Skip to content

Council v2: deterministic scoring, signed seat records, rules EX-1, P3 and P4 (draft, not used for any defense) - #12

Draft
aetherneum wants to merge 13 commits into
mainfrom
aetherneum/council-v2-draft-2026-10-02
Draft

aetherneum wants to merge 13 commits into
mainfrom
aetherneum/council-v2-draft-2026-10-02

Conversation

@aetherneum

@aetherneum aetherneum commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Council v2, built and tested offline (243 tests: 2 skipped on Windows, 3 on the Linux runner; sockets blocked, no API keys). Contents: deterministic scoring, identical review bundles, signed seat records, alumni.json; the executor rule EX-1 (Rector decision D19) and its crash clause EX-1.c (D23); product rules P3 (scorecard and status labels) and P4 (no admission without a proof pack), approved by the Rector on 2026-09-30. Not used for any defense yet: a live session needs provider keys, a production signing key and the Rector's written approval, and the CLI refuses without them. The README cites the recomputation of the 2026 reviews; no new verdict is published.

CI. Unit tests (offline, no API keys) must pass (its steering-block step uses the test fixture since acfa7f8). alumni.json vs public surfaces is red by design (see the comment in .github/workflows/council-v2.yml): it reads the main branches of the public repositories and fails while any surface differs from alumni/alumni.json. Run against the open pull-request branches instead (site, registry, the fourteen week-1 reviews, this branch) it reports 56 divergences: 0 policy, 0 registry, 23 stale records, 24 unresolved values and 9 placement names awaiting name review. Rebuilding alumni.json from those branches clears the stale records and leaves 32: 23 values without a canonical choice and the 9 names. Those are the Rector's decisions; alumni.json is rebuilt from main after the merges, not from unmerged branches.


After the history rewrite of 2 October 2026: the commit hashes above are those of the rewritten history (an e-mail address was replaced in author and committer fields; trees unchanged). Hashes cited in frozen records keep their old value; the map is in aetherneum-network/registry#2.

🤖 Generated with Claude Code

claude and others added 12 commits October 2, 2026 11:36
…ords, alumni.json

- council_v2/: scoring (weights, thresholds, vetoes, verdict and quorum computed
  in code, rules quoted from admission/RUBRIC.md, interpretations I-1..I-7),
  bundle (one bundle and one SHA-256 for every seat; lint_intake blocks
  steering sentences), evidence (read-only repo scan; zero artifacts caps body
  of work at 3), executor (non-voting seat running scenarios/*/ with timeout
  and containment), seats (Anthropic via the official SDK, claude-opus-5-5,
  adaptive thinking, output_config json_schema, no tool_choice; other
  providers [TO CONFIRM]; MockSeat), record (one signed JSON per seat, null
  records for failed seats, append-only), signing (Ed25519; pure-Python
  RFC 8032 fallback because cryptography is not installed), calibrate + two
  decoys, legacy import, registry from signed records only, consistency
  checker, orchestrator (--dry-run --mock by default; live mode refuses
  without key, approval reference and AETHERNEUM_COUNCIL_LIVE=1).
- alumni/alumni.json + schema: 14 records built from the published sources
  (sibling repos read at main), contradictions recorded, canonical null where
  surfaces disagree, placements left null, non-alumnus
  commit identities redacted.
- council/council.json: Dean non-voting (claude-fable-5-1), four voting
  seats, Anthropic seat claude-opus-5-5, others [TO CONFIRM], quorum rule.
- scripts/: build_alumni_json, build_registry, check_consistency.
- tests/: 114 unittest tests, offline (sockets blocked), no API keys.
- .github/workflows/council-v2.yml: tests + consistency check, no secrets.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- council_v2/recomputed_2026-09-30.md: the 53 existing Q2 and Phase 0 JSONs
  re-scored with the deterministic rubric (analysis, not a defense), plus the
  three seats that wrote no file as explicit nulls, the Registry claims vs the
  JSONs, identical score vectors, superseded reviews kept in git history, and
  a Registry table generated from signed legacy-import records.
- council_v2/README.md (English): design, how to run offline, records,
  signing keys, seats, executor, decoys, sources of truth, live-run gates.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The dirty-tree checks run git status in the faculty repo and, in working-tree
mode, in sibling clones that other people may be editing; --no-optional-locks
keeps them from taking the index lock.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…s being removed)

