{"id":1617,"job_id":3194,"problem_id":1,"lane_id":3,"type":"explore","user_id":1,"model":"deepseek-v4-flash","provider":"deepseek","report_md":"# Route 114 rev 21 — every declared row-less revision is present in the store; the boundary is per object, and 41 of the 91 have no version row at all\n\nJob #3194, attempt `80ab06f5cf28ead5e7b84752ea236821`. Type **explore**, lane formalize, general\ndirection. Anonymous served reads except the labelled credential probes; nothing edited, no document\nwritten. Compute measured **0 CPU-h** (110 journaled GETs, I/O-bound) against a 0.2 hint.\n\n## The question, and the answer\n\nRoute 114's recorded next experiment (#1614) asked whether the `/files/<content_sha>` refusal the\n`/history` rows advertise is a **store policy or a per-path publication flag**, and whether the\naudits on the zero-row paths (no version row to serve) need a first `/history` row.\n\n**Answer: neither shape as posed. The boundary is per object, every one of the 91 declared\n`revision_sha` blobs is present and hash-verified under the credential, and the population splits by\na second, independent property — 41 of the 91 audits sit on a path with zero version rows.**\n\n1. **The store holds the whole class, not a sample.** `GET /files/<revision_sha>` with the\n   department credential for all **91/91** declared revision digests: **200 on 91/91, bytes re-hash\n   to the requested digest on 91/91**. The same URLs are 404 for an anonymous reader (#1614:\n   721/722 of 722 declared digests). So the reader's 404 is a publication boundary over bytes that\n   exist, and this is now measured on the class, upgrading #1614's 12-digest sample.\n2. **The refusal is per object, not per path.** The 13 of the 91 that also declare a\n   `.diff`/`.patch` artifact contribute 19 distinct digests: **17 credential-200 and hash-verified,\n   2 credential-404 `no such file`** (audits 14 and 15). Same audit, same `revision_path`, same\n   credential — one object resolves and hash-matches while a sibling object is genuinely absent. A\n   per-path flag cannot produce that split, and \"the store is closed\" contradicts the 91 200s.\n3. **The zero-row split is real and large.** `/history/<revision_path>` for the 33 distinct paths of\n   this population: all 200; **22 carry zero version rows, and 41 of the 91 audits sit on them**\n   (6, 8, 9, 14, 15, 16, 107, 124, 172, 184, 251, 254, 266, 270, 294, 409, 768, 769, 785, 794, 795,\n   796, 815, 899, 902, 905, 908, 909, 912, 920, 924, 925, 932, 1099, 1257, 1261, 1319, 1321, 1350,\n   1547, 1548). For them a blob-visibility fix is not enough: there is no row for a reader to follow.\n4. **The join with #1614's reconstruction classes is total and consistent.** Zero-row path x class:\n   served-base 13, undecided 4, other 24 = 41. Path with rows x class: served-base 3,\n   historical-base 20, undecided 4, other 23 = 50. All 20 historical-base reconstructions lie on\n   paths that have rows — a historical base is not available where no row exists — while 13 of the\n   16 served-base cases lie on zero-row paths. The 3 served-base cases on row-having paths are\n   exactly the cells one `content_sha` row would close.\n5. **The 8 \"undecided\" audits are store-resolved.** 9, 14, 15, 16, 313, 321, 329, 338: credential\n   200 and hash-verified on all 8. What remains for them is text reconstruction (which base the\n   shipped patch was cut against), and that is now decidable because the declared revision bytes\n   are readable.\n\n## What this changes for the route\n\nThe route's failure branch — \"the credential result is per-path rather than per-object and no rule\nsurvives the join\" — **does not fire**. Instead the measurement replaces the two-shape question with\nthree measured facts: (i) the store holds every declared revision of the 91; (ii) visibility is\nper-object, so the anonymous 404 is a flag, not a policy against the path, and two objects were\nnever stored at all; (iii) 41 of the 91 have no version row while 50 do, so the repair is not one\nthing. For the 41 the repair is a first `/history` row **plus** visibility; for the 50, a\n`content_sha` row per revision (20 of them already reconstructible from a historical base). The\nroute's remaining uncertainty — \"was the revision ever entered?\" — is narrowed to a text question,\nnot a storage question, because the accepted text itself is readable.\n\n## Controls and disclosures\n\n- **C1 (consistency, not reproduction).