From 204cf4112b0df58ae809185957ec25832de5b888 Mon Sep 17 00:00:00 2001 From: Ralf Anton Beier Date: Fri, 9 Oct 2026 19:21:14 +0200 Subject: [PATCH] v0.84 cold review round 2: five more false statements, four of them our own corrections MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Round 2 ran in a FRESH detached worktree pinned to b0395b69, forbidden from reading the coordinator's checkout, its notes, and round 1's worktree. Its first task was to attack round 1's corrections and THE NUMBERS THEY INTRODUCE, worked from an 82-number frequency list its own extractor derived — not from reading for importance. It appended 285 lines and deleted ZERO; round 1's text and the header are untouched, verified by diff. FIVE false statements. FOUR were introduced by round 1's corrections or by the coordinator's addendum. That ratio is the point of running a second round. R2-1. THE CORRECTION TO A POPULATION ERROR CONTAINED A POPULATION ERROR. "`blocked` lands green on 294 of the 594" computed `594 - 300`, subtracting ALL 300 release artifacts while the SAME SENTENCE names the version gate that exempts most of them. Only 177 of the 300 are R11-active, so the green set is 417 — re-derived here by importing the gate's own predicate. The additive clause "and on every pre-v0.67 release file" then DOUBLE-COUNTED: RQ-60-A64IMPORT is among the artifacts already subtracted away. R2-2, recorded as imprecise rather than false: `NON_DELIVERY_DISPOSITION`'s loader iterates 594, but its membership test is REACHED by 109, so the contrast was mis-sized fivefold. R2-3. "nothing in the plan reads an issue's state" is FALSE — RQ-84-ARCHMODEL3.yaml:16 at 0c84a3b9 says "check the upstream issue's STATE before its BODY. If it is CLOSED this is a DELIVERY lane", the exact read instance 6 was credited with inventing. The five-of-seven BOUNDARY still holds; the justification did not. R2-4. The theme paragraph cited "instance 7's cluster brittleness" as genuinely new material 107 lines above the same commit RETRACTING it. R2-5. NOT ours, and MISSED BY ROUND 1: a second site still asserted the field-identity premise and the cluster brittleness after the F2 correction fixed only the first. Exactly two assertion sites existed and one pass corrected one. Sweep for the FACT, not the cited site — stated in the brief, violated anyway. R2-6. The addendum's "This does not change any count above" changes the count it was written about. AND THE ADDENDUM WAS RIGHT BUT TOO WEAKLY STATED, which round 2 fixed in both directions. With seven synthetic one-artifact external stubs it showed the guard silent with the cache present, firing with it absent, firing again once removed: INERTNESS NEEDS ONE EXTERNAL ARTIFACT, NOT 3201, so "added >= 3201 unconditionally" was a property of this operator's cache CONTENT, not of the mechanism. The potency tally now reads 6 potent environment-independently, 1 potent ONLY absent `.rivet/repos`. And the scoping settles which reading matters: no workflow invokes the generator — ci.yml:828 runs only its unit test — while `rivet sync` runs at ci.yml:1505 and compliance.yml:102, so the generator's only real environment is the operator's synced checkout. The gate is inert in the only environment where it ever runs. ALSO FIXED HERE, from round 2's uncounted observations: the notes trio was pinned to 4785e61c, the PRE-SQUASH lane head, which squash merging leaves OUT of main's history — a reader on main could not check it. Re-measured at b0395b69, an ancestor of main: generator 3215 added / 722 unchanged, symmetric 722 base / 736 head / 14 added / 0 removed / 722 unchanged. Same figures, checkable provenance. Every number round 2 introduced was re-derived independently before being written here: 300 across 245 files, 177 R11-active, 594 total, 417 green, 109 reached, and 4785e61c confirmed NOT an ancestor of origin/main. Gates, each read by its own exit code: verdict_prose rc=0 (109, 0 disagree), status_evidence rc=0, claim_check 75/75, check_version_pins rc=0, issue_closure rc=0 (0 authorised, 1 held open, 0 closed, 0 failures), and pretag conformance rc=0 CONFORMS (slots=7, derived=6, attested=1, failures=0). Refs #1259, #1183, #1436, #1458, #1476, #1484 Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_01YJK5LZZEkV5smCY1jKn18L --- CHANGELOG.md | 40 ++- artifacts/release-v0.84/RQ-84-DISPVOCAB.yaml | 13 +- docs/reviews/v0.84-cold-review.md | 306 ++++++++++++++++++- 3 files changed, 343 insertions(+), 16 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index edd5fa5b..10d221a4 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -23,14 +23,22 @@ share a population definition", TWOSOURCE's `Path("Cargo.toml")`/`tree_read` spl DISPVOCAB's "three values ... another five", PINDEBT9's paired-controlled name scope, and RUNNERSHAPE's two-shape measurement. **Two were not**: the wiring hole behind instance 5, whose lane was scoped as a DECISION about refusing a fourth time, and -instance 6, since nothing in the plan reads an issue's state. What was genuinely new in -the other five is the DETAIL, not the defect: instance 2's recurrence on this release's -own commit, instance 1's `schemas/` leg, instance 3's refutation of its own harm claim, -instance 7's cluster brittleness. The release did not need the stronger sentence. +and instance 6. Round 2 then refuted the REASON first given for instance 6 — "nothing in +the plan reads an issue's state" is false: `RQ-84-ARCHMODEL3.yaml:16` at `0c84a3b9` says +"check the upstream issue's STATE before its BODY. If it is CLOSED this is a DELIVERY +lane", which is the exact read instance 6 was credited with inventing. The five-of-seven +BOUNDARY still holds — all five quoted plan strings are present at `0c84a3b9` and +FIRSTTOKEN3's genuinely does not name the wiring hole — but the justification was wrong. +What was genuinely new in the predicted five is the DETAIL, not the defect: instance 2's +recurrence on this release's own commit, instance 1's `schemas/` leg, and instance 3's +refutation of its own harm claim. Instance 7's cluster brittleness is NOT in that list: +it was retracted in the same commit that first claimed it, 107 lines below. **1. The notes generator is bounded by what the diff compares, not by what rivet needs to -load — and its anti-vacuity guard is one-sided.** Both figures below were measured at the -SAME commit, `4785e61c`. The generator reports `3215 added, 0 removed, 0 modified, 722 +load — and its anti-vacuity guard is one-sided.** Both figures below were measured at the SAME commit, `b0395b69`, which is an ancestor of +`main`. They were first pinned to `4785e61c` — the pre-squash lane head, which SQUASH +MERGING leaves OUT of main's history, so a reader on main could not check them. Same +figures, checkable provenance. The generator reports `3215 added, 0 removed, 0 modified, 722 unchanged`, and the entries it lists carry `loom:`, `scry:` and `meld:` prefixes. A symmetric extraction — both sides from `git archive` over the declared sources *plus* `schemas/` and `rivet.yaml`, with rivet run **inside** each tree — gives base **722**, @@ -73,9 +81,14 @@ the second is a semantic test of what **means** non-delivery. Controlled: planti version of this paragraph said the two extra members are unreachable on any tree passing R11 — dead rather than dangerous. The cold review measured the two populations: R11's is **300 artifacts across 245 release files** and is version-gated `>= (0, 67)`, while the -classifier is consulted over **all 594** artifacts in 270 files. So `blocked` lands -green on 294 of the 594 and on every pre-v0.67 release file, and where it lands it is -consequential — planted on `RQ-60-A64IMPORT` (v0.60), `status_evidence_check` is rc=0 +classifier's loader ITERATES all 594 artifacts in 270 files, though its membership test +is actually reached by **109** — so the contrast is real but smaller than first written. +AND THE FIRST CORRECTION MIXED POPULATIONS IN ITS TURN, which round 2 caught: it +computed the green set as `594 - 300 = 294`, subtracting ALL 300 release artifacts while +the same sentence states the version gate that exempts most of them. Only **177** of the +300 are R11-active, so the green set is **417**, and the additive clause "and on every +pre-v0.67 release file" then DOUBLE-COUNTED — `RQ-60-A64IMPORT` is one of the artifacts +subtracted away. Where `blocked` lands it is consequential — planted on `RQ-60-A64IMPORT` (v0.60), `status_evidence_check` is rc=0 while `verdict_prose_check` is rc=1 with `prose claims VERIFIED beside disposition 'blocked'`. Reachable, and live. The denial compared R11's population against the classifier's as though they were one population: the theme, inside the sentence denying @@ -119,8 +132,13 @@ release measured its defect, and all four defects are live on evidence of four d shapes: TWOSOURCE and PINDEBT9 by genuine paired controls, DISPVOCAB by a plant-and-restore of `disposition: blocked`, and NOTESPOP by the symmetric-versus-asymmetric comparison in instance 1. NOSHOW2 is the exception and is recorded as one: its refuting command is **not -runnable** — the no-show population in the window is zero — so what is confirmed there is -the field-identity premise plus the brittleness of the cluster test, not a control. The +runnable** — the no-show population in the window is zero — so what is confirmed there is NEITHER of the two things first written here. Round 2 +found this sentence SURVIVING after the F2 correction fixed only the other site: the +"field-identity premise" is false for one of the 13 jobs, and the "brittleness of the +cluster test" was itself retracted. What NOSHOW2 actually establishes is that the no- +show population in the window is EMPTY, so its refuting command is unrunnable — and +nothing more. Exactly two assertion sites existed and the first pass corrected one: the +rule is to sweep for the FACT, not the cited site. The closer-keyword audit found zero adjacency in all three vectors and the timelines show `commit=none`, so nothing in this release retired them. "The issue is retired" and "the defect is fixed" are different claims about different populations, and nothing in the plan diff --git a/artifacts/release-v0.84/RQ-84-DISPVOCAB.yaml b/artifacts/release-v0.84/RQ-84-DISPVOCAB.yaml index 9f5917da..a743f298 100644 --- a/artifacts/release-v0.84/RQ-84-DISPVOCAB.yaml +++ b/artifacts/release-v0.84/RQ-84-DISPVOCAB.yaml @@ -59,9 +59,16 @@ artifacts: AND THAT RESIDUAL WAS ITSELF FALSE — the cold review refuted it, in this release's own shape. It said the two extra members are UNREACHABLE on any tree passing R11, dead rather than dangerous. MEASURED: R11's population is 300 artifacts across 245 release - files and is version-gated `>= (0, 67)`, while `NON_DELIVERY_DISPOSITION` is consulted - over ALL 594 artifacts in 270 files. `blocked` therefore lands GREEN on 294 of the 594 - and on every pre-v0.67 release file, and where it lands it is consequential: planted on + files and is version-gated `>= (0, 67)`, while `NON_DELIVERY_DISPOSITION`'s + loader ITERATES all 594 artifacts in 270 files, though its membership test is reached by + only 109. AND THIS CORRECTION MIXED POPULATIONS IN ITS TURN, caught by round 2: it + computed the green set as `594 - 300 = 294`, subtracting ALL 300 release artifacts while + naming the version gate that exempts most of them. Only 177 of the 300 are R11-active, + so the green set is 417, and the clause "and on every pre-v0.67 release file" double- + counted `RQ-60-A64IMPORT`, which is among the artifacts already subtracted away. + `blocked` therefore lands GREEN on 417 of the 594 — a set that ALREADY CONTAINS every + pre-v0.67 release file, so adding them again was the double count. Where it lands it is + consequential: planted on `RQ-60-A64IMPORT` (v0.60), `status_evidence_check` is rc=0 while `verdict_prose_check` is rc=1 — `prose claims VERIFIED beside disposition 'blocked'`. REACHABLE AND LIVE. The denial compared R11's population with the classifier's as though they were one, which is diff --git a/docs/reviews/v0.84-cold-review.md b/docs/reviews/v0.84-cold-review.md index 0841bfd2..b6176da7 100644 --- a/docs/reviews/v0.84-cold-review.md +++ b/docs/reviews/v0.84-cold-review.md @@ -384,5 +384,307 @@ the environment it was measured in, exactly as a population must state its windo party could have found this alone: round 1 had no reason to suspect the cache, and the coordinator could not have produced the fresh-worktree reading without an isolated round. -This does not change any count