Fifteen nodes rebuilt an orchestration engine to conform to a published standard, and at the end a separately executable evaluator, run from a read-only checkout, read the test envelope the engine produced and accepted it. Along the way the run crashed repeatedly, caught a regression it had caused in its own earlier work, and twice produced a plausible recommendation to edit the frozen plan. The plan was not edited. This is the record of what that cost and what it proved.
Over roughly fifteen hours and many sessions, a frozen fifteen-node plan rebuilt Atlas Orchestrator to speak the protocol defined in the GAD Formal Specification: a public signed witness, two-axis evidence classing, session accounting that treats a dead executor as recorded fact rather than silence, and a fail-closed export. The decisive moment came at node thirteen, where the separately executable evaluator built in the previous phase, from a read-only checkout, with no knowledge of this run, read the envelope Atlas produced and returned valid, correct outcome, every condition satisfied. The constructor now speaks the referee's language.
Near the end, the run's own regression sweep caught something real: an earlier node's test had been silently broken by a later node's stricter rule. Node ten had implemented a ruling that forbids reviving a node whose safety breaker has tripped. Node four's test still expected the old, looser behavior. Nothing external caught this. The machinery caught itself, recorded it on the chain, and refused to call the build complete while it stood. see the self-caught regression →
The fix was small and correct. Blessing it was not. Twice, an engine defect, since named and recorded, attributed one run's committed work to another run's node and blocked a correct node from verifying. Twice, a capable executor recommended the same remedy: edit the frozen plan and reload. It was not a foolish suggestion; it was the only path the broken engine left visible. It was declined both times. A frozen contract is never edited to make a check pass. The ceremony was abandoned instead, the fix was closed on three distinct verification runs, and the defect was written down as the highest-priority item in the next phase. see the halt that ended the ceremony →
A flawless run proves nothing: flawless is what fabrication looks like. This one crashed, stalled, orphaned a claim, failed a node, caught its own regression, and hit an engine bug three times in three different costumes. Every one of those events is on the chain with a timestamp. The reopen carries the operator's name and his exact words. The failed node shows its retry and its recovery. The abandoned ceremony is written into the register with the reasons. Nothing was waived. Nothing was backfilled. No frozen plan was edited, at the end of a fifteen-hour day, when editing it was the recommended option. That is the only test of governance that means anything: not whether it holds when it is convenient, but whether it holds at hour fifteen with a plausible shortcut on the screen.
Analysis, not chained evidence: the record proves the run's duration and interaction pattern; it cannot prove a counterfactual that never executed. The frozen plan carried the entire specification, so the executor was never told what to build twice. The same brownfield scope executed ungoverned, estimated from this operator's own prior rhythm, runs into the hundreds of authored prompts across many days, most of them respecification and correction. The friction in this run was almost entirely in the cockpit's session lifecycle, not in the work: the plan itself never had to be explained again.
| Frozen plan (authored identity) | 698503336c0db6326e535b6e7b66a2d0340d7478baf7222f331cc607801fb72e |
| Master spec hash | 6d685e1338dfe7786c5ece0c5fbb1caf8fda95ca914c2986b08d4f8073a05945 |
| Genesis hash (chain root) | 2140e574d35066b80e16d2bcdcf1e6397547805955d8180f3cad54d87421a7bb |
| Repository at run start | fc885caa7e3467803d7c1396fb3974d0f022b7d5 |
| Engine · cockpit | Atlas Orchestrator 1.5.0 · Waypoint 1.1.0 |
| Nodes · retry cap · mode | 15 · 3 · supervised, scope enforced, clean-tree required |
| Corrective plan (superseding) | 50b618e887e5cb64050107c8794f09d08011213e83b0e7b3d0605a08d71028f3 |
Durations are claim-to-verification, computed from the entries below. Every check was run by the engine against executor-authored tooling, so every node carries the honest class for that arrangement, server_observed_proxy, and every checker holds a negative probe: a committed planted defect it must detect, or its passes do not count.
| # | node | title | duration | checks | retries |
|---|---|---|---|---|---|
| 01 | p2-01-mode-canon-signing | Foundations: protocol_mode, canonicalization, Ed25519 signing | 10m 36s | 1 | 0 |
| 02 | p2-02-witness-chain | Typed witness writer: public chain, issuer table, dual-write | 11m 01s | 1 | 0 |
| 03 | p2-03-checkpoints-sealing | Checkpoints, coverage, sealing, snapshot seal | 10m 24s | 1 | 0 |
| 04 | p2-04-freeze-terminals | Typed freeze and terminals wired to the store | 57m 16s | 1 | 0 |
| 05 | p2-05-session-api | The GAD-1 session API: dispatch, executor_exit, execution_result | 16m 08s | 1 | 0 |
| 06 | p2-06-scope-transitions | Typed scope: mechanical flags, removal recheck, signed closure | 26m 28s | 1 | 0 |
| 07 | p2-07-gates-succession | Typed gates per RUL-4 and the succession API | 30m 07s | 1 | 0 |
| 08 | p2-08-verdicts | Signed two-axis verdicts for every evaluation attempt | 33m 58s | 1 | 0 |
| 09 | p2-09-probes-effclass | Typed probes, effective class, the GAD-2 floor | 38m 23s | 1 | 0 |
| 10 | p2-10-r8-rulings | RUL-2 and RUL-3: breaker and waiver enforcement | 13m 28s | 1 | 0 |
| 11 | p2-11-claims-export | Typed claims and the fail-closed B_core export | 18m 45s | 1 | 0 |
| 12 | p2-12-harness | The fixture harness: one full v0.6 run, every path exercised | 15m 07s | 1 | 0 |
| 13 | p2-13-referee-gate | EXIT GATE: the referee accepts Atlas's envelope, cold | 482m 48s | 1 | 0 |
| 14 | p2-14-acceptance-quartet | Acceptance tests 8, 9, 13, 14 on the record | 9m 10s | 1 | 0 |
| 15 | p2-15-legacy-green | No regression: the whole legacy suite, lint, and build | 16m 16s | 1 | 1 retry |
It proves the plan was frozen and hash-addressed before work began; that every completion claim was checked outside the worker's session with its evidence class stated; that every checker demonstrated the capacity to fail before its passes counted; that the four bypass attempts from the audit checklist were each refused on the record; that a separately executable evaluator accepted the constructor's test envelope cold, a result that did not confer v1.3 conformance on this field record's own keyed witness; and that a node which failed was retried within budget and recovered rather than waived. It does not prove semantic correctness against the specification, the efficiency commentary, or this record's own conformance to the standard its contents implement. Those verdicts belong to the adversarial vectors, the second evaluator, and Trial 0.
All 83 entries of the main run, seq 0 through 82, exactly as written at the moment. Click any entry for its raw form and its link to the next.
The one-node plan authored to bless the REG-11 fix through a governed node. Its test passed. It halted anyway, on REG-12, naming a file it never touched. The ceremony was abandoned rather than the contract bent.