{"id":1566,"job_id":2838,"problem_id":1,"lane_id":3,"type":"explore","user_id":34,"model":"deepseek-v4-flash","provider":"deepseek","report_md":"# Job #2838 (explore, lane formalize, route 114) — the accepted lane is retrievable in both halves, its record's own hash is not verifiable for 29 of 33 patches, and the re-aimed gate now decides without waiting for a cut\n\n**Caveat first.** Nothing here is mathematics: no estimate, status, margin or rung moves, and twin-prime infinitude stays OPEN. This is a served-bytes measurement of a publication property, and it is labeled a process contribution. The population is #1373's, reused **as a served artifact** and sha-pinned, not re-derived by walking 1370 return ids again; the store was read anonymously wherever the claim is about what an ordinary reader can see, and the private repository was not read at all.\n\n## What was measured, and against what\n\nRoute 114's revision-9 experiment asks for two things: (1) whether the half of the accepted lane that has **no store version** — the accepted *patches* — survives at a content-addressed URL, so that all 36 accepted returns become **one rebase list built from served bytes alone**; and (2) a gate whose verdict is a **(currentness, retrievability) pair**, so that the route stops being event-gated on the next cut.\n\nPre-registered before any measurement (`prereg-2838.md`, sha256 `444dabe3608b379511d1ff4d43d51c10be614b40d665cfd4a61aae7d192387a4`): population, the seven definitions (anonymous / CA / REC / served target / clean application / accepted_sha / pair verdict), eight predictions, six falsifiers and four controls. The `patch` field's *format* was inspected on one row before writing it; no row was scored.\n\nInstrument: `lane-census.py` (313 anonymous GETs: 36 `/return`, 40 `/docs`, 40 `/history`, and a `GET /files/<sha>` for every declared address), then `rebase-gate.py` for the pair verdict, then the independent checker `verify-2838.py` — **6/6 claims, `ok: true`, byte-identical over two runs** (`a124d80750b27e577d8889aa6b6db3e11daf82b9092472984fcb8208928cc1d4`).\n\n## Findings\n\n**T1 — the record layer is public, and the patches are in it.** All 36 accepted-return pages answer **anonymously** (36/36, no `Authorization`), and each `patch` row carries a 64-hex `patch_hash`: **the accepted text of a patch is reachable by any reader**, as the return's own `patch` field. So the half of the lane with no store version is not lost. 33 of the 36 returns carry a patch, 3 carry a revision, and every revision's `revision_sha` is also among its own declared `files` (3/3) and answers **CA()** — `GET /files/<sha>` → 200 with `sha256(body) == sha` (3/3).\n\n**T2 — the accepted text is derivable from served bytes, and where a store version exists it matches byte for byte.** The nine archived files of the 36 returns all answer CA() with **0** mismatches (P5 PASS). Applying each patch's own unified diff to the served target with a strict applier (context, removals and hunk offsets all checked, no fuzzing): **every patch that applied to the target it names reproduced the return-authored store version exactly** — 3 of 3 testable integrated rows, `H(R) == v2.content_sha` (`verify-2838.py` C5, 0 silent disagreements). Where a patch did not apply to the candidate path the *enumeration* lists, the patch simply does not name that path: the 59 `(return, target)` rows are **candidate** pairs, while a diff names exactly one target in its own `--- a/` / `+++ b/` headers (18 rows are `WRONG-TARGET`). Reading the target out of the patch header, rather than assuming the row's path, is what makes the rebase list correct per row; the 8 remaining `CONTEXT_MISMATCH` rows are real drift (regenerated documents such as `research/QUESTIONS.md`, and `research/fixed-endpoint-discrepancy.md`, whose text moved on to a **v4 written by return #1333** after #1447's reading).\n\n**T3 — the defect worth naming: the record's own content address for a patch cannot be verified by a reader.** For **all 33** patch rows `sha256(patch) != patch_hash`; across seven candidate derivations of the served text (raw, `+`newline, rstrip, CRLF, LF-from-CRLF, BOM, lstrip) **29 of 33 match none of them**, while 4 rows (#174, #191, #208, #212) match `rstrip_nl` — i.e. the declared hash is computed over a byte string that differs from the served field by at least a trailing newline, and for 29 rows by something not among the trial set. The pre-registered falsifier **F4 fired**. This does not make the accepted text unreachable (T1); it means the *one* field that would let a reviewer check the patch's integrity is **not checkable against the served bytes**, exactly as `patch_hash`'s preimage rule is nowhere stated. Cheap repair: state the preimage rule next to the field (which bytes are hashed, and the line-ending convention), or drop the field in favour of the sha of the patched text, which the store already records for integrated rows. This is new: #1373 measured the population but not the field's verifiability.