Three operator-contract truth debts from the clock-projection gate: probe-scope wording, a missing Contract Ledger, and a live-restated default outside compose parity
Three operator-contract truth debts from the clock-projection gate: probe-scope wording, a missing Contract Ledger, and a live-restated default outside compose parity
Follow-up carved from PR #17117's Approve+Follow-Up review (review). That PR made the behavior-binding clock projection gate executable — canonical comment shape, both token boundaries, resolved-default equality, per-line guidance, declared guidance-block count, and a workflow watch covering its own scan surface.
Three documentation / coverage-boundary debts were explicitly recorded as non-blocking rather than reopening a release-blocking cycle. None is a runtime defect: the runtime AiConfig authority stays singular and effective deployment values are unchanged. All three are places where an operator-facing artifact still says something less true than the gate now enforces.
Filed as one ticket because they share a single root — the projection contract's prose has not fully caught up to the contract its gate enforces — and because splitting them would produce three micro-tickets on the same surface.
The three debts
1. The Compose scope claim is still not precise enough
PR #17117 corrected the block from "every single-input embed" to the interactive embedText path, after review showed bulk work is deliberately routed through embedTexts under the batch ceiling.
That is closer and still overstated. Deadline-bearing probe calls bypass the contention ladder — #17122 landed caller-owned embedding probe deadlines, so a probe carries its own deadline rather than inheriting the ladder. The accurate scope is therefore deadline-free interactive calls, not all interactive ones.
This is the third successive narrowing of the same sentence, which is itself the finding: a scope claim in operator-facing prose attracts overstatement, because the writer knows the mechanism and the reader only gets the sentence.
2. #17115 retains superseded framing and has no Contract Ledger
#17115's body still carries the "every behavior-binding clock" universal wording and its dependency on #17114, which closed NOT_PLANNED on 2026-08-14 without ever producing the derivation table it was cited for. PR #17117's body was corrected to own the declared clock set; the ticket was not, so the two now disagree and the ticket is the more discoverable of the pair.
#17115 also lacks a Contract Ledger — the target-surface / authority / new-behavior / failure-posture / evidence table that every contract-bearing ticket carries. The projection contract is exactly the kind of surface that table exists to pin down.
3. provider-lane-worker live-restates a default the file says lives nowhere else
ai/deploy/docker-compose.provider-lanes.yml sets NEO_OPENAI_COMPATIBLE_BATCH_EMBEDDING_CHUNK_SIZE: "5" as a live key on the provider-lane-worker service. The config default is also 5.
So the file simultaneously carries a projection block stating that defaults live only in configBase.mjs, and a live key restating one. That is precisely the second-declaration-site matches-config-default exists to prevent — and it does not fire, because provider-lanes.yml is outside $composeDefaultParity.profiles.
PR #17117 deliberately narrowed rather than fixed this, with the reason recorded: adding the profile surfaces two further pre-existing restatements in the shared anchor (NEO_EMBEDDING_PROVIDER=openAiCompatible, NEO_OLLAMA_MODEL=gemma4:26b), and clearing those means deleting live keys from a deployment template minutes before a deployment. That was a timing decision, not a verdict — this ticket is where the verdict belongs.
The decision is genuinely open, and it is not "delete the keys". A deployment file arguably should name the model it runs: explicit value-pinning is legitimate operator documentation for an identity, and a poor trade for a timeout. The three candidates need judging on their own terms:
key
equals default
plausible intent
NEO_OPENAI_COMPATIBLE_BATCH_EMBEDDING_CHUNK_SIZE
yes
none obvious — a tuning knob, likely accidental
NEO_EMBEDDING_PROVIDER
yes
lane identity; the file's whole purpose is declaring which provider serves which lane
NEO_OLLAMA_MODEL
yes
model identity; an operator reading a deployment file expects to see the model
Acceptance Criteria
The Compose ladder block scopes the ~47s ceiling to deadline-free interactive calls, and names why probe calls are exempt (caller-owned deadlines) so the exemption is not rediscovered.
#17115's body drops the universal "every clock" wording and the closed-#17114 dependency, matching the declared namespaces × clockSuffixes set PR #17117 shipped.
#17115 carries a Contract Ledger covering the projection contract's target surfaces, authority, new behavior, failure posture, and evidence.
Each of the three live-restated keys is either removed or explicitly classified as intentional identity-pinning, with the classification recorded where the next reader will find it — not in a PR comment.
If any key is classified as intentional, $composeDefaultParity gains provider-lanes.yml with that key exempted by name and reason, so the file is no longer silently outside the rule. If all three are removed, it joins with no exemptions.
Out of scope
Runtime behavior of any clock. No effective deployment value changes.
The projection gate's parser, policy shape, or scan surface — all shipped and mutation-tested in PR #17117.
Widening the clock set beyond the declared namespace/suffix profile. Coverage growth is a separate, deliberate policy edit.
