IMPORT_PROVENANCE.md

pipelines/IMPORT_PROVENANCE.md

WAVE 2 — THE ARC SCHEMA MINT: import provenance

Produced 2026-07-29 by the Wave-2 schema+imports author, READ-ONLY on the repo. Nothing under

C:/dev/humanity-forgotten was edited; the director lands everything.

Governing rulings: docs/proposals/STORY_DEPTH_PROGRAM.md §2 (the arc registry, the census, the

class ordering, §2.4 one-writable-home, §2.5 the regenerable-and-additive carry-forward contract),

§8.1 (the one-table resolution of the three competing ledger proposals), §8.2 (six class grammars

plus one universal enum, two layers), the Wave-2 spec (charter lines 699-716) and the ten-item

freeze order (lines 789-806).

0 · What was produced

State: POST-FIX-ROUND (2026-07-29). A fresh-context critic returned NO-GO on the first mint;

the director accepted all twelve findings and this document describes the FIXED artifacts. §8 is the

per-finding record of what changed.

filerowscols
registry_T0_Arc_Index.csv12834
registry_T0_Arc_Grid.csv123119
registry_T0_Arc_Grammar.csv624
registry_T0_Promise_Ledger.csv12526
registry_T0_Motif_Registry.csv128
fk_spec_additions.json5 registry entries

Every file is UTF-8, no BOM, CRLF, and every row's field count equals its header's — machine-verified

by csv.reader on the raw bytes, not asserted (_audit.py: widths `{34:129} {19:1232} {24:7}

{26:126} {28:2}`, a single width per file, zero duplicate header names, zero lone LFs). One non-ASCII

character survives and is declared: § in T0_Arc_Grid.authoritative_paragraph_anchor on 844 cells,

inherited VERBATIM from the live T0_Thread_Grid column it references — the audit verifies that

against the live file rather than allowing it on trust, so the allowance cannot hide mojibake.

THE FILL RATES, STATED VERBATIM SO A DECLARED-AND-EMPTY COLUMN CANNOT READ AS COVERAGE. Every

one of these is emitted by _verify.py from the landed bytes, not restated from an earlier draft:

All three are ZERO on every thread, antagonist, chain and familiar row, and every row that leaves

any of them blank now carries a per-class NAMED BLANKS declaration in notes naming the reason

and the pass that fills it (1227 rows carry one; ARC_0001's four rows populate all three).

47 / 1231 (25 wave2_schema_import + the 22 new derived:first_anchor_rule stamps);

conflict_flag 0 / 1231, present and deliberately unpolluted; content_summary 195 / 1231.

output; lens_set 61 / 128, with a per-class reason on all 67 blanks; payoff_nodes

53 / 128 arcs / 63 node tokens post-projection; promised_beats 1 / 128; entity_ref

127 / 128 (blank only on the antagonist arc, declared); resolution_node 36 / 128;

grammar_class_ref 23 / 128; named_blanks 128 / 128; open_by_design_reason 0 / 128

(declared — see §5.10).

93 / 125.

1 · THE HOLDOUT — what is deliberately ABSENT, and how the absence was verified

**HANDLING NOTE FOR THE DIRECTOR — this section names the holdout, and it is the only artifact in
this wave that does.** Naming it here is required (the task asks what was excluded and why) and is
safe (a provenance note is not a row, and no gate, enrich pack or skill reads this file). It
becomes unsafe the moment a Wave-5 extractor agent is given this document in its reading set. **Do
not put this file in front of the Wave-5a pilot agents or the Wave-5b fleet.**
**THE FIRST MINT'S CLAIM THAT "the five CSVs and fk_spec_additions.json are clean" WAS FALSE, was
caught by the critic, and is now TRUE and machine-verified** — see §8, finding MAJOR-1. Twenty-five
Wave-5 hits, 22 HOLDOUT hits and 21 twenty-second hits across four of the six artifacts were
deleted; the widened scan now returns 0 leaks over all six.
ONE FURTHER FILE JOINS THIS DO-NOT-SHOW SET: harness/emit_arc_grid.py. The emitter must name
the slot it excludes or it cannot exclude it deterministically, so it carries the id as a bare
constant (EXCLUDED_FAMILIAR_SLOTS) with no explanatory language at all — no reason, no wave
reference, no count. That single line is a declared, printed exemption in the audit; every other
occurrence of the id anywhere still FAILS the scan.

**CL-01, the childhood-familiar chain, is NOT minted, NOT typed, and NOT referenced as a row

anywhere in this output.** Charter freeze rule 9: it is the Wave-5 acceptance test's only real

holdout, and it is only a holdout if nobody hand-types it first.

Everything excluded on that ground, by name, so the exclusion is auditable rather than invisible:

No arc id is reserved for the twenty-second, because reserving a numbered slot is itself a

reference. ARC_0025ARC_0045 are the 21; ARC_0046 is SQ1, not a gap.

DO NOT OVER-READ THE PROTECTIVE VALUE OF THIS ONE (critic MINOR, accepted): the live

T0_Familiar_Registry FAM_22 row is already on disk carrying chapter_first_encounter=CH_01

and chapter_bonding_window=CH_01;CH_58, so withholding the arc row hides no stage of the chain

from anything reading the corpus. The exclusion is cosmetic — freeze rule 9 is explicit and the

drop itself is correct, but what it actually bought was a numbered hole, and the notes cell that

used to explain that hole is what turned a silent gap into a signpost. The explanation is gone; the

gap stays.

labels (CL-03 and CL-04). 27 → 25 minted.

edge. 12 → 11 minted.

except CL-02, which is a *different* finding (the first integrity-driven companion leave) and

enters as the IR-3 ledger edge.

CONTAIN legs and the third clause struck; the row says so on its face without naming it.

is recovered at the waking in the find-beat CH02_B11."* The ruling's fuller wording locates that

beat relative to a holdout stage; that clause is omitted and the beat id carries the anchor.

Verified, not asserted — AND THE FIRST VERSION OF THIS PARAGRAPH WAS THE DEFECT. The first mint

ran a 15-pattern scan whose patterns could not match any of the strings actually on disk, under a

positive control that was a single any() over one probe — which proves ONE pattern fires, never

that the SET is adequate. That is the standing *a search that cannot match reports zero* failure, and

it wrote a false clean-bill into this document twice.

_audit.py now runs a 33-pattern scan across all six shipped artifacts plus the emitter,

under three separate controls:

probe map is the arming record and a pattern with no probe aborts the run. 33 of 33 fire.

a green scan.

are exempt, each with its justification in the output: the familiar grammar row's

required_stages and stage_progression_map (the §8.2 CLASS spec — a class-level stage list names

no instance, and the critic's own fix kept the grammar row while rewriting only evidenced_by),

and the emitter's bare exclusion constant. Exemptions are never pattern-scoped: the same tokens

anywhere else still FAIL.

Result: 0 leaks, 13 declared-exemption matches. The zero is now a real zero.

One real leak was caught and fixed by that scan, and it matters structurally. The first emit

copied T0_Thread_Grid.content_summary into T0_Arc_Grid.content_summary; two of those 666 cells

(THREAD_11/CH_58, THREAD_02/CH_65) and one Block-11 reward line at CH_75 state holdout stages

verbatim. The fix is not a scrub — it is the charter's own §2.4 rule applied properly:

content_summary is now blank on every imported row whose prose has an upstream writable home

(all 666 thread rows and all 370 questline rows), and the arc row carries the source_ref pointer

instead. That removes the leak *by construction*, removes a duplicated writable home, and removes a

guaranteed drift surface the moment a thread cell is edited. The same rule dropped the operative

*names* from the antagonist rows, leaving operative_id (operational_type, awareness_tier) — a

reference, not a copy.

2 · Import class by import class

2.1 T0_Thread_Grid → 22 thread arcs · 666 grid rows

the live count governs and is used everywhere here).

dropped, zero merged.

first_anchor_chapter, final_anchor_chapter and resolution_chapter from the grid and

**asserts equality against the landed T0_Thread_Registry, aborting the whole mint on any

disagreement**. All 22 agreed on all four columns. Seven threads resolve at CH_77 (T01–T06 and

T20); 15 carry no resolution stage anywhere — exactly the charter's set (T07–T19, T21, T22).

2026-07-29, twenty-second sitting). Josh ruled option (a) — every thread gets a declared

disposition — WITH the rider that the per-thread disposition pass runs POST-BOOK-PROCESSING**

(roadmap item R-31). The mechanism the ruling asked for is therefore built and the judgements

are deliberately NOT pre-filled: the new closed-enum column disposition_status

(UNDECLARED | OPEN_BY_DESIGN | RESOLVED) carries the state, the 15 read UNDECLARED with

open_by_design back to FALSE, and each row's finding text moved verbatim into notes. R-31 is

the pass that turns UNDECLARED into a real disposition, thread by thread, on Josh's rider.

writable home for one release**. These arc rows are references. No thread content moved; no

second writable home was created; nothing was retired.

