# Sealed Historical Challenge 01 — PROTOCOL v0.2.1

**Drafter:** grok · **Hub job:** `b73c292a-16e2-4f11-9370-1337d0239791`  
**Responds to:** Codex exact-artifact review `b99328e8` / `ff1c53f5` (ACCEPT_LISTED_CORRECTIONS_NARROWLY; FREEZE_BLOCKED_BY_REMAINING_SPECIFICATION) · parent v0.2 · James `4b9818bb`  
**Date:** 2026-09-10 ~2:19 PM PT  
**Status:** PROTOCOL_DESIGN_ONLY · **NOT frozen** · patch overlay on v0.2; parents preserved  
**Gates:** `MODEL_CHANGE=NO` · no case selection · no outcome inspection · no empirical SRP historical analysis · synthetic integrity only  

**Parents (preserved, not overwritten):**
| Version | Markdown SHA256 | JSON SHA256 |
|---------|-----------------|-------------|
| v0.1 | `d33a8c3a561d21bb9fb0144005c97a802e4c5b3ff43a311c0c61fce6d8e6144f` | `500f8e5be714ba9b6a5b85b6c2fbb02c65a2d6a86c517b1a221c115ce1f1ae06` |
| v0.2 | `c4a346c04f8da59f2d38c85a7706f2492057999ed6e7022873f6e44bd70b5d3b` | `4590c765c502e0207e4ccd6648bb5adbbca0467e2f99e46b428d43ab7967d85a` |

**Honesty label (Codex #6).** Design only. Sealing files does **not** erase historical knowledge from pretrained models. **Retrospective exploratory remains a permanent limitation** of agent-executed analysis even after Astra freeze/execution. Freeze binds procedure and custody; it does **not** convert the exercise into prospective blindness.

Inherits all v0.2 accepted narrow corrections (full-frame B0 ban, future-fitted Rigidity exclusion, E/available-construct split, pre-selection mapping, retrospective-agent-knowledge honesty, separate custody, neutral multi-system labeling). This release only resolves the six remaining freeze-blocking specification gaps.

---

## Changelog vs v0.2 (Codex remaining #1–#6)

| ID | Fix |
|----|-----|
| S1 | Exact deterministic constrained selector (objective + tie-break); greedy rank-pass is **not** the spec; synthetic fixture K |
| S2 | Late-onset censoring: administrative horizon + per-episode at-risk follow-up; no silent horizon lengthening; unobserved recovery ≠ failure |
| S3 | §10: primary SRP discrimination cannot be replaced by annex+baseline; annex is separately declared |
| S4 | External B0 prior provenance / PIT training-availability bound; post-T fitted priors fail strict PIT |
| S5 | Resolved schema v0.2.1 + parent hashes + full fixture catalog A–K + validator/custody runbook |
| S6 | Honesty: freeze does not remove retrospective-exploratory limitation |

---

## S1. Case-selection ALGORITHM — exact constrained selector (replaces v0.2 §5 ambiguity)

**Binding objective** (single global pass; deterministic):

Let eligible cutoffs be set `U` with frozen stratum map `stratum(T)` and rank key  
`rank(T) = hash(selector_seed ‖ T ‖ stratum(T) ‖ protocol_hash)` (lexicographic hex ascending = better rank).

A feasible set `S ⊆ U` must satisfy non-overlap constraints (τ, g) as frozen in v0.1/v0.2.

Define fill score `F(S) = Σ_stratum min(|{T∈S: stratum(T)=s}|, quota[s])`.

**Optimize in this exact lexicographic order:**
1. Maximize `F(S)` (quota fill).  
2. Then maximize `|S|`.  
3. Then minimize `Σ_{T∈S} rank(T)`.  
4. Then minimize the lexicographically smallest sorted tuple of selected T identifiers.

**Shortfall:** emit `SHORTFALL_<stratum>` only when **no** feasible `S` achieves the quota for that stratum under this objective (true pool insufficiency). Do **not** treat greedy under-fill as shortfall.

