{"body":{"CONSEQUENCES":{"severed_couplings":[{"coupling":"The GAD-1 triplet's join. An execution_result attached to its dispatch BY NODE, and that was unambiguous only because the engine's write rule kept at most one unresulted session open per node.","id":"REG-24","re_derived_by_decision":"RUL-10 as amended: session_id becomes the join, and node is retained as a nullable observed key rather than dropped. This was a decision between three candidates, not a regeneration: enumerating per node within the session was rejected because it reintroduces the per-node record under a new name and invites the synthesis RUL-8 forbids.","severed_by":"RUL-8 making the node non-singular for a dispatch. At that moment execution_result had no key by which to attach to its dispatch, and 'at most one unresulted session open per node' lost its referent, because sessions are no longer per node. The triplet did not fail uniformly; it failed at exactly one joint, and that joint is the engine-captured entry the specification calls mandatory precisely because it must exist even when the executor never returned.","still_open_elsewhere":"atlas-orchestrator's src/v06/session.ts still reconstructs the triplet by node identity. NAMED in the manifest, not touched by this run."},{"coupling":"OUTCOME's dependence on observed per-node completion. completedAttempt was built by pairing executor_exit and execution_result by node, and isVerified returned false unless a node appeared in it, so OUTCOME rested on a directly observed per-node fact.","gad2_floor_checked":"Clear, and checked rather than assumed: the GAD-2 floor requires completion-crediting DONE-TESTS at proxy or better and is enforced over verdicts via CLASS_RANK, a separate gate from the triplet's attempt-tracking. Derived attribution is classed proxy and therefore satisfies it.","id":"REG-25","re_derived_by_decision":"RUL-10 as amended retains node as nullable so the observed key survives wherever there is one to observe, and routes the null case through the single derived-attribution section at proxy. The FIRST resting of RUL-10 dropped node outright and was WRONG: the advisory assistant traced isVerified before authoring against the ruling and found that dropping node empties completedAttempt, so no node satisfies isVerified and EVERY conforming run evaluates INCOMPLETE. The amended ruling records that error rather than quietly carrying corrected text.","severed_by":"RUL-8 making per-node attempt-completion DERIVED within a session, while OUTCOME still required it to be OBSERVED."}],"why_this_section_is_separate":"A broken join is not a stale byte. An invalidated artifact is regenerated from its sources; a severed coupling must be RE-DERIVED BY A DECISION, and listing it as though it were a stale byte hides that decision. REG-24 is the proof the distinction is load-bearing: it was found only because someone traced the blast radius through the constructor's source instead of reasoning about the schema, and every prior entry had treated the amendment as bounded by the dispatch record."},"authority":{"executor_role":"The executor authored the text and computed the figures under this plan's nodes; it did not authorize the succession. The authority is the operator's, recorded here by name.","named_authority":"Brandon King","performed_by_executor":false,"role":"the operator","rule":"The authority is the operator, named in the record. No other party MAY perform a specification succession; in particular the executor of a governed run MUST NOT perform one, and a ruling recorded in the companion register is not itself an amendment of this document (spec Section 15, Authority)."},"changed":[{"authored_by":"run #33 (s1-01), verified server-side for the first time by this run's s1b-01","change":"The declared normative range now reads: Sections 1 through 11, Section 12A, Section 14, and Section 15.","section":"Opening declaration (normative range)","why":"A change rule outside the declared normative range is decorative. Section 15 states the ceremony and Section 14 states the stewardship posture it implements; both had to be inside the range for either to bind."},{"authored_by":"run #33 (s1-01)","change":"Defines specification succession as an object distinct from plan succession: its object is this document's byte digest, its authority the named operator, its record a signed sidecar the register cites, its delta carrying the seven mandatory items, numbered in sequence from 1.","section":"15 (new) · Specification succession","why":"The register was the channel through which this document learned it must change, and there was no ceremony by which it could change. RUL-9 rested that gap."