# Stale claims, cut entries, and everything that did not survive

<!-- GENERATED FILE — DO NOT EDIT. Rendered by `scripts/build_top_jewels.py`. -->
<!-- SUPERSEDED-FACTS-OK: LEAN-KERNEL-CHECKED N-MACHINE-CHECKED — this document QUOTES retracted and superseded strings in order to name them as retracted. Every occurrence below is a mention, never a use. -->

> **This document is why [`VC_PITCH.md`](VC_PITCH.md) can be read at face value.** The pitch is confident because everything that could not survive a confident statement is here instead, with its reason and its deciding register. A claim that was hedged into a pitch would have contaminated it; a claim recorded here does not.

> **Blocking rows come first.** A blocking row must not be quoted to a third party today. Everything after is a correction, a cut, or an unselected entry.

## Gate runs behind this document

| Command | Exit | Output |
|---|---|---|
| `python3 scripts/build_crown_jewels.py --check` | `0` | `crown-jewels --check: 40/40 jewels re-derive == artifact (35 BULLETPROOF, 0 with missing evidence); coverage 157/157 bindings compared, 0 artifact(s) absent; 0 drift(s)` |  <!-- PD-OK: pasted gate output -->
| `python3 scripts/build_evidence_standing.py --check` | `0` | `evidence-standing: 25/25 STANDING; 106/106 bindings compared, 0 absent; 0 drift(s); 0 unresolved reference(s)` |  <!-- PD-OK: pasted gate output -->
| `python3 scripts/check_closure_root_binding.py` | `1` | `closure-root binding: live_root=a389476538f1451e…  published=2f3d27c92d8d530f…  n_leaves=385/385` |  <!-- PD-OK: pasted gate output -->

## 1. BLOCKING — do not quote these today

### S1 · The Merkle closure root is `2f3d27c9…`  <!-- PD-OK: row title quotes the claim being adjudicated -->

- **What is true** — The live tree does not fold to it. `python3 scripts/check_closure_root_binding.py` prints `live_root=a389476538f1451e… published=2f3d27c92d8d530f… n_leaves=385/385` and FAILS. The leaf COUNT still matches exactly; only the fold differs. Pinned by commit 49a6be7 on 2026-07-17; the evidence set has moved since.  <!-- PD-OK: quotes the measured value that refutes the claim -->
- **Still live at** — **73 tracked files** cite the literal, DERIVED at build time by `git grep -lI 2f3d27c9` and excluding the documents this generator writes (they quote it in order to withdraw it). Largest holders: `dataroom/VC_DILIGENCE_MEMO.md`, `MASTER_DOSSIER.md`, `ARCHITECTURE.md`, `README.md`, `provenance/claims.toml:115`.  <!-- PD-OK: counts of stale SITES, not portfolio counts -->
- **What to say instead** — Do not quote the root to a third party. Say: 385 leaves, internally consistent with the certificate, root re-pin pending. Re-pinning is an OWNER decision.  <!-- PD-OK: the replacement wording, quoted -->
- **Source** — CLAIM_TRUST.md `B.closure.root` (CONTRADICTED, left red deliberately 2026-08-15)  <!-- PD-OK: pasted command output -->

### S3 · "66/66 lead-with numbers re-derived (55 BULLETPROOF)"  <!-- PD-OK: row title quotes the claim being adjudicated -->

- **What is true** — `artifacts/claim_certainty.json` says **54**. Commit 668ef86 (2026-08-15) deliberately downgraded the Lean claim's tier from `lean-checked` to `regex-credited` and the total fell 55→54; the generator's literal was never propagated, so `build_crown_jewels.py --check` sat RED for two days. FIXED this pass at the generator; `dataroom/CROWN_JEWELS.md` regenerated.  <!-- PD-OK: quotes the measured value that refutes the claim -->
- **Still live at** — **PROPAGATED THIS PASS to 0 live assertions.** It had been live at 25 sites across 11 documents (README.md 5, OWNER_BRIEFING.md 3, ARCHITECTURE.md 2, dataroom/VC_DILIGENCE_MEMO.md 2, THE_PITCH.md, BRAG_SHEET.md, IP_READINESS.md, MASTER_INVENTION_DISCLOSURE.md, ASSET_INVENTORY_CURRENT.md, COMPLETE_ASSET_DOSSIER.md 2, and the two generated omnibuses). DERIVED now: the string survives in **4** tracked files — `COMMERCIAL_JEWELS_2026-08-27.md`, `dataroom/EVIDENCE_STANDING.md`, `scripts/build_evidence_standing.py`, `scripts/check_prose_drift.py` — and every one is a MENTION (the stale-number record, its generator, and the drift guard's comment explaining this very correction). Zero assertions remain.  <!-- PD-OK: counts of stale SITES, not portfolio counts -->
- **What to say instead** — 54 BULLETPROOF of 66.  <!-- PD-OK: the replacement wording, quoted -->
- **Source** — `python3 scripts/build_crown_jewels.py --check` before the fix: `DRIFT: invariant 'Claim-certainty ledger': got [66, 54] != [66, 55]`  <!-- PD-OK: pasted command output -->

### S4 · "there is a **live public break-it portal** running the real verifier"  <!-- PD-OK: row title quotes the claim being adjudicated -->

- **What is true** — `https://nickharris808--wrfl-breakit-portal-fastapi-app.modal.run` returns **HTTP 404**. `artifacts/portal_live.json` still asserts `health_ok: true`, `all_pass: true`, `verifier_is_real: true` and a 0.633 s median round-trip. That artifact is NOT a closure leaf, so nothing gated it.  <!-- PD-OK: quotes the measured value that refutes the claim -->
- **Still live at** — **6 tracked files**, derived at build time: `MASTER_DOSSIER.md`, `README.md`, `artifacts/portal_live.json`, `dataroom/BRAG_SHEET.md`, `dataroom/THE_PITCH.md`, `modal_app.py`.  <!-- PD-OK: counts of stale SITES, not portfolio counts -->
- **What to say instead** — Nothing, until it is redeployed. The live public surface that DOES answer is <https://nickharris808.github.io/verification-docs/> (HTTP 200) and it is cited in none of the pitch documents.  <!-- PD-OK: the replacement wording, quoted -->
- **Source** — `curl -s -o /dev/null -w '%{http_code}' …modal.run` → 404, checked 2026-08-17  <!-- PD-OK: pasted command output -->

