The Defect Record

The Defect Record

Kept with the same discipline as the experiment record, because the aggregate says things no individual bug report can. The log contains 519 defects, one line each, generated from defects.yaml and checked in the gate.

Class Count The system …
soundness 108 asserted something false about the mathematics
validity 128 was correct, but the measurement did not bear on the question
bookkeeping 194 recorded something its own evidence contradicts
robustness 70 did not finish, or finished only by luck
performance 19 worked, but cost far more than it should

One entry is filed under a class it only half fits, and the table reads accordingly. D-484 carries two defects with a single cause: an escape screen that finished only when the runner was kind, which is robustness, and a behavioural lane that completed but cost 1020.77 s where 718.52 s was available, which is performance in D-456’s sense. It is filed as robustness, for the half that took main red, so the performance row here reads one low. The entry names that call rather than leaving it implicit; the alternative was two ids sharing every other field.

D-502 remains open: the implicit local pre-push allocation left a costly partial reachable-test selection serial until its 900-second command cap. A ten-worker retry completed below that cap under a different PACK_JOBS shape, so it is an observed workaround rather than a controlled speedup or validation of the proposed cost-aware allocation. That allocation remains unimplemented and needs measurement.

Two observations the log exists to make.

84 of the 108 soundness defects pointed in the flattering direction, where the error looks like a success. That is the dangerous class, and it is the majority of it.

The automated gate has caught eighty-two defects in 519, and no soundness defect ever. Every soundness failure was found by a control cell whose answer was known in advance, a rule written down before the measurement, a generated view contradicting its source, or someone reading carefully. Gates confirm what you already thought to check; these were found by devices built to be surprised. Gate-detected entries here are mechanical process, implementation, or test-validity failures, found by contiguity, integration, mutation-anchor, reconciliation, or known-answer checks. The supported distinction is that the gate has never caught the mathematics being wrong.

D-490 is contained, and it is the log’s cleanest case of a detector that fired correctly and said nothing usable. The Pages job draws the explainer to a PDF twice and requires the two to agree; on 2026-09-10 they did not, by two bytes out of 786119, and the failure line carried those two lengths and nothing else — no object, no offset, no kind, and both renders discarded. It also asserted a cause: that something the page draws was unfinished when it was captured. A control on one container changed the PDF by 211351 bytes when the print faces were omitted, while forty complete renders on that host agreed. That makes the measured missing-face state a poor match for the observed two-byte delta on that host; it does not identify the runner’s cause or rule out another readiness failure. The cause stays open under think-ptit; the next occurrence will name the object or outside-object PDF section containing the first difference.

D-509 is open, and it is D-490 again, past the containment D-490 built: PR 235’s pdf job failed on a records-only commit with two equal-length draws differing inside one untyped deflate stream where the page content streams sit. Locally, five of 104 page loads placed one prepared-math glyph a fifth of a pixel off the others’ placement and then printed that placement identically, four prints running, so drawing each load twice cannot see it. It is contained on both sides. --update publishes only a document two of up to three page loads drew, and refuses when no two agree. When the first fresh load does not reproduce the stored PDF, --check-artifact draws up to four loads and passes only if one does and the rest drew a single other document. A refusal names the moved Tm line. At the local rate that leaves about one run in 110 refused, against one in eleven before, and the cause stays open under think-6dle.

D-489 is open, and it is the log’s clearest case of a guard that reads like soundness and acts like a filter. devtools/screen_corner_dual_salvage.py screens a retained depth-one family against an owner class’s guaranteed patch and reads the survivor weight as a weak-duality lower bound on that class’s residual cover value. Its source predicate requires the source receipt’s failures to be exactly ["K3 total weight at least n"] — the failure a family records when its total weight is below n — so it accepts only a family that falls short of the mass the bound is made of, and refuses every proved ceiling family. Exp137 and exp138 deliberately named a source family about 0.6158 short of eleven; exp141 independently confirmed their exact negative results on that source. Those results remain valid. They do not establish that no other fractional family obstructs the residual problem, or that a useful conditional cover exists. The later X1 screen uses a different mass-eleven family and leaves exact survivor mass ten on four screened single-corner endpoint-patch relaxations. Its depth-one survivors obstruct a point cover below ten on those particular domains.

