feat: an argument may lower the ceiling for one call, and it is not believed on its word - #11
Merged
Conversation
…elieved on its word greenhouse decisions/0029, forced by capabilities:enable --dry-run asking permission to do nothing: rule S2 judges the OPERATION, so a rehearsal of an Executable and Privileged operation carried the ceiling of the real thing though it wrote nothing. This is the dangerous direction and the code says so. escalatesOn is safe because it can only raise — a careless or lying declarant harms only themself, which is what lets an adversarial enumerator be additive under GOV-14. Lowering inverts that: whoever declares a descent badly is not punished but EXEMPTED, and the failure is invisible, a heavy operation that quietly stops asking. So a Descent names the full resulting ceiling rather than a delta — "a bit less" is not a place — and carries its reason, the shape rollbackContract already has for the one reversibility level that buys less scrutiny. A descent with no reason lowers nothing, and one that raises any axis is ignored rather than honoured, because it would otherwise be a back door for climbing quietly. Failing upwards is the only failure this axis can afford. The field goes LAST in the constructor on purpose: join() and every other positional construction keep working untouched, and a new field that renumbers the old ones breaks callers to make room for something they never asked for. join() itself is deliberately not touched — the descent resolves one concrete call, and a descent inside the fold would take GOV-14 down with it. Five cases, and the second is the control: without the argument the ceiling must not move. A descent that applies either way is not lowering on demand, it is a lighter ceiling declared through a longer sentence.
PHPStan asked and it is right to: an untyped array in a signature that decides whether a ceiling comes down is exactly where a reader should not have to guess.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
decisions/0029, forced bycapabilities:enable --dry-runasking permission to do nothing: S2 judges the OPERATION, so a rehearsal carried the ceiling of the real thing though it wrote nothing.This is the dangerous direction.
escalatesOnis safe because it can only raise — a careless declarant harms only themself, which is what lets an adversarial enumerator be additive (GOV-14). Lowering inverts it: a bad declaration does not punish, it exempts, and the failure is invisible.So a
Descentcarries:rollbackContractalready has for the one reversibility level that buys less scrutinyA descent with no reason lowers nothing; one that raises any axis is ignored. Failing upwards is the only failure this axis can afford.
The field goes last in the constructor:
join()and every positional construction keep working.join()itself is untouched — a descent inside the fold would take GOV-14 down with it.Five cases, and the second is the control: without the argument the ceiling must not move. A descent that applies either way is a lighter ceiling declared through a longer sentence.