### S7 · (hygiene, not a claim) The repository is clean of local paths  <!-- PD-OK: row title quotes the claim being adjudicated -->

- **What is true** — **21 tracked files contain the operator's home-directory prefix**, including `artifacts/backends/hostapd_shadow_release_v2_20260716/release_receipt.json`, `artifacts/backends/status.json`, `artifacts/formal_backends/status.json` and `SPRINT_PLAN.md`. Any buyer receiving this tree receives the owner's home directory and username. **The account segment is redacted here as `/Users/<redacted>`, because this row exists to disclose THAT a machine path leaked and how it was found, and publishing the account name in order to prove it once leaked would repeat the leak on a served page.**  <!-- PD-OK: quotes the measured value that refutes the claim -->
- **Still live at** — `git grep -lI "/Users/<redacted>"` → **25 tracked files**, of which **6 are Merkle closure leaves** — `telecom_formal/reports/improvements/frer_latent_detect.json`, `telecom_formal/reports/improvements/ptp_bounded_holdover.json`, `telecom_formal/reports/improvements/tas_adaptive_guard.json`, `telecom_formal/reports/tsn/frer_elimination.json`, `telecom_formal/reports/tsn/ptp_grandmaster_failover.json`, `telecom_formal/reports/tsn/tas_guardband.json` — so editing those is a RE-PIN, not a cleanup. Both counts are derived at build time from the REAL prefix and exclude the documents this generator writes; only the printed form is redacted, so the measurement is unchanged.  <!-- PD-OK: counts of stale SITES, not portfolio counts -->
- **What to say instead** — Strip before any data-room hand-off. **Several are closure leaves, so editing them moves the Merkle root** — this must be done as part of a deliberate re-pin, not as a cleanup. Matches `portfolio-control` `PB-NEG-001` [OPEN].  <!-- PD-OK: the replacement wording, quoted -->
- **Source** — `git grep -lI "/Users/<redacted>"` (run against the real prefix), run 2026-08-17  <!-- PD-OK: pasted command output -->

### S9 · "489/489 adversarial weakenings refuted" is live at 120 sites, and the register states "this count must not increase"  <!-- PD-OK: row title quotes the claim being adjudicated -->

- **What is true** — **It increased to 122, and this pass caused both.** They are mentions, not assertions — one is the withdrawal banner added to `dataroom/PITCH_RANKED_VERIFIED.md:10`, which quotes the string in order to retract it; the other is `dataroom/TOP_N_CROWN_JEWELS.md:257`, where jewel 40's scope text (imported verbatim from the register, where it argues the 489 is the WEAKER claim) carries it. Neither is a new use. It is recorded anyway, because a register whose count only moves when someone volunteers the increase is decoration. `scripts/build_top_jewels.py`, `dataroom/STALE_CLAIMS.md` and `tests/test_top_jewels_is_a_subset.py` WERE added to `build_evidence_standing.RETRACTION_MACHINERY` — those quote every retracted string by construction, and without the exclusion the count self-inflates: publishing the register raises the count, which restates the register.  <!-- PD-OK: quotes the measured value that refutes the claim -->
- **Still live at** — `dataroom/EVIDENCE_STANDING.md` EV-R01: **124 occurrences**, re-derived from `build_evidence_standing.kill_list_status()`. Largest holders: `MASTER_DOSSIER.md` (26), `README.md` (13), `UNIFIED_DILIGENCE_DOSSIER.md` (13), `ARCHITECTURE.md` (5), `dataroom/VC_DILIGENCE_MEMO.md` (5).  <!-- PD-OK: counts of stale SITES, not portfolio counts -->
- **What to say instead** — The honest headline is **16/16 planted-broken controls refused, 0 false-certify, across 489 screenings** — 473 of the 489 are monotone lattice weakenings over a register CLOSED under weakening, so zero survivors there is guaranteed by construction rather than discovered. Converging the remaining 122 is a separate mechanical job and each site needs its own correction: several are dated records where a blanket find-and-replace would falsify history rather than supersede it (`EVIDENCE_STANDING.md` EV-U06 says exactly this).  <!-- PD-OK: the replacement wording, quoted -->
- **Source** — `python3 scripts/build_evidence_standing.py` — EV-R01 `STILL LIVE AT` went 120 → 122; per-file tally re-derived from `build_evidence_standing.kill_list_status()['EV-R01']`  <!-- PD-OK: pasted command output -->

### S10 · "The real-radio hostapd corpus" / "real 802.11 infrastructure" (sidecar rank 26)  <!-- PD-OK: row title quotes the claim being adjudicated -->

- **What is true** — mac80211_hwsim is a Linux kernel RF SIMULATOR, the hostapd version is recorded nowhere in this repository, and the run was on a cloud droplet. Worse: the documented reproduce command's no-credential path OVERWRITES artifacts/backends/hostapd_live_run.json with a stub carrying all_pass: true, executed: false (scripts/hostapd_live.sh:33-45) -- an exit-0 stub that reads green. Found S02, 2026-09-02, by reading the script; the command was refused, not run.  <!-- PD-OK: quotes the measured value that refutes the claim -->
- **Still live at** — dataroom/VC_TOP_40.md rank 26 (title unchanged, scope corrected); scripts/hostapd_live.sh:33-45  <!-- PD-OK: counts of stale SITES, not portfolio counts -->
- **What to say instead** — An unmodified hostapd Fast-Transition stack (version unrecorded) under mac80211_hwsim on a droplet, 2026-07-16, guard fired as expected, 0.89x roaming negative kept. Not real radio, not over-the-air. Do not run the documented command until the skip stub is fixed.  <!-- PD-OK: the replacement wording, quoted -->
- **Source** — python3 tools/hostapd/smd_gate_hook.py (offline surrogate) -> 3/3 scenarios OK, 2026-09-02; scripts/hostapd_live.sh read  <!-- PD-OK: pasted command output -->