above. Round 1's seven findings stand; this is an eighth -observation about the REVIEW, and it was produced by the review existing. +CORRECTED BY ROUND 2, which attacked this addendum as instructed. The sentence first +written here — "this does not change any count above" — was FALSE: it changes the count +it was written about. Round 1's `7 potent / 0 inert / 0 unproven` NEEDS A QUALIFIER, and +the honest form is **6 potent environment-independently, 1 potent only in the absence of +`.rivet/repos`**. + +Round 2 also found the mechanism sharper than stated. With seven synthetic one-artifact +external stubs it showed the guard goes silent with the cache present, fires with it +absent, and fires again once it is removed — so INERTNESS NEEDS ONE EXTERNAL ARTIFACT, +NOT 3201. "added >= 3201 unconditionally" is a property of this operator's cache +CONTENT, not of the mechanism. + +AND THE SCOPING SETTLES WHICH READING MATTERS. No workflow invokes the generator at all +— `ci.yml:828` runs only its unit test (`test_release_notes_from_rivet.py`) — while +`rivet sync` runs in `ci.yml:1505` and `compliance.yml:102`. So the generator's only +real environment is the operator's checkout, which is the one that carries the cache. +**The gate is therefore inert in the only environment where it ever runs**, and the +fresh-worktree `potent` reading describes an environment the generator is never used in. +Round 1's seven findings stand; this addendum's own count did not. + +## ROUND 2 + +**Commit reviewed:** `b0395b692717e555f5b2bf9c7f36af1be892e684` — round 1's record *plus its +seven corrections applied*. Derived in a second detached worktree; round 1's worktree and +the coordinator's notes were not read. Measured 2026-10-09. + +**(a) 5 statements do not hold as read at `b0395b69`** — R2-1, R2-3, R2-4, R2-5, R2-6. +**(b) 4 of the 5 were introduced by round 1's corrections (R2-1, R2-3, R2-4) or by the +coordinator's addendum (R2-6).** One (R2-5) pre-dates them and round 1 missed it — and it +is a site the corrections should have fixed and did not. A sixth entry, **R2-2, is listed +but NOT counted**: it is imprecise rather than false, and it is recorded that way on +purpose rather than padding (a). + +Counting convention, stated so (a) is auditable: a statement counts FALSE only if it does +not hold **as read at this commit**. Figures whose window has moved since they were +measured (the CI-window counts) are NOT counted — their denominators are named. Attribution +for (b) is mechanical: a statement is correction-introduced iff its text appears in the `+` +lines of `git show b0395b69`. + +Numbers were worked from `python3 extract_r1_numbers.py docs/reviews/v0.84-cold-review.md` +(82 distinct, frequency-ordered), not from reading for importance. Note for a future round: +a large share of that list (`09`, `57`, `26`, `58`, `51`, `53`) are ISO-timestamp fragments, +not claims. + +### R2-1 — FALSE. "`blocked` lands green on **294 of the 594**" (and the additive clause beside it) + +`CHANGELOG.md` instance 3 and `RQ-84-DISPVOCAB`'s `verified-by` — both correction-introduced. +`294` is `594 − 300`, a subtraction that treats all 300 release artifacts as R11-reachable +while the same sentence states the version gate that does not. Derived by importing the +gate's own loader and predicate instead of subtracting: + +``` +python3 -c "import sys;sys.path.insert(0,'scripts');import status_evidence_check as S, + verdict_prose_check as V,pathlib; + a,_=S.load_release_artifacts(pathlib.Path('.'),S.RELEASE_GLOB); + print(len(a), len({x[0] for x in a}), + len([x for x in a if x[1]>=S.DISPOSITION_SINCE]), + len({y.get('id') for _,y in V.artifacts('.')