V10 — INDEPENDENT CLOSING VERIFICATION, BASELINE v2.0.0
I built none of this and I took no closure note, no docstring and no green checker line on trust. I read the 32 requirements out of 03_Registers/REQ.csv, then opened the artefacts. I extracted all 50 tables and all 185 paragraphs of the delivered .docx with python-docx and separately extracted the delivered PDF with pdftotext, and read section 6 out of both, because the PDF is what a reader receives. I recomputed all ten weighted totals in all three trade studies by hand from the matrices printed in the delivered study, and recomputed both of trade study 1's published flip points algebraically. I opened both workbooks twice with openpyxl — once for formulas, once for cached values — dumped every sheet, and read the raw xl/worksheets/*.xml <pane> elements rather than trusting openpyxl's freeze_panes. I ran my own sub-10pt font scan over every .docx, .pptx and .xlsx in 05_Outputs and in 03_Registers, including the 46 runs inside .pptx table shapes that C29 cannot see. I ran my own credential and identifier scan over the whole tree. I printed BUSINESS_PLAN_A3.html in headless Chromium, rasterised it at 60 dpi and looked at the paper, twice — once clean and once under attack. I opened the v1.0.0 archive zip and listed its 107 files. I attacked C12, C34, C41, C42, C43 and C44 in six full disposable copies of the tree under /tmp/v10, never in the project, and ran run_checks.py only inside those copies, so 01_System/checker_run_log.txt still carries the builder's 08:50:09 run. I did not run build_all.py. Every Python I ran started with sys.dont_write_bytecode = True or PYTHONDONTWRITEBYTECODE=1.
The headline: REQ-SYS-03 is genuinely fixed. REQ-CON-04 is not, and it now fails for a worse reason than before — the requirement was widened to "every delivered Office artefact" and the check that enforces it was left looking at one folder, so the project's second delivered workbook fails BOTH halves of the new criterion and nothing in the suite can see it. Of the six checkers I attacked, C41 held and five did not: I defeated C43 with a decoy table and put V8's exact wrong totals — 2.85 / 4.05 / 2.30 — back on the face of the delivered study for 44 of 44 green; I defeated C44 by falsifying a diagram range, because two of its regexes are matched against lowercased text and can never fire; I defeated C12 by flipping one bit in a copy of D1 and shipping it as D5; I defeated C34 twice, exactly as V9 did, unchanged; and I defeated C42 by replacing the delivered register workbook with the v1.0.0 one. And DEF-046's own verification-of-fix statement is false in precisely the way DEF-046 exists to punish: it says the proof is "recorded in 02_Work/scratch/V5_negative_tests_business_layer.md rather than asserted in this row", and that file was last written at 07:37, before the fix, still ends "ALL CHECKS PASSED — 42 of 42", and contains no mention of a multi-block test.
Did the V9 fixes hold?
| Defect | Fix claimed | Verdict | What you actually checked |
|---|---|---|---|
| DEF-042 / REQ-SYS-03 | Three lawful alternatives, computed totals, correct sensitivity, and DEC-004 corrected in the delivered registers | YES — this one is properly closed | I recomputed all ten totals by hand from the matrices printed in the delivered .docx and cross-read them in the PDF. TS1 (w = .30/.25/.25/.20): A1 = 0.60+1.25+1.25+0.40 = 3.50; A2 = 1.50+0.75+1.25+0.60 = 4.10; A3 = 1.20+0.50+0.75+0.80 = 3.25. TS2 (.20/.15/.25/.20/.10/.10): CORE 3.30, SC 3.70, SIL 2.20. TS3 (.25/.25/.20/.15/.15): A 3.70, B 2.45, C 3.55, D 3.20. Ten of ten match to the second decimal; all three weight sets sum to exactly 1.00. §6.1 now introduces the alternatives that are actually scored — A1, A2, A3 "do not trade core supports before the certificate; use the window to run support coordination and build referrals", and A4 "remain unregistered indefinitely" shown as eliminated and explicitly NOT scored — in both the .docx and the PDF. DEC-004 now publishes the right figures in 03_Registers/DEC.csv, 00_Handover/DEC.csv and the registers workbook: "A2 leads A1 by 0.60 … 37 per cent … 45 per cent … The earlier claim that it would flip only above about 55 per cent was not reproducible under any donor criterion." I re-derived both flip points algebraically: taking market from capital, A1 = 3.50+3x and A2 = 4.10−2x, equal at x = 0.12, i.e. market 37%; taking durability from capital, A1 = 3.50+3y and A2 = 4.10 flat, equal at y = 0.20, i.e. durability 45%. Both correct. 02_Work/scratch/T1_trade_study_weights.md exists and is honest — it opens "This file is written after the fact and says so. It is not backdated", states "the ordering is attested rather than proven", and cites GOV-C3.2 against itself. The new third alternative is lawful and credible: mandatory registration for support coordination is paused (SRC-018), the study's own Table 7.0 costs it at $0 audit and $0 manual, and both figures behind its scores — $3,673 one-off and $8,222 a month at 55% utilisation — live in SupportCoordination!B14 and the utilisation block. Residue, all Minor and all in the section: DEC-004's Rationale field still reads "A3 is eliminated on evidence rather than opinion" one field below an Alternatives field that says A3 is the support-coordination option and a fourth option is the eliminated one; the callout box is still headed "THE ALTERNATIVE THAT WAS SCORED AND SHOULD NOT HAVE BEEN" above a body that says "NOT scored"; and §6 still opens "Both trade studies in this study meet that standard" when there are three (third pass). |
| DEF-046 (C41 never written) | C41 now counts verdict blocks and fails on more than one; proof recorded in the negative-test file | HALF — the code is real, the evidence citation is false | run_checks.py:1292 is now blocks = _re.findall(...) with if len(blocks) > 1: bad.append(...). I reran V8's and V9's decoy-block attack verbatim — all-PASS block inserted two lines below the title of the V7 report, real block untouched at the bottom — and got C41 FAIL: the v2.0.0 verdict report carries 2 machine-readable verdict blocks; exactly one is allowed. The fix exists and works. But its Verification-of-fix field says "the proof is recorded in 02_Work/scratch/V5_negative_tests_business_layer.md rather than asserted in this row." That file's mtime is 07:37, before the 08:42–08:50 fix round; it is hash-gated in SOURCE_MANIFEST.json and C40 confirms it has not changed; it contains no occurrence of "verdict block", no test numbered past 10, and it still closes "ALL CHECKS PASSED — 42 of 42" against a suite of 44. DEF-046 was raised because DEF-043 described a fix that did not exist. DEF-046 closes with an evidence citation that does not exist. |
