Independent review against bff9c9a. One finding, blocking, and it inverted
M7's result.
M7 claimed the capability check "does not fire". Pin 3a requires commit and
commit_versioned to validate a newly emitted canonical base, which is
exactly what both B_raw and the parsed A commit. The check fires on both
paths and accepts, because the raw version equals the real authority. That
acceptance is the laundering result: the base is not slipped past an absent
check, it is admitted by a check working correctly that cannot tell a
coincidence from a rebuild.
As written, M7 was satisfiable by deleting pin 3a's writer check entirely --
a passing M7 demonstrating the exact opposite of its purpose.
M7 now requires three observations: A.image() equals B_fixed.image(); pin
3a's validation ran and accepted on both commits; and a control. The control
is required -- in the same run, same harness, repeat the import with a base
version deliberately not equal to the real authority and observe the commit
rejected with CanonicalBaseRequiresRebuild. The matching case succeeding
means something only once the mismatching case is seen to fail on the same
path, under the same removals.
M7's removals are now explicitly limited to the text refusals. Pin 3a is not
among them and may not be weakened: it is the thing under observation, not
an obstacle to it. Removing both boundaries would not be a stronger
mutation, it would be a different and empty experiment.
This is a new failure shape worth naming: an observation satisfiable by the
absence of the thing it observes. M7's earlier defects were about being
unrunnable, or comparing the wrong artifacts. This one would have run,
passed, and reported success on a tree where the writer check had been
removed. "The check does not fire" cannot distinguish a check that accepts
from a check that is not there, and only one of those is the finding.
Two dependent sites updated as pointers rather than restatements: section 7
item 4a's M7 row now owes every observation including the control, and item
1 notes the control's expected outcome is a rejection, so a reporter does
not read it as a problem.
Still NOT RATIFIED, NOT DISPATCHABLE. Findings 9, 6, 6, 5, 4, 3, 3, 2, 2, 1,
3, 2, 1. Blocking 4, 4, 4, 4, 2, 3, 3, 2, 2, 1, 2, 2, 1. Thirteen rounds,
none clean. Round 13 is the narrowest since the probe, but it asked a
question no earlier round had asked -- not "can this run?" or "does this
compare the right things?" but "could this pass for the wrong reason?" --
and that question has not been put to M1 through M6, M5a or M5b.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Ps1szk2mSfgp4Cz21eVH9x