Skip to content

Record how long a held-back record waits and what the listing shows meanwhile #183

Description

@iderex

Entry six of #46 is answered, and this issue writes the answer down where a
decision lives. The answer, decided 2026-08-24: a held-back record waits 90
days from the report, the window is published in the security policy, and there
is exactly one written extension on a reasoned request.

docs/decisions/0010-a-flaw-in-shipped-software.md decides that an experiment
which finds a flaw in shipped software does not start here in public, and that
the record is written once the flaw is fixed and the affected project has said
what it wants said. It deliberately does not say what happens when neither
arrives. This is that gap closed, so the new record names 0010 in its first
section and says what moved, which is what record 0000 requires of a record
that changes an earlier one.

Why a window rather than waiting indefinitely. Waiting is safest for the people
running the affected software and it hands the schedule to whoever is slowest to
reply, which leaves this board carrying an unwritten record nobody outside knows
exists - the invisible half-finished state this board was opened to make
impossible. Why one written extension rather than a bare window: a date chosen in
advance is sometimes wrong for the flaw in front of it, and publishing on
schedule against a flaw still live in software this organisation ships is a thing
to choose deliberately. The known cost of the extension is that it needs somebody
to answer the request inside the window, which is the failure the window exists
to handle in the first place, and the record has to say so rather than present
the middle option as free.

The half that reaches the runner. Entry six requires the answer to say what
the record looks like while it waits. It appears in lab list as its own dated
state, which says nothing about content. An experiment held back is otherwise
either sitting in asking with a question that says nothing, or not existing at
all, and both make the listing quietly misreport what is running, which is the
one thing that listing exists to prevent.

That reaches two things already fixed and the record has to face both. There are
three states and no others - asking, answered, abandoned - in
docs/decisions/0003-the-experiment-lifecycle.md, and record-state-is-not-one-of-the-three
refuses a fourth today:

git grep -n 'RecordStateIsNotOneOfTheThree = ' origin/main -- internal/check/

So a fourth state is a change to 0003 and to that check rather than a wording
choice, and docs/decisions/0013-how-the-record-format-changes.md is how a
change that invalidates existing records is announced. Whether the dated state is
a fourth state or a field beside asking is the design question this record has
to settle, and neither answer is free.

The 90 days also has to reach SECURITY.md, which is where entry six says the
window is published.

What section three has to list: waiting indefinitely, and a fixed window with no
extension. Section four says what each would have cost, and entry six of #46 sets
both out.

Done when docs/decisions/0022-how-long-a-held-back-record-waits.md exists on the
default branch, carries the four sections record 0000 fixes, names 0010 in its
first section and says what moved, states 90 days from the report and one written
extension on a reasoned request, says what the listing shows while a record waits
and whether that is a fourth state or a field, names what that costs 0003 and
the state refusal, and lists in sections three and four both rejected options with
what each would have cost.

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

Relationships

None yet

Development

No branches or pull requests

Issue actions