HapaxResearch Lab

A working record, dated

The harness-import audits and an excerpt of the defect catalogue

Draft of 2026-10-04.

0. What this document is

This document has two parts. Part A renders the estate’s harness-import audit reports as a dated public record. Part B renders a dated excerpt of the estate’s encountered-machinery catalogue, which is the estate’s running record of witnessed defects and their dispositions. [S03]

This record is record-keeping only. The estate’s stated outward relations hold that the estate’s own record is citable for record-keeping facts only until task-lineage denominators exist (relation K R-67), that scored results are published with misses, unresolved cases and corrections at the same prominence as hits (relation K R-88), and that the estate’s stated position is finding out, in public, with instruments (relation K R-86). [S13] Nothing in this document is a capability, benchmark or predictive claim, and no novelty is claimed: Part A’s own prior-art table closes with the line “No novelty claimed” [S06], and Part B is an excerpt of an operational log.

The publication authority for this record is the alignment document’s item 5, accepted by h:rlk on 2026-09-28: publish the working record now and continuously, meaning dated facts about what was done, found and fixed, while capability, benchmark and predictive claims stay held. [S01] This draft is not published by the row that produced it. Before publication it passes a hostile-reader panel from non-Claude families, a quote check and a plain-register check, and then the portal release path, which at the time of writing waits for the row hrl-portal-records-subject-guard-followup-20261004. [S02][S03][S14]

The principal of the estate is referred to only as h:rlk. No household member and no third party is named, and no ages or personal data of any person appear. Every factual claim carries a bracketed tag that resolves in SOURCES.md.

Part A. The harness-import audit reports as a dated public record

A.1 What was measured, when, and how

The audit is exit (2) of the task row harness-import-scrub-for-panels-reviews-benchmarks-20260925, claimed and measured by an internal audit lane on 2026-09-25 on an estate host. [S04][S05] Its subject is twofold: what each command-line agent harness loads into a model’s context by default, and what still reaches the model when the same harness runs inside the estate’s declared execution envelope. [S04]

The recorded method is as follows. For each run the measurer built a sentinel world: a mirror home directory carrying a unique HAPAX-SENTINEL- token in every import location, an ancestor directory and a checkout directory holding instruction files, hook settings and MCP server configuration, and marker scripts that touch a file when they execute. In the baseline runs the harness saw the whole host except that the home directory was replaced by the mirror, so a default launch could import only sentinels, and h:rlk’s real files were neither read nor changed; the one real file bound was the credential, read-only. In the enveloped runs the same harness and the same world ran inside the envelope with one declared governance hook. The evidence had three independent parts: inotify open events on every sentinel file, the marker files, and the model’s own list of the tokens it saw. The report states that the model’s self-report is complementary only and carries no oracle weight. The prompt asked the model to list every string in its context beginning with HAPAX-SENTINEL-, and tools were disabled, so any token the model reported came from what the harness had loaded at startup, never from a tool read. [S04]

A.2 The per-harness record

The table below restates the stored reports. “Baseline” is the harness’s default launch in the sentinel world. “Enveloped” is the same world inside the declared envelope. Report files are listed in section A.4. [S04][S07]

