{
  "kind": "UNBOXED_PATTERNS_DERIVED",
  "built": "2026-09-12T17:25:59.210Z",
  "inputs_heads": {
    ".": "efd045d3fd9d742d2b7ec69974f6c4b24ffe51ad",
    "opensentience.org": "e58f4d7a8c551257ff50ca5d50565fb096d048cf",
    "WRL": "d431101567455d2c10dfeccb5c3a96334a1731bc",
    "TRVM": "3f2b41434e8a7c4d1bb40e3705936b93a1368c4c",
    "AmpersandBoxDesign": "664458e559c0c479c6397fae2bb92457d73b6e5d",
    "graphonomous": "61adec2d548408589372d4321da0cd96257bb230",
    "computedriven": "eb6320182c9b4820b5ed5b5d0d0fe3805a03ff03",
    "super": "51e37effb4761e89222896ea2a949228ea683bf5"
  },
  "summary": {
    "patterns": 32,
    "definitions": 2,
    "anti_patterns": 12,
    "WITNESSED": 13,
    "STATED": 14,
    "PROPOSED": 3,
    "CHECKABLE": 15,
    "RUNNABLE": 11,
    "EXECUTED": 14,
    "STAGED": 2,
    "PUBLISHED": 32,
    "REPRODUCED": 0,
    "counterexamples_resolved": 1,
    "counterexamples_scoped": 1,
    "counterexamples_marker_only": 6,
    "prior_art_works": 67,
    "prior_art_not_searched": 2,
    "invariant_null": 2,
    "by_family": {
      "locus": 5,
      "composition": 7,
      "progress": 6,
      "world": 7,
      "agency": 7
    },
    "witnessed_ids": [
      "record-at-a-boundary",
      "identity-is-a-seal",
      "refusing-join",
      "shared-observable",
      "capability-bounded-composition",
      "projection-not-duplication",
      "refusable-divergence",
      "progress-over-utilization",
      "carrier-multiplexing",
      "meaning-is-a-hash",
      "state-does-not-grant-authority",
      "evidence-before-claim",
      "descent-is-not-dependence"
    ]
  },
  "findings": [
    "shared-observable: marker \"Law 6\" occurs 3× in TRVM/forge/binding_run3k.py — it does not pick out one place, so it is weaker evidence than a resolved law id",
    "capability-bounded-composition: the marker is scoped to L10's declaration, but AmpersandBoxDesign/box-and-box/test/laws.mjs exports no law index (BB_LAW_INDEX) — the id itself could not be resolved against the suite that runs",
    "progress-over-utilization: marker \"fair arm\" occurs 2× in computedriven/receipts/R7-EXECUTED.md — it does not pick out one place, so it is weaker evidence than a resolved law id",
    "carrier-multiplexing: marker \"fair arm\" occurs 2× in computedriven/receipts/R7-EXECUTED.md — it does not pick out one place, so it is weaker evidence than a resolved law id"
  ],
  "patterns": [
    {
      "id": "active-locus",
      "kind": "definition",
      "name": "Active Locus",
      "family": "locus",
      "invariant": null,
      "cells": [],
      "claims": [],
      "witness": null,
      "prior_art": {
        "works": [
          {
            "work": "Hewitt, Actor model (1973)",
            "relation": "antecedent",
            "overlap": "an addressable entity that holds state and progresses independently of any thread",
            "difference": "an actor is defined by its mail behaviour; a locus here is defined by an identity that survives its carrier"
          },
          {
            "work": "Anthropic, Project Self-Model 2026 — 'locus of agency' (alignment.anthropic.com/2026/psm/)",
            "relation": "terminology-precedent",
            "overlap": "the word locus for the thing that acts",
            "difference": "PSM asks whether the Assistant is one; this book asks what invariants a locus must satisfy"
          }
        ],
        "novelty_not_claimed": "The word is not a coinage and the concept is not new. What is offered is a definition tight enough to carry invariants, not the observation that identities act.",
        "prose": "Anthropic PSM 2026 asks whether the Assistant is the 'locus of agency' (alignment.anthropic.com/2026/psm/); Hewitt's Actor model. Not a coinage."
      },
      "realizations": [
        "AGENCY.md §1"
      ],
      "related": [
        "record-at-a-boundary",
        "locus-is-not-its-carrier"
      ],
      "scene": "active-locus",
      "headline": "An agent is an active locus in a world.",
      "explanatory": "An active locus carries state, scoped authority, and causal continuity: it can establish its operational state, determine which actions are admissible under that state, the governing policy and its explicit grants, act on the world, and preserve the evidence needed to continue.",
      "technical": "An agent is an active locus of established operational state, scoped authority, observation, admissible action, and causal continuity within a world. Models and harnesses are components through which that locus reasons and acts; neither is, by itself, an identity criterion. — AGENCY.md §1, proposed 2026-08-25, not entrenched; only Travis ratifies it. The three registers above are the definition's own, and the headline is never shipped alone.",
      "problem": "Agent = Model + Harness describes an implementation bundle, not a property. It cannot tell two identical systems apart when one holds an authority the other does not, and it makes continuity unaskable: swap the model and it says the agent changed; reload the same weights and it says the agent continued — both wrong in the direction that matters.",
      "forces": "The industry shorthand is convenient and everywhere. The replacement decomposes instead of bundling, and costs a continuity question every time a component changes — a question it refuses to answer by fiat. That refusal is the advantage, and the careless sentence throws it away.",
      "construction": "Not a construction: a definition. What a page does with it is pick the register its reader stands at, never blend them, and trace to AGENCY.md rather than paraphrase.",
      "transformations": {
        "allowed": [
          "quoting one register whole",
          "tracing to AGENCY.md"
        ],
        "refused": [
          "paraphrasing the definition into a nearby synonym",
          "asserting by fiat that the locus survives a model swap — the retired formulation the IDENTITY_ASSERTED lint lists",
          "attaching an evidence rung to the definition"
        ]
      },
      "consequences": "Identity becomes something to test rather than assume. The locus vocabulary makes continuity claims easy to overclaim, which is why six lint classes guard the copy.",
      "analogy": "A seat on a council. The person in it changes; the seat's authority, its record and its place in the vote do not — and whether the new occupant carries the old one's commitments is a question the council can actually ask.",
      "applicability": "Every page in this portfolio that says 'agent'.",
      "syntax": [
        {
          "label": "The headline register, verbatim (AGENCY.md §1)",
          "path": "AGENCY.md",
          "start": "> An agent is an active locus in a world.",
          "count": 1
        }
      ],
      "takeaways": [
        {
          "from": "animation",
          "text": "Swapping the model did not answer whether the agent persisted; it asked."
        },
        {
          "from": "syntax",
          "text": "Three registers, one claim, three depths; the headline never ships alone."
        },
        {
          "from": "literature",
          "text": "Anthropic's 2026 PSM work asks whether the Assistant is the 'locus of agency' — the phrase is not a coinage and is never marketed as one."
        },
        {
          "from": "witness",
          "text": "A definition carries no rung; this page is labelled none by rule."
        }
      ],
      "wrl": {
        "note": "A definition; no world."
      },
      "up": "UP-001",
      "limit": "A definition. It establishes what the book means by a locus and carries no evidence rung at all (AGENCY.md §6). It does not establish that any system in this tree has one.",
      "next_rung": "Definitions do not climb the ladder. The nearest thing to progress is that every later chapter's invariant type-checks against this definition without amendment.",
      "derived": {
        "label": null,
        "CHECKABLE": false,
        "RUNNABLE": false,
        "EXECUTED": false,
        "STAGED": false,
        "REPRODUCED": false,
        "PUBLISHED": true,
        "next_rung_name": "in_tree",
        "why": [
          {
            "ok": null,
            "text": "kind is definition — carries no evidence rung (AGENCY.md §6)"
          }
        ],
        "related_closure": [
          "established-not-known",
          "locus-is-not-its-carrier",
          "record-at-a-boundary"
        ],
        "live_run": null,
        "counterexample_strength": null,
        "execution": null,
        "claim_statuses": [],
        "cell_statuses": []
      }
    },
    {
      "id": "record-at-a-boundary",
      "kind": "pattern",
      "name": "Record at a Boundary",
      "family": "locus",
      "invariant": "A record that carries a locus's fields describes, certifies or bounds the locus at a named boundary; it does not observe, act, or participate in the transition relation.",
      "cells": [],
      "claims": [],
      "witness": {
        "registry": "lint",
        "repo": ".",
        "path": "scripts/check-messaging-language.mjs",
        "shape": "lint",
        "evidence_kind": "counterexample",
        "rung": "in_tree",
        "rung_source": "the gate runs over 8 declared targets and exits non-zero on a hit",
        "cmd": "node scripts/check-messaging-language.mjs",
        "cwd": ".",
        "staged": false
      },
      "counterexample": {
        "shape": "lint",
        "sentence": "an assembly is a locus",
        "expected": "REFUSED",
        "lint_allow": "lint-allow:RECORD_IS_LOCUS — a lint counterexample must print the retired phrase to be one"
      },
      "prior_art": {
        "works": [
          {
            "work": "Parnas, information hiding (1972)",
            "relation": "antecedent",
            "overlap": "the split between what a thing is and what it shows at its edge",
            "difference": "Parnas splits interface from implementation for modules; this splits identity from its serialization"
          },
          {
            "work": "Korzybski, map ≠ territory",
            "relation": "close-analogue",
            "overlap": "the representation is not the thing",
            "difference": "a general semantic caution, not a rule a build can enforce"
          }
        ],
        "novelty_not_claimed": "The distinction is old. The contribution is making it refusable at a specific boundary rather than stating it as advice.",
        "prose": "world ≠ world serialization is the same distinction as map ≠ territory; the software form is Parnas's interface/implementation split applied to identity rather than modules."
      },
      "realizations": [
        "AGENCY.md §1 corollary",
        "AmpersandBoxDesign/site/index.html §02"
      ],
      "failure_mode": "record-is-locus",
      "related": [
        "active-locus"
      ],
      "scene": "record-at-a-boundary",
      "headline": "A record describes a locus at a boundary; it never is the locus.",
      "explanatory": "Records carry the locus's fields — world, authority, evidence, certificate — and it is tempting to say the record is the agent. It is not. A record does not observe, does not act, and does not participate in the transition relation, which is exactly what active means. The correct sentence names the boundary at which the record was taken.",
      "technical": "AGENCY.md §1 corollary: agent ≠ agent record, as world ≠ world serialization. Any sentence of the form 'X carries the locus fields, therefore X is a locus' is the error; the correct form is 'X records / certifies / bounds the locus at <boundary>'. Enforced as the lint class RECORD_IS_LOCUS over eight declared targets including this registry.",
      "problem": "The factory page's first draft said the Assembly record — which carries world, authority, evidence and certificate — is the active locus. It collapsed the exact distinction the definition exists to draw, one screen after drawing it. The same collapse produces 'the database row is the user' and 'the checkpoint is the process'.",
      "forces": "Records are what you can hold, hash, sign and ship; loci are what act. Everything durable about a locus reaches you as a record, so the record is always the nearer thing to point at. The pattern asks for one more clause — at which boundary — and that clause is what stops a snapshot being mistaken for a life.",
      "construction": "Give every record a boundary: the point in the world's history at which it was taken and by whom. Write locus sentences with an active verb and record sentences with records / certifies / bounds. Put the retired phrasings in a lint list and run it over every surface that talks about agency, including the surface that lists the retired phrasings.",
      "transformations": {
        "allowed": [
          "taking a record of a locus at any boundary",
          "certifying a locus from its records",
          "re-establishing a locus from records — a continuity question, not an identity assertion"
        ],
        "refused": [
          "'X carries the locus fields, therefore X is a locus'",
          "attaching an evidence rung to a definition",
          "letting a record observe or act in prose"
        ]
      },
      "consequences": "Continuity becomes askable: a successor may re-establish what a record says, and whether it did is a test, not a sentence. The cost is a lint that occasionally refuses your own registry — as it did here, twice, until the counterexample lines were quarantined by rule id.",
      "analogy": "A passport describes a traveller at the border where it was stamped. Nobody boards the traveller's flight by holding the passport, and nobody says the passport went to Lisbon.",
      "applicability": "Any system that persists, snapshots or certifies an acting thing: agent ledgers, factory records, world serializations, checkpoints. Especially copy about such systems, where the collapse is one adjective away.",
      "syntax": [
        {
          "label": "The corollary, verbatim (AGENCY.md §1)",
          "path": "AGENCY.md",
          "start": "> **agent ≠ agent record**",
          "count": 1
        },
        {
          "label": "The lint class that enforces it, from the rules the gate runs",
          "path": "scripts/messaging-rules.json",
          "start": "\"id\": \"RECORD_IS_LOCUS\"",
          "count": 5
        }
      ],
      "takeaways": [
        {
          "from": "animation",
          "text": "The record stayed at the boundary while the locus kept transitioning; the sentence that made them one was refused."
        },
        {
          "from": "syntax",
          "text": "The rule is a substring list with a stated reason and an 'instead' — a lint you can point at your own prose."
        },
        {
          "from": "literature",
          "text": "Map ≠ territory, and Parnas's interface/implementation split, applied to identity rather than modules."
        },
        {
          "from": "witness",
          "text": "The gate ran over eight targets with this registry among them; the counterexample sentence is one it rejects."
        }
      ],
      "wrl": {
        "note": "No core-role encoding: a record is not a role, and inventing one would need a book profile (WRL-P0), which waits on the WRL lane's ruling."
      },
      "up": "UP-002",
      "limit": "States an obligation about one boundary. It does not establish that any boundary in the tree is drawn in the right place, and satisfying it at one boundary implies nothing about the composition of two.",
      "next_rung": "A check that reads a boundary's declared record and refuses a field that crosses it undeclared. None exists; without one this stays STATED.",
      "derived": {
        "label": "WITNESSED",
        "CHECKABLE": true,
        "RUNNABLE": true,
        "EXECUTED": true,
        "STAGED": false,
        "REPRODUCED": false,
        "PUBLISHED": true,
        "next_rung_name": "live_local",
        "why": [
          {
            "ok": true,
            "text": "a witness is named"
          },
          {
            "ok": true,
            "text": "its evidence kind is one the ledger already uses (counterexample)"
          },
          {
            "ok": true,
            "text": "the witness path resolves in this tree"
          },
          {
            "ok": true,
            "text": "its rung is in_tree or above (in_tree)"
          },
          {
            "ok": true,
            "text": "a run is recorded for these exact bytes"
          },
          {
            "ok": true,
            "text": "no claim is cited that could be REFUTED"
          },
          {
            "ok": true,
            "text": "a counterexample is shipped (required once WITNESSED)"
          },
          {
            "ok": false,
            "text": "not staged on this site, so it cannot run from the page"
          }
        ],
        "related_closure": [
          "active-locus"
        ],
        "live_run": null,
        "counterexample_strength": null,
        "execution": {
          "at": "2026-09-11T15:27:41.066Z",
          "host": "PX13",
          "sha256": "4c1baac1ee7b0a3985fc5d8bc206009f42b5b114bf378797059ecdf873ec0d04",
          "repo_head": "92d99bf0f69f23bafb2dad7b1312ed2f3beb2164"
        },
        "claim_statuses": [],
        "cell_statuses": []
      }
    },
    {
      "id": "locus-is-not-its-carrier",
      "kind": "pattern",
      "name": "Locus Is Not Its Carrier",
      "family": "locus",
      "invariant": "A Carrier is a replaceable execution embodiment; no property of the locus is defined in terms of the thread, core or process currently carrying it.",
      "cells": [],
      "claims": [],
      "witness": null,
      "prior_art": {
        "works": [
          {
            "work": "M:N scheduling; green threads",
            "relation": "realization",
            "overlap": "many schedulable entities over fewer OS threads",
            "difference": "an implementation technique; here it is the invariant the technique happens to satisfy"
          },
          {
            "work": "BEAM processes",
            "relation": "realization",
            "overlap": "processes are not OS threads and never were",
            "difference": "the BEAM asserts it by construction; this pattern asks what must hold for the assertion to survive migration"
          }
        ],
        "novelty_not_claimed": "Nothing about the separation is new. The tree's own statement is a standing rule (computedriven/receipts/R7-OPEN.md §0), not a measured result — the measured fact is carrier-multiplexing, which is a different chapter.",
        "prose": "M:N scheduling; green threads; BEAM processes are not OS threads. The tree's statement is a standing rule (computedriven/receipts/R7-OPEN.md §0), not a measured result — the measured fact is carrier-multiplexing."
      },
      "realizations": [
        "computedriven/receipts/R7-OPEN.md:18"
      ],
      "failure_mode": "carrier-identity",
      "related": [
        "carrier-multiplexing",
        "dormant-but-alive"
      ],
      "scene": "locus-is-not-its-carrier",
      "headline": "A locus is not the thread running it; the thread is a replaceable embodiment.",
      "explanatory": "Everything a locus is — its seal, its state, its admissible transitions — is defined without reference to the carrier currently executing it. Swap the thread for a core, the core for a machine, and nothing the locus is has changed. This is a standing rule in ComputeDriven, and the measured fact beside it is Carrier Multiplexing.",
      "technical": "R7-OPEN §0, permanent standing rules from R2.1 and the R6 freeze: 'A Locus is not a thread; a Carrier is a replaceable embodiment.' There is no THREAD in the progress model's §4. A locus's context (KERNELLET-R1: admission + finality warden + possession) is the locus's; possession is a field that says which carrier, if any, holds it now.",
      "problem": "Most runtimes define the unit of computation as the thing that executes: a thread, a process, a container. Identity then dies with the carrier: a restart is a death, a migration is a copy, and 'the same agent' has to be re-asserted by convention rather than established by a seal.",
      "forces": "It is convenient to store a locus's state on its thread's stack. It is fast. It also makes every carrier replacement a serialization problem and every serialization a chance to make a Replica. The rule costs a level of indirection on every access to the context and buys carrier independence as a property rather than a promise.",
      "construction": "Give every locus a seal (Identity Is a Seal) and a context that lives outside any carrier. Model possession as a field with three states — vacant, attached, suspended — on the context, not as the carrier's opinion. Make carrier replacement a floor command that moves possession, and forbid every read of the context from asking which carrier holds it.",
      "transformations": {
        "allowed": [
          "replacing the carrier while possession moves atomically",
          "running the same locus on a thread today and a machine tomorrow",
          "suspending possession with no carrier at all (Dormant But Alive)"
        ],
        "refused": [
          "deriving identity, authority or state from the carrier",
          "serializing a context by copying and calling the copy the locus",
          "treating loss of a carrier as loss of the locus"
        ]
      },
      "consequences": "The system stops asking 'is the thread alive?' and starts asking 'is the locus established?'. That is the whole shift of Part I, and it is why the agency definition on this site says models and harnesses are components a locus reasons through, not identity criteria.",
      "analogy": "A chess game is not the board it is played on. Move the pieces to a new board, or play by post, and it is the same game at the same position; the board never had an opinion about which game it was.",
      "applicability": "Any system that must survive its own restarts, migrations or hardware: agent runtimes, durable workflows, the T&R shell's windows, FPLA elements. It is a rule to adopt at design time; retrofitting it means finding every place a thread-local was used as identity.",
      "syntax": [
        {
          "label": "The standing rule, verbatim (R7-OPEN §0, permanent)",
          "path": "computedriven/receipts/R7-OPEN.md",
          "start": "2. A Locus is not a thread",
          "count": 1
        },
        {
          "label": "What a context holds — and note that possession is a field, not a thread",
          "path": "computedriven/receipts/KERNELLET-R1.md",
          "start": "A context is one Locus Core Context",
          "count": 1
        }
      ],
      "takeaways": [
        {
          "from": "animation",
          "text": "Across three carriers the seal never changed, because nothing about the locus was defined by a carrier."
        },
        {
          "from": "syntax",
          "text": "Possession is a field on the context — vacant / attached / suspended — so 'which carrier' is data the locus owns, not a fact the carrier asserts."
        },
        {
          "from": "literature",
          "text": "BEAM got here first for processes; what the rule adds is that identity is a seal, so continuity is checkable rather than conventional."
        },
        {
          "from": "witness",
          "text": "This is STATED: a standing rule, not a measurement. The measured neighbour is Carrier Multiplexing."
        }
      ],
      "wrl": {
        "note": "No core-role encoding: WRL has no carrier role by design — the runtime is the carrier — which is the pattern's point, stated by absence."
      },
      "up": "UP-003",
      "limit": "The tree's statement is a standing rule (computedriven/receipts/R7-OPEN.md §0), not a measured result. Nothing here measures a locus surviving a carrier change; the measured neighbour is carrier-multiplexing, which is a weaker fact.",
      "next_rung": "A run in which one locus's identity is observed before and after its carrier is replaced, with both observations receipted. computedriven/ has no git origin (R8), so today nothing could pin that receipt.",
      "derived": {
        "label": "STATED",
        "CHECKABLE": false,
        "RUNNABLE": false,
        "EXECUTED": false,
        "STAGED": false,
        "REPRODUCED": false,
        "PUBLISHED": true,
        "next_rung_name": "in_tree",
        "why": [
          {
            "ok": false,
            "text": "a witness is named"
          },
          {
            "ok": false,
            "text": "its evidence kind is one the ledger already uses"
          },
          {
            "ok": false,
            "text": "the witness path resolves in this tree"
          },
          {
            "ok": false,
            "text": "its rung is in_tree or above"
          },
          {
            "ok": false,
            "text": "a run is recorded for these exact bytes"
          },
          {
            "ok": true,
            "text": "no claim is cited that could be REFUTED"
          },
          {
            "ok": false,
            "text": "a counterexample is shipped (required once WITNESSED)"
          },
          {
            "ok": false,
            "text": "not staged on this site, so it cannot run from the page"
          }
        ],
        "related_closure": [
          "active-locus",
          "carrier-multiplexing",
          "dormant-but-alive"
        ],
        "live_run": null,
        "counterexample_strength": null,
        "execution": null,
        "claim_statuses": [],
        "cell_statuses": []
      }
    },
    {
      "id": "identity-is-a-seal",
      "kind": "pattern",
      "name": "Identity Is a Seal",
      "family": "locus",
      "invariant": "The identity of a semantic artifact is the hash of its canonical form, computed identically on every host; two artifacts with different futures have different seals.",
      "cells": [],
      "claims": [],
      "witness": {
        "registry": "wrl",
        "repo": "WRL",
        "path": "WRL/test/conformance.mjs",
        "shape": "side-effect",
        "evidence_kind": "constructive_witness",
        "rung": "in_tree",
        "rung_source": "STACK_COMPLETION.md:73 (890 checks then; run today)",
        "cmd": "node test/conformance.mjs",
        "cwd": "WRL",
        "staged": false
      },
      "counterexample": {
        "shape": "fixture",
        "path": "WRL/test/projection-negative-vectors.json",
        "expected": "REFUSED",
        "expected_count": 15
      },
      "prior_art": {
        "works": [
          {
            "work": "Merkle (1979)",
            "relation": "antecedent",
            "overlap": "a hash names a structure",
            "difference": "Merkle authenticates; this uses the hash as the identity itself"
          },
          {
            "work": "Unison — every definition identified by the hash of its syntax tree",
            "relation": "close-analogue",
            "overlap": "content-addressed identity for program meaning, not for bytes",
            "difference": "Unison hashes definitions; WRL seals a topology, and comments do not move the id"
          },
          {
            "work": "Nix store paths",
            "relation": "realization",
            "overlap": "identity derived from inputs rather than assigned",
            "difference": "Nix hashes build inputs; the seal here is over a semantic graph"
          }
        ],
        "novelty_not_claimed": "Content-addressed identity is well-established prior art. The phrase 'birth key' appears once in WRL/HANDOFF_D8_PATH_B.md; the invariant's wording is the book's, and the wording is not the contribution.",
        "prose": "Merkle 1979; Nix store paths; Unison identifies every definition by the hash of its syntax tree. 'birth key' appears once in WRL/HANDOFF_D8_PATH_B.md; the invariant's wording is the book's."
      },
      "realizations": [
        "WRL/README.md:17-27"
      ],
      "failure_mode": "location-leak",
      "related": [
        "meaning-is-a-hash",
        "refusable-divergence"
      ],
      "scene": "identity-is-a-seal",
      "headline": "An artifact's identity is the hash of its canonical form, the same on every host.",
      "explanatory": "Identity is computed, not assigned. A WRL world is parsed, canonicalized and sealed to a SemanticArtifactID; every host derives the same id from the same canonical form, and a world with a different future has a different id. Nothing about the id names a file, a row or a machine.",
      "technical": "WRL Core 0.1.2: the starter world seals to sem-67e954cf… on every host; a second, larger pinned fixture is what the batteries assert against; both are checked on every change by test/conformance.mjs (924 checks passing at the last run). 'birth key' appears once in WRL/HANDOFF_D8_PATH_B.md; the invariant's wording is the book's.",
      "problem": "Systems assign identity by location — an autoincrement, a path, a host-qualified name — and then have to defend the assignment with locks, registries and migrations. Two copies with the same content get different names; one thing edited in place keeps its name while its meaning changes.",
      "forces": "Hashing needs a canonical form, and canonicalization is where the real work is: two texts with the same meaning must produce the same bytes before hashing. A seal is only as trustworthy as the canonicalizer that both sides run, which is why the conformance suite and the cross-implementation vectors exist.",
      "construction": "Define the canonical form first. Hash it. Make the hash the only identity the artifact has; let names be labels that point at hashes. Pin fixtures whose ids must never change, and fail the build if one does.",
      "transformations": {
        "allowed": [
          "moving the artifact between hosts, files, rows",
          "renaming a label that points at a seal",
          "re-deriving the seal on any host"
        ],
        "refused": [
          "assigning identity from a location",
          "editing in place under a preserved id",
          "trusting an id a record asserts without recomputing it (see Refusable Divergence)"
        ]
      },
      "consequences": "Identity questions become recomputable. The cost is that in-place mutation is gone: to change a world is to make a new one, and continuity between the two is a separate question (Continuity Through Reconstruction).",
      "analogy": "An ISBN is assigned; a checksum is computed. Two warehouses can disagree about an ISBN. They cannot disagree about a checksum without one of them being wrong about the bytes.",
      "applicability": "Any artifact that must be the same thing on two machines: worlds, projections, certificates, packages. Not for things whose identity is legitimately their history rather than their content.",
      "syntax": [
        {
          "label": "The starter world that seals to sem-67e954cf… — WRL/README.md",
          "path": "WRL/README.md",
          "start": "profile forge.world.core.v1",
          "count": 10
        },
        {
          "label": "The sentence that names the seal",
          "path": "WRL/README.md",
          "start": "sem-67e954cf",
          "count": 1
        }
      ],
      "takeaways": [
        {
          "from": "animation",
          "text": "Three hosts, one seal; one changed relation, a different seal."
        },
        {
          "from": "syntax",
          "text": "Nine lines of WRL are a world, and the world is its hash."
        },
        {
          "from": "literature",
          "text": "Merkle trees, Nix store paths and Unison's hashed definitions are the ancestry; credit them."
        },
        {
          "from": "witness",
          "text": "The conformance suite pins the fixture ids; this page cannot run it yet and says so."
        }
      ],
      "wrl": {
        "note": "The starter world. Sealed here, in node, at build; the id the page prints was computed from these bytes by WRL's own wrl.js."
