P13-S27 probe result: the round trip needs a fixed point, and round 10 had none
Bounded scratch probe, authorised as an explicit narrow exception, run on a branch that has been deleted. It falsified round 10. Recorded as evidence in its own right: M7 cannot be executed until S27 lands. BundleCapabilities and CURRENT_REDUCTION_ALGORITHM_VERSION do not exist in the tree -- they are S27's own deliverables -- and M7 step 1 needs a base committed under the real authority. M7 is a mutation of this rung's implementation, so it runs after the rung, not before. The probe therefore tested the round-trip machinery M7 depends on, base-free, which removes no refusal since both project_text_document and serialize_document gate on canonical_base.is_some(). Result: the round trip is byte-preserving, but only from a fixed point, and round 10's comparison did not compare from one. It compared A against a B built from the input document, which is valid only when that document is already a fixed point of document_from_bundle after serialize_document. minimal_document(42) happens to be one, so the first probe passed and would have been reported as success. minimal_document(99) was not. The one-extension case diverged by 295 bytes from offset 352. Rebuilt from the fixed point, all three cases are byte-identical at 1641, 1800 and 1894 bytes. The non-idempotent field is envelopes, not extensions. Diagnosed field by field: document_id, manifest_schema_version, lineage_id, profiles, canonical_base, blobs and extensions -- including every TextChunk payload -- survive exactly. document_from_bundle applies a canonical envelope ordering, as its own test name says, so a document whose envelopes arrive in any other order is not a fixed point and its operation-block bytes differ. project_text_document into parse_document proved lossless: b_doc == d in every case. The text leg was never the problem. The defect was entirely in which artifact round 10 chose as the reference. What M7 must add, for round 11 to ratify rather than for this probe to assume: an explicit fixed-point normalisation and assertion before any byte comparison, because otherwise a mismatch is round 10's own unclassifiable third category. Probe hygiene: the comparison was mutation-verified -- a different FileUuid for A produced 20 differing bytes at offsets 32-47 and 60-63, observed, then restored by hand-editing. That incidentally confirms round 9's point that FixedHeader.file_uuid is byte-visible and round 8's enumeration had omitted it. One file touched, 142 insertions, all inside cfg(test); no refusal removed; no canonical base carried, so the live constraint was never engaged; diff captured before the branch was deleted. Four paper rounds refined this comparison and none found that it silently depended on an unstated precondition. One execution found it in minutes, via the case a reviewer would least likely hand-pick. Had the probe stopped at the case round 10 implied, the contract would have been ratified on a comparison that fails for most documents. Still NOT RATIFIED, NOT DISPATCHABLE. Pins unchanged; the probe produced evidence, not amendments. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Ps1szk2mSfgp4Cz21eVH9x
This commit is contained in:
parent
5aed861e31
commit
39f261774a
|
|
@ -59,7 +59,62 @@ cannot leave one unrestored.
|
|||
byte-identical, M7's whole-image comparison is unsound **regardless of bases**,
|
||||
and round 10's fix is wrong too. If it **is**, the comparison design survives its
|
||||
first contact with the code and only the base leg remains unverified — pending
|
||||
S27. **No execution work may begin** — not implementation, not staging,
|
||||
S27.
|
||||
|
||||
### Probe RESULT — run 2026-08-08 on a discarded branch. It falsified round 10.
|
||||
|
||||
**Verdict: the round trip is byte-preserving, but ONLY from a fixed point — and
|
||||
round 10's comparison did not compare from one.**
|
||||
|
||||
| Case | `original` already a fixed point? | Round 10's comparison | From the fixed point |
|
||||
|---|---|---|---|
|
||||
| minimal, seed 42 | **yes** | **equal** (1641 B) | equal |
|
||||
| minimal, seed 99 | no | *not run* | equal (1800 B) |
|
||||
| with one extension | no | **295 differing bytes from offset 352** | equal (1894 B) |
|
||||
|
||||
**Round 10's design compared `A` against a `B` built from the *input* document,
|
||||
which is only valid when that document is already a fixed point of
|
||||
`document_from_bundle ∘ serialize_document`.** `minimal_document(42)` happens to
|
||||
be one — which is why the first probe passed and would have been reported as
|
||||
success. **Two of three documents were not, and the extension case diverged by
|
||||
295 bytes.**
|
||||
|
||||
**The non-idempotent field is `envelopes`, not extensions.** Diagnosed
|
||||
field-by-field: `document_id`, `manifest_schema_version`, `lineage_id`,
|
||||
`profiles`, `canonical_base`, `blobs` and **`extensions` — including every
|
||||
`TextChunk` payload — all survive exactly.** `document_from_bundle` applies a
|
||||
**canonical envelope ordering** (its own test is named
|
||||
`document_from_bundle_reads_every_section_and_orders_envelopes_canonically`), so a
|
||||
document whose envelopes arrive in any other order is not a fixed point, and its
|
||||
operation-block bytes differ.
|
||||
|
||||
**`project_text_document` → `parse_document` is LOSSLESS**: `b_doc == d` held in
|
||||
every case. The text leg was never the problem. **The defect was entirely in which
|
||||
artifact round 10 chose as the reference.**
|
||||
|
||||
**What M7 must therefore add — for round 11 to ratify, not for this probe to
|
||||
assume:** an explicit **fixed-point normalisation and assertion** before any byte
|
||||
comparison — build `B` from `document_from_bundle(serialize_document(doc))`, and
|
||||
**assert that document is a fixed point** — because otherwise a mismatch is round
|
||||
10's own "third category", a deterministic setup difference, and unclassifiable.
|
||||
|
||||
**Probe hygiene, recorded because the discipline demands it:** the comparison was
|
||||
**mutation-verified** — giving `A` a different `FileUuid` produced **20 differing
|
||||
bytes at offsets 32–47 and 60–63**, observed, then restored by hand-editing.
|
||||
(Incidentally confirming round 9's finding: `FixedHeader.file_uuid` is
|
||||
byte-visible at offset 32, and round 8's enumeration had omitted it.) The probe
|
||||
touched **one file, 142 insertions, all inside `#[cfg(test)]`**; removed **no**
|
||||
refusal (`CanonicalBaseUnsupported` occurrences unchanged at 7 and 8); carried
|
||||
**no** canonical base, so §1.2 was never engaged; and the branch was deleted. **The
|
||||
diff was captured before deletion.**
|
||||
|
||||
> **The methodological point, stated plainly.** Four paper rounds refined this
|
||||
> comparison and none found that it silently depended on an unstated
|
||||
> precondition. **One execution found it in minutes, and found it via the case a
|
||||
> reviewer would least likely hand-pick — a document with an extension.** M7's
|
||||
> first probe *passed*; had the probe stopped at the case round 10 implied, the
|
||||
> contract would have been ratified on a comparison that fails for most
|
||||
> documents. **No execution work may begin** — not implementation, not staging,
|
||||
not partial work against "the settled pins."
|
||||
|
||||
**History — the running tally, which has now gone stale three times and been
|
||||
|
|
|
|||
File diff suppressed because one or more lines are too long
Loading…
Reference in New Issue