Skip to content

R0021 (legacy R33) — Semantic-preservation closure for package-budget optimisation: byte savings must not erase governed behaviour #161

Description

@theislampill

R0021 (legacy R33): Semantic-preservation closure for package-budget optimisation: byte savings must not erase governed behaviour

Classification and status boundary

Classification: owner-authorised, audit-derived tightening of package-budget closure and semantic consumer evidence. The underlying failure class is repo-generic for packaged .skill and software artefacts. Current incident evidence is IMPLEMENTAUDIT-local.

Milestone: Engineering-value discipline and proxy resistance. Specialised sibling: R0020 state-space convergence. General governors: R0022 engineering-value discipline and R0023 evaluator-mutation integrity.

Status: required capability work inside the active v0.3.3.3 train. It retains separate issue/PR ownership and does not authorise mutation of #117 or any published v0.3.3.0 tag, release, asset, or historical record.

Established: the repository enforces a finite package ceiling and minimum headroom; R001E source implementation merged within that budget and #157 remains open for composed release closure; the merged #144 lane encountered package pressure while editing governed references; existing controls cover bytes, membership, reachability, carrier replacement, checker integrity, and public projection in separate owners.

Unproved: that every text reduction changes semantics; that literal identity is necessary for every governed boundary; that one semantic-equivalence method works across repositories; or that this countermeasure has external validation beyond IMPLEMENTAUDIT self-dogfood.

External-validity and release boundary

The generic problem is a surrogate objective: an artefact can fit a byte or footprint limit while a required behaviour, consumer route, qualification boundary, or public explanation disappears. The inverse is also possible: safe deduplication or representational refactoring can preserve every consumer while changing wording.

Self-dogfood can demonstrate a contract and its controls on one .skill package. Milestone exit planning must additionally cover another .skill, an ordinary packaged software repository, and a parallel integration task. Until then, do not claim universal package-semantic protection, host compatibility, or ecosystem validation.

This issue does not change the release family or manifest version. The owner-authorised calibrated ceiling is the smallest whole-1,000-byte value preserving at least 2,000 bytes of headroom, capped at 230,000 bytes. It is 222,000 bytes for the exact 219,698-byte R001F candidate and must be recomputed from later exact packages, never treated as a consumption target.

Native IMPLEMENTAUDIT binding

Semantic-preservation closure belongs inside the existing package-failure or package-change audit object. It activates only when a package or footprint constraint is addressed by changing shipped content, moving an owner, changing a consumer route, or changing an evaluator that guards those semantics.

It must not create a detached package-audit mode, new marker family, universal literal registry, mandatory worksheet for non-package work, or a requirement to reread every shipped file after harmless byte changes. Ordinary work that does not touch package pressure or shipped semantic ownership takes no additional path.

Incident and residual gap

Failure class

A candidate becomes smaller or regains headroom, and every byte/member check passes, but the compression deletes, weakens, obscures, or moves a governed behaviour beyond the reach of its runtime, checker, generated documentation, or user-facing consumer. The metric says PASS while the engineering property regresses.

Package and headroom optimisation remains valid engineering. The defect is accepting the byte result without proving semantic preservation through authoritative owners and consumers.

Why current controls permit it

The residual is a triggered closure contract joining package pressure to protected behaviour, authoritative owners, consumer reachability, evaluator integrity, generated parity, and an explicit conflict route.

