C932–C1131:200-action verification and packaging
The current cycle starts at C932 and ends at C1131 inclusive: 200 actions. The preseal prefix ends at C1130: 199 actions. C1132 is outside this cycle. These helpers were adapted without running an old full verification or executing a new numbered action.
Root-supplied file contracts
journal.json: contiguous completed records starting at932, using the existing schema, canonical record hash, and one sequentialbegin/finishpair per action. The first predecessor value isC931:55a6faf783579d9119c15adafb3697ab140daddaeda4547bcd674196a4951a9f.evidence/C931_PREDECESSOR.json: the exact completed C931 record. The verifier pins its SHA256 to55a6faf783579d9119c15adafb3697ab140daddaeda4547bcd674196a4951a9f.evidence/SOURCE_MANIFEST.json: snapshot basename → SHA256; every member resides inevidence/sources/. The source count is dynamic rather than hardcoded.evidence/SOURCE_BINDINGS.json: optional snapshot basename → current-original path or path list. Absolute paths are intentionally retained as identity metadata and must not be relocated to simulate source absence.- Required predecessor snapshot aliases:
C931_checkpoint.md,C931_synthesis.md, andC931_technical.md. They bind by hash and byte count to the matching entries in C931'sresults.final_artifacts. OptionalC931_reading_guide.mdis bound if included. - Required controlling inverse-source alias:
File52c_latest.md, SHA256a5ea84562101158b60d0cf296765d6eff38e7a2abda4e74ad1b353dfd13b9530. evidence/sN.py: historical action scripts. Replay substitutes a read-onlyresearchmodule and never imports the live writer. Available exports remainPath,F,ROOT,E,P,J,json,hashlib,clean,inv,begin,finish,REPLAY,artifact.evidence/research.py, source preparation, model artifacts, pending state and all numbered actions remain root-owned. The helper author owns onlyverify.py,package.py, and this file.
The predecessor artifact basenames are:
| Snapshot alias | C931 artifact |
|---|---|
C931_checkpoint.md | 490d_Chronological_Families_Checkpoint_After_C931.md |
C931_synthesis.md | 490d_Chronological_Families_Integrated_Synthesis_C931.md |
C931_technical.md | 490d_Chronological_Families_Technical_Companion_C931.md |
C931_reading_guide.md (optional) | 490d_Chronological_Families_Reading_Guide_C931.md |
Commands and closure gates
Run between numbered actions from /workspace/scratch/1b40da62dcbd:
python3 c932_c1131/evidence/verify.py --through 951 --require-current-sources --output c932_c1131/VERIFY_THROUGH_C951.json
python3 c932_c1131/evidence/package.py --through 951 --date 20260928
The packager's optional --first changes only the displayed research-report range. Its evidence ZIP retains the full completed current-cycle prefix. It does not save the artifacts remotely; the root handles saving.
After completing C1130 and before opening C1131, run the199-action preseal gate:
python3 c932_c1131/evidence/verify.py --through 1130 --require-current-sources --output c932_c1131/VERIFY_THROUGH_C1130.json
The root's C1131 seal should bind the passing prefix report and final artifact identities. After C1131 is complete, run:
python3 c932_c1131/evidence/verify.py --require-current-sources --output c932_c1131/VERIFY.json
python3 c932_c1131/evidence/package.py --through 1131 --date 20260928
The default verifier endpoint is1131. It requires exactly200 records and no pending action. Final packaging requires a passing VERIFY.json whose first/last/count are932/1131/200, whose final_200_step_verification is true, and whose journal hash matches the current journal bytes. It also requires no pending action. The verifier reports requested_steps:200 and preseal_199_step_verification for the1130 prefix; the old final_100_step_verification field is not used.
Portable verification
For an ordinarily detached extracted packet, omit --require-current-sources:
python3 evidence/verify.py --through 1130
Frozen sources and the exact predecessor remain verified even when originals are absent. Absolute source-binding metadata must remain byte-identical: some historical scripts use it to resolve the identity of a frozen snapshot. --workspace alone does not hide absolute original paths when they still exist.
To demonstrate isolation while the original workspace exists, first verify the archive manifest and all extracted payload hashes. In a separate subprocess, make original-workspace file-availability checks report false and install an audit gate rejecting original-workspace file opens, while leaving the extracted packet unchanged. Then run the ordinary extracted verifier and confirm zero current copies, all frozen snapshots, and the frozen C931 binding. Recheck extracted payload hashes afterward. Do not move or rename originals, rewrite binding metadata, or patch historical scripts for this test.
Replay limits
The replay checks one matching begin/finish pair, metadata, results, reassessment, true Boolean checks, timestamps, hash chain, source identity, and unchanged journal records. It blocks file writes, filesystem mutation, subprocesses and network actions during replay. artifact() recomputes byte/hash metadata without writing. Final on-disk artifact availability remains a separate preflight responsibility because intermediate outputs may have been superseded.
The independent string-based decimal reversal preserves zero placeholders. Static nested-call checks and provenance-tracked inverse values reject a second inverse. This is not a proof against arbitrary manual reimplementation or deliberate provenance erasure; the packet is trusted research code rather than an arbitrary-code sandbox.
Validation totals are not counts of independent discoveries or statistical evidence.
Explicit historical draft reads
VERSIONED_INPUTS.json binds a logical preparation-file path, exact frozen snapshot, SHA-256, declared steps and the existing journal draft_sha256 field. The verifier validates safe paths, snapshot hashes, declared source names and journal hashes before activating any binding. Its narrow ReplayPath subclass redirects only read_text() and read_bytes() on the exact declared ROOT-derived path for steps marked historical; other paths and current-version reads remain ordinary reads. No begin/finish metadata or result comparison is skipped. Every activated historical binding must actually be read.
C1090–C1094 use the exact frozen manuscript_covenant_v1.json bytes for prep/manuscript_covenant.json. C1095 is explicitly bound to the current v2 bytes and is not redirected. Both versions are retained in evidence/input_versions/. Their JSON objects differ only in scope_note; the manuscript modules are unchanged. The recorded old SHA-256 is reproduced exactly, rather than normalized or replaced.
The C1101 prefix passes with these bindings (170 actions, 425 checks). VERSIONED_INPUTS_REVIEW.json records six rejected negative cases: a wrong but internally hash-consistent version, unsafe path, duplicate binding, modified snapshot, incorrect current version, and omission of the needed historical binding. The live draft, completed records and numbered scripts were not modified.