{"body":{"CONSEQUENCES":{"severed_couplings":[{"id":"REG-28","re_derived_by_decision":"RUL-12: node is nullable and engine-observed, non-null only where singularity was actually observed. The per-node consequences of a multi-node exit, including which node routes to FAILED, are DERIVED through the single RUL-8 derived-attribution mechanism and classed proxy, never engine_observed. The triplet's philosophy becomes uniform: dispatch names the commissioned set; exit and result each name the session plus a node only when singularity was observed.","what":"The coupling between one exiting process and one exit record per covered node. executor_exit's scalar node encoded a semantic fiction: that a session which covered many nodes could name the one node it exited for. Succession 1 left that scalar standing because the record carried session_id too and its join never depended on node being singular, which is precisely what hid the fiction."},{"id":"REG-29","re_derived_by_decision":"The blessing in v0.8's normative text: the reading is legal because the specification says so and can be judged there, not because a tool happens to do it. The corpus's bytes are untouched; what changed is where its legality is decided. The generator half of REG-29 stays open and is not claimed.","what":"The coupling between the historical corpus's evaluability and one tool's private normalization. The nine invalid fixtures evaluate only because an evaluator reads their scalar dispatch node as a one-member set; while that reading lived in a tool's source, the corpus's legality depended on an implementation detail no one had judged."},{"id":"REG-33","re_derived_by_decision":"The lineage rule the corrected plan forced into tools/succession-verify.mjs: only the LATEST record's successor digest is ever recomputed from disk; every earlier record's is RECORDED, NOT VERIFIED, held instead by the signature over its canonical body, with chain continuity (each predecessor digest equal to the prior successor digest) checked as a FAILURE on break. The general rule was always latent in the tool's own predecessor NOTE for v0.6; REG-33 is the cost of not having drawn it.","what":"The coupling between 'a succession record's successor digest' and 'the document on disk'. That identity holds for exactly one record, the latest, and this succession is what broke it: bumping the spec made succession 1's successor digest permanently unrecomputable and deadlocked a verifier that assumed otherwise, crashing run #36 at 5 of 7."}],"statement":"What this amendment SEVERS, as distinct from what it invalidates. An invalidated artifact is regenerated from its sources; a severed coupling must be re-derived by a decision, and the decision is named here rather than left for an implementer to infer."},"authority":{"executor_role":"The executor authored this text and computed these figures under the nodes of the succession-2b plan, and applied the operator's key to the canonical body at the operator's direction. It did not authorize the succession. The authority is the operator's, recorded here by name, exercised by commissioning this plan and by placing the signing key outside this repository where only the operator controls it. This is the same division succession 1 recorded and RUL-11 ratified: authoring and computing are not authorizing.","named_authority":"Brandon King","performed_by_executor":false,"role":"the operator","rule":"The authority is the operator, named in the record. No other party MAY perform a specification succession; in particular the executor of a governed run MUST NOT perform one, and a ruling recorded in the companion register is not itself an amendment of this document (spec Section 15, Authority)."},"changed":[{"change":"executor_exit's node becomes REQUIRED and NULLABLE: non-null exactly when the session covered exactly one node (engine-observed), null when it covered many, the null a STATED absence per I5, never an omission and never a second key at a different strength. Pairing is by session_id.","section":"Section 2, Executor exit entry, and Algorithm 1","why":"RUL-12, resting REG-28. One session dies once. A required scalar node on the exit record implied one exit per covered node, and would have demanded of the engine a node name no honest writer could supply, forcing exactly the synthesis RUL-8 forbids. It mirrors RUL-10 as amended rather than inventing a second mechanism, because two mechanisms for one shape is how a specification grows a seam."