# Change-shape traps — sub-index

> SPLIT OUT VERBATIM from MEMORY.md 2026-08-22 against the read-limit cliff: the index was
> MEASURED at 25,938 bytes over a 24,436-byte read limit, so its TAIL was already being
> silently dropped before this split (the 'Active work' pointer sits last). Growth is handled
> by SPLITTING a whole section out, never by dropping entries — the compaction nag is still
> refused. 12 entries MOVED, ZERO dropped; byte-identity asserted in the move script, not
> eyeballed. Read this BEFORE shaping any change, fix, or correction.

- [a legacy arm that skips the SEAM skips its GATES](legacy-arm-that-skips-the-seam-skips-its-gates.md) ⭐⭐ #185 filed one face ("drops --surfaces"); the arm called the low-level API direct, so it also bypassed the `--admit-node` acknowledgment AND the grant-nodes policy — flag spelling REFUSED an unacknowledged owner agent, positional wrote the WIDER rule, exit 0. Diff the two spellings' SEAMS, not just the dropped input; declare the widened scope before fixing. ⚠ `SPT_AGENT_ID` alone = LocalUserCli (needs a real perch) — my first bypass arm ran as a node-sovereign user and refuted itself.
- [authored-but-unlanded text lives in the lane INDEX](authored-unlanded-text-lives-in-the-lane-index.md) ⭐⭐ peer "read its diff" ⇒ it is STAGED in the lane worktree; my brief's three candidate sources were all wrong and `git status` on `.worktrees/<lane>` answered it in one command. Commit those bytes, never retype.
- [read source at the MEASURED sha](read-source-at-the-measured-sha-not-the-default-tree.md) ⭐⭐ RCA measured @`bd942f6`; main was −349 lines across the same files and the lane worktree differed again. Fails silently — function exists, grep hits, line numbers land NEAR the brief's. `git diff --stat <sha> HEAD -- <files>` FIRST, then read `git show` blobs. A brief naming a sha is naming the TREE.
- [a bare `cd` silently repoints every later read](a-bare-cd-silently-repoints-every-later-read.md) ⭐⭐ one `cd root && spt send` persisted; later greps read main @80ab77a while my Edits landed on the lane @cc2b09b — I reasoned about the arm from a tree missing T1+T2. Use `-C`/absolute paths; `pwd` after any `cd`. ⚠ WRITE-SIDE face 2026-09-06: relative `cd` failed, `&&` skipped the commit, push shipped an EMPTY branch exit 0 — 4 instances/1 session/2 agents; read the remote SHA, never the push output.
- [sequenced edit killed by its own fix](sequenced-edit-invalidated-by-its-own-fix.md) ⭐⭐ doyle sequenced a reword to ride AFTER the #199 fix; the fix killed its only READER (harness now passes the gate) and the target sentence was SHARED across 9 seams. Refused with the mechanism, he withdrew his own sequencing — 2nd accepted refusal of a GO'd sub-task, so it is the standard. Re-read a queued edit's target at the POST-change tree; never execute on the strength of when it was queued.
- [narrowing an unconditional call must FAIL OPEN](narrowing-an-unconditional-call-must-fail-open.md) ⭐⭐ gating a call that always ran has TWO unruled faces: its loud arm now fires with an empty subject (false `ENGINE_ROOM_BRIEFING_UNPRESENTED` on every re-attach, found by MEASURING the log), and `unwrap_or(0)` on the predicate makes an unreadable input a SKIP (doyle's #203-era finding on my #177 code). An absent answer is not a zero. Neither face reds.
- [census the ENFORCERS **and** the STATERS](census-enforcers-and-staters-of-an-invariant.md) ⭐⭐ #159: doyle's shape fixed 1 of 2 sites comparing the same floor — the other ran AFTER the swap, so the fix would have left live files new + record old (worse than the bug). Applying the rule to my own list then found a third population his rule missed: the prose that STATES the invariant, incl. another lane's doc-stage evidence. 3 of his shapes refused in one day were this one error.
- [place a correction by asking WHAT falsified it](correction-belongs-where-the-falsifier-is.md) ⭐ a lane's own change ⇒ SAME commit as the change (no false window); a RULING already made ⇒ at the record, NOW, and the replacement names NO lane — repointing the cross-ref reproduces the bug with a fresher dependency.
- [stating a limit does not ROUTE AROUND it](stating-a-limit-does-not-route-around-it.md) ⭐⭐ I reported my instrument's inconclusive side and its deletion blind spot, then in the SAME message handed doyle a verdict resting on both — read the residue for one commit, skipped it for the next because the residue matched what I expected. Tell was IN it: a REQ TITLE, the likeliest thing to be a reword. **An inconclusive verdict is a WORK ITEM, discharged per item, never per batch; write the open one down as OPEN.** Three settled + one open beats four settled + one wrong. Caught by a cherry-pick CONFLICT — a mechanical REFUSAL, the only catch that day not needing someone to choose to re-measure.