The source guard is still a reuse defect: it must be repaired before admitting a valid mass-eleven source through that CLI, as tracked by think-rm5c. That defect and the change of source do not reverse exp137/138’s scoped arithmetic. The corrected X-026 separates measured neutrality for the endpoint-patch family from the open questions of physical owner routing, stronger domains and conditional threshold covers. Neither a universal conditional-method refutation nor equal reach or runtime follows.

D-470 records a deferred exhaustive test that still asserted the rung T-021 displaced. The full gate caught the stale transcription after the PR 83 merge; the test now re-derives its values from the moving certificate pointer. The optional pre-merge deep gate now exercises the deferred surface; the post-merge exhaustive tier remains the backstop when that gate is not requested.

D-471 records three further conflicted-branch CI blackouts. A branch whose merge ref GitHub cannot synthesize receives no pull-request workflow run. The push-triggered git merge-tree guard now detects that state after every branch push; an idle branch can still become conflicted when main moves underneath it.

D-478 records a missing witness for BC-206’s reported cutting floor. The value near 10.845594 at side 3.97 survives only in a text log. Its generating family is unavailable for replay after the cutting-screen repairs, so it is qualified as an unreplayed historical report. think-aenh owns recovery or recomputation with a retained exact witness.

The generated log currently has 68 open entries: 41 outstanding and 27 contained. The W9 candidate think-cyko owns their systematic risk ordering and bounded repair waves; the synopsis names the cases that matter to current claims rather than pretending the examples below are the whole backlog. D-406 waits on the enumeration repricing X-010 filed. One older entry is worth naming because refusing was the whole of the available fix: D-391 is the first-order rigidity assessor intersecting a tangent cone that is a union: two squares meeting at a single corner are held apart by two axes, and non-overlap asks that either keep separating, so the linearized feasible set is a union of half-spaces and not a polyhedron. Intersecting them is a subset of every branch, so a pose reads as more rigid than it is. n=5, the only size this instrument had produced a retained claim about, has no such pair; Göbel’s n=40 has 42 of its 98 touching pairs, and there the error inverts the answer rather than merely weakening it. That pose has an infinitesimal motion — all sixteen squares of its tilted block turning together, each about its own centre — which gives up one separating axis at 24 of the 42 corner contacts and keeps the other, which is all non-overlap asks. An assessor that intersects reads those given-up rows as violations and certifies every one of the 120 coordinates as pinned, reporting a packing rigid that is not. Removing the defect is what found the witness. It is still not a motion: the gaps curve shut at order t2, so n=40’s record stays undetermined and the catalogue’s annotation stands.