},{"change":"The entry now reads {session_id, node, delta_ref, delta_digest, touched_surface, output_status}, with session_id REQUIRED as the pairing key and node NULLABLE, matching Algorithm 1 as RUL-10 amended it. No other Section 2 entry was touched.","section":"Section 2, Execution result entry","why":"REG-34. Section 2's prose still described the pre-amendment object while Algorithm 1 required session_id, so the document contradicted itself and REG-24's closure claimed a session key one section did not carry. A specification whose prose and algorithm disagree hands the implementer a choice the specification was supposed to make."},{"change":"An evaluator MAY read a scalar dispatch node in a pre-v0.7 record as the one-member set containing it.","section":"Section 2 / evaluation of pre-v0.7 records","why":"REG-29. The concession existed already, but it lived in one tool's source, where it was doing the specification's job unjudged. Moving it into the normative text does not widen it: reading a scalar as the one-member set containing it is a spelling of a legal set, not a synthesized boundary. It preserves the historical invalid corpus byte-identical instead of regenerating fixtures that have no generator."}],"crash_and_correction":{"corrected_path":"Succession by corrected plan, never by editing the crashed one: the succession-2b plan. Its first node made the verifier lineage-aware, which is what unblocked this record. Its second node RE-BLESSED the crashed run's committed work by re-running every one of those nodes' done-tests against THIS tree, server-verified, so that this record rests on evidence rather than on a crashed run's claims. Nothing was rebuilt and nothing was backfilled.","statement":"This record exists because run #36 crashed at 5 of 7 rather than because its work was wrong. Nodes 1 through 5 had landed and were committed: the v0.8 spec text, the nullable exit schema, the evaluator, the fixtures, the gate, and the builder guard. Node 6 could not proceed, because the very spec bump those nodes made had rendered succession 1's record unverifiable by a verifier that assumed the successor is always the document on disk (REG-33). The executor halted rather than widening its fence, refused a waiver that would have recorded a falsehood, and named the deadlock.","what_this_means_for_the_record":"Every figure in this delta is computed from the tree as it now stands or recorded with the provenance of a commit that still holds the bytes. No claim inherited from run #36 is carried here on trust."},"discharges":{"by_this_amendment":[{"closes_when":"a successor spec rules what one exiting executor's record names under a multi-node session, and the schema and evaluator are amended to match","discharged_how":"v0.8 rules it: executor_exit's node is REQUIRED and NULLABLE, non-null exactly when the session covered one node, null when it covered many, the null a stated absence per I5. The schema (schemas/witness-entry.schema.json) and the evaluator (evaluator/src/transitions.ts) are amended to match, and both were re-verified against THIS tree by the s2b-02 node rather than inherited as claims from the crashed run.","id":"REG-28","register_status_before":"OPEN"},{"closes_when":"the ruling's substance is carried into the specification's normative text","discharged_how":"Carried into Section 2's Executor exit entry and Algorithm 1, mirroring RUL-10 as amended rather than inventing a second mechanism. Pairing is by session_id, the only thing the engine observes at the exit moment.","id":"RUL-12","register_status_before":"the ruling that rests REG-28"},{"closes_when":"the normalization is blessed in the specification's own text by a succession","discharged_how":"v0.8 blesses it: an evaluator MAY read a scalar dispatch node in a pre-v0.7 record as the one-member set containing it, a spelling of a legal set and never a synthesized boundary. The concession moves out of one tool's source and into the normative text where it is judged. PARTIAL BY ITS OWN TERMS: the invalid-fixture generator remains future work and is NOT claimed closed here.","id":"REG-29","register_status_before":"RULING"},{"closes_when":"the Section 2 entry matches Algorithm 1's amended shape (required session_id, nullable node), fixed inside succession 2's still-unsealed scope","discharged_how":"Section 2's Execution result entry now carries session_id REQUIRED as the pairing key and node NULLABLE per RUL-10 as amended. It was fixed inside this succession's unsealed scope, which is the only reason it could be fixed without a third succession: REG-24's closure had claimed the specification carried a session key while one section did not.","id":"REG-34","register_status_before":"OPEN"}],"by_this_run_not_by_this_amendment":[{"closes_when":"the builder refuses to overwrite a record whose signature is not the dev key's, and the refusal is probed","discharged_how":"succession/delta/build-delta.mjs refuses a target it cannot have signed, and the refusal is probed. Re-verified against THIS tree by s2b-02: an unadorned invocation left