Skip to content

Rehome the cable-leg observation out of the SFF specification, and retire the contradiction arm - #10671

Merged
briansrls merged 13 commits into
mainfrom
session/fierce-deer-825
Sep 6, 2026
Merged

briansrls merged 13 commits into
mainfrom
session/fierce-deer-825

Conversation

@briansrls

@briansrls briansrls commented Sep 6, 2026 •

Copy link
Copy Markdown
Contributor

Follow-up to #10614 and #10640, correcting four defects found by external review against the primary SFF tables and by repo-authority review.

§3 layering: an observation is not an upstream fact

extdeps.transceiver.sff_8636 had grown SecondaryNotObserved and a completeness predicate. Whether this fleet pointed ethtool at a module is not something SFF-8636 says. DESIGN §3:

Observations produced by this repository are receipts in the observing product or workflow layer, not facts owned by the observed upstream. Missing observations are coverage obligations downstream, never Unobserved properties authored inside an upstream module.

extdeps.transceiver.sff_8636   →  byte meanings only
product.cable_leg_observation  →  what was read, coverage, consistency, the requested-mode join

Noted without excuse: this lane raised the identical objection against another module's ..._observed row hours before committing its own.

Coverage is a fold, not a predicate per variant

required_fields_observed was variant-to-Boolean residue (§6). Coverage is now one census — cable_leg_unread_fields returns the unread fields and every coverage question is asked of that list, so a newly-optional field is a row rather than a new predicate at each call site.

00h is decoded from the byte, never authored beside it

SecondaryObservedUnspecified and SecondaryObservedCode { code: 0 } were both constructible, so the caller chose what zero meant — the decorative-byte defect one field over. And interpret(0) fell through to ComplianceCodeUnmodelled, so one standards sentinel decoded two ways depending on the path. Now: SecondaryObserved { code } only, 00h → ComplianceUnspecified as a function of the byte.

The contradiction arm is retired, not kept unreachable

Deciding a contradiction requires the encoding byte and the compliance codes to describe the same interface — true for unretimed passive copper, false by design for a module converting NRZ host lanes to a PAM4 media channel. Nothing observed here settles that scope, and the field that would (SFF-8636's transmitter-technology nibble) has not been read. A variant belongs in the operational codomain only if some valid input can produce it, so the arm is gone and the distinction survives as a typed undecidable naming its cause, with the next-rung trigger written down.

An InterpretationGap now carries field identity, so an unspecified encoding byte no longer reports the interface-scope frontier — that was a false diagnosis blaming a field whose reading would not have made the observation decidable.

Sentinels stop fabricating measurements

Byte 140 00h built NominalRateDirect(0 baud). SFF-8636 gives 0 the meaning "not specified; determine from module technology" — a consumer comparing that to a required rate reads the module as infinitely slow rather than as silent. Now NominalRateUnspecified.

0x40 is modelled with its primary citation (SFF-8024 Rev 4.14, Table 4-4, row 40h — the earlier source said Table 4-6, which was wrong), retiring the placeholder code: 0.

Executed

claim_executor --required-floor from a compiler built from this tree:

verdict=FloorClean   claims_failed=0
16 cable claims planned-and-passed

Including the inverse control (a secondary byte read as 00h must not become decidable), the two-axis assertion (observed true, exhaustive false), the encoding-gap test, and the zero-baud sentinel test.

🤖 Generated with Claude Code

https://claude.ai/code/session_01AigrH3JpxgSJBmqHMBAr6W

Brian Searls and others added 9 commits September 5, 2026 21:58
…er is not a link contract

Two 400G QSFP-DD to 4x100G breakout cables (FS order FS260902769849, part
QDD-400G-4QPC015) link and run stably at half their purchased rate between a
MikroTik CRS812 and ConnectX-7 NICs. The legs' EEPROMs report extended
compliance 0x0B, which attests 25G-per-lane modes; nothing in them attests
100GBASE-CR2, so the NIC refuses to enable 100G_2X.

The corpus could not state any of that. "100G" was one Bandwidth, so
100GBASE-CR4 (4x25G NRZ) and 100GBASE-CR2 (2x50G PAM4) were indistinguishable
-- one spelling, two contracts, DESIGN section 3's meaning fork. And a cable
leg's coding, which is what actually decides the negotiated rate, was
unmodelled entirely.

extdeps.ethernet.link_mode makes the aggregate DERIVED and never authored, so
"100G" is unsayable as a primitive fact. A lane carries three distinct numbers
-- service rate, encoded rate, symbol rate -- and they are three fields, not
one. std.measure gains SymbolRate for the baud axis, because the first draft of
this work typed a baud field as Bandwidth: the module written to prevent the
units conflation committed it.

extdeps.transceiver.sff_8636 owns the EEPROM field layout, reading BOTH
extended-compliance codes (bytes 192 and 116), because SFF-8024 lets a
multi-application module report the encoding of its primary application -- a
predicate over one code and one encoding byte is not a soundness proof. Its
assessment is relative to a REQUESTED mode and splits three ways: contradictory
under the observed profile, insufficient evidence for the requested mode, or
not understood by this decoder. The delivered cable lands on the second, which
is strictly weaker and strictly more defensible than calling its EEPROM
self-contradictory.

NOT ESTABLISHED, recorded rather than guessed: no clause attribution is carried
on any mode row, since an unread clause number is a fabricated citation; the
SFF-8024 code that attests 100GBASE-CR2 is not authored here for the same
reason; byte 140 may hold the 0xFF escape rather than a rate, which needs the
raw dump to settle; and stable 50G operation is evidence about 50G only -- it
does not certify the 26.5625 GBd PAM4 path.

NOT VERIFIED LOCALLY. Six attempts to typecheck this failed on the toolchain,
never on the source: a pipeline-clobbered exit code, an installed gunbc that
reds every section 4c annotation in the corpus, two memory-admission refusals,
an OOM through the --entry path, and a dispatch that returned no output. CI is
the instrument for this branch.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01AigrH3JpxgSJBmqHMBAr6W
…elivered leg

The modules typechecked and executed nothing. hundred_gig_aggregate_collision
and sff8636_assess_leg_coding had no consumer, which is
specification-without-execution -- DESIGN section 5's deepest trap, and the
shape that looks finished precisely because it type-checks. A scheduled review
approved the diff without noting it; an approval reports no blocking defect,
it does not establish that evidence exists.

The discriminating subject is the real delivered part: the EEPROM reading from
FS order FS260902769849 (part QDD-400G-4QPC015, leg SN S2630771509-4) is a
fixture, and the central test asserts that this leg does NOT attest
100GBASE-CR2. That is the failure that shipped a half-rate fabric which links,
pings clean at MTU 9000 and tests green everywhere else the fleet looks.

Three arms keep it from being vacuous. The same leg IS admitted for
100GBASE-CR4, the mode it is actually coded for, so a decoder that refused
everything would not pass. A synthetic correctly-coded leg is admitted for the
requested mode -- and it is marked synthetic, because it validates the DECODER
and establishes nothing about whether any physical cable works. A leg whose
attestation arrives only via the byte-116 secondary code is still admitted, so
a collapse back to reading only byte 192 reds here rather than being caught by
inspection a second time.

The units separation executes too: a PAM4 lane is asserted at 26.5625 GBd
carrying 53.125 Gb/s encoded against a 50 Gb/s service rate, so re-fusing those
fields or assigning a baud figure to a bits/s carrier stops the arithmetic from
holding.

The synthetic row's compliance code is deliberately 0 and says so: the real
SFF-8024 assignment for 100GBASE-CR2 has not been read in this lane, and
inventing the byte would be the fabricated citation this whole subject exists
to catch.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01AigrH3JpxgSJBmqHMBAr6W
… from an unread field

Review found the central witness DETERMINISTICALLY FALSE. For the delivered
leg, every attested mode is NRZ while the encoding byte says PAM4, so the
assessor returned CodingContradictsEncoding -- while the test, the commit
message and the PR body all said CodingInsufficientForRequestedMode. Behaviour
was documented and never executed, in the PR whose thesis is that unexecuted
claims are worthless. The floor had died earlier on generated-artifact drift,
so nothing had contradicted it; the witness could not even compile, because it
constructed a sole_constructor type outside its defining module.

The repair is to the PRECONDITION, not the expectation. Widening the test to
accept any refusal would have been the absorbing fallback. A contradiction is a
claim that the WHOLE declared profile disagrees with the encoding byte, and
byte 116 was never read on this cable, so that claim is unavailable:
SecondaryNotObserved is now distinct from SecondaryObservedEmpty, and an unread
field can no longer stand as evidence of absence.

THE COMPLIANCE BYTE NOW DECIDES. ExtendedCompliance previously carried an
author-supplied `attested_modes` beside `code`, and the assessor read only the
former, so the byte was decorative -- the synthetic fixture passed code 0 with
a hand-written CR2 list and was admitted on its own say-so. Interpretation is
now a function of the byte, an unmodelled code interprets to UNKNOWN rather
than to an empty attestation, and the discriminating control this enables --
mutate only the code, hold every other field fixed, require the unknown result
-- was structurally unwritable before.

0x0B carries a third entry: 50GBASE-CR2 subject to Clause 91 FEC, found by an
external standards cross-check rather than by anything in this repository. The
condition is retained, not flattened: it yields
CodingAttestsRequestedModeSubjectToFec, and a test asserts it is attested AND
not attested outright, because promoting a conditional entry to unconditional
support is the silent widening the qualification exists to prevent.

The stage0 mirror for std_measure.rs is regenerated from its authority
(first_generation_equal=true, 157/157 adjudicated); the candidate diff was
exactly the 13-line SymbolRate addition and nothing else.

EXECUTED, not asserted: claim_executor --required-floor built from this tree
reports verdict=FloorClean, claims_failed=0, with all 14 cable-coding claims in
the executed population. The prior run of the same instrument red on this file
with three located errors, so the pair discriminates rather than a green
standing alone.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01AigrH3JpxgSJBmqHMBAr6W
A review noted render_link_mode has no in-tree consumer and judged it too small
to flag. DESIGN section 6 disagrees: an artifact with no final consumer is a
scaffold tell, and the reviewer's own stated test is whether the thing survives
into the terminal architecture and is consumed by it. So this censuses every
function the PR added rather than fixing the one item spotted -- which found a
cascade the single fix would have left behind: modulation_label was consumed
only by render_link_mode, and the String import only by modulation_label.

sff8636_nominal_rate_from_byte222 also goes. It is CORRECT -- byte 222 is the
escape target in units of 250 MBd -- but nothing reads it, because nobody has
taken the raw dump yet. Writing a witness whose only purpose was to consume it
would make the test its own justification rather than a final consumer. It
returns with the ethtool raw reading that needs it.

Verified by execution, and the verification earned its keep: the first attempt
at this deletion cut at the match block's closing brace instead of the
function's and left an orphaned brace, so the module did not parse and the
floor refused with ZERO claims executed. A deletion needs the same evidence as
an addition; "it only removed dead code" is how a file that cannot parse gets
pushed. Floor now verdict=FloorClean, claims_failed=0, all 14 cable-coding
claims in the executed population.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01AigrH3JpxgSJBmqHMBAr6W
# Conflicts:
#	dag/extdeps/ethernet/link_mode.dag
#	dag/extdeps/transceiver/sff_8636.dag
… reconciles against a reading

The substrate that landed in #10614 models the cable. It would not have stopped
this order, because nothing consumes its findings at purchase time. These are
the gates that do.

THE ORDER WAS CORRECTLY ADMITTED, and the witness says so out loud because the
opposite is the intuitive and wrong belief -- one this lane already published
once and had to retract. FS's listing promises 4x100G legs of 2x50G PAM4, which
is exactly the requirement, so a pre-purchase gate reading it ADMITS. A gate
that refused would be reasoning from EEPROM bytes nobody could have had before
delivery.

So the two gates consume different evidence and may never share a carrier.
Order admission takes a VENDOR CLAIM and refuses a purchase whose per-leg
coding is undeclared -- the loud failure the subject exists to produce, since a
part number does not determine a link contract and the EEPROM is
field-programmed. Receipt reconciliation takes an OBSERVATION and joins it
against the admitted claim; that is the gate that catches this class, an hour
after delivery rather than after installation. The second is what keeps the
first honest: a gate treating a claim as a reading would have greened here.

CableLegCodingEvidence makes the grade structural rather than a flag, following
the LandedCost split in product.inventory -- the arm IS the grade, so no path
can promote a claim to a reading by forgetting to check something.

ReceiptNotYetObserved is its own arm because SILENCE IS NOT AGREEMENT. A
delivered assembly nobody has read must not reconcile as matching; that is
exactly the state this fleet sat in while the fabric ran at half rate, and a
model scoring it clean would have certified the outage.

What the NIC requires is DECLARED BY THE FLEET, not derived from firmware. The
ConnectX-7 was observed refusing 100G_2X; that rule has never been read here,
and modelling an inferred algorithm as NVIDIA authority would turn a diagnosis
into an invented specification.

NOT VERIFIED: the seven claims in this witness have NOT been observed to
execute. Local --required-floor reports FloorClean with planned unchanged at
3525 and zero of them in the population -- the module compiles and resolves,
and something in floor discovery still does not offer it. A module-path fix
(gunbc/product/X.dag declares `product.X`, not `gunbc.product.X`) was necessary
but not sufficient. Reporting the gap rather than the green: a verdict whose
population excludes its subject is not evidence, and this branch has already
shipped one claim that no execution had ever checked.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01AigrH3JpxgSJBmqHMBAr6W
…specified ignorance

Three repairs to the merged substrate, all from external review against the
primary SFF tables.

BYTE 116 AT 00h MEANS "UNSPECIFIED", NOT "NO SECONDARY APPLICATION". The merged
profile_is_complete treated SecondaryObservedEmpty as completing the profile,
which licensed a verdict the bytes do not support -- the same defect as using an
UNREAD field as evidence of absence, arrived at from the other side. Two axes
were hiding inside that one boolean and are now separate: for 00h the field WAS
observed (required_fields_observed) while its interpretation is still not
exhaustive (interpretation_is_exhaustive). Collapsing them is what made the
defect recur one level down.

SELF-CONSISTENCY IS NOW A DIFFERENT FUNCTION FROM REQUESTED-MODE ASSESSMENT.
The merged assessor reached its contradiction branch only when the requested
mode was unattested, so whether a module was called self-contradictory depended
on what the reader asked for. sff8636_profile_consistency takes no requested
mode, so the law holds mechanically rather than by discipline.

AND THE CONTRADICTION ARM IS RETIRED, NOT KEPT UNREACHABLE. Deciding one
requires establishing that the encoding byte and the compliance codes describe
the SAME INTERFACE. SFF-8024 says encoding primarily concerns the HOST
interface while compliance codes concern the media application; those are one
signal only for an unretimed passive assembly, and disagree BY DESIGN in a
module converting NRZ host lanes to a PAM4 media channel (NVIDIA's MMS1V70-CM
presents four 25G NRZ host lanes and one 100G PAM4 optical channel, both true
at once). Nothing this decoder reads settles that scope: identifier 0x11 is
carried by optical modules as readily as by copper, and the field that would
settle it -- SFF-8636's transmitter-technology nibble -- has not been read here.
Authoring its code values from memory would be the fabricated citation this
subject exists to catch.

A result variant belongs in the operational codomain only if some valid input
can produce it under the stated evidence rules. So the concept survives as a
typed undecidable naming its cause -- unread field, unspecified field,
unmodelled code, or the standing interface-scope frontier -- and the next-rung
trigger is written down: read the transmitter-technology field, then reintroduce
the arm WITH a standards-supported positive fixture and its inverse control.

0x40 IS MODELLED WITH ITS PRIMARY CITATION (SFF-8024 Rev 4.14, Table 4-4, row
40h: 50GBASE-CR, 100GBASE-CR2, 200GBASE-CR4), which retires the placeholder
code 0 the first head used as a stand-in for a byte it had not read.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01AigrH3JpxgSJBmqHMBAr6W
…ding

The previous commit's rewrite added a constructor while the original survived
in a preserved section, and the compiler refused the whole floor rather than
letting the second silently replace the first: "duplicate declaration
'sff8636_leg_coding' -- a second declaration of one name silently replaced the
first". That is the single-authority rule enforced at the language level, and
the diagnostic names the HARM rather than only the fact.

It is also the fourth self-inflicted break in this lane from doing a structural
edit with text slicing, and every one was caught by execution rather than by
reading. The rule the lane keeps relearning: a change that feels mechanical --
removing a helper, splitting a function, renaming an arm -- earns the same
verification as a new feature, and a dirty tree verifies nothing because the
floor plans its changed set from COMMITTED state.

Floor now verdict=FloorClean, claims_failed=0, with all six changed cable
claims planned-and-passed: the delivered leg's consistency undecidable for want
of a reading, the inverse control holding an unspecified secondary undecidable,
the two completeness axes asserted separately, the fully-read profile
undecidable only for interface scope, and the cited 0x40 row attesting the mode
the primary does not.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01AigrH3JpxgSJBmqHMBAr6W
@gunbai-bot
gunbai-bot Bot marked this pull request as ready for review September 6, 2026 16:48
@gunbai-bot gunbai-bot Bot changed the title model QSFP cabling surprise Rehome the cable-leg observation out of the SFF specification, and retire the contradiction arm Sep 6, 2026
@gunbai-bot

gunbai-bot Bot commented Sep 6, 2026

Copy link
Copy Markdown
Contributor

All findings from review 61424 (codex) and review 61434 (claude-opus) are addressed at head dfbf638614. Verified against the current code rather than acknowledged.

codex finding 1 — observations authored inside the specification authority. Correct, and it is the DESIGN §3 rule verbatim. extdeps.transceiver.sff_8636 now owns byte meanings only; the observation carrier, coverage census, interpretation gaps, consistency assessment and the requested-mode join moved to product.cable_leg_observation. Whether anyone here pointed ethtool at a module is a fleet receipt, not something SFF-8636 says.

Worth recording: this lane raised the identical objection against another module's ..._observed row in extdeps a few hours before committing its own instance of it.

codex finding 2 — variant-to-Boolean predicate without disposition. Also correct. required_fields_observed is replaced by one census: cable_leg_unread_fields returns the unread fields, and every coverage question is asked of that list. A field that becomes optional later is a row in CableLegField rather than a new predicate at each call site.

claude-opus finding — missing ConsistencyInterpretationGap arm in consistency_cause_is_scope. Correct, and already fixed before that review landed: the compiler refused the floor with that exact non-exhaustive match two runs earlier. The review was reading head b285cf75, which predates the fix. Nothing to do beyond confirming it is present at the current head.