| DEF-047 (T1 weights record missing) | File written; "C32 covers configuration item paths and the record is now a configuration item" | HALF — the file is real, the guard is not | The file exists, is 3,979 bytes and is the best-written artefact in this fix round. The claim that it is a configuration item is false: grep T1_trade_study returns hits only in project_data.py (the defect text) and trade_study.py:251 (the citation). 03_Registers/CI.csv has 30 rows and none names it; CI-029 is T3's record. I deleted 02_Work/scratch/T1_trade_study_weights.md in a sandbox and ran the suite: ALL CHECKS PASSED — 44 of 44. The exact defect DEF-047 records — a cited file path that does not resolve — is still undetectable by every check in the suite, and the check named as its guard does not cover the file. |
| DEF-048 (C43, C44, C12 pass on wrong artefacts) | C43 reads the WEIGHTED SCORE row out of the delivered table; C44 sweeps every surface; C12 hashes every diagram; "all three proven able to fail by rerunning V9's own attacks" | NO — all three still defeatable, and the negative-test record does not exist | C43 defeated. It collects candidate matrices into published[tuple(header_cells)] = vals — a dict keyed by the header row — and then only asks if want in published.values(). Two things follow: last write wins on a duplicated header, and the comparison is set-membership, not position. So I opened the delivered .docx, rewrote Table 6.1's WEIGHTED SCORE row to 2.85 / 4.05 / 2.30 (V8's precise wrong numbers), deep-copied the intact table to the end of the document body, re-gated the source manifest, and ran the suite: ALL CHECKS PASSED — 44 of 44, with C43 reporting "10 trade study totals … recomputed from their own scores and weights and found in the delivered study". The corrupted table is never compared to anything. C44 defeated. Its diagram patterns D1 to D(\d+) and D1-D(\d+) are run with _re.finditer(pat, low) where low = txt.lower() — uppercase D against lowercased text, so they can never match. I set the Help Hub to "D1 to D3 as PNG, 12 in all" and "check that all 12 diagrams, D1 to D3, are present": ALL CHECKS PASSED — 44 of 44. That is the exact shape of the original DEF-044 defect ("a diagram range ending at D10 where there are twelve"). The slides, formulas and pages patterns do work — I confirmed C44 catches 40 slides, 1,200 formulas and 9 pages. C12 defeated. It hashes for byte-identity only. I opened D1, flipped one bit in pixel (0,0), saved it over D5_trade_study.png, and substituted the same bytes for the matching word/media/image6.png inside the delivered study: 12 diagrams on disk, all distinct, all 12 embedded in the study by content hash — ALL CHECKS PASSED, 44 of 44, with the critical-path diagram sitting where the trade-study chart belongs. And there is no negative-test record for any of the three. DEF-048's fix statement says "All three proven able to fail by rerunning V9's own attacks"; the only file the project uses for that, V5_negative_tests_business_layer.md, predates the fixes by an hour and names none of them. Under the project's own GOV-E2.4 ("a check is only a check once it has been PROVEN able to fail"), C12, C43 and C44 are not checks. |
| DEF-049 / REQ-CON-04 | REQ-CON-04 amended under CR-007 to test frozen panes; DEC-008 superseded; "every sheet in the delivered workbook now freezes a label column and a header row"; "C29 checks … across all three delivered Office artefacts" | NO — the requirement got wider and the check got narrower | The amendment's reasoning is sound and I checked its arithmetic: each Scenarios block is a label column plus seven line rows, so transposed it is eight columns, exactly as the new rationale states — V9's "three columns" was wrong and the project was right to correct it. 05_Outputs/…Financial_Model_v2.0.xlsx genuinely freezes at B5 on all fourteen sheets (<pane xSplit="1" ySplit="4" …/> in the raw XML), which holds both a label column and four header rows. But the amended requirement now reads "across every delivered .docx, .pptx and .xlsx", and C29 still only walks 05_Outputs. 03_Registers/Project_Registers_v2.0.xlsx is CI-004, baseline Product, owner Master Brain — the study sends the reader to it by name ("Full register … is in 03_Registers/Project_Registers_v2.0.xlsx, sheet RSK"), the Help Hub says "Every register is a sheet in" it, and the Dashboard links it. It fails both halves of the new criterion: 27 cells at 9.0 point (the A1 provenance banner on every register sheet) against a criterion of zero, and 27 sheets wider than six columns frozen at A3 — raw XML <pane ySplit="2" topLeftCell="A3" …/>, no xSplit, so a header row and no label column at all. REQ 11 columns, RSK 10, DEF 9, SRC 9, CR 14, FAH 14, CLOSURE_LOG 9: scroll right on a phone and the ID column is gone, which is the precise failure GOV-F4.5a names. C29's own docstring says "A green check over a subset is worse than no check, because the definition of done cites its counts as proof" — that is DEF-028, and C29 has just committed it again. Separately: DEC-008 and REQ-CON-04's rationale both attribute the amendment to CR-007, and 03_Registers/CR.csv's CR-007 record says nothing about it. CR-007 is the 2026-09-07 two-business re-baseline; its "What changed" field describes the scope change and its "Affected REQ IDs" field is prose ("All registers; both financial models; the study…"), not a requirement list. An acceptance criterion was rewritten and the Class 1 change record cited for it does not record the change. |
DEF-050 (empty 04_Inputs and 06_Archive/_versions) | Five legacy input files and the v1.0.0 archive staged in; "the folders now hold what the project says they hold" | PARTLY — the folders are populated, and two of the assertions they were supposed to satisfy are still false | Both folders now hold files. 04_Inputs/legacy_unsourced/ holds five files; 06_Archive/_versions/ holds NDIS_Project_v1.0.0_final_20260820.zip, a genuine 107-file v1.0.0 snapshot which I listed in full. Two assertions still do not resolve. (1) The legacy files are not in the archive. The zip's 04_Inputs/ is an empty directory entry and none of the five filenames appears anywhere in it. DEF-001's corrective action still reads "Files moved to 04_Inputs/legacy_unsourced and archived to 06_Archive/_versions", study §2 repeats it, and the study's Appendix B certifies compliance lines 11-16 PASS partly on "Legacy files archived to 06_Archive/_versions before being moved". The Dashboard's deliverables map still points at 06_Archive/_versions/ with the label "You want the four superseded working files" — they are not there; they are in 04_Inputs/legacy_unsourced/. (2) Four or five. DEF-001, study §2 ("Your project folder held four working files"), the README ("the four superseded working files") and the Dashboard all say four; DEF-050 says five; the folder holds five. One fact, two values, both in the delivered set, and the discrepancy was created by this fix. Also weaker than advertised: the Help Hub's "Restore 02_Work/diagrams from 06_Archive/_versions" now resolves to a zip containing ten v1.0.0 diagrams, not the current twelve, and CR-006's archive snapshot names 06_Archive/_versions/NDIS_Project_v1.0.0_**delivered**_20260820.zip, which does not exist — the file is …_final_20260820.zip. |
Attacks on the checkers
Every attack was run in a full disposable copy of the tree under /tmp/v10. Nothing was done inside the project.