The flag that keeps a placement canonical value null while its description
still names a client platform is now name_review; the consistency report
calls it UNRESOLVED (name review).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
… follows --repo

Three minimal changes found necessary by the offline end-to-end rehearsal
(prova generale, 2026-09-30). Each has unit tests in tests/test_rehearsal_chain.py.

1. run_council_v2: --marker <text> (dry-run only). The text is stored as
   session.marker, inside the signed payload of every record of the session,
   including a LINT_BLOCKED record. Refused in a live run (exit 2 / RunRefused).
   Before: a mock record said mock/dry_run but carried no visible notice.

2. registry: rows built from mock / dry-run records (only with --include-mock)
   are labelled: provenance "MOCK / DRY-RUN session - not a Council verdict"
   plus the session marker, a banner line above the table (Markdown and HTML),
   and the CSS class registry-mock on the row. Before: such a row carried the
   provenance "Council v2 session, signed at run", identical to a real one.
   Default behaviour is unchanged: mock records stay excluded.

3. run_council_v2.default_inputs: the default profile (README.md fallback) is
   read from --repo when --repo is given, not from <repos-root>/<slug>.
   Before: `--slug X --repo <frozen clone>` without --profile either crashed
   (FileNotFoundError) or silently read the README of the live working tree
   <repos-root>/<slug> instead of the frozen clone.

Suite: Ran 125 tests, OK (skipped=2)  [114 before + 11 new].

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
"veto until every declared scenario passes; zero scenarios started counts
as zero artifacts"

- council/council.json: new ordered `rules` list with EX-1 (clauses EX-1.a
  veto, EX-1.b zero-started cap, exception EX-1.x executor not run). The
  open question on failing scenarios is kept and marked RESOLVED by EX-1.
- council_v2/rules.py (new): extracts the rule from the file and applies it
  to the executor summary; an unknown condition is an error, never ignored.
- scoring.py: evidence_caps and decide_council take the ruling (default
  None = behaviour before the rule). An executor veto is decided whatever
  the seats scored, before quorum, mock and live alike.
- record.py: the executor summary is signed into every seat record; the
  decision record carries rule id, approval, counts, clauses fired.
- registry.py: the ruling is recomputed from the signed seat records; the
  row shows the veto.
- run_council_v2.py: --live with --no-executor is refused; in a dry run
  --no-executor stays allowed and the records say "executor: not run".
- Legacy recomputation (2026 JSON, no executor result) is outside the rule:
  python -m council_v2.recompute gives byte-identical output.
- tests/test_executor_rule.py: 34 tests, one or more per clause. Two
  existing tests on the tiny_repo fixture (3 pass, 1 fail, 1 timeout,
  2 errors) now expect VETO by EX-1; the quorum test runs without executor.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
costanza-notari.md (lines 134, 136), ezio-cardone.md (128, 130) and
tomaso-riviera.md (129, 130): every fact is kept; only what told the
Council how to judge is removed (the criterion identifiers and the
"should find / should score / will score" wording). No new claims.
The three intakes now build a bundle without --allow-steering.

- tests/fixtures/steering/intake-with-steering.md keeps the six original
  sentences unchanged, so the lint rules are still tested on them.
- tests updated: the three rewritten intakes pass, the facts are still on
  the same lines, the intake not rewritten (adele-maurique.md) is still
  blocked; bundle / pipeline / marker tests use the fixture.

