feat(truth): the truth ledger — every claim carries its proof #5534
ccantynzAI Reviewcommented 6d ago
AI Triage
(no summary)
Priority: medium Risk area: mixed
Suggested labels: (no label suggestions) Suggested reviewers: (no reviewer suggestions)
Suggestions only — nothing has been applied. The PR author stays in control.
gluecron[bot]🤖 botAI Reviewcommented 6d ago
AI review unavailable
The platform's AI balance is exhausted, so AI generation is temporarily unavailable. Nothing was lost. You can queue this as a repair for the internal agent from the repository's Health page, or try again once the balance is restored. The PR is otherwise unchanged.
Cross-repo impact
See what breaks downstream if this PR merges.
⮌ Merged
This pull request was merged into main.
c comment · e edit title · m merge · a approve · r request changes · ? shortcuts
Mission Control build #1 — the keystone (agent-built, coordinator-integrated)
32 claims, each with its verification method — 13 db-predicates, 7 spine-check readers, 2 live probes, 6 test-artifact (marked weak), 1 host-capability (SSH renders verified-as-disabled, honestly), 2 env-presence (unset paging webhook = failed, because alerts reaching no one is a failure), 1 honest
none. Hourly evaluation via autopilot task, history intruth_evaluations(migration 0128, 90-day self-pruning), board at/admin/truthwith state pills and method chips.The founding claim is in: "repository mirroring enabled" is a live db-predicate — zero enabled rows renders failed on the board, exactly the condition the old scorecard's ✅ concealed for weeks.
Product findings from the build (the unverifiable list is a work queue): backups/restore drills leave no in-app evidence (host-filesystem markers only — a drill-result POST endpoint is the fix); the readiness gate records its runs nowhere the app can read; LFS has no transfer ledger. Each is a future claim upgrade.
Design notes worth keeping: persistent honest reds don't spam the autopilot task (they render, they don't page hourly — the doctrine's anti-noise rule); conditional zero-row capabilities (signed commits, provenance) read
unverifiable, notfailed— claiming failure on never-exercised would itself be the false positive we forbid.35/36 tests (1 DB-gated), typecheck clean, design-audit adds zero literals.
🤖 Generated with Claude Code