Skip to content

feat: an argument may lower the ceiling for one call, and it is not believed on its word - #11

Merged
rodrigoteamx merged 2 commits into
mainfrom
feat/descent
Aug 12, 2026
Merged

feat: an argument may lower the ceiling for one call, and it is not believed on its word#11
rodrigoteamx merged 2 commits into
mainfrom
feat/descent

Conversation

@rodrigoteamx

Copy link
Copy Markdown
Contributor

decisions/0029, forced by capabilities:enable --dry-run asking permission to do nothing: S2 judges the OPERATION, so a rehearsal carried the ceiling of the real thing though it wrote nothing.

This is the dangerous direction. escalatesOn is safe because it can only raise — a careless declarant harms only themself, which is what lets an adversarial enumerator be additive (GOV-14). Lowering inverts it: a bad declaration does not punish, it exempts, and the failure is invisible.

So a Descent carries:

  • the full resulting ceiling, never a delta — «a bit less» is not a place
  • its reason, the shape rollbackContract already has for the one reversibility level that buys less scrutiny

A descent with no reason lowers nothing; one that raises any axis is ignored. Failing upwards is the only failure this axis can afford.

The field goes last in the constructor: join() and every positional construction keep working. join() itself is untouched — a descent inside the fold would take GOV-14 down with it.

Five cases, and the second is the control: without the argument the ceiling must not move. A descent that applies either way is a lighter ceiling declared through a longer sentence.

…elieved on its word

greenhouse decisions/0029, forced by capabilities:enable --dry-run asking permission to do
nothing: rule S2 judges the OPERATION, so a rehearsal of an Executable and Privileged operation
carried the ceiling of the real thing though it wrote nothing.

This is the dangerous direction and the code says so. escalatesOn is safe because it can only
raise — a careless or lying declarant harms only themself, which is what lets an adversarial
enumerator be additive under GOV-14. Lowering inverts that: whoever declares a descent badly is
not punished but EXEMPTED, and the failure is invisible, a heavy operation that quietly stops
asking.

So a Descent names the full resulting ceiling rather than a delta — "a bit less" is not a place
— and carries its reason, the shape rollbackContract already has for the one reversibility level
that buys less scrutiny. A descent with no reason lowers nothing, and one that raises any axis is
ignored rather than honoured, because it would otherwise be a back door for climbing quietly.
Failing upwards is the only failure this axis can afford.

The field goes LAST in the constructor on purpose: join() and every other positional
construction keep working untouched, and a new field that renumbers the old ones breaks callers
to make room for something they never asked for. join() itself is deliberately not touched — the
descent resolves one concrete call, and a descent inside the fold would take GOV-14 down with it.

Five cases, and the second is the control: without the argument the ceiling must not move. A
descent that applies either way is not lowering on demand, it is a lighter ceiling declared
through a longer sentence.
PHPStan asked and it is right to: an untyped array in a signature that decides whether a ceiling
comes down is exactly where a reader should not have to guess.
@rodrigoteamx
rodrigoteamx merged commit 7ff85f4 into main Aug 12, 2026
2 checks passed
@rodrigoteamx
rodrigoteamx deleted the feat/descent branch August 12, 2026 19:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant