UNI Universal Natural Intelligence

Wiki · Architecture & Decisions

PHASE 9 — RESUME POINT

Architecture & Decisions · docs/control-plane/RESUME.md @ 5c4b433688c9 (hierarchical-aif/motor-stack) — opens the published snapshot 3c078d47fbb5
2 values were removed from this page. Each one is marked in place as [redacted: category] 1 private address, 1 tailscale address. Nothing else was altered. The document is otherwise exactly as it is written in the repository, and the sha256 below is of the original, so what was ingested stays checkable.

How to read this page

Three ways to read this page. Precise is the document itself, exactly as it is written in the repository. Plain and Clear were written for this website to help you meet that document — they are about it. They are not it, and they are not evidence.

This is the design record of the part of the estate whose job is to stop the rest of it claiming more than it has measured. It runs to architecture notes, numbered decision records, phase plans, and the results written after each phase ran.

It is for anyone curious how a decision was actually reached — what was considered, what was refused, and what the refusal cost. The decision records are the most durable part: each names one choice, the alternatives, and the consequence accepted in exchange. The failure-modes page is worth the detour, because it states each refusal as something you could go and test rather than as a promise.

Read the architecture page first. It opens by declaring itself part design and part built, which sets the tone for the whole section. Then the first decision record, then whichever phase interests you — read as a pair, the plan and the results page written afterwards, including the phases where a premise turned out to be wrong and the receipt says so.

What it is not: a description of running software, and not a complete record. Three documents from this area were withheld from publication, because they describe private infrastructure or the operator declined them; they are listed as withheld rather than quietly dropped, so you can see that they exist.

Your browser cannot switch reading levels, so the document itself is shown.

Precise — the source document

This is the document. Rendered from the repository at the commit above, with nothing rewritten for the web. A gate re-renders it on every deploy and fails the build if a single byte differs.

Marked 2026-07-28. This file is corrected whenever it becomes false; a resume point that lies is worse than none. It had been false in every material clause since 2026-07-27 — see THE CORRECTION at the end, which is kept rather than deleted.

THE NEXT ACT

NEXT ACT: RESUME-THE-LIVE-FRONTS — AGENTS

Two live fronts, both agent work, both measured live since 2026-08-19: (1) the whiteboard defect programme -- docs/whiteboard/DEFECTS-AND-REPAIRS.md, every repair proven on the real engine before it ships; (2) the public University assembly -- labs, course, falsification wall and contribution surfaces served from the documentation estate, every page pinned to the commit it was read from. The checkpoint this key used to name was ruled out by the operator; see was.

Declared at docs/whiteboard/DEFECTS-AND-REPAIRS.md and the UNI.Public estate (the University routes). Blocked on: nothing -- both fronts accept agent work today; operator dependencies inside them (per-repair co-signs) are queued as they arise, and none gates the next step

Retired: L6 (Stage 4 step 4.6 -- build L6, THE GAUNTLET THEN THE CO-SIGN, shipped 6234f3d); CHECKPOINT-E (WITHDRAWN by operator ruling 2026-08-10: the two-image shot surface at the lab viewer was ruled a fatal hallucination -- never resurface it.).

The plan is the source of truth, not this file: UNI.Minecraft/evidence/remediation/phase9_plan.json. viewer/verify_plan_consistency.cjs holds it to its own vocabulary, because it had carried two different next acts at once — and since 2026-07-29 it also refuses a $.next_act that is absent or points backwards.

This section said "build L6" for six hours after L6 shipped at 6234f3d, and so did four other documents. It is generated now.

