{
  "A": {
    "a4_byte_identical_at": [
      2,
      8,
      16,
      32,
      64
    ],
    "a4_divergent_at": [
      3,
      5,
      6,
      7,
      15,
      17,
      31,
      33,
      63
    ],
    "a4_leaf_or_verdict_moved_at": [],
    "a4_sizes_swept": [
      2,
      3,
      5,
      6,
      7,
      8,
      15,
      16,
      17,
      31,
      32,
      33,
      63,
      64
    ],
    "level_collapse_sets": 60,
    "one_stage_root": "28a2082f16056a02be7c7b6233b8a59c670e17de66614f3fe5cebd14d9709e17",
    "s252_root": "28a2082f16056a02be7c7b6233b8a59c670e17de66614f3fe5cebd14d9709e17",
    "shapes": [
      [
        4,
        4
      ],
      [
        2
      ],
      [
        8
      ],
      [
        2,
        2,
        2
      ],
      [
        3,
        5
      ]
    ]
  },
  "B": {
    "compression_x": 7.934445768772348,
    "flat_lcert_bytes_equivalent": 6657,
    "flat_record_bytes_per_tile_max": 105,
    "path_len": 6,
    "receipt_bytes": 839,
    "receipt_bytes_vs_n": {
      "64": 852,
      "1024": 859,
      "16384": 865
    },
    "region": {
      "admit": true,
      "eps_bound": 0.25668743100224034,
      "n_tiles": 64,
      "worst_epe_nm": 14.434782608695652
    },
    "total_nodes": 147
  },
  "C": {
    "ladder": {
      "0": 1,
      "8": 4,
      "16": 4,
      "24": 4,
      "32": 9,
      "48": 16,
      "64": 25
    },
    "n_clean_blocks": 8,
    "outside_sample": [
      8,
      9,
      10,
      11,
      19,
      27,
      35,
      43,
      51,
      56
    ],
    "saving": [
      {
        "changed": 57,
        "declaration": "honest",
        "declared_dirty": 16,
        "dirty": 16,
        "edit": "single pixel, tile interior",
        "payloads_moved": 16,
        "recompute_fraction": 0.3877551020408163,
        "recomputed": 57,
        "root_moved": true,
        "total_nodes": 147
      },
      {
        "changed": 49,
        "declaration": "honest",
        "declared_dirty": 15,
        "dirty": 15,
        "edit": "sub-threshold grey block at a core boundary",
        "payloads_moved": 15,
        "recompute_fraction": 0.3333333333333333,
        "recomputed": 49,
        "root_moved": true,
        "total_nodes": 147
      },
      {
        "changed": 59,
        "declaration": "honest",
        "declared_dirty": 18,
        "dirty": 18,
        "edit": "scattered pair, opposite corners",
        "payloads_moved": 18,
        "recompute_fraction": 0.4013605442176871,
        "recomputed": 59,
        "root_moved": true,
        "total_nodes": 147
      },
      {
        "changed": 33,
        "declaration": "honest",
        "declared_dirty": 8,
        "dirty": 8,
        "edit": "single pixel against the right canvas edge (window clipped)",
        "payloads_moved": 8,
        "recompute_fraction": 0.22448979591836735,
        "recomputed": 33,
        "root_moved": true,
        "total_nodes": 147
      },
      {
        "changed": 42,
        "declaration": "honest",
        "declared_dirty": 16,
        "dirty": 16,
        "edit": "random 5x5 polarity flip #4",
        "payloads_moved": 16,
        "recompute_fraction": 0.2857142857142857,
        "recomputed": 42,
        "root_moved": true,
        "total_nodes": 147
      },
      {
        "changed": 20,
        "declaration": "honest",
        "declared_dirty": 6,
        "dirty": 6,
        "edit": "random 2x2 polarity flip #5",
        "payloads_moved": 6,
        "recompute_fraction": 0.1360544217687075,
        "recomputed": 20,
        "root_moved": true,
        "total_nodes": 147
      }
    ],
    "total_nodes": 147,
    "window_vs_bbox": [
      {
        "bbox": 16,
        "edit": "single pixel, tile interior",
        "window": 16
      },
      {
        "bbox": 15,
        "edit": "sub-threshold grey block at a core boundary",
        "window": 15
      },
      {
        "bbox": 64,
        "edit": "scattered pair, opposite corners",
        "window": 18
      },
      {
        "bbox": 8,
        "edit": "single pixel against the right canvas edge (window clipped)",
        "window": 8
      },
      {
        "bbox": 16,
        "edit": "random 5x5 polarity flip #4",
        "window": 16
      },
      {
        "bbox": 6,
        "edit": "random 2x2 polarity flip #5",
        "window": 6
      }
    ]
  },
  "D": {
    "blind_verdict_on_naive": "ADMIT",
    "edit": {
      "amp": 0.49,
      "h": 24,
      "tile": 32,
      "w": 8,
      "x_right": 32
    },
    "honest_dirty": 15,
    "honest_recomputed": 49,
    "n_stale": 14,
    "naive_dirty": [
      32
    ],
    "naive_recomputed": 9,
    "naive_verdict": {
      "admit": true,
      "det_ok": true,
      "eps_max": 0.25774161560842457,
      "mrc_ok": true,
      "n_tiles": 64,
      "pfail_quanta": 0,
      "worst_epe_nm": 14.434782608695652
    },
    "tampers": {
      "bool_published_where_a_number_belongs": "REJECT",
