V-1 · a renumbering broke a cross-reference
V-1 — v3.1 carries one stale internal cross-reference from v3.0.
Measured 2026-09-10, docs/source/spec-v3.1.md:69
| what | value | reading |
|---|---|---|
| §2 table, row 1 | 10 | cites "the bb2g-elections monorepo (§10)" — correct in v3.0, wrong in v3.1 |
| correct target | 12 | §12 is One build, where the monorepo is specified |
| §10 in v3.1 | — | is Vote centers — the reader is sent to polling places |
| other §10/§11 citations checked | 4 | L6, L513, L525 and the changelog all correctly reference the NEW meanings |
A renumbering silently invalidated a cross-reference. Nothing in the document is wrong on its own terms — the row is right, the section is right, only the pointer between them rotted. This is the exact failure a version register exists to catch, and it was found by checking every §N citation against the section titles in both versions rather than by reading the prose.
Version 3.1 inserted two sections in the middle of the document. That pushed One build from §10 to §12 and Before anything binding from §11 to §13. Four citations were updated. One was not.
The published copy on this site corrects it, and says so in the document rather than fixing it silently.
V-2 · the corrected copy violates the spec that governs it
V-2 — the "corrected" copy violates the specification that governs it. Newer is not better, and the direction of the regression is the dangerous one.
Measured 2026-09-10, line-by-line diff of all three copies against v3.1 LOG-7
| what | value | reading |
|---|---|---|
| C line 151 | 1 | "**Tamper-proof**, with a full report" |
| B line 149 | 1 | "**Tamper-evident**, with a full report" — B is the honest one HERE |
| v3.1 LOG-7 | — | "The word tamper-proof MUST NOT appear on any BB2G surface" |
| v3.1 §2 row 6 | — | "Tamper-evident, never immutable. The word tamper-proof is withdrawn from every BB2G surface." |
C is better than B on four of five differing passages: it completes the anchor→witness conversion, adds the two-line definition of "anchored to", and fixes the StrongRooms's possessive typo. On the fifth it strengthens a deliberately weak claim into a forbidden one. Publishing C — the obvious reading of "use the corrected version" — would have put a word onto a live BB2G surface that the governing specification forbids by name, on the exact subject (the audit log) that finding C1 proves the system does not achieve. The regression is small, one hyphenated word, and it points directly at the system's weakest claim.
This is the finding worth carrying forward, because it inverts the obvious instinct. Of three copies of the integration specification, one is plainly the corrected one — it completes a terminology change the others abandoned halfway and adds a definition the others lack. Publishing it is the natural move.
On one line it changes tamper-evident to tamper-proof. Requirement LOG-7 of the specification governing this system reads: "The word tamper-proof MUST NOT appear on any BB2G surface." The system is tamper-evident — it makes alteration detectable by an independent party. It does not prevent alteration, and finding C1 of the audit proves it: the hash-chained log can be rewritten end to end and its own verifier still reports success.
So the "corrected" copy is better in four places and forbidden in the fifth — and the forbidden change points directly at the system's weakest claim. The merge is on the next page.
How this page works
A 95-second spoken walk-through of what is on this page and why it matters.