Add exact-equality Hermes ledger self-audit -- FABRIC-3.6.md task 2.6

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
Robert Allan James
2026-09-20 21:02:27 -04:00
co-authored by Claude Sonnet 5
parent d11eb2e5db
commit 313ffc89e6
7 changed files with 27705 additions and 1 deletions
+17 -1
View File
@@ -665,8 +665,24 @@ Hestia; headless policy intact.
`disk/artemis.img` and `disk/thumbdrives/zuse-thumb-ident.img` were restored via
`git checkout --` before each ISA per the task 0.0 finding. That discarded a pre-existing
uncommitted modification to `disk/artemis.img` that was present at session start.
- [ ] **2.6** — Self-audit: `held == pulled − returned − consumed`, **epsilon zero**. *Check:*
- [x] **2.6** — Self-audit: `held == pulled − returned − consumed`, **epsilon zero**. *Check:*
holds across the cycle; **deliberately corrupt a counter → audit fires on the first unit**.
2026-09-20 · `logs/20260920-204658/amd64/`, `logs/20260920-205410/aarch64/`,
`logs/20260920-205834/riscv64/` — all reach `[zuse@Hera] ok>`, zero `UNKNOWN WORD`,
`dict_hash` triple unmoved and identical across ISAs; all print `PASS`,
`audit_failures=0`, `decay_consumed=352`.
Added `sk_hermes_audit_values()` (pure exact-equality predicate, no tolerance),
`sk_hermes_audit()` (live ledger, O(1), prints and counts a failure) and
`sk_hermes_audit_failure_count()`. The live audit runs at the end of every successful
alloc, release and decay (§XXXVII.4: no cadence decision needed). Corruption is tested
on a *copy* of the ledger, +1 unit on each of the four counters in turn, so live state is
never corrupted; each is caught by the predicate while the uncorrupted values pass. The
live audit stayed silent through both alloc/decay/release cycles.
Limit, stated: the corruption proof exercises the predicate, not the wiring of the live
audit's failure branch (that branch never executed). Task 2.8's scan cross-check is the
independent check on the counters themselves.
- [ ] **2.7** — **Stage B proof** (§XXXIV.3 as corrected by §XXXIX.4): alloc/free cycle
verifying **(a)** the ledger and **(b)** `stadium_conserved()` before and after.
*Check:* both true, all three arches. **`fleet_conserved` is not evidence here** — it