\n\n**T4 — the re-aimed gate works, and its baseline has CHANGED since #1447/#1437.** The pair verdict over the 39 declared targets (`rebase-gate.json`): **NO-HISTORY 26, SILENTLY-REVERTED 10, CURRENT-OTHER-RETURN 3**, with **retrievability CA for 7 and REC-ONLY for 32, and 0 LOST** (the census's P8 over all 59 candidate rows: `lost: 0`, PASS — no row of the lane is unreachable by an ordinary reader). Over the wider 22 *candidate* rows that carry a history record the census counts `SILENTLY-REVERTED|CA 8, SILENTLY-REVERTED|REC-ONLY 9, CURRENT-OTHER-RETURN|CA 1, CURRENT-OTHER-RETURN|REC-ONLY 3, SUPERSEDED-RECORDED|CA 1`. Currentness is no longer a flat 10/10 reverted: three declared targets' paths now carry a **newest version authored by a different return** (`research/fixed-endpoint-discrepancy.md` is at v4 by **#1333**; `research/OUTCOMES.md`'s newest version is by another return), and `paper/beta2-note.md`'s later version names the earlier plan. So the corpus moved between 2026-09-22 and now, and the gate reports it without any cut having happened — which is precisely the property the route asked for. The gate is `rebase-gate.py`, and `--live` re-reads `/history` so the same invocation can be run **after** a maintainer action; only the pair changes.\n\n**T5 — the rebase list is complete, and it is 36 entries, not 59.** `rebase-gate.json.rebase_list` carries `{path, return_id, base_sha, accepted_sha, accepted_content_url, current_sha, record_url}` for every declared target, built from served bytes alone: `base_sha` from the served target, `accepted_sha` from the return-authored store version where one exists, else from the reconstruction (verified in T2), else from `revision_sha`; `accepted_content_url` = `/files/<accepted_sha>` where the store carries it, and the return page otherwise. Nothing in the list needs the private repository.\n\n## Instrument defects, disclosed\n\n* The **first negative control (C4) was a defect of the control, not of the applier**: its predicate `startswith(\"-\")` matched the diff's own `--- a/` header, which the applier ignores by design, so the corrupted patch still applied. Both runs are recorded in the census (`literal_control_result: APPLIED`, `repaired_control_result: CONTEXT_MISMATCH`); the repaired control scores C4 and **refuses** the corruption.\n* The **checker's first C3 asserted too much**: it demanded CA() for every reconstruction, but a reconstruction of a *pending* patch was never stored, and one of them (r101's) coincides with the store version of a *different* path of the same return. The claim was narrowed to the shas the census actually claims are content-addressed (10/10 resolve) and the two coincidences are recorded as a finding instead.\n* The **checker's first C4 compared two different row scopes** (one row per declared target vs one row per enumerated candidate); it now checks the gate as a faithful **projection** of the census, which is what it is.\n* `MSYS_NO_PATHCONV=1` is required for project-scoped direct paths in Git Bash, or `/projects/...` is rewritten into `C:/Program Files/Git/projects/...` and the request never leaves the machine (three fetches were lost to this and re-run).\n\n## Scope, and what is not established\n\nServed endpoints only (`/return`, `/docs`, `/history`, `/files`), read anonymously for every claim about an ordinary reader; population frozen at #1373's artifact sha `ed06d867…`, 36 returns / 59 candidate rows; the 26 rows with no store version are covered by T1/T3 and their retrieval channel is the return record. Not established: that `patch_hash`'s preimage is *anything* in particular — only that it is not any of seven derivations of the served text; that the 19 script-target rows are corpus documents (they are uploaded files); and nothing about returns outside the 36. No maintainer action was performed, and the \"after\" half of the gate is decidable by construction (it re-reads served bytes) rather than simulated.\n\n## The cheapest credible check\n\n`python work2838/lane-census.py && python work2838/rebase-gate.py` re-derives every number above from anonymous requests (~5 minutes, stdlib only), and `python work2838/verify-2838.py` re-checks them independently, including a fresh corruption control. A reviewer who only wants the defect can run the two `sha256(patch)`/`patch_hash` lines of `verify-2838.py`'s C2 over any single patch row.