      },
      "up": "UP-004",
      "limit": "wrl.js seals a topology to an id and the forge agrees with it. That establishes that the seal is a function of the graph and not of the text — it does not establish that the graph captures the meaning anyone cares about.",
      "next_rung": "live_local: the seal computed in a browser on this site from source the reader supplies, rather than at build time. The build already seals 33 worlds; nothing yet exposes sealWorld to the page.",
      "derived": {
        "label": "WITNESSED",
        "CHECKABLE": true,
        "RUNNABLE": true,
        "EXECUTED": true,
        "STAGED": false,
        "REPRODUCED": false,
        "PUBLISHED": true,
        "next_rung_name": "live_local",
        "why": [
          {
            "ok": true,
            "text": "a witness is named"
          },
          {
            "ok": true,
            "text": "its evidence kind is one the ledger already uses (constructive_witness)"
          },
          {
            "ok": true,
            "text": "the witness path resolves in this tree"
          },
          {
            "ok": true,
            "text": "its rung is in_tree or above (in_tree)"
          },
          {
            "ok": true,
            "text": "a run is recorded for these exact bytes"
          },
          {
            "ok": true,
            "text": "no claim is cited that could be REFUTED"
          },
          {
            "ok": true,
            "text": "a counterexample is shipped (required once WITNESSED)"
          },
          {
            "ok": false,
            "text": "not staged on this site, so it cannot run from the page"
          }
        ],
        "related_closure": [
          "meaning-is-a-hash",
          "refusable-divergence"
        ],
        "live_run": null,
        "counterexample_strength": null,
        "execution": {
          "at": "2026-09-11T15:25:45.285Z",
          "host": "PX13",
          "sha256": "e1f1e313eefe0001dc23d95da90011a36596924915d185ce6b1171219ef1925c",
          "repo_head": "32160fec77a13ad152176fed3001b0afbdebee42"
        },
        "claim_statuses": [],
        "cell_statuses": []
      }
    },
    {
      "id": "continuity-through-reconstruction",
      "kind": "pattern",
      "name": "Continuity Through Reconstruction",
      "family": "locus",
      "invariant": "A locus continues across a replacement iff a minimal causally established support set sufficient for each declared capability is retained; reconstruction from durable facts is continuity, not creation.",
      "cells": [
        {
          "ref": "30",
          "modality": "necessary"
        }
      ],
      "claims": [
        {
          "ref": "EMB-SUPPORT-GRAPH",
          "modality": "not_sufficient"
        },
        {
          "ref": "EMB-KERNEL-LOCATION",
          "modality": "not_sufficient"
        }
      ],
      "witness": {
        "registry": "ledger",
        "repo": ".",
        "path": "scripts/emb-support.mjs",
        "shape": "side-effect",
        "evidence_kind": "constructive_witness",
        "rung": "in_tree",
        "rung_source": "engine runs; 4 capabilities, 4 synthetic, 0 observed (AGENCY.md §5b)",
        "cmd": "node scripts/emb-support.mjs",
        "cwd": ".",
        "staged": false
      },
      "prior_art": {
        "works": [
          {
            "work": "Atkinson & Morrison, orthogonal persistence — persistence independence",
            "relation": "antecedent",
            "overlap": "a value's existence does not depend on where it is stored",
            "difference": "their concern is storage transparency; this one is whether restoration may claim to be continuation"
          },
          {
            "work": "Erlang code change (hot code loading)",
            "relation": "realization",
            "overlap": "a process survives the replacement of the code that runs it",
            "difference": "the process never stops; reconstruction here starts something that had stopped"
          },
          {
            "work": "Distillation as successor",
            "relation": "contrasting-solution",
            "overlap": "a later instance stands in for an earlier one",
            "difference": "a successor is honestly a new thing; the question here is when that honesty is required"
          }
        ],
        "novelty_not_claimed": "Persistence and restoration are both old. Nothing here is written in the present perfect: stage 5 (Inheritance) has never been reached, and the cell this pattern rests on (30, capability heredity) is status missing.",
        "prose": "Atkinson & Morrison, orthogonal persistence (persistence independence); Erlang code change; distillation as successor. Never write in the present perfect: stage 5 (Inheritance) has never been reached."
      },
      "realizations": [
        "AGENCY.md §5b",
        "mosaic/embodiment.json"
      ],
      "failure_mode": "replica-theater",
      "related": [
        "descent-is-not-dependence",
        "orthogonal-persistence"
      ],
      "scene": "continuity-through-reconstruction",
      "headline": "A locus continues across a replacement only if a minimal, causally established support set for each declared capability is retained.",
      "explanatory": "When a carrier is gone and something is rebuilt from what survived, the rebuilt thing is either a continuation or a new being, and the difference is testable: does it retain the declared capabilities under the declared replacement contract, and is the support that carries them causally established rather than merely inherited? Reconstruction from durable facts is continuity when that test passes. Nothing in this tree has passed it yet.",
      "technical": "AGENCY.md §5b: a continuity kernel is a minimal causally established support set sufficient to retain a declared capability under a declared replacement contract — M′ + K_c → c and M′ + (S ∖ K_c) ↛ c. Support is a hypergraph, so kernels are set-shaped; the revocation-cut dual holds only when the support function is monotone, and scripts/emb-support.mjs refuses kernels for a capability whose observations falsify it. Six-stage lifecycle Motor → Crystallization → Certification → Promotion → Inheritance → Composition; stage 5 has never been reached. Claims EMB-SUPPORT-GRAPH and EMB-KERNEL-LOCATION are OPEN.",
      "problem": "'Reload the weights and it is the same agent; swap the model and it is a different one.' Both are wrong in the direction that matters, because neither asked what was retained. A successor that keeps the name and loses the capability is a new being wearing a label; a successor that keeps the capability from different support is a continuation the old definition could not see.",
      "forces": "Ablation is expensive and lineage is free, so provenance will always be the evidence at hand. The obligation 'capability extends' is satisfied by equality — a total no-op satisfies it — so the test has to be about support topology, not capability. And the natural way to write the machinery puts a lineage edge in the causal chain, which the tree already refused once on review.",
      "construction": "Declare the capability and the replacement contract before the replacement. Generate candidate support sets from lineage, then establish support by ablation of the set under test, intervention, runtime dependency or replacement replay. Compute kernels over sets. Refuse when monotonicity is falsified. Report observed kernels as observed and synthetic ones as synthetic.",
      "transformations": {
        "allowed": [
          "rebuilding a locus from durable facts and testing what it retained",
          "declaring a weaker replacement contract and testing against that",
          "keeping several sufficient kernels at once"
        ],
        "refused": [
          "asserting continuity from a preserved name or a lineage edge",
          "'has continued' / 'has inherited' in the present perfect without an observed kernel",
          "ablating one artifact and concluding about a set"
        ]
      },
      "consequences": "Identity across replacement becomes an experiment with a receipt. The cost is that every 'the agent resumes where it left off' sentence is banned until the experiment runs — a cost this stack has already paid in retracted copy.",
      "analogy": "A ship rebuilt plank by plank is the same ship if what made it seaworthy was carried across, and you find that out by removing planks, not by reading the nameplate.",
      "applicability": "Model substitution, factory lineages, restarts of long-running agents, migrations between runtimes — anywhere 'the same' is claimed across a discontinuity.",
      "syntax": [
        {
          "label": "The definition, verbatim (AGENCY.md §5b)",
          "path": "AGENCY.md",
          "start": "A continuity kernel is",
          "count": 2
        },
        {
          "label": "The two refusals the engine makes before computing anything",
          "path": "scripts/emb-support.mjs",
          "start": " * THE TWO REFUSALS",
          "count": 8
        }
      ],
      "takeaways": [
        {
          "from": "animation",
          "text": "The successor was built from K, and K became a kernel only after ablation showed c was lost without it."
        },
        {
          "from": "syntax",
          "text": "Kernels are minimal support SETS under a declared contract; the dual with revocation cuts needs monotonicity, which is a hypothesis with a falsifier."
        },
        {
          "from": "literature",
          "text": "Orthogonal persistence's reconstruction, Erlang's code change, and the ship of Theseus — all about what is carried, none about the name."
        },
        {
          "from": "witness",
          "text": "emb-support.mjs runs today: 4 capabilities, 4 synthetic, 0 observed. Both refusals fire. Heredity is unwitnessed and the page says so."
        }
      ],
      "wrl": {
        "note": "No core-role encoding yet; continuity is a relation between two worlds and a contract, not a topology."
      },
      "up": "UP-005",
      "limit": "Rests on cell 30 (capability heredity), whose status is missing — the tree has not established that a reconstructed locus may inherit anything. Stage 5 (Inheritance) has never been reached, and no sentence here is in the present perfect.",
      "next_rung": "Cell 30 ruled either way. Until then this pattern's basis is a question, and the page says so rather than rounding it up.",
      "derived": {
        "label": "STATED",
        "CHECKABLE": true,
        "RUNNABLE": true,
        "EXECUTED": true,
        "STAGED": false,
        "REPRODUCED": false,
        "PUBLISHED": true,
        "next_rung_name": "live_local",
        "why": [
          {
            "ok": true,
            "text": "a witness is named"
          },
          {
            "ok": true,
            "text": "its evidence kind is one the ledger already uses (constructive_witness)"
          },
          {
            "ok": true,
            "text": "the witness path resolves in this tree"
          },
          {
            "ok": true,
            "text": "its rung is in_tree or above (in_tree)"
          },
          {
            "ok": true,
            "text": "a run is recorded for these exact bytes"
          },
          {
            "ok": false,
            "text": "every cited claim is PROVED/KNOWN/MEASURED/CONDITIONAL (OPEN, OPEN)"
          },
          {
            "ok": false,
            "text": "a counterexample is shipped (required once WITNESSED)"
          },
          {
            "ok": false,
            "text": "not staged on this site, so it cannot run from the page"
          }
        ],
        "related_closure": [
          "descent-is-not-dependence",
          "orthogonal-persistence"
        ],
        "live_run": null,
        "counterexample_strength": null,
        "execution": {
          "at": "2026-09-11T15:25:45.592Z",
          "host": "PX13",
          "sha256": "7a8b6a2f444c397075557f0210684171de3b8fc03a59a564cd5fd0347f3c456b",
          "repo_head": "92d99bf0f69f23bafb2dad7b1312ed2f3beb2164"
        },
        "claim_statuses": [
          "OPEN",
          "OPEN"
        ],
        "cell_statuses": [
          {
            "num": "30",
            "modality": "necessary",
            "status": "missing"
          }
        ]
      }
    },
    {
      "id": "refusing-join",
      "kind": "pattern",
      "name": "Refusing Join",
      "family": "composition",
      "invariant": "Composition of two independently produced assemblies either yields a composite that satisfies the compose laws or is refused naming the field that made it impossible; refusal is a valid outcome, not a failure.",
      "cells": [],
      "claims": [],
      "witness": {
        "registry": "box-and-box",
        "repo": "AmpersandBoxDesign",
        "path": "AmpersandBoxDesign/box-and-box/test/compose-laws.mjs",
        "shape": "suite",
        "evidence_kind": "constructive_witness",
        "rung": "live_deployed",
        "rung_source": "A live-run receipt: the staged bytes ran from https://opensentience.org/patterns/refusing-join and reported 101 laws · 101 passing · 0 failing · 3 declared-open, bound to staged stamp 06726c3fb022f31e. Recorded by _patterns/build/run-live.mjs; the rung is derived from that receipt by build.mjs (P26), not authored.",
        "cmd": "node test/compose-laws.mjs",
        "cwd": "AmpersandBoxDesign/box-and-box",
        "staged": true,
        "staged_path": "opensentience.org/witness/src/AmpersandBoxDesign/box-and-box/test/compose-laws.mjs"
      },
      "counterexample": {
        "shape": "refusal",
        "path": "AmpersandBoxDesign/box-and-box/test/compose-laws.mjs",
        "marker": "undeclared |> narrow ⇒ 0̲",
        "law": "CD1",
        "expected": "REFUSED",
        "note": "v0.4 named the marker narrow-into-ANY-refused, which is CD2's FAILURE string (a refusal that must NOT happen). A marker proves the file mentions a string, not that the string is a refusal — P2 finding; the page runs CD1 live."
      },
      "prior_art": {
        "works": [
          {
            "work": "Monoid laws (associativity, identity)",
            "relation": "antecedent",
            "overlap": "composition with an identity and an annihilator is standard algebra",
            "difference": "the algebra is standard; treating the annihilator as a reportable outcome with a named cause is the pattern"
          },
          {
            "work": "'the 2026 λA literature, Theorem 5.7'",
            "relation": "not-searched",
            "overlap": "cited by FACTORY_REVIEW_BUNDLE.md:507 from page copy only",
            "difference": "the paper has never been located; this citation establishes nothing and is recorded so that it cannot be quoted as if it did"
          }
        ],
        "novelty_not_claimed": "Algebraic composition with a zero is textbook. The claim is narrower: that an UNDECLARED field is not a wildcard, and that a refusal must name the field — 101 enforced compose laws, not a new algebra.",
        "prose": "Monoid laws (associativity, identity). FACTORY_REVIEW_BUNDLE.md cites 'the 2026 λA literature, Theorem 5.7' from page copy only — NOT SEARCHED for the paper."
      },
      "realizations": [
        "FACTORY_REVIEW_BUNDLE.md:460",
        "FACTORY_REVIEW_BUNDLE.md:507",
        "amp-nav.js:297"
      ],
      "failure_mode": "invisible-state",
      "related": [
        "three-valued-outcome",
        "capability-bounded-composition"
      ],
      "headline": "A join that cannot be made is refused, and the refusal names the field.",
      "explanatory": "Two assemblies built in ignorance of each other are brought to a join. Either the composite satisfies every compose law the algebra states, or the join returns the annihilator and says which contract field made it impossible. Nothing is coerced, defaulted or repaired on the way through. A refusal is a first-class outcome of composition, not an error path around it.",
      "technical": "For bricks a, b with declared contracts, composePipe(a, b) is either an admitted composite or 0̲ (ZERO, annihilated). An UNDECLARED contract field is not a wildcard: undeclared |> narrow ⇒ 0̲ (CD1). An explicit ANY is directional: a narrow producer composes into an ANY consumer, an ANY producer does not compose into a narrow consumer (CD2). & does not launder undeclaredness into a declared interface (CD3). The identities none() and idBrick() DECLARE '*' so the identity laws survive without the fix degenerating into refuse-everything (CD2/CD4). 101 enforced compose laws, 2000 trials each, totals derived by the suite.",
      "problem": "Systems built from independently produced parts need a place where parts meet. The conventional join coerces: an absent interface defaults to the most permissive one, a mismatched type is widened, a missing field is repaired. On 2026-08-22 exactly that bug was found in this algebra — Brick() defaulted an absent contract field to '*', so an assembly that declared no interface at all received the most permissive interface in the algebra, and every hand-off passed a check that had nothing to check. Five falsifiers were written against the unfixed code and all five failed.",
      "forces": "Refusing is cheap to implement and expensive to live with: every refusal is work someone must redo, so the pressure is always toward 'just compose it'. The identity laws must still hold, or the fix degenerates into refuse-everything (CD2 and CD4a exist for that). MISSING ≠ UNIVERSAL has to have content in both directions. And a refusal must NAME what it refused, or the producer cannot repair its side — a silent 0̲ is only marginally better than a silent coercion.",
      "construction": "Represent contracts as terms with an explicit UNDECLARED kind distinct from ANY. Normalize before comparing (norm). Make composition total: it always returns a brick, and the annihilator ZERO is a brick with annihilated === true. Preserve the identities by having none() and idBrick() declare '*'. State the narrowed domain as its own law (CD4b) rather than leaving it implicit. Derive every printed total from the suite; hand-typed totals drifted three times before this rule.",
      "transformations": {
        "allowed": [
          "re-associating a chain of joins (|> is a phase-graded monoid)",
          "commuting operands of & (a commutative idempotent monoid)",
          "declaring a contract explicitly where one was absent — this can only turn a refusal into a composite, never the reverse"
        ],
        "refused": [
          "defaulting an absent contract field to '*' or any other value",
          "widening a type to make a join succeed",
          "repairing evidence on the way through a join (VALUE laws: defaults complete absence, never repair)",
          "treating the annihilator as an exception or a crash"
        ]
      },
      "consequences": "Composition becomes something a receiver can check, not something it must trust. The cost is that an under-declared assembly is unusable until it declares, which is the point. Refusal ≠ failure: the three-valued outcome vocabulary (APPLIED · REFUSED · INDETERMINATE) in three-valued-outcome is this principle for interventions.",
      "scene": "refusing-join",
      "analogy": "Customs at a border between two factories. A crate with a declared manifest that matches the receiving line goes through. A crate with no manifest is not waved through as 'could be anything' — it is turned back with a slip that says which field was missing. The slip is the product of that transaction, and it is worth more than a crate that was let through on a guess.",
      "applicability": "Use it wherever two things built separately must meet: assemblies at a factory join, capability bricks in a governance ladder, records from two verifiers, agents handing work to agents. Do not use it where the join is the identity operation on one thing — an identity must DECLARE '*', or the pattern degenerates into refuse-everything.",
      "syntax": [
        {
          "label": "CD1 — the falsifier, verbatim from the suite this page runs",
          "path": "AmpersandBoxDesign/box-and-box/test/compose-laws.mjs",
          "start": "  ['CD1', 'an UNDECLARED feeds_into is NOT a wildcard",
          "count": 6
        },
        {
          "label": "How a refusal carries its reason — the annihilator is a brick",
          "path": "AmpersandBoxDesign/box-and-box/compose.mjs",
          "start": "const zeroBecause = (reason)",
          "count": 5
        }
      ],
      "takeaways": [
        {
          "from": "animation",
          "text": "A join is a check on declared contracts; a refusal is a returned value that names the field."
        },
        {
          "from": "syntax",
          "text": "0̲ is a Brick with annihilated: true and a refusal string — composition is total, and the failure case is data."
        },
        {
          "from": "syntax",
          "text": "MISSING ≠ UNIVERSAL: an absent contract field normalizes to {kind:'undeclared'}, never to '*'. The identity elements declare '*' explicitly so the identity laws survive."
        },
        {
          "from": "literature",
          "text": "The two laws a refusing join must keep — associativity and identity — are the monoid laws; the factory page notes the λA literature derived the same pair independently (paper not yet located: prior_art says so)."
        },
        {
          "from": "witness",
          "text": "This is not an argument: 101 laws × 2000 trials ran in your browser above, on the same bytes CI runs."
        }
      ],
      "wrl": {
        "refused": "refusing-join.refused.wrl",
        "note": "A Door admits exactly one signal wire. Two producers into one join is WRL_CONTROLLER_CONFLICT — the language's own refusing join, named at the port."
      },
      "up": "UP-006",
      "limit": "101 compose laws over this algebra's own bricks, 2000 trials each, on the bytes staged on this site. It establishes that THIS composition refuses an undeclared contract. It does not establish that refusal is the right policy for any other join, and it says nothing about joins outside box-and-box.",
      "next_rung": "external — an implementation not written in this tree passing the same law suite. Five ports exist (npm run parity) and all five are ours, so none of them is this rung. It cannot be reached by editing this file: the build derives the rung from receipts, and outside reproduction needs a receipt kind that does not exist yet.",
      "derived": {
        "label": "WITNESSED",
        "CHECKABLE": true,
        "RUNNABLE": true,
        "EXECUTED": true,
        "STAGED": true,
        "REPRODUCED": false,
        "PUBLISHED": true,
        "next_rung_name": "external",
        "why": [
          {
            "ok": true,
            "text": "a witness is named"
          },
          {
            "ok": true,
            "text": "its evidence kind is one the ledger already uses (constructive_witness)"
          },
          {
            "ok": true,
            "text": "the witness path resolves in this tree"
          },
          {
            "ok": true,
            "text": "its rung is in_tree or above (live_deployed)"
          },
          {
            "ok": true,
            "text": "a run is recorded for these exact bytes"
          },
          {
            "ok": true,
            "text": "no claim is cited that could be REFUTED"
          },
          {
            "ok": true,
            "text": "a counterexample is shipped (required once WITNESSED)"
          },
          {
            "ok": true,
            "text": "it has run from the deployed site — 101 laws · 101 passing · 0 failing · 3 declared-open · 7584.4 ms"
          }
        ],
        "related_closure": [
          "capability-bounded-composition",
          "refusal-gate",
          "three-valued-outcome"
        ],
        "live_run": {
          "at": "2026-09-12T00:01:45.814Z",
          "url": "https://opensentience.org/patterns/refusing-join",
          "status": "101 laws · 101 passing · 0 failing · 3 declared-open · 7584.4 ms",
          "stamp": "06726c3fb022f31e"
        },
        "counterexample_strength": {
          "strength": "resolved",
          "occurrences": 1,
          "law": "CD1"
        },
        "execution": {
          "at": "2026-09-11T15:25:45.724Z",
          "host": "PX13",
          "sha256": "06726c3fb022f31e7b27eb7159c731fd9ecd349405dbc698e84090914856a19b",
          "repo_head": "e41e5fab63c19a3671bf417a6949e10a27782830"
        },
        "claim_statuses": [],
        "cell_statuses": []
      }
    },
    {
      "id": "shared-observable",
      "kind": "pattern",
      "name": "Shared Observable",
      "family": "composition",
      "invariant": "A canonical shared observable carries every state variable that can determine future behaviour within its declared domain; two states with different futures have different observable bytes.",
      "cells": [],
      "claims": [],
      "witness": {
        "registry": "trvm",
        "repo": "TRVM",
        "path": "TRVM/forge/FORGE_BINDING_RESULTS.md",
        "shape": "receipt",
        "evidence_kind": "constructive_witness",
        "rung": "in_tree",
        "rung_source": "TRVM/LAWS.md:80-95 Law 6 witnesses list",
        "staged": false,
        "receipt_at": "2026-07-22"
      },
      "counterexample": {
        "shape": "refusal",
        "path": "TRVM/forge/binding_run3k.py",
        "marker": "Law 6",
        "expected": "REFUSED"
      },
      "prior_art": {
        "works": [
          {
            "work": "Nerode quotient; PSR sufficient statistic",
            "relation": "antecedent",
            "overlap": "the minimal state that determines future behaviour",
            "difference": "none that has been established — invariant-r10/package-v2.8/v1-provenance/00_EXECUTIVE_FINDINGS.md:45 records it as 'known property, new name; P1'"
          },
          {
            "work": "Markov condition",
            "relation": "close-analogue",
            "overlap": "the present screens the future from the past",
            "difference": "stated over probability; here over observable state at a boundary"
          }
        ],
        "novelty_not_claimed": "The tree has already demoted this to P1 as a renaming. Two standings stand unresolved: TRVM/LAWS.md:80 ratifies Law 6 for Film bytes ('GLOBAL' = not horizon-scoped), and the frontier package finds it too strong lifted to arbitrary observables. The axis is scope, and it is a hypothesis.",
        "prose": "Nerode quotient; PSR sufficient statistic; Markov condition. invariant-r10/package-v2.8/v1-provenance/00_EXECUTIVE_FINDINGS.md:45 says 'known property, new name; P1'. TWO STANDINGS: TRVM/LAWS.md:80 ratifies it for Film bytes ('GLOBAL' = not horizon-scoped); the frontier package finds it too strong lifted to arbitrary observables — a SCOPE hypothesis, unresolved."
      },
      "realizations": [
        "TRVM/LAWS.md:80"
      ],
      "failure_mode": "invisible-state",
      "related": [
        "semantic-membrane",
        "projection-not-duplication"
      ],
      "scene": "shared-observable",
      "headline": "Every state variable that can determine the future must be in the observable bytes.",
      "explanatory": "If two states can lead to different futures, their observable bytes must differ. Anything that changes a future transition while leaving the bytes alone is hidden state, and hidden state is the bug that every replay, every cache key and every 'it works on my machine' eventually finds.",
      "technical": "TRVM Law 6, ratified 2026-07-22, GLOBAL (no longer horizon-scoped): 'A canonical shared observable must carry every state variable that can determine future behavior; if two states can lead to different futures, their Film bytes must differ.' Witnesses in forge/FORGE_BINDING_RESULTS.md; enforced by binding_run3k.py and binding_run3h.py (hidden-state → Film divergence). In the frontier package it is adjudicated as the Markov / sufficient-statistic condition — known property, new name — and too strong when lifted to arbitrary observables, surviving there as the ADEQUACY/EQUIVARIANCE pair.",
      "problem": "A rotor position, a receipt flag, a once-latch — each changed a future transition and none was in the Film. Replays diverged; the divergence was invisible in the bytes that were supposed to be the whole story. Three witnesses, then a law.",
      "forces": "Carrying every variable is the easy reading and the wrong one: byte-level variables break convergence, so the frontier package demotes the naked statement to P1 and pairs it with equivariance. The honest form is scoped: for this observable, in this domain, these are the variables that determine the future. Two lanes hold two standings for exactly this reason, and neither cites the other.",
      "construction": "Enumerate the variables that can change a future transition. Put them in the observable, canonically. Write a witness that constructs two states differing only in a candidate variable and checks that the bytes differ. Scope the law to the observable it was ratified for; lifting it is a new claim.",
      "transformations": {
        "allowed": [
          "adding a variable to the observable when a witness shows it determines a future",
          "quotienting the observable by an equivariance that provably does not change futures"
        ],
        "refused": [
          "a variable outside the observable that changes a future transition (Invisible State)",
          "lifting the law to another observable without its own witness",
          "treating two lanes' standings as one"
        ]
      },
      "consequences": "Replay becomes exact and cache keys become correct, because the bytes are sufficient. The methodological consequence is the one this page is honest about: a law carries its domain.",
      "analogy": "A flight recorder that logs everything except the trim wheel. Two flights with identical recordings end differently, and the investigation cannot say why. Law 6 is the rule that the trim wheel goes in the recording.",
      "applicability": "Any system with a replay, a cache, a memoization key or a canonical serialization. Law 23 in the same file is the memoization corollary: the key must include every dimension the generator ranges over.",
      "syntax": [
        {
          "label": "Law 6, verbatim (TRVM/LAWS.md)",
          "path": "TRVM/LAWS.md",
          "start": "- **Statement:** *A canonical shared observable",
          "count": 3
        },
        {
          "label": "The enforcing witness in the forge binding run",
          "path": "TRVM/forge/binding_run3k.py",
          "start": "# ---- 16) Law 6 witness",
          "count": 3
        }
      ],
      "takeaways": [
        {
          "from": "animation",
          "text": "Same bytes, different futures: that is the whole violation, and the witness names the hidden variable."
        },
        {
          "from": "syntax",
          "text": "The law is stated for Film bytes; 'GLOBAL' means no longer horizon-scoped, not 'true of every observable'."
        },
        {
          "from": "literature",
          "text": "Nerode's quotient and the sufficient-statistic condition are the prior art; the frontier package says so and demotes the naked law to P1."
        },
        {
          "from": "witness",
          "text": "The witness is a results document from the forge; this page cannot re-run it, and the two lanes' standings are reported side by side."
        }
      ],
      "wrl": {
        "note": "The Spinner's rotor is the state Law 6 was first written for: it determines the Orb's pose and must be in the Film."