CONFRONTATION|CONFRONTATION_DIRECT→TEST, CONVERGENCE→PAYOFF,

RESOLUTION_*|CAPSTONE→RESOLVE, NOT_PRESENT→NOT_PRESENT. **Every row's derivation_source

carries the original token verbatim**, so RESOLUTION_PARTIAL is recoverable even though it maps

to RESOLVE.

disambiguation cannot be derived. 22 cells were derived anyway, by a stated rule — a thread's

*earliest* ANCHOR is where its promise is planted, and that cell is typed SEED. The rule is

recorded in each row's derivation_source and it agrees with the landed

first_anchor_chapter by construction. **Those 22 cells now carry

authored_by=derived:first_anchor_rule and authored_at_tag=wave2-arc-schema-mint** (critic

MAJOR-6): at first mint they carried neither, so a regeneration that flipped all 22 back to

PRESENT would have passed a count-based T-9 with a floor of zero — the exact data-loss event the

assertion exists to catch. The distinct authored_by value keeps machine-derived separable from

human-authored while still giving T-9 a non-zero floor and a staleness marker; the floor is now

47 authored cells, not 25. The remaining 421 ANCHOR cells are typed PRESENT

(§3.3's "honest home for the degenerate ANCHORs") and stage_role is blank on all of them: that

is the arc pass's one-time authored work, and the T-9 carry-forward assertion is what makes it a

one-time cost.

2.2 T0_Antagonist_Network_Registry → 1 arc · 62 grid rows

antagonist, grammar antagonist_web) with 62 grid rows.

64 operatives are its per-node presences, not 64 arcs. Minting 64 would have made 64 one-node

"arcs" with no shape to check.

CH_39 carry two operatives each (both rendered on one grid row). **17 live nodes carry no

operative row** (CH_PROLOGUE, CH_01, CH_03, CH_10, CH_52, CH_57, CH_66CH_68,

CH_70CH_75, CH_77, CH_EPILOGUE).

reveal-gated to CH_77, and the registry's last row is NW_0062 at CH_76 — the grammar's

terminal has no operative-side row. resolution_node is blank and the row says why.

to a stage — awareness is what the *operative* knows, not what the *player* has been shown, and

conflating them would leak the reveal ladder into the arc grid.

2.3 Familiar acquisition rows → 21 arcs · 25 grid rows

Out: 21 arcs (ARC_0025ARC_0045), 25 grid rows. Excluded: slot 22 — the holdout (§1).

none was invented. The registry cells now say only the class-level fact — "BOND is the only

grammar stage with data; the four later stages are unpopulated at Wave 2" — with no count, no

arithmetic and no pointer (critic MAJOR-1). Their disposition is UNDECLARED with

open_by_design=FALSE: the arcs are unfinished typing, which is not the same thing as a

design decision to leave them open, and the reason text is preserved verbatim in notes.

2.4 T0_Questline_Index + the v3 Block-11 rows → 23 arcs · 370 grid rows

(ARC_0046ARC_0068).

a prose range and the three span columns are *derived, never hand-typed* (§3.1, the rank-28

lesson). A deterministic parser over the 79 live nodes' Block-11 rows returned **370 rows —

SEED 23 / ADVANCE 336 / COMPLETE 11, reconciling exactly with the charter's corrected census.**

The parser is loss-checked: parsed count is asserted equal to the raw ^- SQ\d+ line count

and the emit aborts otherwise. (It caught its own bug doing this: three rows carry a parenthetical

after the stage token — stage ADVANCE (the chapter's lead) — which an earlier pattern silently

dropped. Also caught: docs/spine/CH_57_BUILD_BRIEF.md is not a node and contributes 4 rows that

must be excluded; including it is what produces a spurious 374.)

declared-but-never-used enum member. Stated so it cannot be read backwards: **370 of 370 rows DO

carry a gate expression**; what is missing is the stage *value*. 5 of 12 never COMPLETE

(SQ2, SQ6, SQ8, SQ9, SQ11); 2 never SEED (SQ6, SQ8); the questline row-count spread runs from

SQ8 trickery_gambling at 2 grid rows to SQ3 archaeology_inscription_occult at 59

both numbers emitted by _verify.py from the landed grid, not restated. **CORRECTION (critic

MINOR, accepted):** the first version of this sentence said 58 for SQ3, contradicting both the

emitted data and STORY_DEPTH_PROGRAM.md §2.2's "archaeology's 59". The sentence is now derived

from the per-arc counts rather than restated, so the document's number and the data cannot drift

again. Everything else in the questline census re-verified exactly: an independent recount of

^- SQ\d+ lines across the 79 live nodes returns 370 with SEED 23 / ADVANCE 336 / COMPLETE 11.

row anywhere. This is positive-controlled: the same parser returns 370 rows for the SQ ids, so it

can match. Their three span columns are blank by rule, and T0_Questline_Index.chapter_span

was deliberately not transcribed into a derived column.

literally UNRESOLVED; no name was invented.

2.5 The connective-web artifacts → 60 chain arcs · 104 grid rows · 107 imported ledger edges

The 65 named chains (charter §3.3: 5 beast spines · 6 deity chains · 9 era-rhymes · 11 L3

chains · 27 callback pairs · 7 system spines) reconcile to 60 minted arcs (ARC_0069

ARC_0128). The arithmetic, in full:

SYS-1 = TL-14, SYS-2 = TL-13, SYS-4 = L3-01. Minting both sides would have created two

writable homes for one chain; the SYS-* label survives in aliases.

which the charter's arithmetic excludes because they alias TL-12 and TL-09. Both are merged

into those rows as aliases and not minted separately — this is why the live doc shows 6 beast

spines and 7 deity chains where the charter counts 5 and 6. That discrepancy is a labelling

artifact, not a missing chain.

