PTV-SCF-0001 P1 — verification round
Date: 2026-08-12 Status: closed — countersigned 2026-08-12 Supersedes: none Superseded-by: none — current Phase: PTV-SCF-0001 P1 · Specification Terminal state of this record: a classified friction list. This record does not close P1. Closing is G-03 and its preconditions include this record being merged.
Context
Section titled “Context”P1’s task list is discharged: estate.yaml and its generator exist, checks.yaml
unifies the three check ID spaces, a domain module exists per registered slug, the
SDD carries its amendments, and PTV-SR-0015 has a ratification record awaiting
countersign. This is the round that asks whether the gates actually pass.
Run in the G-02 shape (docs/PETROVA-GOLDEN-PROMPTS.md §3): gates evaluated
against cited evidence, friction surfaced, every surfaced item classified. A round
that surfaces nothing was not run properly.
Part A · Gate evaluation
Section titled “Part A · Gate evaluation”P1’s exit gate, verbatim from docs/specs/2026-08-12-ptv-scf-0001-scaffold-rev-a.xml:
estate.yaml parses. Generator is deterministic across two runs. Every DR traces to at least one SR. Every SR traces to root (SR-0001 or SR-0002) or is reclassified. Every requirement carries exactly one verification method.
Five assertions. Three PASS, two FAIL.
| # | Gate | Verdict | Evidence |
|---|---|---|---|
| 1 | estate.yaml parses | PASS | loadEstate() parses it on every run of host/tests/estate.test.ts; 16 tests, all green. Parsing is also a precondition of gates 2 and the diagram build, so a regression here fails four other things first. |
| 2 | Generator deterministic across two runs | PASS | estate.test.ts renders twice and compares; npm run estate:generate -- --check re-renders and compares byte-for-byte against the committed docs/diagrams/PTV-DWG-0002.mmd. Same code path as the write, so the checker cannot drift from the generator. Nothing in the generator reads a clock, a random source, or an unordered map. |
| 3 | Every DR traces to at least one SR | FAIL | PTV-DR-3104 carries no traces edge in the TRACEO requirement diagram (docs/PETROVA-SDD-BASELINE.md §6.2). Eleven of twelve authored DRs trace; one does not. |
| 4 | Every SR traces to root, or is reclassified | FAIL | Six of fourteen do not reach PTV-SR-0001 or PTV-SR-0002, and none of the six is reclassified. Detail below. |
| 5 | Every requirement carries exactly one verification method | PASS | All fourteen SRs and all twelve authored DRs carry exactly one verifymethod. One qualification, recorded rather than waived: PTV-SR-0015 carries none, because it is not yet in the catalogue — it is a proposed requirement with an uncountersigned ratification record, so gate 5 does not reach it. |
Gate 4 in detail — six orphaned SRs
Section titled “Gate 4 in detail — six orphaned SRs”The relation set in §3 is:
0001 contains 0005 0001 contains 0006 0002 contains 00070002 contains 0008 0005 derives 0012 0003 derives 00060009 derives 0013 0014 refines 0003 0010 refines 0002Reaching a root: 0005, 0006, 0007, 0008, 0010, 0012. Not reaching a
root: 0003, 0004, 0009, 0011, 0013, 0014.
0003(registry is the sole authority) has no parent.0014refines it, so the edge points the wrong way to help.0004(unauthenticated reads) and0011(prompts served as a versioned service) have no relations at all.0009(read-time conformance evaluation) has no parent, and0013(stale rendering) inherits the orphaning through it.0014(project truth in the repo, methodology in the control plane) reaches only0003.
§3’s own intake rule is “trace-to-root or reclassify”, and its rationale says a
requirement that cannot be traced up to 0001 or 0002 “does not belong in SR
and is almost always an OR or a DR in disguise.” Applied literally that would
reclassify six of fourteen system requirements, including three the estate leans
on hardest.
The more likely reading is that the root set is wrong, not that the six
requirements are misfiled. PTV-SR-0003 is not a consequence of “the system is
the sole path for fleet change” or “every mutation is a reviewable PR” — it is a
third independent premise, and 0004, 0009 and 0011 look like consequences of
premises nobody wrote down (read access is free; the estate is observable; law is
served, not carried).
This round does not rule on it. Choosing between “reclassify six SRs” and “admit further roots” changes the shape of the requirement tree, which is a baseline change and wants its own decision record with alternatives. Gate 4 is recorded FAIL and the ruling is DEFERRED — see F-02.
What was deliberately not done
Section titled “What was deliberately not done”The gate could be made to pass by adding trace edges from the six orphans up to
0001 or 0002. Every one of those edges would be invented to satisfy the gate
rather than because the relationship holds — 0004 is not contained by “the
system is the sole path for fleet change” in any sense that survives being read
aloud.