Avoided traps
Deleting the live keys reflexively because a lint would flag them. Two of the three plausibly carry identity information an operator needs; matches-config-default is right in general and its generality is exactly what needs judging here.
Fixing the Compose sentence without recording why. Three successive narrowings mean the next writer will overstate it again unless the exemption's reason is in the file.
Splitting into three micro-tickets. One root, one surface, one reviewer context.
Evidence class
Reviewer source/test audit at PR #17117 head 40b8989b5dcb8eae80c8604474890556dea4b3f2 (exact-head CI green, unit 15m52s); #17114 verified CLOSED/NOT_PLANNED 2026-08-14T14:12:13Z; the two additional anchor restatements observed by adding the parity profile locally and reverting.
Context
Follow-up carved from PR #17117's Approve+Follow-Up review (review). That PR made the behavior-binding clock projection gate executable — canonical comment shape, both token boundaries, resolved-default equality, per-line guidance, declared guidance-block count, and a workflow watch covering its own scan surface.
Three documentation / coverage-boundary debts were explicitly recorded as non-blocking rather than reopening a release-blocking cycle. None is a runtime defect: the runtime AiConfig authority stays singular and effective deployment values are unchanged. All three are places where an operator-facing artifact still says something less true than the gate now enforces.
Filed as one ticket because they share a single root — the projection contract's prose has not fully caught up to the contract its gate enforces — and because splitting them would produce three micro-tickets on the same surface.
The three debts
1. The Compose scope claim is still not precise enough
PR #17117 corrected the block from "every single-input embed" to the interactive
embedTextpath, after review showed bulk work is deliberately routed throughembedTextsunder the batch ceiling.That is closer and still overstated. Deadline-bearing probe calls bypass the contention ladder — #17122 landed caller-owned embedding probe deadlines, so a probe carries its own deadline rather than inheriting the ladder. The accurate scope is therefore deadline-free interactive calls, not all interactive ones.
This is the third successive narrowing of the same sentence, which is itself the finding: a scope claim in operator-facing prose attracts overstatement, because the writer knows the mechanism and the reader only gets the sentence.
2. #17115 retains superseded framing and has no Contract Ledger
#17115's body still carries the "every behavior-binding clock" universal wording and its dependency on #17114, which closed NOT_PLANNED on 2026-08-14 without ever producing the derivation table it was cited for. PR #17117's body was corrected to own the declared clock set; the ticket was not, so the two now disagree and the ticket is the more discoverable of the pair.
#17115 also lacks a Contract Ledger — the target-surface / authority / new-behavior / failure-posture / evidence table that every contract-bearing ticket carries. The projection contract is exactly the kind of surface that table exists to pin down.
3.
provider-lane-workerlive-restates a default the file says lives nowhere elseai/deploy/docker-compose.provider-lanes.ymlsetsNEO_OPENAI_COMPATIBLE_BATCH_EMBEDDING_CHUNK_SIZE: "5"as a live key on theprovider-lane-workerservice. The config default is also5.So the file simultaneously carries a projection block stating that defaults live only in
configBase.mjs, and a live key restating one. That is precisely the second-declaration-sitematches-config-defaultexists to prevent — and it does not fire, becauseprovider-lanes.ymlis outside$composeDefaultParity.profiles.PR #17117 deliberately narrowed rather than fixed this, with the reason recorded: adding the profile surfaces two further pre-existing restatements in the shared anchor (
NEO_EMBEDDING_PROVIDER=openAiCompatible,NEO_OLLAMA_MODEL=gemma4:26b), and clearing those means deleting live keys from a deployment template minutes before a deployment. That was a timing decision, not a verdict — this ticket is where the verdict belongs.The decision is genuinely open, and it is not "delete the keys". A deployment file arguably should name the model it runs: explicit value-pinning is legitimate operator documentation for an identity, and a poor trade for a timeout. The three candidates need judging on their own terms:
NEO_OPENAI_COMPATIBLE_BATCH_EMBEDDING_CHUNK_SIZENEO_EMBEDDING_PROVIDERNEO_OLLAMA_MODELAcceptance Criteria
namespaces × clockSuffixesset PR #17117 shipped.$composeDefaultParitygainsprovider-lanes.ymlwith that key exempted by name and reason, so the file is no longer silently outside the rule. If all three are removed, it joins with no exemptions.Out of scope
Avoided traps
matches-config-defaultis right in general and its generality is exactly what needs judging here.Evidence class
Reviewer source/test audit at PR #17117 head
40b8989b5dcb8eae80c8604474890556dea4b3f2(exact-head CI green, unit 15m52s);#17114verified CLOSED/NOT_PLANNED 2026-08-14T14:12:13Z; the two additional anchor restatements observed by adding the parity profile locally and reverting.Parent: #17072. Follows PR #17117 / #17115.
Retrieval Hint:
provider-lane compose default parity live restatement deadline-free interactive contention ladder scope Contract Ledger #17115Origin Session ID:
471d17f2-777c-4676-a137-fa37a9ac834d