diff --git a/EVIDENCE-ALIGNMENT.md b/EVIDENCE-ALIGNMENT.md
index 788abfd..13300a9 100644
--- a/EVIDENCE-ALIGNMENT.md
+++ b/EVIDENCE-ALIGNMENT.md
@@ -61,7 +61,7 @@ causal independence.
| LIR-3/PHEME | With 40% of exact parent-status IDs hidden but reply-target author retained, the frozen author-only rule achieved recorded-root precision, recall, and F1 of 1.0 with zero root-count error on 425 sealed cases. | Causal copying, evidence independence, author authentication, content truth, cross-platform generalization, or general provenance recovery. |
| LIR-4/PHEME | At 50% missing reply-target identity among hidden-edge records, precision remained 1.0 but recall fell to 0.4329, F1 to 0.6043, and root-count MAE rose to 2.405, rejecting graceful degradation. | General resistance to false identity or cross-root misbinding; only one final-holdout case had multiple roots, so the safety diagnostic was underpowered. |
-## v1.0.6 manuscript alignment
+## v1.0.7 manuscript alignment
The active manuscript corrects two inherited presentation defects without
altering earlier snapshots:
@@ -77,12 +77,15 @@ altering earlier snapshots:
supported typed-provenance bridge and the rejected degradation claim, while
preserving the distinction between recorded platform roots and causal
evidence independence.
+- v1.0.7 adds a reader-first abstract, example, visual, boundary table, results
+ map, glossary, and selected primary-source links. It changes no theorem,
+ canonical status, result, limitation, or release blocker.
## Manuscript policy
-- `papers/minority-prophet-v1.0.6.md` is the active evidence-aligned draft, adopted
- 2026-08-08.
-- v0.9, v1.0, v1.0.1, v1.0.2, v1.0.3, v1.0.4, and v1.0.5 are preserved historical drafts and defer to
+- `papers/minority-prophet-v1.0.7.md` is the active evidence-aligned draft, adopted
+ 2026-08-09.
+- v0.9, v1.0, v1.0.1, v1.0.2, v1.0.3, v1.0.4, v1.0.5, and v1.0.6 are preserved historical drafts and defer to
this ledger.
- EXP008's archived attack mixture is not EXP007A's selected attack.
- All point estimates must name their record and scope.
diff --git a/app/page.tsx b/app/page.tsx
index 9679674..7d78d18 100644
--- a/app/page.tsx
+++ b/app/page.tsx
@@ -4,6 +4,8 @@ import { useMemo, useState } from "react";
type ClaimKind = "independent" | "copied" | "contradiction";
+const paperUrl = "https://github.com/Silentpartnercoding/minority-prophet/blob/main/papers/minority-prophet-v1.0.7.md";
+
const claims: { id: string; agent: string; belief: string; confidence: number; kind: ClaimKind; source: string }[] = [
{ id: "C-003", agent: "Observer 03", belief: "TRUE", confidence: 98, kind: "independent", source: "Instrument C" },
{ id: "C-002", agent: "Observer 02", belief: "TRUE", confidence: 96, kind: "independent", source: "Instrument B" },
@@ -38,6 +40,7 @@ export default function Home() {
MINORITY PROPHET RESEARCH PROGRAM
+
Paper
Benchmark
Dashboard
Boundary
@@ -53,7 +56,7 @@ export default function Home() {
A focused benchmark testing whether aggregation methods can recover independently grounded truth under overwhelming copying pressure.
diff --git a/papers/00-CURRENT-PAPER.md b/papers/00-CURRENT-PAPER.md
index c61ee46..9905817 100644
--- a/papers/00-CURRENT-PAPER.md
+++ b/papers/00-CURRENT-PAPER.md
@@ -2,7 +2,7 @@
The current evidence-aligned pre-submission manuscript is:
-**[The Minority Prophet Property — v1.0.6](./minority-prophet-v1.0.6.md)**
+**[The Minority Prophet Property — v1.0.7](./minority-prophet-v1.0.7.md)**
Earlier versions are preserved as historical records. Their filenames and text
are not silently rewritten; the current manuscript, canonical record registry,
diff --git a/papers/README.md b/papers/README.md
index d9a37ab..038a095 100644
--- a/papers/README.md
+++ b/papers/README.md
@@ -1,10 +1,11 @@
# Papers
-Start with **[the current paper](./minority-prophet-v1.0.6.md)**.
+Start with **[the current paper](./minority-prophet-v1.0.7.md)**.
| File | Status |
| --- | --- |
-| [`minority-prophet-v1.0.6.md`](./minority-prophet-v1.0.6.md) | Current evidence-aligned pre-submission manuscript; closes LIR-1–LIR-4 |
+| [`minority-prophet-v1.0.7.md`](./minority-prophet-v1.0.7.md) | Current reader-first, evidence-aligned pre-submission manuscript |
+| [`minority-prophet-v1.0.6.md`](./minority-prophet-v1.0.6.md) | Preserved prior snapshot; closes LIR-1–LIR-4 |
| [`minority-prophet-v1.0.5.md`](./minority-prophet-v1.0.5.md) | Preserved prior snapshot |
| [`minority-prophet-v1.0.4.md`](./minority-prophet-v1.0.4.md) | Preserved prior snapshot |
| [`minority-prophet-v1.0.3.md`](./minority-prophet-v1.0.3.md) | Preserved historical snapshot |
diff --git a/papers/minority-prophet-v1.0.7.md b/papers/minority-prophet-v1.0.7.md
new file mode 100644
index 0000000..2b8bbdf
--- /dev/null
+++ b/papers/minority-prophet-v1.0.7.md
@@ -0,0 +1,266 @@
+# The Minority Prophet Property
+
+## Truth recovery under copying pressure requires unforgeable origins, unblended sides, and a protected margin — and nothing more
+
+**v1.0.7 — reader-first, evidence-aligned pre-submission draft. Remaining release blockers are stated in §8.**
+
+*Author: James Siyuan He (Silent Partner). Reference implementations, proof drafts, replica experiments, and literature synthesis produced in collaboration with AI systems (Claude Fable 5; Codex) and re-verified as described in §10.*
+
+---
+
+### Abstract
+
+When copying is nearly free, a crowd can look large while containing very little independent evidence. This paper studies a narrow question: when can an aggregator recover a grounded minority from an overwhelming copied majority? Within a binary rooted-claim model, the answer depends on three conditions: protect the genuine evidence roots, prevent evidence from crossing between opposing sides, and expose the surviving root margin. Recorded copies then add no evidence, and same-side lineage mistakes that preserve the root set do not change the verdict. Formal proofs, exhaustive checks, randomized tests, synthetic adversarial experiments, a real-market measurement, and bounded lineage studies test different parts of that claim. Several preregistered hypotheses failed and remain reported as failures. The strongest results concern counting *declared* evidence correctly; they do not prove that a root is true, independent, authentic, complete, or authorized. Discovery coverage, root qualification, graded dependence, and deployment against a real provider remain open. The practical conclusion is deliberately small: count protected origins rather than repeated voices, preserve uncertainty, and report how much genuinely new opposing evidence could change the result.
+
+---
+
+### The idea in one minute
+
+Imagine that three people each look out a different window and report rain. Then 95 accounts copy one of those reports. A voice-count says **98 reports**. If the three original reports satisfy the root contract, an evidence-count says **three purported observations**. The copies may spread the message, but they do not create 95 new windows.
+
+```mermaid
+flowchart LR
+ A["Window A: one observation"] --> RA["Evidence root A"]
+ B["Window B: one observation"] --> RB["Evidence root B"]
+ C["Window C: one observation"] --> RC["Evidence root C"]
+ RA --> D["95 copied or transformed claims"]
+ RA --> E["Count roots, not repetitions"]
+ RB --> E
+ RC --> E
+ D -. "still descends from A" .-> E
+ E --> F["Result: 3 roots, plus margin and uncertainty"]
+```
+
+The hard part is not collapsing an acknowledged copy. The hard part is deciding what is allowed to become a root. This paper proves rules for counting a declared root structure and tests mechanisms around that boundary. It does **not** turn identity, signatures, agreement, or third-party labels into truth.
+
+### What the paper establishes—and what it does not
+
+| Established within the stated boundary | Not established |
+| --- | --- |
+| A recorded copy adds no new evidence. | That an asserted root is true or independent. |
+| Same-side rewiring is harmless when the root set is preserved. | That text similarity or timing can reliably recover causal copying. |
+| The honest root margin is the decision's safety budget. | That the search found every relevant observation. |
+| Unknown, ambiguous, or insufficient provenance should widen uncertainty or escalate. | That an evidence result authorizes an action. |
+| Several operational mechanisms work in their frozen test regimes. | Universal real-world performance or provider validation. |
+
+### Results at a glance
+
+| Question | Evidence | Status | Plain-language result |
+| --- | --- | --- | --- |
+| Do recorded copies create new evidence? | Theorems 1–4; Lean and finite checks | **Proved in model** | No. Preserve roots and sides, and repeated descendants do not change the count. |
+| Can an optimizer break inferred lineage? | EXP007A | **Supported, synthetic** | Yes. The frozen attack beat uniform comparators; thin-margin worlds failed more often. |
+| Can a conservative hybrid recover some missed minorities? | EXP009 | **Supported, synthetic** | Yes, but only a small slice and with a measured false-reversal cost. |
+| Can extra names, keys, or services manufacture independence? | HVI-1 | **Supported in frozen tests** | Not when supported control provenance is preserved; unknown control escalates. |
+| Can copied or transformed claims mint fresh origins? | HEO-1 | **Supported in frozen tests** | Not when supported derivation lineage is preserved; unknown or forged origins escalate. |
+| Does interval dependence accounting solve shared context? | HGD-1 and HGD-2 | **Rejected** | It often acted as a useful brake, but failed frozen effect, coverage, or usefulness criteria. |
+| Can new evidence restore coverage after abstention? | HES-1 | **Supported with a material limitation** | Often, but source competence depended on the direction and type of claim. |
+| Can text and time recover recorded reply roots? | LIR-1 | **Rejected** | Not well enough on the tested PHEME boundary. |
+| Can typed counterpart identity recover recorded components? | LIR-3 | **Supported, narrow boundary** | Yes on the sealed recorded-platform task; this is not causal independence. |
+| Does that recovery degrade gracefully when identity disappears? | LIR-4 | **Rejected** | No. Missing identity fragmented roots sharply, even while precision remained high. |
+
+### Choose a reading path
+
+- **Five-minute reader:** read this page, §1, §6, and §8.
+- **Technical reader:** add §§3–5 for definitions, proofs, and experiment-level results.
+- **Reviewer or reproducer:** also read §10, [`CANONICAL-RECORDS.md`](../CANONICAL-RECORDS.md), and [`EVIDENCE-ALIGNMENT.md`](../EVIDENCE-ALIGNMENT.md). The registries control if prose and evidence ever conflict.
+
+---
+
+### 1. Introduction
+
+Every consensus mechanism humanity relies on — markets, elections, peer review, "multiple sources confirm" — silently assumes independent agreement is costly to manufacture. Machine agents void that assumption: a claim can be copied perfectly, instantly, at scale, so a thousand assertions may contain one observation. The question is not whether majorities can be wrong but whether *any* aggregation procedure can tell a grounded minority from an ungrounded one once copying is free — and, if so, what infrastructure that requires.
+
+We formalize the **minority prophet property**: an aggregator satisfies it at level (ρ, α) if it recovers ground truth with probability α when a copied false majority outnumbers independent grounded observers by ratio ρ, *and* rejects ungrounded minorities. The property has two halves — recovery and rejection — with, we find, sharply different costs.
+
+Contributions: (i) an exact characterization, within the binary rooted-claim model, of when non-root lineage changes are verdict-irrelevant (Theorems 1–4); (ii) compiler-ratified Lean 4 proofs, exhaustive finite model checking over 5,912 side-consistent forest worlds and 116,032 root-preserving forest rewirings, a separate 252-world/1,992-rewiring multi-parent DAG audit, and 100,000 randomized instances with zero reported violations; (iii) a preregistered-and-rejected scalar-corruption hypothesis whose failure mode *is* the margin law; (iv) adversarial validation by an optimizing attacker that rediscovers the theorems' predictions; (v) a copy-dominant adversarial benchmark in which behavioral comparators, including a shared-mistake dependence detector, fail while declared-lineage aggregation remains invariant; (vi) a real-market measurement of recovery and rejection behavior across 5,729 resolved on-chain markets; (vii) canonical tests of graded dependence and evidence-seeking escalation that preserve rejected results and subgroup limitations; (viii) a closed lineage-inference series separating constructed root recovery, recorded platform lineage, typed provenance availability, and causal independence; and (ix) a three-part provenance requirement stack with a bounded-issuance reference and a normative proposal for agent-communication standards.
+
+The proved contribution concerns how declared evidence is counted, not whether discovery found every relevant observation. We therefore separate **discovery** (where the system looked), **provenance** (which records are genuinely distinct roots), and **decision** (what those roots support). Section 9 develops the resulting knowledge-ledger architecture only as a falsifiable research direction.
+
+### 2. Related work
+
+**Jury theorems and correlated votes.** Condorcet's theorem requires independent votes, and its literature has long shown effectiveness *decreasing* in inter-vote correlation (Ladha 1992; Berg 1993; Kaniovski 2010), with strong pairwise dependency destroying even monotonicity in group size (Berg 1993) and Dietrich (2008) arguing the theorem's premises are not simultaneously justified once deliberation, shared evidence, and opinion leaders induce correlation. The standard rescue — conditionalizing dependence away given common causes (Dietrich & Spiekermann; cf. Reichenbach's common-cause principle) — explicitly *fails* when votes influence one another directly rather than through shared evidence, i.e., precisely under copying. Our contribution can be read as the constructive complement: rather than conditioning on common causes one cannot observe, make the common-cause structure (the evidence roots) an attested observable, and aggregation over roots restores the theorem's engine. Hong & Page's re-interpretation — independently generated signals need not yield probabilistically independent votes — cautions that root-distinctness is a structural proxy for, not an equivalent of, probabilistic independence; we adopt that framing in §3.