WHERE THE STAGES STAND

stage status detail
0 CONSERVE DONE 5/5
1 THE INSTRUMENTS DONE 9/9
2 THE RECORDER DONE 7/7 — closed by step 2.7, the operator's ruling of 2026-07-27
3 THE REFUSALS BLOCKED 5 DONE, 3.3 BLOCKED on the operator (the presence mint is S6)
4 THE UNRUN AND UNWIRED IN_PROGRESS 5 DONE; 4.6 IN_PROGRESS — every build DONE, waiting on Checkpoint E, which is the operator's
5 THE DOCUMENTS PLANNED 4 PLANNED + 1 OPERATOR. Last, always — editing a document to match a broken world closes the only signal telling the truth
6 THE FINAL RUN PLANNED 4 PLANNED + 1 OPERATOR

Plan: 7 stages · 43 steps (31 DONE · 1 BLOCKED · 8 PLANNED · 3 OPERATOR) · 7 builds under step 4.6, 7 DONE.

Step 2.7 was added during execution — a necessary repair, not an invention, and the register now records it as such.

MEASURED STATE

Gates: 36 registered, of which 33 ci:true and 3 ci:false (colony, hud, overlays — listed, never run, never a fabricated pass). 7 lab gates (lab-l0, lab-l1, lab-l2-shot, lab-l3, lab-l4, lab-l5, lab-l6).

Both numbers are stated because both were written before without saying which was which: one banner paragraph said 25 and another said 23, and a single file said 23 at one line and 25 at another. Neither was the registered count.

Gate ledger evidence/gates.ndjsonca8fd61ab5380994..., 212 rows / 112 unique names. Last row per name: 94 PASS · 5 PARTIAL · 12 PENDING · 1 FAIL.

The per-name tally is stated as such because the per-ROW tally is a different set of numbers, and a count whose derivation is unstated is how a backlog and the history of a backlog came to be reported as one word.

Registry vs. the canonical ledger: of 36 registered gates, 1 appear in evidence/gates.ndjson and 35 do not (0 of those carry a glob gate_row, which no kebab-case row can ever bear). gate_row.schema.json says every gate the project claims MUST be represented there.

The intersection is NOT empty, and four governing documents said it was. They declared "EVERY registered gate has ZERO rows" and "the intersection is empty by id and by gate_row" for two weeks after a row landed for one of them on 2026-07-17 — inside the paragraph that says these numbers are generated. It was hand-written. It is not any more.

Authoring the missing rows is S4 — the operator's, but the blocker is not his signature: desk.preRegistration() reports most of them blocked on an empty receipt_path the schema requires, which is a pre-registration document an agent owes him. He could not append them today even if he wanted to.

Control-plane ledger: 32 entries, tip b90b74980f47b93a... at seq 32. Anchor declares length 32, head b90b74980f47b93a...they agree.

Three things are deliberately NOT stated here, because no committed file can hold them honestly. They are facts about a run or about now, not about the tree:

question the command
Are the trees clean? git -C <tree> status -sb
Does the Elixir suite pass? mix test
Do the gates pass? node viewer/gate_runner.cjs

This banner used to answer all three. The gate-runner answer was measured at 06:01:09 on 2026-07-29 and was false by 06:04:06 — a half-life of 176 seconds — and it was committed reading as present tense. Run the commands.

Three gates are RED, and as of 2026-07-29 each reason is MEASURED, not inherited.

  • ip-fence — red by acceptance, confirmed. 8/8 self-checks PASS, 30 live literal(s) against an acceptance asking for ≥12: "a green fence here is a broken walk." Its M5 historical replay finds 34 uses on the pre-fix tree. Working exactly as designed.
  • host-tracking — 6 PASS / 1 FAIL, and the one failure is chip-names-resolve-via-dns: music -> [redacted: tailscale-address] via=declared, the name not answering so the stable overlay plane answers instead. On the operator's not_mine list. This description was HALF WRONG until today — the gate was failing two checks, and the second was no-chip-literal-in-consumer-code pointing at viewer/track/verify_track.cjs:109, a [redacted: private-address] inside the chip's real /24 planted by an agent in a fixture of addresses that must be refused. A mention, not a use — and the fence was right anyway, because nothing distinguishes a fixture from a hardcoded endpoint by inspection. Swapped to RFC 5737 documentation space; the TRACK gate still passes 7/7.
  • gate-attempts — 8/9, evidence/gates.ndjson hashes 1daac912… against a pin of 964ea25c… hardcoded in four places (so mix test is red too). Commit 2dcbfd2 legitimately appended a probe row carrying no pin update and no ledger entry. Advancing that pin is S4 — the operator's.