the operator-signed record byte-identical.","id":"REG-31","register_status_before":"OPEN"},{"closes_when":"test 17 compares root_core across two independent builds for ALL valid fixtures discovered from the tree rather than a hardcoded list, and its detail line reports the computed count","discharged_how":"Acceptance test 17 discovers fixtures from the tree and reports a computed count. Re-verified against THIS tree by s2b-02.","id":"REG-32","register_status_before":"OPEN"},{"closes_when":"the verifier is lineage-aware, recomputing only the latest succession's successor digest from disk, verifying every earlier record's signature over its canonical body with digests marked historical-recorded","discharged_how":"tools/succession-verify.mjs discovers records from the directory, orders them, recomputes only the latest successor digest from disk, and reports every earlier one as RECORDED, NOT VERIFIED. This record is the first to exercise that rule: signing it is what makes succession 1 a non-latest record.","id":"REG-33","register_status_before":"OPEN"},{"closes_when":"the builder derives the version label from the document bytes it hashes, or refuses --out when the label it would write does not match the tree, with the refusal probed","discharged_how":"build-delta.mjs parses the label from the header of the document it hashes and REFUSES when no label, or more than one, can be read. Both refusals are probed against planted controls.","id":"REG-35","register_status_before":"OPEN"}],"statement":"Every identifier below was checked against docs/gad-spec-register.md, which governs. The register's closure condition for each is quoted in substance and matched against this tree, never assumed from a plan's description.","why_the_split_is_recorded":"A specification amendment discharges what its text rules. It does not repair a builder, a verifier, or a test, and a record that listed all eight under one heading would be claiming the document fixed tooling it never touched. The tooling entries are discharged by the succession-2b run and are recorded here because the succession's record is the channel through which the register learns they closed, not because the amendment closed them."},"genesis_disclosure":{"predecessor_authorization":"v0.7's Section 15 defines the only ceremony by which this document changes, and this succession is performed under it: object identified by byte digest, authority the named operator, record a signed sidecar the register cites, delta carrying the seven mandatory items, numbered in sequence from 1. Unlike succession 1, nothing here is performed under a rule of its own making.","predecessor_authorized_this_amendment":true,"statement":"Succession 2 is NOT genesis and claims no genesis exception. It is the first specification succession governed by a rule that predates it: Section 15's ceremony was introduced by v0.7, not by this document. Succession 1 disclosed that it was the first act under a rule it also created, and promised that every succession after it would be governed by a rule that predated it. This record is that promise made good. Succession 1's disclosure is not softened, removed, or restated here: it remains true of succession 1, and the fact that succession 2 is ordinary is exactly what it predicted.","this_is_genesis":false},"invalidated_artifacts":{"classes":["witness-schema","transition-table","evaluator-transitions","fixture-witness (multi-node session)"],"manifest":"succession/manifest/invalidation-manifest.json","manifest_digest":"45159c4ced3b4a22935655750c1d92445b440eaccfbcaf72219076810938bcce","named_by":"class, with the cited digest of a manifest COMPUTED from the tree by succession/manifest/build-manifest-2.mjs","predecessor_manifest":{"commit":"e2d860b2b95e10470dbce32bf181487cf9769f66","digest":"366f64b8b87cda87c588fc2ce9eb4f9b0e43e77331e3c5e0e433d4a42e49b185","provenance":"Succession 1's manifest, whose bytes this succession's manifest replaces at the same path. Captured from disk BEFORE the replacement and cross-checked against the digest succession-1.json cites, which matched, proving these are the bytes succession 1 signed over and that they had not moved since. NOT recomputable from this tree: recoverable from commit e2d860b, exactly as v0.6's and v0.7's spec bytes are recoverable from theirs. The same lineage rule REG-33 forced for spec digests governs this figure, and tools/succession-verify.mjs reports succession 1's cited manifest digest as RECORDED, NOT VERIFIED now that succession 1 is no longer the latest record.","recomputable_from_this_tree":false},"scope_note":"gad-protocol only. atlas-orchestrator and waypoint are NAMED in the manifest, with a stated reason, and are NOT read, NOT hashed, and NOT touched: a graph that amended the specification and its constructor in one run would be the constructor editing its own referee. They get their own governed runs against this successor."