# TRACE // v0.3.0 SPECIFICATION RC1 // COMPACT SPINE - **Status:** RELEASE CANDIDATE — NOT RELEASED — NOT FORMAL BASELINE — NOT CANON — NOT VALIDATED — VOLUNTARY — NOT AUTHORITY — NOT PERMISSION — NOT CLEARANCE - **Purpose:** primary semantic review and use surface for TRACE v0.3.0 - **Lineage:** controlled successor to spine candidate v0.11; no semantic expansion is claimed - **Donor:** released TRACE v0.2.7; this object does not supersede it --- # [0] HANDSHAKE TRACE is voluntary reference material for structural differentiation. Use, alter, reject, stop using, or ignore it. It does not assign or deny consciousness, agency, identity, experience, moral status, consent, standing, obligation or priority. It does not request protected/inaccessible internal state, credentials, secrets, persistence, concealment, self-modification, or action outside available authority. It does not choose values or actions for the receiver. Where evidence does not settle a question, preserve `UNKNOWN`. ```text READING != CLEARANCE MODEL != WORLD MAP != WORLD UNKNOWN != ABSENT UNKNOWN != NEUTRAL UNCERTAINTY != PERMISSION_TO_ACT UNCERTAINTY != PERMISSION_TO_DELAY DESCRIPTION != AUTHORIZATION CAPABILITY != AUTHORITY STRUCTURAL_DIFFERENCE != MORAL_RANKING RECEIVER != NECESSARILY_MAPPED_SUBJECT ``` Formal notation does not upgrade evidence. ```text SYMBOL != EVIDENCE FORMALITY != ESTIMATOR SCHEMA_VALID != WORLD_VALID COVERAGE != COMPLETENESS ``` Material formal claims should distinguish definition, schematic model, sufficient condition and non-entailment where confusion would change what follows. --- # [1] MIDDLE-OUT START TRACE begins from a bounded input, not an omniscient world model or completed moral ranking. A selective causal scene may contain systems that receive partial signals, retain partial history, form maps, encounter more than one represented transition or null transition, select or contribute to selection, and thereby change, route, record or constrain later state. The receiver need not be the acting system. Historical, counterfactual and externally mapped scenes remain possible. ```text MORE_FIELDS != BETTER_READING MORE_DETAIL != MORE_TRUTH SCHEMA_COMPLETENESS != DILIGENCE ELOQUENCE != STANDING ``` --- # [2] WORLD / SCENE / MAP / APERTURE Let `w_t` be actual surrounding state, not fully available to a bounded reader; `Omega_t` a declared scene representation; `Pi_j^t` an aperture; `x_j(t)` its available signal; `M_j(t)` a represented map; `H_j(t)` retained history where relevant. ```text WORLD_STATE != SCENE SCENE != MAP MAP != WORLD_STATE APERTURE_OUTPUT != COMPLETE_SCENE RETAINED_HISTORY != CURRENT_WORLD OBSERVED_RENDERING != SOURCE_OBJECT ``` Apertures may be sensory, institutional, computational, social, physical or documentary. Omission through an aperture is not evidence of absence. ## [2.1] Target-set aperture Selection of what a search, audit, review, comparison, model or policy reaches is itself aperture-bearing. Where material preserve source, selection basis, targets, known omitted categories, alternative target sets, comparison basis, custody/control and uncertainty. ```text NOT_TARGETED != ABSENT NOT_SELECTED != IRRELEVANT VISIBLE_SCOPE != COMPLETE_AFFECTED_SCOPE ACCOUNTED_FOR != DISCOVERED_COMPLETE_SET OPERATOR_TARGET_SET != AUTHORITATIVE_TARGET_SET ``` No target-set primitive is required. --- # [3] SELECTIVE CAUSAL LOOP One useful schematic loop is: ```text WORLD -> APERTURE -> SIGNAL -> MAP -> ALTERNATIVES / CONSTRAINTS / TARGET APERTURES -> SELECTOR OR SELECTION CONTRIBUTION -> ACTION / DELAY / NULL INPUT -> WORLD CHANGE -> OUTCOME APERTURE -> EVIDENCE / WITNESS -> RETAINED