### S14 · provenance-lint "runs against repositories nobody here owns" (sidecar rank 23; crown jewel 39)  <!-- PD-OK: row title quotes the claim being adjudicated -->

- **What is true** — The committed verdict covers THIS repository only (artifacts/backends/provenance_lint.json, honest_scope: 'over this repository'); no run against a foreign repository is receipted anywhere in the tree (git grep over provenance/*.py: 0 foreign targets). It CAN be pointed elsewhere; that is a capability, not a result. S02, 2026-09-02.  <!-- PD-OK: quotes the measured value that refutes the claim -->
- **Still live at** — dataroom/top40.json rank 23 scope (corrected); scripts/build_crown_jewels.py jewel 39 (corrected)  <!-- PD-OK: counts of stale SITES, not portfolio counts -->
- **What to say instead** — A stdlib-only linter, runnable anywhere; its only receipted run is over this repository.  <!-- PD-OK: the replacement wording, quoted -->
- **Source** — git grep -nE 'repo|path' -- provenance/*.py; artifacts/backends/provenance_lint.json honest_scope  <!-- PD-OK: pasted command output -->

### S15 · `make prereg`: "a prediction's SHA-256 is committed to git before the benchmark; overfitting to test data is provably excluded"  <!-- PD-OK: row title quotes the claim being adjudicated -->

- **What is true** — The seal (artifacts/prereg/preregistration_v37.json, sealed_at_commit f904b6a, first commit 8f8f63e on 2026-07-07) post-dates the benchmark output artifacts/referee_stats_v37.json, which entered git in 4383bd0 on 2026-07-01 together with the predictions. The seal proves tamper-evidence since 07-07, not temporal priority. No asset in this tree carries a seal that predates its run (S02 census, 2026-09-02, git log --diff-filter=A over 27 bar/result pairs: every bar shares a first commit with its result).  <!-- PD-OK: quotes the measured value that refutes the claim -->
- **Still live at** — scripts/check_prereg.py contract string; artifacts/preregistration.json 'honesty' field is the careful one  <!-- PD-OK: counts of stale SITES, not portfolio counts -->
- **What to say instead** — The decision rules are sealed against tampering since 2026-07-07; they are the gates the benchmark code already enforced. Do not say pre-registered.  <!-- PD-OK: the replacement wording, quoted -->
- **Source** — out/s02/phase4_dates.log  <!-- PD-OK: pasted command output -->

### S17 · "F3-02 11 sabotages, F3-03 ~22, F3-04 17, F3-05 18, F3-06 24, F3-07 19+19, F3-08 13 -- recorded per leg" (sidecar rank 4)  <!-- PD-OK: row title quotes the claim being adjudicated -->

- **What is true** — The tallies exist only as a hand-authored line in scripts/build_evidence_standing.py; no per-leg receipt for any of them exists, and the artifact the entry cited (_ORCH/SPRINT_PROGRESS.md) contains no sabotage record at all. The sabotage MECHANISM is real and embedded in the gates' code and artifacts; the NUMBERS are unreceipted. S02, 2026-09-02.  <!-- PD-OK: quotes the measured value that refutes the claim -->
- **Still live at** — dataroom/EVIDENCE_STANDING.md 'The numbers.' line; dataroom/top40.json rank 4 (artifact and scope corrected)  <!-- PD-OK: counts of stale SITES, not portfolio counts -->
- **What to say instead** — Each package gate carries its own red-before-green findings in code; do not quote a per-package tally.  <!-- PD-OK: the replacement wording, quoted -->
- **Source** — git grep -ci sabotag _ORCH/SPRINT_PROGRESS.md -> 0; git grep -F '19+19' -> only sidecar-derived documents  <!-- PD-OK: pasted command output -->

### S24 · `python3 xdomain/mcp/impossibility.py` reproduces the impossibility artifact  <!-- PD-OK: row title quotes the claim being adjudicated -->

- **What is true** — It reproduces the verdicts and NOT the scope. The committed artifact records full_factorial true with 9,216 assignments per semantic spot-check; the producer's --semantic-sample default is 400, so the published bare command writes full_factorial false with 400, and the audit wrapper's snapshot restore put the committed file back -- so the receipt read REPRODUCED while a scope field had been downgraded. Measured on one pair both ways: 9,216 assignments in 129.2 s versus 400 in 5.5 s.  <!-- PD-OK: quotes the measured value that refutes the claim -->
- **Still live at** — artifacts/backends/impossibility.json; xdomain/mcp/impossibility.py argparse default at --semantic-sample  <!-- PD-OK: counts of stale SITES, not portfolio counts -->
- **What to say instead** — 62 of 140 slots impossible over five hazard fields. To reproduce the full-factorial scope the command must read `--semantic-sample 0`, priced at roughly two hours.  <!-- PD-OK: the replacement wording, quoted -->
- **Source** — out/s04/impossibility_fullfactorial_probe.log  <!-- PD-OK: pasted command output -->

## 2. Corrections found this pass

### S2 · Crown jewel 7's headline root was covered by the drift-guard  <!-- PD-OK: row title quotes the claim being adjudicated -->

- **What is true** — It was not. Until 2026-08-17 the jewel's ONLY binding was `n_leaves == 385`, while its headline leads with "under one SHA-256 Merkle root". `--check` reported it green throughout. FIXED this pass: the root is now bound, taking the coverage from 156/156 to 157/157 bindings compared.  <!-- PD-OK: quotes the measured value that refutes the claim -->
- **Still live at** — `scripts/build_crown_jewels.py`, jewel 7.  <!-- PD-OK: counts of stale SITES, not portfolio counts -->
- **What to say instead** — The binding now catches a silent re-pin of the certificate. It still cannot catch the live-tree divergence in S1 — that root appears in no artifact.  <!-- PD-OK: the replacement wording, quoted -->
- **Source** — found by inspecting the binding against the headline it guards  <!-- PD-OK: pasted command output -->

### S5 · "Jewel #20's certificate is a stale, self-attested one-time snapshot; the gate passes green with **zero clouds run**" — `dataroom/PITCH_RANKED_VERIFIED.md:123`  <!-- PD-OK: row title quotes the claim being adjudicated -->

