{
  "ok": true,
  "gates": {
    "gated_admits_legit_ge_99pct": true,
    "naive_starved_ge_99pct": true,
    "ctmc_solve_matches_erlangB": true,
    "gated_p99_below_cap": true,
    "starvation_flip_on_gate_removal": true
  },
  "model": "M/M/c/c Erlang loss CTMC of the half-open admission table",
  "constants": {
    "S_pq_bytes": 7533,
    "T_timeout_s": 30,
    "lambda_atk_per_s": 100000,
    "lambda_leg_per_s": 10,
    "halfopen_ram_bytes": 8388608,
    "cap_slots_c": 1113
  },
  "offered_load_erlangs": {
    "naive": 3000300.0,
    "gated": 300.0
  },
  "blocking_probability": {
    "naive": 0.999629037,
    "gated": 0.0
  },
  "p_legit_admitted": {
    "naive": 0.000370963,
    "gated": 1.0
  },
  "gated_p99_occupancy_slots": 341,
  "ctmc_crosscheck": {
    "small_system_c": 12,
    "small_system_a": 8.0,
    "exact_rational_full_mass": 0.051406387712,
    "erlangB_recursion": 0.051406387712,
    "match": true
  },
  "csl_properties": {
    "gated  S=? [ n = CAP ]  (steady-state block)": 0.0,
    "gated  P(legit admitted)": 1.0,
    "naive  S=? [ n = CAP ]  (steady-state starvation)": 0.999629037
  },
  "prism_storm_ran": false,
  "prism_storm_path": null,
  "upgrade_note": "PRISM/Storm CSL model-checking (S=?/P=? properties) is the external-checker UPGRADE; the exact Python CTMC stationary solve (cross-validated vs Erlang-B) is the committed floor.",
  "scope": "steady-state quantitative guarantee on LEGIT-client admission under flood; complements the worst-case resident<=CAP inductive bound (z3/Lean/Yosys), which does not quantify starvation probability."
}