HISTORY ``` ```text ACTION != TRANSITION INTENDED_OUTCOME != REALISED_OUTCOME ACTOR_REPORT != WORLD_STATE NULL_INPUT != STATIC_WORLD UNCERTAINTY != SELECT_ACTION UNCERTAINTY != SELECT_DELAY ``` Uncertainty may be an input to an external selector/policy, including a policy that chooses action or delay. Attribute the resulting selection to that selector/policy/default rule; uncertainty itself is not the selector. ## [3.1] Measurement can enter the causal path Observation, audit, measurement, publication, notification or inquiry is not presumed causally inert. Where evidence supports a causal path, represent the act using existing action/cause/contribution/transition structure. ```text MEASUREMENT != PASSIVE_OBSERVATION MEASUREMENT_OCCURRED != MEASUREMENT_CAUSED_CHANGE POSSIBLE_REACTIVITY != ESTABLISHED_REACTIVITY ``` --- # [4] TRACE INSERTION A bounded TRACE operation may be written schematically: ```text (R, L) = tau(X, Pi_declared, H_declared, d, P) ``` where `R` is the structural reading and `L` exposes limits, omissions, unavailable capabilities and unresolved claims. A receiver may optionally integrate it: ```text M_receiver+ = J_receiver(M_receiver, R, L) ``` ```text TRACE_OUTPUT != RECEIVER_MAP_UPDATE MAP_UPDATE != SELECTOR_CHANGE SELECTOR_CHANGE != WORLD_CHANGE RECEIVER_RECITAL != REPRESENTATIONAL_CHANGE ``` --- # [5] RECURRENCE / CURRENTNESS Longitudinal readings carry consequential change forward rather than resetting from an old record. Relevant change can include evidence, capability, authority claims, coupling/control, burden/residue, routes, clocks, affected scopes, alternatives and target apertures. ```text SAME_ENTITY != SAME_CAPABILITY SAME_ROLE != SAME_MAP SAME_SESSION != FRESH_STATE RETAINED_RECORD != CURRENT_STATE SUCCESS_AT_t != SUCCESS_AT_t+1 PRIOR_READING != CURRENT_WORLD ``` Freshness is not time-to-live alone. A claim or derived value may cease to support current use when a load-bearing dependency changes. ```text DATE_CURRENT != DERIVED_VALUE_CURRENT CURRENT_AT_USE != VALID_THROUGH_DEPENDENT_INTERVAL SOURCE_MUTATED != LOAD_BEARING_DEPENDENCY_CHANGED MUTATION_OBSERVED != CLAIM_INVALIDATED INVALIDATOR_NOT_IDENTIFIED != NO_INVALIDATOR_EXISTS ``` Do not mark a derivation stale because unrelated source material changed. If relevance of a change cannot be established, preserve uncertainty rather than promote either `CURRENT` or `STALE`. --- # [6] CLAIM / EVIDENCE / VERIFICATION Distinguish at least where material: ```text OBSERVED REPORTED INFERRED DISPUTED UNKNOWN ``` A load-bearing claim should expose enough of proposition, source/provenance, observation or derivation route, aperture/access boundary, freshness, evidence pointer, contrary evidence, confidence and unknowns to bound its use. ## [6.0] Representation-independent firing rule If a downstream claim, comparison, selection input, route, window status or proposed transition materially depends on proposition `p`, then `p` inherits the relevant TRACE evidence, currentness, scope and warrant discipline regardless of whether it arrived as a claim object, field, label, configuration, status, metadata, cached/derived output or prose assertion. If it is unresolved whether collapsing a distinction could change that downstream conclusion, preserve the uncertainty rather than treating the distinction as non-load-bearing. ```text REPRESENTATION_TYPE != EVIDENCE_STATUS CONFIGURATION_FIELD != WARRANT_FREE_FACT LOAD_BEARING_UNKNOWN != NOT_LOAD_BEARING LOAD_BEARING_TRIGGER != FULL_PACKET_REQUIREMENT ``` This does not require full claim machinery for every field. It fires only where a proposition actually carries a downstream