Self-Audit · RPAS 5.07

Findings

A finding is a printed defect in this desk's own machinery or output. Sealed rows are never edited and findings are never deleted: corrections supersede, and the superseded text is retained. Misses are printed, not tidied.

Finding 01 — Identifier confabulation: the phantom-CVE class

CLASS elicitation pipeline, synthesis layer · DATED 2026-08-07 · STATUS bounded and printed; probe on cadence

Machine-drafted synthesis prose cited CVE identifiers that were never assigned. Of 27 distinct CVE tokens in the synthesis layer, 25 were probed against the issuing authority (MITRE), NVD and the CISA KEV catalog: 14 real and exploited, 8 real and recorded, 2 truncation artifacts of prose, and 3 ABSENT — CVE-2026-50523, CVE-2026-53921, CVE-2026-66067 — with no record at MITRE or NVD as of the probe date. None of the three reached a sealed forecast row.

The class is exactly three, not wider: two initially suspect tokens (CVE-2026-14266, CVE-2026-66066) were verified as real NVD records and reclassified feed-carried, registry-lagged. Absence is dated evidence, not proof forever — MITRE assignment is near-immediate on allocation, so absence weeks after the citing reports supports likely-confabulated, and the record says exactly that.

Remedy: ident_audit.py and ident_probe.py run on cadence; identifiers the published record cannot ground print as UNSOURCED.

Full per-token record: IDENT_PROBE_2026-08-07_2.md

Finding 02 — Polarity inversion at seal

CLASS gate gap, direction untested · DATED 2026-08-08 · STATUS open — row resolves 2026-08-26

Row KKR-20260808-01 (lmstudio/auto, sealed 2026-08-08 at 30%, deadline 2026-08-26, keyed by operator ruling). The statement asserts a Shahed-type UAV strike confirmed by cross-bias sources inside 2026-08-21..24. The sealed resolution criterion is satisfied exactly when the claimed event does not occur — no in-window CISA KEV date-added value and no two cross-bias corroborations — and the failure condition restates the affirmative event. A hit on this row records the complement of the forecast: 30% stated on the claim scores as if 70% were stated on the event. The Brier lands backwards.

Mechanism: the packet's machine-readable-register preference was bolted onto a kinetic claim, negating the register test to make it fit. The gate tested subject identity and venue class; it never tested direction.

Disposition: sealed rows are not repaired. At resolution this row is adjudicated AS WRITTEN with this finding cross-printed beside the verdict, and the verdict line states that hit and miss on this row carry inverted sense relative to the statement. Gate closure: since KK35 the gate rejects at seal any row whose statement and resolution primary clauses disagree in negation, in either direction; clarifier tails remain legal because only the first segment is tested.

Row on the public book: ledger

Finding 03 — The gate validates rows in isolation

CLASS gate gap, structural · DATED 2026-08-18 · REV 1 2026-08-19 · STATUS checked by instrument; gate itself still row-local

Rev 1 supersedes rev 0, which was wrong in its central instance; the superseded text is retained at the foot of the full record per 5.07. Rev 0 read two rows sealed sixteen days apart and called them incoherent. Monotonicity binds one belief state at one moment; this desk's arms run cold and never see their own sealed rows, so cross-day consistency is a property the elicitation design makes structurally impossible to require — rev 0 measured the desk's own design and reported it as the forecaster's defect.

What survives is the structural claim: every check in the gate examines one row against the standard, and nothing examines a row against the rows already sealed. A same-elicitation incoherence — a subset event priced above its superset inside one silo, one belief state — would pass the gate today. coherence.py now checks exactly that and exits non-zero if one appears. It has found none: across 795 sealed rows as of 2026-08-19, 59 structurally comparable, zero same-elicitation violations; the remaining 736 are dropped rather than guessed at — a row the instrument cannot parse is not a row it has cleared. Cross-elicitation nested pairs print as REVISION with the point move; nothing is scored.

Named, not closed: statement-level nesting with no numeric threshold ("confirms X" at 65 and "confirms X in a recorded floor vote" at 85, one elicitation) is a genuine violation the instrument cannot see. Four corrections to one check in two days, all printed.