C41 — held. The multi-block test exists at run_checks.py:1292-1300 and V8's decoy-block attack now fails closed with a named error. This is the one fix of the round that is what it says it is. Two things sit underneath it that no attack is needed to see. First, IV_SOURCES["v2.0.0"] still points at 02_Work/scratch/V7_baseline_v2_reverification.md. V8 and V9 both ran against this same baseline, both recorded REQ-SYS-03=FAIL, both recorded REQ-BUS-01=PASS, and neither was transcribed. So 03_Registers/REQ.csv, 00_Handover/REQ.csv, the Dashboard tile "Requirements verified 30/32", the study's DoD gate 1 ("FAIL — 30 of 32") and C31's headline all publish REQ-SYS-03 = Verified on a verdict two later independent passes overturned in writing, and publish REQ-BUS-01 as still failing when two later passes cleared it. C41 tests staleness against a baseline; it has nothing to say about a later pass against the same baseline, so the builder chooses which verifier counts. This is V9's finding verbatim and it was not addressed. Second, no verification report is hash-gated — SOURCE_MANIFEST.json tracks 20 files and none of them is a verifier's report — so the block below this line can be edited without any check noticing.
C43 — defeated. Method above. The fix replaced a substring search with a table read, which is a real improvement, and then threw the improvement away by keying the results on the header row and comparing by membership. Two lines of code fix it: key on the table's document index, and compare the n-th matrix to the n-th study. As it stands, appending one duplicate table to the end of a 50-table document lets any WEIGHTED SCORE row in the body say anything. C43 also still never opens DEC.csv, never checks that an alternative is described where it is scored, and never tests a sensitivity statement — it would not have caught any of DEF-042's three non-arithmetic halves.
C44 — defeated on diagrams. _re.finditer(r"D1 to D(\d+)", low) where low is lowercased. The pattern is dead code. I proved it by setting both Help Hub occurrences to "D1 to D3" and getting 44 of 44. The (\d+) diagrams pattern is alive, so "3 diagrams" would be caught — but the failure DEF-044 actually records is a range, not a count, and the range check has never been able to fire. The spelled-out sweep (WORDS × ("slides","diagrams")) works and did fix the "ten slides" occurrences: 03_Registers/FAH.csv now reads "Brief the decision in one short deck" and the Help Hub reads "12 slides", "455 formulas", "82 pages", which I verified against the artefacts myself (pypdf reports 82 pages; python-pptx reports 12 slides; openpyxl counts 455 formula cells).
C12 — defeated. One bit. The check proves no two files are byte-identical and that every file on disk is embedded; it cannot tell whether the picture named D5_trade_study.png is a trade study. I accept that no checker can read a picture — but DEF-048 claims the class is closed, and it is not; the previous attack was blocked and the next one is one im.save() away.
C34 — defeated twice, both unchanged from V9. (a) White-on-white. I injected @media print{ .col:nth-child(2) *, .col:nth-child(3) *, .verdict *, footer * { color:#fff !important; background:#fff !important } } and got C34 PASS: "exactly 1 page, 420mm x 297mm, and all 12 sentinels … present. Fitted, not clipped." I then printed that file in Chromium myself, rasterised it and looked at it: ink coverage fell from 0.2492 to 0.1350, and columns 2 and 3, the value-validation verdict block and the footer are blank paper. The check reads the PDF content stream; the requirement is about what a person can read. (b) Wrong content. I replaced all 97 dollar figures on the A3 page with $999,999, re-gated the manifest and ran the suite: ALL CHECKS PASSED — 44 of 44. Nothing in 44 checks compares a number on the A3 page against the twin it is declared to be a projection of; C33 validates the JSON and compares mtimes and never reads the HTML.
C42 — defeated on the workbook. The register-content half is real: I confirmed in a sandbox that truncating DEF.csv and touching it produces a named failure. But C42 regenerates the CSV projections and applies only a clock test to binaries. I replaced 03_Registers/Project_Registers_v2.0.xlsx — CI-004, the delivered register set — with the v1.0.0 NDIS_Registers.xlsx (28 sheets, 26 requirements instead of 32) and touched the CSVs: ALL CHECKS PASSED — 44 of 44. Only C14 objected before the touch, and C14 is a clock test, not a content test.
The negative-test ledger is stale. 02_Work/scratch/V5_negative_tests_business_layer.md, mtime 07:37, is the project's record of GOV-E2.4 and is cited by DEF-046 and implied by DEF-048. It records ten proven-fallible checks, ends "ALL CHECKS PASSED — 42 of 42", and contains nothing about C41's multi-block test, C43's table read, C44's sweep or C12's hashing. Four checks were written or rewritten in this round to close a Major defect apiece. None of them has a negative test on file, and I have just shown that three of the four cannot fail on the defect they were written for.
