MotirBuilding in public
MOTIR · moooon
onMotir
You’re viewing a public project. Anyone can view it — no account needed. Sign in to submit, upvote, or comment on requests.View-only — you can’t edit work items
MOTIR-2929

(motir-meta) W6 — the third limb's other half: NAME WHAT ANSWERED, when the address comes from our own config (`kind-leaf-deepen.md`)

To Do
Description

Repo: motir-meta. One PR. Type: content · Executor: coding_agent. Filed 2026-08-17 by the close-out of MOTIR-2916, whose deliverable was settling the promote question that card left open. The mirror half is the motir-ai card that is blocked_by this one.

This is a WIDENING of an existing paragraph — no new gate, no new limb number.

The gap

plan-rules/kind-leaf-deepen.md's THIRD LIMB (wired is not provisioned; a config file is a claim about the deployment, not a reading of it) already reaches databases. Its discharge reads:

"A deployed-state assertion read from the PLATFORM'S OWN API — or, for a database, from ITS OWN CATALOG — fly status / GET https://api.machines.dev/v1/apps/<app>machine_count, vercel env ls production, a job's step shape read back from a real run; and pg_policies for policy coverage, pg_roles for role attributes … A FILE IN OUR REPO IS NEVER THIS ASSERTION, HOWEVER AUTHORITATIVE IT READS."

and the mirror in motir-ai/src/llm/planningRulePacks.ts states its tell as:

"THE TELL: the card's evidence for a RUNTIME property is a file in our own repo, and nothing reads the platform."

MOTIR-2795 performed that discharge and the tell read clean. It ran pnpm reconcile:orgs against a live Postgres and pasted the verbatim output; nothing in its evidence was a file in our repo. The database that answered was a 22-day-old copy of production, so the card asserted that three identifiers belonging to a live paying-surface customer did not exist, and its criterion 4 asked to decide whether to discard the row.

Every example the limb offers is addressed by a name the PLATFORM ownsfly status <app>, vercel env ls production, a catalog view on a connection you are already inside. CORE_DATABASE_URL is the case it does not reach: here a config file did not make the assertion, it chose who would answer it. The limb's own governing distinction (repo file vs platform) is silently satisfied by a read that is wrong in exactly the way the limb exists to prevent.

The neighbouring core.md claim-vs-pointer gate knows the mechanism and names it in a parentheticalgrepped on origin/main (not a stale checkout) — but its subject is a code fact and its discharge is a git ref, so it reaches the source tree and not a database. The corpus has the mechanism and has never turned it on this failure.

The widening (the text to land)

Extend limb (c)'s second bullet — do NOT add a limb (e):

AND NAME WHAT ANSWERED. Every discharge above is addressed by a name the platform itself owns. When the address comes from OUR configuration instead — a *_DATABASE_URL, a *_URL, a CLI profile or context, an account/tenant token — the config did not make the assertion, it chose who would answer it, and a stale, sibling or snapshot copy connects, authenticates and answers in milliseconds with the correct answer to a question about last month. Nothing errors, and having run something real raises confidence. So such a reading is discharged only by a WITNESS that dates the responder — a row whose existence dates the database, a build version, an id you verified independently — or by reading from inside the system (fly machine exec on the running machine, using its own env). And an assertion of ABSENCE through such an address is the one that must not be acted on: "not there" is the identical reply from a current system and from a copy of it, and it is the direction whose remedy deletes.

Warrant line, in COMPRESSION.md § Decision 1's printed two-line form:

Warrant: MOTIR-2795 · 2026-08-12 · a reconciliation read answered by a 22-day-old copy of production reported a live customer's organization as unknown, and the card asked whether to discard it · ×1 → [fixtures/kind-leaf-deepen.md#name-what-answered]

Why ×1 is enough — the rule RAN and stopped short

The standing discriminator (MOTIR-2280) refuses a widening when the governing clause covers the case and merely was not performed. Here it does not cover, and the rule was in the pass:

  • MANIFEST.md routes motir log-bug — author a bug card to core.md + phase-deepen.md + kind-leaf.md + kind-leaf-deepen.md + kind-bug.md + type-bars.md + type-code.md + type-migration.md. MOTIR-2795 was authored by exactly that pass, filed mid-run under the logged-not-absorbed protocol.
  • The third limb landed 0192e05, 2026-08-05T01:24Z. MOTIR-2795 was authored 2026-08-12T15:00:23Z — seven days later, same planner. The ORDER test alone would read as diligence.
  • It is not. The limb's discharge was performed (a live database was read, not a config file) and its tell — a negative — reads clean. A rule that is loaded, performed, and still admits the false fact has a trigger gap, not a diligence problem (the MOTIR-2339 / MOTIR-2897 discriminator).

Family is honestly ONE. No other notes.html entry is this check: #215 is the config-instead-of-platform original, and #254's "a dead command's empty result reads as nothing-is-wrong" is a retired vendor, not a wrong responder. The promotion rests on trigger shape, not on a count — say so in the PR body rather than assembling a family.