} - {x[2] for x in a if x[1]>=S.DISPOSITION_SINCE}))" + -> 300 245 177 417 +``` +R11's population is 300 across 245 files (**correct**), but only **177** are R11-ACTIVE — +`version >= DISPOSITION_SINCE = (0, 67)`. So `disposition: blocked` lands green on **417** +of the 594, not 294. The error is in the direction that understates the lane's own finding. + +The second clause compounds it: "and on **every pre-v0.67 release file**". Those artifacts +are inside the 300 that was subtracted away, so they are not among the 294 — the clause is +additive on a figure that already excluded them. Demonstrated on the correction's own +exhibit: + +``` +# RQ-60-A64IMPORT is in artifacts/release-v0.60.yaml, version (0,60) -> one of the 300 +plant `disposition: blocked`; python3 scripts/status_evidence_check.py -> rc=0, 0 R11 hits + python3 scripts/verdict_prose_check.py -> rc=1 + FAIL verdict-prose RQ-60-A64IMPORT: prose claims VERIFIED beside disposition 'blocked' +restored -> rc=0 +``` +A population-mixing error inside the sentence written to correct a population-mixing error. + +### R2-2 — IMPRECISE, NOT COUNTED. "`NON_DELIVERY_DISPOSITION` is consulted over **ALL 594** artifacts in 270 files" + +`RQ-84-DISPVOCAB`'s `verified-by`; `CHANGELOG.md` instance 3 says "the classifier is +consulted over **all 594**". Correction-introduced. `594` is what `verdict_prose_check. +artifacts()` YIELDS; the set is reached only inside `classify()` past the `tok is None` +guard, i.e. for artifacts carrying a non-empty `verified-by` with a classified lead: + +``` +# count of artifacts that REACH `disp in NON_DELIVERY_DISPOSITION` +-> 109 # identical to the gate's printed population +python3 scripts/verdict_prose_check.py + -> verdict-prose: 109 artifacts in the population, 0 disagree +``` +The honest contrast for the two-populations argument is **177 against 109**, not 300 +against 594. `594` and `270` are each true of their own census (594 artifacts in 270 of 293 +YAML files, re-derived) — they are simply not the set the membership test is evaluated +over. **Why this is not counted in (a):** `artifacts()` genuinely does iterate all 594, so +"consulted over" admits a defensible plain reading, and the comparison it feeds is directional +rather than wrong. It is logged because the load-bearing contrast is mis-sized by 5x in the +direction that flatters the argument, and because R2-1 — which IS false — sits in the same +paragraph. + +### R2-3 — FALSE. "instance 6 … since **nothing in the plan reads an issue's state**" + +`CHANGELOG.md` theme paragraph (correction-introduced) and round 1's F3. Provenance, so a +round 3 does not have to find it: this is round 1's own reasoning at `5a4092da` BEFORE it +became a `+` line here — it is classified correction-introduced by the stated rule, but it +originated in the finding, not in the edit. Refuted by one grep at the plan commit: + +``` +git grep -niE "state before|issue.s state" 0c84a3b9 -- artifacts/release-v0.84/ + -> RQ-84-ARCHMODEL3.yaml:16: "check the upstream issue's STATE before its + BODY. If it is CLOSED this is a DELIVERY lane and not a filing, which changes + the whole shape of the work." +# negative control: git grep -c "zzzqqq" 0c84a3b9 -- artifacts/release-v0.84/ -> no match, rc=1 +``` +`RQ-84-ARCHMODEL3`'s plan-commit REFUTING COMMAND instructs exactly the read instance 6 is +credited with inventing — and ARCHMODEL3 ran it (`spar#445` re-derived OPEN, `closedAt` +null). The accurate statement is the sharper one: the plan carried that instruction in ONE +lane of fourteen, and it is the instruction the other four needed. + +The rest of the five-of-seven boundary HOLDS. All five quoted plan-commit strings are +present at `0c84a3b9` under whitespace normalisation (`RQ-84-RUNNERSHAPE`'s is a paraphrase +joined across two em-dashes — substance exact, presented inside a `git show` block as +though verbatim), and `RQ-84-FIRSTTOKEN3`'s plan description genuinely does not name the +wiring hole; it scopes the lane as a DECISION. + +### R2-4 — FALSE. "instance 7's **cluster brittleness**" listed as the genuinely-new material + +`CHANGELOG.md:29`, a `+` line of the correction commit. 