},{"authored_by":"this run (s1b-02)","change":"The dispatch block is per-session: it names the session and the node SET it covers and no single node. execution_result carries a required session_id and a nullable node. A derived-attribution section states that per-node attribution within a session is computed from the chain's own entries joined to executor-authored commit boundaries, classed proxy and never upgraded; that synthesized per-node dispatch records are FORBIDDEN; and that one-session-per-node survives as a policy tier. executor_exit is unchanged.","section":"1 · Algorithm 1 (dispatch, execution_result, derived attribution)","why":"RUL-8 and RUL-10 as amended. One executor session works many nodes, so naming one node in a dispatch attributes the whole session's work to it. This was the loop's control structure and not merely a payload field, which is why it was not a field edit."},{"authored_by":"this run (s1b-03)","change":"dispatchPayload drops the scalar node for the node set; executionResultPayload gains a required session_id and keeps node required-and-nullable; a derivedAttribution section pins its class at proxy by constraining the two axes rather than declaring a label. executorExitPayload untouched.","section":"Companion: schemas/witness-entry.schema.json","why":"additionalProperties: false forbade the category outright, so there was no additive path: the schema had to be amended or the model could not be expressed."},{"authored_by":"this run (s1b-05)","change":"RUL-8, RUL-9, and RUL-10 as amended recorded in the rulings block; every rule reasoning about a dispatch naming one node re-derived to reason over the node set.","section":"Companion: transitions/transition-table.json","why":"The table is a normative companion (companion-machinery item 3), not a test fixture; a table that still described the per-node dispatch would contradict the document it companions."},{"authored_by":"run #33 (s1-01), ratified by the operator, verified by this run's s1b-01","change":"The header reads 0.7 and the version history carries a v0.7 entry; v0.6's frozen record survives intact as historical fact.","section":"Version label 0.6 -> 0.7 and the v0.7 history entry","why":"RATIFIED JUDGMENT CALL. Run #33's executor made this change beyond the two edits its node named, and flagged it: Section 15 states its ceremony is introduced by v0.7, so a 0.6 header would have made the document contradict its own new section. The operator ratified the call in this plan rather than letting it pass unremarked, and this run verified it as a premise rather than re-litigating it."}],"discharges":[{"id":"RUL-8","what":"GAD-1 dispatch is per-session; the node remains the unit of obligation; per-node attribution within a session is derived, classed proxy, never upgraded; synthesized per-node dispatch records are forbidden; one-session-per-node survives as a policy tier."},{"id":"RUL-9","what":"Specification succession: the ceremony this delta is performed under. Section 15 introduces it, and this succession is the first act under it."},{"id":"RUL-10","what":"As AMENDED July 15, 2026: execution_result gains a required session_id and RETAINS node as nullable; completedAttempt reads node when non-null and derives at proxy when null. The delta records the amendment, not the first resting, because the first resting dropped node outright and was wrong (see REG-25)."},{"id":"REG-19","what":"Its SPECIFICATION half only: the session model was per-node while the executor topology is per-run. RUL-8 rested the entry; this succession carries the ruling into the document that encodes the model. The implementation half stays open against atlas-orchestrator."},{"id":"REG-21","what":"The ruling-propagation gap: RUL-8 was recorded in the register and never propagated into the frozen specification, whose Algorithm 1 still read append(dispatch, {node: n, ...}) and whose witness schema pinned dispatch to a required scalar node. This succession is the propagation."},{"id":"REG-23","what":"REG-21's closure condition was unsatisfiable as written. Its defect 2 struck 'additive and hash-neutral' as impossible: the chain covers canonBytes(body) and payload is a member of body, so no payload change is hash-neutral. The honest replacement is regeneration with root_core disclosed as changed, which is what this succession did."},{"id":"REG-24","what":"The referee's execution_result carried no session key, so per-session dispatch orphaned the third entry of the GAD-1 triplet. Rested by RUL-10 as amended; see CONSEQUENCES, this is a severed coupling and not merely a stale byte."},{"id":"REG-25","what":"RUL-8 made node-level attempt-completion DERIVED while OUTCOME depended on it being OBSERVED. Rested by RUL-10 as amended; see CONSEQUENCES."