+
+**Information cascades.** Banerjee (1992) and Bikhchandani, Hirshleifer & Welch (1992) showed rational sequential observers can lock into wrong cascades carried by the private information of a few early actors, and emphasized cascade *fragility*: revealing a private signal — not merely an action — can shatter a wrong cascade (BHW 1992; Peres et al. 2020). Our program operationalizes exactly that lever: an attested evidence root is a machine-checkable "revealed private signal," and the margin of Theorem 4 quantifies how many such revelations a cascade's correction requires. Smith & Sørensen (2000) and the herding literature supply the equilibrium analysis our generative model deliberately simplifies.
+
+**Truth discovery and source dependence.** The Dawid–Skene family and its EM descendants weight sources by inferred competence under an independence assumption. The source-dependence line — Dong, Berti-Équille & Srivastava (2009a,b), the global copying-detection extension (Dong et al. 2010), the SOLOMON system, HMM-based dynamic copy detection, and group-level aggregation over latent source clusters — is our closest neighbor: it detects copying from shared values, especially shared *false* values, and discounts dependent votes. Two limits, both stated within that literature, define our departure point: the principle weakens when sources copy a *good* source, and a source duplicated many times can dominate the first voting round, capturing the truth estimate on which dependence detection conditions (Dong et al. 2009a; Li et al. 2016 survey). Our E8b reproduces exactly this capture in the copy-dominant regime with a faithful shared-mistake detector, and our theorems characterize the structural guarantee under which the entire inference problem is dissolved rather than solved. We claim no superiority in their regimes (moderate copying, rich objects, no optimizing adversary); our claims are confined to copy-dominant and adversarial regimes, and a canonical head-to-head against their released implementations is a stated release blocker.
+
+**Peer prediction and elicitation without verification.** Prelec's Bayesian Truth Serum and the peer-prediction line (Miller, Resnick & Zeckhauser 2005; Witkowski & Parkes 2012; Shnayder et al. 2016) attack a complementary problem: *incentivizing* honest reports when truth is unverifiable. These mechanisms assume common priors and well-mixed pools, and admit uninformed/coordination equilibria whenever agents can coordinate on cheap signals (Gao et al.) — the incentive-layer analogue of our finding that behavioral signals collapse under coordinated copying. We view peer prediction as a candidate *pricing layer* atop attested roots (rewarding surprisingly-common answers among roots rather than among all voices) and leave the composition to future work.
+
+**Sybil resistance and Byzantine bounds (inherited endpoints).** Douceur (2002): without a costly or trusted identity substrate, one attacker simulates arbitrarily many participants. Byzantine agreement bounds and robust-statistics breakdown points delimit what any aggregator survives. Our composed-attack collapse instantiates this known territory; the contribution is the middle — the degradation shape and the minimal sufficient guarantee — not the endpoints.
+
+**Multi-agent LLM systems.** The debate literature now documents our disease in vivo: a "tyranny of the majority" in which minority agents conform to an incorrect majority (Wynn, Satija & Hadfield 2025); a proof that with many similar agents the probability debate changes the leading answer approaches zero (Estornell & Liu, NeurIPS 2024); measured herd behavior and conformity dynamics (Cho, Guntuku & Ungar 2025; Choi et al. 2025); and a conformity-driven prompt-injection attack on debate systems (MAD-Spear; Cui & Du 2025). Against this stand positive results — debate amplifying correctness over static ensembles under adaptive stopping (NeurIPS 2025) and interventions (diversity-pruning, misconception-refutation) with supporting theory (Estornell & Liu 2024). We reconcile by regime: those gains arise among capable heterogeneous reasoners without an adversary; our results concern adversarial copying, where E8/E8b indicate intervention-free behavioral aggregation does not survive. The debate community measures the failure; the requirement stack is a proposed cure at the transport layer rather than the prompt layer.
+
+**Provenance and agent-identity infrastructure.** C2PA signs media transformation history; W3C DIDs/VCs provide portable signed claims, now being specialized to agents (ledger-anchored agent DIDs with VC attestations, arXiv:2511.02841; AGNTCY agent badges; zero-trust agent IAM architectures). A recent survey frames a systemic "Identity Gap": many high-impact agentic failures are structural identity/authorization failures, not prompt-level misalignment. Closest to us at the protocol layer, Pramana (2026) proposes typed attestation surfaces for agent claims and observes that the VC data model does not type claims by epistemic ground. These efforts motivate the R1 substrate and wire formats. Our requirement stack (§6) states the guarantees this model needs from that substrate; the claimed distinction remains subject to the primary-source review listed in §8.
+
+**Logical aggregation.** Our E1 semantic aggregation is Łoś-inspired — verdicts over sufficiently large agreeing sets preserve logical coherence that propositionwise majority violates (cf. judgment-aggregation discursive dilemmas). Design inspiration only; no literal ultraproduct claims.
+
+### 3. Definitions
+
+A **world** W = (C, parents, assert) is a finite claim set C, a parent relation `parents(c) ⊆ C` inducing a DAG through a time order (p.t < c.t for every p ∈ parents(c)), and assert : C → {0,1}. Parentless claims are **roots** (purported independent observations); roots(c) is the set of parentless ancestors of c. W is **side-consistent** if every edge joins same-assertion claims — satisfied by construction when copies inherit assertions. Following Hong & Page, root-distinctness is a *structural independence proxy*: distinct roots are causally, not necessarily probabilistically, independent; graded dependence among roots is outside the counting theorem. Two scope notes from independent verification: outside side-consistency the literal S_a can place one root on both sides simultaneously, so all flow accounting is defined over side-consistent comparisons; and the (ρ, α) parameterization describes the inference regime only — under attested root counting the verdict is provably independent of copy volume, so ρ motivates the problem rather than parameterizing the attested solution.
+
+Root identity remains an operational trust-boundary decision, not a semantic theorem. The reference registry binds an authenticated issuer, issuer-scoped observation, proposition, value, evidence digest, key, time, and nonce into a bounded root receipt. This prevents arbitrary caller labels from entering the graph; it does not prove that an observation is true or independent.
+
+The **evidence-root aggregator** computes S_a(W) = ⋃ {roots(c) : assert(c) = a} and returns 1 if |S₁| > |S₀|, 0 if reversed, abstaining on ties (optionally below a margin threshold). The **margin** is ||S₁| − |S₀||. **[E6]** Every experimental result reported in this paper and its conformance program was produced at **τ = 0** — abstention on exact ties only, no positive margin threshold. The threshold remains an option of the definition, not an evaluated configuration; this is a scope condition on all published results, declared here after KL-000's traceability audit (TRC-101 rule CF-threshold) found it previously undeclared.
+
+Generative benchmark (E1, E3–E8b): hidden truth T; n independent observers (reliability r), each its own root; a prestigious originator; m ≫ n copiers attaching preferentially to the originator's tree; 60% of worlds place the copied majority on the false side. Adversary transformations (paraphrase, citation forgery, sybil identities, timing front-running, composition) corrupt the observables from which lineage must be inferred.
+
+### 4. Theorems
+
+**Lemma 1 (Side-locality).** In a side-consistent world, S_a is exactly the set of a-asserting roots. *Every parent path preserves assertion by well-founded induction; roots are their own ancestors.*
+
+**Theorem 1 (Immunity).** Any rewiring of parent edges that (i) preserves which claims are roots and (ii) preserves side-consistency leaves S₀, S₁, and the verdict exactly unchanged. *Both worlds reduce via Lemma 1 to the same root filter.* **Attribution accuracy among non-roots is irrelevant to the verdict; root-set integrity is load-bearing** (a single root-set-disturbing edit changes verdicts 33.0% of the time pooled at n=6 — concentrated entirely on margin-1 decisions; see T5). Empirical shadow: side-preserving corruption drove attribution 1.00 → 0.59 with accuracy never below 0.98 (E5); across 10 seeds, immunity-condition accuracy 0.994 [0.989, 0.999], indistinguishable from baseline (E7). **[E8]** Immunity is proved; in the schema the conformance program evaluates (v0.1, no parent edges) it is only *shadow-tested*: permutation invariance (KL-000 invariant I7) is strictly weaker than rewiring immunity, because the theorem's structure — parent edges to rewire — does not exist in that model. An end-to-end test requires a lineage-bearing schema.
+
+**Theorem 2 (Recorded-copy invariance).** Duplicating any claim *with its parent edge recorded* (same assertion, parent = the original) leaves the verdict unchanged. *The duplicate's root is already counted.* **[E1]** A copy whose provenance is **not** recorded is a parentless claim — an evidence root — and does change the verdict; it is governed by T5, not by this theorem. Compiled: `MinorityProphet.copy_invariance`.
+
+**Theorem 3 (Head-counting fails).** Majority voting is not copy-invariant (explicit counterexample); with no lineage, evidence-root aggregation degenerates to majority exactly (observed identically in E3). Together with the jury-theorem correlation results, this locates the failure of every voice-counting mechanism under free copying.
+
+**Theorem 4 (Margin flip condition).** For any transformation preserving claims and assertions, the verdict flips only if net per-side phantom root gain meets or exceeds the honest margin. *Immediate: the verdict is a threshold function of the side-count margin.* **The attacker's budget equals the margin in net per-side root-gain units (p₀ − p₁); the defender's lever is margin, not lineage purity.** **[E2]** Measured instead in adversary *actions* that convert a root from one side to the other — each worth two units — reversal costs ⌊margin/2⌋+1, not margin+1 (4,638/4,638 decisive worlds). Tightness (He), in p₀ − p₁ units: flow equal to the margin forces abstention (denial); reversal (deception) requires margin+1. **[E3]** T5, corrected: if two side-consistent worlds have the *same assertions* and their root sets differ by at most k elements, a verdict with margin > k survives and one with margin ≥ k cannot be reversed. The equal-assertions hypothesis is necessary (`T5_needs_assert_fixed`), and no immunity to "any single key compromise or operational error" follows — one deleted record can orphan a whole subtree and one compromised key can mint unboundedly many roots, which is why R1.4 was added to the requirement stack. This is the quantitative form of cascade fragility: BHW's observation that revealing private signals shatters wrong cascades becomes "a cascade is broken by attested roots exceeding its phantom margin."
+
+**Verification status (revised 2026-08-08). [E4]** Lean 4, pinned and compiling (v4.32.2 / Mathlib `905b958`, zero `sorry`, no added axioms): Lemma 1, Theorems 1, 2, 3, 4, 4′ and 5, a conversion-parity theorem, and three necessity witnesses — `formal/lean/`. The earlier claim that Theorem 3 was "fully proved" in Lean referred to a file that could not compile (`Fin.strongRecOn` does not exist in Mathlib). The independent forest implementation checked 5,912 side-consistent worlds, 116,032 root-preserving rewirings, and 4,166 duplications with zero violations. The multi-parent DAG audit separately checked 252 side-consistent worlds, 1,992 root-preserving rewirings, 962 duplications, and 1,072 single-edge edits with zero violations. Another 100,000 randomized larger forest instances reported zero violations. These are finite checks and randomized experiments, not proofs. The previously reported "flow == margin yielded abstain in 4,638/4,638" was produced by a check that never constructed a perturbed world; it has been rewritten.
+
+### 5. Experiments
+
+*Provenance labels: E1–E2 are canonical derived records. E3R–E6R and E8R are canonical archived-implementation replays, which establish deterministic portability rather than external validity. E6R reproduced a rejected H5. E7R is canonically incomplete; EXP007A is the distinct preregistered repository-native adversary completion. Other E8/E8b narrative claims remain replica/design-validation claims.*
+
+**E1 (canonical, synthetic pilot).** Under declared lineage, evidence-root and Łoś-inspired semantic aggregation recover minority truth where propositionwise majority fails; semantic aggregation preserves a three-proposition logical constraint majority violates. All methods fail under sufficiently corrupted lineage — the observation motivating everything below.
+
+**E2 (canonical, real markets).** 11,307 candidates → 5,729 eligible resolved weather-tagged binary on-chain markets. Market price dominates: Brier 0.0744, accuracy 89.7%, calibration error 1.24%, vs one-wallet voting 0.1221/84.0% and dependence-adjusted voting 0.1223/83.9%. H2a **rejected** (Brier Δ −0.000207, practically null — a shared-root domain offers no independence structure to exploit; consistent with the cascade literature's common-signal regime). H2b **rejected**: 1 underdog recovery vs exposure-weighting's 58 — at 0.10% vs 9.50% false-reversal rate — a 95× rate asymmetry; overrule precision at observed base rates is 14.9% vs 9.6% (≈1 correct : 5.7 false overrules at N=5,729), so the method's merit is its per-decision false-alarm rate, not precision-when-firing. H2c **provisionally supported**: abstention lifted answered-case accuracy 4.61 points at 88.9% coverage; matched-coverage comparison remains pending. Interpretation: in this dataset the method mostly went quiet rather than overrule a shared-signal domain; prices already perform stake-weighted aggregation, motivating a future stake-weighted root-counting test.
+
+**E3 (replica).** Inferred lineage (temporal + similarity + citation scorers) matches declared lineage under every *single* adversary (0.94–0.99; signal redundancy: each attack blinds one scorer, others compensate) and collapses under composition (lineage F1 0.99 → 0.32; accuracy 0.99 → 0.51).
+
+**E4 (replica).** Random-corruption degradation is a smooth ramp — no phase transition. The attack-intensity curve is a *valley*: uniform-maximal attacks self-defeat because uniformly disguised sybils become mutually similar and re-cluster (multi-seed: composed-0.5 accuracy 0.514 [0.495, 0.534] vs composed-1.0 recovery 0.910 [0.890, 0.929], disjoint CIs). Root-*set* overlap is blind to the damage; attribution is the meaningful lineage metric — which Theorem 1 then demotes.
+
+**E5 (replica).** Side-preserving control: corruption confined to same-side rewiring destroyed attribution (→ 0.59) at zero side-confusion with no accuracy cost (≥ 0.98) — the Immunity theorem's empirical shadow.
+
+**E6 (replica; H5 preregistered → REJECTED).** Signed side-confusion does not collapse corruption modes (max cross-mode spread 0.651): adversaries need only meet each world's margin, concentrating where margins are thin. The rejection is the discovery: promoted to Theorem 4.
+
+**EXP007A (canonical synthetic adversary completion).** The archived E7 runner was incomplete and is preserved as EXP007R with verdict `incomplete`. A new protocol and implementation were committed before execution. Its deterministic 45-evaluation search selected `(0.701175, 1.0, 0.0, 0.0)` and, on ten untouched holdout seeds, reduced inferred evidence-root accuracy to 0.3715 versus 0.4461 for uniform-0.5 and 0.4133 for uniform-1.0. Incorrect verdicts occurred in thinner-margin worlds than correct verdicts (3.7684 vs 5.6886; Welch t = 25.1144). Both preregistered hypotheses were supported and two clean runs were byte-identical. This replaces the unsupported historical E7 point estimates; it does not establish external validity.
+
+**E8 (replica; archived comparator shootout).** The archived multi-proposition runner and its table replay deterministically as E8R. Its attack condition uses a historical exploratory mixture, not EXP007A's selected parameters. The simplified baseline comparison remains design-validation pending a canonical head-to-head against released implementations; E8R does not promote those broader claims.
+
+**E8b (replica; the Dong conflict test).** Dong et al. report high accuracy under transitive copying; to test whether E8's collapse was a strawman artifact, we implemented the faithful mechanism — shared-*false*-value dependence likelihoods conditioned on estimated truth, temporal direction, vote discounting, jointly iterated. Result: it remains at majority performance (0.737 no-adversary; 0.742 under attack; minority recovery ≤ 0.004) in the copy-dominant regime, for the exact reason Dong et al. flag: with 40 of 47 sources copying one root, the initial truth estimate is captured by the echo, so copiers' shared errors score as shared truths. Their successes and ours are regime-separated, not contradictory. Additional finding: attacks are *method-specific* — an optimizer targeting the dependence detector found only a mild minimum (0.704) whose mix leaves it at 0.740 in full evaluation while *improving* inferred-lineage root counting to 0.772; conversely E7's anti-inference mix leaves the dependence detector unmoved. No universal behavioral attack emerged, but no behavioral method was attack-invariant; only attested lineage was (0.996 across every condition tested). (Caveats: our implementation is a faithful reconstruction, not Dong et al.'s released code, and their exact initialization may narrow the gap; canonical head-to-head is a release blocker.)
+
+**EXP009 (canonical selective-hybrid confirmation; SUPPORTED).** A selective challenger froze majority as the default and permitted inferred-root reversal only on disagreement with root margin at least 3. On untouched attack-regime seeds 301–320, it recovered 1.97697% of copied-minority cases, lost 0.1125 percentage points of overall accuracy, and produced a 0.64375% false-reversal rate. The paired world-bootstrap intervals satisfied all three frozen primary hypotheses. With hidden generator lineage, the diagnostic ceiling recovered 87.3590% with zero false reversals. Two clean runs produced byte-identical scientific output. This is a synthetic policy result; the declared result is an oracle ceiling and neither result grants authority.
+
+**HVI-1 (canonical shared-control confirmation; SUPPORTED).** Across 5,000 base worlds and 50,000 matched representations, supported controller provenance made alias, key-rotation, service-split, and label multiplication evidentially null; self-verification added zero roots; unknown control always escalated; and genuinely separate supported controllers were retained. All six frozen hypotheses passed, with byte-identical clean runs. The boundary was equally important: eight separate controllers carrying the same matched adverse claim remained eight roots and yielded 75.72% error. Control separation blocks representation laundering; it does not prove causal evidence independence, hidden ownership, truth, or authority.
+
+**HEO-1 (canonical evidence-origin confirmation; SUPPORTED).** Across 5,000 base worlds and 50,000 matched representations, supported derivation lineage made byte copying, paraphrasing, translation, summarization, model transformation, and mixed transformation evidentially null. Unknown and forged origins always escalated, and supported separate origins were retained. Origin-aware decision error remained 3.54% across transformed-copy conditions, while controller counting treated 32 descendants as 32 roots and reached 75.32% error. Two clean runs were byte-identical. The genuine-origin condition again marks the boundary: separate captured observations can agree and still be wrong; recorded origin structure is not truth or authority.
+
+**HGD-1 (canonical graded-dependence experiment; REJECTED).** HGD-1 tested whether interval-valued dependency accounting could preserve distinct measurements while reducing false confidence from shared sensor context and common-mode failure. Six of seven frozen hypotheses passed, but the primary claim failed because the largest observational false-confident-error reduction was 4.23 percentage points, below the preregistered 5-point requirement. In 5,000 synthetic common-mode worlds, head counting was confidently wrong in 100% of worlds; interval accounting was confidently wrong in 75.78% and abstained in 24.22%. The 50,978-case EPA track showed a strong directional safety signal without meeting the frozen absolute-effect threshold. Collocation does not prove causal dependence, and the result grants no authority.
+
+**HGD-2 (canonical graded-dependence replication; REJECTED).** HGD-2 activated common-mode failures in EPA measurements and NIST SARD software-analysis cases while adding untouched controls. Five of seven frozen hypotheses passed. Interval accounting substantially reduced false-confident error and preserved control accuracy, but control coverage and attacked usefulness failed: on activated software cases, interval coverage was 32.14%, and untouched answered coverage fell to 25%. The method behaved as a strong brake but not a reliable steering system; much of its safety gain came from abstention.
+
+**HES-1 (canonical evidence-seeking experiment; SUPPORTED WITH MATERIAL SUBGROUP LIMITATION).** After dependency-aware abstention, HES-1 selected one missing evidence source using frozen provenance, availability, and cost criteria before candidate values were inspected. All seven hypotheses passed. Independent EPA evidence recovered 85.05%–88.98% of environmental abstentions; Cppcheck recovered 71.05% of 38 software abstentions. The pooled software result concealed a decisive asymmetry: conditional accuracy was 100% on false-positive attacks but only 40% on false-negative attacks, where six of eleven unresolved cases became wrong answers. Structural independence was necessary but not sufficient; evidence sources must also be qualified for the direction and type of claim they are allowed to support. Unknown evidence and dependent duplicates continued to escalate rather than lowering the decision threshold.
+
+**LIR-1/PHEME-R2 (canonical recorded-lineage recovery; REJECTED).** With 40% of recorded PHEME reply edges hidden, the frozen text/time parent method produced hidden-parent F1 `0.1044` and root-pair recall `0.2256`, rejecting its preregistered criterion. PHEME reply trees record platform relationships, not causal evidence ancestry or independence.
+
+**LIR-1E and LIR-2 (canonical constructed recovery; SUPPORTED WITH BOUNDARIES).** LIR-1E recovered useful constructed roots but materially abstained: on 36 confirmatory cases it answered 25 and was correct on 21. LIR-2's direct root grouping then answered 34 of 36 new constructed cases correctly, with root precision `1.0` and recall `0.9522`. When transferred without retuning to PHEME-R2, however, LIR-2 retained precision `1.0` but recall fell to `0.2020`, F1 to `0.3362`, and root-count MAE rose to `5.5517`; the transfer claim was rejected.