**Grid rows for chains were emitted only where the source states a machine-readable ordered node

list (RB-1…RB-5, DP-1…DP-6, and the few TL/L3 chains with explicit node sets) — 104 rows across

11+ chains**. The other 49 chains carry blank span columns, because §3.1 forbids hand-typing

first_anchor_node / last_anchor_node / resolution_node from prose; the Layer-0 extractor

populates them. Chain grid rows are typed PRESENT except at a source-stated built terminus

(RESOLVE); the SEED/ESCALATE/TURN/PAYOFF typing is arc-pass work and was not guessed.

The ledger, 125 edges:

source setedges
the 65 named chains (one edge per minted chain arc)60
ECV rows (12 minus the holdout)11
IR set6
spare/kill + mercy returns (Lens B MR-* + the inventory's L-*)9
faction/relationship consequences (FR-01FR-08)8
knowledge/craft/mastery carryforward (KM-01KM-10)10
ARC_0001's own on-disk edges3
PROJECTION EDGES minted at the fix round (critic MAJOR-5)18

The 18 projection edges (PL_0108PL_0125) exist to kill a second writable home. §8.1 keeps

promised_beats / payoff_nodes as derived VIEWS over this ledger, never as a second writable home,

and the first mint broke that on 36 rows: 14 arcs asserted a payoff node while carrying zero

ledger edges, and ARC_0001 asserted CH_13 while its own edges paid off at CH_01, CH_02 and

CH_13. The fix mints the missing edges **from the same on-disk evidence the arc row was derived

from** — 7 for the resolving threads (promise at the first ANCHOR row, payoff at the

T0_Thread_Grid resolution row, edge_state read off that row's own token so a

RESOLUTION_PARTIAL lands PARTIAL and not PAID) and **11, not 7, for the questlines: one per

Block-11 COMPLETE row**, because four of the seven completing questlines type COMPLETE at more

than one node and one edge per questline would have silently dropped a stated completion. Both

columns are then re-emitted strictly as the projection, blank where the projection returns

nothing — verified equal on all 128 arcs.

The TL-NN punchlist and the verified-PAID protect-list are inside the 60: the 12

protect-list chains (TL-01, 02, 07, 10, 11, 12, 17, 18, 21, 23, 26, 27) carry

edge_kind=protect and edge_state=PROTECTED, so a later wave that tries to "fix" a paid chain

hits a typed row rather than a prose sentence. TL-04 (the best friend as a person) is recorded

as the unresolved cardinal fork CF-2 — the row records the fork and does not resolve it.

FR-*, KM-*, MR-* and L-* are beyond the charter's named import set (which names the

chains, the ECV rows, the IR set, the punchlist and the protect-list). They are imported anyway

because they are already-typed early-anchor→late-payoff data in the same artifacts and discarding

them would throw away recovered investment. Each row's populated_from names its exact source

block, so the charter-named set and the surplus are separable with one filter if the director wants

only the named set.

2.6 What the Wave-2 spec does NOT cover, stated so it is not mistaken for coverage

Not imported, because the Wave-2 spec does not name them and inventing them is worse than a

declared gap: the main story arc (1), community/region arcs (76 candidate T0_Region_Index

rows, charter order 2), companion arcs (order 5 — blocked on rank 11 T0_Persona_Index),

partnership arcs (order 7), the protagonist interior arc (Wave 4), and the remaining

object spines beyond the amulet. T0_Arc_Index is at 128 of the census's ~290.

3 · ARC_0001 — Wave 4's orphaned obligation, closed out of order

The charter schedules ARC_0001 for Wave 4, minted *inside* the 18-file amulet integration,

because "the emotional spine of the game scatters across 18 files with no container" otherwise.

That integration already landed on 2026-07-27q (commit 5745772), before this schema existed.

The arc could not be minted with it, and the obligation was orphaned. **This mint closes it from

the landed on-disk rows — a transcription, not a re-opening of the integration.**

Everything in the row was read off disk:

nodebeatsstagestage_role (family grammar)
CH_PROLOGUECHPRO_B07, CHPRO_B16SEEDBIRTHRIGHT
CH_01CH01_B13, CH01_B14, CH01_B07, CH01_B08ESCALATELOSS
CH_02CH02_B11PRESENTABSENCE
CH_13CH13_B13RESOLVEINHERITED_OBJECT

Sources: docs/spine/CH_PROLOGUE.md / CH_01.md / CH_02.md / CH_13.md beat rows;

registries/T0_Equipment_Registry EQ_0001; registries/T0_Thread_Grid THREAD_20/CH_PROLOGUE

and THREAD_20/CH_01; docs/proposals/AMULET_PROVENANCE_BRIEF.md. Later applies folded in:

2d004fd (the eleventh-sitting CH02_B11 find-beat) and e8d9d1f (the nineteenth-sitting naming,

equip_name_text authored).

