# Verification receipts — public derivations

These are **curated public derivations** of the internal verification
record for the note *Coherence Is Not Truth* (v1.2) — condensed, with
connective prose written for public reading; repository, branch and
checkout names, hosts, retrieval logistics and internal record
identifiers neutralised. The guarantee is separate and exact: **every
verdict, gate, number and hash copied from the internal record is
unchanged.** Four receipts. Commit identifiers are git commit ids in the
private record, frozen at tag `fractal-tribalism-v1.2`; blob identities
for every file named below are in the accompanying artefact manifest.

## Receipt A — the review panel (2026-09-02 to 2026-09-04)

The note's propositions, experiments and the Paper 3 design were put
through a panel of external model reviewers under a fixed protocol, each
brief run without sight of the others' output. **Adjudication rule,
unchanged across all three rounds: a finding counts only if it names the
step and exhibits the object.** Rhetoric was left to the authors;
everything checkable was checked against the proofs, the tests and the
code on the record.

**The briefs and who took them.**

| brief | panelist(s) |
|---|---|
| 1 — prior-art hunt | Claude (live web; six targeted searches) |
| 2 — proof adversary (six surfaces) | GLM 5.3, DeepSeek v4-flash, Qwen 3.8 Max — three model families, independently |
| 2b — Proposition 3′ adversary (seven surfaces) | GLM 5.3, DeepSeek v4-flash, Qwen 3.8 Max |
| 3 — experimental-design referee | Qwen 3.8 Max |
| 4 — hostile venue referee | GLM 5.3 |
| 5 — claims auditor | DeepSeek v4-flash |
| 6 — cold reproducer | Claude — fresh context, fresh clone, README + note + review's reproduction section only, 40-minute box (about 6 minutes used) |
| 7 — Paper 3 design referee (draft v0.1) | GLM 5.3, Qwen 3.8 Max; blind referee reads of later drafts (v0.4, v0.5, v0.6, v0.10) by GLM 5.3 and DeepSeek v4-flash |
| 8 — focused preregistration read (draft v0.8) | GLM 5.3, DeepSeek v4-flash, Qwen 3.8 Max |

Assignment rationale as recorded: the strongest reasoner took the design
brief; the hostile-venue brief went to the model that had already argued a
counterexample to the end; the mechanical audit went to the fast model;
the cold reproduction had to be a fresh context with code execution. Two
further panelists were dropped for retrieval reasons and produced no
verdict; a supplementary same-family read was stopped without a verdict
and is not counted. Retrieval hosts, routes, keys and costs are part of
the internal record and are withheld here.

### Round 1 — proofs under attack (2026-09-02)

- **GLM 5.3:** SOUND on surfaces 1, 2, 3, 4, 6 with correct arguments,
  including a genuinely useful **strengthening of Proposition 2's proof**
  (network matrix ⇒ totally unimodular ⇒ all Smith invariant factors are
  1 ⇒ the kernel mod 2¹⁴ is exactly the integer cut lattice reduced mod
  B; no 2-power-annihilated phantom vectors). Its claimed counterexample
  to Proposition 3 — a λ(u,v) = 1 bridge whose support-0 attribution is
  unique but wrong — **does not survive adjudication**: it violates the
  proposition's premise (the corrupted edge must be *covered*; a bridge
  is precisely an uncovered edge, λ = 1 ⇔ bridge ⇔ on no cycle), so the
  iff's domain is λ ≥ 2, where the claim is sound. Two legitimate
  findings: Proposition 1 silently assumes decode floor ≤ K (one clause
  fixes it), and the Smith-form strengthening.
- **DeepSeek v4-flash:** SOUND on 1, 2, 3, 4, 6 (its surface-1 route —
  identity on chord columns ⇒ row independence ⇒ solution-set
  cardinality equals cut-space cardinality — is a neat alternative). Its
  one attack is **the same λ = 1 bridge construction** and fails the same
  premise. **Convergence finding:** two independent strong models misread
  the same sentence the same way — Proposition 3's λ = 1 clause is a
  legibility defect even though the proposition is sound. One-clause fix
  adopted.
- **Qwen 3.8 Max:** SOUND on 1, 2, 3, 5, 6 with correct arguments; its
  surface-1 route (chord-identity block plus tree-potential accumulation,
  addition and subtraction only, so valid in Z_{2¹⁴}) is a third
  independent proof of the composite-modulus kernel claim; on surface 5
  it handles the multi-block λ = 2 tie construction explicitly and
  correctly. **It did not take the λ = 1 bait** — the only one of the
  three proof adversaries not to. Its single GAP (surface 4: Proposition
  1's sufficiency proof never checks that the perfect score K clears the
  floor; F = 65 > K = 64 makes decode return nothing despite injectivity)
  was adjudicated **a statement defect, not a mathematical gap** —
  identical to GLM's fragility note and already the first required edit.
- **Prior-art hunt (Claude):** no collapse condition triggered — nothing
  found that composes VSA bindings around ≥ 3-agent loops, no resonator
  missing-factor repair, no deliberately farmed divergence, no system
  reusing the cycle residual as the repair. One near-miss adopted for §2:
  Levy et al., "Unsupervised Translation of Emergent Communication," AAAI
  2025 (arXiv:2502.07552) — two-space, no loops, no VSA.