Deliberately NOT in this PR

  • run.md's run-time twin (the ⚠️ A CONFIG FILE IS A CLAIM ABOUT THE DEPLOYMENT block in Build/serve rules). It carries the same paragraph for the executing agent and deserves the same sentence — but MOTIR-2878 is a live claimant on run.md and is already at estimateMinutes: 60, the estimation gate's agent-run ceiling with no CI to absorb it. It is criterion 4 below, marked droppable, and the drop test is MECHANICAL rather than a judgement call: when this branch is cut, run gh pr list --repo moooon-B-V/motir-meta --state open and read each open PR's files — if ANY of them touches prompts/run.md, DROP criterion 4, say so in the PR body, and the twin is then owed by whichever card lands last. Two cards editing one file is the exact collision the fold rule exists to prevent, and "is a second concurrent PR worth it?" is the question a tired reader at the end of a run answers wrong.
  • A mechanical validate_work_item advisory. MOTIR-2432's discriminator refuses it: which environment answered a command is not readable from a card body by any lexical matcher, so this belongs in prose, not in the third tier.
  • Re-opening MOTIR-2795. It is done — re-scoped in place and shipped as motir-ai PR #235, which makes the freshness witness an assertion in code. This card is the planner-side half of the same lesson and touches no motir-ai runtime code.

Acceptance criteria

  1. BEFORE any other edit, git show origin/main:prompts/plan-rules/kind-leaf-deepen.md and confirm limb (c)'s platform-assertion bullet still ends on the "Nor is 'the PR merged'" sentence quoted above; if it has already gained a responder-identity clause, the card closes as verified-no-change and says so.
  2. prompts/plan-rules/kind-leaf-deepen.md limb (c) carries the widening as an extension of its existing platform-assertion bullet, not as a new limb, including the address enumeration, the witness discharge, the read-from-inside alternative, and the absence-is-the-dangerous-direction clause — landing AFTER criterion 1's read and BEFORE the fixture is written.
  3. prompts/plan-rules/fixtures/kind-leaf-deepen.md gains a #name-what-answered section under a new ## heading, in the file's existing numbered-fixture form, carrying the two timestamps that disprove each other (motir-ai's mirror row 2026-08-12T14:41:12.636Z against the answering core's newest organization 2026-07-21T04:44:17.733Z) and the one-line reason a mirror cannot predate its source — written AFTER the limb text, so the anchor it is referenced by already exists.
  4. DROPPABLE. prompts/run.md's ⚠️ A CONFIG FILE IS A CLAIM ABOUT THE DEPLOYMENT block gains ONE sentence naming the responder-identity case and cross-referring the limb rather than restating it. If dropped, the PR body names MOTIR-2878 as the reason and states that the run-time twin is then owed by whichever card lands last.
  5. python3 prompts/plan-rules/COMPRESSION.conserve.py is run and its verdict quoted in the PR body. ⚠️ Expect [FAIL] on kind-leaf-deepen.md — it is one of the three packs already failing at baseline (MOTIR-2773: the checker has no verdict for added). Pin the baseline on a clean origin/main worktree first and quote BOTH sides; do not re-word rule text to make it pass, and do not "fix" the checker here.
  6. The PR body states the family count as ONE, quotes the limb's own tell ("nothing reads the platform") as the thing that read clean, and states that the ORDER test alone reads as diligence and is overturned by the trigger-shape argument — so no reader re-derives the verdict from the timestamp and reverses it.
  7. The mirror card carries the same clause into motir-ai; this PR merges FIRST and the PR body says so (the mirror is blocked_by this card).

Context refs

  • prompts/plan-rules/kind-leaf-deepen.md — limb (c)'s platform-assertion bullet, the edit site. ⚠️ It already enumerates database catalogs, so a grep for pg_policies returns a hit and reads as coverage; the gap is the ADDRESS, not the catalog.
  • prompts/plan-rules/MANIFEST.md — the motir log-bug row, which is what proves the pack was loaded in the offending pass.
  • prompts/plan-rules/core.md gate 2's claim-vs-pointer limb — the (not a stale checkout) parenthetical, i.e. the same mechanism scoped to the source tree. Read, not edited.
  • prompts/run.md Build/serve rules — the run-time twin (see criterion 4). MOTIR-2878 holds this file.
  • motir-ai/src/llm/planningRulePacks.ts — the mirror home, and where "THE TELL" sentence lives. ⚠️ SHARED_PLANNING_RULES moved here from treeGeneration.ts; a grep of treeGeneration.ts returns 0 for this whole family and is a false negative. Read it with python — the lines are very long.
  • MOTIR-2916 — the record card whose close-out filed this; MOTIR-2795 — the fixture, done via motir-ai PR #235; notes.html #291 (motir-meta PR #207, merged 2026-08-17T17:32:41Z), whose "why nothing caught it" half was itself corrected by motir-meta PR #215 — read the corrected version, not the merged original, which credits a gate that postdates the defect by four days.
  • MOTIR-2878 / MOTIR-2879 — the sibling widenings pair; MOTIR-2913 / MOTIR-2914 — W5. Disjoint file sets apart from criterion 4's run.md; no merge order required between the pairs.