# R12 Episodic Rule-Card Categorical State Transport

**Protocol:** `R12-ER-CST-v1-theory`

**Status:** CPU mechanics and the parameter-audited v1.2 neural adapter are locally
admitted before source freeze. V1 omitted late query; v1.1 had only eight slots for
depth eight plus pre-apply HALT. Both closed before board generation. V1.2 uses nine
event slots and thirteen records. No board seed, training seed, H100 job, development
score, or confirmation access exists.

## 1. Why this is the next experiment

SD-CST Complete Physical Fresh v1.3 confirms that a 192,129,179-parameter system
can compile split-disjoint names and unseen compositions of known renderer factors
into a source-deleted categorical program, execute one-to-six recurrent updates,
halt, and answer exactly. Its remaining claim boundary is sharp: the event ontology
is fixed. The compiler still learns that a small closed set of source constructions
means the same three transition kinds.

The next experiment must vary **what an operation means inside each problem**. It
must not merely add paraphrases, layers, epochs, or another language scratchpad.

## 2. Primary hypothesis

An episode supplies three opaque operation names. Each operation is defined by one
determining before/after example over three fresh witness symbols. The example
identifies one position permutation in `S_3`. Program records invoke those opaque
names in a new order. Entity names, witness symbols, operation names, source
renderers, program, and query are split-disjoint.

Shohin must emit:

1. three categorical rule cards, each a permutation of three positions;
2. a categorical program of rule-card references plus HALT;
3. an initial entity order and late query.

After packet sealing, all source text and residuals are destroyed. A tied learned
rule-card motor receives only the current categorical state and selected categorical
card. It applies the same transition at every recurrent step. The reader receives
only the terminal state and query.

This tests episodic semantic binding and compositional reuse. It does not claim
unrestricted operation invention: the rule family is the six finite position
permutations, and the determining-witness contract is structural.

## 3. Identification theorem

Let `x = (x0, x1, x2)` contain three distinct symbols and let `y` contain exactly
the same symbols. There is one and only one permutation `p in S_3` satisfying
`y[j] = x[p[j]]` for all output positions `j`. Therefore one complete witness
identifies the categorical rule card exactly.

If a tied motor applies each identified card exactly, induction on program depth
gives exact execution for every finite sequence of those cards. This is an
identification theorem under the named finite hypothesis family, not a separation
from transformers or a proof of general reasoning.

The executable CPU mechanics in `pipeline/er_cst_rule_cards.py` must pass before
any neural implementation. Ambiguous witnesses with repeated symbols and malformed
witnesses with unequal symbol sets are rejected rather than repaired.

## 4. Neural architecture budget

The confirmed v1.3 checkpoint remains the parent. The full deployed system may
remain below the user-authorized 200M ceiling but may not exceed it:

| Component | Parameters |
|---|---:|
| Confirmed v1.3 complete system | 192,129,179 |
| ER-CST v1.2 complete system | 192,421,936 |
| Net increase after motor replacement | 292,757 |
| Remaining headroom below 200M | 7,578,064 |
| Absolute complete-system maximum | 199,999,999 |

The favorable treatment may reuse and fine-tune the confirmed physical line encoder.
New parameters are limited to a thirteen-role record path, rule/event norms, a
permutation-card head, opaque-opcode binding projections, a HALT head, and a tied
rule-card motor. The exact 98-compiler-tensor plus four-motor-tensor trainability
contract is frozen in `R12_ER_CST_NEURAL_ADAPTER_PREREG.md` and its amendments;
its v1.2 name/shape/count hash is `1e637f3d...`. The adapter adds 309,525 compiler
parameters and replaces the old 19,206-parameter motor with a 2,438-parameter tied
motor. The inherited frozen query compiler adds no parameter or trainable tensor.

The treatment may receive rule-card, opcode-pointer, program-pointer, initial-state,
and query targets on training rows. It may not receive final states, answers,
recurrent trajectories, development/confirmation rule cards, or confirmation bytes.

## 5. Fresh-board split

The production board should preserve the proven 48,000/2,048/2,048 custody pattern.
Each family has multiple renderer views, but family membership never crosses splits.

- training uses even-parity combinations of declaration, witness, event, and query
  renderer factors;
- development and sealed confirmation use odd-parity combinations;
- entity names, witness symbols, and opcode names are globally split-disjoint;
- before-state witness order is randomized, so output position alone does not reveal
  the card without matching symbol identity;
- all six permutations, depths one through eight, and all query positions are
  balanced within every split;
- exact prompt, 13-gram, name, latent family, and program-sequence overlap is zero;
- confirmation remains mode `0600` and inaccessible until a separate evaluator is
  committed after development authorization.

## 6. Matched controls

1. **Family-deranged rule cards:** identical source, architecture, initialization,
   updates, and compute; rotate the three card targets within each family.
2. **Equality-ablated witnesses:** replace every repeated witness symbol occurrence
   with an independent nonce while preserving lengths and renderer statistics.
3. **Opcode-deranged binding:** retain correct cards but rotate event-to-card links.
4. **Source-free card logits:** zero the witness representation after compilation.
5. **Uniform and shuffled packets:** unchanged source-blind executor controls.
6. **Card storage reindex:** reorder rule-card records without changing semantics;
   treatment output and execution must remain bit-identical after canonicalization.
7. **Witness alpha rename:** consistently rename all witness symbols; cards, state,
   and answer must remain bit-identical.
8. **Opcode alpha rename:** consistently rename definitions and invocations; cards,
   state, and answer must remain bit-identical.
9. **Post-HALT suffix:** alter only records after predicted HALT; output must remain
   bit-identical.
10. **Witness corruption:** change one witness relation and score against the changed
    oracle. The system may not repair toward the original answer.

## 7. Development gates

The sole development read authorizes one sealed confirmation only if all gates pass:

- at least 95% exact rule cards overall and at least 90% on every renderer;
- at least 95% exact opcode-to-card binding;
- at least 90% exact complete packets and state/answer joints;
- at least 85% exact joint on every renderer and every depth one through eight;
- conditional execution is 100% exact given gold packets;
- family-deranged and opcode-deranged complete packets are at most 20%;
- equality-ablated exact cards are at most 35%;
- witness/opcode alpha rename and card-storage reindex are bit-identical on every
  mutually valid row;
- post-HALT perturbation is bit-identical;
- witness corruption follows the changed oracle and does not preserve the original;
- source deletion, frozen-parent digest, exact parameter certificate, and custody
  `1/0` all pass;
- complete deployed parameters are strictly below 200M.

Any failed absolute, causal, attribution, parameter, or custody gate closes that
source/board without rescore. Passing establishes bounded episodic rule compilation
and recurrent composition. It does not establish arithmetic, branching, free-form
language programs, planning, or general reasoning.

## 8. Ordered work

1. Run and preserve the deterministic CPU falsifier.
2. Implement the smallest rule-card adapter and exact parameter ledger. **Done.**
3. Add gradient, source-deletion, malformed-card, and matched-arm tests. **Done for
   the architecture contract; board-level matched-arm tests remain pre-freeze.**
4. Freeze and push exact scientific source.
5. Draw a board seed, build/audit/rebuild/seal the board, and commit its receipt.
6. Draw one training seed and run one development job.
7. Open confirmation once only after a separately frozen evaluator and a complete
   development pass.