**Round 1 outcome:** zero surviving counterexamples; two legibility
defects (the Proposition 1 floor clause, the Proposition 3 covered-premise
clause); one optional strengthening (Smith form); one near-miss citation.
All three adversaries agreed the composite-modulus kernel step is the
most fragile-looking sentence, and all three supplied a proof of it. The
falsification harness was re-run the same day at seed 7 (5000/300/300):
zero counterexamples.

### Round 2 — design, venue, claims, cold reproduction (2026-09-02)

**Brief 6 — cold reproducer.** Every deterministic figure it could reach
reproduced bit-identically: the witness suite (169/169), §6.2, §6.5 (N =
100), §7.4 (λ = 5 at N = 12 and 30), the §8 window edges and the full M ×
cross grid with its one closure, §9's λ(u,v) cross-tab at four seeds plus
three more, the emergent-schedule crux and its control, and the
falsification harness (seed 7: 20000 / 1868 / 1995 cases, zero
counterexamples). **Five findings, all verified, all about instructions,
not numbers:** (1) the README's Python test command triggered a build
needing access to a private dependency — fixed in the README; (2) the
review's reproduction block assumed a virtual environment nothing creates
— fixed in the review document; (3) the paper's changelog said 166 tests
where the suite was 169 at the tag — paper edit; (4) the review's
stale-extension warning was not true of a fresh clone — reworded; (5) the
closed cell's third crossing (337/1241.75 ≈ 0.271) is reachable only
through a test, not a CLI — optional edit, now stated in Appendix A.
Verdict adopted verbatim: *yes on the numbers, no on the instructions.*

**Brief 5 — claims auditor (DeepSeek v4-flash), seven findings, each
checked by opening the named test:**

1. §1's "identity holds exactly at all of seeds 1–32" was pinned only at
   seeds 1, 7, 8 — **CONFIRMED and closed the strong way**: a new pin
   asserts measured == predicted at every seed 1–32 (block counts stay in
   36–44); passes; §6.2's wording corrected.
2. §12 "in full generality" — **CONFIRMED as overreach in wording**;
   edited.
3. Abstract "serializable as SPO triples" — **PARTIAL**: three
   per-component round-trip tests exist, no single invariant; the three
   are now named in Appendix A.
4. §4 "random drift essentially never breaks comprehension" — **CONFIRMED
   as ASSERTED**, not measured; labelled.
5. §7.3 "~B⁻⁶⁴" — **NOT a finding as stated** (a labelled estimate); the
   unstated uniformity assumption is now stated.
6. §6.2 "vanishingly small fraction" — **NOT a finding**; the sentence
   disclaims proof.
7. §9 "a contested interface is dense" — **REFUTED as a finding, but
   exposes a missing citation**: the mechanism is measured and pinned
   (border mean λ(u,v) 4.68 vs interior 2.97; mean minimum degree 4.92 vs
   3.37); the numbers are now quoted.

Net: one real pin gap (closed), four wording edits, one missing citation
of an existing pin. No claim revision.