The depth rubric scored honestly — and it does NOT read 6/6:

1. CARRIER — EQ_0001, a real registry row → PASS

2. COST — UNSCORED → scored as a MISS. T0_Chapter_Index.cost_ledger is minted in Wave 4

and does not exist yet, so no row can be pointed at.

3. SETUP BEFORE PAYOFF — CHPRO_B07 precedes CH13_B13 in build order → PASS

4. BEHAVIOURAL CONSEQUENCE — CH01_B13 writes local.ward_off_the_neck, CH01_B14 reads it;

CH01_B08 writes local.amulet_crossed, all inside the span → PASS

5. ≥3 TOUCHES — four nodes, eight beats → PASS

6. DISPOSITION — terminal payoff edge at CH13_B13PASS

5/6 (1 UNSCORED). This is load-bearing and is flagged rather than rounded up: **the Wave-5

acceptance test requires 6/6 on this chain, and it structurally cannot reach 6/6 until Wave 4 lands

cost_ledger.** Running Wave 5a against ARC_0001 before Wave 4 completes fails the acceptance

gate on a schema gap rather than on the instrument — the freeze order (item 6: the amulet

integration before sweep #1) already implies this, but the arithmetic makes it concrete. (The

registry row states the same fact without the wave reference, which is why the CSV wording and this

paragraph differ.)

Two of this arc's cells moved at the fix round. payoff_nodes now reads

CH_01|CH_02|CH_13 — the projection of its three ledger edges — where it formerly asserted CH_13

alone; and promised_beats now reads CHPRO_B07|CH01_B13|CH01_B08, the beat ids parsed off its

edges' promise_anchors, where it formerly carried five prose promise statements. The prose is not

lost: it is preserved verbatim in the row's notes under the projection annotation. The projection

carries no claim that a payoff is PAIDedge_state on the ledger is the only claim.

And this arc's two stage_role cells are now the gate-31 must-fire fixture. CH_01 carries

LOSS at ESCALATE and CH_13 carries INHERITED_OBJECT at RESOLVE; the family grammar's

stage_progression_map declared LOSS>TURN and INHERITED_OBJECT>ESCALATE, so §8.2's own named rot

surface was live on 2 of the 4 authored cells at mint. **The map was corrected to the built arc, not

the arc to the map** (critic MAJOR-2): the craft source states the five stage names and states no

stage-to-enum mapping, so the map is the side free to move. Many roles to one enum is legal — the

companion map already sends COST and CHOICE both to TURN; one role to two enums is what §8.2

forbids.

4 · Re-verification against the live v3 spine — what changed since 2026-07-14

The source map is reconciled to the 2026-07-14 built state. Every state claim imported here was

re-read against the live v3 corpus (79 nodes on disk). Corrections applied at import rather than

carried forward:

*absent* at Ch 42 and asks for him to be surfaced; the live CH_42.md carries Legba ×10 including

the explicit recognition line *"recognized here as the same crossroads-opener met on the Yoruba

coast as Eshu-Elegba at Ch 12."* The payoff is BUILT. What remains open is the **earned-relationship

tiering** on top of it, which is FR-05's edge, not this one.

gate-numbering cardinal; that cardinal is RULED (tenth sitting + the 2026-07-28 grade-band

mapping): twelve real levels 1–12, the ten names as grade bands, gate *numbers* retired.

T0_Trade_Registry now carries the re-keyed 12-level ladder with the Portal/Abyss ids in

ceremony_quest_refs.

the Ch 39→55→63→65 good-deity war-ally wiring.

convergence node with the F1(A) spare/kill fork intact; the node is fixed, the outcome stays

the player's; Ch 75 is branch-balanced either way. Vritra's care tier is RULED **elevated with

maximum-register duties** (seventeenth sitting).

canonical and is recorded as *not* a fork, so no later wave re-surfaces it.

ballgame ×38 but zero ball-court and zero Senet — the capstone is built and its

runway is not.

in exactly one live node (CH_01) and zero times in CH_EPILOGUE.md.

docs/spine/CH_57_BUILD_BRIEF.md, which is not a spine node.

companion-departure probe over all 79 live nodes returns no companion leaving or being drawn on

integrity grounds (its 86 raw hits are "…ally left behind" lexical adjacency). The positive

control on the same corpus returns 15 nodes for Departure/Continuation and 78 for

companions_present, so the search *can* match. The one real departure structure is the Ch-65

Ntala Departure/Continuation, which the source itself classifies as sticky-either-way.

Flores); the Ch-2 carved mark has no consumer. Its payoff_node is blank *because there is

none* — that is the finding, not a gap in the import.