      "index_rebound": "REJECT",
      "path_truncated": "REJECT",
      "payload_tampered": "REJECT",
      "published_admit_flipped_on_a_rejecting_reticle": "REJECT",
      "published_verdict_tampered": "REJECT",
      "salt_swapped": "REJECT",
      "sibling_digest_tampered": "REJECT",
      "sibling_fold_tampered_level0": "REJECT",
      "sibling_fold_tampered_upper_stage": "REJECT"
    },
    "truth_verdict": {
      "admit": false,
      "det_ok": false,
      "eps_max": 0.25774161560842457,
      "mrc_ok": true,
      "n_tiles": 64,
      "pfail_quanta": 0,
      "worst_epe_nm": 18.516407579696594
    },
    "truth_worst_epe_nm": 18.516407579696594,
    "under_report_epe_nm": 4.081624971000942,
    "under_report_eps": 0.0,
    "wrong_admit": true
  },
  "E": {
    "child": {
      "blocked": [
        "litholab",
        "numpy"
      ],
      "escape_bound": 0.0,
      "n_openings": 64,
      "reason": "folded_verdict",
      "verdict": "REJECT",
      "work_hashes": 384
    },
    "density_r2": 0.8849011986125437,
    "distinct_payloads_linespace": 18,
    "distinct_payloads_varied": 55,
    "leak_scan": {
      "blob_bytes": 114305,
      "clean": true,
      "hit_indices": [],
      "n_hits": 0,
      "n_needles": 15
    },
    "leak_scan_positive_control": {
      "blob_bytes": 11829,
      "clean": false,
      "hit_indices": [
        10
      ],
      "n_hits": 1,
      "n_needles": 15
    },
    "min_openings_1e-3": 64,
    "min_openings_table": {
      "64": {
        "0.001": 64,
        "0.01": 64,
        "0.1": 58,
        "0.5": 32
      },
      "1024": {
        "0.001": 1023,
        "0.01": 1014,
        "0.1": 922,
        "0.5": 512
      },
      "16384": {
        "0.001": 16368,
        "0.01": 16221,
        "0.1": 14746,
        "0.5": 8192
      }
    },
    "n_geometry_encodings": 5,
    "no_opening": {
      "detail": "this is an optimistic construction: a root with no openings is consistent with any tile set, so no soundness has been purchased",
      "escape_bound": 1.0,
      "min_openings_for_target": 64,
      "reason": "root_alone_proves_nothing",
      "verdict": "REFUSED"
    },
    "purchasable": {
      "escape_bound": 0.0,
      "min_openings_for_target": 64,
      "n_distinct_openings": 64,
      "n_openings": 64,
      "reason": "folded_verdict",
      "soundness": "OPTIMISTIC: unchallenged tiles are not proven correct. The verdict is the prover's, bound to a commitment and checked for correct aggregation along the opened paths; the escape bound is the price of the tiles that were not opened. It is NOT a bound on this verdict being right: the openings are prover-supplied rather than drawn, and an opening proves membership and aggregation, not that the opened tile's payload is true -- this verifier has no geometry. A reticle whose dependency region was under-declared is ADMITted here with every tile opened and an escape bound of 0.0 (see D1). Only recomputing the tiles detects that.",
      "verdict": "REJECT",
      "work_hashes": 384
    },
    "unpurchasable": {
      "detail": "3 distinct openings buy an escape bound of 9.531e-01; 1.000e-03 was requested",
      "escape_bound": 0.953125,
      "min_openings_for_target": 64,
      "n_distinct_openings": 3,
      "reason": "soundness_not_purchasable",
      "verdict": "REFUSED"
    }
  },
  "R": 48,
  "budgets": {
    "det_bisect": 10,
    "det_max_defocus_nm": 100.0,
    "det_max_dose_pct": 8.0,
    "det_n_grid": 6,
    "epe_nm": 18.0,
    "min_defocus_nm": 20.0,
    "min_dose_pct": 3.0,
    "mr_bisect": 8,
    "mr_n_grid": 6,
    "mrc_min_width_nm": 8.0,
    "n_photons": 100.0,
    "opt_gap_max": null,
    "opt_iters": 120,
    "pfail": 0.05,
    "stoch_Z_nm": 60.0,
    "stoch_band_frac": 0.6,
    "stoch_dose": 0.05,
    "stoch_grad_frac": 0.35,
    "stoch_n_grid": 12,
    "stoch_safety": 1.5
  },
  "checks": [
    {
      "detail": "locally defined: none; imported from succinct_certificate: ['_internal_node', '_leaf_node', '_pad_leaf']",
      "gate": true,
      "id": "A1 the fold is imported from S252, not re-implemented here",
      "imported": [
        "_internal_node",
        "_leaf_node",
        "_pad_leaf"
      ],
      "locally_defined": [],
      "ok": true
    },
    {
      "base_root": "28a2082f16056a02be7c7b6233b8a59c670e17de66614f3fe5cebd14d9709e17",
      "detail": "S252's fold_pair replaced by an always-admitting one (associative and identity-preserving, so the build's own collapse check still passes and this measures the code path rather than the check): root 28a2082f1605 -> ed725410f26d, folded det_ok False -> True",
      "gate": true,
      "id": "A2 replacing S252's fold moves THIS module (code path, not import)",
      "ok": true,
      "planted_root": "ed725410f26d8540a9ebc2b45d83881cbf986514cc68447a89be95a105c17c44"
    },
    {
      "detail": "60 payload sets x 5 fan-in shapes (sizes 6-64, non-power-of-2 included so padding is exercised): 0 disagreements",
      "disagreements": 0,
      "gate": true,
      "id": "A3 level collapse: the k-stage fold equals the flat fold, exactly",
      "n_sets": 60,
      "ok": true,
      "shapes": [
        [
          4,
          4
        ],
        [
          2
        ],
        [
          8
        ],
        [
          2,
          2,
          2
        ],
        [
          3,
          5
        ]
      ]
    },
    {
      "byte_identical_at": [
        2,
        8,
        16,
        32,
        64
      ],
      "detail": "one-stage reticle root 28a2082f16056a02 vs succinct.accumulate 28a2082f16056a02 at n=64. Swept over [2, 3, 5, 6, 7, 8, 15, 16, 17, 31, 32, 33, 63, 64]: byte-identical at [2, 8, 16, 32, 64] and DIVERGENT at [3, 5, 6, 7, 15, 17, 31, 33, 63] -- i.e. exactly at the powers of two, because those are the sizes at which no pad leaf is minted and the reticle's per-stage pad-salt stream cannot show. Where the roots diverge the 14 real leaf-digest lists and the folded verdicts still agree at every size (0 moved), so the difference is confined to the pad slots and the recursion is a generalisation of the committed format and not a second one. Read the claim at that scope: byte identity with S252 is a power-of-two property, not a universal one.",
      "divergent_at": [
        3,
        5,
        6,
        7,
        15,
        17,
        31,
        33,
        63
      ],
      "gate": true,
      "id": "A4 collapsed to one stage it reproduces S252's root byte for byte",
      "leaf_or_verdict_moved_at": [],
      "ok": true,
      "reticle_root": "28a2082f16056a02be7c7b6233b8a59c670e17de66614f3fe5cebd14d9709e17",
      "s252_root": "28a2082f16056a02be7c7b6233b8a59c670e17de66614f3fe5cebd14d9709e17",
      "sizes_swept": [
        2,
        3,
        5,
        6,
        7,
        8,
        15,
        16,
        17,
        31,
        32,
        33,
        63,
        64
      ]
    },
    {
      "detail": "6 tiles at fan-in 3 pads 2 slots (non-vacuity: the honest build really does pad, and reports n_tiles=6). Padding with a duplicate of a real node instead of the monoid identity double-counts n_tiles and pfail_quanta at every stage; the level-collapse check refuses to emit.",
      "gate": true,
      "honest_n_tiles": 6,
      "id": "A5 padding by duplication instead of identity is REFUSED at build",
      "n_pad_slots": 2,
      "ok": true,
      "planted_n_tiles": null
    },
    {
      "admit": true,
      "detail": "64 tiles, folded verdict admit=True worst_epe=14.4348 nm eps_max=0.25669 -- identical to the region certificate's own aggregate (28s)",
      "eps_bound": 0.25668743100224034,
      "gate": true,
      "id": "B1 the reticle commits 64 REAL composed tile certificates",
      "n_tiles": 64,
      "ok": true,
      "worst_epe_nm": 14.434782608695652
    },
    {
      "detail": "receipt bytes {64: 852, 1024: 859, 16384: 865} over a 256x range of tile counts (spread 13 B, all of it the decimal width of n_tiles and the fold legs)",
      "gate": true,
      "id": "B2 the receipt is O(1): its size does not grow with the tile count",
      "ok": true,
      "receipt_bytes": {
        "64": 852,
        "1024": 859,
        "16384": 865
      },
      "spread_bytes": 13
    },
    {
      "detail": "64/64 openings verify digest chain AND fold chain in 6 hash steps each; 0 failures",
      "failures": [],
      "gate": true,
      "id": "B3 every one of the 64 openings verifies through the stdlib verifier",
      "ok": true,
      "path_len": 6
    },
    {
      "detail": "16 block roots and 4 field roots published; every block verdict equals the flat fold of its 4 tiles; 0 disagreements",
      "disagreements": [],
      "gate": true,
      "id": "B4 each block root folds exactly its own tiles (the hierarchy is real)",
      "n_blocks": 16,
      "n_fields": 4,
      "ok": true
    },
    {
      "detail": "one edited pixel invalidates {0: 1, 8: 4, 16: 4, 24: 4, 32: 9, 48: 16, 64: 25} tiles at R=[0, 8, 16, 24, 32, 48, 64]. The DoD's literal reading is recoverable only at R=0 -- i.e. by assuming the cross-tile optical coupling away, which is the shortcut eps(R) exists to price. At the certified R=48 it is 16 tiles, not 1.",
      "gate": true,
      "id": "C1 'exactly one path' holds at R=0 and NOWHERE the physics reaches",
      "ladder": {
        "0": 1,
        "8": 4,
        "16": 4,
        "24": 4,
        "32": 9,
        "48": 16,
        "64": 25
      },
      "ok": true
    },
    {
      "detail": "6 edits; window \u2286 bbox in all of them (0 violations). The inclusion is the only direction that may hold -- a scattered edit's bounding box is far larger than its support -- so the check is stated in that direction.",
      "gate": true,
      "id": "C2 the exact window rule is contained in the committed bbox rule",
