# C532–C631 verification runner notes

`evidence/verify.py` is portable relative to its packet root. It never imports the production journal writer. It replaces `research.begin`, `research.finish`, and `research.artifact` in memory, sets `research.REPLAY=True`, independently recomputes reversal, and installs a runtime audit guard during each script replay.

## Invocation

For a completed prefix:

```bash
python3 evidence/verify.py --through 610
```

For the completed full100-step packet:

```bash
python3 evidence/verify.py --output VERIFY.json
```

The default requires every completed stepC532–C631 and no pending record. Do not use that final invocation beforeC631 is complete. `--through N` requires only the completed prefix throughN, even if the live journal later contains additional steps.

Current originals are checked automatically when found in the packet's parent workspace. In the original workspace, require all originals:

```bash
python3 evidence/verify.py --require-current-sources --output VERIFY.json
```

For a different workspace, add `--workspace /absolute/workspace/path`. In a separately extracted portable packet, unavailable live originals are listed as absent; all bundled source snapshots and pinned primary identities still must match. This distinction is explicit in the JSON report.

## Checks

- Exact sequential step range, record schema, nonempty research/reassessment metadata, opening/closing time order, complete canonical record hashes, and every predecessor link.
- The completeC531 predecessor snapshot and its pinned hash; its draft/checkpoint bindings; the currentC531 record when available.
- Every bundled source snapshot against `SOURCE_MANIFEST.json`; all available corresponding current originals; latestFile52c pinned to `a5ea84562101158b60d0cf296765d6eff38e7a2abda4e74ad1b353dfd13b9530`.
- Script metadata, source lists, inputs, results, findings, reassessments, and Boolean checks against the completed records. Each script must call exactly one begin and one finish.
- No replay file writes, removals, renames, directory mutations, processes, or network actions. The optional final JSON report is written only after replay ends; otherwise output is stdout only.
- `artifact(relative_path, content)` recomputes content bytes/hash/path without writing. This reproduces each historical generation event even if a later step revised the file. It does not claim that every earlier draft still exists as the current artifact.
- The independent placeholder-preserving inverse implementation tracks integer outputs and their ordinary arithmetic descendants. Nested `inv` calls and re-inversion of tracked descendants fail. Fresh input3430 is accepted, as is its equality to its own inverse; unrelated equal integer values are not treated as second passes merely because they coincide numerically.

The inverse guard is deliberately described within its actual scope. It is not a security proof against arbitrary hand-coded reversal or deliberate provenance erasure. The scripts are trusted research artifacts; the runner adds practical read-only and operation guards and reports them honestly.

## Validation performed

The runner was tested on completed prefixes only:

| Prefix | Result | Steps | Replayed record checks | Single-pass inverse calls |
|---|---|---:|---:|---:|
|C532–C551|PASS|20|54|0|
|C532–C610|PASS|79|186|7|

Both runs verified28 source snapshots and29 current source copies (Strategy has two available matching copies), plus theC531 predecessor. Reports are `prep/verification_test_C551.json` and `prep/verification_test_C610.json`. No unfinished full-range run was attempted. The lead owns the remaining numbered research and final verification sequence.

Counts are execution coverage, not independent discoveries, probabilities, or a new audit of the historical source-file verification suites.
