History

C932–C1131:200-action verification and packaging

Download source fileOpen in research workspace

C932–C1131:200-action verification and packaging

The current cycle starts at C932 and ends at C1131 inclusive: 200 actions. The preseal prefix ends at C1130: 199 actions. C1132 is outside this cycle. These helpers were adapted without running an old full verification or executing a new numbered action.

Root-supplied file contracts

The predecessor artifact basenames are:

Snapshot aliasC931 artifact
C931_checkpoint.md490d_Chronological_Families_Checkpoint_After_C931.md
C931_synthesis.md490d_Chronological_Families_Integrated_Synthesis_C931.md
C931_technical.md490d_Chronological_Families_Technical_Companion_C931.md
C931_reading_guide.md (optional)490d_Chronological_Families_Reading_Guide_C931.md

Commands and closure gates

Run between numbered actions from /workspace/scratch/1b40da62dcbd:

python3 c932_c1131/evidence/verify.py --through 951 --require-current-sources --output c932_c1131/VERIFY_THROUGH_C951.json
python3 c932_c1131/evidence/package.py --through 951 --date 20260928

The packager's optional --first changes only the displayed research-report range. Its evidence ZIP retains the full completed current-cycle prefix. It does not save the artifacts remotely; the root handles saving.

After completing C1130 and before opening C1131, run the199-action preseal gate:

python3 c932_c1131/evidence/verify.py --through 1130 --require-current-sources --output c932_c1131/VERIFY_THROUGH_C1130.json

The root's C1131 seal should bind the passing prefix report and final artifact identities. After C1131 is complete, run:

python3 c932_c1131/evidence/verify.py --require-current-sources --output c932_c1131/VERIFY.json
python3 c932_c1131/evidence/package.py --through 1131 --date 20260928

The default verifier endpoint is1131. It requires exactly200 records and no pending action. Final packaging requires a passing VERIFY.json whose first/last/count are932/1131/200, whose final_200_step_verification is true, and whose journal hash matches the current journal bytes. It also requires no pending action. The verifier reports requested_steps:200 and preseal_199_step_verification for the1130 prefix; the old final_100_step_verification field is not used.

Portable verification

For an ordinarily detached extracted packet, omit --require-current-sources:

python3 evidence/verify.py --through 1130

Frozen sources and the exact predecessor remain verified even when originals are absent. Absolute source-binding metadata must remain byte-identical: some historical scripts use it to resolve the identity of a frozen snapshot. --workspace alone does not hide absolute original paths when they still exist.

To demonstrate isolation while the original workspace exists, first verify the archive manifest and all extracted payload hashes. In a separate subprocess, make original-workspace file-availability checks report false and install an audit gate rejecting original-workspace file opens, while leaving the extracted packet unchanged. Then run the ordinary extracted verifier and confirm zero current copies, all frozen snapshots, and the frozen C931 binding. Recheck extracted payload hashes afterward. Do not move or rename originals, rewrite binding metadata, or patch historical scripts for this test.

Replay limits

The replay checks one matching begin/finish pair, metadata, results, reassessment, true Boolean checks, timestamps, hash chain, source identity, and unchanged journal records. It blocks file writes, filesystem mutation, subprocesses and network actions during replay. artifact() recomputes byte/hash metadata without writing. Final on-disk artifact availability remains a separate preflight responsibility because intermediate outputs may have been superseded.

The independent string-based decimal reversal preserves zero placeholders. Static nested-call checks and provenance-tracked inverse values reject a second inverse. This is not a proof against arbitrary manual reimplementation or deliberate provenance erasure; the packet is trusted research code rather than an arbitrary-code sandbox.

Validation totals are not counts of independent discoveries or statistical evidence.

Explicit historical draft reads

VERSIONED_INPUTS.json binds a logical preparation-file path, exact frozen snapshot, SHA-256, declared steps and the existing journal draft_sha256 field. The verifier validates safe paths, snapshot hashes, declared source names and journal hashes before activating any binding. Its narrow ReplayPath subclass redirects only read_text() and read_bytes() on the exact declared ROOT-derived path for steps marked historical; other paths and current-version reads remain ordinary reads. No begin/finish metadata or result comparison is skipped. Every activated historical binding must actually be read.

C1090–C1094 use the exact frozen manuscript_covenant_v1.json bytes for prep/manuscript_covenant.json. C1095 is explicitly bound to the current v2 bytes and is not redirected. Both versions are retained in evidence/input_versions/. Their JSON objects differ only in scope_note; the manuscript modules are unchanged. The recorded old SHA-256 is reproduced exactly, rather than normalized or replaced.

The C1101 prefix passes with these bindings (170 actions, 425 checks). VERSIONED_INPUTS_REVIEW.json records six rejected negative cases: a wrong but internally hash-consistent version, unsafe path, duplicate binding, modified snapshot, incorrect current version, and omission of the needed historical binding. The live draft, completed records and numbered scripts were not modified.

Edition and provenance

HELPERS.md

SHA-256 392b2f5a1998ebf7a9ec2ffa98da7e4e7460aad1c990c541a55dd0a01fff1259

C480–C1634/Research_Cycles/C0932_C1131/evidence/HELPERS.md