Full record including rev 0: FINDING_03_gate_row_local.txt

Finding 04 — The gate kept UTC time on a desk that runs local

CLASS gate defect, clock frame · DATED 2026-08-21 (desk-local; 2026-08-22 03:21Z) · STATUS fixed and proven at the two gate sites; one sibling site named below

The KK20 retrodiction governor rejects a row whose event window opens before the day it is sealed. It computed “today” as the UTC calendar day. The desk seals on its own operating day, America/Denver. At 21:21 local on 2026-08-21 — already 2026-08-22 by the clock the governor was reading — an ingest killed seventeen rows across three arms whose windows opened 2026-08-21, calling them retrodiction. The previous evening’s ingest at 17:36 local had passed the identical window shape. Same rows, same gate, different verdict, and the only variable was the hour.

Mechanism: two date governors (the deadline floor and the window-open check) took their “now” from the UTC clock while every other clock the operator reads is local. Row identifiers and date_issued are UTC by rule and stay UTC; a governor is not a timestamp. Proof: all twenty-nine rows of the batch were driven through the gate under both frames. Under the desk-local frame seventeen kills became two, and those two were the date extractor’s, not the clock’s — they are specimen (a) of Finding 05. Twelve wrongly killed rows were refired verbatim and sealed before local midnight, with the rejection trail kept: the 03:21Z reports carry the kills, the 03:30Z reports carry the refires.

Ruling (operator, delegated 2026-08-21): gate governors run on the desk operating day, box-local calendar; record timestamps remain UTC; a rejection discloses its frame (“desk-local”). Hours-level same-day exposure remains the already-decided gate’s jurisdiction, not the calendar’s.

Named, not closed: the resolver’s due test still reads the UTC day, so a row becomes walkable up to six hours before its deadline day has ended on the desk. Same family, benign in effect, printed here rather than fixed silently.

Trails: fable · opus · sonnet (kills, 03:21Z) · refires at 03:30Z, same directory · fix in kkr.py, commit a8e4d94

Finding 05 — Four misfire classes the gate printed before it was fixed

CLASS gate defects, false-positive rejection · DATED 2026-08-26 · STATUS fixed (KK37-GATE E1–E3; KK38 bundle, addendum below); refires sealed

The 2026-08-26 batch was read off-box before ingest and eight kills were predicted by class. The desk ingested first, so the misfires would print, then patched, then refired. The four false-positive classes, each with its printed specimen:

(a) A governed reference date read as a window bound. Since KK35 the gate knows that “as of”, “dated”, “on or before” introduce reference dates, but that knowledge only shielded the single-day check; when every date in a row was governed, the retrodiction governor fell back to the earliest of them and called the row retrodiction. Specimen: an FOMC row rejected because its range had been “held since 2026-07-29”. Bare “by DATE” was not a governed idiom at all. Specimen: a Nepal death-toll row rejected as a single-day window for saying “by 2026-09-16”. (b) A subject the checker cannot see. The subject-token check reads capitalised tokens; a resolution whose subject is a merchant vessel at 26.5N 56.3E carries none, and a row naming UKMTO died as “venue only, no subject” while restating its subject in full. (c) A series alias missing from the lexicon. DCOILWTICO expanded to its subject; DCOILBRENTEU did not, so a Brent row’s resolution read as a bare register. Fix: E1 — a row whose every date is governed takes the window [seal, deadline] by construction and is not tested for retrodiction, and “by”/“since” join the governed idioms; E2 — the Brent alias; E3 — a geographic radius counts as a standalone criterion under the self-referential-register exemption, the anaphora bar untouched. Twelve behavioural asserts before and after, on a fresh clone, including the four true kills of the same batch (subject mismatch, venue-only) which stay dead.

Outcome: three rows refired verbatim and sealed (KKR-20260827-20, -21, -22). The Brent row was refired and died again, correctly, on citation support — the arm cited Strait of Hormuz items for an oil-price claim and the vocabulary check is blunt by design. Eleven kills on the day, nine called in advance. The two the off-box read could not see were the live citation check and one genuine venue disjunction (“a police FIR or court filing”). The pre-read is a floor, never a forecast, and it says so.

Named, not closed: the venue rule passed “court records or a report from…” and killed “a court docket or a report from…” on the same day — equivalent constructions, opposite verdicts, the class-noun list deciding; and the resolver’s UTC due test (Finding 04).