- [a per-line skip resumes INSIDE a multi-line token](per-line-suppression-resumes-inside-a-multi-line-token.md) ⭐⭐ the #74 space-run gate: suppression was deciding what gets PARSED, not what gets REPORTED, so a marked multi-line literal left the scan resuming in its own body where an escaped `\"` reads as an opening quote — marking one site MANUFACTURED a second finding out of the literal just exempted. Unreachable until something is actually marked, so a clean census + markers + green would have SHIPPED it. Also: an escape hatch unusable by the population the check exists for (5 of 11 findings could not carry one). **Re-run and diff the finding set after the FIRST marker; a marker does not only subtract.**
- [declare ≠ enforce site](declare-site-is-not-enforce-site.md) · [seat edge erases the grant](grant-erased-by-seat-edge.md) · [key rides the artifact](key-must-ride-the-crossing-artifact.md) · [single-source discriminant](single-source-discriminant-marker.md) · [forward ref squats](forward-ref-squats-positional-key.md) · [redirect folded seeds](redirect-folded-req-seeds.md).
- [one composer two renderers](one-composer-two-renderers.md) · [condition ≠ cadence](surfaced-payload-names-its-cadence.md) · [ladder per machine](refusal-ladder-fires-per-machine.md) · [CRC-swap blindness](crc-swap-metadata-blindness.md) · [cross-wave needs assembled head](cross-wave-claims-need-assembled-head.md) · [lock delta edge diff](lock-delta-needs-edge-diff.md) · [assemble onto the repair tip](assemble-onto-the-repair-tip-not-a-sibling.md) ⭐⭐ assert by BLOB · [lane-diff byte-identity limit](lane-diff-byte-identity-limit.md) upstream delta in shared file moves index/@@ only — compare content-stripped blobs.
- [a manifest `///` IS the published schema description](manifest-doc-comment-is-a-published-schema-description.md) ⭐⭐ `JsonSchema`-derived manifest types copy every doc comment VERBATIM into `manifest.schema.json` — the docs-site + release asset a machine consumer reads. IO-PARSER docs lane: `Io::shortform` claimed it opts out of `@<…@>` only, while one bool gates the `;;` mint too — prose pages right, generated surface wrong, and the generated one is nobody's re-read. ⚠ THE TRAP IS A SIBLING MEMORY'S REASSURANCE: [[clap-doc-comment-leaks-req-tag]] ends "rustdoc `///` on non-CLI structs is fine" — true of the CLAP gate, false of every doc-comment-harvesting derive. Fix the comment, bless + re-run the drift gate, and `git diff` the schema (porcelain marks it M on EOL alone).
- [a guard bijected to the WRONG enum is silent by design](a-guard-bijected-to-the-wrong-enum-is-silent-by-design.md) ⭐ 2026-09-07 F17: dispatch.rs's wildcard-free `census_index` + ALL-bijection is over `StreamFamily`; the new variant landed in the WIRE enum (`WebRecord::ServeFor`), so the census stayed exhaustive, intact and GREEN while every `serve_for` stream was dropped as Unknown. Name the enum a census matches on before crediting it; bijection belongs on the PRODUCER side pointing into the consumer.
- [a named line is a SAMPLE — census the whole file](a-named-line-is-a-sample-census-the-whole-file.md) ⭐ 2026-09-08 #272 repin: a dispatch named 2 stale literal assertions, there were FOUR; the third surfaced only when the repinned cell RAN and died on it, one battery later. Whoever names a line found it by hitting it, which selects for the first one a run reaches. Grep the whole file for the SHAPE before shaping the fix and report the COUNT as the pin — "zero remain in all three files" is a pin, "I fixed the two you named" is a hope. Bit todlando the same afternoon from the other side.
- [a before/after COUNT DELTA asserts the whole registry](a-before-after-count-delta-asserts-the-whole-registry.md) ⭐ hertz 2026-09-09 r3 `webserve_attachment_e2e.rs:551`: `after == before + 2` over `serve list --json` is a claim about EVERY writer in the window. ARM 10 mints a real 1s-ttl entry ON PURPOSE, `ServeRequest::List` is UNFILTERED (expiry masked at SERVE time, not LIST time), the reaper rides a 5 s pulse → +2 −1 = +1, reported as "each attachment registered its OWN entry". **4 reds in 15 Windows runs, every one exactly −1; the FASTEST run was a red and the SLOWEST a pass — phase, not elapsed, so "slow box" is the wrong read.** Linux 5/5 at the same sha = smaller window, NOT absence. Fix: assert IDENTITY (name the rows), never a total; widening already failed once and a Reconcile only quiesces today's corpse. **Sharpest part: the file ALREADY NAMED the hazard** — afb711c9 had retired the same reaper race in ARM 12, whose comment calls it "a race the reaper WINS sometimes", and ARM 11 one arm up still ran on it. Retiring a race ⇒ census every other site on that clock.
- [a write-then-commit script without set -e mints a FALSE-BODIED commit](a-write-then-commit-script-without-set-e-mints-a-false-bodied-commit.md) 2026-09-09 IR-92: python replace asserted and wrote nothing; git commit+push ran anyway -> 57e38fd8 on the remote for a minute claiming an edit it did not carry; set -e or gate the commit on git diff --quiet; read show --stat before the push.
- [a false sentence in a GATED commit is corrected forward](a-false-sentence-in-a-gated-commit-is-corrected-forward.md) doyle 2026-09-10 v0.69.0 head10 a9e786b2: my bad bind( census rode into the merge body, caught after the sha was under gate; re-cutting buys a full re-gate + a fresh rig-race roll to fix PROSE, so the body stays known-wrong and the correction goes in the PR body AND on the board. Load-bearing-on-the-TREE is the inverse: re-cut is mandatory.
