# EXPECTED — `extraction-to-circuit-boundary`

<!-- kit:claim witness="PYTHONPATH=. python3 scripts/audit/verify_passive_export_gate.py" extract="A: nonpassive_before=(\w+) passive_after=(\w+) enforced=(\w+) file_passive=(\w+) fit_rms=([0-9.eE+-]+) sigma_max_before=([0-9.eE+-]+) sigma_max_after=([0-9.eE+-]+) passivity_margin_after=([0-9.eE+-]+)\s+B: unenforced_stays_nonpassive=(\w+)\s+C: passive_after=(\w+)" -->
<!-- repro:expect [{"group": 1, "equals": "True"}, {"group": 2, "equals": "True"}, {"group": 3, "equals": "True"}, {"group": 4, "equals": "True"}, {"group": 5, "near": 0.104, "abs_tol": 0.005}, {"group": 6, "near": 1.1985, "abs_tol": 0.002}, {"group": 7, "near": 0.9987, "abs_tol": 0.002}, {"group": 8, "near": 0.0013, "abs_tol": 0.002}, {"group": 9, "equals": "True"}, {"group": 10, "equals": "True"}] -->

**The claim** (`top40.json` rank 28, `CROWN_JEWELS_RESOLVED.md` §2): extraction ends in passive N-port models that
a circuit simulator will accept.

**What this packet reproduces.** `verify_passive_export_gate.py` (§9 Gate 82) builds a two-port rational network
whose largest singular value is 1.2 at DC, so it is deliberately NON-passive. It runs the export path
`genesis.io.passive_export.enforce_passive_network` / `write_passive_touchstone` on it, and asks scikit-rf, a
library Genesis does not own, to judge the result.

| parsed group | expected | meaning |
|---|---|---|
| 1 | True | case A: the input network really is non-passive (skrf `is_passive()` False) |
| 2 | True | case A: the enforced macromodel is passive |
| 3 | True | case A: enforcement actually ran |
| 4 | True | case A: the written `.s2p`, read back by skrf, is passive |
| 5 | 0.104 ± 0.005 | case A: RMS error of the passive fit against the input S-data, the approximation cost |
| 6 | 1.1985 ± 0.002 | case A: **σ_max(S) of the input network, derived by the lane** — > 1 is what "non-passive" means |
| 7 | 0.9987 ± 0.002 | case A: **σ_max(S) of the enforced macromodel, derived by the lane** — ≤ 1 is what a circuit simulator accepts |
| 8 | 0.0013 ± 0.002 | case A: the passivity margin, 1 − σ_max after; ≥ 0 is now a necessary condition of the gate's PASS |
| 9 | True | case B: without enforcement the same network stays non-passive, so the enforcement is load-bearing |
| 10 | True | case C: an already-passive network stays passive |

**Sprint S18 — the claim is bound to a number this repository derives.** kit2's exhaustive pass over
**1,647** numeric candidates in the listed inputs found **zero** that moved this packet's claim, and it
graded FAIL for exactly that reason: every verdict was a boolean scikit-rf returned, and the one number
(`fit_rms`) is scikit-rf's fit error. Passivity, though, is not an opinion — it is
σ_max(S(f)) ≤ 1 — so `genesis/io/passive_export.max_singular_value` now computes it with numpy on the
lane's own model data, on both sides of the enforcement, and `verify_passive_export_gate.py` adds
**two new necessary conditions** to its PASS: the input's σ_max must exceed 1 (it really is
non-passive) and the enforced model's margin must be ≥ 0 (it really is passive). Nothing was removed
and no tolerance was widened; groups 1–5 and the old verdicts are unchanged, and what were groups 6–7
are now 9–10.

**Tolerance.**
- The six verdicts are exact.
- σ_max before, σ_max after and the margin are printed to four decimals and given ±0.002 — the same
  reasoning as the fit error's band: vector fitting and Hamiltonian enforcement are floating-point
  iterations, so other LAPACK builds move the last digits. The band is far tighter than any
  claim-moving change: the gate's constructed σ_max is 1.2, and skipping enforcement leaves
  σ_max_after at 1.1985 with a margin of −0.1985, both an order of magnitude outside it.
- The fit error is printed to three significant figures, `1.04e-01`. It reproduced bit-identically against the
  committed witness (0.10417448468198073, scikit-rf 1.10.0). The ±0.005 band admits other scikit-rf/LAPACK builds
  (vector fitting and the Hamiltonian enforcement are floating-point iterations) but not a different enforcement
  outcome: skipping enforcement drops the error to machine precision (`2.41e-16`, measured by the lab's S14
  mutation), which is far outside the band.

**Not covered.** The corpus-leakage measurement named under the same register entry. `dataroom/witness_quality.json`
records it as unbound by this command.

**Measured** 2026-09-17 in a tree holding exactly commit `cb6d9d7d`: exit 0 in 11.7 s under the input tracer. The
same run prints a scikit-rf `UserWarning` that the DC point cannot be preserved; the warning is not parsed.