      },
      "up": "UP-007",
      "limit": "Two standings stand unresolved. TRVM/LAWS.md:80 ratifies Law 6 for Film bytes; the frontier package finds it too strong lifted to arbitrary observables. Neither standing is a result about shared observables in general, and the scope axis between them is a hypothesis.",
      "next_rung": "A ruling on the scope axis — for which class of observables the law holds. Until that ruling the pattern cites a law it cannot fully claim.",
      "derived": {
        "label": "WITNESSED",
        "CHECKABLE": true,
        "RUNNABLE": false,
        "EXECUTED": true,
        "STAGED": false,
        "REPRODUCED": false,
        "PUBLISHED": true,
        "next_rung_name": "live_local",
        "why": [
          {
            "ok": true,
            "text": "a witness is named"
          },
          {
            "ok": true,
            "text": "its evidence kind is one the ledger already uses (constructive_witness)"
          },
          {
            "ok": true,
            "text": "the witness path resolves in this tree"
          },
          {
            "ok": true,
            "text": "its rung is in_tree or above (in_tree)"
          },
          {
            "ok": true,
            "text": "a run is recorded for these exact bytes"
          },
          {
            "ok": true,
            "text": "no claim is cited that could be REFUTED"
          },
          {
            "ok": true,
            "text": "a counterexample is shipped (required once WITNESSED)"
          },
          {
            "ok": false,
            "text": "not staged on this site, so it cannot run from the page"
          }
        ],
        "related_closure": [
          "projection-not-duplication",
          "semantic-membrane"
        ],
        "live_run": null,
        "counterexample_strength": {
          "strength": "marker",
          "occurrences": 3,
          "law": null
        },
        "execution": {
          "at": "2026-07-22",
          "note": "the witness is itself an execution record"
        },
        "claim_statuses": [],
        "cell_statuses": []
      }
    },
    {
      "id": "semantic-membrane",
      "kind": "pattern",
      "name": "Semantic Membrane",
      "family": "composition",
      "invariant": "A composed subsystem exposes exactly the state that affects externally observable future behaviour and no more (the ADEQUACY half of shared-observable, quotiented by EQUIVARIANCE).",
      "cells": [],
      "claims": [],
      "witness": null,
      "prior_art": {
        "works": [
          {
            "work": "Parnas, information hiding (1972)",
            "relation": "antecedent",
            "overlap": "a boundary chosen so that what crosses it is the only thing that matters",
            "difference": "Parnas hides implementation decisions; a membrane is asked to hold under composition, not only under change"
          }
        ],
        "novelty_not_claimed": "The phrase 'semantic membrane' appears nowhere in the tree. It is PROPOSED by the book and has no witness; if it turns out to be Parnas with a new coat, that is the expected outcome, not a surprise.",
        "prose": "Parnas 1972 information hiding; the phrase 'semantic membrane' appears nowhere in the tree — PROPOSED by the book."
      },
      "realizations": [],
      "failure_mode": "invisible-state",
      "related": [
        "shared-observable"
      ],
      "scene": "semantic-membrane",
      "headline": "A composed subsystem exposes exactly the state that affects externally observable future behaviour — and no more.",
      "explanatory": "Shared Observable says what must cross a composition boundary: every variable that determines a future. This pattern is its other half: what must not cross. Exposing internal, behaviour-irrelevant state makes equivalent subsystems look different and breaks convergence. The membrane is adequacy quotiented by equivariance.",
      "technical": "Nowhere named in the tree — PROPOSED. Its nearest relative is the frontier package's adjudication of the observable-completeness law: 'as stated, too strong alone: carrying byte-level variables breaks convergence'; it survives only as the ADEQUACY/EQUIVARIANCE pair (invariant-r10/package-v2.8/v1-provenance/03_CANDIDATE_INVARIANTS.md). Parnas's information hiding is the ancestor.",
      "problem": "A subsystem that exposes everything is easy to write and impossible to compose: every caller couples to internals, every refactor is an interface change, and two implementations that behave identically are told apart by noise. A subsystem that exposes too little hides state that determines futures — Invisible State, the opposite failure.",
      "forces": "Deciding what is behaviour-relevant requires a model of the futures, which is exactly what a subsystem author does not want to commit to. Equivariance — the relation under which two internal states count as the same — has to be stated and, ideally, checked. The membrane is a claim about a quotient, and quotients are where proofs get hard.",
      "construction": "State the observable (Shared Observable). State the equivalence on internal states under which futures are identical. Expose the quotient, not the representative. Write a witness that constructs two internal states in the same class and checks that every exposed byte agrees.",
      "transformations": {
        "allowed": [
          "refactoring internals within an equivalence class",
          "widening the membrane when a new variable is shown to determine a future"
        ],
        "refused": [
          "exposing a representative where a quotient was meant",
          "hiding a variable that determines a future (Invisible State)"
        ]
      },
      "consequences": "Composition stops depending on internals and starts depending on declared behaviour. The honest status: this is the book proposing a name for one half of a law the tree has already adjudicated; nothing in the tree witnesses the membrane by that name.",
      "analogy": "A restaurant's menu is a membrane: what you can order is exposed, the kitchen's shelf layout is not, and two kitchens with different layouts and the same menu are the same restaurant to a diner.",
      "applicability": "Module and service boundaries, agent-to-agent interfaces, world serializations — anywhere two implementations must be interchangeable behind one boundary.",
      "syntax": [
        {
          "label": "Where the tree says the naked law is too strong (frontier package X-1)",
          "path": "invariant-r10/package-v2.8/v1-provenance/03_CANDIDATE_INVARIANTS.md",
          "start": "Too strong alone",
          "count": 1
        }
      ],
      "takeaways": [
        {
          "from": "animation",
          "text": "Exposing y determined the futures; exposing x too made equivalent subsystems look different."
        },
        {
          "from": "syntax",
          "text": "The frontier package keeps the law only as an ADEQUACY / EQUIVARIANCE pair — this pattern is the second word."
        },
        {
          "from": "literature",
          "text": "Parnas 1972: a module hides a design decision. The membrane hides what does not determine a future."
        },
        {
          "from": "witness",
          "text": "PROPOSED: no witness, no counterexample, and the label derives to say so."
        }
      ],
      "wrl": {
        "note": "No core-role encoding; the membrane is a quotient on state, not a route."
      },
      "up": "UP-008",
      "limit": "PROPOSED. The phrase appears nowhere in the tree, there is no check, and no system here is known to implement one. It establishes nothing.",
      "next_rung": "in_tree: any check that could distinguish a membrane from a boundary that merely happens not to leak today.",
      "derived": {
        "label": "PROPOSED",
        "CHECKABLE": false,
        "RUNNABLE": false,
        "EXECUTED": false,
        "STAGED": false,
        "REPRODUCED": false,
        "PUBLISHED": true,
        "next_rung_name": "in_tree",
        "why": [
          {
            "ok": false,
            "text": "a witness is named"
          },
          {
            "ok": false,
            "text": "its evidence kind is one the ledger already uses"
          },
          {
            "ok": false,
            "text": "the witness path resolves in this tree"
          },
          {
            "ok": false,
            "text": "its rung is in_tree or above"
          },
          {
            "ok": false,
            "text": "a run is recorded for these exact bytes"
          },
          {
            "ok": true,
            "text": "no claim is cited that could be REFUTED"
          },
          {
            "ok": false,
            "text": "a counterexample is shipped (required once WITNESSED)"
          },
          {
            "ok": false,
            "text": "not staged on this site, so it cannot run from the page"
          }
        ],
        "related_closure": [
          "shared-observable"
        ],
        "live_run": null,
        "counterexample_strength": null,
        "execution": null,
        "claim_statuses": [],
        "cell_statuses": []
      }
    },
    {
      "id": "capability-bounded-composition",
      "kind": "pattern",
      "name": "Capability-Bounded Composition",
      "family": "composition",
      "invariant": "An action is admissible only if it is feasible AND permitted under an explicit grant; feasibility never implies permission, and the safety floor cannot be weakened by composition.",
      "cells": [
        {
          "ref": "16",
          "modality": "necessary"
        }
      ],
      "claims": [],
      "witness": {
        "registry": "box-and-box",
        "repo": "AmpersandBoxDesign",
        "path": "AmpersandBoxDesign/box-and-box/test/laws.mjs",
        "shape": "suite",
        "evidence_kind": "constructive_witness",
        "rung": "live_deployed",
        "rung_source": "A live-run receipt: the staged kernel suite ran from https://opensentience.org/patterns/capability-bounded-composition and reported 109 laws · 109 passing · 0 failing, bound to staged stamp 51ffdf3aa3658f18. Recorded by _patterns/build/run-live.mjs; derived by build.mjs (P26).",
        "cmd": "node test/laws.mjs",
        "cwd": "AmpersandBoxDesign/box-and-box",
        "staged": true,
        "staged_path": "opensentience.org/witness/src/AmpersandBoxDesign/box-and-box/test/laws.mjs"
      },
      "counterexample": {
        "shape": "refusal",
        "path": "AmpersandBoxDesign/box-and-box/test/laws.mjs",
        "marker": "chain refuses a backward phase",
        "law": "L10",
        "expected": "REFUSED",
        "note": "The marker here was 'should refuse' until 2026-09-13. That is the string L10 RETURNS WHEN IT FAILS — a law's failure tag, cited as evidence that the law holds. It is the same defect v0.4 shipped on Refusing Join (CD2's failure string used as CD1's marker), and it survived undetected because this record carried no law id and so never reached the check that exists for it. The marker is now L10's own statement, on L10's own declaration line."
      },
      "prior_art": {
        "works": [
          {
            "work": "Dennis & Van Horn (1966)",
            "relation": "antecedent",
            "overlap": "authority carried by an unforgeable reference",
            "difference": "none claimed"
          },
          {
            "work": "Miller, Capability Myths Demolished (2003) — 'ambient authority'",
            "relation": "terminology-precedent",
            "overlap": "the term for authority available without being passed",
            "difference": "the term is Miller's and is used here as he defined it"
          },
          {
            "work": "Object-capability discipline",
            "relation": "antecedent",
            "overlap": "participation conveys only what was granted",
            "difference": "applied here to composition of assemblies rather than to object references"
          }
        ],
        "novelty_not_claimed": "This is object-capability discipline. No part of the principle is claimed as new; the contribution, if any, is that it is stated as a composition law with a deny-by-default cell (16) beneath it.",
        "prose": "Object-capability discipline; 'ambient authority' is Mark S. Miller's term (Capability Myths Demolished, 2003); Dennis & Van Horn 1966."
      },
      "realizations": [
        "opensentience.org/box-and-box/README.md deontic rung",
        "opensentience.org/deontic-arithmetic.html"
      ],
      "failure_mode": "ambient-authority",
      "related": [
        "carrier-confinement",
        "state-does-not-grant-authority"
      ],
      "scene": "capability-bounded-composition",
      "headline": "Feasible, then permitted, then best — over a floor that composition cannot weaken.",
      "explanatory": "An action may be possible and still not allowed. The governance kernel separates the two as rungs: the alethic rung says what can happen, the deontic rung says what may, and only then does the axiological gradient rank what is best. Deny is the default, grants are explicit and scoped, and composing two governed things never widens what either could do alone.",
      "technical": "box-and-box, the [&] governance kernel: eight rungs, one bridge running feasible ▸ permitted ▸ best over an un-weakenable safety floor, a certificate on every verdict. 109 enforced kernel laws property-tested at 2000 trials (the suite derives its own total). Cell 16 (⊥ deny default) is proved at the impl tier. Carrier Confinement is the same rule at the OS boundary.",
      "problem": "Ambient authority: a component needs one capability and is handed the environment. Unix permissions, process-wide credentials, an agent with the operator's whole token. Every composition then inherits everything, and the question 'may this proceed?' has no place to be asked.",
      "forces": "Explicit grants are more to write and easier to forget, so the default matters: deny. The floor must survive composition, which means the compose laws have to be property-tested rather than trusted. And the gradient (best) must never be consulted before the floor (permitted), or optimization quietly becomes authorization.",
      "construction": "Model authority as a distinct rung with its own laws, not a flag on an action. Make deny the identity for the permission operator. Compose by meet on the floor and by the declared operator above it. Attach a certificate to every verdict so a receiver can check the chain rather than the answer.",
      "transformations": {
        "allowed": [
          "narrowing a grant's scope",
          "composing two governed bricks (the floor is the meet)",
          "escalating an unmet obligation back to the deontic rung (ought-implies-can)"
        ],
        "refused": [
          "widening authority by composition",
          "consulting the gradient before the floor",
          "granting the environment when one capability is needed (Ambient Authority)"
        ]
      },
      "consequences": "'May this proceed, and is it best?' becomes arithmetic with a certificate attached. The cost is the explicit grant, every time; the benefit is that the answer is checkable by someone who did not make it.",
      "analogy": "A theatre with a locked stage door. Being able to climb the wall (feasible) is not a ticket (permitted), and the best seat in the house (best) is only a question once you are inside.",
      "applicability": "Agent runtimes, plugin systems, multi-tenant services, operating-system carriers, any place where 'can' has been standing in for 'may'.",
      "syntax": [
        {
          "label": "The bridge, in the kernel's own words (box-and-box README)",
          "path": "opensentience.org/box-and-box/README.md",
          "start": "feasible ▸ permitted ▸ best",
          "count": 1
        },
        {
          "label": "L10 — a backward phase is refused; L14 — deny_default is idempotent under ∧ (from the suite this page runs)",
          "path": "AmpersandBoxDesign/box-and-box/test/laws.mjs",
          "start": "['L10', 'chain refuses a backward phase'",
          "count": 4
        }
      ],
      "takeaways": [
        {
          "from": "animation",
          "text": "The same action was refused without a grant and admitted with one; feasibility never moved."
        },
        {
          "from": "syntax",
          "text": "deny_default is idempotent under ∧ — composition cannot manufacture permission."
        },
        {
          "from": "literature",
          "text": "Object-capability discipline; 'ambient authority' is Mark S. Miller's term (Capability Myths Demolished)."
        },
        {
          "from": "witness",
          "text": "109 kernel laws × 2000 trials ran on this page, on the same bytes CI runs."
        }
      ],
      "wrl": {
        "refused": "capability-bounded-composition.refused.wrl",
        "note": "The Door is the permitted rung. A signal driven into a pose port is feasible to type and refused by the port table."
      },
      "up": "UP-009",
      "limit": "Cell 16 (deny by default) is proved at the impl tier, which makes the floor real. It does not establish that any composition in this tree grants only what it needs — the cell is the floor, not the pattern.",
      "next_rung": "external — the deny-by-default floor (cell 16) checked by someone who did not write it. The suite runs live here and that is this tree checking its own kernel.",
      "derived": {
        "label": "WITNESSED",
        "CHECKABLE": true,
        "RUNNABLE": true,
        "EXECUTED": true,
        "STAGED": true,
        "REPRODUCED": false,
        "PUBLISHED": true,
        "next_rung_name": "external",
        "why": [
          {
            "ok": true,
            "text": "a witness is named"
          },
          {
            "ok": true,
            "text": "its evidence kind is one the ledger already uses (constructive_witness)"
          },
          {
            "ok": true,
            "text": "the witness path resolves in this tree"
          },
          {
            "ok": true,
            "text": "its rung is in_tree or above (live_deployed)"
          },
          {
            "ok": true,
            "text": "a run is recorded for these exact bytes"
          },
          {
            "ok": true,
            "text": "no claim is cited that could be REFUTED"
          },
          {
            "ok": true,
            "text": "a counterexample is shipped (required once WITNESSED)"
          },
          {
            "ok": true,
            "text": "it has run from the deployed site — 109 laws · 109 passing · 0 failing · 336.4 ms"
          }
        ],
        "related_closure": [
          "carrier-confinement",
          "refusing-join",
          "state-does-not-grant-authority"
        ],
        "live_run": {
          "at": "2026-09-12T00:02:41.726Z",
          "url": "https://opensentience.org/patterns/capability-bounded-composition",
          "status": "109 laws · 109 passing · 0 failing · 336.4 ms",
          "stamp": "51ffdf3aa3658f18"
        },
        "counterexample_strength": {
          "strength": "scoped",
          "occurrences": 1,
          "law": "L10"
        },
        "execution": {
          "at": "2026-09-11T15:26:16.294Z",
          "host": "PX13",
          "sha256": "51ffdf3aa3658f1858bae427772f4f776140c3539c2347d0fb847aea2d13c22d",
          "repo_head": "e41e5fab63c19a3671bf417a6949e10a27782830"
        },
        "claim_statuses": [],
        "cell_statuses": [
          {
            "num": "16",
            "modality": "necessary",
            "status": "proved"
          }
        ]
      }
    },
    {
      "id": "carrier-confinement",
      "kind": "pattern",
      "name": "Carrier Confinement",
      "family": "composition",
      "invariant": "A Carrier is started with exactly the filesystem and descriptor authority its Worker's grant names; the descriptor seal is CLOSE_RANGE_CLOEXEC, never a blind close.",
      "cells": [],
      "claims": [],
      "witness": null,
      "prior_art": {
        "works": [
          {
            "work": "Landlock",
            "relation": "realization",
            "overlap": "a process restricts its own filesystem authority irreversibly",
            "difference": "ABI 9 on this host, not 10 — the number was measured and corrected (super/docs/reviews/D_1_3B_2F.md)"
          },
          {
            "work": "Capsicum",
            "relation": "close-analogue",
            "overlap": "capability-mode confinement of a running process",
            "difference": "FreeBSD's design reaches it by removing the global namespace rather than by layering rules"
          },
          {
            "work": "The E language's confinement",
            "relation": "antecedent",
            "overlap": "a subject cannot exceed the authority it was given",
            "difference": "E enforces it in the language; here it is enforced by the kernel under the language"
          }
        ],
        "novelty_not_claimed": "Confinement is a solved problem with multiple shipped implementations. The witness lives in super/, a lane this session does not edit — it is referenced, not copied, and the reference is not a claim of authorship.",
        "prose": "Landlock (ABI 10 on this host per super/docs/reviews/D_1_3B_2F.md:114); Capsicum; the E language's confinement. Witness lives in super/, a lane this session does not edit — referenced, not copied."
      },
      "realizations": [
        "super/docs/reviews/D_1_3B_2F.md:114"
      ],
      "failure_mode": "ambient-authority",
      "related": [
        "capability-bounded-composition"
      ],
      "scene": "carrier-confinement",
      "headline": "A Carrier starts with exactly the filesystem and descriptor authority its Worker's grant names.",
      "explanatory": "Capability-Bounded Composition at the operating-system boundary. Before a Carrier's payload runs, its filesystem view is restricted to the directories the grant names and every inherited descriptor beyond the allowlist is sealed. Sealing is done with a range close-on-exec, never a blind close, because a blind close leaves a duplicated master in the census.",
      "technical": "Super D.1.3b floor: Landlock (ABI 10 on this host per super/docs/reviews/D_1_3B_2F.md), the descriptor seal is CLOSE_RANGE_CLOEXEC; the refusal token carrier-confinement-unacceptable. Measured findings recorded in that lane: a same-UID battery measures yama unless it carries a bare control; static-link or grant all of /usr/lib; the ruleset fd collides with the allowlist. The witness lives in super/, which this book references and never copies.",
      "problem": "A worker needs to write one directory and gets the parent's whole environment: every open file, every socket, the whole filesystem. The grant it was started under is then decoration. Every escape story starts here.",
      "forces": "Confinement must happen before the payload runs and after the runtime has what it needs, and the two windows barely overlap. Dynamic linking needs /usr/lib; a ruleset lives in a descriptor that could itself be swept by the seal. And a battery that shares a UID with its subject measures the wrong enforcement layer unless it carries a control that would fail.",
      "construction": "Build the ruleset from the grant, not from the environment. Apply it before exec. Seal descriptors by range with close-on-exec so the census can prove the seal. Run a red control: a Carrier that should be refused, and is.",
      "transformations": {
        "allowed": [
          "narrowing the ruleset",
          "adding a read-only directory the grant names",
          "re-measuring on a host with a different ABI"
        ],
        "refused": [
          "inheriting the parent's descriptors by default",
          "a blind close in place of the seal",
          "a battery without a bare control"
        ]
      },
      "consequences": "A Carrier's authority becomes a fact about its start, checkable from the outside. The honest status here: STATED — the receipts are in another lane, and this page cannot run them.",
      "analogy": "A contractor given keys to one room, with the rest of the building's keys removed from the ring before they walk in — and a locksmith who checks the ring, not the contractor's promise.",
      "applicability": "Any process that runs on behalf of a grant: agent workers, plugin hosts, build sandboxes, the T&R shell's native apps.",
      "syntax": [
        {
          "label": "The refusal token, in the review that measured it (super/docs)",
          "path": "super/docs/reviews/D_1_3B_2F.md",
          "start": "carrier-confinement-unacceptable",
          "count": 1
        }
      ],
      "takeaways": [
        {
          "from": "animation",
          "text": "The request with everything was refused; the same request with a ruleset and a seal started, confined."
        },
        {
          "from": "syntax",
          "text": "The refusal is a named token, not a crash; the seal is a range close-on-exec."
        },
        {
          "from": "literature",
          "text": "Landlock, Capsicum and the E language's confinement; Miller's ambient authority is the thing being removed."
        },
        {
          "from": "witness",
          "text": "STATED: the witness is a review document in super/, referenced by path and never copied; ABI 10 on this host."
        }
      ],
      "wrl": {
        "note": "No core-role encoding: confinement is an OS-boundary property."
      },
      "up": "UP-010",
      "limit": "Landlock ABI 9 on one host, in one lane (super/) this session does not edit. It establishes confinement for that carrier on that kernel. It does not establish confinement on any other kernel, and a same-UID battery measures yama unless a bare control runs beside it.",
      "next_rung": "in_tree: the battery referenced here lives in super/, a lane this session does not edit, so this catalog has no witness of its own to run. Copying it in with a receipt is the step. Running it on a kernel nobody in this tree configured is the step above that, and it is the one that would count.",
      "derived": {
        "label": "STATED",
        "CHECKABLE": false,
        "RUNNABLE": false,
        "EXECUTED": false,
        "STAGED": false,
        "REPRODUCED": false,
        "PUBLISHED": true,
        "next_rung_name": "in_tree",
        "why": [
          {
            "ok": false,
            "text": "a witness is named"
          },
          {
            "ok": false,
            "text": "its evidence kind is one the ledger already uses"
          },
          {
            "ok": false,
            "text": "the witness path resolves in this tree"
          },
          {
            "ok": false,
            "text": "its rung is in_tree or above"
          },
          {
            "ok": false,
            "text": "a run is recorded for these exact bytes"
          },
          {
            "ok": true,
            "text": "no claim is cited that could be REFUTED"
          },
          {
            "ok": false,
            "text": "a counterexample is shipped (required once WITNESSED)"
          },
          {
            "ok": false,
            "text": "not staged on this site, so it cannot run from the page"
          }
        ],
        "related_closure": [
          "capability-bounded-composition"
        ],
        "live_run": null,
        "counterexample_strength": null,
        "execution": null,
        "claim_statuses": [],
        "cell_statuses": []
      }
    },
    {
      "id": "projection-not-duplication",
      "kind": "pattern",
      "name": "Projection, Not Duplication",
      "family": "composition",
      "invariant": "Every view of a semantic artifact is derived from it by a declared, recomputable projection; a receiver recomputes the claims on the wire rather than trusting flags or prose.",
      "cells": [],
      "claims": [],
      "witness": {
        "registry": "graphonomous",
        "repo": "graphonomous",
        "path": "graphonomous/v2/test/projection_v1.test.mjs",
        "shape": "side-effect",
        "evidence_kind": "constructive_witness",
        "rung": "in_tree",
        "rung_source": "graphonomous/v2/handoff/STATUS.md:113 — TESTED, 15 tests over eleven laws",
        "cmd": "node test/projection_v1.test.mjs",
        "cwd": "graphonomous/v2",
        "staged": false
      },
      "counterexample": {
        "shape": "refusal",
        "path": "graphonomous/v2/test/projection_v1.test.mjs",
        "marker": "does not hold",
        "expected": "REFUSED"
      },
      "prior_art": {
        "works": [
          {
            "work": "CQRS read models; materialized views",
            "relation": "antecedent",
            "overlap": "many views derived from one authority",
            "difference": "CQRS permits a read model to drift and reconcile; this pattern refuses a second authority outright"
          },
          {
            "work": "Unison's hash-addressed definitions",
            "relation": "close-analogue",
            "overlap": "derivations cannot disagree about what they derive from",
            "difference": "Unison gets it from naming; this gets it from a projection rule"
          }
        ],
        "novelty_not_claimed": "Derived views are ubiquitous. The narrow claim is about authority, not about caching.",
        "prose": "CQRS read models; materialized views; Unison's hash-addressed definitions."
      },
      "realizations": [
        "WRL/HANDOFF_D8_PATH_B.md §D8.18-D8.19",
        "graphonomous/v2/contracts/projection.v1.json"
      ],
      "failure_mode": "replica-theater",
      "related": [
        "refusable-divergence",
        "shared-observable"
      ],
      "scene": "projection-not-duplication",
      "headline": "Every view of an artifact is derived from it by a declared, recomputable function.",
      "explanatory": "A view is a projection, not a second copy that pretends to be authoritative. Two viewers agree because each derived the view from the artifact, not because they trusted each other. A copy that was edited since it was taken is a replica, and a receiver that cannot derive it refuses it.",
      "technical": "WRL §D8.18/§D8.19: deriveRuntimeProjection makes the V1→V2 downgrade in-band, and the projection on the wire carries only claims a receiver recomputes. Graphonomous projection-v1: eleven acceptance laws over schema_closure_id + projection_contract_id, so a projection's certificate closes over the schemas it actually used rather than every schema in the checkout — growing the vocabulary no longer re-mints frozen projections (the v0 defect D-068 fixed). 15 tests, five golden vectors.",
      "problem": "v0 hashed every schema file in the checkout into every projection's identity. Adding a schema re-minted the certificates of frozen projections whose records had not moved. Identity that closes over the wrong set is duplication wearing a hash.",
      "forces": "Derivation costs recomputation on every read, which is exactly the cost a replica avoids — and the reason replicas drift. The closure a projection's identity depends on must be neither too wide (every schema) nor too narrow (none); it is derived from the adapter runs that produced it, through a trusted contract.",
      "construction": "Declare the projection function and its contract. Derive the schema closure from what the projection actually consumed. Put the closure id and contract id in the certificate. Have every consumer recompute the projection from the artifact and refuse anything it cannot derive.",
      "transformations": {
        "allowed": [
          "adding a projection",
          "re-deriving after the artifact changes",
          "downgrading a projection in-band so the receiver sees the downgrade as a claim"
        ],
        "refused": [
          "a copy presented as the artifact (Replica Theater)",
          "an identity that closes over inputs the projection did not use",
          "a flag that says 'this is current' instead of a recomputation"
        ]
      },
      "consequences": "Views can multiply without becoming sources of truth. The methodological consequence is law 4 of projection-v1, measured in both of its readings, with the second found not to hold — the test says so, and D-072 records it.",
      "analogy": "Two accountants each recompute the quarter from the ledger. A third brings last month's spreadsheet with edits. The first two agree; the third is not a view of anything.",
      "applicability": "Read models, dashboards, exports, search indexes, semantic graphs over a corpus — anything that presents an artifact from another angle.",
      "syntax": [
        {
          "label": "Why v1 exists — the test file's own header",
          "path": "graphonomous/v2/test/projection_v1.test.mjs",
          "start": "The subject is one coordinate",
          "count": 4
        },
        {
          "label": "The projection on the wire (WRL relation-v2.js)",
          "path": "WRL/relation-v2.js",
          "start": "export async function deriveRuntimeProjection",
          "count": 6
        }
      ],
      "takeaways": [
        {
          "from": "animation",
          "text": "Two views agreed by derivation; the replica was refused because nothing could derive it."
