{"schema":"veilos.promises-ledger.v1","ok":true,"counts":{"total":13,"pending":4,"standing":3,"upheld":0,"kept":5,"overdue":0,"broken":0,"released":0,"undischargeable":1,"unknown":0},"human_twin":"/promises","text_integrity":{"schema":"veilos.obligation-text-integrity.v1","whole":true,"edited_fields":0,"edited_promises":0,"fields_watched":10,"edited":[],"basis":"every registered promise is published in full — no field reached its bound"},"promises":[{"id":"node-only:veil/crossing.mjs","status":"pending","reason":"due at S350; currently S342","due":{"kind":"session","value":350},"standing":false,"citation":null,"external":false,"discharge":"entry removed from NODE_ONLY_MODULES, or recheckSession advanced with a decision","decision":"D-S300.13","owner":"founder","promise":"Recheck the owned gap in veil/crossing.mjs: the Phase-0-manifest-pinned crossing entry point; engine.crossVeil (its only implementation) is Node-lane-only, so no veil crossing is ever policy-evaluated or recorded at the edge. Whether to build an edge policy-evaluation twin (receipts, quarantine, telemetry with real traffic) is a product decision, not a refactor.","truncated":{}},{"id":"record:no-control-characters","status":"standing","reason":"no end date — upheld continuously by tests/s260-carrier-and-vocabulary.test.mjs; this lane cannot watch it run","due":null,"standing":true,"citation":"tests/s260-carrier-and-vocabulary.test.mjs","external":false,"discharge":"tests/s260-carrier-and-vocabulary.test.mjs control-character ratchet over the record surfaces","decision":"D-S260.8","owner":"agent","promise":"Record prose is written with the editor or via a file, never through shell interpolation — PowerShell reads the backtick as an escape introducer and eats the first character of every Markdown code span. D-S250.32 promised this in prose and it recurred ten sessions later.","truncated":{}},{"id":"parity:unbacked-claims-shrink","status":"standing","reason":"no end date — upheld continuously by tests/s250-parity-claims.test.mjs; this lane cannot watch it run","due":null,"standing":true,"citation":"tests/s250-parity-claims.test.mjs","external":false,"discharge":"tests/s250-parity-claims.test.mjs BASELINE_UNBACKED monotone ceiling","decision":"D-S250.59","owner":"agent","promise":"Every comment claiming parity with a named module or symbol must actually READ that counterparty; the population that does not is debt and may only ever shrink.","truncated":{}},{"id":"upstream:writeback-currency-root","status":"pending","reason":"undated promise — recorded, never judged","due":null,"standing":false,"citation":"vaultspark-studio-ops:scripts/check-writeback-currency.mjs","external":true,"discharge":"upstream scripts/check-writeback-currency.mjs resolves root from git or cwd","decision":"D-S260.4","owner":"founder","promise":"The control plane's write-back currency probe resolves its repository root from its own module path and can therefore only measure studio-ops. The corrected resolution was shipped as Ark cargo so every sibling can inherit it; VEILOS no longer waits on it.","truncated":{}},{"id":"outward-claim:every-crossing-is-policy-evaluated","status":"kept","reason":"discharged by either an edge twin evaluates crossings, or the ip.mjs sentence is rewritten to describe what production actually does — asserted by tests/s262-ip-doctrine-grading.test.mjs, which drives the live renderer in both states","due":{"kind":"session","value":265},"standing":false,"citation":"tests/s262-ip-doctrine-grading.test.mjs","external":false,"discharge":"either an edge twin evaluates crossings, or the ip.mjs sentence is rewritten to describe what production actually does — asserted by tests/s262-ip-doctrine-grading.test.mjs, which drives the live renderer in both states","decision":"D-S261.3","owner":"founder","promise":"src/worker/ip.mjs publishes, to the public: \"Every crossing is policy-evaluated and produces a signed verdict; nothing crosses unwitnessed.