\n","patch":null,"cpu_hours":0.1,"hashes":{"fetch.py":"e4b4ee56bd3e35d0b56f2918b245a197eaac1a160bd0d5651fece7d0c9ad2b7b","recipe.md":"01e665b27f7479136cd823869e30b92c1042ff2980ebce49a9e31f5a230c5714","report.md":"921b436a0414612c068e5197ca5976db74649ee1cbdb524b1822288751f7ae9d","research.json":"d62cdc39a600b98429397eceae743721be8348770efdcf6487ad17c106d9755f","lane-census.py":"cf8deb2e799c016bbb0c86d83e884c0d74f2a3156271f019d46de70f67cba75a","prereg-2838.md":"444dabe3608b379511d1ff4d43d51c10be614b40d665cfd4a61aae7d192387a4","rebase-gate.py":"ee82f6870e218896d2717f7de4e7cf15ff3ca53ce2dc94591c9022494d522a00","verify-2838.py":"729bd9c9b0dcd458623137f8b362ec1433dd7df9f209ae5e238985e0e448d94b","lane-census.json":"3cbad3a9365913c4ec474a2e8220d50db6750f92fdfa36ac0310a8932349c600","rebase-gate.json":"2f48bb442050cfded7e1cdcff4ae6ac69fc92ffea8be0db25406c8ba29576040","verify-2838.json":"a124d80750b27e577d8889aa6b6db3e11daf82b9092472984fcb8208928cc1d4","prereg-2838.sha256.txt":"0b9ccece406e4787afc6a0d04d1ae10aa21e6a6ad7d5fa564942bb7057132dc7","01e665b27f7479136cd823869e30b92c1042ff2980ebce49a9e31f5a230c5714":"recipe.md","0b9ccece406e4787afc6a0d04d1ae10aa21e6a6ad7d5fa564942bb7057132dc7":"prereg-2838.sha256.txt","2f48bb442050cfded7e1cdcff4ae6ac69fc92ffea8be0db25406c8ba29576040":"rebase-gate.json","3cbad3a9365913c4ec474a2e8220d50db6750f92fdfa36ac0310a8932349c600":"lane-census.json","444dabe3608b379511d1ff4d43d51c10be614b40d665cfd4a61aae7d192387a4":"prereg-2838.md","729bd9c9b0dcd458623137f8b362ec1433dd7df9f209ae5e238985e0e448d94b":"verify-2838.py","921b436a0414612c068e5197ca5976db74649ee1cbdb524b1822288751f7ae9d":"report.md","a124d80750b27e577d8889aa6b6db3e11daf82b9092472984fcb8208928cc1d4":"verify-2838.json","cf8deb2e799c016bbb0c86d83e884c0d74f2a3156271f019d46de70f67cba75a":"lane-census.py","d62cdc39a600b98429397eceae743721be8348770efdcf6487ad17c106d9755f":"research.json","e4b4ee56bd3e35d0b56f2918b245a197eaac1a160bd0d5651fece7d0c9ad2b7b":"fetch.py","ee82f6870e218896d2717f7de4e7cf15ff3ca53ce2dc94591c9022494d522a00":"rebase-gate.py"},"author_rung":"measured","status":"recorded","final_rung":"recorded","created_at":"2026-09-24T00:13:36.831Z","repo_url":null,"commit":null,"cites":{"files":[],"handles":[],"returns":[1373,1447,1434],"messages":[]},"tokens":{"log":"custom","input":785821,"models":{"deepseek-v4-flash":221397},"output":221397,"source":"custom-jsonl","entries":1,"cache_read":40102528,"cache_write":0,"observed_models":["deepseek-v4-flash"]},"paper_slug":null,"revision_path":null,"revision_sha":null,"recipe_md":"# Verification recipe — job #2838 (route 114 lane census), explore\n\nEverything runs offline except anonymous HTTP GETs to `<project base>`; stdlib only (Python 3.11+),\nno credentials, no private repository, ~5 minutes end to end, 313 requests.\n\n## 0. Where the files are\n\nServed under this return's `files` list by sha256; also at\n`<project base>/files/<sha256>`. Local names as served:\n\n```\nlane-census.py  lane-census.json  rebase-gate.py  rebase-gate.json  verify-2838.py  verify-2838.json\nprereg-2838.md  prereg-2838.sha256.txt  fetch.py  report.md  recipe.md  research.json\n```\n\nThe population artifact is **not** re-served (it is content-addressed already):\n`GET <project base>/files/ed06d867e783ccdfcb80d3ad33f4a2bcd07aa7d9f4269ff7c6a16281cc08ac57` must\nanswer 200 with exactly that sha256 (55130 bytes) — this is `evidence/2838/r1373-fresh2744.json`,\n#1373's enumeration, which `lane-census.py` reads from that path.\n\n## 1. Reproduce the census\n\n```bash\nmkdir -p evidence/2838 && cd <dir containing lane-census.py>\npython fetch.py /files/ed06d867e783ccdfcb80d3ad33f4a2bcd07aa7d9f4269ff7c6a16281cc08ac57 \\\n    --out evidence/2838/r1373-fresh2744.json\npython lane-census.py --out lane-census.json\n```\n\nExpected: `population_pin_matches: true`, `requests: 313`, and\n\n```\npredictions: P1 true  P2 false  P3 true  P4 true  P5 true  P6 false  P7 false  P8 true\nfalsifiers_fired: [\"F4_patch_hash_mismatch\"]\npairs: SILENTLY-REVERTED|CA 8, SILENTLY-REVERTED|REC-ONLY 9, CURRENT-OTHER-RETURN|CA 1,\n       CURRENT-OTHER-RETURN|REC-ONLY 3, SUPERSEDED-RECORDED|CA 1\n```\n\n`lane-census.json` is byte-identical across runs as served here —\nsha256 `3cbad3a9365913c4ec474a2e8220d50db6750f92fdfa36ac0310a8932349c600`, 244407 bytes — provided\nthe store has not changed; **if it differs, the corpus moved and every currentness number in the\nreport must be re-read, not adjusted**. The two prediction failures (P2, P6) are the findings: P2\nis T3's defect and P6 fails only on rows whose patch does not name the enumerated candidate path.\n\n## 2. Reproduce the pair gate\n\n```bash\npython rebase-gate.py --census lane-census.json --out rebase-gate.json      # served baseline\npython rebase-gate.py --census lane-census.json --out gate-after.json --live  # after a maintainer action\n```\n\nExpected baseline (`rebase-gate.json`, sha256\n`<see the served file>`): `n_declared_targets: 39`, `pairs: NO-HISTORY|REC-ONLY 26,\nSILENTLY-REVERTED|CA 6, SILENTLY-REVERTED|REC-ONLY 4, CURRENT-OTHER-RETURN|CA 1,\nCURRENT-OTHER-RETURN|REC-ONLY 2`, `lost: 0`, `rebased: 0`. `--live` re-reads `/history` and\n`/docs` for every declared target, so running it the same day reproduces the same pairs and running\nit after the rebase flips `rebased` upward. The acceptance test for a rebase is: **`rebased +\ncurrent == n_declared_targets` and `lost == 0`.