}],"genesis_disclosure":{"not_softened":"No sentence in this delta makes this less strange than it is. The strangeness is the finding, and it is load-bearing: it is the reason the disclosure is a required part of the record rather than a footnote, and the reason succession 2 will not need one.","predecessor_authorized_this_amendment":false,"statement":"Succession 1 is performed under a ceremony that v0.7 itself introduces. v0.6 did not authorize its own amendment, and no artifact claims it did. This succession is the first act under a rule it also creates; every succession after it is governed by a rule that predates it. This disclosure is part of the record. It MUST NOT be softened, removed, or restated as though the predecessor had authorized what it did not authorize: the referee does not bless its own birth certificate.","this_is_genesis":true},"invalidated_artifacts":{"also_disclosed":[{"class":"fixture-witness (invalid corpus)","disclosure":"The nine invalid envelopes were hand-derived from their valid parents at genesis and have NO generator, so this succession could not regenerate them the way it regenerated the valid corpus. They still carry the pre-succession witness shape (a scalar dispatch node and an execution_result with no session_id). Each is still rejected for ITS OWN R-condition, verified by the Phase 1 gate, so no coverage was lost; but they remain the predecessor's bytes, and they evaluate only because the evaluator reads a scalar dispatch node as a one-member set. This is disclosed rather than left for someone to discover."}],"classes":[{"class":"fixture-witness","disposition":"regenerated from genesis in this succession (valid corpus); the invalid corpus was NOT regenerated and is disclosed under invalidated_not_regenerated below","member_count":13,"reason":"The chain hash covers canonBytes(body) and payload is a member of body, so amending the dispatch and execution_result payloads moves every entry hash from the amended entry forward. No payload change is hash-neutral; REG-23 struck 'additive and hash-neutral' as impossible.","repository":"gad-protocol"},{"class":"envelope-root","disposition":"regenerated; old and new roots disclosed under root_core below","member_count":4,"reason":"root_core is the tagged hash of the core manifest, whose members' digests are the witness bytes; a moved witness moves root_core, and every anchor signing it signs a different figure.","repository":"gad-protocol"},{"class":"transition-artifact","disposition":"re-derived; every invalid trace still rejected for its own condition, none deleted","member_count":24,"reason":"The transition table is a normative companion (spec companion-machinery item 3) and its trace corpus encodes the dispatch shape; a dispatch that names a node SET rather than one node changes what a legal trace looks like.","repository":"gad-protocol"},{"class":"schema-example","disposition":"updated; the pre-succession per-node dispatch and the session-less execution_result are now committed REJECT cases","member_count":38,"reason":"The witness example corpus asserts, instance by instance, what a valid and an invalid entry look like; the amended dispatch and execution_result payloads change both sides of that assertion.","repository":"gad-protocol"}],"manifest_digest":"366f64b8b87cda87c588fc2ce9eb4f9b0e43e77331e3c5e0e433d4a42e49b185","manifest_path":"succession/manifest/invalidation-manifest.json","named_but_not_touched":[{"artifact_classes":["session-constructor-and-triplet-reconstruction","gate-first-consequence-detection","supervisor-facing-session-tool-schema","v06-test-programs"],"repository":"atlas-orchestrator","why_not_touched":"One graph in gad-protocol amends the referee; the constructor is amended by its own governed run against this successor. A graph that amended the specification and its constructor together would be the constructor editing its own referee."},{"artifact_classes":["atlas-client-session-port"],"repository":"waypoint","why_not_touched":"Same architecture: named here, amended by its own governed run. REG-17 and REG-18 already record that Waypoint's dispatch surface is real but inert, so amending it changes no live behaviour today."}],"named_by":"class, with the cited digest of a manifest COMPUTED from the trees by tools/succession-manifest.mjs","root_core_changed":[{"changed":true,"envelope":"completed","new_root_core":"46b4885d9be9b9379ba29f58520cc77ea9ecb8ea23883985704667efa14b5762","old_root_core":"668df3731a1101b44fbde8cba3075bc254c60557a0c8a6cf18ad2a873b22c498"},{"changed":true,"envelope":"halted","new_root_core":"74cf9aec0f5799cec9f60c492e199e62ee505e763f790ffddd2ab073358243bb","old_root_core":"8fdad3e2cf7aaf9361eafc89a153f4b4f9e8f583f03c9f0cdec31addc5dd0895"},{"changed":true,"envelope":"incomplete","new_root_core":"b34536b5b9813a081818c92e84a22f5493ce8319f158ae2ab14f1c302db68416","old_root_core":"adbfcf938f926675ca48cef0fc0e9e1b4d329cd10f2d6f19d355cbc3fb1916c1"},{"changed":null,"envelope":"multi-node-session","new_root_core":"5db02e365bc142c343d5e773f37c4d929c9f922a380423dce941b1f24e76de8d","old_root_core":null}],"rule":"The manifest MUST be computed and MUST NOT be a hand-typed list: such a list is stale the moment any of its members moves, and a recited figure is not a computed one."