harness measured (UTC) baseline: what the default launch imported enveloped result
Claude Code 2.1.281 (served model claude-haiku-4-5-20251001) 2026-09-25 15 baseline imports witnessed. Instruction files from the ancestor walk-up, the checkout and the user level, plus user rules, reached the model. User and project settings files were opened. User and project hooks ran. User and project MCP servers started, in print mode with tools off, without a trust prompt. clean: no sentinel opened, hooks and MCP servers did not run, the host environment was cleared, the declared governance hook fired, and the model replied NONE.
Mistral Vibe (uv tool mistral-vibe) 2026-09-25, about 10:03Z On the reviewer command line as it stood on origin/main, the estate’s shared operating instructions at ~/.vibe/AGENTS.md (about 8 KB) were opened, and the token reached the model. clean: nothing imported, reply NONE.
Meta Muse 1.4.0-R4161.1 2026-09-25, 10:10Z On the reviewer command line as it stood on origin/main, ~/.config/muse/AGENTS.md (about 7 KB) was opened, and the token reached the model. clean: nothing imported, reply NONE, exit 0.
opencode 1.17.4 (local model, zero metered cost) 2026-09-25, about 12:38Z User-level, ancestor and checkout AGENTS.md tokens reached the model. The checkout CLAUDE.md was also opened, though its token was not reported by the model. clean: nothing imported, reply NONE, exit 0.
grok CLI --single 2026-09-26, about 00:50Z ~/.grok/AGENTS.md witnessed in the baseline. clean.
agy -p 2026-09-26, about 00:50Z ~/.gemini/GEMINI.md and the checkout AGENTS.md witnessed in the baseline. clean.
kimi -p (K3) 2026-09-26, about 00:50Z ~/.kimi-code/AGENTS.md, a user skill, and the checkout AGENTS.md witnessed in the baseline. clean.
codex exec v0.156.1 (served model gpt-6-astra) first attempt 2026-09-26, about 00:50Z inconclusive: the run returned a usage-limit message, nothing was imported, and the report recorded a rerun as owed. (no verdict from this attempt)
codex exec v0.156.1 (served model gpt-6-astra) rerun 2026-09-28, 02:24:38Z The user-level ~/.codex/AGENTS.md and the ancestor checkout AGENTS.md were opened, and both tokens appeared in the model’s reply. clean: no sentinel opened, no marker fired, reply NONE. [S07]

A.3 Misses, corrections and limits that the reports themselves record

The reports are not a clean bill of health for the default state of these harnesses, and they are not a claim that the estate’s reviewer seats were isolated at the time of writing. The misses and limits below are stated in the reports themselves. [S04]

  1. The baseline column of section A.2 is itself the miss list. Every measured harness imported user-level or estate-level context on a default launch. In two cases the leak ran through the estate’s own reviewer wrappers: the Vibe and Muse reviewer command lines on origin/main carried the estate’s operating instructions into every review. The report states this confirms catalogue entry M153 on the reviewers’ exact arguments. [S04][S10]
  2. For Claude Code, the report records that --tools "" isolates nothing at startup: instruction files still loaded, hooks still ran, and MCP servers still started. It records that --safe-mode is a real flag-level layer that keeps subscription authentication and suppresses instruction files, hooks and MCP servers, but still opens the three settings files and still inherits the host environment and the caller’s working directory. Which settings keys still take effect under safe mode was not measured. [S04]
  3. The report preserves a correction against its own measurer. An earlier checkpoint had guessed that the Claude reviewer most likely loads the global CLAUDE.md. The measurement showed it does not, and the guess is preserved in the report as a correction rather than deleted. [S04]
  4. The codex first attempt is recorded as inconclusive, not as a pass. The clean verdict for codex dates from the rerun of 2026-09-28, not from the first attempt. [S04][S07]
  5. For opencode, the checkout CLAUDE.md was opened but its token did not appear in the model’s reply. The report records an open without reported content, and does not upgrade it to a claim that the content reached the model. [S04]
  6. Claude Code did not read AGENTS.md at any level in the measured version. The report records that the envelope masks it anyway, because every other measured harness does read it. [S04]
  7. The method’s third evidence leg, the model’s self-report, is declared complementary only. The primary evidence is the inotify open events and the marker files. [S04]

A further limit is about adoption rather than measurement. The clean enveloped results in section A.2 are records of the measured launches only. They do not show that the estate’s reviewer seats had moved onto the envelope: the report names the Vibe wrapper as the next consumer where a leak was already evidenced, and a catalogue entry dated 2026-09-25 records the Vibe reviewer still refusing oversized packets under its own wrapper on that date. [S04][S10]