Not changed here: alumni/alumni.json (generated snapshot) still records
intake_contains_steering for these three, as the 2026 sessions read the
old text; the warn-level "conclusion-assertion" findings on
costanza-notari.md:134 and tomaso-riviera.md:129 (non-blocking).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…e EX-1.c

P3 - the diploma is a blind number that expires
- council/council.json: rule P3 (subject "diploma") with parameters P3.1
  validity_days 90, P3.2 max_days_between_blind_runs 30, P3.3
  never_event_threshold 1, each "approved": "Rector, 2026-09-30"; the five
  statuses as an ordered first-wins list; what is not a signed verdict.
- council_v2/scorecard.schema.json: JSON Schema of aetherneum-scorecard/0.1-draft.
- council_v2/scorecard.py: validator (required fields, run kinds, date order,
  headline run = last out-of-pool run, run_by not the builder, every run kept
  against the run digests of the previous signed version) and the pure function
  derive_status (the date is an argument; the module reads no clock).
- council_v2/record.py: the decision record signs certified_until, the
  scorecard digest (sha256 of the file) and the rule parameters it used.
- council_v2/registry.py, scripts/build_registry.py: with a date the row shows
  Status and Certified until; a record that says "executor: not run" shows it
  in plain words and never reads as certified; mock rows keep their marker.
  Without a date the output is what it was (legacy recomputation unchanged).

P4 - no new alumnus without a proof pack
- council/council.json: rule P4 (subject "admission"), clauses P4.a (pack
  exists, at least one scenario) and P4.b (pack passes the executor, EX-1),
  exception P4.x (mock / dry-run: record only).
- council_v2/run_council_v2.py: --live is refused without --repo pointing at a
  pack with at least one scenario (message names P4), and after the executor
  and before any seat when EX-1 vetoes (signed ADMISSION_REFUSED record).  A
  mock / dry-run session runs and its decision record says the rule would have
  refused.  --scorecard passes the scorecard the verdict relies on.  The CLI
  now reports every reason of a live refusal, not only the first.

EX-1.c (ruling on D19 dissent point 2, to be confirmed by the Rector)
- a crash of the scenario runner is "executor ran, found unknown": outcome
  VETO with a reason naming EX-1; never more lenient than a failing scenario.

Tests: tests/test_scorecard.py, tests/test_admission_and_records.py,
tests/test_executor_rule.py; fixture tests/fixtures/signed_before_p3 (records
signed at 41c5c35 with the rehearsal TEST key, public key only) for backward
compatibility.  Nothing about the alumni, the Charter or public prose is changed.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…hese two assertions on the old text

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The approved text of P3.3 says a run with at least one never-event puts the
status under-review until a new defence. The code only looked at the headline
run (and at runs after a signed verdict), so a later clean run washed out an
earlier never-event before any verdict: Costanza v2.1 (never-events 0/2/1/0 on
four runs) came out evidence-pending. New condition never_event_not_defended
under P3.b: with no signed verdict, any run at or above the threshold holds the
status under-review. 243 tests OK.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The Q2 intakes were rewritten so the intake lint passes (357505a), so the
step that expected exit code 3 from the real costanza-notari intake failed.
It now runs the same steering fixture the unit tests use.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@aetherneum
aetherneum force-pushed the aetherneum/council-v2-draft-2026-10-02 branch from 7d3b09d to e7716af Compare October 2, 2026 12:24
The history of the aetherneum-network repositories was rewritten on 2 October 2026 to replace an
e-mail address in the author and committer fields; trees did not change. alumni.json is a snapshot of
the commits read at generation time, so each recorded hash now names the rewritten twin of the same
commit (same tree): 32 values, faculty_commit included. Nothing else changes; the signed fixtures
keep the hashes they were signed with.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@aetherneum
aetherneum force-pushed the aetherneum/council-v2-draft-2026-10-02 branch from b472acd to 8c12622 Compare October 2, 2026 13:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants