core/docs/assessment/10-layer-cards/M0-substrate.md
Shay 36cb29a693 docs(assessment): Phase 2 — nine layer cards, verified against code not documents
Fills the taxonomy with evidence. Every liveness label re-verified at
8927c563 rather than inherited from the 2026-06-09 system map. Three
inherited claims did not survive, and every one of them came from a
document while every falsification came from reading code.

CORRECTIONS:

- Phase 0 Finding 0-C was WRONG. The L11 always-on process IS BUILT:
  chat/always_on.py::run_continuous, chat/always_on_daemon.py::run_daemon
  (single-instance lock, SIGINT/SIGTERM stop, load-time identity guard),
  CLI `core always-on`. Landed 2026-06-14 — five days AFTER the system-map
  snapshot that declared no forever entrypoint exists. The real finding is
  sharper: built, with a complete falsifiable soak harness, never run to a
  recorded artifact, and enforced by NO SUITE AT ALL.
- CR-1 attention/allocation is not a missing layer but a live undocumented
  one: generate/stream.py:255-263 runs SalienceOperator -> AttentionOperator
  and gates every generation step; use_salience defaults True. It owns the
  ~73%-of-turn hot path and has no ADR, no card, no layer in any ratified
  articulation. (generate/salience.py COMPOSES core.physics.salience — not
  a duplicate; that false lead is recorded, not propagated.)
- CR-2's components exist: DriveGradientMap and ExertionMeter are both
  constructed in chat/runtime.py. DriveGradientMap is NEVER READ — textbook
  decoration by the sabotage test. ExertionMeter runs but feeds telemetry
  only; fatigue gates no decision. The claim survives and sharpens: CORE has
  drive objects and no chooser.

STAGE-COVERAGE AUDIT: 7 of 9 covered; non-text ingest uncovered (59
sensorium modules reach no serving path); the cycle's runner claimed-only.

CROSS-CUTTING: F-1 built-and-off is the dominant pattern (17 flags default
False, only deduction_serving ratified ON) with no register of the set or
what would flip it. F-2 enforcement lags capability — orphaned pins are
undetectable because suite tuples are hand-curated. F-3 formation's
six-boundary trust standard is not applied at M2, the surface facing
untrusted user text. F-4 ADR/code contradictions are load-bearing (the
daemon has no ADR while ADR-0146 rejected the daemon shape; ADR-0252's
"34 surface organs" does not reproduce — 18 found). F-5 what is excellent,
stated plainly: the typed learning boundary, selection-not-rewrite, the
non-hardening invariant, fail-closed lane shapes.

No layer is wrong-solution. Two candidates deferred to Phase 4 with
evidence: Wilson/replay independence in licensing, DriveGradientMap.
2026-07-27 15:45:52 -07:00

6.9 KiB
Raw Blame History

M0 — Substrate

Kind: layer · Parent: CORE · Assessor: Opus 5 (Phase 2) Verified at: 8927c563 (2026-07-27) Liveness: live-serving · Fitness: fit · Topology role: runtime boundary

The medium, not the mind. Per the governing mental model, the field is the electricity and the intelligence is in the wiring — M0's entire job is to be a substrate so well-behaved that everything above it can be exact, replayable, and locatable when wrong. Cl(4,1) was chosen for one reason: it is the minimal algebra in which every conformal transformation is a versor, so every cognitive operation is algebraically closed by construction rather than by special-case handling. M0 must contain no cognition-specific policy; the moment it does, the substrate has started deciding.

Telos stages: recall, think/reason, articulate, backbone-runtime, replay/determinism (as the medium of all) Macro role: Supplies closure, exactness, and bit-level replayability to every layer above.


What it is / What it does

algebra/ (9 modules) implements Cl(4,1) — geometric product, versor apply, reverse, cga_inner, the versor condition — with algebra/backend.py dispatching between a pure-Python implementation and an opt-in Rust one. field/ (4 modules) holds FieldState and propagation. core/physics/ (37 modules) sits atop the algebra with the wave/identity/quantity machinery.

The one non-negotiable invariant is versor_condition(F) = ‖F·reverse(F) 1‖_F < 1e-6, checked at the injection gate and preserved across every transition, which is only ever the sandwich product F' = V·F·reverse(V). Closure of field transitions is owned solely by algebra/versor.py::_close_applied_versor; no other site may repair it. AGENTS.md draws the bright line explicitly: semantic anchoring (allowed at named construction boundaries, preserves the condition by construction, expresses a relation in the cognitive model) versus drift repair (forbidden — restoring an invariant a prior function should have preserved). Naming may not disguise the distinction.


Contract

  • Inputs: injected multivectors from M2's gate; versors from packs and operators.
  • Outputs: FieldState, exact CGA distances, closure verdicts.
  • Invariants:
    • versor_condition(F) < 1e-6 — never weakened to make code or tests pass — pin: algebra suite (15 files) — status: running.
    • No normalization/closure/repair outside owned boundaries; forbidden in generate/stream.py, field/propagate.py, vault/store.py, logging/telemetry — pin: tests/test_third_door_cohesion.py (AST-pinned off-serve quarantine).
    • Physics hot ops must import from algebra.backend, not direct pure-algebra modules — pin: tests/test_physics_backend_dispatch_hygiene.py.
    • f64 wave-residual pins stay on the Python product (Rust f32 GP is not parity-safe for 1e-9 pins).

Design vs build

  • Design: docs/Yellowpaper.md (formal Cl(4,1) specification), docs/position_paper.md §3, ADR-0241/0242 (wave-field, Fibonacci operators), ADR-0245 (CGA unification), ADR-0243 (lifecycle). AGENTS.md carries the invariants as law.
  • Build: live-serving. Key files: algebra/versor.py, algebra/backend.py, field/state.py, field/propagate.py, core/physics/.
  • Evidence:
    • Versor closure is enforced and the algebra suite runs it (15 test files) — pin+suite — would-fail-if-absent: yes.
    • Pure Python is the deterministic default; Rust is opt-in via CORE_BACKEND=rust — code-read — algebra/backend.py:1-9 — would-fail-if-absent: yes.
    • versor_condition costs 0.448 ms against a 200 ms turn — 0.22% — measurement — docs/research/cga-hot-path-measurement-2026-07-25.md — would-fail-if-absent: n/a (a measurement).
    • CGA is ~73% of turn time via cga_innergeometric_product at ~33,986 calls/turn in nearest-neighbour and salience search — measurement — same document.

Capacity

  • Designed: algebraically closed over the full conformal group; exact recall as a geometric fact.
  • Measured: closure holds at the 1e-6 gate across all serving lanes; Rust backend records core_rs import: False, using_rust(): False, status python_fallback in the benchmark run.
  • Ceilings: bit-exact determinism forbids JIT float reassociation (blocks MLX fusion without a ratifying ADR) and rules out bf16 (ε ≈ 7.8e-3, four orders coarser than the gate). Rust f32 geometric product is not parity-safe for the f64 residual pins.

Dependencies & provenance

feeds → every layer; constrained-by → MV (bit-exact parity pins, core-rs/tests/test_crdt_hash_parity.rs); owning ADRs: ADR-0241, ADR-0242, ADR-0243, ADR-0245, ADR-0180.


Stage coverage

Stage Verdict Evidence
(medium for) recall / think / articulate / backbone / replay covered Closure enforced by a running suite; exact CGA distance is the recall primitive; determinism pinned bit-exact

Zone roster: L0-algebra (live-serving, confirmed), L1-field (partial-wiring-debt, not individually re-verified).

Rollup note: weakest-link rollup. M0 is the most solid layer in CORE and the least in doubt.


Judgment

Fitness: fit. M0 does exactly one thing and does it without compromise. Notably, the position paper's claim that drift-correction machinery "was deleted because it only exists when the algebra is not closed" is architecturally coherent with AGENTS.md's bright-line rule — the doctrine and the code tell the same story here, which is not true everywhere else in this assessment.

Honest wrinkles:

  • The optimization target has been repeatedly misidentified, twice in documented history. Both an external assessment and a hardware blueprint aimed at versor_condition (0.22%) rather than cga_inner/geometric_product (~73%). The lesson generalizes past M0: the invariant is the most visible thing in the layer, so it attracts attention the profile does not justify.
  • CORE_BACKEND=rust is off by default and nobody currently knows whether parity holds. The verification attempt on 2026-07-25 was blocked — cargo could not reach static.crates.io under the sandbox network policy. This is an open question with a stated blocker, which is the honest state, but it means a written-and-shipped Rust kernel sits unused and unverified.
  • The measured hot path (cga_inner in salience/nearest-neighbour search) is M0 compute driven by an M3/CR-1 mechanism that has no owning card or ADR. Optimization work here has nowhere to attach architecturally — see the Candidate Register CR-1 revision in the M2/M3 cards and Phase 4.

Open questions:

  • Does core_rs still hold bit-exact parity, and should Rust become the default? (→ ruling; blocked on network access)
  • Does the ~73% CGA cost in salience search justify an algorithmic change rather than a backend change? (→ Phase 4)