- **What is true** — Half right, and the wrong half is the one that reads worst. The ARTIFACT records three clouds genuinely executed: `clouds_executed: ['do','modal','aws']`, `n_byte_identical_total: 24`, `n_mismatch_total: 0`. What is toothless is the GATE — criterion 1 reads "≥1 cloud executed **(or the whole leg skip-clean)**", so it would pass with none. The run happened; the gate cannot tell you that it did.  <!-- PD-OK: quotes the measured value that refutes the claim -->
- **Still live at** — `dataroom/PITCH_RANKED_VERIFIED.md:123`.  <!-- PD-OK: counts of stale SITES, not portfolio counts -->
- **What to say instead** — "Producer determinism re-derived byte-identical on DO + Modal + AWS in a recorded one-time run; the gate does not re-establish it." Do not say zero clouds ran.  <!-- PD-OK: the replacement wording, quoted -->
- **Source** — `artifacts/v62_acceptance.json`, read 2026-08-17  <!-- PD-OK: pasted command output -->

### S6 · "Jewel #25's reproduce command is broken … real producer: `scripts/pqc_fabric_certify.py`" — `dataroom/PITCH_RANKED_VERIFIED.md:132`  <!-- PD-OK: row title quotes the claim being adjudicated -->

- **What is true** — Already fixed, and the correction itself is now the stale thing. The generator emits `python3 scripts/pqc_fabric_certify.py` and `build_crown_jewels.unresolvable_repro()` would refuse to render otherwise. A reviewer following the reconcile-before-external-use list is sent to fix a non-defect.  <!-- PD-OK: quotes the measured value that refutes the claim -->
- **Still live at** — `dataroom/PITCH_RANKED_VERIFIED.md:132-134`.  <!-- PD-OK: counts of stale SITES, not portfolio counts -->
- **What to say instead** — Nothing — strike the item.  <!-- PD-OK: the replacement wording, quoted -->
- **Source** — `scripts/build_crown_jewels.py` JEWELS[25].reproduce, read 2026-08-17  <!-- PD-OK: pasted command output -->

### S8 · (dead code) This folder's CI gates the repository  <!-- PD-OK: row title quotes the claim being adjudicated -->

- **What is true** — The git root is `Desktop/untitled folder 3`; GitHub reads only `<root>/.github/workflows/`. This folder carries its own `.github/workflows/{ci,provenance,verify}.yml`, and **`provenance.yml` and `verify.yml` have no counterpart at the root — they have never run**. The two `ci.yml` files differ by 134 diff lines.  <!-- PD-OK: quotes the measured value that refutes the claim -->
- **Still live at** — `05_wireless_reliability_fallback_lab/.github/workflows/` — the two `ci.yml` files differ by **134** diff lines.  <!-- PD-OK: counts of stale SITES, not portfolio counts -->
- **What to say instead** — A provenance gate and a verify gate that look authoritative in the tree and gate nothing — this estate's own recurring failure class, living in its CI config. Matches `portfolio-control` `F3-STR-013` [FAILING] and `F3-STR-014`.  <!-- PD-OK: the replacement wording, quoted -->
- **Source** — `diff .github/workflows/ci.yml 05_.../.github/workflows/ci.yml | wc -l` → 134  <!-- PD-OK: pasted command output -->

### S11 · Sidecar rank 37 (802.1CB FRER injectivity floor) is NOT_RUN_CANNOT: "nothing here can produce it"  <!-- PD-OK: row title quotes the claim being adjudicated -->

- **What is true** — False. lean/TTEInjectivityFloor.lean + TTEFrerRecoveryFloor.lean + TTEFrerRecoveryFoils.lean build locally (`cd lean && lake build ...`, 7 jobs, ~9 s) and #print axioms over the seven foil theorems shows only propext / Quot.sound. lean/frer_recovery.receipt.json already recorded verdict EXACT, 14/14 axiom-audited. Ownership of the META-theorem stays with the sibling estate; the instance is ours.  <!-- PD-OK: quotes the measured value that refutes the claim -->
- **Still live at** — dataroom/top40.json rank 37 -- status corrected to RAN, S02 2026-09-02  <!-- PD-OK: counts of stale SITES, not portfolio counts -->
- **What to say instead** — The transferred FRER instance re-typechecks here; the meta-theorem is owned elsewhere.  <!-- PD-OK: the replacement wording, quoted -->
- **Source** — out/s02/rank37_lake.log, out/s02/rank37_axioms.log  <!-- PD-OK: pasted command output -->

### S12 · Sidecar rank 25 (two-engine tail-latency converses) is regenerated by its reproduce command  <!-- PD-OK: row title quotes the claim being adjudicated -->

- **What is true** — Half of it was. The entry cites BOTH mlo_latency_converse_v94.json and fec_llr_latency_v98b.json; the command ran only the MLO producer, so the FEC x LLR half had no regeneration receipt. Fixed S02, 2026-09-02: both producers are in the command.  <!-- PD-OK: quotes the measured value that refutes the claim -->
- **Still live at** — dataroom/VC_TOP_40.md rank 25 reproduce line  <!-- PD-OK: counts of stale SITES, not portfolio counts -->
- **What to say instead** — Both halves regenerate; both are converses of the declared abstraction.  <!-- PD-OK: the replacement wording, quoted -->
- **Source** — out/run_receipts.json rank 25, 2026-09-02  <!-- PD-OK: pasted command output -->

### S13 · Kit gate 3 (cross-references) PASSES on this lane  <!-- PD-OK: row title quotes the claim being adjudicated -->

- **What is true** — Vacuously: it examines 0 references here, because it matches only the tied form `entry N (\`id\`)` and this lane writes `entry #N`. Local gate C examines 17 and is proved to catch an injected bare reference. A PASS that examined nothing is recorded as a kit finding, not a lane pass (orchestrator note and S02, 2026-09-02).  <!-- PD-OK: quotes the measured value that refutes the claim -->
- **Still live at** — ~/Documents/portfolio-control/reaudit-kit/gates/check_top40_crossrefs.py; out/gates_local/check_top40_prose_crossrefs.py  <!-- PD-OK: counts of stale SITES, not portfolio counts -->
- **What to say instead** — Cross-references are checked by the local gate C (17 examined, 0 bad); the kit gate is blind here.  <!-- PD-OK: the replacement wording, quoted -->
- **Source** — python3 <kit>/check_top40_crossrefs.py -> 'checking 0 internal cross-reference(s)'  <!-- PD-OK: pasted command output -->