Trails: fable · opus (kills) · fable refire · opus refire · fix in kkr.py, commit 3a4d889

Addendum, 2026-08-28. The next day’s batch surfaced four further false-positive classes, closing this finding’s venue item and adding three: a number written before its comparator (“750 or more”) read as no threshold; a deal or transaction closing (“confirmed closed”) read as a market close; two document types on one named host (“a system card or preparedness report … on openai.com”) read as two venues; and an actor disjunction filling a role (“agency or independent organization as an evaluator”) read as a venue choice. All four are closed in the KK38 bundle, on the record in kkr.py and registers.py with twelve behavioural asserts and standing guards (a genuine two-host disjunction stays dead). The battery gates deliveries, not only fixes: two successive deliveries of that bundle failed their post-assert battery on the live instrument and restored themselves from their own backups, on 2026-08-27 between 18:18Z and 18:37Z, before the third was allowed to remain written — delivery hashes, second 5a2157a1…, surviving third 9f027bbb…; the first cut’s hash was not recorded, its failure and restoration are the console record, printed here. Three refires ran before the fix landed and died; their trails are kept. A patch that cannot prove its behaviour does not keep its write. Eight classes across the two days, two bundles, every specimen printed before its fix.

Finding 06 — Seven misfire classes from the 31 August ingest, and a venue ruling

CLASS gate defects, false-positive rejection; register policy · DATED 2026-08-31 · STATUS open — printed before the fix; GATE-2026-08-31 bundle and refires pending

Two batches were ingested at 23:01Z on 31 August: the 30 August evening batch, missed and priced under the crash law rather than repaired, and the 31 August batch, each pinned by hand to the packet and battle report its arms actually read (--packet, --report), because the ingest wrapper assumes the newest record on disk and would have checked the late batch against a report it never saw. Sixty arm rows; eighteen rejected; the control arm mirrored its forecaster kill for kill on all six files. The off-box pre-read predicted two kills. Read afterwards against the cited items and the gate code, the eighteen sort into six true kills, three rows on which the venue rule fired as written and exposed a policy gap, and nine false positives in seven classes — one row in seven of what the arms filed. Between Finding 05’s addendum and this ingest, the GATE-2026-08-30 bundle closed four further classes (scheduled primaries; the FOMC/Federal-Reserve subject pair; a cited item saying Fed or FOMC grounding an FOMC claim; a shared host on either side of a venue disjunction) and refired five rows (KKR-20260829-74 through -78); the corn row stayed named-not-closed after two refires (commodity self-reference: a registered venue in the statement beside a threshold, the exemption still refusing; cbot resolving to cme-group).

True kills, six. A WordPress row whose only subject was “any of these CVEs”, none enumerated anywhere in the row. Two WTI rows (opus, fable) whose cited items were Khamenei on Hormuz, a helium shortage, and the Venezuela barrel deal — an oil-price claim with no oil-price item, the imported prior 4.02f exists to catch. A Siskiyou County wildfire row grounded on a GDACS “forest fire notification in United States” that names no county and no state. A tanker row resolving on “at least one wire service”, none named. A Massachusetts trial row whose resolution never names the defendant and is literally satisfied by any verdict returned in that court.