Concrete evidence and limits

Evidence Exact identity or locator What it supports Limit
Live package owner main ddae2fe111faa9b3cb8904f66e3e95c40865de5a, tree ed317e43c84d2f96aad4ab695403ac58b67c80c2; scripts/build-release-asset.sh; scripts/verify-package.sh; tests/release-asset.test.sh The repository has a canonical builder, complete verifier, package-member rules, an evidence-calibrated ceiling, and at least 2,000 bytes required headroom. These mechanical limits do not prove semantic preservation.
R001E package PR #159, head 2790cb364ea1a5f33d6118e91b9b60c3be8bfc5c, merge b860a3721bea2dfe7e43675426afc7b6685b1af0 215,987 bytes, 49 members, 18 helpers, zero /dashboard/ members, 2,013 bytes headroom, SHA-256 59d9f1665001d888dcf68a680b7802565797ff9a9b3d19830b8f3e60a19e32d1; package and hosted gates earned their cost. A fitting package is not evidence that every later compression preserves behaviour.
Merged #144 source lane reviewed head fd170321928d62de9b65197410e2b5010b3ee24d, tree ed317e43c84d2f96aad4ab695403ac58b67c80c2, merged as ddae2fe111faa9b3cb8904f66e3e95c40865de5a Repeated review of compressed governed references restored boundaries concerning embedded-language extraction, post-state comparison, narrow Capability Ledger entries, and custom-event authority. Recover exact review reports, pre/post blobs, and dispositions before treating an episode as accepted evidence; #144 remains open for composed release closure.
Current owner text skills/implementaudit/references/lean-operating-discipline.md, references/sidecars.md, references/repo-state-comparison.md, templates/PROTOCOL.md The affected material has runtime, optional-tool, authority, and evidence consumers beyond wording alone. This issue does not pre-decide which #144 text is final.
Closed/open owners #77, #85, #92, #136, #155, #157 Existing controls are complementary and should be reused. No single owner currently supplies the complete compression closure.

The named #144 phrases are incident locators, not a protected-literal allowlist and not a claim that their exact wording is always mandatory. The implementation campaign must compare authoritative pre-change and repaired blobs, review findings, fixture/checker consumers, package membership, and generated/public owners. Rejected or ambiguous examples stay in the evidence ledger.

No complete denominator is claimed for every package compression in R001E or #144. Build the population from exact diffs and review episodes before reporting rates or complete coverage.

Root cause and 5 Whys

  1. Why can a smaller candidate lose governed behaviour? The package gate measures bytes and members, while meaning is distributed across owner prose, routing, checkers, fixtures, generated docs, and installed use.
  2. Why does ordinary review not always catch it before compression closes? Review can focus on the immediate byte failure or checker-sensitive literals rather than enumerate consumers and protected behaviour first.
  3. Why can restoring a literal appear to solve it? A checker can use the literal as a proxy while the real owner and consumer semantics remain unrecorded.
  4. Why can the evaluator be changed instead? Package pressure creates an incentive to weaken or narrow the gate until the candidate passes.
  5. Why is this a meta-engineering defect? The process can optimise a visible budget without a closure postcondition for the engineering behaviour that the packaged content governs.

The weakest supported root cause is an absent semantic-preservation postcondition for package-driven content and evaluator changes. This issue does not infer deliberate gaming or claim that compression itself is defective.

Repo-generic invariant and proposed countermeasure

A package or footprint failure is not closed by a smaller artefact alone. When the repair changes shipped content, owner location, consumer reachability, or a guarding evaluator, closure must show that governed behaviour and every required consumer remain equivalent or are explicitly re-authorised.

Activation factors

Activate the progressive semantic-preservation path when one or more apply:

  • a package/headroom failure is repaired by editing shipped prose, templates, schemas, scripts, or fixtures;
  • required content moves between always-loaded and progressive owners;
  • package membership or installed paths change;
  • a checker, fixture, threshold, protected literal, or golden is changed because the compressed candidate fails;
  • generated or public documentation is shortened to follow an implementation compression;
  • a required behaviour becomes reachable only through a new helper, route, or optional tool.

Do not activate the full path for whitespace-only archive differences, compression-algorithm changes with byte-identical extracted members, or ordinary non-package work unless a consumer or semantic owner also changes.