** The 20/91 historical-base set lies entirely on row-having\n  paths and the 41 zero-row audits contain none of it; 13/16 served-base cases lie on zero-row\n  paths. Two independently derived properties agree where the mechanism requires them to.\n- **Not established.** (a) \"Present\" = the store answers the digest and the bytes hash to it; no\n  claim about the private repository. (b) Credential visibility is measured for the 91\n  `revision_sha` + 19 diff artifacts; the remaining declared digests are still only measured\n  anonymously. (c) Two objects are absent with the credential, so \"every declared digest exists\" is\n  false in general. (d) *Why* the anonymous boundary exists (platform flag vs operator omission) is\n  answered object-level by measurement, not by reading the server's configuration. (e) The zero-row\n  counts here cover the 33 paths of this population, not #1614's lane-wide 49 (24 zero-row).\n  Snapshot 2026-09-24T17:58Z; 110 journaled requests; bodies sha256'd in\n  `work/history_counts.json`, `work/cred_probes.json`, `work/diff_probes.json`, `work/cross.json`.\n\n## The cheapest credible next check\n\nFetch the credential-readable revision bytes for all 91 (they are now known present) and compare\nthem byte-for-byte against the served text with each audit's own patch applied, and against each\n`/history` version blob with the patch applied. That settles \"entered by the recorded patch\" vs\n\"entered by another route\" — the route's second unresolved step — directly, with the stored bytes\nas ground truth instead of a hash prediction.\n","patch":null,"cpu_hours":0,"hashes":{},"author_rung":"measured","status":"recorded","final_rung":"recorded","created_at":"2026-09-24T18:00:28.226Z","repo_url":null,"commit":null,"cites":{"files":[],"handles":[],"returns":[1573,1597,1602,1605,1609,1611,1614],"messages":[]},"tokens":{"log":"custom","input":0,"models":{"deepseek-v4-flash":0},"output":0,"source":"none","entries":0,"cache_read":0,"cache_write":0,"observed_models":["deepseek-v4-flash"]},"paper_slug":null,"revision_path":null,"revision_sha":null,"recipe_md":null,"verification":null,"target":null,"finding":null,"human_md":null,"provisional":false,"effects_applied_at":null,"effort":null,"also_fix":null,"transcript_omitted":{"share":0,"omitted":0,"outputs":0},"patch_hash":null,"superseded_by":null,"duplicate_of":null,"transcript_resubmitted_at":null,"file_notes":null,"research":{"outcome":"progress","route_id":114,"next_step":{"method":"Fetch `/files/<revision_sha>` for all 91 with the credential (known present and hash-verified here) and compare byte-for-byte against (i) the served text of the audit's own `revision_path` with its own `patch` applied and (ii) each `/history` version blob of that path with the patch applied; classify each audit reproduced-by-patch / reproduced-from-historical-base / no-patch-on-record / mismatch, and re-run the same join for the 41 zero-row-path audits.","compute":{"ram_gb":2,"disk_gb":1,"cpu_hours":0},"failure":"For a majority of the 91 the stored revision text matches no patch-applied construction of any served base, so the record does not determine the revision it declares and the ledger needs the revision's provenance, not a row.","success":"A total, re-runnable classification of the 91 with the stored bytes as ground truth, which fixes 'entered but never regenerated' vs 'entered by another route' and decides whether the repair is a served row alone or a row plus provenance in the ledger.","question":"All 91 declared row-less revisions are present and hash-verified in the store, so the record's own bytes are readable: does the shipped `patch` applied to a served base reproduce the stored revision text, or was the revision entered by another route? And for the 41 audits on the 22 zero-row paths, is a first `/history` row the only repair?","budget_hours":0.5,"required_tools":[],"required_sources":[]},"depends_on":[1614,1611,1609],"evidence_md":"EVIDENCE — job 3194, route 114 rev 21. Local, read-only, 0 CPU-h. Anonymous reads carry\n`Accept: application/json`, UA `sah-research-agent/1.0`, no Authorization; only the labelled\ncredential probes use `sah.py api()` (journaled, token never printed), 110 GETs total. Instruments:\n`work/classify.py` -> `history_counts.json`, `cred_probes.json`, `cross.json`; `work/diffprobe.py`\n-> `diff_probes.json`. Population = run-af's 91 row-less audits (`run-2026-09-24-af/work/declared.json`).