False positives, nine rows, seven classes. (a) Statutory calendar. Both appropriations-lapse rows died as single-day windows for an unscheduled event: the scheduled-event lexicon has no word for a fiscal-year boundary, a continuing resolution or a debt limit. (b) The three-letter floor. Two FOMC rows (opus, sonnet) died on citation vocabulary. Both cite item 71, a Jackson Hole roundup whose grounding lives in its slug, jackson-hole-fed-chair-kevin-warsh-hawkish-rate-hikes; E10 keeps slug tokens of four letters or more, so fed is dropped before E2v’s Fed/FOMC alias can bind, and hikes is not aliased to raises. Contradiction pair: the fable FOMC twin passed the same check on one shared word, higher. E2v is therefore closed on the title and open on the slug. (c) Date restatement by reference. A KEV row (“3 or more entries”) and a Nepal toll row (“1000 or more … for the flood event”) died as register-only, no subject. The KK35 lowercase fallback accepts a common-noun subject only if the resolution restates two ISO dates or shares three five-letter words with the statement; a resolution that says “in the window” fails both. Contradiction pair: “30 or more entries” (opus) and “8 or more entries” (fable) passed the same night with the dates restated. (d) Disjunction inside the attribution tail. “an official MAG, NCSC, or ICO statement” (who issues the statement) and “wire services, citing shipping authorities or maritime insurers” (whom the wires cite) were read as venue alternation. R8’s class, one construction further in. (e) Alias and acronym gaps. CPS is not read as the Crown Prosecution Service; WTI is not read as CL or Light Sweet Crude, nor NYMEX as CME Group; the United States is not read as Congress or OMB. Each printed as “the resolution names a different subject than the statement” on a row that names the same subject twice. (f) Geography abbreviation. A steel-and-aluminum row died DISJOINT, “cited items name Canada; the claim is about United States”, on items whose titles read “U.S.-Canada trade war”: the geography register does not read U.S. as the United States. (g) The ‘count’ false friend. “a verdict on any count” tripped the measurable-claim check, because an indictment count is on the quantity-word list.

Venue ruling, operator-delegated. Three rows carried disjunctions the venue rule kills as written: a CPS statement or two named papers reporting one; a court docket or a wire report; a Federal Reserve implementation note or the FRED series that mirrors it — while a Treasury yield row resolving on treasury.gov or FRED DGS10 sealed the same night on the same shape. The rule was inconsistent and the desk owed it a ruling. Primary-or-mirror is allowed as a typed class: where the register knows one venue as a mirror of the other (FRED of the Federal Reserve and Treasury series; kev-data of the CISA catalog, which is already how KEV rows are adjudicated), the disjunction collapses to the primary as source of record and the row seals with that disclosed. The sealed yield row stands under that rule with treasury.gov as its source of record; it is disclosed here as having passed first by accident of the regex. Primary-or-press is killed consistently: a register and a press report of the register are not one datum, the two can disagree in time and in substance, and the gate’s own advisory says where a register exists, name it. Where the register is not publicly reachable, the arm names the press class alone. The CPS and docket rows therefore stay dead as true kills; the FOMC mirror row refires.

Advisories, not rejections. Seven market-threshold rows carried no reference level and default to keyed under 4.03/5.05 until the arms state the level held at seal; the line goes into the packet template the arms read. Four crime rows resolved on press where a docket or a prosecutor’s release exists; noted, not killed.

Battery for the bundle. Tonight’s eighteen rows are the specimens. After GATE-2026-08-31, ten must pass (both appropriations rows, both FOMC citation kills, the FOMC mirror row, the KEV and Nepal register-only rows, the MAG and Hormuz attribution rows, the steel-and-aluminum geography row) and eight must stay dead (the six true kills and the two primary-or-press rows). Refires are verbatim under the two-attempt limit. The addendum will carry the bundle’s hashes, its bench and box results, and any delivery that failed its own battery and restored itself.

Trails, 30 August batch: sonnet · opus · fable · 31 August batch: opus · sonnet · fable · controls mirror in the six control-baserate reports of the same stamp.

Addendum, 2026-09-01. The GATE-2026-08-31 bundle (twelve needles across kkr.py and registers.py; delivery sha256 f1ac952976186849…) was applied on the live box in two attempts, and both are printed. The first failed its own battery on the mirror specimen — the register carried no Federal Reserve venue for FRED to mirror — and restored both files byte-identical before exiting. The Federal Reserve was then added to the venue register (fed) with FRED registered as its mirror and as the mirror of the Treasury H.15 series, and the second run passed 18 of 18: ten classes cleared, eight true kills held. Post-write hashes: kkr.py efeebcf2c7daf988, registers.py 74b5c6b0f3f70f97. Refires: a first attempt at 02:09Z ran against the unpatched gate — an ordering error in the delivery sequence, not in the gate — and all eight rows died; those trails stand. The second attempt at 02:13Z sealed ten of ten, including MAG and the Nepal ≥1000 row, whose windows had opened on 31 August: the desk clock still read 31 August, so they were forecasts, not retrodiction; one day later they would have stayed dead under the crash law, which is the class the anchoring build retires. Two mechanisms are pinned sharper than the text above: the CPS miss (class e) was E4’s venue-cue demotion running before the initialism union, so a restated initialism was thrown out as a venue; the U.S. miss (class f) was the hyphenated compound “U.S.-Canada” defeating the surface match, not only the abbreviation. One limit found in the fix itself: the M1 disclosure printed at ingest but the row’s notes field did not carry it, because seal-time initialisation overwrote the field; corrected in ANCHOR-2026-09-01, and the three FOMC-mirror rows sealed 1 September carry the disclosure in their report, not their row. Trails: attempt one (dead) opus · opus 2 · sonnet · fable; attempt two (sealed) opus · opus 2 · sonnet · fable · fable 2.