### S16 · Sidecar rank 9 (SKY130 gate-level) reproduces: `make v38` / asic_flow_v38.py -> "8/8 CORE criteria pass"  <!-- PD-OK: row title quotes the claim being adjudicated -->

- **What is true** — On a host without pono/eqy/sby (this one) the producer is skip-clean and the acceptance is skip-aware, so the command overwrites the committed executed:true artifact with a skip stub, prints 8/8 and exits 0 having proved nothing; the audit wrapper's snapshot restore is what preserved the committed artifact and produced a 'REPRODUCED' receipt. The committed artifact is a receipt from a host that had the toolchain. S02, 2026-09-02.  <!-- PD-OK: quotes the measured value that refutes the claim -->
- **Still live at** — artifacts/asic_flow_v38.json (committed, executed:true); scripts/check_acceptance_v38.py:56-68  <!-- PD-OK: counts of stale SITES, not portfolio counts -->
- **What to say instead** — The two-engine gate-level re-proof is a committed receipt; reproducing it needs the OSS CAD Suite toolchain ($0, ~20 min).  <!-- PD-OK: the replacement wording, quoted -->
- **Source** — out/s02/rank9_skipcheck.log  <!-- PD-OK: pasted command output -->

### S18 · `make prereg` seals a prediction BEFORE the benchmark, so "overfitting to test data is provably excluded"  <!-- PD-OK: row title quotes the claim being adjudicated -->

- **What is true** — The seal entered git on 2026-07-07 (commit 8f8f63e). The benchmark output it claims to precede, artifacts/referee_stats_v37.json, entered git on 2026-07-01 in commit 4383bd0, in the same commit as the predictions. The seal is real tamper-evidence from 07-07 onward; it is not temporal priority. A census of 27 bar/result pairs found NO asset in this tree whose bar predates its result other than by construction (byte-equality, a published ordering, a marker contract).  <!-- PD-OK: quotes the measured value that refutes the claim -->
- **Still live at** — scripts/check_prereg.py contract string; artifacts/preregistration.json's own `honesty` field is the careful one and does not overreach  <!-- PD-OK: counts of stale SITES, not portfolio counts -->
- **What to say instead** — The decision rules are sealed against tampering since 2026-07-07, and they are the gates the benchmark code already enforced. Do not say pre-registered.  <!-- PD-OK: the replacement wording, quoted -->
- **Source** — out/s02/phase4_dates.log (git log --diff-filter=A over 27 bar/result pairs)  <!-- PD-OK: pasted command output -->

### S19 · The unlisted acceptance gates are green  <!-- PD-OK: row title quotes the claim being adjudicated -->

- **What is true** — Three are red when run in isolation on an idle host: scripts/check_acceptance_tsn.py fails its TLA+ TLC cross-check leg (11/12); scripts/check_100x_builds.py fails the evidence-DAG leg while its committed artifact says all_ok true; scripts/check_gate_selfconsistency.py reports one pinned verdict that no longer follows from its own pinned inputs, and states that both files are byte-identical to the manifest so tamper-evidence cannot see it.  <!-- PD-OK: quotes the measured value that refutes the claim -->
- **Still live at** — 66 unlisted validators triaged; 3 red (out/s02/unlisted_triage.tsv)  <!-- PD-OK: counts of stale SITES, not portfolio counts -->
- **What to say instead** — Sixty-three of sixty-six unlisted validators pass; three are red and named.  <!-- PD-OK: the replacement wording, quoted -->
- **Source** — out/s04/red_validators_isolated.log  <!-- PD-OK: pasted command output -->

### S20 · Apalache 0.47.2 (artifacts/backends/apalache_refinement.json)  <!-- PD-OK: row title quotes the claim being adjudicated -->

- **What is true** — artifacts/backends/pinned_versions.json records apalache 0.58.2 for the same toolchain. Two receipts in the same tree disagree about the version of a third-party prover.  <!-- PD-OK: quotes the measured value that refutes the claim -->
- **Still live at** — artifacts/backends/apalache_refinement.json and artifacts/backends/pinned_versions.json  <!-- PD-OK: counts of stale SITES, not portfolio counts -->
- **What to say instead** — Quote the version from pinned_versions.json, or re-run the refinement receipt and let it record the live version.  <!-- PD-OK: the replacement wording, quoted -->
- **Source** — S03 third-party census; both artifacts read 2026-09-02  <!-- PD-OK: pasted command output -->

### S21 · Real DICHASUS CSI is present on this host  <!-- PD-OK: row title quotes the claim being adjudicated -->

- **What is true** — artifacts/dichasus_guarantee_multi.json reports executed true over 8 real scenarios while artifacts/dichasus_guarantee.json reports executed false with reason 'real DICHASUS CSI absent' and dichasus_fetch.json reports n_carded 0. The multi-scenario and single-scenario legs disagree about the same data on the same machine.  <!-- PD-OK: quotes the measured value that refutes the claim -->
- **Still live at** — artifacts/dichasus_guarantee.json vs artifacts/dichasus_guarantee_multi.json  <!-- PD-OK: counts of stale SITES, not portfolio counts -->
- **What to say instead** — Quote the multi-scenario leg, which is the one with the receipt, and say the single-scenario leg skipped clean.  <!-- PD-OK: the replacement wording, quoted -->
- **Source** — register addition rank 60; both artifacts read 2026-09-02  <!-- PD-OK: pasted command output -->

### S22 · Sionna is unavailable (artifacts/sota_headtohead.json sionna_available false)  <!-- PD-OK: row title quotes the claim being adjudicated -->

- **What is true** — artifacts/backends/real_sionna_olla.json records sionna_available true at version 2.0.1, and artifacts/realstack_harq_guard.json runs 400 blocks through the Sionna chain. Two artifacts disagree about whether the dependency is installed.  <!-- PD-OK: quotes the measured value that refutes the claim -->
- **Still live at** — artifacts/sota_headtohead.json vs artifacts/backends/real_sionna_olla.json  <!-- PD-OK: counts of stale SITES, not portfolio counts -->
- **What to say instead** — Sionna 2.0.1 is present; the head-to-head's flag is stale.  <!-- PD-OK: the replacement wording, quoted -->
- **Source** — S03 third-party census; register additions ranks 61 and 62  <!-- PD-OK: pasted command output -->

### S23 · Tamarin is this estate's ninth independent proof engine  <!-- PD-OK: row title quotes the claim being adjudicated -->

- **What is true** — dataroom/VC_TOP_40.md withdraws the nine-engine framing outright -- 'the load-bearing core is two (z3 + BFS)' -- while artifacts/tamarin_pqc_v85.json still describes itself as the 9th engine. The RESULT (5/5 lemmas under an active attacker) is unaffected; the engine-count framing is what was withdrawn.  <!-- PD-OK: quotes the measured value that refutes the claim -->
- **Still live at** — artifacts/tamarin_pqc_v85.json `engine` field vs the withdrawal in dataroom/VC_TOP_40.md  <!-- PD-OK: counts of stale SITES, not portfolio counts -->
- **What to say instead** — Five security lemmas verified by tamarin-prover. Do not count engines.  <!-- PD-OK: the replacement wording, quoted -->
- **Source** — register addition rank 43  <!-- PD-OK: pasted command output -->

### S25 · The forall-trust impossibility run takes 8,502 s  <!-- PD-OK: row title quotes the claim being adjudicated -->

- **What is true** — RETRACTED. A clean re-run under caffeinate measured 327.6 s. The 2026-08-27 figure was wall-clock inflated by machine sleep; the verdicts it reported did not move.  <!-- PD-OK: quotes the measured value that refutes the claim -->
- **Still live at** — dataroom/top40.json rank 31 (corrected 2026-09-02)  <!-- PD-OK: counts of stale SITES, not portfolio counts -->
- **What to say instead** — 327.6 s measured.  <!-- PD-OK: the replacement wording, quoted -->
- **Source** — out/s02/t3_receipts.json  <!-- PD-OK: pasted command output -->

### S26 · The lane's ranking documents cover the lane's evidence  <!-- PD-OK: row title quotes the claim being adjudicated -->

- **What is true** — 589 tracked artifact-like files are named in none of the four ranking documents, 281 of them manifest leaves; 74 Lean declarations are proved and credited in no pinned list; 33 numeric bounds are asserted only in the test suite; and two structured corpora of killed candidates (197 tracked files) sit at the git root, one directory above every lane-scoped tool that looks for them. S04 admitted 25 of these as register entries; the remainder are recorded, not claimed.  <!-- PD-OK: quotes the measured value that refutes the claim -->
- **Still live at** — out/s03/unreferenced.tsv, artifacts/backends/lean_uncredited.json, out/s03/test_bounds.tsv, artifacts/backends/moonshot_corpora_index.json  <!-- PD-OK: counts of stale SITES, not portfolio counts -->
- **What to say instead** — Sixty-five assets are registered with receipts; the register names what is still uncovered rather than implying coverage.  <!-- PD-OK: the replacement wording, quoted -->
- **Source** — LANE_REGISTER_2026-09.md and dataroom/register_additions_2026-09.json  <!-- PD-OK: pasted command output -->

### S27 · This lane's closure certificate is the UNIVERSAL closure certificate  <!-- PD-OK: row title quotes the claim being adjudicated -->

- **What is true** — Three lanes ship a closure certificate and the orchestrator measured them DISJOINT (f3 x genesis jaccard 0.11, either x f8 0.00, against a control of 1.00 on a document compared with a copy of itself). None of the three is universal and two were calling themselves so. The word is dropped from this lane's name by orchestrator instruction, at the producer and on every live surface. The COMMITTED artifact still reads v31-universal-closure-certificate, because rewriting it means running scripts/build_closure_cert.py and running that script IS the re-pin, which is a standing refusal. The name changes when an owner re-pins; the gap is disclosed, not closed by hand.  <!-- PD-OK: quotes the measured value that refutes the claim -->
- **Still live at** — scripts/build_closure_cert.py:66 (producer, renamed) vs artifacts/closure_certificate.json:397 (committed, unchanged); findings/check_closure_collision.py at the orchestrator  <!-- PD-OK: counts of stale SITES, not portfolio counts -->
- **What to say instead** — One Merkle root over 385 pinned evidence files, re-derivable offline by a stdlib verifier. It is this lane's closure, not the estate's.  <!-- PD-OK: the replacement wording, quoted -->
- **Source** — scripts/verify_closure.py and artifacts/closure_certificate.json  <!-- PD-OK: pasted command output -->

### S28 · This lane's Lean census counts the Lean declarations in this lane  <!-- PD-OK: row title quotes the claim being adjudicated -->

- **What is true** — It counted 192 declarations across lean/ and lean-mathlib/ and never looked at xdomain/, which holds three Lean files carrying 15 more. The true count is 207 declarations, 198 unique names, 89 of them credited nowhere. Found by scripts/lean_credit_audit.py censusing the whole tree during S08; the producer's directory set was fixed and the artifact regenerated by its own command, so no number was edited by hand.  <!-- PD-OK: quotes the measured value that refutes the claim -->
- **Still live at** — scripts/lean_uncredited.py DIRS, artifacts/backends/lean_uncredited.json  <!-- PD-OK: counts of stale SITES, not portfolio counts -->
- **What to say instead** — Eighty-nine Lean declarations are proved in this tree and credited in no pinned list.  <!-- PD-OK: the replacement wording, quoted -->
- **Source** — artifacts/backends/lean_uncredited.json  <!-- PD-OK: pasted command output -->

### S29 · A FRER recovery function must distinguish 3^w states, for every window width w  <!-- PD-OK: row title quotes the claim being adjudicated -->

- **What is true** — The Lean kernel checks 2^w <= s for EVERY width (frer_recovery_bit_floor) and the sharper 3^w bound ONLY at width two (attribution_floor_at_width_two, with attribution_strictly_above_discard_only giving 2^2 < 3^2). The general 3^w statement is made in the register and is not machine-checked. Found at S14 while writing the site package, by reading the theorem statements the kernel had actually elaborated rather than the names they carry -- the same gap this lane's own Lean credit audit exists to catch, in this lane's own register.  <!-- PD-OK: quotes the measured value that refutes the claim -->
- **Still live at** — lean/TTEFrerRecoveryFloor.lean:142 and lean/TTEFrerRecoveryFoils.lean:110,118; artifacts/backends/lean_credit_audit.json  <!-- PD-OK: counts of stale SITES, not portfolio counts -->
- **What to say instead** — Recovering what happened in each of w in-window slots forces at least 2^w states for every width; with member-path attribution the floor is 9 states at a two-slot window, against the 4 of the bitmap the standard describes.  <!-- PD-OK: the replacement wording, quoted -->
- **Source** — lean/frer_local_check.json  <!-- PD-OK: pasted command output -->

## 3. Entries CUT from the top list, for cause

These are results this estate has led with. Each was refused by a named gate, and the deciding register entry is quoted, not paraphrased.

### Jewel 4 · Resource “memory walls” (MODEL ratio)

> 19,660,800× (32 B token vs 2400 B ML-KEM-768 pinned per half-open session) · 67,108,864× (UEC reorder)  <!-- PD-OK: the CUT entry's own headline, shown so the cut is auditable -->

- **G3** — EV-W08: The entry IS the ratio.  <!-- PD-OK: the deciding register entry, quoted -->

### Jewel 18 · Two new physics floors — energy & token-minimality

> energy floor −1.5917 dB (exact wideband converse, sandwiched); 19,660,800× token wall floor-to-floor  <!-- PD-OK: the CUT entry's own headline, shown so the cut is auditable -->

- **G3** — EV-W08: Jewel 18 leads with the token wall floor-to-floor at 19,660,800x. The energy floor half (-1.5917 dB) is untouched and strong, but the entry as written puts the collapsing ratio in the headline.  <!-- PD-OK: the deciding register entry, quoted -->

### Jewel 7 · Tamper-evident reproducibility (Merkle closure)

> 385 leaves under one SHA-256 Merkle root (stdlib + browser verifier)  <!-- PD-OK: the CUT entry's own headline, shown so the cut is auditable -->

- **G3** — B.closure.evidence_regenerates: `scripts/verify_closure.py` on a clean tree: internal_root_ok=True, full_provenance_ok=False, VERIFY FAILED.  <!-- PD-OK: the deciding register entry, quoted -->
- **G3** — B.closure.root: The headline is 'under one SHA-256 Merkle root' and the live tree does not fold to the published root. No footnote rescues an integrity claim whose subject is refuted by the estate's own gate.  <!-- PD-OK: the deciding register entry, quoted -->

### Jewel 6 · Design-around inevitability (red-team)

> 16/16 planted-broken controls REFUSED and 0 false-certify across 489 screenings (473 lattice weakenings, closed by construction, + 16 planted)  <!-- PD-OK: the CUT entry's own headline, shown so the cut is auditable -->

- **G3** — EV-R01: RETRACTED framing still live at 124 sites; jewel 6 leads with the 489 denominator  <!-- PD-OK: the deciding register entry, quoted -->

### Jewel 17 · Provably-optimal decode scheduler + randomized class-optimum

> exact DP, Bellman residual 0 (gap-to-optimum 0 by construction); EMLSR switch ρ=1.6067679 at pinned k=20, ρ=1.597521 at k=32, both strictly between 2 and e/(e−1)=1.581977  <!-- PD-OK: the CUT entry's own headline, shown so the cut is auditable -->

- **G3** — EV-W04: The HEADLINE is accurate -- rho=1.6067679 sits strictly between e/(e-1) and 2, and the entry says so. The jewel's NAME calls it a 'randomized class-optimum', and the artifact's own gap_to_optimum field is 0.024791. A name that claims optimality for a number 1.57% above the optimum cannot go on a pitch surface, and renaming it is the register's call, not this document's.  <!-- PD-OK: the deciding register entry, quoted -->

### Jewel 8 · Measured wins vs the FAITHFUL real standards

> CSI overhead −71.23%, Wi-Fi 8 crit-MPDU loss −53.93% (deterministic sim, CI-lower-bound gated)  <!-- PD-OK: the CUT entry's own headline, shown so the cut is auditable -->

- **G3** — EV-W02: The -53.93% is real; the surgical-repair MECHANISM attribution is not (dup_attempts = 0). A pitch cannot carry a number whose mechanism is wrong.  <!-- PD-OK: the deciding register entry, quoted -->

### Jewel 9 · Machine-checked standards-essentiality (modeling entailment)

> 8 machine-checked entailments — 1 OUTCOME (harq) + 7 PROSPECTIVE-SEP (incl. 3 AI/ML-LCM species), unbounded z3 induction + BFS agree  <!-- PD-OK: the CUT entry's own headline, shown so the cut is auditable -->

- **G3** — B.essentiality.csi_lcm_fallback: PROSPECTIVE-SEP against TR 38.843, which is a non-normative study item. UNTRUSTED in the trust register.  <!-- PD-OK: the deciding register entry, quoted -->
- **G3** — B.essentiality.outcome_count: CONTRADICTED and left so deliberately on 2026-08-15: both artifacts report n_outcome_essential=1 while two charts on disk carry tier OUTCOME. The error direction is UNDERSTATEMENT, which is the safe direction -- and still a number a buyer cannot reconcile against the charts they are handed.  <!-- PD-OK: the deciding register entry, quoted -->
- **G3** — B.essentiality.semantic_fallback: Same: PROSPECTIVE against TR 38.843.  <!-- PD-OK: the deciding register entry, quoted -->
- **G3** — EV-W05: 7 of the 8 entailments are PROSPECTIVE against change requests we drafted ourselves. The headline number is 8. Exactly one targets published third-party text and it is jewel 32, which is in this list on its own merit -- so nothing is lost by cutting the aggregate.  <!-- PD-OK: the deciding register entry, quoted -->