The lesson worth keeping: two of these three were described in the documents by inherited prose, and one of those descriptions understated a real defect authored by the agent that wrote the description.

This section used to state a test count, a gate-runner tally and "both trees clean". All three were deleted rather than corrected: they are facts about a run or about now, and the gate-runner one was measured at 06:01:09 on 2026-07-29 and false by 06:04:06 — 176 seconds — while committed reading as present tense.

WHAT MUST NOT BE SOFTENED

  1. The off-box witness is COMPROMISED — node2 accepts the writer's key, independent_custodians: 0. Tamper-evident, not unforgeable. Removing that key is S1.
  1. Most registered gates have no row in the canonical ledger — the count is in the generated block above, not restated here. This used to read "EVERY registered gate has ZERO rows... the intersection is empty by id and by gate_row"false since 2026-07-17. The row schema says every gate the project claims MUST be represented there. Appending is S4 — the operator's, but the blocker is NOT his signature: most rows are blocked on an empty receipt_path the schema requires, which is a pre-registration document an agent owes him. /lab/l5 prints each exact line.
  2. No verdict has yet been authored about a real scientific claim, and runs/pureworld_qa_gate.exs still raises @scaffold, so colony_on_program stays blocked.
  3. F31 is presence_evident, not unforgeable, and it binds this codebase's paths only. The OBS WebSocket on 127.0.0.1:4455 still has no authentication — S2, the operator's studio.

STILL OPEN, AND THE OPERATOR'S ALONE

  • ADR-0008 (human presence for go-live) is PROPOSED, not adopted — S5
  • the presence mint does not exist, so the airlock has no door — S6
  • truth_class is absent from the gate row schema, which is why the lab's floor is entirely fog — S5
  • S10 names a count and no members ("the nine PENDING science gates"): the scaffolded set is EIGHT, pending now is TWELVE, ever pending is FIFTY-NINE. Nothing can enforce it. Naming the nine is his.
  • whether the three CLAUDE.md RESUME banners are S5-exempt. Corrected 2026-07-28 on the reading that a block declaring itself "navigation and measured state only, it amends no law" may have its measured facts corrected without amending anything. Flagged for his ruling, not assumed closed.

THE CORRECTION — what this file said until 2026-07-28, and why it is kept

Every material clause was false:

  • "Present the ledger collision to Michael and get his ruling before touching Stage 2 again"resolved 2026-07-27 by step 2.7.
  • "Stage 2 is IN_PROGRESS, 5 of 6 DONE, 1 (step 2.6) marked DONE_WITH_DEFECT" — false on every clause, and DONE_WITH_DEFECT is not in the plan's status vocabulary at all, which is the error step 3.3's own status_correction field warns about.
  • "Stages 3–6 are unstarted, PLANNED" — Stage 3 is 5/6 DONE, Stage 4 is 5/6 DONE.
  • "mix test 1016 tests, 1 failure", "42 steps", "Gaia gate 12/12", "ledger.ndjson now 11 entries", "not a production caller yet (Stage 4 item 4.1)" — all superseded.
  • "the go-live guard is still a string comparison … F31 has no code and no test" — F31 has a guard, a gate and an operator's prover.
  • "The next act: … then move to Stage 3" — four stages stale.

It is kept because the failure is the lesson: this file has no gate. Nothing checks it, so it drifts silently, and the only defence is that whoever reads it verifies the numbers against the world first. The plan has verify_plan_consistency.cjs; this does not.

sha256 091940783f6e7cff — of the original file, so what was ingested stays checkable.

