{"body":{"CONSEQUENCES":{"severed_couplings":[{"coupling":"The coupling between VERIFICATION and the SIGNING boundary. While the fixture-key boundary question was unruled, reading the committed dev public key to verify the genesis exhibit was treated as potentially crossing the boundary its key file declares, so the verifier carried the conservative shape: dev signature RECORDED, NOT VERIFIED, held only by the byte-identity of its body.","id":"REG-37","re_derived_by_decision":"tools/succession-verify.mjs adopts dev-key verification of the genesis exhibit BY CHOICE (s3-02), ruling cited in the code, fail closed — an exhibit whose one binding has broken now FAILS the run instead of passing as merely-recorded — with what the verification attests bounded honestly: the CEREMONY, never authorship, because the dev key's private half is committed and binds no one's name.","severed_by":"The v0.9 ruling that verification is a read: a signature check under a public key reads public material and crosses no signing boundary, because signing boundaries govern what keys SIGN."},{"coupling":"The coupling between 'key material' and DETECTABLE SHAPE. Every key-hygiene check before this ruling asked what a value LOOKS LIKE (substrings, PEM headers, hex lengths), a coupling REG-36 proved unsatisfiable in one direction (a field name tripping a content check) and REG-38 proved unsound in the other (a 64-hex Ed25519 seed slipping under an 80-character floor; 35 legitimate digests flagged by pattern).","id":"REG-38","re_derived_by_decision":"Key material is decided by what a value DERIVES: it parses as a private key, derives a trusted public key, or HMAC-derives from a held secret. tools/key-material-check.mjs is that decision made executable, its probe catching three planted real keys by named clause while a random scalar passes clean. This record's own signing applied the same standard: the key was required to DERIVE the committed public half before it signed.","severed_by":"The mathematical fact the register carries — a secret scalar has no detectable shape; every 32-byte string is a valid Ed25519 seed — made normative: pattern-matching on length or encoding is NOT a conforming check."},{"coupling":"The coupling between 'the probe FIRED' and 'the probe process exited NONZERO'. Every probe judgment in this project's history that read only an exit code inherited the ambiguity: a spawn failure also exits nonzero, so a checker could report its probe fired when the runner was never found (run #41: 10 of 10 reported, 9 of 10 never executed).","id":"REG-39","re_derived_by_decision":"FIRED means spawned, exited nonzero, AND produced output — all three, judged by conforming tooling. The sweep of this repository computed zero sites needing change (both spawn-based probe judgments already required all three), and this plan's own probes are judged by the corrected standard.","severed_by":"The v0.9 probe-fired standard: an exit code cannot distinguish a probe that proved its check can fail from a probe that never found its runner; the OUTPUT is what separates them."}],"statement":"What this amendment SEVERS, as distinct from what it invalidates. An invalidated artifact is regenerated from its sources; a severed coupling must be RE-DERIVED BY A DECISION, and the decision is named here rather than left for an implementer to infer."},"amended_files":{"files":[{"digest":"20daf6004a8eb23344067f216e5f81c85b4ef998c249448fe5042110352dca81","path":"docs/gad-formal-spec.md"},{"digest":"1533e4333e9568ad463d8c21e60d1fe178273e172fc1a061ab2bc12ad5cc1fc2","path":"tools/key-material-check.mjs"},{"digest":"61fe9add9ef735192865b83b3c1bbe41c439e5c9d526793c7deab9340eb55406","path":"tools/succession-verify.mjs"},{"digest":"88ac26386c9058fdf9c74accf91f45efebe66724fde965226b242b096889ba67","path":"package.json"}],"statement":"The files this succession amended or landed, each digest hashed from the bytes on disk at build time, never transcribed. The companion register (docs/gad-spec-register.md) is cited by identifier throughout this record and deliberately NOT by digest: it is the append-only companion whose next append is this very record's citation, and a digest here would freeze the document this record exists to be cited by."