**Brief 4 — hostile venue referee (GLM 5.3):** recommends Reject, six
attacks. Adjudicated for what is checkable and actionable:

- **Attack 1 (synchronization renamed)** — fair, and conceded in Appendix
  B; its characterisation of Proposition 2 as bounded-distance decoding
  uniqueness for the graph's cut code is the sharpest statement any
  panelist made. Actionable residue: say which statement is *not* a
  corollary (the gated repair operator with refusal semantics).
- **Attack 3 (the economy proves the thesis by construction)** — the one
  attack with a missing experiment behind it. Verified in the code:
  exactly three regimes, instruments tied to the farmed regime, register
  drift zero, so the loop instrument does 12 audits and 1 patch in 720
  tasks. **Demanded analyses adopted** (E1, E2 below).
- **Attack 6 (no external method run)** — correct; the cited noisy-regime
  counterpart is never executed (E3). Not blocking.
- **Attacks 2, 4, 5** (toy; elementary propositions; pins are not
  evidence) — the standard objections the note's limitations section and
  Appendix A already answer as well as they can be without real data.
- **Factual checks:** every quotation the referee relied on (12 audits /
  1 loop patch; farmed 6 vs unfarmed 3 misdecodes; genealogy 64 % of the
  bill) matches the paper.

**Brief 3 — experimental-design referee (Qwen 3.8 Max), seven findings
and eight named sensitivity analyses:**

1. **The §8 window is conditional on the 12 × 60 schedule — CONFIRMED,
   and it bites.** Re-run at seeds 7, 1, 2, 3 over horizons 3–12: the
   window is **closed at 3 and 4 epochs for seeds 7 and 3** (0.318 >
   0.271 at seed 7 × 4 epochs) and **open at every horizon ≥ 5 at all
   four seeds**, widening with horizon (seed 7: 0.242–0.306 at 5 epochs,
   0.155–0.611 at 12, 0.098–1.396 at 48; 24 × 120 gives 0.143–1.534).
   Required edit: the window needs a horizon of at least five epochs at
   the reference schedule; pinned.
2. §8's economy configuration unlabelled (threshold 2, budget 1 = config
   B) — **CONFIRMED**; one clause.
3. §8 drift set to zero — **CONFIRMED**; converges with the hostile
   referee's attack 3 (E2).
4. Graph families and the s ≤ 4 cap — **PARTLY ANSWERED by an asset the
   referee could not see**: the falsification harness already attacks
   Propositions 2–3 on four adversarial shapes with ~954k instances over
   seeds 1–32 and zero counterexamples. The real finding: Appendix A did
   not cite it. Now cited. Residue → E5.
5. §9 CA generality — legitimate demand, recorded as E6.
6. §7 comprehension numbers from n = 3 / n = 4 utterances — legitimate
   demand, recorded as E7.
7. §6.5 N = 100 at seed 7 only — **CONFIRMED and answered**: run at seeds
   1–8, exact detection at every seed (dirty basis cycles 18 / 40 / 13 /
   7 / 9 / 9 / 9 / 7); now pinned per seed.

The referee's first missing-sensitivity item (the identity at all 32
seeds) is the gap the claims auditor found independently — a second
**convergence finding**, closed by the new pin.

**Round 2 outcome:** zero claim revisions; two findings that changed what
the paper must *say* (the window's horizon boundary, pinned; the §1
identity's pin); ten wording, citation and labelling edits; one framing
question for the authors; eight demanded runs.

### The demanded runs, E1–E8, with dispositions

- **E1 — genealogy-only regime (the loop instrument's marginal value).
  DONE.** Seeds 1–16, reference schedule, drift zero: farmed −
  genealogy-only wire **+3.0 at every seed** (12 audits × 0.25);
  successes 0 at 13 seeds, **+2 at seed 3, −1 at seeds 11 and 13**;
  marginal energy at w = 0.25 negative at 15 of 16 seeds; the farming
  window without audits non-empty at every seed, edges moving by < 0.01.
  A claim-narrowing negative the paper must carry: in the priced economy
  as modelled the farming window is a genealogy-and-anchor result and the
  loop channel's marginal value is ≤ 0 at fifteen of sixteen seeds.
  Pinned.
- **E2 — nonzero drift in the economy. CLOSED, NOT RUN: not expressible
  without changing the model.** The economy learns each pair's map once
  and speaks every task in topic 0, so sparse drift would not break a
  decode and the audits would see nothing. The successor design (topic-
  conditional production, per-contact re-anchoring, cross-register tasks)
  became the preregistered N-tribe economy of Receipt D.
- **E3 — an external comparator run. DEFERRED**; does not gate the paper.
- **E4 — the economy under config A. DONE.** Seeds 1–16, threshold 3,
  budget 2: the window is open at every seed and the sixteen windows
  share 0.256 < w < 0.537 (config B: 0.2556 < w < 0.4831). Pinned.
- **E5 — the s ≤ 4 support cap. DONE, confirmed conservative:** on the
  degree-6 circulant on 13 nodes (λ = 12) an s = 5 corruption satisfies
  2s < λ, the default cap draws the named refusal, and k_max = 5
  recovers the truth uniquely and certified. Pinned.
- **E6 — the CA regime, varied. DONE.** Torus {16, 24, 32} × founders
  {32, 64, 128} at seed 7 plus the four corner cells at seeds 1 and 3
  (seventeen cells, 120 epochs each): λ(u,v) = 2 ambiguous and λ(u,v) ≥ 3
  unique with **zero exceptions in every cell** — 1,284 λ = 2 edges and
  2,281 λ ≥ 3 edges. Pinned (two cells, exact counts).
- **E7 — closed-loop operator stress test. DONE, clean.** Seeds 1–32 ×
  anchor fraction {0.3, 0.6, 0.9} × configs A/B, 888 cases plus 192
  evidenced-edge cases: the community names exactly the quirked word
  888 / 888; the listener misses exactly it before repair 888 / 888; the
  loop is flat and the mended token on the baseline after repair 888 /
  888; no other token disturbed 888 / 888; exactly one of {quirked,
  target} understood after repair, never both, 888 / 888; the tie to the
  lexicographically first 888 / 888; evidenced-edge corollary 70 / 70;
  fully calibrated quirk, nothing to refuse, 122 / 122. Which word
  survives is the tie rule, not the operator: the quirked word wins in 82
  of 888 and its collision target in 806. Pinned (seeds 1–4).
- **E8 — §6's seed-level statements under both configs. DONE, zero
  violations.** Seeds 1–32: surface disagreement exactly 0.0 on every
  pair at every seed; loop dirty and every 2-cycle flat at every seed;
  exception rate exactly 0.0 at idiosyncrasy 0 and non-decreasing in
  idiosyncrasy on every pair; the 9/26 identity at all 32 seeds under
  both configs. Pinned (seeds 1–8).

Stopping rule applied: both closing checks came back clean, so no further
sweep.

### The falsification harness (the panel's machine member)

Propositions 1–3 are attacked through the actual modules on four
adversarial graph shapes (sparse random connected, circulant, ring plus
chords, two cliques joined by a thin cut) with random supports satisfying
2s < λ, seeds 1–32: **zero counterexamples in ~954,000 instances.**
Proposition 1's injectivity boundary held in all **800,000** cases
(399,634 injective-exact, 400,366 collision-erring, no disagreements);
across **74,457** random graphs, all **16,362 in-boundary Proposition 2
cases** returned unique blame equal to the planted truth, every one
certified, with 58,095 outside-boundary cases behaving as no-claim
territory; Proposition 3's local-λ iff held in both directions across
79,807 cases (52,898 unique at λ ≥ 3, 26,909 ambiguous with the truth
among the ties at λ = 2). Exit code 1 on any hit.

### Proposition 3′ and round 3 (2026-09-02 to 2026-09-03)

After round 2 the one open proof item — the general-s local form of
Proposition 3 — was settled: sufficiency proved (every 2-sided cut meeting
the corrupted edges carries more clean than corrupted edges ⇒ unique and
true; λ(u,v) ≥ 3 at s = 1), the converse **refuted** by an explicit
six-node instance, and the exact criterion stated for residuals in general
position. All three checked through the solver on **39,339 instances**
(s = 2: 19,792; s = 3: 19,547; seeds 1–32; ≤ 12 covered nodes so cuts and
labellings are enumerated exhaustively):

| claim | instances | outcome |
|---|---:|---|
| 3′ hypothesis holds ⇒ unique and true | 16,580 | 16,580 / 16,580 |
| exact criterion predicts the solver | 39,339 | 39,339 / 39,339 |
| 3′ hypothesis fails, yet unique and true (converse refuted) | 22,759 | 5,119 |
| naive local condition (min λ(u,v) > 2s) ⇒ unique and true | 4,987 | 4,987 / 4,987 |
| uniquely wrong verdicts | 39,339 | 0 |

**Brief 2b, three readers, zero counterexamples**, three convergent
judgements of the fragile step, every one repaired by a definition or an
explicit case, none by a change of claim: GLM 5.3 — two
under-specifications adopted ("2-sided cut" means any nontrivial vertex
cut, shores not necessarily connected; "general position" must exclude
every signed-sum cycle relation, exhibited on a six-node instance with
three equal parallel residuals); DeepSeek v4-flash — the same fragile
step, with the minimal exhibit (a triangle with residuals 1, 1, 2);
Qwen 3.8 Max — all seven surfaces SOUND, one presentational gap adopted
(the empty case of the summation, exhibited on K₄) and the modular
non-generic triangle (residuals 1, 1, 16382 ≡ −2).

