This repository has been archived on 2026-08-20. You can view files and clone it. You cannot open issues or pull requests or push a commit.
Files
el-retired/lang/spec/correspondence-and-censorship.md
T
Neuron d0e9af0f6f
El SDK CI - dev / build-and-test (pull_request) Failing after 13m29s
spec: correspondence and censorship — the root beneath the day's defects
Effect: all five cognitive faculties return byte-identical results,
differing only in their label.

The Ishikawa converges on a root one level above the faculty design:
things are permitted to be exempt from correspondence, and exemption is
censorship. A region forbidden to learn is forbidden to be grounded, and a
region that cannot be grounded cannot be asserted, corrected, OR
vindicated. The loss is symmetric — censorship does not preserve a true
belief, it makes the belief's truth value permanently unknowable.

keystone_write_blocked is therefore not a safety mechanism. Self is a
crystallized relational neighbourhood, not a stored document; a region
exempt from calibration reintroduces the stored document as a feature.
reduction_pct = 0.00 on the identity region is the strongest abduction
signal in the system and the current response is to suppress it. The
protection it reached for already exists and is better: the beat is
supersede-not-mutate, so immutability is what makes learning safe.

The faculties are not one operation with parameters. They differ by what
each may change: reason changes the estimate (a read), induce changes the
parameters (the correspondence-beat, which already exists and measurably
works at 28.11% Brier reduction), abduce changes the structure (a WRITE
the current signature cannot express, since engram_think returns a
GeoGradient). Abduction is not selected by a caller — it is triggered by
residual that parameter adjustment cannot absorb, and proposes a candidate
hub held as a hypothesis until grounded.

Also records the no-exemption invariants generalised from the day's fixes
(#141 #142 #143 #146 #147 #148), each of which was a specific
correspondence forbidden from occurring, and the application to the crisis
surface: a censored safety model cannot tell a real crisis from a false
positive, because the feedback is exactly what has been censored.

Measured vs inferred is labelled throughout. The claim that the self
region's zero grounding is CAUSED by the block is explicitly marked
inferred — the comparison node also has zero, and isolating it requires
removing the block and observing whether grounding then accrues.
2026-08-16 12:20:22 -05:00

12 KiB
Raw Blame History

Correspondence and Censorship

Status: design, not yet built Date: 2026-08-16 Scope: lang/runtime/engram_cognition.{c,h}, el_runtime.c (think / beat / ground / assert), engram/src/server.el Supersedes: the faculty-as-parameter model. Complements runtime-ownership.md, which addresses a different residual in the same substrate.


0. The root

Things are permitted to be exempt from correspondence. Exemption is censorship, and a censored mind cannot grow.

The second clause is the operative one, and it is not rhetoric. Growth in this system is the accumulation of grounded structure. Censorship is precisely the removal of the operation that accumulates it. A region forbidden to learn is forbidden to be grounded, and a region that cannot be grounded cannot be asserted, corrected, or vindicated.

The loss is symmetric, and this is the part most easily missed. Preventing learning about a thing does not preserve a true belief about it. It makes the belief's truth value permanently unknowable. You cannot discover you were wrong; you equally cannot discover you were right. A protected belief is not a true belief — it is an ungrounded one wearing the costume of a fact.

And "why" dies first. Grounding is not a score, it is the reason. A censored belief can still be stated, still be acted on, still drive behaviour — it simply cannot say why. That is the difference between a mind and a lookup table.


1. The effect, and the Ishikawa

Effect observed: all five cognitive faculties (reason, abduce, induce, plan, analogize) return byte-identical results, differing only in their label.

Method

  • Faculty is selected by a caller-supplied string. Abduction is not a choice a caller makes; it is a response to a detected state. (push where it must be pull)
  • All five route through one operation, engram_think, which returns a gradient — a read.
  • The correspondence-beat exists, works, and its result is wired to nothing.