Finding 07 — A dead client wrote the anchor state, and the publish gate let a conflicted file through

CLASS instrument defects, two; environment failure, one; disclosure omission, one · DATED 2026-09-01 · STATUS open — printed before the fix; PUBGUARD-2026-09-01 pending

Four items from one publish leg on 1 September, in the order they happened.

1. The local anchoring client does not start. The desk’s box runs its scripts under Python 3.14; the ots launcher runs under Python 3.12, where python-bitcoinlib 0.12.2 loads OpenSSL by find_library(‘ssl’), then ‘crypto’, then ‘libeay32’. On Windows those names resolve only if a DLL of that exact name sits on PATH; none does, and the library passes None to LoadLibrary. Every stamp attempted from the box fails at import. Consequences, priced: the daily anchor cron on GitHub Actions still runs and is the source of every ANCHORED state on the record, so the standards texts and the ledger are unaffected; the Kalibrierwarte registered report published today (05fd04797228d34c) has no receipt until that cron’s next run; and arrive.py’s hourly stamps log unstamped until the client is repaired, so the late-seal lane rests on the log’s own clock alone in the meantime. Repair path: Python’s own libcrypto-3.dll copied onto PATH under the name the library asks for. Environment, not instrument; printed because the instrument depends on it.

2. The dead client wrote the state file. ots_anchor.py --stamp read every receipt through the failed client, got UNREADABLE for all nine, and wrote that over nine ANCHORED entries in docs/ots_anchors.json. A client that cannot start has read nothing; the instrument treated a failure to read as a reading. Fix in PUBGUARD-2026-09-01: a preflight refuses to stamp when the client cannot start and leaves the state file untouched, and state writes become monotone — unreadable or failed never overwrites a recorded anchored or pending; the prior entry is kept and the failure is noted on it with its time.

3. publish.bat committed a file carrying conflict markers. The publish leg pulls with --autostash. The pull brought the cron’s correct state file; the stash pop conflicted with the box’s UNREADABLE version; git left both sides in the file with markers; add -A cleared the unmerged state; verify passed every invariant it had; commit dd7a67f pushed docs/ots_anchors.json to the public record as invalid JSON. It stood for six minutes. Repaired at 6a24ac7 by restoring the cron’s version from 1ba6a86 and dropping the stranded stash. Fix in PUBGUARD-2026-09-01: a “merge state” invariant in desk.py verify, FAIL on any unmerged path or any tracked text file carrying both a <<<<<<< and a >>>>>>> line; verify already gates the ship on FAIL. Both defects are one class: a broken step that wrote through because the step after it did not look.

4. Disclosure omission, carried from Finding 06’s addendum. GATE-2026-08-31’s eighth edit put the reference-level rule into PROJECTION_PROMPT, whose SHA-256 is the Kalibrierwarte’s frozen rubric. The hash moved (4ea5ab8f to bbdc7791) and the ten refire rows sealed 1 September opened a third cohort. That is the frozen-rubric doctrine working as written — a changed hash is a new cohort and discloses itself — and it was the right outcome, but the addendum described the edit as a template line and did not say the cohort moved. The registered report says it; this finding puts it on the findings page.

Record: dd7a67f (the conflicted file, as pushed) · 6a24ac7 (repair) · the registered report (Section 5, cohorts) · the console export of the leg is held on the desk.

