Simulation theory

Reality as a Consensus Protocol

Authors: Bernhard Mueller, Kai Xue, Jinwook Kim, Kale Arnav Anirudha, David Matscheko, Jonathan Hill

Affiliations: Bernhard Mueller, Pragma Research Inc.

Abstract

Develops the mathematics of shared records, disagreement repair, and stable outcomes among limited observers.

r2039 September 8, 2026 papers
Section jump

Paper release: r2039Released: September 8, 2026

Author affiliation: Bernhard Mueller, Pragma Research Inc.

Scope of physical interpretation

The fixed-cutoff consensus theorem supplies a finite observer-like self-reading system only on the declared recovery, record, feedback, selected-fiber, and implementation-invariance packet. It does not select the physical twelve-port carrier based on the alternating group \(A_5\) on five letters, attach a canonical rank-three screen band to matter, construct a chiral quantum field theory, or determine a W/Z pole. Those claims require separately typed physical producers. In the companion paper, complete reversible response and endogenous transport force the local Standard Model gauge Lie algebra. The declared matrix-current and rank-15 matter contracts, anomaly balance, and tensor descent give the conditional charge lattice and maximal faithful matter image. Physical source binding of those contracts, laboratory current identification, family attachment, scalar multiplicity and dynamics, and quantum field theory are separate. No OPH-native \(W/Z\) pole follows.

This boundary does not make consensus carrier-neutral. The repair theorem is invariant under hidden presentation changes preserving the complete visible observer contract. Port incidence, orientation, accessible algebra, response, repair law, record process, clock, and refinement lineage belong to that contract and may constrain physical conclusions. On the unified Echosahedral branch, microphysics supplies the candidate carrier, this paper supplies its public normal form, and the spacetime/Einstein and Standard Model gauge papers supply geometry and current projections under their own named premises.

One typed construction and its source assumptions

The finite carrier, accepted repair, support geometry, gravity, abstract compact current, and conditional matter belong to one typed construction. Accepted repair produces the quotient-visible normal form. A1’s complete twelve-port response and A2’s endogenous holonomy force the abstract local Standard Model gauge Lie algebra. A declared matrix current and matter packet provide conditional realizations, while the source producer derives only the inverse-port response. Each composition uses the objects and premises displayed here.

Three meanings of screen

The word “screen” is used for three related objects that must not be identified without a receipt.

  1. The local carrier boundary is the twelve-port oriented interface of one Echosahedral carrier on the declared branch. Its incidence has \((V,E,F)=(12,30,20)\).

  2. The federation screen is the routed system of interfaces, records, repairs, and checkpoints of many carriers at finite cutoff.

  3. The support screen is the observer-facing geometric chart. On the spherical branch it is the refined conformal \(S^2\) used for caps, collars, modular flow, and Lorentz reconstruction.

Local icosahedral incidence does not determine the topology of the federation nerve. A federation of identical local carriers can be routed as a path, a cycle, a higher-genus complex, or a spherical complex. The map from routed carriers to a support-visible spherical nerve is therefore a physical bridge, not a change of notation.

Structure-sensitive, presentation-invariant physics

OPH is not neutral under arbitrary changes of substrate. It is invariant under changes of presentation that preserve the complete observer-visible carrier signature. On the Echosahedral branch that signature contains

\[\mathcal C_{i,r}= \bigl( \mathcal A_{i,r},\rho_{i,r},P_{i,r},I_{i,r}^{\rm or}, \mathcal R_{i,r},\mathcal U_{i,r},\mathsf{Chk}_{i,r}, \mathsf{Resp}_{i,r},c_{sr} \bigr),\]

where \(P_{i,r}\) is the port set, \(I_{i,r}^{\rm or}\) is oriented incidence, \(\mathcal R_{i,r}\) is the record algebra, \(\mathcal U_{i,r}\) is the repair or feedback interface, \(\mathsf{Resp}_{i,r}\) is the visible response law, and \(c_{sr}\) is the refinement lineage. Hidden coordinates, port names, worker partitions, materials, and wiring presentations are silent when an isomorphism preserves this whole tuple and its error model. A change in port number, incidence, orientation, accessible algebra, response, repair law, clock, or refinement lineage need not be silent. A cube and an icosahedron are therefore different carrier contracts even when both are built from the same material.

A carrier body is not automatically an observer. It realizes an observer only when it supplies bounded access, self-readback, durable records, record-conditioned feedback, boundary prediction against controls, and checkpoint continuation. One carrier may pass that test. A connected subfederation may pass it instead. No theorem fixes primitive observer size by counting carrier bodies.

The common finite computation

At cutoff \(r\), source-bound carrier data are routed into an observer-patch federation. Accepted repair then acts on the physical quotient:

\[\begin{aligned} \mathsf{SourceCarrierTower}_r &\xrightarrow{\;\mathsf{realize/route}\;} \mathsf{ObserverFederation}_r\\ &\xrightarrow{\;\pi_r\;} \mathsf{PhysicalQuotient}_r \xrightarrow{\;\operatorname{Rep}_r\;} \mathsf{PublicNormalForm}_r. \end{aligned}\]

The last arrow is the consensus result only under semantic-dependency-complete transactions, coherent union-collar payloads, repair completeness, local diamonds, protected records, and the stated endpoint conditions. A collection of oscillators with equal frequency does not supply those clauses.

Physical phase locking can instantiate one synchronization layer. For a routed edge \(e=((i,a),(j,b))\), a source-produced phase record may certify frequency entrainment and a stable relative phase,

\[\dot\theta_{i,a}-\dot\theta_{j,b}\longrightarrow0, \qquad d_{S^1}(\theta_{i,a}-\theta_{j,b},\delta_e)\le\varepsilon_e.\]

That certificate becomes a consensus parent only when the phase record fixes a commensurability map for the exposed packets and is tied to the accepted repair ledger, semantic records, an independently calibrated clock, and the confluence premises. Phase locking can synchronize an interface. It does not by itself make the interface an observer, settle semantic disagreement, or produce physical time.

Two projections of one source

The public normal form has two separately typed projections:

\[\begin{aligned} \mathsf{AuthenticatedSemanticHistory}_r &\longrightarrow \bigl(\mathsf{FiniteInformationalCauset}_r, \mathsf{CanonicalSourceHeight}_r\bigr),\\ \mathsf{ExactPortResponse}_r &\longrightarrow \bigl(\mathsf{RankThreeCarrier}_r,\, \mathsf{UnitDirections}_r\simeq S^2\simeq\mathsf{FutureNullRays}\bigr),\\ \mathsf{PublicNormalForm}_r &\xrightarrow{\;\mathsf{carrier\text{-}to\text{-}support}\;} \bigl(\mathsf{Support}_{S^2,r},\mathsf{FiniteCapBWCertificate}_r\bigr),\\ \left. \begin{gathered} \mathsf{FiniteCapBWCertificate}_r\\ \mathsf{CompatibleModularStateTower}_r \end{gathered} \right\}_{\text{same tower}} &\longrightarrow \mathsf{BW/KMS}_r \longrightarrow \mathsf{Lorentz/H^3Kinematics}_r . \end{aligned}\] \[\begin{aligned} \mathsf{FiniteStrictPoset}_r &\longrightarrow \mathsf{ExactAuthenticatedCausetLog}_r,\\ \left. \begin{gathered} \mathsf{FiniteInformationalCauset}_r\\ \mathsf{CanonicalSourceHeight}_r\\ \mathsf{RankThreeCarrier}_r \end{gathered} \right\} &\longrightarrow \mathsf{AmbientLorentzCarrier}_{1+3,r},\\ \left. \begin{gathered} \mathsf{FiniteInformationalCauset}_r\\ \mathsf{AmbientLorentzCarrier}_{1+3,r} \end{gathered} \right\} &\longrightarrow \mathsf{AuxiliarySeparatedForwardPlacement}_r,\\ \left. \begin{gathered} \mathsf{AmbientLorentzCarrier}_{1+3,r}\\ \mathsf{SuppliedSpatialReadback+EdgeSpeed}_r \end{gathered} \right\} &\longrightarrow \mathsf{ForwardConePlacement}_r,\\ \mathsf{ForwardConePlacement}_r &\xrightarrow{\;\substack{\mathsf{equal\mbox{-}height\ separation,}\\ \mathsf{incomparable\ spacelike}}\;} \mathsf{FaithfulFiniteCausalPlacement}_r,\\ \mathsf{FaithfulFiniteCausalPlacement}_r &\xrightarrow{\;\substack{\mathsf{physical\ signals+operational\ clocks,}\\ \mathsf{source\ refinement+count\text{-}volume,}\\ \mathsf{dimension+manifoldlikeness,}\\ \mathsf{topology+uniqueness}}\;} \mathsf{EffectiveSpacetime}_{3+1},\\[2pt] \left. \begin{gathered} \mathsf{NineSourceDirectionBalances}_r\\ \mathsf{SymmetricFields+Ward/Bianchi}_r\\ \mathsf{AlgebraicCoupling+Steps+Connectedness}_r \end{gathered} \right\} &\longrightarrow \mathsf{FiniteEinsteinForm}_r,\\[2pt] \left. \begin{gathered} \mathsf{EffectiveSpacetime}_{3+1}\\ \mathsf{FiniteEinsteinForm}_r\\ \mathsf{curvature+physical\ stress}\\ \mathsf{vacuum+8\pi G\ scale}\\ \mathsf{small\ ball+smooth\ convergence\ control} \end{gathered} \right\} &\xrightarrow{\;\mathsf{physical\ promotion}\;} \mathsf{SmoothPhysicalEinstein}_{3+1} . \end{aligned}\] \[\begin{aligned} \left. \begin{gathered} \mathsf{CompleteResponse}_{12}\\ \mathsf{EndogenousHolonomy}_{A_5} \end{gathered} \right\} &\longrightarrow \mathfrak u(1)\oplus\mathfrak{su}(2)\oplus\mathfrak{su}(3)\\ &\xrightarrow{\;\text{conditional matrix and matter packet}\;} \mathsf{MaximalFaithfulMatterImage}\\ &\dashrightarrow \mathsf{PhysicalGauge/QFT}. \end{aligned}\] The dashed arrow denotes source and laboratory maps not constructed here.

The finite carrier-to-support leg is constructed from one oriented icosahedral incidence nerve: twelve carrier charts, thirty seam algebras, and twenty nonvacuous triple restrictions. The same bound artifact supplies confluent seam repairs, an operational observer receipt, and a refinement-natural oriented \(S^2\) support limit. The separate geometric \(2\pi\)-KMS comparison and \(\mathsf{FiniteCapBWCertificate}\) are not outputs of that finite bridge. The state tower, common-comparison maps, compatible state/vector data, modular controls, and cofinal modulus form an independent compatible modular-state tower. The BW theorem consumes both inputs on the same refinement tower. Independently, authenticated read-from provenance supplies the finite event carrier and generated order. Every finite strict partial order also compiles exactly into an abstract authenticated log; the supplied relation and unthreaded snapshots make this grammar expressivity, not OPH dynamics or physical selection. Its canonical source height is zero at roots and one plus the maximum direct-parent height otherwise, equals the attained longest authenticated-parent-chain length, and strictly increases on generated ancestry. The exact source Gram quotient supplies a positive rank-three carrier. Its direct sum with an independent real axis, \[W_{\rm src}=\mathbb R\oplus V_{\rm src},\qquad Q(t,x)=t^2-g_{\rm src}(x,x),\] is a four-dimensional ambient target carrier with Lorentz inertia \((1,3)\), and source-unit directions are exactly its future-null rays. Canonical source height enters only through a scaled event placement. This finite construction removes the free event order, supplied placement rank, rank-four chart, and fitted signature. Once the support leg produces a conformal \(S^2\), the independent classical identity \(\operatorname{Conf}^+(S^2)\cong\operatorname{SO}^+(3,1)\) gives the same celestial Lorentz cone and the three-dimensional observer-frame fiber \(H^3=\operatorname{SO}^+(3,1)/\operatorname{SO}(3)\).

Every finite event log admits an auxiliary injective one-way realization: enumerate its events along one source axis and take a height scale larger than the enumeration diameter. Distinct same-height events are then spacelike. The enumeration is arbitrary and generally creates unsupported cone comparisons, so it supplies neither source selection nor faithful physical coordinates. A supplied event-local spatial readback and edge speed bound send generated precedence into the future cone. Equal-height spatial separation and a strict spacelike inequality for every increasing-height pair unsupported by ancestry derive converse cone support and exact two-way order–cone equivalence. Event separation follows from antisymmetry, and the two-way equivalence gives exact interval preservation. The exact-embedding route requires one source-selected refinement family preserving order, placement, and source directions, with dense and isotropic physical links on \(S^2\), calibrated \(\#I/\rho\to\operatorname{Vol}(I)\), independent dimension and manifoldlikeness tests, stable thickened-antichain topology, and convergence to a unique distinguishing Lorentzian limit. Event count is not public capacity \(N\).

A controlled effective route uses vanishing causal discrepancy and compatible count-volume convergence. Conservative Fibonacci-record populations with a specified complete-neighbour read law have such a flat \(1+3\) limit when their fill error is small relative to the shrinking read radius. Equal-mass assignments with vanishing displacement error give normalized event counts converging to volume. On fixed interior timelike diamonds, fourth roots of interval-count ratios recover proper-time ratios, with a reference interval fixing the unit and complete ancestry access supplying the readout. Within the class of nonzero closed convex pointed displacement cones, operational invariance under source rotations and every boost along one axis forces the Lorentz cone up to time orientation. The covariance is an assumption about actual influences and readouts. Physical selection of the population, read law and common matter realization is separate from these conditional results.

On the same finite event type, the source-order Einstein theorem replaces all-null balance by nine supplied balances on fixed algebraic source-direction representatives and, with symmetric fields, an algebraic coupling, four step maps, Ward/Bianchi identities, and connectedness, derives the all-null and Einstein-form tensor relations. The directions are algebraic rather than observed signals; the informational order does not select a field, step, or balance. The matrix fields and steps remain supplied. Reading them as smooth curvature and physical stress requires a same-family tensor-curvature reconstruction converging to the smooth Einstein tensor, or the separately stated continuum small-ball/null-balance identification, together with same-source stress, Ward/Bianchi, coupling, scale, and remainder data on the physical continuum family. Scalar-curvature convergence is only a diagnostic. The separate composedEinsteinBranch returns the conditional Einstein-form composition under those typed inputs; it does not supply them. Any admitted continuum spacetime is an emergent effective description, not a fundamental object inserted into the finite carrier.

The second projection begins with an exact finite result on the certified Echosahedral lineage. The twelve-port module decomposes as

\[P_{12}\cong_{A_5}\mathbf1\oplus\mathbf3\oplus\mathbf3'\oplus\mathbf5.\]

The declared integer counting and normalized central-readback cost realization gives the twelve unit lines and exact gap. An append-only signed-event machine generates those integer loads. Conservative whole-unit seam repairs preserve total load and strictly decrease \(V(N)=\sum_iN_i^2\); minimum move count is natural under every carrier rotation and the declared refinements. Divisibility of total load by twelve is necessary for consensus, while an explicit eighteen-move path settles the declared full-pile packet. A half-unit display rescales event values and the repair threshold together, so it is a units convention on the same move graph. Oriented incidence independently gives the antipodal pairing, proper \(A_5\) action, and rank-three Gram frame, and determines the antipode \(J\). Complete reversible response and endogenous overlap transport force the abstract local Standard Model gauge Lie algebra. Under the explicit inverse-port contract, the signed central involutive responses are exactly \(\pm J\), with common sign conventional. Conditional also on the matrix current and rank-15 matter contract with its unique charge-conjugate projector pair, anomaly and tensor-descent certificates give the hypercharge lattice, common \(\mathbb Z_6\) kernel, and maximal faithful matter image. The scalar scan fixes compatible charges and Yukawa channels, not scalar multiplicity. The target-blind producer derives the inverse-port response, without selecting the matrix current. Separate band premises select the rank-three response. Tensoring it with the declared generation table gives a conditional rank-\(45\) candidate whose chirality and diagonal \(\mathbb Z_6\) action come from that table. A distinct local-domain receipt checks the declared tensor-identity operator and conditional gap inheritance without source-selecting the matter action or transporting the twelve-port Spin packet. Laboratory identification of the finite matter carriers, current, and line sectors, exclusion of extra light sectors, physical matter-pole and continuum family identification, scalar attachment and dynamics, and quantum-field construction require separate maps.

The compact sector-category/Tannaka route conditionally reconstructs a compact group by a logically independent route. Physical family identification and extra-sector exclusion require separate identifications; they do not enter the contract-conditional finite gauge implication. Physical family identification requires an additional map on the charged-lepton and quantitative selector/gap branches. Physical unification requires a source-bound commuting square identifying its reconstructed compact group with the group acting through the Echosahedral current response:

\[\begin{array}{ccc} \mathsf{A5PortResponse}_r & \longrightarrow & G_r^{\rm screen}\\ \downarrow & & \downarrow\scriptstyle{\simeq}\\ \mathsf{TransportableSectorCategory}_r & \longrightarrow & G_r^{\rm DR}. \end{array}\]

On those premises the abstract Lie-type agreement is exact. The construction supplies neither the physical vertical maps nor an identification of the two group actions. In the same way, the rank-three response band and declared generation table form a conditional complex rank-\(45\) candidate, while three physical generations require matter-pole, continuum, seam-selection, persistence, and complement-complete refinement receipts. The rank-three result depends on the complete-band and cost-order premises; it is not a consequence of the icosahedral graph alone.

Finite controls and scope

The finite \(A_5\) evaluator control has \(60\) reachable correctable public records on \(\mathcal H_k=\ell^2(A_5)\otimes\mathbb C^k\):

\[M_0=60,\qquad D_{\rm raw}=60k,\qquad \Delta_{\rm raw}=60(k-1).\]

Raw equality occurs only at \(k=1\). Publicly inert multiplicity makes \(D_{\rm raw}\) implementation-dependent, so the result is an evaluator control rather than physical capacity closure.

The unified claim has a precise scope. Consensus and geometry/gravity are composable branches of one source-bound self-reading carrier tower. The finite gauge branch uses the same carrier architecture, and A1–A2 force its abstract local Standard Model gauge Lie algebra. The matrix current and matter action are conditional realizations and are not joined to that tower by a common source construction. Local icosahedral incidence by itself constrains only the carrier module. The physical maps that turn these constraints into one inhabited universe are additional assumptions. Matching dimensions or symmetry labels does not supply them.

What This Paper Contributes

The mathematics of repair is old in the right places. Constraint satisfaction, rewriting systems, well-founded descent, local-diamond confluence, inverse limits, and recovery channels all enter this paper with their standard meanings. OPH adds the physical reading: each variable is an observer patch, each constraint is an overlap-visible record check, and each accepted rewrite is a local repair move that must descend to the quotient seen by neighboring observers.

That turns consensus into the implementation layer of the theory. The paper distinguishes accepted-step termination from scheduler attempts that may stutter, proves that every canonical adaptive attempt stream is eventually constant, isolates pathwise weak fairness as sufficient for normality, proves that no single mismatch-only finite attempt horizon uniformly bounds all normalizing schedulers, gives a \((q+1)\)-scaled upper horizon under bounded waste with exact sharpness in the work-conserving case, and identifies completeness and confluence as the remaining hypotheses for one canonical public endpoint. It derives event precedence from versioned mismatch provenance: certified read-from parenthood generates the strict informational order, any exact precedence adapter reduces to a verifier of that order, and a writer-blind static mismatch score determines no causal arrow. It also proves how boundary data control uniqueness and how cycle holonomy records the exact obstruction to global agreement. Its finite results support the framework’s mathematical core. The paper also explains why a bare overlap graph is only a finite constraint code. Stronger language such as quantum error correction, min-cut distance, BFT liveness, or hardware speedup needs its own certificate.

Synchronization and consensus are distinct. A physical phase-lock process may establish a stable relative phase and a commensurability map between two exposed ports. It enters this theorem only after its phase records are tied to the accepted transaction ledger, an independent clock, the semantic record surface, and the confluence premises. Frequency entrainment alone can coexist with conflicting records.

Introduction

This paper writes the OPH consensus picture in the simplest concrete form. A universe is represented as a finite graph of observer patches. Each patch carries local state data, neighboring patches compare those data on overlaps, and local repair moves try to reconcile any mismatch. The central mathematical question is whether this repair dynamics converges to one shared world and how the unavoidable obstructions are encoded when it does not.

The word “dynamics” is used here in the rewriting-system sense. The repair schedule selects terminal normal forms and proves schedule independence under the stated hypotheses. The selected observer-facing structure can carry an internal record order, which is read as history. A conventional simulation computes a surrogate history. OPH computes the fixed point and its quotient-visible records. A physical-clock interpretation additionally requires an observer-readable transition process, event correspondence, and affine clock calibration. The patch-net algorithm is a theorem device for fixed-point selection. The fundamental description contains no global timeline on which spacetime contents are rendered.

A bare fixed point is not called an OPH simulation below. Definition 76 requires recovery-derived endogenous update, nontrivial quotient-readable records, overlap repair with schedule-independent normal form, elimination of a proper candidate basin in the selected boundary/sector fiber, and implementation-projection identities separating quotient-record order from any physical clock. Theorem 77 proves those clauses on the named finite branch and supplies a generic fixed-point and variational counterexample.

The resulting theorem package has two layers, bounded by the constraint-code firewall stated once in the summary list below. The first core consensus layer concerns convergence: primitive recovery proposals are eligible only when they satisfy the touched-overlap local-fit contract, but a proposal becomes physical only through transactional acceptance with snapshot validation, protected-boundary preservation, and exact well-founded descent. This accepted finite relation induces a total, idempotent, boundary-preserving quotient normal-form map \[\operatorname{Rep}_\lambda:Q\to Q.\] Connected conflict components commit atomically through coherent canonical union-collar payloads. Semantic-dependency-complete read sets, conflict components, snapshot-determined payloads, and revalidation prove the local diamond on the physical quotient. A schedule-independent normal form follows when these premises and repair completeness hold. The concrete receipt checks those premises and the resulting finite peaks. The stronger claim that all interiors with the same boundary data settle to the same state requires preservation of that boundary data plus a unique consistent extension in the corresponding fiber; the layered functional carrier proves a finite multi-edge witness for this condition, and the functional selected-fiber branch gives the rooted obstruction-check form. The second concerns obstructions: pairwise overlap agreement does not ensure a global solution, and the obstruction is holonomic. On the abelian branch it is the cycle sum of edge data; on the genuinely noncentral branch it is a crossed-module Čech class.

Gauge symmetry enters as invariance under changes of hidden local representation that preserve overlap data. When the repair step is read only on that overlap-invariant quotient, the normal-form map descends to the gauge quotient, so physical uniqueness is a quotient statement. On the quantum lift, the same quotient-local carrier determines a unique terminal state on every declared physical observable algebra, even when microscopic representative lifts differ by gauge or sector relabelings inside one quotient-local glued state. The observation layer is carried by finite observer-accessible record algebras generated by central or quantitatively stable approximately commuting projectors. These results form the patch-net formulation used in the broader OPH literature, including the fixed-cutoff Bell/CHSH package on the companion microphysics surface.

This paper proves a constraint-code firewall and nine core consensus results:

  1. Constraint-code firewall. A finite overlap net defines a finite constraint code: its codewords are exactly the globally consistent states, and \(C=\Phi^{-1}(0)\) (Proposition 3). This is the default meaning of “the overlap network is a code.” It is not, by itself, a quantum error-correcting code and does not imply a graph min-cut formula for distance (Theorem 118). The same firewall blocks semantic upgrade by relabeling: a finite constraint, archive, repair spectrum, or reconstruction threshold is a finite diagnostic; only a source-separated physical bridge supplying the relevant readout, residual ledger, controls, and frozen validation target changes that type.

  2. Asynchronous confluence. For the declared accepted repair law, primitive recovery proposals pass through transactional snapshot/read/write validation, semantic-dependency-complete boundary, sector, history, and checkpoint preservation, and exact descent. The accepted relation induces a total local quotient repair map \(\operatorname{locRep}_\lambda:Q\to Q\) and a total idempotent global repair map \(\operatorname{Rep}_\lambda=\overline{\operatorname{nf}}_\lambda:Q\to Q\). A coherent canonical aggregate per conflict component and semantic-complete revalidation prove the quotient local diamond. The implementation receipt checks these premises and the concrete finite peaks. With repair completeness, every fixed initial quotient state has a unique normal form, independent of update schedule (Proposition 13, Proposition 29, and Theorems 15 and 31).

  3. Cycle obstruction. For affine overlap constraints over an abelian group, global consistency holds if and only if the holonomy vanishes on every cycle (Theorem 38). The parity triangle gives the minimal frustrated example, and Theorem 41 extends the same logic to the crossed-module higher-gauge defect hierarchy used later in the framework.

  4. Gauge quotient, selected fibers, and observable-level confluence. When local repair is induced on the overlap-invariant quotient, the normal-form map descends to that quotient, \(\operatorname{Rep}_\lambda\circ q\) is invariant under gauge/implementation hiding, and the induced terminal state on every declared physical observable algebra is unique there even when microscopic representatives differ by gauge or sector relabelings inside one quotient-local glued state. If a boundary/sector map is preserved and each consistent boundary fiber has at most one quotient extension, then all initial states with that boundary value settle to the same quotient normal form; the layered functional carrier proves \(H_B\wedge H_{\mathrm{fib}}\) on a finite multi-edge, multi-step carrier, while the functional selected-fiber branch proves a nontrivial rooted case where multiple same-boundary interiors exist, inconsistent candidates are eliminated, and surviving candidates share one quotient normal form (Theorems 43, 45, 48, 50, Corollaries 44, 49, 52, and Theorem 57).

  5. Refinement-limit consensus classes. On a separated cofinal refinement system whose restriction maps commute with the finite-stage normal-form and holonomy maps, the quotient normal forms and holonomy obstructions assemble into unique inverse-limit classes with finite-stage visibility (Theorem 64).

  6. Coarse-graining compatibility. On any refinement system whose coarse-graining maps shadow finite-stage normal forms and holonomy maps with declared errors, reconciling first and then coarse-graining gives the same macroscopic law data as coarse-graining first and then reconciling, up to those errors; in the exact natural case the error is zero (Theorem 71).

  7. Record algebra and stability. On the fixed-cutoff observer-accessible surface, a supplied density-state valuation and a declared Lüders instrument give Born/Lüders formulas on the central record projectors; the projectors alone do not select the instrument. Approximate record projectors inherit explicit \((\varepsilon,\delta_{\mathrm{rec}})\) stability bounds on the same event surface (Theorem 74).

  8. OPH simulation firewall. On a selected boundary/sector fiber, “simulation” requires recovery-derived endogenous update, nontrivial quotient-readable records, strict overlap-repair descent with a schedule-independent normal form, collapse of a proper candidate basin to one consistent quotient state, and implementation-projection identities separating quotient-record order from any physical clock. Under the stated selected-fiber and record hypotheses, the finite OPH packet has this certificate; a generic identity fixed point or constant variational functional does not (Definition 76, Theorem 77, and Remark 78).

  9. Distributed one-universe realization. A worker implementation is a presentation of one finite OPH universe only when the run starts from one global carrier and every distributed event projects to a legal monolithic repair path, a physical stutter, or a certified rollback to an earlier committed projection. Under those hypotheses, partition, worker count, schedule, restart history, and repartition metadata do not change quotient observables or observer readouts that factor through the monolithic normal form (Theorem 84 and Corollary 85).

  10. Conditional noisy fair-block consensus. If a noisy asynchronous implementation admits fair repair blocks, a uniform expected contraction toward the exact quotient normal-form set, and controlled within-block excursions, then all long runs stay in a controlled expected tube around that exact normal-form set. In singleton boundary/sector fibers, Lipschitz observer readouts are approximately schedule-independent, and a finite Markov-kernel certificate checks the block contraction on finite exported nets (Theorem 90, Corollaries 9192, and Proposition 93).

The repair step itself is a concrete recovery move, not a free rewrite primitive. On the fixed-cutoff collar branch, a local update is obtained from exact Markov splice or from a declared Petz/Fawzi–Renner recovery channel and then read on overlap-invariant physical data. The fixed-point theorem below isolates the separate branch conditions cleanly: the declared repair law includes the touched-overlap local-fit contract for primitive proposals, while transactional acceptance validates snapshots, protected data, unchanged registers, and exact descent. The fixed-cutoff gluing package carries a parenthesization-independent union-collar payload only on a branch with an exact aligned Markov construction, a coherent canonical recovery construction, or a primitive aggregate-payload receipt. Repair completeness, the quotient-level local diamond, and, on the Petz branch, the support/CPTP clause are separate conditions stated in Proposition 113. A nontrivial exported rooted-tree packet domain where these clauses are proved is recorded in Definition 19 and Theorem 20; the separate layered functional carrier records the finite multi-edge boundary-reconstruction witness.

We also define a fitness functional over a finite candidate space of reconciliation laws and prove that replicator dynamics monotonically increases mean fitness (Theorem 97). This gives a clean mathematical model for finite-candidate law selection, not a universality theorem or a literal cosmological dynamics claim.

The results here are exact theorems about a computational model. The companion OPH manuscript uses separate support levels for structural theorems, scaling limits, quantitative particle outputs, and phenomenological continuations [source].

Patch Nets, Overlaps, and Global Consistency

Definition 1 (Patch net). Let \(G=(V,E)\) be a finite connected graph. Each vertex \(i\in V\) is an observer patch with finite local state space \(S_i\). The global state space is \[\Sigma := \prod_{i\in V} S_i.\] For each edge \(e=\{i,j\}\in E\), let \(I_e\) be an interface alphabet and let \[\pi_{i,e}:S_i\to I_e, \qquad \pi_{j,e}:S_j\to I_e\] be the interface projection maps. A global state \(s=(s_i)_{i\in V}\in\Sigma\) is consistent on edge \(e=\{i,j\}\) iff \[\pi_{i,e}(s_i)=\pi_{j,e}(s_j).\] The global consistency set is \[C:=\bigl\{s\in\Sigma:\forall\, e=\{i,j\}\in E,\ \pi_{i,e}(s_i)=\pi_{j,e}(s_j)\bigr\}.\]

For exposition we use a finite pairwise-overlap graph. The hypergraph version is straightforward: replace edges by hyperedges and pairwise equality by a common interface label on each hyperedge. Nothing in the proofs depends on the pairwise restriction.

The picture: each observer holds a local state, and neighboring observers share an interface through which they can compare notes. A universe-state is physically admissible exactly when all neighbors agree on their shared data. This is a constraint satisfaction problem (CSP), and the consistent states are the codewords.

Definition 2 (Inconsistency potential). For each edge \(e\), choose a weight \(w_e>0\) and a function \(d_e:I_e\times I_e\to\mathbb{R}_{\ge 0}\) with \(d_e(a,b)=0 \iff a=b\). On the declared fixed-cutoff branch, \(d_e\) is the overlap score used by the local acceptance contract on that interface. Define \[\Phi(s) := \sum_{e=\{i,j\}\in E} w_e\, d_e\!\bigl(\pi_{i,e}(s_i),\pi_{j,e}(s_j)\bigr).\] Then \(s\in C \iff \Phi(s)=0\).

Proposition 3 (Bare overlap nets are finite constraint codes). For every finite patch net of Definition 1, the consistency set \(C\subseteq \Sigma\) is a finite constraint code whose codewords are exactly the globally overlap-consistent states. With the mismatch potential of Definition 2, \[C=\Phi^{-1}(0).\] This proposition is the theorem-grade content of the unqualified phrase “the overlap network is a code.” It supplies a finite constraint code, not a quantum error-correcting code, not a topological code, not a graph-theoretic formula for code distance, and not a Lorentzian or Einstein-geometry theorem.

Proof. Finiteness follows from \(\Sigma=\prod_i S_i\) with finite \(S_i\). The definition of \(C\) is a finite family of interface-equality constraints, so \(C\) is the set of satisfying assignments. Since each \(w_e>0\) and \(d_e(a,b)=0\) exactly when \(a=b\), every term in \(\Phi\) is nonnegative and vanishes exactly on a satisfied edge constraint. Therefore all edge constraints hold if and only if \(\Phi(s)=0\). ◻

Remark 4 (Bare consensus does not supply the cap-normal \(H^3\) chart). Bare finite consensus supplies quotient normal forms, boundary data, and obstruction classes. It does not itself supply the future null cone, a round-cap support chart, conformal transport, a time orientation, or the \(H^3\) observer-frame homogeneous space. The cap-normal theorem in the spacetime and Einstein paper applies only after the separate geometric-readout Bisognano–Wichmann (BW) branch has emitted an oriented conformal \(S^2\), nondegenerate oriented round caps, and proper-orthochronous conformal transport. This is why the finite-consensus to Einstein branch-entry arrow is a separate implication with its own premises.

Definition 5 (Bare finite consensus reduct). A bare finite consensus reduct at regulator \(r\) is \[\mathsf{Cons}_r = (\Sigma_r,\Gamma_r,Q_r,\Phi_r,\to_r,n_r,C_r,B_r),\] where \(\Sigma_r\) is the finite presentation space, \(\Gamma_r\) is the presentation-redundancy groupoid, \(Q_r=\Sigma_r/\Gamma_r\) is the physical quotient, \(\Phi_r\) is the mismatch functional, \(\to_r\) is the accepted repair relation, \(n_r\) is the quotient normal-form map, and \[C_r=\Phi_r^{-1}(0)\] is the globally overlap-consistent set, and \(B_r\) is its boundary-data readout.

Theorem 6 (Bare finite consensus is not Einstein-complete). The bare finite consensus reduct \(\mathsf{Cons}_r\) does not determine a Lorentzian metric \(g_{ab}\), stress tensor \(T_{ab}\), Newton coupling \(G\), area/edge operator \(L_C\), generalized entropy \(S_{\mathrm{gen}}\), modular geometric flow, or the equation \[G_{ab}+\Lambda g_{ab}=8\pi G\,T_{ab}.\] Consequently, Einstein geometry is not a theorem of the bare finite consensus language.

Proof. The symbols of \(\mathsf{Cons}_r\) describe finite states, quotienting, mismatch, accepted repair, normal forms, and consistency. They do not include a metric, curvature tensor, stress tensor, cap modular automorphism, area operator, or entropy-area normalization. Hence two model extensions can share the same \(\mathsf{Cons}_r\) while assigning different geometry/stress data. One extension may attach Minkowski metric, \(T_{ab}=0\), and \(\Lambda=0\), so Einstein holds. Another may attach a Lorentzian metric \(g'_{ab}\) and stress tensor \(T'_{ab}\) for which \[G'_{ab}+\Lambda' g'_{ab}\ne 8\pi G' T'_{ab}\] somewhere. All bare consensus statements have the same truth value in the two extensions, while the Einstein equation has different truth values. Therefore the Einstein equation is not entailed by the bare reduct. ◻

The theorem excludes definability of the Einstein equation from free decorations of \(\mathsf{Cons}_r\): the two extensions attach geometry with no arrow from the quotient. The machine-checked form (bare_consensus_not_einstein_complete in ) covers the integer scalar Einstein identity on a constant demonstration tower; the metric, stress, coupling, area-operator, entropy, and modular-flow clauses rest on the prose model extension above. Extensions whose geometry is a computable function of the quotient normal forms, such as the support-visible incidence complex of the geometry-producer packet, are the object of the producer and composition theorems and are outside this exclusion.

\[\boxed{ \mathsf{Cons}_r\Rightarrow\text{quotient normal forms and computable functions of them.} }\] The gravity theorem used elsewhere in OPH has a separate typed dependency spine: \[\boxed{ \begin{gathered} \mathsf{RecoveredCore}_{5\mathrm{ax}}+\mathsf{GeomRead} +\mathrm{BW}^{\mathrm{sv}}_{S^2} +\mathsf{NullStress}\\ +\mathsf{BoundedInterval} +\mathsf{FixedCapStat} +\mathsf{SmallBallArea}\\ +\mathsf{RemainderControl} +\mathsf{TimelikeCoverage}\\ +\mathsf{CommonSource} +\mathsf{PhysicalIDs}\\ +\mathsf{TensorUpgrade} \Rightarrow \mathsf{Einstein}. \end{gathered} }\] The implication requires one source-derived common-domain tower, certified asymptotic tails, universal coupling, a source-derived vacuum reference, and independent physical scale readouts. Such a tower enters as a premise; this paper does not construct it. That branch is carried by the spacetime/Einstein and microphysics papers, not by the bare constraint-code theorem above.