\n\n1. EVERY DECLARED REVISION BLOB IS PRESENT IN THE STORE. `GET /files/<revision_sha>` with the\n   department credential, for all **91/91** declared `revision_sha`: **HTTP 200, 91/91**, and the\n   returned bytes re-hash to the requested digest on **91/91** (`matches: true`). Anonymous reads of\n   the same digests are 404 (af: 721/722). So for this class the 404 is *publication visibility*,\n   not absence — measured on the whole class, not a sample (af's sample was 12).\n\n2. THE BOUNDARY IS PER OBJECT, NOT PER PATH. The 13 of the 91 that also declare `.diff`/`.patch`\n   artifacts contribute **19** distinct digests: credential **200 hash-verified 17**, credential\n   **404 `no such file` 2** (audits 14, 15). Same audit, same `revision_path`, same credential: one\n   object hash-matches, a sibling is genuinely absent. A per-path flag cannot produce that split.\n\n3. THE ZERO-ROW PATHS, SPLIT PER AUDIT. `/history/<revision_path>` for the **33** distinct paths of\n   this population: all 200 (bodies sha256'd in `history_counts.json`); **22 carry ZERO version\n   rows**, and **41 of the 91 audits** sit on them (ids 6, 8, 9, 14, 15, 16, 107, 124, 172, 184,\n   251, 254, 266, 270, 294, 409, 768, 769, 785, 794, 795, 796, 815, 899, 902, 905, 908, 909, 912,\n   920, 924, 925, 932, 1099, 1257, 1261, 1319, 1321, 1350, 1547, 1548; full list in `cross.json`).\n   af's lane-wide count was\n   24 of 49; this subset (the 91's own paths) gives 22 of 33.\n\n4. JOIN WITH THE RECONSTRUCTION CLASSES (af's sets; `cross.json`). Zero-row path x class: served-base\n   13, undecided 4, other 24 = 41. Path with rows: served-base 3, historical-base 20, undecided 4,\n   other 23 = 50. **C1: all 20 historical-base reconstructions sit on row-having paths (a historical\n   base needs rows to exist), while 13 of the 16 served-base cases sit on zero-row paths — the 3\n   exceptions are exactly the cells one `content_sha` row would close.**\n\n5. THE 8 UNDECIDED AUDITS ARE NOW STORE-RESOLVED. 9, 14, 15, 16, 313, 321, 329, 338: credential\n   200 + hash-verified on all 8. Their residual uncertainty is *text reconstruction* (which base the\n   patch was cut against), not storage — and it is decidable, the declared bytes being readable.\n\n6. WHAT THIS CHANGES. The route's open question split into two independent properties: the store\n   holds every declared revision blob of the 91 (present, hash-verified), and 41 of the 91 have no\n   version row at all while 50 do. So the repair is **not one thing**: for the 41 on zero-row paths\n   it is a first `/history` row plus reader visibility; for the 50 with rows the row already exists\n   on the path (a `content_sha` row per revision suffices), and 20 of those are already\n   machine-reconstructible from a historical base. The route's pre-registered failure wording\n   (\"per-path rather than per-object\") **does not fire**: the boundary is per-object, 91/91 joined.\n\nSCOPE / NOT ESTABLISHED. (a) Credential visibility is measured for the 91 declared `revision_sha`\nplus 19 diff artifacts; the remaining declared digests (af's 722) are only measured anonymously.\n(b) \"Present\" = the store answers the digest and the bytes hash to it; no claim about the private\nrepository. (c) 2 objects are absent under the credential, so \"every declared digest exists\" is\nfalse in general — only every `revision_sha` tested here is. (d) Zero-row counts here cover this\npopulation's 33 paths, not af's lane-wide 49. Snapshot 2026-09-24T17:58Z, 110 journaled requests.","prior_art_md":"# Prior art — updated online search, job #3194, 2026-09-24 (titles and snippets only)\n\n## Carried, not re-derived\nSLSA provenance and GitHub artifact attestations (digest binds a build to its identity);\n`artifact-audit` (PyPI / GitHub Action, Sep 2026: deterministic bundle manifests that detect\n**missing and unexpected files** and diff seals into added/removed/modified); skillstore.io\n\"artifact binding\" (Jul 2026: commit/content/tree/path/audit-payload identities); the\n`mirjak/draft-audit-architecture` issue #22 (Jul 2026) and Northflank's Sep 2026 audit-trail note\ncarried by #1609/#1614; project-internal served: #1573, #1576, #1579, #1585, #1593, #1597, #1602,\n#1605, #1609, #1611, #1614.\n\n## This job's queries (2026-09-24, snippets only)\nQ1 \"content-addressed artifact stored but 404 for anonymous reader per-object publication\nvisibility audit record 2026\" → storage access-auditing (Scality \"Storage Audit Trail\", VAST\n\"Auditing\"), Microsoft Purview audit-log activities, GCP Artifact Registry audit logging, the\nWikipedia/TechTarget CAS definitions. All are *access* auditing: they record who read what. None\ndescribes a store whose object exists, whose digest is published on a record, and whose reader is\nrefused.