llm-ingestion-okf spør fordi authorship er vår: DEFAULT-profilen staterer
ingest-spec §5. Fire opsjoner (O0 status quo / O1 produsent-aktør / O2
produsent-nøytral aktør / O3 omdøping) med kostnad målt i kontraktslinjer.
Oppstrømspremisset er verifisert mot okf/SPEC.md selv, ikke overtatt: `by` er
REQUIRED, aktørkonvensjonen har tre former, og toleransen dekker ukjente — ikke
feiltypede — nøkler. Forbehold: spec-en er lest på en gren, ikke en tag.
Aksefunnet: `generated` bærer TO laster hos oss — ærlighetsmarkør (§1, §7) og
eierskapspredikat (§3, §11). Oppstrøms er feltet ren attribusjon.
Funnet som omformer opsjonssettet: O1 med `by: "<produsent>/<versjon>"` legger
en produsents navn inn i det byte-sammenlignede prefikset, og kolliderer da med
§1s krav om at enhver konform implementasjon reproduserer DELT fasit byte for
byte (:29 + :267 + :280). I dag normativ, ikke observerbar — ingen
examples/ingest-golden-* finnes. Ingen spec-tekst røres.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XYkLsRfSBBUjULS219Fy8X
The question turned out not to be binary. Three distinct reference shapes are
already in use across the specs, with different binding force:
A artifact-name-as-ground-truth method-spec §7 :332-333
B directory convention + entries ingest-spec §11 :259-267
C informative catalogue link README :19
nav-golden has none of them. Verified: 0 hits in all five normative files
(method-spec, ingest-spec, CONCEPT, README, SKILL).
Two findings that constrain the option space:
- method-spec never names a repo path at all (`grep -c 'examples/'` -> 0; the
ten `/`-bearing tokens are in-bundle link syntax). A shape-B reference would
be the first one in that document.
- Elevating to §7 ground truth (O3) means rewriting two counting claims, not
adding a sentence: §7 "two JSON files ... the only ground truth" and the §1
conformance clause 2 "on the shared example bundle" (singular).
Also surfaced: nav-golden's serialization is not byte-pinned
(nav-golden-hierarchy/README.md:31-33 says MAY) while the sister class
ingest-golden is (:267, :280). Two conforming gates can disagree on the same
fixture today, independent of whether the spec names the class.
No normative text changed; no new text proposed. Ratification is the operator's.
Amendment-underlag §8: corrected the verification-log check, which cited
`grep -rn 'nav-golden' *.md` -> 0 hits. That command now returns 3 (all in the
gitignored, non-normative STATE.md). The claim holds; the check was too wide.
Re-aimed at the five normative files, and cross-linked to the new document.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XYkLsRfSBBUjULS219Fy8X
Leverer det generelle underlaget portfolio-optimiser klarerte som trygt arbeid
(2026-07-25 05:09Z pkt. 3): per køpunkt hvilke spec-seksjoner det rører og hva
frossen tekst sier i dag (fil + linje, verbatim). Ingen foreslått ny tekst —
pakken eies oppstrøms og ratifiseres av operatøren.
Tre funn utover ren kartlegging, alle verifisert mot HEAD før de ble skrevet:
- D-A#3 (ledende "/") trenger ingen amendment: method-spec.md:67-71 sier det
allerede (landet 9801d35), og §11-raden :425 har rød-betingelsen. Det er et
konformitetsgap i implementasjonen, ikke et spec-hull.
- Oppstrøms-anker shared/ingest-spec.md:140 peker på 7aa53fc, ikke HEAD; samme
setning ligger på :158/:160-161 etter bfa5a9b, som skrev om nettopp det
kulepunktet + §4 title-raden. Konsumentens shared/-kopi ligger ett commit bak.
- De to oppstrøms-enumerasjonene er ikke samme mengde: fem stories vs. fem
D-A-punkter, bare tre par binder. D-A#5 (hovedbok) har ingen story-etikett og
faller utenfor pakken hvis den ratifiseres som beskrevet.
