Skip to content

docs(sds): withdraw the refuted 'structurally blocked' Co-Authored-By claim - #374

Open
wshallwshall wants to merge 9 commits into
mainfrom
provenance-claim-fix
Open

docs(sds): withdraw the refuted 'structurally blocked' Co-Authored-By claim#374
wshallwshall wants to merge 9 commits into
mainfrom
provenance-claim-fix

Conversation

@wshallwshall

Copy link
Copy Markdown
Collaborator

Withdraws a refuted claim from Secure_AI_Development_Standards 6.7. 2 files, +92 -43.

The doc asserted that Co-Authored-By trailers were structurally blocked. The 2026-07-29 count
was right; the prediction was not -- 15 trailer-bearing commits merged between 2026-07-30 and
2026-08-09
. So the claim is falsified by the record.

Also withdraws a phantom compensating control, and retargets the drift guard that was requiring the
document to keep asserting the refuted cause
-- a guard enforcing a false claim is worse than no
guard, because it makes the correction fail CI.

This is a truth-repair on a security standard, in the direction of claiming less. Armed.

… disprove it

The 2026-07-29 measurement in section 6.7 was CORRECT when taken: zero
`Co-Authored-By` trailers and zero `Tier:` lines in the last 300 commits. What
was wrong was the prediction attached to it -- that the trailer was
"structurally blocked" because cla.yml allowlists three identities and `cla` is
a required context, so "adding the trailer reds a required context and blocks
the merge."

Re-measured 2026-08-13: 15 commits on origin/main carry the trailer (77 trailer
lines; a squash merge concatenates the bodies it absorbs), all dated 2026-07-30
to 2026-08-09 -- the first landing the day AFTER the claim was written. They
merged through ordinary numbered PRs. Whatever the CLA action reads to decide
who must sign, it is not this trailer, and the merge gate never fired. `Tier:`
lines remain at zero.

The conclusion is unchanged -- the trailer is still not Built and still not A.4
evidence -- but the reason is now the honest one: unprescribed, unenforced, and
intermittently present anyway across an eleven-day window nobody recorded. That
is worse evidence than a clean zero, not better.

Also withdraws a compensating control that never existed. The A.6 deviation
cited "the PR template's AI/tier declaration"; .github/PULL_REQUEST_TEMPLATE.md
has What this changes / Type of change / Checklist and no such field. Naming a
control that does not exist is the SDS-3.7 defect this document defines, and a
deviation register is exactly where it does the most damage.

The drift guard needed the same correction, for the same reason. It asserted
that section 6.7 states the CAUSE, matching /block|reds\b|red the/ -- so the
test was the mechanism REQUIRING the document to keep asserting a refuted
claim, and it passed green throughout the eleven days those commits were
merging. It now pins the discipline instead: state the status, carry a DATED
measurement, and do not restate the withdrawn cause. Its companion test was
renamed off the same claim; it only ever proved the allowlist exists.

The refuted phrase is quoted in backticks where the document withdraws it, and
the check strips inline code before searching -- a withdrawal has to name what
it withdraws. That is CLAUDE.md section 11's own rule for quoting a term
without adopting it, and the same code-span strip scripts/docs/link_check.py
already uses.
@wshallwshall
wshallwshall enabled auto-merge (squash) August 13, 2026 16:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant