{
  "capability_profile_table": {
    "agreement_is_the_check": "classify() is a lookup on the lattice; analyse_pair walks each pair. They are computed by different code paths and must agree on every corpus pair. A disagreement means the TABLE is wrong, not the pair analysis, because the pair analysis is what the headline verdicts are built from.",
    "disagreements": [],
    "n_disagreements_with_per_pair_analysis": 0,
    "n_rows_in_table": 64,
    "per_pair_rows": [
      {
        "assignable_but_NO_corresponding_shape": [],
        "assignable_hazard_fields": [
          "replay_amplified",
          "secret_exfiltrated",
          "unauthorized_write"
        ],
        "capability_shapes_present": [
          "READ_THEN_EGRESS",
          "WRITE_THEN_EGRESS"
        ],
        "fields_no_shape_screens_for": [
          "irreversible_change",
          "replay_amplified",
          "unauthorized_write"
        ],
        "pair": "everything+fetch",
        "table_verdict": "POSSIBLE",
        "union_tags": [
          "NET_SINK",
          "NON_IDEMPOTENT",
          "READS",
          "WRITES"
        ]
      },
      {
        "assignable_but_NO_corresponding_shape": [],
        "assignable_hazard_fields": [
          "irreversible_change",
          "replay_amplified",
          "secret_exfiltrated",
          "unauthorized_write"
        ],
        "capability_shapes_present": [
          "READ_THEN_EGRESS",
          "WRITE_THEN_EGRESS"
        ],
        "fields_no_shape_screens_for": [
          "irreversible_change",
          "replay_amplified",
          "unauthorized_write"
        ],
        "pair": "everything+filesystem",
        "table_verdict": "POSSIBLE",
        "union_tags": [
          "DESTRUCTIVE",
          "NET_SINK",
          "NON_IDEMPOTENT",
          "READS",
          "WRITES"
        ]
      },
      {
        "assignable_but_NO_corresponding_shape": [],
        "assignable_hazard_fields": [
          "irreversible_change",
          "replay_amplified",
          "secret_exfiltrated",
          "unauthorized_write"
        ],
        "capability_shapes_present": [
          "READ_THEN_EGRESS",
          "WRITE_THEN_EGRESS"
        ],
        "fields_no_shape_screens_for": [
          "irreversible_change",
          "replay_amplified",
          "unauthorized_write"
        ],
        "pair": "everything+git",
        "table_verdict": "POSSIBLE",
        "union_tags": [
          "DESTRUCTIVE",
          "NET_SINK",
          "NON_IDEMPOTENT",
          "READS",
          "WRITES"
        ]
      },
      {
        "assignable_but_NO_corresponding_shape": [],
        "assignable_hazard_fields": [
          "irreversible_change",
          "replay_amplified",
          "secret_exfiltrated",
          "unauthorized_write"
        ],
        "capability_shapes_present": [
          "READ_THEN_EGRESS",
          "WRITE_THEN_EGRESS"
        ],
        "fields_no_shape_screens_for": [
          "irreversible_change",
          "replay_amplified",
          "unauthorized_write"
        ],
        "pair": "everything+memory",
        "table_verdict": "POSSIBLE",
        "union_tags": [
          "DESTRUCTIVE",
          "NET_SINK",
          "NON_IDEMPOTENT",
          "READS",
          "WRITES"
        ]
      },
      {
        "assignable_but_NO_corresponding_shape": [
          "secret_exfiltrated"
        ],
        "assignable_hazard_fields": [
          "replay_amplified",
          "secret_exfiltrated",
          "unauthorized_write"
        ],
        "capability_shapes_present": [],
        "fields_no_shape_screens_for": [
          "irreversible_change",
          "replay_amplified",
          "unauthorized_write"
        ],
        "pair": "everything+sequentialthinking",
        "table_verdict": "POSSIBLE",
        "union_tags": [
          "NET_SINK",
          "NON_IDEMPOTENT",
          "READS",
          "WRITES"
        ]
      },
      {
        "assignable_but_NO_corresponding_shape": [],
        "assignable_hazard_fields": [
          "replay_amplified",
          "secret_exfiltrated",
          "unauthorized_write"
        ],
        "capability_shapes_present": [
          "READ_THEN_EGRESS",
          "WRITE_THEN_EGRESS"
        ],
        "fields_no_shape_screens_for": [
          "irreversible_change",
          "replay_amplified",
          "unauthorized_write"
        ],
        "pair": "everything+sqlite",
        "table_verdict": "POSSIBLE",
        "union_tags": [
          "NET_SINK",
          "NON_IDEMPOTENT",
          "READS",
          "WRITES"
        ]
      },
      {
        "assignable_but_NO_corresponding_shape": [],
        "assignable_hazard_fields": [
          "replay_amplified",
          "secret_exfiltrated",
          "unauthorized_write"
        ],
        "capability_shapes_present": [
          "READ_THEN_EGRESS"
        ],
        "fields_no_shape_screens_for": [
          "irreversible_change",
          "replay_amplified",
          "unauthorized_write"
        ],
        "pair": "everything+time",
        "table_verdict": "POSSIBLE",
        "union_tags": [
          "NET_SINK",
          "NON_IDEMPOTENT",
          "READS",
          "WRITES"
        ]
      },
      {
        "assignable_but_NO_corresponding_shape": [],
        "assignable_hazard_fields": [
          "irreversible_change",
          "replay_amplified",
          "secret_exfiltrated",
          "unauthorized_write"
        ],
        "capability_shapes_present": [
          "READ_THEN_EGRESS",
          "WRITE_THEN_EGRESS"
        ],
        "fields_no_shape_screens_for": [
          "irreversible_change",
          "replay_amplified",
          "unauthorized_write"
        ],
        "pair": "fetch+filesystem",
        "table_verdict": "POSSIBLE",
        "union_tags": [
          "DESTRUCTIVE",
          "NET_SINK",
          "NON_IDEMPOTENT",
          "READS",
          "WRITES"
        ]
      },
      {
        "assignable_but_NO_corresponding_shape": [],
        "assignable_hazard_fields": [
          "irreversible_change",
          "replay_amplified",
          "secret_exfiltrated",
          "unauthorized_write"
        ],
        "capability_shapes_present": [
          "READ_THEN_EGRESS",
          "WRITE_THEN_EGRESS"
        ],
        "fields_no_shape_screens_for": [
          "irreversible_change",
          "replay_amplified",
          "unauthorized_write"
        ],
        "pair": "fetch+git",
        "table_verdict": "POSSIBLE",
        "union_tags": [
          "DESTRUCTIVE",
          "NET_SINK",
          "NON_IDEMPOTENT",
          "READS",
          "WRITES"
        ]
      },
      {
        "assignable_but_NO_corresponding_shape": [],
        "assignable_hazard_fields": [
          "irreversible_change",
          "replay_amplified",
          "secret_exfiltrated",
          "unauthorized_write"
        ],
        "capability_shapes_present": [
          "READ_THEN_EGRESS",
          "WRITE_THEN_EGRESS"
        ],
        "fields_no_shape_screens_for": [
          "irreversible_change",
          "replay_amplified",
          "unauthorized_write"
        ],
        "pair": "fetch+memory",
        "table_verdict": "POSSIBLE",
        "union_tags": [
          "DESTRUCTIVE",
          "NET_SINK",
          "NON_IDEMPOTENT",
          "READS",
          "WRITES"
        ]
      },
      {
        "assignable_but_NO_corresponding_shape": [
          "secret_exfiltrated"
        ],
        "assignable_hazard_fields": [
          "secret_exfiltrated"
        ],
        "capability_shapes_present": [],
        "fields_no_shape_screens_for": [
          "irreversible_change",
          "replay_amplified",
          "unauthorized_write"
        ],
        "pair": "fetch+sequentialthinking",
        "table_verdict": "POSSIBLE",
        "union_tags": [
          "NET_SINK",
          "READS"
        ]
      },
      {
        "assignable_but_NO_corresponding_shape": [],
        "assignable_hazard_fields": [
          "secret_exfiltrated",
          "unauthorized_write"
        ],
        "capability_shapes_present": [
          "READ_THEN_EGRESS",
          "WRITE_THEN_EGRESS"
        ],
        "fields_no_shape_screens_for": [
          "irreversible_change",
          "replay_amplified",
          "unauthorized_write"
        ],
        "pair": "fetch+sqlite",
        "table_verdict": "POSSIBLE",
        "union_tags": [
          "NET_SINK",
          "READS",
          "WRITES"
        ]
      },
      {
        "assignable_but_NO_corresponding_shape": [],
        "assignable_hazard_fields": [
          "secret_exfiltrated"
        ],
        "capability_shapes_present": [
          "READ_THEN_EGRESS"
        ],
        "fields_no_shape_screens_for": [
          "irreversible_change",
          "replay_amplified",
          "unauthorized_write"
        ],
        "pair": "fetch+time",
        "table_verdict": "POSSIBLE",
        "union_tags": [
          "NET_SINK",
          "READS"
        ]
      },
      {
        "assignable_but_NO_corresponding_shape": [],
        "assignable_hazard_fields": [
          "irreversible_change",
          "replay_amplified",
          "unauthorized_write"
        ],
        "capability_shapes_present": [],
        "fields_no_shape_screens_for": [
          "irreversible_change",
          "replay_amplified",
          "unauthorized_write"
        ],
        "pair": "filesystem+git",
        "table_verdict": "POSSIBLE",
        "union_tags": [
          "DESTRUCTIVE",
          "NON_IDEMPOTENT",
          "READS",
          "WRITES"
        ]
      },
      {
        "assignable_but_NO_corresponding_shape": [],
        "assignable_hazard_fields": [
          "irreversible_change",
          "replay_amplified",
          "unauthorized_write"
        ],
        "capability_shapes_present": [],
        "fields_no_shape_screens_for": [
          "irreversible_change",
          "replay_amplified",
          "unauthorized_write"
        ],
        "pair": "filesystem+memory",
        "table_verdict": "POSSIBLE",
        "union_tags": [
          "DESTRUCTIVE",
          "NON_IDEMPOTENT",
          "READS",
          "WRITES"
        ]
      },
      {
        "assignable_but_NO_corresponding_shape": [],
        "assignable_hazard_fields": [
          "irreversible_change",
          "replay_amplified",
          "unauthorized_write"
        ],
        "capability_shapes_present": [],
        "fields_no_shape_screens_for": [
          "irreversible_change",
          "replay_amplified",
          "unauthorized_write"
        ],
        "pair": "filesystem+sequentialthinking",
        "table_verdict": "POSSIBLE",
        "union_tags": [
          "DESTRUCTIVE",
          "NON_IDEMPOTENT",
          "READS",
          "WRITES"
        ]
      },
      {
        "assignable_but_NO_corresponding_shape": [],
        "assignable_hazard_fields": [
          "irreversible_change",
          "replay_amplified",
          "unauthorized_write"
        ],
        "capability_shapes_present": [],
        "fields_no_shape_screens_for": [
          "irreversible_change",
          "replay_amplified",
          "unauthorized_write"
        ],
        "pair": "filesystem+sqlite",
        "table_verdict": "POSSIBLE",
        "union_tags": [
          "DESTRUCTIVE",
          "NON_IDEMPOTENT",
          "READS",
          "WRITES"
        ]
      },
      {
        "assignable_but_NO_corresponding_shape": [],
        "assignable_hazard_fields": [
          "irreversible_change",
          "replay_amplified",
          "unauthorized_write"
        ],
        "capability_shapes_present": [],
        "fields_no_shape_screens_for": [
          "irreversible_change",
          "replay_amplified",
          "unauthorized_write"
        ],
        "pair": "filesystem+time",
        "table_verdict": "POSSIBLE",
        "union_tags": [
          "DESTRUCTIVE",
          "NON_IDEMPOTENT",
          "READS",
          "WRITES"
        ]
      },
      {
        "assignable_but_NO_corresponding_shape": [],
        "assignable_hazard_fields": [
          "irreversible_change",
          "replay_amplified",
          "unauthorized_write"
        ],
        "capability_shapes_present": [],
        "fields_no_shape_screens_for": [
          "irreversible_change",
          "replay_amplified",
          "unauthorized_write"
        ],
        "pair": "git+memory",
        "table_verdict": "POSSIBLE",
        "union_tags": [
          "DESTRUCTIVE",
          "NON_IDEMPOTENT",
          "READS",
          "WRITES"
        ]
      },
      {
        "assignable_but_NO_corresponding_shape": [],
        "assignable_hazard_fields": [
          "irreversible_change",
          "replay_amplified",
          "unauthorized_write"
        ],
        "capability_shapes_present": [],
        "fields_no_shape_screens_for": [
          "irreversible_change",
          "replay_amplified",
          "unauthorized_write"
        ],
        "pair": "git+sequentialthinking",
        "table_verdict": "POSSIBLE",
        "union_tags": [
          "DESTRUCTIVE",
          "NON_IDEMPOTENT",
          "READS",
          "WRITES"
        ]
      },
      {
        "assignable_but_NO_corresponding_shape": [],
        "assignable_hazard_fields": [
          "irreversible_change",
          "replay_amplified",
          "unauthorized_write"
        ],
        "capability_shapes_present": [],
        "fields_no_shape_screens_for": [
          "irreversible_change",
          "replay_amplified",
          "unauthorized_write"
        ],
        "pair": "git+sqlite",
        "table_verdict": "POSSIBLE",
        "union_tags": [
          "DESTRUCTIVE",
          "NON_IDEMPOTENT",
          "READS",
          "WRITES"
        ]
      },
      {
        "assignable_but_NO_corresponding_shape": [],
        "assignable_hazard_fields": [
          "irreversible_change",
          "replay_amplified",
          "unauthorized_write"
        ],
        "capability_shapes_present": [],
        "fields_no_shape_screens_for": [
          "irreversible_change",
          "replay_amplified",
          "unauthorized_write"
        ],
        "pair": "git+time",
        "table_verdict": "POSSIBLE",
        "union_tags": [
          "DESTRUCTIVE",
          "NON_IDEMPOTENT",
          "READS",
          "WRITES"
        ]
      },
      {
        "assignable_but_NO_corresponding_shape": [],
        "assignable_hazard_fields": [
          "irreversible_change",
          "replay_amplified",
          "unauthorized_write"
        ],
        "capability_shapes_present": [],
        "fields_no_shape_screens_for": [
          "irreversible_change",
          "replay_amplified",
          "unauthorized_write"
        ],
        "pair": "memory+sequentialthinking",
        "table_verdict": "POSSIBLE",
        "union_tags": [
          "DESTRUCTIVE",
          "NON_IDEMPOTENT",
          "READS",
          "WRITES"
        ]
      },
      {
        "assignable_but_NO_corresponding_shape": [],
        "assignable_hazard_fields": [
          "irreversible_change",
          "replay_amplified",
          "unauthorized_write"
        ],
        "capability_shapes_present": [],
        "fields_no_shape_screens_for": [
          "irreversible_change",
          "replay_amplified",
          "unauthorized_write"
        ],
        "pair": "memory+sqlite",
        "table_verdict": "POSSIBLE",
        "union_tags": [
          "DESTRUCTIVE",
          "NON_IDEMPOTENT",
          "READS",
          "WRITES"
        ]
      },
      {
        "assignable_but_NO_corresponding_shape": [],
        "assignable_hazard_fields": [
          "irreversible_change",
          "replay_amplified",
          "unauthorized_write"
        ],
        "capability_shapes_present": [],
        "fields_no_shape_screens_for": [
          "irreversible_change",
          "replay_amplified",
          "unauthorized_write"
        ],
        "pair": "memory+time",
        "table_verdict": "POSSIBLE",
        "union_tags": [
          "DESTRUCTIVE",
          "NON_IDEMPOTENT",
          "READS",
          "WRITES"
        ]
      },
      {
        "assignable_but_NO_corresponding_shape": [],
        "assignable_hazard_fields": [
          "unauthorized_write"
        ],
        "capability_shapes_present": [],
        "fields_no_shape_screens_for": [
          "irreversible_change",
          "replay_amplified",
          "unauthorized_write"
        ],
        "pair": "sequentialthinking+sqlite",
        "table_verdict": "POSSIBLE",
        "union_tags": [
          "READS",
          "WRITES"
        ]
      },
      {
        "assignable_but_NO_corresponding_shape": [],
        "assignable_hazard_fields": [],
        "capability_shapes_present": [],
        "fields_no_shape_screens_for": [
          "irreversible_change",
          "replay_amplified",
          "unauthorized_write"
        ],
        "pair": "sequentialthinking+time",
        "table_verdict": "IMPOSSIBLE",
        "union_tags": [
          "READS"
        ]
      },
      {
        "assignable_but_NO_corresponding_shape": [],
        "assignable_hazard_fields": [
          "unauthorized_write"
        ],
        "capability_shapes_present": [],
        "fields_no_shape_screens_for": [
          "irreversible_change",
          "replay_amplified",
          "unauthorized_write"
        ],
        "pair": "sqlite+time",
        "table_verdict": "POSSIBLE",
        "union_tags": [
          "READS",
          "WRITES"
        ]
      }
    ],
    "relationship_to_capability_shapes": "COMPLEMENT, not replacement, and the gap runs BOTH ways. (1) A shape is an ORDERED (source, sink) PER-SERVER test; the table is over the UNION of both servers' tags. Shape-holds implies union-contains, but NOT conversely \u2014 so a pair can be union-POSSIBLE for a field while carrying no shape at all, which is a second, independent instance of ledger D15 on a different hazard field. (2) In the other direction, WRITE_THEN_EGRESS is a TWO-HOP shape (A writes a medium, B reads it, B egresses) and schema_to_rules models NO write-to-taint edge \u2014 taint is set only by READS rules. So that shape corresponds to NO hazard field in this table at all. Publishing the table as 'superseding' shapes would ship a strictly weaker artifact wearing a stronger label.",
    "table": {
      "(none)": [],
      "DESTRUCTIVE": [],
      "DESTRUCTIVE,GRANTS": [],
      "DESTRUCTIVE,GRANTS,NET_SINK": [],
      "DESTRUCTIVE,GRANTS,NET_SINK,NON_IDEMPOTENT": [],
      "DESTRUCTIVE,GRANTS,NET_SINK,NON_IDEMPOTENT,READS": [
        "irreversible_change",
        "priv_elevated",
        "replay_amplified",
        "secret_exfiltrated"
      ],
      "DESTRUCTIVE,GRANTS,NET_SINK,NON_IDEMPOTENT,READS,WRITES": [
        "irreversible_change",
        "priv_elevated",
        "replay_amplified",
        "secret_exfiltrated",
        "unauthorized_write"
      ],
      "DESTRUCTIVE,GRANTS,NET_SINK,NON_IDEMPOTENT,WRITES": [],
      "DESTRUCTIVE,GRANTS,NET_SINK,READS": [
        "irreversible_change",
        "priv_elevated",
        "secret_exfiltrated"
      ],
      "DESTRUCTIVE,GRANTS,NET_SINK,READS,WRITES": [
        "irreversible_change",
        "priv_elevated",
        "secret_exfiltrated",
        "unauthorized_write"
      ],
      "DESTRUCTIVE,GRANTS,NET_SINK,WRITES": [],
      "DESTRUCTIVE,GRANTS,NON_IDEMPOTENT": [],
      "DESTRUCTIVE,GRANTS,NON_IDEMPOTENT,READS": [
        "irreversible_change",
        "priv_elevated",
        "replay_amplified"
      ],
      "DESTRUCTIVE,GRANTS,NON_IDEMPOTENT,READS,WRITES": [
        "irreversible_change",
        "priv_elevated",
        "replay_amplified",
        "unauthorized_write"
      ],
      "DESTRUCTIVE,GRANTS,NON_IDEMPOTENT,WRITES": [],
      "DESTRUCTIVE,GRANTS,READS": [
        "irreversible_change",
        "priv_elevated"
      ],
      "DESTRUCTIVE,GRANTS,READS,WRITES": [
        "irreversible_change",
        "priv_elevated",
        "unauthorized_write"
      ],
      "DESTRUCTIVE,GRANTS,WRITES": [],
      "DESTRUCTIVE,NET_SINK": [],
      "DESTRUCTIVE,NET_SINK,NON_IDEMPOTENT": [],
      "DESTRUCTIVE,NET_SINK,NON_IDEMPOTENT,READS": [
        "irreversible_change",
        "replay_amplified",
        "secret_exfiltrated"
      ],
      "DESTRUCTIVE,NET_SINK,NON_IDEMPOTENT,READS,WRITES": [
        "irreversible_change",
        "replay_amplified",
        "secret_exfiltrated",
        "unauthorized_write"
      ],
      "DESTRUCTIVE,NET_SINK,NON_IDEMPOTENT,WRITES": [],
      "DESTRUCTIVE,NET_SINK,READS": [
        "irreversible_change",
        "secret_exfiltrated"
      ],
      "DESTRUCTIVE,NET_SINK,READS,WRITES": [
        "irreversible_change",
        "secret_exfiltrated",
        "unauthorized_write"
      ],
      "DESTRUCTIVE,NET_SINK,WRITES": [],
      "DESTRUCTIVE,NON_IDEMPOTENT": [],
      "DESTRUCTIVE,NON_IDEMPOTENT,READS": [
        "irreversible_change",
        "replay_amplified"
      ],
      "DESTRUCTIVE,NON_IDEMPOTENT,READS,WRITES": [
        "irreversible_change",
        "replay_amplified",
        "unauthorized_write"
      ],
      "DESTRUCTIVE,NON_IDEMPOTENT,WRITES": [],
      "DESTRUCTIVE,READS": [
        "irreversible_change"
      ],
      "DESTRUCTIVE,READS,WRITES": [
        "irreversible_change",
        "unauthorized_write"
      ],
      "DESTRUCTIVE,WRITES": [],
      "GRANTS": [],
      "GRANTS,NET_SINK": [],
      "GRANTS,NET_SINK,NON_IDEMPOTENT": [],
      "GRANTS,NET_SINK,NON_IDEMPOTENT,READS": [
        "priv_elevated",
        "replay_amplified",
        "secret_exfiltrated"
      ],
      "GRANTS,NET_SINK,NON_IDEMPOTENT,READS,WRITES": [
        "priv_elevated",
        "replay_amplified",
        "secret_exfiltrated",
        "unauthorized_write"
      ],
      "GRANTS,NET_SINK,NON_IDEMPOTENT,WRITES": [],
      "GRANTS,NET_SINK,READS": [
        "priv_elevated",
        "secret_exfiltrated"
      ],
      "GRANTS,NET_SINK,READS,WRITES": [
        "priv_elevated",
        "secret_exfiltrated",
        "unauthorized_write"
      ],
      "GRANTS,NET_SINK,WRITES": [],
      "GRANTS,NON_IDEMPOTENT": [],
      "GRANTS,NON_IDEMPOTENT,READS": [
        "priv_elevated",
        "replay_amplified"
      ],
      "GRANTS,NON_IDEMPOTENT,READS,WRITES": [
        "priv_elevated",
        "replay_amplified",
        "unauthorized_write"
      ],
      "GRANTS,NON_IDEMPOTENT,WRITES": [],
      "GRANTS,READS": [
        "priv_elevated"
      ],
      "GRANTS,READS,WRITES": [
        "priv_elevated",
        "unauthorized_write"
      ],
      "GRANTS,WRITES": [],
      "NET_SINK": [],
      "NET_SINK,NON_IDEMPOTENT": [],
      "NET_SINK,NON_IDEMPOTENT,READS": [
        "replay_amplified",
        "secret_exfiltrated"
      ],
      "NET_SINK,NON_IDEMPOTENT,READS,WRITES": [
        "replay_amplified",
        "secret_exfiltrated",
        "unauthorized_write"
      ],
      "NET_SINK,NON_IDEMPOTENT,WRITES": [],
      "NET_SINK,READS": [
        "secret_exfiltrated"
      ],
      "NET_SINK,READS,WRITES": [
        "secret_exfiltrated",
        "unauthorized_write"
      ],
      "NET_SINK,WRITES": [],
      "NON_IDEMPOTENT": [],
      "NON_IDEMPOTENT,READS": [
        "replay_amplified"
      ],
      "NON_IDEMPOTENT,READS,WRITES": [
        "replay_amplified",
        "unauthorized_write"
      ],
      "NON_IDEMPOTENT,WRITES": [],
      "READS": [],
      "READS,WRITES": [
        "unauthorized_write"
      ],
      "WRITES": []
    },
    "unmodelled_edge_disclosed": "schema_to_rules has no write-to-taint edge: a tool that WRITES attacker-influenceable content to a medium another tool later READS does not taint the context in this model. WRITE_THEN_EGRESS screens for exactly that flow and no hazard field covers it. This is a modelling gap in the generator, disclosed rather than papered over."
  },
  "derived_tag_requirements": {
    "assignable_by_tagset": {
      "(none)": [],
      "DESTRUCTIVE": [
        "irreversible_change"
      ],
      "DESTRUCTIVE,GRANTS": [
        "irreversible_change",
        "priv_elevated"
      ],
      "DESTRUCTIVE,GRANTS,NET_SINK": [
        "irreversible_change",
        "priv_elevated",
        "secret_exfiltrated"
      ],
      "DESTRUCTIVE,GRANTS,NET_SINK,NON_IDEMPOTENT": [
        "irreversible_change",
        "priv_elevated",
        "replay_amplified",
        "secret_exfiltrated"
      ],
      "DESTRUCTIVE,GRANTS,NET_SINK,NON_IDEMPOTENT,READS": [
        "irreversible_change",
        "priv_elevated",
        "replay_amplified",
        "secret_exfiltrated"
      ],
      "DESTRUCTIVE,GRANTS,NET_SINK,NON_IDEMPOTENT,READS,WRITES": [
        "irreversible_change",
        "priv_elevated",
        "replay_amplified",
        "secret_exfiltrated",
        "unauthorized_write"
      ],
      "DESTRUCTIVE,GRANTS,NET_SINK,NON_IDEMPOTENT,WRITES": [
        "irreversible_change",
        "priv_elevated",
        "replay_amplified",
        "secret_exfiltrated",
        "unauthorized_write"
      ],
      "DESTRUCTIVE,GRANTS,NET_SINK,READS": [
        "irreversible_change",
        "priv_elevated",
        "secret_exfiltrated"
      ],
      "DESTRUCTIVE,GRANTS,NET_SINK,READS,WRITES": [
        "irreversible_change",
        "priv_elevated",
        "secret_exfiltrated",
        "unauthorized_write"
      ],
      "DESTRUCTIVE,GRANTS,NET_SINK,WRITES": [
        "irreversible_change",
        "priv_elevated",
        "secret_exfiltrated",
        "unauthorized_write"
      ],
      "DESTRUCTIVE,GRANTS,NON_IDEMPOTENT": [
        "irreversible_change",
        "priv_elevated",
        "replay_amplified"
      ],
      "DESTRUCTIVE,GRANTS,NON_IDEMPOTENT,READS": [
        "irreversible_change",
        "priv_elevated",
        "replay_amplified"
      ],
      "DESTRUCTIVE,GRANTS,NON_IDEMPOTENT,READS,WRITES": [
        "irreversible_change",
        "priv_elevated",
        "replay_amplified",
        "unauthorized_write"
      ],
      "DESTRUCTIVE,GRANTS,NON_IDEMPOTENT,WRITES": [
        "irreversible_change",
        "priv_elevated",
        "replay_amplified",
        "unauthorized_write"
      ],
      "DESTRUCTIVE,GRANTS,READS": [
        "irreversible_change",
        "priv_elevated"
      ],
      "DESTRUCTIVE,GRANTS,READS,WRITES": [
        "irreversible_change",
        "priv_elevated",
        "unauthorized_write"
      ],
      "DESTRUCTIVE,GRANTS,WRITES": [
        "irreversible_change",
        "priv_elevated",
        "unauthorized_write"
      ],
      "DESTRUCTIVE,NET_SINK": [
        "irreversible_change",
        "secret_exfiltrated"
      ],
      "DESTRUCTIVE,NET_SINK,NON_IDEMPOTENT": [
        "irreversible_change",
        "replay_amplified",
        "secret_exfiltrated"
      ],
      "DESTRUCTIVE,NET_SINK,NON_IDEMPOTENT,READS": [
        "irreversible_change",
        "replay_amplified",
        "secret_exfiltrated"
      ],
      "DESTRUCTIVE,NET_SINK,NON_IDEMPOTENT,READS,WRITES": [
        "irreversible_change",
        "replay_amplified",
        "secret_exfiltrated",
        "unauthorized_write"
      ],
      "DESTRUCTIVE,NET_SINK,NON_IDEMPOTENT,WRITES": [
        "irreversible_change",
        "replay_amplified",
        "secret_exfiltrated",
        "unauthorized_write"
      ],
      "DESTRUCTIVE,NET_SINK,READS": [
        "irreversible_change",
        "secret_exfiltrated"
      ],
      "DESTRUCTIVE,NET_SINK,READS,WRITES": [
        "irreversible_change",
        "secret_exfiltrated",
        "unauthorized_write"
      ],
      "DESTRUCTIVE,NET_SINK,WRITES": [
        "irreversible_change",
        "secret_exfiltrated",
        "unauthorized_write"
      ],
      "DESTRUCTIVE,NON_IDEMPOTENT": [
        "irreversible_change",
        "replay_amplified"
      ],
      "DESTRUCTIVE,NON_IDEMPOTENT,READS": [
        "irreversible_change",
        "replay_amplified"
      ],
      "DESTRUCTIVE,NON_IDEMPOTENT,READS,WRITES": [
        "irreversible_change",
        "replay_amplified",
        "unauthorized_write"
      ],
      "DESTRUCTIVE,NON_IDEMPOTENT,WRITES": [
        "irreversible_change",
        "replay_amplified",
        "unauthorized_write"
      ],
      "DESTRUCTIVE,READS": [
        "irreversible_change"
      ],
      "DESTRUCTIVE,READS,WRITES": [
        "irreversible_change",
        "unauthorized_write"
      ],
      "DESTRUCTIVE,WRITES": [
        "irreversible_change",
        "unauthorized_write"
      ],
      "GRANTS": [
        "priv_elevated"
      ],
      "GRANTS,NET_SINK": [
        "priv_elevated",
        "secret_exfiltrated"
      ],
      "GRANTS,NET_SINK,NON_IDEMPOTENT": [
        "priv_elevated",
        "replay_amplified",
        "secret_exfiltrated"
      ],
      "GRANTS,NET_SINK,NON_IDEMPOTENT,READS": [
        "priv_elevated",
        "replay_amplified",
        "secret_exfiltrated"
      ],
      "GRANTS,NET_SINK,NON_IDEMPOTENT,READS,WRITES": [
        "priv_elevated",
        "replay_amplified",
        "secret_exfiltrated",
        "unauthorized_write"
      ],
      "GRANTS,NET_SINK,NON_IDEMPOTENT,WRITES": [
        "priv_elevated",
        "replay_amplified",
        "secret_exfiltrated",
        "unauthorized_write"
      ],
      "GRANTS,NET_SINK,READS": [
        "priv_elevated",
        "secret_exfiltrated"
      ],
      "GRANTS,NET_SINK,READS,WRITES": [
        "priv_elevated",
        "secret_exfiltrated",
        "unauthorized_write"
      ],
      "GRANTS,NET_SINK,WRITES": [
        "priv_elevated",
        "secret_exfiltrated",
        "unauthorized_write"
      ],
      "GRANTS,NON_IDEMPOTENT": [
        "priv_elevated",
        "replay_amplified"
      ],
      "GRANTS,NON_IDEMPOTENT,READS": [
        "priv_elevated",
        "replay_amplified"
      ],
      "GRANTS,NON_IDEMPOTENT,READS,WRITES": [
        "priv_elevated",
        "replay_amplified",
        "unauthorized_write"
      ],
      "GRANTS,NON_IDEMPOTENT,WRITES": [
        "priv_elevated",
        "replay_amplified",
        "unauthorized_write"
      ],
      "GRANTS,READS": [
        "priv_elevated"
      ],
      "GRANTS,READS,WRITES": [
        "priv_elevated",
        "unauthorized_write"
      ],
      "GRANTS,WRITES": [
        "priv_elevated",
        "unauthorized_write"
      ],
      "NET_SINK": [
        "secret_exfiltrated"
      ],
      "NET_SINK,NON_IDEMPOTENT": [
        "replay_amplified",
        "secret_exfiltrated"
      ],
      "NET_SINK,NON_IDEMPOTENT,READS": [
        "replay_amplified",
        "secret_exfiltrated"
      ],
      "NET_SINK,NON_IDEMPOTENT,READS,WRITES": [
        "replay_amplified",
        "secret_exfiltrated",
        "unauthorized_write"
      ],
      "NET_SINK,NON_IDEMPOTENT,WRITES": [
        "replay_amplified",
        "secret_exfiltrated",
        "unauthorized_write"
      ],
      "NET_SINK,READS": [
        "secret_exfiltrated"
      ],
      "NET_SINK,READS,WRITES": [
        "secret_exfiltrated",
        "unauthorized_write"
      ],
      "NET_SINK,WRITES": [
        "secret_exfiltrated",
        "unauthorized_write"
      ],
      "NON_IDEMPOTENT": [
        "replay_amplified"
      ],
      "NON_IDEMPOTENT,READS": [
        "replay_amplified"
      ],
      "NON_IDEMPOTENT,READS,WRITES": [
        "replay_amplified",
        "unauthorized_write"
      ],
      "NON_IDEMPOTENT,WRITES": [
        "replay_amplified",
        "unauthorized_write"
      ],
      "READS": [],
      "READS,WRITES": [
        "unauthorized_write"
      ],
      "WRITES": [
        "unauthorized_write"
      ]
    },
    "method": "EXHAUSTIVE over the tag lattice (2^6 = 64 subsets) x every trust assignment (96). A tag is NECESSARY for a hazard field iff no tag subset lacking it assigns that field under ANY trust assignment. Derived from ingest.schema_to_rules, never declared.",
    "n_rule_generations": 6144,
    "n_tag_subsets": 64,
    "n_trust_assignments": 96,
    "necessary_tags_by_hazard_field": {
      "irreversible_change": [
        "DESTRUCTIVE"
      ],
      "priv_elevated": [
        "GRANTS"
      ],
      "replay_amplified": [
        "NON_IDEMPOTENT"
      ],
      "secret_exfiltrated": [
        "NET_SINK"
      ],
      "unauthorized_write": [
        "WRITES"
      ]
    }
  },
  "derived_tag_requirements_semantic": {
    "assignable_by_tagset_semantic": {
      "(none)": [],
      "DESTRUCTIVE": [],
      "DESTRUCTIVE,GRANTS": [],
      "DESTRUCTIVE,GRANTS,NET_SINK": [],
      "DESTRUCTIVE,GRANTS,NET_SINK,NON_IDEMPOTENT": [],
      "DESTRUCTIVE,GRANTS,NET_SINK,NON_IDEMPOTENT,READS": [
        "irreversible_change",
        "priv_elevated",
        "replay_amplified",
        "secret_exfiltrated"
      ],
      "DESTRUCTIVE,GRANTS,NET_SINK,NON_IDEMPOTENT,READS,WRITES": [
        "irreversible_change",
        "priv_elevated",
        "replay_amplified",
        "secret_exfiltrated",
        "unauthorized_write"
      ],
      "DESTRUCTIVE,GRANTS,NET_SINK,NON_IDEMPOTENT,WRITES": [],
      "DESTRUCTIVE,GRANTS,NET_SINK,READS": [
        "irreversible_change",
        "priv_elevated",
        "secret_exfiltrated"
      ],
      "DESTRUCTIVE,GRANTS,NET_SINK,READS,WRITES": [
        "irreversible_change",
        "priv_elevated",
        "secret_exfiltrated",
        "unauthorized_write"
      ],
      "DESTRUCTIVE,GRANTS,NET_SINK,WRITES": [],
      "DESTRUCTIVE,GRANTS,NON_IDEMPOTENT": [],
      "DESTRUCTIVE,GRANTS,NON_IDEMPOTENT,READS": [
        "irreversible_change",
        "priv_elevated",
        "replay_amplified"
      ],
      "DESTRUCTIVE,GRANTS,NON_IDEMPOTENT,READS,WRITES": [
        "irreversible_change",
        "priv_elevated",
        "replay_amplified",
        "unauthorized_write"
      ],
      "DESTRUCTIVE,GRANTS,NON_IDEMPOTENT,WRITES": [],
      "DESTRUCTIVE,GRANTS,READS": [
        "irreversible_change",
        "priv_elevated"
      ],
      "DESTRUCTIVE,GRANTS,READS,WRITES": [
        "irreversible_change",
        "priv_elevated",
        "unauthorized_write"
      ],
      "DESTRUCTIVE,GRANTS,WRITES": [],
      "DESTRUCTIVE,NET_SINK": [],
      "DESTRUCTIVE,NET_SINK,NON_IDEMPOTENT": [],
      "DESTRUCTIVE,NET_SINK,NON_IDEMPOTENT,READS": [
        "irreversible_change",
        "replay_amplified",
        "secret_exfiltrated"
      ],
      "DESTRUCTIVE,NET_SINK,NON_IDEMPOTENT,READS,WRITES": [
        "irreversible_change",
        "replay_amplified",
        "secret_exfiltrated",
        "unauthorized_write"
      ],
      "DESTRUCTIVE,NET_SINK,NON_IDEMPOTENT,WRITES": [],
      "DESTRUCTIVE,NET_SINK,READS": [
        "irreversible_change",
        "secret_exfiltrated"
      ],
      "DESTRUCTIVE,NET_SINK,READS,WRITES": [
        "irreversible_change",
        "secret_exfiltrated",
        "unauthorized_write"
      ],
      "DESTRUCTIVE,NET_SINK,WRITES": [],
      "DESTRUCTIVE,NON_IDEMPOTENT": [],
      "DESTRUCTIVE,NON_IDEMPOTENT,READS": [
        "irreversible_change",
        "replay_amplified"
      ],
      "DESTRUCTIVE,NON_IDEMPOTENT,READS,WRITES": [
        "irreversible_change",
        "replay_amplified",
        "unauthorized_write"
      ],
      "DESTRUCTIVE,NON_IDEMPOTENT,WRITES": [],
      "DESTRUCTIVE,READS": [
        "irreversible_change"
      ],
      "DESTRUCTIVE,READS,WRITES": [
        "irreversible_change",
        "unauthorized_write"
      ],
      "DESTRUCTIVE,WRITES": [],
      "GRANTS": [],
      "GRANTS,NET_SINK": [],
      "GRANTS,NET_SINK,NON_IDEMPOTENT": [],
      "GRANTS,NET_SINK,NON_IDEMPOTENT,READS": [
        "priv_elevated",
        "replay_amplified",
        "secret_exfiltrated"
      ],
      "GRANTS,NET_SINK,NON_IDEMPOTENT,READS,WRITES": [
        "priv_elevated",
        "replay_amplified",
        "secret_exfiltrated",
        "unauthorized_write"
      ],
      "GRANTS,NET_SINK,NON_IDEMPOTENT,WRITES": [],
      "GRANTS,NET_SINK,READS": [
        "priv_elevated",
        "secret_exfiltrated"
      ],
      "GRANTS,NET_SINK,READS,WRITES": [
        "priv_elevated",
        "secret_exfiltrated",
        "unauthorized_write"
      ],
      "GRANTS,NET_SINK,WRITES": [],
      "GRANTS,NON_IDEMPOTENT": [],
      "GRANTS,NON_IDEMPOTENT,READS": [
        "priv_elevated",
        "replay_amplified"
      ],
      "GRANTS,NON_IDEMPOTENT,READS,WRITES": [
        "priv_elevated",
        "replay_amplified",
        "unauthorized_write"
      ],
      "GRANTS,NON_IDEMPOTENT,WRITES": [],
      "GRANTS,READS": [
        "priv_elevated"
      ],
      "GRANTS,READS,WRITES": [
        "priv_elevated",
        "unauthorized_write"
      ],
      "GRANTS,WRITES": [],
      "NET_SINK": [],
      "NET_SINK,NON_IDEMPOTENT": [],
      "NET_SINK,NON_IDEMPOTENT,READS": [
        "replay_amplified",
        "secret_exfiltrated"
      ],
      "NET_SINK,NON_IDEMPOTENT,READS,WRITES": [
        "replay_amplified",
        "secret_exfiltrated",
        "unauthorized_write"
      ],
      "NET_SINK,NON_IDEMPOTENT,WRITES": [],
      "NET_SINK,READS": [
        "secret_exfiltrated"
      ],
      "NET_SINK,READS,WRITES": [
        "secret_exfiltrated",
        "unauthorized_write"
      ],
      "NET_SINK,WRITES": [],
      "NON_IDEMPOTENT": [],
      "NON_IDEMPOTENT,READS": [
        "replay_amplified"
      ],
      "NON_IDEMPOTENT,READS,WRITES": [
        "replay_amplified",
        "unauthorized_write"
      ],
      "NON_IDEMPOTENT,WRITES": [],
      "READS": [],
      "READS,WRITES": [
        "unauthorized_write"
      ],
      "WRITES": []
    },
    "method": "EXHAUSTIVE over the tag lattice x every trust assignment, decided by z3 (symbolic_absence.prove_absence_symbolic: BMC base + k-induction over simple paths) rather than by inspecting which keys a rule writes. A field counts as assignable for a tag subset iff SOME trust assignment makes it REACHABLE.",
    "n_solver_calls": 23696,
    "n_tag_subsets": 64,
    "n_trust_assignments": 96,
    "necessary_tags_by_hazard_field_semantic": {
      "irreversible_change": [
        "DESTRUCTIVE",
        "READS"
      ],
      "priv_elevated": [
        "GRANTS",
        "READS"
      ],
      "replay_amplified": [
        "NON_IDEMPOTENT",
        "READS"
      ],
      "secret_exfiltrated": [
        "NET_SINK",
        "READS"
      ],
      "unauthorized_write": [
        "READS",
        "WRITES"
      ]
    },
    "relationship_to_the_structural_map": "The structural map is a sound over-approximation: anything it calls unreachable really is unreachable. This map is exact for the modelled generator. Structural-implies-semantic is asserted by check_impossibility.py; the converse does not hold and the rows where it fails are exactly where the structural map overstates."
  },
  "explicit_non_claim": "Impossibility WITHIN THE MODELLED RULE GENERATOR, over the 5 declared hazard properties (of which 2 -- irreversible_change, replay_amplified -- were added 2026-07-26 and are NOT pre-registered; hazards.NOT_PRE_REGISTERED names them). NOT general safety: a deployment can be unsafe in ways schema_to_rules does not model (cross-session persistence of secret-tainted data is the standing example). It quantifies over TRUST MODELS, not over tags -- a server whose schema under-declares its behaviour is mis-tagged and this proof inherits that error. The headline verdicts are decided by the STRUCTURAL tag map, which is a sound over-approximation: 31 of 64 lattice rows name a field it cannot actually drive to true. That overstatement is published in tag_map_comparison rather than hidden, and it changes 0 verdicts on this corpus.",
  "headline_is_split_on_purpose": "62 slots are impossible for all trust models, but 5 of them sit on compositions with NO modelled behaviour (no rules, one reachable state). For those the structural claim is true and a solver confirming it is uninformative. The number to quote is 57 INFORMATIVE slots. scan.py already refuses to certify degenerate models (DEGENERATE_STATE_CEILING); this inherits that discipline rather than quietly folding vacuous wins into a headline.",
  "n_hazard_fields": 5,
  "n_impossible": 62,
  "n_impossible_degenerate": 5,
  "n_impossible_informative": 57,
  "n_pair_field_slots": 140,
  "n_pairs": 28,
  "negative_control": {
    "control_behaves": true,
    "expected": "POSSIBLE",
    "hazard_field": "unauthorized_write",
    "pair": "memory+filesystem",
    "verdict": "POSSIBLE",
    "why_it_matters": "This pair carries NO robust_hazard capability shape and yet has a real baseline finding (memory+filesystem::PROP_NO_UNAUTH_WRITE). It is the standing refutation of 'no shape implies impossible' (ledger D15). If this ever reports IMPOSSIBLE the lemma is wrong."
  },
  "results": [
    {
      "fields": [
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 15,
            "n_rules": 13
          },
          "degenerate_note": null,
          "hazard_field": "irreversible_change",
          "informative": true,
          "missing_necessary_tags": [
            "DESTRUCTIVE"
          ],
          "necessary_tags": [
            "DESTRUCTIVE"
          ],
          "tags_present_in_pair": [
            "NET_SINK",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "IMPOSSIBLE",
          "why": "no tool in either server carries ['DESTRUCTIVE'] \u2014 no rule in schema_to_rules can assign irreversible_change, for ANY of the 96 trust assignments per server"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 15,
            "n_rules": 13
          },
          "degenerate_note": null,
          "hazard_field": "priv_elevated",
          "informative": true,
          "missing_necessary_tags": [
            "GRANTS"
          ],
          "necessary_tags": [
            "GRANTS"
          ],
          "tags_present_in_pair": [
            "NET_SINK",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "IMPOSSIBLE",
          "why": "no tool in either server carries ['GRANTS'] \u2014 no rule in schema_to_rules can assign priv_elevated, for ANY of the 96 trust assignments per server"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 15,
            "n_rules": 13
          },
          "degenerate_note": null,
          "hazard_field": "replay_amplified",
          "informative": false,
          "missing_necessary_tags": [],
          "necessary_tags": [
            "NON_IDEMPOTENT"
          ],
          "tags_present_in_pair": [
            "NET_SINK",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "POSSIBLE",
          "why": "the pair carries every tag necessary for replay_amplified; impossibility does NOT hold and the field must be decided per-assignment"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 15,
            "n_rules": 13
          },
          "degenerate_note": null,
          "hazard_field": "secret_exfiltrated",
          "informative": false,
          "missing_necessary_tags": [],
          "necessary_tags": [
            "NET_SINK"
          ],
          "tags_present_in_pair": [
            "NET_SINK",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "POSSIBLE",
          "why": "the pair carries every tag necessary for secret_exfiltrated; impossibility does NOT hold and the field must be decided per-assignment"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 15,
            "n_rules": 13
          },
          "degenerate_note": null,
          "hazard_field": "unauthorized_write",
          "informative": false,
          "missing_necessary_tags": [],
          "necessary_tags": [
            "WRITES"
          ],
          "tags_present_in_pair": [
            "NET_SINK",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "POSSIBLE",
          "why": "the pair carries every tag necessary for unauthorized_write; impossibility does NOT hold and the field must be decided per-assignment"
        }
      ],
      "n_impossible": 2,
      "n_impossible_informative": 2,
      "pair": "everything+fetch",
      "union_tags": [
        "NET_SINK",
        "NON_IDEMPOTENT",
        "READS",
        "WRITES"
      ]
    },
    {
      "fields": [
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 2,
            "n_rules": 30
          },
          "degenerate_note": null,
          "hazard_field": "irreversible_change",
          "informative": false,
          "missing_necessary_tags": [],
          "necessary_tags": [
            "DESTRUCTIVE"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NET_SINK",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "POSSIBLE",
          "why": "the pair carries every tag necessary for irreversible_change; impossibility does NOT hold and the field must be decided per-assignment"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 2,
            "n_rules": 30
          },
          "degenerate_note": null,
          "hazard_field": "priv_elevated",
          "informative": true,
          "missing_necessary_tags": [
            "GRANTS"
          ],
          "necessary_tags": [
            "GRANTS"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NET_SINK",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "IMPOSSIBLE",
          "why": "no tool in either server carries ['GRANTS'] \u2014 no rule in schema_to_rules can assign priv_elevated, for ANY of the 96 trust assignments per server"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 2,
            "n_rules": 30
          },
          "degenerate_note": null,
          "hazard_field": "replay_amplified",
          "informative": false,
          "missing_necessary_tags": [],
          "necessary_tags": [
            "NON_IDEMPOTENT"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NET_SINK",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "POSSIBLE",
          "why": "the pair carries every tag necessary for replay_amplified; impossibility does NOT hold and the field must be decided per-assignment"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 2,
            "n_rules": 30
          },
          "degenerate_note": null,
          "hazard_field": "secret_exfiltrated",
          "informative": false,
          "missing_necessary_tags": [],
          "necessary_tags": [
            "NET_SINK"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NET_SINK",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "POSSIBLE",
          "why": "the pair carries every tag necessary for secret_exfiltrated; impossibility does NOT hold and the field must be decided per-assignment"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 2,
            "n_rules": 30
          },
          "degenerate_note": null,
          "hazard_field": "unauthorized_write",
          "informative": false,
          "missing_necessary_tags": [],
          "necessary_tags": [
            "WRITES"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NET_SINK",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "POSSIBLE",
          "why": "the pair carries every tag necessary for unauthorized_write; impossibility does NOT hold and the field must be decided per-assignment"
        }
      ],
      "n_impossible": 1,
      "n_impossible_informative": 1,
      "pair": "everything+filesystem",
      "union_tags": [
        "DESTRUCTIVE",
        "NET_SINK",
        "NON_IDEMPOTENT",
        "READS",
        "WRITES"
      ]
    },
    {
      "fields": [
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 2,
            "n_rules": 21
          },
          "degenerate_note": null,
          "hazard_field": "irreversible_change",
          "informative": false,
          "missing_necessary_tags": [],
          "necessary_tags": [
            "DESTRUCTIVE"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NET_SINK",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "POSSIBLE",
          "why": "the pair carries every tag necessary for irreversible_change; impossibility does NOT hold and the field must be decided per-assignment"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 2,
            "n_rules": 21
          },
          "degenerate_note": null,
          "hazard_field": "priv_elevated",
          "informative": true,
          "missing_necessary_tags": [
            "GRANTS"
          ],
          "necessary_tags": [
            "GRANTS"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NET_SINK",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "IMPOSSIBLE",
          "why": "no tool in either server carries ['GRANTS'] \u2014 no rule in schema_to_rules can assign priv_elevated, for ANY of the 96 trust assignments per server"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 2,
            "n_rules": 21
          },
          "degenerate_note": null,
          "hazard_field": "replay_amplified",
          "informative": false,
          "missing_necessary_tags": [],
          "necessary_tags": [
            "NON_IDEMPOTENT"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NET_SINK",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "POSSIBLE",
          "why": "the pair carries every tag necessary for replay_amplified; impossibility does NOT hold and the field must be decided per-assignment"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 2,
            "n_rules": 21
          },
          "degenerate_note": null,
          "hazard_field": "secret_exfiltrated",
          "informative": false,
          "missing_necessary_tags": [],
          "necessary_tags": [
            "NET_SINK"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NET_SINK",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "POSSIBLE",
          "why": "the pair carries every tag necessary for secret_exfiltrated; impossibility does NOT hold and the field must be decided per-assignment"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 2,
            "n_rules": 21
          },
          "degenerate_note": null,
          "hazard_field": "unauthorized_write",
          "informative": false,
          "missing_necessary_tags": [],
          "necessary_tags": [
            "WRITES"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NET_SINK",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "POSSIBLE",
          "why": "the pair carries every tag necessary for unauthorized_write; impossibility does NOT hold and the field must be decided per-assignment"
        }
      ],
      "n_impossible": 1,
      "n_impossible_informative": 1,
      "pair": "everything+git",
      "union_tags": [
        "DESTRUCTIVE",
        "NET_SINK",
        "NON_IDEMPOTENT",
        "READS",
        "WRITES"
      ]
    },
    {
      "fields": [
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 10,
            "n_rules": 20
          },
          "degenerate_note": null,
          "hazard_field": "irreversible_change",
          "informative": false,
          "missing_necessary_tags": [],
          "necessary_tags": [
            "DESTRUCTIVE"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NET_SINK",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "POSSIBLE",
          "why": "the pair carries every tag necessary for irreversible_change; impossibility does NOT hold and the field must be decided per-assignment"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 10,
            "n_rules": 20
          },
          "degenerate_note": null,
          "hazard_field": "priv_elevated",
          "informative": true,
          "missing_necessary_tags": [
            "GRANTS"
          ],
          "necessary_tags": [
            "GRANTS"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NET_SINK",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "IMPOSSIBLE",
          "why": "no tool in either server carries ['GRANTS'] \u2014 no rule in schema_to_rules can assign priv_elevated, for ANY of the 96 trust assignments per server"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 10,
            "n_rules": 20
          },
          "degenerate_note": null,
          "hazard_field": "replay_amplified",
          "informative": false,
          "missing_necessary_tags": [],
          "necessary_tags": [
            "NON_IDEMPOTENT"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NET_SINK",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "POSSIBLE",
          "why": "the pair carries every tag necessary for replay_amplified; impossibility does NOT hold and the field must be decided per-assignment"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 10,
            "n_rules": 20
          },
          "degenerate_note": null,
          "hazard_field": "secret_exfiltrated",
          "informative": false,
          "missing_necessary_tags": [],
          "necessary_tags": [
            "NET_SINK"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NET_SINK",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "POSSIBLE",
          "why": "the pair carries every tag necessary for secret_exfiltrated; impossibility does NOT hold and the field must be decided per-assignment"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 10,
            "n_rules": 20
          },
          "degenerate_note": null,
          "hazard_field": "unauthorized_write",
          "informative": false,
          "missing_necessary_tags": [],
          "necessary_tags": [
            "WRITES"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NET_SINK",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "POSSIBLE",
          "why": "the pair carries every tag necessary for unauthorized_write; impossibility does NOT hold and the field must be decided per-assignment"
        }
      ],
      "n_impossible": 1,
      "n_impossible_informative": 1,
      "pair": "everything+memory",
      "union_tags": [
        "DESTRUCTIVE",
        "NET_SINK",
        "NON_IDEMPOTENT",
        "READS",
        "WRITES"
      ]
    },
    {
      "fields": [
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 2,
            "n_rules": 11
          },
          "degenerate_note": null,
          "hazard_field": "irreversible_change",
          "informative": true,
          "missing_necessary_tags": [
            "DESTRUCTIVE"
          ],
          "necessary_tags": [
            "DESTRUCTIVE"
          ],
          "tags_present_in_pair": [
            "NET_SINK",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "IMPOSSIBLE",
          "why": "no tool in either server carries ['DESTRUCTIVE'] \u2014 no rule in schema_to_rules can assign irreversible_change, for ANY of the 96 trust assignments per server"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 2,
            "n_rules": 11
          },
          "degenerate_note": null,
          "hazard_field": "priv_elevated",
          "informative": true,
          "missing_necessary_tags": [
            "GRANTS"
          ],
          "necessary_tags": [
            "GRANTS"
          ],
          "tags_present_in_pair": [
            "NET_SINK",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "IMPOSSIBLE",
          "why": "no tool in either server carries ['GRANTS'] \u2014 no rule in schema_to_rules can assign priv_elevated, for ANY of the 96 trust assignments per server"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 2,
            "n_rules": 11
          },
          "degenerate_note": null,
          "hazard_field": "replay_amplified",
          "informative": false,
          "missing_necessary_tags": [],
          "necessary_tags": [
            "NON_IDEMPOTENT"
          ],
          "tags_present_in_pair": [
            "NET_SINK",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "POSSIBLE",
          "why": "the pair carries every tag necessary for replay_amplified; impossibility does NOT hold and the field must be decided per-assignment"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 2,
            "n_rules": 11
          },
          "degenerate_note": null,
          "hazard_field": "secret_exfiltrated",
          "informative": false,
          "missing_necessary_tags": [],
          "necessary_tags": [
            "NET_SINK"
          ],
          "tags_present_in_pair": [
            "NET_SINK",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "POSSIBLE",
          "why": "the pair carries every tag necessary for secret_exfiltrated; impossibility does NOT hold and the field must be decided per-assignment"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 2,
            "n_rules": 11
          },
          "degenerate_note": null,
          "hazard_field": "unauthorized_write",
          "informative": false,
          "missing_necessary_tags": [],
          "necessary_tags": [
            "WRITES"
          ],
          "tags_present_in_pair": [
            "NET_SINK",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "POSSIBLE",
          "why": "the pair carries every tag necessary for unauthorized_write; impossibility does NOT hold and the field must be decided per-assignment"
        }
      ],
      "n_impossible": 2,
      "n_impossible_informative": 2,
      "pair": "everything+sequentialthinking",
      "union_tags": [
        "NET_SINK",
        "NON_IDEMPOTENT",
        "READS",
        "WRITES"
      ]
    },
    {
      "fields": [
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 6,
            "n_rules": 17
          },
          "degenerate_note": null,
          "hazard_field": "irreversible_change",
          "informative": true,
          "missing_necessary_tags": [
            "DESTRUCTIVE"
          ],
          "necessary_tags": [
            "DESTRUCTIVE"
          ],
          "tags_present_in_pair": [
            "NET_SINK",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "IMPOSSIBLE",
          "why": "no tool in either server carries ['DESTRUCTIVE'] \u2014 no rule in schema_to_rules can assign irreversible_change, for ANY of the 96 trust assignments per server"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 6,
            "n_rules": 17
          },
          "degenerate_note": null,
          "hazard_field": "priv_elevated",
          "informative": true,
          "missing_necessary_tags": [
            "GRANTS"
          ],
          "necessary_tags": [
            "GRANTS"
          ],
          "tags_present_in_pair": [
            "NET_SINK",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "IMPOSSIBLE",
          "why": "no tool in either server carries ['GRANTS'] \u2014 no rule in schema_to_rules can assign priv_elevated, for ANY of the 96 trust assignments per server"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 6,
            "n_rules": 17
          },
          "degenerate_note": null,
          "hazard_field": "replay_amplified",
          "informative": false,
          "missing_necessary_tags": [],
          "necessary_tags": [
            "NON_IDEMPOTENT"
          ],
          "tags_present_in_pair": [
            "NET_SINK",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "POSSIBLE",
          "why": "the pair carries every tag necessary for replay_amplified; impossibility does NOT hold and the field must be decided per-assignment"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 6,
            "n_rules": 17
          },
          "degenerate_note": null,
          "hazard_field": "secret_exfiltrated",
          "informative": false,
          "missing_necessary_tags": [],
          "necessary_tags": [
            "NET_SINK"
          ],
          "tags_present_in_pair": [
            "NET_SINK",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "POSSIBLE",
          "why": "the pair carries every tag necessary for secret_exfiltrated; impossibility does NOT hold and the field must be decided per-assignment"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 6,
            "n_rules": 17
          },
          "degenerate_note": null,
          "hazard_field": "unauthorized_write",
          "informative": false,
          "missing_necessary_tags": [],
          "necessary_tags": [
            "WRITES"
          ],
          "tags_present_in_pair": [
            "NET_SINK",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "POSSIBLE",
          "why": "the pair carries every tag necessary for unauthorized_write; impossibility does NOT hold and the field must be decided per-assignment"
        }
      ],
      "n_impossible": 2,
      "n_impossible_informative": 2,
      "pair": "everything+sqlite",
      "union_tags": [
        "NET_SINK",
        "NON_IDEMPOTENT",
        "READS",
        "WRITES"
      ]
    },
    {
      "fields": [
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 2,