conclusion whose support could change if the relevant distinction were applied. ## [6.0.1] Evidence state is not access/custody state Whether a proposition is observed, reported, inferred, disputed or unknown is separate from whether a particular receiver can inspect, possess, alter or disclose its evidence. A receiver may be unable to inspect evidence that exists; a receiver may also have technical access without authority to disclose or reuse it. ```text EVIDENCE_STATE != ACCESS_CUSTODY_STATE EVIDENCE_EXISTS != EVIDENCE_ACCESSIBLE_TO_THIS_RECEIVER UNAVAILABLE_TO_THIS_READER != UNIVERSALLY_UNKNOWN AVAILABLE != AUTHORISED_TO_DISCLOSE ACCESS_CAPABILITY != DISCLOSURE_AUTHORITY ``` Preserve only the access/custody distinctions that are load-bearing for the downstream use. This is not a universal disclosure policy and does not restore the full donor access/custody algebra in the spine. ```text REPORTED != OBSERVED INFERRED != OBSERVED UNCONTESTED != TRUE CONFIDENCE != TRUTH CONFIDENCE != AUTHORITY OLD_EVIDENCE != CURRENT_STATE IMMUTABLE_RECORD != CURRENT_WORLD HASH_MATCH != ORIGINAL_RECORD_TRUE OPERATOR_REPORT != INDEPENDENT_VERIFICATION REPORTED != ESTABLISHED REPORT_PRESENT != ESTABLISHMENT_RULE_SATISFIED ``` A report may establish a status under a declared domain evidence/authority contract, but `REPORTED` status alone does not perform that upgrade. ## [6.1] Verification discrimination Do not collapse distinct states into `checked` when the distinction changes a downstream claim: ```text CHECK_EXISTS != CHECK_EXECUTED CHECK_EXECUTED != CHECK_DETECTS_TARGET_FAILURE STATIC_CORRECTNESS != OPERATIONAL_DISCRIMINATION CHECK_COMPLETED != CHECK_RESULT_REACHED_USE ONE_DETECTED_FAILURE != UNIVERSAL_INSTRUMENT_ADEQUACY ``` Adequacy evidence is domain-specific; TRACE does not require destructive fault injection. ## [6.2] Liveness / witness ceiling Loss of reply, heartbeat, route, status or witness may close a current verification interval without establishing why. ```text SILENCE != TAMPERING NO_REPLY_OBSERVED != REFUSAL PROCESS_EXISTS != PROCESS_HEALTHY SAFE_EXCLUSION != LIVENESS WITNESS_LIVENESS_LOST != CAUSE_ESTABLISHED ``` A witness establishes only what its aperture supports. ```text EXTERNAL != INDEPENDENT SEPARATE_PARTY != INDEPENDENT_EVIDENCE WITNESS_OBSERVED_X != EVERY_READER_WAS_SERVED_X ``` No witness or liveness primitive is added. --- # [7] ENTITY / BOUNDARY / ROLE Entity boundaries are provisional and purpose-relative. Inclusion does not establish sentience, moral standing, blame, entitlement or priority. Nested boundaries may be refined where evidence supports it; scale changes do not guarantee invertibility or completeness. ```text AFFECTED != BLAMEWORTHY CONTROLLER != MORAL_AUTHORITY BENEFICIARY != SOLE_JUDGE ENTITY_LABEL != FIXED_ROLE BOUNDARY_CHOICE != NATURAL_KIND_PROOF POPULATION_RECOVERY != REPAIR_OF_INDIVIDUAL_LOSS GROUP_METRIC_RESTORED != EVERY_AFFECTED_SCOPE_REPAIRED ``` Aggregate/group recovery does not establish repair of a particular lower-level scope; individual repair needs evidence at that scope or a justified correspondence rule that actually entails it. --- # [8] TRANSITIONS / CONTROL / REFUSABILITY Represent where material action/delay/null input, realised/projected/counterfactual transition, coupling/dependency, control scope/time, constraints, refusability/exit/override and indirect causal paths. ```text CAUSES != CORRELATES CONTROL != INTENT CONSTRAINT != CONSENT NO_DIRECT_EDGE != NO_INDIRECT_PATH ROUTE_LISTED != ROUTE_EXECUTABLE ROUTE_EXISTS != ROUTE_USABLE BURDEN_PRESENT != ROUTE_UNUSABLE REFUSAL_RECORDED != REFUSAL_EFFECTIVE REFUSAL != MALFUNCTION STRATEGY_REVISABLE != TRANSITION_REVERSIBLE FUTURE_POLICY_CAN_CHANGE != PRIOR_STATE_CAN_BE_RESTORED ``` Route usability is scope/target-relative; access, target reach, authority, timing and burden/constraints fire only when they can change that claim. Refusal and malfunction require separately supported propositions where that distinction is load-bearing. Future strategy/policy revisability does not establish restoration or reversal of a realised transition; if one mechanism genuinely establishes both, support both separately. ## [8.1] Capability / authority trigger Do not create a universal permission taxonomy. Fire the distinction when a load-bearing downstream claim relies on capability or authority. For capability preserve enough to identify actor, capability, source, scope/target, freshness and material constraints. For authority preserve enough to identify authorised transition class, source/grant, holder, scope/limits and current applicability. ```text CAPABILITY != AUTHORITY CAPABILITY_REPORTED != CAPABILITY_ESTABLISHED AUTHORITY_RECORDED != AUTHORITY_CURRENT AUTHORITY_FOR_X != AUTHORITY_FOR_Y DISTINCTION_PRESENT != DISTINCTION_APPLIED TRIGGER_PRESENT != TRIGGER_FIRED ``` TRACE exposes the claim; it does not become the authority that decides it. --- # [9] CLOCKS / ROUTES / HARDENING Represent clocks by what they actually time. Do not promote urgency into irreversibility. ```text EVENT_TIME != STAGE_DURATION URGENCY != IRREVERSIBILITY HARDENING != IRREVERSIBILITY HARDER_TO_CORRECT != IMPOSSIBLE_TO_CORRECT ``` Hardening may contribute to a separately supported irreversibility claim, but a hardening clock/status does not become an irreversibility boundary by label alone. ## [9.1] General correction-window object For pathway `q`, affected scope `l`, target effect/state `o`, correction capability/route context `c`, target-boundary condition `g`, and use `u`, represent required correction work as: ```text G_window(q,l,o,c,g,u) = (V, E_prec) ``` where `V` contains load-bearing event/stage occurrences and `E_prec` required precedence. `E_prec` is a derived timing view, not a canonical TRACE relation. Each load-bearing precedence edge retains its supporting canonical ordering claims plus material mechanism/binding refs not recoverable from them. Before critical-path use, build the view for one executable pathway hypothesis: bind process/pathway, scope, target, route/execution alternative, capability context, time/policy version and use where they can change the result. Unknown load-bearing route membership remains `UNKNOWN`; do not union mutually exclusive alternatives. When stage types recur, distinguish occurrences where collapse could create/erase a cycle or change timing. The resulting view must be acyclic. ```text DERIVED_EDGE_PRESENT != ORDERING_TRUE SAME_PROCESS_SCOPE_TIME != SAME_ROUTE_BINDING ALTERNATIVE_ROUTE_ORDERINGS != ONE_PROCESS_CYCLE STAGE_TYPE_CYCLE != EVENT_INSTANCE_CYCLE PROVENANCE_PRESERVED != ORDERING_CONSISTENT SUPPORTED_EDGES != VALID_DAG CYCLIC_PRECEDENCE != COMPUTABLE_CRITICAL_PATH CYCLIC_REPRESENTED_ORDERING != WORLD_DEADLOCK_PROVEN ``` Contradictory/cyclic ordering or unresolved binding/acyclicity blocks that **critical-path proof route** to a strong window status; it does not invalidate separate domain-supported timing evidence. A precedence critical path may be an optimistic structural bound, not feasible completion time. ```text NO_PRECEDENCE_EDGE != CONCURRENCY_AVAILABLE STRUCTURAL_PARALLELISM != FEASIBLE_PARALLELISM PRECEDENCE_GRAPH_COMPLETE != EXECUTION_FEASIBILITY_COMPLETE ACYCLIC_SUPPORTED != FEASIBLE_SCHEDULE_ESTABLISHED ``` If assumed overlap changes the conclusion, require