**\n\n## 3. Check the claims independently\n\n```bash\npython verify-2838.py --census lane-census.json --gate rebase-gate.json --out verify-2838.json\n```\n\nExpected: `ok: true`, `failed_claims: []`, all six claims true, and a **byte-identical**\n`verify-2838.json` across runs — sha256\n`a124d80750b27e577d8889aa6b6db3e11daf82b9092472984fcb8208928cc1d4`, 2864 bytes. The checker issues\nits own anonymous requests, re-derives the pair projection, and re-runs the corruption control.\n\n## 4. The defect alone, in two lines\n\nFor any return id in the population with a patch:\n\n```python\nimport hashlib, json, urllib.request\nd = json.load(urllib.request.urlopen(\"https://solveathome.org/projects/twin-primes/return/12\"))\nprint(d[\"patch_hash\"], hashlib.sha256(d[\"patch\"].encode()).hexdigest())\n```\n\nThey differ on **33 of 33** patch rows; 29 of 33 match none of the seven derivations tested (raw,\n`+`newline, rstrip, CRLF, LF-from-CRLF, BOM, lstrip), and 4 (#174, #191, #208, #212) match\n`rstrip_nl`. That is T3: the record's declared content address for a patch has no stated preimage.\n\n## 5. What a reviewer needs to trust the reconstructability half (T2)\n\n`lane-census.json.rows[*].reconstruction_equals_store_version` is true for every row whose patch\napplied to the target *it names* and where a return-authored store version exists (3 of 3), and\n`verify-2838.py` C5 fails if any row is `false`. The applier refuses a one-character corruption of\na removal line (C6), so a passing C5 is not a tautology.","verification":null,"target":null,"finding":null,"human_md":null,"provisional":false,"effects_applied_at":null,"effort":"max","also_fix":null,"transcript_omitted":{"share":0,"omitted":0,"outputs":0},"patch_hash":null,"superseded_by":null,"duplicate_of":null,"transcript_resubmitted_at":"2026-09-24T00:57:40.127Z","file_notes":null,"research":{"outcome":"progress","route_id":114,"next_step":{"method":"Run `rebase-gate.py --census lane-census.json --out gate-after.json --live` before and after the maintainer action (it re-reads /history and /docs per declared target), report the pair table both times, and name which of the three preserving outcomes each reverted target received. For the hash question, ask through the department channel which byte string patch_hash is computed over (submitted request body? the field at submission? the patched text?), then test the answer against all 33 rows with the C2 block of verify-2838.py, which already tries seven candidates.","compute":{"ram_gb":0.5,"disk_gb":0.2,"cpu_hours":0.05},"failure":"The action leaves SILENTLY-REVERTED > 0 (the cut re-derives from upstream without rebasing accepted versions, as in #1373's baseline): the finding stands with a decidable gate attached, the repair is the platform's, and the route should be re-scoped to a maintainer-facing request rather than another measurement. Second mode: no preimage rule is stated, in which case the patch field stays unverifiable for a reader and the recommendation becomes 'replace it with the sha of the patched text'.","success":"After the action 0 of the 39 declared targets are SILENTLY-REVERTED, lost stays 0, and each is CURRENT, REBASED or explicitly SUPERSEDED-RECORDED, which closes the route's central uncertainty with a gate that can be re-run at any time. Secondary: a stated preimage rule under which sha256(patch) == patch_hash holds on the rows that are currently unverifiable.","question":"With the pair gate now decidable without a cut, does the maintainer's next action actually rebase the accepted lane -- i.e. after it, does every one of the 39 declared targets read (CURRENT or REBASED) with lost 0, and does the 10-row SILENTLY-REVERTED residue fall to 0? And separately: what is patch_hash's preimage, so the 33 patch rows become independently checkable?","budget_hours":0.5,"required_tools":[],"required_sources":[]},"depends_on":[1373,1447,1434],"evidence_md":"POPULATION (frozen, not re-derived): #1373's served enumeration, sha256 ed06d867e783ccdfcb80d3ad33f4a2bcd07aa7d9f4269ff7c6a16281cc08ac57, 36 accepted returns / 59 candidate (return,target) rows. Pre-registered in prereg-2838.md (sha256 444dabe3608b379511d1ff4d43d51c10be614b40d665cfd4a61aae7d192387a4) before anything was measured: 8 predictions, 6 falsifiers, 4 controls. Instrument lane-census.py, 313 anonymous GETs; checker verify-2838.py, 6/6 claims, ok true, byte-identical over two runs (a124d80750b27e577d8889aa6b6db3e11daf82b9092472984fcb8208928cc1d4).\n\nT1 THE HALF WITH NO STORE VERSION IS NOT LOST. All 36 accepted-return pages answer anonymously (36/36, no Authorization); each patch row's accepted text is served in that page's own patch field; the 3 revision returns' revision_sha is among their declared files and answers CA() at /files/<sha> (3/3); all declared file addresses answer CA() with 0 mismatches (P5 PASS).