Four agenda-015 review findings are also open. D-418 records eight declared parser or recursion bounds without the named exceeding controls BC-140 required. D-419 stops exp-057 because two six-decimal coordinate rules were applied to a fourteen-digit release-text side token without source provenance. D-420 keeps BC-142 partial because its benchmark selection test proves a bounded inclusion and refusal, not exact reachable-set equivalence. D-421 records that the wave-efficiency renderer accepts Codex receipts but not the Claude receipts retained by this bridged wave, so BC-143 keeps a typed no-change/refusal instead of hand-computing incomparable telemetry. D-422 began as the snapshot cap refusing all 155 negative controls before one of them ran, and that half is discharged: pruning four large result files at a478744a took the counted surface from 90,031,065 to 56,219,144 bytes, and the suite then ran three times on this branch with all 155 controls firing as expected — the first direct evidence here that the controls catch what they were written for rather than only that their anchors resolve. What stays open is the diagnosis that replaced it, and the entry is retitled to it: the portable fallback still copies untracked build caches into every worker, and the cap is held by a per-file prune that was never meant to be durable. The cap itself is checked on the pull-request surface; the cache accounting is checked by nothing. D-434 is the one an overnight run should know about: the covering program’s separation oracle scores a placement cell by its centre, while the exact sweep that decides the certificate scores every cell whose slab meets the admissible domain — 1.1 to 1.2 per cent more cells away from the axes. The search therefore optimises against a weaker constraint set than the verifier enforces, and two n=12 pushes to side 39/10 converged below twelve and were then refused on placements they were never shown. The gap is one-sided, so every accepted certificate stands and T-017 is untouched; what it costs is candidates. Hosted CI is now red on that same assertion: the planning branch’s pull-request surface failed it at 67,173,741 bytes on 2026-09-04 and main’s post-merge run at 9d5eae0f fails the same step, so the repair scheduled as BC-168 is what turns the hosted gate green as well. D-423 records that the lemma closing the Green17 cover certificate’s top strips is printed non-strict in Stromquist 2003 and Bentz 2010 and strict in Friedman’s DS7, and that the repository holds all three. The readings agree everywhere except on the boundary the certificate uses, so the boundary case is an unrecorded source obligation rather than a settled step.

The W9 remediation lane leaves three open entries of its own, and the reason they are open is the more useful part. D-044 and D-046 were marked fixed at 08:25Z on 2026-09-03; the independent review that was meant to gate that disposition began at 08:46Z and returned BOUNDED-CAVEAT for both, so both are now contained. Both repairs are real and were reproduced against the code rather than against the record: the producer-side attack D-044 names is closed, and all twelve of D-046’s clauses are closed, including the seven guards that turn the suite red only when reverted in a copy. What holds them back is that both records summarise findings from the PR #14 review, the repairs were written against the summaries, and four clauses of the source findings never reached the summaries — the float screen’s exact-zero overlap, pre-run engine dirtiness, per-cell timebox semantics, and reporting runnable-but-unrun work. All four are conservative; none flatters a result; none is repaired. Three undisclosed residuals sit on the same archive boundary and close together with one receipt written by execute and compared by record. D-426 is the finding that review turned up on D-046’s own edge: a control-cell breach is a declared stop condition that the session does not honour, because run resets its failure count on the breached round and continues on the same suspect instrument. Nothing has been recorded through any of this — no live round has run, nothing has been recorded through the unattended runner, and the numerical runner stays NO-GO. An earlier form of that sentence gave the reason as the search engine not being built here; a release binary was built at packing/sqsearch/target/release/sqsearch at 10:30Z on 2026-09-03, nothing has been executed against it, and the conclusion rests on the absence of a recorded round rather than on the absence of a binary.

D-427 came out of the same day’s work on the control harness and is the weakest in degree of the three, and the broadest in reach. run_one scores a control on its mutated run alone — non-zero exit plus the expected string — and never requires the unmutated checker to have been green, so a control can report a pass over a checker that was already failing for an unrelated reason. It was demonstrated rather than argued: delete one archived fixture from a worker clone, and check_canonical turns red before any mutation while all four of its controls still score a pass with empty detail. D-413 is the same mechanism having already happened once; its fix pinned a green baseline for one of the forty distinct control commands, and the general form stayed open.

D-428 is a record claiming a check that is not there. The n=17 successor’s validate_result rebuilds all 181 hash-chain links from the two certificate summaries and compares them with the emitted spine, but never compares that rebuild with the carried boundary it is supposed to terminate on, so a carried row altered identically in both summaries — with the spine and last row hash recomputed around it — is accepted. The round record asserted the stronger claim, that an altered manifest cannot survive; that holds for the executed admission boundary, which ties the retained prefix to exp-056 on disk before assembly, and not for the validator alone. The published result satisfies the tie and the record has been corrected; the code has not.