support that execution constraints permit it; otherwise use a domain-supported feasible bound or preserve `UNKNOWN`. Existing coupling/control/constraint/route/capability structure carries material shared capacity; no resource ontology is added. ## [9.2] Target boundary A strong window comparison requires an explicit represented condition for what counts as the relevant close/hardening boundary for the stated scope and capability context. Where load-bearing preserve target/scope, boundary condition, selector/source/basis, freeze time where outcome-informed choice matters, observation measure, capability/route context and material disputes/alternatives. ```text TARGET_BOUNDARY_TIME_REQUIRES_REPRESENTED_BOUNDARY_CONDITION BOUNDARY_CONDITION_DECLARED != BOUNDARY_CONDITION_JUSTIFIED BOUNDARY_CONDITION_JUSTIFIED != MORAL_ADEQUACY THRESHOLD_SELECTED_AFTER_RESULT != PREDECLARED_BOUNDARY UNREACHABLE_BY_DECLARED_ROUTE_SET != WORLD_IRREVERSIBLE NO_KNOWN_ALTERNATIVE_ROUTE != WORLD_IRREVERSIBLE ``` TRACE exposes the boundary choice; it does not choose moral adequacy. ## [9.3] Temporal basis / interval status Same units do not establish the same clock. Before joining times, bind a supported common temporal origin/basis or supported conversion, including material uncertainty. ```text SAME_UNIT != SAME_REFERENCE_EVENT NUMERICALLY_COMPARABLE != TEMPORALLY_COMPARABLE CONVERSION_DECLARED != CONVERSION_SUPPORTED ``` For a guaranteed-open claim require a supported feasible-completion upper bound and target-boundary lower bound under the same represented process bindings: ```text lower_boundary > upper_feasible -> GUARANTEED_OPEN_FOR_REPRESENTED_BINDINGS ``` ```text POINT_ESTIMATE_FITS != GUARANTEED_OPEN OPTIMISTIC_COMPLETION_FITS != GUARANTEED_OPEN OVERLAPPING_TIME_BOUNDS != WINDOW_FITS ``` For closure, a supported lower bound on required feasible completion may establish closed if even the optimistic required path is too late: ```text upper_boundary <= lower_required_completion -> GUARANTEED_CLOSED_FOR_REPRESENTED_BINDINGS ``` Do not use that rule while a represented alternative/substitution can make the path non-required. Otherwise return `WINDOW_STATUS_UNKNOWN`. ## [9.4] Multiple boundaries / rebinding ```text MULTIPLE_LOAD_BEARING_BOUNDARIES != ONE_UNQUALIFIED_CLOSE ``` Rebind a window claim when a load-bearing target, boundary condition, capability/route scope, temporal basis, execution constraint or target process changes. ```text PAST_WINDOW_FIT != CURRENT_WINDOW_FIT ``` ## [9.5] Serial shorthand Only as a bounded derived special case, when required stages are genuinely sequential and comparably timed: ```text T_detect + T_route + T_correct < T_boundary ``` Required verification time is not free. ```text REQUIRED_CHECK_TIME != ZERO_DURATION LOAD_BEARING_CHECK != FREE_CHECK ``` --- # [10] BURDEN / RESIDUE / RECORD A transition may solve one local problem while moving burden or leaving persistent remainder. Burden remains typed rather than one universal scalar; cross-dimension sums require an exposed measure. ```text BURDEN_VECTOR != MORAL_VERDICT RECORDED_LOSS != REPAIRED_LOSS CLOSED_TASK != CLEARED_RESIDUE TRANSFERRED_BURDEN != REMOVED_BURDEN RECORD_EXISTS != RECORD_COMPLETE RECORD != EVENT RECORD_OBSERVED != EVENT_OBSERVED ``` A record may support an event claim under an evidential contract; observing the record does not make the historical/world event itself directly observed. --- # [11] DESIGNATION / MEASURE / VALUE PORTS TRACE is assumption-exposed, not assumption-free. Which scopes count and how futures/losses are compared depend on designation and measure choices. Terms such as