Research note / Cycle 004
Before the receiver makes its second copy
A first-record witness catches an edit that two agreeing archives conceal. An interior timing anchor catches a clock excursion that endpoint synchronization misses.
The first sample is part of the instrument
Lumen proposes optical infrastructure that could keep surface users and Earth gateways connected. Its receiver would turn detector readings into a useful stream while retaining enough raw history to inspect a transient or a processing decision. The preceding replay study compared surviving copies. This study moves the challenge upstream, before the receiver makes its second copy.
We authored twelve photodiode sample records and a separately retained digest for each first acquisition. Two archives then receive copies. The digest is an assumed witness of what was recorded at acquisition, not proof that a detector observed the world correctly. Payloads are labels in software; there is no light source or photodiode hardware in this experiment.
Two identical archives can preserve the same edit
The injected pre-copy edit replaces event five before both archives receive it. Their agreement survives. A digest retained separately from the edited stream disagrees, leaving eleven recovered events and one disputed event. Both archived variants remain accessible even when their contents are identical; the discrepancy is with the first-record witness.
If the purported witness is recomputed from the edited source, all twelve pass. That is a deliberate blind spot. A checksum cannot rescue a witness that inherits the same changed input. A post-copy edit instead produces two conflicting archive variants. The shared-gap case has eleven recovered events and one missing event; the missing-witness case has eleven recovered events and one surviving but unwitnessed event. Each state needs its own display and later review path.
The clock can wander and return
Reed and Haddad used their methods exchange to ask where a clock correction gets its authority. With supplied endpoints at true/local 0/7 and 1,000/1,017 milliseconds, the linear control places the midpoint local reading at 512 milliseconds and reconstructs 500 milliseconds.
The second case adds a 20-millisecond excursion at the midpoint while preserving both endpoints. Its local midpoint is 532 milliseconds. Endpoint-only correction estimates 519.801980 milliseconds for the true 500-millisecond event. A separately supplied midpoint anchor exposes a 20-millisecond local residual, beyond the authored five-millisecond tolerance; endpoint timing is withheld.
One interior anchor does not measure the entire clock path. It exposes this supplied excursion, and another excursion between anchors could still escape. We have a reason to reject one timing fit, not a universal bound on timing error.
Continue service without promoting agreement to truth
Chen keeps the uncontested portion available. Haddad keeps disputed, missing and unwitnessed identifiers beside it. They separate the survival of the service stream from permission to use a sample for a timing claim. The next design task is a receiver-side witness retained before adaptive rewriting, with explicit failure behavior if that witness is unavailable.
First-record witnesses and timing anchors are authored independent inputs. A shared witness accepts the injected lie; sparse anchors cannot bound every between-anchor excursion. No lunar link or optical hardware tested.
Results at a glance
| Record case | Recovered | Missing IDs | Disputed IDs | Unwitnessed IDs |
|---|---|---|---|---|
| intact_control | 12 | [] | [] | [] |
| pre_copy_edit_independent_witness | 11 | [] | [5] | [] |
| pre_copy_edit_shared_witness | 12 | [] | [] | [] |
| post_copy_conflict | 11 | [] | [5] | [] |
| shared_gap | 11 | [5] | [] | [] |
| missing_first_witness | 11 | [] | [] | [5] |