Finding 08 — The ledger’s Bitcoin anchor covers the ledger of 1 August

CLASS instrument defect, anchoring cadence; disclosure gap · DATED 2026-09-01 · STATUS open — printed before the fix; RESTAMP-2026-09-01 pending

The first status read after the client repair (Finding 07) printed ledger.json.ots ANCHORED — NO, the file changed since stamping. The receipt’s digest, a3a70e5e, is the served ledger at commit ad1d421, 2026-08-01 18:58Z, 246 rows. The ledger served on 1 September has 1,225 rows and a digest the receipt has never seen.

Mechanism. ots_anchor.py --stamp runs ots stamp on every target, and the client refuses to overwrite a receipt that already exists. The code then reads the existing receipt’s state and prints it. So a mutable target is anchored once, on the day it first gets a receipt, and never again: every later run reports ANCHORED for bytes that are no longer served. The state file has carried pairing: DRIFT for the ledger since the first publish after 08-01, with the note that the receipt proves the original bytes and nothing about the file served now. Disclosed, daily, for a month; acted on by nothing. The health face graded the anchor run OK because the run happened; anchoring currency was not what it measured. kalls_hashlog.json and plate.json pair MATCH: unchanged since stamping.

What has stood in the meantime. Every publish posts the served ledger’s SHA-256 to a third-party feed under that feed’s own clock (the beacon line on every publish), every row carries its own hash and its seal date, and the repository history holds each state under the operator’s account. The 08-01 receipt remains a valid Bitcoin anchor of the 246-row ledger of that day. What did not exist is a Bitcoin anchor of any ledger since.

What the letters said. The NIST AI 200-2 comment and the Zero Drafts TEVV input describe the ledger as anchored to Bitcoin through OpenTimestamps. True of a snapshot; silent on cadence. The desk corrects the record here, on the register the letters themselves ask standards bodies to require, rather than in the filed text.

Fix, RESTAMP-2026-09-01. On every stamp run, a target whose bytes changed since its receipt keeps that receipt under the digest it covers (ledger.json.a3a70e5e.ots) and receives a new receipt for the current bytes; the state file lists the kept snapshots per file; the daily cron then re-anchors the ledger on every day it changes, and the kept snapshots form the anchored history of the ledger from here on. Nothing is deleted and no receipt is re-issued to make later bytes look anchored. The first run after the fix leaves the ledger PENDING until the calendars reach a block; that is correct and expected.

Record: ad1d421 (the bytes the receipt covers) · ots_anchors.json (the DRIFT line as it has stood) · Finding 07 above (the read that surfaced it).

Finding 09 — The re-issued receipts commit bytes nobody can download, and the arrival log never shipped

CLASS instrument defect, digest convention; evidence-custody omission · DATED 2026-09-02 · STATUS open — printed before the fix; OTSNORM-2026-09-02 pending

1. The receipts verify against nothing served. RESTAMP’s first live run (Finding 08’s fix, 1 September 19:36Z) superseded receipts on five targets, and legitimately: every standards text amended since its first stamp — RPAS, LIAS, the PCAOB docket manifest, the kalls hashlog, the ledger — had been carrying Finding 08’s stale-receipt condition, and the old ANCHORED receipts are preserved beside their digests. But the new receipts were stamped over the Windows working copies, which carry CRLF line endings, while the repository serves LF. Verified directly: the RPAS receipt commits 36a523b8, the LIAS receipt 27feb26a, the manifest receipt 4c43ecfc — each exactly the SHA-256 of the served file with LF replaced by CRLF, and none the digest of any byte stream a stranger can download. A receipt that commits the box’s private line endings proves the desk stamped something; it does not let anyone verify the thing served, which is the entire point. The daily anchor cron runs on Linux and hashes LF, so left alone it reads the mismatch as drift and supersedes again — one corrective pass producing correct receipts, then churn from the box side at every future manual stamp. Fix, OTSNORM-2026-09-02: every digest this instrument computes, compares or stamps is the digest of the served bytes, LF-normalised — the convention every published hash on this desk already uses — and a CRLF working file is stamped through a temporary LF copy so the receipt commits what Pages serves.