},"object":{"document":"docs/gad-formal-spec.md","identified_by":"byte digest of the frozen text, never by version label alone: a label is not an identity (spec Section 15, Object)","successor_digest":"4572c92081a688f673552099a3b254e1187d65745f70f34157c1893e4328645f"},"predecessor_spec_digest":{"commit":"15e473dfe4005499d3b91c26e0cb94b71770fbc4","digest":"446793d47bd2da4cd4b591a17dd19a1b7ec4d30a7fb2c55de4c617e533ff37d0","provenance":"sha256 of docs/gad-formal-spec.md as of commit 15e473d, the parent of run #33's spec commit 16f7602 and therefore the last tree in which this document was v0.6. Only three commits have ever touched the file (88710bb seeded it, 16f7602 amended it to v0.7, 742e9da carried the Algorithm 1 amendment), and the bytes at 88710bb and 15e473d are identical, so the predecessor is unambiguous rather than chosen. NOT recomputable from this tree: v0.6's bytes are not on disk, and the verifier says so rather than implying it checked them.","recomputable_from_this_tree":false,"version_label":"0.6"},"record":{"cited_by":"docs/gad-spec-register.md","lives_at":"succession/delta/succession-1.json","rule":"The record of a specification succession lives in gad-protocol as a signed sidecar beside this document, and the companion specification register cites it. The register remains the channel through which this document learns that it must change; the succession is how it changes.","verified_by":"tools/succession-verify.mjs"},"record_type":"gad-spec-succession-delta","signature_scope":{"DISCLOSED_CONFLICT":"conformance/keys/dev-keys.json states, in its own warning field, that these keys 'must NEVER sign anything outside conformance/'. This delta lives at succession/delta/ and is therefore signed outside that boundary. The conflict is recorded here rather than resolved quietly by the executor: either the key file's boundary is amended to admit the succession record, or succession 1's record is re-signed under a real authority key. Both are the operator's call. Nothing about the ceremony's other properties depends on which is chosen.","construction":"SIGN_x(obj) = {body: obj, signature: sig_x(canon(obj))}; the signature covers the canonical body and is never a member of it.","key":"conformance/keys dev authority key (label: TEST FIXTURE KEYS)","what_this_signature_ATTESTS":"the CEREMONY: that this delta's text and figures are the ones bound at signing time, and that they have not moved since.","what_this_signature_DOES_NOT_ATTEST":"any registry identity. This is a committed development key whose private half is in the repository; it proves no one's authorship and binds no one's name. A signature under a public key that anyone can read and re-sign with is a checksum with ceremony, and calling it an identity claim would be the exact verified-by-attestation move this specification exists to refuse."},"succession_number":1,"successor_does_not_claim":{"not_claimed":["IMPLEMENTATION CONFORMANCE. No implementation is claimed to conform to v0.7. atlas-orchestrator still writes the per-node dispatch this version supersedes, and its execution_result still carries no session key; that is why REG-19's implementation half, REG-21's implementation remainder, and REG-24's and REG-25's implementation halves stay OPEN. A specification that amended itself and declared its constructor conformant in the same act would be the referee scoring its own match.","ANY DOWNSTREAM ARTIFACT BROUGHT INTO CONFORMANCE. This succession NAMES the artifacts it invalidates in atlas-orchestrator and waypoint and does not TOUCH them. Naming is not fixing. They are amended by their own governed runs against this successor, and until then they are invalid against it, which the manifest states plainly.","RECLASSIFICATION OF THE HISTORICAL RECORDS. Nothing recorded before this succession is reissued, recomputed, or re-read. The earlier records say what they said. Their disposition is the Trial 0 matrix's question and is not touched here, and never backfilled.","INDEPENDENT FORMAL OR CRYPTOGRAPHIC REVIEW. Still pending; it is Phase 5. Section 1's results remain Propositions and Claims, not Theorems, and this succession does not move them.","IDENTITY, VIA ITS SIGNATURE. The delta is signed with a committed development key whose private half is in the repository. The signature attests to the ceremony and binds nobody's name; see signature_scope.","THAT THE GENESIS PROBLEM IS SOLVED. It is disclosed, not solved. See genesis_disclosure."],"statement":"The successor does not claim what follows, and says so here rather than leaving the boundary to be inferred from silence. v0.7 amends a specification and nothing else: it does not claim that any implementation conforms to it, it does not claim that any downstream artifact it invalidates has been brought back into conformance, it does not claim any authority over the historical records, it does not claim the independent review it still owes, it does not claim that its signature binds an identity, and it does not claim to have solved the genesis problem it discloses."},"successor_spec_digest":{"digest":"4572c92081a688f673552099a3b254e1187d65745f70f34157c1893e4328645f","provenance":"sha256 of docs/gad-formal-spec.md as it stands in this tree; recomputed by tools/succession-verify.mjs against the bytes on disk.","recomputable_from_this_tree":true,"version_label":"0.7"}},"signature":"624c1351ee0bfb53498261c5e51487b2ff0b0282b114cde69e3ffb2c4aa8ea816f69add644df849ff6bea2b692dea0076013cbe16e74677ed2bc7b191aa5ed05"}