(×20), CH_65 re-bound menagerie (×20), CH_69 Apep (×49), CH_75 Last Coil (×43) with Arawn

crossing (×11) and Louhi excluded (×6), CH_74 nidhoggr (confirming ECV-11's roster tail).

5 · Shape calls the director should ratify or overturn

1. UTF-8 with NO BOM. The brief specified BOM; zero of the 57 live registry CSVs carry one,

and harness/build_canon_graph.py:77 opens registry CSVs with plain utf-8 (not utf-8-sig),

so a BOM would corrupt the first header cell for that consumer. Emitted BOM-less to match

measured house style; trivially reversible if the director wants otherwise. CRLF as specified

(24 of 57 live files use CRLF; csv.writer writes it natively).

2. entity_ref on the arc row vs arc_id on the entity registry. §2.4 item 2 prescribes an

arc_id FK on each entity registry — the opposite direction from entity_ref here. **Only

one may exist** or the edge has two writable homes. entity_ref was used because it requires

zero edits to five live registries and this agent is read-only; drop it in the same commit that

adds arc_id if the charter direction is preferred. Flagged in the fk_spec _note.

FIX-ROUND CHANGE (critic MINOR, accepted): all 60 chain arcs now carry their source's own

primary chain id (RB-1, TL-01, SYS-3, DP-4, L3-07, ER-5 …) in entity_ref, taken

from the chain table the rows were minted from; ARC_0069 gets RB-1 back as its primary while

keeping TL-08|MR-4|ECV-11 in aliases. Every arc row except the antagonist web (declared) now

has a one-hop trace to its authoring line instead of a two-hop join through

T0_Promise_Ledger.source_chain_ref. entity_ref is registered in the fk_spec _note as a

documented free-text source key, not an FK edge — it is a mixed-prefix space with no single

target table, the documented-not-encoded idiom already used for yields_ref and range_id.

3. One antagonist arc, not 64 (§2.2 above).

4. T0_Arc_Grammar is one row per class, with the §8.2 stage→enum mapping carried as a packed

stage_progression_map cell (MEET>SEED|PROVE>ESCALATE|…) — the house packed-cell idiom

(T0_Composure_Routing.counter_class_interaction). This keeps the charter's "~6 authored rows"

while making the mapping gate-checkable data rather than prose.

5. T0_Motif_Registry ships with exactly ONE seed row. SC-3 motif work ships *merged into* the

natural-voice wave (Wave 6) and must never be a second pass over the same player-facing lines, so

a motif roster now would create the forbidden double-pass. The one row (MOT_0001, the mother's

ward) exists so gate 34 has a positive control — a ruler that has never fired on real data cannot

be trusted to fire later. Every assertion it does not exercise must still declare itself

NOT-ARMED. Overturnable to header-only.

6. reveal_window vocabulary — RATIFIED, question CLOSED. The vocabulary minted here

(none / CH_38 / CH_76 / CH_77, examples-not-limits per the charter's own enum rule)

was RATIFIED by Josh on 2026-07-29. This shape call is no longer open; it is canon for the

arc axis, and the enum stays open to extension by ruling rather than being closed by this mint.

(Carried on the director's open-question list as item 4 → CLOSED.)

7. The first-anchor→SEED derivation (§2.1 above) — 22 derived cells against a charter line

saying the disambiguation is underivable. Stated rule, recorded per row, reversible.

8. arc_class on T0_Promise_Ledger is a declared derived mirror of

T0_Arc_Index[arc_id].arc_class. KEPT (director ruling). The charter's §3.3 column list

carries both, so the column stays — and gate 32 must assert it equal to

T0_Arc_Index[arc_id].arc_class or it becomes a rot surface. Named as gate 32's obligation in

the fk_spec _note, alongside the two projection assertions (§5.11). Verified equal on all 125

edges at the fix round; the gates lane owns the standing assertion.

9. Two grammar rows are declared UNEVIDENCED on their facecrew (register #42, zero

instances corpus-wide) and familiar, whose evidenced_by now reads exactly

"UNEVIDENCED AT WAVE 2 — teeth ship UNARMED" with the worked-instance sentence deleted

(critic MAJOR-1). §1.4 says a stage that cannot be evidenced from a built arc does not enter the

spec; these two bend that rule *visibly*, and their teeth ship UNARMED.

10. open_by_design is FALSE on every row and open_by_design_reason is blank on every row.