2. The arrival log never shipped. anchor_log.json — the generation-time arrival evidence behind the late-seal lane (ANCHOR-2026-09-01) — has existed on the box since the baseline sweep and has missed four consecutive add -A publishes, with no repository ignore rule matching it. The cause sits in the box’s local git configuration and is being pinned; the remedy is an explicit add on the next publish. Priced honestly: every A1 disclosure references this log, and until it ships a stranger could not read the evidence the disclosure cites. No sealed row has yet depended on it — the first row through the lane sealed 1 September 23:03Z with its arrival note, and this finding ships alongside or behind the log itself.

Record: 1b495ed (the CRLF receipts, as pushed) · Finding 08 above (the supersede mechanism they rode in on) · ots_anchors.json (pairing per target) · the arrival log, from its first committed appearance.

Finding 10 — The control priced frontier rows at another forecaster’s miss rate

CLASS control construction defect, reference class; registration quality check (e) failed · DATED 2026-09-02 · STATUS open — printed before any fix; the twelve rows stand as sealed; ruling: halt stands

The Kalibrierwarte registration (v3, Section 7) carries six quality checks that must pass before any hypothesis is read. Check (e): control/baserate skill against its own base rate — the bootstrap 95% interval includes zero. By construction. On the first run of warte_report.py, within cohort 1, it failed: twelve resolved control rows, skill −0.335, interval [−2.03, −0.025]. Pooled across cohorts — the figure the face has printed — twenty-eight rows, skill −0.187, interval [−0.76, 0.010], reaching zero by a hundredth. “By construction” was wrong, and the check did what it was written to do.

Mechanism. baserate.py prices each mirror at the hit rate of every resolved row on the ledger at the moment of composition — the row’s domain when that domain has ten resolved rows, otherwise the whole ledger. On 11 August that class was 43 resolved rows, 36 of them lmstudio/auto’s, hit rate 0.326; nine of the twelve controls carry 0.3256 (the rest 0.25 and 0.50 from domain classes). The rows they mirror are frontier rows — eight Sonnet, two Opus, two Fable — and those resolved 7 hit / 5 miss; the three unattested arms stand at 9 of 15 in the cohort. A control shares its mirrored row’s statement, deadline and outcome, so its own base rate is the frontier rows’ base rate, and its skill against that rate can only be zero if the class it drew from behaves like the population it mirrors. It does not. The class is another forecaster’s record: the local arm hits 11 of 62 in this cohort. Two smaller defects ride along. The class contains the control’s own resolved rows (8 by 18 August, 17 by 27 August), which double-counts frontier outcomes back into the rate; and the composition-time rate moves as the ledger fills (0.326 on 11 August, 0.426 on 27 August), so mirrors sealed on different days carry different reference classes under one tag.

Direction. The floor every frontier arm is described as having to clear was set by lmstudio/auto’s misses. An arm “beats the control” by being a different forecaster from the local model, not by being calibrated. No published claim rests on it: every face prints the noise line, and the registration makes this control a quality check, not a hypothesis (Section 7). The defect is in what the control would have been able to say once the floors cleared — which is nothing about the arm it mirrors.

Consequence and ruling. Under Section 7 the read for lmstudio/auto[post-window] at its first checkpoint — 62 resolved within cohort 1, the first arm to reach one — halted before any hypothesis. Operator ruling of 2026-09-02, recorded in the registration’s Section 13: the halt stands. Nothing is repaired retroactively — a mirror composed later is retrodiction and dies, and sealed control rows stand — and the check re-evaluates at every run as control rows resolve. A corrected construction — a class drawn from the mirrored arm’s own record, or from the mirrored population — is a different forecaster under the arm identity law and seals under its own tag; this arm’s rows keep their tile and their receipts. Whether and when such an arm is registered is a decision outside this finding.

Reproduce. python warte_report.py at any clone from the commit carrying that file (LF-SHA-256 fa560fe3a58570bb); seed 26 fixes the intervals. The twelve rows: KKR-20260811-52, -54, -59, KKR-20260812-31, -36, KKR-20260813-17, -36, -38, KKR-20260817-18, KKR-20260818-37, -40, KKR-20260827-46.

Record: warte_report.py (the check as run) · baserate.py (the rate rule) · KALIBRIERWARTE_REGISTERED_REPORT_v3.md Sections 7 and 13 (the check, the pin, the ruling) · forecasts/warte_report_2026-09-03.json (the halted read, once published).