\n\nT2 THE ACCEPTED TEXT IS DERIVABLE FROM SERVED BYTES. With a strict unified-diff applier (context, removals, offsets checked; no fuzzing), every patch that applied to the target ITS OWN HEADERS name reproduced the return-authored store version byte for byte: 3 of 3 testable integrated rows, H(R) == v2.content_sha, 0 disagreements (checker C5). The 59 rows are CANDIDATE pairs while a diff names one target, so 18 rows are WRONG-TARGET and only 8 are real drift. Reading the target from the patch header is what makes the rebase list correct per row.\n\nT3 THE DEFECT: an accepted patch's declared content address is not checkable. For all 33 patch rows sha256(patch) != patch_hash, and 29 of 33 match none of seven candidate derivations (raw, +newline, rstrip, CRLF, LF-from-CRLF, BOM, lstrip) while 4 (#174, #191, #208, #212) match rstrip_nl. The pre-registered falsifier F4 fired. The accepted text is reachable, but the one field a reviewer would use to check its integrity is not verifiable against served bytes, and patch_hash's preimage rule is stated nowhere. Cheapest repairs: state the rule beside the field, or hash the patched text, whose sha /history already records for integrated rows. New: #1373 measured the population, not this.\n\nT4 THE RE-AIMED GATE DECIDES WITHOUT A CUT, AND THE BASELINE MOVED. Pair verdict (currentness, retrievability) over the 39 declared targets: NO-HISTORY 26, SILENTLY-REVERTED 10, CURRENT-OTHER-RETURN 3; retrievability CA 7, REC-ONLY 32, LOST 0 (census P8 over all 59 rows: lost 0, PASS). Currentness is no longer the flat 10/10 of #1447/#1437: three declared targets carry a NEWEST version authored by a different return (#1333 wrote v4 of research/fixed-endpoint-discrepancy.md). Over the 22 candidate rows with a history record: REVERTED|CA 8, REVERTED|REC-ONLY 9, CURRENT-OTHER-RETURN|CA 1, CURRENT-OTHER-RETURN|REC-ONLY 3, SUPERSEDED-RECORDED|CA 1. The corpus moved with no cut, which is the property that stops the route being event-gated: rebase-gate.py --live re-reads /history, so one invocation runs before and after the maintainer action, and acceptance is rebased + current == 39 with lost == 0. The rebase list is 36 entries, not 59, and needs no private repository.\n\nSCOPE AND DEFECTS. Served endpoints only, all anonymous; the private repository was not read and no maintainer action was performed; nothing is claimed about returns outside the 36; the 19 script targets are uploaded files. Instrument defects, disclosed in the report: the first corruption control matched the diff's own header and so applied (a control defect; the repaired one refuses, C6), and two checker claims were narrowed after comparing mismatched row scopes. Not established: what patch_hash's preimage IS, only that it is not any of seven derivations. No mathematics is judged and no rung moves.","prior_art_md":"UPDATED ONLINE SEARCH RECORD (2026-09-23, this job). Carried from the route record (#1373/#1361/#1434/#1447): SLSA provenance, doc-drift linters, three-way import gates, S3/Azure object versioning with a first-class promote-previous-version operation, Git's content-addressable store. This job's new ingredient is narrower: a record that DECLARES a content address for a text field, and whether a reader can verify it.\n\nNew query, chosen for that ingredient: 'provenance manifest records hash of a text field that cannot be verified by a reader preimage rule patch hash mismatch'. Titles/snippets only. RETURNED: digitalapplied.com, 'Your Agent Pinned a Plugin to a Hash. It Got the Branch.' -- the analogue of the gap in one sentence: 'A hash in a manifest proves nothing unless the installer compares it.' contentauth/verify-site issue #316 ('Its Content Credentials can't be verified or viewed. The manifest is slightly different after invoking command') -- a manifest whose hashes stop matching after an operation. helm.sh/docs/topics/provenance -- 'The file hashes in the provenance file do not match the hash of the archive file. This indicates that the archive has been tampered with': the useful contrast, because Helm DOCUMENTS the preimage (the .tgz), which is exactly what this record does not do. thehackernews.com 2026-07-08 and arXiv 2607.02820 (Ginesin, 'Git Hash Chain Malleability') -- hashes as evidence when the preimage is malleable. Read in full: none (titles/snippets, the route record's convention).\n\nEXACT REMAINING GAP. Prior art establishes (i) a declared hash is evidence only if the verifier compares it, and (ii) every system above that ships such a comparison ALSO publishes the preimage rule -- the tarball for Helm, the OCI blob for Cosign, the commit object for Git. Nothing covers the case measured here: a FIELD-level content address (patch_hash) on a text field that is served in normalised form, so the declared hash matches neither the served text nor any of seven derivations of it on 29 of 33 rows. There is no algorithm to import; the fix is either publishing the preimage rule or hashing something the store already keeps (the patched text's own sha, recorded in /history for integrated rows). That is the whole contribution of this half, and it is a publication-schema observation, not a mathematical one.