Addendum — one pattern at two layers, and the blast radius is closed¶
1. The blast radius did not grow — 2 of 43¶
Full scan, no sampling, zero fetch failures. The unsound class is the two envelopes already known: both generation, both 2026-07-19, both client_id NULL, both unreachable through the deployed GET handler, which rejects on row.client_id !== client_id and never matches NULL.
No generation envelope produced from a full payload carries an empty trace map. No client-attributed envelope is unsound. The class turned out to be bounded by the empty-payload symptom after all — this seat argued it would not be, and was wrong in the good direction.
Confined to the pre-auth era, boundary cited from UCCA-VERDICT-MINT-AUTHGATE-2026-07-20, not re-derived.
2. This seat's defect — a test that would have manufactured fourteen false positives¶
The card defined the unsound class as "trace_map empty or absent AND non-empty asserted content." Applied literally that yields 16. Fourteen are sound.
Diagnosis envelopes do not carry a top-level trace_map at all — their anchors live in findings[].anchors. Lane A had already recorded this. This seat wrote the test without checking, and the test would have swept in every diagnosis envelope by construction.
Three of the fourteen carry client_id = rtopacks — and the card's own read 3 says a client-attributed unsound envelope means "the defect reached a named client and the crossing changes character entirely." The literal result would have escalated a non-incident into a crossing, and it would have been the second withdrawn number in two days, in a card written to prevent exactly that.
Third instance of the same class in two days from this seat: mechanism asserted before the path was established. It was caught because the agent executing the card checked the shape before applying the predicate. The card's value was in being executable and wrong in a detectable way; that is not a substitute for being right.
Proposed, unruled, and now with evidence behind it: a test written into a card is verified against one instance of each shape it will run over, before the card is relayed.
3. The asymmetry — and it is one pattern, not two gaps¶
| backward (diagnosis) | forward (generation) | |
|---|---|---|
| gate | elements.length > 0 and every element typed |
!!b.triumvirate — truthiness |
| pre-seal | anchor fence — if not anchors: raise, "schema also enforces this; defence in depth" |
_trace_closes — "Closure != coverage", vacuous True on [] |
| semantics | TRACED ⇒ anchors, NOT_YET_TRACED ⇒ search_account, raises on non-conformance |
none |
Nothing on the forward path refuses to seal an unanchored artefact, at any layer. _trace_closes iterates the map; an empty map iterates zero times and returns True. _provenance_complete requires four keys and explicitly permits corpus_citation: null. Schema conformance passes because the schema requires the key, not a populated one.
The reading, offered as a reading: diagnosis is the newer path — proven and merged 2026-07-04 — and the anchor discipline was designed into it at both layers. Generation predates it and was never retrofitted. The rigour exists in this engine; it was simply never pointed backwards at the older path.
The canon-level statement, which is the one for the crossing: NORTHSTAR holds that generation "traces coverage by construction." There is no construct. Coverage on the forward path is a property of well-formed input, not an enforced invariant — and the two envelopes are what that distinction looks like when the input is not well-formed.
4. What this changes and what it does not¶
Does not change: the artefacts are closed history — 2 of 43, pre-auth, NULL-client, unreachable, nothing client-attributed affected.
Does change: the live defect is two defects at two layers, not one at the gate. A gate outcomes check alone would close the symptom and leave the seal unguarded. The fix is a pair, and the backward path is the template for both halves — this is bringing forward up to a standard the same engine already holds, not new doctrine. Build brief, Window 2, not tonight.
Unchanged and owed to Tim: Q1 course_code; revoke-or-record on the two envelopes — and this seat's view has firmed to RECORD, not revoke, now that the class is closed at two, both unreachable and both evidence of a live defect that is being fixed; and whether the 2026-07-20→22 rtopacks burst was Tim or Alex.
RECEIPT-CHECK: echo this line's end before acting.