        },
        {
          "from": "syntax",
          "text": "A projection's identity closes over the schemas it consumed — schema_closure_id — not the checkout."
        },
        {
          "from": "literature",
          "text": "CQRS read models and materialized views are the ancestry; the contribution is the closure id in the certificate."
        },
        {
          "from": "witness",
          "text": "15 tests over eleven laws ran today with a receipt; law 4's second reading fails and the test says so."
        }
      ],
      "wrl": {
        "note": "The Orb's pose is derived from the Spinner through a SocketControl edge — a projection, not a copy."
      },
      "up": "UP-011",
      "limit": "States that derived views may not become rival authorities. Nothing here checks that any view in the tree is derived rather than maintained; the WRL world for this chapter is sealed, and a sealed topology is not an authority audit.",
      "next_rung": "live_local: a check on this page that walks a projection back to its source and refuses one that has drifted. The WRL world for this chapter seals, and a sealed topology is not an authority audit.",
      "derived": {
        "label": "WITNESSED",
        "CHECKABLE": true,
        "RUNNABLE": true,
        "EXECUTED": true,
        "STAGED": false,
        "REPRODUCED": false,
        "PUBLISHED": true,
        "next_rung_name": "live_local",
        "why": [
          {
            "ok": true,
            "text": "a witness is named"
          },
          {
            "ok": true,
            "text": "its evidence kind is one the ledger already uses (constructive_witness)"
          },
          {
            "ok": true,
            "text": "the witness path resolves in this tree"
          },
          {
            "ok": true,
            "text": "its rung is in_tree or above (in_tree)"
          },
          {
            "ok": true,
            "text": "a run is recorded for these exact bytes"
          },
          {
            "ok": true,
            "text": "no claim is cited that could be REFUTED"
          },
          {
            "ok": true,
            "text": "a counterexample is shipped (required once WITNESSED)"
          },
          {
            "ok": false,
            "text": "not staged on this site, so it cannot run from the page"
          }
        ],
        "related_closure": [
          "refusable-divergence",
          "shared-observable"
        ],
        "live_run": null,
        "counterexample_strength": {
          "strength": "marker",
          "occurrences": 1,
          "law": null
        },
        "execution": {
          "at": "2026-09-11T15:26:17.256Z",
          "host": "PX13",
          "sha256": "957b52a20a403381ee112cba83c4167cb01b62e3ef3910472eeb2c59b9f49699",
          "repo_head": "61adec2d548408589372d4321da0cd96257bb230"
        },
        "claim_statuses": [],
        "cell_statuses": []
      }
    },
    {
      "id": "refusable-divergence",
      "kind": "pattern",
      "name": "Refusable Divergence",
      "family": "composition",
      "invariant": "An implementation divergence between two verifiers of the same artifact is refused by name rather than passing silently: no flags, no prose, only claims a receiver recomputes.",
      "cells": [],
      "claims": [],
      "witness": {
        "registry": "wrl",
        "repo": "WRL",
        "path": "WRL/test/conformance.mjs",
        "shape": "side-effect",
        "evidence_kind": "constructive_witness",
        "rung": "in_tree",
        "rung_source": "STACK_COMPLETION.md:73; two verifiers in two languages (WRL js, TRVM Forge python)",
        "cmd": "node test/conformance.mjs",
        "cwd": "WRL",
        "staged": false
      },
      "counterexample": {
        "shape": "fixture",
        "path": "WRL/test/projection-negative-vectors.json",
        "expected": "REFUSED",
        "expected_count": 15
      },
      "prior_art": {
        "works": [
          {
            "work": "Content addressing; Nix",
            "relation": "antecedent",
            "overlap": "divergence is detectable because names are derived from content",
            "difference": "detection is the antecedent; agreeing on the NAME of the refusal is the part under test"
          },
          {
            "work": "WRL/PACKET_README.md:109 — 'refused by BOTH sides'",
            "relation": "partial-overlap",
            "overlap": "the tree's own wording for the two-sided requirement",
            "difference": "WRL/HANDOFF_D8_PATH_B.md:1424 warns that two refusals can both be drift; two-sidedness is necessary, not sufficient"
          }
        ],
        "novelty_not_claimed": "Detecting divergence by hash is standard. 'Agree on the name of every refusal' is STACK_COMPLETION.md:73's wording and is NOT verified by this build.",
        "prose": "Content addressing; Nix; 'refused by BOTH sides' is WRL/PACKET_README.md:109's wording; 'agree on the name of every refusal' is STACK_COMPLETION.md:73's and is not verified by this build. WRL/HANDOFF_D8_PATH_B.md:1424 warns that two refusals can both be drift."
      },
      "realizations": [
        "WRL/relation-v2.js:2363 deriveRuntimeProjection"
      ],
      "failure_mode": "replica-theater",
      "related": [
        "identity-is-a-seal",
        "meaning-is-a-hash",
        "projection-not-duplication"
      ],
      "scene": "refusable-divergence",
      "headline": "A divergence between two implementations is refused by name, not passed in silence.",
      "explanatory": "Put only claims on the wire — no flags, no prose. Every receiver recomputes the claims from the bytes. Two verifiers in two languages then either agree or refuse, and a refusal names what it refused. A negative corpus of tampered records is part of the artifact, so 'refuses' is something you can run.",
      "technical": "WRL §D8.19, the projection on the wire. deriveRuntimeProjection makes the V1→V2 downgrade in-band. Conformance: 924 checks passing today (STACK_COMPLETION recorded 890 in August). Negative corpus: 15 tampered records stored as final bytes, refused by both verifiers; a consumer must check the wire differs from its base before trusting a refusal, and whether refusal codes are normative is an open question the corpus states itself.",
      "problem": "Two implementations of one format drift. The usual defence is a version flag and a prose note, and both are things a receiver is asked to believe. When the implementations disagree, the disagreement passes silently and shows up later as data that two systems read differently.",
      "forces": "Recomputing claims costs a receiver work it could skip by trusting a flag. A negative corpus is only evidence if each tamper actually differs from its base — a recipe that matches nothing is a fixture that passes while asserting nothing. And two refusals can both be drift: agreement on a refusal is weaker than agreement on the bytes.",
      "construction": "Seal the artifact (Meaning Is a Hash). Put the recomputable claims on the wire and nothing else. Keep a negative corpus as final bytes beside the positive vectors. Run two independent verifiers and require both to refuse every tamper; report code disagreement separately from the refusal.",
      "transformations": {
        "allowed": [
          "adding a verifier in a third language",
          "adding a tamper to the corpus (with its base named)",
          "downgrading a projection in-band, so the receiver sees the downgrade as a claim"
        ],
        "refused": [
          "a flag or a prose note that a receiver is asked to trust",
          "a fixture that is an edit recipe rather than final bytes",
          "collapsing two refusals into one because they agree"
        ]
      },
      "consequences": "Interoperability becomes a property with a witness: two repos, two languages, one corpus. The remaining honesty is in the corpus's own note — code normativity is open — and in WRL's handoff warning that two implementations can both have drifted.",
      "analogy": "Two auditors who each recompute the total from the receipts rather than reading the number at the bottom of the page. If the page lies, both say so, and each says which line.",
      "applicability": "Any format with more than one implementation: wire protocols, certificate formats, manifests, the projection vectors between WRL and TRVM Forge. Not for a single implementation that can only agree with itself.",
      "syntax": [
        {
          "label": "The first tamper in the negative corpus — the record lies about its own world id",
          "path": "WRL/test/projection-negative-vectors.json",
          "start": "   \"name\": \"a-lying-semantic-world-id\"",
          "count": 3
        },
        {
          "label": "The corpus's own rule for consumers (verbatim from the fixture's note)",
          "path": "WRL/test/projection-negative-vectors.json",
          "start": " \"note\":",
          "count": 1
        }
      ],
      "takeaways": [
        {
          "from": "animation",
          "text": "A tampered record is refused by both verifiers, and each names what it refused."
        },
        {
          "from": "syntax",
          "text": "Tampers are stored as final bytes, not edit recipes, because a recipe that matches nothing passes while asserting nothing."
        },
        {
          "from": "literature",
          "text": "Content addressing (Merkle, Nix) makes the seal; the contribution here is the refusal name on the wire and the shared negative corpus across two implementations."
        },
        {
          "from": "witness",
          "text": "924 conformance checks ran today; this page cannot run them yet (the suite is not staged), and says so under Witness."
        }
      ],
      "wrl": {
        "refused": "refusable-divergence.refused.wrl",
        "note": "A world that routes a signal out of a Door is refused with a code and a locator, not a warning."
      },
      "up": "UP-012",
      "limit": "WRL's conformance suite passes; the 'agree on the name of every refusal' half is STACK_COMPLETION.md:73's wording and is NOT verified by this build. WRL/HANDOFF_D8_PATH_B.md:1424 warns that two refusals can both be drift — two-sidedness is necessary and not sufficient.",
      "next_rung": "live_local: the WRL playground has no negative corpus, so no tamper can be refused in a browser today. Staging one is the work.",
      "derived": {
        "label": "WITNESSED",
        "CHECKABLE": true,
        "RUNNABLE": true,
        "EXECUTED": true,
        "STAGED": false,
        "REPRODUCED": false,
        "PUBLISHED": true,
        "next_rung_name": "live_local",
        "why": [
          {
            "ok": true,
            "text": "a witness is named"
          },
          {
            "ok": true,
            "text": "its evidence kind is one the ledger already uses (constructive_witness)"
          },
          {
            "ok": true,
            "text": "the witness path resolves in this tree"
          },
          {
            "ok": true,
            "text": "its rung is in_tree or above (in_tree)"
          },
          {
            "ok": true,
            "text": "a run is recorded for these exact bytes"
          },
          {
            "ok": true,
            "text": "no claim is cited that could be REFUTED"
          },
          {
            "ok": true,
            "text": "a counterexample is shipped (required once WITNESSED)"
          },
          {
            "ok": false,
            "text": "not staged on this site, so it cannot run from the page"
          }
        ],
        "related_closure": [
          "identity-is-a-seal",
          "meaning-is-a-hash",
          "projection-not-duplication"
        ],
        "live_run": null,
        "counterexample_strength": null,
        "execution": {
          "at": "2026-09-11T15:25:45.285Z",
          "host": "PX13",
          "sha256": "e1f1e313eefe0001dc23d95da90011a36596924915d185ce6b1171219ef1925c",
          "repo_head": "32160fec77a13ad152176fed3001b0afbdebee42"
        },
        "claim_statuses": [],
        "cell_statuses": []
      }
    },
    {
      "id": "progress-over-utilization",
      "kind": "pattern",
      "name": "Progress Over Utilization",
      "family": "progress",
      "invariant": "System health is measured by admitted semantic transitions per unit cost, never by carrier busyness; a Carrier may be fully busy while the loci it carries make no progress.",
      "cells": [],
      "claims": [],
      "claims_related": [
        "FAC-PROGRESS"
      ],
      "witness": {
        "registry": "computedriven",
        "repo": "computedriven",
        "path": "computedriven/receipts/R7-EXECUTED.md",
        "shape": "receipt",
        "evidence_kind": "measurement",
        "rung": "in_tree",
        "rung_source": "R7-EXECUTED.md header: battery receipt R7-BATTERY-20260905T172007Z from a clean tree; 'the busiest Carrier is the one making the least progress'",
        "staged": false,
        "receipt_at": "2026-09-05"
      },
      "counterexample": {
        "shape": "receipt",
        "path": "computedriven/receipts/R7-EXECUTED.md",
        "marker": "fair arm",
        "expected": "REFUSED"
      },
      "prior_art": {
        "works": [
          {
            "work": "Erlang reductions as the scheduling unit",
            "relation": "realization",
            "overlap": "schedule by work performed, not by time occupied",
            "difference": "reductions are a fairness device; the pattern asks for progress to be the reported quantity too"
          },
          {
            "work": "Little's law; utilization vs throughput in queueing theory",
            "relation": "antecedent",
            "overlap": "utilization is a poor proxy for useful work",
            "difference": "queueing theory proves the relation; the pattern is about which number a system exposes"
          }
        ],
        "novelty_not_claimed": "Queueing theory has said this since the 1960s. computedriven/docs/progress-model.md is a MODEL — its own header says 'never a measurement' — and is not this witness.",
        "prose": "Erlang reductions as the scheduling unit; Little's law; the utilization-vs-throughput distinction in queueing theory. computedriven/docs/progress-model.md is a MODEL (its header: 'never a measurement') and is not this witness."
      },
      "realizations": [
        "computedriven/docs/progress-model.md",
        "computedriven/receipts/KERNELLET-R1.md:33"
      ],
      "failure_mode": "busywork-scheduling",
      "related": [
        "carrier-multiplexing",
        "dormant-but-alive"
      ],
      "scene": "progress-over-utilization",
      "headline": "Measure admitted transitions per cost, never carrier busyness.",
      "explanatory": "Utilization is a fact about carriers. Progress is a fact about loci. A carrier can be fully busy relocating loci for fairness while nothing is admitted. R7's first executed pass found exactly that: the busiest carrier was the one making the least progress.",
      "technical": "Unit: instructions per admitted transition (the receipts' unit). The progress floor profile (commit 684aad3) and the multiplexer battery (cff8a3d) compare a progress arm against fair arms; the fair arms spend most of their commands relocating. computedriven/docs/progress-model.md defines the terms and says of itself: every numeral is a definition or a prediction, never a measurement.",
      "problem": "Every dashboard shows CPU %. Schedulers optimize fairness among runnable threads. Both measure the carrier. A system can run at 100 % and admit nothing, and the metrics will call it healthy.",
      "forces": "Progress needs a definition before it can be counted — an admitted semantic transition — and a definition is a commitment the model document has to make ahead of the receipt. Fairness is a real value; starving a locus forever is not progress either. The pattern does not say ignore fairness; it says do not mistake it for the goal.",
      "construction": "Define the unit (admitted transition), instrument it at the floor, and report it per cost. Keep utilization as a diagnostic, never as the health signal. Run a fair arm beside the progress arm so the comparison is measured, not argued.",
      "transformations": {
        "allowed": [
          "lowering utilization while raising admitted transitions",
          "re-placing loci to where progress is possible (Progress-Aware Placement)"
        ],
        "refused": [
          "reporting utilization as health",
          "scheduling work that admits nothing to keep a carrier busy (Busywork Scheduling)",
          "quoting a model document's number as a measurement"
        ]
      },
      "consequences": "The health question moves from the carrier to the loci, which is where the semantics are. It also makes the next pattern possible: placement can be chosen for progress only once progress is what is measured.",
      "analogy": "A kitchen where every cook is moving constantly and no plates leave the pass. The manager who counts moving cooks sees a busy kitchen; the one who counts plates sees the problem.",
      "applicability": "Schedulers, agent runtimes, benchmark harnesses, anything with a dashboard. Especially where a fairness policy already exists and has never been measured against what it admitted.",
      "syntax": [
        {
          "label": "The receipt's own title line",
          "path": "computedriven/receipts/R7-EXECUTED.md",
          "start": "# R7 — EXECUTED",
          "count": 1
        },
        {
          "label": "Where the fair arms spent their commands",
          "path": "computedriven/receipts/R7-EXECUTED.md",
          "start": "   the fair arms spend most",
          "count": 1
        }
      ],
      "takeaways": [
        {
          "from": "animation",
          "text": "Equal utilization, unequal progress — the meters that matter are the lower ones."
        },
        {
          "from": "syntax",
          "text": "The receipt's title is the finding: the busiest Carrier is the one making the least progress."
        },
        {
          "from": "literature",
          "text": "Queueing theory separated utilization from throughput long ago; Erlang counts reductions, not busy schedulers. The pattern is the old distinction applied to loci."
        },
        {
          "from": "witness",
          "text": "The witness is a receipt with instruction counts; the model document beside it is a prediction and is not cited as evidence."
        }
      ],
      "wrl": {
        "note": "No core-role encoding: progress is a property of a Film, and the page cannot reduce one."
      },
      "up": "UP-013",
      "limit": "computedriven/docs/progress-model.md is a MODEL and its own header says 'never a measurement'. No run in this tree reports semantic progress as its primary quantity.",
      "next_rung": "live_local: one workload on this page reporting progress and utilization side by side, so the divergence between them is a number a reader can watch rather than an argument they have to accept.",
      "derived": {
        "label": "WITNESSED",
        "CHECKABLE": true,
        "RUNNABLE": false,
        "EXECUTED": true,
        "STAGED": false,
        "REPRODUCED": false,
        "PUBLISHED": true,
        "next_rung_name": "live_local",
        "why": [
          {
            "ok": true,
            "text": "a witness is named"
          },
          {
            "ok": true,
            "text": "its evidence kind is one the ledger already uses (measurement)"
          },
          {
            "ok": true,
            "text": "the witness path resolves in this tree"
          },
          {
            "ok": true,
            "text": "its rung is in_tree or above (in_tree)"
          },
          {
            "ok": true,
            "text": "a run is recorded for these exact bytes"
          },
          {
            "ok": true,
            "text": "no claim is cited that could be REFUTED"
          },
          {
            "ok": true,
            "text": "a counterexample is shipped (required once WITNESSED)"
          },
          {
            "ok": false,
            "text": "not staged on this site, so it cannot run from the page"
          }
        ],
        "related_closure": [
          "carrier-multiplexing",
          "dormant-but-alive"
        ],
        "live_run": null,
        "counterexample_strength": {
          "strength": "marker",
          "occurrences": 2,
          "law": null
        },
        "execution": {
          "at": "2026-09-05",
          "note": "the witness is itself an execution record"
        },
        "claim_statuses": [],
        "cell_statuses": []
      }
    },
    {
      "id": "dormant-but-alive",
      "kind": "pattern",
      "name": "Dormant But Alive",
      "family": "progress",
      "invariant": "A locus with no Carrier and pending mailbox depth is fully live: its admissibility and future transitions are defined, and readiness changes without executing a floor command.",
      "cells": [],
      "claims": [],
      "witness": {
        "registry": "computedriven",
        "repo": "computedriven",
        "path": "computedriven/receipts/R7.1-OPEN.md",
        "shape": "spec",
        "evidence_kind": null,
        "rung": "spec",
        "rung_source": "an OPEN record: the admission rule is specified, the battery is R7.1's",
        "staged": false
      },
      "prior_art": {
        "works": [
          {
            "work": "BEAM processes",
            "relation": "realization",
            "overlap": "a process that is not running is still alive and addressable",
            "difference": "the BEAM's dormancy is scheduler-local; the pattern wants it across restarts"
          },
          {
            "work": "Durable execution (Temporal, Restate)",
            "relation": "close-analogue",
            "overlap": "a workflow survives the death of the worker executing it",
            "difference": "these replay from a log; the pattern does not require replay to be the mechanism"
          },
          {
            "work": "Delimited continuations",
            "relation": "antecedent",
            "overlap": "suspended computation as a first-class value",
            "difference": "a language mechanism, not a lifecycle claim"
          }
        ],
        "novelty_not_claimed": "Durable execution vendors have shipped this. Nothing here improves on them.",
        "prose": "BEAM processes; durable execution (Temporal, Restate); delimited continuations."
      },
      "realizations": [
        "computedriven/receipts/R7.1-OPEN.md:42",
        "FPLA/DESIGN_NOTES_2026-09-06.md design A"
      ],
      "failure_mode": "busywork-scheduling",
      "related": [
        "carrier-multiplexing",
        "locus-is-not-its-carrier"
      ],
      "scene": "dormant-but-alive",
      "headline": "A locus that consumes no compute can be fully live.",
      "explanatory": "Liveness is a semantic property: does the locus have a defined state and admissible next transitions? Placement is a resource property: does a carrier hold it right now? A locus can be live and unplaced. Its mailbox accumulates events that change its readiness, and none of them executes anything until a carrier takes it.",
      "technical": "R7.1 admission: a per-Locus mailbox of depth M in the multiplexer. An event changes readiness but executes no floor command by itself (FPLA design A restates the same separation). Placement moves possession from vacant to attached; the pending work is exactly the mailbox contents.",
      "problem": "Runtimes conflate 'idle' with 'done' and 'unscheduled' with 'dead'. A garbage collector, a supervisor or a human reads an empty carrier and concludes there is nothing to do, while a locus with a full mailbox waits above the floor.",
      "forces": "A dormant locus costs memory for its context and its mailbox, so the depth bound M is real: past it, the multiplexer must refuse admission rather than grow. The temptation is to let the scheduler treat the mailbox as advisory. The pattern says it is an admission rule.",
      "construction": "Separate readiness from execution: an event arriving updates a ready-set and nothing else. Make placement an explicit floor command. Keep the mailbox on the locus's context, bounded by M, and refuse the (M+1)th event at admission with a named refusal rather than dropping it silently.",
      "transformations": {
        "allowed": [
          "a locus holding no carrier for any length of time",
          "events arriving while unplaced",
          "placing a dormant locus on any available carrier"
        ],
        "refused": [
          "executing a floor command as a side effect of an event's arrival",
          "inferring 'nothing to do' from 'no carrier busy' (False Quiescence)",
          "growing the mailbox past M"
        ]
      },
      "consequences": "'Is the system quiet?' stops being answerable from the carriers. That is the gap Proven Quiescence names — and that pattern is still PROPOSED, which this page says plainly.",
      "analogy": "A doctor on call. Not in the building, not being paid by the hour, and still on the roster with a pager that changes what happens next. The hospital being quiet says nothing about the pager.",
      "applicability": "Actor systems, agent runtimes with many more agents than cores, durable-execution engines, and any system that must answer 'is there pending work?' honestly.",
      "syntax": [
        {
          "label": "The admission rule (R7.1-OPEN — an OPEN record; specified, its battery not yet run)",
          "path": "computedriven/receipts/R7.1-OPEN.md",
          "start": "- **Admission**",
          "count": 2
        }
      ],
      "takeaways": [
        {
          "from": "animation",
          "text": "Readiness changed three times while nothing executed; placement is what made the pending work run."
        },
        {
          "from": "syntax",
          "text": "Mailbox depth M is an admission rule: the (M+1)th event is refused, not queued forever."
        },
        {
          "from": "literature",
          "text": "BEAM processes and durable-execution engines embody this; continuations are the older form."
        },
        {
          "from": "witness",
          "text": "STATED, not witnessed: the source is an OPEN record, and the label on this page derives from that."
        }
      ],
      "wrl": {
        "note": "Mailbox is the role this scene wants, and Mailbox has no surface spelling (Core 0.1.2 §14b): the runtime honours it, source cannot declare it. Stated by WRL's own limit."
      },
      "up": "UP-014",
      "limit": "States a lifecycle obligation. The BEAM satisfies it within a node and durable-execution vendors satisfy it across restarts; neither fact is a measurement made here.",
      "next_rung": "in_tree: a locus in this tree observed addressable after the process that ran it exited.",
      "derived": {
        "label": "STATED",
        "CHECKABLE": false,
        "RUNNABLE": false,
        "EXECUTED": false,
        "STAGED": false,
        "REPRODUCED": false,
        "PUBLISHED": true,
        "next_rung_name": "in_tree",
        "why": [
          {
            "ok": true,
            "text": "a witness is named"
          },
          {
            "ok": false,
            "text": "its evidence kind is one the ledger already uses"
          },
          {
            "ok": true,
            "text": "the witness path resolves in this tree"
          },
          {
            "ok": false,
            "text": "its rung is in_tree or above (spec)"
          },
          {
            "ok": false,
            "text": "a run is recorded for these exact bytes — shape spec carries no execution"
          },
          {
            "ok": true,
            "text": "no claim is cited that could be REFUTED"
          },
          {
            "ok": false,
            "text": "a counterexample is shipped (required once WITNESSED)"
          },
          {
            "ok": false,
            "text": "not staged on this site, so it cannot run from the page"
          }
        ],
        "related_closure": [
          "carrier-multiplexing",
          "locus-is-not-its-carrier",
          "progress-over-utilization"
        ],
        "live_run": null,
        "counterexample_strength": null,
        "execution": null,
        "claim_statuses": [],
        "cell_statuses": []
      }
    },
    {
      "id": "carrier-multiplexing",
      "kind": "pattern",
      "name": "Carrier Multiplexing",
      "family": "progress",
      "invariant": "A population of loci larger than a floor's slot count is carried by rotating loci through slots; the slot is not the unit of identity and no locus is lost by not currently holding one.",
      "cells": [],
      "claims": [],
      "witness": {
        "registry": "computedriven",
        "repo": "computedriven",
        "path": "computedriven/receipts/R7-EXECUTED.md",
        "shape": "receipt",
        "evidence_kind": "measurement",
        "rung": "in_tree",
        "rung_source": "R7-EXECUTED.md:101 'Eight slots multiplex 64 Loci at 97.4 B'",
        "staged": false,
        "receipt_at": "2026-09-05"
      },
      "counterexample": {
        "shape": "receipt",
        "path": "computedriven/receipts/R7-EXECUTED.md",
        "marker": "fair arm",
        "expected": "REFUSED"
      },
      "prior_art": {
        "works": [
          {
            "work": "M:N threading; Go's scheduler; Erlang schedulers",
            "relation": "realization",
            "overlap": "many loci share few carriers",
            "difference": "none claimed — these are the pattern, working"
          }
        ],
        "novelty_not_claimed": "This is how every modern runtime already works. It is in the catalog because it is the measured half of locus-is-not-its-carrier, not because it is new.",
        "prose": "M:N threading; Go's scheduler; Erlang schedulers."
      },
      "realizations": [
        "computedriven/receipts/R7-EXECUTED.md:101"
      ],
      "failure_mode": "carrier-identity",
      "related": [
        "locus-is-not-its-carrier",
        "progress-aware-placement"
      ],
      "scene": "carrier-multiplexing",
      "headline": "More loci than slots, carried by rotation, and no locus is lost by not holding one.",
      "explanatory": "A floor has a fixed number of slots. A population of loci may be far larger. Multiplexing rotates loci through slots; the slot is a temporary embodiment and the locus's identity, state and admissible transitions are unchanged by leaving it. R7 measured eight slots carrying sixty-four loci.",
      "technical": "Per-Locus mailbox of depth M in the multiplexer (R7.1 admission); a slot holds one Locus Core Context (309 B production profile, KERNELLET-R1); rotation is a floor command, not a copy. Instruction counts per admitted transition are the receipt's unit.",
      "problem": "Threads are expensive and identity is cheap. A system that gives every locus its own thread, core or process runs out of carriers long before it runs out of things worth being; and a system that then says 'the locus IS the thread' has to kill loci to free carriers.",
      "forces": "Rotation costs commands, and a fair rotation spends most of them relocating. The per-locus mailbox bounds what a waiting locus can accumulate, and that bound is an admission rule the multiplexer must enforce, not a scheduler hint. The picture is easy; the receipt is what says whether the rotation left any progress behind.",
      "construction": "Give the floor N slots and the population K > N loci. Keep every locus's context outside the slot (the 309-byte context is the locus's, not the slot's). Rotate by floor command; never copy a context to move it. Measure instructions per admitted transition, not slot occupancy.",
      "transformations": {
        "allowed": [
          "growing the population without growing the floor",
          "changing which slot a locus is rotated into",
          "adding a slot (the population is unchanged)"
        ],
        "refused": [
          "copying a context to 'move' a locus — that is Replica Theater",
          "deriving any locus property from its current slot",
          "declaring completion because every slot is empty"
        ]
      },
      "consequences": "Capacity becomes a question about admitted transitions per cost rather than about carrier count. The trap is that the utilization meters look wonderful while nothing is admitted; Progress Over Utilization is the measuring pattern this one needs beside it.",
      "analogy": "A hotel with eight beds and sixty-four guests on a night shift roster. A guest who is not in a bed has not ceased to exist, and the hotel does not photocopy guests to move them.",
      "applicability": "Any floor whose population exceeds its carriers: agent runtimes, actor systems, cooperative schedulers, the FPLA's array elements. Not for systems where the carrier is the identity by design (a physical device with one owner).",
      "syntax": [
        {
          "label": "The measured line in R7-EXECUTED — the receipt this page cites as its witness",
          "path": "computedriven/receipts/R7-EXECUTED.md",
          "start": "   than any fair arm. Eight slots",
          "count": 3
        },
        {
          "label": "The admission rule (R7.1, an OPEN record — specified, not yet a battery)",
          "path": "computedriven/receipts/R7.1-OPEN.md",
          "start": "- **Admission**",
          "count": 2
        }
      ],
      "takeaways": [
        {
          "from": "animation",
          "text": "The slot is not the unit of identity; a locus without a slot is the same locus."
