. It has been explained conversationally to every new assistant for months and was written in no document, which is the reason it is now here. Section 0 claims this document describes how work gets done; the part it did not describe was how work actually arrives.
3a covers: nothing but the operator writes, because the assistant reads Gitea read-only and the operator is the only party with write access anywhere in the chain. Three command groups rather than one, because section 4 requires a suite result the assistant has actually seen before a commit exists. The shell-free idioms - make -C, git -C, runuser - because pct exec runs no shell. Commit messages parsed by the host shell before pct sees them, so repeated -m flags and no dollar sign, backtick or exclamation mark. Which failures are passes, because an operator who cannot tell success from failure cannot report usefully.
3a also records the amendment rule: do not ship a rewritten file to change a few passages of a large one. Ship an anchored script that validates every anchor matches exactly once and writes nothing if any does not. This commit was made that way. A rewrite regenerates the document from the assistant reading of it and a transcription error is silent - the same hazard as rewriting HANDOFF.md in place, one level down.
Section 4: the oracle check and git status are one check, not two (F-033). And the two interpreters are deliberate - verify-oracle runs python3 because make_fixtures.py imports nothing outside the standard library, test runs venv/bin/python because the suite imports mechcomp, Shapely and pytest. Neither is a mistake to be tidied into consistency.
Section 8: the reading order was missing HANDOFF.md for three weeks while HANDOFF section 0 carried a different order missing ENVIRONMENT.md. Two lists, neither complete, each looking authoritative. Both now name DIVERGENCES.md. The authority ladder gains the rule underneath it: a document that describes something yields to the thing it describes, a document that prescribes something does not. That dissolves the apparent contradiction with deploy/README.md, which is correct to claim the repository wins for the files it owns.
Section 8 also qualifies promote-the-deviation. It applies to facts about a host, not to a requirement the code has not met. A REQ is never lowered to match what was built; the gap is recorded in DIVERGENCES.md and the correction is owed by the code. A specification that agrees with whatever exists specifies nothing.
Section 10 described 18 AUG: repository at its seed commit, port not started, 3 passed and 236 skipped. It now states that it no longer records a commit, a version or a test count, because git rev-parse, git describe and make test report those and every attempt to hold them current in prose went stale.
Suite 643 passed, oracle intact at 113 accepted and 10 rejected. Documentation only.
Four documents brought into line with what landed at 54f0296 and ee3fedf.
HANDOFF section 4 item 5 said the ACL was deliberately last. It is deleted, not
deferred. Authorisation lives upstream at the last proxy hop, decided against a
membership system this repository knows nothing about, so the compiler will
never have a user table, a login form, a session, or a group name in any form --
including as a configuration value, which is how that leak arrives by the side
door. An item left the roadmap rather than moving down it.
Item 4 claimed persistence was the prerequisite for a library of saved designs
and for access control. The second half has been false since the identity
contract landed and was found by reading the anchor rather than recalling it.
Corrected, and item 4 now states the position that follows: the filesystem is
the first store, not a database. Design records are already plain text, already
content-addressed by input_id, and already readable by someone with none of this
software. A directory of them is a store with perfect provenance and no schema
to migrate. SQL earns its way in when there is a query walking files cannot
answer -- "every design by this author since March" is that query, and it
arrives with membership, not before.
"Acceptable for a development name" is withdrawn from HANDOFF section 4 and
WORK-ORDER-004 section 3. The name is production, dev abbreviates Mechanical
Compiler Developers, and it appears on printed material. The posture is
unchanged -- world-reachable, unauthenticated, /m/ not yet gated, STL export
will ship open -- but it is carried openly as open question 10 instead of
excused. The phrase survived three documents and two earlier corrections
because it was plausible and nobody challenged it, which is the same mechanism
that produced the stale ingress paragraph.
Section 0 gains the two new documents, with CONSUMER_INTERFACE_GATES.md marked
read-before-proposing-an-integration: several tempting cross-project moves are
recorded there specifically as things not to build yet, and a successor who
finds them independently will be tempted to solve them. Also a note that
deploy/ now holds the unit and the vhost as they actually run, and that the
repository is the single source of truth -- read a container when you suspect
drift, then fix the drift here rather than on the host.
