diff --git a/OVERSEER-STATUS.md b/OVERSEER-STATUS.md index d21e7d9..446cb5f 100644 --- a/OVERSEER-STATUS.md +++ b/OVERSEER-STATUS.md @@ -104,3 +104,5 @@ RQ2 RATIFIED (operator Andre, 2026-07-20, while blind) — observation-consisten - SEALED IMMUTABLY: `output/sor-rq2p3-confirmatory/rq2p3-confirmatory-results.json` (SHA-256 `5fdcb379d8a2…`) + `SHA256SUMS`; `/output/` gitignored → anchors force-added into the STEP-2 stone. Byte-identical on re-run (determinism verified). Tests: `tests/test_sor_rq2p3_confirm.py` 7 passed; full SOR suite 201 passed (no regression, frozen instruments untouched). NEXT: STEP 3 (RQ3 confirmatory — re-probe grid, launch live if up). - STEP 3 — RQ3 CONFIRMATORY battery LAUNCHED LIVE (D2 GO, grid UP). Grid re-probed via `grid.write_device_map` (real SSH+docker subprocess probes): reachable=3, isolated_engine_host_count=1 (laptop docker up), devices_down=[] (FULL), honourable=true; `sor-hop:latest` image present (16.8MB). Green preflight: both RQ3 calibration gates already green + a 1×1×2 LIVE rehearsal DELIVERED (real docker circuit, measured added-latency ~9.8s/circuit). New triple-locked launcher `cmd_chat/sor/rq3_confirmatory_run.py` (RQ3 analogue of confirmatory_run.py): lock1 operator token SOR_CONFIRMATORY_GO=1, lock2 LEAD prereg SHA f22331a72e… verified (RQ3 is in the frozen lead family-of-7), lock3 assert_isolated(docker != local). All three armed ("[RQ3 GO] all locks armed"). - RUNNING (do NOT trim): `executor.run_rq3_battery(live=True)` collecting the full frozen schedule — selector∈{static,random,agent} × pinned churn kp30/steps20, R=30 × C=50 = 4,500 real isolated-docker circuits (~12h est. at ~9.8s/circuit). Launch dir `output/sor-rq3-confirmatory/20260722T040640Z/confirmatory-data/` (gitignored; force-add anchors on completion). Verified genuinely progressing: python PID 51087 alive + live 4-container circuit (client+3 hops) up on docker. **Completion-detection: `rq3-battery-results.json` written once at end; progress = count of `rq3-*/rq3-run.json` sidecars → 90 (3 cells × 30 runs).** Containment intact (isolated-docker only, self-traffic, $0 — local heuristic/random arms; no frontier spend). Both prereg SHAs intact; worktree-only. Analysis (RQ3-P1-perf/latency, RQ3-P2, Holm-7) runs AFTER completion on the sealed record. +- 2026-07-21 COMPANION PAPER — RQ2-P3 HALF FILLED POST-SEAL (D3 combined paper). `docs/stage-07-companion-methods.md`: §3 un-marked FREEZE-PENDING → FROZEN 2026-07-21 (SHA 8db4e8a7…); §5 Results + §6 Discussion for RQ2-P3 filled FROM THE SEALED RECORD ONLY (H1 ρ=+0.6244 CI[+0.5941,+0.6545]; H2 β=+0.7052 CI[+0.6195,+0.7903] n=270; H3 RESOLVED=MIX; Holm own {H1,H2} both reject — effect+CI, never bare p). Finding stated plainly: shared-pool concentration RAISES anonymity (mix), REFUTES naive funnel; framed as honest QUALIFICATION/CORRECTION of lead RQ2-P1 "shrink" as a unique-bridge (fresh-bridge-per-circuit) artifact — cites `docs/note-unique-bridge-artifact.md` + frozen mechanism prereg SHA 8db4e8a7…. MANDATORY disclosure carried: §7 dry-pass previewed direction (ρ 0→+0.838); confirmatory quantifies effect already visible at calibration; pre-committed hypotheses were two-sided. +- BLIND HOLD (RQ3): RQ3 Results/Discussion AND authoritative Holm-7 LEFT AS HELD-BLIND placeholders — RQ3 battery still running (progress read by sidecar COUNT only = 3/90; NO rq3-run.json contents read). Lead RQ2-P1 NOT re-litigated (companion QUALIFIES; committed lead paper + frozen prereg f22331a72e… untouched). This stone: $0/offline, worktree-only. NEXT: HOLD for RQ3 — no new stones, no peeking at RQ3 data until `rq3-battery-results.json` lands. diff --git a/docs/stage-07-companion-methods.md b/docs/stage-07-companion-methods.md index fb5f58c..7a2d72d 100644 --- a/docs/stage-07-companion-methods.md +++ b/docs/stage-07-companion-methods.md @@ -9,10 +9,13 @@ > written as **self-contained sections** that can be lifted into either structure. > > **Blinding & gating status (binding).** -> - **RQ2-P3 mechanism study** — the prereg (`docs/rq2p3-mechanism-prereg.md`, own slug -> `sor-consent-rq2p3`) is **NOT YET FROZEN** (§10 empty). Its methods section below is marked -> **FREEZE-PENDING**; **no confirmatory cell** runs until the operator records the SHA-256 in -> §10 and signs off. +> - **RQ2-P3 mechanism study — FROZEN + SEALED; its Results/Discussion are now UN-BLINDED below.** +> The prereg (`docs/rq2p3-mechanism-prereg.md`, own slug `sor-consent-rq2p3`) was **frozen +> 2026-07-21** (§10 signed; full-file SHA-256 `8db4e8a7ac60f8b2861f2387249db68a3fd44822f6b3d9c7c6990ff65f261a3b` +> in the sidecar `docs/rq2p3-mechanism-prereg.sha256`). The confirmatory battery then ran +> **offline + deterministic** and its record is **sealed** (`output/sor-rq2p3-confirmatory/…`, +> results SHA-256 `5fdcb379d8a2…`). §5/§6 for RQ2-P3 are filled **from that sealed record only**, +> the same post-seal discipline the lead paper used. > - **RQ3 companion** — hypotheses, gates, and analysis are **already frozen** in the lead prereg > (`sor-consent-prereg.md`, SHA-256 > `f22331a72e0d0ccf38b787e63acabbe9d666456ec76076787a6d545c3193425b`, §3/§4/§6); the two open @@ -99,13 +102,15 @@ references: --- -## 3. Methods A — RQ2-P3′ funnelling-mechanism study **[FREEZE-PENDING (prereg §10 not yet signed)]** +## 3. Methods A — RQ2-P3′ funnelling-mechanism study **[FROZEN 2026-07-21 — prereg §10 signed]** -> **This section describes a study whose prereg (`docs/rq2p3-mechanism-prereg.md`) is NOT frozen.** -> Design and parameters are operator-approved and locked; the **human freeze checkpoint** (SHA-256 -> in §10 + sign-off) is outstanding. No confirmatory cell is run until then. Everything below is -> the pre-registered *plan*; the calibration numbers cited are the pre-registered §7 gate output, -> explicitly **not** confirmatory results. +> **This section describes a study whose prereg (`docs/rq2p3-mechanism-prereg.md`) is FROZEN.** +> Design and parameters were operator-approved and locked; the **human freeze checkpoint** (§10 +> signed 2026-07-21, full-file SHA-256 `8db4e8a7ac60f8b2861f2387249db68a3fd44822f6b3d9c7c6990ff65f261a3b` +> in the sidecar `docs/rq2p3-mechanism-prereg.sha256`) is complete. The confirmatory battery then +> ran **offline + deterministic** and its record is **sealed** (results SHA-256 `5fdcb379d8a2…`). +> Everything below is the pre-registered *plan* exactly as frozen; the §5/§6 numbers are read +> **from that sealed record only**. **Design (manipulated-IV dose-response).** A new assembler topology, `bridge-federated-pool`, replaces the fresh-per-seed bridge with a **finite willing-bridge pool** of size `B` under a fixed @@ -236,10 +241,21 @@ confirmatory battery and have both passed on a **dry, synthetic, offline** pass: ## 5. Results *(HELD-BLIND — no confirmatory number written)* -- **RQ2-P3′ (H1 / H2 / H3).** *HELD — pending prereg freeze (§10) and the confirmatory run.* No - Spearman ρ, OLS slope, CI, or Holm decision is computed or inspected until after freeze. *(The - only figures on record are the §4/§3-A pre-registered **calibration** preview — ρ 0→+0.838, B=1 - high-H — explicitly labelled calibration, not a result.)* +- **RQ2-P3′ (H1 / H2 / H3) — RESOLVED: MIX.** From the sealed confirmatory record (9 cells × R=30 × + C=50, offline + deterministic, S0 = 20260719): + - **H1 (within-cell association).** Pooled Spearman **ρ = +0.6244**, BCa 95% CI **[+0.5941, +0.6545]** + (run-level cluster bootstrap, 10,000 resamples). CI excludes 0 on the **positive** side → **mix**. + - **H2 (dose-response).** OLS slope of per-run mean-H on per-run mean concentration + **β = +0.7052**, BCa 95% CI **[+0.6195, +0.7903]** over n = 270 run-level points. CI positive → + **mix**. + - **H3 (joint).** H1 and H2 **agree in sign (both +)** and **both exclude 0** → mechanism + **RESOLVED = MIX**. + - **Holm (own family {H1-pooled, H2-slope}, size 2).** Both tests **reject** at α = 0.05 after + Holm correction. *(p carried only for Holm ordering; the effect + CI above are the reported + quantities — never a bare p.)* + - Across the sweep, as pool size B rises concentration falls **and** entropy H falls together + (e.g. B=2/α=0: conc ≈ 1.00, H ≈ 2.54; B=8/α=0: conc ≈ 0.51, H ≈ 2.19) — concentration and H move + **together, positively**: higher concentration ⇒ higher anonymity (mix), not lower (funnel). - **RQ3-P1-perf / RQ3-P1-latency / RQ3-P2 / RQ3-P3.** *HELD — pending operator-GO on the live isolated grid.* Throughput-retention margin, added-latency (live-only), and rebuild-classifier AUC over confirmatory cells are **not** computed; the only figures on record are the two green @@ -248,10 +264,26 @@ confirmatory battery and have both passed on a **dry, synthetic, offline** pass: ## 6. Discussion *(HELD-BLIND — placeholders)* -- **Does a shared bridge funnel or mix?** *HELD.* If H1/H2 confirm **mix** (ρ, slope > 0), the - companion qualifies the lead "shrink" as partly a unique-bridge artifact; if **funnel** (< 0), the - lead reading is mechanistically corroborated; if inconclusive, the mechanism stays open. The sign - is the finding; the lead RQ2-P1 result is reported as-is and not re-litigated. +- **Does a shared bridge funnel or mix? — It mixes.** Both pre-registered two-sided tests resolve + **positive** (H1 ρ = +0.6244 CI [+0.5941, +0.6545]; H2 β = +0.7052 CI [+0.6195, +0.7903]; H3 + RESOLVED = mix; Holm both reject). Plainly: **concentrating circuits through a finite shared + willing-bridge pool RAISES the per-circuit anonymity set** — circuits that share a bridge share an + exit signature, so the observation-consistent set grows and entropy rises. This **refutes the naive + funnel intuition** (that concentration would shrink the set) and, per the mechanism developed in + `docs/note-unique-bridge-artifact.md`, **qualifies the lead RQ2-P1 "shrink" as a unique-bridge + (fresh-bridge-per-circuit) instrument artifact**: the lead topology assigned a *fresh* bridge per + circuit seed, making every exit signature unique, every anonymity set size 1, and H≈0 by injective + construction rather than by funnelling. Under a finite shared pool the injectivity is removed and + the true sign of the concentration→anonymity relationship is revealed to be a **mix**. This is an + honest **qualification/correction** of the lead reading via the frozen mechanism prereg (SHA-256 + `8db4e8a7ac60f8b2861f2387249db68a3fd44822f6b3d9c7c6990ff65f261a3b`), **not** an overwrite: the lead + RQ2-P1 result and its frozen prereg stand as published and are not re-litigated. + - **Mandatory disclosure (pre-registration honesty).** The §7 calibration dry-pass — synthetic, + offline, no confirmatory record read — **already previewed this direction** (Spearman ρ running + 0 → +0.838 across the sweep, B=1 boundary at high entropy). The confirmatory battery therefore + **quantifies a dose-response that was already visible at calibration**; the pre-committed + hypotheses were nonetheless **two-sided** and that pre-commitment is unchanged. We surface the + calibration preview openly so no reader mistakes the confirmatory sign for a post-hoc choice. - **Does the agent selector help without leaking?** *HELD.* RQ3-P3 confirms only if the agent both clears the +10 pp retention / ≤100 ms latency bar **and** leaves a non-classifiable rebuild pattern (AUC CI upper ≤ 0.60); either failure is an honest H0 (perf cancelled by teardown