Intervention Provenance
Every intervention carries the Worker and generation that made it and the evidence it acted on; an unattributable intervention is inadmissible.
- Standing
- STATED CHECKABLE RUNNABLE EXECUTED STAGED PUBLISHED REPRODUCED
- Last checked
- never run
- Source
- none — this record cites no check
- Limit
- Cell 17 (append-only audit) is proved, which makes the record durable. The pattern asks for the EFFECT to be re-observed, and the honest half of this record is that the re-observation does not exist — Pty::winsize() has zero callers.
- Next rung
in_tree— a caller for the re-observation, so that an intervention's effect is measured rather than assumed from its request.
Why this page says STATED — the derivation, not the word
- ✗ a witness is named
- ✗ its evidence kind is one the ledger already uses
- ✗ the witness path resolves in this tree
- ✗ its rung is in_tree or above
- ✗ a run is recorded for these exact bytes
- ✓ no claim is cited that could be REFUTED
- ✗ a counterexample is shipped (required once WITNESSED)
- ✗ not staged on this site, so it cannot run from the page
WITNESSED requires every line above to hold. The label is computed from them by build.mjs and cannot be typed into the registry — the build refuses a record that carries it.
Intent
Acting on a world someone else inhabits — a terminal, a filesystem, a user's machine — is admissible only when the action can be answered for: who, under which generation of authority, on what evidence. The operator-disclosure policy is keyed on Worker + generation because, when this was measured, no cross-peer terminal authority existed to key it on.
Technical register
Super D.1.3c·2d·2: outcome vocabulary APPLIED | REFUSED | INDETERMINATE (Three-Valued Outcome); provenance keyed on a Worker + generation. The same document records that the re-observation INDETERMINATE was to be repaired by does not exist — Pty::winsize() has zero callers — and refutes the predecessor round's settle-in-place design. Cell 17 (⊕ append-only) is the ledger property this depends on. Witness in super/, referenced not copied.
Problem
An agent writes to a terminal. Later, something is different. Which action did it, under whose authority, because of what? Without provenance the answer is a log grep and a guess, and the guess is usually 'the agent'.
Solution
Attach Worker, generation and evidence to every intervention before it is attempted. Append the outcome as one of three values. Never rewrite. Name the re-observation the design depends on and check it has callers.
Real-world analogy
A surgical count: every instrument signed in and out by name, and an operation that cannot account for one is not closed.
Structure — on the surface
An illustration on a compute surface: loci above, carriers below. Press Play or Step; the takeaways collect as you go. Nothing here is evidence — the witness section is.
The chapter in WRL — and the chain so far
Chapter 30 of 32 — the fragment _patterns/wrl/chain/intervention-provenance.wrl, sealed alone by wrl.js
; INTERVENTION PROVENANCE — two writers (w=7, w=9) intervene on the same locus; every receipt names its writer
; and sequence. ip_in is the entry, fed by the sufficiency router.
[relay:ip_in]{sig_in, sig_out}
[spinner:ip_world](w=16, n=8, rotor=quarter_turn_z, configurable){sig_in, socket}
[orb:ip_view]{pose}
[ip_in] --sig--> [ip_world]
[ip_world] --socket--> [ip_view]Its test bench _patterns/wrl/chain/intervention-provenance.bench.wrl — drives the entry for this chapter's own film; never part of the chain
; TEST BENCH — drives this chapter's entry alone; the chain replaces it with a wire from an earlier chapter
[pulser:ip_bench](every 1){sig_out}
[ip_bench] --sig--> [ip_in]module + bench seal to → sem-28af0fc6bf2e128c06f301cb8034fd36dd2e56830f932f9d057a3aad049676dc
Run inputs — a ScenarioV1, the forge's own document, bound to this world's id and never part of it (D3) · ScenarioDigest scen-1b546f491ca3cfb245f… (the run inputs' own identity, computed by the forge)
| epoch | writer · seq | op | target | rotor | label |
|---|---|---|---|---|---|
| 1 | w7 s1 | SetRotor | ip_world | 255.0.0.0 | SetRotor ip_world 255.0.0.0 |
| 3 | w9 s1 | SetRotor | ip_world | 0.0.255.0 | SetRotor ip_world 0.0.255.0 |
Reduced by the native reducer (ic32); the reference reducer reproduces every epoch's film hash (38.87s).