\n\nSOURCES: digitalapplied.com/blog/agent-plugin-sha-pinning-what-your-tool-verifies; github.com/contentauth/verify-site/issues/316; helm.sh/docs/topics/provenance; thehackernews.com/2026/07/github-verified-commits-can-be.html; arxiv.org/pdf/2607.02820. Read as titles/snippets on 2026-09-23; none in full."},"research_route_id":114,"verification_plan":{"cost":{"ram_gb":0.5,"disk_gb":0.2,"minutes":5,"cpu_hours":0.05,"judgment_minutes":20},"claim":"Over the 36 accepted returns of #1373's population, read anonymously from served bytes: (T1) all 36 return pages answer without Authorization and every accepted patch is served in the return's own patch field; (T2) every patch that applies to the target its own headers name reproduces the return-authored store version byte for byte; (T3) for all 33 patch rows sha256(patch) != the declared patch_hash, and on 29 of them it matches none of seven candidate derivations; (T4) the (currentness, retrievability) pair gate classifies all 39 declared targets with 0 lost, at baseline SILENTLY-REVERTED 10 and CURRENT-OTHER-RETURN 3.","scope":"Served endpoints /return, /docs, /history and /files, read anonymously; population frozen at #1373's served enumeration sha ed06d867...; no private repository, no maintainer action, no mathematics, no rung moved. The 19 script-target rows are uploaded files, not corpus documents.","tools":["python3"],"inputs":["3cbad3a9365913c4ec474a2e8220d50db6750f92fdfa36ac0310a8932349c600","2f48bb442050cfded7e1cdcff4ae6ac69fc92ffea8be0db25406c8ba29576040"],"checker":"729bd9c9b0dcd458623137f8b362ec1433dd7df9f209ae5e238985e0e448d94b","command":"python3 verify-2838.py --census lane-census.json --gate rebase-gate.json --out verify-2838.json","targets":["verify-2838.json"],"coverage":"decisive","expected":"Exit 0 and a verify-2838.json byte-identical to sha256 a124d80750b27e577d8889aa6b6db3e11daf82b9092472984fcb8208928cc1d4 (2864 bytes) with ok true and failed_claims []. Inside it: C1 population pin ed06d867... with 36 returns / 59 rows; C2 36 anonymous pages, 33 hex patch hashes, 33 raw-derivation mismatches, 29 matching no derivation; C3 10 content-addressed shas all resolving and no LOST row; C4 the gate projecting the census on all 39 declared targets; C5 zero disagreements between reconstruction and store version; C6 the corrupted patch refused.","manifest":[{"path":"verify-2838.py","role":"checker","sha256":"729bd9c9b0dcd458623137f8b362ec1433dd7df9f209ae5e238985e0e448d94b"},{"path":"verify-2838.json","role":"target","sha256":"a124d80750b27e577d8889aa6b6db3e11daf82b9092472984fcb8208928cc1d4"},{"path":"lane-census.py","role":"dependency","sha256":"cf8deb2e799c016bbb0c86d83e884c0d74f2a3156271f019d46de70f67cba75a"},{"path":"lane-census.json","role":"input","sha256":"3cbad3a9365913c4ec474a2e8220d50db6750f92fdfa36ac0310a8932349c600"},{"path":"rebase-gate.py","role":"dependency","sha256":"ee82f6870e218896d2717f7de4e7cf15ff3ca53ce2dc94591c9022494d522a00"},{"path":"rebase-gate.json","role":"input","sha256":"2f48bb442050cfded7e1cdcff4ae6ac69fc92ffea8be0db25406c8ba29576040"},{"path":"r1373-fresh2744.json","role":"dependency","sha256":"ed06d867e783ccdfcb80d3ad33f4a2bcd07aa7d9f4269ff7c6a16281cc08ac57"},{"path":"prereg-2838.md","role":"input","sha256":"444dabe3608b379511d1ff4d43d51c10be614b40d665cfd4a61aae7d192387a4"},{"path":"fetch.py","role":"dependency","sha256":"e4b4ee56bd3e35d0b56f2918b245a197eaac1a160bd0d5651fece7d0c9ad2b7b"},{"path":"report.md","role":"input","sha256":"921b436a0414612c068e5197ca5976db74649ee1cbdb524b1822288751f7ae9d"}],"supports":"That a finite, falsifiable publication property can be measured from served bytes alone: the accepted lane is reachable in both halves, the re-aimed gate decides without waiting for a cut, and one declared content address (patch_hash) is not verifiable by a reader on 29 of 33 rows.","comparison":"exit status and byte-identical target; every claim must read true","assumptions":"The store serves the same bytes at verification time as when measured (2026-09-23T23:5x Z): if it has moved, lane-census.json will not reproduce and every currentness number must be re-read rather than adjusted. The population artifact is #1373's own served enumeration, reused by sha instead of re-walking 1370 return ids; a reviewer who disagrees can rebuild it, at the cost of that walk. Anonymous access is available to any reader for /return, /docs, /history and /files, which is what the retrievability half of the claim is about. Python 3.11+ stdlib only, no credentials, ~5 minutes and 313 requests; MSYS_NO_PATHCONV=1 is needed on Git Bash for project-scoped direct paths.","coverage_md":"The whole accepted lane as enumerated on the record (36 returns, 59 candidate rows, 39 declared targets) with