},"authority":{"executor_role":"The executor authored this text and computed these figures under the succession-3 arc's nodes (s3-01/s3-02/s3-03, re-blessed by s3c-01; this record by s3c-02), and applied the operator's key to the canonical body at the operator's direction. It did not authorize the succession. The authority is the operator's, recorded here by name, exercised by commissioning the plan, by the logged per-node authorization gating the ceremony node (see gate_channel), and by holding the signing key outside this repository where only the operator controls it. Authoring and computing are not authorizing (succession 1's division, RUL-11's ratification).","named_authority":"Brandon King","performed_by_executor":false,"role":"the operator","rule":"The authority is the operator, named in the record. No other party MAY perform a specification succession; in particular the executor of a governed run MUST NOT perform one, and a ruling recorded in the companion register is not itself an amendment of this document (spec Section 15, Authority)."},"changed":[{"authored_by":"the s3 arc (s3-01, commit 2e85e7b), re-blessed against this tree by s3c-01","change":"Added the normative sentence: Verification is a read (REG-37). VERIFYING under a public key is a READ of public material and does not cross a signing boundary; signing boundaries govern what keys SIGN.","section":"5 · The constructor, explained","why":"REG-37's endorsed judgment call needed a home in normative text. The s2b-01 executor read RUL-11's boundary conservatively against its own instruction and proved a weaker honest claim because the boundary question was UNRULED; the ruling makes verification a read, so the stronger claim (the genesis exhibit's dev signature VERIFIED) is legal and strictly stronger, adopted by choice rather than slid into."},{"authored_by":"the s3 arc (s3-01, commit 2e85e7b), re-blessed against this tree by s3c-01","change":"Added the normative definition: Key material, defined (REG-38). A value IS key material iff it parses as a private key (PEM or DER PKCS#8) or derives a public key the tree trusts; pattern-matching on length or encoding is NOT a conforming check; key-hygiene checks are judged against this definition.","section":"9 · Time, anchoring, and export","why":"REG-36's closure demanded a check that detects ACTUAL key material in content, and REG-38 recorded the mathematical fact underneath: a secret scalar has no detectable shape (every 32-byte string is a valid Ed25519 seed), so only derivation can decide. A definition that lived in one repository's checker would be the concession-in-a-tool's-source shape REG-29 already taught against."},{"authored_by":"the s3 arc (s3-01, commit 2e85e7b), re-blessed against this tree by s3c-01","change":"Added the normative standard: The probe-fired standard (REG-39). A planted-defect probe counts as FIRED only if it really spawned, exited NONZERO, and produced OUTPUT; conforming tooling judges probes by all three.","section":"11 · Conformance, in three levels, and conformance trials","why":"A spawn failure also exits nonzero, so an exit code alone cannot distinguish a probe that proved its check can fail from a probe that never found its runner; run #41's first attempt reported 10 of 10 probes fired while 9 of 10 checkers had not executed. Fired means ran, failed, and said so."},{"authored_by":"the s3 arc (s3-01, commit 2e85e7b), re-blessed against this tree by s3c-01","change":"Added the design paragraph: Key lifecycle (REG-14). Stable key_id/algorithm/custody_statement per principal; supersession only through a signed lifecycle entry naming both ids and the effective boundary; revocation forward-looking; lifecycle events recorded in the succession record stream; interim rule (compromise handled by succession) stated; implementation post-v1.0.","section":"12A · Profile One: Governed AI Development (normative)","why":"REG-14 deferred rotation and revocation with an interim rule improvised nowhere; the operator key RUL-11 created is the first key that rule will ever apply to, and this record is the third signed under it. The design had to be fixed BEFORE an incident forces it, and fixing the design is not implementing it: the entry stays OPEN and tracks the implementation."