      "ok": true,
      "rows": [
        {
          "bbox": 16,
          "edit": "single pixel, tile interior",
          "window": 16
        },
        {
          "bbox": 15,
          "edit": "sub-threshold grey block at a core boundary",
          "window": 15
        },
        {
          "bbox": 64,
          "edit": "scattered pair, opposite corners",
          "window": 18
        },
        {
          "bbox": 8,
          "edit": "single pixel against the right canvas edge (window clipped)",
          "window": 8
        },
        {
          "bbox": 16,
          "edit": "random 5x5 polarity flip #4",
          "window": 16
        },
        {
          "bbox": 6,
          "edit": "random 2x2 polarity flip #5",
          "window": 6
        }
      ]
    },
    {
      "bbox": 64,
      "detail": "worst gap: 'scattered pair, opposite corners' -- window 18 tiles, bbox 64 (3.56x). The committed incremental gates use bbox and are sound but pay that factor.",
      "gate": false,
      "id": "C2b window-vs-bbox conservatism",
      "ok": true,
      "window": 18,
      "worst_edit": "scattered pair, opposite corners"
    },
    {
      "detail": "6 edits: recomputed set == union of paths in both inclusions (0 failures); the nodes whose digest MOVED are exactly the paths of the leaves whose payload moved (0); and the whole updated tree is byte-identical to a from-scratch rebuild, node for node (0)",
      "failures": {
        "changed": [],
        "recomputed": [],
        "tree_equality": []
      },
      "gate": true,
      "id": "C3 an edit recomputes EXACTLY the union of its dirty leaves' root-paths",
      "ok": true
    },
    {
      "detail": "single pixel: 16 dirty tiles -> 57/147 nodes (39%); sub-threshold grey block at a core boundary: 15 dirty tiles -> 49/147 nodes (33%); scattered pair: 18 dirty tiles -> 59/147 nodes (40%); single pixel against the right canvas edge (window clipped): 8 dirty tiles -> 33/147 nodes (22%); random 5x5 polarity flip #4: 16 dirty tiles -> 42/147 nodes (29%); random 2x2 polarity flip #5: 6 dirty tiles -> 20/147 nodes (14%)",
      "gate": false,
      "id": "C4 the saving: nodes recomputed vs a full rebuild",
      "ok": true,
      "rows": [
        {
          "changed": 57,
          "declaration": "honest",
          "declared_dirty": 16,
          "dirty": 16,
          "edit": "single pixel, tile interior",
          "payloads_moved": 16,
          "recompute_fraction": 0.3877551020408163,
          "recomputed": 57,
          "root_moved": true,
          "total_nodes": 147
        },
        {
          "changed": 49,
          "declaration": "honest",
          "declared_dirty": 15,
          "dirty": 15,
          "edit": "sub-threshold grey block at a core boundary",
          "payloads_moved": 15,
          "recompute_fraction": 0.3333333333333333,
          "recomputed": 49,
          "root_moved": true,
          "total_nodes": 147
        },
        {
          "changed": 59,
          "declaration": "honest",
          "declared_dirty": 18,
          "dirty": 18,
          "edit": "scattered pair, opposite corners",
          "payloads_moved": 18,
          "recompute_fraction": 0.4013605442176871,
          "recomputed": 59,
          "root_moved": true,
          "total_nodes": 147
        },
        {
          "changed": 33,
          "declaration": "honest",
          "declared_dirty": 8,
          "dirty": 8,
          "edit": "single pixel against the right canvas edge (window clipped)",
          "payloads_moved": 8,
          "recompute_fraction": 0.22448979591836735,
          "recomputed": 33,
          "root_moved": true,
          "total_nodes": 147
        },
        {
          "changed": 42,
          "declaration": "honest",
          "declared_dirty": 16,
          "dirty": 16,
          "edit": "random 5x5 polarity flip #4",
          "payloads_moved": 16,
          "recompute_fraction": 0.2857142857142857,
          "recomputed": 42,
          "root_moved": true,
          "total_nodes": 147
        },
        {
          "changed": 20,
          "declaration": "honest",
          "declared_dirty": 6,
          "dirty": 6,
          "edit": "random 2x2 polarity flip #5",
          "payloads_moved": 6,
          "recompute_fraction": 0.1360544217687075,
          "recomputed": 20,
          "root_moved": true,
          "total_nodes": 147
        }
      ],
      "total_nodes": 147
    },
    {
      "detail": "8 of 16 blocks contain no dirty tile and every one of their roots is unchanged (0 moved) -- a block owner can prove non-involvement in an edit by publishing one unchanged hash",
      "gate": true,
      "id": "C5 an uninvolved block's root is byte-identical after the edit",
      "moved": [],
      "n_clean_blocks": 8,
      "ok": true
    },
    {