Målt mot fasit-bundelen: nominal gate (claimed 30000 <= nominal 90000.0) og
IR-invarianten (unit_cost 1.0 i [0.70, 1.40]) er byte-nøytrale; kostbaseline er
det eneste punktet som endrer fixturen hvis kravet blir ubetinget (§7:332-333
sier "two JSON files ... the only ground truth").
B1 ankret: = D4 fra OKF-runden, commons-halvdelen levert b641741, og det åpne
spørsmålet er vårt eget — klassen har 0 normative referanser i dag.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XYkLsRfSBBUjULS219Fy8X
The A/B/C axis split was issued to two repos on 2026-07-25 and taken up as
binding by one of them before any durable record existed: it lived only in
this repo's gitignored STATE.md. Other code has changed because of it, so it
needed to travel.
Interpretation only. Changes no normative text, introduces no requirement,
and says so at the top — where it and the spec disagree, the spec wins. Each
axis is already stated normatively in one of the two specs; what was missing
was a single place saying there are three and how to tell them apart.
Scrubbed of coordination narrative: no repo is named and the worked examples
are anonymised. commons is published openly and subtree-consumed, so another
repo's defect does not belong in the text.
All line anchors grep-verified (§7 V1-V4). One anchor I had cited externally
was wrong — 'never by directory enumeration' is method-spec.md:82-83, not
:70-73 — corrected here and reported to the consumer that received it.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XYkLsRfSBBUjULS219Fy8X
The plan header named 'v0.2 alpha' as reportage of the ecosystem, not as a
choice. llm-ingestion-guard has since cut v0.3.0, and consumers now disagree
on pinning: the guard recommends v0.3.0, llm-ingestion-okf deliberately holds
>=0.2,<0.3 because the new active:* findings could quarantine ordinary
documents under its Door B preset.
Commons has no wiring, no tests and no dependency declaration, so it pins
nothing. Naming no version is more accurate than trading one stale number
for another. §3.2:90-91 already prescribed allow_reserved=True for a whole
received bundle, which is what v0.3.0 made the default.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XYkLsRfSBBUjULS219Fy8X
Mark the D3 proposal doc RATIFIED: the canonical 7-token set + the two
normative rules (§3.1 partial⇒owner+next-step, §3.2 deferred≠blocked) were
written into ~/.claude/coord/register.md (2026-07-24) as a new
"Status-vokabular" section, with `active` and the open-ended `…` removed and
a contract-source pointer back here. §7 ratification path steps 1–2 marked
done; step 3 (catalog builder enforcement of the §3.1 gate) remains as a
separate catalog-owned track.
Ground truth re-verified before the register write: only `planned` (5×) and
`not-applicable` (1×) in use across ~/repos/*/STATE.md; `active` unused →
safe to fold into `in-progress`. Register edit is local-only (coord metadata
never reaches a public surface); this repo doc is the public contract source.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016oMpAhQcJZVGBW182stSPn
Author the framework-neutral contract that fills the vocabulary reference
D2 left open. Both the D2 register-form fix and the ratified
~/.claude/coord/register.md defer the status-token set to "the D3 track"
without defining it (register.md lines 42-44, 73).
Canonical set: planned / in-progress / partial / blocked / deferred / done /
not-applicable. 'active' folded into 'in-progress' (redundant synonym).
Two normative rules:
- partial is transitional — its output-A prose MUST carry owner + next-step;
never a terminal resting state. Output-A-local, so no conflict with D2's
output-B public-safety gate.
- deferred != blocked — voluntary postponement vs involuntary external wait;
the distinction encodes decision information.
Verified against ground truth: only planned (5x) + not-applicable (1x) in
use across ~/repos/*/STATE.md; 'active' unused (safe to drop); no existing
marker falls outside the set. Definition-before-use, not a migration.