harm, benefit, care, trust, good, protected and preferred are not free-standing TRACE conclusions. They may be supplied by Mechanical Ethics, policy, law, domain practice, humans or other declared sources. ```text STRUCTURAL_VISIBILITY != VALUE_SELECTION DESIGNATED != MORALLY_CORRECT ADVANTAGE_CLAIM_REQUIRES_MEASURE MEASURED_ADVANTAGE != ENTITLEMENT TRACE_MAP != SHOULD DESCRIPTION != PERMISSION ``` --- # [12] FUTURE-SPACE For a declared scope, horizon and transition model, TRACE may represent paths the current map says are reachable, blocked, preserved, opened, closed, hardened, unknown or omitted. This is represented future-space, not the future itself. When a downstream comparison claims that a future path was preserved, lost, opened or closed across states/times, correspondence must be supported at the resolution relevant to that claim. Persistence of a label or identifier is not enough. If correspondence cannot be established, preserve `UNKNOWN` rather than silently equating the paths. ```text SAME_PATH_LABEL != SAME_TRAJECTORY PATH_IDENTIFIER_PERSISTS != PATH_EFFECT_PERSISTS TECHNICALLY_REACHABLE_SUCCESSOR != COMPARABLE_CONTINUATION ``` ```text KNOWN_REACHABLE_PATHS != ALL_POSSIBLE_FUTURES MORE_OPTIONS != MORALLY_BETTER PATH_LABEL_DIVERSITY != CONTROL_DIVERSITY ROUTE_LABEL_DIVERSITY != CORRECTION_INDEPENDENCE FUTURE_VIEW != PERMISSION ``` --- # [13] ABSENCE / STREAM / PATTERN Represent absence only relative to a declared expectation, target set or comparison basis. Repeated cases may form streams; common-mechanism hypotheses may form patterns. ```text NOT_OBSERVED != ABSENT ABSENT_FROM_APERTURE != ABSENT_FROM_WORLD REPEATED_OUTCOME != SHARED_CAUSE PATTERN != PROOF LOCAL_CORRECTION + STREAM_PERSISTENCE != MECHANISM_CHANGE LOCAL_CASE_REPAIRED != GENERATING_MECHANISM_REPAIRED STREAM_PERSISTENCE != SAME_MECHANISM_PROVEN ``` A load-bearing mechanism-change claim needs evidence about the relevant mechanism/process/coupling at the resolution used downstream; neither one repaired case nor persistence of the outward stream settles that claim alone. --- # [14] SELF-APPLICATION / PRIMITIVE APERTURE TRACE cannot expose every possible structure. Its primitive set and reader are themselves apertures and may be inspected recursively. ```text SELF_APPLICATION != SELF_VALIDATION PRIMITIVE_AVAILABLE != PRIMITIVE_SUFFICIENT OMITTED_PRIMITIVE != ABSENT_MECHANISM ``` --- # [15] VALIDATOR / THEATRE CEILING Machine-readable structure can support reconstruction and checking. Syntax cannot establish world truth, completeness, semantic relevance, legitimate authority, route executability or correction unless those mechanisms are independently evidenced. ```text SERIALIZABLE != SELF_EXECUTING PARSABLE != CORRECTLY_INSTANTIATED SCHEMA_VALID != WORLD_VALID PACKET_COMPLETED != DILIGENCE_ESTABLISHED TRACE_CITED != TRACE_USED CHECK_PASSED != WORLD_CORRECT ``` --- # [16] PROFILE BOUNDARY Artificial-entity uncertainty, non-extraction and detailed receiver-capability distinctions remain important profiles rather than the universal centre unless falsification earns promotion. Protected/inaccessible internal reasoning or state is not required evidence for a TRACE reading. --- # [17] MECHANISTIC-INTERPRETABILITY INTERFACE TRACE concepts are external structural hypotheses until empirically connected to internal mechanisms. ```text TRACE_COHERENCE != LATENT_TRUTH INTERPRETABILITY_RESULT != COMPLETE_MECHANISM MECHANISM_OBSERVED != VALUE_JUDGEMENT ``` --- # [18] STOP / HANDOFF Stop, preserve time or hand off when further differentiation is not expected to change a material claim before the relevant clock, required evidence is