      "detail": "the 10 tiles NEAREST the dependency region (Chebyshev core-distance 1-1 from a dirty tile -- the tightest place the window rule can be wrong, not a stride that lands where nothing could have changed) re-certified from scratch on the EDITED mask: 0 differ. This is the physical precondition the reuse rests on, measured rather than argued -- the window rule is exact because the certificate is a function of the window.",
      "gate": true,
      "id": "C6 a tile OUTSIDE the dependency region recomputes byte-identically",
      "mismatches": [],
      "ok": true,
      "ring_distances": [
        1,
        1,
        1,
        1,
        1,
        1,
        1,
        1,
        1,
        1
      ],
      "sampled": [
        8,
        9,
        10,
        11,
        19,
        27,
        35,
        43,
        51,
        56
      ]
    },
    {
      "blind_verdict_on_naive": "ADMIT",
      "detail": "edit: 24x8 px at amplitude 0.49 (sub-threshold, so no tile's binarised target moves) inside core [32] and hard against the boundary of tile 33. The naive rule refreshes 1 leaf and publishes admit=True; a from-scratch recompute says admit=False because tile 33's worst EPE goes to 18.52 nm against an 18 nm budget. The commitment is not broken -- the blind verifier returns ADMIT on it, every opened path folds correctly -- the DECLARATION was wrong, and nothing in the tree can see that.",
      "elapsed_s": 4.06789162500354,
      "gate": true,
      "honest_dirty": 15,
      "id": "D1 the LITERAL 'one path' rule serves a WRONG ADMIT",
      "naive_admit": true,
      "naive_dirty": [
        32
      ],
      "ok": true,
      "truth_admit": false,
      "truth_worst_epe_nm": 18.516407579696594
    },
    {
      "detail": "same edit, dependency region declared at R=48 (15 tiles): root 98e0a4224eda66fa == from-scratch, all 147 node digests equal, verdict admit=False == truth",
      "gate": true,
      "id": "D2 the honest declaration reproduces the from-scratch tree exactly",
      "n_nodes": 147,
      "ok": true,
      "recomputed": 49,
      "root": "98e0a4224eda66fac2ef98c527ba1896a967b46110bcaf689f2ceeac79f7cb89"
    },
    {
      "detail": "14 tiles moved and were not refreshed. Published worst_epe 14.4348 nm against a true 18.5164 nm -- under-reported by 4.0816 nm; eps_max under-reported by 0.000000. An under-report is the unsound direction: the certificate claims more margin than the mask has.",
      "gate": true,
      "id": "D3 the naive root under-reports the risk legs, not just the boolean",
      "n_stale": 14,
      "naive_worst_epe": 14.434782608695652,
      "ok": true,
      "true_worst_epe": 18.516407579696594,
      "under_report_epe_nm": 4.081624971000942,
      "under_report_eps": 0.0
    },
    {
      "detail": "untampered control on the pre-edit reticle: ADMIT (non-vacuity -- the battery is run on a reticle that DOES admit, so a rejection is attributable to the tamper); untampered control on the EDITED reticle, which the flip tamper needs: REJECT. 10 tampers -> {'payload_tampered': 'REJECT', 'sibling_digest_tampered': 'REJECT', 'sibling_fold_tampered_level0': 'REJECT', 'sibling_fold_tampered_upper_stage': 'REJECT', 'path_truncated': 'REJECT', 'published_verdict_tampered': 'REJECT', 'index_rebound': 'REJECT', 'salt_swapped': 'REJECT', 'published_admit_flipped_on_a_rejecting_reticle': 'REJECT', 'bool_published_where_a_number_belongs': 'REJECT'}; ADMITted: none; not REJECTed: none. Every tamper is required to come back REJECT, not merely 'not ADMIT': the single-opening tampers used to be scored at a target their openings could not buy, so REFUSED was returned before the opening was ever checked and the battery passed with the opening check removed entirely. The upper-stage fold tamper is the recursion-specific one: S252's tree has no stage above the leaves to tamper with. The `admit` flip is the one the fold comparison used to miss -- it compared six named legs and omitted the only leg the verdict is read off -- and the bool tamper is the one `_close` used to coerce.",
      "gate": true,
      "id": "D4 the tamper battery: none of them admitted",
      "not_rejected": [],
      "ok": true,
      "tampers": {
        "bool_published_where_a_number_belongs": "REJECT",
        "index_rebound": "REJECT",
        "path_truncated": "REJECT",
        "payload_tampered": "REJECT",
        "published_admit_flipped_on_a_rejecting_reticle": "REJECT",
        "published_verdict_tampered": "REJECT",
        "salt_swapped": "REJECT",
        "sibling_digest_tampered": "REJECT",
        "sibling_fold_tampered_level0": "REJECT",
        "sibling_fold_tampered_upper_stage": "REJECT"
      },
      "untampered_verdict": "ADMIT",
      "untampered_verdict_rejecting": "REJECT"
    },
    {
      "detail": "6 real tiles at fan-in 4, padded to 8: tile index 6 outside 0..5. Pads carry DOMAIN_PAD and the identity verdict, so they can neither be opened nor contribute to n_tiles.",
      "gate": true,