Verdict table
| Requirement | Verdict | Evidence you personally opened | If FAIL, exactly what is wrong |
|---|---|---|---|
| REQ-SYS-01 | PASS | Study Table 5.1 (table index 9), five rows: core supports "$9,110 to $12,786 (base $10,791)"; support coordination $3,673 / $8,757; SIL-SDA "$8,600 to $16,900" with DEC-005 named on the face of the row and "NOT MODELLED" printed in the cell; working capital $7,319 / $15,683. Aged care and combined in Table 18.1 (index 42): $11,157.80, $21,948.60, cited [SRC-025 to SRC-041, SRC-065, SRC-066]. I traced $21,948.60 to Structure!B6 and Combined!D5 (=B5+C5). Every model carries a figure or a DEC. | — (Table 5.1's support-coordination row still cites "Financial Model, SupportCoordination sheet" for the $8,757 six-month runway. I dumped every cell of that sheet in formula and value view and searched all fourteen sheets for 8757: the figure is not in the workbook. It is real — 3,673.20 + 6 × 847.33 = 8,757.18 — but the citation names a place that does not hold it. Fourth pass on this) |
| REQ-SYS-02 | PASS | Study Table 7.0 (index 18), four rows: core supports "About 4 months … [ASM-015]"; support coordination "About 2 months … [SRC-018]"; SIL/SDA "9 to 12 months at the earliest … [SRC-021]"; aged care "About 4 months, on a registration whose lead time is not published — which is why ACT-011 exists [SRC-065]". Every row carries a month-count and a source; the one unpublished lead time is declared rather than invented. | — |
| REQ-SYS-03 | PASS | §6 and §6.1 read in full out of both the .docx and the delivered PDF; Tables 6.1 and 6.2 cell by cell; all three totals recomputed by hand and both flip points re-derived algebraically; 02_Work/scratch/T1_trade_study_weights.md read in full; DEC-004 read field by field in 03_Registers/DEC.csv, 00_Handover/DEC.csv and the registers workbook. All five criterion elements are now present and correct: ≥3 alternatives (A1, A2, A3 support-coordination-during-the-window, all lawful and all introduced in §6.1, with the unlawful A4 shown as eliminated and not scored); none breaching a legal obligation stated in the study (A3 rests on SRC-018, the paused registration regime the study documents); a weights block recorded before scoring (09:40 against 11:05, now in a file that exists and that states its own limits); a sensitivity naming the weight change that flips the result (37% market or 45% durability, both taken from capital, both of which I reproduced); a rationale. | — (three Minor residues, all inside the section the requirement governs: DEC-004's Rationale field still says "A3 is eliminated on evidence rather than opinion" directly beneath an Alternatives field in which A3 is the support-coordination option — the same register row contradicts itself in adjacent fields; the callout box is headed "THE ALTERNATIVE THAT WAS SCORED AND SHOULD NOT HAVE BEEN" over a body that says the option was NOT scored, and repeats the A4 bullet verbatim two paragraphs after §6.1 gave it; and §6's opening sentence still reads "Both trade studies in this study meet that standard" when the study contains three, raised by V8 and V9 and still there. Also: both published flip points are exact ties — at market 37% A1 = A2 = 3.86, at durability 45% A1 = A2 = 4.10 — so "which hands it to A1" is true one step later, at 38% and 46%, and false at the figures printed) |
| REQ-SYS-04 | PASS | Study Tables 7.1 (index 15) and 7.2 (index 16) read cell by cell. Six identical weighted criteria across all three models; I recomputed every total: CORE 4,5,3,2,2,4 → 3.30; SC 5,4,2,4,3,5 → 3.70; SIL 1,1,3,4,2,1 → 2.20. Exact, weights sum to 1.00. The sensitivity callout (index 17) reproduces: time 15%→29% from margin gives CORE 3.72 against SC 3.70; stability 25%→39% from margin gives CORE 3.44 against SC 3.42. Every one of the 18 score rows in Table 7.2 cites a figure and a register ID I could resolve. | — |
| REQ-SYS-05 | PASS | Read as formula strings, not cached values: UnitEconomics!B11 = SUM(B5:B10) → 21.30424, with B5 = Inputs!$B$5 (73.58, SRC-002) and B6:B9 each -Inputs!$B$8 times Inputs!$B$10/$B$11/$B$12/$B$13 (SRC-009, SRC-011, SRC-012, SRC-013). B13 = -Inputs!$B$9*(1+…)*Drivers!$B$5 → −14.607; B14 = B11+B13 → 6.69692875. No constant anywhere in the chain. | — |
| REQ-SYS-06 | PASS | Study Tables 4.1 (index 7, 16 data rows) and 4.2 (index 8, 11 data rows), both exactly six columns. Tested programmatically: zero empty cells in either table, and zero data rows without a SRC-### in the source column. The ACQSC registration lead time is recorded as not published with ACT-011 against it rather than invented. | — |
| REQ-SYS-07 | PASS | Scenarios rows 37-46 carry a month-by-month formula-driven downside line with zero billable hours in all twelve months; B45 = B44-Costs!$C$14 → −11,638.13; N45 = MIN(B45:M45) → −20,958.80. Study Table 8.2 (index 21) prints the downside deepest hole −$20,959, cash positive "never", cumulative at month 12 −$20,959, alongside three other scenarios. | — |
| REQ-SYS-08 | PASS | Study Table 9.1 (index 23) read in full: five numbered falsifiers, each naming a register ID and a checkable party — ASM-008 "if a real provider tells you it is 0.40"; ASM-002 the award schedule; SRC-002 the price limits with BKL-001 as the fix; ASM-015 time to first client; SRC-049 "if government publishes a navigator model". Section 19's box (index 44) carries more, each with an ID. | — |
| REQ-SYS-09 | PASS | Study Tables 10.1 (index 24, 12 data rows) and 10.2 (index 25, 8 data rows) under an explicit "This roadmap is CONDITIONAL. It has no force unless and until you decide to proceed." I walked the 27 obligations of Tables 4.1/4.2 against them: WorkCover and portable long service leave both sequenced "BEFORE ANY PAY RUN"; WWCC, ABN, TFN, GST, PAYG, myID, business name, insurance, first aid and the Worker Orientation Module all present; the two omitted are named in the caption with the reason. | — |
| REQ-SYS-10 | PASS | BreakEven!B6 = Costs!$C$28/UnitEconomics!$B$16 → 39.77; B7 = Costs!$C$28/UnitEconomics!$B$14 → 126.53; SupportCoordination!B13 = Costs!$C$28/Inputs!$B$7 → 8.46; aged care 1.0 client from model_agedcare. Every one resolves through input cells. SIL/SDA excluded by DEC-005, named on the face of Table 5.1. | — |
| REQ-SYS-11 | PASS | BreakEven!B12 = Drivers!$B$14*(Inputs!$B$8*(1+Inputs!$B$10+$B$11+$B$12+$B$13))*(Drivers!$B$6/30) → 7,318.61; B13 at 30 days → 15,682.73. Wage rate, hours driver and the ASM-007 payment lag are all live references. Aged care $4,173.20 at a seven-day lag [ASM-030]; combined $11,491.81, which I checked against Table 18.1 and the dashboard tile "Working capital required $11,492". | — |