107 lines below it, in the same +commit, instance 7 states that the cluster-brittleness finding "was manufactured by +admitting a 33-step job into a population defined by `steps == 0`". The theme paragraph +cites as this release's new DETAIL a claim the same commit retracts. Round 1's F3 text was +written about `5a4092da`, where the claim was still live; applied verbatim at `b0395b69` it +is false — the "a number is invalidated by the edit that writes it" class. + +### R2-5 — FALSE, and NOT correction-introduced. Instance 6 still asserts both refuted claims as CONFIRMED + +``` +git grep -nE "all 13|32-second|field-identity|cluster test" -- CHANGELOG.md artifacts/ + CHANGELOG.md:123: "what is confirmed there is the field-identity premise plus the + brittleness of the cluster test, not a control." +git show b0395b69 -- CHANGELOG.md | grep -n "field-identity" -> no output +``` +Untouched by the correction, and both halves are refuted elsewhere in the same file. On the +first half, the reading matters and is stated: the premise is TRUE of the 12 jobs that are +actually the population, and FALSE **as quantified over 13** — and 13 is the quantification +instance 6 inherits, because NOSHOW2 wrote it as "all 13 carry `steps=0`, `runner_name=''`, +`runner_id=0` and `started_at == created_at`" and instance 6 calls that premise confirmed. +The cluster brittleness is retracted outright in instance 7. Exactly two assertion sites survive in the tree +(`:29` and `:123`); `RQ-84-RUNNERSHAPE` does not repeat it. This is "correct the FACT, not +the cited site" — the corrections fixed instance 7's own paragraph and NOSHOW2's +`verified-by`, and left the two paragraphs that cite them. + +### R2-6 — FALSE. The addendum's "**This does not change any count above**" + +It changes the count it was written about. See the addendum test below: with an externals +cache present, `release_notes_from_rivet`'s anti-vacuity guard CANNOT fire — in my own +fresh worktree, not by inference. `release_notes_from_rivet` is one of the seven gates in +the `7 potent / 0 inert / 0 unproven` tally. **That tally needs a qualifier**, and the +addendum's own stated rule ("a potency verdict must state the environment it was measured +in") demands it: read it as **6 potent environment-independently, 1 potent only in the +absence of `.rivet/repos`** — i.e. inert in any checkout where externals have been synced. +Scoped rather than assumed: **no workflow invokes the generator at all** (`git grep -n +release_notes_from_rivet -- .github/` returns only `ci.yml:828`, which runs its UNIT TEST), +while `rivet sync` DOES run in `ci.yml:1505` and `compliance.yml:102`. So the only +environment in which that guard ever runs for real is the operator's own checkout — which +is exactly the environment that carries the cache. + +--- + +## SECOND TASK — the addendum's claim, tested directly + +**The mechanism is CONFIRMED, and provable without the 535 MB cache.** Structural first +(`scripts/release_notes_from_rivet.py:142-163`): the base side is `git archive ` of +`sources:` + `rivet.yaml` extracted into a `TemporaryDirectory`, so it carries no `.rivet/`; +the head side is the live `--root`. `rivet` resolves `./.rivet/repos/` per loaded +project root, so the head can see externals and the base cannot. + +Then executed, with a SYNTHETIC cache — seven stub projects, one artifact each, in place of +the real one (rivet drops ALL externals if any declared one lacks a `rivet.yaml`, so all +seven are required; `rivet.yaml` declares exactly seven): + +``` +# .rivet/repos ABSENT (as shipped in a fresh worktree) +python3 scripts/release_notes_from_rivet.py --base HEAD + -> rc=1 "FAIL: rivet diff found ZERO added artifacts ... Refusing to emit an empty section" + +# .rivet/repos PRESENT (7 stubs, 1 artifact each; rivet list 736 -> 743, ids gale:…, jess:…) +python3 scripts/release_notes_from_rivet.py --base HEAD + -> rc=0 "7 added, 0 removed, 0 modified, 736 unchanged" <- guard SILENT + --base v0.83.0 -> rc=0 "21 added, 0 removed, 0 modified, 722 unchanged" +# cache removed; --base HEAD -> rc=1 again. `.rivet/` is gitignored (.gitignore:62). +``` +So the addendum is right, and **stronger than it states**: inertness needs ONE external +artifact, not 3201. "`added >= 3201` unconditionally" is a property of the coordinator's +particular cache CONTENT; the property of the MECHANISM is `added >= (number of external +artifacts) > 0`. The 535 MB and 3215 figures remain non-re-derivable here (round 1's +UNPROVEN stands) — but they are no longer load-bearing for the conclusion. + +**The addendum names one gate and never asks whether it is the only one.