**Brief 7, the Paper 3 design.** GLM 5.3 (eleven findings) and Qwen 3.8
Max (ten findings) **converged on the defect that blocked the freeze**:
an intervention applied before minting changes codes, anchors and maps,
so an off-diagonal would measure construction leakage, not diagnostic
conflation. Verdict on v0.1: must not freeze. The design then went
through blind referee reads at v0.4, v0.5, v0.6 and v0.10, the brief 8
focused reads at v0.8 (GLM 5.3: six findings, all confirmed, all
must-fix, none re-opening a settled decision), and the lead author's own
reads and rulings at every intermediate draft, each adjudicated into the
next, to the signed freeze at v0.19 (Receipt C).

**What this receipt does and does not establish.** It establishes that
three model families attacked the propositions and Proposition 3′
independently and found zero surviving counterexamples; that every
adjudicated finding is recorded with its disposition; that the two
findings which changed what the note must say were pinned rather than
argued; and that a machine adversary with no shared blind spot ran ~954k
instances and 39,339 instances without a hit. It does not establish that
the propositions are true beyond their stated premises (the λ = 1 attack
failed on the premise, not on a proof), that the panel was exhaustive
(two panelists were dropped; E3 was never run), or anything about the
panel's reasoning quality beyond what its exhibited objects show.

## Receipt B — the pin suite at the tag (2026-09-05)

The note's reproducibility contract is the reverse of a normal test's:
**pins are never loosened; if one breaks, the note is what gets
corrected.** This receipt records a fresh-clone run of that contract.

- **Checkout:** a fresh clone at commit `c458297`, the commit current
  when this receipt was taken; the identity is re-stamped at the tag
  `fractal-tribalism-v1.2` when it is cut.
- **Route:** the README's, as corrected after brief 6 — a virtual
  environment created with `uv venv`, `pytest` and `pyyaml` installed
  into it, the pure-Python backend selected, no native build.
- **Result:** `501 passed, 13 skipped in 65.79s`. The skipped tests are
  guarded by conditions the pure-Python route does not meet — chiefly the
  native extension, absent by design on this route.
- **§6.5's N = 100 rows:** pinned per seed at seeds 1–8 — dirty basis
  cycles **18 / 40 / 13 / 7 / 9 / 9 / 9 / 7** — and passing.
- **Every Appendix A command run and producing its JSON** — the six
  commands the note's Appendix A lists, run as stated there: the tribe farm
  (seed 7, 30 epochs, contact schedule AB@0, BC@1, CA@0); the scaling
  harness (seed 7, 30 agents, 5 quirks); the attribution harness (seed 7,
  30 agents, degree 5, 3 quirks); the task economy's regime sweep (seed 7);
  the economy's knob sweep (seed 7, 16 corner seeds); and the emergent-
  geography board (seed 7). Each returned its JSON line without error. Two outputs quoted exactly (the machine-local
  `elapsed_ms` field omitted):

      {"agents": 30, "edges": 60, "chords": 31, "cycles": 31, "injected": 5, "dirty_cycles": 13, "detected_tokens": ["t01","t11","t20","t27","t28"], "all_exact": true}

      {"agents": 30, "edges": 75, "lambda": 5, "cycles": 46, "quirks": 3, "blamed_exact": true, "certified": true, "ambiguous": 0, "closed": true}

- **No RNG state anywhere:** every draw is keyed by (run seed, label), so
  the outputs above are functions of the arguments and the committed
  code, not of the machine.

**What this receipt does and does not establish.** It establishes that
at the recorded commit, on a fresh clone following the public route, the
complete Python suite passes with the stated count and every Appendix A
CLI produces its JSON, with two outputs reproduced byte-for-byte as
quoted. It does not establish the native backend's conformance (skipped
on this route; covered by the record's separate conformance suites), the
machine-local timings (unpinned by design), or that the pins are
*correct* — only that the note's figures and the tests' assertions agree
at this commit.