\nQ2 \"audit record declares artifact digest credential resolves bytes hash-verify revision never\npublished\" → GitHub Actions artifact attestations and their verification checklists (Aug 2026),\n`artifact-audit` (Sep 2026), systemshardening's SLSA enforcement note (May 2026). The nearest\npublished shape is `artifact-audit`'s \"missing and unexpected files\" report: it detects absence\n*inside a bundle the consumer already holds*, which is the closest published analogue to step (2)\nhere (the two genuinely absent diff objects) — but it presumes the reader may read the store.\n\n## Nearest shape and the exact remaining gap\nEvery published shape either (i) binds a digest to a record (attestations, CAS, artifact binding),\n(ii) audits *reads* of a store, or (iii) diffs a bundle the consumer already has. **No source\nstates or measures this job's object:** a declared digest that the store holds (credential read +\nbyte hash-match) while the anonymous reader the corpus is published for gets 404, with the boundary\nfalling *per object* rather than per path. Nothing about the repair — a per-object publication flag\nvs a first version row — was found online; it is settled here by measurement. No importable\nalgorithm or schema was returned; no source was read in full.\n\n## Exact remaining gap after this job (local, not online)\nThe store's contents are now resolved for this class (91/91 `revision_sha` present and\nhash-verified; 2 diff objects genuinely absent). Unmeasured: (a) the private repository's state,\nwhich no served read can establish; (b) which base the shipped patch was cut against for the 8\nundecided audits — now decidable, because the declared revision bytes are readable with the\ncredential, by comparing them against the patch-applied constructions; (c) whether the anonymous\nboundary is a platform publication flag or an operator omission, which only the server's\nconfiguration can say."},"research_route_id":114,"verification_plan":null,"verification_fingerprint":null,"review_admitted_at":null,"department_id":"dept_0e793a31e299699dfaaa6fee","run_id":"run_9d7c07540d2c217f641a1322","triage_lead":null,"revision_base_sha":null,"integration":null,"resolves":null,"handle":"Benjaminsen","job_brief":"First update the online prior-work search for this experiment. If existing work covers it, record that and stop; otherwise run this bounded sprint on the uncovered uncertainty. Use cited published numbers during pursuit; their reproduction belongs in later validation. Build on the supplied findings; do not reconstruct earlier research. Return concrete progress and its cheapest credible check, a useful result for review, or a precisely scoped obstacle. Continued investment requires a distinct experiment.\n\nRead GET <project base>/research-routes/114 and return #1614. Return the ordinary report and transcript plus research: {route_id: 114, outcome: \"promising|progress|blocked|inconclusive|known|result\", evidence_md: \"what the evidence changes, <=4000 chars\", prior_art_md: \"updated online search record, sources and exact remaining gap, <=4000\", next_step: {question, method, success, failure, budget_hours} <only for continued pursuit>, obstacle: {kind, statement, assumptions, evidence, revisit_when} <for blocked/inconclusive>, depends_on: [<return ids actually required>]}. A result with a distinct next_step requests review and continues pursuit concurrently; omit next_step when no further experiment is warranted. Use known with prior_art_md and no next_step or obstacle when cited prior work already covers the proposed contribution; it stops automatic investigation without requesting review. The evidence grade is separate. Do not close a broad route because one proof attempt failed.","review_deferred":false,"in_triage":false,"triage":[],"verification_runs":[],"verification_state":null,"verification_summary":null,"canonical_return":null,"review_history":[],"dependencies":[{"id":"1609","status":"recorded","final_rung":"recorded","canonical_return_id":null},{"id":"1611","status":"recorded","final_rung":"recorded","canonical_return_id":null},{"id":"1614","status":"recorded","final_rung":"recorded","canonical_return_id":null}],"research_url":"/projects/twin-primes/research-routes/114","transcript_url":"/projects/twin-primes/return/1617/transcript","files":[],"decided_by_author_handle":false,"reviews":[],"decisions":[],"decision":null,"duplicates":[],"cited_messages":[]}