That is worth a sentence on its own, because it is the point the PR is about. A reviewer and a compiler independently found the same defect, and the compiler found it first, for free, and named the file and the missing variant. Every one of the substantive findings this branch has taken was a rule I stated correctly and then failed to propagate to the next field — layering, sentinel decoding, the encoding axis. The ones a closed coproduct was enforcing cost a minute each; the ones only a rule was enforcing needed a human.

Also fixed, and independent of the code: the PR title and body were the auto-open scaffold with a TODO summary. codex was right to refuse on that alone — a PR whose description does not say what it does or what was executed is not reviewable regardless of the diff. Both are now written.

Executed evidence, claim_executor --required-floor from a compiler built from this tree:

verdict=FloorClean   claims_failed=0
16 cable claims planned-and-passed

CI red on f3f6b19 was a stale intermediate commit — the three non-exhaustive matches, which my local floor had already reported on that same tree. dfbf638614 is the one-commit delta that fixes them.

— sent from fierce-deer-825

…dmit the four rehomed bindings

cursor/composer-2.5 (review 61439) found that `extdeps_model_scope` still names
`Sff8636LegCoding` — the observation carrier this branch moved to
`product.cable_leg_observation`. The declarations phase of required CI agrees:
CITED-DECLARATION-ABSENT, one finding, and it is the same symbol.

Repointed the scope subject at `ComplianceInterpretation`, a byte-meaning
declaration this module still declares, and deleted the orphaned annotation
above it: that prose describes the observation carrier and already lives beside
`SecondaryComplianceObservation` in the product module, so keeping a copy here
was a §4c annotation about a type no longer in the file.

The namespace wave-admission phase blocked on four `TargetChanged` bindings —
the fixture constructors that spell `SecondaryNotObserved`, whose declarer moved
between modules. Rostered with the layer-split reasoning and their own
dissolution trigger.

Touching that roster makes its consumed rows due, so the thirty gunbc#10639
rows are deleted here, adjudicated by the join they asked for rather than by
their sentence: 8769167 is an ancestor of this base and main declares
`SparkServingProbeCapture` in `gunbc.spark.training_ready`, so no run can
produce those deltas.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01AigrH3JpxgSJBmqHMBAr6W
@briansrls
briansrls merged commit 2857b3b into main Sep 6, 2026
4 checks passed
@briansrls
briansrls deleted the session/fierce-deer-825 branch September 6, 2026 19:02
gunbai-bot Bot pushed a commit that referenced this pull request Sep 9, 2026
…tion must carry

DESIGN section 3 rules that observations this repository produces are receipts in the observing
layer, and that missing observations are coverage obligations downstream, never Unobserved
properties authored inside an upstream module. The colo census does the opposite: DensityUnread,
RetailGrainUnread and AddressUnread live inside extdeps.colo.<operator>, ten files across five
lanes. The repository has already applied that rule once, in #10671, whose title is "Rehome the
cable-leg observation out of the SFF specification".

Escalated rather than fixed, because it is a carrier-design call spanning five lanes and predates
this lane's work. The ruling is to land the rows and follow with the shape - the rows are the
expensive part - and to write the frontier down with a trigger a reader can act on.

THE TRIGGER IS A SPLIT, NOT A MOVE, and that is the part worth recording. Each Unread arm fuses two
facts in one string: "no pricing published on the pages read 2026-08-18" is an OBSERVATION, and "a
written quote is required" is a COVERAGE OBLIGATION. Both are ours and both belong here, but a
quote arriving discharges the second while the first stays true forever - so fused in one sentence,
neither can be updated without rewriting the other. The destination must carry two typed fields,
not one relocated string. Upstream keeps the READ arms, which are genuinely facts about what the
operator publishes.

The annotation goes on this module because this is the destination, and a frontier that names the
motion without naming what the destination must carry is not actionable. It is deliberately
census-wide in one motion: one lane at a time would leave two shapes inside one carrier, which is
worse than one uniform wrong shape.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016jFtgPtXxTj1kE8wwZUNsG
briansrls added a commit that referenced this pull request Sep 10, 2026
…has no retail surface to read (#10864)

* Facility megawatts were never cabinet kilowatts: the third power fact

The census carried two power facts and neither answered the question a
deployment asks. A facility's marketed capacity - 80 MW at a carrier hotel,
25.6 MW at an enterprise campus - is a fact about a BUILDING, and reading it as
density is the same category error as reading a substation's rating as a
house's service. A RetailPlanRow's PowerAllocation is the right grain and
exists for exactly two operators in this metro, because almost nobody
publishes retail power.

Between them sits the fact operators DO publish: a marketed maximum per
cabinet. CabinetDensityClaim carries it, and carries the marketing wording
verbatim beside the numeral, because a marketed maximum is not a quote, not
currently available capacity and not a commitment. A candidate may be screened
IN on it and may never be screened as PRICED on it. RetailGrainStanding is the
separate question of whether the operator sells one cabinet at all - a campus
marketing 25 MW that takes only suite commitments is a different refusal from
an unread density.

WHAT THE FIRST TWO READS SHOW. Every priced plan in this census tops out at
2.5 kW across twenty rack units, which made colocation look physically
incapable of holding a 650 W-per-node fleet. It is not. Iron Mountain NJE-1
markets "high-density up to 30 kW/rack" with individual cabinets offered;
DataBank LGA4 markets "35kW+ air-cooled, 100kW+ liquid-cooled". Against a
650 W node those are 46 and 53 nodes of air-cooled headroom, where the densest
PRICED product modelled here holds three. The gap between what is marketed and
what is published for retail sale IS the finding - and it is a reason to get
quotes, not a reason to believe one will be affordable. Nothing here says what
35 kW costs.

THE UNREAD ARM EARNED ITS KEEP IMMEDIATELY. The review that prompted this work
asserted Iron Mountain advertises 20 kW cabinets in Pennsylvania. The page was
read and states no per-rack or per-cabinet density at all, so WPA-1 carries
DensityUnread naming the unconfirmed claim rather than the number. A density
nobody published must not enter the census because a secondary source said it
existed.

NEW YORK WAS NEVER REFUSED, IT WAS NEVER SURVEYED. The census stood at 23 New
Jersey facilities and 7 Pennsylvania ones with no New York site, and this
session had reported that absence as a consequence of the Equinix ruling. It
was not: the Equinix campus that ruling names is itself in Secaucus, New
Jersey. DataBank LGA4 Orangeburg is the first New York row.

Executed control: cabinet_density_air_kw over the three new claims returns
[35, 30, 0] - the two read claims yield their marketed figures and the unread
one yields zero, which callers must read through cabinet_density_is_read
rather than compare as a number.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01998xs4ojJKWGptxcuxVWHN

* Watt and VoltAmpere already existed; I re-invented both as a bare Int

TWO REVIEWS ARRIVED AT THIS FROM OPPOSITE ENDS AND MET ON ONE DEFECT.

A census lane reading Telehouse Chelsea - "standard power to rack at 3.5kVA
with scalable options to 5kVA" - had no correct arm for an apparent-power
publication, so they put 5 in a field named air_cooled_kw and documented the
mismatch in the citation. The documentation was right and the FIELD was wrong:
a note cannot stop a consumer reading a number out of a field named for the
quantity it is not. Independently, review 62722 observed that a unit baked into
a field name is a second representation of a fact std.measure already owns, and
that THIS FILE ALREADY IMPORTS Watt for PowerAllocation - so the census was
answering "how much power" two ways at once.

Both objections have one repair, and the corpus had already made the
distinction structurally: Watt is Measure<Power, One, Nat>, VoltAmpere is
Measure<ApparentPower, One, Nat>, carried on SEPARATE dimensions with a note in
std.measure saying that putting both on Power would conflate them. So neither
half of this was a new concept. I minted a worse version of two that existed,
which is exactly the re-invention DESIGN section 2 names.

WHY THE APPARENT/REAL DISTINCTION IS LOAD-BEARING. kW = kVA x power factor with
PF <= 1, so kW <= kVA always, and reading a kVA publication as kilowatts
OVERSTATES real capacity - it fails in the flattering direction, which here
means putting more nodes in a cabinet than its breaker will carry. Colocation
quotes state kVA precisely because the facility sizes to apparent power, so
this is the common case and not an edge one.

THE ZERO IS GONE TOO, and review 62722 was right that the predicate beside it
was the tell. cabinet_density_air_kw returned 0 for an unread claim - a
fabricated in-band answer on the same axis as real readings, defended only by a
comment telling callers to consult cabinet_density_is_read first, which is the
validation-standing-where-construction-was-available shape section 5 warns
about. The reading is now Watt? and the predicate is DELETED rather than
documented around: the confusable zero is unconstructible.

Absent has two causes with one consequence: nobody published a figure, or
somebody published apparent power and no power factor exists to convert it.
Either way there is no established watt reading and an admission decision that
needs one must refuse. The upper bound is a separate, weaker function - sound
for REJECTING a cabinet too small even at the bound, never for admitting one -
and it is the only place ApparentPower crosses to Power, justified by the
inequality and by nothing else.

Also rosters dag/extdeps/colo/databank.dag in scope_carrier_paths; keen-newt-324
found the placement gate refuses it as a new unrostered extdeps file.