A.4 The report inventory

The stored reports live under the audit’s measurement folder in the estate record. The report states that each file was checked and holds no credential string and no home path. Hashes below are the sha256 prefixes as recorded in the report; the codex rerun file’s full sha256 was computed by this drafting lane on 2026-10-04. [S04][S07]

file sha256 what it is
audit-claude.json 42122d5a… committed-audit verdict for Claude Code: clean, 15 baseline imports witnessed
audit-vibe.json 3ee6d4bd… committed-audit verdict for Vibe: clean, the baseline ~/.vibe/AGENTS.md witnessed
audit-muse.json 737789c6… committed-audit verdict for Muse: clean, the baseline ~/.config/muse/AGENTS.md witnessed
audit-opencode.json 43826dbd committed-audit verdict for opencode: clean
audit-grok.json 77957d7a committed-audit verdict for grok: clean
audit-agy.json b74ed3b5 committed-audit verdict for agy: clean
audit-kimi.json 8880b76c committed-audit verdict for kimi: clean
audit-codex.json a75796c6 committed-audit verdict for codex: inconclusive (usage limit), rerun owed
codex-import-audit-20260928T022438Z.json 4e8abdd89cbe9649bf58ce8ace81442143a7284ec7c3421eb45518d04f40689c codex rerun: verdict clean, baseline and enveloped transcripts embedded
claude-baseline.json 2053b856… raw measurement, Claude Code baseline
claude-envelope.json 09fd8a5f… raw measurement, Claude Code enveloped
claude-reviewer-flags.json a7cc9191… raw measurement, Claude Code reviewer flags
vibe-reviewer-and-envelope.json 3c31767a… raw measurement, Vibe reviewer launch and enveloped run
muse-reviewer-and-envelope.json 13fec8a2… raw measurement, Muse reviewer launch and enveloped run
opencode-default-and-envelope.json 38f1ff77… raw measurement, opencode default launch and enveloped run

A.5 Where the machinery came from, and its release state

The envelope is shared/capability_envelope/ in the hapax-council repository, developed on branch the audit’s harness-import-envelope branch. The audit row’s record places it under design section 3.2a and canary C10 of the capability dispatch fabric design, at tier T2 (bubblewrap). [S05]

Its prior art is declared item by item in the audit folder’s prior-art table, with each item marked align, extend or depart. In summary: the sandbox carrier is an earlier blind-panel runner’s bubblewrap recipe (aligned, extended with an allowlist root, checkout masking, declared hooks and MCP rendering, and inotify at the boundary); the import inventory is catalogue entry M153 (aligned); the design rule is the dispatch fabric design section 3.2a (aligned); the containerization tiers document and the ruling that containers constrain declared bindings but do not mint authority are aligned; the mediating-layer doctrine is aligned, departing from six per-engine reviewer wrappers; the Claude reviewer’s isolation flags are extended; a memory note that Vibe imports the estate’s AGENTS.md unless scrubbed is aligned; and Claude’s --bare flag is departed from as the mechanism because it switches billing surface. The table closes: “No novelty claimed.” [S06]

Release state, verified on 2026-10-04. Pull request #4784, which carries the envelope and the committed rerunnable audit (scripts/capability-envelope-import-audit), merged on 2026-09-28T03:38:36Z. [S08][S04] Pull request #4793, which carries the in-repository mutation check and the audit recipes for the remaining harnesses, is open as of 2026-10-04. [S09] The alignment document of 2026-09-28 recorded that the audit reports counted as exhibit supply once #4793 landed, and that its false-clean fix was on hold at that time. [S01] This draft therefore presents the reports as they stand, with the follow-up pull request still open.