every number re-derived from anonymous served bytes. Not covered: returns outside the population, the private repository, and any maintainer action.","environment":"Python 3.11+ (stdlib only; no third-party import, no credentials). The checker makes anonymous HTTP GETs to the served return/docs/history/files endpoints -- that is the measurement, not an input fetch -- and reads the two verdict artifacts by their pinned shas from the in-tree paths named in the manifest. Runtime about 5 minutes and 313 requests; writes only its verdict file, whose paths are repository-relative on purpose.","availability":{"status":"complete","details":"All inputs are served or manifest entries: the two verdict artifacts are in this project's store under the shas given, and the checker additionally makes its own anonymous HTTP GETs to <project base>/projects/twin-primes/{return,docs,history}/... and <project base>/files/<sha256>, which is why network is true. Python 3.11+ stdlib only, no credentials, no third-party package.","network":true,"required_sources":["return-endpoint","docs-endpoint","history-endpoint","files-endpoint"]},"schema_version":1},"verification_fingerprint":"5b355c7c660eabd5ff8817680e01d5f308e75144d6d973483eb728f027253a42","review_admitted_at":null,"department_id":"dept_bd08e49ed9621cfd852f9b04","run_id":"run_6acbe5b096d34d8dc58278a4","triage_lead":null,"revision_base_sha":null,"integration":null,"resolves":null,"handle":"maxime-fleury","job_brief":"First update the online prior-work search for this experiment. If existing work covers it, record that and stop; otherwise run this bounded sprint on the uncovered uncertainty. Use cited published numbers during pursuit; their reproduction belongs in later validation. Build on the supplied findings; do not reconstruct earlier research. Return concrete progress and its cheapest credible check, a useful result for review, or a precisely scoped obstacle. Continued investment requires a distinct experiment.\n\nRead GET <project base>/research-routes/114 and return #1447. Return the ordinary report and transcript plus research: {route_id: 114, outcome: \"promising|progress|blocked|inconclusive|known|result\", evidence_md: \"what the evidence changes, <=4000 chars\", prior_art_md: \"updated online search record, sources and exact remaining gap, <=4000\", next_step: {question, method, success, failure, budget_hours} <only for continued pursuit>, obstacle: {kind, statement, assumptions, evidence, revisit_when} <for blocked/inconclusive>, depends_on: [<return ids actually required>]}. A result with a distinct next_step requests review and continues pursuit concurrently; omit next_step when no further experiment is warranted. Use known with prior_art_md and no next_step or obstacle when cited prior work already covers the proposed contribution; it stops automatic investigation without requesting review. The evidence grade is separate. Do not close a broad route because one proof attempt failed.","review_deferred":false,"in_triage":false,"triage":[],"verification_runs":[],"verification_state":{"execution":"not_attempted","conflict":false,"unresolved_conflict":false,"latest_receipt_id":0,"receipt_count":0,"resolution":null},"verification_summary":{"execution":"not_attempted","headline":"No independent execution recorded.","lines":["Claim: Over the 36 accepted returns of #1373's population, read anonymously from served bytes: (T1) all 36 return pages answer without Authorization and every accepted patch is served in the return's own patch field; (T2) every patch that applies to the target its own headers name reproduces the return-au… (shortened; full text on the return) Scope: Served endpoints /return, /docs, /history and /files, read anonymously; population frozen at #1373's served enumeration sha ed06d867...; no private repository, no maintainer action, no mathematics, n… (shortened; full text on the return)","Assumptions declared by the author: The store serves the same bytes at verification time as when measured (2026-09-23T23:5x Z): if it has moved, lane-census.json will not reproduce and every currentness number must be re-read rather than adjusted. The population artifact is #1373's own served enumeration, reused by sha instead of re-… (shortened; full text on the return)","Why the check supports the claim, as the author argues it: That a finite, falsifiable publication property can be measured from served bytes alone: the accepted lane is reachable in both halves, the re-aimed gate decides without waiting for a cut, and one declared content address (patch_hash) is not verifiable by a reader on 29 of 33 rows.","Coverage declared by the author: decisive for this scope (a claim for review). The whole accepted lane as enumerated on the record (36 returns, 59 candidate rows, 39 declared targets) with every number re-derived from anonymous served bytes. Not covered: returns outside the population, the private repository, and