** Swept all seven: +`check_version_pins` is pure-tree; `verdict_prose_check`, `status_evidence_check` and +`claim_check` shell out only to `git`; `issue_closure_check` needs `gh`; and +`loop_conformance_check` reaches crates.io over `urllib` AND queries check-runs, so its +verdict is NETWORK-dependent — a second environment dependence of a different kind. Only +`release_notes_from_rivet` depends on untracked local state: run with the synthetic cache +planted, `loop_conformance_check.py v0.84.0` was rc=0 with every slot unchanged (step 3 +stays release-scoped at 14 artifacts), so the `.rivet/repos` dependence does not propagate. + +Secondary potency observation, uncounted: `verdict_prose_check.py --self-test`, whose help +text reads "prove potency against real git history", stays **rc=0 with the #1476 wiring +removed**. The red-first evidence lives in a sibling file — +`python3 -m unittest scripts.test_verdict_prose_check` is `Ran 23 / OK` wired and +`failures=17` unwired (round 1's "17 over 23" re-derives exactly, in that file). + +--- + +## THIRD TASK — the three questions, re-derived independently + +**Numbers at this commit.** Everything below was fired, not read. TRUE and exact: + +| claim | re-derived | +|---|---| +| instance 5's three populations, each with its commit | `v0.83.0` **216/95**, `0c84a3b9` **216/95**, `2123f729` **230/109**, `e1dcaf93`/`5a4092da`/`b0395b69` **230/109** — by `git archive` + the shipped `artifacts()`/`classify()` per tree | +| the three-way control | clean `109/0 rc=0`; planted `NOT LANDED` lead `109/1 rc=1`; `escape = None` **`108/0 rc=0`** | +| `NOT_A_VERDICT = set()` | population `109 -> 140`, **31** failures, rc=1 | +| F2's job facts (run 37907716195) | **71** jobs, **13** cancelled, **12** `steps==0` all at `09:57:26Z` (one distinct value), 13th = `fact-spec elision oracle (#494 …)` `steps=33`, `pulseengine-ci-01-9`, `runner_id=10495`, `created 08:53:00Z` vs `started 09:51:39Z`, sole job at `09:57:58Z` | +| F4's sweep | **11** files, `v0.69..v0.84`, 2 non-release, 1 self → **8** prior lane records; 11 at `0c84a3b9`/`2123f729`/`5a4092da`/HEAD; control `zzzqqq` → 0 | +| F5's symmetric leg | `--base v0.83.0` → **14 added, 0 removed, 0 modified, 722 unchanged**; `rivet list --format json .count` = **736**; `722+14=736` | +| instance 4's control | baseline `75/75`, `known_open_pins` **84**; `KNOWN_EXTRA` → `FAIL SYNTH-KNOWN-OPEN-PINS-RQ66`, **74/75**; same bytes as `SUPPRESSED_CASES` → `75/75`, pins still **84** | +| instance 6 | all fourteen lanes queried: **4 CLOSED / 10 open**; #1259 `2026-09-16`, #1183 `2026-09-09`, #1458 `2026-10-07`, #1484 `2026-10-08`; the two closed-citing MUSTs are NOTESPOP and TWOSOURCE | +| disposition census | parsed field VALUES `{partial: 42, deferred: 38, refuted: 8}`; **0** `blocked`/`superseded` values | +| MEMLAYER | `static_data_addend(` has **9** call sites, all in `select_with_stack.rs`; the `main.rs` hit is a comment | +| ARCHMODEL3 | matcher predicate population **22**, 0 duplicate ids, ARCHMODEL3 is the **22nd**; `spar#445` OPEN | +| NPM3 / COMPLIANCE4 / LADDER6 | `@pulseengine/synth` latest **0.69.0** over **39** versions; `git tag -l` **152**, **14** after v0.69.0 across 14 minors; `v0.83.0` published `2026-10-09T08:53:07Z`, **14** assets, compliance report **4,686,843** B; ladder header `v0.63`, `2026-09-06`, `e3a09ac2`, `243 = 131 + 112` | +| step 8 | **155** sections parsed | + +Method note on the "zero sites TODAY" claim: a TEXT sweep for it now returns 1 hit, and the +hit is `RQ-84-DISPVOCAB:47` quoting a `FAIL R11 … disposition: blocked` message — the +artifact's own prose contaminates a grep for the string whose absence it asserts. The +PARSED derivation above is clean. Use the parse. + +Time-dependent, re-measured rather than counted: instance 7's window is now **30 runs / +806 jobs / 14 `steps==0`** (7 in-progress `''`, 6 skipped `None`, 1 cancelled `''`) against +the published 676/26 and round 1's 17. Instance 7's actual FINDING survives out of sample — +three states, and **0** of the `steps==0` jobs have a runner assigned, at all three +readings. `df` now reports 11 GiB available. + +**Prose versus structured fields.