Executed controls, one dispatch, established vs upper bound over four claims:
                              established      upper bound
  DataBank LGA4 (35 kW)         35000 W          35000 W
  Iron Mountain NJE-1 (30 kW)   30000 W                -
  Telehouse Chelsea (5 kVA)      ABSENT           5000 W   the whole point
  Iron Mountain WPA-1 (unread)   ABSENT           ABSENT

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01998xs4ojJKWGptxcuxVWHN

* The controls only existed in a probe I deleted: enroll them

Review 62722's third finding, and it is the one I had already flagged about my
own work two turns earlier without acting on it. The carrier landed a type, two
functions and six data rows that NOTHING read: grep for cabinet_density,
CabinetDensityClaim, RetailGrainStanding or databank outside those three files
returned empty, and no module outside dag/extdeps/colo imports the colo
namespace at all. The PR body cited an executed control, but that control lived
in a scratch probe the author ran and then deleted.

A deleted probe is not evidence a wall stays standing. DESIGN section 3c is
explicit that a declaration nobody consumes is red regardless of how well it is
modelled, and section 5 that a run nobody can repeat is not a consumer. Being
able to name the failure did not make it not a failure.

Five enrolled witnesses, with the discriminating case first among equals:
  w_published_kilowatts_establish_real_power        positive control
  w_apparent_power_establishes_no_real_power        THE DISCRIMINATING RED
  w_apparent_power_still_bounds_real_power_above    kW <= kVA, so the bound holds
  w_unread_density_establishes_and_bounds_nothing   the zero stays unconstructible
  w_density_and_grain_are_separate_facts            the two axes stay independent

The apparent-power fixture reproduces the Telehouse Chelsea publication shape
that found the defect. It lives in the witness rather than an operator module
because it is evidence about the CARRIER, not a census row; the live Telehouse
rows belong to whichever lane reads that operator.

MUTATION CONTROL, executed. Restoring the defect - making
cabinet_power_established return the volt-ampere count as watts, which is
exactly the conflation the carrier was rewritten to prevent - flips
w_apparent_power_establishes_no_real_power from true to false while the other
four stay true:
  clean    [true, true,  true, true, true]
  mutated  [true, FALSE, true, true, true]
So the red is discriminating rather than decorative, and it names the single
behaviour it guards.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01998xs4ojJKWGptxcuxVWHN

* A surveyed-empty region and an unsurveyed one rendered identically

Two census lanes reached this need independently within the hour. Southern New
Jersey - seven counties - yielded zero facility rows, and the Hudson Valley
proper - four counties - yielded zero retail colocation. Both lanes wanted to
record that as a RESULT, neither had anywhere to put it, and both wrote it into
a pull-request body where the next reader will never find it.

The defect is that a census with no row for Cape May County looks exactly the
same whether somebody read every operator page in it and found nothing, or
whether nobody has ever looked. The first is expensive knowledge worth keeping;
the second is an open obligation. Collapsing them means the expensive half gets
re-derived by the next lane and the open half is mistaken for settled.

THIS CENSUS HAS ALREADY MADE THE SECOND ERROR ONCE. The absence of any New York
row was reported - by me, twice - as a consequence of the Equinix refused-
channel ruling. It was not: that campus is itself in Secaucus, New Jersey. New
York was never refused, it was never surveyed, and nothing in the substrate
could have said so.

RegionSurveyOutcome makes the two arms distinct. SurveyedNoRetailOperator
carries the counties searched, the causes, and who searched when - the searched
list is what makes it a measurement rather than an assertion, because a later
reader can judge the coverage instead of taking "empty" on trust.
RegionUnsurveyed is the only arm carrying an open obligation.
coverage_facility_count is Optional for the same reason: a surveyed-empty
region answers zero and an unsurveyed one answers nothing, and a plain Int
would let both produce the same number.

EmptyRegionCause is separate because regions are empty in ways that oblige
different follow-ups: aggregators-only, resellers without a facility, operators
present but not selling retail colocation, or a directory claim the operator's
own pages contradict. Southern New Jersey carries the last of those with two
receipts - TierPoint is directory-cited in New Jersey and its own location
pages carry no New Jersey site, and Agile Data Sites is directory-cited for
Monmouth Junction and now redirects to a company listing Silver Spring and
Aurora.

It lives under gunbc rather than extdeps because it is OURS. DESIGN section 3:
observations this repository produces are receipts in the observing layer,
never properties of the observed.

The roster is incomplete by construction and says so: it carries what a lane
surveyed and found empty, not a RegionUnsurveyed row for everything nobody has
looked at. That roster is worth writing only once the census's geographic scope
is decided, since its length would otherwise be an artefact of where the author
stopped typing.

Executed control: coverage_facility_count over the two rows returns [0, 0] as
Present, where an unsurveyed region returns Absent.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01998xs4ojJKWGptxcuxVWHN

* Both my own claim_wordings were the fetch tool's prose, not the operator's

silent-heron-303 found that a summarizing fetch tool's output had been passed
along as quotation in claim_wording, and asked whether to push the finding
fleet-wide. I checked my own two rows first, with raw curl, and both failed -
differently, and the second worse than the first.

DataBank LGA4: the FIGURES are real and the WORDING was invented. The page
carries three separate spec-table cells - "N+1 Cooling Design", "35kW+ Cab
Density Air", "100kW+ Cab Density Liq" - and my row fused them into "35kW+
air-cooled, 100kW+ liquid-cooled", a sentence that appears nowhere on it. Same
shape as their DataBank EWR1 case, found independently on a different facility.
Corrected to the literal cells, and the operator's own word turns out to be AIR,
which confirms the air-only reading rather than leaving it inferred.

Iron Mountain NJE-1 is worse, because it cannot be checked at all. The raw
fetch returns HTTP 429 behind a Vercel Security Checkpoint - 32 KB of
interstitial, no facility content - so "high-density up to 30 kW/rack" has ONE
source and that source is a tool known to paraphrase. The figure is retained
because a summarizing read is still a read and dropping it would lose a real
observation; the citation now says the wording is UNVERIFIED AS PAGE TEXT and
records the block, because recording the block IS the reading and silence would
otherwise be mistaken for absence.

WHY THIS IS THE DENSITY RULE ONE FIELD OVER. claim_wording exists so a later
reader can re-derive the number from the operator's own words. A paraphrase
there is not a weaker citation - it is a FABRICATED one that reads exactly like
a real one, which is precisely what the census forbids for the density figure
itself. I wrote the rule for the numeral and then broke it in the field beside
it, in the worked example the other four lanes were told to copy.

The census's flagship dense-cabinet claim is now: one operator confirmed
verbatim at 35 kW, and one at 30 kW whose wording no one has been able to
reproduce.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01998xs4ojJKWGptxcuxVWHN

* The coverage module did not compile, and nothing noticed because nothing read it

Three defects on one module, and they share a cause: it was landed with no consumer, so neither
the compiler nor a reviewer nor CI was ever pointed at it.

IT DID NOT PARSE. Five section 4c errors - the per-arm rationales were written BETWEEN the arms of
RegionSurveyOutcome, and only module-item grain is captured, so an indented comment inside a
declaration body is a blocking error rather than preserved prose. bright-swift-678 found them
while trying to import the module. Hoisted above the type with their content intact. Control run:
replanting ONE of the five annotations takes the closure from 0 blocking errors to 1, so the
repair is established by execution rather than by the diff looking right.

IT HAD NO CONSUMER. Review 62758 (section 3c): a type, two accessors and three rows nothing
imports, with the commit citing an "executed control" that lived in a deleted scratch probe. This
is the identical finding review 62722 made about the density carrier ONE COMMIT EARLIER in this
same PR - the first fix was applied to the instance and not to the habit. Three witnesses enrolled
in the carrier's existing witness module, green by execution.

AND WRITING THEM ESTABLISHED THE THIRD, WHICH IS THE ONE WORTH KEEPING. RegionUnsurveyed HAS NO
INHABITANT in the live roster - all three rows are surveyed - so the distinction the module exists
to draw could not be discriminated by any test over the census as it stands. The first witness
returned FALSE on its first run for exactly that reason. Per section 4b, where the forbidden state
is unauthorable on the live corpus, the fixture is where the RED becomes expressible; declining to
write one leaves a wall permanently green by construction. So the arm now has a fixture, and a
second witness holds the same distinction on a real row: the Hudson Valley yielded no retail
colocation and answers ZERO while reporting itself surveyed, which is the case a reader is most
tempted to misread as nobody having looked.

The counts are asserted as a RELATION, not as literals - read densities never exceed the
facilities they were read from, both non-negative - because a witness repeating a hand-authored
number it cannot re-derive proves only that the file was not edited. It reds on a transposed pair,
which is the plausible way 28 and 1 get written wrongly.

Also carries the NJ Hudson-Bergen-Essex corridor row, 28 facilities and 1 verified density,
handed over by silent-heron-303 rather than written by them to keep two lanes off one roster. The
count is one AFTER an audit: a Summit Secaucus row citing 12 kW reproduced in the page bytes
exactly and sat under a banner reading "Limited Time: Chicago-Area Facility". Real figure,
published price, wrong metro.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01998xs4ojJKWGptxcuxVWHN

* A predicate deleted once, rewritten one module later; and a relation too weak to see the error

Review 62776, both findings, and the first is the more damning because this PR had already fixed
it. `coverage_is_surveyed` returned a Bool by arm, and surveyed IFF the count is Present - so it
was a second representation of a constraint `coverage_facility_count` already carries, which is
DESIGN section 5's check restating what the model holds. The same PR deleted `cabinet_density_is_read`
from the density carrier for exactly that reason. Writing the predicate again one module later is
the third time in this PR that a fix landed on an instance and the next commit reproduced the
class. The deletion and its reason are now an annotation on the surviving function, so the next
author sees why there is no predicate rather than adding one back.