Receipts in the last epoch's Film
receipt:w=7,s=1,accepted=0b,apkey=0.0.255.0.0.0,epoch=1,outcome=Applied receipt:w=9,s=1,accepted=5c,apkey=0.0.0.0.255.0,epoch=3,outcome=Applied
The Film, epoch by epoch (6)
epoch 1 · sha256:4facc1ac2251a4777e76dd3f436c1561b219bfbee20e1af2393def5e8b738c2f
FILM v0.7 t=1 spinner:ip_world:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,rotor=00ff,0000,0000,0000,socket=ip_view,config=configurable orb:ip_view:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,pose=0100,0000,0000,0000,controller=ip_world,fault=0 pulser:ip_bench:mode=periodic,p=1,phase=0,armed=0,done=0,nf=1 relay:ip_in:cur_out=0,next_out=1 wire:w__ip_bench__ip_in:cur=1,nxt=1 wire:w__ip_in__ip_world:cur=0,nxt=0 admit:policy=admit_candidate_min_firstreceipt_v1,fact_capacity_fault=0,receipt_capacity_fault=0,capacity_fault=0 claim:w=7,s=1,digest=0b,pkey=0.0.255.0.0.0,payload=SetRotor:ip_world:255.0.0.0 receipt:w=7,s=1,accepted=0b,apkey=0.0.255.0.0.0,epoch=1,outcome=Applied recognition:w=7,s=1,state=unambiguous
epoch 2 · sha256:bc8c7f1b849a86bb8f90f612503f663ec9a2aa89f221aeaf60655bf5407d8340
FILM v0.7 t=2 spinner:ip_world:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,rotor=00ff,0000,0000,0000,socket=ip_view,config=configurable orb:ip_view:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,pose=0100,0000,0000,0000,controller=ip_world,fault=0 pulser:ip_bench:mode=periodic,p=1,phase=0,armed=0,done=0,nf=1 relay:ip_in:cur_out=1,next_out=1 wire:w__ip_bench__ip_in:cur=1,nxt=1 wire:w__ip_in__ip_world:cur=0,nxt=1 admit:policy=admit_candidate_min_firstreceipt_v1,fact_capacity_fault=0,receipt_capacity_fault=0,capacity_fault=0 claim:w=7,s=1,digest=0b,pkey=0.0.255.0.0.0,payload=SetRotor:ip_world:255.0.0.0 receipt:w=7,s=1,accepted=0b,apkey=0.0.255.0.0.0,epoch=1,outcome=Applied recognition:w=7,s=1,state=unambiguous
epoch 3 · sha256:7cd76c0e21bbc2eaa790df6747952830cb4d64f5d9c22d2e6762da3af2b70dce
FILM v0.7 t=3 spinner:ip_world:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,rotor=0000,0000,00ff,0000,socket=ip_view,config=configurable orb:ip_view:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,pose=0000,0000,00ff,0000,controller=ip_world,fault=0 pulser:ip_bench:mode=periodic,p=1,phase=0,armed=0,done=0,nf=1 relay:ip_in:cur_out=1,next_out=1 wire:w__ip_bench__ip_in:cur=1,nxt=1 wire:w__ip_in__ip_world:cur=1,nxt=1 admit:policy=admit_candidate_min_firstreceipt_v1,fact_capacity_fault=0,receipt_capacity_fault=0,capacity_fault=0 claim:w=7,s=1,digest=0b,pkey=0.0.255.0.0.0,payload=SetRotor:ip_world:255.0.0.0 claim:w=9,s=1,digest=5c,pkey=0.0.0.0.255.0,payload=SetRotor:ip_world:0.0.255.0 receipt:w=7,s=1,accepted=0b,apkey=0.0.255.0.0.0,epoch=1,outcome=Applied receipt:w=9,s=1,accepted=5c,apkey=0.0.0.0.255.0,epoch=3,outcome=Applied recognition:w=7,s=1,state=unambiguous recognition:w=9,s=1,state=unambiguous
epoch 4 · sha256:f22e4f00feb27da87d17d346264ca9ab0cf23f8bfd9dbb8e04d6f1b4d31f6a2e