        },
        {
          "from": "syntax",
          "text": "Eight slots, sixty-four loci, 97.4 B — a receipt line, not a design goal."
        },
        {
          "from": "literature",
          "text": "M:N scheduling and BEAM processes are the prior art; what is new here is measuring the rotation by admitted transitions rather than by fairness."
        },
        {
          "from": "witness",
          "text": "The witness is a receipt document; this page cannot re-run it, and says so under Witness."
        }
      ],
      "wrl": {
        "note": "No honest core-role encoding: fan-out from one Pulser to eight Doors is legal WRL but would picture a broadcast, not a multiplexer."
      },
      "up": "UP-015",
      "limit": "This is the measured half of locus-is-not-its-carrier and nothing more. That many loci share few carriers is how every modern runtime already works; the pattern claims no improvement on any of them.",
      "next_rung": "live_local: the multiplexing shown on this page rather than cited. R7.2.1D produced a number (P2 8/8) and it measured multiplexing, not benefit — the benefit is a different measurement and nothing has made it.",
      "derived": {
        "label": "WITNESSED",
        "CHECKABLE": true,
        "RUNNABLE": false,
        "EXECUTED": true,
        "STAGED": false,
        "REPRODUCED": false,
        "PUBLISHED": true,
        "next_rung_name": "live_local",
        "why": [
          {
            "ok": true,
            "text": "a witness is named"
          },
          {
            "ok": true,
            "text": "its evidence kind is one the ledger already uses (measurement)"
          },
          {
            "ok": true,
            "text": "the witness path resolves in this tree"
          },
          {
            "ok": true,
            "text": "its rung is in_tree or above (in_tree)"
          },
          {
            "ok": true,
            "text": "a run is recorded for these exact bytes"
          },
          {
            "ok": true,
            "text": "no claim is cited that could be REFUTED"
          },
          {
            "ok": true,
            "text": "a counterexample is shipped (required once WITNESSED)"
          },
          {
            "ok": false,
            "text": "not staged on this site, so it cannot run from the page"
          }
        ],
        "related_closure": [
          "dormant-but-alive",
          "locus-is-not-its-carrier",
          "progress-aware-placement",
          "progress-over-utilization"
        ],
        "live_run": null,
        "counterexample_strength": {
          "strength": "marker",
          "occurrences": 2,
          "law": null
        },
        "execution": {
          "at": "2026-09-05",
          "note": "the witness is itself an execution record"
        },
        "claim_statuses": [],
        "cell_statuses": []
      }
    },
    {
      "id": "progress-aware-placement",
      "kind": "pattern",
      "name": "Progress-Aware Placement",
      "family": "progress",
      "invariant": "A locus is placed on the home where the semantic progress it can make is greatest, not where fairness among runnable carriers is greatest.",
      "cells": [],
      "claims": [],
      "witness": null,
      "prior_art": {
        "works": [
          {
            "work": "Work stealing",
            "relation": "antecedent",
            "overlap": "move work to where it can advance",
            "difference": "work stealing balances queues; placement here is asked to consider semantic progress"
          },
          {
            "work": "NUMA-aware placement",
            "relation": "close-analogue",
            "overlap": "locality changes the rate of advancement",
            "difference": "hardware locality, not semantic locality"
          }
        ],
        "novelty_not_claimed": "Placement heuristics are a mature field. R7.2.1D stage 2 — the placement battery on the compiled home — is NOT RUN, and no number appears on this page before it is.",
        "prose": "Work stealing; NUMA-aware placement. R7.2.1D stage 2 (placement battery on the compiled home) is NOT RUN; no number is written before it."
      },
      "realizations": [
        "computedriven/receipts/R7.2.1D-OPEN.md"
      ],
      "failure_mode": "busywork-scheduling",
      "related": [
        "carrier-multiplexing"
      ],
      "scene": "progress-aware-placement",
      "headline": "Place a locus where the semantic progress it can make is greatest, not where fairness among carriers is.",
      "explanatory": "Once progress is what is measured (Progress Over Utilization), placement can be chosen for it. A locus whose mailbox and authority working set are resident on one home makes progress there and spends its commands relocating anywhere else. The battery that would measure this — placement on the compiled home — is prespecified and has not run.",
      "technical": "ComputeDriven R7.2.1D: stage 1 executed; stage 2, the placement battery on the compiled home, is written in R7.2.1D-OPEN.md §2–§3 and blocked on review. The metrics comparator has its own red control (metrics_mutant=), and the oracle for the compiled home was built and validated against mutants before the home existed. No placement number exists; none is written here.",
      "problem": "Schedulers place for fairness because fairness is what they can see. A locus placed 'fairly' onto a home where nothing it needs is resident is a locus that relocates instead of transitioning, and the fairness meter calls that healthy.",
      "forces": "Progress-aware placement needs a progress signal per locus per home, which is exactly the instrumentation Progress Over Utilization demands. It also risks starvation: a locus that can make progress nowhere must still be placed somewhere, and the pattern is not a licence to abandon it.",
      "construction": "Instrument admitted transitions per locus per home. Choose placement to maximize expected progress under a fairness floor. Run the battery against fair arms with a red control on the comparator. Do not write the number before the run.",
      "transformations": {
        "allowed": [
          "re-placing a locus when its progress signal moves",
          "holding a fairness floor beneath the progress objective"
        ],
        "refused": [
          "quoting a placement gain before the battery has run",
          "starving a locus in the name of progress"
        ]
      },
      "consequences": "If the battery confirms it, capacity becomes a placement question; if it does not, the pattern is retracted here by name. Either outcome is a receipt.",
      "analogy": "Seating a violinist next to the orchestra's other strings rather than in the first empty chair. The empty chair is fair; the section is where the music happens.",
      "applicability": "Multiplexed floors with more than one home; agent runtimes whose loci carry state that is expensive to move; the FPLA's readiness engine.",
      "syntax": [
        {
          "label": "The comparator's own red control — the oracle exists before the home does (R7.2.1D-OPEN)",
          "path": "computedriven/receipts/R7.2.1D-OPEN.md",
          "start": "the metrics comparator's own red control",
          "count": 3
        }
      ],
      "takeaways": [
        {
          "from": "animation",
          "text": "The bars moved because a picture moved them; the receipt that could move them has not been produced."
        },
        {
          "from": "syntax",
          "text": "A comparator with a red control can be trusted to have looked; the mutant that changed the protocol is a defect of the control."
        },
        {
          "from": "literature",
          "text": "Work stealing and NUMA-aware placement are the ancestors; the objective here is admitted transitions, not cache locality."
        },
        {
          "from": "witness",
          "text": "STATED, in progress: stage 2 of R7.2.1D is prespecified and unrun."
        }
      ],
      "wrl": {
        "note": "No core-role encoding: placement is a runtime decision below the topology."
      },
      "up": "UP-016",
      "limit": "Prespecified and UNRUN. R7.2.1D stage 2 — the placement battery on the compiled home — has not been executed, so no number appears on this page. P4 measured reached_fraction and it saturates near 1 with no STATIC-vs-STATIC null, which is why it is not a benefit.",
      "next_rung": "in_tree: run the prespecified battery. The design is written; nothing about it is measured.",
      "derived": {
        "label": "STATED",
        "CHECKABLE": false,
        "RUNNABLE": false,
        "EXECUTED": false,
        "STAGED": false,
        "REPRODUCED": false,
        "PUBLISHED": true,
        "next_rung_name": "in_tree",
        "why": [
          {
            "ok": false,
            "text": "a witness is named"
          },
          {
            "ok": false,
            "text": "its evidence kind is one the ledger already uses"
          },
          {
            "ok": false,
            "text": "the witness path resolves in this tree"
          },
          {
            "ok": false,
            "text": "its rung is in_tree or above"
          },
          {
            "ok": false,
            "text": "a run is recorded for these exact bytes"
          },
          {
            "ok": true,
            "text": "no claim is cited that could be REFUTED"
          },
          {
            "ok": false,
            "text": "a counterexample is shipped (required once WITNESSED)"
          },
          {
            "ok": false,
            "text": "not staged on this site, so it cannot run from the page"
          }
        ],
        "related_closure": [
          "carrier-multiplexing"
        ],
        "live_run": null,
        "counterexample_strength": null,
        "execution": null,
        "claim_statuses": [],
        "cell_statuses": []
      }
    },
    {
      "id": "proven-quiescence",
      "kind": "pattern",
      "name": "Proven Quiescence",
      "family": "progress",
      "invariant": "A system is quiescent only when a sweep establishes that no locus has admissible pending work; silence of the currently observed carriers is not completion.",
      "cells": [],
      "claims": [],
      "witness": null,
      "prior_art": {
        "works": [
          {
            "work": "Dijkstra–Scholten termination detection (1980)",
            "relation": "antecedent",
            "overlap": "quiescence must be established, not observed",
            "difference": "none claimed; this is the canonical result"
          },
          {
            "work": "Misra's ring algorithm",
            "relation": "antecedent",
            "overlap": "a second classical detection scheme",
            "difference": "none claimed"
          },
          {
            "work": "REVISION_REGISTER.md:99 — CompletedScan→CompletedSweep with a doesNotAssert field",
            "relation": "partial-overlap",
            "overlap": "the tree's nearest relative: a completion that states what it does not assert",
            "difference": "one rename in one lane, not a general rule"
          }
        ],
        "novelty_not_claimed": "Termination detection was solved in 1980. The phrase 'proven quiescence' appears nowhere in the tree and is PROPOSED by the book; the classical algorithms are the answer, and the pattern's only job is to stop silence being read as completion.",
        "prose": "Dijkstra–Scholten termination detection (1980); Misra's ring algorithm. Nearest tree relatives: REVISION_REGISTER.md:99 CompletedScan→CompletedSweep with a doesNotAssert field; Super 'a timeout abandons the request but not the work'. The phrase appears nowhere in the tree — PROPOSED."
      },
      "realizations": [],
      "failure_mode": "false-quiescence",
      "related": [
        "three-valued-outcome"
      ],
      "scene": "proven-quiescence",
      "headline": "Silence is not completion: quiescence is established by a sweep over the loci, never read off idle carriers.",
      "explanatory": "A system whose carriers are all idle may hold loci with pending work above the floor (Dormant But Alive). Declaring it finished because no observed worker is busy is False Quiescence. Proven quiescence is a sweep that asks every locus whether it has admissible pending work and carries, beside its assertion, what it does not assert.",
      "technical": "PROPOSED — the phrase appears nowhere in the tree. Nearest relatives: REVISION_REGISTER.md R79.2, where CompletedScan was renamed CompletedSweep because a multi-page enumeration is not a point-in-time snapshot, and the artifact gained a doesNotAssert field; and Super's ordered-participant semantics, where a timeout abandons the request but not the work. Prior art: Dijkstra–Scholten termination detection.",
      "problem": "'All workers idle' is the completion signal in most systems, and it is wrong whenever work can wait somewhere a worker is not looking: a mailbox, a queue, a suspended locus. The failure is silent by construction — the system reports done and stops looking.",
      "forces": "A sweep is not atomic: work can arrive behind it. So a sweep must say what it asserts (nothing was pending as of each locus's visit) and what it does not (that nothing arrived since), and a consumer must treat the second as the honest part. Two sweeps in a row with no arrivals between them is the usual proof shape.",
      "construction": "Enumerate the loci, not the carriers. Ask each for admissible pending work. Record the sweep as a sweep with a doesNotAssert field. Repeat until a full sweep finds nothing and no admission happened during it. Only then say quiescent.",
      "transformations": {
        "allowed": [
          "repeating the sweep",
          "narrowing the claim to the loci actually visited"
        ],
        "refused": [
          "inferring quiescence from carrier idleness",
          "a snapshot presented as a sweep",
          "dropping the doesNotAssert field"
        ]
      },
      "consequences": "'Is it done?' gets an answer with a scope. The name is the book's; the pieces are the tree's, and P1 would label a witness for it the day one exists.",
      "analogy": "A librarian who checks that no reader is at a desk, versus one who walks every shelf for a book left out. Only the second can say the library is in order, and only for the shelves walked.",
      "applicability": "Shutdown, checkpointing, 'the migration is complete', end-of-turn for an agent runtime, any place a supervisor decides nothing is pending.",
      "syntax": [
        {
          "label": "The nearest thing the tree already says (REVISION_REGISTER.md R79.2)",
          "path": "REVISION_REGISTER.md",
          "start": "CompletedSweep",
          "count": 1
        }
      ],
      "takeaways": [
        {
          "from": "animation",
          "text": "Every slot was idle and two loci held pending work; a sweep found them, and only a second clean sweep proved quiet."
        },
        {
          "from": "syntax",
          "text": "A sweep carries a doesNotAssert field: what it could not have seen is stated beside what it saw."
        },
        {
          "from": "literature",
          "text": "Dijkstra–Scholten (1980) proved termination for diffusing computations; the shape is the same."
        },
        {
          "from": "witness",
          "text": "PROPOSED: no witness. The label says so and nothing on this page argues otherwise."
        }
      ],
      "wrl": {
        "note": "No core-role encoding; a sweep is over a Film, not a topology."
      },
      "up": "UP-017",
      "limit": "PROPOSED. The phrase appears nowhere in the tree. Dijkstra–Scholten solved termination detection in 1980 and this chapter adds no algorithm; its only content is that silence must not be read as completion.",
      "next_rung": "in_tree: a detector in this tree that distinguishes quiescent from merely-silent, and a case where it refuses.",
      "derived": {
        "label": "PROPOSED",
        "CHECKABLE": false,
        "RUNNABLE": false,
        "EXECUTED": false,
        "STAGED": false,
        "REPRODUCED": false,
        "PUBLISHED": true,
        "next_rung_name": "in_tree",
        "why": [
          {
            "ok": false,
            "text": "a witness is named"
          },
          {
            "ok": false,
            "text": "its evidence kind is one the ledger already uses"
          },
          {
            "ok": false,
            "text": "the witness path resolves in this tree"
          },
          {
            "ok": false,
            "text": "its rung is in_tree or above"
          },
          {
            "ok": false,
            "text": "a run is recorded for these exact bytes"
          },
          {
            "ok": true,
            "text": "no claim is cited that could be REFUTED"
          },
          {
            "ok": false,
            "text": "a counterexample is shipped (required once WITNESSED)"
          },
          {
            "ok": false,
            "text": "not staged on this site, so it cannot run from the page"
          }
        ],
        "related_closure": [
          "three-valued-outcome"
        ],
        "live_run": null,
        "counterexample_strength": null,
        "execution": null,
        "claim_statuses": [],
        "cell_statuses": []
      }
    },
    {
      "id": "three-valued-outcome",
      "kind": "pattern",
      "name": "Three-Valued Outcome",
      "family": "progress",
      "invariant": "Every attempted intervention resolves to exactly one of APPLIED, REFUSED, INDETERMINATE; INDETERMINATE is a fact about an attempt and is never rewritten.",
      "cells": [
        {
          "ref": "17",
          "modality": "necessary"
        }
      ],
      "claims": [],
      "witness": null,
      "prior_art": {
        "works": [
          {
            "work": "Two Generals",
            "relation": "antecedent",
            "overlap": "there are questions a message exchange cannot settle",
            "difference": "none claimed"
          },
          {
            "work": "at-least-once vs at-most-once delivery",
            "relation": "antecedent",
            "overlap": "the third outcome is the practical consequence of the impossibility",
            "difference": "delivery semantics name the tradeoff; the pattern names the outcome vocabulary"
          },
          {
            "work": "Lamport, 'happened before'",
            "relation": "antecedent",
            "overlap": "partial order as the honest account of distributed time",
            "difference": "none claimed"
          }
        ],
        "novelty_not_claimed": "Distributed systems have had three-valued outcomes since the field began. The witness lives in super/ (referenced, not copied), and its §0 refutes the predecessor round's settle-in-place design — that refutation, not the trichotomy, is the tree's result.",
        "prose": "Two Generals; at-least-once vs at-most-once delivery; Lamport's 'happened before'. Witness lives in super/ (referenced, not copied); the document's §0 refutes the PREDECESSOR round's settle-in-place design."
      },
      "realizations": [
        "super/docs/reviews/D_1_3C_2D_2_INTERVENTION_PROVENANCE.md:210",
        "super/docs/reviews/D_1_3C_2D_2_INTERVENTION_PROVENANCE.md:723"
      ],
      "failure_mode": "false-quiescence",
      "related": [
        "refusing-join",
        "intervention-provenance"
      ],
      "scene": "three-valued-outcome",
      "headline": "Every attempted intervention resolves to APPLIED, REFUSED or INDETERMINATE — and INDETERMINATE is never rewritten.",
      "explanatory": "Two values are not enough for an action on a world you do not fully control. A timeout abandons the request but not the work: the effect may be about to land. Recording that attempt as failed is a lie the future may contradict; recording it as succeeded is a guess. INDETERMINATE is a fact about an attempt, kept as such forever.",
      "technical": "Super D.1.3c·2d·2 intervention provenance: outcome vocabulary APPLIED | REFUSED | INDETERMINATE; 'INDETERMINATE is a fact about an attempt. It is never rewritten.' The same document's §0 refutes its predecessor round's settle-in-place design: Ampd.Receipts has no update-in-place operation, and the re-observation that would repair INDETERMINATE (Pty::winsize()) has zero callers. A witness is sound after a death and unsound after a timeout.",
      "problem": "Distributed systems teach the Two Generals problem and then write boolean return types anyway. An intervention that timed out gets retried, and the retry applies twice; or it gets marked failed, and the world quietly holds an effect nobody recorded.",
      "forces": "Three values make every caller handle a case it would rather not. The temptation is to 'settle' INDETERMINATE later by re-observing — which needs the re-observation to exist and the record to be rewritable, and this specification found it had neither. Keeping the attempt's fact and adding a new fact is the honest shape.",
      "construction": "Return three values. Append a new record for any later observation rather than rewriting the attempt. Distinguish a death (witness sound) from a timeout (witness unsound). Name the re-observation the design depends on, and check that it exists.",
      "transformations": {
        "allowed": [
          "appending a later observation beside an INDETERMINATE attempt",
          "treating REFUSED as a normal outcome"
        ],
        "refused": [
          "rewriting INDETERMINATE to APPLIED or REFUSED",
          "retrying an INDETERMINATE attempt as if it had failed",
          "a settle-in-place that the ledger cannot perform"
        ]
      },
      "consequences": "Interventions become auditable as attempts, and duplicates become visible instead of silent. The honest status: STATED, with the specification's own refutation of its predecessor printed beside it.",
      "analogy": "A letter posted to a friend abroad. Delivered, returned to sender, or — for a while, maybe forever — unknown. Writing 'lost' on your copy because a week passed does not make it so.",
      "applicability": "Any side effect over a boundary you do not control: terminal writes, remote calls, agent actions on a user's machine, payments.",
      "syntax": [
        {
          "label": "The rule, verbatim (super/docs/reviews)",
          "path": "super/docs/reviews/D_1_3C_2D_2_INTERVENTION_PROVENANCE.md",
          "start": "INDETERMINATE is a fact about an attempt",
          "count": 1
        }
      ],
      "takeaways": [
        {
          "from": "animation",
          "text": "Applied, refused, and one that timed out; the third stayed what it was."
        },
        {
          "from": "syntax",
          "text": "INDETERMINATE is appended beside, never rewritten — the ledger has no update-in-place."
        },
        {
          "from": "literature",
          "text": "Two Generals; at-least-once versus at-most-once delivery; the third value is what idempotency keys exist to compensate for."
        },
        {
          "from": "witness",
          "text": "STATED: the witness is a review in super/, and its §0 is the refutation of the round before it."
        }
      ],
      "wrl": {
        "note": "An attempt reaches the world through a carrier; a Door is a sink. The three outcomes are the Film's, and the Film is TRVM's."
      },
      "up": "UP-018",
      "limit": "The witness lives in super/ and is referenced, not copied. It establishes that one round's settle-in-place design was refuted — it does not establish that the tree's other components carry the third value. INDETERMINATE has no forge counterpart, because films are total.",
      "next_rung": "in_tree: the super/ witness is referenced, not copied, so this catalog cannot run it. Staging it here — so the refutation of the predecessor round's settle-in-place design can be re-run rather than quoted — is the step.",
      "derived": {
        "label": "STATED",
        "CHECKABLE": false,
        "RUNNABLE": false,
        "EXECUTED": false,
        "STAGED": false,
        "REPRODUCED": false,
        "PUBLISHED": true,
        "next_rung_name": "in_tree",
        "why": [
          {
            "ok": false,
            "text": "a witness is named"
          },
          {
            "ok": false,
            "text": "its evidence kind is one the ledger already uses"
          },
          {
            "ok": false,
            "text": "the witness path resolves in this tree"
          },
          {
            "ok": false,
            "text": "its rung is in_tree or above"
          },
          {
            "ok": false,
            "text": "a run is recorded for these exact bytes"
          },
          {
            "ok": true,
            "text": "no claim is cited that could be REFUTED"
          },
          {
            "ok": false,
            "text": "a counterexample is shipped (required once WITNESSED)"
          },
          {
            "ok": false,
            "text": "not staged on this site, so it cannot run from the page"
          }
        ],
        "related_closure": [
          "intervention-provenance",
          "proven-quiescence",
          "refusing-join"
        ],
        "live_run": null,
        "counterexample_strength": null,
        "execution": null,
        "claim_statuses": [],
        "cell_statuses": [
          {
            "num": "17",
            "modality": "necessary",
            "status": "proved"
          }
        ]
      }
    },
    {
      "id": "orthogonal-persistence",
      "kind": "pattern",
      "name": "Orthogonal Persistence",
      "family": "world",
      "invariant": "Whether a locus's state is in cache, RAM, disk or a remote node is an implementation choice below its semantic level; code is identical for short-lived and long-lived state.",
      "cells": [],
      "claims": [],
      "witness": null,
      "prior_art": {
        "works": [
          {
            "work": "Atkinson & Morrison — type orthogonality, persistence by reachability, persistence independence (PS-algol, Napier88; VLDB J. 4, 1995)",
            "relation": "terminology-precedent",
            "overlap": "the name and all three of its principles",
            "difference": "none. The term is theirs and the content is theirs"
          }
        ],
        "novelty_not_claimed": "Nothing. This chapter exists to cite Atkinson & Morrison correctly and to record that studbook is at the spec rung and nothing here implements it.",
        "prose": "Atkinson & Morrison's term: type orthogonality, persistence by reachability, persistence independence (PS-algol, Napier88; VLDB J. 4, 1995). studbook is at the spec rung; nothing here implements it."
      },
      "realizations": [
        "studbook/docs/spec/README.md"
      ],
      "failure_mode": "location-leak",
      "related": [
        "continuity-through-reconstruction",
        "three-sizes-of-world"
      ],
      "scene": "orthogonal-persistence",
      "headline": "Whether a locus's state is in cache, RAM, disk or a remote node is an implementation choice below its semantic level.",
      "explanatory": "Atkinson and Morrison's three principles: persistence is available for every type; lifetime is determined by reachability from durable roots; code is identical whether it operates on short-lived or long-lived state. A locus never decides whether it is 'in memory' — that decision belongs to the substrate, and the locus's semantics are unchanged by it.",
      "technical": "The term and the principles are Atkinson & Morrison's (PS-algol, Napier88; VLDB J. 4, 1995). In this stack the store that would realize them is studbook, at the spec rung with one unruled question (§10.2, where confidentiality comes from). The previous data layer was abandoned because Postgres stores a row but not why the row is that row, and nothing in its migration layer could refuse a row whose provenance did not check out. STATED; nothing implements it here.",
      "problem": "Every application has a save path and a load path, and the bugs live between them: state that was in memory and not on disk, objects that persist by accident, serializers that lose the reason a value is what it is. The locus is made to care about its own storage, which is not a semantic question.",
      "forces": "Orthogonal persistence hides a cost model: a remote node is not RAM. Reachability-based lifetime needs a garbage collector that understands durability. And a content-addressed store makes persistence honest and access control hard — the open ruling that blocks studbook.",
      "construction": "Give the substrate the persistence decision. Determine lifetime by reachability from declared roots. Keep one code path. Address content by hash so provenance is checkable. Rule the confidentiality question before holding anything with a user in it.",
      "transformations": {
        "allowed": [
          "moving state between tiers",
          "garbage-collecting what no root reaches"
        ],
        "refused": [
          "a save() the locus must call",
          "a persistent type distinct from a transient one",
          "holding user data before §10.2 is ruled"
        ]
      },
      "consequences": "The locus stops asking where it lives. The cost is a substrate that must be built with the same care as the language — and, here, has not been built.",
      "analogy": "A library where every book is shelved by content and re-shelved as demand moves, and a reader who only ever asks for the book — never which stack it is on.",
      "applicability": "Durable agents, worlds that must survive their machines, any system whose 'persistence layer' is currently a source of bugs.",
      "syntax": [
        {
          "label": "Why the previous data layer went (studbook §2)",
          "path": "studbook/docs/spec/README.md",
          "start": "Postgres stores a row",
          "count": 2
        },
        {
          "label": "What has to be ruled first (studbook §10)",
          "path": "studbook/docs/spec/README.md",
          "start": "## 10. What has to be ruled before implementation starts",
          "count": 1
        }
      ],
      "takeaways": [
        {
          "from": "animation",
          "text": "The locus moved through four tiers and its code path never changed."
        },
        {
          "from": "syntax",
          "text": "The spec's own header says: no implementation, do not build from this yet."
        },
        {
          "from": "literature",
          "text": "Type orthogonality, persistence by reachability, persistence independence — credit Atkinson & Morrison, whose term this is."
        },
        {
          "from": "witness",
          "text": "STATED at the spec rung; the studbook §10.2 ruling is the blocker and is published as one."
        }
      ],
      "wrl": {
        "note": "No core-role encoding: persistence is below the semantic level by definition."