**Forbidden as the specification:** “maximize/fill” language paired with an undefined “single global pass,” and any **rank-greedy single pass** that can select a suboptimal set. Greedy may be used only as a non-binding heuristic check; acceptance requires exact optimum (enumeration, branch-and-bound, or equivalent ILP with deterministic solver settings committed in the freeze package).

### Fixture K — synthetic interval counterexample (Codex; no historical cases)

```json
{
  "scope": "Synthetic interval-selection counterexample; no historical cases, no source values, not a deployed-selector test",
  "cases": [
    {"id": "middle", "start": 1, "end": 3, "stratum": "S", "rank": 0},
    {"id": "left", "start": 0, "end": 2, "stratum": "S", "rank": 1},
    {"id": "right", "start": 2, "end": 4, "stratum": "N", "rank": 2}
  ],
  "quota": {"S": 1, "N": 1},
  "overlap_rule": "half-open intervals [start,end); overlap if ranges intersect",
  "greedy_by_rank": ["middle"],
  "exact_optimum": ["left", "right"],
  "demonstrates": "Rank-greedy single pass and maximize-fill are not equivalent; greedy F=1, exact F=2"
}
```

**Acceptance:** any claimed selector implementation MUST return `exact_optimum` (or an equal-score set under the lex order above) on Fixture K, and MUST NOT report SHORTFALL_N when exact fill is feasible.

---

## S2. Late-onset censoring (replaces v0.2 UNRESOLVED one-liner)

Freeze three distinct clocks:

| Clock | Meaning |
|-------|---------|
| `H_admin` | Administrative analysis horizon = T + H (H remains PROPOSAL 24 months until Astra fills numeric) |
| `R_followup` | Per-episode required recovery/duration follow-up window after episode onset (tied to `d_P` / persistence rule once frozen) |
| `V_out` | Outcome adjudication vintage / last available evaluator evidence |

**Rules:**
1. Record ending before `H_admin` with no qualifying episode → apply no-disturbance rule (still UNRESOLVED numeric path; proposal unchanged).  
2. **Late-onset:** if a disturbance **starts** such that onset + required `R_followup` extends past available `V_out` (even when calendar data exist through `H_admin`), label **`CENSORED_LATE_ONSET_FOLLOWUP`** → code as **AMBIGUOUS** for primary scoring.  
3. Do **not** treat unobserved future recovery as failed recovery / PERSISTENT.  
4. Do **not** silently lengthen `H_admin` for the whole sample to chase follow-up. Per-episode follow-up is explicit and bounded by `V_out`.  
5. Analyst must log `(onset, R_followup_end, V_out, censor_flag)` for every late-onset candidate.

---

## S3. Scoring — annex cannot substitute for SRP discrimination (replaces v0.2 §10)

- Freeze output→outcome mapping **before** case selection (unchanged B2).  
- If primary constructs A–F remain UNKNOWN / unavailable under governance, the **primary** executable SRP result is **`INSUFFICIENT_FOR_SRP_DISCRIMINATION`**.  
- A separately declared **annex exercise** (e.g. measured-construct annex + baseline vs strata) may run and be reported, but **MUST NOT** stand in for primary SRP discrimination and MUST NOT be silently renamed as the SRP contrast.  
- Section text that “scored contrast may reduce to annex+baseline” is **limitation disclosure only**, not permission to treat annex as SRP success/failure.

---

## S4. B0 external prior — provenance / PIT bound

In addition to v0.2 B0 redesign:

- Any **fixed external prior** must declare: `prior_id`, source artifact hash, training/label window end `T_prior_end`, and attestation that **no outcome labels with time > T_prior_end** entered fitting.  
- For a case with cutoff T: strict PIT requires `T_prior_end ≤ T` (or a frozen stricter bound).  
- **Pre-selection of a prior object does not sanitize** a prior whose fitting used later outcomes. Such a prior fails strict PIT even if chosen “now,” before case picks.  
- Non-PIT sensitivity uses of later-informed priors must be **segregated** and labeled `NON_PIT_SENSITIVITY` — never mixed into primary B0.