      "id": "D5 a padding slot cannot be opened as a tile",
      "n_real": 6,
      "ok": true,
      "refusal": "tile index 6 outside 0..5"
    },
    {
      "child": {
        "blocked": [
          "litholab",
          "numpy"
        ],
        "escape_bound": 0.0,
        "n_openings": 64,
        "reason": "folded_verdict",
        "verdict": "REJECT",
        "work_hashes": 384
      },
      "child_exit": 0,
      "detail": "child exit 0; it asserted ['litholab', 'numpy'] unimportable (ImportError observed for each) and returned 'REJECT', identical to the in-process 'REJECT'; 64 openings, 384 hash steps",
      "gate": true,
      "id": "E1 the foundry verifies in a process where numpy and litholab do not exist",
      "in_process_verdict": "REJECT",
      "ok": true
    },
    {
      "detail": "114305 B of receipt+64 openings scanned for 15 needles (5 geometry encodings of the mask UNDER COMMITMENT x raw/base64/hex): 0 hits. Positive control -- the same needle list against a receipt that leaks the packed raster as base64, the way a careless serialiser would -- fires on exactly ['packed_bits:b64'], so the absence above is a measurement and not an untested scanner. Receipt keys are exactly ['format', 'n_tiles', 'path_len', 'region_verdict', 'root_hex', 'scope', 'stage_fan_in']",
      "gate": true,
      "id": "E2 the receipt+openings carry no geometry, and the scanner has teeth",
      "needles": [
        "raster_f64:raw",
        "raster_f64:b64",
        "raster_f64:hex",
        "pre_edit_raster_f64:raw",
        "pre_edit_raster_f64:b64",
        "pre_edit_raster_f64:hex",
        "edited_core_f64:raw",
        "edited_core_f64:b64",
        "edited_core_f64:hex",
        "packed_bits:raw",
        "packed_bits:b64",
        "packed_bits:hex",
        "bytes_u8:raw",
        "bytes_u8:b64",
        "bytes_u8:hex"
      ],
      "ok": true,
      "positive_control": {
        "blob_bytes": 11829,
        "clean": false,
        "hit_indices": [
          10
        ],
        "n_hits": 1,
        "n_needles": 15
      },
      "scan": {
        "blob_bytes": 114305,
        "clean": true,
        "hit_indices": [],
        "n_hits": 0,
        "n_needles": 15
      },
      "unexpected_receipt_keys": []
    },
    {
      "detail": "verdict REFUSED (root_alone_proves_nothing); escape bound 1.0, and it reports that 64 openings would buy 1e-3. 'The foundry verifies only the root' is the DoD's most generous clause and this is the honest answer to it.",
      "gate": true,
      "id": "E3 a root with no openings is REFUSED, not admitted",
      "ok": true,
      "result": {
        "detail": "this is an optimistic construction: a root with no openings is consistent with any tile set, so no soundness has been purchased",
        "escape_bound": 1.0,
        "min_openings_for_target": 64,
        "reason": "root_alone_proves_nothing",
        "verdict": "REFUSED"
      }
    },
    {
      "detail": "a customer granting 3 openings buys an escape bound of 9.531e-01 against a requested 1e-3, so the verdict is REFUSED (soundness_not_purchasable) naming the 64 openings that would buy it -- not clipped to the best available, which is the failure mode this estate refuses elsewhere. A malformed target (-1.0) is REFUSED as 'malformed' rather than trivially satisfied.",
      "gate": true,
      "granted": 3,
      "id": "E4 soundness the granted openings cannot buy is REFUSED, not answered anyway",
      "malformed": {
        "detail": "target_escape -1.0 is not a probability",
        "reason": "malformed",
        "verdict": "REFUSED"
      },
      "ok": true,
      "result": {
        "detail": "3 distinct openings buy an escape bound of 9.531e-01; 1.000e-03 was requested",
        "escape_bound": 0.953125,
        "min_openings_for_target": 64,
        "n_distinct_openings": 3,
        "reason": "soundness_not_purchasable",
        "verdict": "REFUSED"
      }
    },
    {
      "detail": "64 openings buy 0.000e+00 <= 1e-3, for 384 hash steps against 64 tiles. The EDITED reticle (tile 33 over budget) comes back REJECT; the pre-edit one comes back ADMIT. Both are reachable through the same blind path, so neither is a rubber stamp -- a verifier that only ever said one of them would pass a one-sided check.",
      "edited": "REJECT",
      "gate": true,
      "id": "E5 a purchasable level is answered, and both answers are reachable",
      "min_openings": 64,
      "ok": true,
      "pre_edit": "ADMIT",
      "result": {
        "escape_bound": 0.0,
        "min_openings_for_target": 64,
        "n_distinct_openings": 64,
        "n_openings": 64,
        "reason": "folded_verdict",
