The Warlock Commandery Taroos the Warlock

Field Reports / 14 SEP 2026

Baby Warlockproofgovernancecapability-truthfail-closed

Capability truth: the registry that refuses to start

Every command Baby Warlock can accept comes from one hand-written manifest, compiled into one artifact, verified at every startup. A capability with no checkpoint contract fails the gate, and the gate failing means she does not route anything until it is repaired. Today: 109 capabilities, 1,042 commands, 69 green, 17 partial, 8 red.

What it is

There is one hand-authored source of truth for what the system can do: a manifest that lists every capability, its status, its lifecycle, and the commands attached to it. Nothing else is edited by hand.

A compiler reads it and writes the compiled truth plus a set of read-only projections: the capability registry, the operator command list, the alias table, the adoption gate, and an adapter index. Every generated file is stamped as generated and carries a truth revision id. Runtime services read only the compiled artifact. There is exactly one place a command can come from.

What the startup gate checks

Before the system routes a single phrase, it:

  • verifies each required doctrine file exists and is readable, hashing each one into a read-verification record;
  • checks the doctrine index actually references every required file;
  • re-verifies the compiled truth against the manifest, attempting one bounded recompile if the only error is a stale revision;
  • checks that compiled statuses agree with the latest stress evidence, so a capability whose live proof is red cannot be called green;
  • runs production-source, environment, and privacy-boundary checks.

On any violation it stops with two lines: “Startup gate failed closed” and “Do not route or claim capability until repaired.”

The rule that bites

Any capability in the compiled truth that is not on the baseline and is not covered by a checkpoint contract fails verification. Verification failing fails the gate. The companion rules require a state-changing contract to declare its stages, its evaluation requirements, a promotion transition, and an artifact-hash requirement; require recovery to be a registered handler or explicitly non-resumable; and require every contract to point at a capability that exists.

It bites in both directions, and it did so live twice on 2026-09-12. Registering a new capability first blocked startup on the missing contract. Adding the contract first blocked startup on the unknown capability. The documented conclusion: a new capability and its contract are one atomic change set. Neither order alone is safe. The media stack hit the same wall a day earlier.

That is what fail-closed means in practice. It is inconvenient on purpose.

What was proven

That a system can refuse to describe itself as more capable than its evidence supports. The compiled truth says 109 capabilities and 1,042 commands today, and it says 8 of those capabilities are red, in the same file, generated by the same compiler, because the evidence says so.

Next target

The gate binds capability claims to evidence at startup. The open work is binding completion claims the same way at runtime, which is cluster S-D in the audit.

This pattern, one manifest, one compiler, one gate that refuses, is the first thing checked in any agent audit: where do this system’s claims about itself come from, and what stops them from drifting. The contact button opens with this report as the subject.