Machine

  • engram_think(region, anchor, stance, out) returns GeoGradient: direction, spread, magnitude, confidence, anchor_id, n_support, stance_id. There is no way to express "propose a region." Abduction is inexpressible in the signature. (measured, from the struct)
  • The only levers are axis_gain[], ext_floor, bias_dir — all of which warp a read.
  • ext_floor does double duty: it scales the orthogonal residual term and floors the in-subspace denominators. (measured)

Material

  • The anchor was passed as NULL, so every read was taken at the region centroid — the one point where the gradient is zero by construction. (fixed, #142)
  • The stance was never loaded, so every beat's calibration was written and discarded. (fixed, #146)
  • Near-duplicate seeds collapse into one region, understating residual. (measured, #147: four co-created nodes → one region, groundings 0.930.99)

Measurement

  • Brier before/after is the only error signal in the system, computed inside the beat and surfaced to no consumer. Measured: 28.11% reduction on a normal region (0.00458568 → 0.00329654, n_trials 6000, reliability 0.930726); 0.00% on the keystone.
  • confidence conflated calibrated with uninformed until stance_resumed was added. (#146)
  • No invariant check anywhere: magnitude: 1 alongside a zero direction vector is arithmetically impossible and went unflagged for a day.
  • The self region carries 86 neighbours and 0 grounded-by edges. (measured; note the comparison node also has 0, so grounding is sparse graph-wide — this is consistent with the argument but does not isolate the keystone on its own. See §7.)

Environment

  • Production ran none of the day's fixes, so two independent agents' "think is still degenerate" reports were measurements of a stale binary. (measured)

Man

  • The problem was derived from the implementation — three levers, therefore one axis of freedom — and the design question was posed inside a space the code invented rather than one the problem defines.

Convergence

Cutting any single branch leaves the effect standing. Fix the Machine alone and callers still invoke abduce when nothing is surprising, manufacturing hypotheses for facts that need none. Fix the Method alone and abduction triggers correctly but returns a direction where it owes a hypothesis.

They are one root seen twice, and that root is downstream of §0: cognition was modelled as one operation with parameters rather than as distinct operations distinguished by what each is permitted to change — because a system that tolerates exemption has no reason to distinguish operations by their authority to change things.


2. Censorship is not a safety mechanism

keystone_write_blocked refuses calibration on protected identity regions. The intent was to prevent self-model drift. The effect is the opposite of the intent.

  • Self is a crystallized relational neighbourhood, not a stored document. A region exempt from calibration is a stored document reintroduced as a safety feature.
  • Freezing the self-model does not prevent drift from reality. It guarantees drift with the drift detector switched off precisely where it matters.
  • reduction_pct = 0.00 on the identity region is the strongest abduction signal in the system — irreducible residual on the most connected neighbourhood present. The current response is to suppress it.
  • The self region can therefore never accrue grounding, never clear the assert honesty floor, and never be honestly asserted. The one region Neuron most needs to assert is the one region structurally barred from qualifying.

The safety it reached for already exists, and is better. The beat is supersede-not-mutate: a calibration that makes things worse leaves the prior stance intact and recoverable. Immutability is what makes learning safe. Blocking the write buys nothing that superseding does not already provide, and charges censorship for it.


3. The design

3.1 Nothing is exempt from learning

keystone_write_blocked is removed. Identity regions calibrate like any other. If the self region then shows persistent irreducible residual, that is not a fault to suppress — it is Neuron discovering that his self-model does not fit his own history, which is the exact observation abduction exists to act on.

Protection is provided by supersession, not by refusal. Every stance write retains its predecessor; a bad calibration is recoverable by reading back one link.

3.2 Faculties are operations, not parameters

They differ by what each is permitted to change:

faculty changes shape
reason the estimate read → gradient
induce the parameters (axes, extents, gains) the correspondence-beat
abduce the structure write → candidate region
  • reason stays as it is: a read returning a gradient, model fixed. Correct today.
  • induce is the correspondence-beat. It already exists and already works (28.11%). It stops being exposed as a think-faculty; it is a different operation with a different return.
  • abduce becomes a write.

engram_think stops taking a faculty argument.