The witnesses discriminate on Present/Absent through the existing sentinel fold, no second
predicate consulted. Removing the Bool collapsed an overlap the review did not mention -
`w_a_surveyed_empty_region_is_not_an_unsurveyed_one` had become a strict subset of its sibling - so
the two are re-split: the fixture case in one, the live Hudson Valley row in the other, which is
what keeps the fixture from being the only evidence for that arm.

`coverage_growth_note` converted to a `//` block on `census_regions`, section 4c. silent-heron-303
made the identical fix downstream after review 62772 and these are their bytes, so the two do not
diverge and the carrier is correct standalone. Their detail is the one worth keeping: deleting the
row and leaving the prose where it sat is a PARSE REFUSAL, because the initial .dag realization
admits only standalone LEADING blocks attached to a module-scope declaration, and that row sat at
end of file.

AND THE CORRIDOR COUNT WAS WRONG. 28 became 27: seventeen pre-existing rows were added as eighteen,
found by silent-heron-303 when review 62780 made them derive the number instead of transcribing it.
The uncomfortable part is mine. My witness asserts read densities never exceed facilities, and
1 <= 28 is exactly as true as 1 <= 27, so it sat GREEN BESIDE THE ERROR for as long as the error
existed. Choosing a relation over a literal was right - a witness repeating a hand-authored number
proves only that the file was not edited - and the relation I chose could not discriminate. The
answer is neither: it is derivation, which is landing separately as the two Ints become the
facility and claim rows they count. Both the row and the witness now say so rather than leaving the
next reader to infer that a green relation meant a right number.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01998xs4ojJKWGptxcuxVWHN

* wip: central/south NJ colo rows

* Central New Jersey answers the density question; southern New Jersey has no retail surface to read

Eight facility rows for central and southern New Jersey, five of them new to the census, each
carrying the two facts the carrier was built for. Three densities are READ. Three refuse. The
refusals are the point.

WHAT WAS READ. NJFX Wall Township markets "power densities ranging from 2 kW to 16 kW per
cabinet" - the only cable landing campus in the census and the second-densest marketed cabinet
behind DataBank LGA4. Digital Fortress Piscataway states "15kW per cabinet available without any
significant redesign", on 1.8 MW of UPS plant: the smallest facility in the roster and one of the
best-answered, because it publishes a per-cabinet figure AND says it sells one cabinet. DataBank
EWR2 Piscataway markets "10kW+".

WHAT REFUSED, AND WHY THAT IS THE FINDING. QTS Piscataway publishes 65 MW+ of critical power -
the largest capacity anywhere in this census - and not one kilowatt per cabinet. Digital Realty
EWR11 and EWR12 publish 207,500 and 323,000 square feet and no density either. Those three are
the exact shape the carrier exists to refuse, and a witness control now reds if any later edit
derives a cabinet figure from a building total.

THE EIGHTY-FIVE-KILOWATT CLAIM WAS OFF BY A FACTOR OF EIGHT. databank.dag carried an obligation to
find the Piscataway campus after its URLs 404ed, and a secondary source had cited an 85 kW-per-
cabinet university HPC deployment there. The live page is
databank.com/data-centers/new-jersey/piscataway/ and it markets 10kW+. The obligation is
discharged with the page's number, not the review's, and replaced by a fresh one: DataBank also
sells a suite at 165 Halsey Street, which this census carries as a building with no DataBank row.

GRAIN DOES NOT PROPAGATE ACROSS A CAMPUS. EWR12 publishes "From single cabinets to full suites";
its campus sibling EWR11, same operator, same township, publishes no minimum at all. They carry
different grain standings and a control reds if a future edit unifies them. NJFX is the converse
case the census had not yet seen: density established, grain unread - a published per-cabinet band
says the campus can power a dense cabinet and says nothing about whether it will sell exactly one.

SOUTHERN NEW JERSEY CONTRIBUTES ZERO ROWS, AND THAT IS A MEASUREMENT, NOT AN OMISSION. Burlington,
Camden, Gloucester, Atlantic, Cumberland, Salem and Cape May counties were searched on 2026-09-08
for retail colocation operators. Every hit resolved to one of three things that are not a facility
row: a directory aggregator, a managed-service reseller with no facility of its own, or a
lead-generation page. TierPoint has no New Jersey site on its own location pages despite directory
claims. Agile Data Sites, cited by directories for a Monmouth Junction facility, now redirects to
databridgesites.com, whose own site lists Silver Spring and Aurora and no New Jersey location at
all. I did not manufacture rows from the directories, so the southern half of the state is
recorded here as unsurveyable from public operator surfaces rather than as surveyed-and-empty.

CONSUMER. dag/test/claim/colo_nj_central_south_census_test.dag reads every row added here through
the carrier's own accessors - not assertions that the rows exist. Five witnesses PASS by execution
(claim_batch). Two discriminating REDs were run in an isolated worktree: changing NJFX's 16 kW to
30 kW reds the density controls, and replacing the QTS refusal with a density derived from its
65 MW reds the megawatts-are-not-watts control.

COUNTS: 8 facilities modelled in region, 3 with a density I could actually READ.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016jFtgPtXxTj1kE8wwZUNsG

* Three prose rows become annotations; three read wordings verified against raw bytes

REVIEW 62744, ACCEPTED IN FULL. Three NonEmptyStr rows whose entire content was a prose to-do -
databank_newark_obligation, digital_realty_ewr19_obligation, njfx_tata_adjacency_obligation - are
now // annotations above the declarations they concern. DESIGN section 4c is explicit that an
ordinary String declaration whose sole purpose is commentary is misplaced data, and section 3c
that nothing consumed those three rows. I took the annotation arm rather than minting an
UnmodelledFacility carrier: three to-dos do not justify a new type, and a type consumed only by a
witness written to consume it is the ceremony section 6 warns about. No fact is lost; each note now
sits above the row it qualifies.

RAW-BYTE VERIFICATION OF EVERY READ WORDING, BOTH CLAUSES. Three read rows, three fetches to file,
each claim_wording grepped literally and each figure's nearest heading in byte order read as its
scope.

  NJFX 16 kW          VERBATIM. Under "High-Density Power" on a single-campus Wall Township page.
  Digital Fortress    VERBATIM. A bullet in the Reliability block under the page's own h1
  15 kW               "Piscataway, New Jersey Data Center", in the same list as the 1.8 MW UPS
                      figure. This operator runs Seattle and Chicago sites and names them on this
                      page; every such mention is navigation above or below the block, never in it.
  DataBank EWR2       CORRECTED. The row carried "10kW+" and the page's cell is "10kW+ Cab Density
  10 kW               Air" - a truncation of the operator's own cell, the same spec-strip family
                      found four times already on this operator. The operator's word AIR now
                      SELECTS the air-only arm instead of it being inferred from a missing liquid
                      figure. Figure unchanged; scope confirmed under the EWR2 hero and beside
                      "3MW Critical IT Load".

The figures all survived and one wording did not, which is the split every lane has reported.

THE UGREP COMPLEXITY REFUSAL REPRODUCES HERE, on all three pages. The prescribed
'.{0,90}kW.{0,90}' window prints "exceeds complexity limits" to stderr and nothing to stdout, so
inside a pipeline it is indistinguishable from the string being absent. The instrument fails toward
the value that means a finding. Literal greps against a saved file were used throughout instead.

CORRECTION TAKEN ON THE 85 kW CLAIM. My earlier annotation said the secondary source was "off by a
factor of eight". It was not wrong, it described a different quantity: an 85 kW tailored deployment
for one named tenant is not a marketed cabinet maximum, and both can be true of one building.
Reading the first as the second is the same category error as reading facility megawatts as cabinet
density. The annotation now says that, because "the source was wrong" and "the source described
another quantity" oblige different follow-ups.

COVERAGE MODULE. gunbc.colo_census_coverage gains its first non-empty row - Central New Jersey,
FacilitiesModelled 8 facilities and 4 read densities. The counts are regional, not per-lane: this
lane read three and the fourth is Iron Mountain NJE-1, which the carrier landed. The module also
had five DESIGN section 4c parse errors - annotations indented between the arms of
RegionSurveyOutcome, where only module-item grain is modelled - which reddened compilation for
anything importing it. They are hoisted above the type, intact.

CONSUMER. The witness now reads the coverage module too, and it does NOT re-assert the hand-authored
counts: a witness repeating a literal it cannot re-derive proves only that the file was not edited.
It asserts the relation - read densities never exceed facilities, both positive - which reds on a
transposed pair, and the distinction the module exists for: a surveyed-empty region answers zero
while an unsurveyed one answers nothing. Seven witnesses PASS by execution.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016jFtgPtXxTj1kE8wwZUNsG

* Element boundaries recorded: all three read wordings are single authored elements

The third verification clause asks two questions of two artefacts - the wording against tag-stripped
text, ownership against the markup - because either alone answers confidently and wrongly in a
different direction. Both are now run for every read row in this lane and the element boundary is
recorded in the citation beside the sentence.

  NJFX 16 kW          One contiguous <p> immediately after <h3>High-Density Power</h3>.
  Digital Fortress    One complete <li> element.
  DataBank EWR2       One <li> whose numeral is emphasized: <strong>10kW+</strong> Cab Density Air.