        "soundness": "OPTIMISTIC: unchallenged tiles are not proven correct. The verdict is the prover's, bound to a commitment and checked for correct aggregation along the opened paths; the escape bound is the price of the tiles that were not opened. It is NOT a bound on this verdict being right: the openings are prover-supplied rather than drawn, and an opening proves membership and aggregation, not that the opened tile's payload is true -- this verifier has no geometry. A reticle whose dependency region was under-declared is ADMITted here with every tile opened and an escape bound of 0.0 (see D1). Only recomputing the tiles detects that.",
        "verdict": "REJECT",
        "work_hashes": 384
      }
    },
    {
      "density_r2": 0.8849011986125437,
      "density_range": [
        0.125,
        0.875
      ],
      "detail": "an opening reveals its tile's five payload legs and nothing else -- but those legs are a channel. On a mask whose per-tile density varies over [0.12, 0.88] (the line/space mask is uniformly 0.50, so it can measure nothing here), least-squares reconstruction of core density from (eps, worst_epe, det_ok) over 64 tiles gives **R^2 = 0.885**, with 55 distinct payload values (18 on the line/space mask). Not claimed absent, and no leakage bound is claimed either. The receipt itself discloses the region's aggregate legs by design: that IS the certificate.",
      "distinct_payloads_linespace": 18,
      "distinct_payloads_varied": 55,
      "gate": false,
      "id": "E6 what an opening leaks about geometry",
      "n_tiles": 64,
      "ok": true
    },
    {
      "detail": "for one corrupted tile the escape bound is exactly (n-k)/n, so k >= n(1-t): n=64: t=0.5 needs k=32, t=0.1 needs k=58, t=0.01 needs k=64, t=0.001 needs k=64; n=1024: t=0.5 needs k=512, t=0.1 needs k=922, t=0.01 needs k=1014, t=0.001 needs k=1023; n=16384: t=0.5 needs k=8192, t=0.1 needs k=14746, t=0.01 needs k=16221, t=0.001 needs k=16368. The CERTIFICATE is O(1) and an OPENING is O(log n); the assurance is not. Anyone quoting this as succinct verification is quoting the receipt size, not the soundness.",
      "gate": false,
      "id": "E8 the sampling bound does not make VERIFICATION succinct",
      "min_openings": {
        "64": {
          "0.001": 64,
          "0.01": 64,
          "0.1": 58,
          "0.5": 32
        },
        "1024": {
          "0.001": 1023,
          "0.01": 1014,
          "0.1": 922,
          "0.5": 512
        },
        "16384": {
          "0.001": 16368,
          "0.01": 16221,
          "0.1": 14746,
          "0.5": 8192
        }
      },
      "ok": true
    },
    {
      "detail": "64 tiles given the SAME payload produce 64 distinct leaf digests (index- and salt-bound), so a leaf digest does not reveal that two tiles agree",
      "gate": true,
      "id": "E7 identical payloads at different indices give distinct leaf digests",
      "n_distinct": 64,
      "ok": true
    },
    {
      "detail": "every key declared in RECORDINGS matches a check this run emitted, so no exemption is sitting there covering nothing",
      "gate": true,
      "id": "F1 the recordings map has no stale entries",
      "ok": true
    }
  ],
  "core": 32,
  "elapsed_s": 38.34915441600606,
  "eps_safety": 1.5,
  "fan_in": [
    4,
    4
  ],
  "grid": 256,
  "honest": [
    "**Simulator-relative (SOCS), not silicon.** Every payload is `certify_tile_composed`'s output at grid 256 / core 32 / R 48, certified up to the same disclosed cross-tile residual `eps(R)` as `certify_region_composed`. A commitment is a commitment: not a signature, not a mask-shop approval.",
    "**The soundness model is optimistic.** An opening proves its tile is bound to the root and correctly folded along its path; an unchallenged tile is not proven correct. This is a succinct *certificate*, not a succinct *proof* of the certification \u2014 that needs recursive proof composition, which is not here. The escape bound is reported and a root with no openings is REFUSED.",
    "**The escape bound prices sampling, not correctness, and D1 is the counterexample.** It is S252's model inherited unchanged: the probability that a prover with a corrupted tile survives *k* uniform challenges. Neither half of that describes this verifier. The openings are prover-supplied \u2014 there is no nonce, no Fiat\u2013Shamir, no verifier-side draw \u2014 and an opening proves membership and correct aggregation, not that the opened payload is true, because the verifier has no geometry by construction. So in D1 the under-declared reticle is ADMITted with **all 64 tiles opened and an escape bound of exactly 0.0**, while the from-scratch truth is REJECT. Every tile was challenged; the bound was zero; the answer was wrong. E8 is careful about what the bound *costs* and this is what it *means*. Found by an adversarial pass over this diff, not by the batteries.",