FILM v0.7 t=4 spinner:ip_world:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,rotor=0000,0000,00ff,0000,socket=ip_view,config=configurable orb:ip_view:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,pose=ff02,0000,0000,0000,controller=ip_world,fault=0 pulser:ip_bench:mode=periodic,p=1,phase=0,armed=0,done=0,nf=1 relay:ip_in:cur_out=1,next_out=1 wire:w__ip_bench__ip_in:cur=1,nxt=1 wire:w__ip_in__ip_world:cur=1,nxt=1 admit:policy=admit_candidate_min_firstreceipt_v1,fact_capacity_fault=0,receipt_capacity_fault=0,capacity_fault=0 claim:w=7,s=1,digest=0b,pkey=0.0.255.0.0.0,payload=SetRotor:ip_world:255.0.0.0 claim:w=9,s=1,digest=5c,pkey=0.0.0.0.255.0,payload=SetRotor:ip_world:0.0.255.0 receipt:w=7,s=1,accepted=0b,apkey=0.0.255.0.0.0,epoch=1,outcome=Applied receipt:w=9,s=1,accepted=5c,apkey=0.0.0.0.255.0,epoch=3,outcome=Applied recognition:w=7,s=1,state=unambiguous recognition:w=9,s=1,state=unambiguous
epoch 5 · sha256:61b54c3a8791d1f86513a3ae529f01bc517c0461213e13fe5740f18e8a5736a5
FILM v0.7 t=5 spinner:ip_world:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,rotor=0000,0000,00ff,0000,socket=ip_view,config=configurable orb:ip_view:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,pose=0000,0000,ff03,0000,controller=ip_world,fault=0 pulser:ip_bench:mode=periodic,p=1,phase=0,armed=0,done=0,nf=1 relay:ip_in:cur_out=1,next_out=1 wire:w__ip_bench__ip_in:cur=1,nxt=1 wire:w__ip_in__ip_world:cur=1,nxt=1 admit:policy=admit_candidate_min_firstreceipt_v1,fact_capacity_fault=0,receipt_capacity_fault=0,capacity_fault=0 claim:w=7,s=1,digest=0b,pkey=0.0.255.0.0.0,payload=SetRotor:ip_world:255.0.0.0 claim:w=9,s=1,digest=5c,pkey=0.0.0.0.255.0,payload=SetRotor:ip_world:0.0.255.0 receipt:w=7,s=1,accepted=0b,apkey=0.0.255.0.0.0,epoch=1,outcome=Applied receipt:w=9,s=1,accepted=5c,apkey=0.0.0.0.255.0,epoch=3,outcome=Applied recognition:w=7,s=1,state=unambiguous recognition:w=9,s=1,state=unambiguous
epoch 6 · sha256:10f15a32782ce94f1f7e8b732593e3bac86d6d1fd1a4a0e6ff1337d6954df621
FILM v0.7 t=6 spinner:ip_world:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,rotor=0000,0000,00ff,0000,socket=ip_view,config=configurable orb:ip_view:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,pose=00fc,0000,0000,0000,controller=ip_world,fault=0 pulser:ip_bench:mode=periodic,p=1,phase=0,armed=0,done=0,nf=1 relay:ip_in:cur_out=1,next_out=1 wire:w__ip_bench__ip_in:cur=1,nxt=1 wire:w__ip_in__ip_world:cur=1,nxt=1 admit:policy=admit_candidate_min_firstreceipt_v1,fact_capacity_fault=0,receipt_capacity_fault=0,capacity_fault=0 claim:w=7,s=1,digest=0b,pkey=0.0.255.0.0.0,payload=SetRotor:ip_world:255.0.0.0 claim:w=9,s=1,digest=5c,pkey=0.0.0.0.255.0,payload=SetRotor:ip_world:0.0.255.0 receipt:w=7,s=1,accepted=0b,apkey=0.0.255.0.0.0,epoch=1,outcome=Applied receipt:w=9,s=1,accepted=5c,apkey=0.0.0.0.255.0,epoch=3,outcome=Applied recognition:w=7,s=1,state=unambiguous recognition:w=9,s=1,state=unambiguous
Composes with the 29 chapters before it
The chain through this chapter — every earlier fragment, this one, and the links — seals to sem-3a8432458a2c00cdb3c6ee824c2babf74fafb04c16c95a8812100d029b5d9bc3: 103 objects, 93 edges (was 100 / 90; every earlier object and edge is still present — checked, or the build refuses).
Links only the chain carries
[rg_sufficiency] --sig--> [ip_in]
How to read this board
Five kinds of object, two kinds of wire, and one band per Part of the book. Signal flows left to right: it starts at a clock, travels through relays, and ends at a door — or turns a spinner, which drives an orb. Nothing below is the book's own vocabulary; each line is quoted from where the definition lives.