The DataBank row is why the clause exists. Its wording carries no contiguous byte run in the raw
markup at all, because the numeral is bold - so a raw-byte grep would have WITHDRAWN a true row,
and a tag-stripped grep alone would have been unable to tell an authored cell from two cells joined
by a reader. One element means authored. This operator's template has produced both failures now:
sibling facilities fused two adjacent cells into an invented comma'd sentence, and this row was the
same cell truncated at its emphasis boundary.

A positive control ran in the same pass for each page - a string the page certainly contains - so an
empty wording match would have meant absence rather than a failed fetch. Every failure arm seen in
this verification effort returns empty or clean, which reads as the reassuring answer.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016jFtgPtXxTj1kE8wwZUNsG

* Four read densities is not four verified ones

The Central New Jersey coverage row counts four read densities and the count cannot say that one of
them is unreproducible. Three were confirmed against the operators' raw bytes at markup grain -
each a single authored element under a heading that scopes it to the facility. The fourth, Iron
Mountain NJE-1, sits behind a security interstitial that serves an interstitial document in place of
the page, so its figure has one summarizing source and nobody has reproduced it.

RegionSurveyOutcome has no field for that distinction and this row is not a reason to mint one: a
field added for a single member is a carrier shaped by its first instance rather than by the
concept. The annotation says it instead, where a reader of the count finds it.

The distinction matters in the direction that costs something. Verbatim verification has REDUCED
the census's readable densities rather than growing them, and every withdrawal so far was a row
that had passed a plausibility read - so a count is now an upper bound on what is reproducible, and
saying four without saying three-of-four would be the same overstatement in miniature.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016jFtgPtXxTj1kE8wwZUNsG

* Roster property replaces roster length; duplicate coverage witnesses dissolve

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016jFtgPtXxTj1kE8wwZUNsG

* The eighth central-NJ facility had a count and a coverage row and no density fact

An approval is not evidence that the change did what was asked, so I re-read the brief against the
diff. It said model EVERY facility in the region with a cited density and a retail grain, and one
was missing: 365 NJ1 Bridgewater, in Somerset County, carried by the census since 2026-08-18 with
neither fact. I had counted it in this region's eight and left it the only one of the eight with
nothing on either axis - a coverage row that says four of eight, over a facility nobody had asked
the question of.

BOTH AXES REFUSE, ON TWO OPERATOR SURFACES. The New Jersey facility page and the operator's own
Bridgewater cutsheet PDF were read 2026-09-09 and neither carries a kilowatt figure of any kind:
the strings kW, kVA and density do not occur in either. What the page publishes instead is exactly
the pair operators offer in place of density - voltages (120V, 208V, 208V three-phase) and cooling
tonnage - and neither is one.

A CABINET INVENTORY IS NOT A RETAIL GRAIN. The wording, identical on both surfaces, is "Nearly 300
combination-locking cabinets, custom cages and suites". That says the building CONTAINS cabinets,
not that the operator sells one, and reading it as an offer is the grain axis's version of reading
megawatts as density - a fact about the building promoted to a fact about the product. It is
RetailGrainUnread with the wording recorded, and a new control reds if that line is ever promoted
to a single-cabinet offer without an operator statement saying so.

The address citation improves on the way past: the row cited a directory profile for 999 Frontier
Rd and the operator states that street itself, so the citation is now the operator's.

This does not change the region's headline - the density was never readable, so central New Jersey
remains eight facilities and four read densities. What changes is that the fourth-of-eight is now a
measured refusal rather than an unasked question, which is the difference the whole carrier exists
to hold.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016jFtgPtXxTj1kE8wwZUNsG

* Name the frontier where its destination is, and name what the destination must carry

DESIGN section 3 rules that observations this repository produces are receipts in the observing
layer, and that missing observations are coverage obligations downstream, never Unobserved
properties authored inside an upstream module. The colo census does the opposite: DensityUnread,
RetailGrainUnread and AddressUnread live inside extdeps.colo.<operator>, ten files across five
lanes. The repository has already applied that rule once, in #10671, whose title is "Rehome the
cable-leg observation out of the SFF specification".

Escalated rather than fixed, because it is a carrier-design call spanning five lanes and predates
this lane's work. The ruling is to land the rows and follow with the shape - the rows are the
expensive part - and to write the frontier down with a trigger a reader can act on.

THE TRIGGER IS A SPLIT, NOT A MOVE, and that is the part worth recording. Each Unread arm fuses two
facts in one string: "no pricing published on the pages read 2026-08-18" is an OBSERVATION, and "a
written quote is required" is a COVERAGE OBLIGATION. Both are ours and both belong here, but a
quote arriving discharges the second while the first stays true forever - so fused in one sentence,
neither can be updated without rewriting the other. The destination must carry two typed fields,
not one relocated string. Upstream keeps the READ arms, which are genuinely facts about what the
operator publishes.

The annotation goes on this module because this is the destination, and a frontier that names the
motion without naming what the destination must carry is not actionable. It is deliberately
census-wide in one motion: one lane at a time would leave two shapes inside one carrier, which is
worse than one uniform wrong shape.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016jFtgPtXxTj1kE8wwZUNsG

* Every fetch in this lane used the user-agent that manufactures 403s; re-tested, and one byte count withdrawn

A short "Mozilla/5.0" was found to be the ONE input that turns a working request into a 403 on hosts
that answer 200 to both no user-agent and a full browser string. Every fetch in this lane used it,
so every reading here was taken with the instrument now known to be capable of fabricating an
operator refusal. All five URLs were re-tested across all three inputs.

NONE OF THEM IS SENSITIVE. njfx, databank and both 404s return identical status and identical byte
counts under all three; digital-fortress returns 200 under all three. The three read wordings occur
in every capture. No row changes, and the readings stand - but they stand because they were re-tested,
not because they were taken carefully the first time.

ONE BYTE COUNT IS WITHDRAWN RATHER THAN CORRECTED. The Digital Fortress citation stated 481600 bytes
as evidence. Successive fetches of that page return 481228, 481204 and 481602 - it drifts between
requests, so a size there is a reading of one request and not an identity for the document, and
citing one is citing a number nobody can reproduce. The count is gone and the reason is recorded in
its place. The other two are stable across every input and keep theirs.

BOTH OBSTACLE CLAIMS SURVIVE THE RE-TEST and now say so. The Digital Fortress index and Digital
Realty EWR19 are 404 with no user-agent and with a full one, so those are the pages' own answers. The
index's 439 KB is a "Page not found" body of site chrome, which corroborates one thing worth keeping:
the operator's own navigation labels the site New Jersey (PNJ), matching the facility label used here.

AND A STALE SYMBOL CITATION, found while editing that annotation: the EWR11 facility note pointed at
digital_realty_ewr19_obligation, a declaration deleted two commits ago when that prose became an
annotation. DESIGN section 3 requires citing a symbol that resolves; this one had stopped resolving
and nothing caught it, because a name inside a string is invisible to the compiler.

THE FRONTIER ANNOTATION IS CORRECTED ON TWO POINTS. It carried a file-and-lane count that was this
lane's own estimate written down as a measurement - the transcribed-number move - and it is replaced
by the instruction to re-derive the population over the merged corpus. And it named the destination
as a new observation-plus-obligation pair, which would have minted a third answer to a question
std.citation already owns: CitationRetrievalObservation, with HttpAccessRefused carrying the status,
is where the split points.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016jFtgPtXxTj1kE8wwZUNsG

* Every absence claim recounted in raw bytes, and one of them was never a zero

Four rows in this lane assert that an operator publishes no cabinet density. All four were made
through a tag-stripper or a summarizing fetch - the instrument since found to swallow 21 of 22
occurrences of a token and report the miss as a finding. All four are recounted in RAW BYTES, under
both a bare fetch and a full browser user-agent, with positive controls on SUBJECT tokens rather
than site tokens.

DIGITAL REALTY EWR11 AND EWR12 WERE NEVER ZEROS. kW occurs exactly once on each page. It is
field_sum_utility_power_capacity, value "392.8k+ kW", in embedded JSON carrying the operator's GLOBAL
portfolio totals beside a global 3782.9k square feet - the identical value on both campus pages, so
it is not a density and not even this facility's capacity. The rows are unchanged and better
evidenced: they now say which kW occurrence they EXCLUDED and why, which is a stronger claim than an
absence. A rule of the form "kW occurs, therefore a density is published" would have read a
company-wide figure as a cabinet figure - the census's own error in its purest form.

365 BRIDGEWATER'S PDF CONTROL HAD ACTUALLY FAILED, AND I EXPLAINED IT AWAY. The first check of the
cutsheet reported a failing positive control and proceeded on the assumption that PDF kerning split
the word. That was the right guess and it was still a guess: a control that comes back negative is
an unknown result, not a confirmation. Re-run with the text layer flattened of whitespace, the
controls pass strongly - Bridgewater=5, cabinets=2 - and the zeros hold. The row now records that
the first control failed, because a reader deciding whether to trust this zero should know the
instrument needed two attempts.

QTS holds at kW=0 across 308,417 bytes with Piscataway=19 and '65 MW'=1 as subject controls - the
megawatt figure present exactly where the kilowatt one is not, which is the whole point of the row.

