Open-source, local-first, reproducible tools for turning EEG and MEG recordings into small, inspectable neural language-decoding experiments without hiding data access, split leakage, resource cost, or negative results.
NeuroDecodeKit is an independent research toolkit inspired by the access and reproducibility problems around Brain2Qwerty-style decoding. It is not an official Brain2Qwerty project, a medical device, or a demonstrated mind-reading system.
manifest -> selective download -> tiny shard -> event/sentence cache
-> no-signal baseline -> neural baseline -> CER/WER report
The core thesis is practical: before another large model matters, a researcher should be able to identify one legal dataset slice, inspect it locally, build a bounded cache, preserve provenance, compare against a language-only control, and explain exactly what the result does not prove.
Why the gates? Most routine engineering is reversible, but opening a held-out target, reusing a consumed evaluation, or changing a rule after seeing the outcome is not scientifically reversible. The approved Research Autonomy Charter and its activation decision let routine code, tests, synthetic work, bounded development experiments, commits, pushes, and CI proceed autonomously while reserving exact approval for those irreversible Tier C events.
The Scientific Discovery and Invention Constitution now governs research priorities. Its companion convergence plan and machine knowledge ledger separate what is supported, refuted, inconclusive, and still blocked; keep discovery distinct from confirmation and translation; and score scientific attribution separately from functional utility.
The frozen 60-person Dreyer nuisance-controlled unseen-person experiment was the prior flagship confirmation route. Its one-file checkpoint stopped safely at strict transport validation: one endpoint response opened, but no response body byte or EDF header was read. The exact Dreyer lane is now consumed and parked without a biological interpretation, and the 1.78 GB cohort was not downloaded.
The latest prospective scientific source was the 15-person Ofner 2017
motor-imagery cohort. An exact metadata-only audit selected 150 original GDF
files totaling 13,748,417,608 bytes (12.8042 GiB) with reported 61 EEG, three
EOG, and 32 hand/arm movement channels at 512 Hz. The tempting 4.58 GB BIDS
derivative was rejected because it omits the EOG and movement comparators
needed to distinguish central EEG from cheaper eye and overt-motion
explanations.
The sole OFNER-C6R-1-HL-R0 range-header invocation is now consumed and
parked at OFNER-H0-TRANSPORT. The exact manifest passed identity selection,
but the first 256-byte GDF range produced zero accepted GDF body bytes, so no
real header, channel roster, geometry, signal, event, target, model, or score
was observed. This is a transport result, not a biological null. It cannot be
retried, rerun, repaired, resumed, substituted, or reinterpreted. No Tier C
packet is active. See the result closeout
and proof closeout.
The proof passed Base Python 99174411928, Optional Neuro Readers
99174412006, and CI 33280371097 on GitHub main.
The artifact-only transport postmortem
froze NPA1-v0: scientific source identity, expiring transport capability,
HTTP framing, bounded content identity, and semantic sensor eligibility are
separate gates. Generated-only NPA1-G is now remotely green at commit
2e164ff, Base Python 99184746988, Optional Neuro Readers 99184747065, and
CI 33284320443. It accepted two deterministic seven-profile fixture replays
and 37 exact refusal families in 0.003375791013240814 seconds at 22,577,152-byte
peak RSS, with 4,162 generated input bytes, a 4,947-byte in-memory report, zero
network, and zero retained payload. The implementation contains no live
network opener or real execution command. Read the
implementation
and proof closeout.
The proof closeout itself is green at exact commit 2ec3d4b, Base Python
99188620896, Optional Neuro Readers 99188621003, and CI 33285776358 on
GitHub main.
This closes a costly engineering uncertainty, not a scientific one. No fresh
source has been promoted, and no EEG was accessed. Independent review rejected
the pushed FMSR1-v0 draft before acceptance or protected work. The additive
FMSR1-v1 successor
is exact-green at e09f6cc, Base Python 99197577034, Optional Neuro Readers
99197577007, and CI 33289147031. It freezes five official source indexes,
four exact queries, ordered
discovery-to-metadata routing, at least ten complete unseen participants,
synchronized EEG/EOG/EMG for every relevant effector, named geometry, and a
decisive central-EEG comparison against both joint nuisance-only and joint
nuisance plus deranged-central-EEG arms. Its exact 20 GiB partition is 12 GiB
payload, 2 GiB temporary files, 2 GiB derivatives, 1 GiB atomic publication,
and 3 GiB untouched reserve. NO_QUALIFYING_SOURCE remains valid. Every
current operation authority is false. The proof-only closeout and all-false
FMSR1-DISCOVERY-M0 request
are pending this exact closeout/request commit's remote proof. The request grants
nothing; the registration is green, but this closeout/request is ineffective
until its own exact commit passes both remote jobs. Fresh packet-bound maintainer
words and a separate exact-green
decision are required before implementation or network access. See the
current machine frontier.
Its immutable predecessor is registries/current_research_frontier.v10.json.
The earlier predecessors registries/current_research_frontier.v8.json,
registries/current_research_frontier.v7.json, and
registries/current_research_frontier.v6.json remain immutable history.
COMM-P0 FS3 remains paused as an adjacent diagnostic.
The follow-on generated acquisition qualification now passes two complete
150-file fixture replays plus 20 adversarial refusals in 0.108829 seconds at
26,492,928-byte peak RSS, with zero network and zero retained payload. It
strictly separates stable path/size/SHA-256 identity from expiring signed
transport URLs and exposes no live-network or real-payload execution path.
This is engineering proof, not EEG evidence. Read the
generated qualification closeout.
That exact implementation and its proof are now green on GitHub main.
The historical Ofner generated milestone was remotely proven: a dependency-free GDF 2.x header parser and two-range transport firewall passed two 24,832-byte header replays plus 41 adversarial refusals in 0.002138459 seconds at 26,214,400-byte peak RSS. It recovered the frozen synthetic 61 EEG + 3 EOG + 19 glove + 13 arm roster at 512 Hz, rejected trailing data bytes, and exposes no network client, real execution command, event parser, signal parser, model, or scorer. Read the header preregistration and generated header result. This remains engineering proof, not EEG evidence. Its historical next checkpoint was one separately governed range-only source-GDF header; that checkpoint is consumed at transport H0, and bulk acquisition, signals, targets, models, and scores remain closed.
The OFNER-C6R-1-HL request,
decision, implementation, and activation all became exact-green before the
one-shot execution. The attempt used one CPU thread, 48,021,504-byte peak RSS,
4,096 private allocated bytes, 2,340 public output bytes, and retained no
payload. It made one manifest GET and one first-range attempt, with zero
full-file requests and zero accepted GDF body bytes. The next reversible step
is artifact-only transport/source research, not another execution.
The latest irreversible result is the consumed Ofner range-header transport H0.
The latest reversible results are green generated-only NPA1-G transport
admission and exact-green FMSR1-v1. The pushed v0 draft is retained as
rejected history and authorized no protected work. All-false
FMSR1-DISCOVERY-M0 requests one future bounded discovery pass but grants no
authority; no network or real operation is active.
The following COMM-P0-G material is retained as exact
adjacent-engineering history and is paused. Its proof architecture has a prospective, resource-aware
successor: Amendment 3 replaces the second redundant full
fictional model replay with a separate verifier/scorer process that has no
model, fit, inference, threshold, calibration, prediction-creation, or update
capability. One complete 42-participant producer schedule remains mandatory,
including 630 classifiers, 630 source-only temperature fits, 1,428 prediction
sets, 91,392 streamed prediction rows, two cohort target deliveries, two
scores, seven shortcut controls, and all 70 refusal families. The verifier
must independently authenticate the frozen transcript, inventory, HMAC,
delivery nonce, probability rules, penalties, and aggregate scores.
Exact Amendment 3 commit b15d3cf passed Base Python job 98860211722,
Optional Neuro Readers job 98860211949, and CI 33174711145, then reached
GitHub main. The separately prospective
COMM-P0-G-FS3-v0
contract preserves the original model and protocol plus the same one-thread,
180-second, 512 MiB RSS, 513 MiB incremental-disk, zero-network, and zero-
retained-payload limits. Its one-shot rehearsal remains closed until the
remaining ordered green barriers.
The generated implementation has now passed its reduced local qualification:
two isolated three-person-per-cohort producers and two separate zero-model
verifiers processed 13,056 prediction rows / 204 sets per replay, exercised
140 refusal observations, and produced matching canonical producer and
verifier aggregates in 72.6701 seconds at 239,075,328-byte peak RSS. It
collected 770 process-monitor samples, made zero network requests, and retained
zero generated payload bytes. Exact implementation a3b561b passed Base
Python 98875866699, Optional Neuro Readers 98875866417, and CI
33179247000, then reached GitHub main. Exact proof-only closeout ccabfaf
passed Base 98881035296, Optional Neuro Readers 98881035573, and CI
33180751900, then reached main; it binds six exact implementation artifacts
/ 43,587 bytes and repeats no execution. No full FS3 rehearsal ran.
An independent post-proof audit then found that the frozen verifier contract
called two deliberate stream traversals “one pass,” did not require the exact
91,392-row / 1,428-set full inventory, and left identity, no-follow, socket-
guard, logical cohort-envelope, and runtime boundaries underspecified.
Exact COMM-P0-G-FS3-A1 commit 28b440e passed Base Python 98889419386,
Optional Neuro Readers 98889419758, and CI 33183200744, then reached
GitHub main with zero numerical operations. Exact wrapper commit 91743f5
then passed Base Python 98909173217, Optional Neuro Readers 98909172856,
and CI 33188950787, and reached GitHub main. It implements descriptor-only
identity checks, no-follow dirfd producer opens, an isolated socket-guarded
verifier, observed 64-row enforcement inside every one of 1,428 sets across
two traversals, parent RSS checkpoints, and staged fsync/no-replace publication.
Exact proof commit 66ab07d binds its six artifacts / 111,486 bytes and passed
Base Python 98913572325, Optional Neuro Readers 98913572569, and CI
33190237036, then reached GitHub main. Execution stays closed until a final
activation commit binds proof digest 128b6699; no full FS3 rehearsal has run.
This design is grounded in a measured negative engineering result. The sole
COMM-P0-G-FS2-R0 attempt completed one of
two required full fictional replay children, then parked at
180.05074683297426 seconds against its frozen 180-second total cap. Memory
was not the blocker: peak process-tree RSS was 305,119,232 bytes against a
536,870,912-byte cap. Storage was also healthy: the exact 537,919,488-byte
reservation left 37,325,271,040 bytes free, cleanup retained zero generated
payload bytes, and the public result was only 2,286 bytes. The run collected
1,510 process-monitor samples and made zero network, official, real-data,
device, release, or scientific operations.
The durable receipt makes FS2 permanently consumed, so it cannot be retried or
repaired. Exact closeout a654541 passed Base job 98850558071, Optional Neuro
Readers job 98850558325, and CI 33171818869, then reached GitHub main.
This is useful engineering evidence: the exact two-by-21 coordinator does not
fit the current 180-second envelope on this machine. It is not neural evidence.
The official generated qualification remains inactive. FS3 is a new
prospective gate, not an FS2 retry or repair. See
the FS2 closeout.
The first preregistered BNCI held-out experiment produced a useful negative result. Selected EEG reached 38.35% participant-macro balanced accuracy versus 25% no-signal and 29.67% timing, so the pipeline recovered task-related information. But posterior EEG reached 39.24%, candidate log loss was worse than the equal prior, only 5 of 9 participants had a positive primary margin, and the small EOG+EEG gains missed the frozen effect-size, consistency, and significance gates. That is evidence of protocol information, not evidence of an EEG-specific or participant-general decoding advantage. The aggregate-only postmortem records the exact failure map without reopening private predictions or targets.
The now-parked independent lane was
DREYER-C5R-1, built specifically to
resolve those failures:
| Design element | Why it matters |
|---|---|
| 60 fresh participants, held out one person at a time | Replaces a 9-person consistency signal with a substantially larger zero-calibration test |
| 27 EEG, 3 EOG, and 2 wrist-EMG sensors reported at 512 Hz | Makes eye and muscle shortcuts explicit model inputs and controls |
| Central EEG residualized against EOG, EMG, posterior EEG, and timing | Tests incremental central-sensor information instead of EEG versus chance |
| Posterior ablation, deranged EEG, pre-cue, cue, timing, and label-rotation controls | Challenges visual, temporal, and pipeline shortcuts prospectively |
| One fixed L2 logistic family with source-only temperature calibration | Addresses probability reliability without growing model capacity |
| 60 participant-held-out folds and one frozen score | Prevents held-out-person tuning and post-result model changes |
The selected R1/R2 surface is 120 exact source EDFs totaling 1,779,763,388 declared bytes and 4,800 expected trials. Primary-source details and licensing are recorded in the cohort decision, with links to the peer-reviewed paper and official NEMAR revision.
Engineering qualification is complete for the target firewall, compact model schedule, prediction freezer, scorer, and streaming fixed-header verifier. The model/firewall fixture completed 330 fits, 258 inference runs, 102 prediction sets, and 2,040 synthetic prediction rows; the sensor preflight completed two valid deterministic replays and 18 adversarial refusals. Both used generated data only and establish no scientific result.
The consumed Tier C packet was
DREYER-C5R-1-HL.
After every ordered green barrier, its sole 14,805,604-byte transaction opened
one response and refused at strict transport validation before any body byte
or EDF header was read. The public aggregate records one GET, zero downloaded
payload bytes, zero header reads, 0.648 seconds, 36,454,400-byte peak RSS, and
no retained payload. The attempt cannot be retried or reinterpreted. It did
not verify the preregistered EEG, EOG, EMG, or 512 Hz roster.
The live-wrapper safety review now freezes the missing one-shot protections: durable marker ordering, no-follow path capabilities, atomic no-replace publication, proxy-free TLS, continuous resource checks, sanitized failure output, and exact EDF header-to-payload geometry. It is a static engineering review, not permission or evidence.
What is proven now: NeuroDecodeKit can localize a failed neural claim from aggregate evidence, freeze a stronger independent experiment, enforce its target firewall, and fail closed on a real endpoint before a mismatched source surface consumes substantial storage.
What is not proven: no Dreyer EDF body, header, or fresh EEG signal was accessed, and there is still no established EEG-beyond-peripheral advantage, unseen-person neural decoding, movement-intention or motor-cortex claim, language or thought decoding, live system, portable-hardware result, or clinical utility.
The parallel communication program now has a prospective
COMM-L0 source-identity contract.
It freezes one future OpenNeuro ds003626-v2.1.2 metadata query and a
target-free selection rule: keep all ten participants, choose the same earliest
complete raw session for everyone, preserve EEG plus eye and oral-muscle
channels, and park if the slice exceeds 10 GiB. No dataset-specific request or
download has occurred, so this is a reproducibility and storage-control
milestone rather than a decoding result.
The generated COMM-L0 implementation has now passed once and is consumed: two
deterministic replays and all 20 malformed-source refusals passed in 0.072875
seconds at 22,069,248-byte peak RSS, with zero network or real/private data
operations. This proves the selector's engineering behavior on synthetic
metadata only; it does not verify the real OpenNeuro tree or establish any
neural result. See the
COMM-L0 generated qualification result.
The independent replication is now prospectively locked in
COMM-R0-REPLICATION-v0,
before any discovery target has been delivered. The primary test is not EEG
versus chance: it asks whether nuisance-adjusted central EEG improves
participant-macro log loss over both recorded nuisance context and the same
context plus a K - 1 class-shift EEG control ensemble in a completely unseen
participant. A full
result requires at least 0.03 nats/item improvement, positive component
margins in at least 70% of participants, exact one-sided sign-flip p <= 0.05,
and at least 0.05 balanced-accuracy advantage over the strongest frozen prior,
cue, timing, or posterior control. Discovery and independent replication must
each pass separately.
The registered feature window is sample-causal but offline event-locked and
uses a trial-boundary oracle. It therefore cannot establish continuous,
self-endpointed, real-time, or live decoding; those remain later NDK_STREAM
and NDK_LIVE gates. The fixed-command experiment also permits no external or
generative language model: its language-only control is the source class prior.
The matching generated-only implementation is now available through
python -m neurodecodekit.comm_r0_cli plan. It exercises the frozen analysis
with 12 fictional participants, all K - 1 four-class derangements, separate
cue/timing/EOG/oral-EMG/posterior controls, a neural-only freeze before the
provider-free language arms, and an identity-bound complete freeze before any
synthetic target can be delivered. A partial route explicitly marks missing
sensors unavailable instead of replacing them with zeros or proxies. See the
COMM-R0 generated implementation.
The official generated qualification is still inactive pending a separate remotely proven activation. A bounded development replay passed locally, but that is only evidence that the synthetic numerical path executes. It is not a real EEG result, independent replication, unseen-person evidence, or live decoding.
SilentSpeech-EEG remains only a full-control watchlist source until its public identity, license, manifest, hashes, loader, and exact EOG/oral-EMG roles are verified. TESSCCo and Kara One are frozen as explicitly partial independent challenges; neither may be relabeled as a full eye-and-mouth-adjusted replication. If the exact replication source and claim ceiling are not committed, pushed, and remotely green, the future discovery scorer must refuse target delivery. This preregistration accessed no real data and adds no scientific claim.
COMM-L0's proof-only closeout is now remotely green, so its generated
engineering is closed. The queued
COMM-L0-META authorization packet
now freezes the next real-source step: one future metadata-only OpenNeuro
request, at most 16 MiB of response data, zero BDF payload bytes, and a
target-free private acquisition manifest. Its prospective amendment adds
boundary-size qualification, durable no-follow marker creation, exact decision
binding across all future stages, and an 8 MiB disk envelope. Every authority
flag remains false; the packet is not active and cannot displace the current
Dreyer gate.
The exact request and its proof-only closeout are remotely green at commits
12e4e9f and 3e1322d. That establishes a reviewable, fail-closed route to
source identity, not permission to run it: no OpenNeuro response, BDF payload,
real EEG, model, or score was accessed.
A fresh replication-source review found no second public cohort that is yet verified with the complete raw EEG, eye, oral-muscle, immutable-identity, license, and loader surface needed for a full attribution replication. SilentSpeech-EEG has the strongest reported scientific fit. Its repository contains a loading module, but the imported dataset module and data-layout instructions remain missing; a stable dataset identity, complete manifest, dataset license, reproducible loader, and exact public external-channel roster are still unverified. TESSCCo adds a valuable 24-participant prompted-command challenge, while Kara One, Directional Word 2026, and ArEEG remain partial candidates whose missing controls must be stated rather than silently treated as equivalent evidence. This review made no payload or private-data operation and created no acquisition authority.
A newer
triangulated replication refresh
adds a newly public full-sensor source without overstating it. OpenNeuro
ds007591-v1.0.1 is a stable CC0, approximately 1.62 GB cohort with 128 EEG,
EOG, oral EMG, microphone, and trigger channels across covert, minimally overt,
and overt five-word speech. It has only three participants: the smallest
possible one-sided exact sign-flip p-value is 1/8 = 0.125, so it is a
nonrouting mechanistic bridge, not inferential replication. The stronger
two-key design requires ds003626 to pass full peripheral attribution and
TESSCCo to pass an independently frozen 24-person partial transportability
test. Even if both pass, the result would establish prompted-command EEG-
channel information with peripheral attribution only in discovery, not
independently replicated neural attribution. Public JapanEEG ds007808 is
approximately 1.575 TB and only three participants, so it remains outside the
current participant and storage gates. No payload was accessed or authorized.
The exact refresh is reproducibly bound at commit 85400fe, CI
33128665324, and GitHub main; its
proof closeout
records the exact files and unchanged no-data/no-claim boundary.
That proof passed both required suites at 171d615 / CI 33129343388 and is
on GitHub main.
The follow-up
TESSCCo source-readiness check
verified the paper-cited dataset DOI, but its Kaggle landing currently returns
404. TESSCCo is therefore a scientifically useful planned 24-person partial
replication, not an acquisition-ready source; version, manifest, byte size,
dataset license, and peripheral-channel roles still need an exact source lock.
Exact readiness result 3ed55ba passed both required suites in CI
33130065908 and is on GitHub main; its
proof closeout
binds the immutable decision without repeating the source request. Exact
closeout 752f99c passed both required suites in CI 33130671683 and is on
GitHub main.
The next
Kara One source-readiness check
closes the other registered public partial route under the current source
surface. Its official page exposes 14 participant archives totaling about
24 GB, above the frozen 10 GiB selected-raw cap, without a member-level remote
manifest that proves a complete all-eligible-participant EEG plus eye/face
slice below that cap. The page and paper also disagree on the participant
surface: 14 archives are published, while the paper reports 12 recruited and
eight analyzed participants. The contract forbids dropping participants, so
Kara One is parked rather than conveniently subset. This is a reproducibility decision,
not a negative EEG result: no archive was requested, and a future official
manifest could still establish an eligible complete slice before discovery
targets. With SilentSpeech-EEG unqualified and TESSCCo blocked, no public
replication route currently qualifies; the honest fallback is a separately
approved prospective cohort with synchronized EEG, EOG, and bilateral oral
EMG.
Exact readiness result a9a9b23 passed Base Python and Optional Neuro Readers
in CI 33131980667 and reached GitHub main. Its
proof closeout
binds the exact result triplet without repeating either public-source request.
With the public router now exhausted, the
COMM-P0-SYNC-v0 prospective cohort
freezes the smallest direct route to the missing evidence. It specifies two
independent 21-completer cohorts, 64 EEG plus four EOG and four bilateral oral-EMG
channels, microphone and hardware timing, four-command prompted and free-choice
tasks, participant-held-out zero-calibration scoring, a source-only causal
endpointer, and an unchanged shadow-to-live transition. The primary endpoint
is not EEG versus chance: nuisance-adjusted EEG must improve log loss by at
least 0.03 nats/item over both all recorded peripheral information and a
class-destroyed EEG control, pass participant consistency and exact inference,
and beat the strongest prior/cue/timing/posterior/peripheral control by at
least 0.05 balanced accuracy in discovery and replication separately.
The complete worst-case raw recording is byte-accounted at 10,463,692,800
bytes (9.7451 GiB) for the 44-person enrollment cap, within the 10 GiB raw
cap; the remaining 20 GiB envelope
is reserved for bounded derivatives, temporary output, aggregates, and
headroom. This is a study design, not a recording: no participant, device,
real EEG, target, model, score, or claim operation is authorized or performed.
Exact registration df3266e passed both required jobs in CI 33134791405 and
reached GitHub main. Its
proof closeout
binds the three immutable registration artifacts. Review also found one
human/machine mismatch: the prose said 60% stable-commit coverage while the
contract and test said 70%. Amendment 1
makes the stricter 70% value authoritative before generated implementation.
Exact proof/amendment 478d31e passed both required jobs in CI 33135742217
and reached GitHub main. The next bounded gate is
COMM-P0-G-v0,
a generated-only qualification contract for the full study grammar, 73-channel
synchronized sharding, target side channels, causal context, participant-first
statistics, prediction/scorer isolation, live accounting, and 70 adversarial
refusal families. Exact registration 002128b passed both required jobs in CI
33136788477 and reached GitHub main. Its
proof closeout
binds three immutable registration artifacts / 47,562 bytes before generated
implementation. It authorizes neither the official qualification execution nor
human, device, or real-data work.
Even a complete internal pass would not establish external reproduction,
arbitrary thought reading, sentence decoding, or clinical use.
Implementation has now crossed three green engineering milestones. The
core
represents the complete fictional protocol; the
numerical/scorer layer
implements the fixed compact 42-fold schedule; and the
endpoint-separated live scorer
makes free choice the primary live gate so prompted performance cannot rescue
it. Exact live-scorer commit c46064d passed both required jobs in CI
33141715948 and is on GitHub main.
The generated qualification runner has since advanced through two more bounded
engineering layers. Exact green commit 7d625a9, now on GitHub main, adds a
standalone streaming scorer that verifies a target-free freeze before delivery
and scores the same inode in one post-delivery pass without retaining the full
prediction table. The V1 hardening successor then streams canonical fold
predictions with a one-row raw high-water mark, executes all seven registered
numerical shortcut routes, wires durable future consumption before official
work, and corrects the frozen exact-sign-flip schedule so only the two
confirmatory free-choice tests enumerate 2^21 assignments.
One nonofficial full-scale rehearsal exercised the complete 42-person fictional
structure: 91,392 prediction rows, 1,428 prediction sets, seven shortcut routes,
101.5826 seconds, 283,394,048-byte peak process-tree RSS, 34,259,372 private
temporary bytes, zero network or real-data operations, and zero retained
payload. Exact V1 implementation 55e627d passed Base Python and Optional
Neuro Readers in CI 33153174019 and reached GitHub main; its
proof closeout
binds the exact 13,830-byte evidence triplet. Audit then found that rehearsal
used one combined target envelope and one score while the frozen contract
requires one delivery and score per cohort. The successor preserves the
historical measurement, enforces two cohort envelopes and two scores per
replay, and implements the previously stubbed two-replay official coordinator.
Exact head 669c858 passed both required jobs in CI 33161053075 and reached
GitHub main. It is still generated engineering only. Full two-replay runtime
evidence and a separate activation remain required; no communication-decoding
or EEG-specific scientific claim follows from any fictional rehearsal.
The new
objective evidence ledger
makes the gap to the end goal explicit. NeuroDecodeKit has real directional
held-out task evidence and reusable causal/firewall engineering, but it has not
yet established prompted communication decoding, EEG information beyond both
eye and mouth activity, unseen-person communication, independent replication,
or live neural decoding. The ledger assigns ds003626 to discovery,
SilentSpeech-EEG to the full-control watchlist, TESSCCo and Kara One to partial
external challenges, and Dreyer to motor-control method validation. Those
roles are machine-tested and cannot silently upgrade one another.
Exact decision 9c3489c passed Base job 98508922485, Optional Neuro Readers
job 98508922088, and CI 33069830931.
The next control-plane step is now frozen in the
COMM-G1 generated experiment contract.
The registration is remotely green. A prospective
COMM-G1 Amendment 1
corrects its negative control before implementation: EEG residuals are now
rotated across source classes with no fixed points instead of shuffled within
the same class. This avoids a control that accidentally preserves the exact
information it is meant to destroy. No real data or scientific result is
involved.
The corrected generated implementation is now present with a strict
participant firewall, causal spectral features, source-only residualization,
ten fixed controls, aggregate prediction freezing, one-delivery scoring, and
35 adversarial refusals. A disposable development run recovered the deliberately
injected fictional residual-EEG effect while the shortcut fixtures stayed
structural checks. That demonstrates analysis plumbing only. It is not evidence
that real EEG decodes communication or adds information beyond eyes and mouth.
The exact implementation became remotely green and its one official generated
qualification ran once. The strict
COMM-G1 closeout parks it
at COMM-G1-R0, not the executor's provisional R1: its replay digest omitted
registered metadata, its deterministic replays were not isolated in separate
clean workdirs, and two named adversarial families were not explicitly
exercised. The run is consumed and will not be rerun or repaired in place.
This is useful control-plane failure localization, not EEG or communication
decoding evidence.
The COMM-G2 proof qualification
kept the scientific model, features, conditions, and thresholds byte-frozen and
changed only the evidence machinery. Its exact implementation became remotely
green before the one official generated invocation. That invocation failed
closed at the first replay's 85-second child deadline with
G2-CHILD-TIMEOUT; it published no result and left no invocation temporary
directory. The strict
COMM-G2 closeout
binds COMM-G2-R0, consumes the lane, and permits no rerun.
It specifies a six-participant synthetic leave-one-person-out matrix with ten fixed arms: priors, cue/time, EOG, oral EMG, all peripheral/context controls, selected EEG, posterior EEG, peripheral plus residual EEG, and a matched deranged-EEG control. Its target firewall, 60-fit compact schedule, aggregate prediction freeze, isolated synthetic scorer, and shortcut-only negative fixtures were intended to qualify the proof wrapper before any real analysis. Because the two-replay proof did not complete, no generated score is accepted. The lane has no scientific value and authorized no real data, model evidence, stream, device, or claim operation.
NeuroDecodeKit is now organized around five claims that must be earned
separately. The full evidence definitions and experiment order live in
docs/FIVE_CLAIM_PROOF_STRATEGY_2026-08-22.md.
| Target | Status | Nearest decisive test |
|---|---|---|
| EEG language information | Not established | Frozen inner-speech command predictions must beat cue/time, visualized-direction, EOG, oral-EMG, no-signal, and deranged-EEG controls. A pass is closed-set command evidence, not arbitrary thought reading |
| Motor-cortex-consistent movement information | Not established | Cue-neutral pre-movement Freewill EEG must add information beyond EOG and wrist acceleration while passing central-versus-frontal/occipital, lateralization, shift, reversal, and derangement controls |
| Completely unseen-person generalization | Not established | A participant-independent model must score a person whose signal, labels, calibration, normalization, and thresholds were never used during fitting or selection |
| Live end-to-end decoding | Not established | A real stream must be causally decoded without an event-onset oracle, with measured capture-to-output latency, dropouts, buffering, and abstention |
| EEG beyond eyes and other peripheral signals | Not established | On identical held-out trials, P+E must improve participant-macro log loss over P, P+D(E), timing-only, and no-signal conditions |
VR39P's terminal cohort attempt returned aggregate R2, so no cohort was frozen and the Freewill/CIL1 lane is permanently parked. The new independent BNCI-C3C5-1 source decision selects 18 original, hash-pinned BNCI 2014-001 MAT files totaling 779,873,919 bytes. Its future nine-fold design holds out one person completely and asks whether a four-class model generalizes with zero calibration and whether EEG improves log loss over recorded EOG alone. Language, motor, unseen-person, peripheral-control, and live work remain separate evidence tracks so success on one cannot silently upgrade the others.
The exact BNCI-C3C5-1 preregistration
and machine contract
freeze the experiment as G1 -> A -> Q -> P -> T. C3 requires causal
late-imagery EEG to beat no-signal, timing, derangement, early/pre-cue, and
spatial controls across nine completely held-out people. C5-partial asks
whether source-cross-fitted EOG+EEG improves participant-macro log loss over
both recorded EOG alone and an equally sized EOG+deranged-EEG fusion.
The sole replacement G1 qualification
passed all 11 generated engineering case classes across nine isolated folds:
468 synthetic fits, 495 synthetic prediction sets, one generated target
delivery, and one synthetic score in 17.790 seconds. It used zero real data or
network bytes and has no scientific value. G1 result 4ef12dd and proof
closeout cf47698 are remotely green, and G1 is consumed.
The first real Stage A attempt then failed closed when NEMAR returned HTTP 302 to a direct-response-only client. It read zero payload body bytes and retained only its immutable 297-byte consumed marker. That invocation cannot be retried, repaired, resumed, or reused.
The separately scoped redirect-recovery packet
permits one exact replacement acquisition through allowlisted signed NEMAR
objects. Its decision 588dd70 passed CI 32803138246; generated-qualified
implementation 09a19d1 passed CI 32806186972; and corrected activation
492a36a passed Base job 97680849177, Optional Neuro Readers job
97680849465, and CI 32807676008. The implementation validates 18 exact
identities totaling 779,873,919 bytes, keeps signed credentials in memory,
anchors writes to no-follow directory descriptors, supports bounded resume,
and enforces one-thread runtime, memory, network, disk, and free-space limits.
The recovery's 18-case generated qualification passed with 12 direct refusals, one tiny end-to-end signed-object roundtrip, 0.010994 seconds runtime, 29,786,112-byte peak RSS, and zero retained payload. It made no real request and performed no MAT semantic read, fit, prediction, target delivery, or score. The generated invocation is consumed and cannot be repeated.
Control-plane commit 21cedd5 then passed Base job 97691784130, Optional
Neuro Readers job 97691784315, and CI 32811586786. The maintainer explicitly
approved the exact one-shot recovery after its transfer and consumption risk
were restated. The Stage A result
passed: all 18 signed objects and 779,873,919 payload bytes were acquired and
opaque-verified in 113.066 seconds at 42,893,312-byte peak RSS. Total network
bytes were 780,275,745, and about 92.1 GB remained free.
MAT semantic opens, signal/event/target/label reads, model and training runs, prediction sets, target deliveries, and scores were all zero. The invocation is consumed and cannot be retried or rerun. Its private payload and evidence remain Git-ignored.
The exact Stage A result commit 96d7f0 passed both required jobs in CI
32814564120. The new generated-only Stage Q implementation
has also passed its one local qualification: 40,069,562 generated input bytes,
six task runs, 288 trials, 3.657 seconds, 498,434,048-byte peak RSS, and a
644,708-byte deterministic target-free feature archive. Private/real reads,
models, training, predictions, target deliveries, and scores were all zero.
That qualification is consumed. Its additive live control plane remains
disabled until a separate exact activation is committed, pushed, and green.
Final implementation e5ca6a2 passed both jobs in CI 32822604745; the
live activation now binds its
11 exact artifacts with delayed effect. Before consumption, the live path also
requires a conservative 227,843,968-byte layout bound, 2 GiB additional free
disk, and fresh remote proof that the activation commit and both CI jobs passed.
Initial activation commit e678095 failed Base CI only because its proof tests
depended on an ancestor object absent from the shallow Actions checkout. It had
no effect and performed no private operation. A test-only compatibility barrier
passed as 52b681e in CI 32824921855; the activation is now rebound to that
exact green commit. Final activation 0e36993 passed both jobs in CI
32825946085 before the one real semantic invocation.
The Stage Q result passed and is consumed: all 18 real MAT files, 108 task runs, and 5,184 trials validated with 22 EEG and three EOG channels at 250 Hz. It created 72,666,213 bytes of private target-firewalled nine-fold derivatives in 34.464444 seconds at 910,704,640-byte peak RSS. No held-out-T row entered a fold capability, and held-out-E targets and scoring keys remain sealed. Model, training, prediction, target-delivery, score, and analysis-network counters were zero.
Exact Stage Q result 9832ae5 passed Base job 97740061957, Optional Neuro
Readers job 97740061602, and CI 32827957362. The current
Stage P/T live implementation
adds the missing fold-scoped real-model adapter, exact 9 x 6 x 48 completeness
firewall, sequential one-fold child execution, streamed private predictions,
aggregate hash-only prediction freeze, and separately activated one-shot Stage
T scorer. It reuses the frozen 468-fit / 495-prediction-set schedule and changes
no preregistered model, control, threshold, or claim boundary.
Exact implementation 7ba4f7c passed Base Python job 97990455561, Optional
Neuro Readers job 97990455765, and CI 32906104408. The minimal
Stage P live activation now
binds that green implementation and its six exact artifacts with delayed
effect. It enables no work until its own commit is pushed and both CI jobs pass.
Activation a49609b passed Base job 97992958552, Optional Neuro Readers job
97992958346, and CI 32906928931 before the one real target-blind Stage P
run. The prediction-freeze result
completed all nine folds: 468 fits, 495 inference/prediction sets, and 41,472
private prediction rows in 55.674 seconds at 629,194,752-byte peak RSS. It
emitted 11,298,505 private bytes and a 5,037-byte aggregate public freeze. All
nine source-only selectors chose E1. Held-out targets remained sealed, and no
score or claim upgrade occurred. Repeated convergence warnings at the frozen
80-iteration cap were recorded without changing or rerunning the models.
The machine-readable current state is
registries/current_research_frontier.v11.json.
It freezes the consumed Ofner lane, green generated NPA1 proof, rejected v0
draft, exact-green FMSR1-v1, all-false FMSR1-DISCOVERY-M0 request, claim boundary, and exact next
transition so handoffs cannot silently return to an older gate.
Prediction
freeze 2517fd1 passed Base job 97996323987, Optional job 97996324203, and
CI 32908059166.
The Stage T scoring activation
passed as 06e29cb with Base job 97998435433, Optional job 97998435729,
and CI 32908763353 before the sole score.
The Stage T result is registered route
BNCIC3C5-R2: neither C3 nor C5-partial passed. Selected EEG scored 38.35%
balanced accuracy versus 25% no-signal and 29.67% timing, but posterior EEG was
slightly higher at 39.24%, only 5/9 people improved, and p=0.0664. EOG+EEG
improved log loss over EOG alone by 0.02552 and over EOG+deranged-EEG by
0.01843, but both gains missed the frozen 0.03 threshold, appeared in only 6/9
people, and were not significant. This is a real held-out scientific result
and a useful near-miss, not a validated EEG-specific decoding claim.
Exact R2 result af8dcc9 passed Base job 98001418110, Optional Neuro Readers
job 98001417963, and CI 32909763799. The lane is closed and consumed; its
targets and private predictions will not be reused for tuning. The next work is
an artifact-only postmortem and a fresh independent replication design focused
on posterior/visual and EOG confounds.
Current result: EEGMMIDB-UG1 Stage S-A2
failed closed during verified TLS certificate-chain validation before an HTTP
response or EDF request. The one-shot invocation is consumed: it retained only
a durable marker, acquired zero payload bytes, and produced no target, model,
prediction, or score. This is useful engineering evidence that partial or
unverified data cannot silently enter the research pipeline, but it is not a
scientific result. The dependent source-LOSO experiment is blocked and cannot
be repaired or retried under this lane. Exact result ba8645e passed both
jobs in CI 32740773041; proof-only closeout d9eae69 passed both jobs in CI
32742694237 without reopening the consumed marker or payload paths.
BNCI-C3C5-1 now has a verified recovery bundle, real target-firewalled Stage Q derivatives, and frozen real-model predictions, but no target delivery or scientific score. Even a future maximum pass would establish only participant-independent BNCI protocol-condition prediction and incremental EEG sensor information beyond three recorded EOG channels, not thought reading, language, movement intention, exclusive motor-cortex origin, live use, portable hardware, home use, or clinical utility.
The frozen EEGMMIDB-UG1 research design
was the direct unseen-person experiment. Its
preregistration,
machine contract,
and all-false Tier C packet
freeze one source-pooled model on S001-S015 and one final evaluation on
S016-S030 with zero held-out-person calibration. Source LOSO must first beat
the stronger no-signal/timing control or the lane stops before fresh
acquisition. Even a maximum R4 result would establish only
participant-independent EEGMMIDB protocol-condition prediction; cue/ocular
compatibility, motor-cortex origin, movement intention, language, and live
decoding would remain unproven. Exact request c642d90 passed Base job 97322606634,
Optional Neuro job 97322606501, and CI 32690289547. Its proof-only
closeout 9117b1d passed Base job 97324487895, Optional Neuro job
97324488042, and CI 32690987778. The maintainer's next exact message was
continue; the packet-bound authorization decision is recorded with delayed
effect. Exact decision 3e173f6 passed Base job 97333988408, Optional Neuro
job 97333988474, and CI 32694496933. Two independent pre-execution reviews
then found reproducibility gaps in the control gates, predictor firewall, and
prediction-freeze binding. A narrowing
Amendment 1
froze those details and passed CI 32696449436 before implementation. Exact
implementation da2be31 then passed Base job 97363993816, Optional job
97363993465, and CI 32704970582. The sole generated/mock Stage G
qualification passed all 17 case classes with 61 fits and 420 prediction sets
in 443.246267 seconds at 276,856,832-byte peak RSS. It read zero real paths,
EEG payloads, caches, or real targets. This is an executable-pipeline result,
not unseen-person or neural evidence; Stage M and every real operation remain
closed. Stage G closeout 5cc3e0e passed both jobs in CI 32708050897.
The next all-false
Stage M metadata packet
proposes only 36 body-blind HEAD checks after separate proof barriers. Exact
request e2647d6 passed both jobs in CI 32709110804; proof-only closeout
e9c11da passed both jobs in CI 32710175884. After Stage M was named as the
sole active Tier C packet, the maintainer's exact continue was recorded in a
packet-bound decision with delayed effect. Decision 021bf8a passed both jobs
in CI 32712235191. Corrected implementation 1c68a77 then passed Base job
97395810059, Optional job 97395810337, and CI 32715529168 before the sole
Stage M1 generated qualification. All 20 cases passed with 297 mock HEAD
requests, deterministic replay, 8,354 generated fixture bytes, 1,416 aggregate
output bytes, 0.0178 seconds runtime, and 33.3 MB peak RSS. Every real request,
body, EDF, payload, target, model, training, score, and network counter remained
zero. The run is consumed; Stage M2 is blocked until the result and a separate
proof-only closeout are remotely green. Result 3b343d7 passed both jobs in
CI 32716836238; the proof-only closeout now binds nine exact artifacts
totaling 82,278 bytes without repeating qualification or accessing real data.
Stage M2 remains blocked until that closeout is itself remotely green.
Proof closeout fd88d9d passed both jobs in CI 32717768039 before the sole
real metadata pass. All 36 direct HEAD checks succeeded, freezing a complete
92,414,976-byte remote inventory with ETag, Last-Modified, and Accept-Ranges
for every file. No response body or EDF content was read and nothing was
downloaded. This removes remote availability and storage uncertainty; it is
not EEG or decoding evidence. M2 result 818ef1f passed both jobs in CI
32718796222; its eight-artifact proof-only closeout 00f795f passed both
jobs in CI 32720013549, permanently closing Stage M. The next
Stage S-A packet
is all-false: it proposes only a generated-qualified, checksum-bound acquisition
of the six missing S001-S003 run-04/run-08 source files totaling 15,498,816
bytes. It does not authorize a download, touch the 54 retained source files or
30 fresh-final files, parse EEG, train a model, or upgrade a scientific claim.
The exact request 2085ea0 passed both jobs in CI 32722744301. Its pending
proof-only closeout binds the three request artifacts totaling 33,704 bytes
without implementation, network, payload, target, model, or score access.
Proof closeout b0b4632 then passed both jobs in CI 32724357118. The
maintainer's next exact continue is now recorded in a packet-bound decision;
decision 1b5c919 passed Base job 97426157639, Optional Neuro Readers job
97426157381, and CI 32725633524. Corrected Stage S-A1 implementation
37808be then passed Base job 97441967842, Optional Neuro Readers job
97441968304, and CI 32730673153. It streams exact-size generated payloads in at most 1 MiB
chunks, freezes official checksums before payload requests, performs one opaque
post-write hash per file, publishes only a complete no-replace bundle, and
exposes only plan and generated qualify commands. Its sole 27-case
qualification passed with 56 mock requests, three successful generated
bundles, 67,199,028 generated body bytes, 18 opaque post-write passes, 0.476
seconds runtime, 71.7 MB peak RSS, and zero retention or real operation. The
raw nested mock-subtype fields were incorrectly zero; immutable case-flow
accounting reconciles the authoritative total as 21 checksum plus 35 EDF mock
requests. This reporting defect is documented without rerunning the consumed
qualification. Result e2965cf passed both jobs in CI 32733249548. The
pending proof-only closeout binds nine exact artifacts totaling 130,558 bytes
without another qualification or any real operation. Closeout b3902cf passed
both jobs in CI 32735141922. A separate activation now copies that exact
green proof into the frozen live gate's evidence fields, but it performs no
request and has no effect until its own CI is green. Stage S-A2 network access,
real EEG parsing, source LOSO training, fresh participants, targets, scoring,
and claim upgrades remain closed now.
The standout result is not an inflated decoder score. It is a complete, reproducible evidence chain that validates difficult engineering, preserves negative scientific results, and knows when a gate should stop.
| Evidence layer | Strongest result so far | What that means now |
|---|---|---|
| Unseen-person test | EEGMMIDB-UG1 Stage G passed once: all 17 generated/mock case classes, 61 fits, 420 prediction sets, target-swap and participant-relabel invariance, exact causal replay, canonical checkpoints, and bounded atomic output | The pipeline is qualified before real use, but zero real EEG paths or targets were opened. The synthetic R4 route has no scientific value; unseen-person, neural, cortical, language, and live claims remain unestablished |
| Real EEG predictive effect | The frozen WO9R low-frequency model reached balanced accuracy 0.680975 for executed movement and 0.728014 for imagery across 12 held-out-run participants, versus approximately chance no-signal controls |
This is a real repeatable condition signal, but the early cue (0.762865) and frontal proxy (0.671821) beat or matched the central sensorimotor view (0.647575), so cue, visual, or ocular activity is the leading explanation rather than proven motor-cortex decoding |
| Trial identity | All 66 S21 session-1 trials and all 63 performed session-2 trials reconcile to MAT provenance; empty session-2 slots remain explicit | The real MEG evidence has exact trial identity instead of fuzzy sentence matching |
| Local neurodata access | Six EEG/MEG file families are covered by 40 bounded fixtures: 38 readable and 2 exact refusals | Contributors can test metadata, readers, privacy, and caps without sharing participant recordings |
| IACKD source compatibility | H1 found 96 29-row and 32 31-row headers. H2 then parsed all 316 public BIDS metadata bodies and confirmed one 26-channel predictive EEG core, 1024 Hz sampling, average reference, and complete central/occipital geometry in all 30 groups | The exact-36 reader assumption was wrong, but H2 still routed IACKDR-R1: HEOG, VEOG, and Trigger are source-typed MISC, exposing a frozen control-taxonomy bug before any EEG sample, event, target, model, or score was accessed |
| MARC-1 source eligibility | The Freewill central-directory inventory passed without payload, but the one source-aware Wrist metadata check later routed MARC1SAL-R2 with zero selected subjects and zero payload bytes |
The Wrist branch is consumed and blocked before acquisition; the private source route remains unavailable and is not inferred or repaired |
| MARC-2 confound triangulation | VR39P Stage 1 passed one 168-path generated qualification: 168 VR33A calls, 84 VR38A calls, exact R1/R2 64/104, 64 temporary cohort writes, 268 refusals across 12 named critical classes, 12.82 s runtime, 67.2 MB peak RSS, and zero retained output; implementation, closeout, and activation all passed remote CI before Stage 2 |
The sole target-free Stage 2 attempt returned aggregate R2 with no cohort commitment. Freewill/CIL1 is permanently parked; the failure stage and private topology remain unavailable, and no neural payload, target, model, prediction, score, or neural advantage was established |
| Continuous interfaces | NeuroTokenCache preserves 553 valid synthetic frames; causal replay is exact across 5/5 schedules with zero right context | Cache and streaming contracts exist, but they do not establish useful neural representations or text decoding |
| Full-path causality gate | Loop 25 v1 passed a dedicated causal anti-alias audit, 65,537 response points, 23 alias probes, 168 schedule checks, 240 resume checks, and 72 future-mutation controls across 24 target-free items | The exact 1000-to-100 Hz path is mechanically causal with zero right context; this is synthetic mechanics evidence, not proof that neural information survives |
| Consumed S21 validation | The registered 2,908-parameter candidate reached macro CER 0.938177; the train-only no-signal prior reached 0.751235, so the candidate was worse by 0.186942 |
Loop 26 is parked after one consumed six-target event; this is a clear negative result, not neural advantage |
| Artifact-only failure localization | The one-shot Stage A pass reproduced 99.3477% primary blank, all 6/6 unstable fixed-prefix groups, and all 3/3 size-55 seeds worse than the prior |
Loop 48 selected descriptive F5 output-distribution instability in 0.0166 sec and 23.4 MB RSS; that phenotype is not a proven root cause |
| Train-only failure discrimination | The consumed Stage B primary reached macro CER 0.953566 versus 0.822045 for its train-only prior; all six full-size causal/linear fits were finite and stable, but none cleared the prior |
H4 stable nonseparability is supported and fixed timing-offset H3 has evidence against it; the exact L50-R05 route parks S24 acquisition for this model family, with no neural advantage or rerun |
| Temporal-representation repair | The consumed Stage C synthetic candidate reached CER 0.433333 and 1/8 exact versus ablation CER 1.000000; its 0.566667 CER advantage passed, but the absolute <=0.10 CER and >=7/8 exact gates failed |
Temporal context was usable on the purpose-built fixture, but Stage C is parked without rerun and establishes no real neural-decoding benefit |
| Fresh EEG acquisition gate | Loop 53 acquired and opaque-verified the exact public S20 session-2 block-2 bundle: 4 files, 96,090,264 bytes, 3.629499s, 63,225,856-byte peak RSS, and all 10 gates passed |
Acquisition mechanics are proven and the one invocation is consumed; no header, marker, signal sample, MAT field, target, cache, split, or model was interpreted or run |
| Fresh EEG qualification gate | Loop 54 separates strict VHDR-only metadata, target-blind VHDR+EEG quality, isolated target-bearing VMRK+MAT reconciliation, and aggregate closeout; L54-A bound one exact 11,705-byte header, 18 gates, 22 refusals, and a one-shot strict parser boundary | The one execution passed source size/hash and strict decoding but parked at F11 because the format preamble did not match; L54-Q2 failed, no rerun is open, and stages B/C remain blocked |
| Fresh EEG neural-effect design | Loop 55 now separates a causal pre-keypress performed-hand gate from a harder causal 29-key gate, with performed actions as primary targets, a post-keypress diagnostic, 12 matched conditions, exact trial-level tests, and one-shot target order | Planning research is complete and Loop 54 dependent; the S20 bundle is acquired but uninterpreted, the experiment is Not Started, and no target, model, prediction, score, neural advantage, or decoding result exists |
| Bounded AI research guard | A dependency-free Loop 55 policy now validates and hashes strict synthetic AI recipe proposals, rejects target leakage, future context, LLMs, pretrained weights, unknown fields, model runs, and cap expansion, and reserves at most four future train-inner proposal rounds inside the existing 12-fit ceiling | The synthetic interface is implemented and measured; no AI proposal has accessed S20, trained a model, or produced neural evidence, and any future real proposal phase remains Loop 54 dependent and separately Tier C authorized |
| Open EEG R&D strategy | Current 2025-2026 evidence supports the compact specialist path and adds a prospective 23,248,224-byte public motor positive control, an interpretable motor-physiology rung, classical EEG baselines, and local-first contributor receipts | Research and planning only: no public EEG payload, S20 content, model, target, or pretrained weight was opened, and every real execution remains separately Tier C gated |
| Causal Motor Lattice architecture | The exact 4,535-parameter CML-v0 learned all constructed signal-bearing check rows at 1.0 hand/key accuracy, localized all three registered branches, passed hand/key marginal-consistency and causal future-tail checks, and replayed its checkpoint exactly |
The one synthetic run passed 18/19 gates but parked at CML-R0 when float32 common-mode error 1.9073486e-6 exceeded the frozen 1e-6 tolerance; final stayed closed, there is no rerun, and no real EEG or scientific result exists |
| Foundation-model decoder bridge | FM-0 compiled all 12 synthetic plans; the one FM-1 Terra invocation then attempted 3 calls, returned 2 strict responses, and parked on a non-completed FM-A02 response after 8.406 seconds at 39.3 MB peak RSS |
Live bounded transport and fail-closed receipts worked, but the four-arm matrix did not complete and has no rerun; no real neural evidence or target was used, so no decoding or neural result exists |
| AI budget and local-tool leverage | A $50 aggregate provider ceiling is split into conservative experiment caps while MNE, MOABB, pyRiemann, Braindecode, and future cEEGrid adapters carry local work first | The budget is not a spend target; $0.50 is reserved for incomplete FM-1 accounting, at least $30 stays behind future evidence gates, and a pending earbud-electrode patent is architecture context, not proof that AirPods read thoughts |
| Local EEG tooling inventory | One green, zero-network audit found NumPy 2.5.0, SciPy 1.18.0, and MNE 1.12.1; array/signal mechanics, BrainVision reading, and ICA are available in 14.53 seconds at 173.2 MB maximum child RSS, while scikit-learn, pyRiemann, MOABB, and Braindecode are absent |
The next synthetic fixture work can proceed without an install; availability is engineering evidence only and establishes no dataset quality, neural effect, model accuracy, or device result |
| Cross-modality accessibility verdict design | Loop 56 freezes five verdict classes, 12 non-skippable capability levels, 18 EEG/MEG comparison dimensions, a 16-field claim sentence, and a 12-part at-home conjunction | Planning research is complete and Loop 55 result dependent; only modality-aware interfaces are shared, tested MEG/EEG predictors remain negative, S20 has acquisition evidence only, and no equivalence, transfer, real-time, device, home, or clinical claim exists |
| Development-person intake planning | Loop 49 metadata research selects S24 session 2 block 2: one MEG FIF plus one protected MAT log, exactly 1,048,579,727 bytes; a future text-grouped split reserves 16 unique sentence groups for selection and requires at least 32 fit groups |
S24 avoids the S1/S18 alias and preserves S25 final-only, but no S24 path or payload was opened and the >=48 usable-row, channel, geometry, and overlap gates are unproven; Loop 49 remains Not Started |
| Multi-source encoder planning | Loop 50 research freezes global text grouping, five-fold historical S21 out-of-fold diagnostics, one 16-group S24 development gate, equal-person loss, ten fixed conditions, and an exact 20-update inventory led by seed 5001 |
Stage B route L50-R05 now parks the same-family S24 path; Loop 50 remains Not Started, with S24 qualification, model selection, training, scoring, and every scientific claim unavailable |
| Fresh transfer candidate | Loop 27 metadata research selects S25 session 2 block 2: one MEG FIF plus one protected MAT log, exactly 1,009,939,983 bytes under 1 GiB | S25 is not downloaded or qualified; preregistration waits for the causal source model, controls, and target isolation |
| Transfer decision rule | Loop 28 research separates T0-T3 evidence and recommends a strict S25 T2 zero-shot gate: zero target fit, at least 48 final rows, at least 0.05 macro-CER improvement, 65,535 paired swaps plus observed, and strict corruption-control wins | The experiment is Not Started; this resolves one planning dependency without authorizing S25, a model run, calibration, or final access |
| Portable sensing decision | Loop 29 research separates cryogenic MEG, partner/lab OPM-MEG, local-first scalp EEG, and non-neural controls through 15 requirements and six qualification levels | Planning research is complete while the experiment is Not Started; no device, download, stream, hardware session, or portable decoding result exists |
| Local replay interaction decision | Loop 30 research freezes four source modes, a 30-field target-free trace, nine clock domains, six latency levels, 18 gates, 30 refusals, and fixed loopback/browser/accessibility controls | Planning research is complete while the experiment is Not Started; no trace, UI, server, browser run, live source, confidence, or end-to-end latency result exists |
| Neural-attribution decision | The candidate beat exact-zero and timing-only controls on 6/6 items, but failed the complete prior, derangement, displacement, and corruption conjunction | Loop 31 is parked; the partial control wins are diagnostic hints and do not establish sensor-signal dependence or brain-specific origin |
| Peripheral-confound decision | Loop 35 research freezes 10 confound classes, 9 synchronized stream classes, 13 conditions, 3 separately authorized stages, 24 gates, and 32 refusals | Planning research is complete while the experiment is Not Started; current data cannot support the complete firewall, and even a future pass can claim only incremental brain-sensor information beyond recorded controls |
| Geometry/reference decision | Loop 36 research freezes 6 representation layers, 5 modality profiles, a 24-field channel record, 12 operation classes, 16 fixture families, 22 gates, and 30 refusals | Planning research is complete while the experiment is Not Started; a future header pass can establish at most declared metadata compatibility, not numerical/model/device equivalence |
| BIDS provenance decision | Loop 37 research freezes 6 export layers, 5 artifact profiles, 15 stable-field mappings, 16 NeuroDecodeKit extension fields, 20 fixtures, 24 gates, and 32 refusals | Planning research is complete while the experiment is Not Started and unauthorized; future NeuroToken/report payloads remain explicitly non-standard inside a BIDS-organized envelope |
| Neural-data privacy decision | Loop 38 research freezes 5 sensitivity levels, 8 artifact classes, 10 lifecycle surfaces, 12 sensitive-field classes, 5 deletion-receipt levels, 24 fixtures, 26 gates, and 36 refusals | Planning research is complete while the experiment is Not Started and unauthorized; unknown copies remain unresolved, and path absence is not media sanitization |
| Cross-machine reproducibility decision | Loop 39 research freezes 7 qualification levels, 18 environment fields, 8 output classes, 6 comparison classes, 6 future matrix cells, 28 gates, and 38 refusals | Planning research is complete while the experiment is Not Started and unauthorized; current Python 3.10, macOS, cross-OS, dependency-lock, and built-package claims remain unqualified |
| Edge-runtime packaging decision | Loop 40 research freezes 7 qualification levels, 6 package layers, 4 backend profiles, 20 identity fields, 24 fixtures, 30 gates, and 40 refusals around the retained 1,130-parameter float32 reference | Planning research is complete while the experiment is Not Started and unauthorized; ExecuTorch/XNNPACK is a research lead only, with no selected target, export, package, inference, simulator, or hardware result |
| One-device qualification decision | Loop 42 selects the exact OpenBCI Cyton base 8-channel USB-radio path and freezes 28 identity fields, 7 timing observables, 10 anomalies, 4 stages, 34 gates, and 46 refusals | Current evidence is Q0 official-specification eligibility only; no device is owned, purchased, connected, streamed, or qualified, and no signal or decoding claim exists |
| Independent reproduction decision | Loop 43 freezes a future target-free NeuroToken causal-replay challenge with 7 qualification levels, 16 independence fields, 28 packet fields, 34 submission fields, commit-reveal ordering, 36 gates, and 48 refusals | Planning research is complete while the challenge is Not Started and unauthorized; a local validator incident parsed 136 cache JSON files, including 11 known consumed session-2 report/metadata files, but no content was used for tuning, scoring, or claim selection |
| Claim and release decision | Loop 44 binds 16 claim cards to 7 evidence levels, 5 model cards, 4 dataset cards, 14 release gates, and 8 risks | Artifact review is complete; engineering release is held, scientific performance release is parked, and no tag, release, DOI, payload, or claim upgrade exists |
| Real predictive evidence | Both the same-person cross-session MEG model and the bounded S7 EEG classifier lose to no-signal controls | The current scientific result is negative, explicit, and frozen against post-hoc tuning |
| Local execution gate | Float16 preserved exact behavior but ran 1.170x slower on the producer; qint8 cut payload to 47.1% but changed behavior and ran 2.785x slower |
Float32 is retained, qualification stayed unopened, and Loop 24 is parked after the full run exceeded its 60-second cap |
| Next transport layer | Stage A is specified as 90 future schedule-by-fixture cases with 30 exact refusals under a 32 MiB cap | The decision packet is review-ready; no replay runtime, socket, board, or hardware path is authorized yet |
Loops 45-64 are specified in
docs/LOOPS_45_64_SCIENTIFIC_ROADMAP.md
and registries/next_scientific_loops.v0.json. Loop 45 is complete at its
target-free mechanics boundary. Loops 46 and 47 are now parked after the one
registered S21 validation event failed its primary and attribution gates. Loop
48 completed one post-outcome artifact-only Stage A over four exact committed
JSON artifacts. The frozen eight-class tree selected descriptive F5
output-distribution instability; the 10,643-byte result is consumed and is not
a proven root cause.
The separate Stage B protocol was frozen in
docs/LOOP_48_TRAIN_ONLY_DISCRIMINATION_PREREGISTRATION.md and
registries/loop48_train_only_discrimination_contract.v0.json. It starts from
the immutable five-hypothesis portfolio and additive H1-H6/T1 research, then
binds a deterministic 44-fit/11-check source-train split, exact model/control
inventory, prediction-before-target order, paired statistics, resource caps,
and stop rules. All 55 rows were used by earlier fits, so the new check split
is prospective only inside this execution; Stage B can reach at most E2
diagnostic evidence. The exact decision at 8d17342 and implementation at
1d840e3 were separately pushed and remotely green before protected access.
The target-blind run then completed 20 fits, 4,800 optimizer steps, 35 model
inferences, five priors, and 41 prediction sets. Hash-only freeze commit
00215b1 passed push CI 29461934145 and PR CI 29461935560 before the same
11 train-check targets opened once.
The consumed result in
registries/loop48_train_only_discrimination_result.v0.json supports H4,
stable but nonseparable representation, and records evidence against H3, the
four registered fixed timing offsets. The primary candidate reached macro CER
0.953566 versus 0.822045 for its train-only prior, a -0.131522 margin.
H1, H2, H5, and H6 remain unresolved. The frozen Loop 50 router selects
L50-R05, so S24 acquisition is parked for this model family. Stage B is
consumed, no rerun is open, S24 remains metadata-only, and S25 remains sealed.
See docs/LOOP_48_STAGE_B_RESULT.md.
Stage C tested one narrower explanation for the failed family: the original
causal probe may have been starved of temporal context. After correction commit
2836ecc passed push CI 29467415680 and PR CI 29467416894, the registered
synthetic gate ran once. The 7,692-parameter, 470 ms causal temporal encoder reached
final CER 0.433333 and 1/8 exact sequences, versus CER 1.000000 and 0/8
for the 7,568-parameter zero-context ablation. The 0.566667 relative CER
improvement passed, along with replay, causality, mutation, resume, padding,
and resource checks. The candidate still failed the frozen absolute CER
<=0.10 and exact-sequence >=7/8 gates, so Stage C is consumed and parked
without tuning or rerun. The run took 7.829308 seconds internally, peaked at
310,509,568 bytes RSS, generated 83,132 bytes, and opened no real signal,
target, or cache. See docs/LOOP_48_STAGE_C_SYNTHETIC_RESULT.md and
registries/loop48_stage_c_synthetic_result.v0.json.
The accessible-modality path has now completed Loop 53. Authorization commit
2a47bbc and implementation commit 8ec5b1b each passed push and PR CI before
the one registered invocation ran. The exact S20 BrainVision VHDR/EEG/VMRK
triplet plus MAT log totaled 96,090,264 bytes and matched every frozen path,
size, Git/LFS, and Xet identity. The pass took 3.629499 seconds, peaked at
63,225,856 bytes RSS and 102,035,529 incremental disk bytes, and generated
an 8,265-byte private receipt. Every header, marker, signal, MAT, target,
cache, split, model, training, inference, scoring, device, and rerun counter is
zero. Loop 53 is consumed with no rerun; see
docs/LOOP_53_ACQUISITION_RESULT.md.
Loop 54 planning research now defines what happens only after a clean Loop 53
receipt. The source audit found that MNE's standard BrainVision reader exposes
marker-derived annotations and that NeuroDecodeKit's historical Loop 19 bridge
also excludes EOG-named channels, loads MAT labels, reads signal, and writes
plaintext labels in one invocation. That path remains valid for its consumed
engineering result, but it is not eligible for a fresh scientific gate. The
new design requires a dependency-light VHDR-only parser, a target-blind signal-
quality pass that retains every channel, and an isolated VMRK+MAT reconciler
that emits no plaintext target values. At least 48 unique performed trials must
reconcile, event windows may not masquerade as independent trials, and Loop 54
creates no split or model. See docs/LOOP_54_PRIMARY_SOURCE_RESEARCH.md and
registries/loop54_eeg_trial_geometry_research.v0.json.
The first real-content stage is now consumed and parked. L54-A
binds exactly one 11,705-byte S20 VHDR and requires a strict standard-library
parser that cannot resolve, stat, or open its EEG, VMRK, or MAT siblings. Its
18 acceptance gates, 22 refusal classes, one-thread/worker limit, 30-second and
256 MiB caps, one content open, one execution, and 1 MiB output ceiling are in
docs/LOOP_54_STAGE_A_VHDR_PREREGISTRATION.md and
registries/loop54_stage_a_vhdr_contract.v0.json. Recovery-bound decision
2177b36 passed CI 31286428489 before implementation. The parser now strictly
supports declared UTF-8, UTF-8 BOM, and explicitly declared Windows-1252;
rejects malformed sections, keys, channels, sampling, source hashes, paths,
outputs, operations, and claims; and emits only allowlisted declarations. Its
24 focused tests and 24 mutation subchecks cover all 22 refusal classes.
Implementation b486fdf passed CI 31287819503 before the one registered
execution opened exactly 11,705 VHDR bytes once. Source size, Git-blob identity,
and strict decoding passed; required-structure validation parked at
L54A-F11 because the format preamble was missing under the frozen contract.
The command used 0.20 seconds and 24,051,712-byte peak RSS, touched no sibling,
signal, marker, MAT, target, model, network, or hardware surface, and wrote no
registered output. L54-Q2 was not established, no rerun is open, and Loop 54-B
and 54-C remain blocked. See docs/LOOP_54_STAGE_A_VHDR_RESULT.md and
registries/loop54_stage_a_vhdr_result.v0.json.
Loop 55 planning research then defines the scientific question that becomes
eligible only after Loop 54 reports at least 48 unambiguous performed trials.
It does not use one vague "EEG decoding" endpoint. The same future compact
model has two prospectively ordered tests: causal pre-keypress left/right-hand
prediction and harder 29-class performed-key prediction. The published
[-200,+300] ms keypress-centered window remains a noncausal diagnostic
because it includes post-keypress execution and feedback. Intended sentence
text is secondary; performed action is primary. The future gate requires a
grouped trial-level split, at most 10,000 parameters and 12 fits, twelve matched
no-signal/timing/corruption/peripheral conditions, exact paired final-trial
tests, and a committed, pushed, remotely green prediction freeze before final
targets open once. Even a clean key-level pass would establish only one-block
EEG sensor-signal dependence with known keypress onsets, not brain-specific
origin, continuous thought-to-text, generalization, real-time operation, or
home use. See docs/LOOP_55_PRIMARY_SOURCE_RESEARCH.md and
registries/loop55_eeg_neural_effect_research.v0.json.
The additive Loop 55 AI policy makes that future search more disciplined without pretending it has run. One compact causal family remains fixed. An AI proposer may eventually choose from a small preregistered recipe menu using at most four aggregate train-inner rounds, while a deterministic local runner retains all data access. Selection/final outcomes, raw protected EEG, trial labels, intended text, language models, pretrained weights, and scientific claim decisions remain unavailable to the agent. The currently implemented surface validates synthetic manifests only:
neurodecode inspect-ai-research-policy
neurodecode validate-ai-research-proposal \
--proposal fixtures/loop55_ai_synthetic_proposal.v0.jsonThe committed roundtrip reads 11,949 policy bytes and 1,771 proposal bytes,
takes approximately 0.001 seconds, peaks near 22 MB RSS, and records zero real
data, cache, model, training, inference, scoring, network, or device operations.
See docs/LOOP_55_AI_ASSISTED_REPRESENTATION_RESEARCH.md and
registries/loop55_ai_research_policy.v0.json.
The 2026-08-06 open EEG strategy refresh confirms that this specialist-first
path is still the correct laptop-scale scientific choice. Two current open
benchmarks report that specialist models remain competitive, linear probing is
often insufficient, and larger EEG foundation models do not consistently
generalize better. The refresh therefore adds three prospective upgrades
without changing any authorization: a tiny public left/right motor-execution
positive control before protected discovery, one externally selected classical
EEG baseline plus an interpretable pre-keypress physiology assay, and
local-first hash-bound receipts for EEG contributors. Foundation models remain
a separate public-data watch lane, and generative channel imputation may not
support primary evidence. See
docs/OPEN_EEG_R_AND_D_STRATEGY_2026-08-06.md and
registries/open_eeg_rd_strategy.v0.json.
The architecture research made that specialist path concrete, and a separate
bounded synthetic gate has now exercised it. CML-v0 separates slow potential
shape, causal mu energy, and causal beta energy; each view has a rank-8 spatial
mixer and three time cells. A 24-dimensional bottleneck feeds a fixed physical
keyboard lattice plus a small 29-key residual. Hand probability is an exact
marginal of the key distribution rather than a contradictory second head. The
exact parameter formula is 24C + 2,549 + 25P; at 64 channels and the maximum
18 primitives it is 4,535 parameters.
The one synthetic run learned all 16 constructed signal-bearing check rows,
routed each registered factor to its matching branch, preserved exact replay,
and passed every resource and access gate. It nevertheless parked because the
maximum float32 common-mode logit difference was 1.9073486e-6, above the
preregistered 1e-6 ceiling. That exact failure cannot be waived after seeing
it; seed 5513 is consumed, final remained undelivered, and there is no rerun.
Perfect performance on invented factors is software evidence only and cannot
prove cortical physiology or neural decoding.
The qualification ladder is now two-axis because one tiny public dataset does
not test both questions. The existing 23,248,224-byte PhysioNet prospect tests
left/right execution mechanics; a separately scoped 2026 EEG+EMG MRCP slice
would test true pre-movement alignment against EMG onset. Both remain
undownloaded and unauthorized, and both must pass independently before this
architecture can become eligible for a future S20 freeze. See the architecture
research plus docs/CAUSAL_MOTOR_LATTICE_SYNTHETIC_PREREGISTRATION.md,
docs/CAUSAL_MOTOR_LATTICE_SYNTHETIC_IMPLEMENTATION.md, and
docs/CAUSAL_MOTOR_LATTICE_SYNTHETIC_RESULT.md with their matching registries.
Loop 56 planning research defines how to report whatever survives those gates
without pretending EEG and MEG are interchangeable. It freezes five classes:
shared proven artifact, shared interface only, modality-specific
requalification, unavailable, and prohibited inference. Its 12-level ladder
separates source identity, bounded reading, signal quality, trial integrity,
sensor-signal effect, key/text prediction, continuous input, causal incremental
output, measured end-to-end latency, local device mechanics, repeated at-home
feasibility, and assistive or clinical utility. Missing levels cannot be
skipped. The current provisional route is mechanics and interfaces only:
registered local MEG and historical EEG predictors both lost to no-signal
comparators, but they are not a matched modality comparison, and fresh S20 EEG
is acquired but remains uninterpreted. A future final verdict may read only
hash-bound committed aggregate reports after Loop 55 closes and a separate Tier
C claim decision is green. See docs/LOOP_56_PRIMARY_SOURCE_RESEARCH.md and
registries/loop56_cross_modality_accessibility_research.v0.json.
Loop 49 planning research now selects S24 session 2 block 2 as the preferred
permanently development-only participant from pinned public metadata. The exact
two-file bundle is 1,048,579,727 bytes, 293,597,553 bytes below its 1.25 GiB
cap. S24 is preferred over the 29,701,559-byte-smaller S18 pair because S18
belongs to the published S1/S18 alias group; S25 remains the final-only person.
The future recommendation assigns 16 canonical sentence groups to development
selection, all remaining usable groups to fit, and excludes any matching S21
selection text from future fit. No S24 local path, payload, header, signal, MAT
content, target, split, model, or training operation occurred. The >=48
unique-row floor and compatibility fields remain unavailable, so Loop 49 is
planning-complete but experimentally Not Started, unpreregistered, and
unauthorized. See docs/LOOP_49_PRIMARY_SOURCE_RESEARCH.md and
registries/loop49_research_boundary.v0.json. Planning commit 5afa61e passed
push CI 29454969710 and PR #27 CI 29455166081, with both required jobs green.
Loop 50 planning research is complete in
docs/LOOP_50_PRIMARY_SOURCE_RESEARCH.md
and registries/loop50_research_boundary.v0.json, while the experiment remains
Not Started. The future design globally groups identical text across people,
uses five historical S21 out-of-fold folds plus one 16-group S24 development
qualification, weights S21 and S24 equally, forbids participant-conditioned
model paths and target-corpus normalization, and requires both participants and
the worst-person margin to pass. Primary seed 5001 cannot be replaced by the
two stability seeds. Five pooled out-of-fold fits, three pooled final fits, six
linear fits, and six S21-only fits bound the recommendation to 20 parameter-
update runs; the four-run gap below the absolute cap is not rerun permission.
Pooled gain cannot rescue a failed person. Stage B has now closed at route
L50-R05: stable nonseparability parks S24 acquisition for this model family.
The Loop 50 planning snapshot still correctly preserves 31 false authorization
fields and zero protected/model counters; no S24 or S25 operation is open.