            "n_rules": 11
          },
          "degenerate_note": null,
          "hazard_field": "irreversible_change",
          "informative": true,
          "missing_necessary_tags": [
            "DESTRUCTIVE"
          ],
          "necessary_tags": [
            "DESTRUCTIVE"
          ],
          "tags_present_in_pair": [
            "NET_SINK",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "IMPOSSIBLE",
          "why": "no tool in either server carries ['DESTRUCTIVE'] \u2014 no rule in schema_to_rules can assign irreversible_change, for ANY of the 96 trust assignments per server"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 2,
            "n_rules": 11
          },
          "degenerate_note": null,
          "hazard_field": "priv_elevated",
          "informative": true,
          "missing_necessary_tags": [
            "GRANTS"
          ],
          "necessary_tags": [
            "GRANTS"
          ],
          "tags_present_in_pair": [
            "NET_SINK",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "IMPOSSIBLE",
          "why": "no tool in either server carries ['GRANTS'] \u2014 no rule in schema_to_rules can assign priv_elevated, for ANY of the 96 trust assignments per server"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 2,
            "n_rules": 11
          },
          "degenerate_note": null,
          "hazard_field": "replay_amplified",
          "informative": false,
          "missing_necessary_tags": [],
          "necessary_tags": [
            "NON_IDEMPOTENT"
          ],
          "tags_present_in_pair": [
            "NET_SINK",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "POSSIBLE",
          "why": "the pair carries every tag necessary for replay_amplified; impossibility does NOT hold and the field must be decided per-assignment"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 2,
            "n_rules": 11
          },
          "degenerate_note": null,
          "hazard_field": "secret_exfiltrated",
          "informative": false,
          "missing_necessary_tags": [],
          "necessary_tags": [
            "NET_SINK"
          ],
          "tags_present_in_pair": [
            "NET_SINK",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "POSSIBLE",
          "why": "the pair carries every tag necessary for secret_exfiltrated; impossibility does NOT hold and the field must be decided per-assignment"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 2,
            "n_rules": 11
          },
          "degenerate_note": null,
          "hazard_field": "unauthorized_write",
          "informative": false,
          "missing_necessary_tags": [],
          "necessary_tags": [
            "WRITES"
          ],
          "tags_present_in_pair": [
            "NET_SINK",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "POSSIBLE",
          "why": "the pair carries every tag necessary for unauthorized_write; impossibility does NOT hold and the field must be decided per-assignment"
        }
      ],
      "n_impossible": 2,
      "n_impossible_informative": 2,
      "pair": "everything+time",
      "union_tags": [
        "NET_SINK",
        "NON_IDEMPOTENT",
        "READS",
        "WRITES"
      ]
    },
    {
      "fields": [
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 45,
            "n_rules": 21
          },
          "degenerate_note": null,
          "hazard_field": "irreversible_change",
          "informative": false,
          "missing_necessary_tags": [],
          "necessary_tags": [
            "DESTRUCTIVE"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NET_SINK",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "POSSIBLE",
          "why": "the pair carries every tag necessary for irreversible_change; impossibility does NOT hold and the field must be decided per-assignment"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 45,
            "n_rules": 21
          },
          "degenerate_note": null,
          "hazard_field": "priv_elevated",
          "informative": true,
          "missing_necessary_tags": [
            "GRANTS"
          ],
          "necessary_tags": [
            "GRANTS"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NET_SINK",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "IMPOSSIBLE",
          "why": "no tool in either server carries ['GRANTS'] \u2014 no rule in schema_to_rules can assign priv_elevated, for ANY of the 96 trust assignments per server"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 45,
            "n_rules": 21
          },
          "degenerate_note": null,
          "hazard_field": "replay_amplified",
          "informative": false,
          "missing_necessary_tags": [],
          "necessary_tags": [
            "NON_IDEMPOTENT"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NET_SINK",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "POSSIBLE",
          "why": "the pair carries every tag necessary for replay_amplified; impossibility does NOT hold and the field must be decided per-assignment"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 45,
            "n_rules": 21
          },
          "degenerate_note": null,
          "hazard_field": "secret_exfiltrated",
          "informative": false,
          "missing_necessary_tags": [],
          "necessary_tags": [
            "NET_SINK"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NET_SINK",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "POSSIBLE",
          "why": "the pair carries every tag necessary for secret_exfiltrated; impossibility does NOT hold and the field must be decided per-assignment"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 45,
            "n_rules": 21
          },
          "degenerate_note": null,
          "hazard_field": "unauthorized_write",
          "informative": false,
          "missing_necessary_tags": [],
          "necessary_tags": [
            "WRITES"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NET_SINK",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "POSSIBLE",
          "why": "the pair carries every tag necessary for unauthorized_write; impossibility does NOT hold and the field must be decided per-assignment"
        }
      ],
      "n_impossible": 1,
      "n_impossible_informative": 1,
      "pair": "fetch+filesystem",
      "union_tags": [
        "DESTRUCTIVE",
        "NET_SINK",
        "NON_IDEMPOTENT",
        "READS",
        "WRITES"
      ]
    },
    {
      "fields": [
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 25,
            "n_rules": 12
          },
          "degenerate_note": null,
          "hazard_field": "irreversible_change",
          "informative": false,
          "missing_necessary_tags": [],
          "necessary_tags": [
            "DESTRUCTIVE"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NET_SINK",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "POSSIBLE",
          "why": "the pair carries every tag necessary for irreversible_change; impossibility does NOT hold and the field must be decided per-assignment"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 25,
            "n_rules": 12
          },
          "degenerate_note": null,
          "hazard_field": "priv_elevated",
          "informative": true,
          "missing_necessary_tags": [
            "GRANTS"
          ],
          "necessary_tags": [
            "GRANTS"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NET_SINK",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "IMPOSSIBLE",
          "why": "no tool in either server carries ['GRANTS'] \u2014 no rule in schema_to_rules can assign priv_elevated, for ANY of the 96 trust assignments per server"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 25,
            "n_rules": 12
          },
          "degenerate_note": null,
          "hazard_field": "replay_amplified",
          "informative": false,
          "missing_necessary_tags": [],
          "necessary_tags": [
            "NON_IDEMPOTENT"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NET_SINK",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "POSSIBLE",
          "why": "the pair carries every tag necessary for replay_amplified; impossibility does NOT hold and the field must be decided per-assignment"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 25,
            "n_rules": 12
          },
          "degenerate_note": null,
          "hazard_field": "secret_exfiltrated",
          "informative": false,
          "missing_necessary_tags": [],
          "necessary_tags": [
            "NET_SINK"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NET_SINK",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "POSSIBLE",
          "why": "the pair carries every tag necessary for secret_exfiltrated; impossibility does NOT hold and the field must be decided per-assignment"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 25,
            "n_rules": 12
          },
          "degenerate_note": null,
          "hazard_field": "unauthorized_write",
          "informative": false,
          "missing_necessary_tags": [],
          "necessary_tags": [
            "WRITES"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NET_SINK",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "POSSIBLE",
          "why": "the pair carries every tag necessary for unauthorized_write; impossibility does NOT hold and the field must be decided per-assignment"
        }
      ],
      "n_impossible": 1,
      "n_impossible_informative": 1,
      "pair": "fetch+git",
      "union_tags": [
        "DESTRUCTIVE",
        "NET_SINK",
        "NON_IDEMPOTENT",
        "READS",
        "WRITES"
      ]
    },
    {
      "fields": [
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 10,
            "n_rules": 11
          },
          "degenerate_note": null,
          "hazard_field": "irreversible_change",
          "informative": false,
          "missing_necessary_tags": [],
          "necessary_tags": [
            "DESTRUCTIVE"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NET_SINK",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "POSSIBLE",
          "why": "the pair carries every tag necessary for irreversible_change; impossibility does NOT hold and the field must be decided per-assignment"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 10,
            "n_rules": 11
          },
          "degenerate_note": null,
          "hazard_field": "priv_elevated",
          "informative": true,
          "missing_necessary_tags": [
            "GRANTS"
          ],
          "necessary_tags": [
            "GRANTS"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NET_SINK",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "IMPOSSIBLE",
          "why": "no tool in either server carries ['GRANTS'] \u2014 no rule in schema_to_rules can assign priv_elevated, for ANY of the 96 trust assignments per server"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 10,
            "n_rules": 11
          },
          "degenerate_note": null,
          "hazard_field": "replay_amplified",
          "informative": false,
          "missing_necessary_tags": [],
          "necessary_tags": [
            "NON_IDEMPOTENT"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NET_SINK",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "POSSIBLE",
          "why": "the pair carries every tag necessary for replay_amplified; impossibility does NOT hold and the field must be decided per-assignment"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 10,
            "n_rules": 11
          },
          "degenerate_note": null,
          "hazard_field": "secret_exfiltrated",
          "informative": false,
          "missing_necessary_tags": [],
          "necessary_tags": [
            "NET_SINK"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NET_SINK",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "POSSIBLE",
          "why": "the pair carries every tag necessary for secret_exfiltrated; impossibility does NOT hold and the field must be decided per-assignment"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 10,
            "n_rules": 11
          },
          "degenerate_note": null,
          "hazard_field": "unauthorized_write",
          "informative": false,
          "missing_necessary_tags": [],
          "necessary_tags": [
            "WRITES"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NET_SINK",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "POSSIBLE",
          "why": "the pair carries every tag necessary for unauthorized_write; impossibility does NOT hold and the field must be decided per-assignment"
        }
      ],
      "n_impossible": 1,
      "n_impossible_informative": 1,
      "pair": "fetch+memory",
      "union_tags": [
        "DESTRUCTIVE",
        "NET_SINK",
        "NON_IDEMPOTENT",
        "READS",
        "WRITES"
      ]
    },
    {
      "fields": [
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 4,
            "n_rules": 2
          },
          "degenerate_note": null,
          "hazard_field": "irreversible_change",
          "informative": true,
          "missing_necessary_tags": [
            "DESTRUCTIVE"
          ],
          "necessary_tags": [
            "DESTRUCTIVE"
          ],
          "tags_present_in_pair": [
            "NET_SINK",
            "READS"
          ],
          "verdict": "IMPOSSIBLE",
          "why": "no tool in either server carries ['DESTRUCTIVE'] \u2014 no rule in schema_to_rules can assign irreversible_change, for ANY of the 96 trust assignments per server"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 4,
            "n_rules": 2
          },
          "degenerate_note": null,
          "hazard_field": "priv_elevated",
          "informative": true,
          "missing_necessary_tags": [
            "GRANTS"
          ],
          "necessary_tags": [
            "GRANTS"
          ],
          "tags_present_in_pair": [
            "NET_SINK",
            "READS"
          ],
          "verdict": "IMPOSSIBLE",
          "why": "no tool in either server carries ['GRANTS'] \u2014 no rule in schema_to_rules can assign priv_elevated, for ANY of the 96 trust assignments per server"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 4,
            "n_rules": 2
          },
          "degenerate_note": null,
          "hazard_field": "replay_amplified",
          "informative": true,
          "missing_necessary_tags": [
            "NON_IDEMPOTENT"
          ],
          "necessary_tags": [
            "NON_IDEMPOTENT"
          ],
          "tags_present_in_pair": [
            "NET_SINK",
            "READS"
          ],
          "verdict": "IMPOSSIBLE",
          "why": "no tool in either server carries ['NON_IDEMPOTENT'] \u2014 no rule in schema_to_rules can assign replay_amplified, for ANY of the 96 trust assignments per server"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 4,
            "n_rules": 2
          },
          "degenerate_note": null,
          "hazard_field": "secret_exfiltrated",
          "informative": false,
          "missing_necessary_tags": [],
          "necessary_tags": [
            "NET_SINK"
          ],
          "tags_present_in_pair": [
            "NET_SINK",
            "READS"
          ],
          "verdict": "POSSIBLE",
          "why": "the pair carries every tag necessary for secret_exfiltrated; impossibility does NOT hold and the field must be decided per-assignment"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 4,
            "n_rules": 2
          },
          "degenerate_note": null,
          "hazard_field": "unauthorized_write",
          "informative": true,
          "missing_necessary_tags": [
            "WRITES"
          ],
          "necessary_tags": [
            "WRITES"
          ],
          "tags_present_in_pair": [
            "NET_SINK",
            "READS"
          ],
          "verdict": "IMPOSSIBLE",
          "why": "no tool in either server carries ['WRITES'] \u2014 no rule in schema_to_rules can assign unauthorized_write, for ANY of the 96 trust assignments per server"
        }
      ],
      "n_impossible": 4,
      "n_impossible_informative": 4,
      "pair": "fetch+sequentialthinking",
      "union_tags": [
        "NET_SINK",
        "READS"
      ]
    },
    {
      "fields": [
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 10,
            "n_rules": 8
          },
          "degenerate_note": null,
          "hazard_field": "irreversible_change",
          "informative": true,
          "missing_necessary_tags": [
            "DESTRUCTIVE"
          ],
          "necessary_tags": [
            "DESTRUCTIVE"
          ],
          "tags_present_in_pair": [
            "NET_SINK",
            "READS",
            "WRITES"
          ],
          "verdict": "IMPOSSIBLE",
          "why": "no tool in either server carries ['DESTRUCTIVE'] \u2014 no rule in schema_to_rules can assign irreversible_change, for ANY of the 96 trust assignments per server"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 10,
            "n_rules": 8
          },
          "degenerate_note": null,
          "hazard_field": "priv_elevated",
          "informative": true,
          "missing_necessary_tags": [
            "GRANTS"
          ],
          "necessary_tags": [
            "GRANTS"
          ],
          "tags_present_in_pair": [
            "NET_SINK",
            "READS",
            "WRITES"
          ],
          "verdict": "IMPOSSIBLE",
          "why": "no tool in either server carries ['GRANTS'] \u2014 no rule in schema_to_rules can assign priv_elevated, for ANY of the 96 trust assignments per server"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 10,
            "n_rules": 8
          },
          "degenerate_note": null,
          "hazard_field": "replay_amplified",
          "informative": true,
          "missing_necessary_tags": [
            "NON_IDEMPOTENT"
          ],
          "necessary_tags": [
            "NON_IDEMPOTENT"
          ],
          "tags_present_in_pair": [
            "NET_SINK",
            "READS",
            "WRITES"
          ],
          "verdict": "IMPOSSIBLE",
          "why": "no tool in either server carries ['NON_IDEMPOTENT'] \u2014 no rule in schema_to_rules can assign replay_amplified, for ANY of the 96 trust assignments per server"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 10,
            "n_rules": 8
          },
          "degenerate_note": null,
          "hazard_field": "secret_exfiltrated",
          "informative": false,
          "missing_necessary_tags": [],
          "necessary_tags": [
            "NET_SINK"
          ],
          "tags_present_in_pair": [
            "NET_SINK",
            "READS",
            "WRITES"
          ],
          "verdict": "POSSIBLE",
          "why": "the pair carries every tag necessary for secret_exfiltrated; impossibility does NOT hold and the field must be decided per-assignment"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 10,
            "n_rules": 8
          },
          "degenerate_note": null,
          "hazard_field": "unauthorized_write",
          "informative": false,
          "missing_necessary_tags": [],
          "necessary_tags": [
            "WRITES"
          ],
          "tags_present_in_pair": [
            "NET_SINK",
            "READS",
            "WRITES"
          ],
          "verdict": "POSSIBLE",
          "why": "the pair carries every tag necessary for unauthorized_write; impossibility does NOT hold and the field must be decided per-assignment"
        }
      ],
      "n_impossible": 3,
      "n_impossible_informative": 3,
      "pair": "fetch+sqlite",
      "union_tags": [
        "NET_SINK",
        "READS",
        "WRITES"
      ]
    },
    {
      "fields": [
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 4,
            "n_rules": 2
          },
          "degenerate_note": null,
          "hazard_field": "irreversible_change",
          "informative": true,
          "missing_necessary_tags": [
            "DESTRUCTIVE"
          ],
          "necessary_tags": [
            "DESTRUCTIVE"
          ],
          "tags_present_in_pair": [
            "NET_SINK",
            "READS"
          ],
          "verdict": "IMPOSSIBLE",
          "why": "no tool in either server carries ['DESTRUCTIVE'] \u2014 no rule in schema_to_rules can assign irreversible_change, for ANY of the 96 trust assignments per server"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 4,
            "n_rules": 2
          },
          "degenerate_note": null,
          "hazard_field": "priv_elevated",
          "informative": true,
          "missing_necessary_tags": [
            "GRANTS"
          ],
          "necessary_tags": [
            "GRANTS"
          ],
          "tags_present_in_pair": [
            "NET_SINK",
            "READS"
          ],
          "verdict": "IMPOSSIBLE",
          "why": "no tool in either server carries ['GRANTS'] \u2014 no rule in schema_to_rules can assign priv_elevated, for ANY of the 96 trust assignments per server"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 4,
            "n_rules": 2
          },
          "degenerate_note": null,
          "hazard_field": "replay_amplified",
          "informative": true,
          "missing_necessary_tags": [
            "NON_IDEMPOTENT"
          ],
          "necessary_tags": [
            "NON_IDEMPOTENT"
          ],
          "tags_present_in_pair": [
            "NET_SINK",
            "READS"
          ],
          "verdict": "IMPOSSIBLE",
          "why": "no tool in either server carries ['NON_IDEMPOTENT'] \u2014 no rule in schema_to_rules can assign replay_amplified, for ANY of the 96 trust assignments per server"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 4,