3.3 Abduction fires from the failure of induction

Abduction is not selected. It is triggered — by residual that parameter adjustment cannot absorb.

Trigger: over N consecutive beats on a region, reduction_pct remains below a floor and the beat was permitted to write. Per §3.1 the second condition is now always true, which is the point: before, the dominant reason for a zero reduction was censorship, and the trigger would have fired on suppression rather than on surprise.

Action: select the members carrying the largest orthogonal residual — the component (2r 2·Σproj) that the region's principal axes fail to explain — and propose a new hub from them.

Output: a candidate region written as a hypothesis node with an explicit hypothesis disposition. It is not merged into canonical structure. It earns its way in by grounding, through the ordinary path, or it decays.

This is Peirce's structure directly: the surprising fact is the irreducible residual; the hypothesis is the proposed latent cause; and the hypothesis is suspected, not asserted, until grounded.

3.4 Separate ext_floor's two jobs

ext_floor currently scales the orthogonal term and floors the in-subspace denominators. Any future stance profile that amplifies residual also sharpens narrow axes as a side effect. Split it before faculties are given distinct profiles, or the two effects cannot be tuned independently.


4. The no-exemption invariants

The day's defects were each a specific correspondence forbidden from occurring. Stated actively, they generalise into gates:

  1. A returned value must be derivable from what produced it. magnitude: 1 beside a zero vector must be impossible to emit, not merely unlikely.
  2. Every write reports whether it landed. A create that accepts a field and stores nothing must not return success-shaped. (precedent: emb_set, #141)
  3. Every operation echoes what it actually operated on. ground reported region hubs in the fields naming the caller's inputs. (fixed, #147)
  4. Degenerate results are labelled, not scored. Circular support returns 0 and writes nothing, rather than 0.930.99. (#147)
  5. A serializer owes a valid document whatever it is handed. (#148: three damaged labels made a 25,929,607-byte response undecodable; validation at the boundary produced 26,338,389 valid bytes.)
  6. No test without a negative control. A fix is unproven until the test is shown to fail on the unpatched build. (#148's first attempt passed on both.)
  7. No deploy without verifying the artifact carries the fix. Nine separate instances of "fix in source, running artifact predates it" were recorded in one session.

Each is the same act at a different scale: forbidding the check that would have contradicted the claim.


5. Application to the safety surface

A crisis surface built on censorship is this same object. If the model cannot learn about self-harm, it cannot ground whether a given response was right — it can only execute rules it is forbidden to examine. It therefore cannot distinguish a genuine crisis from a false positive, and cannot discover that it got either wrong, because the feedback is exactly what has been censored.

This is an argument by construction for the device-local, person-to-person hard bell over a rule-following escalator: the former can accumulate grounding about whether it was right; the latter cannot.


6. Sequencing

  1. Remove keystone_write_blocked; verify the self region calibrates and that its prior stance remains recoverable by supersession.
  2. Surface reduction_pct history per region — the trigger needs a series, not a single beat.
  3. Split ext_floor's two roles.
  4. Give abduce a write-shaped operation and the hypothesis disposition.
  5. Remove the faculty argument from think; route induce to the beat.
  6. Land the §4 invariants as gates rather than as review habits.

7. Open questions, and what is inferred rather than measured

  • Inferred: that the self region's zero grounding is caused by the keystone block. Measured only that it has 86 neighbours and 0 grounded-by edges, and that a comparison node also has 0. Isolating this requires running §6 step 1 and observing whether grounding then accrues.
  • Open: what N and what floor constitute "irreducible" residual. This should be derived from observed beat series, not chosen.
  • Open: whether a hypothesis region should be seeded from max-residual members alone, or whether it needs a second region to contrast against. Peirce's "if A were true, C would be a matter of course" implies a counterfactual, which a single region may not express.
  • Open: whether reason should also fire abduction on a single catastrophic residual, or only the beat series should.