The scaffold’s own termination condition covers this: “A phase gate cannot be evidenced and the crew is considering weakening the gate. Weakening a gate to pass it is the failure this whole system exists to prevent. Halt and ask.” Halting and asking is what this record is.
Part B · Friction surfaced
Section titled “Part B · Friction surfaced”Fourteen items. Ordered by whether they were resolved in-phase, absorbed, or handed forward.
F-01 · G2 as specified refuses the artefact it governs. SDD §7.3 asserts every
edge carries exactly one of C1–C5. The hand-drawn master carries nine with no
class — control-plane internals, the refusal path, ring-1 surface adjacency —
because none of them crosses a boundary. Resolved in-phase by admitting INTERNAL
constrained to same-ring edges with a required rationale, recorded as SDD §8.8.
F-02 · Six SRs do not trace to root, and the tree’s shape is the question. Gate 4. See Part A.
F-03 · PTV-DR-3104 carries no trace edge. Gate 3. A single missing edge in
an authored domain module, in a document whose own gate G4 exists to catch exactly
this.
F-04 · 35 of 40 registered slugs belong to no domain. They draw from the open
DR-3600+ block, which is not a domain but the absence of one. For those slugs,
part 3 of the domain module is not unwritten — it is blocked on a DR block
allocation, which is a G1 act.
F-05 · Domain module parts 3–5 are unspecified for every generated slug. By design; a generated judgement is a fabrication with a build step in front of it. But 40 × 3 unspecified sections is real work with no owner named per slug.
F-06 · The alert budget was over cap on first run. checks.yaml was authored
with seven page-grade alerts against the five PTV-CHK-0019 declares. Caught by
the test, not by review. Two were demoted with their reasons recorded.
F-07 · checks.yaml did not carry the check D-20’s disposition promised. The
class fix for “a governing document existed only in a transcript” was named in a
finding and absent from the registry that finding pointed at. Added as
PTV-CHK-0035 mid-phase.
F-08 · Domain allocation was conflated with depiction on the master. The
domain generator reported kahn-hq’s domain as KAHN — a reader-plane element,
which appears on the drawing precisely because it sits outside the estate it
reads. Would have implied a DR block claim that does not exist.
F-09 · The verification debt is unchanged. Six T-verified SRs (0001, 0002,
0005, 0006, 0007, 0008) still have no executing test. checks.yaml now specifies
the probe as PTV-CHK-0008 and PTV-CHK-0009, which is strictly better than a
prose description in a handbook — and a specified check is not an executing test.
PTV-VCRM-DEBT-01 stands.
F-10 · PTV-SR-0015 is ratified by nobody. The record is drafted with four
alternatives and its conformance evidence has been amended twice, and the
countersign box is unticked. INV-3 therefore still cites a requirement that is not
yet estate law.
F-11 · INV-3’s n8n axis is conforming by role, not by scope. Community edition issues a key carrying its holder’s role. A licence change or role promotion widens it with no artefact changing anywhere in this repo, and the write refusal is inferred from the read refusal rather than measured.
F-12 · The scoped credential is ambient. _loader.zsh sources every
env/*.env bar two, so the key is in every interactive shell — the C-1 condition,
reproduced by the fix for a different one.
F-13 · Both deployed surfaces still serve a build-time snapshot of state/.
D-09/D-12. A sweep on main does not change what either surface reports until the
next deploy, so PTV-CHK-0001 asserts on the surface rather than the repo, and the
gap between them is the defect.
F-14 · ARES is on the master with no registered slug behind it. An
integration applicability field, not a governed repository. Recorded in
estate.yaml with empty membership rather than pointed at a plausible slug.
Part C · Classification
Section titled “Part C · Classification”Every item classified as exactly one of CLOSED (resolved in-phase, no carry), IN-BUDGET (justified carry, absorbed here) or DEFERRED (assigned to a named later phase). Friction is not absorbed by extending this phase.