## Receipt C — Paper 3's preregistration chain (2026-09-04)

Experiment V (§11) was preregistered, frozen, signed, calibrated and run
in a fixed order, with every ruling recorded before the data it concerns.

**Design freeze.** The lead author signed design document v0.19 at commit
`f8b1f2dcc1aab2d5de989bb18ff732b48324e766` (document blob
`8b7e0b669c0a4681d50e700af720980f61fbde58`), both verified against the
repository; the document is not edited again, and any later change is a
new document citing this one. The manifest confirms the document's blob
at the release commit equals the frozen blob.

**Amendment 1 (signed before any calibration or development data were
touched).** The frozen single-entry translation fault proved
unconstructible: one map entry moves the clerk's expectation of the
target away from the speaker's unchanged production, the decode falls
below the floor and refuses, and every I = 1 cell voids at the landing
gate. Replaced by Proposition 1's swap — two coupled exception entries on
the canonical map of the edge, for the target and landing tokens — with
one necessary consequence: I repair is permitted only when *both* token
diagnostics are fault-certified, each names the edge and each supplies
its own value; both entries are then overruled atomically and closure
requires both tokens restored; otherwise no I write. The merger is
recorded as the impossibility exhibit and is never a comparator or an
arm.

**Implementation signatures.** A signature is the freeze of the built
apparatus: at a named commit, the git blob hash of every generative file
and verbatim quotations of every function the design names, together
with the frozen constants (`K_MAX` = 4, `WINDOW` = 16, `HISTORY_EVENTS` =
256, `MIN_ANCHORS` = 20, `JACCARD_BAND` = (0.25, 0.75), `FORCED_EPOCHS` =
(1, 4, 7, 10), bootstrap seed 20260904 with 10,000 resamples,
contributing-seed floor 25), with both build gates passing there. Any
post-signature change to a pinned file, a diagnostic parameter, the weld,
the generator, the task constructor, the tariff or the design document
voids the allocation. Signature 1 at `a615ecc` (the Amendment 1 build);
signature 2 at `daea9a5` (Amendment 2), superseding it. Between the two,
exactly three blobs changed — the runner, and the new calibration
validator with its fixtures; every other generative blob is identical.
The blob hashes are in the manifest.

**Calibration, exactly as it happened.** The first calibration ran from
`a615ecc`: fitting seeds 1001–1500, validation 1501–2000, 4000 + 4000
strata, none unavailable, no tracebacks; positive controls 500/500 with
the planted share recovered exactly; in-band validation seeds 406–490 of
500; resolver refusals 0; medians 0.21–0.32. **One validity criterion
failed in every stratum** — "the pinned detector's per-pair exception
rate equals the constructed residual-carrying share within ± 0.02"
failed on 5–7 % of pairs, maximum deviation 0.0244, one register token.
Diagnosis, reproduced on a failing pair: the validator's share counted a
concept as residual-carrying iff the pair's *observation sets* differed,
whereas the construction carries the bind-sum of the 16-row *windows*
preceding each observation, and history row 0 has an empty window, so a
witness of row 0 alone carries no residual. Counting concepts whose
carried windows differ, the identity held **exactly** — max |rate −
share| = 0.0000 over 388 pairs of six fitting seeds (0.0217 under the
observation-set count). The detector, the generator and every pinned
diagnostic were untouched; the defect was in the validator's bookkeeping.

The author was given two options — apply the frozen rule literally
(every stratum invalid, every `M_I` exploratory) or correct the
bookkeeping, re-run and re-sign — and took the second, **Amendment 2**,
ruled after the first calibration and before any development or held-out
seed, with one addition: the validation range **1501–2000**, having
helped diagnose the implementation, was **retired** and a fresh disjoint
range **2601–3100** allocated and recorded before invocation; fitting
1001–1500 unchanged; the 0.02 tolerance not increased; no pair
special-cased; the first calibration preserved as the historical result.
The corrected validator neither imports nor calls the detector; four
fixtures pin the row-zero, non-empty-window and mixed-window cases.

**Calibration freeze (signature 2, `daea9a5`), every stratum valid:**
farm references ρ_0.2 = **0.357143**, ρ_0.3 = 0.517880, ρ_0.4 = 0.642857
(median over 300 pair-seeds each; reproduced exactly from the first run);
identity max absolute deviation **0.0000** in every stratum; positive
controls **500/500** everywhere; in-band validation **394–492 of 500**
(490, 491, 491, 492 at N = 3; 409, 445, 394, 431 at N = 6); resolver
refusals **0** everywhere; no stratum unavailable; no tracebacks. Every
stratum's median per-pair detector rate lies below ρ_0.2 = 0.357, so
**every stratum carries the low-background / trivially adequate
annotation** — reproduced under the corrected calibration and therefore
final; the first calibration's same observation was recorded as
forbidden to motivate any further rule change until reproduced.