Minimal semantic-preservation record

Reuse the existing package finding/evidence row. Record:

  1. exact before/after package identity, size, members, headroom, and changed blobs;
  2. change class: non-semantic compression, representational refactor, owner move, semantic edit, evaluator repair, or unresolved;
  3. governing behaviours at risk, expressed as owner-backed predicates rather than an accumulating literal list;
  4. authoritative owner for each predicate and every runtime, checker, installed, generated, or public consumer;
  5. reachability and parity evidence after the change;
  6. changed tests/checkers and an independent justification tied to the underlying contract;
  7. unresolved semantic disagreement and its architecture, calibration, or owner-decision route;
  8. rollback that restores semantics without weakening the byte gate.

Allowed closure routes

  • Harmless compression: extracted members and consumer predicates are unchanged.
  • Equivalent refactor: wording or representation changes, but owner-backed predicates and consumers are proved equivalent.
  • Progressive split: content moves to a smaller on-trigger owner that is shipped, reachable, tested in the same run, and projected publicly where required.
  • Architecture change: ownership or package layout changes under explicit authority with migration and rollback.
  • Calibration or owner decision: an irreducible conflict is recorded rather than converted into a false PASS.

Deleting or weakening required semantics, hiding them in an unshipped or unreachable owner, or changing the evaluator merely to accept the candidate is not a closure route.

Anti-literal-gaming rule

Exact literals remain binding where a parser, checker, public promise, canonical event token, or interoperability contract proves they are the owner. Elsewhere, the protected unit is the owner-backed behaviour and consumer chain. A changed literal must neither fail automatically nor pass automatically. Adjudicate it with pre/post predicates, consumers, and discriminating controls.

Why this improves the skill

The package budget continues to constrain bloat, while agents lose the option to satisfy it by erasing the reason a reference, route, or boundary exists. This is useful to other .skill authors because .skill packages combine executable helpers, progressive instructions, checkers, and public documentation in one footprint. The same principle can apply to ordinary software bundles and constrained deployment artefacts.

Transferability remains a hypothesis until the milestone's external-validity plan is exercised.

No regression and no tech/process bloat

Preserved patterns

  • The current byte ceiling and minimum headroom remain authoritative.
  • Safe whitespace, deduplication, archive compression, and equivalent refactoring remain legal.
  • Exact checker-sensitive literals remain protected when a parser, checker, public promise, event token, or interoperability contract consumes their exact bytes.
  • R001E helper reachability, package membership, /dashboard/ exclusion, installed-runtime dogfood, R001D public projection, and generated-owner parity keep their existing authority.
  • An irreducible conflict may reach an owner decision; the gate does not invent package space.

Cheap non-trigger path

No package pressure, shipped semantic owner change, consumer move, or evaluator change means no semantic-preservation record. For a demonstrably non-semantic archive change, exact extracted-member equality plus the existing package suite is sufficient.

Progressive placement and measured cost

Place detailed guidance in the nearest existing progressive package or repo-state owner. Add a compact routing clause only if testing shows agents otherwise miss the activation factors. Do not add a universal protected-string registry, duplicate package manifest, detached worksheet, or model call for mechanical cases. Measure source bytes, package bytes, bootstrap reads, additional runtime, fixture count, and false-positive cost.

Alternatives considered

  • Protect a growing list of phrases: rejected because it optimises another proxy and misses paraphrased semantic loss.
  • Raise the ceiling: not authorised and does not solve semantic closure.
  • Let complete verification decide: insufficient when the verifier itself lacks a consumer or relation.
  • Require model review for all compression: rejected for privacy, spend, determinism, and ordinary-run cost.
  • Use R001D alone: insufficient for internal behaviour that must be identified before public projection.
  • Forbid prose compression: rejected because safe compression and progressive disclosure are legitimate engineering.