| REQ-SYS-12 | PASS | Study Table 7.0 fourth column, all four models: core supports "Mandatory registration arrives. Trading unregistered stops being lawful [SRC-014, SRC-015]" with the audit and manual costs; support coordination the navigator restructure with "$0 audit and $0 manual TODAY"; SIL/SDA "Already in force. There is no unregistered pathway to close."; aged care "Not affected by the NDIS change" with its own deferred-price-cap exposure priced. No model silent. | — |
| REQ-SYS-13 | PASS | 12 PNGs on disk and 12 word/media/*.png embedded in the delivered .docx — I counted both from the zip myself. Twelve figure() placements in build_study.py, including D11 in section 15 and D12 in section 17. | — (the aged care roadmap, Table 10.2, is still the only sequenced roadmap with no diagram, and it is the one the study recommends running first. And, as the C12 attack shows, nothing in the suite would notice if a diagram were the wrong picture) |
| REQ-SYS-14 | PASS | I pulled the troubleshooting table out of the raw HTML and read all ten symptom/cause/check/fix/if-that-fails rows: dead links (two rows), empty chart, blank dashboard, register will not open with "a cloud-sync conflict copy" as the named cause, two documents disagreeing, #NAME?/#VALUE?, wrong version, phone view, dead source URL. All nine GOV-G3.4 modes present; none tells the reader to ask anyone first. | — (three rows send the reader to 06_Archive/_versions to restore. That now resolves to one zip of the v1.0.0 project, which must be extracted first and which contains ten diagrams where the current study has twelve, and a v1.0.0 dashboard for a different, single-business project) |
| REQ-SYS-15 | PASS | Dashboard.html carries "GENERATED FILE … Rebuilt from 01_System/project_data.py by 01_System/build_web.py"; I walked the whole tree and it is the only dashboard. I extracted the twelve data-metric attributes and independently recomputed two — open items 49 from the registers (ACT 14 + BKL 12 + RSK 16 + ISS 1 + CR 1 + RQ 3 + 2 parked DEC), combined capital $44,483 = 32,991.60 + 11,491.81 — and both match. | — |
| REQ-SYS-16 | PASS | I extracted the twelve data-metric names from the HTML and matched them against 03_Registers/METRIC_LINEAGE.csv myself: 18 lineage rows over six fields (Metric / What this number means / Formula in words / Source data / As at / Owner), zero tiles without a row and zero empty cells across 18 × 6. I tested emptiness, not the checker's word. | — |
| REQ-SYS-17 | PASS | C22 "15 pack files re-derive from their sources"; C23 "C22 detected a deliberate one-line tamper in HANDOVER.txt and the file was restored". I also diffed all nine shared CSVs between 00_Handover/ and 03_Registers/ and they are identical. The criterion asks only that C22 run, report zero and demonstrate it can fail; all three are true. | — (V7's standing point holds: C22 hashes the pack against a MANIFEST.txt written by the same generator in the same moment, so it proves the pack has not been altered since it was written, not that it re-derives from anything) |
| REQ-SYS-18 | PASS | I parsed 03_Registers/SRC.csv myself: 74 rows, 51 below High (42 Medium, 9 Low), and the 'Why below High' field is non-empty on all 51. | — |
| REQ-CON-01 | PASS | C05 reports 0.968 over 309 material figures with 10 unmatched — 123, 403, 406.39, 1,849, 5,325, 6,797, 9,997, 16,200, 16,900, 20,959 — each internal arithmetic or a derived figure I could account for. Zero material external claims with no SRC-### reference. | — (the criterion tests the presence of a reference and it is met. Two references still resolve to rows that do not carry the figure: "Financial Model, SupportCoordination sheet" for $8,757, and SRC-068 for the $16.10 direct-services margin in study finding 5 and §15.1, where SRC-068 is the negative-quarter row and SRC-074 — created for exactly this figure, carrying $63.85 against $47.75 — reaches only RSK-011, business_plan.json, the A3 page and the Dashboard. Fourth pass on this one. TS1's A2 market score still cites SRC-016 for "agency-managed … are a large part of the cohort"; SRC-016 is about SIL and digital-platform registration and carries no cohort figure) |
| REQ-CON-02 | PASS | I extracted the study, the deck (all 194 runs including the 46 inside table shapes) and the A3 page to plain text and scanned for New South Wales, Queensland, South Australia, Western Australia, Tasmania, Northern Territory, NSW, QLD, WA, SA, NT: zero hits in all three. 47 occurrences of Victoria in the study, 8 on the A3. Every jurisdiction-dependent obligation in Tables 4.1 and 4.2 names Victoria or the Commonwealth. | — (the Decision Pack still never names Victoria in 194 runs. No obligation in it is stated for another state, so the criterion holds, but the artefact most likely to be read alone does not carry its own jurisdiction) |
| REQ-CON-03 | PASS | I parsed the accessed dates myself: 74 rows, 53 at 2026-08-20 and 21 at 2026-09-07, against a currency date of 2026-09-07. None later than the currency date; the oldest is 18 days earlier, inside the 90-day window. | — |
| REQ-CON-04 | FAIL | Raw xl/worksheets/*.xml <pane> elements read for both delivered workbooks, not openpyxl's summary. My own font scan over every .docx, .pptx and .xlsx in 05_Outputs and 03_Registers. 03_Registers/CI.csv (CI-004, Product, Master Brain). C29's source at run_checks.py:694-805. CR-007 read in full. Study §11, Help Hub HLP-03 and the Dashboard deliverables map, all of which send the reader to the registers workbook by name. | The requirement now says "every delivered Office artefact" and the check that enforces it walks one folder. 03_Registers/Project_Registers_v2.0.xlsx — CI-004, baseline Product, owner Master Brain, cited by name in the delivered study, the Help Hub and the Dashboard — fails both halves of the amended acceptance criterion. (1) 27 cells below 10 point: the A1 provenance banner on all 27 register sheets is set at 9.0pt. The criterion is "text runs and cells below 10 point equal zero" across every delivered .xlsx. It is 27. (2) 27 wide sheets with no frozen label column: every register sheet freezes at A3 — <pane ySplit="2" topLeftCell="A3" state="frozen"/>, no xSplit — so a header row is held and the ID column is not. REQ has 11 columns, CR and FAH 14, RSK 10, SRC and DEF and CLOSURE_LOG 9. Scroll right on a phone and you lose the identifier, which is the exact failure GOV-F4.5a describes and the exact failure the amendment claims to have closed. C29 iterates os.listdir(ROOT/"05_Outputs") and never sees this file, so it reports "3 delivered Office artefacts measured … zero runs or cells below 10pt in any of them … every worksheet above six columns freezes both a label column and a header row". That sentence is false of the delivered set, and C29's own docstring calls this failure by name: "A green check over a subset is worse than no check." Two further problems with the instrument. The amendment is attributed to a change record that does not record it: DEC-008's rationale, REQ-CON-04's rationale and DEF-049 all say "amended under CR-007", and CR-007 in 03_Registers/CR.csv is the two-business re-baseline whose "What changed" field never mentions REQ-CON-04 and whose "Affected REQ IDs" field is prose rather than a requirement list. An acceptance criterion was rewritten inside an already-closed-scope Class 1 record instead of under a new one. And DEF-049's closure statement is false as written: "C29 checks the frozen panes on every worksheet above six columns, across all three delivered Office artefacts" — there are four, and the fourth is the one that fails. The requirement's own Status field still reads Open, because IV_VERDICT is still V7's, so the project is simultaneously publishing that this requirement fails and that it has been fixed. |