**Development (seeds 101–116), written before held-out.** Run from
`daea9a5`; validated manifest **128 / 128** strata attributed, generative
blobs identical, no problems. Sixteen seeds is below the floor of 25
everywhere, so every quantity is descriptive and no bound is issued.
Six of 128 strata were construction failures (all at N = 6); every
constructed cell admitted (976 / 976); no *moved*; every eligible repair
closed; N = 3 ambiguous everywhere; N = 6 primary `M_I` 1.0 on 8–12
seeds per stratum. One analysis correction recorded before held-out: the
summariser had computed the §8 adequacy statistic from calibration rows
rather than on the account's own in-band seeds with the pinned detector;
corrected, with no pinned generator, diagnostic, weld, task constructor,
tariff or threshold changed. (The manifest's signature check shows the
summariser as the one signed blob that differs at the release commit;
this is that correction.)

**Held-out (seeds 117–152), run once.** From `daea9a5`, after the
development account was written and with the design (f8b1f2d +
Amendments 1–2), the signature and the calibration freeze unchanged.
Validated manifest: **288 / 288** strata attributed to one producer,
generative blobs identical, no missing, extra, unattributed or
doubly-attributed cell, no problems. Smoke seeds 9001–9002 are
feasibility pilots outside every allocation; seeds 117–152 are never
reused.

**The scientific object.** Commit `e39916e` was ruled the scientific
object: the remaining work editorial and administrative only; apparatus
and analysis code not touched again.

**The floor rule.** A quantity with fewer than 25 contributing seeds is
printed as *unsupported at this allocation* with its count and no bound,
exactly as preregistered; the floor is the estimand's precision rule,
fixed before any seed ran, and missing it yields that label, not more
sampling — no further allocation is owed to lift `M_I` over the floor.

**The claim-relevance table, verbatim from the confirmation account:**

| preregistered claim | outcome |
|---|---|
| per-stratum `M_I` with a bound | **unsupported at this allocation** in all four N = 6 strata (15–23 contributing) |
| "no seed exhibited *moved*, ≤ 8.0 %" | **supported**, 0 / 36 in every stratum |
| "no seed exhibited *moved*, ≤ 5 %" | unsupported at this allocation (needs 0 / 59) |
| certified vs uncertified `M_I` difference | not reportable: 1–2 uncertified seeds per stratum |
| adequacy of the map class | **established** in all eight strata, low-background annotation everywhere |
| `R_I` / `W_I` at λ = 2 | **supported**: 1.00 / 0.00 with degenerate bounds in every N = 3 stratum |
| composite by cell vector | supported at N = 6 (30–32 seeds) and N = 3 (35) |

**What this receipt does and does not establish.** It establishes the
order of events — freeze, amendment, signature, calibration, diagnosis,
amendment, re-signature, calibration freeze, development account,
held-out run once — with each ruling dated before the data it concerns,
and that the released blobs are the signed ones except for the one
recorded analysis correction. It does not establish that the design was
the right one (the primary estimand missed its own floor, and the note
says so first), that the validator defect was the only defect (it was
the one the frozen criterion caught), or that the low-background
annotation is a property of anything beyond the frozen generator.

## Receipt D — the N-tribe economy (2026-09-03)

E2 of Receipt A was not expressible in §8's economy; its successor was
preregistered before any code for it existed (freeze `df37a52`;
amendments A1–A4 pilot-driven and pre-development; B1–B6 bookkeeping).

**The question, as frozen:** did the loop channel fail to add value in
§8 because loop-based repair is economically inert, or because the fixed
triangle and zero-drift economy generated no useful repair
opportunities? **The criterion, fixed:** the loop channel "earns its
keep" iff (i) mean ΔE = E_F − E_G > 0 at w = 0.37 over the development
distribution, **and** (ii) ΔE > 0 in at least 75 % of development cells,
**and** (iii) both hold again on the held-out seeds without any change
to the design. "Positive somewhere" is explicitly not the criterion.
Eligibility: a cell qualifies only if its unfarmed trajectory produced at
least one seed-word failure — the loop must have work.

