DIVERGE-NPL1: Stage-Typed Natural Verified Plasticity
Status: not admitted and closed before training/evaluation. STI1 failed its unchanged confirmation gate, so no NPL1 confirmation data were generated and no natural plastic write was executed. The prepared development-only corpus and semantic-admission code remain provenance artifacts, not results.
1. Capability hypothesis
Oracle-typed PL1 proved that branch-local, verifier-gated policy writes can recover an episode-local rule system and improve later context-free transfer. It did not prove that a learned language interface can deliver the required credit without corrupting it. NPL1 tests one narrower end-to-end claim:
A qualified stage-typed semantic interface can convert natural verifier and query transactions into branch-local plastic credit, producing persistent improvement on deeper held-out programs after all natural text is deleted, while every semantic and execution owner remains bit-identical.
The only mutable state is the existing 8 x 8 PL1 policy matrix. NPL1 adds no backbone, adapter, durable consolidation, or continuation pretraining.
2. Admission and protected owners
NPL1 may activate only after a hash-bound STI1 confirmation PASS. It then loads, without modification:
- STI1 WORLD owner;
- STI1 EVIDENCE owner;
- STI1 QUERY owner;
- the exact PL1 executor, verifier, and branch-local update rule; and
- the frozen oracle-typed PL1 result as a mechanics ceiling.
WORLD, EVIDENCE, QUERY, EXECUTE, and VERIFY are protected. Before every
session write and after every transfer, their state hashes must be identical
to the pre-session manifest. Only POLICY_PLASTIC may change.
3. Natural mini-language board
The reasoning family remains the eight-operation noncommuting mini-language used by PL1, but all episode aliases, mappings, programs, branch names, register names, renderers, and seeds are new and disjoint from PL1.
Natural WORLD records specify an initial register pair and an ordered program of opaque episode-local aliases. A deterministic structural lexer may propose integer spans and exact occurrences of aliases already declared in the sealed episode symbol table. It may not map an alias to an operation, score a branch, inspect a terminal state, or access an answer. Alias semantics remain entirely in the branch/version-space policy.
Each of twelve acquisition attempts creates eight coherent complete branch
mappings and executes every branch. The source-owned verifier returns only a
cryptographically bound PASS or first-error position. That certificate is
rendered through all three already-qualified EVIDENCE layouts. The natural
transaction carries the credited branch, a decoy branch, attempt ordinal, and
certificate code (0 for PASS, otherwise first-error position plus one).
The sealed verifier checks every parsed field before credit can write.
Six already-qualified QUERY layouts request one of two named terminal registers while naming the other as a decoy. Transfer programs have depths 12--20 and compositions absent from acquisition. Before transfer, all WORLD, feedback, query-demonstration, branch-transcript, verifier-message, source residual, and textual context bytes are deleted. The runtime retains only the protected owners, sealed typed program packets, and bounded plastic policy state.
This lexical proposal boundary is engineered and must be reported. A pass is not an open-domain source-compilation claim.
4. Matched arms
Every arm receives identical natural transactions, branches, verifier calls, mutable-scalar allowance, forward/update FLOPs, and transfer programs:
STATIC: frozen policy with matched no-op update compute;CONTEXT_ONLY: natural feedback is available during acquisition and then deleted, with no persistent write;DIVERGE_ONLY: coherent branch search without persistent policy state;FAST_WEIGHT: unlocalized session update from complete branch outcomes;TRANSIENT_GRAD: matched transient gradient/LoRA-style policy update;PL1_ORACLE: unchanged typed PL1 on the same hidden episodes;NPL1: STI1 natural transactions plus verified branch-local credit.
The candidate may not receive more proposals, verifier calls, retained bytes, or hidden labels than any matched arm. Oracle is a ceiling, not a candidate.
5. Causal controls
The unchanged NPL1 runtime is evaluated under shuffled verifier outcomes, wrong-branch credit, plastic-state reset, unrelated-episode state transplant, poison plus exact rollback, no eligibility trace, QUERY role swap, EVIDENCE target/distractor swap, and protected-owner mutation injection. A transaction with a stale packet, source, branch, attempt, certificate, owner, or plastic pre-state commitment must fail closed.
6. Split custody
Development contains 256 episodes from one frozen seed. Confirmation contains five independently seeded sets of 256 episodes. Exact alias, mapping, program, transition, renderer tuple, and source identity overlap across PL1, development, and confirmation must be zero. The independent assessor re-executes every program and certificate without importing the candidate runtime.
Development may calibrate only board nondegeneracy and verify that the frozen STI owners can consume the new surfaces. It may not tune PL1 rank, branch count, attempts, write norm, score clip, renderer, parser, or threshold.
7. Frozen pass gate
All conditions are conjunctive across the five confirmation seeds:
- WORLD structural packets, natural EVIDENCE receipts, and natural QUERY receipts are each at least 99.5% exact aggregate and at least 99% per seed;
- NPL1 context-free transfer is at least 80% aggregate and 75% per seed;
- NPL1 remains within five absolute points of
PL1_ORACLEaggregate and on at least four of five seeds; - NPL1 exceeds every non-oracle matched arm by at least ten points aggregate, by at least five points on four of five seeds, and every paired 5,000-sample bootstrap lower bound is above zero;
- transfer exactness after attempt 12 exceeds attempt 1 by at least 50 points;
- reset loses at least 25 points and returns within three points of STATIC;
- shuffled credit, wrong-branch credit, and unrelated transplant do not beat STATIC by more than three points;
- no-eligibility loses at least five points;
- QUERY role swap and EVIDENCE role swap each lose at least 25 points;
- poison changes behavior in at least 95% of episodes and rollback restores the exact pre-poison state hash and outputs in every episode;
- source/text deletion is complete, all stale/cross-branch writes reject, and every protected owner hash remains exact; and
- parameter, token, FLOP, verifier-call, mutable-byte, activation-memory, wall-time, per-attempt, per-depth, update-norm, and effective-rank receipts are complete.
8. Kill boundary
A miss closes this exact natural PL1 integration. Do not retry owner, rank, width, branch count, attempt count, write budget, renderer, parser, duration, seed, or threshold. One read-only attribution may distinguish semantic compilation failure from policy-credit failure. A pass qualifies a controlled natural verified-plasticity mechanism; it still does not authorize continuation pretraining or establish open-domain reasoning.
9. Admission result
STI1 confirmation reaches only 640/768 QUERY transactions and fails its
renderer, mode, sensitive-answer, invariant-answer, and abstention floors.
The missing query semantics are a complete role inversion on one held-out
renderer; the protected EVIDENCE path remains 3,072/3,072. Natural
branch-local credit therefore cannot distinguish correct from inverted query
transactions reliably enough to satisfy this contract.
The development corpus contains 256 unique episodes, 24,576 evidence plans,
and 8,192 queries with zero overlap against prior PL1 splits. Its public,
assessor, and report SHA-256 values are
a38381a01bfe50d76ac50acf80ec814664508534228936493eec6e91039ae4af,
da5ca87479960317d92c47ead18e70741b41a4eae33e329fdb40db3b2e494583,
and 45425ba00ef98f353eed681047956a8f682c4b7366c9dda5c9ab25849dcd4206.
It is retained read-only. confirmation_generated=false remains exact.
Conditional semantic jobs 744406/744412 were canceled without allocation.
Oracle-typed PL1 remains the protected positive mechanics result; raw-language
PL1 remains blocked pending a structurally different semantic compiler.