\" That is FALSE in production. crossVeil — the only implementation of the faculty — is Node-lane only, so no crossing at the edge is ever policy-evaluated, no verdict is ever signed, and state.veilCrossings is permanently empty. The sentence is not aspirational phrasing; it is stated in the present tense as a property the organism has. This is the outward-claim class (D-S256.7) on a live public surface, and it is the same defect S256 fixed on the front-door h1 — a claim the organism's own machinery grades false, published as though earned.","truncated":{}},{"id":"veil:edge-trigger-decision","status":"kept","reason":"discharged by a trigger is chosen and recorded as a decision, or the faculty is retired — asserted by tests/s268-edge-veil-crossing.test.mjs, which drives the recorder and reads the live handler","due":{"kind":"session","value":270},"standing":false,"citation":"tests/s268-edge-veil-crossing.test.mjs","external":false,"discharge":"a trigger is chosen and recorded as a decision, or the faculty is retired — asserted by tests/s268-edge-veil-crossing.test.mjs, which drives the recorder and reads the live handler","decision":"D-S261.4","owner":"founder","promise":"Decide what edge event constitutes a veil crossing, so the faculty can reach production. S261 proposed shadow mode (evaluate and record, deny nothing) as a way to convert the enforcement question into a measurement — and that proposal was too strong, which is recorded here rather than quietly dropped: shadow mode still requires a TRIGGER, and choosing the trigger is precisely the product decision D-S251.1 declined to make silently. Building the twin before that choice would ship an inert primitive, the most recurring defect class in this record, which the edge-reachability sentinel would correctly red.","truncated":{}},{"id":"budget:veil-crossing-byte-funding","status":"pending","reason":"due at S350; currently S342","due":{"kind":"session","value":350},"standing":false,"citation":null,"external":false,"discharge":"either veilCrossings gains a funded maxBytes with the source of those bytes named, or the ring is documented as permanently entry-bounded and its residual cost accepted by measurement","decision":"D-S300.14","owner":"agent","promise":"veilCrossings ships entry-bounded (150) with its BYTES abstaining, because S214 #3 rightly refuses a measured basis without a maxBytes, and funding one would either grow an invariant already 1,166,062 B over the wall or take reach from another ring. A real row measures 517 B, so the ring's realistic ceiling is ~77,550 B and it currently lands in the unbudgeted residual. Through S297 this promise said that residual was over-reserved and therefore that \"the honest funding source likely exists\". S298 measured it in the reserve's own denomination and it does not: the residual is BREACHED, so funding this ring out of it would spend bytes the organism has already overdrawn. The live authority is census.residual_verdict on /_health, which re-decides this on every read — fund from that, never from a figure typed into this sentence.","truncated":{}},{"id":"upstream:test-live-state-annotation-scan","status":"kept","reason":"discharged by the upstream owner either fixes the scan's comment detection or the annotation contract is restated so a fixture string cannot satisfy it; VEILOS observes, and does not patch a propagated file in place","due":{"kind":"session","value":303},"standing":false,"citation":"vaultspark-studio-ops:scripts/lib/test-live-state.mjs","external":true,"discharge":"the upstream owner either fixes the scan's comment detection or the annotation contract is restated so a fixture string cannot satisfy it; VEILOS observes, and does not patch a propagated file in place","decision":"D-S293.11","owner":"upstream","promise":"scripts/lib/test-live-state.mjs states a placement claim — that its annotation scan must treat the annotation as a COMMENT rather than as text appearing inside one, found 'on the first full-suite run after this shipped' against tier1-test-ambient-state.mjs:14, which holds the annotation inside a string literal as its own fixture. The claim is registered here rather than suppressed because the calibrated sweep caught it correctly: it arrived in a studio-ops propagation drop during S268, so it is UPSTREAM-owned code making a dated-shaped promise inside this tree. Registering it keeps the sweep honest without editing a file this repo does not own — the fix, if one is needed, belongs upstream as Ark cargo (D-S250.48).","truncated":{}},{"id":"veil:edge-enforcement-decision","status":"pending","reason":"due at S350; currently S342","due":{"kind":"session","value":350},"standing":false,"citation":null,"external":false,"discharge":"either an edge policy that can return a non-allow verdict is enforced with signed receipts, or the deny branch is retired and the rate limiter is documented as the whole enforcement story","decision":"D-S290.11","owner":"founder","promise":"Decide whether the edge crossing policy should gain teeth that can genuinely refuse or quarantine a passage, beyond the rate limiter that is its only refusal