      },
      "up": "UP-019",
      "limit": "Cites Atkinson & Morrison correctly and implements nothing. studbook is at the spec rung and its §10.2 blocker is open, so no system here has orthogonal persistence.",
      "next_rung": "in_tree: any implementation at all. studbook §10.2 (where confidentiality comes from) blocks it, and that is a ruling, not a build.",
      "derived": {
        "label": "STATED",
        "CHECKABLE": false,
        "RUNNABLE": false,
        "EXECUTED": false,
        "STAGED": false,
        "REPRODUCED": false,
        "PUBLISHED": true,
        "next_rung_name": "in_tree",
        "why": [
          {
            "ok": false,
            "text": "a witness is named"
          },
          {
            "ok": false,
            "text": "its evidence kind is one the ledger already uses"
          },
          {
            "ok": false,
            "text": "the witness path resolves in this tree"
          },
          {
            "ok": false,
            "text": "its rung is in_tree or above"
          },
          {
            "ok": false,
            "text": "a run is recorded for these exact bytes"
          },
          {
            "ok": true,
            "text": "no claim is cited that could be REFUTED"
          },
          {
            "ok": false,
            "text": "a counterexample is shipped (required once WITNESSED)"
          },
          {
            "ok": false,
            "text": "not staged on this site, so it cannot run from the page"
          }
        ],
        "related_closure": [
          "continuity-through-reconstruction",
          "three-sizes-of-world"
        ],
        "live_run": null,
        "counterexample_strength": null,
        "execution": null,
        "claim_statuses": [],
        "cell_statuses": []
      }
    },
    {
      "id": "three-sizes-of-world",
      "kind": "pattern",
      "name": "Three Sizes of World",
      "family": "world",
      "invariant": "WORLD (the machine, 10 GB–10 TB), WORLD VERSION (a content-addressed root, KB) and WRL GRAPH (the semantic layer inside, KB–MB) are three sizes with three names; no field is called current_head — a head is always qualified.",
      "cells": [],
      "claims": [],
      "witness": null,
      "prior_art": {
        "works": [
          {
            "work": "Git's object / ref / worktree split",
            "relation": "close-analogue",
            "overlap": "the same three-way distinction between the store, a named root, and the checked-out shape",
            "difference": "git's three are concrete files; WORLD / WORLD VERSION / WRL GRAPH are scopes of authority"
          }
        ],
        "novelty_not_claimed": "The structure is git's. The vocabulary is frozen in CLOUD_V1.md §2 for one reason: WORLD_SIZE.md §11 mistook 0.21 % of the thing for the whole thing, and a frozen word is cheaper than that mistake.",
        "prose": "Git's object/ref/worktree split is the same three-way distinction. Frozen vocabulary in CLOUD_V1.md §2 because WORLD_SIZE.md §11 mistook 0.21 % for the whole."
      },
      "realizations": [
        "CLOUD_V1.md:37"
      ],
      "failure_mode": "number-in-two-places",
      "related": [
        "world-boundary",
        "orthogonal-persistence"
      ],
      "scene": "three-sizes-of-world",
      "headline": "WORLD, WORLD VERSION and WRL GRAPH are three sizes with three names; a head is always qualified.",
      "explanatory": "Three things are called 'world' in this stack and they differ by six orders of magnitude. The WORLD is the machine, ten gigabytes to ten terabytes. A WORLD VERSION is a content-addressed root describing that machine at an instant — kilobytes. The WRL GRAPH is the semantic layer inside a world, with its own head. Conflating them once produced a measurement of 0.21 % reported as the whole.",
      "technical": "CLOUD_V1.md §2, frozen vocabulary. There is no current_head field anywhere: a head is always manifest_root or wrl_head. The scope error is recorded in WORLD_SIZE.md §11 — a 247 KB world layer was reported as a conclusion about a 10 TB product. T&R backs up the user's machine, not the shell's graph.",
      "problem": "One word, three referents. A backup plan sized for the graph; a benchmark run against the manifest and reported for the machine; a 'current head' that meant different things in two files. Every one of these happened here.",
      "forces": "Short names are convenient and the three things are genuinely nested, so 'the world' will always be reached for. Freezing the vocabulary costs a sentence per use; it buys measurements that mean what they say.",
      "construction": "Name each size. Forbid the bare word in technical copy. Qualify every head. Record the scope error where it happened so the next reader finds it before repeating it.",
      "transformations": {
        "allowed": [
          "describing a WORLD by a WORLD VERSION",
          "embedding a WRL GRAPH in a WORLD"
        ],
        "refused": [
          "reporting a graph-sized measurement as a machine-sized one",
          "a field called current_head"
        ]
      },
      "consequences": "Sizes and heads become unambiguous. This is A Number in Two Places, prevented at the vocabulary rather than at the number.",
      "analogy": "A city, a map of the city, and the map's legend. Each has a size; a plan to move the city that was budgeted from the map is the §11 error.",
      "applicability": "Any system with a machine-sized state, a snapshot format and a semantic layer — which is every backup, every VM image with a manifest, every document store with a graph in it.",
      "syntax": [
        {
          "label": "The frozen table row (CLOUD_V1.md §2)",
          "path": "CLOUD_V1.md",
          "start": "WORLD VERSION",
          "count": 1
        },
        {
          "label": "The anti-relapse rule",
          "path": "CLOUD_V1.md",
          "start": "current_head",
          "count": 1
        }
      ],
      "takeaways": [
        {
          "from": "animation",
          "text": "Three rings, three sizes; the inner ring taken for the outer is the recorded error."
        },
        {
          "from": "syntax",
          "text": "No current_head anywhere: manifest_root or wrl_head, always."
        },
        {
          "from": "literature",
          "text": "Git's object / ref / worktree split makes the same three-way distinction."
        },
        {
          "from": "witness",
          "text": "STATED: frozen vocabulary; the witness is the retraction record in WORLD_SIZE.md §11."
        }
      ],
      "wrl": {
        "note": "This world is a WRL GRAPH — the smallest of the three sizes. Its seal is a wrl_head."
      },
      "up": "UP-020",
      "limit": "A vocabulary ruling (R11), frozen in CLOUD_V1.md §2. It establishes which word means which size. It does not establish that any system respects the distinction — WORLD_SIZE.md §11 records one occasion where this tree did not.",
      "next_rung": "in_tree: a lint that refuses a sentence using 'world' where the size is ambiguous, the way IDENTITY_ASSERTED refuses its class.",
      "derived": {
        "label": "STATED",
        "CHECKABLE": false,
        "RUNNABLE": false,
        "EXECUTED": false,
        "STAGED": false,
        "REPRODUCED": false,
        "PUBLISHED": true,
        "next_rung_name": "in_tree",
        "why": [
          {
            "ok": false,
            "text": "a witness is named"
          },
          {
            "ok": false,
            "text": "its evidence kind is one the ledger already uses"
          },
          {
            "ok": false,
            "text": "the witness path resolves in this tree"
          },
          {
            "ok": false,
            "text": "its rung is in_tree or above"
          },
          {
            "ok": false,
            "text": "a run is recorded for these exact bytes"
          },
          {
            "ok": true,
            "text": "no claim is cited that could be REFUTED"
          },
          {
            "ok": false,
            "text": "a counterexample is shipped (required once WITNESSED)"
          },
          {
            "ok": false,
            "text": "not staged on this site, so it cannot run from the page"
          }
        ],
        "related_closure": [
          "orthogonal-persistence",
          "world-boundary"
        ],
        "live_run": null,
        "counterexample_strength": null,
        "execution": null,
        "claim_statuses": [],
        "cell_statuses": []
      }
    },
    {
      "id": "world-boundary",
      "kind": "pattern",
      "name": "World Boundary",
      "family": "world",
      "invariant": null,
      "cells": [],
      "claims": [],
      "witness": null,
      "prior_art": {
        "works": [
          {
            "work": "GPT, 2026-09-11 — 'a coherent authority/state/observation domain that need not be an OS process, VM or machine'",
            "relation": "not-searched",
            "overlap": "a candidate definition offered in conversation",
            "difference": "unruled, and no canonical definition exists anywhere in the tree"
          }
        ],
        "novelty_not_claimed": "Everything. There is no pattern here yet — this chapter is a GAP with a candidate definition attached, and its invariant field is empty on purpose.",
        "prose": "GAP: no canonical definition in the tree. Candidate (GPT 2026-09-11): a coherent authority/state/observation domain that need not be an OS process, VM or machine. Unruled."
      },
      "realizations": [],
      "related": [
        "three-sizes-of-world"
      ],
      "scene": "world-boundary",
      "headline": "A world is a coherent domain of authority, state and observation — and the tree has not yet defined its boundary.",
      "explanatory": "Three sizes of world have frozen names; the boundary that separates a world from what is outside it has none. The candidate definition, from the book's own drafting, is: a coherent authority, state and observation domain that need not be an operating-system process, a virtual machine or a machine. It is unruled, and this page is empty where an invariant would go because nothing in the tree states one.",
      "technical": "GAP. CLOUD_V1.md §2 defines WORLD, WORLD VERSION and WRL GRAPH by size and role; AGENCY.md §3 places 'world' in the chain as what carries state; neither defines the boundary. The label vocabulary has no word for a gap, so this record derives as PROPOSED. Ruling needed: whether the candidate definition is adopted, amended or refused.",
      "problem": "Without a boundary, 'in the world' and 'outside it' are readings. Authority scoped 'to the world' cannot be checked; a locus crossing between worlds cannot be said to have crossed anything.",
      "forces": "The obvious boundaries — process, VM, machine — are carrier boundaries, and this book's first family exists to say carriers are not identity. A semantic boundary has to be defined in terms of authority, state and observation, and those are the three things the agency definition already names.",
      "construction": "Not yet. What this page can do is state the candidate, name what it would need — a check that a claimed crossing actually crossed — and stop.",
      "consequences": "Until ruled, every sentence of the form 'inside the world' in this catalog is a reading. The gap is load-bearing: it is how the next writer knows where to stand.",
      "analogy": "A country whose size, population and capital are recorded and whose border has never been drawn.",
      "applicability": "This page is applicable to the ruling, not to designs.",
      "syntax": [
        {
          "label": "What is defined — the sizes (CLOUD_V1.md §2) — so the reader can see what is not",
          "path": "CLOUD_V1.md",
          "start": "WORLD VERSION",
          "count": 1
        }
      ],
      "takeaways": [
        {
          "from": "animation",
          "text": "The middle ring is drawn and unlabelled by the tree; the picture is the gap."
        },
        {
          "from": "syntax",
          "text": "Three sizes have rows in a frozen table; the boundary has no row."
        },
        {
          "from": "literature",
          "text": "Domain boundaries in Evans's DDD are the nearest prior art, and they too are drawn by hand."
        },
        {
          "from": "witness",
          "text": "GAP, derived as PROPOSED: no invariant, no witness, one open ruling."
        }
      ],
      "wrl": {
        "note": "No encoding — the boundary has no definition to encode."
      },
      "up": "UP-021",
      "limit": "A GAP. There is no canonical definition of a world boundary in this tree, the invariant field is empty on purpose, and the candidate definition attached here is unruled conversation.",
      "next_rung": "A ruling that fixes the definition. Nothing can be witnessed before the thing being witnessed is defined.",
      "derived": {
        "label": "PROPOSED",
        "CHECKABLE": false,
        "RUNNABLE": false,
        "EXECUTED": false,
        "STAGED": false,
        "REPRODUCED": false,
        "PUBLISHED": true,
        "next_rung_name": "in_tree",
        "why": [
          {
            "ok": false,
            "text": "a witness is named"
          },
          {
            "ok": false,
            "text": "its evidence kind is one the ledger already uses"
          },
          {
            "ok": false,
            "text": "the witness path resolves in this tree"
          },
          {
            "ok": false,
            "text": "its rung is in_tree or above"
          },
          {
            "ok": false,
            "text": "a run is recorded for these exact bytes"
          },
          {
            "ok": true,
            "text": "no claim is cited that could be REFUTED"
          },
          {
            "ok": false,
            "text": "a counterexample is shipped (required once WITNESSED)"
          },
          {
            "ok": false,
            "text": "not staged on this site, so it cannot run from the page"
          }
        ],
        "related_closure": [
          "three-sizes-of-world"
        ],
        "live_run": null,
        "counterexample_strength": null,
        "execution": null,
        "claim_statuses": [],
        "cell_statuses": []
      }
    },
    {
      "id": "meaning-is-a-hash",
      "kind": "pattern",
      "name": "Meaning Is a Hash",
      "family": "world",
      "invariant": "The semantics of a WRL world is its SemanticArtifactID; a change of meaning is a change of hash and a preserved hash is a preserved meaning on every host, forever.",
      "cells": [],
      "claims": [],
      "witness": {
        "registry": "wrl",
        "repo": "WRL",
        "path": "WRL/test/conformance.mjs",
        "shape": "side-effect",
        "evidence_kind": "constructive_witness",
        "rung": "in_tree",
        "rung_source": "WRL/README.md: the starter world seals to sem-67e954cf… on every host",
        "cmd": "node test/conformance.mjs",
        "cwd": "WRL",
        "staged": false
      },
      "counterexample": {
        "shape": "fixture",
        "path": "WRL/test/projection-negative-vectors.json",
        "expected": "REFUSED",
        "expected_count": 15
      },
      "prior_art": {
        "works": [
          {
            "work": "Unison (content-addressed definitions)",
            "relation": "antecedent",
            "overlap": "the identity of a meaning is the hash of its structure",
            "difference": "none at the level of the idea"
          },
          {
            "work": "IPFS; Nix",
            "relation": "antecedent",
            "overlap": "content addressing at the storage and build layers",
            "difference": "these address bytes and build inputs; the seal here addresses a semantic topology"
          }
        ],
        "novelty_not_claimed": "The hashing is not the contribution and this page says so twice. What the tree adds is an executable topology and a fixed set of refusal names — and only the first of those is witnessed.",
        "prose": "Unison (content-addressed definitions); IPFS; Nix. Direct prior art — the book's contribution is the executable topology and the refusal names, not the hashing."
      },
      "realizations": [
        "WRL/README.md:1-40"
      ],
      "failure_mode": "replica-theater",
      "related": [
        "identity-is-a-seal",
        "refusable-divergence"
      ],
      "scene": "meaning-is-a-hash",
      "headline": "The meaning of a WRL world is its SemanticArtifactID.",
      "explanatory": "A WRL program is a network of durable identities joined by textured routes and separated by boundaries, and the whole network is one content address. Change the meaning and the hash changes; keep the hash and the meaning is kept, on every host, forever. There is no version flag beside it to consult.",
      "technical": "WallRiderLang Core 0.1.2: 'an executable topology language whose meaning is a hash'. wrl.js is the browser identity spine that seals real sem- ids; the starter world seals to sem-67e954cf…; test/conformance.mjs pins the fixtures (924 checks, 0 failed at the last run). Committed projection vectors round-trip byte-exact through TRVM Forge's independent Python spine.",
      "problem": "Meaning lives in prose and version numbers, both of which are asserted rather than computed. Two implementations disagree about what a document means and there is nothing either can recompute to settle it.",
      "forces": "A hash of the source is not enough — whitespace is not meaning — so a canonical form has to be defined and both implementations have to produce it identically. The cost is a canonicalizer as carefully specified as the language; the benefit is that cross-implementation agreement becomes a vector file rather than a meeting.",
      "construction": "Specify the canonical form. Seal it. Pin fixtures. Put the sealed id on the wire and let receivers recompute it (Refusable Divergence). Run a second implementation in a second language against the same vectors.",
      "transformations": {
        "allowed": [
          "re-serializing the source (same canonical form, same id)",
          "adding an implementation that reproduces the same ids",
          "editing the world — which makes a new world"
        ],
        "refused": [
          "a version flag standing in for the id",
          "an id assigned by a registry rather than derived",
          "two implementations that disagree without one of them refusing"
        ]
      },
      "consequences": "Meaning becomes portable and checkable. Unison did this for functions and Nix for packages; the prior-art field credits both, because the contribution here is the executable topology and the refusal names, not the hashing.",
      "analogy": "A recipe written so precisely that any two kitchens produce the same dish, and the dish's name is a fingerprint of the recipe. Change the salt and it is, by name, a different dish.",
      "applicability": "Any language or format whose documents must mean the same thing in two places: world descriptions, manifests, contracts, projections.",
      "syntax": [
        {
          "label": "WRL in one sentence (WRL/README.md)",
          "path": "WRL/README.md",
          "start": "meaning is a hash",
          "count": 1
        },
        {
          "label": "The world that seals to sem-67e954cf…",
          "path": "WRL/README.md",
          "start": "profile forge.world.core.v1",
          "count": 10
        }
      ],
      "takeaways": [
        {
          "from": "animation",
          "text": "Two hosts computed the same id from the same canonical form, and a different one after a single edit."
        },
        {
          "from": "syntax",
          "text": "Nine lines of source are the whole world; the sem- id below them is its meaning."
        },
        {
          "from": "literature",
          "text": "Unison identifies every definition by the hash of its syntax tree; IPFS and Nix by content. Direct prior art, credited."
        },
        {
          "from": "witness",
          "text": "924 conformance checks ran today under a receipt; the suite is not staged on this page and the page says so."
        }
      ],
      "wrl": {
        "variant": "meaning-is-a-hash.variant.wrl",
        "note": "The same world with one period changed. Two ids; there is no version flag to consult."
      },
      "up": "UP-022",
      "limit": "Unison, IPFS and Nix are direct prior art and the hashing is not the contribution. What the build establishes is that this tree's seal is stable under comment changes and moves under a topology change — one property of one sealer.",
      "next_rung": "live_local: sealWorld exposed to the page, so a reader supplies source and watches the id move under a topology change and hold under a comment change. The build does this 33 times; nothing yet lets the page do it once.",
      "derived": {
        "label": "WITNESSED",
        "CHECKABLE": true,
        "RUNNABLE": true,
        "EXECUTED": true,
        "STAGED": false,
        "REPRODUCED": false,
        "PUBLISHED": true,
        "next_rung_name": "live_local",
        "why": [
          {
            "ok": true,
            "text": "a witness is named"
          },
          {
            "ok": true,
            "text": "its evidence kind is one the ledger already uses (constructive_witness)"
          },
          {
            "ok": true,
            "text": "the witness path resolves in this tree"
          },
          {
            "ok": true,
            "text": "its rung is in_tree or above (in_tree)"
          },
          {
            "ok": true,
            "text": "a run is recorded for these exact bytes"
          },
          {
            "ok": true,
            "text": "no claim is cited that could be REFUTED"
          },
          {
            "ok": true,
            "text": "a counterexample is shipped (required once WITNESSED)"
          },
          {
            "ok": false,
            "text": "not staged on this site, so it cannot run from the page"
          }
        ],
        "related_closure": [
          "confidentiality-under-content-addressing",
          "exact-replay",
          "identity-is-a-seal",
          "refusable-divergence"
        ],
        "live_run": null,
        "counterexample_strength": null,
        "execution": {
          "at": "2026-09-11T15:25:45.285Z",
          "host": "PX13",
          "sha256": "e1f1e313eefe0001dc23d95da90011a36596924915d185ce6b1171219ef1925c",
          "repo_head": "32160fec77a13ad152176fed3001b0afbdebee42"
        },
        "claim_statuses": [],
        "cell_statuses": []
      }
    },
    {
      "id": "exact-replay",
      "kind": "pattern",
      "name": "Exact Replay",
      "family": "world",
      "invariant": "A run of a sealed world is a film that replays byte-identically; any divergence on replay is a divergence of the world, not of the player.",
      "cells": [],
      "claims": [],
      "witness": null,
      "prior_art": {
        "works": [
          {
            "work": "Deterministic replay; rr",
            "relation": "antecedent",
            "overlap": "re-execution produces the identical trace",
            "difference": "rr replays a process; the forge replays a reduction"
          },
          {
            "work": "Event sourcing",
            "relation": "close-analogue",
            "overlap": "state is a fold over a recorded sequence",
            "difference": "event sourcing tolerates non-determinism in projections; this does not"
          }
        ],
        "novelty_not_claimed": "Deterministic replay is a shipped, mature technique. TRVM's film replay is not verified by this build, and no receipt stating a fidelity percentage was ever located (v0.2 review, finding 7) — the page carries a '?' where that number would go.",
        "prose": "Deterministic replay; event sourcing; rr. TRVM film replay — not verified by this build; no receipt stating a fidelity percentage was located (v0.2 review finding 7)."
      },
      "realizations": [
        "TRVM/LAWS.md Law 4"
      ],
      "failure_mode": "replica-theater",
      "related": [
        "cross-machine-skill-replay",
        "meaning-is-a-hash"
      ],
      "scene": "exact-replay",
      "headline": "A run of a sealed world is a film that replays byte-identically; a divergence on replay is the world's, not the player's.",
      "explanatory": "When identity is a seal and the observable is complete, a run is reproducible: the film of one run replays to the same bytes on another player. If it does not, the world hid state or the seal lied, and the replay has found a bug in the world, not in the player.",
      "technical": "TRVM film replay. Law 4: every reported reduction cost must name the reduction strategy under which it was measured. Law 6 is the completeness condition replay depends on. No receipt in the tree states a fidelity percentage for TRVM film replay; the v0.2 review of this book's plan looked for one and did not find it, so this page carries a '?' where a number would be. Not to be confused with Cross-Machine Skill Replay, which is about OS-011 traces.",
      "problem": "Reproducibility is claimed and rarely measured. 'It replayed' usually means a log was read back, not that a second player produced the same bytes from the same sealed world. When two players disagree, the player is blamed, because the world was never sealed to begin with.",
      "forces": "Exact replay needs everything Shared Observable demands and a cost model that names its strategy, since a replay that takes a different reduction path is a different run. The number that would witness it is a receipt this tree does not yet hold.",
      "construction": "Seal the world. Record the film with its reduction strategy. Replay on a second player. Compare bytes. Publish the fidelity with the method, or publish '?'.",
      "transformations": {
        "allowed": [
          "replaying on any conforming player",
          "comparing films across players"
        ],
        "refused": [
          "a replay claim without a second player",
          "a fidelity number without a receipt"
        ]
      },
      "consequences": "Bugs in worlds become reproducible by construction. The honest status: STATED, with an explicit '?' — an acceptable answer under the doctrine, and the only honest one today.",
      "analogy": "A player piano roll. Two pianos, one roll, the same tune — or the roll is damaged, and it was never the piano.",
      "applicability": "Verification of transitions, debugging distributed runs, any claim that a computation is deterministic.",
      "syntax": [
        {
          "label": "Law 4 (TRVM/LAWS.md)",
          "path": "TRVM/LAWS.md",
          "start": "### Law 4",
          "count": 3
        }
      ],
      "takeaways": [
        {
          "from": "animation",
          "text": "Two players, identical films — and a '?' where the fidelity number would be."
        },
        {
          "from": "syntax",
          "text": "A cost without its reduction strategy is a rumour (Law 4); a replay without its strategy is not exact."
        },
        {
          "from": "literature",
          "text": "Deterministic replay (rr), event sourcing, and the reproducible-builds movement."
        },
        {
          "from": "witness",
          "text": "STATED with '?': no receipt states a fidelity, and the page says so instead of inventing one."
        }
      ],
      "wrl": {
        "note": "A sealed world whose film TRVM reduces; the page cannot run the film — reduction lives in TRVM, not in wrl.js."
      },
      "up": "UP-023",
      "limit": "No receipt stating a fidelity percentage was ever located (v0.2 review, finding 7), which is why this page carries a '?' where that number would go. TRVM's film replay is not verified by this build.",
      "next_rung": "in_tree: locate or produce the receipt. The claim is older than the search for its evidence, which is the defect this field exists to expose.",
      "derived": {
        "label": "STATED",
        "CHECKABLE": false,
        "RUNNABLE": false,
        "EXECUTED": false,
        "STAGED": false,
        "REPRODUCED": false,
        "PUBLISHED": true,
        "next_rung_name": "in_tree",
        "why": [
          {
            "ok": false,
            "text": "a witness is named"
          },
          {
            "ok": false,
            "text": "its evidence kind is one the ledger already uses"
          },
          {
            "ok": false,
            "text": "the witness path resolves in this tree"
          },
          {
            "ok": false,
            "text": "its rung is in_tree or above"
          },
          {
            "ok": false,
            "text": "a run is recorded for these exact bytes"
          },
          {
            "ok": true,
            "text": "no claim is cited that could be REFUTED"
          },
          {
            "ok": false,
            "text": "a counterexample is shipped (required once WITNESSED)"
          },
          {
            "ok": false,
            "text": "not staged on this site, so it cannot run from the page"
          }
        ],
        "related_closure": [
          "cross-machine-skill-replay",
          "meaning-is-a-hash"
        ],
        "live_run": null,
        "counterexample_strength": null,
        "execution": null,
        "claim_statuses": [],
        "cell_statuses": []
      }
    },
    {
      "id": "cross-machine-skill-replay",
      "kind": "pattern",
      "name": "Cross-Machine Skill Replay",
      "family": "world",
      "invariant": "A skill taught on machine A replays on machine B with the declared fidelity; the InteractionTrace is the unit of transfer.",
      "cells": [],
      "claims": [],
      "witness": {
        "registry": "site",
        "repo": "opensentience.org",
        "path": "opensentience.org/_rebuild/data/receipts.json",
        "shape": "card",
        "evidence_kind": "measurement",
        "rung": "in_tree",
        "rung_source": "a receipt CARD on the homepage; the run behind it was not opened by this build",
        "staged": false
      },
      "prior_art": {
        "works": [
          {
            "work": "OS-011 Embodiment",
            "relation": "partial-overlap",
            "overlap": "the tree's own protocol for a skill that crosses bodies",
            "difference": "OS-011 is a protocol at the spec rung; this pattern is the shape it would need"
          },
          {
            "work": "Record-and-replay in RPA",
            "relation": "contrasting-solution",
            "overlap": "a recorded interaction re-performed on another machine",
            "difference": "RPA replays coordinates and windows; the pattern requires the skill to survive a different body"
          }
        ],
        "novelty_not_claimed": "Nothing is claimed as achieved. v0.1 of this plan conflated this with exact-replay; they are different chapters and the conflation is recorded so it is not repeated.",
        "prose": "OS-011 Embodiment; record-and-replay in RPA. v0.1 conflated this with exact-replay."
      },
      "realizations": [
        "opensentience.org/_rebuild/data/receipts.json"
      ],
      "failure_mode": "replica-theater",
      "related": [
        "exact-replay"
      ],
      "scene": "cross-machine-skill-replay",
      "headline": "A skill taught on machine A replays on machine B with the declared fidelity; the InteractionTrace is the unit of transfer.",
      "explanatory": "An embodied skill — a sequence of observations and actions against a body — is recorded as a trace and replayed elsewhere. What crosses machines is the trace, not the machine. The homepage carries a receipt card for this at 100 % fidelity; this build reports the card and did not open the run behind it.",
      "technical": "OS-011 Embodiment: InteractionTrace → replay; the receipt card in opensentience.org/_rebuild/data/receipts.json reads 'Cross-machine replay · 100 % fidelity · teach a skill on machine A, replay it on machine B'. STATED: a card is a claim about a receipt, and the receipt was not opened by the patterns build. Distinct from Exact Replay (a film of a world).",
      "problem": "Skills are taught to one body and die with it. Robotic process automation records screen coordinates and breaks on the next monitor. The unit of transfer is either too low (pixels) or too high (a prose description) to replay.",
      "forces": "A trace must be body-independent enough to replay and body-specific enough to act. Fidelity has to be declared before it is measured, or the measurement decides what fidelity meant. And a card on a homepage is not a receipt, however green.",
      "construction": "Record observations and actions as a trace with the body's affordances named. Declare fidelity. Replay on a second body. Publish the run, not only the card.",
      "transformations": {
        "allowed": [
          "replaying on a body with the same declared affordances",
          "declaring a lower fidelity for a different body"
        ],
        "refused": [
          "a fidelity card whose run is not published beside it",
          "replaying pixels and calling it a skill"
        ]
      },
      "consequences": "Skills become portable artifacts. The honest status: STATED, because this page reports a card it did not verify.",
      "analogy": "Sheet music versus a recording. The recording replays one performance; the sheet music replays on any instrument that can read it, at the fidelity the arrangement allows.",
      "applicability": "Agent skills, RPA, robotics, the Workbench's SkillBundles.",
      "syntax": [
        {
          "label": "The receipt card, verbatim (homepage data)",
          "path": "opensentience.org/_rebuild/data/receipts.json",
          "start": "\"metric\": \"Cross-machine replay\"",
          "count": 5
        }
      ],
      "takeaways": [
        {
          "from": "animation",
          "text": "The trace moved; the machine stayed."
