Eight load-bearing ADRs closing the loop from contemplation Phase 5 through a public showcase demo. Each one is small and evidence-bearing; together they sequence the next arc without duplicating existing substrate. - 0092 Reviewer Registry v1 — populates docs/reviewers.yaml schema; unblocks all reasoning-capable claims under ADR-0091. - 0093 Domain Pack Contract v1 Implementation — wires ADR-0091's five follow-up items (parser, dry-run validator, chain registry, eval lane refs, reviewer resolution) so manifest fields actually gate status. - 0094 Proposal Source Provenance — sealed ProposalSource type widening proposal schemas ahead of 0095. - 0095 Miner-Sourced Teaching Proposals — closes the contemplation loop: articulation_quality / contradiction_detection / frontier_compare miners emit PackMutationProposal candidates routed through the single reviewed teaching path; identity-pack defense at construction, not review; replay-equivalence pre-gate. - 0096 Fabrication-Control Eval Lane — first negative-control measure; three case classes (phantom endpoint, cross-pack non-bridge, sibling collapse) with frozen thresholds (fabrication_rate ≤ 0.01). - 0097 Mathematics-Logic Reasoning-Capable Ratification — first domain claim under ADR-0091; chain corpus + eval lanes already exist, this is the formal contract ratification. - 0098 Demo Composition Contract — DemoCommand protocol so demos can be composed without reimplementation; deterministic JSON, no global state mutation, declared output paths only. - 0099 Public Showcase Demo — composes four scenes (determinism / honest unknown / reviewed learning / multi-hop+trace) under 30s; pure composition enforced by grep gate; JSON byte-equality CI-pinned. Landing order: 0092 → 0094 → 0095 → 0093 → 0096 → 0097 → 0098 → 0099. Deliberately not included: curriculum compiler, formation course runner, calculator operators, response-mode taxonomy expansion, learning-scale 10k harness. Each is deferred with a documented reason.
4.8 KiB
ADR-0095 — Miner-Sourced Teaching Proposals
Status: Proposed Date: 2026-05-21 Author: CORE agents + reviewers Depends on: ADR-0094
Context
Phase 5 of the contemplation arc landed three miners under
core/contemplation/miners/:
articulation_quality.py(closed the articulation loop signal)contradiction_detection.pyfrontier_compare.py
Each miner emits observations. None of them currently produce
PackMutationProposal candidates. The loop is one-way: contemplation
sees the gap, but the only way to close it is for an operator to
read the miner output and manually file a proposal. That breaks the
"learn from reviewed correction" arc CLAUDE.md names as load-bearing:
listen → comprehend → recall → think → articulate → learn from reviewed correction → replay deterministically
This ADR closes the loop without weakening the reviewed-teaching discipline. The doctrine constraint is sharp: there must be exactly one correction path, and miner-sourced proposals must traverse it.
Decision
Introduce teaching/proposals/from_miner.py that translates miner
observations into PackMutationProposal candidates with
source = ProposalSource(kind="miner", source_id=<miner_id>, …) from
ADR-0094.
Hard constraints
- Single review path. Miner-sourced proposals enter
teaching/review.pyvia the same entry point as operator proposals. No parallel reviewer, no auto-acceptance, no shortened review path. - Default status
speculative. Miner-sourced proposals are never coherent at emission. - Identity-pack defense. Proposals touching identity-pack axes are rejected at proposal-construction time (before review), not at review time. This prevents the miner from ever filing an identity override candidate, even one that would fail review. ADR-0027's identity-override rejection rule extends upstream.
- Replay-equivalence pre-gate. Before a miner-sourced proposal is
review-eligible, replay the originating turn under the proposed
mutation. If
trace_hashchanges on any non-target turn in the lane, the proposal is rejected at construction. - Deterministic emission. Same miner observations + same head SHA
→ byte-identical proposal stream. Proposal IDs are SHA-256 of
(miner_id, observation_canonical, emitted_at_revision).
What miners do not gain
- Direct write access to packs.
- Ability to mark proposals coherent.
- Ability to mutate identity, safety, or ethics packs at all.
Telemetry
Miner-sourced proposals emit a "type": "proposal_emitted" event to
the existing telemetry sink (ADR-0040), carrying the redacted
source.serialize() string and proposal ID. Content is redacted by
default per ADR-0040.
Invariant
miner_proposal_replay_equivalence — for every miner-sourced proposal
that reaches review eligibility, replaying the originating lane with
the proposed mutation applied yields identical trace_hash on every
non-target turn. The lane gate refuses proposals that violate this.
miner_proposal_single_review_path — grep gate refuses any code path
that promotes a miner-sourced proposal to coherent outside
teaching/review.py.
Lane
evals/miner_loop_closure/ (new):
- positive: legitimate articulation gap → proposal emitted → reviewable
- negative: identity-override attempt via miner → rejected at construction
- negative: proposal that breaks replay-equivalence → rejected at construction
- negative: malformed miner observation → typed error, no proposal
- coincidence: random/noise observation → no proposal under threshold
- determinism: same observations across two runs → identical proposal stream
Trust Boundary
Miners read turn telemetry only; they do not read user-controlled text
directly. The miner-to-proposal boundary sanitizes source_id via
safe_pack_id traversal rejection. The replay-equivalence gate is a
filesystem-only operation against the existing eval runners; no network
or shell.
Consequences
- Phase 5 contemplation becomes a closed loop in code, not just in doctrine.
- The capability ledger gains a new evidence row class: "miner-sourced proposal accepted into coherent" — measurable, replayable.
- Learning-scale claims (the deferred 10k harness) become eventually defensible because every replayed proposal will have a real provenance, not a synthetic one.
PR Checklist
- Capability added: closed contemplation loop through reviewed teaching.
- Invariants proved:
miner_proposal_replay_equivalence,miner_proposal_single_review_path. - Lane proving it:
evals/miner_loop_closure/. - Hidden normalization / stochastic fallback / approximate recall / unreviewed mutation: none. Single review path enforced by grep gate.
- Trust boundary: miner reads telemetry, never user text; identity-pack rejection at construction.