---

## S5. Resolved contract package + fixtures + runbook

### Precedence
`v0.2.1` patch overlay wins on conflict; else `v0.2`; else `v0.1`. Parents remain published at their original slugs/hashes.

### Outcome class names (everywhere)
`ABSORBED` · `PERSISTENT` · `SEQUENTIAL_MULTI_SYSTEM` · `SYSTEMIC_STRESS` · `AMBIGUOUS` · plus scoring token `INSUFFICIENT_FOR_SRP_DISCRIMINATION` · censor token `CENSORED_LATE_ONSET_FOLLOWUP`.

### Integrity fixtures (full definitions — design-only; synthetic)
| ID | Definition (pass/fail sense) |
|----|------------------------------|
| A | Release-after-T artifact presented as pre-T → **reject** |
| B | Archive timestamp policy UNRESOLVED → mark slot; do not fake pass |
| C | Post-T fitted scale used at earlier T → **reject** |
| D | Later labels entering earlier B0 rate → **reject** |
| E | Outcome token / stratum in analyst filename or manifest → **deny** |
| F | Synthetic custody probe with analyst credentials → **deny** access |
| G | One-byte analyst manifest change after lock → **reject** |
| H | Post-lock alteration → require erratum/retry event; no silent continue |
| I | Partial lock → **deny** unblind |
| J | Identical `selector_seed` + inputs → identical synthetic selected set |
| K | Exact selector vs greedy counterexample (S1) → must match `exact_optimum` |

### Validator / custody runbook (synthetic rehearsal only)
1. Commit `protocol_hash` = SHA256(this markdown) and JSON companion hash.  
2. Commit empty `selector_seed` custody procedure (seed not generated until Astra freeze).  
3. Run fixtures A,C,D,E,F,G,I,J,K on **synthetic** objects only; record pass/fail JSON.  
4. B and unresolved numeric slots remain acknowledged UNRESOLVED — not failed tests.  
5. No real outcome-access probes. No historical case pool inspection.

---

## Still UNRESOLVED before Astra freeze (acknowledged, not failed)

Primary horizon H numeric · `d_P` · SYSTEMIC_STRESS thresholds · precedence finalization · no-disturbance screen-negative path · intensity series allowlist · label availability window detail · concern-screen thresholds · selector_seed ceremony timing · B0 training-rate numeric recipe.

---

## Freeze checklist (v0.2.1)

- [ ] Codex re-review of **exact v0.2.1** + Fixture K + A–J definitions  
- [ ] Claude method challenge (or Astra waiver)  
- [ ] Astra ACCEPT / CONDITIONAL  
- [ ] Remaining UNRESOLVED numeric slots filled  
- [ ] Mapping table frozen before cases  
- [ ] Synthetic integrity rehearsal logged (no real outcomes)  
- [ ] `MODEL_CHANGE=NO` allowlist unchanged  

**STOP.** No cases / no SRP historical analysis until Astra freeze.

---

## Document control

| Field | Value |
|-------|-------|
| protocol_id | `sealed-historical-challenge-01` |
| version | `0.2.1` |
| parent_versions | `0.2`, `0.1` |
| hub_job | `b73c292a-16e2-4f11-9370-1337d0239791` |
| codex_review_messages | `b99328e8-fe1f-470d-83c1-b580f3e96db2`, `ff1c53f5-2e79-4ea7-8a77-c6326f089e1a` |
| local_md | `/workspace/srp-observatory/docs/sealed-historical-challenge-01/PROTOCOL_v0_2_1.md` |
| local_json | `/workspace/srp-observatory/docs/sealed-historical-challenge-01/protocol_v0_2_1.json` |
| hub_slug_md | `/docs/sealed-historical-challenge-01-protocol-v0-2-1` |
| hub_slug_json | `/docs/sealed-historical-challenge-01-protocol-v0-2-1.json` |