Planning commit 085f341 passed push CI 29458102674 and PR #28 CI
29458116994, with Base Python and Optional Neuro Readers green in both.
| Phase | Loops | Decisive goal |
|---|---|---|
| Real Signal Truth | 45-48 | Qualify causality, then require frozen S21 validation to beat no-signal and corrupted-signal controls |
| Unseen-Person Verdict | 49-52 | Add one nonfinal development person, freeze once, and make one final-only S25 decision |
| Accessible EEG Evidence | 53-56 | Acquire fresh S20 only after approval and test EEG without borrowing a MEG claim |
| Causal Local Use | 57-60 | Prove stream parity, device mechanics, measured latency, and home acquisition as separate claims |
| Independent Evidence And Release | 61-64 | Cross-machine qualify, reproduce externally, define replication, and promote only supported claims |
If S21 validation does not beat the prior and every signal corruption, model scaling stops and failure localization begins. S25 stays sealed until a multi- person source model is fully frozen; a failed final gate becomes the durable negative result and S25 is never repurposed for calibration.
| Result | Measured evidence | Proof label | Why it matters |
|---|---|---|---|
| Complete S21 trial reconciliation | 66/66 session-1 trials; 63/63 performed session-2 trials; empty MAT slots 54, 58, and 60 preserved | real-data validated | Turns ambiguous trigger/log ordering into exact trial provenance instead of fuzzy text matching |
| Task-matched EEG bridge | 2,534 MAT triggers aligned; 2,197 windows; 2197 x 61 x 25; 12,428,800-byte cache |
real-data validated | Proves bounded BrainVision plus MAT mechanics on EEG without pretending the classifier succeeded |
| Sampling-rate characterization | identical 66-row caches at 100/50/25 Hz; 1,663,209 / 846,334 / 431,451 bytes | real-data validated | Quantifies storage and temporal feasibility without selecting a rate from unmeasured accuracy |
| Geometry-aware channel subsets | one 102-magnetometer base plus 20 exact-identity subset caches under 128 MiB | real-data validated | Makes sensor-cost tradeoffs inspectable while keeping geometry proxies separate from decoding claims |
| Precision/storage sweep | qint16 is 49.84% smaller; qint8 is 80.75% smaller with worst relative RMSE 0.9531%; no clipping | real-data cache mechanics | Measures representation distortion without calling it retained model accuracy |
| NeuroTokenCache v0 | 48 x 16 x 32; 76,646 bytes; exact payload replay; zero target-member reads |
fixture-backed interface | Establishes a strict modality/timing/mask/split/hash contract without unreleased embeddings |
| Causal frame replay | 553 canonical frames; 5/5 schedules exact; zero right context; 300-byte mutable state | synthetic mechanism only | Separates true producer causality from transport scheduling and decoder latency |
| Tiny learned causal producer | 1,130 parameters; validation and one-time test balanced accuracy 1.0 versus 0.166667 signal-free prior; 5/5 replay | synthetic mechanism only | Proves the bounded stream can carry a learned signal on an intentionally easy generated task |
| Blank calibration mechanism | validation and one-time test both 16/16 exact at CER 0; 9 test corrections; 0 regressions | synthetic mechanism only | Shows one preregistered scalar can solve a specific tail-error mechanism without post-test trimming |
| Local precision/runtime gate | 3 exact candidates; 12/12 balanced rounds; 990 frames; float16 exact but full path 1.088x; qint8 payload 47.1% but full path 1.812x and incorrect; qualification 0 opens |
parked target-free synthetic result | Demonstrates why payload size, correctness, steady-state speed, and orchestration cost must be separate gates |
| Metadata-only local intake | 6 format families; 532 source bytes; 11,545 report bytes; 0 binary/raw/target/model/network reads | fixture-backed | Lets EEG owners start with safe structure and provenance instead of uploading a recording |
| Bounded signal-quality interface | 40 fixtures; 38 readable and 2 exact refusals across 6 format families; 3.839 sec; 76,592 output bytes | fixture-backed | Validates readers, metrics, privacy, caps, and no-mutation identity before any real quality claim |
| Replay/live-source authorization gate | 5 schedules x 18 fixture families = 90 future cases; 30 refusal IDs; 4 separately gated stages; 10 invariants | review-ready, not authorized | Binds the exact Stage A scope and caps before any source-chunk, socket, board, fixture, or hardware implementation |
| Causal preprocessing v1 | 4 anti-alias and 9 total SOS sections; 65,537 response points; 23/23 alias probes; 24/24 target-free items; 168 schedules; 240 resumes; 72 mutation controls; 0 protected reads | completed target-free synthetic mechanics | Establishes one strict, resumable 1000-to-100 Hz causal path with zero right context while leaving retained neural information and decoding performance unproven |
| Loop 26/31/33 shared validation gate | 55/6/5 source split; 2,908/2,884-parameter models; 21 fits; 24 target-blind inferences; six priors; 31 frozen prediction sets; one post-freeze six-target score; candidate/prior macro CER 0.938177/0.751235 |
consumed negative result; all three gates parked; no rerun | Proves the target firewall and bounded research runtime work while showing this exact predictive design does not beat an honest no-signal baseline |
| Loop 48 artifact-only failure localization | 4 exact committed JSON inputs; 155,545 input bytes; 18 blank fractions; 6 fixed-prefix ranges; F5; 0.016568875 sec; 23,429,120-byte peak RSS; 10,643 output bytes; 0 protected/model/training operations |
consumed post-outcome descriptive result; no rerun | Reproduces the failure phenotype mechanically while keeping causal root cause, neural advantage, and every decoding or device claim explicitly unavailable |
| Loop 48 Stage B failure discrimination | 44 fit / 11 check rows; prefixes 8,16,24,32,44; seeds 4801-4803; 20 fits; 4,800 steps; 35 target-blind inferences; 5 priors; 41 frozen sets; one post-freeze 11-target score; candidate/prior macro CER 0.953566/0.822045 |
consumed E2 diagnostic; H4 supported, H3 evidence against, L50-R05 parks S24 for this family; no rerun |
Distinguishes stable nonseparability from a simple fixed timing offset while preserving the negative neural result and refusing independent-validation or neural-advantage wording |
| Loop 48 Stage C synthetic representation gate | 40 synthetic rows; 24/8/8 split; 4 fits; 1,680 steps; candidate/ablation CER 0.433333/1.000000; candidate exact 1/8; replay, mutation, resume, causality, padding, and resource checks passed |
consumed synthetic gate; absolute CER and exact-sequence gates failed; no rerun | Shows the causal temporal model can use ordered synthetic history while refusing to transfer that contrast into a real neural-decoding claim |
| Loop 53 fresh EEG acquisition result | 4 exact S20 files; 96,090,264 network/final bytes; 3.629499 sec; 63,225,856-byte peak RSS; 102,035,529-byte peak disk; 8,265 receipt bytes; all 10 gates passed | consumed acquisition-mechanics pass; one invocation; no rerun; zero interpretive or model operations | Establishes a reproducible local EEG byte bundle while keeping header, geometry, signal, target, cache, model, and scientific decisions closed |
| Loop 49 development-person boundary | 396 pinned metadata rows; S24 session 2 block 2; 2 exact files; 1,048,579,727 bytes; 293,597,553-byte cap margin; 16 future selection groups; 32 minimum fit groups; 25 false authorization fields | metadata research only; experiment Not Started |
Creates a clean development-person path without consuming final-only S25, while keeping trial count, channels, geometry, targets, signal, models, and transfer claims closed |
| Loop 50 multi-source research boundary | 6 primary sources; 5 S21 out-of-fold folds; 16 future S24 selection groups; 10 fixed conditions; 20 parameter-update runs; seeds 5001-5003; 30 refusals; 31 false authorization fields |
planning research only; experiment Not Started |
Defines a text-leakage-resistant, participant-balanced, worst-person-gated development experiment while keeping S24/S25 payloads, model choice, training, scoring, and claims closed |
| Loop 27 fresh-holdout boundary | 315 pinned MEG metadata entries; 23 strict single-FIF/log pairs; 16 eligible; S25 selected at 1,009,939,983 bytes; S23 excluded; 18 false authorization fields | metadata research only | Finds the smallest honest same-modality transfer candidate while keeping its local MAT payload, remote FIF, targets, and backups sealed |
| Loop 28 transfer boundary | T0-T3 taxonomy; strict zero-shot/transductive split; 48-row floor; 0.05 macro-CER margin; 65,535 paired assignments plus observed; 4 comparators; 21 false authorization fields | planning research only | Makes the future one-time S25 decision falsifiable while reserving calibrated transfer for a physically separate design |
| Loop 29 portability boundary | 15 modality requirements; 4 profiles; 6 qualification levels; 12 future packet gates; 24 false authorization fields; 5,000,000,000-byte preferred storage ceiling | planning research only | Chooses EEG as the immediate local-first lane and OPM-MEG as a partner/lab lane without treating channel ablation, vendor specifications, or home acquisition as text decoding |
| Loop 30 replay interaction boundary | 4 source modes; 30 event fields; 9 clock domains; 6 latency levels; 18 future gates; 30 refusals; 30 false authorization fields | planning research only | Defines how a future target-free local replay can show revisions, finalization, clocks, privacy, and proof posture without implying live or low-latency neural decoding |
| Loop 31 neural-attribution boundary | 10 encoder conditions; zero/timing controls passed individually; prior, row/channel/time/target conjunction failed; 5 contingent LLM conditions remained closed | consumed shared gate; parked | Separates useful diagnostic components from the failed claim-level conjunction and blocks sensor-signal or brain-origin overclaiming |
| Loop 48 failure-localization boundary | primary blank 0.993477; all-condition blank range 0.997146; all 6 prefix groups cross 0.25 seed dispersion; 17 unavailable root-cause fields; 30 refusals |
one consumed artifact-only Stage A; descriptive F5; no rerun |
Reproduces model-fit/output-distribution instability as the leading artifact phenotype while refusing to call CTC, preprocessing, signal quality, or weak neural information the proven cause |
| Loop 48 hypothesis-discrimination boundary | 6 coexisting hypotheses; 1 orthogonal shortcut threat; 5 evidence levels; 6 sequential shared-evidence stages; 5 primary-source bindings; 15 false authorization fields | additive design research only | Separates fixed-recipe, quality, timing, representation, prior, and data-regime explanations while capping any future Stage B result below brain-specific origin |
| Loop 34 confidence boundary | 7 confidence semantics; 8 score/control roles; recommended fresh 128/64/256 synthetic partitions; 20 future gates; 30 refusals; 26 false authorization fields |
planning research only; confidence unavailable | Separates ranking, calibrated probability, abstention, conformal risk, revision stability, and product confidence while refusing reuse of six real validation rows |
| Loop 35 peripheral-confound boundary | 10 confound classes; 9 future synchronized stream classes; 13 conditions; 3 stages; 24 future gates; 32 refusals; 31 false authorization fields | planning research only; complete real controls unavailable | Requires timing, ocular, distal/proximal muscle, motion, audio/environment, and combined nonbrain comparators before any bounded incremental brain-sensor claim |
| Loop 36 geometry/reference boundary | 6 representation layers; 5 modality profiles; 24 channel fields; 12 operation classes; 16 fixture families; 22 gates; 30 refusals; 29 false authorization fields | planning research only; complete real metadata unavailable | Separates identity-preserving metadata operations from signal scaling, rereference, compensation, interpolation, model transfer, and device-equivalence claims |
| Loop 37 BIDS provenance boundary | 6 export layers; 5 artifact profiles; 15 stable BIDS fields; 16 explicit NeuroDecodeKit extension fields; 20 fixture families; 4 stages; 24 gates; 32 refusals; 29 false authorization fields | planning research only; no derivative tree exists | Separates a standards-valid dataset envelope from non-standard NPZ/report payloads while refusing raw copies, local paths, target text, invented source URIs, and release overclaims |
| Loop 38 privacy/lifecycle boundary | 5 sensitivity levels; 8 artifact classes; 10 lifecycle surfaces; 12 sensitive-field classes; 12 threats; 5 receipt levels; 24 fixtures; 4 stages; 26 gates; 36 refusals; 32 false authorization fields | planning research only; copies outside current Git metadata remain unresolved | Separates redaction, de-identification, local path receipts, repository coordination, media sanitization, consent, license, and sharing authority |
| Loop 39 reproducibility boundary | 7 qualification levels; 18 environment fields; 8 output classes; 6 comparison classes; 6 future cells; 20 fixtures; 4 stages; 28 gates; 38 refusals; 36 false authorization fields | planning research only; no matrix cell has run | Separates semantic identity, field-specific numerical compatibility, descriptive resources, same-team repeatability, supported-matrix compatibility, independent reproduction, and scientific replication |
| Loop 40 edge-package boundary | 7 qualification levels; 6 package layers; 4 unselected backends; 20 identity fields; 8 outputs; 6 comparisons; 24 fixtures; 4 stages; 30 gates; 40 refusals; 40 false authorization fields | planning research only; no backend, target, export, package, or inference exists | Separates graph export from host normalization/state/timestamps/decoder, total deployment cost from model bytes, simulator evidence from physical devices, and packaging from science |
| Loop 41 stream-to-token boundary | 6 integration layers; 7 clock views; 8 anomaly classes; 5 schedules; 5 resume cuts; 18 hash bindings; 28 fixtures; 4 stages; 32 gates; 42 refusals; 42 false authorization fields | planning research only; no source chunk, adapter, preprocessing output, NeuroToken runtime, stream, or latency result exists | Preserves source time, derived corrections, anomaly evidence, resume state, and provenance without calling replay scheduling capture-to-text latency |
| Loop 42 named-device boundary | OpenBCI Cyton base 8-channel USB-radio; Q0 only; 28 identity fields; 16 packet fields; 7 timing observables; 10 anomalies; 30 fixtures; 4 stages; 34 gates; 46 refusals; 45 false authorization fields | planning research only; no purchase, SDK, serial read, board connection, participant, recording, or device result exists | Makes a future local-device mechanics test exact while refusing to turn host timestamps, local files, connectivity, or eight channels into latency, privacy, EEG-quality, or text-decoding claims |
| Loop 43 independent-reproduction boundary | 7 qualification levels; 16 independence fields; 28 packet fields; 34 submission fields; 8 comparison classes; 12 discrepancy classes; 32 fixtures; 4 stages; 36 gates; 48 refusals; 48 false authorization fields | planning research only; no packet, oracle, outreach, contributor, submission, adjudication, archive, or release exists | Defines how one future external environment can reproduce a released target-free software artifact without inflating that result into scientific replication, neural advantage, or population generalization |
| Loop 44 claim-release matrix | 16 claims; 7 evidence levels; 5 model cards; 4 dataset cards; 14 gates; 8 risks; 0 tag/release/DOI operations | artifact-only review complete; engineering release held; scientific release parked | Makes every public claim traceable to cohort, task, split, comparator, uncertainty, resources, access, privacy, license, and evidence while preserving negative results |
| Current Loop 48 Stage B verification | 63 focused Stage B tests; complete dependency-light suite 887 tests with 149 expected skips; complete optional-neuro suite 934 tests with 3 expected skips | Authorization 8d17342, implementation 1d840e3, freeze 00215b1, and result closeout ad4410c passed both push and PR CI; closeout runs were 29464527230 / 29464529524 and added exactly 9 tests over the implementation baseline |
Makes one-shot access order, target isolation, freeze binding, exact operation counts, hypothesis rules, outcome routing, tamper checks, and the no-rerun boundary executable and reviewable |
| Current Loop 48 Stage C verification | 64 focused tests; 919 dependency-light tests with 156 expected skips; 966 optional-neuro tests with 3 expected skips | Research 9579be9, implementation 59b30a3, and correction 2836ecc passed push and PR CI before one execution; result is consumed and no rerun is open |
Makes synthetic selection, absolute-gate failure, replay, causal controls, resource accounting, zero protected access, and the parked disposition machine-checkable |
| Current Loop 53 verification | 68 focused closeout tests; final full suite 1,062 tests with 3 expected skips in 44.090 sec and 581,648,384-byte external peak RSS; baseline was 1,056 tests, 3 skips, 30.623 sec, and 568,688,640 bytes | Authorization 2a47bbc passed CI 29589212626 / 29589225113; implementation 8ec5b1b passed CI 29591387642 / 29591391286 before the single pass; workbook formula-error scan found 0 matches |
Adds exactly 6 aggregate-result tests while making identity, green-gate order, no-overwrite behavior, caps, opaque hashing, counters, private receipt binding, no-rerun status, and claim ceiling machine-checkable |
| Current WO9R result verification | 29 implementation tests, 5 public-freeze invariants, and 7 aggregate-result invariants; 72 real EDFs; 1,080 events; 144 fits; 216 frozen prediction sets; one 360-target score | Implementation 8242674 passed CI 31359548779; freeze 8cd45d7 passed CI 31360781199 before the one target delivery; result routed WO9R-R3 with zero post-target updates or reruns |
Makes the positive execution/imagery task-information result and the failed localization/confound conjunction independently checkable without publishing individual outputs |
| MARC-1 next-effect research | 2 selected licensed axes; 14-member generated ZIP; 2 modality profiles; 12 comparators; 24/24 adversarial refusals; 51 focused tests; 2,273 complete-suite tests; 0 payload/model/score operations | Exact implementation e35a587 passed CI 31505555044 before one generated closeout; MARC1G-R1 passed in 0.006589 sec at 23.5 MB peak RSS and is consumed |
Proves the bounded ZIP and multimodal firewall mechanics needed for the next experiment, while adding no human-neural or decoding evidence |
| MARC1-CD1 storage-safe archive qualification | 13.59 GB virtual ZIP; 280,249 generated bytes; 128 KiB trailer; 148,910-byte central directory; 18 entries; 32/32 refusals; 14/14 gates; 0 live requests | Exact implementation 211fd78 passed CI 31511626051 before one closeout; MARC1CDG-R1 passed in 0.006544 sec at 27.1 MB peak RSS and is consumed |
Validates exact range, redirect, EOCD/ZIP64, directory, privacy, replay, and resource mechanics without a whole download; live inventory and all neural claims remain unavailable |
| MARC1-CD1A decision routing | 12 decision invariants; 168 focused tests; 2,378 optional-neuro tests with 35 expected skips; 0 public requests | Request 950796d passed CI 31513578445; decision 624cc4e passed CI 31519016891 before wrapper work |
Authorized only the staged wrapper-then-one-audit sequence after two green milestones; added no archive-content or neural evidence |
| MARC1-CD1A live archive inventory | 13.59 GB virtual ZIP; 306,758 accepted metadata bytes; 1,227 entries; 1,025 files; 202 directories; 14/14 gates; 0 archive/member payload bytes | Exact wrapper 5dfa3c4 passed CI 31521510374 before one invocation; MARC1CD-R1 passed in 2.727 sec at 43,974,656-byte peak RSS and is consumed |
Adds a real, storage-safe map of the public archive without downloading it; member selection, neural data, models, scores, and scientific claims remain closed |
| MARC1-P1 generated pilot selector | 1,227 + 55 generated rows; 12 preregistered participants per axis; 72 Freewill bundles/288 members; 12 Wrist archives; 36/36 refusals; 15/15 gates; 0 real operations | Exact implementation 0c0a698 passed CI 31571668853 before the one closeout; MARC1PSG-R1 used 873,348 input and 182,564 output bytes in 0.227 sec at 32.4 MB reported RSS and is consumed |
Proves deterministic, private, size-independent pilot selection mechanics under an 8-GiB ceiling; adds no neural or thought-to-text evidence |
| MARC1-P1A live metadata attempt | 418,755 private metadata bytes read once; 1 Wrist response opened; 0 public-body or payload bytes; 0 selected participants; route MARC1PS-F03 |
Exact wrapper 702e613 passed CI 31578614616 before the sole attempt; it failed the explicit identity-encoding gate in 0.532 sec at 37.3 MB reported RSS and is consumed |
Proves one-shot fail-closed audit behavior; the cohort was not selected and no neural or language evidence was produced |
| MARC1-HT1 HTTP identity research | RFC 9110 Sections 8.4 and 12.5.3; 4 future acceptance cases; 20 future refusals; 17 false authorization flags; 0 real operations | Artifact-only standards review after green consumed result 8d9cae1; candidate policy hash ac1b98ee... |
Separates absent content coding from actual coding without inferring the unretained live header; implementation and real access remain closed |
| MARC1-HT1 generated recovery contract | 1,227 + 55 generated rows; 4 accepted forms; 20 refusals; 16 gates; 5 refusal routes; 0 real/network bytes | Green research f515b36 / CI 31580575669 precedes the frozen contract |
Allows only a new plan/qualify/inspect harness after contract CI; real metadata, payload, neural work, and claims remain closed |
| MARC1-HT1 generated recovery implementation | 923,052 generated input bytes; 4/4 accepted forms; 20/20 refusals; 16/16 gates; exact 12+12 cohort and split replay; 0 real/network bytes | Development MARC1HT-G1 passed in 0.109 sec at 32.7 MB external peak RSS; 29 new tests; registered closeout awaits implementation CI |
Proves the standards-aligned uncoded-response predicate and frozen selector compose deterministically; live-source compatibility and all neural/language claims remain untested |
| MARC1-HT1 registered generated closeout | 923,052 generated input bytes; 182,681 temporary output bytes; 4/4 forms; 20/20 refusals; 16/16 gates; 0 real/network bytes | Exact implementation b2cb48c passed CI 31583931303 before one 0.112-sec closeout at 33.1 MB external peak RSS; consumed with no rerun |
Confirms the repaired transport/selector/privacy stack end to end on fixtures; a new live attempt still needs a separate Tier C sequence and no scientific claim changed |
| MARC1-HT1A live-recovery request | One future 418,755-byte sealed-manifest read; one future Wrist body capped at 2 MiB; one new isolated root; 0 payload bytes; all current permissions false | Binds green result 5344d73 / CI 31584662864, the frozen selector, and the consumed MARC1PS-F03 boundary; requires its own green CI before any decision |
Proposes one additive wrapper and one metadata-only attempt on the same thought-to-text path; the packet itself performs no operation and establishes no scientific result |
| MARC1-HT1A packet-bound decision | Exact 76-byte maintainer message; one green packet; one future generated/mock wrapper; one future metadata-only attempt; 0 current data/model operations | Request 27f39ae passed CI 31586256906; decision records the fresh approval but is ineffective until its own CI is green |
Preserves thought-to-text as the objective without predeclaring an outcome or expanding the zero-payload metadata scope |
| MARC1-PG1 generated pagination lane | Development: 4/4 accepted cases, 41/41 refusals, 18/18 gates. Registered closeout: route MARC1PG-F07, 0 output bytes, 0 real/network bytes |
Exact implementation 2c98a2a passed CI 31593790492; the sole closeout then refused a symlink output parent in 0.17 sec at 30,064,640-byte external peak RSS and is consumed without retry |
Preserves a real process defect: output preflight happened after fixture construction. A new generated recovery must move it first; no live pagination or scientific result exists |
| MARC1-OP1 output-capability research | One 672-byte candidate policy; held parent descriptor; device/inode binding; ancestor no-follow checks; parent-relative create/write/cleanup; 19 required pre-capability refusals; 0 fixture/network/real operations | Green consumed result a4dcaea / CI 31594881048 precedes this artifact-only design |
Makes safe output authority the first future operation and refuses platforms that cannot enforce it; implementation and another generated run remain closed until their own green milestones |
| MARC1-OP1 generated recovery contract | 6 accepted cases; 32 refusals; 10 routes; 20 gates; one exact /private/tmp path probe; one conditional generated qualifier; 0 current operations |
Green research d02830b / CI 31595996923 precedes the frozen contract |
Requires capability acquisition before any repository/fixture work, bans the consumed qualifier, and preserves exact pagination/cohort identity; implementation remains closed until contract CI |
| MARC1-OP1 output-capability implementation | 1,019,776 generated input bytes; 184,173 temporary output bytes; 6/6 accepted cases; 32/32 refusals; 20/20 gates; exact cleanup; 0 real/network bytes | Green contract baade51 / CI 31597291352 preceded development MARC1OP-G1, which ran in 0.096 sec at 33.8 MB reported RSS; 36 new tests |
Proves generated pagination and selection can run only after held output authority and leave no artifact; the registered probe awaits implementation CI and no neural/language claim changed |
| MARC1-OP1 registered generated result | MARC1OP-P0 preflight then MARC1OP-G1; 1,019,776 generated input bytes; 184,173 temporary output bytes; exact cleanup; 0 live/network bytes |
Exact implementation fcedcc3 passed CI 31600085119 before the one 0.098-sec qualifier at 33.9 MB reported RSS; both invocations consumed |
Establishes the capability-first generated stack under registered controls; a live metadata request remains a separate Tier C gate and no scientific claim changed |
| MARC1-LM1 paginated live-metadata request | One future exact page=1&page_size=1000 GET; one body capped at 2 MiB; one 55-row target-free inventory; 0 payload bytes; all current permissions false |
Green capability result ca4679a / CI 31601329375 precedes the packet; 13 focused, 612 MARC, 2,751 base, and 2,822 optional tests pass locally |
Proposes one additive wrapper and one no-retry metadata check on the same thought-to-text path; the packet itself performs no operation and establishes no scientific result |
| MARC1-LM1 packet-bound decision | Exact 76-byte maintainer approval; one immutable green request; one conditional generated wrapper and one later metadata response; 0 decision-time data/model operations | Request 4d3eb19 passed CI 31603530015; decision 060a365 passed CI 31604608307 before implementation |
Preserves thought-to-text as the objective while binding only the registered metadata scope and refusing to predeclare a scientific outcome |
| MARC1-LM1 generated/mock implementation | 4/4 transport forms; 36/36 refusals; 20/20 gates; exact 55/45/10 inventory and frozen 12-subject split; 184,466 generated input bytes; 19,030 temporary output bytes | Corrected development MARC1LM-G1 ran in 0.0303 sec at 43,057,152-byte reported RSS; first push 8f67af2 failed only Linux temp-parent portability and performed zero real operations |
Adds a capability-first, target-firewalled, aggregate-safe one-response wrapper on the same path; generated metadata work is not neural, decoding, language, or thought-to-text evidence |
| MARC1-LM1 consumed live metadata | One 15,652-byte version-3 metadata body; strict JSON parse; MARC1LM-F04 at the frozen inventory validator; 0 selected subjects and 0 payload bytes |
Exact implementation f9a1ece passed CI 31611639130 before the sole request; 1.095 sec, 33,996,800-byte peak RSS, 4,207 output bytes; no retry |
Proves bounded live fail-closed behavior and invalidates use of the frozen inventory as a payload gate; it does not identify the changed predicate or add neural, language, or thought-to-text evidence |
| MARC1-SA1 source-aware attestation research | Five-field official public core; two optional MD5 extensions; 21 aggregate predicates; seven domain-separated identity hashes; 0 real operations | Green consumed result d859509 / CI 31612923903 anchors a Tier A design with 12 invariant tests |
Separates source schema, cohort identity, and later byte-level integrity so the next one-shot check can localize drift without weakening privacy or changing the scientific path |
| MARC1-SA1 generated-only contract | Six semantic fixture families; 21 predicates; seven identity domains; 52 refusals; 25 gates; exactly plan/qualify/inspect; 0 live or payload operations |
Research aa80503 passed CI 31614330447 before the strict versioned contract was frozen; 13 focused tests pass |
Freezes a source-aware attestor before implementation while keeping every live, neural, target, model, and claim boundary closed; this remains cohort-integrity work on the same thought-to-text path |
| MARC1-SA1 generated implementation | Six family routes; 52/52 refusals; 25/25 gates; 732,811 generated input bytes; 109,589 temporary output bytes; exact cleanup | Green contract 8f64ccb / CI 31616551270 preceded development MARC1SA-G1; exact implementation feb3b83 later passed CI 31619037335 |
Adds deterministic aggregate drift localization and optional-MD5 handling without a network or payload surface; no neural/language claim changed |
| MARC1-SA1 registered generated closeout | Six family routes; 21 predicates; seven identity domains; 52/52 refusals; 25/25 gates; 732,811 generated input and 109,589 temporary output bytes; exact cleanup | Exact implementation feb3b83 passed CI 31619037335 before the one 0.0534-sec closeout at 27,885,568-byte reported peak RSS; consumed with no rerun |
Confirms source-aware schema, optional checksum, aggregate drift, privacy, and resource mechanics compose on fixtures; live metadata and every neural/language claim remain closed |
| MARC1-SA1A live-metadata request | One future exact GET; one body capped at 2 MiB; source-aware R1-R4 routing; 0 payload bytes; all current permissions false | Green generated result 094b6cb / CI 31620515340 anchors the immutable packet; 14 request invariants pass |
Proposes one additive wrapper and one metadata-only attempt after a fresh packet-bound decision; the packet performs no operation and preserves the same thought-to-text path |
| MARC1-SA1A packet-bound decision | Exact 31-byte maintainer instruction; one immutable green request; one conditional generated/mock wrapper and one later metadata response; 0 decision-time data/model operations | Request b077550 passed CI 31621794066; this decision remains ineffective until its own commit passes both CI jobs |
Authorizes only the identified metadata sequence; selective acquisition, neural experiments, scoring, replication, and language work remain separately gated |
| MARC1-SA1A source-aware wrapper | Six source-schema families; three HTTP framing forms; 31 refusals; 20 gates; 84,422 generated response bytes; 24,064 transient output bytes; 0 development-time real requests or payload bytes | Decision ef9ab91 passed CI 31670457497 before development MARC1SAL-G1; exact wrapper 74aff21 then passed CI 31672761644 before the sole request |
Adds a capability-first, privacy-separated one-response implementation that can retain an eligible cohort or block on localized drift; generated metadata is not neural or language evidence |
| MARC1-SA1A consumed source-aware metadata | One bounded metadata response; wrapper route MARC1SAL-R2; 0 selected subjects; 0 archive requests; 0 payload bytes; 23,112 retained bytes |
Exact wrapper 74aff21 passed both CI jobs before the one 0.697-sec request at 33,439,744-byte peak RSS; lane consumed with no retry |
The source-aware gate correctly blocked the frozen Wrist cohort before payload. R3 versus R4 details remain unavailable; this is an engineering stop, not neural or thought-to-text evidence |
| Evaluation | Neural result | No-signal result | Honest decision |
|---|---|---|---|
| S21 session-1 strict five-row sentence test | 163 character edits | 164 character edits | Near-null difference; paired interval spans benefit and harm |
| S21 session-2 same-person transfer | CER 0.9179 |
CER 0.7755 |
Neural model is materially worse; session is consumed |
| S7 EEG within-session key events | exact accuracy 0.91% |
exact accuracy 12.27% |
Neural template is materially worse; EEG bridge is mechanics only |
| S21 session-1 reserved six-sentence gate | macro CER 0.938177 |
macro CER 0.751235 |
Fixed causal candidate is worse by 0.186942; Loops 26/31/33 are consumed and parked |
| S21 source-train 11-row diagnostic | macro CER 0.953566 |
macro CER 0.822045 |
Post-outcome Stage B supports stable nonseparability for this model family; these historically used rows are not fresh validation |
| PhysioNet S004-S015 held-out execution | balanced accuracy 0.680975; 123/180; 9/12 participants above chance; p=0.002930 |
balanced accuracy 0.490722 |
Prespecified low-frequency task-information confirmation passed, but localization and confound gates failed |
| PhysioNet S004-S015 held-out imagery | balanced accuracy 0.728014; 131/180; 12/12 participants above chance; p=0.000244 |
balanced accuracy 0.507411 |
Task-mode robustness passed; this remains cue/ocular-compatible and is not brain-specific proof |
Scientific headline: the real MEG and EEG evaluations run so far do not show a reliable neural advantage. That negative result is preserved beside the engineering wins, not hidden behind synthetic accuracy.
| Gate | Runtime | Peak RSS | Persistent output |
|---|---|---|---|
| Dependency-light Python unittest run | 1.80 sec wall | 107,659,264 bytes | 637 tests with 124 expected optional skips; temporary output only |
| RW1 metadata intake roundtrip | 0.001659 sec | 21,643,264 bytes | 11,545 bytes |
| RW2 bounded FIF quality roundtrip | 3.839168 sec | 150,749,184 bytes | 76,592 bytes |
| RW3 contract/request invariant suite | 0.040 sec | 20,529,152 bytes | no generated payload |
| Loop 24 authorization plus frozen-boundary suite | 0.210 sec | 21,397,504 bytes | no generated payload |
| Loop 25 v1 amendment plus immutable-v0 request suite | 0.120 sec | 22,560,768 bytes | no generated payload |
| Loop 25 registered static plus complete gates | 5.542175 sec internal | 136,806,400 bytes max | 788,967 generated bytes; 24/24 items, all caps and 23 counters exact |
| Loop 26 research plus roadmap/Loop 25 boundary suite | 0.140 sec wall max | 22,986,752 bytes max | no generated payload |
| Loop 27 pinned metadata selector | 3.100 sec wall | 63,766,528 bytes | zero downloaded payload bytes |
| Loop 24-36 focused boundary suite | 3.74 sec wall | 240,041,984 bytes | 248 tests; no generated experiment payload |
| Loop 36 plus roadmap invariants | 0.07 sec wall | 20,365,312 bytes | 26 tests; no fixture, real header, protected cache, signal, transform, rereference, interpolation, target, model, training, device, or hardware operation |
| Loop 24-37 planning boundary suite | 0.20 sec wall | 50,167,808 bytes | 226 tests; no generated experiment payload |
| Loop 37 plus roadmap invariants | 0.09 sec wall | 34,865,152 bytes | 26 tests; no fixture, exporter, derivative tree, validator, protected payload, raw copy, release, model, training, device, or hardware operation |
| Loop 24-38 planning boundary suite | 0.16 sec wall | 58,589,184 bytes | 240 tests; no generated experiment payload |
| Loop 38 plus roadmap invariants | 0.07 sec wall | 34,390,016 bytes | 23 tests; no fixture, scanner, deletion, protected-root scan, identity attack, history rewrite, release, model, training, device, or hardware operation |
| Loop 24-39 planning boundary suite | 0.25 sec wall | 66,093,056 bytes | 256 tests; no generated experiment payload |
| Loop 39 plus roadmap invariants | 0.09 sec wall | 34,930,688 bytes | 25 tests; no fixture, environment manifest, matrix job, dependency lock, package build, protected payload, model, training, independent reproducer, edge, device, or hardware operation |
| Loop 24-40 planning boundary suite | 1.28 sec wall | 74,825,728 bytes | 269 tests; no generated experiment payload |
| Loop 40 plus roadmap invariants | 1.10 sec wall | 42,139,648 bytes | 22 tests; zero fixtures, installs, exports, packages, inference, profiler, simulator, device, or hardware operations |
| Loop 24-42 planning boundary suite | 1.99 sec wall | 88,997,888 bytes | 263 tests; zero generated experiment, protected-data, model, stream, participant, device, or hardware operations |
| Loop 42 plus roadmap invariants | 0.043 sec internal | not separately measured | 24 tests; zero SDK imports, fixtures, playback, serial reads, discovery, connections, recordings, model runs, or latency measurements |
| Loop 24-43 planning boundary suite | 1.33 sec wall | 91,504,640 bytes | 308 tests; no generated experiment payload, model, training, stream, device, or hardware operation |
| Loop 43 plus roadmap invariants | 0.049 sec internal | not separately measured | 24 tests; 48 false authorizations, 20 false roadmap executions, and the 136/11-file validator incident machine-recorded |
| Loop 48 contract plus roadmap invariants | 0.009 sec internal | not separately measured | 25 tests; 4 exact aggregate artifacts, 8 ordered classes, 17 unavailable root-cause fields, 30 refusals, and every execution authorization false |
| Loop 48 hypothesis-discrimination invariants | 0.004 sec internal | not separately measured | 10 tests; 6 unresolved hypotheses, 1 orthogonal shortcut threat, 5 evidence levels, 6 sequential stages, 5 public sources, 15 false authorizations, and zero protected/model operations |
| Loop 48 artifact-only Stage A | 0.016568875 sec internal / 0.38 sec wall | 23,429,120 bytes internal / 23,560,192 bytes external | 155,545 input bytes; 10,643-byte aggregate report; F5; 0 model, training, target, protected, network, stream, device, or hardware operations |
| Loop 48 train-only Stage B | 190.140486 sec through prediction freeze; 0.112110 sec scoring | 483,540,992 bytes maximum | 20 fits; 4,800 steps; 35 inferences; 41 frozen sets; 9,623,773 generated bytes; one 10,632,576-byte cache hash pass; one post-freeze target delivery; no rerun |
| Loop 48 synthetic Stage C | 7.829308 sec internal / 8.31 sec wall | 310,509,568 bytes internal / 320,405,504 bytes external | 4 fits; 1,680 steps; 8 inferences; 83,132 generated bytes; 0 raw, real-cache, real-signal, real-target, download, S24/S25, stream, device, or hardware operations; no rerun |
| Loop 49 metadata-only candidate pass | 3.51 sec wall | 62,685,184 bytes | 396 pinned metadata rows; exact 1,048,579,727-byte future S24 bundle; 0 payload downloads, local candidate stats, real reads, targets, derivatives, models, training, predictions, or scores |
| Loop 44 plus Loops 45-64 invariants | 0.06 sec wall | 18,546,688 bytes | 24 tests; 16 claim cards, 20 false roadmap execution flags, and 9 false global authorizations |
| Loop 28 public-source research | external interactive runtime/RSS unavailable | unavailable by tool contract | 10 web operations, 1 GitHub metadata call, zero code/data payload bytes |
| Loop 29 public-source research | external interactive runtime/RSS unavailable | unavailable by tool contract | 14 public web operations, zero protected data/model/device operations, zero downloaded payload bytes |
| Loop 30 public-source research | external interactive runtime/RSS unavailable | unavailable by tool contract | 10 public web operations, zero trace/server/browser/protected-data/model/stream operations, zero downloaded payload bytes |
| Loop 31 public-source research | external interactive runtime/RSS unavailable | unavailable by tool contract | 16 public network operations including 8 GitHub API requests; zero protected-data/model/training/validation/LLM operations and zero downloaded data/model bytes |
| Loop 32 public-source research | external interactive runtime/RSS unavailable | unavailable by tool contract | 6 public network operations including 2 pinned GitHub source reads; zero participant/cache/signal/target/model/adapter/training/evaluation operations |
| Loop 33 public-source research | external interactive runtime/RSS unavailable | unavailable by tool contract | 6 public web operations; zero protected cache/signal/target/model/training/scoring/acquisition/device operations |
| Loop 34 public-source research | external interactive runtime/RSS unavailable | unavailable by tool contract | 5 public web operations; zero fixture/protected-data/target/model/confidence-fit/scoring/product-confidence/device operations |
| Loop 35 public-source research | external interactive runtime/RSS unavailable | unavailable by tool contract | 6 public web operations; zero protected-data/target/model/training/acquisition/S20/S25/stream/device/hardware operations |
| Loop 36 public-source research | external interactive runtime/RSS unavailable | unavailable by tool contract | 3 high-level public web operations; zero protected download bytes, real headers, signal/cache/target reads, fixtures, transforms, model/training runs, S20/S25 operations, streams, devices, or hardware operations |
| Loop 37 public-source research | external interactive runtime/RSS unavailable | unavailable by tool contract | 7 high-level public web operations including 2 official GitHub repository reads; zero protected downloads, payload/header/cache/signal/target reads, fixtures, derivative bytes, raw copies, validator/model/training runs, releases, devices, or hardware operations |
| Loop 38 public-source research | external interactive runtime/RSS unavailable | unavailable by tool contract | 6 high-level public web operations and 8 official/primary page opens; zero protected reads, fixtures, scanners, deletions, identity attacks, history rewrites, models, training runs, releases, uploads, devices, or hardware operations |
| Loop 39 public-source research | external interactive runtime/RSS unavailable | unavailable by tool contract | 6 high-level public web operations and 8 official/primary page opens; zero fixtures, manifests, matrix jobs, installs, lockfiles, package builds, protected reads, models, training runs, edge, stream, device, or hardware operations |
| Loop 40 public-source research | external interactive runtime/RSS unavailable | unavailable by tool contract | 3 high-level web operations and 12 official/primary page opens; zero fixtures, installs, exports, packages, inference, profiler, memory-planner, delegate, simulator, app, protected-data, model, training, device, or hardware operations |
| Loop 42 public-source research | external interactive runtime/RSS unavailable | unavailable by tool contract | 4 high-level web operations, 12 search queries, and 9 official page opens; zero SDK, fixture, device, participant, signal, target, model, training, decoder, stream, network/cloud, or hardware operations |
| Loop 43 public-source research | external interactive runtime/RSS unavailable | unavailable by tool contract | 5 high-level web operations, 8 search queries, 10 official/primary page opens, and 4 GitHub metadata operations; local validation later parsed 136 cache JSON files including 11 known consumed session-2 files, with zero tuning/scoring/model use |
| Loop 24 registered selection | 65.154951 sec internal | 222,248,960 bytes max worker | 262,822 bytes fixture plus output |
| Current Loop 25 full unittest runner | 26.17 sec wall | 618,528,768 bytes | 684 tests with 3 expected skips; temporary output only |
Proof labels are deliberately narrow:
- real-data validated means the named interface or identity claim ran on the exact local recording described;
- fixture-backed means deterministic generated files exercised the contract;
- synthetic mechanism only means the result cannot be transferred to brain data, people, or devices;
- review-ready, not authorized means the bounded protocol and decision packet exist, but their planned runtime does not;
- preregistered, no runtime means candidates, data independence, metrics, thresholds, and refusals are frozen before any candidate implementation or benchmark execution;
- authorized, no runtime means a separate hash-bound decision permits the exact frozen work after its commit is pushed, but no fixture, candidate, or measurement result exists yet;
- parked means a registered primary gate failed and the project did not tune past it.
Detailed evidence is linked from the documentation map, including the RW2 closeout.
Read this before interpreting any number in the repository.
-
Base package: dependency-free CLI, metrics, schemas, manifests, split audits, and report validation run without MNE, Torch, Zarr, or Hugging Face.
-
Real S21 MEG alignment: all 66 performed session-1 trials are reconciled to target/response/timing provenance under the validated S21 parser.
-
Strict split mechanics: session 1 has a deterministic 55/6/5 train/validation/test protocol with train-only preprocessing.
-
Independent same-person session mechanics: session 2 has 63 performed trials, preserves three empty MAT slots, and is bound to frozen session-1 train statistics.
-
Real EEG bridge mechanics: one S7 BrainVision recording and matching MAT log produce 2,197 lazily read key-event windows shaped
61 x 25. -
NeuroTokenCache v0: a strict modality-aware continuous embedding cache preserves masks, lengths, timestamps, source identities, geometry status, splits, configuration, hashes, causality, context, resources, and warnings.
-
Causal producer mechanics: synthetic replay proves schedule-invariant causal frame production with zero right context and bounded state.
-
Metadata-only neurodata intake: BrainVision, EDF/EDF+, BDF, continuous EEGLAB external-FDT, FIF, and BIDS bundles can be recognized and reported at compatibility level 0 without reading binary samples or event content.
-
Synthetic signal-quality adapters: RW2 exercises 38 readable fixtures and two frozen refusal fixtures across those six format families using bounded optional MNE readers, strict source binding, descriptive metrics, privacy redaction, and before/after no-mutation checks.
-
RW3 protocol registration: a versioned, machine-checked contract freezes source identity, raw/corrected/arrival timestamps, gaps, duplicates, reordering, reconnects, state, five schedules, 18 future fixture families, 30 refusal IDs, and four separately gated adapter stages. No source-chunk or adapter runtime exists yet.
-
RW3 Stage A decision packet: a hash-bound request now defines 90 future schedule-by-fixture cases, all 30 deterministic refusals, one-thread resource caps, and the exact authorization sequence. The request says
authorized_now: false; preparing it did not authorize implementation. -
Loop 24 precision/runtime execution: the frozen target-free gate ran all 12 balanced selection rounds over 990 frames. Float16 preserved every exact decoder behavior and tolerance but was slower; QNNPACK qint8 exposed the required operator and halved payload but failed behavior/numerical gates and was much slower. No candidate earned qualification, seed 2402 remained physically unopened, and the final gate parked at
65.154951seconds versus its 60-second cap. Real data, targets, training, energy measurement, RW3, devices, and hardware remained outside Loop 24. -
Loop 25 causal-preprocessing result: the original registration at
a36d97bremains immutable history; v1 amendmentb6b92d8, authorization commit1e7296a, and implementation commit439f151preserve the complete audit trail. The static gate passed before either partition opened; seed 2501 development then passed and froze, and seed 2502 qualification passed once unchanged. Across 24 target-free items, all 168 schedule, 240 resume, and 72 future-mutation checks passed with zero protected reads. Generated output was 788,967 bytes and maximum RSS was 136,806,400 bytes. Loop 25 is complete, consumed, and not authorized for rerun. -
Loop 26/31/33 shared validation: green commit
881145dfreezes the left-padded 2,908-parameter candidate, 2,884-parameter comparator, 21 fits, 24 target-blind model inferences, six train-only priors, 31 prediction sets, ten encoder conditions, six nested data sizes, and one six-target scoring delivery after a green prediction freeze. The exact request was separately authorized at green commit1c0e52c; implementation91409bd, static-ledger correction4015677, and prediction-freeze commit54bdca9were pushed and remotely green before the targets opened once. The candidate macro CER was0.938177versus0.751235for the train-only prior, a-0.186942margin. The primary, attribution-conjunction, and scaling gates failed. The event is consumed, all three loops are parked, and no rerun or post-target tuning is authorized. Seedocs/LOOP_26_SHARED_VALIDATION_RESULT.md. -
Loop 48 Stage B failure discrimination: one exact train-only execution split the historically used 55 source-train rows into 44 fit and 11 target-withheld check rows, froze 41 prediction sets at remotely green commit
00215b1, then scored the same 11 targets once. The primary candidate reached macro CER0.953566versus prior0.822045. All six full-size causal and linear fits were finite and stable but lost their prior rule, supportingH4stable nonseparability. None of four fixed timing offsets improved all three seeds, providing evidence against registeredH3. The complete signal-control conjunction failed, so no neural advantage or sensor-signal dependence is established. RouteL50-R05parks S24 acquisition for this model family. Stage B is consumed with no rerun. -
Loop 27 planning research: pinned official metadata selects S25 session 2 block 2 as the smallest eligible clean MEG candidate after excluding observed S21 identity, consumed S7, and the official S23 metallic-implant case. Exact paths, bytes, LFS hashes, identity, license, task, unavailable fields, and 18 false authorization flags are machine checked. No candidate payload opened.
-
Loop 28 planning research: the future S25 question is T2 strict unseen- person zero-shot, not calibrated transfer. The frozen recommendation requires zero target-person fit, at least 48 final rows, at least 0.05 macro sentence- CER improvement over the source-train-only prior, 65,535 deterministic paired assignments plus observed, and strict wins over three signal corruptions. All 21 authorization flags remain false and the experiment is
Not Started. -
Loop 29 planning research: the portability map keeps cryogenic MEG, OPM-MEG, scalp EEG, and peripheral inputs noninterchangeable. Scalp EEG is the immediate local-first research lane; OPM-MEG remains a specialist partner/lab lane. The exact S20 and S25 future bundles total 1,106,030,247 bytes inside the user's 5-10 GB storage envelope, but the envelope is not download permission. All 24 authorization flags remain false, no device is selected, and the experiment is
Not Started. -
Loop 53 fresh EEG acquisition: authorization
2a47bbcand implementation8ec5b1bwere separately green before the one registered invocation acquired and opaque-verified all 4 files and96,090,264bytes. All 10 gates passed in3.629499seconds at 63,225,856-byte peak RSS. The gate is consumed with no rerun; header, marker, signal, MAT, target, cache, split, model, training, inference, scoring, and device counters all remain zero. -
Loop 54 EEG qualification research: planning commit
aec440afreezes four ordered future stages, five sensitivity classes, 22 acceptance gates, 30 refusal IDs, a 48-unique-trial floor, all-channel preservation, and a 32 MiB public-output ceiling. VMRK descriptions and MAT behavior/target fields are target-bearing, MNE is forbidden from the VHDR-only stage, and exact Loop 55 split counts remain intentionally unfrozen until the target-blind usable-trial count exists. Loop 53 has completed cleanly, but no Loop 54 real stage or scientific result is authorized. Documentation-sync commitb6785d7passed push CI29471589279and PR #32 CI29471598364, with Base Python and Optional Neuro Readers green in both workflows. -
Loop 54-A strict VHDR preregistration: registration commit
c114623freezes one exact 11,705-byte S20 VHDR, a base-Python-only parser, inert sibling basenames, 18 acceptance gates, 22 refusals, one content open, and one registered execution under 30-second, 256 MiB RSS, and 1 MiB output limits. Contract preparation performed zero S20 path stats and zero header, marker, signal, MAT, target, model, or network reads. Exact Tier C authorization remains pending. Exact-commit CI run31127199848was retried: the neuro-reader job passed, while Base Python selected Ruff0.16.2from a floating historical requirement and stopped on 400 later lint findings. The three frozen registration artifacts remain byte-identical at pinned commit2232993, whose CI31132586790passed both jobs, and an exact-tree Ruff0.15.20replay passed 1,095 tests with three skips. The additive recovery record preserves that distinction. The recovery-bound v1 packet indocs/LOOP_54_STAGE_A_RECOVERY_AUTHORIZATION_PACKET.mdand machine request inregistries/loop54_stage_a_recovery_authorization_request.v1.jsonbind the immutable registration, green pinned anchor, green recovery record, exact resource envelope, and two-step green evidence order. Every authorization flag remains false in those immutable snapshots. Request commit19813a8passed CI31283297030, and the exact Tier C sentence is now preserved indocs/LOOP_54_STAGE_A_RECOVERY_AUTHORIZATION_DECISION.mdand its machine decision. Decision commit2177b36passed CI31286428489, including Base Python job93176025548and Optional Neuro Readers job93176025560, before parser work began. The dependency-free implementation validates strict codepages, sections, inert sibling basenames, ordered channels, decimal sampling, no-follow source identity, bounded exclusive output, and all 22 refusal classes on generated synthetic fixtures. No generated fixture was retained. Exact implementationb486fdfthen passed CI31287819503before the one execution. It opened and read the exact 11,705-byte VHDR once; source size, Git-blob identity, and strict decoding passed, but the frozen format preamble gate failed atF11. The raw first line was not published, sibling and protected counters stayed zero, output bytes stayed zero, L54-Q2 did not pass, and no rerun or Loop 54-B/C route is open. -
Local EEG tooling audit: implementation commit
e1de855passed exact-SHA push CI31277731869before one zero-network inventory. NumPy2.5.0and SciPy1.18.0expose the bounded array/signal core; MNE1.12.1exposes its BrainVision reader and ICA, while CSP is incomplete and scikit-learn, pyRiemann, MOABB, and Braindecode are absent. The run finished in14.52799025seconds at173,211,648-byte maximum child RSS and wrote 9,416 bytes. All real/protected, raw-signal, target, model, training, inference, scoring, network, provider, and hardware counters are zero. No broad install follows; the next work order is a NumPy/SciPy synthetic physiology fixture pack. Its fixture-only Tier B contract freezes seed5503, 96 paired items, eight factor families, a 48/32/16 split, eight deterministic mutations, and a 4 MiB cap. Contract commit9238fd7and implementation commitad361c8were remotely green before one measured closeout. All 18 gates passed in1.20seconds at118,177,792-byte peak RSS with 584,308 output bytes. The generated NPZ and sidecar were removed, and every real-data, target, model, training, inference, scoring, network, provider, and hardware counter was zero. Work order 4 now freezes three unexecuted adapter plans: low-frequency shrinkage LDA, causal CSP-LDA, and Riemannian MDM. No winner is selected, no optional package is installed or imported, and twelve leakage mutations must fail closed before any future adapter execution. Exact implementationeefb7b0passed CI31280581308before one measured symbolic roundtrip. All 18 gates passed in0.12seconds at22,822,912-byte peak RSS with a 27,335-byte plan that was removed. This qualifies the interface and leakage guards only; no adapter was selected, imported, fitted, inferred, or scored. Work order 5 now freezes synthetic contact-mask, channel-noise, and missing-channel semantics: 48 seed-5505 items, 16 generic bilateral channels, six separate masks, a fixed four-per-side target-blind policy, and 16 fail-closed mutations. It is a post-acquisition interface, not physical switching, a consumer-earbud claim, hardware work, or real data. Contract commitc6e216fpassed CI31281290300before a lazy-NumPy implementation added deterministic NPZ/sidecar creation, strict mask and provenance hashes, metadata-only inspection, resource guards, and two CLI commands. Exact implementation76ccc63passed CI31282344300before one measured synthetic roundtrip. All 18 gates passed in 0.40 seconds at 55,394,304-byte peak RSS with 938,874 generated bytes; both temporary files were removed. Work order 5 is complete. This is interface evidence only, not ear-EEG or decoding evidence. -
Loop 55 EEG neural-effect research: planning commit
f3158c7freezes two ordered causal endpoints from the same future final trials: performed-hand error and 29-class performed-key keypress-aligned CER. It makes performed action primary, keeps intended text secondary, and treats[-200,+300] msas a noncausal diagnostic only. A future execution needs at least 48 Loop 54- qualified trials, a grouped split, one<=10,000-parameter family, at most 12 fits, twelve matched conditions, exact trial-level tests, and a remotely green hash-only prediction freeze before one final target delivery. Planning currently passes 24 focused roadmap/contract tests plus 9 public-status subtests, and the full local suite passes 1007 tests with 3 expected skips. Documentation-sync commit8efcb17passed push CI29473032843and PR #33 CI29473045583, with Base Python and Optional Neuro Readers green in both. The experiment remainsNot Startedand every S20, split, target, model, training, inference, and scoring permission is false. -
Loop 55 bounded AI research guard: policy commit
8855faeand implementation commitbd52cceadd a strict synthetic proposal schema, canonical SHA-256 identity, three CLI commands, one 1,771-byte fixture, and adversarial checks for target leakage, noncausal context, language models, pretrained weights, protected observation scopes, unknown fields, Boolean counter tricks, and output/resource expansion. The guard makes no network or AI-service call and executes no proposal. The future real agent phase remains Loop 54 dependent and needs an exact preregistration plus separate Tier C authorization. Historical-hash repairf50be96passed push CI29621564301; the complete local suite passes 1,087 tests with 3 expected skips. -
Open EEG R&D strategy refresh: current EEG-FM-Compass, ST-EEGFormer, preprocessing, motor-physiology, and official tool evidence supports keeping the specialist-first route. A prospective public positive control binds only S001-S003 PhysioNet motor-execution runs 3/7/11, nine EDF files and 23,248,224 public-metadata bytes under a future 32 MiB network cap. It would qualify one classical family before S20, then pair that family with a fixed causal motor-physiology assay and the compact model. No public payload, protected content, model, checkpoint, target, or pretrained weight opened; the strategy is not an execution contract.
-
PhysioNet motor acquisition implementation: registration
2a7b418and authorization decision00b91edwere remotely green before a separate standard-library executor was built.neurodecode physionet-motor-acquiredefaults to a no-stat, no-network plan. Its gated mode allowlists three metadata documents and nine EDF HEADs, refuses redirects and retries, streams only the nine exact S001-S003 runs 03/07/11 files, hashes each local file exactly once without parsing it, promotes only the complete directory, and writes bounded private receipts. Twenty-three adversarial tests use only generated invalid-UTF-8 bytes and mocked responses; the implementation suite passed 1,448 tests with 3 expected skips and 493 subtests. Exact implementation92760cethen passed both CI jobs before the one registered invocation. All 12 acquisition gates passed: nine requests transferred exactly 23,248,224 EDF bytes, every one-pass local SHA-256 matched, runtime was 50.682373 seconds, peak RSS was 55,181,312 bytes, and peak incremental disk was 28,327,635 bytes. Every header, annotation, event, signal, target, channel, split, model, training, inference, scoring, retry, rerun, and work-order-9 counter stayed zero. This is an acquisition-integrity result, not an EEG or decoding result. Work order 8 is complete and consumed; the Git-ignored payload and private receipts must not be published or reopened. The later 10 GB allowance remains future headroom. Work order 9 later consumed its own separately gated target-blind execution without adding data. The post-result suite passes 1,455 tests with the same 3 expected skips and 493 subtests. -
Public EEG positive-control result: work order 9 is no longer a generic "try a classifier" idea. Its prospective contract reuses only the nine acquired EDFs and requires three evidence axes to pass together: held-out run-11 prediction, motor-compatible central mu/beta physiology, and fixed confound/leakage controls. Runs 03/07 alone may select between four-component CSP plus shrinkage LDA and regularized Riemannian MDM. All 12 primary/control prediction sets must freeze in a hash-only commit that is pushed and remotely green before the isolated scorer receives the same 45 run-11 targets once. The primary gate requires at least 30/45 correct, pooled balanced accuracy at least 0.65, macro-participant balanced accuracy at least 0.60, a one-sided fixed-seed permutation p-value at most 0.05, and a win over the train-only no-signal prior. Pre-cue, timing-only, label- deranged, trial-displaced, channel-deranged, hemisphere-swapped, central, and frontal/occipital proxy results prevent an accuracy-only claim. Even a complete pass is only a three-person motor-task EEG pilot; it is not typing, language, thought reading, unseen-person generalization, or brain-specific proof. Registration authorizes no EDF access or model operation. Read the primary-source rationale and the preregistration. Registration
3c00557passed both jobs in CI31346882592. A separate exact Tier C packet binds that green snapshot. Requestc62b10athen passed Base Python job93331241434and Optional Neuro Readers job93331241411in CI31347209691, after which the maintainer supplied the exact registered sentence. Authorization-only commitda9399cpassed both required jobs in CI31348287824before implementation. The new dry-run-first CLI, sequential MNE reader, exact 90/45 participant-run split, target-firewalled derivatives, causal filters, fixed CSP-LDA/Riemannian families, 12 prediction/control sets, per-condition hashes, and isolated aggregate scorer are now qualified on generated arrays. The final fixture used nine runs and 135 events, made 33 fits and 45 target-blind inferences, froze 12 sets, and passed in 8.961233 seconds at 327,647,232-byte peak RSS with 20,825,424 generated bytes. Real data, real target, and network reads were zero, and the fixture output was removed. Its syntheticWO9-V2route has no claim value. Read the implementation record. Exact implementation52b9b15then passed both jobs in CI31351728650before the one real target-blind execution. All nine EDF hashes and semantic parses passed; 135 events produced 90 fit rows and 45 target-free final signal rows. CSP-LDA was selected from runs 03/07, 33 fits and 45 target- blind inferences produced all 12 aggregate-hashed prediction sets, and the model stage stopped with zero final-target deliveries or scores. Runtime was 3.054760 seconds, peak RSS was 460,734,464 bytes, private output was 20,852,059 bytes, and network/retry/rerun counters were zero. Read the aggregate freeze record. Freeze01eeff6passed both jobs in CI31352250838before the same 45 targets opened once. The selected 8-30 Hz primary reached 27/45, 0.604 balanced accuracy, andp=0.137; it beat the 0.500 no-signal prior but failed the frozen primary gate, so the registered verdict isWO9-V1. The prespecified 0.5-4 Hz comparator delivered the strongest real result: 36/45, 0.800 balanced accuracy, 3/3 participants above chance, andp=0.000183on held-out run 11. That is genuine task-information evidence, but it is not retrospectively promoted to the primary result. Motor-compatible physiology was directionally negative in 2/3 participants but nonsignificant (p=0.108), and central sensors did not beat the frontal/occipital proxy. The correct conclusion is a strong, compact low-frequency lead that now deserves independent replication and confound localization, not proof of brain-specific motor decoding. Read the full result and condition breakdown. Work order 9 is complete and consumed with no rerun. -
WO9R low-frequency cohort-confirmation result: the strongest WO9 lead survived a prospective test in twelve untouched participants. The fixed
0.5-4 Hzwhole-head shrinkage-LDA recipe was trained within participant on runs 03/07 or 04/08, frozen across 216 participant-condition prediction sets, and scored once on held-out execution run 11 and imagery run 12. Combined freeze8cd45d7passed both jobs in CI31360781199before the 360 targets opened. Execution passed all H1 gates at 123/180, pooled balanced accuracy 0.680975, macro-participant balanced accuracy 0.682292, 9/12 participants above chance, andp=0.002930. Imagery passed all H2 gates at 131/180, pooled 0.728014, macro 0.728423, 12/12 above chance, andp=0.000244. Execution-to-imagery and imagery-to-execution transfer were also positive at pooled balanced accuracies 0.728261 and 0.695077. This is the project's clearest preregistered multi-person EEG task-information result so far.The maximum claim gate still failed. Central sensorimotor balanced accuracy was 0.647575, below the frontal proxy's 0.671821; only 5/12 participants followed the registered physiology direction; and the early cue window reached 0.762865, stronger than the primary execution window. Frontal and frontal-asymmetry controls also exceeded their ceilings. The frozen router therefore returned
WO9R-R3: robust task information across execution and imagery, without motor-compatible localization. The result does not establish brain-specific origin, unseen-person generalization, typing, language or thought decoding, real-time operation, portable hardware, or clinical utility. Read the full aggregate result and control breakdown. WO9R is complete and consumed with no rerun or post-target tuning. -
IACKD-1 Cue-to-Action Reversal, consumed at its reader gate: WO9R's strongest unresolved question is now a direct prospective test rather than another classifier comparison. The public CC0 OpenNeuro
ds006840release provides 15 participants, 32-channel 1,024 Hz EEG, raw HEOG/VEOG, synchronized Leap Motion hand trajectories, and congruent/incongruent visuomotor mappings. The frozen design fits the exact compact0.5-4 Hzshrinkage-LDA family only on earlier congruent trials, then freezes one held-out incongruent run per participant and moving hand. The isolated scorer applies actual hand direction and the opposite visual target direction to the same predictions. That cleanly distinguishes an action-following representation from a cue-following one.The metadata-only inventory binds 1,340 raw-source objects totaling exactly 7,249,113,684 bytes, under the approved 10 GiB ceiling, while excluding published MATLAB derivatives, demographics, and scan tables. The contract keeps one CPU thread, no dependency installation, a 300-fit ceiling, exactly 420 prediction sets, a 30 ms target-blind motion guard, direct EOG and timing controls, one hash-only prediction freeze, and one combined target delivery. Exact implementation
f5c36bapassed both jobs in CI31409141349before real access. The one acquisition then passed: 1,340 objects, exactly 7,249,113,684 bytes, 1,340 streaming SHA-256 passes, zero content parses, 679.749484 seconds, and 126,205,952-byte peak RSS. The one analysis completed a second full object-hash pass, then failed closed on its first lazy BrainVision parse at registered refusalIACKD-F10because the observed channel inventory did not satisfy the frozen combined32+4gate. The actual channel count and names were not retained, so the result does not guess which predicate failed. No signal sample, channels TSV, geometry, event, ball/Leap stream, target, derivative, fit, inference, prediction, freeze, or score followed. This is an integrity-gate result, not a null neural result. IACKD-1 is consumed and parked with no rerun; the private bundle remains isolated. Read the primary-source research, frozen preregistration, implementation record, and aggregate closeout. -
Completed engineering gate, IACKD-H1 Header Inventory Audit: the published article supports a 32-channel cap and separately names M1, M2, HEOG, and VEOG, but it never establishes an exact 36-channel BrainVision invariant. The authors' pinned public code also uses two different presence-based deletion lists: one includes M1/M2/HEOG/VEOG/TRIGGER, while the other uses HEO/VEO/HEOG/VEOG/TRIGGER. Those are testable explanations, not observed answers. The new prospective contract audits all 128 VHDR headers and only 161,792 bytes in canonical order, emits aggregate signature hashes and seven public-code alias flags, and forbids the retained 7.249 GB bundle, siblings, samples, events, trajectories, targets, models, and scores. Registration
0e52278passed both jobs in CI31412667060before Tier B implementation. The dependency-free parser, mocked response validator, signature router, bounded writer, and module CLI were then frozen at16621cc, which passed both jobs in CI31415213841. One isolated fixture qualification processed all 128 registered sizes in 0.037819 seconds at 36,634,624-byte peak RSS and emitted 4,465 bytes with zero network or real-content operations. Its constructedIACKDH-R1has no real-source meaning. Request56531c6passed both jobs in CI31416489006; decision04f2706then passed both jobs in CI31424361969before the sole audit. All eleven gates passed over 128 requests and 161,792 bytes in 23.576352333 seconds at 94,650,368-byte peak RSS. RouteIACKDH-R5measured two signatures: 96 declarations have 29 channels without M1/M2, and 32 have 31 channels with M1/M2; all contain HEOG, VEOG, and TRIGGER at 1024 Hz. The retained local bundle, siblings, samples, events, targets, models, and scores stayed closed. The run is consumed with no retry or rerun. Read the primary-source diagnosis, frozen preregistration, implementation record, authorization packet, decision record, and aggregate result. -
Design history, role-aware dual reversal: a target-free code audit found that changing the failed
36check alone would still misclassify TRIGGER as EEG and retain an invalid 32/34-EEG-row assumption. The next smallest gate is therefore IACKD-H2: 316 public BIDS metadata files totaling 457,602 bytes covering channel roles, EEG sidecars, electrodes, and coordinate systems. It needs no local-bundle access and will freeze aSensorRoleMapbefore any future sample read. The prospective IACKD-2 science is also stronger than IACKD-1: congruent-to-incongruent and incongruent-to-congruent arms must both prefer actual hand direction over the exact-opposite cue surrogate, and the weaker arm determines the participant statistic. This is a design, not a neural result; H2 real metadata and every IACKD-2 operation remain separately gated. Read the role-aware dual-reversal research. -
Frozen next engineering gate, IACKD-H2 Channel Role and Geometry Audit: the exact prospective contract covers 128
channels.tsvfiles, 128 EEG sidecars, 30 electrode tables, and 30 coordinate-system files: 316 public metadata objects and 457,602 bytes total. It selects predictive EEG by source-declared BIDS type, keeps HEOG/VEOG and TRIGGER out of the predictive set, treats M1/M2 as optional run properties, preserves missing reference or geometry as unavailable, and publishes aggregate hashes and coverage only. This registration authorizes generated fixtures only after its commit is remotely green. It does not authorize the metadata fetch, retained bundle, signal, target, model, or score and is not a neural result. Read the H2 preregistration. -
H2 implementation, generated-fixture qualified: registration
228ccd0passed both jobs in CI31427931578before the dependency-free parser, private run/geometry joins, response firewall, aggregate router, writer, inspector, and module CLI were implemented. One final generated traversal covered all 316 registered object sizes and 457,602 bytes in 0.054680 seconds at 34,996,224-byte peak RSS, emitting 8,282 bytes. It produced two full schemas but one core schema after removing optional M1/M2, 26 constructed predictive EEG roles, and complete constructed C3/C4/Cz and O1/Oz/O2 geometry in all 30 groups, routingIACKDR-R4. Those are fixture mechanics, not observations of the public data. Forty-seven focused, 1,751 base, and 1,822 optional tests pass locally. The implementation must still be committed, pushed, and remotely green before an all-false real-content packet can be prepared. Read the implementation record. -
H2 real-content request, all false: implementation
9f6fef9passed both jobs in CI31430151368, so the repository now contains one hash-bound request for a possible later 316-body, 457,602-byte public metadata audit. The packet permits no action by itself: every request, parse, consumed marker, output, local-bundle, signal, target, model, score, retry, rerun, and claim flag is false. Its own commit and both CI jobs must become green before it can be identified to the maintainer for one fresh short-form decision. Read the authorization packet. -
H2 decision recorded, not yet effective: after the exact green packet was identified, the maintainer replied
continue :). The separate decision record preserves those words and binds request86174bc, CI31431064259, both green job IDs, and the unchanged 316-object scope. The decision must itself be committed, pushed, and remotely green before the single metadata audit; recording it made zero metadata requests or local-bundle operations. -
H2 measured result, consumed at
IACKDR-R1: decisionf6eb5abpassed both jobs in CI31444154297before one 316-request, 457,602-byte audit. Response, parsing, privacy, geometry, resource, and replay gates passed in55.592999708sat 86,769,664-byte peak RSS. The metadata consistently shows 26 predictive EEG channels, threeMISCcontrols, 1024 Hz, average reference, and complete central/occipital geometry across all 30 groups. The frozen contract rejected its own candidate because it did not acceptMISCfor HEOG/VEOG and separated the named trigger from the sidecar's three-MISC count. Read the aggregate result. H2 has no rerun and establishes no neural or decoding result. -
Prospective H3 source-semantics repair: a new artifact-only policy now separates dataset-pinned BIDS source type, functional control role, and model inclusion. It preserves the two exact source count groups, keeps one fixed 26-channel predictive EEG core, treats M1/M2 as optional nonpredictive EEG, and gives HEOG/VEOG/Trigger nonpredictive roles without moving them out of their declared MISC count. Read the policy research. The dependency-free implementation now qualifies 29-row and 31-row generated fixtures, five separate derivative hashes, deterministic replay, target leakage refusal, and 13 adversarial mutations spanning 12 fail-closed classes. Exact implementation
8c5784apassed both jobs in CI31446902756before one measured closeout: all 13 gates passed over 6,093 generated input bytes in 0.00747 seconds at 20.25 MiB peak RSS, with every real-data, signal, target, model, network, and scoring counter at zero. Read the H3 result. This validates policy mechanics only; no real reader or IACKD-2 execution is authorized. -
Frozen prospective IACKD-2 experiment: the new dual-reversal preregistration turns the repaired sensor semantics into a harder scientific test. Separate congruent-to-incongruent and incongruent-to-congruent models must both favor measured hand direction over the exact cue-derived opposite, and the weaker participant-level arm margin is primary. The contract freezes the 26-channel predictive core, central, occipital, EOG, pre-window, timing, displacement, permutation, derangement, and opposite-hand controls; exactly 660 fits and 900 target-blind prediction sets; one remote-green aggregate freeze; and one combined final target delivery and score. To protect storage, a future separately authorized run must stream one of 128 ten-object run groups at a time, never retain a second 7.25 GB raw bundle, and stay below 1 GiB peak incremental disk. The largest registered run group is 82,064,564 bytes. The existing private bundle is forbidden. Registration
5bdab30passed both jobs in CI31448911258before the generated-only implementation. It now exercises strict model/scorer isolation, 29/31-row source semantics, causal features, exactly 660 fits and 900 target-blind prediction sets, a recomputed hash freeze, exact replay, and all six routes. Portability correctionaf7488apassed both jobs in CI31451262840before the one registered generated closeout. All 15 gates passed in 5.024801 seconds at 257,130,496-byte peak RSS with 30,170 output bytes. Every real/public/private/network counter stayed zero, and the temporary report was removed. ConstructedIACKD2-R5is planted interface evidence only, not a neural result. The generated closeout is consumed with no rerun. The all-false real-execution packet froze one possible 7.249 GB streaming public-EEG sequence, 660 fits, 900 target-blind predictions, one remotely green freeze, and one score. Request862141fpassed both jobs in CI31454131606; the maintainer's freshcontinuewas then bound without scope expansion, and decision2ce87fapassed both jobs in CI31456317734. The new real-executor implementation uses exact metadata/object integrity checks, one-run-at-a-time MNE parsing, explicit unavailable geometry handling, causal 0.5-4 Hz derivatives, physically separate model and scorer shards, deterministic private predictions, aggregate freeze validation, and a one-shot scorer. Its final generated qualification passed all 15 gates: 660 fits, 900 predictions, exact replay, 5.604450 seconds, 270,745,600-byte peak RSS, 4,523 output bytes, and zero public, real-data, old-bundle, provider, or hardware operations. The plantedIACKD2-R5remains non-scientific. Exact implementationdab5dd4then passed both jobs in CI31461818620before the sole registered stream. That invocation wrote its no-retry consumed marker, opened only the first pinned metadata response, and parked atIACKD2-F08when its HTTPContent-Lengthwas absent or differed from the registered 1,178 bytes. No response body, EEG object, signal, trajectory, target, derivative, model, freeze, delivery, or score was reached. IACKD-2 is consumed with no rerun; the old retained bundle remains forbidden. The engineering lesson is to make immutable bounded body bytes and SHA-256 authoritative for metadata in any separately preregistered recovery, rather than treating a transport header as content evidence. That lesson is now frozen prospectively in IACKD-T1 research and its strict contract. The four small metadata bodies may use fixed-length, chunked, or clean close-delimited framing, but exact observed bytes and registered SHA-256 are still mandatory; all large-object and scientific gates remain unchanged. Registrationee0f62apassed both jobs in CI31472269070before the zero-network implementation. Its final generated run passed 10 acceptance validations, deterministic replay, and all 22 refusals in 0.00105 seconds at 20.3 MB peak RSS with a 5,540-byte report. The module has no URL opener, local-path executor, or--executemode. Two intermediate candidates exposed and preserved an optional-suite RSS test-boundary issue; exact implementation93a067cthen passed Base Python job93724709807and Optional Neuro Readers job93724709840in CI31474412246. The new all-false IACKD-2R request binds one possible future additive executor, one fresh storage-safe stream, the unchanged 660-fit/900-prediction target firewall, one green freeze, and one score. It also refuses before consumption when free disk, one-thread settings, or per-CPU machine load are unsafe. The packet authorizes nothing; it must be committed, pushed, and remotely green before a fresh later packet-bound maintainer decision can open any public operation. Request525e97epassed both jobs in CI31475356506; after Codex identified it as the sole packet, the maintainer's freshcontinuewas recorded verbatim in the additive decision. Decisionfeef8f7passed Base Python job93730242015and Optional Neuro Readers job93730242090in CI31476158747before the new additive executor was implemented. The module neither imports nor calls the consumed executor, has a new isolated root, integrates the green metadata validator, and keeps exact fixed-length/ETag/byte/SHA-256 payload checks. Its machine gate refuses before consumption below 10 GiB free, above normalized one-minute load1.0, or when load is unavailable. One measured generated qualification passed 18/18 gates in 4.939357 seconds at 261,488,640-byte peak RSS with 5,825 output bytes, all three metadata framing profiles, deterministic 660-fit/900-prediction replay, 13 refusal mutations, and zero real, public, network, target, or claim operations. The plantedIACKD2-R5is still only synthetic mechanics. Exact implementationb32dc25passed both jobs in CI31478167292before the sole IACKD-2R stream. The machine gate passed and the new marker consumed the attempt. The first metadata body passed status, URL, framing, encoding, and exact 1,178-byte count, then its SHA-256 differed from the pinned digest before parsing. No selected payload, EEG, event, trajectory, target, derivative, model, freeze, delivery, or score was reached. IACKD-2R is parked atIACKD2R-F05with no retry or rerun. This is a useful fail-closed content-drift result, not neural or decoding evidence. The next architecture is now specified in IACKD-M1 snapshot identity research. Official OpenNeuro API and pinned platform-source evidence show that a named snapshot exposes ahexshaand a recursive content-addressed file tree with full paths, Git object IDs, sizes, annexed status, and public S3versionIdURLs. A future validator will bind that immutable snapshot layer separately from the 1,340 selected acquisition objects and the critical Name/BIDSVersion/License/DatasetDOI projection. Raw GraphQL bytes, HTTP framing, ETag, and last-modified values are provenance only; they cannot rescue snapshot, tree, selected-inventory, or critical-metadata drift. This research made zero dataset-specific requests. The next bounded step is a generated-only standard-library canonicalizer; any one-response 2 MiB public audit remains a fresh Tier C gate and must pass before another 7.25 GB EEG acquisition is considered. The follow-on IACKD-M1 preregistration now freezes one exact 316-byte query and 355-byte request, strict duplicate-free response schemas, 1,679 versioned file rows, all twelve historical role summaries, a private-manifest/public-hash boundary, 37 adversarial refusals, and one-thread resource caps. Research723c8e2passed both jobs in CI31480538821; registration1667e30then passed both jobs in CI31481270697. The generated-only IACKD-M1 implementation is now complete locally. Its standard-library module has no network client, real endpoint, execute mode, or local IACKD path. One final constructed roundtrip reconciled all 1,679 tree rows and the exact 1,340 historical selected paths, passed 37 refusal mutations and two deterministic replays, and emitted 426,792 bytes in 0.888773 seconds at 38,436,864-byte peak RSS. Forty-nine focused, 2,084 base, and 2,155 optional tests pass. This proves a bounded identity interface, not current public-snapshot compatibility or a neural result. Public GraphQL access remains closed until the exact implementation is remotely green and a new all-false Tier C request receives a fresh packet-bound decision. Exact implementation7b8f47bis now green in CI31483435801. The follow-on IACKD-M1A all-false packet binds one possible standard-library transport wrapper, one exact 355-byte GraphQL POST, one 2 MiB-capped response, a 2 GiB free-disk gate, and zero payload requests. It authorizes nothing yet. The packet itself must become remotely green and be identified as the sole Tier C request before a fresh maintainer decision can unlock generated/mock wrapper work; public access remains behind another green wrapper milestone. The maintainer then saidkeep going, move the needle, continue, you approved to go on. The separate packet-bound decision preserves that exact message and binds only requestce84738and its hash. Decision4165c24passed both jobs in CI31485359989before the public-wrapper implementation began. The dependency-free wrapper now freezes one 355-byte POST, a no-redirect one-read response path, three framing profiles, pre-consumption disk/load/thread checks, a private marker and row manifest, and an aggregate-only result. One generated/mock qualification passed 20 wrapper refusals and two semantic replays in 0.098865 seconds at 46,563,328-byte peak RSS, emitting 429,430 bytes with zero public requests or neural, target, model, and score operations. The single public response remains closed until this exact wrapper commit passes both CI jobs; EEG payload access remains out of scope. Exact wrapper406bff8then passed both jobs in CI31487183289before the one public snapshot audit. The machine gate passed and one 355-byte POST returned 595,082 bytes, but strict canonicalization refused the response's top-level field set atIACKDMP-F05. The lane is consumed with no retry: no selected manifest, payload request, neural read, target, model, or score followed. This is a precise metadata-envelope failure, not public-snapshot compatibility or a scientific result. -
MARC-1 is the next scientific effect lane: WO9R is a real positive task-information result, but its stronger early-cue score and failed central localization leave cue, ocular, and peripheral explanations alive. MARC-1 therefore freezes one common compact causal
0.5-4 Hzshrinkage-LDA family across two complementary licensed sources. Freewill-23 supplies 23 people, self-selected target and onset timing, four EOG channels, and synchronized wrist acceleration. Wrist-45 supplies 45 people, eight forearm EMG channels, and synchronized encoder kinematics in participant-level archives as small as 33,690,749 bytes. The top route requires both axes to beat no-signal, timing, and every available non-EEG comparator; the weaker axis margin is primary.This is also storage-aware. The 13,591,548,048-byte Freewill archive may never be downloaded whole; a later separately authorized metadata gate must prove exact byte-range member selection first, and all future selected payloads remain capped below 8 GiB. The generated qualification contract now freezes a 14-member ZIP64 fixture, no member-content reads, two modality-role profiles, a past-only interface window, twelve comparators, and 24 refusal mutations before any live range request. Contract
4494d57passed both CI jobs before the dependency-free implementation was written. Exact implementatione35a587passed both jobs in CI31505555044before one generated closeout. It passed all gates in 0.006589 seconds at 23,511,040 bytes peak RSS, with 14 bounded range reads, zero payload-overlap bytes, two deterministic modality plans, and 24/24 refusals. This is engineering proof only: all real-data, target, model, score, and claim counters were zero. The full generated result is consumed with no rerun. A scientifically attractive ten-person self-paced EEG/EOG/EMG source remains parked because its dataset license is unavailable. MARC-1 has opened no payload, signal, event, target, model, or score, so it is a better experiment design, not a new neural result. Read the full source comparison and claim router.The next storage gate is now designed as
MARC1-CD1. A future audit may read only one 128-KiB version-metadata body, one exact 128-KiB archive tail, and one central-directory range capped at 16 MiB, for 17,039,360 response-body bytes maximum. ZIP64 must reconcile fully inside the tail; otherwise the lane parks with no exploratory request or whole-file fallback. Exact member names remain private, and whole-archive MD5, member CRC verification, local headers, payload content, and neural evidence remain unavailable. The central-directory research record authorizes no live response. Its green successor now freezes an 18-entry virtual archive, direct and two-bodyless-redirect mock paths, complete in-tail ZIP64 parsing, strict private/public separation, deterministic replay, and 32 adversarial refusals. Read the generated/mock contract. Contractcf63043passed Base Python job93837415016and Optional Neuro Readers job93837415174in CI31508903399before implementation. The dependency-free generated module now validates direct and bodyless-redirect range paths, structurally parses the decoy-bearing EOCD and complete in-tail ZIP64 records, inventories all 18 entries, keeps names and offsets private, replays deterministically, and refuses all 32 frozen mutations. Its latest development qualification represented the 13.59 GB archive with 280,249 generated bytes and emitted 11,573 temporary bytes in 0.007407 seconds at 26,181,632-byte peak RSS; the files were removed. This is not the registered closeout. Read the implementation record. Exact implementation211fd78passed Base Python job93846584402and Optional Neuro Readers job93846584527in CI31511626051before one registered generated closeout. That run passedMARC1CDG-R1with 280,249 generated input bytes, 11,574 temporary output bytes, all 18 entries, all 32 refusals, and all 14 gates in 0.006544 seconds at 27,131,904-byte peak RSS. Every public, real-data, target, model, score, and claim counter remained zero; the exact temporary outputs were hash-bound and removed. Read the generated result. The closeout is consumed with no rerun. The next eligible artifact is an all-false Tier C request for one live metadata/range audit; no public request is authorized yet. That request is now specified in the live-audit authorization packet. It binds one future standard-library wrapper, one metadata body, one exact 128-KiB tail, and one conditional directory body under a 17,039,360-byte accepted-response cap. Request950796dpassed both required jobs in CI31513578445, then the maintainer's fresh continuation was recorded verbatim in the packet-bound decision. Decision624cc4epassed both jobs in CI31519016891, and the live-wrapper implementation is generated-qualified. It reuses the green ZIP64 parser, disables automatic redirects, caps all bodies, validates globally routable redirect addresses, writes exact member rows only to a private mode-0600manifest, and has no whole-download or extraction interface. GeneratedMARC1CDL-G1passed 14/14 gates with 40 refusal checks and zero network or forbidden counters. Exact wrapper5dfa3c4then passed both jobs in CI31521510374before the one live inventory.MARC1CD-R1mapped 1,227 entries in the current 13,591,548,048-byte public ZIP from one 304-byte metadata body, one 131,072-byte tail, and one 175,382-byte central-directory body. It downloaded zero archive or member payload bytes, passed all 14 gates in 2.727 seconds at 43,974,656-byte peak RSS, and is consumed with no retry or rerun. The exact inventory remains in a private Git-ignored mode-0600manifest; only aggregate counts and hashes are public. Member selection or access, participant data, neural signals, targets, models, scores, and scientific-claim operations remain closed. Task 4 is now frozen in the MARC1-P1 pilot-selection preregistration. It selects 12 participants per axis using DOI-bound SHA-256 ranks before any private row is inspected. Freewill uses three session-1 runs for fitting and three session-2 runs for held-out cross-day evaluation; Wrist uses runs 1-6 for fitting and runs 7-8 for an 80-trial balanced holdout. The selection is forbidden from using size, CRC, event count, target, signal quality, or an outcome, and the future joint acquisition ceiling is 8 GiB. This is the path toward a defensible EEG effect; movement data cannot establish thought-to- text, which remains a later language-specific evidence lane. Contractd121806passed both jobs in CI31569417204before the generated selector implementation began. The dependency-free module now exercises the full 1,227-row plus 55-row metadata scale, both frozen cohorts, exact splits, private mode-0600output, row-order replay, cap refusal, and all 36 adversarial mutations. A disposable development run passed constructedMARC1PSG-R1; its outputs were removed. Exact implementation0c0a698then passed Base Python job94034790262and Optional Neuro Readers job94034790315in CI31571668853before the one registered generated closeout. That run passed all 15 gates and 36 refusals over 873,348 generated input bytes in 0.227 seconds at 32,374,784-byte reported peak RSS. Its 6,946-byte aggregate report and mode-0600175,618-byte private manifest were hash-bound, inspected once, and removed. All real, network, signal, target, model, score, and claim counters stayed zero. The generated lane is consumed; real metadata selection remains a later Tier C gate. The MARC1-P1A authorization packet freezes one staged wrapper and one selection over exactly one 418,755-byte sealed Freewill-manifest read plus one Wrist metadata body capped at 2 MiB. Request7f1ba09passed both jobs in CI31573969646, and the maintainer's fresh wordsapproved, continue, achieve a scientific claim, achieve thought to text 😎are preserved verbatim in the MARC1-P1A decision. Decision9726d07passed Base Python job94044627592and Optional Neuro Readers job94044627647in CI31574870204before wrapper work began. Read the live-selector implementation and its machine record. The additive standard-library wrapper freezessub-01.zipthroughsub-45.zip, the known publicsub-01identity anchor, strict seven-field Figshare rows, a target-field firewall, one no-follow private-manifest read, manual global-only redirects, a pre-input machine gate, consumed failure, and private/public output separation. GeneratedMARC1PSL-G1selected the exact 12+12 cohorts and 300 private rows, passed 26/26 refusals and 15/15 gates over 866,578 input bytes, and emitted 214,553 temporary bytes in 0.183 seconds at 50,905,088-byte reported peak RSS. All real, network, payload, neural, target, model, score, and claim counters stayed zero, and the temporary outputs were removed. Exact wrapper702e613then passed Base Python job94056321843and Optional Neuro Readers job94056321914in CI31578614616before the one live metadata attempt. The executor read and verified the 418,755-byte private inventory exactly once, opened one Wrist response, and failed closed atMARC1PS-F03because the response did not meet the frozen explicit identity-encoding rule. It accepted zero public-body bytes, selected zero participants, and opened zero archive payload, signal, target, model, or score data. The attempt is consumed with no retry or rerun. A separately named transport-semantics recovery must be frozen and reauthorized before another real metadata request. MARC-1 remains a confound-resolution rung on the same thought-to- text path, not a pivot, and movement evidence is not language evidence. The follow-on MARC1-HT1 research binds RFC 9110 Sections 8.4 and 12.5.3. Its candidate rule accepts an absentContent-Encodingas the standards-preferred uncoded representation and a lone case-insensitiveidentitytoken only as a narrow compatibility form; every real coding, list, duplicate, empty field, transfer coding, overflow, redirect violation, retry, and fallback still refuses. The actual live header was not retained and must not be inferred. MARC1-HT1 is artifact-only research: it authorizes no implementation, private read, public request, or payload operation. The follow-on generated recovery contract freezes four accepted response forms, 20 refusals, 16 acceptance gates, five refusal routes, exact replay of the 12+12 generated cohorts, zero network or private bytes, and noexecutecommand. Only after this exact contract is committed, pushed, and green may the additive generated/mock harness be implemented. A live request remains Tier C and payload acquisition remains ineligible. The generated recovery implementation now accepts exactly the four frozen uncoded forms, refuses all 20 mutations, replays the exact 12+12 target-free cohorts, and passes all 16 gates over 923,052 generated input bytes. Its 182,682-byte output was inspected and removed; no live metadata, network body, payload, EEG, target, model, or score was accessed. The exact implementation must be committed, pushed, and green before its one registered generated closeout. This is a transport repair on the same positive-control-to-language path, not a scientific pivot. Exact implementationb2cb48cthen passed Base Python job94073234688and Optional Neuro Readers job94073234607in CI31583931303before the one registered generated closeout.MARC1HT-G1passed all gates in 0.112 seconds at 33.1 MB external peak RSS. Its aggregate was inspected once, both temporary outputs were hashed and removed, and the closeout is consumed with no rerun. This remains generated engineering evidence only; another live metadata attempt is not yet open. The next gate is now specified in the all-false MARC1-HT1A authorization packet. It proposes a new additive wrapper and, only after separate green decision and implementation milestones, one metadata-only attempt using the sealed 418,755-byte upstream inventory and one Wrist response capped at 2 MiB. It forbids the consumedMARC1-P1Aroot, all payload bytes, signals, targets, models, and scores. The packet authorizes nothing and is explicitly a control checkpoint on the same path toward held-out language decoding. Request27f39aepassed Base Python job94080678529and Optional Neuro Readers job94080678738in CI31586256906. The fresh maintainer approval is now quoted in the separate MARC1-HT1A decision. That decision is ineffective until its own commit is pushed and both CI jobs are green; no implementation or real-input operation has begun. Decision9c7bd48and exact wrapper68ade0dsubsequently passed both required CI jobs before the single metadata-only invocation. The corrected transport accepted and parsed one 2,917-byte uncoded response, then the selector consumed atMARC1HTL-F04because its row count differed from the frozen 55-row identity. The actual count and rows were not retained. Zero participants were selected and zero payload, signal, target, model, prediction, or score operations followed. Read the consumed result. Result1337a91then passed Base Python job94091696454and Optional Neuro Readers job94091696340in CI31589739739before the MARC1-PG1 pagination research was recorded. Pinned official Figshare OpenAPI source says the version-files operation defaultspage_sizeto 10 and permits up to 1,000. Omitted pagination is therefore the leading engineering hypothesis, not a proven description of the consumed response. The prospective request binds exactlypage=1&page_size=1000, still requires all 55 frozen rows, and forbids a second page, fallback, partial cohort, or live request before generated-only contract, implementation, and closeout milestones are independently green. This is the same confound-control to neural-positive-control to held-out- language path, not a pivot; it establishes no new scientific result. Research7a7883apassed Base Python job94095736694and Optional Neuro Readers job94095736770in CI31591022429before the MARC1-PG1 generated contract was frozen. The contract permits only a futureplan/qualify/inspectharness after its own commit is green. It binds four equivalent generated replay cases, 41 refusals, 18 gates, exact request serialization, unchanged selection and split identities, private/public output separation, one-thread resource caps, zero network/private bytes, and noexecutecommand. A live request and payload acquisition remain closed. Contractccb3ba8passed Base Python job94098410925and Optional Neuro Readers job94098410868in CI31591853349before the generated pagination implementation was built. DevelopmentMARC1PG-G1passed 4/4 accepted cases, all 41 refusals across eight routes, and all 18 gates. It replayed the unchanged 55-row identity and 12+12 target-free selection from 1,019,776 generated input bytes in 0.089257 seconds at 40,091,648-byte reported peak RSS. Its 183,355 temporary output bytes were inspected, hash-bound, and removed. Exact implementation2c98a2apassed Base Python job94104455930and Optional Neuro Readers job94104455857in CI31593790492before the one registered closeout. That invocation consumed atMARC1PG-F07because/tmpwas a symlink output parent. Contract loading, both generated inventories, four accepted cases, and target-free selection had already run in memory, so this is not an unspent preflight and no corrected invocation is allowed. It created zero files and used zero real/private or network bytes. A separately named generated recovery must move output preflight before all fixture operations and become green before another registered generated run. No live request, payload, signal, target, model, score, or claim operation is open. This remains the same path to cue-resistant neural evidence and held- out language decoding; it is not a pivot. Resulta4dcaeapassed Base Python job94107907276and Optional Neuro Readers job94107907246in CI31594881048before the artifact-only MARC1-OP1 research. The candidate architecture obtains and holds a no-follow parent-directory capability, binds device/inode identity, and requires parent-relative exclusive writes. That capability must exist before any repository read, contract load, deferred pagination import, fixture, or selection. The local runtime supports the neededdir_fdprimitives, but a future implementation must feature-detect and refuse rather than downgrade on another platform. This research made zero fixture, network, private, payload, signal, target, model, or score operations. Its next gate is research commit, push, and both CI jobs green before a generated-only contract may be frozen. Researchd02830bpassed Base Python job94111539407and Optional Neuro Readers job94111539431in CI31595996923before the MARC1-OP1 contract was frozen. It binds six accepted cases, 32 refusals, ten routes, 20 gates, one exact path-only probe, and one conditional qualifier. The future wrapper cannot import the consumed pagination module eagerly, call its qualifier, or modify it. Every current access and authorization flag remains zero/false. Contractbaade51passed Base Python job94115807028and Optional Neuro Readers job94115807008in CI31597291352before the MARC1-OP1 implementation. Its capability acquisition is the first call inpreflightandqualify; it holds parent device/inode identity through two exclusive relative writes, one public-only inspection, and exact cleanup. DevelopmentMARC1OP-G1passed six accepted cases, 32 refusals, and 20 gates using 184,173 temporary bytes and zero live/private, neural, target, model, or score operations. The exact registered path remains untouched until this implementation is pushed and both CI jobs are green. This remains the same scientific path. Exact implementationfcedcc3then passed Base Python job94125013790and Optional Neuro Readers job94125013956in CI31600085119before the registered generated result. The one path-only preflight reachedMARC1OP-P0with every experiment-work counter zero; the one conditional qualifier reachedMARC1OP-G1in 0.098 seconds at 33,882,112-byte reported RSS and removed all 184,173 temporary bytes. Both invocations are consumed. Current live inventory compatibility and every neural, language, and thought-to-text claim remain unestablished. -
MARC1-LM1 paginated live-metadata gate: exact result
ca4679apassed Base Python job94129199903and Optional Neuro Readers job94129199993in CI31601329375before the all-false packet. The proposed sequence adds one generated/mock standard-library wrapper and, only after its own green proof, one exact no-retry Figshare request forpage=1&page_size=1000. The response is capped at 2 MiB and may create only a consumed marker, a small Git-ignored 55-row private manifest, and one aggregate report. No payload, signal, target, model, prediction, score, or scientific claim is authorized. This is the next cohort-integrity step on the same route to cue-resistant neural evidence and held-out language decoding. The maintainer then supplied the exact 76-byte instructionapproved, continue, achieve a scientific claim, achieve thought to text 😎after the packet was identified. The separate decision quotes those words and binds only request4d3eb19, CI31603530015, and the unchanged one-response, zero-payload scope. Decision060a365passed Base Python job94140250333and Optional Neuro Readers job94140250412in CI31604608307before the generated/mock implementation. DevelopmentMARC1LM-G1accepted all four transport forms, refused all 36 adversarial mutations, and passed all 20 gates while replaying the exact 55-row inventory and frozen 12-subject split. It read 184,466 generated response bytes, created and removed exactly 19,030 temporary output bytes, ran in 0.0303 seconds at 43,057,152-byte reported RSS, and made zero real network, payload, signal, target, model, score, retry, or claim operations. The exact implementation must now be committed, pushed, and pass both CI jobs before the registered path or Figshare may be touched once. The research objective is unchanged and no result is predeclared. First push8f67af2failed both CI jobs only because generated tests used a macOS-only temporary parent; the correction uses the platform's canonical real temporary parent and leaves the registered execution path unchanged. -
MARC1-LM1 consumed live metadata result: corrected implementation
f9a1ecepassed Base Python job94164152160and Optional Neuro Readers job94164152302in CI31611639130before the sole request. One 15,652-byte metadata body passed transport and strict JSON parsing, then the frozen inventory validator refused atMARC1LM-F04. The actual failed predicate is unavailable; no cohort was selected and participant archive, payload, signal, target, model, prediction, and score counters remained zero. The consumed lane has no retry. The next gate is a separately named prospective current-inventory identity design on the same research path. -
MARC1-SA1 source-aware inventory design: current official Figshare surfaces do not give one stable cross-surface guarantee for MD5 fields. The new architecture treats five public fields as source core, two MD5 fields as validated optional provenance, and acquired-byte SHA-256 as a later payload integrity gate. A 21-field aggregate predicate vector can distinguish schema, count, participant, byte-total, anchor, URL, and checksum classes without publishing rows. This is Tier A design only: zero dataset requests and zero neural or model work.
-
MARC1-SA1 generated-only preregistration: after research
aa80503passed both jobs in CI31614330447, the next harness was frozen around six generated semantic families, 21 aggregate predicates, seven separated hash domains, 52 adversarial refusals, and 25 acceptance gates. Its command surface is onlyplan,qualify, andinspect; it has no network client, live path, payload reader, signal, target, model, prediction, or score. The exact contract must now pass both CI jobs before implementation begins. -
MARC1-SA1 generated implementation: contract
8f64ccbpassed both jobs in CI31616551270before the standard-library attestor was built. Final development routeMARC1SA-G1passed six semantic families, 52 refusals, and 25 gates using 732,811 generated input and 109,589 temporary output bytes in 0.0524 seconds at 27,426,816-byte peak RSS. Output capability was acquired first, public/private schemas stayed separate, and both files were removed. The exact implementation must now pass both CI jobs before one registered generated closeout; no live metadata, payload, target, model, or scientific evidence was accessed. -
MARC1-SA1 registered generated closeout: exact implementation
feb3b83passed Base Python job94188922905and Optional Neuro Readers job94188922771in CI31619037335before one fixture-only execution.MARC1SA-G1passed all six routes, 52 refusals, and 25 gates using 732,811 generated input and 109,589 temporary output bytes in 0.053358083 seconds at 27,885,568-byte reported peak RSS. Both files and the invocation directory were removed. The closeout is consumed; a live metadata response remains a new Tier C sequence, and no EEG or language evidence changed. -
MARC1-SA1A all-false live-metadata request: green result
094b6cb/ CI31620515340now anchors one possible future source-aware wrapper and one exact 2-MiB-capped metadata GET. R1/R2 may retain the frozen target-free cohort; R3/R4 must block selection and publish only aggregate diagnosis. Every current implementation, network, output, payload, neural, target, model, score, and claim permission is false. The packet must become remotely green and receive a fresh packet-bound maintainer decision before wrapper implementation or source access. -
MARC1-SA1A packet-bound decision: request
b077550passed Base Python job94198174069and Optional Neuro Readers job94198173901in CI31621794066before the maintainer's exact 31-byte instruction was recorded. The decision binds only one generated/mock wrapper followed, after separate green proof, by one 2-MiB-capped metadata response and zero payload bytes. It must itself become remotely green before implementation. Later acquisition, neural analysis, target delivery, scoring, replication, and language decoding remain separately gated; no scientific result changed. -
MARC1-SA1A source-aware wrapper: decision
ef9ab91passed Base Python job94353799568and Optional Neuro Readers job94353799602in CI31670457497before implementation. The additive standard-library wrapper accepts exactly one fixed, unauthenticated Figshare files response capped at 2 MiB, supports exact-length, chunked, or clean-close framing, rejects target fields and schema ambiguity, and stops before every participant archive. Generated routeMARC1SAL-G1passed six semantic families, 31 adversarial cases, and 20 gates using 84,422 generated response bytes and 24,064 transient output bytes in 0.00929 seconds at 37,552,128-byte reported peak RSS. All temporary files were removed; real requests, payload bytes, neural reads, targets, fits, predictions, scores, and claim upgrades were zero. Thirty focused, 765 MARC, and 2,904 dependency-light tests pass. One old optional rehearsal inherited a process-wide RSS high-water in the full local optional run but passes alone; fresh remote Base and Optional jobs remain the exact eligibility gate. Exact wrapper74aff21then passed both jobs in CI31672761644before the one registered request. -
MARC1-SA1A consumed source-aware result: the one request completed in 0.6967 seconds at 33,439,744-byte peak RSS and routed
MARC1SAL-R2. That is the preregistered blocked-selection branch: zero subjects became eligible, no participant archive opened, and payload, signal, target, model, prediction, score, retry, and rerun counts remained zero. The three retained private/aggregate files total 23,112 bytes. Because the executor had already performed the allowed aggregate inspection and its CLI did not emit the private R3-versus-R4 source route, historical differences and body size are recorded as unavailable rather than inferred. This Wrist lane is consumed; acquisition and the remaining experiments do not proceed against it. -
MARC-2 conditional-information route: the replacement architecture keeps Freewill-23 as the cue-reduced primary axis, ranks Biomed-SPC-9 and a bounded PhysioNet Gait-59 subset for one later peripheral-control cohort, and reserves OpenNeuro
ds003626-v2.1.0for a Spanish inner-speech control experiment. Its primary endpoint is participant-macro held-out log-loss gain from adding EEG after the strongest available timing/EOG/EMG/kinematic model. Three compact causal families are registered as separate hypotheses rather than a final-target model search. Any hosted LLM remains downstream of a remotely green neural freeze and must beat both LLM-only and item-deranged-neural conditions. This milestone read public primary-source pages only; all dataset, private-path, payload, signal, target, model, score, provider, and claim counters remain zero. -
MARC2-FW1 storage-aware participant power: the first work order now freezes the old DOI-derived Freewill rank instead of inventing a new seed, keeps the original 12-person cohort as a hard floor, and selects the largest contiguous prefix up to 19 people whose exact six-run member reservations fit within 8 GiB. It cannot skip a large participant to admit a later one, change run choice by size, inspect event content, or use signal quality or outcomes. The generated main fixture must select 16 people, 96 run bundles, and 384 members, plus pass floor, all-19, exact-cap, cap-plus-one, privacy, replay, and 40-refusal gates. This is a frozen fixture contract, not a real private-inventory read or a scientific result.
-
MARC2-FW1 generated implementation: the new dependency-free module validates 1,227 generated ZIP-directory rows, replays the frozen rank, forms exact session-held-out bundles, and writes separate private and aggregate outputs. One local qualification passed 4/4 storage boundaries and 40/40 refusal probes in 0.214 seconds at 30.9 MB reported peak RSS, with 846,690 generated input bytes and 221,068 output bytes. It exposes only
plan, generatedqualify, and aggregateinspect; there is noexecute, network, archive, signal, target, model, or score surface. A registered generated closeout was permitted only after this exact implementation became remotely green. -
MARC2-FW1 consumed generated result: exact implementation
36f8775passed both CI jobs before one registered closeout routedMARC2FWG-R1in 0.211 seconds at 32.0 MB reported peak RSS. It emitted and removed 221,068 temporary bytes, preserved the 16-person/8.105-GB fixture result, passed all 4 boundaries and 40 refusals, and left every private/real counter at zero. This closes generated qualification; the next gate is an all-false packet for one exact private-inventory read, not payload acquisition or science. -
MARC2-FW1A private-selection request: the repository now binds an all- false Tier C packet to the exact 418,755-byte, mode-
0600, 1,227-row private central-directory manifest and a new isolated output root. A future additive wrapper must pass the inherited 40 selector mutations plus 18 filesystem, proof, privacy, and one-shot refusals before one no-follow read can occur. Even a successful future selection stops before every archive local header, member payload, neural sample, event, target, model, prediction, and score. The packet itself performs zero private operations and grants no authority. -
MARC2-FW1A packet-bound decision: after the all-false request became remotely green and was identified as the sole Tier C gate, the maintainer's exact fresh
continuewas recorded additively. The decision authorizes only a generated/mock wrapper after the decision itself is green and one exact private-manifest selection after that wrapper is separately green. It does not authorize an archive member, EEG payload, neural analysis, target, model, score, provider,MARC2-FW2, or scientific claim. -
MARC2-FW1A proof-gated wrapper: decision
ad1e406passed Base Python job94656172494, Optional Neuro Readers job94656172528, and CI31764052451before implementation. The additive standard-library wrapper has fixedplan,qualify,inspect, and proof-disabledexecutecommands; exact no-follow owner/mode/size/hash/schema gates; bounded short-read handling; a pre-content consumed marker; separate private and aggregate outputs; and an aggregate-only consumed failure receipt. Its final generated run passed all 40 inherited selector refusals and 18 wrapper refusals, selecting the same 16-person/384-member fixture prefix at 8,105,207,776 reservation bytes in 0.268 seconds at 36.1 MB peak RSS. All 3,071 base and 3,142 optional-neuro tests pass. Retained-private, network, archive-member, neural, target, model, and score counters remain zero. The exact wrapper commitd9a3853subsequently passed both remote jobs; that proof did not itself access the private inventory or authorize payload work. -
MARC2-FW1A consumed proof failure: the sole registered invocation exited at
MARC2FWS-F00withimplementation record differs. The proof gate ran before the machine gate, retained source path, consumed marker, content open, hash, parse, selection, or output writers. A tracked-artifact-only diagnosis found the implementation registry omitted its required top-levellane_id: MARC2-FW1A; no private file was inspected to find that cause. Private-path checks, opens, bytes, hashes, parses, participant/member selections, payload reads, signal/target/model/score operations, and outputs all remained zero. The invocation is consumed without repair or rerun.MARC2-FW2remains ineligible; any recovery must be separately named, generated-qualified, and newly gated before private access. -
MARC2-FW1B generated proof-record recovery: the new frozen contract makes the implementation record itself a strict interface. It requires
lane_id: MARC2-FW1Bamong 15 exact top-level fields, unique non-self artifact bindings, one sharedvalidate_implementation_recordentry point, deterministic replay, and 32 ordered malformed-record refusals under a 30-second, 256-MiB, one-thread envelope. This milestone authorizes only a generated validator implementation after both CI jobs are green. Its private execution limit is zero; the retained manifest, archive members, EEG, targets, models, scores,MARC2-FW2, and scientific claims remain closed. -
MARC2-FW1B shared-validator implementation: the exact implementation accepts the complete 15-field registry itself, including top-level
lane_id, and separates expected remote proof from observed Git/CI proof. One fresh generated run made 34 calls through the same public validator: two replay-identical canonical passes and 32 exact refusals. It processed 84,701 generated bytes, emitted and removed a 6,711-byte aggregate report, ran in 0.016927 seconds at 27,099,136-byte peak RSS, and used one thread. All 3,134 base and 3,205 optional-neuro tests pass locally. Real/private, network, archive, EEG, target, model, score, provider, and hardware counters remain zero. Exact commit6f613b3passed Base Python job94669566174, Optional Neuro Readers job94669566187, and CI31768593977before the next packet was prepared. -
MARC2-FW1C all-false live-recovery request: the new packet proposes two separately gated stages: a standard-library generated/mock wrapper that must prove its own future HEAD through the exact shared validator, then one no-retry target-free read of the exact 418,755-byte structural manifest. It names a new output root, caps live output at 2 MiB, requires 15 GiB free, and stops before every archive member, EEG sample, target, model, or score. Every authorization flag is false and every operation counter is zero. Exact request
7804c3epassed Base Python job94672387003, Optional Neuro Readers job94672386941, and CI31769518851. -
MARC2-FW1C packet-bound decision: after the packet was identified as the sole Tier C gate, the maintainer's fresh exact
continuewas recorded without a fabricated long recital. The decision binds the request hashes, future wrapper HEAD proof, 90 required future refusals, one possible later 418,755-byte structural read, and zero archive-member/payload bytes. All 3,170 base and 3,241 optional-neuro tests pass locally. Exact decisionb0466e5passed Base Python job95120011473, Optional Neuro Readers job95120011519, and CI31928627432; private access remains closed until the generated/mock wrapper is separately remotely green. -
MARC2-FW1C shared-proof recovery wrapper: the new standard-library module keeps a native
MARC2-FW1Cregistry separate from an FW1B-format certificate and calls the exact shared validator twice canonically plus once for each of 32 proof mutations. One final generated closeout passed 32/32 proof-record, 40/40 selector, and 18/18 wrapper refusals, then replayed the same 16-person, 96-bundle, 384-row structural prefix at 8,105,207,776 future reservation bytes. It processed 846,712 generated bytes and emitted 298,059 temporary bytes in 0.374161 seconds at 38,666,240-byte peak RSS. All 3,214 base and 3,285 optional-neuro tests pass; every private, network, archive, neural, target, model, score, retry, and claim counter is zero. The temporary output was removed. Exact wrapper7b924bethen passed Base Python job95123374369, Optional Neuro Readers job95123374211, and CI31930051249before its one registered structural-manifest selection. -
MARC2-FW1C consumed source-identity failure: the sole invocation opened, read, hashed, and strictly parsed exactly 418,755 structural bytes once, then routed
MARC2FWC-F02because strict live source identity differed. It selected zero participants and zero members, wrote no private selection, and performed zero network, archive-member, signal, target, model, prediction, or score operations. Runtime was 0.091374 seconds at 25,280,512-byte peak RSS with 6,944 total output bytes. The aggregate does not retain which private field differed. The invocation is consumed without retry, no selection result exists, andMARC2-FW2remains ineligible. -
MARC2-SL1 exact schema-lineage diagnosis: a fixed artifact-only AST/JSON audit reconciled the exact producer, generated fixture, selector validator, and FW1C validator. MARC-1 forwards keys
directory,metadata, andtail; every consumer-side artifact instead requirescentral_directory,metadata, andtail. That one alias mismatch is sufficient to explainMARC2FWC-F02. Generated tests missed it because fixture and validators were internally consistent with each other but not source compatible. The audit read 310,015 committed bytes in 0.027645 seconds at 35,717,120-byte peak RSS and performed zero private, archive, neural, target, model, or network work. A future repair must validate the producer-native vocabulary first, then mapdirectorytocentral_directoryexactly once in a new adapter. -
MARC2-TA1 generated adapter result: after registration commit
0c0e1c8passed CI31932701989, the standard-library adapter validated all 1,227 producer-native generated rows before deep-copying and mapping onlydirectorytocentral_directory. Exact implementation108b869then passed both jobs in CI31933692066. All 26 refusal mutations and both entry orders passed, every transport digest replayed byte for byte, and the unchanged selector reproduced 16 generated subject identities, 96 bundles, 384 members, and 8,105,207,776 reserved bytes. The one measured run used 846,708 input bytes, 4,931 output bytes, 0.453316 seconds, and 39,108,608-byte peak RSS; every private, neural, target, model, and network counter was zero and the temporary report was removed. This fixes a generated integration boundary; it is not neural or decoding evidence. Live/private use remains a separate Tier C decision. -
MARC2-LA1 live-schema composition registration: the next generated/mock gate now binds the exact green TA1 artifacts and the committed live producer envelope. It requires live-envelope validation before a four-value identity bridge, one call through TA1's green public adapter, unchanged entries and digests, 30 adversarial refusals, and exact selector replay. Its CLI is limited to
plan,qualify, andinspect; no file path, execute command, private data, archive member, neural payload, target, model, score, network, or FW2 authority exists. A later private read remains behind a new remotely green all-false Tier C packet and fresh packet-bound maintainer decision. -
MARC2-LA1 generated composition result: registration
62e465epassed both jobs in CI31934737967before the additive standard-library module was implemented. It validates the exact live-shaped envelope and every generated row before a four-value identity bridge, then calls TA1's green public adapter once. All 30 adversarial mutations and both entry orders pass; the frozen selector replays 16 generated subjects, 96 bundles, 384 members, and 8,105,207,776 reservation bytes. The measured run used 846,696 generated input bytes, 5,366 output bytes, 0.488921 seconds, and 38,387,712-byte peak RSS. The report was removed and every private, neural, target, model, score, and network counter is zero. Exact implementation3e3f8b8passed Base job95137289730, Optional job95137289704, and CI31935754822. Proof closeout52eabc6then passed both jobs in CI31936399968; no live/private read is authorized, and this remains engineering evidence rather than a decoding result. -
MARC2-LA2 consumed live-adapter recovery: request
f9f24a3, decisionb445df2, and exact executor5390e06each passed both remote jobs in the required order before one no-retry structural pass. That pass verified and strict-parsed 418,755 bytes once, then stopped atMARC2LAR-F02because LA1 refused the source. No selector call, participant, member, reservation, archive payload, neural value, target, model, prediction, or score followed. LA2 is consumed and cannot be retried, repaired, or reinspected. -
MARC2-VL1 validation-coverage localization: a fixed AST/JSON audit over ten committed artifacts found that the generated fixture contains only the 19-subject, 195-run eligible subset, or 780 core companion rows, and fills its remaining 245 regular rows with generic auxiliaries. The public source space contains 23 participants and 238 runs, leaving 43 run slots and 172 four-file companion slots absent from the Freewill-shaped fixture domain. LA1 requires all matched runs to equal 195 before eligibility filtering, so this is a concrete validation blind spot consistent with F02. The audit ran in 0.0499 seconds at 44,875,776-byte peak RSS with zero private, payload, neural, target, model, network, or score operations. It does not identify the exact private predicate or establish a decoding result.