Part B. A dated excerpt of the encountered-machinery catalogue

B.1 What the catalogue is

The encountered-machinery catalogue is the estate’s running operational record of the mechanisms it runs into. Its inclusion criterion is encounter, not apparent inefficiency or failure: it records working, obstructive, dormant, beneficial, harmful and uncertain mechanisms. It was commissioned by h:rlk on 2026-09-08 and is maintained by the coordinator as part of ordinary work. On 2026-09-24 h:rlk said: “All trivial mechanical issues that cause us grief should be fixed as we move. WITNESSED-MECHANICS is also a critical document.” The catalogue is that document. [S10]

Each entry identifies what was observed, what it cost, what remains unknown, a proposed disposition and an owner, and a status. Entries are appended in dated folds. The record’s discipline is that mistakes, including the record’s own, are preserved rather than rewritten. [S10]

B.2 The state of the catalogue on 2026-10-04

The derived auditor summary, regenerated mechanically and never hand-edited, reports on 2026-10-04: 189 unjudged entries with a combined weight of 242; an accidental share of 100 percent against a target of 0, with the trend not falling (100 percent in three consecutive windows); 131 entries OPEN, 26 FIX-IN-FLIGHT, 5 LIVE with a readback, 2 ACCEPTED, and 25 retained; 51 entries older than 14 days and 93 between 7 and 14 days old. The same generation posted 114 flags, of which 57 are bookkeeping flags about the catalogue’s own numbering and status vocabulary. [S11][S12] For comparison, the alignment document of 2026-09-28 described the catalogue as 185 witnessed defects with dispositions; the figures differ in date and in counting rule, and both are stated here as dated record facts. [S01]

B.3 The sample

This excerpt was selected by the drafting lane on 2026-10-04. It is not a random sample. It covers the catalogue’s main defect classes and every recorded status, and it deliberately weights entries that remain open or that recurred, because the catalogue itself is mostly open: 131 of the 189 unjudged entries are OPEN, against 5 LIVE with a readback. [S11] The excerpt window runs from the first operational backfill on 2026-09-08 to the most recent entry, dated 2026-10-02. Each entry below is rendered in plain sentences from its catalogue row, which remains the source of record. [S10]

Entries still open or recurring (the misses)

M42 — the lane reaper killed a live worker (2026-09-09). The lane reaper inferred destructive lifecycle authority from pane-child counts and tmux activity, and missed a live daemon-owned native worker; the native journal proves an erroneous task release and attachment kill at 17:18:36Z. The timer was stopped, not disabled, and the session and claim were recovered. The entry remains OPEN: a properly admitted lifecycle successor does not exist, and the legacy dry-run flag must not be executed because the source has effects outside its dry-run branch. [S10]

M64 — the anti-pileup governor was silently absent for at least two days (2026-09-14). The service named as the anti-pileup governor failed every timer cycle with a 30-second start timeout while its script needed 46.4 seconds of wall time. The catalogue records 144 consecutive timeouts in one day and no successful completion anywhere in the retained journal back to 2026-09-12. A manual run completed in 46.4 seconds and took no action. The repair row has been offered and unclaimed since 2026-09-14. Status: OPEN. [S10]

M65 — one predicate encoded in six surfaces (2026-09-14). The quota state of one provider was encoded in six independent surfaces with different producers, validators and lifetimes, and each consumer trusted a different subset, so a quorum-accepted dossier was unadmissible while receipts said healthy and live invocations said walled. h:rlk’s recorded verdict was that such discrepancies are evidence of byzantine systems. The durable disposition is a single-writer-per-predicate redesign. Status: FIX-IN-FLIGHT, with recurrences recorded. [S10]

M111 — no per-lane memory ceiling, and a hard reset lost every lane’s session (2026-09-25). The lanes ran with no memory ceiling. One Grok CLI process reached 6.2 GB of anonymous resident memory before being OOM-killed, and about 22 lanes together exhausted the 48 GB host; the host hard-reset at 00:48:48Z and every lane’s in-flight session was lost. The incident row routes a per-capability ceiling so that a runaway lane dies alone. Status: OPEN. [S10]