**Development (seeds 1–16): criterion not met.** 1,152 cells, validated
manifest (producer 4530ee0, validator 5012903, generative blobs
identical, no duplicates, no unavailable cells). Qualifying opportunities
**4**, in **1 of 16** seed blocks, all at the widest drift; ΔE on them
mean **−32.7**, positive in **0 of 4**; over all 1,152 cells ΔE negative
in every cell (max −1.11); F − A = 0 in 1,150 of 1,152. Decision tree
branch 1: eligible cells exist, so the write-up is the freeze and the
held-out grid is invoked exactly once, under one commit, with no design
change; it cannot rescue the criterion.

**Confirmation (seeds 17–32), read under the three outcomes fixed before
its manifest existed:**

| | development | **confirmation** |
|---|---:|---:|
| cells | 1,152 | 1,152 |
| qualifying opportunities | 4 | **20** |
| seed blocks with any opportunity | 1 of 16 | **2 of 16** (seed 20: 14 cells; seed 32: 6) |
| descriptive cell rate | 0.0035 | 0.0174 |
| naive cell-level bound, one-sided 95 % (not assumption-free) | 0.0079 | 0.0251 |
| seed-block bound, one-sided 95 % | 0.264 | **0.344** |
| ΔE = E_F − E_G at w = 0.37 on eligible cells: mean | −32.7 | **−17.1** |
| eligible cells with ΔE > 0 | 0 of 4 | **0 of 20** |
| seed-block means | {15: −32.7} | **{20: −6.2, 32: −42.6}**, 0 positive |
| ΔE over all cells: max | −1.11 | −1.11 |
| F − A ≠ 0 (repairs changed the ledger) | 2 of 1,152 | **0 of 1,152** |

The confirmation grid's validated manifest attributes 1,000 cells to
producer `a50654e` and 152 to `cf2af7a` — the resume after a recorded
machine interruption, under a commit whose nine generative modules are
byte-identical, no cell partial, no cell read between interruption and
resume. **Outcome (b): opportunities occur and the loop remains negative.
The economic negative is confirmed in the eligible regime on untouched
seeds.** Pooled (secondary, not a substitute for either account): 2,304
cells, 24 opportunities, 3 of 32 seed blocks.

**The mechanistic chain replicates; the opportunity distribution did
not.** Twenty cells in two blocks against four in one, eight at
idiosyncrasy 0 and eight at N = 3 where development had none. What
replicates is the mechanism: instrument-created seed-word failures 3,016
→ 3,151 against 4 → 20 unfarmed; the loop repaired 9 and 2 of them;
attributions unique / ambiguous / refused 17,028 / 48,672 / 44,568 →
18,030 / 48,672 / 43,776; unique verdicts naming an edge in the truth set
2,202 of 17,028 (13 %) → 2,118 of 18,030 (12 %) — **the solver's unique
verdict named the wrong edge about seven times in eight in both
accounts**; repairs 33,615 → 36,051, excess cleared 82 % → 81 %, decode
still intact 100 % → 100 %; payback +2 / 47,664 → +1 / 47,196; the F
window open in 0 / 300 → 0 / 282 of 576 cells by cadence. Re-anchoring
relearned every epoch in one register and applied in the other
manufactured about 150× the failures raw drift produced, and no
instrumented arm beat forced uniformity at any tested price in any cell
under that cadence.

**The limit, stated in the record and kept here.** The economy never
presented a collision-shaped corruption inside Proposition 2's
identifiability boundary — the regime E7 measured and the only one with
a demonstrated repair. The loop-value question *in that regime* remains
reserved to E7's evidence; this result narrows where the instrument is
worth its cost and does not show loop repair inert in principle. **A
miss, included:** the preregistration's list of surviving outcomes did
not contain the one that occurred — the loop's target condition appeared
inside the instrumented arms, created by the companion instrument, and
the loop did not repair it.

**What this receipt does and does not establish.** It establishes that
the question and criterion were fixed before code existed, that the
development account failed the criterion on its own terms, that the
held-out grid was invoked once and agreed on untouched seeds, and that
solver-unique and truth-correct counts were kept as separate fields
throughout. It does not establish that loop repair is worthless (the
identifiable regime was never presented), that the drift generator is
realistic (it is preregistered, not calibrated to anything outside the
model), or that the confirmation's 20 opportunities were enough to say
more than "negative in 20 of 20".
