Simulation theory

Reality as a Consensus Protocol

Authors: Bernhard Mueller, Kai Xue, Kale Arnav Anirudha, David Matscheko, Jonathan Hill

Abstract

The OPH fixed-point consensus paper. It formulates observer patches, overlap-visible records, repair moves, Lyapunov descent, quotient normal forms, and obstruction classes.

r1577 July 23, 2026 papers
Section jump

Paper release: r1577 Released: July 23, 2026

Downstream physical boundary

The fixed-cutoff consensus theorem supplies a finite observer-like self-reading system only on the declared recovery, record, feedback, selected-fiber, and implementation-invariance packet. It does not select the physical twelve-port \(A_5\) carrier, attach a canonical rank-three screen band to matter, construct a chiral quantum field theory, or determine a W/Z pole. Those claims require separately typed physical producers. The A5 result is a conditional finite recognition criterion, and the W/Z sufficiency stack has no OPH-native pole promotion.

This boundary does not make consensus carrier-neutral. The repair theorem is invariant under hidden presentation changes preserving the complete visible observer contract. Port incidence, orientation, accessible algebra, response, repair law, record process, clock, and refinement lineage belong to that contract and may constrain downstream physics. On the unified Echosahedral branch, microphysics supplies the candidate carrier, this paper supplies its public normal form, and the compact paper supplies separately gated geometry and current projections.

One carrier stack, three paper surfaces

The microphysics, consensus, and compact SM/GR papers describe one typed construction. The microphysics paper owns the finite carrier and its public interfaces. The consensus paper owns accepted repair and the quotient public normal form. The compact paper owns the conditional maps from that public normal form into support geometry, gravity, compact currents, and matter. A claim may cross from one paper to another only through the exported object and premises named here.

Three meanings of screen

The word “screen” is used for three related objects that must not be identified without a receipt.

  1. The local carrier boundary is the twelve-port oriented interface of one Echosahedral carrier on the declared branch. Its incidence has \((V,E,F)=(12,30,20)\).

  2. The federation screen is the routed system of interfaces, records, repairs, and checkpoints of many carriers at finite cutoff.

  3. The support screen is the observer-facing geometric chart. On the spherical branch it is the refined conformal \(S^2\) used for caps, collars, modular flow, and Lorentz reconstruction.

Local icosahedral incidence does not determine the topology of the federation nerve. A federation of identical local carriers can be routed as a path, a cycle, a higher-genus complex, or a spherical complex. The map from routed carriers to a support-visible spherical nerve is therefore a physical bridge, not a change of notation.

Structure-sensitive, presentation-invariant physics

OPH is not neutral under arbitrary changes of substrate. It is invariant under changes of presentation that preserve the complete observer-visible carrier signature. On the Echosahedral branch that signature contains

\[ \mathcal C_{i,r}= \bigl( \mathcal A_{i,r},\rho_{i,r},P_{i,r},I_{i,r}^{\rm or}, \mathcal R_{i,r},\mathcal U_{i,r},\mathsf{Chk}_{i,r}, \mathsf{Resp}_{i,r},c_{sr} \bigr), \]

where \(P_{i,r}\) is the port set, \(I_{i,r}^{\rm or}\) is oriented incidence, \(\mathcal R_{i,r}\) is the record algebra, \(\mathcal U_{i,r}\) is the repair or feedback interface, \(\mathsf{Resp}_{i,r}\) is the visible response law, and \(c_{sr}\) is the refinement lineage. Hidden coordinates, port names, worker partitions, materials, and wiring presentations are silent when an isomorphism preserves this whole tuple and its error model. A change in port number, incidence, orientation, accessible algebra, response, repair law, clock, or refinement lineage need not be silent. A cube and an icosahedron are therefore different carrier contracts even when both are built from the same material.

A carrier body is not automatically an observer. It realizes an observer only when it supplies bounded access, self-readback, durable records, record-conditioned feedback, boundary prediction against controls, and checkpoint continuation. One carrier may pass that test. A connected subfederation may pass it instead. No theorem fixes primitive observer size by counting carrier bodies.

The common finite computation

At cutoff \(r\), source-bound carrier data are routed into an observer-patch federation. Accepted repair then acts on the physical quotient:

\[ \begin{aligned} \mathsf{SourceCarrierTower}_r &\xrightarrow{\;\mathsf{realize/route}\;} \mathsf{ObserverFederation}_r\\ &\xrightarrow{\;\pi_r\;} \mathsf{PhysicalQuotient}_r \xrightarrow{\;\operatorname{Rep}_r\;} \mathsf{PublicNormalForm}_r. \end{aligned} \]

The last arrow is the consensus result only under semantic-dependency-complete transactions, coherent union-collar payloads, repair completeness, local diamonds, protected records, and the stated endpoint conditions. A collection of oscillators with equal frequency does not supply those clauses.

Physical phase locking can instantiate one synchronization layer. For a routed edge \(e=((i,a),(j,b))\), a source-produced phase record may certify frequency entrainment and a stable relative phase,

\[ \dot\theta_{i,a}-\dot\theta_{j,b}\longrightarrow0, \qquad d_{S^1}(\theta_{i,a}-\theta_{j,b},\delta_e)\le\varepsilon_e. \]

That certificate becomes a consensus parent only when the phase record fixes a commensurability map for the exposed packets and is tied to the accepted repair ledger, semantic records, an independently calibrated clock, and the confluence premises. Phase locking can synchronize an interface. It does not by itself make the interface an observer, settle semantic disagreement, or produce physical time.

Two downstream projections of one source

The public normal form has two separately typed projections:

\[ \begin{aligned} \mathsf{PublicNormalForm}_r &\xrightarrow{\;\mathsf{carrier\text{-}to\text{-}support}\;} \bigl(\mathsf{Support}_{S^2,r},\mathsf{FiniteCapBWCertificate}_r\bigr),\\ \left. \begin{gathered} \mathsf{FiniteCapBWCertificate}_r\\ \mathsf{MGNS\text{-}1}_r\ \text{independently complete} \end{gathered} \right\}_{\text{same tower}} &\longrightarrow \mathsf{BW/KMS}_r \longrightarrow \mathsf{Lorentz/H^3}_r\\ &\longrightarrow \mathsf{Events}_{3+1,r} \longrightarrow \mathsf{Einstein}_r , \end{aligned} \] \[ \begin{aligned} \mathsf{PublicNormalForm}_r &\xrightarrow{\;\mathsf{port\text{-}response}\;} (\mathsf{A5Carrier}_r,J_r)\\ &\longrightarrow \mathsf{CompactCurrent}_r \longrightarrow \mathsf{SM}_{Q0,r}\\ &\longrightarrow \mathsf{Matter/QFT}_r . \end{aligned} \]

The carrier-to-support leg requires full interface algebra homomorphisms, higher-overlap coherence, spherical incidence, refinement-natural mesh and cross-ratio data, and an independently normalized geometric \(2\pi\)-KMS comparison. It emits the support \(S^2\) and \(\mathsf{FiniteCapBWCertificate}\). The state tower, common-comparison maps, compatible state/vector data, modular controls, and cofinal modulus belong to the independently produced \(\mathsf{MGNS\text{-}1}\) package. The BW theorem consumes both inputs on the same tower. Once the support leg produces a conformal \(S^2\), \(\operatorname{Conf}^+(S^2)\cong\operatorname{SO}^+(3,1)\) and \(H^3=\operatorname{SO}^+(3,1)/\operatorname{SO}(3)\) is exactly three-dimensional. \(H^3\) is the observer-frame fiber. A \(3{+}1\)-dimensional event manifold requires the population/realization, separation, rank-four affine-chart, overlap-cocycle, held-out quadratic-cone, and causal-reachability receipts \(\mathsf{(E1)}\)\(\mathsf{(E6)}\), together with the \(\mathsf{MI}\)/assembly premise. Operational-clock gluing separately requires observer-readable transitions, event correspondence, affine calibration, cycle identity, and normal-form invariance. The Einstein relation additionally requires the common-domain stress, entropy, vacuum, coupling, scale, and remainder packet. Hidden Cartesian coordinates of a finite carrier are ineligible as support-screen, event, or Lorentz data.

The second projection begins with an exact finite result on the certified Echosahedral lineage. The twelve-port module decomposes as

\[ P_{12}\cong_{A_5}\mathbf1\oplus\mathbf3\oplus\mathbf3'\oplus\mathbf5. \]

The source selector derives the twelve unit lines, antipodal pairing, proper \(A_5\) action, and rank-three Gram frame. On a declared charged-double-triplet response representation with four signed nonzero coefficients, an exact finite certificate constructs a full-rank, compact, skew-adjoint, commutator-closed algebra with inner \(A_5\) action and algebraic refinement naturality. The representation, coefficients, and physical refinement maps require source binding before these register and algebra facts become gauge facts. Noncentral action of the five-dimensional block then selects the Standard-Model Lie type from the compact classification. Trace balance, Spin and deck descent, matter selection, exclusion of extra sectors, family attachment, and quantum-field construction remain separate maps.

The compact sector-category and Minimal Admissible Realization route conditionally reconstructs an abstract Standard Model quotient of the same type by a logically independent route. Physical unification requires a source-bound commuting square identifying its reconstructed compact group with the group acting through the Echosahedral current response:

\[ \begin{array}{ccc} \mathsf{A5PortResponse}_r & \longrightarrow & G_r^{\rm screen}\\ \downarrow & & \downarrow\scriptstyle{\simeq}\\ \mathsf{TransportableSectorCategory}_r & \longrightarrow & G_r^{\rm DR/MAR}. \end{array} \]

On those premises the abstract Lie-type agreement is exact. The physical vertical maps and the source identity of the two group actions are open. In the same way, the rank-three face band is a canonical candidate family carrier, while three physical generations require the complex rank-45 attachment and complement-complete refinement receipts. The value \(N_g=3\) in the compact paper is the minimum of the declared economy class, not a consequence of the icosahedral graph alone.

Finite controls and status boundaries

The finite \(A_5\) evaluator control has \(60\) reachable correctable public records on \(\mathcal H_k=\ell^2(A_5)\otimes\mathbb C^k\):

\[ M_0=60,\qquad D_{\rm raw}=60k,\qquad \Delta_{\rm raw}=60(k-1). \]

Raw equality occurs only at \(k=1\). Publicly inert multiplicity makes \(D_{\rm raw}\) implementation-dependent, so the result is an evaluator control rather than physical capacity closure.

The unified claim has a precise scope. Consensus, geometry/gravity, and gauge/matter are composable branches of one source-bound self-reading carrier tower. Its full quotient-visible architecture can constrain both branches; local icosahedral incidence by itself constrains only the local carrier route. The physical maps that turn those constraints into one inhabited universe are named premises. Matching dimensions or symmetry labels does not supply them.

What This Paper Contributes

The mathematics of repair is old in the right places. Constraint satisfaction, rewriting systems, well-founded descent, local-diamond confluence, inverse limits, and recovery channels all enter this paper with their standard meanings. OPH adds the physical reading: each variable is an observer patch, each constraint is an overlap-visible record check, and each accepted rewrite is a local repair move that must descend to the quotient seen by neighboring observers.

That turns consensus into the implementation layer of the theory. The paper proves when finite patch repair terminates, when the terminal public state is schedule-independent, how boundary data control uniqueness, and how cycle holonomy records the exact obstruction to global agreement. Its finite results support the stack’s mathematical core. The paper also explains why a bare overlap graph is only a finite constraint code. Stronger language such as quantum error correction, min-cut distance, BFT liveness, or hardware speedup needs its own certificate.

Synchronization and consensus are distinct. A physical phase-lock process may establish a stable relative phase and a commensurability map between two exposed ports. It enters this theorem only after its phase records are tied to the accepted transaction ledger, an independent clock, the semantic record surface, and the confluence premises. Frequency entrainment alone can coexist with conflicting records.

Introduction

This paper writes the OPH consensus picture in the simplest concrete form. A universe is represented as a finite graph of observer patches. Each patch carries local state data, neighboring patches compare those data on overlaps, and local repair moves try to reconcile any mismatch. The central mathematical question is whether this repair dynamics converges to one shared world and how the unavoidable obstructions are encoded when it does not.

The word “dynamics” is used here in the rewriting-system sense. The repair schedule selects terminal normal forms and proves schedule independence under the stated hypotheses. The selected observer-facing structure can carry an internal record order, which is read as history. A conventional simulation computes a surrogate history. OPH computes the fixed point and its quotient-visible records. Physical-clock status additionally requires an observer-readable transition process, event correspondence, and affine clock calibration. The patch-net algorithm is a theorem device for fixed-point selection. The fundamental description contains no global timeline on which spacetime contents are rendered.

A bare fixed point is not called an OPH simulation below. Definition 70 requires recovery-derived endogenous update, nontrivial quotient-readable records, overlap repair with schedule-independent normal form, elimination of a proper candidate basin in the selected boundary/sector fiber, and implementation/clock closure. Theorem 71 proves those clauses on the named finite branch and supplies a generic fixed-point and variational counterexample.

The resulting theorem package has two layers, bounded by the constraint-code firewall stated once in the summary list below. The first core consensus layer concerns convergence: primitive recovery proposals are eligible only when they satisfy the touched-overlap local-fit contract, but a proposal becomes physical only through transactional acceptance with snapshot validation, protected-boundary preservation, and exact well-founded descent. This accepted finite relation induces a total, idempotent, boundary-preserving quotient normal-form map \[ \operatorname{Rep}_\lambda:Q\to Q. \] Connected conflict components commit atomically through coherent canonical union-collar payloads. Semantic-dependency-complete read sets, conflict components, snapshot-determined payloads, and revalidation prove the local diamond on the physical quotient. A schedule-independent normal form follows when these premises and repair completeness hold. The concrete receipt checks those premises and the resulting finite peaks. The stronger claim that all interiors with the same boundary data settle to the same state requires preservation of that boundary data plus a unique consistent extension in the corresponding fiber; the layered functional carrier proves a finite multi-edge witness for this condition, and the functional selected-fiber branch gives the rooted obstruction-check form. The second concerns obstructions: pairwise overlap agreement does not ensure a global solution, and the obstruction is holonomic. On the abelian branch it is the cycle sum of edge data; on the genuinely noncentral branch it is a crossed-module Čech class.

Gauge symmetry enters as invariance under changes of hidden local representation that preserve overlap data. When the repair step is read only on that overlap-invariant quotient, the normal-form map descends to the gauge quotient, so physical uniqueness is a quotient statement. On the quantum lift, the same quotient-local carrier determines a unique terminal state on every declared physical observable algebra, even when microscopic representative lifts differ by gauge or sector relabelings inside one quotient-local glued state. The observation layer is carried by finite observer-accessible record algebras generated by central or quantitatively stable approximately commuting projectors. These results form the patch-net formulation used in the broader OPH literature, including the fixed-cutoff Bell/CHSH package on the companion microphysics surface.

This paper proves a constraint-code firewall and nine core consensus results:

  1. Constraint-code firewall. A finite overlap net defines a finite constraint code: its codewords are exactly the globally consistent states, and \(C=\Phi^{-1}(0)\) (Proposition 3). This is the default meaning of “the overlap network is a code.” It is not, by itself, a quantum error-correcting code and does not imply a graph min-cut formula for distance (Theorem 112). The same firewall blocks semantic promotion by relabeling: a finite constraint, archive, repair spectrum, or reconstruction threshold remains a finite diagnostic until a source-separated physical bridge supplies the relevant readout, residual ledger, controls, and frozen validation target.

  2. Asynchronous confluence. For the declared accepted repair law, primitive recovery proposals pass through transactional snapshot/read/write validation, semantic-dependency-complete boundary, sector, history, and checkpoint preservation, and exact descent. The accepted relation induces a total local quotient repair map \(\operatorname{locRep}_\lambda:Q\to Q\) and a total idempotent global repair map \(\operatorname{Rep}_\lambda=\overline{\operatorname{nf}}_\lambda:Q\to Q\). A coherent canonical aggregate per conflict component and semantic-complete revalidation prove the quotient local diamond. The implementation receipt checks these premises and the concrete finite peaks. With repair completeness, every fixed initial quotient state has a unique normal form, independent of update schedule (Proposition 13, Proposition 27, and Theorems 15 and 29).

  3. Cycle obstruction. For affine overlap constraints over an abelian group, global consistency holds if and only if the holonomy vanishes on every cycle (Theorem 32). The parity triangle gives the minimal frustrated example, and Theorem 35 extends the same logic to the crossed-module higher-gauge defect hierarchy used later in the framework.

  4. Gauge quotient, selected fibers, and observable-level confluence. When local repair is induced on the overlap-invariant quotient, the normal-form map descends to that quotient, \(\operatorname{Rep}_\lambda\circ q\) is invariant under gauge/implementation hiding, and the induced terminal state on every declared physical observable algebra is unique there even when microscopic representatives differ by gauge or sector relabelings inside one quotient-local glued state. If a boundary/sector map is preserved and each consistent boundary fiber has at most one quotient extension, then all initial states with that boundary value settle to the same quotient normal form; the layered functional carrier proves \(H_B\wedge H_{\mathrm{fib}}\) on a finite multi-edge, multi-step carrier, while the functional selected-fiber branch proves a nontrivial rooted case where multiple same-boundary interiors exist, inconsistent candidates are eliminated, and surviving candidates share one quotient normal form (Theorems 37, 39, 42, 44, Corollaries 38, 43, 46, and Theorem 52).

  5. Refinement-limit consensus classes. On a separated cofinal refinement system whose restriction maps commute with the finite-stage normal-form and holonomy maps, the quotient normal forms and holonomy obstructions assemble into unique inverse-limit classes with finite-stage visibility (Theorem 59).

  6. Coarse-graining compatibility. On any refinement system whose coarse-graining maps shadow finite-stage normal forms and holonomy maps with declared errors, reconciling first and then coarse-graining gives the same macroscopic law data as coarse-graining first and then reconciling, up to those errors; in the exact natural case the error is zero (Theorem 66).

  7. Record algebra and stability. On the fixed-cutoff observer-accessible surface, central record projectors carry Born/Lüders measurement directly, and approximate record projectors inherit explicit \((\varepsilon,\delta_{\mathrm{rec}})\) stability bounds on the same event surface (Theorem 69).

  8. OPH simulation firewall. On a selected boundary/sector fiber, “simulation” requires recovery-derived endogenous update, nontrivial quotient-readable records, strict overlap-repair descent with a schedule-independent normal form, collapse of a proper candidate basin to one consistent quotient state, and implementation/clock closure. Under the stated selected-fiber and record hypotheses, the finite OPH packet has this certificate; a generic identity fixed point or constant variational functional does not (Definition 70, Theorem 71, and Remark 72).

  9. Distributed one-universe realization. A worker implementation is a presentation of one finite OPH universe only when the run starts from one global carrier and every distributed event projects to a legal monolithic repair path, a physical stutter, or a certified rollback to an earlier committed projection. Under those hypotheses, partition, worker count, schedule, restart history, and repartition metadata do not change quotient observables or observer readouts that factor through the monolithic normal form (Theorem 78 and Corollary 79).

  10. Conditional noisy fair-block consensus. If a noisy asynchronous implementation admits fair repair blocks, a uniform expected contraction toward the exact quotient normal-form set, and controlled within-block excursions, then all long runs stay in a controlled expected tube around that exact normal-form set. In singleton boundary/sector fibers, Lipschitz observer readouts are approximately schedule-independent, and a finite Markov-kernel certificate checks the block contraction on finite exported nets (Theorem 84, Corollaries 8586, and Proposition 87).

The repair step itself is a concrete recovery move, not a free rewrite primitive. On the fixed-cutoff collar branch, a local update is obtained from exact Markov splice or from a declared Petz/Fawzi–Renner recovery channel and then read on overlap-invariant physical data. The fixed-point theorem below isolates the separate branch conditions cleanly: the declared repair law includes the touched-overlap local-fit contract for primitive proposals, while transactional acceptance validates snapshots, protected data, unchanged registers, and exact descent. The fixed-cutoff gluing package carries a parenthesization-independent union-collar payload only on a branch with an exact aligned Markov construction, a coherent canonical recovery construction, or a primitive aggregate-payload receipt. Repair completeness, the quotient-level local diamond, and, on the Petz branch, the support/CPTP clause remain separate conditions stated in Proposition 107. A nontrivial exported rooted-tree packet domain where these clauses are proved is recorded in Definition 19 and Theorem 20; the separate layered functional carrier records the finite multi-edge boundary-reconstruction witness.

We also define a fitness functional over a finite candidate space of reconciliation laws and prove that replicator dynamics monotonically increases mean fitness (Theorem 91). This gives a clean mathematical model for finite-candidate law selection, not a universality theorem or a literal cosmological dynamics claim.

The results here are exact theorems about a computational model. The companion OPH manuscript uses separate support levels for structural theorems, scaling limits, quantitative particle outputs, and phenomenological continuations .

Patch Nets, Overlaps, and Global Consistency

Definition 1 (Patch net). Let \(G=(V,E)\) be a finite connected graph. Each vertex \(i\in V\) is an observer patch with finite local state space \(S_i\). The global state space is \[ \Sigma := \prod_{i\in V} S_i. \] For each edge \(e=\{i,j\}\in E\), let \(I_e\) be an interface alphabet and let \[ \pi_{i,e}:S_i\to I_e, \qquad \pi_{j,e}:S_j\to I_e \] be the interface projection maps. A global state \(s=(s_i)_{i\in V}\in\Sigma\) is consistent on edge \(e=\{i,j\}\) iff \[ \pi_{i,e}(s_i)=\pi_{j,e}(s_j). \] The global consistency set is \[ C:=\bigl\{s\in\Sigma:\forall\, e=\{i,j\}\in E,\ \pi_{i,e}(s_i)=\pi_{j,e}(s_j)\bigr\}. \]

For exposition we use a finite pairwise-overlap graph. The hypergraph version is straightforward: replace edges by hyperedges and pairwise equality by a common interface label on each hyperedge. Nothing in the proofs depends on the pairwise restriction.

The picture: each observer holds a local state, and neighboring observers share an interface through which they can compare notes. A universe-state is physically admissible exactly when all neighbors agree on their shared data. This is a constraint satisfaction problem (CSP), and the consistent states are the codewords.

Definition 2 (Inconsistency potential). For each edge \(e\), choose a weight \(w_e>0\) and a function \(d_e:I_e\times I_e\to\mathbb{R}_{\ge 0}\) with \(d_e(a,b)=0 \iff a=b\). On the declared fixed-cutoff branch, \(d_e\) is the overlap score used by the local acceptance contract on that interface. Define \[ \Phi(s) := \sum_{e=\{i,j\}\in E} w_e\, d_e\!\bigl(\pi_{i,e}(s_i),\pi_{j,e}(s_j)\bigr). \] Then \(s\in C \iff \Phi(s)=0\).

Proposition 3 (Bare overlap nets are finite constraint codes). For every finite patch net of Definition 1, the consistency set \(C\subseteq \Sigma\) is a finite constraint code whose codewords are exactly the globally overlap-consistent states. With the mismatch potential of Definition 2, \[ C=\Phi^{-1}(0). \] This proposition is the theorem-grade content of the unqualified phrase “the overlap network is a code.” It supplies a finite constraint code, not a quantum error-correcting code, not a topological code, not a graph-theoretic formula for code distance, and not a Lorentzian or Einstein-geometry theorem.

Proof. Finiteness follows from \(\Sigma=\prod_i S_i\) with finite \(S_i\). The definition of \(C\) is a finite family of interface-equality constraints, so \(C\) is the set of satisfying assignments. Since each \(w_e>0\) and \(d_e(a,b)=0\) exactly when \(a=b\), every term in \(\Phi\) is nonnegative and vanishes exactly on a satisfied edge constraint. Therefore all edge constraints hold if and only if \(\Phi(s)=0\). ◻

Remark 4 (Bare consensus does not supply the cap-normal \(H^3\) chart). Bare finite consensus supplies quotient normal forms, boundary data, and obstruction classes. It does not itself supply the future null cone, a round-cap support chart, conformal transport, a time orientation, or the \(H^3\) observer-frame homogeneous space. The cap-normal theorem in the compact paper applies only after the separate geometric-readout Bisognano–Wichmann (BW) branch has emitted an oriented conformal \(S^2\), nondegenerate oriented round caps, and proper-orthochronous conformal transport. This is why the finite-consensus to Einstein branch-entry arrow remains a separate proof burden.

Definition 5 (Bare finite consensus reduct). A bare finite consensus reduct at regulator \(r\) is \[ \mathsf{Cons}_r \mathrel{=} (\Sigma_r,\Gamma_r,Q_r,\Phi_r,\to_r,n_r,C_r,B_r), \] where \(\Sigma_r\) is the finite presentation space, \(\Gamma_r\) is the presentation-redundancy groupoid, \(Q_r=\Sigma_r/\Gamma_r\) is the physical quotient, \(\Phi_r\) is the mismatch functional, \(\to_r\) is the accepted repair relation, \(n_r\) is the quotient normal-form map, and \[ C_r=\Phi_r^{-1}(0) \] is the globally overlap-consistent set, and \(B_r\) is its boundary-data readout.

Theorem 6 (Bare finite consensus is not Einstein-complete). The bare finite consensus reduct \(\mathsf{Cons}_r\) does not determine a Lorentzian metric \(g_{ab}\), stress tensor \(T_{ab}\), Newton coupling \(G\), area/edge operator \(L_C\), generalized entropy \(S_{\mathrm{gen}}\), modular geometric flow, or the equation \[ G_{ab}+\Lambda g_{ab}=8\pi G\,T_{ab}. \] Consequently, Einstein geometry is not a theorem of the bare finite consensus language.

Proof. The symbols of \(\mathsf{Cons}_r\) describe finite states, quotienting, mismatch, accepted repair, normal forms, and consistency. They do not include a metric, curvature tensor, stress tensor, cap modular automorphism, area operator, or entropy-area normalization. Hence two model extensions can share the same \(\mathsf{Cons}_r\) while assigning different geometry/stress data. One extension may attach Minkowski metric, \(T_{ab}=0\), and \(\Lambda=0\), so Einstein holds. Another may attach a Lorentzian metric \(g'_{ab}\) and stress tensor \(T'_{ab}\) for which \[ G'_{ab}+\Lambda' g'_{ab}\ne 8\pi G' T'_{ab} \] somewhere. All bare consensus statements have the same truth value in the two extensions, while the Einstein equation has different truth values. Therefore the Einstein equation is not entailed by the bare reduct. ◻

\[ \boxed{ \mathsf{Cons}_r\Rightarrow\text{quotient normal forms only.} } \] The gravity theorem used elsewhere in OPH has a separate typed dependency spine: \[ \boxed{ \begin{gathered} \mathsf{RecoveredCore}_{5\mathrm{ax}}+\mathsf{GeomRead} +\mathrm{BW}^{\mathrm{sv}}_{S^2} +\mathsf{NullStress}\\ +\mathsf{BoundedInterval} +\mathsf{FixedCapStat} +\mathsf{SmallBallArea}\\ +\mathsf{RemainderControl} +\mathsf{TimelikeCoverage}\\ +\mathsf{CommonSource} +\mathsf{PhysicalIDs}\\ +\mathsf{TensorUpgrade} \Rightarrow \mathsf{Einstein}. \end{gathered} } \] The implication requires one source-derived common-domain tower, certified asymptotic tails, universal coupling, a source-derived vacuum reference, and independent physical scale readouts. Construction and certification of such a tower are work in progress. That branch is carried by the compact SM/GR and microphysics papers, not by the bare constraint-code theorem above.

So \(\Phi\) is the total disagreement energy of the universe. Consistent states have zero energy. Everything else is frustrated.

Asynchronous Reconciliation and the Main Fixed-Point Theorem

Definition 7 (Recovery-derived local repair law). Fix for each patch \(i\) a finite collar chart \(A_i\!-\!B_i\!-\!D_i\) around the overlaps touched by \(i\), together with a fixed local decoder from repaired collar data back to the finite patch label at \(i\). A law \(\lambda\) is a family of local repair maps \[ T_i^\lambda:\Sigma\to\Sigma \qquad (i\in V) \] such that \(T_i^\lambda\) changes only the state of patch \(i\) (or, more generally, only a bounded neighborhood of \(i\)), and the local update is induced by one of the declared OPH recovery moves on that collar, where \(\omega_{A_iB_i}(s)\) denotes the \(A_i\cup B_i\) marginal of the input collar state encoded by \(s\):

  1. exact Markov splice on the collar, using Theorem 92 when \(I(A_i:D_i\mid B_i)=0\); or

  2. a declared recoverability channel \[ (\mathrm{id}_{A_i}\otimes \mathcal R_i)(\omega_{A_iB_i}(s)), \qquad \mathcal R_i=\mathcal R_{\sigma_i,\mathcal N_i}, \] with \(\mathcal R_i\) in the Petz/Fawzi–Renner class of Definition 105 and Theorem 92.

The decoder back to \(S_i\) is bookkeeping for the finite patch presentation; the physical content is the repaired collar state on the declared fixed-cutoff branch. Write \(s\rightsquigarrow_i t\) iff \(t=T_i^\lambda(s)\neq s\). These are primitive proposals awaiting acceptance as physical rewrite steps. A proposal is committed only through the transactional acceptance layer below.

Definition 8 (Touched-overlap potential and accepted local-fit contract). For each repair site \(i\), let \[ E_i^{\mathrm{touch}} := \bigl\{ e\in E:\text{the interface data on }e\text{ may change under }T_i^\lambda \bigr\}. \] Define the touched-overlap potential \[ \Phi_i(s) := \sum_{e=\{u,v\}\in E_i^{\mathrm{touch}}} w_e\, d_e\!\bigl(\pi_{u,e}(s_u),\pi_{v,e}(s_v)\bigr). \] On the declared fixed-cutoff branch, a recovery-derived primitive candidate is eligible for transactional commitment only if it strictly lowers this touched-overlap score: \[ s\rightsquigarrow_i t \implies \Phi_i(t)<\Phi_i(s). \] This is the patch-net form of the regulator-side monotone local-fit contract carried by the declared repair package.

Definition 9 (Overlap-associative union-collar gluing). Fix \(s\in\Sigma\) and two enabled primitive proposals \(s\rightsquigarrow_i t\), \(s\rightsquigarrow_j u\). Write \[ E_{ij}^{\mathrm{touch}} := E_i^{\mathrm{touch}}\cup E_j^{\mathrm{touch}}. \] The declared repair branch is overlap-associative if the following hold.

  1. If \(E_i^{\mathrm{touch}}\cap E_j^{\mathrm{touch}}=\varnothing\), the two local proposals have disjoint support on the declared branch and therefore commute if they are committed as separate transactions.

  2. If \(E_i^{\mathrm{touch}}\cap E_j^{\mathrm{touch}}\neq\varnothing\), there is a finite union collar \(U_{ij}\) covering the interfaces in \(E_{ij}^{\mathrm{touch}}\) such that the physical glued state on \(U_{ij}\) is parenthesization-independent on the quotient, in the sense of Proposition 100, and the local decoders/lifts of Definition 7 are restriction-compatible on nested collars.

This is the concrete compatibility package used below to build canonical aggregate payloads for conflicting repair components.

Definition 10 (Transactional acceptance layer). Let \(X\) denote the finite physical presentation on which a repair step is being checked: before quotienting one may take \(X=\Sigma\), and on the physical branch \(X\) is the quotient by hidden representatives. Registers are the finite patch, interface, sector, and record coordinates. Fix a boundary/sector/holonomy record map \[ B:X\to\mathcal B \] and a well-founded exact measure \[ \mu:X\to(W,\prec), \] for example a lexicographic integer vector \((N_{\mathrm{hard}},\Phi,N_{\mathrm{unresolved}})\).

A prepared transaction is a tuple \[ \tau=(R_\tau,W_\tau,\sigma_\tau,p_\tau) \] with read set, write set, read snapshot, and payload. It commits at \(x\in X\) only if all of the following hold:

  1. the snapshot is current: \(x|_{R_\tau}=\sigma_\tau\);

  2. the payload changes no register outside \(W_\tau\);

  3. boundary, sector, holonomy, and protected record data are preserved: \(B(\operatorname{Apply}_\tau(x))=B(x)\);

  4. exact descent holds: \[ \mu(\operatorname{Apply}_\tau(x))\prec \mu(x). \]

A stale, aborted, ambiguous, or obstructed transaction is not a rewrite step. The read set is semantic-dependency-complete as follows. Let \(\mathcal F\) contain every finite-support functional whose value enters acceptance: the supported terms of \(\mu\), the protected boundary/sector/holonomy functions, enablement predicates, semantic-history and event-parent functions, observer-registry updates, and checkpoint-continuation functions. For a write set \(W\), define \[ D_{\mathcal F}(W) := \bigcup_{\substack{f\in\mathcal F\\ \operatorname{supp}(f)\cap W\ne\varnothing}} \operatorname{supp}(f). \] Every prepared transaction satisfies \(R_\tau\supseteq D_{\mathcal F}(W_\tau)\); its enablement and payload are functions of the read snapshot, and every acceptance functional affected by its write is revalidated at commit. For seam potentials this reads both endpoints of every seam whose score can change. Protected-support completeness and protected-conflict completeness are the restrictions of this condition to protected functionals; they are not substitutes for the full semantic closure.

At a state \(x\), form the conflict graph of enabled primitive repair proposals, with \[ \tau\#\sigma \quad\Longleftrightarrow\quad W_\tau\cap(R_\sigma\cup W_\sigma)\ne\varnothing \ \text{or}\ W_\sigma\cap(R_\tau\cup W_\tau)\ne\varnothing . \] Each connected conflict component \(K\) is replaced by exactly one canonical aggregate transaction \(\tau_K\), computed on the union-collar or conflict-component support. Primitive members of \(K\) never commit separately. Write \(x\to y\) for a successful aggregate transaction commit, and let \(\to^*\) be its reflexive-transitive closure. A state is a normal form when no aggregate transaction is enabled.

The quotient repair operator

The transactional layer above defines the physically accepted one-step relation. The object used as law is the induced finite normal-form map on the physical quotient, not a hidden-representative rewrite.

Definition 11 (Finite quotient repair presentation). A finite quotient repair presentation is a tuple \[ \mathcal P=(\Sigma,\Gamma,q,Q,C_Q,B,\mu,\mathsf A,\prec_{\mathsf A}) \] where \[ Q=\Sigma/\Gamma,\qquad q:\Sigma\to Q \] is the physical quotient by hidden representative data, \(C_Q\subseteq Q\) is the quotient-level consistency set, \[ B:Q\to\mathcal B \] is the protected boundary, sector, root-packet, charge, or holonomy-sector map, and \[ \mu:Q\to(W,\prec) \] is a well-founded exact descent measure whose image on \(Q\) is finite. The finite set \(\mathsf A\) consists of accepted aggregate repair transactions, equipped with a fixed total order \(\prec_{\mathsf A}\). Each \(a\in\mathsf A\) has a domain \(D_a\subseteq Q\) and a map \[ a:D_a\to Q. \] The accepted one-step relation is \[ x\to_{\mathcal P} y \quad\Longleftrightarrow\quad \exists a\in\mathsf A,\ x\in D_a,\ y=a(x). \] The presentation is OPH-admissible when: \[ (H_B)\qquad x\to_{\mathcal P}y\implies B(y)=B(x), \] \[ (H_\downarrow)\qquad x\to_{\mathcal P}y\implies \mu(y)\prec\mu(x), \] \[ (H_\diamond)\qquad \to_{\mathcal P}\text{ is locally confluent on }Q, \] and \[ (H_{\mathrm{comp}})\qquad x\in C_Q \quad\Longleftrightarrow\quad \text{no accepted aggregate transaction is enabled at }x. \]

Definition 12 (Local quotient repair operator). For \(x\in Q\), let \[ \mathsf A(x):=\{\,a\in\mathsf A:x\in D_a\,\} \] be the enabled aggregate transaction set. Define \[ \operatorname{locRep}_\lambda(x):= \begin{cases} a_{\min}(x),& \mathsf A(x)\ne\varnothing,\\ x,& \mathsf A(x)=\varnothing, \end{cases} \] where \(a_{\min}\) is the \(\prec_{\mathsf A}\)-least enabled aggregate transaction.

Proposition 13 (Local quotient repair is total, protected, and descending). For every OPH-admissible finite quotient repair presentation, \[ \operatorname{locRep}_\lambda:Q\to Q \] is a total map. For every \(x\in Q\), \[ B(\operatorname{locRep}_\lambda(x))=B(x), \] and either \(\operatorname{locRep}_\lambda(x)=x\) or \[ \mu(\operatorname{locRep}_\lambda(x))\prec\mu(x). \] Finally, \[ \operatorname{locRep}_\lambda(x)=x \quad\Longleftrightarrow\quad x\in C_Q. \]

Proof. The set \(\mathsf A\) is finite and totally ordered, so a least enabled transaction exists whenever \(\mathsf A(x)\ne\varnothing\). If no transaction is enabled, the definition returns \(x\). Hence \(\operatorname{locRep}_\lambda\) is total.

If no transaction is enabled, boundary preservation is immediate. If \(a_{\min}\) is enabled, \((H_B)\) gives \(B(a_{\min}(x))=B(x)\). The descent statement is immediate from \((H_\downarrow)\). Since strict descent excludes \(a_{\min}(x)=x\), the local operator fixes exactly those states with no enabled aggregate transaction. By \((H_{\mathrm{comp}})\), these are exactly the elements of \(C_Q\). ◻

Definition 14 (Global quotient repair operator). For \(x\in Q\), define the canonical local-repair iterates by \[ x_0=x,\qquad x_{n+1}=\operatorname{locRep}_\lambda(x_n). \] By Proposition 13, the sequence either stops or strictly descends inside the finite value set \(\mu(Q)\). Hence there is a least \(N(x)\) such that \[ x_{N(x)+1}=x_{N(x)}. \] The global quotient repair operator is \[ \operatorname{Rep}_\lambda(x):=x_{N(x)}. \]

Theorem 15 (Global Repair is the finite quotient normal-form map). For every OPH-admissible finite quotient repair presentation, \[ \operatorname{Rep}_\lambda:Q\to Q \] is total and satisfies \[ \operatorname{Rep}_\lambda(x)\in C_Q,\qquad B(\operatorname{Rep}_\lambda(x))=B(x), \] \[ \operatorname{Rep}_\lambda(\operatorname{Rep}_\lambda(x)) \mathrel{=} \operatorname{Rep}_\lambda(x), \] and \[ \operatorname{Rep}_\lambda(x)=x \quad\Longleftrightarrow\quad x\in C_Q. \] If \(x\to_{\mathcal P}^{\!*}y\) and \(y\) is terminal, then \[ y=\operatorname{Rep}_\lambda(x). \] Thus \[ \operatorname{Rep}_\lambda=\overline{\operatorname{nf}}_\lambda:Q\to Q \] is independent of the accepted asynchronous repair schedule.

Proof. Totality follows from finite descent. If \(x_{n+1}\ne x_n\), then Proposition 13 gives \[ \mu(x_{n+1})\prec\mu(x_n). \] Since \(\mu(Q)\) is finite and well founded, no infinite strictly descending sequence exists. Thus the canonical iteration reaches a fixed point \(x_N\). By Proposition 13, \[ x_N=\operatorname{locRep}_\lambda(x_N) \quad\Longleftrightarrow\quad x_N\in C_Q, \] so \(\operatorname{Rep}_\lambda(x)\in C_Q\). Boundary preservation follows by induction from \((H_B)\), hence \(B(\operatorname{Rep}_\lambda(x))=B(x)\). Idempotence follows because every point of \(C_Q\) is fixed by Proposition 13.

For schedule independence, \((H_\downarrow)\) gives termination of \(\to_{\mathcal P}\), and \((H_\diamond)\) gives local confluence. Newman’s lemma gives confluence. A terminating confluent rewrite system has a unique terminal normal form reachable from each initial state. The canonical iteration defining \(\operatorname{Rep}_\lambda\) is one accepted repair execution, so it reaches that unique terminal normal form. Therefore every other maximal accepted repair execution from \(x\) reaches the same value. ◻

Closure item Paper object Result
physical one-step repair \(\operatorname{locRep}_\lambda:Q\to Q\) Proposition 13
physical global repair \(\operatorname{Rep}_\lambda=\overline{\operatorname{nf}}_\lambda\) Theorem 15
protected data boundary/sector map \(B\) preserved by accepted transactions Theorem 15
quotient normal form terminal point in \(C_Q\), idempotent and schedule-independent Theorem 15

Proposition 16 (Validation support for local mismatch measures). Suppose the exact repair measure has finite local supports, \[ \mu(x)=\sum_{a\in A}\mu_a(x|_{S_a}). \] If a transaction writes \(W\), then only terms with \(S_a\cap W\ne\varnothing\) can change. Consequently, the descent validation is snapshot-local once the read set contains \[ R^\mu(W):=\bigcup_{a:S_a\cap W\ne\varnothing}S_a . \] For the OPH overlap potential \[ \Phi(x)=\sum_{e=\{i,j\}}w_e\,d_e\!\bigl(\pi_{i,e}(x_i),\pi_{j,e}(x_j)\bigr), \] this means reading both endpoints of every overlap whose score may change when a written register changes.

Proof. If \(S_a\cap W=\varnothing\), the transaction leaves every register read by \(\mu_a\) unchanged, so that term cancels between the pre- and post-state. Every remaining term is determined by the payload together with the restriction to \(R^\mu(W)\). The displayed edge-potential formula has one two-endpoint support for each overlap term, giving the stated seam rule. ◻

Remark 17 (Inputs and branch conditions). The repair step is therefore not an abstract rewrite primitive. Its declared inputs are the fixed-cutoff collar chart, either exact Markov splice or a chosen Petz/Fawzi–Renner recovery channel, a local decoder/lift back to the finite patch presentation, and the touched-overlap local-fit contract of Definition 8, together with the support-local disjoint-commutation clause and the restriction-compatible union-collar package of Definition 9. The parenthesization-independent quotient-local glue used there is supplied by Proposition 100 from the fixed-cutoff center-sector / higher-gauge gluing package. The actual accepted step is the validated aggregate transaction of Definition 10. The theorem package takes repair completeness as an explicit branch condition. On the Petz branch, full CPTP action on all inputs also requires the support clause recorded in Proposition 107. On broader branches one must also prove that the declared union-collar compatibility is preserved under refinement or branch change.

The theorem package separates the imported repair-law data from the theorem-local inputs cleanly:

Assumption 18 (Repair completeness). For the accepted transactional relation \(\to\), \(s\in C\) if and only if no aggregate repair transaction is enabled at \(s\).

Normal forms are exactly the globally consistent states. The dynamics is neither too weak (missing some inconsistencies) nor too strong (repairing things that were fine).

Definition 19 (Verified rooted-tree packet-net domain). Fix a finite rooted tree \(T=(V,E,r)\). For each non-root vertex \(i\), write \(p(i)\) for its parent and write \(w_i>0\) for the weight of the edge \(\{p(i),i\}\). Let \(A\) be a finite packet alphabet with \(|A|\ge2\), and let \(K_i\) be a finite hidden-label set. The patch state space is \[ S_i=A\times K_i, \qquad s_i=(x_i,k_i). \] For every edge \(e=\{i,j\}\), the interface alphabet is \(I_e=A\), and both endpoint projections read the packet component: \[ \pi_{i,e}(x_i,k_i)=x_i, \qquad \pi_{j,e}(x_j,k_j)=x_j. \] Thus \(e\) is consistent exactly when \(x_i=x_j\). Choose the weights so that \[ w_i>\sum_{j:p(j)=i}w_j \qquad \text{for every non-root } i, \] with an empty sum equal to \(0\). Define \[ \Phi(s)=\sum_{\{p(i),i\}\in E}w_i\,\mathbf 1[x_i\ne x_{p(i)}]. \] The repair map at a non-root vertex \(i\) is \[ T_i(s)_i=(x_{p(i)},k_i), \] with all other vertices unchanged; if \(x_i=x_{p(i)}\), the map is a no-op. The root repair map is the identity. The hidden labels \(k_i\) are acted on by arbitrary finite gauge relabelings and are not read by any interface projection.

Theorem 20 (Rooted-tree packet repair completeness and quotient closure). On the domain of Definition 19, Assumption 18 is a theorem. Every enabled repair strictly decreases \(\Phi\). Every maximal asynchronous repair run terminates at the unique state \[ x_i=x_r\quad\text{for all }i\in V, \] with all hidden labels \(k_i\) unchanged. The normal-form map descends to the quotient by hidden gauge relabeling. If several tree repairs lie in one conflict component, the canonical aggregate transaction applies them in increasing tree depth and is the same as the corresponding serial tree repair path. The four-vertex instance with edges \(r\!-\!a\), \(a\!-\!b\), \(a\!-\!c\), alphabet \(A=\mathbb Z_3\), hidden labels \(K_i=\mathbb Z_2\), and weights \(5,1,1\) is exported as a verified domain record with the released consensus code.

Proof. First, repair completeness is immediate from the rooted tree. If \(s\in C\), every edge has \(x_i=x_{p(i)}\), so every non-root repair is a no-op. Conversely, if every repair is a no-op, then \(x_i=x_{p(i)}\) for every non-root vertex, hence every edge is consistent and \(s\in C\).

Let \(i\ne r\) be enabled. Only the parent edge \(\{p(i),i\}\) and child edges \(\{i,j\}\) with \(p(j)=i\) can change their contribution to \(\Phi\). The parent edge changes from inconsistent to consistent, contributing \(-w_i\). Each child edge can increase by at most its weight. Therefore \[ \Phi(T_i(s))-\Phi(s) \le -w_i+\sum_{j:p(j)=i}w_j <0. \] So every enabled repair is accepted by the Lyapunov contract.

Since \(\Phi\) takes finitely many values, every maximal repair run terminates. At a terminal state no non-root vertex differs from its parent, so the terminal packet label is \(x_r\) on every vertex. The root label and every hidden label are invariant under all repairs, so the terminal state is unique and independent of update order. Because interface projections, enabledness, \(\Phi\), and the repair maps depend only on \(x_i\), arbitrary relabelings of the hidden \(K_i\) commute with quotienting: \[ q\circ T_i=\overline T_i\circ q. \] Thus the normal-form map descends to the hidden-label quotient. ◻

Corollary 21 (Physical-law map on the verified packet domain). On the rooted-tree packet domain, every gauge-invariant observable \[ M:\prod_i(A\times K_i)\to Y \] has a schedule-independent repaired value \[ M(\operatorname{nf}(s)), \] and this value depends only on the quotient class of \(s\). Hence the promoted normal-form map is usable as physical law on this verified packet branch without adding a representative-level gauge-covariance assumption.

Proof. Theorem 20 gives a unique terminal state for every asynchronous repair schedule and shows that the normal-form map descends to the quotient by hidden-label relabeling. A gauge-invariant observable factors through that quotient, so its value on the terminal state is independent of both the repair schedule and the hidden representative. ◻

Proposition 22 (Classical full-support Petz packet domain). Let \(B\) and \(D\) be finite packet alphabets, let the collar algebras be diagonal, and let \(\mathcal N:\mathbb C^{B\times D}\to\mathbb C^B\) be the marginal channel \((\mathcal N p)(b)=\sum_d p(b,d)\). Fix a reference state \(\sigma_{BD}\) with \(\sigma_B(b)>0\) for every \(b\). Let \[ \gamma_\sigma:=\min_{b\in B}\sigma_B(b)>0. \] Define the Petz recovery channel \[ \mathcal R_{\sigma,\mathcal N}(\mu)(b,d) \mathrel{=} \mu(b)\,\sigma(d\mid b), \qquad \sigma(d\mid b):=\frac{\sigma_{BD}(b,d)}{\sigma_B(b)}. \] Then \(\mathcal R_{\sigma,\mathcal N}\) is stochastic, completely positive and trace preserving on the diagonal algebra, and \(\ell^1\)-contractive: \[ \|\mathcal R_{\sigma,\mathcal N}(\mu)-\mathcal R_{\sigma,\mathcal N}(\nu)\|_1 \le \|\mu-\nu\|_1. \] The support inverse is uniformly bounded on this domain by \[ \|\sigma_B^{-1/2}\|\le \gamma_\sigma^{-1/2}. \] If a collar state has the exact classical Markov form \[ \omega_{ABD}(a,b,d)=\omega_{AB}(a,b)\sigma(d\mid b), \] then \((\mathrm{id}_A\otimes\mathcal R_{\sigma,\mathcal N})(\omega_{AB})=\omega_{ABD}\). The support obstruction is exact: if \(\sigma_B(b)=0\) and an input assigns mass to \(b\), the Petz inverse on that sector is undefined unless the channel domain is restricted or a separate trace-preserving completion is declared.

Proof. The displayed formula is the finite diagonal specialization of the Petz map \[ \sigma_{BD}^{1/2} \left(\sigma_B^{-1/2}\mu\,\sigma_B^{-1/2}\otimes \mathbf 1_D\right) \sigma_{BD}^{1/2}. \] Full support of \(\sigma_B\) makes the inverse well defined, with support gap \(\gamma_\sigma>0\), hence \(\|\sigma_B^{-1/2}\|\le\gamma_\sigma^{-1/2}\). Nonnegativity is immediate, and \[ \sum_{b,d}\mathcal R_{\sigma,\mathcal N}(\mu)(b,d) \mathrel{=} \sum_b \mu(b)\sum_d\sigma(d\mid b) \mathrel{=} \sum_b\mu(b), \] so the map is trace preserving. Diagonal positive trace-preserving maps are completely positive on the diagonal algebra. For signed diagonal inputs, \[ \|\mathcal R_{\sigma,\mathcal N}(\mu)-\mathcal R_{\sigma,\mathcal N}(\nu)\|_1 \mathrel{=} \sum_{b,d}|\mu(b)-\nu(b)|\,\sigma(d\mid b) \mathrel{=} \sum_b|\mu(b)-\nu(b)|, \] which gives the stated contraction. The exact Markov recovery identity follows by substitution. If \(\sigma_B(b)=0\), the factor \(\sigma_B^{-1/2}\) has no value on that sector; mass placed there by an input is outside the Petz support domain. That is the claimed obstruction. ◻

Proposition 23 (Accepted repair moves are decreasing). For the accepted transactional repair law of Definitions 710, every enabled repair strictly decreases the declared exact measure: \[ s\to t \implies \mu(t)\prec\mu(s). \] On the scalar \(\Phi\)-branch, this specializes to \(\Phi(t)<\Phi(s)\).

Proof. This is part of the commit validation in Definition 10. For a single-site scalar-\(\Phi\) transaction it reduces to the touched-overlap contract of Definition 8; for an aggregate conflict component it is checked on the aggregate payload before the component can commit. ◻

Proposition 24 (Termination from the OPH Lyapunov functional). Under Proposition 23, every repair sequence is finite; equivalently, the repair relation \(\to\) is terminating.

Proof. Along any nontrivial repair step \(s\to t\), Proposition 23 gives \(\mu(t)\prec\mu(s)\). The measure order is well founded, so an infinite strictly descending chain is impossible. On the scalar-\(\Phi\) branch this is the finite-value argument on \(\Phi(\Sigma)\). ◻

Proposition 25 (Finite repair step bound). Let \(s_0\in\Sigma\). Under Proposition 23, every accepted repair run starting at \(s_0\) has length at most the number of distinct \(\mu\)-values reachable below \(\mu(s_0)\) minus one. On the scalar-\(\Phi\) branch this gives \[ \bigl|\{\,\Phi(s):s\in\Sigma,\ \Phi(s)\le \Phi(s_0)\,\}\bigr|-1 \le |\Phi(\Sigma)|-1. \] If, additionally, \(\Phi\) is integer-valued, or more generally every accepted move lowers \(\Phi\) by at least a fixed \(\eta>0\), then the run length satisfies \[ T(s_0)\le \left\lceil\frac{\Phi(s_0)}{\eta}\right\rceil . \] This is a finite descent bound in repair steps only. It is not a wall-clock bound, not a probability-one scheduling statement, and not spectral or exponential convergence.

Proof. The values of \(\mu\) strictly decrease along the run, so no \(\mu\)-value can occur twice. This gives the finite reachable-value bound. On the scalar-\(\Phi\) branch, the values of \(\Phi\) strictly decrease along the run, so no value in \(\{\,\Phi(s):s\in\Sigma,\ \Phi(s)\le \Phi(s_0)\,\}\) can occur twice. This gives the finite value-set bound. If each move lowers \(\Phi\) by at least \(\eta\), after \(T\) moves the value has dropped by at least \(T\eta\). Since \(\Phi\ge0\), \(T\eta\le\Phi(s_0)\), giving the displayed ceiling bound. ◻

Remark 26 (Termination is not confluence). Proposition 24 proves only that accepted repair runs stop. It does not prove that two update orders stop at the same physical state. Schedule-independence enters only after the local-diamond property of Proposition 27 is combined with termination via Newman’s lemma and with repair completeness in Assumption 18. If two accepted repair schedules from the same initial state reach different observer-facing quotient normal forms, with no declared holonomy or higher-gauge obstruction and no mere gauge-representative difference, then the proposed repair law is not OPH-admissible as a consensus mechanism.

Proposition 27 (Semantic-complete transactional local diamond). For the accepted repair law of Definitions 710, assume semantic-dependency-complete read sets and revalidation, payload determination from the read snapshot, and a coherent canonical aggregate union-collar payload from Proposition 100. Then every one-step quotient peak \[ t\longleftarrow s\longrightarrow u \] admits a quotient state \(v\) with \(t\to v\leftarrow u\). Hence the transactional repair relation is locally confluent. The finite implementation receipt \(\mathsf{TXN\text{-}DIAMOND\text{-}1}\) exports the functional supports, dependency closures, read/write sets, conflict components, aggregate payload hashes, and pre/post protected, semantic-parent, checkpoint, and descent values needed to check that the concrete engine realizes these premises.

Proof. A one-step peak cannot choose two different payloads from one conflict component because that component has one canonical aggregate transaction. Its two steps therefore come from distinct components, say \(\tau\) and \(\sigma\). By the conflict definition, \[ W_\tau\cap(R_\sigma\cup W_\sigma)=\varnothing, \qquad W_\sigma\cap(R_\tau\cup W_\tau)=\varnothing. \] The writes are disjoint and neither changes the other’s read snapshot. If an acceptance functional can change under \(\tau\), semantic dependency closure puts its support in \(R_\tau\); hence \(\sigma\) leaves that functional’s input unchanged. Thus \(\tau\)’s enablement, descent comparison, protected-data check, semantic parents, checkpoint continuation, and payload remain valid after \(\sigma\), and conversely. Both second commits are legal. Since their writes are disjoint and their payloads are determined by unchanged snapshots, \[ \operatorname{Apply}_\sigma\operatorname{Apply}_\tau(s) =\operatorname{Apply}_\tau\operatorname{Apply}_\sigma(s)=v. \] This is the local diamond on the physical quotient. ◻

Remark 28 (Atomic commits do not prove the local diamond). Let \(Q=\{0,1\}^2\), \(s=(0,0)\), and protect \(B(x_1,x_2)=x_1x_2\). The transactions \[ \tau_1:(0,x_2)\mapsto(1,x_2), \qquad \tau_2:(x_1,0)\mapsto(x_1,1) \] have disjoint write sets and each preserves \(B\) at \(s\). Both lower \(\mu(x_1,x_2)=2-x_1-x_2\). Their peak has endpoints \((1,0)\) and \((0,1)\), while either second write would reach \((1,1)\) and change \(B\). Neither continuation is admissible. The missing dependency is the nonlinear protected observable shared by the two writes. Protected-support and conflict completeness expose that dependency; an implementation must check the resulting quotient peak.

Theorem 29 (Asynchronous confluence / fixed-point law). For the accepted repair law of Definitions 710, under Proposition 27 and Assumption 18, each fixed initial state \(s\in\Sigma\) has a unique normal form \[ \operatorname{nf}_\lambda(s)\in C, \] and every maximal asynchronous repair execution from \(s\) terminates at that same state. The terminal state is independent of update order because descent, local confluence on the physical quotient, and repair completeness all hold; termination alone is not enough.

Proof. By Proposition 24, the repair relation \(\to\) is terminating. By Proposition 27, it is locally confluent. Newman’s lemma  therefore makes it confluent. A terminating confluent repair relation has a unique normal form reachable from each fixed initial state. By Assumption 18, the normal forms are exactly \(C\). Every maximal execution terminates and reaches \(\operatorname{nf}_\lambda(s)\), and that terminal state is independent of update order. ◻

Corollary 30 (Objective law is schedule-independent). Let \(M:\Sigma\to Y\) be any observable. Under the hypotheses of Theorem 29, \(M(\operatorname{nf}_\lambda(s))\) is independent of the asynchronous update schedule. If physical law is identified with the map \(s\mapsto M(\operatorname{nf}_\lambda(s))\), then physical law is objective.

Proof. All schedules from the same initial \(s\) terminate at \(\operatorname{nf}_\lambda(s)\), so all yield the same \(M\)-value. ◻

Here objectivity is identified with schedule-independent convergence of the repair dynamics; Theorem 52 sharpens this to schedule-independent convergence of the physical observable algebra even when microscopic representatives are not unique.

Remark 31 (Quantifier on normal-form uniqueness). Theorem 29 proves uniqueness from a fixed initial state, and Theorem 37 below turns that into uniqueness from a fixed physical quotient state. It does not say that all possible initial data settle to one universal state. Different boundary conditions, conserved charges, root packets, holonomy sectors, or external records can legitimately determine different normal forms.

The quotient normal-form theorems of this section state that the public world is the quotient normal form that survives agreement on overlaps. Two failure shapes would break the claim: an OPH-admissible overlap presentation on which no quotient normal form exists under the declared descent, local-diamond, and repair-completeness conditions, or two inequivalent quotient normal forms surviving from the same declared boundary data where the fiber-uniqueness hypothesis of Theorem 39 holds. Either exhibit defeats the claim on its declared branch.

Why Local Agreement Is Not Enough: Cycle Holonomy and Frustration

Pairwise neighbor agreement does not by itself imply global consistency.

Theorem 32 (Cycle-obstruction / holonomy criterion). Let \(A\) be an abelian group, and let \(G=(V,E)\) be a connected graph with an arbitrary orientation on each edge. For each oriented edge \(e:u\to v\), assign a label \(b_e\in A\). Consider the affine consistency equations \[ x_v - x_u = b_e \qquad \text{for every oriented edge } e:u\to v, \] where \(x_v\in A\) are unknown patch labels. A global solution \(x:V\to A\) exists if and only if for every cycle \(C\subseteq G\), \[ \sum_{e\in C}\varepsilon_C(e)\, b_e = 0, \] where \(\varepsilon_C(e)=+1\) if the cycle traverses \(e\) in the chosen orientation and \(-1\) otherwise.

Proof. Necessity. Suppose \(x\) is a solution. Summing the edge equations around any cycle \(C\), \[ \sum_{e:u\to v\in C}\varepsilon_C(e)\,(x_v-x_u) \mathrel{=} \sum_{e\in C}\varepsilon_C(e)\,b_e. \] The left side telescopes to \(0\) because every vertex appears once with \(+\) sign and once with \(-\) sign.

Sufficiency. Fix a root \(r\in V\). For any vertex \(v\), choose a path \(P_{r\to v}\) and define \[ x_v := \sum_{e\in P_{r\to v}} \varepsilon_{P_{r\to v}}(e)\, b_e, \qquad x_r:=0. \] If \(P\) and \(P'\) are two paths from \(r\) to \(v\), traversing \(P\) followed by the reverse of \(P'\) yields a cycle. By the vanishing-holonomy assumption, the total signed sum is zero, so \(x_v\) is well-defined. For any edge \(e:u\to v\), extending a path to \(u\) by that edge gives \(x_v = x_u + b_e\). ◻

Corollary 33 (Parity triangle: pairwise consistency is not enough). Take \(A=\mathbb{Z}_2\) on the triangle \(A\)-\(B\)-\(C\)-\(A\) with edge labels \(b_{AB}=0\), \(b_{BC}=0\), \(b_{CA}=1\). Each individual edge equation is satisfiable. But the global system is not: the cycle sum is \(0\oplus 0\oplus 1 = 1\neq 0\).

This example shows that pairwise consistency does not imply a global solution. The obstruction is carried by the cycle.

Corollary 34 (Stable defects as frustrated holonomy). Define the defect energy \[ \Phi_b(x) := \sum_{e:u\to v\in E} w_e\,\mathbf{1}\!\left[x_v - x_u \neq b_e\right]. \] If the cycle-holonomy condition fails, then \(\min_{x:V\to A}\Phi_b(x)>0\). Every minimizer contains irreducible residual inconsistency.

Proof. If \(\min_x\Phi_b(x)=0\), some assignment satisfies all edge equations, contradicting Theorem 32. ◻

Residual inconsistencies of this type cannot be removed by local repair moves. In the OPH interpretation they are stable topological defects of the reconciliation dynamics.

Theorem 35 (Higher-gauge defect hierarchy). Let a finite overlap nerve carry crossed-module defect data \((g_{ij},h_{ijk})\) for a compact crossed module \[ H\xrightarrow{\partial} G. \] Under local rechartings by \[ C^1(N,H)\rtimes C^0(N,G), \] the nonabelian Čech class \[ q=[(g,h)]\in \check H^2(N,H\to G) \] is invariant and classifies the full crossed-module orbit. Its neutral element is equivalent to full gauge trivialization of both levels. The higher associator alone is removable precisely when \(q\) lies in the image of the natural strict-locus map \[ \check H^1(N,G)\longrightarrow\check H^2(N,H\to G),\qquad[g]\longmapsto[(g,1)]. \] After such a strictification, endpoint-only ordinary reconciliation additionally requires an allowed strict representative with trivial represented loop holonomy. The strict-locus map need not be injective, so \(q\) need not determine one ordinary \(H^1\) class.

Proof. The allowed rechartings are exactly the crossed-module coboundaries, so they preserve the full orbit. The neutral orbit admits the completely trivial representative. More generally, the higher associator is removed when the orbit meets the strict locus \((g,1)\); different points of that locus can be related by \(H\)-valued edge changes. Ordinary loop coherence is therefore the separate existential holonomy test stated above. ◻

Gauge Symmetry as Implementation Hiding

Definition 36 (Gauge action). Let \(\Gamma = \prod_{i\in V}\Gamma_i\) act on \(\Sigma\) componentwise. The action is a gauge action if for every \(e=\{i,j\}\in E\), \[ \pi_{i,e}(\gamma_i\cdot x)=\pi_{i,e}(x) \qquad \forall\, x\in S_i,\ \forall\, \gamma_i\in \Gamma_i. \] Gauge changes alter hidden local representations but do not alter overlap data.

Gauge transformations change hidden local representations while leaving overlap data fixed. Write \[ q:\Sigma\to \Sigma/\Gamma, \qquad q(s)=[s], \] for the gauge-orbit map. A physical repair law is the family of quotient-local maps \[ \overline T_i^\lambda:\Sigma/\Gamma\to \Sigma/\Gamma \] induced by the recovery-derived collar updates of Definition 7. A representative repair family is any choice of lifts \[ T_i^\lambda:\Sigma\to\Sigma \] such that \[ q\circ T_i^\lambda \mathrel{=} \overline T_i^\lambda\circ q. \] This is the finite patch-net form of saying that the repair step is defined first on overlap-invariant physical data and only then lifted to hidden representatives. The rooted-tree packet domain of Theorem 20 proves repair completeness and quotient descent on a nontrivial exported packet net, while Proposition 22 proves the classical full-support Petz clause used by that domain. A broader fixed-cutoff branch requires repair completeness for the chosen exported packet net and the support/CPTP clause on the Petz branch where that channel is used. The touched-overlap local-fit contract gives scalar \(\Phi\)-descent for primitive proposals on the corresponding branch, while the transaction layer supplies exact accepted-step descent. Proposition 100 together with Definition 9 supplies the quotient-local compatibility package used to build canonical aggregate payloads. Proposition 27 derives the local diamond from semantic-dependency-complete read sets, canonical conflict components, snapshot-determined payloads, and revalidation. The implementation receipt checks those premises and the concrete finite peaks. Stability under refinement or branch change is a separate question. The point here is also that no extra gauge-covariance axiom is needed once repair is formulated on the quotient.

Theorem 37 (Gauge quotient theorem). Under the gauge action of Definition 36, any representative lift of a physical repair law as just defined, and the hypotheses of Theorem 29, \[ q\bigl(\operatorname{nf}_\lambda(\gamma\cdot s)\bigr) \mathrel{=} q\bigl(\operatorname{nf}_\lambda(s)\bigr) \qquad \forall\, \gamma\in\Gamma,\ \forall\, s\in\Sigma. \] Hence the normal-form map descends to the quotient: \[ \overline{\operatorname{nf}}_\lambda:\Sigma/\Gamma \to \Sigma/\Gamma, \qquad [s]\mapsto [\operatorname{nf}_\lambda(s)]. \]

Proof. Let \(s\to t\) be an accepted aggregate transaction, and let \(\overline\tau\) be its quotient payload. If \(s'=\gamma\cdot s\), the representative-lift hypothesis gives an accepted lift \(s'\to t'\) of the same quotient transaction, and \[ q(t') \mathrel{=} \overline\tau\bigl(q(s')\bigr) \mathrel{=} \overline\tau\bigl(q(s)\bigr) \mathrel{=} q(t). \] Thus gauge-equivalent inputs induce the same repaired orbit, and by induction the orbit reached after any repair sequence depends only on the initial orbit. Every maximal repair sequence from \(s\) ends at \(\operatorname{nf}_\lambda(s)\) by Theorem 29, so the terminal orbit \(q(\operatorname{nf}_\lambda(s))\) depends only on \(q(s)=[s]\). This makes \[ [s]\longmapsto [\operatorname{nf}_\lambda(s)] \] well-defined on \(\Sigma/\Gamma\). ◻

Corollary 38 (Repair respects gauge). Let \(Q=\Sigma/\Gamma\), let \(q:\Sigma\to Q\) be the quotient map, and let \[ \operatorname{Rep}^{\Sigma}_\lambda := \operatorname{Rep}_\lambda\circ q : \Sigma\to Q \] be the quotient-valued physical repair of a representative. Then for every \(\gamma\in\Gamma\) and \(s\in\Sigma\), \[ \operatorname{Rep}^{\Sigma}_\lambda(\gamma\cdot s) \mathrel{=} \operatorname{Rep}^{\Sigma}_\lambda(s). \] Equivalently, \[ \operatorname{Rep}_\lambda(q(\gamma\cdot s)) \mathrel{=} \operatorname{Rep}_\lambda(q(s)). \] If \(M:Q\to Y\) is any physical observable, then \[ M(\operatorname{Rep}^{\Sigma}_\lambda(\gamma\cdot s)) \mathrel{=} M(\operatorname{Rep}^{\Sigma}_\lambda(s)). \]

Proof. Since \(q\) is the quotient map, \(q(\gamma\cdot s)=q(s)\). Therefore \[ \operatorname{Rep}^{\Sigma}_\lambda(\gamma\cdot s) \mathrel{=} \operatorname{Rep}_\lambda(q(\gamma\cdot s)) \mathrel{=} \operatorname{Rep}_\lambda(q(s)) \mathrel{=} \operatorname{Rep}^{\Sigma}_\lambda(s). \] Applying \(M\) gives the observable statement. ◻

Theorem 39 (Boundary-conditioned quotient uniqueness). Let \[ B:\Sigma/\Gamma\to\mathcal B \] record fixed external boundary data, conserved charge, root packet, holonomy sector, or task input. Assume accepted quotient repairs preserve \(B\): \[ [s]\to [t]\implies B([s])=B([t]). \] For \(b\in\mathcal B\), define the consistent quotient fiber \[ C_b:=\{\,x\in q(C):B(x)=b\,\}. \] If every \(C_b\) has at most one element, then all initial states with the same boundary value settle to the same observer-facing quotient normal form: \[ B([s])=B([s'])\implies \overline{\operatorname{nf}}_\lambda([s]) \mathrel{=} \overline{\operatorname{nf}}_\lambda([s']). \]

Proof. Theorem 37 gives unique quotient normal forms \(\overline{\operatorname{nf}}_\lambda([s])\) and \(\overline{\operatorname{nf}}_\lambda([s'])\) in \(q(C)\). Boundary preservation along accepted repair sequences gives \[ B(\overline{\operatorname{nf}}_\lambda([s]))=B([s]), \qquad B(\overline{\operatorname{nf}}_\lambda([s']))=B([s']). \] If \(B([s])=B([s'])=b\), both quotient normal forms lie in \(C_b\). By the unique consistent extension assumption, \(C_b\) has at most one element, so the quotient normal forms are equal. ◻

Remark 40 (Same-source and cross-source quantifiers). Theorem 29 compares repair schedules from one fixed initial source. The stronger comparison of endpoints reached from different sources with the same protected boundary is controlled by the consistent boundary fibers. Under boundary preservation and \(\operatorname{NF}=q(C)\), Ref.  proves that cross-source endpoint agreement, modulo any declared silent equivalence, is equivalent to injectivity of the induced boundary map on the consistent quotient. Weak normalization and all-schedule liveness are separate obligations. The layered and functional carriers below establish the injectivity premise on their declared domains. On the verified rooted-tree packet-net domain of Definition 19, the declared boundary map is the root-packet readback, and its injectivity modulo hidden-label gauge on the consistent set is established class-wide, together with the resulting cross-source endpoint form for the tree repair. Same-source confluence alone does not establish the injectivity premise for an arbitrary physical boundary map, and outside the declared domains it remains a named per-net hypothesis with explicit failure witnesses.

A multi-edge finite carrier for boundary reconstruction

Definition 41 (Layered functional boundary carrier). A layered functional boundary carrier is a finite directed layered graph \[ G=(V,E),\qquad V=L_0\sqcup L_1\sqcup\cdots\sqcup L_D, \] with \(D\ge2\). The boundary layer is \(L_0\). For each \(v\in L_d\), \(d\ge1\), choose a nonempty parent set \[ P(v)\subseteq L_0\sqcup\cdots\sqcup L_{d-1} \] and a finite alphabet \(A_v\). Each interior vertex has a deterministic local rule \[ F_v:\prod_{u\in P(v)}A_u\to A_v. \] The carrier is genuinely multi-edge when at least two dependency edges occur and at least one layer contains more than one dependency or more than one repaired vertex.

The quotient state space is \[ Q=\prod_{v\in V}A_v, \] and the boundary map is \[ B:Q\to\prod_{v\in L_0}A_v,\qquad B(a)=a|_{L_0}. \] Given boundary data \(b\in\prod_{v\in L_0}A_v\), define its functional extension \(E(b)\in Q\) recursively by \[ E(b)_v=b_v\quad(v\in L_0), \] and, for \(v\in L_d\), \(d\ge1\), \[ E(b)_v=F_v\bigl((E(b)_u)_{u\in P(v)}\bigr). \] Optional cross-check edges may be included by choosing finite predicates \[ \chi_e(a_u,a_v)=0. \] A state \(a\in Q\) is consistent when every interior functional equation \[ a_v=F_v\bigl((a_u)_{u\in P(v)}\bigr) \] holds and all cross-check predicates pass. Let \(C_Q\) be the set of consistent states. A boundary \(b\) is admissible when \(E(b)\in C_Q\); equivalently, \[ C_Q=\{\,E(b):b\text{ admissible}\,\}. \] For each layer \(d=1,\ldots,D\), define a layer repair map \(R_d:Q\to Q\) by \[ (R_d(a))_v= \begin{cases} F_v((a_u)_{u\in P(v)}),& v\in L_d,\\ a_v,& v\notin L_d. \end{cases} \] The full staged repair sweep is \[ R_{\mathrm{sweep}}=R_D\circ R_{D-1}\circ\cdots\circ R_1. \] Gauge representatives may be added by replacing \(A_v\) with \(A_v\times H_v\), letting \(\Gamma_v\) act only on \(H_v\), and defining all boundary and consistency maps through the \(A_v\)-coordinate. The quotient is then the \(Q\) above.

Theorem 42 (Layered carrier proves \(H_B\wedge H_{\mathrm{fib}}\)). Let \(G\) be a layered functional boundary carrier. For every initial quotient state \(a\in Q\), set \[ a^{(0)}=a,\qquad a^{(d)}=R_d(a^{(d-1)}),\quad d=1,\ldots,D. \] Let \(b=B(a)\). Then \[ B(a^{(d)})=b \qquad \text{for all }d=0,\ldots,D. \] If \(b\) is admissible, then \[ a^{(D)}=E(b)\in C_Q. \] The consistent boundary fiber is a singleton: \[ C_Q\cap B^{-1}(b)=\{E(b)\}. \] Thus preserved boundary data plus consistency reconstruct the observer-facing quotient bulk on this carrier.

Proof. Boundary preservation is immediate because each \(R_d\) writes only layer \(L_d\), with \(d\ge1\). No \(R_d\) writes \(L_0\), so \(B(a^{(d)})=B(a)=b\) for every stage.

We prove by induction on \(d\) that after stage \(d\), \[ a^{(d)}_v=E(b)_v \qquad \text{for every }v\in L_0\sqcup\cdots\sqcup L_d. \] For \(d=0\), this is the definition of \(b\). Assume the claim holds through layer \(d-1\), and let \(v\in L_d\). Every parent \(u\in P(v)\) lies in an earlier layer, so \(a^{(d-1)}_u=E(b)_u\). The layer repair therefore gives \[ a^{(d)}_v \mathrel{=} F_v\bigl((a^{(d-1)}_u)_{u\in P(v)}\bigr) \mathrel{=} F_v\bigl((E(b)_u)_{u\in P(v)}\bigr) \mathrel{=} E(b)_v. \] Earlier layers are not modified by \(R_d\), so the induction closes. At \(d=D\), all layers agree with \(E(b)\). If \(b\) is admissible, \(E(b)\in C_Q\).

For boundary-fiber uniqueness, let \(c\in C_Q\cap B^{-1}(b)\). Since \(c\) has boundary \(b\), it agrees with \(E(b)\) on \(L_0\). Since \(c\in C_Q\), every interior vertex satisfies \[ c_v=F_v((c_u)_{u\in P(v)}). \] The same induction on layers gives \(c_v=E(b)_v\) for every vertex. Hence \(c=E(b)\). ◻

Corollary 43 (Boundary reconstruction by global Repair). Assume the layered carrier’s layer updates are included among the accepted aggregate transactions of an OPH-admissible finite quotient repair presentation, and let \(b=B(x)\) be admissible. Then \[ \operatorname{Rep}_\lambda(x)=E(b). \] Consequently, for every physical readout \[ \operatorname{Read}:Q\to\mathcal Y \] that factors through the quotient normal form, \[ \operatorname{Read}(\operatorname{Rep}_\lambda(x)) \mathrel{=} \operatorname{Read}(E(B(x))). \]

Proof. By Theorem 15, \[ \operatorname{Rep}_\lambda(x)\in C_Q \qquad\text{and}\qquad B(\operatorname{Rep}_\lambda(x))=B(x)=b. \] Therefore \(\operatorname{Rep}_\lambda(x)\in C_Q\cap B^{-1}(b)\). Theorem 42 identifies this fiber with \(\{E(b)\}\), so \(\operatorname{Rep}_\lambda(x)=E(b)\). Applying \(\operatorname{Read}\) gives the readout statement. ◻

Finite binary audit fixture: a sharp reconstruction carrier

The layered carrier above proves boundary reconstruction for a feed-forward finite class. A useful stress test for the same logic is a two-neighbor linear binary update on a finite cylinder. A row is a function \[ x_t:\mathbb Z_n\to\mathbb F_2, \] and the update rule is \[ x_{t+1}(j)=x_t(j-1)+x_t(j+1)\pmod 2. \] This update is not a proposed microscopic physics law. It is a minimal finite-consensus fixture: the local rule is linear, all records are exact finite objects, and boundary reconstruction can be tested without continuum or geometric assumptions.

For the time slab \(0,\ldots,t\), a two-column timelike tube \[ \{j_0,j_0+g\}\times\{0,\ldots,t\} \] is an information set when its values determine the whole finite spacetime record. The sharp two-column classification: \[ \text{tube}(g)\text{ is an information set} \quad\Longleftrightarrow\quad \gcd(g,n)=1\ \text{ and }\ n\le 2(t+1). \] Thus adjacent columns (\(g=1\)) achieve the full capacity threshold, while a non-coprime stride loses information at every horizon. The same fixture also separates realizable from unrealizable boundary readings: if a tube reading is not carried by any consistent record, no boundary-preserving repair operator can make it consistent without changing the boundary.

The audit then assembles a Route-A repair on this same carrier. The positive operator is a local transactional decoder: each transaction writes one non-tube cell using a bounded edge-local window, the declared rank schedule terminates in one finite pass, and the tube reading is preserved at every accepted step. At the sharp threshold \(n\le2(t+1)\), any two records with the same tube reading settle to the same normal form; the settled world is consistent exactly when the tube fiber is realizable.

The same formal fixture supplies the important negative controls. On this binary cylinder there is no single-patch frustration-free local repair satisfying the strongest \(H_1\wedge H_2\wedge H_3\) binder form. The canonical single-patch repair can also stall on the smallest audit witness \((n,t)=(3,2)\), leaving a broken edge in normal form. This is not a failure of the positive decoder; the stalled record has an unrealizable tube fiber. The lesson for OPH is structural: boundary reconstruction is theorem-grade only after the preserved boundary, realizable-fiber condition, and declared repair roster are specified. A bare local-update slogan is too weak.

Theorem 44 (Functional selected-fiber uniqueness). Let \(Q_b:=B^{-1}(b)\subseteq\Sigma/\Gamma\) be a same-boundary quotient fiber presented on a rooted finite overlap graph with spanning tree \(T\), root \(r\), and patch state sets \(X_v\). Assume the boundary value fixes the root value \[ u_r=\beta(b), \] and every non-root vertex has a deterministic extension map \[ f_v:X_{p(v)}\times\mathcal B\to X_v . \] Define \(u_b\) recursively by \[ u_v=f_v(u_{p(v)},b). \] Evaluate all non-tree overlap equations, sector constraints, and holonomy checks on this candidate. If they all pass, then \(C_b=\{u_b\}\). If any check fails, then \(C_b=\varnothing\).

Proof. Every consistent state in \(Q_b\) must have root value \(\beta(b)\). Along each tree edge, the deterministic extension equation forces the child value to be \(f_v(u_{p(v)},b)\). Induction over tree depth therefore forces every consistent state in the fiber to equal the single recursively constructed candidate \(u_b\). The remaining constraints are exactly the non-tree overlaps, sector equations, and holonomy checks. If they pass, \(u_b\) is a consistent state and no other state can be. If one fails, the only tree-compatible candidate is inconsistent, so no element of \(C_b\) exists. ◻

The layered functional carrier of Theorem 42 is the finite multi-edge, multi-step witness that the boundary-fiber hypothesis is non-vacuous beyond one-dimensional propagation intuition.

Proposition 45 (Tree repair realizes the selected extension). Under the hypotheses of Theorem 44, choose positive weights \[ w_v>\sum_{c:p(c)=v}w_c \] and set \[ \Phi_T(x)=\sum_{v\ne r}w_v\,\mathbf 1[x_v\ne f_v(x_{p(v)},b)] . \] The repair that sets a non-root vertex to \(f_v(x_{p(v)},b)\) strictly decreases \(\Phi_T\), and the aggregate transaction for a connected tree-repair conflict component computes the same result in increasing tree depth.

Proof. Repairing \(v\) removes the \(v\)-term of weight \(w_v\). Only children of \(v\) can become unmatched, contributing at most \(\sum_{c:p(c)=v}w_c\), which is strictly smaller than \(w_v\). Thus the tree potential decreases. For a connected conflict component, applying parent repairs before child repairs is forced by the same extension equations, and any different parenthesization has the same quotient result because each child value is a deterministic function of the repaired parent and \(b\). ◻

Corollary 46 (Nontrivial branch elimination). Assume transactional confluence, boundary preservation, repair completeness, and Theorem 44. If a selected boundary fiber has \(|Q_b|\ge2\) and \(C_b=\{u_b\}\), then \[ \overline{\operatorname{nf}}_\lambda(Q_b)=\{u_b\}, \] while \(Q_b\setminus C_b\ne\varnothing\). Thus multiple candidate interiors exist, inconsistent candidates are eliminated by repair, and all surviving candidates share one quotient normal form. If \(C_b=\varnothing\), the branch is obstructed. If a union solver returns two physically distinct consistent quotient endpoints for the same selected data, the result is an ambiguous union repair and requires an explicit continuation gate, not selection by hash.

Remark 47 (Receipts do not replace the theorem). Implementation receipts named seam descent, atomic commit, distributed local diamond, repair completeness, same-boundary multistart confluence, and quotient normal-form canonical hash are public evidence contracts for the finite theorem hypotheses above. They are not proof substitutes. In particular, a normal-form hash certifies that two emitted quotient normal forms agree after the declared quotienting; it is not allowed to choose between two physically distinct minimizing states. The same convention applies to continuation receipts used by implementation evidence. A receipt is a compact name for primitive evidence and residual checks. Producer-declared booleans, labels, hashes, or successful plots cannot override failed residuals, missing objects, or undeclared quotient maps. When a later paper names a physical receipt, the evidence bundle must expose the raw objects needed to recompute it.

Remark 48 (Triality as finite quotient-fusion example). The \(E_8/\mathrm{Spin}(8)\) triality certificate is a finite exact example of the quotient discipline used here. Before quotienting by the allowed outer symmetry, the vector \(\mathrm{Alt}(9)\) and positive-half-spin \(2\!\cdot\!\mathrm{Alt}(9)\) presentations have different orbit partitions on \(E_8/2E_8\setminus\{0\}\), namely \(\{9,36,84,126\}\) and \(\{120,135\}\), so they are not conjugate in \(O_8^+(2)\). After adjoining Spin(8) triality they become different charts of one triality-fused exceptional datum. This is not a new confluence theorem and does not imply repair termination, noisy convergence, code distance, BFT liveness, or hardware speedup.

Corollary 49 (Gauge-invariant law). If \(M:\Sigma\to Y\) is gauge-invariant (\(M(\gamma\cdot s)=M(s)\) for all \(\gamma\)), then \(M(\operatorname{nf}_\lambda(s))\) depends only on the gauge orbit \([s]\), not the representative.

Proof. Because \(M\) is gauge-invariant, it factors through the orbit map: \(M=\overline M\circ q\) for some \(\overline M:\Sigma/\Gamma\to Y\). Theorem 37 gives \[ q\bigl(\operatorname{nf}_\lambda(\gamma\cdot s)\bigr) \mathrel{=} q\bigl(\operatorname{nf}_\lambda(s)\bigr), \] hence \[ M\bigl(\operatorname{nf}_\lambda(\gamma\cdot s)\bigr) \mathrel{=} \overline M\!\left(q\bigl(\operatorname{nf}_\lambda(\gamma\cdot s)\bigr)\right) \mathrel{=} \overline M\!\left(q\bigl(\operatorname{nf}_\lambda(s)\bigr)\right) \mathrel{=} M\bigl(\operatorname{nf}_\lambda(s)\bigr). \]  ◻

Remark 50 (Sphere folding as quotient readout). When a spherical support chart \(\chi_{S,r}\) is supplied by the screen-microphysics branch, the folded screen presentation of a finite state \(s\) is \[ \operatorname{Fold}_{S,r}(s) \mathrel{=} \chi_{S,r}\!\left(n_r(\pi_r(s))\right). \] Here \(\pi_r\) passes to the physical quotient and \(n_r\) is the accepted repair normal-form map. The word “folding” therefore names a readout of the same quotient normal form studied in this paper. It does not add a repair law, force term, or hidden state variable.

Definition 51 (Physical observable algebra on the quantum lift). Fix a finite patch region or union collar \(R\) on the declared fixed-cutoff quantum lift of Appendix 16. Its physical observable algebra \(\mathcal A_{\mathrm{phys}}(R)\) is the fixed-point collar algebra under the compact boundary redundancy action on the ordinary or central-defect branch, or the corresponding quotient-local algebra on the genuinely noncentral branch. The central sector projectors carried by the collar decomposition belong to \(Z(\mathcal A_{\mathrm{phys}}(R))\). A physical observable is any \(X\in \mathcal A_{\mathrm{phys}}(R)\). For a microscopic representative \(s\in\Sigma\), let \(\omega_R^s\) denote the induced state on \(\mathcal A_{\mathrm{phys}}(R)\).

Theorem 52 (Observable-level confluence on the quantum lift). Under the hypotheses of Theorems 29 and 37, every initial orbit \([s]\in\Sigma/\Gamma\) has a unique quotient normal form \[ \overline{\operatorname{nf}}_\lambda([s])\in q(C). \] Fix a declared region \(R\). Let \(t,u\in\Sigma\) be terminal microscopic representatives reached by representative lifts of maximal repair sequences from initial states in the same orbit \([s]\). If the induced \(R\)-collar states of \(t\) and \(u\) are representatives of the same quotient-local glued state in the sense of Proposition 100, then for every physical observable \(X\in\mathcal A_{\mathrm{phys}}(R)\), \[ \omega_R^t(X)=\omega_R^u(X). \] Hence all physical observables converge to the same overlap-consistent values even when the microscopic terminal representatives differ by gauge relabelings globally or by sector/higher-gauge relabelings inside one declared quotient-local glued state.

Proof. Theorems 29 and 37 give the unique quotient normal form \(\overline{\operatorname{nf}}_\lambda([s])=[\operatorname{nf}_\lambda(s)]\in q(C)\). Let \(t\) and \(u\) be as stated. By Corollary 102, representatives of the same quotient-local glued state induce the same state on the physical observable algebra \(\mathcal A_{\mathrm{phys}}(R)\), including the central sector projectors carried by that algebra. Therefore \(\omega_R^t(X)=\omega_R^u(X)\) for every \(X\in\mathcal A_{\mathrm{phys}}(R)\). ◻

Remark 53 (Inputs and boundary for observable-level confluence). Theorem 52 does not add a new repair hypothesis beyond the confluence and fixed-cutoff gluing package. Its inputs are exactly the representative-level confluence theorem, quotient descent of the repair law, Definition 51, and Corollary 102 from the fixed-cutoff union-collar gluing package. The boundary item is extension of the same statement to broader refinement-stable branches where the declared union-collar compatibility is only approximate or where the chosen physical observable algebra itself changes under refinement.

Corollary 54 (Inert ancillary refinement does not change physical law). Let \(K=\prod_i K_i\) be a finite ancillary state space and define \(\Sigma^\eta:=\Sigma\times K\). Lift the repair maps by \[ T_i^{\lambda,\eta}(s,k):=(T_i^\lambda(s),k). \] If \(M^\eta:\Sigma^\eta\to Y\) ignores the ancillary factor, \[ M^\eta(s,k)=M(s), \] with \(M\) gauge-invariant on \(\Sigma\), then \[ M^\eta(\operatorname{nf}_\lambda^\eta(s,k)) \mathrel{=} M(\operatorname{nf}_\lambda(s)) \] for all \((s,k)\in\Sigma^\eta\).

Proof. Because the ancillary factor is inert, \[ \operatorname{nf}_\lambda^\eta(s,k)=\bigl(\operatorname{nf}_\lambda(s),k\bigr). \] Therefore \(M^\eta(\operatorname{nf}_\lambda^\eta(s,k))=M(\operatorname{nf}_\lambda(s))\), and Corollary 49 supplies gauge-orbit independence. ◻

Physical uniqueness therefore holds on the quotient by gauge or implementation hiding. The same statement is unchanged under inert ancillary stabilization.

Definition 55 (Finite packet closure simplex). Assume the finite fixed-cutoff consensus branch of Theorems 29 and 37, so the physical quotient \(Q:=\Sigma/\Gamma\) is finite and carries the schedule-independent quotient normal-form map \[ \overline{\operatorname{nf}}_\lambda:Q\to Q. \] Let \[ N_\lambda:=\overline{\operatorname{nf}}_\lambda(Q)=q(C) \] be the quotient normal-form set. The finite packet simplex on \(Q\) is \[ \Delta(Q):= \left\{ \mu:Q\to\mathbb R_{\ge0}\ \middle|\ \sum_{x\in Q}\mu(x)=1 \right\}, \] and the finite packet closure map is the pushforward \[ \mathcal C_\lambda:\Delta(Q)\to\Delta(Q), \qquad \mathcal C_\lambda(\mu):= \bigl(\overline{\operatorname{nf}}_\lambda\bigr)_*\mu, \] equivalently \[ \mathcal C_\lambda(\mu)(y) \mathrel{=} \sum_{\substack{x\in Q\\ \overline{\operatorname{nf}}_\lambda(x)=y}}\mu(x). \]

Theorem 56 (Finite packet-quotient closure map). On the finite fixed-cutoff consensus branch of Definition 55, the map \(\mathcal C_\lambda\) is an affine continuous idempotent self-map of \(\Delta(Q)\). Its image is exactly the normal-form simplex \[ \Delta(N_\lambda) \mathrel{=} \left\{ \mu\in\Delta(Q)\ \middle|\ \operatorname{supp}(\mu)\subseteq N_\lambda \right\}. \] Hence the fixed points of \(\mathcal C_\lambda\) are exactly the packets supported on quotient normal forms. For every initial quotient state \([s]\in Q\), \[ \mathcal C_\lambda(\delta_{[s]}) \mathrel{=} \delta_{\overline{\operatorname{nf}}_\lambda([s])}. \]

Proof. Because \(\overline{\operatorname{nf}}_\lambda:Q\to Q\) is a set map on a finite set, its pushforward on probability packets is affine and continuous in the finite-dimensional simplex topology.

By Theorems 29 and 37, the quotient normal form is schedule-independent and terminal, so \[ \overline{\operatorname{nf}}_\lambda\circ\overline{\operatorname{nf}}_\lambda \mathrel{=} \overline{\operatorname{nf}}_\lambda. \] Pushforward therefore gives \[ \mathcal C_\lambda^2 \mathrel{=} \bigl(\overline{\operatorname{nf}}_\lambda\bigr)_* \bigl(\overline{\operatorname{nf}}_\lambda\bigr)_* \mathrel{=} \bigl(\overline{\operatorname{nf}}_\lambda\circ\overline{\operatorname{nf}}_\lambda\bigr)_* \mathrel{=} \mathcal C_\lambda, \] so \(\mathcal C_\lambda\) is idempotent.

If \(\nu=\mathcal C_\lambda(\mu)\), then every point in \(\operatorname{supp}(\nu)\) lies in the image of \(\overline{\operatorname{nf}}_\lambda\), namely \(N_\lambda\). Thus \(\operatorname{im}(\mathcal C_\lambda)\subseteq \Delta(N_\lambda)\). Conversely, if \(\nu\in\Delta(N_\lambda)\), then \(\overline{\operatorname{nf}}_\lambda(y)=y\) for every \(y\in N_\lambda\), so \[ \mathcal C_\lambda(\nu)=\nu. \] Hence \(\Delta(N_\lambda)\subseteq \operatorname{im}(\mathcal C_\lambda)\), proving \(\operatorname{im}(\mathcal C_\lambda)=\Delta(N_\lambda)\). The same identity shows that \(\nu\) is a fixed point if and only if it is supported on \(N_\lambda\). The Dirac-mass formula is the pushforward of a point mass under \(\overline{\operatorname{nf}}_\lambda\). ◻

Remark 57 (Boundary of the finite closure theorem). Theorem 56 is an exact finite-branch result. It proves a closure map only on the finite packet simplex built from one fixed quotient carrier whose repair law is terminating, confluent, and quotient-descended. It does not prove a habitat-level closure map for arbitrary OPH state-and-law data, does not identify a nonempty observer-supporting invariant sector inside the Appendix-B habitat, and does not supply uniqueness or stability estimates beyond this finite packet branch.

Refinement-Limit Consensus Classes

The finite consensus theorem is the operational object used by the continuum branches. To pass from one finite patch net to a refining family, the paper uses an explicit inverse-limit package with named compatibility clauses.

Definition 58 (Separated cofinal refinement consensus system). Let \((R,\preceq)\) be a directed refinement set. For each \(r\in R\), let \[ Q_r:=\Sigma_r/\Gamma_r \] be the finite physical quotient state space of a patch presentation, let \[ n_r:Q_r\to Q_r \] be the finite-stage quotient normal-form map supplied by Theorems 29 and 37, and let \[ h_r:Q_r\to \mathcal H_r \] be the finite-stage holonomy or higher-gauge obstruction map supplied by Theorems 32 and 35. For \(r\preceq s\), assume restriction maps \[ \rho_{sr}:Q_s\to Q_r, \qquad \chi_{sr}:\mathcal H_s\to\mathcal H_r, \] with \(\rho_{rr}=\mathrm{id}\), \(\chi_{rr}=\mathrm{id}\), and the cocycle identities \[ \rho_{tr}=\rho_{sr}\circ\rho_{ts}, \qquad \chi_{tr}=\chi_{sr}\circ\chi_{ts} \qquad (r\preceq s\preceq t). \] The system is a separated cofinal refinement consensus system when:

  1. Normal-form naturality: \[ \rho_{sr}\circ n_s=n_r\circ\rho_{sr} \qquad (r\preceq s). \]

  2. Holonomy naturality: \[ \chi_{sr}\circ h_s=h_r\circ\rho_{sr} \qquad (r\preceq s). \]

  3. Visible separation: two compatible families in \(\varprojlim Q_r\), or in \(\varprojlim \mathcal H_r\), are equal whenever their projections agree on a cofinal subset of stages.

Theorem 59 (Refinement-limit consensus and holonomy classes). For any separated cofinal refinement consensus system, the formulas \[ n_\infty\bigl((x_r)_r\bigr):=(n_r(x_r))_r, \qquad h_\infty\bigl((x_r)_r\bigr):=(h_r(x_r))_r \] define maps \[ n_\infty:\varprojlim Q_r\to\varprojlim Q_r, \qquad h_\infty:\varprojlim Q_r\to\varprojlim\mathcal H_r. \] The class \(n_\infty(x)\) is the unique schedule-independent refinement-limit normal form of \(x\). The class \(h_\infty(x)\) is the refinement-limit holonomy obstruction. The pair \((n_\infty(x),h_\infty(x))\) is the refinement-limit consensus class. In the inverse-limit topology, finite-stage normal forms and holonomy classes converge to these two classes: for every stage \(r\), all refinements \(s\succeq r\) restrict to the fixed values \[ \rho_{sr}(n_s(x_s))=n_r(x_r), \qquad \chi_{sr}(h_s(x_s))=h_r(x_r). \] The relation \(h_\infty(x)=0\) holds if and only if every finite projection has zero finite-stage obstruction. If \(h_\infty(x)\ne0\), visible separation gives a finite stage that witnesses the nonzero obstruction. If two refinement-limit candidates have the same normal-form and holonomy projections on a cofinal tail, then they determine the same refinement-limit consensus class.

Proof. Let \(x=(x_r)_r\in\varprojlim Q_r\), so \(\rho_{sr}(x_s)=x_r\) for \(r\preceq s\). Normal-form naturality gives \[ \rho_{sr}(n_s(x_s)) \mathrel{=} n_r(\rho_{sr}(x_s)) \mathrel{=} n_r(x_r), \] so \((n_r(x_r))_r\) is a compatible family and \(n_\infty\) is well defined. The same argument with holonomy naturality gives \[ \chi_{sr}(h_s(x_s)) \mathrel{=} h_r(\rho_{sr}(x_s)) \mathrel{=} h_r(x_r), \] so \(h_\infty\) is well defined.

Each finite \(n_r(x_r)\) is independent of update schedule by Theorems 29 and 37. Therefore every finite projection of \(n_\infty(x)\) is schedule-independent, and visible separation makes the inverse-limit class unique. The displayed restriction identities are exactly the cylinder convergence statement in the inverse-limit topology.

The zero-obstruction statement follows from the definition of the inverse-limit zero class. The identity \(h_\infty(x)=0\) holds exactly when every projection \(h_r(x_r)\) is zero. If \(h_\infty(x)\ne0\), at least one finite projection is nonzero, and any cofinal tail containing a refinement of that stage carries the same nonzero projected obstruction by holonomy naturality. The last claim is visible separation applied to the compatible normal-form and holonomy families. ◻

Remark 60 (Scope of the refinement theorem). Theorem 59 is a controlled continuum bridge. It proves persistence, exhaustion, and collapse of the consensus data once the OPH refinement system supplies the restriction maps and the two naturality clauses in Definition 58. It leaves uniform complexity bounds, automatic fair-block noisy-consensus certificates, and automatic normal-form naturality for arbitrary changing repair laws as separate branch conditions.

Definition 61 (Repair morphism). Let \((Q_s,\to_s,C_s,n_s)\) and \((Q_r,\to_r,C_r,n_r)\) be two finite quotient repair systems covered by Theorems 29 and 37. A map \[ \rho_{sr}:Q_s\to Q_r \] is a repair morphism when:

  1. every fine repair step \(x\to_s y\) maps to a coarse repair path or a stutter, \[ \rho_{sr}(x)\to_r^*\rho_{sr}(y); \]

  2. fine consistency maps into coarse consistency, \[ \rho_{sr}(C_s)\subseteq C_r. \]

For a concrete local repair law this is checked by giving, for every fine repair generator, a coarse witness word in the accepted coarse repair generators or the empty word, and by verifying that the restriction maps carry every fine consistency equation to a coarse consistency equation.

Theorem 62 (Normal-form naturality from repair morphisms). If \(\rho_{sr}:Q_s\to Q_r\) is a repair morphism, then \[ \rho_{sr}\circ n_s=n_r\circ\rho_{sr}. \]

Proof. Fix \(x\in Q_s\). Since \(x\to_s^* n_s(x)\), repeated use of the step-simulation clause gives \[ \rho_{sr}(x)\to_r^*\rho_{sr}(n_s(x)). \] The consistency-preservation clause gives \(\rho_{sr}(n_s(x))\in C_r\), because \(n_s(x)\in C_s\). Thus \(\rho_{sr}(n_s(x))\) is a coarse normal form reachable from \(\rho_{sr}(x)\). The coarse system has a unique normal form reachable from each initial quotient state, so \(\rho_{sr}(n_s(x))=n_r(\rho_{sr}(x))\). ◻

Definition 63 (Holonomy cochain morphism). For obstruction maps \(h_s:Q_s\to\mathcal H_s\) and \(h_r:Q_r\to\mathcal H_r\), a map \(\chi_{sr}:\mathcal H_s\to\mathcal H_r\) is a holonomy cochain morphism when the edge, cycle, or crossed-module cochains that compute \(h_s\) restrict to the cochains that compute \(h_r\), modulo the declared quotient identifications. Equivalently, \[ \chi_{sr}\circ h_s=h_r\circ\rho_{sr}. \]

Remark 64 (How exact refinement naturality is discharged). Definition 58 may be used as an interface contract, but on an implemented exact branch the normal-form part is proved by Theorem 62 from explicit coarse witness words for fine repairs. The holonomy part is proved by the cochain morphism check of Definition 63. Approximate RG branches use the controlled defects of Definition 65 instead.

Definition 65 (Controlled coarse-graining / reconciliation square). Fix refinement stages \(r\preceq s\). Let \(Q_r,Q_s\) be the physical quotient state spaces, \(n_r,n_s\) their finite-stage normal-form maps, and \(h_r,h_s\) their holonomy or higher-gauge obstruction maps. Let \[ \rho_{sr}:Q_s\to Q_r, \qquad \chi_{sr}:\mathcal H_s\to\mathcal H_r \] be the coarse-graining maps on quotient states and obstruction data. Equip \(Q_r\) and \(\mathcal H_r\) with pseudometrics \(d^Q_r\) and \(d^{\mathcal H}_r\) that define the macroscopic readout scale at stage \(r\).

The square is \((\varepsilon^n_{sr},\varepsilon^h_{sr})\)-controlled when, for every \(x\in Q_s\), \[ d^Q_r\!\left(\rho_{sr}(n_s(x)),\,n_r(\rho_{sr}(x))\right) \le \varepsilon^n_{sr}, \] and \[ d^{\mathcal H}_r\!\left(\chi_{sr}(h_s(x)),\,h_r(\rho_{sr}(x))\right) \le \varepsilon^h_{sr}. \] The errors are cofinally vanishing when, for every fixed macroscopic stage \(r\) and every \(\delta>0\), there is a refinement stage \(s_0\succeq r\) such that \(\varepsilon^n_{sr},\varepsilon^h_{sr}<\delta\) for all \(s\succeq s_0\).

Theorem 66 (Coarse-graining commutes with reconciliation up to controlled error). Suppose the refinement square of Definition 65 is \((\varepsilon^n_{sr},\varepsilon^h_{sr})\)-controlled. Define the coarse-stage consensus readout \[ \mathcal C_r(y):=(n_r(y),h_r(y)) \] and the fine-then-coarse readout \[ \mathcal C_{s\to r}^{\mathrm{fine}}(x):=(\rho_{sr}(n_s(x)),\chi_{sr}(h_s(x))). \] Then, for every fine state \(x\in Q_s\), the product readout distance between \(\mathcal C_{s\to r}^{\mathrm{fine}}(x)\) and \(\mathcal C_r(\rho_{sr}(x))\) is bounded by \[ \max\{\varepsilon^n_{sr},\varepsilon^h_{sr}\}. \] Thus reconciling at the fine stage and then coarse-graining gives the same macroscopic law data as coarse-graining first and reconciling at the coarse stage, up to the declared control errors. If the exact naturality clauses of Definition 58 hold, then \(\varepsilon^n_{sr}=\varepsilon^h_{sr}=0\). If the errors are cofinally vanishing, the two procedures determine the same cylinder values in the inverse-limit topology at every fixed macroscopic stage.

Proof. The normal-form component of the product readout is bounded by the first inequality in Definition 65, and the obstruction component is bounded by the second. Taking the maximum gives the stated product bound. Exact naturality is precisely the special case \[ \rho_{sr}\circ n_s=n_r\circ\rho_{sr}, \qquad \chi_{sr}\circ h_s=h_r\circ\rho_{sr}, \] so both errors vanish there. Cofinal vanishing means that, for any fixed coarse cylinder and any desired readout tolerance, all sufficiently fine presentations give the same cylinder value within that tolerance, which is convergence in the inverse-limit topology. ◻

Remark 67 (What remains to verify on a concrete RG branch). Theorem 66 is not a claim that arbitrary renormalization maps commute with arbitrary repair laws. It identifies the exact branch burden: derive or estimate the two square defects \(\varepsilon^n_{sr}\) and \(\varepsilon^h_{sr}\) from the chosen coarse-graining channel, recovery map, decoder, and obstruction readout. The exact refinement theorem is the zero-defect case; approximate RG matching is theorem-grade only when these defects are explicitly controlled.

Record Algebras and the Operator Observation Layer

Inputs used here.

From the fixed-cutoff collar package we use only the observer-accessible finite-dimensional algebra on one completed compare/write/verify slice, the declared pointer and overlap-sector projectors read on that same slice, and the trace-distance control on restored accessible states when restoration is invoked. No continuum lift and no broader observer-metaphysical assumption is used here.

Definition 68 (Exact record algebras and approximate record presentations). Fix one completed observer-accessible slice at cycle \(t\), and let \(\mathcal A_t^{\mathrm{acc}}\) be the corresponding finite-dimensional accessible algebra. An exact record presentation is a family of orthogonal projectors \(\{\widehat P_a(t)\}_a\subset Z(\mathcal A_t^{\mathrm{acc}})\) whose generated algebra \[ \mathcal Z_{\mathrm{rec}}(t) := \mathrm{Alg}\bigl(\{\widehat P_a(t)\}_a\bigr) \] is finite and commutative.

An approximate record presentation on the same declared readout slots is a family of projectors \(\{P_a(t)\}_a\subset \mathcal A_t^{\mathrm{acc}}\) together with an exact record presentation \(\{\widehat P_a(t)\}_a\) such that \[ \delta_{\mathrm{rec}}(t) := \max_a \|P_a(t)-\widehat P_a(t)\| \] is finite.

Theorem 69 (Record algebra, Born-Lüders update, and quantitative stability). Fix one completed observer-accessible slice at cycle \(t\).

  1. The exact record projectors generate a finite commutative central algebra \(\mathcal Z_{\mathrm{rec}}(t)\subset Z(\mathcal A_t^{\mathrm{acc}})\).

  2. For every event \(E\) in the finite event algebra generated by \(\mathcal Z_{\mathrm{rec}}(t)\), \[ \mathbb P_t(E)=\operatorname{Tr}\!\bigl(\rho_t \widehat P_E(t)\bigr), \qquad \rho_t\!\mid_E \mathrel{=} \frac{\widehat P_E(t)\rho_t \widehat P_E(t)} {\operatorname{Tr}(\rho_t \widehat P_E(t))}. \]

  3. If no accepted repair between \(t\) and \(t+1\) touches the support of \(\widehat P_E(t)\), then the next read of \(E\) has probability \(1\).

  4. If \(\{P_a(t)\}_a\) is an approximate record presentation with modulus \(\delta_{\mathrm{rec}}(t)\), then \[ \|[P_a(t),P_b(t)]\|\le 4\,\delta_{\mathrm{rec}}(t) \] for all declared record projectors \(P_a(t),P_b(t)\). For every declared elementary record event \(a\) and every restored accessible state \(\widetilde\rho_t\) satisfying \[ \|\widetilde\rho_t-\rho_t\|_1\le \varepsilon, \] one has \[ \Bigl| \operatorname{Tr}\!\bigl(\widetilde\rho_t P_a(t)\bigr) \text{-} \operatorname{Tr}\!\bigl(\rho_t \widehat P_a(t)\bigr) \Bigr| \le \varepsilon+\delta_{\mathrm{rec}}(t). \]

Proof. Because the exact record projectors lie in the center of \(\mathcal A_t^{\mathrm{acc}}\), they generate a finite commutative central algebra. Finite-dimensional projective measurement on that commuting algebra gives the Born trace and the Lüders conditioned state, proving (1) and (2). The finite-matrix steps behind (1) and (2) are machine-checked in the companion Lean 4 event-algebra development : the commutative span of a projective partition and its containment in the center of the partition commutant, the trace-preserving expectation onto that span, preservation of the partition Born statistics, the Lüders fixed-point law, and the collapse of conditioning on a partition member to its normalized projector are theorem-level exports with declaration-level axiom audits.

If no accepted repair touches the support of \(\widehat P_E(t)\), then the next completed read is performed on the same central projector surface. After conditioning on \(E\), the state lies in the range of \(\widehat P_E(t)\), so the next read of the same event has probability \(1\). This gives (3).

For (4), write \[ [P_a(t),P_b(t)] \mathrel{=} [P_a(t)-\widehat P_a(t),P_b(t)] + [\widehat P_a(t),P_b(t)-\widehat P_b(t)], \] because \([\widehat P_a(t),\widehat P_b(t)]=0\). Since every projector has operator norm at most \(1\), \[ \|[P_a(t),P_b(t)]\| \le 2\|P_a(t)-\widehat P_a(t)\| + 2\|P_b(t)-\widehat P_b(t)\| \le 4\,\delta_{\mathrm{rec}}(t). \] For the probability bound, \[ \Bigl| \operatorname{Tr}\!\bigl(\widetilde\rho_t P_a(t)\bigr) \text{-} \operatorname{Tr}\!\bigl(\rho_t \widehat P_a(t)\bigr) \Bigr| \le \Bigl|\operatorname{Tr}\!\bigl((\widetilde\rho_t-\rho_t)P_a(t)\bigr)\Bigr| + \Bigl|\operatorname{Tr}\!\bigl(\rho_t(P_a(t)-\widehat P_a(t))\bigr)\Bigr|. \] The first term is bounded by \(\|\widetilde\rho_t-\rho_t\|_1\|P_a(t)\|\le \varepsilon\), and the second by \(\|\rho_t\|_1\|P_a(t)-\widehat P_a(t)\|\le \delta_{\mathrm{rec}}(t)\). Hence the total error is at most \(\varepsilon+\delta_{\mathrm{rec}}(t)\). ◻

Merge boundary.

What is closed here is the fixed-cutoff operator-algebraic observation surface: a central record algebra on the exact readout slice, Born/Lüders measurement on its event projectors, exact repeated-read stability under the untouched-support hypothesis, and explicit \((\varepsilon,\delta_{\mathrm{rec}})\) control when practical readout projectors are only close to that central surface. The broader export problem asks whether richer branches keep physically relevant pointer surfaces close to one such central record algebra and whether the same control survives refinement and continuation.

OPH Simulation Criterion and Fixed-Point Firewall

A fixed-point equation is necessary for a selected finite OPH packet, but it is not the definition of an OPH simulation. The additional clauses below are the nontrivial content.

Definition 70 (Nontrivial OPH simulation certificate). Work on the finite fixed-cutoff branch of Definition 55. Write \[ Q:=\Sigma/\Gamma, \qquad n:=\overline{\operatorname{nf}}_\lambda:Q\to Q, \qquad N_\lambda:=q(C). \] Let \(B:Q\to\mathcal B\) be a boundary/sector map preserved by accepted quotient repairs, fix \(b\in\mathcal B\), and set \[ Q_b:=B^{-1}(b), \qquad C_b:=N_\lambda\cap Q_b. \] For \(u\in C_b\), let \(\mathfrak U_u:=\delta_u\in\Delta(Q)\). The selected pair \((b,u)\), equivalently the packet \(\mathfrak U_u\), has an OPH simulation certificate when all of the following hold.

  1. Endogenous update. The local maps are the recovery-derived collar maps of Definition 7, descend to the physical quotient, and use only the declared patch, overlap, recovery, decoder, and acceptance data. No undeclared oracle variable is an argument of an accepted physical update.

  2. Observer-readable records. A declared observer-accessible region carries an exact record presentation \(\{\widehat P_a\}_a\) as in Definition 68, with at least two nonzero orthogonal event projectors. Event probabilities, conditioned readouts, and any checkpoint/order relation interpreted as history are collected in a physical map \[ \operatorname{Read}:Q\to\mathcal Y_{\rm rec} \] whose terminal value depends only on the quotient normal form.

  3. Overlap repair. Every accepted nontrivial move strictly lowers the declared touched-overlap score, normal forms are exactly the globally consistent states, and the quotient normal form \(n\) is terminating and schedule-independent.

  4. Nontrivial branch elimination. The selected fiber has one consistent quotient state but more than one candidate: \[ C_b=\{u\}, \qquad Q_b\setminus C_b\ne\varnothing, \qquad n(Q_b)=\{u\}. \] Thus at least one inconsistent candidate is genuinely removed instead of merely renamed a fixed point. A candidate with a nonzero declared holonomy or higher-gauge obstruction is rejected as obstructed and is not counted as an alternative selected world.

  5. Implementation and clock closure. The physical update and record readout have types \[ n:Q\to Q, \qquad \operatorname{Read}:Q\to\mathcal Y_{\rm rec}, \] with no indispensable machine-state or external-time argument. More precisely, for any auxiliary implementation and clock sets \(\mathcal E_{\rm ext}\) and \(\Theta_{\rm ext}\), let \[ p:Q\times\mathcal E_{\rm ext}\times\Theta_{\rm ext}\to Q \] be the physical projection. An admissible lifted update \(\widetilde n\) and readout \(\widetilde{\operatorname{Read}}\) must satisfy \[ p\circ\widetilde n=n\circ p, \qquad \widetilde{\operatorname{Read}}=\operatorname{Read}\circ p. \] The asynchronous schedule and repair-step counter are proof data, not physical clock coordinates. Any history claimed by the branch is read from records in the terminal quotient state instead of supplied by an external clock. Promoting that record order to physical time requires the independent clock instrument, event correspondence, and calibration receipts.

The identities \[ n(u)=u, \qquad \mathcal C_\lambda(\mathfrak U_u)=\mathfrak U_u \] are therefore consequences of the certificate, not its definition.

Theorem 71 (Selected OPH packet and fixed-point firewall). Assume Definitions 7, 8, and 9, Assumption 18, and the quotient and record hypotheses of Theorems 37, 52, and 69. Fix a preserved boundary/sector value \(b_{\rm OPH}\) for which \[ C_{b_{\rm OPH}}=\{u_{\rm OPH}\}, \qquad Q_{b_{\rm OPH}}\setminus C_{b_{\rm OPH}}\ne\varnothing, \] and assume the selected observer surface has a nontrivial exact record presentation whose checkpoint/order data, when interpreted as history, are quotient-observable. Then the selected finite OPH packet \[ \mathfrak U_{\rm OPH}:=\delta_{u_{\rm OPH}} \] has an OPH simulation certificate in the sense of Definition 70. In particular, \[ n(u_{\rm OPH})=u_{\rm OPH}, \qquad \mathcal C_\lambda(\mathfrak U_{\rm OPH})=\mathfrak U_{\rm OPH}. \]

The converse is false: a fixed point, equilibrium, stationary point, or variational solution does not by itself imply an OPH simulation certificate. Indeed, for any set \(X\) with \(|X|>1\), the identity map \(F=\mathrm{id}_X\) satisfies \(F(x)=x\) for every \(x\in X\), and every \(x\) is a global minimizer and stationary point of the constant functional \(V\equiv0\). Nevertheless, \(F^{-1}(x)=\{x\}\), so no proper candidate basin collapses to \(x\); clause (S4) fails. The fixed-point or variational equation alone also supplies none of clauses (S1)(S3)* or (S5).

Proof. Clause (S1) is Definition 7 together with quotient descent from Theorem 37. Clause (S2) follows from Theorem 69; terminal representative independence is Theorem 52. Definition 8, Proposition 24, Proposition 27, Assumption 18, and Theorem 29 give clause (S3).

For \(x\in Q_{b_{\rm OPH}}\), boundary preservation gives \(B(n(x))=b_{\rm OPH}\), while repair completeness gives \(n(x)\in N_\lambda\). Hence \(n(x)\in C_{b_{\rm OPH}}=\{u_{\rm OPH}\}\), proving \(n(Q_{b_{\rm OPH}})=\{u_{\rm OPH}\}\). The assumed nonempty difference \(Q_{b_{\rm OPH}}\setminus C_{b_{\rm OPH}}\) makes this elimination nontrivial. The holonomy and higher-gauge rejection statement is Theorems 32 and 35. This proves clause (S4). Its proper-basin requirement is nonvacuous: on the verified rooted-tree packet domain of Theorem 20, fixing the root packet gives a singleton consistent fiber, while changing any non-root packet supplies an inconsistent candidate in that fiber.

The quotient normal-form and physical-record maps are defined on the declared physical state alone. Schedule independence removes the scheduler from the output, and Corollary 54 proves invariance under inert carrier enlargement. The displayed projection identities are the admissibility condition for any more general carrier or clock realization. Thus an auxiliary implementation state or iteration counter cannot change the physical result, proving clause (S5). Finally, Theorem 56 gives \[ \mathcal C_\lambda(\delta_{u_{\rm OPH}}) =\delta_{n(u_{\rm OPH})} =\delta_{u_{\rm OPH}}, \] because \(u_{\rm OPH}\in N_\lambda\). The identity-map and constant-functional example proves the final non-implication. ◻

Remark 72 (Structural falsification hooks). An asserted OPH simulation certificate fails if any one of the following occurs: an accepted update depends on undeclared oracle, carrier, or external-clock data; the observer record algebra is trivial, unstable, or not quotient-readable; an accepted move fails strict mismatch descent; terminal states are not exactly the overlap-consistent states; two admissible schedules or two candidates in the selected boundary fiber produce different physical normal forms; the selected fiber has no inconsistent candidate to eliminate; a claimed global branch has nonzero holonomy or higher-gauge obstruction; or a carrier/clock lift changes the physical update or readout after projection. These are theorem-level failure conditions, not semantic disagreements about the word “simulation.”

Remark 73 (Scope). Theorem 71 certifies the named finite fixed-cutoff branch and selected boundary/sector fiber. It does not promote the finite packet closure to an arbitrary habitat-level state-and-law space, and it does not remove the branch and record hypotheses stated in the theorem.

Distributed Presentations of One Finite Universe

The implementation closure clause in Definition 70 has a distributed form. A worker partition is allowed to accelerate or package the computation, but it is not a new physical ingredient. The physical question is whether the worker run presents the same finite quotient repair system as the monolithic carrier.

Definition 74 (Finite global OPH carrier). At refinement stage \(r\), a finite global OPH carrier consists of a finite patch graph \[ G_r=(V_r,E_r), \] finite patch state sets \(S_i\), interface alphabets \(I_e\), endpoint maps \(\pi_{i,e}:S_i\to I_e\), an implementation-hiding group \(\Gamma_r\), a boundary/sector map \(B_r\), a mismatch potential \(\Phi_r\), accepted quotient repairs \(\to_r\), and an observer-readable map \[ \operatorname{Read}_r:Q_r\to\mathcal Y_r, \qquad Q_r:=\left(\prod_{i\in V_r}S_i\right)/\Gamma_r. \] Let \(C_r\subseteq Q_r\) be the quotient consistency set. On the finite branch covered by Theorems 29 and 37, the accepted quotient repair relation has a unique normal-form map \[ n_r:Q_r\to C_r. \] A one-universe input is the pair \(\mathbf U_r=(\mathfrak U_r,q_0)\), where \(\mathfrak U_r\) is the carrier data above and \(q_0\in Q_r\). A worker partition is not part of \(\mathfrak U_r\).

Definition 75 (Worker presentation and physical projection). Let \(\kappa:V_r\to W\) assign every patch to one authoritative worker. The cut set is \[ E_\kappa^{\mathrm{cut}} := \bigl\{\{i,j\}\in E_r:\kappa(i)\ne\kappa(j)\bigr\}. \] A distributed presentation for \(\kappa\) has worker-owned states, ghost or halo copies, message queues, transaction records, retries, worker identifiers, checkpoints, event logs, and scheduler state. Let \(\widetilde Q_{r,\kappa}\) be its quotient by purely local worker bookkeeping that leaves authoritative physical states unchanged. The physical projection \[ p_{r,\kappa}:\widetilde Q_{r,\kappa}\to Q_r \] keeps only the authoritative patch states, quotients by \(\Gamma_r\), and discards queues, retry metadata, worker labels, and external clocks. Let \[ D_r:=\bigsqcup_{\kappa}\{\kappa\}\times\widetilde Q_{r,\kappa}, \qquad P_r(\kappa,\tilde q):=p_{r,\kappa}(\tilde q). \] A distributed readout is physical when it factors as \[ \widetilde{\operatorname{Read}}_r=\operatorname{Read}_r\circ P_r. \]

Definition 76 (Admissible distributed event). For \(d,d'\in D_r\), a distributed event \(d\Rightarrow d'\) is admissible when one of the following holds.

  1. Linearizable physical commit. There is a nonempty monolithic accepted repair path \[ P_r(d)\to_r^*P_r(d') \] whose repair word is recorded as the event’s linearization witness.

  2. Physical stutter. \(P_r(d')=P_r(d)\). Message delivery, halo refresh, prepare, abort, checkpoint, worker start or stop, idempotent replay, and repartition metadata are allowed only in this class unless they also carry a physical commit witness.

  3. Certified rollback. There is an earlier committed state \(d_j\) in the same run history such that \(P_r(d')=P_r(d_j)\), and the rollback certificate names that committed projection root. Transparent restart from a committed frontier is a stutter.

Proposition 77 (Normal form is constant on an accepted reachability cone). If \(q\to_r^*q'\), then \[ n_r(q')=n_r(q). \]

Proof. The state \(q'\) is reachable from \(q\). The state \(n_r(q')\) is a normal form reachable from \(q'\), hence also reachable from \(q\). Theorem 29 and Theorem 37 give the unique quotient normal form reachable from \(q\), so \(n_r(q')=n_r(q)\). ◻

Theorem 78 (Distributed realization of one finite OPH universe). Fix a finite global carrier \(\mathbf U_r=(\mathfrak U_r,q_0)\) satisfying Theorems 29 and 37. Let \[ d_0\Rightarrow d_1\Rightarrow\cdots\Rightarrow d_m \] be a finite distributed execution in \(D_r\) with \(P_r(d_0)=q_0\), and assume every event is admissible in the sense of Definition 76. Then, for every \(t\), \[ q_0\to_r^*P_r(d_t), \qquad n_r(P_r(d_t))=n_r(q_0). \] If the final projection is a monolithic normal form, then \[ P_r(d_m)=n_r(q_0). \] For every physical observable or observer readout \(M:Q_r\to Y\), \[ M(P_r(d_m))=M(n_r(q_0)) \] whenever \(P_r(d_m)\) is normal. In particular, \(\widetilde{\operatorname{Read}}_r(d_m)=\operatorname{Read}_r(n_r(q_0))\) for every distributed readout that factors through \(P_r\).

Proof. Induct on \(t\). The claim is true at \(t=0\). Suppose it holds at \(t\). For a linearizable physical commit, admissibility gives \[ P_r(d_t)\to_r^*P_r(d_{t+1}), \] so \(q_0\to_r^*P_r(d_{t+1})\), and Lemma 77 gives \[ n_r(P_r(d_{t+1}))=n_r(P_r(d_t))=n_r(q_0). \] For a physical stutter, \(P_r(d_{t+1})=P_r(d_t)\), so both statements are unchanged. For a certified rollback, \(P_r(d_{t+1})\) is the projection of an earlier committed state; the induction hypothesis gives reachability from \(q_0\) and equality of normal forms for that projection. This proves the two displayed identities for every \(t\).

If \(P_r(d_m)\) is a monolithic normal form, then it is the unique quotient normal form reachable from \(q_0\), hence \(P_r(d_m)=n_r(q_0)\). The observable and readout statements follow by applying \(M\) or \(\operatorname{Read}_r\) to this equality and using \(\widetilde{\operatorname{Read}}_r=\operatorname{Read}_r\circ P_r\). ◻

Corollary 79 (Partition, schedule, and restart invariance). Any two admissible distributed executions of the same finite carrier \(\mathbf U_r\), with the same initial quotient state \(q_0\), have the same terminal quotient observables and observer-readable outputs once their final projections are monolithic normal forms. The statement is independent of partition \(\kappa\), worker count, scheduler choices, restart history, and repartition metadata.

Proof. Apply Theorem 78 to each execution. Both final projections equal \(n_r(q_0)\), so every quotient observable and every readout factoring through the projection has the same value. ◻

Proposition 80 (Restart stabilization separates safety from liveness). Assume \(Q_r\) is finite, every physical commit strictly descends the accepted potential until normality, every rollback returns to an earlier committed projection, only finitely many progress-erasing rollbacks occur, and after the last such rollback the scheduler is fair enough to commit an enabled repair whenever the projected state is not normal. Then the distributed run reaches a monolithic normal form after finitely many physical commits.

Proof. Safety is Theorem 78. For liveness, ignore stutters and the finitely many progress-erasing rollbacks before the last one. After that time, each nonnormal projected state takes a strict descending accepted repair after finitely many scheduler steps. The set of possible potential values below the post-rollback value is finite, so strict descent can occur only finitely many times before a normal projected state is reached. ◻

Theorem 81 (Distributed refinement cube). Let \(r\preceq s\). Suppose \(\rho_{sr}:Q_s\to Q_r\) is a repair morphism, the corresponding holonomy maps form a cochain morphism, and distributed presentations at both stages are exact in the sense of Theorem 78. If the lifted restriction \(\widetilde\rho_{sr}:D_s\to D_r\) commutes with physical projection, \[ P_r\circ\widetilde\rho_{sr}=\rho_{sr}\circ P_s, \] then distributed execution and coarse restriction commute on normal forms and readouts: \[ P_r\!\left(\widetilde\rho_{sr}(d_m^s)\right) \mathrel{=} n_r\!\left(\rho_{sr}(q_0^s)\right) \mathrel{=} \rho_{sr}\!\left(n_s(q_0^s)\right) \] whenever the fine final projection is normal. The same statement holds for holonomy readouts via \(\chi_{sr}\).

Proof. The fine distributed theorem gives \(P_s(d_m^s)=n_s(q_0^s)\). Projection compatibility gives \[ P_r(\widetilde\rho_{sr}(d_m^s))=\rho_{sr}(n_s(q_0^s)). \] Theorem 62 identifies this value with \(n_r(\rho_{sr}(q_0^s))\). The holonomy statement is exactly the cochain-morphism identity of Definition 63. ◻

Public certificate contract.

A run pack that claims Theorem 78 must emit enough evidence for a verifier to reconstruct the premises without trusting worker narration. The required fields are: a global carrier manifest and hash, the monolithic graph \(G_r\), the global initial quotient state \(q_0\), a partition map \(\kappa\), cut-interface records \(E_\kappa^{\mathrm{cut}}\) with restriction maps, a global observer registry, code/config/run hashes, a committed event log with a linearization witness for each physical commit, stutter records for noncommitting worker events, rollback records naming earlier committed projection roots, repartition records preserving the physical projection root, a final monolithic normal-form certificate, and a final readout recomputed from the projected state. Missing, stale, shard-local, or synthetic replacements for these fields fail closed. The exact branch uses this contract; noisy branches additionally need the fair-block constants of Theorem 84.

Quotient Chart Transport and Neutral Geometry

The distributed certificate above proves that a worker presentation is one finite quotient system. A separate step is needed before observer rows from different shards may be read as a common neutral geometry.

Definition 82 (Common quotient chart atlas). For a shard \(s\), let \(\Sigma_s\) be raw records, let \(\Gamma_s\) be the groupoid of declared presentation-only moves such as gauge representative changes and local port relabelings, and set \[ \overline Q_s:=\Sigma_s/\Gamma_s,\qquad X_s:=n_s(\overline Q_s), \] where \(n_s\) is the schedule-independent normal-form map. An interface atlas is a family of domains \(U_{st}\subseteq X_s\), \(U_{ts}\subseteq X_t\), and bijections \[ \tau_{ts}:U_{st}\to U_{ts} \] satisfying identity, inverse, and cocycle laws, with zero closed-path holonomy on graph-shaped systems. A channel registry assigns each channel \(c\) a metric space \((Z_c,d_c)\), weight \(w_c>0\), and local features \(F_{s,c}:D_{s,c}\subseteq X_s\to Z_c\). The channel descends through the atlas when both domain membership and values are transported: \[ x\in D_{s,c}\Longleftrightarrow \tau_{ts}x\in D_{t,c}, \qquad F_{t,c}(\tau_{ts}x)=F_{s,c}(x). \]

Theorem 83 (Quotient-visible neutral readout). Under Definition 82, the relation generated by interface transport on \(\bigsqcup_sX_s\) is an equivalence relation and defines \[ Q_{\mathrm{vis}}:=\left(\bigsqcup_sX_s\right)/\!\sim_\tau . \] The canonical maps \(X_s\to Q_{\mathrm{vis}}\) agree with transport, and zero closed-path holonomy makes them injective. Every compatible family of local channel maps descends uniquely to partial maps \(F_c:Q_{\mathrm{vis}}\dashrightarrow Z_c\). Therefore, on the complete channel domain \[ Q_\star=\{x:F_c(x)\ \text{exists for every }c\in\mathcal C_\star\}, \] the product formula \[ d_{\mathrm{neu}}(x,y) \mathrel{=} \left(\sum_{c\in\mathcal C_\star}w_c\,d_c(F_c(x),F_c(y))^p\right)^{1/p} \] is a well-defined pseudometric. It is a metric only after quotienting by zero-distance feature collisions, or after proving that the declared channel family separates points.

Proof. Identity, inverse, and cocycle laws give reflexivity, symmetry, and transitivity. The transport compatibility of local features is exactly the universal-property condition for descent through the quotient. The weighted product distance is then independent of the representative. Its triangle inequality is Minkowski’s inequality applied to the channel metrics. The only possible failure of identity of indiscernibles is equality of all declared feature values, which is removed by quotienting feature-collision classes or by a joint-separation proof. ◻

Certificate boundary.

Pairwise available-channel comparison is not a metric policy: different pairs can share different channels and violate the triangle inequality. A neutral-geometry run must therefore use complete cases, a fixed missing symbol whose mask is quotient-visible, or train-only imputation labelled as an imputed-representation metric. Presentation invariance requires a bijection of \(Q_{\mathrm{vis}}\) and channel isometries, so gauge changes, port relabelings, observer order, repair schedule, and shard partition changes are checked on distance matrices, not on displayed coordinates. Refinement requires a cofinally vanishing tail modulus for the finite-stage distances. Euclidean claims require the double-centered Gram test \[ B=-\frac12H(D^{\circ2})H\succeq0 \] and noisy runs report negative spectral mass, rank/effective rank, held-out stress, and positive/negative controls. Statistical certificates split independent generative batches before preprocessing; chart alignment, scaling, imputation, weights, graph construction, dimension selection, and thresholds are train/validation objects. Any shared shard batch, seed, boundary condition, trajectory family, duplicate, descendant, or repeated test-set inspection blocks the held-out theorem. This section certifies a common quotient metric or pseudometric only; physical Riemannian or Lorentzian spacetime identification belongs to the separate modular/geometric branch.

Noisy Fair-Block Approximate Consensus

The exact consensus theorem supplies the quotient normal-form target. A noisy implementation needs one more quantitative certificate: complete fair blocks must contract expected distance to that target. This section records the conditional bridge from local noisy repair to long-run observer-facing approximate consensus.

Theorem 84 (Global noisy approximate consensus under fair-block contraction). Let \((Q,d_Q)\) be the observer-facing quotient state space of a fixed exported OPH patch federation, and let \(\mathcal N\subset Q\) be the exact quotient normal-form set supplied by the finite repair theorem on that quotient. Define \[ D(q):=d_Q(q,\mathcal N)=\inf_{n\in\mathcal N}d_Q(q,n). \] Let \(q_{t+1}=\widetilde T_{i_t,t}(q_t)\) be a noisy asynchronous repair process adapted to a filtration \((\mathcal F_t)_t\). Assume:

  1. Exact quotient target. The ideal repair relation on \(Q\) has the exact OPH normal-form package: finite exact descent, the semantic-complete transactional local-diamond theorem with its concrete premise receipt, and repair completeness, so every fixed initial quotient state has a schedule-independent exact normal form in \(\mathcal N\).

  2. Fair asynchronous blocks. There are stopping times \[ 0=\tau_0<\tau_1<\tau_2<\cdots \] such that each interval \([\tau_m,\tau_{m+1})\) contains enough local repairs to expose and act on every active mismatch class required by the exact transaction/confluence and repair-completeness certificate, with uniformly bounded length \(\tau_{m+1}-\tau_m\le L\). Write the noisy block map as \[ \widetilde B_m := \widetilde T_{i_{\tau_{m+1}-1},\,\tau_{m+1}-1} \circ\cdots\circ \widetilde T_{i_{\tau_m},\,\tau_m}. \]

  3. Uniform block contraction toward normal form. There are constants \(0<\lambda<1\) and \(\varepsilon\ge0\) such that, for every block \(m\) and every reachable quotient state \(q\) at time \(\tau_m\), \[ \mathbb E\!\left[ D\!\left(\widetilde B_m(q)\right) \mid \mathcal F_{\tau_m} \right] \le \lambda D(q)+\varepsilon. \]

  4. Controlled within-block excursions. There are constants \(A\ge1\) and \(\beta\ge0\) such that, for every \(t\in[\tau_m,\tau_{m+1})\), \[ \mathbb E\!\left[ D(q_t)\mid \mathcal F_{\tau_m} \right] \le A\,D(q_{\tau_m})+\beta. \]

Then, at fair-block times, \[ \mathbb E[D(q_{\tau_m})] \le \lambda^mD(q_0) + \frac{1-\lambda^m}{1-\lambda}\,\varepsilon, \] and hence \[ \limsup_{m\to\infty}\mathbb E[D(q_{\tau_m})] \le \frac{\varepsilon}{1-\lambda}. \] At all intermediate asynchronous times, \[ \limsup_{t\to\infty}\mathbb E[D(q_t)] \le A\,\frac{\varepsilon}{1-\lambda}+\beta. \] Thus the noisy asynchronous OPH repair process converges in expectation to a controlled tube around the exact quotient normal-form set. If \(\varepsilon=\beta=0\), then \(D(q_t)\to0\) in \(L^1\), hence also in probability, along the full asynchronous run.

Proof. Let \(D_m:=D(q_{\tau_m})\). Assumption (G3), applied to the realized state \(q_{\tau_m}\), gives \[ \mathbb E[D_{m+1}\mid \mathcal F_{\tau_m}] \le \lambda D_m+\varepsilon. \] Taking expectations, \[ \mathbb E[D_{m+1}] \le \lambda\,\mathbb E[D_m]+\varepsilon. \] Iterating the scalar recursion gives \[ \mathbb E[D_m] \le \lambda^mD(q_0) + \varepsilon\sum_{r=0}^{m-1}\lambda^r \mathrel{=} \lambda^mD(q_0) + \frac{1-\lambda^m}{1-\lambda}\varepsilon. \] Taking \(m\to\infty\) yields the fair-block limsup bound. For \(t\in[\tau_m,\tau_{m+1})\), Assumption (G4) gives \[ \mathbb E[D(q_t)] \le A\,\mathbb E[D(q_{\tau_m})]+\beta. \] Substitution of the fair-block estimate and then taking the limsup over all intermediate times gives \[ \limsup_{t\to\infty}\mathbb E[D(q_t)] \le A\,\frac{\varepsilon}{1-\lambda}+\beta. \] If \(\varepsilon=\beta=0\), then \(\mathbb E[D(q_{\tau_m})]\le\lambda^mD(q_0)\to0\). Since \(D\ge0\), convergence in expectation to zero implies convergence in probability at block times. Assumption (G4) then gives \(\mathbb E[D(q_t)]\le A\,\mathbb E[D(q_{\tau_m})]\) inside each block, so the same \(L^1\) and probability convergence holds along the full asynchronous run. ◻

Corollary 85 (Approximate observer-facing schedule independence). Let \(M:Q\to Y\) be an observer-facing readout into a metric space \((Y,d_Y)\), and suppose \(M\) is \(L_M\)-Lipschitz. Fix an exact sector \(\zeta\) whose exact normal-form set is the singleton \(\mathcal N_\zeta=\{n_\zeta\}\), and apply Theorem 84 on that sector, so that \(D(q)=d_Q(q,n_\zeta)\). Then \[ \limsup_{t\to\infty} \mathbb E\!\left[ d_Y(M(q_t),M(n_\zeta)) \right] \le L_M\left(A\,\frac{\varepsilon}{1-\lambda}+\beta\right). \] For two noisy asynchronous schedules \(q_t\) and \(q'_t\) started in the same exact singleton sector and satisfying the same certificate, \[ \limsup_{t\to\infty} \mathbb E\!\left[ d_Y(M(q_t),M(q'_t)) \right] \le 2L_M\left(A\,\frac{\varepsilon}{1-\lambda}+\beta\right). \]

Proof. The Lipschitz condition gives \[ d_Y(M(q_t),M(n_\zeta)) \le L_M d_Q(q_t,n_\zeta) \mathrel{=} L_M D(q_t). \] The first bound follows from Theorem 84. The two-schedule bound follows from the triangle inequality through \(M(n_\zeta)\) and applying the first estimate to both schedules. ◻

Corollary 86 (High-probability noisy consensus tube). Assume the block-distance process also admits the pathwise decomposition \[ D_{m+1} \le \lambda D_m+\varepsilon+\xi_{m+1}, \qquad \mathbb E[\xi_{m+1}\mid\mathcal F_{\tau_m}]=0, \qquad |\xi_{m+1}|\le b \] almost surely. Then, for every \(a>0\), \[ \Pr\!\left[ D_m> \lambda^mD_0 + \frac{1-\lambda^m}{1-\lambda}\varepsilon + a \right] \le \exp\!\left( -\frac{a^2(1-\lambda^2)}{2b^2} \right). \]

Proof. Unrolling the recursion gives \[ D_m \le \lambda^mD_0 + \frac{1-\lambda^m}{1-\lambda}\varepsilon + \sum_{r=1}^{m}\lambda^{m-r}\xi_r. \] The final term is a weighted martingale sum with increments bounded by \(|\lambda^{m-r}\xi_r|\le\lambda^{m-r}b\). Azuma–Hoeffding gives \[ \Pr\!\left[ \sum_{r=1}^{m}\lambda^{m-r}\xi_r>a \right] \le \exp\!\left( -\frac{a^2}{2\sum_{r=1}^{m}\lambda^{2(m-r)}b^2} \right). \] Since \(\sum_{r=1}^{m}\lambda^{2(m-r)}\le(1-\lambda^2)^{-1}\), substitution yields the claimed bound. ◻

Proposition 87 (Finite fair-block contraction certificate). Let \(Q\) be finite, let \(\mathfrak B_{\mathrm{fair}}\) be a finite list of noisy fair-block types, and let \(K_B(q,q')\) be the Markov kernel induced by block type \(B\). If there are constants \(0<\lambda<1\) and \(\varepsilon\ge0\) such that \[ \sum_{q'\in Q}K_B(q,q')D(q') \le \lambda D(q)+\varepsilon \qquad \forall q\in Q,\quad \forall B\in\mathfrak B_{\mathrm{fair}}, \] then Assumption (G3) of Theorem 84 holds for any run whose fair blocks are drawn from \(\mathfrak B_{\mathrm{fair}}\).

Proof. Conditioning on the current quotient state \(q\) and the realized fair-block type \(B\), the conditional expectation of \(D\) after the block is exactly \(\sum_{q'}K_B(q,q')D(q')\). The displayed inequality is therefore Assumption (G3), uniformly over all reachable states and fair-block types. ◻

Finite audit route and constants.

For a finite exported packet net, Proposition 87 gives the practical certificate path: \[ \begin{gathered} \text{finite quotient }Q \Rightarrow \text{exact normal forms }\mathcal N \Rightarrow \text{distance table }D(q)\\ \Rightarrow \text{noisy fair-block kernels }K_B \Rightarrow (\lambda,\varepsilon)\text{ certificate}. \end{gathered} \] Here \(\mathcal N\) is the exact quotient normal-form set, \(D(q)\) is observer-facing residual distance to that set, \(\lambda\) is the net contraction produced by one completed fair block, \(\varepsilon\) is the per-block irreducible local recovery / record / readout / calibration / environmental noise, \(A\) bounds transient within-block expansion, \(\beta\) is the within-block noise floor, and \(L\) is the fairness horizon before all required active mismatch classes are serviced. In quantum/collar implementations, \(\varepsilon\) may absorb Petz-domain truncation, Fawzi–Renner recovery error, approximate central-record error, detector/readout noise, and coarse-graining defect.

Claim boundary.

Theorem 84 is a conditional global noisy-consensus theorem. It does not follow from the exact finite repair theorem alone. The exact OPH theorem supplies the quotient normal-form target \(\mathcal N\); the noisy theorem requires a separate fair-block contraction certificate \((\lambda,\varepsilon,A,\beta,L)\) for the chosen implementation. Without that certificate, OPH retains exact fixed-cutoff convergence and the collar-local splice and record-stability estimates above. With that certificate, arbitrarily long asynchronous noisy repair sequences converge to a controlled observer-facing tube around the exact quotient normal-form set.

Law-Space Selection and Observer Emergence

This section studies a simple meta-selection model on law space. The aim is to formalize one criterion for favoring schedule-stable, observer-supporting, and simple laws; the replicator dynamics below is part of the model, not a claim about literal cosmological dynamics.

We begin by defining what it means for a law to support observers. An observer is treated operationally as a persistent predictive module: a subgraph that maintains a stable record algebra and uses its output law to predict its boundary’s future behavior.

Definition 88 (Schedule stability). Fix distributions \(\mu\) over initial conditions and \(\nu\) over asynchronous schedules, and a gauge-invariant observable \(M\). For a law \(\lambda\), define \[ \mathcal{R}_M(\lambda) := \Pr_{s\sim\mu,\;\sigma,\tau\sim\nu} \!\left[ M\bigl(\operatorname{nf}^{\sigma}_\lambda(s)\bigr) \mathrel{=} M\bigl(\operatorname{nf}^{\tau}_\lambda(s)\bigr) \right]. \] If Theorem 29 holds for \(\lambda\), then \(\mathcal{R}_M(\lambda)=1\).

Definition 89 (Observer yield). Let \(X_t^\lambda\) denote the stationary process obtained by repeated local perturbation plus reconciliation under law \(\lambda\). For each subgraph \(U\subseteq V\), let \(\mathcal Z_U^{\mathrm{rec}}(t)\) be the declared exact record algebra on its observer-accessible surface, or the reference exact algebra when only an approximate record presentation is available, and let \(Y_U(t)\) be the corresponding finite outcome variable induced by that record algebra. Then \(U\) is \((\eta,\varepsilon,h)\)-observer-like if it is record-stable: \[ d_{\mathrm{TV}}\!\bigl(\operatorname{Law}(Y_U(t+h)),\operatorname{Law}(Y_U(t))\bigr)\le \eta, \] and predictive: \[ I\bigl(Y_U(t);\; X_{\partial U,\,t+1:t+h}^\lambda\bigr)\ge\varepsilon. \] Define \[ \mathcal{O}_{\eta,\varepsilon,h}(\lambda) := \mathbb{E}\!\left[ \#\left\{ U\subseteq V: U \text{ is } (\eta,\varepsilon,h)\text{-observer-like} \right\} \right]. \]

Definition 90 (Law fitness). Let \(K(\lambda)\) be a description-length penalty. Define \[ f(\lambda) = \alpha\,\mathcal{R}_M(\lambda) + \beta\,\mathcal{O}_{\eta,\varepsilon,h}(\lambda) - \gamma\,K(\lambda), \] with \(\alpha,\beta,\gamma>0\).

Theorem 91 (Replicator monotonicity on law space). Let \(\Lambda=\{\lambda_1,\dots,\lambda_m\}\) be candidate laws with population weights \(x_i(t)\) under replicator dynamics: \[ \dot{x}_i = x_i(f_i - \bar{f}), \qquad f_i := f(\lambda_i), \qquad \bar{f} := \sum_{j=1}^m x_j f_j. \] Then \[ \frac{d}{dt}\bar{f} = \operatorname{Var}_x(f) \ge 0. \] Mean fitness is nondecreasing, and strictly increasing unless all extant laws have the same fitness.

Proof. Direct computation: \[ \frac{d}{dt}\bar{f} \mathrel{=} \sum_i \dot{x}_i f_i \mathrel{=} \sum_i x_i(f_i - \bar{f})f_i \mathrel{=} \sum_i x_i f_i^2 - \bar{f}^2 \mathrel{=} \operatorname{Var}_x(f) \ge 0. \] Equality iff all \(f_i\) on the support of \(x\) are equal. ◻

This theorem records the monotonicity property of the meta-selection model.

Connection to Observer-Patch Holography

The formalism above is the computational skeleton of Observer-Patch Holography (OPH). The observer patches carry von Neumann algebras on support-visible holographic cuts. In symmetric regulator charts those cuts may be represented by patches on a screen \(S^2\). The fixed-cutoff microphysics carrier is a federated patch system with echosahedral local interfaces. The \(S^2\) chart supplies cap and collar geometry, and in the companion relativity branch its conformal group supplies the Lorentz bridge. The carrier supplies finite ports, records, and repair interfaces. The overlap projections are restrictions to shared subalgebras, and the consistency condition is algebraic state agreement on overlaps.

The local carrier boundary, finite federation screen, and support \(S^2\) are different typed objects. Identical local Icosahedral carriers can be routed into federation nerves of different topology. A spherical physical branch therefore requires the microphysics paper’s carrier-to-support bridge: full interface-algebra maps, higher-overlap coherence, a quotient-visible spherical nerve, and refinement-natural support data. The consensus theorem neither supplies nor replaces that bridge.

The bridge to physics works as follows in the broader companion corpus:

  • The patch net becomes a net of support-visible subregion algebras; \(S^2\) is the standard observer-facing support chart, not a required literal material shell. Its quotient-visible topology and conformal data are physical on the spherical branch even though hidden carrier coordinates are not.

  • Overlap Consistency, one of the canonical framework axioms, is the algebraic version of Definition 1.

  • The recoverability clause of the canonical Recoverable Generalized Entropy axiom provides controlled collar recovery data. The exact collar factorization \(\rho_{ABD} = \bigoplus_\alpha p_\alpha\,\rho^{(\alpha)}_{Ab_L^\alpha}\otimes\rho^{(\alpha)}_{b_R^\alpha D}\) is used only at exact Markovity together with the Markov-split alignment of the HJPW factors with the preselected edge split (the compact paper’s alignment hypothesis; exact Markovity alone yields the normal form only over a state-dependent split), or along the fixed-collar replacement limit with EC-aligned comparison states, while the declared Petz/Fawzi–Renner recovery channels supply recovered comparison states from which the local repair moves are built (see Appendix 15 and Definition 105).

  • Gauge symmetry as implementation hiding (Theorem 37) becomes the fixed-cutoff edge-sector seed package. On the companion compact paper’s branch carrying the explicit compact-gauge refinement receipt, coherent surjective pullback functors and compatible forgetful fibers reconstruct a compact group from the tensor-generated combined-zero-obstruction sectors. Here zero obstruction means central or higher-associator strictifiability together with at least one allowed strict \(1\)-cocycle representative having trivial represented holonomy. This supplies receipt-conditional transport across cutoffs and classification. The cofinal witness uses the same receipt, and the Minimal Admissible Realization rule (MAR) plus the explicit one-Higgs matter packet conditionally selects the Standard Model quotient \(\mathrm{SU}(3)\times\mathrm{SU}(2)\times\mathrm{U}(1)/\mathbb{Z}_6\), the exact hypercharge lattice, \(N_c=3\), and the economy minimum \(N_g=3\) inside the window \(3\le N_g\le5\). This does not attach the canonical rank-three screen band to three physical families; the complex rank-45 attachment and complement-complete refinement receipts remain separate.

  • On the declared support-visible compact-gauge branch, the companion compact paper obtains the four-dimensional Euclidean Yang–Mills form from compact-gauge holonomy data and the local MaxEnt/Gibbs continuum limit only with the branch’s renormalized four-dimensional identification receipt. The compact paper separately proves projective weak-* / GNS extraction from its finite cylinder system. On a finite support quotient, weighted resampling inside observation fibers is the orthogonal conditional-expectation projector. A concrete active repair kernel has that status only when its independently extracted transition matrix satisfies the support, equal-fiber-row, and weighted detailed-balance receipt of Ref. ; constructing the tested matrix from the target projector formula is not a verification. Identification with Euclidean transfer, vacuum persistence, OS reconstruction, noncollapse, and passage of the uniform repair gap require their separately named finite and continuum receipts. On that certified branch the Yang–Mills gap equals the repair gap; coherent cylinder extraction alone does not make that identification or supply a Clay-admissible theory.

  • The coarse-graining compatibility theorem (Theorem 66) is the link between the finite reconciliation protocol and the refinement/RG language used by the OPH branches: the macroscopic law space is stable when the selected coarse-graining channel shadows the normal-form and obstruction maps with controlled defects.

  • Stable defects (Corollary 34) become the topologically protected excitations identified with particles on the declared branch.

  • The record-algebra theorem (Theorem 69) provides the formal basis for the fixed-cutoff observation layer, where records are carried by central or quantitatively stable approximately commuting projectors in overlap centers.

The companion manuscripts develop a derived gravity branch from entanglement equilibrium and modular geometry, the SM gauge-group and count closure from edge-sector reconstruction plus the realized MAR branch, a conditional support-visible compact-gauge Yang–Mills form and repair-gap theorem under the separately named continuum-identification, transfer, OS/noncollapse, and uniform-gap receipts, and a controlled large-\(N_{\mathrm{edge}}\) worldsheet effective-description branch above the heat-kernel edge-sector identity. The cosmological capacity branch defines direct readback by the correctable code of reachable public records, \(M_0(q)=\alpha(G_q)\). A source-derived fixed-cutoff simulator packet at \(D=24\) scalarizes its complete declared terminal fiber and supplies reversible extension/refinement receipts inside its declared source category. When the whole capacity-indexed terminal fiber scalarizes, \(M_0(\mathfrak U_N)=\widehat F_{r,0}(e^N)\) and the universe-level equation is \(N=\log M_0(\mathfrak U_N)\); its stable finite form is \(\mathfrak F_{r,0}(D_\star)=\{D_\star\}\). Physical-universe attachment, the capacity-indexed family, unique finite-size slack zero, horizon–record identification, and common screen/electroweak load-carrier identification are kept explicitly separate from that recovered-core claim set.

This paper provides the finite patch-net foundation for the broader companion corpus.

Discussion and Scope Boundaries

The fixed-point consensus spine of OPH consists of a total, idempotent, boundary-preserving quotient repair operator on the declared finite branch; schedule-independent normal forms from fixed initial quotient states; boundary-conditioned uniqueness when a preserved boundary/sector fiber has a unique consistent extension; a finite layered carrier proving \(H_B\wedge H_{\mathrm{fib}}\); nontrivial functional selected-fiber branch elimination; holonomy obstructions; gauge-quotient invariance, separated cofinal refinement-limit consensus classes, controlled coarse-graining compatibility, the fixed-cutoff operator-record theorem, distributed one-universe realization for admissible worker presentations of a single global carrier, and conditional noisy fair-block convergence once a separate contraction certificate is supplied. It also proves the full repair-completeness, Petz-domain, and quotient-compatibility package on the rooted-tree packet-net domain of Theorem 20, and gives a clean law-selection meta-model. The relativity chain and the realized Standard Model structural chain are the recovered core. The capacity relation is a separate implemented branch with universe-level equation \(N=\log M_0(\mathfrak U_N)\), stable whole-fiber target \(\mathfrak F_{r,0}(D_\star)=\{D_\star\}\), and an independent EW/Higgs comparison bridge. Downstream phenomenology requires additional assumptions beyond the consensus results proved here.

The unified carrier hypothesis assigns this paper one exact role. Consensus turns a routed, self-reading carrier federation into a public quotient normal form. The support-screen producer may then read geometry from that normal form, and the physical-current producer may read compact charge response from it. Neither readout is created by confluence. Their physical composition requires one source manifest and refinement tower so that geometry, current, records, and clocks refer to the same system rather than to isomorphic fixtures assembled after the fact.

Complexity boundary.

On a fixed finite patch net, the accepted reconciliation dynamics is a finite-state asynchronous rewrite system on \(\Sigma\). Under Theorem 29, every accepted repair run has at most the number of distinct reachable \(\mu\)-values below its start value minus one, because each accepted transaction strictly lowers the declared exact measure. On the scalar \(\Phi\)-branch this specializes to the \(|\Phi(\Sigma)|-1\le |\Sigma|-1\) bound. Exact normal-form computation is therefore decidable by direct iteration of accepted aggregate transactions. This step bound is a termination statement; the schedule-independent answer depends on the atomic conflict-component local diamond and repair-completeness clauses of Theorem 29. What this paper does not prove is a uniform polynomial-time bound, a sharper complexity-class placement for families of growing patch nets, or any hardness lower bound.

Approximate-stability boundary.

The theorem-grade consensus statement is exact on the declared fixed-cutoff branch. Approximate control begins collar-locally: Theorem 92 gives the exact-Markov modulus \(\delta^{\mathrm M}_{A:B:D}(\varepsilon)\to0\) on one fixed finite-dimensional collar model and the one-shot recovery comparison bound \(2\sqrt{1-e^{-\varepsilon}}\le 2\sqrt{\varepsilon}\), while Theorem 69 gives the \((\varepsilon,\delta_{\mathrm{rec}})\) repeated-read stability bound for approximate record projectors. The long-run noisy statement is conditional: Theorem 84 upgrades those local noisy controls to a global expected tube around the exact quotient normal-form set only after a fair-block contraction certificate \((\lambda,\varepsilon,A,\beta,L)\) is supplied for the chosen implementation. It does not follow from finite descent or fairness alone, and it gives a unique approximate readout only inside singleton boundary/sector fibers. Ref.  supplies a complementary receipt-only endpoint estimate from a residual error-bound modulus and an inverse-observation modulus, together with refinement comparison bounds. Those results do not manufacture the fair-block contraction used here and do not imply pathwise long-run confinement under persistent noise.

Expressive-power boundary.

The law-selection model of Theorem 91 is a finite-candidate monotonicity result. For each fixed patch net the theorem package proves a finite-state exact reconciliation mechanism. A universality claim would require an explicit uniform family of patch nets and repair laws that simulates arbitrary circuits or machines with stated encoding overhead and stability under asynchronous schedules. No such theorem is supplied here.

With those boundaries explicit, the consensus-paper boundaries and companion interfaces are:

  1. Sharper RG-shadowing estimates. Theorem 66 closes the abstract reconciliation/coarse-graining square once its normal-form and obstruction defects are supplied. The quantitative task is to derive model-specific or uniform bounds for \(\varepsilon^n_{sr}\) and \(\varepsilon^h_{sr}\) from concrete OPH coarse-graining channels and recovery decoders.

  2. Defect classification and refinement-limit transportability. The fixed-cutoff hierarchy extends from abelian frustrations to crossed-module classes \(q\in \check H^2(N,H\to G)\). The continuation task is to connect those higher-gauge defect sectors to the refinement-stable transportable sector category used in the broader compact-gauge reconstruction lane.

  3. Observable-level confluence beyond the declared fixed-cutoff physical algebra. Theorem 52 closes the fixed-cutoff quantum-lift statement when microscopic representatives differ by gauge relabelings globally or by sector/higher-gauge relabelings on the same declared quotient-local glued state. The continuation question is whether an analogous observable theorem survives on broader refinement-stable branches where the union-collar compatibility is only approximate or where the physical observable algebra itself changes under refinement.

  4. Distributed implementation certificates. Theorem 78 proves invariance for a worker presentation only after the implementation supplies one global carrier, authoritative ownership, cut interfaces, projection-preserving events, rollback roots, and final monolithic normal-form/readout certificates. Shard-local seeds, missing cut artifacts, stale manifests, synthetic seam trajectories, or worker-id histories do not certify a one-universe realization.

  5. Global approximate-consensus stability. Theorem 92 and Theorem 69 supply the collar-local perturbative controls carried by this paper. The rooted-tree packet domain proves the exact finite repair package on one nontrivial exported domain. Theorem 84 closes the long-run noisy branch only after a fair-block contraction certificate is supplied. No automatic theorem is supplied showing that arbitrary approximate recovery moves on arbitrary packet-closed exported overlap nets are repair-complete, preserve transactional validation, satisfy an independent quotient local diamond, satisfy the support/CPTP clause on every Petz branch used there, and meet that fair-block contraction certificate.

  6. Expressive power / universality. The paper supplies no uniform simulation construction, so universality is outside the theorem-grade output.

  7. Applied material, plasma, and device branches. The fixed-point theorem classifies quotient normal forms and obstructions once a physical quotient and repair law are declared. It does not select a Hall sector, material order, confinement regime, nuclear yield, or hardware performance number without a quotient-intrinsic ensemble, source action, repair ledger, and evidence receipts for that branch.

  8. Interface to the companion gravity/gauge stack. The companion compact paper derives the gravity chain through the support-visible BW scaling theorem on the geometric cap subnet. This consensus paper supplies the finite-state and refinement-consensus spine used by that bridge. The finite-quotient baryogenesis theorem uses that spine to define an oriented repair current, while also proving that quotient settlement and an oriented register select no CP sign. The natural \(\mathbb Z_6\) gauge/deck attachment has zero electroweak anomaly coefficient. A nonzero baryogenesis branch, dark-sector proposals, spectroscopy, and string/worldsheet topics require their own declared physical inputs beyond what this paper proves.

The last item is an interface statement instead of an extra consensus premise. The fixed-point theorems proved here stand on their stated finite and refinement-consensus hypotheses, while companion gravity, gauge, and continuation sectors add their own theorem surfaces and declared inputs.

Assumption-Dependent BFT and QECC Extensions

The consensus formalism of OPH has natural analogies to classical and quantum distributed Byzantine agreement. Observer patches correspond to protocol nodes, overlap repair corresponds to a quorum vote, and the repair fixed-point corresponds to a consensus state. Under explicit structural assumptions (partial synchrony, one-vote-per-view, certificate semantics, authentication, and quorum overlap: either the classical exact sizing \(n=3f+1,q=2f+1\) or a general threshold \(q\) with \(2q\ge n+f+1\)), a QBFT-style interpretation of OPH repair satisfies safety and liveness (Appendix 17, Theorem 104). On the fixed-cutoff collar branch used here, the repair map is written in exact-splice / Petz form; the assumption-dependent item is the CPTP property on all inputs, which requires either full-rank \(\mathcal{N}(\sigma)\) or an explicit domain restriction, and trace-preserving completion is not automatic when \(\mathcal{N}(\sigma)\) has a non-trivial kernel (Proposition 107). A quantum error-correcting interpretation is possible only after a genuine code subspace, logical dictionary, error family, and recovery map are supplied. The graph-min-cut equality for distance is not a property of a bare overlap graph: the same graph can realize distance \(1\) or distance \(|V|\) under different interface maps (Theorem 112). Distance/min-cut statements require the topological-code certificate of Definition 113 and Theorem 114; resilience requires the Knill–Laflamme certificate of Theorem 116. All of these extensions are assumption-dependent or conjectural and are not part of the core theorem package of Paper 4.

Desired statement Required certificate
Overlap network is a code finite constraint-code data of Proposition 3
Local repair is a physical map \(\operatorname{locRep}_\lambda:Q\to Q\) on the finite quotient presentation, with boundary preservation and exact descent
Global repair is a physical normal-form map \(\operatorname{Rep}_\lambda=\overline{\operatorname{nf}}_\lambda:Q\to Q\), total, idempotent, schedule-independent, and landing in \(C_Q\)
Repair respects gauge quotient-valued \(\operatorname{Rep}^{\Sigma}_\lambda=\operatorname{Rep}_\lambda\circ q\), hence invariant under \(\Gamma\)
Boundary reconstruction layered finite carrier with \(H_B\wedge H_{\mathrm{fib}}\) and \(\operatorname{Rep}_\lambda(x)=E(B(x))\) on admissible fibers
Repair converges finite exact descent; confluence additionally needs semantic-complete transactions, coherent canonical aggregate gluing, and repair completeness, with a concrete receipt for the theorem premises and peaks
Distance equals min-cut topological-code certificate with homological logicals and matching systole/min-cut geometry
Corrects \(t\) corrupted carriers code projector, error family, Knill–Laflamme condition, and certified \(t<d/2\) distance bound
Exponential convergence declared transfer/channel operator with stationary projection and spectral gap
Long-run noisy approximate consensus fair-block contraction certificate \((\lambda,\varepsilon,A,\beta,L)\) for distance to the exact quotient normal-form set
Wall-clock BFT liveness partial synchrony, quorum certificates, authentication, and quorum-overlap sizing: \(n=3f+1,q=2f+1\) or \(2q\ge n+f+1\)
Hardware search work reduction exact-verifier candidate-enrichment factor measured under controls

Quantum/Algebraic Lift: Markov-Collar Splice Theorem

This appendix records the algebraic splice statement relating the finite patch-net model to the OPH collar formalism.

For this collar lemma, write the support-local algebra-state-record reduct of an observer patch as \[ O_{\mathrm{red}}=(P,\mathcal{A}(P),\rho,R), \] where \(P\) is the support-screen patch, \(\mathcal{A}(P)\) the local von Neumann algebra, \(\rho\) the local state, and \(R\) the record algebra. The full operational observer also carries overlap interface algebras and restriction maps, allowed update and repair instruments, and checkpoint data used for continuation.

Theorem 92 (Markov-collar splice theorem, exact and controlled). Suppose a collar tripartition \(A\)-\(B\)-\(D\) has the EC-aligned exact Markov decomposition \[ \rho_{ABD} \mathrel{=} \bigoplus_{\alpha} p_\alpha\, \rho^{(\alpha)}_{A b_L^\alpha} \otimes \rho^{(\alpha)}_{b_R^\alpha D} \] over the preselected edge factors. This displayed form is the hypothesis: by the compact paper’s Markov-split alignment analysis it is strictly stronger than \(I(A:D\mid B)_\rho=0\), which by HJPW yields such a factorization only over a state-dependent split of \(B\). Let \(\sigma_{b_R^\alpha D'}^{(\alpha)}\) be any family of normalized environment states compatible with the same right-boundary sectors. Define \[ \rho'_{AB D'} \mathrel{=} \bigoplus_{\alpha} p_\alpha\, \rho^{(\alpha)}_{A b_L^\alpha} \otimes \sigma_{b_R^\alpha D'}^{(\alpha)}. \] Then for every observable \(X\) supported on \(A\cup b_L\), \[ \operatorname{Tr}(X\rho'_{AB D'}) \mathrel{=} \operatorname{Tr}(X\rho_{ABD}). \] Fix one finite-dimensional collar model and let \[ \mathfrak M_{A:B:D} := \left\{ \tau_{ABD}: I(A:D\mid B)_\tau=0 \right\}, \] with exact-Markov distance modulus \[ \delta^{\mathrm M}_{A:B:D}(\varepsilon) := \sup\left\{ \inf_{\tau\in\mathfrak M_{A:B:D}}\|\omega-\tau\|_1: I(A:D\mid B)_\omega\le\varepsilon \right\}. \] Then \[ \delta^{\mathrm M}_{A:B:D}(\varepsilon)\to0 \qquad (\varepsilon\downarrow0). \] On a fixed faithful collar class with lower floor \(\lambda_\ast>0\), this qualitative modulus can be sharpened to a collar-local rate \[ \delta^{\mathrm M,\lambda_\ast}_{A:B:D}(\varepsilon) \le C_{A:B:D,\lambda_\ast}\,\varepsilon^{\theta_{A:B:D,\lambda_\ast}}, \] by the compact real-analytic Lojasiewicz inequality applied to \(I(A:D\mid B)\). The constants depend on the fixed collar model and floor; they are not a dimension-free stability theorem for arbitrary tripartite systems. Hence if \(I(A:D\mid B)_\omega\le \varepsilon\) and \(\widetilde\omega_\varepsilon\in\mathfrak M_{A:B:D}\) is chosen so that \[ \|\omega-\widetilde\omega_\varepsilon\|_1 \le \delta^{\mathrm M}_{A:B:D}(\varepsilon), \] the corresponding exact splice \(\widetilde\omega'_\varepsilon\) satisfies \[ \left| \operatorname{Tr}(X\omega)-\operatorname{Tr}(X\widetilde\omega'_\varepsilon) \right| \le \|X\|_\infty\, \delta^{\mathrm M}_{A:B:D}(\varepsilon) \] for every observable \(X\) supported on \(A\cup b_L\).

Independently, if \(I(A:D\mid B)_\omega\le \varepsilon\), then there exists a recovery map \(\mathcal R_{B\to BD}\) such that \[ \left\| \omega_{ABD} \text{-} (\mathrm{id}_A\otimes \mathcal R_{B\to BD})(\omega_{AB}) \right\|_1 \le 2\sqrt{1-e^{-\varepsilon}} \le 2\sqrt{\varepsilon}. \]

Proof. The exact splice statement is the usual blockwise factorization argument: \[ \operatorname{Tr}(X\rho'_{AB D'}) \mathrel{=} \sum_\alpha p_\alpha\, \operatorname{Tr}\!\left( X\, \rho^{(\alpha)}_{A b_L^\alpha} \right) \operatorname{Tr}\!\left(\sigma_{b_R^\alpha D'}^{(\alpha)}\right). \] Each right factor is normalized, so the value agrees with the same computation for \(\rho_{ABD}\).

For the controlled statement, compactness of the fixed finite-dimensional state space and continuity of conditional mutual information imply \(\delta^{\mathrm M}_{A:B:D}(\varepsilon)\to0\): otherwise one could find a sequence with \(I(A:D\mid B)\to0\) staying a fixed trace distance away from every exact Markov state, contradicting convergence of a subsequence to an exact Markov limit point. The splice identity additionally requires \(\widetilde\omega_\varepsilon\) to be EC-aligned over the preselected edge factors; small conditional mutual information supplies closeness only to the full exact Markov set, so the existence of EC-aligned replacements is carried as an explicit hypothesis on the controlled family (the compact paper’s Markov-split alignment hypothesis). Once such an EC-aligned \(\widetilde\omega_\varepsilon\) is chosen, the exact splice identity for \(\widetilde\omega_\varepsilon\) gives \[ \left| \operatorname{Tr}(X\omega)-\operatorname{Tr}(X\widetilde\omega'_\varepsilon) \right| \mathrel{=} \left| \operatorname{Tr}\!\left[X(\omega-\widetilde\omega_\varepsilon)\right] \right| \le \|X\|_\infty\, \delta^{\mathrm M}_{A:B:D}(\varepsilon). \] The final inequality is the standard Fawzi–Renner recovery bound . ◻

This appendix therefore uses exact splice identities in only two regimes: literal EC-aligned exact Markovity, or a controlled collar family on one fixed finite-dimensional model for which \(\delta^{\mathrm M}_{A:B:D}(\varepsilon)\to0\) and EC-aligned replacements exist. Fawzi–Renner recovery supplies the constructive recovered comparison state; the fixed-collar modulus supplies the exact-Markov comparison. Small one-shot conditional mutual information is not silently upgraded to an exact normal form.

For later dark-sector continuations, the exact finite identity is only an expectation identity. For a faithful finite state \(\rho_{ABD}\), with \(K_X=-\log\rho_X\), \[ \operatorname{Tr}\rho_{ABD}(K_{AB}+K_{BD}-K_B-K_{ABD}) \mathrel{=} I_\rho(A:D\mid B). \] This does not identify raw conditional mutual information with a state-independent local stress source. Near a full-rank exact Markov state \(\sigma\), a perturbation \(\rho(t)=\sigma+tX+O(t^2)\) has \[ \left.\frac{\mathrm d}{\mathrm d t}I_{\rho(t)}(A:D\mid B)\right|_{t=0}=0, \] while a fixed-reference modular-energy variation is generically linear in \(t\). Recovery bounds therefore do not by themselves prove a local stress-source theorem; source-specific coarse graining, collar localization, cover independence, and finite-model proof receipts are separate continuation data.

Fixed-Cutoff Realization, Quotient Repair, and Edge Centers

This appendix carries the fixed-cutoff realization and edge-center items for the consensus paper. They sharpen the quotient-first repair interpretation used throughout the consensus paper and make the collar boundary data explicit at the same finite patch-net level. On the declared fixed-cutoff collar branch, the local repair step is read from exact Markov splice or a declared Petz/Fawzi–Renner recovery move on that same collar data; the recovery move gives a recovered comparison state, while exact splice requires exact Markovity or a controlled fixed-collar replacement modulus. Representative repair maps are only lifts of the resulting quotient-local update.

Quotient Repair and UV Underdetermination

At fixed cutoff, each regulator cell \(x\) carries a finite-dimensional factor \(\mathfrak h_x\), patch algebras are finite type-I algebras, and gauge-as-gluing is realized as a compact boundary redundancy action on cut data. The physical repair law therefore belongs on the overlap-invariant quotient rather than on hidden representatives. If \(q:\Sigma\to\Sigma/\Gamma\) is the quotient by boundary redundancy and \(\overline T_i\) is the physical quotient update, a representative-level map \(T_i\) is only required to be a lift satisfying \[ q\circ T_i=\overline T_i\circ q. \] Hence \[ q(T_i(\gamma\cdot s))=q(T_i(s)) \] for gauge-equivalent inputs. Quotient descent is therefore structural, while strict representative-level covariance is only implementation bookkeeping. The burden is to prove that the accepted recovery-derived local moves satisfy the stated repair-completeness, support-local disjoint-commutation, nested-collar restriction-compatibility, and Petz-domain control clauses on the declared branch. The touched-overlap acceptance contract yields finite Lyapunov descent and derived termination for accepted moves, while the fixed-cutoff gluing package carries the parenthesization-invariant union-collar state used for the local diamond.

Proposition 93 (Ancilla-stable UV underdetermination). Let a fixed-cutoff OPH realization be stabilized by finite ancillary factors \(K_P\) in a fixed product state, with observable patch algebras embedded as \(\mathcal A(P)\otimes \mathbf 1_{K_P}\) and repair dynamics acting trivially on the ancillas. Then observable expectations on the physical subalgebras, overlap data, the local-Gibbs branch, the collar conditional mutual information \(I(A:D\mid B)\), the Fawzi–Renner remainder, the collar Markov modulus, and the quotient normal form are unchanged. Thus the fixed-cutoff theorem package determines the UV branch only modulo such ancillary stabilization together with gauge or implementation hiding, not a unique microscopic presentation.

Proof. Product ancillas leave physical observables unchanged, cancel additively inside conditional mutual information, and are inert under the repair maps. Hence every invariant listed above is unchanged. ◻

Derived Boundary Data and Ordinary EC

Proposition 94 (Derived boundary gluing datum). Choose a finite regulator chart for the patches meeting along a connected cut \(\Sigma\). Because the local overlap algebras are finite-dimensional matrix algebras, any overlap-consistent recharting is an inner automorphism and is implemented by a unitary on the cut Hilbert space. The compact closure of the subgroup generated by these recharting unitaries is a compact boundary redundancy group \(K_\Sigma\). If triple-overlap defects are central, the projective composition law lifts to a compact central extension \(\widehat K_\Sigma\); on the ordinary branch one simply sets \(\widehat K_\Sigma = K_\Sigma\). A genuinely noncentral \(2\)-group defect is the only obstruction to reducing the overlap transition system to an ordinary compact group action.

Theorem 95 (Derived EC decomposition). Under the fixed-cutoff regulator realization above, and on the ordinary or central-defect branch, the collar Hilbert space is \[ \mathcal H_{B_\delta} \mathrel{=} (\tilde{\mathcal H}_{B_L}\otimes \tilde{\mathcal H}_{B_R})^{\widehat K_\Sigma} \cong \bigoplus_{\alpha} \left(\mathcal H_{b_L^\alpha}\otimes \mathcal H_{b_R^\alpha}\right), \] and the center of the collar algebra is generated by the block projectors: \[ Z(\mathcal A(B_\delta)) \mathrel{=} \bigoplus_\alpha \mathbb C\cdot \mathbf 1_\alpha. \] The right half-collar carries the contragredient representation because it sees inverse transport across the same cut.

Remark 96. This is the finite-patch-net origin of the collar center used by the later Markov, record, and observer packages. Exact Markovity is an additional state hypothesis; EC provides the kinematic block structure.

Higher-Gauge Replacement on the Genuinely Noncentral Branch

Proposition 97 (Derived higher-gauge cut datum). On the genuinely noncentral branch, weak overlap gluing on a connected cut \(\Sigma\) is encoded by a compact crossed module \[ \mathbb K_\Sigma=(H_\Sigma\xrightarrow{\partial_\Sigma}G_\Sigma,\triangleright) \] with defect class \[ q_\Sigma\in \check H^2(N_\Sigma,H_\Sigma\to G_\Sigma), \] and compact higher-gauge change system \[ \mathcal T_\Sigma=C^1(N_\Sigma,H_\Sigma)\rtimes C^0(N_\Sigma,G_\Sigma). \]

Theorem 98 (Higher-gauge EC decomposition and defect transport). On the genuinely noncentral branch, \[ \mathcal H_{B_\delta}^{2g} \mathrel{=} (\tilde{\mathcal H}_{B_L}\otimes \tilde{\mathcal H}_{B_R})^{\mathcal T_\Sigma} \cong \bigoplus_\lambda (\mathcal H_{b_L^\lambda}\otimes \mathcal H_{b_R^\lambda}), \] and \[ Z(\mathcal A_{2g}(B_\delta)) \mathrel{=} \bigoplus_\lambda \mathbb C\cdot \mathbf 1_\lambda. \] The full crossed-module orbit \(q_\Sigma\) is also invariant under local rechartings and classifies fixed-cutoff genuinely noncentral gluing data. The higher associator is removable iff \(q_\Sigma\) lies in the image of \[ \check H^1(N_\Sigma,G_\Sigma)\longrightarrow \check H^2(N_\Sigma,H_\Sigma\to G_\Sigma), \qquad [g]\longmapsto[(g,1)]. \] That map need not be injective. Strict endpoint-only ordinary transport additionally requires at least one allowed strict representative with trivial represented loop holonomy.

Corollary 99 (Exact Markov plus split alignment adds the state factorization). On either the ordinary/central branch described in the main consensus theorem or the genuinely noncentral higher-gauge branch, if in addition \[ I_\omega(A_\delta:D_\delta\mid B_\delta)=0 \] and the state satisfies the Markov-split alignment hypothesis (its HJPW decomposition of \(\mathcal H_{B_\delta}\) can be chosen to be the EC decomposition itself; see the main-text Section 2.3 and the compact paper’s alignment definition), or one passes to the explicitly stated idealized recoverability limit that supplies both conditions, then \[ \rho_{A_\delta B_\delta D_\delta} \mathrel{=} \bigoplus_\alpha p_\alpha \left(\rho_{A_\delta b_L^\alpha}\otimes \rho_{b_R^\alpha D_\delta}\right). \] EC therefore gives the kinematic block decomposition, while exact Markovity plus split alignment is the extra state input that gives the EC-aligned HJPW normal form. Exact Markovity alone yields the normal form only over a state-dependent HJPW split, which a Bell-pair example (main text, Section 2.3) shows can be transposed relative to the EC factors.

Proposition 100 (Certified parenthesization-invariant union-collar gluing). Fix a finite union collar \(U\) built from two overlapping local repair collars on the declared fixed-cutoff branch. Assume one of the following payload receipts:

  1. an exact aligned Markov construction, including the HJPW split-alignment condition, whose nested collar recovery maps satisfy the commuting-square and pentagon identities;

  2. a specified canonical recovery construction, such as a fixed Petz/Markov splice, together with those commuting-square and pentagon identities; or

  3. a primitive aggregate state \(\omega_U\) whose restrictions to every constituent and nested collar equal the declared local payloads.

On the ordinary or central-defect branch, assume in addition that changes of representative act through the declared boundary-redundancy action. On the genuinely noncentral branch, assume the corresponding coherence identities hold in the crossed-module change system \(\mathcal T_\Sigma\). Then the physical quotient-local glued state on \(U\) is independent of parenthesization. The finite export \(\mathsf{GLUE\text{-}COHERENCE\text{-}1}\) contains the constituent and union collars, recovery maps or primitive aggregate state, all restriction hashes, commuting squares, pentagon checks, quotient action, and refinement-compatibility fields.

Proof. In cases (i) and (ii), the commuting-square identities identify every two-step restriction and the pentagon identity identifies all iterated parenthesizations. In case (iii), every parenthesization is a restriction of the same primitive state \(\omega_U\). The additional quotient clause removes only the declared boundary representative action or its crossed-module analogue, so all parenthesizations define one quotient-local state. ◻

Remark 101 (Marginals and sectors do not determine the aggregate state). Central sector labels and compatible proper marginals do not imply any of the three payload receipts. The uniform even-parity and odd-parity distributions on three bits have identical one- and two-bit marginals and different tripartite states. The states \[ |\mathrm{GHZ}_{\pm}\rangle \mathrel{=} \frac{|000\rangle\pm|111\rangle}{\sqrt2} \] give the quantum counterpart: all two-party reductions agree while the global states differ. Approximate recoverability therefore carries a coherence defect in addition to its local recovery error.

Corollary 102 (Physical observables are invariant on one quotient-local glued state). Let \(U\) be a finite union collar on the declared fixed-cutoff branch, and let \(\omega_U,\omega'_U\) be two microscopic representatives of the same quotient-local glued state from Proposition 100. Then every physical observable \(X\) on the collar fixed-point / quotient-local algebra has the same expectation in both representatives: \[ \operatorname{Tr}(X\omega_U)=\operatorname{Tr}(X\omega'_U). \] In particular the same holds for the central sector projectors and for any observer-accessible record observable generated from them on that same declared surface.

Proof. On the ordinary or central-defect branch, Proposition 100 says the two representatives differ only by the boundary-redundancy action inside one fixed sector block. The fixed-point collar algebra and its central block projectors are invariant under that action, so their expectation values agree. On the genuinely noncentral branch, the same proposition says the two representatives differ only inside one \(\mathcal T_\Sigma\)-orbit, and the quotient-local physical algebra \(\mathcal A_{\mathrm{phys}}(U)\) of Definition 51 is defined precisely on that orbit space. Therefore the induced physical state and all expectations of physical observables agree there as well. ◻

Assumption-Dependent Distributed-Systems and QECC Extensions of the Consensus Formalism

Support labels.

[Established] Follows from cited prior work or a complete argument given here.

[Assumption-dependent] True under additional assumptions not derived from OPH first principles.

[Conjecture] A plausible open direction, not a settled result.

B.1Theorem 1: QBFT Safety Bound

Definition 103 (QBFT-style protocol). A consensus protocol is QBFT-style in this analysis if it satisfies the following three structural properties. The safety proof of Theorem 104 uses all three; the theorem does not hold for protocols lacking any of them without a compensating change to the argument.

  1. One-vote-per-view. Each nonfaulty node casts at most one vote per view number. A node that has voted in view \(v\) ignores any later request to vote in view \(v\).

  2. Certificate semantics. A decision requires a valid quorum certificate: in the classical exact-size case used below, \(q=2f+1\) distinct, unforgeable, authenticated votes for the same value in the same view. For larger validator sets at fixed fault budget, the quorum threshold must be scaled so that the overlap condition in (A6) remains true.

  3. DLS-style view-change. If no certificate is produced within a timeout, every nonfaulty node increments the view number by one and a new leader is selected by a fixed deterministic rule. At GST, timeouts fire correctly and the view-change terminates in bounded rounds.

The Istanbul BFT / QBFT protocol family satisfies (P1)–(P3) and is the intended instance.

Assumptions A1–A6.

  1. Partial synchrony (DLS). Fixed but initially unknown bounds \(\Delta\) (message delay) and \(\Phi\) (processing rates). Safety holds without extra timing assumptions; liveness holds after the Global Stabilisation Time (GST).

  2. Byzantine fault model. At most \(f\) observers behave arbitrarily; the remaining \(n-f\) are nonfaulty.

  3. Classical exact sizing for this fixed-quorum theorem. \(n = 3f+1\), so that \(q=2f+1\) certificates have a nonfaulty overlap witness. The usual resilience condition \(n\ge 3f+1\) is necessary for the fault model, but when \(n>3f+1\) a fixed \(q=2f+1\) quorum is insufficient for the overlap used in the safety proof; one must either impose (A6) directly or choose a threshold \(q\) with \(2q\ge n+f+1\).

  4. Strong quorum connectivity. Every quorum \(Q\) with \(|Q|=q\) is strongly connected within \(G\): for any \(u,v\in Q\) there is a directed path in \(G\) contained entirely in \(Q\). This is strictly stronger than requiring the overlap graph of quorums to be connected, and is needed to propagate signed votes within a quorum.

  5. Message authentication. All messages carry unforgeable digital signatures.

  6. OPH quorum overlap. Any two quorums \(Q_a, Q_b\) of size \(q\) satisfy \(|Q_a\cap Q_b|\geq f+1\). For \(q=2f+1\) this is guaranteed by the exact sizing \(n=3f+1\) in (A3); for general \(n\) it is the separate threshold condition \(2q\ge n+f+1\), not a consequence of \(n\ge3f+1\) alone.

D. Matscheko’s review of this appendix covers the finite quorum-overlap core and records the same boundary caveat: at fixed \(q=2f+1\), the overlap step is exact-size \(n=3f+1\) logic unless (A6) is imposed separately.

Theorem 104 (QBFT Safety Bound [Same-view case established under A1–A6; cross-view safety conditional on a (P4) locking rule]). Under assumptions (A1)–(A6), any consensus protocol satisfying (P1)–(P3) of Definition 103 and run over the OPH observer graph satisfies:

  1. Same-view safety. No two nonfaulty observers finalise conflicting patch states in the same view.

  2. Liveness. After GST, every nonfaulty observer finalises within \(O(f\cdot\Delta)\) wall-clock time.

  3. Optimality. The bound \(f<n/3\) is tight.

Cross-view boundary.

Clause (i) is stated for same-view finalisation because the argument below covers exactly that case. Cross-view safety in the IBFT/QBFT protocol family uses an additional prepared-certificate locking property, an explicit (P4) hypothesis under which a nonfaulty node votes in a later view only for a value carried by the highest prepared certificate it has received. (P1)–(P3) alone do not exclude finalisation of conflicting values across views; a cross-view extension of this theorem requires (P4) and its accompanying view-change justification argument. On its stated assumptions, this finalisation theorem gives record permanence: no two nonfaulty observers finalise conflicting patch states. Record permanence enters as a consistency requirement on the observer net, not as an added postulate.

Proof sketch. Safety. Suppose \(O_a\) and \(O_b\) finalise \(s_a\neq s_b\) in the same view. By (P2), each required a certificate of \(q\) votes: sets \(Q_a,Q_b\). By (A6), \(|Q_a\cap Q_b|\geq f+1\). In the classical exact-size case this is the inclusion-exclusion calculation \(|Q_a\cap Q_b|\geq(2f+1)+(2f+1)-(3f+1)=f+1\). By (A2), at most \(f\) are Byzantine, so \(Q_a\cap Q_b\) contains a nonfaulty \(O^*\). By (A4), \(O^*\)’s signed vote is path-reachable within both quorums. By (P1), \(O^*\) voted for at most one value. Contradiction.

Liveness and Optimality follow from (Thm. 4.4) and , cited directly.

Note on FLP. Fischer, Lynch, Paterson  is an impossibility result for fully asynchronous systems; it does not bear on achievability under partial synchrony (A1). ◻

B.2Theorem 2: Convergence of the OPH Repair Map

Definition 105 (OPH Repair Map: Petz form). Let \(\sigma\in\mathcal{D}(\mathcal{H})\) be a full-rank reference state and \(\mathcal{N}:\mathcal{B}(\mathcal{H})\to\mathcal{B}(\mathcal{K})\) a quantum channel. The OPH repair map is \[ \mathcal{R}_{\sigma,\mathcal{N}}(\rho) := \sigma^{1/2}\, \mathcal{N}^\dagger\!\bigl( \mathcal{N}(\sigma)^{-1/2}\,\rho\,\mathcal{N}(\sigma)^{-1/2} \bigr) \,\sigma^{1/2}, \] where \(\mathcal{N}^\dagger\) is the adjoint channel and inverses are taken on \(\mathrm{supp}(\mathcal{N}(\sigma))\).

Remark 106 (Petz map vs. trace-distance projection). The closest-point trace-distance projection \(\mathcal{P}_{\mathcal{S}}(\rho):=\arg\min_{\tau\in\mathcal{S}}\tfrac12\|\rho-\tau\|_1\) is a different object from the Petz map: it is defined by a variational problem in trace-norm geometry and is not CPTP in general. The two coincide only in very special cases not automatic in the OPH setting. All subsequent properties refer exclusively to Definition 105.

Proposition 107 (Petz map CPTP: domain-restricted statement [Established, subject to domain restriction]). Let \(\sigma\) have full support on \(\mathcal{H}\).

  1. \(\mathcal{R}_{\sigma,\mathcal{N}}\) is completely positive.

  2. \(\mathcal{R}_{\sigma,\mathcal{N}}\) is trace-preserving on \(\mathrm{supp}(\mathcal{N}(\sigma))\), i.e., on inputs \(\rho\) for which \(\mathcal{N}(\sigma)^{-1/2}\rho\,\mathcal{N}(\sigma)^{-1/2}\) is well-defined.

  3. If additionally \(\mathcal{N}(\sigma)\) has full rank on \(\mathcal{K}\), then \(\mathcal{R}_{\sigma,\mathcal{N}}\) is CPTP on all of \(\mathcal{B}(\mathcal{K})\).

If \(\mathcal{N}(\sigma)\) is not full rank on \(\mathcal{K}\), then either (i) the domain must be restricted to \(\mathrm{supp}(\mathcal{N}(\sigma))\), or (ii) pseudoinverses must replace the inverses (generalised Petz map; cf. ), or (iii) a regularisation \(\mathcal{N}(\sigma)\mapsto\mathcal{N}(\sigma)+\varepsilon\mathbf{1}\) must be introduced. Note that full-rank \(\sigma\) does not prevent \(\mathcal{N}(\sigma)\) from being rank-deficient: the channel may map the support of \(\sigma\) into a strict subspace of \(\mathcal{K}\). In the OPH setting, whether \(\mathcal{N}(\sigma)\) is full rank depends on the specific overlap channel and must be verified for the chosen analytic channel model. The finite OPH repair theorem instead uses the declared Lyapunov descent law on a finite patch net.

Proof. Complete positivity follows from composing three CP operations:

  1. sandwiching by \(\mathcal{N}(\sigma)^{-1/2}(\cdot)\mathcal{N}(\sigma)^{-1/2}\) on \(\mathrm{supp}(\mathcal{N}(\sigma))\);

  2. \(\mathcal{N}^\dagger\);

  3. sandwiching by \(\sigma^{1/2}(\cdot)\sigma^{1/2}\).

Trace preservation in the full-rank case: Petz ; Fagnola–Umanità . ◻

Proposition 108 (Analytic contraction certificate [Assumption-dependent]). Suppose a declared quotient repair map \(T:Q\to Q\) on a metric physical quotient \((Q,d_Q)\) is strictly contractive with coefficient \(\lambda\in(0,1)\): \[ d_Q(Tx,Ty)\le \lambda d_Q(x,y). \] Then \(T\) has at most one fixed point. If a fixed point \(x_\star\) exists, the ideal iterates obey \(d_Q(T^t x,x_\star)\le \lambda^t d_Q(x,x_\star)\). This is an analytic contraction condition. It is not required for the finite OPH normal-form theorem, where termination follows from strict Lyapunov descent of accepted repairs.

Theorem 109 (Noisy approximate repair stability [Contraction branch]). Assume the contraction certificate of Proposition 108, and let \(\widetilde T:Q\to Q\) be an implemented noisy repair map satisfying \[ d_Q(\widetilde T x,Tx)\le \varepsilon \qquad\text{for all }x\in Q. \] If \(x_\star\) is the ideal fixed point of \(T\), then \[ d_Q(\widetilde T^t x,x_\star) \le \lambda^t d_Q(x,x_\star)+\frac{\varepsilon}{1-\lambda}. \] Thus the noisy branch converges only to a controlled error ball, and only after the contraction certificate and uniform implementation-error bound are supplied.

Proof. The recursion \[ d_Q(\widetilde T x,x_\star) \le d_Q(\widetilde T x,Tx)+d_Q(Tx,Tx_\star) \le \varepsilon+\lambda d_Q(x,x_\star) \] iterates to the displayed geometric-series bound. ◻

Proposition 110 (Spectral-gap criterion [Model-dependent]). Let \(\mathcal T\) be the Markov, channel, or transfer operator induced by iterated OPH repair on a declared analytic realization. If \(\mathcal T\) has stationary projection \(\Pi_\star\) and constants \(C<\infty\), \(\delta>0\) such that on the nonstationary subspace \[ \|\mathcal T^t-\Pi_\star\|\le C e^{-\delta t}, \] then the corresponding analytic channel model has exponential convergence. The finite OPH repair package supplies termination by Lyapunov descent on its declared finite state space; a spectral gap is a separate quantitative mixing condition for this BFT/QECC-style extension.

Theorem 111 (Exponential Convergence [Under Proposition 110]). Under Proposition 110, for any initial analytic state \(\rho\), \[ \bigl\|\mathcal T^t\rho-\Pi_\star\rho\bigr\| \leq C\,e^{-\delta t}\bigl\|\rho-\Pi_\star\rho\bigr\|. \] This theorem belongs only to the spectral-gap branch. It is not a consequence of a bare finite overlap graph or of finite Lyapunov descent alone.

B.3Theorem 3: QECC Correspondence

Notation.

\(N=\dim(\mathcal{H})=2^n\) for \(n\) physical qubits. Standard notation: \([[n,k,d]]\) stabilizer code; \(K=2^k\); quantum Singleton bound: \(k\leq n-2(d-1)\).

Theorem 112 (No free min-cut theorem for bare overlap graphs [Established]). Let \(G=(V,E)\) be any connected graph with \(|V|\ge2\). The graph \(G\) alone does not determine the Hamming distance of the consistency set \(C\) of a finite overlap net on \(G\). In particular, the same graph can realize a binary constraint code of distance \(1\) or a binary repetition code of distance \(|V|\).

Proof. Set \(S_i=\{0,1\}\) for every vertex. For the repetition realization, choose \(I_e=\{0,1\}\) and let both endpoint readouts be the identity. Then every edge imposes \(x_i=x_j\), so the only global codewords are \(00\cdots0\) and \(11\cdots1\), whose Hamming distance is \(|V|\).

For the trivial-overlap realization, keep the same vertex state spaces but let every endpoint readout be the constant map to \(0\). Then every binary assignment is globally consistent, so the minimum Hamming distance among distinct codewords is \(1\). The graph is unchanged. Therefore distance is a property of the code realization (state spaces, readout maps, logical dictionary, metric, and error model), not of the bare overlap graph. ◻

Definition 113 (Topological-code realization certificate). An OPH overlap network may be treated as a QECC/topological code only after supplying a tuple \[ \mathsf{TCert}= (K,\mathcal H_{\mathrm{phys}},\mathcal H_{\mathrm{code}}, \partial_2,\partial_1,S_X,S_Z,\mathcal L_X,\mathcal L_Z,\mathcal E,\mathcal R), \] where \(C_2\xrightarrow{\partial_2}C_1\xrightarrow{\partial_1}C_0\) is a chain complex over \(\mathbb F_2\), the physical carriers live in \(\mathcal H_{\mathrm{phys}}\), the protected subspace is \(\mathcal H_{\mathrm{code}}\), \(S_X,S_Z\) are stabilizer or gauge checks, \(\mathcal L_X,\mathcal L_Z\) are logical-operator classes, \(\mathcal E\) is a declared error family, and \(\mathcal R\) is a recovery map or recovery family.

Theorem 114 (Certified topological-code distance and min-cut [Assumption-dependent]). Suppose a certificate \(\mathsf{TCert}\) of Definition 113 is supplied, with logical classes identified as \[ \mathcal L_X\simeq H_1(K;\mathbb F_2), \qquad \mathcal L_Z\simeq H^1(K;\mathbb F_2), \] and with boundary conditions excluding lower-weight trivial representatives. Then the certified distance is \[ d= \min\left\{ \min_{\ell\in\mathcal L_X\setminus0}|\ell|, \min_{\ell^\star\in\mathcal L_Z\setminus0}|\ell^\star| \right\}. \] Only in geometries where this homological systole equals the relevant graph min-cut may one write \(d=\mathrm{mincut}(G_{\mathrm{OPH}})\) .

Proof. This is the standard stabilizer/topological-code distance statement once the chain complex, checks, logical representatives, and boundary conditions are declared. The min-cut equality is an additional geometric identification of that homological minimum with a graph cut. By Theorem 112, it cannot be inferred from the bare graph. ◻

Conjecture 115 (Communication complexity [Conjecture]). The OPH consensus-repair protocol, realised as a quantum communication task, has per-round complexity \(O(n\cdot\mathrm{poly}(d))\) for a chosen communication encoding (cf. ). The fixed finite repair theorem gives termination after a supplied descent law; it does not by itself fix a quantum communication complexity class for every implementation.

Theorem 116 (QECC resilience under a supplied code certificate [Assumption-dependent]). Assume a genuine code subspace \(\mathcal H_{\mathrm{code}}\subseteq\mathcal H_{\mathrm{phys}}\) with projector \(\Pi\), and let \(\mathcal E_t\) be the declared set of errors supported on fewer than \(t\) corrupted patches or physical carriers. If \[ \Pi E_a^\dagger E_b \Pi=\alpha_{ab}\Pi \qquad \forall E_a,E_b\in\mathcal E_t, \] then there exists a recovery channel correcting all errors in \(\mathcal E_t\) . If the supplied certificate also gives distance \(d\), then all errors of weight \(t<d/2\) are correctable. No such resilience statement follows from the bare overlap graph.

Corollary 117 (QECC extension inventory). Under Definition 113, Theorem 114, and Theorem 116, the OPH BFT/QECC extension carries the following claim split:

  1. [Assumption-dependent] Code distance is the certified homological minimum; it equals \(\mathrm{mincut}(G_{\mathrm{OPH}})\) only under the additional systole/min-cut identification.

  2. [Established] The Knill–Laflamme QECC theorem supplies recovery once the projector and error family satisfy the displayed condition.

  3. [Conjecture] Per-round communication complexity is \(O(n\cdot\mathrm{poly}(d))\).

B.4Theorem 4: Asynchronous Convergence

Why fairness alone does not give a probability-1, spectral, or wall-clock statement.

Standard strong fairness guarantees that every enabled action fires infinitely often along any fair schedule; it does not impose a probability space on schedules, a transfer-operator spectral gap, or a message-delay bound. A convergence statement of the form “converges with probability 1” requires a measure on schedules. Exponential convergence requires the spectral-gap certificate of Theorem 111. Bounded wall-clock liveness requires partial synchrony and quorum assumptions. The FLP impossibility result  confirms that fairness is insufficient for bounded-time consensus in a fully asynchronous system.

Additional assumptions for a quantitative bound.

  1. Finite known bound \(\Delta\) on message delay after GST.

  2. Finite bound \(\Phi\) on processing rates.

  3. \(f < n/3\).

Theorem 118 (Eventual finite repair termination [Finite-descent branch]). For a finite OPH patch net with a strict Lyapunov-decreasing accepted repair relation, every maximal repair run terminates after finitely many accepted repairs. The step count is bounded by the finite value-set bound of Proposition 25. If the local-diamond and repair-completeness clauses also hold, Newman’s lemma upgrades this termination statement to the unique schedule-independent quotient normal form of Theorem 29.

This theorem is finite descent convergence in repair steps. It is not trace-norm convergence of a Petz channel, not probability-one convergence over random schedules, not exponential convergence, and not a wall-clock liveness theorem.

Theorem 119 (Quantitative Convergence [Assuming (B1)–(B3)]). In a partially synchronous OPH observer network satisfying (B1)–(B3), after GST every nonfaulty observer reaches consensus within \(T=O(f\cdot\Delta)\) wall-clock time (by applying the DLS framework , Thm. 4.4, to the OPH repair protocol; requires (B1) and (B2) explicitly and does not follow from fairness alone).

B.5Extension Boundaries

  • A bare OPH overlap graph is a finite constraint-code presentation only. Its graph does not determine code distance, correctable error weight, or min-cut resilience.

  • Analytic spectral-gap and full-rank estimates for a chosen stochastic or channel-level BFT/QECC realization are model-specific refinements. They are separate from the finite OPH repair theorem, where the accepted repair law supplies Lyapunov descent directly.

  • Long-run noisy approximate consensus is available only on the fair-block contraction branch of Theorem 84: the chosen implementation must certify fair blocks, expected contraction toward the exact quotient normal-form set, and controlled within-block excursions. Fairness alone does not supply that certificate.

  • Topological-code distance equals graph min-cut only after a concrete chain complex, boundary condition, logical-operator dictionary, error family, and systole/min-cut identification are supplied for the chosen code realization.

  • Communication-complexity bounds require a concrete quantum communication encoding and implementation cost model. They are not consequences of finite normal-form termination alone.

  • The core OPH consensus paper supplies observable-level confluence and refinement-limit normal-form/holonomy classes on their declared theorem surfaces; the BFT/QECC statements above are separate protocol-style extensions.

99

B. Müller, D. Matscheko, and J. Hill, Observation-Determined Normal Forms: Stability, Obstructions, and Refinement in Constraint and Rewrite Systems, 2026. Available at https://github.com/FloatingPragma/observer-patch-holography/blob/main/extra/observable_normal_forms.pdf.

B. Müller, Verified Projection-Event Calculus in Lean 4: Bundled Arbitrary-Partition Pinching, Lüders Retractions, and CHSH Interoperability, 2026. Available at https://github.com/FloatingPragma/observer-patch-holography/blob/main/extra/machine_checked_finite_event_algebras.pdf.

B. Müller, A. Osika, M. Poneder, K. Xue, B. Cassie, P. Nguyen, M. A. Visser, K. A. Anirudha, D. Matscheko, and J. Hill, Observers Are All You Need, 2026. Available at https://github.com/FloatingPragma/observer-patch-holography/blob/main/paper/observers_are_all_you_need.pdf.

M. H. A. Newman, “On theories with a combinatorial definition of ‘equivalence’,” Ann. of Math. 43 (1942), no. 2, 223–243.

M. J. Fischer, N. A. Lynch, and M. S. Paterson, “Impossibility of distributed consensus with one faulty process,” J. ACM 32 (1985), no. 2, 374–382.

L. Lamport, R. Shostak, and M. Pease, “The Byzantine generals problem,” ACM Trans. Program. Lang. Syst. 4 (1982), no. 3, 382–401.

C. Dwork, N. A. Lynch, and L. Stockmeyer, “Consensus in the presence of partial synchrony,” J. ACM 35 (1988), no. 2, 288–323.

H. Moniz, The Istanbul BFT Consensus Algorithm, arXiv:2002.03613, 2020.

R. Saltini et al., QBFT Formal Specification and Verification. Available at https://github.com/Consensys/qbft-formal-spec-and-verification.

D. Petz, “Sufficient subalgebras and the relative entropy of states of a von Neumann algebra,” Commun. Math. Phys. 105 (1986), no. 1, 123–131.

F. Fagnola and V. Umanità, “Generators of detailed balance quantum Markov semigroups,” Infinite Dimensional Analysis, Quantum Probability and Related Topics 13 (2010), no. 3, 459–486.

M. Junge et al., “Universal recovery maps and approximate sufficiency of quantum relative entropies,” Ann. Henri Poincaré 19 (2018), no. 8, 2505–2555.

E. Knill and R. Laflamme, “Theory of quantum error-correcting codes,” Phys. Rev. A 55 (1997), no. 2, 900–911.

A. Kitaev, “Fault-tolerant quantum computation by anyons,” Ann. Phys. 303 (2003), no. 1, 2–30.

E. Dennis, A. Kitaev, A. Landahl, and J. Preskill, “Topological quantum memory,” J. Math. Phys. 43 (2002), no. 9, 4452–4505.

H. Buhrman, R. Cleve, and A. Wigderson, “Quantum vs. classical communication and computation,” in Proceedings of STOC 1998, pp. 63–68.

O. Fawzi and R. Renner, “Quantum conditional mutual information and approximate Markov chains,” Commun. Math. Phys. 340 (2015), 575–611, arXiv:1410.0664.