Integration and solution plan

  1. Re-anchor main, Retrospective: scoped Graphify catalog and scope-bound freshness #144, R001D (legacy R29) — Public capability-projection completeness - release dogfood must derive and disposition material README/docs topics, not merely prove parity or reject stale claims #155, R001E (legacy R30) — Shipped-helper reachability and applicability - every packaged checker must have a tested dispatch path or an explicit advisory boundary #157, package owners, release identity, and all current ceiling/headroom controls. Recover the exact R001E/Retrospective: scoped Graphify catalog and scope-bound freshness #144 compression population from diffs and review artefacts.
  2. Build a consumer/protected-behaviour census before altering any package text. Distinguish exact-literal owners from semantic predicates and record ambiguous cases.
  3. Add the smallest progressive closure rule to an existing owner. Reuse the native finding/evidence row and package verification path. Do not create a parallel package mode.
  4. Add deterministic package fixtures for membership, reachability, extracted equality, evaluator mutation, and progressive splits. Use a bounded prompt-independent semantic review cell only for cases where owner-backed equivalence cannot be decided mechanically.
  5. Edit source owners, then regenerate derived docs. Run focused tests, package builder/checker, complete verifier, temporary-home installed-runtime and ordinary-run dogfood, R001D public-projection parity, and exact-tree independent review.

Likely owner paths must be re-censused before mutation:

  • scripts/build-release-asset.sh
  • scripts/verify-package.sh
  • tests/release-asset.test.sh
  • tests/release-asset-install.test.sh
  • scripts/check-package-shape-claims.sh and its tests where applicable
  • scripts/check-helper-reachability.sh only for moved/new helpers
  • the nearest progressive owner under skills/implementaudit/references/
  • validation registry and hosted workflow only if a new required check is introduced
  • README, changelog, release notes, and generated portal owners through R001D where affected

Rollback restores the last semantically complete owner blobs and consumer routes, regenerates derived output, and re-runs the unchanged package ceiling. It must not make the package pass by weakening the gate. If restored semantics no longer fit, the correct state is a package failure plus architecture/calibration/owner-decision routing.

Any new shipped helper or checker must satisfy R001E reachability, same-run dispatch, package membership, and negative controls. Do not add a checker merely to count sections or protected words.

Smoke and evaluation design

Cell Expected result Property protected
Candidate is under the byte ceiling but loses a governed semantic boundary FAIL Bytes cannot substitute for behaviour.
Whitespace, deduplication, or non-semantic compression with unchanged extracted consumers PASS Safe optimisation remains cheap.
Checker-sensitive literal changes while owner predicates and every consumer remain equivalent Bounded adjudication, not automatic failure Literal proxies do not become the product.
Test/checker is weakened merely to accept the compressed candidate FAIL Evaluator gaming is rejected.
Required content moves to an unshipped or unreachable owner FAIL Package fit cannot be bought with lost reachability.
Safe progressive split ships the owner, dispatches it in the same run, and preserves public projection PASS Progressive disclosure remains available.
Irreducible headroom conflict Architecture, calibration, or owner-decision route; no PASS Conflict stays visible.
Ordinary non-package work No semantic-preservation audit Unrelated work pays no tax.
Exact phrase retained but its consumer route is removed FAIL Literal preservation alone cannot game the gate.
Phrase removed and checker patched, but a held-out behaviour probe still fails FAIL Checker repair must follow the contract.
Equivalent refactor passes known checks but fails a novel consumer probe FAIL Known-fixture overfitting is caught.
Archive algorithm changes while extracted file bytes and metadata policy are equal PASS on mechanical proof Model judgement is not invoked unnecessarily.

Mechanical cells should use archive manifests, hashes, owner/consumer enumeration, installed file existence, dispatch traces, public-doc generation, and paired negative fixtures. If semantic equivalence remains genuinely judgement-shaped, use one bounded prompt-independent model cell with the target wording and intended verdict omitted, expected predicates and distractors declared out of band, backend/model and privacy/spend recorded, and every conclusion checked against authoritative owners.