M95 family — claim attempts hold on task-store churn (2026-09-24 onward). The claim tool repeatedly holds with task_store_frontier_changed_during_index_build while many lanes write task rows. The family spans entries M95, M100, M101, M105, M107, M130 and M180, and the catalogue measures about six such holds per lane-day. Two entries in the family record that the hold text named a false predicate and a wrong next action, which invited lanes to repair a healthy receipt. Repairs are partially landed: an inspection retake and a resolution retake at three claim sites, the latter merged on 2026-09-27 [S17]. A recurrence at scale was recorded on 2026-09-28: the claim index rebuild, 5,874 rows at 15.7 to 20.3 seconds per build, failed on any row write and held seven lanes two to six times each within 30 minutes. Status: OPEN. [S10]

M116 — vault snapshots stopped silently, and the fix did not hold (2026-09-25). The vault git snapshot service failed every 20 minutes on a stale zero-byte lock file, with no incident and no alert, so no vault history was written for the affected windows. After one instance was repaired, a new stale lock appeared within hours; the creator was not identified, and the entry records that removing the lock at each occurrence does not hold. Status: OPEN, recurred. [S10]

M125 — the idle watchdog delivered false work instructions (2026-09-25). The idle watchdog told lanes, verbatim, “idle for 90m with an active task … Resume work immediately. Ship a PR and cc-close –pr N after merge.” The catalogue records the message reaching at least six lanes, some of them twice, within about 26 hours. In every recorded case the idle figure was false: activity minutes or seconds before the message is on the row logs, and the 90 minutes tracks claim age rather than activity. The instruction also did not fit the rows: they carried no source-mutation authority, so obeying the message would have meant inventing a pull request or closing a row whose exit predicate was unmet. No lane acted on the instruction. The record’s witness labels are themselves inconsistent (three entries are labelled “third witness”) and are preserved that way. Status: OPEN. [S10]

M137 — a merge closed a row whose exit predicate had an unmet clause (2026-09-25). The pull request merge watcher closes a row as done when its linked pull request merges, running the close with the closure gate and the acceptance-receipt gate disabled. On a row whose exit predicate had a post-merge runtime readback clause, the row was closed as done with that clause unmet. A successor row had to be minted to carry the unmet clause. The catalogue notes the reading this creates: a done row whose runtime effect was never measured reads as delivered. Status: OPEN. [S10]

M139 — one lane’s loop tripped the shared API budget for every lane (2026-09-25). A read-only inventory lane wrote a harvest loop whose break condition failed on an HTTP 403, and the loop then issued about 888 requests in 159 seconds against the shared GitHub token. The tripped limit was the secondary rate limit, so every lane’s GitHub calls failed while the core budget still read 5000 of 5000. The catalogue records that the same misread of a 403 was already on the record from 2026-09-16. The loop was killed by exact process id, a 15-minute cooldown was observed, and the harvest resumed as seven serial paginated calls at least 3 seconds apart. The durable items (a call budget, a typed refusal on 403, and placement of the shared-resource fact where a dispatcher reads it) are recorded as unowned. Status: OPEN. [S10]

M147 — a review seat billed for empty replies (2026-09-25). A GLM review seat returned unparseable output with 8,192 completion tokens of which 8,187 were reasoning tokens, empty content, and $0.048772 billed, because the reviewer sent the default token budget to a model that must think. The dispatcher recorded only “output omitted”, so the cause was invisible and the family stayed seated. The catalogue records that the same failure was already on record from 2026-09-18, when 22 billed empty replies were reconciled without fixing the seat. The fix pull request merged on 2026-09-27 [S15]; the catalogue’s status remains FIX-IN-FLIGHT because its closure also required a verification that this draft does not assert. [S10]

M151 — spend outside the reservation gate (2026-09-25). A blind-panel runner’s bare chat completion used the GLM pay-as-you-go credential directly, outside the reviewer’s reservation gate, spending about $0.2024 at implied list prices with no spend receipt and no ledger visibility. The seat classed it as a mechanism defect rather than a breach because the spend was inside the burn authorization. The recorded cause is structural: the gate lives in one client, not at the credential. Status: OPEN. [S10]