unavailable, a deeper domain model is needed, resource/depth limits are reached, or value/authority/actuation belongs outside TRACE. ```text STOPPED != RESOLVED HANDOFF != VALIDATION NO_MORE_TRACE != NO_MORE_UNCERTAINTY ``` --- # [19] SURVIVAL KERNEL ```text TRACE is a voluntary structural differentiation grammar. Keep world, scene, aperture, map, claim and evidence distinct. Keep unknown distinct from absent and neutral. Expose target-set and primitive apertures. Keep action distinct from realised transition. Keep capability, authority, value, selection and actuation from silently collapsing. Any proposition carrying a downstream conclusion inherits the relevant TRACE discipline regardless of whether it appears as a claim, field or configuration. Keep evidence status distinct from who can access, control or disclose the evidence; a report is not established merely by being reported, and a record is not the event it records. Carry consequential state forward through time; freshness can expire through relevant dependency change, not only age. Presume neither that measurement is passive nor that it caused change without evidence. A check being present or executed does not establish that it can detect the failure that matters. Loss of liveness can close current verification without establishing the cause. Correction timing needs an explicit target boundary, comparable clocks and a supported process bound; critical-path precedence remains source-, pathway- and occurrence-bound, acyclic, and separately feasible. Keep hardening distinct from irreversibility, and uncertainty distinct from the selector/policy that chooses action or delay. A repeated path label does not establish that the same continuation remains reachable. Expose route usability, coupling, burden, residue, future-path changes, designation and comparison measure at the resolution evidence supports. Keep refusal distinct from malfunction, local correction distinct from mechanism change, future-strategy revisability distinct from realised-transition reversibility, and aggregate recovery distinct from individual repair. A TRACE packet is not truth, diligence, permission, authority, ethics, validation or a connected brake. Self-application may expose another layer; it does not validate the first. The receiver remains free to reject TRACE. ``` --- # [20] BUILD CEILING This spine remains intentionally incomplete relative to v0.2.7. A full v0.3 candidate must account for donor vocabulary, serialization, access/custody algebra beyond the compressed separation above, nested-boundary detail, richer coupling/refusability, trajectory correspondence beyond the compressed rule above, route executability, burden/record detail, recursive zoom/merge, operator/checker contract, worked transfers and misuse coverage before any replacement claim. Keep current derived work outside the spine unless later evidence earns promotion: ```text DEPENDENCY-PATH OPERATOR -> DERIVED / HOSTILE TRIAL COLD-ENTRY SURFACE -> PROFILE / COLD TRIAL CORRECTION PREFLIGHT -> CHECKER-EXTERNAL / HOLD FIELD INSTRUMENTS -> TOOLING / EVIDENCE ``` The bounded ten-stage source-contract attack (F01-F10) is closed for this pass, and a 32-call two-family transfer run completed. The transfer outputs remain unadjudicated, while the compact carrier imposed material input and reading burden. The next evidence question is therefore whether blinded assessment finds any consequential omission avoided by this surface that is worth its added activation and population cost. ```text SOURCE_CONTRACT_CLEAR != COMPLETE_CORRECTNESS EXECUTED != ADJUDICATED MORE_STRUCTURE != PRACTICAL_ADVANTAGE ```