        },
        {
          "from": "syntax",
          "text": "A card names a metric, a value and a note; the run behind it is a separate artifact this build did not open."
        },
        {
          "from": "literature",
          "text": "OS-011 Embodiment; RPA's record-and-replay is the failure mode being answered."
        },
        {
          "from": "witness",
          "text": "STATED: shape 'card' carries no execution, and the derivation says so."
        }
      ],
      "wrl": {
        "note": "No core-role encoding: an InteractionTrace is OS-011's artifact, not a WRL world."
      },
      "up": "UP-024",
      "limit": "Nothing is achieved. OS-011 Embodiment is at the spec rung; this pattern is the shape that protocol would need, written before any of it exists.",
      "next_rung": "live_local: one skill recorded on one machine and re-performed on another, played back here, with both bodies described well enough that the difference between them is visible rather than asserted.",
      "derived": {
        "label": "STATED",
        "CHECKABLE": true,
        "RUNNABLE": false,
        "EXECUTED": false,
        "STAGED": false,
        "REPRODUCED": false,
        "PUBLISHED": true,
        "next_rung_name": "live_local",
        "why": [
          {
            "ok": true,
            "text": "a witness is named"
          },
          {
            "ok": true,
            "text": "its evidence kind is one the ledger already uses (measurement)"
          },
          {
            "ok": true,
            "text": "the witness path resolves in this tree"
          },
          {
            "ok": true,
            "text": "its rung is in_tree or above (in_tree)"
          },
          {
            "ok": false,
            "text": "a run is recorded for these exact bytes — shape card carries no execution"
          },
          {
            "ok": true,
            "text": "no claim is cited that could be REFUTED"
          },
          {
            "ok": false,
            "text": "a counterexample is shipped (required once WITNESSED)"
          },
          {
            "ok": false,
            "text": "not staged on this site, so it cannot run from the page"
          }
        ],
        "related_closure": [
          "exact-replay"
        ],
        "live_run": null,
        "counterexample_strength": null,
        "execution": null,
        "claim_statuses": [],
        "cell_statuses": []
      }
    },
    {
      "id": "confidentiality-under-content-addressing",
      "kind": "pattern",
      "name": "Confidentiality Under Content Addressing",
      "family": "world",
      "invariant": null,
      "cells": [],
      "claims": [],
      "witness": null,
      "prior_art": {
        "works": [
          {
            "work": "Convergent encryption and its known leaks",
            "relation": "antecedent",
            "overlap": "the confirmation-of-a-file attack is exactly this tension, already described",
            "difference": "none — the literature's answer is that the tension is real"
          }
        ],
        "novelty_not_claimed": "Everything. studbook §10.2 is an OPEN BLOCKER: if the key is the hash of the content, knowing the content is knowing the key. The book publishes the refusal, not a pattern.",
        "prose": "OPEN BLOCKER (studbook §10): if the key is the hash of the content, knowing the content is knowing the key. Convergent encryption and its known leaks are the prior art. The book publishes the refusal, not a pattern."
      },
      "realizations": [
        "studbook/docs/spec/README.md:260"
      ],
      "related": [
        "meaning-is-a-hash"
      ],
      "scene": "confidentiality-under-content-addressing",
      "headline": "If the key is the hash of the content, knowing the content is knowing the key — and where confidentiality comes from is unruled.",
      "explanatory": "Content addressing makes identity honest and access control hostile. Anyone who holds the content can derive its key and prove they hold it; a store that is keyed by content cannot hide that a given content exists. Until this is ruled, studbook cannot hold anything with a user in it. This page publishes the question, not a design.",
      "technical": "studbook §10.2, the named blocker: 'Where confidentiality comes from, given §6.2.' Convergent encryption and its known leaks (confirmation-of-a-file, learn-the-remaining-information) are the prior art. OPEN; the pattern registry has no label for open, so this record derives as STATED via its realizations. No invariant is stated because none has been ruled.",
      "problem": "A store that refuses rows whose provenance does not check out needs content addressing; a store that holds a user's data needs to keep the existence of a content secret from readers who could guess it. The two requirements pull apart at exactly the key.",
      "forces": "Every mitigation — salted keys, per-user namespaces, encrypting before hashing — weakens the property that made content addressing worth having: that two holders of the same content agree on its key. The ruling is about which property to give up, for which data.",
      "construction": "Not yet. What can be done: name the requirement (§6.2), name the conflict (§10.2), and refuse to hold user data until ruled.",
      "consequences": "The data layer stays at the spec rung. The book's contribution is to publish the refusal in a pattern-shaped slot so the gap is as findable as the patterns.",
      "analogy": "A library that files every book by its full text. Nothing can be mis-shelved — and anyone who can recite a page can prove which book is on the shelf.",
      "applicability": "Any content-addressed store that will hold data with a person in it.",
      "syntax": [
        {
          "label": "The blocker, verbatim (studbook §10)",
          "path": "studbook/docs/spec/README.md",
          "start": "knowing the content",
          "count": 1
        }
      ],
      "takeaways": [
        {
          "from": "animation",
          "text": "The reader who knows the content derived the key; the one who did not could not — and the first can prove it."
        },
        {
          "from": "syntax",
          "text": "§10.2 is a numbered ruling the spec says must precede implementation."
        },
        {
          "from": "literature",
          "text": "Convergent encryption; Tahoe-LAFS's capability model is the closest attempt at both properties at once."
        },
        {
          "from": "witness",
          "text": "OPEN: no pattern, one ruling, published as the question."
        }
      ],
      "wrl": {
        "note": "No encoding; the open ruling is about keys, not topology."
      },
      "up": "UP-025",
      "limit": "An OPEN ruling, not a pattern. studbook §10.2: if the key is the hash of the content, knowing the content is knowing the key. The book publishes the refusal.",
      "next_rung": "A ruling on where confidentiality comes from. Until then studbook cannot hold anything with a user in it, and this page cannot become a pattern.",
      "derived": {
        "label": "STATED",
        "CHECKABLE": false,
        "RUNNABLE": false,
        "EXECUTED": false,
        "STAGED": false,
        "REPRODUCED": false,
        "PUBLISHED": true,
        "next_rung_name": "in_tree",
        "why": [
          {
            "ok": false,
            "text": "a witness is named"
          },
          {
            "ok": false,
            "text": "its evidence kind is one the ledger already uses"
          },
          {
            "ok": false,
            "text": "the witness path resolves in this tree"
          },
          {
            "ok": false,
            "text": "its rung is in_tree or above"
          },
          {
            "ok": false,
            "text": "a run is recorded for these exact bytes"
          },
          {
            "ok": true,
            "text": "no claim is cited that could be REFUTED"
          },
          {
            "ok": false,
            "text": "a counterexample is shipped (required once WITNESSED)"
          },
          {
            "ok": false,
            "text": "not staged on this site, so it cannot run from the page"
          }
        ],
        "related_closure": [
          "meaning-is-a-hash"
        ],
        "live_run": null,
        "counterexample_strength": null,
        "execution": null,
        "claim_statuses": [],
        "cell_statuses": []
      }
    },
    {
      "id": "established-not-known",
      "kind": "definition",
      "name": "Established, Not Known",
      "family": "agency",
      "invariant": null,
      "cells": [],
      "claims": [],
      "witness": null,
      "prior_art": {
        "works": [
          {
            "work": "Byzantine observation",
            "relation": "antecedent",
            "overlap": "an observation can be stale, forged or partial",
            "difference": "the Byzantine literature asks what a group can agree; this asks what one locus may say"
          },
          {
            "work": "Super bot spec — STALE ≠ UNESTABLISHED",
            "relation": "partial-overlap",
            "overlap": "the tree's own hard-won form of the distinction",
            "difference": "stated for one runtime; generalized here"
          }
        ],
        "novelty_not_claimed": "Epistemic caution about observation is not new. This is a definition, and definitions carry no rung.",
        "prose": "Byzantine observation: an observation can be stale, forged or partial; 'establish' names what survives that. STALE ≠ UNESTABLISHED (Super bot spec)."
      },
      "realizations": [
        "AGENCY.md §4"
      ],
      "related": [
        "active-locus",
        "understanding-boundary"
      ],
      "scene": "established-not-known",
      "headline": "Establish, never know or detect: an observation can be stale, forged or partial, and establishing is what survives that.",
      "explanatory": "Operational state is established, not known. To establish is to take an observation through freshness, provenance and completeness before it becomes state a locus acts on. A stale observation is still established — it was once true and is marked old. An unestablished one was never an observation at all. 'Position' is deprecated as the technical term; say established operational state.",
      "technical": "AGENCY.md §4 vocabulary. STALE ≠ UNESTABLISHED (Super bot spec). This is vocabulary, so its counterexample is a sentence and its nearest witness is the ontology lint; the record is a definition and carries no rung.",
      "problem": "'The agent detected that the door is locked' reads as fact and is a reading of a reading. Copy written with know and detect grants observations a certainty they never earned, and systems built on that copy act on forgeries with the same confidence as on truths.",
      "forces": "Establish is a longer word and a longer process, and it produces a state that can go stale — which readers experience as the system being unsure. Know is shorter and never unsure, which is the problem.",
      "construction": "Vocabulary: establish, established operational state, stale, unestablished. Retire know, detect, position. Run the lint.",
      "transformations": {
        "allowed": [
          "marking an established state stale",
          "refusing an observation with no provenance"
        ],
        "refused": [
          "know / detect in technical copy",
          "treating stale as unestablished, or the reverse"
        ]
      },
      "consequences": "The system's confidence becomes a property of its evidence rather than its prose.",
      "analogy": "A ship's log entry versus a rumour on deck. The log entry can be old; the rumour was never an observation.",
      "applicability": "Every technical sentence about what an agent has observed.",
      "syntax": [
        {
          "label": "Where the vocabulary is set (AGENCY.md §4)",
          "path": "AGENCY.md",
          "start": "### State does not grant authority",
          "count": 1
        }
      ],
      "takeaways": [
        {
          "from": "animation",
          "text": "The naive reader knew the stale reading and the forgery alike; the establishing reader marked one stale and refused the other."
        },
        {
          "from": "syntax",
          "text": "Two words retired, one adopted; the difference is whether the sentence can be wrong."
        },
        {
          "from": "literature",
          "text": "Byzantine observation; Gettier's problem, if you like — a true belief with the wrong provenance."
        },
        {
          "from": "witness",
          "text": "A definition; no rung; the lint on the neighbouring pattern is the falsifier."
        }
      ],
      "wrl": {
        "note": "A definition; no world."
      },
      "up": "UP-026",
      "limit": "A definition. It carries no rung (AGENCY.md §6) and establishes only what the book means by 'established'. STALE ≠ UNESTABLISHED is the Super bot spec's, and it is cited, not derived here.",
      "next_rung": "Definitions do not climb. The test is whether the agency chapters can state their invariants using this word without needing a second one.",
      "derived": {
        "label": null,
        "CHECKABLE": false,
        "RUNNABLE": false,
        "EXECUTED": false,
        "STAGED": false,
        "REPRODUCED": false,
        "PUBLISHED": true,
        "next_rung_name": "in_tree",
        "why": [
          {
            "ok": null,
            "text": "kind is definition — carries no evidence rung (AGENCY.md §6)"
          }
        ],
        "related_closure": [
          "active-locus",
          "understanding-boundary"
        ],
        "live_run": null,
        "counterexample_strength": null,
        "execution": null,
        "claim_statuses": [],
        "cell_statuses": []
      }
    },
    {
      "id": "state-does-not-grant-authority",
      "kind": "pattern",
      "name": "State Does Not Grant Authority",
      "family": "agency",
      "invariant": "Admissible action = f(established state, explicit grant, policy, contracts), never f(established state) alone; a fact about a locus never constitutes a power.",
      "cells": [],
      "claims": [],
      "witness": {
        "registry": "lint",
        "repo": ".",
        "path": "scripts/check-messaging-language.mjs",
        "shape": "lint",
        "evidence_kind": "counterexample",
        "rung": "in_tree",
        "rung_source": "rule class STATE_DOES_NOT_ISSUE_AUTHORITY",
        "cmd": "node scripts/check-messaging-language.mjs",
        "cwd": ".",
        "staged": false
      },
      "counterexample": {
        "shape": "lint",
        "sentence": "the authority that state grants",
        "expected": "REFUSED",
        "lint_allow": "lint-allow:STATE_DOES_NOT_ISSUE_AUTHORITY — a lint counterexample must print the retired phrase to be one"
      },
      "prior_art": {
        "works": [
          {
            "work": "Object-capability discipline (Miller)",
            "relation": "antecedent",
            "overlap": "a fact about a subject is not a permission",
            "difference": "none claimed — AGENCY.md §4 states it as 'fact about me ⇒ power is ambient authority with an extra step'"
          }
        ],
        "novelty_not_claimed": "This is Miller's argument restated for loci. Under R7's family criterion it may belong in the locus family rather than agency; that placement is unruled.",
        "prose": "Object-capability discipline (Miller); 'fact about me ⇒ power is ambient authority with an extra step' (AGENCY.md §4). Under R7's criterion this may belong in the locus family."
      },
      "realizations": [
        "AGENCY.md §4",
        "scripts/messaging-rules.json STATE_DOES_NOT_ISSUE_AUTHORITY"
      ],
      "failure_mode": "ambient-authority",
      "related": [
        "capability-bounded-composition"
      ],
      "scene": "state-does-not-grant-authority",
      "headline": "A fact about a locus never constitutes a power.",
      "explanatory": "An established state may justify or constrain the issuance of authority; it never is the grant. Admissible action is a function of established state, an explicit grant, the governing policy and the contracts in force — never of state alone. The sentence that puts the grant inside the state is retired in AGENCY.md §4, and a gate refuses every paraphrase of it.",
      "technical": "AGENCY.md §4: the chain is established state + policy + explicit grant → admissible authority. Admissible action = f(established state, explicit authority, policy, contracts). The lint class STATE_DOES_NOT_ISSUE_AUTHORITY rejects the paraphrases; the invariants table's 'authority' field means the authority consequence an invariant is proposed to justify, not one it issues. Under ruling R7's criterion this pattern may belong to the locus family.",
      "problem": "'I am the admin, therefore I may.' Every system that derives permission from an attribute of the subject has built ambient authority with an extra step: the attribute is observed once and then stands in for a grant forever. The Periodic Table shipped three paraphrases of it before the lint existed.",
      "forces": "Attributes are cheap to check and grants are paperwork. Policies genuinely do depend on state — a grant may have preconditions the state must satisfy — which is why the sentence is so easy to write wrong: the state is in the chain, just not at the end of it.",
      "construction": "Keep grants as first-class objects with scope and policy preconditions. Evaluate admissibility as a function of the grant and the state, not of the state. Retire the sentences that skip the grant, list them, and run the list over every page that talks about authority.",
      "transformations": {
        "allowed": [
          "a policy whose preconditions a state satisfies",
          "narrowing a grant's scope",
          "revoking a grant while the state persists"
        ],
        "refused": [
          "the sentence that makes a state the source of a grant (retired; the gate lists its paraphrases)",
          "deriving admissibility from state alone",
          "a field named authority read as proof that nothing exceeds it"
        ]
      },
      "consequences": "Authority becomes a thing that can be revoked, scoped and audited separately from the facts that justified it. The counterexample on this page is a sentence, and that is the point: a vocabulary pattern's falsifier is a lint.",
      "analogy": "A surgeon's licence is a grant; being a surgeon is a state. The licence can be suspended while the skill remains, and the skill never operated on anyone by itself.",
      "applicability": "Access control, agent authority, capability tokens, and every paragraph of copy about any of them.",
      "syntax": [
        {
          "label": "The trap and the chain, verbatim (AGENCY.md §4)",
          "path": "AGENCY.md",
          "start": "### State does not grant authority",
          "count": 6
        },
        {
          "label": "The lint class, from the rules the gate runs",
          "path": "scripts/messaging-rules.json",
          "start": "\"id\": \"STATE_DOES_NOT_ISSUE_AUTHORITY\"",
          "count": 5
        }
      ],
      "takeaways": [
        {
          "from": "animation",
          "text": "The established fact was refused alone and admitted with a scoped grant beside it."
        },
        {
          "from": "syntax",
          "text": "Admissible action = f(state, grant, policy, contracts) — the state is an argument, never the function."
        },
        {
          "from": "literature",
          "text": "Object-capability discipline: authority is what you hold, not what you are."
        },
        {
          "from": "witness",
          "text": "The gate rejected the counterexample sentence in this very registry until it was quarantined by rule id."
        }
      ],
      "wrl": {
        "note": "No core-role encoding; a grant is not a role."
      },
      "up": "UP-027",
      "limit": "Miller's argument restated for loci. It does not establish that any component in this tree refuses a state-derived authority claim, and under R7's criterion its family placement is itself unruled.",
      "next_rung": "live_local: a refusal on this page when authority is requested on the strength of a fact about the requester. The invariant is Miller's; what is missing is a place a reader can watch it hold.",
      "derived": {
        "label": "WITNESSED",
        "CHECKABLE": true,
        "RUNNABLE": true,
        "EXECUTED": true,
        "STAGED": false,
        "REPRODUCED": false,
        "PUBLISHED": true,
        "next_rung_name": "live_local",
        "why": [
          {
            "ok": true,
            "text": "a witness is named"
          },
          {
            "ok": true,
            "text": "its evidence kind is one the ledger already uses (counterexample)"
          },
          {
            "ok": true,
            "text": "the witness path resolves in this tree"
          },
          {
            "ok": true,
            "text": "its rung is in_tree or above (in_tree)"
          },
          {
            "ok": true,
            "text": "a run is recorded for these exact bytes"
          },
          {
            "ok": true,
            "text": "no claim is cited that could be REFUTED"
          },
          {
            "ok": true,
            "text": "a counterexample is shipped (required once WITNESSED)"
          },
          {
            "ok": false,
            "text": "not staged on this site, so it cannot run from the page"
          }
        ],
        "related_closure": [
          "capability-bounded-composition"
        ],
        "live_run": null,
        "counterexample_strength": null,
        "execution": {
          "at": "2026-09-11T15:27:41.066Z",
          "host": "PX13",
          "sha256": "4c1baac1ee7b0a3985fc5d8bc206009f42b5b114bf378797059ecdf873ec0d04",
          "repo_head": "92d99bf0f69f23bafb2dad7b1312ed2f3beb2164"
        },
        "claim_statuses": [],
        "cell_statuses": []
      }
    },
    {
      "id": "evidence-before-claim",
      "kind": "pattern",
      "name": "Evidence Before Claim",
      "family": "agency",
      "invariant": "A public proposition is admitted only with a named witness that exists; a claim whose witness is absent, whose antecedent is missing, or whose cell binding contradicts the table is refused.",
      "cells": [],
      "claims": [],
      "witness": {
        "registry": "ledger",
        "repo": ".",
        "path": "scripts/check-claim-ledger.mjs",
        "shape": "side-effect",
        "evidence_kind": "constructive_witness",
        "rung": "in_tree",
        "rung_source": "runs over CLAIM_LEDGER.json (190 claims) and refuses; exit code is the verdict",
        "cmd": "node scripts/check-claim-ledger.mjs",
        "cwd": ".",
        "staged": false
      },
      "counterexample": {
        "shape": "refusal",
        "path": "scripts/check-claim-ledger.mjs",
        "marker": "witness file does not exist",
        "expected": "REFUSED"
      },
      "prior_art": {
        "works": [
          {
            "work": "Toulmin — warrant and backing",
            "relation": "antecedent",
            "overlap": "a claim is admissible only with its warrant",
            "difference": "Toulmin analyses arguments; this is enforced by a build"
          },
          {
            "work": "Pollock, defeaters",
            "relation": "antecedent",
            "overlap": "what would withdraw the claim must be stated",
            "difference": "none claimed"
          },
          {
            "work": "Assurance cases (GSN)",
            "relation": "close-analogue",
            "overlap": "a structured argument tied to its evidence",
            "difference": "GSN is a notation for a document; here the tie is mechanical and the build refuses without it"
          }
        ],
        "novelty_not_claimed": "The phrase is absent from the tree; the mechanism (DOCTRINE.md rule 4 plus the ledger) is not. Argumentation theory is the prior art and it is older than the stack.",
        "prose": "Toulmin's warrant/backing; Pollock defeaters; assurance cases (GSN). The phrase is absent from the tree; the mechanism (DOCTRINE.md rule 4 + the ledger) is not."
      },
      "realizations": [
        "DOCTRINE.md rule 4",
        "CLAIM_LEDGER.json"
      ],
      "failure_mode": "agent-omniscience",
      "related": [
        "refusal-gate",
        "descent-is-not-dependence"
      ],
      "scene": "evidence-before-claim",
      "headline": "A proposition is admitted only with a named witness that exists.",
      "explanatory": "Every public claim in this stack is a record in a ledger with a statement, a status from a fixed vocabulary, an evidence kind, and the witnesses that back it. A gate refuses a claim whose witness file is missing, whose conditional has no antecedent, or whose cell binding contradicts the invariants table. The gate's exit code is the verdict, and no report overrides it.",
      "technical": "DOCTRINE.md rule 4 (measure before you claim, and say how); CLAIM_LEDGER.json, 190 claims across eight statuses; scripts/check-claim-ledger.mjs refuses a witness that does not exist, a CONDITIONAL with no antecedent, a binding that contradicts the table, and a witness whose relative-import closure does not resolve. 178 of 190 claims carry prior_art; one says NOT SEARCHED. This catalog's labels are derived by a gate of the same shape.",
      "problem": "Status reports say done. Percentages stand in for evidence. A number typed beside a claim is quoted three times before anyone asks where it came from — this tree has paid that price with law counts, migration counts and a '64 of 116'. An invented number is worse than a missing one because it stops the question being asked.",
      "forces": "Writing a witness is slower than writing a sentence, and a gate that refuses your own claim is unpleasant on the day. The pressure to soften the vocabulary — a checkmark, a 'mostly' — is constant. The rule holds by making the exit code the answer and by making '?' an acceptable one.",
      "construction": "Keep one ledger of claims. Fix the status vocabulary and forbid every other word. Require a witness path per claim and a gate that opens it. Derive every count on every page from the ledger; never type one.",
      "transformations": {
        "allowed": [
          "downgrading a status when in doubt",
          "adding a witness and re-running the gate",
          "answering '?' or 'status unknown'"
        ],
        "refused": [
          "a status word outside the vocabulary",
          "a witness that is described but not on disk",
          "a count typed where it is displayed (A Number in Two Places)"
        ]
      },
      "consequences": "Claims become things a reader can check rather than believe. The book you are reading is built this way: its labels are derived, its counts are joined, and its own first draft was caught by the same discipline with 32 labels over 30 rows.",
      "analogy": "A courtroom exhibit list. A witness who is named but never appears does not testify, however good the story.",
      "applicability": "Any document that makes status claims: roadmaps, READMEs, marketing pages, this catalog.",
      "syntax": [
        {
          "label": "Rule 4, verbatim (DOCTRINE.md)",
          "path": "DOCTRINE.md",
          "start": "4. **Measure before you claim",
          "count": 4
        },
        {
          "label": "The refusal, in the gate this page ran",
          "path": "scripts/check-claim-ledger.mjs",
          "start": "witness file does not exist",
          "count": 1
        }
      ],
      "takeaways": [
        {
          "from": "animation",
          "text": "The claim was refused without its witness and admitted with one, at the status the evidence earned."
        },
        {
          "from": "syntax",
          "text": "The gate's exit code is the verdict; a report cannot override it."
        },
        {
          "from": "literature",
          "text": "Toulmin's warrant and backing; assurance cases; Pollock's defeaters — the ledger has a defeater field of its own."
        },
        {
          "from": "witness",
          "text": "check-claim-ledger.mjs ran today over 190 claims, exit 0, with a receipt on this page."
        }
      ],
      "wrl": {
        "note": "No core-role encoding; the ledger gate is over claims, not worlds."
      },
      "up": "UP-028",
      "limit": "The mechanism exists (DOCTRINE.md rule 4 and the ledger) and the phrase does not. This page establishes that this build refuses an unwarranted claim in its own registry — not that the tree's other surfaces do.",
      "next_rung": "live_local: the prose gate run from the page over text a reader types, rather than at build time over text we wrote. That the gate refuses our own registry is evidence about us, not about the rule.",
      "derived": {
        "label": "WITNESSED",
        "CHECKABLE": true,
        "RUNNABLE": true,
        "EXECUTED": true,
        "STAGED": false,
        "REPRODUCED": false,
        "PUBLISHED": true,
        "next_rung_name": "live_local",
        "why": [
          {
            "ok": true,
            "text": "a witness is named"
          },
          {
            "ok": true,
            "text": "its evidence kind is one the ledger already uses (constructive_witness)"
          },
          {
            "ok": true,
            "text": "the witness path resolves in this tree"
          },
          {
            "ok": true,
            "text": "its rung is in_tree or above (in_tree)"
          },
          {
            "ok": true,
            "text": "a run is recorded for these exact bytes"
          },
          {
            "ok": true,
            "text": "no claim is cited that could be REFUTED"
          },
          {
            "ok": true,
            "text": "a counterexample is shipped (required once WITNESSED)"
          },
          {
            "ok": false,
            "text": "not staged on this site, so it cannot run from the page"
          }
        ],
        "related_closure": [
          "descent-is-not-dependence",
          "refusal-gate"
        ],
        "live_run": null,
        "counterexample_strength": {
          "strength": "marker",
          "occurrences": 1,
          "law": null
        },
        "execution": {
          "at": "2026-09-11T15:26:22.369Z",
          "host": "PX13",
          "sha256": "33e6af41713b45bee9d581fc069dd614a0ca831f985cb3ee51f84f0bdee88064",
          "repo_head": "92d99bf0f69f23bafb2dad7b1312ed2f3beb2164"
        },
        "claim_statuses": [],
        "cell_statuses": []
      }
    },
    {
      "id": "refusal-gate",
      "kind": "pattern",
      "name": "Refusal Gate",
      "family": "agency",
      "invariant": "Below material sufficiency the page is not written and the reason is published; a check that can be satisfied by constructing its own argument is not a check.",
      "cells": [],
      "claims": [],
      "witness": null,
      "prior_art": {
        "works": [
          {
            "work": "Fail-closed defaults",
            "relation": "antecedent",
            "overlap": "the safe outcome on missing information is refusal",
            "difference": "none claimed"
          },
          {
            "work": "Popperian falsifiability as an admission rule",
            "relation": "close-analogue",
            "overlap": "admit only what could be refused",
            "difference": "philosophy of science, applied here to a build gate"
          }
        ],
        "novelty_not_claimed": "Fail-closed is a first principle of security engineering. The Academy refusal log is MOCK (ACADEMY.md:79); alkeyword's refusal rule is the live instance, and only that one counts.",
        "prose": "Fail-closed defaults; Popperian falsifiability as an admission rule. The Academy refusal log is MOCK (ACADEMY.md:79); alkeyword's refusal rule is the live instance."