},{"authored_by":"the s3 arc (s3-01, commit 2e85e7b), re-blessed against this tree by s3c-01","change":"The header reads 0.9, the version history carries a v0.9 entry enumerating the four amendments, and the document ends 'End of v0.9.' All earlier history entries stand intact as fact.","section":"Version label 0.8 -> 0.9, the v0.9 history entry, and the closing line","why":"The history is fact and the label must not contradict the bytes beside it (REG-35: this record's own version labels are derived from the bytes it hashes, never recited). Succession 1's genesis disclosure is neither softened nor restated."}],"discharges":{"by_this_amendment":[{"closes_when":"the P1-09 lifecycle design plus its implementation in a later phase; the design half is rested here and the entry records DESIGN RESTED by succession 3","discharged_how":"DESIGN HALF ONLY, partial by its own terms: v0.9's Profile One fixes the key lifecycle design the implementation must conform to — AuthorizedPrincipals binding public material with stable key_id, algorithm, and custody_statement; supersession only through a SIGNED LIFECYCLE ENTRY naming both ids and the effective boundary; revocation FORWARD-LOOKING (past signatures remain valid for the records they signed); lifecycle events recorded in the succession record stream; and the interim rule (a compromised key is handled by succession) stated in the text rather than improvised at the incident. The IMPLEMENTATION remains post-v1.0 work and is NOT claimed; the register entry stays OPEN and tracks it.","id":"REG-14","register_status_before":"OPEN (key custody: rotation and revocation deferred, P1-09)"},{"closes_when":"the ruling is spec text and succession-verify adopts dev-key verification of the genesis exhibit by choice — both now hold; the register records CLOSED by succession 3","discharged_how":"The ruling is normative v0.9 text (Section 5): VERIFYING under a public key is a READ of public material and does not cross a signing boundary; signing boundaries govern what keys SIGN. The verifier's adoption of the ruling is the run's work, recorded separately below: a specification amends text, not tools.","id":"REG-37","register_status_before":"executor judgment call, ENDORSED, awaiting the ruling a spec could carry"},{"closes_when":"the derive-based definition is normative and tools/key-material-check.mjs is its executable form, probe-proven — both now hold; the register records CLOSED by succession 3","discharged_how":"The derive-based definition is normative v0.9 text (Section 9): a value IS key material iff it parses as a private key or derives a public key the tree trusts; pattern-matching on length or encoding is NOT a conforming check. Key-hygiene checks are judged against this definition. The executable form is the run's work, recorded separately below.","id":"REG-38","register_status_before":"check-design finding: a secret scalar has no detectable shape"},{"closes_when":"the standard is normative spec text, adopted in this repository's tools, and this plan judges its own probes by it — all now hold; the register records CLOSED by succession 3","discharged_how":"The probe-fired standard is normative v0.9 text (Section 11): a planted-defect probe counts as FIRED only if it really spawned, exited NONZERO, and produced OUTPUT; conforming tooling judges probes by all three. The sweep of this repository's tools is the run's work, recorded separately below.","id":"REG-39","register_status_before":"probe-epistemics defect: an exit code alone cannot distinguish a probe that fired from a probe that never found its runner"}],"by_this_run_not_by_this_amendment":[{"discharged_how":"tools/succession-verify.mjs adopts the ruling BY CHOICE (s3-02, commit 13f51aa; re-blessed against this tree by s3c-01): the retained genesis exhibit's dev signature is VERIFIED under the dev authority PUBLIC key, ruling cited in the code, fail closed (an exhibit whose one binding has broken fails the run), with the ceremony-not-identity note kept so VERIFIED never reads as an identity claim.","id":"REG-37 (adoption)"},{"discharged_how":"tools/key-material-check.mjs lands the derive-based sweep: a finding iff a candidate parses as a PEM/DER PKCS#8 private key, derives a trusted public key, or HMAC-derives from a held secret — never shape. Its probe is discriminating: three planted real keys each caught by a named clause, a random-scalar negative control passing clean. Wired as npm run key-material-check.","id":"REG-38 (executable form)"},{"discharged_how":"The sweep over this repository's tools COMPUTED zero sites needing change: both spawn-based probe judgments (succession/exit/build-exit-gate-2.mjs and its predecessor pattern) already required spawn + nonzero + output. A computed zero is a figure too, and it is recorded as computed, not assumed.","id":"REG-39 (sweep)"}],"cited_rulings_not_discharged_here":[{"id":"REG-46","status":"CLOSED July 16, 2026, constructor-side","why_cited":"The operator's ruling rested the fix in the CONSTRUCTOR'S ORDERING (the terminal withheld at both terminals while any dispatched session lacks its closing triplet), landed in atlas-orchestrator with a two-sided probe that names the strand. Cited because this ceremony is performed under the engine that ruling repaired, and the register's rulings travel through the succession record stream; NOT discharged here — the amendment's text touches none of it."},{"id":"REG-48","status":"OPEN; ruling RESTED (operator, July 16, 2026)","why_cited":"Verification is post-quiescence by the specification's semantics; the Movement 2 choreography is the multi-node session with post-session verification. THIS RECORD WAS PRODUCED UNDER THAT CHOREOGRAPHY (see session_choreography). The entry closes only when a live-choreography record evaluates fully referee-valid, which this succession does not claim."}],"statement":"Every identifier below was checked against docs/gad-spec-register.md, which governs. The register's closure condition for each is quoted in substance and matched against this tree, never assumed from a plan's description."},"gate_channel":{"rule":"REG-51 (plan ruling): this ceremony node is HIGH-RISK, and the product's two-channel out-of-band approval secret is deferred in v1, so the gate is the logged-authorization channel.","what_happened":"The run stopped at awaiting_approval and proceeded ONLY on the operator's logged authorization naming the node s3c-02-delta-ceremony, delivered through the engine's approval inbox and recorded in the run's audit log. The SIGNATURE over this record is the operator's human act with the authority key, performed through the established signing flow (the key verified to derive the committed public half before it signed, key material never entering this repository); it remains the ceremony's substance whatever the gate's channel count."},"genesis_disclosure":{"predecessor_authorization":"v0.8's Section 15 defines the only ceremony by which this document changes, and this succession is performed under it: object identified by byte digest, authority the named operator, record a signed sidecar the register cites, delta carrying the seven mandatory items, numbered in sequence from 1.","predecessor_authorized_this_amendment":true,"statement":"Succession 3 is NOT genesis and claims no genesis exception. It is the second specification succession governed by a rule that predates it: Section 15's ceremony was introduced by v0.7 and carried intact through v0.8. Succession 1's disclosure is not softened, removed, or restated here: it remains true of succession 1, and every succession after it being ordinary is exactly what it predicted.","this_is_genesis":false},"invalidated_artifacts":{"classes":[{"class":"succession-verifier","disposition":"amended in this succession (s3-02, commit 13f51aa; re-blessed against this tree by s3c-01)","member_count":1},{"class":"key-material-checker","disposition":"landed in this succession (s3-02, commit 13f51aa) as REG-38's executable form","member_count":1},{"class":"script-surface (root package.json)","disposition":"amended in this succession (s3-02, commit 13f51aa)","member_count":1}],"manifest_digest":"5c9c530142f7a731e7d1f7e99ecfb01d903b82174e944af1baa3f81388e3e7b5","manifest_path":"succession/manifest/invalidation-manifest.json","named_by":"class, with the cited digest of a manifest COMPUTED from the tree by succession/manifest/build-manifest-3.mjs","predecessor_manifest":{"commit":"31fe72e1cdba5fdc3aba44a14f3bf013e71807a4","digest":"45159c4ced3b4a22935655750c1d92445b440eaccfbcaf72219076810938bcce","provenance":"Succession 2's manifest, whose bytes this succession's manifest replaces at the same path. The blob at commit 31fe72e1cdba5fdc3aba44a14f3bf013e71807a4 was hashed and required to equal the digest succession-2.json cites BEFORE