HANDOFF section 1 and PROCESS section 9 gain the same rule: pct exec runs no
shell. A glob, redirect, pipe or && is expanded by the host shell against the
host's filesystem and the container receives whatever literal survives, so an
unwrapped glob reports "No such file or directory" and reads as a broken
container. Third instance of this class after F-035 and F-036 -- each time the
tool was invoked wrongly and the error named the wrong subject. Not filed as a
new failure: it is the same finding as those two, and a third entry would
record the instance rather than the pattern.
STAGING-STATE records the deployment configuration as committed. The unit had
been marked delivered at deploy/mechcomp.service on 11 SEP while existing only
on the host.
HANDOFF section 4 said WORK-ORDER-004 was pending and that CIVICVS could not
see any of this work. It was rewritten thirty-two minutes after 1fdb115 closed
the ingress, in the same session, against the work order's old state rather
than its new one -- so HEAD described a world where the thing you were already
looking at did not exist. Section 11 row 7 carried the same staleness. Both
corrected, and the correction says how it happened, because section 0 was added
to prevent exactly this and did not.
Three things 1fdb115 recorded as unsettled were never promoted into section 11
and are now rows 8 through 10: TLS renewal has never been observed to succeed
for this name and is first due before 2026-12-10; the composer has no
acceptance criteria of its own, only the path to it does; and the service is
world-reachable and unauthenticated, which section 4 item 5 called a conscious
decision to be made before publishing and which publishing has now made due.
Priority items 1 and 2 reversed. The original case for authorship first was
that records made before the field exists can never be attributed. That was too
strong, and too strong because the field is excluded from both hashes: a record
regenerated later keeps its input_id. What it does not keep is build_id, which
covers Shapely and GEOS, and boolean results on near-degenerate geometry shift
between GEOS releases -- the F-034 mechanism. Attribution is recoverable, not
free. The residual argument stands and the field landed first at 48d5665.
Recorded under item 2, because it is the first thing STL export runs into:
length_view is not in COMMON_GROUPS, so the Full Length branch is unreachable
from the composer and every export would silently be a 100 mm preview. The
sweep must equal model_length_mm(p), already published as LENGTH_MM, or the
record's VOLUME_MM3 and MASS_G describe a different object than the file beside
them. Also split the roadmap's STL/STEP bullet: STEP needs the kernel, STL does
not, and one line implying both was left behind by the section 5 correction.
F-037: a tar stream rooted at "." re-owned the repository root. tar x ran as
root and applied the "." entry's ownership to /var/www/mechcomp; the chown that
followed named only src and tests. Everything below the root was correct, so
547 tests passed and only git noticed. Corrected by chown on one path, owner
only, no -R. safe.directory was not added -- that is F-008 and would have
masked this and every later instance.
Two of F-037's three consequences are process defects of mine rather than facts
about the environment. The verification step ran before the landing that
destroyed it, so a git status ahead of the breaking step reads as a pass -- the
F-027 pattern in a new place. And section 7 says record a failure before
correcting it; I corrected first. Both recorded rather than quietly fixed.
PROCESS section 3 gains two REQs, because the delivery path as documented
produces F-037 every time: the chown must name the directory the files land in,
and a tar transport must name its top-level directories rather than root at
".". pct push is simpler for a single file and cannot reproduce it at all.
Section 8 gains the bytecode rule: PYTHONDONTWRITEBYTECODE=1 and clear
__pycache__ between mutations. A stale .pyc masked a real defect once and every
mutation result reported before that was optimistic by an unknown amount. A
mutation surviving on stale bytecode is indistinguishable from one surviving on
a weak test.
Open question 11 is new and is CIVICVS's: ct-baseline.sh exits 0 with the F-037
condition present, so by section 9a the ownership of a service working tree is
not part of the container standard. Whether it should be is a decision about
host property covering three projects.