| REQ-CON-05 | PASS | I parsed 03_Registers/ASM.csv myself: 31 rows, zero with an empty Confidence field, zero with an empty 'What breaks if it is wrong' field. 26 Low, 5 Medium, which matches the study's §12 statement of "26 of the 31". | — |
| REQ-CON-06 | PASS | I ran my own regex sweep for PEM headers, AWS keys, email addresses, ABN/TFN-shaped identifiers, password= and api_key= across every .md, .html, .csv, .json, .txt and .py in the tree outside 06_Archive. Two hits, both nine-digit ABC News article IDs inside source URLs in research scratch files. Nothing else. C08 returns zero over the controlled set. | — |
| REQ-MOE-01 | PASS | I read all 14 rows of 03_Registers/ACT.csv. Every one carries a non-empty Due value; the owner is carried by the register's own column header, "Action owed by Zaid", for all fourteen. ACT-010 and ACT-012 carry conditional dates ("2026-10-31 or before the sixth client") which are still dates. | — (nine of the fourteen are past their stated due date as at the currency date; the criterion does not test that) |
| REQ-MOP-01 | PASS | C27 reports 0.912 over 171 units carrying a dollar figure, 15 unattributed. I read all fifteen: one legacy quotation and fourteen trade-study score rows quoting a figure inside the score's own justification. Above 0.90. | — (the margin has narrowed from V9's 0.951 over 164 units to 0.912 over 171, because the DEF-042 fix added twelve score-justification rows carrying dollar figures with no SRC or ASM beside them. The fix moved this requirement four points closer to its own floor) |
| REQ-AC-01 | PASS | I rebuilt $1,002.06 from scratch without calling the model: $30,000/12 = $2,500; less 10% (SRC-063) = $2,250; ÷ $103.11 (SRC-060) = 21.8214 hr; × ($43.03 × 1.1545) = $1,084.04; + $250 pool; less 1.5 × ($50.61 × 1.1545) = $87.64; less $318.75; less $7.50 = $1,002.06. AC_ClientEconomics!B17 is a live formula caching 1002.06053495854; C17 caches 435.300368749999. Both appear in study Table 15.3 on the same stated basis, and C37 reconciles fifteen figures to the cent. | — |
| REQ-AC-02 | PASS | Study Table 15.2 (index 32) and AC_ClientEconomics!A21:D27 span $10,731 (1.80 hr/wk, $894.25, $302.14) to $78,106 (13.11 hr/wk, $6,508.83, $2,749.44) over six rows. I opened all 18 value cells in formula view: every one is a live formula over A22:A27, AC_Inputs and Inputs; not one is typed. Deck slide 9 renders the same six rows. | — (Table 15.2's caption still asserts "most buy under five" hours a week, a claim about the distribution of assessed budgets that no source in the project supports — the table shows what each budget buys, not how many clients hold each budget) |
| REQ-AC-03 | PASS | $606.50 / $7,278.00 / $22,578.00 read in study Table 17.1 and finding 6, and in Structure!D5 (=B5-C5), D7 (=D5*12) and D8 (=D5*36+D6). All three are in business_plan.json. I recomputed 606.50 = 1,840.50 − 1,234.00, 7,278 = 606.50 × 12, and 22,578 = 606.50 × 36 + 744, with 744 = 21,948.60 − 21,204.60. | — |
| REQ-AC-04 | PASS | §15.1 read in full from the delivered PDF. It states the mechanism (dual care-management 15-20% plus package-management 10-15% replaced by one 10% pool, landing on cost bases built for the old structure), cites the pass by name ("an independent verification pass was run specifically to resolve it (V4)"), and names the falsifier ("the DIRECT-SERVICES line turning negative in the quarterly sector report — not the total result, which is already negative and already explained"). All three elements present. | — (the $16.10 figure that carries this requirement is still cited to [SRC-068, SRC-069, RSK-011, V4] here and in finding 5. SRC-074 carries the underlying $63.85/$47.75 and is not cited at either place. Deck slide 9 no longer carries the bad citation, which is an improvement) |
| REQ-BUS-01 | PASS | All four clauses tested myself. Twin exists: business_plan.json, 21,362 bytes, 12 top-level sections. Twelve checks: C33 runs the generator's validate() in-process, 12 of 12. Not staler than the twin: both written 08:50. Fits one A3 landscape sheet as measured in a browser: I printed it in headless Chromium with prefer_css_page_size=True, got 1 page at 420 × 297 mm, rasterised it and read the paper — three columns, sections 1 to 9, the value-validation verdict block and the footer all on the sheet, legible, nothing clipped, nothing overlapping. | — (the check that certifies it is defeatable twice over, and the footer of the delivered page still reads verified_by: "PENDING — independent verification pass V5 has not yet run against this plan" when V5 through V9 have all run and V5's own file is hash-gated in the source manifest. Neither is a property the criterion tests. Note also that the delivered registers publish this requirement as Open on V7's FAIL, which V8, V9 and I all overturn) |
| REQ-WEB-01 | PASS | 01_System/SYSTEM_BREAKDOWN.md §5 declares the slot with an explicit status — "Status in this project: SLOT DECLARED, NOT BUILT" — names GOV-B7.1/B7.2/B7.4 and states the three constraints that bind regardless. BKL-011 carries it against REQ-WEB-01. My own credential scan over the whole tree returns zero. | — (its evidence record EVD-032 now says "Produced by: PENDING V10") |
Findings that will remain open
Ordered by what they cost a reader.
F-V10-1 (Major). REQ-CON-04 fails on the delivered register workbook, and the check written to enforce it cannot see the file. 27 nine-point cells and 27 wide sheets frozen without a label column, in 03_Registers/Project_Registers_v2.0.xlsx — a Product-baseline configuration item that the study, the Help Hub and the Dashboard all send the reader to by name. C29 walks 05_Outputs only, so it reports zero on a subset and the definition of done quotes that count as proof. Cost to a reader: they open the register set on a phone, scroll right to read a risk rating or a defect status, and lose the ID column — which is exactly what the requirement exists to prevent, and the project's own paperwork tells them it cannot happen. Fixing it is small: ws.freeze_panes = "B3" in build_registers.py and a 10pt banner.