today. S268 closed the RECORD half of D-S261.4 and deliberately did not answer this: denying a crossing turns a real person away at the front door, so the rules must be ones the founder wants enforced. Recorded now because the record half made the gap precise — evaluateCrossingPolicy's own deny branch is currently UNREACHABLE (checkCrossingRate 429s first), so the edge policy is a judgement that cannot refuse. That is a coherent state to stay in; it is not a coherent state to leave undecided by accident.","truncated":{}},{"id":"release:responsive-evidence-reason-split-enumerates","status":"kept","reason":"discharged by the reason classification is derived rather than enumerated, with deploy.mjs's refusal verified BEFORE the suite is relaxed and asserted after — asserted by tests/s263-responsive-reason-classification.test.mjs","due":{"kind":"session","value":266},"standing":false,"citation":"tests/s263-responsive-reason-classification.test.mjs","external":false,"discharge":"the reason classification is derived rather than enumerated, with deploy.mjs's refusal verified BEFORE the suite is relaxed and asserted after — asserted by tests/s263-responsive-reason-classification.test.mjs","decision":"D-S262.2","owner":"agent","promise":"D-S259.3 split responsiveEvidenceCurrent by REASON rather than force-greening it, and that was right. But it enumerated ONE tolerable reason — build_sha_mismatch — and a second reason that is equally deploy-gated sits outside the classification. S262's suite reds on verified_at_stale: the cached capture has simply aged out, and only a fresh Playwright run against a real deploy can clear it. That is the S260 keystone once more — a split classifies, and an unclassified member falls to the default side. It is left as a NAMED honest red rather than widened in a hurry at the tail of a long session, because relaxing a release tolerance without first verifying deploy.mjs still refuses is how a decoy gets built inside a fix (S251's lesson about S250).","truncated":{}},{"id":"guard:parity-scan-has-no-quote-rule","status":"kept","reason":"discharged by parityScan gains a quote-disqualifier with a control proving a quoted claim does not red and an asserted one still does — asserted by tests/s263-parity-quote-rule.test.mjs","due":{"kind":"session","value":268},"standing":false,"citation":"tests/s263-parity-quote-rule.test.mjs","external":false,"discharge":"parityScan gains a quote-disqualifier with a control proving a quoted claim does not red and an asserted one still does — asserted by tests/s263-parity-quote-rule.test.mjs","decision":"D-S261.7","owner":"agent","promise":"The parity guard reads a QUOTED example of a parity claim as a real claim. Found live at S261: a comment in src/core/obligations.mjs quoting an illustrative claim reddened the guard, because the claim form is verbatim identical whether it is asserted or merely recounted. This is the same blind spot D-S260.7 fixed in the production-claim predicate, where the rule adopted was that a quotation mark immediately before the phrase disqualifies it — tense frees the paraphrase, quoting frees the verbatim. The parity guard has the tense half and not the quoting half, so a record cannot yet discuss its own parity claims without re-asserting them. Worked around at S261 by rephrasing rather than by fixing the guard, which is the weaker move and is recorded as such.","truncated":{}},{"id":"placement:coherence-gate-runs-last","status":"standing","reason":"no end date — upheld continuously by tests/s258-production-sha-carriers.test.mjs; this lane cannot watch it run","due":null,"standing":true,"citation":"tests/s258-production-sha-carriers.test.mjs","external":false,"discharge":"tests/s258-production-sha-carriers.test.mjs asserts steps.at(-1) === 'closeout:coherence' against the autopilot's own parsed step list","decision":"D-S258.3","owner":"agent","promise":"The closeout coherence gate runs LAST, on the final tree, right before commit — a claim stated in three files at once, and false for seventeen sessions (D-S258.3): the gate was on none of the autopilot's eleven steps while every one of those three comments said it ran.","truncated":{}},{"id":"founder:outward-claim-class","status":"undischargeable","reason":"no discharge predicate — this promise is recorded but nothing can decide it","due":null,"standing":false,"citation":null,"external":false,"discharge":null,"decision":"D-S256.7","owner":"founder","promise":"THE OUTWARD CLAIM CLASS — scope decision remains founder-owned and unstarted.","truncated":{}}]}