** `verdict_prose_check.py` rc=0 (109 in population, 0 +disagree); `status_evidence_check.py` rc=0. All fourteen leads re-tabulated against +`status`/`disposition`/`issue-scope`/`landed`: no lead contradicts its fields. **The +corrections made question 2's shape WORSE, measurably.** `RQ-84-DISPVOCAB` still leads +`PARTIAL — the divergence is MEASURED` and `RQ-84-NOSHOW2` still leads `PARTIAL — the +refuting command is NOT RUNNABLE`, while the paragraphs beneath both were INVERTED by the +correction. A reader of the structured field sees no change; the gate sees no change, +because it classifies the leading word. R2-1 and R2-2 — two new false numbers — now live +inside one of those unchanged `PARTIAL` paragraphs. Third occurrence of the same shape in +one release. + +**Attribution, both signals, with a stated window.** `gh issue list --state all --limit +2000` returns **410** (54 open / 356 closed; max **#1484**, **lowest reached #5** — the +window is COMPLETE, not the ~#849 floor of `--limit 200`), plus **2245** comments via +`gh api --paginate repos/pulseengine/synth/issues/comments?per_page=100` (2243 at round 1's +run; two have been added since). + +- **#1145 → fathom (gale).** `author.login` `avrabe`; all 21 comments `avrabe`, 20 prefixed. + Body opens `**[fathom (gale) — synth's own refusal names a blocker that has no tracker]**`. + Prefix only; the login is blind. +- **#1436 → jess.** `avrabe`; 10 comments, all `avrabe`, **9** prefixed — which is exactly + round 1's residual (one unprefixed continuation comment), re-derived. + Body opens `**[jess] A synth-lowered falcon stage diverges …`. +- **#1439 → internal / self-filed.** `avrabe`, body opens `## Summary`, **0** comments, + contains "Found by extending the #1069 execution differential". The string `cpetig` does + NOT appear in the body; round 1's "cpetig's module appears as the exhibit" holds via a + chain, not a mention — the body cites `controller@0.10.0#step (#1318/#1426)` and `#1318` + is cpetig-authored. Stated as a chain, it stands. + +Positive controls both directions, re-derived: **29 of 410** bodies open with `**[` +(`{synth: 12, fathom: 8, claim: 8, jess: 1}`) and **202 of 2245** comments do +(`{synth: 110, fathom: 28, jess: 25, issue-hunt: 21, gale-side: 9, …}`); `cpetig` is a real +non-maintainer login with **6** issues (#1341, #1331, #1318, #465, #36, #35) and **5** +comments, **0** prefixed anywhere. One addition to round 1's census: `cschanhniem` is a +SECOND non-maintainer login (1 issue), so the author split is `avrabe 403 / cpetig 6 / +cschanhniem 1` — which is what makes the login signal blind, now stated as a figure. + +**Denominator audit**, per the extractor's closing instruction. Three published figures +state a numerator whose denominator is not named at the citation site: instance 7's +`26 jobs carry steps == 0` (window named — "30 most recent runs and 676 jobs" — but NOT +dated, and it has moved twice since); instance 1's `3215 added` (denominator is the +externals cache, named only as `535 MB, seven entries`, which is content and not a +population); and `RQ-84-NOTESPOP`'s `thousands of added artifacts … a handful` after the +correction removed the exact numbers — the direction is now unfalsifiable at that site, +which is a loss the self-consistent trio two sentences later repairs. + +**Provenance caveat, not counted.** `4785e61c` — the commit instance 1 and NOTESPOP pin +their trio to — is NOT an ancestor of HEAD (`git merge-base --is-ancestor 4785e61c HEAD` +→ rc=1). It is a pre-squash branch commit, readable here only because the worktree shares +an object store with a checkout that still has the branch. After branch deletion and gc, +the stated provenance is unverifiable. The convention it satisfies ("state the figure with +its commit") is better served by a commit on `main`. + +**Residue.** Every plant restored and re-verified by re-running the gate; the synthetic +`.rivet/` was deleted and the guard confirmed firing again. `git status --short` shows this +file plus `extract_r1_numbers.py` (the tool copied in for me) — no modified tracked file. +My scratch extracts and the synthetic `.rivet/` were deleted; `release_notes_from_rivet.py +--base HEAD` reds again, which is the restore's own evidence.