Plain — written for this website, not the source document

Written for this website — not the document. This is a plain-language retelling, written to help you meet the document. It is not the source, and it is not evidence. It has not yet been checked by a person. (or choose Precise in the reading-level control above)

Somebody arriving cold reads this to find out where the work stands and what to do next — that is what a resume point is for. It says of itself that it is corrected whenever it becomes false, because a resume point that lies is worse than none.

Much of it is generated rather than written, and the file explains why. Hand-written numbers in this project kept going stale — one next act was declared for hours after the thing had already shipped, and several documents repeated it. So the counts now come from the artifacts they describe.

Three things are deliberately not stated, with the commands to measure them given instead, because no committed file can honestly hold a fact about a run or about now. One such figure had a half-life of under three minutes and was committed reading as present tense.

The most useful section lists what must not be softened. An outside witness, compromised. An anchor that is not unforgeable. A contract proposed rather than adopted. And almost every registered gate still missing from the ledger that counts — corrected in place, because the file once said every one was missing and that had not been true for a fortnight. The last section keeps, rather than deletes, everything the file said while it was false.

Plain · written 2026-08-31 by claude-opus-5 · not yet checked by a person · about the document whose sha256 is 091940783f6e7cff

Clear — written for this website, not the source document

Written for this website — not the document. This is a clearer retelling, written to help you meet the document. It is not the source, and it is not evidence. It has not yet been checked by a person. (or choose Precise in the reading-level control above)

A resume point is the file a person or agent reads to find out where the work stands, what happens next, and what is still open. It says it is corrected whenever it becomes false, because a resume point that lies is worse than none — and that it had been false in every material clause for a period recorded at the end.

Its first section names the next act, generated from the plan rather than typed. The page is explicit that the plan file is the source of truth and this page is not. A checker holds the plan to its own vocabulary, because it had once carried two different next acts at once. And this section once declared the wrong next act for hours after the work shipped.

A table shows where each stage stands: most steps done, one blocked, several planned, and three with the operator - one a checkpoint his own later ruling withdrew, kept visible with how it ended. The declared next act is two working fronts open to agents. One stage is deliberately last, with the reason given — editing a document to match a broken world closes the only signal telling the truth.

The measured-state section is a series of generated blocks, each noting the error it exists to prevent. The gate counts are stated in two forms, because both had been written before without saying which was which. The ledger tally, only ever added to, is given per name and says so, because a count whose derivation is unstated is how a backlog and its history came to be reported as one word.

Then comes a block that answers nothing and lists commands instead: three facts about a run or about now that no committed file can hold honestly. It used to answer all three, and one answer was false again within minutes.

Three checks are reported red, each reason measured, not inherited. One is red on purpose: its acceptance criterion asks it to find things, and a green result there would mean the walk is broken. One fails on a name that does not resolve. The page records that its own description had been half wrong until recently, because the check was failing twice, the second failure authored by an agent writing a fixture. One fails on a digest that no longer matches a pin; advancing that pin is the operator's decision. The lesson is that two of the three had been described by inherited prose, one of them understating a real defect.

A section headed what must not be softened lists the standing adverse facts: the outside witness is compromised, the anchor tamper-evident rather than unforgeable. All but one registered gate is absent from the ledger that counts, though the schema says every one must be. The file is emphatic that it formerly said ALL were absent, which stopped being true when a row landed and stood uncorrected for two weeks. No verdict has yet been authored about a real scientific claim, and a guard binds this codebase's paths rather than the machine.

A further section lists what is open and the operator's alone. A proposed contract not yet adopted. A component that does not exist, so an airlock has no door. And a set named by a count with no members.

The final section keeps everything the file said while it was false, clause by clause, and explains why. This file has no gate, so it drifts silently, and the only defence is a reader who checks the numbers against the world.

Clear · written 2026-08-31 by claude-opus-5 · not yet checked by a person · about the document whose sha256 is 091940783f6e7cff