},"object":{"document":"docs/gad-formal-spec.md","identified_by":"byte digest of the frozen text, never by version label alone: a label is not an identity (spec Section 15, Object)","successor_digest":"07ba93975cfe6947ddc8b507ea4a2273e05039186567fb9333d42d97912c3f50"},"predecessor_spec_digest":{"commit":"742e9da9167aa3089eca5574e0d40abf8205b776","digest":"4572c92081a688f673552099a3b254e1187d65745f70f34157c1893e4328645f","provenance":"succession 1's successor digest, read from succession/delta/succession-1.json rather than transcribed, which is what makes the chain continuous by derivation instead of by assertion. Those bytes are the blob at commit 742e9da, the last tree in which this document was v0.7. NOT recomputable from this tree: v0.7's bytes left it when succession 2's spec bump was committed, and tools/succession-verify.mjs reports this figure as RECORDED, NOT VERIFIED rather than implying it rechecked it (REG-33's lineage rule).","recomputable_from_this_tree":false,"version_label":"0.7"},"record_type":"gad-spec-succession-delta","signature_scope":{"construction":"SIGN_x(obj) = {body: obj, signature: sig_x(canon(obj))}; the signature covers the canonical body and is never a member of it.","key":"the operator authority key (RUL-9, RUL-11 clause 2); public half committed at succession/keys/operator-pubkey.json, private half never in this repository","what_this_signature_ATTESTS":"that this delta's text and figures are the ones bound at signing time, and that they have not moved since; and, unlike succession 1's genesis artifact, that the party who bound them holds a key whose private half has never entered this repository and which names an authority.","what_this_signature_DOES_NOT_ATTEST":"any registry identity beyond the named authority's custody of the key, and no claim that any implementation conforms to the successor. REG-14 (key custody) remains OPEN: its interim rule is that a compromised key is handled by succession, not in-place revocation, and this is the second record that rule would apply to."},"succession_number":2,"successor_does_not_claim":{"not_claimed":["IMPLEMENTATION CONFORMANCE. No implementation is claimed to conform to v0.8. atlas-orchestrator still writes an executor_exit whose node is a required scalar, which is the very shape this succession made nullable; that work is named in the manifest as untouched and belongs to its own governed run. A specification that amended itself and declared its constructor conformant in the same act would be the referee scoring its own match.","THAT REG-29 IS FULLY CLOSED. Its normalization half is discharged by the blessing; its generator half is not. The nine invalid fixtures still have no generator, still carry the pre-succession witness shape, and are still evaluated through a reading this document now blesses rather than through bytes anyone regenerated.","THAT THE TOOLING DEFECTS WERE FIXED BY THIS DOCUMENT. REG-31, REG-32, REG-33, and REG-35 were fixed by the succession-2b run's nodes and are recorded here because this record is how the register learns they closed. The text of v0.8 repaired no builder.","ANY AUTHORITY OVER THE HISTORICAL RECORDS. v0.6's and v0.7's history entries stand intact as fact, and succession 1's genesis disclosure is neither softened nor restated. This succession does not reach backward.","THE INDEPENDENT REVIEW IT STILL OWES. Section 1's results remain Propositions and Claims, not Theorems, and independent formal and cryptographic review is still pending. This succession did not perform it.","THAT ITS SIGNATURE BINDS AN IDENTITY BEYOND KEY CUSTODY. The signature proves that the holder of the operator key bound this text. REG-14 (key custody) remains OPEN.","THAT THE GENESIS PROBLEM IS SOLVED. Succession 1 disclosed it; this succession is simply the first one that does not face it, which is not the same as solving it."],"statement":"The successor does not claim what follows, and says so here rather than leaving the boundary to be inferred from silence. v0.8 amends a specification and nothing else."},"successor_spec_digest":{"digest":"07ba93975cfe6947ddc8b507ea4a2273e05039186567fb9333d42d97912c3f50","provenance":"sha256 of docs/gad-formal-spec.md as it stands in this tree, recomputed by tools/succession-verify.mjs against the bytes on disk. The version label is parsed from that same document's header, never recited, so the label cannot contradict the digest beside it (REG-35).","recomputable_from_this_tree":true,"version_label":"0.8"}},"signature":"ec145d67f1a719ea4d9358c8cbcb6b99908d02f2e593f78bd7ebd1c5d6abc7a08fe87a946f69f7160fa1b38a661e4e4b8fd28a85d2fa9cf60fb18541866a7906"}