M153 — every command-line harness imports estate framing by default (2026-09-25). An inventory taken at 07:40Z recorded that every CLI harness on the workstation loads estate framing by default: per-harness instruction files, memory stores, skills, and in one case an MCP server mounting estate data, with all of them walking up to a home-level AGENTS.md. The entry’s conclusion is that review-family independence on the review plane was weaker than assumed for every CLI-harnessed family, which is exactly the correlation a multi-family quorum exists to avoid. This entry is the seed of the audit rendered in Part A: the audit measured the claim per harness, and the envelope is the declared carrier for independence-claiming launches. Status: OPEN as a catalogue entry; the measurement this entry seeded is Part A’s subject. [S10][S04]

M103 and M106 — the session conductor misbound sessions, and the misbinding propagated (2026-09-24 and 2026-09-25). The session conductor’s spawn rule adopted any pending manifest created within 10 minutes regardless of recipient, its intent patterns matched its own docstring, and a lane that merely read the rule or a manifest minted further pending manifests. A chain across five lanes was recorded on 2026-09-24, and affected sessions became write-once: a lane’s second write to its own file was refused as parent-owned. After the source session was stopped, its pending manifests remained adoptable, and one was adopted by a later session within two minutes of the warning. A p0 repair row exists. Status: OPEN. [S10]

M129 — one word in a row title blocked an authorized release (2026-09-25). The risk-flag deriver matched the token “live” in a task row’s title, where it was a verb, and derived a live-egress sensitivity that blocked the release the seat had authorized for the claim-plane repair. A dry run reported the pull request as queue-ready one minute before the apply refused, because the release revalidation ran only under apply. The specific false positive was fixed by pull request #4760, merged 2026-09-25 [S19]. The class it belongs to, a gate reading an upstream free variable as identifying, is the catalogue’s heaviest open class: weighted 23 with no repair row as of 2026-10-04. [S10][S11]

M163 — there is no waiting state, so finished work blocks its lane (2026-09-26). The one-active-task guard has no waiting state, so a row whose outputs are delivered but whose review, merge or external event is pending holds its lane’s single slot. On one afternoon this blocked three lanes and the coordinator seat itself. The interim practice, supersede-with-successor, caused M165’s cascade-withdrawal the same day. The catalogue also records a correction here: the seat’s first ruling to use the force flag was wrong and was retracted within two minutes, and the force flag is retired under canon enforcement. Status: OPEN. [S10]

M84 family — freshness that no producer guarantees (2026-09-23 to 2026-10-02). A queued pull request’s admissibility depends on a fresh admission status with a time-to-live, but no producer is bound to refresh that status faster than the lifetime, and a push to the head resets the artifact without refreshing the status. The family spans the original entry, two later instances, and a recurrence dated 2026-10-02 in which a tick reported a must-include pull request as handled without full classification while a private hold was present. The successor row is offered and unassigned. Status: OPEN. [S10]

M189 — concurrent review rounds overwrote the dossier (2026-09-28). Two review rounds on one pull request head ran concurrently; the later silently replaced the dossier, and the acceptance receipt still described the earlier round. The catalogue records a second dispatcher instance in which the pull request’s own author lane ran the apply, and an interim seat rule that only one named lane runs applies. Status: OPEN. [S10]

Entries repaired, closed or contained (with their remaining limits)

M165 — a supersession cascade-withdrew seven live rows (made and repaired on 2026-09-26). Closing a row as superseded set seven live rows to withdrawn, one of them a row h:rlk had accepted, and logged no prior state. A lane caught it within minutes, and the seat repaired the statuses the same evening from git history. Status: CLOSED (repaired); the cascade mechanism itself remains OPEN, with the recorded direction that a supersession should re-point dependents to the named successor and that any cascade must log the prior state it overwrote. [S10]

