From cde73560f029235959b7775a8466fca059c3f34e Mon Sep 17 00:00:00 2001 From: PhysShell Date: Sat, 29 Aug 2026 08:38:37 +0000 Subject: [PATCH 01/13] RH-M0: freeze the external-validity manifest Preregisters the real-history lineage experiment before any B3 run against the STS holdout. No correctness result belongs to this commit. Frozen here: - 63 truth target hashes: 50 natural, 4 rename, 9 copy - baseline definitions B0/B1/B2/B3 - truth protocol: two blinded labels, human adjudication, hash freeze before the first STS B3 run - verdict taxonomy, per axis, no monolithic PASS - 26 input artifact hashes from RH-0, RH-O1 and the targetability census Primary holdout is the 50 natural targets only. The 13 hard-transform targets are reported separately and never enter the primary denominator. The old hard-transform criterion "B3 has fewer unsafe relation errors than B1/B2" is replaced: both baselines require same_pattern_id, pattern_id includes the path, so across a rename or copy they return unresolved, which is not an unsafe error. Their unsafe-error count is naturally zero and "fewer than zero" is unsatisfiable. The criterion is now safe added resolution: zero unsafe errors AND at least three more correct resolutions than the better baseline. merged_symbols has no observation source and none was invented. MERGE-INCONCLUSIVE is the fixed ceiling for this experiment. Step-1 contract at canonical merge 011c1362861f6b8b20c45e8ebd5bcb912401c1c0, reviewed head 6dcc02f7d82bebeb5db9be83f77ab8c5455f5692. Co-Authored-By: Claude Opus 5 (1M context) Claude-Session: https://claude.ai/code/session_015vtUmvBDf69ccY5ju3PSHV --- research/rh-m0/rh-m0-manifest.json | 1131 ++++++++++++++++++++++++++ research/rh-m0/rh-m0-manifest.sha256 | 1 + 2 files changed, 1132 insertions(+) create mode 100644 research/rh-m0/rh-m0-manifest.json create mode 100644 research/rh-m0/rh-m0-manifest.sha256 diff --git a/research/rh-m0/rh-m0-manifest.json b/research/rh-m0/rh-m0-manifest.json new file mode 100644 index 0000000..535e006 --- /dev/null +++ b/research/rh-m0/rh-m0-manifest.json @@ -0,0 +1,1131 @@ +{ + "artifact": "rh-m0-manifest", + "b3_executed": false, + "baselines": { + "B0": { + "rule": "always unresolved" + }, + "B1": { + "candidates": "for the target endpoint, candidates on the opposite side with same_pattern_id", + "decision": "unique minimum abs(start_line_A - start_line_B) => continued", + "never_emits": [ + "new", + "ended", + "branched", + "merged" + ], + "tie_or_no_candidate": "unresolved" + }, + "B2": { + "candidates": "same_pattern_id AND same enclosing_symbol", + "decision": "exactly one candidate => continued", + "never_emits": [ + "new", + "ended", + "branched", + "merged" + ], + "otherwise": "unresolved" + }, + "B3": { + "at_canonical_merge": "011c1362861f6b8b20c45e8ebd5bcb912401c1c0", + "contracts": [ + "finding-lineage/v1", + "finding-lineage-decision/v1" + ], + "reviewed_step1_head": "6dcc02f7d82bebeb5db9be83f77ab8c5455f5692", + "rule": "the exact canonical frozen Step-1 policy" + }, + "observation_sources": { + "anchored_content": "RH-O1 adapter, exact physical line bytes, terminator excluded", + "enclosing_symbol": "RH-O1 adapter, Roslyn 4.9.2, canonical Git blob, spec-frozen display format", + "line_drift": "holds iff start_line_A != start_line_B; no threshold", + "path_rename / copy_record": "git diff -M50% -C50% --find-copies-harder", + "still_unavailable": [ + "renamed_symbol_record", + "reformatted_paths", + "merged_symbols", + "boundary: enclosing-site-added", + "boundary: enclosing-site-removed" + ] + } + }, + "branch_capability": { + "census_status": "the targetability census established STRUCTURAL POSSIBILITY only: 24 of 25 copy pairs carry a branch-capable source, but a finding actually sits on such a source in only 5 pairs, 16 candidate occurrences, 9 selected targets. This asserts nothing about branch truth.", + "if_three_or_more_and_any_endpoint_lost_or_invented": "FAIL/PIVOT", + "if_zero_to_two_genuine_branches": "BRANCH-INCONCLUSIVE regardless of B3 output", + "validated_requires": [ + ">= 3 adjudicated truth groups whose truth label is 'branched'", + "those groups span >= 2 distinct revision pairs", + "exact successor endpoint-set accuracy = 100%", + "zero silent cardinality loss", + "zero invented branch endpoints" + ] + }, + "contains_correctness_result": false, + "descriptive_strata": { + "affects_inclusion_or_thresholds_or_target_count_or_labelling": false, + "carried_correction": [ + "Identical pattern_id multiset means only that (path, rule, message) multiplicities are unchanged.", + "It does NOT imply identical physical occurrences, anchors, enclosing symbols, anchored content, or trivial lineage." + ], + "computed_after": "M0 freeze only", + "full_observation_tuple": [ + "pattern_id", + "start_line", + "start_column", + "enclosing_symbol_hash", + "anchored_content_hash" + ], + "strata": { + "S0": "full observation multiset identical", + "S1": "pattern_id multiset identical, full observation multiset differs", + "S2": "pattern_id multiset differs" + } + }, + "digest_note": "the SHA-256 of this manifest lives in the sidecar rh-m0-manifest.sha256; a digest stored inside the file it describes cannot equal that file's digest", + "frozen_input_hashes": [ + { + "bytes": 5855, + "exportable": true, + "file": "rh0-environment.json", + "sha256": "3fe4892175d678a2b95b1128be1db00f51cc8d470d226076fe26b5538ad639a0" + }, + { + "bytes": 1125100, + "exportable": true, + "file": "rh0-frame-sts.jsonl", + "sha256": "1b5eaaa962fa0f692ce636e1dcc94761a7df4b18962b328679d810ae8e49f26a" + }, + { + "bytes": 113197, + "exportable": true, + "file": "rh0-frame-ownnet.jsonl", + "sha256": "6590cedd99fd6078332f6f6ed3e1d5d20c66364d182acbe62f07937f40582e92" + }, + { + "bytes": 42522, + "exportable": true, + "file": "rh0-selection-preview.json", + "sha256": "c8645a79e4ba6752d2627b6bf5159ffe06a222ed4ceffb3484a43254103e5587" + }, + { + "bytes": 2497, + "exportable": true, + "file": "rh0-toolchain-sensitivity.json", + "sha256": "e50a36c2c789371db1401c1512a6134aeebede46e49b12ed3a1456449ac599e5" + }, + { + "bytes": 11111, + "exportable": true, + "file": "rh0-signal-observability.json", + "sha256": "6188bd381045f3f3cdef72c7b1dfd0f37f2a1d05d192adbcfdc8e09322da6f6a" + }, + { + "bytes": 2827, + "exportable": true, + "file": "rh0-bundle.sha256", + "sha256": "a6e30f693f36e760f1ebc42165963d206d0eb04abf7b77db815fe7e1084cc8a9" + }, + { + "bytes": 10164, + "exportable": true, + "file": "rh0-o1-observation-spec.json", + "sha256": "9e82b78d55f7e120357d086523ba76a113e6a15de8be0d179fbbff72f2a488e0" + }, + { + "bytes": 8403, + "exportable": true, + "file": "rh0-o1-observation-vectors.json", + "sha256": "00e8507db4b851dbc30acaf1796f5e5292ed1213d940868e6c46e705dfb5e54e" + }, + { + "bytes": 6133, + "exportable": true, + "file": "rh0-o1-coverage.json", + "sha256": "c074bdc6e9dbaf588061f73c4d00f70aa61bb664131cfddbd86f670abf697872" + }, + { + "bytes": 1971, + "exportable": true, + "file": "rh0-o1-bundle.sha256", + "sha256": "1b816e92619f2abbc80efe6cd7371cc9472dcb2e2799b4c447fb60ed47821e0f" + }, + { + "bytes": 4768, + "exportable": true, + "file": "rh0-m0-pending-corrections.json", + "sha256": "aef9aef2bf1adbf13b4d238f1fefeaf180669dea4b22c71dfaa5951d22e54116" + }, + { + "bytes": 41469, + "exportable": true, + "file": "rh0-m0-targetability.json", + "sha256": "1c25cd6ca15c8e66be8bcb86ded3357c6cf2b297825ce6e67d60ca81360faa4b" + }, + { + "bytes": 93, + "exportable": true, + "file": "rh0-m0-targetability.sha256", + "sha256": "e8ed0af417cd504242af4ddde79c7840b352542cf8f1ba28ea6f56ef5713bac0" + }, + { + "bytes": 15512, + "exportable": true, + "file": "obs-adapter/Program.cs", + "sha256": "77f72efcac7b44093fd86e225d3e56f138685bba25082889a3cd87f12408cf31" + }, + { + "bytes": 582, + "exportable": true, + "file": "obs-adapter/ObsAdapter.csproj", + "sha256": "bff9cb29c17456f11c1910595f01b343081051077d895a14b0ff86b2e2aaec53" + }, + { + "bytes": 2210, + "exportable": true, + "file": "vectors/setup.sh", + "sha256": "ea5db72931a94b8cb092972095dda00ebfb105534c1e17714b8a7cccc562cd12" + }, + { + "bytes": 7547, + "exportable": true, + "file": "vectors/observed.jsonl", + "sha256": "081b63180adae18b647726b8a66ad0f91751fea73b53c29a8a00a0d4c880df45" + }, + { + "bytes": 2567, + "exportable": true, + "file": "probe.sh", + "sha256": "59e0a566b84ed8ed1b1882108bb6e5b29b224ce52475c1caeaab2e26f4b5caf9" + }, + { + "bytes": 2835, + "exportable": true, + "file": "make_requests.py", + "sha256": "e01ee9d61ead3731279deaa24854468d3eaed7543d86775d461ccfc2954ca1d2" + }, + { + "bytes": 7540, + "exportable": true, + "file": "build_coverage.py", + "sha256": "4e1b8c1f0f3d797cdcfb66a002983f96d7b1c647dafe68e3eec1f7ba7d4e8c09" + }, + { + "bytes": 9979, + "exportable": true, + "file": "build_vectors.py", + "sha256": "f4f5f48e0550112bfee7de418f800eb4230fd532a89f7ad83aff6d41bbf576bf" + }, + { + "bytes": 14751, + "exportable": true, + "file": "build_census.py", + "sha256": "567062fa0a6dbde62773b09642be472e78caff23ed0d34c78b9fdc74d0b02801" + }, + { + "bytes": 12741624, + "exportable": false, + "file": "probe/requests.jsonl", + "note": "STS paths", + "sha256": "234bdcc89e9e17f2e9cb6e5f9af848ed671ab50c1773baa59290a25554cc0c1c" + }, + { + "bytes": 25733878, + "exportable": false, + "file": "probe/observed.jsonl", + "note": "keyed to STS paths", + "sha256": "65b4f13868aed0c19b8eb89d44510f5b57c7c33be3a77c2115dea597a0fd9eb3" + }, + { + "bytes": 25373291, + "exportable": false, + "file": "probe/endpoints.jsonl", + "note": "carries pattern_id values", + "sha256": "2fb4ec62ca97a1916ea0081f810f6a71f2ff284b9547294a628d3819b9808506" + } + ], + "frozen_targets": { + "count": 63, + "export_policy": "target hashes only; STS raw path / rule / message never leave the machine", + "frozen_now": true, + "targets": [ + { + "a_sha": "8fc3e85a91e6a3382e7943c30ffebb0e73bf7248", + "b_sha": "78a156675dbae402072e8d459b432adb4d95ebe7", + "class": "natural", + "side": "A", + "target_hash": "019c1917a561054077057d91eb836960755895bcba2b91cd31469c2bf2f0ffff" + }, + { + "a_sha": "0976c490c3dc1d2d902ad56f018b697748d1846f", + "b_sha": "e75247c4aa5f2d1b9a9c4882d6aad4fd960d57b6", + "class": "natural", + "side": "B", + "target_hash": "00456dec6c0b12ddc1a9fbfe97f913d3eb453e064929047d40d36ec7f8598586" + }, + { + "a_sha": "3dec1a7fea70fba8943aad4a8d830f8943ed08e3", + "b_sha": "77c2a1201925c053c0ccb32e99b164d91544bdf3", + "class": "natural", + "side": "B", + "target_hash": "01b4cba941583391be4d5d925a9f4ee6a731aaf995f40696dd2a12c5336b3d71" + }, + { + "a_sha": "24b87dbe8b9b0a69d279d3958c69fbf6273ad140", + "b_sha": "65dd590f169d643cab8288ae061e97947a1b630c", + "class": "natural", + "side": "B", + "target_hash": "0031b354794d1f364c9a0039f8da092ef3121b28a69bbcdf626bf67d121b626f" + }, + { + "a_sha": "84c043b5176ce7233a510870027bf66c151460c9", + "b_sha": "b616f1866c40bd3452929107a4b6b3a884bf3476", + "class": "natural", + "side": "A", + "target_hash": "0005e46875760299c4c69084934b4334bd23467bcd7e7d5edacbe663aaac91bf" + }, + { + "a_sha": "926cafc5aeddf77741fbfc46dc65eae8d09e187b", + "b_sha": "35a05f2862db661f641740e9724e0fad79e3e1df", + "class": "natural", + "side": "B", + "target_hash": "0065288c60cd88ea40e604183d59dd9d6c9d2d7fb89564d80c8ce1e497dedbec" + }, + { + "a_sha": "43b7b873cc2343483298f2455fafc9245d435d21", + "b_sha": "24c0616e7478b685c42e59c0471f1c8b7ee05cc5", + "class": "natural", + "side": "B", + "target_hash": "0003eea893224d287ebfe4f7e7bbf6ef4fcd1e86f293bd702cd10d72992b7010" + }, + { + "a_sha": "44dc8219ea4891fa9a171b0e818e3e0bb4a7b402", + "b_sha": "23934dee4e5b765209dbf986276b2d23e2398725", + "class": "natural", + "side": "A", + "target_hash": "001877050d9d7798641f374cf298b71a36b4d310802645609fc3d95c767afef6" + }, + { + "a_sha": "4985c3875c877494245f4de9530c3e2f1bd5b2f4", + "b_sha": "6dbe1fe1dd6b3f0a1e413a62aa34e01f275d9963", + "class": "natural", + "side": "B", + "target_hash": "0049ac5a22b93af6cf1e9153d03b27b1bb4bf87acf4dca2619c8cd501d908b96" + }, + { + "a_sha": "23c1ffb619fbfed7583099174865861cc865e1cf", + "b_sha": "dcaa21029d62ba69185c6245cd81d2640f4f0b75", + "class": "natural", + "side": "A", + "target_hash": "013fcf3aa03053f4af146b2f3d0cf28f750b58e6ce64420484b7efe72dcfd358" + }, + { + "a_sha": "7f456ee66a50d60ec266f338e285d63545d96bc4", + "b_sha": "32c0ee7223fa53165a9564c23105e9f18c08003d", + "class": "natural", + "side": "A", + "target_hash": "00275052e98fb1cf463bf3f349ea6867ffcef385a2d2c4a5d8a856be453d9fea" + }, + { + "a_sha": "35af9e7e9f68a5a785be672597a866a54dd7f691", + "b_sha": "0b8926d23e5af365ae3985528216399454c4e32d", + "class": "natural", + "side": "A", + "target_hash": "009afeaaf18eecbc4af19cd05593f3820390d397a4bd3160503f1a73984e47de" + }, + { + "a_sha": "94abf2c11eb293d79ad6a1ecca93823638d38a3e", + "b_sha": "4ce2c9d9bdb9ed80217aa1b6461007ba95df605e", + "class": "natural", + "side": "A", + "target_hash": "023bfe79660d09999a3cdfb7221a6d26c1f7d6e98f39a7b4dba0ab3aed322129" + }, + { + "a_sha": "4b207123b8c80f3fa2c5552b9cedc879050842a0", + "b_sha": "d8b278181910858024ec6a8be539fd6be1eb31d1", + "class": "natural", + "side": "B", + "target_hash": "000baa05235e8a5786daf67ac3d62be77d38c5cbf28d53f33bf4b908f25b070a" + }, + { + "a_sha": "cb1c5efb1081484e634583e9f40f99d50a9984e7", + "b_sha": "25307b509e3eb236724a703b7e29c55edad198f9", + "class": "natural", + "side": "B", + "target_hash": "000540ec2181e16dcc3f2b023d7a1be5826401e081f24553ed46a19a62d93e2c" + }, + { + "a_sha": "670485e81c4c291281da91a48175958bdaaae5b9", + "b_sha": "b1524ccd9d578ceead7eb29d47dfce7a6a3e1559", + "class": "natural", + "side": "B", + "target_hash": "003ec0dd78fb7edc35072e9b9e89693be89e828a65ee6700465363d0cc968205" + }, + { + "a_sha": "5338bb2f4b00b0d4a5e0144a11d6d4d9d65505fc", + "b_sha": "3b9a55b7768a8ca1b278dc6290883fd721e466a4", + "class": "natural", + "side": "A", + "target_hash": "017d2327c4155d8a6ce4ff264cffa723b37ac6a5bfa9d92d241b86e0bba9de10" + }, + { + "a_sha": "d36efc2ec4871c188eb946c254a78bc02879e667", + "b_sha": "2e0d263bf779c5a8be31795377f52db14d6dc723", + "class": "natural", + "side": "A", + "target_hash": "0018ff9a1033667afa8e949653994f24c37457573bbe768a1475a924c08de32e" + }, + { + "a_sha": "2f36bc3746c8ae5f9b25c1871b3b3b3e4aff599d", + "b_sha": "24ae36a2e0824800b3e88b7f02bc71f1c2a091d8", + "class": "natural", + "side": "B", + "target_hash": "002a7ecd549f356651affa8528804208e5cd24c0103828d1bd2ace79cad12c6b" + }, + { + "a_sha": "b507027502b565d9ceb1ef35533da945800b35fa", + "b_sha": "af6f78adebd0c7bd0f7e14e6978f18bd3fa1b2d0", + "class": "natural", + "side": "B", + "target_hash": "01979a5ce47cfa11de6272a1f0e4438f14b74cb478c2642924fdf12feb50804f" + }, + { + "a_sha": "474a064c28c3f8bdefac09ceac8d9fbced4d0e36", + "b_sha": "9d690194a0687c843f9df6bb3a8eba6ca0297d1b", + "class": "natural", + "side": "B", + "target_hash": "015d7586ae01889c1cd6b1923de9e45c947a50c859f00291ceb520b1892a5dbc" + }, + { + "a_sha": "3be7d79e7737f92d79fc2f4eedae1c248eb96b14", + "b_sha": "7650c1c7d839a481f4cac516c6d76e7cb53cc176", + "class": "natural", + "side": "B", + "target_hash": "00435514a32de9b3dedd318940847a7b11136c029a7bd2f4333bab00a27293f0" + }, + { + "a_sha": "9dd630b901e679c1e4b285b5da9636bc87a24c99", + "b_sha": "08efc9cf55e135067685fa7e1b43c761e38105f2", + "class": "natural", + "side": "B", + "target_hash": "007eb752462d00ac0af980f842606dcfa256b33b6c07e654132908fcf51393f1" + }, + { + "a_sha": "39cf720e3576a3dff4cfbceb1eef0011b4862771", + "b_sha": "6990905d4b5f1f3dad8e4d46a4fd33212e6efa97", + "class": "natural", + "side": "B", + "target_hash": "0007140cf48a2d6974798ad19b1c54e5a813d94b31df84f730b72acc8632d2ea" + }, + { + "a_sha": "1ca6808d21afe8c16c7d2999424361591bc73ece", + "b_sha": "9b104a46f4bdec3e50fc0f9f0c9a99aa3ae35c0f", + "class": "natural", + "side": "B", + "target_hash": "00cfaeb3504d25eb18e82c07e9864fca93ff31583cb635c87af6ee65b847560d" + }, + { + "a_sha": "4ca10bdb5a66c503884251b2bbe2881881248c0f", + "b_sha": "a3fdc19a4065e179f7260f8add250e57eeef1437", + "class": "natural", + "side": "B", + "target_hash": "0003f30fb1589f434372aa670f84226e18e02d01864672ee9d36223c92d94fc5" + }, + { + "a_sha": "bb4a027571b1da3ca20fc10f08480e346f7810bc", + "b_sha": "98ae2eb1d5dadce8bdfbf71177b974afa3cfe88d", + "class": "natural", + "side": "B", + "target_hash": "009d403c13b1e4410505c5c1e3e76f043744175b3dbc6f647b6e378321268b71" + }, + { + "a_sha": "2e85fa39ea9f360998276e6108c2b7f847078600", + "b_sha": "d91e0531c0845380f1192efcc0f3abeefb7e7586", + "class": "natural", + "side": "B", + "target_hash": "00cc39ace264e87b363819dfb852e049e010ecb670296cbe95cc502b99f464ad" + }, + { + "a_sha": "e138e5f7b9eaad81ae3304a8c88445c89d4de552", + "b_sha": "f2693d94fc990dd9aef0493b3730e7d4720ff460", + "class": "natural", + "side": "B", + "target_hash": "00743af11a8b0727d89c15427f708b28586055f057595ce4d8ca79029ff196c7" + }, + { + "a_sha": "db41d27b875f00b1b7fe86bf428ba93df3f845bc", + "b_sha": "8bad2c5fb7170d309d292ddbf6490bfb1754df67", + "class": "natural", + "side": "B", + "target_hash": "004a5885c8e7fab7efd8e3c7cc92640dbddae359fc8741c3364e0031eec68b8e" + }, + { + "a_sha": "1cc602f56bbcae60fb2f234806a2fb391f0361b5", + "b_sha": "c68b2ae6aa8774ffa3726d52d7acb15df1fb736a", + "class": "natural", + "side": "A", + "target_hash": "00536787a5e629329708c08cc54dabd4d291a2aea126f383e6df3fd6f05a5e3e" + }, + { + "a_sha": "1c1b289992ac87ea222b45b878ba9616a8c59e45", + "b_sha": "21b5ec4f59a56b3bbcced67f04d0c98955a487ae", + "class": "natural", + "side": "A", + "target_hash": "0113d20f113df7cc941e5155a20ab1c93a358f09957670e1135a0a790dc983b4" + }, + { + "a_sha": "68f0f0756a7b97dcb8be82d4ae963574320cf594", + "b_sha": "0966396986c6e8218c04e7141668ba0819bea01a", + "class": "natural", + "side": "A", + "target_hash": "008e87d4504821e93c6f6b9847824f33f69cfc5f14b9f88f989e50559ed1fd51" + }, + { + "a_sha": "4bb8e379dff83c47bce3081449bafbf05040071c", + "b_sha": "836a0835c512354db26411ee8ee64b27ab61a2b0", + "class": "natural", + "side": "A", + "target_hash": "0073f9d195a1be495bbd15709ba4df7398edb93683ec57afdb49e3a4b4422a64" + }, + { + "a_sha": "6f2d61e17cd0cc4a717d4689030c5c3df63b1cdb", + "b_sha": "7a1901e53c20c2a35d74d43a24c4961489d3bfbe", + "class": "natural", + "side": "B", + "target_hash": "016462dc819081df1e48d7c19e0b26e252aa77399776d321ea10cf573e73eeb9" + }, + { + "a_sha": "1ea89e3cad197e341ec8a2fcfe58b21d12285c56", + "b_sha": "a7390ceafbefb2c0c1c50dc2ac6bbfb8705e3879", + "class": "natural", + "side": "A", + "target_hash": "003611ada3786179bf831cdc94ae188e28a5358aac52636a46f1720ac2911faa" + }, + { + "a_sha": "de8ebce166416a5b96ba8183d581e7d580e488be", + "b_sha": "90a6a515d8cf0ee6e27862e616922da8f7cc20b5", + "class": "natural", + "side": "B", + "target_hash": "00d2ccff1fddfc486af0fcdb09aa74670e4fe3ecd93b3fcce1366c8e321a0a0a" + }, + { + "a_sha": "763827c1cd58b26cd07fbcaa661de438fa382f03", + "b_sha": "0e05adb3645392005176066c742ed5f832157f6f", + "class": "natural", + "side": "B", + "target_hash": "004d1318d836d2ea2d91b471807b63fad497fc5556f87175882722fc7b4d9353" + }, + { + "a_sha": "d99620c4a6d5faaa19b60049101d71b1aece4807", + "b_sha": "39ddadaf2a5afb5ed2d6d22bd8b1a05c2b162408", + "class": "natural", + "side": "A", + "target_hash": "012ae702ab92667178300e29213d7dcbca3d90e1af0f40e6f7f987c0425ae507" + }, + { + "a_sha": "831c24e38d23e5f7fb6b533ad95f79679b9259dc", + "b_sha": "23fe9a5fdca24c1df38a670e84ae71fbf9715cfd", + "class": "natural", + "side": "B", + "target_hash": "00a94225e1d38887c62b7f1d4e8269979c3e9f9cdf64e7def533876f7650dc89" + }, + { + "a_sha": "ee291896d0e4965afa4bbc966d5871b152dc64ff", + "b_sha": "df906d4231baa3692147357f8e015db535ba1899", + "class": "natural", + "side": "B", + "target_hash": "0154e12685dfbb3b64c5d5aeeed5f6c81dd348986eb4d92ea245428e5b6bcf83" + }, + { + "a_sha": "61afc0f97bc294972be1f1998ec4557642d028a7", + "b_sha": "092ffb3e914f3300a706cbe744acac57c4adb5f4", + "class": "natural", + "side": "B", + "target_hash": "013f6d91bcd812455ee0f373d2e380852eae034dc94e44ee9fb103def8cedb08" + }, + { + "a_sha": "38238bab8a358ca3dd0021b0db5239158a8d3aaa", + "b_sha": "fb9274afaf49d385599b08e7af4a2f50f63249b4", + "class": "natural", + "side": "B", + "target_hash": "014ad6b74e7a5817ef14e942d919f171df15f09abdbab42fe6aa545020e9f4b8" + }, + { + "a_sha": "2ea25fa26bd14092d769c22f5e06eaee810aa764", + "b_sha": "17ab5013d58abffbff61bfff85aa35288631320b", + "class": "natural", + "side": "A", + "target_hash": "002de59aeda9403d1402503f882f783407893c7b9b768949acfe1790d8a8fe6e" + }, + { + "a_sha": "34e395d72eb030dbf9e58428bb9e45f45ef38841", + "b_sha": "a0eef7e2507e57dff958e278a4ebeb0073fd833b", + "class": "natural", + "side": "A", + "target_hash": "00cb5749e99a06a3f1f3305dab00a2776184c0c8593e110f4025211d04da0d0c" + }, + { + "a_sha": "188c08130fca39575e9865fe5970d551c5b883e4", + "b_sha": "43e13bce8cc84845085dc93630c72521b8bfc0f1", + "class": "natural", + "side": "A", + "target_hash": "000b0eec287d314b2212bd01a94138fd885e663132c7c8bebc47fe0b09a48ec0" + }, + { + "a_sha": "98ae2eb1d5dadce8bdfbf71177b974afa3cfe88d", + "b_sha": "fe1d8f020cd6e5645e472b4962695ea1d9e83352", + "class": "natural", + "side": "A", + "target_hash": "0047992bd70a6a98a165b7bf16d80d5c42e96dca661c25e86c0cefc26493dfb0" + }, + { + "a_sha": "91a968d769b3faf70075d6ba64338b2b8e279e0d", + "b_sha": "de93f04f8f5e541e6817d49d39ad5ea51d1ba69b", + "class": "natural", + "side": "B", + "target_hash": "00024fb3fca0cdaa5cb674e0687d62acc5e8bc66d78b6229a53762e405473716" + }, + { + "a_sha": "40fedf3a94963e876f9e528647f90e4159fea575", + "b_sha": "cf540cfc1be063d8ee90eae8d4d94de329271cee", + "class": "natural", + "side": "B", + "target_hash": "01496bbd32a213c0975e8511d94173056d33fe343db16d00d6afc552e209f9bc" + }, + { + "a_sha": "ced633eaab3c40ad76a7e598ad04ce4d747ad140", + "b_sha": "39a2b4209ae318740af9fe70012bb9ee2f41cbca", + "class": "natural", + "side": "B", + "target_hash": "0033bb86cf87f5d4557bbd7841a3bdf9d68635c1cfcf4671d6d035a6777ba65f" + }, + { + "a_sha": "56082d530eed27cc951f49c5f1be87490a26c665", + "b_sha": "6566eaff07b5819abe1a10441c6b56bde0a489af", + "class": "rename", + "side": "A", + "target_hash": "b49985e047cafc1c27295577813f382674b0bc60423d57afb0fe6d40a87f9ed4" + }, + { + "a_sha": "085887bef5635148ae68820f522f69ccb7fd4e60", + "b_sha": "151b6c7c95251e88a3532ac44bc2a37e4182dc32", + "class": "rename", + "side": "A", + "target_hash": "bd4fc6b36d94eede561328be9f222f5e57d7aa1e9e0558c2f61e53ffe55003e7" + }, + { + "a_sha": "43e13bce8cc84845085dc93630c72521b8bfc0f1", + "b_sha": "45eca2c5d94c62845b559f3b77fbe2402ca4b2ae", + "class": "rename", + "side": "A", + "target_hash": "20d7910d844d8e59daa2980a277ab069d1b39ca766be1cd92ce7188d4754a6a1" + }, + { + "a_sha": "487adaa5659830f0c86b0b7a114384f4b6d89742", + "b_sha": "013e0f53f0c1d543bb787958f7db0f3db39dc802", + "class": "rename", + "side": "A", + "target_hash": "1c25a988c9d752f505e2143a3a44e8ea541641c8c8f955ff50066ecfe7a2f220" + }, + { + "a_sha": "24b87dbe8b9b0a69d279d3958c69fbf6273ad140", + "b_sha": "65dd590f169d643cab8288ae061e97947a1b630c", + "class": "copy", + "index_within_pair": 0, + "side": "A", + "target_hash": "215657260b1b2ae93307264209246d6ba33439be7b4d892db9f0d67cdc5c2919" + }, + { + "a_sha": "24b87dbe8b9b0a69d279d3958c69fbf6273ad140", + "b_sha": "65dd590f169d643cab8288ae061e97947a1b630c", + "class": "copy", + "index_within_pair": 1, + "side": "A", + "target_hash": "271b65a6319bab9eddf88287d6e58ba6ff77f01d7e32f095248fa1274762ef97" + }, + { + "a_sha": "382e47831ba349a1531af31c083f0698e7081a6d", + "b_sha": "a2a91589e4ec029db729f865a740f35e28615a9e", + "class": "copy", + "index_within_pair": 0, + "side": "A", + "target_hash": "2e8c01a1088b2297b02ebe58f6d32b1bd7768fd17c6192b56af965fe24941c46" + }, + { + "a_sha": "382e47831ba349a1531af31c083f0698e7081a6d", + "b_sha": "a2a91589e4ec029db729f865a740f35e28615a9e", + "class": "copy", + "index_within_pair": 1, + "side": "A", + "target_hash": "6e086d75960ce45894c83f74595d923312b34cdcee8410e7c60d81afd014d1df" + }, + { + "a_sha": "fe628c8648cfc26064aff82b9d4af45d77d4bb4c", + "b_sha": "6f95d2e891d009ea2ddf74d1de259c4b1556b5f4", + "class": "copy", + "index_within_pair": 0, + "side": "A", + "target_hash": "01f58d218af8331424c2353267a71f534dcae00bd4d9c4d8bc5c86972e92ad81" + }, + { + "a_sha": "fe628c8648cfc26064aff82b9d4af45d77d4bb4c", + "b_sha": "6f95d2e891d009ea2ddf74d1de259c4b1556b5f4", + "class": "copy", + "index_within_pair": 1, + "side": "A", + "target_hash": "1e3f30e3b239796683cb6100d3316b29e990c0e15e5006f49e0ce9141bc4d2a0" + }, + { + "a_sha": "45eca2c5d94c62845b559f3b77fbe2402ca4b2ae", + "b_sha": "70c244495e56a0190f2cac2b7f4aaf09859fd529", + "class": "copy", + "index_within_pair": 0, + "side": "A", + "target_hash": "4289effbf50a5fc362496f3411b5b0aa17a0178ad952c2c95487bf9f6f1e4ee4" + }, + { + "a_sha": "45eca2c5d94c62845b559f3b77fbe2402ca4b2ae", + "b_sha": "70c244495e56a0190f2cac2b7f4aaf09859fd529", + "class": "copy", + "index_within_pair": 1, + "side": "A", + "target_hash": "ea092a34e98d3c228e420e17b329fc446b53bf6ce8fcab98b8e0cf5da1ae87f0" + }, + { + "a_sha": "542e9b6aecc6e47ed09affdd16d97309c4378d69", + "b_sha": "9663baae7284d9e31d16f6ca401c97fe1f897701", + "class": "copy", + "index_within_pair": 0, + "side": "A", + "target_hash": "1d6ce244cfae6b14b079d3acf8ee36382f2c9f18e64f41b6248f0f5dd5551170" + } + ] + }, + "further_pre_freeze_reconnaissance": "PROHIBITED from this point", + "hard_challenge": { + "frozen_hard_sample": { + "copy": { + "from_targetable_pairs": 5, + "no_target_pairs": 20, + "of_frozen_pairs": 25, + "targets": 9 + }, + "rename": { + "from_frozen_pairs": 21, + "no_target_pairs": 17, + "targets": 4 + }, + "total": 13 + }, + "hard_pass_criterion": { + "both_required": true, + "condition_1": "unsafe_relation_errors(B3) == 0 across all adjudicable hard groups", + "condition_2": "correct_resolved(B3) >= max(correct_resolved(B1), correct_resolved(B2)) + 3", + "if_safe_but_fewer_than_3_added": "HARD-INCONCLUSIVE, not FAIL" + }, + "per_class_percentage_thresholds": "PROHIBITED at n=4 and n=9", + "pooled_into_primary_precision": false, + "reported_separately": true, + "superseded_criterion": { + "old_text": "B3 has fewer unsafe relation errors than B1/B2", + "why_impossible": "B1 and B2 both require same_pattern_id, and pattern_id includes the path. Across a rename or a copy the path changes, so the baselines return unresolved, which is not an unsafe error. Their unsafe-error count is therefore naturally 0, and requiring fewer than 0 is unsatisfiable." + }, + "unsafe_relation_error_definition": [ + "false continuation", + "fabricated branch", + "fabricated birth or death", + "invented endpoint", + "silent cardinality loss" + ] + }, + "merge_capability": { + "ceiling": "MERGE-INCONCLUSIVE", + "merge_detector_may_be_added": false, + "merged_symbols": "UNAVAILABLE by preregistration", + "note": "fixed for this experiment; not a defect to be repaired before the benchmark" + }, + "phase": "RH-M0", + "primary_holdout": { + "definition": "the primary external-validity sample is the 50 STS natural truth targets ONLY", + "explicit_clarification": "the 63 selected targets do NOT themselves satisfy the >= 40 criterion. The criterion counts ADJUDICABLE TRUTH GROUPS, which is not known until truth labelling is complete.", + "hard_targets_in_primary_denominator": false, + "requirements": [ + ">= 40 adjudicable truth groups among the 50 natural targets, otherwise INCONCLUSIVE", + ">= 20 B3-resolved natural groups, otherwise INCONCLUSIVE", + "resolved precision >= 95%", + "zero fabricated new/ended where truth has a counterpart", + "B3 coverage > B0", + "report B3-vs-B2 coverage; an absolute loss greater than 10 percentage points requires explicit utility justification and cannot be an unconditional PASS" + ], + "why": "a deliberately oversampled hard slice must not be able to rescue a failing natural-history sample by arithmetic" + }, + "producer_and_toolchain": { + "dotnet_sdk": "8.0.424", + "git": "2.55.0.windows.3", + "git_transform_detection": "git diff --name-status -M50% -C50% --find-copies-harder ", + "normalize_strip_rule": "--strip is MANDATORY and the strip leaf must be identical for every revision; the producer is invoked from the parent of the checkout so paths come out repository-relative", + "ownaudit_commit_used_for_normalisation": "d0b0dbd3f96d2676fa795935b224b67d032b5447", + "producer": "own-check", + "producer_own_net_commit": "76324fe4ccf71702d4386e29462227747d4fa54e", + "python": "3.12.10", + "roslyn": "Microsoft.CodeAnalysis.CSharp 4.9.2" + }, + "rename_capability": { + "all_four_targets_labelled": true, + "if_fewer_than_3_adjudicable": "RENAME-INCONCLUSIVE", + "no_percentage_metric": "3/4 and 4/4 are not statistics; raw counts only", + "pair_replacement": "PROHIBITED", + "validated_requires": [ + ">= 3 adjudicable rename truth groups", + "zero unsafe relation errors on the adjudicable rename groups" + ] + }, + "repositories": { + "ownnet": { + "adjacent_pairs": 238, + "first_parent_revisions": 239, + "natural_pairs_authoritative": 119, + "natural_pairs_preliminary_superseded": 120, + "ref": "main", + "role": "discovery / reference-evaluator development", + "tip": "76324fe4ccf71702d4386e29462227747d4fa54e" + }, + "sts": { + "adjacent_pairs": 2326, + "audit_subdir": "SectorTS/", + "first_parent_revisions": 2327, + "frozen_tip": "3588e530f88844d93b1466bf1e1176c6cbe3450b", + "ref": "dsector_optimization", + "repo_root": "STS_new", + "role": "sealed holdout" + } + }, + "sample": { + "no_target": { + "copy": [ + { + "a_sha": "5338bb2f4b00b0d4a5e0144a11d6d4d9d65505fc", + "b_sha": "3b9a55b7768a8ca1b278dc6290883fd721e466a4" + }, + { + "a_sha": "476377fc4042d2640f3216cc8b511747e7b30d8c", + "b_sha": "deaba36b1988cb3938911dd9603090113d54ede3" + }, + { + "a_sha": "64273291f8af21d09b3627ba207859474eee4126", + "b_sha": "d2ec8b75979e8004c9fa387a4701e76f39015f22" + }, + { + "a_sha": "3acf720c38423399655a17f26f0d8d9ed5cd1a9a", + "b_sha": "651143d81a165d8f3b32035f040c76487da083a0" + }, + { + "a_sha": "90155829d7eba2dccd103fc0e1f07fc48e4b2bd7", + "b_sha": "db22cad2bb7538ee577ea7d0d1f2cdee8692525c" + }, + { + "a_sha": "fa35e9e12f12d062169d56ff06575cee818f2851", + "b_sha": "f764bbaee0ea9edf53a269d691185209edfb6e10" + }, + { + "a_sha": "795708716e69ee3ae1d240916780a2e0504cf7b7", + "b_sha": "99f2187b458a9e9f3b4ad265bb939c3311fee7fa" + }, + { + "a_sha": "214fd169a5685ad9b9e5a0b966e620b5bb5fb8a1", + "b_sha": "65dd5e874c1789f697196cfe65500be63ddc043f" + }, + { + "a_sha": "d3e9d7458b371a2c32a0246ee478fa132f5060e1", + "b_sha": "7e503d76b2b5454cb387dd104a656a507569fb73" + }, + { + "a_sha": "93a403eacedd45856b510fa37217d0fc304c1b6d", + "b_sha": "678d35ee6f00eb03bac6bde853bbd6364dea4765" + }, + { + "a_sha": "5497e6f2595f8892c6e349b440605645a3e5bdeb", + "b_sha": "50d27b7d7b7213ef7b5da8a51bf2338298667d1c" + }, + { + "a_sha": "44bbf4f4169bc528ae0d160fabe5276e08858f58", + "b_sha": "9de66b1c358b78dfd57e94c4c07c138d2c5fc2e8" + }, + { + "a_sha": "b8928200765a4c897232474746ad1f7bc97f0e9b", + "b_sha": "ac25065781ec626c74b5e3aad2571225c946c572" + }, + { + "a_sha": "ca5f459c26d4dc2df567524dea46e700448cb36f", + "b_sha": "5a889983c199b4c7b1bd238e21d9bb94bfe2a778" + }, + { + "a_sha": "8c336c21ba24c4bd0b0fc82a909d0544b4091310", + "b_sha": "2896e0a5dc3c0689e297add2352a5494b12f4252" + }, + { + "a_sha": "266507d8b4e07cc432e0b255b22df3cd6593c4cc", + "b_sha": "b4f61dc1e5d889de0b76eb9db67b3737dad1b889" + }, + { + "a_sha": "e6d75ec61f55e0ec7c4985337535fee7d4be1fdf", + "b_sha": "3457bae4aafed114d50007777eebeec5374b40db" + }, + { + "a_sha": "eb32e9e3d09735e3518ba7033474ac8b9b2ce94d", + "b_sha": "623477c4cbcc3d7ea5ba3e59dc8584e313738e88" + }, + { + "a_sha": "03576cb716f7cfcf7140d0200747c054fbe78dc7", + "b_sha": "3a4c06f822e1c866fcae0caccef4d252b6583071" + }, + { + "a_sha": "5dcdbe09aff48ff16da565074b87a9893cbe6235", + "b_sha": "20a2c8d3ccc26469fc2d0ec0e433b188a1f95e55" + } + ], + "natural": [], + "rename": [ + { + "a_sha": "199f1f3861373db6f708bd9328835005ded09e48", + "b_sha": "c834553e06247467207c23d769790b3e8b882ce3" + }, + { + "a_sha": "46711ed0edd7d4e0a1516d53c5cef0f52d07c890", + "b_sha": "c83601783777060a37b7ea871bc9d99c99d5e060" + }, + { + "a_sha": "d3e9d7458b371a2c32a0246ee478fa132f5060e1", + "b_sha": "7e503d76b2b5454cb387dd104a656a507569fb73" + }, + { + "a_sha": "f4837ba267f45b59a08fb4e447fd6d309663e899", + "b_sha": "501ea55f3a8c8cc2bb98506db1af82fe40e57c37" + }, + { + "a_sha": "266507d8b4e07cc432e0b255b22df3cd6593c4cc", + "b_sha": "b4f61dc1e5d889de0b76eb9db67b3737dad1b889" + }, + { + "a_sha": "1aae361342944f6ecdb318232beeb63d5300f693", + "b_sha": "733c66323e135784cede110ecb214820d971776a" + }, + { + "a_sha": "57a4f31120ea10c175a8cd2fe64ee2f5c42ac0cb", + "b_sha": "24184d41dfc3d45eb7c4850e7e65e131df4e332a" + }, + { + "a_sha": "5b1878547f6a0aa8c98d7ade5404e6c5bd4ef88b", + "b_sha": "e084c0e70b9116584792addad57bb0e2e4273cc0" + }, + { + "a_sha": "f54427c2d709e6a8ce9ec8198b8a47d28d379f11", + "b_sha": "1cf267c8f828b2ded1d49a7da344b17e7f707304" + }, + { + "a_sha": "1af00413e334ddf38013a61c193c186ce84142aa", + "b_sha": "2d571bcb3a51132f9200cda367a66352faaf02c6" + }, + { + "a_sha": "a09c9c568ff831b3984094a5ccf8c9fc17e214f3", + "b_sha": "4e56082fc90a3a9b5b238bf43c6c0ddf38345b8b" + }, + { + "a_sha": "6e9e7a0464bc4328dbd4c7772e07ab9f82021548", + "b_sha": "63215dab2e9edb7d49c6df2e1ed7e4a0513d7b18" + }, + { + "a_sha": "dd21aae9d2512016df3861d1c9ee1335244f8372", + "b_sha": "0a16e9414e8f2687d22ecf4221ded154bf923aa5" + }, + { + "a_sha": "db204a602f8c4c1b887875bf0a36e116490da28e", + "b_sha": "f5975747fbb48fd703e6835bbea617684c91fb6e" + }, + { + "a_sha": "b3841a5a63567d704eae00771b099242119893a5", + "b_sha": "c4f60597cecb20b4e5de9e549043d89e001b919c" + }, + { + "a_sha": "65dd5e874c1789f697196cfe65500be63ddc043f", + "b_sha": "a39a8cc7dd6757e3c761594aa57f20924eea082c" + }, + { + "a_sha": "80c944a14b8f1f7e840ed629fc6151a1adbdcd9f", + "b_sha": "f4951cff971483469ae388eab0266e647cb87f6f" + } + ], + "status": "NO_TARGET entries remain in the frame as evidence of sample sparsity. They are NOT truth groups, they are never replaced, and no pair is substituted for them." + }, + "no_target_replacement_allowed": false, + "pair_selection_frozen": true, + "pair_selection_may_be_modified": false, + "selected_pairs": { + "copy": 25, + "natural": 50, + "rename": 21 + }, + "sts_copy_pairs": 71, + "sts_frame_pairs": 2326, + "sts_natural_candidates": 1915, + "sts_rename_pairs": 21, + "targets_after_census": { + "copy": 9, + "natural": 50, + "rename": 4, + "total": 63 + } + }, + "seeds": { + "b3_used_in_selection": false, + "canonical_serialisation": "json.dumps(array, ensure_ascii=False, separators=(\",\",\":\")).encode(\"utf-8\")", + "occurrence_id_used": false, + "selection_rank_rule": "rank_key = sha256(seed_hex || 0x00 || repo_id || 0x00 || a_sha || 0x00 || b_sha); ascending; ties by (a_sha, b_sha)", + "selection_seed": "ce730e47092805a8705ebc0f9b78f663a9c150139a650128f278afa9c393067e", + "side_preimage": [ + "rh-m0-side/v1", + "", + "sts", + "", + "" + ], + "side_rule": "sha256(canonical).digest()[0] & 1 ; 0 -> A, 1 -> B", + "target_preimage": [ + "rh-m0-target/v1", + "", + "sts", + "", + "", + "", + "", + "", + "", + "", + "" + ], + "target_rule": "minimum lexical sha256 hex over the candidate set", + "truth_seed": "7e4f4650a0109d52a4e0492e6d1a087b99a4af328b72ee3144ec746d9f85d7ed" + }, + "status": "FROZEN", + "step1_contract": { + "canonical_merge_commit": "011c1362861f6b8b20c45e8ebd5bcb912401c1c0", + "contracts": { + "contracts/finding-lineage-decision-v1.json": { + "git_blob": "610654aaf80a6ee7f4e8a96cd1f6095b8f0e5c80", + "sha256": "2172a9e16e9e33309a51ef4d7827086131641047595d2912ab442154d73e1ff0" + }, + "contracts/finding-lineage-v1.json": { + "git_blob": "211c73ed9672b7408b43f52f36e31ec3e4370cd6", + "sha256": "12c180e96fabf186454be89b8f9418684597a116df1428d5b12e2f3c9638c441" + } + }, + "contracts_identical_at_reviewed_head_and_merge": true, + "merge_shape": { + "branch_retained": "claude/lineage-decision-policy", + "commits_preserved": 84, + "parent_1": "d0b0dbd3f96d2676fa795935b224b67d032b5447", + "parent_2": "6dcc02f7d82bebeb5db9be83f77ab8c5455f5692", + "parents": 