Clergy housing rules: Codex adversarial review (2026-09-25)
Recorded by the orchestrator. Codex completed the review (job task-muh133ek-zsbmez), but its sandbox allowed writes only under C:\dev\churchwiseai-web, so it could not write this file. Its full per-finding detail was not kept. The text below is its final summary, quoted from the job log.
"The arithmetic ledger is complete: every published numeric result matches the formulas as written. The serious defects are structural rather than calculator-key errors — one U.S. case presents a definite exclusion without resolving the reasonable-pay ceiling, Canada can return a negative deduction for overlapping claims, and the part-year remuneration rule overstates what the statute/form text establishes."
Findings (reconstructed from that summary)
| id | severity | area | problem | fix |
|---|---|---|---|---|
| CX-01 | critical | CA-05 / T1223 line 8 | rent_or_FRV − other_claims can go negative, and the cascade then returns a negative deduction | Clamp every intermediate line and the result at a minimum of 0. Add the invariant 0 ≤ deduction ≤ remuneration. |
| CX-02 | major | US reasonable-pay (Pub 517) | A US test case presents a definite exclusion without addressing the "reasonable pay" ceiling | Show the reasonable-pay limit as a visible qualitative warning on every US result, and don't present the output as unconditional. |
| CX-03 | major | CA-06/07 part-year | The part-year remuneration rule overstates what the ITA/T1223 text establishes | This is the same issue as Opus critical #1 and Fable F-01; resolve it per the current T1223 form text. |
Invariants the implementation must satisfy (orchestrator's list, from the Codex brief)
- CA: 0 ≤ deduction ≤ remuneration from the qualifying office; deduction ≤ rent_or_FRV; months are between 0 and 12 and are integers; the result never decreases as months increase, all else equal.
- US: 0 ≤ exclusion ≤ min(designated, actual, FRV + utilities); taxable excess ≥ 0; the SECA base includes the housing amount.
Follow-up
Codex runs again in the final verification pass, and must return its findings in its final message rather than writing a file.