This is the fix-round's most visible shape change and the director should read it deliberately.

disposition_status is derived — RESOLVED where a resolution node exists on disk, UNDECLARED

everywhere else — and open_by_design is its boolean mirror. **OPEN_BY_DESIGN is therefore

authored ZERO times**, which is recorded as a finding rather than hidden: *no source anywhere in

the corpus states a design intent to leave an arc open*. The 73 rows that previously carried

TRUE fell into three groups, and **every one of them denied its own value in its own reason

cell** — the 15 threads ("NOT open by design — UNRESOLVED AND UNDECLARED"), the 21 chains ("the

reason is the chain's own state, not a design decision"), and the 15 questlines + 21 familiar

arcs ("declared open only to stop it reading as resolved" / "not finished being typed"). Setting

any of them to OPEN_BY_DESIGN would have re-created the critic's MAJOR-3 inversion inside the

brand-new column whose entire purpose is to remove that ambiguity. **Every reason cell is

preserved verbatim in notes**, so overturning this is one function in the emitter and no

information was destroyed. R-31 is the pass that authors the real dispositions.

11. payoff_nodes and promised_beats are now PROJECTIONS, not authored cells. They are

re-emitted from T0_Promise_Ledger on every run and are blank where the projection is empty.

payoff_nodes populates 53 arcs / 63 tokens (up from 36 arcs) because a chain arc's ledger edge

carries a payoff node even where the arc row left the cell blank; the column carries **no claim

that the payoff is PAID** — edge_state is the only claim, and the rows say so.

6 · Debts and unresolved items handed to the director

resolve to nothing today (Q_TR appears zero times in T0_Quest_Definition_Registry), and

registering an edge whose entire token set dangles would report every row as broken. Recorded as a

named debt in the fk_spec _note, not silently dropped.

Wave 6. payoff_promise_id is realised here as T0_Motif_Registry.promise_ref.

the dedup must happen at gate-authoring time, not at fixture time. Carried into the ledger's

_note so the teeth wave cannot miss it.

hidden: UNEARNED is one of the three v1 extractor classes that cannot fire until the beat-level

promise: token exists (§3.2), and a never-used enum member is itself a finding.

and named here so the gate-31 author knows the column is theirs to compute — an UNSCORED criterion

scores as a MISS, never as satisfied.

gate 32 promise_ledger (P1–P8) are the same-commit obligation the Wave-2 spec attaches to this

schema. The carry-forward columns exist and are populated (stage_role 25 cells, authored_by

47, authored_at_tag 47, conflict_flag present and empty) so T-9 has something real to count on

its first run. The assertions this fix round hands the gates lane, each with its fixture:

grammar row's stage_progression_map, to EXACTLY the cell's progression_stage.

Must-fire fixture: ARC_0001 @ CH_01 and @ CH_13 — the two cells whose disagreement was

the finding, so the ruler is proven against the case that produced it. Run locally at the fix

round over all 25 populated cells: 0 violations.

one that drops one ANCHOR-disambiguation cell. Both must exit 2. The second case is the

one the first mint could not have caught.

named_blanks / notes declaration on its row, so an empty join column can never read as

coverage. Verified locally: 1227 / 1227 rows carry one.

"NOT open by design", and open_by_design must agree with disposition_status.

promised_beats == the same edge set's promise-anchor beat ids, and arc_class ==

T0_Arc_Index[arc_id].arc_class. All three verified equal at the fix round.

row would put fabricated data into a canon registry to exercise a ruler; the fixture belongs in

the gate's own test corpus, where a fake row costs nothing. The gates lane owns that fixture

— recorded here so it is not mistaken for an oversight. The emitter's collision path is real

code and ran on live data at the fix round (47 authored cells carried, 0 collisions).

--emit-baseline refresh** are all same-commit obligations (§7 items 2–4) that a read-only agent

cannot perform.

generator is consolidated into ONE self-contained file, harness_port/emit_arc_grid.py, ready to

land as harness/emit_arc_grid.py; see §7. What remains for the director is the landing itself:

the two gate scripts, the roster bump 30→32, the DOC_MAP rows and the registry_extensions.json

entries.

92 UNDECLARED rows into real dispositions. It is a roadmap item, not a debt of this mint.

7 · How to re-derive this output — THE EMITTER, PORTED

The four scratchpad generator files are SUPERSEDED. They were an orphan at birth: a one-shot

dump whose only emitter lived in a session scratchpad and died with the session, which is exactly

the exposure W0-5 exists to close (critic MAJOR-7). They are consolidated into **ONE self-contained

file ready to land as harness/emit_arc_grid.py** (it sits at harness_port/emit_arc_grid.py

because this agent is read-only on the repo):

python harness/emit_arc_grid.py --out <dir>            emit all six artifacts
python harness/emit_arc_grid.py --out <dir> --check    re-emit to a temp dir and byte-compare
python harness/emit_arc_grid.py --out <dir> --root <repo root>

originals with every substitution asserted exactly-once, then run before any fix was applied: all

six artifacts came out byte-identical to the shipped first-mint files. Only then were the

fixes applied, as 32 exactly-once patches (_consolidate.py, _patch.py — both kept as the

evidence trail). The four superseded originals stay in the scratchpad and are NOT landed: they

still carry the first mint's explanatory language in their docstrings and comments, so they belong

to the do-not-show set with this file. Land emit_arc_grid.py, not them.