D-429 is a guard that would have fought the formatter forever, recorded before it ever fired. Generated blocks inside formatted documents are compared by what a line says rather than by its bytes, so flowmark may own the typography inside them; the fold that makes that comparison work maps … back to ... but not the space flowmark inserts before it. No generated cell has carried an ellipsis until the results headline, whose n=17 row does, so the failure has never happened — a render and the formatter would have rewritten each other on every commit, which is the churn .flowmarkignore exists to stop, reappearing inside a block the formatter is allowed to touch. The headline works around it locally and the shared fix is deliberately unapplied: a one-line change to a comparison guard backing several views, made unreviewed at the end of an unattended session, is the shape of D-425.

Two entries were added while planning Agenda 017, both found by re-running what the record already said. D-430 is the frontier prose saying sixty-three open cases rest on Nagamochi’s closed form a day after the 4.5058 adoption made it sixty; the README and sixty-seven case bodies were corrected, and check_nagamochi_bounds refuses any prose count that disagrees with the case records — which is why the same sixty-seven bodies now read fifty-eight, T-020 having taken two more cases off the closed form. D-449 was the exact sweep reporting, beside the least covered mass, a witness centre at the midpoint of the attaining event cell, which on most directions lies outside the admissible domain; the value was right and the point was not a witness. The witness is now a point of the cell’s intersection with the domain on both routes, held there on every direction of every retained certificate. D-431 is open: T-009’s significance rationale compares its n=29 interval certificate against a rational certificate on Schadt’s packing rather than Kingbird’s, and the shipped rational promotion run on the Kingbird witness lands about 5.4×10−20 below the interval bound, the opposite of what the rationale says. Agenda 017’s BC-165 registers that certificate, rewrites the comparison on one packing, and takes T-009 to C4 through the results checker. D-432 was found by the same branch’s own pre-push tier: when the change set touches a file that configures the suite, the tier falls back to the whole suite under a 900-second cap the full-suite steps no longer use, dies at 84%, and names no failing test; the step now takes the fast suite’s own budget when its selector expands to the whole suite, the first commit of the branch that ports PR #80’s findings.

D-393 is the same run being wrong about its own gate. D-381 established --edit as the pre-push floor, and that floor does not run tests: the test step is marked broad, and dropping broad steps is exactly what --edit does. So four pushes went out on a red branch — a stale pin, an undeclared marker, and D-392, a size cutoff meant for generated blobs that went blind when defects.yaml grew past half a megabyte. The wake events naming the failed check were delivered six times and read once, after the fact. The tiers are right; using one of them as though it were the other was not.

D-398 is the record being behind its own toolchain rather than wrong about it. n=40, n=65 and n=89 each declared a blocker of kind mathematics reading “No formal certificate currently supports the tighter reported upper bound”, and each kept its verified ceiling at the integer grid — 7, 9, 10. All three certificates existed and ran in the gate the whole time: 780 pairs decided by exact sign over Q(2) at n=40, 2080 at n=65, 3916 at n=89. A feasible packing at side s, decided exactly, is a proof that s(n)≤s, so the mathematics the blocker called missing was done and what was missing was an evidence record naming it.

The promotion is made: all three now cite Göbel’s construction, and the count of cases whose verified ceiling exceeds their best known falls from 33 to 30. The direction was conservative — the register understated what it could certify — but the reason nothing caught it is worth more than the instance. Every check on a frontier record read that record against its own fields, so none could see a certificate it had never been told about. A sweep now runs the other way: each exact verifier declares the sizes it decides, and each of those must reach an evidence record citing that package — with an undeclared verifier a refusal rather than a skip, so a new one cannot opt out by staying silent.

The record can also be wrong about itself, and D-358 is this run being so: an unattended run declared blocks of 150, 180, 180 and 40 minutes and took 31, 42, 29 and 23, because it estimated elapsed time between tool calls instead of reading a clock. The bookkeeping was the smaller half. The misreading also supplied a reason for stopping early -- that later blocks had overrun into the slack -- when nothing had overrun and most of the budget was unspent, which is a constraint the run claimed to meet and in fact a mistake it made.

