{"body":{"CONSEQUENCES":{"severed_couplings":[{"coupling":"The coupling between Algorithm 1's supervised object and a single node. From v0.5's session monitors through v1.0, the dispatch commissioned a session over a node SET (RUL-8, resting REG-19) while the supervision call, the fence check, the verdict loop, and the advancement branch were still written against a singular n — one algorithm, two units of account, the seam papered over by the reader's goodwill.","id":"REG-58 (the singular-n coupling)","re_derived_by_decision":"Per-node accountability is RE-DERIVED, not abandoned, and the derivation is the decision: verification candidates are derived after the session closes from the chain's own entries (submitted nodes whose execution_result is recorded); per-node attribution of the session surface is derived at proxy against each candidate's fence, never observed and never upgraded (structure is not history); verdicts are recorded between sessions, before any dispatch that names the node again, because dispatch resets the completed attempt; and a failed session routes every in-flight node to retry or trip and none to verification. The node remains the unit of obligation; the session is merely the unit of observation, which is all it ever honestly was.","severed_by":"The session-scoped rewrite: SUPERVISE_EXECUTOR takes the session, the exit and result attach to the session, the surface is captured at session close, and the singular n disappears from every line that never honestly had one."},{"coupling":"The coupling between three status passages and the pre-Trial-0 moment that wrote them. The header paragraph, Section 12A's reference-implementation passage, and Section 14's stewardship passage all described Trial 0 as the next milestone — true when written, and preserved byte-for-byte through v1.0 because the ratification succession deliberately amended no prose beyond its version line, history entry, and closing line.","id":"the stale-status coupling","re_derived_by_decision":"Each passage is re-derived as a RECORD with the ratification's own bounded scope, not deleted and not inflated: the document is a Trial 0-ratified implementation specification; record-level results never establish general implementation conformance or GAD-4 defensibility; conformance is demonstrated per-record, permanently; item (9), independent review, is the one item still owed, and until it completes GAD is a ratified implementation specification, not an independently validated standard. The decision is that the corrected passages carry the SAME boundary the ratification manifest, the v1.0 history entry, and succession 4's successor_does_not_claim already carry — a fourth place that must agree, none of them inflatable alone.","severed_by":"Trial 0's closure (REG-57) and succession 4's ratification, which made the three passages false-by-time: the milestone they promised had been met, recorded, signed, and anchored, while the prose still promised it."}],"statement":"What this amendment SEVERS, as distinct from what it invalidates. An invalidated artifact is regenerated from its sources; a severed coupling must be RE-DERIVED BY A DECISION, and the decision is named here rather than left for an implementer to infer."},"amended_files":{"files":[{"digest":"86c8ea8c37bcb4243112032dd5f0016d4815eaca367371b051112936a14a05ab","path":"docs/gad-formal-spec.md"}],"statement":"The files this succession amended, each digest hashed from the bytes on disk at build time, never transcribed. v1.1 amends exactly one digest-frozen file: the specification itself (the header status paragraph, Section 2's Algorithm 1 and its demonstration paragraph, Section 12A's reference-implementation passage, Section 14's stewardship passage, the version line, the v1.1 history entry, and the closing line). The amendment's arc also APPENDED two entries to the companion register (REG-58 closed by this succession; REG-59 opened); the register is cited by identifier throughout this record and deliberately NOT by digest: it is the append-only companion whose next append is this very record's citation, and a digest here would freeze the document this record exists to be cited by."},"amendment_class":{"demonstrated_by":"Trial 0's run 20 record (docs/trial-0/) and the supervisor's between-sessions verifier are the demonstrating implementations of the session-scoped loop, named in the specification's own REG-58 demonstration paragraph: that record carries every verdict strictly between its node's execution_result and the node's next dispatch, and the referee's evaluation computes zero verdict-preconditions errors over it (REG-54).","found_by":"external review of the stamped v1.0 (REG-58) and the first gated protocol-mode run (REG-59): both arrived through the companion register, which remains the only channel through which this document learns that it must change.","statement":"v1.1 is an AMENDMENT succession, the first after ratification, and its class is stated here so the boundary cannot be inflated by citation: three status passages that still described Trial 0 as pending were corrected to the post-ratification truth with its bounded scope (record-level, per-record, item 9 pending); Algorithm 1 was made session-scoped, discharging REG-58 (the multi-node ambiguity found by external review of the stamped v1.0); REG-59 was registered open (the unwired typed gate plane, surfaced by the first gated protocol-mode run); and NO conformance requirement was weakened — every existing R-condition and predicate stands as strong or stronger, exactly as REG-58's closure records."},"authority":{"executor_role":"The executor authored this text and computed these figures under the succession-5 arc's nodes (the v1.1 text by s5-01; this record by s5-02), and applied the operator's key to the canonical body at the operator's direction. It did not authorize the succession. The authority is the operator's, recorded here by name, exercised by commissioning the plan, by the run's logged launch (see gate_channel for why this ceremony carries no engine gate), and by holding the signing key outside this repository where only the operator controls it. Authoring and computing are not authorizing (succession 1's division, RUL-11's ratification).","named_authority":"Brandon King","performed_by_executor":false,"role":"the operator","rule":"The authority is the operator, named in the record. No other party MAY perform a specification succession; in particular the executor of a governed run MUST NOT perform one, and a ruling recorded in the companion register is not itself an amendment of this document (spec Section 15, Authority)."},"changed":[{"authored_by":"the s5 run (s5-01), against the tree this ceremony seals","change":"The pre-Trial-0 status prose ('the next milestone is Trial 0 and the minimal open reference evaluator...'; 'v0.6 is the final pre-Trial-0 corrective revision'; 'independent formal and cryptographic review is pending' stated as the draft's posture) is replaced by the post-ratification truth: this document is a Trial 0-ratified implementation specification, Trial 0's record-level results ratified and recorded in docs/trial-0/; independent review remains pending (Phase 5) and Section 1's results remain Propositions and Claims until it completes; record-level results do not establish general implementation conformance or GAD-4 defensibility, conformance being demonstrated per-record, permanently; revisions arrive by succession.","section":"Header status paragraph (the companion line under the version line)","why":"The passage still described Trial 0 as the next milestone after the trial had closed (REG-57) and the ratification succession had sealed (succession 4). A status passage contradicting the record beside it is a stale figure in prose form."},{"authored_by":"the s5 run (s5-01), against the tree this ceremony seals","change":"The loop is made session-scoped, discharging REG-58: the session is the supervised object throughout — the dispatch COMMISSIONS a session over the node set (with the completedAttempt reset rule stated at the dispatch itself); SUPERVISE_EXECUTOR takes the session; executor_exit and execution_result attach to the session, node non-null exactly when the session covers one node and null as stated absence otherwise; the session delta and touched surface are captured at session close, after quiescence; a failed session routes every in-flight node of that session to retry or trip and no node of that session to verification; the verification candidates C_s are DERIVED after the session closes, from the chain's own entries; per-node attribution of the session surface is derived at proxy against each candidate's fence, never observed; and every candidate's verdicts are recorded BETWEEN sessions, strictly after the session's execution_result and before any dispatch that names the node again. A demonstration paragraph is added naming Trial 0's run 20 record and the supervisor's between-sessions verifier as the demonstrating implementations: the loop is demonstrated, not aspirational. Claims generalize from a single r.claim to per-node (m, text) pairs.","section":"Section 2, Algorithm 1 (CONSTRUCT) and its demonstration paragraph","why":"External review of the stamped v1.0 found the ambiguity REG-58 records: the dispatch commissioned a set while supervision, the fence check, and verification were written against a singular n, leaving per-node attribution, advancement, and verification candidacy ambiguous in the pseudocode even as the implementations demonstrated the intent. The rewrite states in the algorithm what the between-sessions verifier already does; no conformance requirement is weakened, and every existing R-condition and predicate stands as strong or stronger."},{"authored_by":"the s5 run (s5-01), against the tree this ceremony seals","change":"The pre-trial passage ('Conformance of that implementation and those witnesses to this version has not been established... Trial 0 exists to establish the distance, and its gap register publishes either way') is replaced by the post-trial truth: Trial 0 established record-level bundle conformance for one specifically identified record under named artifacts (docs/trial-0/); it did not establish constructor-wide, operational, or general implementation conformance, which are demonstrated per-record, permanently, no record conferring conformance on the tooling that produced it. The closing sentence stands: grandfathering the tooling into conformance would be exactly the counterfeit this specification defines.","section":"Section 12A, 'On the reference implementation'","why":"The passage described Trial 0 as future after it had closed. The correction states what the trial established USING the trial's own bounded scope, so the passage can neither understate the record nor inflate it."},{"authored_by":"the s5 run (s5-01), against the tree this ceremony seals","change":"The pre-trial stewardship decision ('prose expansion is frozen; the next milestone is Trial 0 and item (7)...') is replaced by the stewardship record: companion machinery items (1) through (8) were produced and exercised through Trial 0; item (9), independent formal and cryptographic review, is the pending item; until it completes, GAD is a ratified implementation specification, not an independently validated standard.","section":"Section 14, companion-machinery stewardship passage","why":"Same defect, third instance: a stewardship passage promising a milestone that had already been met. The correction is a record, not a promise, and it names the one item still owed."},{"authored_by":"the s5 run (s5-01), against the tree this ceremony seals","change":"The version line reads 'Version 1.1 draft · Atlas North Institute · July 2026'; one history entry is appended (v1.1: amendment succession; three pre-Trial-0 status passages corrected to the post-ratification truth; Algorithm 1 made session-scoped, discharging REG-58; no conformance requirement weakened); the document ends 'End of v1.1 draft.' All earlier history entries stand intact as fact.","section":"Version line, version history, closing line","why":"The header, history, and closing line are part of the bytes the successor digest freezes and must agree with each other and with the record beside them (REG-35's discipline applied to both ends of the document). The 'draft' designation returns honestly: v1.0 was the ratified version; v1.1 is an amendment of it that no trial has evaluated, and its label says so."}],"discharges":{"by_this_amendment":[{"how":"The session-scoped rewrite makes the session the supervised object throughout: the dispatch commissions a session over the node set; SUPERVISE_EXECUTOR takes the session; the executor_exit and execution_result attach to the session (node non-null exactly when the session covers one node, null as stated absence otherwise, RUL-10/RUL-12 as amended); the session delta and touched surface are captured at session close; per-node attribution of the surface is derived at proxy against each candidate node's fence, never observed; the verification candidates are derived after the session closes as the submitted nodes whose execution_result is recorded, their verdicts recorded between sessions, before any dispatch that names them (the completedAttempt reset rule); and a failed session routes every in-flight node of that session to retry or trip and no node of that session to verification. No conformance requirement was weakened.","id":"REG-58","status":"CLOSED by succession 5 (this record), per the register's own entry","what_was_discharged":"The stamped v1.0's Algorithm 1 carried a multi-node ambiguity, found by external review: the dispatch commissioned a session over a node set while supervision and the fence check were written against a singular n, leaving per-node attribution, advancement, and verification candidacy ambiguous in the pseudocode even as the between-sessions verifier demonstrated the intent."}],"cited_rulings_not_discharged_here":[{"id":"REG-59","status":"OPEN as product work (Wave 9), registered by this amendment's arc","why_cited":"The reason this ceremony is GATELESS: the typed gate plane is unwired, a witness cannot yet carry a principal-signed gate approval, and the engine correctly fail-closes on a done-but-gated dependency without one. Registering the gap is this arc's work; closing it (a gated ceremony producing a live record the evaluator accepts with R7 evaluated) is Wave 9's, not claimed here."},{"id":"REG-54","status":"OPEN; the referee's ruling this choreography obeys","why_cited":"Verification belongs between sessions, in nobody's session — the placement this amendment writes into Algorithm 1's pseudocode and the choreography this record was produced under. The entry's own closure condition (a witness whose every verdict lies strictly between its node's execution_result and that node's next dispatch, with the referee computing zero verdict-preconditions errors and a probe reproducing run 15's defect) is the register's to judge, not this record's to claim."},{"id":"REG-48","status":"OPEN; ruling RESTED with its July 16 precision amendment","why_cited":"Verification is post-quiescence by the specification's semantics; this record was produced under the between-sessions choreography (see session_choreography). The entry closes only when a live-choreography record evaluates fully referee-valid, which this record does not claim (see successor_does_not_claim)."},{"id":"REG-56","status":"OPEN as product work (Wave 8)","why_cited":"A completed run must be inert. This run obeys the interim procedural rule (no sessions after the run's final verification lines); the engine-level refusal of dispatch over a terminal-carrying witness remains product work and is not claimed here."}],"statement":"v1.1 discharges exactly one register entry: REG-58, closed by this succession's session-scoped rewrite of Algorithm 1. The register's own entry records the closure as 'CLOSED by succession 5'; this record is that succession, and the citation below is the discharge. Every other ruling this ceremony operates under is cited beside it with its register status, none of them discharged here."},"gate_channel":{"rule":"REG-59: this ceremony node carries NO ENGINE GATE, and the record says so plainly rather than leaving the witness's silence to be discovered. The typed gate plane is unwired (Wave 9): a witness cannot yet carry a principal-signed gate approval, and in v0.6 mode the engine's dependency rule correctly FAIL-CLOSES on a done-but-gated dependency whose witness lacks one, so a gated node would deadlock its own run's final verification. The engine's refusal is the designed behavior; the defect is the unwired plane above it, registered open as REG-59.","what_happened":"The first gated protocol-mode run surfaced exactly this: the classic inbox approval was real and chain-logged, but the witness could carry no typed approval, so the engine refused to unblock the run's final node. That run was superseded GATELESS and the work re-blessed — the register entry records it. This ceremony therefore proceeds gateless BY DESIGN, not by omission: the operator's authorization is the run's LOGGED launch and the SIGNATURE over this record, both chain-recorded. The signature is the operator's human act with the authority key, performed through the established signing flow (the key verified to derive the committed public half before it signed, key material never entering this repository); it remains the ceremony's substance whatever the gate plane's state.","what_this_makes_possible":"The first fully gated ceremony under protocol mode is succession 6's, after Wave 9 lands the typed gate plane (gate_request and approval appended by the supervisor's principal pen, ordered before the gated node's dispatch, alongside the REG-51 approval-secret surface). REG-59 closes when a gated ceremony produces a live record the evaluator accepts with R7 evaluated; this record states that condition and claims nothing about when it is met (see successor_does_not_claim)."},"genesis_disclosure":{"predecessor_authorization":"v1.0's Section 15 defines the only ceremony by which this document changes, and this succession is performed under it: object identified by byte digest, authority the named operator, record a signed sidecar the register cites, delta carrying the seven mandatory items, numbered in sequence from 1.","predecessor_authorized_this_amendment":true,"statement":"Succession 5 is NOT genesis and claims no genesis exception. It is the fourth specification succession governed by a rule that predates it: Section 15's ceremony was introduced by v0.7 and carried intact through v0.8, v0.9, v1.0, and into the v1.1 text this record seals. Succession 1's disclosure is not softened, removed, or restated here: it remains true of succession 1, and every succession after it being ordinary is exactly what it predicted.","this_is_genesis":false},"invalidated_artifacts":{"classes":[],"classes_note":"COMPUTED ZERO classes: v1.1 amends no tool and weakens no conformance requirement; its changes are three status passages, the session-scoped Algorithm 1, the version line, the history entry, the closing line, and two register appends. The zero is grounded in the manifest's amendment_diff (the set of paths changed between the pinned v1.0 and v1.1 commits, required to name nothing but the two governed documents), not asserted. What this succession replaces is the invalidation manifest itself, exactly as every succession before it did.","manifest_digest":"2773c36b99ca7acc9156a44621529751a2df0a552bb50d40ff7926737c4e29c4","manifest_path":"succession/manifest/invalidation-manifest.json","named_by":"class, with the cited digest of a manifest COMPUTED from the tree by succession/manifest/build-manifest-5.mjs","predecessor_manifest":{"commit":"ca703c5ea4709461540eb6bf4de24df7e6c717b2","digest":"931dc4ba20dc906ff1c77a052114e4c85616e66f8a0f447232ea86b26b918542","provenance":"Succession 4's manifest, whose bytes this succession's manifest replaces at the same path. The blob at commit ca703c5ea4709461540eb6bf4de24df7e6c717b2 was hashed and required to equal the digest succession-4.json cites BEFORE this record was written, proving these are the bytes succession 4 signed over and that they had not moved since. NOT recomputable from this tree once replaced: recoverable from that commit, exactly as v1.0's spec bytes are recoverable from theirs. tools/succession-verify.mjs reports succession 4's cited manifest digest as RECORDED, NOT VERIFIED now that succession 4 is no longer the latest record (REG-33's lineage rule).","recomputable_from_this_tree":false},"predecessor_members_comparison":{"members_moved":0,"members_recorded":0,"note":"Computed by build-manifest-5.mjs and VACUOUS BY CONSTRUCTION: succession 4's manifest recorded zero members (its classes were themselves a computed zero), so there was nothing to re-hash. Stated honestly rather than dressed up as evidence; the load-bearing grounding is the manifest's amendment_diff beside it."},"rule":"The manifest MUST be computed and MUST NOT be a hand-typed list: such a list is stale the moment any of its members moves, and a recited figure is not a computed one.","scope_note":"gad-protocol only. atlas-orchestrator and waypoint are NAMED in the manifest, with a stated reason, and are NOT read, NOT hashed, and NOT touched: a graph that amended the specification and its constructor in one run would be the constructor editing its own referee. They are judged against this successor by their own governed runs — and Wave 9's typed gate plane (REG-59) is theirs to build, not this run's."},"object":{"document":"docs/gad-formal-spec.md","identified_by":"byte digest of the frozen text, never by version label alone: a label is not an identity (spec Section 15, Object)","successor_digest":"86c8ea8c37bcb4243112032dd5f0016d4815eaca367371b051112936a14a05ab"},"predecessor_record":{"path":"succession/delta/succession-4.json","provenance":"sha256 of succession-4.json's bytes on disk at build time — the record-level chain link, computed and never transcribed. The lineage's continuity is verified by tools/succession-verify.mjs over the spec digests (each predecessor digest equal to the prior successor digest); this figure additionally binds WHICH record bytes this succession chained from.","record_digest":"906f01ccb3eab4ee0079a4528326793b8a1cad0d428b7fefeead29aa6ff73900"},"predecessor_spec_digest":{"commit":"ca703c5ea4709461540eb6bf4de24df7e6c717b2","digest":"fa2192e1250a743a3e695589eb27c50e14d1ac7a3aeb5aee0bae66e9c708fa18","provenance":"succession 4's successor digest, read from succession/delta/succession-4.json rather than transcribed, which is what makes the chain continuous by derivation instead of by assertion. Those bytes are the blob at commit ca703c5ea4709461540eb6bf4de24df7e6c717b2, the last committed tree in which this document was v1.0 (the v1.1 text landed in s5-01's commits before this ceremony ran, so the predecessor tree is the commit before them — the same run-22 commit that landed succession 4's records); that blob was hashed and required to equal this figure before this record was written. NOT recomputable from this tree's working document: v1.0's bytes left it with v1.1's landing, and tools/succession-verify.mjs reports this figure as RECORDED, NOT VERIFIED rather than implying it rechecked it (REG-33's lineage rule).","recomputable_from_this_tree":false,"version_label":"1.0"},"record":{"cited_by":"docs/gad-spec-register.md","lives_at":"succession/delta/succession-5.json","rule":"The record of a specification succession lives in gad-protocol as a signed sidecar beside this document, and the companion specification register cites it. The register remains the channel through which this document learns that it must change; the succession is how it changes.","verified_by":"tools/succession-verify.mjs"},"record_type":"gad-spec-succession-delta","session_choreography":{"rule":"REG-48 (ruling rested July 16, 2026, with its precision amendment) and REG-54 (the referee's own ruling): verification is post-quiescence by the specification's semantics, and it belongs BETWEEN sessions, in nobody's session, exactly where Algorithm 1 places it — the very placement this amendment writes into Algorithm 1's pseudocode (REG-58's discharge).","what_happened":"This record was built and signed inside a session with BETWEEN-SESSIONS verification: the executor claimed and submitted the ceremony node and exited; the recorded verdicts are the supervisor's, computed after quiescence over the captured delta, each verdict lying strictly between its node's execution_result and that node's next dispatch. Producing this record under that choreography is an instance of the ruling — and of the session-scoped Algorithm 1 this very amendment seals — not the referee-valid live-choreography evaluation REG-48's entry still awaits (see successor_does_not_claim)."},"signature_scope":{"construction":"SIGN_x(obj) = {body: obj, signature: sig_x(canon(obj))}; the signature covers the canonical body and is never a member of it.","key":"the operator authority key (RUL-9, RUL-11 clause 2); public half committed at succession/keys/operator-pubkey.json, private half never in this repository","what_this_signature_ATTESTS":"that this delta's text and figures are the ones bound at signing time, and that they have not moved since; that the party who bound them holds a key whose private half has never entered this repository and which names an authority; and that the key was verified to DERIVE the committed public half before it signed (REG-38's derive-based standard, normative since v0.9, applied to its own signing moment). REG-38's checker is run over succession/ after signing and its computed zero is recorded in the exit-gate record beside this ceremony.","what_this_signature_DOES_NOT_ATTEST":"any registry identity beyond the named authority's custody of the key, and no claim that any implementation conforms to the successor. REG-14's key lifecycle design is normative text (v0.9, Profile One) but its implementation remains post-v1.0 and the register entry stays OPEN tracking it; until that implementation lands, a compromised key is handled by succession, not in-place revocation — the interim rule, stated in the specification rather than improvised at the incident. This is the fifth record that rule applies to."},"succession_number":5,"successor_does_not_claim":{"not_claimed":["GENERAL IMPLEMENTATION CONFORMANCE. The corrected passages state it in the document's own text now: record-level Trial 0 results do not establish general implementation conformance or GAD-4 defensibility; conformance is demonstrated per-record, permanently. No implementation — not the evaluator, not the engine, not the product — is claimed to conform to v1.1 in general.","RATIFICATION OF v1.1 ITSELF. v1.0 was ratified by Trial 0; v1.1 is an amendment of the ratified text that no trial has evaluated, and its version line says 'draft' for exactly that reason. Nothing here extends Trial 0's ratification forward onto bytes the trial never saw.","THAT INDEPENDENT REVIEW HAPPENED. Phase 5's independent formal and cryptographic review is pending, and this succession did not perform it. Section 1's results remain Propositions and Claims, not Theorems, until it completes — the same sentence the corrected Section 14 passage carries: until it completes, GAD is a ratified implementation specification, not an independently validated standard.","THAT REG-59 IS FIXED. The typed gate plane remains unwired; this ceremony proceeded GATELESS by design and says so in its own gate_channel. REG-59 closes when a gated ceremony produces a live record the evaluator accepts with R7 evaluated — Wave 9's work, after which the first fully gated ceremony is succession 6's. Nothing here claims that record exists.","THAT R7 EVALUATED NON-VACUOUSLY IN A LIVE RECORD. This run carries no approval gate, so the referee's R7 condition evaluates vacuously over its record, exactly as it did over every pre-succession-4 record. The gated live record that moves R7 to evaluated is the record REG-59's closure demands, and it does not exist yet.","THAT REG-54 OR REG-48 CLOSED. This record was produced under the between-sessions choreography those entries govern, and the session-scoped Algorithm 1 now states that placement in the pseudocode; but each entry's closure condition is the register's to judge over the records it names, not this record's to claim by having obeyed it.","THAT REG-14 IS IMPLEMENTED. The key lifecycle v0.9 designed (signed lifecycle entries, key_id supersession, forward-looking revocation) still has NO implementation; it remains post-v1.0 by the ruling itself, and the register entry stays OPEN tracking it.","THAT REG-29's GENERATOR HALF CLOSED. The nine invalid fixtures still have no generator, exactly as successions 2, 3, and 4 disclosed; the blessing stands and the generator remains future work.","THAT REG-56's PRODUCT FIX EXISTS. This run obeys the interim procedural rule (a completed run is inert; no sessions after the final verification lines); the engine-level refusal of dispatch over a terminal-carrying witness remains Wave 8 product work.","ANY AUTHORITY OVER THE HISTORICAL RECORDS. Nothing recorded before this succession is reissued, recomputed, or re-read. Every prior version's history entry stands intact as fact, and succession 1's genesis disclosure is neither softened nor restated.","FINALITY. v1.1 is an amendment draft, not the specification's last word: per the stewardship rule, further revisions arrive from concrete implementation findings through the companion register and Section 15's ceremony, exactly as the five before it did.","THAT THE GENESIS PROBLEM IS SOLVED. Succession 1 disclosed it; this is the fourth succession that does not face it, which is not the same as solving it."],"statement":"The successor does not claim what follows, and says so here rather than leaving the boundary to be inferred from silence. v1.1 corrects status prose to the ratified truth and discharges one pseudocode ambiguity, and nothing else."},"successor_spec_digest":{"digest":"86c8ea8c37bcb4243112032dd5f0016d4815eaca367371b051112936a14a05ab","provenance":"sha256 of docs/gad-formal-spec.md as it stands in this tree, recomputed by tools/succession-verify.mjs against the bytes on disk. The version label is PARSED from that same document's header at build time, never recited, so the label cannot contradict the digest beside it (REG-35).","recomputable_from_this_tree":true,"version_label":"1.1"}},"signature":"33d1c87e24d6acc32cc764e748edf9f632ea5fa5d13e85b0d6721c6f0172c449af1a03309546970c46c9103cfe7fddadd27c9b18f8182b0b50b91a70ce67230d"}