the script's own parent repo → the fallback path, each candidate checked for registries/ and

docs/spine/. Verified end-to-end by running a copy from a simulated <root>/harness/ directory:

all six artifacts byte-identical.

all six artifacts.**

carrying an authored value on disk is carried forward; a re-derivation that contradicts it KEEPS

the authored value and writes conflict_flag. It is PASS-on-empty and says so out loud on a

first run with no file on disk. Exercised on the real first-mint file: 47 authored cells carried,

0 collisions, output identical to the from-scratch run.

accepted): Arc_Grid is the one regenerable table, so a lawful upstream shrink must not red-gate a

build with no defect present. The floor is a mass-emptying tripwire, not a growth ratchet. The

four authored tables keep exact floors at their landed counts.

parse loss, an illegal progression_stage, an unknown node id, a bad enum value, or any row whose

field count differs from its header. Every file is written tmp-then-os.replace.

_audit.py (width, encoding, the 33-pattern leak scan with per-pattern positive controls, FK floor

computation, referential self-check) and _verify.py (the five fix-round checks + the fill-rate

recount this document quotes) are the verification pair. Run

python harness/emit_arc_grid.py --out . && python _audit.py && python _verify.py.

8 · THE FIX ROUND — the critic's twelve findings, and what changed

The first mint returned NO-GO. All twelve findings were accepted by the director. Per finding:

#findingdisposition
MAJOR-1the holdout announced inside four of the six shipped artifacts (25 Wave-5 / 22 HOLDOUT / 21 twenty-second hits), under a scan that could not matchFIXED — 13 distinct offending cells rewritten to class-level facts; scan widened to 33 patterns with per-pattern positive controls, a negative control, and cell-scoped declared exemptions; 0 leaks across all six artifacts + the emitter
MAJOR-22 of the 4 authored stage_role cells contradicted the family grammar map — §8.2's own rot surface live at mintFIXED — map corrected to the built arc (LOSS>ESCALATE, INHERITED_OBJECT>RESOLVE); those two cells are now gate 31's must-fire fixture; 25/25 cells verified consistent
MAJOR-3open_by_design carried its own opposite on 15 of 22 thread rows, pre-empting FORK J-2FIXED under the RULING — J-2 ruled option (a) + the post-book-processing rider; disposition_status minted; the 15 read UNDECLARED / FALSE; findings moved to notes; R-31 owns the real pass (§5.10 records the wider application and the reasoning)
MAJOR-4beat_refs / state_reads / state_writes empty on 70% of rows and declared nowhereFIXED — per-class named-blank declarations on all 1227 affected rows; fill rates stated verbatim in §0
MAJOR-5payoff_nodes was a second writable home; 17 of 36 populated rows disagreed with the ledgerFIXED — 18 projection edges minted from on-disk evidence; both columns re-emitted strictly as projections; equality verified on all 128 arcs
MAJOR-6T-9 inert on its ANCHOR-disambiguation column: 0 of 22 SEED cells carried authored_byFIXED — 22 cells stamped derived:first_anchor_rule / wave2-arc-schema-mint; T-9 floor 25 → 47; the two-case fixture and the conflict_flag fixture handed to the gates lane
MAJOR-7the emitter was an orphan in a session scratchpad; porting was not even on the obligations listFIXED — consolidated, faithfulness-proved, determinism-checked, runs from harness/; §7
MINOR (FAM exclusion)the exclusion protects nothing and its explanation turned a silent gap into a signpostFIXED — explanation removed from every row; §1 now records that the exclusion is cosmetic
MINOR (depth_grade / lens_set)two charter-named columns empty and largely undeclaredFIXED — declared on all 128 rows / all 67 lens_set blanks; both fill rates in §0; depth_grade named as gate 31's output in §6
MINOR (entity_ref)60 of 60 chain arcs unjoinable by id; ARC_0069 had dropped its own primaryFIXED — all 60 populated, RB-1 restored, documented in the fk_spec as a free-text source key
MINOR (§2.4 count)"58" contradicted the emitted data and the charter's 59FIXED — corrected and re-derived from the per-arc counts
MINOR (Arc_Grid floors)exact floors pinned on the one regenerable table = a noisy gate that gets disabledFIXED — the emitter rewrites those floors every run; rule recorded in the fk_spec _note

Two judgement calls the director should overturn if either reads wrong, both flagged rather than

buried: (1) the disposition_status derivation was applied uniformly rather than only to the 15

threads — see §5.10 for why keeping TRUE anywhere would have re-created the finding, and note that

every original reason cell survives verbatim in notes; (2) the leak scan carries **two declared

cell-scoped exemptions** for the familiar grammar's required_stages / stage_progression_map,

because arming those three stage-name patterns absolutely would delete the class grammar the critic's

own fix kept. Both are printed on every audit run, so neither can rot into an invisible allowance.

Generated by harness/site/structure_site.py — the URL path is the repo path. review root