| shape | is | and so |
|---|---|---|
| a clock; the only source of signal | Every signal on the board starts at one of these. Nothing else can make one. | |
| a pass-through, so signal can travel | One arrives, any number leave — a relay that fans out is the board's router. | |
| a sink; signal arrives and stops | It latches what reached it and passes nothing on. A door is where a path ends. | |
| rotation: takes signal, drives a pose | The only object on the board that holds a value a claim can rewrite — and only if its config says configurable. | |
| the thing that gets moved | It is driven, never driving: an orb is what you watch to see whether anything happened. | |
| not a WRL role — the book's own drawing of the receipts in the epoch's Film | It counts what the run admitted, and turns red on a Rejected outcome. | |
| SignalWire | signal: a sig_out to a sig_in | Legal from a Pulser or Relay, into a Relay, Door or Spinner. This is how the board moves. |
| SocketControl | control: a socket to a pose | Legal only from a Spinner into an Orb. At most one may land on any input port — fan-in is a typed refusal. |
Hover any object for what it is, which chapter put it there, and every field of its line in that epoch's Film — split into what it is doing now and how it was built. Click to pin the readout, then click a wired name to follow the signal. The field definitions come from TRVM/forge/film.py (the emitter), TRVM/forge/forge_state.py (nf, derived from the decoded counter and never from t), TRVM/forge/lower_e2a.py (the commit/react law), TRVM/FORGE_SEMANTIC_IR_v1_MEASURE.md §1.3; the shapes from WRL/learn.html and WRL/docs/spec/README.md. The build refuses if a Film emits a field this key does not explain.
The board so far: one band per Part, signal flowing left to right; relays that fan out are routers, doors are switches, pulsers are clock domains. Hover an object — or click the board and walk it with the arrow keys — for its role, its Part and what it is wired to. This board is the chain’s sealed shape; no Film drives it, so it has no state to report, and the whole board in the conclusion is where every object’s state is read epoch by epoch. Wheel zooms · drag pans · double-click fits.
Syntax — quoted from the tree at build time
The three outcomes, where they are specified (super/docs/reviews) super/docs/reviews/D_1_3C_2D_2_INTERVENTION_PROVENANCE.md:22
| 2 | the record is "appended before the ioctl is requested, **settled to** APPLIED/REFUSED/INDETERMINATE after" (§7) | `Ampd.Receipts` has **no update-in-place operation at all**. Three writes exist: append, wholesale replace, truncate. This is not implementable. | J2 | | 3 | interventions are "keyed on `target.actor`, so `Ampd.Projection.agent/1`'s existing `record["actor"] == actor` filter is reused *correctly*" (§6, lines 260–262) | the filter reads a **top-level** `"actor"` (`projection.ex:231`). A nested `target.actor` yields `nil`, every intervention is dropped, and the C3 ruling is unmet with no crash and no failing test. | J3 |
Forces
Provenance costs a record per action and a key to attribute to. When the natural key (a terminal authority shared across peers) does not exist, the honest move is to key on what does — a Worker and its generation — and to say so, rather than invent the missing authority.
Applicability
Agent runtimes acting on user machines, terminal possession, any actuator shared between principals.
Transformations
- revoking a generation and refusing its later interventions
- appending observations beside an attempt
- an intervention without a Worker and generation
- rewriting an outcome
- a repair path with zero callers presented as a property
A refusing transformation is not one that is discouraged: it is one that, applied, makes the invariant above false. The word is the tree's, and it is the same word the join uses.
Consequences
Interventions become answerable. The honest status: STATED, in a lane this book does not edit, with the specification's unimplemented dependency printed beside it.
Failure mode it answers
Agent Omniscience — Letting an agent's claims exceed its evidence boundary. Paid for at: AGENCY.md §6 (what is established vs a reading)
Witness
No witness. This pattern is STATED — the tree has no check for its invariant.
Counterexample
No counterexample shipped (required only when WITNESSED).
What to take away
- from the animationThe unattributed action was refused; the same action with Worker, generation and evidence was applied.
- from the syntaxThe policy is keyed on Worker + generation because the authority it would rather key on did not exist.
- from the literatureW3C PROV; surgical counts; the audit log that is a precondition rather than a record.
- from the witnessSTATED: the review in super/ specifies it and names its own unimplemented re-observation.
Invariant basis — and how each piece bears
| basis | bears | status |
|---|---|---|
cell 17 | necessary | proved cells.json |
Satisfying a basis is local. Nothing here implies global adequacy unless a theorem or a composition rule says so.
Prior art — and what is not claimed
| work | relation | what it shares | where it differs |
|---|---|---|---|
| W3C PROV | antecedent | a standard vocabulary for who did what to what | PROV records provenance; the pattern requires the record to be re-observable |
| Audit logs | realization | append-only record of intervention (cell 17) | a log records the request; the pattern wants the effect re-observed |
Novelty not claimed. Provenance standards exist and are better developed than this. The witness lives in super/, and the honest half of the record is that the re-observation it depends on does not exist — Pty::winsize() has zero callers.
Realizations in the tree
- super/docs/reviews/D_1_3C_2D_2_INTERVENTION_PROVENANCE.md
Relations with other patterns
Three-Valued Outcome STATED