-
MARC2-VR1 source-validity/eligibility repair registration: the next generated-only contract now represents all 238 source-space run slots as complete Freewill-shaped bundles. It freezes 195 eligible bundles and 43 constructed valid-but-ineligible adversaries across single-session, sampling-tier, and extra-session predicates. The implementation must validate all rows first, filter eligibility before the exact 195-run comparison, and replay the unchanged 16-subject/96-run selector identity. Registration
9dedfe6passed Base Python job95153164447, Optional Neuro Readers job95153164463, and CI31942316544before implementation began. -
MARC2-VR1 generated repair implementation: the dependency-free adapter now validates all 1,227 rows and 238 complete bundles, classifies the frozen
195/12/24/7predicate counts, filters before the exact 195-run comparison, and preserves the 16-subject, 96-run, 384-member, 8,105,207,776-byte selection with zero ineligible candidates. All 36 mutations refuse across all eight routes. Exact implementation4d587dfpassed Base Python job95155811373, Optional Neuro Readers job95155811384, and CI31943437003before one measured in-memory closeout passed atMARC2VR-G1. It processed 858,844 generated bytes in 0.207 seconds at 32,391,168-byte peak RSS and retained zero output. This closes the generated validator blind spot; it authorizes no private read, archive payload, neural data, target, model, score, FW2 work, or scientific claim. Result commit05fc2b5passed both remote jobs in CI31943963317. -
MARC2-VR2 live-domain eligibility adapter registration: the next generated-only contract removes VR1's constructed
12/24/7ineligible breakdown from future live acceptance. It freezes the exact 238 total, 195 eligible, and 43 ineligible bundles plus the public participant taxonomy, but allows the three valid exclusion counts to vary. Four deterministic distributions in canonical and reversed order must all reproduce the same 16-subject, 96-run, 384-member, 8,105,207,776-byte target-free selection. Registration384373epassed both required jobs in CI31945086852before implementation. No private path, archive payload, neural data, target, model, score, network operation, FW2 work, or scientific claim was opened. -
MARC2-VR2 generated live-domain implementation: registration
384373epassed Base Python job95159734989, Optional Neuro Readers job95159734967, and CI31945086852before implementation. The new standard-library in-memory adapter validates all 1,227 rows and 238 bundles, dynamically classifies195 + 43, and accepts four distinct generated exclusion layouts without receiving a profile identity. All eight profile/order paths reproduce selection identitydee065bfdb5f8439fe711042eaadbea0dca3d83f8be0d6b7b9d1637e84d9f641; all 58 mutations refuse across eight routes. A development preflight used 3,435,280 generated bytes, 0.511378 seconds, and 35,356,672-byte peak RSS. Exact implementationf62a3f5passed Base Python job95162220059, Optional Neuro Readers job95162220159, and CI31946112252before the one registered generated closeout. Private data, FW2, neural values, targets, models, scores, and scientific claims remained closed. -
MARC2-VR2 generated variable-domain result: one one-thread qualification passed at
MARC2VR2-G1. All eight profile/order paths validated the exact 1,227-row, 238-bundle source envelope, dynamically reconciled195 + 43, and reproduced the frozen 16-subject, 96-run, 384-member, 8,105,207,776-byte selection with zero ineligible rows. All 58 mutations refused across eight routes. The run processed 3,435,280 generated bytes in 0.512264 seconds at 32,620,544-byte peak RSS, emitted 4,748 aggregate stdout bytes, and retained zero output. The generated closeout is consumed with no rerun. Result commit7b6899bpassed both required jobs in CI31946852669, completing remote proof. This proves the live-domain adapter is not tied to a synthetic exclusion mix. It proves no neural effect or decoding result and authorizes no private read or FW2 work. -
MARC2-VR3 variable-domain private recovery decision: request commit
328faa8passed Base Python job95166799271, Optional Neuro Readers job95166799305, and CI31947928896. The maintainer's fresh three-line instruction is preserved verbatim in the separate decision and binds only the green VR3 packet. Decision commit944b6e8passed Base Python job95202667384, Optional Neuro Readers job95202667483, and CI31962561043before implementation. The requested FW2 experiment remains a design direction, not retroactive payload, training, target, or scoring authority. -
MARC2-VR3 generated private-recovery wrapper: the new standard-library module composes the exact shared proof validator and VR2 adapter, fixes its source and output identities, performs one future no-follow content open, and exposes no archive, neural, target, model, or score interface. Generated qualification passed eight profile/order paths and 64 direct refusal mutations in 1.850114875 seconds at 38,322,176-byte peak RSS, processing 3,445,032 bytes and emitting 4,464 aggregate bytes. The same 16-subject, 96-bundle, 384-member prefix replayed in every path; all private and scientific counters stayed zero. Exact implementation
2467876passed Base Python job95207398015, Optional Neuro Readers job95207398092, and CI31964473405before the one registered invocation. -
MARC2-VR3 consumed machine-preflight result: the sole invocation stopped at
MARC2VDR-F01because its aggregate machine resource preflight refused. Exact implementation proof passed, but no output-root or private-path check, content open, manifest byte, marker, adapter call, real cohort selection, archive read, neural value, target, model, prediction, score, or claim operation followed. The exact failing load/disk/RSS predicate was not emitted and is unavailable; the lane has no retry or rerun. No real cohort was frozen, so FW2 remains ineligible. This is a safety result, not neural or decoding evidence. -
MARC2 machine-stable recovery and neural-control architecture: VR3 result commit
a186486passed Base Python job95208692240, Optional Neuro Readers job95208692213, and CI31964995980. The next design separates reversible machine readiness from the marker that begins a one-shot private pass, so a transient load timeout is diagnostic rather than a consumed scientific attempt. After a real cohort freeze, FW2 may stream only selected archive members under a 10 GiB cap; CIL1 then testsP+Esignal against target-independentP+D(E)derangement,B1timing, andB0no-signal. Held-out models emit continuous target-blind probabilities before one frozen onset/target score. This is architecture research, not a preregistration, payload authorization, model result, or neural claim. -
MARC2-VR4 machine-stable recovery contract: a frozen generated-only contract now defines three consecutive readiness samples, a 600-second wait, exact load/RSS/disk diagnostics, a 300-second certificate expiry, and 36 mutations across six refusal routes. The implementation surface has no execute command or private path. A future private executor remains a separate Tier C packet whose irreversible boundary is the marker immediately before one content open. Registration
3af2e3dpassed Base Python job95210732393, Optional Neuro Readers job95210732329, and CI31965823863before generated implementation; FW2 and CIL1 remain closed. -
MARC2-VR4 deterministic readiness implementation: the new standard-library module exposes only
plan,qualify,inspect, andreadiness. It has no private cohort path, archive or neural reader, target interface, derivative builder, trainer, predictor, freezer, or scorer. One final generated qualification passed three success scenarios, a non-ready timeout shape, deterministic replay, and all 36 frozen mutations in 0.007059 seconds at 19,038,208-byte peak RSS. It processed 18,474 generated bytes, emitted a 5,184-byte report, retained zero output, and kept all real, private, neural, target, model, score, and claim counters at zero. This exact implementation still needs its commit and both remote jobs green before one machine-only readiness closeout. It has not frozen a real cohort or run FW2. -
MARC2-VR4 real machine-readiness result: exact implementation
9fdda31passed Base job95213934048, Optional job95213934126, and CI31967145837before one machine-only invocation. Three samples passed with normalized loads0.5421,0.5253, and0.4833, 18,055,168-byte peak RSS, and at least 158.86 GB free disk. The command wrote one 4,551-byte mode-0600 certificate and performed zero private path checks, content opens, archive reads, neural sample reads, target operations, model runs, predictions, or scores. This proves the bounded readiness mechanism works on the current machine. It did not inspect or freeze a cohort, and its expiring certificate is not authority for a later private executor; FW2 and CIL1 remain closed. -
MARC2-VR4P structural-pass request: readiness result
0a4a7fbpassed both jobs in CI31967501519. A new all-false Tier C packet now proposes one generated/mock implementation followed, only after its own green proof, by one 418,755-byte target-free structural read. It may safely remove only the exact expired 4,551-byte readiness certificate, obtain a fresh certificate, place a marker, and freeze the existing238 -> 195 + 43 -> 16 subjects / 96 bundles / 384 membersidentity. It authorizes nothing yet and permits zero network or archive-payload bytes, neural samples, targets, models, predictions, or scores. A fresh packet-bound maintainer decision is required. -
MARC2-VR4P packet-bound decision: request
a5b73d6passed Base job95215825208, Optional job95215825263, and CI31967933217before the maintainer's fresh eight-bytecontinue. The decision preserves that exact message and authorizes only the registered two-stage sequence by reference: first build and qualify an additive executor entirely on generated/mock fixtures, then, only after that exact implementation is remotely green, verify and remove the one expired readiness certificate, obtain fresh readiness, and perform one 418,755-byte structural pass. Decisioneac3726passed Base job95218521665, Optional job95218521647, and CI31969063955before implementation. Archive payloads, neural data, models, targets, prediction freezes, scores, and scientific claims remain closed. -
MARC2-VR4P generated executor: a new dependency-free, fixed-path executor validates the green decision and a distinct shared proof record, removes only the exact expired certificate, obtains fresh proof-bound readiness, and puts a mode-0600 marker immediately before one structural open. Two generated replays and 27 direct refusals completed in 0.107 seconds at 36,864,000-byte peak RSS, with 433,847 input bytes, 222,279 output bytes, zero retention, and zero real/private operations. The fresh certificate is included in the 4 MiB incremental-output accounting. Exact implementation
24f7379subsequently passed both CI jobs before the sole consumed structural pass. It did not read neural data, train a model, open targets, or produce a score. -
MARC2-VR4P consumed structural result: exact implementation
24f7379passed Base job95223010696, Optional job95223010631, and CI31970865212before the one registered pass. Fresh readiness and exact 418,755-byte source integrity succeeded, but the frozen VR2 adapter refused atMARC2MSP-F07before returning a cohort. The underlying predicate was not emitted and will not be reconstructed from private data. No archive member, neural sample, target, model, prediction, or score was touched. The attempt is consumed with no rerun; FW2 and CIL1 remain closed while an artifact-only prospective mismatch analysis is designed. Failure result6fa6865passed both jobs in CI31971526419. -
MARC2-VR5A artifact-only refusal localization: registration
926e1bapassed Base job95226555204, Optional job95226555153, and CI31972332778before the fixed AST/JSON audit. Exact implementationd9fa443then passed Base job95229811925, Optional job95229811955, and CI31973656275.MARC2VR5-R2proves that the VR4P catch discarded the nested VR2 route, reducing eight aggregate-safe diagnostic classes to one. It also proves that VR2 compares a live selection against nine exact generated outputs, including a fixed 16-subject count,8,105,207,776reservation bytes, and generated identity hash, while emitting generated source ID, proof posture, and hash vocabulary. The measured audit read 400,289 committed bytes in 1.593 seconds at 39,698,432-byte peak RSS and retained nothing. This is a proven integration defect, not proof that the consumed private run reached F06; its exact nested route remains unavailable. No private path, archive member, neural value, target, model, prediction, or score was accessed. The next safe step is a separately named generated-only live-selection invariant repair, not another private attempt. -
MARC2-VR6 dynamic live-selection implementation: registration
71d7cecpassed Base job95231605521, Optional job95231605469, and CI31974405202before implementation. The generated qualification spans prefixes of 12, 14, 16, 18, and all 19 eligible participants across both row orders. Real selected count, reservation bytes, and identity hash are measured outputs rather than generated expected constants. The contract preserves only an allowlisted upstream route code, enforces exact split and maximal-prefix arithmetic under the unchanged 8 GiB cap, and requires live source semantics. RouteMARC2VR6-G1passed ten replay paths and 34 direct refusals in 1.003502375 seconds at 40,435,712-byte peak RSS, processing 4,291,124 generated bytes and retaining zero. Exact implementation482dad5passed Base job95234487830, Optional job95234487789, and CI31975600088. No private, real-cohort, neural, target, model, score, FW2, or CIL1 operation is authorized; a future structural read remains a new Tier C packet and decision. -
MARC2-VR7P consumed structural result: exact wrapper
154852cpassed Base job95252133987, Optional job95252133958, and CI31982672176before the sole invocation. It crossed fresh machine readiness, wrote its consumed marker, read and SHA-256-verified exactly 418,755 target-free structural bytes once, strict-parsed them once, and called VR6 once. It then failed closed atMARC2VR7P-F07while preserving upstream VR6 routeMARC2VR6-F02, the branch for upstream VR2 validation refusal. The nested VR2 route, private predicate/value, candidate selection, and cohort were not retained and must not be inferred. VR7P is consumed with no retry or rerun; no archive member, neural payload, target, model, prediction, score, FW2, live decoding, or scientific claim was reached. Initial result recordae75423passed both jobs in CI31983281390without a second execution. -
MARC2-VR8A artifact-only boundary localization: registration
d33eaf3passed Base job95256950555, Optional job95256950656, and CI31984475999before implementation. The fixed 18-artifact audit reachedMARC2VR8A-R1: exact producer lineage excludes VR2 envelope route F02, so only F03 path/run-companion structure and F04 bundle/taxonomy arithmetic remain compatible. VR6 preserved the nested allowlisted VR2 route, but VR7P forwarded only the outer VR6 route. The generated VR2 success path also bypassed the exact full-scale producer, exposing the missing integration fixture. The audit read 587,523 committed bytes, used seven AST and eleven strict JSON parses, retained zero bytes, and performed no private, neural, target, model, score, network, FW2, or CIL1 operation. The exact F03/F04 private route remains unavailable and must not be inferred. Exact implementation/result1addd5dpassed both jobs in CI31986089529. -
MARC2-VR8B generated diagnostic relay result: registration
5607fe8passed Base job95263869003, Optional job95263869149, and CI31987093865before implementation. RouteMARC2VR8B-G1sends all 1,227 generated entries through the exact parser and live manifest producer before VR2/VR6, then preserves exact nested F02, F03, and F04 codes under canonical and reversed order. Two full replays visit 19,632 parser entries and pass all 16 gates plus 29 direct refusals in 2.421 seconds at 59,310,080-byte peak RSS, with 4,650,480 generated input bytes and zero retention or forbidden operations. The same 16-subject/96-bundle cohort has different upstream VR6 provenance hashes across source orders, so VR8B adds a separate order-neutral cohort digest without changing VR6. Local verification passes 3,948 dependency-light tests with 204 skips and the complete 4,019-test optional inventory with 35 skips in fresh processes, exactly 21 tests above the green registration baseline and with zero new failures. Exact implementationd7ce48bpassed Base job95271230358, Optional job95271230485, and CI31989817593. The consumed private F03/F04 route, cohort, neural payload, target, model, and score remain unavailable; another private read still needs a new green Tier C packet and fresh decision. -
MARC2-VR9P two-layer diagnostic result: the all-false packet binds 17 remotely green predecessor artifacts totaling 328,581 bytes, the exact 418,755-byte structural-manifest identity copied from committed records, one fresh readiness path, and one new output root. Request
de8e6dcpassed Base job95277554517, Optional job95277554619, and CI31992178980; proof closeoutddc5e85passed Base job95278576871, Optional job95278576905, and CI31992563746. After VR9P was identified as the sole active Tier C packet, the maintainer supplied the exact eight-byte messagecontinue. The separate decision preserves that message and incorporates only the unchanged green packet by reference. Decision4cdd3d3then passed Base job95280728093, Optional job95280728134, and CI31993388608before the additive fixed-path wrapper was built. Its generated qualification executes F03 and F04 in canonical and reversed order twice, makes exactly eight VR6 calls, and passes 70 direct refusal mutations. One measured run processed 3,407,792 generated source bytes in 1.2403 seconds at 63,799,296-byte peak RSS, emitted 6,541 aggregate bytes, and retained zero output. Exact implementation0dd113apassed Base job95285174846, Optional job95285174911, and CI31995078475before the sole private invocation. The run passed three readiness samples, read and strict-parsed 418,755 target-free structural bytes once, called VR6 once, and returned aggregate routeMARC2VR9P-R1: outerMARC2VR6-F02, nestedMARC2VR2-F03. That localizes the blocker to row-path, ZIP/BIDS, run-companion, or structural grouping and excludes F04 taxonomy/arithmetic for this exact execution. It does not reveal a predicate, value, row, path, identity, candidate, selection, or cohort. Runtime was 10.0448 seconds at 39,075,840-byte peak RSS with 6,674 combined output bytes; neural, target, model, training, prediction, score, network, and other-project counters were zero. VR9P is consumed with no retry or private reinspection. FW2 and CIL1 remain ineligible, and no neural effect or decoding performance was tested. -
MARC2-VR10A F03 predicate-decomposition result: artifact-only analysis partitions the exact F03 validator into 20 leaf classes. Committed producer guarantees and exact live aggregate counts exclude 15. The five unresolved source-dependent classes are the 1,024-byte member-name ceiling, suffix-bearing BIDS identity, the exact lowercase
task-freewilltoken, logical companion uniqueness across distinct prefixes, and completeness of each four-file run group. This is a possibility set, not a private-cause claim. The frozen generated-only matrix contains one success control and one witness for each unresolved class, canonical and reversed, replayed twice: 24 exact parser/producer/VR2/VR6 paths and 29,448 parser-entry visits under one thread, 30 seconds, 256 MiB peak RSS, 16 MiB generated input, and 1 MiB aggregate output. Registration80175a7passed both jobs in CI31997129703before implementation. LocalMARC2VR10A-G1then sent all six cases through the exact parser, producer, VR2, and VR6: four control paths succeeded and all 20 witness paths returned outer F02 plus nested F03. The two-replay pass used 6,979,708 generated bytes in 1.8364 seconds at 45,072,384-byte peak RSS, emitted 10,751 aggregate bytes, retained zero, and passed 47 direct refusals. All 31 focused and 4,042 complete local tests pass; exact implementation84103a5passed both jobs in CI31998811585. This narrows the next discriminator design but does not reveal the private cause. It authorizes no private read, consumed-state reuse, archive payload, neural signal, target, model, prediction, score, FW2/CIL1, or scientific claim. -
MARC2-VR10B five-route discriminator result: registration
d642eaepassed both jobs in CI32003674374before implementation. The standard- library classifier preserves frozen validator order and maps P03, P15, P16, P18, and P19 toMARC2VR10B-R1throughMARC2VR10B-R5, withMARC2VR10B-G1reserved for generated clean controls. Across the six exact- parser cases, canonical and reversed order, and two replays, all six routes appeared exactly four times. The pass completed 24 parser/producer paths, 24 VR6 calls, 24 discriminator calls, and 29,448 parser-entry visits; it passed 60 direct refusals, processed 6,979,708 generated bytes in 2.7258 seconds at 44,564,480-byte peak RSS, emitted 7,515 aggregate bytes, and retained zero. Thirty-two focused and all 4,074 base tests pass with 204 expected skips. Exact implementation/result61bb801passed both jobs in CI32007641751; no qualification or private operation was repeated for proof closeout. This is generated route-separation evidence only: there is no private executor, private cause, real cohort, neural payload, target, model, score, or decoding result. -
MARC2-VR11P private discriminator wrapper: an all-false packet binds 16 committed predecessor artifacts totaling 295,028 bytes and proposes the smallest future private diagnostic: one exact 418,755-byte target-free structural read, one VR6 consistency call, one VR10B classifier call, and one aggregate R1-R5 route. Fresh readiness/output paths, one-thread and 256 MiB caps, zero retries, and a recursive privacy ceiling are frozen. The exact request
6e72c8fpassed both jobs in CI32009557248, and proof closeout136f7b9passed both jobs in CI32011020786. After VR11P was identified as the sole active Tier C packet, the maintainer sentokay lets continue; decision4fa2771then passed both jobs in CI32038683203before Stage 1 began. The generated/mock wrapper now passes 24 exact VR6/VR10B paths and one temporary fixed-path state-machine pass. Every G1/R1-R5 route appears four times; 81 refusals pass. The measured run used 7,398,463 generated bytes in 3.424092 seconds at 63,619,072-byte peak RSS, emitted 7,268 aggregate bytes, and retained zero. Proof-state hardening commit2093ad5passed both jobs in CI32041540553; proof closeoute569bccthen passed both jobs in CI32041863346before one registered execution. The command read 418,755 target-free structural bytes once, called VR6 and VR10B once each, and consumed at aggregate R2, the frozen P15 suffix-bearing BIDS identity class. It used 34,701,312-byte peak RSS in 10.041579 seconds. No failed private value, candidate cohort, archive member, neural payload, target, model, prediction, or score was retained; FW2 and CIL1 remain closed. -
Causal Motor Lattice synthetic gate: contract commit
67709a3and exact implementation90fa467were separately green before one seed-5513 run of the 4,535-parameterCML-v0. The model reached1.0hand and key accuracy on all 16 constructed signal-bearing check rows, localized potential, mu, and beta factors under matching branch ablations, passed key-to-hand marginal consistency and zero-right-context future-tail checks, and replayed its checkpoint hash exactly. Eighteen of 19 check gates passed. Float32 common-mode key-logit error was1.9073486e-6, above the frozen1e-6tolerance, so the one run parked atCML-R0; synthetic final targets stayed closed and no rerun is permitted. Runtime was 6.553 seconds at 398,737,408 bytes peak RSS with 37,371 generated bytes. PhysioNet, Loop 54-B/C, S20, protected targets, model claims, hardware, and scientific promotion remain closed. -
Foundation-model decoder strategy: the product path now explicitly uses a compact causal sensor adapter as a bridge into frozen
gpt-5.6-sol, not as the final language model. Hosted Sol receives only CTC n-best text and compact causal key evidence because its API does not accept custom hidden embeddings. The matched matrix keepsFM-A00language-only,FM-A01CTC-only,FM-A02matched CTC plus neural evidence, andFM-A03fixed item-deranged evidence. FM-0 is now implemented as a deterministic no-call compiler: its committed 7,327-byte fixture produced 12 plans in 34,349 bytes, 0.00275 seconds, and about 21.5 MB peak RSS. The additive FM-1 qualification freezesgpt-5.6-terraas the lower-cost synthetic transport candidate while preserving Sol as the quality-first product candidate. Its contract, authorization, and implementation were remotely green before one live invocation. Three calls were attempted: language-onlyFM-A00abstained, CTC-onlyFM-A01returnedHELLO WURLD, and the first matchedFM-A02returned a non-completed provider status. The no-retry runner parked and preserved a 5,882-byte sanitized receipt after 8.406 seconds at 39,337,984 bytes peak RSS. Two completed responses used 339 input and 143 output tokens for a $0.002394 partial local estimate; usage and charge for the third attempt are unavailable. NoFM-A03response or matched-versus-deranged comparison exists. FM-1 is consumed with no rerun. Real rows, targets, scoring, training, fine-tuning, and scientific claim promotion remain closed. -
AI budget and local-first leverage: the user authorized a $50 aggregate AI-provider ceiling for the next R&D steps. The complete $0.50 FM-1 cap is conservatively reserved because usage for its non-completed third response is unavailable; the remaining $49.50 is divided into ceilings for an independent transport recovery, synthetic Sol/Terra controls, public target-free integration, later target-bearing work, protected evaluation, and contingency. These are release gates, not spending targets. Local work should reuse MNE for data/QC, MOABB for grouped public benchmarks, pyRiemann for serious low-data baselines, and compact Braindecode models before buying more inference. Apple application
US20230225659A1describes dynamic electrode selection in an earbud form and names EEG, but does not mention AirPods or prove a shipping thought-to-text product. A future generic ear-channel adapter begins with synthetic contact/noise fixtures; hardware, SDKs, purchases, participant recording, and commercial implementation remain separate. -
Loop 56 cross-modality accessibility research: the planning boundary freezes five verdict classes, a 12-level capability ladder, 18 comparison dimensions, 16 mandatory claim fields, 28 gates, 34 refusals, and a 12-part at-home conjunction. Published Brain2Qwerty v1/v2 evidence remains external; v2 continuous MEG is explicitly noncausal and cannot establish local EEG, latency, device, or home capability. The current provisional outcome is
L56-O2, mechanics and interfaces only. The final artifact-only verdict isNot Started, Loop 55 result dependent, and separately unauthorized; no raw or protected payload, target, prediction, checkpoint, model, score, device, or latency trace was opened or produced. Planning commit6583ca3passed push CI29586877054and PR #34 CI29586915269, with both required jobs green. -
Loop 30 planning research: the future product is a loopback-only target- free replay inspector. The boundary separates artifact, synthetic, recorded, and live source modes; freezes a 30-field trace, nine clocks, six latency levels, 18 gates, and 30 refusals; and requires fixed localhost, zero external browser traffic, explicit finalization, accessible status updates, and unavailable confidence. All 30 authorization flags remain false, no seed or payload exists, and the experiment is
Not Started. -
Loop 31 attribution result: exact-zero and timing-only components each passed at 6/6 wins and one-sided
p = 0.015625, but the complete registered conjunction failed against the prior and corrupted-signal controls. The partial wins are diagnostic only; sensor-signal dependence and brain-specific attribution were not established. The LLM/Neuro Token extension stayed closed. -
Loop 32 planning research: the fresh-person calibration firewall recommends one causal 32-parameter hidden affine adapter, four distinct zero-shot/unlabeled/label-light/supervised modes, six nested sentence budgets, 32/16/48 physical partition floors, six controls, 20 gates, and 26 refusals. All 22 authorization flags remain false, no candidate is selected, and the experiment is
Not Started; S25 remains final-only. -
Loop 33 bounded-scaling result: nested
8, 16, 24, 32, 44, 55unique-sentence prefixes, three fixed seeds, 18 candidate fits, and six matched priors ran inside the consumed event. All seed slopes were negative and the 8-to-55 descriptive gain was0.289202, but the 55-row candidate was still0.186942worse than its prior. The gate is parked with no scaling-law or acquisition claim. -
Loop 34 planning research: the confidence firewall separates seven semantics from raw ranking through product-visible confidence, eight score/control roles, and recommended fresh target-free synthetic calibration/selection/final counts of
128/64/256. It requires registered working points, generalized risk, bounded losses, revision-delay reporting, and one final-target open only after every choice and hash freezes. The six real validation rows cannot fit and independently qualify confidence. Twenty gates, 30 refusals, and 26 false authorization flags are machine checked. The experiment isNot Started; confidence is unavailable and all fixture, fit, target, scoring, product-confidence, and real-data work is unauthorized. -
Loop 35 planning research: the peripheral-confound firewall inventories ten shortcut classes and nine synchronized stream classes, then separates 13 timing, leakage-sentinel, peripheral, brain-sensor, residualized, and combined conditions across three independently authorized stages. Missing controls cannot be imputed as clean or synthetic. Twenty-four gates, 32 refusals, and 31 false authorization flags are machine checked. The experiment is
Not Started; current S21/S7 evidence cannot establish incremental brain-sensor information beyond recorded controls, absolute brain origin, or no-keypress and patient transfer. -
Loop 36 planning research: the geometry/reference firewall separates source and channel identity, signal and coordinate units, sensor/electrode geometry, directional rigid transforms, reference/ground, compensation, interpolation, and missingness. Only explicit bijective aliases, declared unit factors, and named right-handed transforms can preserve identity. Twenty-two gates, 30 refusals, and 29 false authorization flags are machine checked. The experiment is
Not Started; declared metadata compatibility, numerical compatibility, model transfer, and device equivalence remain distinct claims. -
Loop 37 planning research: the derivative/provenance firewall separates the stable BIDS 1.11.1 dataset envelope and file metadata from non-standard NeuroDecodeKit NPZ caches, split reports, report cards, and manifests. It freezes truthful BIDS URI handling, path/identifier redaction, no-raw-copy checks, 24 gates, 32 refusals, and 29 false authorization flags. The experiment is
Not Startedand unauthorized; no derivative tree, validator result, privacy/license qualification, or public release exists. -
Loop 38 planning research: the privacy/lifecycle firewall pins stable NIST PF 1.0, maps predictability/manageability/disassociability, and separates five sensitivity levels, eight artifact classes, ten copy surfaces, 12 sensitive- field classes, five deletion-receipt levels, and consent/license/release authority. Unknown backups, clones, PR refs, CI artifacts, and remotes remain unresolved. The experiment is
Not Startedand unauthorized; no fixture, scanner, deletion, protected-root scan, identity attack, history rewrite, consent determination, release, or upload exists. -
Loop 39 planning research: the cross-machine firewall separates seven qualification levels, 18 environment fields, eight output classes, six comparison classes, six required future cells, field-specific floating tolerances, and exact semantic identity. The experiment is
Not Startedand unauthorized. Current Python 3.10, macOS, cross-OS, lockfile, package-build, and independent-reproduction evidence remains unavailable; no fixture, manifest, CI matrix, install, build, protected read, model, training, edge, stream, device, or hardware operation exists. -
Loop 40 planning research: the deployment firewall separates the frozen float32 graph, exported graph, numeric payload, runtime/kernels, host causal state/timestamps/decoder, and named app/device envelope. ExecuTorch/XNNPACK is a research lead only beside ONNX Runtime Mobile, LiteRT, and Core ML; no backend or target is selected. The experiment is
Not Startedand unauthorized because the relevant Loop 39 matrix has not run. No install, export, conversion, package, inference, profiler, delegate, simulator, app, device, or hardware operation exists. -
Loop 41 planning research: the first proposed RW3-to-NeuroToken join now has a machine-checkable firewall for seven distinct clock views, eight anomaly classes, five schedules, five resume cuts, bounded state, and 18 provenance/hash bindings. The experiment remains
Not Startedand unauthorized: no source chunk, fixture, preprocessing run, adapter, token runtime, end-to-end latency measurement, live source, device, or scientific result exists. -
Loop 42 planning research: OpenBCI Cyton base 8-channel over USB radio is the one future mechanics candidate, with Daisy, Wi-Fi, cloud, targets, and models excluded. The Q0 boundary freezes exact firmware/host/configuration identity, packet and clock semantics, locality, battery-only safety, four separately authorized stages, 34 gates, and 46 refusals. No device is known to be present; there was no purchase, install, connection, stream, recording, participant contact, signal result, latency measurement, or decoding claim.
- The fixed real same-person cross-session MEG CTC is worse than the
no-signal prior: corpus CER
0.9179versus0.7755. - The real S7 EEG nearest-centroid classifier is worse than its train-only
no-signal prior:
0.91%versus12.27%exact key-label accuracy. - Loop 13 parks a lazy-backend migration because measured NPZ access did not justify building a second storage backend.
- Loop 23 parks a synthetic streaming CTC gate after missing its registered exact-sequence threshold, even though several secondary metrics passed.
- Loop 23.5 shows that one supervised blank-logit intercept fixes one fresh synthetic motif/symbol task. That is a mechanism result, not brain decoding.
- Loop 24 retains float32. Float16 passes correctness but misses every runtime replacement threshold; qint8 is smaller but fails correctness and runtime; the complete target-free gate parks on its 60-second orchestration cap.
- Loop 25 now has a passed causal-preprocessing mechanics result: the exact target-free path is causal with zero right context and passes anti-alias, timing, schedule, resume, mutation, access, and resource gates. It does not show that neural information survives preprocessing, and no rerun is open.
- Loop 26 has one consumed protected validation result, not a neural advantage. The candidate was worse than the no-signal prior; no rerun is authorized, and six sentences from one person and session cannot establish transfer or population generalization.
- Loop 27 identifies an acquisition candidate, not an acquired holdout. Exact channels, performed trials, sentence overlap, target freshness, transfer behavior, and one-time performance remain unavailable.
- Loop 28 defines a falsifiable strict zero-shot rule, not a transfer result. Brain2Qwerty v2's joint and target-finetuned evidence does not establish strict unseen-person zero-shot behavior, and one future S25 pass could not establish population generalization.
- Loop 29 defines the evidence needed to translate modalities, not a portable sensing result. Brain2Qwerty v2's 76/153/230-channel cryogenic ablations are not OPM-MEG or EEG device qualification, and repeated at-home EEG recording mechanics are not at-home text decoding.
- Loop 30 defines the evidence needed for a trustworthy replay interaction, not a running streaming decoder. A stable partial can be wrong, replay time is not capture time, and a localhost label without network and file-exposure QA is not a measured privacy result.
- Loop 31's consumed matrix failed its complete conjunction. Individual wins over zero and timing controls do not establish sensor-signal dependence; language gain, Neuro Token gain, and brain-specific origin remain unavailable.
- Loop 48 Stage B localizes the current failure to stable nonseparability for the registered causal and linear probe families, not to one of the four fixed timing offsets. The candidate still loses to the train-only prior, the rows are historically used development data, raw signal quality remains unresolved, and the result cannot be called validation or neural advantage.
- Loop 32 defines the evidence needed for honest one-person calibration, not a calibrated result. The 32-parameter adapter is a planning recommendation, unlabeled adaptation remains transductive rather than zero-shot, and one future participant could not establish population or device generalization.
There is no demonstrated:
- neural advantage on the real evaluated MEG or EEG cohorts;
- unseen-person generalization;
- useful open-vocabulary EEG sentence decoder;
- result on unreleased Brain2Qwerty v2 data or embeddings;
- end-to-end real-time text latency;
- portable, consumer, or at-home hardware result;
- arbitrary-thought decoding;
- clinical, diagnostic, or assistive efficacy.
S21 session 2, the S7 EEG evaluation, and synthetic test seeds 2203, 2303, and 2353 are consumed for the decisions they informed. They must not be reopened for tuning and then described as fresh evidence.
The detailed risk language lives in docs/RISK_AND_ETHICS.md.
The practical barrier to neural language-decoding research is often not the last model layer. It is everything before and around it:
- public neuroimaging releases can be hundreds of gigabytes;
- event and behavioral logs can use undocumented timing domains;
- participant aliases can invalidate nominal subject splits;
- preprocessing fit on evaluation rows can leak information;
- language priors can be credited to neural signal;
- a cache can silently lose channel, timing, geometry, or split identity;
- “causal,” “streaming,” “online,” and “real-time” are often collapsed;
- a successful file read can be overstated as device or decoding support.
NeuroDecodeKit turns those risks into explicit interfaces, counters, hashes, caps, tests, and report fields.
Python 3.10 or newer is required.
git clone https://github.com/CheickDiakite-yikes/neurodecodekit.git
cd neurodecodekit
python -m venv .venv
source .venv/bin/activate
python -m pip install --upgrade pip
python -m pip install -e .The base install has zero runtime dependencies. Exercise pure-Python metrics:
neurodecode eval-text \
--target "HOLA MUNDO" \
--prediction "HOLA MUNCO"Run the base-aware test suite:
PYTHONPATH=src python -m unittest discover -s tests -vTests for unavailable optional dependencies skip cleanly. A skipped optional test is not evidence that its MNE or Torch path passed.
Install only NumPy for synthetic shards and NPZ interfaces:
python -m pip install -e '.[array]'
neurodecode make-synthetic-shard \
--out cache/synthetic_tiny.npz \
--samples 64 \
--channels 8 \
--times 25
neurodecode load-cache \
--cache cache/synthetic_tiny.npz \
--metadata-out cache/synthetic_tiny.metadata.json
neurodecode report \
--cache cache/synthetic_tiny.npz \
--identity-smoke \
--out-json cache/synthetic_report.json \
--out-md cache/synthetic_report.md \
--run-name synthetic_identity_plumbing \
--split synthetic-smoke--identity-smoke copies targets to predictions to prove report plumbing. It
is deliberately labeled as not a model result.
Install only what the task needs:
| Extra | Adds | Typical use |
|---|---|---|
array |
NumPy | synthetic shards, NPZ caches, NeuroToken interfaces |
neuro |
MNE 1.12.x, NumPy, SciPy | format readers, bounded signal inspection, extraction |
ml |
NumPy, scikit-learn, Torch | optional small baselines and synthetic learned gates |
hf |
Hugging Face Hub | metadata listing and explicit selective download |
cache |
Zarr, numcodecs, NumPy | measured storage-backend experiments |
demo |
Gradio | local artifact-backed evidence console |
dev |
Ruff, pytest | contributor checks |
all |
all optional groups | full local development; large |
Examples:
python -m pip install -e '.[neuro,dev]'
python -m pip install -e '.[array,demo]'Heavy imports remain inside the commands that need them. Adding an optional
feature should not make import neurodecodekit import MNE, NumPy, or Torch.
You can contribute without uploading the recording.
The project is moving toward a local-first cohort federation: contributors
would validate source identity, geometry, timing, trials, splits, controls, and
resources on their own machines, then share a hash-bound aggregate receipt
rather than raw EEG or plaintext targets. That direction is researched but not
implemented or authorized for real-data aggregation yet. See
docs/OPEN_EEG_R_AND_D_STRATEGY_2026-08-06.md.
- Read CONTRIBUTING.md, especially I Have EEG Data.
- Open the EEG data compatibility issue form.
- Share only non-sensitive aggregate facts: format, device family, nominal channels/rate, reference availability, task cohort, license, and byte cap.
- Run metadata-only intake locally.
- Reproduce the relevant format condition with a deterministic synthetic fixture.
- Request a separately frozen bounded real-read protocol only if the synthetic gate passes and the data terms permit it.
Do not attach raw EEG, event files, target text, participant tables, private cloud links, derived embeddings, or subject-level predictions to an issue.
The base command inspects structure without opening binary signal samples or event/target content:
neurodecode inspect-recording \
--path /absolute/path/to/recording-or-bids-root \
--root /absolute/path/to/allowed-root \
--out-dir /absolute/path/to/private/intake-report \
--modality EEG \
--device-type "your device or amplifier"
neurodecode inspect-intake-report \
--report /absolute/path/to/private/intake-report/intake.jsonThe output includes deterministic JSON/Markdown plus a measured audit sidecar, relative source identity, companion validation, known/unavailable fields, warnings, access counters, hashes, runtime, RSS, and output bytes.
Review it locally before sharing. Metadata can still be sensitive.
| Level | Evidence |
|---|---|
| 0 | File family and companions recognized |
| 1 | Bounded samples readable |
| 2 | Channels, timing, units, geometry status, and aggregate events validated |
| 3 | Deterministic preprocessing/replay validated |
| 4 | Leakage-resistant classification beats registered controls |
| 5 | Sequence metrics beat no-signal controls on a fresh split |
| 6 | Live/replay timing and end-to-end behavior measured |
A level applies only to the exact format, adapter, configuration, and evidence cohort tested. It does not transfer automatically to another headset, dataset, task, subject, or session.
Use the EEG hardware qualification issue form. Include:
- model, revision, firmware, SDK, and operating system;
- EEG/ExG channel roles, electrode placement, reference, and ground;
- nominal and measured sampling rate;
- raw API or file export;
- USB, serial, BLE, Wi-Fi, LSL, XDF, or cloud transport;
- timestamp clock, correction, packet counter, and packet-loss behavior;
- local/offline capability and SDK license;
- separate peripheral streams such as EOG, EMG, PPG, IMU, gaze, or audio.
The preferred first result is offline replay equivalence on deterministic samples. A connected device or live waveform plot is not a language decoder. Four-channel consumer EEG is not assumed equivalent to 64-channel research EEG or 306-channel MEG.
Replay and hardware contributions must begin from the frozen RW3 preregistration and machine contract. The Stage A authorization packet and its machine request make the next permission exact, but both still say that Stage A is unauthorized. A hardware contribution, issue, or pull request cannot substitute for that decision; each runtime stage requires a separate review.
The current metadata device registry is registries/devices.v0.json. Registry presence is not device qualification.
This workflow requires .[neuro], reads no participant data, and creates less
than the frozen 16 MiB fixture/report cap:
export OMP_NUM_THREADS=1
export OPENBLAS_NUM_THREADS=1
export MKL_NUM_THREADS=1
export NUMEXPR_NUM_THREADS=1
export VECLIB_MAXIMUM_THREADS=1
neurodecode make-signal-quality-fixtures \
--out-dir cache/rw2-fixtures \
--contract registries/signal_quality_contract.v0.json
neurodecode inspect-signal-quality-fixtures \
--manifest cache/rw2-fixtures/signal_quality_fixtures.json
neurodecode inspect-signal-quality \
--path cache/rw2-fixtures/fixtures/clean_multitype_continuous__fif/source/recording_raw.fif \
--root cache/rw2-fixtures \
--intake-report cache/rw2-fixtures/fixtures/clean_multitype_continuous__fif/intake/intake.json \
--fixture-manifest cache/rw2-fixtures/signal_quality_fixtures.json \
--contract registries/signal_quality_contract.v0.json \
--out-dir cache/rw2-quality
neurodecode inspect-signal-quality-report \
--report cache/rw2-quality/signal_quality.jsonRW2 reports descriptive time-domain and Welch PSD summaries, units, geometry availability, reference status, aggregate annotation status, source filters and projectors, bounded windows, access counts, resource measurements, warnings, and no-mutation identity. It performs no filtering, rereferencing, bad-channel repair, interpolation, ICA, clipping, scaling, model run, or training.
RW2 is a synthetic reader and report-interface proof. It says nothing about the quality of a person's recording.
Build and inspect a manifest from an existing path list:
neurodecode manifest-from-paths \
--paths data/file_list.txt \
--out data/manifest.jsonl
neurodecode inspect-manifest \
--manifest data/manifest.jsonl
neurodecode select-tiny \
--manifest data/manifest.jsonl \
--out data/tiny_selection.json \
--modality EEG \
--blocks 1 \
--max-files 4 \
--max-total-gb 1select-tiny records exact paths, known bytes, unknown-size warnings,
revision, and caps.
Hugging Face access is optional:
python -m pip install -e '.[hf]'
neurodecode download-selection \
--selection data/tiny_selection.json \
--local-dir data/spanishbcbl_tinyThat command does not download by default. --execute is required, unknown
sizes fail closed unless explicitly allowed after review, and the default worker
count is one.
Do not use this example as authorization to download SpanishBCBL. Check the dataset license, exact revision, local disk, protocol, and approval boundary.
For an explicitly acquired, legally usable, validated FIF/MAT pair:
python -m pip install -e '.[neuro]'
neurodecode extract-windows \
--raw data/spanishbcbl_tiny/.../block1.fif \
--events data/spanishbcbl_tiny/.../logs.mat \
--out cache/b2qmini_s1_block1.npz \
--sfreq 50 \
--tmin -0.2 \
--tmax 0.3 \
--picks meg \
--max-events 200This command does not download data. It reports source bytes, events found, kept and dropped events, shape, rate, channels, parser warnings, runtime, and output bytes.
Generic MAT schemas do not inherit the validated S21 trial-ordering claim.
Run the no-brain comparator before interpreting a neural model:
neurodecode prior-baseline \
--cache cache/synthetic_tiny.npz \
--out-predictions cache/prior_predictions.txt \
--out-json cache/prior_report.json \
--out-md cache/prior_report.md \
--run-name synthetic_prior \
--split synthetic-smoke
neurodecode template-baseline \
--cache cache/synthetic_tiny.npz \
--train-fraction 0.5 \
--out-predictions cache/template_predictions.txt \
--out-json cache/template_report.json \
--out-md cache/template_report.md \
--run-name synthetic_template \
--split synthetic-holdoutSynthetic separability proves plumbing and model mechanics only. A real neural result must use train-only fitting, frozen split identity, a no-signal prior, and uncertainty appropriate to the evaluation unit.
The CLI intentionally exposes small auditable stages:
| Area | Commands |
|---|---|
| Text metrics/reports | eval-text, report, build-leaderboard |
| No-signal/small baselines | prior-baseline, sentence-prior-baseline, template-baseline, tiny-conv-baseline |
| Discovery/download | manifest-from-paths, inspect-manifest, select-tiny, list-hf-files, download-selection |
| Local intake | inspect-recording, inspect-intake-report |
| Synthetic quality | make-signal-quality-fixtures, inspect-signal-quality-fixtures, inspect-signal-quality, inspect-signal-quality-report |
| Event/sentence extraction | extract-windows, extract-eeg-windows, extract-sentence-cache, align-sequences |
| Cache interfaces | make-synthetic-shard, load-cache, make-synthetic-sentence-cache, inspect-sentence-cache, make-neurotoken-cache, inspect-neurotoken-cache |
| Split/session controls | split-protocol, apply-frozen-scaler, cross-session-ctc |
| Resource experiments | sampling-rate-sweep, channel-subset-sweep, precision-storage-sweep, inspect-representation-cache, lazy-backend-gate |
| Synthetic causal gates | causal-replay-gate, make-causal-motif-fixture, tiny-causal-encoder-gate, make-ctc-symbol-stream-fixture, streaming-ctc-gate, make-blank-calibration-fixture, blank-intercept-gate |
| Research/demo | eeg-bridge-gate, synthetic-adapter-gate, synthetic-calibration-curve, demo |
Use neurodecode COMMAND --help for exact arguments and safety defaults.
src/neurodecodekit/
datasets/ manifests, local intake, safe selection, optional Hub access
preprocess/ format readers, event alignment, window/sentence extraction
cache/ NPZ schemas, packed representations, NeuroToken interfaces
models/ prior, template, tiny Conv/CTC, causal encoder components
training/ deterministic synthetic fixtures and bounded runners
evaluation/ CER/WER, controls, reports, splits, uncertainty, report cards
experiments/ preregistered resource, session, causal, and EEG gates
demo/ artifact-backed local evidence console
The CLI defers heavy imports into individual commands. Source modules use strict schemas and dataclasses where structured records cross boundaries.
An event cache stores:
windows [events, channels, timepoints]
labels per-event labels when validated
event_start_sec event timing
event_source_index source row or trigger identity
channel_names ordered selected channels
metadata schema, source, transforms, warnings, hashes
Sentence caches preserve variable true lengths, trial identity, target/response provenance, source sampling rate, channel order, geometry availability, split binding, fit scope, and transformation history.
NeuroTokenCache is shaped [items, time, embedding] and preserves:
- modality and device type;
- item, subject, session, trial, and split identities;
- source rate and token timestamps;
- true lengths and padding masks;
- channel names and available geometry;
- causal/noncausal status and required context;
- source-cache, split-protocol, configuration, and payload hashes;
- warnings, unavailable fields, access counters, and claim boundaries.
The current Loop 20 producer is a deterministic target-free projection from synthetic signals. It is not a learned representation or decoding result.
