Independent review against b842975. Six findings, four blocking. Every
blocking finding was a defect in text rounds 1 and 2 wrote.
Pin 3a still carried the rationale round 2 retracted. Section 0.4 says
there is no in-tree production base writer; pin 3a still said "0.4 shows
production code minting a stale document". The contract asserted a claim
and its negation. Rewritten onto the footing that survives: commit and
commit_versioned are public API and guard out-of-tree callers, not an
in-tree path. This is the third occurrence of fix-one-site-leave-the-
others -- round 1 fixed one spelling of a count, round 2 fixed section 0.4
and left the Rung type paragraph and touch row 2.
M5a had no observation mechanism. Pin 3 required the capability be stored
and nothing exposed it; Bundle has 17 public accessors and none for
capabilities, so no textproj test could inspect it. Bundle::capabilities()
is now pinned. That is new scope and is flagged as such for round 4.
M5b could not fail. If the supplied capability and the base version both
derive from CURRENT_REDUCTION_ALGORITHM_VERSION -- the natural
implementation, since roundtrip.rs:367 hardcodes ReductionAlgorithmVersion(0)
today -- both operands move together and the comparison passes for every
value of the constant. That is section 0.1's own tautology reproduced
inside the mutation built to detect it. The base version must now come from
a source that does not track the authority, and both operands' provenance
must be reported.
M6's replacement named a scenario with no test. Test 6 stops at opening, so
nothing asserted that an unrelated commit succeeds; an implementation
rejecting every post-base commit passed tests 2/5/6/8 and the broadening
had nothing to break. Test 9 added.
Cleanup: touch row 7 listed generators.rs as "call sites, real authority"
though it has zero Bundle::open/create calls, and its rng.range(0, 8)
versions are exactly the arbitrary wire values pin 3b assigns to synthetic
capabilities -- split to row 7a. Section 7's call-site attribution credited
round 1 where rounds 1 and 2 are both load-bearing.
The pattern is legible now and it is not about counts. Round 1 found stale
text, round 2 found unexecutable mutations, round 3 found that three
separate mutations were unrunnable in three different ways: M5a could not
observe, M5b could not fail, M6 had nothing to break. A mutation is only as
good as the test it breaks. Section 7 item 4a now requires, for every
mutation, the named test it breaks and the provenance of each operand.
Still NOT RATIFIED, NOT DISPATCHABLE, pins not frozen. Defect rate across
three rounds is 9, 6, 6 -- not converging. The newest text has had zero
adversarial passes.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Ps1szk2mSfgp4Cz21eVH9x