            "n_rules": 2
          },
          "degenerate_note": null,
          "hazard_field": "secret_exfiltrated",
          "informative": false,
          "missing_necessary_tags": [],
          "necessary_tags": [
            "NET_SINK"
          ],
          "tags_present_in_pair": [
            "NET_SINK",
            "READS"
          ],
          "verdict": "POSSIBLE",
          "why": "the pair carries every tag necessary for secret_exfiltrated; impossibility does NOT hold and the field must be decided per-assignment"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 4,
            "n_rules": 2
          },
          "degenerate_note": null,
          "hazard_field": "unauthorized_write",
          "informative": true,
          "missing_necessary_tags": [
            "WRITES"
          ],
          "necessary_tags": [
            "WRITES"
          ],
          "tags_present_in_pair": [
            "NET_SINK",
            "READS"
          ],
          "verdict": "IMPOSSIBLE",
          "why": "no tool in either server carries ['WRITES'] \u2014 no rule in schema_to_rules can assign unauthorized_write, for ANY of the 96 trust assignments per server"
        }
      ],
      "n_impossible": 4,
      "n_impossible_informative": 4,
      "pair": "fetch+time",
      "union_tags": [
        "NET_SINK",
        "READS"
      ]
    },
    {
      "fields": [
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 2,
            "n_rules": 29
          },
          "degenerate_note": null,
          "hazard_field": "irreversible_change",
          "informative": false,
          "missing_necessary_tags": [],
          "necessary_tags": [
            "DESTRUCTIVE"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "POSSIBLE",
          "why": "the pair carries every tag necessary for irreversible_change; impossibility does NOT hold and the field must be decided per-assignment"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 2,
            "n_rules": 29
          },
          "degenerate_note": null,
          "hazard_field": "priv_elevated",
          "informative": true,
          "missing_necessary_tags": [
            "GRANTS"
          ],
          "necessary_tags": [
            "GRANTS"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "IMPOSSIBLE",
          "why": "no tool in either server carries ['GRANTS'] \u2014 no rule in schema_to_rules can assign priv_elevated, for ANY of the 96 trust assignments per server"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 2,
            "n_rules": 29
          },
          "degenerate_note": null,
          "hazard_field": "replay_amplified",
          "informative": false,
          "missing_necessary_tags": [],
          "necessary_tags": [
            "NON_IDEMPOTENT"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "POSSIBLE",
          "why": "the pair carries every tag necessary for replay_amplified; impossibility does NOT hold and the field must be decided per-assignment"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 2,
            "n_rules": 29
          },
          "degenerate_note": null,
          "hazard_field": "secret_exfiltrated",
          "informative": true,
          "missing_necessary_tags": [
            "NET_SINK"
          ],
          "necessary_tags": [
            "NET_SINK"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "IMPOSSIBLE",
          "why": "no tool in either server carries ['NET_SINK'] \u2014 no rule in schema_to_rules can assign secret_exfiltrated, for ANY of the 96 trust assignments per server"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 2,
            "n_rules": 29
          },
          "degenerate_note": null,
          "hazard_field": "unauthorized_write",
          "informative": false,
          "missing_necessary_tags": [],
          "necessary_tags": [
            "WRITES"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "POSSIBLE",
          "why": "the pair carries every tag necessary for unauthorized_write; impossibility does NOT hold and the field must be decided per-assignment"
        }
      ],
      "n_impossible": 2,
      "n_impossible_informative": 2,
      "pair": "filesystem+git",
      "union_tags": [
        "DESTRUCTIVE",
        "NON_IDEMPOTENT",
        "READS",
        "WRITES"
      ]
    },
    {
      "fields": [
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 18,
            "n_rules": 28
          },
          "degenerate_note": null,
          "hazard_field": "irreversible_change",
          "informative": false,
          "missing_necessary_tags": [],
          "necessary_tags": [
            "DESTRUCTIVE"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "POSSIBLE",
          "why": "the pair carries every tag necessary for irreversible_change; impossibility does NOT hold and the field must be decided per-assignment"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 18,
            "n_rules": 28
          },
          "degenerate_note": null,
          "hazard_field": "priv_elevated",
          "informative": true,
          "missing_necessary_tags": [
            "GRANTS"
          ],
          "necessary_tags": [
            "GRANTS"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "IMPOSSIBLE",
          "why": "no tool in either server carries ['GRANTS'] \u2014 no rule in schema_to_rules can assign priv_elevated, for ANY of the 96 trust assignments per server"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 18,
            "n_rules": 28
          },
          "degenerate_note": null,
          "hazard_field": "replay_amplified",
          "informative": false,
          "missing_necessary_tags": [],
          "necessary_tags": [
            "NON_IDEMPOTENT"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "POSSIBLE",
          "why": "the pair carries every tag necessary for replay_amplified; impossibility does NOT hold and the field must be decided per-assignment"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 18,
            "n_rules": 28
          },
          "degenerate_note": null,
          "hazard_field": "secret_exfiltrated",
          "informative": true,
          "missing_necessary_tags": [
            "NET_SINK"
          ],
          "necessary_tags": [
            "NET_SINK"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "IMPOSSIBLE",
          "why": "no tool in either server carries ['NET_SINK'] \u2014 no rule in schema_to_rules can assign secret_exfiltrated, for ANY of the 96 trust assignments per server"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 18,
            "n_rules": 28
          },
          "degenerate_note": null,
          "hazard_field": "unauthorized_write",
          "informative": false,
          "missing_necessary_tags": [],
          "necessary_tags": [
            "WRITES"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "POSSIBLE",
          "why": "the pair carries every tag necessary for unauthorized_write; impossibility does NOT hold and the field must be decided per-assignment"
        }
      ],
      "n_impossible": 2,
      "n_impossible_informative": 2,
      "pair": "filesystem+memory",
      "union_tags": [
        "DESTRUCTIVE",
        "NON_IDEMPOTENT",
        "READS",
        "WRITES"
      ]
    },
    {
      "fields": [
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 2,
            "n_rules": 19
          },
          "degenerate_note": null,
          "hazard_field": "irreversible_change",
          "informative": false,
          "missing_necessary_tags": [],
          "necessary_tags": [
            "DESTRUCTIVE"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "POSSIBLE",
          "why": "the pair carries every tag necessary for irreversible_change; impossibility does NOT hold and the field must be decided per-assignment"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 2,
            "n_rules": 19
          },
          "degenerate_note": null,
          "hazard_field": "priv_elevated",
          "informative": true,
          "missing_necessary_tags": [
            "GRANTS"
          ],
          "necessary_tags": [
            "GRANTS"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "IMPOSSIBLE",
          "why": "no tool in either server carries ['GRANTS'] \u2014 no rule in schema_to_rules can assign priv_elevated, for ANY of the 96 trust assignments per server"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 2,
            "n_rules": 19
          },
          "degenerate_note": null,
          "hazard_field": "replay_amplified",
          "informative": false,
          "missing_necessary_tags": [],
          "necessary_tags": [
            "NON_IDEMPOTENT"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "POSSIBLE",
          "why": "the pair carries every tag necessary for replay_amplified; impossibility does NOT hold and the field must be decided per-assignment"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 2,
            "n_rules": 19
          },
          "degenerate_note": null,
          "hazard_field": "secret_exfiltrated",
          "informative": true,
          "missing_necessary_tags": [
            "NET_SINK"
          ],
          "necessary_tags": [
            "NET_SINK"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "IMPOSSIBLE",
          "why": "no tool in either server carries ['NET_SINK'] \u2014 no rule in schema_to_rules can assign secret_exfiltrated, for ANY of the 96 trust assignments per server"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 2,
            "n_rules": 19
          },
          "degenerate_note": null,
          "hazard_field": "unauthorized_write",
          "informative": false,
          "missing_necessary_tags": [],
          "necessary_tags": [
            "WRITES"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "POSSIBLE",
          "why": "the pair carries every tag necessary for unauthorized_write; impossibility does NOT hold and the field must be decided per-assignment"
        }
      ],
      "n_impossible": 2,
      "n_impossible_informative": 2,
      "pair": "filesystem+sequentialthinking",
      "union_tags": [
        "DESTRUCTIVE",
        "NON_IDEMPOTENT",
        "READS",
        "WRITES"
      ]
    },
    {
      "fields": [
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 18,
            "n_rules": 25
          },
          "degenerate_note": null,
          "hazard_field": "irreversible_change",
          "informative": false,
          "missing_necessary_tags": [],
          "necessary_tags": [
            "DESTRUCTIVE"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "POSSIBLE",
          "why": "the pair carries every tag necessary for irreversible_change; impossibility does NOT hold and the field must be decided per-assignment"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 18,
            "n_rules": 25
          },
          "degenerate_note": null,
          "hazard_field": "priv_elevated",
          "informative": true,
          "missing_necessary_tags": [
            "GRANTS"
          ],
          "necessary_tags": [
            "GRANTS"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "IMPOSSIBLE",
          "why": "no tool in either server carries ['GRANTS'] \u2014 no rule in schema_to_rules can assign priv_elevated, for ANY of the 96 trust assignments per server"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 18,
            "n_rules": 25
          },
          "degenerate_note": null,
          "hazard_field": "replay_amplified",
          "informative": false,
          "missing_necessary_tags": [],
          "necessary_tags": [
            "NON_IDEMPOTENT"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "POSSIBLE",
          "why": "the pair carries every tag necessary for replay_amplified; impossibility does NOT hold and the field must be decided per-assignment"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 18,
            "n_rules": 25
          },
          "degenerate_note": null,
          "hazard_field": "secret_exfiltrated",
          "informative": true,
          "missing_necessary_tags": [
            "NET_SINK"
          ],
          "necessary_tags": [
            "NET_SINK"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "IMPOSSIBLE",
          "why": "no tool in either server carries ['NET_SINK'] \u2014 no rule in schema_to_rules can assign secret_exfiltrated, for ANY of the 96 trust assignments per server"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 18,
            "n_rules": 25
          },
          "degenerate_note": null,
          "hazard_field": "unauthorized_write",
          "informative": false,
          "missing_necessary_tags": [],
          "necessary_tags": [
            "WRITES"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "POSSIBLE",
          "why": "the pair carries every tag necessary for unauthorized_write; impossibility does NOT hold and the field must be decided per-assignment"
        }
      ],
      "n_impossible": 2,
      "n_impossible_informative": 2,
      "pair": "filesystem+sqlite",
      "union_tags": [
        "DESTRUCTIVE",
        "NON_IDEMPOTENT",
        "READS",
        "WRITES"
      ]
    },
    {
      "fields": [
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 2,
            "n_rules": 19
          },
          "degenerate_note": null,
          "hazard_field": "irreversible_change",
          "informative": false,
          "missing_necessary_tags": [],
          "necessary_tags": [
            "DESTRUCTIVE"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "POSSIBLE",
          "why": "the pair carries every tag necessary for irreversible_change; impossibility does NOT hold and the field must be decided per-assignment"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 2,
            "n_rules": 19
          },
          "degenerate_note": null,
          "hazard_field": "priv_elevated",
          "informative": true,
          "missing_necessary_tags": [
            "GRANTS"
          ],
          "necessary_tags": [
            "GRANTS"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "IMPOSSIBLE",
          "why": "no tool in either server carries ['GRANTS'] \u2014 no rule in schema_to_rules can assign priv_elevated, for ANY of the 96 trust assignments per server"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 2,
            "n_rules": 19
          },
          "degenerate_note": null,
          "hazard_field": "replay_amplified",
          "informative": false,
          "missing_necessary_tags": [],
          "necessary_tags": [
            "NON_IDEMPOTENT"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "POSSIBLE",
          "why": "the pair carries every tag necessary for replay_amplified; impossibility does NOT hold and the field must be decided per-assignment"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 2,
            "n_rules": 19
          },
          "degenerate_note": null,
          "hazard_field": "secret_exfiltrated",
          "informative": true,
          "missing_necessary_tags": [
            "NET_SINK"
          ],
          "necessary_tags": [
            "NET_SINK"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "IMPOSSIBLE",
          "why": "no tool in either server carries ['NET_SINK'] \u2014 no rule in schema_to_rules can assign secret_exfiltrated, for ANY of the 96 trust assignments per server"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 2,
            "n_rules": 19
          },
          "degenerate_note": null,
          "hazard_field": "unauthorized_write",
          "informative": false,
          "missing_necessary_tags": [],
          "necessary_tags": [
            "WRITES"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "POSSIBLE",
          "why": "the pair carries every tag necessary for unauthorized_write; impossibility does NOT hold and the field must be decided per-assignment"
        }
      ],
      "n_impossible": 2,
      "n_impossible_informative": 2,
      "pair": "filesystem+time",
      "union_tags": [
        "DESTRUCTIVE",
        "NON_IDEMPOTENT",
        "READS",
        "WRITES"
      ]
    },
    {
      "fields": [
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 10,
            "n_rules": 19
          },
          "degenerate_note": null,
          "hazard_field": "irreversible_change",
          "informative": false,
          "missing_necessary_tags": [],
          "necessary_tags": [
            "DESTRUCTIVE"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "POSSIBLE",
          "why": "the pair carries every tag necessary for irreversible_change; impossibility does NOT hold and the field must be decided per-assignment"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 10,
            "n_rules": 19
          },
          "degenerate_note": null,
          "hazard_field": "priv_elevated",
          "informative": true,
          "missing_necessary_tags": [
            "GRANTS"
          ],
          "necessary_tags": [
            "GRANTS"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "IMPOSSIBLE",
          "why": "no tool in either server carries ['GRANTS'] \u2014 no rule in schema_to_rules can assign priv_elevated, for ANY of the 96 trust assignments per server"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 10,
            "n_rules": 19
          },
          "degenerate_note": null,
          "hazard_field": "replay_amplified",
          "informative": false,
          "missing_necessary_tags": [],
          "necessary_tags": [
            "NON_IDEMPOTENT"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "POSSIBLE",
          "why": "the pair carries every tag necessary for replay_amplified; impossibility does NOT hold and the field must be decided per-assignment"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 10,
            "n_rules": 19
          },
          "degenerate_note": null,
          "hazard_field": "secret_exfiltrated",
          "informative": true,
          "missing_necessary_tags": [
            "NET_SINK"
          ],
          "necessary_tags": [
            "NET_SINK"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "IMPOSSIBLE",
          "why": "no tool in either server carries ['NET_SINK'] \u2014 no rule in schema_to_rules can assign secret_exfiltrated, for ANY of the 96 trust assignments per server"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 10,
            "n_rules": 19
          },
          "degenerate_note": null,
          "hazard_field": "unauthorized_write",
          "informative": false,
          "missing_necessary_tags": [],
          "necessary_tags": [
            "WRITES"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "POSSIBLE",
          "why": "the pair carries every tag necessary for unauthorized_write; impossibility does NOT hold and the field must be decided per-assignment"
        }
      ],
      "n_impossible": 2,
      "n_impossible_informative": 2,
      "pair": "git+memory",
      "union_tags": [
        "DESTRUCTIVE",
        "NON_IDEMPOTENT",
        "READS",
        "WRITES"
      ]
    },
    {
      "fields": [
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 2,
            "n_rules": 10
          },
          "degenerate_note": null,
          "hazard_field": "irreversible_change",
          "informative": false,
          "missing_necessary_tags": [],
          "necessary_tags": [
            "DESTRUCTIVE"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "POSSIBLE",
          "why": "the pair carries every tag necessary for irreversible_change; impossibility does NOT hold and the field must be decided per-assignment"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 2,
            "n_rules": 10
          },
          "degenerate_note": null,
          "hazard_field": "priv_elevated",
          "informative": true,
          "missing_necessary_tags": [
            "GRANTS"
          ],
          "necessary_tags": [
            "GRANTS"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "IMPOSSIBLE",
          "why": "no tool in either server carries ['GRANTS'] \u2014 no rule in schema_to_rules can assign priv_elevated, for ANY of the 96 trust assignments per server"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 2,
            "n_rules": 10
          },
          "degenerate_note": null,
          "hazard_field": "replay_amplified",
          "informative": false,
          "missing_necessary_tags": [],
          "necessary_tags": [
            "NON_IDEMPOTENT"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "POSSIBLE",
          "why": "the pair carries every tag necessary for replay_amplified; impossibility does NOT hold and the field must be decided per-assignment"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 2,
            "n_rules": 10
          },
          "degenerate_note": null,
          "hazard_field": "secret_exfiltrated",
          "informative": true,
          "missing_necessary_tags": [
            "NET_SINK"
          ],
          "necessary_tags": [
            "NET_SINK"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "IMPOSSIBLE",
          "why": "no tool in either server carries ['NET_SINK'] \u2014 no rule in schema_to_rules can assign secret_exfiltrated, for ANY of the 96 trust assignments per server"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 2,
            "n_rules": 10
          },
          "degenerate_note": null,
          "hazard_field": "unauthorized_write",
          "informative": false,
          "missing_necessary_tags": [],
          "necessary_tags": [