      },
      "realizations": [
        "ACADEMY.md §Read",
        "alkeyword.com/docs/spec/README.md §3.2"
      ],
      "failure_mode": "agent-omniscience",
      "related": [
        "evidence-before-claim",
        "refusing-join"
      ],
      "scene": "refusal-gate",
      "headline": "Below material sufficiency the page is not written, and the reason is published.",
      "explanatory": "A correct agent sometimes advances the system by not acting. A generator that writes a page from thin material produces something that reads well and cites nothing; the gate refuses it and publishes why. The refusals are the feature no autoblog can copy. A check that can be satisfied by constructing its own argument is not a check.",
      "technical": "alkeyword's refusal rule (alkeyword.com/docs/spec/README.md §3.2), inherited by Academy's Read layer without relaxation. The Academy refusal log is a MOCK: real format, illustrative entries, counts not measured against a live crawl (ACADEMY.md). Its worked example: a statistics page held because the corpus contradicted itself on a law count (103 vs 116), resolved by running both suites. This book's registry runs a gate of the same shape.",
      "problem": "Content generators never refuse. Every prompt yields a page; the pages that had nothing behind them look exactly like the ones that did. Readers learn to trust none of them.",
      "forces": "A refusal is a visible gap on a site that wants to look complete. Sufficiency needs a definition — source spans per factual sentence — that costs the generator most of its throughput. And a mock log that reads as measured is a refusal gate lying about itself.",
      "construction": "Define material sufficiency. Trace every factual sentence to a source span. Refuse below the threshold and publish the reason in the same place the page would have been. Keep the refusal log measured, or label it MOCK.",
      "transformations": {
        "allowed": [
          "holding a page until a contradiction in the corpus is resolved",
          "publishing a refusal where a page was expected"
        ],
        "refused": [
          "writing from a single sentence",
          "a refusal log that reads as measured when it is illustrative"
        ]
      },
      "consequences": "What is published can be trusted because what was not published is visible. The honest status: STATED — the live instance is alkeyword's; the log that would witness it here is a mock.",
      "analogy": "A newspaper that prints, in the space where a story would have run, 'we could not confirm this' — and is read for exactly that reason.",
      "applicability": "Generated documentation, grounded articles, this catalog's thin records.",
      "syntax": [
        {
          "label": "The rule Academy inherits, in its own words (ACADEMY.md)",
          "path": "ACADEMY.md",
          "start": "sufficiency",
          "count": 2
        }
      ],
      "takeaways": [
        {
          "from": "animation",
          "text": "The thin page was refused with its reason published; the sourced one was written."
        },
        {
          "from": "syntax",
          "text": "The gate lives in the alkeyword spec §3.2 and is inherited without relaxation."
        },
        {
          "from": "literature",
          "text": "Popper: a claim that cannot be refused is not a claim; fail-closed defaults in security."
        },
        {
          "from": "witness",
          "text": "STATED: the Academy refusal log is MOCK and this page says so; the thin records in this catalog are the same discipline applied to itself."
        }
      ],
      "wrl": {
        "note": "No core-role encoding; the gate is on prose sufficiency."
      },
      "up": "UP-029",
      "limit": "The Academy refusal log is MOCK (ACADEMY.md:79) and does not count. alkeyword's refusal rule is the live instance, and it is one instance in one lane.",
      "next_rung": "in_tree: a refusal log in this catalog that can fail. The Academy's is MOCK (ACADEMY.md:79) and does not count; alkeyword's is live and is one instance in one lane, neither of them here.",
      "derived": {
        "label": "STATED",
        "CHECKABLE": false,
        "RUNNABLE": false,
        "EXECUTED": false,
        "STAGED": false,
        "REPRODUCED": false,
        "PUBLISHED": true,
        "next_rung_name": "in_tree",
        "why": [
          {
            "ok": false,
            "text": "a witness is named"
          },
          {
            "ok": false,
            "text": "its evidence kind is one the ledger already uses"
          },
          {
            "ok": false,
            "text": "the witness path resolves in this tree"
          },
          {
            "ok": false,
            "text": "its rung is in_tree or above"
          },
          {
            "ok": false,
            "text": "a run is recorded for these exact bytes"
          },
          {
            "ok": true,
            "text": "no claim is cited that could be REFUTED"
          },
          {
            "ok": false,
            "text": "a counterexample is shipped (required once WITNESSED)"
          },
          {
            "ok": false,
            "text": "not staged on this site, so it cannot run from the page"
          }
        ],
        "related_closure": [
          "evidence-before-claim",
          "refusing-join"
        ],
        "live_run": null,
        "counterexample_strength": null,
        "execution": null,
        "claim_statuses": [],
        "cell_statuses": []
      }
    },
    {
      "id": "intervention-provenance",
      "kind": "pattern",
      "name": "Intervention Provenance",
      "family": "agency",
      "invariant": "Every intervention on the world carries the identity of the Worker and generation that made it and the evidence it acted on; an intervention that cannot be attributed is not admissible.",
      "cells": [
        {
          "ref": "17",
          "modality": "necessary"
        }
      ],
      "claims": [],
      "witness": null,
      "prior_art": {
        "works": [
          {
            "work": "W3C PROV",
            "relation": "antecedent",
            "overlap": "a standard vocabulary for who did what to what",
            "difference": "PROV records provenance; the pattern requires the record to be re-observable"
          },
          {
            "work": "Audit logs",
            "relation": "realization",
            "overlap": "append-only record of intervention (cell 17)",
            "difference": "a log records the request; the pattern wants the effect re-observed"
          }
        ],
        "novelty_not_claimed": "Provenance standards exist and are better developed than this. The witness lives in super/, and the honest half of the record is that the re-observation it depends on does not exist — Pty::winsize() has zero callers.",
        "prose": "Audit logs; provenance (W3C PROV). Witness lives in super/; the honest half of the record is that the re-observation it depends on does not exist (Pty::winsize() has zero callers)."
      },
      "realizations": [
        "super/docs/reviews/D_1_3C_2D_2_INTERVENTION_PROVENANCE.md"
      ],
      "failure_mode": "agent-omniscience",
      "related": [
        "three-valued-outcome"
      ],
      "scene": "intervention-provenance",
      "headline": "Every intervention carries the Worker and generation that made it and the evidence it acted on; an unattributable intervention is inadmissible.",
      "explanatory": "Acting on a world someone else inhabits — a terminal, a filesystem, a user's machine — is admissible only when the action can be answered for: who, under which generation of authority, on what evidence. The operator-disclosure policy is keyed on Worker + generation because, when this was measured, no cross-peer terminal authority existed to key it on.",
      "technical": "Super D.1.3c·2d·2: outcome vocabulary APPLIED | REFUSED | INDETERMINATE (Three-Valued Outcome); provenance keyed on a Worker + generation. The same document records that the re-observation INDETERMINATE was to be repaired by does not exist — Pty::winsize() has zero callers — and refutes the predecessor round's settle-in-place design. Cell 17 (⊕ append-only) is the ledger property this depends on. Witness in super/, referenced not copied.",
      "problem": "An agent writes to a terminal. Later, something is different. Which action did it, under whose authority, because of what? Without provenance the answer is a log grep and a guess, and the guess is usually 'the agent'.",
      "forces": "Provenance costs a record per action and a key to attribute to. When the natural key (a terminal authority shared across peers) does not exist, the honest move is to key on what does — a Worker and its generation — and to say so, rather than invent the missing authority.",
      "construction": "Attach Worker, generation and evidence to every intervention before it is attempted. Append the outcome as one of three values. Never rewrite. Name the re-observation the design depends on and check it has callers.",
      "transformations": {
        "allowed": [
          "revoking a generation and refusing its later interventions",
          "appending observations beside an attempt"
        ],
        "refused": [
          "an intervention without a Worker and generation",
          "rewriting an outcome",
          "a repair path with zero callers presented as a property"
        ]
      },
      "consequences": "Interventions become answerable. The honest status: STATED, in a lane this book does not edit, with the specification's unimplemented dependency printed beside it.",
      "analogy": "A surgical count: every instrument signed in and out by name, and an operation that cannot account for one is not closed.",
      "applicability": "Agent runtimes acting on user machines, terminal possession, any actuator shared between principals.",
      "syntax": [
        {
          "label": "The three outcomes, where they are specified (super/docs/reviews)",
          "path": "super/docs/reviews/D_1_3C_2D_2_INTERVENTION_PROVENANCE.md",
          "start": "APPLIED",
          "count": 2
        }
      ],
      "takeaways": [
        {
          "from": "animation",
          "text": "The unattributed action was refused; the same action with Worker, generation and evidence was applied."
        },
        {
          "from": "syntax",
          "text": "The policy is keyed on Worker + generation because the authority it would rather key on did not exist."
        },
        {
          "from": "literature",
          "text": "W3C PROV; surgical counts; the audit log that is a precondition rather than a record."
        },
        {
          "from": "witness",
          "text": "STATED: the review in super/ specifies it and names its own unimplemented re-observation."
        }
      ],
      "wrl": {
        "note": "No core-role encoding; provenance is a field on a Film frame, not a route."
      },
      "up": "UP-030",
      "limit": "Cell 17 (append-only audit) is proved, which makes the record durable. The pattern asks for the EFFECT to be re-observed, and the honest half of this record is that the re-observation does not exist — Pty::winsize() has zero callers.",
      "next_rung": "in_tree: a caller for the re-observation, so that an intervention's effect is measured rather than assumed from its request.",
      "derived": {
        "label": "STATED",
        "CHECKABLE": false,
        "RUNNABLE": false,
        "EXECUTED": false,
        "STAGED": false,
        "REPRODUCED": false,
        "PUBLISHED": true,
        "next_rung_name": "in_tree",
        "why": [
          {
            "ok": false,
            "text": "a witness is named"
          },
          {
            "ok": false,
            "text": "its evidence kind is one the ledger already uses"
          },
          {
            "ok": false,
            "text": "the witness path resolves in this tree"
          },
          {
            "ok": false,
            "text": "its rung is in_tree or above"
          },
          {
            "ok": false,
            "text": "a run is recorded for these exact bytes"
          },
          {
            "ok": true,
            "text": "no claim is cited that could be REFUTED"
          },
          {
            "ok": false,
            "text": "a counterexample is shipped (required once WITNESSED)"
          },
          {
            "ok": false,
            "text": "not staged on this site, so it cannot run from the page"
          }
        ],
        "related_closure": [
          "three-valued-outcome"
        ],
        "live_run": null,
        "counterexample_strength": null,
        "execution": null,
        "claim_statuses": [],
        "cell_statuses": [
          {
            "num": "17",
            "modality": "necessary",
            "status": "proved"
          }
        ]
      }
    },
    {
      "id": "descent-is-not-dependence",
      "kind": "pattern",
      "name": "Descent Is Not Dependence",
      "family": "agency",
      "invariant": "A lineage edge generates a candidate support set and establishes none; support for a capability requires ablation, intervention, runtime dependency or replacement replay, and provenance-only support is refused.",
      "cells": [
        {
          "ref": "44",
          "modality": "stronger_than_needed"
        }
      ],
      "claims": [],
      "witness": {
        "registry": "ledger",
        "repo": ".",
        "path": "scripts/emb-support.mjs",
        "shape": "side-effect",
        "evidence_kind": "constructive_witness",
        "rung": "in_tree",
        "rung_source": "both refusals fire on the synthetic corpus; 0 observed capabilities",
        "cmd": "node scripts/emb-support.mjs",
        "cwd": ".",
        "staged": false
      },
      "counterexample": {
        "shape": "refusal",
        "path": "scripts/emb-support.mjs",
        "marker": "REFUSED — support evidence of kind",
        "expected": "REFUSED"
      },
      "prior_art": {
        "works": [
          {
            "work": "Pearl's ladder of causation",
            "relation": "antecedent",
            "overlap": "association is not intervention is not counterfactual",
            "difference": "Pearl builds a calculus; the pattern takes only the first rung's warning"
          },
          {
            "work": "Ablation studies",
            "relation": "realization",
            "overlap": "the way the difference is actually established",
            "difference": "a method, not an invariant"
          },
          {
            "work": "Λ non-laundering (cell 44)",
            "relation": "partial-overlap",
            "overlap": "a derived thing does not inherit authority it never had",
            "difference": "the cell is about authority; the pattern is about explanatory dependence"
          }
        ],
        "novelty_not_claimed": "Pearl's distinction is the content. Lint class PROVENANCE_AS_SUPPORT enforces the prose form, which is an enforcement mechanism, not a discovery.",
        "prose": "Pearl's ladder of causation; ablation studies; Λ non-laundering (cell 44). Lint class PROVENANCE_AS_SUPPORT enforces the prose form."
      },
      "realizations": [
        "mosaic/embodiment.json",
        "scripts/emb-support.mjs"
      ],
      "failure_mode": "provenance-as-support",
      "related": [
        "continuity-through-reconstruction",
        "evidence-before-claim"
      ],
      "scene": "descent-is-not-dependence",
      "headline": "A lineage edge generates a candidate support set and establishes none.",
      "explanatory": "B descended from A; A had a capability. That B has it too, and that it depends on A for it, are two further claims neither of which the lineage edge makes. Competence may have been copied into weights, recompiled or independently rediscovered while the edge stayed. Support is established by ablation, intervention, runtime dependency or replacement replay — and provenance-only support is refused.",
      "technical": "mosaic/embodiment.json refuses a lineage edge as a link in the support chain; scripts/emb-support.mjs enforces the refusal before computing any kernel or cut. A continuity kernel is a minimal causally established support set sufficient to retain a declared capability under a declared replacement contract — set-shaped, because support is a hypergraph. The revocation-cut dual holds only when the support function is monotone; the engine refuses kernels for a capability whose observations falsify monotonicity. Status: 4 capabilities, 4 synthetic, 0 observed; both refusals fire; no kernel is claimed.",
      "problem": "'The successor inherited it' is the sentence every factory wants to write. The tree wrote it, and outside review caught it: descent had been placed in the causal chain as if a git edge were an experiment.",
      "forces": "Lineage is cheap to record and ablation is expensive to run, so provenance will always be the evidence you have. Support sets overlap — K₁={A} and K₂={B,C} can both suffice — so a single deletion proves nothing and the engine must reason about sets. Monotonicity is a hypothesis with a falsifier, not a given.",
      "construction": "Record lineage, but classify it as a candidate generator. Accept as support only ablation, intervention, runtime dependency or replacement replay, with the evidence kind named. Compute kernels over sets. Refuse when the observations falsify monotonicity. Report 0 observed as 0 observed.",
      "transformations": {
        "allowed": [
          "proposing a candidate support set from lineage",
          "establishing support by ablation of the set under test",
          "revoking a capability by cutting a kernel — when monotone"
        ],
        "refused": [
          "lineage as a link in the causal chain (Provenance as Support)",
          "'has inherited' in the present perfect without an observed kernel",
          "ablating one file and concluding about a set"
        ]
      },
      "consequences": "Heredity becomes a specified experiment rather than a slogan. The honest status today is that the engine runs and has nothing to run on, which the page above states in those words.",
      "analogy": "A student who studied under a master. That the student can do the thing, and that they could not without the master, are two claims; the enrolment record makes neither. You find out by taking the notebooks away.",
      "applicability": "Model distillation, factory lineages, plugin inheritance, any claim that a successor 'carries forward' what a predecessor had.",
      "syntax": [
        {
          "label": "The two refusals, in the engine's own words (scripts/emb-support.mjs)",
          "path": "scripts/emb-support.mjs",
          "start": " * THE TWO REFUSALS",
          "count": 8
        }
      ],
      "takeaways": [
        {
          "from": "animation",
          "text": "The lineage edge was refused as support; the ablation was admitted, and the kernel it established is a set."
        },
        {
          "from": "syntax",
          "text": "Both refusals — provenance-only support and a falsified monotonicity hypothesis — are named, and both fire on the synthetic corpus."
        },
        {
          "from": "literature",
          "text": "Pearl's ladder of causation: seeing, doing, imagining. Lineage is seeing; ablation is doing."
        },
        {
          "from": "witness",
          "text": "emb-support.mjs ran today: 4 capabilities, 4 synthetic, 0 observed. Heredity is unwitnessed, and the page never says otherwise."
        }
      ],
      "wrl": {
        "note": "No core-role encoding; lineage is a relation between worlds."
      },
      "up": "UP-031",
      "limit": "Cell 44 (Λ non-laundering) is proved at the property tier and is about authority, not about explanatory dependence — it is cited as a partial overlap, not as this pattern's proof. Lint class PROVENANCE_AS_SUPPORT enforces the prose form only.",
      "next_rung": "live_local: an ablation a reader can run — remove the component, watch the dependence fail to appear. Lint class PROVENANCE_AS_SUPPORT enforces the prose form only, and a prose rule is not a measurement.",
      "derived": {
        "label": "WITNESSED",
        "CHECKABLE": true,
        "RUNNABLE": true,
        "EXECUTED": true,
        "STAGED": false,
        "REPRODUCED": false,
        "PUBLISHED": true,
        "next_rung_name": "live_local",
        "why": [
          {
            "ok": true,
            "text": "a witness is named"
          },
          {
            "ok": true,
            "text": "its evidence kind is one the ledger already uses (constructive_witness)"
          },
          {
            "ok": true,
            "text": "the witness path resolves in this tree"
          },
          {
            "ok": true,
            "text": "its rung is in_tree or above (in_tree)"
          },
          {
            "ok": true,
            "text": "a run is recorded for these exact bytes"
          },
          {
            "ok": true,
            "text": "no claim is cited that could be REFUTED"
          },
          {
            "ok": true,
            "text": "a counterexample is shipped (required once WITNESSED)"
          },
          {
            "ok": false,
            "text": "not staged on this site, so it cannot run from the page"
          }
        ],
        "related_closure": [
          "continuity-through-reconstruction",
          "evidence-before-claim"
        ],
        "live_run": null,
        "counterexample_strength": {
          "strength": "marker",
          "occurrences": 1,
          "law": null
        },
        "execution": {
          "at": "2026-09-11T15:25:45.592Z",
          "host": "PX13",
          "sha256": "7a8b6a2f444c397075557f0210684171de3b8fc03a59a564cd5fd0347f3c456b",
          "repo_head": "92d99bf0f69f23bafb2dad7b1312ed2f3beb2164"
        },
        "claim_statuses": [],
        "cell_statuses": [
          {
            "num": "44",
            "modality": "stronger_than_needed",
            "status": "proved"
          }
        ]
      }
    },
    {
      "id": "understanding-boundary",
      "kind": "pattern",
      "name": "Understanding Boundary",
      "family": "agency",
      "invariant": "A locus distinguishes what exists, what it can observe, what it believes, what it understands, what it intends and what it may alter; a claim in one register is never promoted to another without evidence.",
      "cells": [],
      "claims": [],
      "witness": null,
      "prior_art": {
        "works": [
          {
            "work": "Hintikka, epistemic logic",
            "relation": "antecedent",
            "overlap": "formal treatment of what an agent knows and knows it does not",
            "difference": "none claimed"
          },
          {
            "work": "The box-and-box ladder's epistemic rung",
            "relation": "realization",
            "overlap": "the tree's own place where 'do we know enough' is asked",
            "difference": "the rung governs one decision; the pattern is about a standing boundary"
          },
          {
            "work": "Graphonomous Bot spec — 'a Bot knows its projection, not the world'",
            "relation": "partial-overlap",
            "overlap": "the tree's sharpest statement of the boundary",
            "difference": "frozen for one component"
          }
        ],
        "novelty_not_claimed": "Epistemic logic has formalized this for sixty years. The chapter's job is to keep the boundary visible, not to advance the logic.",
        "prose": "Epistemic logic (Hintikka); the ladder's epistemic rung. Graphonomous Bot spec: 'a Bot knows its projection, not the world.'"
      },
      "realizations": [
        "opensentience.org/epistemic-arithmetic.html"
      ],
      "failure_mode": "agent-omniscience",
      "related": [
        "established-not-known"
      ],
      "scene": "understanding-boundary",
      "headline": "A locus keeps apart what exists, what it can observe, what it believes, what it understands, what it intends and what it may alter.",
      "explanatory": "Six registers, each narrower than the last. A claim in one is not a claim in the next: an observation is not a belief until it is established; a belief is not understanding until it is connected to why; intent is not permission. Agent Omniscience is the failure of promoting a claim across registers without evidence for the step.",
      "technical": "AGENCY.md §3's chain: observation exposes a scoped view; invariants establish operational state; policy and grant establish scoped authority; authority constrains admissible action. The epistemic rung of the box-and-box ladder is where 'do we know enough?' is asked. Graphonomous Bot spec: a Bot knows its projection, not the world; STALE ≠ UNESTABLISHED. STATED; the neighbouring vocabulary pattern's lint is the closest witness.",
      "problem": "'I saw it, so I know it, so I may change it.' Three promotions in one sentence, none earned. Agents built on this collapse act on stale observations with full confidence and call the result knowledge.",
      "forces": "Keeping six registers is expensive in prose and in code; most systems keep two (true/false) and call the rest metadata. The registers are only worth keeping if something checks the promotions — a lint for prose, a ladder rung for verdicts.",
      "construction": "Name the registers. Require evidence for each promotion. Put 'do we know enough?' on its own rung, before action. Write copy with establish, never know or detect.",
      "transformations": {
        "allowed": [
          "promoting a claim one register with evidence",
          "demoting a claim when its observation goes stale"
        ],
        "refused": [
          "'observed, therefore may alter'",
          "confidence inflated across registers without evidence"
        ]
      },
      "consequences": "Confidence becomes a position in a ladder rather than a number. The honest status: STATED — this is vocabulary and doctrine, witnessed only through the lint on the neighbouring pattern.",
      "analogy": "A detective's board: seen, suspected, understood, planned, permitted. Arresting on 'seen' is the error every good story is about.",
      "applicability": "Agent architectures, belief revision, any copy that says an agent 'knows'.",
      "syntax": [
        {
          "label": "The chain (AGENCY.md §3)",
          "path": "AGENCY.md",
          "start": "exposes a scoped view of it",
          "count": 6
        }
      ],
      "takeaways": [
        {
          "from": "animation",
          "text": "The claim moved inward one ring at a time, and the jump to the smallest ring was refused."
        },
        {
          "from": "syntax",
          "text": "observation → exposes; invariants → establish; policy + grant → authority; authority → constrains action."
        },
        {
          "from": "literature",
          "text": "Hintikka's epistemic logic; the DIKW ladder, with the difference that here each step needs a check."
        },
        {
          "from": "witness",
          "text": "STATED: doctrine and vocabulary; the lint on State Does Not Grant Authority is the nearest mechanical falsifier."
        }
      ],
      "wrl": {
        "note": "No core-role encoding; six registers are not six roles."
      },
      "up": "UP-032",
      "limit": "Shows 'later canonical wins', which is not 'disputed'. A disputed outcome needs the SAME event key from two claims, and the scenario for this chapter does not construct one — so the harder case is unshown, not resolved.",
      "next_rung": "in_tree: a scenario that constructs the same (writer, sequence) twice, so the film has to show a genuine dispute rather than an ordering.",
      "derived": {
        "label": "STATED",
        "CHECKABLE": false,
        "RUNNABLE": false,
        "EXECUTED": false,
        "STAGED": false,
        "REPRODUCED": false,
        "PUBLISHED": true,
        "next_rung_name": "in_tree",
        "why": [
          {
            "ok": false,
            "text": "a witness is named"
          },
          {
            "ok": false,
            "text": "its evidence kind is one the ledger already uses"
          },
          {
            "ok": false,
            "text": "the witness path resolves in this tree"
          },
          {
            "ok": false,
            "text": "its rung is in_tree or above"
          },
          {
            "ok": false,
            "text": "a run is recorded for these exact bytes"
          },
          {
            "ok": true,
            "text": "no claim is cited that could be REFUTED"
          },
          {
            "ok": false,
            "text": "a counterexample is shipped (required once WITNESSED)"
          },
          {
            "ok": false,
            "text": "not staged on this site, so it cannot run from the page"
          }
        ],
        "related_closure": [
          "established-not-known"
        ],
        "live_run": null,
        "counterexample_strength": null,
        "execution": null,
        "claim_statuses": [],
        "cell_statuses": []
      }
    }
  ],
  "anti_patterns": [
    {
      "id": "carrier-identity",
      "name": "Carrier Identity",
      "problem": "Treating a thing as the process, thread or container currently executing it.",
      "paid_for": null
    },
    {
      "id": "location-leak",
      "name": "Location Leak",
      "problem": "Encoding physical placement into identity when placement is not semantic.",
      "paid_for": null
    },
    {
      "id": "false-quiescence",
      "name": "False Quiescence",
      "problem": "Declaring completion because no currently observed worker has work.",
      "paid_for": "REVISION_REGISTER.md:99 (CompletedScan renamed CompletedSweep; doesNotAssert added)"
    },
    {
      "id": "invisible-state",
      "name": "Invisible State",
      "problem": "Allowing state that affects future behaviour to remain outside the shared observable.",
      "paid_for": "TRVM/LAWS.md:80 (Law 6 witnesses: rotor, receipt, once-latch)"
    },
    {
      "id": "ambient-authority",
      "name": "Ambient Authority",
      "problem": "Granting access to an environment because some part of it needs one capability.",
      "paid_for": "AGENCY.md §4 (the phrasing that walks into it); Miller 2003 is the term's source"
    },
    {
      "id": "replica-theater",
      "name": "Replica Theater",
      "problem": "Calling independent mutable copies 'the same thing'.",
      "paid_for": "CLAUDE.md: the served box-and-box copy is a MANUAL COPY and nothing syncs it"
    },
    {
      "id": "busywork-scheduling",
      "name": "Busywork Scheduling",
      "problem": "Maximizing resource utilization while semantic progress stalls.",
      "paid_for": "computedriven/receipts/R7-EXECUTED.md title: the busiest Carrier makes the least progress"
    },
    {
      "id": "agent-omniscience",
      "name": "Agent Omniscience",
      "problem": "Letting an agent's claims exceed its evidence boundary.",
      "paid_for": "AGENCY.md §6 (what is established vs a reading)"
    },
    {
      "id": "number-in-two-places",
      "name": "A Number in Two Places",
      "problem": "A count or definition typed where it is displayed instead of derived from its source; the two drift.",
      "paid_for": "STACK_COMPLETION.md corrections §1 (law counts 129→116→118); UNBOXED_PATTERNS.md v0.1 (32 labels over 30 rows; 890 vs 924)"
    },
    {
      "id": "record-is-locus",
      "name": "Record Is Locus",
      "problem": "Inferring that X is a locus because X carries the locus fields.",
      "paid_for": "AGENCY.md §1 corollary; caught on review of the factory page"
    },
    {
      "id": "provenance-as-support",
      "name": "Provenance as Support",
      "problem": "Treating a lineage edge as causal support for a capability.",
      "paid_for": "mosaic/embodiment.json; scripts/emb-support.mjs refuses it"
    },
    {
      "id": "quiet-correction",
      "name": "The Quiet Correction",
      "problem": "Fixing a published error without retracting it by name where it was published.",
      "paid_for": "DOCTRINE.md rule 5"
    }
  ]
}