F-V10-2 (Major). The project's published requirement status is three verification passes out of date. IV_SOURCES["v2.0.0"] still names V7. V8, V9 and now V10 have all run against this same baseline. REQ.csv (both copies), the registers workbook, the Dashboard tile, the study's DoD gate 1 and C31's headline all publish REQ-SYS-03 = Verified (V8 and V9 both recorded FAIL) and REQ-BUS-01 = Open, still failing (V8, V9 and I all record PASS). C41 tests staleness against a baseline and has nothing to say about a later pass against the same one, so the builder picks which verifier counts. Cost to a reader: the two numbers on the front of the project — "30 of 32" and "FAIL — 30 of 32" — are about neither the artefacts as they stand nor the most recent verdict on them.
F-V10-3 (Major). C12, C43 and C44 are all defeatable on the defects they were written for, and none has a negative test. Details and reproductions above. DEF-048 asserts all three were "proven able to fail by rerunning V9's own attacks"; the file that would hold that proof is an hour older than the fixes and still ends "42 of 42". Under GOV-E2.4, as the project states it, these are not checks. Cost to a reader: the wrong trade-study totals, a falsified diagram range and the wrong picture in the study all pass a 44-of-44 green suite, and the suite is what the study's Appendix A and B cite as evidence.
F-V10-4 (Major). C34 still certifies a page two thirds of which can be blank paper, and no check compares a figure on the A3 page to the twin. White-on-white print CSS: 44 of 44 with columns 2 and 3, the verdict block and the footer invisible — I printed it and looked at it. All 97 dollar figures replaced with $999,999: 44 of 44. Both raised by V8 and V9. Cost to a reader: REQ-BUS-01's only mechanical guarantee is that a PDF has one page and twelve strings somewhere in its content stream.
F-V10-5 (Moderate). DEF-046 and DEF-047 each close on a false statement about their own evidence. DEF-046: "the proof is recorded in 02_Work/scratch/V5_negative_tests_business_layer.md rather than asserted in this row" — it is not in that file, and the file has not been written to since 07:37. DEF-047: "the record is now a configuration item" — CI.csv has 30 rows and none of them is T1_trade_study_weights.md; I deleted the file and got 44 of 44. This is the third consecutive round in which a defect record describes a change that was not made — DEF-043 did it about C41, DEF-046 was raised for that, and DEF-046 has now done it about itself. Cost to a reader: the defect register is the project's account of its own reliability, and parts of it are not checkable against the tree.
F-V10-6 (Moderate). The requirement amendment is attributed to a change record that does not record it. CR-007's "What changed" field describes the two-business re-baseline and says nothing about REQ-CON-04; its "Affected REQ IDs" field is prose. DEC-008, REQ-CON-04's rationale and DEF-049 all cite it. Amending an acceptance criterion inside an existing closed-scope Class 1 record rather than raising a new one is the specific manoeuvre GOV-D2 change control exists to make visible. Cost to a reader: they cannot find, from the change register, when or under whose approval the requirement's meaning moved.
F-V10-7 (Moderate). The archive and legacy-input story is still partly false, and the fix created a new count discrepancy. The v1.0.0 zip's 04_Inputs/ is empty, so DEF-001's "archived to 06_Archive/_versions", study §2's repetition of it, Appendix B's certification of compliance lines 11-16 on it, and the Dashboard's "06_Archive/_versions/ — you want the four superseded working files" are all still wrong about where those files are. 04_Inputs/legacy_unsourced/ holds five files; DEF-001, study §2, the README and the Dashboard say four; DEF-050 says five. CR-006 names NDIS_Project_v1.0.0_delivered_20260820.zip; the file is …_final_…. Cost to a reader: two of the project's recovery and provenance instructions send them to the wrong folder, and the first thing they see when they follow one is a file count that disagrees with the document that sent them.
F-V10-8 (Moderate). C42 does not read the register workbook's content. I replaced CI-004 with the v1.0.0 workbook — 26 requirements instead of 32 — touched the CSVs, and got 44 of 44. The CSV half of C42 is genuinely real; the binary half is a clock. Cost to a reader: the one artefact in the project that presents all 27 registers in one place is unprotected against substitution.
F-V10-9 (Moderate). The daily audit log is still the day-one entry, and a compliance gate is still certified on an entry that does not exist. 01_System/daily_audit_log.md has one entry, headed 2026-09-07, describing the 20 August work: "26 requirements", "53 sourced claims and 15 assumptions", "DEF-001 to DEF-003", "All 26 REQ. All 53 SRC. All 15 ASM.", "this is the first cycle", and — inside a single line — "14 actions owed by Zaid (ACT-001 to ACT-008)". The project has 32 requirements, 74 sources, 31 assumptions and 50 defects. It does not mention Part II, aged care, DEC-006 to DEC-008, CR-004 to CR-007, or DEF-004 to DEF-050. Its own breakdown of "49 items" sums to 44. And study Appendix B lines 38-41 are certified PASS on "Daily audit entry for 2026-08-20 in 01_System/daily_audit_log.md". There is no 2026-08-20 entry. Raised by V8 and V9; untouched twice. Cost to a reader: GOV-H3.8 says the first action of the next working day is to read the last entry and clear what it left open. The last entry is about a different, smaller project.
F-V10-10 (Minor, but it is the fourth pass). The $16.10 citation and the $8,757 citation are still wrong. Study finding 5 and §15.1 cite SRC-068 for the direct-services margin; SRC-074 was created for that figure and reaches neither. Table 5.1 cites "Financial Model, SupportCoordination sheet" for $8,757; the figure is in no cell of the workbook. Both raised by V6, V7, V8 and V9. Cost to a reader: the two citations they are most likely to follow — the number that carries REQ-AC-04, and the runway for the option the study recommends running alongside everything — resolve to places that do not hold them.
F-V10-11 (Minor). Assorted, each verified individually. DEC-004's Rationale field says "A3 is eliminated" one field below an Alternatives field where A3 is the support-coordination option. The callout box is headed "THE ALTERNATIVE THAT WAS SCORED AND SHOULD NOT HAVE BEEN" over a body reading "NOT scored", and repeats the A4 bullet verbatim. §6 still says "Both trade studies" when there are three. Recommendation 4 still says July 2027 is "about eleven months away"; from the currency date it is ten. business_plan.json and the A3 page still carry verified_by: "PENDING — independent verification pass V5 has not yet run against this plan". Both TS1 flip points are exact ties presented as hand-overs. Section 20's source table is captioned "Table 14.1", the same number as section 14's settled-position table. EVD-027 to EVD-032 have now been renumbered from "PENDING V6" to "PENDING V8" to "PENDING V10" without ever being resolved. C29 still reads only 148 of the deck's 194 runs because its .pptx branch iterates sh.has_text_frame and a table shape has none — nothing sub-10pt is hiding there today, but the check cannot see it. C29's exclusion set is still {basename(ci[4]) for ci in P.CI if ci[2].lower() == "zaid"}, a builder-writable owner column: change one cell and any artefact leaves the check's scope.
