# REPORT — making the picture true (2026-08-09, unattended) Read-only against all live infrastructure. **Both demo machines were powered off and in transit; no box was probed, woken or waited on.** Claims that only a running box could settle are marked `needs-hardware`, which is a verdict, not a gap. --- ## 1. The verdict table **55 claims. Statuses moved on 12 of them — all downwards.** `walked 32 → 20`, `built 5 → 17`; `partial 14` and `missing 4` unchanged. Full per-claim detail with sources is in `documentation/architecture/where-felhom-stands.yaml`. | claim | was | now | why | |---|---|---|---| | `install.installer-by-tag` | walked | **built** | gate 6 asserts the manifest names an installer tag; no walk of a rollback on file | | `use.lifecycle` | walked | **built** | no walk document cited | | `drives.enrol` | walked | **built** | the 08-09 walk exercised RE-attach (which failed, R-280); first enrolment of a NEW drive has no walk | | `drives.migrate` | walked | **built** | no walk document cited | | `backup.tier1` | walked | **built** | no walk document cited | | `backup.whole-machine` | walked | **built** | no walk document cited | | `backup.restore-proof` | walked | **built** | no walk cited, **and the last recorded restore-test on demo-hp FAILED** (2026-08-05) | | `fault.selfheal` | walked | **built** | no walk document cited | | `fault.operator-email` | walked | **built** | source-verified as correct, but no run observed delivering | | `fail.drive-filling` | walked | **built** | no walk document cited | | `fail.lost-recovery-code` | walked | **built** | by-design refusal; no walk document cited | | `fail.hub-down` | walked | **built** | no walk document cited | **Upgraded: 1.** `install.byo` — the page said *"the first real one has not happened"*. A real `--mode byo` install completed on demo-hp on 2026-08-09 (`Day-0 provision SUCCESS`, 3 m 49 s). Still not a customer's own hardware, so not *walked*, but the sentence was false. **`needs-hardware`: 4** — `use.lan-fallback`, `backup.restore-proof`, `fail.disk-failing`, `fail.internet-down`. Each needs an observation on a running box; each says which. **Confirmed: 38.** Seven of those were re-confirmed against live source or the live hub tonight rather than against paperwork: the tripwire, the off-site repository, the claim path, the catalogue, the tunnel, the reset code and the operator-email digest. ## 2. Every downgrade, with the coupling that broke The rule is *"a proof is about the code that existed when it ran"*. **It did not fire the way the task expected.** Not one downgrade came from code moving under an old proof. **All twelve came from step 1 of the same rule — the cited evidence does not exist.** Measured: of the 28 capability-map rows behind the page's claims, **8 carry a `tests/` or `audits/` path in their evidence column and 20 carry prose only.** The green dots were being drawn from rows that cite an argument, not a walk. Filed as **R-290**. **And the decay ran the other way once.** `fault.operator-email` — *"one mail per run, every failing app named"* — I first took to be contradicted by R-182 (open, *"tells the operator about ONE app and silently swallows every other"*). Reading live source: the digest `backup_run_failures` is allowlisted (`hub/internal/api/handler.go:1837`), operator-only (`notify/dispatcher.go:423`) and templated (`notify/templates.go:48`); `recovery_unit_capture_failed` is record-only (`dispatcher.go:376`); a cooldown drop now logs a `suppressed` row (`dispatcher.go:314-330`). **The claim is right and the register row is stale** — filed as **R-289**. The session went looking for stale proofs and found a stale defect. ## 3. The positive control ``` 1 BASELINE real dataset -> OK, exit 0 2 PLANT scratch copy: use.dlna missing -> walked -> CONVICTED, exit 1 "use.dlna: status 'walked' but NO evidence document cited" 3 REMOVE scratch copy deleted; committed dataset never touched 4 RE-RUN real dataset -> OK, exit 0 ``` Plant → convicted → removed → clean. The gate also convicted **51 problems in my own first draft** of the dataset (bad anchors, register ids that are not in `OPEN-ITEMS.md`, an evidence path that does not exist) before any of this — which is the more convincing demonstration, because it was not staged. ## 4. The two known disagreements — both settled, and neither document was wrong **"A customer restores their own data with no help."** The map says **MISSING (as evidence)**; the 2026-08-07 walk records a customer route completed with no shell. **Not a contradiction.** The map's row is *"A customer (**not the operator**) performs a restore via UI alone"* — it is about *who*. The walk proves the *route*. No non-operator has ever done it, which is what the page's own neighbouring claim already says. **The reinstall story.** The map's `PROVEN-LIVE (2026-08-04 night drill)` row is scoped in its own text to *"a controller-data-volume rebuild — NOT a total host loss"*. The 2026-08-09 rehearsal was a whole-host uninstall and reinstall. **The map has no row for that case at all** — a gap, not a disagreement. **Would anything here have caught either one? No — and it could not have, because neither was false.** Both are collisions of vocabulary: "customer" meaning *the route* or *a person*, "rebuild" meaning *the guest* or *the host*. No gate detects an ambiguity that makes two true sentences look contradictory. They surfaced only when someone tried to state them side by side. **That is the argument for the dataset** — one id, one scope, one status — and against prose rows. ## 5. The data file `documentation/architecture/where-felhom-stands.yaml`, 55 entries. **Every entry cites at least one source and the gate proves it** (`check_stands.py` rule 1). YAML rather than JSON because statuses move one line at a time and a YAML diff shows which claim moved; a JSON re-dump reflows. Rules honoured: it is a **view** (every entry cites map / register / evidence); **no status was raised in it** — the one upgrade is recorded against evidence and the map is named as the thing that must change; and it is **regenerated, not hand-edited** for the page. ## 6. The page - `where-felhom-stands.html` — **generated, 54 KB, zero `