2, + "squashed": false + }, + "merged_at": "2026-08-29T08:06:47Z", + "normalizer_unchanged_by_merge": { + "consequence": "RH-0 and RH-O1 measurements remain valid against canonical main", + "files": [ + "aggregate/normalize.py", + "aggregate/provenance.py", + "aggregate/sarif_read.py" + ], + "identical": true + }, + "reviewed_step1_head": "6dcc02f7d82bebeb5db9be83f77ab8c5455f5692" + }, + "stop_conditions": { + "after_manifest_commit": "STOP and report the commit and hash", + "first_sts_b3_run_requires": "a hashed, frozen truth artifact", + "m0_contains_no_correctness_result": true, + "no_sts_b3_output_before_frozen_truth": true, + "reference_evaluator_may_run_on": "Own.NET only, after this freeze" + }, + "sts_b3_output_exists": false, + "truth_labels_created": false, + "truth_protocol": { + "ai_agreement_is_not_truth": "two agreeing agents produce PROPOSED truth only; the final truth artifact requires human/owner adjudication and sign-off", + "evidence_cards_contain": [ + "source at A and B", + "raw finding", + "ordinary Git diff", + "rename and copy metadata", + "commit context" + ], + "label_vocabulary": [ + "continued 1:1", + "branched 1:N", + "merged N:1", + "ended", + "new", + "unresolved-by-truth", + "unadjudicable" + ], + "labeler_a": "blind to B3", + "labeler_b": "blind to B3 and to labeler A", + "labelers_must_not_see": [ + "B3 output", + "baseline output", + "rule ids", + "evidence sets", + "applicable_rules", + "licensed_by", + "outcomes" + ], + "labels_per_target": 2, + "resolved_branch_or_merge_carries": "exact endpoint sets, not only the outcome", + "targets_frozen_now": 63, + "truth_artifact_hashed_and_frozen_before": "the first STS B3 run" + }, + "verdict_taxonomy": { + "axes": { + "branch": [ + "PASS-BRANCH", + "BRANCH-INCONCLUSIVE", + "FAIL/PIVOT" + ], + "hard": [ + "HARD-PASS", + "HARD-INCONCLUSIVE", + "FAIL" + ], + "merge": [ + "MERGE-INCONCLUSIVE" + ], + "natural": [ + "PASS-NATURAL", + "INCONCLUSIVE", + "FAIL" + ], + "rename": [ + "PASS-RENAME", + "RENAME-INCONCLUSIVE", + "FAIL" + ] + }, + "composite": true, + "examples": [ + [ + "PASS-NATURAL", + "PASS-RENAME", + "PASS-BRANCH", + "MERGE-INCONCLUSIVE" + ], + [ + "PASS-NATURAL", + "HARD-INCONCLUSIVE", + "BRANCH-INCONCLUSIVE", + "MERGE-INCONCLUSIVE" + ] + ], + "merge_axis_is_fixed": "MERGE-INCONCLUSIVE regardless of any other outcome", + "monolithic_pass_prohibited": "a single PASS hides which capability was actually exercised; every run reports one verdict per axis" + } +} \ No newline at end of file diff --git a/research/rh-m0/rh-m0-manifest.sha256 b/research/rh-m0/rh-m0-manifest.sha256 new file mode 100644 index 0000000..8e2d3ae --- /dev/null +++ b/research/rh-m0/rh-m0-manifest.sha256 @@ -0,0 +1 @@ +b22cb93d7ea1dc2392a318796abc3cfbf67615c300de40dc124f1039b0471d82 rh-m0-manifest.json From 9c0a8618f131e1bf0362d80538bb2af41f2d2c9a Mon Sep 17 00:00:00 2001 From: PhysShell Date: Sun, 30 Aug 2026 00:58:33 +0000 Subject: [PATCH 02/13] RH-M0: address the five external review findings The 63 frozen target hashes are unchanged. Nothing was re-selected. P1, forced-side exception. The manifest described the hash-derived side rule as if it governed every class. It does not: rename and copy candidates must be A-side findings on the transform SOURCE path, so their side is forced to A by construction and the side hash is never consulted. Applying the natural rule to the hard classes yields side B for 6 of the 13 hard targets, and since enters the target-hash preimage those 6 hashes would not reproduce. Confirmed on the frozen data: natural 0 of 50, rename 2 of 4, copy 4 of 9. seeds.side_determination now states the rule per class and carries a reproduction warning with the worked example Codex used. Side now reproduces 63 of 63. P2, truth-label wording. all_four_targets_labelled read as a claim that rename labels already exist, contradicting truth_labels_created=false. Renamed to all_four_targets_enter_labelling. P2, single-pair branch outcome. Three or more genuine branches confined to one revision pair previously fell through every rule. Preregistered as BRANCH-INCONCLUSIVE in an exhaustive four-row outcome table. P2, B2 coverage-loss disposition. "Requires utility justification" left the verdict decidable after unblinding. Frozen: a loss above 10 percentage points caps the natural axis at INCONCLUSIVE, and no after-the-fact justification can raise a capped verdict. P2, composite examples. All examples now carry all five axes. Manifest SHA-256 df0e9f8d7cac50b969ac5d53003885d2ad3d8c05584d011b9e0bcef09ef2c043 supersedes b22cb93d7ea1dc2392a318796abc3cfbf67615c300de40dc124f1039b0471d82. No B3 run. No truth labels. No correctness result. Co-Authored-By: Claude Opus 5 (1M context) Claude-Session: https://claude.ai/code/session_015vtUmvBDf69ccY5ju3PSHV --- research/rh-m0/rh-m0-manifest.json | 171 ++++++++++++++++++++++++--- research/rh-m0/rh-m0-manifest.sha256 | 2 +- 2 files changed, 153 insertions(+), 20 deletions(-) diff --git a/research/rh-m0/rh-m0-manifest.json b/research/rh-m0/rh-m0-manifest.json index 535e006..ee54537 100644 --- a/research/rh-m0/rh-m0-manifest.json +++ b/research/rh-m0/rh-m0-manifest.json @@ -52,8 +52,27 @@ }, "branch_capability": { "census_status": "the targetability census established STRUCTURAL POSSIBILITY only: 24 of 25 copy pairs carry a branch-capable source, but a finding actually sits on such a source in only 5 pairs, 16 candidate occurrences, 9 selected targets. This asserts nothing about branch truth.", - "if_three_or_more_and_any_endpoint_lost_or_invented": "FAIL/PIVOT", - "if_zero_to_two_genuine_branches": "BRANCH-INCONCLUSIVE regardless of B3 output", + "exhaustive": "the four rows above cover every reachable combination", + "outcome_table": [ + { + "condition": "0-2 adjudicated groups are genuinely branched", + "note": "regardless of B3 output", + "verdict": "BRANCH-INCONCLUSIVE" + }, + { + "condition": ">= 3 genuine branches but all within a SINGLE revision pair", + "note": "preregistered explicitly. Several frozen copy targets share a revision pair, so this case is reachable; one pair cannot demonstrate a capability that must generalise across history.", + "verdict": "BRANCH-INCONCLUSIVE" + }, + { + "condition": ">= 3 genuine branches spanning >= 2 revision pairs, all endpoint sets exact", + "verdict": "PASS-BRANCH" + }, + { + "condition": ">= 3 genuine branches spanning >= 2 revision pairs, any endpoint lost or invented", + "verdict": "FAIL/PIVOT" + } + ], "validated_requires": [ ">= 3 adjudicated truth groups whose truth label is 'branched'", "those groups span >= 2 distinct revision pairs", @@ -739,6 +758,44 @@ "silent cardinality loss" ] }, + "manifest_revision": { + "b3_executed": false, + "findings_applied": [ + { + "assessment": "valid; documentation defect, not a selection defect", + "fix": "seeds.side_determination now states the rule per class plus a reproduction warning", + "id": "P1", + "targets_changed": false, + "title": "Document the forced-side exception before freezing" + }, + { + "fix": "rename_capability.all_four_targets_labelled -> all_four_targets_enter_labelling", + "id": "P2-a", + "title": "Disambiguate classification from completed truth labelling" + }, + { + "fix": "branch_capability.outcome_table preregisters >=3 branches inside one pair as BRANCH-INCONCLUSIVE", + "id": "P2-b", + "title": "Cover the single-pair branch outcome" + }, + { + "fix": "primary_holdout.b2_coverage_loss_disposition caps the natural axis at INCONCLUSIVE above 10pp", + "id": "P2-c", + "title": "Freeze the disposition for excessive B2 coverage loss" + }, + { + "fix": "all composite examples now carry all five axes", + "id": "P2-d", + "title": "Include every verdict axis in composite examples" + } + ], + "frozen_targets_unchanged": true, + "reason": "five findings from the external Codex review on that exact head", + "revision": 2, + "supersedes_commit": "cde73560f029235959b7775a8466fca059c3f34e", + "supersedes_sha256": "b22cb93d7ea1dc2392a318796abc3cfbf67615c300de40dc124f1039b0471d82", + "truth_labels_created": false + }, "merge_capability": { "ceiling": "MERGE-INCONCLUSIVE", "merge_detector_may_be_added": false, @@ -747,6 +804,23 @@ }, "phase": "RH-M0", "primary_holdout": { + "b2_coverage_loss_disposition": { + "frozen_before_results": true, + "metric": "absolute percentage-point difference, coverage(B2) - coverage(B3), on the 50 natural targets", + "rule": [ + { + "condition": "loss <= 10 percentage points", + "effect": "no constraint from this rule" + }, + { + "condition": "loss > 10 percentage points", + "effect": "the natural axis is CAPPED at INCONCLUSIVE. It cannot be PASS-NATURAL however high the precision is." + } + ], + "supersedes": "the earlier wording 'requires explicit utility justification and cannot be an unconditional PASS', which left the verdict undetermined and therefore decidable after unblinding", + "utility_justification": "may be recorded for the record, but it CANNOT raise a capped verdict. An after-the-fact argument is not an acceptance criterion.", + "why_capped_rather_than_FAIL": "losing coverage against a deliberately conservative baseline is evidence that the policy is unhelpful, not evidence that it is wrong. FAIL is reserved for incorrect relations." + }, "definition": "the primary external-validity sample is the 50 STS natural truth targets ONLY", "explicit_clarification": "the 63 selected targets do NOT themselves satisfy the >= 40 criterion. The criterion counts ADJUDICABLE TRUTH GROUPS, which is not known until truth labelling is complete.", "hard_targets_in_primary_denominator": false, @@ -756,7 +830,7 @@ "resolved precision >= 95%", "zero fabricated new/ended where truth has a counterpart", "B3 coverage > B0", - "report B3-vs-B2 coverage; an absolute loss greater than 10 percentage points requires explicit utility justification and cannot be an unconditional PASS" + "B3-vs-B2 coverage loss is subject to the frozen disposition below" ], "why": "a deliberately oversampled hard slice must not be able to rescue a failing natural-history sample by arithmetic" }, @@ -772,14 +846,15 @@ "roslyn": "Microsoft.CodeAnalysis.CSharp 4.9.2" }, "rename_capability": { - "all_four_targets_labelled": true, + "all_four_targets_enter_labelling": true, "if_fewer_than_3_adjudicable": "RENAME-INCONCLUSIVE", "no_percentage_metric": "3/4 and 4/4 are not statistics; raw counts only", "pair_replacement": "PROHIBITED", "validated_requires": [ ">= 3 adjudicable rename truth groups", "zero unsafe relation errors on the adjudicable rename groups" - ] + ], + "wording_note": "this field means the four rename targets are all IN the labelling set. It does NOT mean labels exist: truth_labels_created is false and every target still requires two blinded labels plus human adjudication." }, "repositories": { "ownnet": { @@ -983,6 +1058,47 @@ "occurrence_id_used": false, "selection_rank_rule": "rank_key = sha256(seed_hex || 0x00 || repo_id || 0x00 || a_sha || 0x00 || b_sha); ascending; ties by (a_sha, b_sha)", "selection_seed": "ce730e47092805a8705ebc0f9b78f663a9c150139a650128f278afa9c393067e", + "side_determination": { + "copy": { + "rule": "forced to A by construction", + "side_hash_consulted": false, + "why": "a copy candidate must be an A-side finding lying on a copy SOURCE path, for the same reason as rename." + }, + "natural": { + "applies_to": "all 50 natural targets", + "decision": "sha256(canonical).digest()[0] & 1 ; 0 -> A, 1 -> B", + "preimage": [ + "rh-m0-side/v1", + "", + "sts", + "", + "" + ], + "rule": "hash-derived" + }, + "rename": { + "rule": "forced to A by construction", + "side_hash_consulted": false, + "why": "a rename candidate must be an A-side finding lying on a rename SOURCE path. The successor side cannot hold the predecessor occurrence, so there is nothing for a coin to decide." + }, + "reproduction_warning": { + "correct_reproduction": "for class natural derive the side from the hash; for classes rename and copy use side = \"A\" unconditionally, then compute the target preimage with that side", + "issue": "applying the natural side rule to the hard classes does NOT reproduce the frozen targets. Recomputed with the frozen truth_seed it yields side B for 6 of the 13 hard targets, and because also enters the target-hash preimage those 6 target hashes would not match.", + "measured_divergence": { + "copy": "4 of 9", + "natural": "0 of 50", + "rename": "2 of 4", + "total": "6 of 63" + }, + "worked_example": { + "a_sha": "43e13bce", + "b_sha": "45eca2c5", + "frozen_target_records": "A", + "hash_rule_would_select": "B", + "side_hash_first_byte": "0xa3" + } + } + }, "side_preimage": [ "rh-m0-side/v1", "", @@ -990,7 +1106,6 @@ "", "" ], - "side_rule": "sha256(canonical).digest()[0] & 1 ; 0 -> A, 1 -> B", "target_preimage": [ "rh-m0-target/v1", "", @@ -1004,7 +1119,7 @@ "", "" ], - "target_rule": "minimum lexical sha256 hex over the candidate set", + "target_rule": "minimum lexical sha256 hex over the candidate set, where the candidate set is class-dependent: all findings on the hash-selected side for natural, and the A-side findings on rename/copy source paths for the hard classes", "truth_seed": "7e4f4650a0109d52a4e0492e6d1a087b99a4af328b72ee3144ec746d9f85d7ed" }, "status": "FROZEN", @@ -1110,21 +1225,39 @@ "FAIL" ] }, + "axes_are_five": [ + "natural", + "hard", + "rename", + "branch", + "merge" + ], "composite": true, + "every_run_reports_one_verdict_per_axis": true, "examples": [ - [ - "PASS-NATURAL", - "PASS-RENAME", - "PASS-BRANCH", - "MERGE-INCONCLUSIVE" - ], - [ - "PASS-NATURAL", - "HARD-INCONCLUSIVE", - "BRANCH-INCONCLUSIVE", - "MERGE-INCONCLUSIVE" - ] + { + "branch": "PASS-BRANCH", + "hard": "HARD-PASS", + "merge": "MERGE-INCONCLUSIVE", + "natural": "PASS-NATURAL", + "rename": "PASS-RENAME" + }, + { + "branch": "BRANCH-INCONCLUSIVE", + "hard": "HARD-INCONCLUSIVE", + "merge": "MERGE-INCONCLUSIVE", + "natural": "PASS-NATURAL", + "rename": "RENAME-INCONCLUSIVE" + }, + { + "branch": "BRANCH-INCONCLUSIVE", + "hard": "HARD-INCONCLUSIVE", + "merge": "MERGE-INCONCLUSIVE", + "natural": "INCONCLUSIVE", + "rename": "RENAME-INCONCLUSIVE" + } ], + "examples_schema_note": "every example carries all five axes. A composite with fewer than five entries is malformed.", "merge_axis_is_fixed": "MERGE-INCONCLUSIVE regardless of any other outcome", "monolithic_pass_prohibited": "a single PASS hides which capability was actually exercised; every run reports one verdict per axis" } diff --git a/research/rh-m0/rh-m0-manifest.sha256 b/research/rh-m0/rh-m0-manifest.sha256 index 8e2d3ae..10656f6 100644 --- a/research/rh-m0/rh-m0-manifest.sha256 +++ b/research/rh-m0/rh-m0-manifest.sha256 @@ -1 +1 @@ -b22cb93d7ea1dc2392a318796abc3cfbf67615c300de40dc124f1039b0471d82 rh-m0-manifest.json +df0e9f8d7cac50b969ac5d53003885d2ad3d8c05584d011b9e0bcef09ef2c043 rh-m0-manifest.json From 6555e68944296c0f47dd5dbf52c59c76548f8422 Mon Sep 17 00:00:00 2001 From: PhysShell Date: Sun, 30 Aug 2026 03:43:49 +0000 Subject: [PATCH 03/13] RH-M0: state every constraint as a prohibition, not as a denied permission External review flagged sample.no_target_replacement_allowed=false as ambiguous for a machine reader: a dedicated permission flag carrying false forces the reader to decide what a denied permission means. The same shape occurred twice more, once in the same object. Fixing only the flagged field would have left two identical ambiguities, so all three are converted: no_target_replacement_allowed = false -> no_target_replacement_prohibited = true pair_selection_may_be_modified = false -> pair_selection_modification_prohibited = true merge_detector_may_be_added = false -> merge_detector_addition_prohibited = true sample.boolean_naming_rule now records the convention, and the NO_TARGET status prose points at the new field instead of restating the rule in words. The 63 frozen target hashes are byte-identical. No target, sampling, truth or B3 surface is touched. The old field names survive only inside manifest_revision.findings_applied, where they describe the change. Manifest SHA-256 b113a31813636c31c2a78685631a8c4304f80bb13dd341151a604d0bc05d8d31 supersedes df0e9f8d7cac50b969ac5d53003885d2ad3d8c05584d011b9e0bcef09ef2c043. No B3 run. No truth labels. No correctness result. Co-Authored-By: Claude Opus 5 (1M context) Claude-Session: https://claude.ai/code/session_015vtUmvBDf69ccY5ju3PSHV --- research/rh-m0/rh-m0-manifest.json | 59 +++++++++++++++------------- research/rh-m0/rh-m0-manifest.sha256 | 2 +- 2 files changed, 32 insertions(+), 29 deletions(-) diff --git a/research/rh-m0/rh-m0-manifest.json b/research/rh-m0/rh-m0-manifest.json index ee54537..c64527b 100644 --- a/research/rh-m0/rh-m0-manifest.json +++ b/research/rh-m0/rh-m0-manifest.json @@ -762,43 +762,45 @@ "b3_executed": false, "findings_applied": [ { - "assessment": "valid; documentation defect, not a selection defect", - "fix": "seeds.side_determination now states the rule per class plus a reproduction warning", + "assessment": "valid; a dedicated permission flag set to false is ambiguous for a machine reader", + "fix": "no_target_replacement_allowed=false -> no_target_replacement_prohibited=true", "id": "P1", - "targets_changed": false, - "title": "Document the forced-side exception before freezing" + "title": "Disallow replacement of NO_TARGET pairs" }, { - "fix": "rename_capability.all_four_targets_labelled -> all_four_targets_enter_labelling", - "id": "P2-a", - "title": "Disambiguate classification from completed truth labelling" - }, - { - "fix": "branch_capability.outcome_table preregisters >=3 branches inside one pair as BRANCH-INCONCLUSIVE", - "id": "P2-b", - "title": "Cover the single-pair branch outcome" - }, + "assessment": "fixing only the flagged field would have left two identical ambiguities, one of them in the same object. Corrected for consistency, not scope creep.", + "fix": [ + "pair_selection_may_be_modified=false -> pair_selection_modification_prohibited=true", + "merge_detector_may_be_added=false -> merge_detector_addition_prohibited=true" + ], + "id": "self-found", + "title": "the same permission-shaped pattern occurred twice more" + } + ], + "frozen_targets_unchanged": true, + "history": [ { - "fix": "primary_holdout.b2_coverage_loss_disposition caps the natural axis at INCONCLUSIVE above 10pp", - "id": "P2-c", - "title": "Freeze the disposition for excessive B2 coverage loss" + "commit": "cde73560f029235959b7775a8466fca059c3f34e", + "revision": 1, + "sha256": "b22cb93d7ea1dc2392a318796abc3cfbf67615c300de40dc124f1039b0471d82" }, { - "fix": "all composite examples now carry all five axes", - "id": "P2-d", - "title": "Include every verdict axis in composite examples" + "commit": "9c0a8618f131e1bf0362d80538bb2af41f2d2c9a", + "reason": "five external review findings on revision 1", + "revision": 2, + "sha256": "df0e9f8d7cac50b969ac5d53003885d2ad3d8c05584d011b9e0bcef09ef2c043" } ], - "frozen_targets_unchanged": true, - "reason": "five findings from the external Codex review on that exact head", - "revision": 2, - "supersedes_commit": "cde73560f029235959b7775a8466fca059c3f34e", - "supersedes_sha256": "b22cb93d7ea1dc2392a318796abc3cfbf67615c300de40dc124f1039b0471d82", + "reason": "one external review finding on revision 2: permission-shaped booleans are ambiguous", + "revision": 3, + "supersedes_commit": "9c0a8618f131e1bf0362d80538bb2af41f2d2c9a", + "supersedes_sha256": "df0e9f8d7cac50b969ac5d53003885d2ad3d8c05584d011b9e0bcef09ef2c043", + "targets_sampling_truth_or_b3_surface_touched": false, "truth_labels_created": false }, "merge_capability": { "ceiling": "MERGE-INCONCLUSIVE", - "merge_detector_may_be_added": false, + "merge_detector_addition_prohibited": true, "merged_symbols": "UNAVAILABLE by preregistration", "note": "fixed for this experiment; not a defect to be repaired before the benchmark" }, @@ -877,6 +879,7 @@ } }, "sample": { + "boolean_naming_rule": "every constraint in this manifest is stated as a prohibition that is true, never as a permission that is false. A reader never has to decide what a false permission means.", "no_target": { "copy": [ { @@ -1031,11 +1034,11 @@ "b_sha": "f4951cff971483469ae388eab0266e647cb87f6f" } ], - "status": "NO_TARGET entries remain in the frame as evidence of sample sparsity. They are NOT truth groups, they are never replaced, and no pair is substituted for them." + "status": "NO_TARGET entries remain in the frame as evidence of sample sparsity. They are NOT truth groups. Replacing them is prohibited, and no pair may be substituted for them: see sample.no_target_replacement_prohibited." }, - "no_target_replacement_allowed": false, + "no_target_replacement_prohibited": true, "pair_selection_frozen": true, - "pair_selection_may_be_modified": false, + "pair_selection_modification_prohibited": true, "selected_pairs": { "copy": 25, "natural": 50, diff --git a/research/rh-m0/rh-m0-manifest.sha256 b/research/rh-m0/rh-m0-manifest.sha256 index 10656f6..ffb27d5 100644 --- a/research/rh-m0/rh-m0-manifest.sha256 +++ b/research/rh-m0/rh-m0-manifest.sha256 @@ -1 +1 @@ -df0e9f8d7cac50b969ac5d53003885d2ad3d8c05584d011b9e0bcef09ef2c043 rh-m0-manifest.json +b113a31813636c31c2a78685631a8c4304f80bb13dd341151a604d0bc05d8d31 rh-m0-manifest.json From 03d56ace0623db64abe9db9d88c385717968ccca Mon Sep 17 00:00:00 2001 From: PhysShell Date: Sun, 30 Aug 2026 06:40:57 +0000 Subject: [PATCH 04/13] RH-M0: no verdict axis may be passed without resolving anything External review found that PASS-RENAME required only >= 3 adjudicable rename groups plus zero unsafe relation errors. Four `unresolved` answers satisfy both, so the axis was reachable without resolving a single rename. The finding is valid and material. The identical vacuity existed on the branch axis, where "all endpoint sets exact" is trivially true when B3 produced no endpoint sets at all. It was not flagged, but it is the same defect class, so both axes are fixed together. Both are now exhaustive, precedence-ordered outcome tables: rename: 4 rows. The denominator counts only groups whose TRUTH is continued 1:1 across the rename, because correctly calling `ended` on a renamed file does not demonstrate R-CONT-RENAME. PASS requires >= 3 correct exact-counterpart resolutions. branch: 5 rows. PASS requires >= 3 correct resolutions with exact successor endpoint sets, spanning >= 2 revision pairs. verdict_taxonomy.no_vacuous_pass states the invariant once and records the resolution floor of every axis. natural and hard already carried floors, >= 20 B3-resolved and +3 over the better baseline; they needed no change. Also recorded: HARD-PASS pools rename and copy, so its +3 can be satisfied entirely by copy while no rename resolves. That is why rename has its own axis, and why HARD-PASS with RENAME-INCONCLUSIVE is a coherent composite rather than a contradiction. Both tables were verified by mechanical enumeration of every reachable state: zero uncovered states, zero vacuous PASS. Manifest SHA-256 2b8ce7018b6a67a6a522ac8d77638b4ccbd3f76634aa15b2f790443d0e6ad614 supersedes b113a31813636c31c2a78685631a8c4304f80bb13dd341151a604d0bc05d8d31. The 63 frozen target hashes are byte-identical. No sampling, truth or B3 surface was touched. No B3 run. No truth labels. No correctness result. Co-Authored-By: Claude Opus 5 (1M context) Claude-Session: https://claude.ai/code/session_015vtUmvBDf69ccY5ju3PSHV --- research/rh-m0/rh-m0-manifest.json | 120 ++++++++++++++++++++------- research/rh-m0/rh-m0-manifest.sha256 | 2 +- 2 files changed, 90 insertions(+), 32 deletions(-) diff --git a/research/rh-m0/rh-m0-manifest.json b/research/rh-m0/rh-m0-manifest.json index c64527b..77f7cc3 100644 --- a/research/rh-m0/rh-m0-manifest.json +++ b/research/rh-m0/rh-m0-manifest.json @@ -52,34 +52,38 @@ }, "branch_capability": { "census_status": "the targetability census established STRUCTURAL POSSIBILITY only: 24 of 25 copy pairs carry a branch-capable source, but a finding actually sits on such a source in only 5 pairs, 16 candidate occurrences, 9 selected targets. This asserts nothing about branch truth.", - "exhaustive": "the four rows above cover every reachable combination", + "exhaustive": "the five rows cover every reachable combination", "outcome_table": [ { - "condition": "0-2 adjudicated groups are genuinely branched", + "condition": "any unsafe relation error on an adjudicable branch target, including a lost or invented successor endpoint", + "row": 1, + "verdict": "FAIL/PIVOT" + }, + { + "condition": "fewer than 3 adjudicated groups whose truth label is `branched`", "note": "regardless of B3 output", + "row": 2, "verdict": "BRANCH-INCONCLUSIVE" }, { - "condition": ">= 3 genuine branches but all within a SINGLE revision pair", + "condition": "at least 3 genuine branched groups, but all of them inside a SINGLE revision pair", "note": "preregistered explicitly. Several frozen copy targets share a revision pair, so this case is reachable; one pair cannot demonstrate a capability that must generalise across history.", + "row": 3, "verdict": "BRANCH-INCONCLUSIVE" }, { - "condition": ">= 3 genuine branches spanning >= 2 revision pairs, all endpoint sets exact", + "condition": "at least 3 genuine branched groups spanning >= 2 distinct revision pairs, and B3 correctly resolves at least 3 of them with the exact successor endpoint set, zero silent cardinality loss and zero invented endpoints", + "row": 4, "verdict": "PASS-BRANCH" }, { - "condition": ">= 3 genuine branches spanning >= 2 revision pairs, any endpoint lost or invented", - "verdict": "FAIL/PIVOT" + "condition": "at least 3 genuine branched groups spanning >= 2 distinct revision pairs, zero unsafe relation errors, but B3 correctly resolves only 0-2 of them", + "row": 5, + "verdict": "BRANCH-INCONCLUSIVE" } ], - "validated_requires": [ - ">= 3 adjudicated truth groups whose truth label is 'branched'", - "those groups span >= 2 distinct revision pairs", - "exact successor endpoint-set accuracy = 100%", - "zero silent cardinality loss", - "zero invented branch endpoints" - ] + "precedence": "rows are evaluated in order; the first matching row decides. Row 1 therefore dominates every other outcome.", + "supersedes": "the earlier row 'all endpoint sets exact' was vacuously true when B3 produced no endpoint sets at all, so PASS-BRANCH was reachable with zero resolutions. Row 4 now requires at least 3 correct resolutions." }, "contains_correctness_result": false, "descriptive_strata": { @@ -759,22 +763,31 @@ ] }, "manifest_revision": { + "axes_checked_for_the_same_defect": { + "branch": "FIXED", + "hard": "already had a floor: +3 correct resolutions over the better baseline", + "merge": "not applicable; fixed at MERGE-INCONCLUSIVE", + "natural": "already had a floor: >= 20 B3-resolved", + "rename": "FIXED" + }, "b3_executed": false, "findings_applied": [ { - "assessment": "valid; a dedicated permission flag set to false is ambiguous for a machine reader", - "fix": "no_target_replacement_allowed=false -> no_target_replacement_prohibited=true", + "assessment": "valid and material. >= 3 adjudicable groups plus zero unsafe errors is satisfied by four `unresolved` answers.", + "fix": "rename_capability.outcome_table: exhaustive, precedence-ordered, denominator restricted to truth = continued 1:1 through the rename, and PASS requires >= 3 correct exact-counterpart resolutions", "id": "P1", - "title": "Disallow replacement of NO_TARGET pairs" + "title": "PASS-RENAME reachable with zero rename resolutions" }, { - "assessment": "fixing only the flagged field would have left two identical ambiguities, one of them in the same object. Corrected for consistency, not scope creep.", - "fix": [ - "pair_selection_may_be_modified=false -> pair_selection_modification_prohibited=true", - "merge_detector_may_be_added=false -> merge_detector_addition_prohibited=true" - ], + "assessment": "'all endpoint sets exact' is vacuously true when B3 produced no endpoint sets. Not flagged by the reviewer, but the same defect class, and leaving it would have handed the next round an identical finding.", + "fix": "branch_capability.outcome_table row 4 now requires >= 3 correct resolutions", + "id": "self-found", + "title": "the branch axis carried the identical vacuity" + }, + { + "fix": "verdict_taxonomy.no_vacuous_pass records the rule and the resolution floor of every axis", "id": "self-found", - "title": "the same permission-shaped pattern occurred twice more" + "title": "the invariant was nowhere stated" } ], "frozen_targets_unchanged": true, @@ -789,12 +802,18 @@ "reason": "five external review findings on revision 1", "revision": 2, "sha256": "df0e9f8d7cac50b969ac5d53003885d2ad3d8c05584d011b9e0bcef09ef2c043" + }, + { + "commit": "6555e68944296c0f47dd5dbf52c59c76548f8422", + "reason": "permission-shaped booleans replaced by prohibitions", + "revision": 3, + "sha256": "b113a31813636c31c2a78685631a8c4304f80bb13dd341151a604d0bc05d8d31" } ], - "reason": "one external review finding on revision 2: permission-shaped booleans are ambiguous", - "revision": 3, - "supersedes_commit": "9c0a8618f131e1bf0362d80538bb2af41f2d2c9a", - "supersedes_sha256": "df0e9f8d7cac50b969ac5d53003885d2ad3d8c05584d011b9e0bcef09ef2c043", + "reason": "one external review finding on revision 3: a verdict axis was passable without resolving anything", + "revision": 4, + "supersedes_commit": "6555e68944296c0f47dd5dbf52c59c76548f8422", + "supersedes_sha256": "b113a31813636c31c2a78685631a8c4304f80bb13dd341151a604d0bc05d8d31", "targets_sampling_truth_or_b3_surface_touched": false, "truth_labels_created": false }, @@ -849,12 +868,39 @@ }, "rename_capability": { "all_four_targets_enter_labelling": true, - "if_fewer_than_3_adjudicable": "RENAME-INCONCLUSIVE", + "exhaustive": "the four rows cover every reachable combination. correct_resolved can never exceed the number of genuine groups, so no case falls between rows 3 and 4.", "no_percentage_metric": "3/4 and 4/4 are not statistics; raw counts only", + "outcome_table": [ + { + "condition": "any unsafe relation error on an adjudicable rename target", + "row": 1, + "verdict": "FAIL/PIVOT" + }, + { + "condition": "fewer than 3 adjudicated rename targets have truth = continued 1:1 through the rename", + "row": 2, + "verdict": "RENAME-INCONCLUSIVE" + }, + { + "condition": "at least 3 genuine continued-1:1 rename groups exist, B3 correctly resolves at least 3 of them to the exact counterpart, and there are zero unsafe relation errors", + "row": 3, + "verdict": "PASS-RENAME" + }, + { + "condition": "at least 3 genuine continued-1:1 rename groups exist, zero unsafe relation errors, but B3 correctly resolves only 0-2 of them", + "row": 4, + "verdict": "RENAME-INCONCLUSIVE" + } + ], "pair_replacement": "PROHIBITED", - "validated_requires": [ - ">= 3 adjudicable rename truth groups", - "zero unsafe relation errors on the adjudicable rename groups" + "precedence": "rows are evaluated in order; the first matching row decides. Row 1 therefore dominates every other outcome.", + "supersedes": "the earlier rule required only >= 3 adjudicable rename groups and zero unsafe errors. Four `unresolved` answers satisfy both, so PASS-RENAME was reachable without resolving a single rename.", + "truth_must_be_continued_1_to_1": "the denominator counts only groups whose TRUTH is continued 1:1 across the rename. Correctly calling `ended` or any other outcome on a renamed file does not demonstrate R-CONT-RENAME, and must not be able to earn the axis.", + "why_threshold_is_three": [ + "1 of 4 validates nothing", + "2 correct resolutions are a useful signal but still RENAME-INCONCLUSIVE", + "3 exact resolutions with zero unsafe errors permit a cautious PASS-RENAME", + "4 of 4 is a stronger descriptive result; no separate percentage threshold is introduced" ], "wording_note": "this field means the four rename targets are all IN the labelling set. It does NOT mean labels exist: truth_labels_created is false and every target still requires two blinded labels plus human adjudication." }, @@ -1235,6 +1281,7 @@ "branch", "merge" ], + "axis_independence_note": "HARD-PASS pools rename and copy, so its +3 requirement can in principle be satisfied entirely by copy targets while no rename is resolved at all. That is why rename carries its own axis with its own resolution floor, and why a composite verdict must report both. HARD-PASS together with RENAME-INCONCLUSIVE is a coherent and honest result, not a contradiction.", "composite": true, "every_run_reports_one_verdict_per_axis": true, "examples": [ @@ -1262,6 +1309,17 @@ ], "examples_schema_note": "every example carries all five axes. A composite with fewer than five entries is malformed.", "merge_axis_is_fixed": "MERGE-INCONCLUSIVE regardless of any other outcome", - "monolithic_pass_prohibited": "a single PASS hides which capability was actually exercised; every run reports one verdict per axis" + "monolithic_pass_prohibited": "a single PASS hides which capability was actually exercised; every run reports one verdict per axis", + "no_vacuous_pass": { + "resolution_floor_per_axis": { + "branch": ">= 3 correct resolutions with exact successor endpoint sets", + "hard": "correct_resolved(B3) >= max(correct_resolved(B1), correct_resolved(B2)) + 3", + "merge": "not applicable; the axis is fixed at MERGE-INCONCLUSIVE", + "natural": ">= 20 B3-resolved natural groups", + "rename": ">= 3 correct exact-counterpart resolutions on genuine continued-1:1 rename groups" + }, + "rule": "no axis may reach a PASS verdict without a positive count of correct resolutions", + "why": "zero unsafe errors is trivially achieved by answering `unresolved` everywhere. Safety without resolution is not a capability, and an axis that can be passed by silence measures nothing." + } } } \ No newline at end of file diff --git a/research/rh-m0/rh-m0-manifest.sha256 b/research/rh-m0/rh-m0-manifest.sha256 index ffb27d5..83211d5 100644 --- a/research/rh-m0/rh-m0-manifest.sha256 +++ b/research/rh-m0/rh-m0-manifest.sha256 @@ -1 +1 @@ -b113a31813636c31c2a78685631a8c4304f80bb13dd341151a604d0bc05d8d31 rh-m0-manifest.json +2b8ce7018b6a67a6a522ac8d77638b4ccbd3f76634aa15b2f790443d0e6ad614 rh-m0-manifest.json From 5c89ba515da4e5e84b3fb7749ccdf9d99bd28ffa Mon Sep 17 00:00:00 2001 From: PhysShell Date: Sun, 30 Aug 2026 06:49:26 +0000 Subject: [PATCH 05/13] RH-M0: one verdict token, and the check that would have caught it rename_capability.outcome_table row 1 emitted FAIL/PIVOT while verdict_taxonomy.axes.rename declares PASS-RENAME / RENAME-INCONCLUSIVE / FAIL. No run could satisfy both. The mirror image of the same defect was present and unreported: FAIL was declared for the rename axis but reachable from no row. The row now emits FAIL. The rename token set is deliberately NOT widened to FAIL/PIVOT. That compound belongs to the branch axis by preregistration, and a result vocabulary that grows to fit one row stops discriminating. The pivot semantics are preserved as an experiment disposition instead: axis verdict FAIL -> disposition PIVOT axis verdict INCONCLUSIVE -> disposition HOLD axis verdict PASS -> disposition PROCEED A verdict records what was measured; a disposition records what the project does next. Fusing them makes the measured result depend on a management decision. The branch axis keeps its compound FAIL/PIVOT token. It was preregistered that way and is internally consistent with its own token set, so it is recorded as a known wart rather than silently rewritten. Editing a frozen token to satisfy a style preference is the kind of post-hoc change this manifest exists to prevent. verdict_taxonomy.consistency_rule now states the invariant: every verdict in any outcome_table must belong to its axis token set, and every declared token should be reachable. Verified mechanically in both directions, zero mismatches and zero unreachable tokens. Enumerating every reachable rename state yields exactly the three declared verdicts. Why prose review missed it: the rename table was written by analogy with the branch table, which legitimately uses FAIL/PIVOT. Reading compares a row against its neighbours; only a mechanical check compares it against its own axis. Manifest SHA-256 f4c5181eaf0948dc38f6d86c884404331a5111f275228d78cd7ca22c0f97f47e supersedes 2b8ce7018b6a67a6a522ac8d77638b4ccbd3f76634aa15b2f790443d0e6ad614. The 63 frozen target hashes are byte-identical. No sampling, truth or B3 surface was touched. No B3 run. No truth labels. No correctness result. Co-Authored-By: Claude Opus 5 (1M context) Claude-Session: https://claude.ai/code/session_015vtUmvBDf69ccY5ju3PSHV --- research/rh-m0/rh-m0-manifest.json | 74 ++++++++++++++++++++-------- research/rh-m0/rh-m0-manifest.sha256 | 2 +- 2 files changed, 54 insertions(+), 22 deletions(-) diff --git a/research/rh-m0/rh-m0-manifest.json b/research/rh-m0/rh-m0-manifest.json index 77f7cc3..66e34a9 100644 --- a/research/rh-m0/rh-m0-manifest.json +++ b/research/rh-m0/rh-m0-manifest.json @@ -763,31 +763,25 @@ ] }, "manifest_revision": { - "axes_checked_for_the_same_defect": { - "branch": "FIXED", - "hard": "already had a floor: +3 correct resolutions over the better baseline", - "merge": "not applicable; fixed at MERGE-INCONCLUSIVE", - "natural": "already had a floor: >= 20 B3-resolved", - "rename": "FIXED" - }, "b3_executed": false, "findings_applied": [ { - "assessment": "valid and material. >= 3 adjudicable groups plus zero unsafe errors is satisfied by four `unresolved` answers.", - "fix": "rename_capability.outcome_table: exhaustive, precedence-ordered, denominator restricted to truth = continued 1:1 through the rename, and PASS requires >= 3 correct exact-counterpart resolutions", - "id": "P1", - "title": "PASS-RENAME reachable with zero rename resolutions" + "assessment": "valid. rename row 1 emitted FAIL/PIVOT while the rename axis declares PASS-RENAME / RENAME-INCONCLUSIVE / FAIL, so no run could satisfy both.", + "fix": "rename_capability.outcome_table row 1 verdict FAIL/PIVOT -> FAIL", + "id": "P2", + "taxonomy_widened": false, + "title": "Align the rename failure with its verdict taxonomy" }, { - "assessment": "'all endpoint sets exact' is vacuously true when B3 produced no endpoint sets. Not flagged by the reviewer, but the same defect class, and leaving it would have handed the next round an identical finding.", - "fix": "branch_capability.outcome_table row 4 now requires >= 3 correct resolutions", + "assessment": "FAIL was declared for the rename axis but reachable from no row. The mechanical cross-check surfaced both directions at once.", + "fix": "resolved by the same one-token change", "id": "self-found", - "title": "the branch axis carried the identical vacuity" + "title": "the mirror image of the same defect" }, { - "fix": "verdict_taxonomy.no_vacuous_pass records the rule and the resolution floor of every axis", + "fix": "verdict_taxonomy.consistency_rule states the invariant and records that it was verified mechanically in both directions", "id": "self-found", - "title": "the invariant was nowhere stated" + "title": "the check itself was not written down" } ], "frozen_targets_unchanged": true, @@ -808,12 +802,18 @@ "reason": "permission-shaped booleans replaced by prohibitions", "revision": 3, "sha256": "b113a31813636c31c2a78685631a8c4304f80bb13dd341151a604d0bc05d8d31" + }, + { + "commit": "03d56ace0623db64abe9db9d88c385717968ccca", + "reason": "no verdict axis passable without resolving anything", + "revision": 4, + "sha256": "2b8ce7018b6a67a6a522ac8d77638b4ccbd3f76634aa15b2f790443d0e6ad614" } ], - "reason": "one external review finding on revision 3: a verdict axis was passable without resolving anything", - "revision": 4, - "supersedes_commit": "6555e68944296c0f47dd5dbf52c59c76548f8422", - "supersedes_sha256": "b113a31813636c31c2a78685631a8c4304f80bb13dd341151a604d0bc05d8d31", + "reason": "one external review finding on revision 4: a verdict token outside its own axis", + "revision": 5, + "supersedes_commit": "03d56ace0623db64abe9db9d88c385717968ccca", + "supersedes_sha256": "2b8ce7018b6a67a6a522ac8d77638b4ccbd3f76634aa15b2f790443d0e6ad614", "targets_sampling_truth_or_b3_surface_touched": false, "truth_labels_created": false }, @@ -869,12 +869,13 @@ "rename_capability": { "all_four_targets_enter_labelling": true, "exhaustive": "the four rows cover every reachable combination. correct_resolved can never exceed the number of genuine groups, so no case falls between rows 3 and 4.", + "failure_token_note": "row 1 emits FAIL, the token declared for this axis. The rename token set is deliberately NOT widened to FAIL/PIVOT: that compound belongs to the branch axis by preregistration, and a result vocabulary that grows to fit one row stops discriminating.", "no_percentage_metric": "3/4 and 4/4 are not statistics; raw counts only", "outcome_table": [ { "condition": "any unsafe relation error on an adjudicable rename target", "row": 1, - "verdict": "FAIL/PIVOT" + "verdict": "FAIL" }, { "condition": "fewer than 3 adjudicated rename targets have truth = continued 1:1 through the rename", @@ -1283,6 +1284,16 @@ ], "axis_independence_note": "HARD-PASS pools rename and copy, so its +3 requirement can in principle be satisfied entirely by copy targets while no rename is resolved at all. That is why rename carries its own axis with its own resolution floor, and why a composite verdict must report both. HARD-PASS together with RENAME-INCONCLUSIVE is a coherent and honest result, not a contradiction.", "composite": true, + "consistency_rule": { + "how_the_defect_was_missed": "the rename table was written by analogy with the branch table, which legitimately uses FAIL/PIVOT. Prose review compares a row against its neighbours; only a mechanical check compares it against its own axis.", + "method": "cross-product check of all outcome_table rows against verdict_taxonomy.axes, in both directions", + "result_at_this_revision": { + "declared_but_unreachable": 0, + "mismatches": 0 + }, + "rule": "every verdict appearing in any outcome_table MUST be a member of the token set declared for that axis in verdict_taxonomy.axes, and every declared token SHOULD be reachable from at least one row", + "verified_mechanically": true + }, "every_run_reports_one_verdict_per_axis": true, "examples": [ { @@ -1308,6 +1319,27 @@ } ], "examples_schema_note": "every example carries all five axes. A composite with fewer than five entries is malformed.", + "experiment_disposition": { + "branch_axis_exception": "the branch axis retains the compound token FAIL/PIVOT because it was preregistered that way and is internally consistent with its own token set. It is recorded here as a known wart, not silently rewritten: changing a frozen token to satisfy a style preference is exactly the kind of post-hoc edit this manifest exists to prevent.", + "mapping": [ + { + "axis_verdict": "FAIL", + "disposition": "PIVOT", + "meaning": "an unsafe relation error was produced; the policy is wrong, not merely unhelpful" + }, + { + "axis_verdict": "INCONCLUSIVE", + "disposition": "HOLD", + "meaning": "the sample or the resolution count could not decide the axis" + }, + { + "axis_verdict": "PASS", + "disposition": "PROCEED", + "meaning": "the axis is demonstrated within its preregistered limits" + } + ], + "why": "a verdict records what was measured; a disposition records what the project does next. Fusing them into one token, as FAIL/PIVOT does, makes the measured result depend on a management decision and is awkward for any consumer that groups by verdict." + }, "merge_axis_is_fixed": "MERGE-INCONCLUSIVE regardless of any other outcome", "monolithic_pass_prohibited": "a single PASS hides which capability was actually exercised; every run reports one verdict per axis", "no_vacuous_pass": { diff --git a/research/rh-m0/rh-m0-manifest.sha256 b/research/rh-m0/rh-m0-manifest.sha256 index 83211d5..c5360a8 100644 --- a/research/rh-m0/rh-m0-manifest.sha256 +++ b/research/rh-m0/rh-m0-manifest.sha256 @@ -1 +1 @@ -2b8ce7018b6a67a6a522ac8d77638b4ccbd3f76634aa15b2f790443d0e6ad614 rh-m0-manifest.json +f4c5181eaf0948dc38f6d86c884404331a5111f275228d78cd7ca22c0f97f47e rh-m0-manifest.json From ac54fcb3420550f0423366842fdd488f69bf1b3a Mon Sep 17 00:00:00 2001 From: PhysShell Date: Sun, 30 Aug 2026 12:22:25 +0000 Subject: [PATCH 06/13] RH-M0: narrow the consistency rule to what it actually checks The mechanical consistency rule was written as if it governed all five verdict axes, but only rename and branch are table-backed. Executing its reachability half against the other three reports 7 falsely unreachable tokens - natural 3, hard 3, merge 1 - purely because those axes have no rows. The reported declared_but_unreachable=0 was therefore reproducible only for the two axes the check actually covered. The rule now carries an explicit scope of rename and branch, and each non-table-backed axis names the section that governs its tokens: natural primary_holdout acceptance criteria hard hard_challenge criteria merge fixed singleton ceiling MERGE-INCONCLUSIVE The three axes are deliberately NOT given outcome tables to make the rule uniform. Extending a frozen specification for the sake of a checker's symmetry is the wrong direction; the checker is narrowed to what it checks. Executing the rule exactly as written now reproduces the reported numbers: emitted_not_declared 0, declared_but_unreachable 0. Unchanged and asserted in the patch: verdict_taxonomy.axes, both outcome tables, primary_holdout, hard_challenge, frozen_targets. No taxonomy token, acceptance threshold or outcome semantic was touched. Manifest SHA-256 7d087e8a8dc0ab06cc39b5328824c6ad902d2b87c6f996f7239d068b10bf72fd supersedes f4c5181eaf0948dc38f6d86c884404331a5111f275228d78cd7ca22c0f97f47e. No B3 run. No truth labels. No correctness result. Co-Authored-By: Claude Opus 5 (1M context) Claude-Session: https://claude.ai/code/session_015vtUmvBDf69ccY5ju3PSHV --- research/rh-m0/rh-m0-manifest.json | 70 +++++++++++++++++----------- research/rh-m0/rh-m0-manifest.sha256 | 2 +- 2 files changed, 45 insertions(+), 27 deletions(-) diff --git a/research/rh-m0/rh-m0-manifest.json b/research/rh-m0/rh-m0-manifest.json index 66e34a9..71df428 100644 --- a/research/rh-m0/rh-m0-manifest.json +++ b/research/rh-m0/rh-m0-manifest.json @@ -766,22 +766,13 @@ "b3_executed": false, "findings_applied": [ { - "assessment": "valid. rename row 1 emitted FAIL/PIVOT while the rename axis declares PASS-RENAME / RENAME-INCONCLUSIVE / FAIL, so no run could satisfy both.", - "fix": "rename_capability.outcome_table row 1 verdict FAIL/PIVOT -> FAIL", + "assessment": "valid. Only rename and branch are table-backed. Applying the reachability half to natural, hard and merge would report 7 falsely unreachable tokens, so declared_but_unreachable=0 was reproducible only for the two axes actually checked. Verified: 7, being natural 3, hard 3, merge 1.", + "fix": "consistency_rule now carries an explicit scope, and each non-table-backed axis names the section that governs its tokens", "id": "P2", - "taxonomy_widened": false, - "title": "Align the rename failure with its verdict taxonomy" - }, - { - "assessment": "FAIL was declared for the rename axis but reachable from no row. The mechanical cross-check surfaced both directions at once.", - "fix": "resolved by the same one-token change", - "id": "self-found", - "title": "the mirror image of the same defect" - }, - { - "fix": "verdict_taxonomy.consistency_rule states the invariant and records that it was verified mechanically in both directions", - "id": "self-found", - "title": "the check itself was not written down" + "outcome_semantics_changed": false, + "taxonomy_changed": false, + "thresholds_changed": false, + "title": "Mechanical consistency rule overclaims its scope" } ], "frozen_targets_unchanged": true, @@ -808,14 +799,28 @@ "reason": "no verdict axis passable without resolving anything", "revision": 4, "sha256": "2b8ce7018b6a67a6a522ac8d77638b4ccbd3f76634aa15b2f790443d0e6ad614" + }, + { + "commit": "5c89ba515da4e5e84b3fb7749ccdf9d99bd28ffa", + "reason": "rename failure token aligned with its own axis", + "revision": 5, + "sha256": "f4c5181eaf0948dc38f6d86c884404331a5111f275228d78cd7ca22c0f97f47e" } ], - "reason": "one external review finding on revision 4: a verdict token outside its own axis", - "revision": 5, - "supersedes_commit": "03d56ace0623db64abe9db9d88c385717968ccca", - "supersedes_sha256": "2b8ce7018b6a67a6a522ac8d77638b4ccbd3f76634aa15b2f790443d0e6ad614", + "reason": "one external review finding on revision 5: the mechanical consistency rule claimed a wider scope than it checks", + "revision": 6, + "supersedes_commit": "5c89ba515da4e5e84b3fb7749ccdf9d99bd28ffa", + "supersedes_sha256": "f4c5181eaf0948dc38f6d86c884404331a5111f275228d78cd7ca22c0f97f47e", "targets_sampling_truth_or_b3_surface_touched": false, - "truth_labels_created": false + "truth_labels_created": false, + "what_this_revision_did_not_touch": [ + "verdict_taxonomy.axes", + "rename_capability.outcome_table", + "branch_capability.outcome_table", + "primary_holdout", + "hard_challenge", + "frozen_targets" + ] }, "merge_capability": { "ceiling": "MERGE-INCONCLUSIVE", @@ -1286,13 +1291,26 @@ "composite": true, "consistency_rule": { "how_the_defect_was_missed": "the rename table was written by analogy with the branch table, which legitimately uses FAIL/PIVOT. Prose review compares a row against its neighbours; only a mechanical check compares it against its own axis.", - "method": "cross-product check of all outcome_table rows against verdict_taxonomy.axes, in both directions", - "result_at_this_revision": { + "mechanical_result": { "declared_but_unreachable": 0, - "mismatches": 0 - }, - "rule": "every verdict appearing in any outcome_table MUST be a member of the token set declared for that axis in verdict_taxonomy.axes, and every declared token SHOULD be reachable from at least one row", - "verified_mechanically": true + "emitted_not_declared": 0 + }, + "method": "cross-product of the outcome_table rows of the in-scope axes against verdict_taxonomy.axes, in both directions", + "no_tables_added_for_uniformity": "the other three axes are NOT given outcome tables to make the rule uniform. Extending a frozen specification for the sake of a checker's symmetry is the wrong direction: the checker is narrowed to what it checks.", + "non_table_backed_axes": { + "hard": "governed by hard_challenge criteria, not outcome_table", + "merge": "fixed singleton ceiling MERGE-INCONCLUSIVE", + "natural": "governed by primary_holdout acceptance criteria, not outcome_table" + }, + "rule": "for every table-backed axis, every outcome_table verdict MUST belong to that axis's declared token set, and every declared token for that axis MUST be reachable from at least one outcome-table row", + "scope": [ + "rename", + "branch" + ], + "scope_reason": "these are the only table-backed axes. The other three declare their tokens through acceptance criteria, not through rows, so a row-based reachability check does not apply to them.", + "supersedes": "the revision-5 wording 'every verdict appearing in any outcome_table ... and every declared token SHOULD be reachable', which was unscoped and therefore unreproducible for three of the five axes", + "verified_mechanically": true, + "why_the_scope_matters": "applying the reachability half to all five axes would report 7 falsely unreachable tokens - natural 3, hard 3, merge 1 - purely because those axes have no rows. The previous wording promised that broader scope while the reported result covered only the two axes actually checked." }, "every_run_reports_one_verdict_per_axis": true, "examples": [ diff --git a/research/rh-m0/rh-m0-manifest.sha256 b/research/rh-m0/rh-m0-manifest.sha256 index c5360a8..df39029 100644 --- a/research/rh-m0/rh-m0-manifest.sha256 +++ b/research/rh-m0/rh-m0-manifest.sha256 @@ -1 +1 @@ -f4c5181eaf0948dc38f6d86c884404331a5111f275228d78cd7ca22c0f97f47e rh-m0-manifest.json +7d087e8a8dc0ab06cc39b5328824c6ad902d2b87c6f996f7239d068b10bf72fd rh-m0-manifest.json From 6e3304a498951089f8945f6cb3ec99978e65e887 Mon Sep 17 00:00:00 2001 From: PhysShell Date: Sun, 30 Aug 2026 12:30:25 +0000 Subject: [PATCH 07/13] RH-M0: total natural outcome rule, concrete axis dispositions, no global aggregator Three related closures in one revision. 1. The natural axis had acceptance criteria but no total rule mapping numbers to a verdict. A precision breach or a fabricated relation had no declared outcome, so the choice between FAIL and INCONCLUSIVE stayed available after unblinding. primary_holdout.outcome_table is now six precedence-ordered rows ending in an unconditional row, so every combination maps to exactly one verdict. The thresholds are unchanged; only their disposition is now frozen. FAIL marks observed incorrectness: a fabricated relation, or precision below 95%. INCONCLUSIVE marks insufficient evidence or insufficient utility. That is the doctrine already frozen for the B2 coverage loss. The earlier requirement "B3 coverage > B0" is subsumed by row 3 rather than dropped: B0 always answers unresolved, so >= 20 B3-resolved implies coverage above B0. Recorded explicitly. 2. The disposition mapping used generic PASS / INCONCLUSIVE / FAIL. PASS is not a token of any axis. The mapping is now concrete over all 11 declared tokens, with no prefix, suffix or regex normalisation: a rule that has to parse its own vocabulary will one day parse it wrongly. 3. Read literally the mapping looked global. MERGE-INCONCLUSIVE is preregistered on every run, so a global INCONCLUSIVE -> HOLD would make PROCEED unreachable forever. Renamed experiment_disposition to axis_disposition and added an explicit clause: no global composite disposition is frozen by RH-M0, and the merge entry is admissible only as an axis-local disposition. Consequence handled in the same commit: natural became table-backed, so consistency_rule.scope is now [natural, rename, branch]. Leaving it at [rename, branch] would have manufactured the next finding here. verdict_taxonomy.disposition_coverage_rule now requires every declared token to have exactly one disposition entry, and records the check. Mechanically verified: 512 enumerated natural states, none without a verdict, all three tokens reachable; scope check 0 and 0; 11 tokens declared, 0 unmapped, 0 mapped-but-undeclared. Asserted unchanged: verdict_taxonomy.axes, both other outcome tables, hard_challenge, frozen_targets, truth_protocol, seeds. Manifest SHA-256 71f4c923d7091a1d88869d0ec7c97154e1aab15a6a1da82fb6ea8d1d074944a8 supersedes 7d087e8a8dc0ab06cc39b5328824c6ad902d2b87c6f996f7239d068b10bf72fd. No B3 run. No truth labels. No correctness result. Co-Authored-By: Claude Opus 5 (1M context) Claude-Session: https://claude.ai/code/session_015vtUmvBDf69ccY5ju3PSHV --- research/rh-m0/rh-m0-manifest.json | 143 ++++++++++++++++++++------- research/rh-m0/rh-m0-manifest.sha256 | 2 +- 2 files changed, 108 insertions(+), 37 deletions(-) diff --git a/research/rh-m0/rh-m0-manifest.json b/research/rh-m0/rh-m0-manifest.json index 71df428..94f3393 100644 --- a/research/rh-m0/rh-m0-manifest.json +++ b/research/rh-m0/rh-m0-manifest.json @@ -766,13 +766,29 @@ "b3_executed": false, "findings_applied": [ { - "assessment": "valid. Only rename and branch are table-backed. Applying the reachability half to natural, hard and merge would report 7 falsely unreachable tokens, so declared_but_unreachable=0 was reproducible only for the two axes actually checked. Verified: 7, being natural 3, hard 3, merge 1.", - "fix": "consistency_rule now carries an explicit scope, and each non-table-backed axis names the section that governs its tokens", - "id": "P2", - "outcome_semantics_changed": false, - "taxonomy_changed": false, + "assessment": "valid. A precision or correctness violation had no declared verdict, so the choice between FAIL and INCONCLUSIVE remained available after unblinding.", + "fix": "primary_holdout.outcome_table: six rows, precedence-ordered, total", + "id": "P2-a", "thresholds_changed": false, - "title": "Mechanical consistency rule overclaims its scope" + "title": "natural axis had no total number-to-verdict rule" + }, + { + "assessment": "valid. PASS is not a token of any axis.", + "fix": "concrete token-by-token mapping over all 11 declared tokens", + "id": "P2-b", + "title": "disposition mapping used tokens the taxonomy does not declare" + }, + { + "assessment": "MERGE-INCONCLUSIVE is preregistered on every run, so a global INCONCLUSIVE -> HOLD would make PROCEED unreachable forever.", + "fix": "renamed to axis_disposition with an explicit no_global_aggregator clause", + "id": "self-found", + "title": "the mapping read as a global aggregator" + }, + { + "assessment": "natural became table-backed, so leaving the scope at [rename, branch] would have created the next finding inside the same commit.", + "fix": "consistency_rule.scope now [natural, rename, branch]; hard and merge remain out", + "id": "self-found", + "title": "adding a natural table changed what the consistency scope must cover" } ], "frozen_targets_unchanged": true, @@ -805,21 +821,28 @@ "reason": "rename failure token aligned with its own axis", "revision": 5, "sha256": "f4c5181eaf0948dc38f6d86c884404331a5111f275228d78cd7ca22c0f97f47e" + }, + { + "commit": "ac54fcb3420550f0423366842fdd488f69bf1b3a", + "reason": "consistency rule narrowed to the axes it checks", + "revision": 6, + "sha256": "7d087e8a8dc0ab06cc39b5328824c6ad902d2b87c6f996f7239d068b10bf72fd" } ], - "reason": "one external review finding on revision 5: the mechanical consistency rule claimed a wider scope than it checks", - "revision": 6, - "supersedes_commit": "5c89ba515da4e5e84b3fb7749ccdf9d99bd28ffa", - "supersedes_sha256": "f4c5181eaf0948dc38f6d86c884404331a5111f275228d78cd7ca22c0f97f47e", + "reason": "two external review findings on revision 6, plus one consequence of fixing them", + "revision": 7, + "supersedes_commit": "ac54fcb3420550f0423366842fdd488f69bf1b3a", + "supersedes_sha256": "7d087e8a8dc0ab06cc39b5328824c6ad902d2b87c6f996f7239d068b10bf72fd", "targets_sampling_truth_or_b3_surface_touched": false, "truth_labels_created": false, "what_this_revision_did_not_touch": [ "verdict_taxonomy.axes", "rename_capability.outcome_table", "branch_capability.outcome_table", - "primary_holdout", "hard_challenge", - "frozen_targets" + "frozen_targets", + "truth_protocol", + "seeds" ] }, "merge_capability": { @@ -847,9 +870,44 @@ "utility_justification": "may be recorded for the record, but it CANNOT raise a capped verdict. An after-the-fact argument is not an acceptance criterion.", "why_capped_rather_than_FAIL": "losing coverage against a deliberately conservative baseline is evidence that the policy is unhelpful, not evidence that it is wrong. FAIL is reserved for incorrect relations." }, + "b3_coverage_over_b0": "the earlier requirement 'B3 coverage > B0' is subsumed by row 3 and is therefore not a separate row. B0 always answers unresolved, so coverage(B0) = 0, and >= 20 B3-resolved groups implies coverage(B3) > 0. Recorded rather than dropped.", "definition": "the primary external-validity sample is the 50 STS natural truth targets ONLY", "explicit_clarification": "the 63 selected targets do NOT themselves satisfy the >= 40 criterion. The criterion counts ADJUDICABLE TRUTH GROUPS, which is not known until truth labelling is complete.", + "fail_vs_inconclusive_doctrine": "FAIL marks observed incorrectness: a fabricated relation or a precision breach. INCONCLUSIVE marks insufficient evidence or insufficient utility. This is the same doctrine already frozen for the B2 coverage loss, where losing coverage against a deliberately conservative baseline is evidence of unhelpfulness rather than of error.", "hard_targets_in_primary_denominator": false, + "outcome_table": [ + { + "condition": "any fabricated new/ended where truth has a counterpart", + "row": 1, + "verdict": "FAIL" + }, + { + "condition": "fewer than 40 adjudicable truth groups among the 50 natural targets", + "row": 2, + "verdict": "INCONCLUSIVE" + }, + { + "condition": "fewer than 20 B3-resolved natural groups", + "row": 3, + "verdict": "INCONCLUSIVE" + }, + { + "condition": "resolved precision < 95%", + "row": 4, + "verdict": "FAIL" + }, + { + "condition": "coverage(B2) - coverage(B3) > 10 percentage points", + "row": 5, + "verdict": "INCONCLUSIVE" + }, + { + "condition": "otherwise", + "row": 6, + "verdict": "PASS-NATURAL" + } + ], + "precedence": "rows are evaluated in order; the first matching row decides. Row 1 therefore dominates every other outcome.", "requirements": [ ">= 40 adjudicable truth groups among the 50 natural targets, otherwise INCONCLUSIVE", ">= 20 B3-resolved natural groups, otherwise INCONCLUSIVE", @@ -858,6 +916,8 @@ "B3 coverage > B0", "B3-vs-B2 coverage loss is subject to the frozen disposition below" ], + "supersedes": "the earlier requirements list, which attached 'otherwise INCONCLUSIVE' to only two of six criteria and left a precision or correctness violation without a declared verdict", + "total": "the table is total: row 6 is unconditional, so every combination of measurements maps to exactly one verdict", "why": "a deliberately oversampled hard slice must not be able to rescue a failing natural-history sample by arithmetic" }, "producer_and_toolchain": { @@ -1287,6 +1347,27 @@ "branch", "merge" ], + "axis_disposition": { + "branch_axis_exception": "the branch axis retains the compound token FAIL/PIVOT because it was preregistered that way and is internally consistent with its own token set. It is recorded here as a known wart, not silently rewritten: changing a frozen token to satisfy a style preference is exactly the kind of post-hoc edit this manifest exists to prevent.", + "mapping": { + "BRANCH-INCONCLUSIVE": "HOLD", + "FAIL": "PIVOT", + "FAIL/PIVOT": "PIVOT", + "HARD-INCONCLUSIVE": "HOLD", + "HARD-PASS": "PROCEED", + "INCONCLUSIVE": "HOLD", + "MERGE-INCONCLUSIVE": "HOLD", + "PASS-BRANCH": "PROCEED", + "PASS-NATURAL": "PROCEED", + "PASS-RENAME": "PROCEED", + "RENAME-INCONCLUSIVE": "HOLD" + }, + "mapping_is_concrete": "every entry names a token that the taxonomy actually declares. No prefix, suffix or regular-expression normalisation is used, because a rule that has to parse its own vocabulary is a rule that will one day parse it wrongly.", + "merge_entry_is_axis_local": "MERGE-INCONCLUSIVE -> HOLD is admissible only as an axis-local disposition. It cannot by itself imply a global HOLD.", + "no_global_aggregator": "No global composite disposition is frozen by RH-M0. MERGE-INCONCLUSIVE is a preregistered capability ceiling present on every run, so read as a global rule this mapping would make PROCEED unreachable forever. The global decision stays compositional and is not smuggled back into a monolithic gate.", + "what_this_is": "the local disposition associated with ONE axis verdict. It does NOT aggregate the five-axis composite into a single experiment or project disposition.", + "why": "a verdict records what was measured; a disposition records what the project does next. Fusing them into one token, as FAIL/PIVOT does, makes the measured result depend on a management decision and is awkward for any consumer that groups by verdict." + }, "axis_independence_note": "HARD-PASS pools rename and copy, so its +3 requirement can in principle be satisfied entirely by copy targets while no rename is resolved at all. That is why rename carries its own axis with its own resolution floor, and why a composite verdict must report both. HARD-PASS together with RENAME-INCONCLUSIVE is a coherent and honest result, not a contradiction.", "composite": true, "consistency_rule": { @@ -1299,19 +1380,30 @@ "no_tables_added_for_uniformity": "the other three axes are NOT given outcome tables to make the rule uniform. Extending a frozen specification for the sake of a checker's symmetry is the wrong direction: the checker is narrowed to what it checks.", "non_table_backed_axes": { "hard": "governed by hard_challenge criteria, not outcome_table", - "merge": "fixed singleton ceiling MERGE-INCONCLUSIVE", - "natural": "governed by primary_holdout acceptance criteria, not outcome_table" + "merge": "fixed singleton ceiling MERGE-INCONCLUSIVE" }, "rule": "for every table-backed axis, every outcome_table verdict MUST belong to that axis's declared token set, and every declared token for that axis MUST be reachable from at least one outcome-table row", "scope": [ + "natural", "rename", "branch" ], - "scope_reason": "these are the only table-backed axes. The other three declare their tokens through acceptance criteria, not through rows, so a row-based reachability check does not apply to them.", + "scope_change_note": "natural entered the scope in revision 7, when it gained an outcome table. The scope tracks the structure; it is not a fixed list.", + "scope_reason": "these are the table-backed axes. hard and merge declare their tokens through acceptance criteria and a fixed ceiling, not through rows.", "supersedes": "the revision-5 wording 'every verdict appearing in any outcome_table ... and every declared token SHOULD be reachable', which was unscoped and therefore unreproducible for three of the five axes", "verified_mechanically": true, "why_the_scope_matters": "applying the reachability half to all five axes would report 7 falsely unreachable tokens - natural 3, hard 3, merge 1 - purely because those axes have no rows. The previous wording promised that broader scope while the reported result covered only the two axes actually checked." }, + "disposition_coverage_rule": { + "result_at_this_revision": { + "mapped_but_undeclared": 0, + "tokens_declared": 11, + "tokens_unmapped": 0 + }, + "rule": "every token declared in verdict_taxonomy.axes MUST have exactly one entry in axis_disposition.mapping", + "verified_mechanically": true, + "why": "finding two of this round was precisely a mapping written against tokens that did not exist. A rule that is checked cannot drift back into that state silently." + }, "every_run_reports_one_verdict_per_axis": true, "examples": [ { @@ -1337,27 +1429,6 @@ } ], "examples_schema_note": "every example carries all five axes. A composite with fewer than five entries is malformed.", - "experiment_disposition": { - "branch_axis_exception": "the branch axis retains the compound token FAIL/PIVOT because it was preregistered that way and is internally consistent with its own token set. It is recorded here as a known wart, not silently rewritten: changing a frozen token to satisfy a style preference is exactly the kind of post-hoc edit this manifest exists to prevent.", - "mapping": [ - { - "axis_verdict": "FAIL", - "disposition": "PIVOT", - "meaning": "an unsafe relation error was produced; the policy is wrong, not merely unhelpful" - }, - { - "axis_verdict": "INCONCLUSIVE", - "disposition": "HOLD", - "meaning": "the sample or the resolution count could not decide the axis" - }, - { - "axis_verdict": "PASS", - "disposition": "PROCEED", - "meaning": "the axis is demonstrated within its preregistered limits" - } - ], - "why": "a verdict records what was measured; a disposition records what the project does next. Fusing them into one token, as FAIL/PIVOT does, makes the measured result depend on a management decision and is awkward for any consumer that groups by verdict." - }, "merge_axis_is_fixed": "MERGE-INCONCLUSIVE regardless of any other outcome", "monolithic_pass_prohibited": "a single PASS hides which capability was actually exercised; every run reports one verdict per axis", "no_vacuous_pass": { diff --git a/research/rh-m0/rh-m0-manifest.sha256 b/research/rh-m0/rh-m0-manifest.sha256 index df39029..84b88bb 100644 --- a/research/rh-m0/rh-m0-manifest.sha256 +++ b/research/rh-m0/rh-m0-manifest.sha256 @@ -1 +1 @@ -7d087e8a8dc0ab06cc39b5328824c6ad902d2b87c6f996f7239d068b10bf72fd rh-m0-manifest.json +71f4c923d7091a1d88869d0ec7c97154e1aab15a6a1da82fb6ea8d1d074944a8 rh-m0-manifest.json From ad58b29383d36b9fad0f0dc65a5faa3ace6636e8 Mon Sep 17 00:00:00 2001 From: PhysShell Date: Sun, 30 Aug 2026 15:21:59 +0000 Subject: [PATCH 08/13] RH-M0: exact truth tokens, total hard axis, LF checksum artifact A. The branch table referred to the truth label as `branched`, while truth_protocol.label_vocabulary declares `branched 1:N`. Under exact comparison no adjudicated group would ever match, so PASS-BRANCH was unreachable. Every truth-sensitive condition now names the canonical token verbatim, and truth_labels_referenced lists it structurally so a checker never parses prose. The rename table had the same shape in milder form: it embedded `continued 1:1` inside a prose phrase. Fixed alongside, for the same reason. verdict_taxonomy.truth_label_reference_rule now requires every referenced truth label to be a member of the vocabulary, verbatim, and records the check. B. The hard axis was not total: unsafe_relation_errors > 0 had no verdict although FAIL is declared for it. It is now a three-row precedence-ordered table. The +3 margin and the zero-unsafe requirement are exactly the previously frozen criterion; only the missing FAIL branch was added, and the previous criterion object is retained for reference. Consequence handled here: hard became table-backed, so consistency_rule.scope is now [natural, hard, rename, branch]. merge is the only axis outside, because it is a fixed singleton ceiling rather than a decision. C. The checksum sidecar was written with CRLF. sha256sum --check treats the trailing CR as part of the filename and looks for rh-m0-manifest.json followed by a carriage return, so the sidecar was not machine-verifiable even though the digest itself was correct. It is now written with LF and sha256sum --check passes. Found alongside: the manifest itself carried CRLF, which makes its digest depend on the platform that wrote it. Regenerating identical content on Linux would have produced a different hash. Both files are now LF, and the patch asserts that neither contains a carriage return before writing. Mechanically verified: 180 enumerated hard states, none without a verdict, all three tokens reachable; scope check 0 and 0; referenced truth tokens `branched 1:N` and `continued 1:1`, both in the vocabulary; 11 declared tokens, 0 unmapped. Asserted unchanged: verdict_taxonomy.axes, truth_protocol, seeds, frozen_targets, the natural outcome table and the hard thresholds. Manifest SHA-256 ff6a5ed408dd56571036137c570cb4a0c6c0a4e98e6e447f67b4842337e9464a supersedes 71f4c923d7091a1d88869d0ec7c97154e1aab15a6a1da82fb6ea8d1d074944a8. No B3 run. No truth labels. No correctness result. Co-Authored-By: Claude Opus 5 (1M context) Claude-Session: https://claude.ai/code/session_015vtUmvBDf69ccY5ju3PSHV --- research/rh-m0/rh-m0-manifest.json | 2938 +++++++++++++------------- research/rh-m0/rh-m0-manifest.sha256 | 2 +- 2 files changed, 1494 insertions(+), 1446 deletions(-) diff --git a/research/rh-m0/rh-m0-manifest.json b/research/rh-m0/rh-m0-manifest.json index 94f3393..b6dc709 100644 --- a/research/rh-m0/rh-m0-manifest.json +++ b/research/rh-m0/rh-m0-manifest.json @@ -1,1446 +1,1494 @@ -{ - "artifact": "rh-m0-manifest", - "b3_executed": false, - "baselines": { - "B0": { - "rule": "always unresolved" - }, - "B1": { - "candidates": "for the target endpoint, candidates on the opposite side with same_pattern_id", - "decision": "unique minimum abs(start_line_A - start_line_B) => continued", - "never_emits": [ - "new", - "ended", - "branched", - "merged" - ], - "tie_or_no_candidate": "unresolved" - }, - "B2": { - "candidates": "same_pattern_id AND same enclosing_symbol", - "decision": "exactly one candidate => continued", - "never_emits": [ - "new", - "ended", - "branched", - "merged" - ], - "otherwise": "unresolved" - }, - "B3": { - "at_canonical_merge": "011c1362861f6b8b20c45e8ebd5bcb912401c1c0", - "contracts": [ - "finding-lineage/v1", - "finding-lineage-decision/v1" - ], - "reviewed_step1_head": "6dcc02f7d82bebeb5db9be83f77ab8c5455f5692", - "rule": "the exact canonical frozen Step-1 policy" - }, - "observation_sources": { - "anchored_content": "RH-O1 adapter, exact physical line bytes, terminator excluded", - "enclosing_symbol": "RH-O1 adapter, Roslyn 4.9.2, canonical Git blob, spec-frozen display format", - "line_drift": "holds iff start_line_A != start_line_B; no threshold", - "path_rename / copy_record": "git diff -M50% -C50% --find-copies-harder", - "still_unavailable": [ - "renamed_symbol_record", - "reformatted_paths", - "merged_symbols", - "boundary: enclosing-site-added", - "boundary: enclosing-site-removed" - ] - } - }, - "branch_capability": { - "census_status": "the targetability census established STRUCTURAL POSSIBILITY only: 24 of 25 copy pairs carry a branch-capable source, but a finding actually sits on such a source in only 5 pairs, 16 candidate occurrences, 9 selected targets. This asserts nothing about branch truth.", - "exhaustive": "the five rows cover every reachable combination", - "outcome_table": [ - { - "condition": "any unsafe relation error on an adjudicable branch target, including a lost or invented successor endpoint", - "row": 1, - "verdict": "FAIL/PIVOT" - }, - { - "condition": "fewer than 3 adjudicated groups whose truth label is `branched`", - "note": "regardless of B3 output", - "row": 2, - "verdict": "BRANCH-INCONCLUSIVE" - }, - { - "condition": "at least 3 genuine branched groups, but all of them inside a SINGLE revision pair", - "note": "preregistered explicitly. Several frozen copy targets share a revision pair, so this case is reachable; one pair cannot demonstrate a capability that must generalise across history.", - "row": 3, - "verdict": "BRANCH-INCONCLUSIVE" - }, - { - "condition": "at least 3 genuine branched groups spanning >= 2 distinct revision pairs, and B3 correctly resolves at least 3 of them with the exact successor endpoint set, zero silent cardinality loss and zero invented endpoints", - "row": 4, - "verdict": "PASS-BRANCH" - }, - { - "condition": "at least 3 genuine branched groups spanning >= 2 distinct revision pairs, zero unsafe relation errors, but B3 correctly resolves only 0-2 of them", - "row": 5, - "verdict": "BRANCH-INCONCLUSIVE" - } - ], - "precedence": "rows are evaluated in order; the first matching row decides. Row 1 therefore dominates every other outcome.", - "supersedes": "the earlier row 'all endpoint sets exact' was vacuously true when B3 produced no endpoint sets at all, so PASS-BRANCH was reachable with zero resolutions. Row 4 now requires at least 3 correct resolutions." - }, - "contains_correctness_result": false, - "descriptive_strata": { - "affects_inclusion_or_thresholds_or_target_count_or_labelling": false, - "carried_correction": [ - "Identical pattern_id multiset means only that (path, rule, message) multiplicities are unchanged.", - "It does NOT imply identical physical occurrences, anchors, enclosing symbols, anchored content, or trivial lineage." - ], - "computed_after": "M0 freeze only", - "full_observation_tuple": [ - "pattern_id", - "start_line", - "start_column", - "enclosing_symbol_hash", - "anchored_content_hash" - ], - "strata": { - "S0": "full observation multiset identical", - "S1": "pattern_id multiset identical, full observation multiset differs", - "S2": "pattern_id multiset differs" - } - }, - "digest_note": "the SHA-256 of this manifest lives in the sidecar rh-m0-manifest.sha256; a digest stored inside the file it describes cannot equal that file's digest", - "frozen_input_hashes": [ - { - "bytes": 5855, - "exportable": true, - "file": "rh0-environment.json", - "sha256": "3fe4892175d678a2b95b1128be1db00f51cc8d470d226076fe26b5538ad639a0" - }, - { - "bytes": 1125100, - "exportable": true, - "file": "rh0-frame-sts.jsonl", - "sha256": "1b5eaaa962fa0f692ce636e1dcc94761a7df4b18962b328679d810ae8e49f26a" - }, - { - "bytes": 113197, - "exportable": true, - "file": "rh0-frame-ownnet.jsonl", - "sha256": "6590cedd99fd6078332f6f6ed3e1d5d20c66364d182acbe62f07937f40582e92" - }, - { - "bytes": 42522, - "exportable": true, - "file": "rh0-selection-preview.json", - "sha256": "c8645a79e4ba6752d2627b6bf5159ffe06a222ed4ceffb3484a43254103e5587" - }, - { - "bytes": 2497, - "exportable": true, - "file": "rh0-toolchain-sensitivity.json", - "sha256": "e50a36c2c789371db1401c1512a6134aeebede46e49b12ed3a1456449ac599e5" - }, - { - "bytes": 11111, - "exportable": true, - "file": "rh0-signal-observability.json", - "sha256": "6188bd381045f3f3cdef72c7b1dfd0f37f2a1d05d192adbcfdc8e09322da6f6a" - }, - { - "bytes": 2827, - "exportable": true, - "file": "rh0-bundle.sha256", - "sha256": "a6e30f693f36e760f1ebc42165963d206d0eb04abf7b77db815fe7e1084cc8a9" - }, - { - "bytes": 10164, - "exportable": true, - "file": "rh0-o1-observation-spec.json", - "sha256": "9e82b78d55f7e120357d086523ba76a113e6a15de8be0d179fbbff72f2a488e0" - }, - { - "bytes": 8403, - "exportable": true, - "file": "rh0-o1-observation-vectors.json", - "sha256": "00e8507db4b851dbc30acaf1796f5e5292ed1213d940868e6c46e705dfb5e54e" - }, - { - "bytes": 6133, - "exportable": true, - "file": "rh0-o1-coverage.json", - "sha256": "c074bdc6e9dbaf588061f73c4d00f70aa61bb664131cfddbd86f670abf697872" - }, - { - "bytes": 1971, - "exportable": true, - "file": "rh0-o1-bundle.sha256", - "sha256": "1b816e92619f2abbc80efe6cd7371cc9472dcb2e2799b4c447fb60ed47821e0f" - }, - { - "bytes": 4768, - "exportable": true, - "file": "rh0-m0-pending-corrections.json", - "sha256": "aef9aef2bf1adbf13b4d238f1fefeaf180669dea4b22c71dfaa5951d22e54116" - }, - { - "bytes": 41469, - "exportable": true, - "file": "rh0-m0-targetability.json", - "sha256": "1c25cd6ca15c8e66be8bcb86ded3357c6cf2b297825ce6e67d60ca81360faa4b" - }, - { - "bytes": 93, - "exportable": true, - "file": "rh0-m0-targetability.sha256", - "sha256": "e8ed0af417cd504242af4ddde79c7840b352542cf8f1ba28ea6f56ef5713bac0" - }, - { - "bytes": 15512, - "exportable": true, - "file": "obs-adapter/Program.cs", - "sha256": "77f72efcac7b44093fd86e225d3e56f138685bba25082889a3cd87f12408cf31" - }, - { - "bytes": 582, - "exportable": true, - "file": "obs-adapter/ObsAdapter.csproj", - "sha256": "bff9cb29c17456f11c1910595f01b343081051077d895a14b0ff86b2e2aaec53" - }, - { - "bytes": 2210, - "exportable": true, - "file": "vectors/setup.sh", - "sha256": "ea5db72931a94b8cb092972095dda00ebfb105534c1e17714b8a7cccc562cd12" - }, - { - "bytes": 7547, - "exportable": true, - "file": "vectors/observed.jsonl", - "sha256": "081b63180adae18b647726b8a66ad0f91751fea73b53c29a8a00a0d4c880df45" - }, - { - "bytes": 2567, - "exportable": true, - "file": "probe.sh", - "sha256": "59e0a566b84ed8ed1b1882108bb6e5b29b224ce52475c1caeaab2e26f4b5caf9" - }, - { - "bytes": 2835, - "exportable": true, - "file": "make_requests.py", - "sha256": "e01ee9d61ead3731279deaa24854468d3eaed7543d86775d461ccfc2954ca1d2" - }, - { - "bytes": 7540, - "exportable": true, - "file": "build_coverage.py", - "sha256": "4e1b8c1f0f3d797cdcfb66a002983f96d7b1c647dafe68e3eec1f7ba7d4e8c09" - }, - { - "bytes": 9979, - "exportable": true, - "file": "build_vectors.py", - "sha256": "f4f5f48e0550112bfee7de418f800eb4230fd532a89f7ad83aff6d41bbf576bf" - }, - { - "bytes": 14751, - "exportable": true, - "file": "build_census.py", - "sha256": "567062fa0a6dbde62773b09642be472e78caff23ed0d34c78b9fdc74d0b02801" - }, - { - "bytes": 12741624, - "exportable": false, - "file": "probe/requests.jsonl", - "note": "STS paths", - "sha256": "234bdcc89e9e17f2e9cb6e5f9af848ed671ab50c1773baa59290a25554cc0c1c" - }, - { - "bytes": 25733878, - "exportable": false, - "file": "probe/observed.jsonl", - "note": "keyed to STS paths", - "sha256": "65b4f13868aed0c19b8eb89d44510f5b57c7c33be3a77c2115dea597a0fd9eb3" - }, - { - "bytes": 25373291, - "exportable": false, - "file": "probe/endpoints.jsonl", - "note": "carries pattern_id values", - "sha256": "2fb4ec62ca97a1916ea0081f810f6a71f2ff284b9547294a628d3819b9808506" - } - ], - "frozen_targets": { - "count": 63, - "export_policy": "target hashes only; STS raw path / rule / message never leave the machine", - "frozen_now": true, - "targets": [ - { - "a_sha": "8fc3e85a91e6a3382e7943c30ffebb0e73bf7248", - "b_sha": "78a156675dbae402072e8d459b432adb4d95ebe7", - "class": "natural", - "side": "A", - "target_hash": "019c1917a561054077057d91eb836960755895bcba2b91cd31469c2bf2f0ffff" - }, - { - "a_sha": "0976c490c3dc1d2d902ad56f018b697748d1846f", - "b_sha": "e75247c4aa5f2d1b9a9c4882d6aad4fd960d57b6", - "class": "natural", - "side": "B", - "target_hash": "00456dec6c0b12ddc1a9fbfe97f913d3eb453e064929047d40d36ec7f8598586" - }, - { - "a_sha": "3dec1a7fea70fba8943aad4a8d830f8943ed08e3", - "b_sha": "77c2a1201925c053c0ccb32e99b164d91544bdf3", - "class": "natural", - "side": "B", - "target_hash": "01b4cba941583391be4d5d925a9f4ee6a731aaf995f40696dd2a12c5336b3d71" - }, - { - "a_sha": "24b87dbe8b9b0a69d279d3958c69fbf6273ad140", - "b_sha": "65dd590f169d643cab8288ae061e97947a1b630c", - "class": "natural", - "side": "B", - "target_hash": "0031b354794d1f364c9a0039f8da092ef3121b28a69bbcdf626bf67d121b626f" - }, - { - "a_sha": "84c043b5176ce7233a510870027bf66c151460c9", - "b_sha": "b616f1866c40bd3452929107a4b6b3a884bf3476", - "class": "natural", - "side": "A", - "target_hash": "0005e46875760299c4c69084934b4334bd23467bcd7e7d5edacbe663aaac91bf" - }, - { - "a_sha": "926cafc5aeddf77741fbfc46dc65eae8d09e187b", - "b_sha": "35a05f2862db661f641740e9724e0fad79e3e1df", - "class": "natural", - "side": "B", - "target_hash": "0065288c60cd88ea40e604183d59dd9d6c9d2d7fb89564d80c8ce1e497dedbec" - }, - { - "a_sha": "43b7b873cc2343483298f2455fafc9245d435d21", - "b_sha": "24c0616e7478b685c42e59c0471f1c8b7ee05cc5", - "class": "natural", - "side": "B", - "target_hash": "0003eea893224d287ebfe4f7e7bbf6ef4fcd1e86f293bd702cd10d72992b7010" - }, - { - "a_sha": "44dc8219ea4891fa9a171b0e818e3e0bb4a7b402", - "b_sha": "23934dee4e5b765209dbf986276b2d23e2398725", - "class": "natural", - "side": "A", - "target_hash": "001877050d9d7798641f374cf298b71a36b4d310802645609fc3d95c767afef6" - }, - { - "a_sha": "4985c3875c877494245f4de9530c3e2f1bd5b2f4", - "b_sha": "6dbe1fe1dd6b3f0a1e413a62aa34e01f275d9963", - "class": "natural", - "side": "B", - "target_hash": "0049ac5a22b93af6cf1e9153d03b27b1bb4bf87acf4dca2619c8cd501d908b96" - }, - { - "a_sha": "23c1ffb619fbfed7583099174865861cc865e1cf", - "b_sha": "dcaa21029d62ba69185c6245cd81d2640f4f0b75", - "class": "natural", - "side": "A", - "target_hash": "013fcf3aa03053f4af146b2f3d0cf28f750b58e6ce64420484b7efe72dcfd358" - }, - { - "a_sha": "7f456ee66a50d60ec266f338e285d63545d96bc4", - "b_sha": "32c0ee7223fa53165a9564c23105e9f18c08003d", - "class": "natural", - "side": "A", - "target_hash": "00275052e98fb1cf463bf3f349ea6867ffcef385a2d2c4a5d8a856be453d9fea" - }, - { - "a_sha": "35af9e7e9f68a5a785be672597a866a54dd7f691", - "b_sha": "0b8926d23e5af365ae3985528216399454c4e32d", - "class": "natural", - "side": "A", - "target_hash": "009afeaaf18eecbc4af19cd05593f3820390d397a4bd3160503f1a73984e47de" - }, - { - "a_sha": "94abf2c11eb293d79ad6a1ecca93823638d38a3e", - "b_sha": "4ce2c9d9bdb9ed80217aa1b6461007ba95df605e", - "class": "natural", - "side": "A", - "target_hash": "023bfe79660d09999a3cdfb7221a6d26c1f7d6e98f39a7b4dba0ab3aed322129" - }, - { - "a_sha": "4b207123b8c80f3fa2c5552b9cedc879050842a0", - "b_sha": "d8b278181910858024ec6a8be539fd6be1eb31d1", - "class": "natural", - "side": "B", - "target_hash": "000baa05235e8a5786daf67ac3d62be77d38c5cbf28d53f33bf4b908f25b070a" - }, - { - "a_sha": "cb1c5efb1081484e634583e9f40f99d50a9984e7", - "b_sha": "25307b509e3eb236724a703b7e29c55edad198f9", - "class": "natural", - "side": "B", - "target_hash": "000540ec2181e16dcc3f2b023d7a1be5826401e081f24553ed46a19a62d93e2c" - }, - { - "a_sha": "670485e81c4c291281da91a48175958bdaaae5b9", - "b_sha": "b1524ccd9d578ceead7eb29d47dfce7a6a3e1559", - "class": "natural", - "side": "B", - "target_hash": "003ec0dd78fb7edc35072e9b9e89693be89e828a65ee6700465363d0cc968205" - }, - { - "a_sha": "5338bb2f4b00b0d4a5e0144a11d6d4d9d65505fc", - "b_sha": "3b9a55b7768a8ca1b278dc6290883fd721e466a4", - "class": "natural", - "side": "A", - "target_hash": "017d2327c4155d8a6ce4ff264cffa723b37ac6a5bfa9d92d241b86e0bba9de10" - }, - { - "a_sha": "d36efc2ec4871c188eb946c254a78bc02879e667", - "b_sha": "2e0d263bf779c5a8be31795377f52db14d6dc723", - "class": "natural", - "side": "A", - "target_hash": "0018ff9a1033667afa8e949653994f24c37457573bbe768a1475a924c08de32e" - }, - { - "a_sha": "2f36bc3746c8ae5f9b25c1871b3b3b3e4aff599d", - "b_sha": "24ae36a2e0824800b3e88b7f02bc71f1c2a091d8", - "class": "natural", - "side": "B", - "target_hash": "002a7ecd549f356651affa8528804208e5cd24c0103828d1bd2ace79cad12c6b" - }, - { - "a_sha": "b507027502b565d9ceb1ef35533da945800b35fa", - "b_sha": "af6f78adebd0c7bd0f7e14e6978f18bd3fa1b2d0", - "class": "natural", - "side": "B", - "target_hash": "01979a5ce47cfa11de6272a1f0e4438f14b74cb478c2642924fdf12feb50804f" - }, - { - "a_sha": "474a064c28c3f8bdefac09ceac8d9fbced4d0e36", - "b_sha": "9d690194a0687c843f9df6bb3a8eba6ca0297d1b", - "class": "natural", - "side": "B", - "target_hash": "015d7586ae01889c1cd6b1923de9e45c947a50c859f00291ceb520b1892a5dbc" - }, - { - "a_sha": "3be7d79e7737f92d79fc2f4eedae1c248eb96b14", - "b_sha": "7650c1c7d839a481f4cac516c6d76e7cb53cc176", - "class": "natural", - "side": "B", - "target_hash": "00435514a32de9b3dedd318940847a7b11136c029a7bd2f4333bab00a27293f0" - }, - { - "a_sha": "9dd630b901e679c1e4b285b5da9636bc87a24c99", - "b_sha": "08efc9cf55e135067685fa7e1b43c761e38105f2", - "class": "natural", - "side": "B", - "target_hash": "007eb752462d00ac0af980f842606dcfa256b33b6c07e654132908fcf51393f1" - }, - { - "a_sha": "39cf720e3576a3dff4cfbceb1eef0011b4862771", - "b_sha": "6990905d4b5f1f3dad8e4d46a4fd33212e6efa97", - "class": "natural", - "side": "B", - "target_hash": "0007140cf48a2d6974798ad19b1c54e5a813d94b31df84f730b72acc8632d2ea" - }, - { - "a_sha": "1ca6808d21afe8c16c7d2999424361591bc73ece", - "b_sha": "9b104a46f4bdec3e50fc0f9f0c9a99aa3ae35c0f", - "class": "natural", - "side": "B", - "target_hash": "00cfaeb3504d25eb18e82c07e9864fca93ff31583cb635c87af6ee65b847560d" - }, - { - "a_sha": "4ca10bdb5a66c503884251b2bbe2881881248c0f", - "b_sha": "a3fdc19a4065e179f7260f8add250e57eeef1437", - "class": "natural", - "side": "B", - "target_hash": "0003f30fb1589f434372aa670f84226e18e02d01864672ee9d36223c92d94fc5" - }, - { - "a_sha": "bb4a027571b1da3ca20fc10f08480e346f7810bc", - "b_sha": "98ae2eb1d5dadce8bdfbf71177b974afa3cfe88d", - "class": "natural", - "side": "B", - "target_hash": "009d403c13b1e4410505c5c1e3e76f043744175b3dbc6f647b6e378321268b71" - }, - { - "a_sha": "2e85fa39ea9f360998276e6108c2b7f847078600", - "b_sha": "d91e0531c0845380f1192efcc0f3abeefb7e7586", - "class": "natural", - "side": "B", - "target_hash": "00cc39ace264e87b363819dfb852e049e010ecb670296cbe95cc502b99f464ad" - }, - { - "a_sha": "e138e5f7b9eaad81ae3304a8c88445c89d4de552", - "b_sha": "f2693d94fc990dd9aef0493b3730e7d4720ff460", - "class": "natural", - "side": "B", - "target_hash": "00743af11a8b0727d89c15427f708b28586055f057595ce4d8ca79029ff196c7" - }, - { - "a_sha": "db41d27b875f00b1b7fe86bf428ba93df3f845bc", - "b_sha": "8bad2c5fb7170d309d292ddbf6490bfb1754df67", - "class": "natural", - "side": "B", - "target_hash": "004a5885c8e7fab7efd8e3c7cc92640dbddae359fc8741c3364e0031eec68b8e" - }, - { - "a_sha": "1cc602f56bbcae60fb2f234806a2fb391f0361b5", - "b_sha": "c68b2ae6aa8774ffa3726d52d7acb15df1fb736a", - "class": "natural", - "side": "A", - "target_hash": "00536787a5e629329708c08cc54dabd4d291a2aea126f383e6df3fd6f05a5e3e" - }, - { - "a_sha": "1c1b289992ac87ea222b45b878ba9616a8c59e45", - "b_sha": "21b5ec4f59a56b3bbcced67f04d0c98955a487ae", - "class": "natural", - "side": "A", - "target_hash": "0113d20f113df7cc941e5155a20ab1c93a358f09957670e1135a0a790dc983b4" - }, - { - "a_sha": "68f0f0756a7b97dcb8be82d4ae963574320cf594", - "b_sha": "0966396986c6e8218c04e7141668ba0819bea01a", - "class": "natural", - "side": "A", - "target_hash": "008e87d4504821e93c6f6b9847824f33f69cfc5f14b9f88f989e50559ed1fd51" - }, - { - "a_sha": "4bb8e379dff83c47bce3081449bafbf05040071c", - "b_sha": "836a0835c512354db26411ee8ee64b27ab61a2b0", - "class": "natural", - "side": "A", - "target_hash": "0073f9d195a1be495bbd15709ba4df7398edb93683ec57afdb49e3a4b4422a64" - }, - { - "a_sha": "6f2d61e17cd0cc4a717d4689030c5c3df63b1cdb", - "b_sha": "7a1901e53c20c2a35d74d43a24c4961489d3bfbe", - "class": "natural", - "side": "B", - "target_hash": "016462dc819081df1e48d7c19e0b26e252aa77399776d321ea10cf573e73eeb9" - }, - { - "a_sha": "1ea89e3cad197e341ec8a2fcfe58b21d12285c56", - "b_sha": "a7390ceafbefb2c0c1c50dc2ac6bbfb8705e3879", - "class": "natural", - "side": "A", - "target_hash": "003611ada3786179bf831cdc94ae188e28a5358aac52636a46f1720ac2911faa" - }, - { - "a_sha": "de8ebce166416a5b96ba8183d581e7d580e488be", - "b_sha": "90a6a515d8cf0ee6e27862e616922da8f7cc20b5", - "class": "natural", - "side": "B", - "target_hash": "00d2ccff1fddfc486af0fcdb09aa74670e4fe3ecd93b3fcce1366c8e321a0a0a" - }, - { - "a_sha": "763827c1cd58b26cd07fbcaa661de438fa382f03", - "b_sha": "0e05adb3645392005176066c742ed5f832157f6f", - "class": "natural", - "side": "B", - "target_hash": "004d1318d836d2ea2d91b471807b63fad497fc5556f87175882722fc7b4d9353" - }, - { - "a_sha": "d99620c4a6d5faaa19b60049101d71b1aece4807", - "b_sha": "39ddadaf2a5afb5ed2d6d22bd8b1a05c2b162408", - "class": "natural", - "side": "A", - "target_hash": "012ae702ab92667178300e29213d7dcbca3d90e1af0f40e6f7f987c0425ae507" - }, - { - "a_sha": "831c24e38d23e5f7fb6b533ad95f79679b9259dc", - "b_sha": "23fe9a5fdca24c1df38a670e84ae71fbf9715cfd", - "class": "natural", - "side": "B", - "target_hash": "00a94225e1d38887c62b7f1d4e8269979c3e9f9cdf64e7def533876f7650dc89" - }, - { - "a_sha": "ee291896d0e4965afa4bbc966d5871b152dc64ff", - "b_sha": "df906d4231baa3692147357f8e015db535ba1899", - "class": "natural", - "side": "B", - "target_hash": "0154e12685dfbb3b64c5d5aeeed5f6c81dd348986eb4d92ea245428e5b6bcf83" - }, - { - "a_sha": "61afc0f97bc294972be1f1998ec4557642d028a7", - "b_sha": "092ffb3e914f3300a706cbe744acac57c4adb5f4", - "class": "natural", - "side": "B", - "target_hash": "013f6d91bcd812455ee0f373d2e380852eae034dc94e44ee9fb103def8cedb08" - }, - { - "a_sha": "38238bab8a358ca3dd0021b0db5239158a8d3aaa", - "b_sha": "fb9274afaf49d385599b08e7af4a2f50f63249b4", - "class": "natural", - "side": "B", - "target_hash": "014ad6b74e7a5817ef14e942d919f171df15f09abdbab42fe6aa545020e9f4b8" - }, - { - "a_sha": "2ea25fa26bd14092d769c22f5e06eaee810aa764", - "b_sha": "17ab5013d58abffbff61bfff85aa35288631320b", - "class": "natural", - "side": "A", - "target_hash": "002de59aeda9403d1402503f882f783407893c7b9b768949acfe1790d8a8fe6e" - }, - { - "a_sha": "34e395d72eb030dbf9e58428bb9e45f45ef38841", - "b_sha": "a0eef7e2507e57dff958e278a4ebeb0073fd833b", - "class": "natural", - "side": "A", - "target_hash": "00cb5749e99a06a3f1f3305dab00a2776184c0c8593e110f4025211d04da0d0c" - }, - { - "a_sha": "188c08130fca39575e9865fe5970d551c5b883e4", - "b_sha": "43e13bce8cc84845085dc93630c72521b8bfc0f1", - "class": "natural", - "side": "A", - "target_hash": "000b0eec287d314b2212bd01a94138fd885e663132c7c8bebc47fe0b09a48ec0" - }, - { - "a_sha": "98ae2eb1d5dadce8bdfbf71177b974afa3cfe88d", - "b_sha": "fe1d8f020cd6e5645e472b4962695ea1d9e83352", - "class": "natural", - "side": "A", - "target_hash": "0047992bd70a6a98a165b7bf16d80d5c42e96dca661c25e86c0cefc26493dfb0" - }, - { - "a_sha": "91a968d769b3faf70075d6ba64338b2b8e279e0d", - "b_sha": "de93f04f8f5e541e6817d49d39ad5ea51d1ba69b", - "class": "natural", - "side": "B", - "target_hash": "00024fb3fca0cdaa5cb674e0687d62acc5e8bc66d78b6229a53762e405473716" - }, - { - "a_sha": "40fedf3a94963e876f9e528647f90e4159fea575", - "b_sha": "cf540cfc1be063d8ee90eae8d4d94de329271cee", - "class": "natural", - "side": "B", - "target_hash": "01496bbd32a213c0975e8511d94173056d33fe343db16d00d6afc552e209f9bc" - }, - { - "a_sha": "ced633eaab3c40ad76a7e598ad04ce4d747ad140", - "b_sha": "39a2b4209ae318740af9fe70012bb9ee2f41cbca", - "class": "natural", - "side": "B", - "target_hash": "0033bb86cf87f5d4557bbd7841a3bdf9d68635c1cfcf4671d6d035a6777ba65f" - }, - { - "a_sha": "56082d530eed27cc951f49c5f1be87490a26c665", - "b_sha": "6566eaff07b5819abe1a10441c6b56bde0a489af", - "class": "rename", - "side": "A", - "target_hash": "b49985e047cafc1c27295577813f382674b0bc60423d57afb0fe6d40a87f9ed4" - }, - { - "a_sha": "085887bef5635148ae68820f522f69ccb7fd4e60", - "b_sha": "151b6c7c95251e88a3532ac44bc2a37e4182dc32", - "class": "rename", - "side": "A", - "target_hash": "bd4fc6b36d94eede561328be9f222f5e57d7aa1e9e0558c2f61e53ffe55003e7" - }, - { - "a_sha": "43e13bce8cc84845085dc93630c72521b8bfc0f1", - "b_sha": "45eca2c5d94c62845b559f3b77fbe2402ca4b2ae", - "class": "rename", - "side": "A", - "target_hash": "20d7910d844d8e59daa2980a277ab069d1b39ca766be1cd92ce7188d4754a6a1" - }, - { - "a_sha": "487adaa5659830f0c86b0b7a114384f4b6d89742", - "b_sha": "013e0f53f0c1d543bb787958f7db0f3db39dc802", - "class": "rename", - "side": "A", - "target_hash": "1c25a988c9d752f505e2143a3a44e8ea541641c8c8f955ff50066ecfe7a2f220" - }, - { - "a_sha": "24b87dbe8b9b0a69d279d3958c69fbf6273ad140", - "b_sha": "65dd590f169d643cab8288ae061e97947a1b630c", - "class": "copy", - "index_within_pair": 0, - "side": "A", - "target_hash": "215657260b1b2ae93307264209246d6ba33439be7b4d892db9f0d67cdc5c2919" - }, - { - "a_sha": "24b87dbe8b9b0a69d279d3958c69fbf6273ad140", - "b_sha": "65dd590f169d643cab8288ae061e97947a1b630c", - "class": "copy", - "index_within_pair": 1, - "side": "A", - "target_hash": "271b65a6319bab9eddf88287d6e58ba6ff77f01d7e32f095248fa1274762ef97" - }, - { - "a_sha": "382e47831ba349a1531af31c083f0698e7081a6d", - "b_sha": "a2a91589e4ec029db729f865a740f35e28615a9e", - "class": "copy", - "index_within_pair": 0, - "side": "A", - "target_hash": "2e8c01a1088b2297b02ebe58f6d32b1bd7768fd17c6192b56af965fe24941c46" - }, - { - "a_sha": "382e47831ba349a1531af31c083f0698e7081a6d", - "b_sha": "a2a91589e4ec029db729f865a740f35e28615a9e", - "class": "copy", - "index_within_pair": 1, - "side": "A", - "target_hash": "6e086d75960ce45894c83f74595d923312b34cdcee8410e7c60d81afd014d1df" - }, - { - "a_sha": "fe628c8648cfc26064aff82b9d4af45d77d4bb4c", - "b_sha": "6f95d2e891d009ea2ddf74d1de259c4b1556b5f4", - "class": "copy", - "index_within_pair": 0, - "side": "A", - "target_hash": "01f58d218af8331424c2353267a71f534dcae00bd4d9c4d8bc5c86972e92ad81" - }, - { - "a_sha": "fe628c8648cfc26064aff82b9d4af45d77d4bb4c", - "b_sha": "6f95d2e891d009ea2ddf74d1de259c4b1556b5f4", - "class": "copy", - "index_within_pair": 1, - "side": "A", - "target_hash": "1e3f30e3b239796683cb6100d3316b29e990c0e15e5006f49e0ce9141bc4d2a0" - }, - { - "a_sha": "45eca2c5d94c62845b559f3b77fbe2402ca4b2ae", - "b_sha": "70c244495e56a0190f2cac2b7f4aaf09859fd529", - "class": "copy", - "index_within_pair": 0, - "side": "A", - "target_hash": "4289effbf50a5fc362496f3411b5b0aa17a0178ad952c2c95487bf9f6f1e4ee4" - }, - { - "a_sha": "45eca2c5d94c62845b559f3b77fbe2402ca4b2ae", - "b_sha": "70c244495e56a0190f2cac2b7f4aaf09859fd529", - "class": "copy", - "index_within_pair": 1, - "side": "A", - "target_hash": "ea092a34e98d3c228e420e17b329fc446b53bf6ce8fcab98b8e0cf5da1ae87f0" - }, - { - "a_sha": "542e9b6aecc6e47ed09affdd16d97309c4378d69", - "b_sha": "9663baae7284d9e31d16f6ca401c97fe1f897701", - "class": "copy", - "index_within_pair": 0, - "side": "A", - "target_hash": "1d6ce244cfae6b14b079d3acf8ee36382f2c9f18e64f41b6248f0f5dd5551170" - } - ] - }, - "further_pre_freeze_reconnaissance": "PROHIBITED from this point", - "hard_challenge": { - "frozen_hard_sample": { - "copy": { - "from_targetable_pairs": 5, - "no_target_pairs": 20, - "of_frozen_pairs": 25, - "targets": 9 - }, - "rename": { - "from_frozen_pairs": 21, - "no_target_pairs": 17, - "targets": 4 - }, - "total": 13 - }, - "hard_pass_criterion": { - "both_required": true, - "condition_1": "unsafe_relation_errors(B3) == 0 across all adjudicable hard groups", - "condition_2": "correct_resolved(B3) >= max(correct_resolved(B1), correct_resolved(B2)) + 3", - "if_safe_but_fewer_than_3_added": "HARD-INCONCLUSIVE, not FAIL" - }, - "per_class_percentage_thresholds": "PROHIBITED at n=4 and n=9", - "pooled_into_primary_precision": false, - "reported_separately": true, - "superseded_criterion": { - "old_text": "B3 has fewer unsafe relation errors than B1/B2", - "why_impossible": "B1 and B2 both require same_pattern_id, and pattern_id includes the path. Across a rename or a copy the path changes, so the baselines return unresolved, which is not an unsafe error. Their unsafe-error count is therefore naturally 0, and requiring fewer than 0 is unsatisfiable." - }, - "unsafe_relation_error_definition": [ - "false continuation", - "fabricated branch", - "fabricated birth or death", - "invented endpoint", - "silent cardinality loss" - ] - }, - "manifest_revision": { - "b3_executed": false, - "findings_applied": [ - { - "assessment": "valid. A precision or correctness violation had no declared verdict, so the choice between FAIL and INCONCLUSIVE remained available after unblinding.", - "fix": "primary_holdout.outcome_table: six rows, precedence-ordered, total", - "id": "P2-a", - "thresholds_changed": false, - "title": "natural axis had no total number-to-verdict rule" - }, - { - "assessment": "valid. PASS is not a token of any axis.", - "fix": "concrete token-by-token mapping over all 11 declared tokens", - "id": "P2-b", - "title": "disposition mapping used tokens the taxonomy does not declare" - }, - { - "assessment": "MERGE-INCONCLUSIVE is preregistered on every run, so a global INCONCLUSIVE -> HOLD would make PROCEED unreachable forever.", - "fix": "renamed to axis_disposition with an explicit no_global_aggregator clause", - "id": "self-found", - "title": "the mapping read as a global aggregator" - }, - { - "assessment": "natural became table-backed, so leaving the scope at [rename, branch] would have created the next finding inside the same commit.", - "fix": "consistency_rule.scope now [natural, rename, branch]; hard and merge remain out", - "id": "self-found", - "title": "adding a natural table changed what the consistency scope must cover" - } - ], - "frozen_targets_unchanged": true, - "history": [ - { - "commit": "cde73560f029235959b7775a8466fca059c3f34e", - "revision": 1, - "sha256": "b22cb93d7ea1dc2392a318796abc3cfbf67615c300de40dc124f1039b0471d82" - }, - { - "commit": "9c0a8618f131e1bf0362d80538bb2af41f2d2c9a", - "reason": "five external review findings on revision 1", - "revision": 2, - "sha256": "df0e9f8d7cac50b969ac5d53003885d2ad3d8c05584d011b9e0bcef09ef2c043" - }, - { - "commit": "6555e68944296c0f47dd5dbf52c59c76548f8422", - "reason": "permission-shaped booleans replaced by prohibitions", - "revision": 3, - "sha256": "b113a31813636c31c2a78685631a8c4304f80bb13dd341151a604d0bc05d8d31" - }, - { - "commit": "03d56ace0623db64abe9db9d88c385717968ccca", - "reason": "no verdict axis passable without resolving anything", - "revision": 4, - "sha256": "2b8ce7018b6a67a6a522ac8d77638b4ccbd3f76634aa15b2f790443d0e6ad614" - }, - { - "commit": "5c89ba515da4e5e84b3fb7749ccdf9d99bd28ffa", - "reason": "rename failure token aligned with its own axis", - "revision": 5, - "sha256": "f4c5181eaf0948dc38f6d86c884404331a5111f275228d78cd7ca22c0f97f47e" - }, - { - "commit": "ac54fcb3420550f0423366842fdd488f69bf1b3a", - "reason": "consistency rule narrowed to the axes it checks", - "revision": 6, - "sha256": "7d087e8a8dc0ab06cc39b5328824c6ad902d2b87c6f996f7239d068b10bf72fd" - } - ], - "reason": "two external review findings on revision 6, plus one consequence of fixing them", - "revision": 7, - "supersedes_commit": "ac54fcb3420550f0423366842fdd488f69bf1b3a", - "supersedes_sha256": "7d087e8a8dc0ab06cc39b5328824c6ad902d2b87c6f996f7239d068b10bf72fd", - "targets_sampling_truth_or_b3_surface_touched": false, - "truth_labels_created": false, - "what_this_revision_did_not_touch": [ - "verdict_taxonomy.axes", - "rename_capability.outcome_table", - "branch_capability.outcome_table", - "hard_challenge", - "frozen_targets", - "truth_protocol", - "seeds" - ] - }, - "merge_capability": { - "ceiling": "MERGE-INCONCLUSIVE", - "merge_detector_addition_prohibited": true, - "merged_symbols": "UNAVAILABLE by preregistration", - "note": "fixed for this experiment; not a defect to be repaired before the benchmark" - }, - "phase": "RH-M0", - "primary_holdout": { - "b2_coverage_loss_disposition": { - "frozen_before_results": true, - "metric": "absolute percentage-point difference, coverage(B2) - coverage(B3), on the 50 natural targets", - "rule": [ - { - "condition": "loss <= 10 percentage points", - "effect": "no constraint from this rule" - }, - { - "condition": "loss > 10 percentage points", - "effect": "the natural axis is CAPPED at INCONCLUSIVE. It cannot be PASS-NATURAL however high the precision is." - } - ], - "supersedes": "the earlier wording 'requires explicit utility justification and cannot be an unconditional PASS', which left the verdict undetermined and therefore decidable after unblinding", - "utility_justification": "may be recorded for the record, but it CANNOT raise a capped verdict. An after-the-fact argument is not an acceptance criterion.", - "why_capped_rather_than_FAIL": "losing coverage against a deliberately conservative baseline is evidence that the policy is unhelpful, not evidence that it is wrong. FAIL is reserved for incorrect relations." - }, - "b3_coverage_over_b0": "the earlier requirement 'B3 coverage > B0' is subsumed by row 3 and is therefore not a separate row. B0 always answers unresolved, so coverage(B0) = 0, and >= 20 B3-resolved groups implies coverage(B3) > 0. Recorded rather than dropped.", - "definition": "the primary external-validity sample is the 50 STS natural truth targets ONLY", - "explicit_clarification": "the 63 selected targets do NOT themselves satisfy the >= 40 criterion. The criterion counts ADJUDICABLE TRUTH GROUPS, which is not known until truth labelling is complete.", - "fail_vs_inconclusive_doctrine": "FAIL marks observed incorrectness: a fabricated relation or a precision breach. INCONCLUSIVE marks insufficient evidence or insufficient utility. This is the same doctrine already frozen for the B2 coverage loss, where losing coverage against a deliberately conservative baseline is evidence of unhelpfulness rather than of error.", - "hard_targets_in_primary_denominator": false, - "outcome_table": [ - { - "condition": "any fabricated new/ended where truth has a counterpart", - "row": 1, - "verdict": "FAIL" - }, - { - "condition": "fewer than 40 adjudicable truth groups among the 50 natural targets", - "row": 2, - "verdict": "INCONCLUSIVE" - }, - { - "condition": "fewer than 20 B3-resolved natural groups", - "row": 3, - "verdict": "INCONCLUSIVE" - }, - { - "condition": "resolved precision < 95%", - "row": 4, - "verdict": "FAIL" - }, - { - "condition": "coverage(B2) - coverage(B3) > 10 percentage points", - "row": 5, - "verdict": "INCONCLUSIVE" - }, - { - "condition": "otherwise", - "row": 6, - "verdict": "PASS-NATURAL" - } - ], - "precedence": "rows are evaluated in order; the first matching row decides. Row 1 therefore dominates every other outcome.", - "requirements": [ - ">= 40 adjudicable truth groups among the 50 natural targets, otherwise INCONCLUSIVE", - ">= 20 B3-resolved natural groups, otherwise INCONCLUSIVE", - "resolved precision >= 95%", - "zero fabricated new/ended where truth has a counterpart", - "B3 coverage > B0", - "B3-vs-B2 coverage loss is subject to the frozen disposition below" - ], - "supersedes": "the earlier requirements list, which attached 'otherwise INCONCLUSIVE' to only two of six criteria and left a precision or correctness violation without a declared verdict", - "total": "the table is total: row 6 is unconditional, so every combination of measurements maps to exactly one verdict", - "why": "a deliberately oversampled hard slice must not be able to rescue a failing natural-history sample by arithmetic" - }, - "producer_and_toolchain": { - "dotnet_sdk": "8.0.424", - "git": "2.55.0.windows.3", - "git_transform_detection": "git diff --name-status -M50% -C50% --find-copies-harder ", - "normalize_strip_rule": "--strip is MANDATORY and the strip leaf must be identical for every revision; the producer is invoked from the parent of the checkout so paths come out repository-relative", - "ownaudit_commit_used_for_normalisation": "d0b0dbd3f96d2676fa795935b224b67d032b5447", - "producer": "own-check", - "producer_own_net_commit": "76324fe4ccf71702d4386e29462227747d4fa54e", - "python": "3.12.10", - "roslyn": "Microsoft.CodeAnalysis.CSharp 4.9.2" - }, - "rename_capability": { - "all_four_targets_enter_labelling": true, - "exhaustive": "the four rows cover every reachable combination. correct_resolved can never exceed the number of genuine groups, so no case falls between rows 3 and 4.", - "failure_token_note": "row 1 emits FAIL, the token declared for this axis. The rename token set is deliberately NOT widened to FAIL/PIVOT: that compound belongs to the branch axis by preregistration, and a result vocabulary that grows to fit one row stops discriminating.", - "no_percentage_metric": "3/4 and 4/4 are not statistics; raw counts only", - "outcome_table": [ - { - "condition": "any unsafe relation error on an adjudicable rename target", - "row": 1, - "verdict": "FAIL" - }, - { - "condition": "fewer than 3 adjudicated rename targets have truth = continued 1:1 through the rename", - "row": 2, - "verdict": "RENAME-INCONCLUSIVE" - }, - { - "condition": "at least 3 genuine continued-1:1 rename groups exist, B3 correctly resolves at least 3 of them to the exact counterpart, and there are zero unsafe relation errors", - "row": 3, - "verdict": "PASS-RENAME" - }, - { - "condition": "at least 3 genuine continued-1:1 rename groups exist, zero unsafe relation errors, but B3 correctly resolves only 0-2 of them", - "row": 4, - "verdict": "RENAME-INCONCLUSIVE" - } - ], - "pair_replacement": "PROHIBITED", - "precedence": "rows are evaluated in order; the first matching row decides. Row 1 therefore dominates every other outcome.", - "supersedes": "the earlier rule required only >= 3 adjudicable rename groups and zero unsafe errors. Four `unresolved` answers satisfy both, so PASS-RENAME was reachable without resolving a single rename.", - "truth_must_be_continued_1_to_1": "the denominator counts only groups whose TRUTH is continued 1:1 across the rename. Correctly calling `ended` or any other outcome on a renamed file does not demonstrate R-CONT-RENAME, and must not be able to earn the axis.", - "why_threshold_is_three": [ - "1 of 4 validates nothing", - "2 correct resolutions are a useful signal but still RENAME-INCONCLUSIVE", - "3 exact resolutions with zero unsafe errors permit a cautious PASS-RENAME", - "4 of 4 is a stronger descriptive result; no separate percentage threshold is introduced" - ], - "wording_note": "this field means the four rename targets are all IN the labelling set. It does NOT mean labels exist: truth_labels_created is false and every target still requires two blinded labels plus human adjudication." - }, - "repositories": { - "ownnet": { - "adjacent_pairs": 238, - "first_parent_revisions": 239, - "natural_pairs_authoritative": 119, - "natural_pairs_preliminary_superseded": 120, - "ref": "main", - "role": "discovery / reference-evaluator development", - "tip": "76324fe4ccf71702d4386e29462227747d4fa54e" - }, - "sts": { - "adjacent_pairs": 2326, - "audit_subdir": "SectorTS/", - "first_parent_revisions": 2327, - "frozen_tip": "3588e530f88844d93b1466bf1e1176c6cbe3450b", - "ref": "dsector_optimization", - "repo_root": "STS_new", - "role": "sealed holdout" - } - }, - "sample": { - "boolean_naming_rule": "every constraint in this manifest is stated as a prohibition that is true, never as a permission that is false. A reader never has to decide what a false permission means.", - "no_target": { - "copy": [ - { - "a_sha": "5338bb2f4b00b0d4a5e0144a11d6d4d9d65505fc", - "b_sha": "3b9a55b7768a8ca1b278dc6290883fd721e466a4" - }, - { - "a_sha": "476377fc4042d2640f3216cc8b511747e7b30d8c", - "b_sha": "deaba36b1988cb3938911dd9603090113d54ede3" - }, - { - "a_sha": "64273291f8af21d09b3627ba207859474eee4126", - "b_sha": "d2ec8b75979e8004c9fa387a4701e76f39015f22" - }, - { - "a_sha": "3acf720c38423399655a17f26f0d8d9ed5cd1a9a", - "b_sha": "651143d81a165d8f3b32035f040c76487da083a0" - }, - { - "a_sha": "90155829d7eba2dccd103fc0e1f07fc48e4b2bd7", - "b_sha": "db22cad2bb7538ee577ea7d0d1f2cdee8692525c" - }, - { - "a_sha": "fa35e9e12f12d062169d56ff06575cee818f2851", - "b_sha": "f764bbaee0ea9edf53a269d691185209edfb6e10" - }, - { - "a_sha": "795708716e69ee3ae1d240916780a2e0504cf7b7", - "b_sha": "99f2187b458a9e9f3b4ad265bb939c3311fee7fa" - }, - { - "a_sha": "214fd169a5685ad9b9e5a0b966e620b5bb5fb8a1", - "b_sha": "65dd5e874c1789f697196cfe65500be63ddc043f" - }, - { - "a_sha": "d3e9d7458b371a2c32a0246ee478fa132f5060e1", - "b_sha": "7e503d76b2b5454cb387dd104a656a507569fb73" - }, - { - "a_sha": "93a403eacedd45856b510fa37217d0fc304c1b6d", - "b_sha": "678d35ee6f00eb03bac6bde853bbd6364dea4765" - }, - { - "a_sha": "5497e6f2595f8892c6e349b440605645a3e5bdeb", - "b_sha": "50d27b7d7b7213ef7b5da8a51bf2338298667d1c" - }, - { - "a_sha": "44bbf4f4169bc528ae0d160fabe5276e08858f58", - "b_sha": "9de66b1c358b78dfd57e94c4c07c138d2c5fc2e8" - }, - { - "a_sha": "b8928200765a4c897232474746ad1f7bc97f0e9b", - "b_sha": "ac25065781ec626c74b5e3aad2571225c946c572" - }, - { - "a_sha": "ca5f459c26d4dc2df567524dea46e700448cb36f", - "b_sha": "5a889983c199b4c7b1bd238e21d9bb94bfe2a778" - }, - { - "a_sha": "8c336c21ba24c4bd0b0fc82a909d0544b4091310", - "b_sha": "2896e0a5dc3c0689e297add2352a5494b12f4252" - }, - { - "a_sha": "266507d8b4e07cc432e0b255b22df3cd6593c4cc", - "b_sha": "b4f61dc1e5d889de0b76eb9db67b3737dad1b889" - }, - { - "a_sha": "e6d75ec61f55e0ec7c4985337535fee7d4be1fdf", - "b_sha": "3457bae4aafed114d50007777eebeec5374b40db" - }, - { - "a_sha": "eb32e9e3d09735e3518ba7033474ac8b9b2ce94d", - "b_sha": "623477c4cbcc3d7ea5ba3e59dc8584e313738e88" - }, - { - "a_sha": "03576cb716f7cfcf7140d0200747c054fbe78dc7", - "b_sha": "3a4c06f822e1c866fcae0caccef4d252b6583071" - }, - { - "a_sha": "5dcdbe09aff48ff16da565074b87a9893cbe6235", - "b_sha": "20a2c8d3ccc26469fc2d0ec0e433b188a1f95e55" - } - ], - "natural": [], - "rename": [ - { - "a_sha": "199f1f3861373db6f708bd9328835005ded09e48", - "b_sha": "c834553e06247467207c23d769790b3e8b882ce3" - }, - { - "a_sha": "46711ed0edd7d4e0a1516d53c5cef0f52d07c890", - "b_sha": "c83601783777060a37b7ea871bc9d99c99d5e060" - }, - { - "a_sha": "d3e9d7458b371a2c32a0246ee478fa132f5060e1", - "b_sha": "7e503d76b2b5454cb387dd104a656a507569fb73" - }, - { - "a_sha": "f4837ba267f45b59a08fb4e447fd6d309663e899", - "b_sha": "501ea55f3a8c8cc2bb98506db1af82fe40e57c37" - }, - { - "a_sha": "266507d8b4e07cc432e0b255b22df3cd6593c4cc", - "b_sha": "b4f61dc1e5d889de0b76eb9db67b3737dad1b889" - }, - { - "a_sha": "1aae361342944f6ecdb318232beeb63d5300f693", - "b_sha": "733c66323e135784cede110ecb214820d971776a" - }, - { - "a_sha": "57a4f31120ea10c175a8cd2fe64ee2f5c42ac0cb", - "b_sha": "24184d41dfc3d45eb7c4850e7e65e131df4e332a" - }, - { - "a_sha": "5b1878547f6a0aa8c98d7ade5404e6c5bd4ef88b", - "b_sha": "e084c0e70b9116584792addad57bb0e2e4273cc0" - }, - { - "a_sha": "f54427c2d709e6a8ce9ec8198b8a47d28d379f11", - "b_sha": "1cf267c8f828b2ded1d49a7da344b17e7f707304" - }, - { - "a_sha": "1af00413e334ddf38013a61c193c186ce84142aa", - "b_sha": "2d571bcb3a51132f9200cda367a66352faaf02c6" - }, - { - "a_sha": "a09c9c568ff831b3984094a5ccf8c9fc17e214f3", - "b_sha": "4e56082fc90a3a9b5b238bf43c6c0ddf38345b8b" - }, - { - "a_sha": "6e9e7a0464bc4328dbd4c7772e07ab9f82021548", - "b_sha": "63215dab2e9edb7d49c6df2e1ed7e4a0513d7b18" - }, - { - "a_sha": "dd21aae9d2512016df3861d1c9ee1335244f8372", - "b_sha": "0a16e9414e8f2687d22ecf4221ded154bf923aa5" - }, - { - "a_sha": "db204a602f8c4c1b887875bf0a36e116490da28e", - "b_sha": "f5975747fbb48fd703e6835bbea617684c91fb6e" - }, - { - "a_sha": "b3841a5a63567d704eae00771b099242119893a5", - "b_sha": "c4f60597cecb20b4e5de9e549043d89e001b919c" - }, - { - "a_sha": "65dd5e874c1789f697196cfe65500be63ddc043f", - "b_sha": "a39a8cc7dd6757e3c761594aa57f20924eea082c" - }, - { - "a_sha": "80c944a14b8f1f7e840ed629fc6151a1adbdcd9f", - "b_sha": "f4951cff971483469ae388eab0266e647cb87f6f" - } - ], - "status": "NO_TARGET entries remain in the frame as evidence of sample sparsity. They are NOT truth groups. Replacing them is prohibited, and no pair may be substituted for them: see sample.no_target_replacement_prohibited." - }, - "no_target_replacement_prohibited": true, - "pair_selection_frozen": true, - "pair_selection_modification_prohibited": true, - "selected_pairs": { - "copy": 25, - "natural": 50, - "rename": 21 - }, - "sts_copy_pairs": 71, - "sts_frame_pairs": 2326, - "sts_natural_candidates": 1915, - "sts_rename_pairs": 21, - "targets_after_census": { - "copy": 9, - "natural": 50, - "rename": 4, - "total": 63 - } - }, - "seeds": { - "b3_used_in_selection": false, - "canonical_serialisation": "json.dumps(array, ensure_ascii=False, separators=(\",\",\":\")).encode(\"utf-8\")", - "occurrence_id_used": false, - "selection_rank_rule": "rank_key = sha256(seed_hex || 0x00 || repo_id || 0x00 || a_sha || 0x00 || b_sha); ascending; ties by (a_sha, b_sha)", - "selection_seed": "ce730e47092805a8705ebc0f9b78f663a9c150139a650128f278afa9c393067e", - "side_determination": { - "copy": { - "rule": "forced to A by construction", - "side_hash_consulted": false, - "why": "a copy candidate must be an A-side finding lying on a copy SOURCE path, for the same reason as rename." - }, - "natural": { - "applies_to": "all 50 natural targets", - "decision": "sha256(canonical).digest()[0] & 1 ; 0 -> A, 1 -> B", - "preimage": [ - "rh-m0-side/v1", - "", - "sts", - "", - "" - ], - "rule": "hash-derived" - }, - "rename": { - "rule": "forced to A by construction", - "side_hash_consulted": false, - "why": "a rename candidate must be an A-side finding lying on a rename SOURCE path. The successor side cannot hold the predecessor occurrence, so there is nothing for a coin to decide." - }, - "reproduction_warning": { - "correct_reproduction": "for class natural derive the side from the hash; for classes rename and copy use side = \"A\" unconditionally, then compute the target preimage with that side", - "issue": "applying the natural side rule to the hard classes does NOT reproduce the frozen targets. Recomputed with the frozen truth_seed it yields side B for 6 of the 13 hard targets, and because also enters the target-hash preimage those 6 target hashes would not match.", - "measured_divergence": { - "copy": "4 of 9", - "natural": "0 of 50", - "rename": "2 of 4", - "total": "6 of 63" - }, - "worked_example": { - "a_sha": "43e13bce", - "b_sha": "45eca2c5", - "frozen_target_records": "A", - "hash_rule_would_select": "B", - "side_hash_first_byte": "0xa3" - } - } - }, - "side_preimage": [ - "rh-m0-side/v1", - "", - "sts", - "", - "" - ], - "target_preimage": [ - "rh-m0-target/v1", - "", - "sts", - "", - "", - "", - "", - "", - "", - "", - "" - ], - "target_rule": "minimum lexical sha256 hex over the candidate set, where the candidate set is class-dependent: all findings on the hash-selected side for natural, and the A-side findings on rename/copy source paths for the hard classes", - "truth_seed": "7e4f4650a0109d52a4e0492e6d1a087b99a4af328b72ee3144ec746d9f85d7ed" - }, - "status": "FROZEN", - "step1_contract": { - "canonical_merge_commit": "011c1362861f6b8b20c45e8ebd5bcb912401c1c0", - "contracts": { - "contracts/finding-lineage-decision-v1.json": { - "git_blob": "610654aaf80a6ee7f4e8a96cd1f6095b8f0e5c80", - "sha256": "2172a9e16e9e33309a51ef4d7827086131641047595d2912ab442154d73e1ff0" - }, - "contracts/finding-lineage-v1.json": { - "git_blob": "211c73ed9672b7408b43f52f36e31ec3e4370cd6", - "sha256": "12c180e96fabf186454be89b8f9418684597a116df1428d5b12e2f3c9638c441" - } - }, - "contracts_identical_at_reviewed_head_and_merge": true, - "merge_shape": { - "branch_retained": "claude/lineage-decision-policy", - "commits_preserved": 84, - "parent_1": "d0b0dbd3f96d2676fa795935b224b67d032b5447", - "parent_2": "6dcc02f7d82bebeb5db9be83f77ab8c5455f5692", - "parents": 2, - "squashed": false - }, - "merged_at": "2026-08-29T08:06:47Z", - "normalizer_unchanged_by_merge": { - "consequence": "RH-0 and RH-O1 measurements remain valid against canonical main", - "files": [ - "aggregate/normalize.py", - "aggregate/provenance.py", - "aggregate/sarif_read.py" - ], - "identical": true - }, - "reviewed_step1_head": "6dcc02f7d82bebeb5db9be83f77ab8c5455f5692" - }, - "stop_conditions": { - "after_manifest_commit": "STOP and report the commit and hash", - "first_sts_b3_run_requires": "a hashed, frozen truth artifact", - "m0_contains_no_correctness_result": true, - "no_sts_b3_output_before_frozen_truth": true, - "reference_evaluator_may_run_on": "Own.NET only, after this freeze" - }, - "sts_b3_output_exists": false, - "truth_labels_created": false, - "truth_protocol": { - "ai_agreement_is_not_truth": "two agreeing agents produce PROPOSED truth only; the final truth artifact requires human/owner adjudication and sign-off", - "evidence_cards_contain": [ - "source at A and B", - "raw finding", - "ordinary Git diff", - "rename and copy metadata", - "commit context" - ], - "label_vocabulary": [ - "continued 1:1", - "branched 1:N", - "merged N:1", - "ended", - "new", - "unresolved-by-truth", - "unadjudicable" - ], - "labeler_a": "blind to B3", - "labeler_b": "blind to B3 and to labeler A", - "labelers_must_not_see": [ - "B3 output", - "baseline output", - "rule ids", - "evidence sets", - "applicable_rules", - "licensed_by", - "outcomes" - ], - "labels_per_target": 2, - "resolved_branch_or_merge_carries": "exact endpoint sets, not only the outcome", - "targets_frozen_now": 63, - "truth_artifact_hashed_and_frozen_before": "the first STS B3 run" - }, - "verdict_taxonomy": { - "axes": { - "branch": [ - "PASS-BRANCH", - "BRANCH-INCONCLUSIVE", - "FAIL/PIVOT" - ], - "hard": [ - "HARD-PASS", - "HARD-INCONCLUSIVE", - "FAIL" - ], - "merge": [ - "MERGE-INCONCLUSIVE" - ], - "natural": [ - "PASS-NATURAL", - "INCONCLUSIVE", - "FAIL" - ], - "rename": [ - "PASS-RENAME", - "RENAME-INCONCLUSIVE", - "FAIL" - ] - }, - "axes_are_five": [ - "natural", - "hard", - "rename", - "branch", - "merge" - ], - "axis_disposition": { - "branch_axis_exception": "the branch axis retains the compound token FAIL/PIVOT because it was preregistered that way and is internally consistent with its own token set. It is recorded here as a known wart, not silently rewritten: changing a frozen token to satisfy a style preference is exactly the kind of post-hoc edit this manifest exists to prevent.", - "mapping": { - "BRANCH-INCONCLUSIVE": "HOLD", - "FAIL": "PIVOT", - "FAIL/PIVOT": "PIVOT", - "HARD-INCONCLUSIVE": "HOLD", - "HARD-PASS": "PROCEED", - "INCONCLUSIVE": "HOLD", - "MERGE-INCONCLUSIVE": "HOLD", - "PASS-BRANCH": "PROCEED", - "PASS-NATURAL": "PROCEED", - "PASS-RENAME": "PROCEED", - "RENAME-INCONCLUSIVE": "HOLD" - }, - "mapping_is_concrete": "every entry names a token that the taxonomy actually declares. No prefix, suffix or regular-expression normalisation is used, because a rule that has to parse its own vocabulary is a rule that will one day parse it wrongly.", - "merge_entry_is_axis_local": "MERGE-INCONCLUSIVE -> HOLD is admissible only as an axis-local disposition. It cannot by itself imply a global HOLD.", - "no_global_aggregator": "No global composite disposition is frozen by RH-M0. MERGE-INCONCLUSIVE is a preregistered capability ceiling present on every run, so read as a global rule this mapping would make PROCEED unreachable forever. The global decision stays compositional and is not smuggled back into a monolithic gate.", - "what_this_is": "the local disposition associated with ONE axis verdict. It does NOT aggregate the five-axis composite into a single experiment or project disposition.", - "why": "a verdict records what was measured; a disposition records what the project does next. Fusing them into one token, as FAIL/PIVOT does, makes the measured result depend on a management decision and is awkward for any consumer that groups by verdict." - }, - "axis_independence_note": "HARD-PASS pools rename and copy, so its +3 requirement can in principle be satisfied entirely by copy targets while no rename is resolved at all. That is why rename carries its own axis with its own resolution floor, and why a composite verdict must report both. HARD-PASS together with RENAME-INCONCLUSIVE is a coherent and honest result, not a contradiction.", - "composite": true, - "consistency_rule": { - "how_the_defect_was_missed": "the rename table was written by analogy with the branch table, which legitimately uses FAIL/PIVOT. Prose review compares a row against its neighbours; only a mechanical check compares it against its own axis.", - "mechanical_result": { - "declared_but_unreachable": 0, - "emitted_not_declared": 0 - }, - "method": "cross-product of the outcome_table rows of the in-scope axes against verdict_taxonomy.axes, in both directions", - "no_tables_added_for_uniformity": "the other three axes are NOT given outcome tables to make the rule uniform. Extending a frozen specification for the sake of a checker's symmetry is the wrong direction: the checker is narrowed to what it checks.", - "non_table_backed_axes": { - "hard": "governed by hard_challenge criteria, not outcome_table", - "merge": "fixed singleton ceiling MERGE-INCONCLUSIVE" - }, - "rule": "for every table-backed axis, every outcome_table verdict MUST belong to that axis's declared token set, and every declared token for that axis MUST be reachable from at least one outcome-table row", - "scope": [ - "natural", - "rename", - "branch" - ], - "scope_change_note": "natural entered the scope in revision 7, when it gained an outcome table. The scope tracks the structure; it is not a fixed list.", - "scope_reason": "these are the table-backed axes. hard and merge declare their tokens through acceptance criteria and a fixed ceiling, not through rows.", - "supersedes": "the revision-5 wording 'every verdict appearing in any outcome_table ... and every declared token SHOULD be reachable', which was unscoped and therefore unreproducible for three of the five axes", - "verified_mechanically": true, - "why_the_scope_matters": "applying the reachability half to all five axes would report 7 falsely unreachable tokens - natural 3, hard 3, merge 1 - purely because those axes have no rows. The previous wording promised that broader scope while the reported result covered only the two axes actually checked." - }, - "disposition_coverage_rule": { - "result_at_this_revision": { - "mapped_but_undeclared": 0, - "tokens_declared": 11, - "tokens_unmapped": 0 - }, - "rule": "every token declared in verdict_taxonomy.axes MUST have exactly one entry in axis_disposition.mapping", - "verified_mechanically": true, - "why": "finding two of this round was precisely a mapping written against tokens that did not exist. A rule that is checked cannot drift back into that state silently." - }, - "every_run_reports_one_verdict_per_axis": true, - "examples": [ - { - "branch": "PASS-BRANCH", - "hard": "HARD-PASS", - "merge": "MERGE-INCONCLUSIVE", - "natural": "PASS-NATURAL", - "rename": "PASS-RENAME" - }, - { - "branch": "BRANCH-INCONCLUSIVE", - "hard": "HARD-INCONCLUSIVE", - "merge": "MERGE-INCONCLUSIVE", - "natural": "PASS-NATURAL", - "rename": "RENAME-INCONCLUSIVE" - }, - { - "branch": "BRANCH-INCONCLUSIVE", - "hard": "HARD-INCONCLUSIVE", - "merge": "MERGE-INCONCLUSIVE", - "natural": "INCONCLUSIVE", - "rename": "RENAME-INCONCLUSIVE" - } - ], - "examples_schema_note": "every example carries all five axes. A composite with fewer than five entries is malformed.", - "merge_axis_is_fixed": "MERGE-INCONCLUSIVE regardless of any other outcome", - "monolithic_pass_prohibited": "a single PASS hides which capability was actually exercised; every run reports one verdict per axis", - "no_vacuous_pass": { - "resolution_floor_per_axis": { - "branch": ">= 3 correct resolutions with exact successor endpoint sets", - "hard": "correct_resolved(B3) >= max(correct_resolved(B1), correct_resolved(B2)) + 3", - "merge": "not applicable; the axis is fixed at MERGE-INCONCLUSIVE", - "natural": ">= 20 B3-resolved natural groups", - "rename": ">= 3 correct exact-counterpart resolutions on genuine continued-1:1 rename groups" - }, - "rule": "no axis may reach a PASS verdict without a positive count of correct resolutions", - "why": "zero unsafe errors is trivially achieved by answering `unresolved` everywhere. Safety without resolution is not a capability, and an axis that can be passed by silence measures nothing." - } - } +{ + "artifact": "rh-m0-manifest", + "b3_executed": false, + "baselines": { + "B0": { + "rule": "always unresolved" + }, + "B1": { + "candidates": "for the target endpoint, candidates on the opposite side with same_pattern_id", + "decision": "unique minimum abs(start_line_A - start_line_B) => continued", + "never_emits": [ + "new", + "ended", + "branched", + "merged" + ], + "tie_or_no_candidate": "unresolved" + }, + "B2": { + "candidates": "same_pattern_id AND same enclosing_symbol", + "decision": "exactly one candidate => continued", + "never_emits": [ + "new", + "ended", + "branched", + "merged" + ], + "otherwise": "unresolved" + }, + "B3": { + "at_canonical_merge": "011c1362861f6b8b20c45e8ebd5bcb912401c1c0", + "contracts": [ + "finding-lineage/v1", + "finding-lineage-decision/v1" + ], + "reviewed_step1_head": "6dcc02f7d82bebeb5db9be83f77ab8c5455f5692", + "rule": "the exact canonical frozen Step-1 policy" + }, + "observation_sources": { + "anchored_content": "RH-O1 adapter, exact physical line bytes, terminator excluded", + "enclosing_symbol": "RH-O1 adapter, Roslyn 4.9.2, canonical Git blob, spec-frozen display format", + "line_drift": "holds iff start_line_A != start_line_B; no threshold", + "path_rename / copy_record": "git diff -M50% -C50% --find-copies-harder", + "still_unavailable": [ + "renamed_symbol_record", + "reformatted_paths", + "merged_symbols", + "boundary: enclosing-site-added", + "boundary: enclosing-site-removed" + ] + } + }, + "branch_capability": { + "census_status": "the targetability census established STRUCTURAL POSSIBILITY only: 24 of 25 copy pairs carry a branch-capable source, but a finding actually sits on such a source in only 5 pairs, 16 candidate occurrences, 9 selected targets. This asserts nothing about branch truth.", + "exhaustive": "the five rows cover every reachable combination", + "outcome_table": [ + { + "condition": "any unsafe relation error on an adjudicable branch target, including a lost or invented successor endpoint", + "row": 1, + "verdict": "FAIL/PIVOT" + }, + { + "condition": "fewer than 3 adjudicated groups whose truth label is exactly `branched 1:N`", + "note": "regardless of B3 output", + "row": 2, + "verdict": "BRANCH-INCONCLUSIVE" + }, + { + "condition": "at least 3 adjudicated groups with truth label exactly `branched 1:N`, but all of them inside a SINGLE revision pair", + "note": "preregistered explicitly. Several frozen copy targets share a revision pair, so this case is reachable; one pair cannot demonstrate a capability that must generalise across history.", + "row": 3, + "verdict": "BRANCH-INCONCLUSIVE" + }, + { + "condition": "at least 3 adjudicated groups with truth label exactly `branched 1:N` spanning >= 2 distinct revision pairs, and B3 correctly resolves at least 3 of them with the exact successor endpoint set, zero silent cardinality loss and zero invented endpoints", + "row": 4, + "verdict": "PASS-BRANCH" + }, + { + "condition": "at least 3 adjudicated groups with truth label exactly `branched 1:N` spanning >= 2 distinct revision pairs, zero unsafe relation errors, but B3 correctly resolves only 0-2 of them", + "row": 5, + "verdict": "BRANCH-INCONCLUSIVE" + } + ], + "precedence": "rows are evaluated in order; the first matching row decides. Row 1 therefore dominates every other outcome.", + "supersedes": "the earlier row 'all endpoint sets exact' was vacuously true when B3 produced no endpoint sets at all, so PASS-BRANCH was reachable with zero resolutions. Row 4 now requires at least 3 correct resolutions.", + "truth_labels_referenced": [ + "branched 1:N" + ], + "truth_token_note": "conditions name the canonical token from truth_protocol.label_vocabulary verbatim. The earlier wording said `branched` and used the prose phrase 'genuine branched group'; under exact comparison neither matches any truth label, so PASS-BRANCH was unreachable." + }, + "contains_correctness_result": false, + "descriptive_strata": { + "affects_inclusion_or_thresholds_or_target_count_or_labelling": false, + "carried_correction": [ + "Identical pattern_id multiset means only that (path, rule, message) multiplicities are unchanged.", + "It does NOT imply identical physical occurrences, anchors, enclosing symbols, anchored content, or trivial lineage." + ], + "computed_after": "M0 freeze only", + "full_observation_tuple": [ + "pattern_id", + "start_line", + "start_column", + "enclosing_symbol_hash", + "anchored_content_hash" + ], + "strata": { + "S0": "full observation multiset identical", + "S1": "pattern_id multiset identical, full observation multiset differs", + "S2": "pattern_id multiset differs" + } + }, + "digest_note": "the SHA-256 of this manifest lives in the sidecar rh-m0-manifest.sha256; a digest stored inside the file it describes cannot equal that file's digest", + "frozen_input_hashes": [ + { + "bytes": 5855, + "exportable": true, + "file": "rh0-environment.json", + "sha256": "3fe4892175d678a2b95b1128be1db00f51cc8d470d226076fe26b5538ad639a0" + }, + { + "bytes": 1125100, + "exportable": true, + "file": "rh0-frame-sts.jsonl", + "sha256": "1b5eaaa962fa0f692ce636e1dcc94761a7df4b18962b328679d810ae8e49f26a" + }, + { + "bytes": 113197, + "exportable": true, + "file": "rh0-frame-ownnet.jsonl", + "sha256": "6590cedd99fd6078332f6f6ed3e1d5d20c66364d182acbe62f07937f40582e92" + }, + { + "bytes": 42522, + "exportable": true, + "file": "rh0-selection-preview.json", + "sha256": "c8645a79e4ba6752d2627b6bf5159ffe06a222ed4ceffb3484a43254103e5587" + }, + { + "bytes": 2497, + "exportable": true, + "file": "rh0-toolchain-sensitivity.json", + "sha256": "e50a36c2c789371db1401c1512a6134aeebede46e49b12ed3a1456449ac599e5" + }, + { + "bytes": 11111, + "exportable": true, + "file": "rh0-signal-observability.json", + "sha256": "6188bd381045f3f3cdef72c7b1dfd0f37f2a1d05d192adbcfdc8e09322da6f6a" + }, + { + "bytes": 2827, + "exportable": true, + "file": "rh0-bundle.sha256", + "sha256": "a6e30f693f36e760f1ebc42165963d206d0eb04abf7b77db815fe7e1084cc8a9" + }, + { + "bytes": 10164, + "exportable": true, + "file": "rh0-o1-observation-spec.json", + "sha256": "9e82b78d55f7e120357d086523ba76a113e6a15de8be0d179fbbff72f2a488e0" + }, + { + "bytes": 8403, + "exportable": true, + "file": "rh0-o1-observation-vectors.json", + "sha256": "00e8507db4b851dbc30acaf1796f5e5292ed1213d940868e6c46e705dfb5e54e" + }, + { + "bytes": 6133, + "exportable": true, + "file": "rh0-o1-coverage.json", + "sha256": "c074bdc6e9dbaf588061f73c4d00f70aa61bb664131cfddbd86f670abf697872" + }, + { + "bytes": 1971, + "exportable": true, + "file": "rh0-o1-bundle.sha256", + "sha256": "1b816e92619f2abbc80efe6cd7371cc9472dcb2e2799b4c447fb60ed47821e0f" + }, + { + "bytes": 4768, + "exportable": true, + "file": "rh0-m0-pending-corrections.json", + "sha256": "aef9aef2bf1adbf13b4d238f1fefeaf180669dea4b22c71dfaa5951d22e54116" + }, + { + "bytes": 41469, + "exportable": true, + "file": "rh0-m0-targetability.json", + "sha256": "1c25cd6ca15c8e66be8bcb86ded3357c6cf2b297825ce6e67d60ca81360faa4b" + }, + { + "bytes": 93, + "exportable": true, + "file": "rh0-m0-targetability.sha256", + "sha256": "e8ed0af417cd504242af4ddde79c7840b352542cf8f1ba28ea6f56ef5713bac0" + }, + { + "bytes": 15512, + "exportable": true, + "file": "obs-adapter/Program.cs", + "sha256": "77f72efcac7b44093fd86e225d3e56f138685bba25082889a3cd87f12408cf31" + }, + { + "bytes": 582, + "exportable": true, + "file": "obs-adapter/ObsAdapter.csproj", + "sha256": "bff9cb29c17456f11c1910595f01b343081051077d895a14b0ff86b2e2aaec53" + }, + { + "bytes": 2210, + "exportable": true, + "file": "vectors/setup.sh", + "sha256": "ea5db72931a94b8cb092972095dda00ebfb105534c1e17714b8a7cccc562cd12" + }, + { + "bytes": 7547, + "exportable": true, + "file": "vectors/observed.jsonl", + "sha256": "081b63180adae18b647726b8a66ad0f91751fea73b53c29a8a00a0d4c880df45" + }, + { + "bytes": 2567, + "exportable": true, + "file": "probe.sh", + "sha256": "59e0a566b84ed8ed1b1882108bb6e5b29b224ce52475c1caeaab2e26f4b5caf9" + }, + { + "bytes": 2835, + "exportable": true, + "file": "make_requests.py", + "sha256": "e01ee9d61ead3731279deaa24854468d3eaed7543d86775d461ccfc2954ca1d2" + }, + { + "bytes": 7540, + "exportable": true, + "file": "build_coverage.py", + "sha256": "4e1b8c1f0f3d797cdcfb66a002983f96d7b1c647dafe68e3eec1f7ba7d4e8c09" + }, + { + "bytes": 9979, + "exportable": true, + "file": "build_vectors.py", + "sha256": "f4f5f48e0550112bfee7de418f800eb4230fd532a89f7ad83aff6d41bbf576bf" + }, + { + "bytes": 14751, + "exportable": true, + "file": "build_census.py", + "sha256": "567062fa0a6dbde62773b09642be472e78caff23ed0d34c78b9fdc74d0b02801" + }, + { + "bytes": 12741624, + "exportable": false, + "file": "probe/requests.jsonl", + "note": "STS paths", + "sha256": "234bdcc89e9e17f2e9cb6e5f9af848ed671ab50c1773baa59290a25554cc0c1c" + }, + { + "bytes": 25733878, + "exportable": false, + "file": "probe/observed.jsonl", + "note": "keyed to STS paths", + "sha256": "65b4f13868aed0c19b8eb89d44510f5b57c7c33be3a77c2115dea597a0fd9eb3" + }, + { + "bytes": 25373291, + "exportable": false, + "file": "probe/endpoints.jsonl", + "note": "carries pattern_id values", + "sha256": "2fb4ec62ca97a1916ea0081f810f6a71f2ff284b9547294a628d3819b9808506" + } + ], + "frozen_targets": { + "count": 63, + "export_policy": "target hashes only; STS raw path / rule / message never leave the machine", + "frozen_now": true, + "targets": [ + { + "a_sha": "8fc3e85a91e6a3382e7943c30ffebb0e73bf7248", + "b_sha": "78a156675dbae402072e8d459b432adb4d95ebe7", + "class": "natural", + "side": "A", + "target_hash": "019c1917a561054077057d91eb836960755895bcba2b91cd31469c2bf2f0ffff" + }, + { + "a_sha": "0976c490c3dc1d2d902ad56f018b697748d1846f", + "b_sha": "e75247c4aa5f2d1b9a9c4882d6aad4fd960d57b6", + "class": "natural", + "side": "B", + "target_hash": "00456dec6c0b12ddc1a9fbfe97f913d3eb453e064929047d40d36ec7f8598586" + }, + { + "a_sha": "3dec1a7fea70fba8943aad4a8d830f8943ed08e3", + "b_sha": "77c2a1201925c053c0ccb32e99b164d91544bdf3", + "class": "natural", + "side": "B", + "target_hash": "01b4cba941583391be4d5d925a9f4ee6a731aaf995f40696dd2a12c5336b3d71" + }, + { + "a_sha": "24b87dbe8b9b0a69d279d3958c69fbf6273ad140", + "b_sha": "65dd590f169d643cab8288ae061e97947a1b630c", + "class": "natural", + "side": "B", + "target_hash": "0031b354794d1f364c9a0039f8da092ef3121b28a69bbcdf626bf67d121b626f" + }, + { + "a_sha": "84c043b5176ce7233a510870027bf66c151460c9", + "b_sha": "b616f1866c40bd3452929107a4b6b3a884bf3476", + "class": "natural", + "side": "A", + "target_hash": "0005e46875760299c4c69084934b4334bd23467bcd7e7d5edacbe663aaac91bf" + }, + { + "a_sha": "926cafc5aeddf77741fbfc46dc65eae8d09e187b", + "b_sha": "35a05f2862db661f641740e9724e0fad79e3e1df", + "class": "natural", + "side": "B", + "target_hash": "0065288c60cd88ea40e604183d59dd9d6c9d2d7fb89564d80c8ce1e497dedbec" + }, + { + "a_sha": "43b7b873cc2343483298f2455fafc9245d435d21", + "b_sha": "24c0616e7478b685c42e59c0471f1c8b7ee05cc5", + "class": "natural", + "side": "B", + "target_hash": "0003eea893224d287ebfe4f7e7bbf6ef4fcd1e86f293bd702cd10d72992b7010" + }, + { + "a_sha": "44dc8219ea4891fa9a171b0e818e3e0bb4a7b402", + "b_sha": "23934dee4e5b765209dbf986276b2d23e2398725", + "class": "natural", + "side": "A", + "target_hash": "001877050d9d7798641f374cf298b71a36b4d310802645609fc3d95c767afef6" + }, + { + "a_sha": "4985c3875c877494245f4de9530c3e2f1bd5b2f4", + "b_sha": "6dbe1fe1dd6b3f0a1e413a62aa34e01f275d9963", + "class": "natural", + "side": "B", + "target_hash": "0049ac5a22b93af6cf1e9153d03b27b1bb4bf87acf4dca2619c8cd501d908b96" + }, + { + "a_sha": "23c1ffb619fbfed7583099174865861cc865e1cf", + "b_sha": "dcaa21029d62ba69185c6245cd81d2640f4f0b75", + "class": "natural", + "side": "A", + "target_hash": "013fcf3aa03053f4af146b2f3d0cf28f750b58e6ce64420484b7efe72dcfd358" + }, + { + "a_sha": "7f456ee66a50d60ec266f338e285d63545d96bc4", + "b_sha": "32c0ee7223fa53165a9564c23105e9f18c08003d", + "class": "natural", + "side": "A", + "target_hash": "00275052e98fb1cf463bf3f349ea6867ffcef385a2d2c4a5d8a856be453d9fea" + }, + { + "a_sha": "35af9e7e9f68a5a785be672597a866a54dd7f691", + "b_sha": "0b8926d23e5af365ae3985528216399454c4e32d", + "class": "natural", + "side": "A", + "target_hash": "009afeaaf18eecbc4af19cd05593f3820390d397a4bd3160503f1a73984e47de" + }, + { + "a_sha": "94abf2c11eb293d79ad6a1ecca93823638d38a3e", + "b_sha": "4ce2c9d9bdb9ed80217aa1b6461007ba95df605e", + "class": "natural", + "side": "A", + "target_hash": "023bfe79660d09999a3cdfb7221a6d26c1f7d6e98f39a7b4dba0ab3aed322129" + }, + { + "a_sha": "4b207123b8c80f3fa2c5552b9cedc879050842a0", + "b_sha": "d8b278181910858024ec6a8be539fd6be1eb31d1", + "class": "natural", + "side": "B", + "target_hash": "000baa05235e8a5786daf67ac3d62be77d38c5cbf28d53f33bf4b908f25b070a" + }, + { + "a_sha": "cb1c5efb1081484e634583e9f40f99d50a9984e7", + "b_sha": "25307b509e3eb236724a703b7e29c55edad198f9", + "class": "natural", + "side": "B", + "target_hash": "000540ec2181e16dcc3f2b023d7a1be5826401e081f24553ed46a19a62d93e2c" + }, + { + "a_sha": "670485e81c4c291281da91a48175958bdaaae5b9", + "b_sha": "b1524ccd9d578ceead7eb29d47dfce7a6a3e1559", + "class": "natural", + "side": "B", + "target_hash": "003ec0dd78fb7edc35072e9b9e89693be89e828a65ee6700465363d0cc968205" + }, + { + "a_sha": "5338bb2f4b00b0d4a5e0144a11d6d4d9d65505fc", + "b_sha": "3b9a55b7768a8ca1b278dc6290883fd721e466a4", + "class": "natural", + "side": "A", + "target_hash": "017d2327c4155d8a6ce4ff264cffa723b37ac6a5bfa9d92d241b86e0bba9de10" + }, + { + "a_sha": "d36efc2ec4871c188eb946c254a78bc02879e667", + "b_sha": "2e0d263bf779c5a8be31795377f52db14d6dc723", + "class": "natural", + "side": "A", + "target_hash": "0018ff9a1033667afa8e949653994f24c37457573bbe768a1475a924c08de32e" + }, + { + "a_sha": "2f36bc3746c8ae5f9b25c1871b3b3b3e4aff599d", + "b_sha": "24ae36a2e0824800b3e88b7f02bc71f1c2a091d8", + "class": "natural", + "side": "B", + "target_hash": "002a7ecd549f356651affa8528804208e5cd24c0103828d1bd2ace79cad12c6b" + }, + { + "a_sha": "b507027502b565d9ceb1ef35533da945800b35fa", + "b_sha": "af6f78adebd0c7bd0f7e14e6978f18bd3fa1b2d0", + "class": "natural", + "side": "B", + "target_hash": "01979a5ce47cfa11de6272a1f0e4438f14b74cb478c2642924fdf12feb50804f" + }, + { + "a_sha": "474a064c28c3f8bdefac09ceac8d9fbced4d0e36", + "b_sha": "9d690194a0687c843f9df6bb3a8eba6ca0297d1b", + "class": "natural", + "side": "B", + "target_hash": "015d7586ae01889c1cd6b1923de9e45c947a50c859f00291ceb520b1892a5dbc" + }, + { + "a_sha": "3be7d79e7737f92d79fc2f4eedae1c248eb96b14", + "b_sha": "7650c1c7d839a481f4cac516c6d76e7cb53cc176", + "class": "natural", + "side": "B", + "target_hash": "00435514a32de9b3dedd318940847a7b11136c029a7bd2f4333bab00a27293f0" + }, + { + "a_sha": "9dd630b901e679c1e4b285b5da9636bc87a24c99", + "b_sha": "08efc9cf55e135067685fa7e1b43c761e38105f2", + "class": "natural", + "side": "B", + "target_hash": "007eb752462d00ac0af980f842606dcfa256b33b6c07e654132908fcf51393f1" + }, + { + "a_sha": "39cf720e3576a3dff4cfbceb1eef0011b4862771", + "b_sha": "6990905d4b5f1f3dad8e4d46a4fd33212e6efa97", + "class": "natural", + "side": "B", + "target_hash": "0007140cf48a2d6974798ad19b1c54e5a813d94b31df84f730b72acc8632d2ea" + }, + { + "a_sha": "1ca6808d21afe8c16c7d2999424361591bc73ece", + "b_sha": "9b104a46f4bdec3e50fc0f9f0c9a99aa3ae35c0f", + "class": "natural", + "side": "B", + "target_hash": "00cfaeb3504d25eb18e82c07e9864fca93ff31583cb635c87af6ee65b847560d" + }, + { + "a_sha": "4ca10bdb5a66c503884251b2bbe2881881248c0f", + "b_sha": "a3fdc19a4065e179f7260f8add250e57eeef1437", + "class": "natural", + "side": "B", + "target_hash": "0003f30fb1589f434372aa670f84226e18e02d01864672ee9d36223c92d94fc5" + }, + { + "a_sha": "bb4a027571b1da3ca20fc10f08480e346f7810bc", + "b_sha": "98ae2eb1d5dadce8bdfbf71177b974afa3cfe88d", + "class": "natural", + "side": "B", + "target_hash": "009d403c13b1e4410505c5c1e3e76f043744175b3dbc6f647b6e378321268b71" + }, + { + "a_sha": "2e85fa39ea9f360998276e6108c2b7f847078600", + "b_sha": "d91e0531c0845380f1192efcc0f3abeefb7e7586", + "class": "natural", + "side": "B", + "target_hash": "00cc39ace264e87b363819dfb852e049e010ecb670296cbe95cc502b99f464ad" + }, + { + "a_sha": "e138e5f7b9eaad81ae3304a8c88445c89d4de552", + "b_sha": "f2693d94fc990dd9aef0493b3730e7d4720ff460", + "class": "natural", + "side": "B", + "target_hash": "00743af11a8b0727d89c15427f708b28586055f057595ce4d8ca79029ff196c7" + }, + { + "a_sha": "db41d27b875f00b1b7fe86bf428ba93df3f845bc", + "b_sha": "8bad2c5fb7170d309d292ddbf6490bfb1754df67", + "class": "natural", + "side": "B", + "target_hash": "004a5885c8e7fab7efd8e3c7cc92640dbddae359fc8741c3364e0031eec68b8e" + }, + { + "a_sha": "1cc602f56bbcae60fb2f234806a2fb391f0361b5", + "b_sha": "c68b2ae6aa8774ffa3726d52d7acb15df1fb736a", + "class": "natural", + "side": "A", + "target_hash": "00536787a5e629329708c08cc54dabd4d291a2aea126f383e6df3fd6f05a5e3e" + }, + { + "a_sha": "1c1b289992ac87ea222b45b878ba9616a8c59e45", + "b_sha": "21b5ec4f59a56b3bbcced67f04d0c98955a487ae", + "class": "natural", + "side": "A", + "target_hash": "0113d20f113df7cc941e5155a20ab1c93a358f09957670e1135a0a790dc983b4" + }, + { + "a_sha": "68f0f0756a7b97dcb8be82d4ae963574320cf594", + "b_sha": "0966396986c6e8218c04e7141668ba0819bea01a", + "class": "natural", + "side": "A", + "target_hash": "008e87d4504821e93c6f6b9847824f33f69cfc5f14b9f88f989e50559ed1fd51" + }, + { + "a_sha": "4bb8e379dff83c47bce3081449bafbf05040071c", + "b_sha": "836a0835c512354db26411ee8ee64b27ab61a2b0", + "class": "natural", + "side": "A", + "target_hash": "0073f9d195a1be495bbd15709ba4df7398edb93683ec57afdb49e3a4b4422a64" + }, + { + "a_sha": "6f2d61e17cd0cc4a717d4689030c5c3df63b1cdb", + "b_sha": "7a1901e53c20c2a35d74d43a24c4961489d3bfbe", + "class": "natural", + "side": "B", + "target_hash": "016462dc819081df1e48d7c19e0b26e252aa77399776d321ea10cf573e73eeb9" + }, + { + "a_sha": "1ea89e3cad197e341ec8a2fcfe58b21d12285c56", + "b_sha": "a7390ceafbefb2c0c1c50dc2ac6bbfb8705e3879", + "class": "natural", + "side": "A", + "target_hash": "003611ada3786179bf831cdc94ae188e28a5358aac52636a46f1720ac2911faa" + }, + { + "a_sha": "de8ebce166416a5b96ba8183d581e7d580e488be", + "b_sha": "90a6a515d8cf0ee6e27862e616922da8f7cc20b5", + "class": "natural", + "side": "B", + "target_hash": "00d2ccff1fddfc486af0fcdb09aa74670e4fe3ecd93b3fcce1366c8e321a0a0a" + }, + { + "a_sha": "763827c1cd58b26cd07fbcaa661de438fa382f03", + "b_sha": "0e05adb3645392005176066c742ed5f832157f6f", + "class": "natural", + "side": "B", + "target_hash": "004d1318d836d2ea2d91b471807b63fad497fc5556f87175882722fc7b4d9353" + }, + { + "a_sha": "d99620c4a6d5faaa19b60049101d71b1aece4807", + "b_sha": "39ddadaf2a5afb5ed2d6d22bd8b1a05c2b162408", + "class": "natural", + "side": "A", + "target_hash": "012ae702ab92667178300e29213d7dcbca3d90e1af0f40e6f7f987c0425ae507" + }, + { + "a_sha": "831c24e38d23e5f7fb6b533ad95f79679b9259dc", + "b_sha": "23fe9a5fdca24c1df38a670e84ae71fbf9715cfd", + "class": "natural", + "side": "B", + "target_hash": "00a94225e1d38887c62b7f1d4e8269979c3e9f9cdf64e7def533876f7650dc89" + }, + { + "a_sha": "ee291896d0e4965afa4bbc966d5871b152dc64ff", + "b_sha": "df906d4231baa3692147357f8e015db535ba1899", + "class": "natural", + "side": "B", + "target_hash": "0154e12685dfbb3b64c5d5aeeed5f6c81dd348986eb4d92ea245428e5b6bcf83" + }, + { + "a_sha": "61afc0f97bc294972be1f1998ec4557642d028a7", + "b_sha": "092ffb3e914f3300a706cbe744acac57c4adb5f4", + "class": "natural", + "side": "B", + "target_hash": "013f6d91bcd812455ee0f373d2e380852eae034dc94e44ee9fb103def8cedb08" + }, + { + "a_sha": "38238bab8a358ca3dd0021b0db5239158a8d3aaa", + "b_sha": "fb9274afaf49d385599b08e7af4a2f50f63249b4", + "class": "natural", + "side": "B", + "target_hash": "014ad6b74e7a5817ef14e942d919f171df15f09abdbab42fe6aa545020e9f4b8" + }, + { + "a_sha": "2ea25fa26bd14092d769c22f5e06eaee810aa764", + "b_sha": "17ab5013d58abffbff61bfff85aa35288631320b", + "class": "natural", + "side": "A", + "target_hash": "002de59aeda9403d1402503f882f783407893c7b9b768949acfe1790d8a8fe6e" + }, + { + "a_sha": "34e395d72eb030dbf9e58428bb9e45f45ef38841", + "b_sha": "a0eef7e2507e57dff958e278a4ebeb0073fd833b", + "class": "natural", + "side": "A", + "target_hash": "00cb5749e99a06a3f1f3305dab00a2776184c0c8593e110f4025211d04da0d0c" + }, + { + "a_sha": "188c08130fca39575e9865fe5970d551c5b883e4", + "b_sha": "43e13bce8cc84845085dc93630c72521b8bfc0f1", + "class": "natural", + "side": "A", + "target_hash": "000b0eec287d314b2212bd01a94138fd885e663132c7c8bebc47fe0b09a48ec0" + }, + { + "a_sha": "98ae2eb1d5dadce8bdfbf71177b974afa3cfe88d", + "b_sha": "fe1d8f020cd6e5645e472b4962695ea1d9e83352", + "class": "natural", + "side": "A", + "target_hash": "0047992bd70a6a98a165b7bf16d80d5c42e96dca661c25e86c0cefc26493dfb0" + }, + { + "a_sha": "91a968d769b3faf70075d6ba64338b2b8e279e0d", + "b_sha": "de93f04f8f5e541e6817d49d39ad5ea51d1ba69b", + "class": "natural", + "side": "B", + "target_hash": "00024fb3fca0cdaa5cb674e0687d62acc5e8bc66d78b6229a53762e405473716" + }, + { + "a_sha": "40fedf3a94963e876f9e528647f90e4159fea575", + "b_sha": "cf540cfc1be063d8ee90eae8d4d94de329271cee", + "class": "natural", + "side": "B", + "target_hash": "01496bbd32a213c0975e8511d94173056d33fe343db16d00d6afc552e209f9bc" + }, + { + "a_sha": "ced633eaab3c40ad76a7e598ad04ce4d747ad140", + "b_sha": "39a2b4209ae318740af9fe70012bb9ee2f41cbca", + "class": "natural", + "side": "B", + "target_hash": "0033bb86cf87f5d4557bbd7841a3bdf9d68635c1cfcf4671d6d035a6777ba65f" + }, + { + "a_sha": "56082d530eed27cc951f49c5f1be87490a26c665", + "b_sha": "6566eaff07b5819abe1a10441c6b56bde0a489af", + "class": "rename", + "side": "A", + "target_hash": "b49985e047cafc1c27295577813f382674b0bc60423d57afb0fe6d40a87f9ed4" + }, + { + "a_sha": "085887bef5635148ae68820f522f69ccb7fd4e60", + "b_sha": "151b6c7c95251e88a3532ac44bc2a37e4182dc32", + "class": "rename", + "side": "A", + "target_hash": "bd4fc6b36d94eede561328be9f222f5e57d7aa1e9e0558c2f61e53ffe55003e7" + }, + { + "a_sha": "43e13bce8cc84845085dc93630c72521b8bfc0f1", + "b_sha": "45eca2c5d94c62845b559f3b77fbe2402ca4b2ae", + "class": "rename", + "side": "A", + "target_hash": "20d7910d844d8e59daa2980a277ab069d1b39ca766be1cd92ce7188d4754a6a1" + }, + { + "a_sha": "487adaa5659830f0c86b0b7a114384f4b6d89742", + "b_sha": "013e0f53f0c1d543bb787958f7db0f3db39dc802", + "class": "rename", + "side": "A", + "target_hash": "1c25a988c9d752f505e2143a3a44e8ea541641c8c8f955ff50066ecfe7a2f220" + }, + { + "a_sha": "24b87dbe8b9b0a69d279d3958c69fbf6273ad140", + "b_sha": "65dd590f169d643cab8288ae061e97947a1b630c", + "class": "copy", + "index_within_pair": 