What I could not verify, and why
- Whether any external fact is true. I verified internal consistency, derivation and citation, not the world. I opened none of the 74 source URLs. Nothing here is evidence that $103.11, $73.58, $45.28, $43.03, $10,731, $78,106, $63.85, $47.75 or the July 2027 date are correct. Fifty-one of 74 sources sit below High confidence with a stated reason, which is honest rather than verified.
- Whether the trade-study judgements are right. I proved the arithmetic of all three studies reproduces and that the sensitivities do. Whether A1's capital deserves a 2 and A2's a 5 is a judgement no verification pass can settle, and the project is right to escalate DEC-003 and DEC-007 rather than decide them.
- Whether trade study 1's weights really were fixed before its scores. The record now exists and says plainly that it does not prove this. I can confirm the file is honest; I cannot confirm the ordering, and neither can anyone else.
- Whether the new A3 is the best available third alternative. It is lawful, credible and costed from figures I traced. Whether staged registration, a partnership or contracting to an existing provider would have been stronger is not something I can test. I note that A3's distinguishing feature — running support coordination during the window — is also what the study's recommendation 3 tells the owner to do under A2, which makes A3 less independent of A2 than a trade study wants.
- Print behaviour on any engine but Chromium. I measured with headless Chromium via Playwright, which is what C34 drives, rasterised the output at 60 dpi and looked at it. I did not test Word, Safari, Firefox or a physical printer.
- Whether the Decision Pack renders as designed. I read every run, every table cell and every font size through python-pptx. I did not render the twelve slides, so I cannot speak to overflow, overlap or contrast.
- Eleven of the twelve diagrams. I read D5's underlying matrix and confirmed all twelve as files on disk and as content-hash-matched embeds. I did not view D1, D2, D3, D4, D6, D7, D8, D9, D10, D11 or D12 as images this pass — and, as F-V10-3 shows, nothing in the suite would notice if they were the wrong pictures.
- Whether my own verdicts survive transcription. C41 now compares this file's machine-readable block line by line against what the project transcribes and refuses a second block, which is worth something. But this file is not hash-gated, no verification report is in
SOURCE_MANIFEST.json, and the project is at present transcribing a report three passes old while leavingIV_SOURCESuntouched. Nothing mechanically prevents a builder from editing the block below, or from never reading this file at all.
Closing verdict
31 of 32 requirements PASS.
REQ-SYS-03 is closed, and closed properly. The arithmetic reproduces, §6.1 introduces the alternatives that are actually scored, DEC-004 publishes 0.60 and 37 per cent in all three delivered copies, and T1_trade_study_weights.md is the most honest document in this project — it says what it cannot prove, cites the rule that gives a builder's word no weight, and does not backdate itself. That is what a fix looks like.
REQ-CON-04 is not closed, and the way it failed this round is worse than the way it failed last round. The project widened the requirement's scope from a flat six-column rule to "every delivered Office artefact", correctly, on reasoning I checked and agree with — and then left the enforcing check pointed at a single folder, so the second delivered workbook fails both halves of the new criterion and reports zero. C29's own docstring names that failure: "A green check over a subset is worse than no check, because the definition of done cites its counts as proof." The instrument that closed DEF-028 has committed DEF-028.
Read the rest before the count. Five of the six checkers I attacked fell, four of them to attacks V9 published in writing three hours earlier, and I put V8's exact wrong trade-study totals back onto the face of the delivered study and got 44 of 44 green from the check written specifically to stop that. The pattern this project has repeated through V6, V7, V8, V9 and now V10 is not that it fixes things badly — the DEF-042 work was excellent — it is that it writes a checker against the instance it was shown and then records the class as closed. C43 was told about a substring bug and now reads tables, keyed on a header. C12 was told about byte-identical copies and now hashes. C44 was told about three regexes and now has a dozen, two of which are case-mismatched and can never fire. Each closes the demonstrated attack and nothing adjacent to it. And in three consecutive rounds a defect record has asserted a fix or an evidence file that does not exist — DEF-043 about C41, then DEF-046 about its own negative test, then DEF-047 about a configuration item. When the register that records the project's reliability is itself unreliable in the same way three times running, that is the finding, not the individual defects.
Finally, and independent of any of this: the delivered registers still publish requirement status derived from verification pass V7. Two independent passes have ruled since, both against this same baseline, and neither was transcribed or refused in writing. The project is shipping a "30 of 32" that is not the verdict of the most recent verifier, and it will ship this one the same way unless someone moves IV_SOURCES.
Left behind: nothing. Every attack ran in /tmp/v10/* sandboxes; 01_System/checker_run_log.txt still carries the builder's 08:50:09 run and 01_System/SOURCE_MANIFEST.json is still gated at 2026-09-07T08:50:09. find . -newermt "2026-09-07 08:51" -type f returns nothing but this file, and find . -name __pycache__ -o -name "*.pyc" returns nothing. python 01_System/tidy.py --report returns TIDY PASS — placement map satisfied: no loose root files, no debris, no secret stores, no links to live files, no unknown folders, no missing mandated folders. V9's orphaned BUSINESS_PLAN_A3.html.probe.pdf is gone — C34 now deletes its print probe in a finally block. This report is the only thing I added to the tree.
MACHINE-READABLE VERDICTS
REQ-SYS-01=PASS
REQ-SYS-02=PASS
REQ-SYS-03=PASS
REQ-SYS-04=PASS
REQ-SYS-05=PASS
REQ-SYS-06=PASS
REQ-SYS-07=PASS
REQ-SYS-08=PASS
REQ-SYS-09=PASS
REQ-SYS-10=PASS
REQ-SYS-11=PASS
REQ-SYS-12=PASS
REQ-SYS-13=PASS
REQ-SYS-14=PASS
REQ-SYS-15=PASS
REQ-SYS-16=PASS
REQ-SYS-17=PASS
REQ-SYS-18=PASS
REQ-CON-01=PASS
REQ-CON-02=PASS
REQ-CON-03=PASS
REQ-CON-04=FAIL
REQ-CON-05=PASS
REQ-CON-06=PASS
REQ-MOE-01=PASS
REQ-MOP-01=PASS
REQ-AC-01=PASS
REQ-AC-02=PASS
REQ-AC-03=PASS
REQ-AC-04=PASS
REQ-BUS-01=PASS
REQ-WEB-01=PASS