| Item | Class | Disposition |
|---|---|---|
| F-01 G2 refuses its own artefact | CLOSED | INTERNAL admitted, constrained to same-ring, rationale required. SDD §8.8. Test asserts a fleet→repo edge cannot be smuggled through it. |
| F-06 alert budget over cap | CLOSED | Two checks demoted, reasons recorded on each. The cap is now a test. |
| F-07 missing PTV-CHK for D-20 | CLOSED | PTV-CHK-0035. |
| F-08 domain vs depiction | CLOSED | Separate Reader plane row; index counts ring 2 only; two tests. |
F-03 PTV-DR-3104 untraced | DEFERRED → P2 | One edge, in an authored module. Deferred rather than fixed here because the correct target depends on F-02’s ruling — if the root set changes, so may this trace. |
| F-02 six orphaned SRs | DEFERRED → P2, blocking | Wants a decision record with alternatives: reclassify six SRs to OR/DR, or admit further roots. This is what blocks P1’s close. |
| F-04 35 slugs, no DR block | DEFERRED → P2 | Allocation is a G1 act and wants a decision record. Enumerated per slug in docs/domains/. |
| F-05 unspecified module parts | DEFERRED → P2 | Needs an owner per slug before it needs authoring. |
| F-09 verification debt | DEFERRED → P4 | Discharged by building PTV-CHK-0008/0009 against the canary, which is P4’s work and P3’s credential. |
| F-10 SR-0015 uncountersigned | IN-BUDGET | Absorbed: the record is complete and the remaining act is human. An agent does not tick the box, and a phase does not wait on a signature it cannot give. Tracked, not carried as work. |
| F-11 conforming by role | DEFERRED → P5 | The negative test — an apply attempt that is refused — is P5’s, against a throwaway inactive workflow. |
| F-12 ambient credential | DEFERRED → P3 | Operator action: move the key outside env/, or add it to the loader’s skip list. |
F-13 state/ frozen at build | DEFERRED → P4 | Fixing it means addressing both surfaces. PTV-CHK-0001 already encodes the correct assertion. |
| F-14 ARES without a slug | IN-BUDGET | Absorbed: the empty membership is the honest record and needs no further work until a slug exists. |
Four CLOSED · two IN-BUDGET · eight DEFERRED. No item was resolved by extending the phase.
Part D · Round verdict
Section titled “Part D · Round verdict”P1 does not close. Gates 3 and 4 FAIL, and the failure is substantive rather than clerical — gate 4 asks a question about the shape of the requirement tree that this round is not authorised to answer.
The smallest action that would satisfy the close: a decision record ruling on F-02 (reclassify the six orphans, or admit further roots), and the single trace edge in F-03 once that ruling lands. Both are P2 work by the deferral above, which means P2 opens with a P1 gate still open — legal only if P1 is not claimed closed, and it is not.
What was built and evidenced
estate.yaml, the deterministic PTV-DWG-0002 generator, and the G1/G2/G3 gates as
tests. checks.yaml, 35 checks unifying M-01..19, N-01..11 and G-01..08 with total
coverage asserted mechanically. 40 domain modules with parts 1–2 sourced and 3–5
visibly absent. Four SDD amendments. A read-only bearer enforced on three
transports. The scaffold spec itself, rescued from a transcript into version
control.
What was deferred, and where to
Eight items, each to a named phase, above.
What questions were raised
One, and it is the phase’s real output: is PTV-SR-0003 a consequence, or a
third root? The same question applies to 0004, 0009 and 0011. §3’s intake
rule assumes two roots are sufficient; six orphans suggest the assumption, not the
requirements, is what needs revisiting.
References
Section titled “References”docs/specs/2026-08-12-ptv-scf-0001-scaffold-rev-a.xml— P1 tasks and exit gate.docs/PETROVA-SDD-BASELINE.md§3 (SR catalogue and relations), §3.1 (verification allocation), §6.1–6.2 (authored DR sets), §8.8 (G2 amendment).estate.yaml,docs/diagrams/PTV-DWG-0002.mmd,host/tests/estate.test.ts.checks.yaml,host/tests/checks-registry.test.ts.docs/domains/README.md— the 35-of-40 count and the per-slug blockers.docs/decisions/2026-08-12-ptv-sr-0015-automation-plane-boundary.md— F-10, F-11.docs/findings/20260811-1749-ptv-scf-0001-p0-delta-register.md— F-13 (D-09, D-12), F-07 (D-20).docs/PETROVA-GOLDEN-PROMPTS.md§3 — the G-02 shape this round follows.
Sign-off
Section titled “Sign-off”- Subagent: PTV-SCF-0001 P1 verification round (session 2026-08-12)
- Human: Alex Devarno (alex@devarno.com) — countersigned 2026-08-12, instructed in
session; transcribed by the agent on explicit direction, not ticked on its own
authority. Accepts the gate verdicts and the friction classification as recorded.
The clause “P1 remains open pending a ruling on F-02” was satisfied the same day:
the ruling is
docs/decisions/2026-08-12-requirement-tree-root-set.mdand the close isdocs/decisions/2026-08-12-ptv-scf-0001-p1-close.md. The FAIL verdicts above stand as recorded — they were correct against the tree as it stood, and are not retroactively amended.