this record was written, proving these are the bytes succession 2 signed over and that they had not moved since. NOT recomputable from this tree once replaced: recoverable from that commit, exactly as v0.8's spec bytes are recoverable from theirs. tools/succession-verify.mjs reports succession 2's cited manifest digest as RECORDED, NOT VERIFIED now that succession 2 is no longer the latest record (REG-33's lineage rule).","recomputable_from_this_tree":false},"predecessor_members_comparison":{"members_moved":0,"members_recorded":5,"note":"Computed by build-manifest-3.mjs: every member succession 2's manifest recorded was re-hashed from this tree. v0.9's amendments are additive definitions, and the computed zero moved-members shows it: what this succession invalidates is the tooling its rulings amended or landed, not the predecessor's members."},"rule":"The manifest MUST be computed and MUST NOT be a hand-typed list: such a list is stale the moment any of its members moves, and a recited figure is not a computed one.","scope_note":"gad-protocol only. atlas-orchestrator and waypoint are NAMED in the manifest, with a stated reason, and are NOT read, NOT hashed, and NOT touched: a graph that amended the specification and its constructor in one run would be the constructor editing its own referee. They are judged against this successor by their own governed runs."},"object":{"document":"docs/gad-formal-spec.md","identified_by":"byte digest of the frozen text, never by version label alone: a label is not an identity (spec Section 15, Object)","successor_digest":"20daf6004a8eb23344067f216e5f81c85b4ef998c249448fe5042110352dca81"},"predecessor_record":{"path":"succession/delta/succession-2.json","provenance":"sha256 of succession-2.json's bytes on disk at build time — the record-level chain link, computed and never transcribed. The lineage's continuity is verified by tools/succession-verify.mjs over the spec digests (each predecessor digest equal to the prior successor digest); this figure additionally binds WHICH record bytes this succession chained from.","record_digest":"0fe4fca85cdc676c22490851f3245b2e755133a5cc35a32f10027085f84e99fa"},"predecessor_spec_digest":{"commit":"db8726aff850f7d0ed164bec310212f00e62363b","digest":"07ba93975cfe6947ddc8b507ea4a2273e05039186567fb9333d42d97912c3f50","provenance":"succession 2's successor digest, read from succession/delta/succession-2.json rather than transcribed, which is what makes the chain continuous by derivation instead of by assertion. Those bytes are the blob at commit db8726aff850f7d0ed164bec310212f00e62363b, the last tree in which this document was v0.8; that blob was hashed and required to equal this figure before this record was written. NOT recomputable from this tree: v0.8's bytes left it when succession 3's spec bump was committed, and tools/succession-verify.mjs reports this figure as RECORDED, NOT VERIFIED rather than implying it rechecked it (REG-33's lineage rule).","recomputable_from_this_tree":false,"version_label":"0.8"},"record":{"cited_by":"docs/gad-spec-register.md","lives_at":"succession/delta/succession-3.json","rule":"The record of a specification succession lives in gad-protocol as a signed sidecar beside this document, and the companion specification register cites it. The register remains the channel through which this document learns that it must change; the succession is how it changes.","verified_by":"tools/succession-verify.mjs"},"record_type":"gad-spec-succession-delta","session_choreography":{"rule":"REG-48 (ruling rested July 16, 2026): verification is post-quiescence by the specification's own semantics; mid-session server verification exists only as advisory feedback, never as record entries.","what_happened":"This record was built and signed inside a MULTI-NODE SESSION with POST-SESSION verification: the executor claimed and submitted the ceremony node and exited; the recorded verdicts are the engine's, computed after quiescence over the captured delta. Producing this record under that choreography is an instance of the ruling, not the referee-valid live-choreography evaluation REG-48's entry still awaits (see successor_does_not_claim)."