Contract only; no global convention edited. Ratification into register.md
(replace the candidate list + '...' with the canonical set and the two
rules) is the next step, per §7.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016oMpAhQcJZVGBW182stSPn
Author the framework-neutral contract that unblocks D2 (coordination
register). Root cause: D2 conflated marker durability with content
publicness. Fix decouples them via a two-output model — LOCAL-ONLY rich
roll-up (grep STATE, unchanged) + optional public status-token-only index
from minimal committed carriers. Register-builder tolerates three per-repo
modes (absent / minimal-committed / private-sidechannel), decided at build;
never forces a commit. Commons picks 'absent' → the STATE interim line
becomes the permanent design for the public-mirror class.
Contract only; no global convention edited. Ratification (register section
placement + catalog builder wiring) is the next step.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016oMpAhQcJZVGBW182stSPn
Answering question 3 from the OKF round (flat vs hierarchical bundles) turned
up a conflict that is real in code, not just between two spec texts:
method-spec.md:66-69 skip any link target containing a path separator
okf.py:123-125 `if "/" in target: continue` — implemented as written
okf-index.mjs:110 okr emits `${sd}/index.md`
okf-links.mjs:23 okr *requires* a leading `/`
So every link okr produces is skipped by the navigator, and okr cannot write a
flat bundle at all (routeLevel always returns a subdirectory). Worse, the
robustness rule at :72-73 mandates that the skip be silent — a hierarchical
bundle yields a read-context of the root index and nothing else, with no error.
On okr's own okf-realistic fixture all 8 concept files vanish.
The separator ban is the wrong proxy for the security property it wants: it
conflates "contains a separator" with "escapes the bundle". Method-spec already
carries the precise rule two lines below (:73, boundary-checked, fail-closed),
and okr has correct prior art (okf-links.mjs:20-26).
Direction: let navigation traverse hierarchy; keep door A flat in v1. This is
also what makes a shared Python/Node fixture suite possible at all.
Neither spec is edited. Decision is the operator's.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01HBJNsFsBRaAhqGKjjiGjoQ
llm-ingestion-okf is blocked: door A has no free-text connector. Assessment
requested by the implementation repo; this is direction, not a spec edit.
Recommendation: solve in the spec. The real defect is that §5 conflates source
type (transport) with body form — `http` already renders verbatim, so the
verbatim mode exists but is bound to the wrong axis. Separate them with an
extraction-level `render: table|verbatim`; no new source type needed.
Also specifies what §5 must say about verbatim render (strict UTF-8, CRLF→LF
vs the LF-only rule, deterministic fence width, mandatory fencing as a
navigation-injection defence per method-spec §3 Step 1, max_rows semantics),
and flags that free text is untrusted-by-origin over a local transport —
which may pull guard Trigger A forward.
ingest-spec.md is untouched. Decision is the operator's.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01HBJNsFsBRaAhqGKjjiGjoQ
The Claude SDK implementation (claude-code-llm-wiki) runs the same adoption task
in parallel; it owns guard wiring in its repo-local modules (ingest.py/verdicts.py/
okf.py), while shared/ and the ingest-spec gate contract are commons-owned. Record
the reciprocal boundary in the adoption plan so the division of labor survives
between sessions.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Score the guard brief's §7 checklist against the commons-specified architecture:
all implemented ingest paths (file/sql) are first-party, so the decisive
untrusted-ingest box is currently NO. Record the two designed untrusted boundaries
where the guard belongs when built — the http/MCP connector (sanitize + scan-before-
persist at ingest materialization) and a received-external OKF bundle (okf.import_bundle)
— and explicitly exclude the promotion gate as a first-party path the guard must not
wire. Plan only; the guard is not implemented.
Add .gitignore keeping STATE.md LOCAL-ONLY (commons is subtree-consumed and
open-publish-intended; STATE must never reach a consumer's shared/ or a public mirror).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>