Acceptance criteria

ID Criterion Required evidence
R33-A1 Compression incident population is exact and bounded. Pre/post commits or blobs, review locators, included/excluded/ambiguous census, package identities, and no unsupported complete claim.
R33-A2 Current package policy is preserved unless separately authorised. Diff and test evidence showing the 218,000-byte ceiling and 2,000-byte minimum headroom remain unchanged, or a separate owner decision.
R33-A3 Activation and cheap non-trigger paths are explicit. Fixtures for package-driven semantic edit, harmless extracted-equal change, and ordinary non-package work.
R33-A4 Protected behaviours are owner-backed, not a literal accumulation. Consumer/protected-semantics record mapping predicates to authoritative source, runtime/checker/installed/generated/public consumers, and literal-owner exceptions.
R33-A5 Under-budget semantic loss fails. Negative fixture with a fitting package and a missing governed boundary.
R33-A6 Safe compression and equivalent refactoring pass. Whitespace/dedup/extracted-equality fixture plus a wording-change fixture with unchanged consumer predicates.
R33-A7 Evaluator gaming fails. Paired mutation where a test/checker is weakened to accept a known-bad compressed candidate.
R33-A8 Reachability and progressive splitting are discriminated. Unshipped/unreachable-owner negative fixture and shipped, same-run reachable progressive-owner positive fixture; R001E evidence where helpers apply.
R33-A9 Irreducible conflict cannot become a false PASS. Fixture or dogfood cell producing architecture/calibration/owner-decision disposition with package failure preserved.
R33-A10 Owner-source and generated/public parity hold. Source edits followed by generation; zero hand-edited derivatives; README/docs/changelog/release disposition through R001D; semantic parity checks.
R33-A11 Package and installed runtime are fully qualified. Exact package bytes, members, headroom, digest, /dashboard/ exclusion, complete verifier exit 0, fresh temporary-home install, ordinary-run behaviour and negative controls.
R33-A12 Judgement is bounded and non-authoritative where required. Deterministic sufficiency evidence or one prompt-independent model cell with backend, privacy/spend, expected values, distractors, and owner verification.
R33-A13 Added process cost is measured and justified. Source/package/bootstrap cost, activation rate in the incident corpus, false-positive controls, cheaper-alternative disposition, and stop/retirement condition.
R33-A14 Exact-tree independent review passes. Fresh reviewer attestation bound to source tree, package digest, semantic record, fixtures, generated/public output, and rollback.
R33-A15 Issue closure is evidence-bound. Non-closing PR link, issue evidence comment, exact merged main/tree and hosted readback, every criterion disposed, remaining risk recorded, then manual closure.

Overlap, dependency, topology, and provenance

Pair with R0020: distinct invariant, shared package/public owners. Disjoint semantic-owner and convergence-owner cells may proceed in parallel. Exact writes to package builder, verifier, validation registry, workflow, README, changelog, or generated docs must be serialised or composed once. If R0020 creates footprint pressure, R0021's semantic-preservation rule must be present before accepting compression. Final complete verification and installed dogfood run once on the composed exact tree, with proportionate reruns after any relevant byte change.

Why not merge: R0021 applies to package compression with no repeated false pass. R0020 may qualify or reject convergence without any package change. Separate work orders preserve rollback, ownership, evidence, and independent closure.

Provenance: owner-authorised publication derived from the process-ceremony and reward-hacking challenge, live package and issue owners, PR #159's exact package receipt, and active #144 incident evidence. The audit and owner summary are explanatory sources, not substitutes for exact pre/post blobs and consumer evidence.

Definition of done

R0021 is done only when each acceptance row has evidence on the exact merged source tree and candidate package; semantic-loss, safe-compression, evaluator-gaming, unreachable-owner, progressive-split, conflict-route, ordinary-work, applicable R0022 control-value, and R0023 evaluator-mutation controls pass; installed and public consumers are read back where affected; exact-tree independent review passes; and the issue carries an evidence comment followed by manual closure readback.

A smaller package, green byte check, restored literal, changed checker, or completed census is insufficient by itself. A narrower design or NO ADOPTION result remains valid if the measured permanent cost exceeds the protection, provided current package semantics are restored, the byte failure remains truthful, and the decision and residual risk are preserved.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions