- docs/commit-map.tsv: 4,032 rows (ordinal of the ORIGINAL main -> rewritten hash, author/committer dates, subject);
1 pruned row of zeros (ordinal 1712, "session archive update"); 0 old hashes asserted; ordinal 1 unchanged by the
rewrite (byte-identical)
- resolve_tokens: 1,238 commit:NNNN tokens -> shortest-unique new hashes in 98 files (docs, phase-ends, logs, tool
docstrings, 2 C comments, the A5 evidence logs); residue left as tokens: commit:1712 x4 (the pruned commit),
commit:orphan-24 x2, commit:orphan-26, commit:orphan-35 (cited commits that exist in no lineage)
- the rewrite (C4): filter-repo 2.47.0 on a bare clone of the C2 tip, 311 s, exactly 1 pruned, main 4,032 -> 4,031;
the pre-rewrite history is mirrored in the private archive repo and in the local bundle
- the proof (C5): verify_rewrite 4,031 pairs / 0 failures; absent_scan 0 offenders; gate_scan 0 offenders on the clone
- adoption (C6): 100 text files differ at the tip, 0 purge paths, 0 added/deleted; leftover refs dropped; no gc yet
- resolver skips tools/public_rewrite/ (its self-test fixtures are the token grammar, not citations); repo-local
identity is the GitHub noreply address from here on; CURRENT_PHASE: C4–C7 logged, checkpoint -> NEXT = C8
- pre-checks: census (nothing project-authored under a purged dir), ignore coverage with `git check-ignore --no-index`
on every path, and the control that the public build needs none of it (main 143dbb89 byte-identical with tools/psyq
+ .run/obj40 + .run/obj42 moved aside; WITH state restored)
- after: git ls-files on every purge path = 0; no untracked purge path; tools/audit_public.py OK — 0 offenders among
6,566 tracked paths (255 before; the no-rom `audits` CI job goes green from here); make check-env 0
- docs/public-flip-runbook.md (NEW): Block C operational — decisions, actor table, C3..C11 with commands/checks, the
Support-ticket text, the probe, the fallback, the risk register, rollback; the mailmap is scratch, no personal
address in any tracked file
- SETUP §2.3/§2.4: the zips' sha256 + sizes (download-only now); verification.md: a --cached removal changes no
tracked-content byte, A5 holds for this tip; CLAUDE.md fail-safe: never `git clean -x` (ignored-but-present RE data);
decision-log R31 entry (why the purge leaves the index before the rewrite); CURRENT_PHASE -> NEXT = C1