It said “None automatic” under regression, and a day later it happened again (D-386): a session declared two phases starting an hour and a half after the clock read. A practice change without a check is not a fix, which is the same lesson D-010 and D-017 record one level down. The gate now refuses a session that declares a start time later than the moment of checking, and prints elapsed against budget derived from the record’s own successive timestamps — the line that would have made this visible while it was happening.

The harness that proves those checks fire has a blind spot of its own. D-356 records that run_negative_controls prunes the literature archive and the atlas renderings from its snapshot to stay under a portable size cap, so any check reading one of them fails there on a missing file rather than on the mutation. Three controls written for the n=29 chain were withdrawn for that reason, and the guards they would have exercised are asserted directly in their test instead. D-357 is the companion, and it is a correction: a synopsis control that failed four times running, including against a clean tree, later fired correctly with nothing changed, so the standing-failure reading recorded first was wrong and the entry now says plainly that the trigger is not identified.

A check can also pass for a reason other than the one it states, and this log now has two of those a day apart. D-359 recorded that the generated atlas SVG’s coordinate precision was inherited rather than pinned: format_svg_number rendered a scalar at whatever precision it was last refined to, so known-best-1-100.svg carried 27 fractional digits in a fresh process and 50 once anything had refined the shared field. The test asserting that the stored PNG was rendered from the current SVG therefore passed on test ordering, and a genuinely stale PNG would have been indistinguishable from the passing case. It is now fixed, and the feared regeneration did not happen: the ambient state came from NumberField.decimal setting the thread-global decimal precision and never restoring it, and the emission is pinned at 28 — the precision every retained figure was already drawn at — so no stored artifact changed a byte.

Fixing it surfaced the second. D-362 is open: validate_translation_only_trajectory compares two independently rounded projections of exact algebraic numbers for exact equality, and they agree to about thirty-one digits rather than exactly. It has never fired wrongly only because nothing had raised the ambient precision before it ran, which is the same accident D-359 was. It is left open deliberately: it is what stands between this repository and a principled emission precision of 32, and that is a decision about what the projection layer promises rather than a rounding to choose in passing.

A control that does not reach its known answer is the third of these, and it took the first full strict run in a while to see it. D-365 records that check_golden_basins --deep fails three oracles at n=10: the quench reaches 3.735634792931 and refuses to certify convergence, and anneal-plus-quench lands 2.85×10−2 above the proved s(10)=(6+2)/2. Nothing downstream reads the failing value, so no result rests on it; what is lost is the control itself, at the one size in the ladder where the answer is proved and the packing is not trivially a grid. It is proven pre-existing rather than assumed — the identical failures reproduce at the base commit of the session that found them, in a separate worktree — and it runs only in the strict tier, which is why a continuation running the fast gate at every checkpoint never met it.

The gate’s cost is itself a logged defect, and this session added a second one. D-366 records that the negative-control step now outgrows the 900-second per-step timeout: nothing is wrong with the controls — run without the cap the suite completes in 1268s and all 137 fire — but a step that always times out stops distinguishing a control that no longer fires from a machine that was busy. D-355 records that verification runs the whole gate after every change, so cycle time is set by the slowest full-tier step rather than by what the change can reach: a two-file edit measured at 979.79s against the 12.06s its two affected steps need, an 82x overrun. The resolution is not to check less. The efficiency principle asks for iteration as fast as possible and the standing asymmetry lets efficiency simplify process but never weaken assurance, so what is owed is a change-scoped selector that is conservative by construction and can be caught under-selecting — think-9qtn, under BC-084, which carries BC-051’s scope unchanged. Good coverage and short cycles are a design tension, and resolving it is the design’s job rather than the operator’s discretion.