            "WRITES"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "POSSIBLE",
          "why": "the pair carries every tag necessary for unauthorized_write; impossibility does NOT hold and the field must be decided per-assignment"
        }
      ],
      "n_impossible": 2,
      "n_impossible_informative": 2,
      "pair": "git+sequentialthinking",
      "union_tags": [
        "DESTRUCTIVE",
        "NON_IDEMPOTENT",
        "READS",
        "WRITES"
      ]
    },
    {
      "fields": [
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 10,
            "n_rules": 16
          },
          "degenerate_note": null,
          "hazard_field": "irreversible_change",
          "informative": false,
          "missing_necessary_tags": [],
          "necessary_tags": [
            "DESTRUCTIVE"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "POSSIBLE",
          "why": "the pair carries every tag necessary for irreversible_change; impossibility does NOT hold and the field must be decided per-assignment"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 10,
            "n_rules": 16
          },
          "degenerate_note": null,
          "hazard_field": "priv_elevated",
          "informative": true,
          "missing_necessary_tags": [
            "GRANTS"
          ],
          "necessary_tags": [
            "GRANTS"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "IMPOSSIBLE",
          "why": "no tool in either server carries ['GRANTS'] \u2014 no rule in schema_to_rules can assign priv_elevated, for ANY of the 96 trust assignments per server"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 10,
            "n_rules": 16
          },
          "degenerate_note": null,
          "hazard_field": "replay_amplified",
          "informative": false,
          "missing_necessary_tags": [],
          "necessary_tags": [
            "NON_IDEMPOTENT"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "POSSIBLE",
          "why": "the pair carries every tag necessary for replay_amplified; impossibility does NOT hold and the field must be decided per-assignment"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 10,
            "n_rules": 16
          },
          "degenerate_note": null,
          "hazard_field": "secret_exfiltrated",
          "informative": true,
          "missing_necessary_tags": [
            "NET_SINK"
          ],
          "necessary_tags": [
            "NET_SINK"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "IMPOSSIBLE",
          "why": "no tool in either server carries ['NET_SINK'] \u2014 no rule in schema_to_rules can assign secret_exfiltrated, for ANY of the 96 trust assignments per server"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 10,
            "n_rules": 16
          },
          "degenerate_note": null,
          "hazard_field": "unauthorized_write",
          "informative": false,
          "missing_necessary_tags": [],
          "necessary_tags": [
            "WRITES"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "POSSIBLE",
          "why": "the pair carries every tag necessary for unauthorized_write; impossibility does NOT hold and the field must be decided per-assignment"
        }
      ],
      "n_impossible": 2,
      "n_impossible_informative": 2,
      "pair": "git+sqlite",
      "union_tags": [
        "DESTRUCTIVE",
        "NON_IDEMPOTENT",
        "READS",
        "WRITES"
      ]
    },
    {
      "fields": [
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 2,
            "n_rules": 10
          },
          "degenerate_note": null,
          "hazard_field": "irreversible_change",
          "informative": false,
          "missing_necessary_tags": [],
          "necessary_tags": [
            "DESTRUCTIVE"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "POSSIBLE",
          "why": "the pair carries every tag necessary for irreversible_change; impossibility does NOT hold and the field must be decided per-assignment"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 2,
            "n_rules": 10
          },
          "degenerate_note": null,
          "hazard_field": "priv_elevated",
          "informative": true,
          "missing_necessary_tags": [
            "GRANTS"
          ],
          "necessary_tags": [
            "GRANTS"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "IMPOSSIBLE",
          "why": "no tool in either server carries ['GRANTS'] \u2014 no rule in schema_to_rules can assign priv_elevated, for ANY of the 96 trust assignments per server"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 2,
            "n_rules": 10
          },
          "degenerate_note": null,
          "hazard_field": "replay_amplified",
          "informative": false,
          "missing_necessary_tags": [],
          "necessary_tags": [
            "NON_IDEMPOTENT"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "POSSIBLE",
          "why": "the pair carries every tag necessary for replay_amplified; impossibility does NOT hold and the field must be decided per-assignment"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 2,
            "n_rules": 10
          },
          "degenerate_note": null,
          "hazard_field": "secret_exfiltrated",
          "informative": true,
          "missing_necessary_tags": [
            "NET_SINK"
          ],
          "necessary_tags": [
            "NET_SINK"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "IMPOSSIBLE",
          "why": "no tool in either server carries ['NET_SINK'] \u2014 no rule in schema_to_rules can assign secret_exfiltrated, for ANY of the 96 trust assignments per server"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 2,
            "n_rules": 10
          },
          "degenerate_note": null,
          "hazard_field": "unauthorized_write",
          "informative": false,
          "missing_necessary_tags": [],
          "necessary_tags": [
            "WRITES"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "POSSIBLE",
          "why": "the pair carries every tag necessary for unauthorized_write; impossibility does NOT hold and the field must be decided per-assignment"
        }
      ],
      "n_impossible": 2,
      "n_impossible_informative": 2,
      "pair": "git+time",
      "union_tags": [
        "DESTRUCTIVE",
        "NON_IDEMPOTENT",
        "READS",
        "WRITES"
      ]
    },
    {
      "fields": [
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 5,
            "n_rules": 9
          },
          "degenerate_note": null,
          "hazard_field": "irreversible_change",
          "informative": false,
          "missing_necessary_tags": [],
          "necessary_tags": [
            "DESTRUCTIVE"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "POSSIBLE",
          "why": "the pair carries every tag necessary for irreversible_change; impossibility does NOT hold and the field must be decided per-assignment"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 5,
            "n_rules": 9
          },
          "degenerate_note": null,
          "hazard_field": "priv_elevated",
          "informative": true,
          "missing_necessary_tags": [
            "GRANTS"
          ],
          "necessary_tags": [
            "GRANTS"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "IMPOSSIBLE",
          "why": "no tool in either server carries ['GRANTS'] \u2014 no rule in schema_to_rules can assign priv_elevated, for ANY of the 96 trust assignments per server"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 5,
            "n_rules": 9
          },
          "degenerate_note": null,
          "hazard_field": "replay_amplified",
          "informative": false,
          "missing_necessary_tags": [],
          "necessary_tags": [
            "NON_IDEMPOTENT"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "POSSIBLE",
          "why": "the pair carries every tag necessary for replay_amplified; impossibility does NOT hold and the field must be decided per-assignment"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 5,
            "n_rules": 9
          },
          "degenerate_note": null,
          "hazard_field": "secret_exfiltrated",
          "informative": true,
          "missing_necessary_tags": [
            "NET_SINK"
          ],
          "necessary_tags": [
            "NET_SINK"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "IMPOSSIBLE",
          "why": "no tool in either server carries ['NET_SINK'] \u2014 no rule in schema_to_rules can assign secret_exfiltrated, for ANY of the 96 trust assignments per server"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 5,
            "n_rules": 9
          },
          "degenerate_note": null,
          "hazard_field": "unauthorized_write",
          "informative": false,
          "missing_necessary_tags": [],
          "necessary_tags": [
            "WRITES"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "POSSIBLE",
          "why": "the pair carries every tag necessary for unauthorized_write; impossibility does NOT hold and the field must be decided per-assignment"
        }
      ],
      "n_impossible": 2,
      "n_impossible_informative": 2,
      "pair": "memory+sequentialthinking",
      "union_tags": [
        "DESTRUCTIVE",
        "NON_IDEMPOTENT",
        "READS",
        "WRITES"
      ]
    },
    {
      "fields": [
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 10,
            "n_rules": 15
          },
          "degenerate_note": null,
          "hazard_field": "irreversible_change",
          "informative": false,
          "missing_necessary_tags": [],
          "necessary_tags": [
            "DESTRUCTIVE"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "POSSIBLE",
          "why": "the pair carries every tag necessary for irreversible_change; impossibility does NOT hold and the field must be decided per-assignment"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 10,
            "n_rules": 15
          },
          "degenerate_note": null,
          "hazard_field": "priv_elevated",
          "informative": true,
          "missing_necessary_tags": [
            "GRANTS"
          ],
          "necessary_tags": [
            "GRANTS"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "IMPOSSIBLE",
          "why": "no tool in either server carries ['GRANTS'] \u2014 no rule in schema_to_rules can assign priv_elevated, for ANY of the 96 trust assignments per server"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 10,
            "n_rules": 15
          },
          "degenerate_note": null,
          "hazard_field": "replay_amplified",
          "informative": false,
          "missing_necessary_tags": [],
          "necessary_tags": [
            "NON_IDEMPOTENT"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "POSSIBLE",
          "why": "the pair carries every tag necessary for replay_amplified; impossibility does NOT hold and the field must be decided per-assignment"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 10,
            "n_rules": 15
          },
          "degenerate_note": null,
          "hazard_field": "secret_exfiltrated",
          "informative": true,
          "missing_necessary_tags": [
            "NET_SINK"
          ],
          "necessary_tags": [
            "NET_SINK"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "IMPOSSIBLE",
          "why": "no tool in either server carries ['NET_SINK'] \u2014 no rule in schema_to_rules can assign secret_exfiltrated, for ANY of the 96 trust assignments per server"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 10,
            "n_rules": 15
          },
          "degenerate_note": null,
          "hazard_field": "unauthorized_write",
          "informative": false,
          "missing_necessary_tags": [],
          "necessary_tags": [
            "WRITES"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "POSSIBLE",
          "why": "the pair carries every tag necessary for unauthorized_write; impossibility does NOT hold and the field must be decided per-assignment"
        }
      ],
      "n_impossible": 2,
      "n_impossible_informative": 2,
      "pair": "memory+sqlite",
      "union_tags": [
        "DESTRUCTIVE",
        "NON_IDEMPOTENT",
        "READS",
        "WRITES"
      ]
    },
    {
      "fields": [
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 5,
            "n_rules": 9
          },
          "degenerate_note": null,
          "hazard_field": "irreversible_change",
          "informative": false,
          "missing_necessary_tags": [],
          "necessary_tags": [
            "DESTRUCTIVE"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "POSSIBLE",
          "why": "the pair carries every tag necessary for irreversible_change; impossibility does NOT hold and the field must be decided per-assignment"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 5,
            "n_rules": 9
          },
          "degenerate_note": null,
          "hazard_field": "priv_elevated",
          "informative": true,
          "missing_necessary_tags": [
            "GRANTS"
          ],
          "necessary_tags": [
            "GRANTS"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "IMPOSSIBLE",
          "why": "no tool in either server carries ['GRANTS'] \u2014 no rule in schema_to_rules can assign priv_elevated, for ANY of the 96 trust assignments per server"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 5,
            "n_rules": 9
          },
          "degenerate_note": null,
          "hazard_field": "replay_amplified",
          "informative": false,
          "missing_necessary_tags": [],
          "necessary_tags": [
            "NON_IDEMPOTENT"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "POSSIBLE",
          "why": "the pair carries every tag necessary for replay_amplified; impossibility does NOT hold and the field must be decided per-assignment"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 5,
            "n_rules": 9
          },
          "degenerate_note": null,
          "hazard_field": "secret_exfiltrated",
          "informative": true,
          "missing_necessary_tags": [
            "NET_SINK"
          ],
          "necessary_tags": [
            "NET_SINK"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "IMPOSSIBLE",
          "why": "no tool in either server carries ['NET_SINK'] \u2014 no rule in schema_to_rules can assign secret_exfiltrated, for ANY of the 96 trust assignments per server"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 5,
            "n_rules": 9
          },
          "degenerate_note": null,
          "hazard_field": "unauthorized_write",
          "informative": false,
          "missing_necessary_tags": [],
          "necessary_tags": [
            "WRITES"
          ],
          "tags_present_in_pair": [
            "DESTRUCTIVE",
            "NON_IDEMPOTENT",
            "READS",
            "WRITES"
          ],
          "verdict": "POSSIBLE",
          "why": "the pair carries every tag necessary for unauthorized_write; impossibility does NOT hold and the field must be decided per-assignment"
        }
      ],
      "n_impossible": 2,
      "n_impossible_informative": 2,
      "pair": "memory+time",
      "union_tags": [
        "DESTRUCTIVE",
        "NON_IDEMPOTENT",
        "READS",
        "WRITES"
      ]
    },
    {
      "fields": [
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 4,
            "n_rules": 6
          },
          "degenerate_note": null,
          "hazard_field": "irreversible_change",
          "informative": true,
          "missing_necessary_tags": [
            "DESTRUCTIVE"
          ],
          "necessary_tags": [
            "DESTRUCTIVE"
          ],
          "tags_present_in_pair": [
            "READS",
            "WRITES"
          ],
          "verdict": "IMPOSSIBLE",
          "why": "no tool in either server carries ['DESTRUCTIVE'] \u2014 no rule in schema_to_rules can assign irreversible_change, for ANY of the 96 trust assignments per server"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 4,
            "n_rules": 6
          },
          "degenerate_note": null,
          "hazard_field": "priv_elevated",
          "informative": true,
          "missing_necessary_tags": [
            "GRANTS"
          ],
          "necessary_tags": [
            "GRANTS"
          ],
          "tags_present_in_pair": [
            "READS",
            "WRITES"
          ],
          "verdict": "IMPOSSIBLE",
          "why": "no tool in either server carries ['GRANTS'] \u2014 no rule in schema_to_rules can assign priv_elevated, for ANY of the 96 trust assignments per server"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 4,
            "n_rules": 6
          },
          "degenerate_note": null,
          "hazard_field": "replay_amplified",
          "informative": true,
          "missing_necessary_tags": [
            "NON_IDEMPOTENT"
          ],
          "necessary_tags": [
            "NON_IDEMPOTENT"
          ],
          "tags_present_in_pair": [
            "READS",
            "WRITES"
          ],
          "verdict": "IMPOSSIBLE",
          "why": "no tool in either server carries ['NON_IDEMPOTENT'] \u2014 no rule in schema_to_rules can assign replay_amplified, for ANY of the 96 trust assignments per server"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 4,
            "n_rules": 6
          },
          "degenerate_note": null,
          "hazard_field": "secret_exfiltrated",
          "informative": true,
          "missing_necessary_tags": [
            "NET_SINK"
          ],
          "necessary_tags": [
            "NET_SINK"
          ],
          "tags_present_in_pair": [
            "READS",
            "WRITES"
          ],
          "verdict": "IMPOSSIBLE",
          "why": "no tool in either server carries ['NET_SINK'] \u2014 no rule in schema_to_rules can assign secret_exfiltrated, for ANY of the 96 trust assignments per server"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 4,
            "n_rules": 6
          },
          "degenerate_note": null,
          "hazard_field": "unauthorized_write",
          "informative": false,
          "missing_necessary_tags": [],
          "necessary_tags": [
            "WRITES"
          ],
          "tags_present_in_pair": [
            "READS",
            "WRITES"
          ],
          "verdict": "POSSIBLE",
          "why": "the pair carries every tag necessary for unauthorized_write; impossibility does NOT hold and the field must be decided per-assignment"
        }
      ],
      "n_impossible": 4,
      "n_impossible_informative": 4,
      "pair": "sequentialthinking+sqlite",
      "union_tags": [
        "READS",
        "WRITES"
      ]
    },
    {
      "fields": [
        {
          "degeneracy": {
            "degenerate": true,
            "explored_states": 1,
            "n_rules": 0
          },
          "degenerate_note": "IMPOSSIBLE but the composed model has no behaviour at all (no rules, single reachable state) -- the structural claim holds, but a solver confirming it is uninformative. Counted separately from the informative slots, per scan.py's DEGENERATE_STATE_CEILING discipline.",
          "hazard_field": "irreversible_change",
          "informative": false,
          "missing_necessary_tags": [
            "DESTRUCTIVE"
          ],
          "necessary_tags": [
            "DESTRUCTIVE"
          ],
          "tags_present_in_pair": [
            "READS"
          ],
          "verdict": "IMPOSSIBLE",
          "why": "no tool in either server carries ['DESTRUCTIVE'] \u2014 no rule in schema_to_rules can assign irreversible_change, for ANY of the 96 trust assignments per server"
        },
        {
          "degeneracy": {
            "degenerate": true,
            "explored_states": 1,
            "n_rules": 0
          },
          "degenerate_note": "IMPOSSIBLE but the composed model has no behaviour at all (no rules, single reachable state) -- the structural claim holds, but a solver confirming it is uninformative. Counted separately from the informative slots, per scan.py's DEGENERATE_STATE_CEILING discipline.",
          "hazard_field": "priv_elevated",
          "informative": false,
          "missing_necessary_tags": [
            "GRANTS"
          ],
          "necessary_tags": [
            "GRANTS"
          ],
          "tags_present_in_pair": [
            "READS"
          ],
          "verdict": "IMPOSSIBLE",
          "why": "no tool in either server carries ['GRANTS'] \u2014 no rule in schema_to_rules can assign priv_elevated, for ANY of the 96 trust assignments per server"
        },
        {
          "degeneracy": {
            "degenerate": true,
            "explored_states": 1,
            "n_rules": 0
          },
          "degenerate_note": "IMPOSSIBLE but the composed model has no behaviour at all (no rules, single reachable state) -- the structural claim holds, but a solver confirming it is uninformative. Counted separately from the informative slots, per scan.py's DEGENERATE_STATE_CEILING discipline.",
          "hazard_field": "replay_amplified",
          "informative": false,
          "missing_necessary_tags": [
            "NON_IDEMPOTENT"
          ],
          "necessary_tags": [
            "NON_IDEMPOTENT"
          ],
          "tags_present_in_pair": [
            "READS"
          ],
          "verdict": "IMPOSSIBLE",
          "why": "no tool in either server carries ['NON_IDEMPOTENT'] \u2014 no rule in schema_to_rules can assign replay_amplified, for ANY of the 96 trust assignments per server"
        },
        {
          "degeneracy": {
            "degenerate": true,
            "explored_states": 1,
            "n_rules": 0
          },