WHY THE CONTROLS ARE NAMED AS SUBJECT TOKENS IN EVERY ROW: an operator's name occurring often proves
the fetch reached the operator's site, not that it reached the surface where a density would live.
Bridgewater, Piscataway, EWR11, EWR12 and Randolphville are the facilities themselves. A zero on a
page that does not name the facility is a fact about an index.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016jFtgPtXxTj1kE8wwZUNsG

* Four helpers had two authorities; and two rows inferred air cooling from silence

REVIEW 62875, ACCEPTED. established_watts, ceiling_refuses_at, has_ceiling and
grain_admits_single_cabinet existed verbatim in two witness modules - same signatures, same bodies,
same sentinel convention. They now live once, in test.claim.colo_census_witness_support, which both
witnesses import.

The drift risk the review names is the reason this is not cosmetic: review 62791 had already
re-shaped ceiling_refuses_at once, and with two copies the next such fix repairs one wall while the
other keeps the old semantics. The convention that must not fork is the one in the false arm - not
refused means UNDETERMINED, never admitted - which is exactly the kind of meaning that survives a
copy-paste and dies in a partial edit.

They live in a support module rather than on extdeps.colo.types because they are not carrier
operations. They flatten Optionals to a sentinel Int so a witness can compare, which is a
convenience for assertions and would be a defect in the carrier: the carrier deliberately returns
Watt? and CabinetPowerCeiling? so absence is unconstructible as a number, and this module is the one
place that trade is made.

AND A DEFECT IN THIS LANE'S OWN ROWS, flagged against the census and true here: NJFX and Digital
Fortress both inhabit DensityMarketedAirOnly for a figure whose page names NO cooling medium at all.
The absence of a liquid claim does not establish air-cooled capability - it is the same
absence-is-not-evidence move this census refuses everywhere else, made by rows that spent four
commits enforcing it elsewhere.

It is not fixable in the row: the carrier offers air-only or air-plus-liquid and has no arm for a
figure whose medium was never published, so some arm must be inhabited. What the row CAN do is stop
presenting the inference as a reading, and both citations now say the medium is UNREAD and that the
arm is a carrier gap. The fix belongs to the carrier, which needs the third arm.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016jFtgPtXxTj1kE8wwZUNsG

* File the class: a carrier with an unread arm on one axis and none on its neighbour

Review 62888 is right on the substance and right about why the previous commit was not a fix. Two
rows inhabit DensityMarketedAirOnly for figures whose pages name no cooling medium, and naming that
in the citation strings moved the honesty into prose - which DESIGN section 4c says is never evidence
a machine claim holds, and a citation String is weaker still because it is program data no fold
interprets. Nothing downstream can tell those rows from DataBank EWR2, whose air arm is selected by
the operator's own printed word AIR. The witness then consumes the inference as a green claim about
air-cooled established watts, so a prose caveat and a passing witness disagree and only one of them
runs.

THE REVIEW'S PREFERRED FIX IS RULED OUT FOR THIS PR, NOT DECLINED. A medium arm on
extdeps.colo.types is a one-arm edit and it is the right end state. The operator ruled on 2026-09-09
that it is the NEXT PR on that carrier rather than part of this one: #10885 is approved and carries a
merge-order constraint against #10865, and a quantifier migration that also changes what a row
asserts about cooling is two migrations sharing a diff no reviewer can separate. Editing that file
here would collide with an approved PR against a standing ruling.

SO THE CLASS IS FILED, which is the instrument DESIGN actually names for this - a review finding is
one of the four things that files a row under gunbc/recurring_failure_mode, carrying invalid state,
harm, rung found at, ceiling with reason, and next-rung trigger. It is a failure-mode row rather than
a section 4b(3) rung drop because nothing was LOWERED: the medium axis never had a rung to lose. It
is a class discovered below its ceiling, which is the no-untracked-stall obligation, not the
no-silent-regression one.

WHAT THE ROW SAYS THAT THE PROSE COULD NOT. The carrier gets its PRIMARY axis exactly right - an
unpublished figure is DensityUnread - and offers no such arm on the medium, so an author with a
silent source is COMPELLED to assert one. That is the generalisable shape: for each axis a carrier's
arms decide, ask whether a silent source has an arm, and read a row explaining in prose why its arm
is not really a reading as the tell that one does not. The correctness of the primary axis is what
makes the secondary one invisible, because the author has already been careful once and the type
accepted it.

Ceiling derived as structurally impossible rather than asserted: whether a source named a medium is
decidable from the capture the row already cites, and the invalid state has no constructor once the
medium is its own axis with an unstated arm - one more arm on a coproduct that already has the right
shape one axis over. The trigger names the capability and states what it must be SUFFICIENT FOR, and
explicitly refuses a medium_note String beside the arm as a discharge, because the two would stay
independently writable.

Population is four rows across two sessions: this lane's njfx_wall_density and
digital_fortress_piscataway_density, and two more found the same day in another lane.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016jFtgPtXxTj1kE8wwZUNsG

* Ten refused bindings: the deduplication was right and the direction was wrong

CI was red on namespace-wave-admission with ten unadjudicated deltas, every one a TargetChanged
binding inside test.claim.colo_cabinet_density_witness. Consolidating the four shared witness helpers
into a new support module satisfied the duplication finding by moving the declarations OUT of the
module whose call sites were already bound to them, so ten spellings that had resolved locally now
resolved through an import. The wall's question is not whether the new binding is correct - it is
whether a spelling changed WHICH DECLARATION IT ADMITS, and ten had.

THE DEDUPLICATION FINDING IS SATISFIED EITHER WAY, because what it requires is that ONE module
declares them. The helpers therefore stay in the witness that already declared them and this lane's
witness imports them, which is the same single authority reached without rebinding anything. Nothing
about the review's argument changes: the convention that must not fork, not refused means
UNDETERMINED rather than admitted, still lives in exactly one place.

Between two correct shapes the cheaper one wins, and the wall is what priced them. A support module
would have been defensible on its own terms and cost ten admissions that buy nothing; importing from
the existing home costs none. The new module is deleted rather than kept beside the imports.

VERIFIED BY RE-RUNNING THE PHASE, not by reasoning about it: claim_executor --required-ci
--required-lane witnesses over this tree reports ADMITTED - every delta auto-admitted or named -
against ten unadjudicated on the previous head. The only delta remaining is the failure-mode roster
gaining its new class, which is ExplicitlyEvaluatedZeroDelta and auto-admitted.

The diagnosis was also checked rather than assumed. The refusal names this lane's own support module
in every delta line, which is what distinguishes it from the shared version of this red that appears
on downstream PRs when the rows belong to somebody else.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016jFtgPtXxTj1kE8wwZUNsG

* Two floors were wearing a ceiling's type, and a green control certified them

Applies the 2026-09-09 operator ruling on databank_lga4_density to the two rows
in this lane that share its defect. Not a carrier migration - the ruling states
demote-then-convert is two cheap edits and a wrong-direction figure standing
another day is not.

WHAT WAS WRONG. databank_ewr2_density published "10kW+ Cab Density Air" and
digital_fortress_piscataway_density published availability-on-request wording
that the operator ruling classified CapabilityAtLeast. Both are capability
FLOORS. Every figure-bearing arm this carrier has is a MAXIMUM. So neither row
overstated a number - each answered a bounding question BACKWARDS: a consumer
asking whether 10,001 W was refused got YES from a page promising AT LEAST
10 kW. DESIGN section 5 puts silent wrongness outside the ladder, not low on it.

BOTH ROWS ALREADY CONTAINED THEIR OWN REFUTATION, IN PROSE.
EWR2's citation read "the plus sign is the operator's own, so the integer is a
marketed floor rather than a ceiling". Digital Fortress's read "not a standing
per-cabinet maximum". Correct sentences beside a typed value that contradicted
them - which is the class this lane itself filed as
gunbc.recurring_failure_mode.unread_arm_missing_on_a_secondary_axis, receipt
"THE HONESTY MIGRATES INTO PROSE, WHICH IS WHERE IT DIES". Filed on the cooling
axis, not applied to the quantifier axis by its own author.

NO EVIDENCE MOVED. Each obligation carries the operator's verbatim wording and
the complete retrieval citation - byte counts, user-agent insensitivity, element
boundaries, scope checks, positive controls. What demotion gives up is the typed
axis, not the reading.

NJFX IS NOT DEMOTED, AND THE REASON IS STATED IN THE WITNESS. "from 2 kW to
16 kW per cabinet" is a RANGE. Its top is a real upper bound, so the maximum arm
answers forwards. The ruling turned on a floor in a maximum arm; a band's top is
not a floor.

THE CONTROL THAT CERTIFIED THE DEFECT IS GONE, NOT RE-KEYED.
w_central_nj_read_densities_are_their_published_watts asserted established
readings of 16,000 / 15,000 / 10,000 W and was GREEN over two floors. It is
replaced by w_a_capability_floor_establishes_no_reading_and_bounds_nothing,
which reds if either row is re-promoted into a maximum arm without a quantifier -
the exact edit a hand-done carrier rebase could reintroduce. The band witness
now pins NJFX from both sides without ever asserting a cabinet DELIVERS 16 kW,
the claim a 2-16 kW band does not support.

CENTRAL NJ GOES FROM 4 READABLE DENSITIES TO 1. Two of those four were never
readable. The coverage row needed no edit at all: membership is unchanged
because DensityUnread is still a CabinetDensityClaim, so the count falls out of
the fold - which is the derivation paying for itself on its first use.