0, + "side": "A", + "target_hash": "215657260b1b2ae93307264209246d6ba33439be7b4d892db9f0d67cdc5c2919" + }, + { + "a_sha": "24b87dbe8b9b0a69d279d3958c69fbf6273ad140", + "b_sha": "65dd590f169d643cab8288ae061e97947a1b630c", + "class": "copy", + "index_within_pair": 1, + "side": "A", + "target_hash": "271b65a6319bab9eddf88287d6e58ba6ff77f01d7e32f095248fa1274762ef97" + }, + { + "a_sha": "382e47831ba349a1531af31c083f0698e7081a6d", + "b_sha": "a2a91589e4ec029db729f865a740f35e28615a9e", + "class": "copy", + "index_within_pair": 0, + "side": "A", + "target_hash": "2e8c01a1088b2297b02ebe58f6d32b1bd7768fd17c6192b56af965fe24941c46" + }, + { + "a_sha": "382e47831ba349a1531af31c083f0698e7081a6d", + "b_sha": "a2a91589e4ec029db729f865a740f35e28615a9e", + "class": "copy", + "index_within_pair": 1, + "side": "A", + "target_hash": "6e086d75960ce45894c83f74595d923312b34cdcee8410e7c60d81afd014d1df" + }, + { + "a_sha": "fe628c8648cfc26064aff82b9d4af45d77d4bb4c", + "b_sha": "6f95d2e891d009ea2ddf74d1de259c4b1556b5f4", + "class": "copy", + "index_within_pair": 0, + "side": "A", + "target_hash": "01f58d218af8331424c2353267a71f534dcae00bd4d9c4d8bc5c86972e92ad81" + }, + { + "a_sha": "fe628c8648cfc26064aff82b9d4af45d77d4bb4c", + "b_sha": "6f95d2e891d009ea2ddf74d1de259c4b1556b5f4", + "class": "copy", + "index_within_pair": 1, + "side": "A", + "target_hash": "1e3f30e3b239796683cb6100d3316b29e990c0e15e5006f49e0ce9141bc4d2a0" + }, + { + "a_sha": "45eca2c5d94c62845b559f3b77fbe2402ca4b2ae", + "b_sha": "70c244495e56a0190f2cac2b7f4aaf09859fd529", + "class": "copy", + "index_within_pair": 0, + "side": "A", + "target_hash": "4289effbf50a5fc362496f3411b5b0aa17a0178ad952c2c95487bf9f6f1e4ee4" + }, + { + "a_sha": "45eca2c5d94c62845b559f3b77fbe2402ca4b2ae", + "b_sha": "70c244495e56a0190f2cac2b7f4aaf09859fd529", + "class": "copy", + "index_within_pair": 1, + "side": "A", + "target_hash": "ea092a34e98d3c228e420e17b329fc446b53bf6ce8fcab98b8e0cf5da1ae87f0" + }, + { + "a_sha": "542e9b6aecc6e47ed09affdd16d97309c4378d69", + "b_sha": "9663baae7284d9e31d16f6ca401c97fe1f897701", + "class": "copy", + "index_within_pair": 0, + "side": "A", + "target_hash": "1d6ce244cfae6b14b079d3acf8ee36382f2c9f18e64f41b6248f0f5dd5551170" + } + ] + }, + "further_pre_freeze_reconnaissance": "PROHIBITED from this point", + "hard_challenge": { + "frozen_hard_sample": { + "copy": { + "from_targetable_pairs": 5, + "no_target_pairs": 20, + "of_frozen_pairs": 25, + "targets": 9 + }, + "rename": { + "from_frozen_pairs": 21, + "no_target_pairs": 17, + "targets": 4 + }, + "total": 13 + }, + "hard_pass_criterion": { + "both_required": true, + "condition_1": "unsafe_relation_errors(B3) == 0 across all adjudicable hard groups", + "condition_2": "correct_resolved(B3) >= max(correct_resolved(B1), correct_resolved(B2)) + 3", + "if_safe_but_fewer_than_3_added": "HARD-INCONCLUSIVE, not FAIL" + }, + "hard_pass_criterion_retained_for_reference": { + "both_required": true, + "condition_1": "unsafe_relation_errors(B3) == 0 across all adjudicable hard groups", + "condition_2": "correct_resolved(B3) >= max(correct_resolved(B1), correct_resolved(B2)) + 3", + "if_safe_but_fewer_than_3_added": "HARD-INCONCLUSIVE, not FAIL" + }, + "outcome_table": [ + { + "condition": "unsafe_relation_errors(B3) > 0 on any adjudicable hard group", + "row": 1, + "verdict": "FAIL" + }, + { + "condition": "unsafe_relation_errors(B3) == 0 AND correct_resolved(B3) >= max(correct_resolved(B1), correct_resolved(B2)) + 3", + "row": 2, + "verdict": "HARD-PASS" + }, + { + "condition": "unsafe_relation_errors(B3) == 0 AND correct_resolved(B3) < max(correct_resolved(B1), correct_resolved(B2)) + 3", + "row": 3, + "verdict": "HARD-INCONCLUSIVE" + } + ], + "per_class_percentage_thresholds": "PROHIBITED at n=4 and n=9", + "pooled_into_primary_precision": false, + "precedence": "rows are evaluated in order; the first matching row decides. Row 1 therefore dominates every other outcome.", + "reported_separately": true, + "superseded_criterion": { + "old_text": "B3 has fewer unsafe relation errors than B1/B2", + "why_impossible": "B1 and B2 both require same_pattern_id, and pattern_id includes the path. Across a rename or a copy the path changes, so the baselines return unresolved, which is not an unsafe error. Their unsafe-error count is therefore naturally 0, and requiring fewer than 0 is unsatisfiable." + }, + "supersedes": "hard_pass_criterion, which declared HARD-PASS and HARD-INCONCLUSIVE but left unsafe_relation_errors > 0 without a verdict although FAIL is declared for the axis", + "thresholds_unchanged": "the +3 margin and the zero-unsafe requirement are exactly the previously frozen criterion; only the FAIL branch, which had no declared verdict, was added", + "total": "the table is total: rows 2 and 3 partition the unsafe == 0 case, and row 1 covers the remainder. Every combination maps to exactly one verdict.", + "unsafe_relation_error_definition": [ + "false continuation", + "fabricated branch", + "fabricated birth or death", + "invented endpoint", + "silent cardinality loss" + ] + }, + "manifest_revision": { + "b3_executed": false, + "findings_applied": [ + { + "assessment": "valid and blocking. The vocabulary declares `branched 1:N`; the table said `branched`. Under exact comparison PASS-BRANCH was unreachable.", + "fix": "all truth-sensitive branch conditions name the canonical token verbatim, and truth_labels_referenced lists it structurally", + "id": "P2-a", + "same_class_fixed_alongside": "the rename table embedded `continued 1:1` inside prose; it now names the token the same way", + "title": "branch referenced a truth token that does not exist" + }, + { + "assessment": "valid. unsafe_relation_errors > 0 had no verdict although FAIL is declared.", + "consequence": "hard became table-backed, so consistency_rule.scope now includes it", + "fix": "three-row precedence-ordered table; thresholds unchanged", + "id": "P2-b", + "title": "hard axis was not total" + }, + { + "assessment": "valid. sha256sum --check treats the trailing \\r as part of the filename and looks for rh-m0-manifest.json\\r, so the sidecar was not machine-verifiable even though the digest was correct.", + "fix": "sidecar written with LF; verified with sha256sum --check", + "id": "artifact-integrity", + "self_found_alongside": "the manifest itself was CRLF, which makes its digest depend on the writing platform: regenerating it on Linux would produce a different hash for identical content. Now written with LF.", + "title": "checksum sidecar written with CRLF" + } + ], + "frozen_targets_unchanged": true, + "history": [ + { + "commit": "cde73560f029235959b7775a8466fca059c3f34e", + "revision": 1, + "sha256": "b22cb93d7ea1dc2392a318796abc3cfbf67615c300de40dc124f1039b0471d82" + }, + { + "commit": "9c0a8618f131e1bf0362d80538bb2af41f2d2c9a", + "reason": "five external review findings on revision 1", + "revision": 2, + "sha256": "df0e9f8d7cac50b969ac5d53003885d2ad3d8c05584d011b9e0bcef09ef2c043" + }, + { + "commit": "6555e68944296c0f47dd5dbf52c59c76548f8422", + "reason": "permission-shaped booleans replaced by prohibitions", + "revision": 3, + "sha256": "b113a31813636c31c2a78685631a8c4304f80bb13dd341151a604d0bc05d8d31" + }, + { + "commit": "03d56ace0623db64abe9db9d88c385717968ccca", + "reason": "no verdict axis passable without resolving anything", + "revision": 4, + "sha256": "2b8ce7018b6a67a6a522ac8d77638b4ccbd3f76634aa15b2f790443d0e6ad614" + }, + { + "commit": "5c89ba515da4e5e84b3fb7749ccdf9d99bd28ffa", + "reason": "rename failure token aligned with its own axis", + "revision": 5, + "sha256": "f4c5181eaf0948dc38f6d86c884404331a5111f275228d78cd7ca22c0f97f47e" + }, + { + "commit": "ac54fcb3420550f0423366842fdd488f69bf1b3a", + "reason": "consistency rule narrowed to the axes it checks", + "revision": 6, + "sha256": "7d087e8a8dc0ab06cc39b5328824c6ad902d2b87c6f996f7239d068b10bf72fd" + }, + { + "commit": "6e3304a498951089f8945f6cb3ec99978e65e887", + "reason": "total natural outcome rule, concrete axis dispositions", + "revision": 7, + "sha256": "71f4c923d7091a1d88869d0ec7c97154e1aab15a6a1da82fb6ea8d1d074944a8" + } + ], + "reason": "two external review findings and one artifact-integrity finding on revision 7", + "revision": 8, + "supersedes_commit": "6e3304a498951089f8945f6cb3ec99978e65e887", + "supersedes_sha256": "71f4c923d7091a1d88869d0ec7c97154e1aab15a6a1da82fb6ea8d1d074944a8", + "targets_sampling_truth_or_b3_surface_touched": false, + "truth_labels_created": false, + "what_this_revision_did_not_touch": [ + "verdict_taxonomy.axes", + "truth_protocol", + "seeds", + "frozen_targets", + "primary_holdout.outcome_table", + "hard thresholds" + ] + }, + "merge_capability": { + "ceiling": "MERGE-INCONCLUSIVE", + "merge_detector_addition_prohibited": true, + "merged_symbols": "UNAVAILABLE by preregistration", + "note": "fixed for this experiment; not a defect to be repaired before the benchmark" + }, + "phase": "RH-M0", + "primary_holdout": { + "b2_coverage_loss_disposition": { + "frozen_before_results": true, + "metric": "absolute percentage-point difference, coverage(B2) - coverage(B3), on the 50 natural targets", + "rule": [ + { + "condition": "loss <= 10 percentage points", + "effect": "no constraint from this rule" + }, + { + "condition": "loss > 10 percentage points", + "effect": "the natural axis is CAPPED at INCONCLUSIVE. It cannot be PASS-NATURAL however high the precision is." + } + ], + "supersedes": "the earlier wording 'requires explicit utility justification and cannot be an unconditional PASS', which left the verdict undetermined and therefore decidable after unblinding", + "utility_justification": "may be recorded for the record, but it CANNOT raise a capped verdict. An after-the-fact argument is not an acceptance criterion.", + "why_capped_rather_than_FAIL": "losing coverage against a deliberately conservative baseline is evidence that the policy is unhelpful, not evidence that it is wrong. FAIL is reserved for incorrect relations." + }, + "b3_coverage_over_b0": "the earlier requirement 'B3 coverage > B0' is subsumed by row 3 and is therefore not a separate row. B0 always answers unresolved, so coverage(B0) = 0, and >= 20 B3-resolved groups implies coverage(B3) > 0. Recorded rather than dropped.", + "definition": "the primary external-validity sample is the 50 STS natural truth targets ONLY", + "explicit_clarification": "the 63 selected targets do NOT themselves satisfy the >= 40 criterion. The criterion counts ADJUDICABLE TRUTH GROUPS, which is not known until truth labelling is complete.", + "fail_vs_inconclusive_doctrine": "FAIL marks observed incorrectness: a fabricated relation or a precision breach. INCONCLUSIVE marks insufficient evidence or insufficient utility. This is the same doctrine already frozen for the B2 coverage loss, where losing coverage against a deliberately conservative baseline is evidence of unhelpfulness rather than of error.", + "hard_targets_in_primary_denominator": false, + "outcome_table": [ + { + "condition": "any fabricated new/ended where truth has a counterpart", + "row": 1, + "verdict": "FAIL" + }, + { + "condition": "fewer than 40 adjudicable truth groups among the 50 natural targets", + "row": 2, + "verdict": "INCONCLUSIVE" + }, + { + "condition": "fewer than 20 B3-resolved natural groups", + "row": 3, + "verdict": "INCONCLUSIVE" + }, + { + "condition": "resolved precision < 95%", + "row": 4, + "verdict": "FAIL" + }, + { + "condition": "coverage(B2) - coverage(B3) > 10 percentage points", + "row": 5, + "verdict": "INCONCLUSIVE" + }, + { + "condition": "otherwise", + "row": 6, + "verdict": "PASS-NATURAL" + } + ], + "precedence": "rows are evaluated in order; the first matching row decides. Row 1 therefore dominates every other outcome.", + "requirements": [ + ">= 40 adjudicable truth groups among the 50 natural targets, otherwise INCONCLUSIVE", + ">= 20 B3-resolved natural groups, otherwise INCONCLUSIVE", + "resolved precision >= 95%", + "zero fabricated new/ended where truth has a counterpart", + "B3 coverage > B0", + "B3-vs-B2 coverage loss is subject to the frozen disposition below" + ], + "supersedes": "the earlier requirements list, which attached 'otherwise INCONCLUSIVE' to only two of six criteria and left a precision or correctness violation without a declared verdict", + "total": "the table is total: row 6 is unconditional, so every combination of measurements maps to exactly one verdict", + "truth_labels_referenced": [], + "why": "a deliberately oversampled hard slice must not be able to rescue a failing natural-history sample by arithmetic" + }, + "producer_and_toolchain": { + "dotnet_sdk": "8.0.424", + "git": "2.55.0.windows.3", + "git_transform_detection": "git diff --name-status -M50% -C50% --find-copies-harder ", + "normalize_strip_rule": "--strip is MANDATORY and the strip leaf must be identical for every revision; the producer is invoked from the parent of the checkout so paths come out repository-relative", + "ownaudit_commit_used_for_normalisation": "d0b0dbd3f96d2676fa795935b224b67d032b5447", + "producer": "own-check", + "producer_own_net_commit": "76324fe4ccf71702d4386e29462227747d4fa54e", + "python": "3.12.10", + "roslyn": "Microsoft.CodeAnalysis.CSharp 4.9.2" + }, + "rename_capability": { + "all_four_targets_enter_labelling": true, + "exhaustive": "the four rows cover every reachable combination. correct_resolved can never exceed the number of genuine groups, so no case falls between rows 3 and 4.", + "failure_token_note": "row 1 emits FAIL, the token declared for this axis. The rename token set is deliberately NOT widened to FAIL/PIVOT: that compound belongs to the branch axis by preregistration, and a result vocabulary that grows to fit one row stops discriminating.", + "no_percentage_metric": "3/4 and 4/4 are not statistics; raw counts only", + "outcome_table": [ + { + "condition": "any unsafe relation error on an adjudicable rename target", + "row": 1, + "verdict": "FAIL" + }, + { + "condition": "fewer than 3 adjudicated rename targets whose truth label is exactly `continued 1:1` across the rename", + "row": 2, + "verdict": "RENAME-INCONCLUSIVE" + }, + { + "condition": "at least 3 adjudicated rename targets with truth label exactly `continued 1:1` across the rename, B3 correctly resolves at least 3 of them to the exact counterpart, and there are zero unsafe relation errors", + "row": 3, + "verdict": "PASS-RENAME" + }, + { + "condition": "at least 3 adjudicated rename targets with truth label exactly `continued 1:1` across the rename, zero unsafe relation errors, but B3 correctly resolves only 0-2 of them", + "row": 4, + "verdict": "RENAME-INCONCLUSIVE" + } + ], + "pair_replacement": "PROHIBITED", + "precedence": "rows are evaluated in order; the first matching row decides. Row 1 therefore dominates every other outcome.", + "supersedes": "the earlier rule required only >= 3 adjudicable rename groups and zero unsafe errors. Four `unresolved` answers satisfy both, so PASS-RENAME was reachable without resolving a single rename.", + "truth_labels_referenced": [ + "continued 1:1" + ], + "truth_must_be_continued_1_to_1": "the denominator counts only groups whose TRUTH is continued 1:1 across the rename. Correctly calling `ended` or any other outcome on a renamed file does not demonstrate R-CONT-RENAME, and must not be able to earn the axis.", + "why_threshold_is_three": [ + "1 of 4 validates nothing", + "2 correct resolutions are a useful signal but still RENAME-INCONCLUSIVE", + "3 exact resolutions with zero unsafe errors permit a cautious PASS-RENAME", + "4 of 4 is a stronger descriptive result; no separate percentage threshold is introduced" + ], + "wording_note": "this field means the four rename targets are all IN the labelling set. It does NOT mean labels exist: truth_labels_created is false and every target still requires two blinded labels plus human adjudication." + }, + "repositories": { + "ownnet": { + "adjacent_pairs": 238, + "first_parent_revisions": 239, + "natural_pairs_authoritative": 119, + "natural_pairs_preliminary_superseded": 120, + "ref": "main", + "role": "discovery / reference-evaluator development", + "tip": "76324fe4ccf71702d4386e29462227747d4fa54e" + }, + "sts": { + "adjacent_pairs": 2326, + "audit_subdir": "SectorTS/", + "first_parent_revisions": 2327, + "frozen_tip": "3588e530f88844d93b1466bf1e1176c6cbe3450b", + "ref": "dsector_optimization", + "repo_root": "STS_new", + "role": "sealed holdout" + } + }, + "sample": { + "boolean_naming_rule": "every constraint in this manifest is stated as a prohibition that is true, never as a permission that is false. A reader never has to decide what a false permission means.", + "no_target": { + "copy": [ + { + "a_sha": "5338bb2f4b00b0d4a5e0144a11d6d4d9d65505fc", + "b_sha": "3b9a55b7768a8ca1b278dc6290883fd721e466a4" + }, + { + "a_sha": "476377fc4042d2640f3216cc8b511747e7b30d8c", + "b_sha": "deaba36b1988cb3938911dd9603090113d54ede3" + }, + { + "a_sha": "64273291f8af21d09b3627ba207859474eee4126", + "b_sha": "d2ec8b75979e8004c9fa387a4701e76f39015f22" + }, + { + "a_sha": "3acf720c38423399655a17f26f0d8d9ed5cd1a9a", + "b_sha": "651143d81a165d8f3b32035f040c76487da083a0" + }, + { + "a_sha": "90155829d7eba2dccd103fc0e1f07fc48e4b2bd7", + "b_sha": "db22cad2bb7538ee577ea7d0d1f2cdee8692525c" + }, + { + "a_sha": "fa35e9e12f12d062169d56ff06575cee818f2851", + "b_sha": "f764bbaee0ea9edf53a269d691185209edfb6e10" + }, + { + "a_sha": "795708716e69ee3ae1d240916780a2e0504cf7b7", + "b_sha": "99f2187b458a9e9f3b4ad265bb939c3311fee7fa" + }, + { + "a_sha": "214fd169a5685ad9b9e5a0b966e620b5bb5fb8a1", + "b_sha": "65dd5e874c1789f697196cfe65500be63ddc043f" + }, + { + "a_sha": "d3e9d7458b371a2c32a0246ee478fa132f5060e1", + "b_sha": "7e503d76b2b5454cb387dd104a656a507569fb73" + }, + { + "a_sha": "93a403eacedd45856b510fa37217d0fc304c1b6d", + "b_sha": "678d35ee6f00eb03bac6bde853bbd6364dea4765" + }, + { + "a_sha": "5497e6f2595f8892c6e349b440605645a3e5bdeb", + "b_sha": "50d27b7d7b7213ef7b5da8a51bf2338298667d1c" + }, + { + "a_sha": "44bbf4f4169bc528ae0d160fabe5276e08858f58", + "b_sha": "9de66b1c358b78dfd57e94c4c07c138d2c5fc2e8" + }, + { + "a_sha": "b8928200765a4c897232474746ad1f7bc97f0e9b", + "b_sha": "ac25065781ec626c74b5e3aad2571225c946c572" + }, + { + "a_sha": "ca5f459c26d4dc2df567524dea46e700448cb36f", + "b_sha": "5a889983c199b4c7b1bd238e21d9bb94bfe2a778" + }, + { + "a_sha": "8c336c21ba24c4bd0b0fc82a909d0544b4091310", + "b_sha": "2896e0a5dc3c0689e297add2352a5494b12f4252" + }, + { + "a_sha": "266507d8b4e07cc432e0b255b22df3cd6593c4cc", + "b_sha": "b4f61dc1e5d889de0b76eb9db67b3737dad1b889" + }, + { + "a_sha": "e6d75ec61f55e0ec7c4985337535fee7d4be1fdf", + "b_sha": "3457bae4aafed114d50007777eebeec5374b40db" + }, + { + "a_sha": "eb32e9e3d09735e3518ba7033474ac8b9b2ce94d", + "b_sha": "623477c4cbcc3d7ea5ba3e59dc8584e313738e88" + }, + { + "a_sha": "03576cb716f7cfcf7140d0200747c054fbe78dc7", + "b_sha": "3a4c06f822e1c866fcae0caccef4d252b6583071" + }, + { + "a_sha": "5dcdbe09aff48ff16da565074b87a9893cbe6235", + "b_sha": "20a2c8d3ccc26469fc2d0ec0e433b188a1f95e55" + } + ], + "natural": [], + "rename": [ + { + "a_sha": "199f1f3861373db6f708bd9328835005ded09e48", + "b_sha": "c834553e06247467207c23d769790b3e8b882ce3" + }, + { + "a_sha": "46711ed0edd7d4e0a1516d53c5cef0f52d07c890", + "b_sha": "c83601783777060a37b7ea871bc9d99c99d5e060" + }, + { + "a_sha": "d3e9d7458b371a2c32a0246ee478fa132f5060e1", + "b_sha": "7e503d76b2b5454cb387dd104a656a507569fb73" + }, + { + "a_sha": "f4837ba267f45b59a08fb4e447fd6d309663e899", + "b_sha": "501ea55f3a8c8cc2bb98506db1af82fe40e57c37" + }, + { + "a_sha": "266507d8b4e07cc432e0b255b22df3cd6593c4cc", + "b_sha": "b4f61dc1e5d889de0b76eb9db67b3737dad1b889" + }, + { + "a_sha": "1aae361342944f6ecdb318232beeb63d5300f693", + "b_sha": "733c66323e135784cede110ecb214820d971776a" + }, + { + "a_sha": "57a4f31120ea10c175a8cd2fe64ee2f5c42ac0cb", + "b_sha": "24184d41dfc3d45eb7c4850e7e65e131df4e332a" + }, + { + "a_sha": "5b1878547f6a0aa8c98d7ade5404e6c5bd4ef88b", + "b_sha": "e084c0e70b9116584792addad57bb0e2e4273cc0" + }, + { + "a_sha": "f54427c2d709e6a8ce9ec8198b8a47d28d379f11", + "b_sha": "1cf267c8f828b2ded1d49a7da344b17e7f707304" + }, + { + "a_sha": "1af00413e334ddf38013a61c193c186ce84142aa", + "b_sha": "2d571bcb3a51132f9200cda367a66352faaf02c6" + }, + { + "a_sha": "a09c9c568ff831b3984094a5ccf8c9fc17e214f3", + "b_sha": "4e56082fc90a3a9b5b238bf43c6c0ddf38345b8b" + }, + { + "a_sha": "6e9e7a0464bc4328dbd4c7772e07ab9f82021548", + "b_sha": "63215dab2e9edb7d49c6df2e1ed7e4a0513d7b18" + }, + { + "a_sha": "dd21aae9d2512016df3861d1c9ee1335244f8372", + "b_sha": "0a16e9414e8f2687d22ecf4221ded154bf923aa5" + }, + { + "a_sha": "db204a602f8c4c1b887875bf0a36e116490da28e", + "b_sha": "f5975747fbb48fd703e6835bbea617684c91fb6e" + }, + { + "a_sha": "b3841a5a63567d704eae00771b099242119893a5", + "b_sha": "c4f60597cecb20b4e5de9e549043d89e001b919c" + }, + { + "a_sha": "65dd5e874c1789f697196cfe65500be63ddc043f", + "b_sha": "a39a8cc7dd6757e3c761594aa57f20924eea082c" + }, + { + "a_sha": "80c944a14b8f1f7e840ed629fc6151a1adbdcd9f", + "b_sha": "f4951cff971483469ae388eab0266e647cb87f6f" + } + ], + "status": "NO_TARGET entries remain in the frame as evidence of sample sparsity. They are NOT truth groups. Replacing them is prohibited, and no pair may be substituted for them: see sample.no_target_replacement_prohibited." + }, + "no_target_replacement_prohibited": true, + "pair_selection_frozen": true, + "pair_selection_modification_prohibited": true, + "selected_pairs": { + "copy": 25, + "natural": 50, + "rename": 21 + }, + "sts_copy_pairs": 71, + "sts_frame_pairs": 2326, + "sts_natural_candidates": 1915, + "sts_rename_pairs": 21, + "targets_after_census": { + "copy": 9, + "natural": 50, + "rename": 4, + "total": 63 + } + }, + "seeds": { + "b3_used_in_selection": false, + "canonical_serialisation": "json.dumps(array, ensure_ascii=False, separators=(\",\",\":\")).encode(\"utf-8\")", + "occurrence_id_used": false, + "selection_rank_rule": "rank_key = sha256(seed_hex || 0x00 || repo_id || 0x00 || a_sha || 0x00 || b_sha); ascending; ties by (a_sha, b_sha)", + "selection_seed": "ce730e47092805a8705ebc0f9b78f663a9c150139a650128f278afa9c393067e", + "side_determination": { + "copy": { + "rule": "forced to A by construction", + "side_hash_consulted": false, + "why": "a copy candidate must be an A-side finding lying on a copy SOURCE path, for the same reason as rename." + }, + "natural": { + "applies_to": "all 50 natural targets", + "decision": "sha256(canonical).digest()[0] & 1 ; 0 -> A, 1 -> B", + "preimage": [ + "rh-m0-side/v1", + "", + "sts", + "", + "" + ], + "rule": "hash-derived" + }, + "rename": { + "rule": "forced to A by construction", + "side_hash_consulted": false, + "why": "a rename candidate must be an A-side finding lying on a rename SOURCE path. The successor side cannot hold the predecessor occurrence, so there is nothing for a coin to decide." + }, + "reproduction_warning": { + "correct_reproduction": "for class natural derive the side from the hash; for classes rename and copy use side = \"A\" unconditionally, then compute the target preimage with that side", + "issue": "applying the natural side rule to the hard classes does NOT reproduce the frozen targets. Recomputed with the frozen truth_seed it yields side B for 6 of the 13 hard targets, and because also enters the target-hash preimage those 6 target hashes would not match.", + "measured_divergence": { + "copy": "4 of 9", + "natural": "0 of 50", + "rename": "2 of 4", + "total": "6 of 63" + }, + "worked_example": { + "a_sha": "43e13bce", + "b_sha": "45eca2c5", + "frozen_target_records": "A", + "hash_rule_would_select": "B", + "side_hash_first_byte": "0xa3" + } + } + }, + "side_preimage": [ + "rh-m0-side/v1", + "", + "sts", + "", + "" + ], + "target_preimage": [ + "rh-m0-target/v1", + "", + "sts", + "", + "", + "", + "", + "", + "", + "", + "" + ], + "target_rule": "minimum lexical sha256 hex over the candidate set, where the candidate set is class-dependent: all findings on the hash-selected side for natural, and the A-side findings on rename/copy source paths for the hard classes", + "truth_seed": "7e4f4650a0109d52a4e0492e6d1a087b99a4af328b72ee3144ec746d9f85d7ed" + }, + "status": "FROZEN", + "step1_contract": { + "canonical_merge_commit": "011c1362861f6b8b20c45e8ebd5bcb912401c1c0", + "contracts": { + "contracts/finding-lineage-decision-v1.json": { + "git_blob": "610654aaf80a6ee7f4e8a96cd1f6095b8f0e5c80", + "sha256": "2172a9e16e9e33309a51ef4d7827086131641047595d2912ab442154d73e1ff0" + }, + "contracts/finding-lineage-v1.json": { + "git_blob": "211c73ed9672b7408b43f52f36e31ec3e4370cd6", + "sha256": "12c180e96fabf186454be89b8f9418684597a116df1428d5b12e2f3c9638c441" + } + }, + "contracts_identical_at_reviewed_head_and_merge": true, + "merge_shape": { + "branch_retained": "claude/lineage-decision-policy", + "commits_preserved": 84, + "parent_1": "d0b0dbd3f96d2676fa795935b224b67d032b5447", + "parent_2": "6dcc02f7d82bebeb5db9be83f77ab8c5455f5692", + "parents": 2, + "squashed": false + }, + "merged_at": "2026-08-29T08:06:47Z", + "normalizer_unchanged_by_merge": { + "consequence": "RH-0 and RH-O1 measurements remain valid against canonical main", + "files": [ + "aggregate/normalize.py", + "aggregate/provenance.py", + "aggregate/sarif_read.py" + ], + "identical": true + }, + "reviewed_step1_head": "6dcc02f7d82bebeb5db9be83f77ab8c5455f5692" + }, + "stop_conditions": { + "after_manifest_commit": "STOP and report the commit and hash", + "first_sts_b3_run_requires": "a hashed, frozen truth artifact", + "m0_contains_no_correctness_result": true, + "no_sts_b3_output_before_frozen_truth": true, + "reference_evaluator_may_run_on": "Own.NET only, after this freeze" + }, + "sts_b3_output_exists": false, + "truth_labels_created": false, + "truth_protocol": { + "ai_agreement_is_not_truth": "two agreeing agents produce PROPOSED truth only; the final truth artifact requires human/owner adjudication and sign-off", + "evidence_cards_contain": [ + "source at A and B", + "raw finding", + "ordinary Git diff", + "rename and copy metadata", + "commit context" + ], + "label_vocabulary": [ + "continued 1:1", + "branched 1:N", + "merged N:1", + "ended", + "new", + "unresolved-by-truth", + "unadjudicable" + ], + "labeler_a": "blind to B3", + "labeler_b": "blind to B3 and to labeler A", + "labelers_must_not_see": [ + "B3 output", + "baseline output", + "rule ids", + "evidence sets", + "applicable_rules", + "licensed_by", + "outcomes" + ], + "labels_per_target": 2, + "resolved_branch_or_merge_carries": "exact endpoint sets, not only the outcome", + "targets_frozen_now": 63, + "truth_artifact_hashed_and_frozen_before": "the first STS B3 run" + }, + "verdict_taxonomy": { + "axes": { + "branch": [ + "PASS-BRANCH", + "BRANCH-INCONCLUSIVE", + "FAIL/PIVOT" + ], + "hard": [ + "HARD-PASS", + "HARD-INCONCLUSIVE", + "FAIL" + ], + "merge": [ + "MERGE-INCONCLUSIVE" + ], + "natural": [ + "PASS-NATURAL", + "INCONCLUSIVE", + "FAIL" + ], + "rename": [ + "PASS-RENAME", + "RENAME-INCONCLUSIVE", + "FAIL" + ] + }, + "axes_are_five": [ + "natural", + "hard", + "rename", + "branch", + "merge" + ], + "axis_disposition": { + "branch_axis_exception": "the branch axis retains the compound token FAIL/PIVOT because it was preregistered that way and is internally consistent with its own token set. It is recorded here as a known wart, not silently rewritten: changing a frozen token to satisfy a style preference is exactly the kind of post-hoc edit this manifest exists to prevent.", + "mapping": { + "BRANCH-INCONCLUSIVE": "HOLD", + "FAIL": "PIVOT", + "FAIL/PIVOT": "PIVOT", + "HARD-INCONCLUSIVE": "HOLD", + "HARD-PASS": "PROCEED", + "INCONCLUSIVE": "HOLD", + "MERGE-INCONCLUSIVE": "HOLD", + "PASS-BRANCH": "PROCEED", + "PASS-NATURAL": "PROCEED", + "PASS-RENAME": "PROCEED", + "RENAME-INCONCLUSIVE": "HOLD" + }, + "mapping_is_concrete": "every entry names a token that the taxonomy actually declares. No prefix, suffix or regular-expression normalisation is used, because a rule that has to parse its own vocabulary is a rule that will one day parse it wrongly.", + "merge_entry_is_axis_local": "MERGE-INCONCLUSIVE -> HOLD is admissible only as an axis-local disposition. It cannot by itself imply a global HOLD.", + "no_global_aggregator": "No global composite disposition is frozen by RH-M0. MERGE-INCONCLUSIVE is a preregistered capability ceiling present on every run, so read as a global rule this mapping would make PROCEED unreachable forever. The global decision stays compositional and is not smuggled back into a monolithic gate.", + "what_this_is": "the local disposition associated with ONE axis verdict. It does NOT aggregate the five-axis composite into a single experiment or project disposition.", + "why": "a verdict records what was measured; a disposition records what the project does next. Fusing them into one token, as FAIL/PIVOT does, makes the measured result depend on a management decision and is awkward for any consumer that groups by verdict." + }, + "axis_independence_note": "HARD-PASS pools rename and copy, so its +3 requirement can in principle be satisfied entirely by copy targets while no rename is resolved at all. That is why rename carries its own axis with its own resolution floor, and why a composite verdict must report both. HARD-PASS together with RENAME-INCONCLUSIVE is a coherent and honest result, not a contradiction.", + "composite": true, + "consistency_rule": { + "how_the_defect_was_missed": "the rename table was written by analogy with the branch table, which legitimately uses FAIL/PIVOT. Prose review compares a row against its neighbours; only a mechanical check compares it against its own axis.", + "mechanical_result": { + "declared_but_unreachable": 0, + "emitted_not_declared": 0 + }, + "method": "cross-product of the outcome_table rows of the in-scope axes against verdict_taxonomy.axes, in both directions", + "no_tables_added_for_uniformity": "the other three axes are NOT given outcome tables to make the rule uniform. Extending a frozen specification for the sake of a checker's symmetry is the wrong direction: the checker is narrowed to what it checks.", + "non_table_backed_axes": { + "merge": "fixed singleton ceiling MERGE-INCONCLUSIVE" + }, + "rule": "for every table-backed axis, every outcome_table verdict MUST belong to that axis's declared token set, and every declared token for that axis MUST be reachable from at least one outcome-table row", + "scope": [ + "natural", + "hard", + "rename", + "branch" + ], + "scope_change_note": "natural entered in revision 7 and hard in revision 8, each when it gained an outcome table. The scope tracks the structure; it is not a fixed list.", + "scope_reason": "these are the table-backed axes. merge is the only axis left outside, because it is a fixed singleton ceiling rather than a decision.", + "supersedes": "the revision-5 wording 'every verdict appearing in any outcome_table ... and every declared token SHOULD be reachable', which was unscoped and therefore unreproducible for three of the five axes", + "verified_mechanically": true, + "why_the_scope_matters": "applying the reachability half to all five axes would report 7 falsely unreachable tokens - natural 3, hard 3, merge 1 - purely because those axes have no rows. The previous wording promised that broader scope while the reported result covered only the two axes actually checked." + }, + "disposition_coverage_rule": { + "result_at_this_revision": { + "mapped_but_undeclared": 0, + "tokens_declared": 11, + "tokens_unmapped": 0 + }, + "rule": "every token declared in verdict_taxonomy.axes MUST have exactly one entry in axis_disposition.mapping", + "verified_mechanically": true, + "why": "finding two of this round was precisely a mapping written against tokens that did not exist. A rule that is checked cannot drift back into that state silently." + }, + "every_run_reports_one_verdict_per_axis": true, + "examples": [ + { + "branch": "PASS-BRANCH", + "hard": "HARD-PASS", + "merge": "MERGE-INCONCLUSIVE", + "natural": "PASS-NATURAL", + "rename": "PASS-RENAME" + }, + { + "branch": "BRANCH-INCONCLUSIVE", + "hard": "HARD-INCONCLUSIVE", + "merge": "MERGE-INCONCLUSIVE", + "natural": "PASS-NATURAL", + "rename": "RENAME-INCONCLUSIVE" + }, + { + "branch": "BRANCH-INCONCLUSIVE", + "hard": "HARD-INCONCLUSIVE", + "merge": "MERGE-INCONCLUSIVE", + "natural": "INCONCLUSIVE", + "rename": "RENAME-INCONCLUSIVE" + } + ], + "examples_schema_note": "every example carries all five axes. A composite with fewer than five entries is malformed.", + "merge_axis_is_fixed": "MERGE-INCONCLUSIVE regardless of any other outcome", + "monolithic_pass_prohibited": "a single PASS hides which capability was actually exercised; every run reports one verdict per axis", + "no_vacuous_pass": { + "resolution_floor_per_axis": { + "branch": ">= 3 correct resolutions with exact successor endpoint sets", + "hard": "correct_resolved(B3) >= max(correct_resolved(B1), correct_resolved(B2)) + 3", + "merge": "not applicable; the axis is fixed at MERGE-INCONCLUSIVE", + "natural": ">= 20 B3-resolved natural groups", + "rename": ">= 3 correct exact-counterpart resolutions on genuine continued-1:1 rename groups" + }, + "rule": "no axis may reach a PASS verdict without a positive count of correct resolutions", + "why": "zero unsafe errors is trivially achieved by answering `unresolved` everywhere. Safety without resolution is not a capability, and an axis that can be passed by silence measures nothing." + }, + "truth_label_reference_rule": { + "result_at_this_revision": { + "not_in_vocabulary": 0, + "referenced": [ + "branched 1:N", + "continued 1:1" + ] + }, + "rule": "every truth label named in truth_labels_referenced of any outcome table MUST be a member of truth_protocol.label_vocabulary, verbatim", + "verified_mechanically": true, + "why": "the branch table referred to `branched` while the vocabulary declares `branched 1:N`. A verdict machinery that is exact about its own vocabulary must be equally exact about the vocabulary it consumes." + } + } } \ No newline at end of file diff --git a/research/rh-m0/rh-m0-manifest.sha256 b/research/rh-m0/rh-m0-manifest.sha256 index 84b88bb..33e5a9f 100644 --- a/research/rh-m0/rh-m0-manifest.sha256 +++ b/research/rh-m0/rh-m0-manifest.sha256 @@ -1 +1 @@ -71f4c923d7091a1d88869d0ec7c97154e1aab15a6a1da82fb6ea8d1d074944a8 rh-m0-manifest.json +ff6a5ed408dd56571036137c570cb4a0c6c0a4e98e6e447f67b4842337e9464a rh-m0-manifest.json From 11057180fe0c12011ea82c7f85cb57483c0225da Mon Sep 17 00:00:00 2001 From: PhysShell Date: Sun, 30 Aug 2026 15:58:50 +0000 Subject: [PATCH 09/13] RH-M0: make the checker prose follow the structure it describes Two sentences inside consistency_rule stopped being true when natural gained an outcome table in revision 7 and hard in revision 8. They still said "the other three axes are NOT given outcome tables" and reported seven falsely unreachable tokens as natural 3, hard 3, merge 1. Both statements were correct at revision 6. They are historical, not current state. Current state, derived from the structure: four axes are table-backed, and applying table reachability to all five would falsely report exactly one unreachable token, MERGE-INCONCLUSIVE, solely because merge intentionally has no outcome_table. no_tables_added_for_uniformity now refers to merge alone. why_the_scope_matters states the current figure, marks seven as historical, and points at the derived field as authoritative rather than at itself. The count moved into consistency_rule.falsely_unreachable_if_applied_to_all_axes, computed from the structure, with the revision-6 value retained as history. A number that lives in prose goes stale the moment the structure moves, which is exactly what happened here. Two structural invariants are now asserted, against the structure rather than against any wording: set(consistency_rule.scope) == set(axes whose section contains an outcome_table) set(non_table_backed_axes) == set(verdict_taxonomy.axes) - set(scope) Asserting the wording would need a checker for the checker's description, and then one for that. Documentation only. Asserted unchanged before writing: verdict_taxonomy.axes, axis_disposition, consistency_rule.scope, all four outcome tables, truth_protocol, seeds and the 63 frozen target hashes. The diff touches manifest_revision and consistency_rule and nothing else. Both files remain LF; sha256sum --check passes. Manifest SHA-256 502477c44fb9a315efef10d3504ef33eabfa12f17401ed4abc7905c5c9c50b94 supersedes ff6a5ed408dd56571036137c570cb4a0c6c0a4e98e6e447f67b4842337e9464a. No B3 run. No truth labels. No correctness result. Co-Authored-By: Claude Opus 5 (1M context) Claude-Session: https://claude.ai/code/session_015vtUmvBDf69ccY5ju3PSHV --- research/rh-m0/rh-m0-manifest.json | 85 ++++++++++++++++++---------- research/rh-m0/rh-m0-manifest.sha256 | 2 +- 2 files changed, 57 insertions(+), 30 deletions(-) diff --git a/research/rh-m0/rh-m0-manifest.json b/research/rh-m0/rh-m0-manifest.json index b6dc709..dc67675 100644 --- a/research/rh-m0/rh-m0-manifest.json +++ b/research/rh-m0/rh-m0-manifest.json @@ -795,27 +795,20 @@ }, "manifest_revision": { "b3_executed": false, + "documentation_only": true, "findings_applied": [ { - "assessment": "valid and blocking. The vocabulary declares `branched 1:N`; the table said `branched`. Under exact comparison PASS-BRANCH was unreachable.", - "fix": "all truth-sensitive branch conditions name the canonical token verbatim, and truth_labels_referenced lists it structurally", - "id": "P2-a", - "same_class_fixed_alongside": "the rename table embedded `continued 1:1` inside prose; it now names the token the same way", - "title": "branch referenced a truth token that does not exist" - }, - { - "assessment": "valid. unsafe_relation_errors > 0 had no verdict although FAIL is declared.", - "consequence": "hard became table-backed, so consistency_rule.scope now includes it", - "fix": "three-row precedence-ordered table; thresholds unchanged", - "id": "P2-b", - "title": "hard axis was not total" - }, - { - "assessment": "valid. sha256sum --check treats the trailing \\r as part of the filename and looks for rh-m0-manifest.json\\r, so the sidecar was not machine-verifiable even though the digest was correct.", - "fix": "sidecar written with LF; verified with sha256sum --check", - "id": "artifact-integrity", - "self_found_alongside": "the manifest itself was CRLF, which makes its digest depend on the writing platform: regenerating it on Linux would produce a different hash for identical content. Now written with LF.", - "title": "checksum sidecar written with CRLF" + "assessment": "valid. Two sentences still described three axes without tables and seven falsely unreachable tokens. Both were correct at revision 6; natural gained a table in revision 7 and hard in revision 8, so the current figure is one, MERGE-INCONCLUSIVE.", + "fix": [ + "no_tables_added_for_uniformity now refers to merge alone", + "why_the_scope_matters states the current figure and marks seven as historical", + "the count moved into a derived field so it cannot go stale again" + ], + "id": "P2", + "semantics_changed": false, + "tables_changed": false, + "thresholds_changed": false, + "title": "consistency_rule prose did not follow the structure" } ], "frozen_targets_unchanged": true, @@ -860,21 +853,28 @@ "reason": "total natural outcome rule, concrete axis dispositions", "revision": 7, "sha256": "71f4c923d7091a1d88869d0ec7c97154e1aab15a6a1da82fb6ea8d1d074944a8" + }, + { + "commit": "ad58b29383d36b9fad0f0dc65a5faa3ace6636e8", + "reason": "exact truth tokens, total hard axis, LF checksum artifact", + "revision": 8, + "sha256": "ff6a5ed408dd56571036137c570cb4a0c6c0a4e98e6e447f67b4842337e9464a" } ], - "reason": "two external review findings and one artifact-integrity finding on revision 7", - "revision": 8, - "supersedes_commit": "6e3304a498951089f8945f6cb3ec99978e65e887", - "supersedes_sha256": "71f4c923d7091a1d88869d0ec7c97154e1aab15a6a1da82fb6ea8d1d074944a8", + "reason": "one external review finding on revision 8: stale current-state prose inside the checker metadata", + "revision": 9, + "supersedes_commit": "ad58b29383d36b9fad0f0dc65a5faa3ace6636e8", + "supersedes_sha256": "ff6a5ed408dd56571036137c570cb4a0c6c0a4e98e6e447f67b4842337e9464a", "targets_sampling_truth_or_b3_surface_touched": false, "truth_labels_created": false, "what_this_revision_did_not_touch": [ "verdict_taxonomy.axes", + "axis_disposition", + "consistency_rule.scope", + "all four outcome tables", "truth_protocol", "seeds", - "frozen_targets", - "primary_holdout.outcome_table", - "hard thresholds" + "frozen_targets" ] }, "merge_capability": { @@ -1407,13 +1407,34 @@ "axis_independence_note": "HARD-PASS pools rename and copy, so its +3 requirement can in principle be satisfied entirely by copy targets while no rename is resolved at all. That is why rename carries its own axis with its own resolution floor, and why a composite verdict must report both. HARD-PASS together with RENAME-INCONCLUSIVE is a coherent and honest result, not a contradiction.", "composite": true, "consistency_rule": { + "falsely_unreachable_if_applied_to_all_axes": { + "count": 1, + "derivation": "for every axis without an outcome_table, every token declared for it in verdict_taxonomy.axes", + "derived": true, + "historical_values": [ + { + "correct_at_the_time": true, + "count": 7, + "revision": 6, + "tokens": [ + "natural: 3", + "hard: 3", + "merge: 1" + ] + } + ], + "tokens": [ + "merge: MERGE-INCONCLUSIVE" + ], + "why_derived": "the count was prose at revision 6 and went stale the moment natural and hard gained tables. It is computed from the structure so it cannot drift again." + }, "how_the_defect_was_missed": "the rename table was written by analogy with the branch table, which legitimately uses FAIL/PIVOT. Prose review compares a row against its neighbours; only a mechanical check compares it against its own axis.", "mechanical_result": { "declared_but_unreachable": 0, "emitted_not_declared": 0 }, "method": "cross-product of the outcome_table rows of the in-scope axes against verdict_taxonomy.axes, in both directions", - "no_tables_added_for_uniformity": "the other three axes are NOT given outcome tables to make the rule uniform. Extending a frozen specification for the sake of a checker's symmetry is the wrong direction: the checker is narrowed to what it checks.", + "no_tables_added_for_uniformity": "merge is deliberately NOT given an outcome table merely to make the checker uniform. It remains a fixed singleton ceiling and therefore stays outside the table-backed scope.", "non_table_backed_axes": { "merge": "fixed singleton ceiling MERGE-INCONCLUSIVE" }, @@ -1425,10 +1446,16 @@ "branch" ], "scope_change_note": "natural entered in revision 7 and hard in revision 8, each when it gained an outcome table. The scope tracks the structure; it is not a fixed list.", - "scope_reason": "these are the table-backed axes. merge is the only axis left outside, because it is a fixed singleton ceiling rather than a decision.", + "scope_reason": "these are the table-backed axes, derived from which sections actually carry an outcome_table. merge is the only axis left outside, because it is a fixed singleton ceiling rather than a decision.", + "structural_invariants": { + "non_table_backed_is_the_complement": "set(non_table_backed_axes) == set(verdict_taxonomy.axes) - set(consistency_rule.scope)", + "scope_equals_table_backed_axes": "set(consistency_rule.scope) == set(axes whose section contains an outcome_table)", + "verified_mechanically": true, + "why_structural_not_textual": "the invariants are asserted against the structure, never against the wording. A checker that verifies its own description needs a second checker for that description, and so on." + }, "supersedes": "the revision-5 wording 'every verdict appearing in any outcome_table ... and every declared token SHOULD be reachable', which was unscoped and therefore unreproducible for three of the five axes", "verified_mechanically": true, - "why_the_scope_matters": "applying the reachability half to all five axes would report 7 falsely unreachable tokens - natural 3, hard 3, merge 1 - purely because those axes have no rows. The previous wording promised that broader scope while the reported result covered only the two axes actually checked." + "why_the_scope_matters": "At revision 9, natural, hard, rename and branch are table-backed. Applying table reachability to all five axes would falsely report exactly one unreachable token, MERGE-INCONCLUSIVE, solely because merge intentionally has no outcome_table. The earlier count of seven applied before natural and hard became table-backed and is historical, not the current mechanical result. The authoritative value is the derived field below, not this sentence." }, "disposition_coverage_rule": { "result_at_this_revision": { diff --git a/research/rh-m0/rh-m0-manifest.sha256 b/research/rh-m0/rh-m0-manifest.sha256 index 33e5a9f..4b71617 100644 --- a/research/rh-m0/rh-m0-manifest.sha256 +++ b/research/rh-m0/rh-m0-manifest.sha256 @@ -1 +1 @@ -ff6a5ed408dd56571036137c570cb4a0c6c0a4e98e6e447f67b4842337e9464a rh-m0-manifest.json +502477c44fb9a315efef10d3504ef33eabfa12f17401ed4abc7905c5c9c50b94 rh-m0-manifest.json From b10d48b231de80fa4a5deeb636174a555188a74b Mon Sep 17 00:00:00 2001 From: PhysShell Date: Sun, 30 Aug 2026 16:31:32 +0000 Subject: [PATCH 10/13] RH-M0: remove the cached value instead of building something to maintain it Both external reviewers independently found that falsely_unreachable_if_applied_to_all_axes stored a literal count and token list while declaring derived: true, with no generator committed anywhere in the repository. The arithmetic was correct and both reviewers confirmed the value. The claim about its provenance was not: a reader of this repository sees a JSON literal and a declaration that something derives it, and nothing does. The materialised current value is removed rather than backed by a new checker. current_value_materialization is now PROHIBITED, with the derivation rule kept so a consumer can compute the value from the authoritative structure. The revision-6 entry stays, because it records what the computation yielded then and cannot become semantically stale. why_the_scope_matters no longer names the number at all. Stating it in a third place would only schedule the next archaeological layer. The same seam ran wider than the finding. Four verified_mechanically flags and three result snapshots read as claims that a permanent validator enforces those properties. RH-M0 commits the manifest and its checksum sidecar only, so nothing does. They are renamed to say what they are: verified_mechanically -> verified_during_revision_construction mechanical_result -> result_at_revision_construction result_at_this_revision -> result_at_revision_construction verdict_taxonomy.verification_status states the position once: these are construction-time observations, not live repository invariants, and no checker is committed to service one counter. Documentation only. Asserted before writing: verdict_taxonomy.axes, axis_disposition, consistency_rule.scope, all four outcome tables, truth_protocol, seeds and the 63 frozen target hashes. A key-level scan confirms none of the retired names survive as keys; they appear only inside prose that describes the rename. Both files remain LF; sha256sum --check passes. Manifest SHA-256 08f266e927d733ac177a6b5592da6cab4db51df8b82467e0bacc3b7f6b342758 supersedes 502477c44fb9a315efef10d3504ef33eabfa12f17401ed4abc7905c5c9c50b94. No B3 run. No truth labels. No correctness result. Co-Authored-By: Claude Opus 5 (1M context) Claude-Session: https://claude.ai/code/session_015vtUmvBDf69ccY5ju3PSHV --- research/rh-m0/rh-m0-manifest.json | 85 ++++++++++++++++++---------- research/rh-m0/rh-m0-manifest.sha256 | 2 +- 2 files changed, 56 insertions(+), 31 deletions(-) diff --git a/research/rh-m0/rh-m0-manifest.json b/research/rh-m0/rh-m0-manifest.json index dc67675..d33bf58 100644 --- a/research/rh-m0/rh-m0-manifest.json +++ b/research/rh-m0/rh-m0-manifest.json @@ -798,17 +798,32 @@ "documentation_only": true, "findings_applied": [ { - "assessment": "valid. Two sentences still described three axes without tables and seven falsely unreachable tokens. Both were correct at revision 6; natural gained a table in revision 7 and hard in revision 8, so the current figure is one, MERGE-INCONCLUSIVE.", + "assessment": "valid. The arithmetic was right and both reviewers confirmed the value; the provenance claim was wrong. A reader of the repository sees a JSON literal and a declaration that it is derived, with nothing that derives it.", + "checker_committed": false, "fix": [ - "no_tables_added_for_uniformity now refers to merge alone", - "why_the_scope_matters states the current figure and marks seven as historical", - "the count moved into a derived field so it cannot go stale again" + "removed count, tokens and derived", + "current_value_materialization is now PROHIBITED with the reason recorded", + "why_the_scope_matters no longer names the number anywhere", + "the revision-6 historical entry is retained as an immutable fact" ], "id": "P2", - "semantics_changed": false, - "tables_changed": false, - "thresholds_changed": false, - "title": "consistency_rule prose did not follow the structure" + "raised_by": [ + "Codex", + "CodeRabbit" + ], + "raised_independently": true, + "title": "falsely_unreachable_if_applied_to_all_axes stored a cache and called it derived", + "why_not": "adding a validator for one counter would re-expand the surface" + }, + { + "assessment": "verified_mechanically and mechanical_result read as claims that a permanent validator enforces those properties. Nothing does; RH-M0 commits the manifest and its checksum only.", + "fix": [ + "verified_mechanically -> verified_during_revision_construction, four places", + "mechanical_result and result_at_this_revision -> result_at_revision_construction", + "verdict_taxonomy.verification_status states the position once" + ], + "id": "self-found", + "title": "the same seam ran through four flags and three snapshots" } ], "frozen_targets_unchanged": true, @@ -859,12 +874,18 @@ "reason": "exact truth tokens, total hard axis, LF checksum artifact", "revision": 8, "sha256": "ff6a5ed408dd56571036137c570cb4a0c6c0a4e98e6e447f67b4842337e9464a" + }, + { + "commit": "11057180fe0c12011ea82c7f85cb57483c0225da", + "reason": "checker prose follows the structure it describes", + "revision": 9, + "sha256": "502477c44fb9a315efef10d3504ef33eabfa12f17401ed4abc7905c5c9c50b94" } ], - "reason": "one external review finding on revision 8: stale current-state prose inside the checker metadata", - "revision": 9, - "supersedes_commit": "ad58b29383d36b9fad0f0dc65a5faa3ace6636e8", - "supersedes_sha256": "ff6a5ed408dd56571036137c570cb4a0c6c0a4e98e6e447f67b4842337e9464a", + "reason": "one finding raised independently by both external reviewers on revision 9: a materialised value declared as derived, with no generator in the repository", + "revision": 10, + "supersedes_commit": "11057180fe0c12011ea82c7f85cb57483c0225da", + "supersedes_sha256": "502477c44fb9a315efef10d3504ef33eabfa12f17401ed4abc7905c5c9c50b94", "targets_sampling_truth_or_b3_surface_touched": false, "truth_labels_created": false, "what_this_revision_did_not_touch": [ @@ -1408,9 +1429,8 @@ "composite": true, "consistency_rule": { "falsely_unreachable_if_applied_to_all_axes": { - "count": 1, - "derivation": "for every axis without an outcome_table, every token declared for it in verdict_taxonomy.axes", - "derived": true, + "current_value_materialization": "PROHIBITED", + "derivation": "for every axis without an outcome_table, take every token declared for that axis in verdict_taxonomy.axes", "historical_values": [ { "correct_at_the_time": true, @@ -1423,21 +1443,19 @@ ] } ], - "tokens": [ - "merge: MERGE-INCONCLUSIVE" - ], - "why_derived": "the count was prose at revision 6 and went stale the moment natural and hard gained tables. It is computed from the structure so it cannot drift again." + "historical_values_are_immutable_facts": "the revision-6 entry is retained. It is not a derived current value but a record of what the computation yielded at that revision, so it cannot become semantically stale.", + "reason": "the current count and token list are intentionally not stored. Consumers compute them from the authoritative structure, which prevents the cache drift that produced this finding: the value was materialised at revision 9, was correct then, and would have gone stale again the next time an axis gained or lost a table." }, "how_the_defect_was_missed": "the rename table was written by analogy with the branch table, which legitimately uses FAIL/PIVOT. Prose review compares a row against its neighbours; only a mechanical check compares it against its own axis.", - "mechanical_result": { - "declared_but_unreachable": 0, - "emitted_not_declared": 0 - }, "method": "cross-product of the outcome_table rows of the in-scope axes against verdict_taxonomy.axes, in both directions", "no_tables_added_for_uniformity": "merge is deliberately NOT given an outcome table merely to make the checker uniform. It remains a fixed singleton ceiling and therefore stays outside the table-backed scope.", "non_table_backed_axes": { "merge": "fixed singleton ceiling MERGE-INCONCLUSIVE" }, + "result_at_revision_construction": { + "declared_but_unreachable": 0, + "emitted_not_declared": 0 + }, "rule": "for every table-backed axis, every outcome_table verdict MUST belong to that axis's declared token set, and every declared token for that axis MUST be reachable from at least one outcome-table row", "scope": [ "natural", @@ -1450,21 +1468,21 @@ "structural_invariants": { "non_table_backed_is_the_complement": "set(non_table_backed_axes) == set(verdict_taxonomy.axes) - set(consistency_rule.scope)", "scope_equals_table_backed_axes": "set(consistency_rule.scope) == set(axes whose section contains an outcome_table)", - "verified_mechanically": true, + "verified_during_revision_construction": true, "why_structural_not_textual": "the invariants are asserted against the structure, never against the wording. A checker that verifies its own description needs a second checker for that description, and so on." }, "supersedes": "the revision-5 wording 'every verdict appearing in any outcome_table ... and every declared token SHOULD be reachable', which was unscoped and therefore unreproducible for three of the five axes", - "verified_mechanically": true, - "why_the_scope_matters": "At revision 9, natural, hard, rename and branch are table-backed. Applying table reachability to all five axes would falsely report exactly one unreachable token, MERGE-INCONCLUSIVE, solely because merge intentionally has no outcome_table. The earlier count of seven applied before natural and hard became table-backed and is historical, not the current mechanical result. The authoritative value is the derived field below, not this sentence." + "verified_during_revision_construction": true, + "why_the_scope_matters": "Applying table reachability outside consistency_rule.scope would classify the declared tokens of intentionally non-table-backed axes as unreachable. The current value is intentionally not materialized; it is computed from verdict_taxonomy.axes and the actual presence of outcome_table." }, "disposition_coverage_rule": { - "result_at_this_revision": { + "result_at_revision_construction": { "mapped_but_undeclared": 0, "tokens_declared": 11, "tokens_unmapped": 0 }, "rule": "every token declared in verdict_taxonomy.axes MUST have exactly one entry in axis_disposition.mapping", - "verified_mechanically": true, + "verified_during_revision_construction": true, "why": "finding two of this round was precisely a mapping written against tokens that did not exist. A rule that is checked cannot drift back into that state silently." }, "every_run_reports_one_verdict_per_axis": true, @@ -1506,7 +1524,7 @@ "why": "zero unsafe errors is trivially achieved by answering `unresolved` everywhere. Safety without resolution is not a capability, and an axis that can be passed by silence measures nothing." }, "truth_label_reference_rule": { - "result_at_this_revision": { + "result_at_revision_construction": { "not_in_vocabulary": 0, "referenced": [ "branched 1:N", @@ -1514,8 +1532,15 @@ ] }, "rule": "every truth label named in truth_labels_referenced of any outcome table MUST be a member of truth_protocol.label_vocabulary, verbatim", - "verified_mechanically": true, + "verified_during_revision_construction": true, "why": "the branch table referred to `branched` while the vocabulary declares `branched 1:N`. A verdict machinery that is exact about its own vocabulary must be equally exact about the vocabulary it consumes." + }, + "verification_status": { + "consumer_expectation": "a consumer needing a current value computes it from the authoritative structure rather than reading a stored one", + "no_committed_validator": "RH-M0 commits the manifest and its checksum sidecar only. No checker is committed alongside them.", + "supersedes": "the earlier verified_mechanically and mechanical_result naming, which could be read as asserting that a permanent validator enforces these properties", + "what_the_flags_mean": "every verified_during_revision_construction flag and every result_at_revision_construction object records what was computed while that revision was being built. They are construction-time observations, not live repository invariants, and nothing re-runs them.", + "why_no_checker_is_added": "committing a validator to service one counter would extend the RH-M0 surface at the exact moment the remaining defects became purely meta-level. The cache is removed instead of being managed." } } } \ No newline at end of file diff --git a/research/rh-m0/rh-m0-manifest.sha256 b/research/rh-m0/rh-m0-manifest.sha256 index 4b71617..9926bc7 100644 --- a/research/rh-m0/rh-m0-manifest.sha256 +++ b/research/rh-m0/rh-m0-manifest.sha256 @@ -1 +1 @@ -502477c44fb9a315efef10d3504ef33eabfa12f17401ed4abc7905c5c9c50b94 rh-m0-manifest.json +08f266e927d733ac177a6b5592da6cab4db51df8b82467e0bacc3b7f6b342758 rh-m0-manifest.json From e418ec72076605e8c735c8971c7eff6228b34ae6 Mon Sep 17 00:00:00 2001 From: PhysShell Date: Sun, 30 Aug 2026 16:52:13 +0000 Subject: [PATCH 11/13] RH-M0: truth needs endpoints, and the evidence card needs an allowlist Two substantive truth-protocol defects, both found before any truth label exists. P1. A `continued 1:1` label recorded what happened but not with whom. Endpoint sets were required only for branched 1:N and merged N:1, yet the rename axis scores resolution to the exact counterpart, and natural precision must separate a correct continuation from a continuation to a neighbouring similar finding. With two plausible candidates on the far side, nobody could decide after the freeze whether B3 was right. endpoint_contract now covers every entry of the vocabulary with an explicit cardinality: continued 1:1 exactly 1 opposite-side endpoint branched 1:N >= 2 successor endpoints merged N:1 >= 2 predecessor endpoints ended empty opposite-side set new empty opposite-side set unresolved-by-truth, unadjudicable not resolved relations ended and new carry a structurally empty set on purpose. Natural row 1 fails on a fabricated new/ended where truth has a counterpart, so the scorer applies one endpoint contract instead of guessing per verdict what absence meant. Endpoint identity is a frozen hash over the canonical identity of one normalized finding, computed by the truth-artifact builder. Labelers designate endpoints by the candidate index on the evidence card and never see the preimage. Prose such as "the finding one line below" is prohibited: a natural-language foreign key cannot be scored. P1. The evidence card carried a raw finding while the protocol forbids labelers to see rule ids. This is not hypothetical. The canonical normalized finding carries rule, category, category_name, pattern_id and occurrence_id, confirmed against a real normalized snapshot from the probe. The fix is an allowlist, never a subtraction: path, line, start_line, start_column, message. "Raw finding minus rule" would silently start carrying whatever field the normalizer gains next. Forbidden fields are enumerated, and the naming gap between "rule ids" in the prohibition and `rule` in the schema is stated rather than assumed. tool is excluded because one producer is used for the whole experiment, so it is constant and carries nothing for adjudication. truth_protocol changes on purpose here, having been asserted unchanged in earlier revisions: both defects are in the truth representation itself. label_vocabulary, labels_per_target, labelers_must_not_see and ai_agreement_is_not_truth are untouched. Construction-time checks: allowlist and forbidden list disjoint, every vocabulary entry has an endpoint contract, no entry outside the vocabulary, no resolved outcome without a cardinality. Not repository-enforced; see verdict_taxonomy.verification_status. Asserted unchanged: frozen_targets, seeds, verdict_taxonomy.axes, axis_disposition, consistency_rule.scope, all four outcome tables, and truth_protocol.label_vocabulary. Manifest SHA-256 858d80beeeb82619a0adc2fb29c505d1c03831cea2344541b576a7bb0139ee3e supersedes 08f266e927d733ac177a6b5592da6cab4db51df8b82467e0bacc3b7f6b342758. No B3 run. No truth labels. No correctness result. Co-Authored-By: Claude Opus 5 (1M context) Claude-Session: https://claude.ai/code/session_015vtUmvBDf69ccY5ju3PSHV --- research/rh-m0/rh-m0-manifest.json | 169 ++++++++++++++++++++++----- research/rh-m0/rh-m0-manifest.sha256 | 2 +- 2 files changed, 139 insertions(+), 32 deletions(-) diff --git a/research/rh-m0/rh-m0-manifest.json b/research/rh-m0/rh-m0-manifest.json index d33bf58..fbd6516 100644 --- a/research/rh-m0/rh-m0-manifest.json +++ b/research/rh-m0/rh-m0-manifest.json @@ -795,35 +795,26 @@ }, "manifest_revision": { "b3_executed": false, - "documentation_only": true, "findings_applied": [ { - "assessment": "valid. The arithmetic was right and both reviewers confirmed the value; the provenance claim was wrong. A reader of the repository sees a JSON literal and a declaration that it is derived, with nothing that derives it.", - "checker_committed": false, + "assessment": "valid. Endpoint sets were required only for branched 1:N and merged N:1, yet the rename axis scores resolution to the exact counterpart and natural precision must separate a correct continuation from one to a neighbouring similar finding. With two candidates on the far side the question was undecidable after the freeze.", "fix": [ - "removed count, tokens and derived", - "current_value_materialization is now PROHIBITED with the reason recorded", - "why_the_scope_matters no longer names the number anywhere", - "the revision-6 historical entry is retained as an immutable fact" + "endpoint_contract covers every vocabulary entry with an explicit cardinality", + "endpoint identity is a frozen hash, computed by the builder, never free text", + "ended and new carry a structurally empty opposite-side set so the scorer has one contract instead of per-verdict guesses" ], - "id": "P2", - "raised_by": [ - "Codex", - "CodeRabbit" - ], - "raised_independently": true, - "title": "falsely_unreachable_if_applied_to_all_axes stored a cache and called it derived", - "why_not": "adding a validator for one counter would re-expand the surface" + "id": "P1-a", + "title": "continued 1:1 carried no counterpart endpoint" }, { - "assessment": "verified_mechanically and mechanical_result read as claims that a permanent validator enforces those properties. Nothing does; RH-M0 commits the manifest and its checksum only.", + "assessment": "valid and not hypothetical. evidence_cards_contain listed 'raw finding' while labelers_must_not_see forbids rule ids, and the canonical normalized finding carries rule, category, category_name, pattern_id and occurrence_id. Confirmed against a real normalized snapshot.", "fix": [ - "verified_mechanically -> verified_during_revision_construction, four places", - "mechanical_result and result_at_this_revision -> result_at_revision_construction", - "verdict_taxonomy.verification_status states the position once" + "an explicit allowlist replaces the raw finding", + "forbidden fields are enumerated, and the rule ids / `rule` naming gap is stated", + "tool is excluded because a single producer makes it constant" ], - "id": "self-found", - "title": "the same seam ran through four flags and three snapshots" + "id": "P1-b", + "title": "the evidence card leaked forbidden fields" } ], "frozen_targets_unchanged": true, @@ -880,22 +871,31 @@ "reason": "checker prose follows the structure it describes", "revision": 9, "sha256": "502477c44fb9a315efef10d3504ef33eabfa12f17401ed4abc7905c5c9c50b94" + }, + { + "commit": "b10d48b231de80fa4a5deeb636174a555188a74b", + "reason": "cached derived value removed, not managed", + "revision": 10, + "sha256": "08f266e927d733ac177a6b5592da6cab4db51df8b82467e0bacc3b7f6b342758" } ], - "reason": "one finding raised independently by both external reviewers on revision 9: a materialised value declared as derived, with no generator in the repository", - "revision": 10, - "supersedes_commit": "11057180fe0c12011ea82c7f85cb57483c0225da", - "supersedes_sha256": "502477c44fb9a315efef10d3504ef33eabfa12f17401ed4abc7905c5c9c50b94", - "targets_sampling_truth_or_b3_surface_touched": false, + "reason": "two external review findings on revision 10, both substantive truth-protocol defects", + "revision": 11, + "supersedes_commit": "b10d48b231de80fa4a5deeb636174a555188a74b", + "supersedes_sha256": "08f266e927d733ac177a6b5592da6cab4db51df8b82467e0bacc3b7f6b342758", "truth_labels_created": false, + "truth_protocol_changed_on_purpose": "this revision edits truth_protocol, which earlier revisions asserted unchanged. Both findings are defects in the truth representation itself, so it is the correct thing to change. label_vocabulary is unchanged.", "what_this_revision_did_not_touch": [ + "frozen_targets", + "seeds", "verdict_taxonomy.axes", "axis_disposition", "consistency_rule.scope", "all four outcome tables", - "truth_protocol", - "seeds", - "frozen_targets" + "truth_protocol.label_vocabulary", + "labels_per_target", + "labelers_must_not_see", + "ai_agreement_is_not_truth" ] }, "merge_capability": { @@ -1339,9 +1339,85 @@ "truth_labels_created": false, "truth_protocol": { "ai_agreement_is_not_truth": "two agreeing agents produce PROPOSED truth only; the final truth artifact requires human/owner adjudication and sign-off", + "construction_time_guarantees": { + "checks": [ + "labeler_finding_projection.allowlist and forbidden_finding_fields are disjoint", + "every label_vocabulary entry has an endpoint_contract.by_outcome entry", + "every resolved outcome declares an endpoint cardinality" + ], + "not_repository_enforced": "RH-M0 commits the manifest and its checksum only; see verdict_taxonomy.verification_status", + "result_at_revision_construction": { + "allowlist_forbidden_overlap": 0, + "endpoint_contract_entries_outside_vocabulary": 0, + "resolved_outcomes_without_cardinality": 0, + "vocabulary_entries_without_endpoint_contract": 0 + }, + "verified_during_revision_construction": true + }, + "endpoint_contract": { + "by_outcome": { + "branched 1:N": { + "cardinality": ">= 2", + "endpoint_set": "successors", + "resolved": true + }, + "continued 1:1": { + "cardinality": "exactly 1", + "endpoint_set": "opposite side", + "resolved": true + }, + "ended": { + "cardinality": "empty", + "endpoint_set": "opposite side", + "resolved": true + }, + "merged N:1": { + "cardinality": ">= 2", + "endpoint_set": "predecessors", + "resolved": true + }, + "new": { + "cardinality": "empty", + "endpoint_set": "opposite side", + "resolved": true + }, + "unadjudicable": { + "cardinality": "not applicable; not a resolved relation", + "endpoint_set": null, + "resolved": false + }, + "unresolved-by-truth": { + "cardinality": "not applicable; not a resolved relation", + "endpoint_set": null, + "resolved": false + } + }, + "endpoint_identity": { + "computed_by": "the truth-artifact builder, from the normalized snapshot of the named revision. Labelers never compute it and never see its preimage.", + "digest": "sha256, lowercase hex", + "form": "endpoint_id, a hash over the canonical identity of one normalized finding", + "free_text_prohibited": "an endpoint is never recorded as prose such as 'the finding one line below'. A natural-language foreign key cannot be scored.", + "how_labelers_designate_endpoints": "by the candidate index printed on the evidence card. The builder resolves an index to its endpoint_id. This keeps rule and message-identity machinery out of the labeler's view while still producing a machine-comparable record.", + "preimage": [ + "rh-m0-endpoint/v1", + "", + "", + "", + "", + "", + "", + "", + "" + ], + "serialisation": "json.dumps(array, ensure_ascii=False, separators=(\",\",\":\")).encode(\"utf-8\")" + }, + "scorer_consequence": "a B3 relation is correct only if its endpoint set equals the truth endpoint set exactly, by endpoint_id. Cardinality mismatch is a silent cardinality loss or an invented endpoint, both already defined as unsafe relation errors.", + "why": "a truth label states what happened. Without endpoints it does not state with whom, and with two plausible candidates on the far side nobody can decide after the freeze whether a resolution was a true positive or a false continuation to a neighbouring finding.", + "why_ended_and_new_carry_an_empty_set": "natural outcome row 1 fails on a fabricated new/ended where truth has a counterpart. If the truth artifact states an EMPTY opposite-side set structurally, the scorer applies one endpoint contract instead of guessing per verdict what absence was supposed to mean." + }, "evidence_cards_contain": [ "source at A and B", - "raw finding", + "finding projection, allowlist below", "ordinary Git diff", "rename and copy metadata", "commit context" @@ -1357,6 +1433,38 @@ ], "labeler_a": "blind to B3", "labeler_b": "blind to B3 and to labeler A", + "labeler_finding_projection": { + "allowlist": [ + "path", + "line", + "start_line", + "start_column", + "message" + ], + "forbidden_finding_fields": [ + "rule", + "category", + "category_name", + "pattern_id", + "occurrence_id", + "resource", + "identity_limitations", + "suppressed", + "suppress_reason" + ], + "principle": "an allowlist, never a subtraction. 