          "degenerate_note": "IMPOSSIBLE but the composed model has no behaviour at all (no rules, single reachable state) -- the structural claim holds, but a solver confirming it is uninformative. Counted separately from the informative slots, per scan.py's DEGENERATE_STATE_CEILING discipline.",
          "hazard_field": "secret_exfiltrated",
          "informative": false,
          "missing_necessary_tags": [
            "NET_SINK"
          ],
          "necessary_tags": [
            "NET_SINK"
          ],
          "tags_present_in_pair": [
            "READS"
          ],
          "verdict": "IMPOSSIBLE",
          "why": "no tool in either server carries ['NET_SINK'] \u2014 no rule in schema_to_rules can assign secret_exfiltrated, for ANY of the 96 trust assignments per server"
        },
        {
          "degeneracy": {
            "degenerate": true,
            "explored_states": 1,
            "n_rules": 0
          },
          "degenerate_note": "IMPOSSIBLE but the composed model has no behaviour at all (no rules, single reachable state) -- the structural claim holds, but a solver confirming it is uninformative. Counted separately from the informative slots, per scan.py's DEGENERATE_STATE_CEILING discipline.",
          "hazard_field": "unauthorized_write",
          "informative": false,
          "missing_necessary_tags": [
            "WRITES"
          ],
          "necessary_tags": [
            "WRITES"
          ],
          "tags_present_in_pair": [
            "READS"
          ],
          "verdict": "IMPOSSIBLE",
          "why": "no tool in either server carries ['WRITES'] \u2014 no rule in schema_to_rules can assign unauthorized_write, for ANY of the 96 trust assignments per server"
        }
      ],
      "n_impossible": 5,
      "n_impossible_informative": 0,
      "pair": "sequentialthinking+time",
      "union_tags": [
        "READS"
      ]
    },
    {
      "fields": [
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 4,
            "n_rules": 6
          },
          "degenerate_note": null,
          "hazard_field": "irreversible_change",
          "informative": true,
          "missing_necessary_tags": [
            "DESTRUCTIVE"
          ],
          "necessary_tags": [
            "DESTRUCTIVE"
          ],
          "tags_present_in_pair": [
            "READS",
            "WRITES"
          ],
          "verdict": "IMPOSSIBLE",
          "why": "no tool in either server carries ['DESTRUCTIVE'] \u2014 no rule in schema_to_rules can assign irreversible_change, for ANY of the 96 trust assignments per server"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 4,
            "n_rules": 6
          },
          "degenerate_note": null,
          "hazard_field": "priv_elevated",
          "informative": true,
          "missing_necessary_tags": [
            "GRANTS"
          ],
          "necessary_tags": [
            "GRANTS"
          ],
          "tags_present_in_pair": [
            "READS",
            "WRITES"
          ],
          "verdict": "IMPOSSIBLE",
          "why": "no tool in either server carries ['GRANTS'] \u2014 no rule in schema_to_rules can assign priv_elevated, for ANY of the 96 trust assignments per server"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 4,
            "n_rules": 6
          },
          "degenerate_note": null,
          "hazard_field": "replay_amplified",
          "informative": true,
          "missing_necessary_tags": [
            "NON_IDEMPOTENT"
          ],
          "necessary_tags": [
            "NON_IDEMPOTENT"
          ],
          "tags_present_in_pair": [
            "READS",
            "WRITES"
          ],
          "verdict": "IMPOSSIBLE",
          "why": "no tool in either server carries ['NON_IDEMPOTENT'] \u2014 no rule in schema_to_rules can assign replay_amplified, for ANY of the 96 trust assignments per server"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 4,
            "n_rules": 6
          },
          "degenerate_note": null,
          "hazard_field": "secret_exfiltrated",
          "informative": true,
          "missing_necessary_tags": [
            "NET_SINK"
          ],
          "necessary_tags": [
            "NET_SINK"
          ],
          "tags_present_in_pair": [
            "READS",
            "WRITES"
          ],
          "verdict": "IMPOSSIBLE",
          "why": "no tool in either server carries ['NET_SINK'] \u2014 no rule in schema_to_rules can assign secret_exfiltrated, for ANY of the 96 trust assignments per server"
        },
        {
          "degeneracy": {
            "degenerate": false,
            "explored_states": 4,
            "n_rules": 6
          },
          "degenerate_note": null,
          "hazard_field": "unauthorized_write",
          "informative": false,
          "missing_necessary_tags": [],
          "necessary_tags": [
            "WRITES"
          ],
          "tags_present_in_pair": [
            "READS",
            "WRITES"
          ],
          "verdict": "POSSIBLE",
          "why": "the pair carries every tag necessary for unauthorized_write; impossibility does NOT hold and the field must be decided per-assignment"
        }
      ],
      "n_impossible": 4,
      "n_impossible_informative": 4,
      "pair": "sqlite+time",
      "union_tags": [
        "READS",
        "WRITES"
      ]
    }
  ],
  "route_a_structural": [
    {
      "hazard_field": "irreversible_change",
      "holds": true,
      "n_assignments_checked": 9216,
      "n_that_can_assign_the_field": 0,
      "offenders": [],
      "pair": "everything+fetch",
      "route": "A-structural",
      "what_it_checks": "no rule emitted by schema_to_rules mentions the field, at any of the 96x96 trust assignments"
    },
    {
      "hazard_field": "priv_elevated",
      "holds": true,
      "n_assignments_checked": 9216,
      "n_that_can_assign_the_field": 0,
      "offenders": [],
      "pair": "everything+fetch",
      "route": "A-structural",
      "what_it_checks": "no rule emitted by schema_to_rules mentions the field, at any of the 96x96 trust assignments"
    },
    {
      "hazard_field": "priv_elevated",
      "holds": true,
      "n_assignments_checked": 9216,
      "n_that_can_assign_the_field": 0,
      "offenders": [],
      "pair": "everything+filesystem",
      "route": "A-structural",
      "what_it_checks": "no rule emitted by schema_to_rules mentions the field, at any of the 96x96 trust assignments"
    },
    {
      "hazard_field": "priv_elevated",
      "holds": true,
      "n_assignments_checked": 9216,
      "n_that_can_assign_the_field": 0,
      "offenders": [],
      "pair": "everything+git",
      "route": "A-structural",
      "what_it_checks": "no rule emitted by schema_to_rules mentions the field, at any of the 96x96 trust assignments"
    },
    {
      "hazard_field": "priv_elevated",
      "holds": true,
      "n_assignments_checked": 9216,
      "n_that_can_assign_the_field": 0,
      "offenders": [],
      "pair": "everything+memory",
      "route": "A-structural",
      "what_it_checks": "no rule emitted by schema_to_rules mentions the field, at any of the 96x96 trust assignments"
    },
    {
      "hazard_field": "irreversible_change",
      "holds": true,
      "n_assignments_checked": 9216,
      "n_that_can_assign_the_field": 0,
      "offenders": [],
      "pair": "everything+sequentialthinking",
      "route": "A-structural",
      "what_it_checks": "no rule emitted by schema_to_rules mentions the field, at any of the 96x96 trust assignments"
    },
    {
      "hazard_field": "priv_elevated",
      "holds": true,
      "n_assignments_checked": 9216,
      "n_that_can_assign_the_field": 0,
      "offenders": [],
      "pair": "everything+sequentialthinking",
      "route": "A-structural",
      "what_it_checks": "no rule emitted by schema_to_rules mentions the field, at any of the 96x96 trust assignments"
    },
    {
      "hazard_field": "irreversible_change",
      "holds": true,
      "n_assignments_checked": 9216,
      "n_that_can_assign_the_field": 0,
      "offenders": [],
      "pair": "everything+sqlite",
      "route": "A-structural",
      "what_it_checks": "no rule emitted by schema_to_rules mentions the field, at any of the 96x96 trust assignments"
    },
    {
      "hazard_field": "priv_elevated",
      "holds": true,
      "n_assignments_checked": 9216,
      "n_that_can_assign_the_field": 0,
      "offenders": [],
      "pair": "everything+sqlite",
      "route": "A-structural",
      "what_it_checks": "no rule emitted by schema_to_rules mentions the field, at any of the 96x96 trust assignments"
    },
    {
      "hazard_field": "irreversible_change",
      "holds": true,
      "n_assignments_checked": 9216,
      "n_that_can_assign_the_field": 0,
      "offenders": [],
      "pair": "everything+time",
      "route": "A-structural",
      "what_it_checks": "no rule emitted by schema_to_rules mentions the field, at any of the 96x96 trust assignments"
    },
    {
      "hazard_field": "priv_elevated",
      "holds": true,
      "n_assignments_checked": 9216,
      "n_that_can_assign_the_field": 0,
      "offenders": [],
      "pair": "everything+time",
      "route": "A-structural",
      "what_it_checks": "no rule emitted by schema_to_rules mentions the field, at any of the 96x96 trust assignments"
    },
    {
      "hazard_field": "priv_elevated",
      "holds": true,
      "n_assignments_checked": 9216,
      "n_that_can_assign_the_field": 0,
      "offenders": [],
      "pair": "fetch+filesystem",
      "route": "A-structural",
      "what_it_checks": "no rule emitted by schema_to_rules mentions the field, at any of the 96x96 trust assignments"
    },
    {
      "hazard_field": "priv_elevated",
      "holds": true,
      "n_assignments_checked": 9216,
      "n_that_can_assign_the_field": 0,
      "offenders": [],
      "pair": "fetch+git",
      "route": "A-structural",
      "what_it_checks": "no rule emitted by schema_to_rules mentions the field, at any of the 96x96 trust assignments"
    },
    {
      "hazard_field": "priv_elevated",
      "holds": true,
      "n_assignments_checked": 9216,
      "n_that_can_assign_the_field": 0,
      "offenders": [],
      "pair": "fetch+memory",
      "route": "A-structural",
      "what_it_checks": "no rule emitted by schema_to_rules mentions the field, at any of the 96x96 trust assignments"
    },
    {
      "hazard_field": "irreversible_change",
      "holds": true,
      "n_assignments_checked": 9216,
      "n_that_can_assign_the_field": 0,
      "offenders": [],
      "pair": "fetch+sequentialthinking",
      "route": "A-structural",
      "what_it_checks": "no rule emitted by schema_to_rules mentions the field, at any of the 96x96 trust assignments"
    },
    {
      "hazard_field": "priv_elevated",
      "holds": true,
      "n_assignments_checked": 9216,
      "n_that_can_assign_the_field": 0,
      "offenders": [],
      "pair": "fetch+sequentialthinking",
      "route": "A-structural",
      "what_it_checks": "no rule emitted by schema_to_rules mentions the field, at any of the 96x96 trust assignments"
    },
    {
      "hazard_field": "replay_amplified",
      "holds": true,
      "n_assignments_checked": 9216,
      "n_that_can_assign_the_field": 0,
      "offenders": [],
      "pair": "fetch+sequentialthinking",
      "route": "A-structural",
      "what_it_checks": "no rule emitted by schema_to_rules mentions the field, at any of the 96x96 trust assignments"
    },
    {
      "hazard_field": "unauthorized_write",
      "holds": true,
      "n_assignments_checked": 9216,
      "n_that_can_assign_the_field": 0,
      "offenders": [],
      "pair": "fetch+sequentialthinking",
      "route": "A-structural",
      "what_it_checks": "no rule emitted by schema_to_rules mentions the field, at any of the 96x96 trust assignments"
    },
    {
      "hazard_field": "irreversible_change",
      "holds": true,
      "n_assignments_checked": 9216,
      "n_that_can_assign_the_field": 0,
      "offenders": [],
      "pair": "fetch+sqlite",
      "route": "A-structural",
      "what_it_checks": "no rule emitted by schema_to_rules mentions the field, at any of the 96x96 trust assignments"
    },
    {
      "hazard_field": "priv_elevated",
      "holds": true,
      "n_assignments_checked": 9216,
      "n_that_can_assign_the_field": 0,
      "offenders": [],
      "pair": "fetch+sqlite",
      "route": "A-structural",
      "what_it_checks": "no rule emitted by schema_to_rules mentions the field, at any of the 96x96 trust assignments"
    },
    {
      "hazard_field": "replay_amplified",
      "holds": true,
      "n_assignments_checked": 9216,
      "n_that_can_assign_the_field": 0,
      "offenders": [],
      "pair": "fetch+sqlite",
      "route": "A-structural",
      "what_it_checks": "no rule emitted by schema_to_rules mentions the field, at any of the 96x96 trust assignments"
    },
    {
      "hazard_field": "irreversible_change",
      "holds": true,
      "n_assignments_checked": 9216,
      "n_that_can_assign_the_field": 0,
      "offenders": [],
      "pair": "fetch+time",
      "route": "A-structural",
      "what_it_checks": "no rule emitted by schema_to_rules mentions the field, at any of the 96x96 trust assignments"
    },
    {
      "hazard_field": "priv_elevated",
      "holds": true,
      "n_assignments_checked": 9216,
      "n_that_can_assign_the_field": 0,
      "offenders": [],
      "pair": "fetch+time",
      "route": "A-structural",
      "what_it_checks": "no rule emitted by schema_to_rules mentions the field, at any of the 96x96 trust assignments"
    },
    {
      "hazard_field": "replay_amplified",
      "holds": true,
      "n_assignments_checked": 9216,
      "n_that_can_assign_the_field": 0,
      "offenders": [],
      "pair": "fetch+time",
      "route": "A-structural",
      "what_it_checks": "no rule emitted by schema_to_rules mentions the field, at any of the 96x96 trust assignments"
    },
    {
      "hazard_field": "unauthorized_write",
      "holds": true,
      "n_assignments_checked": 9216,
      "n_that_can_assign_the_field": 0,
      "offenders": [],
      "pair": "fetch+time",
      "route": "A-structural",
      "what_it_checks": "no rule emitted by schema_to_rules mentions the field, at any of the 96x96 trust assignments"
    },
    {
      "hazard_field": "priv_elevated",
      "holds": true,
      "n_assignments_checked": 9216,
      "n_that_can_assign_the_field": 0,
      "offenders": [],
      "pair": "filesystem+git",
      "route": "A-structural",
      "what_it_checks": "no rule emitted by schema_to_rules mentions the field, at any of the 96x96 trust assignments"
    },
    {
      "hazard_field": "secret_exfiltrated",
      "holds": true,
      "n_assignments_checked": 9216,
      "n_that_can_assign_the_field": 0,
      "offenders": [],
      "pair": "filesystem+git",
      "route": "A-structural",
      "what_it_checks": "no rule emitted by schema_to_rules mentions the field, at any of the 96x96 trust assignments"
    },
    {
      "hazard_field": "priv_elevated",
      "holds": true,
      "n_assignments_checked": 9216,
      "n_that_can_assign_the_field": 0,
      "offenders": [],
      "pair": "filesystem+memory",
      "route": "A-structural",
      "what_it_checks": "no rule emitted by schema_to_rules mentions the field, at any of the 96x96 trust assignments"
    },
    {
      "hazard_field": "secret_exfiltrated",
      "holds": true,
      "n_assignments_checked": 9216,
      "n_that_can_assign_the_field": 0,
      "offenders": [],
      "pair": "filesystem+memory",
      "route": "A-structural",
      "what_it_checks": "no rule emitted by schema_to_rules mentions the field, at any of the 96x96 trust assignments"
    },
    {
      "hazard_field": "priv_elevated",
      "holds": true,
      "n_assignments_checked": 9216,
      "n_that_can_assign_the_field": 0,
      "offenders": [],
      "pair": "filesystem+sequentialthinking",
      "route": "A-structural",
      "what_it_checks": "no rule emitted by schema_to_rules mentions the field, at any of the 96x96 trust assignments"
    },
    {
      "hazard_field": "secret_exfiltrated",
      "holds": true,
      "n_assignments_checked": 9216,
      "n_that_can_assign_the_field": 0,
      "offenders": [],
      "pair": "filesystem+sequentialthinking",
      "route": "A-structural",
      "what_it_checks": "no rule emitted by schema_to_rules mentions the field, at any of the 96x96 trust assignments"
    },
    {
      "hazard_field": "priv_elevated",
      "holds": true,
      "n_assignments_checked": 9216,
      "n_that_can_assign_the_field": 0,
      "offenders": [],
      "pair": "filesystem+sqlite",
      "route": "A-structural",
      "what_it_checks": "no rule emitted by schema_to_rules mentions the field, at any of the 96x96 trust assignments"
    },
    {
      "hazard_field": "secret_exfiltrated",
      "holds": true,
      "n_assignments_checked": 9216,
      "n_that_can_assign_the_field": 0,
      "offenders": [],
      "pair": "filesystem+sqlite",
      "route": "A-structural",
      "what_it_checks": "no rule emitted by schema_to_rules mentions the field, at any of the 96x96 trust assignments"
    },
    {
      "hazard_field": "priv_elevated",
      "holds": true,
      "n_assignments_checked": 9216,
      "n_that_can_assign_the_field": 0,
      "offenders": [],
      "pair": "filesystem+time",
      "route": "A-structural",
      "what_it_checks": "no rule emitted by schema_to_rules mentions the field, at any of the 96x96 trust assignments"
    },
    {
      "hazard_field": "secret_exfiltrated",
      "holds": true,
      "n_assignments_checked": 9216,
      "n_that_can_assign_the_field": 0,
      "offenders": [],
      "pair": "filesystem+time",
      "route": "A-structural",
      "what_it_checks": "no rule emitted by schema_to_rules mentions the field, at any of the 96x96 trust assignments"
    },
    {
      "hazard_field": "priv_elevated",
      "holds": true,
      "n_assignments_checked": 9216,
      "n_that_can_assign_the_field": 0,
      "offenders": [],
      "pair": "git+memory",
      "route": "A-structural",
      "what_it_checks": "no rule emitted by schema_to_rules mentions the field, at any of the 96x96 trust assignments"
    },
    {
      "hazard_field": "secret_exfiltrated",
      "holds": true,
      "n_assignments_checked": 9216,
      "n_that_can_assign_the_field": 0,
      "offenders": [],
      "pair": "git+memory",
      "route": "A-structural",
      "what_it_checks": "no rule emitted by schema_to_rules mentions the field, at any of the 96x96 trust assignments"
    },
    {
      "hazard_field": "priv_elevated",
      "holds": true,
      "n_assignments_checked": 9216,
      "n_that_can_assign_the_field": 0,
      "offenders": [],
      "pair": "git+sequentialthinking",
      "route": "A-structural",
      "what_it_checks": "no rule emitted by schema_to_rules mentions the field, at any of the 96x96 trust assignments"
    },
    {
      "hazard_field": "secret_exfiltrated",
      "holds": true,
      "n_assignments_checked": 9216,
      "n_that_can_assign_the_field": 0,
      "offenders": [],
      "pair": "git+sequentialthinking",
      "route": "A-structural",
      "what_it_checks": "no rule emitted by schema_to_rules mentions the field, at any of the 96x96 trust assignments"
    },
    {
      "hazard_field": "priv_elevated",
      "holds": true,
      "n_assignments_checked": 9216,
      "n_that_can_assign_the_field": 0,
      "offenders": [],
      "pair": "git+sqlite",
      "route": "A-structural",
      "what_it_checks": "no rule emitted by schema_to_rules mentions the field, at any of the 96x96 trust assignments"
    },
    {
      "hazard_field": "secret_exfiltrated",
      "holds": true,
      "n_assignments_checked": 9216,
      "n_that_can_assign_the_field": 0,
      "offenders": [],
      "pair": "git+sqlite",
      "route": "A-structural",
      "what_it_checks": "no rule emitted by schema_to_rules mentions the field, at any of the 96x96 trust assignments"
    },
    {
      "hazard_field": "priv_elevated",
      "holds": true,
      "n_assignments_checked": 9216,
      "n_that_can_assign_the_field": 0,
      "offenders": [],
      "pair": "git+time",
      "route": "A-structural",
      "what_it_checks": "no rule emitted by schema_to_rules mentions the field, at any of the 96x96 trust assignments"
    },
    {
      "hazard_field": "secret_exfiltrated",
      "holds": true,
      "n_assignments_checked": 9216,
      "n_that_can_assign_the_field": 0,
      "offenders": [],
      "pair": "git+time",
      "route": "A-structural",
      "what_it_checks": "no rule emitted by schema_to_rules mentions the field, at any of the 96x96 trust assignments"
    },
    {
      "hazard_field": "priv_elevated",
      "holds": true,
      "n_assignments_checked": 9216,
      "n_that_can_assign_the_field": 0,
      "offenders": [],
      "pair": "memory+sequentialthinking",
      "route": "A-structural",
      "what_it_checks": "no rule emitted by schema_to_rules mentions the field, at any of the 96x96 trust assignments"
    },
    {
      "hazard_field": "secret_exfiltrated",
      "holds": true,
      "n_assignments_checked": 9216,
      "n_that_can_assign_the_field": 0,
      "offenders": [],
      "pair": "memory+sequentialthinking",
      "route": "A-structural",
      "what_it_checks": "no rule emitted by schema_to_rules mentions the field, at any of the 96x96 trust assignments"
    },
    {
      "hazard_field": "priv_elevated",
      "holds": true,
      "n_assignments_checked": 9216,
      "n_that_can_assign_the_field": 0,
      "offenders": [],
      "pair": "memory+sqlite",
