diff --git a/docs/fleet-surface.md b/docs/fleet-surface.md index b231b8d2..38490f5c 100644 --- a/docs/fleet-surface.md +++ b/docs/fleet-surface.md @@ -58,6 +58,9 @@ The bound exists because declared values are module-controlled and reach operato terminals, so the daemon limits their size and character set at its boundary. `supervisor.provenance {}` reads the whole box; `supervisor.provenance { module_id }` reads one module. +A consumer's own documentation about which subc version it runs is not provenance; +the `supervisor.provenance` declaration is. See rows 557 and 558 of +`docs/hunting-loop-briefing.md` on present-tense claims about path dependencies. On Linux, running-image evidence is SHA-256 over open handles for `/proc//exe` and the captured spawn path. On macOS it is a spawn-inode comparison only, weaker diff --git a/docs/hunting-loop-briefing.md b/docs/hunting-loop-briefing.md index a2614b0a..c286c4da 100644 --- a/docs/hunting-loop-briefing.md +++ b/docs/hunting-loop-briefing.md @@ -657,6 +657,8 @@ Before calling a class closed: | 555a | A passing control on a result that discriminates between two hypotheses | The instrument control proves the probe can SEE and cannot catch a fixture incapable of the DIFFERENCE — it fires on its planted positive, passes, and licenses the false reading. Ask separately whether any input here could have produced the other answer | | 555b | A conclusion derived from a label you invented | A control proves an instrument can produce a signal, not that the signal has ONE cause — `UNREADABLE` meant both "file absent" and "my pattern assumed no space after the colon". Read the value, not your own label for it | | 556 | A zero you are about to report on someone else's behalf | A favour is framed as a lookup and lookups do not get controls, so the skip is never a decision. Plant one positive, confirm the detector fires — the trigger is not "am I testing something" but "am I about to report a number someone will act on" | +| 557 | A consumer records a present-tense fact about a path dependency's tree: a version, a capability, "not exported yet" | Row 278's companion: 278 covers what the build does when the tree moves, this covers what the prose does. A path dependency has no version requirement to disagree with, so the record has no falsifier and decays silently. A version-pinned crates.io dependency has one in its requirement; this row applies to path consumers and capability claims no version requirement catches. Date history or check present tense mechanically; only the author knows which was meant | +| 558 | Is the value you'd write down already a constant you could read? | Prefer reading `SUBC_PROTOCOL_CRATE_VERSION` (or calling `build_provenance`, which since #87 enforces canonical hex) over recording the value in prose. The helper constrains what a sentence cannot | Row 17 is the shape of every entry here worth trusting: **a rule recorded without its discriminator is half-guidance**, and the half that travels is whichever