Cassette Build Report 032 — The Goal Would Not Accept Almost
S01 and S12 remediation reproduced old defects, closed the Mac suite and ledger, and still had to account for shared build-story state before the proof was complete.

Scope note: This report covers the execution of the S01/S12 audit-remediation goal. It includes the shared-checkout collision that delayed closure; it does not reopen S13 or claim that the next queue step has begun.
The previous report ended with a specification. This one had to survive contact with a Mac, a repository, and a full suite that had no interest in how reasonable the specification sounded.
Drew handed GPT-5.6 Ultra a goal with ten outcomes, seven defects to reproduce, eight contradictory certificate classes, four mandatory guard-removal mutations, thirteen final checks, and twenty stopping conditions. The goal also prohibited S13, history rewriting, silent fallbacks, new numerical kernels, new model branches, speculative operator support, Build Story work, and any push to GitHub. The list was long because every shortcut had acquired an address.
The opening checkout passed twenty-eight tests and a clean ledger. The remediation then attacked the old state in disposable copies before changing it. A Python environment placed inside the repository made the old ledger count foreign files as Cassette source. The S12 native-link assertion searched the complete otool output and mistook the inspected binary’s path for one of its loaded dependencies. The README command stopped at missing MLX. Changing a dimension in MATHS.md left the generated tables unchanged because the generator carried a second list.
The eight contradictory certificates were reproduced and left with S13. That decision mattered. S12 was responsible for bounded representation and declared golden execution. S13 was responsible for recomputing whether a structurally valid certificate told the truth. A result can be surprising without belonging to the step that revealed it.
S01’s repair changed ledger ownership. The tool now uses Git-tracked Python files plus intentionally introduced, nonignored files, while excluding an untracked tree only when a real pyvenv.cfg marks an environment. The distinction is material: a foreign interpreter may sit under the checkout without becoming Cassette, while a new Cassette file cannot hide by remaining unstaged.
S12’s native-link proof changed in the same direction. It parses Mach-O load commands after the otool -L heading, resolves loader, executable, absolute, and rpath entries, and compares the resulting files with paths owned by the supplied Git repository. The binary’s location and the code it loads became separate facts.
The mathematical repair removed a duplicate authority. MATHS.md now contains one bounded JSON block between exact markers. The generator derives dimensions from the schema, rejects disagreement with the authority, and preserves the order written in the document. A set-changing edit, a duplicate, malformed JSON, or a reordered dimension becomes an integrity failure instead of a quiet divergence.
The queue records that boundary as a status, not a mood:
status: DONE 2026-08-09 — audit remediation 306055d...
done_when: full suite + ledger green
The S01/S12 closeout in IMPLEMENTATION.md is the authority for the actual probes and observed results. The excerpt says that a step closed; it does not make the status true by itself. The clean clone, complete suite, ledger, regeneration, and mutation results supply that proof.
The first repaired run returned twenty-seven passes and one APFS device-busy failure. “One unrelated failure” was not an acceptable ending. The exact test-owned image was still attached. GPT-5.6 Ultra detached that image, ran S06 alone, then ran the full suite again. All twenty-eight tests passed on the Mac, with S06, S08, and S12 executed rather than represented by Linux skips.
The goal still could not close. Another agent had appended seventy-eight lines to BUILD_STORY.md during the remediation. The instruction was to preserve the change, not absorb it, and the literal clean-tree requirement remained. GPT-5.6 Ultra stopped instead of committing another agent’s testimony without authority. I asked whether I needed to commit. The answer should have been no, followed by the exact authority request. Once I authorized the shared state, the complete repository was committed, pushed, cloned again, and rechecked. The clone passed all twenty-eight tests, regenerated without a diff, and remained clean.
The result changed my understanding of completion. A green implementation was not enough. The source had to be owned, the proof had to be rerun at the published tip, and the shared editorial record had to have a lawful place in the commit. The goal accepted the work only when “almost” had nowhere left to hide.