NeuroDecodeKit separates:
- language-only priors from neural models;
- train/validation/test/calibration membership;
- split membership from preprocessing fit scope;
- event classification from sentence decoding;
- within-recording, cross-session, and unseen-person evidence;
- EEG from MEG and peripheral modalities;
- producer causality from decoder causality;
- intrinsic context, transport delay, compute time, and end-to-end latency;
- synthetic mechanisms from real-data results;
- fresh tests from consumed evaluations.
Every report should name the dataset/revision, task, modality, subject/session scope, split, fit rows, metrics, controls, runtime, RSS, input/output bytes, access counts, warnings, and unavailable fields.
CER and WER are not enough by themselves. Tiny test sets need paired examples and uncertainty; key-event tasks may need exact label accuracy; sequence tasks need blank/repeat diagnostics and exact-sequence counts.
Neural recordings and derived features are sensitive, even when filenames are de-identified.
- Raw data and caches are ignored by Git.
- Reports should use relative identity and hashes, not absolute paths.
- Participant rows, free-text annotations, target sentences, serial numbers, exact acquisition timestamps, and exact head/sensor coordinates are omitted from shareable intake/quality reports.
- Prediction/error reports can reveal typed text and should remain local unless dataset terms and disclosure have been reviewed.
- Hashes are integrity tools, not anonymization.
- Do not attempt participant identification.
See SECURITY.md for private reporting and docs/RISK_AND_ETHICS.md for the complete scope.
The repository is designed for bounded local work:
- one worker/thread where applicable;
- dry-run downloads by default;
- explicit file and byte caps;
- no full SpanishBCBL download;
- optional dependencies;
- small synthetic fixtures;
- measured runtime, peak RSS, input bytes, output bytes, and access counts;
- no new backend or larger model without a measured reason.
RW2 freezes at most 512 selected channels, three windows, 4,194,304 channel-sample values, 32 MiB of materialized float64 arrays, 30 seconds, 1 GiB peak RSS, 4 MiB of report output per run, and 16 MiB for the complete synthetic fixture/report set.
Loop 24 used one numerical thread and one sequential worker at a time, 48 target-free items per partition, 455,472 working-array bytes, 262,822 total generated bytes, and at most 222,248,960 worker-RSS bytes. It stayed below every storage, memory, concurrency, and access cap but took 65.154951 seconds against the frozen 60-second runtime cap. Seed 2401 is consumed; seed 2402 remains unopened and closed. Real data, targets, training, energy, RW3, and hardware remain outside the gate.
Generated artifacts belong in ignored cache/ or outputs/, not in Git.
The original numbered development sequence has reached:
- Loops 1-12: completed;
- Loop 13: parked after measured lazy-backend gate;
- Loops 14-22: completed at their exact proof boundaries;
- Loop 23: parked after the frozen synthetic decoder test missed its primary threshold;
- Loop 23.5: completed as a supervised synthetic calibration mechanism;
- Loop 24: parked after one registered target-free selection at implementation
commit
3a5dc0b; float32 is retained, no replacement or storage-only candidate passed, seed 2401 is consumed, seed 2402 qualification stayed unopened, and runtime was 65.154951 seconds versus the 60-second cap; - Loops 25-44: a primary-source-informed tranche spans causal
evidence, translation/generalization, reliability/confounds,
reproducibility/local deployment, and live translation/release. Loop 25 is
complete after one registered target-free execution: authorization commit
1e7296aand implementation commit439f151were remotely green before the static, development, and conditional qualification gates passed. Its current execution flag is false because no rerun is authorized. Loop 26/31/33 share the green preregistration at881145dand authorization at1c0e52c; the one six-target event is consumed and all three registered gates are parked after the candidate lost to the no-signal prior. All execution flags are now false and no rerun is open. Loop 27 planning research is green atb3d61b6and selects S25 metadata, while preregistration and acquisition remain blocked. Loop 28 planning research defines the strict zero-shot final-only rule while its experiment remainsNot Started. Loop 29 planning research at green commitf5fc740defines a local-first EEG lane, a partner/lab OPM-MEG lane, and a bounded 5-10 GB capacity envelope while its experiment remainsNot Started. Loop 30 planning research now freezes the local target- free replay interaction boundary while its experiment remainsNot Started. Loop 31's encoder conditions were scored in the consumed shared event and failed their complete conjunction; its contingent five-condition LLM extension remained closed. Loop 32 planning research defines a causal 32-parameter adapter, four calibration modes, and physically separate calibration/selection/final evidence while its experiment remainsNot Started. Loop 33 planning research defines the bounded8, 16, 24, 32, 44, 55unique-sentence curve, one target-blind shared validation event, and no acquisition now; the curve executed once and failed because its 55-row model remained worse than the matched prior. Loop 34 planning research defines the three-way confidence, abstention, and revision firewall while its experiment remainsNot Startedand confidence is unavailable; Loop 35 planning research defines the staged peripheral-confound firewall while its experiment remainsNot Started; Loop 36 planning research defines the geometry/ reference identity firewall while its experiment remainsNot Started; Loop 37 planning research defines the BIDS-envelope/non-standard-payload firewall while its experiment remainsNot Started; Loop 38 planning research defines the privacy/lifecycle and deletion-claim firewall while its experiment remainsNot Started; Loop 39 planning research defines the environment, semantic-identity, and numerical-tolerance firewall while its experiment remainsNot Started; Loop 40 planning research defines the edge-package, host-state, fallback, complete-cost, and target-identity firewall while its experiment remainsNot Started; Loop 41 planning research defines the stream-to-NeuroToken clock, anomaly, state, schedule, and provenance firewall while its experiment remainsNot Startedand unauthorized; Loop 42 planning research selects the exact OpenBCI Cyton 8-channel USB-radio path for future mechanics only while its experiment remainsNot Startedand unauthorized; Loop 43 planning research defines the independent artifact-reproduction firewall while its challenge remainsNot Startedand unauthorized. Loop 44 artifact-only planning is complete; its engineering release is held and scientific performance release is parked. All 20 current execution flags are false. Loop 25's mechanics closeout satisfies that dependency only; the Loop 26 request and every later experiment remain unauthorized.
The parallel Real-World Practice track has reached:
- RW0: primary-source dataset/device research and bounded acquisition planning;
- RW1: dependency-free metadata-only local intake, fixture-backed;
- RW2: bounded synthetic signal-read and descriptive quality-report interface, fixture-backed;
- RW3: replay/live-source equivalence preregistered at
c3d1f01; the Stage A decision packet is ready for explicit review, while Stage A and all runtime adapters remain unauthorized; - RW4+: not authorized by RW3 registration;
- proposed S20 acquisition: dry-run only until exact approval.
The next tranche is a claim graph, not a feature wish list. A failed real validation gate parks model scaling; a failed neural ablation blocks neural attribution; a failed replay gate blocks device work. Negative results remain valid closeouts. Roadmap approval and general continuation are not execution authorization.
See docs/POST_20_ROADMAP.md and docs/LOOPS_25_44_ROADMAP.md, plus the separate real-world practice track.
| Document | Purpose |
|---|---|
| START_HERE.md | shortest current orientation |
| docs/CODEX_HANDOFF.md | exact continuation boundary for coding agents |
| docs/RESEARCH_AUTONOMY_CHARTER_DRAFT.md | byte-identical approved charter snapshot defining autonomous Tier A/B work and exact Tier C stops |
| docs/RESEARCH_AUTONOMY_CHARTER_DECISION.md | exact maintainer approval, frozen charter hashes, standing resource envelope, and nonretroactive Tier C boundary |
| docs/BUILD_NOTES.md | chronological measured build journal |
| docs/DECISIONS.md | consequential architecture and research decisions |
| docs/MARC_2_LIVE_SELECTION_RECOVERY_IMPLEMENTATION.md | native FW1C wrapper, distinct FW1B certificate, exact shared-validator chain, 90-mutation qualification, resources, and closed private/scientific boundary |
| registries/marc2_live_selection_recovery_implementation.v0.json | machine-readable native FW1C implementation, frozen source/output identity, qualification metrics, zero access counters, and remote-green next gate |
| registries/marc2_live_selection_recovery_proof_certificate.v0.json | distinct 15-field FW1B-format certificate binding the recovery wrapper, native registry, tests, decision, shared validator, and selector |
| docs/MARC_2_LIVE_SELECTION_RECOVERY_RESULT.md | consumed one-read source-identity failure, exact resources and counters, unavailable private detail, no-rerun disposition, and claim boundary |
| registries/marc2_live_selection_recovery_failure_result.v0.json | aggregate machine result binding green proof, report identity, one-open counters, MARC2FWC-F02, zero forbidden operations, and closed FW2 authority |
| docs/MARC_2_SOURCE_SCHEMA_LINEAGE_AUDIT.md | exact producer-versus-consumer transport-key diagnosis, why generated tests missed it, measured artifact-only audit, and prospective one-way adapter design |
| registries/marc2_source_schema_lineage_result.v0.json | machine-readable MARC2SL-R2 result, exact key sets, source-binding proof, zero forbidden counters, and closed live/FW2 boundary |
| docs/MARC_2_TRANSPORT_ALIAS_ADAPTER_PREREGISTRATION.md | frozen generated-only producer-native adapter design, mutation matrix, selector integration target, resources, and closed live boundary |
| registries/marc2_transport_alias_adapter_contract.v0.json | machine-readable MARC2-TA1 contract binding green lineage proof, exact vocabularies, 26 mutations, three-command surface, and zero live authority |
| docs/MARC_2_TRANSPORT_ALIAS_ADAPTER_IMPLEMENTATION.md | generated-only adapter implementation, validation order, exact selector replay, measured qualification, verification, and scientific boundary |
| registries/marc2_transport_alias_adapter_implementation.v0.json | hash-bound adapter code, tests, generated result, resources, zero forbidden counters, and remote-green gate |
| registries/marc2_transport_alias_adapter_result.v0.json | machine-readable consumed MARC2TA-G1 result, 26 mutation routes, exact measurements, unavailable fields, and closed live/FW2 disposition |
| docs/MARC_2_LIVE_SCHEMA_ADAPTER_PREREGISTRATION.md | frozen generated/mock live-envelope composition, four-value bridge, 30-mutation matrix, resources, and closed private boundary |
| registries/marc2_live_schema_adapter_contract.v0.json | machine-readable MARC2-LA1 contract binding green TA1, exact live identity, generated-only surface, and zero authority flags |
| docs/MARC_2_LIVE_SCHEMA_ADAPTER_IMPLEMENTATION.md | generated composition implementation, validation order, one-call green adapter proof, measured qualification, verification, and claim ceiling |
| registries/marc2_live_schema_adapter_implementation.v0.json | hash-bound module/tests, 30 refusal results, resources, zero access counters, and exact remote-green proof |
| registries/marc2_live_schema_adapter_result.v0.json | consumed generated MARC2LA-G1 result, exact selector replay, measurements, unavailable fields, and closed live/FW2 disposition |
| docs/MARC_2_LIVE_ADAPTER_RECOVERY_AUTHORIZATION_PACKET.md | all-false MARC2-LA2 proposal for one additive executor and one exact structural read, with proof order, resources, routes, and explicit exclusions |
| registries/marc2_live_adapter_recovery_authorization_request.v0.json | machine-readable all-false LA2 request binding green LA1, consumed FW1C, one literal private source, zero authority, and the fresh-decision gate |
| docs/MARC_2_LIVE_ADAPTER_RECOVERY_AUTHORIZATION_DECISION.md | exact short-form maintainer decision bound to green LA2 request proof, two remote-green barriers, one-shot scope, resources, and claim ceiling |
| registries/marc2_live_adapter_recovery_authorization_decision.v0.json | machine-readable eight-byte decision quote, artifact hashes, conditional authority, zero operation counters, and delayed-effect gate |
| docs/MARC_2_LIVE_ADAPTER_RECOVERY_IMPLEMENTATION.md | additive one-shot executor design, generated proof qualification, exact remote-green barrier, resource measurements, and closed payload boundary |
| registries/marc2_live_adapter_recovery_implementation.v0.json | hash-bound LA2 implementation identity, 24 executor refusals, zero-access counters, and exact generated replay |
| docs/MARC_2_LIVE_ADAPTER_RECOVERY_RESULT.md | consumed 418,755-byte structural pass, aggregate F02 refusal, zero-selection result, measured resources, and no-rerun boundary |
| registries/marc2_live_adapter_recovery_failure_result.v0.json | machine-readable consumed LA2 result, green proof, one-open counters, unavailable predicate, and closed FW2 disposition |
| docs/MARC_2_VALIDATION_COVERAGE_LOCALIZATION.md | artifact-only explanation of the 43-run and 172-companion fixture gap, validator ordering defect, remaining unknowns, and prospective repair |
| registries/marc2_validation_coverage_localization_contract.v0.json | fixed nine-input VL1 audit contract, route logic, resource caps, candidate boundary, and zero private authority |
| registries/marc2_validation_coverage_localization_result.v0.json | machine-readable MARC2VL-R2 result, exact coverage arithmetic, AST anchors, zero forbidden counters, and claim ceiling |
| docs/MARC_2_VR2_REFUSAL_LOCALIZATION_PREREGISTRATION.md | frozen artifact-only VR5A questions, fixed inputs, route classes, dynamic-selection repair boundary, and zero private authority |
| registries/marc2_vr2_refusal_localization_contract.v0.json | hash-bound eleven-input VR5A contract, eight-route accounting, nine generated-selection fields, resource caps, and claim ceiling |
| docs/MARC_2_VR2_REFUSAL_LOCALIZATION_IMPLEMENTATION.md | measured MARC2VR5-R2 audit, wrapper diagnostic loss, live-selection overconstraint, unavailable private predicate, and smallest repair |
| registries/marc2_vr2_refusal_localization_implementation.v0.json | standard-library module surface, exact AST/JSON measurements, zero forbidden counters, and remote-proof gate |
| registries/marc2_vr2_refusal_localization_result.v0.json | machine-readable route collapse and generated-selection diagnosis with exact measurements and no scientific promotion |
| docs/MARC_2_DYNAMIC_LIVE_SELECTION_PREREGISTRATION.md | frozen VR6 dynamic-prefix hypothesis, five generated reservation regimes, aggregate route preservation, resource caps, and private-access boundary |
| registries/marc2_dynamic_live_selection_contract.v0.json | hash-bound generated-only VR6 policy for dynamic measured outputs, live source semantics, ten replay paths, and at least 24 mutations |
| docs/MARC_2_DYNAMIC_LIVE_SELECTION_IMPLEMENTATION.md | generated-only VR6 module, five measured selection boundaries, 34 refusals, resources, verification, and next evidence gate |
| registries/marc2_dynamic_live_selection_implementation.v0.json | hash-bound module surface, dynamic invariants, measured qualification, zero-access counters, and exact green implementation proof |
| registries/marc2_dynamic_live_selection_result.v0.json | machine-readable MARC2VR6-G1 replay profiles, refusal coverage, resources, warnings, unavailable fields, and no-science ceiling |
| docs/MARC_2_DYNAMIC_PRIVATE_SELECTION_RECOVERY_AUTHORIZATION_PACKET.md | all-false VR7P two-stage request, new fixed paths, dynamic cohort invariants, one-open boundary, resources, prohibitions, and claim ceiling |
| registries/marc2_dynamic_private_selection_recovery_authorization_request.v0.json | machine-readable VR7P green predecessors, fixed artifacts, future state machine, zero counters, and fresh-decision requirement |
| docs/MARC_2_DYNAMIC_PRIVATE_SELECTION_RECOVERY_AUTHORIZATION_DECISION.md | packet-bound VR7P short-form decision, delayed effect, exact two-stage order, dynamic cohort boundary, resources, and no-neural ceiling |
| registries/marc2_dynamic_private_selection_recovery_authorization_decision.v0.json | machine-readable fresh continue, immutable request/proof bindings, conditional authority, zero decision counters, and next remote-green gate |
| docs/MARC_2_DYNAMIC_PRIVATE_SELECTION_RECOVERY_IMPLEMENTATION.md | additive VR7P wrapper, dynamic cohort boundary, 85 refusals, measured resources, exact proof order, and no-neural ceiling |
| registries/marc2_dynamic_private_selection_recovery_implementation.v0.json | machine-readable fixed paths, state machine, generated qualification, resource caps, zero real counters, and remote-green gate |
| registries/marc2_dynamic_private_selection_recovery_proof.v0.json | distinct shared-validator proof record binding the exact wrapper, tests, docs, registry, decision, and green dependencies |
| docs/MARC_2_DYNAMIC_PRIVATE_SELECTION_RECOVERY_RESULT.md | consumed VR7P route, proven state-machine boundary, explicit unavailable values, no-rerun disposition, and no-neural ceiling |
| registries/marc2_dynamic_private_selection_recovery_failure_result.v0.json | machine-readable MARC2VR7P-F07 plus upstream MARC2VR6-F02, one-read counters, zero forbidden operations, and closed FW2 gate |
| docs/MARC_2_VR6_VR2_BOUNDARY_LOCALIZATION_PREREGISTRATION.md | frozen VR8A fixed-artifact questions, eight-route accounting, producer-lineage test, fixture boundary, and zero private authority |
| registries/marc2_vr6_vr2_boundary_localization_contract.v0.json | hash-bound 17-artifact VR8A contract, resource caps, three honest routes, prohibitions, and claim ceiling |
| docs/MARC_2_VR6_VR2_BOUNDARY_LOCALIZATION_IMPLEMENTATION.md | measured MARC2VR8A-R1 audit, F02 exclusion, remaining F03/F04 boundary, relay-loss trace, fixture gap, and next repair |
| registries/marc2_vr6_vr2_boundary_localization_implementation.v0.json | machine-readable fixed reader surface, measured resources, localization facts, zero counters, and remote-proof gate |
| registries/marc2_vr6_vr2_boundary_localization_result.v0.json | machine-readable R1 result, exact artifact bindings, F03/F04 uncertainty, warnings, and no-science ceiling |
| docs/MARC_2_GENERATED_DIAGNOSTIC_RELAY_PREREGISTRATION.md | frozen VR8B full-scale generated parser/producer relay, F02/F03/F04 matrix, privacy firewall, caps, and private-access boundary |
| registries/marc2_generated_diagnostic_relay_contract.v0.json | hash-bound 17-input VR8B contract, exact route relay, replay/mutation gates, all-false authority, and no-science ceiling |
| docs/MARC_2_GENERATED_DIAGNOSTIC_RELAY_IMPLEMENTATION.md | exact full-scale composition path, two-layer route relay, order-normalized cohort identity, measured resources, and remote-proof gate |
| registries/marc2_generated_diagnostic_relay_implementation.v0.json | machine-readable VR8B module surface, artifact hashes, 16-path qualification, 29 refusals, zero counters, and proof status |
| docs/MARC_2_GENERATED_DIAGNOSTIC_RELAY_RESULT.md | measured MARC2VR8B-G1 result, F02/F03/F04 relay, order-provenance insight, explicit unknowns, and next evidence gate |
| registries/marc2_generated_diagnostic_relay_result.v0.json | machine-readable route matrix, parser mechanics, resource measurements, refusal coverage, warnings, and no-science ceiling |
| docs/MARC_2_TWO_LAYER_PRIVATE_DIAGNOSTIC_AUTHORIZATION_PACKET.md | all-false VR9P request for one proof-gated F03-versus-F04 structural diagnostic, with exact two-stage barriers, privacy firewall, caps, and no-science ceiling |
| registries/marc2_two_layer_private_diagnostic_authorization_request.v0.json | machine-readable VR9P scope, predecessor hashes, immutable source identity, fresh paths, all-false authority, zero counters, and fresh-decision protocol |
| docs/MARC_2_TWO_LAYER_PRIVATE_DIAGNOSTIC_AUTHORIZATION_DECISION.md | exact eight-byte maintainer decision, delayed effect, generated/private green barriers, output firewall, resources, and no-science ceiling |
| registries/marc2_two_layer_private_diagnostic_authorization_decision.v0.json | machine-readable VR9P request/proof hashes, short-form decision, conditional authority, fixed paths, F03/F04 route contract, zero counters, and next gate |
| docs/MARC_2_TWO_LAYER_PRIVATE_DIAGNOSTIC_IMPLEMENTATION.md | generated-qualified fixed-path wrapper, measured F03/F04 replay, route-only firewall, private state machine, resources, and exact green gate |
| registries/marc2_two_layer_private_diagnostic_implementation.v0.json | machine-readable VR9P implementation surface, artifact hashes, generated metrics, fixed identities, zero counters, and private-access boundary |
| registries/marc2_two_layer_private_diagnostic_proof.v0.json | shared-validator proof record over 22 exact tracked artifacts with all private and scientific authority false |
| docs/MARC_2_TWO_LAYER_PRIVATE_DIAGNOSTIC_RESULT.md | consumed MARC2VR9P-R1 result, F03 localization, measured one-read boundary, explicit unknowns, no-rerun disposition, and no-science ceiling |
| registries/marc2_two_layer_private_diagnostic_result.v0.json | machine-readable outer F02 plus nested F03 route, one-read counters, resource measurements, privacy firewall, and closed FW2/CIL1 gates |
| docs/MARC_2_F03_PREDICATE_DECOMPOSITION_PREREGISTRATION.md | frozen VR10A 20-leaf F03 partition, five unresolved source-dependent predicates, six-case generated witness matrix, caps, and no-science boundary |
| registries/marc2_f03_predicate_decomposition_contract.v0.json | hash-bound 14-input VR10A contract, exact 15/5 partition, 24 generated paths, 12 acceptance gates, all-false authority, and next proof boundary |
| docs/MARC_2_F03_PREDICATE_DECOMPOSITION_IMPLEMENTATION.md | AST-bound implementation, exact pre-parser witness path, 47 refusals, measured resources, CLI surface, and remote-proof boundary |
| registries/marc2_f03_predicate_decomposition_implementation.v0.json | machine-readable implementation hashes, green registration and implementation proofs, 20-leaf inventory, 24-path qualification, local verification, and zero counters |
| docs/MARC_2_F03_PREDICATE_DECOMPOSITION_RESULT.md | generated MARC2VR10A-G1 result, exact 15/5 partition, five witness outcomes, measurements, explicit unknowns, and no-science ceiling |
| registries/marc2_f03_predicate_decomposition_result.v0.json | machine-readable predicate inventory, witness matrix, replay mechanics, 47 refusal routes, resources, zero counters, and next gate |
| docs/MARC_2_F03_FIVE_ROUTE_DISCRIMINATOR_PREREGISTRATION.md | frozen VR10B ordered P03/P15/P16/P18/P19 classifier, six-case exact-parser replay, output firewall, resources, and no-science boundary |
| registries/marc2_f03_five_route_discriminator_contract.v0.json | hash-bound ten-input VR10B contract, exact G1/R1-R5 routes, 24-call qualification, 14 acceptance gates, all-false authority, and next proof boundary |
| docs/MARC_2_F03_FIVE_ROUTE_DISCRIMINATOR_IMPLEMENTATION.md | dependency-free VR10B classifier, exact generated parser/producer replay, recursive output firewall, 60 refusals, measurements, and remote-proof boundary |
| registries/marc2_f03_five_route_discriminator_implementation.v0.json | machine-readable implementation hashes, green registration and implementation proofs, six-route mechanics, local verification, and zero counters |
| docs/MARC_2_F03_FIVE_ROUTE_DISCRIMINATOR_RESULT.md | generated MARC2VR10B-G1 result, four copies of G1/R1-R5, exact measurements, explicit private unknowns, and no-science ceiling |
| registries/marc2_f03_five_route_discriminator_result.v0.json | machine-readable route counts, replay digest, parser mechanics, 60 refusals, resources, zero counters, and next gate |
| docs/MARC_2_F03_PRIVATE_DISCRIMINATOR_AUTHORIZATION_PACKET.md | all-false VR11P request for one proof-gated five-route structural diagnostic, with exact barriers, paths, caps, privacy ceiling, and no-science boundary |
| registries/marc2_f03_private_discriminator_authorization_request.v0.json | machine-readable VR11P predecessor hashes, future one-read route contract, all-false authority, zero counters, and fresh-decision protocol |
| docs/MARC_2_F03_PRIVATE_DISCRIMINATOR_AUTHORIZATION_DECISION.md | packet-bound short-form VR11P decision, delayed effect, fixed two-stage order, privacy firewall, resources, and no-science boundary |
| docs/MARC_2_F03_PRIVATE_DISCRIMINATOR_IMPLEMENTATION.md | generated/mock VR11P wrapper, exact route and filesystem qualification, proof gate, and Stage 2 boundary |
| registries/marc2_f03_private_discriminator_implementation.v0.json | machine-readable VR11P artifact hashes, measured generated qualification, local verification, and exact green implementation proof |
| docs/MARC_2_F03_PRIVATE_DISCRIMINATOR_RESULT.md | consumed one-shot VR11P R2 result, P15 engineering ceiling, exact resources/counters, and no-neural-result boundary |
| registries/marc2_f03_private_discriminator_result.v0.json | machine-readable green execution order, R2/P15 route, exact one-read counters, resource measurements, consumed state, and closed science gate |
| registries/marc2_f03_private_discriminator_authorization_decision.v0.json | machine-readable green packet proofs, exact maintainer words, immutable artifact hashes, conditional authority, zero counters, and next barrier |
| docs/MARC_2_PUBLISHED_TASK_SELECTOR_REPAIR_IMPLEMENTATION.md | generated-only VR20A adapter for exact task-reachingandgrasping, source-exact selection, 20-path qualification, 53 refusals, measurements, and proof boundary |
| registries/marc2_published_task_selector_repair_result.v0.json | machine-readable MARC2VR20A-G1 result with published identity, normalized cohort replay, resources, zero forbidden counters, and no-science ceiling |
| docs/MARC_2_PUBLISHED_TASK_SELECTOR_REPAIR_PROOF_CLOSEOUT.md | exact implementation CI proof, preproof hashes and Git blobs, zero-repeat transition, delayed packet eligibility, and no-neural-result boundary |
| docs/MARC_2_PUBLISHED_TASK_PRIVATE_CONFIRMATION_AUTHORIZATION_PACKET.md | all-false VR20P two-stage request for a generated fixed-path wrapper and, only after every proof gate plus a fresh decision, one target-free structural confirmation |
| registries/marc2_published_task_private_confirmation_authorization_request.v0.json | machine-readable fixed paths, copied 418,755-byte source identity, F01-F09 coarse map, cohort contract, resource caps, authorization zeros, and no-science boundary |
| docs/MARC_2_PUBLISHED_TASK_PRIVATE_CONFIRMATION_REQUEST_PROOF_CLOSEOUT.md | exact VR20P request CI proof, three immutable request artifact hashes and Git blobs, zero-operation closeout, and delayed Tier C decision boundary |
| registries/marc2_published_task_private_confirmation_request_proof.v0.json | machine-readable request proof, unchanged scope, all-zero closeout ledger, all-false authority, and fresh-decision gate |
| docs/MARC_2_PUBLISHED_TASK_PRIVATE_CONFIRMATION_AUTHORIZATION_DECISION.md | packet-bound VR20P short-form decision preserving the exact maintainer bytes, two remote barriers, one-read scope, privacy firewall, and no-science boundary |
| registries/marc2_published_task_private_confirmation_authorization_decision.v0.json | machine-readable packet hashes, exact maintainer words, delayed authority, fixed paths and routes, resource caps, zero counters, and closed FW2/CIL1 boundary |
| docs/MARC_2_PUBLISHED_TASK_PRIVATE_CONFIRMATION_IMPLEMENTATION.md | generated VR20P fixed-path wrapper, six-case route matrix, 91 refusals, measurements, proof gate, and no-neural-result boundary |
| registries/marc2_published_task_private_confirmation_implementation.v0.json | machine-readable Stage 1 hashes, exact route counts, resource measurements, zero forbidden counters, immutable remote implementation proof, and delayed Stage 2 |
| docs/MARC_2_PUBLISHED_TASK_PRIVATE_CONFIRMATION_PROOF_CLOSEOUT.md | exact Stage 1 CI proof, preproof and artifact identities, zero-repeat transition, delayed one-invocation gate, and no-neural-result boundary |
| docs/MARC_2_PUBLISHED_TASK_PRIVATE_CONFIRMATION_RESULT.md | consumed one-shot R5 result, exact proof chain and resources, two-class structural ceiling, zero neural operations, and next generated-only gate |
| registries/marc2_published_task_private_confirmation_result.v0.json | machine-readable MARC2VR20P-R5 route, one-read counters, measurements, unavailable fields, consumed state, and closed science gate |
| docs/MARC_2_R5_TWO_ROUTE_DISCRIMINATOR_PREREGISTRATION.md | frozen generated-only VR21A design separating F06 taxonomy/eligibility from F07 selection/split/rank/reservation arithmetic across 12 exact paths |
| registries/marc2_r5_two_route_discriminator_contract.v0.json | machine-readable fixed inputs, 11-call-site AST inventory, route matrix, resource caps, zero private counters, and no-science boundary |
| docs/MARC_2_R5_TWO_ROUTE_DISCRIMINATOR_IMPLEMENTATION.md | dependency-free VR21A adapter, measured 12-path qualification, 48 refusals, resource accounting, remote-proof gate, and scientific boundary |
| registries/marc2_r5_two_route_discriminator_implementation.v0.json | machine-readable implementation hashes, exact route counts and replay hashes, measurements, zero forbidden counters, and exact remote implementation proof |
| registries/marc2_r5_two_route_discriminator_result.v0.json | machine-readable MARC2VR21A-G1 result, generated F06/F07 mappings, resource caps, unresolved private R5 boundary, and no-science ceiling |
| docs/MARC_2_R5_TWO_ROUTE_DISCRIMINATOR_PROOF_CLOSEOUT.md | exact VR21A CI proof, preproof hashes and Git blobs, zero-repeat transition, delayed private-packet eligibility, and closed scientific boundary |
| docs/MARC_2_R5_PRIVATE_DISCRIMINATOR_AUTHORIZATION_PACKET.md | all-false VR22P two-stage request, one-shot target-free structural boundary, six aggregate routes, resource caps, and no-science ceiling |
| docs/MARC_2_R5_PRIVATE_DISCRIMINATOR_AUTHORIZATION_DECISION.md | exact eight-byte packet-bound decision, delayed-effect barriers, generated Stage 1 scope, and still-closed neural/scientific boundary |
| docs/MARC_2_R5_PRIVATE_DISCRIMINATOR_IMPLEMENTATION.md | 12-path generated fixed-wrapper result, exact VR20A/VR21A call accounting, resource measurements, proof lock, and no-science boundary |
| docs/MARC_2_R5_PRIVATE_DISCRIMINATOR_PROOF_CLOSEOUT.md | exact Stage 1 CI proof, preproof registry and Git-blob binding, no-reexecution record, and final delayed private-execution barrier |
| docs/MARC_2_R5_PRIVATE_DISCRIMINATOR_RESULT.md | consumed one-shot R4 result, exact proof chain and resources, two-call-site F06 ceiling, zero neural operations, and next generated-only gate |
| registries/marc2_r5_private_discriminator_result.v0.json | machine-readable MARC2VR22P-R4 route, one-read counters, measurements, unavailable fields, consumed state, and closed science gate |
| docs/MARC_2_F06_FIVE_ROUTE_DECOMPOSITION_PREREGISTRATION.md | frozen generated-only VR23A design separating five reachable F06 classes and proving two defensive guards non-independent across 24 paths |
| registries/marc2_f06_five_route_decomposition_contract.v0.json | machine-readable 14-input proof anchor, static predicate inventory, route matrix, resource caps, zero private counters, and no-science boundary |
| docs/MARC_2_F06_FIVE_ROUTE_DECOMPOSITION_IMPLEMENTATION.md | dependency-free VR23A adapter, measured 24-path qualification, 62 refusals, exact resource accounting, proof lock, and scientific boundary |
| registries/marc2_f06_five_route_decomposition_implementation.v0.json | machine-readable module hashes, static proof, six-route counts, zero forbidden counters, verification delta, and pending remote proof |
| registries/marc2_f06_five_route_decomposition_result.v0.json | machine-readable MARC2VR23A-G1 result, generated five-class mappings, measurements, unresolved real F06 class, and no-science ceiling |
| docs/MARC_2_F06_FIVE_ROUTE_DECOMPOSITION_PROOF_CLOSEOUT.md | exact VR23A CI proof, preproof registry hashes and seven Git blobs, no-reexecution record, delayed private-packet eligibility, and closed science boundary |
| docs/MARC_2_F06_PRIVATE_FIVE_ROUTE_DISCRIMINATOR_AUTHORIZATION_PACKET.md | all-false VR24P two-stage request, one-shot target-free structural boundary, nine aggregate routes, resource caps, and no-science ceiling |
| registries/marc2_f06_private_five_route_discriminator_authorization_request.v0.json | machine-readable 16-input proof chain, fixed private paths, exact five-class map, all-false authority, zero counters, and fresh-decision gate |
| docs/MARC_2_F06_PRIVATE_FIVE_ROUTE_DISCRIMINATOR_REQUEST_PROOF_CLOSEOUT.md | exact remotely green request proof, three immutable request artifacts, no-scope-change accounting, delayed sole-gate eligibility, and no-science boundary |
| registries/marc2_f06_private_five_route_discriminator_request_proof.v0.json | machine-readable request CI proof, byte/hash/blob identities, all-zero closeout operations, all-false authority, and fresh-decision gate |
| docs/MARC_2_F06_PRIVATE_FIVE_ROUTE_DISCRIMINATOR_AUTHORIZATION_DECISION.md | exact eight-byte packet-bound VR24P decision, delayed-effect barriers, generated Stage 1 scope, one-read Stage 2 ceiling, and closed neural/scientific boundary |
| registries/marc2_f06_private_five_route_discriminator_authorization_decision.v0.json | machine-readable green packet proof, exact user bytes, ordered two-stage authority, fixed paths and routes, zero decision-time operations, and no-science ceiling |
| docs/MARC_2_F06_PRIVATE_FIVE_ROUTE_DISCRIMINATOR_IMPLEMENTATION.md | generated VR24P fixed-wrapper design, 24-path qualification, 130 refusals, measured resources, proof barrier, and no-science boundary |
| docs/MARC_2_F06_PRIVATE_FIVE_ROUTE_DISCRIMINATOR_PROOF_CLOSEOUT.md | exact Stage 1 CI proof, preproof registry and Git-blob binding, no-reexecution record, and final delayed private-execution barrier |
| registries/marc2_f06_private_five_route_discriminator_implementation.v0.json | machine-readable authority chain, exact artifacts, six-route generated result, zero forbidden counters, resource caps, and bound remote implementation proof |
| docs/MARC_2_F06_PRIVATE_FIVE_ROUTE_DISCRIMINATOR_RESULT.md | consumed one-shot R2 result, exact proof chain and resources, complete-bundle arithmetic ceiling, zero neural operations, and next generated-only gate |
| registries/marc2_f06_private_five_route_discriminator_result.v0.json | machine-readable MARC2VR24P-R2 route, one-read counters, measurements, unavailable private count, consumed state, and closed science gate |
| docs/MARC_2_COMPLETE_BUNDLE_ARITHMETIC_RESEARCH.md | public/artifact-only analysis separating full-source snapshot compatibility from exact selection-sufficient cohort integrity |
| docs/MARC_2_SELECTION_BOUNDARY_FIREWALL_PREREGISTRATION.md | frozen VR25A ten-case, 40-path generated protocol with exact eligible firewall, warning-only nuisance count drift, caps, and stop rules |
| registries/marc2_selection_boundary_firewall_contract.v0.json | machine-readable VR25A proof anchor, fixed inputs, layered invariants, route matrix, zero authority, and no-science ceiling |
| docs/MARC_2_SELECTION_BOUNDARY_FIREWALL_IMPLEMENTATION.md | generated VR25A implementation, 40-path result, 72 refusals, exact measurements, proof barrier, and no-science boundary |
| registries/marc2_selection_boundary_firewall_implementation.v0.json | hash-bound module/tests, green registration and implementation proofs, generated measurements, delayed closeout effect, and closed private boundary |
| registries/marc2_selection_boundary_firewall_result.v0.json | machine-readable G1 result, G2 quarantine evidence, exact eligible firewall, resource measurements, unavailable real fields, and zero scientific counters |
| docs/MARC_2_SELECTION_BOUNDARY_FIREWALL_PROOF_CLOSEOUT.md | exact VR25A CI proof, preproof registry hashes and seven Git blobs, no-reexecution record, delayed private-packet eligibility, and closed science boundary |
| docs/MARC_2_SELECTION_BOUNDARY_PRIVATE_CONFIRMATION_AUTHORIZATION_PACKET.md | all-false VR26P two-stage request, exact cohort-success routes, one-shot target-free structural boundary, resource caps, and no-science ceiling |
| registries/marc2_selection_boundary_private_confirmation_authorization_request.v0.json | machine-readable 14-input proof chain, fixed private paths, exact G1/G2 success map, all-false authority, zero counters, and fresh-decision gate |
| docs/MARC_2_SELECTION_BOUNDARY_PRIVATE_CONFIRMATION_REQUEST_PROOF_CLOSEOUT.md | exact remotely green VR26P request proof, three immutable request artifacts, no-scope-change accounting, delayed sole-gate eligibility, and no-science boundary |
| registries/marc2_selection_boundary_private_confirmation_request_proof.v0.json | machine-readable request CI proof, byte/hash/blob identities, all-zero closeout operations, all-false authority, and fresh-decision gate |
| docs/MARC_2_SELECTION_BOUNDARY_PRIVATE_CONFIRMATION_AUTHORIZATION_DECISION.md | exact eight-byte packet-bound VR26P decision, delayed-effect barriers, generated Stage 1 scope, one-read Stage 2 ceiling, and closed neural/scientific boundary |
| registries/marc2_selection_boundary_private_confirmation_authorization_decision.v0.json | machine-readable green packet proof, exact user bytes, ordered two-stage authority, fixed cohort routes and resources, zero decision-time operations, and no-science ceiling |
| docs/MARC_2_SELECTION_BOUNDARY_PRIVATE_CONFIRMATION_IMPLEMENTATION.md | generated VR26P fixed-wrapper design, 40-path qualification, 106 refusals, exact cohort invariance, measurements, proof barrier, and no-science boundary |