},"signature_scope":{"construction":"SIGN_x(obj) = {body: obj, signature: sig_x(canon(obj))}; the signature covers the canonical body and is never a member of it.","key":"the operator authority key (RUL-9, RUL-11 clause 2); public half committed at succession/keys/operator-pubkey.json, private half never in this repository","what_this_signature_ATTESTS":"that this delta's text and figures are the ones bound at signing time, and that they have not moved since; that the party who bound them holds a key whose private half has never entered this repository and which names an authority; and that the key was verified to DERIVE the committed public half before it signed — the derive-based standard this very amendment makes normative (REG-38), applied to its own signing moment. REG-38's checker is run over succession/ after signing and its computed zero is recorded in the exit-gate record beside this ceremony.","what_this_signature_DOES_NOT_ATTEST":"any registry identity beyond the named authority's custody of the key, and no claim that any implementation conforms to the successor. REG-14's key lifecycle DESIGN is rested by this very amendment (v0.9, Profile One), but its implementation remains post-v1.0 and the register entry stays OPEN tracking it; until that implementation lands, a compromised key is handled by succession, not in-place revocation — the interim rule, now stated in the specification rather than improvised at the incident. This is the third record that rule applies to."},"succession_number":3,"successor_does_not_claim":{"not_claimed":["IMPLEMENTATION CONFORMANCE. No implementation is claimed to conform to v0.9. In particular the key lifecycle this version designs (REG-14) has NO implementation — signed lifecycle entries, key_id supersession, and forward-looking revocation exist as design only, post-v1.0 by the ruling itself — and naming a design is not implementing it.","THAT REG-14 IS CLOSED. Its design half is rested by this amendment; the register entry stays OPEN and tracks the implementation. A record that read 'design rested' as 'closed' would be claiming work that does not exist.","THAT REG-48 IS CLOSED. Its ruling is rested and this very record was produced under the choreography it names, but the entry closes only when a live-choreography record evaluates fully referee-valid, and producing a record under the choreography is not that evaluation.","THE REG-47 RULING. The anchor-class question (an RFC 3161 token's WHEN versus an authority signature's WHO) awaits the operator's ruling and is not rested, restated, or prejudged here.","THAT REG-29's GENERATOR HALF CLOSED. The nine invalid fixtures still have no generator, exactly as succession 2 disclosed; the blessing stands and the generator remains future work.","ANY AUTHORITY OVER THE HISTORICAL RECORDS. Nothing recorded before this succession is reissued, recomputed, or re-read. v0.6's, v0.7's, and v0.8's history entries stand intact as fact, and succession 1's genesis disclosure is neither softened nor restated.","THE INDEPENDENT REVIEW IT STILL OWES. Section 1's results remain Propositions and Claims, not Theorems; independent formal and cryptographic review is still pending, and this succession did not perform it.","IDENTITY, VIA ITS SIGNATURE, BEYOND KEY CUSTODY. The signature proves that the holder of the operator key bound this text, and that the key derived the committed public half at the signing moment. What it binds beyond custody awaits REG-14's implementation, which this version designs and does not build.","THAT THE GENESIS PROBLEM IS SOLVED. Succession 1 disclosed it; this is the second succession that does not face it, which is not the same as solving it."],"statement":"The successor does not claim what follows, and says so here rather than leaving the boundary to be inferred from silence. v0.9 amends a specification and nothing else."},"successor_spec_digest":{"digest":"20daf6004a8eb23344067f216e5f81c85b4ef998c249448fe5042110352dca81","provenance":"sha256 of docs/gad-formal-spec.md as it stands in this tree, recomputed by tools/succession-verify.mjs against the bytes on disk. The version label is PARSED from that same document's header at build time, never recited, so the label cannot contradict the digest beside it (REG-35).","recomputable_from_this_tree":true,"version_label":"0.9"}},"signature":"3c4fe071efd9cb36b8a1a460d817c4d0c8584fe4bd31c68bbdbe257072d1471451c0f2495f89e02754ccaf1f1c8d8b23c3165c9fb66b182da72893e5d9b32709"}