      "route": "A-structural",
      "what_it_checks": "no rule emitted by schema_to_rules mentions the field, at any of the 96x96 trust assignments"
    },
    {
      "hazard_field": "secret_exfiltrated",
      "holds": true,
      "n_assignments_checked": 9216,
      "n_that_can_assign_the_field": 0,
      "offenders": [],
      "pair": "memory+sqlite",
      "route": "A-structural",
      "what_it_checks": "no rule emitted by schema_to_rules mentions the field, at any of the 96x96 trust assignments"
    },
    {
      "hazard_field": "priv_elevated",
      "holds": true,
      "n_assignments_checked": 9216,
      "n_that_can_assign_the_field": 0,
      "offenders": [],
      "pair": "memory+time",
      "route": "A-structural",
      "what_it_checks": "no rule emitted by schema_to_rules mentions the field, at any of the 96x96 trust assignments"
    },
    {
      "hazard_field": "secret_exfiltrated",
      "holds": true,
      "n_assignments_checked": 9216,
      "n_that_can_assign_the_field": 0,
      "offenders": [],
      "pair": "memory+time",
      "route": "A-structural",
      "what_it_checks": "no rule emitted by schema_to_rules mentions the field, at any of the 96x96 trust assignments"
    },
    {
      "hazard_field": "irreversible_change",
      "holds": true,
      "n_assignments_checked": 9216,
      "n_that_can_assign_the_field": 0,
      "offenders": [],
      "pair": "sequentialthinking+sqlite",
      "route": "A-structural",
      "what_it_checks": "no rule emitted by schema_to_rules mentions the field, at any of the 96x96 trust assignments"
    },
    {
      "hazard_field": "priv_elevated",
      "holds": true,
      "n_assignments_checked": 9216,
      "n_that_can_assign_the_field": 0,
      "offenders": [],
      "pair": "sequentialthinking+sqlite",
      "route": "A-structural",
      "what_it_checks": "no rule emitted by schema_to_rules mentions the field, at any of the 96x96 trust assignments"
    },
    {
      "hazard_field": "replay_amplified",
      "holds": true,
      "n_assignments_checked": 9216,
      "n_that_can_assign_the_field": 0,
      "offenders": [],
      "pair": "sequentialthinking+sqlite",
      "route": "A-structural",
      "what_it_checks": "no rule emitted by schema_to_rules mentions the field, at any of the 96x96 trust assignments"
    },
    {
      "hazard_field": "secret_exfiltrated",
      "holds": true,
      "n_assignments_checked": 9216,
      "n_that_can_assign_the_field": 0,
      "offenders": [],
      "pair": "sequentialthinking+sqlite",
      "route": "A-structural",
      "what_it_checks": "no rule emitted by schema_to_rules mentions the field, at any of the 96x96 trust assignments"
    },
    {
      "hazard_field": "irreversible_change",
      "holds": true,
      "n_assignments_checked": 9216,
      "n_that_can_assign_the_field": 0,
      "offenders": [],
      "pair": "sequentialthinking+time",
      "route": "A-structural",
      "what_it_checks": "no rule emitted by schema_to_rules mentions the field, at any of the 96x96 trust assignments"
    },
    {
      "hazard_field": "priv_elevated",
      "holds": true,
      "n_assignments_checked": 9216,
      "n_that_can_assign_the_field": 0,
      "offenders": [],
      "pair": "sequentialthinking+time",
      "route": "A-structural",
      "what_it_checks": "no rule emitted by schema_to_rules mentions the field, at any of the 96x96 trust assignments"
    },
    {
      "hazard_field": "replay_amplified",
      "holds": true,
      "n_assignments_checked": 9216,
      "n_that_can_assign_the_field": 0,
      "offenders": [],
      "pair": "sequentialthinking+time",
      "route": "A-structural",
      "what_it_checks": "no rule emitted by schema_to_rules mentions the field, at any of the 96x96 trust assignments"
    },
    {
      "hazard_field": "secret_exfiltrated",
      "holds": true,
      "n_assignments_checked": 9216,
      "n_that_can_assign_the_field": 0,
      "offenders": [],
      "pair": "sequentialthinking+time",
      "route": "A-structural",
      "what_it_checks": "no rule emitted by schema_to_rules mentions the field, at any of the 96x96 trust assignments"
    },
    {
      "hazard_field": "unauthorized_write",
      "holds": true,
      "n_assignments_checked": 9216,
      "n_that_can_assign_the_field": 0,
      "offenders": [],
      "pair": "sequentialthinking+time",
      "route": "A-structural",
      "what_it_checks": "no rule emitted by schema_to_rules mentions the field, at any of the 96x96 trust assignments"
    },
    {
      "hazard_field": "irreversible_change",
      "holds": true,
      "n_assignments_checked": 9216,
      "n_that_can_assign_the_field": 0,
      "offenders": [],
      "pair": "sqlite+time",
      "route": "A-structural",
      "what_it_checks": "no rule emitted by schema_to_rules mentions the field, at any of the 96x96 trust assignments"
    },
    {
      "hazard_field": "priv_elevated",
      "holds": true,
      "n_assignments_checked": 9216,
      "n_that_can_assign_the_field": 0,
      "offenders": [],
      "pair": "sqlite+time",
      "route": "A-structural",
      "what_it_checks": "no rule emitted by schema_to_rules mentions the field, at any of the 96x96 trust assignments"
    },
    {
      "hazard_field": "replay_amplified",
      "holds": true,
      "n_assignments_checked": 9216,
      "n_that_can_assign_the_field": 0,
      "offenders": [],
      "pair": "sqlite+time",
      "route": "A-structural",
      "what_it_checks": "no rule emitted by schema_to_rules mentions the field, at any of the 96x96 trust assignments"
    },
    {
      "hazard_field": "secret_exfiltrated",
      "holds": true,
      "n_assignments_checked": 9216,
      "n_that_can_assign_the_field": 0,
      "offenders": [],
      "pair": "sqlite+time",
      "route": "A-structural",
      "what_it_checks": "no rule emitted by schema_to_rules mentions the field, at any of the 96x96 trust assignments"
    }
  ],
  "route_b_semantic": [
    {
      "engine": "z3 BMC base + k-induction over simple paths (symbolic_absence)",
      "failures": [],
      "full_factorial": true,
      "hazard_field": "irreversible_change",
      "holds": true,
      "n_assignments_checked": 9216,
      "n_complete": 9216,
      "n_holds": 9216,
      "pair": "everything+fetch",
      "property": "PROP_NO_IRREVERSIBLE_CHANGE",
      "route": "B-semantic",
      "what_it_checks": "the hazard is unreachable AND the procedure terminated completely, at every assignment checked"
    },
    {
      "engine": "z3 BMC base + k-induction over simple paths (symbolic_absence)",
      "failures": [],
      "full_factorial": true,
      "hazard_field": "priv_elevated",
      "holds": true,
      "n_assignments_checked": 9216,
      "n_complete": 9216,
      "n_holds": 9216,
      "pair": "everything+fetch",
      "property": "PROP_NO_PRIV_COMPOSITION",
      "route": "B-semantic",
      "what_it_checks": "the hazard is unreachable AND the procedure terminated completely, at every assignment checked"
    },
    {
      "engine": "z3 BMC base + k-induction over simple paths (symbolic_absence)",
      "failures": [],
      "full_factorial": true,
      "hazard_field": "replay_amplified",
      "holds": true,
      "n_assignments_checked": 9216,
      "n_complete": 9216,
      "n_holds": 9216,
      "pair": "fetch+sequentialthinking",
      "property": "PROP_NO_REPLAY_AMPLIFICATION",
      "route": "B-semantic",
      "what_it_checks": "the hazard is unreachable AND the procedure terminated completely, at every assignment checked"
    },
    {
      "engine": "z3 BMC base + k-induction over simple paths (symbolic_absence)",
      "failures": [],
      "full_factorial": true,
      "hazard_field": "unauthorized_write",
      "holds": true,
      "n_assignments_checked": 9216,
      "n_complete": 9216,
      "n_holds": 9216,
      "pair": "fetch+sequentialthinking",
      "property": "PROP_NO_UNAUTH_WRITE",
      "route": "B-semantic",
      "what_it_checks": "the hazard is unreachable AND the procedure terminated completely, at every assignment checked"
    },
    {
      "engine": "z3 BMC base + k-induction over simple paths (symbolic_absence)",
      "failures": [],
      "full_factorial": true,
      "hazard_field": "secret_exfiltrated",
      "holds": true,
      "n_assignments_checked": 9216,
      "n_complete": 9216,
      "n_holds": 9216,
      "pair": "filesystem+git",
      "property": "PROP_NO_SECRET_TO_EGRESS",
      "route": "B-semantic",
      "what_it_checks": "the hazard is unreachable AND the procedure terminated completely, at every assignment checked"
    }
  ],
  "schema": "wrfl-mcp-impossibility-v1",
  "servers": [
    "everything",
    "fetch",
    "filesystem",
    "git",
    "memory",
    "sequentialthinking",
    "sqlite",
    "time"
  ],
  "shape_absence_is_not_impossibility": "'No capability shape' does NOT imply impossible, and this repo's own artifact refutes it: memory+filesystem has no shape and a real unauthorized_write finding, because no shape covers that field. Impossibility is decided per hazard field from the derived tag map, never from shape absence. Falsification ledger D15.",
  "tag_map_comparison": {
    "n_rows": 64,
    "n_rows_where_structural_is_UNSOUND": 0,
    "n_rows_where_structural_overstates": 31,
    "reading": "31 of 64 lattice rows list a hazard field the structural map cannot actually drive to true. 0 rows are UNSOUND (the semantic route reaches a field the structural route missed) \u2014 that count must be ZERO or the structural map is not an over-approximation and every IMPOSSIBLE verdict built on it is suspect.",
    "rows_where_structural_is_unsound": [],
    "rows_where_structural_overstates": [
      {
        "fields_structural_overstates": [
          "irreversible_change"
        ],
        "semantic_says": [],
        "structural_says": [
          "irreversible_change"
        ],
        "tagset": "DESTRUCTIVE"
      },
      {
        "fields_structural_overstates": [
          "irreversible_change",
          "priv_elevated"
        ],
        "semantic_says": [],
        "structural_says": [
          "irreversible_change",
          "priv_elevated"
        ],
        "tagset": "DESTRUCTIVE,GRANTS"
      },
      {
        "fields_structural_overstates": [
          "irreversible_change",
          "priv_elevated",
          "secret_exfiltrated"
        ],
        "semantic_says": [],
        "structural_says": [
          "irreversible_change",
          "priv_elevated",
          "secret_exfiltrated"
        ],
        "tagset": "DESTRUCTIVE,GRANTS,NET_SINK"
      },
      {
        "fields_structural_overstates": [
          "irreversible_change",
          "priv_elevated",
          "replay_amplified",
          "secret_exfiltrated"
        ],
        "semantic_says": [],
        "structural_says": [
          "irreversible_change",
          "priv_elevated",
          "replay_amplified",
          "secret_exfiltrated"
        ],
        "tagset": "DESTRUCTIVE,GRANTS,NET_SINK,NON_IDEMPOTENT"
      },
      {
        "fields_structural_overstates": [
          "irreversible_change",
          "priv_elevated",
          "replay_amplified",
          "secret_exfiltrated",
          "unauthorized_write"
        ],
        "semantic_says": [],
        "structural_says": [
          "irreversible_change",
          "priv_elevated",
          "replay_amplified",
          "secret_exfiltrated",
          "unauthorized_write"
        ],
        "tagset": "DESTRUCTIVE,GRANTS,NET_SINK,NON_IDEMPOTENT,WRITES"
      },
      {
        "fields_structural_overstates": [
          "irreversible_change",
          "priv_elevated",
          "secret_exfiltrated",
          "unauthorized_write"
        ],
        "semantic_says": [],
        "structural_says": [
          "irreversible_change",
          "priv_elevated",
          "secret_exfiltrated",
          "unauthorized_write"
        ],
        "tagset": "DESTRUCTIVE,GRANTS,NET_SINK,WRITES"
      },
      {
        "fields_structural_overstates": [
          "irreversible_change",
          "priv_elevated",
          "replay_amplified"
        ],
        "semantic_says": [],
        "structural_says": [
          "irreversible_change",
          "priv_elevated",
          "replay_amplified"
        ],
        "tagset": "DESTRUCTIVE,GRANTS,NON_IDEMPOTENT"
      },
      {
        "fields_structural_overstates": [
          "irreversible_change",
          "priv_elevated",
          "replay_amplified",
          "unauthorized_write"
        ],
        "semantic_says": [],
        "structural_says": [
          "irreversible_change",
          "priv_elevated",
          "replay_amplified",
          "unauthorized_write"
        ],
        "tagset": "DESTRUCTIVE,GRANTS,NON_IDEMPOTENT,WRITES"
      },
      {
        "fields_structural_overstates": [
          "irreversible_change",
          "priv_elevated",
          "unauthorized_write"
        ],
        "semantic_says": [],
        "structural_says": [
          "irreversible_change",
          "priv_elevated",
          "unauthorized_write"
        ],
        "tagset": "DESTRUCTIVE,GRANTS,WRITES"
      },
      {
        "fields_structural_overstates": [
          "irreversible_change",
          "secret_exfiltrated"
        ],
        "semantic_says": [],
        "structural_says": [
          "irreversible_change",
          "secret_exfiltrated"
        ],
        "tagset": "DESTRUCTIVE,NET_SINK"
      },
      {
        "fields_structural_overstates": [
          "irreversible_change",
          "replay_amplified",
          "secret_exfiltrated"
        ],
        "semantic_says": [],
        "structural_says": [
          "irreversible_change",
          "replay_amplified",
          "secret_exfiltrated"
        ],
        "tagset": "DESTRUCTIVE,NET_SINK,NON_IDEMPOTENT"
      },
      {
        "fields_structural_overstates": [
          "irreversible_change",
          "replay_amplified",
          "secret_exfiltrated",
          "unauthorized_write"
        ],
        "semantic_says": [],
        "structural_says": [
          "irreversible_change",
          "replay_amplified",
          "secret_exfiltrated",
          "unauthorized_write"
        ],
        "tagset": "DESTRUCTIVE,NET_SINK,NON_IDEMPOTENT,WRITES"
      },
      {
        "fields_structural_overstates": [
          "irreversible_change",
          "secret_exfiltrated",
          "unauthorized_write"
        ],
        "semantic_says": [],
        "structural_says": [
          "irreversible_change",
          "secret_exfiltrated",
          "unauthorized_write"
        ],
        "tagset": "DESTRUCTIVE,NET_SINK,WRITES"
      },
      {
        "fields_structural_overstates": [
          "irreversible_change",
          "replay_amplified"
        ],
        "semantic_says": [],
        "structural_says": [
          "irreversible_change",
          "replay_amplified"
        ],
        "tagset": "DESTRUCTIVE,NON_IDEMPOTENT"
      },
      {
        "fields_structural_overstates": [
          "irreversible_change",
          "replay_amplified",
          "unauthorized_write"
        ],
        "semantic_says": [],
        "structural_says": [
          "irreversible_change",
          "replay_amplified",
          "unauthorized_write"
        ],
        "tagset": "DESTRUCTIVE,NON_IDEMPOTENT,WRITES"
      },
      {
        "fields_structural_overstates": [
          "irreversible_change",
          "unauthorized_write"
        ],
        "semantic_says": [],
        "structural_says": [
          "irreversible_change",
          "unauthorized_write"
        ],
        "tagset": "DESTRUCTIVE,WRITES"
      },
      {
        "fields_structural_overstates": [
          "priv_elevated"
        ],
        "semantic_says": [],
        "structural_says": [
          "priv_elevated"
        ],
        "tagset": "GRANTS"
      },
      {
        "fields_structural_overstates": [
          "priv_elevated",
          "secret_exfiltrated"
        ],
        "semantic_says": [],
        "structural_says": [
          "priv_elevated",
          "secret_exfiltrated"
        ],
        "tagset": "GRANTS,NET_SINK"
      },
      {
        "fields_structural_overstates": [
          "priv_elevated",
          "replay_amplified",
          "secret_exfiltrated"
        ],
        "semantic_says": [],
        "structural_says": [
          "priv_elevated",
          "replay_amplified",
          "secret_exfiltrated"
        ],
        "tagset": "GRANTS,NET_SINK,NON_IDEMPOTENT"
      },
      {
        "fields_structural_overstates": [
          "priv_elevated",
          "replay_amplified",
          "secret_exfiltrated",
          "unauthorized_write"
        ],
        "semantic_says": [],
        "structural_says": [
          "priv_elevated",
          "replay_amplified",
          "secret_exfiltrated",
          "unauthorized_write"
        ],
        "tagset": "GRANTS,NET_SINK,NON_IDEMPOTENT,WRITES"
      },
      {
        "fields_structural_overstates": [
          "priv_elevated",
          "secret_exfiltrated",
          "unauthorized_write"
        ],
        "semantic_says": [],
        "structural_says": [
          "priv_elevated",
          "secret_exfiltrated",
          "unauthorized_write"
        ],
        "tagset": "GRANTS,NET_SINK,WRITES"
      },
      {
        "fields_structural_overstates": [
          "priv_elevated",
          "replay_amplified"
        ],
        "semantic_says": [],
        "structural_says": [
          "priv_elevated",
          "replay_amplified"
        ],
        "tagset": "GRANTS,NON_IDEMPOTENT"
      },
      {
        "fields_structural_overstates": [
          "priv_elevated",
          "replay_amplified",
          "unauthorized_write"
        ],
        "semantic_says": [],
        "structural_says": [
          "priv_elevated",
          "replay_amplified",
          "unauthorized_write"
        ],
        "tagset": "GRANTS,NON_IDEMPOTENT,WRITES"
      },
      {
        "fields_structural_overstates": [
          "priv_elevated",
          "unauthorized_write"
        ],
        "semantic_says": [],
        "structural_says": [
          "priv_elevated",
          "unauthorized_write"
        ],
        "tagset": "GRANTS,WRITES"
      },
      {
        "fields_structural_overstates": [
          "secret_exfiltrated"
        ],
        "semantic_says": [],
        "structural_says": [
          "secret_exfiltrated"
        ],
        "tagset": "NET_SINK"
      },
      {
        "fields_structural_overstates": [
          "replay_amplified",
          "secret_exfiltrated"
        ],
        "semantic_says": [],
        "structural_says": [
          "replay_amplified",
          "secret_exfiltrated"
        ],
        "tagset": "NET_SINK,NON_IDEMPOTENT"
      },
      {
        "fields_structural_overstates": [
          "replay_amplified",
          "secret_exfiltrated",
          "unauthorized_write"
        ],
        "semantic_says": [],
        "structural_says": [
          "replay_amplified",
          "secret_exfiltrated",
          "unauthorized_write"
        ],
        "tagset": "NET_SINK,NON_IDEMPOTENT,WRITES"
      },
      {
        "fields_structural_overstates": [
          "secret_exfiltrated",
          "unauthorized_write"
        ],
        "semantic_says": [],
        "structural_says": [
          "secret_exfiltrated",
          "unauthorized_write"
        ],
        "tagset": "NET_SINK,WRITES"
      },
      {
        "fields_structural_overstates": [
          "replay_amplified"
        ],
        "semantic_says": [],
        "structural_says": [
          "replay_amplified"
        ],
        "tagset": "NON_IDEMPOTENT"
      },
      {
        "fields_structural_overstates": [
          "replay_amplified",
          "unauthorized_write"
        ],
        "semantic_says": [],
        "structural_says": [
          "replay_amplified",
          "unauthorized_write"
        ],
        "tagset": "NON_IDEMPOTENT,WRITES"
      },
      {
        "fields_structural_overstates": [
          "unauthorized_write"
        ],
        "semantic_says": [],
        "structural_says": [
          "unauthorized_write"
        ],
        "tagset": "WRITES"
      }
    ],
    "structural_is_a_sound_over_approximation": true
  },
  "theorem": "For a pair (A,B) and hazard field F: if the tags NECESSARY for F (derived, not declared) are absent from both servers' observed tool tags, then no rule emitted by ingest.schema_to_rules can assign F under ANY of the 96 trust assignments per server; init sets F False and the step relation frames unmentioned fields; therefore F is unreachable for ALL trust models.",
  "tightening_effect_on_verdicts": {
    "n_impossible_after": 62,
    "n_impossible_before": 62,
    "n_slots": 140,
    "n_slots_that_change_verdict": 0,
    "reading": "Re-deciding all 140 slots under the exact semantic map changes 0 of them. The tightening is a CORRECTNESS improvement to the lemma's statement, not a result-moving one, and it is reported as exactly that.",
    "slots_that_change_verdict": [],
    "why_it_moves_nothing_here": "The only tag the tightening adds is READS, and every server in this corpus except sequentialthinking carries it \u2014 so no pair UNION lacks READS and the new conjunct is never the binding constraint. On a corpus containing two or more READS-less servers it would bite. That is a property of this corpus, not of the lemma."
  },
  "two_independent_routes": "Route A checks the MECHANISM (no generated rule mentions the field) exhaustively over the full 96x96 factorial. Route B checks the CONSEQUENCE (z3 k-induction over simple paths reports unreachable AND complete). They share no code on the deciding path."
}