+
+**LIR-3 (canonical observable-provenance bridge; SUPPORTED).** LIR-3 tested previously unused PHEME cases after preserving reply-target author identity while still hiding 40% of exact parent-status IDs. A configuration selected on 417 development cases used only target-author identity—no mention or text fallback. On a sealed 425-case, 5,000-claim holdout it achieved recorded-root precision, recall, and F1 of `1.0` with zero root-count error; frozen LIR-2 on the same cases had recall `0.2534`. This supports a narrow interface result: non-exact typed provenance can recover recorded platform components. It does not authenticate an author, establish causal copying, or prove independent evidence.
+
+**LIR-4 (canonical provenance-degradation experiment; REJECTED).** On 400 final-unused PHEME cases, intact target-author identity again yielded precision and recall `1.0`. Removing identity from 25% of hidden-edge records reduced recall to `0.6764`; removing it from 50% reduced recall to `0.4329`, F1 to `0.6043`, and raised root-count MAE to `2.405`, rejecting the graceful-degradation claim. Precision remained `1.0` throughout the missingness curve: failure appeared as fragmentation rather than false merging. But 399 of 400 cases contained only one recorded root, leaving the preregistered forged-identity safety diagnostic underpowered. No general resistance-to-misbinding claim is permitted.
+
+**Field observation (noncanonical).** A sanitized structural derivative of an internal 17-claim run reproduced 8 self-attestation abstentions and 9 one-root decisions. Six records from one observer counted as one root when keyed by observer and six when keyed by event, changing margin without changing claim values. This demonstrates the operational importance of root identity and observer concentration; it does not validate the private claims, prove independence, or resolve U1.
+
+### 6. The provenance requirement stack
+
+Within the formal model, the theorems reduce "what must provenance guarantee?" to three layers, replacing the full-lineage assumption:
+
+**R1 — Root integrity.** Evidence roots unforgeable: no manufactured originals, no copies laundered into roots. Douceur's impossibility is escaped here by importing cost or cryptography (attestation, capture-time signing, stake); the theorems are vacuous without it. *Metric: root-set accuracy.*
+
+The repository now includes a provider-neutral `RootRegistry` reference for R1.4. It authenticates issuers, bounds root issuance per issuer and time window, rejects replay and uncertain state, serializes cross-process allocation, preserves tombstones, and detects audit-log mutation. This is an operational mechanism outside the theorem: it limits root-forgery capacity but does not establish truth or causal independence.
+
+**R2 — Side-separation.** Claims never attributable to opposing-side roots. Given R1 and R2, all other lineage error is provably harmless (T1). *Metric: side-confusion = 0; runtime diagnostic `immunity_applicable`.*
+
+**R3 — Margin sufficiency.** The honest independent-root margin must exceed the adversary's root-forgery capacity (T4); defense planning is necessarily margin-relative (H5's rejection). *Metrics: `flip_budget` in units of net per-side root change and `conversions_to_reverse` in side-conversion actions; both are surfaced with every verdict.*
+
+**Not required by these theorems:** who-copied-whom accuracy, full lineage trees, copy counts, and non-root attribution accuracy. This narrows the information the formal aggregator consumes to protected roots, side separation, and margin. Whether that narrower infrastructure is cheaper in a deployment remains an engineering question, not a theorem.
+
+The LIR series adds an empirical interface qualification without changing the theorem: exact parent attribution was unnecessary for recorded-component recovery when typed counterpart identity survived, but that identity was load-bearing and its loss produced fragmentation. A ledger may therefore omit full non-root trees only if it preserves enough typed provenance to identify the protected roots it intends to count; otherwise it must expose uncertainty rather than mint apparent independence.
+
+For agent-communication standards, one normative sentence: *transports MUST preserve evidence-origin attestations such that claims descending from distinct attested roots remain distinguishable and cross-origin attribution is infeasible; systems SHOULD expose the surviving root margin with every aggregate decision.*
+
+### 7. Applications
+
+A reference aggregator implementing the specification (stdlib Python; conformance vectors derived from the formal definitions) returns with every verdict: decision, per-side root sets, `immunity_applicable` (whether T1's side-consistency precondition holds on this input), `flip_budget` (net per-side root-change units), and `conversions_to_reverse` (the cheapest side-conversion count). These convert the theorems into runtime diagnostics for multi-agent orchestration: a consumer of "7 of 9 sub-agents agree" can act on roots and margin rather than voices. They do not grant authority; consequential systems must preserve an independent authorization decision and escalate evidential uncertainty rather than translate it into permission.
+
+These outputs form a candidate **evidence label**: an auditable summary of roots, collapsed repetitions, dependencies, opposing evidence, margin, reversal units, and reasons for abstention. The label exposes what the formal aggregator consumed; it does not certify that the collection process searched a complete domain.
+
+### 8. Limitations
+
+The counting theorems remain binary and do not model graded dependence. HGD-1 and HGD-2 test one interval-accounting mechanism operationally; their rejected primary claims do not promote that mechanism into the theorem. HES-1 tests one bounded evidence-seeking policy and has a material claim-direction limitation. The constructed lineage generator uses token sets and controlled single-parent cases. PHEME supplies recorded reply-tree labels, not causal evidence-lineage or independence labels; it is one previously studied corpus family, and its final LIR-4 holdout contained only one multi-root case. LIR-3's perfect recorded-root result therefore cannot support forged-identity resistance or cross-platform generalization, and LIR-4's preserved precision under missingness cannot establish safety against false cross-root metadata. Root identity is assigned by an operational contract rather than derived semantically. Expiry, revocation, shared infrastructure, and key compromise remain outside the counting theorems. Canonical replays validate archived implementations rather than scientific generalization; EXP007A and EXP009 are canonical but synthetic; and the field observation is noncanonical. E8/E8b comparisons await a canonical released-implementation head-to-head, E2's matched-coverage analysis remains open, the neutral evidence contract has not been tested against a real provider, and literature citations still require primary-source verification. The R1 reference limits issuance but does not prove truth or independence.
+
+The theorems evaluate a declared evidence set; they do not prove that discovery covered every place a counterexample could occur. An absence claim requires a finite, declared search space and exhaustive reported coverage. Otherwise the strongest permissible conclusion is **not established**, not **absent**. Independent agreement cannot repair incomplete search, just as exhaustive search cannot repair duplicated or forged evidence.
+
+### 9. Research direction: a dual-ledger knowledge architecture
+
+> Minority Prophet reduces the lineage needed to evaluate evidence; it does not reduce the coverage needed to prove absence. Absence remains practical when the possible locations are finite, declared in advance, and exhaustively searchable.
+
+This boundary suggests two linked audit records. An **evidence ledger** records authenticated roots, collapsed copies, declared dependencies, side separation, supporting and opposing root sets, margin, reversal units, and reasons for abstention. A **search ledger** records the proposition, claim type, finite eligible search space, inclusion and exclusion rules, locations searched or unavailable, coverage numerator and denominator, retrieval method, and stopping rule. **[E7]** Search-ledger location identifiers MUST be pairwise distinct. A ledger padded with duplicate entries for an already-searched location inflates the coverage denominator's reconciliation exactly as unrecorded copies inflate evidence — the search-ledger form of the copy attack this paper exists to prevent, and a gap in it: the theorems govern the evidence ledger and were silent here. Both independently written implementations refused duplicate identifiers unprompted before this requirement was stated anywhere; KL-000 registered it as hard invariant I11 (protocol v1.1.0).
+
+Discovery writes the search ledger; provenance writes the evidence ledger; decision consumes both.
+
+The completed LIR series sharpens what the provenance writer must retain. Content and time did not substitute for recorded lineage on PHEME; reply-target author identity did, but performance collapsed as that field disappeared. Typed provenance is therefore a measured information dependency in this corpus, not merely decorative metadata. Whether a signed evidence-origin attestation supplies the same bridge across platforms remains an open test.
+
+The architecture is intended to prevent two different category errors: copies becoming witnesses and incomplete searching becoming proof of absence. It is not established by the present theorems. Schemas, deterministic conclusion-strength rules, positive and negative controls, incomplete-coverage adversaries, matched comparisons, and at least one real-provider test must be preregistered and evaluated before any performance or product claim. The controlled program is specified in [`RESEARCH-DIRECTION.md`](../RESEARCH-DIRECTION.md).
+
+The proposed endpoint is measurable knowledge accounting, not a general truth machine: every material conclusion should expose where the system looked, which observations were independently grounded, what evidence was collapsed, what could reverse the verdict, and what remains unknown.
+
+### Acknowledgments
+
+Christopher He independently re-implemented the Section 3 definitions from this manuscript, reproduced the formal checks, and identified corrections C1–C5 first incorporated in v1.0.1 — including the E2 precision framing and the T4 tightness distinction.
+
+### 10. Provenance of this paper
+
+An independent re-implementation from the manuscript by Christopher He (August 2026) reproduced the stated formal checks and sourced corrections C1–C5. E2 normalized results and analysis are hash-bound; raw trades are not redistributed. EXP003R–EXP008R preserve canonical replay records, including E6R's rejected H5 and E7R's incompleteness. EXP007A, EXP009, HVI-1, HEO-1, HGD-1, HGD-2, HES-1, and LIR-1–LIR-4 have public preregistrations or pre-execution protocol commits, complete bounded outputs, source or input manifests, and byte-identical clean reruns. PHEME tweet text and identities remain local; public hashes bind normalized inputs without redistributing them. The bounded-issuance reference is covered by adversarial and cross-process tests. The sanitized field packet is hash-bound but noncanonical. See `CANONICAL-RECORDS.md` and `EVIDENCE-ALIGNMENT.md`; where this manuscript conflicts with them, the registry controls. Citation verification remains a release blocker.
+
+*For the reader who skims: copied agreement is not independent evidence; count protected roots, preserve side separation, and report margin.*
+
+---
+
+### Glossary
+
+| Term | Meaning in this paper |
+| --- | --- |
+| **Claim** | One recorded assertion for either side of a binary proposition. |
+| **Copy / descendant** | A claim derived from an earlier claim. A recorded descendant does not become new evidence merely because it is repeated or transformed. |
+| **Evidence root** | A parentless claim admitted by the operational root contract as a purported original observation. “Root” does not mean “true.” |
+| **Lineage** | The recorded derivation path connecting descendants to roots. |
+| **Side-separation** | The requirement that a claim cannot be attributed to a root supporting the opposing side. |
+| **Margin** | The absolute difference between the number of admitted roots supporting each side. |
+| **Flip budget** | The smallest net per-side root change that can erase or reverse the current root margin. |
+| **Abstention** | Refusing to choose a side when the evidence is tied, insufficient, ambiguous, or outside the mechanism's qualified boundary. |
+| **Canonical record** | A record whose protocol, implementation, inputs or manifests, outputs, and hashes are identified by the repository registry. Canonical does not mean universally true. |
+| **Preregistered** | The hypothesis, metric, threshold, and stopping rule were fixed before the confirmatory run. |
+| **Synthetic** | Produced by a controlled generator rather than observed as a general real-world deployment. |
+| **PHEME** | The public social-media rumor corpus used here only for recorded reply-tree lineage tasks. Its reply edges are not labels of causal evidence dependence. |
+| **Evidence ledger** | The proposed record of admitted roots, collapsed repetitions, dependencies, margins, and uncertainty. |
+| **Search ledger** | The proposed record of where the system looked, what was eligible, what was unavailable, and when the search stopped. |
+
+### Selected primary references
+
+These links are reader entry points for central neighboring results, not a declaration that the full citation audit is complete. The verbatim primary-source review of every literature claim remains a release blocker in §8.
+
+1. Abhijit V. Banerjee, “[A Simple Model of Herd Behavior](https://doi.org/10.2307/2118364),” *The Quarterly Journal of Economics* 107(3), 1992.
+2. Sushil Bikhchandani, David Hirshleifer, and Ivo Welch, “[A Theory of Fads, Fashion, Custom, and Cultural Change as Informational Cascades](https://doi.org/10.1086/261849),” *Journal of Political Economy* 100(5), 1992.
+3. Sven Berg, “[Condorcet's Jury Theorem, dependency among jurors](https://doi.org/10.1007/BF00187435),” *Social Choice and Welfare* 10, 1993.
+4. Krishna K. Ladha, “[The Condorcet Jury Theorem, Free Speech, and Correlated Votes](https://doi.org/10.2307/2111584),” *American Journal of Political Science* 36(3), 1992.
+5. John R. Douceur, “[The Sybil Attack](https://www.microsoft.com/en-us/research/publication/the-sybil-attack/),” *IPTPS*, 2002.
+6. Xin Luna Dong, Laure Berti-Équille, and Divesh Srivastava, “[Integrating Conflicting Data: The Role of Source Dependence](https://www.vldb.org/pvldb/vol2/vldb09-pvldb47.pdf),” *Proceedings of the VLDB Endowment* 2(1), 2009.
+7. Andrew Estornell and Yang Liu, “[Multi-LLM Debate: Framework, Principals, and Interventions](https://proceedings.neurips.cc/paper_files/paper/2024/hash/32e07a110c6c6acf1afbf2bf82b614ad-Abstract-Conference.html),” *NeurIPS 2024*.
+8. Andrea Wynn, Harsh Satija, and Gillian Hadfield, “[Talk Isn't Always Cheap: Understanding Failure Modes in Multi-Agent Debate](https://arxiv.org/abs/2509.05396),” arXiv:2509.05396, 2025.
+9. Young-Min Cho, Sharath Chandra Guntuku, and Lyle Ungar, “[Herd Behavior: Investigating Peer Influence in LLM-based Multi-Agent Systems](https://arxiv.org/abs/2505.21588),” arXiv:2505.21588, 2025.
+10. Hyeong Kyu Choi, Xiaojin Zhu, and Sharon Li, “[Debate or Vote: Which Yields Better Decisions in Multi-Agent Large Language Models?](https://proceedings.neurips.cc/paper_files/paper/2025/hash/934252acd87f254d5d4672fbde283bd2-Abstract-Conference.html),” *NeurIPS 2025*.
+11. Yu Cui and Hongyang Du, “[MAD-Spear: A Conformity-Driven Prompt Injection Attack on Multi-Agent Debate Systems](https://arxiv.org/abs/2507.13038),” arXiv:2507.13038, 2025.