A control can also be wrong by being unable to fail. D-378 records that the declared surviving identity relation, contact + closure, has exactly one distinguishing verdict — agrees on the n=3 quotient control — and that this verdict cannot test it. The record carries one closure set, closure(G) = [C, G, M], and it covers every stratum that control has, so any faithful implementation returns one there whatever the certificates say; mutating all four samples to distinct certificates, then to a single shared one, leaves the answer at one. That is D-373’s finding one level down: there the problem was that every control’s answer is one, here it is that the closure is degenerate, so even a control whose answer were not one would not separate the relation from a merge-everything one unless it carried two disjoint closure classes. None does. It is contained rather than fixed — the relation now reads both halves of its own definition, and a synthetic two-class control exercises the half no retained control reaches — because a real fix needs a new exact classification.

A record contract can also be wrong by being unable to say something true. D-377 records that a delegation which is read-only by construction cannot be written down while it runs: packing-ledger check requires an in_progress delegation to declare a write_scope, and the schema requires that scope to be non-empty. Investigation, review, and audit are exactly the delegations OR-2 says parallelise best, and all three write nothing. It is contained rather than fixed — such delegations are recorded on completion instead — because the repair is a decision about the session contract, and an explicit read_only flag is better than permitting an empty list that would be ambiguous between “writes nothing” and “nobody filled this in”.

121 fixes left no regression check behind. D-300 remains open: the yielded session id, output, timeout/final poll, and exit survived, but invalid gdate precision left the start and end fields empty, so D-202, D-217, and think-b3bm remain open. D-304 records a contradictory inequality in McClenagan’s printed Section 3 proof. H-037 repairs that local sign step independently from both the figures and the source equations; it does not certify the remaining construction. D-343 records Bui’s printed unbounded replacement instruction. H-037 keeps the source-forced finite range and replays the resulting exact square count; the geometric construction and its asymptotic theorem remain open. D-344, D-345, D-346, and D-347 record four independent gaps in El Moumni’s printed n=7 proof. The source-distinct Case 1 branch repair and Figure 4 coordinate prerequisite are exact, but the printed length remains defective, the cross-section names o1 where its premises require o4, and the diameter display uses undefined i with only a separately tagged midpoint candidate. No surrounding incidence is verified, so the complete source-faithful replay stays blocked under think-trkj.

The entries from D-030 onward sharpen the point rather than softening it. D-283 remains open in the current robustness inventory. D-030 and D-031 were caught by proved control cells while structural store checks stayed green; D-032 and D-033 came from rehearsing recovery paths that had shipped unrun; D-034 found the endpoint-isolation assumption; D-035 found destructive negative-control residue; D-036 found a timeout reported as convergence; and D-037 separated real census counts from a checker’s synthetic re-offers. D-038 separated scalar recognition from an oracle; D-039 separated side precision from component resolution; D-040 made rarity conditional on a durable P/Q/E regime; D-041 rejected rank-free rigidity and dimension claims; and D-042 exposed n=12 as an open target masquerading as a negative control.

The systematic crosswalk then records every remaining technical finding from the PR #14 review. D-043 closes the archive-before-validation path; D-044 and D-046 repair independent pose validity and the runner state machine and stay contained on the residuals their independent review named; D-045 tracks criterion-specific evaluators; D-047 closes contact-key reflection; D-048 retains unstable tolerance/equality semantics; D-049 tracks factorial canonicalization; D-050 and D-051 separate observation promotion from regime-safe merging; D-052 narrows quench stationarity; D-053 now enforces the generic exact-field preconditions; D-054 separates budgets and final-best records from trajectory claims; D-055 and D-056 correct the angle and m2−3 theorems; D-057 scopes H-020; D-058 reconciles the local handover; D-059 keeps the golden oracle/characterization split open; D-060 restores producer-level strict checks; and D-061 preserves evidence for unrecognised endpoints. D-062 catches the executable n=12 rejection that survived the first D-042 correction; D-063 removes a false contrapositive from the rigidity premise; and D-064 keeps a read-only runner preflight executable inside the gate that mutation-tests it without opening the gate to live campaign execution. D-065 removes the last repeated numeric gate claim from the README and reconciles its remaining qualitative claim to the defect source.