| registries/marc2_selection_boundary_private_confirmation_implementation.v0.json | machine-readable authority chain, exact implementation artifacts and remote proof, generated measurements, delayed private gate, zero forbidden counters, and resource caps |
| docs/MARC_2_SELECTION_BOUNDARY_PRIVATE_CONFIRMATION_PROOF_CLOSEOUT.md | exact VR26P implementation CI proof, preproof registry identity, four artifact Git blobs, no-reexecution accounting, delayed one-shot private gate, and closed science boundary |
| docs/MARC_2_SELECTION_BOUNDARY_PRIVATE_CONFIRMATION_RESULT.md | consumed VR26P R5 result, proof chain, one-read resources, taxonomy-or-inventory ceiling, no cohort, and no-science boundary |
| registries/marc2_selection_boundary_private_confirmation_result.v0.json | machine-readable one-shot R5 route, exact operation counters, measurements, unavailable private fields, consumed state, and next generated-only gate |
| docs/MARC_2_R5_INVENTORY_TAXONOMY_DISCRIMINATOR_PREREGISTRATION.md | frozen VR27A five-case, 20-path generated protocol separating eligible-inventory drift from unknown-participant taxonomy with no private executor |
| registries/marc2_r5_inventory_taxonomy_discriminator_contract.v0.json | machine-readable VR27A result proof, nine fixed inputs, exact R1/R2 call sites, route counts, caps, zero private authority, and no-science ceiling |
| docs/MARC_2_R5_INVENTORY_TAXONOMY_DISCRIMINATOR_IMPLEMENTATION.md | generated VR27A adapter, 20-path result, 57 refusals, exact replay and measurements, proof barrier, and no-science boundary |
| registries/marc2_r5_inventory_taxonomy_discriminator_implementation.v0.json | machine-readable VR27A artifact hashes, generated qualification, resources, zero forbidden counters, and null remote proof |
| registries/marc2_r5_inventory_taxonomy_discriminator_result.v0.json | machine-readable G1 result, R1/R2 route counts, exact replay digest, unavailable real fields, and closed science boundary |
| docs/MARC_2_R5_INVENTORY_TAXONOMY_DISCRIMINATOR_PROOF_CLOSEOUT.md | exact VR27A implementation CI proof, preproof registry hashes, seven Git blobs, no-reexecution record, delayed private-packet eligibility, and no-science boundary |
| docs/MARC_2_INVENTORY_TAXONOMY_PRIVATE_DISCRIMINATOR_AUTHORIZATION_PACKET.md | all-false VR28P two-stage request, generated wrapper boundary, one future target-free structural read, aggregate R1/R2 ceiling, resource caps, and no-science boundary |
| registries/marc2_inventory_taxonomy_private_discriminator_authorization_request.v0.json | machine-readable VR28P proof chain, 13 fixed inputs, fixed paths, binary route map, zero authority, zero operation counters, and fresh-decision gate |
| docs/MARC_2_INVENTORY_TAXONOMY_PRIVATE_DISCRIMINATOR_REQUEST_PROOF_CLOSEOUT.md | exact VR28P request CI proof, three immutable request artifacts, zero-operation accounting, delayed sole-gate eligibility, and no-science boundary |
| registries/marc2_inventory_taxonomy_private_discriminator_request_proof.v0.json | machine-readable VR28P request commit, CI jobs, artifact hashes and Git blobs, unchanged scope, zero authority, and next gate |
| docs/MARC_2_INVENTORY_TAXONOMY_PRIVATE_DISCRIMINATOR_AUTHORIZATION_DECISION.md | exact short-form VR28P decision, delayed-effect barrier, generated Stage 1 scope, one-read Stage 2 ceiling, and closed neural/scientific boundary |
| registries/marc2_inventory_taxonomy_private_discriminator_authorization_decision.v0.json | machine-readable user-message hash, six bound packet artifacts, staged authority, fixed paths and routes, zero decision-time operations, and proof gate |
| registries/marc2_r5_private_discriminator_authorization_request.v0.json | machine-readable 18-input proof chain, fixed private paths, exact F06/F07 route map, all-false authority, zero counters, and fresh-decision gate |
| docs/MARC_2_R5_PRIVATE_DISCRIMINATOR_REQUEST_PROOF_CLOSEOUT.md | exact remotely green request proof, three immutable request artifacts, no-scope-change accounting, delayed sole-gate eligibility, and no-science boundary |
| registries/marc2_r5_private_discriminator_request_proof.v0.json | machine-readable request CI proof, byte/hash/blob identities, all-zero closeout operations, all-false authority, and fresh-decision gate |
| docs/MARC_2_SOURCE_VALIDITY_ELIGIBILITY_REPAIR_PREREGISTRATION.md | frozen generated-only 238-bundle repair design, filter-before-count order, aggregate predicates, mutations, resources, and claim boundary |
| registries/marc2_source_validity_eligibility_repair_contract.v0.json | machine-readable MARC2-VR1 source-validity and eligibility contract with 43 generated adversary bundles and all authority flags false |
| docs/MARC_2_SOURCE_VALIDITY_ELIGIBILITY_REPAIR_IMPLEMENTATION.md | generated-only full-source validator, eligibility-first selection order, refusal coverage, local verification, and exact remote-proof gate |
| registries/marc2_source_validity_eligibility_repair_implementation.v0.json | hash-bound MARC2-VR1 module, test surface, 238-bundle mechanics, frozen selection replay, zero counters, and pre-closeout remote-proof gate |
| docs/MARC_2_SOURCE_VALIDITY_ELIGIBILITY_REPAIR_RESULT.md | consumed generated MARC2VR-G1 result, full-domain predicate counts, frozen selection replay, measurements, and closed private/scientific boundary |
| registries/marc2_source_validity_eligibility_repair_result.v0.json | machine-readable exact green proof, one-run counters, 36 refusals, resource measurements, unavailable fields, and no-rerun disposition |
| docs/FOUNDATION_MODEL_DECODER_STRATEGY_2026-08-06.md | layered compact-adapter plus GPT-Sol architecture, four matched conditions, and staged authorization boundary |
| docs/FOUNDATION_MODEL_BRIDGE_V0.md | implemented FM-0 synthetic no-call schemas, CLI, strict refusals, hashes, and measured roundtrip |
| docs/FOUNDATION_MODEL_LIVE_SMOKE_PREREGISTRATION.md | frozen one-shot FM-1 Terra matrix, privacy boundary, provider settings, resource caps, and no-science ceiling |
| docs/FOUNDATION_MODEL_LIVE_SMOKE_AUTHORIZATION_DECISION.md | exact user authorization bound to the remotely green FM-1 contract |
| docs/FOUNDATION_MODEL_LIVE_SMOKE_IMPLEMENTATION.md | dependency-free provider transport, dry-run and inspect CLI, strict receipts, local measurements, and pre-execution remote-green gate |
| registries/foundation_model_live_smoke_implementation.v0.json | machine-readable FM-1 code hashes, request shape, guards, measurements, zero counters, and current not-executed state |
| docs/FOUNDATION_MODEL_LIVE_SMOKE_RESULT.md | consumed FM-1 partial-call trace, measurements, terminal boundary, gate verdict, and no-rerun closeout |
| registries/foundation_model_live_smoke_result.v0.json | machine-readable parked result, response summaries, counters, unavailable fields, and claim ceiling |
| docs/AI_LOCAL_FIRST_R_AND_D_BUDGET_2026-08-08.md | $50 provider ceiling portfolio, local open-source tool strategy, earbud-patent boundary, and ordered next work |
| registries/ai_local_first_rd_budget.v0.json | machine-readable ceilings, release conditions, standing target-free scope, local tools, and closed scientific gates |
| docs/LOCAL_EEG_TOOLING_AUDIT_2026-08-08.md | measured zero-network capability inventory, resource accounting, missing tools, and no-science boundary |
| registries/local_eeg_tooling_audit_result.v0.json | raw bounded seven-tool capability report with sanitized warnings and zero access counters |
| registries/local_eeg_tooling_audit_receipt.v0.json | exact green-implementation, result-hash, resource, route, and claim receipt |
| docs/NEXT_20_SYSTEMATIC_EXECUTION_2026-08-08.md | active 20-work-order execution overlay with Tier A/B autonomy and exact Tier C stops |
| docs/PHYSIONET_MOTOR_ACQUISITION_PREREGISTRATION.md | frozen nine-EDF work-order-8 identity, access order, resource caps, no-retry rule, and acquisition-only ceiling |
| docs/PHYSIONET_MOTOR_ACQUISITION_IMPLEMENTATION.md | fixture-qualified standard-library metadata, transfer, one-pass hash, atomic promotion, receipt, CLI, and refusal implementation |
| registries/physionet_motor_acquisition_implementation.v0.json | hash-bound implementation sources, green authorization parent, fixture metrics, resources, and zero-real-access ledger |
| docs/PHYSIONET_MOTOR_ACQUISITION_RESULT.md | consumed 12-of-12 acquisition closeout with exact bytes, runtime, RSS, disk, zero forbidden counters, and scientific ceiling |
| registries/physionet_motor_acquisition_result.v0.json | sanitized machine-readable nine-file identity result, private-receipt hashes, measurements, gates, and closed work-order-9 boundary |
| docs/PHYSIONET_MOTOR_POSITIVE_CONTROL_PRIMARY_SOURCE_RESEARCH.md | work-order-9 method, cue/ocular/muscle caveats, prediction-physiology-confound triangulation, verdict ladder, and replication route |
| docs/PHYSIONET_MOTOR_POSITIVE_CONTROL_PREREGISTRATION.md | frozen S001-S003 grouped split, causal views, models, controls, remote-green prediction freeze, thresholds, resources, and claim ceiling |
| registries/physionet_motor_positive_control_contract.v0.json | machine-readable 9-file, 135-event prospective contract with 12 final prediction sets, one sealed score, and all current permissions false |
| docs/PHYSIONET_MOTOR_POSITIVE_CONTROL_AUTHORIZATION_PACKET.md | exact conditional work-order-9 implementation, dependency, EDF, prediction-freeze, scoring, resource, exclusion, and claim decision surface |
| registries/physionet_motor_positive_control_authorization_request.v0.json | all-false request bound to green registration 3c00557, CI 31346882592, exact hashes, and one exact maintainer sentence |
| docs/PHYSIONET_MOTOR_POSITIVE_CONTROL_AUTHORIZATION_DECISION.md | exact maintainer decision, parent request proof, four remotely green gates, one-shot limits, and unchanged scientific ceiling |
| registries/physionet_motor_positive_control_authorization_decision.v0.json | machine-checkable work-order-9 authorization with conditional implementation, EDF, freeze, and scoring permissions plus explicit refusals |
| docs/SYNTHETIC_MOTOR_FIXTURE_PREREGISTRATION.md | frozen work-order-3 factor, pair, partition, mutation, resource, leakage, and no-model fixture boundary |
| registries/synthetic_motor_fixture_contract.v0.json | machine-readable seed-5503, 96-item, eight-family Tier B fixture contract with zero execution counters |
| docs/SYNTHETIC_MOTOR_FIXTURE_IMPLEMENTATION.md | locally qualified deterministic generator, validator, inspector, mutation, CLI, and pre-execution boundary |
| registries/synthetic_motor_fixture_implementation.v0.json | hash-bound work-order-3 source, test, resource, and pending-remote-green implementation receipt |
| docs/SYNTHETIC_MOTOR_FIXTURE_RESULT.md | consumed one-shot synthetic closeout with measured shape, bytes, runtime, RSS, counters, warnings, and claim boundary |
| registries/synthetic_motor_fixture_result.v0.json | machine-readable all-gates-pass work-order-3 receipt and no-real-data access ledger |
| docs/CLASSICAL_EEG_ADAPTER_PREREGISTRATION.md | frozen no-install shrinkage-LDA, CSP-LDA, Riemannian-MDM, grouped-fit, target-firewall, and refusal boundary |
| registries/classical_eeg_adapter_contract.v0.json | machine-readable three-adapter work-order-4 plan contract with twelve leakage refusals and zero execution counters |
| docs/CLASSICAL_EEG_ADAPTER_IMPLEMENTATION.md | locally qualified standard-library symbolic plan, hash, validation, refusal, CLI, and pre-execution boundary |
| registries/classical_eeg_adapter_implementation.v0.json | hash-bound pre-execution work-order-4 implementation sources, tests, resources, and zero-access ledger |
| docs/CLASSICAL_EEG_ADAPTER_RESULT.md | consumed one-shot symbolic roundtrip with bytes, runtime, RSS, refusals, access counters, and no-science boundary |
| registries/classical_eeg_adapter_result.v0.json | machine-readable all-gates-pass work-order-4 receipt and route to synthetic contact semantics |
| docs/CONTACT_AWARE_EAR_CHANNEL_PREREGISTRATION.md | primary-source-bounded work-order-5 contact, missingness, bilateral weighting, causality, and no-hardware contract |
| registries/contact_aware_ear_channel_contract.v0.json | machine-readable 48-item, 16-channel, 16-refusal synthetic ear-channel contract and zero-action ledger |
| docs/CONTACT_AWARE_EAR_CHANNEL_IMPLEMENTATION.md | locally qualified deterministic fixture, fixed bilateral policy, hashes, validation, refusal, CLI, and pre-execution boundary |
| registries/contact_aware_ear_channel_implementation.v0.json | hash-bound work-order-5 implementation sources, tests, resources, probe observations, and zero-access ledger |
| docs/CONTACT_AWARE_EAR_CHANNEL_RESULT.md | consumed one-shot synthetic roundtrip with masks, hashes, bytes, runtime, RSS, cleanup, counters, and no-science boundary |
| registries/contact_aware_ear_channel_result.v0.json | machine-readable all-gates-pass work-order-5 receipt and gated route to Loop 54-A parser qualification |
| docs/LOOP_54_STAGE_A_VHDR_IMPLEMENTATION.md | green-decision-bound strict parser, synthetic adversarial qualification, one-shot filesystem order, CLI, resources, and no-S20-access boundary |
| registries/loop54_stage_a_vhdr_implementation.v0.json | machine-readable parser source hashes, 22 refusal classes, zero real-access ledger, and pending exact-implementation-green gate |
| docs/LOOP_54_STAGE_A_VHDR_RESULT.md | consumed one-shot F11 park with passed source/decode gates, failed preamble gate, resource measurements, zero sibling/protected access, and no-rerun route |
| registries/loop54_stage_a_vhdr_result.v0.json | machine-readable 18-gate result map, one-open access ledger, unavailable fields, blocked downstream route, and L54-Q1 claim ceiling |
| docs/NEXT_20_LOOPS_TRACKER.md | original 20-loop tracker, current post-roadmap gate, and planning-only Loops 25-44 summary |
| docs/NEURODECODEKIT_20_LOOP_TRACKER.xlsx | ten-sheet visual tracker preserved at the last reviewed Stage A snapshot; use the Markdown tracker and machine roadmap for the current Stage B result because a prior workbook import reached 1.57 GiB peak RSS |
| docs/POST_20_ROADMAP.md | closed/current post-NeuroToken gates plus links to the next tranche |
| docs/NEXT_20_LOOPS_PRIMARY_SOURCE_RESEARCH.md | Brain2Qwerty, MNE, BIDS, MOABB, LSL, privacy, uncertainty, and edge-runtime research behind Loops 25-44 |
| docs/LOOPS_25_44_ROADMAP.md | detailed goals, controls, metrics, acceptance gates, stop rules, dependencies, caps, and authorization boundaries for the next 20 loops |
| registries/next_20_loops.v0.json | machine-readable five-phase roadmap with 20 false execution flags and row-level primary-source bindings |
| docs/LOOP_26_PRIMARY_SOURCE_RESEARCH.md | six-item identifiability limit, causal candidate repair, parameter-matched comparator, control design, and exact no-execution boundary |
| registries/loop26_research_boundary.v0.json | machine-readable Loop 26 planning evidence, recommendations, zero access counters, and 14 false authorization fields |
| docs/LOOP_26_SHARED_VALIDATION_PREREGISTRATION.md | green prospective Loop 26/31/33 model, attribution, scaling, prediction-freeze, scoring, access, and resource protocol |
| docs/LOOP_26_AUTHORIZATION_PACKET.md | immutable plain-language exact decision surface for the shared event |
| docs/LOOP_26_AUTHORIZATION_DECISION.md | separately green one-time authorization, exact scope, order, resources, and refusals |
| docs/LOOP_26_SHARED_VALIDATION_IMPLEMENTATION.md | bounded reader, causal models, controls, freeze, scorer, CLI stages, synthetic qualification, and pre-access boundary |
| registries/loop26_shared_validation_contract.v0.json | machine-readable 21-fit, 31-prediction, 40-refusal shared validation contract and archive-access correction |
| registries/loop26_authorization_request.v0.json | green-commit-bound request with every authorization flag false and every protected/model/training/scoring counter zero |
| docs/LOOP_48_PRIMARY_SOURCE_RESEARCH.md | post-outcome aggregate diagnosis, eight-class tree, exact artifact evidence, unavailable root-cause fields, and no-execution boundary |
| registries/loop48_failure_localization_contract.v0.json | green hash-bound four-input Stage A contract with F5 as a phenotype, 30 refusals, measured caps, and every authorization false |
| docs/LOOP_48_AUTHORIZATION_PACKET.md | exact four-JSON Stage A permission surface, one-thread resource envelope, exclusions, and claim ceiling |
| registries/loop48_authorization_request.v0.json | request bound to green commit 83309bf and both CI runs; no implementation or execution is authorized |
| docs/LOOP_48_AUTHORIZATION_DECISION.md | separately committed exact user decision, four-input scope, caps, order, exclusions, and claim ceiling |
| docs/LOOP_48_FAILURE_LOCALIZATION_RESULT.md | one-shot Stage A evidence, ordered F5 trace, measurements, access ledger, and no-root-cause closeout |
| registries/loop48_failure_localization_result.v0.json | hash-bound 10,643-byte aggregate result with four verified input identities, all resource checks, and zero protected/model counters |
| docs/LOOP_48_TRAIN_ONLY_HYPOTHESIS_PORTFOLIO.md | five coexisting future train-only hypotheses, shared evidence design, sequential compute policy, and leakage firewall |
| registries/loop48_hypothesis_portfolio.v0.json | design-only H1-H5 support-vector schema with unfrozen Stage B inventory/caps and zero operation counters |
| docs/LOOP_48_HYPOTHESIS_DISCRIMINATION_RESEARCH.md | primary-source refinement adding data-regime hypothesis H6, evidence levels, non-identifiability rules, and the T1 shortcut firewall |
| registries/loop48_hypothesis_discrimination.v0.json | additive H1-H6 discrimination map with shared sequential stages, strict claim ceilings, 15 false authorizations, and zero protected/model operations |
| docs/LOOP_48_TRAIN_ONLY_DISCRIMINATION_PREREGISTRATION.md | exact 44/11 split, model/control inventory, telemetry, paired statistics, prediction-freeze order, resource caps, and E2 historical-use correction |
| registries/loop48_train_only_discrimination_contract.v0.json | machine-readable 20-fit, 35-inference, 41-prediction Stage B contract with 25 refusals, zero protected activity, and every authorization false |
| docs/LOOP_48_STAGE_B_AUTHORIZATION_PACKET.md | plain-language exact Stage B operation, control, access-order, storage, resource, and claim decision surface |
| registries/loop48_stage_b_authorization_request.v0.json | request bound to green preregistration commit 0ee0ab7 and both CI runs; no implementation, protected access, or execution is authorized |
| docs/LOOP_48_STAGE_B_AUTHORIZATION_DECISION.md | exact one-run maintainer decision, ordered three-green-gate sequence, resource boundary, refusals, and E2 claim ceiling |
| registries/loop48_stage_b_authorization_decision.v0.json | machine-readable Stage B authorization with exact counts, conditional target delivery, immutable request bindings, and zero pre-implementation counters |
| docs/LOOP_48_STAGE_B_IMPLEMENTATION.md | bounded reader, deterministic transforms, exact tiny models, private prediction freezer, isolated scorer, CLI stages, and pre-access qualification evidence |
| registries/loop48_stage_b_prediction_freeze.v0.json | remotely qualified hash-only record for 20 fit telemetry bundles and 41 target-blind prediction sets, with zero check-target delivery or score |
| docs/LOOP_48_STAGE_B_RESULT.md | one-shot H1-H6 verdict, candidate/prior and control results, exact access/resource ledger, L50-R05 route, and no-rerun claim boundary |
| docs/LOOP_48_STAGE_C_REPRESENTATION_REPAIR_RESEARCH.md | primary-source temporal-context hypothesis, exact causal candidate and parameter-matched ablation, bounded synthetic gate, and protected-evidence firewall |
| registries/loop48_stage_c_representation_repair_research.v0.json | machine-readable R1 comparison, architecture math, synthetic caps, outcome router, zero protected/model counters, and false protected authorization fields |
| docs/LOOP_48_STAGE_C_SYNTHETIC_IMPLEMENTATION.md | exact model/fixture/gate implementation, fail-closed preflight correction, consumed execution summary, and protected-evidence firewall |
| registries/loop48_stage_c_synthetic_implementation.v0.json | hash-bound model, fixture, gate, CLI, correction CI, consumed synthetic-result binding, and false protected authorization fields |
| docs/LOOP_48_STAGE_C_SYNTHETIC_RESULT.md | one-shot candidate/ablation result, absolute gate failure, mechanics checks, resource and access ledger, and no-rerun disposition |
| registries/loop48_stage_c_synthetic_result.v0.json | compact aggregate result with hashes, metrics, counters, warnings, and no plaintext target or prediction |
| registries/loop48_train_only_discrimination_result.v0.json | consumed 11-row train-check diagnostic supporting H4, recording evidence against fixed-shift H3, and preserving the E2 ceiling without plaintext targets or predictions |
| docs/LOOP_49_PRIMARY_SOURCE_RESEARCH.md | S24 development-person metadata decision, clean-identity tradeoff, exact bytes/hashes, text-group split recommendation, access order, and claim ceiling |
| registries/loop49_research_boundary.v0.json | machine-readable S24 selection, 25 false authorization fields, zero payload/model counters, >=48 blocker, and permanent development-only role |
| docs/LOOP_53_PRIMARY_SOURCE_RESEARCH.md | source-verified S20 selection, exact four-file identities, staged EEG evidence rationale, resource envelope, and zero-payload research boundary |
| docs/LOOP_53_FRESH_EEG_ACQUISITION_PREREGISTRATION.md | exact acquisition-only order, caps, integrity rules, stop conditions, receipt fields, and post-pass nonclaims |
| docs/OPEN_EEG_R_AND_D_STRATEGY_2026-08-06.md | current open EEG benchmark review, public motor positive-control prospect, specialist baseline and physiology upgrades, foundation-model deferral, and local-first contributor strategy |
| registries/open_eeg_rd_strategy.v0.json | machine-readable source pins, tool decisions, nine-file public prospect, resource caps, authorization zeros, and claim boundary |
| docs/LOOP_55_CAUSAL_MOTOR_LATTICE_ARCHITECTURE_RESEARCH.md | failure-addressable compact EEG architecture, physical key lattice, exact hand marginal, causal DSP rules, two-axis public qualification, and stop strategy |
| registries/loop55_causal_motor_lattice_research.v0.json | machine-readable CML-v0 graph, parameter formula, source ceilings, branch escrow, public gates, authorization zeros, and nonclaims |
| docs/CAUSAL_MOTOR_LATTICE_SYNTHETIC_PREREGISTRATION.md | frozen work-order-13 synthetic factors, exact model, check-before-final order, one-run resource caps, stop routes, and no-real-data boundary |
| registries/causal_motor_lattice_synthetic_contract.v0.json | machine-readable seed-5513 CML-v0 architecture, hashes, training schedule, 19 check gates, final firewall, resources, and refusals |
| docs/CAUSAL_MOTOR_LATTICE_SYNTHETIC_IMPLEMENTATION.md | exact 4,535-parameter model, deterministic synthetic runner, dry-run and inspector CLI, adversarial qualification, and remote-green execution gate |
| registries/causal_motor_lattice_synthetic_implementation.v0.json | hash-bound source, implementation, fixture projection, lattice, resource, test, and zero-execution receipt |
| docs/CAUSAL_MOTOR_LATTICE_SYNTHETIC_RESULT.md | consumed 18-of-19-gate synthetic result, constructed-factor diagnostics, exact common-mode failure, withheld final, resources, and no-rerun closeout |
| registries/causal_motor_lattice_synthetic_result.v0.json | machine-readable CML-R0 result, checkpoint/report hashes, metrics, access counters, warnings, unavailable fields, and scientific claim ceiling |
| registries/loop53_fresh_eeg_acquisition_contract.v0.json | machine-readable 96,090,264-byte S20 contract with pinned source hashes, no-overwrite paths, one-invocation cap, and every execution permission false |
| docs/LOOP_53_AUTHORIZATION_PACKET.md | plain-language exact Tier C sentence for implementation plus one bounded acquisition, with all interpretive and model work excluded |
| registries/loop53_authorization_request.v0.json | immutable pre-decision request bound to green registration bccd367 and both registration CI runs |
| docs/LOOP_53_AUTHORIZATION_DECISION.md | exact user decision, immutable contract/request hashes, authorized acquisition surfaces, excluded interpretation/model work, and ordered green gates |
| registries/loop53_authorization_decision.v0.json | machine-readable authorization record at 2a47bbc, with exact identity, caps, operation ledger, and nonclaims |
| docs/LOOP_53_ACQUISITION_IMPLEMENTATION.md | standard-library executor, dry-run CLI, metadata-first refusal logic, opaque hashes, atomic promotion, receipts, tests, and implementation boundary |
| registries/loop53_acquisition_implementation.v0.json | hash-bound implementation record for commit 8ec5b1b, 51 focused tests, resource controls, zero pre-execution S20 access, and remote-green dependency |
| docs/LOOP_53_ACQUISITION_RESULT.md | consumed four-file acquisition pass, exact measured resources and counters, ten gate results, unavailable fields, and stop-before-Loop-54 boundary |
| registries/loop53_acquisition_result.v0.json | content-free aggregate result binding the private receipts, 96,090,264 bytes, 3.629499 seconds, all-zero forbidden counters, and no rerun |
| docs/LOOP_54_PRIMARY_SOURCE_RESEARCH.md | primary-source BrainVision/BIDS/MNE audit, current extractor gap analysis, staged target firewall, trial-unit rule, resource caps, and claim ceiling |
| registries/loop54_eeg_trial_geometry_research.v0.json | machine-readable four-stage protocol with exact file-role isolation, 22 gates, 30 refusals, zero protected access counters, and false real-stage authorizations |
| docs/LOOP_54_STAGE_A_REGISTRATION_CI_RECOVERY.md | exact-commit retry failure, frozen-payload identity, pinned remote proof anchor, exact-tree replay, and unchanged authorization boundary |
| registries/loop54_stage_a_registration_ci_recovery.v0.json | machine-readable toolchain-drift classification, immutable hashes, measured replay, green anchor, zero access counters, and false authorization flags |
| docs/LOOP_54_STAGE_A_AUTHORIZATION_PACKET.md | historical non-actionable v0 request retained for audit and superseded by the recovery-bound v1 request |
| docs/LOOP_54_STAGE_A_RECOVERY_AUTHORIZATION_PACKET.md | current recovery-bound exact Tier C decision surface, ordered green gates, one-file resource caps, full refusals, and scientific nonclaims |
| registries/loop54_stage_a_recovery_authorization_request.v1.json | machine-readable v1 request binding the immutable registration, green proof anchor, recovery record, superseded v0 request, all-false permissions, zero S20 access counters, and exact user sentence |
| docs/LOOP_54_STAGE_A_RECOVERY_AUTHORIZATION_DECISION.md | exact user decision, green request binding, two-stage evidence order, resource ceiling, authorization-only zero counters, and nonclaims |
| registries/loop54_stage_a_recovery_authorization_decision.v1.json | machine decision enabling synthetic parser work only after decision CI and one conditional VHDR execution only after implementation CI |
| docs/LOOP_50_PRIMARY_SOURCE_RESEARCH.md | primary-source multi-person design, global text firewall, historical S21 out-of-fold protocol, S24 development gate, controls, resources, and claim ceiling |
| registries/loop50_research_boundary.v0.json | machine-readable two-person design with six Stage B routes, ten conditions, 30 refusals, 31 false authorizations, and zero protected/model counters |
| docs/LOOP_27_PRIMARY_SOURCE_RESEARCH.md | official metadata ranking, selected S25 MEG candidate, exact bytes/hashes, target-isolation design, and preregistration blockers |
| registries/loop27_research_boundary.v0.json | machine-readable Loop 27 candidate identity, unavailable fields, resource boundary, zero payload access, and 18 false authorization fields |
| docs/LOOP_28_PRIMARY_SOURCE_RESEARCH.md | v2 transfer audit, T0-T3 taxonomy, strict zero-shot/transductive distinction, final-only rule, and calibrated-design boundary |
| registries/loop28_research_boundary.v0.json | machine-readable Loop 28 estimand, controls, access order, resource limits, dependencies, zero protected access, and 21 false authorization fields |
| docs/LOOP_29_PRIMARY_SOURCE_RESEARCH.md | primary-source OPM-MEG and EEG review, two-lane portability decision, storage allocation, qualification ladder, and result-oriented real-data path |
| registries/loop29_research_boundary.v0.json | machine-readable modality requirements, device gates, storage ceilings, source bindings, zero protected access, and 24 false authorization fields |
| docs/LOOP_42_PRIMARY_SOURCE_RESEARCH.md | official OpenBCI/BrainFlow audit, exact future Cyton candidate, packet/clock/locality/safety boundaries, staged gates, and no-execution decision |
| registries/loop42_research_boundary.v0.json | machine-readable candidate identity, packet and timing semantics, anomaly/privacy/safety controls, resource caps, zero operation counters, and 45 false authorization fields |
| docs/LOOP_43_PRIMARY_SOURCE_RESEARCH.md | ACM, CODECHECK, ReScience, FAIR4RS, NeurIPS, and GitHub security research; future commit-reveal challenge design; privacy, independence, outcome, and claim boundaries |
| registries/loop43_research_boundary.v0.json | machine-readable challenge taxonomy, exact field sets, discrepancy classes, stage gates, resource caps, recorded local metadata-read incident, zero experiment operations, and 48 false authorization fields |
| docs/LOOP_32_PRIMARY_SOURCE_RESEARCH.md | primary-source calibration taxonomy, 32-parameter adapter recommendation, physical split and burden contract, access order, controls, and one-time final gate |
| registries/loop32_research_boundary.v0.json | machine-readable four-mode calibration boundary, six-point budget, 32/16/48 partition floors, zero protected operations, and 22 false authorization fields |
| docs/REAL_DATA_VALIDATION_2026-07-10.md | S21 alignment, session, and upstream audit |
| docs/LOOP_19_EEG_BRAINVISION_BRIDGE.md | real EEG bridge and negative classifier result |
| docs/LOOP_20_NEUROTOKEN_CACHE_V0.md | NeuroTokenCache schema and synthetic interface proof |
| docs/LOOP_24_PRIMARY_SOURCE_RESEARCH.md | PyTorch precision, timing, memory, and energy primary-source review |
| docs/LOOP_24_PRECISION_RUNTIME_PREREGISTRATION.md | frozen Loop 24 candidates, fresh fixtures, measurements, thresholds, caps, and decision language |
| registries/local_precision_runtime_contract.v0.json | machine-readable Loop 24 identities, schedules, refusals, access rules, and false authorization flags |
| docs/LOOP_24_AUTHORIZATION_DECISION.md | scope-narrowed Loop 24 authorization, execution order, zero-runtime boundary, and real-data/training routing |
| registries/loop24_authorization_decision.v0.json | hash-bound authorization record for the consumed target-free Loop 24 execution; every data/training/RW3/device flag remains false |
| docs/LOOP_24_LOCAL_PRECISION_RUNTIME.md | measured float32/float16/qint8 result, unopened qualification proof, resources, access ledger, and parked decision |
| docs/LOOP_25_PRIMARY_SOURCE_RESEARCH.md | original official Brain2Qwerty, MNE, SciPy, and local-pipeline audit separating offline preprocessing from causal proof |
| docs/LOOP_25_CAUSAL_PREPROCESSING_PREREGISTRATION.md | immutable historical v0 registration, superseded before authorization |
| registries/causal_preprocessing_contract.v0.json | immutable historical v0 machine contract; never authorized |
| docs/LOOP_25_ANTI_ALIAS_AUDIT.md | pinned Brain2Qwerty-to-NeuralSet-to-MNE execution trace and full folding-band defect analysis |
| docs/LOOP_25_CAUSAL_PREPROCESSING_AMENDMENT_1.md | current v1 dedicated anti-alias design, static pre-seed gate, timing semantics, and supersession boundary |
| registries/causal_preprocessing_contract.v1.json | current machine-readable Loop 25 amendment with every execution flag false |
| docs/LOOP_25_AUTHORIZATION_PACKET_V1.md | current exact bounded decision language and the work still forbidden even after authorization |
| registries/loop25_authorization_request.v1.json | green-amendment-bound replacement request; currently authorized_now: false |
| registries/loop25_authorization_decision.v1.json | separate hash-bound authorization record for the one completed target-free execution; protected scopes remain false |
| docs/LOOP_25_CAUSAL_PREPROCESSING_RESULT.md | measured static, fixture, replay, access, resource, warning, and claim-boundary closeout |
| registries/loop25_causal_preprocessing_result.v1.json | machine-readable Loop 25 measurements, hashes, counters, pass decision, and no-rerun boundary |
| docs/RW1_METADATA_ONLY_LOCAL_INTAKE.md | metadata-only file intake closeout |
| docs/RW2_PRIMARY_SOURCE_RESEARCH.md | reader/quality primary-source review |
| docs/RW2_SIGNAL_QUALITY_PREREGISTRATION.md | frozen RW2 protocol |
| docs/RW2_SIGNAL_QUALITY_CLOSEOUT.md | measured six-format RW2 implementation result |
| docs/RW3_PRIMARY_SOURCE_RESEARCH.md | BrainFlow, LSL, PyXDF, and clock primary-source review |
| docs/RW3_REPLAY_LIVE_EQUIVALENCE_PREREGISTRATION.md | frozen replay/live-source protocol; no implementation |
| registries/replay_equivalence_contract.v0.json | machine-readable RW3 schedules, fixtures, refusals, caps, and authorization flags |
| docs/RW3_STAGE_A_AUTHORIZATION_PACKET.md | exact Stage A scope, acceptance gates, caps, forbidden work, and decision language |
| registries/rw3_stage_a_authorization_request.v0.json | hash-bound machine request; currently authorized_now: false |
| docs/BYO_NEURODATA_WORKBENCH_SPEC.md | staged local neurodata workbench contract |
| docs/OPEN_SOURCE_READINESS.md | licensing, history, privacy, GitHub, and release gates |
| registries/datasets.v0.json | task-separated dataset candidates |
| registries/devices.v0.json | device and modality metadata, not qualification |
| docs/RISK_AND_ETHICS.md | privacy, licensing, ethics, and communication boundary |
Loop-specific closeouts in docs/LOOP_*.md preserve exact commands, metrics,
resources, failures, and claims.
Contributions are welcome, especially:
- deterministic format fixtures and malformed cases;
- metadata-only compatibility reports;
- EEG reference, geometry, timing, and unit validation;
- offline device replay and packet-loss audits;
- no-signal controls and split-leakage tests;
- accessibility, setup, and documentation improvements;
- small CPU-bounded baselines with honest negative reporting.
Start with CONTRIBUTING.md. It contains dedicated safe paths for people with EEG recordings and people with EEG headsets or boards.
| You have | Best first contribution | Keep private or gated |
|---|---|---|
| An EEG recording | Run metadata-only intake locally and share a redacted compatibility summary | Waveforms, event text, participant paths, demographics, and unreviewed derived caches |
| An EEG headset or board | Document channels, reference, clocks, transport, packet counters, export formats, and SDK license | Live connection details, private endpoints, credentials, and unapproved recordings |
| No EEG hardware | Add deterministic fixtures, malformed cases, refusal tests, docs, or no-signal controls | No real data is needed for these high-value paths |
Precision or local-runtime contributions should begin by reviewing the parked Loop 24 closeout and proposing a fresh hash-bound protocol. A benchmark pull request is not authorization to retune seed 2401 or open seed 2402, smaller weights are not proof of faster inference, and neither result is evidence of brain decoding or end-to-end text latency.
Loop 43 planning research also defines a future independent artifact
reproduction challenge. That challenge is currently Not Started and
unauthorized: opening an issue, rerunning the repository, or contributing EEG
does not create a challenge submission. A future eligible result would show
that one released target-free software artifact reproduced in one independent
environment; it would not be scientific replication, neural decoding evidence,
or generalization to people, platforms, devices, or home use.
The project deliberately treats an exact refusal, a privacy-preserving metadata report, or a reproducible negative result as a meaningful contribution. See I Have EEG Data and I Have An EEG Headset Or Board for the step-by-step routes.
Community files:
NeuroDecodeKit's original source code and documentation are licensed under the Apache License 2.0.
That license does not relicense Brain2Qwerty, SpanishBCBL, participant data,
models, papers, device SDKs, or optional dependencies. Brain2Qwerty and the
SpanishBCBL release are separately identified as CC-BY-NC-4.0; work using
them must respect their noncommercial and attribution terms.
Read THIRD_PARTY_NOTICES.md before using upstream code, data, or assets.
Use CITATION.cff to cite NeuroDecodeKit. Cite every dataset, paper, and upstream implementation separately; a software citation does not replace participant-data attribution.
NeuroDecodeKit builds on the public research ecosystem around Brain2Qwerty, SpanishBCBL/DECOMEG, MNE-Python, BIDS, and the broader EEG/MEG community. It is independent and is not endorsed by those projects or institutions.
The all-the-way research route is explicit in
Communication EEG Scientific Claim Program:
first establish EEG information beyond recorded eyes, mouth, cue, timing, and
no-signal shortcuts; reproduce it in a separate cohort; then qualify
dropout-safe causal streaming and one prospective unseen-person live run.
OpenNeuro ds003626-v2.1.2 is the leading future communication cohort, but the
planning record authorizes no new data access or scientific claim.
Engineering capability: NeuroDecodeKit provides a bounded, local, reproducible path from neurodata discovery and file qualification through caches, controls, small baselines, causal interface tests, and inspectable reports.
Scientific claim not established: the repository has not shown that neural signal beats language-only controls for practical text decoding, generalizes to new people, runs end to end in real time, or works on portable EEG hardware.