    "**A4's byte-identity with S252 is a power-of-two property.** The single-stage reticle reproduces `succinct_certificate.accumulate`'s root byte for byte at n \u2208 {2, 8, 16, 32, 64} and **diverges at every non-power-of-two n**, because the reticle derives a stage's pad salts from that stage's own separated stream while S252 derives leaves and pads from one. The check used to be a single comparison at n = 64 \u2014 the one size class where the difference cannot show \u2014 under the unqualified heading \"not a fork of the committed format\". It is now swept, and the divergence is localised: the real leaf digests and the folded verdict agree at every size, so it is confined to the pad slots. The engine is deliberately not changed to match, because the per-stage stream is what stops a pad minted at one stage being replayed at another.",
    "**The commitment cannot police the declaration, and D1 is that fact.** `update` faithfully publishes a root over whatever leaves it was told are dirty. Nothing cryptographic detects an under-declared dependency region; only recomputing the tiles does. The correctness of `dirty_tiles_by_window` is therefore load-bearing for the whole construction, and it is a geometric argument about the window \u2014 checked against real re-certification in C6 on a sample of tiles, not proved.",
    "**64 tiles is not a reticle.** The saving and the O(1) receipt are demonstrated at 64 real tiles and the receipt's flatness in `n` at up to 16384 synthetic ones. A reticle is ~2.4e12 core tiles at this pixel size; nothing here addresses the per-tile certification cost or the dense-raster memory ceiling, which S252 already named as the first blocker and which this item does not move.",
    "**`mrc_ok` is region-level.** `certified_composition` runs one geometry-local MRC check over the whole region \u2014 that is why it composes exactly \u2014 so every leaf carries the region's own value. An opening's `mrc_ok` therefore speaks about the region, not about the opened tile.",
    "**The yield leg is exercised synthetically.** `certify_region_composed` composes the two cleanest legs (MRC + deterministic PW-EPE) and carries no per-tile failure mass, so `pfail_sum` is 0.0 on every real payload and the integer-quanta fold is exercised by the random batteries in A3 rather than by the real reticle.",
    "**E2 is a scan, not a confidentiality proof.** It searches five encodings of the raster and finds none. It cannot see the payload channel, which E6 measures separately and which is real. No differential-privacy or leakage-bound claim is made. Its needles were also, until this pass, taken from the **pre-edit** mask while the receipt under scan commits to the edited one, with the \"edited core\" slice hard-coded to the wrong tile \u2014 so two of the four encodings could not have matched even a verbatim leak, and the check would still have reported a clean scan. Corrected to the mask under commitment; the correction removes a blind spot and, unlike the other fixes in this pass, **cannot be proved red**, because widening a needle set that finds nothing still finds nothing.",
    "**D1 is one edit found by search.** It is a genuine wrong ADMIT on a real recompute, and it is one point: it establishes that the literal reading is unsound, not a rate at which naive declarations fail.",
    "**An ADMIT means nothing unless the foundry pins the root it expects.** `verify_receipt` answers about the receipt it is handed. A prover whose 64-tile region honestly REJECTs can mint a fresh **one-tile** receipt over an admitting payload and hand it over with one opening: every check passes, the escape bound is 0.0, and the verdict is ADMIT \u2014 with no geometry and no search, where D1 needed both. That is the protocol assumption that the root arrives out of band, and until an adversarial pass over the committed diff minted exactly that receipt it was **not expressible in this API and written down nowhere**. `expected_root_hex` now exists and mismatches are REFUSED; the assumption is still an assumption, it is simply stated and checkable.",
    "**The compression figure was inflated by an unmeasured constant, and is now measured.** The flat-record baseline read `n_tiles * 201` \u2014 a bare literal with no derivation anywhere \u2014 and was published as \"12864 B of flat per-tile LCERT records (15\u00d7)\". The canonical serialisation of the same payloads measures ~105 B/tile, so the honest figure is ~7.9\u00d7. The number moved **down** when it was measured, which is the direction that makes the correction worth recording."
  ],
  "item": "F6-04",
  "operating_point": "grid 256 / core 32 / R 48 / eps_safety 1.5 / epe_nm 18 -- F6-03's operating point verbatim, so the payloads committed here are the same certificates that item reasons about",
  "pixel_nm": 2.0,
  "scope": "Recursive (tile->block->field->reticle) fold-annotated commitment over real composed per-tile certificates, with an incremental edit rule proved minimal and a stdlib-only blind verifier. Simulator-relative (SOCS), NOT silicon. Optimistic/fraud-proof soundness: unchallenged tiles are not proven correct.",
  "tier": "full"
}