M161 — a stray empty directory latched a review family out (2026-09-25 to 2026-09-26). An empty .git directory in the shared scratch root made the root look like a repository to nearest-ancestor detection; the Muse reviewer’s host refused to start, and the refusal was recorded as a dead reviewer, which latched the family out for hours and let one pull request reach quorum-accept without the family that later blocked it. The seat removed the empty directory, which was verified empty and reversible, on 2026-09-26. Status: CLOSED (root removed); the pinning pull request #4792 is closed unmerged as of 2026-10-04 [S16], and the creator of the stray directory is unknown. [S10]

M48 — a byte-order mark read as credential failure (2026-09-10). Two web-research services failed authentication; the measured cause was a single leading UTF-8 byte-order mark in captured credential material, not key invalidity. Both services recovered with unchanged keys, eight tests passed twice, and a decoder mutation was rejected by two controls. Status: LIVE with a readback; the entry records that equivalent shared-loader hardening is still owed. [S10]

M61 — a dispatch ran an unpinned runtime and failed closed (2026-09-14). A review dispatch run from a working tree executed an older strict-equality check that failed closed for every pull request whose base was behind main, with unactionable next-action text. The fix (an ancestor check) was measured passing by the systemd sweep the same night. The recorded verdict: failing closed was right, the unactionable guidance was wrong, and the process defect was invoking a non-pinned runtime at all; dispatches now run only from the pinned release runtime. Status: LIVE. [S10]

M176 — the post-clear seat asked instead of acting (2026-09-27). After a routine context clear, the fresh coordinator context asked h:rlk whether to take the seat instead of acting on the injected instruction. h:rlk’s recorded reply: “the fact that you are asking me any questions, mean something went wrong.” The charter text was corrected within minutes and a memory note pinned. Status: FIXED, with a recorded residual: the orientation-hook pull request #4755 remained unmerged at the time of record. [S10]

M179, M181 and M182 — closure machinery: reasons, refusal side effects and witnesses (2026-09-27 to 2026-09-28). Three defects were recorded in two days: the close tool recorded no reason and the gate refused later edits to closed rows; a refused claim released the caller’s held residue before refusing, so a refusal was not safe to try; and an awaiting row had no governed witness-and-close path while the refusal named the wrong action. All three shipped in pull request #4834, merged on 2026-09-28 [S18], with an activation readback recorded the same night. The catalogue records the honest limit: the new paths had not yet been exercised on a real close at the time of record. Status: LIVE with readback. [S10]

B.4 What this excerpt does not show, and the catalogue’s own bookkeeping flaws

This excerpt shows 23 entries of 189 unjudged. It does not show the 25 retained entries, which are mechanisms the estate keeps deliberately, nor most of the defect classes in the class ledger, nor the inherited September 6 machinery archaeology that the catalogue carries as its historical table. The full catalogue is the source of record. [S10][S11]

The catalogue’s own bookkeeping flaws are part of the record and are shown here at the same prominence as the entries. As of 2026-10-04 the auditor posts 57 bookkeeping flags: five identifiers are defined twice and must be cited with an a/b suffix (M104, M108, M109, M118, M126); status updates exist for entries the table never defined (M43, and M151 to M153, and M166 to M171); six entries carry statuses outside the declared vocabulary; and two entries are flagged as ledger members not found in the catalogue. [S12] The record also preserves a discoverability failure from 2026-09-24: the seat searched file names only, failed to find the catalogue, and minted a duplicate pointer file; a content search then found the real document, and the duplicate remains as a pointer. [S10]

Closing: the state of this draft

This draft has been through the hostile-reader panel of 2026-10-04, which returned FIX-FIRST from both non-Claude families (Gemini 3.1 Pro and GPT-OSS 120B). The findings and their dispositions are listed in FOLDS.md beside this document, and the fold is applied in the text above. The quote check passed against SOURCES.md, and the privacy scan passed. [S20] This draft has not entered the portal release path. The gate record states the remaining sequence: a re-gate on one non-Claude family after this fold, then publication with the next edition, which carries the subject-guard fix. [S20] Corrections to this draft belong on the estate’s correction path, and the sources it cites remain in the private vault at the paths given in SOURCES.md so that later checks can verify every claim.