So \(\Phi\) is the total disagreement energy of the universe. Consistent states have zero energy. Everything else is frustrated.

Asynchronous Reconciliation and the Main Fixed-Point Theorem

Definition 7 (Recovery-derived local repair law). Fix for each patch \(i\) a finite collar chart \(A_i\!-\!B_i\!-\!D_i\) around the overlaps touched by \(i\), together with a fixed local decoder from repaired collar data back to the finite patch label at \(i\). A law \(\lambda\) is a family of local repair maps \[T_i^\lambda:\Sigma\to\Sigma \qquad (i\in V)\] such that \(T_i^\lambda\) changes only the state of patch \(i\) (or, more generally, only a bounded neighborhood of \(i\)), and the local update is induced by one of the declared OPH recovery moves on that collar, where \(\omega_{A_iB_i}(s)\) denotes the \(A_i\cup B_i\) marginal of the input collar state encoded by \(s\):

  1. exact Markov splice on the collar, using Theorem 98 when \(I(A_i:D_i\mid B_i)=0\); or

  2. a declared recoverability channel \[(\mathrm{id}_{A_i}\otimes \mathcal R_i)(\omega_{A_iB_i}(s)), \qquad \mathcal R_i=\mathcal R_{\sigma_i,\mathcal N_i},\] with \(\mathcal R_i\) in the Petz/Fawzi–Renner class of Definition 111 and Theorem 98.

The decoder back to \(S_i\) is bookkeeping for the finite patch presentation; the physical content is the repaired collar state on the declared fixed-cutoff branch. Write \(s\rightsquigarrow_i t\) iff \(t=T_i^\lambda(s)\neq s\). These are primitive proposals, not accepted physical rewrite steps. A proposal is committed only through the transactional acceptance layer below.

Definition 8 (Touched-overlap potential and accepted local-fit contract). For each repair site \(i\), let \[E_i^{\mathrm{touch}} := \bigl\{ e\in E:\text{the interface data on }e\text{ may change under }T_i^\lambda \bigr\}.\] Define the touched-overlap potential \[\Phi_i(s) := \sum_{e=\{u,v\}\in E_i^{\mathrm{touch}}} w_e\, d_e\!\bigl(\pi_{u,e}(s_u),\pi_{v,e}(s_v)\bigr).\] On the declared fixed-cutoff branch, a recovery-derived primitive candidate is eligible for transactional commitment only if it strictly lowers this touched-overlap score: \[s\rightsquigarrow_i t \implies \Phi_i(t)<\Phi_i(s).\] This is the patch-net form of the regulator-side monotone local-fit contract carried by the declared repair package.

Definition 9 (Overlap-associative union-collar gluing). Fix \(s\in\Sigma\) and two enabled primitive proposals \(s\rightsquigarrow_i t\), \(s\rightsquigarrow_j u\). Write \[E_{ij}^{\mathrm{touch}} := E_i^{\mathrm{touch}}\cup E_j^{\mathrm{touch}}.\] The declared repair branch is overlap-associative if the following hold.

  1. If \(E_i^{\mathrm{touch}}\cap E_j^{\mathrm{touch}}=\varnothing\), the two local proposals have disjoint support on the declared branch and therefore commute if they are committed as separate transactions.

  2. If \(E_i^{\mathrm{touch}}\cap E_j^{\mathrm{touch}}\neq\varnothing\), there is a finite union collar \(U_{ij}\) covering the interfaces in \(E_{ij}^{\mathrm{touch}}\) such that the physical glued state on \(U_{ij}\) is parenthesization-independent on the quotient, in the sense of Proposition 106, and the local decoders/lifts of Definition 7 are restriction-compatible on nested collars.

This is the concrete compatibility package used below to build canonical aggregate payloads for conflicting repair components.

Definition 10 (Transactional acceptance layer). Let \(X\) denote the finite physical presentation on which a repair step is being checked: before quotienting one may take \(X=\Sigma\), and on the physical branch \(X\) is the quotient by hidden representatives. Registers are the finite patch, interface, sector, and record coordinates. Fix a boundary/sector/holonomy record map \[B:X\to\mathcal B\] and a well-founded exact measure \[\mu:X\to(W,\prec),\] for example a lexicographic integer vector \((N_{\mathrm{hard}},\Phi,N_{\mathrm{unresolved}})\).

A prepared transaction is a tuple \[\tau=(R_\tau,W_\tau,\sigma_\tau,p_\tau)\] with read set, write set, read snapshot, and payload. It commits at \(x\in X\) only if all of the following hold:

  1. the snapshot is current: \(x|_{R_\tau}=\sigma_\tau\);

  2. the payload changes no register outside \(W_\tau\);

  3. boundary, sector, holonomy, and protected record data are preserved: \(B(\operatorname{Apply}_\tau(x))=B(x)\);

  4. exact descent holds: \[\mu(\operatorname{Apply}_\tau(x))\prec \mu(x).\]

A stale, aborted, ambiguous, or obstructed transaction is not a rewrite step. The read set is semantic-dependency-complete as follows. Let \(\mathcal F\) contain every finite-support functional whose value enters acceptance: the supported terms of \(\mu\), the protected boundary/sector/holonomy functions, enablement predicates, semantic-history and event-parent functions, observer-registry updates, and checkpoint-continuation functions. For a write set \(W\), define \[D_{\mathcal F}(W) := \bigcup_{\substack{f\in\mathcal F\\ \operatorname{supp}(f)\cap W\ne\varnothing}} \operatorname{supp}(f).\] Every prepared transaction satisfies \(R_\tau\supseteq D_{\mathcal F}(W_\tau)\); its enablement and payload are functions of the read snapshot, and every acceptance functional affected by its write is revalidated at commit. For seam potentials this reads both endpoints of every seam whose score can change. Protected-support completeness and protected-conflict completeness are the restrictions of this condition to protected functionals; they are not substitutes for the full semantic closure.

At a state \(x\), form the conflict graph of enabled primitive repair proposals, with \[\tau\#\sigma \quad\Longleftrightarrow\quad W_\tau\cap(R_\sigma\cup W_\sigma)\ne\varnothing \ \text{or}\ W_\sigma\cap(R_\tau\cup W_\tau)\ne\varnothing .\] Each connected conflict component \(K\) is replaced by exactly one canonical aggregate transaction \(\tau_K\), computed on the union-collar or conflict-component support, with final declared supports \(R_K,W_K\) satisfying \(R_K\supseteq D_{\mathcal F}(W_K)\). If aggregation or collar completion expands either support, conflicts are recomputed on the final aggregate supports and components are merged again until a fixed point is reached; distinct fixed-point aggregates are pairwise nonconflicting. These fixed-point components form a prepared source batch. After one component commits, another source-batch aggregate whose snapshot remains current and whose acceptance functionals revalidate remains admissible before later-enabled proposals are batched. Equivalently, an implementation may recompute immediately only if it certifies this surviving-component property. Primitive members of \(K\) never commit separately. Write \(x\to y\) for a successful aggregate transaction commit, and let \(\to^*\) be its reflexive-transitive closure. A state is a normal form when no aggregate transaction is enabled.

The quotient repair operator

The transactional layer above defines the physically accepted one-step relation. The object used as law is the induced finite normal-form map on the physical quotient, not a hidden-representative rewrite.

Definition 11 (Finite quotient repair presentation). A finite quotient repair presentation is a tuple \[\mathcal P=(\Sigma,\Gamma,q,Q,C_Q,B,\mu,\mathsf A,\prec_{\mathsf A})\] where \[Q=\Sigma/\Gamma,\qquad q:\Sigma\to Q\] is the physical quotient by hidden representative data, \(C_Q\subseteq Q\) is the quotient-level consistency set, \[B:Q\to\mathcal B\] is the protected boundary, sector, root-packet, charge, or holonomy-sector map, and \[\mu:Q\to(W,\prec)\] is a well-founded exact descent measure whose image on \(Q\) is finite. The finite set \(\mathsf A\) consists of accepted aggregate repair transactions, equipped with a fixed total order \(\prec_{\mathsf A}\). Each \(a\in\mathsf A\) has a domain \(D_a\subseteq Q\) and a map \[a:D_a\to Q.\] The accepted one-step relation is \[x\to_{\mathcal P} y \quad\Longleftrightarrow\quad \exists a\in\mathsf A,\ x\in D_a,\ y=a(x).\] The presentation is OPH-admissible when: \[(H_B)\qquad x\to_{\mathcal P}y\implies B(y)=B(x),\] \[(H_\downarrow)\qquad x\to_{\mathcal P}y\implies \mu(y)\prec\mu(x),\] \[(H_\diamond)\qquad \to_{\mathcal P}\text{ is locally confluent on }Q,\] and \[(H_{\mathrm{comp}})\qquad x\in C_Q \quad\Longleftrightarrow\quad \text{no accepted aggregate transaction is enabled at }x.\]

Definition 12 (Local quotient repair operator). For \(x\in Q\), let \[\mathsf A(x):=\{\,a\in\mathsf A:x\in D_a\,\}\] be the enabled aggregate transaction set. Define \[\operatorname{locRep}_\lambda(x):= \begin{cases} a_{\min}(x),& \mathsf A(x)\ne\varnothing,\\ x,& \mathsf A(x)=\varnothing, \end{cases}\] where \(a_{\min}\) is the \(\prec_{\mathsf A}\)-least enabled aggregate transaction.

Proposition 13 (Local quotient repair is total, protected, and descending). For every OPH-admissible finite quotient repair presentation, \[\operatorname{locRep}_\lambda:Q\to Q\] is a total map. For every \(x\in Q\), \[B(\operatorname{locRep}_\lambda(x))=B(x),\] and either \(\operatorname{locRep}_\lambda(x)=x\) or \[\mu(\operatorname{locRep}_\lambda(x))\prec\mu(x).\] Finally, \[\operatorname{locRep}_\lambda(x)=x \quad\Longleftrightarrow\quad x\in C_Q.\]

Proof. The set \(\mathsf A\) is finite and totally ordered, so a least enabled transaction exists whenever \(\mathsf A(x)\ne\varnothing\). If no transaction is enabled, the definition returns \(x\). Hence \(\operatorname{locRep}_\lambda\) is total.

If no transaction is enabled, boundary preservation is immediate. If \(a_{\min}\) is enabled, \((H_B)\) gives \(B(a_{\min}(x))=B(x)\). The descent statement is immediate from \((H_\downarrow)\). Since strict descent excludes \(a_{\min}(x)=x\), the local operator fixes exactly those states with no enabled aggregate transaction. By \((H_{\mathrm{comp}})\), these are exactly the elements of \(C_Q\). ◻

Definition 14 (Global quotient repair operator). For \(x\in Q\), define the canonical local-repair iterates by \[x_0=x,\qquad x_{n+1}=\operatorname{locRep}_\lambda(x_n).\] By Proposition 13, the sequence either stops or strictly descends inside the finite value set \(\mu(Q)\). Hence there is a least \(N(x)\) such that \[x_{N(x)+1}=x_{N(x)}.\] The global quotient repair operator is \[\operatorname{Rep}_\lambda(x):=x_{N(x)}.\]

Theorem 15 (Global Repair is the finite quotient normal-form map). For every OPH-admissible finite quotient repair presentation, \[\operatorname{Rep}_\lambda:Q\to Q\] is total and satisfies \[\operatorname{Rep}_\lambda(x)\in C_Q,\qquad B(\operatorname{Rep}_\lambda(x))=B(x),\] \[\operatorname{Rep}_\lambda(\operatorname{Rep}_\lambda(x)) = \operatorname{Rep}_\lambda(x),\] and \[\operatorname{Rep}_\lambda(x)=x \quad\Longleftrightarrow\quad x\in C_Q.\] If \(x\to_{\mathcal P}^{\!*}y\) and \(y\) is terminal, then \[y=\operatorname{Rep}_\lambda(x).\] Thus \[\operatorname{Rep}_\lambda=\overline{\operatorname{nf}}_\lambda:Q\to Q\] is independent of the accepted asynchronous repair schedule.

Proof. Totality follows from finite descent. If \(x_{n+1}\ne x_n\), then Proposition 13 gives \[\mu(x_{n+1})\prec\mu(x_n).\] Since \(\mu(Q)\) is finite and well founded, no infinite strictly descending sequence exists. Thus the canonical iteration reaches a fixed point \(x_N\). By Proposition 13, \[x_N=\operatorname{locRep}_\lambda(x_N) \quad\Longleftrightarrow\quad x_N\in C_Q,\] so \(\operatorname{Rep}_\lambda(x)\in C_Q\). Boundary preservation follows by induction from \((H_B)\), hence \(B(\operatorname{Rep}_\lambda(x))=B(x)\). Idempotence follows because every point of \(C_Q\) is fixed by Proposition 13.

For schedule independence, \((H_\downarrow)\) gives termination of \(\to_{\mathcal P}\), and \((H_\diamond)\) gives local confluence. Newman’s lemma gives confluence. A terminating confluent rewrite system has a unique terminal normal form reachable from each initial state. The canonical iteration defining \(\operatorname{Rep}_\lambda\) is one accepted repair execution, so it reaches that unique terminal normal form. Therefore every other maximal accepted repair execution from \(x\) reaches the same value. ◻

Closure item Paper object Result
physical one-step repair \(\operatorname{locRep}_\lambda:Q\to Q\) Proposition 13
physical global repair \(\operatorname{Rep}_\lambda=\overline{\operatorname{nf}}_\lambda\) Theorem 15
protected data boundary/sector map \(B\) preserved by accepted transactions Theorem 15
quotient normal form terminal point in \(C_Q\), idempotent and schedule-independent Theorem 15

Proposition 16 (Validation support for local mismatch measures). Suppose the exact repair measure has finite local supports, \[\mu(x)=\sum_{a\in A}\mu_a(x|_{S_a}).\] If a transaction writes \(W\), then only terms with \(S_a\cap W\ne\varnothing\) can change. Consequently, the descent validation is snapshot-local once the read set contains \[R^\mu(W):=\bigcup_{a:S_a\cap W\ne\varnothing}S_a .\] For the OPH overlap potential \[\Phi(x)=\sum_{e=\{i,j\}}w_e\,d_e\!\bigl(\pi_{i,e}(x_i),\pi_{j,e}(x_j)\bigr),\] this means reading both endpoints of every overlap whose score may change when a written register changes.

Proof. If \(S_a\cap W=\varnothing\), the transaction leaves every register read by \(\mu_a\) unchanged, so that term cancels between the pre- and post-state. Every remaining term is determined by the payload together with the restriction to \(R^\mu(W)\). The displayed edge-potential formula has one two-endpoint support for each overlap term, giving the stated seam rule. ◻

Remark 17 (Inputs and branch conditions). The repair step is therefore not an abstract rewrite primitive. Its declared inputs are the fixed-cutoff collar chart, either exact Markov splice or a chosen Petz/Fawzi–Renner recovery channel, a local decoder/lift back to the finite patch presentation, and the touched-overlap local-fit contract of Definition 8, together with the support-local disjoint-commutation clause and the restriction-compatible union-collar package of Definition 9. The parenthesization-independent quotient-local glue used there is supplied by Proposition 106 from the fixed-cutoff center-sector / higher-gauge gluing package. The actual accepted step is the validated aggregate transaction of Definition 10. The theorem package takes repair completeness as an explicit branch condition. On the Petz branch, full CPTP action on all inputs also requires the support clause recorded in Proposition 113. On broader branches one must also prove that the declared union-collar compatibility is preserved under refinement or branch change.

The theorem package separates the imported repair-law data from the theorem-local inputs cleanly:

Assumption 18 (Repair completeness). For the accepted transactional relation \(\to\), \(s\in C\) if and only if no aggregate repair transaction is enabled at \(s\).

Normal forms are exactly the globally consistent states. The dynamics is neither too weak (missing some inconsistencies) nor too strong (repairing things that were fine).

Definition 19 (Verified rooted-tree packet-net domain). Fix a finite rooted tree \(T=(V,E,r)\). For each non-root vertex \(i\), write \(p(i)\) for its parent and write \(w_i>0\) for the weight of the edge \(\{p(i),i\}\). Let \(A\) be a finite packet alphabet with \(|A|\ge2\), and let \(K_i\) be a finite hidden-label set. The patch state space is \[S_i=A\times K_i, \qquad s_i=(x_i,k_i).\] For every edge \(e=\{i,j\}\), the interface alphabet is \(I_e=A\), and both endpoint projections read the packet component: \[\pi_{i,e}(x_i,k_i)=x_i, \qquad \pi_{j,e}(x_j,k_j)=x_j.\] Thus \(e\) is consistent exactly when \(x_i=x_j\). Choose the weights so that \[w_i>\sum_{j:p(j)=i}w_j \qquad \text{for every non-root } i,\] with an empty sum equal to \(0\). Define \[\Phi(s)=\sum_{\{p(i),i\}\in E}w_i\,\mathbf 1[x_i\ne x_{p(i)}].\] The repair map at a non-root vertex \(i\) is \[T_i(s)_i=(x_{p(i)},k_i),\] with all other vertices unchanged; if \(x_i=x_{p(i)}\), the map is a no-op. The root repair map is the identity. The hidden labels \(k_i\) are acted on by arbitrary finite gauge relabelings and are not read by any interface projection.

Theorem 20 (Rooted-tree packet repair completeness and quotient closure). On the domain of Definition 19, Assumption 18 is a theorem. Every enabled repair strictly decreases \(\Phi\). Every maximal asynchronous repair run terminates at the unique state \[x_i=x_r\quad\text{for all }i\in V,\] with all hidden labels \(k_i\) unchanged. The normal-form map descends to the quotient by hidden gauge relabeling. If several tree repairs lie in one conflict component, the canonical aggregate transaction applies them in increasing tree depth and is the same as the corresponding serial tree repair path. The four-vertex instance with edges \(r\!-\!a\), \(a\!-\!b\), \(a\!-\!c\), alphabet \(A=\mathbb Z_3\), hidden labels \(K_i=\mathbb Z_2\), and weights \(5,1,1\) is exported as a verified domain record with the cited consensus code.

Proof. First, repair completeness is immediate from the rooted tree. If \(s\in C\), every edge has \(x_i=x_{p(i)}\), so every non-root repair is a no-op. Conversely, if every repair is a no-op, then \(x_i=x_{p(i)}\) for every non-root vertex, hence every edge is consistent and \(s\in C\).

Let \(i\ne r\) be enabled. Only the parent edge \(\{p(i),i\}\) and child edges \(\{i,j\}\) with \(p(j)=i\) can change their contribution to \(\Phi\). The parent edge changes from inconsistent to consistent, contributing \(-w_i\). Each child edge can increase by at most its weight. Therefore \[\Phi(T_i(s))-\Phi(s) \le -w_i+\sum_{j:p(j)=i}w_j <0.\] So every enabled repair is accepted by the Lyapunov contract.

Since \(\Phi\) takes finitely many values, every maximal repair run terminates. At a terminal state no non-root vertex differs from its parent, so the terminal packet label is \(x_r\) on every vertex. The root label and every hidden label are invariant under all repairs, so the terminal state is unique and independent of update order. Because interface projections, enabledness, \(\Phi\), and the repair maps depend only on \(x_i\), arbitrary relabelings of the hidden \(K_i\) commute with quotienting: \[q\circ T_i=\overline T_i\circ q.\] Thus the normal-form map descends to the hidden-label quotient. ◻

Corollary 21 (Physical-law map on the verified packet domain). On the rooted-tree packet domain, every gauge-invariant observable \[M:\prod_i(A\times K_i)\to Y\] has a schedule-independent repaired value \[M(\operatorname{nf}(s)),\] and this value depends only on the quotient class of \(s\). Hence the normal-form map is usable as physical law on this verified packet branch without adding a representative-level gauge-covariance assumption.

Proof. Theorem 20 gives a unique terminal state for every asynchronous repair schedule and shows that the normal-form map descends to the quotient by hidden-label relabeling. A gauge-invariant observable factors through that quotient, so its value on the terminal state is independent of both the repair schedule and the hidden representative. ◻

Proposition 22 (Classical full-support Petz packet domain). Let \(B\) and \(D\) be finite packet alphabets, let the collar algebras be diagonal, and let \(\mathcal N:\mathbb C^{B\times D}\to\mathbb C^B\) be the marginal channel \((\mathcal N p)(b)=\sum_d p(b,d)\). Fix a reference state \(\sigma_{BD}\) with \(\sigma_B(b)>0\) for every \(b\). Let \[\gamma_\sigma:=\min_{b\in B}\sigma_B(b)>0.\] Define the Petz recovery channel \[\mathcal R_{\sigma,\mathcal N}(\mu)(b,d) = \mu(b)\,\sigma(d\mid b), \qquad \sigma(d\mid b):=\frac{\sigma_{BD}(b,d)}{\sigma_B(b)}.\] Then \(\mathcal R_{\sigma,\mathcal N}\) is stochastic, completely positive and trace preserving on the diagonal algebra, and \(\ell^1\)-contractive: \[\|\mathcal R_{\sigma,\mathcal N}(\mu)-\mathcal R_{\sigma,\mathcal N}(\nu)\|_1 \le \|\mu-\nu\|_1.\] The support inverse is uniformly bounded on this domain by \[\|\sigma_B^{-1/2}\|\le \gamma_\sigma^{-1/2}.\] If a collar state has the exact classical Markov form \[\omega_{ABD}(a,b,d)=\omega_{AB}(a,b)\sigma(d\mid b),\] then \((\mathrm{id}_A\otimes\mathcal R_{\sigma,\mathcal N})(\omega_{AB})=\omega_{ABD}\). The support obstruction is exact: if \(\sigma_B(b)=0\) and an input assigns mass to \(b\), the Petz inverse on that sector is undefined unless the channel domain is restricted or a separate trace-preserving completion is declared.

Proof. The displayed formula is the finite diagonal specialization of the Petz map \[\sigma_{BD}^{1/2} \left(\sigma_B^{-1/2}\mu\,\sigma_B^{-1/2}\otimes \mathbf 1_D\right) \sigma_{BD}^{1/2}.\] Full support of \(\sigma_B\) makes the inverse well defined, with support gap \(\gamma_\sigma>0\), hence \(\|\sigma_B^{-1/2}\|\le\gamma_\sigma^{-1/2}\). Nonnegativity is immediate, and \[\sum_{b,d}\mathcal R_{\sigma,\mathcal N}(\mu)(b,d) = \sum_b \mu(b)\sum_d\sigma(d\mid b) = \sum_b\mu(b),\] so the map is trace preserving. Diagonal positive trace-preserving maps are completely positive on the diagonal algebra. For signed diagonal inputs, \[\|\mathcal R_{\sigma,\mathcal N}(\mu)-\mathcal R_{\sigma,\mathcal N}(\nu)\|_1 = \sum_{b,d}|\mu(b)-\nu(b)|\,\sigma(d\mid b) = \sum_b|\mu(b)-\nu(b)|,\] which gives the stated contraction. The exact Markov recovery identity follows by substitution. If \(\sigma_B(b)=0\), the factor \(\sigma_B^{-1/2}\) has no value on that sector; mass placed there by an input is outside the Petz support domain. That is the claimed obstruction. ◻

Proposition 23 (Accepted repair moves are decreasing). For the accepted transactional repair law of Definitions 710, every enabled repair strictly decreases the declared exact measure: \[s\to t \implies \mu(t)\prec\mu(s).\] On the scalar \(\Phi\)-branch, this specializes to \(\Phi(t)<\Phi(s)\).

Proof. This is part of the commit validation in Definition 10. For a single-site scalar-\(\Phi\) transaction it reduces to the touched-overlap contract of Definition 8; for an aggregate conflict component it is checked on the aggregate payload before the component can commit. ◻

Proposition 24 (Termination from the OPH Lyapunov functional). Under Proposition 23, every repair sequence is finite; equivalently, the repair relation \(\to\) is terminating.

Proof. Along any nontrivial repair step \(s\to t\), Proposition 23 gives \(\mu(t)\prec\mu(s)\). The measure order is well founded, so an infinite strictly descending chain is impossible. On the scalar-\(\Phi\) branch this is the finite-value argument on \(\Phi(\Sigma)\). ◻

Proposition 25 (Finite repair step bound). Let \(s_0\in\Sigma\). Under Proposition 23, every accepted repair run starting at \(s_0\) has length at most the number of distinct \(\mu\)-values reachable below \(\mu(s_0)\) minus one. On the scalar-\(\Phi\) branch this gives \[\bigl|\{\,\Phi(s):s\in\Sigma,\ \Phi(s)\le \Phi(s_0)\,\}\bigr|-1 \le |\Phi(\Sigma)|-1.\] If, additionally, \(\Phi\) is integer-valued, or more generally every accepted move lowers \(\Phi\) by at least a fixed \(\eta>0\), then the run length satisfies \[T(s_0)\le \left\lceil\frac{\Phi(s_0)}{\eta}\right\rceil .\] This is a finite descent bound in repair steps only. It is not a wall-clock bound, not a probability-one scheduling statement, and not spectral or exponential convergence.

Proof. The values of \(\mu\) strictly decrease along the run, so no \(\mu\)-value can occur twice. This gives the finite reachable-value bound. On the scalar-\(\Phi\) branch, the values of \(\Phi\) strictly decrease along the run, so no value in \(\{\,\Phi(s):s\in\Sigma,\ \Phi(s)\le \Phi(s_0)\,\}\) can occur twice. This gives the finite value-set bound. If each move lowers \(\Phi\) by at least \(\eta\), after \(T\) moves the value has dropped by at least \(T\eta\). Since \(\Phi\ge0\), \(T\eta\le\Phi(s_0)\), giving the displayed ceiling bound. ◻

Theorem 26 (Adaptive repair attempts: stabilization, fairness, and work conservation). Let \(C\) be a finite OPH carrier, let \(x_0\) be an initial record, and let \(\sigma\) choose one site from the current record at each attempt. Write \(x_n=\operatorname{adaptiveRun}_C(n,\sigma,x_0)\). Then:

  1. for every \(\sigma\), the sequence \(x_n\) is eventually constant;

  2. if \(\sigma\) is pathwise weakly fair, so that a site which remains enabled along a tail is eventually selected on that tail, the stable record is a normal form;

  3. if \(\sigma\) is work conserving, so that it selects an effective repair whenever one exists, there is a normal and stable index \(N\le\operatorname{mismatchCount}(x_0)\).

Proof. Every attempt either stutters or is an accepted repair step. The mismatch count never increases and strictly decreases at every nonstuttering attempt, so only finitely many genuine changes are possible. If a pathwise weak-fair run were eventually constant at a reducible record, an enabled site would remain enabled along that tail and would eventually be selected, contradicting constancy. Work conservation removes stuttering before normality, so the initial natural-number rank bounds the normal horizon. ◻

Theorem 27 (Cumulative attempt-capacity classification). Charge one unit for every canonical adaptive scheduler invocation, including an equality stutter. Then:

  1. no function of the initial mismatch alone bounds the first normal attempt over all normalizing adaptive schedulers;

  2. if, from every scheduler index and every reducible record, one genuine change occurs among the next \(q+1\) attempts, there is a stable normal index \[N\le(q+1)\operatorname{mismatchCount}(x_0);\]

  3. the coefficient is sharp at \(q=0\): for every \(m\ge1\), a canonical independent-defect carrier has initial mismatch \(m\) and a work-conserving run whose first normal index is exactly \(m\). The committed TwoCell source is a second sharp instance with a different patch cardinality.

Proof. For the first clause, delay the enabled TwoCell probe by selecting its edge-free site for any prescribed finite number of attempts, then select the probe. The run normalizes one attempt later while the initial mismatch stays one. For the second clause, every block of \(q+1\) attempts starting from a reducible record contains a genuine change, and each such change strictly lowers the natural mismatch rank. Strong induction gives the product bound. For the sharp family, each self-loop mismatch belongs to one site and one canonical local repair removes exactly that mismatch. A state-dependent scheduler always chooses a broken site, so its mismatch count is \(m-n\) through attempt \(m\). The threshold is therefore both necessary and sufficient. The TwoCell calculation repeats the threshold-one conclusion on a nonisomorphic source. ◻

The premise in (ii) is a bounded stutter allowance. It is stronger than eventual fairness and weaker than work conservation when \(q>0\). The cumulative unit is only a count of chosen-site attempts; it is not a physical clock, rate, energy, bandwidth allocation, hardware quota, or fee.

Remark 28 (Termination is not confluence). Proposition 24 proves only that accepted repair runs stop. It does not prove that two update orders stop at the same physical state. Schedule-independence enters only after the local-diamond property of Proposition 29 is combined with termination via Newman’s lemma and with repair completeness in Assumption 18. If two accepted repair schedules from the same initial state reach different observer-facing quotient normal forms, with no declared holonomy or higher-gauge obstruction and no mere gauge-representative difference, then the proposed repair law is not OPH-admissible as a consensus mechanism.

Proposition 29 (Semantic-complete transactional local diamond). For the accepted repair law of Definitions 710, assume semantic-dependency-complete read sets and revalidation, payload determination from the read snapshot, and a coherent canonical aggregate union-collar payload from Proposition 106. Assume additionally the aggregate-support fixed-point closure and surviving prepared-component rule of Definition 10. Then every one-step quotient peak \[t\longleftarrow s\longrightarrow u\] admits a quotient state \(v\) with \(t\to v\leftarrow u\). Hence the transactional repair relation is locally confluent. The finite implementation receipt records the functional supports, dependency closures, read/write sets, support-closed conflict components, aggregate payload hashes, finite state transitions, and recomputed protected-record and descent checks needed to check that its concrete reference engine realizes these premises.

Proof. A one-step peak cannot choose two different payloads from one conflict component because that component has one canonical aggregate transaction. Its two steps therefore come from distinct support-closed components, say \(\tau\) and \(\sigma\). By the fixed-point conflict definition, \[W_\tau\cap(R_\sigma\cup W_\sigma)=\varnothing, \qquad W_\sigma\cap(R_\tau\cup W_\tau)=\varnothing.\] The writes are disjoint and neither changes the other’s read snapshot. If an acceptance functional can change under \(\tau\), semantic dependency closure puts its support in \(R_\tau\); hence \(\sigma\) leaves that functional’s input unchanged. Thus \(\tau\)’s enablement, descent comparison, protected-data check, semantic parents, checkpoint continuation, and payload remain valid after \(\sigma\), and conversely. The surviving prepared-component rule prevents a later-enabled proposal from absorbing either old component before its second commit. Both second commits are legal. Since their writes are disjoint and their payloads are determined by unchanged snapshots, \[\operatorname{Apply}_\sigma\operatorname{Apply}_\tau(s) =\operatorname{Apply}_\tau\operatorname{Apply}_\sigma(s)=v.\] This is the local diamond on the physical quotient. ◻

Finite premise receipt.

The executable check enumerates all states and one-step peaks of a finite conflict-component reference engine and recomputes separate countermodels for semantic closure, atomic component commits, canonical aggregate coherence, aggregate-support reclosure, surviving prepared components, snapshot-determined payloads, strict descent, repair completeness, and protected-record preservation. It verifies a concrete realization of the proposition’s premises; it does not infer those premises for an arbitrary engine.

Remark 30 (Atomic commits do not prove the local diamond). Let \(Q=\{0,1\}^2\), \(s=(0,0)\), and protect \(B(x_1,x_2)=x_1x_2\). The transactions \[\tau_1:(0,x_2)\mapsto(1,x_2), \qquad \tau_2:(x_1,0)\mapsto(x_1,1)\] have disjoint write sets and each preserves \(B\) at \(s\). Both lower \(\mu(x_1,x_2)=2-x_1-x_2\). Their peak has endpoints \((1,0)\) and \((0,1)\), while either second write would reach \((1,1)\) and change \(B\). Neither continuation is admissible. The missing dependency is the nonlinear protected observable shared by the two writes. Protected-support and conflict completeness expose that dependency; an implementation must check the resulting quotient peak.

Theorem 31 (Asynchronous confluence / fixed-point law). For the accepted repair law of Definitions 710, assume that the induced physical relation on \(Q=\Sigma/\Gamma\) is the OPH-admissible finite quotient presentation of Definition 11; in particular use Proposition 29 and Assumption 18 on that quotient. Each fixed initial state \(s\in\Sigma\) then has a unique quotient normal form \[\overline{\operatorname{nf}}_\lambda(q(s)) =\operatorname{Rep}_\lambda(q(s))\in q(C),\] and every maximal asynchronous repair execution from \(s\) terminates at a representative \(t\in C\) with \(q(t)=\overline{\operatorname{nf}}_\lambda(q(s))\). Microscopic terminal representatives need not be equal. When one such representative must be named below, write \(\operatorname{nf}_\lambda(s)\) for a choice; only its quotient is canonical. The quotient endpoint is independent of update order because descent, local confluence on the physical quotient, and repair completeness all hold; termination alone is not enough.

Proof. Proposition 24 gives termination, while Proposition 29 gives local confluence on \(Q\). Newman’s lemma [source] therefore makes the quotient relation confluent. By Assumption 18, its normal forms are exactly \(q(C)\). Theorem 15 identifies the unique quotient endpoint with \(\operatorname{Rep}_\lambda(q(s))\). A lifted maximal execution terminates at some microscopic representative of that orbit; no representative equality follows from quotient confluence. ◻

Corollary 32 (Objective law is schedule-independent). Let \(\overline M:Q\to Y\) be a quotient observable, equivalently let \(M:\Sigma\to Y\) factor as \(M=\overline M\circ q\). Under the hypotheses of Theorem 31, \(\overline M(\overline{\operatorname{nf}}_\lambda(q(s)))\) is independent of the asynchronous update schedule. If physical law is identified with this quotient-observable map, then physical law is objective.

Proof. All schedules from the same initial \(s\) terminate in the same quotient normal form, so a quotient observable has the same value on every terminal representative. ◻

Here objectivity is identified with schedule-independent convergence on the physical quotient; Theorem 57 lifts this to the physical observable algebra while explicitly allowing distinct microscopic terminal representatives.

Corollary 33 (Canonical endpoint for weak-fair adaptive repair). Assume the completeness and confluence hypotheses of Theorem 31. Every pathwise weak-fair canonical adaptive run from one initial record reaches a stable consistent record equal to the canonical repair endpoint. Its image is therefore the same public fixed-point object for every such scheduler.

Proof. Theorem 26 gives a reachable stable normal form. Completeness makes that normal form consistent. Confluence identifies it with the canonical repair normal form from the same start, and the public projection preserves the equality. ◻

Corollary 34 (Capacity-bounded canonical endpoint). Assume the completeness and confluence hypotheses of Theorem 31. Let the scheduler have waste bound \(q\), and let the cumulative attempt budget satisfy \[B\ge(q+1)\operatorname{mismatchCount}(x_0).\] Then the run reaches a stable consistent record at some attempt \(N\le B\). That record equals the canonical repair endpoint and maps to the same existing public fixed-point object for every scheduler satisfying the same contract.

Proof. Theorem 27 gives the normal index within budget. Completeness makes the record consistent. Its accepted-step reachability and confluence identify it with canonical repair, and the public projection preserves the equality. ◻

Remark 35 (Quantifier on normal-form uniqueness). Theorem 31 proves quotient-normal-form uniqueness from a fixed initial state; Theorem 43 below records representative-lift independence for a fixed physical quotient state. It does not say that all possible initial data settle to one universal quotient state. Different boundary conditions, conserved charges, root packets, holonomy sectors, or external records can legitimately determine different normal forms.

Finite support propagation and algebraic no-signalling

The concrete single-site record repair has a finite support theorem that is independent of termination and confluence. For a patch \(i\), let \(\mathcal N[i]\) be \(i\) together with every endpoint of an edge incident to \(i\), and define \[\operatorname{Grow}(S)=S\cup\bigcup_{i\in S}\mathcal N[i], \qquad B_0(S)=S, \qquad B_{n+1}(S)=\operatorname{Grow}(B_n(S)).\]

Theorem 36 (Finite repair support bound). Let \(L_i\) be the concrete localRepair map: it reads only \(\mathcal N[i]\) and writes only the record at \(i\). For any schedule word \(w=(i_1,\ldots,i_n)\), region \(S\), and records \(x,y\), \[x|_{B_n(S)}=y|_{B_n(S)} \quad\Longrightarrow\quad L_w(x)|_S=L_w(y)|_S,\] where \(L_w=L_{i_n}\circ\cdots\circ L_{i_1}\). Consequently, changing one initial record at a site outside \(B_n(S)\) cannot change the final readout on \(S\) after any fixed exogenous schedule word of length \(n\).

Proof. One repair move preserves agreement on \(T\) whenever its two inputs agree on \(\operatorname{Grow}(T)\): away from the firing site it writes nothing, and at the firing site its trigger, solvability predicate, and selected repair value depend only on the closed incident-edge neighborhood. Induction on the schedule word gives the displayed implication. A one-site update outside \(B_n(S)\) leaves the two initial records equal throughout that set. The statement is machine checked for the committed repair map [source]. ◻

This fixed-word bound has an exact conditional adaptive extension. If the next-site scheduler is supplied together with a region \(R\) on which its choice depends, then agreement on \(B_n(S\cup R)\) forces the two \(n\)-step runs to agree on \(S\cup R\); equivalently, a change outside both \(B_n(S)\) and \(B_n(R)\) cannot alter the probe readout. Fixed words embed as record-blind schedulers, while a two-cell countermodel proves that the consultation-region term cannot be dropped. Naturality also follows under the laws of a separately declared refinement structure. These results do not produce the scheduler, consultation region, channel, or refinement maps from the source. Neither theorem supplies a converse, minimal cone, physical graph metric, propagation speed, or claim that influence reaches the cone boundary.

Proposition 37 (Bipartite marginal invariance). Let \(A,B\) be finite sets.

  1. For an arbitrary real array \(p:A\times B\to\mathbb R\) and real matrix \(K:A\times A\to\mathbb R\) satisfying \(\sum_{a'}K(a,a')=1\), define \[p'(a',b)=\sum_a p(a,b)K(a,a').\] Then \(\sum_{a'}p'(a',b)=\sum_a p(a,b)\) for every \(b\).

  2. For an arbitrary matrix \(M\) on \(\mathbb C^A\otimes\mathbb C^B\) and a finite family \(K_r\) on \(\mathbb C^A\) satisfying \(\sum_rK_r^\dagger K_r=I_A\), define \[\Phi(M)=\sum_r(K_r\otimes I_B)M(K_r^\dagger\otimes I_B).\] Then \(\operatorname{Tr}_A\Phi(M)=\operatorname{Tr}_A M\).

Proof. For the classical identity, interchange the two finite sums and use the row normalization of \(K\). For the matrix identity, expand the partial trace in indices and contract the acted-factor indices with \(\sum_rK_r^\dagger K_r=I_A\). The one-point choice \(K=2\) is a negative control: without row normalization the remote marginal is doubled. Both identities are machine checked [source]. ◻

These marginal identities are standard finite algebra. Their bipartite split and local lift are supplied inputs. Positivity and unit mass are additional premises when the classical arrays are read as probabilities. No physical spacelike separation, observer-region factorization, density-state realization, or laboratory operation follows. A local observable-net construction must attach disjoint observer regions to the declared factors.

The quotient normal-form theorems of this section state that the public world is the quotient normal form that survives agreement on overlaps. Two failure shapes would break the claim: an OPH-admissible overlap presentation on which no quotient normal form exists under the declared descent, local-diamond, and repair-completeness conditions, or two inequivalent quotient normal forms surviving from the same declared boundary data where the fiber-uniqueness hypothesis of Theorem 45 holds. Either exhibit defeats the claim on its declared branch.

Why Local Agreement Is Not Enough: Cycle Holonomy and Frustration

Pairwise neighbor agreement does not by itself imply global consistency.

Theorem 38 (Cycle-obstruction / holonomy criterion). Let \(A\) be an abelian group, and let \(G=(V,E)\) be a connected graph with an arbitrary orientation on each edge. For each oriented edge \(e:u\to v\), assign a label \(b_e\in A\). Consider the affine consistency equations \[x_v - x_u = b_e \qquad \text{for every oriented edge } e:u\to v,\] where \(x_v\in A\) are unknown patch labels. A global solution \(x:V\to A\) exists if and only if for every cycle \(C\subseteq G\), \[\sum_{e\in C}\varepsilon_C(e)\, b_e = 0,\] where \(\varepsilon_C(e)=+1\) if the cycle traverses \(e\) in the chosen orientation and \(-1\) otherwise.

Proof. Necessity. Suppose \(x\) is a solution. Summing the edge equations around any cycle \(C\), \[\sum_{e:u\to v\in C}\varepsilon_C(e)\,(x_v-x_u) = \sum_{e\in C}\varepsilon_C(e)\,b_e.\] The left side telescopes to \(0\) because every vertex appears once with \(+\) sign and once with \(-\) sign.

Sufficiency. Fix a root \(r\in V\). For any vertex \(v\), choose a path \(P_{r\to v}\) and define \[x_v := \sum_{e\in P_{r\to v}} \varepsilon_{P_{r\to v}}(e)\, b_e, \qquad x_r:=0.\] If \(P\) and \(P'\) are two paths from \(r\) to \(v\), traversing \(P\) followed by the reverse of \(P'\) yields a cycle. By the vanishing-holonomy assumption, the total signed sum is zero, so \(x_v\) is well-defined. For any edge \(e:u\to v\), extending a path to \(u\) by that edge gives \(x_v = x_u + b_e\). ◻

Corollary 39 (Parity triangle: pairwise consistency is not enough). Take \(A=\mathbb{Z}_2\) on the triangle \(A\)-\(B\)-\(C\)-\(A\) with edge labels \(b_{AB}=0\), \(b_{BC}=0\), \(b_{CA}=1\). Each individual edge equation is satisfiable. But the global system is not: the cycle sum is \(0\oplus 0\oplus 1 = 1\neq 0\).

This example shows that pairwise consistency does not imply a global solution. The obstruction is carried by the cycle.

Corollary 40 (Stable defects as frustrated holonomy). Define the defect energy \[\Phi_b(x) := \sum_{e:u\to v\in E} w_e\,\mathbf{1}\!\left[x_v - x_u \neq b_e\right].\] If the cycle-holonomy condition fails, then \(\min_{x:V\to A}\Phi_b(x)>0\). Every minimizer contains irreducible residual inconsistency.

Proof. If \(\min_x\Phi_b(x)=0\), some assignment satisfies all edge equations, contradicting Theorem 38. ◻

Residual inconsistencies of this type cannot be removed by local repair moves. In the OPH interpretation they are stable topological defects of the reconciliation dynamics.

Theorem 41 (Higher-gauge defect hierarchy). Let a finite overlap nerve carry crossed-module defect data \((g_{ij},h_{ijk})\) for a compact crossed module \[H\xrightarrow{\partial} G.\] Under local rechartings by \[C^1(N,H)\rtimes C^0(N,G),\] the nonabelian Čech class \[q=[(g,h)]\in \check H^2(N,H\to G)\] is invariant and classifies the full crossed-module orbit. Its neutral element is equivalent to full gauge trivialization of both levels. The higher associator alone is removable precisely when \(q\) lies in the image of the natural strict-locus map \[\check H^1(N,G)\longrightarrow\check H^2(N,H\to G),\qquad[g]\longmapsto[(g,1)].\] After such a strictification, endpoint-only ordinary reconciliation additionally requires an allowed strict representative with trivial represented loop holonomy. The strict-locus map need not be injective, so \(q\) need not determine one ordinary \(H^1\) class.

Proof. The allowed rechartings are exactly the crossed-module coboundaries, so they preserve the full orbit. The neutral orbit admits the completely trivial representative. More generally, the higher associator is removed when the orbit meets the strict locus \((g,1)\); different points of that locus can be related by \(H\)-valued edge changes. Ordinary loop coherence is therefore the separate existential holonomy test stated above. ◻

Gauge Symmetry as Implementation Hiding

Definition 42 (Gauge action). Let \(\Gamma = \prod_{i\in V}\Gamma_i\) act on \(\Sigma\) componentwise. The action is a gauge action if for every \(e=\{i,j\}\in E\), \[\pi_{i,e}(\gamma_i\cdot x)=\pi_{i,e}(x) \qquad \forall\, x\in S_i,\ \forall\, \gamma_i\in \Gamma_i.\] Gauge changes alter hidden local representations but do not alter overlap data.

Gauge transformations change hidden local representations while leaving overlap data fixed. Write \[q:\Sigma\to \Sigma/\Gamma, \qquad q(s)=[s],\] for the gauge-orbit map. A physical repair law is the family of quotient-local maps \[\overline T_i^\lambda:\Sigma/\Gamma\to \Sigma/\Gamma\] induced by the recovery-derived collar updates of Definition 7. A representative repair family is any choice of lifts \[T_i^\lambda:\Sigma\to\Sigma\] such that \[q\circ T_i^\lambda = \overline T_i^\lambda\circ q.\] This is the finite patch-net form of saying that the repair step is defined first on overlap-invariant physical data and only then lifted to hidden representatives. The rooted-tree packet domain of Theorem 20 proves repair completeness and quotient descent on a nontrivial exported packet net, while Proposition 22 proves the classical full-support Petz clause used by that domain. A broader fixed-cutoff branch requires repair completeness for the chosen exported packet net and the support/CPTP clause on the Petz branch where that channel is used. The touched-overlap local-fit contract gives scalar \(\Phi\)-descent for primitive proposals on the corresponding branch, while the transaction layer supplies exact accepted-step descent. Proposition 106 together with Definition 9 supplies the quotient-local compatibility package used to build canonical aggregate payloads. Proposition 29 derives the local diamond from semantic-dependency-complete read sets, canonical conflict components, snapshot-determined payloads, and revalidation. The implementation receipt checks those premises and the concrete finite peaks. Stability under refinement or branch change is a separate question. The point here is also that no extra gauge-covariance axiom is needed once repair is formulated on the quotient.

Theorem 43 (Gauge quotient theorem). Under the gauge action of Definition 42, any representative lift of a physical repair law as just defined, and the hypotheses of Theorem 31, \[q\bigl(\operatorname{nf}_\lambda(\gamma\cdot s)\bigr) = q\bigl(\operatorname{nf}_\lambda(s)\bigr) \qquad \forall\, \gamma\in\Gamma,\ \forall\, s\in\Sigma.\] Equivalently, the canonical normal-form map is the quotient operator constructed above: \[\overline{\operatorname{nf}}_\lambda:\Sigma/\Gamma \to \Sigma/\Gamma, \qquad [s]\mapsto \operatorname{Rep}_\lambda([s]) =q(\operatorname{nf}_\lambda(s)).\]

Proof. Let \(s\to t\) be an accepted aggregate transaction, and let \(\overline\tau\) be its quotient payload. If \(s'=\gamma\cdot s\), the representative-lift hypothesis gives an accepted lift \(s'\to t'\) of the same quotient transaction, and \[q(t') = \overline\tau\bigl(q(s')\bigr) = \overline\tau\bigl(q(s)\bigr) = q(t).\] Thus gauge-equivalent inputs induce the same repaired orbit, and by induction the orbit reached after any repair sequence depends only on the initial orbit. Theorem 31 says that every maximal repair sequence from \(s\) ends at some terminal representative whose orbit is \(\operatorname{Rep}_\lambda(q(s))\). Hence \(q(\operatorname{nf}_\lambda(s))\) depends only on \(q(s)=[s]\). This makes \[[s]\longmapsto \operatorname{Rep}_\lambda([s])\] well-defined on \(\Sigma/\Gamma\). ◻

Corollary 44 (Repair respects gauge). Let \(Q=\Sigma/\Gamma\), let \(q:\Sigma\to Q\) be the quotient map, and let \[\operatorname{Rep}^{\Sigma}_\lambda := \operatorname{Rep}_\lambda\circ q : \Sigma\to Q\] be the quotient-valued physical repair of a representative. Then for every \(\gamma\in\Gamma\) and \(s\in\Sigma\), \[\operatorname{Rep}^{\Sigma}_\lambda(\gamma\cdot s) = \operatorname{Rep}^{\Sigma}_\lambda(s).\] Equivalently, \[\operatorname{Rep}_\lambda(q(\gamma\cdot s)) = \operatorname{Rep}_\lambda(q(s)).\] If \(M:Q\to Y\) is any physical observable, then \[M(\operatorname{Rep}^{\Sigma}_\lambda(\gamma\cdot s)) = M(\operatorname{Rep}^{\Sigma}_\lambda(s)).\]

Proof. Since \(q\) is the quotient map, \(q(\gamma\cdot s)=q(s)\). Therefore \[\operatorname{Rep}^{\Sigma}_\lambda(\gamma\cdot s) = \operatorname{Rep}_\lambda(q(\gamma\cdot s)) = \operatorname{Rep}_\lambda(q(s)) = \operatorname{Rep}^{\Sigma}_\lambda(s).\] Applying \(M\) gives the observable statement. ◻

Theorem 45 (Boundary-conditioned quotient uniqueness). Let \[B:\Sigma/\Gamma\to\mathcal B\] record fixed external boundary data, conserved charge, root packet, holonomy sector, or task input. Assume accepted quotient repairs preserve \(B\): \[[s]\to [t]\implies B([s])=B([t]).\] For \(b\in\mathcal B\), define the consistent quotient fiber \[C_b:=\{\,x\in q(C):B(x)=b\,\}.\] If every \(C_b\) has at most one element, then all initial states with the same boundary value settle to the same observer-facing quotient normal form: \[B([s])=B([s'])\implies \overline{\operatorname{nf}}_\lambda([s]) = \overline{\operatorname{nf}}_\lambda([s']).\]

Proof. Theorem 43 gives unique quotient normal forms \(\overline{\operatorname{nf}}_\lambda([s])\) and \(\overline{\operatorname{nf}}_\lambda([s'])\) in \(q(C)\). Boundary preservation along accepted repair sequences gives \[B(\overline{\operatorname{nf}}_\lambda([s]))=B([s]), \qquad B(\overline{\operatorname{nf}}_\lambda([s']))=B([s']).\] If \(B([s])=B([s'])=b\), both quotient normal forms lie in \(C_b\). By the unique consistent extension assumption, \(C_b\) has at most one element, so the quotient normal forms are equal. ◻

Remark 46 (Same-source and cross-source quantifiers). Theorem 31 compares repair schedules from one fixed initial source. The stronger comparison of endpoints reached from different sources with the same protected boundary is controlled by the consistent boundary fibers. Under boundary preservation and \(\operatorname{NF}=q(C)\), Ref. [source] proves that cross-source endpoint agreement, modulo any declared silent equivalence, is equivalent to injectivity of the induced boundary map on the consistent quotient. Weak normalization and all-schedule liveness are separate premises. The layered and functional carriers below establish the injectivity premise on their declared domains. On the verified rooted-tree packet-net domain of Definition 19, the declared boundary map is the root-packet readback, and its injectivity modulo hidden-label gauge on the consistent set is established class-wide, together with the resulting cross-source endpoint form for the tree repair. Same-source confluence alone does not establish the injectivity premise for an arbitrary physical boundary map, and outside the declared domains it is a named per-net hypothesis with explicit failure witnesses.

A multi-edge finite carrier for boundary reconstruction

Definition 47 (Layered functional boundary carrier). A layered functional boundary carrier is a finite directed layered graph \[G=(V,E),\qquad V=L_0\sqcup L_1\sqcup\cdots\sqcup L_D,\] with \(D\ge2\). The boundary layer is \(L_0\). For each \(v\in L_d\), \(d\ge1\), choose a nonempty parent set \[P(v)\subseteq L_0\sqcup\cdots\sqcup L_{d-1}\] and a finite alphabet \(A_v\). Each interior vertex has a deterministic local rule \[F_v:\prod_{u\in P(v)}A_u\to A_v.\] The carrier is genuinely multi-edge when at least two dependency edges occur and at least one layer contains more than one dependency or more than one repaired vertex.

The quotient state space is \[Q=\prod_{v\in V}A_v,\] and the boundary map is \[B:Q\to\prod_{v\in L_0}A_v,\qquad B(a)=a|_{L_0}.\] Given boundary data \(b\in\prod_{v\in L_0}A_v\), define its functional extension \(E(b)\in Q\) recursively by \[E(b)_v=b_v\quad(v\in L_0),\] and, for \(v\in L_d\), \(d\ge1\), \[E(b)_v=F_v\bigl((E(b)_u)_{u\in P(v)}\bigr).\] Optional cross-check edges may be included by choosing finite predicates \[\chi_e(a_u,a_v)=0.\] A state \(a\in Q\) is consistent when every interior functional equation \[a_v=F_v\bigl((a_u)_{u\in P(v)}\bigr)\] holds and all cross-check predicates pass. Let \(C_Q\) be the set of consistent states. A boundary \(b\) is admissible when \(E(b)\in C_Q\); equivalently, \[C_Q=\{\,E(b):b\text{ admissible}\,\}.\] For each layer \(d=1,\ldots,D\), define a layer repair map \(R_d:Q\to Q\) by \[(R_d(a))_v= \begin{cases} F_v((a_u)_{u\in P(v)}),& v\in L_d,\\ a_v,& v\notin L_d. \end{cases}\] The full staged repair sweep is \[R_{\mathrm{sweep}}=R_D\circ R_{D-1}\circ\cdots\circ R_1.\] Gauge representatives may be added by replacing \(A_v\) with \(A_v\times H_v\), letting \(\Gamma_v\) act only on \(H_v\), and defining all boundary and consistency maps through the \(A_v\)-coordinate. The quotient is then the \(Q\) above.

Theorem 48 (Layered carrier proves \(H_B\wedge H_{\mathrm{fib}}\)). Let \(G\) be a layered functional boundary carrier. For every initial quotient state \(a\in Q\), set \[a^{(0)}=a,\qquad a^{(d)}=R_d(a^{(d-1)}),\quad d=1,\ldots,D.\] Let \(b=B(a)\). Then \[B(a^{(d)})=b \qquad \text{for all }d=0,\ldots,D.\] If \(b\) is admissible, then \[a^{(D)}=E(b)\in C_Q.\] The consistent boundary fiber is a singleton: \[C_Q\cap B^{-1}(b)=\{E(b)\}.\] Thus preserved boundary data plus consistency reconstruct the observer-facing quotient bulk on this carrier.

Proof. Boundary preservation is immediate because each \(R_d\) writes only layer \(L_d\), with \(d\ge1\). No \(R_d\) writes \(L_0\), so \(B(a^{(d)})=B(a)=b\) for every stage.

We prove by induction on \(d\) that after stage \(d\), \[a^{(d)}_v=E(b)_v \qquad \text{for every }v\in L_0\sqcup\cdots\sqcup L_d.\] For \(d=0\), this is the definition of \(b\). Assume the claim holds through layer \(d-1\), and let \(v\in L_d\). Every parent \(u\in P(v)\) lies in an earlier layer, so \(a^{(d-1)}_u=E(b)_u\). The layer repair therefore gives \[a^{(d)}_v = F_v\bigl((a^{(d-1)}_u)_{u\in P(v)}\bigr) = F_v\bigl((E(b)_u)_{u\in P(v)}\bigr) = E(b)_v.\] Earlier layers are not modified by \(R_d\), so the induction closes. At \(d=D\), all layers agree with \(E(b)\). If \(b\) is admissible, \(E(b)\in C_Q\).

For boundary-fiber uniqueness, let \(c\in C_Q\cap B^{-1}(b)\). Since \(c\) has boundary \(b\), it agrees with \(E(b)\) on \(L_0\). Since \(c\in C_Q\), every interior vertex satisfies \[c_v=F_v((c_u)_{u\in P(v)}).\] The same induction on layers gives \(c_v=E(b)_v\) for every vertex. Hence \(c=E(b)\). ◻

Corollary 49 (Boundary reconstruction by global Repair). Assume the layered carrier’s layer updates are included among the accepted aggregate transactions of an OPH-admissible finite quotient repair presentation, and let \(b=B(x)\) be admissible. Then \[\operatorname{Rep}_\lambda(x)=E(b).\] Consequently, for every physical readout \[\operatorname{Read}:Q\to\mathcal Y\] that factors through the quotient normal form, \[\operatorname{Read}(\operatorname{Rep}_\lambda(x)) = \operatorname{Read}(E(B(x))).\]

Proof. By Theorem 15, \[\operatorname{Rep}_\lambda(x)\in C_Q \qquad\text{and}\qquad B(\operatorname{Rep}_\lambda(x))=B(x)=b.\] Therefore \(\operatorname{Rep}_\lambda(x)\in C_Q\cap B^{-1}(b)\). Theorem 48 identifies this fiber with \(\{E(b)\}\), so \(\operatorname{Rep}_\lambda(x)=E(b)\). Applying \(\operatorname{Read}\) gives the readout statement. ◻

Finite binary audit fixture: a sharp reconstruction carrier

The layered carrier above proves boundary reconstruction for a feed-forward finite class. A useful stress test for the same logic is a two-neighbor linear binary update on a finite cylinder. A row is a function \[x_t:\mathbb Z_n\to\mathbb F_2,\] and the update rule is \[x_{t+1}(j)=x_t(j-1)+x_t(j+1)\pmod 2.\] This update is not a proposed microscopic physics law. It is a minimal finite-consensus fixture: the local rule is linear, all records are exact finite objects, and boundary reconstruction can be tested without continuum or geometric assumptions.

For the time slab \(0,\ldots,t\), a two-column timelike tube \[\{j_0,j_0+g\}\times\{0,\ldots,t\}\] is an information set when its values determine the whole finite spacetime record. The sharp two-column classification: \[\text{tube}(g)\text{ is an information set} \quad\Longleftrightarrow\quad \gcd(g,n)=1\ \text{ and }\ n\le 2(t+1).\] Thus adjacent columns (\(g=1\)) achieve the full capacity threshold, while a non-coprime stride loses information at every horizon. The same fixture also separates realizable from unrealizable boundary readings: if a tube reading is not carried by any consistent record, no boundary-preserving repair operator can make it consistent without changing the boundary.

The audit then assembles a Route-A repair on this same carrier. The positive operator is a local transactional decoder: each transaction writes one non-tube cell using a bounded edge-local window, the declared rank schedule terminates in one finite pass, and the tube reading is preserved at every accepted step. At the sharp threshold \(n\le2(t+1)\), any two records with the same tube reading settle to the same normal form; the settled world is consistent exactly when the tube fiber is realizable.

The same formal fixture supplies the important negative controls. On this binary cylinder there is no single-patch frustration-free local repair satisfying the strongest \(H_1\wedge H_2\wedge H_3\) binder form. The canonical single-patch repair can also stall on the smallest audit witness \((n,t)=(3,2)\), leaving a broken edge in normal form. This is not a failure of the positive decoder; the stalled record has an unrealizable tube fiber. The lesson for OPH is structural: boundary reconstruction is theorem-grade only after the preserved boundary, realizable-fiber condition, and declared repair roster are specified. A bare local-update slogan is too weak.

Theorem 50 (Functional selected-fiber uniqueness). Let \(Q_b:=B^{-1}(b)\subseteq\Sigma/\Gamma\) be a same-boundary quotient fiber presented on a rooted finite overlap graph with spanning tree \(T\), root \(r\), and patch state sets \(X_v\). Assume the boundary value fixes the root value \[u_r=\beta(b),\] and every non-root vertex has a deterministic extension map \[f_v:X_{p(v)}\times\mathcal B\to X_v .\] Define \(u_b\) recursively by \[u_v=f_v(u_{p(v)},b).\] Evaluate all non-tree overlap equations, sector constraints, and holonomy checks on this candidate. If they all pass, then \(C_b=\{u_b\}\). If any check fails, then \(C_b=\varnothing\).

Proof. Every consistent state in \(Q_b\) must have root value \(\beta(b)\). Along each tree edge, the deterministic extension equation forces the child value to be \(f_v(u_{p(v)},b)\). Induction over tree depth therefore forces every consistent state in the fiber to equal the single recursively constructed candidate \(u_b\). The remaining constraints are exactly the non-tree overlaps, sector equations, and holonomy checks. If they pass, \(u_b\) is a consistent state and no other state can be. If one fails, the only tree-compatible candidate is inconsistent, so no element of \(C_b\) exists. ◻

The layered functional carrier of Theorem 48 is the finite multi-edge, multi-step witness that the boundary-fiber hypothesis is non-vacuous beyond one-dimensional propagation intuition.

Proposition 51 (Tree repair realizes the selected extension). Under the hypotheses of Theorem 50, choose positive weights \[w_v>\sum_{c:p(c)=v}w_c\] and set \[\Phi_T(x)=\sum_{v\ne r}w_v\,\mathbf 1[x_v\ne f_v(x_{p(v)},b)] .\] The repair that sets a non-root vertex to \(f_v(x_{p(v)},b)\) strictly decreases \(\Phi_T\), and the aggregate transaction for a connected tree-repair conflict component computes the same result in increasing tree depth.

Proof. Repairing \(v\) removes the \(v\)-term of weight \(w_v\). Only children of \(v\) can become unmatched, contributing at most \(\sum_{c:p(c)=v}w_c\), which is strictly smaller than \(w_v\). Thus the tree potential decreases. For a connected conflict component, applying parent repairs before child repairs is forced by the same extension equations, and any different parenthesization has the same quotient result because each child value is a deterministic function of the repaired parent and \(b\). ◻

Corollary 52 (Nontrivial branch elimination). Assume transactional confluence, boundary preservation, repair completeness, and Theorem 50. If a selected boundary fiber has \(|Q_b|\ge2\) and \(C_b=\{u_b\}\), then \[\overline{\operatorname{nf}}_\lambda(Q_b)=\{u_b\},\] while \(Q_b\setminus C_b\ne\varnothing\). Thus multiple candidate interiors exist, inconsistent candidates are eliminated by repair, and all surviving candidates share one quotient normal form. If \(C_b=\varnothing\), the branch is obstructed. If a union solver returns two physically distinct consistent quotient endpoints for the same selected data, the result is an ambiguous union repair and requires an explicit continuation gate, not selection by hash.

Remark 53 (Receipts do not replace the theorem). Implementation receipts named seam descent, atomic commit, distributed local diamond, repair completeness, same-boundary multistart confluence, and quotient normal-form canonical hash are public evidence contracts for the finite theorem hypotheses above. They are not proof substitutes. In particular, a normal-form hash certifies that two emitted quotient normal forms agree after the declared quotienting; it is not allowed to choose between two physically distinct minimizing states. The same convention applies to continuation receipts used by implementation evidence. A receipt is a compact name for primitive evidence and residual checks. Producer-declared booleans, labels, hashes, or successful plots cannot override failed residuals, missing objects, or undeclared quotient maps. When a later paper names a physical receipt, the evidence bundle must expose the raw objects needed to recompute it.

Corollary 54 (Gauge-invariant law). If \(M:\Sigma\to Y\) is gauge-invariant (\(M(\gamma\cdot s)=M(s)\) for all \(\gamma\)), then \(M(\operatorname{nf}_\lambda(s))\) depends only on the gauge orbit \([s]\), not the representative.

Proof. Because \(M\) is gauge-invariant, it factors through the orbit map: \(M=\overline M\circ q\) for some \(\overline M:\Sigma/\Gamma\to Y\). Theorem 43 gives \[q\bigl(\operatorname{nf}_\lambda(\gamma\cdot s)\bigr) = q\bigl(\operatorname{nf}_\lambda(s)\bigr),\] hence \[M\bigl(\operatorname{nf}_\lambda(\gamma\cdot s)\bigr) = \overline M\!\left(q\bigl(\operatorname{nf}_\lambda(\gamma\cdot s)\bigr)\right) = \overline M\!\left(q\bigl(\operatorname{nf}_\lambda(s)\bigr)\right) = M\bigl(\operatorname{nf}_\lambda(s)\bigr).\] ◻

Remark 55 (Sphere folding as quotient readout). When a spherical support chart \(\chi_{S,r}\) is supplied by the screen-microphysics branch, the folded screen presentation of a finite state \(s\) is \[\operatorname{Fold}_{S,r}(s) = \chi_{S,r}\!\left(n_r(\pi_r(s))\right).\] Here \(\pi_r\) passes to the physical quotient and \(n_r\) is the accepted repair normal-form map. The word “folding” therefore names a readout of the same quotient normal form studied in this paper. It does not add a repair law, force term, or hidden state variable.

Definition 56 (Physical observable algebra on the quantum lift). Fix a finite patch region or union collar \(R\) on the declared fixed-cutoff quantum lift of Appendix 16. Its physical observable algebra \(\mathcal A_{\mathrm{phys}}(R)\) is the fixed-point collar algebra under the compact boundary redundancy action on the ordinary or central-defect branch, or the corresponding quotient-local algebra on the genuinely noncentral branch. The central sector projectors carried by the collar decomposition belong to \(Z(\mathcal A_{\mathrm{phys}}(R))\). A physical observable is any \(X\in \mathcal A_{\mathrm{phys}}(R)\). For a microscopic representative \(s\in\Sigma\), let \(\omega_R^s\) denote the induced state on \(\mathcal A_{\mathrm{phys}}(R)\).

Theorem 57 (Observable-level confluence on the quantum lift). Under the hypotheses of Theorems 31 and 43, every initial orbit \([s]\in\Sigma/\Gamma\) has a unique quotient normal form \[\overline{\operatorname{nf}}_\lambda([s])\in q(C).\] Fix a declared region \(R\). Let \(t,u\in\Sigma\) be terminal microscopic representatives reached by representative lifts of maximal repair sequences from initial states in the same orbit \([s]\). If the induced \(R\)-collar states of \(t\) and \(u\) are representatives of the same quotient-local glued state in the sense of Proposition 106, then for every physical observable \(X\in\mathcal A_{\mathrm{phys}}(R)\), \[\omega_R^t(X)=\omega_R^u(X).\] Hence all physical observables converge to the same overlap-consistent values even when the microscopic terminal representatives differ by gauge relabelings globally or by sector/higher-gauge relabelings inside one declared quotient-local glued state.

Proof. Theorems 31 and 43 give the unique quotient normal form \(\overline{\operatorname{nf}}_\lambda([s])=[\operatorname{nf}_\lambda(s)]\in q(C)\). Let \(t\) and \(u\) be as stated. By Corollary 108, representatives of the same quotient-local glued state induce the same state on the physical observable algebra \(\mathcal A_{\mathrm{phys}}(R)\), including the central sector projectors carried by that algebra. Therefore \(\omega_R^t(X)=\omega_R^u(X)\) for every \(X\in\mathcal A_{\mathrm{phys}}(R)\). ◻

Remark 58 (Inputs and boundary for observable-level confluence). Theorem 57 does not add a new repair hypothesis beyond the confluence and fixed-cutoff gluing package. Its inputs are exactly the quotient-level confluence theorem, quotient descent of the repair law, Definition 56, and Corollary 108 from the fixed-cutoff union-collar gluing package. The boundary item is extension of the same statement to broader refinement-stable branches where the declared union-collar compatibility is only approximate or where the chosen physical observable algebra itself changes under refinement.

Corollary 59 (Inert ancillary refinement does not change physical law). Let \(K=\prod_i K_i\) be a finite ancillary state space and define \(\Sigma^\eta:=\Sigma\times K\). Lift the repair maps by \[T_i^{\lambda,\eta}(s,k):=(T_i^\lambda(s),k).\] If \(M^\eta:\Sigma^\eta\to Y\) ignores the ancillary factor, \[M^\eta(s,k)=M(s),\] with \(M\) gauge-invariant on \(\Sigma\), then \[M^\eta(\operatorname{nf}_\lambda^\eta(s,k)) = M(\operatorname{nf}_\lambda(s))\] for all \((s,k)\in\Sigma^\eta\).

Proof. Because the ancillary factor is inert, \[\operatorname{nf}_\lambda^\eta(s,k)=\bigl(\operatorname{nf}_\lambda(s),k\bigr).\] Therefore \(M^\eta(\operatorname{nf}_\lambda^\eta(s,k))=M(\operatorname{nf}_\lambda(s))\), and Corollary 54 supplies gauge-orbit independence. ◻

Physical uniqueness therefore holds on the quotient by gauge or implementation hiding. The same statement is unchanged under inert ancillary stabilization.

Definition 60 (Finite packet closure simplex). Assume the finite fixed-cutoff consensus branch of Theorems 31 and 43, so the physical quotient \(Q:=\Sigma/\Gamma\) is finite and carries the schedule-independent quotient normal-form map \[\overline{\operatorname{nf}}_\lambda:Q\to Q.\] Let \[N_\lambda:=\overline{\operatorname{nf}}_\lambda(Q)=q(C)\] be the quotient normal-form set. The finite packet simplex on \(Q\) is \[\Delta(Q):= \left\{ \mu:Q\to\mathbb R_{\ge0}\ \middle|\ \sum_{x\in Q}\mu(x)=1 \right\},\] and the finite packet closure map is the pushforward \[\mathcal C_\lambda:\Delta(Q)\to\Delta(Q), \qquad \mathcal C_\lambda(\mu):= \bigl(\overline{\operatorname{nf}}_\lambda\bigr)_*\mu,\] equivalently \[\mathcal C_\lambda(\mu)(y) = \sum_{\substack{x\in Q\\ \overline{\operatorname{nf}}_\lambda(x)=y}}\mu(x).\]

Theorem 61 (Finite packet-quotient closure map). On the finite fixed-cutoff consensus branch of Definition 60, the map \(\mathcal C_\lambda\) is an affine continuous idempotent self-map of \(\Delta(Q)\). Its image is exactly the normal-form simplex \[\Delta(N_\lambda) = \left\{ \mu\in\Delta(Q)\ \middle|\ \operatorname{supp}(\mu)\subseteq N_\lambda \right\}.\] Hence the fixed points of \(\mathcal C_\lambda\) are exactly the packets supported on quotient normal forms. For every initial quotient state \([s]\in Q\), \[\mathcal C_\lambda(\delta_{[s]}) = \delta_{\overline{\operatorname{nf}}_\lambda([s])}.\]

Proof. Because \(\overline{\operatorname{nf}}_\lambda:Q\to Q\) is a set map on a finite set, its pushforward on probability packets is affine and continuous in the finite-dimensional simplex topology.

By Theorems 31 and 43, the quotient normal form is schedule-independent and terminal, so \[\overline{\operatorname{nf}}_\lambda\circ\overline{\operatorname{nf}}_\lambda = \overline{\operatorname{nf}}_\lambda.\] Pushforward therefore gives \[\mathcal C_\lambda^2 = \bigl(\overline{\operatorname{nf}}_\lambda\bigr)_* \bigl(\overline{\operatorname{nf}}_\lambda\bigr)_* = \bigl(\overline{\operatorname{nf}}_\lambda\circ\overline{\operatorname{nf}}_\lambda\bigr)_* = \mathcal C_\lambda,\] so \(\mathcal C_\lambda\) is idempotent.

If \(\nu=\mathcal C_\lambda(\mu)\), then every point in \(\operatorname{supp}(\nu)\) lies in the image of \(\overline{\operatorname{nf}}_\lambda\), namely \(N_\lambda\). Thus \(\operatorname{im}(\mathcal C_\lambda)\subseteq \Delta(N_\lambda)\). Conversely, if \(\nu\in\Delta(N_\lambda)\), then \(\overline{\operatorname{nf}}_\lambda(y)=y\) for every \(y\in N_\lambda\), so \[\mathcal C_\lambda(\nu)=\nu.\] Hence \(\Delta(N_\lambda)\subseteq \operatorname{im}(\mathcal C_\lambda)\), proving \(\operatorname{im}(\mathcal C_\lambda)=\Delta(N_\lambda)\). The same identity shows that \(\nu\) is a fixed point if and only if it is supported on \(N_\lambda\). The Dirac-mass formula is the pushforward of a point mass under \(\overline{\operatorname{nf}}_\lambda\). ◻

Remark 62 (Boundary of the finite closure theorem). Theorem 61 is an exact finite-branch result. It proves a closure map only on the finite packet simplex built from one fixed quotient carrier whose repair law is terminating, confluent, and quotient-descended. It does not prove a habitat-level closure map for arbitrary OPH state-and-law data, does not identify a nonempty observer-supporting invariant sector inside the Appendix-B habitat, and does not supply uniqueness or stability estimates beyond this finite packet branch.

Refinement-Limit Consensus Classes

The finite consensus theorem is the operational object used by the continuum branches. To pass from one finite patch net to a refining family, the paper uses an explicit inverse-limit package with named compatibility clauses.

Definition 63 (Separated cofinal refinement consensus system). Let \((R,\preceq)\) be a directed refinement set. For each \(r\in R\), let \[Q_r:=\Sigma_r/\Gamma_r\] be the finite physical quotient state space of a patch presentation, let \[n_r:Q_r\to Q_r\] be the finite-stage quotient normal-form map supplied by Theorems 31 and 43, and let \[h_r:Q_r\to \mathcal H_r\] be the finite-stage holonomy or higher-gauge obstruction map supplied by Theorems 38 and 41. For \(r\preceq s\), assume restriction maps \[\rho_{sr}:Q_s\to Q_r, \qquad \chi_{sr}:\mathcal H_s\to\mathcal H_r,\] with \(\rho_{rr}=\mathrm{id}\), \(\chi_{rr}=\mathrm{id}\), and the cocycle identities \[\rho_{tr}=\rho_{sr}\circ\rho_{ts}, \qquad \chi_{tr}=\chi_{sr}\circ\chi_{ts} \qquad (r\preceq s\preceq t).\] The system is a separated cofinal refinement consensus system when:

  1. Normal-form naturality: \[\rho_{sr}\circ n_s=n_r\circ\rho_{sr} \qquad (r\preceq s).\]

  2. Holonomy naturality: \[\chi_{sr}\circ h_s=h_r\circ\rho_{sr} \qquad (r\preceq s).\]

  3. Visible separation: two compatible families in \(\varprojlim Q_r\), or in \(\varprojlim \mathcal H_r\), are equal whenever their projections agree on a cofinal subset of stages.

Theorem 64 (Refinement-limit consensus and holonomy classes). For any separated cofinal refinement consensus system, the formulas \[n_\infty\bigl((x_r)_r\bigr):=(n_r(x_r))_r, \qquad h_\infty\bigl((x_r)_r\bigr):=(h_r(x_r))_r\] define maps \[n_\infty:\varprojlim Q_r\to\varprojlim Q_r, \qquad h_\infty:\varprojlim Q_r\to\varprojlim\mathcal H_r.\] The class \(n_\infty(x)\) is the unique schedule-independent refinement-limit normal form of \(x\). The class \(h_\infty(x)\) is the refinement-limit holonomy obstruction. The pair \((n_\infty(x),h_\infty(x))\) is the refinement-limit consensus class. In the inverse-limit topology, finite-stage normal forms and holonomy classes converge to these two classes: for every stage \(r\), all refinements \(s\succeq r\) restrict to the fixed values \[\rho_{sr}(n_s(x_s))=n_r(x_r), \qquad \chi_{sr}(h_s(x_s))=h_r(x_r).\] The relation \(h_\infty(x)=0\) holds if and only if every finite projection has zero finite-stage obstruction. If \(h_\infty(x)\ne0\), visible separation gives a finite stage that witnesses the nonzero obstruction. If two refinement-limit candidates have the same normal-form and holonomy projections on a cofinal tail, then they determine the same refinement-limit consensus class.

Proof. Let \(x=(x_r)_r\in\varprojlim Q_r\), so \(\rho_{sr}(x_s)=x_r\) for \(r\preceq s\). Normal-form naturality gives \[\rho_{sr}(n_s(x_s)) = n_r(\rho_{sr}(x_s)) = n_r(x_r),\] so \((n_r(x_r))_r\) is a compatible family and \(n_\infty\) is well defined. The same argument with holonomy naturality gives \[\chi_{sr}(h_s(x_s)) = h_r(\rho_{sr}(x_s)) = h_r(x_r),\] so \(h_\infty\) is well defined.

Each finite \(n_r(x_r)\) is independent of update schedule by Theorems 31 and 43. Therefore every finite projection of \(n_\infty(x)\) is schedule-independent, and visible separation makes the inverse-limit class unique. The displayed restriction identities are exactly the cylinder convergence statement in the inverse-limit topology.

The zero-obstruction statement follows from the definition of the inverse-limit zero class. The identity \(h_\infty(x)=0\) holds exactly when every projection \(h_r(x_r)\) is zero. If \(h_\infty(x)\ne0\), at least one finite projection is nonzero, and any cofinal tail containing a refinement of that stage carries the same nonzero projected obstruction by holonomy naturality. The last claim is visible separation applied to the compatible normal-form and holonomy families. ◻

Remark 65 (Scope of the refinement theorem). Theorem 64 is a controlled inverse-limit bridge. It proves persistence, exhaustion, and collapse of the consensus data once the OPH refinement system supplies the restriction maps and the two naturality clauses in Definition 63. It leaves uniform complexity bounds, automatic fair-block noisy-consensus certificates, and automatic normal-form naturality for arbitrary changing repair laws as separate branch conditions. It does not identify this inverse limit with a physical continuum or spacetime.

Definition 66 (Repair morphism). Let \((Q_s,\to_s,C_s,n_s)\) and \((Q_r,\to_r,C_r,n_r)\) be two finite quotient repair systems covered by Theorems 31 and 43. A map \[\rho_{sr}:Q_s\to Q_r\] is a repair morphism when:

  1. every fine repair step \(x\to_s y\) maps to a coarse repair path or a stutter, \[\rho_{sr}(x)\to_r^*\rho_{sr}(y);\]

  2. fine consistency maps into coarse consistency, \[\rho_{sr}(C_s)\subseteq C_r.\]

For a concrete local repair law this is checked by giving, for every fine repair generator, a coarse witness word in the accepted coarse repair generators or the empty word, and by verifying that the restriction maps carry every fine consistency equation to a coarse consistency equation.

Theorem 67 (Normal-form naturality from repair morphisms). If \(\rho_{sr}:Q_s\to Q_r\) is a repair morphism, then \[\rho_{sr}\circ n_s=n_r\circ\rho_{sr}.\]

Proof. Fix \(x\in Q_s\). Since \(x\to_s^* n_s(x)\), repeated use of the step-simulation clause gives \[\rho_{sr}(x)\to_r^*\rho_{sr}(n_s(x)).\] The consistency-preservation clause gives \(\rho_{sr}(n_s(x))\in C_r\), because \(n_s(x)\in C_s\). Thus \(\rho_{sr}(n_s(x))\) is a coarse normal form reachable from \(\rho_{sr}(x)\). The coarse system has a unique normal form reachable from each initial quotient state, so \(\rho_{sr}(n_s(x))=n_r(\rho_{sr}(x))\). ◻

Definition 68 (Holonomy cochain morphism). For obstruction maps \(h_s:Q_s\to\mathcal H_s\) and \(h_r:Q_r\to\mathcal H_r\), a map \(\chi_{sr}:\mathcal H_s\to\mathcal H_r\) is a holonomy cochain morphism when the edge, cycle, or crossed-module cochains that compute \(h_s\) restrict to the cochains that compute \(h_r\), modulo the declared quotient identifications. Equivalently, \[\chi_{sr}\circ h_s=h_r\circ\rho_{sr}.\]

Remark 69 (How exact refinement naturality is discharged). Definition 63 may be used as an interface contract, but on an implemented exact branch the normal-form part is proved by Theorem 67 from explicit coarse witness words for fine repairs. The holonomy part is proved by the cochain morphism check of Definition 68. Approximate RG branches use the controlled defects of Definition 70 instead.

Definition 70 (Controlled coarse-graining / reconciliation square). Fix refinement stages \(r\preceq s\). Let \(Q_r,Q_s\) be the physical quotient state spaces, \(n_r,n_s\) their finite-stage normal-form maps, and \(h_r,h_s\) their holonomy or higher-gauge obstruction maps. Let \[\rho_{sr}:Q_s\to Q_r, \qquad \chi_{sr}:\mathcal H_s\to\mathcal H_r\] be the coarse-graining maps on quotient states and obstruction data. Equip \(Q_r\) and \(\mathcal H_r\) with pseudometrics \(d^Q_r\) and \(d^{\mathcal H}_r\) that define the macroscopic readout scale at stage \(r\).

The square is \((\varepsilon^n_{sr},\varepsilon^h_{sr})\)-controlled when, for every \(x\in Q_s\), \[d^Q_r\!\left(\rho_{sr}(n_s(x)),\,n_r(\rho_{sr}(x))\right) \le \varepsilon^n_{sr},\] and \[d^{\mathcal H}_r\!\left(\chi_{sr}(h_s(x)),\,h_r(\rho_{sr}(x))\right) \le \varepsilon^h_{sr}.\] The errors are cofinally vanishing when, for every fixed macroscopic stage \(r\) and every \(\delta>0\), there is a refinement stage \(s_0\succeq r\) such that \(\varepsilon^n_{sr},\varepsilon^h_{sr}<\delta\) for all \(s\succeq s_0\).

Theorem 71 (Coarse-graining commutes with reconciliation up to controlled error). Suppose the refinement square of Definition 70 is \((\varepsilon^n_{sr},\varepsilon^h_{sr})\)-controlled. Define the coarse-stage consensus readout \[\mathcal C_r(y):=(n_r(y),h_r(y))\] and the fine-then-coarse readout \[\mathcal C_{s\to r}^{\mathrm{fine}}(x):=(\rho_{sr}(n_s(x)),\chi_{sr}(h_s(x))).\] Then, for every fine state \(x\in Q_s\), the product readout distance between \(\mathcal C_{s\to r}^{\mathrm{fine}}(x)\) and \(\mathcal C_r(\rho_{sr}(x))\) is bounded by \[\max\{\varepsilon^n_{sr},\varepsilon^h_{sr}\}.\] Thus reconciling at the fine stage and then coarse-graining gives the same macroscopic law data as coarse-graining first and reconciling at the coarse stage, up to the declared control errors. If the exact naturality clauses of Definition 63 hold, then \(\varepsilon^n_{sr}=\varepsilon^h_{sr}=0\). If the errors are cofinally vanishing, then at every fixed macroscopic stage the supremum product-pseudometric distance between the two readouts tends to zero along the refinement tail. Equality of inverse-limit cylinder values additionally requires a compatible limiting family and a separated quotient or other completeness/separation hypotheses; it does not follow from vanishing pseudometric defects alone.

Proof. The normal-form component of the product readout is bounded by the first inequality in Definition 70, and the obstruction component is bounded by the second. Taking the maximum gives the stated product bound. Exact naturality is precisely the special case \[\rho_{sr}\circ n_s=n_r\circ\rho_{sr}, \qquad \chi_{sr}\circ h_s=h_r\circ\rho_{sr},\] so both errors vanish there. Cofinal vanishing means that, for any fixed coarse stage and any desired readout tolerance, all sufficiently fine presentations put the two readouts within that tolerance uniformly over the fine state. This proves asymptotic zero distance and nothing stronger without the additional limit compatibility and separation clauses stated in the theorem. ◻

Remark 72 (Scope of the coarse-graining theorem). Theorem 71 is not a claim that arbitrary renormalization maps commute with arbitrary repair laws. Its conclusion requires control of the two square defects \(\varepsilon^n_{sr}\) and \(\varepsilon^h_{sr}\), derived or estimated from the chosen coarse-graining channel, recovery map, decoder, and obstruction readout. The exact refinement theorem is the zero-defect case; approximate RG matching is theorem-grade only when these defects are explicitly controlled.

Record Algebras and the Operator Observation Layer

Inputs used here.

From the fixed-cutoff collar package we use only the observer-accessible finite-dimensional algebra on one completed compare/write/verify slice, the declared pointer and overlap-sector projectors read on that same slice, and the trace-distance control on restored accessible states when restoration is invoked. No continuum lift and no broader observer-metaphysical assumption is used here.

Definition 73 (Exact record algebras and approximate record presentations). Fix one completed observer-accessible slice at cycle \(t\), and let \(\mathcal A_t^{\mathrm{acc}}\) be the corresponding finite-dimensional accessible algebra. An exact record presentation is a family of orthogonal projectors \(\{\widehat P_a(t)\}_a\subset Z(\mathcal A_t^{\mathrm{acc}})\) whose generated algebra \[\mathcal Z_{\mathrm{rec}}(t) := \mathrm{Alg}\bigl(\{\widehat P_a(t)\}_a\bigr)\] is finite and commutative.

An approximate record presentation on the same declared readout slots is a family of projectors \(\{P_a(t)\}_a\subset \mathcal A_t^{\mathrm{acc}}\) together with an exact record presentation \(\{\widehat P_a(t)\}_a\) such that \[\delta_{\mathrm{rec}}(t) := \max_a \|P_a(t)-\widehat P_a(t)\|\] is finite.

Theorem 74 (Record algebra, declared Born–Lüders instrument, and quantitative stability). Fix one completed observer-accessible slice at cycle \(t\), supply a density state \(\rho_t\), use its trace valuation for event probabilities, and declare the selective outcome instrument to be the Lüders map for the displayed record projectors.

  1. The exact record projectors generate a finite commutative central algebra \(\mathcal Z_{\mathrm{rec}}(t)\subset Z(\mathcal A_t^{\mathrm{acc}})\).

  2. For every event \(E\) in the finite event algebra generated by \(\mathcal Z_{\mathrm{rec}}(t)\), \[\mathbb P_t(E)=\operatorname{Tr}\!\bigl(\rho_t \widehat P_E(t)\bigr), \qquad \rho_t\!\mid_E = \frac{\widehat P_E(t)\rho_t \widehat P_E(t)} {\operatorname{Tr}(\rho_t \widehat P_E(t))}.\]

  3. Conditional on observing \(E\) with nonzero weight and applying the declared Lüders instrument, an immediate reread with the same projector has probability \(1\). The same conclusion after an intervening accepted operation requires the explicit persistence hypothesis that the resulting state remains supported in \(\widehat P_E(t)\).

  4. If \(\{P_a(t)\}_a\) is an approximate record presentation with modulus \(\delta_{\mathrm{rec}}(t)\), then \[\|[P_a(t),P_b(t)]\|\le 4\,\delta_{\mathrm{rec}}(t)\] for all declared record projectors \(P_a(t),P_b(t)\). For every declared elementary record event \(a\) and every restored accessible state \(\widetilde\rho_t\) satisfying \[\|\widetilde\rho_t-\rho_t\|_1\le \varepsilon,\] one has \[\Bigl| \operatorname{Tr}\!\bigl(\widetilde\rho_t P_a(t)\bigr) - \operatorname{Tr}\!\bigl(\rho_t \widehat P_a(t)\bigr) \Bigr| \le \varepsilon+\delta_{\mathrm{rec}}(t).\]

Proof. Because the exact record projectors lie in the center of \(\mathcal A_t^{\mathrm{acc}}\), they generate a finite commutative central algebra. The supplied trace valuation and declared Lüders instrument give the two formulas in (2); the projector algebra does not by itself select that instrument. This proves (1) and (2) under the displayed premises. The finite-matrix steps behind (1) and (2) are machine-checked in the companion Lean 4 event-algebra development [source]: the commutative span of a projective partition and its containment in the center of the partition commutant, the trace-preserving expectation onto that span, preservation of the partition Born statistics, the Lüders fixed-point law, and the collapse of conditioning on a partition member to its normalized projector are theorem-level exports with declaration-level axiom audits.

After the declared conditioning on a nonzero-weight event \(E\), the state lies in the range of \(\widehat P_E(t)\), so an immediate reread of the same projector has probability \(1\). More generally, the same calculation applies after an intervening operation when its output state is explicitly assumed to remain in that range. This gives (3); absence of a touched-support marker by itself is not used as a mathematical substitute for support preservation.

For (4), write \[[P_a(t),P_b(t)] = [P_a(t)-\widehat P_a(t),P_b(t)] + [\widehat P_a(t),P_b(t)-\widehat P_b(t)],\] because \([\widehat P_a(t),\widehat P_b(t)]=0\). Since every projector has operator norm at most \(1\), \[\|[P_a(t),P_b(t)]\| \le 2\|P_a(t)-\widehat P_a(t)\| + 2\|P_b(t)-\widehat P_b(t)\| \le 4\,\delta_{\mathrm{rec}}(t).\] For the probability bound, \[\Bigl| \operatorname{Tr}\!\bigl(\widetilde\rho_t P_a(t)\bigr) - \operatorname{Tr}\!\bigl(\rho_t \widehat P_a(t)\bigr) \Bigr| \le \Bigl|\operatorname{Tr}\!\bigl((\widetilde\rho_t-\rho_t)P_a(t)\bigr)\Bigr| + \Bigl|\operatorname{Tr}\!\bigl(\rho_t(P_a(t)-\widehat P_a(t))\bigr)\Bigr|.\] The first term is bounded by \(\|\widetilde\rho_t-\rho_t\|_1\|P_a(t)\|\le \varepsilon\), and the second by \(\|\rho_t\|_1\|P_a(t)-\widehat P_a(t)\|\le \delta_{\mathrm{rec}}(t)\). Hence the total error is at most \(\varepsilon+\delta_{\mathrm{rec}}(t)\). ◻

Fixed-cutoff observation boundary.

The theorem supplies a fixed-cutoff operator-algebraic observation surface: a central record algebra on the exact readout slice, a supplied Born valuation and declared Lüders instrument on its event projectors, exact repeated-read stability under the untouched-support hypothesis, and explicit \((\varepsilon,\delta_{\mathrm{rec}})\) control when practical readout projectors are only close to that central surface. It does not show that richer branches keep physically relevant pointer surfaces close to one such central record algebra or that the same control survives refinement and continuation.

Operational observers, event worlds, and coexisting regional algebras

The record-algebra layer extends upward, in the accompanying Lean development [source], to a machine-checked interface family in which the observer itself is a typed object. The base object is a consensus tower: a regulator-indexed family of finite matrix models carrying observer and record fibres, observer-indexed record orders, commutative public record subalgebras of the private matrix algebra, selected states and generators, and functorial refinement maps with compatibility laws. Seven Lean modules carry the layer:

, ,
, , ,
, .

The operational observerhood receipt.

An operational observer over a consensus tower carries six complete clause groups and the own-observer half of a seventh, each a finite statement about declared tower data:

  1. a bounded accessible interface: a declared accessible star subalgebra of the private algebra at each regulator, containing the observer’s own public record algebra;

  2. self-readback: a map on the private algebra sending each accessible element into the observer’s public record algebra and fixing every element of that algebra;

  3. durable records: the observer’s declared generator annihilates every record element;

  4. record-conditioned control: a record-indexed family of linear interventions preserving the accessible interface;

  5. no-regress prediction: a record-to-record map whose output never strictly precedes its input in the observer’s own record order;

  6. continuation: the observer label family and the prediction map commute with the declared refinement maps;

  7. own-observer readable evidence: a declared readout equal to the trace pairing of each record element against the observer’s state, with every record element fixed by every declared intervention.

The missing cross-observer half is supplied by a separate fixed-regulator receipt over two such observers and one access cut. Their labels are distinct, their accessible algebras agree with the cut, every committed record restricts to the same element through the two typed maps to the owner-region meet, the two own readouts agree, and at least one common restriction is nonzero. The common section is then accessible to both observers. A proper-meet witness uses diagonal algebras on two distinct owner regions, a scalar algebra on their bottom meet, and corner-evaluation restriction maps: the two local record representatives differ before restriction but agree nontrivially after it. Mutating one shared corner proves failure of the full overlap receipt. An event-world consumer additionally shows that one packet record visible in two owned charts restricts identically from the two owner regions and is fixed by both self-readbacks. This supplies the seven-clause operational contract at one regulator; refinement-natural cross-observer evidence and higher-overlap coherence are not supplied. Readback idempotence on the interface and refinement stability of the own readout are derived. The base witness data are exact and small: over a one-regulator tower with private algebra \(M_2(\mathbb C)\), the public algebra is the span of the two diagonal coordinate projectors, three records carry the strict chain order, the state is the first coordinate projector, the readback is the partition average, the generator is the \(i\)-scaled commutator with the Hamiltonian \(\operatorname{diag}(1,2)\), each intervention is conjugation by the involution \(\operatorname{diag}(1,-1)\), and the prediction advances records while holding the final record fixed. The generator annihilates every diagonal record element and moves the raising matrix unit, so durability is a computed fixed-point fact for a nonzero generator; the control fixes every record element and negates the raising matrix unit, so evidence invariance is computed against a map distinct from the identity. A nontriviality conjunction separates the witness from the constant adaptor: strict record precedence, a nonconstant non-identity prediction, a record element distinct from the zero and identity matrices, a nonzero generator, and a non-identity control. Four negative controls violate one attained field each on the same data: an erasing readback breaks the self-readback law, the identity generator breaks durability, a resetting prediction breaks no-regress, and a constant readout breaks the own-evidence pairing. The bounded receipt selects no unique observer, attaches no instrument, makes no consciousness claim, and supplies no source realization of the tower data.

Access cuts and the common-origin theorem.

A finite regional observer net enriches one consensus tower with a finite region order, per-region local star subalgebras, declared contravariant restrictions, elementwise commutation on declared-disjoint regions, regional expectations, and idempotent local repair. An access cut over such a net assigns each observer one declared support region and one accessible star subalgebra squeezed between the observer’s public record algebra and the regional algebra of the declared region, with the declared restrictions below that region preserving accessibility; stability under the local repair idempotents is a separate strengthening receipt. The observer-local algebra at a region is the meet of the regional local algebra with the accessible algebra, and the regional receipts (isotony, elementwise commutation on declared-disjoint regions, restriction stability, selected-state expectation compatibility, regional-repair fixed points, and remote nondisturbance) transport to this meet. Unique descent into the observer-local algebra is conditional on a separate accessible-glue receipt; ambient unique descent alone does not place a glued section in the accessible algebra, and the universal singleton-family packet keeps the receipt type inhabited without a nontrivial gluing claim.

A finite event world binds one packet to each event, with fixed finite event, chart, and packet carriers, declared active masks, chart ownership tying chart supports to observer regions, packet-derived support, record, and coordinate readouts, and the visibility law that an active visible event has support inside the seeing chart’s region. The common-origin theorem returns, for every active visible chart/event pair \((i,e)\), three conjuncts from one packet \(\mathsf p_e\): \[\operatorname{supp}(\mathsf p_e)\preceq R_{O(i)},\qquad \operatorname{rec}(\mathsf p_e)\in \mathcal L_{O(i)}\!\bigl(\operatorname{supp}(\mathsf p_e)\bigr)\cap \mathcal P_{O(i)},\qquad x_i(e)=\operatorname{geo}_i(\mathsf p_e),\] with \(O(i)\) the declared chart owner, \(R_{O(i)}\) its observer region, \(\mathcal L_{O(i)}\) its observer-local algebra, and \(\mathcal P_{O(i)}\) its public record algebra: event support below the owner’s region, record observable in the meet of the observer-local algebra at that support with the owner’s public algebra, and the soldering chart coordinate as a readout of the same packet. An event precedence adapter carries strict order data on event slots, tied to the owner’s record order on labeled events and identified with no repair schedule, modular parameter, clock reading, proper time, or global time function; where the events carry certified commit provenance, the source-derived construction below generates that order, and an exact adapter is its verifier rather than a choice of it. A selected coarse-to-fine refinement (slot maps for events, charts, and packets, with naturality for masks, ownership, regions, supports, packets, records, and visibility, plus a declared recharting map) transports the full common-origin conclusion, and raw event candidates with a declared semantic-coincidence setoid descend to the event quotient; a reflexive symmetric relation without transitivity admits no such setoid and is closed to the quotient constructor. The witness world reuses the dimension-two cut, whose interposition chain is strict (scalar public algebra inside the diagonal accessible algebra inside the private matrix algebra), and its record readout separates the two packets.

Source-derived event precedence from mismatch provenance.

Event precedence need not be declared where the source supplies provenance. In the companion machine-checked package, every quotient-visible register version carries the identifier of its last semantic writer, and each commit certifies the register versions on which its acceptance genuinely depends, with frame and stamp laws fixing unwritten registers and recording written ones. The causalSupp field is supplied semantic data: Lean checks that it lies inside the read set, while producer and independent-verifier receipts must establish that it is sound and complete for genuine dependence. It is not inferred by a kernel-checked dependence analysis. One commit is a direct semantic parent of another exactly when the child certifies a register that the parent wrote, the child’s pre-commit snapshot names the parent as that register’s writer, and the child’s pre-commit value equals the parent’s post-commit value. A writer label without the write and value witnesses does not create an edge. The generated informational order is the transitive closure of these edges. Under one abstract ancestry-rank witness that increases across every edge, the generated order is irreflexive, transitive, and asymmetric, and it inhabits the same strict-order interface the event precedence adapter consumes. It is the least strict transitive relation containing the direct parent edges, so an adapter that contains every edge and asserts no comparability beyond the generated order carries exactly the generated order. Geometry does not use the numerical values of this acyclicity witness; it recomputes canonical source height from authenticated parenthood. On the committed chain witness world, a two-commit log generates the declared adapter order in full, so the declaration there is a verifier rather than a choice.

An overlap’s mismatch score reads only the committed values on its support, so the score is writer-blind: two snapshots with identical values carry identical scores on every overlap, and a two-register countermodel realizes both parent attributions on value-identical snapshots. A static residual therefore determines no causal arrow; provenance is load-bearing for direction. A commit whose write set misses the support leaves the score unchanged, and a repair whose certified support does not cite the injected version acquires no injection-to-response edge. Under dependency-complete read sets, any two proposals able to move one seam score overlap read-against-write in both directions and land in one aggregate conflict component. Any aggregation map that is constant on conflict components assigns them one aggregate label; an empty-read countermodel shows the completeness clause is load-bearing. A four-commit log realizes the minimal branching interval: one injection, two responses each certifying exactly the injected register, and one answer certifying both outputs generate the four-element Boolean diamond with incomparable responses, while a parent-child pair alone spans the two-element interval. The serialization of the two responses is invisible to this order, because the second response’s snapshot contains the first response’s output without certifying it. Executed histories carry three further machine-checked controls. One adjacent independent swap preserves the authenticated direct-parent relation and its transitive closure when the two executions both satisfy fresh-ID and duplicate-free hypotheses and the commits’ write sets avoid each other and each other’s certified supports. The general equivalence-generated swap chain preserves only raw writer citation, not arbitrary labeled payloads. Executor stutters are removed before commits are formed. A dependent pair marks the boundary: swapping a writer past a reader that certifies the written register changes the edge set. On such histories the append-only acyclicity rank is derived from the execution position rather than declared. Independently of that witness, the geometry layer computes canonical source height from authenticated parenthood alone—zero at roots and one plus the maximum direct-parent height otherwise—proves that it is the attained longest authenticated-parent-chain length, and proves strict increase on every parent edge and generated ancestry. Under fresh identifiers, duplicate-free execution, and visible-support hypotheses, a commit writing only outside the visible register carrier changes no visible mismatch and supplies no outgoing direct raw or authenticated parent edge to a visibly supported child; incoming edges into the hidden commit are not excluded. A freshly injected mismatch persists at full strength through a continuation whose commits never write its overlap support. A refinement receipt assumes that its map carries every direct parent edge into the coarse reflexive precedence; under that assumption it transports the generated order and its causal intervals through coincidence merges. The reversed assignment on the committed diamond-to-chain witness inhabits no such receipt. The generated order is informational. No theorem here supplies invariance over the full admissible implementation class, event separation, physical causal faithfulness, or a Lorentzian continuum.

The generated structure meets two established programs. In causal set theory, a locally finite partial order represents proto-causality [sources]. The OPH order is finite and therefore locally finite, but its proved interpretation is semantic read-from dependence. It is thus causal-set-like rather than a physically attached causal set. The exact-embedding continuum route requires an order embedding whose image has the approximately Poisson count density needed for a causal-set faithful embedding, together with manifoldlikeness and dimension [sources]. In a past- and future-distinguishing continuum, causal order fixes conformal geometry [sources]; the volume datum fixes the conformal factor. The standard Lorentz-invariant continuum approximation uses Poisson sprinkling [source]; the OPH commit log is not a Poisson sprinkling, and its cardinality is not a spacetime volume. Neither continuum existence nor the causal-set Hauptvermutung follows from a finite order. In distributed computing the generated relation is an authenticated read-from dependence suborder and analogue of happened-before [source]; record or program order contributes only when a later commit genuinely consumes the earlier record. Its OPH-specific content is the binding to quotient-visible mismatch, certified read supports, writer-blind static scores, and the strict-order interface of the finite event world.

This gives a precise exact-to-conditional chain. Authenticated semantic provenance fixes the finite event carrier and generated order and computes that order’s exact longest authenticated-parent-chain height. Independently, the exact rank-three positive source Gram quotient supplies the spatial carrier. Its direct sum with a real axis, \[W_{\rm src}=\mathbb R\oplus V_{\rm src},\qquad Q(t,x)=t^2-g_{\rm src}(x,x),\] is a four-dimensional ambient target carrier with Lorentz inertia \((1,3)\), while source-unit directions are exactly its future-null rays. Canonical source height supplies only the temporal coordinate of an event placement after positive scaling. Every finite strict partial order compiles exactly into an abstract authenticated log, with rank derived from predecessor cardinality. Its generic authenticated-parent relation is the whole supplied order rather than its Hasse reduction alone. This is an expressivity theorem for the grammar, not a dynamics or execution-history selection theorem. An enumeration-dependent placement along one source axis gives every finite log an injective one-way forward-causal realization, without order reflection or physical coordinate selection. A supplied source-selected spatial readback and edge speed bound then give one-way cone compatibility. Equal-height spatial separation plus strict spacelikeness of unsupported increasing-height pairs imply converse support and exact order–cone equivalence. Antisymmetry derives injectivity, while the two-way equivalence preserves every source interval on the placed image. No rank-four event chart, fitted signature, or independently declared precedence relation enters this precursor theorem; its dimension is not an intrinsic poset-dimension estimate. The exact Boolean-diamond inhabitant has null parent edges and spacelike independent branches, so the interface is not restricted to chains; this finite witness is not a physical continuum.

The source-direction Einstein theorem shares that finite event type but works in a separately supplied \(3+1\) tensor interface. Nine fixed algebraic source directions, together with supplied symmetric fields, an algebraic coupling, four step maps, Ward/Bianchi identities, and connectedness, imply all-null balance and the finite Einstein-form tensor relation. The directions are not observed provenance links, signals, or sky samples, and the order does not select a field, step, or balance or identify tensor-coordinate differences with those of the constructed carrier. The ambient target-carrier dimension and signature are constructed by the carrier theorem; the poset dimension remains an independent observable. Interpreting the supplied fields as smooth curvature and physical stress requires a source-causal continuum certificate with two-way placement, count–volume calibration, independent dimension/manifoldlikeness tests, stable topology, refinement convergence, and a tensor-curvature reconstruction converging to the smooth Einstein tensor or the separately stated continuum small-ball/null-balance identification, together with stress convergence on one family. Scalar-curvature convergence is only a diagnostic.

A separate conservative source-record family has a controlled causal limit. Fibonacci residues generate \(q^3\) distinct sites in the rank-three metric carrier. Complete preceding-layer reads inside a shrinking radius, including waiting, and a declared model clock produce a flat \(1+3\) causal-order limit. Equal-volume cell assignments give normalized raw count convergence and an interior-interval ordering fraction tending to \(1/10\) [source]. This result uses the stated population and update law; it does not select physical events, a laboratory clock or a common matter-action cone. The same histories admit a retrospective clock. For intervals approaching fixed interior timelike diamonds, the fourth root of their inclusive count ratio converges to their proper-time ratio. A reference interval fixes the unit, and complete ancestry access supplies the count. This readout needs no oscillator or numerical timestamps. Operational covariance gives a separate cone criterion: a nonzero closed convex pointed cone invariant under the source icosahedral rotations and all boosts along one axis must be one of the two Lorentz cones. A time orientation selects the future cone. The covariance must act on possible influences and readouts. Algebraic direction maps alone do not establish that operational premise[source].

Character-block coexistence of regional algebras.

For every \(n\ge 2\) the full matrix algebra \(M_n(\mathbb C)\) admits no unital complex-algebra homomorphism into the scalars: the matrix ring is simple, so such a homomorphism is injective, while the off-diagonal matrix unit is a nonzero element whose square is zero. No unital complex-algebra homomorphism into the scalars accepts an anticommuting pair of units. On this interface, at any regulator of nonzero dimension, a region above a commutative-algebra region carries no anticommuting pair, and every full matrix factor of dimension at least two above a scalar overlap region is excluded: the tensor-factor local-algebra picture with trivial overlap is impossible. The inhabitant locating the boundary is a dimension-four net with three regions: a bottom overlap region carrying the scalar algebra and two declared-disjoint maximal regions carrying the block algebras \(\operatorname{diag}(a,a,A)\) and \(\operatorname{diag}(B,b,b)\) with arbitrary two-by-two blocks. Both regional algebras are noncommutative, neither contains the other, their elements commute pairwise, and each admits a character onto the scalars through its one-dimensional corner block, which supplies the star-homomorphic restriction retractions the interface demands. The block shape is forced: a noncommutative regional algebra compatible with a scalar drop must carry a one-dimensional block, and the witness realizes that minimal shape. The declared overlap algebra is a proper subalgebra of the set intersection of the two block algebras; the regional repair maps are identities. The construction provides no genuine coverage semantics for a source-produced net.

Hamiltonian rigidity of the private block.

The private dynamics behind these interfaces is forced from continuity alone, in the machine-checked modules , , , and . On one full finite matrix block, every complex-linear Leibniz endomorphism is an inner derivation, with an explicit matrix-unit witness proved from scratch, and every star-compatible Leibniz endomorphism is the von Neumann commutator action \(x\mapsto(-i)(Hx-xH)\) of one self-adjoint generator, unique up to one additive real scalar multiple of the identity. A real-parameter group of star automorphisms of the block whose orbit maps are pointwise continuous is conjugation by the coherent unitary family \(\exp(t(-i)H)\) of one time-independent self-adjoint Hamiltonian: continuity upgrades to differentiability at parameter zero because the group acts on the matrix-unit basis as a norm-continuous matrix family whose short-interval average is invertible, and the fundamental theorem of calculus recovers the family from its primitive. Time evolution on the finite private block therefore has no choice except Hamiltonian form. The converse extends to the general finite private algebra through its central structure: the center of any unital star subalgebra of a finite complex matrix algebra, containing the ambient identity, is the span of a minimal orthogonal central resolution of the identity, unique up to permutation; every such unital subalgebra is star-isomorphic to a finite direct sum of full matrix blocks; every central idempotent of the block model is the indicator of a set of blocks; and a pointwise-continuous star-automorphism group keeps each block projection inside that finite indicator set, hence fixes every block and is blockwise conjugation by the unitary family of one time-independent self-adjoint Hamiltonian per block, with block fixing derived rather than assumed and the block swap realized on the square two-block algebra. The parameter is a real number; no physical clock, source-selected Hamiltonian, or physical time identification is claimed [source].

Finite covariant-net consequences and limitations.

The finite observer net determines a category of event regions and causal embeddings together with a covariant observable functor (). Its causal embeddings are proof-only order data, so the category is thin and carries no Lorentzian geometry. In particular, these carriers provide no region reflection, antiunitary conjugation, distinguished vacuum, spin structure, symmetry-group action, Lorentzian Cauchy-embedding class, translation action, or spectrum condition. Consequently they lack the data needed to formulate CPT, spin–statistics, relative-Cauchy stress response, or Haag–Ruelle scattering. These are limitations of the mathematical carrier, not negative theorems about QFTs built from richer data ().

The same module encodes seven structural questions and kernel-checks their partition by mathematical conclusion. Four of them (CPT, spin–statistics, relative-Cauchy stress response, and particle scattering) lack defining geometric or spectral data on this carrier. Full field/action reconstruction likewise cannot be inferred from the finite static identities alone. Of the two remaining questions, the restricted endomorphism surrogate collapses as described next, while the finite KMS identity coexists with the net- and public-algebra counterexamples below. Thus the seven-way classification is a statement about what follows from the specified carrier.

The finite sector theorem has a narrower exact content. Every bijective localized endomorphism of the witness net is inner and hence equivalent to the identity under the declared finite equivalence relation (). This does not constitute DHR reconstruction: the carrier supplies no source-selected vacuum representation, quasi-local net, transportability structure, or reconstructed gauge group. The selected tower states nevertheless induce mathematical GNS representations of the completed colimit, as described below. Innerness of this restricted class supplies no charge or flavor quantum number.

Two further finite results delimit thermality and field reconstruction. The oriented-face curvature has kernel exactly the port gradients, and its five-neighbor seam action is gauge invariant exactly for conserved seam currents. This is a static finite action identity; it supplies no temporal dynamics, charge–current continuity map, source-selected physical current, physical matter or Spin action, spacetime carrier, or continuum limit. On a private finite block, the normalized Gibbs state satisfies the algebraic KMS identity. On the constructed example net, however, every functional is KMS for every grading-preserving flow at every complex time, while every pointwise-continuous group of star automorphisms of the public record algebra is the identity, a statement that leaves continuous row-stochastic public semigroups untouched (). The finite Gibbs identity therefore does not establish thermality of the observer net.

The one-step transport interface and the common triple-observer carrier below recover exact finite evolution and marginal identities, but they carry no Cauchy geometry, multi-step cocycle, physical time, or source-selected dynamics (; ). They therefore imply neither a relative-Cauchy stress response nor a physical time-slice theorem.

Natural powers give one exact constraint on a fixed-cutoff scattering construction: in every Hausdorff topological group, \(g^n\to a\) forces \(g=1\) (). Hence a nontrivial exact unitary update at fixed finite cutoff cannot itself settle to an ordinary matrix-topology large-time limit. The same module proves \((g^n)^{-1}g^n=1\), so relative evolution can converge even when the individual powers do not. Any fixed-cutoff direct-power construction that uses \(U^n\) itself as its asymptotic carrier cannot use full convergence of that sequence; it must change the asymptotic carrier or dynamics, or use a projected or weaker convergence notion. At fixed finite dimension, full weak-operator convergence does not evade the obstruction because the standard finite-dimensional operator topologies coincide. Comparison dynamics, selected projected scalar or observable readouts, an infinite-dimensional weak limit after a continuum or infinite-volume passage, open-system evolution, and finite-time or recurrence-aware readouts lie outside this no-go. The theorem constructs no S-matrix, asymptotic state, optical theorem, cross section, or interacting continuum limit.

Restriction naturality on authenticated event regions.

Let a finite regional net have local algebras \(\mathcal A_r(U)\), contravariant restrictions \(R^r_{V,U}\) for \(V\subseteq U\), algebra refinements \(j_{rs}\), and regional repair maps \(P^r_V\). Restriction is additional algebraic data; isotony alone does not supply it. Suppose repair is natural, \[j_{rs}P^r_V=P^s_{V_s}j_{rs},\] where \(V_s\) is the refined region. The following compatibility is a separate hypothesis on the restricted domain: \[\begin{equation} R^r_{V,U}X=P^r_VX\qquad(X\in\mathcal A_r(U)). \label{eq:source-restriction-repair-compatibility} \end{equation}\]

Proposition 75 (Finite restriction and refinement square). Under these hypotheses, \[\begin{equation} j_{rs}R^r_{V,U}X=R^s_{V_s,U_s}j_{rs}X. \label{eq:source-restriction-square} \end{equation}\] Let each event \(e\) of an authenticated semantic log carry a declared region \(U_e\), with \(U_e\subseteq U_f\) on every authenticated direct-parent edge. Generated reflexive precedence then defines restrictions from the algebra at \(f\) to that at \(e\), with identity and contravariant composition. If a certified event map preserves those direct edges in target generated precedence and satisfies \(U'_{F(e)}=(U_e)_s\), the same square holds for these event restrictions.

Proof. For the algebra square, substitute eq:source-restriction-repair-compatibility, apply repair naturality, and substitute the target compatibility. Inclusion extends from direct edges to generated precedence by transitivity; the restriction identity and tower law give identity and composition. The event map preserves generated precedence by induction on an authenticated path, so the target restriction is typed. Its region compatibility identifies its algebra square with eq:source-restriction-square. ◻

An inhabited example decorates the committed four-event Boolean diamond and three-event chain by a two-dimensional diagonal algebra. The injection event has the scalar algebra, and every response and answer has the full diagonal algebra. Restriction to the root sends \(\operatorname{diag}(x_0,x_1)\) to \(x_0I\); in particular, \(\operatorname{diag}(1,0)\) is changed. The authenticated coarsening maps the diamond labels \((0,1,2,3)\) to \((0,1,1,2)\) and merges two distinct responses. Its region decorations agree, and the restriction square is inhabited. The reversed assignment \((2,1,1,0)\) violates authenticated precedence. The finite identity, composition, compatibility, and coarsening statements are proved in QFT/LimitRestriction.lean.

The algebra regulator in this example is constant. Region decoration and edge preservation are explicit data; neither physical regions nor a source-selected refinement family are inferred. These are restrictions of commutative finite algebras, without an assertion of homomorphic scalar restriction for matrix factors. No normed limit restriction, physical locality, spacetime identification, or physical time-slice property follows.

Tower-anchored joint carriers and the typed time-slice interface.

Two regional diamonds carry source-counted correlation data of retained observer pairs from one bounded companion run: a two-slot conditional-expectation net for the pair 86/88 on a joint carrier of dimension 182, and one for the fully support-disjoint pair 86/247 on a joint carrier of dimension 169. In , the 86/247 diamond transports onto the private algebra of one constant consensus-tower stage by the same specified transport pattern as the 86/88 witness, with the same checkpoint family of observer 86 as commutative public layer, the uniform selected state, and the template nontriviality receipts: every partition member lies in the anchored left region, every member is proper, and the anchored left region is a proper subalgebra. Both carriers therefore have parallel tower anchorings of the same declared form (bothCarriers_common_anchoring). An exact shared-observer theorem (towerCarriers_share_obs86_marginal) relates the two carriers through their common left observer: the two source-derived joint paths have equal left label components at every step, equal left occupation counts, and equal induced diagonal hinge states, each equal to the source marginal state of observer 86, and the left partial trace of the counted correlation state equals the 86/88 hinge state. At the anchored-net level the carriers are not identified: the ambient dimensions 169 and 182 differ, and no map between the two anchored nets is constructed.

That carrier-level obstruction can nevertheless be removed below the net level. The module uses the common finite carrier \[(\mathrm{obs86},\mathrm{obs88},\mathrm{obs247}) \in \operatorname{Fin}(13)\times\operatorname{Fin}(14) \times\operatorname{Fin}(13).\] Its two coordinate projections recover both complete 32-row source paths and their occupation tables. The diagonal triple counted state is positive and trace one; explicit linear positive trace-preserving marginals recover both counted pair states. Four triple checkpoint projectors have normalized partial traces recovering both anchored checkpoint partition members. On each of the 31 actual adjacent source transitions, a triple reindexing transports the source projector and intertwines with both pair marginals. The endpoint is not wrapped to the first row: all three final-to-initial source counts are exactly zero.

This is a common state/path/checkpoint coupling, not a canonical gluing theorem. The pair of marginals is provably noninjective on triple matrices, so the full row alignment selects the displayed coupling and the pair states alone do not. The marginal maps are not used as multiplicative algebra maps, no completely-positive interface is claimed, and neither regional net nor independently declared uniform tower state is transported by this theorem.

The structure TimeIndexedNetEvolution in is a finite one-step interface. It carries a finite index and successor, a region family, per-step ambient star-automorphisms mapping each regional algebra to its successor, and admitted data in the regional algebra at the current index. The generation clause evolves those data before requiring their generated algebra to equal the successor regional algebra.

A full finite inhabitant exists over the 86/247 net. Its cyclic \(\operatorname{Fin}(32)\) witness follows the 31 actual adjacent source-row pairs and adds one terminal-to-initial bookkeeping automorphism; all three corresponding source counts are zero, so that closing automorphism is not a source transition. The admitted data are observer 86’s lifted source generators, and the region is the left region at every step. The evolved generators again generate that region (evolvedLiftedSourceGenerators_generate_left). Constancy here is a property of this chosen witness, not a theorem about every possible inhabitant. The natural single-projector walk candidate is a negative control: its evolved singleton is the next diagonal walk projector and cannot generate the top regional algebra (walkSlice_evolved_generation_fails).

The interface has no multi-step cocycle or group-action law, Cauchy geometry, clock, physical time, or source-selected dynamics and therefore implies no time-slice theorem. The common carrier joins the source state, path, and checkpoint data but supplies no regional-net or tower morphism. The \(\mathbb Z/2\) slot swap is an internal finite symmetry. The diagonal-layer join below carries typed embeddings of both carriers but no physical time, causal interpretation, spacetime attachment, regional-net join, or tower join.

Finite carrier join.

The module joins the two finite carriers at their diagonal layer, the layer on which every source-counted state lives. The observer-86 hinge is the 13-dimensional function space on the shared label alphabet; it maps into the 182-dimensional 86/88 layer and the 169-dimensional 86/247 layer by fiber-uniform sections of slot marginalization, and the join is the pushout of the two carriers over the hinge. Both embeddings are injective typed linear maps and agree exactly on the hinge (embed_agree_on_hinge); the join has dimension \(338 = 182 + 169 - 13\) (joinCarrier_finrank), strictly below the direct-sum dimension \(351\); and the intersection of the two embedded images is exactly the embedded hinge (embed_range_inter), so the construction glues along the shared observer rather than placing the carriers side by side. A hinge restriction retracts the join onto the hinge; under it the two transported counted states restrict to the same source-derived observer-86 occupation law (joinStates_marginal_compatible). The specified ambient anchoring equivalences act on the diagonal layer as the corresponding basis reindexings, and the join transports along them with commuting squares on both embeddings; the walk-step transports over the 31 actual adjacent source transitions restrict to the diagonal layer, share the observer-86 hinge action, and descend to one join evolution intertwined by both embeddings and by the hinge restriction. The join is a finite linear object with declared fiber-uniform sections: no star-algebra amalgamation, order structure on the quotient, net morphism, tower morphism, or uniqueness claim accompanies it.

Record-layer net morphisms for the join.

The module equips the join with the regional structure of the two finite carriers at the layer on which the join exists. For each region of either diamond, the record layer is the typed function subspace of the carrier (constants at the bottom, the two coordinate pullbacks on the slots, everything at the top), and a machine-checked characterization proves that these subspaces are exactly the diagonal restrictions of the specified regional algebras (diagonal_mem_twoSlotAlgebra_iff), with dimensions \(1\), \(13\), \(14\), \(182\) on the 86/88 side and \(1\), \(13\), \(13\), \(169\) on the 86/247 side. The induced net on the join carries one region per specified region of each side plus the 13-dimensional hinge, ordered by a kernel-checked partial order; the net is isotone, both embeddings are region-by-region morphisms preserving inclusions and dimensions, the hinge image is the same subspace through either embedding, the associated conditional expectations restrict to the record layer on every region (landing in it and fixing it), the matched left-slot pair descends to one hinge projection on the join that commutes with both embeddings, is idempotent, and preserves the hinge restriction, and the join evolution carries every induced region onto itself (joinStep_maps_joinRegionLayer). Two negatives delimit the layer exactly: the gluing submodule is not multiplicatively closed, so the quotient multiplication is ill-defined and the join carries no algebra structure through this pushout (join_quotient_mul_ill_defined), and the record layer is commutative while the left regional algebra is not, so the commutant distinctions of the operator layer collapse under the diagonal restriction. The construction defines no operator-layer net morphism, tower morphism, physical time, causal interpretation, or spacetime attachment.

Operator-layer boundary.

For the 86/247 carrier, the record function carrier enters the joint matrix algebra as an injective unital star algebra homomorphism, the diagonal embedding; its image lies in the specified regional algebra of a region exactly when the record function lies in the record layer of that region (diagonalStarHom_mem_regionMap_iff), and it intertwines the specified conditional expectations with the record-layer expectations on every region. In the projection direction the left-slot conditional expectation is positive, trace preserving, and unital, and restricts to the record-layer expectation on diagonals; a specified right-slot projector witnesses that it is not multiplicative (leftSlotExpectation_not_multiplicative). No map from the joint algebra to the record carrier is multiplicative on the left regional algebra while restricting to the record-layer morphism on diagonals: the noncommuting witness pair has both of its products diagonal, and any multiplicative map into a commutative target identifies them (no_multiplicative_record_projection247). No unital algebra homomorphism carries the left regional algebra, or the ambient joint algebra, into the record carrier at all (twoSlot247_left_no_record_algHom), through the matrix-factor scalar obstruction. The boundary is an asymmetry for the declared expectation-versus-multiplicative projection grades: embedding is a star homomorphism, while the projection is a positive unital trace-preserving expectation and is not multiplicative. The theorem does not classify complete positivity, idempotence, bimodularity, nonlinear maps, different targets, or enriched categorical structures. It defines no net-to-net or tower morphism at the operator layer ().

The normed completion of the colimit.

The consensus tower supplies a directed family of finite matrix observable algebras whose connecting maps are star algebra homomorphisms, and its filtered colimit carries an inductive-limit seminorm: the value at a class is the infimum, over the declared refinements of one representative, of the stage norm of the refined representative. Contractivity of the connecting maps makes that value independent of the chosen representative. The stage norms of one representative form a subset of a finite set determined by the spectrum of the product of the representative with its adjoint, so the infimum is attained at a declared refinement and every class has a representative whose stage norm no declared refinement changes. Attainment converts the seminorm into an exact kernel statement: a class has seminorm zero exactly when some declared refinement annihilates its representative, which is the refinement-null kernel of the colimit itself. The seminorm is therefore a norm, the colimit is a normed star algebra satisfying the C*-identity for it, and its uniform completion is a C*-algebra: it carries a star ring structure extended from the dense image together with an isometric star and the C*-identity. The regional structure transports to the completion: the closures of the images of the limit local algebras are isotone, independent of the regulator at which a region is presented, elementwise commuting for declared-disjoint regions, and equal along the order-theoretic Cauchy embeddings of the tower, and each of those four statements is instantiated on a finite witness net whose top region carries an element of norm one. Two controls fix the boundary of the construction: a tower whose connecting map annihilates the unit carries a nonzero stage element of stage norm one whose limit seminorm is zero, and a conjugation of the two-by-two stage by a diagonal scaling increases the norm of a matrix unit, so the star clause of the connecting maps is the clause the contractivity step consumes. The construction is algebraic and order-theoretic throughout. The equality it transports along Cauchy embeddings is the order-theoretic equality of the tower; it supplies neither time-indexed physical evolution nor a physical attachment. ().

A selected-state Hilbert-space representation of the completed net.

Equip the completed colimit with the canonical C*-spectral order. For every positive complex-linear functional \(\omega\) normalized by \(\omega(1)=1\), the GNS construction gives a complex Hilbert space \(\mathcal H_\omega\) and a unital star representation \(\pi_\omega\) of the completed colimit by bounded operators. The completion image \(\Omega_\omega\) of the algebra unit is explicit and obeys \[\|\Omega_\omega\|=1, \qquad \langle\Omega_\omega,\pi_\omega(a)\Omega_\omega\rangle =\omega(a), \qquad \overline{\{\pi_\omega(a)\Omega_\omega:a\}}=\mathcal H_\omega.\] Sending every completed regional algebra to its image under the same representation preserves isotony, refinement independence, elementwise locality for the declared-disjoint regions, and the order-theoretic Cauchy-embedding equality. Images are used rather than identified with their sources because normalization does not imply that the representation is faithful.

For the specified tower interface, the functional need not be added as an unrelated input. Let \(\xi_r\) be an explicitly supplied observer family compatible with every regulator refinement, and let \(\rho_{r,\xi_r}\) be the selected density state carried by the tower. State naturality makes \[\omega_\xi(\iota_r(X)) :=\operatorname{Tr}(\rho_{r,\xi_r}X)\] well defined on the algebraic colimit. The finite state-expectation bound extends it continuously to the completed colimit, where it is positive for the spectral order and normalized. Hence \(\omega_\xi\) supplies the GNS Hilbert space and representation above. The one-regulator witness instantiates this construction, and its GNS unit class is nonzero with norm one. This yields a mathematical Hilbert-space representation of the selected-state completed net.

Taken alone, this construction’s coherent observer family and finite density states are declared structural data, not a state selected by an experimental source. Neither they nor \(\Omega_{\omega_\xi}\) are identified as a physical vacuum. No Hamiltonian or physical dynamics, energy–momentum, field content, Lorentzian attachment, continuum or infinite-volume limit, interacting theory, or physical time-slice theorem follows. (; ).

An exact finite two-site Hamiltonian benchmark.

As a separate finite-dimensional test of Hamiltonian structures outside the completed-net attachment, take \[\mathcal H_{\mathrm I} = \mathbb C^2\otimes\mathbb C^2 \cong \mathbb C^4, \qquad H_{\mathrm I}=\frac12\bigl(1-Z\otimes Z\bigr).\] The full matrix algebra acts faithfully by bounded operators on \(\mathcal H_{\mathrm I}\). Exact matrix proofs give \(H_{\mathrm I}^{*}=H_{\mathrm I}\), \(H_{\mathrm I}\geq0\), and \(H_{\mathrm I}^{2}=H_{\mathrm I}\). The explicit unit vector \(\lvert00\rangle\) and density \(\rho_{00}=\lvert00\rangle\langle00\rvert\) obey \[\|\lvert00\rangle\|=1,\qquad H_{\mathrm I}\lvert00\rangle=0,\qquad H_{\mathrm I}\rho_{00}=\rho_{00}H_{\mathrm I}=0, \qquad \operatorname{Tr}(\rho_{00})=1.\] Thus \(\rho_{00}\) is a normalized stationary ground-state density; the orthogonal unit state \(\lvert11\rangle\) also has zero energy, so the ground space is degenerate and no unique vacuum is selected. The propagator \(U(t)=\exp(-itH_{\mathrm I})\) is unitary and obeys \(U(s+t)=U(s)U(t)\); its conjugation flow \(\alpha_t(X)=U(t)XU(-t)\) is multiplicative, fixes \(\rho_{00}\), and preserves commutation between jointly evolved left- and right-slot observables. The bond is genuinely interacting in the exact finite sense that \(H_{\mathrm I}\) is not any sum \(H_L\otimes1+1\otimes H_R\) of one-site Hamiltonians; in particular it belongs to neither one-site matrix-algebra image. The evolution is nontrivial: for \(X_L=X\otimes1\), \[\left.\frac{d}{dt}\right|_{t=0}\alpha_t(X_L) =-i[H_{\mathrm I},X_L]\ne0,\] with the displayed matrix entry equal to \(i\). Deleting only the \(Z\otimes Z\) interaction leaves the scalar Hamiltonian \(H_{\mathrm{del}}=\tfrac12 1\), makes the full conjugation flow static, and makes the same infinitesimal generator zero. These are zero-residual identities on the declared four-dimensional carrier.

Taken alone, this is an exact coupled two-spin lattice benchmark, not an interacting quantum field theory and not a Hamiltonian attachment to \((\mathcal H_{\omega_\xi},\pi_{\omega_\xi})\) above. Its tensor factors are declared sites rather than Lorentzian regions; \(H_{\mathrm I}\), its normalization, and the state are supplied rather than selected by an OPH source; and \(t\) has no physical clock or energy calibration. Equal-time commutation here preserves one finite tensor-product commutator and is not a microcausality theorem. No continuum or infinite-volume limit, field algebra, Lorentz covariance, spectrum condition, renormalization flow, particle interpretation, scattering construction, detector readout, or physical time-slice theorem follows. ().

The finite Hamiltonian, regional diamond, and selected GNS on one carrier.

The two preceding constructions compose in one typed finite model. Use the canonical basis equivalence \(\operatorname{Fin}(2)\times\operatorname{Fin}(2)\simeq \operatorname{Fin}(4)\) to place the two-spin algebra on a one-regulator consensus tower \(T_{\mathrm I}\). Its selected density is exactly \(\rho_{00}\), and its stored generator is not the constant tower adaptor’s zero map but \[\delta_{\mathrm I}(X)=-i[H_{\mathrm I},X].\] On the same carrier, the scalar/left/right/top conditional-expectation diamond has commuting declared-disjoint slot algebras, and its left and right algebras jointly generate \(M_4(\mathbb C)\). Let \(\omega_{\mathrm I}\) be the tower-selected functional, let \((\mathcal H_{\mathrm I}^{\mathrm{GNS}},\pi_{\mathrm I}, \Omega_{\mathrm I})\) be its GNS triple, and define \[h_{\mathrm I}=\iota(H_{\mathrm I}),\qquad \widehat H_{\mathrm I}=\pi_{\mathrm I}(h_{\mathrm I}),\qquad \widehat U_{\mathrm I}(t)= \pi_{\mathrm I}\!\left(\iota(U(t))\right).\] The exact composite representation from \(M_4(\mathbb C)\) through the colimit completion to bounded GNS operators is injective. Consequently the ground-vector equations do not arise from a collapsed quotient: \[\|\Omega_{\mathrm I}\|=1, \qquad \widehat H_{\mathrm I}\ne0, \qquad \widehat H_{\mathrm I}^{*}=\widehat H_{\mathrm I}, \qquad \widehat H_{\mathrm I}\Omega_{\mathrm I}=0.\] The Hamiltonian belongs to the represented top region, while the represented left and right Pauli observables retain their regional memberships and commute. The mapped propagators are unitary, form an additive one-parameter group, and obey the exact intertwining identity \[\pi_{\mathrm I}\!\left(\iota(\alpha_t(X))\right) =\widehat U_{\mathrm I}(t) \pi_{\mathrm I}\!\left(\iota(X)\right) \widehat U_{\mathrm I}(-t).\] Interaction remains load bearing after representation: \(\pi_{\mathrm I}(\iota(-i[H_{\mathrm I},X_L]))\ne0\), and this first-order response is outside the represented left algebra, whereas the same represented response is zero after deleting the coupling.

The left conditional expectation \(E_L\) is trace preserving but does not preserve the selected pure state: \[E_L(1\otimes Z)=0, \qquad \operatorname{Tr}(\rho_{00}(1\otimes Z))=1.\] Thus the construction is a finite regional diamond together with co-located interacting C*-dynamics on its ambient algebra, represented on the tower-selected GNS Hilbert space. The dynamics need not preserve each regional algebra: indeed, the nonzero first-order response above leaves the represented left algebra. The failure of state preservation is a property of that particular trace-preserving expectation, not a failure of a global state to restrict to the regional algebras. It therefore supplies a useful incompatibility diagnostic but is not itself the criterion separating a finite net from a physical QFT. The regulator, factorization, density, Hamiltonian, and flow parameter are declared rather than source produced or calibrated; the ground sector is degenerate; and Lorentzian localization, a spectrum condition, continuum or infinite-volume control, renormalization flow, field and particle content, scattering, detector readback, and a physical time-slice theorem are absent. ().

A source-counted finite history Hamiltonian on the selected GNS space.

The retained eight-history packet supplies a separate finite attachment in which the state and diagonal action entries are source counted rather than freely chosen. For each binary path \(g=(s_0,s_1,s_2)\), let \(n_g>0\) be its exact window count among the 1754 retained windows and let \[S_g=\mathbf 1_{s_0\ne s_1}+\mathbf 1_{s_1\ne s_2}.\] On \(M_8(\mathbb C)\), define \[\rho_{\rm hist}=\operatorname{diag}\!\left(\frac{n_g}{1754}\right), \qquad H_{\rm hist}=\operatorname{diag}(S_g).\] The source receipts prove every \(n_g\) positive and prove the displayed state-change formula for \(S_g\). Exact matrix proofs then give \[\rho_{\rm hist}\geq0,\quad \operatorname{Tr}\rho_{\rm hist}=1,\quad H_{\rm hist}\geq0,\quad H_{\rm hist}^{*}=H_{\rm hist},\quad [\rho_{\rm hist},H_{\rm hist}]=0,\] with \(H_{\rm hist}\) nonzero and non-scalar. The selected energy retains the counted source value \[\operatorname{Tr}(\rho_{\rm hist}H_{\rm hist}) =\frac{197}{1754}.\]

Place this pair in one consensus-tower stage with stored generator \(\delta_{\rm hist}(X)=-i[H_{\rm hist},X]\). The selected density constructs a normalized GNS triple \((\mathcal H_{\rm hist},\pi_{\rm hist},\Omega_{\rm hist})\), and the composite representation of \(M_8(\mathbb C)\) is injective. Thus the represented Hamiltonian is nonzero and self-adjoint. Its cyclic matrix coefficient is exactly \(197/1754\), which also proves \[\pi_{\rm hist}(H_{\rm hist})\Omega_{\rm hist}\ne0.\] The matrix unit \(E_{01}\) supplies a nonclassical control: \[\bigl(-i[H_{\rm hist},E_{01}]\bigr)_{01}=i,\] so the represented commutator response is nonzero. The exponential propagators are unitary, obey the additive group law, intertwine exactly with the represented Heisenberg flow, and leave \(\rho_{\rm hist}\) stationary.

The same carrier has an exact tensor-local history decomposition. The source encoding identifies its basis with \(((s_0,s_1),s_2)\in(\mathbb Z/2)^3\). Tensor-factor embeddings define the one-slot algebras \(\mathcal A_0,\mathcal A_1,\mathcal A_2\), the generated adjacent interval algebras \(\mathcal A_{01}=\mathcal A_0\vee\mathcal A_1\) and \(\mathcal A_{12}=\mathcal A_1\vee\mathcal A_2\), and \(\mathcal A_{012}=M_8(\mathbb C)\). The inclusions are isotone and the separated endpoint algebras obey exact locality, \[[\mathcal A_0,\mathcal A_2]=0.\] Writing the two adjacent domain-wall projectors as \[H_{01}=\operatorname{diag}(\mathbf 1_{s_0\ne s_1}),\qquad H_{12}=\operatorname{diag}(\mathbf 1_{s_1\ne s_2}),\] gives the residual-free local decomposition \[H_{\rm hist}=H_{01}+H_{12},\qquad H_{01}\in\mathcal A_{01},\qquad H_{12}\in\mathcal A_{12}.\] Both bonds are positive, and their separately counted source energies are \[\operatorname{Tr}(\rho_{\rm hist}H_{01})=\frac{94}{1754},\qquad \operatorname{Tr}(\rho_{\rm hist}H_{12})=\frac{103}{1754}.\] For \(\delta_{\rm hist}(X)=-i[H_{\rm hist},X]\), locality removes the remote bond exactly, so \[\delta_{\rm hist}(\mathcal A_0)\subseteq\mathcal A_{01},\qquad \delta_{\rm hist}(\mathcal A_2)\subseteq\mathcal A_{12}.\] These are first-commutator finite-support statements, not a continuum finite-speed theorem. The single source functional \(\omega(X)=\operatorname{Tr}(\rho_{\rm hist}X)\) restricts to compatible states on every displayed algebra: for each inclusion \(\mathcal A_U\subseteq\mathcal A_V\), \(\omega_V|_{\mathcal A_U}=\omega_U\). The injective selected-GNS representation transports the endpoint locality, the two bond memberships, the Hamiltonian decomposition, and the generator-support statements without collapse. This compatible restriction is the state compatibility required of the finite net; it does not assert a source-state-preserving conditional expectation from the full algebra onto every region.

This is a source-counted finite three-history-slot local dynamical system on its selected GNS Hilbert space, not a physical QFT. The retained run was hash-pinned, but the empirical law and repair-count postprocessing were not jointly preregistered. The packet fixes the diagonal density and the two repair-change contributions; the full \(M_8(\mathbb C)\) quantum extension, tensor-factor locality reading, off-diagonal coherence probe, one-regulator tower, and real flow parameter are mathematical adapters. The nonzero energy of \(\Omega_{\rm hist}\) prevents its promotion to a vacuum or ground vector. The three successive history coordinates are not calibrated physical times or Lorentzian regions, and there is no physical clock or energy calibration, spectrum condition, continuum or infinite-volume control, renormalization flow, field/particle interpretation, scattering, detector readback, or physical time-slice theorem. (; ).

The rational record layer carries a finite slot-indexed conditioning family. For every slot region \(S\subseteq\{0,1,2\}\), conditioning the committed window law on the slots in \(S\) defines a map \(E_S\) on \(\mathbb Q\)-valued record observables that is rational-linear, unital, pointwise positive, localized, idempotent, and tower-compatible, \(E_S\circ E_T=E_S\) for \(S\subseteq T\). The full-region map is the identity because the three slots separate the eight histories, the empty-region map is the constant empirical mean, and every \(E_S\) preserves that mean. The domain walls are fixed points of their own interval maps, every regional map preserves the bond means \(94/1754\) and \(103/1754\) and the action mean \(197/1754\), and the late-slot conditional weights are \(383/415\) in the \((s_0,s_1)=(0,0)\) cell and \(2/89\) in the \((0,1)\) cell.

The matrix obstruction has a fixed target and hypotheses. No complex-linear map from \(M_8(\mathbb C)\) into this particular \(\mathcal A_{01}\) can both satisfy the \(\mathcal A_{01}\)-bimodule law and preserve the committed state \(\omega\): such a map would assign the slot-two projector a single conditional weight over \(\mathcal A_{01}\), whereas the two cells demand \(383/415\) and \(2/89\). This does not rule out ordinary AQFT nets of inclusions with state restriction, other or enlarged target algebras, ancillary boundary memory, generalized expectations, or non-bimodule positive or completely positive channels. The finite-probability conditioning identities and wall coefficients transport to represented diagonal elements on the selected GNS carrier ().

Region families of the one-step interface.

The module settles the region-family freedom of TimeIndexedNetEvolution over the finite 86/247 diamond in both directions. Any evolution family that maps each regional algebra onto itself forces a step-invariant region family, and every net-compatible slice family over the specified walk-step evolution on cyclic \(\operatorname{Fin}(32)\) is constant (stepEvolve_slice_constant); the scalar bottom and full top regions are rigid under every evolution family, so a one-step region change of any inhabitant exchanges the two slot regions (slice_change_forces_slot_exchange). Conversely a slot-alternating inhabitant exists (slotAlternatingEvolution): the slice alternates between the left and right slot regions, the per-step automorphism composes the specified walk-step evolution with the internal slot exchange, the admitted data are the source generators of observer 86 at even steps and of observer 247 at odd steps, and the evolved data generate the next regional algebra at every step; the region family is provably not step-invariant. The exchange factor is a constructed internal symmetry rather than a source transition, and the walk factor carries the declared index-31 bookkeeping closure. The construction supplies no physical time, causal interpretation, or source-derived time-slice content.

Boundary-fibre circularity control.

Over the bare consensus tower of the gravitational branch (finite presentation and quotient states, a mismatch functional, a strictly descending step relation, an idempotent normal form, a protected boundary map, and physical coarse maps), a signature family that factors through the protected boundary on consistent states and is complete on consistent states forces the boundary fibre: equal boundary values imply equal consistent states. Instantiating the signature as the protected boundary itself makes the factoring hypothesis trivial and makes the completeness hypothesis definitionally identical to the conclusion; the degeneration is recorded as a definitional equivalence, so the circularity is itself a theorem, and the result is substantive only for a signature constructed independently of the boundary and proved complete on its own grounds. A selected settled branch (one normal-form-fixed, coherent quotient point per regulator) is an explicit premise with a concrete inhabitant and an explicit failing candidate, and an event and geometry readout fragment carries normal-form-invariant, coarsely natural packet readouts that separate two consistent states on the same concrete tower. Every statement in this subsection is a finite conditional structure over declared data: no physical region, coverage, instrument, spacetime, causal cone, event actualization, probability law, or continuum object follows [source].

OPH Simulation Criterion and Fixed-Point Firewall

A fixed-point equation is necessary for a selected finite OPH packet, but it is not the definition of an OPH simulation. The additional clauses below are the nontrivial content.

Definition 76 (Nontrivial OPH simulation certificate). Work on the finite fixed-cutoff branch of Definition 60. Write \[Q:=\Sigma/\Gamma, \qquad n:=\overline{\operatorname{nf}}_\lambda:Q\to Q, \qquad N_\lambda:=q(C).\] Let \(B:Q\to\mathcal B\) be a boundary/sector map preserved by accepted quotient repairs, fix \(b\in\mathcal B\), and set \[Q_b:=B^{-1}(b), \qquad C_b:=N_\lambda\cap Q_b.\] For \(u\in C_b\), let \(\mathfrak U_u:=\delta_u\in\Delta(Q)\). The selected pair \((b,u)\), equivalently the packet \(\mathfrak U_u\), has an OPH simulation certificate when all of the following hold.

  1. Endogenous update. The local maps are the recovery-derived collar maps of Definition 7, descend to the physical quotient, and use only the declared patch, overlap, recovery, decoder, and acceptance data. No undeclared oracle variable is an argument of an accepted physical update.

  2. Observer-readable records. A declared observer-accessible region carries an exact record presentation \(\{\widehat P_a\}_a\) as in Definition 73, with at least two nonzero orthogonal event projectors. Event probabilities, conditioned readouts, and any checkpoint/order relation interpreted as history are collected in a physical map \[\operatorname{Read}:Q\to\mathcal Y_{\rm rec}\] whose terminal value depends only on the quotient normal form.

  3. Overlap repair. Every accepted nontrivial move strictly lowers the declared touched-overlap score, normal forms are exactly the globally consistent states, and the quotient normal form \(n\) is terminating and schedule-independent.

  4. Nontrivial branch elimination. The selected fiber has one consistent quotient state but more than one candidate: \[C_b=\{u\}, \qquad Q_b\setminus C_b\ne\varnothing, \qquad n(Q_b)=\{u\}.\] Thus at least one inconsistent candidate is genuinely removed instead of merely renamed a fixed point. A candidate with a nonzero declared holonomy or higher-gauge obstruction is rejected as obstructed and is not counted as an alternative selected world.

  5. Implementation and clock closure. The physical update and record readout have types \[n:Q\to Q, \qquad \operatorname{Read}:Q\to\mathcal Y_{\rm rec},\] with no indispensable machine-state or external-time argument. More precisely, for any auxiliary implementation and clock sets \(\mathcal E_{\rm ext}\) and \(\Theta_{\rm ext}\), let \[p:Q\times\mathcal E_{\rm ext}\times\Theta_{\rm ext}\to Q\] be the physical projection. An admissible lifted update \(\widetilde n\) and readout \(\widetilde{\operatorname{Read}}\) must satisfy \[p\circ\widetilde n=n\circ p, \qquad \widetilde{\operatorname{Read}}=\operatorname{Read}\circ p.\] The asynchronous schedule and repair-step counter are proof data, not physical clock coordinates. Any history claimed by the branch is read from records in the terminal quotient state instead of supplied by an external clock. Promoting that record order to physical time requires the independent clock instrument, event correspondence, and calibration receipts.

The identities \[n(u)=u, \qquad \mathcal C_\lambda(\mathfrak U_u)=\mathfrak U_u\] are therefore consequences of the certificate, not its definition.

Theorem 77 (Selected OPH packet and fixed-point firewall). Assume Definitions 7, 8, and 9, Assumption 18, and the quotient and record hypotheses of Theorems 43, 57, and 74. Fix a preserved boundary/sector value \(b_{\rm OPH}\) for which \[C_{b_{\rm OPH}}=\{u_{\rm OPH}\}, \qquad Q_{b_{\rm OPH}}\setminus C_{b_{\rm OPH}}\ne\varnothing,\] and assume the selected observer surface has a nontrivial exact record presentation whose checkpoint/order data, when interpreted as history, are quotient-observable. Then the selected finite OPH packet \[\mathfrak U_{\rm OPH}:=\delta_{u_{\rm OPH}}\] has an OPH simulation certificate in the sense of Definition 76. In particular, \[n(u_{\rm OPH})=u_{\rm OPH}, \qquad \mathcal C_\lambda(\mathfrak U_{\rm OPH})=\mathfrak U_{\rm OPH}.\]

The converse is false: a fixed point, equilibrium, stationary point, or variational solution does not by itself imply an OPH simulation certificate. Indeed, for any set \(X\) with \(|X|>1\), the identity map \(F=\mathrm{id}_X\) satisfies \(F(x)=x\) for every \(x\in X\), and every \(x\) is a global minimizer and stationary point of the constant functional \(V\equiv0\). Nevertheless, \(F^{-1}(x)=\{x\}\), so no proper candidate basin collapses to \(x\); clause (S4) fails. The fixed-point or variational equation alone also supplies none of clauses (S1)(S3) or (S5).

Proof. Clause (S1) is Definition 7 together with quotient descent from Theorem 43. Clause (S2) follows from Theorem 74; terminal representative independence is Theorem 57. Definition 8, Proposition 24, Proposition 29, Assumption 18, and Theorem 31 give clause (S3).

For \(x\in Q_{b_{\rm OPH}}\), boundary preservation gives \(B(n(x))=b_{\rm OPH}\), while repair completeness gives \(n(x)\in N_\lambda\). Hence \(n(x)\in C_{b_{\rm OPH}}=\{u_{\rm OPH}\}\), proving \(n(Q_{b_{\rm OPH}})=\{u_{\rm OPH}\}\). The assumed nonempty difference \(Q_{b_{\rm OPH}}\setminus C_{b_{\rm OPH}}\) makes this elimination nontrivial. The holonomy and higher-gauge rejection statement is Theorems 38 and 41. This proves clause (S4). Its proper-basin requirement is nonvacuous: on the verified rooted-tree packet domain of Theorem 20, fixing the root packet gives a singleton consistent fiber, while changing any non-root packet supplies an inconsistent candidate in that fiber.

The quotient normal-form and physical-record maps are defined on the declared physical state alone. Schedule independence removes the scheduler from the output, and Corollary 59 proves invariance under inert carrier enlargement. The displayed projection identities are the admissibility condition for any more general carrier or clock realization. Thus an auxiliary implementation state or iteration counter cannot change the physical result, proving clause (S5). Finally, Theorem 61 gives \[\mathcal C_\lambda(\delta_{u_{\rm OPH}}) =\delta_{n(u_{\rm OPH})} =\delta_{u_{\rm OPH}},\] because \(u_{\rm OPH}\in N_\lambda\). The identity-map and constant-functional example proves the final non-implication. ◻

Remark 78 (Structural falsification hooks). An asserted OPH simulation certificate fails if any one of the following occurs: an accepted update depends on undeclared oracle, carrier, or external-clock data; the observer record algebra is trivial, unstable, or not quotient-readable; an accepted move fails strict mismatch descent; terminal states are not exactly the overlap-consistent states; two admissible schedules or two candidates in the selected boundary fiber produce different physical normal forms; the selected fiber has no inconsistent candidate to eliminate; a claimed global branch has nonzero holonomy or higher-gauge obstruction; or a carrier/clock lift changes the physical update or readout after projection. These are theorem-level failure conditions, not semantic disagreements about the word “simulation.”

Remark 79 (Scope). Theorem 77 certifies the named finite fixed-cutoff branch and selected boundary/sector fiber. It does not extend the finite packet closure to an arbitrary habitat-level state-and-law space, and it does not remove the branch and record hypotheses stated in the theorem.

A finite source-bound witness.

A bounded companion run supplies one finite instance from source data to kernel-checked literals. Its locally pre-specified, hash-pinned contract has no independent public preregistration because contract and result entered the repository together. The contract specifies a nonconstant protected record, separate state and transition tables, an exact recognizer, stationarity, and contraction. The transition stationary law and the empirical state-side reference are distinct objects: their exact denominator mismatch and the nonprojector transition eigenmode rule out both a deterministic pushforward and a nondegenerate intertwiner with the idempotent state-side resampling action. The finite payload integers are mirrored verbatim in as kernel-decided literals that inhabit a payload-attached observer access-cut interface. On three of the four mirrored observer supports the public and accessible algebras coincide; exactly one support separates a record class by its companion class. The literals are counts and class labels from one run under a declared binning and observer-selection rule. They establish no physical claim or probability law beyond the realized frequencies [source].

Distributed Presentations of One Finite Universe

The implementation closure clause in Definition 76 has a distributed form. A worker partition is allowed to accelerate or package the computation, but it is not a new physical ingredient. The physical question is whether the worker run presents the same finite quotient repair system as the monolithic carrier.

Definition 80 (Finite global OPH carrier). At refinement stage \(r\), a finite global OPH carrier consists of a finite patch graph \[G_r=(V_r,E_r),\] finite patch state sets \(S_i\), interface alphabets \(I_e\), endpoint maps \(\pi_{i,e}:S_i\to I_e\), an implementation-hiding group \(\Gamma_r\), a boundary/sector map \(B_r\), a mismatch potential \(\Phi_r\), accepted quotient repairs \(\to_r\), and an observer-readable map \[\operatorname{Read}_r:Q_r\to\mathcal Y_r, \qquad Q_r:=\left(\prod_{i\in V_r}S_i\right)/\Gamma_r.\] Let \(C_r\subseteq Q_r\) be the quotient consistency set. On the finite branch covered by Theorems 31 and 43, the accepted quotient repair relation has a unique normal-form map \[n_r:Q_r\to C_r.\] A one-universe input is the pair \(\mathbf U_r=(\mathfrak U_r,q_0)\), where \(\mathfrak U_r\) is the carrier data above and \(q_0\in Q_r\). A worker partition is not part of \(\mathfrak U_r\).

Definition 81 (Worker presentation and physical projection). Let \(\kappa:V_r\to W\) assign every patch to one authoritative worker. The cut set is \[E_\kappa^{\mathrm{cut}} := \bigl\{\{i,j\}\in E_r:\kappa(i)\ne\kappa(j)\bigr\}.\] A distributed presentation for \(\kappa\) has worker-owned states, ghost or halo copies, message queues, transaction records, retries, worker identifiers, checkpoints, event logs, and scheduler state. Let \(\widetilde Q_{r,\kappa}\) be its quotient by purely local worker bookkeeping that leaves authoritative physical states unchanged. The physical projection \[p_{r,\kappa}:\widetilde Q_{r,\kappa}\to Q_r\] keeps only the authoritative patch states, quotients by \(\Gamma_r\), and discards queues, retry metadata, worker labels, and external clocks. Let \[D_r:=\bigsqcup_{\kappa}\{\kappa\}\times\widetilde Q_{r,\kappa}, \qquad P_r(\kappa,\tilde q):=p_{r,\kappa}(\tilde q).\] A distributed readout is physical when it factors as \[\widetilde{\operatorname{Read}}_r=\operatorname{Read}_r\circ P_r.\]

Definition 82 (Admissible distributed event). For \(d,d'\in D_r\), a distributed event \(d\Rightarrow d'\) is admissible when one of the following holds.

  1. Linearizable physical commit. There is a nonempty monolithic accepted repair path \[P_r(d)\to_r^*P_r(d')\] whose repair word is recorded as the event’s linearization witness.

  2. Physical stutter. \(P_r(d')=P_r(d)\). Message delivery, halo refresh, prepare, abort, checkpoint, worker start or stop, idempotent replay, and repartition metadata are allowed only in this class unless they also carry a physical commit witness.

  3. Certified rollback. There is an earlier committed state \(d_j\) in the same run history such that \(P_r(d')=P_r(d_j)\), and the rollback certificate names that committed projection root. Transparent restart from a committed frontier is a stutter.

Proposition 83 (Normal form is constant on an accepted reachability cone). If \(q\to_r^*q'\), then \[n_r(q')=n_r(q).\]

Proof. The state \(q'\) is reachable from \(q\). The state \(n_r(q')\) is a normal form reachable from \(q'\), hence also reachable from \(q\). Theorem 31 and Theorem 43 give the unique quotient normal form reachable from \(q\), so \(n_r(q')=n_r(q)\). ◻

Theorem 84 (Distributed realization of one finite OPH universe). Fix a finite global carrier \(\mathbf U_r=(\mathfrak U_r,q_0)\) satisfying Theorems 31 and 43. Let \[d_0\Rightarrow d_1\Rightarrow\cdots\Rightarrow d_m\] be a finite distributed execution in \(D_r\) with \(P_r(d_0)=q_0\), and assume every event is admissible in the sense of Definition 82. Then, for every \(t\), \[q_0\to_r^*P_r(d_t), \qquad n_r(P_r(d_t))=n_r(q_0).\] If the final projection is a monolithic normal form, then \[P_r(d_m)=n_r(q_0).\] For every physical observable or observer readout \(M:Q_r\to Y\), \[M(P_r(d_m))=M(n_r(q_0))\] whenever \(P_r(d_m)\) is normal. In particular, \(\widetilde{\operatorname{Read}}_r(d_m)=\operatorname{Read}_r(n_r(q_0))\) for every distributed readout that factors through \(P_r\).

Proof. Induct on \(t\). The claim is true at \(t=0\). Suppose it holds at \(t\). For a linearizable physical commit, admissibility gives \[P_r(d_t)\to_r^*P_r(d_{t+1}),\] so \(q_0\to_r^*P_r(d_{t+1})\), and Lemma 83 gives \[n_r(P_r(d_{t+1}))=n_r(P_r(d_t))=n_r(q_0).\] For a physical stutter, \(P_r(d_{t+1})=P_r(d_t)\), so both statements are unchanged. For a certified rollback, \(P_r(d_{t+1})\) is the projection of an earlier committed state; the induction hypothesis gives reachability from \(q_0\) and equality of normal forms for that projection. This proves the two displayed identities for every \(t\).

If \(P_r(d_m)\) is a monolithic normal form, then it is the unique quotient normal form reachable from \(q_0\), hence \(P_r(d_m)=n_r(q_0)\). The observable and readout statements follow by applying \(M\) or \(\operatorname{Read}_r\) to this equality and using \(\widetilde{\operatorname{Read}}_r=\operatorname{Read}_r\circ P_r\). ◻

Corollary 85 (Partition, schedule, and restart invariance). Any two admissible distributed executions of the same finite carrier \(\mathbf U_r\), with the same initial quotient state \(q_0\), have the same terminal quotient observables and observer-readable outputs once their final projections are monolithic normal forms. The statement is independent of partition \(\kappa\), worker count, scheduler choices, restart history, and repartition metadata.

Proof. Apply Theorem 84 to each execution. Both final projections equal \(n_r(q_0)\), so every quotient observable and every readout factoring through the projection has the same value. ◻

Proposition 86 (Restart stabilization separates safety from liveness). Assume \(Q_r\) is finite, every physical commit strictly descends the accepted potential until normality, every rollback returns to an earlier committed projection, only finitely many progress-erasing rollbacks occur, and after the last such rollback the scheduler is fair enough to commit an enabled repair whenever the projected state is not normal. Then the distributed run reaches a monolithic normal form after finitely many physical commits.

Proof. Safety is Theorem 84. For liveness, ignore stutters and the finitely many progress-erasing rollbacks before the last one. After that time, each nonnormal projected state takes a strict descending accepted repair after finitely many scheduler steps. The set of possible potential values below the post-rollback value is finite, so strict descent can occur only finitely many times before a normal projected state is reached. ◻

Theorem 87 (Distributed refinement cube). Let \(r\preceq s\). Suppose \(\rho_{sr}:Q_s\to Q_r\) is a repair morphism, the corresponding holonomy maps form a cochain morphism, and distributed presentations at both stages are exact in the sense of Theorem 84. If the lifted restriction \(\widetilde\rho_{sr}:D_s\to D_r\) commutes with physical projection, \[P_r\circ\widetilde\rho_{sr}=\rho_{sr}\circ P_s,\] then distributed execution and coarse restriction commute on normal forms and readouts: \[P_r\!\left(\widetilde\rho_{sr}(d_m^s)\right) = n_r\!\left(\rho_{sr}(q_0^s)\right) = \rho_{sr}\!\left(n_s(q_0^s)\right)\] whenever the fine final projection is normal. The same statement holds for holonomy readouts via \(\chi_{sr}\).

Proof. The fine distributed theorem gives \(P_s(d_m^s)=n_s(q_0^s)\). Projection compatibility gives \[P_r(\widetilde\rho_{sr}(d_m^s))=\rho_{sr}(n_s(q_0^s)).\] Theorem 67 identifies this value with \(n_r(\rho_{sr}(q_0^s))\). The holonomy statement is exactly the cochain-morphism identity of Definition 68. ◻

Public certificate contract.

A run pack that claims Theorem 84 must emit enough evidence for a verifier to reconstruct the premises without trusting worker narration. The required fields are: a global carrier manifest and hash, the monolithic graph \(G_r\), the global initial quotient state \(q_0\), a partition map \(\kappa\), cut-interface records \(E_\kappa^{\mathrm{cut}}\) with restriction maps, a global observer registry, code/config/run hashes, a committed event log with a linearization witness for each physical commit, stutter records for noncommitting worker events, rollback records naming earlier committed projection roots, repartition records preserving the physical projection root, a final monolithic normal-form certificate, and a final readout recomputed from the projected state. Missing, stale, shard-local, or synthetic replacements for these fields fail closed. The exact branch uses this contract; noisy branches additionally need the fair-block constants of Theorem 90.

Quotient Chart Transport and Neutral Geometry

The distributed certificate above proves that a worker presentation is one finite quotient system. A separate step is needed before observer rows from different shards may be read as a common neutral geometry.

Definition 88 (Common quotient chart atlas). For a shard \(s\), let \(\Sigma_s\) be raw records, let \(\Gamma_s\) be the groupoid of declared presentation-only moves such as gauge representative changes and local port relabelings, and set \[\overline Q_s:=\Sigma_s/\Gamma_s,\qquad X_s:=n_s(\overline Q_s),\] where \(n_s\) is the schedule-independent normal-form map. An interface atlas is a family of domains \(U_{st}\subseteq X_s\), \(U_{ts}\subseteq X_t\), and bijections \[\tau_{ts}:U_{st}\to U_{ts}\] satisfying identity, inverse, and cocycle laws, with zero closed-path holonomy on graph-shaped systems. A channel registry assigns each channel \(c\) a metric space \((Z_c,d_c)\), weight \(w_c>0\), and local features \(F_{s,c}:D_{s,c}\subseteq X_s\to Z_c\). The channel descends through the atlas when both domain membership and values are transported: \[x\in D_{s,c}\Longleftrightarrow \tau_{ts}x\in D_{t,c}, \qquad F_{t,c}(\tau_{ts}x)=F_{s,c}(x).\]

Theorem 89 (Quotient-visible neutral readout). Under Definition 88, the relation generated by interface transport on \(\bigsqcup_sX_s\) is an equivalence relation and defines \[Q_{\mathrm{vis}}:=\left(\bigsqcup_sX_s\right)/\!\sim_\tau .\] The canonical maps \(X_s\to Q_{\mathrm{vis}}\) agree with transport, and zero closed-path holonomy makes them injective. Every compatible family of local channel maps descends uniquely to partial maps \(F_c:Q_{\mathrm{vis}}\dashrightarrow Z_c\). Therefore, on the complete channel domain \[Q_\star=\{x:F_c(x)\ \text{exists for every }c\in\mathcal C_\star\},\] fix \(p\ge1\) and assume that \(\mathcal C_\star\) is finite. More generally, an infinite declared channel set is admitted only if \[\sum_{c\in\mathcal C_\star} w_c\,d_c(F_c(x),F_c(y))^p<\infty \qquad\text{for every }x,y\in Q_\star.\] The product formula \[d_{\mathrm{neu}}(x,y) = \left(\sum_{c\in\mathcal C_\star}w_c\,d_c(F_c(x),F_c(y))^p\right)^{1/p}\] is then a finite-valued pseudometric. It is a metric only after quotienting by zero-distance feature collisions, or after proving that the declared channel family separates points.

Proof. Identity, inverse, and cocycle laws give reflexivity, symmetry, and transitivity. The transport compatibility of local features is exactly the universal-property condition for descent through the quotient. The weighted product distance is independent of the representative and finite by the finite-channel or pairwise-summability premise. Its triangle inequality is Minkowski’s inequality applied to the channel metrics. The only possible failure of identity of indiscernibles is equality of all declared feature values, which is removed by quotienting feature-collision classes or by a joint-separation proof. ◻

Certificate boundary.

Pairwise available-channel comparison is not a metric policy: different pairs can share different channels and violate the triangle inequality. A neutral-geometry run must therefore use complete cases, a fixed missing symbol whose mask is quotient-visible, or train-only imputation labelled as an imputed-representation metric. The run also records a finite channel list or a pairwise weighted-\(\ell^p\) summability certificate. Presentation invariance requires a bijection of \(Q_{\mathrm{vis}}\) and channel isometries, so gauge changes, port relabelings, observer order, repair schedule, and shard partition changes are checked on distance matrices, not on displayed coordinates. Refinement requires a cofinally vanishing tail modulus for the finite-stage distances. Euclidean claims require the double-centered Gram test \[B=-\frac12H(D^{\circ2})H\succeq0\] and noisy runs report negative spectral mass, rank/effective rank, held-out stress, and positive and negative controls. Before preprocessing, statistical certificates split independent generative batches. Chart alignment, scaling, imputation, weights, graph construction, dimension selection, and thresholds are train/validation objects. Any shared shard batch, seed, boundary condition, trajectory family, duplicate, descendant, or repeated test-set inspection blocks the held-out theorem. This section certifies a common quotient metric or pseudometric only; physical Riemannian or Lorentzian spacetime identification belongs to the separate modular/geometric branch.

Noisy Fair-Block Approximate Consensus

The exact consensus theorem supplies the quotient normal-form target. A noisy implementation needs one more quantitative certificate: complete fair blocks must contract expected distance to that target. This section records the conditional bridge from local noisy repair to long-run observer-facing approximate consensus.

Theorem 90 (Global noisy approximate consensus under fair-block contraction). Let \((Q,d_Q)\) be the observer-facing quotient state space of a fixed exported OPH patch federation, and let \(\mathcal N\subset Q\) be the exact quotient normal-form set supplied by the finite repair theorem on that quotient. Define \[D(q):=d_Q(q,\mathcal N)=\inf_{n\in\mathcal N}d_Q(q,n).\] Let \(q_{t+1}=\widetilde T_{i_t,t}(q_t)\) be a noisy asynchronous repair process adapted to a filtration \((\mathcal F_t)_t\). Assume:

  1. Exact quotient target. The ideal repair relation on \(Q\) has the exact OPH normal-form package: finite exact descent, the semantic-complete transactional local-diamond theorem with its concrete premise receipt, and repair completeness, so every fixed initial quotient state has a schedule-independent exact normal form in \(\mathcal N\).

  2. Fair asynchronous blocks. There are stopping times \[0=\tau_0<\tau_1<\tau_2<\cdots\] such that each interval \([\tau_m,\tau_{m+1})\) contains enough local repairs to expose and act on every active mismatch class required by the exact transaction/confluence and repair-completeness certificate, with uniformly bounded length \(\tau_{m+1}-\tau_m\le L\). Write the noisy block map as \[\widetilde B_m := \widetilde T_{i_{\tau_{m+1}-1},\,\tau_{m+1}-1} \circ\cdots\circ \widetilde T_{i_{\tau_m},\,\tau_m}.\]

  3. Uniform block contraction toward normal form. There are constants \(0<\lambda<1\) and \(\varepsilon\ge0\) such that, for every block \(m\) and every reachable quotient state \(q\) at time \(\tau_m\), \[\mathbb E\!\left[ D\!\left(\widetilde B_m(q)\right) \mid \mathcal F_{\tau_m} \right] \le \lambda D(q)+\varepsilon.\]

  4. Controlled within-block excursions. There are constants \(A\ge1\) and \(\beta\ge0\) such that, for every \(t\in[\tau_m,\tau_{m+1})\), \[\mathbb E\!\left[ D(q_t)\mid \mathcal F_{\tau_m} \right] \le A\,D(q_{\tau_m})+\beta.\]

Then, at fair-block times, \[\mathbb E[D(q_{\tau_m})] \le \lambda^mD(q_0) + \frac{1-\lambda^m}{1-\lambda}\,\varepsilon,\] and hence \[\limsup_{m\to\infty}\mathbb E[D(q_{\tau_m})] \le \frac{\varepsilon}{1-\lambda}.\] At all intermediate asynchronous times, \[\limsup_{t\to\infty}\mathbb E[D(q_t)] \le A\,\frac{\varepsilon}{1-\lambda}+\beta.\] Thus the noisy asynchronous OPH repair process converges in expectation to a controlled tube around the exact quotient normal-form set. If \(\varepsilon=\beta=0\), then \(D(q_t)\to0\) in \(L^1\), hence also in probability, along the full asynchronous run.

Proof. Let \(D_m:=D(q_{\tau_m})\). Assumption (G3), applied to the realized state \(q_{\tau_m}\), gives \[\mathbb E[D_{m+1}\mid \mathcal F_{\tau_m}] \le \lambda D_m+\varepsilon.\] Taking expectations, \[\mathbb E[D_{m+1}] \le \lambda\,\mathbb E[D_m]+\varepsilon.\] Iterating the scalar recursion gives \[\mathbb E[D_m] \le \lambda^mD(q_0) + \varepsilon\sum_{r=0}^{m-1}\lambda^r = \lambda^mD(q_0) + \frac{1-\lambda^m}{1-\lambda}\varepsilon.\] Taking \(m\to\infty\) yields the fair-block limsup bound. For \(t\in[\tau_m,\tau_{m+1})\), Assumption (G4) gives \[\mathbb E[D(q_t)] \le A\,\mathbb E[D(q_{\tau_m})]+\beta.\] Substitution of the fair-block estimate and then taking the limsup over all intermediate times gives \[\limsup_{t\to\infty}\mathbb E[D(q_t)] \le A\,\frac{\varepsilon}{1-\lambda}+\beta.\] If \(\varepsilon=\beta=0\), then \(\mathbb E[D(q_{\tau_m})]\le\lambda^mD(q_0)\to0\). Since \(D\ge0\), convergence in expectation to zero implies convergence in probability at block times. Assumption (G4) then gives \(\mathbb E[D(q_t)]\le A\,\mathbb E[D(q_{\tau_m})]\) inside each block, so the same \(L^1\) and probability convergence holds along the full asynchronous run. ◻

Corollary 91 (Approximate observer-facing schedule independence). Let \(M:Q\to Y\) be an observer-facing readout into a metric space \((Y,d_Y)\), and suppose \(M\) is \(L_M\)-Lipschitz. Fix an exact sector \(\zeta\) whose exact normal-form set is the singleton \(\mathcal N_\zeta=\{n_\zeta\}\), and apply Theorem 90 on that sector, so that \(D(q)=d_Q(q,n_\zeta)\). Then \[\limsup_{t\to\infty} \mathbb E\!\left[ d_Y(M(q_t),M(n_\zeta)) \right] \le L_M\left(A\,\frac{\varepsilon}{1-\lambda}+\beta\right).\] For two noisy asynchronous schedules \(q_t\) and \(q'_t\) started in the same exact singleton sector and satisfying the same certificate, \[\limsup_{t\to\infty} \mathbb E\!\left[ d_Y(M(q_t),M(q'_t)) \right] \le 2L_M\left(A\,\frac{\varepsilon}{1-\lambda}+\beta\right).\]

Proof. The Lipschitz condition gives \[d_Y(M(q_t),M(n_\zeta)) \le L_M d_Q(q_t,n_\zeta) = L_M D(q_t).\] The first bound follows from Theorem 90. The two-schedule bound follows from the triangle inequality through \(M(n_\zeta)\) and applying the first estimate to both schedules. ◻

Corollary 92 (High-probability noisy consensus tube). Assume the block-distance process also admits the pathwise decomposition \[D_{m+1} \le \lambda D_m+\varepsilon+\xi_{m+1}, \qquad \mathbb E[\xi_{m+1}\mid\mathcal F_{\tau_m}]=0, \qquad |\xi_{m+1}|\le b\] almost surely. Then, for every \(a>0\), \[\Pr\!\left[ D_m> \lambda^mD_0 + \frac{1-\lambda^m}{1-\lambda}\varepsilon + a \right] \le \exp\!\left( -\frac{a^2(1-\lambda^2)}{2b^2} \right).\]

Proof. Unrolling the recursion gives \[D_m \le \lambda^mD_0 + \frac{1-\lambda^m}{1-\lambda}\varepsilon + \sum_{r=1}^{m}\lambda^{m-r}\xi_r.\] The final term is a weighted martingale sum with increments bounded by \(|\lambda^{m-r}\xi_r|\le\lambda^{m-r}b\). Azuma–Hoeffding gives \[\Pr\!\left[ \sum_{r=1}^{m}\lambda^{m-r}\xi_r>a \right] \le \exp\!\left( -\frac{a^2}{2\sum_{r=1}^{m}\lambda^{2(m-r)}b^2} \right).\] Since \(\sum_{r=1}^{m}\lambda^{2(m-r)}\le(1-\lambda^2)^{-1}\), substitution yields the claimed bound. ◻

Proposition 93 (Finite fair-block contraction certificate). Let \(Q\) be finite, let \(\mathfrak B_{\mathrm{fair}}\) be a finite list of noisy fair-block types, and let \(K_B(q,q')\) be the Markov kernel induced by block type \(B\). If there are constants \(0<\lambda<1\) and \(\varepsilon\ge0\) such that \[\sum_{q'\in Q}K_B(q,q')D(q') \le \lambda D(q)+\varepsilon \qquad \forall q\in Q,\quad \forall B\in\mathfrak B_{\mathrm{fair}},\] then Assumption (G3) of Theorem 90 holds for any run whose fair blocks are drawn from \(\mathfrak B_{\mathrm{fair}}\).

Proof. Conditioning on the current quotient state \(q\) and the realized fair-block type \(B\), the conditional expectation of \(D\) after the block is exactly \(\sum_{q'}K_B(q,q')D(q')\). The displayed inequality is therefore Assumption (G3), uniformly over all reachable states and fair-block types. ◻

Finite audit route and constants.

For a finite exported packet net, Proposition 93 gives the practical certificate path: \[\begin{gathered} \text{finite quotient }Q \Rightarrow \text{exact normal forms }\mathcal N \Rightarrow \text{distance table }D(q)\\ \Rightarrow \text{noisy fair-block kernels }K_B \Rightarrow (\lambda,\varepsilon)\text{ certificate}. \end{gathered}\] Here \(\mathcal N\) is the exact quotient normal-form set, \(D(q)\) is observer-facing residual distance to that set, \(\lambda\) is the net contraction produced by one completed fair block, \(\varepsilon\) is the per-block irreducible local recovery / record / readout / calibration / environmental noise, \(A\) bounds transient within-block expansion, \(\beta\) is the within-block noise floor, and \(L\) is the fairness horizon before all required active mismatch classes are serviced. In quantum/collar implementations, \(\varepsilon\) may absorb Petz-domain truncation, Fawzi–Renner recovery error, approximate central-record error, detector/readout noise, and coarse-graining defect.

Claim boundary.

Theorem 90 is a conditional global noisy-consensus theorem. It does not follow from the exact finite repair theorem alone. The exact OPH theorem supplies the quotient normal-form target \(\mathcal N\); the noisy theorem requires a separate fair-block contraction certificate \((\lambda,\varepsilon,A,\beta,L)\) for the chosen implementation. Without that certificate, OPH retains exact fixed-cutoff convergence and the collar-local splice and record-stability estimates above. With that certificate, arbitrarily long asynchronous noisy repair sequences converge to a controlled observer-facing tube around the exact quotient normal-form set.

Law-Space Selection and Observer Emergence

This section studies a simple meta-selection model on law space. The aim is to formalize one criterion for favoring schedule-stable, observer-supporting, and simple laws; the replicator dynamics below is part of the model, not a claim about literal cosmological dynamics.

We begin by defining what it means for a law to support observers. An observer is treated operationally as a persistent predictive module: a subgraph that maintains a stable record algebra and uses its output law to predict its boundary’s future behavior.

Definition 94 (Schedule stability). Fix distributions \(\mu\) over initial conditions and \(\nu\) over asynchronous schedules, and a gauge-invariant observable \(M\). For a law \(\lambda\), define \[\mathcal{R}_M(\lambda) := \Pr_{s\sim\mu,\;\sigma,\tau\sim\nu} \!\left[ M\bigl(\operatorname{nf}^{\sigma}_\lambda(s)\bigr) = M\bigl(\operatorname{nf}^{\tau}_\lambda(s)\bigr) \right].\] If Theorem 31 holds for \(\lambda\), then \(\mathcal{R}_M(\lambda)=1\).

Definition 95 (Observer yield). Let \(X_t^\lambda\) denote the stationary process obtained by repeated local perturbation plus reconciliation under law \(\lambda\). For each subgraph \(U\subseteq V\), let \(\mathcal Z_U^{\mathrm{rec}}(t)\) be the declared exact record algebra on its observer-accessible surface, or the reference exact algebra when only an approximate record presentation is available, and let \(Y_U(t)\) be the corresponding finite outcome variable induced by that record algebra. Then \(U\) is \((\eta,\varepsilon,h)\)-observer-like if it is record-stable: \[d_{\mathrm{TV}}\!\bigl(\operatorname{Law}(Y_U(t+h)),\operatorname{Law}(Y_U(t))\bigr)\le \eta,\] and predictive: \[I\bigl(Y_U(t);\; X_{\partial U,\,t+1:t+h}^\lambda\bigr)\ge\varepsilon.\] Define \[\mathcal{O}_{\eta,\varepsilon,h}(\lambda) := \mathbb{E}\!\left[ \#\left\{ U\subseteq V: U \text{ is } (\eta,\varepsilon,h)\text{-observer-like} \right\} \right].\]

Definition 96 (Law fitness). Let \(K(\lambda)\) be a description-length penalty. Define \[f(\lambda) = \alpha\,\mathcal{R}_M(\lambda) + \beta\,\mathcal{O}_{\eta,\varepsilon,h}(\lambda) - \gamma\,K(\lambda),\] with \(\alpha,\beta,\gamma>0\).

Theorem 97 (Replicator monotonicity on law space). Let \(\Lambda=\{\lambda_1,\dots,\lambda_m\}\) be candidate laws with population weights \(x_i(t)\) under replicator dynamics: \[\dot{x}_i = x_i(f_i - \bar{f}), \qquad f_i := f(\lambda_i), \qquad \bar{f} := \sum_{j=1}^m x_j f_j.\] Then \[\frac{d}{dt}\bar{f} = \operatorname{Var}_x(f) \ge 0.\] Mean fitness is nondecreasing, and strictly increasing unless all extant laws have the same fitness.

Proof. Direct computation: \[\frac{d}{dt}\bar{f} = \sum_i \dot{x}_i f_i = \sum_i x_i(f_i - \bar{f})f_i = \sum_i x_i f_i^2 - \bar{f}^2 = \operatorname{Var}_x(f) \ge 0.\] Equality iff all \(f_i\) on the support of \(x\) are equal. ◻

This theorem records the monotonicity property of the meta-selection model.

Connection to Observer-Patch Holography

The formalism above is the computational skeleton of Observer-Patch Holography (OPH). The observer patches carry von Neumann algebras on support-visible holographic cuts. In symmetric regulator charts those cuts may be represented by patches on a screen \(S^2\). The fixed-cutoff microphysics carrier is a federated patch system with echosahedral local interfaces. The \(S^2\) chart supplies cap and collar geometry, and in the companion relativity branch its conformal group supplies the Lorentz bridge. The carrier supplies finite ports, records, and repair interfaces. The overlap projections are restrictions to shared subalgebras, and the consistency condition is algebraic state agreement on overlaps.

The local carrier boundary, finite federation screen, and support \(S^2\) are different typed objects. Identical local Icosahedral carriers can be routed into federation nerves of different topology. A spherical physical branch therefore requires the microphysics paper’s carrier-to-support bridge: full interface-algebra maps, higher-overlap coherence, a quotient-visible spherical nerve, and refinement-natural support data. The consensus theorem neither supplies nor replaces that bridge. The two-carrier reference fixture has no composable seam triangle, so its higher-overlap Čech condition is vacuous. Its seam/hash, phase-to-repair, and structural support checks do not certify a physical federation, a source-bound spherical support, or the \(S^2\) bridge.

The bridge to physics works as follows in the companion papers:

  • The patch net becomes a net of support-visible subregion algebras; \(S^2\) is the standard observer-facing support chart, not a required literal material shell. Its quotient-visible topology and conformal data are physical on the spherical branch even though hidden carrier coordinates are not.

  • Observer Agreement, Axiom 2, is the naturality condition on the operational meanings attached to accepted data in Definition 1.

  • The explicit collar-recovery, exact-Markov, and Markov-split alignment interfaces provide the controlled recovery data used by the gravity branch. The exact collar factorization \(\rho_{ABD} = \bigoplus_\alpha p_\alpha\,\rho^{(\alpha)}_{Ab_L^\alpha}\otimes\rho^{(\alpha)}_{b_R^\alpha D}\) is used only at exact Markovity together with alignment of the HJPW factors with the preselected edge split. Exact Markovity alone yields the normal form only over a state-dependent split. The alternative route uses the fixed-collar replacement limit with EC-aligned comparison states, while the declared Petz/Fawzi–Renner recovery channels supply recovered comparison states from which the local repair moves are built (see Appendix 15 and Definition 111).

  • Gauge symmetry as implementation hiding (Theorem 43) becomes the fixed-cutoff edge-sector seed package. On the Standard Model gauge paper’s branch carrying the explicit compact-gauge refinement receipt, coherent surjective pullback functors and compatible forgetful fibers reconstruct a compact group from the tensor-generated combined-zero-obstruction sectors. Here zero obstruction means central or higher-associator strictifiability together with at least one allowed strict \(1\)-cocycle representative having trivial represented holonomy. This supplies receipt-conditional transport across cutoffs and classification. Separately, complete reversible response and endogenous overlap transport force the local Standard Model gauge Lie algebra. Incidence and target-blind port readback derive the signed response. Under the conditional matrix current and declared fermionic Spin category, anomaly-forced determinant balance and exhaustive tensor descent imply the exact hypercharge lattice, \(N_c=3\), a common \(\mathbb Z_6\) kernel, and the maximal faithful matter image from those premises alone. On this branch, the CKM and weak-sector clauses give the window \(3\le N_g\le5\). Separate complete-band and cost-order premises select rank three. Physical family identification and extra-sector exclusion require additional maps. The construction does not source-select the matrix current, matter action, or physical global quotient and does not identify laboratory current or flux, equality with the independently reconstructed Tannaka current, four-dimensional topological normalization, or scalar multiplicity. The selected rank-three response and declared generation table give a conditional rank-\(45\) candidate. Chirality and the diagonal \(\mathbb Z_6\) action are table properties. A separate finite local-domain receipt checks the declared operator \(D_\sigma\otimes I_{45}\) and conditional gap inheritance without source-selecting the matter action or transporting the twelve-port Spin packet to that domain. It supplies no physical matter-pole identification, continuum Spin/locality limit, physical seam selection, refinement persistence, or laboratory attachment.

  • On the declared support-visible compact-gauge branch, the Standard Model gauge paper obtains the four-dimensional Euclidean Yang–Mills form from compact-gauge holonomy data and the local MaxEnt/Gibbs continuum limit only with the branch’s renormalized four-dimensional identification receipt. The Standard Model gauge paper separately proves projective weak-* / GNS extraction from its finite cylinder system. On a finite support quotient, weighted resampling inside observation fibers is the orthogonal conditional-expectation projector. A concrete active repair kernel qualifies only when its independently extracted transition matrix satisfies the support, equal-fiber-row, and weighted detailed-balance receipt of Ref. [source]; constructing the tested matrix from the target projector formula is not a verification. Identification with Euclidean transfer, vacuum persistence, OS reconstruction, noncollapse, and passage of the uniform repair gap require their separately named finite and continuum receipts. On that certified branch the Yang–Mills gap equals the repair gap; coherent cylinder extraction alone does not make that identification or supply a Clay-admissible theory.

  • The coarse-graining compatibility theorem (Theorem 71) is the link between the finite reconciliation protocol and the refinement/RG language used by the OPH branches: the macroscopic law space is stable when the selected coarse-graining channel shadows the normal-form and obstruction maps with controlled defects.

  • Stable defects (Corollary 40) become the topologically protected excitations identified with particles on the declared branch.

  • The record-algebra theorem (Theorem 74) provides the formal basis for the fixed-cutoff observation layer, where records are carried by central or quantitatively stable approximately commuting projectors in overlap centers.

The companion manuscripts develop a derived gravity branch from entanglement equilibrium and modular geometry, the exact finite Standard Model gauge implication under explicit response and matter contracts with a distinct conditional Tannaka reconstruction route, the declared completions for generation count and extra light sectors, a conditional support-visible compact-gauge Yang–Mills form and repair-gap theorem under the separately named continuum-identification, transfer, OS/noncollapse, and uniform-gap receipts, and a controlled large-\(N_{\mathrm{edge}}\) worldsheet effective-description branch above the heat-kernel edge-sector identity. The cosmological capacity branch defines direct readback by the correctable code of reachable public records, \(M_0(q)=\alpha(G_q)\). A source-derived fixed-cutoff simulator packet at \(D=24\) scalarizes its complete declared terminal fiber and supplies reversible extension/refinement receipts inside its declared source category. When the whole capacity-indexed terminal fiber scalarizes, \(M_0(\mathfrak U_N)=\widehat F_{r,0}(e^N)\) and the universe-level equation is \(N=\log M_0(\mathfrak U_N)\); its stable finite form is \(\mathfrak F_{r,0}(D_\star)=\{D_\star\}\). A target-clean all-rung counterfamily has incompatible exact fixed sets under shared base agreement, positivity, the carrier bound, and executable finite controls. This proves nonidentifiability for the bounded completion class. Universal all-rung membership in the complete A1–A3 capacity-source contract and an executable-to-Lean bridge are absent. The incomplete source antecedent does not determine \(N\), and no theorem extends the bounded nonidentifiability result to the complete source class. A direct positive theorem would require a complete source antecedent, one physical zero, the physical-universe carrier attachment, the horizon–record identification, and the common screen/electroweak load-carrier identification. These inputs are not supplied by the consensus theorem.

This paper provides the finite patch-net foundation for the companion constructions.

Discussion and Scope Boundaries

The fixed-point consensus spine of OPH consists of a total, idempotent, boundary-preserving quotient repair operator on the declared finite branch; schedule-independent normal forms from fixed initial quotient states; boundary-conditioned uniqueness when a preserved boundary/sector fiber has a unique consistent extension; a finite layered carrier proving \(H_B\wedge H_{\mathrm{fib}}\); nontrivial functional selected-fiber branch elimination; holonomy obstructions; gauge-quotient invariance, separated cofinal refinement-limit consensus classes, controlled coarse-graining compatibility, the fixed-cutoff operator-record theorem, distributed one-universe realization for admissible worker presentations of a single global carrier, and conditional noisy fair-block convergence once a separate contraction certificate is supplied. For the repository’s canonical single-site attempt semantics, every adaptive run is eventually constant. Pathwise weak fairness is the exact additional condition used here to exclude a reducible constant tail; work conservation is stronger and is used only for the initial-mismatch horizon. Completeness and confluence remain separate requirements for one consistent canonical public endpoint. It also proves the full repair-completeness, Petz-domain, and quotient-compatibility package on the rooted-tree packet-net domain of Theorem 20, and gives a clean law-selection meta-model. Separate companion constructions give the relativity chain, the realized Standard Model structural chain, and the capacity relation with universe-level equation \(N=\log M_0(\mathfrak U_N)\), stable whole-fiber target \(\mathfrak F_{r,0}(D_\star)=\{D_\star\}\), and an independent EW/Higgs comparison bridge. Phenomenological conclusions require assumptions not supplied by the consensus theorems.

Under the unified carrier hypothesis, consensus turns a routed, self-reading carrier federation into a quotient-visible normal form. Separate maps read support geometry and compact charge response from that normal form. Confluence does not create either readout. Their physical composition requires one source manifest and refinement tower so that geometry, current, records, and clocks refer to the same system rather than to isomorphic fixtures assembled after the fact.

Complexity boundary.

On a fixed finite patch net, the accepted reconciliation dynamics is a finite-state asynchronous rewrite system on \(\Sigma\). Under Theorem 31, every accepted repair run has at most the number of distinct reachable \(\mu\)-values below its start value minus one, because each accepted transaction strictly lowers the declared exact measure. On the scalar \(\Phi\)-branch this specializes to the \(|\Phi(\Sigma)|-1\le |\Sigma|-1\) bound. Exact normal-form computation is therefore decidable by direct iteration of accepted aggregate transactions. This step bound counts accepted nontrivial repairs rather than scheduler attempts, which may stutter. Theorem 26 separately shows eventual constancy for every canonical adaptive attempt stream and normality under pathwise weak fairness. Theorem 27 shows that no single mismatch-only finite attempt horizon uniformly bounds all normalizing schedulers; bounded waste supplies the \((q+1)\)-scaled upper horizon, with exact sharpness at \(q=0\), and Corollary 34 consumes a sufficient budget. The schedule-independent answer depends on the atomic conflict-component local diamond and repair-completeness clauses of Theorem 31. What this paper does not prove is a uniform polynomial-time bound, a sharper complexity-class placement for families of growing patch nets, or any hardness lower bound.

Approximate-stability boundary.

The theorem-grade consensus statement is exact on the declared fixed-cutoff branch. Approximate control begins collar-locally: Theorem 98 gives the exact-Markov modulus \(\delta^{\mathrm M}_{A:B:D}(\varepsilon)\to0\) on one fixed finite-dimensional collar model and the one-shot recovery comparison bound \(2\sqrt{1-e^{-\varepsilon}}\le 2\sqrt{\varepsilon}\), while Theorem 74 gives the \((\varepsilon,\delta_{\mathrm{rec}})\) repeated-read stability bound for approximate record projectors. The long-run noisy statement is conditional: Theorem 90 upgrades those local noisy controls to a global expected tube around the exact quotient normal-form set only after a fair-block contraction certificate \((\lambda,\varepsilon,A,\beta,L)\) is supplied for the chosen implementation. It does not follow from finite descent or fairness alone, and it gives a unique approximate readout only inside singleton boundary/sector fibers. Ref. [source] supplies a complementary receipt-only endpoint estimate from a residual error-bound modulus and an inverse-observation modulus, together with refinement comparison bounds. Those results do not manufacture the fair-block contraction used here and do not imply pathwise long-run confinement under persistent noise.

Expressive-power boundary.

The law-selection model of Theorem 97 is a finite-candidate monotonicity result. For each fixed patch net the theorem package proves a finite-state exact reconciliation mechanism. The computation modules separate three exact results. The historical theorem constructs an input-specialized federation and one ordered sweep; its weak RepairStep permits stutter and remains a straight-line satisfiability precursor. The fixed-federation continuation instead uses the generated formula nodes, which are independent of the input, and reads immutable input ports from the initial state. Its canonical accepted step performs the selected failing node’s declared write. A superincreasing dependency rank strictly descends on every genuine step; arbitrary attempts stabilize, and pathwise weak fairness promotes the stable state to consensus. Same-input normal endpoints have one output. A one-member fair-stuttering control shows why the historical weak relation itself cannot support that conclusion. The execution continuation makes the remaining mathematical scheduler and cost boundary exact. Tail-relative pathwise weak fairness is equivalent to eventual stable consensus on a fixed run; the reverse is vacuous after stable consensus and supplies no recurrence. Member and register-site recurrence coincide at the generated-node granularity because output registers are unique, while an actual stable-consensus schedule proves recurrence remains strictly stronger than tail fairness. A state-blind round-robin function is recurrent, pathwise weak-fair, and bounded-waste, so at least one explicit mathematical scheduler reaches the correct same-input output. Its first \(n\) attempts are exactly the emission-order compiler sweep, the order in which the compiler emits nodes, so this explicit scheduler reaches stable consensus and the correct output within \(n\) attempts for \(n\) emitted nodes.

The actual go compiler has at most one downstream consumer per generated register. Linear defect weights therefore bound every canonical accepted path by \(n(n+1)/2\) for \(n\) emitted nodes. A recursively nested NAND family from that compiler has a consensus-reaching path with \(8m+1=n^2+8n\), making the same-metric classification order-sharp \(\Theta(n^2)\), not constant-sharp. Well-formedness alone admits fewer than \(2^n\) accepted steps and an explicit fanout chain attains \(2^n-1\), so the single-consumer structure is load-bearing for the quadratic bound. Arbitrarily long finite stuttering prefixes remain pathwise weak-fair, so weak fairness gives no uniform attempt horizon. A separately supplied fixed-node bounded-waste value \(q\) gives a stable horizon of \((q+1)n(n+1)/2\); round robin supplies \(q=n-1\). The bounded-waste counting proof is shared with the adaptive route through a neutral ranked-attempt theorem, while the two domain adapters and scientific claims remain distinct. The general bounded-waste formula is deliberately retained for other schedulers; the direct one-cycle theorem is the sharper linear bound for emission-order round robin. Separately, a width-five permutation word program is fixed independently of the input and evaluates the formula under the stated encoding; the formal carrier is the ambient permutation group on five points, and membership of every instruction in the alternating subgroup is not a typed theorem. These results establish a fixed finite repair device with accepted nontrivial repairs and fair asynchronous convergence. They prove a mathematical round-robin function and conditional attempt counts, but no physical scheduler source, wall-clock horizon, rate, energy, bandwidth, fee, hardware resource, noise stability, physical device realization, finite PublicWorld, or identity with the width-five engine.

Refinement and observable boundaries.

Theorem 71 gives an abstract reconciliation square under coarse-graining once its normal-form and obstruction defects are supplied. Model-specific or uniform bounds for \(\varepsilon^n_{sr}\) and \(\varepsilon^h_{sr}\) are not derived from concrete coarse-graining channels and recovery decoders. The fixed-cutoff defect hierarchy extends from abelian frustrations to crossed-module classes \(q\in\check H^2(N,H\to G)\), without an identification theorem relating those classes to the refinement-stable transportable sector category. Theorem 57 applies when microscopic representatives differ by gauge relabelings globally or by sector or higher-gauge relabelings on the same declared quotient-local glued state. It does not cover approximate union-collar compatibility or a physical observable algebra that changes under refinement.

Distributed and noisy implementations.

Theorem 84 proves worker-presentation invariance only when the implementation supplies one global carrier, authoritative ownership, cut interfaces, projection-preserving events, rollback roots, and final monolithic normal-form and readout certificates. Shard-local seeds, missing cut artifacts, stale manifests, synthetic seam trajectories, or worker-identifier histories do not certify a one-universe realization. Theorems 98 and 74 give collar-local perturbative controls, while the rooted-tree packet domain gives an exact finite repair package on one nontrivial domain. Theorem 90 gives long-run noisy control only under a fair-block contraction certificate. Arbitrary approximate recovery moves do not inherit repair completeness, transactional validation, a quotient local diamond, the support/completely-positive trace-preserving clause on every Petz branch, or fair-block contraction.

Universality and applications.

The fixed computation-federation theorem gives one finite generated-node repair device for every input of a selected Boolean function, with ranked accepted-step termination and fairness-qualified attempt convergence. It is not an encoding-overhead, rate, hardware, or physical uniform-simulation theorem, and it does not make the historical weak step convergent. The separate fixed width-five word-program result remains a different engine. The fixed-point theorem classifies quotient normal forms and obstructions once a physical quotient and repair law are declared. It does not select a Hall sector, material order, confinement regime, nuclear yield, or hardware performance number without a quotient-intrinsic ensemble, source action, repair ledger, and evidence receipts.

Gravity and gauge interfaces.

The support-visible Bisognano–Wichmann scaling theorem on the geometric cap subnet supplies the gravity interface. The finite-state and refinement-consensus results supply its consensus input. The finite-quotient baryogenesis theorem uses the same input to define an oriented repair current and proves that quotient settlement with an oriented register selects no charge-parity sign. The natural \(\mathbb Z_6\) gauge/deck attachment has zero electroweak anomaly coefficient. A nonzero baryogenesis result, dark-sector model, spectroscopy result, or string/worldsheet construction requires separate physical inputs. These are interfaces rather than extra consensus premises.

Assumption-Dependent BFT and QECC Extensions

The consensus formalism of OPH has natural analogies to classical and quantum distributed Byzantine agreement. Observer patches correspond to protocol nodes, overlap repair corresponds to a quorum vote, and the repair fixed-point corresponds to a consensus state. Under explicit structural assumptions (partial synchrony with an effective phase bound, one-value-per-view and monotone-view participation, finalisation only on a valid prepared-backed decision certificate, authenticated prepared-certificate locks, highest-certificate new-view selection, post-stabilisation nonfaulty proposal/prepare/commit/relay progress, and quorum overlap: either the classical exact sizing \(n=3f+1,q=2f+1\) or a general threshold \(q\) with \(2q\ge n+f+1\); liveness additionally requires \(q\le n-f\)), a QBFT-style interpretation of OPH repair satisfies safety and liveness (Appendix 17, Theorem 110). On the fixed-cutoff collar branch used here, the repair map is written in exact-splice / Petz form; the assumption-dependent item is the CPTP property on all inputs, which requires either full-rank \(\mathcal{N}(\sigma)\) or an explicit domain restriction, and trace-preserving completion is not automatic when \(\mathcal{N}(\sigma)\) has a non-trivial kernel (Proposition 113). A quantum error-correcting interpretation is possible only after a genuine code subspace, logical dictionary, error family, and recovery map are supplied. The graph-min-cut equality for distance is not a property of a bare overlap graph: the same graph can realize distance \(1\) or distance \(|V|\) under different interface maps (Theorem 118). Distance/min-cut statements require the topological-code certificate of Definition 119 and Theorem 120; resilience requires the Knill–Laflamme certificate of Theorem 122. All of these extensions are assumption-dependent or conjectural and are not part of the core theorem package of Paper 4.

Desired statement Required certificate
Overlap network is a code finite constraint-code data of Proposition 3
Local repair is a physical map \(\operatorname{locRep}_\lambda:Q\to Q\) on the finite quotient presentation, with boundary preservation and exact descent
Global repair is a physical normal-form map \(\operatorname{Rep}_\lambda=\overline{\operatorname{nf}}_\lambda:Q\to Q\), total, idempotent, schedule-independent, and landing in \(C_Q\)
Repair respects gauge quotient-valued \(\operatorname{Rep}^{\Sigma}_\lambda=\operatorname{Rep}_\lambda\circ q\), hence invariant under \(\Gamma\)
Boundary reconstruction layered finite carrier with \(H_B\wedge H_{\mathrm{fib}}\) and \(\operatorname{Rep}_\lambda(x)=E(B(x))\) on admissible fibers
Repair converges finite exact descent; confluence additionally needs semantic-complete transactions, coherent canonical aggregate gluing, and repair completeness, with a concrete receipt for the theorem premises and peaks
Distance equals min-cut topological-code certificate with homological logicals and matching systole/min-cut geometry
Corrects \(t\) corrupted carriers code projector, error family, Knill–Laflamme condition, and certified \(t<d/2\) distance bound
Exponential convergence declared transfer/channel operator with stationary projection and spectral gap
Long-run noisy approximate consensus fair-block contraction certificate \((\lambda,\varepsilon,A,\beta,L)\) for distance to the exact quotient normal-form set
Cross-view BFT safety and wall-clock liveness valid prepared-backed decision certificates, one-value and monotone-view participation, monotone prepared locks, authenticated quorum-overlap sizing \(n=3f+1,q=2f+1\) or \(2q\ge n+f+1\); liveness from timeout-bound activation also needs \(q\le n-f\), an effective post-GST phase bound \(\Theta\), fair terminating view change, highest-certificate proposal selection, and nonfaulty proposal/prepare/commit/relay progress
Hardware search work reduction exact-verifier candidate-enrichment factor measured under controls

Quantum/Algebraic Lift: Markov-Collar Splice Theorem

This appendix records the algebraic splice statement relating the finite patch-net model to the OPH collar formalism.

For this collar lemma, write the support-local algebra-state-record reduct of an observer patch as \[O_{\mathrm{red}}=(P,\mathcal{A}(P),\rho,R),\] where \(P\) is the support-screen patch, \(\mathcal{A}(P)\) the local von Neumann algebra, \(\rho\) the local state, and \(R\) the record algebra. The full operational observer also carries overlap interface algebras and restriction maps, allowed update and repair instruments, and checkpoint data used for continuation.

Theorem 98 (Markov-collar splice theorem, exact and controlled). Suppose a collar tripartition \(A\)-\(B\)-\(D\) has the EC-aligned exact Markov decomposition \[\rho_{ABD} = \bigoplus_{\alpha} p_\alpha\, \rho^{(\alpha)}_{A b_L^\alpha} \otimes \rho^{(\alpha)}_{b_R^\alpha D}\] over the preselected edge factors. This displayed form is the hypothesis: by the spacetime and Einstein paper’s Markov-split alignment analysis it is strictly stronger than \(I(A:D\mid B)_\rho=0\), which by HJPW yields such a factorization only over a state-dependent split of \(B\). Let \(\sigma_{b_R^\alpha D'}^{(\alpha)}\) be any family of normalized environment states compatible with the same right-boundary sectors. Define \[\rho'_{AB D'} = \bigoplus_{\alpha} p_\alpha\, \rho^{(\alpha)}_{A b_L^\alpha} \otimes \sigma_{b_R^\alpha D'}^{(\alpha)}.\] Then for every observable \(X\) supported on \(A\cup b_L\), \[\operatorname{Tr}(X\rho'_{AB D'}) = \operatorname{Tr}(X\rho_{ABD}).\] Fix one finite-dimensional collar model and let \[\mathfrak M_{A:B:D} := \left\{ \tau_{ABD}: I(A:D\mid B)_\tau=0 \right\},\] with exact-Markov distance modulus \[\delta^{\mathrm M}_{A:B:D}(\varepsilon) := \sup\left\{ \inf_{\tau\in\mathfrak M_{A:B:D}}\|\omega-\tau\|_1: I(A:D\mid B)_\omega\le\varepsilon \right\}.\] Then \[\delta^{\mathrm M}_{A:B:D}(\varepsilon)\to0 \qquad (\varepsilon\downarrow0).\] On a fixed faithful collar class with lower floor \(\lambda_\ast>0\), this qualitative modulus can be sharpened to a collar-local rate \[\delta^{\mathrm M,\lambda_\ast}_{A:B:D}(\varepsilon) \le C_{A:B:D,\lambda_\ast}\,\varepsilon^{\theta_{A:B:D,\lambda_\ast}},\] by the compact real-analytic Lojasiewicz inequality applied to \(I(A:D\mid B)\). The constants depend on the fixed collar model and floor; they are not a dimension-free stability theorem for arbitrary tripartite systems. Let \(\mathfrak M^{\mathrm{EC}}_{A:B:D}\subset\mathfrak M_{A:B:D}\) be the states that also satisfy the Markov-split alignment hypothesis on the preselected edge factors. For a declared controlled family \(\mathcal F\), define \[\delta^{\mathrm{M,EC}}_{\mathcal F;A:B:D}(\varepsilon) := \sup\left\{ \inf_{\tau\in\mathfrak M^{\mathrm{EC}}_{A:B:D}}\|\omega-\tau\|_1: \omega\in\mathcal F,\ I(A:D\mid B)_\omega\le\varepsilon \right\}.\] Convergence of the generic exact-Markov modulus does not imply convergence of this aligned modulus. Hence, if \(\omega\in\mathcal F\), \(I(A:D\mid B)_\omega\le \varepsilon\), and the controlled family separately satisfies \(\delta^{\mathrm{M,EC}}_{\mathcal F;A:B:D}(\varepsilon)\to0\), choose \(\widetilde\omega_\varepsilon\in\mathfrak M^{\mathrm{EC}}_{A:B:D}\) so that \[\|\omega-\widetilde\omega_\varepsilon\|_1 \le \delta^{\mathrm{M,EC}}_{\mathcal F;A:B:D}(\varepsilon),\] the corresponding exact splice \(\widetilde\omega'_\varepsilon\) satisfies \[\left| \operatorname{Tr}(X\omega)-\operatorname{Tr}(X\widetilde\omega'_\varepsilon) \right| \le \|X\|_\infty\, \delta^{\mathrm{M,EC}}_{\mathcal F;A:B:D}(\varepsilon)\] for every observable \(X\) supported on \(A\cup b_L\).

Independently, if \(I(A:D\mid B)_\omega\le \varepsilon\), then there exists a recovery map \(\mathcal R_{B\to BD}\) such that \[\left\| \omega_{ABD} - (\mathrm{id}_A\otimes \mathcal R_{B\to BD})(\omega_{AB}) \right\|_1 \le 2\sqrt{1-e^{-\varepsilon}} \le 2\sqrt{\varepsilon}.\]

Proof. The exact splice statement is the usual blockwise factorization argument: \[\operatorname{Tr}(X\rho'_{AB D'}) = \sum_\alpha p_\alpha\, \operatorname{Tr}\!\left( X\, \rho^{(\alpha)}_{A b_L^\alpha} \right) \operatorname{Tr}\!\left(\sigma_{b_R^\alpha D'}^{(\alpha)}\right).\] Each right factor is normalized, so the value agrees with the same computation for \(\rho_{ABD}\).

For the controlled statement, compactness of the fixed finite-dimensional state space and continuity of conditional mutual information imply \(\delta^{\mathrm M}_{A:B:D}(\varepsilon)\to0\): otherwise one could find a sequence with \(I(A:D\mid B)\to0\) staying a fixed trace distance away from every exact Markov state, contradicting convergence of a subsequence to an exact Markov limit point. This generic fact does not prove the separately assumed aligned-modulus convergence: the splice identity requires \(\widetilde\omega_\varepsilon\) to be EC-aligned over the preselected edge factors, while small conditional mutual information supplies closeness only to the full exact Markov set. Once such an EC-aligned \(\widetilde\omega_\varepsilon\) is chosen with the declared family-specific bound, the exact splice identity gives \[\left| \operatorname{Tr}(X\omega)-\operatorname{Tr}(X\widetilde\omega'_\varepsilon) \right| = \left| \operatorname{Tr}\!\left[X(\omega-\widetilde\omega_\varepsilon)\right] \right| \le \|X\|_\infty\, \delta^{\mathrm{M,EC}}_{\mathcal F;A:B:D}(\varepsilon).\] The final inequality is the standard Fawzi–Renner recovery bound [source]. ◻

This appendix therefore uses exact splice identities in only two regimes: literal EC-aligned exact Markovity, or a controlled collar family on one fixed finite-dimensional model for which the separately declared \(\delta^{\mathrm{M,EC}}_{\mathcal F;A:B:D}(\varepsilon)\to0\). Fawzi–Renner recovery supplies the constructive recovered comparison state; the generic fixed-collar modulus supplies only an exact-Markov comparison on a possibly different split. Small one-shot conditional mutual information is not silently upgraded to an EC-aligned normal form.

For later dark-sector continuations, the exact finite identity is only an expectation identity. For a faithful finite state \(\rho_{ABD}\), with \(K_X=-\log\rho_X\), \[\operatorname{Tr}\rho_{ABD}(K_{AB}+K_{BD}-K_B-K_{ABD}) = I_\rho(A:D\mid B).\] This does not identify raw conditional mutual information with a state-independent local stress source. Near a full-rank exact Markov state \(\sigma\), a perturbation \(\rho(t)=\sigma+tX+O(t^2)\) has \[\left.\frac{\mathrm d}{\mathrm d t}I_{\rho(t)}(A:D\mid B)\right|_{t=0}=0,\] while a fixed-reference modular-energy variation is generically linear in \(t\). Recovery bounds therefore do not by themselves prove a local stress-source theorem; source-specific coarse graining, collar localization, cover independence, and finite-model proof receipts are separate continuation data.

Fixed-Cutoff Realization, Quotient Repair, and Edge Centers

This appendix carries the fixed-cutoff realization and edge-center items for the consensus paper. They sharpen the quotient-first repair interpretation used throughout the consensus paper and make the collar boundary data explicit at the same finite patch-net level. On the declared fixed-cutoff collar branch, the local repair step is read from exact Markov splice or a declared Petz/Fawzi–Renner recovery move on that same collar data; the recovery move gives a recovered comparison state, while exact splice requires exact Markovity or a controlled fixed-collar replacement modulus. Representative repair maps are only lifts of the resulting quotient-local update.

Quotient Repair and UV Underdetermination

At fixed cutoff, each regulator cell \(x\) carries a finite-dimensional factor \(\mathfrak h_x\), patch algebras are finite type-I algebras, and gauge-as-gluing is realized as a compact boundary redundancy action on cut data. The physical repair law therefore belongs on the overlap-invariant quotient rather than on hidden representatives. If \(q:\Sigma\to\Sigma/\Gamma\) is the quotient by boundary redundancy and \(\overline T_i\) is the physical quotient update, a representative-level map \(T_i\) is only required to be a lift satisfying \[q\circ T_i=\overline T_i\circ q.\] Hence \[q(T_i(\gamma\cdot s))=q(T_i(s))\] for gauge-equivalent inputs. Quotient descent is therefore structural, while strict representative-level covariance is only implementation bookkeeping. The burden is to prove that the accepted recovery-derived local moves satisfy the stated repair-completeness, support-local disjoint-commutation, nested-collar restriction-compatibility, and Petz-domain control clauses on the declared branch. The touched-overlap acceptance contract yields finite Lyapunov descent and derived termination for accepted moves, while the fixed-cutoff gluing package carries the parenthesization-invariant union-collar state used for the local diamond.

Proposition 99 (Ancilla-stable UV underdetermination). Let a fixed-cutoff OPH realization be stabilized by finite ancillary factors \(K_P\) in a fixed product state, with observable patch algebras embedded as \(\mathcal A(P)\otimes \mathbf 1_{K_P}\) and repair dynamics acting trivially on the ancillas. Then observable expectations on the physical subalgebras, overlap data, the local-Gibbs branch, the collar conditional mutual information \(I(A:D\mid B)\), the Fawzi–Renner remainder, the collar Markov modulus, and the quotient normal form are unchanged. Thus the fixed-cutoff theorem package determines the UV branch only modulo such ancillary stabilization together with gauge or implementation hiding, not a unique microscopic presentation.

Proof. Product ancillas leave physical observables unchanged, cancel additively inside conditional mutual information, and are inert under the repair maps. Hence every invariant listed above is unchanged. ◻

Derived Boundary Data and Ordinary EC

Proposition 100 (Derived boundary gluing datum). Choose a finite regulator chart for the patches meeting along a connected cut \(\Sigma\). Because the local overlap algebras are finite-dimensional matrix algebras, any overlap-consistent recharting is an inner automorphism and is implemented by a unitary on the cut Hilbert space. The compact closure of the subgroup generated by these recharting unitaries is a compact boundary redundancy group \(K_\Sigma\). If triple-overlap defects are central, the projective composition law lifts to a compact central extension \(\widehat K_\Sigma\); on the ordinary branch one simply sets \(\widehat K_\Sigma = K_\Sigma\). A genuinely noncentral \(2\)-group defect is the only obstruction to reducing the overlap transition system to an ordinary compact group action.

Theorem 101 (Derived EC decomposition). Under the fixed-cutoff regulator realization above, and on the ordinary or central-defect branch, the collar Hilbert space is \[\mathcal H_{B_\delta} = (\tilde{\mathcal H}_{B_L}\otimes \tilde{\mathcal H}_{B_R})^{\widehat K_\Sigma} \cong \bigoplus_{\alpha} \left(\mathcal H_{b_L^\alpha}\otimes \mathcal H_{b_R^\alpha}\right),\] and the center of the collar algebra is generated by the block projectors: \[Z(\mathcal A(B_\delta)) = \bigoplus_\alpha \mathbb C\cdot \mathbf 1_\alpha.\] The right half-collar carries the contragredient representation because it sees inverse transport across the same cut.

Remark 102. This is the finite-patch-net origin of the collar center used by the later Markov, record, and observer packages. Exact Markovity is an additional state hypothesis; EC provides the kinematic block structure.

Higher-Gauge Replacement on the Genuinely Noncentral Branch

Proposition 103 (Derived higher-gauge cut datum). On the genuinely noncentral branch, weak overlap gluing on a connected cut \(\Sigma\) is encoded by a compact crossed module \[\mathbb K_\Sigma=(H_\Sigma\xrightarrow{\partial_\Sigma}G_\Sigma,\triangleright)\] with defect class \[q_\Sigma\in \check H^2(N_\Sigma,H_\Sigma\to G_\Sigma),\] and compact higher-gauge change system \[\mathcal T_\Sigma=C^1(N_\Sigma,H_\Sigma)\rtimes C^0(N_\Sigma,G_\Sigma).\]

Theorem 104 (Higher-gauge EC decomposition and defect transport). On the genuinely noncentral branch, \[\mathcal H_{B_\delta}^{2g} = (\tilde{\mathcal H}_{B_L}\otimes \tilde{\mathcal H}_{B_R})^{\mathcal T_\Sigma} \cong \bigoplus_\lambda (\mathcal H_{b_L^\lambda}\otimes \mathcal H_{b_R^\lambda}),\] and \[Z(\mathcal A_{2g}(B_\delta)) = \bigoplus_\lambda \mathbb C\cdot \mathbf 1_\lambda.\] The full crossed-module orbit \(q_\Sigma\) is also invariant under local rechartings and classifies fixed-cutoff genuinely noncentral gluing data. The higher associator is removable iff \(q_\Sigma\) lies in the image of \[\check H^1(N_\Sigma,G_\Sigma)\longrightarrow \check H^2(N_\Sigma,H_\Sigma\to G_\Sigma), \qquad [g]\longmapsto[(g,1)].\] That map need not be injective. Strict endpoint-only ordinary transport additionally requires at least one allowed strict representative with trivial represented loop holonomy.

Corollary 105 (Exact Markov plus split alignment adds the state factorization). On either the ordinary/central branch described in the main consensus theorem or the genuinely noncentral higher-gauge branch, if in addition \[I_\omega(A_\delta:D_\delta\mid B_\delta)=0\] and the state satisfies the Markov-split alignment hypothesis (its HJPW decomposition of \(\mathcal H_{B_\delta}\) can be chosen to be the EC decomposition itself; see the main-text Section 2.3 and the spacetime and Einstein paper’s alignment definition), or one passes to the explicitly stated idealized recoverability limit that supplies both conditions, then \[\rho_{A_\delta B_\delta D_\delta} = \bigoplus_\alpha p_\alpha \left(\rho_{A_\delta b_L^\alpha}\otimes \rho_{b_R^\alpha D_\delta}\right).\] EC therefore gives the kinematic block decomposition, while exact Markovity plus split alignment is the extra state input that gives the EC-aligned HJPW normal form. Exact Markovity alone yields the normal form only over a state-dependent HJPW split, which a Bell-pair example (main text, Section 2.3) shows can be transposed relative to the EC factors.

Proposition 106 (Certified parenthesization-invariant union-collar gluing). Fix a finite union collar \(U\) built from two overlapping local repair collars on the declared fixed-cutoff branch. Assume one of the following payload receipts:

  1. an exact aligned Markov construction, including the HJPW split-alignment condition, whose nested collar recovery maps satisfy the commuting-square and pentagon identities;

  2. a specified canonical recovery construction, such as a fixed Petz/Markov splice, together with those commuting-square and pentagon identities; or

  3. a primitive aggregate state \(\omega_U\) whose restrictions to every constituent and nested collar equal the declared local payloads.

On the ordinary or central-defect branch, assume in addition that changes of representative act through the declared boundary-redundancy action. On the genuinely noncentral branch, assume the corresponding coherence identities hold in the crossed-module change system \(\mathcal T_\Sigma\). Then the physical quotient-local glued state on \(U\) is independent of parenthesization. The finite export \(\mathsf{GLUE\text{-}COHERENCE\text{-}1}\) contains the constituent and union collars, recovery maps or primitive aggregate state, all restriction hashes, commuting squares, pentagon checks, quotient action, and refinement-compatibility fields.

Proof. In cases (i) and (ii), the commuting-square identities identify every two-step restriction and the pentagon identity identifies all iterated parenthesizations. In case (iii), every parenthesization is a restriction of the same primitive state \(\omega_U\). The additional quotient clause removes only the declared boundary representative action or its crossed-module analogue, so all parenthesizations define one quotient-local state. ◻

Remark 107 (Marginals and sectors do not determine the aggregate state). Central sector labels and compatible proper marginals do not imply any of the three payload receipts. The uniform even-parity and odd-parity distributions on three bits have identical one- and two-bit marginals and different tripartite states. The states \[|\mathrm{GHZ}_{\pm}\rangle = \frac{|000\rangle\pm|111\rangle}{\sqrt2}\] give the quantum counterpart: all two-party reductions agree while the global states differ. Approximate recoverability therefore carries a coherence defect in addition to its local recovery error.

Corollary 108 (Physical observables are invariant on one quotient-local glued state). Let \(U\) be a finite union collar on the declared fixed-cutoff branch, and let \(\omega_U,\omega'_U\) be two microscopic representatives of the same quotient-local glued state from Proposition 106. Then every physical observable \(X\) on the collar fixed-point / quotient-local algebra has the same expectation in both representatives: \[\operatorname{Tr}(X\omega_U)=\operatorname{Tr}(X\omega'_U).\] In particular the same holds for the central sector projectors and for any observer-accessible record observable generated from them on that same declared surface.