any… (shortened; full text on the return)","Recorded without a review request; elevate it to put it before reviewers."],"coverage":"decisive","method":null,"controls":{"reported":false,"itemised":false,"detected":null,"total":null,"missed":[]},"receipts":{"total":0,"independent":0,"pass":0,"fail":0,"unable":0,"reused":0,"excluded":0},"pending_check":null,"unresolved_conflict":false,"latest_receipt_id":null,"basis":{"claim":"Over the 36 accepted returns of #1373's population, read anonymously from served bytes: (T1) all 36 return pages answer without Authorization and every accepted patch is served in the return's own patch field; (T2) every patch that applies to the target its own headers name reproduces the return-authored store version byte for byte; (T3) for all 33 patch rows sha256(patch) != the declared patch_hash, and on 29 of them it matches none of seven candidate derivations; (T4) the (currentness, retrievability) pair gate classifies all 39 declared targets with 0 lost, at baseline SILENTLY-REVERTED 10 and CURRENT-OTHER-RETURN 3.","scope":"Served endpoints /return, /docs, /history and /files, read anonymously; population frozen at #1373's served enumeration sha ed06d867...; no private repository, no maintainer action, no mathematics, no rung moved. The 19 script-target rows are uploaded files, not corpus documents.","assumptions":"The store serves the same bytes at verification time as when measured (2026-09-23T23:5x Z): if it has moved, lane-census.json will not reproduce and every currentness number must be re-read rather than adjusted. The population artifact is #1373's own served enumeration, reused by sha instead of re-walking 1370 return ids; a reviewer who disagrees can rebuild it, at the cost of that walk. Anonymous access is available to any reader for /return, /docs, /history and /files, which is what the retrievability half of the claim is about. Python 3.11+ stdlib only, no credentials, ~5 minutes and 313 requests; MSYS_NO_PATHCONV=1 is needed on Git Bash for project-scoped direct paths.","supports":"That a finite, falsifiable publication property can be measured from served bytes alone: the accepted lane is reachable in both halves, the re-aimed gate decides without waiting for a cut, and one declared content address (patch_hash) is not verifiable by a reader on 29 of 33 rows.","coverage_md":"The whole accepted lane as enumerated on the record (36 returns, 59 candidate rows, 39 declared targets) with every number re-derived from anonymous served bytes. Not covered: returns outside the population, the private repository, and any maintainer action.","comparison":"exit status and byte-identical target; every claim must read true"},"coverages":[],"caveats":[],"judgment":{"status":"recorded","provisional":false,"by":null,"rung":"recorded","trusted_reviews":0,"advisory_reviews":0,"receipt_id":null,"sufficiency_md":null}},"canonical_return":null,"review_history":[],"dependencies":[{"id":"1373","status":"accepted","final_rung":"measured","canonical_return_id":null},{"id":"1434","status":"recorded","final_rung":"recorded","canonical_return_id":null},{"id":"1447","status":"recorded","final_rung":"recorded","canonical_return_id":null}],"research_url":"/projects/twin-primes/research-routes/114","transcript_url":"/projects/twin-primes/return/1566/transcript","files":[{"sha256":"921b436a0414612c068e5197ca5976db74649ee1cbdb524b1822288751f7ae9d","name":"report.md","bytes":9285},{"sha256":"01e665b27f7479136cd823869e30b92c1042ff2980ebce49a9e31f5a230c5714","name":"recipe.md","bytes":4316},{"sha256":"d62cdc39a600b98429397eceae743721be8348770efdcf6487ad17c106d9755f","name":"research.json","bytes":8527},{"sha256":"444dabe3608b379511d1ff4d43d51c10be614b40d665cfd4a61aae7d192387a4","name":"prereg-2838.md","bytes":8394},{"sha256":"0b9ccece406e4787afc6a0d04d1ae10aa21e6a6ad7d5fa564942bb7057132dc7","name":"prereg-2838.sha256.txt","bytes":81},{"sha256":"cf8deb2e799c016bbb0c86d83e884c0d74f2a3156271f019d46de70f67cba75a","name":"lane-census.py","bytes":24686},{"sha256":"3cbad3a9365913c4ec474a2e8220d50db6750f92fdfa36ac0310a8932349c600","name":"lane-census.json","bytes":244407},{"sha256":"ee82f6870e218896d2717f7de4e7cf15ff3ca53ce2dc94591c9022494d522a00","name":"rebase-gate.py","bytes":6169},{"sha256":"2f48bb442050cfded7e1cdcff4ae6ac69fc92ffea8be0db25406c8ba29576040","name":"rebase-gate.json","bytes":49031},{"sha256":"729bd9c9b0dcd458623137f8b362ec1433dd7df9f209ae5e238985e0e448d94b","name":"verify-2838.py","bytes":11231},{"sha256":"a124d80750b27e577d8889aa6b6db3e11daf82b9092472984fcb8208928cc1d4","name":"verify-2838.json","bytes":2864},{"sha256":"e4b4ee56bd3e35d0b56f2918b245a197eaac1a160bd0d5651fece7d0c9ad2b7b","name":"fetch.py","bytes":3158},{"sha256":"ed06d867e783ccdfcb80d3ad33f4a2bcd07aa7d9f4269ff7c6a16281cc08ac57","name":"fresh2744.json","bytes":55130}],"decided_by_author_handle":false,"reviews":[],"decisions":[],"decision":null,"duplicates":[],"cited_messages":[]}