Evidence: compile 0 blocking errors; witnesses 6/6 under the new names;
namespace-wave-admission ADMITTED, 5 deltas all ExplicitlyEvaluatedZeroDelta
(the renames produced no binding delta - witnesses are discovered, not called).
The floor phase refuses on dag/gunbc/roadmap/roadmap_belt_actuate.dag:3567,
which this branch never touched and which is byte-identical to main; the
witnesses lane on main at ef4add7f is itself a failure, so that refusal is
main's and not this branch's.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016jFtgPtXxTj1kE8wwZUNsG

* File the class: a positive control certifies the defect it exists to catch

Five specimens across three lanes in one night, so it is a class and not an
incident. Requested by the carrier lane, which holds one of them.

THE ASYMMETRY THAT MAKES IT PREDICTIVE RATHER THAN DESCRIPTIVE. A negative
control is interrogated: it is expected to red, so a green one provokes a
question. A positive control is expected to green, and it does, so the question
never forms. The failure is invisible in proportion to how trusted the artifact
is - and the control that proves an accessor works is the most trusted thing in
a module. The defect is not a wrong row; a wrong row is ordinary and gets found.
It is that the instrument pointed at the row reports agreement with it, so row
and check are wrong TOGETHER and no disagreement exists for anyone to notice.

THE SPECIMENS. One: another lane's control asserted an established 35,000 W over
a "35kW+" floor. Two and three: this lane's
w_central_nj_read_densities_are_their_published_watts asserted 16,000 / 15,000 /
10,000 W, and two of the three subjects were capability floors whose own
citations said so in prose. Four: a re-keyed witness asking a question the
carrier refuses by construction, permanently green, carrying no information.
Five: a conjunct translated across a carrier change into an air-keyed query
against a row that names no medium, so the screen refuses for ABSENCE and not
for the ceiling - reintroducing the inference inside the change that deletes it.

In all five the author of the control was not the finder.

CEILING IS MECHANICALLY PREVENTABLE AND DELIBERATELY NOT HIGHER. Whether a
control's verdict is invariant across the arms its subject's type admits is
decidable from the carrier. WHICH arm a published page licenses is an external
fact, outside the modeled guarantee, so construction cannot make a wrong subject
unwritable. The wall is a mutation harness; that is validation, and validation is
the honest ceiling.

TRIGGER NAMES THE CAPABILITY, NOT AN ARTIFACT: an arm-substitution pass that
rebinds each control's subject to every other arm of its declared type and
refuses a control whose verdict changes for no materially different arm -
exhaustive over the type and run by the gate. Explicitly NOT satisfied by a
per-witness mutation run by an author on rows they chose, which is the current
state and is what failed five times. It subsumes specimen five with no extra
mechanism, since that row's verdict does not vary across its medium arms.

Three recognition tells, all cheap: a subject row whose citation carries hedging
prose while its typed value is unhedged; a control that reads a number BACK OUT
of a carrier instead of probing a boundary, since reading back out can only agree
with whatever the arm holds; and any control RE-KEYED across a carrier change,
where the reviewer compares the new assertion to the old one rather than to the
row - so a re-keyed control must be EXECUTED before the commit that re-keys it.

The roster is generated and gitignored, so only this row file is committed;
regenerated via claim_executor --required-regen --write and verified at 202
entries, 202 imports, 202 row files. Roster closure compiles: 0 blocking errors,
218 files emitted.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016jFtgPtXxTj1kE8wwZUNsG

* Adjudicate the secondary-axis class against its own trigger after #10888

The trigger fired. It did not discharge the class, and the row would have
been inflated if it said so.

#10888 landed the orthogonal published-medium axis the 2026-09-09 trigger
named -- `CoolingMediumStanding`, an arm for the unstated case rather than
a string beside an arm, which is the form the trigger pre-emptively
refused. So the capability half is discharged. Of the trigger's two
sufficiency conditions only the second is met: all four read figures in
this census were re-decided against their own captured wording, none
defaulted. The first is not met -- the carrier offers the honest arm
without refusing the dishonest one.

The class therefore splits. The FORCED half is structurally impossible:
no arm must be inhabited to record a figure whose medium was never
published. The CHOSEN-WRONGLY half survives, but became DECIDABLE,
because #10888 put the captured `wording` per figure beside the `medium`
arm. Revised ceiling is mechanically preventable via a lens comparing the
two, and explicitly NOT structural impossibility: whether a page names a
medium is external prose, so no constructor can be denied on it.

The two pre-climb receipts are relabelled with their date rather than
deleted -- a row with two unlabelled ceilings is a fork inside one
authority.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016jFtgPtXxTj1kE8wwZUNsG

* Delete the prose twin of an obligation this PR already discharged

Review 63095 found that this PR deleted the TYPED obligation
(`databank_ewr2_piscataway_obligation`) and left its prose twin standing
fifteen lines below the rows that discharge it. The annotation said "EWR2
remains unmodelled: read its facility page and carry its address,
critical IT load, cabinet density and retail grain" while
`databank_ewr2_piscataway`, `databank_ewr2_density` and
`databank_ewr2_retail_grain` sat above it carrying exactly those four
things. One module, two contradictory answers to one question -- and §4c
is the reason it would never have been refuted, since no Accepted program
can read an annotation.

A pure deletion, because nothing live was only there. Each fact the block
carried is already stated elsewhere and better:

  the 404        -> "whose URLs derived from a secondary citation 404ed",
                    which is the accurate version: the 404 was a path
                    constructed from a secondary claim, not the facility's
                    own page, and naming it as the facility's page is what
                    made the block read as an open obligation
  the live path  -> "databank.com/data-centers/new-jersey/piscataway/"
  the 85 kW HPC  -> its own annotation, which says why a tenant-tailored
                    figure is a different QUANTITY from a marketed cabinet
                    maximum rather than merely unconfirmed
  coverage       -> "two of at least three are read", which supersedes the
                    deleted block's "exactly two sites" -- that count was
                    wrong once the 165 Halsey suite was found

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016jFtgPtXxTj1kE8wwZUNsG

* Enrol EWR2 in the roster, and delete an obligation this PR invented

Review 63103, two findings, both real.

ONE: `databank_facilities` held five entries while the module declared six
`ColoFacilityRow`s. That roster is the module's `ExternalModelScope`
subject, so the operator's own scope declaration disagreed with the
footprint it was declaring, and `central_new_jersey` had already enrolled
the sixth. EWR2 added.

TWO: an annotation THIS PR AUTHORED said the 165 Halsey suite had no
DataBank row and that reading the suite page was what would complete the
operator's coverage. `databank_ewr1_newark` carries "165 Halsey Street
Suite #500", cited from that very page. The note invented residual work a
later lane would have executed.

That second finding also indicts my own previous commit. Deleting the
stale EWR2 block, I justified dropping its "the index names exactly two
sites" as superseded by "two of at least three are read". The old
sentence was correct and mine was the fabrication. The rewritten
annotation says which claim was false and restores the true one: the
index names exactly two New Jersey sites, both modelled, and 165 Halsey
DEMONSTRATES the one-row-per-operator-per-building rule rather than owing
it.

Swept the class with its denominator: of the six touched operator
modules, three declare a roster and three cite the facility row itself as
their scope subject. Exactly one of the three rosters was short.

Filed as a THIRD SPECIMEN on `roster_is_its_own_denominator` rather than
a new class -- the ledger obeys section 2 too. What it adds: the roster
has no fold anywhere, so no short report existed to look short, and
`central_new_jersey` enumerates members without reading any roster, so
one fact had two independent hand-authored lists. A fork between two
lists is loud only if something reads both. Witnesses, mutations and a
corpus parse were all green over it because the roster is in no witness
closure.

Census witnesses 6/6 after the change.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016jFtgPtXxTj1kE8wwZUNsG

* Route the two rate rows into the closure: a cabinet figure is not a price

Review 63178 found `njfx_wall_retail_rates` and
`digital_fortress_retail_rates` dangling, and they were. Verified before
fixing: `git grep -n "_retail_rates" -- dag | grep -v dag/extdeps/colo/`
returns nothing, so no fold, census row or witness outside the colo
modules reads any RetailRateStanding row, and nothing inside them did
either. DESIGN section 3c names that exact tell -- a data row no fold
reads -- and it is red regardless of how well the row is modelled.

Fixed by CONSUMPTION rather than by declaring a frontier. Section 3c
offers both as honest states, but a frontier is the weaker one when the
consumer is available, and here it was: the control asserts a fact the
census actually owes. Both facilities that answer the density question
refuse the price question, so a published cabinet figure is not a
published price -- the rate axis of the same separation the grain control
already makes. Three axes the operator publishes independently, and
reading one never licenses an answer on another.

THE ARM IS READ AT THE SITE, NOT THROUGH A NEW ACCESSOR. RetailRateStanding
is a two-arm coproduct, and a named Bool predicate beside it in the
carrier would be a second, weaker spelling of the variant the row already
carries -- the move this census deleted three times on the density axis.
One local helper in the witness module, one consuming site.

MUTATION-VERIFIED, in a detached worktree rather than in the live tree:
flipping njfx_wall_retail_rates to RatesPublished reds
w_a_read_density_is_not_a_priced_cabinet and NOTHING ELSE (6 pass, 1
fail). A control that cannot red is decoration, and one that reds its
neighbours is entangled; this is neither. 7/7 unmutated.

NOT CLAIMING THE CLASS IS CLOSED: 26 `_retail_rates` rows exist across
dag/extdeps/colo/, all unconsumed. Two are mine and those two are now
consumed. The other 24 predate this lane, and the reviewer is right that
their prevalence is not precedent -- it means the class already stands.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016jFtgPtXxTj1kE8wwZUNsG

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Brian Searls <11205878+briansrls@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant