Published Updated

From numerical bounds to a controlled paired-t execution candidate

The reviewed Release 2 formal decision packet now assembles the paired-t evidence and required decisions without adopting or issuing Protocol support.

Current status

The proposed paired-t capability now has independently reviewed candidate decisions for its numerical contract, full execution trace, controlled runtime, and final reason-code inventory. The four groups have been assembled into one final R2-D5 review-readiness package, and its exact-head independent review returned GO with no findings.

This means the complete candidate can be considered by the Steward after the public review window. It is not a ratified Protocol capability. No paired-t identifier, Public Check, schema, or bundle has been issued, and the one selected Node, V8, Linux, and executable-hash tuple is not broad cross-platform support.

A separate exact-head review also found the proposed Requirement namespaces, identifiers, schemas, fixtures, dispatch rules, and public surfaces internally consistent as decision-preparation material. Those structural candidates remain unissued and have not yet been adopted.

The repository has now assembled those reviewed inputs into a formal D1–D6 decision packet. Its first independent review required two major and seven minor repairs. A close-only review confirmed every finding closed and returned GO. The packet prepares a decision; it does not make one.

Why this is a milestone

Earlier increments established the numerical pieces separately: the arithmetic from paired observations to a test statistic, the Student-t tail calculation, the fixed critical-value table, and confidence-interval endpoint arithmetic. The new closure composes those pieces into one candidate contract and verifies the entire returned trace rather than trusting disconnected outputs.

The execution work answers a different question. A numerically reviewed graph is not useful as a reproducibility claim until its runtime, executable, permissions, and evaluated code are also identified. The selected candidate makes that boundary explicit and rejects execution outside it.

The latest step moves beyond the numerical work-group package. It assembles the complete D1–D6 decision ledger, evidence and review receipts, and the future authoritative landing order. Instead of asking the Steward to infer which reviewed candidate maps to which decision, the repository now provides one repaired and independently reviewed formal-decision input.

Closing the numerical path

The paired-data path fixes the operation order for differences, mean difference, sample variance, standard error, test statistic, and integer degrees of freedom. Its mathematical-truth ledger places exact targets inside rational intervals and measures the actual binary64 trace against them. Independent review reconstructed that arithmetic through a separate exact route and completed 568 checks without a failure.

The Student-t path uses positive series forms and a reviewed normalization table. For each evaluated input, it combines the rounding error of the executed graph with a bound on the unevaluated positive series terms. It also measures the result against the nearest probability-class boundary. If the bound cannot establish the class, the candidate rule refuses instead of silently treating the class as known.

Confidence-interval work then binds the selected critical value, the margin calculation, both endpoint operations, and their exact-rational truth envelopes to the same verified paired-data trace. The Group 2 closure now checks these components, their table hashes, numerical outputs, resource accounting, and nested trace digests as one full-trace envelope. Its independent review returned GO with no findings.

Selecting critical values

The candidate uses fixed-95% Student-t critical values for every integer degree of freedom from 1 through 200. Each mathematical quantile was certified inside one exact binary64 rounding cell, and independent review checked all 200 cells and their ordering.

The selected ordered-cell content hash is sha256:24ccc86d7a49b9e1ef1e3fc9b038a5b8d338b8b5ca4a02492d8900d7e7dea3c0. Pinning those bytes prevents later candidate work from quietly changing a critical value. It does not make degrees of freedom 1 through 200 a supported Protocol range or turn the table into an authoritative artifact.

One controlled execution candidate

Group 3 selected exactly one candidate environment: Node 24.19.0, V8 13.6.233.17-node.51, Linux x64, and the Node executable whose SHA-256 is bc17c508ffeed0ec622934f9b7fa72f8e78da65350e63c3eceb56fa688aa5e12. A different Node patch, V8 build, operating system, architecture, or executable hash is outside this candidate selection.

The controlled runner pins the compiled candidate files, freezes built-in objects, disables native add-ons and dynamically compiled strings, grants read access only to the declared code and executable, and denies process spawning, workers, WASI, the inspector, and filesystem writes. It checks these conditions before and after one full-trace evaluation and verifies the returned numerical envelope again.

Cold and post-warm-up runs produced byte-identical projections for six cases. The preserved evidence also contains the compiled-file digest manifest and 145 matched optimization-trace lines. Independent review accepted the one-entry candidate and the later Group 3 closure with no findings.

What the review tested

The Group 2 review independently re-executed the candidate numerical graph and checked its exact-rational truth envelopes, p-value projection rules, fixed-95% interval endpoints, table bindings, resource envelope, and full-trace composition. It found no BLOCKER, SHOULD-FIX, or NICE-TO-HAVE issue.

The Group 3 review checked the exact runtime and executable identity, controlled process restrictions, cold and warm evidence, compiled-file digests, and the link back to the reviewed Group 2 trace. A reviewer-owned set of 216 adversarial mutations attempted to alter the environment, evidence, candidate matrix, maturity state, and authority boundary. All were rejected deterministically.

Group 4 then closed the candidate inventory that explains how failed structural, relationship, numerical, and execution checks would be reported. Its selection and closure both received independent GO dispositions with no findings. The names are still candidates: they have not become issued Public Check or refusal-code identities.

Final review readiness

The final R2-D5 package binds the preserved Groups 1 through 4 closures to the selected numerical, boundary, resource, execution, and reporting evidence. Its independent exact-head review returned GO with no BLOCKER, SHOULD-FIX, or NICE-TO-HAVE finding.

Review readiness is a concrete engineering milestone, but it is not ratification. It means the candidate decisions and their evidence can now be evaluated as one coherent unit when the public review window permits a Steward decision. It does not make the candidate authoritative or available to users as paired-t support.

The formal decision packet is ready

The merged formal decision packet separates six decisions: completion of public discussion; identifiers and Requirement namespaces; schemas and public surfaces; ordered Checks and bundle composition; the numerical contract; and the bounded release candidate. Existing candidate reviews are evidence for those decisions, not the decisions themselves.

Its initial independent review returned REPAIR_REQUIRED with no blocker, two major findings, and seven minor findings. The repairs added omitted D5 and D6 evidence requirements, the public-contract-surface and authority assignments, exact reviewed-head identities, later-drift accounting, and the rule that a material scope or semantic change restarts the applicable discussion window. The close-only review returned GO and found no change to the candidate decisions, evidence receipts, authority boundary, or Release 1 behavior.

If the Steward later approves the required decisions, the packet requires one coupled authoritative change set: registries, schemas, ordered Public Checks, bundle composition, source pin, conformance, authority assignments, generated views, and Release 1 compatibility evidence must land together. This prevents a partial publication from silently creating support before all parts agree.

What remains open

The remaining step is the formal Steward disposition of D1 through D6. The public review window reaches its earliest decision time at . Reaching that time does not adopt the proposal. Until an affirmative disposition and the coupled landing complete, the reviewed packet creates no authoritative supported domain, execution allowlist, runtime activation rule, final reason-code set, Public Check, bundle, or permanent paired-t identifier.

The numerical contract is not formally frozen. Release 2 D2 through D5 are not adopted, Release 2 has not been published, and public review issue #25 remains open. The current result is final candidate review readiness—not user-facing paired-t support.

Public evidence