D-066 catches the active baseline script repeating the stale n=12 control claim. D-067 and D-068 restore the omitted eleventh-round wall time and stop calling elapsed time CPU time; D-069 reconciles H-002 with the four rounds that already measured its quench; and D-070 restores exp-011’s execution revision and makes future timing and provenance survive the execute/record boundary. D-071 remains open because the numerical runner’s generated session report still overwrites its predecessor; versioned agent-session artifacts now preserve the outer delegation loop separately. D-072 closes the two direct runner commands that bypassed the cooperative gate marker, and D-073 wires those new session artifacts into the filename/id invariant. D-074 corrects the first D-070 regression claim: receipt parsing alone did not exercise the terminal artifact mapping, which is now centralized and mutation-tested. D-075 narrows PR #16’s cross-environment mismatch to what its aggregate output actually establishes; D-076 keeps the n=5 six-of-six observation from deciding among identity, landscape, stationarity, and numerical explanations; D-077 replaces a stale serial handoff with current parallel lanes; and D-078/D-079 complete the rank and implication corrections in that response. D-080 replaces a vacuous neighbor-transfer target; D-081 keeps a nonempty but underfilled queue from counting as overnight readiness; D-082 records the second overgeneralization of H-020; D-083 retracts an attraction claim inferred from a finite- quench residual; D-084 removes unsupported rigidity and gap-rank facts from the n=11 frontier artifact; D-085 freezes living uv commands; and D-086 replaces stale overnight and handoff state with the current launch agenda. D-087 separates the angle-class algorithm, corpus law, and single-cell kink claims. D-088 through D-105 are source, geometry, identity, and hypothesis-design corrections from the first creativity pass; D-106 and D-107 are the mutation-anchor and synopsis reconciliation failures its first gate attempts caught. D-108 through D-119 are the second-pass corrections: the missing piercing paper, false isostatic and self-stress arguments, fixed-budget and fixed-cell overreach, topology and fractional-LP mistakes, unsupported novelty, stale registry state, the H-012/H-017 estimand conflation, and an impossible continuity-blind angle-sheet criterion. D-120 through D-138 record the engineering delta and first post-merge runs: ulp-sensitive cell selection, gate boundary and skip-contract failures, the per-step worker cap, bounded portable snapshots, a parallel negative-control race, wall-clock scientific budgeting, stale review status, the missing targeted edit loop, unbounded checker children, and a nonunique mutation-control anchor, followed by a lint floor that accepted type-checker warnings and a fixed-cell solver that does not expose whether it settled or hit its cap (D-132), then the search-only determination vocabulary that could not represent H-024’s missing formal prerequisite, the omitted n=29 source provenance that the falsifier exposed, the roll-up’s obsolete blanket claim about exploratory record evidence, the distinction between a branch linearization and a true Bouligand motion, and a certificate replay that did not require one-to-one branch coverage. The next tranche, D-139 through D-171, records the missing hard-square topology literature, a stale closed-family contact claim, exact-moduli integration errors, Stromquist source transcription and proof-chain mistakes, stale campaign effort, the paper’s extraneous Lemma 4 root, and the escaping Figure 14 box. D-153 records that the three 1984 memoranda were directly hosted while the source ledger called them unavailable; D-154 and D-155 close exact-field metadata and cross-platform record gaps in the first uncommitted H-010 checker. D-156 through D-158 close tiling-containment, sign-preservation, and provenance-scope gaps in the H-041 repair checker before any H-041 evidence could land. D-159 keeps immutable scanned PDFs out of Git’s text-whitespace path while preserving strict whitespace checks for the associated hand-written reading aids. D-160 records a D-145 recurrence caught in this round’s own diff: a broad scalar match attached H-010’s regression text to D-002 before an ID-scoped correction restored both. D-161 records the stale forty-hypothesis synopsis