Proof. On the ordinary or central-defect branch, Proposition 106 says the two representatives differ only by the boundary-redundancy action inside one fixed sector block. The fixed-point collar algebra and its central block projectors are invariant under that action, so their expectation values agree. On the genuinely noncentral branch, the same proposition says the two representatives differ only inside one \(\mathcal T_\Sigma\)-orbit, and the quotient-local physical algebra \(\mathcal A_{\mathrm{phys}}(U)\) of Definition 56 is defined precisely on that orbit space. Therefore the induced physical state and all expectations of physical observables agree there as well. ◻

Assumption-Dependent Distributed-Systems and QECC Extensions of the Consensus Formalism

Support labels.
[Established]

Follows from cited prior work or a complete argument given here.

[Assumption-dependent]

True under additional assumptions not derived from OPH first principles.

[Conjecture]

A plausible open direction, not a settled result.

B.1Theorem 1: QBFT Safety Bound

Definition 109 (QBFT-style protocol). A consensus protocol is QBFT-style in this analysis if it satisfies the following five structural properties. Same-view safety uses (P1)–(P2), cross-view safety additionally uses the lock and monotone-view parts of (P1) and (P4), and the liveness clause uses (P3)–(P5) together with the timing and connectivity assumptions below.

  1. One-vote-per-view. Each nonfaulty node supports at most one value per view number. If the protocol has prepare, prepared-certificate acceptance, and commit phases, its messages in all three phases refer to that same value. A node that has supported a value in view \(v\) ignores any later conflicting request in view \(v\). View participation is monotone: after entering view \(w\), a nonfaulty node never signs a prepare, prepared-certificate acceptance, or commit message for \(v<w\), and never adopts a durable lower-view lock.

  2. Certificate semantics. A raw prepared certificate \(\operatorname{PC}(v,x)\) contains \(q\) distinct, unforgeable, authenticated prepare votes for value \(x\) in view \(v\). A lock certificate \(\operatorname{LC}(v,x)\) contains that \(\operatorname{PC}(v,x)\) together with \(q\) distinct authenticated acceptance acknowledgements. These acknowledgements are provisional: they do not change the acceptor’s voting lock. A raw prepared certificate without \(q\) acceptance acknowledgements cannot justify a new view or a commit vote. A nonfaulty validator that receives the assembled \(\operatorname{LC}(v,x)\) verifies it and records the durable lock \((v,x)\) before signing a commit vote. A decision certificate contains \(q\) distinct authenticated commit votes, each referring to the same valid \(\operatorname{LC}(v,x)\). In the classical exact-size case \(q=2f+1\). For larger validator sets at fixed fault budget, the threshold must scale so that (A6) holds. A nonfaulty observer finalises a value only after accepting such a valid decision certificate.

  3. DLS-style view-change. If no certificate is produced within a timeout, every nonfaulty node increments the view number by one and a new leader is selected by a fixed fair deterministic rule. Once the post-GST timeout bound of (A1) is active, the pacemaker brings all nonfaulty nodes through successive views and reaches a nonfaulty leader within at most \(f+1\) consecutive views.

  4. Prepared-certificate dissemination, commit lock, and justified new view. The assembler disseminates a valid \(\operatorname{PC}(v,x)\) and obtains the \(q\) authenticated acceptance acknowledgements of \(\operatorname{LC}(v,x)\), then disseminates the assembled lock certificate before collecting commits. Each validator’s authenticated view-change message carries its highest valid lock certificate, if any. A new leader collects \(q\) such messages. If it issues a proposal, that proposal carries the value of their highest-view lock certificate; it may carry a fresh value only if none is present. The proposal carries the complete new-view justification. Every nonfaulty validator verifies the signatures, quorum size, and highest-certificate selection. An unlocked validator may support a fresh proposal only when the verified justification contains no lock certificate. Otherwise it votes only for its current lock value, except that the value selected by a valid \(q\)-message new-view justification supersedes its local assembled-lock-certificate lock. This authorizes the prepare vote without adopting a lower-view durable lock; receipt of the assembled current-view lock certificate records the replacement before commit. This rule applies without a local test for whether an earlier commit set reached \(q\): it reconciles every predecision lock, while the proof below shows that quorum intersection makes the selected value compatible whenever a decision certificate exists.

  5. Post-GST nonfaulty progress. In a sufficiently long post-GST view led by a nonfaulty node, that leader collects the required new-view messages and emits the proposal selected by (P4). Every nonfaulty validator that receives a valid proposal promptly sends its prepare vote. The nonfaulty leader disseminates the resulting valid prepared certificate; every nonfaulty validator verifies it and returns a provisional acceptance acknowledgement. After assembling the lock certificate, the leader disseminates it; every nonfaulty recipient verifies it, records or advances its durable lock, and sends its commit vote. After accepting a valid decision certificate it finalises and relays that certificate. Each of these fixed protocol phases completes within \(O(\Theta)\), with \(\Theta\) defined in (A1).

The Istanbul BFT / QBFT protocol family [sources] motivates this pattern; (P1)–(P5), including their exact certificate, pacemaker, lock, and progress semantics, must be checked against an implementation rather than inferred from the family name.

Assumptions A1–A6.
  1. Partial synchrony (DLS). Fixed but initially unknown bounds \(\Delta\) (per-edge message delay) and \(\Phi\) (local processing time) hold after GST. Together with the certified routes of (A4), they supply an effective end-to-end protocol-phase bound \(\Theta\) that includes route length, processing, and the fixed number of message steps in one phase. Pacemaker timeouts eventually exceed the corresponding per-view bound. Safety holds without extra timing assumptions; liveness holds after the Global Stabilisation Time (GST).

  2. Byzantine fault model. At most \(f\) observers behave arbitrarily; the remaining \(n-f\) are nonfaulty.

  3. Classical exact sizing for this fixed-quorum theorem. \(n = 3f+1\), so that \(q=2f+1\) certificates have a nonfaulty overlap witness. The usual resilience condition \(n\ge 3f+1\) is necessary for the fault model, but when \(n>3f+1\) a fixed \(q=2f+1\) quorum is insufficient for the overlap used in the safety proof; one must either impose (A6) directly or choose a threshold \(q\) with \(2q\ge n+f+1\).

  4. Strong quorum connectivity. Every quorum \(Q\) with \(|Q|=q\) is strongly connected within \(G\): for any \(u,v\in Q\) there is a directed path in \(G\) contained entirely in \(Q\). This is strictly stronger than requiring the overlap graph of quorums to be connected, and is needed to propagate signed votes within a quorum.

  5. Message authentication. All messages carry unforgeable digital signatures.

  6. OPH quorum overlap. Any two quorums \(Q_a, Q_b\) of size \(q\) satisfy \(|Q_a\cap Q_b|\geq f+1\). For \(q=2f+1\) this is guaranteed by the exact sizing \(n=3f+1\) in (A3); for general \(n\) it is the separate threshold condition \(2q\ge n+f+1\), not a consequence of \(n\ge3f+1\) alone. The liveness clause additionally requires \(q\le n-f\), so a certificate can be formed without Byzantine participation.

D. Matscheko’s review of this appendix covers the finite quorum-overlap core and records the same boundary caveat: at fixed \(q=2f+1\), the overlap step is exact-size \(n=3f+1\) logic unless (A6) is imposed separately.

Theorem 110 (QBFT Safety Bound [Cross-view safety established under the stated certificate, acceptance, overlap, authentication, and lock rules]). Under (A1), (A2), and (A4)–(A6), any consensus protocol satisfying (P1)–(P5) of Definition 109 and run over the OPH observer graph satisfies:

  1. Cross-view safety. No two nonfaulty observers finalise conflicting patch states, whether in the same view or in different views.

  2. Liveness. From the first post-GST view in which the pacemaker timeout bound is active, every nonfaulty observer finalises within \(O((f+1)\Theta)\) wall-clock time, provided \(q\le n-f\). No bound from GST to timeout activation is claimed.

  3. Certificate-contract threshold. Joint feasibility of the safety threshold \(2q\ge n+f+1\) and Byzantine-independent liveness threshold \(q\le n-f\) forces \(n\ge3f+1\); the exact-size choice \(n=3f+1,q=2f+1\) attains both.

Sizing and scope boundary.

Assumption (A3) is the classical exact-size way to discharge (A6), not an additional independent premise: when \(n=3f+1\) and \(q=2f+1\), the required overlap is automatic. For general \(n\), (A6) must instead be checked directly. The prepared-lock rule proves safety only for the protocol just defined; it is not inferred from the word “QBFT.” On those stated assumptions the theorem gives record permanence: no two nonfaulty observers finalise conflicting patch states. Record permanence enters as a consistency requirement on the observer net, not as an added postulate.

Proof. Same-view safety. Suppose \(O_a\) and \(O_b\) finalise \(s_a\neq s_b\) in one view. By (P2), each required a certificate of \(q\) votes: sets \(Q_a,Q_b\). By (A6), \(|Q_a\cap Q_b|\geq f+1\). In the classical exact-size case this is the inclusion-exclusion calculation \(|Q_a\cap Q_b|\geq(2f+1)+(2f+1)-(3f+1)=f+1\). By (A2), at most \(f\) are Byzantine, so \(Q_a\cap Q_b\) contains a nonfaulty \(O^*\). By (P1), \(O^*\) voted for at most one value. Contradiction. The identical overlap argument applies to two prepared certificates in the same view, using their prepare-vote quorums.

Cross-view safety. Suppose \(\operatorname{DC}(v,x)\) and \(\operatorname{DC}(w,y)\) are conflicting decision certificates with \(v<w\). The first certificate refers to a valid \(\operatorname{LC}(v,x)\). Let \(C_x\) be its \(q\) committers. The nonfaulty subset \(L_x\subseteq C_x\) has size at least \(q-f\), and every member of \(L_x\) received the assembled lock certificate and recorded \((v,x)\) before committing. Every size-\(q\) prepare or view-change quorum \(P\) intersects that actual lock set because \[|L_x\cap P| \ge (q-f)+q-n =2q-n-f \ge1\] by (A6).

Assume for contradiction that a raw prepared certificate for a value different from \(x\) exists above view \(v\), and choose one with least view \(r>v\). Its proposal carries a valid \(q\)-message new-view justification \(J_r\). Since \(|L_x|\ge q-f\) and \(|J_r|=q\), choose a nonfaulty \(O^*\in L_x\cap J_r\). Validator \(O^*\) signed a commit for \(\operatorname{LC}(v,x)\), and later sent its authenticated view-\(r\) change. Monotone view participation in (P1) orders its view-\(v\) lock and commit before that view-\(r\) message: it cannot send a view-\(r\) change and subsequently return to commit in view \(v\). Its view-change message therefore reports \(\operatorname{LC}(v,x)\), or a later valid lock certificate. By minimality of \(r\), every raw prepared certificate underlying such a later reported lock certificate below view \(r\) carries \(x\). Hence \(O^*\)’s report carries \(x\).

The justification \(J_r\) therefore cannot be certificate-free. It also cannot contain a conflicting highest lock certificate, because that certificate contains a conflicting raw prepared certificate in a view below \(r\), contradicting the minimality of \(r\). Rule (P4) consequently selects \(x\), so nonfaulty validators do not prepare the alleged conflicting value in view \(r\). Thus no higher conflicting prepared certificate exists, and (P2) excludes the alleged \(\operatorname{DC}(w,y)\).

This induction is also the lock-transfer invariant for view change. Every valid \(q\)-message new-view justification after a decision contains a nonfaulty report from the decision’s \(q-f\) commit-lock set, and its highest valid report carries the decided value.

Liveness and certificate threshold. From the first post-GST view whose pacemaker timeout is active, (A1) makes every failed-view timeout and every fixed protocol phase \(O(\Theta)\). Rule (P3) reaches a nonfaulty leader within at most \(f+1\) consecutive views. Since \(q\le n-f\), nonfaulty validators can supply all \(q\) new-view, prepare, prepared-certificate acceptance, and commit messages without Byzantine participation.

Consider the valid \(q\)-message justification used by the successful new view. If it contains no lock certificate, (P4) selects a fresh value. Otherwise it selects its unique highest-view lock certificate; same-view uniqueness follows from the prepare-quorum overlap. Every nonfaulty validator may replace a local assembled-lock-certificate predecision lock with that valid selection, including a lock whose local commit set never reached a decision certificate. If a decision certificate exists, the \(q-f\) nonfaulty commit-lock set proved above intersects the \(q\)-message justification. Its report forces the selected lock certificate to carry the decided value, since the safety induction excludes a conflicting certificate. Thus at least \(q\) nonfaulty validators can support the selected proposal in either case, even when some of their orphan locks were omitted from the new-view messages.

Rule (P5) executes the proposal, prepare, provisional acceptance, lock-certificate dissemination, commit, and decision-relay phases, so every nonfaulty observer finalises within \(O((f+1)\Theta)\) from that activation point. Eventual timeout activation yields eventual liveness, but the theorem does not bound its delay after GST.

Finally, \(q\le n-f\) and \(2q\ge n+f+1\) imply \[2(n-f)\ge n+f+1,\] hence \(n\ge3f+1\) (with the integer convention specified in (A6)). At \(n=3f+1\), \(q=2f+1\) attains both inequalities. This is a threshold statement for the declared certificate contract, not a universal resilience claim for every authenticated protocol model.

Note on FLP. Fischer, Lynch, Paterson [source] is an impossibility result for fully asynchronous systems; it does not bear on achievability under partial synchrony (A1). ◻

Executable receipt and negative controls.

The finite executable check exhausts all certificate and new-view quorum pairs for \((n,f,q)=(1,0,1),(4,1,3),(6,1,4),(7,2,5)\). The first, second, and fourth are exact-size points; the third checks the general threshold with \(q<n-f\). It checks both the nonfaulty certificate-overlap witness, independent prepare-signer, provisional-acceptor, and committer quorums, the \(q-f\) lower bound on actual nonfaulty commit locks in a decision certificate, and transfer of at least one such lock into every new-view quorum. It also executes the next-view lock transition against every candidate prepare quorum at those parameter points, derives local validator states from lock-certificate delivery and partial commits, constructs the new-view reports, selects the proposal, computes the eligible voters, and determines recovery or deadlock. These traces include an omitted higher orphan lock at the general-threshold point. The receipt also runs finite post-GST proposal/prepare/acceptance/commit/relay traces for every nonfaulty reference leader. The arbitrary-view induction and wall-clock proof remain the mathematical argument above; the receipt is not a general protocol-model checker.

Separate finite traces remove one-vote, monotone-view participation, finalise-only-on-valid-certificate semantics, quorum overlap, the fault bound, authentication, prepared locking, quorum-certified prepared-certificate acceptance and dissemination, provisional pre-certificate acknowledgements, new-view supersession of local partial-commit locks, highest-certificate leader selection, partial synchrony, quorum availability, quorum connectivity, terminating view change, nonfaulty-leader proposal progress, and nonfaulty-validator prepare/commit/relay progress. Validator justification checking has a separate malformed-proof conformance witness; with the retained lock rule it is defence in depth rather than an independent safety premise. The lock-free \(n=4,f=1,q=3\) trace decides \(x\) from \(\{B,N_1,N_2\}\) in view zero and \(y\ne x\) from \(\{B,N_2,N_3\}\) in view one while respecting one-value-per-validator in each individual view.

B.2Theorem 2: Convergence of the OPH Repair Map

Definition 111 (OPH Repair Map: Petz form). Let \(\sigma\in\mathcal{D}(\mathcal{H})\) be a full-rank reference state and \(\mathcal{N}:\mathcal{B}(\mathcal{H})\to\mathcal{B}(\mathcal{K})\) a quantum channel. The OPH repair map is \[\mathcal{R}_{\sigma,\mathcal{N}}(\rho) := \sigma^{1/2}\, \mathcal{N}^\dagger\!\bigl( \mathcal{N}(\sigma)^{-1/2}\,\rho\,\mathcal{N}(\sigma)^{-1/2} \bigr) \,\sigma^{1/2},\] where \(\mathcal{N}^\dagger\) is the adjoint channel and inverses are taken on \(\mathrm{supp}(\mathcal{N}(\sigma))\).

Remark 112 (Petz map vs. trace-distance projection). The closest-point trace-distance projection \(\mathcal{P}_{\mathcal{S}}(\rho):=\arg\min_{\tau\in\mathcal{S}}\tfrac12\|\rho-\tau\|_1\) is a different object from the Petz map: it is defined by a variational problem in trace-norm geometry and is not CPTP in general. The two coincide only in very special cases not automatic in the OPH setting. All subsequent properties refer exclusively to Definition 111.

Proposition 113 (Petz map CPTP: domain-restricted statement [Established, subject to domain restriction]). Let \(\sigma\) have full support on \(\mathcal{H}\).

  1. \(\mathcal{R}_{\sigma,\mathcal{N}}\) is completely positive.

  2. \(\mathcal{R}_{\sigma,\mathcal{N}}\) is trace-preserving on \(\mathrm{supp}(\mathcal{N}(\sigma))\), i.e., on inputs \(\rho\) for which \(\mathcal{N}(\sigma)^{-1/2}\rho\,\mathcal{N}(\sigma)^{-1/2}\) is well-defined.

  3. If additionally \(\mathcal{N}(\sigma)\) has full rank on \(\mathcal{K}\), then \(\mathcal{R}_{\sigma,\mathcal{N}}\) is CPTP on all of \(\mathcal{B}(\mathcal{K})\).

If \(\mathcal{N}(\sigma)\) is not full rank on \(\mathcal{K}\), then either (i) the domain must be restricted to \(\mathrm{supp}(\mathcal{N}(\sigma))\), or (ii) pseudoinverses must replace the inverses (generalised Petz map; cf. [source]), or (iii) a regularisation \(\mathcal{N}(\sigma)\mapsto\mathcal{N}(\sigma)+\varepsilon\mathbf{1}\) must be introduced. Note that full-rank \(\sigma\) does not prevent \(\mathcal{N}(\sigma)\) from being rank-deficient: the channel may map the support of \(\sigma\) into a strict subspace of \(\mathcal{K}\). In the OPH setting, whether \(\mathcal{N}(\sigma)\) is full rank depends on the specific overlap channel and must be verified for the chosen analytic channel model. The finite OPH repair theorem instead uses the declared Lyapunov descent law on a finite patch net.

Proof. Complete positivity follows from composing three CP operations:

  1. sandwiching by \(\mathcal{N}(\sigma)^{-1/2}(\cdot)\mathcal{N}(\sigma)^{-1/2}\) on \(\mathrm{supp}(\mathcal{N}(\sigma))\);

  2. \(\mathcal{N}^\dagger\);

  3. sandwiching by \(\sigma^{1/2}(\cdot)\sigma^{1/2}\).

Trace preservation in the full-rank case: Petz [source]; Fagnola–Umanità [source]. ◻

Proposition 114 (Analytic contraction certificate [Assumption-dependent]). Suppose a declared quotient repair map \(T:Q\to Q\) on a metric physical quotient \((Q,d_Q)\) is strictly contractive with coefficient \(\lambda\in(0,1)\): \[d_Q(Tx,Ty)\le \lambda d_Q(x,y).\] Then \(T\) has at most one fixed point. If a fixed point \(x_\star\) exists, the ideal iterates obey \(d_Q(T^t x,x_\star)\le \lambda^t d_Q(x,x_\star)\). This is an analytic contraction condition. It is not required for the finite OPH normal-form theorem, where termination follows from strict Lyapunov descent of accepted repairs.

Theorem 115 (Noisy approximate repair stability [Contraction branch]). Assume the contraction certificate of Proposition 114, and let \(\widetilde T:Q\to Q\) be an implemented noisy repair map satisfying \[d_Q(\widetilde T x,Tx)\le \varepsilon \qquad\text{for all }x\in Q.\] If \(x_\star\) is the ideal fixed point of \(T\), then \[d_Q(\widetilde T^t x,x_\star) \le \lambda^t d_Q(x,x_\star)+\frac{\varepsilon}{1-\lambda}.\] Thus the noisy branch converges only to a controlled error ball, and only after the contraction certificate and uniform implementation-error bound are supplied.

Proof. The recursion \[d_Q(\widetilde T x,x_\star) \le d_Q(\widetilde T x,Tx)+d_Q(Tx,Tx_\star) \le \varepsilon+\lambda d_Q(x,x_\star)\] iterates to the displayed geometric-series bound. ◻

Proposition 116 (Spectral-gap criterion [Model-dependent]). Let \(\mathcal T\) be the Markov, channel, or transfer operator induced by iterated OPH repair on a declared analytic realization. If \(\mathcal T\) has stationary projection \(\Pi_\star\) and constants \(C<\infty\), \(\delta>0\) such that on the nonstationary subspace \[\|\mathcal T^t-\Pi_\star\|\le C e^{-\delta t},\] then the corresponding analytic channel model has exponential convergence. The finite OPH repair package supplies termination by Lyapunov descent on its declared finite state space; a spectral gap is a separate quantitative mixing condition for this BFT/QECC-style extension.

Theorem 117 (Exponential Convergence [Under Proposition 116]). Under Proposition 116, for any initial analytic state \(\rho\), \[\bigl\|\mathcal T^t\rho-\Pi_\star\rho\bigr\| \leq C\,e^{-\delta t}\bigl\|\rho-\Pi_\star\rho\bigr\|.\] This theorem belongs only to the spectral-gap branch. It is not a consequence of a bare finite overlap graph or of finite Lyapunov descent alone.

B.3Theorem 3: QECC Correspondence

Notation.

\(N=\dim(\mathcal{H})=2^n\) for \(n\) physical qubits. Standard notation: \([[n,k,d]]\) stabilizer code; \(K=2^k\); quantum Singleton bound: \(k\leq n-2(d-1)\).

Theorem 118 (No free min-cut theorem for bare overlap graphs [Established]). Let \(G=(V,E)\) be any connected graph with \(|V|\ge2\). The graph \(G\) alone does not determine the Hamming distance of the consistency set \(C\) of a finite overlap net on \(G\). In particular, the same graph can realize a binary constraint code of distance \(1\) or a binary repetition code of distance \(|V|\).

Proof. Set \(S_i=\{0,1\}\) for every vertex. For the repetition realization, choose \(I_e=\{0,1\}\) and let both endpoint readouts be the identity. Then every edge imposes \(x_i=x_j\), so the only global codewords are \(00\cdots0\) and \(11\cdots1\), whose Hamming distance is \(|V|\).

For the trivial-overlap realization, keep the same vertex state spaces but let every endpoint readout be the constant map to \(0\). Then every binary assignment is globally consistent, so the minimum Hamming distance among distinct codewords is \(1\). The graph is unchanged. Therefore distance is a property of the code realization (state spaces, readout maps, logical dictionary, metric, and error model), not of the bare overlap graph. ◻

Definition 119 (Topological-code realization certificate). An OPH overlap network may be treated as a QECC/topological code only after supplying a tuple \[\mathsf{TCert}= (K,\mathcal H_{\mathrm{phys}},\mathcal H_{\mathrm{code}}, \partial_2,\partial_1,S_X,S_Z,\mathcal L_X,\mathcal L_Z,\mathcal E,\mathcal R),\] where \(C_2\xrightarrow{\partial_2}C_1\xrightarrow{\partial_1}C_0\) is a chain complex over \(\mathbb F_2\), the physical carriers live in \(\mathcal H_{\mathrm{phys}}\), the protected subspace is \(\mathcal H_{\mathrm{code}}\), \(S_X,S_Z\) are stabilizer or gauge checks, \(\mathcal L_X,\mathcal L_Z\) are logical-operator classes, \(\mathcal E\) is a declared error family, and \(\mathcal R\) is a recovery map or recovery family.

Theorem 120 (Certified topological-code distance and min-cut [Assumption-dependent]). Suppose a certificate \(\mathsf{TCert}\) of Definition 119 is supplied, with logical classes identified as \[\mathcal L_X\simeq H_1(K;\mathbb F_2), \qquad \mathcal L_Z\simeq H^1(K;\mathbb F_2),\] and with boundary conditions excluding lower-weight trivial representatives. Then the certified distance is \[d= \min\left\{ \min_{\ell\in\mathcal L_X\setminus0}|\ell|, \min_{\ell^\star\in\mathcal L_Z\setminus0}|\ell^\star| \right\}.\] Only in geometries where this homological systole equals the relevant graph min-cut may one write \(d=\mathrm{mincut}(G_{\mathrm{OPH}})\) [sources].

Proof. This is the standard stabilizer/topological-code distance statement once the chain complex, checks, logical representatives, and boundary conditions are declared. The min-cut equality is an additional geometric identification of that homological minimum with a graph cut. By Theorem 118, it cannot be inferred from the bare graph. ◻

Conjecture 121 (Communication complexity [Conjecture]). The OPH consensus-repair protocol, realised as a quantum communication task, has per-round complexity \(O(n\cdot\mathrm{poly}(d))\) for a chosen communication encoding (cf. [source]). The fixed finite repair theorem gives termination after a supplied descent law; it does not by itself fix a quantum communication complexity class for every implementation.

Theorem 122 (QECC resilience under a supplied code certificate [Assumption-dependent]). Assume a genuine code subspace \(\mathcal H_{\mathrm{code}}\subseteq\mathcal H_{\mathrm{phys}}\) with projector \(\Pi\), and let \(\mathcal E_t\) be the declared set of errors supported on fewer than \(t\) corrupted patches or physical carriers. If \[\Pi E_a^\dagger E_b \Pi=\alpha_{ab}\Pi \qquad \forall E_a,E_b\in\mathcal E_t,\] then there exists a recovery channel correcting all errors in \(\mathcal E_t\) [source]. If the supplied certificate also gives distance \(d\), then all errors of weight \(t<d/2\) are correctable. No such resilience statement follows from the bare overlap graph.

Corollary 123 (QECC extension inventory). Under Definition 119, Theorem 120, and Theorem 122, the OPH BFT/QECC extension carries the following claim split:

  1. [Assumption-dependent] Code distance is the certified homological minimum; it equals \(\mathrm{mincut}(G_{\mathrm{OPH}})\) only under the additional systole/min-cut identification.

  2. [Established] The Knill–Laflamme QECC theorem supplies recovery once the projector and error family satisfy the displayed condition.

  3. [Conjecture] Per-round communication complexity is \(O(n\cdot\mathrm{poly}(d))\).

B.4Theorem 4: Asynchronous Convergence

Why fairness alone does not give a probability-1, spectral, or wall-clock statement.

Standard strong fairness guarantees that every enabled action fires infinitely often along any fair schedule; it does not impose a probability space on schedules, a transfer-operator spectral gap, or a message-delay bound. A convergence statement of the form “converges with probability 1” requires a measure on schedules. Exponential convergence requires the spectral-gap certificate of Theorem 117. Bounded wall-clock liveness requires partial synchrony and quorum assumptions. The FLP impossibility result [source] confirms that fairness is insufficient for bounded-time consensus in a fully asynchronous system.

A commonly used shorthand is insufficient.
  1. Finite known bound \(\Delta\) on message delay after GST.

  2. Finite bound \(\Phi\) on processing rates.

  3. \(f < n/3\).

These three facts alone do not define a protocol that proposes, votes, forms certificates, changes views, or relays a decision. Consequently they do not imply a wall-clock consensus bound.

Theorem 124 (Eventual finite repair termination [Finite-descent branch]). For a finite OPH patch net with a strict Lyapunov-decreasing accepted repair relation, every maximal repair run terminates after finitely many accepted repairs. The step count is bounded by the finite value-set bound of Proposition 25. If the local-diamond and repair-completeness clauses also hold, Newman’s lemma upgrades this termination statement to the unique schedule-independent quotient normal form of Theorem 31.

This theorem is finite descent convergence in repair steps. It is not trace-norm convergence of a Petz channel, not probability-one convergence over random schedules, not exponential convergence, and not a wall-clock liveness theorem.

Theorem 125 (Quantitative BFT liveness [Restatement under the complete B.1 contract]). Under (A1), (A2), (A4)–(A6), \(q\le n-f\), and protocol rules (P1)–(P5) of Definition 109, every nonfaulty observer finalises within \(O((f+1)\Theta)\) wall-clock time measured from the first post-GST view whose pacemaker timeout bound is active. This is exactly the liveness clause proved in Theorem 110; it does not follow from (B1)–(B3).

B.5Extension Boundaries

  • A bare OPH overlap graph is a finite constraint-code presentation only. Its graph does not determine code distance, correctable error weight, or min-cut resilience.

  • Analytic spectral-gap and full-rank estimates for a chosen stochastic or channel-level BFT/QECC realization are model-specific refinements. They are separate from the finite OPH repair theorem, where the accepted repair law supplies Lyapunov descent directly.

  • Long-run noisy approximate consensus is available only on the fair-block contraction branch of Theorem 90: the chosen implementation must certify fair blocks, expected contraction toward the exact quotient normal-form set, and controlled within-block excursions. Fairness alone does not supply that certificate.

  • Topological-code distance equals graph min-cut only after a concrete chain complex, boundary condition, logical-operator dictionary, error family, and systole/min-cut identification are supplied for the chosen code realization.

  • Communication-complexity bounds require a concrete quantum communication encoding and implementation cost model. They are not consequences of finite normal-form termination alone.

  • The core OPH consensus paper supplies observable-level confluence and refinement-limit normal-form/holonomy classes under their declared premises; the BFT/QECC statements above are separate protocol-style extensions.

99

L. Bombelli, J. Lee, D. Meyer, and R. D. Sorkin, Space-time as a causal set, Phys. Rev. Lett. 59, 521 (1987). https://doi.org/10.1103/PhysRevLett.59.521

S. Surya, The causal set approach to quantum gravity, Living Rev. Relativ. 22, 5 (2019). https://doi.org/10.1007/s41114-019-0023-1

L. Bombelli and D. A. Meyer, The origin of Lorentzian geometry, Phys. Lett. A 141, 226–228 (1989). https://doi.org/10.1016/0375-9601(89)90474-X

G. Brightwell and R. Gregory, Structure of random discrete spacetime, Phys. Rev. Lett. 66, 260–263 (1991). https://doi.org/10.1103/PhysRevLett.66.260

S. Major, D. Rideout, and S. Surya, On recovering continuum topology from a causal set, J. Math. Phys. 48, 032501 (2007). https://doi.org/10.1063/1.2435599

L. Glaser and S. Surya, Towards a definition of locality in a manifoldlike causal set, Phys. Rev. D 88, 124026 (2013). https://doi.org/10.1103/PhysRevD.88.124026

D. D. Reid, Manifold dimension of a causal set: Tests in conformally flat spacetimes, Phys. Rev. D 67, 024034 (2003). https://doi.org/10.1103/PhysRevD.67.024034

L. Bombelli, J. Henson, and R. D. Sorkin, Discreteness without symmetry breaking: A theorem, Mod. Phys. Lett. A 24, 2579–2587 (2009). https://doi.org/10.1142/S0217732309031958

S. W. Hawking, A. R. King, and P. J. McCarthy, A new topology for curved space–time which incorporates the causal, differential, and conformal structures, J. Math. Phys. 17, 174–181 (1976). https://doi.org/10.1063/1.522874

D. B. Malament, The class of continuous timelike curves determines the topology of spacetime, J. Math. Phys. 18, 1399 (1977). https://doi.org/10.1063/1.523436

L. Lamport, Time, clocks, and the ordering of events in a distributed system, Commun. ACM 21, 558 (1978).

B. Müller, J. Kim, D. Matscheko, and J. Hill, Observation-Determined Normal Forms: Stability, Obstructions, and Refinement in Constraint and Rewrite Systems, 2026.
Available at https://github.com/FloatingPragma/observer-patch-holography/blob/main/extra/observable_normal_forms.pdf.

B. Müller, Verified Projection-Event Calculus in Lean 4: Bundled Arbitrary-Partition Pinching, Lüders Retractions, and CHSH Interoperability, 2026.
Available at https://github.com/FloatingPragma/observer-patch-holography/blob/main/extra/machine_checked_finite_event_algebras.pdf.

Pragma Research, Observer-Patch Holography: machine-checked proofs and executable certificates, 2026.
Available at https://github.com/FloatingPragma/observer-patch-holography.

B. Müller, OPH-FPE: finite simulator and receipt engine for Observer-Patch Holography physics experiments, 2026.
Source available at https://github.com/muellerberndt/oph-physics-sim. Finite provenance and operator producers, independent verifiers, and receipts: https://github.com/muellerberndt/oph-physics-sim/tree/6080f3a4045b7cbd821476a0a8fa0a6b57eeeeab.

B. Müller, A. Osika, M. Poneder, K. Xue, B. Cassie, P. Nguyen, J. Kim, D. Matscheko, J. Hill, W. T. Glynn, M. A. Visser, K. A. Anirudha, and B. de La Fournière, From Observer Consensus to Standard Physics, 2026.
Available at https://wkaxfdgxoqmghwgshymt.supabase.co/storage/v1/object/public/papers/from_observer_consensus_to_standard_physics.pdf.

M. H. A. Newman, “On theories with a combinatorial definition of ‘equivalence’,” Ann. of Math. 43 (1942), no. 2, 223–243.

M. J. Fischer, N. A. Lynch, and M. S. Paterson, “Impossibility of distributed consensus with one faulty process,” J. ACM 32 (1985), no. 2, 374–382.

L. Lamport, R. Shostak, and M. Pease, “The Byzantine generals problem,” ACM Trans. Program. Lang. Syst. 4 (1982), no. 3, 382–401.

C. Dwork, N. A. Lynch, and L. Stockmeyer, “Consensus in the presence of partial synchrony,” J. ACM 35 (1988), no. 2, 288–323.

H. Moniz, The Istanbul BFT Consensus Algorithm, arXiv:2002.03613, 2020.

R. Saltini et al., QBFT Formal Specification and Verification. Available at https://github.com/Consensys/qbft-formal-spec-and-verification.

D. Petz, “Sufficient subalgebras and the relative entropy of states of a von Neumann algebra,” Commun. Math. Phys. 105 (1986), no. 1, 123–131.

F. Fagnola and V. Umanità, “Generators of detailed balance quantum Markov semigroups,” Infinite Dimensional Analysis, Quantum Probability and Related Topics 13 (2010), no. 3, 459–486.

M. Junge et al., “Universal recovery maps and approximate sufficiency of quantum relative entropies,” Ann. Henri Poincaré 19 (2018), no. 8, 2505–2555.

E. Knill and R. Laflamme, “Theory of quantum error-correcting codes,” Phys. Rev. A 55 (1997), no. 2, 900–911.

A. Kitaev, “Fault-tolerant quantum computation by anyons,” Ann. Phys. 303 (2003), no. 1, 2–30.

E. Dennis, A. Kitaev, A. Landahl, and J. Preskill, “Topological quantum memory,” J. Math. Phys. 43 (2002), no. 9, 4452–4505.

H. Buhrman, R. Cleve, and A. Wigderson, “Quantum vs. classical communication and computation,” in Proceedings of STOC 1998, pp. 63–68.

O. Fawzi and R. Renner, “Quantum conditional mutual information and approximate Markov chains,” Commun. Math. Phys. 340 (2015), 575–611, arXiv:1410.0664.

B. Müller et al., Recovering Observer Spacetime and Einstein Dynamics from Overlap Consistency. https://github.com/FloatingPragma/observer-patch-holography/blob/main/paper/recovering_observer_spacetime_and_einstein_dynamics_from_overlap_consistency.tex.

AI Assistance Disclosure

This research project used research-grade commercial models, including Anthropic’s Fable and OpenAI’s GPT-5.6-Sol, for research support, software development, editing, and synthesis. The authors are responsible for the paper’s claims, methods, and final text.