### Jewel 25 · Combined cross-domain flagship — one token gates two hazards

> a single 32 B token gates BOTH PQC anti-clogging AND fabric ordered-acquisition, 3 guards, 0 red-team survivors  <!-- PD-OK: the CUT entry's own headline, shown so the cut is auditable -->

- **G3** — EV-R11: The estate's own prior-art screen retracted the broad cross-domain compose-check-repair genus as anticipated by feature-interaction analysis and Ramadge-Wonham supervisory control, with the Wi-Fi/NR-U finding textbook (Fu & Liew JSAC 2011, IEEE 802.19.1, US 9,088,910). The engineering is real and the capability is genuine; the breadth claim that makes this entry interesting on a pitch surface is not.  <!-- PD-OK: the deciding register entry, quoted -->

## 4. Unselected — no comparative authored

**These are not stale and nothing is wrong with them.** Each re-derives from its artifact today and passed G1–G3. None has an authored comparative — a named thing it beats or is first at — so none met G4. That is a gap in the top-list document, not a defect in the result, and saying so plainly is the difference between a short-list and a quiet demotion. Authoring a sourced comparative promotes any of them.

| Jewel | Result | Artifact |
|---|---|---|
| 13 | The rounds sandwich | `rounds_converse_v54.json` |
| 20 | Multi-cloud determinism certificate | `v62_acceptance.json` |
| 2 | Discovery beyond the boolean frontier | `discovery_v34.json` |
| 11 | The Sound Factory — proof-as-fitness | `openevolve_atlas.json` |
| 15 | Spec-fidelity MAC + fast-enough + shielded learned scheduler | `mac_full_fidelity_v58.json` |
| 19 | Evolution Wave 2 — the shipped scope is machine-maximal | `v61_acceptance.json` |
| 10 | File-ready claims + reads-on-the-wire evidence | `claim_structure_v45.json` |
| 21 | Second AND third domains — the claims compiler runs on CXL 3.x (v75) + AI-fabric (v79) | `ai_fabric_flagships_v79.json` |
| 23 | Observable-completeness — the essentiality DUAL — v73 | `observable_completeness_v73.json` |
| 24 | Exact ∀-parameter region certification — v74 | `parametric_region_v74.json` |
| 27 | Anytime-valid statistical certificates — v71 | `evalue_certificates.json` |
| 26 | Distributionally-robust conformal coverage — v72 | `dro_conformal_v72.json` |
| 28 | The HONEST exact MIMO fading converse | `wall_mimo_exact.json` |
| 33 | The covert square-root law — v98c | `covert_fbl_v98c.json` |
| 34 | The FEC x LLR x queueing tail-latency floor — v98b | `fec_llr_latency_v98b.json` |

## 5. The standing registers this merges

Nothing above replaces these; this document is a view over them, and each is generated with its own drift-guard.

| Register | What it holds | Live retracted strings |
|---|---|---|
| `dataroom/EVIDENCE_STANDING.md` | every number the estate publishes and whether it is still true — 11 RETRACTED, 8 WEAKENED, 7 UNVERIFIED | **125** occurrences still in tracked files |
| `CLAIM_TRUST.md` | 30 claims adjudicated 2026-08-15 into REPRODUCIBLE / PROVISIONAL / CONTRADICTED / UNTRUSTED | 3 left CONTRADICTED deliberately |
| `DILIGENCE.md` | the honest front door: what reproduces, what is skip-clean | — |
| `~/Documents/portfolio-control/views/folder3/KNOWN_FAILURES.md` | 75 cross-repo negative results, sealed 2026-08-10 | predates `CLAIM_TRUST.md` |

### Retracted strings still live in this tree

| Standing id | What was withdrawn | Live occurrences |
|---|---|---|
| `EV-R01` | "489/489 adversarial weakenings refuted, zero survivors" | **124** |  <!-- PD-OK: the retracted string itself, listed as retracted -->
| `EV-R02` | "5,594 Ed25519 differential fuzz trials" | **0** |  <!-- PD-OK: the retracted string itself, listed as retracted -->
| `EV-R03` | "pcar ships **46** vectors" (the corpus total, published as 46) | **0** |  <!-- PD-OK: the retracted string itself, listed as retracted -->
| `EV-R04` | Crown jewel 39 bound `artifacts/lean_axioms.json`'s schema string | no grep pattern |  <!-- PD-OK: the retracted string itself, listed as retracted -->
| `EV-R05` | Crown jewel 33's five bindings all expected `True` | no grep pattern |  <!-- PD-OK: the retracted string itself, listed as retracted -->
| `EV-R06` | Jewel 28's reproduce command, `make wall-mimo-exact` | **0** |  <!-- PD-OK: the retracted string itself, listed as retracted -->
| `EV-R07` | `artifacts/covert_bits.json`, cited as evidence for the 34.55 → ~65.9 correction | **0** |  <!-- PD-OK: the retracted string itself, listed as retracted -->
| `EV-R08` | "monitorgen scores 148/148 on its conformance suite" | **0** |  <!-- PD-OK: the retracted string itself, listed as retracted -->
| `EV-R09` | "39 crown jewels" / "37 canonical" | **1** |  <!-- PD-OK: the retracted string itself, listed as retracted -->
| `EV-R10` | "5.9 ms at N=1,000,000" / "10⁵× beyond BFS reach" | **0** |  <!-- PD-OK: the retracted string itself, listed as retracted -->
| `EV-R11` | Broad Family-III / cross-domain compose-check-repair as patentable IP | no grep pattern |  <!-- PD-OK: the retracted string itself, listed as retracted -->

> `EV-R01` is the one that matters: the "489/489 adversarial weakenings refuted" framing. 473 of the 489 are monotone lattice weakenings over a register CLOSED under weakening, so zero survivors is guaranteed by construction rather than discovered. The honest headline is **16/16 planted-broken controls refused, 0 false-certify, across 489 screenings**. `dataroom/CROWN_JEWELS.md` already leads with the corrected form; `dataroom/PITCH_RANKED_VERIFIED.md` §S2 does not, and it is a pitch surface.

*Generated by `scripts/build_top_jewels.py`.*