+
+### Appendix A — Version history
+
+> **VERSION NOTE (2026-08-09).** v1.0.7 adds a reader-first abstract, plain-language example, visual model, boundary table, results map, reading paths, glossary, and selected primary-source links. It does not change any theorem, experiment result, canonical status, limitation, or release blocker. v1.0.6 remains preserved as the prior evidence-aligned snapshot.
+
+> **VERSION NOTE (2026-08-08).** v1.0.6 closes the LIR-1–LIR-4 lineage-inference series. It records the rejected real-corpus text/time results, supported constructed results, supported typed-provenance bridge, and rejected graceful-degradation claim without promoting recorded PHEME reply roots into causal evidence independence. The series is complete at this boundary; a balanced multi-root or cross-platform LIR-5 would be a separate research chapter. No earlier paper is rewritten.
+
+> **VERSION NOTE (2026-08-08).** v1.0.5 incorporates the canonical HGD-1, HGD-2, and HES-1 records. The graded-dependence primary claims were rejected despite strong safety signals; the evidence-seeking primary claim was supported with a material claim-direction limitation. This version also corrects the stale internal version label in v1.0.4, aligns the definitions with the compiler-ratified multi-parent DAG, and separates the audited forest-world and rewiring counts that earlier versions had summed and mislabeled. No earlier paper is rewritten.
+
+> **VERSION NOTE (2026-08-08).** v1.0.4 adds three evidence-alignment entries from the KL-000 conformance program — [E6] the abstention-threshold scope condition (all published results ran at τ = 0), [E7] search-ledger identifier uniqueness (closing this paper's own thesis gap on the search ledger), and [E8] a footnote recording that Theorem 1 is proved but only shadow-tested in the evaluated schema. No theorem, proof, or result is changed. See [`ERRATA.md`](./ERRATA.md). v1.0.3 remains preserved as the prior evidence-aligned snapshot.
+
+> **VERSION NOTE (2026-08-07).** v1.0.3 preserves every result and limitation in v1.0.2 and makes explicit the architectural consequence of the provenance reduction: a proposed dual evidence/search ledger. The extension is a research direction, not an established theorem, experiment, or product claim. v1.0.2 remains preserved as the prior evidence-aligned snapshot.
diff --git a/tests/rendered-html.test.mjs b/tests/rendered-html.test.mjs
index b646e1b..488849c 100644
--- a/tests/rendered-html.test.mjs
+++ b/tests/rendered-html.test.mjs
@@ -24,5 +24,7 @@ test("server-renders the Minority Prophet research interface", async () => {
assert.match(html, /DEMONSTRATION WORLD/);
assert.match(html, /Evidence is not/);
assert.match(html, /Evidence assessment never grants authority/);
+ assert.match(html, /Read the paper/);
+ assert.match(html, /minority-prophet-v1\.0\.7\.md/);
assert.doesNotMatch(html, /Starter Project|react-loading-skeleton/i);
});
diff --git a/tests/test_evidence_alignment.py b/tests/test_evidence_alignment.py
index c1b1c9d..8729774 100644
--- a/tests/test_evidence_alignment.py
+++ b/tests/test_evidence_alignment.py
@@ -37,7 +37,7 @@ def test_formal_ledger_matches_bounded_issuance_reference(self):
self.assertNotIn("new in v3, unimplemented", requirements)
def test_active_paper_uses_canonical_exp007a_values(self):
- paper = (ROOT / "papers/minority-prophet-v1.0.6.md").read_text()
+ paper = (ROOT / "papers/minority-prophet-v1.0.7.md").read_text()
self.assertIn("EXP007A", paper)
self.assertIn("(0.701175, 1.0, 0.0, 0.0)", paper)
self.assertIn("Welch t = 25.1144", paper)
@@ -54,12 +54,12 @@ def test_alignment_values_equal_canonical_result(self):
def test_exp008_is_not_presented_as_exp007a_attack(self):
source = (ROOT / "experiments/exp008_shootout.py").read_text()
- active_paper = (ROOT / "papers/minority-prophet-v1.0.6.md").read_text()
+ active_paper = (ROOT / "papers/minority-prophet-v1.0.7.md").read_text()
self.assertIn("it is not EXP007A's selected attack", source)
self.assertIn("historical exploratory mixture", active_paper)
def test_active_paper_tracks_current_research_boundaries(self):
- paper = (ROOT / "papers/minority-prophet-v1.0.6.md").read_text()
+ paper = (ROOT / "papers/minority-prophet-v1.0.7.md").read_text()
ledger = (ROOT / "EVIDENCE-ALIGNMENT.md").read_text()
readme = (ROOT / "README.md").read_text()
@@ -67,7 +67,7 @@ def test_active_paper_tracks_current_research_boundaries(self):
self.assertIn("conversions_to_reverse", paper)
self.assertIn("EXP009 (canonical selective-hybrid confirmation; SUPPORTED)", paper)
self.assertIn("Field observation (noncanonical)", paper)
- self.assertIn("minority-prophet-v1.0.6.md", ledger)
+ self.assertIn("minority-prophet-v1.0.7.md", ledger)
self.assertIn("papers/00-CURRENT-PAPER.md", readme)
self.assertIn("evidence ledger", paper)
self.assertIn("search ledger", paper)
@@ -81,8 +81,8 @@ def test_active_paper_tracks_current_research_boundaries(self):
current_pointer = (ROOT / "papers/00-CURRENT-PAPER.md").read_text()
papers_index = (ROOT / "papers/README.md").read_text()
- self.assertIn("minority-prophet-v1.0.6.md", current_pointer)
- self.assertIn("minority-prophet-v1.0.6.md", papers_index)
+ self.assertIn("minority-prophet-v1.0.7.md", current_pointer)
+ self.assertIn("minority-prophet-v1.0.7.md", papers_index)
for stale in (
"Lean 4 formalization in progress",
@@ -96,3 +96,22 @@ def test_active_paper_tracks_current_research_boundaries(self):
self.assertIn("116,032 root-preserving rewirings", paper)
self.assertIn("1,992 root-preserving rewirings", paper)
self.assertIn("parents(c) ⊆ C", paper)
+
+ def test_active_paper_has_a_reader_first_layer_without_hiding_boundaries(self):
+ paper = (ROOT / "papers/minority-prophet-v1.0.7.md").read_text()
+ self.assertTrue(paper.startswith(
+ "# The Minority Prophet Property\n\n"
+ "## Truth recovery under copying pressure requires unforgeable origins, "
+ "unblended sides, and a protected margin — and nothing more"
+ ))
+ self.assertIn("### The idea in one minute", paper)
+ self.assertIn("```mermaid", paper)
+ self.assertIn("### What the paper establishes—and what it does not", paper)
+ self.assertIn("### Results at a glance", paper)
+ self.assertIn("### Choose a reading path", paper)
+ self.assertIn("### Glossary", paper)
+ self.assertIn("### Selected primary references", paper)
+ self.assertIn("They do not grant authority", paper)
+ self.assertIn("literature citations still require primary-source verification", paper)
+ self.assertGreater(paper.index("### Appendix A — Version history"),
+ paper.index("### 10. Provenance of this paper"))