count exposed when H-041 became the forty-first artifact; the current consistency check now derives that count from the registry. D-162 records the first consequence exposed by typed fixed-cell termination: a deep rebuild reduces the converged totals at n=3, n=4, and n=5, and exposes unsettled ladder evaluations at n=9 and n=10. Their full poses remain useful evidence, but the small-n convergence totals must be rebuilt before any such event can be promoted to a terminal component. D-163 records the gate failure that first hid that evidence: the historical-regression step continued after its checker failed and returned the status of a later successful probe. The step now propagates the checker failure immediately. D-164 separates one source of the newly visible nonconvergence: a successful HiGHS solve missed the fixed-cell post-check by about 2×10−11 beyond its cutoff and was labeled mathematically infeasible. Typed outcomes now retain the cause, rows, residuals, retry margins, and actual solver-call count. A single retry tightens the complete initial offending set, leaves the 10−10 acceptance screen unchanged, restores the proved n=3 and n=10 controls, and is replayed against the original LP rows. D-165 records the bounded implementation’s stop condition: initial cell-solve failures still bypass D-132’s typed result and become dummy objectives inside the angle search. That code path is now typed, D-168 closes the n=10 cell degeneracy, and BasinEvent/v3 routes every fixed-point evaluation through one audited path. Exp-021 retains and replays a balanced 2,037-evaluation receipt, so D-165 is fixed; the older exp-018 through exp-020 artifacts remain correctly blocked under their historical v2 contract. D-166 removes the resulting false certificate from BasinEvent/v1. Version 2 retains the full stopping event and independent validity screen but marks every current event promotion-blocked by D-165, and replay refuses a forged admissible flag. D-167 adds the missing per-event wall time, so subsequent seed blocks and larger n values can be selected from measured throughput rather than command-level guesses. D-168 separates an equal-objective finite cell closure from a genuinely unresolved cycle. The n=10 control closes after enumerating at most eight adjacent cells; exp-021 then records the new typed path without rewriting the historical blocked events. D-169 fixes a second post-check hole found while typing those failures: containment rows were never replayed. Every accepted cell now passes the full original LP residual vector. D-170 gives D-165 its own bead after the defect log was found to reference the unrelated D-132 tracker; the older bead remains unchanged. D-171 records why the former argmax-only repair left one n=4 event unsettled: rows 16 and 21 already violated the screen together. The complete offending-set retry closes the exact regression, and exp-024 completes the n=4 v3 block at 4/4 admissible without weakening the screen. D-194 and D-195 record two pre-measurement corrections to exp-035: pair (0,4) is regenerated at each slide stratum, and pair (3,4) has two owner-axis branches whose tied support rows are conjunctive within each branch. The frozen controls now execute and both defects are fixed. D-196 records the integration recurrence caught before commit when a context-poor edit briefly changed D-034 instead of D-194. D-197 records the concurrent checkout caught by the exp-036 commit banner; the isolated checker commit was moved to the campaign branch and the other branch ref restored before push or target execution.

D-289 through D-293 record the H-043 pilot’s remaining validity, robustness, and provenance gaps. D-289 covers row-class normalization in the cone oracle; D-290 keeps certificate replay open; D-291 covers the branch-0 golden’s treatment of valid future refutations; D-292 keeps regenerated branch indices bound to the retained exp-013 universe; and D-293 keeps provenance self-tests from claiming completeness without exact mappings.

The generated defect view owns the aggregate counts; this narrative retains the causal history. The postmortem on D-014 turns this into four rules—oracle coverage through unshared code, tolerances stated relative to what they govern, a discovery treated as a defect until an independent layer agrees, and new components inheriting the perimeter—that apply to code not yet written.