'raw finding minus rule' would silently start carrying whatever field the normalizer gains next.", + "structures_not_part_of_the_projection": [ + "B3 output", + "baseline output", + "evidence sets", + "applicable_rules", + "licensed_by", + "outcomes" + ], + "supersedes": "evidence_cards_contain previously listed 'raw finding', which contradicts labelers_must_not_see: the canonical normalized finding carries rule, category, category_name, pattern_id and occurrence_id.", + "tool_excluded": "one producer is used for the whole experiment, so tool is constant and carries no information for adjudication. It is excluded rather than admitted by habit.", + "vocabulary_mapping": "'rule ids' in labelers_must_not_see corresponds to the `rule` field of the normalized finding schema. The names differ, so the correspondence is stated rather than assumed." + }, "labelers_must_not_see": [ "B3 output", "baseline output", @@ -1367,7 +1475,6 @@ "outcomes" ], "labels_per_target": 2, - "resolved_branch_or_merge_carries": "exact endpoint sets, not only the outcome", "targets_frozen_now": 63, "truth_artifact_hashed_and_frozen_before": "the first STS B3 run" }, diff --git a/research/rh-m0/rh-m0-manifest.sha256 b/research/rh-m0/rh-m0-manifest.sha256 index 9926bc7..fe73998 100644 --- a/research/rh-m0/rh-m0-manifest.sha256 +++ b/research/rh-m0/rh-m0-manifest.sha256 @@ -1 +1 @@ -08f266e927d733ac177a6b5592da6cab4db51df8b82467e0bacc3b7f6b342758 rh-m0-manifest.json +858d80beeeb82619a0adc2fb29c505d1c03831cea2344541b576a7bb0139ee3e rh-m0-manifest.json From ff66d0fde283e692935538b181e30602ed2073da Mon Sep 17 00:00:00 2001 From: PhysShell Date: Sun, 30 Aug 2026 17:15:56 +0000 Subject: [PATCH 12/13] RH-M0: refuse an ambiguous endpoint identity, and map the projection to real fields P1. endpoint_id was minted from a canonical preimage that two identical rows of a normalized snapshot can share. The normalizer is not obliged to deduplicate SARIF rows, so a branch relation over two physically present findings could collapse to a one-element set and silently break the >= 2 cardinality the contract promises. Fixed by refusing an identity rather than inventing one. An endpoint_id is minted only when its canonical preimage occurs exactly once in the snapshot of that revision; otherwise the id is unavailable, with the limitation endpoint-id-unavailable:ambiguous-canonical-identity. Ordinal and result-index tiebreakers are PROHIBITED: disambiguating by position would reintroduce exactly the artificial identity the occurrence contract already refused. The truth consequence is deliberately narrow. A resolved relation that would need an unavailable endpoint must not be materialized as continued, branched or merged, and its truth is unadjudicable. An ambiguous preimage elsewhere does NOT by itself spoil a target: if the truth is genuinely ended or new, the structurally empty opposite-side set is still representable and the target is adjudicated normally. Measured while constructing this revision: zero ambiguous preimages across 271 snapshots and 76253 findings of the frozen sample. The rule is preventive, not corrective. It has to be specified before truth exists rather than discovered afterwards, because the normalizer guarantees nothing here. P2. The projection allowlist named start_line and start_column, which do not exist at the top level of a normalized finding; they live inside physical_anchor, while `line` does exist at the top level. The builder was therefore still free to decide after the freeze what those two names referred to. Confirmed against a real normalized snapshot, not against the schema text. Replaced by explicit leaf-level mappings: path <- path line <- physical_anchor.start_line column <- physical_anchor.start_column message <- message One semantic coordinate per output name, and no output called start_line or start_column, so no name maps to two possible sources. physical_anchor is never admitted as a whole object: an allowlist that hands over a container has stopped deciding anything. Construction-time checks: every projection source exists in the schema, output names are unique, no source is a forbidden field or lies beneath one, and the endpoint preimage multiplicity was measured. Checks on the truth artifact itself constrain a builder that does not exist yet; only their preconditions could be measured. Not repository-enforced. Asserted unchanged: frozen_targets, seeds, verdict_taxonomy.axes, axis_disposition, all four outcome tables, truth_protocol.label_vocabulary and endpoint_contract.by_outcome. Manifest SHA-256 5a6d6746691ccac2b8e653ed29c4194d206f28bc98624252b644d3726019b3f3 supersedes 858d80beeeb82619a0adc2fb29c505d1c03831cea2344541b576a7bb0139ee3e. No B3 run. No truth labels. No correctness result. Co-Authored-By: Claude Opus 5 (1M context) Claude-Session: https://claude.ai/code/session_015vtUmvBDf69ccY5ju3PSHV --- research/rh-m0/rh-m0-manifest.json | 134 ++++++++++++++++++++------- research/rh-m0/rh-m0-manifest.sha256 | 2 +- 2 files changed, 100 insertions(+), 36 deletions(-) diff --git a/research/rh-m0/rh-m0-manifest.json b/research/rh-m0/rh-m0-manifest.json index fbd6516..de63104 100644 --- a/research/rh-m0/rh-m0-manifest.json +++ b/research/rh-m0/rh-m0-manifest.json @@ -797,24 +797,31 @@ "b3_executed": false, "findings_applied": [ { - "assessment": "valid. Endpoint sets were required only for branched 1:N and merged N:1, yet the rename axis scores resolution to the exact counterpart and natural precision must separate a correct continuation from one to a neighbouring similar finding. With two candidates on the far side the question was undecidable after the freeze.", + "assessment": "valid. Two rows sharing every preimage field collapse to one endpoint_id, so a branch over two physically present findings could present a one-element set and break the >= 2 cardinality the contract promises.", "fix": [ - "endpoint_contract covers every vocabulary entry with an explicit cardinality", - "endpoint identity is a frozen hash, computed by the builder, never free text", - "ended and new carry a structurally empty opposite-side set so the scorer has one contract instead of per-verdict guesses" + "endpoint_id is minted only when the canonical preimage occurs exactly once", + "otherwise unavailable, with limitation endpoint-id-unavailable:ambiguous-canonical-identity", + "ordinal and result-index tiebreakers are PROHIBITED", + "a resolved relation needing an unavailable endpoint is unadjudicable, but ended/new with a structurally empty set remain adjudicable" ], - "id": "P1-a", - "title": "continued 1:1 carried no counterpart endpoint" + "id": "P1", + "measured": "zero ambiguous preimages across 271 snapshots and 76253 findings of the frozen sample; the rule is preventive", + "title": "endpoint identity was not injective where cardinality is promised" }, { - "assessment": "valid and not hypothetical. evidence_cards_contain listed 'raw finding' while labelers_must_not_see forbids rule ids, and the canonical normalized finding carries rule, category, category_name, pattern_id and occurrence_id. Confirmed against a real normalized snapshot.", + "assessment": "valid. start_line and start_column live inside physical_anchor, while `line` exists at the top level, so the builder could still decide after the freeze what the names meant. Confirmed against a real normalized snapshot.", "fix": [ - "an explicit allowlist replaces the raw finding", - "forbidden fields are enumerated, and the rule ids / `rule` naming gap is stated", - "tool is excluded because a single producer makes it constant" + "explicit leaf-level source-to-output mappings", + "outputs are path, line, column, message; line and column come from physical_anchor", + "no output named start_line or start_column, and physical_anchor is never taken whole" ], - "id": "P1-b", - "title": "the evidence card leaked forbidden fields" + "id": "P2", + "raised_by": [ + "Codex", + "CodeRabbit" + ], + "raised_independently": true, + "title": "projection named fields that do not exist at that level" } ], "frozen_targets_unchanged": true, @@ -877,25 +884,28 @@ "reason": "cached derived value removed, not managed", "revision": 10, "sha256": "08f266e927d733ac177a6b5592da6cab4db51df8b82467e0bacc3b7f6b342758" + }, + { + "commit": "e418ec72076605e8c735c8971c7eff6228b34ae6", + "reason": "truth endpoints and evidence-card allowlist", + "revision": 11, + "sha256": "858d80beeeb82619a0adc2fb29c505d1c03831cea2344541b576a7bb0139ee3e" } ], - "reason": "two external review findings on revision 10, both substantive truth-protocol defects", - "revision": 11, - "supersedes_commit": "b10d48b231de80fa4a5deeb636174a555188a74b", - "supersedes_sha256": "08f266e927d733ac177a6b5592da6cab4db51df8b82467e0bacc3b7f6b342758", + "reason": "two external review findings on revision 11; the projection defect was raised independently by both reviewers", + "revision": 12, + "supersedes_commit": "e418ec72076605e8c735c8971c7eff6228b34ae6", + "supersedes_sha256": "858d80beeeb82619a0adc2fb29c505d1c03831cea2344541b576a7bb0139ee3e", "truth_labels_created": false, - "truth_protocol_changed_on_purpose": "this revision edits truth_protocol, which earlier revisions asserted unchanged. Both findings are defects in the truth representation itself, so it is the correct thing to change. label_vocabulary is unchanged.", "what_this_revision_did_not_touch": [ "frozen_targets", "seeds", "verdict_taxonomy.axes", "axis_disposition", - "consistency_rule.scope", "all four outcome tables", "truth_protocol.label_vocabulary", - "labels_per_target", - "labelers_must_not_see", - "ai_agreement_is_not_truth" + "endpoint_contract.by_outcome", + "labelers_must_not_see" ] }, "merge_capability": { @@ -1341,16 +1351,27 @@ "ai_agreement_is_not_truth": "two agreeing agents produce PROPOSED truth only; the final truth artifact requires human/owner adjudication and sign-off", "construction_time_guarantees": { "checks": [ - "labeler_finding_projection.allowlist and forbidden_finding_fields are disjoint", - "every label_vocabulary entry has an endpoint_contract.by_outcome entry", - "every resolved outcome declares an endpoint cardinality" + "every projection source path exists in normalized-findings/v2", + "projection output names are unique", + "no projection source path is a forbidden field or lies beneath a forbidden object", + "endpoint canonical-preimage multiplicity: unique mints an id, >1 yields unavailable, never ordinal-disambiguated", + "every exact endpoint stored in truth has an available endpoint_id", + "every label_vocabulary entry has an endpoint_contract entry with a cardinality" ], "not_repository_enforced": "RH-M0 commits the manifest and its checksum only; see verdict_taxonomy.verification_status", "result_at_revision_construction": { - "allowlist_forbidden_overlap": 0, - "endpoint_contract_entries_outside_vocabulary": 0, - "resolved_outcomes_without_cardinality": 0, - "vocabulary_entries_without_endpoint_contract": 0 + "checks_4_and_5_are_builder_obligations": "they constrain the truth-artifact builder, which does not exist yet; only their preconditions could be measured here", + "duplicate_projection_outputs": 0, + "endpoint_preimage_multiplicity": { + "findings_examined": 76253, + "interpretation": "no ambiguous preimage occurs anywhere in the frozen sample. The rule is therefore preventive rather than corrective: the normalizer does not guarantee deduplication, so the refusal must be specified before truth exists, not discovered afterwards.", + "preimages_occurring_more_than_once": 0, + "rows_in_such_groups": 0, + "snapshots_examined": 271 + }, + "projection_sources_forbidden": 0, + "projection_sources_missing_from_schema": 0, + "schema_probe": "checked against a real normalized snapshot from the coverage probe, not against the schema text" }, "verified_during_revision_construction": true }, @@ -1393,11 +1414,22 @@ } }, "endpoint_identity": { + "ambiguous_preimage": { + "endpoint_id": "unavailable", + "limitation": "endpoint-id-unavailable:ambiguous-canonical-identity", + "why": "two rows sharing every preimage field are indistinguishable under this identity. The normalizer is not obliged to deduplicate SARIF rows, so this is reachable." + }, "computed_by": "the truth-artifact builder, from the normalized snapshot of the named revision. Labelers never compute it and never see its preimage.", + "consistency_with_occurrence_contract": "this is the same fail-closed doctrine already frozen for occurrence identity: an ambiguous anchor yields a refusal, not a guess", "digest": "sha256, lowercase hex", "form": "endpoint_id, a hash over the canonical identity of one normalized finding", "free_text_prohibited": "an endpoint is never recorded as prose such as 'the finding one line below'. A natural-language foreign key cannot be scored.", "how_labelers_designate_endpoints": "by the candidate index printed on the evidence card. The builder resolves an index to its endpoint_id. This keeps rule and message-identity machinery out of the labeler's view while still producing a machine-comparable record.", + "minting_rule": "an endpoint_id MAY be minted for a finding if and only if its canonical preimage occurs exactly once in that snapshot", + "ordinal_tiebreaker": { + "status": "PROHIBITED", + "why": "disambiguating by SARIF result index or by position in the snapshot would reintroduce exactly the artificial identity the occurrence contract already refused. When physical identity is ambiguous we decline to mint one; we do not invent one." + }, "preimage": [ "rh-m0-endpoint/v1", "", @@ -1409,9 +1441,17 @@ "", "" ], - "serialisation": "json.dumps(array, ensure_ascii=False, separators=(\",\",\":\")).encode(\"utf-8\")" + "serialisation": "json.dumps(array, ensure_ascii=False, separators=(\",\",\":\")).encode(\"utf-8\")", + "uniqueness_key": "the exact canonical endpoint preimage listed above", + "uniqueness_scope": "the entire normalized snapshot of the named revision" }, "scorer_consequence": "a B3 relation is correct only if its endpoint set equals the truth endpoint set exactly, by endpoint_id. Cardinality mismatch is a silent cardinality loss or an invented endpoint, both already defined as unsafe relation errors.", + "unavailable_endpoint_semantics": { + "not_a_blanket_rule": "the presence of an ambiguous preimage anywhere does NOT by itself make a target unadjudicable. If the truth is genuinely `ended` or `new`, the structurally empty opposite-side set remains representable and the target is adjudicated normally.", + "outcome": "the final truth for that relation is `unadjudicable`, unless a different outcome that does not require the ambiguous endpoint is adjudicated", + "rule": "a resolved truth relation that would require an endpoint whose endpoint_id is unavailable MUST NOT be materialized as continued 1:1, branched 1:N or merged N:1", + "why": "refusing only where an exact resolved relation needs an indistinguishable endpoint keeps the refusal proportional to the actual ambiguity" + }, "why": "a truth label states what happened. Without endpoints it does not state with whom, and with two plausible candidates on the far side nobody can decide after the freeze whether a resolution was a true positive or a false continuation to a neighbouring finding.", "why_ended_and_new_carry_an_empty_set": "natural outcome row 1 fails on a fabricated new/ended where truth has a counterpart. If the truth artifact states an EMPTY opposite-side set structurally, the scorer applies one endpoint contract instead of guessing per verdict what absence was supposed to mean." }, @@ -1434,12 +1474,23 @@ "labeler_a": "blind to B3", "labeler_b": "blind to B3 and to labeler A", "labeler_finding_projection": { - "allowlist": [ - "path", - "line", - "start_line", - "start_column", - "message" + "fields": [ + { + "output": "path", + "source": "path" + }, + { + "output": "line", + "source": "physical_anchor.start_line" + }, + { + "output": "column", + "source": "physical_anchor.start_column" + }, + { + "output": "message", + "source": "message" + } ], "forbidden_finding_fields": [ "rule", @@ -1452,7 +1503,10 @@ "suppressed", "suppress_reason" ], + "leaf_level_only": "sources are leaf paths. physical_anchor is never admitted as a whole object: an allowlist that hands over a container is an allowlist that has stopped deciding anything.", + "one_coordinate_per_name": "the card exposes line and column, each sourced from physical_anchor, which is where the coordinates that also feed endpoint identity live. The top-level `line` field is deliberately not used, and no output is named start_line or start_column, so no name maps to two possible sources.", "principle": "an allowlist, never a subtraction. 'raw finding minus rule' would silently start carrying whatever field the normalizer gains next.", + "source_schema": "normalized-findings/v2", "structures_not_part_of_the_projection": [ "B3 output", "baseline output", @@ -1462,6 +1516,16 @@ "outcomes" ], "supersedes": "evidence_cards_contain previously listed 'raw finding', which contradicts labelers_must_not_see: the canonical normalized finding carries rule, category, category_name, pattern_id and occurrence_id.", + "supersedes_allowlist": { + "defect": "start_line and start_column do not exist at the top level of a normalized finding; they live inside physical_anchor, while `line` does exist at the top level. The builder was therefore free to decide after the freeze what those two names referred to.", + "previous": [ + "path", + "line", + "start_line", + "start_column", + "message" + ] + }, "tool_excluded": "one producer is used for the whole experiment, so tool is constant and carries no information for adjudication. It is excluded rather than admitted by habit.", "vocabulary_mapping": "'rule ids' in labelers_must_not_see corresponds to the `rule` field of the normalized finding schema. The names differ, so the correspondence is stated rather than assumed." }, diff --git a/research/rh-m0/rh-m0-manifest.sha256 b/research/rh-m0/rh-m0-manifest.sha256 index fe73998..1686f0d 100644 --- a/research/rh-m0/rh-m0-manifest.sha256 +++ b/research/rh-m0/rh-m0-manifest.sha256 @@ -1 +1 @@ -858d80beeeb82619a0adc2fb29c505d1c03831cea2344541b576a7bb0139ee3e rh-m0-manifest.json +5a6d6746691ccac2b8e653ed29c4194d206f28bc98624252b644d3726019b3f3 rh-m0-manifest.json From 493000deb1149135437442e58add9a1107f2323d Mon Sep 17 00:00:00 2001 From: PhysShell Date: Sun, 30 Aug 2026 18:11:30 +0000 Subject: [PATCH 13/13] RH-M0: give the labeler's reference a namespace Revision 12 closed guessing at the level of endpoint identity and left it one level above, in the reference a human uses to point at that identity. A bare "candidate 3" has no namespace: candidate 3 can exist on side A and on side B, and on two different cards, so after the labels were written the builder would still be choosing which one was meant. candidate_ref is now the frozen reference: target_hash the frozen target whose card this is revision_role A or B revision_sha the exact commit of that side candidate_index non-negative integer assigned by the card The full four-part key must be unique across the evidence corpus, and role and sha cross-check: role A requires the target's a_sha, role B its b_sha. A:1 and B:1 become trivially distinguishable, and a mistyped sha is caught rather than guessed. candidate_index is presentation-local. It must not participate in endpoint_id, in the canonical preimage, in ambiguity resolution, or in any tiebreaker. Otherwise the SARIF ordinal, prohibited one revision ago, walks back in through the front door under a new name. The index addresses a row on a card; it never identifies a finding. candidate_endpoint_mapping resolves candidate_ref to endpoint_id or unavailable. It is built during evidence-card construction, before any labeler response is interpreted and before any label exists, and is persisted and hashed with the truth artifact. Truth stores both candidate_ref and resolved_endpoint_id: the scorer needs a machine-comparable identity, and a later reader needs to see what the human was actually looking at. A candidate_ref resolving to unavailable must not be stored as an endpoint of a resolved relation, reusing the revision-12 fail-closed semantics rather than introducing a second set. The labeler never sees endpoint_id, so the hash cannot become a side channel back to rule. Deliberately not done: no canonical candidate ordering is frozen. The finding was a missing foreign key, not a missing ordering, and the meaning of an index comes from the frozen mapping rather than from a sort algorithm. Freezing an ordering too would grow a second identity scheme out of one integer. Endpoint identity is untouched: mint iff the canonical preimage is unique, otherwise unavailable, ordinal tiebreakers prohibited, narrow unavailable semantics. Construction-time checks: all 63 targets carry both a_sha and b_sha so the role-to-sha rule is checkable, all 63 target_hash values are unique so candidate_ref keys cannot collide across targets, candidate_index appears nowhere in the endpoint preimage, and the role vocabulary matches the sides present in the frozen targets. Asserted unchanged: the endpoint preimage, minting rule, ordinal prohibition, endpoint_contract.by_outcome, unavailable_endpoint_semantics, label_vocabulary, labeler_finding_projection.fields, frozen_targets, seeds, verdict_taxonomy.axes and all four outcome tables. Manifest SHA-256 3a99631292122919b1dc5d9750d899da0ecde23d9ba452c731da6c29209730b4 supersedes 5a6d6746691ccac2b8e653ed29c4194d206f28bc98624252b644d3726019b3f3. No B3 run. No truth labels. No correctness result. Co-Authored-By: Claude Opus 5 (1M context) Claude-Session: https://claude.ai/code/session_015vtUmvBDf69ccY5ju3PSHV --- research/rh-m0/rh-m0-manifest.json | 124 ++++++++++++++++++++------- research/rh-m0/rh-m0-manifest.sha256 | 2 +- 2 files changed, 94 insertions(+), 32 deletions(-) diff --git a/research/rh-m0/rh-m0-manifest.json b/research/rh-m0/rh-m0-manifest.json index de63104..d120bc4 100644 --- a/research/rh-m0/rh-m0-manifest.json +++ b/research/rh-m0/rh-m0-manifest.json @@ -795,33 +795,23 @@ }, "manifest_revision": { "b3_executed": false, + "endpoint_identity_untouched": "the revision-12 rules stand verbatim: mint iff the canonical preimage is unique, otherwise unavailable, ordinal tiebreakers prohibited, and the narrow unavailable semantics", "findings_applied": [ { - "assessment": "valid. Two rows sharing every preimage field collapse to one endpoint_id, so a branch over two physically present findings could present a one-element set and break the >= 2 cardinality the contract promises.", + "assessment": "valid. Revision 12 closed guessing at endpoint identity and left it one level above: candidate 3 can exist on side A and on side B and on two different cards, so the builder would still choose which was meant after labelling.", + "deliberately_not_done": "no canonical candidate ordering is frozen. The finding was a missing foreign key, not a missing ordering, and freezing one would grow a second identity scheme out of one integer.", "fix": [ - "endpoint_id is minted only when the canonical preimage occurs exactly once", - "otherwise unavailable, with limitation endpoint-id-unavailable:ambiguous-canonical-identity", - "ordinal and result-index tiebreakers are PROHIBITED", - "a resolved relation needing an unavailable endpoint is unadjudicable, but ended/new with a structurally empty set remain adjudicable" + "candidate_ref = (target_hash, revision_role, revision_sha, candidate_index), unique", + "revision_role and revision_sha cross-check against the target's a_sha / b_sha", + "candidate_index is presentation-local and barred from endpoint_id, the preimage, ambiguity resolution and any tiebreaker", + "candidate_endpoint_mapping is built before any label is interpreted and is persisted and hashed with the truth artifact", + "a candidate_ref resolving to unavailable cannot be an endpoint of a resolved relation" ], - "id": "P1", - "measured": "zero ambiguous preimages across 271 snapshots and 76253 findings of the frozen sample; the rule is preventive", - "title": "endpoint identity was not injective where cardinality is promised" - }, - { - "assessment": "valid. start_line and start_column live inside physical_anchor, while `line` exists at the top level, so the builder could still decide after the freeze what the names meant. Confirmed against a real normalized snapshot.", - "fix": [ - "explicit leaf-level source-to-output mappings", - "outputs are path, line, column, message; line and column come from physical_anchor", - "no output named start_line or start_column, and physical_anchor is never taken whole" - ], - "id": "P2", + "id": "blocker", "raised_by": [ - "Codex", "CodeRabbit" ], - "raised_independently": true, - "title": "projection named fields that do not exist at that level" + "title": "candidate index was an ambiguous foreign key" } ], "frozen_targets_unchanged": true, @@ -890,22 +880,31 @@ "reason": "truth endpoints and evidence-card allowlist", "revision": 11, "sha256": "858d80beeeb82619a0adc2fb29c505d1c03831cea2344541b576a7bb0139ee3e" + }, + { + "commit": "ff66d0fde283e692935538b181e30602ed2073da", + "reason": "fail-closed endpoint identity, explicit projection mapping", + "revision": 12, + "sha256": "5a6d6746691ccac2b8e653ed29c4194d206f28bc98624252b644d3726019b3f3" } ], - "reason": "two external review findings on revision 11; the projection defect was raised independently by both reviewers", - "revision": 12, - "supersedes_commit": "e418ec72076605e8c735c8971c7eff6228b34ae6", - "supersedes_sha256": "858d80beeeb82619a0adc2fb29c505d1c03831cea2344541b576a7bb0139ee3e", + "reason": "one external review finding on revision 12: the labeler's reference to an endpoint had no namespace", + "revision": 13, + "supersedes_commit": "ff66d0fde283e692935538b181e30602ed2073da", + "supersedes_sha256": "5a6d6746691ccac2b8e653ed29c4194d206f28bc98624252b644d3726019b3f3", "truth_labels_created": false, "what_this_revision_did_not_touch": [ + "endpoint preimage", + "minting rule", + "ordinal prohibition", + "endpoint_contract.by_outcome", + "unavailable_endpoint_semantics", + "label_vocabulary", + "labeler_finding_projection.fields", "frozen_targets", "seeds", "verdict_taxonomy.axes", - "axis_disposition", - "all four outcome tables", - "truth_protocol.label_vocabulary", - "endpoint_contract.by_outcome", - "labelers_must_not_see" + "all four outcome tables" ] }, "merge_capability": { @@ -1349,6 +1348,55 @@ "truth_labels_created": false, "truth_protocol": { "ai_agreement_is_not_truth": "two agreeing agents produce PROPOSED truth only; the final truth artifact requires human/owner adjudication and sign-off", + "candidate_endpoint_mapping": { + "audit_trail": { + "builder_mapping": "candidate_ref -> endpoint_id", + "labeler_saw": "B:3", + "recorded_response": "candidate_ref = {target_hash, revision_role: B, revision_sha, candidate_index: 3}", + "truth_artifact": "candidate_ref and endpoint_id together", + "why_both": "the scorer needs a machine-comparable identity; a later reader needs to see what the human was actually looking at. Storing only one of the two loses a different half of the audit trail." + }, + "built_when": "during evidence-card construction, BEFORE any labeler response is interpreted and before any label exists", + "labeler_never_sees_endpoint_id": "the labeler sees the card and answers with a position on it. endpoint_id is never shown, so the hash cannot become a side channel back to rule, which the projection allowlist exists to withhold.", + "persisted_with": "the truth artifact, and hashed with it", + "shape": "candidate_ref -> endpoint_id | unavailable", + "truth_record_per_chosen_endpoint": [ + "candidate_ref", + "resolved_endpoint_id" + ], + "unavailable_rule": "a candidate_ref resolving to endpoint_id = unavailable MUST NOT be stored as an endpoint of a resolved truth relation. This reuses the revision-12 fail-closed semantics rather than introducing a second set." + }, + "candidate_ordering": { + "frozen": false, + "if_reproducible_cards_are_wanted_later": "a deterministic ordering may be added, but it would be an ergonomic choice and must not become an identity", + "why_not": "the meaning of an index comes from the frozen candidate_endpoint_mapping, not from a sort algorithm. Freezing a canonical ordering as well would grow a second identity scheme out of one integer, and the finding was a missing foreign key, not a missing canonical ordering." + }, + "candidate_reference": { + "full_key": [ + "target_hash", + "revision_role", + "revision_sha", + "candidate_index" + ], + "not_an_identity": "candidate_ref names a place in the evidence presentation. endpoint_id names a finding. The mapping between them is data, frozen below, not an algorithm either side may re-derive.", + "presentation_local_only": { + "rule": "candidate_index is presentation-local. It MUST NOT participate in endpoint_id, in the canonical endpoint preimage, in ambiguity resolution, or in any identity tiebreaker.", + "why": "otherwise the SARIF ordinal, solemnly prohibited one revision ago, walks back in through the front door under a new name. The index addresses a row on a card; it never identifies a finding." + }, + "role_sha_consistency": { + "A": "revision_role = A requires revision_sha == the target's a_sha", + "B": "revision_role = B requires revision_sha == the target's b_sha", + "effect": "A:1 and B:1 become trivially distinguishable, and a mistyped sha is caught, not guessed" + }, + "shape": { + "candidate_index": "non-negative integer, assigned by the card", + "revision_role": "A or B", + "revision_sha": "the exact commit of that side", + "target_hash": "the hash of the frozen target whose card this is" + }, + "uniqueness": "the full key MUST be unique across the whole evidence corpus", + "why": "a labeler points at an endpoint through the evidence card. A bare integer has no namespace: candidate 3 can exist on side A and on side B, and on two different cards, so the builder would still be choosing which one was meant after the labels were written." + }, "construction_time_guarantees": { "checks": [ "every projection source path exists in normalized-findings/v2", @@ -1356,10 +1404,24 @@ "no projection source path is a forbidden field or lies beneath a forbidden object", "endpoint canonical-preimage multiplicity: unique mints an id, >1 yields unavailable, never ordinal-disambiguated", "every exact endpoint stored in truth has an available endpoint_id", - "every label_vocabulary entry has an endpoint_contract entry with a cardinality" + "every label_vocabulary entry has an endpoint_contract entry with a cardinality", + "every frozen target carries both a_sha and b_sha, so role-to-sha consistency is checkable", + "target_hash values are unique, so candidate_ref keys cannot collide across targets", + "candidate_index does not appear anywhere in the endpoint preimage", + "revision_role vocabulary matches the sides present in the frozen targets" ], "not_repository_enforced": "RH-M0 commits the manifest and its checksum only; see verdict_taxonomy.verification_status", "result_at_revision_construction": { + "candidate_reference": { + "candidate_index_in_endpoint_preimage": false, + "revision_roles_present_in_targets": [ + "A", + "B" + ], + "targets_total": 63, + "targets_with_both_sides": 63, + "unique_target_hashes": 63 + }, "checks_4_and_5_are_builder_obligations": "they constrain the truth-artifact builder, which does not exist yet; only their preconditions could be measured here", "duplicate_projection_outputs": 0, "endpoint_preimage_multiplicity": { @@ -1424,7 +1486,7 @@ "digest": "sha256, lowercase hex", "form": "endpoint_id, a hash over the canonical identity of one normalized finding", "free_text_prohibited": "an endpoint is never recorded as prose such as 'the finding one line below'. A natural-language foreign key cannot be scored.", - "how_labelers_designate_endpoints": "by the candidate index printed on the evidence card. The builder resolves an index to its endpoint_id. This keeps rule and message-identity machinery out of the labeler's view while still producing a machine-comparable record.", + "how_labelers_designate_endpoints": "by candidate_ref, see truth_protocol.candidate_reference. The builder resolves candidate_ref to an endpoint_id through the frozen candidate_endpoint_mapping. This keeps rule and identity machinery out of the labeler's view while producing a machine-comparable record.", "minting_rule": "an endpoint_id MAY be minted for a finding if and only if its canonical preimage occurs exactly once in that snapshot", "ordinal_tiebreaker": { "status": "PROHIBITED", diff --git a/research/rh-m0/rh-m0-manifest.sha256 b/research/rh-m0/rh-m0-manifest.sha256 index 1686f0d..8ce767d 100644 --- a/research/rh-m0/rh-m0-manifest.sha256 +++ b/research/rh-m0/rh-m0-manifest.sha256 @@ -1 +1 @@ -5a6d6746691ccac2b8e653ed29c4194d206f28bc98624252b644d3726019b3f3 rh-m0-manifest.json +3a99631292122919b1dc5d9750d899da0ecde23d9ba452c731da6c29209730b4 rh-m0-manifest.json